--------------- QuickDiag | g3n-h@ckm@n | V5_01.11.19.1 --------------- ----- XP | Vista | 7 | 8 | 8.1 | 10 - 32/64 bits ----- - Start 17/12/2019 14:43:35 Updated 01/11/2019 | 14:35 (GMT) by g3n-h@ckm@n Contact : http://www.sosvirus.net/ Time Zone : (UTC+01:00) Bruxelles, Copenhague, Madrid, Paris [EVRARD (Administrator)] - [ELITE344] (S-1-5-21-548730727-4139670515-3000484307-1001) System: Microsoft Windows 10 Famille - - (10.0.18363) - BuildType: Multiprocessor Free - OSLanguage: 1036 (040c) -> (1909) System: AutoReboot: True - DebugFilePath: %SystemRoot%\MEMORY.DMP - KernelDumpOnly: False - OverwriteExistingDebugFile: True - WriteDebugInfo: True - WriteToSystemLog: True Boot : Microsoft Windows 10 Famille|C:\WINDOWS|\Device\Harddisk1\Partition2 Boot : Normal boot PC: All Series - ASUS - IdNumber: System Serial Number - UUID: 1C8633C0-D7DA-11DD-9C45-D850E63F6F91 Processor : X64 - 3400 Mhz - Intel(R) Core(TM) i5-4670 CPU @ 3.40GHz BIOS Date: 08/15/13 17:46:50 Ver: 06.04 - fr|FR|iso8859-1 - American Megatrends Inc. - S/N: System Serial Number - 0604 - ALASKA - 1072009 CoreTemp : 29.8 Celsius ----------| Quick ---------- | SoundDevice Hercules HD Sunset Mic - Status: OK - Manufacturer: Guillemot Corporation - PNPDeviceID: USB\VID_06F8&PID_3017&MI_02\6&12E2EA49&0&0002 NVIDIA High Definition Audio - Status: OK - Manufacturer: NVIDIA - PNPDeviceID: HDAUDIO\FUNC_01&VEN_10DE&DEV_0051&SUBSYS_10438461&REV_1001\5&176F301B&0&0001 Realtek High Definition Audio - Status: OK - Manufacturer: Realtek - PNPDeviceID: HDAUDIO\FUNC_01&VEN_10EC&DEV_0887&SUBSYS_10438576&REV_1003\4&29E4DF1&0&0001 NVIDIA Virtual Audio Device (Wave Extensible) (WDM) - Status: OK - Manufacturer: NVIDIA - PNPDeviceID: ROOT\UNNAMED_DEVICE\0000 ---------- | Video NVIDIA GeForce GT 630 - Resolution: 1920x1080 - Colors: 4294967296 - RefreshRate: 60 - 32 Bits Per Pixel - DeviceID: VideoController1 - Drivers: C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_77e6900053c33f6f\nvldumdx.dll,C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_77e6900053c33f6f\nvldumdx.dll,C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_77e6900053c33f6f\nvldumdx.dll,C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_77e6900053c33f6f\nvldumdx.dll - PNPDeviceID: PCI\VEN_10DE&DEV_1284&SUBSYS_84611043&REV_A1\4&3834D97&0&0008 - AdapterCompatibility: NVIDIA - RAM: -2147483648 Inegrated Video Chipset DeviceName: NVIDIA GeForce GT 630 - DriverVersion: 26.21.14.4166 - SpecificationVersion: 1025 ---------- | Codecs C:\WINDOWS\system32\IYUV_32.DLL - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 54272 - Manufacturer: Microsoft Corporation - Status: OK C:\WINDOWS\system32\VCT3216.ACM - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 82944 - Manufacturer: Voxware, Inc. - Status: OK C:\WINDOWS\system32\MSGSM32.ACM - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 42600 - Manufacturer: Microsoft Corporation - Status: OK C:\WINDOWS\system32\IMAADP32.ACM - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 36920 - Manufacturer: Microsoft Corporation - Status: OK C:\WINDOWS\system32\SCG726.ACM - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 13239 - Manufacturer: SHARP Corporation - Status: OK C:\WINDOWS\system32\MSVIDC32.DLL - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 39424 - Manufacturer: Microsoft Corporation - Status: OK C:\WINDOWS\system32\MSRLE32.DLL - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 17920 - Manufacturer: Microsoft Corporation - Status: OK C:\WINDOWS\system32\MCDVD_32.DLL - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 261632 - Manufacturer: MainConcept - Status: OK C:\WINDOWS\system32\DIVX.DLL - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 638976 - Manufacturer: DivXNetworks, Inc. - Status: OK C:\WINDOWS\system32\VP6VFW.DLL - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 438272 - Manufacturer: On2.com - Status: OK C:\WINDOWS\system32\MSYUV.DLL - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 27648 - Manufacturer: Microsoft Corporation - Status: OK C:\WINDOWS\system32\LAME.AX - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 245760 - Manufacturer: - Status: OK C:\WINDOWS\system32\XVIDVFW.DLL - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 139264 - Manufacturer: - Status: OK C:\WINDOWS\system32\TSBYUV.DLL - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 16896 - Manufacturer: Microsoft Corporation - Status: OK C:\WINDOWS\system32\LAGARITH.DLL - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 216064 - Manufacturer: - Status: OK C:\WINDOWS\system32\MPG4C32.DLL - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 413760 - Manufacturer: Microsoft Corporation - Status: OK C:\WINDOWS\system32\AC3ACM.ACM - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 81920 - Manufacturer: fccHandler - Status: OK C:\WINDOWS\system32\MSG711.ACM - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 26056 - Manufacturer: Microsoft Corporation - Status: OK C:\WINDOWS\system32\MSADP32.ACM - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 34808 - Manufacturer: Microsoft Corporation - Status: OK C:\WINDOWS\system32\L3CODECA.ACM - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 92672 - Manufacturer: Fraunhofer Institut Integrierte Schaltungen IIS - Status: OK C:\WINDOWS\system32\ALF2CD.ACM - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 38912 - Manufacturer: NCT Company - Status: OK ---------- | Memory Pagefile = Total (MB) : 16715 | Free (MB) : 11245 Virtual = Total (MB) : 4194 | Free (MB) : 3875 Physical Memory (MB) -------------------- Total: 8130 Available: 3122 Cached: 3417 Free: 974 Kernel Memory (MB) ------------------ Paged: 624 Nonpaged: 349 System ------ Handles: 95343 Processes: 192 Threads: 2761 ---------- | SID Users Administrateur : [S-1-5-21-548730727-4139670515-3000484307-500] DefaultAccount : [S-1-5-21-548730727-4139670515-3000484307-503] EVRARD : [S-1-5-21-548730727-4139670515-3000484307-1001] Invité : [S-1-5-21-548730727-4139670515-3000484307-501] WDAGUtilityAccount : [S-1-5-21-548730727-4139670515-3000484307-504] Administrateurs : [S-1-5-32-544] Administrateurs Hyper-V : [S-1-5-32-578] IIS_IUSRS : [S-1-5-32-568] Invités : [S-1-5-32-546] Lecteurs des journaux d’événements : [S-1-5-32-573] System Managed Accounts Group : [S-1-5-32-581] Utilisateurs : [S-1-5-32-545] Utilisateurs de gestion à distance : [S-1-5-32-580] Utilisateurs de l’Analyseur de performances : [S-1-5-32-558] Utilisateurs du journal de performances : [S-1-5-32-559] Utilisateurs du modèle COM distribué : [S-1-5-32-562] WinRMRemoteWMIUsers__ : [S-1-5-21-548730727-4139670515-3000484307-1000] ---------- | Drives C:\ -> [Fixed] | [] | Total : 110.52 Go | Free : 14.36 Go -> NTFS (SSD) [SATA] D:\ -> [Removable] | [SAUVEGARDE] | Total : 57.7 Go | Free : 7.71 Go -> FAT32 [USB] E:\ -> [Fixed] | [Données] | Total : 931.51 Go | Free : 199.69 Go -> NTFS [SATA] G:\ -> [Removable] | [SSD DOCUMEN] | Total : 238.49 Go | Free : 77.03 Go -> exFAT [USB] Drive: 0 Cylinders: 121601 Tracks per Cylinder: 255 Sectors per Track: 63 Bytes per Sector: 512 Total Space: 1000204886016 bytes Drive: 1 Cylinders: 14593 Tracks per Cylinder: 255 Sectors per Track: 63 Bytes per Sector: 512 Total Space: 120034123776 bytes Drive: 2 Cylinders: 31134 Tracks per Cylinder: 255 Sectors per Track: 63 Bytes per Sector: 512 Total Space: 256087425024 bytes Drive: 3 Cylinders: 7538 Tracks per Cylinder: 255 Sectors per Track: 63 Bytes per Sector: 512 Total Space: 62008590336 bytes ---------- | Windows updates - Activation - License W.A.T : :) Test 1 : Windows Is Activated Volume License ---------- | Browsers IE : 11.0.18362.1 (© Microsoft Corporation. Tous droits réservés.) GC : 79.0.3945.79 (Copyright 2019 Google LLC.) ---------- | FlashPlayer FlashPlayer ActiveX : 32.0.0.255 FlashPlayer Plugin : 32.0.0.303 ---------- | Security AV : Windows Defender Disabled AS : Avast Antivirus Enabled FW : WINDOWS Firewall WMI : OK WU: Windows Update Service [Manual(3)] = Running AS: Windows Defender [Auto(2)] = Running WMI: Windows Management Instrumentation [Auto(2)] = Running ---------- | Running processes 420 | [Owner : Système | Parent : 4(System) | ?????] - (.Microsoft Corporation - Gestionnaire de sessions Windows.) - (10.0.18362.329) = C:\Windows\System32\smss.exe [17/09/2019 16:26:37] CPU Usage:0 % 596 | [Owner : Système | Parent : 588() | ?????] - (.Microsoft Corporation - Processus d’exécution client-serveur.) - (10.0.18362.1) = C:\Windows\System32\csrss.exe [19/03/2019 05:44:35] CPU Usage:0 % 692 | [Owner : Système | Parent : 588() | ?????] - (.Microsoft Corporation - Application de démarrage de Windows.) - (10.0.18362.387) = C:\Windows\System32\wininit.exe [09/10/2019 11:08:09] CPU Usage:0 % 700 | [Owner : Système | Parent : 680() | ?????] - (.Microsoft Corporation - Processus d’exécution client-serveur.) - (10.0.18362.1) = C:\Windows\System32\csrss.exe [19/03/2019 05:44:35] CPU Usage:0 % 764 | [Owner : Système | Parent : 692(wininit.exe) | ?????] - (.Microsoft Corporation - Applications Services et Contrôleur.) - (10.0.18362.535) = C:\Windows\System32\services.exe [11/12/2019 13:39:33] CPU Usage:0 % 776 | [Owner : Système | Parent : 692(wininit.exe) | 21.26 Mo] - (.Microsoft Corporation - Local Security Authority Process.) - (10.0.18362.1) = C:\Windows\System32\lsass.exe [19/03/2019 05:44:36] CPU Usage:0 % 856 | [Owner : Système | Parent : 680() | 12.24 Mo] - (.Microsoft Corporation - Application d’ouverture de session Windows.) - (10.0.18362.449) = C:\Windows\System32\winlogon.exe [16/11/2019 17:00:57] CPU Usage:0 % 996 | [Owner : Système | Parent : 764(services.exe) | 3.99 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.18362.1) = C:\Windows\System32\svchost.exe [19/03/2019 05:44:33] CPU Usage:0 % 1020 | [Owner : Système | Parent : 764(services.exe) | 30.01 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.18362.1) = C:\Windows\System32\svchost.exe [19/03/2019 05:44:33] CPU Usage:0 % 344 | [Owner : UMFD-1 | Parent : 856(winlogon.exe) | 11.41 Mo] - (.Microsoft Corporation - Usermode Font Driver Host.) - (10.0.18362.535) = C:\Windows\System32\fontdrvhost.exe [11/12/2019 13:39:33] CPU Usage:0 % 400 | [Owner : UMFD-0 | Parent : 692(wininit.exe) | 4.25 Mo] - (.Microsoft Corporation - Usermode Font Driver Host.) - (10.0.18362.535) = C:\Windows\System32\fontdrvhost.exe [11/12/2019 13:39:33] CPU Usage:0 % 536 | [Owner : SERVICE LOCAL | Parent : 764(services.exe) | 6.36 Mo] - (.Microsoft Corporation - Windows Driver Foundation - Processus hôte de l’infrastructure de pilotes en mode utilisateur.) - (10.0.18362.1) = C:\Windows\System32\WUDFHost.exe [19/03/2019 05:44:53] CPU Usage:0 % 1056 | [Owner : SERVICE RÉSEAU | Parent : 764(services.exe) | 18.53 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.18362.1) = C:\Windows\System32\svchost.exe [19/03/2019 05:44:33] CPU Usage:0 % 1112 | [Owner : Système | Parent : 764(services.exe) | 8.64 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.18362.1) = C:\Windows\System32\svchost.exe [19/03/2019 05:44:33] CPU Usage:0 % 1180 | [Owner : DWM-1 | Parent : 856(winlogon.exe) | 75.44 Mo] - (.Microsoft Corporation - Gestionnaire de fenêtres du Bureau.) - (10.0.18362.387) = C:\Windows\System32\dwm.exe [09/10/2019 11:08:05] CPU Usage:0 % 1256 | [Owner : SERVICE LOCAL | Parent : 764(services.exe) | 5.53 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.18362.1) = C:\Windows\System32\svchost.exe [19/03/2019 05:44:33] CPU Usage:0 % 1308 | [Owner : Système | Parent : 764(services.exe) | 11.08 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.18362.1) = C:\Windows\System32\svchost.exe [19/03/2019 05:44:33] CPU Usage:0 % 1332 | [Owner : SERVICE LOCAL | Parent : 764(services.exe) | 12.48 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.18362.1) = C:\Windows\System32\svchost.exe [19/03/2019 05:44:33] CPU Usage:0 % 1448 | [Owner : Système | Parent : 764(services.exe) | 16.84 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.18362.1) = C:\Windows\System32\svchost.exe [19/03/2019 05:44:33] CPU Usage:0 % 1536 | [Owner : Système | Parent : 764(services.exe) | 12.42 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.18362.1) = C:\Windows\System32\svchost.exe [19/03/2019 05:44:33] CPU Usage:0 % 1544 | [Owner : Système | Parent : 764(services.exe) | 16.8 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.18362.1) = C:\Windows\System32\svchost.exe [19/03/2019 05:44:33] CPU Usage:0 % 1596 | [Owner : SERVICE LOCAL | Parent : 764(services.exe) | 19.25 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.18362.1) = C:\Windows\System32\svchost.exe [19/03/2019 05:44:33] CPU Usage:0 % 1608 | [Owner : SERVICE LOCAL | Parent : 764(services.exe) | 6.14 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.18362.1) = C:\Windows\System32\svchost.exe [19/03/2019 05:44:33] CPU Usage:0 % 1728 | [Owner : SERVICE LOCAL | Parent : 764(services.exe) | 8.51 Mo] - (.Microsoft Corporation - Windows Driver Foundation - Processus hôte de l’infrastructure de pilotes en mode utilisateur.) - (10.0.18362.1) = C:\Windows\System32\WUDFHost.exe [19/03/2019 05:44:53] CPU Usage:0 % 1812 | [Owner : Système | Parent : 764(services.exe) | 19.53 Mo] - (.NVIDIA Corporation - NVIDIA Container.) - (1.19.2722.8896) = C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [15/12/2019 21:02:24] CPU Usage:0 % 1820 | [Owner : Système | Parent : 764(services.exe) | 10.64 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.18362.1) = C:\Windows\System32\svchost.exe [19/03/2019 05:44:33] CPU Usage:0 % 1868 | [Owner : SERVICE LOCAL | Parent : 764(services.exe) | 10 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.18362.1) = C:\Windows\System32\svchost.exe [19/03/2019 05:44:33] CPU Usage:0 % 1912 | [Owner : SERVICE LOCAL | Parent : 764(services.exe) | 7.94 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.18362.1) = C:\Windows\System32\svchost.exe [19/03/2019 05:44:33] CPU Usage:0 % 1968 | [Owner : Système | Parent : 764(services.exe) | 5.89 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.18362.1) = C:\Windows\System32\svchost.exe [19/03/2019 05:44:33] CPU Usage:0 % 1976 | [Owner : SERVICE LOCAL | Parent : 764(services.exe) | 8.02 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.18362.1) = C:\Windows\System32\svchost.exe [19/03/2019 05:44:33] CPU Usage:0 % 1984 | [Owner : Système | Parent : 764(services.exe) | ?????] - (.AVAST Software - Avast Antivirus remediation exe.) - (19.8.4793.0) = C:\Program Files\AVAST Software\Avast\wsc_proxy.exe [20/09/2019 20:15:48] CPU Usage:0 % 2100 | [Owner : Système | Parent : 764(services.exe) | 8.3 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.18362.1) = C:\Windows\System32\svchost.exe [19/03/2019 05:44:33] CPU Usage:0 % 2112 | [Owner : SERVICE LOCAL | Parent : 764(services.exe) | 7.6 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.18362.1) = C:\Windows\System32\svchost.exe [19/03/2019 05:44:33] CPU Usage:0 % 2128 | [Owner : SERVICE RÉSEAU | Parent : 764(services.exe) | 12.49 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.18362.1) = C:\Windows\System32\svchost.exe [19/03/2019 05:44:33] CPU Usage:0 % 2192 | [Owner : SERVICE RÉSEAU | Parent : 764(services.exe) | 9.4 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.18362.1) = C:\Windows\System32\svchost.exe [19/03/2019 05:44:33] CPU Usage:0 % 2244 | [Owner : Système | Parent : 764(services.exe) | 11.41 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.18362.1) = C:\Windows\System32\svchost.exe [19/03/2019 05:44:33] CPU Usage:0 % 2404 | [Owner : Système | Parent : 764(services.exe) | 8.16 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.18362.1) = C:\Windows\System32\svchost.exe [19/03/2019 05:44:33] CPU Usage:0 % 2420 | [Owner : SERVICE LOCAL | Parent : 764(services.exe) | 13.44 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.18362.1) = C:\Windows\System32\svchost.exe [19/03/2019 05:44:33] CPU Usage:0 % 2456 | [Owner : SERVICE LOCAL | Parent : 764(services.exe) | 9.28 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.18362.1) = C:\Windows\System32\svchost.exe [19/03/2019 05:44:33] CPU Usage:0 % 2508 | [Owner : Système | Parent : 764(services.exe) | 22.81 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.18362.1) = C:\Windows\System32\svchost.exe [19/03/2019 05:44:33] CPU Usage:0 % 2572 | [Owner : Système | Parent : 1812(NVDisplay.Container.exe) | 54.63 Mo] - (.NVIDIA Corporation - NVIDIA Container.) - (1.19.2722.8896) = C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [15/12/2019 21:02:24] CPU Usage:0 % 2704 | [Owner : SERVICE LOCAL | Parent : 764(services.exe) | 7.54 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.18362.1) = C:\Windows\System32\svchost.exe [19/03/2019 05:44:33] CPU Usage:0 % 2928 | [Owner : SERVICE LOCAL | Parent : 764(services.exe) | 11.65 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.18362.1) = C:\Windows\System32\svchost.exe [19/03/2019 05:44:33] CPU Usage:0 % 2208 | [Owner : SERVICE LOCAL | Parent : 764(services.exe) | 14.65 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.18362.1) = C:\Windows\System32\svchost.exe [19/03/2019 05:44:33] CPU Usage:0 % 3156 | [Owner : Système | Parent : 764(services.exe) | 18.49 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.18362.1) = C:\Windows\System32\svchost.exe [19/03/2019 05:44:33] CPU Usage:0 % 3184 | [Owner : SERVICE LOCAL | Parent : 764(services.exe) | 6.64 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.18362.1) = C:\Windows\System32\svchost.exe [19/03/2019 05:44:33] CPU Usage:0 % 3192 | [Owner : SERVICE LOCAL | Parent : 764(services.exe) | 10.33 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.18362.1) = C:\Windows\System32\svchost.exe [19/03/2019 05:44:33] CPU Usage:0 % 3340 | [Owner : Système | Parent : 764(services.exe) | 20.34 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.18362.1) = C:\Windows\System32\svchost.exe [19/03/2019 05:44:33] CPU Usage:0 % 3492 | [Owner : Système | Parent : 764(services.exe) | ?????] - (.AVAST Software - Avast Antivirus Service.) - (19.8.4793.0) = C:\Program Files\AVAST Software\Avast\AvastSvc.exe [20/09/2019 20:15:48] CPU Usage:0 % 3504 | [Owner : Système | Parent : 764(services.exe) | 14.95 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.18362.1) = C:\Windows\System32\svchost.exe [19/03/2019 05:44:33] CPU Usage:0 % 3892 | [Owner : Système | Parent : 764(services.exe) | 23.93 Mo] - (.Microsoft Corporation - Application sous-système spouleur.) - (10.0.18362.476) = C:\Windows\System32\spoolsv.exe [16/11/2019 16:59:53] CPU Usage:0 % 3912 | [Owner : EVRARD | Parent : 1820(svchost.exe) | 38.36 Mo] - (.Microsoft Corporation - Shell Infrastructure Host.) - (10.0.18362.1) = C:\Windows\System32\sihost.exe [19/03/2019 05:44:12] CPU Usage:0 % 3928 | [Owner : EVRARD | Parent : 764(services.exe) | 25.2 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.18362.1) = C:\Windows\System32\svchost.exe [19/03/2019 05:44:33] CPU Usage:0 % 3992 | [Owner : EVRARD | Parent : 764(services.exe) | 38.37 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.18362.1) = C:\Windows\System32\svchost.exe [19/03/2019 05:44:33] CPU Usage:0 % 4000 | [Owner : SERVICE LOCAL | Parent : 764(services.exe) | 23.12 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.18362.1) = C:\Windows\System32\svchost.exe [19/03/2019 05:44:33] CPU Usage:0 % 4048 | [Owner : SERVICE RÉSEAU | Parent : 764(services.exe) | 8.57 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.18362.1) = C:\Windows\System32\svchost.exe [19/03/2019 05:44:33] CPU Usage:0 % 3712 | [Owner : EVRARD | Parent : 1448(svchost.exe) | 22.8 Mo] - (.H.D.S. Hungary - Hard Disk Sentinel.) - (5.50.0.0) = C:\Program Files (x86)\Hard Disk Sentinel\HDSentinel.exe [28/01/2019 10:40:27] CPU Usage:0 % 3368 | [Owner : EVRARD | Parent : 1448(svchost.exe) | 8.9 Mo] - (.Microsoft Corporation - Processus hôte pour Tâches Windows.) - (10.0.18362.387) = C:\Windows\System32\taskhostw.exe [09/10/2019 11:08:08] CPU Usage:0 % 4032 | [Owner : Système | Parent : 764(services.exe) | 21.52 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.18362.1) = C:\Windows\System32\svchost.exe [19/03/2019 05:44:33] CPU Usage:0 % 4224 | [Owner : Système | Parent : 764(services.exe) | 8.24 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.18362.1) = C:\Windows\System32\svchost.exe [19/03/2019 05:44:33] CPU Usage:0 % 4372 | [Owner : EVRARD | Parent : 4224(svchost.exe) | 19.87 Mo] - (.Microsoft Corporation - Chargeur CTF.) - (10.0.18362.1) = C:\Windows\System32\ctfmon.exe [19/03/2019 05:44:33] CPU Usage:0 % 4560 | [Owner : Système | Parent : 764(services.exe) | 6.95 Mo] - (.Adobe Systems - Adobe Acrobat Update Service.) - (1.824.35.289) = C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [11/09/2019 07:16:22] CPU Usage:0 % 4568 | [Owner : Système | Parent : 764(services.exe) | 12.3 Mo] - (.-.) - (0.0.0.0) = C:\Program Files (x86)\ASUS\AXSP\1.02.00\atkexComSvc.exe [15/11/2019 17:28:02] CPU Usage:0 % 4576 | [Owner : Système | Parent : 764(services.exe) | 16.72 Mo] - (.AVerMedia - AVerRemote MFC Application.) - (1.0.1.31) = C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerRemote.exe [21/03/2014 22:33:13] CPU Usage:0 % 4584 | [Owner : Système | Parent : 764(services.exe) | 11.55 Mo] - (.- ScheduleService Module.) - (1.0.0.46) = C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerScheduleService.exe [21/03/2014 22:33:13] CPU Usage:0 % 4596 | [Owner : Système | Parent : 764(services.exe) | 8.83 Mo] - (.AVerMedia TECHNOLOGIES, Inc. - AVer Update Service.) - (2.0.2.4) = C:\Program Files (x86)\AVerMedia\AVerUpdate\AVerUpdateServer.exe [31/10/2011 19:30:00] CPU Usage:0 % 4608 | [Owner : Système | Parent : 764(services.exe) | 6.93 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.18362.1) = C:\Windows\System32\svchost.exe [19/03/2019 05:44:33] CPU Usage:0 % 4620 | [Owner : SERVICE RÉSEAU | Parent : 764(services.exe) | 58.25 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.18362.1) = C:\Windows\System32\svchost.exe [19/03/2019 05:44:33] CPU Usage:0 % 4676 | [Owner : Système | Parent : 764(services.exe) | 6.6 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.18362.1) = C:\Windows\System32\svchost.exe [19/03/2019 05:44:33] CPU Usage:0 % 4708 | [Owner : Système | Parent : 764(services.exe) | 33.75 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.18362.1) = C:\Windows\System32\svchost.exe [19/03/2019 05:44:33] CPU Usage:0 % 4732 | [Owner : SERVICE LOCAL | Parent : 764(services.exe) | 32.97 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.18362.1) = C:\Windows\System32\svchost.exe [19/03/2019 05:44:33] CPU Usage:0 % 4768 | [Owner : Système | Parent : 764(services.exe) | 47.53 Mo] - (.Intel - DSAService.) - (19.11.46.6) = C:\Program Files (x86)\Intel\Driver and Support Assistant\DSAService.exe [14/11/2019 16:15:36] CPU Usage:0 % 4816 | [Owner : Système | Parent : 764(services.exe) | 25.9 Mo] - (.Freemake - FreemakeUtilsService.) - (1.0.0.0) = C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [16/12/2019 17:45:19] CPU Usage:0 % 4868 | [Owner : Système | Parent : 764(services.exe) | 11.61 Mo] - (.- HuaweiHiSuiteService.) - (2.0.0.42) = C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe [19/08/2019 02:49:28] CPU Usage:0 % 4904 | [Owner : Système | Parent : 764(services.exe) | 7.93 Mo] - (.Intel(R) Corporation - Intel(R) Capability Licensing Service Interface.) - (1.28.487.1) = C:\Program Files\Intel\iCLS Client\HeciServer.exe [11/05/2013 17:45:38] CPU Usage:0 % 4932 | [Owner : Système | Parent : 764(services.exe) | 17.08 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.18362.1) = C:\Windows\System32\svchost.exe [19/03/2019 05:44:33] CPU Usage:0 % 4952 | [Owner : Système | Parent : 764(services.exe) | 23.49 Mo] - (.McAfee, Inc. - McAfee WebAdvisor.) - (4.1.1.57) = C:\Program Files\McAfee\WebAdvisor\servicehost.exe [12/12/2019 21:52:23] CPU Usage:0 % 4968 | [Owner : Système | Parent : 764(services.exe) | ?????] - (.Malwarebytes - Malwarebytes Service.) - (3.2.0.874) = C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [07/11/2019 22:24:16] CPU Usage:0 % 4996 | [Owner : Système | Parent : 764(services.exe) | 9.32 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.18362.1) = C:\Windows\System32\svchost.exe [19/03/2019 05:44:33] CPU Usage:0 % 5028 | [Owner : Système | Parent : 764(services.exe) | 40.52 Mo] - (.NVIDIA Corporation - NVIDIA Container.) - (1.19.2734.4859) = C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [26/05/2018 15:56:03] CPU Usage:0 % 5076 | [Owner : SERVICE LOCAL | Parent : 764(services.exe) | 6.74 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.18362.1) = C:\Windows\System32\svchost.exe [19/03/2019 05:44:33] CPU Usage:0 % 5084 | [Owner : Système | Parent : 764(services.exe) | 13.14 Mo] - (.- SPDSvc Application.) - (1.0.0.4) = C:\Windows\SysWOW64\spdsvc.exe [29/10/2018 11:44:54] CPU Usage:0 % 5116 | [Owner : SERVICE LOCAL | Parent : 764(services.exe) | 12.11 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.18362.1) = C:\Windows\System32\svchost.exe [19/03/2019 05:44:33] CPU Usage:0 % 2120 | [Owner : SERVICE LOCAL | Parent : 4676(svchost.exe) | 9.02 Mo] - (.Microsoft Corporation - Device Association Framework Provider Host.) - (10.0.18362.1) = C:\Windows\System32\dasHost.exe [19/03/2019 05:44:18] CPU Usage:0 % 4452 | [Owner : Système | Parent : 764(services.exe) | 5.7 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.18362.1) = C:\Windows\System32\svchost.exe [19/03/2019 05:44:33] CPU Usage:0 % 5124 | [Owner : Système | Parent : 764(services.exe) | 20.78 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.18362.1) = C:\Windows\System32\svchost.exe [19/03/2019 05:44:33] CPU Usage:0 % 5144 | [Owner : Système | Parent : 764(services.exe) | ?????] - (.Microsoft Corporation - Antimalware Service Executable.) - (4.18.1911.3) = C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1911.3-0\MsMpEng.exe [11/12/2019 17:43:00] CPU Usage:0 % 5592 | [Owner : Système | Parent : 764(services.exe) | 12.72 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.18362.1) = C:\Windows\System32\svchost.exe [19/03/2019 05:44:33] CPU Usage:0 % 5704 | [Owner : SERVICE LOCAL | Parent : 764(services.exe) | 6.26 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.18362.1) = C:\Windows\System32\svchost.exe [19/03/2019 05:44:33] CPU Usage:0 % 6016 | [Owner : Système | Parent : 5028(nvcontainer.exe) | 8.32 Mo] - (.Microsoft Corporation - Processus hôte Windows (Rundll32).) - (10.0.18362.1) = C:\Windows\System32\rundll32.exe [19/03/2019 05:45:05] CPU Usage:0 % 6220 | [Owner : EVRARD | Parent : 4576(AVerRemote.exe) | 8.84 Mo] - (.- HIDRec Application - AVerHID.) - (1.0.0.9) = C:\Program Files (x86)\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe [21/03/2014 22:33:37] CPU Usage:0 % 6544 | [Owner : Système | Parent : 764(services.exe) | 60.3 Mo] - (.Microsoft Corporation - Indexeur Microsoft Windows Search.) - (7.0.18362.449) = C:\Windows\System32\SearchIndexer.exe [16/11/2019 17:00:17] CPU Usage:0 % 6808 | [Owner : EVRARD | Parent : 1020(svchost.exe) | 10.42 Mo] - (.Microsoft Corporation - Processus hôte Windows (Rundll32).) - (10.0.18362.1) = C:\Windows\System32\rundll32.exe [19/03/2019 05:45:05] CPU Usage:0 % 6864 | [Owner : EVRARD | Parent : 6736() | 249.54 Mo] - (.Microsoft Corporation - Explorateur Windows.) - (10.0.18362.449) = C:\Windows\explorer.exe [16/11/2019 16:59:53] CPU Usage:0 % 7052 | [Owner : Système | Parent : 764(services.exe) | 7.35 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.18362.1) = C:\Windows\System32\svchost.exe [19/03/2019 05:44:33] CPU Usage:0 % 7196 | [Owner : SERVICE LOCAL | Parent : 764(services.exe) | 18.43 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.18362.1) = C:\Windows\System32\svchost.exe [19/03/2019 05:44:33] CPU Usage:0 % 7364 | [Owner : EVRARD | Parent : 1020(svchost.exe) | 10.86 Mo] - (.Microsoft Corporation - Host Process for Setting Synchronization.) - (10.0.18362.239) = C:\Windows\System32\SettingSyncHost.exe [07/08/2019 16:20:59] CPU Usage:0 % 7480 | [Owner : EVRARD | Parent : 4952(servicehost.exe) | 13.89 Mo] - (.McAfee, Inc. - McAfee WebAdvisor.) - (4.1.1.57) = C:\Program Files\McAfee\WebAdvisor\uihost.exe [12/12/2019 21:52:23] CPU Usage:0 % 7740 | [Owner : EVRARD | Parent : 764(services.exe) | 22.82 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.18362.1) = C:\Windows\System32\svchost.exe [19/03/2019 05:44:33] CPU Usage:0 % 8320 | [Owner : EVRARD | Parent : 5028(nvcontainer.exe) | 54.67 Mo] - (.NVIDIA Corporation - NVIDIA Container.) - (1.19.2734.4859) = C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [26/05/2018 15:56:03] CPU Usage:0 % 8608 | [Owner : EVRARD | Parent : 1020(svchost.exe) | 16.54 Mo] - (.Microsoft Corporation - COM Surrogate.) - (10.0.18362.1) = C:\Windows\System32\dllhost.exe [19/03/2019 05:44:33] CPU Usage:0 % 8732 | [Owner : EVRARD | Parent : 1020(svchost.exe) | 99.09 Mo] - (.-.) - (0.0.0.0) = C:\Windows\SystemApps\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\StartMenuExperienceHost.exe [17/09/2019 16:26:24] CPU Usage:0 % 8780 | [Owner : EVRARD | Parent : 4768(DSAService.exe) | 68.91 Mo] - (.Intel - Intel Driver & Support Assistant Tray.) - (19.11.46.6) = C:\Program Files (x86)\Intel\Driver and Support Assistant\DSATray.exe [14/11/2019 16:15:12] CPU Usage:0 % 8928 | [Owner : EVRARD | Parent : 1020(svchost.exe) | 27.16 Mo] - (.Microsoft Corporation - Runtime Broker.) - (10.0.18362.1) = C:\Windows\System32\RuntimeBroker.exe [19/03/2019 05:44:06] CPU Usage:0 % 8936 | [Owner : Système | Parent : 764(services.exe) | 52.56 Mo] - (.Intel - DSAUpdateService.) - (19.11.46.6) = C:\Program Files (x86)\Intel\Driver and Support Assistant\DSAUpdateService.exe [14/11/2019 16:15:06] CPU Usage:0 % 9212 | [Owner : EVRARD | Parent : 4968(MBAMService.exe) | 36.49 Mo] - (.Malwarebytes - Malwarebytes Tray Application.) - (4.0.0.456) = C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe [07/11/2019 22:24:10] CPU Usage:0 % 8100 | [Owner : EVRARD | Parent : 1020(svchost.exe) | 167.36 Mo] - (.Microsoft Corporation - Search and Cortana application.) - (10.0.18362.418) = C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe [09/10/2019 11:08:14] CPU Usage:0 % 9484 | [Owner : EVRARD | Parent : 1020(svchost.exe) | 28.41 Mo] - (.Microsoft Corporation - Runtime Broker.) - (10.0.18362.1) = C:\Windows\System32\RuntimeBroker.exe [19/03/2019 05:44:06] CPU Usage:0 % 9752 | [Owner : Système | Parent : 764(services.exe) | 21.3 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.18362.1) = C:\Windows\System32\svchost.exe [19/03/2019 05:44:33] CPU Usage:0 % 9836 | [Owner : EVRARD | Parent : 1020(svchost.exe) | 215.08 Mo] - (.Microsoft Corporation - SkypeApp.) - (8.55.0.131) = C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.55.131.0_x64__kzf8qxf38zg5c\SkypeApp.exe [12/12/2019 22:54:18] CPU Usage:0 % 9904 | [Owner : EVRARD | Parent : 1020(svchost.exe) | 37 Mo] - (.-.) - (1.19111.85.0) = C:\Program Files\WindowsApps\Microsoft.YourPhone_1.19111.85.0_x64__8wekyb3d8bbwe\YourPhone.exe [03/12/2019 20:27:35] CPU Usage:0 % 9952 | [Owner : EVRARD | Parent : 1020(svchost.exe) | 21.12 Mo] - (.Microsoft Corporation - Reminders WinRT OOP Server.) - (10.0.18362.418) = C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersServer.exe [09/10/2019 11:08:13] CPU Usage:0 % 1592 | [Owner : EVRARD | Parent : 1020(svchost.exe) | 3.26 Mo] - (.-.) - (8.55.0.131) = C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.55.131.0_x64__kzf8qxf38zg5c\SkypeBackgroundHost.exe [12/12/2019 22:54:18] CPU Usage:0 % 10444 | [Owner : EVRARD | Parent : 1020(svchost.exe) | 17.29 Mo] - (.Microsoft Corporation - Runtime Broker.) - (10.0.18362.1) = C:\Windows\System32\RuntimeBroker.exe [19/03/2019 05:44:06] CPU Usage:0 % 10828 | [Owner : SERVICE LOCAL | Parent : 764(services.exe) | ?????] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.18362.1) = C:\Windows\System32\svchost.exe [19/03/2019 05:44:33] CPU Usage:0 % 11488 | [Owner : Système | Parent : 764(services.exe) | 11.14 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.18362.1) = C:\Windows\System32\svchost.exe [19/03/2019 05:44:33] CPU Usage:0 % 11572 | [Owner : EVRARD | Parent : 828() | 7.21 Mo] - (.Node.js - NVIDIA Web Helper Service.) - (11.13.0.0) = C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe [26/05/2018 15:56:05] CPU Usage:0 % 11588 | [Owner : Système | Parent : 764(services.exe) | 9.39 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.18362.1) = C:\Windows\System32\svchost.exe [19/03/2019 05:44:33] CPU Usage:0 % 11784 | [Owner : EVRARD | Parent : 11572(NVIDIA Web Helper.exe) | 1.44 Mo] - (.Microsoft Corporation - Hôte de la fenêtre de la console.) - (10.0.18362.1) = C:\Windows\System32\conhost.exe [19/03/2019 05:44:30] CPU Usage:0 % 11820 | [Owner : Système | Parent : 3720() | 1.52 Mo] - (.Google LLC - Google Crash Handler.) - (1.3.35.421) = C:\Program Files (x86)\Google\Update\1.3.35.422\GoogleCrashHandler.exe [15/12/2019 08:41:07] CPU Usage:0 % 11852 | [Owner : Système | Parent : 3720() | 1.26 Mo] - (.Google LLC - Google Crash Handler.) - (1.3.35.421) = C:\Program Files (x86)\Google\Update\1.3.35.422\GoogleCrashHandler64.exe [15/12/2019 08:41:07] CPU Usage:0 % 11976 | [Owner : EVRARD | Parent : 6864(explorer.exe) | 14.07 Mo] - (.Realtek Semiconductor - Gestionnaire audio HD Realtek.) - (1.0.0.310) = C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [30/01/2014 17:35:43] CPU Usage:0 % 12084 | [Owner : EVRARD | Parent : 1020(svchost.exe) | 26.44 Mo] - (.Microsoft Corporation - Runtime Broker.) - (10.0.18362.1) = C:\Windows\System32\RuntimeBroker.exe [19/03/2019 05:44:06] CPU Usage:0 % 12212 | [Owner : EVRARD | Parent : 12200() | 72.7 Mo] - (.AVAST Software - Avast Antivirus.) - (19.8.4793.0) = C:\Program Files\AVAST Software\Avast\AvastUI.exe [20/09/2019 20:15:51] CPU Usage:0 % 10704 | [Owner : EVRARD | Parent : 1020(svchost.exe) | 17.87 Mo] - (.Microsoft Corporation - Runtime Broker.) - (10.0.18362.1) = C:\Windows\System32\RuntimeBroker.exe [19/03/2019 05:44:06] CPU Usage:0 % 7304 | [Owner : EVRARD | Parent : 10700() | 44.83 Mo] - (.- ProductUpdater.) - (1.0.20.0) = C:\Program Files (x86)\Common Files\Freemake Shared\ProductUpdater\ProductUpdater.exe [16/12/2019 17:45:19] CPU Usage:0 % 11424 | [Owner : SERVICE LOCAL | Parent : 764(services.exe) | 21.29 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.18362.1) = C:\Windows\System32\svchost.exe [19/03/2019 05:44:33] CPU Usage:0 % 9976 | [Owner : EVRARD | Parent : 764(services.exe) | 24.38 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.18362.1) = C:\Windows\System32\svchost.exe [19/03/2019 05:44:33] CPU Usage:0 % 12448 | [Owner : EVRARD | Parent : 12084(RuntimeBroker.exe) | 61.12 Mo] - (.Microsoft Corporation - SkypeBridge.) - (8.55.0.131) = C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.55.131.0_x64__kzf8qxf38zg5c\SkypeBridge\SkypeBridge.exe [12/12/2019 22:54:18] CPU Usage:0 % 12988 | [Owner : Système | Parent : 1020(svchost.exe) | 10.73 Mo] - (.Microsoft Corporation - COM Surrogate.) - (10.0.18362.1) = C:\Windows\System32\dllhost.exe [19/03/2019 05:44:33] CPU Usage:0 % 10212 | [Owner : Système | Parent : 764(services.exe) | 8.62 Mo] - (.MAGIX AG - Verzeichnisüberwachung und Hilfsaufgaben für die Medienbibliothek.) - (2.1.32.0) = C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe [23/01/2012 17:19:32] CPU Usage:0 % 13100 | [Owner : Système | Parent : 764(services.exe) | 6.56 Mo] - (.Intel Corporation - Intel(R) Dynamic Application Loader Host Interface.) - (9.5.12.1682) = C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [30/01/2014 17:38:17] CPU Usage:0 % 10180 | [Owner : Système | Parent : 764(services.exe) | 12.38 Mo] - (.Intel Corporation - Intel(R) Local Management Service.) - (9.5.10.1628) = C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [30/01/2014 17:37:42] CPU Usage:0 % 11396 | [Owner : Système | Parent : 764(services.exe) | ?????] - (.Microsoft Corporation - Service Broker du moniteur d'exécution System Guard.) - (10.0.18362.1) = C:\Windows\System32\SgrmBroker.exe [19/03/2019 05:45:32] CPU Usage:0 % 4744 | [Owner : Système | Parent : 764(services.exe) | 17.02 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.18362.1) = C:\Windows\System32\svchost.exe [19/03/2019 05:44:33] CPU Usage:0 % 12880 | [Owner : Système | Parent : 764(services.exe) | ?????] - (.Microsoft Corporation - Windows Security Health Service.) - (4.18.1901.16384) = C:\Windows\System32\SecurityHealthService.exe [17/09/2019 16:26:38] CPU Usage:0 % 1864 | [Owner : EVRARD | Parent : 6864(explorer.exe) | 35.4 Mo] - (.KC Softwares - SUMo.) - (5.10.4.439) = E:\Mes documents\Ma LOGITHEQUE portable Bollywood\sumo5.10.4.439\sumo\SUMo.exe [09/12/2019 20:39:35] CPU Usage:0 % 2672 | [Owner : Système | Parent : 764(services.exe) | 13.06 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.18362.1) = C:\Windows\System32\svchost.exe [19/03/2019 05:44:33] CPU Usage:0 % 12236 | [Owner : Système | Parent : 764(services.exe) | 10.64 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.18362.1) = C:\Windows\System32\svchost.exe [19/03/2019 05:44:33] CPU Usage:0 % 12808 | [Owner : EVRARD | Parent : 1020(svchost.exe) | 1.42 Mo] - (.-.) - (10.19101.1071.0) = C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19101.10711.0_x64__8wekyb3d8bbwe\Video.UI.exe [29/10/2019 10:31:25] CPU Usage:0 % 13064 | [Owner : SERVICE LOCAL | Parent : 764(services.exe) | 9.78 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.18362.1) = C:\Windows\System32\svchost.exe [19/03/2019 05:44:33] CPU Usage:0 % 13080 | [Owner : EVRARD | Parent : 1020(svchost.exe) | 10.63 Mo] - (.Microsoft Corporation - Runtime Broker.) - (10.0.18362.1) = C:\Windows\System32\RuntimeBroker.exe [19/03/2019 05:44:06] CPU Usage:0 % 6516 | [Owner : EVRARD | Parent : 1020(svchost.exe) | 11.05 Mo] - (.Microsoft Corporation - COM Surrogate.) - (10.0.18362.1) = C:\Windows\System32\dllhost.exe [19/03/2019 05:44:33] CPU Usage:0 % 8264 | [Owner : EVRARD | Parent : 1020(svchost.exe) | 50.52 Mo] - (.Microsoft Corporation - Windows Defender SmartScreen.) - (10.0.18362.1) = C:\Windows\System32\smartscreen.exe [19/03/2019 05:44:03] CPU Usage:0 % 6748 | [Owner : EVRARD | Parent : 6864(explorer.exe) | 126.77 Mo] - (.PersoApps Software - PersoApps Adresses.) - (1.3.1.1278) = C:\Program Files (x86)\EuroSoft Software Development\PersoApps Adresses\address.exe [03/09/2019 13:39:35] CPU Usage:2 % 9420 | [Owner : EVRARD | Parent : 1020(svchost.exe) | 31.44 Mo] - (.Microsoft Corporation - Application Frame Host.) - (10.0.18362.1) = C:\Windows\System32\ApplicationFrameHost.exe [19/03/2019 05:44:23] CPU Usage:0 % 5288 | [Owner : SERVICE LOCAL | Parent : 764(services.exe) | 11.32 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.18362.1) = C:\Windows\System32\svchost.exe [19/03/2019 05:44:33] CPU Usage:0 % 1036 | [Owner : EVRARD | Parent : 1020(svchost.exe) | 16.98 Mo] - (.Microsoft Corporation - Runtime Broker.) - (10.0.18362.1) = C:\Windows\System32\RuntimeBroker.exe [19/03/2019 05:44:06] CPU Usage:0 % 12184 | [Owner : EVRARD | Parent : 1020(svchost.exe) | 72.58 Mo] - (.Microsoft Corporation - Microsoft Edge.) - (11.0.18362.476) = C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe [16/11/2019 17:03:15] CPU Usage:0 % 1560 | [Owner : EVRARD | Parent : 1020(svchost.exe) | 8.47 Mo] - (.Microsoft Corporation - Browser_Broker.) - (11.0.18362.267) = C:\Windows\System32\browser_broker.exe [07/08/2019 16:20:50] CPU Usage:0 % 6060 | [Owner : EVRARD | Parent : 1036(RuntimeBroker.exe) | 13.54 Mo] - (.Microsoft Corporation - Microsoft Edge Web Platform.) - (11.0.18362.1) = C:\Windows\System32\MicrosoftEdgeSH.exe [19/03/2019 05:44:09] CPU Usage:0 % 7272 | [Owner : EVRARD | Parent : 1020(svchost.exe) | 26.36 Mo] - (.Microsoft Corporation - Microsoft Edge Content Process.) - (11.0.18362.1) = C:\Windows\System32\MicrosoftEdgeCP.exe [19/03/2019 05:44:47] CPU Usage:0 % 3860 | [Owner : EVRARD | Parent : 1020(svchost.exe) | 12.03 Mo] - (.Microsoft Corporation - COM Surrogate.) - (10.0.18362.1) = C:\Windows\System32\dllhost.exe [19/03/2019 05:44:33] CPU Usage:0 % 2520 | [Owner : EVRARD | Parent : 1020(svchost.exe) | 49.46 Mo] - (.Microsoft Corporation - WindowsInternal.ComposableShell.Experiences.TextInput.InputApp.exe.) - (10.0.18362.329) = C:\Windows\SystemApps\InputApp_cw5n1h2txyewy\WindowsInternal.ComposableShell.Experiences.TextInput.InputApp.exe [17/09/2019 16:26:30] CPU Usage:0 % 9288 | [Owner : EVRARD | Parent : 1020(svchost.exe) | 7.9 Mo] - (.-.) - (2019.19071.17920.0) = C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2019.19071.17920.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe [26/09/2019 13:46:14] CPU Usage:0 % 7124 | [Owner : EVRARD | Parent : 1020(svchost.exe) | 31.4 Mo] - (.Microsoft Corporation - Runtime Broker.) - (10.0.18362.1) = C:\Windows\System32\RuntimeBroker.exe [19/03/2019 05:44:06] CPU Usage:0 % 13160 | [Owner : EVRARD | Parent : 1152() | 247.54 Mo] - (.Mozilla Corporation - Thunderbird.) - (68.3.0.7288) = C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe [17/12/2019 14:30:10] CPU Usage:0 % 5744 | [Owner : Système | Parent : 764(services.exe) | 6.15 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.18362.1) = C:\Windows\System32\svchost.exe [19/03/2019 05:44:33] CPU Usage:0 % 2616 | [Owner : Système | Parent : 1020(svchost.exe) | 35.73 Mo] - (.Microsoft Corporation - WMI Provider Host.) - (10.0.18362.1) = C:\Windows\System32\wbem\WmiPrvSE.exe [19/03/2019 05:44:00] CPU Usage:0 % 11508 | [Owner : EVRARD | Parent : 12212(AvastUI.exe) | 36.03 Mo] - (.AVAST Software - Avast Antivirus.) - (19.8.4793.0) = C:\Program Files\AVAST Software\Avast\AvastUI.exe [20/09/2019 20:15:51] CPU Usage:0 % 2060 | [Owner : Système | Parent : 764(services.exe) | 16.52 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.18362.1) = C:\Windows\System32\svchost.exe [19/03/2019 05:44:33] CPU Usage:0 % 7020 | [Owner : Système | Parent : 764(services.exe) | 11.97 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.18362.1) = C:\Windows\System32\svchost.exe [19/03/2019 05:44:33] CPU Usage:0 % 11780 | [Owner : SERVICE LOCAL | Parent : 2208(svchost.exe) | 13.46 Mo] - (.Microsoft Corporation - Isolation graphique de périphérique audio Windows.) - (10.0.18362.449) = C:\Windows\System32\audiodg.exe [16/11/2019 16:59:52] CPU Usage:0 % 228 | [Owner : Système | Parent : 1020(svchost.exe) | 15.75 Mo] - (.Microsoft Corporation - USO Core Worker Process.) - (10.0.18362.535) = C:\Windows\System32\usocoreworker.exe [11/12/2019 13:39:31] CPU Usage:0 % 2280 | [Owner : Système | Parent : 764(services.exe) | 26.74 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.18362.1) = C:\Windows\System32\svchost.exe [19/03/2019 05:44:33] CPU Usage:0 % 728 | [Owner : Système | Parent : 764(services.exe) | 7.04 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.18362.1) = C:\Windows\System32\svchost.exe [19/03/2019 05:44:33] CPU Usage:0 % 3412 | [Owner : EVRARD | Parent : 6864(explorer.exe) | 177.89 Mo] - (.Google LLC - Google Chrome.) - (79.0.3945.79) = C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [11/12/2019 17:02:02] CPU Usage:0 % 10424 | [Owner : EVRARD | Parent : 3412(chrome.exe) | 6.92 Mo] - (.Google LLC - Google Chrome.) - (79.0.3945.79) = C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [11/12/2019 17:02:02] CPU Usage:0 % 2820 | [Owner : EVRARD | Parent : 3412(chrome.exe) | 9.27 Mo] - (.Google LLC - Google Chrome.) - (79.0.3945.79) = C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [11/12/2019 17:02:02] CPU Usage:0 % 3640 | [Owner : EVRARD | Parent : 3412(chrome.exe) | 121.64 Mo] - (.Google LLC - Google Chrome.) - (79.0.3945.79) = C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [11/12/2019 17:02:02] CPU Usage:2 % 2152 | [Owner : EVRARD | Parent : 3412(chrome.exe) | 36.78 Mo] - (.Google LLC - Google Chrome.) - (79.0.3945.79) = C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [11/12/2019 17:02:02] CPU Usage:0 % 12352 | [Owner : EVRARD | Parent : 3412(chrome.exe) | 114.92 Mo] - (.Google LLC - Google Chrome.) - (79.0.3945.79) = C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [11/12/2019 17:02:02] CPU Usage:0 % 552 | [Owner : EVRARD | Parent : 3412(chrome.exe) | 81.22 Mo] - (.Google LLC - Google Chrome.) - (79.0.3945.79) = C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [11/12/2019 17:02:02] CPU Usage:0 % 7224 | [Owner : EVRARD | Parent : 3412(chrome.exe) | 34.9 Mo] - (.Google LLC - Google Chrome.) - (79.0.3945.79) = C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [11/12/2019 17:02:02] CPU Usage:0 % 13756 | [Owner : EVRARD | Parent : 3412(chrome.exe) | 84.05 Mo] - (.Google LLC - Google Chrome.) - (79.0.3945.79) = C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [11/12/2019 17:02:02] CPU Usage:11 % 14136 | [Owner : EVRARD | Parent : 1020(svchost.exe) | 14.86 Mo] - (.Microsoft Corporation - Windows Security Health Host.) - (4.18.1901.16384) = C:\Windows\System32\SecurityHealthHost.exe [17/09/2019 16:26:38] CPU Usage:0 % 252 | [Owner : EVRARD | Parent : 1020(svchost.exe) | 52.86 Mo] - (.Microsoft Corporation - Windows Shell Experience Host.) - (10.0.18362.387) = C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe [09/10/2019 11:08:07] CPU Usage:0 % 12300 | [Owner : EVRARD | Parent : 1020(svchost.exe) | 15.46 Mo] - (.Microsoft Corporation - Runtime Broker.) - (10.0.18362.1) = C:\Windows\System32\RuntimeBroker.exe [19/03/2019 05:44:06] CPU Usage:0 % 11256 | [Owner : EVRARD | Parent : 3412(chrome.exe) | 54.18 Mo] - (.Google LLC - Google Chrome.) - (79.0.3945.79) = C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [11/12/2019 17:02:02] CPU Usage:0 % 11932 | [Owner : EVRARD | Parent : 3412(chrome.exe) | 34.22 Mo] - (.Google LLC - Google Chrome.) - (79.0.3945.79) = C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [11/12/2019 17:02:02] CPU Usage:0 % 11540 | [Owner : EVRARD | Parent : 6864(explorer.exe) | 71.33 Mo] - (.SosVirus - QuickDiag.) - (1.11.19.1) = E:\Desktop\QuickDiag.exe [17/12/2019 14:41:16] CPU Usage:0 % 6740 | [Owner : Système | Parent : 764(services.exe) | 20.21 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.18362.1) = C:\Windows\System32\svchost.exe [19/03/2019 05:44:33] CPU Usage:0 % 2324 | [Owner : EVRARD | Parent : 3412(chrome.exe) | 55.08 Mo] - (.Google LLC - Google Chrome.) - (79.0.3945.79) = C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [11/12/2019 17:02:02] CPU Usage:0 % 7600 | [Owner : EVRARD | Parent : 3412(chrome.exe) | 34.52 Mo] - (.Google LLC - Google Chrome.) - (79.0.3945.79) = C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [11/12/2019 17:02:02] CPU Usage:0 % 992 | [Owner : EVRARD | Parent : 3412(chrome.exe) | 35.24 Mo] - (.Google LLC - Google Chrome.) - (79.0.3945.79) = C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [11/12/2019 17:02:02] CPU Usage:0 % 13844 | [Owner : EVRARD | Parent : 3412(chrome.exe) | 31.8 Mo] - (.Google LLC - Google Chrome.) - (79.0.3945.79) = C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [11/12/2019 17:02:02] CPU Usage:0 % 10852 | [Owner : SERVICE RÉSEAU | Parent : 1020(svchost.exe) | 13.98 Mo] - (.Microsoft Corporation - WMI Provider Host.) - (10.0.18362.1) = C:\Windows\SysWOW64\wbem\WmiPrvSE.exe [19/03/2019 05:45:12] CPU Usage:0 % ---------- | Locked Applications [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{f9e93b39-49d1-4179-9848-a5a2896955ea}] - () - (%systemroot%\system32\mrt.exe) ---------- | Policy Restrictions ---------- | Explorer.exe Modules (Microsoft Files Whitelisted) (..-..) - (0.0.0.0) -- C:\WINDOWS\System32\UMPDC.dll (..-..) - (0.0.0.0) -- C:\Windows\System32\VirtualMonitorManager.dll (.NVIDIA Corporation.-.NVIDIA Driver Loader, Version 441.66.) - (26.21.14.4166) -- C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_77e6900053c33f6f\nvldumdx.dll (.NVIDIA Corporation.-.NVIDIA D3D10 Driver, Version 441.66.) - (26.21.14.4166) -- C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_77e6900053c33f6f\nvwgf2umx_cfg.dll (.AVAST Software.-.Avast Antivirus Shell Extension.) - (19.8.4793.0) -- C:\Program Files\AVAST Software\Avast\ashShell.dll (..-..) - (0.0.0.0) -- C:\Windows\ShellExperiences\TileControl.dll (..-..) - (0.0.0.0) -- C:\Windows\ShellComponents\TaskFlowUI.dll (.AVAST Software.-.Avast Antivirus AAVM Remote Procedure Call Library.) - (19.8.4793.0) -- C:\Program Files\AVAST Software\Avast\AavmRpch.dll (..-..) - (0.0.0.0) -- C:\Program Files\Unlocker\UnlockerCOM.dll (.Malwarebytes.-.Malwarebytes.) - (3.0.0.79) -- C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll (.Alexander Roshal.-.WinRAR shell extension.) - (5.80.0.0) -- C:\Program Files\WinRAR\rarext.dll (.TODO: .-.TODO: .) - (1.0.0.1) -- C:\Program Files (x86)\Icecream PDF Split and Merge\x64\IcecreamShell64.dll (.Glarysoft Ltd.-.Context Menu Handler.) - (5.0.0.17) -- C:\Program Files (x86)\Glary Utilities 5\x64\ContextHandler.dll (.Foxit Software Inc..-.ConvertToPDFShellExtension.) - (9.7.0.2220) -- C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\ConvertToPDFShellExtension_x64.dll (.Piriform Ltd.-.DefragglerShell.) - (2.22.33.995) -- C:\Program Files\Defraggler\DefragglerShell64.dll (.Igor Pavlov.-.7-Zip Shell Extension.) - (19.0.0.0) -- C:\Program Files\7-Zip\7-zip.dll ---------- | Winlogon.exe Modules (Microsoft Files Whitelisted) (..-..) - (0.0.0.0) -- C:\WINDOWS\System32\UMPDC.dll ---------- | svchost.exe Modules (Microsoft Files Whitelisted) (..-..) - (0.0.0.0) -- C:\WINDOWS\System32\UMPDC.dll (.AVAST Software.-.Avast Antivirus AMSI COM object.) - (19.8.4793.0) -- C:\Program Files\AVAST Software\Avast\aswAMSI.dll (.AVAST Software.-.Avast Antivirus AAVM Remote Procedure Call Library.) - (19.8.4793.0) -- C:\Program Files\AVAST Software\Avast\AavmRpch.dll (.AVAST Software.-.Avast Antivirus dll loader.) - (19.8.4793.0) -- C:\Program Files\AVAST Software\Avast\dll_loader.dll (.SQLite Development Team.-.SQLite is a software library that implements a self-contained, serverless, zero-configuration, transactional SQL database engine..) - (3.25.3.0) -- c:\windows\system32\winsqlite3.dll (..-..) - (1.8.3.0) -- C:\WINDOWS\system32\SaMinDrv.dll (..-.Device Monitor.) - (1.6.2.0) -- C:\WINDOWS\system32\ssdevm64.dll (.AVAST Software.-.Hook Library.) - (19.8.4793.0) -- C:\Program Files\AVAST Software\Avast\aswhook.dll (..-..) - (0.0.0.0) -- C:\Windows\System32\usocoreps.dll (..-..) - (0.0.0.0) -- C:\WINDOWS\SYSTEM32\WINBIOPLUGINS\FACEBOOTSTRAPADAPTER.DLL ---------- | ZeroAccess Check [HKLM\Software\Classes\CLSID\{1108BE51-F58A-4CDA-BB99-7A0227D11D5E}\InProcServer32] : %systemroot%\system32\wbem\fastprox.dll [HKLM\Software\Classes\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] : %SystemRoot%\system32\windows.storage.dll [HKLM\Software\Classes\CLSID\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] : %systemroot%\system32\wbem\fastprox.dll [HKLM\Software\Classes\CLSID\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] : %systemroot%\system32\wbem\wbemess.dll [HKLM\Software\Classes\CLSID\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] : %SystemRoot%\system32\shell32.dll [HKLM\Software\WOW6432Node\Classes\CLSID\{1108BE51-F58A-4CDA-BB99-7A0227D11D5E}\InProcServer32] : %systemroot%\system32\wbem\fastprox.dll [HKLM\Software\WOW6432Node\Classes\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] : %SystemRoot%\system32\windows.storage.dll [HKLM\Software\WOW6432Node\Classes\CLSID\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] : %systemroot%\system32\wbem\fastprox.dll [HKLM\Software\WOW6432Node\Classes\CLSID\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] : %SystemRoot%\system32\shell32.dll ---------- | Startings up OneDriveSetup - (C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup [HKU\S-1-5-19\SOFTWARE\...\Run]) - User: AUTORITE NT\SERVICE LOCAL OneDriveSetup - (C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup [HKU\S-1-5-20\SOFTWARE\...\Run]) - User: AUTORITE NT\SERVICE RÉSEAU BingSvc - (C:\Users\EVRARD\AppData\Local\Microsoft\BingSvc\BingSvc.exe [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\...\Run]) - User: ELITE344\EVRARD Iperius Backup - (C:\Program Files (x86)\Iperius Backup\Iperius.exe [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\...\Run]) - User: ELITE344\EVRARD CCleaner Smart Cleaning - ("C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\...\Run]) - User: ELITE344\EVRARD Vivaldi Update Notifier - ("C:\Users\EVRARD\AppData\Local\Vivaldi\Application\update_notifier.exe" [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\...\Run]) - User: ELITE344\EVRARD GUDelayStartup - ("C:\Program Files (x86)\Glary Utilities 5\StartupManager.exe" -delayrun [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\...\Run]) - User: ELITE344\EVRARD SecurityHealth - (%windir%\system32\SecurityHealthSystray.exe [HKLM\SOFTWARE\...\Run]) - User: Public RTHDVCPL - ("C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s [HKLM\SOFTWARE\...\Run]) - User: Public AvastUI.exe - ("C:\Program Files\AVAST Software\Avast\AvLaunch.exe" /gui [HKLM\SOFTWARE\...\Run]) - User: Public AdobeGCInvoker-1.0 - ("C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe" [HKLM\SOFTWARE\...\Run]) - User: Public CDAServer - (C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe [HKLM\SOFTWARE\...\Run]) - User: Public [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Microsoft\Command Processor] "CompletionChar"=9 "DefaultColor"=0 "EnableExtensions"=1 "PathCompletionChar"=9 [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Microsoft\Windows\CurrentVersion\Run] "BingSvc"=C:\Users\EVRARD\AppData\Local\Microsoft\BingSvc\BingSvc.exe [27/08/2015 10:21:10] "Iperius Backup"=C:\Program Files (x86)\Iperius Backup\Iperius.exe [15/12/2019 18:41:22] "CCleaner Smart Cleaning"="C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR "Vivaldi Update Notifier"="C:\Users\EVRARD\AppData\Local\Vivaldi\Application\update_notifier.exe" "GUDelayStartup"="C:\Program Files (x86)\Glary Utilities 5\StartupManager.exe" -delayrun [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Microsoft\Windows\CurrentVersion\RunOnce] "Application Restart #1"=C:\Program Files (x86)\Google\Chrome\Application\chrome.exe --flag-switches-begin --flag-switches-end --restore-last-session -- http://s2trkmce2.venteprivee.com/r/?id=h915d4ee,1355d1c0,1355d1d0&p1=www.veepee.fr/ExternalLinks/AutoLoginSecure.ashx?i=oFPtEbO5I4irjLhninXFIRzl3dZhAR/XeqhnaFG7U4PbT5lV42gkXL2P+cV2PAt0VlLETcFid3FAVAPcP1WzRoPaUzxEqb1r67Q07fC/trNDbP5RT8pvrw==&SiteId=1&utm_source=service&utm_medium=email&utm_campaign=expeditionautrecolis&utm_content=sale[AIGLE59]_visual01&member_id=35148513&partnerid=31657 [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run] "LMab1err"=0x03000000BE30B482A7A0D101 "LMADHmon"=0x030000004E3F7E0FF254D101 "CCleaner Monitoring"=0x020000000000000000000000 "NETGEARGenie"=0x03000000B7FA3F6F48AED001 "VDownloader"=0x020000000000000000000000 "GUDelayStartup"=0x030000006FF5A16A48AED001 "uTorrent"=0x03000000205A0CC387E8D001 "BingSvc"=0x030000009041957B9339D101 "Vivaldi Update Notifier"=0x03000000107E9531FC3DD301 "FlashPlayerUpdate"=0x03000000D08434D55260D301 "SUPERAntiSpyware"=0x03000000B09CE283BE8BD301 "vidnotifier.exe"=0x03000000000C33FE065ED401 "Iperius Backup"=0x03000000900B862AE3E1D301 "Startup Sentinel"=0x020000000000000000000000 "CCleaner Smart Cleaning"=0x0300000027C59FB48A82D401 "EEDSpeedLauncher"=0x020000000000000000000000 "AvastBrowserAutoLaunch_7FB317CC0EA8E3006346B5036E0B2495"=0x03000000C0A50E874098D401 "Google Update"=0x020000000000000000000000 [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "Device"=Samsung M2070 Series (USB002),winspool,Ne00: "IsMRUEstablished"=1 "LegacyDefaultPrinterMode"=0 [HKLM\Software\Microsoft\Command Processor] "DefaultColor"=0 "EnableExtensions"=1 "CompletionChar"=64 "PathCompletionChar"=64 [HKLM\Software\Microsoft\Windows\CurrentVersion\Run] "SecurityHealth"=%windir%\system32\SecurityHealthSystray.exe "RTHDVCPL"="C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s "AvastUI.exe"="C:\Program Files\AVAST Software\Avast\AvLaunch.exe" /gui "AdobeGCInvoker-1.0"="C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe" "CDAServer"=C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe [08/09/2014 12:39:36] [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run] "SecurityHealth"=0x0700000053FB84CA8A82D401 "IAStorIcon"=0x03000000CC4B25BD8A82D401 "RTHDVCPL"=0x020000000000000000000000 "NvBackend"=0x020000000000000000000000 "CamserviceHDSunset"=0x030000003D07AF1C3483CF01 "VDownloader"=0x03000000CC07AD7C3870D001 "LMADHmon"=0x030000009038A711F254D101 "ShadowPlay"=0x020000000000000000000000 "WindowsDefender"=0x020000000000000000000000 "Eraser"=0x020000000000000000000000 "AdobeGCInvoker-1.0"=0x03000000BDF5DBAE8A82D401 "CDAServer"=0x03000000A24E9BB98A82D401 "AvastUI.exe"=0x020000000000000000000000 [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32] "Adobe ARM"=0x03000000C34895CDF474CF01 "AvastUI.exe"=0x020000000000000000000000 "KeePass 2 PreLoad"=0x0300000010E4BADA4622CF01 "Family Tree Builder Update"=0x030000006F5354A5F627CF01 "SunJavaUpdateSched"=0x03000000E4BBE2FBF154D101 "SDTray"=0x030000003C16C3C8F474CF01 "APSDaemon"=0x03000000D364B5163483CF01 "QuickTime Task"=0x0300000065BE5D0C3483CF01 "VDownloader"=0x0300000070468FA7D268D001 "LMADHmon"=0x03000000C8170C0DF254D101 "MalTray"=0x03000000700C3436FC3DD301 "DSATray"=0x03000000A089B41D075ED401 "AdobeGCInvoker-1.0"=0x030000009065E10B075ED401 "Intel Driver & Support Assistant"=0x03000000B0818AA3A3A2D501 "ProductUpdater"=0x020000000000000000000000 [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] ""=mnmsrvc "AppInit_DLLs"= "DdeSendTimeout"=0 "DesktopHeapLogging"=1 "DeviceNotSelectedTimeout"=15 "DwmInputUsesIoCompletionPort"=1 "EnableDwmInputProcessing"=7 "GDIProcessHandleQuota"=10000 "IconServiceLib"=IconCodecService.dll "LoadAppInit_DLLs"=0 "NaturalInputHandler"=Ninput.dll "ShutdownWarningDialogTimeout"=4294967295 "Spooler"=yes "ThreadUnresponsiveLogTimeout"=500 "TransmissionRetryTimeout"=90 "USERNestedWindowLimit"=50 "USERPostMessageLimit"=10000 "USERProcessHandleQuota"=10000 "Win32kLastWriteTime"=1D5B02008C8C37D [HKLM\Software\WOW6432Node\Microsoft\Command Processor] "CompletionChar"=9 "DefaultColor"=0 "EnableExtensions"=1 "PathCompletionChar"=9 [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] "Family Tree Builder Update"=C:\Program Files (x86)\MyHeritage\Bin\FTBCheckUpdates.exe [03/12/2019 13:45:58] "KeePass 2 PreLoad"="C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe" --preload "Intel Driver & Support Assistant"=C:\Program Files (x86)\Intel\Driver and Support Assistant\DSATray.exe [14/11/2019 16:15:12] "ProductUpdater"=C:\Program Files (x86)\Common Files\Freemake Shared\ProductUpdater\ProductUpdater.exe [16/12/2019 17:45:19] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Windows] ""=mnmsrvc "AppInit_DLLs"= "DdeSendTimeout"=0 "DesktopHeapLogging"=1 "DeviceNotSelectedTimeout"=15 "DwmInputUsesIoCompletionPort"=1 "EnableDwmInputProcessing"=7 "GDIProcessHandleQuota"=10000 "IconServiceLib"=IconCodecService.dll "LoadAppInit_DLLs"=0 "NaturalInputHandler"=Ninput.dll "ShutdownWarningDialogTimeout"=4294967295 "Spooler"=yes "ThreadUnresponsiveLogTimeout"=500 "TransmissionRetryTimeout"=90 "USERNestedWindowLimit"=50 "USERPostMessageLimit"=10000 "USERProcessHandleQuota"=10000 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] "WebCheck"={E6FB5E20-DE35-11CF-9C87-00AA005127ED} ---------- | Win.ini : ---------- | System.ini : ---------- | Tasks List Adobe Acrobat Update Task Adobe Flash Player NPAPI Notifier Adobe Flash Player PPAPI Notifier Adobe Flash Player Updater AdobeGCInvoker-1.0-MicrosoftAccount-miclau.evrard@sfr.fr Avast Emergency Update CCleaner Update CCleanerSkipUAC CreateChoiceProcessTask EPM Preload GoogleUpdateTaskMachineCore GoogleUpdateTaskMachineUA GoogleUpdateTaskUserS-1-5-21-548730727-4139670515-3000484307-1001Core GoogleUpdateTaskUserS-1-5-21-548730727-4139670515-3000484307-1001UA IntelSURQC-Upgrade-86621605-2a0b-4128-8ffc-15514c247132 IntelSURQC-Upgrade-86621605-2a0b-4128-8ffc-15514c247132-Logon IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} OneDrive Standalone Update Task-S-1-5-21-548730727-4139670515-3000484307-1001 Optimize Start Menu Cache Files-S-1-5-21-548730727-4139670515-3000484307-1001 RunAsStdUser_MyComGames UpdateDetector {0353A36E-2228-4EA6-9EE1-3FB9C487BB33} {1DFD0248-92C4-4C94-8007-AB87138DABAF} {31FFAB5B-29AE-4308-8E14-1BFD84347BC1} {5EDF5B38-0831-4D63-AECF-94FBACA04B2F} {8CB99EC3-4940-420E-A1D3-2A2092A6EB89} {CC4E43D2-EEFA-4757-8C8D-1B73B880D344} ---------- | Startings up registry ¦ Folder ---------- | Control - lsa - SecurityProviders - Session Manager - Terminal Server [HKLM\System\CurrentControlSet\Control] "BootDriverFlags"=28 "CurrentUser"=USERNAME "EarlyStartServices"=RpcSs Power BrokerInfrastructure SystemEventsBroker DcomLaunch RpcEpMapper LSM AppIdSvc "PreshutdownOrder"=DeviceInstall UsoSvc gpsvc trustedinstaller "SvcHostSplitThresholdInKB"=3670016 "WaitToKillServiceTimeout"=2000 "SystemStartOptions"= NOEXECUTE=OPTIN "SystemBootDevice"=multi(0)disk(0)rdisk(0)partition(2) "FirmwareBootDevice"=multi(0)disk(0)rdisk(0)partition(1) "LastBootSucceeded"=1 "LastBootShutdown"=1 "DirtyShutdownCount"=3 [HKLM\System\CurrentControlSet\Control\lsa] "auditbasedirectories"=0 "auditbaseobjects"=0 "Bounds"=0x0030000000200000 "crashonauditfail"=0 "fullprivilegeauditing"=0x00 "NoLmHash"=1 "Security Packages"="" [30/01/2014 17:24:48] "Notification Packages"=scecli "Authentication Packages"=msv1_0 "disabledomaincreds"=0 "everyoneincludesanonymous"=0 "forceguest"=0 "LimitBlankPasswordUse"=0 "LsaPid"=776 "ProductType"=3 "restrictanonymous"=0 "restrictanonymoussam"=1 "SamConnectedAccountsExist"=1 "SecureBoot"=1 [HKLM\System\CurrentControlSet\Control\SecurityProviders] "SecurityProviders"=credssp.dll [HKLM\System\CurrentControlSet\Control\Session Manager] "AutoChkTimeout"=8 "BootExecute"=autocheck autochk * "BootShell"=%SystemRoot%\system32\bootim.exe "CriticalSectionTimeout"=2592000 "ExcludeFromKnownDlls"= "GlobalFlag"=0 "GlobalFlag2"=0 "HeapDeCommitFreeBlockThreshold"=0 "HeapDeCommitTotalFreeThreshold"=0 "HeapSegmentCommit"=0 "HeapSegmentReserve"=0 "InitConsoleFlags"=0 "NumberOfInitialSessions"=2 "ObjectDirectories"=\Windows \RPC Control "ProcessorControl"=2 "ProtectionMode"=1 "RunLevelExecute"=WinInit ServiceControlManager "RunLevelValidate"=ServiceControlManager "SETUPEXECUTE"= "AutoChkSkipSystemPartition"=0 "ResourceTimeoutCount"=648000 "PendingFileRenameOperations"=\??\C:\Program Files (x86)\Mozilla Thunderbird\tobedeleted\repc2a05a9e-7629-47d5-b294-200e804017af \??\C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice_tmp.exe [HKLM\System\CurrentControlSet\Control\Terminal Server] "AllowRemoteRPC"=0 "DelayConMgrTimeout"=0 "DeleteTempDirsOnExit"=1 "fDenyTSConnections"=1 "fSingleSessionPerUser"=1 "NotificationTimeOut"=0 "PerSessionTempDir"=0 "ProductVersion"=5.1 "RCDependentServices"=CertPropSvc SessionEnv "SnapshotMonitors"=1 "StartRCM"=0 "TSUserEnabled"=0 "InstanceID"=a1862af4-3a35-49b1-9455-0c79020 "GlassSessionId"=1 ---------- | .LNK with Arguments ---------- | AppCertDlls ---------- | Dnsapi.dll C:\WINDOWS\System32\dnsapi.dll -> OK : \drivers\etc\hosts C:\WINDOWS\SysWOW64\dnsapi.dll -> OK : \drivers\etc\hosts ---------- | Policies | Registry [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Control Panel\Desktop] "ActiveWndTrackTimeout"=0 "BlockSendInputResets"=0 "CaretTimeout"=5000 "ClickLockTime"=1200 "CoolSwitchColumns"=7 "CoolSwitchRows"=3 "CursorBlinkRate"=530 "DockMoving"=1 "DragFromMaximize"=1 "DragFullWindows"=1 "DragHeight"=4 "DragWidth"=4 "FocusBorderHeight"=1 "FocusBorderWidth"=1 "FontSmoothing"=2 "FontSmoothingGamma"=0 "FontSmoothingOrientation"=1 "FontSmoothingType"=2 "ForegroundFlashCount"=7 "ForegroundLockTimeout"=6945664 "LeftOverlapChars"=3 "MenuShowDelay"=400 "MouseWheelRouting"=2 "PaintDesktopVersion"=0 "Pattern"=0 "RightOverlapChars"=3 "ScreenSaveActive"=1 "SnapSizing"=1 "TileWallpaper"=0 "WallpaperOriginX"=0 "WallpaperOriginY"=0 "WheelScrollChars"=3 "WheelScrollLines"=3 "WindowArrangementActive"=1 "CaretWidth"=3 "WallPaper"=C:\Users\EVRARD\AppData\Local\Microsoft\Windows\Themes\RoamedThemeFiles\DesktopBackground\2015-10-20_portaventura (5).jpg [15/12/2019 09:08:24] "WallpaperStyle"=6 "MouseMonitorEscapeSpeed"=0 "Win8DpiScaling"=0 "UserPreferencesMask"=0x9E1E078012000000 "AutoColorization"=0 "MaxVirtualDesktopDimension"=1920 "MaxMonitorDimension"=1920 "TranscodedImageCount"=1 "LastUpdated"=4294967295 "TranscodedImageCache"=0x7AC30100649A06008B0A0000ED050000C4C61DD31EB3D50143003A005C00550073006500720073005C004500560052004100520044005C0041007000700044006100740061005C004C006F00630061006C005C004D006900630072006F0073006F00660074005C00570069006E0064006F00770073005C005400680065006D00650073005C0052006F0061006D00650064005400680065006D006500460069006C00650073005C004400650073006B0074006F0070004200610063006B00670072006F0075006E0064005C0032003000310035002D00310030002D00320030005F0070006F00720074006100760065006E00740075007200610020002800350029002E006A0070006700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 "ImageColor"=2952184650 "Pattern Upgrade"=TRUE "PreferredUILanguages"=fr-FR "DpiScalingVer"=4096 "EnablePerProcessSystemDPI"=1 "ActiveWndTrkTimeout"=0 "WaitToKillAppTimeout"=2000 "HungAppTimeout"=2000 [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoDriveAutorun"=0 [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel] "{59031a47-3f72-44a7-89c5-5595fe6b30ee}"=0 "{20D04FE0-3AEA-1069-A2D8-08002B30309D}"=0 "{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}"=0 "{018D5C66-4533-4307-9B53-224DE2ED1FE6}"=1 [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu] "{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}"=0 [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Microsoft\Windows\CurrentVersion\Explorer] "EdgeDesktopShortcutCreated"=1 "ShellState"=0x2400000033A8000000000000000000000000000001000000130000000000000062000000 "ExplorerStartupTraceRecorded"=1 "UserSignedIn"=1 "SlowContextMenuEntries"=0x40C7A47B819ECF1199D300AA004AE837152E00005D54A9A2C2A0B4429708A0B2BADD77C892140000BD0E0C47735D584D9CEDE91E22E232829F0A000093C98043430C024E9A7A0D40B6EA75900B13000062B06A59D2B415429F74E9109B0A8153844D0000 "SIDUpdatedOnLibraries"=1 "LocalKnownFoldersMigrated"=1 "TelemetrySalt"=6 "GlobalAssocChangedCounter"=907 "FirstRunTelemetryComplete"=1 "AppReadinessLogonComplete"=1 "PostAppInstallTasksCompleted"=1 "link"=0x1E000000 "Browse For Folder Width"=418 "Browse For Folder Height"=396 "ShowRecent"=1 [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced] "Start_SearchFiles"=2 "ServerAdminUI"=0 "Hidden"=1 "ShowCompColor"=1 "HideFileExt"=0 "DontPrettyPath"=0 "ShowInfoTip"=1 "MapNetDrvBtn"=0 "WebView"=1 "Filter"=0 "ShowSuperHidden"=1 "SeparateProcess"=0 "AutoCheckSelect"=0 "IconsOnly"=0 "ShowTypeOverlay"=1 "ShowStatusBar"=1 "ListviewAlphaSelect"=1 "ListviewShadow"=1 "TaskbarAnimations"=1 "StartMenuInit"=13 "ReindexedProfile"=1 "TaskbarSizeMove"=0 "DisablePreviewDesktop"=1 "TaskbarSmallIcons"=1 "TaskbarGlomLevel"=0 "DontUsePowerShellOnWinX"=1 "Start_JumpListItems"=10 "StoreAppsOnTaskbar"=1 "RTStartMenuNotificationDisplayCount"=0 "EnableStartMenu"=1 "TaskbarStateLastRun"=0x8A36F25D00000000 "ShellViewReentered"=1 "Start_TrackProgs"=0 "ShowCortanaButton"=1 "HideIcons"=0 [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\WordWheelQuery] "MRUListEx"=0x3200000031000000300000000A000000130000002F000000100000002E000000000000002D0000002C0000002B0000002A000000290000002800000027000000250000002600000023000000240000002200000021000000200000001F0000001E0000001D0000001C0000001B0000001A00000019000000180000001700000016000000150000001400000012000000110000000F0000000E0000000D0000000C0000000B000000090000000800000007000000060000000500000004000000030000000200000001000000FFFFFFFF "1"=0x670061006E000000 "2"=0x52004100560041000000 "3"=0x73006F006E000000 "4"=0x65007800740065006C000000 "5"=0x61006A0073000000 "6"=0x730061006D00730075006E0067000000 "7"=0x6D0061006E00630068006F006E000000 "8"=0x63006F006D007000740065007500720073000000 "9"=0x32003000310039002D00300037000000 "11"=0x6200650072006C0069006E0067006F000000 "12"=0x64006500760069007300200032003000310039000000 "13"=0x6400E90074006500630074006500750072000000 "14"=0x320030003100390030003800330031000000 "15"=0x6D00610074006D00750074000000 "17"=0x67006100620061000000 "18"=0x6500610075000000 "20"=0x61006C006C00690061006E007A000000 "21"=0x310033002F00310030002F0032003000310039000000 "22"=0x66006100750074006500750069006C000000 "23"=0x7000E90072006F000000 "24"=0x720069006D000000 "25"=0x6C0069007300740065000000 "26"=0x7000650069006E0074007500720065000000 "27"=0x7000650069006E007400750072006500200032003000310036000000 "28"=0x6C007500780065006E0073000000 "29"=0x6C00650072006F0079000000 "30"=0x6D006F00720074000000 "31"=0x70006500720073006F000000 "32"=0x760069007400720065000000 "33"=0x630061006E0061007000E9000000 "34"=0x61006E0063006F0072007000720069006D000000 "36"=0x730061006300200061007300700069007200610074006500750072000000 "35"=0x73006100630020006100730069007200610074006500750072000000 "38"=0x61007300700069007200610074006500750072000000 "37"=0x7300610063000000 "39"=0x6C006100660075006D0061000000 "40"=0x63006C00650020007500730062000000 "41"=0x6B006F00730069006C0075006D000000 "42"=0x63006C0061007500640065000000 "43"=0x700069006500640073000000 "44"=0x32003000310036002D00300037002D00300031000000 "45"=0x30003600320033003400370034003600320030000000 "0"=0x610074006D0062000000 "46"=0x61006E0065006F000000 "16"=0x640065007600690073000000 "47"=0x740061007200690066000000 "19"=0x660075006D00E90065000000 "10"=0x6500640066000000 "48"=0x70006C00610066006F006E006E006900650072000000 "49"=0x7600650065007000650065000000 "50"=0x61006600720065006D006F0076000000 [HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers] "authenticodeenabled"=0 "DefaultLevel"=262144 "TransparentEnabled"=1 "PolicyScope"=0 "ExecutableTypes"=ADE ADP BAS BAT CHM CMD COM CPL CRT EXE HLP HTA INF INS ISP LNK MDB MDE MSC MSI MSP MST OCX PCD PIF REG SCR SHS URL VB WSC [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System] "ConsentPromptBehaviorAdmin"=5 "ConsentPromptBehaviorUser"=3 "DSCAutomationHostEnabled"=2 "EnableCursorSuppression"=1 "EnableFullTrustStartupTasks"=2 "EnableInstallerDetection"=1 "EnableLUA"=1 "EnableSecureUIAPaths"=1 "EnableUIADesktopToggle"=0 "EnableUwpStartupTasks"=2 "EnableVirtualization"=1 "PromptOnSecureDesktop"=1 "SupportFullTrustStartupTasks"=1 "SupportUwpStartupTasks"=1 "ValidateAdminCodeSignatures"=0 "undockwithoutlogon"=1 "dontdisplaylastusername"=0 "legalnoticecaption"= "legalnoticetext"= "scforceoption"=0 "shutdownwithoutlogon"=1 "SoftwareSASGeneration"=1 "EnableLinkedConnections"=1 [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "ForceActiveDesktopOn"=0 "NoActiveDesktop"=1 "NoRecentDocsHistory"=0 [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel] "{031E4825-7B94-4dc3-B131-E946B44C8DD5}"=1 "{208D2C60-3AEA-1069-A2D7-08002B30309D}"=1 "{20D04FE0-3AEA-1069-A2D8-08002B30309D}"=1 "{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}"=1 "{59031a47-3f72-44a7-89c5-5595fe6b30ee}"=1 "{871C5380-42A0-1069-A2EA-08002B30309D}"=1 "{9343812e-1c37-4a49-a12e-4b2d810d956b}"=1 "{B4FB3F98-C1EA-428d-A78A-D1F5659CBA93}"=1 "{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}"=1 [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu] "{871C5380-42A0-1069-A2EA-08002B30309D}.default"=0 "{9343812e-1c37-4a49-a12e-4b2d810d956b}"=1 [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] "CheckedValue"=1 "DefaultValue"=2 "HKeyRoot"=2147483649 "Id"=2 "RegPath"=Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced "Text"=@shell32.dll,-30500 "Type"=radio "ValueName"=Hidden [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer] "ActiveSetupDisabled"=0 "ActiveSetupTaskOverride"=1 "AsyncRunOnce"=1 "AsyncUpdatePCSettings"=1 "DisableAppInstallsOnFirstLogon"=1 "DisableResolveStoreCategories"=1 "DisableUpgradeCleanup"=1 "EarlyAppResolverStart"=1 "FileOpenDialog"={DC1C5A9C-E88A-4dde-A5A1-60F82A20AEF7} "FSIASleepTimeInMs"=60000 "GlobalFolderSettings"={EF8AD2D1-AE36-11D1-B2D2-006097DF8C11} "IconUnderline"=2 "ListViewPopupControl"={8be9f5ea-e746-4e47-ad57-3fb191ca1eed} "LVPopupSearchControl"={fccf70c8-f4d7-4d8b-8c17-cd6715e37fff} "MachineOobeUpdates"=1 "NoWaitOnRoamingPayloads"=1 "TaskScheduler"={0f87369f-a4e5-4cfc-bd3e-73e6154572dd} "AicEnabled"=PreferStore "SmartScreenEnabled"=RequireAdmin "GlobalAssocChangedCounter"=12 [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced] "Start_TrackDocs"=1 "TaskbarSizeMove"=0 [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] "Application"=http://go.microsoft.com/fwlink/?LinkId=57426&Ext=%s [HKLM\Software\WOW6432Node\Policies\Microsoft\Windows\Safer\CodeIdentifiers] "authenticodeenabled"=0 "DefaultLevel"=262144 "TransparentEnabled"=1 "PolicyScope"=0 "ExecutableTypes"=ADE ADP BAS BAT CHM CMD COM CPL CRT EXE HLP HTA INF INS ISP LNK MDB MDE MSC MSI MSP MST OCX PCD PIF REG SCR SHS URL VB WSC [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\System] "ConsentPromptBehaviorAdmin"=5 "ConsentPromptBehaviorUser"=3 "DSCAutomationHostEnabled"=2 "EnableCursorSuppression"=1 "EnableFullTrustStartupTasks"=2 "EnableInstallerDetection"=1 "EnableLUA"=1 "EnableSecureUIAPaths"=1 "EnableUIADesktopToggle"=0 "EnableUwpStartupTasks"=2 "EnableVirtualization"=1 "PromptOnSecureDesktop"=1 "SupportFullTrustStartupTasks"=1 "SupportUwpStartupTasks"=1 "ValidateAdminCodeSignatures"=0 "undockwithoutlogon"=1 "dontdisplaylastusername"=0 "legalnoticecaption"= "legalnoticetext"= "scforceoption"=0 "shutdownwithoutlogon"=1 "SoftwareSASGeneration"=1 "EnableLinkedConnections"=1 [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer] "ForceActiveDesktopOn"=0 "NoActiveDesktop"=1 "NoRecentDocsHistory"=0 [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel] "{031E4825-7B94-4dc3-B131-E946B44C8DD5}"=1 "{208D2C60-3AEA-1069-A2D7-08002B30309D}"=1 "{20D04FE0-3AEA-1069-A2D8-08002B30309D}"=1 "{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}"=1 "{59031a47-3f72-44a7-89c5-5595fe6b30ee}"=1 "{871C5380-42A0-1069-A2EA-08002B30309D}"=1 "{9343812e-1c37-4a49-a12e-4b2d810d956b}"=1 "{B4FB3F98-C1EA-428d-A78A-D1F5659CBA93}"=1 "{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}"=1 [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu] "{871C5380-42A0-1069-A2EA-08002B30309D}.default"=0 "{9343812e-1c37-4a49-a12e-4b2d810d956b}"=1 [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] "CheckedValue"=1 "DefaultValue"=2 "HKeyRoot"=2147483649 "Id"=2 "RegPath"=Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced "Text"=@shell32.dll,-30500 "Type"=radio "ValueName"=Hidden [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer] "ActiveSetupDisabled"=0 "ActiveSetupTaskOverride"=1 "AsyncRunOnce"=1 "AsyncUpdatePCSettings"=1 "DisableAppInstallsOnFirstLogon"=1 "DisableResolveStoreCategories"=1 "DisableUpgradeCleanup"=1 "EarlyAppResolverStart"=1 "FileOpenDialog"={DC1C5A9C-E88A-4dde-A5A1-60F82A20AEF7} "FSIASleepTimeInMs"=60000 "GlobalFolderSettings"={EF8AD2D1-AE36-11D1-B2D2-006097DF8C11} "IconUnderline"=2 "ListViewPopupControl"={8be9f5ea-e746-4e47-ad57-3fb191ca1eed} "LVPopupSearchControl"={fccf70c8-f4d7-4d8b-8c17-cd6715e37fff} "MachineOobeUpdates"=1 "NoWaitOnRoamingPayloads"=1 "TaskScheduler"={0f87369f-a4e5-4cfc-bd3e-73e6154572dd} "GlobalAssocChangedCounter"=63 [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Advanced] "Start_TrackDocs"=1 "TaskbarSizeMove"=0 [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Associations] "Application"=http://go.microsoft.com/fwlink/?LinkId=57426&Ext=%s ---------- | Winlogon [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] "ExcludeProfileDirs"=AppData\Local;AppData\LocalLow;$Recycle.Bin;OneDrive;Work Folders "PUUActive"=0xCC727E61020002008C00250279B80E00B3181300B3181300D20000000200710018FB5E68668A56003D7C2600DE2409001A9D080033940000000000000000000012DA1900828200002F070000000000006C2D7C8FD9B4D5017AB80E002D321C006345000000D10E00BA470000C20100001E429D0000000000 "BuildNumber"=18363 "FirstLogon"=0 "ParseAutoexec"=1 "DP"=0xD200E800E70002008D000000CC727E61000000000000000066939D8CDFB4D50166939D8CDFB4D501000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000F03F80510100AB0700002909A8186909A838CC6A004002400255524C8655A4E50000C7900418C790143AD14C01006A8108016A891801627E00000026441811264418C1070080219C0810219C0814373E008040008801400EBA0102CA0080F410C201F410E21121A90080000302002283C208A96C00804809480548194A25728300804403090144630909 [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] "AutoRestartShell"=1 "Background"=0 0 0 "CachedLogonsCount"=10 "DebugServerCommand"=no "DisableBackButton"=1 "EnableSIHostIntegration"=1 "ForceUnlockLogon"=0 "LegalNoticeCaption"= "LegalNoticeText"= "PasswordExpiryWarning"=5 "PowerdownAfterShutdown"=0 "PreCreateKnownFolders"={A520A1A4-1780-4FF6-BD18-167343C5AF16} "ReportBootOk"=1 "Shell"=explorer.exe "ShellCritical"=0 "ShellInfrastructure"=sihost.exe "SiHostCritical"=0 "SiHostReadyTimeOut"=0 "SiHostRestartCountLimit"=0 "SiHostRestartTimeGap"=0 "VMApplet"=SystemPropertiesPerformance.exe /pagefile "WinStationsDisabled"=0 "scremoveoption"=0 "LastLogOffEndTimePerfCounter"=403122582841 "ShutdownFlags"=2147484331 "Userinit"=C:\Windows\system32\userinit.exe, "AutoAdminLogon"=1 "DefaultDomainName"=ELITE344 "DefaultUserName"=EVRARD "ShutdownWithoutLogon"=0 "DisableCad"=1 "EnableFirstLogonAnimation"=1 "AutoLogonSID"=S-1-5-21-548730727-4139670515-3000484307-1001 "LastUsedUsername"=EVRARD [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon] "DefaultDomainName"= "DefaultUserName"= "PreCreateKnownFolders"={A520A1A4-1780-4FF6-BD18-167343C5AF16} "Shell"=explorer.exe "ShellCritical"=0 "SiHostCritical"=0 "SiHostReadyTimeOut"=0 "SiHostRestartCountLimit"=0 "SiHostRestartTimeGap"=0 "Userinit"=C:\WINDOWS\system32\userinit.exe [19/03/2019 05:44:35] ---------- | Associations [HKLM\Software\Classes\.exe] ""=exefile "Content Type"=application/x-msdownload [HKLM\Software\Classes\exefile\Shell\Open\Command] ""="%1" %* "IsolatedCommand"="%1" %* [HKLM\Software\Classes\.com] ""=comfile [HKLM\Software\Classes\comfile\Shell\Open\Command] ""="%1" %* [HKLM\Software\Classes\.reg] ""=regfile [HKLM\Software\Classes\regfile\Shell\Open\Command] ""=regedit.exe "%1" [HKLM\Software\Classes\.scr] ""=scrfile [HKLM\Software\Classes\scrfile\Shell\Open\Command] ""="%1" /S [HKLM\Software\Classes\.bat] ""=batfile [HKLM\Software\Classes\batfile\Shell\Open\Command] ""="%1" %* [HKLM\Software\Classes\.cmd] ""=cmdfile [HKLM\Software\Classes\cmdfile\Shell\Open\Command] ""="%1" %* [HKLM\Software\Classes\.pif] ""=piffile [HKLM\Software\Classes\piffile\Shell\Open\Command] ""="%1" %* [HKLM\Software\Classes\.inf] ""=inffile [HKLM\Software\Classes\inffile\Shell\Open\Command] ""=%SystemRoot%\system32\NOTEPAD.EXE %1 [HKLM\Software\Classes\.url] ""=InternetShortcut [HKLM\Software\Classes\.lnk] ""=lnkfile [HKLM\Software\Classes\.hta] ""=htafile "Content Type"=application/hta "PerceivedType"=text [HKLM\Software\Classes\htafile\Shell\Open\Command] ""=C:\Windows\SysWOW64\mshta.exe "%1" {1E460BD7-F1C3-4B2E-88BF-4E770A288AF5}%U{1E460BD7-F1C3-4B2E-88BF-4E770A288AF5} %* [HKLM\Software\Classes\InternetShortcut] "EditFlags"=2 "FriendlyTypeName"=@C:\WINDOWS\system32\ieframe.dll,-10046 "FullDetails"=prop:System.Link.TargetUrl;System.Rating;System.Link.Description;System.Link.Comment "InfoTip"=prop:System.Link.TargetUrl;System.Rating;System.Link.Description;System.Link.Comment "IsShortcut"= "NeverShowExt"= "PreviewDetails"=prop:System.Link.TargetUrl;System.Rating;System.History.VisitCount;System.History.DateChanged;System.Link.DateVisited;System.Link.Description;System.Link.Comment ""=Raccourci Internet [HKLM\Software\Classes\Application.Manifest] ""=Application Manifest "BrowserFlags"=4096 "EditFlags"=4259840 "FriendlyTypeName"=@C:\Windows\System32\dfshim.dll,-200 [HKLM\Software\Classes\Application.Reference] ""=Application Reference "EditFlags"=131072 "FriendlyTypeName"=@C:\Windows\System32\dfshim.dll,-201 "IsShortcut"= "NeverShowExt"= [HKLM\Software\Classes\Folder] ""=Folder "AppUserModelID"=Microsoft.Windows.Explorer "ContentViewModeForBrowse"=prop:~System.ItemNameDisplay;~System.LayoutPattern.PlaceHolder;~System.LayoutPattern.PlaceHolder;~System.LayoutPattern.PlaceHolder;System.DateModified "ContentViewModeForSearch"=prop:~System.ItemNameDisplay;System.DateModified;~System.ItemFolderPathDisplay "ContentViewModeLayoutPatternForBrowse"=delta "ContentViewModeLayoutPatternForSearch"=alpha "EditFlags"=0xD2030000 "FullDetails"=prop:System.PropGroup.Description;System.ItemNameDisplay;System.ItemTypeText;System.Size;System.HomeGroupSharingStatus "NoRecentDocs"= "ThumbnailCutoff"=0 "TileInfo"=prop:System.Title;System.HomeGroupSharingStatus [HKLM\Software\WOW6432Node\Classes\.exe] ""=exefile "Content Type"=application/x-msdownload [HKLM\Software\WOW6432Node\Classes\exefile\Shell\Open\Command] ""="%1" %* "IsolatedCommand"="%1" %* [HKLM\Software\WOW6432Node\Classes\.com] ""=comfile [HKLM\Software\WOW6432Node\Classes\comfile\Shell\Open\Command] ""="%1" %* [HKLM\Software\WOW6432Node\Classes\.reg] ""=regfile [HKLM\Software\WOW6432Node\Classes\regfile\Shell\Open\Command] ""=regedit.exe "%1" [HKLM\Software\WOW6432Node\Classes\.scr] ""=scrfile [HKLM\Software\WOW6432Node\Classes\scrfile\Shell\Open\Command] ""="%1" /S [HKLM\Software\WOW6432Node\Classes\.bat] ""=batfile [HKLM\Software\WOW6432Node\Classes\batfile\Shell\Open\Command] ""="%1" %* [HKLM\Software\WOW6432Node\Classes\.cmd] ""=cmdfile [HKLM\Software\WOW6432Node\Classes\cmdfile\Shell\Open\Command] ""="%1" %* [HKLM\Software\WOW6432Node\Classes\.pif] ""=piffile [HKLM\Software\WOW6432Node\Classes\piffile\Shell\Open\Command] ""="%1" %* [HKLM\Software\WOW6432Node\Classes\.inf] ""=inffile [HKLM\Software\WOW6432Node\Classes\inffile\Shell\Open\Command] ""=%SystemRoot%\system32\NOTEPAD.EXE %1 [HKLM\Software\WOW6432Node\Classes\.url] ""=InternetShortcut [HKLM\Software\WOW6432Node\Classes\.lnk] ""=lnkfile [HKLM\Software\WOW6432Node\Classes\.hta] ""=htafile "Content Type"=application/hta "PerceivedType"=text [HKLM\Software\WOW6432Node\Classes\htafile\Shell\Open\Command] ""=C:\Windows\SysWOW64\mshta.exe "%1" {1E460BD7-F1C3-4B2E-88BF-4E770A288AF5}%U{1E460BD7-F1C3-4B2E-88BF-4E770A288AF5} %* [HKLM\Software\WOW6432Node\Classes\InternetShortcut] "EditFlags"=2 "FriendlyTypeName"=@C:\WINDOWS\system32\ieframe.dll,-10046 "FullDetails"=prop:System.Link.TargetUrl;System.Rating;System.Link.Description;System.Link.Comment "InfoTip"=prop:System.Link.TargetUrl;System.Rating;System.Link.Description;System.Link.Comment "IsShortcut"= "NeverShowExt"= "PreviewDetails"=prop:System.Link.TargetUrl;System.Rating;System.History.VisitCount;System.History.DateChanged;System.Link.DateVisited;System.Link.Description;System.Link.Comment ""=Raccourci Internet [HKLM\Software\WOW6432Node\Classes\Application.Manifest] ""=Application Manifest "BrowserFlags"=4096 "EditFlags"=4259840 "FriendlyTypeName"=@C:\Windows\System32\dfshim.dll,-200 [HKLM\Software\WOW6432Node\Classes\Application.Reference] ""=Application Reference "EditFlags"=131072 "FriendlyTypeName"=@C:\Windows\System32\dfshim.dll,-201 "IsShortcut"= "NeverShowExt"= [HKLM\Software\WOW6432Node\Classes\Folder] ""=Folder "AppUserModelID"=Microsoft.Windows.Explorer "ContentViewModeForBrowse"=prop:~System.ItemNameDisplay;~System.LayoutPattern.PlaceHolder;~System.LayoutPattern.PlaceHolder;~System.LayoutPattern.PlaceHolder;System.DateModified "ContentViewModeForSearch"=prop:~System.ItemNameDisplay;System.DateModified;~System.ItemFolderPathDisplay "ContentViewModeLayoutPatternForBrowse"=delta "ContentViewModeLayoutPatternForSearch"=alpha "EditFlags"=0xD2030000 "FullDetails"=prop:System.PropGroup.Description;System.ItemNameDisplay;System.ItemTypeText;System.Size;System.HomeGroupSharingStatus "NoRecentDocs"= "ThumbnailCutoff"=0 "TileInfo"=prop:System.Title;System.HomeGroupSharingStatus [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Clients\StartMenuInternet\FIREFOX.EXE\Shell\open\Command] ""="C:\Program Files\Mozilla Firefox\firefox.exe" [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Clients\StartMenuInternet\FIREFOX.EXE\InstallInfo] "ReinstallCommand"="C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /SetAsDefaultAppGlobal [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Clients\StartMenuInternet\Vivaldi.4KZN25ELORNAYYGL4WILRQB2IQ\Shell\open\Command] ""="C:\Users\EVRARD\AppData\Local\Vivaldi\Application\vivaldi.exe" [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Clients\StartMenuInternet\Vivaldi.4KZN25ELORNAYYGL4WILRQB2IQ\InstallInfo] "ReinstallCommand"="C:\Users\EVRARD\AppData\Local\Vivaldi\Application\vivaldi.exe" --make-default-browser [HKLM\Software\Clients\StartMenuInternet\FIREFOX.EXE\Shell\open\Command] ""="C:\Program Files\Mozilla Firefox\firefox.exe" [HKLM\Software\Clients\StartMenuInternet\FIREFOX.EXE\InstallInfo] "ReinstallCommand"="C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /SetAsDefaultAppGlobal [HKLM\Software\Clients\StartMenuInternet\Google Chrome\Shell\open\Command] ""="C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" [HKLM\Software\Clients\StartMenuInternet\Google Chrome\InstallInfo] "ReinstallCommand"="C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --make-default-browser [HKLM\Software\Clients\StartMenuInternet\IEXPLORE.EXE\Shell\open\Command] ""=C:\Program Files\Internet Explorer\iexplore.exe [19/03/2019 13:01:28] [HKLM\Software\Clients\StartMenuInternet\IEXPLORE.EXE\InstallInfo] "ReinstallCommand"="C:\Windows\System32\ie4uinit.exe" -reinstall [HKLM\Software\WOW6432Node\Clients\StartMenuInternet\FIREFOX.EXE\Shell\open\Command] ""="C:\Program Files\Mozilla Firefox\firefox.exe" [HKLM\Software\WOW6432Node\Clients\StartMenuInternet\FIREFOX.EXE\InstallInfo] "ReinstallCommand"="C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /SetAsDefaultAppGlobal [HKLM\Software\WOW6432Node\Clients\StartMenuInternet\Google Chrome\Shell\open\Command] ""="C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" [HKLM\Software\WOW6432Node\Clients\StartMenuInternet\Google Chrome\InstallInfo] "ReinstallCommand"="C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --make-default-browser [HKLM\Software\WOW6432Node\Clients\StartMenuInternet\IEXPLORE.EXE\Shell\open\Command] ""=C:\Program Files\Internet Explorer\iexplore.exe [19/03/2019 13:01:28] [HKLM\Software\WOW6432Node\Clients\StartMenuInternet\IEXPLORE.EXE\InstallInfo] "ReinstallCommand"="C:\Windows\System32\ie4uinit.exe" -reinstall ---------- | AppcompatFlags [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Persisted] "C:\Program Files (x86)\InstallShield Installation Information\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}\setup.exe"=33 "C:\Program Files (x86)\Realtek\NICDRV_8169\RTINSTALLER64.EXE"=1 "C:\Users\EVRARD\AppData\Roaming\Foxit Software\Addon\Foxit Reader\FoxitReaderUpdater.exe"=1 [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store] "SIGN.MEDIA=6F8100 Bin\ASSETUP.exe"=0x534143500100000000000000070000002800000058BF19003D351A0001000000000000000000030600010000975FD891C99ECE010000000000000000 "SIGN.MEDIA=7977F06 Drivers\Audio\7040\Driver\dotnetfx40\Stop.bat"=0x534143500100000000000000070000002800000000C604008ED2040001000000000000000000010500100000975FD891C99ECE010000000000000000 "C:\Arrêter\Arrêter.exe"=0x5341435001000000000000000700000028000000483A290097AD2900010000000000000000000206F5220000631F6E6F0EDED40100000000000000000200000028000000000000000000000000000000000000000000000000000000B1BF7004000000001502000015020000 "SIGN.MEDIA=93BD93B6 Mes logiciels\KeePass-2.24-Setup(installé20131108).exe"=0x5341435001000000000000000700000028000000EE7626000000000001000000000000000000030600210000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000F49F0100000000000100000001000000 "SIGN.MEDIA=93BD93B6 Mes logiciels\mbam-setup-1.75.0.1300(installé20131103).exe"=0x5341435001000000000000000700000028000000F0EF9C0071349D0001000000000000000000020600210000975FD891C99ECE010000000000000000020000002800000000000000000000000000000000000000000000000000000029220100000000000100000001000000 "SIGN.MEDIA=93BD93B6 Mes logiciels\SkypeSetup_6.13.0.104(installé20140124).exe"=0x5341435001000000000000000700000028000000A0521900CC091A0001000000000000000000020600010000975FD891C99ECE010000000000000000020000002800000000000000000000400000000000000000000000000000000014300100000000000100000001000000 "SIGN.MEDIA=9DB85 MS Office 2007\SETUP.EXE"=0x534143500100000000000000070000002800000030110700C7F8070001000000000000000000000671220000975FD891C99ECE010000000000000000020000002800000000000000000000400000000000000000000000000000000055600900000000000100000001000000 "SIGN.MEDIA=93BD93B6 Mes logiciels\Finance 2003_setup.exe"=0x53414350010000000000000007000000280000009EAB12000000000001000000000000000000010541200000975FD891C99ECE0100000000000000000200000028000000000000000008004000000000000000000000000000000000967E0000000000000100000001000000 "C:\Program Files (x86)\SoftChris\Finance 2003\Finance2003.exe"=0x5341435001000000000000000700000028000000006220000000000001000000000000000000010561200000631F6E6F0EDED4010000000000000000020000002800000000000000000000000000000000000000000000000000000019153C0500000000B1060000B1060000 "SIGN.MEDIA=93BD93B6 Mes logiciels\speccysetup1.25.674(installé20140130).exe"=0x534143500100000000000000070000002800000048EF4900CEAF4A0001000000000000000000010600010000975FD891C99ECE0100000000000000000200000028000000000000000000004000000000000000000000000000000000FE9A0200000000000100000001000000 "SIGN.MEDIA=93BD93B6 Mes logiciels\ccsetup4.10.4570(installé20140124).exe"=0x5341435001000000000000000700000028000000000D480084C7480001000000000000000000010600010000975FD891C99ECE0100000000000000000200000028000000000000000000004000000000000000000000000000000000CAE20100000000000100000001000000 "SIGN.MEDIA=93BD93B6 Mes logiciels\cobianbackupSetup_V11.2.0.582.exe"=0x534143500100000000000000070000002800000000BE2C010000000001000000000000000000010600010000975FD891C99ECE010000000000000000020000002800000000000000000000000000000000000000000000000000000015794900000000000200000002000000 "SIGN.MEDIA=93BD93B6 Mes logiciels\photofiltre-version-gratuite-avec-installer_7-1-2_fr_10731.exe"=0x5341435001000000000000000700000028000000285C4F000000000001000000000000000000000671000000975FD891C99ECE010000000000000000020000002800000000000000000800400000000000000000000000000000000020550100000000000100000001000000 "SIGN.MEDIA=27A1EF Setup.exe"=0x534143500100000000000000070000002800000040F40400E7B6050001000000000000000000010600210000975FD891C99ECE0100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000004000000000000000000000000000000000DEA30400000000000200000002000000 "SIGN.MEDIA=99BC14 Ctrun\Start.exe"=0x534143500100000000000000070000002800000000E000000000000001000000000000000000010571200000975FD891C99ECE010000000000000000 "SIGN.MEDIA=14A955E7 Driverinstaller for creative webcam setup.exe"=0x534143500100000000000000070000002800000048F82A00CD7F2B0001000000000000000000010600010000975FD891C99ECE010000000000000000 "SIGN.MEDIA=10048 start.exe"=0x5341435001000000000000000700000028000000D8000100CE00020001000000000000000000000671220000975FD891C99ECE0100000000000000000200000028000000000000000000000000000200000000000000000000000000D6290F00000000000200000002000000 "SIGN.MEDIA=17C07910 pc_check___tuning_2010_5.0.30.804_fr.exe"=0x53414350010000000000000007000000280000005880B4018197B40101000000000000000000000671020000975FD891C99ECE0100000080000000000200000028000000000000000000004000000000000000000000000000000000E13A0100000000000100000001000000 "SIGN.MEDIA=17C07910 pc_check___tuning_2010_5.0.107.1006_fr.exe"=0x5341435001000000000000000700000028000000206AC601929CC60101000000000000000000000671020000975FD891C99ECE0100000080000000000200000028000000000000000000004000000000000000000000000000000000683C0100000000000100000001000000 "SIGN.MEDIA=17C07910 pc_check___tuning_2010_5.0.108.1016_fr.exe"=0x5341435001000000000000000700000028000000C8DBC401698CC50101000000000000000000000671020000975FD891C99ECE01000000800000000002000000280000000000000000000040000000000000000000000000000000001EE80000000000000100000001000000 "SIGN.MEDIA=17C07910 pc_check___tuning_2010_5.0.109.1026_fr.exe"=0x53414350010000000000000007000000280000002864C8010B12C90101000000000000000000000671020000975FD891C99ECE0100000080000000000200000028000000000000000000004000000000000000000000000000000000D8FD0000000000000100000001000000 "SIGN.MEDIA=17C07910 pc_check___tuning_2010_5.0.410.1028_fr.exe"=0x53414350010000000000000007000000280000004095C801CE82C90101000000000000000000000671020000975FD891C99ECE01000000800000000002000000280000000000000000000040000000000000000000000000000000005CF50000000000000100000001000000 "SIGN.IE=012EAC0 wlsetup-web.exe"=0x5341435001000000000000000700000028000000C0EA1200F0F3120001000000000000000000030671220000975FD891C99ECE0100000000000000000200000028000000000000000000005000000000000000000000000000000000135F0100000000000100000001000000 "SIGN.MEDIA=17B32A AutoRun.exe"=0x534143500100000000000000070000002800000000D002000000000001000000000000000000010671200000975FD891C99ECE010000000000000000 "C:\Program Files (x86)\AVerMedia\AVerTV 3D\AVerTV.exe"=0x5341435001000000000000000700000028000000001857000000000001000000000000000000010671020000631F6E6F0EDED401000000000000000002000000280000000000000000000000100000000000000000000000000000000CE1FC0A00000000BA020000BA020000 "C:\Program Files (x86)\Ahead\Nero StartSmart\NeroStartSmart.exe"=0x534143500100000000000000070000002800000057404A000000000001000000000000000000010571000000975FD891C99ECE01000000000000000002000000280000000000000000000000002400000000000000000000000000000DD30700000000000200000002000000 "C:\Program Files (x86)\Common Files\Ahead\Lib\specialoffer.exe"=0x5341435001000000000000000700000028000000008008000000000001000000000000000000010571000000975FD891C99ECE01000000000000000002000000280000000000000000000000002000000000000000000000000000000C180000000000000600000006000000 "C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\MSOXMLED.EXE"=0x534143500100000000000000070000002800000010E70000EEE0010001000000000000000000000671020000DB80FDAC2839D30100000000000000000200000028000000000000000000000000000000000000000000000000000000FA7D0000000000002D0000002D000000 "SIGN.MEDIA=6AA90 start.exe"=0x534143500100000000000000070000002800000000AA0600E743070001000000000000000000030671220000975FD891C99ECE0100000000000000000200000050000000000000000000000000000000000000000000000000000000558B320000000000060000000600000000000000800000000000000000000000000000000000000075AA2500000000000100000000000000 "C:\MotionStudios\Vasco da Gama 7 HDPro\setup_fra.exe"=0x5341435001000000000000000700000028000000009005000000000001000000000000000000000671020000975FD891C99ECE010000000000000000020000002800000000000000000000400000000000000000000000000000000013160100000000000100000001000000 "C:\MotionStudios\Vasco da Gama 7 HDPro\Vasco da Gama 7 HDPro_Fra.msi"=0x534143500100000000000000070000002800000000F400008396010001000000000000000000010500100000B395E7CF049FCE0100000000000000000200000028000000000000000000000000000000000000000000000000000000304E0000000000000100000001000000 "C:\Program Files (x86)\MotionStudios\Vasco da Gama 7 HDPro\Vasco da Gama 7 HDPro.exe"=0x534143500100000000000000070000002800000000766900AFC969000100000000000000000002067122000033504C2B57DFD1010000000000000000020000002800000000000000000000000000000000000000000000000000000043A31100000000000900000009000000 "SIGN.MEDIA=92BE3C DirectoryListPrintFR_V2.25(installé20140328)\DirectoryListPrintPro.exe"=0x53414350010000000000000007000000280000003CBE92000000000001000000000000000000030671200000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000D5280000000000000100000001000000 "C:\Program Files (x86)\Microsoft Office\Office12\OIS.EXE"=0x5341435001000000000000000700000028000000802D0400F959040001000000000000000000010671220000631F6E6F0EDED401000000000000000002000000500000000000000000000000000000000000000000000000000000008BA5090000000000DA020000DA0200000000000000000010000000000000000000000000000000005E0D0000000000000100000000000000 "SIGN.MEDIA=D0D914A6 Mes Logiciels\Windows 8.1\clearcompressionflag.exe"=0x5341435001000000000000000700000028000000B09400001285010001000000000000000000030600210000B395E7CF049FCE0100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000004000000000000000000000000000000000CB000000000000000200000002000000 "SIGN.MEDIA=1A635841 Setup.exe"=0x5341435001000000000000000700000028000000288509008AFE090001000000000000000000010671220000975FD891C99ECE010000000000000000 "C:\Program Files (x86)\Hercules\Webcam Station Evolution\StationEv.exe"=0x534143500100000000000000070000002800000050536C0051186D0001000000000000000000020673220000BFA2139DEDD1D3010000000000000000020000002800000000000000000000000000000000000000000000000000000024461D00000000001100000011000000 "C:\Program Files (x86)\Hercules\Hercules HD Sunset\Hercules HD Sunset\XtrCtrlEx.exe"=0x534143500100000000000000070000002800000070C5330047FA330001000000000000000000010673220000B395E7CF049FCE0100000000000000000200000028000000000000000000000000000000000000000000000000000000CB000000000000000200000002000000 "SIGN.MEDIA=5228B MEGEVE-Mémé\FINANCE 2003_SETUP.EXE"=0x53414350010000000000000007000000280000009EAB12000000000001000000000000000000000641200000975FD891C99ECE0100000000000000000500000010000000000000000000000000000000000800000200000028000000000000000008004000002000000000000000200000000000E1330000000000000100000001000000010000000400000001000000 "C:\Program Files\Unlocker\Unlocker.exe"=0x534143500100000000000000070000002800000000E801000000000001000000000000000000020673220000631F6E6F0EDED40100000000000000000200000028000000000000000000004000000000000000000000000000000000ED574D00000000003900000039000000 "SIGN.MEDIA=1BE1FC4 FreemakeVideoConverter_4.1.4.0(installé20140509).exe"=0x53414350010000000000000007000000280000006864C3011BE3C30101000000000000000000030600210000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000EB0D0000000000000100000001000000 "SIGN.IE=0496F80 ccsetup415.exe"=0x5341435001000000000000000700000028000000806F4900D37A490001000000000000000000010600010000975FD891C99ECE010000000000000000020000002800000000000000000000400000000000000000000000000000000038C70000000000000100000001000000 "SIGN.IE=02C5ECA8 spybot-2.4.exe"=0x5341435001000000000000000700000028000000A8ECC5025E02C60201000000000000000000030600210000975FD891C99ECE010000000000000000050000001000000000000000000000000000000000000000020000002800000000000000000000400000000000000000000000000000000029C21000000000000100000001000000 "C:\Program Files\Windows Mail\WindowsMailGadget.exe"=0x534143500100000000000000070000002800000000C00200394C030001000000000000000000000673000000B395E7CF049FCE010000000000000000020000002800000000000000000000000000000000000000000000000000000020000000000000000100000001000000 "SIGN.MEDIA=3F4F70 DirectoryListPrintSetupFR_V2.35(installé20141107).exe"=0x5341435001000000000000000700000028000000704F3F00AE43400001000000000000000000030600210000975FD891C99ECE01000000000000000005000000100000000000000000000000000000000000000002000000280000000000000000000000000000000000000000000000000000003D5E0000000000000100000001000000 "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"=0x5341435001000000000000000700000028000000C8940F00D5FA0F0001000000000000000000030671220000975FD891C99ECE01000000000000000002000000280000000000000000000000000000000000000000000000000000005A84AE02000000000700000007000000 "C:\Users\EVRARD\AppData\Local\Microsoft\SkyDrive\Update\OneDriveSetup.exe"=0x5341435001000000000000000700000028000000B0046E0045BB6E0001000000000000000000030600210000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000FC530000000000000100000001000000 "C:\Program Files (x86)\MAGIX\Video deluxe 2014 Premium\MusicEditor\MusicEditor.exe"=0x53414350010000000000000007000000280000000009AF00FA1AAF0001000000000000000000020671200000DB80FDAC2839D30100000000000000000200000028000000000000000000000000000000000000000000000000000000081B0700000000001F0000001F000000 "C:\Program Files (x86)\ImgBurn\ImgBurn.exe"=0x534143500100000000000000070000002800000000EC2900000000000100000000000000000002067122000033504C2B57DFD101000000000000000002000000280000000000000000000000000000080000000000000000000000002CDB1400000000000A0000000A000000 "C:\Program Files\WinPcap\rpcapd.exe"=0x534143500100000000000000070000002800000010CA0100C910020001000000000000000000000671000000975FD891C99ECE01000000000000000002000000280000000000000000000000000000000000000000000000000000007A590000000000000200000002000000 "SIGN.MEDIA=DDED0740 Mes Logiciels20150404_TOUR\Minecraft.exe"=0x534143500100000000000000070000002800000094500A004D2D060001000000000000000000020671000000975FD891C99ECE0100000000000000000200000028000000000000000000000000100000000000000000000000000000EAA65D00000000000100000001000000 "C:\Program Files (x86)\Common Files\AVerMedia\AVerQuick\AVerQuick.exe"=0x534143500100000000000000070000002800000000500A000000000001000000000000000000010671200000975FD891C99ECE01000000000000000002000000280000000000000000000000001000000000000000000000000000008817BF09000000000100000001000000 "C:\Program Files (x86)\PhotoFiltre 7\PhotoFiltre7.exe"=0x5341435001000000000000000700000028000000001435000000000001000000000000000000030661200000631F6E6F0EDED40100000000000000000200000028000000000000000000000000000000000000000000000000000000722EED0000000000B6040000B6040000 "C:\Program Files (x86)\Icecream Media Converter\bin\converter.exe"=0x534143500100000000000000070000002800000000C40D00D4550E000100000000000000000003066120000067077CBAC54CD40100000000000000000200000028000000000000000000000000000000000000000000000000000000E5AF4900000000000A0000000A000000 "SIGN.MEDIA=7AC8EE SanDiskSecureAccessV2_win.exe"=0x5341435001000000000000000700000028000000F89B7600985C770001000000000000000000030671200000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000A8540000000000000100000001000000 "C:\Program Files (x86)\proDAD\Vitascene-1.0\vitascene.exe"=0x534143500100000000000000070000002800000040FA0000C102010001000000000000000000000671200000975FD891C99ECE01000000000000000002000000280000000000000000000000000000000000000000000000000000005E410000000000000200000002000000 "C:\Program Files (x86)\proDAD\Vitascene-1.0\vt_kickstart.exe"=0x534143500100000000000000070000002800000040FA0000C102010001000000000000000000000671200000975FD891C99ECE010000000000000000020000002800000000000000000000000000000000000000000000000000000030120000000000000200000002000000 "C:\Program Files (x86)\AntiTwin\AntiTwin.exe"=0x53414350010000000000000007000000280000008B7E0D000000000001000000000000000000010671020000DB80FDAC2839D30100000000000000000200000028000000000000000000000000000000000000000000000000000000B2CE0500000000000A0000000A000000 "SIGN.IE=01E7860 uTorrent.exe"=0x534143500100000000000000070000002800000060781E00E2D51E0001000000000000000000030671220000975FD891C99ECE010000000000000000020000002800000000000000000000100000000000000000000000000000000040F90100000000000100000001000000 "SIGN.MEDIA=48B84AA Lenovo_Suite.exe"=0x534143500100000000000000070000002800000088920B009FB70B000100000000000000000003067122000033504C2B57DFD1010000000000000000050000001000000000000000000000000000000000000000020000002800000000000000000000400000000000000000000000000000000029010000000000000A0000000A000000 "C:\Users\EVRARD\AppData\Roaming\Foxit Software\Addon\Foxit Reader\FoxitReaderUpdater.exe"=0x5341435001000000000000000700000028000000C0264C00CD214D0001000000000000000000030671220000975FD891C99ECE010000008000000000020000002800000000000000000000000000000000000000000000000000000001050000000000000100000001000000 "C:\Users\EVRARD\AppData\Local\Microsoft\BingSvc\BSvcProcessor.exe"=0x534143500100000000000000070000002800000098101100C837110001000000000000000000030600210000975FD891C99ECE01000000000000000002000000280000000000000000000000000000000000000000000000000000002D030000000000002000000020000000 "C:\Program Files (x86)\PowerpointImageExtractor_V1_2\PowerpointImageExtractor.exe"=0x5341435001000000000000000700000028000000008C1900000000000100000000000000000002067120000067077CBAC54CD401000000000000000002000000500000000000000000000000000000000000000000000000000000008004010000000000070000000300000000000000000000400000000000000000000000000000000084B70100000000000100000000000000 "C:\Program Files (x86)\PowerpointImageExtractor_V1_2\unins000.exe"=0x5341435001000000000000000700000028000000D1990A000000000003000000000000000000030641220000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000C61B0000000000000100000001000000 "SIGN.IE=0E34000 SkypeWebPlugin.msi"=0x534143500100000000000000070000002800000000FE0000B780010001000000000000000000010500100000B395E7CF049FCE010000000000000000020000002800000000000000000000000000000000000000000000000000000046040000000000000100000001000000 "C:\Program Files\NVIDIA Corporation\Control Panel Client\nvcplui.exe"=0x53414350010000000000000007000000280000007860C20021B8C20001000000000000000000030673220000B395E7CF049FCE0100000000000000000200000028000000000000000000000000000000000000000000000000000000DC0C0100000000000100000001000000 "C:\Program Files (x86)\FreeJPG2PDF\FreeJPG2PDF.exe"=0x5341435001000000000000000700000028000000009007003524080001000000000000000000010671200000BFA2139DEDD1D30100000000000000000200000028000000000000000000000000100000000000000000000000000000D6430200000000000500000005000000 "C:\Program Files (x86)\Common Files\BioWare\Uninstall Star Wars - The Old Republic.exe"=0x5341435001000000000000000700000028000000D0D407000C5408000100000000000000000001060001000033504C2B57DFD101000000000000000005000000100000000000000000000000000000000000000002000000500000000000000000000040000000000000000000000000000000004C10000000000000020000000100000000000000000000000002000000000000000000000000000017110000000000000800000000000000 "C:\Windows\SysWOW64\msiexec.exe"=0x534143500100000000000000070000002800000000EA0000AA51010003000000000000000000030600210000975FD891C99ECE010000000000000000 "SIGN.MEDIA=28FE44 Advanced_Tokens_Manager_v3.5RC5\Advanced Tokens Manager v3.5 RC 5\Advanced Tokens Manager.exe"=0x5341435001000000000000000700000028000000002414000000000001000000000000000000030680210000B395E7CF049FCE01000000000000000005000000100000000000000000000000000000000000000002000000280000000000000000000040000000000000000000000000000000001D2B0200000000000200000002000000 "SIGN.MEDIA=28FE44 Advanced_Tokens_Manager_v3.5RC5(pour activer windows 8.1)\Advanced Tokens Manager v3.5 RC 5\Advanced Tokens Manager.exe"=0x5341435001000000000000000700000028000000002414000000000001000000000000000000030680210000B395E7CF049FCE010000000000000000050000001000000000000000000000000000000000000000020000002800000000000000000000400000000000000000000000000000000000340000000000000100000001000000 "C:\Users\EVRARD\AppData\Local\RadioSure\RadioSure.exe"=0x534143500100000000000000070000002800000000E42B00000000000100000000000000000003067122000067077CBAC54CD4010000000000000000020000002800000000000000000000000000000000000000000000000000000052933403000000005D0000005D000000 "SIGN.MEDIA=C80127 0-A transférer sur DD Archives\Firefox Setup 45.0.1(installé20160319).exe"=0x5341435001000000000000000700000028000000D0339A023FF29A0201000000000000000000030600210000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000F8600100000000000100000001000000 "C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\SETUP.EXE"=0x534143500100000000000000070000002800000078B30600F7A1070003000000000000000000010671220000975FD891C99ECE0100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000000000008000000000000000800000000000011F0000000000000100000001000000010000000400000001000000 "SIGN.MEDIA=3D00273 Logiciels-ACER20160512\vlc-2.2.3-win64_v2.2.3 fr.exe"=0x534143500100000000000000070000002800000028DCE301C395E4010100000000000000000001060001000019B4C529E312D101000000000000000002000000280000000000000000000040000000000000000000000000000000000D590000000000000100000001000000 "SIGN.MEDIA=3D00273 Logiciels-ACER20160512\pdf_converter_setup2.48.exe"=0x534143500100000000000000070000002800000048DEF9075EC4FA0701000000000000000000000A0021000019B4C529E312D1010000000000000000020000002800000000000000000000000000000000000000000000000000000071C80000000000000100000001000000 "C:\Program Files\AVAST Software\Avast\VisthAux.exe"=0x5341435001000000000000000700000028000000A0B80200E02D030001000000000000000000000A0021000019B4C529E312D10100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000004000000000000000000000000000000000BC000000000000000100000001000000 "SIGN.MEDIA=30B7F1D7 AcerCareCenterCheckTool.exe"=0x5341435001000000000000000700000028000000A0CF1600192C170001000000000000000000000A8021000059193B14E312D10100000000000000000200000028000000000000000000000000000000000000000000000000000000342E0000000000000200000002000000 "SIGN.MEDIA=69B340A1 AcerCareCenterCheckTool.exe"=0x5341435001000000000000000700000028000000A0CF1600192C170001000000000000000000000A80210000D5B3B31A57DFD101000000000000000002000000280000000000000000000000000000000000000000000000000000004C100000000000000100000001000000 "SIGN.MEDIA=48B84AA LenovoUsbDriver_autorun_1.0.15_user.exe"=0x5341435001000000000000000700000028000000A4B49400000000000100000000000000000001067100000033504C2B57DFD10100000000000000000200000028000000000000000008004000000000000000000000000000000000A0D50000000000000100000001000000 "SIGN.MEDIA=7FF64400 Mes Logiciels\ZedTV3.1.24.exe"=0x5341435001000000000000000700000028000000CD9FE100000000000100000000000000000002060001000033504C2B57DFD10100000000000000000200000028000000000000000000000000000000000000000000000000000000FA7D0000000000000100000001000000 "SIGN.MEDIA=7FF64400 Mes Logiciels\anyvideoconverter-free.exe"=0x534143500100000000000000070000002800000020360F03FDFC0F030100000000000000000001060001000033504C2B57DFD1010000000000000000020000002800000000000000000000400000000000000000000000000000000030960100000000000100000001000000 "SIGN.MEDIA=78C6C7F8 Mes Logiciels\slideshow_maker_setup2.17.exe"=0x5341435001000000000000000700000028000000303FF401F50CF50101000000000000000000000A0021000033504C2B57DFD10100000000000000000200000028000000000000000000000000000000000000000000000000000000FF710100000000000100000001000000 "SIGN.MEDIA=78C6C7F8 Mes Logiciels\winx-dvd-ripper-pt-February2017.exe"=0x5341435001000000000000000700000028000000F844400270CF40020100000000000000000003060001000033504C2B57DFD1010000000000000000 "SIGN.MEDIA=1E894AA2 Mes Logiciels\persoappsadressesv1.10.exe"=0x5341435001000000000000000700000028000000984CE4000E5EE40001000000000000000000000A0021000033504C2B57DFD1010000000000000000 "SIGN.MEDIA=1E894AA2 Mes Logiciels\calendrierv1.10.350.exe"=0x5341435001000000000000000700000028000000D01AD2003A87D20001000000000000000000000A0021000033504C2B57DFD1010000000000000000020000002800000000000000000000000000000000000000000000000000000060510900000000000100000001000000 "C:\Program Files (x86)\Alinea\Cuisine\Alinéa 3D Cuisine Uninstall.exe"=0x5341435001000000000000000700000028000000289205000000000001000000000000000000000A6122000033504C2B57DFD101000000000000000005000000100000000000000000000000000000000000000002000000500000000000000000000040000000000000000000000000000000008333000000000000010000000100000000000000000000000000000000000000000000000000000042170000000000000100000000000000 "SIGN.MEDIA=1E894AA2 Mes Logiciels\WhatsAppSetup0.2.3699(64bit).exe"=0x534143500100000000000000070000002800000010A5870583D987050100000000000000000003060001000033504C2B57DFD10100000000000000000200000028000000000000000000000000000000000000000000000000000000940B0100000000000200000002000000 "SIGN.MEDIA=1E894AA2 Mes Logiciels\pdf_converter_setup2.70.exe"=0x534143500100000000000000070000002800000010E8E007D071E10701000000000000000000000A0021000033504C2B57DFD1010000000000000000020000002800000000000000000000000000000000000000000000000000000036D70000000000000100000001000000 "SIGN.MEDIA=1E894AA2 Mes Logiciels\LibreOffice_5.3.1.fr_Win_x64.msi"=0x534143500100000000000000070000002800000000FE00009EC4010001000000000000000000010500100000D5B3B31A57DFD10100000000000000000200000028000000000000000000000000000000000000000000000000000000F7FE0200000000000100000001000000 "SIGN.MEDIA=1E894AA2 Mes Logiciels\Thunderbird Setup 52.0.fr.exe"=0x534143500100000000000000070000002800000090AF6C0259A16D020100000000000000000001060001000033504C2B57DFD1010000000000000000020000002800000000000000000000000000000000000000000000000000000017CF0000000000000100000001000000 "SIGN.MEDIA=1E894AA2 Mes Logiciels\AdobeAIRInstaller.exe"=0x5341435001000000000000000700000028000000C855A400E0CEA40001000000000000000000000A0021000033504C2B57DFD101000000000000000002000000280000000000000000000000000000000000000000000000000000009AFD0000000000000100000001000000 "SIGN.MEDIA=3D9B50 setup.exe"=0x5341435001000000000000000700000028000000403B0100473C010001000000000000000000000A00210000D5B3B31A57DFD1010000000000000000 "SIGN.MEDIA=1E8D39C2 Mes Logiciels\gu5setup5.73.exe"=0x5341435001000000000000000700000028000000483F000129ED000101000000000000000000010600010000E63F486B2AA0D2010000000000000000 "SIGN.MEDIA=1E8D39C2 Mes Logiciels\Malware_Hunter_v1.33.0.58.exe"=0x5341435001000000000000000700000028000000B0564C01CE194D0101000000000000000000010600010000E63F486B2AA0D2010000000000000000 "SIGN.MEDIA=1E8D39C2 Mes Logiciels\Skype_v7.35.0.101.msi"=0x53414350010000000000000007000000280000000002010013D4010001000000000000000000010500100000E78E163C2AA0D2010000000000000000020000002800000000000000000000000000000000000000000000000000000093330000000000000100000001000000 "SIGN.MEDIA=1E8D39C2 Mes Logiciels\NVIDIA_GeForce_Experience_v3.5.0.70.exe"=0x5341435001000000000000000700000028000000C8C5D3043092D40401000000000000000000020600010000E63F486B2AA0D2010000000000000000020000002800000000000000000000400000000000000000000000000000000031A90000000000000100000001000000 "C:\Program Files\Windows Mail\wab.exe"=0x534143500100000000000000070000002800000000E40700173D080001000000010000000000000A63220000E78E163C2AA0D2010000000000000000 "C:\Program Files\AVAST Software\Avast\setup\instup.exe"=0x534143500100000000000000070000002800000060CA13000000000003000000000000000000000A00210000E63F486B2AA0D2010000000000000000 "SIGN.MEDIA=579E189A Mes Logiciels\persoappsadresses1.20.exe"=0x534143500100000000000000070000002800000088BFE500F073E60001000000000000000000000A00210000E63F486B2AA0D2010000000000000000 "C:\Users\EVRARD\AppData\Local\Molotov\Update.exe"=0x5341435001000000000000000700000028000000002A17000000000001000000000000000000000A80210000BFA2139DEDD1D30100000080000000000200000028000000000000000000000000000000000000000000000000000000D0E97B01000000000900000009000000 "SIGN.MEDIA=579E5A6A Mes Logiciels\CCleaner_v5.31.6105.exe"=0x5341435001000000000000000700000028000000A8759200420E930001000000000000000000000A00210000E63F486B2AA0D2010000000000000000020000002800000000000000000000400000000000000000000000000000000023851600000000000100000001000000 "SIGN.MEDIA=579E5A6A Mes Logiciels\Glary_Utilities_v5.78.0.99.exe"=0x5341435001000000000000000700000028000000F0C80101F718020101000000000000000000010600010000E63F486B2AA0D20100000000000000000200000028000000000000000000004000000000000000000000000000000000E9A32301000000000100000001000000 "SIGN.MEDIA=579E5A6A Mes Logiciels\Update_Detector_v5.43.0.38.exe"=0x5341435001000000000000000700000028000000800F540021BD540001000000000000000000010600010000E63F486B2AA0D20100000080000000000200000028000000000000000000004000000000000000000000000000000000EAC11000000000000100000001000000 "SIGN.MEDIA=579E5A6A Mes Logiciels\Malware_Hunter_v1.38.0.97.exe"=0x5341435001000000000000000700000028000000B8886C0100626D0101000000000000000000010600010000E63F486B2AA0D20100000000000000000200000028000000000000000000004000000000000000000000000000000000EB2E1F01000000000100000001000000 "SIGN.MEDIA=579E5A6A Mes Logiciels\AdobeAIRInstaller (2).exe"=0x5341435001000000000000000700000028000000882EA600087CA60001000000000000000000000A00210000E63F486B2AA0D2010000000000000000020000002800000000000000000000000000000000000000000000000000000060460000000000000100000001000000 "SIGN.MEDIA=579E5A6A Mes Logiciels\flashplayer26ppau_ga_install.exe"=0x534143500100000000000000070000002800000008581200D385120001000000000000000000000A00210000E63F486B2AA0D20100000000000000000200000028000000000000000000000000000000000000000000000000000000B6FF0800000000000100000001000000 "SIGN.MEDIA=579E5A6A Mes Logiciels\speccysetup131.732.exe"=0x5341435001000000000000000700000028000000C81E6000FDD4600001000000000000000000010600010000E63F486B2AA0D20100000000000000000200000028000000000000000000004000000000000000000000000000000000376C0000000000000100000001000000 "SIGN.MEDIA=579E5A6A Mes Logiciels\gu5.79setup.exe"=0x534143500100000000000000070000002800000050C601013517020101000000000000000000010600010000E63F486B2AA0D2010000000000000000 "SIGN.MEDIA=579E5A6A Mes Logiciels\LibreOffice_5.3.4_Win_x64.msi"=0x53414350010000000000000007000000280000000002010013D4010001000000000000000000010500100000E78E163C2AA0D20100000000000000000200000028000000000000000000000000000000000000000000000000000000358B0400000000000100000001000000 "SIGN.MEDIA=579E5A6A Mes Logiciels\Malware_Hunter_v1.39.0.145.exe"=0x534143500100000000000000070000002800000028B68201E129830101000000000000000000010600010000E63F486B2AA0D201000000000000000002000000280000000000000000000040000000000000000000000000000000003BC11801000000000100000001000000 "SIGN.MEDIA=579E5A6A Mes Logiciels\ccsetup532.6129.exe"=0x534143500100000000000000070000002800000038BC940091CD940001000000000000000000000A00210000E63F486B2AA0D2010000000000000000020000002800000000000000000000400000000000000000000000000000000048B8EC00000000000100000001000000 "SIGN.MEDIA=579E5A6A Mes Logiciels\netsight_setup_7.4.0.13078_MP_Production_mid50927173054_p.exe"=0x5341435001000000000000000700000028000000089430009BBE300001000000000000000000010600010000E63F486B2AA0D2010000000000000000020000002800000000000000000000400000000000000000000000000000000014C70100000000000100000001000000 "SIGN.MEDIA=579E5A6A Mes Logiciels\Windows-KB890830-x64-V5.50.exe"=0x5341435001000000000000000700000028000000D06E9F02BBAE9F0201000000000000000000000A00210000E78E163C2AA0D201000000000000000002000000280000000000000000000040000000000000000000000000000000006E0D0000000000000100000001000000 "SIGN.MEDIA=579E5A6A Mes Logiciels\netsight_setup_7.4.0.13078_MP_Production_mid50927173054_p (1).exe"=0x5341435001000000000000000700000028000000089430009BBE300001000000000000000000010600010000E63F486B2AA0D20100000000000000000200000028000000000000000000004000000000000000000000000000000000295C1400000000000100000001000000 "SIGN.MEDIA=579E4E4A Mes Logiciels\Glary_Utilities_v5.80.0.101.exe"=0x534143500100000000000000070000002800000010DB01012A61020101000000000000000000010600010000E63F486B2AA0D201000000000000000002000000280000000000000000000040000000000000000000000000000000003F160500000000000100000001000000 "SIGN.MEDIA=579E4E4A Mes Logiciels\Malware_Hunter_v1.40.0.155.exe"=0x5341435001000000000000000700000028000000D0029001CAEB900101000000000000000000010600010000E63F486B2AA0D2010000000000000000020000002800000000000000000000400000000000000000000000000000000077D10700000000000100000001000000 "SIGN.MEDIA=579E4E4A Mes Logiciels\Java_Runtime_Environment_(64bit)_v8_Update_141.exe"=0x53414350010000000000000007000000280000004074E50397C6E50301000000000000000000000A73220000E78E163C2AA0D2010000000000000000020000002800000000000000000000400000000000000000000000000000000064400000000000000100000001000000 "SIGN.MEDIA=579E4E4A Mes Logiciels\AdobeAIRInstaller.exe"=0x5341435001000000000000000700000028000000A83AA600E615A70001000000000000000000000A00210000E63F486B2AA0D2010000000000000000020000002800000000000000000000000000000000000000000000000000000036400000000000000100000001000000 "SIGN.MEDIA=22DF00 start.exe"=0x534143500100000000000000070000002800000090DF2200990B23000100000000000000000003060001000067077CBAC54CD40100000000000000000200000028000000000000000000000000000000000000000000000000000000D8AF7300000000000600000006000000 "SIGN.MEDIA=59016C2D AcerCareCenterCheckTool.exe"=0x5341435001000000000000000700000028000000A0CF1600192C170001000000000000000000000A80210000E78E163C2AA0D20100000000000000000200000028000000000000000000000000000000000000000000000000000000320F0000000000000100000001000000 "SIGN.MEDIA=579E4E4A Mes Logiciels\Java_Runtime_Environment_(64bit)_v8_Update_144.exe"=0x53414350010000000000000007000000280000004064E503EAB4E50301000000000000000000000A73220000E78E163C2AA0D201000000000000000002000000280000000000000000000040000000000000000000000000000000006E410000000000000100000001000000 "SIGN.MEDIA=579E4E4A Mes Logiciels\LibreOffice_(64bit)_v5.4.0 (2).msi"=0x53414350010000000000000007000000280000000002010013D4010001000000000000000000010500100000E78E163C2AA0D20100000000000000000200000028000000000000000000000000000000000000000000000000000000E7530100000000000100000001000000 "SIGN.MEDIA=579E4E4A Mes Logiciels\NVIDIA_GeForce_Experience_v3.8.0.89.exe"=0x5341435001000000000000000700000028000000C0FA5B05CC2A5C0501000000000000000000020600010000E63F486B2AA0D2010000000000000000020000002800000000000000000000400000000000000000000000000000000012A10000000000000100000001000000 "SIGN.MEDIA=579E4E4A Mes Logiciels\adwcleaner_7.0.1.0.exe"=0x5341435001000000000000000700000028000000C8E57C00C3187D0001000000000000000000000A00210000E63F486B2AA0D20100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000004000000000000000000000000000000000148C0000000000000100000001000000 "SIGN.MEDIA=2AA65D autorun.exe"=0x5341435001000000000000000700000028000000002E08001E93080001000000000000000000000671000000E63F486B2AA0D20100000000000000000200000028000000000000008000000000000000000000000000000000000000CB090F00000000000400000004000000 "SIGN.MEDIA=579E4E4A Mes Logiciels\ccsetup533.6162.exe"=0x5341435001000000000000000700000028000000486995001FC5950001000000000000000000000A00210000E63F486B2AA0D2010000000000000000020000002800000000000000000000400000000000000000000000000000000099C16701000000000100000001000000 "SIGN.MEDIA=579E4E4A Mes Logiciels\winrar-x64-550fr.exe"=0x5341435001000000000000000700000028000000104F2300C7E9230001000000000000000000000A00210000E78E163C2AA0D20100000000000000000200000028000000000000000000004000000000000000000000000000000000DC1F0000000000000200000002000000 "SIGN.MEDIA=579E4E4A Mes Logiciels\VSDC_Free_Video_Editor_v5.7.8.724.exe"=0x53414350010000000000000007000000280000007014510207AB510201000000000000000000000A00210000E63F486B2AA0D201000000000000000002000000280000000000000000000000000000000000000000000000000000009C140100000000000100000001000000 "SIGN.MEDIA=579E4E4A Mes Logiciels\OBS-Studio-18.0.1-Full-Installer.exe"=0x5341435001000000000000000700000028000000C0C5BC06FD1EBD0601000000000000000000000A00210000E63F486B2AA0D20100000000000000000200000028000000000000000000004000000000000000000000000000000000A39B0000000000000100000001000000 "SIGN.MEDIA=579E4E4A Mes Logiciels\persoappscalendrierv1.21.exe"=0x5341435001000000000000000700000028000000E035D7001E0FD80001000000000000000000000A00210000E63F486B2AA0D20100000000000000000200000028000000000000000000000000000000000000000000000000000000AC070100000000000100000001000000 "SIGN.MEDIA=579E4E4A Mes Logiciels\gu5.82.0.103setup.exe"=0x5341435001000000000000000700000028000000B81D0301F434030101000000000000000000010600010000E63F486B2AA0D20100000000000000000200000028000000000000000000004000000000000000000000000000000000FF6DA700000000000100000001000000 "SIGN.MEDIA=579E4E4A Mes Logiciels\Malware_Hunter_v1.42.0.157.exe"=0x5341435001000000000000000700000028000000B0FFA901F5EAAA0101000000000000000000010600010000E63F486B2AA0D20100000000000000000200000028000000000000000000004000000000000000000000000000000000B22FA300000000000100000001000000 "SIGN.MEDIA=579E4E4A Mes Logiciels\Glary_Utilities_v5.85.0.106.exe"=0x534143500100000000000000070000002800000068130401FD52040101000000000000000000010600010000E63F486B2AA0D2010000000000000000 "SIGN.MEDIA=579E4E4A Mes Logiciels\Malware_Hunter_v1.45.0.422.exe"=0x53414350010000000000000007000000280000006063D5015EA0D50101000000000000000000010600010000E63F486B2AA0D2010000000000000000020000002800000000000000000000400000000000000000000000000000000005FF5800000000000100000001000000 "SIGN.MEDIA=579E4E4A Mes Logiciels\Update_Detector_v5.43.0.39.exe"=0x534143500100000000000000070000002800000018685500B7FC550001000000000000000000010600010000E63F486B2AA0D201000000800000000002000000280000000000000000000040000000000000000000000000000000004AD65600000000000100000001000000 "SIGN.MEDIA=579E96E2 Mes Logiciels\AdobeAIRInstaller (1).exe"=0x534143500100000000000000070000002800000000E2A6009B9AA70001000000000000000000000A00210000E63F486B2AA0D20100000000000000000200000028000000000000000000000000000000000000000000000000000000744D0000000000000100000001000000 "SIGN.MEDIA=579E96E2 Mes Logiciels\CCleaner_v5.35.6210.exe"=0x534143500100000000000000070000002800000018AF95004D8F960001000000000000000000000A00210000E63F486B2AA0D2010000000000000000 "SIGN.MEDIA=579E96E2 Mes Logiciels\Thunderbird Setup 52.4.0.fr.exe"=0x5341435001000000000000000700000028000000A87B6B027FD76B0201000000000000000000000A00210000E63F486B2AA0D20100000000000000000200000028000000000000000000000000000000000000000000000000000000D60D0100000000000100000001000000 "SIGN.MEDIA=579E96E2 Mes Logiciels\FreeVideoEditor_1.4.54.606_d.exe"=0x5341435001000000000000000700000028000000986A1F0212EF1F0201000000000000000000000A00210000E63F486B2AA0D201000000000000000002000000280000000000000000000000000000000000000000000000000000004B330200000000000100000001000000 "SIGN.MEDIA=579E96E2 Mes Logiciels\Windows-KB890830-x64-V5.53.exe"=0x5341435001000000000000000700000028000000C88A53021A68540201000000000000000000000A00210000E78E163C2AA0D20100000000000000000200000028000000000000000000004000000000000000000000000000000000B5570000000000000100000001000000 "C:\Program Files (x86)\Microsoft Office\Office12\POWERPNT.EXE"=0x5341435001000000000000000700000028000000F01A080089E5080001000000000000000000000A71220000631F6E6F0EDED4010000000100000000 "SIGN.MEDIA=579E96E2 Mes Logiciels\calendrier1.23.368.exe"=0x534143500100000000000000070000002800000058F3DA00C410DB0001000000000000000000000A00210000E63F486B2AA0D20100000000000000000200000028000000000000000000000000000000000000000000000000000000792CAD07000000000100000001000000 "SIGN.MEDIA=579E96E2 Mes Logiciels\KeePass-2.37-Setup.exe"=0x5341435001000000000000000700000028000000A8343100EF02320001000000000000000000000A00210000E63F486B2AA0D20100000000000000000200000028000000000000000000000000000000000000000000000000000000FEEF0000000000000100000001000000 "SIGN.MEDIA=49ECF5 Mes Logiciels\captvty-2.6.2\Captvty.exe"=0x534143500100000000000000070000002800000000F624000000000001000000000000000000000AF1220000E63F486B2AA0D201000000000000000002000000280000000000000000000000000000000000000000000000000000007B2A0000000000000100000001000000 "SIGN.MEDIA=24F54C Mes Logiciels\captvty-2.6.2\Captvty2.6.2.exe"=0x534143500100000000000000070000002800000000F624000000000001000000000000000000000AF1220000E63F486B2AA0D2010000000000000000020000002800000000000000000000000000000000000000000000000000000096B90100000000000200000002000000 "SIGN.MEDIA=579E96E2 Mes Logiciels\flashplayer27ppau_ha_install.exe"=0x5341435001000000000000000700000028000000F0611200CB04130001000000000000000000000A00210000E63F486B2AA0D201000000000000000002000000280000000000000000000000000000000000000000000000000000001B9D0000000000000100000001000000 "SIGN.MEDIA=579E96E2 Mes Logiciels\Mozilla_Firefox_(64bit)_v56.0.1.exe"=0x5341435001000000000000000700000028000000A8874E02EA9D4E0201000000000000000000000A00210000E63F486B2AA0D201000000000000000002000000280000000000000000000000000000000000000000000000000000006DC60000000000000100000001000000 "SIGN.MEDIA=579E96E2 Mes Logiciels\NVIDIA_GeForce_Experience_v3.10.0.95.exe"=0x5341435001000000000000000700000028000000C813DA04A406DB0401000000000000000000020600010000E63F486B2AA0D20100000000000000000200000028000000000000000000004000000000000000000000000000000000E0B80000000000000100000001000000 "SIGN.MEDIA=579E96E2 Mes Logiciels\LibreOffice_5.4.2_Win_x64.msi"=0x53414350010000000000000007000000280000000002010013D4010001000000000000000000010500100000E78E163C2AA0D201000000000000000002000000280000000000000000000000000000000000000000000000000000009DBF0200000000000100000001000000 "SIGN.MEDIA=579E96E2 Mes Logiciels\pdf_converter_setup2.74.exe"=0x5341435001000000000000000700000028000000E8C1E007EAA6E10701000000000000000000000A00210000E63F486B2AA0D20100000000000000000200000028000000000000000000000000000000000000000000000000000000F1E40000000000000100000001000000 "SIGN.MEDIA=579E96E2 Mes Logiciels\Revo_Uninstaller_v2.0.4.exe"=0x534143500100000000000000070000002800000000B56D00EED46D0001000000000000000000000A00210000E63F486B2AA0D20100000000000000000200000028000000000000000000000000000000000000000000000000000000F54F0000000000000100000001000000 "SIGN.MEDIA=579E96E2 Mes Logiciels\Java_Runtime_Environment_(64bit)_v8_Update_151.exe"=0x534143500100000000000000070000002800000040F4330477E9340401000000000000000000000A73220000E78E163C2AA0D20100000000000000000200000028000000000000000000004000000000000000000000000000000000DF4A0100000000000100000001000000 "SIGN.MEDIA=1181E10 Mes Logiciels\MediaCreationTool-sospc.name_\MediaCreationTool sospc.name.exe"=0x5341435001000000000000000700000028000000101E18017809190101000000000000000000000A00210000E63F486B2AA0D20100000000000000000200000028000000000000000000004000000000000000000000000000000000C53D0000000000000100000001000000 "SIGN.MEDIA=579E96E2 Mes Logiciels\Windows10Upgrade9252 (1).exe"=0x534143500100000000000000070000002800000080CF6300473C640001000000000000000000000A00210000E63F486B2AA0D2010000000000000000020000002800000000000000000000400000000000000000000000000000000067756100000000000100000001000000 "SIGN.MEDIA=579E96E2 Mes Logiciels\MediaCreationTool (1).exe"=0x5341435001000000000000000700000028000000101E18017809190101000000000000000000000A00210000E63F486B2AA0D2010000000000000000020000002800000000000000000000400000000000000000000000000000000072A60000000000000400000004000000 "SIGN.MEDIA=579E96E2 Mes Logiciels\MediaCreationTool (3).exe"=0x5341435001000000000000000700000028000000C0141C01357C1C0101000000000000000000000A00210000E63F486B2AA0D2010000000000000000020000002800000000000000000000400000000000000000000000000000000036663900000000000200000002000000 "SIGN.MEDIA=3CC2E8 setup.exe"=0x5341435001000000000000000700000028000000383B010034A3010001000000000000000000000A00210000E78E163C2AA0D20100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000004000000000000000000000000000000000DF020000000000000400000004000000 "SIGN.MEDIA=579E96E2 Mes Logiciels\Minitool partition wizard10.2.1-free.exe"=0x53414350010000000000000007000000280000004820CC02BC1CCD0201000000000000000000000A00210000DB80FDAC2839D30100000000000000000200000028000000000000000000000000000000000000000000000000000000EBF40400000000000100000001000000 "SIGN.MEDIA=579E96E2 Mes Logiciels\Minitool partition wizard10.2.2-free.exe"=0x53414350010000000000000007000000280000004820CC02BC1CCD0201000000000000000000000A00210000DB80FDAC2839D30100000000000000000200000028000000000000000000000000000000000000000000000000000000B90A0100000000000100000001000000 "SIGN.MEDIA=579E96E2 Mes Logiciels\Malware_Hunter_v1.45.0.422.exe"=0x53414350010000000000000007000000280000006063D5015EA0D50101000000000000000000010600010000DB80FDAC2839D3010000000000000000020000002800000000000000000000400000000000000000000000000000000090410600000000000100000001000000 "SIGN.MEDIA=579E96E2 Mes Logiciels\Glary_Utilities_v5.86.0.107.exe"=0x5341435001000000000000000700000028000000C8A00401AA9B050101000000000000000000010600010000DB80FDAC2839D301000000000000000002000000280000000000000000000040000000000000000000000000000000001F143A02000000000100000001000000 "SIGN.MEDIA=579E96E2 Mes Logiciels\ccsetup536.6278.exe"=0x5341435001000000000000000700000028000000F01A9F00A9449F0001000000000000000000000A00210000DB80FDAC2839D301000000000000000002000000280000000000000000000040000000000000000000000000000000009A4C0000000000000100000001000000 "SIGN.MEDIA=579E96E2 Mes Logiciels\Malware_Hunter_v1.46.0.430.exe"=0x5341435001000000000000000700000028000000E00AE3012FF9E30101000000000000000000010600010000DB80FDAC2839D30100000000000000000200000028000000000000000000004000000000000000000000000000000000913B3602000000000100000001000000 "SIGN.MEDIA=6DB534 Mes Logiciels\CrystalDiskInfo7_5_0\DiskInfo64.exe"=0x5341435001000000000000000700000028000000B0BD3A0090473B0001000000000000000000000A00210000DB80FDAC2839D301000000000000000002000000280000000000000000000040000000000000000000000000000000008E830200000000000200000002000000 "SIGN.MEDIA=579E96E2 Mes Logiciels\Foxit_Reader_v9.0.0.29935.exe"=0x534143500100000000000000070000002800000048573403D381340301000000000000000000000A00210000DB80FDAC2839D30100000000000000000200000028000000000000000000000000000000000000000000000000000000D3E30100000000000100000001000000 "SIGN.MEDIA=579E96E2 Mes Logiciels\FreemakeVideoConverterSetup4.1.10.24.exe"=0x5341435001000000000000000700000028000000B8750F000D4D100001000000000000000000020600010000DB80FDAC2839D30100000000000000000200000028000000000000000000000000100000000000000000000000000000C7350300000000000100000001000000 "SIGN.MEDIA=579E96E2 Mes Logiciels\FreemakeVideoConverterSetup4.1.9.29.exe"=0x5341435001000000000000000700000028000000107B1C00A97B1C0001000000000000000000030600010000DB80FDAC2839D3010000000000000000 "SIGN.MEDIA=579E96E2 Mes Logiciels\vso_downloader_setup.exe"=0x534143500100000000000000070000002800000000339A01ABC29A0101000000000000000000000A00210000DB80FDAC2839D3010000000000000000020000002800000000000000000000000000000000000000000000000000000052090100000000000100000001000000 "SIGN.MEDIA=579E96E2 Mes Logiciels\gu5.87.0.108setup.exe"=0x5341435001000000000000000700000028000000682005011CB7050101000000000000000000010600010000DB80FDAC2839D3010000000000000000020000002800000000000000000000400000000000000000000000000000000069439702000000000100000001000000 "SIGN.MEDIA=579E96E2 Mes Logiciels\Update_Detector_v5.43.0.40.exe"=0x5341435001000000000000000700000028000000B08356002E0C570001000000000000000000010600010000DB80FDAC2839D30100000000000000000200000028000000000000000000004000000000000000000000000000000000B3629502000000000100000001000000 "SIGN.MEDIA=579E96E2 Mes Logiciels\Malware_Hunter_v1.47.0.438.exe"=0x5341435001000000000000000700000028000000E0D7F001FC2DF10101000000000000000000010600010000DB80FDAC2839D30100000000000000000200000028000000000000000000004000000000000000000000000000000000F60C9402000000000100000001000000 "SIGN.MEDIA=579E96E2 Mes Logiciels\FreemakeVideoConverterSetup.exe"=0x5341435001000000000000000700000028000000B8750F000D4D100001000000000000000000020600010000DB80FDAC2839D3010000000000000000 "C:\Program Files (x86)\Freemake\Freemake Video Converter\FreemakeVC.exe"=0x534143500100000000000000070000002800000020E45000914A510001000000000000000000000A71220000DB80FDAC2839D301000000000000000002000000280000000000000000000000000000000000000000000000000000004E220000000000000100000001000000 "SIGN.MEDIA=579E96E2 Mes Logiciels\adwcleaner_7.0.4.0.exe"=0x5341435001000000000000000700000028000000D00F7E00268F7E0001000000000000000000000A00210000DB80FDAC2839D3010000000000000000 "SIGN.MEDIA=579E96E2 Mes Logiciels\ZHPCleaner2017.exe"=0x534143500100000000000000070000002800000080412D0018D42D0001000000000000000000030600010000DB80FDAC2839D3010000000000000000020000002800000000000000000000400000000000000000000000000000000000990400000000000100000001000000 "SIGN.MEDIA=579E96E2 Mes Logiciels\mb3-setup-35891.35891-3.3.1.2183.exe"=0x5341435001000000000000000700000028000000B079AB04D695AB0401000000000000000000000A00210000DB80FDAC2839D3010000000000000000 "SIGN.MEDIA=579E96E2 Ma Logithèque\flashplayer27ppau_ha_install.exe"=0x5341435001000000000000000700000028000000F0611200CB04130001000000000000000000000A00210000DB80FDAC2839D30100000000000000000200000028000000000000000000000000000000000000000000000000000000F1B00000000000000200000002000000 "SIGN.MEDIA=579E96E2 Ma Logithèque\Adobe_Shockwave_Player_v12.3.1.201.exe"=0x53414350010000000000000007000000280000001070E00063E2E00001000000000000000000000A00210000DB80FDAC2839D30100000000000000000200000028000000000000000000004000000000000000000000000000000000E6200000000000000100000001000000 "SIGN.MEDIA=579E96E2 Ma Logithèque\VSDC_Free_Video_Editor_v5.8.1.788.exe"=0x534143500100000000000000070000002800000068675702B731580201000000000000000000000A00210000DB80FDAC2839D3010000000000000000020000002800000000000000000000000000000000000000000000000000000026210300000000000100000001000000 "SIGN.MEDIA=579E96E2 Ma Logithèque\Thunderbird Setup 52.4.0.fr.exe"=0x5341435001000000000000000700000028000000A87B6B027FD76B0201000000000000000000000A00210000DB80FDAC2839D301000000000000000002000000280000000000000000000000000000000000000000000000000000001B210200000000000100000001000000 "SIGN.MEDIA=23D01C0 Ma Logithèque\DirectoryListPrintPortableFR3.40\DirectoryListPrintPro3.40.exe"=0x53414350010000000000000007000000280000000010020197BF020101000000000000000000000A71200000DB80FDAC2839D30100000000000000000200000028000000000000000000000000000000000000000000000000000000994C0000000000000300000003000000 "SIGN.MEDIA=579E96E2 Ma Logithèque\pdf_split_and_merge_setup3.41.exe"=0x534143500100000000000000070000002800000008132E018B3A2E0101000000000000000000000A00210000DB80FDAC2839D3010000000000000000 "SIGN.MEDIA=579E96E2 Ma Logithèque\NVIDIA_GeForce_Experience_v3.11.0.73.exe"=0x5341435001000000000000000700000028000000E04DEF043AADEF0401000000000000000000020600010000DB80FDAC2839D30100000000000000000200000028000000000000000000004000000000000000000000000000000000259E0000000000000100000001000000 "SIGN.MEDIA=579E96E2 Ma Logithèque\gu5setup5.88.0.109.exe"=0x5341435001000000000000000700000028000000B8A70501CDAD050101000000000000000000010600010000DB80FDAC2839D3010000000000000000 "SIGN.MEDIA=579E96E2 Ma Logithèque\Malware_Hunter_v1.48.0.442.exe"=0x534143500100000000000000070000002800000030EB0C028C0C0D0201000000000000000000010600010000DB80FDAC2839D3010000000000000000 "SIGN.MEDIA=579E96E2 Ma Logithèque\Update_Detector_v5.44.0.41.exe"=0x5341435001000000000000000700000028000000880757000416570001000000000000000000010600010000DB80FDAC2839D3010000000000000000 "SIGN.MEDIA=2E83220 Ma Logithèque\CDBurnerXP-4.5.8.6795\cdbxpp.exe"=0x534143500100000000000000070000002800000070BE1A00F1D01A0001000000000000000000000A00210000DB80FDAC2839D301000000000000000002000000280000000000000000000000000000000000000000000000000000009D300500000000000600000006000000 "SIGN.MEDIA=579E96E2 Ma Logithèque\FreemakeVideoConverterSetup4.1.10.25.exe"=0x534143500100000000000000070000002800000030760F00FAA90F0001000000000000000000020600010000DB80FDAC2839D30100000000000000000200000028000000000000000000000000100000000000000000000000000000807B2001000000000100000001000000 "SIGN.MEDIA=579E96E2 Ma Logithèque\VDownloaderSetup4.5.2880.exe"=0x534143500100000000000000070000002800000048ECF1011AC8F20101000000000000000000000A00210000DB80FDAC2839D3010000000000000000020000002800000000000000000000400000000000000000000000000000000073200100000000000100000001000000 "SIGN.MEDIA=579E96E2 Ma Logithèque\persoappscalendrier1.2.5.369.exe"=0x534143500100000000000000070000002800000098B8DB006864DC0001000000000000000000000A00210000DB80FDAC2839D30100000000000000000200000028000000000000000000000000000000000000000000000000000000791F0100000000000100000001000000 "SIGN.MEDIA=579E96E2 Ma Logithèque\FreeStudio_6.6.39.707_d.exe"=0x5341435001000000000000000700000028000000A0C385035C2D860301000000000000000000000A00210000DB80FDAC2839D3010000000000000000020000002800000000000000000000000000000000000000000000000000000059FA0100000000000100000001000000 "C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\PremiumMembershipOffer.exe"=0x5341435001000000000000000700000028000000E89D13003465140001000000000000000000000A71220000DB80FDAC2839D30100000000000000000200000028000000000000000000000000000000000000000000000000000000C0360000000000000200000002000000 "SIGN.MEDIA=C60D66FC Ma Logithèque\vlc-2.2.8fr-win64.exe"=0x5341435001000000000000000700000028000000C8A8E801B66FE90101000000000000000000010600010000DB80FDAC2839D30100000000000000000200000028000000000000000000004000000000000000000000000000000000EB410000000000000100000001000000 "SIGN.MEDIA=C60D66FC Ma Logithèque\adwcleaner_7.0.5.0.exe"=0x534143500100000000000000070000002800000000B27C000000000001000000000000000000000A00210000DB80FDAC2839D30100000000000000000200000028000000000000000000004000000000000000000000000000000000CB340000000000000200000002000000 "SIGN.MEDIA=C60D66FC Ma Logithèque\gu5.89.0110setup.exe"=0x5341435001000000000000000700000028000000D8AD05017F71060101000000000000000000010600010000DB80FDAC2839D30100000000000000000200000028000000000000000000004000000000000000000000000000000000F618E701000000000100000001000000 "SIGN.MEDIA=C60D66FC Ma Logithèque\Malware_Hunter_v1.49.0.479.exe"=0x5341435001000000000000000700000028000000C0F6B4012D97B50101000000000000000000010600010000DB80FDAC2839D30100000000000000000200000028000000000000000000004000000000000000000000000000000000D5059A02000000000100000001000000 "SIGN.MEDIA=DE7A5D8C Ma Logithèque\vsdc-free-video-editor_5-8-2-796_fr_430963.exe"=0x5341435001000000000000000700000028000000C8AF570272DF570201000000000000000000000A00210000DB80FDAC2839D3010000000000000000020000002800000000000000000000000000000000000000000000000000000074950100000000000100000001000000 "C:\Program Files (x86)\Free Video Joiner\FreeVideoJoiner.exe"=0x5341435001000000000000000700000028000000009E0D000000000001000000000000000000010671220000DB80FDAC2839D3010000000000000000020000002800000000000000000000000000000000000000000000000000000062417900000000000B0000000B000000 "SIGN.MEDIA=DE7A5D8C Ma Logithèque\FreeStudio_6.6.39.707_d.exe"=0x5341435001000000000000000700000028000000A0C385035C2D860301000000000000000000000A00210000DB80FDAC2839D3010000000000000000020000002800000000000000000000000000000000000000000000000000000011120000000000000100000001000000 "SIGN.MEDIA=1DA1FB4 Ma Logitheque Portable\ccsetup537.6309\CCleaner64.exe"=0x5341435001000000000000000700000028000000B0F69800D334990001000000000000000000000A00210000DB80FDAC2839D301000000000000000002000000280000000000000000000000000000000000000000000000000000003AC00200000000000100000001000000 "SIGN.MEDIA=73BCF5 Ma Logithèque\captvty-2.6.5\Captvty.exe"=0x534143500100000000000000070000002800000000DE39000000000001000000000000000000000A71220000DB80FDAC2839D30100000000000000000200000028000000000000000000000000000000000000000000000000000000B45F0000000000000100000001000000 "SIGN.MEDIA=BF3948C2 Ma Logithèque\ICECREAM\icecream-slideshow-maker_2-67_fr_431643.exe"=0x5341435001000000000000000700000028000000F8B03701864A380101000000000000000000000A00210000DB80FDAC2839D30100000000000000000200000028000000000000000000000000000000000000000000000000000000AA580100000000000100000001000000 "SIGN.MEDIA=DE7A5D8C Ma Logithèque\flashplayer28ppau_ha_install.exe"=0x5341435001000000000000000700000028000000F0611200CB04130001000000000000000000000A00210000DB80FDAC2839D30100000000000000000200000028000000000000000000000000000000000000000000000000000000487E0000000000000100000001000000 "SIGN.MEDIA=DE7A5D8C Ma Logithèque\ccsetup538.6357.exe"=0x534143500100000000000000070000002800000038F6AA00A7E8AB0001000000000000000000000A00210000DB80FDAC2839D30100000000000000000200000028000000000000000000004000000000000000000000000000000000AB151101000000000100000001000000 "SIGN.MEDIA=DE7A5D8C Ma Logithèque\VSDC_Free_Video_Editor_v5.8.2.798.exe"=0x5341435001000000000000000700000028000000C0AF5702733A580201000000000000000000000A00210000DB80FDAC2839D301000000000000000002000000280000000000000000000000000000000000000000000000000000001A3D0300000000000100000001000000 "SIGN.MEDIA=DE7A5D8C Ma Logithèque\AdobeAIRInstaller (2).exe"=0x53414350010000000000000007000000280000009049A5005D23A60001000000000000000000000A00210000DB80FDAC2839D30100000000000000000200000028000000000000000000000000000000000000000000000000000000703E0000000000000100000001000000 "SIGN.MEDIA=DE7A5D8C Ma Logithèque\FreemakeVideoConverterSetup4.1.10.31.exe"=0x534143500100000000000000070000002800000038760F00848E0F0001000000000000000000020600010000DB80FDAC2839D30100000000000000000200000028000000000000000000000000100000000000000000000000000000A4CCFE00000000000100000001000000 "SIGN.MEDIA=DE7A5D8C Ma Logithèque\flashplayer28pp_xa_install.exe"=0x5341435001000000000000000700000028000000F0631200176B120001000000000000000000000A00210000DB80FDAC2839D30100000000000000000200000028000000000000000000000000000000000000000000000000000000B3F10000000000000300000003000000 "SIGN.MEDIA=DE7A5D8C Ma Logithèque\Glary_Utilities_v5.90.0.111.exe"=0x5341435001000000000000000700000028000000E8AA050151DF050101000000000000000000010600010000DB80FDAC2839D3010000000000000000 "SIGN.MEDIA=DE7A5D8C Ma Logithèque\Malware_Hunter_v1.50.0.480.exe"=0x53414350010000000000000007000000280000002042B40126CCB40101000000000000000000010600010000DB80FDAC2839D301000000000000000002000000280000000000000000000040000000000000000000000000000000004CD4B202000000000100000001000000 "SIGN.MEDIA=DE7A5D8C Ma Logithèque\persoappsadresses.exe"=0x53414350010000000000000007000000280000004808EE00034DEE0001000000000000000000000A00210000DB80FDAC2839D301000000000000000002000000280000000000000000000000000000000000000000000000000000004A130000000000000100000001000000 "SIGN.MEDIA=DE7A5D8C Ma Logithèque\persoappsadresses1.2.5.1177.exe"=0x53414350010000000000000007000000280000004808EE00034DEE0001000000000000000000000A00210000DB80FDAC2839D30100000000000000000200000028000000000000000000000000000000000000000000000000000000828CE001000000000100000001000000 "SIGN.MEDIA=DE7A5D8C Ma Logithèque\FoxitReader901_L10N_Setup_Prom.exe"=0x534143500100000000000000070000002800000008599D04C74D9E0401000000000000000000000A00210000DB80FDAC2839D30100000000000000000200000028000000000000000000000000000000000000000000000000000000F69E0200000000000100000001000000 "SIGN.MEDIA=DE7A5D8C Ma Logithèque\(intel rapid storage)SetupOptaneMemory.exe"=0x534143500100000000000000070000002800000048F4D9001F9ADA0001000000000000000000000A00210000DB80FDAC2839D3010000000000000000020000002800000000000000000000400000000000000000000000000000000030F20000000000000100000001000000 "SIGN.MEDIA=DE7A5D8C Ma Logithèque\hwmonitor_1-34_fr_192642.exe"=0x5341435001000000000000000700000028000000C09D12001360130001000000000000000000000A00210000DB80FDAC2839D3010000000000000000020000002800000000000000000000000000000000000000000000000000000084740000000000000100000001000000 "SIGN.MEDIA=DE7A5D8C Ma Logithèque\VSDCvideo_editor_x32_5.8.5.802.exe"=0x534143500100000000000000070000002800000048AF5802B353590201000000000000000000000A00210000DB80FDAC2839D30100000000000000000200000028000000000000000000000000000000000000000000000000000000824F0100000000000100000001000000 "SIGN.MEDIA=AF187E88 Ma Logithèque\ICECREAM\Icecream_PDF_Converter_v2.75.exe"=0x5341435001000000000000000700000028000000281FE1079426E10701000000000000000000000A00210000DB80FDAC2839D30100000000000000000200000028000000000000000000000000000000000000000000000000000000A9D60000000000000100000001000000 "SIGN.MEDIA=DE7A5D8C Ma Logithèque\adwcleaner_7.0.6.0.exe"=0x534143500100000000000000070000002800000020197D00CDE67D0001000000000000000000000A00210000DB80FDAC2839D30100000000000000000200000028000000000000000000004000000000000000000000000000000000E0210000000000000100000001000000 "SIGN.MEDIA=A36FCC68 Ma Logithèque\ICECREAM\Icecream_Slideshow_Maker_v3.01.exe"=0x534143500100000000000000070000002800000098DC39017B253A0101000000000000000000000A00210000DB80FDAC2839D3010000000000000000020000002800000000000000000000000000000000000000000000000000000063010100000000000100000001000000 "C:\Program Files\windows nt\accessories\wordpad.exe"=0x53414350010000000000000007000000280000000084440048B7440001000000010000000000000A63220000DB80FDAC2839D3010000000000000000 "C:\Program Files\Mozilla Firefox\pingsender.exe"=0x5341435001000000000000000700000028000000D0F7000096B9010001000000000000000000000A73200000DB80FDAC2839D3010000000000000000020000002800000000000000000000000000000000000000000000000000000040050000000000000D0000000D000000 "SIGN.MEDIA=82F83E89 Ma Logitheque Portable\SUPERAntiSpyware6.6.0.1252.exe"=0x5341435001000000000000000700000028000000C018E1017B41E10101000000000000000000020600010000DB80FDAC2839D30100000000000000000200000028000000000000000000000000000000000000000000000000000000CFDA1700000000000100000001000000 "SIGN.MEDIA=13A6219E Ma Logithèque\flashplayer28_xa_install.exe"=0x5341435001000000000000000700000028000000F0611200D891120001000000000000000000000A00210000DB80FDAC2839D3010000000000000000020000002800000000000000000000000000000000000000000000000000000067A00000000000000100000001000000 "SIGN.MEDIA=13A6219E Ma Logithèque\flashplayer28pp_xa_install.exe"=0x5341435001000000000000000700000028000000F0631200176B120001000000000000000000000A00210000DB80FDAC2839D30100000000000000000200000028000000000000000000000000000000000000000000000000000000BA9A0000000000000100000001000000 "SIGN.MEDIA=13A6219E Ma Logithèque\Install Restore Point Creator.exe"=0x5341435001000000000000000700000028000000482D0D000000000001000000000000000000000A00210000DB80FDAC2839D3010000000000000000020000002800000000000000000000000000000000000000000000000000000050600000000000000100000001000000 "SIGN.MEDIA=13A6219E Ma Logithèque\NVIDIA_GeForce_Experience_v3.12.0.79.exe"=0x534143500100000000000000070000002800000040510205815B020501000000000000000000020600010000DB80FDAC2839D301000000000000000002000000280000000000000000000040000000000000000000000000000000002BA20000000000000100000001000000 "SIGN.MEDIA=13A6219E Ma Logithèque\FreemakeVideoConverterFull4.1.10.38.exe"=0x5341435001000000000000000700000028000000A8DD2F021598300201000000000000000000020600010000DB80FDAC2839D30100000000000000000200000028000000000000000000000000100000000000000000000000000000CC1F0A00000000000100000001000000 "SIGN.MEDIA=13A6219E Ma Logithèque\avast_free_antivirus_setup_online_z2a.exe"=0x5341435001000000000000000700000028000000C06F6D0091586E0001000000000000000000000A00210000DB80FDAC2839D30100000000000000000200000028000000000000000000004000000000000000000000000000000000FADB0300000000000100000001000000 "C:\Users\EVRARD\AppData\Roaming\ZHP\ZHPCleaner.exe"=0x534143500100000000000000070000002800000080732E0067C42E0001000000000000000000030600010000DB80FDAC2839D30100000000000000000200000028000000000000000000004000000000000000000000000000000000655E0800000000000200000002000000 "SIGN.MEDIA=13A6219E Ma Logithèque\SUPERAntiSpyware6.6.0.1254.exe"=0x534143500100000000000000070000002800000078ECE2016614E30101000000000000000000020600010000DB80FDAC2839D3010000000000000000020000002800000000000000000000000000000000000000000000000000000023CC2900000000000100000001000000 "SIGN.MEDIA=1FEF1C2B Ma Logitheque Portable\sumo5.5.1.382\sumo\SUMo5.5.1.382.exe"=0x5341435001000000000000000700000028000000B8621F00A7B61F0001000000000000000000000A61200000DB80FDAC2839D301000000000000000002000000280000000000000000000000000000000000000000000000000000001FCD2200000000000500000005000000 "SIGN.MEDIA=1BC0B34 Ma Logitheque Portable\ccsetup539.6399\CCleaner64.exe"=0x5341435001000000000000000700000028000000D0859C00B2109D0001000000000000000000000A00210000DB80FDAC2839D30100000000000000000200000028000000000000000000000000000000000000000000000000000000F0480000000000000100000001000000 "SIGN.MEDIA=13A6219E Ma Logithèque\Restore Point Creator.exe"=0x5341435001000000000000000700000028000000482D0D000000000001000000000000000000000A00210000DB80FDAC2839D30100000000000000000200000028000000000000000000000000000000000000000000000000000000A1070000000000000100000001000000 "SIGN.MEDIA=13A6219E Ma Logithèque\Restore Point Creator6.8.18.0.exe"=0x53414350010000000000000007000000280000005BFF0C000000000001000000000000000000000A00210000DB80FDAC2839D30100000000000000000200000028000000000000000000000000000000000000000000000000000000F4350000000000000100000001000000 "SIGN.MEDIA=5EE5F8C Ma Logitheque Portable\ccsetup539.6399\CCleaner64.exe"=0x5341435001000000000000000700000028000000D0859C00B2109D0001000000000000000000000A00210000DB80FDAC2839D3010000000000000000020000002800000000000000000000000000000000000000000000000000000097360200000000000300000003000000 "SIGN.MEDIA=8F5599F9 Ma Logithèque\MAGIX\Vdlx2014_Premium_update_13.0.5.5.exe"=0x5341435001000000000000000700000028000000802E60066A34600601000000000000000000030600010000DB80FDAC2839D301000000000000000002000000280000000000000000000040000000000000000000000000000000005ADE0000000000000100000001000000 "C:\Program Files (x86)\MAGIX\Video deluxe 2014 Premium\videodeluxe.exe"=0x5341435001000000000000000700000028000000A8901401E3E2140101000000000000000000000A71220000631F6E6F0EDED40100000000000000000200000028000000000002062004006010000000000000000000000000000000C2925400000000003400000034000000 "SIGN.MEDIA=13A6219E Ma Logithèque\GoogleEarthProSetup7.3.1.4505.exe"=0x5341435001000000000000000700000028000000583F11002342110001000000000000000000000A00210000DB80FDAC2839D301000000000000000002000000280000000000000000000000000000000000000000000000000000001CFD0000000000000100000001000000 "SIGN.MEDIA=13A6219E Ma Logithèque\Restore Point Creator6.9.2.0.exe"=0x53414350010000000000000007000000280000002E000D000000000001000000000000000000000A00210000DB80FDAC2839D301000000000000000002000000280000000000000000000000000000000000000000000000000000007C2F0000000000000100000001000000 "SIGN.MEDIA=13A6219E Ma Logithèque\VSDC video_editor_x64.exe"=0x53414350010000000000000007000000280000004807A70288BBA70201000000000000000000000A00210000DB80FDAC2839D30100000000000000000200000028000000000000000000000000000000000000000000000000000000106A0100000000000100000001000000 "SIGN.MEDIA=13A6219E Ma Logithèque\adwcleaner_7.0.7.0.exe"=0x534143500100000000000000070000002800000020397D00063F7D0001000000000000000000000A00210000DB80FDAC2839D30100000000000000000200000028000000000000000000004000000000000000000000000000000000350C0000000000000100000001000000 "SIGN.MEDIA=13A6219E Ma Logithèque\jre-8u161-windows-x64.exe"=0x534143500100000000000000070000002800000040624004C712410401000000000000000000000A73220000DB80FDAC2839D30100000000000000000200000028000000000000000000004000000000000000000000000000000000801E0100000000000100000001000000 "SIGN.MEDIA=A13BEB09 Ma Logithèque\ICECREAM\Icecream_Slideshow_Maker_v3.15.exe"=0x5341435001000000000000000700000028000000D0723F012326400101000000000000000000000A00210000DB80FDAC2839D3010000000000000000 "SIGN.MEDIA=13A6219E Ma Logithèque\NVIDIA_GeForce_Experience_v3.12.0.84.exe"=0x534143500100000000000000070000002800000070710205E3B1020501000000000000000000020600010000DB80FDAC2839D30100000000000000000200000028000000000000000000004000000000000000000000000000000000C98D0000000000000100000001000000 "SIGN.MEDIA=13A6219E Ma Logithèque\Nero_BurnLite-10.0.10600.exe"=0x534143500100000000000000070000002800000028B1F301AF2AF40101000000000000000000010671020000DB80FDAC2839D3010000000000000000 "SIGN.MEDIA=13A6219E Ma Logithèque\calendrier1.25.370.exe"=0x534143500100000000000000070000002800000048BEDB00A7ACDC0001000000000000000000000A00210000DB80FDAC2839D30100000000000000000200000028000000000000000000000000000000000000000000000000000000B7566802000000000100000001000000 "SIGN.MEDIA=2F5C8E1B Ma Logitheque Portable\InSpectre#6B.exe"=0x534143500100000000000000070000002800000098F401004E63020001000000000000000000000A71220000DB80FDAC2839D30100000000000000000200000028000000000000000000000000000000000000000000000000000000EDA30400000000000200000002000000 "C:\Program Files (x86)\Icecream Slideshow Maker\SlideshowMaker.exe"=0x5341435001000000000000000700000028000000B8242700B4E5270001000000000000000000000A71220000DB80FDAC2839D301000000000000000002000000280000000000000000000000000000000000000000000000000000003D5E0000000000000100000001000000 "C:\Program Files\Defraggler\Defraggler64.exe"=0x5341435001000000000000000700000028000000D8C043006177440001000000000000000000000A73220000DB80FDAC2839D3010000000000000000020000002800000000000000000000400000000000000000000000000000000028D11405000000000200000002000000 "SIGN.MEDIA=27EC9917 Ma Logithèque\family_tree_builder_8453.exe"=0x534143500100000000000000070000002800000048BD0D03CB4D0E0301000000000000000000010600010000DB80FDAC2839D3010000000000000000020000002800000000000000000000400400000000000000000000000000000004230100000000000100000001000000 "SIGN.MEDIA=27EC9917 Ma Logithèque\JavaSetup8u161.exe"=0x534143500100000000000000070000002800000040681C00794D1D0001000000000000000000000A71220000DB80FDAC2839D30100000000000000000200000028000000000000000000004000000000000000000000000000000000B2D70000000000000100000001000000 "SIGN.MEDIA=27EC9917 Ma Logithèque\NVIDIA391.01-desktop-win10-64bit-international-whql.exe"=0x53414350010000000000000007000000280000006015191B6C5B191B01000000000000000000020600010000DB80FDAC2839D30100000000000000000200000028000000000000000000004000100000000000000000000000000000A21E0700000000000100000001000000 "SIGN.MEDIA=5DBD0 Ma Logitheque Portable\guportable5.93.0.115\Integrator_Portable5.93.0.115.exe"=0x5341435001000000000000000700000028000000D0DB050061EA050001000000000000000000000A71220000DB80FDAC2839D3010000000000000000020000002800000000000000000000400000000000000000000000000000000007040000000000000300000003000000 "SIGN.MEDIA=27EC9917 Ma Logithèque clé\SkypeSetupFull7.40.0.151.exe"=0x5341435001000000000000000700000028000000C87F810303EA810301000000000000000000000A00210000DB80FDAC2839D301000000000000000002000000280000000000000000000040000000000000000000000000000000007C6B0000000000000100000001000000 "SIGN.MEDIA=6AE93A9 0-A transférer sur PC TOUR Bollywood\MolotovSetup-2.1.2.exe"=0x5341435001000000000000000700000028000000780AA103E07FA10301000000000000000000030600010000DB80FDAC2839D30100000000000000000200000028000000000000000000000000000000000000000000000000000000737C0000000000000100000001000000 "SIGN.MEDIA=415C489 0-A transférer sur PC TOUR Bollywood\Glary_Utilities_v5.93.0.115.exe"=0x5341435001000000000000000700000028000000904A0501F1F2050101000000000000000000010600010000DB80FDAC2839D301000000000000000002000000280000000000000000000040000000000000000000000000000000007A320000000000000100000001000000 "E:\Mes documents\Ma LOGITHEQUE portable Bollywood\pointofix180de-20171120-direkt\Pointofix.exe"=0x534143500100000000000000070000002800000000A82E000000000001000000000000000000000A7122000067077CBAC54CD40100000000000000000200000028000000000000000000000000000000000000000000000000000000CB93B802000000000800000008000000 "SIGN.MEDIA=27EC9917 Ma Logithèque clé\persoappsadresses1.25.1187.exe"=0x53414350010000000000000007000000280000007089EE00EF61EF0001000000000000000000000A00210000DB80FDAC2839D3010000000000000000 "SIGN.MEDIA=27EC9917 Ma Logithèque clé\calendrier1.25.370.exe"=0x534143500100000000000000070000002800000048BEDB00A7ACDC0001000000000000000000000A00210000DB80FDAC2839D30100000000000000000200000028000000000000000000000000000000000000000000000000000000D3AF0100000000000100000001000000 "SIGN.MEDIA=27EC9917 Ma Logithèque clé\VSDC_video_editor_x64_5.8.7.826.exe"=0x5341435001000000000000000700000028000000103FC20280CFC20201000000000000000000000A00210000DB80FDAC2839D301000000000000000002000000280000000000000000000000000000000000000000000000000000007F5A0100000000000100000001000000 "SIGN.MEDIA=3C5F7540 Ma Logithèque clé\391.24-desktop-win10-64bit-international-whql.exe"=0x534143500100000000000000070000002800000040EFB31B6549B41B01000000000000000000020600010000DB80FDAC2839D301000000000000000002000000280000000000000000000040001000000000000000000000000000008B2E0800000000000100000001000000 "SIGN.MEDIA=3C5F7540 Ma Logithèque clé\Shockwave_Installer_Full (1).exe"=0x53414350010000000000000007000000280000003832E6007813E70001000000000000000000000A00210000DB80FDAC2839D3010000000000000000020000002800000000000000000000400000000000000000000000000000000066230000000000000100000001000000 "SIGN.MEDIA=3C5F7540 Ma Logithèque clé\Intel Driver and Support Assistant Installer3.2.0.9.exe"=0x5341435001000000000000000700000028000000C8DDD300077BD40001000000000000000000000A00210000DB80FDAC2839D3010000000000000000 "SIGN.MEDIA=3C5F7540 Ma Logithèque clé\Shockwave_Installer_Full.exe"=0x53414350010000000000000007000000280000003832E6007813E70001000000000000000000000A00210000DB80FDAC2839D30100000000000000000200000028000000000000000000004000000000000000000000000000000000B5280000000000000100000001000000 "SIGN.MEDIA=9A913BD8 0-A transférer sur PC TOUR Bollywood\VSDC_video_editor_x64_5.8.7.828.exe"=0x53414350010000000000000007000000280000004077C2023865C30201000000000000000000000A00210000DB80FDAC2839D3010000000000000000 "SIGN.MEDIA=9A913BD8 0-A transférer sur PC TOUR Bollywood\FreemakeVideoConverterFull4.1.10.66.exe"=0x534143500100000000000000070000002800000078DB28029D55290201000000000000000000020600010000DB80FDAC2839D3010000000000000000 "SIGN.MEDIA=3C5F7540 Ma Logithèque clé\maj_persoappscalendrier1.2.5.372.exe"=0x53414350010000000000000007000000280000005038DC004941DC0001000000000000000000000A00210000DB80FDAC2839D3010000000000000000 "SIGN.MEDIA=3C5F7540 Ma Logithèque clé\SUPERAntiSpyware6.0.0.1258.exe"=0x53414350010000000000000007000000280000000094EE01986FEF0101000000000000000000020600010000DB80FDAC2839D301000000000000000002000000280000000000000000000000000000000000000000000000000000008A06C602000000000100000001000000 "SIGN.MEDIA=E3DC072B 0-A transférer sur PC TOUR Bollywood\FreemakeVideoConverterFull4.1.10.67.exe"=0x534143500100000000000000070000002800000000CE2802A54B290201000000000000000000020600010000DB80FDAC2839D30100000000000000000200000028000000000000000000000000100000000000000000000000000000899AE102000000000100000001000000 "SIGN.MEDIA=ED1DCF2D 0-A transférer sur PC TOUR Bollywood\FreeStudio_6.6.40.222_o.exe"=0x5341435001000000000000000700000028000000F08E930352D8930301000000000000000000000A00210000DB80FDAC2839D30100000000000000000200000028000000000000000000000000000000000000000000000000000000D5420000000000000100000001000000 "SIGN.MEDIA=102D4C6C 0-A transférer sur PC TOUR Bollywood\MP4Tools-3.6.1-win32.exe"=0x5341435001000000000000000700000028000000D0DF3D010000000001000000000000000000000A00210000DB80FDAC2839D3010000000000000000020000002800000000000000000000000000000000000000000000000000000019710000000000000100000001000000 "SIGN.MEDIA=3C5F7540 Ma Logithèque clé\391.35-desktop-win10-64bit-international-whql.exe"=0x5341435001000000000000000700000028000000A043D61BDA4BD61B01000000000000000000020600010000DB80FDAC2839D3010000000000000000020000002800000000000000000000400010000000000000000000000000000005790400000000000100000001000000 "SIGN.MEDIA=3C5F7540 Ma Logithèque clé\Shockwave_Installer_Full_12.3.2.202.exe"=0x53414350010000000000000007000000280000003832E6007813E70001000000000000000000000A00210000DB80FDAC2839D30100000000000000000200000028000000000000000000004000000000000000000000000000000000D0210000000000000100000001000000 "SIGN.MEDIA=2C2708 Ma Logithèque clé\PILOTES\SetupRST15.9.0.1015.exe"=0x5341435001000000000000000700000028000000480A2701D7B5270101000000000000000000000A00210000DB80FDAC2839D30100000000000000000200000028000000000000000000004000000000000000000000000000000000093D0000000000000100000001000000 "C:\Program Files (x86)\MP4Tools\bin\MP4Joiner.exe"=0x53414350010000000000000007000000280000000EC46000C14A610001000000000000000000000A61200000BFA2139DEDD1D30100000000000000000200000028000000000000000000000000000000000000000000000000000000CD6D7B02000000000D0000000D000000 "SIGN.MEDIA=3A08F3D9 0-A transférer sur PC TOUR Bollywood\NVIDIA_GeForce_Experience_v3.13.1.30.exe"=0x5341435001000000000000000700000028000000C0B46D056A276E0501000000000000000000020600010000DB80FDAC2839D3010000000000000000020000002800000000000000000000400000000000000000000000000000000047930000000000000100000001000000 "SIGN.MEDIA=16442E8 0-A transférer sur PC TOUR Bollywood\persoappscalendrier.exe"=0x5341435001000000000000000700000028000000583EDC00C990DC0001000000000000000000000A00210000DB80FDAC2839D30100000000000000000200000028000000000000000000000000000000000000000000000000000000E1267D00000000000200000002000000 "SIGN.MEDIA=1261448 0-A transférer sur PC TOUR Bollywood\SetupRST.exe"=0x5341435001000000000000000700000028000000481426012C42260101000000000000000000000A00210000DB80FDAC2839D301000000000000000002000000280000000000000000000040000000000000000000000000000000008F240000000000000100000001000000 "SIGN.MEDIA=F60F7CAD 0-A transférer sur PC TOUR Bollywood\calendrier1.26.375.exe"=0x5341435001000000000000000700000028000000583EDC00C990DC0001000000000000000000000A00210000DB80FDAC2839D3010000000000000000020000002800000000000000000000000000000000000000000000000000000045622E00000000000100000001000000 "C:\Program Files (x86)\Microsoft Office\Office12\WINWORD.EXE"=0x5341435001000000000000000700000028000000C06406006E16070001000000000000000000000A71220000631F6E6F0EDED4010000000100000000 "C:\Program Files (x86)\Microsoft Office\Office12\EXCEL.EXE"=0x5341435001000000000000000700000028000000C874180156D2180101000000000000000000000A71220000631F6E6F0EDED4010000000100000000 "SIGN.MEDIA=1717D990 0-A transférer sur PC TOUR Bollywood\FoxitReader91_L10N_Setup_Prom.exe"=0x53414350010000000000000007000000280000006086E0046124E10401000000000000000000000A00210000DB80FDAC2839D30100000000000000000200000028000000000000000000000000000000000000000000000000000000D41F0500000000000100000001000000 "SIGN.MEDIA=173AA20 Ma Logithèque clé\INTEL\Intel Driver and Support Assistant Installer3.3.0.4.exe"=0x5341435001000000000000000700000028000000B011D400FED7D40001000000000000000000000A00210000DB80FDAC2839D3010000000000000000 "SIGN.MEDIA=8B083A 0-A transférer sur PC TOUR Bollywood\PersoAppscalendrier1.26.377.exe"=0x53414350010000000000000007000000280000002041DC00BFCADC0001000000000000000000000A00210000DB80FDAC2839D3010000000000000000 "SIGN.MEDIA=3C5F7540 Ma Logithèque clé\SetupRST16.0.2.1086.exe"=0x5341435001000000000000000700000028000000381821011A79210101000000000000000000000A00210000DB80FDAC2839D3010000000000000000050000001000000000000000000000000000000000000000020000002800000000000000000000400000000000000000000000000000000061310000000000000100000001000000 "SIGN.MEDIA=CDCBE6BD 0-A transférer sur PC TOUR Bollywood\AOMEIPAssist_Std7.0.0.exe"=0x5341435001000000000000000700000028000000D826A8002410A90001000000000000000000010600010000DB80FDAC2839D3010000000000000000050000001000000000000000000000000000000000000000020000002800000000000000000000400000000000000000000000000000000067530500000000000500000005000000 "SIGN.MEDIA=6E51DC 0-A transférer sur PC TOUR Bollywood\Audio_Realtek_6.0.1.8083_W10x64_A\Audio_Realtek_6.0.1.8083_W10x64\Setup.exe"=0x5341435001000000000000000700000028000000E03B120024DF120001000000000000000000030600010000DB80FDAC2839D301000000000000000002000000280000000000000000000040000000000000000000000000000000007FD00000000000000100000001000000 "SIGN.MEDIA=2C25420 0-A transférer sur PC TOUR Bollywood\IperiusBackup.exe"=0x53414350010000000000000007000000280000002054C2020372C20201000000000000000000000A00210000DB80FDAC2839D30100000000000000000200000028000000000000000000000000000000000000000000000000000000CD340300000000000200000002000000 "SIGN.MEDIA=1353D110 0-A transférer sur PC TOUR Bollywood\VSDCvideo_editor_x64_5.8.7.832.exe"=0x53414350010000000000000007000000280000001867C20280FBC20201000000000000000000000A00210000DB80FDAC2839D3010000000000000000 "C:\Users\EVRARD\AppData\Roaming\ZHP\ZHPDiag3.exe"=0x534143500100000000000000070000002800000080192F009EF52F0001000000000000000000000A00210000DB80FDAC2839D30100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000004000000000000000000000000000000000971B0000000000000100000001000000 "SIGN.MEDIA=3C5F7540 Ma Logithèque clé\advisor(pour analyser la config du PC).exe"=0x5341435001000000000000000700000028000000F0D70C0071210D0001000000000000000000010571000000DB80FDAC2839D301000000000000000002000000280000000000000000080040000000000000000000000000000000002F9F2400000000000100000001000000 "SIGN.MEDIA=3C5F7540 Ma Logithèque clé\ALLPlayerEN_5.6.exe"=0x5341435001000000000000000700000028000000BF809C020000000001000000000000000000020600210000DB80FDAC2839D30100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000000000000000000000000000000000000000391B0000000000000100000001000000 "SIGN.MEDIA=3C5F7540 Ma Logithèque clé\AppManagerSetup_1.47(installé20150207POR).exe"=0x5341435001000000000000000700000028000000C8F50C00053E0D0001000000000000000000010600010000DB80FDAC2839D301000000000000000005000000100000000000000000000000000000000000000002000000280000000000000000000040000000000000000000000000000000007F0A0000000000000100000001000000 "SIGN.MEDIA=3C5F7540 Ma Logithèque clé\avast-browser-cleanup9.0.0.224.exe"=0x534143500100000000000000070000002800000030112D009C3A2D0001000000000000000000010671020000DB80FDAC2839D30100000000000000000200000028000000000000000000000002000000000000000000000000000000A8AA0000000000000100000001000000 "SIGN.MEDIA=3C5F7540 Ma Logithèque clé\avast-browser-cleanup_12-1-2272-125_fr_432201.exe"=0x5341435001000000000000000700000028000000D861410049E0410001000000000000000000010671020000DB80FDAC2839D301000000000000000002000000280000000000000000000000000000000000000000000000000000006B8D0000000000000100000001000000 "SIGN.MEDIA=E3914 MANUAL\ViewUserGuide.exe"=0x534143500100000000000000070000002800000040390E004F160F0001000000000000000000000A00210000DB80FDAC2839D30100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000004000000000000000000000000000000000272B0000000000000100000001000000 "SIGN.MEDIA=2C08E4 setup.exe"=0x5341435001000000000000000700000028000000C8471B007CAF1B0001000000000000000000010600010000DB80FDAC2839D3010000000000000000 "C:\Program Files (x86)\Samsung\Easy Printer Manager\EPM2DotNetHandler.exe"=0x5341435001000000000000000700000028000000286D140079B5140001000000000000000000000A71220000DB80FDAC2839D3010000000000000000020000002800000000000000000000000000000000000000000000000000000071D70400000000000200000002000000 "C:\Program Files (x86)\Samsung\Easy Printer Manager\EPM2Migrator.exe"=0x5341435001000000000000000700000028000000282B010071CC010001000000000000000000000A71220000DB80FDAC2839D30100000000000000000200000028000000000000000000000000000000000000000000000000000000EA000000000000000100000001000000 "C:\Program Files (x86)\Samsung Printers\SetIP\SetIp.exe"=0x5341435001000000000000000700000028000000686A5E00464E5F0001000000000000000000020671020000DB80FDAC2839D30100000000000000000200000028000000000000000000000000000000000000000000000000000000E8470300000000000300000003000000 "C:\Program Files (x86)\Samsung\Easy Printer Manager\EasyPrinterManagerV2.exe"=0x53414350010000000000000007000000280000002811350033F9350001000000000000000000000A7120000067077CBAC54CD40100000000000000000200000028000000000000000000000000000000000000000000000000000000E84C8A00000000000F0000000F000000 "C:\Program Files (x86)\Samsung\View User Guide\ViewUserGuide.exe"=0x5341435001000000000000000700000028000000C8070E00B6780E0001000000000000000000010600010000DB80FDAC2839D30100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000004000020200000000000000000000000000DB0D0000000000000200000002000000 "SIGN.MEDIA=5F9D459C Ma Logithèque clé\FreemakeVideoConverterFull4.1.10.80.exe"=0x5341435001000000000000000700000028000000D8013102F8AE310201000000000000000000020600010000DB80FDAC2839D3010000000000000000 "SIGN.MEDIA=5F9D459C Ma Logithèque clé\maj_persoappsadresses1.26.exe"=0x5341435001000000000000000700000028000000F093EE00CAE3EE0001000000000000000000000A00210000DB80FDAC2839D301000000000000000002000000280000000000000000000000000000000000000000000000000000004AFB0300000000000100000001000000 "SIGN.MEDIA=5F9D459C Ma Logithèque clé\Shockwave_Installer_Full12.3.2.202.exe"=0x53414350010000000000000007000000280000003832E6007813E70001000000000000000000000A00210000DB80FDAC2839D30100000000000000000200000028000000000000000000004000000000000000000000000000000000942B0000000000000100000001000000 "SIGN.MEDIA=2219443E Ma Logithèque clé\397.64-desktop-win10-64bit-international-whql.exe"=0x5341435001000000000000000700000028000000189E971D3D23981D01000000000000000000020600010000DB80FDAC2839D3010000000000000000020000002800000000000000000000400000000000000000000000000000000035C00300000000000100000001000000 "SIGN.MEDIA=11C52F3A 0-A transférer sur PC TOUR Bollywood\freemake-video-converter_4-1-10-80_fr_341646.exe"=0x5341435001000000000000000700000028000000D8013102F8AE310201000000000000000000020600010000DB80FDAC2839D3010000000000000000 "E:\Mes documents\Ma LOGITHEQUE portable Bollywood\KeePass-2.39.1\KeePass.exe"=0x534143500100000000000000070000002800000050AE310017D0310001000000000000000000000A75220000631F6E6F0EDED40100000000000000000200000028000000000000000000000004000000000000000000000000000000E880FF14000000001301000013010000 "SIGN.MEDIA=670DB6 0-A transférer sur PC TOUR Bollywood\Thunderbird Setup 52.8.0_fr.exe"=0x534143500100000000000000070000002800000050DE6C02FDF76C0201000000000000000000000A00210000DB80FDAC2839D30100000000000000000200000028000000000000000000000000000000000000000000000000000000207C0100000000000100000001000000 "SIGN.MEDIA=670DB6 0-A transférer sur PC TOUR Bollywood\speccysetup132.740.exe"=0x5341435001000000000000000700000028000000E01E69006B74690001000000000000000000010600010000DB80FDAC2839D301000000000000000002000000280000000000000000000040000000000000000000000000000000008CAC0000000000000100000001000000 "SIGN.MEDIA=8B60A45 SAUVEGARDE PERSO\SanDiskSecureAccessV3_win.exe"=0x534143500100000000000000070000002800000028378300345E830001000000000000000000000A71220000DB80FDAC2839D301000000000000000002000000280000000000000000000000000000000000000000000000000000005B3F0000000000000100000001000000 "SIGN.MEDIA=2219443E Ma Logithèque clé\defragglersetup222.995.exe"=0x534143500100000000000000070000002800000000B861009B19620001000000000000000000010600010000DB80FDAC2839D30100000000000000000200000028000000000000000000004000000000000000000000000000000000F5360200000000000100000001000000 "SIGN.MEDIA=2219443E Ma Logithèque clé\ccsetup543.6520.exe"=0x5341435001000000000000000700000028000000B878F100171BF20001000000000000000000000A00210000DB80FDAC2839D301000000000000000002000000280000000000000000000040000000000000000000000000000000001F351600000000000100000001000000 "C:\Program Files (x86)\Icecream PDF Split and Merge\pdftool.exe"=0x5341435001000000000000000700000028000000B85A1A0051E41A0001000000000000000000000A7122000067077CBAC54CD4010000000000000000020000002800000000000000000000000000000000000000000000000000000056030B00000000000300000003000000 "SIGN.MEDIA=2219443E Ma Logithèque clé\family_tree_builder_8.0.0.8457.exe"=0x534143500100000000000000070000002800000070950E03F2A80E0301000000000000000000010600010000BFA2139DEDD1D3010000000000000000020000002800000000000000000000400000000000000000000000000000000007900100000000000100000001000000 "SIGN.MEDIA=875EE61F Ma Logitheque Portable clé\rufus-3.0.1304portable.exe"=0x534143500100000000000000070000002800000038860F00A271100001000000000000000000000A00210000BFA2139DEDD1D3010000000000000000050000001000000000000000000000000000000000000000020000002800000000000000000000400000000000000000000000000000000084400000000000000100000001000000 "SIGN.MEDIA=1459DE0 0-A transférer sur PC Portable\install_flash_player.exe"=0x5341435001000000000000000700000028000000E09D4501F412460101000000000000000000000A00210000BFA2139DEDD1D3010000000000000000020000002800000000000000000000400000000000000000000000000000000045400000000000000100000001000000 "SIGN.MEDIA=27D8A0 0-A transférer sur PC Portable\AdobeAIRInstaller.exe"=0x5341435001000000000000000700000028000000A022B100D713B20001000000000000000000000A71220000BFA2139DEDD1D3010000000000000000020000002800000000000000000000000000000000000000000000000000000084400000000000000100000001000000 "SIGN.MEDIA=1EBEE158 0-A transférer sur PC Portable\398.11-desktop-win10-64bit-international-whql.exe"=0x534143500100000000000000070000002800000058E1BE1E3005BF1E01000000000000000000020600010000BFA2139DEDD1D301000000000000000002000000280000000000000000000040000000000000000000000000000000005DFD0300000000000100000001000000 "SIGN.MEDIA=2219443E Ma Logithèque clé\Skype-8.23.0.10.exe"=0x5341435001000000000000000700000028000000C8B2C4036AB8C40301000000000000000000000A00210000BFA2139DEDD1D3010000000000000000050000001000000000000000000000000000000000000000020000002800000000000000000000000000000000000000000000000000000050240000000000000100000001000000 "SIGN.MEDIA=2219443E Ma Logithèque clé\ccsetup543.6522.exe"=0x534143500100000000000000070000002800000078AEF10053F8F10001000000000000000000000A00210000BFA2139DEDD1D3010000000000000000 "SIGN.MEDIA=2219443E Ma Logithèque clé\Iperiusbackupfree5.7.0.0..exe"=0x53414350010000000000000007000000280000007064E3021394E30201000000000000000000000A00210000BFA2139DEDD1D30100000000000000000200000028000000000000000000000000000000000000000000000000000000CEC84901000000000100000001000000 "SIGN.MEDIA=EEBACE78 0-A transférer sur PC TOUR Bollywood\GoogleEarthProSetup7.3.2.5481.exe"=0x5341435001000000000000000700000028000000583F11002342110001000000000000000000000A00210000BFA2139DEDD1D30100000000000000000200000028000000000000000000000000000000000000000000000000000000761D0100000000000100000001000000 "SIGN.MEDIA=DD1604C7 0-A transférer sur PC TOUR Bollywood\ccsetup543.151.6522.exe"=0x534143500100000000000000070000002800000078AEF10053F8F10001000000000000000000000A00210000BFA2139DEDD1D3010000000000000000 "SIGN.MEDIA=2219443E Ma Logithèque clé\family_tree_builder_8463.exe"=0x534143500100000000000000070000002800000040410D0365110E0301000000000000000000010600010000BFA2139DEDD1D3010000000000000000020000002800000000000000000000400000000000000000000000000000000076730100000000000100000001000000 "SIGN.MEDIA=2219443E Ma Logithèque clé\Skype-8.24.0.2.exe"=0x5341435001000000000000000700000028000000001FCA03FC2BCA0301000000000000000000000A00210000BFA2139DEDD1D3010000000000000000 "SIGN.MEDIA=2219443E Ma Logithèque clé\VSDC_video_editor_x64_5.8.9.858.exe"=0x53414350010000000000000007000000280000009095E8027182E90201000000000000000000000A00210000BFA2139DEDD1D301000000000000000002000000280000000000000000000000000000000000000000000000000000005F0C0100000000000100000001000000 "SIGN.MEDIA=1B7172DB 0-A transférer sur PC TOUR Bollywood\ccsetup544.exe"=0x5341435001000000000000000700000028000000A8F9F30034F1F40001000000000000000000000A00210000BFA2139DEDD1D3010000000000000000 "SIGN.MEDIA=1B7172DB 0-A transférer sur PC TOUR Bollywood\AOMEIPAssist_Std7.0.exe"=0x5341435001000000000000000700000028000000131AA8000000000001000000000000000000010600010000BFA2139DEDD1D30100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000004000020000000000000000000000000000A0720000000000000100000001000000 "SIGN.MEDIA=3004FDB4 0-A transférer sur PC TOUR Bollywood\winrar-x64-560fr.exe"=0x5341435001000000000000000700000028000000D0F63100853D320001000000000000000000000A00210000BFA2139DEDD1D301000000000000000002000000280000000000000000000040000000000000000000000000000000009C1A0000000000000100000001000000 "SIGN.MEDIA=D6372D0 0-A transférer sur PC TOUR Bollywood\maj_persoappsadresses.exe"=0x5341435001000000000000000700000028000000F093EE00CAE3EE0001000000000000000000000A00210000BFA2139DEDD1D3010000000000000000 "SIGN.MEDIA=2219443E Ma Logithèque clé\MolotovSetup-2.2.2.exe"=0x534143500100000000000000070000002800000090A2A1036ACDA10301000000000000000000030600010000BFA2139DEDD1D30100000000000000000200000028000000000000000000000000000000000000000000000000000000B85E9F01000000000100000001000000 "SIGN.MEDIA=1E1E7DB 0-A transférer sur PC TOUR Bollywood\FoxitReader92_L10N_Setup_Prom.exe"=0x534143500100000000000000070000002800000028058F057F358F0501000000000000000000000A00210000BFA2139DEDD1D30100000000000000000200000028000000000000000000000000000000000000000000000000000000B48D0100000000000100000001000000 "SIGN.MEDIA=46950358 0-A transférer sur PC TOUR Bollywood\Iperiusbackupfree5.7.1.exe"=0x53414350010000000000000007000000280000009051E2020ACFE20201000000000000000000000A00210000BFA2139DEDD1D30100000000000000000200000028000000000000000000000000000000000000000000000000000000D2592601000000000100000001000000 "SIGN.MEDIA=5C635FD3 0-A transférer sur PC TOUR Bollywood\FreemakeVideoConverterSetup4.1.10.88.exe"=0x5341435001000000000000000700000028000000A86C0F00568A0F0001000000000000000000020600010000BFA2139DEDD1D3010000000000000000 "E:\Mes documents\Ma LOGITHEQUE portable Bollywood\Restore Point Creator7.1.2\Restore Point Creator.exe"=0x534143500100000000000000070000002800000000C811000000000001000000000000000000000A00210000631F6E6F0EDED4010000000000000000050000001000000000000000000000000000000000000000020000002800000000000000000000000000000000000000000000000000000053D40100000000000A0000000A000000 "SIGN.MEDIA=2219443E Ma Logithèque clé\FreeStudio_6.6.42.703_d.exe"=0x5341435001000000000000000700000028000000F81AA703D323A70301000000000000000000000A00210000BFA2139DEDD1D30100000000000000000200000028000000000000000000000000000000000000000000000000000000AB230901000000000100000001000000 "SIGN.MEDIA=90539FB4 0-A transférer sur PC TOUR Bollywood\msert1.0.3001.0_x64.exe"=0x5341435001000000000000000700000028000000F0B83909C7FA390901000000000000000000010600010000BFA2139DEDD1D30100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000000000000000000000000000000000000000F85E0000000000000100000001000000 "SIGN.MEDIA=2219443E Ma Logithèque clé\Skype-8.25.0.5 _fr.exe"=0x534143500100000000000000070000002800000008277203F867720301000000000000000000000A00210000BFA2139DEDD1D301000000000000000002000000280000000000000000000000000000000000000000000000000000005F111500000000000100000001000000 "SIGN.MEDIA=2219443E Ma Logithèque clé\FreemakeVideoConverterFull4.1.10.89.exe"=0x5341435001000000000000000700000028000000B00F3B02205F3B0201000000000000000000020600010000BFA2139DEDD1D30100000000000000000200000028000000000000000000000000000000000000000000000000000000E47E1B01000000000100000001000000 "SIGN.MEDIA=2219443E Ma Logithèque clé\adwcleaner_7.2.1.exe"=0x5341435001000000000000000700000028000000D0D87000CA18710001000000000000000000000A00210000BFA2139DEDD1D3010000000000000000050000001000000000000000000000000000000000000000020000002800000000000000000000400000000000000000000000000000000010270000000000000100000001000000 "SIGN.MEDIA=C7011508 Ma Logithèque clé\ICECREAM\Icecream_Slideshow_Maker_v3.33.exe"=0x5341435001000000000000000700000028000000203240016F9B400101000000000000000000000A00210000BFA2139DEDD1D301000000000000000002000000280000000000000000000000000000000000000000000000000000000E8C0100000000000100000001000000 "SIGN.MEDIA=CEDA407B 0-A transférer sur PC TOUR Bollywood\FreemakeVideoConverterSetup4.1.10.93.exe"=0x5341435001000000000000000700000028000000C86C0F00E96D0F0001000000000000000000020600010000BFA2139DEDD1D3010000000000000000 "C:\Program Files (x86)\obs-studio\bin\32bit\obs32.exe"=0x5341435001000000000000000700000028000000C0A12200F0E7220001000000000000000000000A71220000BFA2139DEDD1D30100000000000000000200000028000000000000000000000000000000000000000000000000000000DA150000000000000200000002000000 "E:\Mes documents\Ma LOGITHEQUE portable Bollywood\startupsentinel1.7.4.22\sus\SuS.exe"=0x5341435001000000000000000700000028000000C04819005D8F190001000000000000000000000A61200000BFA2139DEDD1D301000000000000000002000000280000000000000000000000000000000000000000000000000000008D420200000000000100000001000000 "SIGN.MEDIA=2219443E Ma Logithèque clé\Iperiusbackup5.7.3.exe"=0x5341435001000000000000000700000028000000A0D6E202343DE30201000000000000000000000A00210000BFA2139DEDD1D30100000000000000000200000028000000000000000000000000000000000000000000000000000000E2D70000000000000100000001000000 "SIGN.MEDIA=2219443E Ma Logithèque clé\ccsetup546.6652.exe"=0x5341435001000000000000000700000028000000A05300011A31010101000000000000000000000A00210000BFA2139DEDD1D30100000000000000000200000028000000000000000000004000000000000000000000000000000000B2B68001000000000100000001000000 "SIGN.MEDIA=BB6BB5D2 0-A transférer sur PC TOUR Bollywood\iobituninstaller8free.exe"=0x5341435001000000000000000700000028000000D096DF009674E00001000000000000000000000A00210000BFA2139DEDD1D3010000000000000000020000002800000000000000000000000000000000000000000000000000000062570100000000000100000001000000 "E:\Mes documents\Ma LOGITHEQUE portable Bollywood\iCopy1.6.5\iCopy.exe"=0x5341435001000000000000000700000028000000003E06000000000001000000000000000000000A71220000631F6E6F0EDED40100000000000000000200000028000000000000000000000000000000000000000000000000000000D64B0F00000000000C0000000C000000 "SIGN.MEDIA=2219443E Ma Logithèque clé\iobituninstaller8.0.2.29.exe"=0x53414350010000000000000007000000280000009027F3008C6FF30001000000000000000000000A00210000BFA2139DEDD1D301000000000000000002000000280000000000000000000000000000000000000000000000000000001CFF0100000000000100000001000000 "SIGN.MEDIA=D7319088 Ma Logithèque clé\ICECREAM\Icecream_Slideshow_Maker_v3.41.exe"=0x534143500100000000000000070000002800000040154C01E2954C0101000000000000000000000A00210000BFA2139DEDD1D301000000000000000002000000280000000000000000000000000000000000000000000000000000009BC10000000000000100000001000000 "SIGN.MEDIA=D2A4324B Ma Logithèque clé\PILOTES\399.24-desktop-win10-64bit-international-whql.exe"=0x5341435001000000000000000700000028000000A01F171F6ABA171F01000000000000000000020600010000BFA2139DEDD1D301000000000000000002000000280000000000000000000040000000000000000000000000000000007C000A00000000000100000001000000 "SIGN.MEDIA=2219443E Ma Logithèque clé\FreemakeVideoConverterSetup4.1.10.101.exe"=0x5341435001000000000000000700000028000000A86C0F00E7CA0F0001000000000000000000020600010000BFA2139DEDD1D3010000000000000000 "SIGN.MEDIA=2219443E Ma Logithèque clé\mb3-setup-consumer-3.6.1.2711-1.0.463-1.0.6913.exe"=0x5341435001000000000000000700000028000000F80AC504F0EDC50401000000000000000000000A00210000BFA2139DEDD1D30100000000000000000200000028000000000000000000000000000000000000000000000000000000AD330100000000000100000001000000 "SIGN.MEDIA=2219443E Ma Logithèque clé\Iperiusbackup5.7.4.exe"=0x534143500100000000000000070000002800000078D8E2027659E30201000000000000000000000A00210000BFA2139DEDD1D301000000000000000002000000280000000000000000000000000000000000000000000000000000009120EB00000000000100000001000000 "SIGN.MEDIA=2DA9025B Ma Logithèque clé\PILOTES\411.70-desktop-win10-64bit-international-whql.exe"=0x5341435001000000000000000700000028000000E0918520A0A5852001000000000000000000020600010000BFA2139DEDD1D3010000000000000000020000002800000000000000000000400000000000000000000000000000000048EC0900000000000100000001000000 "SIGN.MEDIA=2219443E Ma Logithèque clé\FreemakeVideoConverterSetup4.1.10.106.exe"=0x5341435001000000000000000700000028000000C06C0F00AB770F0001000000000000000000020600010000BFA2139DEDD1D3010000000000000000 "E:\Mes documents\Ma LOGITHEQUE portable Bollywood\Everything-1.4.1.895.x64\Everything.exe"=0x534143500100000000000000070000002800000068902100A76A220001000000000000000000000A73220000BFA2139DEDD1D30100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000000000000000000000000000000000000000CE260400000000000400000004000000 "SIGN.MEDIA=2219443E Ma Logithèque clé\winrar-x64-561.exe"=0x5341435001000000000000000700000028000000F8AC30002849310001000000000000000000000A00210000BFA2139DEDD1D30100000000000000000200000028000000000000000000004000000000000000000000000000000000BD2C0000000000000100000001000000 "SIGN.MEDIA=76399044 0-A transférer sur PC TOUR Bollywood\416.16-desktop-win10-64bit-international-whql.exe"=0x5341435001000000000000000700000028000000C8FD702027A7712001000000000000000000020600010000BFA2139DEDD1D301000000000000000002000000280000000000000000000040000000000000000000000000000000001D8F0400000000000100000001000000 "E:\Mes documents\Ma LOGITHEQUE portable Bollywood\SendToEditor1.1\SendToEditor\SendToEditor_x64.exe"=0x5341435001000000000000000700000028000000F0980E00B96C0F0001000000000000000000010600010000631F6E6F0EDED40100000000000000000200000028000000000000000000004000100000000000000000000000000000E2480300000000000500000005000000 "SIGN.MEDIA=2219443E Ma Logithèque clé\Iperius5.8.0.exe"=0x534143500100000000000000070000002800000098A2F6023612F70201000000000000000000000A00210000BFA2139DEDD1D30100000000000000000200000028000000000000000000000000000000000000000000000000000000C62D5900000000000100000001000000 "SIGN.MEDIA=2219443E Ma Logithèque clé\Persoappscalendrier1.27.378.exe"=0x53414350010000000000000007000000280000001055E000BD2FE10001000000000000000000000A00210000BFA2139DEDD1D301000000000000000002000000280000000000000000000000000000000000000000000000000000009FEA0000000000000100000001000000 "SIGN.MEDIA=4E27A08F 0-A transférer sur PC TOUR Bollywood\FreemakeVideoConverterSetup4.1.10.109.exe"=0x5341435001000000000000000700000028000000B06C0F00C9D00F0001000000000000000000020600010000BFA2139DEDD1D301000000000000000002000000280000000000000000000000000000000000000000000000000000000EE91600000000000100000001000000 "SIGN.MEDIA=2219443E Ma Logithèque clé\Skype-8.32.0.53.exe"=0x5341435001000000000000000700000028000000B8C4BB03110ABC0301000000000000000000000A00210000BFA2139DEDD1D30100000000000000000200000028000000000000000000000000000000000000000000000000000000F9C20200000000000100000001000000 "SIGN.MEDIA=2219443E Ma Logithèque clé\iobituninstaller8.1.0.12.exe"=0x5341435001000000000000000700000028000000E8CFFE00C987FF0001000000000000000000000A00210000BFA2139DEDD1D3010000000000000000020000002800000000000000000000000000000000000000000000000000000050F40400000000000100000001000000 "E:\Mes documents\Ma LOGITHEQUE portable Bollywood\ZHPCleaner.exe"=0x5341435001000000000000000700000028000000801332000ECE320001000000000000000000000A00210000BFA2139DEDD1D3010000000000000000050000001000000000000000000000000000000000000000020000002800000000000000000000400000000000000000000000000000000016190A00000000000100000001000000 "SIGN.MEDIA=2219443E Ma Logithèque clé\iobituninstaller8.1.0.13.exe"=0x534143500100000000000000070000002800000090D4FE00DFECFE0001000000000000000000000A00210000BFA2139DEDD1D30100000000000000000200000028000000000000000000000000000000000000000000000000000000FEAD0100000000000100000001000000 "SIGN.MEDIA=2219443E Ma Logithèque clé\Persoappscalendrier1.28.380.exe"=0x53414350010000000000000007000000280000007016E1001F72E10001000000000000000000000A00210000BFA2139DEDD1D3010000000000000000020000002800000000000000000000000000000000000000000000000000000081D40100000000000100000001000000 "SIGN.MEDIA=1EA07954 Ma Logitheque Portable clé\sumo5.8.4.406\sumo\SUMo.exe"=0x5341435001000000000000000700000028000000C09E1F00A83C200001000000000000000000000A61200000BFA2139DEDD1D3010000000000000000 "SIGN.MEDIA=2219443E Ma Logithèque clé\FreemakeVideoConverterSetup4.1.10.110.exe"=0x5341435001000000000000000700000028000000486D0F00240E100001000000000000000000020600010000BFA2139DEDD1D3010000000000000000 "SIGN.MEDIA=2219443E Ma Logithèque clé\hwmonitor_1.37.exe"=0x534143500100000000000000070000002800000000411300FCF8130001000000000000000000000A00210000BFA2139DEDD1D30100000000000000000200000028000000000000000000000000000000000000000000000000000000B54A0000000000000100000001000000 "SIGN.MEDIA=1181E10 Ma Logithèque clé\MediaCreationTool-sospc.name_\MediaCreationTool sospc.name.exe"=0x5341435001000000000000000700000028000000101E18017809190101000000000000000000000A00210000BFA2139DEDD1D301000000000000000002000000280000000000000000000040000000000000000000000000000000000F2F0000000000000100000001000000 "SIGN.MEDIA=8697CB1D Ma Logithèque clé\Windows 10\MediaCreationTool.exe"=0x5341435001000000000000000700000028000000687C1901F08C190101000000000000000000000A00210000BFA2139DEDD1D30100000000000000000200000028000000000000000000004000000000000000000000000000000000554D0000000000000100000001000000 "C:\Program Files (x86)\Samsung\Samsung Printer Diagnostics\SEInstall\SPD\ESM.exe"=0x5341435001000000000000000700000028000000484224008077240001000000000000000000000A0021000067077CBAC54CD4010000000000000000020000002800000000000000000000400000000000000000000000000000000096A20400000000000500000005000000 "SIGN.MEDIA=2219443E Ma Logithèque clé\MolotovSetup-3.0.0.exe"=0x5341435001000000000000000700000028000000900CAD03CC4BAD0301000000000000000000030600010000BFA2139DEDD1D30100000000000000000200000028000000000000000000000000000000000000000000000000000000D9E70800000000000100000001000000 "C:\Users\EVRARD\AppData\Local\Molotov\Molotov.exe"=0x5341435001000000000000000700000028000000005004000000000001000000000000000000000A00210000631F6E6F0EDED401000000000000000002000000280000000000000000000000000000000000000000000000000000000C403A00000000000400000004000000 "C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorUI.exe"=0x5341435001000000000000000700000028000000F04D0A004B6F0A0001000000000000000000000A71220000BFA2139DEDD1D30100000000000000000500000010000000000000000000000000000000800000000200000028000000000000008000004000000000000000000000000000000000BB700000000000000200000002000000 "E:\Mes documents\Ma LOGITHEQUE portable Bollywood\SendToEditor1.1\SendToEditor\SendToEditor.exe"=0x5341435001000000000000000700000028000000B8480C0040BD0C0001000000000000000000010600010000BFA2139DEDD1D3010000000000000000050000001000000000000000000000000000000000000000020000002800000000000000000000400010000000000000000000000000000051470500000000000100000001000000 "SIGN.MEDIA=4370B74 Courrier\ThunderbirdPortable_60.3.0_French.paf.exe"=0x534143500100000000000000070000002800000098851B026F361C0201000000000000000000000A00210000BFA2139DEDD1D3010000000000000000020000002800000000000000000000000000000000000000000000000000000075EA0200000000000300000003000000 "SIGN.MEDIA=575B9 Courrier\ThunderbirdPortable\ThunderbirdPortable.exe"=0x534143500100000000000000070000002800000088AB0200DD20030001000000000000000000000A00210000BFA2139DEDD1D30100000000000000000200000028000000000000000000000000000000000000000000000000000000BB751400000000001F0000001F000000 "SIGN.MEDIA=70D0EC10 Ma Logithèque clé\VSDC Free video_editor_x64_6.1.1.894.exe"=0x5341435001000000000000000700000028000000E025F902EBACF90201000000000000000000000A00210000BFA2139DEDD1D301000000000000000002000000280000000000000000000000000000000000000000000000000000005AE50100000000000100000001000000 "SIGN.MEDIA=70D0EC10 Ma Logithèque clé\GoogleEarthProSetup7.3.2.5495.exe"=0x53414350010000000000000007000000280000005841110043DD110001000000000000000000000A00210000BFA2139DEDD1D301000000000000000002000000280000000000000000000000000000000000000000000000000000002F140100000000000100000001000000 "SIGN.MEDIA=C7C828 Courrier\ThunderbirdPortable\App\Thunderbird\thunderbird.exe"=0x5341435001000000000000000700000028000000D05D030069B5030001000000000000000000000A00210000BFA2139DEDD1D30100000000000000000200000028000000000000000000000000000000000000000000000000000000C6B66E00000000000400000004000000 "SIGN.MEDIA=70D0EC10 Ma Logithèque clé\Iperiusbackupfree5.8.1.exe"=0x53414350010000000000000007000000280000003039FD02B720FE0201000000000000000000000A00210000BFA2139DEDD1D3010000000000000000020000002800000000000000000000000000000000000000000000000000000014B30000000000000100000001000000 "SIGN.MEDIA=70D0EC10 Ma Logithèque clé\FreemakeVideoConverterSetup4.1.10.115.exe"=0x5341435001000000000000000700000028000000906D0F001EAE0F0001000000000000000000020600010000BFA2139DEDD1D301000000000000000002000000280000000000000000000000000000000000000000000000000000004858E602000000000100000001000000 "SIGN.MEDIA=C1C60AFC Ma Logithèque clé\PILOTES\416.81-desktop-win10-64bit-international-whql.exe"=0x534143500100000000000000070000002800000028F17F20ACF37F2001000000000000000000020600010000BFA2139DEDD1D30100000000000000000200000028000000000000000000004000000000000000000000000000000000C9F40800000000000100000001000000 "SIGN.MEDIA=575B9 Logiciel portable (ne pas FAC)\ThunderbirdPortable\ThunderbirdPortable.exe"=0x534143500100000000000000070000002800000088AB0200DD20030001000000000000000000000A00210000631F6E6F0EDED401000000000000000002000000280000000000000000000000000000000000000000000000000000000D810200000000000300000003000000 "SIGN.MEDIA=70D0EC10 Ma Logithèque clé\FreemakeVideoConverterSetup4.1.10.116.exe"=0x5341435001000000000000000700000028000000286D0F00551E100001000000000000000000020600010000BFA2139DEDD1D301000000000000000002000000280000000000000000000000000000000000000000000000000000005A19CE00000000000100000001000000 "SIGN.MEDIA=70D0EC10 Ma Logithèque clé\ccsetup549.0.6856.exe"=0x534143500100000000000000070000002800000008C013017DE5130101000000000000000000000A00210000BFA2139DEDD1D301000000000000000002000000280000000000000000000040000000000000000000000000000000009D40CA00000000000100000001000000 "SIGN.MEDIA=C1C60AFC Ma Logithèque clé\PILOTES\416.94-desktop-win10-64bit-international-whql.exe"=0x5341435001000000000000000700000028000000B88E8220F150832001000000000000000000020600010000BFA2139DEDD1D3010000000000000000020000002800000000000000000000400000000000000000000000000000000051560600000000000100000001000000 "SIGN.MEDIA=70D0EC10 Ma Logithèque clé\VSDC_video_editor_x64_6.1.1.899.exe"=0x5341435001000000000000000700000028000000883BF902C0D7F90201000000000000000000000A00210000BFA2139DEDD1D301000000000000000002000000280000000000000000000000000000000000000000000000000000003E8C0100000000000100000001000000 "SIGN.MEDIA=2F6759C7 Ma Logithèque clé\INTEL\Intel Driver and Support Assistant Installer.exe"=0x5341435001000000000000000700000028000000F05EF4004933F50001000000000000000000000A00210000BFA2139DEDD1D30100000000000000000200000028000000000000000000000000000000000000000000000000000000EEB17301000000000100000001000000 "SIGN.MEDIA=70D0EC10 Ma Logithèque clé\FreemakeVideoConverterSetup4.1.10.122.exe"=0x5341435001000000000000000700000028000000D86C0F006EDB0F0001000000000000000000020600010000BFA2139DEDD1D301000000000000000002000000280000000000000000000000000000000000000000000000000000003C854002000000000100000001000000 "SIGN.MEDIA=70D0EC10 Ma Logithèque clé\FreemakeVideoConverterSetup4.1.10.123.exe"=0x5341435001000000000000000700000028000000D86C0F001F7C0F0001000000000000000000020600010000BFA2139DEDD1D3010000000000000000 "SIGN.MEDIA=70D0EC10 Ma Logithèque clé\family_tree_builder_8495.exe"=0x534143500100000000000000070000002800000068B411032DD5110301000000000000000000010600010000BFA2139DEDD1D3010000000000000000 "SIGN.MEDIA=C8352224 0-A transférer sur PC TOUR Bollywood\ccsetup550.0.6911.exe"=0x5341435001000000000000000700000028000000685C1501B59E150101000000000000000000000A00210000BFA2139DEDD1D30100000000000000000200000028000000000000000000004000000000000000000000000000000000A6773A00000000000100000001000000 "SIGN.MEDIA=70D0EC10 Ma Logithèque clé\gu5setup5.110.0.135.exe"=0x534143500100000000000000070000002800000060E50901A8DC0A0101000000000000000000010600010000BFA2139DEDD1D3010000000000000000 "SIGN.MEDIA=70D0EC10 Ma Logithèque clé\iobituninstaller8.2.0.14.exe"=0x5341435001000000000000000700000028000000A85AFE006312FF0001000000000000000000000A00210000BFA2139DEDD1D3010000000000000000020000002800000000000000000000000000000000000000000000000000000036C40100000000000100000001000000 "SIGN.MEDIA=70D0EC10 Ma Logithèque clé\MP4Tools-3.7-win32.exe"=0x5341435001000000000000000700000028000000D23264010000000001000000000000000000000A00210000BFA2139DEDD1D30100000000000000000200000028000000000000000000000000000000000000000000000000000000AA850000000000000100000001000000 "SIGN.MEDIA=70D0EC10 Ma Logithèque clé\FreemakeVideoConverterSetup4.1.10.127.exe"=0x5341435001000000000000000700000028000000C06C0F007DBC0F0001000000000000000000020600010000BFA2139DEDD1D3010000000000000000 "SIGN.MEDIA=70D0EC10 Ma Logithèque clé\FreemakeVideoConverterSetup4.1.10.128.exe"=0x5341435001000000000000000700000028000000E86C0F00527F0F0001000000000000000000020600010000BFA2139DEDD1D3010000000000000000 "C:\Windows10Upgrade\Windows10UpgraderApp.exe"=0x534143500100000000000000070000002800000020D11D00AD4E1E0001000000000000000000000A7122000067077CBAC54CD401000000000000000005000000100000000000000000000000000000000000000002000000280000000000000000000040000000000000000000000000000000003A130000000000000100000001000000 "SIGN.MEDIA=92AD5E8 0-A transférer sur PC TOUR Bollywood\ccsetup551.0.6939.exe"=0x5341435001000000000000000700000028000000307B26015C8D260101000000000000000000000A0021000067077CBAC54CD4010000000000000000020000002800000000000000000000400000000000000000000000000000000065380000000000000100000001000000 "SIGN.MEDIA=92AD5E8 0-A transférer sur PC TOUR Bollywood\Intel Driver and Support Assistant Installer.exe"=0x5341435001000000000000000700000028000000B07DF400DB40F50001000000000000000000000A0021000067077CBAC54CD40100000000000000000200000028000000000000000000000000000000000000000000000000000000413E0000000000000100000001000000 "SIGN.MEDIA=92AD5E8 0-A transférer sur PC TOUR Bollywood\Skype-8.36.0.52.exe"=0x53414350010000000000000007000000280000006020E3034D7DE30301000000000000000000000A0021000067077CBAC54CD401000000000000000002000000280000000000000000000000000000000000000000000000000000003603FC01000000000100000001000000 "E:\Mes documents\Ma LOGITHEQUE portable Bollywood\WinDirStatPortable\WinDirStatPortable.exe"=0x534143500100000000000000070000002800000050C202009D68030001000000000000000000010600210000631F6E6F0EDED40100000000000000000200000028000000000000000000000000000000000000000000000000000000F3BA0000000000000600000006000000 "SIGN.MEDIA=C1C60AFC Ma Logithèque clé\PILOTES\417.35-desktop-win10-64bit-international-whql.exe"=0x5341435001000000000000000700000028000000F085FE21A49BFE210100000000000000000002060001000067077CBAC54CD40100000000000000000200000028000000000000000000004000000000000000000000000000000000D0CF0400000000000100000001000000 "SIGN.MEDIA=70D0EC10 Ma Logithèque clé\AdobeAIRInstaller (2).exe"=0x53414350010000000000000007000000280000009049A5005D23A60001000000000000000000000A0021000067077CBAC54CD40100000000000000000200000028000000000000000000000000000000000000000000000000000000D53C0100000000000100000001000000 "SIGN.MEDIA=70C5C948 Ma Logithèque clé\AdobeAIRInstaller31.0.0.96.exe"=0x53414350010000000000000007000000280000002810B00085B7B00001000000000000000000000A0021000067077CBAC54CD4010000000000000000020000002800000000000000000000000000000000000000000000000000000026BD0000000000000100000001000000 "SIGN.MEDIA=71413410 Ma Logithèque clé\Revo_uninstallersetup2.0.6.exe"=0x534143500100000000000000070000002800000078C16C0015806D0001000000000000000000000A0021000067077CBAC54CD4010000000000000000020000002800000000000000000000000000000000000000000000000000000075450000000000000100000001000000 "SIGN.MEDIA=71413410 Ma Logithèque clé\FreemakeVideoConverterSetup4.1.10.135.exe"=0x5341435001000000000000000700000028000000306D0F002FBB0F000100000000000000000002060001000067077CBAC54CD4010000000000000000 "C:\Program Files\LibreOffice\program\swriter.exe"=0x534143500100000000000000070000002800000068440100A404020001000000000000000000000A0021000067077CBAC54CD4010000000000000000020000002800000000000000000000000000000000000000000000000000000016E4C20B000000000400000004000000 "SIGN.MEDIA=2139162 0-A transférer sur PC TOUR Bollywood\gu5setup5.112.0.137.exe"=0x5341435001000000000000000700000028000000A0070B0137910B010100000000000000000001060001000067077CBAC54CD40100000000000000000200000028000000000000000000004000000000000000000000000000000000AC630000000000000100000001000000 "SIGN.MEDIA=71413410 Ma Logithèque clé\video_editor_x64_6.3.1.924.exe"=0x5341435001000000000000000700000028000000287C3B0435103C0401000000000000000000000A0021000067077CBAC54CD40100000000000000000200000028000000000000000000000000000000000000000000000000000000BE110100000000000100000001000000 "SIGN.MEDIA=71413410 Ma Logithèque clé\gu5setup5.112.0.137.exe"=0x5341435001000000000000000700000028000000A0070B0137910B010100000000000000000001060001000067077CBAC54CD4010000000000000000 "C:\Program Files (x86)\MP4Tools\bin\MP4Splitter.exe"=0x53414350010000000000000007000000280000000EBC6000D83C610001000000000000000000000A61200000631F6E6F0EDED40100000000000000000200000028000000000000000000000000000000000000000000000000000000C1924700000000003000000030000000 "E:\Mes documents\CASTRIES GENERAL\NOTICES-MODE d'EMPLOI\NOTICE-MICRO\Notice-Monitor-Ecran BENQ GW2780\auto.exe"=0x534143500100000000000000070000002800000000A000003CB700000100000000000000000001057100000067077CBAC54CD40100000000000000000200000028000000000000000000000000000000000000000000000000000000F73F0000000000000100000001000000 "C:\Program Files\internet explorer\iexplore.exe"=0x5341435001000000000000000700000028000000509D0C0075FF0C0001000000010000000000000A0021000067077CBAC54CD4010000000000000000 "SIGN.MEDIA=71413410 Ma Logithèque clé\videoproc3.2.0.0.exe"=0x5341435001000000000000000700000028000000F804F10237D3F1020100000000000000000001060001000067077CBAC54CD40100000000000000000200000028000000000000000000000000000000000000000000000000000000F8F70100000000000100000001000000 "SIGN.MEDIA=7EE1B0B0 Vdlx2018_Premium_Update_17.0.1.148.exe"=0x534143500100000000000000070000002800000010687C037BD27C0301000000000000000000000A0021000067077CBAC54CD4010000000000000000020000002800000000000000000000400000000000000000000000000000000071500000000000000200000002000000 "SIGN.MEDIA=7EE1B0B0 Vdlx2018_Premium_Update_17.0.2.171.exe"=0x534143500100000000000000070000002800000030782A0174492B0101000000000000000000000A0021000067077CBAC54CD40100000000000000000200000028000000000000000000004000000000000000000000000000000000EB410000000000000100000001000000 "C:\Program Files\Speccy\Speccy64.exe"=0x5341435001000000000000000700000028000000989A6C0074CD6C0001000000000000000000000A73220000631F6E6F0EDED40100000000000000000200000028000000000000000000000000000000000000000000000000000000E7590000000000000400000004000000 "C:\Program Files (x86)\Windows Media Player\wmplayer.exe"=0x5341435001000000000000000700000028000000008C0200DFDF020001000000010000000000000A6122000067077CBAC54CD4010000000000000000 "SIGN.MEDIA=8F5599F9 Ma Logithèque clé\MAGIX\Vdlx2018_Premium_Update_17.0.1.148.exe"=0x534143500100000000000000070000002800000010687C037BD27C0301000000000000000000000A0021000067077CBAC54CD4010000000000000000050000001000000000000000000000000000000000000000020000002800000000000000000000400000000000000000000000000000000071F80500000000000300000003000000 "SIGN.MEDIA=8F5599F9 Ma Logithèque clé\MAGIX\Vdlx2017_Premium_Update_16.0.4.102.exe"=0x534143500100000000000000070000002800000008327A34A9737A340100000000000000000003060001000067077CBAC54CD401000000000000000002000000280000000000000000000040000000000000000000000000000000000E160200000000000100000001000000 "SIGN.MEDIA=8F5599F9 Ma Logithèque clé\MAGIX\Vdlx2018_Premium_Update_17.0.3.184.exe"=0x534143500100000000000000070000002800000080424A011D684A0101000000000000000000000A0021000067077CBAC54CD401000000000000000005000000100000000000000000000000000000000000000002000000280000000000000000000040000000000000000000000000000000008E460000000000000100000001000000 "C:\Program Files\MAGIX\Video deluxe Premium\2017\Videodeluxe.exe"=0x5341435001000000000000000700000028000000003F980176CE980101000000000000000000000A00210000631F6E6F0EDED40100000000000000000200000028000000000000000000000000000000000000000000000000000000609F6200000000004800000048000000 "C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe"=0x53414350010000000000000007000000280000004093080007FB08000100000000000000000001067122000067077CBAC54CD40100000000000000000200000028000000000000000000000000000000000000000000000000000000822E0000000000000100000001000000 "SIGN.MEDIA=725D9468 Ma Logithèque clé\7z1806-x64.exe"=0x5341435001000000000000000700000028000000600716000000000001000000000000000000000A0021000067077CBAC54CD401000000000000000002000000280000000000000000000040000000000000000000000000000000006B2A0000000000000100000001000000 "C:\Program Files\7-Zip\7zFM.exe"=0x534143500100000000000000070000002800000000360D000000000001000000000000000000000A0021000067077CBAC54CD40100000000000000000200000028000000000000000000000000000000000000000000000000000000DE240000000000000100000001000000 "SIGN.MEDIA=725D9468 Ma Logithèque clé\NETGEARGenie-install2.4.60.exe"=0x5341435001000000000000000700000028000000B069C6025602C7020100000000000000000001067100000067077CBAC54CD40100000000000000000200000028000000000000000008004000000000000000000000000000000000F755D501000000000200000002000000 "SIGN.MEDIA=725D9468 Ma Logithèque clé\VSDC_video_editor_x64_6.3.1.936.exe"=0x5341435001000000000000000700000028000000284B3B0421A33B0401000000000000000000000A0021000067077CBAC54CD40100000000000000000200000028000000000000000000000000000000000000000000000000000000FC110100000000000100000001000000 "SIGN.MEDIA=725D9468 Ma Logithèque clé\iobituninstaller8.3.0.11.exe"=0x534143500100000000000000070000002800000090501C01A5881C0101000000000000000000000A0021000067077CBAC54CD40100000000000000000200000028000000000000000000000000000000000000000000000000000000E1970200000000000100000001000000 "C:\Program Files (x86)\Microsoft Silverlight\5.1.50918.0\Silverlight.Configuration.exe"=0x5341435001000000000000000700000028000000889E03005FB7030001000000000000000000000A7122000067077CBAC54CD40100000000000000000200000028000000000000000000000000000000000000000000000000000000549E0000000000000100000001000000 "C:\Program Files (x86)\PDFTK Builder\PDFTKBuilder.exe"=0x534143500100000000000000070000002800000000D026000000000001000000000000000000000A71220000631F6E6F0EDED40100000000000000000200000028000000000000000000000000000000000000000000000000000000E7FF0100000000000500000005000000 "SIGN.MEDIA=725D9468 Ma Logithèque clé\VSDC_video_editor_x64_6.3.1.939.exe"=0x5341435001000000000000000700000028000000F0153B041F753B0401000000000000000000000A0021000067077CBAC54CD40100000000000000000200000028000000000000000000000000000000000000000000000000000000F23F0100000000000100000001000000 "SIGN.MEDIA=4BCB4B14 Ma Logithèque clé\ccsetup552.0.6967.exe"=0x534143500100000000000000070000002800000038222701189F270101000000000000000000000A0021000067077CBAC54CD4010000000000000000020000002800000000000000000000400000000000000000000000000000000040DD9400000000000100000001000000 "SIGN.MEDIA=4BCB4B14 Ma Logithèque clé\FoxitReader941.1628_L10N_Setup_Prom.exe"=0x534143500100000000000000070000002800000050E22106C134220601000000000000000000000A0021000067077CBAC54CD40100000000000000000200000028000000000000000000000000000000000000000000000000000000D0E10100000000000100000001000000 "SIGN.MEDIA=4BCB4B14 Ma Logithèque clé\FreemakeVideoConverterSetup4.1.10.160.exe"=0x5341435001000000000000000700000028000000386D0F00EE1E10000100000000000000000002060001000067077CBAC54CD401000000000000000002000000280000000000000000000000000000000000000000000000000000005EB69100000000000100000001000000 "SIGN.MEDIA=7DDBA839 0-A transférer sur PC TOUR Bollywood\PersoAppscalendrier1.31.392.exe"=0x5341435001000000000000000700000028000000E86CE5001491E50001000000000000000000000A0021000067077CBAC54CD4010000000000000000020000002800000000000000000000000000000000000000000000000000000022AF0200000000000100000001000000 "SIGN.MEDIA=12019B58 0-A transférer sur PC TOUR Bollywood\persoappsadresses1.3.1.1268.exe"=0x5341435001000000000000000700000028000000080FF8007BE1F80001000000000000000000000A0021000067077CBAC54CD40100000000000000000200000028000000000000000000000000000000000000000000000000000000C0B01100000000000100000001000000 "SIGN.MEDIA=1EADF8AA Ma Logitheque Portable clé\sumo5.8.12.415\sumo\SUMo.exe"=0x5341435001000000000000000700000028000000C0A81F00805D200001000000000000000000000A6120000067077CBAC54CD40100000000000000000200000028000000000000000000000000000000000000000000000000000000009F0000000000000100000001000000 "SIGN.MEDIA=4BCB4B14 Ma Logithèque clé\IperiusBackup5.8.6.0.exe"=0x5341435001000000000000000700000028000000D0E8FD029045FE0201000000000000000000000A0021000067077CBAC54CD40100000000000000000200000028000000000000000000000000000000000000000000000000000000559B1400000000000100000001000000 "SIGN.MEDIA=4BCB4B14 Ma Logithèque clé\FreemakeVideoConverterSetup4.1.10.173.exe"=0x5341435001000000000000000700000028000000386D0F00711D10000100000000000000000002060001000067077CBAC54CD4010000000000000000 "E:\Mes documents\Ma LOGITHEQUE portable Bollywood\TreeSizeFree-Portable4.3.1\TreeSizeFree.exe"=0x5341435001000000000000000700000028000000F83E6500A581650001000000000000000000000A0021000067077CBAC54CD4010000000000000000050000001000000000000000000000000000000000000000020000002800000000000000000000000000000000000000000000000000000033860100000000000100000001000000 "SIGN.MEDIA=4BCB4B14 Ma Logithèque clé\ccsetup553.0.7034.exe"=0x534143500100000000000000070000002800000038C927011208280101000000000000000000000A0021000067077CBAC54CD4010000000000000000 "SIGN.MEDIA=4BCB4B14 Ma Logithèque clé\MolotovSetup-3.1.0.exe"=0x534143500100000000000000070000002800000090C69F03530BA0030100000000000000000003060001000067077CBAC54CD40100000000000000000200000028000000000000000000000000000000000000000000000000000000F60BFA00000000000100000001000000 "SIGN.MEDIA=15822BB Ma Logithèque clé\PhotoFiltre-fr-652\PhotoFiltre.exe"=0x5341435001000000000000000700000028000000004E2B00000000000100000000000000000001066120000067077CBAC54CD40100000000000000000200000028000000000000000000000000000000000000000000000000000000F41B0000000000000100000001000000 "SIGN.MEDIA=88235E Ma Logithèque clé\AMD64\amdclock\AMDClock.exe"=0x534143500100000000000000070000002800000000002200000000000100000000000000000001057120000067077CBAC54CD40100000000000000000200000028000000000000000000000000000000000000000000000000000000A2260000000000000200000002000000 "SIGN.MEDIA=59C00 Ma Logithèque clé\Dictionnaires\Dic-ang.exe"=0x5341435001000000000000000700000028000000009C0500000000000100000000000000000001057120000067077CBAC54CD40100000000000000000100000004000000010000000500000010000000000000000000000000000000800800000200000028000000000000008008004000002000000000000000200000000000F1330000000000000200000002000000 "SIGN.MEDIA=4BCB4B14 Ma Logithèque clé\iobituninstalle8.3.0.14.exe"=0x534143500100000000000000070000002800000000161A013A421A0101000000000000000000000A0021000067077CBAC54CD4010000000000000000020000002800000000000000000000000000000000000000000000000000000019330600000000000100000001000000 "SIGN.MEDIA=4BCB4B14 Ma Logithèque clé\readerdc_fr_xa_install.exe"=0x5341435001000000000000000700000028000000F8591200285F120001000000000000000000000A0021000067077CBAC54CD4010000000000000000020000002800000000000000000000000000000000000000000000000000000070BC0200000000000100000001000000 "SIGN.MEDIA=28E61FE 0-A transférer sur PC TOUR Bollywood\FreemakeVideoConverterSetup4.1.10.179.exe"=0x5341435001000000000000000700000028000000686D0F006B7C0F000100000000000000000002060001000067077CBAC54CD4010000000000000000 "SIGN.MEDIA=A28A20 Ma Logitheque Portable clé\captvty-3.0.0.63825\Captvty.exe"=0x5341435001000000000000000700000028000000004051000000000001000000000000000000000A0021000067077CBAC54CD401000000000000000002000000280000000000000000000000000000000000000000000000000000005D0F0100000000000100000001000000 "SIGN.MEDIA=4BCF68FE Ma Logithèque clé\gu5.114.0.139setup.exe"=0x534143500100000000000000070000002800000040D50B01D6D10C010100000000000000000001060001000067077CBAC54CD401000000000000000002000000280000000000000000000040000000000000000000000000000000009A4C0000000000000100000001000000 "C:\Program Files (x86)\Samsung\Easy Document Creator\EDC.exe"=0x534143500100000000000000070000002800000028650C00AED80C0001000000000000000000000A7122000067077CBAC54CD40100000000000000000200000028000000000000000000000000000000000000000000000000000000AF4B0000000000000200000002000000 "E:\Mes documents\MAGIX Téléchargements\Video_deluxe_2017_Premium_KA4_MSMStyles1_INT_170531_12-01_16_0_4_0.exe"=0x53414350010000000000000007000000280000000000C5024395DB1801000000000000000000000A00210000631F6E6F0EDED401000000000000000005000000100000000000000000000000000000000000000002000000280000000000000000000040000000000000000000000000000000005A180000000000000400000004000000 "SIGN.MEDIA=12E62A7C Ma Logithèque clé\ccsetup554.0.7088.exe"=0x534143500100000000000000070000002800000038DF42017E59430101000000000000000000000A0021000067077CBAC54CD4010000000000000000 "SIGN.MEDIA=12E62A7C Ma Logithèque clé\iobituninstaller8.4.0.7.exe"=0x5341435001000000000000000700000028000000A03D2701CC80270101000000000000000000000A0021000067077CBAC54CD4010000000000000000020000002800000000000000000000000000000000000000000000000000000036C70700000000000100000001000000 "SIGN.MEDIA=12E22D42 Ma Logithèque clé\FreeStudio_6.6.44.228_d.exe"=0x53414350010000000000000007000000280000008882A303D244A40301000000000000000000000A0021000067077CBAC54CD40100000000000000000200000028000000000000000000000000000000000000000000000000000000DA5C1600000000000100000001000000 "SIGN.MEDIA=12E22D42 Ma Logithèque clé\FreemakeVideoConverterSetup4.1.10.187.exe"=0x5341435001000000000000000700000028000000586D0F00268F0F000100000000000000000002060001000067077CBAC54CD40100000000000000000200000028000000000000000000000000100000000000000000000000000000E1801200000000000100000001000000 "SIGN.MEDIA=5EA5A3CB Ma Logithèque clé\PILOTES\Intel Driver and Support Assistant Installer.exe"=0x5341435001000000000000000700000028000000B07DF400DB40F50001000000000000000000000A0021000067077CBAC54CD40100000000000000000200000028000000000000000000000000000000000000000000000000000000733B0000000000000100000001000000 "SIGN.MEDIA=5EA5A3CB Ma Logithèque clé\PILOTES\Intel Driver and Support Assistant Installer (1).exe"=0x534143500100000000000000070000002800000030F7D8009A91D90001000000000000000000000A0021000067077CBAC54CD4010000000000000000020000002800000000000000000000000000000000000000000000000000000079610000000000000100000001000000 "SIGN.MEDIA=12E22D42 Ma Logithèque clé\Iperius6.0.0.0.exe"=0x5341435001000000000000000700000028000000500CFE0264B7FE0201000000000000000000000A0021000067077CBAC54CD40100000000000000000200000028000000000000000000000000000000000000000000000000000000C1400A00000000000100000001000000 "SIGN.MEDIA=12E22D42 Ma Logithèque clé\gu5.115.0.140setup.exe"=0x534143500100000000000000070000002800000008FE0B015E870C010100000000000000000001060001000067077CBAC54CD4010000000000000000020000002800000000000000000000400000000000000000000000000000000023941E01000000000100000001000000 "SIGN.MEDIA=17431CB8 Ma Logithèque clé\ICECREAM\Icecream_pdf_converter_setup2.86.exe"=0x53414350010000000000000007000000280000007875E1076ECAE10701000000000000000000000A0021000067077CBAC54CD40100000000000000000200000028000000000000000000000000000000000000000000000000000000706E0200000000000100000001000000 "SIGN.MEDIA=17431CB8 Ma Logithèque clé\ICECREAM\Icecream_Slideshow_Maker_v3.48.exe"=0x5341435001000000000000000700000028000000A03A4C015D6C4C0101000000000000000000000A0021000067077CBAC54CD4010000000000000000020000002800000000000000000000000000000000000000000000000000000097D90000000000000100000001000000 "C:\Program Files\Google\Google Earth Pro\client\googleearth.exe"=0x5341435001000000000000000700000028000000F0B51B005F241C0001000000000000000000000A7322000067077CBAC54CD40100000000000000000200000028000000000000000000001000000000000000000000000000000000EF142E00000000000500000005000000 "C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\FreeStudioManager.exe"=0x5341435001000000000000000700000028000000E80517003212170001000000000000000000000A7122000067077CBAC54CD40100000000000000000200000028000000000000000000000000000000000000000000000000000000CA020100000000000100000001000000 "C:\Program Files (x86)\SDA\SD Card Formatter\SD Card Formatter.exe"=0x534143500100000000000000070000002800000050633700CC5D380001000000000000000000000A7122000067077CBAC54CD40100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000004000000000000000000000000000000000B6960900000000000300000003000000 "SIGN.MEDIA=12E22D42 Ma Logithèque clé\Iperius6.0.1.0.exe"=0x53414350010000000000000007000000280000005013FE0225D4FE0201000000000000000000000A0021000067077CBAC54CD401000000000000000002000000280000000000000000000000000000000000000000000000000000000BD00800000000000100000001000000 "SIGN.MEDIA=12E22D42 Ma Logithèque clé\FreemakeVideoConverterSetup4.1.10.197.exe"=0x5341435001000000000000000700000028000000506D0F00CAE50F000100000000000000000002060001000067077CBAC54CD401000000000000000002000000280000000000000000000000001000000000000000000000000000000DF79302000000000100000001000000 "SIGN.MEDIA=12E22D42 Ma Logithèque clé\install_flash_player (1).exe"=0x5341435001000000000000000700000028000000D81D45016B80450101000000000000000000000A0021000067077CBAC54CD4010000000000000000020000002800000000000000000000400000000000000000000000000000000015550000000000000100000001000000 "SIGN.MEDIA=12E22D42 Ma Logithèque clé\iobituninstaller8.4.0.8.exe"=0x5341435001000000000000000700000028000000F84027019FE7270101000000000000000000000A0021000067077CBAC54CD4010000000000000000020000002800000000000000000000000000000000000000000000000000000009F50100000000000100000001000000 "SIGN.MEDIA=DBE550C Ma Logithèque clé\AOMEIBackupperPro\WBD2019\AOMEIBackupperSetup.exe"=0x5341435001000000000000000700000028000000602ADF06E3A5DF060100000000000000000001060001000067077CBAC54CD40100000000000000000200000028000000000000000000004000000000000000000000000000000000001A1700000000000100000001000000 "SIGN.MEDIA=12E22D42 Ma Logithèque clé\Iperius6.0.2.0.exe"=0x5341435001000000000000000700000028000000101912033171120301000000000000000000000A0021000067077CBAC54CD40100000000000000000200000028000000000000000000000000000000000000000000000000000000184F1C02000000000100000001000000 "SIGN.MEDIA=12E22D42 Ma Logithèque clé\gu5setup5.116.0.141.exe"=0x5341435001000000000000000700000028000000A0010C01BD600C010100000000000000000001060001000067077CBAC54CD401000000000000000002000000280000000000000000000040000000000000000000000000000000002C660000000000000100000001000000 "E:\Mes documents\Ma LOGITHEQUE portable Bollywood\CDBurnerXP-4.5.8.7042\cdbxpp.exe"=0x534143500100000000000000070000002800000070BE1A0088EA1A0001000000000000000000000A0021000067077CBAC54CD401000000000000000002000000280000000000000000000000000000000000000000000000000000005F340000000000000100000001000000 "SIGN.MEDIA=407836CB Ma Logithèque clé\PILOTES\419.67-desktop-win10-64bit-international-whql.exe"=0x5341435001000000000000000700000028000000200E7B2203A17B220100000000000000000002060001000067077CBAC54CD40100000000000000000200000028000000000000000000004000100000000000000000000000000000B8150700000000000100000001000000 "SIGN.MEDIA=12E22D42 Ma Logithèque clé\Iperius6.0.3.0.exe"=0x5341435001000000000000000700000028000000F8691203BA4B130301000000000000000000000A0021000067077CBAC54CD40100000000000000000200000028000000000000000000000000000000000000000000000000000000C0770000000000000100000001000000 "SIGN.MEDIA=12E22D42 Ma Logithèque clé\VSDC_video_editor6.3.2.960_x64.exe"=0x5341435001000000000000000700000028000000585C45043D4B460401000000000000000000000A0021000067077CBAC54CD40100000000000000000200000028000000000000000000000000000000000000000000000000000000DA990100000000000100000001000000 "SIGN.MEDIA=12E22D42 Ma Logithèque clé\family_tree_builder8.0.0_8516.exe"=0x534143500100000000000000070000002800000048741903F4AD19030100000000000000000001060001000067077CBAC54CD40100000000000000000200000028000000000000000000004004000000000000000000000000000000D29ECF00000000000200000002000000 "SIGN.MEDIA=12E22D42 Ma Logithèque clé\FreemakeVideoConverterSetup4.1.10.205.exe"=0x5341435001000000000000000700000028000000086E0F0076870F000100000000000000000002060001000067077CBAC54CD401000000000000000002000000280000000000000000000000000000000000000000000000000000000EE1D800000000000100000001000000 "SIGN.MEDIA=12E22D42 Ma Logithèque clé\VSDC_video_editor_x64_6.3.3.966.exe"=0x5341435001000000000000000700000028000000E86A4504DA70450401000000000000000000000A0021000067077CBAC54CD4010000000000000000 "SIGN.MEDIA=85603F4C Ma Logitheque Portable clé\VSDC_video_editor_x64_6.3.3.968.exe"=0x5341435001000000000000000700000028000000B0B3450476CC450401000000000000000000000A0021000067077CBAC54CD40100000000000000000200000028000000000000000000000000000000000000000000000000000000FC830200000000000100000001000000 "SIGN.MEDIA=12E22D42 Ma Logithèque clé\AOMEIBackupperStd_4.6.3.exe"=0x5341435001000000000000000700000028000000307CE106DB51E2060100000000000000000001060001000067077CBAC54CD401000000000000000002000000280000000000000000000040000000000000000000000000000000003F21210A000000000100000001000000 "SIGN.MEDIA=12E22D42 Ma Logithèque clé\ccsetup556.exe"=0x5341435001000000000000000700000028000000405044017CBF440101000000000000000000000A0021000067077CBAC54CD4010000000000000000020000002800000000000000000000400000000000000000000000000000000023FE1B00000000000100000001000000 "SIGN.MEDIA=12E22D42 Ma Logithèque clé\acrobat-reader-dc_2019-010-20099_fr_431723.exe"=0x5341435001000000000000000700000028000000305A1200678C120001000000000000000000000A0021000067077CBAC54CD401000000000000000002000000280000000000000000000000000000000000000000000000000000006F390000000000000100000001000000 "SIGN.MEDIA=12E22D42 Ma Logithèque clé\readerdc_fr_xa_crd_install.exe"=0x5341435001000000000000000700000028000000305A1200678C120001000000000000000000000A0021000067077CBAC54CD40100000000000000000200000028000000000000000000000000000000000000000000000000000000AD560300000000000100000001000000 "SIGN.MEDIA=12E22D42 Ma Logithèque clé\gu5.117.0.142setup.exe"=0x5341435001000000000000000700000028000000F0970C01FEBB0C010100000000000000000001060001000067077CBAC54CD40100000000000000000200000028000000000000000000004000000000000000000000000000000000815D0000000000000100000001000000 "SIGN.MEDIA=12E22D42 Ma Logithèque clé\FoxitReader9.5.0Build20721_enu_Setup_Prom.exe"=0x5341435001000000000000000700000028000000E81BBC04869ABC0401000000000000000000000A0021000067077CBAC54CD4010000000000000000020000002800000000000000000000000000000000000000000000000000000008E30100000000000100000001000000 "SIGN.MEDIA=12E22D42 Ma Logithèque clé\FreemakeVideoConverterSetup4.1.10.213.exe"=0x5341435001000000000000000700000028000000F06D0F008D2210000100000000000000000002060001000067077CBAC54CD401000000000000000002000000280000000000000000000000001000000000000000000000000000008AAC1400000000000100000001000000 "SIGN.MEDIA=407836CB Ma Logithèque clé\PILOTES\425.31-desktop-win10-64bit-international-whql.exe"=0x534143500100000000000000070000002800000000D99122C14492220100000000000000000002060001000067077CBAC54CD40100000000000000000200000028000000000000000000004000100000000000000000000000000000A2660800000000000100000001000000 "SIGN.MEDIA=12E22D42 Ma Logithèque clé\FreemakeVideoConverterSetup4.1.10.216.exe"=0x534143500100000000000000070000002800000038700F00301110000100000000000000000002060001000067077CBAC54CD40100000000000000000200000028000000000000000000000000000000000000000000000000000000DC108001000000000100000001000000 "SIGN.MEDIA=12E22D42 Ma Logithèque clé\Skype-8.43.0.56.exe"=0x5341435001000000000000000700000028000000908EB4035FC3B40301000000000000000000000A0021000067077CBAC54CD40100000000000000000200000028000000000000000000000000000000000000000000000000000000F1647E01000000000100000001000000 "SIGN.MEDIA=12E22D42 Ma Logithèque clé\family_tree_builder_8.0.0.8519.exe"=0x5341435001000000000000000700000028000000384411066D2B12060100000000000000000001060001000067077CBAC54CD4010000000000000000020000002800000000000000000000400400000000000000000000000000000072C10200000000000100000001000000 "SIGN.MEDIA=12E22D42 Ma Logithèque clé\FreemakeVideoConverterSetup4.1.10.222.exe"=0x5341435001000000000000000700000028000000806D0F00E2AE0F000100000000000000000002060001000067077CBAC54CD4010000000000000000 "SIGN.MEDIA=12E22D42 Ma Logithèque clé\gu5.118.0.143setup.exe"=0x5341435001000000000000000700000028000000C89B0C01592D0D010100000000000000000001060001000067077CBAC54CD4010000000000000000 "SIGN.MEDIA=407836CB Ma Logithèque clé\PILOTES\NVIDIA_GeForce_Experience_v3.18.0.102.exe"=0x5341435001000000000000000700000028000000C01A12076C8712070100000000000000000002060001000067077CBAC54CD40100000000000000000200000028000000000000000000004000000000000000000000000000000000A6720200000000000100000001000000 "SIGN.MEDIA=12E22D42 Ma Logithèque clé\WinPcap_v4.1.3.exe"=0x5341435001000000000000000700000028000000B8F60D00E7DC0E000100000000000000000000067100000067077CBAC54CD4010000000000000000050000001000000000000000000000000000000000080000020000002800000000000000000800500000000000000000000000000000000018860000000000000100000001000000 "SIGN.MEDIA=12E22D42 Ma Logithèque clé\KeePass-2.42-Setup.exe"=0x5341435001000000000000000700000028000000C07F3200E9CD320001000000000000000000000A0021000067077CBAC54CD401000000000000000002000000280000000000000000000000000000000000000000000000000000002CA70000000000000100000001000000 "SIGN.MEDIA=12E22D42 Ma Logithèque clé\Skype-8.44.0.40.exe"=0x53414350010000000000000007000000280000000873B503BFEAB50301000000000000000000000A0021000067077CBAC54CD4010000000000000000020000002800000000000000000000000000000000000000000000000000000090E3A701000000000100000001000000 "SIGN.MEDIA=12E22D42 Ma Logithèque clé\wrar571fr.exe"=0x534143500100000000000000070000002800000060452E00E50A2F0001000000000000000000000A0021000067077CBAC54CD401000000000000000002000000280000000000000000000040000000000000000000000000000000004A470000000000000100000001000000 "SIGN.MEDIA=12E22D42 Ma Logithèque clé\winrar-x64-571fr.exe"=0x5341435001000000000000000700000028000000807731001C95310001000000000000000000000A0021000067077CBAC54CD4010000000000000000020000002800000000000000000000400000000000000000000000000000000047230000000000000200000002000000 "SIGN.MEDIA=12E22D42 Ma Logithèque clé\FoxitReader95.0.20723_L10N_Setup_Prom.exe"=0x5341435001000000000000000700000028000000C0C8380675CC380601000000000000000000000A0021000067077CBAC54CD40100000000000000000200000028000000000000000000000000000000000000000000000000000000A9C30100000000000100000001000000 "SIGN.MEDIA=12E22D42 Ma Logithèque clé\FreemakeVideoConverterSetup4.1.10.231.exe"=0x5341435001000000000000000700000028000000B86E0F00911E10000100000000000000000002060001000067077CBAC54CD401000000000000000002000000280000000000000000000000001000000000000000000000000000001C4F8701000000000100000001000000 "SIGN.MEDIA=12E22D42 Ma Logithèque clé\Vivaldi.2.4.1488.40.x64 (1).exe"=0x534143500100000000000000070000002800000048BA7B03142D7C0301000000000000000000000A0021000067077CBAC54CD40100000000000000000200000028000000000000000000000000000000000000000000000000000000475F0000000000000100000001000000 "SIGN.MEDIA=12E22D42 Ma Logithèque clé\avast_secure_browser_setup73.0.1270.87.exe"=0x53414350010000000000000007000000280000006850280044EF280001000000000000000000000A0021000067077CBAC54CD40100000000000000000200000028000000000000000000000000000000000000000000000000000000680D0100000000000100000001000000 "E:\Desktop\OUTILS\Outils Sécurité-Anti VIRUS-Réglages\avast-browser-cleanup.exe"=0x5341435001000000000000000500000010000000000000000000000000000000000000000700000028000000D861410049E0410001000000000000000000010671020000631F6E6F0EDED40100000000000000000200000028000000000000000000000000000000000000000000000000000000720E0100000000000500000005000000 "SIGN.MEDIA=12E22D42 Ma Logithèque clé\persoappsadresses1.3.1.1269_maj.exe"=0x5341435001000000000000000700000028000000A017FB002CD3FB0001000000000000000000000A0021000067077CBAC54CD4010000000000000000020000002800000000000000000000000000000000000000000000000000000028879001000000000100000001000000 "SIGN.MEDIA=12E22D42 Ma Logithèque clé\adwcleaner_7.3.0.0.exe"=0x5341435001000000000000000700000028000000D0326B00387A6B0001000000000000000000000A0021000067077CBAC54CD4010000000000000000 "SIGN.MEDIA=12E22D42 Ma Logithèque clé\KeePass-2.42.1-Setup.exe"=0x5341435001000000000000000700000028000000307E32004341330001000000000000000000000A0021000067077CBAC54CD4010000000000000000020000002800000000000000000000000000000000000000000000000000000007E40000000000000100000001000000 "SIGN.MEDIA=12E22D42 Ma Logithèque clé\iobituninstaller8.5.0.6.exe"=0x5341435001000000000000000700000028000000B0462701CD16280101000000000000000000000A0021000067077CBAC54CD40100000000000000000200000028000000000000000000000000000000000000000000000000000000D7FF0100000000000100000001000000 "SIGN.MEDIA=12E22D42 Ma Logithèque clé\minitoolpartitionwizard11.0.1-free.exe"=0x534143500100000000000000070000002800000000044C03610C4C0301000000000000000000000A0021000067077CBAC54CD4010000000000000000 "SIGN.MEDIA=12E22D42 Ma Logithèque clé\gu5.119.0.144setup.exe"=0x534143500100000000000000070000002800000000BB0D0155A70E010100000000000000000001060001000067077CBAC54CD4010000000000000000 "SIGN.MEDIA=12E22D42 Ma Logithèque clé\ccsetup557.7182.exe"=0x534143500100000000000000070000002800000018404501DC8F450101000000000000000000000A0021000067077CBAC54CD40100000000000000000200000028000000000000000000004000000000000000000000000000000000FAD45400000000000100000001000000 "SIGN.MEDIA=12E22D42 Ma Logithèque clé\avast_secure_browser_setup74.0.1360.132.exe"=0x53414350010000000000000007000000280000006850280044EF280001000000000000000000000A0021000067077CBAC54CD40100000000000000000200000028000000000000000000000000000000000000000000000000000000E4150100000000000100000001000000 "C:\Program Files\File Converter\FileConverter.exe"=0x5341435001000000000000000500000010000000000000000000000000000000000000000700000028000000903C1300BE28140001000000000000000000000A73220000631F6E6F0EDED40100000000000000000200000050000000000000000000000000000000000000000000000000000000AF2B01000000000008000000080000000000000000000040000000000000000000000000000000000A010000000000000100000000000000 "SIGN.MEDIA=2F9B7A20 Ma Logithèque clé\ICECREAM\Icecream_Slideshow_Maker_v3.49.exe"=0x5341435001000000000000000700000028000000C8504C014FB84C0101000000000000000000000A0021000067077CBAC54CD4010000000000000000020000002800000000000000000000000000000000000000000000000000000055BD0000000000000100000001000000 "SIGN.MEDIA=12E22D42 Ma Logithèque clé\Thunderbird Setup 60.7.0fr.exe"=0x534143500100000000000000070000002800000090E0EA01163DEB0101000000000000000000000A0021000067077CBAC54CD4010000000000000000 "C:\Program Files\FlashIntegro\VideoEditor\VideoEditor.exe"=0x5341435001000000000000000700000028000000781FF3024278F30201000000000000000000000A7322000067077CBAC54CD4010000000000000000020000002800000000000000000000000000000000000000000000000000000092800500000000000100000001000000 "SIGN.MEDIA=12E22D42 Ma Logithèque clé\avast_free_antivirus_setup_offline.exe"=0x534143500100000000000000070000002800000008280E1593270F1501000000000000000000000A0021000067077CBAC54CD401000000000000000002000000280000000000000000000040000000000000000000000000000000005A680100000000000100000001000000 "SIGN.MEDIA=12E22D42 Ma Logithèque clé\FreemakeVideoConverterSetup4.1.10.247.exe"=0x534143500100000000000000070000002800000058700F00DF7C0F000100000000000000000002060001000067077CBAC54CD4010000000000000000 "SIGN.MEDIA=12E22D42 Ma Logithèque clé\DuplicateCleanerFree4.1.2_setup.exe"=0x5341435001000000000000000700000028000000C0335F00F16D5F0001000000000000000000000A0021000067077CBAC54CD40100000000000000000200000028000000000000000000004000000000000000000000000000000000D25A0000000000000100000001000000 "C:\Program Files (x86)\Duplicate Cleaner\DuplicateCleaner.exe"=0x5341435001000000000000000700000028000000D86A180000F1180001000000000000000000000A0021000067077CBAC54CD4010000000000000000020000002800000000000000000000000000000000000000000000000000000055740000000000000100000001000000 "SIGN.MEDIA=12E22D42 Ma Logithèque clé\MolotovSetup_X64-4.0.0.exe"=0x534143500100000000000000070000002800000098AE01049BAA02040100000000000000000003060001000067077CBAC54CD40100000000000000000200000028000000000000000000000000000000000000000000000000000000E29B0000000000000100000001000000 "SIGN.MEDIA=12E22D42 Ma Logithèque clé\gu5.120.0.145setup.exe"=0x5341435001000000000000000700000028000000D06D0E01DE0D0F010100000000000000000001060001000067077CBAC54CD40100000000000000000200000028000000000000000000004000000000000000000000000000000000F2740000000000000200000002000000 "SIGN.MEDIA=12E22D42 Ma Logithèque clé\Iperius6.2.0.0.exe"=0x534143500100000000000000070000002800000018291303C060130301000000000000000000000A0021000067077CBAC54CD40100000000000000000200000028000000000000000000000000000000000000000000000000000000F24D0000000000000100000001000000 "SIGN.MEDIA=12E22D42 Ma Logithèque clé\Skype-8.46.0.60.exe"=0x5341435001000000000000000700000028000000F07EC7032DAAC70301000000000000000000000A0021000067077CBAC54CD40100000000000000000200000028000000000000000000000000000000000000000000000000000000098B4901000000000100000001000000 "SIGN.MEDIA=12E22D42 Ma Logithèque clé\minitool_partition_wizard11.4-free.exe"=0x5341435001000000000000000700000028000000A00B86039CCB860301000000000000000000000A0021000067077CBAC54CD40100000000000000000200000028000000000000000000000000000000000000000000000000000000783C0100000000000100000001000000 "SIGN.MEDIA=407836CB Ma Logithèque clé\PILOTES\GeForce_Experience_v3.19.0.94.exe"=0x534143500100000000000000070000002800000030035D076F5D5D070100000000000000000002060001000067077CBAC54CD401000000000000000002000000280000000000000000000040000000000000000000000000000000005C310100000000000100000001000000 "SIGN.MEDIA=12E22D42 Ma Logithèque clé\FreemakeVideoConverterSetup4.1.10.253.exe"=0x534143500100000000000000070000002800000010700F00AA1310000100000000000000000002060001000067077CBAC54CD4010000000000000000 "SIGN.MEDIA=325BADC Ma Logithèque clé\gu5.121.0.46setup.exe"=0x534143500100000000000000070000002800000070630E0168130F010100000000000000000001060001000067077CBAC54CD401000000000000000002000000280000000000000000000040000000000000000000000000000000003CD21C00000000000100000001000000 "SIGN.MEDIA=325BADC Ma Logithèque clé\revouninstaller2.1.0.0setup.exe"=0x5341435001000000000000000700000028000000C8187100117F710001000000000000000000000A0021000067077CBAC54CD4010000000000000000020000002800000000000000000000000000000000000000000000000000000049690000000000000100000001000000 "SIGN.MEDIA=325BADC Ma Logithèque clé\Skype-8.47.0.59.exe"=0x534143500100000000000000070000002800000030E9C70383BEC80301000000000000000000000A0021000067077CBAC54CD401000000000000000002000000280000000000000000000000000000000000000000000000000000001E861900000000000100000001000000 "E:\Mes documents\Ma LOGITHEQUE portable Bollywood\backup-restore-0.85-portable\hbr.exe"=0x534143500100000000000000070000002800000000CA10000000000001000000000000000000000A75220000631F6E6F0EDED4010000000000000000020000002800000000000000000000000000000000000000000000000000000091B00700000000000800000008000000 "SIGN.MEDIA=325BADC Ma Logithèque clé\FreemakeVideoConverterSetup4.1.10.259.exe"=0x5341435001000000000000000700000028000000D86F0F005B2D10000100000000000000000002060001000067077CBAC54CD401000000000000000002000000280000000000000000000000000000000000000000000000000000009DAE2800000000000100000001000000 "SIGN.MEDIA=325BADC Ma Logithèque clé\flashplayer32pp_xa_install.exe"=0x5341435001000000000000000700000028000000286C12000A76120001000000000000000000000A0021000067077CBAC54CD4010000000000000000 "SIGN.MEDIA=325BADC Ma Logithèque clé\Firefox Installer66.0.5.exe"=0x5341435001000000000000000700000028000000E8630400526E040001000000000000000000000A0021000067077CBAC54CD40100000000000000000200000028000000000000000000000000000000000000000000000000000000B9EA0100000000000100000001000000 "C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exe"=0x5341435001000000000000000700000028000000705AE200741AE30001000000000000000000000A73220000631F6E6F0EDED4010000000000000000020000002800000000000000000000400000000000000000000000000000000003460D00000000000E0000000E000000 "SIGN.MEDIA=325BADC Ma Logithèque clé\VSDC_video_editor_x64_6.3.5.6.exe"=0x5341435001000000000000000700000028000000403F4B0463654B0401000000000000000000000A0021000067077CBAC54CD4010000000000000000020000002800000000000000000000000000000000000000000000000000000018370100000000000100000001000000 "SIGN.MEDIA=325BADC Ma Logithèque clé\splash_2_7_0_setup.exe"=0x534143500100000000000000070000002800000078FAA10251FDA1020100000000000000000001060001000067077CBAC54CD4010000000000000000 "SIGN.MEDIA=778E51C2 Ma Logithèque clé\Skype-8.48.0.51.exe"=0x5341435001000000000000000700000028000000507EC8032B32C90301000000000000000000000A0021000067077CBAC54CD401000000000000000002000000280000000000000000000000000000000000000000000000000000000DE51B00000000000100000001000000 "SIGN.MEDIA=58369DC Ma Logithèque clé\Iperius6.2.1.0.exe"=0x534143500100000000000000070000002800000050331303667F130301000000000000000000000A0021000067077CBAC54CD4010000000000000000020000002800000000000000000000000000000000000000000000000000000035890000000000000100000001000000 "SIGN.MEDIA=58369DC Ma Logithèque clé\gu5.122.0.147setup.exe"=0x5341435001000000000000000700000028000000488F0E0105C90E010100000000000000000001060001000067077CBAC54CD4010000000000000000 "SIGN.MEDIA=7DEB7C2 Ma Logithèque clé\ccsetup559.0.7230.exe"=0x5341435001000000000000000700000028000000B0183B0157E93B0101000000000000000000000A0021000067077CBAC54CD401000000000000000002000000280000000000000000000040000000000000000000000000000000001AD01200000000000100000001000000 "SIGN.MEDIA=407836CB Ma Logithèque clé\PILOTES\NVIDIA_GeForce_Experience_v3.19.0.107.exe"=0x5341435001000000000000000700000028000000A01F5C07B34C5C070100000000000000000002060001000067077CBAC54CD4010000000000000000020000002800000000000000000000400000000000000000000000000000000021EA0000000000000100000001000000 "SIGN.MEDIA=7DEB7C2 Ma Logithèque clé\FreemakeVideoConverterSetup4.1.10.282.exe"=0x5341435001000000000000000700000028000000486E0F000D2310000100000000000000000002060001000067077CBAC54CD4010000000000000000 "SIGN.MEDIA=7DEB7C2 Ma Logithèque clé\avast_free_antivirus_setup_offline19.6.2383.exe"=0x5341435001000000000000000700000028000000689B46155EB8461501000000000000000000000A0021000067077CBAC54CD401000000000000000002000000280000000000000000000040000000000000000000000000000000006E210100000000000100000001000000 "SIGN.MEDIA=7DEB7C2 Ma Logithèque clé\VSDC_video_editor_x64_6.3.5.8.exe"=0x534143500100000000000000070000002800000030AA4A04C42D4B0401000000000000000000000A0021000067077CBAC54CD40100000000000000000200000028000000000000000000000000000000000000000000000000000000E33F0100000000000100000001000000 "SIGN.MEDIA=7DEB7C2 Ma Logithèque clé\Iperius6.2.2.0.exe"=0x5341435001000000000000000700000028000000402B03035B7B030301000000000000000000000A0021000067077CBAC54CD4010000000000000000020000002800000000000000000000000000000000000000000000000000000088990500000000000100000001000000 "SIGN.MEDIA=796B13C Ma Logithèque clé\VSDC_video_editor_x64_6.3.5.13.exe"=0x5341435001000000000000000700000028000000689C4A049B784B0401000000000000000000000A0021000067077CBAC54CD4010000000000000000020000002800000000000000000000000000000000000000000000000000000003790100000000000100000001000000 "SIGN.MEDIA=796B13C Ma Logithèque clé\FoxitReader9.6.0.2514_L10N_Setup_Prom.exe"=0x5341435001000000000000000700000028000000003C7F0652AF7F0601000000000000000000000A0021000067077CBAC54CD401000000000000000002000000280000000000000000000000000000000000000000000000000000000F090200000000000100000001000000 "SIGN.MEDIA=796B13C Ma Logithèque clé\FreemakeVideoConverterSetup4.1.10.287.exe"=0x5341435001000000000000000700000028000000F06F0F00AAE80F000100000000000000000002060001000067077CBAC54CD4010000000000000000 "SIGN.MEDIA=796B13C Ma Logithèque clé\Minitool_partition wizard11.5-free.exe"=0x534143500100000000000000070000002800000058AE9103332B920301000000000000000000000A0021000067077CBAC54CD4010000000000000000020000002800000000000000000000000000000000000000000000000000000062730200000000000100000001000000 "SIGN.MEDIA=796B13C Ma Logithèque clé\FreemakeVideoConverterSetup4.1.10.291.exe"=0x5341435001000000000000000700000028000000C06E0F0049740F000100000000000000000002060001000067077CBAC54CD40100000000000000000200000028000000000000000000000000100000000000000000000000000000E552E92D000000000100000001000000 "SIGN.MEDIA=C0BA8F2B 0-A transférer sur PC TOUR Bollywood\flashplayer32ppau_ha_install.exe"=0x5341435001000000000000000700000028000000286C1200AE9D120001000000000000000000000A0021000067077CBAC54CD40100000000000000000200000028000000000000000000000000000000000000000000000000000000AB6B0000000000000100000001000000 "SIGN.MEDIA=796B13C Ma Logithèque clé\video_editor_x64_6.3.6.18.exe"=0x534143500100000000000000070000002800000038954B04301C4C0401000000000000000000000A0021000067077CBAC54CD4010000000000000000020000002800000000000000000000000000000000000000000000000000000066730100000000000100000001000000 "SIGN.MEDIA=796B13C Ma Logithèque clé\gu5setup5.123.0.148.exe"=0x5341435001000000000000000700000028000000200E0F0134670F010100000000000000000001060001000067077CBAC54CD4010000000000000000020000002800000000000000000000400000000000000000000000000000000049521D00000000000100000001000000 "SIGN.MEDIA=796B13C Ma Logithèque clé\Skype_v8.49.0.49.exe"=0x5341435001000000000000000700000028000000A061BB030B30BC0301000000000000000000000A0021000067077CBAC54CD401000000000000000002000000280000000000000000000000000000000000000000000000000000006CC31B00000000000100000001000000 "SIGN.MEDIA=796B13C Ma Logithèque clé\PatchMyPC4.1.0.3.exe"=0x534143500100000000000000070000002800000048761B00554F1C0001000000000000000000000A7522000067077CBAC54CD40100000000000000000200000028000000000000000000004000000000000000000000000000000000E28E0000000000000100000001000000 "C:\Program Files (x86)\Hard Disk Sentinel\HDSentinel.exe"=0x534143500100000000000000070000002800000010855300E10F540001000000000000000000000A61220000631F6E6F0EDED40100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000004000000000000000000000000000000000AF020000000000000500000005000000 "SIGN.MEDIA=796B13C Ma Logithèque clé\FreemakeVideoConverterSetup4.1.10.293.exe"=0x5341435001000000000000000700000028000000E86F0F00381710000100000000000000000002060001000067077CBAC54CD40100000000000000000200000028000000000000000000000000000000000000000000000000000000F6BE0100000000000200000002000000 "SIGN.MEDIA=D4F3812B 0-A transférer sur PC TOUR Bollywood\AdobeAIRInstaller (2).exe"=0x53414350010000000000000007000000280000005824B000CF5DB00001000000000000000000000A0021000067077CBAC54CD40100000000000000000200000028000000000000000000000000000000000000000000000000000000EC1F0000000000000100000001000000 "SIGN.MEDIA=796B13C Ma Logithèque clé\persoappscalendrier1.3.1.393.exe"=0x5341435001000000000000000700000028000000F887E9004050EA0001000000000000000000000A0021000067077CBAC54CD4010000000000000000020000002800000000000000000000000000000000000000000000000000000078CCB602000000000100000001000000 "SIGN.MEDIA=407836CB Ma Logithèque clé\PILOTES\Intel-Driver-and-Support-Assistant-Installer19.6.26.4.exe"=0x53414350010000000000000007000000280000006858DD008D1ADE0001000000000000000000000A0021000067077CBAC54CD40100000000000000000200000028000000000000000000000000000000000000000000000000000000A32D0100000000000100000001000000 "SIGN.MEDIA=796B13C Ma Logithèque clé\ccsetup560.7307.exe"=0x534143500100000000000000070000002800000048C73E01FBED3E0101000000000000000000000A0021000067077CBAC54CD4010000000000000000 "SIGN.MEDIA=796B13C Ma Logithèque clé\gu5.124setup.exe"=0x534143500100000000000000070000002800000058130F0144EE0F010100000000000000000001060001000067077CBAC54CD4010000000000000000 "SIGN.MEDIA=796B13C Ma Logithèque clé\FreeStudio_6.7.0.712_d.exe"=0x5341435001000000000000000700000028000000E8B18F0326EA8F0301000000000000000000000A0021000067077CBAC54CD4010000000000000000 "SIGN.MEDIA=796B13C Ma Logithèque clé\Skype_v8.50.0.38.exe"=0x534143500100000000000000070000002800000028FFC403872DC50301000000000000000000000A0021000067077CBAC54CD4010000000000000000020000002800000000000000000000000000000000000000000000000000000018CA1A00000000000100000001000000 "E:\Mes documents\Ma LOGITHEQUE portable Bollywood\naps2-6.1.2-portable\NAPS2.Portable.exe"=0x5341435001000000000000000700000028000000005600000000000001000000000000000000000A71220000631F6E6F0EDED4010000000000000000020000002800000000000000000000000000000000000000000000000000000017162B00000000000300000003000000 "SIGN.MEDIA=796B13C Ma Logithèque clé\FreemakeVideoConverterSetup4.1.10.296.exe"=0x5341435001000000000000000700000028000000B86E0F00B65D10000100000000000000000002060001000067077CBAC54CD40100000000000000000200000028000000000000000000000000100000000000000000000000000000E41AD400000000000100000001000000 "E:\Mes documents\Ma LOGITHEQUE portable Bollywood\wizfile_2_06_portable\WizFile64.exe"=0x53414350010000000000000007000000280000003831A00068EFA00001000000000000000000000A00210000631F6E6F0EDED40100000000000000000200000028000000000000000000000000000000000000000000000000000000E520D504000000000D0000000D000000 "SIGN.MEDIA=796B13C Ma Logithèque clé\iobituninstaller8.6.0.10.exe"=0x5341435001000000000000000700000028000000A86C290169B3290101000000000000000000000A0021000067077CBAC54CD401000000000000000002000000280000000000000000000000000000000000000000000000000000000A650200000000000100000001000000 "SIGN.MEDIA=796B13C Ma Logithèque clé\FreemakeVideoConverterSetup4.1.10.311.exe"=0x5341435001000000000000000700000028000000586E0F00CB4B10000100000000000000000002060001000067077CBAC54CD40100000000000000000200000028000000000000000000000000100000000000000000000000000000487D9601000000000100000001000000 "SIGN.MEDIA=796B13C Ma Logithèque clé\gu5.125.0.150setup.exe"=0x5341435001000000000000000700000028000000D0AA0F01383910010100000000000000000001060001000067077CBAC54CD4010000000000000000 "SIGN.MEDIA=796B13C Ma Logithèque clé\AOMEIPAssist_Std8.4.exe"=0x534143500100000000000000070000002800000020316B01D8886B010100000000000000000001060001000067077CBAC54CD40100000000000000000200000028000000000000000000004000000000000000000000000000000000A0800200000000000100000001000000 "C:\Program Files (x86)\AOMEI Partition Assistant\PartAssist.exe"=0x534143500100000000000000070000002800000058B47F00F66D800001000000000000000000000A71220000631F6E6F0EDED40100000000000000000200000028000000000000000000004000000000000000000000000000000000BBD30000000000000400000004000000 "SIGN.MEDIA=796B13C Ma Logithèque clé\AOMEI_Backupper_Standard_v5.0.exe"=0x5341435001000000000000000700000028000000F89C8D0627EE8D060100000000000000000001060001000067077CBAC54CD40100000000000000000200000028000000000000000000004000000000000000000000000000000000D2D80200000000000100000001000000 "C:\Program Files (x86)\Mirillis\Splash\Splash.exe"=0x5341435001000000000000000700000028000000883E8400792D85000100000000000000000002060001000067077CBAC54CD40100000000000000000200000028000000000000000000000004000000000000000000000000000000906C0100000000000200000002000000 "E:\Desktop\OUTILS\Outils Sécurité-Anti VIRUS-Réglages\msert1.0.3001.0_X64.exe"=0x534143500100000000000000070000002800000098C51607B897170701000000000000000000010600010000631F6E6F0EDED4010000000000000000050000001000000000000000000000000000000000000000020000002800000000000000000000000000000000000000000000000000000034620A00000000000100000001000000 "C:\ProgramData\IObit\IObit Uninstaller\Downloader\Db6\DriverBooster.exe.exe"=0x5341435001000000000000000700000028000000D0CF5001FD2F510101000000000000000000000A00210000631F6E6F0EDED4010000000000000000020000002800000000000000000000000000000000000000000000000000000017BC2200000000000100000001000000 "SIGN.MEDIA=2BBB85FC Ma Logithèque clé\persoapps_calendrier1.3.1.400.exe"=0x534143500100000000000000070000002800000060CD03014E15040101000000000000000000000A00210000631F6E6F0EDED4010000000000000000 "SIGN.MEDIA=2BBB85FC Ma Logithèque clé\install_flash_player.exe"=0x534143500100000000000000070000002800000018524501DCBF450101000000000000000000000A00210000631F6E6F0EDED401000000000000000002000000280000000000000000000040000000000000000000000000000000005E340000000000000100000001000000 "SIGN.MEDIA=2BBB85FC Ma Logithèque clé\Skype-8.51.0.72.exe"=0x5341435001000000000000000700000028000000089116047A3E170401000000000000000000000A00210000631F6E6F0EDED4010000000000000000 "SIGN.MEDIA=2BBB85FC Ma Logithèque clé\install_flash_player_ax.exe"=0x534143500100000000000000070000002800000018503D011B7F3D0101000000000000000000000A00210000631F6E6F0EDED4010000000000000000020000002800000000000000000000400000000000000000000000000000000023290000000000000100000001000000 "SIGN.MEDIA=407836CB Ma Logithèque clé\PILOTES\431.60-desktop-win10-64bit-international-whql.exe"=0x5341435001000000000000000700000028000000E839D621DA06D72101000000000000000000020600010000631F6E6F0EDED40100000000000000000200000028000000000000000000004000000000000000000000000000000000327C0400000000000100000001000000 "C:\Program Files\MiniTool Partition Wizard 11\partitionwizard.exe"=0x53414350010000000000000007000000280000002085DC00F6F8DC0001000000000000000000000A73220000631F6E6F0EDED401000000000000000002000000280000000000000000000040000000000000000000000000000000009DDF0100000000000100000001000000 "E:\Desktop\OUTILS\Outils Sécurité-Anti VIRUS-Réglages\Windows-KB890830-x64-V5.71.exe"=0x53414350010000000000000007000000280000002026A602E370A60201000000000000000000000A00210000631F6E6F0EDED4010000000000000000020000002800000000000000000000400000000000000000000000000000000094110000000000000200000002000000 "C:\Program Files (x86)\Microsoft Office\Office12\OUTLOOK.EXE"=0x5341435001000000000000000700000028000000D0CCC5007F3CC60001000000000000000000000A71220000631F6E6F0EDED4010000000100000000 "SIGN.MEDIA=2BBB85FC Ma Logithèque clé\FreemakeVideoConverterSetup_4.1.10.326.exe"=0x534143500100000000000000070000002800000068700F0032750F0001000000000000000000020600010000631F6E6F0EDED401000000000000000002000000280000000000000000000000000000000000000000000000000000009DBFCE00000000000100000001000000 "E:\Desktop\OUTILS\Outils Sécurité-Anti VIRUS-Réglages\stinger64.exe"=0x534143500100000000000000070000002800000088F40B01D5200C0101000000000000000000000A00210000631F6E6F0EDED4010000000000000000 "C:\Program Files (x86)\Icecream PDF Converter\pdfconverter.exe"=0x5341435001000000000000000700000028000000A0B62000F75C210001000000000000000000000A71220000631F6E6F0EDED40100000000000000000200000028000000000000000000000000000000000000000000000000000000A1550000000000000100000001000000 "SIGN.MEDIA=2BBB85FC Ma Logithèque clé\ccsetup561.7392.exe"=0x5341435001000000000000000700000028000000B8BD3E0153F33E0101000000000000000000000A00210000631F6E6F0EDED4010000000000000000 "SIGN.MEDIA=2BBB85FC Ma Logithèque clé\gu5.126.0.151setup.exe"=0x5341435001000000000000000700000028000000D8B10F01D6B90F0101000000000000000000010600010000631F6E6F0EDED4010000000000000000 "SIGN.MEDIA=2BBB85FC Ma Logithèque clé\Skype-8.51.0.86.exe"=0x534143500100000000000000070000002800000030A41604FDA9160401000000000000000000000A00210000631F6E6F0EDED4010000000000000000 "E:\Mes documents\Ma LOGITHEQUE portable Bollywood\vlc-3.0.8fr-win64\vlc-3.0.8\vlc.exe"=0x5341435001000000000000000700000028000000C80A0F00C3970F0001000000000000000000000600010000631F6E6F0EDED40100000000000000000200000028000000000000000000000000000000000000000000000000000000C57A6B00000000005901000059010000 "SIGN.MEDIA=2BBB85FC Ma Logithèque clé\iobituninstaller9.0.2.20.exe"=0x5341435001000000000000000700000028000000A8812001E967210101000000000000000000000A00210000631F6E6F0EDED401000000000000000002000000280000000000000000000000000000000000000000000000000000000C49E700000000000100000001000000 "SIGN.MEDIA=2BBB85FC Ma Logithèque clé\VSDC_video_editor_x64_6.3.8.46.exe"=0x534143500100000000000000070000002800000028DA5F043188600401000000000000000000000A00210000631F6E6F0EDED4010000000000000000 "SIGN.MEDIA=2BBB85FC Ma Logithèque clé\Skype-8.51.0.92.exe"=0x534143500100000000000000070000002800000088991604BA07170401000000000000000000000A00210000631F6E6F0EDED401000000000000000002000000280000000000000000000000000000000000000000000000000000009EA83001000000000100000001000000 "SIGN.MEDIA=2BBB85FC Ma Logithèque clé\iobituninstalle9.0.2.38.exe"=0x5341435001000000000000000700000028000000685B38015B43390101000000000000000000000A00210000631F6E6F0EDED401000000000000000002000000280000000000000000000000000000000000000000000000000000009F2F2401000000000100000001000000 "C:\Program Files (x86)\IObit\IObit Uninstaller\AUpdate.exe"=0x5341435001000000000000000700000028000000107D02003E92020001000000000000000000000A00210000631F6E6F0EDED401000000000000000005000000100000000000000000000000000000000000000002000000280000000000000000000000000000000000000000000000000000008D000000000000000900000009000000 "C:\Program Files (x86)\Digiarty\VideoProc\VideoProc.exe"=0x534143500100000000000000070000002800000098D3D401A2F4D40101000000000000000000000A71220000631F6E6F0EDED401000000000000000002000000280000000000000000000000000000000000000000000000000000004A9D0000000000000100000001000000 "SIGN.MEDIA=2BBB85FC Ma Logithèque clé\gu5.127.0.152setup.exe"=0x534143500100000000000000070000002800000070B40F01AB18100101000000000000000000010600010000631F6E6F0EDED4010000000000000000 "SIGN.MEDIA=2BBB85FC Ma Logithèque clé\Mozilla_Firefox_(64bit)_v69.0.exe"=0x5341435001000000000000000700000028000000F8EEF302A7F3F30201000000000000000000000A00210000631F6E6F0EDED401000000000000000002000000280000000000000000000000000000000000000000000000000000000EC10000000000000100000001000000 "C:\Program Files (x86)\EuroSoft Software Development\PersoApps Calendrier\calendar.exe"=0x5341435001000000000000000700000028000000D04C6C00DF906C0001000000000000000000000A00210000631F6E6F0EDED40100000000000000000200000028000000000000000000000000000000000000000000000000000000FA5DCE02000000000800000008000000 "SIGN.MEDIA=2BBB85FC Ma Logithèque clé\persoappsadressesv1.31.1278.exe"=0x5341435001000000000000000700000028000000306D1501F7A5150101000000000000000000000A00210000631F6E6F0EDED4010000000000000000020000002800000000000000000000000000000000000000000000000000000082350100000000000100000001000000 "SIGN.MEDIA=2BBB85FC Ma Logithèque clé\persoappscalendrierv1.31.400.exe"=0x534143500100000000000000070000002800000060CD03014E15040101000000000000000000000A00210000631F6E6F0EDED401000000000000000002000000280000000000000000000000000000000000000000000000000000003DBE8801000000000100000001000000 "SIGN.MEDIA=1D1304 HiSuiteDownLoader.exe"=0x5341435001000000000000000700000028000000C8DA1D009C1D1E0001000000000000000000000A71220000631F6E6F0EDED401000000000000000005000000100000000000000000000000000000008000000002000000500000000000000000000000000000000000000000000000000000006D1A00000000000005000000050000000000000080000000000000000000000000000000000000002B1F0100000000000100000000000000 "C:\Program Files (x86)\HiSuite\HiSuite.exe"=0x534143500100000000000000070000002800000050ED84003494850001000000000000000000000A71220000631F6E6F0EDED4010000000000000000020000002800000000000000000000000000000000000000000000000000000066090000000000000200000002000000 "C:\Program Files (x86)\EuroSoft Software Development\PersoApps Adresses\address.exe"=0x5341435001000000000000000700000028000000D0449B00FE0B9C0001000000000000000000000A00210000631F6E6F0EDED40100000000000000000200000028000000000000000000000000000000000000000000000000000000505CAD06000000001400000014000000 "SIGN.MEDIA=2BBB85FC Ma Logithèque clé\FreemakeVideoConverterFul4.1.10.354.exe"=0x534143500100000000000000070000002800000050A81703600E180301000000000000000000020600010000631F6E6F0EDED4010000000000000000 "SIGN.MEDIA=2BBB85FC Ma Logithèque clé\CPUIDhwmonitor_1.41.exe"=0x534143500100000000000000070000002800000078A313002DA5130001000000000000000000000A00210000631F6E6F0EDED401000000000000000002000000280000000000000000000000000000000000000000000000000000007F600000000000000100000001000000 "C:\Program Files\CPUID\HWMonitor\HWMonitor.exe"=0x534143500100000000000000070000002800000090FA250026ED260001000000000000000000000A00210000631F6E6F0EDED401000000000000000002000000280000000000000000000040000000000000000000000000000000008A590000000000000200000002000000 "C:\ProgramData\NVIDIA Corporation\Downloader\latest\setup.exe"=0x534143500100000000000000070000002800000028D207002C15080001000000000000000000000A00210000631F6E6F0EDED4010000000000000000020000002800000000000000000000000000000000000000000000000000000094810000000000000100000001000000 "SIGN.MEDIA=2BBB85FC Ma Logithèque clé\Iperius6.2.5.0.exe"=0x534143500100000000000000070000002800000060D60303301C040301000000000000000000000A00210000631F6E6F0EDED40100000000000000000200000028000000000000000000000000000000000000000000000000000000D2740000000000000100000001000000 "SIGN.MEDIA=2BBB85FC Ma Logithèque clé\KeePass-2.43-Setup.exe"=0x534143500100000000000000070000002800000068983200A00C330001000000000000000000000A00210000631F6E6F0EDED40100000000000000000200000028000000000000000000000000000000000000000000000000000000C95E0000000000000100000001000000 "SIGN.MEDIA=2BBB85FC Ma Logithèque clé\Skype-8.52.0.138.exe"=0x5341435001000000000000000700000028000000581617042792170401000000000000000000000A00210000631F6E6F0EDED4010000000000000000 "SIGN.MEDIA=2BBB85FC Ma Logithèque clé\iobituninstalle9.0.2.40.exe"=0x534143500100000000000000070000002800000048653801888B380101000000000000000000000A00210000631F6E6F0EDED401000000000000000002000000280000000000000000000000000000000000000000000000000000000F57D800000000000100000001000000 "SIGN.MEDIA=2BBB85FC Ma Logithèque clé\FreemakeVideoConverterSetup_4.1.10.374.exe"=0x5341435001000000000000000700000028000000906E0F00A059100001000000000000000000020600010000631F6E6F0EDED401000000000000000002000000280000000000000000000000001000000000000000000000000000008E4CBE00000000000100000001000000 "SIGN.MEDIA=2BBB85FC Ma Logithèque clé\shortcut-cleaner1.4.9.0.exe"=0x5341435001000000000000000700000028000000D03307005065070001000000000000000000000A71220000631F6E6F0EDED4010000000000000000020000002800000000000000000000400000000000000000000000000000000061170000000000000100000001000000 "C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe"=0x534143500100000000000000070000002800000050963200C663330001000000000000000000000A75220000631F6E6F0EDED401000000000000000002000000280000000000000000000000000000000000000000000000000000001E5E0000000000000200000002000000 "E:\Mes documents\Ma LOGITHEQUE portable Bollywood\Homedale1.85\Homedale.exe"=0x534143500100000000000000070000002800000010011C0038411C0001000000000000000000000A00210000631F6E6F0EDED4010000000000000000020000002800000000000000000000000000000000000000000000000000000074D40700000000000300000003000000 "E:\Desktop\OUTILS\Outils Sécurité-Anti VIRUS-Réglages\shortcut-cleaner1.4.9.0.exe"=0x5341435001000000000000000700000028000000D03307005065070001000000000000000000000A71220000631F6E6F0EDED40100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000004000000000000000000000000000000000F73F0000000000000200000002000000 "SIGN.MEDIA=2BBB85FC Ma Logithèque clé\avast_free_antivirus_setup_offline19.8.4793.0.exe"=0x5341435001000000000000000700000028000000D8457B1656DE7B1601000000000000000000000A00210000631F6E6F0EDED40100000000000000000200000028000000000000000000004000000000000000000000000000000000E7120100000000000100000001000000 "C:\Program Files\AVAST Software\Avast\AvastUI.exe"=0x53414350010000000000000007000000280000008811B900EC5AB90001000000000000000000000A00210000631F6E6F0EDED401000000000000000002000000280000000000000000000000000000000000000000000000000000007B030000000000000600000006000000 "SIGN.MEDIA=2BBB85FC Ma Logithèque clé\OBS-Studio-24.0.1-Full-Installer-x64.exe"=0x5341435001000000000000000700000028000000504A7704EB09780401000000000000000000000A00210000631F6E6F0EDED40100000000000000000200000028000000000000000000004000000000000000000000000000000000EE7F0000000000000100000001000000 "SIGN.MEDIA=2BBB85FC Ma Logithèque clé\videoproc3.4.exe"=0x534143500100000000000000070000002800000058EA1303AE8B140301000000000000000000010600010000631F6E6F0EDED4010000000000000000 "SIGN.MEDIA=2BBB85FC Ma Logithèque clé\FreemakeVideoConverterSetup_4.1.10.383.exe"=0x5341435001000000000000000700000028000000886E0F00D165100001000000000000000000020600010000631F6E6F0EDED4010000000000000000 "SIGN.MEDIA=5DE27E66 Ma Logitheque Portable clé\windowskey.exe"=0x534143500100000000000000070000002800000068BE0300A60B040001000000000000000000000A75220000631F6E6F0EDED4010000000000000000020000002800000000000000000000000000000000000000000000000000000009370100000000000200000002000000 "SIGN.MEDIA=5DE27E66 Ma Logitheque Portable clé\adwcleaner_7.4.1.exe"=0x5341435001000000000000000700000028000000C84E7400096F740001000000000000000000000A00210000631F6E6F0EDED40100000000000000000200000028000000000000000000004000000000000000000000000000000000F5130000000000000100000001000000 "SIGN.MEDIA=2BBB85FC Ma Logithèque clé\FreemakeVideoConverterFull_4.1.10.384.exe"=0x5341435001000000000000000700000028000000C8A1170358D8170301000000000000000000020600010000631F6E6F0EDED4010000000000000000 "C:\Program Files\Intel\SUR\ICIP\SurConsent.exe"=0x534143500100000000000000070000002800000038810700122D080001000000000000000000000A00210000631F6E6F0EDED40100000000000000000200000028000000000000000000004000000000000000000000000000000000C5640000000000000100000001000000 "SIGN.MEDIA=2BBB85FC Ma Logithèque clé\VSDC_video_editor_x64_6.3.9.49.exe"=0x534143500100000000000000070000002800000008D85F04CFCA600401000000000000000000000A00210000631F6E6F0EDED40100000000000000000200000028000000000000000000000000000000000000000000000000000000C0570100000000000100000001000000 "SIGN.MEDIA=2BBB85FC Ma Logithèque clé\FreemakeVideoConverterSetup_4.1.10.387.exe"=0x5341435001000000000000000700000028000000206E0F00D8E00F0001000000000000000000020600010000631F6E6F0EDED401000000000000000002000000280000000000000000000000001000000000000000000000000000006BE65901000000000100000001000000 "SIGN.MEDIA=2BBB85FC Ma Logithèque clé\FoxitReader9.7.0.29455._L10N_Setup_Prom.exe"=0x534143500100000000000000070000002800000018789906AEA9990601000000000000000000000A00210000631F6E6F0EDED40100000000000000000200000028000000000000000000000000000000000000000000000000000000F0CC0100000000000200000002000000 "C:\Program Files (x86)\Freemake\Freemake Video Converter\FreemakeVideoConverter.exe"=0x534143500100000000000000070000002800000080F51F002AE4200001000000000000000000000A71220000631F6E6F0EDED401000000000000000002000000280000000000000000000000000000000000000000000000000000006E070100000000000100000001000000 "C:\Users\EVRARD\AppData\Local\HiSuite\userdata\LiveUpdateHisuite\full\HiSuite V500R001B007D30SP00C06\870657969B710891\HiSuite_9.1.0.309_OVE.exe"=0x5341435001000000000000000700000028000000E85E37020F52380201000000000000000000010600010000631F6E6F0EDED40100000000000000000200000028000000000000000000004000000000000000000000000000000000F5B88D07000000000100000001000000 "SIGN.MEDIA=2BBB85FC Ma Logithèque clé\AOMEIPAssist_Std8.4.exe"=0x5341435001000000000000000700000028000000E8326B0131D66B0101000000000000000000010600010000631F6E6F0EDED40100000000000000000200000028000000000000000000004000000000000000000000000000000000CA920000000000000100000001000000 "SIGN.MEDIA=2BBB85FC Ma Logithèque clé\Skype-8.53.0.85.exe"=0x534143500100000000000000070000002800000068141B04A8D21B0401000000000000000000000A00210000631F6E6F0EDED4010000000000000000 "SIGN.MEDIA=2BBB85FC Ma Logithèque clé\ccsetup562.7538.exe"=0x534143500100000000000000070000002800000010368401CE54840101000000000000000000000A00210000631F6E6F0EDED4010000000000000000020000002800000000000000000000400000000000000000000000000000000035400000000000000100000001000000 "SIGN.MEDIA=2BBB85FC Ma Logithèque clé\FreemakeVideoConverterSetup_4.1.10.409.exe"=0x5341435001000000000000000700000028000000F86D0F00B5F80F0001000000000000000000020600010000631F6E6F0EDED401000000000000000002000000280000000000000000000000001000000000000000000000000000007DB45500000000000100000001000000 "SIGN.MEDIA=2BBB85FC Ma Logithèque clé\OBS-Studio-24.0.3-Full-Installer-x64.exe"=0x534143500100000000000000070000002800000088F07704DF45780401000000000000000000000A00210000631F6E6F0EDED40100000000000000000200000028000000000000000000004000000000000000000000000000000000ED870000000000000100000001000000 "C:\Program Files (x86)\obs-studio\bin\64bit\obs64.exe"=0x5341435001000000000000000700000028000000101A3300FA61330001000000000000000000000A73220000631F6E6F0EDED40100000000000000000200000028000000000000000000000000000000000000000000000000000000B3400000000000000100000001000000 "SIGN.MEDIA=2BBB85FC Ma Logithèque clé\flashplayer32pp_xa_install.exe"=0x5341435001000000000000000700000028000000286C12007448130001000000000000000000000A00210000631F6E6F0EDED401000000000000000002000000280000000000000000000000000000000000000000000000000000008E330100000000000100000001000000 "SIGN.MEDIA=407836CB Ma Logithèque clé\PILOTES\436.48-desktop-win10-64bit-international-whql.exe"=0x534143500100000000000000070000002800000050F7AE2374BFAF2301000000000000000000020600010000631F6E6F0EDED4010000000000000000020000002800000000000000000000400000000000000000000000000000000044930400000000000100000001000000 "C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe"=0x534143500100000000000000070000002800000028FA090076DD0A0001000000000000000000000A71200000631F6E6F0EDED4010000000000000000020000002800000000000000800000000000000000000000000000000000000092140000000000000300000003000000 "SIGN.MEDIA=2BBB85FC Ma Logithèque clé\Iperius6.3.0.0.exe"=0x5341435001000000000000000700000028000000803D3203505C320301000000000000000000000A00210000631F6E6F0EDED40100000000000000000200000028000000000000000000000000000000000000000000000000000000C708E101000000000100000001000000 "SIGN.MEDIA=2BBB85FC Ma Logithèque clé\gu5.129.0.155setup.exe"=0x5341435001000000000000000700000028000000E0411001854F100101000000000000000000010600010000631F6E6F0EDED40100000000000000000200000028000000000000000000004000000000000000000000000000000000858E0000000000000100000001000000 "C:\Program Files (x86)\AlterPDF\alterpdf.exe"=0x534143500100000000000000070000002800000000AEF8000000000001000000000000000000000A71220000631F6E6F0EDED4010000000000000000020000002800000000000000000000000000000000000000000000000000000098540000000000000300000003000000 "C:\Program Files (x86)\IObit\IObit Uninstaller\Pub\PreMalScn.exe"=0x534143500100000000000000070000002800000010C12400216F250001000000000000000000000A00210000631F6E6F0EDED40100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000000000000000000000000000000000000000B2492B03000000001600000016000000 "C:\Program Files\CCleaner\CCleaner64.exe"=0x534143500100000000000000070000002800000080A276011235770101000000000000000000000A00210000631F6E6F0EDED40100000000000000000200000028000000000000000000000000000000000000000000000000000000B5010000000000000900000009000000 "E:\Mes documents\Ma LOGITHEQUE portable Bollywood\sepdf324\SepPDF.exe"=0x534143500100000000000000070000002800000000D6040074B8050001000000000000000000000A71220000631F6E6F0EDED401000000000000000002000000280000000000000000000000000000000000000000000000000000006F2C0000000000000200000002000000 "C:\Program Files (x86)\Foxit Software\Foxit Reader\FoxitReader.exe"=0x5341435001000000000000000700000028000000D05B8C056FAA8C0501000000000000000000000A00210000631F6E6F0EDED4010000000000000000020000002800000000000000000000100000000000000000000000000000000073BE3A00000000002701000027010000 "SIGN.MEDIA=2BBB85FC Ma Logithèque clé\gu5.130.0.156setup.exe"=0x5341435001000000000000000700000028000000185010011DCC100101000000000000000000010600010000631F6E6F0EDED4010000000000000000020000002800000000000000000000400000000000000000000000000000000003EA2400000000000100000001000000 "SIGN.MEDIA=2BBB85FC Ma Logithèque clé\iobituninstaller9.1.0.8.exe"=0x5341435001000000000000000700000028000000609F3A010BB03A0101000000000000000000000A00210000631F6E6F0EDED401000000000000000002000000280000000000000000000000000000000000000000000000000000009B6D0400000000000100000001000000 "SIGN.MEDIA=2BBB85FC Ma Logithèque clé\AOMEIPAssist_Std8.5.exe"=0x5341435001000000000000000700000028000000D0E973014CE1740101000000000000000000010600010000631F6E6F0EDED4010000000000000000 "SIGN.MEDIA=2BBB85FC Ma Logithèque clé\iobituninstaller9.1.0.11.exe"=0x534143500100000000000000070000002800000028123A019E1A3A0101000000000000000000000A00210000631F6E6F0EDED401000000000000000002000000280000000000000000000000000000000000000000000000000000001F1D3100000000000100000001000000 "SIGN.MEDIA=2BBB85FC Ma Logithèque clé\Iperius6.3.1.0.exe"=0x534143500100000000000000070000002800000090E43D03D50D3E0301000000000000000000000A00210000631F6E6F0EDED40100000000000000000200000028000000000000000000000000000000000000000000000000000000B5243000000000000100000001000000 "E:\Mes documents\Ma LOGITHEQUE portable Bollywood\GetWindowText_x64_3.31\GetWindowText_x64.exe"=0x53414350010000000000000007000000280000007895020069D3020001000000000000000000000A73220000631F6E6F0EDED40100000000000000000200000028000000000000000000000000000000000000000000000000000000B4CF0000000000000100000001000000 "E:\Mes documents\Ma LOGITHEQUE portable Bollywood\ramexpert1.12.0.29\ramexpert\RAMExpert.exe"=0x5341435001000000000000000700000028000000B0951800D7FC180001000000000000000000000A61200000631F6E6F0EDED4010000000000000000020000002800000000000000000000000000000000000000000000000000000054580600000000000200000002000000 "C:\Users\EVRARD\AppData\Local\Microsoft\OneDrive\19.174.0902.0013\FileSyncConfig.exe"=0x5341435001000000000000000700000028000000789E0500CD91060001000000000000000000000A00210000631F6E6F0EDED4010000000100000000 "C:\Program Files\FlashIntegro\VideoEditor\Tools\VideoCapture.exe"=0x53414350010000000000000007000000280000008855540009FE540001000000000000000000000A73220000631F6E6F0EDED401000000000000000002000000280000000000000000000000000000000000000000000000000000009C270000000000000100000001000000 "SIGN.MEDIA=2BBB85FC Ma Logithèque clé\NETGEARGenie-install2.4.62.exe"=0x5341435001000000000000000700000028000000C060D0025B62D00201000000000000000000010671000000631F6E6F0EDED401000000000000000002000000280000000000000000080040000000000000000000000000000000006B595601000000000200000002000000 "SIGN.MEDIA=2BBB85FC Ma Logithèque clé\Skype-8.54.0.85.exe"=0x534143500100000000000000070000002800000020681D04C6C61D0401000000000000000000000A00210000631F6E6F0EDED4010000000000000000 "E:\Mes documents\Ma LOGITHEQUE portable Bollywood\HDCleanerX64_1.277\HDCleaner.exe"=0x534143500100000000000000070000002800000050702F00644C300001000000000000000000000A73220000631F6E6F0EDED4010000000000000000050000001000000000000000000000000000000000000000020000002800000000000000000000000400000000000000000000000000000001E31300000000000400000004000000 "E:\Desktop\OUTILS\Outils Audio-Photo-Video\LosslessCut-2.6.1.exe"=0x5341435001000000000000000700000028000000710218040000000001000000000000000000000A00210000631F6E6F0EDED401000000000000000002000000280000000000000000000000000000000000000000000000000000002D717C00000000000100000001000000 "SIGN.MEDIA=2BBB85FC Ma Logithèque clé\MolotovSetup-4.2.0.exe"=0x534143500100000000000000070000002800000098EA00040F01010401000000000000000000030600010000631F6E6F0EDED401000000000000000002000000280000000000000000000000000000000000000000000000000000001E2D1D00000000000100000001000000 "SIGN.MEDIA=2BBB85FC Ma Logithèque clé\FreemakeVideoConverterSetup_4.1.10.415.exe"=0x5341435001000000000000000700000028000000D86F0F00383B100001000000000000000000020600010000631F6E6F0EDED4010000000000000000 "SIGN.MEDIA=407836CB Ma Logithèque clé\PILOTES\441.12-desktop-win10-64bit-international-whql.exe"=0x5341435001000000000000000700000028000000382F022428AC022401000000000000000000020600010000631F6E6F0EDED40100000000000000000200000028000000000000000000004000000000000000000000000000000000F40A0500000000000100000001000000 "SIGN.MEDIA=2BBB85FC Ma Logithèque clé\MBSetup4.0.0.108.exe"=0x534143500100000000000000070000002800000048BF1C00B54D1D0001000000000000000000000A00210000631F6E6F0EDED40100000000000000000200000028000000000000000000004000000000000000000000000000000000E7280600000000000100000001000000 "C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe"=0x53414350010000000000000007000000280000008823FC0027DAFC0001000000000000000000000A71220000631F6E6F0EDED4010000000000000000020000002800000000000000000000000000000000000000000000000000000067300000000000000200000002000000 "C:\Users\EVRARD\AppData\Local\Vivaldi\Application\vivaldi.exe"=0x534143500100000000000000070000002800000048181B0026541B0001000000000000000000000A00210000631F6E6F0EDED4010000000000000000 "C:\ProgramData\NVIDIA Corporation\Downloader\a38c26e8cedf16bc38244aa77febc13a\GeForce_Experience_Update_v3.20.1.57_Official_B09EB8.exe"=0x5341435001000000000000000700000028000000C80A4507806E450701000000000000000000020600010000631F6E6F0EDED401000000000000000002000000280000000000000000000000000000000000000000000000000000005BA20000000000000100000001000000 "C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe"=0x534143500100000000000000070000002800000028623200313E330001000000000000000000000A00210000631F6E6F0EDED4010000000000000000 "E:\Mes documents\Ma LOGITHEQUE portable Bollywood\CrystalDiskInfo8_3_2\DiskInfo64.exe"=0x534143500100000000000000070000002800000038C049001F784A0001000000000000000000000A00210000631F6E6F0EDED401000000000000000005000000100000000000000000000000000000000000000002000000280000000000000000000040000000000000000000000000000000005C1D0000000000000100000001000000 "SIGN.MEDIA=2BBB85FC Ma Logithèque clé\Skype-8.54.0.91.exe"=0x5341435001000000000000000700000028000000F8801D040B6E1E0401000000000000000000000A00210000631F6E6F0EDED4010000000000000000 "C:\ProgramData\IObit\IObit Uninstaller\Downloader\un\Driver Booster_IU.exe"=0x534143500100000000000000070000002800000008C87301CBA1740101000000000000000000000A00210000631F6E6F0EDED4010000000000000000020000002800000000000000000000000000000000000000000000000000000056AB0600000000000100000001000000 "E:\Mes documents\Ma LOGITHEQUE portable Bollywood\captvty-2.8.5\Captvty.exe"=0x534143500100000000000000070000002800000000EE3B000000000001000000000000000000000A71220000631F6E6F0EDED4010000000000000000020000002800000000000000000000000000000000000000000000000000000079DC1D00000000000400000004000000 "E:\Mes documents\Ma LOGITHEQUE portable Bollywood\captvty-3.0.0.64718\Captvty.exe"=0x534143500100000000000000070000002800000000AC53000000000001000000000000000000000A00210000631F6E6F0EDED40100000000000000000200000028000000000000000000000000000000000000000000000000000000B5D14A02000000000300000003000000 "E:\Mes documents\Ma LOGITHEQUE portable Bollywood\sumo5.10.3.438\sumo\SUMo.exe"=0x5341435001000000000000000700000028000000B0532000A584200001000000000000000000000A61200000631F6E6F0EDED40100000000000000000200000028000000000000000000000000000000000000000000000000000000A6E15403000000001400000014000000 "SIGN.MEDIA=2BBB85FC Ma Logithèque clé\driver_booster_setup7.1.0.534.exe"=0x534143500100000000000000070000002800000090B573012C13740101000000000000000000000A00210000631F6E6F0EDED40100000000000000000200000028000000000000000000000000000000000000000000000000000000CD058401000000000100000001000000 "E:\Desktop\OUTILS\Outils Sécurité-Anti VIRUS-Réglages\adwcleaner_7.4.2.exe"=0x5341435001000000000000000700000028000000C84E7400267A740001000000000000000000000A00210000631F6E6F0EDED4010000000000000000 "SIGN.MEDIA=2BBB85FC Ma Logithèque clé\iobituninstaller9.1.0.13.exe"=0x5341435001000000000000000700000028000000A08E3B0140453C0101000000000000000000000A00210000631F6E6F0EDED4010000000000000000 "E:\Mes documents\Ma LOGITHEQUE portable Bollywood\uninstallview-x64-1.33\UninstallView.exe"=0x534143500100000000000000070000002800000068D302006EDA020001000000000000000000000A00210000631F6E6F0EDED40100000000000000000200000028000000000000000000000000000000000000000000000000000000AD5B0000000000000200000002000000 "C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe"=0x534143500100000000000000070000002800000010E55900B8AF5A0001000000000000000000000A00210000631F6E6F0EDED401000000000000000002000000280000000000000000000000000000000000000000000000000000009A030000000000000200000002000000 "E:\Mes documents\Ma LOGITHEQUE portable Bollywood\alterpdf3.8\setup.exe"=0x5341435001000000000000000700000028000000647208010000000001000000000000000000000A00210000631F6E6F0EDED40100000000000000000200000028000000000000000000000000000000000000000000000000000000D77B0000000000000100000001000000 "E:\Desktop\OUTILS\Outils Audio-Photo-Video\LosslessCut-2.6.2.exe"=0x5341435001000000000000000700000028000000DDF517040000000001000000000000000000000A00210000631F6E6F0EDED40100000000000000000200000028000000000000000000000000000000000000000000000000000000A9660000000000000100000001000000 "C:\Program Files\FlashIntegro\VideoEditor\Tools\ScreenRecorder.exe"=0x5341435001000000000000000700000028000000882955006BFB550001000000000000000000000A73220000631F6E6F0EDED40100000000000000000200000028000000000000000000000000000000000000000000000000000000582F0100000000000100000001000000 "SIGN.MEDIA=2BBB85FC Ma Logithèque clé\LosslessCut-2.6.2.exe"=0x5341435001000000000000000700000028000000DDF517040000000001000000000000000000000A00210000631F6E6F0EDED4010000000000000000 "E:\Mes documents\Ma LOGITHEQUE portable Bollywood\CDBurnerXP-4.5.8.7128\cdbxpp.exe"=0x534143500100000000000000070000002800000078A21A00C55D1B0001000000000000000000000A00210000631F6E6F0EDED40100000000000000000200000028000000000000000000000000000000000000000000000000000000B4160000000000000100000001000000 "E:\Mes documents\0-A transférer sur Portable ou clé ou classer ou envoyer\VSDCvideo_editor_x64_6.4.0.58.exe"=0x534143500100000000000000070000002800000078086C0466926C0401000000000000000000000A00210000631F6E6F0EDED4010000000000000000020000002800000000000000000000000000000000000000000000000000000052790100000000000100000001000000 "E:\Mes documents\0-A transférer sur Portable ou clé ou classer ou envoyer\Eraser_6.2.0.2986.exe"=0x5341435001000000000000000700000028000000C8A68103CEEF810301000000000000000000000A71220000631F6E6F0EDED401000000000000000002000000280000000000000000000040000000000000000000000000000000004D1C0100000000000100000001000000 "E:\Mes documents\0-A transférer sur Portable ou clé ou classer ou envoyer\Unlocker1.9.2.exe"=0x53414350010000000000000007000000280000003F7510000000000001000000000000000000010600010000631F6E6F0EDED401000000000000000002000000280000000000000000000040000000000000000000000000000000005A410100000000000100000001000000 "E:\Mes documents\0-A transférer sur Portable ou clé ou classer ou envoyer\FreemakeVideoConverterSetup_4.1.10.446.exe"=0x5341435001000000000000000700000028000000C06E0F000F920F0001000000000000000000020600010000631F6E6F0EDED4010000000000000000020000002800000000000000000000000000000000000000000000000000000096EE2E00000000000100000001000000 "E:\Mes documents\0-A transférer sur Portable ou clé ou classer ou envoyer\FreemakeVideoConverterFull4.1.10.460.exe"=0x5341435001000000000000000700000028000000F0FD17033152180301000000000000000000020600010000631F6E6F0EDED4010000000000000000 "SIGN.MEDIA=2BBB85FC Ma Logithèque clé\videoproc3.5.0.0.exe"=0x534143500100000000000000070000002800000010471403E43E150301000000000000000000010600010000631F6E6F0EDED40100000000000000000200000028000000000000000000000000000000000000000000000000000000A1840000000000000100000001000000 "E:\Mes documents\Ma LOGITHEQUE portable Bollywood\captvty-2.8.5.1\Captvty.exe"=0x534143500100000000000000070000002800000000E83B000000000001000000000000000000000A71220000631F6E6F0EDED40100000000000000000200000028000000000000000000000000000000000000000000000000000000C3D10400000000000100000001000000 "SIGN.MEDIA=2BBB85FC Ma Logithèque clé\VSDCvideo_editor_x64_6.4.1.62.exe"=0x5341435001000000000000000700000028000000E8246B04D8CF6B0401000000000000000000000A00210000631F6E6F0EDED40100000000000000000200000028000000000000000000000000000000000000000000000000000000444F0100000000000100000001000000 "C:\Users\EVRARD\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe"=0x5341435001000000000000000700000028000000685F170268B1170201000000000000000000000A00210000631F6E6F0EDED4010000000100000000 "C:\Users\EVRARD\AppData\Local\Microsoft\OneDrive\19.192.0926.0012\FileSyncConfig.exe"=0x5341435001000000000000000700000028000000688F05001F71060001000000000000000000000A00210000631F6E6F0EDED4010000000100000000 "SIGN.MEDIA=2BBB85FC Ma Logithèque clé\gu5.132.0.158setup.exe"=0x534143500100000000000000070000002800000058841201CDB0120101000000000000000000010600010000631F6E6F0EDED40100000000000000000200000028000000000000000000004000000000000000000000000000000000CE5E2000000000000100000001000000 "SIGN.MEDIA=2BBB85FC Ma Logithèque clé\iobituninstaller9.2.0.13.exe"=0x534143500100000000000000070000002800000090AA4B0143F44B0101000000000000000000000A00210000631F6E6F0EDED4010000000000000000020000002800000000000000000000000000000000000000000000000000000096391C00000000000100000001000000 "C:\Program Files (x86)\MyHeritage\Bin\MyHeritage.exe"=0x534143500100000000000000070000002800000070380D021EF50D0201000000000000000000000A71220000631F6E6F0EDED4010000000000000000020000002800000000000000000000000000000000000000000000000000000075F50800000000000200000002000000 "SIGN.MEDIA=2BBB85FC Ma Logithèque clé\MolotovSetup-4.2.1.exe"=0x534143500100000000000000070000002800000098EC0004E5B8010401000000000000000000030600010000631F6E6F0EDED4010000000000000000020000002800000000000000000000000000000000000000000000000000000000E95400000000000100000001000000 "SIGN.MEDIA=2BBB85FC Ma Logithèque clé\VSDC_video_editor_x64_6.4.1.65.exe"=0x534143500100000000000000070000002800000048076B0474AC6B0401000000000000000000000A00210000631F6E6F0EDED4010000000000000000 "C:\Program Files (x86)\Intel\Driver and Support Assistant\DSAServiceHelper.exe"=0x534143500100000000000000070000002800000068D90000BD4A010001000000000000000000000A75220000631F6E6F0EDED4010000000000000000 "E:\Desktop\OUTILS\Outils Sécurité-Anti VIRUS-Réglages\adwcleaner_8.0.0.exe"=0x5341435001000000000000000700000028000000B0687D00572A7E0001000000000000000000000A00210000631F6E6F0EDED4010000000000000000 "C:\Program Files (x86)\Glary Utilities 5\Integrator.exe"=0x5341435001000000000000000700000028000000F8FB0D00004C0E0001000000000000000000000A71220000631F6E6F0EDED4010000000000000000 "E:\Desktop\OUTILS\Outils Sécurité-Anti VIRUS-Réglages\KVRT_15.0.22.0.exe"=0x53414350010000000000000007000000280000002839F6097846F60901000000000000000000000A00210000631F6E6F0EDED40100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000004000000000000000000000000000000000E6340100000000000100000001000000 "E:\Desktop\OUTILS\Outils Sécurité-Anti VIRUS-Réglages\KVRT.exe"=0x5341435001000000000000000700000028000000B8BF8C0A514D8D0A01000000000000000000000A00210000631F6E6F0EDED4010000000000000000050000001000000000000000000000000000000000000000020000002800000000000000000000400000000000000000000000000000000072D50300000000000100000001000000 "E:\Mes documents\Ma LOGITHEQUE portable Bollywood\HDCleanerX64_1.2.7.8\HDCleaner.exe"=0x534143500100000000000000070000002800000050702F008FF02F0001000000000000000000000A73220000631F6E6F0EDED4010000000000000000050000001000000000000000000000000000000000000000020000002800000000000000000000000000000000000000000000000000000083E60100000000000100000001000000 "SIGN.MEDIA=2BBB85FC Ma Logithèque clé\iobituninstaller9.2.0.14.exe"=0x5341435001000000000000000700000028000000B84E4B015ECF4B0101000000000000000000000A00210000631F6E6F0EDED4010000000000000000020000002800000000000000000000000000000000000000000000000000000095953C00000000000100000001000000 "C:\Program Files (x86)\Hard Disk Sentinel\HDSCtrl.exe"=0x534143500100000000000000070000002800000010110400D8AD040001000000000000000000000A61220000631F6E6F0EDED4010000000000000000050000001000000000000000000000000000000000000000020000002800000000000000000000400000020000000000000000000000000018230000000000000200000002000000 "SIGN.MEDIA=2BBB85FC Ma Logithèque clé\Karens-Directory-Printer-v5.4.3-Setup.exe"=0x53414350010000000000000007000000280000005032140030CB140001000000000000000000000A00210000631F6E6F0EDED40100000000000000000200000028000000000000000000004000000000000000000000000000000000DC750000000000000100000001000000 "C:\Program Files (x86)\Karen's Power Tools\Directory Printer\DirPrn.exe"=0x534143500100000000000000070000002800000000000F00BAB50F0001000000000000000000000A71220000631F6E6F0EDED401000000000000000002000000280000000000000000000000000000000000000000000000000000001C586E00000000000400000004000000 "C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe"=0x5341435001000000000000000700000028000000C88C05001938060001000000000000000000000A00210000631F6E6F0EDED4010000000000000000020000002800000000000000000000000000000000000000000000000000000085849802000000004D0000004D000000 "E:\Mes documents\0-A transférer sur Portable ou clé ou classer ou envoyer\family_tree_builder_8563.exe"=0x5341435001000000000000000700000028000000F8D5500612D9500601000000000000000000010600010000631F6E6F0EDED4010000000000000000020000002800000000000000000000400000000000000000000000000000000078AC0100000000000100000001000000 "E:\Mes documents\0-A transférer sur Portable ou clé ou classer ou envoyer\video_editor_x64_6.4.1.69.exe"=0x5341435001000000000000000700000028000000B8426504C082650401000000000000000000000A00210000631F6E6F0EDED40100000000000000000200000028000000000000000000000000000000000000000000000000000000020C0100000000000100000001000000 "E:\Mes documents\Ma LOGITHEQUE portable Bollywood\captvty-2.8.6.1\Captvty.exe"=0x534143500100000000000000070000002800000000F03B000000000001000000000000000000000A71220000631F6E6F0EDED4010000000000000000020000002800000000000000000000000000000000000000000000000000000096A05200000000000200000002000000 "C:\Program Files\Mozilla Firefox\firefox.exe"=0x5341435001000000000000000700000028000000C8A608006C11090001000000000000000000000A00210000631F6E6F0EDED4010000000100000000 "C:\Windows\System32\spool\drivers\x64\3\ssm4mei.exe"=0x534143500100000000000000070000002800000018C103006C56040001000000000000000000000A73220000631F6E6F0EDED40100000000000000000200000028000000000000000000000000000000000000000000000000000000C8120100000000000400000004000000 "SIGN.MEDIA=2BBB85FC Ma Logithèque clé\gu5.133.0.159setup.exe"=0x53414350010000000000000007000000280000001891120156DD120101000000000000000000010600010000631F6E6F0EDED40100000000000000000200000028000000000000000000004000000000000000000000000000000000036A9100000000000100000001000000 "E:\Mes documents\Ma LOGITHEQUE portable Bollywood\sumo5.10.4.439\sumo\SUMo.exe"=0x5341435001000000000000000700000028000000B0532000CA8F200001000000000000000000000A61200000631F6E6F0EDED40100000000000000000200000028000000000000000000000000000000000000000000000000000000837CFA00000000000900000009000000 "SIGN.MEDIA=2BBB85FC Ma Logithèque clé\Iperius6.3.3.0.exe"=0x534143500100000000000000070000002800000018724E03D6234F0301000000000000000000000A00210000631F6E6F0EDED4010000000000000000020000002800000000000000000000000000000000000000000000000000000031870000000000000100000001000000 "SIGN.MEDIA=604BC4D6 Ma Logitheque Portable clé\DRwebcureit.exe"=0x534143500100000000000000070000002800000000E93E0CF6B53F0C01000000000000000000030600010000631F6E6F0EDED40100000000000000000200000028000000000000000000004000000000000000000000000000000000437F1700000000000100000001000000 "SIGN.MEDIA=299A90 Ma Logitheque Portable clé\SSDFRESH2019 NOUVELLE TRADUCTION\SSDF\ssdfresh free.exe"=0x5341435001000000000000000700000028000000909A29005E592A0001000000000000000000000A00210000631F6E6F0EDED4010000000000000000020000002800000000000000000000000000000000000000000000000000000033040400000000000100000001000000 "C:\Program Files (x86)\SSDFresh\AbLauncher.exe"=0x5341435001000000000000000700000028000000E84500005648000001000000000000000000000A75220000631F6E6F0EDED40100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000000000000000000000000000000000000000550A0900000000000500000005000000 "SIGN.MEDIA=2BBB85FC Ma Logithèque clé\flashplayer32pp_a_install.exe"=0x5341435001000000000000000700000028000000286C1200F6B5120001000000000000000000000A00210000631F6E6F0EDED40100000000000000000200000028000000000000000000000000000000000000000000000000000000397E0000000000000100000001000000 "SIGN.MEDIA=2BBB85FC Ma Logithèque clé\readerdc_fr_xa_install.exe"=0x5341435001000000000000000700000028000000305A12000224130001000000000000000000000A00210000631F6E6F0EDED40100000000000000000200000028000000000000000000000000000000000000000000000000000000FB290400000000000100000001000000 "C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe"=0x5341435001000000000000000700000028000000304E2800383B290001000000000000000000000A00210000631F6E6F0EDED40100000000000000000200000028000000000000000000001000000000000000000000000000000000C00F0000000000000100000001000000 "SIGN.MEDIA=2BBB85FC Ma Logithèque clé\winrar-x64-580.exe"=0x5341435001000000000000000700000028000000A80C3100F1B8310001000000000000000000000A00210000631F6E6F0EDED40100000000000000000200000028000000000000000000004000000000000000000000000000000000993F0000000000000100000001000000 "SIGN.MEDIA=2BBB85FC Ma Logithèque clé\Skype-8.55.0.135.exe"=0x5341435001000000000000000700000028000000981329047182290401000000000000000000000A00210000631F6E6F0EDED4010000000000000000 "C:\Program Files\WinRAR\WinRAR.exe"=0x5341435001000000000000000700000028000000D808240027A0240001000000000000000000000A00210000631F6E6F0EDED4010000000000000000020000002800000000000000000000000000000000000000000000000000000021680000000000000300000003000000 "SIGN.MEDIA=2BBB85FC Ma Logithèque clé\VSDC_video_editor_x64_6.4.1.71.exe"=0x534143500100000000000000070000002800000020556504F767650401000000000000000000000A00210000631F6E6F0EDED40100000000000000000200000028000000000000000000000000000000000000000000000000000000C4FD1800000000000100000001000000 "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"=0x5341435001000000000000000700000028000000F0031A00D0171A0001000000000000000000000A00210000631F6E6F0EDED4010000000000000000020000002800000000000000000000000000000000000000000000000000000099320000000000001D0000001D000000 "SIGN.MEDIA=2BBB85FC Ma Logithèque clé\windows-kb890830-x64-v5.78.exe"=0x534143500100000000000000070000002800000068435702E9E5570201000000000000000000000A00210000631F6E6F0EDED4010000000000000000020000002800000000000000000000400000000000000000000000000000000056110000000000000300000003000000 "C:\Program Files\LibreOffice\program\soffice.exe"=0x53414350010000000000000007000000280000003055010086FE010001000000000000000000000A00210000631F6E6F0EDED40100000000000000000200000028000000000000000000000000000000000000000000000000000000204E0000000000000200000002000000 "C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe"=0x5341435001000000000000000700000028000000403C74058063740501000000000000000000000A00210000631F6E6F0EDED4010000000000000000 "E:\Mes documents\Ma LOGITHEQUE portable Bollywood\captvty-2.8.6.2\Captvty.exe"=0x534143500100000000000000070000002800000000E43B000000000001000000000000000000000A71220000631F6E6F0EDED40100000000000000000200000028000000000000000000000000000000000000000000000000000000C6DA0200000000000100000001000000 "SIGN.MEDIA=2BBB85FC Ma Logithèque clé\Iperius6.3.4.0.exe"=0x534143500100000000000000070000002800000018DB4E0391FA4E0301000000000000000000000A00210000631F6E6F0EDED40100000000000000000200000028000000000000000000000000000000000000000000000000000000FBF5C500000000000100000001000000 "C:\Users\EVRARD\AppData\Local\HiSuite\userdata\hwtools\hdbtransport.exe"=0x5341435001000000000000000700000028000000202FDC008482DC0001000000000000000000000A71200000631F6E6F0EDED40100000000000000000200000028000000000000000000000000000000000000000000000000000000C117A700000000000200000002000000 "C:\ProgramData\NVIDIA Corporation\Downloader\7198b5a2f380e93dc47ad2ea43088de3_extracted\setup.exe"=0x534143500100000000000000070000002800000080F2070008D8080001000000000000000000000A00210000631F6E6F0EDED4010000000000000000020000002800000000000000800000400000000000000000000000000000000041F71700000000000100000001000000 "C:\Program Files\Malwarebytes\Anti-Malware\malwarebytes_assistant.exe"=0x5341435001000000000000000700000028000000A80210006F49100001000000000000000000000A71220000631F6E6F0EDED4010000000000000000020000002800000000000000000000400000000000000000000000000000000033020000000000000100000001000000 "E:\Mes documents\0-A transférer sur Portable ou clé ou classer ou envoyer\FreemakeVideoConverterFull4.1.10.479.exe"=0x5341435001000000000000000700000028000000E0F917039D7F180301000000000000000000020600010000631F6E6F0EDED40100000000000000000200000028000000000000000000000000000000000000000000000000000000FAC72A01000000000100000001000000 "SIGN.MEDIA=2BBB85FC Ma Logithèque clé\revouninstallersetup2.1.1.exe"=0x5341435001000000000000000700000028000000486971007E92710001000000000000000000000A00210000631F6E6F0EDED4010000000000000000020000002800000000000000000000000000000000000000000000000000000060600000000000000100000001000000 "C:\Program Files (x86)\Iperius Backup\Iperius.exe"=0x5341435001000000000000000700000028000000C86464044D19650401000000000000000000000A00210000631F6E6F0EDED4010000000000000000020000002800000000000000000000000000000000000000000000000000000021130200000000000100000001000000 "E:\Desktop\QuickDiag.exe"=0x534143500100000000000000070000002800000098315100875E510001000000000000000000000A00210000631F6E6F0EDED4010000000000000000 ---------- | IFEO ---------- | Mountpoints2 [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\Mountpoints2\{ab6385a1-ce45-11e9-885a-d850e63f6f91}] : "D:\HiSuiteDownLoader.exe" (AutoRun) [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\Mountpoints2\{ab6386d9-ce45-11e9-885a-d850e63f6f91}] : "D:\HiSuiteDownLoader.exe" (AutoRun) [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\Mountpoints2\{f6456da0-1f0d-11ea-88b0-d850e63f6f91}] : "D:\HiSuiteDownLoader.exe" (AutoRun) ---------- | Windows [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\win.ini\Windows] ""=USR:Software\Microsoft\Windows NT\CurrentVersion\Windows "APPINIT_DLLS"=SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS "Beep"=#USR:Control Panel\Sound "CoolSwitch"=USR:Control Panel\Desktop "DEFAULTSEPARATEVDM"=\\REGISTRY\\MACHINE\\SYSTEM\\CURRENTCONTROLSET\\CONTROL\\WOW "DEVICENOTSELECTEDTIMEOUT"=#SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS "DoubleClickHeight"=#USR:Control Panel\Mouse "DoubleClickSpeed"=#USR:Control Panel\Mouse "DoubleClickWidth"=#USR:Control Panel\Mouse "DragFullWindows"=USR:Control Panel\Desktop "InitialKeyboardIndicators"=USR:Control Panel\Keyboard "LowPowerActive"=#USR:Control Panel\Desktop "LowPowerTimeOut"=#USR:Control Panel\Desktop "MouseSpeed"=#USR:Control Panel\Mouse "MouseThreshold1"=#USR:Control Panel\Mouse "MouseThreshold2"=#USR:Control Panel\Mouse "PowerOffActive"=#USR:Control Panel\Desktop "PowerOffTimeOut"=#USR:Control Panel\Desktop "ScreenSaveActive"=#USR:Control Panel\Desktop "ScreenSaveTimeOut"=#USR:Control Panel\Desktop "SnapToDefaultButton"=#USR:Control Panel\Mouse "Spooler"=#SYS:Microsoft\Windows NT\CurrentVersion\Windows "SWAPDISK"=SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS "SwapMouseButtons"=#USR:Control Panel\Mouse "TRANSMISSIONRETRYTIMEOUT"=#SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\system.ini\Boot] ""=SYS:Microsoft\Windows NT\CurrentVersion\WOW\boot "ScreenSaverActive"=USR:Control Panel\Desktop "ScreenSaverIsSecure"=USR:Control Panel\Desktop "SCRNSAVE.EXE"=USR:Control Panel\Desktop "Shell"=SYS:Microsoft\Windows NT\CurrentVersion\Winlogon [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\IniFileMapping\win.ini\Windows] "APPINIT_DLLS"=SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS "Beep"=#USR:Control Panel\Sound "CoolSwitch"=USR:Control Panel\Desktop "DEFAULTSEPARATEVDM"=\\REGISTRY\\MACHINE\\SYSTEM\\CURRENTCONTROLSET\\CONTROL\\WOW "DEVICENOTSELECTEDTIMEOUT"=#SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS "DoubleClickHeight"=#USR:Control Panel\Mouse "DoubleClickSpeed"=#USR:Control Panel\Mouse "DoubleClickWidth"=#USR:Control Panel\Mouse "DragFullWindows"=USR:Control Panel\Desktop "InitialKeyboardIndicators"=USR:Control Panel\Keyboard "LowPowerActive"=#USR:Control Panel\Desktop "LowPowerTimeOut"=#USR:Control Panel\Desktop "MouseSpeed"=#USR:Control Panel\Mouse "MouseThreshold1"=#USR:Control Panel\Mouse "MouseThreshold2"=#USR:Control Panel\Mouse "PowerOffActive"=#USR:Control Panel\Desktop "PowerOffTimeOut"=#USR:Control Panel\Desktop "ScreenSaveActive"=#USR:Control Panel\Desktop "ScreenSaveTimeOut"=#USR:Control Panel\Desktop "SnapToDefaultButton"=#USR:Control Panel\Mouse "SWAPDISK"=SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS "SwapMouseButtons"=#USR:Control Panel\Mouse "TRANSMISSIONRETRYTIMEOUT"=#SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\IniFileMapping\system.ini\Boot] ""=SYS:Microsoft\Windows NT\CurrentVersion\WOW\boot "ScreenSaverActive"=USR:Control Panel\Desktop "ScreenSaverIsSecure"=USR:Control Panel\Desktop "SCRNSAVE.EXE"=USR:Control Panel\Desktop "Shell"=SYS:Microsoft\Windows NT\CurrentVersion\Winlogon [HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems] "windows"=%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16 ---------- | Security center [HKLM\SOFTWARE\Microsoft\Security Center] "cval"=1 [HKLM\SOFTWARE\Microsoft\Security Center\svc] "VistaSp1"=132096632936323331 [HKLM\SOFTWARE\Microsoft\Windows Defender] "ProductAppDataPath"=C:\ProgramData\Microsoft\Windows Defender "ProductIcon"=@%ProgramFiles%\Windows Defender\EppManifest.dll,-100 "ProductLocalizedName"=@%ProgramFiles%\Windows Defender\EppManifest.dll,-1000 "DisableAntiSpyware"=0 "RemediationExe"=%ProgramFiles%\Windows Defender\MSASCui.exe "ProductType"=2 "ProductStatus"=0 "InstallTime"=0x55122787D61DCF01 "ManagedDefenderProductType"=0 "DisableAntiVirus"=0 "InstallLocation"=C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1911.3-0\ "LastEnabledTime"=0xA1EBCE9B40B0D501 "OOBEInstallTime"=0xBDC635248790D401 "PassiveMode"=2 "BackupLocation"=C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1907.4-0 "IsServiceRunning"=1 [HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall"=1 [HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall"=1 [HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall"=1 ---------- | Safeboot [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ahcache.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppInfo] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppMgmt] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AudioEndpointBuilder] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AudioSrv] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Base] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BasicDisplay.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BasicRender.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Boot Bus Extender] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Boot file system] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BrokerInfrastructure] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CBDHSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CoreMessagingRegistrar] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CryptSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\DcomLaunch] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\DeviceInstall] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dxgkrnl.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EFS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EventLog] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\File system] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Filter] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\FsDepends.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HdAudAddService.Sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HdAudBus.Sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HelpSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\iai2c.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\KeyIso] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\LSM] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Netlogon] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NTDS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PCI Configuration] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PlugPlay] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PNP Filter] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Power] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Primary disk] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ProfSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcEptMapper] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcSs] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SCSI Class] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SerCx2.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sermouse.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SpbCx.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\StateRepository] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SWPRV] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\System Bus Extender] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SystemEventsBroker] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TabletInputService] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TBS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TrustedInstaller] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\uefi.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\usbaudio.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\UserManager] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\VDS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vmms] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgr.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgrx.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinMgmt] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{36FC9E60-C465-11CF-8056-444553540000}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E965-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E969-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96A-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96B-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96C-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96F-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E977-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97B-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97D-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E980-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{71A27CDD-812A-11D0-BEC7-08002BE2092F}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{9DA2B80F-F89F-4A49-A5C2-511B085B9E8A}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{A0A588A4-C46F-4B37-B7EA-C82FE89870C6}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AFD] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Ahcache.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AppInfo] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AppMgmt] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AudioEndpointBuilder] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AudioSrv] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Base] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\BasicDisplay.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\BasicRender.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\BFE] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Boot Bus Extender] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Boot file system] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\bowser] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\BrokerInfrastructure] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Browser] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CBDHSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CoreMessagingRegistrar] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CryptSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\DcomLaunch] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\DeviceInstall] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\dfsc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Dhcp] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\DnsCache] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Dot3Svc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\dxgkrnl.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Eaphost] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\EFS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\EventLog] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\File system] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Filter] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\FsDepends.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\HdAudAddService.Sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\HdAudBus.Sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\HelpSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\IKEEXT] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ipnat.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\KeyIso] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\LanmanServer] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\LanmanWorkstation] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\LmHosts] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\LSM] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Messenger] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MPSDrv] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MPSSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mrxsmb] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mrxsmb10] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mrxsmb20] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NativeWifiP] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NDIS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NDIS Wrapper] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ndiscap] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Ndisuio] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetBIOS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetBIOSGroup] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetBT] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetDDEGroup] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Netlogon] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetMan] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\netprofm] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetSetupSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Network] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetworkProvider] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NlaSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Nsi] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\nsiproxy.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NTDS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PCI Configuration] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PlugPlay] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PNP Filter] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PNP_TDI] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PolicyAgent] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Power] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Primary disk] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ProfSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\rdbss] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\rdpencdd.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\rdsessmgr] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\RpcEptMapper] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\RpcSs] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\sacsvr] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SCardSvr] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SCSI Class] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SerCx2.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\sermouse.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SharedAccess] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SmartcardSimulator] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SpbCx.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\StateRepository] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Streams Drivers] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SWPRV] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\System Bus Extender] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SystemEventsBroker] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TabletInputService] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TBS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Tcpip] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TDI] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TrustedInstaller] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\uefi.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\usbaudio.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\UserManager] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\VaultSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\VDS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\VirtualSmartcardReader] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\vmms] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\volmgr.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\volmgrx.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wcmsvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WinDefend] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WinMgmt] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WinQuic] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wlansvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WudfPf] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WudfRd] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WudfUsbccidDriver] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{36FC9E60-C465-11CF-8056-444553540000}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E965-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E967-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E969-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E96A-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E96B-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E96C-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E96F-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E973-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E974-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E975-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E977-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E97B-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E97D-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E980-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{50DD5230-BA8A-11D1-BF5D-0000F805F530}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{533C5B84-EC70-11D2-9505-00C04F79DEAF}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{71A27CDD-812A-11D0-BEC7-08002BE2092F}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{9DA2B80F-F89F-4A49-A5C2-511B085B9E8A}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{A0A588A4-C46F-4B37-B7EA-C82FE89870C6}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}] ---------- | Winsock (Whitelist) ---------- | Hosts ---------- | Ping Envoi d'une requ?te 'ping' sur google.com [2a00:1450:4007:811::200e] avec 32 octets de donn?es?: R?ponse de 2a00:1450:4007:811::200e?: temps=38 ms R?ponse de 2a00:1450:4007:811::200e?: temps=39 ms R?ponse de 2a00:1450:4007:811::200e?: temps=38 ms R?ponse de 2a00:1450:4007:811::200e?: temps=38 ms Statistiques Ping pour 2a00:1450:4007:811::200e: Paquets?: envoy?s = 4, re?us = 4, perdus = 0 (perte 0%), Dur?e approximative des boucles en millisecondes : Minimum = 38ms, Maximum = 39ms, Moyenne = 38ms ---------- | @ [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Microsoft\Internet Explorer\Main] "Anchor Underline"=yes "Disable Script Debugger"=yes "DisableScriptDebuggerIE"=yes "Display Inline Images"=yes "Do404Search"=0x01000000 "Save_Session_History_On_Exit"=no "Search Page"=http://go.microsoft.com/fwlink/?LinkId=54896 "Show_FullURL"=no "Show_StatusBar"=yes "Show_ToolBar"=yes "Show_URLinStatusBar"=yes "Show_URLToolBar"=yes "Use_DlgBox_Colors"=yes "UseClearType"=no "XMLHTTP"=1 "Cache_Update_Frequency"=Once_Per_Session "Local Page"=C:\Windows\system32\blank.htm "NoUpdateCheck"=1 "Enable Browser Extensions"=yes "Play_Background_Sounds"=yes "Play_Animations"=yes "Start Page"=https://fr.yahoo.com/?fr=yset_ie_syc_oracle&type=orcl_hpset "OperationalData"=13 "FullScreen"=no "ImageStoreRandomFolder"=5jcvcsf "IE10RunOncePerInstallCompleted"=1 "IE10RunOnceCompletionTime"=0x7BE1F1DC8290D401 "CompatibilityFlags"=0 "Window_Placement"=0x2C0000000200000003000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFA70100007C0000004904000035030000 "Start Page Redirect Cache_TIMESTAMP"=0xFF6FCEBE0959D101 "Start Page Redirect Cache AcceptLangs"=fr-FR,fr;q=0.5 "DownloadWindowPlacement"=0x2C0000000000000000000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF9E010000A10000001E04000081020000 "NotifyDownloadComplete"=yes "Use FormSuggest"=no "SuppressScriptDebuggerDialog"=0 "AutoHide"=yes "FormSuggest Passwords"=no "FormSuggest PW Ask"=no "Start Page_TIMESTAMP"=0x3245EDE21498D101 "ApplicationTileImmersiveActivation"=0 "AssociationActivationMode"=2 "EdgeSwitchingOSBuildNumber"=10586.th2_release.160802-1857 "IE10TourShown"=1 "IE10TourShownTime"=0xC87A3CF85C89D301 "IE10RunOnceLastShown"=1 "IE10RunOnceLastShown_TIMESTAMP"=0x6022F3E131B9D201 "IE11EdgeNotifyTime"=0x7EFF7DD35F5CD301 "EdgeReminderRemainingCount"=0 "SearchBandMigrationVersion"=1 "IE10TourNoShow"=1 [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Microsoft\Windows\CurrentVersion\Internet settings] "DisableCachingOfSSLPages"=0 "IE5_UA_Backup_Flag"=5.0 "PrivacyAdvanced"=1 "SecureProtocols"=2688 "CertificateRevocation"=1 "User Agent"=Mozilla/4.0 (compatible; MSIE 8.0; Win32) "ZonesSecurityUpgrade"=0xC8C92942294DD501 "EmailName"=User@ "AutoConfigProxy"=wininet.dll "MimeExclusionListForCache"=multipart/mixed multipart/x-mixed-replace multipart/x-byteranges "WarnOnPost"=0x01000000 "UseSchannelDirectly"=0x01000000 "EnableHttp1_1"=1 "UrlEncoding"=0 "WarnonZoneCrossing"=0 "EnableNegotiate"=1 "MigrateProxy"=1 "ProxyEnable"=0 "MaxConnectionsPerServer"=10 "LockDatabase"=132142370966137215 [HKLM\Software\Microsoft\Internet Explorer\Main] "ApplicationTileImmersiveActivation"=1 "AssociationActivationMode"=0 "AutoHide"=yes "Start Page"=http://go.microsoft.com/fwlink/p/?LinkId=255141 "Anchor_Visitation_Horizon"=0x01000000 "Cache_Percent_of_Disk"=0x0A000000 "Default_Page_URL"=http://go.microsoft.com/fwlink/p/?LinkId=255141 "Default_Search_URL"=http://go.microsoft.com/fwlink/?LinkId=54896 "Default_Secondary_Page_URL"= "Delete_Temp_Files_On_Exit"=yes "Enable_Disk_Cache"=yes "Extensions Off Page"=about:NoAdd-ons "Local Page"=C:\Windows\System32\blank.htm "Placeholder_Height"=0x1A000000 "Placeholder_Width"=0x1A000000 "Search Page"=http://go.microsoft.com/fwlink/?LinkId=54896 "Security Risk Page"=about:SecurityRisk "Use_Async_DNS"=yes "x86AppPath"=C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE "DoNotTrack"=1 [HKLM\Software\Microsoft\Internet Explorer\AboutURLs] "blank"=res://mshtml.dll/blank.htm "DesktopItemNavigationFailure"=res://ieframe.dll/navcancl.htm "Home"=270 "InPrivate"=res://ieframe.dll/inprivate.htm "NavigationCanceled"=res://ieframe.dll/navcancl.htm "NavigationFailure"=res://ieframe.dll/navcancl.htm "NoAdd-ons"=res://ieframe.dll/noaddon.htm "NoAdd-onsInfo"=res://ieframe.dll/noaddoninfo.htm "PostNotCached"=res://ieframe.dll/repost.htm "SecurityRisk"=res://ieframe.dll/securityatrisk.htm [HKLM\Software\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix] ""=http:// [HKLM\Software\Microsoft\Windows\CurrentVersion\URL\Prefixes] "ftp"=ftp:// "home"=http:// "mosaic"=http:// "www"=http:// [HKLM\Software\Microsoft\Windows\CurrentVersion\Internet settings] "ActiveXCache"=C:\Windows\Downloaded Program Files "CodeBaseSearchPath"=CODEBASE "EnablePunycode"=1 "MinorVersion"=0 "WarnOnIntranet"=1 [HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings] "CallLegacyWCMPolicies"=0 [HKLM\Software\WOW6432Node\Microsoft\Internet Explorer\Main] "ApplicationTileImmersiveActivation"=1 "AssociationActivationMode"=0 "AutoHide"=yes "Start Page"=http://go.microsoft.com/fwlink/p/?LinkId=255141 "Anchor_Visitation_Horizon"=0x01000000 "Cache_Percent_of_Disk"=0x0A000000 "Default_Page_URL"=http://go.microsoft.com/fwlink/p/?LinkId=255141 "Default_Search_URL"=http://go.microsoft.com/fwlink/?LinkId=54896 "Default_Secondary_Page_URL"= "Delete_Temp_Files_On_Exit"=yes "Enable_Disk_Cache"=yes "Extensions Off Page"=about:NoAdd-ons "Local Page"=C:\Windows\SysWOW64\blank.htm "Placeholder_Height"=0x1A000000 "Placeholder_Width"=0x1A000000 "Search Page"=http://go.microsoft.com/fwlink/?LinkId=54896 "Security Risk Page"=about:SecurityRisk "Use_Async_DNS"=yes "x86AppPath"=C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE [HKLM\Software\WOW6432Node\Microsoft\Internet Explorer\AboutURLs] "blank"=res://mshtml.dll/blank.htm "DesktopItemNavigationFailure"=res://ieframe.dll/navcancl.htm "Home"=270 "InPrivate"=res://ieframe.dll/inprivate.htm "NavigationCanceled"=res://ieframe.dll/navcancl.htm "NavigationFailure"=res://ieframe.dll/navcancl.htm "NoAdd-ons"=res://ieframe.dll/noaddon.htm "NoAdd-onsInfo"=res://ieframe.dll/noaddoninfo.htm "PostNotCached"=res://ieframe.dll/repost.htm "SecurityRisk"=res://ieframe.dll/securityatrisk.htm [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix] ""=http:// [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\URL\Prefixes] "ftp"=ftp:// "home"=http:// "mosaic"=http:// "www"=http:// [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Internet settings] "ActiveXCache"=C:\Windows\Downloaded Program Files "CodeBaseSearchPath"=CODEBASE "EnablePunycode"=1 "MinorVersion"=0 "WarnOnIntranet"=1 [HKLM\Software\WOW6432Node\Policies\Microsoft\Windows\CurrentVersion\Internet Settings] "CallLegacyWCMPolicies"=0 ---------- | Proxy ---------- | reparsepoint ---------- | Detection of offsets ---------- | Notify [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SDWinLogon] : SDWinLogon.dll ---------- | Execution FileExts [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3g2] "Application"=wmplayer.exe [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3gp] "Application"=wmplayer.exe [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3gp2] "Application"=wmplayer.exe [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3gpp] "Application"=wmplayer.exe [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.amv] "Application"=wmplayer.exe [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ASF] "Application"=wmplayer.exe [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.avi] "Application"=wmplayer.exe [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bdmv] "Application"=wmplayer.exe [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.divx] "Application"=wmplayer.exe [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dv] "Application"=wmplayer.exe [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.evo] "Application"=wmplayer.exe [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.f4v] "Application"=wmplayer.exe [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.flv] "Application"=wmplayer.exe [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.hdmov] "Application"=wmplayer.exe [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ifo] "Application"=wmplayer.exe [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.M1V] "Application"=wmplayer.exe [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m2p] "Application"=wmplayer.exe [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m2t] "Application"=wmplayer.exe [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m2ts] "Application"=wmplayer.exe [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.M2V] "Application"=wmplayer.exe [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4v] "Application"=wmplayer.exe [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mkv] "Application"=wmplayer.exe [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mov] "Application"=wmplayer.exe [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.MP2V] "Application"=wmplayer.exe [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp4] "Application"=wmplayer.exe [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.MPE] "Application"=wmplayer.exe [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpeg] "Application"=wmplayer.exe [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpg] "Application"=wmplayer.exe [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpls] "Application"=wmplayer.exe [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpv2] "Application"=wmplayer.exe [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpv4] "Application"=wmplayer.exe [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mts] "Application"=wmplayer.exe [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mxf] "Application"=wmplayer.exe [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ogm] "Application"=wmplayer.exe [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ogv] "Application"=wmplayer.exe [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ram] "Application"=wmplayer.exe [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rec] "Application"=wmplayer.exe [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rm] "Application"=wmplayer.exe [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rmvb] "Application"=wmplayer.exe [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tp] "Application"=wmplayer.exe [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tps] "Application"=wmplayer.exe [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.trp] "Application"=wmplayer.exe [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.TS] "Application"=wmplayer.exe [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.VOB] "Application"=wmplayer.exe [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.webm] "Application"=wmplayer.exe [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmv] "Application"=wmplayer.exe ---------- | SIOI | SEH | URLSH [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive1] - {BBACC218-34EA-4666-9D7A-C78F2274A524} -- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive2] - {5AB7172C-9C11-405C-8DD5-AF20F3606282} -- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive3] - {A78ED123-AB77-406B-9962-2A5D9D2F7F30} -- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive4] - {F241C880-6982-4CE5-8CF7-7085BA96DA5A} -- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive5] - {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} -- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive6] - {9AA2F32D-362A-42D9-9328-24A483E2CCC3} -- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive7] - {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} -- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00asw] - {472083B0-C522-11CF-8763-00608CC02F24} -- C:\Program Files\AVAST Software\Avast\ashShell.dll [20/09/2019 20:15:48] [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avast] - {472083B0-C522-11CF-8763-00608CC02F24} -- C:\Program Files\AVAST Software\Avast\ashShell.dll [20/09/2019 20:15:48] [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\EnhancedStorageShell] - {D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D} -- C:\Windows\System32\EhStorShell.dll [19/03/2019 05:44:47] [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive1] - {BBACC218-34EA-4666-9D7A-C78F2274A524} -- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive2] - {5AB7172C-9C11-405C-8DD5-AF20F3606282} -- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive3] - {A78ED123-AB77-406B-9962-2A5D9D2F7F30} -- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive4] - {F241C880-6982-4CE5-8CF7-7085BA96DA5A} -- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive5] - {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} -- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive6] - {9AA2F32D-362A-42D9-9328-24A483E2CCC3} -- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive7] - {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} -- [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks] "{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"= ---------- | Toolbar [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "Locked"=1 [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser] "ITBar7Layout"=0x13000000000000000000000020000000100000001500000001000000000700005E010000060000000801000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000B1C218236549D4119B18009027A5CD4F0000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 "{2318C2B1-4965-11D4-9B18-009027A5CD4F}"=0xB1C218236549D4119B18009027A5CD4F [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"={CF5B35C3-8132-4E2E-9204-A802CADAD398} "KnownProvidersUpgradeTime"=0x7BE1F1DC8290D401 "Version"=5 "UpgradeTime"=0x7BE1F1DC8290D401 "ShowSearchSuggestionsInAddressGlobal"=1 "DownloadRetries"=3 "DefaultPackCorrection"=1 "DefaultPackNTCorrection"=1 [HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F}"=avast! Online Security "{2318C2B1-4965-11d4-9B18-009027A5CD4F}"=0x00 [HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"={0633EE93-D776-472f-A0FF-E1416B8B2E3A} [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"={0633EE93-D776-472f-A0FF-E1416B8B2E3A} ---------- | Extensions [HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{48A61126-9A19-4C50-A214-FF08CB94995C}] : (McAfee WebAdvisor) - [] [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Extensions\{48A61126-9A19-4C50-A214-FF08CB94995C}] : (McAfee WebAdvisor) - [] [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Extensions\{92780B25-18CC-41C8-B9BE-3C9C571A8263}] : () - [] ---------- | SearchScopes [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}] - (Bing) - http://www.bing.com/search?FORM=SL5MDF&PC=SL5M&q={searchTerms}&src=IE-SearchBox : [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}] - (Google) - http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7 : [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{CF5B35C3-8132-4E2E-9204-A802CADAD398}] - (Google) - http://www.google.fr/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:{language}:{referrer:source}&ie={inputEncoding?}&oe={outputEncoding?}&rlz=1I7AVNB_frFR630 : [HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}] - (@ieframe.dll,-12512) - http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC : [HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}] - (Google) - http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7 : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}] - (@ieframe.dll,-12512) - http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}] - (Google) - http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7 : ---------- | Browser Helper Objects [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}] -> () : [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}] -> (Google Toolbar Helper) : C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [20/07/2014 20:05:22] [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B164E929-A1B6-4A06-B104-2CD0E90A88FF}] -> (McAfee WebAdvisor) : C:\Program Files\McAfee\WebAdvisor\win32\IEPlugin.dll [12/12/2019 21:52:24] [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}] -> () : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B164E929-A1B6-4A06-B104-2CD0E90A88FF}] -> (McAfee WebAdvisor) : C:\Program Files\McAfee\WebAdvisor\win32\IEPlugin.dll [12/12/2019 21:52:24] ---------- | Chrome C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\aamibngagbgnnllffcldjgppkdjanahe = : Paintings of Flowers Bouquet and Still Life by artist Leonid Afremov - https://afremov.com/Flowers-Still-life/ - Peintures de Fleurs Bouquet et Still... C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\aanbinceghkncmgjkffbionkphnnilha = : lll? Tous les bus en un clin d'œil : comparez ici horaires prix et confort. busradar.fr est le comparateur de bus en France et en Europe : Comparez. Trouvez. Voyagez. - https://www.busradar.fr/recherche/?From=Nimes&To=A%C3%A9roport+Nice+C%C3%B4te+d%E2%80%99Azur&When=2016-09-12&WhenReturn=&ShowTrain=false&ShowRidesharing=true&ShowRidesharing=false&Company=Tous+les+op%C3%A9rateurs&Passengers=1&SearchMode=2&Radius=15000 - busradar.fr C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\abicpkcimgbnmfcaonbfkfeadggnoogj = : Add this delicate and inspiring still life depicting a bunch of charming asters to your interior and fill it with a romantic autumn mood! More palette knife paintings by Leonid Afremov are available in his official gallery. - https://afremov.com/THE-RETURN-OF-LOVE-Palette-knife-Oil-Painting-on-Canvas-by-Leonid-Afremov-Size-24-x30.html - LE RETOUR DE L'AMOUR - Palette coutea... C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\akjkobccidolkhhajdpkcjmogabicald = : L'étang de pêche d'Aimargues situé dans le Gard propose la pêche de truites Arc-en-ciel et de saumons de Fontaine avec vente d'appâts et location de canne. - http://www.etangdepeche.com/ - Etang de pêche - Aimargues - Gard (30) C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\aloikeblpncbmckjfjjdlhonekhjhdpa = : Envie d’en savoir plus sur la carte Visa REGLO FINANCE ? Découvrez les avantages et services de cette carte avec les centres E.Leclerc : points de fidélité paiement en toute sécurité… - http://www.cetelem.fr/cartes-partenaires/visa-reglo-finance/ - Carte partenaire Visa Réglo Finance -... C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\amgobjjbinoomfcihbhhoflhfeinbijb = : Vercors-Tv est la première web TV consacrée au territoire du Parc Naturel Régional du Vercors. Culture économie nature patrimoine ruralité tourisme tout ce qui touche de près ou de loin l... - http://vercorstv.wmaker.tv/ - vercors-tv.com C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\anlegfoopcbpabhbjggejjeoopdkiikk = : Sanithermic - situé à Castries - http://www.sanithermic-herault.fr/contact - Contact Sanithermic Castries - 70 av.... C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\anmidbmjajmcobacechalblpamlbkcnl = : Découvrez Citroën C3 Picasso en détails sur le site Citroën France : prix équipements caractéristiques … et réservez vite votre essai ! - http://www.citroen.fr/vehicules-neufs/citroen/citroen-c3-picasso.html - Citroën C3 Picasso : petit monospace ... C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\aoacldidajicmkjfoodhkcmfgooinick = : Téléchargez gratuitement des milliers de logiciels - http://www.pcastuces.com/logitheque/miseajour.asp?page=5 - PC Astuces : Logithèque et Télécharge... C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\bfdkpbibakhjeigliljdfphkdkmpooec = : - https://www.google.fr/maps/@43.68027153.976053463m/data=!3m1!1e3 - Google Maps C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\bhnelccimbjoeijdbceoimjmmomcnmim = : Pied de table en inox brossé pour plateau rond de grande dimension Ultra tendance ce pied ultra plat en inox brossé apportera la touche raffiné et design à votre établissement. - http://www.onemobilier.com/pied-de-table-de-48-a-108-cm/pch-18-72-8mm-pied-de-table-en-inox-brosse-pour-plateau-rond-de-grande-dimension.html - Pied de table en inox brossé pour pla... C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\bjgfebkmededhggbekonnpfoacgpplap = : Bienvenue dans l'espace Client de Cdiscount n°1 du e-commerce en France ! - https://clients.cdiscount.com/Account/Login.html? - Espace Client Cdiscount C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\bkijekoedejpbhaahjgnccmbnlmmdchj = : - https://mobile.free.fr/moncompte/ - Free Mobile - Bienvenue dans votre Es... C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\bpaidmoepgcpblbmdjhioggmghjelllg = : Dès 59€ -- Rome : hôtel 4* proche du Vatican jsq -70%\u003Cbr> - http://www.travelzoo.com/fr/hotel-booking/6572/?utm_source=top20_fr&utm_medium=email&utm_content=2304555&utm_campaign=fr_top20_2016_30_deal%3a2304555&adid=2304555 - Cardinal Hotel St Peter | Travelzoo C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\bplgagchaidagadkobjgnekgbbhbaich = : - http://piscineinfoservice.com/entretien/pourquoi-comment-entretenir-liner-piscine - Pourquoi et Comment entretenir un lin... C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\bplppnlnofknkkjhhidoalkbialmkkae = : - https://fr.wikipedia.org/wiki/Liste_des_%C3%A9pisodes_de_Jos%C3%A9phine_ange_gardien - Liste des épisodes de Joséphine ange... C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\cfhdojbkjhnklbpkdaibdccddilifddb = : __MSG_description__ - short_name: __MSG_name__ - permissions:[tabs\u003Call_urls>contextMenuswebRequestwebRequestBlockingwebNavigationstorageunlimitedStoragenotifications] - https://clients2.google.com/service/update2/crx C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\cfiflnkhkdbhgmgbanmbegejleohcgca = : Astuces dossiers pratiques et logiciels gratuits pour mieux utiliser son ordinateur optimiser son matériel et résoudre les pannes - http://www.pcastuces.com/ - PC Astuces : Aide Informatique C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\chaieonkincggpeclepajjclimabplpb = : - http://www.plancha-mania.com/index.php?id_page=2142&id_site=1 - PLANCHA MANIA 75 - Plaques de cuisson... C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\cjkhilbefbpkjgdmhlmppjejdehgekjk = : - http://www.bayrol.fr/fileadmin/content/images/documents/distributors_download/FR/Fiches_techniques_A-Z/Desalgine_Jet-Productsheet-FRANCE_bd.pdf - Desalgine_Jet-Productsheet-FRANCE_bd.pdf C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\ckcncmenhcoapffphbhimfhlkgkfdcoc = : SAVE est un partenaire de Ma Maison Solutions Habitat d'EDF qui réalise vos travaux Ventilation / Climatisation Chauffage à ST GELY DU FESC. - https://travaux.edf.fr/trouver-un-professionnel/partenaire/save-586D8B0C73EC4E1D542FBBA2B8F9C660A0EBED96 - EDF Travaux C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\cmglfemieiokmddnopiefomjmjnjadho = : Tous les avantages et caractéristiques de la carte de crédit Visa Premier REGLO FINANCE sur cetelem.fr : bons plans Aurore plafond de retrait élevé… - http://www.cetelem.fr/cartes-partenaires/visa-premier-reglo-finance/ - Carte de crédit Visa Premier Réglo Fi... C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\cpadcpcjeoiaaboogaiipafiabfiijoj = : Sanithermic - Plombiers situé à Castries vous accueille sur son site à Castries - http://www.sanithermic-herault.fr/ - Plombiers - Sanithermic à Castries C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\dgdhldhgeeomehephmkggpcgockhhmnd = : Besoin de shorts bermudas ? Découvrez les shorts bermudas Millet sur le site officiel de la marque. - http://www.millet.fr/produits/short.html?ectrans=1&utm_campaign=1608NouveautesTextile_FR%2B%5B2%5D&utm_medium=email&utm_source=Actifs_MILLET-fr_fr - Short | Millet.fr C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\djdbppaipppgmfkhcabgkkbmehobgoil = : Le site officiel de l’administration française : connaître vos droits effectuer vos démarches - https://www.service-public.fr/ - Accueil Particuliers | service-public.fr C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\dkcbkhipehmemdfiljcmdomedanmdndj = : Comité Des Fêtes Castries. 2449 J’aime · 321 en parlent. Communauté - https://www.facebook.com/Comit%C3%A9-Des-F%C3%AAtes-Castries-803650539766320/ - (1) Comité Des Fêtes Castries C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\dklailnbdjeaiepajmedelfidnfajhhj = : - https://www.flickr.com/ - Flickr une société Yahoo | Flickr - ... C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\dpgghamjgpmddhjkciahdimfflfnfegi = : - https://www.eau-services.com/ - : votre agence Veolia eau en ligne C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\ealoblbgffkpdkonmlcjjhamdpfbiije = : Achat en ligne pour Bricolage dans un vaste choix de Évier de cuisine Bar et plus à prix bas tous les jours. - https://www.amazon.fr/s/ref=s9_dnav_bw_ir01_s?__mk_fr_FR=%C5M%C5Z%D5%D1&node=590748031!590749031171619303118546750311854676031&search-alias=diy&field-lbr_brands_browse-bin=Grohe&bbn=1854676031&pf_rd_m=A1X6FK5RDHNB96&pf_rd_s=merchandised-search-5&pf_rd_r=TH55WMBSAB7JQ1M13Y38&pf_rd_t=101&pf_rd_p=798856667&pf_rd_i=1854676031 - Amazon.fr : Grohe - Robinets de cuisi... C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\eckccjdjplgdjchiiofkgihdjbihfkpa = : Infoconcert - France Billet - http://infoconcert.francebillet.com/submitContactForm.do;jsessionid=51-E6E1D2001FCCAC96FADC877D8066CE19 - Infoconcert C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\ehbdkohclcpkahaaijbkbgndhhcajnkp = : - https://compteperso.leboncoin.fr/account/index.html - Accéder à mon compte - Leboncoin.fr C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\ehiggjlbhloeidoaeekbhjljlloaidbo = : Pied de table en inox brossé pour plateau rond de grande dimension Ultra tendance ce pied ultra plat en inox brossé apportera la touche raffiné et design à votre établissement. - http://www.onemobilier.com/pch-18-72-pied-de-table-en-inox-brosse-pour-plateau-rond-de-grande-dimension.html - Pied de table en inox brossé pour pla... C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\ehopalembaobdpbfabemnlpcjjhbloli = : - http://www.castries.fr/index.php/agenda?idpage=158 - Agenda C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\ejdbkikfbnnhmachnnomjfgjbgkcnjkb = : Adds a button and context menu item to send the page URL or a link URL via email - short_name: Share Link - https://clients2.google.com/service/update2/crx C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\emaglajllgledkpbacbpkihebhheigio = : Accueil - Mutuelle complémentaire santé en Aquitaine. Contrat individuel santé contrat collectif santé mutuelle pour retraités choisissez une mutuelle santé qui vous correspond en découvrant notre gamme IBAMEO et demander votre devis mutuelle. - http://www.mutibm.fr/ - Mutuelle du personnel IBM C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\emhjjbdcnoooenlofgahleifmlloejpb = : Sur cette page vous pouvez vous connecter à votre compte utilisateur du Service Center de MAGIX ou créer un nouveau compte. - https://www.magix.com/fr/assistance-technique/mon-service-center/ - MAGIX Service Center – Connexion comp... C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\fcbgheionpiglcbnefnnfkcieofhpjmb = : Les fêtes de Les fêtes de la Mare de Déu d’Ermitana à Peñíscola font partie du folklore de la Communauté Valencienne. Venez vivre les fêtes de Peñíscola. - http://fr.comunitatvalenciana.com/que-faire/peniscola/festivites/les-fetes-de-la-mare-de-deu-dermitana-peniscola - Fêtes de Peñíscola C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\fcobhlgodofbamjcdjjnfdejinncipfb = : Retrouvez toutes les offres du crédit agricole pour les particuliers les professionnels les agriculteurs les associations et les collectivités publiques. Gestion des comptes épargne et placement crédits assurances actualité financière et bancaire. Accédez à vos comptes en ligne faites vos simulations et prenez rendez-vous avec un conseiller ou souscrivez un produit directement sur le site ! - https://www.ca-languedoc.fr/ - Crédit Agricole Languedoc - Accueil -... C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\ffgmimdhbnfpnknbikeebcajplfbpkkb = : Le traitement choc est le choix à privilégier pour redonner à l'eau son aspect clair et cristallin. Ici on vous explique pourquoi et comment le faire. - http://piscineinfoservice.com/equipements-accessoires/pourquoi-quand-comment-traitement-choc - Traitement Choc Piscine : Pourquoi? Q... C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\fiffaglhmhfedknjkifpcgcgehpoidbg = : - http://www.cyberbricoleur.com/index.php?showtopic=1100081660 - problème eau TROUBLE piscine - CyberB... C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\fllepiajnhlnnjenigonijidlcmjpfln = : - http://assiste.com/Comment_executer_un_programme_en_tant_qu_administrateur.html - Assiste C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\gblkillifadgcfjjmfecamhhlmooahfb = : Achetez GROHE - 31369000 - Mitigeur Évier Start Edge - Chromé (Import Allemagne) sur Amazon.fr | Livraison gratuite dès 25 € d'achat - https://www.amazon.fr/dp/B00CP6C0NW/ref=gb1h_tit_m-5_1767_a251d39e?smid=A1X6FK5RDHNB96&pf_rd_m=A1X6FK5RDHNB96&pf_rd_t=101&pf_rd_s=merchandised-search-5&pf_rd_r=C4YRMQT9339XFHWBM73S&pf_rd_i=10080456031&pf_rd_p=912901767 - GROHE - 31369000 - Mitigeur Évier Sta... C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\gcpfkjbagihokdcphponenjalbijpdgn = : L'étang de pêche d'Aimargues propose un plan d'eau aux techniques de pêche en No- Kill.\nPêche à la Mouche Pêche aux Leurres Pêche au Coup etc..\nLes Carpistes ne sont pas en reste ouvert également à la pêche à la Carpe - http://www.etangdepeche.com/peche-aimargues - Pratique de la pêche en No-Kill C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\ggcjghiogpjjdhobhbcjmndkgifjmajh = : - http://labergeriedesarpoil.com/lacarte/ - Menus › LA BERGERIE DE SARPOIL ‹ Votr... C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\ghokgjdkhlhkafjonomgipjmmjgogpac = : Louez un Appartement à Peñíscola à partir de 60 € 450 €/semaine 900 €/mois à proximité de Château de Peñíscola Parc Natural de la Serra d'Irta - https://fr.bedycasa.com/appartement/peniscola-36436#availability - Appartement à Peñíscola à partir de 6... C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\gighmmpiobklfepjocnamgkkbiglidom = : __MSG_description__ - short_name: __MSG_name__ - permissions:[tabs\u003Call_urls>contextMenuswebRequestwebRequestBlockingwebNavigationstorageunlimitedStoragenotificationsidlealarms] - https://clients2.google.com/service/update2/crx C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\gkjonkaogffifbljnggndmhcahgngofa = : La programmation des chaînes tv beIN SPORTS en France. Grille TV des chaînes beIN SPORTS 1 beIN SPORTS 2 beIN SPORTS 3...Retrouvez les tendances des programmes tv sur les réseaux sociaux. - http://www.beinsports.com/france/programmes - Grille TV - Programme TV beIN SPORTS ... C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\gkojegiobdmkbhkiaedodhlgfnkalaob = : Impôts locaux - https://www.service-public.fr/particuliers/vosdroits/N206 - Impôts locaux | service-public.fr C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\hfldodhibgenhgmbcokopfciaimpmmjm = : La Compagnie du Mont Blanc financera un important plan d'investissements à moyen terme sur Megève en vue de rénover les installations existantes et accroitre la qualité de services. - http://www.chamonix.net/francais/actualite/cmb-financera-le-domaine-skiable-de-meg%C3%A8ve - CMB financera le domaine skiable de M... C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\hhcifghlmkakcplaopjfhancbfmelmog = : Près de 50 000 annonces de chambre à louer chez l’habitant. Jusque 3 fois moins cher que l’hôtel réservez dès maintenant une chambre chez l’habitant partout dans le monde une chambre d’étudiant un b&b - BedyCasa c’est la garantie de faire de belle rencontre et dormir à moindre coût. - https://fr.bedycasa.com/ - Chambre à louer chez l’habitant cham... C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\hhfafmppmelhclinjcpdacmogjfleodp = : Achat et vente en ligne parmi des millions de produits en stock. Livraison gratuite à partir de 25€. Vos articles à petits prix : culture high-tech mode jouets sport maison et bien plus ! - https://www.amazon.fr/ - Amazon.fr : livres DVD jeux vidéo ... C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\hkbojijmjninifclmdilgodgjgnabhkl = : - https://www.google.fr/maps/@43.67928653.975455864m/data=!3m1!1e3 - Google Maps C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\hkohamlakodogmgkjbklfnhpadfaineb = : - https://compteperso.leboncoin.fr/account/index.html?ca=12_s - Accéder à mon compte - Leboncoin.fr C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\hlhkpnaopmjkkikhgffonmdbgopcmgko = : - http://www.lenergiemoinscher.com/les-travaux-concernes/ - Primes énergie E.Leclerc | LES TRAVAU... C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\hpaopchffpbpchjalmimjikihdlandhn = : 50.000 produits disponibles en 24 heures. Häfele est un spécialiste des ferrures de meubles et de matériel de construction partenaire précieux des menuisiers architectes et de l'industrie du meuble - https://www.hafele.fr/fr/ - Ferrures de meubles quincaillerie de... C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\ibmnbgjkmnmpoihdkeoaahmjinogebgj = : Conseil installation suivi de la consommation d'énergie de votre habitat ; Impact Energie est votre partenaire pour des économies au sein de votre habitat - http://www.impactenergie.com/ - IMPACT ENERGIE | Spécialiste en écono... C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\ifbmbpeciboomkkiihcambnjkedpegik = : Téléchargez gratuitement des milliers de logiciels - http://www.pcastuces.com/logitheque/miseajour.asp?page=1 - PC Astuces : Logithèque et Télécharge... C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\igbplhgjomdhejpbicecaokplgjhaalg = : Site officiel de l'Assurance retraite (Cnav Carsat CGSS) – Informations et services sur la retraite à destination des salariés du secteur privé. - https://www.lassuranceretraite.fr/portail-info/accueil - L'Assurance retraite C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\ihmifbceifjefbbifojjnlobmdjkhmbd = : Can anyone help me with wlm error code 0x8007007A? I get this message whenever I try to send an email. Any help will be greatly appreciated. Nick (nickbo13) - http://answers.microsoft.com/en-us/windows/forum/windows8_1-ecoms/windows-live-mail-error-code-0x8007007a/d85a3e8e-942d-4a98-8f05-7804d6c2422c?page=2 - fenêtres code d'erreur de messagerie ... C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\jjhimoahifbphelgbhedpjlpfjehmlki = : Comment entretenir une piscine hors sol ? Ca ne prend pas plus d'1 à 2 heures par semaine quand on sait comment faire. Toutes les infos ici - http://piscineinfoservice.com/entretien/comment-entretenir-piscine-hors-sol - Comment entretenir une piscine hors s... C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\jjmnmfkfphahmdnklldphfgmmikhkeln = : - https://abonnement.vinci-autoroutes.com/Coordonnees?cod_crcl=EVA1&typo=P&cod_ste=04 - Abonnement VINCI Autoroutes C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\jnhbkcbedefpkfinpgcokiljlkfmcaih = : - http://www.hthpiscine.com/HTH/fr/particulier/produit/2/chlore-non-stabilise/255/hth-shock-poudre.html - Particulier C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\jpfcfcdhfgpfdnklleiichbabhjfaihi = : - https://conso.bloctel.fr/ - Accueil - Espace consommateur C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\jphhaoloojelefcncknmgjampjpeniah = : - https://secure.fr.vente-privee.com/authentication/login/FR?ReturnUrl=%2fvp4%2fHome%2fDefault.aspx - Vente-privee.com : grandes marques à ... C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\kbgagjffkppcdakolhpikoihlgkkfhde = : Schlüter®-DESIGNLINE est un listel pour la décoration des revêtements muraux. La gamme se coordonne facilement avec les profilés Schlüter®-RONDEC. - http://www.schluter-systems.fr/DESIGNLINE-profile-mur-carrelage.aspx - Schlüter®-DESIGNLINE | Fonction | Sch... C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\kdjeliceklomhmamelfjnjjmnppmkban = : Proche de l'autoroute A75 à 25 minutes de Clermont-Ferrand et au centre de l'Auvergne trouvez facilement une chambre d'hôte en Pays d'Issoire. - http://www.issoire-tourisme.com/je-prepare/hebergements/chambres-dhotes/ - issoire C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\kdnanlkeigefjhmljpccbnhkelongaib = : Pour tout savoir sur le stabilisant piscine! Quelle différence entre chlore stabilisé et non stabilisé? Combien de stabilisant dans la piscine? Effets indésirables? - http://www.piscine-clic.com/news/2012/07/tout-ce-que-vous-devez-savoir-sur-le-stabilisant-du-chlore-ou-acide-isocyanurique/ - A quoi sert le stabilisant du chlore ... C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\kicnblpokpolcjdoggmghhokdlbmdjpj = : L’eau de votre piscine est trouble ou laiteuse ? Ce problème peut être dû à une variation importante du pH ou à une filtration insuffisante. L’utilisation d’un floculant peut tout arranger. - http://www.guide-piscine.fr/analyse-traitement-eau/couleur-aspect-eau/eau-de-piscine-laiteuse-818_A - Eau de piscine laiteuse : que faire ? C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\kinncfbkfghflboolkdljdfjibpdcihe = : Nous vous proposons un pack de 2 Flovil contenant chacun 18 pastilles de floculant - http://www.piscine-clic.com/produits-piscine-floculant/12642-pack-de-2-flovil-18-pastilles-de-floculant.html#more_info_block - Pack de 2 Flovil pastilles de floculant C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\kipgklbmmjkhlmejofgacfgnhboacodb = : Recette de cuisine Marmiton - http://www.marmiton.org/recettes/recette_aubergines-grillees-sans-matiere-grasse_72198.aspx - marmiton.org C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\kkbllkmonkmackngjhgiecnaamaanpjd = : - http://www.triganostore.com/customer/account/login/ - Login du client C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\kkhnppcpnnnfebbheonicomnlnndcjgn = : EDF fournisseur d'énergie vous propose ses offres d'électricité et de gaz naturel et met à votre service des experts pour vos travaux de rénovation. - https://particulier.edf.fr/fr/accueil.html - EDF Particuliers fournisseur d'élect... C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\kmplihgalkangojailipjahndmhdbejo = : L'Hotel Prado II est situé à Peñiscola sur la Costa Azahar à 50 mètres de la plage. - http://www.booking.com/hotel/es/prado-2.fr.html?aid=7344163;label=metatripad-link-dmetafr-hotel-339211_xqdz-fa186713f089502d7f706186ec147efd_los-06_bw-049_dom-fr_curr-EUR_gst-02_nrm-01_clkid-V43xtQoQHnkAAuTtY24AAAAe_aud-1008;sid=965edd0390de7b38f18fb7346274e063;dcid=4;checkin=2016-09-06;checkout=2016-09-12;room1=AA;homd=1;atlas_src=hp_iw_btn - Booking.com: Hotel Prado II - Peñísco... C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\kolehgjecblaepeagoboagkoehaeicgn = : Retrouvez les infos et conseils boursiers sur Investir - Les Echos Bourse: actu des marchés conseils valeurs… - http://investir.lesechos.fr/index.php - App C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\lajmibpmehmbfcelohcioinecfipemma = : FranceLoc est le spécialiste du camping 4 étoiles en France. Nos nombreuses destinations mer ou campagne vous proposeront différents types d'hébergement en location : camping mobil home chalet gîte. - https://www.franceloc.fr/clix/index.php - CliX Campings et Résidences FranceLoc... C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\lchmfkmplhfajhhmbciljgkbhgdnkbob = : - https://www.google.fr/maps/@43.67961383.97858415z?hl=fr&hl=fr - Google Maps C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\lebgngchkibkmgnaodfbeiangicoonea = : Pain de lotte – Ingrédients :1 kg de lotte que l'on peut séparer en deux soit 500 g de cabillaud et 500 g de lotte4 oeufs1 mignonette de concentré de tomatessel ... - http://www.cuisineaz.com/recettes/pain-de-lotte-13920.aspx - Pain de lotte | Cuisine AZ C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\lhbencfolmmbhoacclfaliepjdheenjj = : Smash the file transfer service for the 21st century. - https://www.fromsmash.com/ - Smash C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\ljlenmaghaejcjgobgjoiepkphldbihd = : - http://investir.lesechos.fr/cours/matiere-premiere-petrole-brentwcomocebrousdbrspcebrousdbrspiso.html?xtor=EPR-6-[NL_cloture]-20160819-[Prov_]-904884@3 - App C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\lkdmkkhbhiemojpkpeembegeogdgookk = : - http://www.pcastuces.com/pratique/windows/disque_cle_usb_installation_windows_10/page1.htm - PC Astuces - Créer un disque ou une c... C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\lkdnjjllhbbhgjfojnheoooeabjimbka = : - https://drive.google.com/drive/my-drive - Mon Drive - Google Drive C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\lkpajdbcckjpdciggbanolcjegddabnd = : lll? Tous les bus en un clin d'œil : comparez ici horaires prix et confort. busradar.fr est le comparateur de bus en France et en Europe : Comparez. Trouvez. Voyagez. - https://www.busradar.fr/recherche/?From=Montpellier&To=Antibes&When=2016-09-12&Passengers=1&ShowRidesharing=true&ShowRidesharing=false - busradar.fr C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\lnlmjomeflimdgnjolokbiknigpmglkf = : - http://www.ville-lecres.fr/index.php?id_rubrique=1&id_sous_rubrique=25 - Site officiel du Crès C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\lpikcgfgloipfplklhdhdacaipjcpald = : Réfrigérateur évier casseroles... Des astuces qui se transmettent de génération en génération à la fois écologiques et économiques permettent de leur redonner de l'éclat. - http://www.notretemps.com/famille/maison-developpement-durable/cuisine-10-astuces-grand-mere-ca-brillei115526?utm_campaign=Newsletter%20edito%20mardi%2007/06/16%20ABO&utm_content=nt_www_sticker&utm_id=201331690&utm_medium=email&utm_source=Newsletter%20Editoriale - Cuisine: 10 astuces de grand-mère pou... C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\mahifkjblanjfkcokgkceoibdebhfpff = : - http://www.vinsphilippevandelle.com/Fiches%20techniques/Fiche%20vieille%20vigne%202010.pdf - Fiche vieille vigne 2010.pdf C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\majdkbnfdfngobonpgnamepmbonpkajc = : - http://www.booking.com/searchresults.fr.html?aid=7344163&dcid=4&label=metatripad-link-dmetafr-hotel-339211_xqdz-fa186713f089502d7f706186ec147efd_los-06_bw-049_dom-fr_curr-EUR_gst-02_nrm-01_clkid-V43xtQoQHnkAAuTtY24AAAAe_aud-1008&sid=5043d77fb9bc58224e3a812265ef9bc8&sb=1&src=hotel&src_elem=sb&error_url=http%3A%2F%2Fwww.booking.com%2Fhotel%2Fes%2Fservipapaluna.fr.html%3Faid%3D7344163%3Blabel%3Dmetatripad-link-dmetafr-hotel-339211_xqdz-fa186713f089502d7f706186ec147efd_los-06_bw-049_dom-fr_curr-EUR_gst-02_nrm-01_clkid-V43xtQoQHnkAAuTtY24AAAAe_aud-1008%3Bsid%3D5043d77fb9bc58224e3a812265ef9bc8%3Bdcid%3D4%3Ball_sr_blocks%3D9151003_90259289_0_17_0%3Bcheckin%3D2016-09-06%3Bcheckout%3D2016-09-12%3Bdest_id%3D-396163%3Bdest_type%3Dcity%3Bdist%3D0%3Bhighlighted_blocks%3D9151003_90259289_0_17_0%3Bhpos%3D16%3Broom1%3DA%252CA%3Bsb_price_type%3Dtotal%3Bsrfid%3D87a6488d4f4960a5ddeba60e250f95a092a4d211X16%3Btype%3Dtotal%3Bucfs%3D1%26%3B&highlighted_hotels=91510&hp_sbox=1&ss=Pe%C3%B1%C3%ADscola&ssne=Pe%C3%B1%C3%ADscola&ssne_untouched=Pe%C3%B1%C3%ADscola&city=-396163&checkin_monthday=10&checkin_year_month=2016-9&checkout_monthday=18&checkout_year_month=2016-9&room1=A%2CA&no_rooms=1&group_adults=2&group_children=0 - Booking.com: Hôtels : Peñíscola. Rése... C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\maobkccpglcifeibfjeiohhllldalofg = : Bienvenue sur vente-privee.com le site des ventes événementielles. Chaque jour les plus grandes marques à prix discount : vêtements lingerie électroménager gastronomie et vins… - https://secure.fr.vente-privee.com/authentication/portal/FR - Vente-privee.com : grandes marques à ... C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\mbfifeopkoiknobdhllchpjkidegpfdm = : Profitez du confort d'une cuisson contrôlée avec cette plancha gaz 3 brûleurs. Surface de cuisson en fonte émaillée. Rapport qualité/prix imbattable ! - http://www.triganostore.com/plancha-gaz-3-bruleurs-42-x-62-cm.html#product-tab-reviews - Plancha gaz 3 brûleurs 42 x 62 cm : T... C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\mfchijchnghbeldgknkdecekhbmdbcpa = : Online Shopping at GearBest for the best cell phones electronic gadgets toys sporting goods home products and apparel for geeks at unbeatable great prices. - http://www.gearbest.com/ - GearBest: Online Shopping - Best Gear... C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\mhblnanebdeailnobegpgmhcjbhnpnco = : Découvrez nos Voitures de collaborateurs - occasions Citroen à faibles kilométrages sous garantie constructeur. - http://www.collcit.com/Collcit/HomePage.aspx - Voitures collaborateurs Citroën Occas... C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\mjclljhlcjlocjipnelldkpamafegakk = : Schlüter®-RONDEC est un profilé pour angles sortants présentant un arrondi symétrique. - http://www.schluter-systems.fr/RONDEC-profil%C3%A9-mur-carrelage.aspx - Schlüter®-RONDEC | Fonction | Schlüte... C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\nbojdklgeenolhnikfneoemdjbekghmi = : ANEO est un partenaire de Ma Maison Solutions Habitat d'EDF qui réalise vos travaux Chauffage Eau chaude sanitaire Ventilation / Climatisation Isolation à BAILLARGUES. - https://travaux.edf.fr/trouver-un-professionnel/partenaire/aneo-7604A6A52B9B8E75DFEFC7A793C1180999E899F2 - EDF Travaux C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\nejpibmibbppnijkfhdhonmolkmknipj = : Vous avez récupéré un fichier au format MP3 ou vous avez converti un CD\nAudio et votre fichier comporte des portions que vous aimeriez récupérer ou\nau contraire des plages que vous voulez éliminer. - http://www.01net.com/astuces/extraire-une-portion-dun-mp3-555466.html - 01net C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\nmmhkkegccagdldgiimedpiccmgmieda = : Google & co - Google & co - 203784468217.apps.googleusercontent.com - https://clients2.google.com/service/update2/crx C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\noppfligjkhknhmdghbifkglpbhakcpb = : Résolu : Bonjour depuis quelques jours il m'est impossible d'envoyer des mail de mon compte SFR depuis windows live mail. Par contre je les - 1570027 - http://forum.sfr.fr/t5/Votre-messagerie-SFR-Mail/Impossible-d-envoyer-des-messages-avec-compte-SFR-depuis-windows/td-p/1570027 - Résolu : Impossible d'envoyer des mes... C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\obpkmfocdmgdobacbdiaekmiebbnmdjb = : Rideaux - http://www.qama.fr/rideaux_27761 - Rideaux - Quincaillerie Qama C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\oddlpildkkfapogknnfjlabagmeihhel = : Chambre privée pour 45€. Attractions: Cathedral Ramblas Barceloneta Portal del Angel. You 'll love my place because of the cozy space and location - in the heart of the ... - https://www.airbnb.fr/rooms/14210522?checkin=10%2F10%2F2016&checkout=13%2F10%2F2016&guests=2&s=_SH3DrOh&sug=50 - Catedral - Double room + WIFI + share... C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\oecfddnmddcdnnnpdmjefpghgnjdekgf = : - https://www.google.fr/webhp?sourceid=chrome-instant&ion=1&espv=2&ie=UTF-8#q=Une+erreur+inconnue+s'est+produite.+Objet+'test+envoi'+Erreur+de+serveur+%3A+451+R%C3%A9ponse+du+serveur+%3A+451+4.3.0+Error%3A+queue+file+write+error+Serveur+%3A+'smtp-auth.sfr.fr'+Num%C3%A9ro+d'erreur+Windows+Live+Mail+%3A+0x800CCC6A+Protocole+%3A+SMTP+Port+%3A+587+S%C3%A9curis%C3%A9+(SSL)+%3A+Non - Une erreur inconnue s'est produite. O... C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\ogmenkndamemaglcdkbnbpdbfbdghmkm = : LEONID AFREMOV - https://afremov.com/FIELD-BOUQUET-PALETTE-KNIFE-Oil-Painting-On-Canvas-By-Leonid-Afremov-Size-24x30.html - FIELD BOUQUET - PALETTE COUTEAU Peint... C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\ohiglmoobedpjakbiminfidkijifpihd = : - https://espace-particuliers.humanis.com/?utm_source=interne_eservices&utm_medium=email&utm_content=Extranautes_Non_Optin&utm_term=CTA_Je_Cree_Mon_compte&utm_campaign=2016_03_Information_Fiscale - Accueil - Espace Particuliers C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\oijlpepeaeckikdlljcaoijgijbdhblg = : - http://www.tousaurestaurant.com/ - Tous au Restaurant C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\ojcgbpdfnphkafjmdkoogmhbapnnhckc = : - https://www.labanquepostale.fr/#layer - Banque - banque en ligne - La Banque ... C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\ojgkknkfaadfpmchofgkpjdoijcldbbp = : LDD : livret developpement durable - plafond LDD et taux LDD - La Banque Postale - https://www.labanquepostale.fr/particulier/produits/epargne/livrets/livrets_defiscalises/ldd.caracteristiques.html - Caractéristiques – La Banque Postale C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\ojlhkjedjbapejfcmhapleaofffmkpbh = : - https://www.rehau.com/download/953786/systeme-de-rideaux-d-armoires-pour-la-cuisine.pdf - systeme-de-rideaux-d-armoires-pour-la... C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\oklfoejikkmejobodofaimigojomlfim = : __MSG_manifest_description__ - short_name: __MSG_product_name__ - https://clients2.google.com/service/update2/crx C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\okpmfaahdeihhohklkefjicpmdinhcci = : Site Destination nature pour des vacances en famille : Imbours camping Rhône Alpes à LARNAS avec piscine En pleine nature. Franceloc propose hebergements en camping location mobil home ou gites. - http://www.domaine-imbours.com/#descriptif - Camping Imbours à LARNAS Rhône Alpes C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\ombkgjonblhkdiolkakdogkjjmeofbaa = : Retrouve avec Trombi.com - retrouveur d'amis - tes anciens camarades de classe tes collègues tes camarades de promotions tes premiers amours et tes amis perdus de vue ! - http://www.trombi.com/contactlist/mycontacts - Trombi.com C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\omipbngkpbfamlljmcfgcagmbefpchlk = : Vous louez votre appartement : choisissez notre pack diagnostic location appartement pour n’oublier aucun diagnostic obligatoire et sécuriser votre transaction. - https://www.allodiagnostic.com/toutes-nos-offres/diagnostic-location-appartement/ - Pack Diagnostic Location Appartement ... C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\oplljonkohdjelhmfljfeoijbicgbkea = : - https://assure.ameli.fr/PortailAS/appmanager/PortailAS/assure?_nfpb=true&_pageLabel=as_accueil_page - ameli.fr - Compte assurés - Connexion... C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\paoemkahgkmoookgbdocaempbofgfdod = : Breathe in the freshness of this amazing bouquet painted in oil with a palette knife! Check out more Leonid Afremov paintings for sale in our online gallery and enjoy free delivery to any country of the world! - https://afremov.com/FONDNESS-Palette-knife-Oil-Painting-on-Canvas-by-Leonid-Afremov-Size-36-x30.html - Fondness - Palette couteau Peinture à... C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\pcahckihlghadjmgcoiochphcnldgfoo = : Histoire d'une piscine verte... Remplie d'algues en 2-3 jours il a fallu 3 semaines pour rattraper l'eau. - http://piscineinfoservice.com/entretien/rattrapage-eau-verte-etude-de-cas - Rattrapage Eau Verte (Etude de Cas) C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\pfiinghdanogomkgfjpdkopifkcmmbkj = : - http://images.google.fr/imgres?imgurl=https%3A%2F%2Fgalerie.alittlemarket.com%2Fgalerie%2Fsell%2F8138%2Fcartes-carte-theiere-rouge-a-pois-et-ses-7396261-tableaux-gourmac86d-975c7_big.jpg&imgrefurl=https%3A%2F%2Fwww.alittlemarket.com%2Fcartes%2Ffr_carte_theiere_rouge_a_pois_et_ses_gourmandises-7396261.html&h=1188&w=1920&tbnid=gxgU_hogYkzuiM%3A&docid=oILkl7uLPNnCRM&ei=RZlMV9flAsyS6QSex6egDA&tbm=isch&iact=rc&uact=3&dur=5&page=1&start=0&ndsp=22&ved=0ahUKEwiXnNftyILNAhVMSZoKHZ7jCcQQMwgiKAEwAQ&noj=1&bih=595&biw=1280 - Résultats Google Recherche d'images c... C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\pjcadlfoeaipfepkldiaklflellcnppl = : Schlüter®-KERDI-BOARD convient particulièrement pour la réalisation de plans de travail de cuisines ou autres surfaces de rangement avec revêtement en céramique ou en pierre naturelle. - http://www.schluter-systems.fr/plan-de-travail-cuisine-sur-mesure.aspx - Plans de travail et crédences avec Sc... C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm = : Provider for discovery and services for mirroring of Chrome Media Router - Chrome Media Router - 919648714761-55j965o0km033psv3i9qls5mo3qtdrb0.apps.googleusercontent.com - https://clients2.google.com/service/update2/crx C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\pmbnmipifblhpjabcbnpjjiaecdgfapl = : Découvrez l'offre Réchaud Essentielb EPI FACILIA avec Boulanger. Retrait en 1 heure dans nos 125 magasins en France*. - web_url: http://www.boulanger.com/ref/149735?xtor=SEC-6904-GOO&xts=171153&origin=%7Badtype%7D&kwd=%7Bkeyword%7D&gclid=CK3Zk8-8yM4CFUQcGwodJOkI5w - Essentielb EPI FACILIA chez Boulanger C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\pmppaiefojmhcgpdoleageikilppokea = : Toute l'actualité économique financière et boursière française et internationale sur Les Echos.fr - http://www.lesechos.fr/ - Les Echos.fr - Actualité économique ... C:\Users\EVRARD\AppData\Local\Google\Chrome\User Data\Default\extensions\pnkefeagooiffaepcmipohcfemhdgcjl = : Jusqu'à 28 Méga 10Go d'espace disque WiFi-MiMo Ligne téléphonique Appels illimités vers 70 destinations 250 chaînes de télévision Vidéo à la Demande. - https://subscribe.free.fr/login/ - Espace abonné Freebox [HKLM\Software\Google\Chrome\Extensions\fheoggkfdfchfphceeifdbepaooicaho] [HKLM\Software\WOW6432Node\Google\Chrome\Extensions\daanglpcpkjjlkhcbladppjphglbigam] [HKLM\Software\WOW6432Node\Google\Chrome\Extensions\eofcbnmajmjmplflapaojjnihcjkigck] [HKLM\Software\WOW6432Node\Google\Chrome\Extensions\fheoggkfdfchfphceeifdbepaooicaho] [HKLM\Software\WOW6432Node\Google\Chrome\Extensions\gomekmidlodglbbmalcneegieacbdmki] ---------- | Opera ---------- | Firefox [HKLM\Software\mozilla\Firefox\Extensions] "{4ED1F68A-5463-4931-9384-8FFF5ED91D92}"=C:\Program Files\McAfee\WebAdvisor\e10ssaffplg.xpi [HKLM\Software\WOW6432Node\mozilla\Firefox\Extensions] "{4ED1F68A-5463-4931-9384-8FFF5ED91D92}"=C:\Program Files\McAfee\WebAdvisor\e10ssaffplg.xpi [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\MozillaPlugins\@my.com/Games] - () : C:\Users\EVRARD\AppData\Local\MyComGames\NPMyComDetector.dll [HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer] - (Adobe® Flash® Player 32.0.0.303 Plugin) : C:\WINDOWS\system32\Macromed\Flash\NPSWF64_32_0_0_303.dll [HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=13.0.2.0] - (Java™ Deployment Toolkit) : C:\Program Files\Java\jre-10.0.2\bin\dtplugin\npDeployJava1.dll [HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=13.0.2.0] - (Oracle® Next Generation Java™ Plug-In) : C:\Program Files\Java\jre-10.0.2\bin\plugin2\npjp2.dll [HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0] - (Ag Player Plugin) : C:\Program Files\Microsoft Silverlight\5.1.50918.0\npctrl.dll [HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.1.3] - (VLC Multimedia Plugin) : C:\Program Files\VideoLAN\VLC\npvlc.dll [HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.1.4] - (VLC Multimedia Plugin) : C:\Program Files\VideoLAN\VLC\npvlc.dll [HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.1.5] - (VLC Multimedia Plugin) : C:\Program Files\VideoLAN\VLC\npvlc.dll [HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.2.0] - (VLC Multimedia Plugin) : C:\Program Files\VideoLAN\VLC\npvlc.dll [HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.2.1] - (VLC Multimedia Plugin) : C:\Program Files\VideoLAN\VLC\npvlc.dll [HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.2.3] - (VLC Multimedia Plugin) : C:\Program Files\VideoLAN\VLC\npvlc.dll [HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.2.4] - (VLC Multimedia Plugin) : C:\Program Files\VideoLAN\VLC\npvlc.dll [HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.2.6] - (VLC Multimedia Plugin) : C:\Program Files\VideoLAN\VLC\npvlc.dll [HKLM\Software\WOW6432Node\MozillaPlugins\@adobe.com/FlashPlayer] - (Adobe® Flash® Player 32.0.0.303 Plugin) : C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_32_0_0_303.dll [HKLM\Software\WOW6432Node\MozillaPlugins\@adobe.com/ShockwavePlayer] - (Adobe Shockwave Player) : C:\WINDOWS\SysWOW64\Adobe\Director\np32dsw_1235205.dll [HKLM\Software\WOW6432Node\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf] - () : C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [HKLM\Software\WOW6432Node\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf] - () : C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [HKLM\Software\WOW6432Node\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xdp] - () : C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [HKLM\Software\WOW6432Node\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xfdf] - () : C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [HKLM\Software\WOW6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0] - (Ag Player Plugin) : C:\Program Files (x86)\Microsoft Silverlight\5.1.50918.0\npctrl.dll [HKLM\Software\WOW6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3] - (Google Update) : C:\Program Files (x86)\Google\Update\1.3.35.422\npGoogleUpdate3.dll [HKLM\Software\WOW6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9] - (Google Update) : C:\Program Files (x86)\Google\Update\1.3.35.422\npGoogleUpdate3.dll [HKLM\Software\WOW6432Node\MozillaPlugins\Adobe Reader] - (Handles PDFs in-place in Firefox) : C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll C:\Users\EVRARD\AppData\Roaming\Mozilla\Firefox\Profiles\7emrho3h.default-1554397007798\Prefs.js user_pref("browser.startup.homepage_override.buildID", "20190326175229"); user_pref("browser.startup.homepage_override.mstone", "66.0.2"); user_pref("extensions.blocklist.pingCountVersion", 0); user_pref("extensions.databaseSchema", 28); user_pref("extensions.getAddons.databaseSchema", 5); user_pref("extensions.lastAppVersion", "66.0.2"); user_pref("extensions.lastPlatformVersion", "66.0.2"); user_pref("extensions.pendingOperations", false); user_pref("extensions.systemAddonSet", "{\"schema\":1,\"addons\":{}}"); user_pref("extensions.webcompat.perform_injections", true); user_pref("extensions.webcompat.perform_ua_overrides", true); user_pref("extensions.webextensions.uuids", "{\"formautofill@mozilla.org\":\"b0792e7f-4bef-404c-a2b9-5dac7e1b86e8\",\"screenshots@mozilla.org\":\"68e54cbb-0064-41d7-b815-7f63b3572734\",\"webcompat-reporter@mozilla.org\":\"4d4a07a8-0522-404f-9321-4bb4b2d76192\",\"webcompat@mozilla.org\":\"fe9630b3-0ba5-4cc2-958f-af3cecffeed9\"}"); C:\Users\EVRARD\AppData\Roaming\Mozilla\Firefox\Profiles\qda5yvll.default\Prefs.js user_pref("app.normandy.startupRolloutPrefs.extensions.fxmonitor.enabled", true); user_pref("browser.startup.homepage_override.buildID", "20190326175229"); user_pref("browser.startup.homepage_override.mstone", "66.0.2"); user_pref("e10s.rollout.cohort", "webextensions-multiBucket4"); user_pref("extensions.avastwrc.settings", "{\"current\":{\"callerId\":2020,\"userId\":\"a68a7b391688bbfdcb53b5970e2ab85d\",\"edition\":0,\"lastApplicationEventSent\":1487940530234},\"features\":{\"phishing\":true,\"dnt\":true,\"dntSocial\":false,\"dntAdTracking\":false,\"dntWebAnalytics\":false,\"dntOthers\":false,\"siteCorrect\":true,\"siteCorrectAuto\":false,\"safeZone\":true,\"communityIQ\":false,\"serp\":true,\"serpPopup\":true},\"siteCorrect\":{\"declined\":{}},\"safeZone\":{\"declined\":{}},\"phishing\":{\"trusted\":{}}}"); user_pref("extensions.avastwrc.whiteList", "{\"trk\":{\"apps.facebook.com\":{\"703\":false},\"avast.com\":{\"779\":false}}}"); user_pref("extensions.blocklist.lastModified", "Fri, 29 Mar 2019 08:10:44 GMT"); user_pref("extensions.blocklist.pingCountTotal", 139); user_pref("extensions.blocklist.pingCountVersion", 3); user_pref("extensions.databaseSchema", 28); user_pref("extensions.e10s.rollout.blocklist", ""); user_pref("extensions.e10s.rollout.hasAddon", true); user_pref("extensions.e10s.rollout.policy", "50allmpc"); user_pref("extensions.e10sBlockedByAddons", false); user_pref("extensions.e10sMultiBlockedByAddons", false); user_pref("extensions.getAddons.cache.lastUpdate", 1554053484); user_pref("extensions.getAddons.databaseSchema", 5); user_pref("extensions.hotfix.lastVersion", "20170302.01"); user_pref("extensions.lastAppBuildId", "20190326175229"); user_pref("extensions.lastAppVersion", "66.0.2"); user_pref("extensions.lastPlatformVersion", "66.0.2"); user_pref("extensions.pendingOperations", false); user_pref("extensions.pioneer-enrollment-study.enrollmentState", "{\"stage\":\"first-prompt\",\"time\":1523284024452}"); user_pref("extensions.pioneer-enrollment-study.expirationDateString", "2018-04-16T14:22:04.376Z"); user_pref("extensions.pocket.settings.test.panelSignUp", "v1"); user_pref("extensions.pug.lookingglass", false); user_pref("extensions.shownSelectionUI", true); user_pref("extensions.systemAddonSet", "{\"schema\":1,\"directory\":\"{54a86f05-706b-41fa-9a71-65ef5f03395f}\",\"addons\":{\"fxmonitor@mozilla.org\":{\"version\":\"2.8\"}}}"); user_pref("extensions.ui.dictionary.hidden", true); user_pref("extensions.ui.experiment.hidden", true); user_pref("extensions.ui.lastCategory", "addons://list/plugin"); user_pref("extensions.ui.locale.hidden", true); user_pref("extensions.webcompat.perform_injections", true); user_pref("extensions.webcompat.perform_ua_overrides", true); user_pref("extensions.webextensions.ExtensionStorageIDB.migrated.sp@avast.com", true); user_pref("extensions.webextensions.ExtensionStorageIDB.migrated.wrc@avast.com", true); user_pref("extensions.webextensions.uuids", "{\"wrc@avast.com\":\"567d616e-89c5-41b1-80a9-c046e6550229\",\"sp@avast.com\":\"91e16af1-5b42-4356-b61d-04924c6c5691\",\"screenshots@mozilla.org\":\"e1abc3bd-55a3-47c7-a66a-61f18df4e532\",\"webcompat@mozilla.org\":\"e7748c5c-ea1f-4d58-9bb8-974d608987b5\",\"formautofill@mozilla.org\":\"23e6604c-764c-4aae-9c3a-c86a20c6648f\",\"fxmonitor@mozilla.org\":\"f9d29ecb-5da1-48e9-b929-db32ba36b818\",\"webcompat-reporter@mozilla.org\":\"11ccde05-3b85-4def-8101-1e11c52a779c\"}"); C:\Users\EVRARD\AppData\Roaming\Mozilla\Firefox\Profiles\rim3ou4e.default-release\Prefs.js user_pref("app.normandy.startupRolloutPrefs.extensions.fxmonitor.enabled", true); user_pref("browser.startup.homepage_override.buildID", "20190619235627"); user_pref("browser.startup.homepage_override.mstone", "67.0.4"); user_pref("extensions.blocklist.pingCountTotal", 2); user_pref("extensions.blocklist.pingCountVersion", 2); user_pref("extensions.databaseSchema", 31); user_pref("extensions.getAddons.cache.lastUpdate", 1561041264); user_pref("extensions.getAddons.databaseSchema", 5); user_pref("extensions.incognito.migrated", true); user_pref("extensions.lastAppBuildId", "20190619235627"); user_pref("extensions.lastAppVersion", "67.0.4"); user_pref("extensions.lastPlatformVersion", "67.0.4"); user_pref("extensions.pendingOperations", false); user_pref("extensions.systemAddonSet", "{\"schema\":1,\"addons\":{}}"); user_pref("extensions.webcompat.perform_injections", true); user_pref("extensions.webcompat.perform_ua_overrides", true); user_pref("extensions.webextensions.ExtensionStorageIDB.migrated.screenshots@mozilla.org", true); user_pref("extensions.webextensions.uuids", "{\"formautofill@mozilla.org\":\"06bdc23b-9773-48cc-bac2-4cbf2c6e814e\",\"fxmonitor@mozilla.org\":\"da3ac6f1-3e3c-4445-8d0b-0a5a56313472\",\"screenshots@mozilla.org\":\"da141416-7c13-42c2-9829-0432a4cab577\",\"webcompat-reporter@mozilla.org\":\"489911b7-cf4f-48f0-9ca4-688a74b26ceb\",\"webcompat@mozilla.org\":\"e745ed29-0cf9-4410-9618-c3c8d29b92cd\"}"); user_pref("services.sync.extension-storage.lastSync", "0"); C:\Users\EVRARD\AppData\Roaming\Mozilla\Firefox\Profiles\zfoj87gz.default-1554397160157\Prefs.js user_pref("browser.startup.homepage_override.buildID", "20191202093317"); user_pref("browser.startup.homepage_override.mstone", "71.0"); user_pref("extensions.activeThemeID", "default-theme@mozilla.org"); user_pref("extensions.blocklist.lastModified", "Fri, 13 Dec 2019 13:02:03 GMT"); user_pref("extensions.blocklist.pingCountTotal", 40); user_pref("extensions.blocklist.pingCountVersion", 3); user_pref("extensions.databaseSchema", 31); user_pref("extensions.getAddons.cache.lastUpdate", 1576426470); user_pref("extensions.getAddons.databaseSchema", 5); user_pref("extensions.incognito.migrated", true); user_pref("extensions.lastAppBuildId", "20191202093317"); user_pref("extensions.lastAppVersion", "71.0"); user_pref("extensions.lastPlatformVersion", "71.0"); user_pref("extensions.pendingOperations", false); user_pref("extensions.signer.hotfixed", true); user_pref("extensions.systemAddonSet", "{\"schema\":1,\"addons\":{}}"); user_pref("extensions.ui.dictionary.hidden", true); user_pref("extensions.ui.lastCategory", "addons://list/plugin"); user_pref("extensions.ui.locale.hidden", true); user_pref("extensions.webcompat.perform_injections", true); user_pref("extensions.webcompat.perform_ua_overrides", true); user_pref("extensions.webextensions.ExtensionStorageIDB.migrated.screenshots@mozilla.org", true); user_pref("extensions.webextensions.ExtensionStorageIDB.migrated.{4ED1F68A-5463-4931-9384-8FFF5ED91D92}", true); user_pref("extensions.webextensions.uuids", "{\"formautofill@mozilla.org\":\"9b9a527f-37b0-4669-a4d6-49351ee378de\",\"screenshots@mozilla.org\":\"2aa7ba18-1015-4d83-b4bb-7359c0b91140\",\"webcompat-reporter@mozilla.org\":\"a37b9b40-8d96-4353-abab-16c7682486b1\",\"webcompat@mozilla.org\":\"a4b18ce6-badf-40c2-add5-c1b0b6520b1c\",\"wrc@avast.com\":\"fd412af8-1f0a-4ea3-8dee-d69dadbad382\",\"baidu-code-update@mozillaonline.com\":\"6580e799-2ee9-493a-b93c-f8da81cf8d2c\",\"fxmonitor@mozilla.org\":\"fa5e1a79-a6d1-44c9-b648-296b4ad9572f\",\"sp@avast.com\":\"b0527c17-6851-4177-9168-725a825dbf52\",\"{4ED1F68A-5463-4931-9384-8FFF5ED91D92}\":\"aa8a6770-9697-4a99-9abc-88925f7d677d\",\"default-theme@mozilla.org\":\"2f4b3f2c-7683-42f0-a5ae-88e6dd61730b\",\"google@search.mozilla.org\":\"d3d0bea5-f76e-45ba-9046-3f3374e18ea3\",\"bing@search.mozilla.org\":\"f4074029-4bf2-4b4f-9798-de83259bbf99\",\"amazon@search.mozilla.org\":\"7f80cc03-3124-4fec-9b49-0762ec28e440\",\"ddg@search.mozilla.org\":\"bfdb802c-e8b5-4a44-b2f8-f448c463d3d0\",\"ebay@search.mozilla.org\":\"580bd970-745a-4bc0-8db0-4fbf1bdd38f7\",\"qwant@search.mozilla.org\":\"86324bc6-28a5-4fc4-aff2-c33238b72d7e\",\"wikipedia@search.mozilla.org\":\"6db690f7-8d6f-47dc-b759-1edbccfc6a9e\",\"twitter@search.mozilla.org\":\"01c917c3-6b94-4eec-ba2d-8995d8a43d5b\"}"); [Profile0] - Name=default -> Profiles/zfoj87gz.default-1554397160157 ---------- | DNS [HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters] "DhcpNameServer"=212.27.40.240 212.27.40.241 [HKLM\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{6b03ebe8-1a2e-4091-a00d-b9862e249720}] "DhcpNameServer"=212.27.40.240 212.27.40.241 [HKLM\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{93e1ff97-b2ec-4b90-9776-bc0da7422eec}] "DhcpNameServer"=212.27.40.240 212.27.40.241 [HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{6b03ebe8-1a2e-4091-a00d-b9862e249720}] "DhcpNameServer"=212.27.40.240 212.27.40.241 [HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{93e1ff97-b2ec-4b90-9776-bc0da7422eec}] "DhcpNameServer"=212.27.40.240 212.27.40.241 ---------- | Applications [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Classes\Applications\chrome.exe] : "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" "%1" [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Classes\Applications\firefox.exe] : "C:\Program Files\Mozilla Firefox\firefox.exe" "%1" [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Classes\Applications\FreemakeVideoConverter.exe] : "C:\Program Files (x86)\Freemake\Freemake Video Converter\FreemakeVideoConverter.exe" "%1" [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Classes\Applications\ImgBurn.exe] : "C:\Program Files (x86)\ImgBurn\ImgBurn.exe" /MODE WRITE /SOURCE "%1" [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Classes\Applications\KeePass.exe] : "E:\Mes documents\Ma LOGITHEQUE portable Bollywood\KeePass-2.39.1\KeePass.exe" "%1" [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Classes\Applications\MyHeritage.exe] : "C:\Program Files (x86)\MyHeritage\Bin\MyHeritage.exe" "%1" [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Classes\Applications\PhotoFiltre7.exe] : "C:\Program Files (x86)\PhotoFiltre 7\PhotoFiltre7.exe" "%1" [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Classes\Applications\thunderbird.exe] : "C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe" "%1" [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Classes\Applications\vlc.exe] : "E:\Mes documents\Ma LOGITHEQUE portable Bollywood\vlc-3.0.8fr-win64\vlc-3.0.8\vlc.exe" "%1" [HKLM\SOFTWARE\Classes\Applications\iexplore.exe] : "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 [HKLM\SOFTWARE\Classes\Applications\notepad.exe] : %SystemRoot%\system32\NOTEPAD.EXE %1 [HKLM\SOFTWARE\Classes\Applications\ois.exe] : C:\Program Files (x86)\Microsoft Office\Office12\OIS.EXE /shellOpen "%1" [HKLM\SOFTWARE\Classes\Applications\photoviewer.dll] : %SystemRoot%\System32\rundll32.exe "%ProgramFiles%\Windows Photo Viewer\PhotoViewer.dll", ImageView_Fullscreen %1 [HKLM\SOFTWARE\Classes\Applications\wmplayer.exe] : "%ProgramFiles(x86)%\Windows Media Player\wmplayer.exe" /Open "%L" [HKLM\SOFTWARE\Classes\Applications\wordpad.exe] : "%ProgramFiles%\Windows NT\Accessories\WORDPAD.EXE" "%1" [HKLM\SOFTWARE\WOW6432Node\Classes\Applications\iexplore.exe] : "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 [HKLM\SOFTWARE\WOW6432Node\Classes\Applications\notepad.exe] : %SystemRoot%\system32\NOTEPAD.EXE %1 [HKLM\SOFTWARE\WOW6432Node\Classes\Applications\ois.exe] : C:\Program Files (x86)\Microsoft Office\Office12\OIS.EXE /shellOpen "%1" [HKLM\SOFTWARE\WOW6432Node\Classes\Applications\photoviewer.dll] : %SystemRoot%\System32\rundll32.exe "%ProgramFiles%\Windows Photo Viewer\PhotoViewer.dll", ImageView_Fullscreen %1 [HKLM\SOFTWARE\WOW6432Node\Classes\Applications\wmplayer.exe] : "%ProgramFiles(x86)%\Windows Media Player\wmplayer.exe" /Open "%L" [HKLM\SOFTWARE\WOW6432Node\Classes\Applications\wordpad.exe] : "%ProgramFiles%\Windows NT\Accessories\WORDPAD.EXE" "%1" ---------- | SvcHost (Whitelist) [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost] "DcomLaunch"=Power LSM BrokerInfrastructure PlugPlay DcomLaunch SystemEventsBroker DeviceInstall "rdxgroup"=RetailDemo "Camera"=FrameS "LocalServiceNoNetworkFirewall"=BFE mpssvc "diagnostics"=DiagSvc "AarSvcGroup"=AarSvc "PrintWorkflow"=PrintWorkflowUserSvc "wusvcs"=WaaSMedicSvc "BcastDVRUserService"=BcastDVRUserService "GraphicsPerfSvcGroup"=GraphicsPerfSvc "autoTimeSvc"=autoTimeSvc "ClipboardSvcGroup"=cbdhsvc "BthAppGroup"=BluetoothUserService "smbsvcs"=lanmanserver browser "DevicesFlow"=DeviceAssociationBrokerSvc DevicesFlowUserSvc DevicePickerUserSvc ConsentUxUserSvc [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost] "DcomLaunch"=DcomLaunch DeviceInstall "PrintWorkflow"=PrintWorkflowUserSvc "DevicesFlow"=DeviceAssociationBrokerSvc "smbsvcs"=lanmanserver ---------- | SvcHost - Netsvcs (Whitelist) ---------- | Software [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\4kdownload.com] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\7-Zip] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\ABBYY] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Adobe] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Ahead] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\AIDeX] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\alterpdf] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Ankama] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\AppDataLow] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Apple Inc.] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\ASUS] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\AVAST Software] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\AVerMedia TECHNOLOGIES, Inc.] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\AVerMedia TV Applications] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\AVG] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\BCL Technologies] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Blizzard Entertainment] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Browser Cleanup] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\BugSplat] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Canneverbe Limited] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Chromium] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Clients] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Common Desktop Agent] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\CompSoft] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Creative Tech] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Datastead] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\DivXNetworks] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Drivers] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\DVDVideoSoft] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Eraser] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\EuroSoft Software Development] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\FileConverter] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\FileHippo] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\FlashIntegro] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Foxit Software] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Freemake] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Glarysoft] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\GNU] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Google] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Hercules] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Icecream] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\IM Providers] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\ImgBurn] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Infonautics] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Intel] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\JavaSoft] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\KarenWare] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\KC Softwares] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\LAV] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Lexmark] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Logitech] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Macromedia] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\MagicPlusMini] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Magix] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\MAGIX AG] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\MAGIX Software GmbH] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\MainConcept] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Malwarebytes] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Malwarebytes' Anti-Malware] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\McAfee] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Microsoft] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\MiniTool Software Limited] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\MiniTool Solution Ltd.] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Mirillis] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Mozilla] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\MozillaPlugins] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\MP4Joiner] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\MP4Splitter] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\MPC-HC] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\MyHeritage.com] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Netscape] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\NLDT] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\NVIDIA Corporation] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\ODBC] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\PhotoFiltre 7] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Piriform] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Policies] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\PrinterSetupUtility] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\proDAD] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\ProtectedStorage] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\QtProject] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\RadioSure] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Realtek] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\RegisteredApplications] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Safer Networking Limited] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Samsung] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Skype] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\skypeapp-41e66b6323b3] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\skypeapp-a7794181fde2] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\SNMP] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Sony Creative Software] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\SSPrint] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\SSScan] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\SubSystems] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\SyncEngines] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\System32] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\The Complete Genealogy Reporter] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\The Document Foundation] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Thunderbird] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Trolltech] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\TuneUp] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Unity] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Vivaldi] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\VS Revo Group] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\WinRAR] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\WinRAR SFX] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Wintertree] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Wow6432Node] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Xara] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\ZebHelpProcess Helper] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\ZHP] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\AppDataLow\Software\Adobe] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\AppDataLow\Software\JavaSoft] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\AppDataLow\Software\Macromedia] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\AppDataLow\Software\Microsoft] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\Accessibility] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\Active Setup] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\ActiveMovie] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\ActiveSync] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\Assistance] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\AuthCookies] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\Avalon.Graphics] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\BingSvc] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\CalendarRT] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\CharMap] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\Clipboard] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\Command Processor] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\CommsAPHost] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\ComPstUI] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\Connection Manager] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\ContactsRT] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\CTF] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\DefaultPack] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\DeviceDirectory] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\DirectX Diagnostic Tool] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\DusmSvc] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\Ease of Access] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\EventSystem] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\Exchange] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\F12] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\FamilyStore] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\Fax] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\Feeds] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\Foxit Software] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\FTP] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\GameBar] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\GameBarApi] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\GDIPlus] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\IAM] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\IdentityCRL] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\IME] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\IMEMIP] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\Input] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\InputMethod] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\InputPersonalization] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\Installer] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\Internet Connection Wizard] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\Internet Explorer] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\Internet Mail and News] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\Java VM] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\Keyboard] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\LanguageOverlay] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\MediaPlayer] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\Messaging] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\Microsoft Management Console] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\MicrosoftEdge] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\MPEG2Demultiplexer] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\MS Design Tools] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\MSF] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\MSNMessenger] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\Multimedia] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\Narrator] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\NGC] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\Notepad] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\Office] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\OneDrive] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\Osk] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\PaidWiFi] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\Payment] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\PeerNet] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\Personalization] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\Phone] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\Pim] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\PlayToReceiver] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\Poom] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\RAS AutoDial] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\RAS Phonebook] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\Remote Assistance] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\ScreenMagnifier] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\Scrunch] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\Sensors] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\Shared] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\Shared Tools] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\Shell] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\Silverlight] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\Siuf] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\SkyDrive] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\Speech] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\Speech Virtual] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\Speech_OneCore] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\Spelling] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\SQMClient] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\StorageLibrary] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\SystemCertificates] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\TabletTip] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\TelemetryClient] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\Terminal Server Client] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\TPG] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\UCCPlatform] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\Unified Store] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\Unistore] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\UserData] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\UserDataService] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\VBA] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\VideoRenderer] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\Visual Basic] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\WAB] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\WcmSvc] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\Web Service Providers] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\wfs] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\Windows] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\Windows Live] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\Windows Live Mail] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\Windows Mail Setup] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\Windows Media] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\Windows NT] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\Windows Photo Viewer] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\Windows Script] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\Windows Script Host] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\Windows Search] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\Windows Security Health] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\Windows Services] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\Wisp] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\XAML] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\XboxLive] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Microsoft\Windows\AssignedAccessConfiguration] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Microsoft\Windows\CurrentVersion] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Microsoft\Windows\DWM] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Microsoft\Windows\PrivacySettingsBeforeCreatorsUpdate] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Microsoft\Windows\Shell] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Microsoft\Windows\ShellNoRoam] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Microsoft\Windows\TabletPC] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Microsoft\Windows\Windows Error Reporting] [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\Software\Microsoft\Windows NT\CurrentVersion] [HKLM\Software\7-Zip] [HKLM\Software\AGEIA Technologies] [HKLM\Software\AVAST Software] [HKLM\Software\Clients] [HKLM\Software\Common Desktop Agent] [HKLM\Software\CPUID] [HKLM\Software\CVSM] [HKLM\Software\DefaultUserEnvironment] [HKLM\Software\Dolby] [HKLM\Software\DTS] [HKLM\Software\FlashIntegro] [HKLM\Software\g3n-h@ckm@n] [HKLM\Software\Google] [HKLM\Software\HaaliMkx] [HKLM\Software\Hercules] [HKLM\Software\Hercules Technologies] [HKLM\Software\Huawei technologies] [HKLM\Software\Icecream] [HKLM\Software\Intel] [HKLM\Software\JavaSoft] [HKLM\Software\JreMetrics] [HKLM\Software\Khronos] [HKLM\Software\Knowles] [HKLM\Software\Lexmark] [HKLM\Software\LexmarkLaser] [HKLM\Software\LibreOffice] [HKLM\Software\Macromedia] [HKLM\Software\MAGIX] [HKLM\Software\Malwarebytes] [HKLM\Software\McAfee] [HKLM\Software\McAfee.com] [HKLM\Software\Microsoft] [HKLM\Software\Mozilla] [HKLM\Software\mozilla.org] [HKLM\Software\MozillaPlugins] [HKLM\Software\Novatek] [HKLM\Software\Nuance] [HKLM\Software\NVIDIA Corporation] [HKLM\Software\ODBC] [HKLM\Software\OEM] [HKLM\Software\Oracle] [HKLM\Software\Patch My PC] [HKLM\Software\Piriform] [HKLM\Software\Policies] [HKLM\Software\Realtek] [HKLM\Software\RegisteredApplications] [HKLM\Software\Restore Point Creator] [HKLM\Software\RTLSetup] [HKLM\Software\Samsung] [HKLM\Software\SonicFocus] [HKLM\Software\SSPrint] [HKLM\Software\SSScan] [HKLM\Software\The Document Foundation] [HKLM\Software\VDownloader] [HKLM\Software\WinRAR] [HKLM\Software\WOW6432Node] [HKLM\Software\Xiph.Org] [HKLM\SOFTWARE\Microsoft\.NETFramework] [HKLM\SOFTWARE\Microsoft\AccountsControl] [HKLM\SOFTWARE\Microsoft\Active Setup] [HKLM\SOFTWARE\Microsoft\ActiveSync] [HKLM\SOFTWARE\Microsoft\ADs] [HKLM\SOFTWARE\Microsoft\Advanced INF Setup] [HKLM\SOFTWARE\Microsoft\ALG] [HKLM\SOFTWARE\Microsoft\AllUserInstallAgent] [HKLM\SOFTWARE\Microsoft\AMSI] [HKLM\SOFTWARE\Microsoft\Analog] [HKLM\SOFTWARE\Microsoft\AOMEI] [HKLM\SOFTWARE\Microsoft\AppServiceProtocols] [HKLM\SOFTWARE\Microsoft\ASP.NET] [HKLM\SOFTWARE\Microsoft\Assistance] [HKLM\SOFTWARE\Microsoft\AuthHost] [HKLM\SOFTWARE\Microsoft\BidInterface] [HKLM\SOFTWARE\Microsoft\BitLockerCsp] [HKLM\SOFTWARE\Microsoft\CallAndMessagingEnhancement] [HKLM\SOFTWARE\Microsoft\Cellular] [HKLM\SOFTWARE\Microsoft\Chkdsk] [HKLM\SOFTWARE\Microsoft\Clipboard] [HKLM\SOFTWARE\Microsoft\ClipboardServer] [HKLM\SOFTWARE\Microsoft\COM3] [HKLM\SOFTWARE\Microsoft\Command Processor] [HKLM\SOFTWARE\Microsoft\CommsAPHost] [HKLM\SOFTWARE\Microsoft\Composition] [HKLM\SOFTWARE\Microsoft\CoreShell] [HKLM\SOFTWARE\Microsoft\Cryptography] [HKLM\SOFTWARE\Microsoft\CTF] [HKLM\SOFTWARE\Microsoft\DataAccess] [HKLM\SOFTWARE\Microsoft\DataCollection] [HKLM\SOFTWARE\Microsoft\DataMarketplace] [HKLM\SOFTWARE\Microsoft\DataSharing] [HKLM\SOFTWARE\Microsoft\DDDS] [HKLM\SOFTWARE\Microsoft\DevDiv] [HKLM\SOFTWARE\Microsoft\Device Association Framework] [HKLM\SOFTWARE\Microsoft\DeviceReg] [HKLM\SOFTWARE\Microsoft\DFP] [HKLM\SOFTWARE\Microsoft\Dfrg] [HKLM\SOFTWARE\Microsoft\DFS] [HKLM\SOFTWARE\Microsoft\DiagnosticLogCSP] [HKLM\SOFTWARE\Microsoft\DirectDraw] [HKLM\SOFTWARE\Microsoft\DirectInput] [HKLM\SOFTWARE\Microsoft\DirectMusic] [HKLM\SOFTWARE\Microsoft\DirectPlay8] [HKLM\SOFTWARE\Microsoft\DirectPlayNATHelp] [HKLM\SOFTWARE\Microsoft\DirectShow] [HKLM\SOFTWARE\Microsoft\DirectX] [HKLM\SOFTWARE\Microsoft\DownloadManager] [HKLM\SOFTWARE\Microsoft\Driver Signing] [HKLM\SOFTWARE\Microsoft\DRM] [HKLM\SOFTWARE\Microsoft\DusmSvc] [HKLM\SOFTWARE\Microsoft\DVDNavigator] [HKLM\SOFTWARE\Microsoft\DVR] [HKLM\SOFTWARE\Microsoft\DXP] [HKLM\SOFTWARE\Microsoft\EAPSIMMethods] [HKLM\SOFTWARE\Microsoft\Enrollment] [HKLM\SOFTWARE\Microsoft\Enrollments] [HKLM\SOFTWARE\Microsoft\EnterpriseCertificates] [HKLM\SOFTWARE\Microsoft\EnterpriseDataProtection] [HKLM\SOFTWARE\Microsoft\EnterpriseResourceManager] [HKLM\SOFTWARE\Microsoft\EventSounds] [HKLM\SOFTWARE\Microsoft\EventSystem] [HKLM\SOFTWARE\Microsoft\F12] [HKLM\SOFTWARE\Microsoft\FamilyStore] [HKLM\SOFTWARE\Microsoft\Fax] [HKLM\SOFTWARE\Microsoft\FaxServer] [HKLM\SOFTWARE\Microsoft\Feeds] [HKLM\SOFTWARE\Microsoft\FilePicker] [HKLM\SOFTWARE\Microsoft\FilterDS] [HKLM\SOFTWARE\Microsoft\FingerKB] [HKLM\SOFTWARE\Microsoft\FTH] [HKLM\SOFTWARE\Microsoft\Function Discovery] [HKLM\SOFTWARE\Microsoft\Fusion] [HKLM\SOFTWARE\Microsoft\FuzzyDS] [HKLM\SOFTWARE\Microsoft\GameOverlay] [HKLM\SOFTWARE\Microsoft\HTMLHelp] [HKLM\SOFTWARE\Microsoft\Hub] [HKLM\SOFTWARE\Microsoft\IdentityCRL] [HKLM\SOFTWARE\Microsoft\IdentityStore] [HKLM\SOFTWARE\Microsoft\IHDS] [HKLM\SOFTWARE\Microsoft\IMAPI] [HKLM\SOFTWARE\Microsoft\IME] [HKLM\SOFTWARE\Microsoft\IMEJP] [HKLM\SOFTWARE\Microsoft\IMEKR] [HKLM\SOFTWARE\Microsoft\IMETC] [HKLM\SOFTWARE\Microsoft\InProcLogger] [HKLM\SOFTWARE\Microsoft\Input] [HKLM\SOFTWARE\Microsoft\InputMethod] [HKLM\SOFTWARE\Microsoft\InputPersonalization] [HKLM\SOFTWARE\Microsoft\Internet Account Manager] [HKLM\SOFTWARE\Microsoft\Internet Domains] [HKLM\SOFTWARE\Microsoft\Internet Explorer] [HKLM\SOFTWARE\Microsoft\IsoBurn] [HKLM\SOFTWARE\Microsoft\KGL] [HKLM\SOFTWARE\Microsoft\LanguageOverlay] [HKLM\SOFTWARE\Microsoft\LexiconUpdate] [HKLM\SOFTWARE\Microsoft\Location] [HKLM\SOFTWARE\Microsoft\LPKSetup] [HKLM\SOFTWARE\Microsoft\Managed Desktop] [HKLM\SOFTWARE\Microsoft\MATS] [HKLM\SOFTWARE\Microsoft\MdmCommon] [HKLM\SOFTWARE\Microsoft\MdmDiagnostics] [HKLM\SOFTWARE\Microsoft\MediaEngine] [HKLM\SOFTWARE\Microsoft\MediaPlayer] [HKLM\SOFTWARE\Microsoft\MemoryDiagnostic] [HKLM\SOFTWARE\Microsoft\Messaging] [HKLM\SOFTWARE\Microsoft\MessengerService] [HKLM\SOFTWARE\Microsoft\Microsoft Camera Codec Pack] [HKLM\SOFTWARE\Microsoft\MiracastReceiver] [HKLM\SOFTWARE\Microsoft\MMC] [HKLM\SOFTWARE\Microsoft\Mobile] [HKLM\SOFTWARE\Microsoft\MpSigStub] [HKLM\SOFTWARE\Microsoft\MSBuild] [HKLM\SOFTWARE\Microsoft\MSDE] [HKLM\SOFTWARE\Microsoft\MSDRM] [HKLM\SOFTWARE\Microsoft\MSDTC] [HKLM\SOFTWARE\Microsoft\MSF] [HKLM\SOFTWARE\Microsoft\MSIME] [HKLM\SOFTWARE\Microsoft\MSLicensing] [HKLM\SOFTWARE\Microsoft\MSMQ] [HKLM\SOFTWARE\Microsoft\MSN Apps] [HKLM\SOFTWARE\Microsoft\MTF] [HKLM\SOFTWARE\Microsoft\MTFFuzzyFactors] [HKLM\SOFTWARE\Microsoft\MTFInputType] [HKLM\SOFTWARE\Microsoft\MTFKeyboardMappings] [HKLM\SOFTWARE\Microsoft\Multimedia] [HKLM\SOFTWARE\Microsoft\Multivariant] [HKLM\SOFTWARE\Microsoft\NET Framework Setup] [HKLM\SOFTWARE\Microsoft\NetSh] [HKLM\SOFTWARE\Microsoft\Network] [HKLM\SOFTWARE\Microsoft\NetworkAccessProtection] [HKLM\SOFTWARE\Microsoft\Non-Driver Signing] [HKLM\SOFTWARE\Microsoft\Notepad] [HKLM\SOFTWARE\Microsoft\ODBC] [HKLM\SOFTWARE\Microsoft\OEM] [HKLM\SOFTWARE\Microsoft\Office] [HKLM\SOFTWARE\Microsoft\OfficeCSP] [HKLM\SOFTWARE\Microsoft\Ole] [HKLM\SOFTWARE\Microsoft\OnlineProviders] [HKLM\SOFTWARE\Microsoft\Outlook Express] [HKLM\SOFTWARE\Microsoft\Palm] [HKLM\SOFTWARE\Microsoft\Personalization] [HKLM\SOFTWARE\Microsoft\Phone] [HKLM\SOFTWARE\Microsoft\Photos] [HKLM\SOFTWARE\Microsoft\PIM] [HKLM\SOFTWARE\Microsoft\PLA] [HKLM\SOFTWARE\Microsoft\PlayReady] [HKLM\SOFTWARE\Microsoft\PlayToReceiver] [HKLM\SOFTWARE\Microsoft\PointOfService] [HKLM\SOFTWARE\Microsoft\Policies] [HKLM\SOFTWARE\Microsoft\PolicyManager] [HKLM\SOFTWARE\Microsoft\Poom] [HKLM\SOFTWARE\Microsoft\PowerShell] [HKLM\SOFTWARE\Microsoft\Print] [HKLM\SOFTWARE\Microsoft\Provisioning] [HKLM\SOFTWARE\Microsoft\PushRouter] [HKLM\SOFTWARE\Microsoft\RADAR] [HKLM\SOFTWARE\Microsoft\Ras] [HKLM\SOFTWARE\Microsoft\RcsPresence] [HKLM\SOFTWARE\Microsoft\Reliability Analysis] [HKLM\SOFTWARE\Microsoft\Remediation] [HKLM\SOFTWARE\Microsoft\RemovalTools] [HKLM\SOFTWARE\Microsoft\rempl] [HKLM\SOFTWARE\Microsoft\RendezvousApps] [HKLM\SOFTWARE\Microsoft\Router] [HKLM\SOFTWARE\Microsoft\Rpc] [HKLM\SOFTWARE\Microsoft\SchedulingAgent] [HKLM\SOFTWARE\Microsoft\SDDS] [HKLM\SOFTWARE\Microsoft\Security Center] [HKLM\SOFTWARE\Microsoft\SecurityManager] [HKLM\SOFTWARE\Microsoft\SEMgr] [HKLM\SOFTWARE\Microsoft\Sensors] [HKLM\SOFTWARE\Microsoft\Settings] [HKLM\SOFTWARE\Microsoft\Shared] [HKLM\SOFTWARE\Microsoft\Shared Tools] [HKLM\SOFTWARE\Microsoft\Shared Tools Location] [HKLM\SOFTWARE\Microsoft\Shell] [HKLM\SOFTWARE\Microsoft\SideShow] [HKLM\SOFTWARE\Microsoft\sih] [HKLM\SOFTWARE\Microsoft\Silverlight] [HKLM\SOFTWARE\Microsoft\Siuf] [HKLM\SOFTWARE\Microsoft\SMB1Uninstall] [HKLM\SOFTWARE\Microsoft\Software] [HKLM\SOFTWARE\Microsoft\Speech] [HKLM\SOFTWARE\Microsoft\Speech_OneCore] [HKLM\SOFTWARE\Microsoft\SQMClient] [HKLM\SOFTWARE\Microsoft\StrongName] [HKLM\SOFTWARE\Microsoft\Sync Framework] [HKLM\SOFTWARE\Microsoft\Sysprep] [HKLM\SOFTWARE\Microsoft\SystemCertificates] [HKLM\SOFTWARE\Microsoft\SystemSettings] [HKLM\SOFTWARE\Microsoft\TableTextService] [HKLM\SOFTWARE\Microsoft\TabletTip] [HKLM\SOFTWARE\Microsoft\TaskFlowDataEngine] [HKLM\SOFTWARE\Microsoft\Tcpip] [HKLM\SOFTWARE\Microsoft\TelemetryClient] [HKLM\SOFTWARE\Microsoft\Terminal Server Client] [HKLM\SOFTWARE\Microsoft\TermServLicensing] [HKLM\SOFTWARE\Microsoft\TouchPrediction] [HKLM\SOFTWARE\Microsoft\TPG] [HKLM\SOFTWARE\Microsoft\Tpm] [HKLM\SOFTWARE\Microsoft\Tracing] [HKLM\SOFTWARE\Microsoft\Transaction Server] [HKLM\SOFTWARE\Microsoft\TV System Services] [HKLM\SOFTWARE\Microsoft\uDRM] [HKLM\SOFTWARE\Microsoft\Uev] [HKLM\SOFTWARE\Microsoft\Unified Store] [HKLM\SOFTWARE\Microsoft\Unistore] [HKLM\SOFTWARE\Microsoft\UNP] [HKLM\SOFTWARE\Microsoft\UPnP Control Point] [HKLM\SOFTWARE\Microsoft\UPnP Device Host] [HKLM\SOFTWARE\Microsoft\UserData] [HKLM\SOFTWARE\Microsoft\UserManager] [HKLM\SOFTWARE\Microsoft\Virtual Machine] [HKLM\SOFTWARE\Microsoft\VisualStudio] [HKLM\SOFTWARE\Microsoft\WAB] [HKLM\SOFTWARE\Microsoft\Wallet] [HKLM\SOFTWARE\Microsoft\Wbem] [HKLM\SOFTWARE\Microsoft\WcmSvc] [HKLM\SOFTWARE\Microsoft\WIMMount] [HKLM\SOFTWARE\Microsoft\Windows] [HKLM\SOFTWARE\Microsoft\Windows Defender] [HKLM\SOFTWARE\Microsoft\Windows Defender Security Center] [HKLM\SOFTWARE\Microsoft\Windows Desktop Search] [HKLM\SOFTWARE\Microsoft\Windows Mail] [HKLM\SOFTWARE\Microsoft\Windows Media Device Manager] [HKLM\SOFTWARE\Microsoft\Windows Media Foundation] [HKLM\SOFTWARE\Microsoft\Windows Media Player NSS] [HKLM\SOFTWARE\Microsoft\Windows Messaging Subsystem] [HKLM\SOFTWARE\Microsoft\Windows NT] [HKLM\SOFTWARE\Microsoft\Windows Performance Toolkit] [HKLM\SOFTWARE\Microsoft\Windows Phone] [HKLM\SOFTWARE\Microsoft\Windows Photo Viewer] [HKLM\SOFTWARE\Microsoft\Windows Portable Devices] [HKLM\SOFTWARE\Microsoft\Windows Script Host] [HKLM\SOFTWARE\Microsoft\Windows Search] [HKLM\SOFTWARE\Microsoft\Windows Security Health] [HKLM\SOFTWARE\Microsoft\Windows10Upgrader] [HKLM\SOFTWARE\Microsoft\WindowsRuntime] [HKLM\SOFTWARE\Microsoft\WindowsSelfHost] [HKLM\SOFTWARE\Microsoft\WindowsStore] [HKLM\SOFTWARE\Microsoft\WindowsUpdate] [HKLM\SOFTWARE\Microsoft\Wisp] [HKLM\SOFTWARE\Microsoft\WlanSvc] [HKLM\SOFTWARE\Microsoft\Wlpasvc] [HKLM\SOFTWARE\Microsoft\Wow64] [HKLM\SOFTWARE\Microsoft\WSDAPI] [HKLM\SOFTWARE\Microsoft\WwanSvc] [HKLM\SOFTWARE\Microsoft\XAML] [HKLM\SOFTWARE\Microsoft\XboxGameSaveStorage] [HKLM\SOFTWARE\Microsoft\XboxLive] [HKLM\Software\Microsoft\Windows\Autopilot] [HKLM\Software\Microsoft\Windows\ClickNote] [HKLM\Software\Microsoft\Windows\CurrentVersion] [HKLM\Software\Microsoft\Windows\Dwm] [HKLM\Software\Microsoft\Windows\DynamicManagement] [HKLM\Software\Microsoft\Windows\EnterpriseResourceManager] [HKLM\Software\Microsoft\Windows\Heat] [HKLM\Software\Microsoft\Windows\HTML Help] [HKLM\Software\Microsoft\Windows\ITStorage] [HKLM\Software\Microsoft\Windows\Notepad] [HKLM\Software\Microsoft\Windows\PrivacySettingsBeforeCreatorsUpdate] [HKLM\Software\Microsoft\Windows\ScheduledDiagnostics] [HKLM\Software\Microsoft\Windows\ScriptedDiagnosticsProvider] [HKLM\Software\Microsoft\Windows\Shell] [HKLM\Software\Microsoft\Windows\Tablet PC] [HKLM\Software\Microsoft\Windows\TabletPC] [HKLM\Software\Microsoft\Windows\UpdateApi] [HKLM\Software\Microsoft\Windows\Windows Error Reporting] [HKLM\Software\Microsoft\Windows\Windows Search] [HKLM\Software\Microsoft\Windows NT\CurrentVersion] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\AarSvc] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\appmodel] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\autotimesvc] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\BcastDVRUserService] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\btagservice] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\BthAppGroup] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\Camera] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\ClipboardSvcGroup] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\defragsvc] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\DevicesFlow] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\diagnostics] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\GraphicsPerfSvcGroup] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\ICService] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalService] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceAndNoImpersonation] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceHttp] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceNetworkRestricted] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceNetworkRestrictedDhcpLmHosts] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceNoNetwork] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceNoNetworkFirewall] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalSystemNetworkRestricted] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\netsvcs] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\NetworkService] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\NetworkServiceDnsNla] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\NetworkServiceRemoteDesktopHyperVAgent] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\NetworkServiceRemoteDesktopPublishing] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\print] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\PrintWorkflow] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\rdxgroup] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\RmSvc] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\SDRSVC] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\swprv] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\termsvcs] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\UnistackSvcGroup] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\utcsvc] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\WepHostSvcGroup] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\wercplsupport] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\wsappx] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\wusvcs] [HKLM\Software\WOW6432Node\2BrightSparks] [HKLM\Software\WOW6432Node\ABBYY] [HKLM\Software\WOW6432Node\Adobe] [HKLM\Software\WOW6432Node\AdwCleaner] [HKLM\Software\WOW6432Node\AGEIA Technologies] [HKLM\Software\WOW6432Node\Ahead] [HKLM\Software\WOW6432Node\AIDeX] [HKLM\Software\WOW6432Node\AppDataLow] [HKLM\Software\WOW6432Node\Apple Inc.] [HKLM\Software\WOW6432Node\ASUS] [HKLM\Software\WOW6432Node\AVAST Software] [HKLM\Software\WOW6432Node\AVerMedia TECHNOLOGIES, Inc.] [HKLM\Software\WOW6432Node\AVerUpdate] [HKLM\Software\WOW6432Node\BCL Technologies] [HKLM\Software\WOW6432Node\BioWare] [HKLM\Software\WOW6432Node\Caphyon] [HKLM\Software\WOW6432Node\Common Desktop Agent] [HKLM\Software\WOW6432Node\Creative Tech] [HKLM\Software\WOW6432Node\DigitalWave] [HKLM\Software\WOW6432Node\DVDVideoSoft] [HKLM\Software\WOW6432Node\Foxit Software] [HKLM\Software\WOW6432Node\Freemake] [HKLM\Software\WOW6432Node\GlarySoft] [HKLM\Software\WOW6432Node\Google] [HKLM\Software\WOW6432Node\HaaliMkx] [HKLM\Software\WOW6432Node\HD Sentinel] [HKLM\Software\WOW6432Node\Hercules] [HKLM\Software\WOW6432Node\Icecream] [HKLM\Software\WOW6432Node\ImgBurn] [HKLM\Software\WOW6432Node\Intel] [HKLM\Software\WOW6432Node\IObit] [HKLM\Software\WOW6432Node\JavaSoft] [HKLM\Software\WOW6432Node\JreMetrics] [HKLM\Software\WOW6432Node\Khronos] [HKLM\Software\WOW6432Node\Lexmark] [HKLM\Software\WOW6432Node\LexmarkLaser] [HKLM\Software\WOW6432Node\Macromedia] [HKLM\Software\WOW6432Node\Magix] [HKLM\Software\WOW6432Node\Malwarebytes' Anti-Malware] [HKLM\Software\WOW6432Node\McAfee] [HKLM\Software\WOW6432Node\McAfee NGI] [HKLM\Software\WOW6432Node\McAfee.com] [HKLM\Software\WOW6432Node\Microsoft] [HKLM\Software\WOW6432Node\MotionStudios] [HKLM\Software\WOW6432Node\Mozilla] [HKLM\Software\WOW6432Node\mozilla.org] [HKLM\Software\WOW6432Node\MozillaPlugins] [HKLM\Software\WOW6432Node\MyHeritage.com] [HKLM\Software\WOW6432Node\NetRatingsNetSight] [HKLM\Software\WOW6432Node\NSCPID] [HKLM\Software\WOW6432Node\Nuance] [HKLM\Software\WOW6432Node\NVIDIA Corporation] [HKLM\Software\WOW6432Node\OBS Studio] [HKLM\Software\WOW6432Node\ODBC] [HKLM\Software\WOW6432Node\Oracle] [HKLM\Software\WOW6432Node\PoINT] [HKLM\Software\WOW6432Node\proDAD] [HKLM\Software\WOW6432Node\Realtek] [HKLM\Software\WOW6432Node\Riot Games] [HKLM\Software\WOW6432Node\Samsung] [HKLM\Software\WOW6432Node\simplitec] [HKLM\Software\WOW6432Node\Skype] [HKLM\Software\WOW6432Node\SSDIAG] [HKLM\Software\WOW6432Node\SSScan] [HKLM\Software\WOW6432Node\Symantec] [HKLM\Software\WOW6432Node\VideoProc] [HKLM\Software\WOW6432Node\Volatile] [HKLM\Software\WOW6432Node\WinPcap] [HKLM\Software\WOW6432Node\WOW6432Node] [HKLM\Software\WOW6432Node\Xara] [HKLM\Software\WOW6432Node\Xiph.Org] [HKLM\Software\WOW6432Node\Yahoo] [HKLM\Software\WOW6432Node\Clients] [HKLM\Software\WOW6432Node\Policies] [HKLM\Software\WOW6432Node\RegisteredApplications] [HKLM\Software\WOW6432Node\Microsoft\.NETFramework] [HKLM\Software\WOW6432Node\Microsoft\Active Setup] [HKLM\Software\WOW6432Node\Microsoft\ADs] [HKLM\Software\WOW6432Node\Microsoft\Advanced INF Setup] [HKLM\Software\WOW6432Node\Microsoft\AMSI] [HKLM\Software\WOW6432Node\Microsoft\AOMEI] [HKLM\Software\WOW6432Node\Microsoft\AppServiceProtocols] [HKLM\Software\WOW6432Node\Microsoft\ASP.NET] [HKLM\Software\WOW6432Node\Microsoft\ASP.NET MVC 4] [HKLM\Software\WOW6432Node\Microsoft\Assistance] [HKLM\Software\WOW6432Node\Microsoft\AudioCompressionManager] [HKLM\Software\WOW6432Node\Microsoft\AuthHost] [HKLM\Software\WOW6432Node\Microsoft\BidInterface] [HKLM\Software\WOW6432Node\Microsoft\BitLockerCsp] [HKLM\Software\WOW6432Node\Microsoft\CameraControl] [HKLM\Software\WOW6432Node\Microsoft\ClipboardServer] [HKLM\Software\WOW6432Node\Microsoft\Code Store Database] [HKLM\Software\WOW6432Node\Microsoft\Command Processor] [HKLM\Software\WOW6432Node\Microsoft\Cryptography] [HKLM\Software\WOW6432Node\Microsoft\CTF] [HKLM\Software\WOW6432Node\Microsoft\DataAccess] [HKLM\Software\WOW6432Node\Microsoft\DevDiv] [HKLM\Software\WOW6432Node\Microsoft\Device Association Framework] [HKLM\Software\WOW6432Node\Microsoft\Direct3D] [HKLM\Software\WOW6432Node\Microsoft\DirectDraw] [HKLM\Software\WOW6432Node\Microsoft\DirectInput] [HKLM\Software\WOW6432Node\Microsoft\DirectMusic] [HKLM\Software\WOW6432Node\Microsoft\DirectPlay] [HKLM\Software\WOW6432Node\Microsoft\DirectPlay8] [HKLM\Software\WOW6432Node\Microsoft\DirectPlayNATHelp] [HKLM\Software\WOW6432Node\Microsoft\DirectShow] [HKLM\Software\WOW6432Node\Microsoft\DirectX] [HKLM\Software\WOW6432Node\Microsoft\DownloadManager] [HKLM\Software\WOW6432Node\Microsoft\DRM] [HKLM\Software\WOW6432Node\Microsoft\DVDNavigator] [HKLM\Software\WOW6432Node\Microsoft\DVR] [HKLM\Software\WOW6432Node\Microsoft\EAPSIMMethods] [HKLM\Software\WOW6432Node\Microsoft\ENROLLMENTS] [HKLM\Software\WOW6432Node\Microsoft\EnterpriseResourceManager] [HKLM\Software\WOW6432Node\Microsoft\Exchange] [HKLM\Software\WOW6432Node\Microsoft\F12] [HKLM\Software\WOW6432Node\Microsoft\Fax] [HKLM\Software\WOW6432Node\Microsoft\Feeds] [HKLM\Software\WOW6432Node\Microsoft\FilePicker] [HKLM\Software\WOW6432Node\Microsoft\Function Discovery] [HKLM\Software\WOW6432Node\Microsoft\Fusion] [HKLM\Software\WOW6432Node\Microsoft\GameOverlay] [HKLM\Software\WOW6432Node\Microsoft\HTMLHelp] [HKLM\Software\WOW6432Node\Microsoft\IdentityCRL] [HKLM\Software\WOW6432Node\Microsoft\IdentityStore] [HKLM\Software\WOW6432Node\Microsoft\IMAPI] [HKLM\Software\WOW6432Node\Microsoft\IME] [HKLM\Software\WOW6432Node\Microsoft\IMEJP] [HKLM\Software\WOW6432Node\Microsoft\IMEKR] [HKLM\Software\WOW6432Node\Microsoft\IMETC] [HKLM\Software\WOW6432Node\Microsoft\Immersive Browser] [HKLM\Software\WOW6432Node\Microsoft\InputMethod] [HKLM\Software\WOW6432Node\Microsoft\Internet Account Manager] [HKLM\Software\WOW6432Node\Microsoft\Internet Domains] [HKLM\Software\WOW6432Node\Microsoft\Internet Explorer] [HKLM\Software\WOW6432Node\Microsoft\IsoBurn] [HKLM\Software\WOW6432Node\Microsoft\Jet] [HKLM\Software\WOW6432Node\Microsoft\Location] [HKLM\Software\WOW6432Node\Microsoft\Machine Debug Manager] [HKLM\Software\WOW6432Node\Microsoft\MediaEngine] [HKLM\Software\WOW6432Node\Microsoft\MediaPlayer] [HKLM\Software\WOW6432Node\Microsoft\MessengerService] [HKLM\Software\WOW6432Node\Microsoft\Microsoft Camera Codec Pack] [HKLM\Software\WOW6432Node\Microsoft\Microsoft Office Outlook Connector] [HKLM\Software\WOW6432Node\Microsoft\Microsoft Reference] [HKLM\Software\WOW6432Node\Microsoft\MiracastReceiver] [HKLM\Software\WOW6432Node\Microsoft\MMC] [HKLM\Software\WOW6432Node\Microsoft\MSBuild] [HKLM\Software\WOW6432Node\Microsoft\MSDE] [HKLM\Software\WOW6432Node\Microsoft\MSDRM] [HKLM\Software\WOW6432Node\Microsoft\MSDTC] [HKLM\Software\WOW6432Node\Microsoft\MSF] [HKLM\Software\WOW6432Node\Microsoft\MSLicensing] [HKLM\Software\WOW6432Node\Microsoft\MSN Apps] [HKLM\Software\WOW6432Node\Microsoft\MSOSOAP] [HKLM\Software\WOW6432Node\Microsoft\MSSearch36] [HKLM\Software\WOW6432Node\Microsoft\MTF] [HKLM\Software\WOW6432Node\Microsoft\Multimedia] [HKLM\Software\WOW6432Node\Microsoft\NET Framework Setup] [HKLM\Software\WOW6432Node\Microsoft\NetSh] [HKLM\Software\WOW6432Node\Microsoft\Network] [HKLM\Software\WOW6432Node\Microsoft\NetworkAccessProtection] [HKLM\Software\WOW6432Node\Microsoft\Notepad] [HKLM\Software\WOW6432Node\Microsoft\ODBC] [HKLM\Software\WOW6432Node\Microsoft\OEM] [HKLM\Software\WOW6432Node\Microsoft\Office] [HKLM\Software\WOW6432Node\Microsoft\Office Server] [HKLM\Software\WOW6432Node\Microsoft\OnlineProviders] [HKLM\Software\WOW6432Node\Microsoft\Outlook Express] [HKLM\Software\WOW6432Node\Microsoft\Palm] [HKLM\Software\WOW6432Node\Microsoft\Photos] [HKLM\Software\WOW6432Node\Microsoft\PLA] [HKLM\Software\WOW6432Node\Microsoft\Policies] [HKLM\Software\WOW6432Node\Microsoft\PowerPoint Viewer] [HKLM\Software\WOW6432Node\Microsoft\PowerShell] [HKLM\Software\WOW6432Node\Microsoft\Print] [HKLM\Software\WOW6432Node\Microsoft\Provisioning] [HKLM\Software\WOW6432Node\Microsoft\RADAR] [HKLM\Software\WOW6432Node\Microsoft\RendezvousApps] [HKLM\Software\WOW6432Node\Microsoft\RFC1156Agent] [HKLM\Software\WOW6432Node\Microsoft\SchedulingAgent] [HKLM\Software\WOW6432Node\Microsoft\Security Center] [HKLM\Software\WOW6432Node\Microsoft\Sensors] [HKLM\Software\WOW6432Node\Microsoft\Shared] [HKLM\Software\WOW6432Node\Microsoft\Shared Tools] [HKLM\Software\WOW6432Node\Microsoft\Shared Tools Location] [HKLM\Software\WOW6432Node\Microsoft\SideShow] [HKLM\Software\WOW6432Node\Microsoft\Silverlight] [HKLM\Software\WOW6432Node\Microsoft\Software] [HKLM\Software\WOW6432Node\Microsoft\SPEECH] [HKLM\Software\WOW6432Node\Microsoft\Speech_OneCore] [HKLM\Software\WOW6432Node\Microsoft\SQMClient] [HKLM\Software\WOW6432Node\Microsoft\Sync Framework] [HKLM\Software\WOW6432Node\Microsoft\SystemSettings] [HKLM\Software\WOW6432Node\Microsoft\TableTextService] [HKLM\Software\WOW6432Node\Microsoft\TabletTip] [HKLM\Software\WOW6432Node\Microsoft\Tcpip] [HKLM\Software\WOW6432Node\Microsoft\Terminal Server Client] [HKLM\Software\WOW6432Node\Microsoft\TouchPrediction] [HKLM\Software\WOW6432Node\Microsoft\TPG] [HKLM\Software\WOW6432Node\Microsoft\Tpm] [HKLM\Software\WOW6432Node\Microsoft\Tracing] [HKLM\Software\WOW6432Node\Microsoft\TV System Services] [HKLM\Software\WOW6432Node\Microsoft\uDRM] [HKLM\Software\WOW6432Node\Microsoft\Updates] [HKLM\Software\WOW6432Node\Microsoft\UPnP Control Point] [HKLM\Software\WOW6432Node\Microsoft\UPnP Device Host] [HKLM\Software\WOW6432Node\Microsoft\VBA] [HKLM\Software\WOW6432Node\Microsoft\VisualStudio] [HKLM\Software\WOW6432Node\Microsoft\VSTAHost] [HKLM\Software\WOW6432Node\Microsoft\WAB] [HKLM\Software\WOW6432Node\Microsoft\WBEM] [HKLM\Software\WOW6432Node\Microsoft\WIMMount] [HKLM\Software\WOW6432Node\Microsoft\Windows] [HKLM\Software\WOW6432Node\Microsoft\Windows Desktop Search] [HKLM\Software\WOW6432Node\Microsoft\Windows Kits] [HKLM\Software\WOW6432Node\Microsoft\Windows Live] [HKLM\Software\WOW6432Node\Microsoft\Windows Live Mail] [HKLM\Software\WOW6432Node\Microsoft\Windows Mail] [HKLM\Software\WOW6432Node\Microsoft\Windows Media Device Manager] [HKLM\Software\WOW6432Node\Microsoft\Windows Media Foundation] [HKLM\Software\WOW6432Node\Microsoft\Windows Media Player NSS] [HKLM\Software\WOW6432Node\Microsoft\Windows Messaging Subsystem] [HKLM\Software\WOW6432Node\Microsoft\Windows NT] [HKLM\Software\WOW6432Node\Microsoft\Windows Phone] [HKLM\Software\WOW6432Node\Microsoft\Windows Photo Viewer] [HKLM\Software\WOW6432Node\Microsoft\Windows Portable Devices] [HKLM\Software\WOW6432Node\Microsoft\Windows Script Host] [HKLM\Software\WOW6432Node\Microsoft\WindowsRuntime] [HKLM\Software\WOW6432Node\Microsoft\WindowsUpdate] [HKLM\Software\WOW6432Node\Microsoft\Wisp] [HKLM\Software\WOW6432Node\Microsoft\WlanSvc] [HKLM\Software\WOW6432Node\Microsoft\WSDAPI] [HKLM\Software\WOW6432Node\Microsoft\Cellular] [HKLM\Software\WOW6432Node\Microsoft\COM3] [HKLM\Software\WOW6432Node\Microsoft\DeviceReg] [HKLM\Software\WOW6432Node\Microsoft\DFS] [HKLM\Software\WOW6432Node\Microsoft\Driver Signing] [HKLM\Software\WOW6432Node\Microsoft\EnterpriseCertificates] [HKLM\Software\WOW6432Node\Microsoft\EventSystem] [HKLM\Software\WOW6432Node\Microsoft\FingerKB] [HKLM\Software\WOW6432Node\Microsoft\FuzzyDS] [HKLM\Software\WOW6432Node\Microsoft\Input] [HKLM\Software\WOW6432Node\Microsoft\LanguageOverlay] [HKLM\Software\WOW6432Node\Microsoft\Messaging] [HKLM\Software\WOW6432Node\Microsoft\MSMQ] [HKLM\Software\WOW6432Node\Microsoft\MTFFuzzyFactors] [HKLM\Software\WOW6432Node\Microsoft\MTFInputType] [HKLM\Software\WOW6432Node\Microsoft\MTFKeyboardMappings] [HKLM\Software\WOW6432Node\Microsoft\Non-Driver Signing] [HKLM\Software\WOW6432Node\Microsoft\Ole] [HKLM\Software\WOW6432Node\Microsoft\Phone] [HKLM\Software\WOW6432Node\Microsoft\Pim] [HKLM\Software\WOW6432Node\Microsoft\Poom] [HKLM\Software\WOW6432Node\Microsoft\Ras] [HKLM\Software\WOW6432Node\Microsoft\Rpc] [HKLM\Software\WOW6432Node\Microsoft\SecurityManager] [HKLM\Software\WOW6432Node\Microsoft\Semgr] [HKLM\Software\WOW6432Node\Microsoft\Shell] [HKLM\Software\WOW6432Node\Microsoft\SystemCertificates] [HKLM\Software\WOW6432Node\Microsoft\TermServLicensing] [HKLM\Software\WOW6432Node\Microsoft\Transaction Server] [HKLM\Software\WOW6432Node\Microsoft\Unified Store] [HKLM\Software\WOW6432Node\Microsoft\UserData] [HKLM\Software\WOW6432Node\Microsoft\Windows Search] [HKLM\Software\WOW6432Node\Microsoft\XAML] [HKLM\Software\WOW6432Node\Microsoft\Windows\ClickNote] [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion] [HKLM\Software\WOW6432Node\Microsoft\Windows\Dwm] [HKLM\Software\WOW6432Node\Microsoft\Windows\EnterpriseResourceManager] [HKLM\Software\WOW6432Node\Microsoft\Windows\Heat] [HKLM\Software\WOW6432Node\Microsoft\Windows\Help] [HKLM\Software\WOW6432Node\Microsoft\Windows\HTML Help] [HKLM\Software\WOW6432Node\Microsoft\Windows\ITStorage] [HKLM\Software\WOW6432Node\Microsoft\Windows\ScriptedDiagnosticsProvider] [HKLM\Software\WOW6432Node\Microsoft\Windows\Tablet PC] [HKLM\Software\WOW6432Node\Microsoft\Windows\UpdateApi] [HKLM\Software\WOW6432Node\Microsoft\Windows\Windows Error Reporting] [HKLM\Software\WOW6432Node\Microsoft\Windows\Windows Search] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\appmodel] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalService] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceAndNoImpersonation] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceHttp] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceNetworkRestricted] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceNetworkRestrictedDhcpLmHosts] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceNoNetwork] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceNoNetworkFirewall] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalSystemNetworkRestricted] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\netsvcs] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\NetworkService] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\NetworkServiceDnsNla] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\NetworkServiceRemoteDesktopHyperVAgent] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\NetworkServiceRemoteDesktopPublishing] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\PrintWorkflow] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\termsvcs] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\wusvcs] ---------- | Drives D: [24/09/2019 17:07:23] - |SH| - (.-.) - [0] - (0.0.0.0) - D:\autorun.inf E: G: [05/11/2018 10:46:14] - |A| - (.-.) - [1553] - (0.0.0.0) - G:\ThunderbirdPortable.exe - Raccourci.lnk ---------- | C: [22/08/2013 16:36:31] - |SHD| - [21797] - C:\$Recycle.Bin [10/12/2018 15:58:22] - |D| - [0] - C:\$Windows.~WS [01/01/1981 00:00:00] - |D| - [0] - C:\5543210.051 [15/01/2016 19:15:32] - |D| - [127905243] - C:\AdwCleaner [MD5.31FBDEA9E40763EAE5903C20F79CAF6D] - [02/05/2017 21:13:53] - |H| - (.-.) - [1024] - (0.0.0.0) - C:\AMTAG.BIN [MD5.865A2FAD4E65D9631101F9BD7F1A900E] - [22/01/2018 22:33:05] - |A| - (.-.) - [2413] - (0.0.0.0) - C:\app_updater.log [31/01/2014 10:27:05] - |D| - [2701896] - C:\Arrêter [MD5.A6799D0F42122C0D1E28655C10DB2707] - [25/06/2017 09:39:47] - |A| - (.-.) - [30] - (0.0.0.0) - C:\AVScanner.ini [MD5.04C91D3AB4CDB766C34A8DC5372BA09E] - [22/08/2013 16:44:03] - |RASH| - (.-.) - [427680] - (0.0.0.0) - C:\bootmgr [MD5.93B885ADFE0DA089CDF634904FD59F71] - [22/08/2013 16:44:04] - |ASH| - (.-.) - [1] - (0.0.0.0) - C:\BOOTNXT [MD5.485C57E0E04FE49656C19A4D29DF1E77] - [03/06/2018 06:55:41] - |SH| - (.-.) - [80] - (0.0.0.0) - C:\bootTel.dat [10/01/2018 12:32:38] - |SHD| - [535624] - C:\Config.Msi [22/08/2013 15:45:52] - |SHD| - [0] - C:\Documents and Settings [27/02/2017 09:52:06] - |D| - [83928034] - C:\Données EuroSoft Software Development [MD5.D41D8CD98F00B204E9800998ECF8427E] - [14/07/2017 10:58:40] - |A| - (.-.) - [0] - (0.0.0.0) - C:\extensions.sqlite [29/07/2019 17:23:34] - |D| - [87577] - C:\KVRT_Data [07/01/2019 15:51:49] - |D| - [26226] - C:\MATS [27/04/2014 19:22:54] - |D| - [947243566] - C:\MotionStudios [03/02/2014 19:09:35] - |RHD| - [529670008] - C:\MSOCache [18/01/2016 09:40:29] - |D| - [2048] - C:\Ne pas jeter [MD5.D41D8CD98F00B204E9800998ECF8427E] - [07/08/2019 15:44:31] - |ASH| - (.-.) - [8589934592] - (0.0.0.0) - C:\pagefile.sys [19/03/2019 05:52:43] - |D| - [0] - C:\PerfLogs [19/03/2019 05:52:43] - |RD| - [10074095993] - C:\Program Files [19/03/2019 05:52:44] - |RD| - [12588263658] - C:\Program Files (x86) [19/03/2019 05:52:44] - |HD| - [21450368032] - C:\ProgramData [17/12/2019 14:43:08] - |D| - [68685] - C:\QuickDiag [MD5.B937C873E9D2396FE55D6ACBE3BF9169] - [17/12/2019 14:43:35] - |A| - (.-.) - [464939] - (0.0.0.0) - C:\QuickDiag.txt [MD5.D41D8CD98F00B204E9800998ECF8427E] - [07/08/2019 15:44:31] - |ASH| - (.-.) - [16777216] - (0.0.0.0) - C:\swapfile.sys [MD5.1B3C0B67EF43473B4BF6E4F44C9DF597] - [26/03/2019 15:53:57] - |AH| - (.-.) - [1024] - (0.0.0.0) - C:\SYSTAG.BIN [30/01/2014 17:15:34] - |SHD| - [0] - C:\System Volume Information [19/03/2019 05:37:22] - |RD| - [32107866309] - C:\Users [19/03/2019 05:37:22] - |D| - [28831769704] - C:\Windows [07/08/2019 16:44:09] - |D| - [0] - C:\Windows.old [10/12/2018 15:56:53] - |D| - [20549810] - C:\Windows10Upgrade ---------- | C:\WINDOWS [19/03/2019 05:52:44] - |D| - [802] - C:\WINDOWS\addins [MD5.16D640FFBEFE88D81AC8A90A60C28088] - [31/10/2019 22:37:18] - |A| - (.-.) - [2165096] - (0.0.0.0) - C:\WINDOWS\ampa.exe [19/03/2019 05:52:44] - |D| - [12342703] - C:\WINDOWS\appcompat [19/03/2019 05:52:44] - |D| - [8449172] - C:\WINDOWS\apppatch [19/03/2019 05:52:44] - |D| - [0] - C:\WINDOWS\AppReadiness [MD5.D41D8CD98F00B204E9800998ECF8427E] - [30/01/2014 17:33:05] - |A| - (.-.) - [0] - (0.0.0.0) - C:\WINDOWS\Ascd_err.ini [MD5.4B1FC2789C658EB9BEA26EEB370AC97A] - [30/01/2014 17:33:05] - |A| - (.-.) - [43897] - (0.0.0.0) - C:\WINDOWS\Ascd_log.ini [MD5.A858169130DDF1F7C4F55803AD3AFA0D] - [30/01/2014 17:31:09] - |A| - (.-.) - [33843] - (0.0.0.0) - C:\WINDOWS\Ascd_tmp.ini [19/03/2019 05:52:43] - |RD| - [1119872100] - C:\WINDOWS\assembly [30/01/2014 17:34:10] - |D| - [14398968] - C:\WINDOWS\AsusInstAll [MD5.12EBDA58437CD1EA7066FCB6455241D2] - [26/08/2016 16:24:17] - |A| - (.Copyright (c) 2014 AVAST Software - avast! Screen Saver stub.) - [53208] - (12.3.3154.0) - C:\WINDOWS\avastSS.scr [19/03/2019 05:52:44] - |D| - [785153] - C:\WINDOWS\bcastdvr [MD5.B75D52E7DBEEF44A2C3324A2CE0272C9] - [19/03/2019 05:43:47] - |A| - (.© Microsoft Corporation. Tous droits réservés. - Utilitaire de service de fichier de démarrage.) - [73216] - (10.0.18362.1) - C:\WINDOWS\bfsvc.exe [19/03/2019 05:52:44] - |D| - [39536175] - C:\WINDOWS\Boot [MD5.0C299D24DBF2A907DC94F67D51848D25] - [07/08/2019 16:24:41] - |AS| - (.-.) - [67584] - (0.0.0.0) - C:\WINDOWS\bootstat.dat [19/03/2019 05:52:44] - |D| - [2450424] - C:\WINDOWS\Branding [19/03/2019 05:37:22] - |D| - [0] - C:\WINDOWS\CbsTemp [19/03/2019 05:52:44] - |D| - [34141949] - C:\WINDOWS\Containers [MD5.1F334AC7713E228137147CBFBB7BC9AA] - [19/03/2019 13:03:26] - |A| - (.-.) - [33951] - (0.0.0.0) - C:\WINDOWS\Core.xml [MD5.91980F1B3352DB9CCD59D8AA640A5BB0] - [06/02/2014 19:26:56] - |A| - (.Copyright (c) Creative Technology Ltd., 1998-1999. - Registration Scheduler Program.) - [41984] - (1.0.1.0) - C:\WINDOWS\Ctregrun.exe [19/03/2019 05:52:44] - |D| - [11501377] - C:\WINDOWS\Cursors [MD5.2AABDB49AD062CC52957094D05B1163A] - [31/10/2019 22:37:24] - |A| - (.-.) - [1298584] - (0.0.0.0) - C:\WINDOWS\ddmmain.exe [19/03/2019 05:52:44] - |D| - [15184481] - C:\WINDOWS\debug [MD5.99F5D5BBD351694638DF3C0CC4A919A3] - [07/08/2019 15:54:13] - |A| - (.-.) - [7623] - (0.0.0.0) - C:\WINDOWS\diagerr.xml [19/03/2019 05:52:44] - |D| - [4293525] - C:\WINDOWS\diagnostics [19/03/2019 05:52:44] - |D| - [1915751] - C:\WINDOWS\DiagTrack [MD5.99F5D5BBD351694638DF3C0CC4A919A3] - [07/08/2019 15:54:13] - |A| - (.-.) - [7623] - (0.0.0.0) - C:\WINDOWS\diagwrn.xml [19/03/2019 13:00:40] - |D| - [0] - C:\WINDOWS\DigitalLocker [19/03/2019 05:52:44] - |SD| - [731753] - C:\WINDOWS\Downloaded Program Files [19/03/2019 05:52:44] - |HD| - [83712] - C:\WINDOWS\ELAMBKUP [19/03/2019 13:00:40] - |D| - [0] - C:\WINDOWS\en-US [MD5.4E196CEA0C9C46A7D656C67E52E8C7C7] - [16/11/2019 16:59:53] - |A| - (.© Microsoft Corporation. Tous droits réservés. - Explorateur Windows.) - [4615616] - (10.0.18362.449) - C:\WINDOWS\explorer.exe [19/03/2019 05:52:44] - |RSD| - [502323906] - C:\WINDOWS\Fonts [19/03/2019 13:00:40] - |D| - [110592] - C:\WINDOWS\fr-FR [19/03/2019 05:52:44] - |D| - [0] - C:\WINDOWS\GameBarPresenceWriter [MD5.249ACB810B04247B080D429168F9F5DD] - [05/08/2019 14:04:17] - |A| - (.-.) - [3376] - (0.0.0.0) - C:\WINDOWS\GA_OF.dat [19/03/2019 05:52:44] - |D| - [53145140] - C:\WINDOWS\Globalization [19/03/2019 05:52:44] - |D| - [71464347] - C:\WINDOWS\Help [MD5.67094590E3D57130C587CD6D8AFB6597] - [16/11/2019 17:02:47] - |A| - (.© Microsoft Corporation. Tous droits réservés. - Aide et support Microsoft.) - [1059840] - (10.0.18362.449) - C:\WINDOWS\HelpPane.exe [04/06/2014 14:41:11] - |D| - [2698712] - C:\WINDOWS\HerculesWebcamUpdater [MD5.DF73D52FDCE65F90A2E49EFB5248C77C] - [19/03/2019 05:45:38] - |A| - (.© Microsoft Corporation. Tous droits réservés. - Exécutable de l’aide HTML Microsoft®.) - [18432] - (10.0.18362.1) - C:\WINDOWS\hh.exe [19/03/2019 05:52:44] - |D| - [29869] - C:\WINDOWS\IdentityCRL [19/03/2019 05:52:44] - |D| - [28823998] - C:\WINDOWS\IME [19/03/2019 05:52:44] - |RD| - [9273676] - C:\WINDOWS\ImmersiveControlPanel [19/03/2019 05:50:07] - |D| - [78483386] - C:\WINDOWS\INF [12/04/2018 00:38:21] - |D| - [0] - C:\WINDOWS\InfusedApps [19/03/2019 05:52:44] - |D| - [38126462] - C:\WINDOWS\InputMethod [MD5.009353733A9771F73F8B5334698E3C15] - [08/02/2014 11:50:53] - |A| - (.-.) - [111] - (0.0.0.0) - C:\WINDOWS\installation.ini [19/03/2019 05:52:44] - |SHDC| - [7355658928] - C:\WINDOWS\Installer [19/03/2019 05:52:44] - |D| - [94304] - C:\WINDOWS\L2Schemas [19/03/2019 05:52:44] - |HD| - [0] - C:\WINDOWS\LanguageOverlayCache [MD5.718FECF22BF4BD4FC05B79AA4BEC75D0] - [30/01/2014 17:31:10] - |A| - (.-.) - [1769] - (0.0.0.0) - C:\WINDOWS\Language_trs.ini [19/03/2019 05:52:44] - |D| - [0] - C:\WINDOWS\LiveKernelReports [19/03/2019 05:52:44] - |D| - [36850426] - C:\WINDOWS\Logs [19/03/2019 05:52:44] - |RSD| - [20063519] - C:\WINDOWS\Media [22/08/2013 16:36:31] - |D| - [1619968] - C:\WINDOWS\MediaViewer [MD5.23AF90D2355D8C83AA4567EF1763B467] - [19/03/2019 05:44:30] - |A| - (.-.) - [43131] - (0.0.0.0) - C:\WINDOWS\mib.bin [19/03/2019 05:52:43] - |RD| - [844070085] - C:\WINDOWS\Microsoft.NET [19/03/2019 05:52:44] - |D| - [3323] - C:\WINDOWS\Migration [19/03/2019 05:52:44] - |D| - [0] - C:\WINDOWS\ModemLogs [MD5.F1139811BBF61362915958806AD30211] - [19/03/2019 05:45:00] - |A| - (.© Microsoft Corporation. Tous droits réservés. - Bloc-notes.) - [181248] - (10.0.18362.1) - C:\WINDOWS\notepad.exe [MD5.74F28574BB8F61FFC7DD419FE6B6E0D5] - [10/04/2017 17:52:59] - |A| - (.-.) - [1951] - (0.0.0.0) - C:\WINDOWS\NvContainerRecovery.bat [19/03/2019 13:02:18] - |D| - [199472] - C:\WINDOWS\OCR [19/03/2019 05:52:44] - |RD| - [65] - C:\WINDOWS\Offline Web Pages [07/08/2019 13:56:20] - |DC| - [267848306] - C:\WINDOWS\Panther [MD5.BB7E8EC9EAE35D8E94C5849AF36D1836] - [23/02/2014 22:52:42] - |A| - (.-.) - [46] - (0.0.0.0) - C:\WINDOWS\PCCT.INI [19/03/2019 05:52:44] - |D| - [428344] - C:\WINDOWS\Performance [MD5.24022D48624A85926B4CF316354AE1DD] - [02/12/2019 22:54:43] - |A| - (.-.) - [285768] - (0.0.0.0) - C:\WINDOWS\PFRO.log [19/03/2019 05:52:44] - |D| - [1136442] - C:\WINDOWS\PLA [19/03/2019 05:52:44] - |D| - [2917417] - C:\WINDOWS\PolicyDefinitions [07/08/2019 15:44:29] - |D| - [5808534] - C:\WINDOWS\Prefetch [19/03/2019 05:52:44] - |RD| - [1997306] - C:\WINDOWS\PrintDialog [MD5.09394999ADB19901C665454EE964B13C] - [20/10/2017 15:32:18] - |A| - (.-.) - [36] - (0.0.0.0) - C:\WINDOWS\progress.ini [19/03/2019 05:52:44] - |D| - [5920068] - C:\WINDOWS\Provisioning [MD5.2BF86F7B6D697405B154764B3CB3AE74] - [30/05/2015 13:07:24] - |A| - (.-.) - [19971] - (0.0.0.0) - C:\WINDOWS\Q-Dir.ini [MD5.A65DBC3902D7075E97F4C9B10D1751A9] - [08/01/2019 22:11:34] - |A| - (.(c) Simplitec GmbH. - RegDefragTask.) - [188512] - (1.0.0.462) - C:\WINDOWS\RegDefragTask.exe [MD5.29409008DF22243BB320333F9FD5C060] - [19/03/2019 05:45:47] - |A| - (.© Microsoft Corporation. Tous droits réservés. - Éditeur du Registre.) - [358400] - (10.0.18362.1) - C:\WINDOWS\regedit.exe [19/03/2019 05:52:44] - |D| - [1117876] - C:\WINDOWS\Registration [19/03/2019 05:52:44] - |D| - [11818536] - C:\WINDOWS\rescache [19/03/2019 05:52:44] - |D| - [5075103] - C:\WINDOWS\Resources [MD5.D41D8CD98F00B204E9800998ECF8427E] - [30/01/2014 17:33:05] - |A| - (.-.) - [0] - (0.0.0.0) - C:\WINDOWS\scd.ini [19/03/2019 05:52:44] - |D| - [0] - C:\WINDOWS\SchCache [19/03/2019 05:52:44] - |D| - [122082] - C:\WINDOWS\schemas [19/03/2019 05:52:44] - |D| - [7889842] - C:\WINDOWS\security [07/08/2019 16:24:17] - |D| - [125285498] - C:\WINDOWS\ServiceProfiles [19/03/2019 05:52:44] - |D| - [4096] - C:\WINDOWS\ServiceState [19/03/2019 05:37:22] - |D| - [1295115825] - C:\WINDOWS\servicing [19/03/2019 05:56:38] - |D| - [84295] - C:\WINDOWS\Setup [MD5.AF029CB0388A02EFC8AAC1122D0D9212] - [02/12/2019 11:12:51] - |A| - (.-.) - [6329] - (0.0.0.0) - C:\WINDOWS\setupact.log [MD5.D41D8CD98F00B204E9800998ECF8427E] - [02/12/2019 11:12:51] - |A| - (.-.) - [0] - (0.0.0.0) - C:\WINDOWS\setuperr.log [19/03/2019 05:52:44] - |D| - [7052288] - C:\WINDOWS\ShellComponents [19/03/2019 05:52:44] - |D| - [56043008] - C:\WINDOWS\ShellExperiences [30/10/2015 20:03:03] - |D| - [97307] - C:\WINDOWS\ShellNew [19/03/2019 05:52:44] - |D| - [3070736] - C:\WINDOWS\SKB [30/01/2014 17:20:39] - |D| - [421114105] - C:\WINDOWS\SoftwareDistribution [19/03/2019 05:52:44] - |D| - [86038209] - C:\WINDOWS\Speech [19/03/2019 05:52:44] - |D| - [64004693] - C:\WINDOWS\Speech_OneCore [MD5.906E1DFC3A3A64D3452C5BA124AC9A4C] - [16/11/2019 16:59:53] - |A| - (.© Microsoft Corporation. - Print driver host for applications.) - [132608] - (10.0.18362.476) - C:\WINDOWS\splwow64.exe [19/03/2019 05:52:44] - |D| - [31039] - C:\WINDOWS\System [MD5.286A9EDB379DC3423A528B0864A0F111] - [22/08/2013 14:25:43] - |A| - (.-.) - [219] - (0.0.0.0) - C:\WINDOWS\system.ini [19/03/2019 05:37:22] - |D| - [6298723108] - C:\WINDOWS\System32 [19/03/2019 05:52:45] - |D| - [208866669] - C:\WINDOWS\SystemApps [19/03/2019 05:52:46] - |D| - [187196685] - C:\WINDOWS\SystemResources [19/03/2019 05:52:46] - |D| - [1632538249] - C:\WINDOWS\SysWOW64 [19/03/2019 05:52:46] - |D| - [0] - C:\WINDOWS\TAPI [22/08/2013 16:36:30] - |D| - [6] - C:\WINDOWS\Tasks [19/03/2019 05:52:46] - |D| - [2498335] - C:\WINDOWS\Temp [19/03/2019 05:52:46] - |D| - [13786112] - C:\WINDOWS\TextInput [22/08/2013 16:36:30] - |RD| - [0] - C:\WINDOWS\ToastData [19/03/2019 05:52:46] - |D| - [0] - C:\WINDOWS\tracing [19/03/2019 05:52:46] - |D| - [11728012] - C:\WINDOWS\twain_32 [22/08/2013 16:36:31] - |D| - [89600] - C:\WINDOWS\Twain_32(old) [MD5.BC67755EBD59B2523C943F0D1A9982EF] - [19/03/2019 05:46:01] - |A| - (.- Gestionnaire de sources Twain_32 (Image Acquisition Interface).) - [64512] - (1.7.1.3) - C:\WINDOWS\twain_32.dll [22/08/2013 16:36:30] - |D| - [0] - C:\WINDOWS\vpnplugins [19/03/2019 05:52:46] - |D| - [12420] - C:\WINDOWS\Vss [19/03/2019 05:52:46] - |D| - [33194] - C:\WINDOWS\WaaS [19/03/2019 05:52:46] - |D| - [16568315] - C:\WINDOWS\Web [MD5.8EA6018B46BADBE8D8E7C24790AEE00D] - [09/05/2018 09:00:47] - |A| - (.- INF Scanner Installer.) - [152520] - (1.0.79.0) - C:\WINDOWS\Wiainst64.exe [MD5.919DAC5548D2000BFE3E43C0F74CE669] - [22/08/2013 14:25:43] - |A| - (.-.) - [167] - (0.0.0.0) - C:\WINDOWS\win.ini [MD5.C844CA459F3B209329984772269B6E56] - [19/03/2019 05:44:30] - |RAH| - (.-.) - [670] - (0.0.0.0) - C:\WINDOWS\WindowsShell.Manifest [MD5.2CC83D93DD1DDE691158CF5E9882420B] - [02/12/2019 11:05:07] - |A| - (.-.) - [276] - (0.0.0.0) - C:\WINDOWS\WindowsUpdate.log [MD5.CAA192BFDFB5F2A131EBD649B7062DE3] - [19/03/2019 05:46:01] - |A| - (.© Microsoft Corporation. Tous droits réservés. - Relais Windows Winhlp32.) - [11776] - (10.0.18362.1) - C:\WINDOWS\winhlp32.exe [19/03/2019 05:37:22] - |D| - [7769521114] - C:\WINDOWS\WinSxS [MD5.EA3ECB92A2EA3A42273CB3B308CA1A5B] - [18/08/2017 08:57:50] - |A| - (.-.) - [156910] - (0.0.0.0) - C:\WINDOWS\WMSysPr8.prx [MD5.E7E4D8D7340DA6934B9EA81CBB21374C] - [19/03/2019 05:58:10] - |A| - (.-.) - [316640] - (0.0.0.0) - C:\WINDOWS\WMSysPr9.prx [MD5.1D27F61CC5D659247D2E0C111C5386DE] - [19/03/2019 05:45:54] - |A| - (.© Microsoft Corporation. - Windows Write.) - [11264] - (10.0.18362.1) - C:\WINDOWS\write.exe ---------- | C:\WINDOWS\System32\GroupPolicy [MD5.CEAD048A81341E7F91C31F96A82E98E3] - [04/06/2018 08:44:51] - |A| - (.-.) - [127] - (0.0.0.0) - C:\WINDOWS\System32\GroupPolicy\GPT.INI [04/06/2018 08:44:51] - |D| - [150] - C:\WINDOWS\System32\GroupPolicy\Machine [04/06/2018 08:44:51] - |D| - [0] - C:\WINDOWS\System32\GroupPolicy\User ---------- | Systemroot\System ---------- | Systemroot\Installer (Microsoft Files Whitelisted) [16/08/2016 13:59:20] - C:\WINDOWS\Installer\15ddb0c.msi : (MAGIX Vidéo deluxe Premium - v16.0.1.22 (fr-FR) - MAGIX Software GmbH) [Header ok : D0CF11E0A1B11AE10000000000000000] [16/08/2016 14:52:23] - C:\WINDOWS\Installer\16eefa3.msi : (MAGIX Movie Edit Pro Premium (Fade effects) - v16.0.0.0 (en-II) - MAGIX Software GmbH) [Header ok : D0CF11E0A1B11AE10000000000000000] [16/08/2016 14:38:30] - C:\WINDOWS\Installer\17f8a3f.msi : (MAGIX Movie Edit Pro Premium (Design elements) - v16.0.0.0 (en-II) - MAGIX Software GmbH) [Header ok : D0CF11E0A1B11AE10000000000000000] [16/08/2016 15:37:28] - C:\WINDOWS\Installer\17f8a48.msi : (MAGIX Movie Edit Pro Premium (title effects) - v16.0.0.0 (en-II) - MAGIX Software GmbH) [Header ok : D0CF11E0A1B11AE10000000000000000] [23/06/2017 11:16:37] - C:\WINDOWS\Installer\189f65e.msi : (MAGIX Video deluxe Premium Update - v16.0.4.102 (de-DE) - MAGIX Software GmbH) [Header ok : D0CF11E0A1B11AE10000000000000000] [22/08/2013 07:29:50] - C:\WINDOWS\Installer\1a093.msi : (Intel(R) Trusted Connect Service Client - Intel Corporation) [Header ok : D0CF11E0A1B11AE10000000000000000] [13/03/2019 18:35:52] - C:\WINDOWS\Installer\2333be.msi : (Google Earth Pro - Google) [Header ok : D0CF11E0A1B11AE10000000000000000] [31/05/2017 11:02:52] - C:\WINDOWS\Installer\2395f14.msi : (MAGIX Movie Edit Pro Premium (Slideshow Maker styles 1) - v16.0.4.0 (en-II) - MAGIX Software GmbH) [Header ok : D0CF11E0A1B11AE10000000000000000] [31/05/2017 11:23:50] - C:\WINDOWS\Installer\2419e54.msi : (MAGIX Movie Edit Pro Premium (movie templates 7) - v16.0.4.0 (en-II) - MAGIX Software GmbH) [Header ok : D0CF11E0A1B11AE10000000000000000] [02/05/2017 09:40:40] - C:\WINDOWS\Installer\248b41.msi : (MAGIX Speed burnR - v7.0.1.27 (fr-FR) - MAGIX Software GmbH) [Header ok : D0CF11E0A1B11AE10000000000000000] [17/03/2015 09:41:29] - C:\WINDOWS\Installer\25aff35.msi : ( - Adobe Systems Incorporated) [Header ok : D0CF11E0A1B11AE10000000000000000] [17/04/2017 13:54:05] - C:\WINDOWS\Installer\261621.msi : (League of Legends - Riot Games) [Header ok : D0CF11E0A1B11AE10000000000000000] [19/04/2017 19:01:24] - C:\WINDOWS\Installer\2c16fa.msi : (Intel(R) Rapid Storage Technology - Intel Corporation) [Header ok : D0CF11E0A1B11AE10000000000000000] [10/08/2019 14:40:51] - C:\WINDOWS\Installer\2e3fb.msi : (Adobe ARM Installer - Adobe Systems Incorporated) [Header ok : D0CF11E0A1B11AE10000000000000000] [20/07/2014 20:05:22] - C:\WINDOWS\Installer\2f17adad.msi : (Google Toolbar for Internet Explorer - Google Inc.) [Header ok : D0CF11E0A1B11AE10000000000000000] [17/01/2014 18:23:26] - C:\WINDOWS\Installer\30cf0f4.msi : (Apple Software Update Installer - Apple Inc.) [Header ok : D0CF11E0A1B11AE10000000000000000] [17/01/2014 16:37:52] - C:\WINDOWS\Installer\30cf223.msi : (Apple Application Support Installer - Apple Inc.) [Header ok : D0CF11E0A1B11AE10000000000000000] [14/11/2018 17:53:00] - C:\WINDOWS\Installer\4258759.msi : (File Converter (64 bit) - Adrien Allard) [Header ok : D0CF11E0A1B11AE10000000000000000] [10/08/2017 16:02:00] - C:\WINDOWS\Installer\4afb58.msi : (MAGIX Video deluxe Premium Update - v16.0.4.119 (de-DE) - MAGIX Software GmbH) [Header ok : D0CF11E0A1B11AE10000000000000000] [29/06/2018 10:42:52] - C:\WINDOWS\Installer\4afb7d.msi : (MAGIX Video deluxe Premium Update - v16.0.4.124 (de-DE) - MAGIX Software GmbH) [Header ok : D0CF11E0A1B11AE10000000000000000] [14/03/2019 19:33:48] - C:\WINDOWS\Installer\52c8e5f.msi : (SD Card Formatter - SD Association) [Header ok : D0CF11E0A1B11AE10000000000000000] [07/12/2012 10:58:21] - C:\WINDOWS\Installer\5df00.msi : (AVerMedia TV Application Setup Wizard - AVerMedia Technologies, Inc.) [Header ok : D0CF11E0A1B11AE10000000000000000] [21/07/2017 12:47:00] - C:\WINDOWS\Installer\5ed4a.msi : (MAGIX Video deluxe 2014 Premium Update - v13.0.5.5 (de-DE) - MAGIX AG) [Header ok : D0CF11E0A1B11AE10000000000000000] [13/11/2019 10:59:58] - C:\WINDOWS\Installer\67c1c.msi : (Intel Driver & Support Assistant - Intel) [Header ok : D0CF11E0A1B11AE10000000000000000] [15/12/2019 08:41:06] - C:\WINDOWS\Installer\67fa8.msi : (Google Update Helper - Google LLC) [Header ok : D0CF11E0A1B11AE10000000000000000] [24/01/2012 11:45:30] - C:\WINDOWS\Installer\68c41e3.msi : (Firebird SQL Server - MAGIX Edition - v2.1.32.0 (en-US) - MAGIX AG) [Header ok : D0CF11E0A1B11AE10000000000000000] [25/02/2014 15:00:19] - C:\WINDOWS\Installer\68c4206.msi : (MAGIX Movie Edit Pro 2014 Premium - v13.0.3.14 (en-II) - MAGIX Software GmbH) [Header ok : D0CF11E0A1B11AE10000000000000000] [17/03/2015 14:52:10] - C:\WINDOWS\Installer\6b9a9.msi : ( - Samsung Electronics Co.,Ltd) [Header ok : D0CF11E0A1B11AE10000000000000000] [21/09/2019 16:34:31] - C:\WINDOWS\Installer\6ea3c8.msi : (Update Service 5.7.29.73 - v5.7.29.73 (en-II) - MAGIX Software GmbH) [Header ok : D0CF11E0A1B11AE10000000000000000] [26/04/2019 17:19:37] - C:\WINDOWS\Installer\6ebbfac.msi : (Adobe AIR Installer - Adobe) [Header ok : D0CF11E0A1B11AE10000000000000000] [28/03/2019 18:37:09] - C:\WINDOWS\Installer\7375a9c.msi : (Adobe Shockwave Player 12.3 - Adobe, Inc) [Header ok : D0CF11E0A1B11AE10000000000000000] [22/05/2019 15:22:40] - C:\WINDOWS\Installer\76af0c.msi : (Intel(R) Computing Improvement Program - Intel Corporation) [Header ok : D0CF11E0A1B11AE10000000000000000] [04/04/2016 10:57:00] - C:\WINDOWS\Installer\7f4cca.msi : ( -) [Header ok : D0CF11E0A1B11AE10000000000000000] [14/11/2019 16:15:38] - C:\WINDOWS\Installer\a1b38.msi : (Intel Driver & Support Assistant - Intel) [Header ok : D0CF11E0A1B11AE10000000000000000] [11/07/2014 11:42:39] - C:\WINDOWS\Installer\c2f1061.msi : (MAGIX Video deluxe 2014 Premium Update - v13.0.5.4 (de-DE) - MAGIX AG) [Header ok : D0CF11E0A1B11AE10000000000000000] [05/06/2013 09:36:54] - C:\WINDOWS\Installer\c55cba3.msi : (Vasco da Gama 7 HDPro - MotionStudios) [Header ok : D0CF11E0A1B11AE10000000000000000] [29/01/2014 03:29:14] - C:\WINDOWS\Installer\d7c10c.msi : (swMSM - Adobe Systems, Inc) [Header ok : D0CF11E0A1B11AE10000000000000000] [17/04/2018 18:53:56] - [9064448] - (.().-. - ()) - C:\WINDOWS\Installer\102042.msp [20/04/2016 05:41:02] - [8040960] - (.().-. - ()) - C:\WINDOWS\Installer\1147ba.msp [14/04/2016 07:05:44] - [4337664] - (.().-. - ()) - C:\WINDOWS\Installer\1147ce.msp [14/04/2016 07:01:50] - [5959680] - (.().-. - ()) - C:\WINDOWS\Installer\1147e2.msp [14/04/2016 07:02:44] - [4988928] - (.().-. - ()) - C:\WINDOWS\Installer\1147f6.msp [14/04/2016 07:04:46] - [11169792] - (.().-. - ()) - C:\WINDOWS\Installer\11480b.msp [14/04/2016 07:00:42] - [11554816] - (.().-. - ()) - C:\WINDOWS\Installer\11481f.msp [25/01/2018 19:06:22] - [12877824] - (.().-. - ()) - C:\WINDOWS\Installer\116f11.msp [25/01/2018 19:07:20] - [1875968] - (.().-. - ()) - C:\WINDOWS\Installer\116f18.msp [24/07/2013 08:36:26] - [8912896] - (.().-. - ()) - C:\WINDOWS\Installer\11ffacd.msp [17/07/2013 13:33:26] - [16541184] - (.().-. - ()) - C:\WINDOWS\Installer\11ffae1.msp [08/05/2013 21:36:50] - [10943488] - (.().-. - ()) - C:\WINDOWS\Installer\11ffb07.msp [06/09/2013 23:07:02] - [11534336] - (.().-. - ()) - C:\WINDOWS\Installer\11ffb0f.msp [08/03/2013 18:34:38] - [5196288] - (.().-. - ()) - C:\WINDOWS\Installer\11ffb26.msp [11/07/2013 05:30:06] - [8865792] - (.().-. - ()) - C:\WINDOWS\Installer\11ffb3a.msp [18/11/2013 06:05:54] - [11192320] - (.().-. - ()) - C:\WINDOWS\Installer\11ffb4f.msp [01/11/2013 18:15:08] - [6185472] - (.().-. - ()) - C:\WINDOWS\Installer\11ffb63.msp [16/09/2013 14:15:32] - [8407552] - (.().-. - ()) - C:\WINDOWS\Installer\11ffb6b.msp [18/09/2013 16:22:18] - [10510848] - (.().-. - ()) - C:\WINDOWS\Installer\11ffb7f.msp [04/09/2013 17:56:48] - [5980160] - (.().-. - ()) - C:\WINDOWS\Installer\11ffb93.msp [18/09/2013 16:23:10] - [9745408] - (.().-. - ()) - C:\WINDOWS\Installer\11ffba7.msp [21/06/2013 10:24:42] - [10079232] - (.().-. - ()) - C:\WINDOWS\Installer\11ffbaf.msp [24/07/2013 10:02:14] - [755712] - (.().-. - ()) - C:\WINDOWS\Installer\11ffbca.msp [09/01/2013 12:39:02] - [19780096] - (.().-. - ()) - C:\WINDOWS\Installer\11ffbdd.msp [04/09/2013 17:56:14] - [11640832] - (.().-. - ()) - C:\WINDOWS\Installer\11ffbf1.msp [06/09/2013 23:07:14] - [2347008] - (.().-. - ()) - C:\WINDOWS\Installer\11ffbf9.msp [18/11/2013 06:06:06] - [4346880] - (.().-. - ()) - C:\WINDOWS\Installer\11ffc0d.msp [12/09/2013 18:07:34] - [9443840] - (.().-. - ()) - C:\WINDOWS\Installer\11ffc15.msp [24/07/2013 08:09:22] - [8138240] - (.().-. - ()) - C:\WINDOWS\Installer\11ffc1d.msp [01/11/2013 18:14:50] - [9660928] - (.().-. - ()) - C:\WINDOWS\Installer\11ffc31.msp [06/09/2013 05:46:04] - [13146112] - (.().-. - ()) - C:\WINDOWS\Installer\11ffc4b.msp [19/12/2012 22:36:38] - [13662720] - (.().-. - ()) - C:\WINDOWS\Installer\11ffc5f.msp [16/09/2014 21:23:56] - [11124736] - (.().-. - ()) - C:\WINDOWS\Installer\127b94.msp [23/09/2014 13:29:08] - [4980736] - (.().-. - ()) - C:\WINDOWS\Installer\127ba8.msp [16/09/2014 20:32:04] - [4333568] - (.().-. - ()) - C:\WINDOWS\Installer\127bbc.msp [18/03/2016 20:07:16] - [4251648] - (.().-. - ()) - C:\WINDOWS\Installer\12bafe.msp [18/03/2016 20:07:26] - [9699328] - (.().-. - ()) - C:\WINDOWS\Installer\12bb12.msp [18/03/2016 20:07:02] - [10059776] - (.().-. - ()) - C:\WINDOWS\Installer\12bb27.msp [24/02/2016 07:14:42] - [9805824] - (.().-. - ()) - C:\WINDOWS\Installer\12bb3b.msp [18/03/2016 20:06:48] - [4988928] - (.().-. - ()) - C:\WINDOWS\Installer\12bb4f.msp [18/03/2016 20:06:44] - [10059776] - (.().-. - ()) - C:\WINDOWS\Installer\12bb63.msp [18/02/2015 05:17:44] - [16441344] - (.().-. - ()) - C:\WINDOWS\Installer\13121d9a.msp [17/02/2015 17:37:22] - [746496] - (.().-. - ()) - C:\WINDOWS\Installer\13121da2.msp [18/02/2015 05:15:46] - [13508608] - (.().-. - ()) - C:\WINDOWS\Installer\13121db6.msp [18/02/2015 05:29:44] - [11120640] - (.().-. - ()) - C:\WINDOWS\Installer\13121dcb.msp [18/02/2015 05:22:54] - [4939776] - (.().-. - ()) - C:\WINDOWS\Installer\13121ddf.msp [17/02/2015 17:43:42] - [8855552] - (.().-. - ()) - C:\WINDOWS\Installer\13121de9.msp [17/02/2015 17:43:02] - [1053696] - (.().-. - ()) - C:\WINDOWS\Installer\13121dea.msp [10/02/2015 13:54:50] - [9691136] - (.().-. - ()) - C:\WINDOWS\Installer\13121dfe.msp [18/02/2015 05:14:44] - [10448896] - (.().-. - ()) - C:\WINDOWS\Installer\13121e12.msp [10/02/2015 22:16:22] - [8412160] - (.().-. - ()) - C:\WINDOWS\Installer\13121e1a.msp [10/02/2015 13:53:02] - [4984832] - (.().-. - ()) - C:\WINDOWS\Installer\13121e2e.msp [10/02/2015 13:54:42] - [4333568] - (.().-. - ()) - C:\WINDOWS\Installer\13121e42.msp [12/08/2019 07:29:03] - [50438144] - (.().-. - ()) - C:\WINDOWS\Installer\13b6492.msp [18/07/2014 04:01:00] - [1012736] - (.().-. - ()) - C:\WINDOWS\Installer\1442e9f.msp [15/07/2014 22:41:12] - [5002752] - (.().-. - ()) - C:\WINDOWS\Installer\1442eb3.msp [22/10/2018 14:33:19] - [2584576] - (.().-. - ()) - C:\WINDOWS\Installer\14fbfc5.msp [15/11/2016 22:18:56] - [9695232] - (.().-. - ()) - C:\WINDOWS\Installer\15a777.msp [15/11/2016 22:17:32] - [16433152] - (.().-. - ()) - C:\WINDOWS\Installer\15a78b.msp [15/11/2016 22:17:00] - [10465280] - (.().-. - ()) - C:\WINDOWS\Installer\15a79f.msp [16/11/2016 09:18:22] - [9089024] - (.().-. - ()) - C:\WINDOWS\Installer\15a7a7.msp [28/06/2011 21:27:28] - [4028928] - (.().-. - ()) - C:\WINDOWS\Installer\15b3f.msp [15/10/2007 00:44:16] - [22625792] - (.().-. - ()) - C:\WINDOWS\Installer\15fee76.msp [15/10/2007 00:44:32] - [965632] - (.().-. - ()) - C:\WINDOWS\Installer\15fee9f.msp [15/10/2007 00:44:40] - [6205440] - (.().-. - ()) - C:\WINDOWS\Installer\15feea7.msp [15/10/2007 00:44:48] - [5749760] - (.().-. - ()) - C:\WINDOWS\Installer\15feeaf.msp [15/10/2007 00:44:28] - [324608] - (.().-. - ()) - C:\WINDOWS\Installer\15feeb5.msp [15/10/2007 00:44:58] - [4116480] - (.().-. - ()) - C:\WINDOWS\Installer\15feebe.msp [15/10/2007 00:44:52] - [324608] - (.().-. - ()) - C:\WINDOWS\Installer\15feec4.msp [15/10/2007 00:44:06] - [6956544] - (.().-. - ()) - C:\WINDOWS\Installer\15feecf.msp [15/10/2007 00:44:22] - [12280320] - (.().-. - ()) - C:\WINDOWS\Installer\15feed5.msp [04/04/2009 05:46:04] - [20993024] - (.().-. - ()) - C:\WINDOWS\Installer\15feff6.msp [04/04/2009 05:46:22] - [1110528] - (.().-. - ()) - C:\WINDOWS\Installer\15ff021.msp [04/04/2009 05:46:28] - [10874880] - (.().-. - ()) - C:\WINDOWS\Installer\15ff02b.msp [04/04/2009 05:46:36] - [9926144] - (.().-. - ()) - C:\WINDOWS\Installer\15ff035.msp [04/04/2009 05:46:16] - [1282560] - (.().-. - ()) - C:\WINDOWS\Installer\15ff03c.msp [04/04/2009 05:46:48] - [4443136] - (.().-. - ()) - C:\WINDOWS\Installer\15ff043.msp [04/04/2009 05:46:42] - [7888384] - (.().-. - ()) - C:\WINDOWS\Installer\15ff04c.msp [04/04/2009 05:45:54] - [7999488] - (.().-. - ()) - C:\WINDOWS\Installer\15ff059.msp [04/04/2009 05:46:12] - [14085120] - (.().-. - ()) - C:\WINDOWS\Installer\15ff05f.msp [15/09/2011 21:27:14] - [33243648] - (.().-. - ()) - C:\WINDOWS\Installer\15ff080.msp [15/09/2011 21:27:26] - [1833984] - (.().-. - ()) - C:\WINDOWS\Installer\15ff0ab.msp [15/09/2011 21:27:30] - [14140416] - (.().-. - ()) - C:\WINDOWS\Installer\15ff0b6.msp [15/09/2011 21:27:34] - [10838528] - (.().-. - ()) - C:\WINDOWS\Installer\15ff0c0.msp [15/09/2011 21:27:22] - [7959552] - (.().-. - ()) - C:\WINDOWS\Installer\15ff0c9.msp [15/09/2011 21:27:42] - [4760064] - (.().-. - ()) - C:\WINDOWS\Installer\15ff0cf.msp [15/09/2011 21:27:38] - [11163136] - (.().-. - ()) - C:\WINDOWS\Installer\15ff0da.msp [15/09/2011 21:27:18] - [15017984] - (.().-. - ()) - C:\WINDOWS\Installer\15ff0e0.msp [04/06/2010 13:38:58] - [11918336] - (.().-. - ()) - C:\WINDOWS\Installer\15ff116.msp [04/06/2010 13:39:04] - [4588032] - (.().-. - ()) - C:\WINDOWS\Installer\15ff12c.msp [10/02/2016 11:45:24] - [13086720] - (.().-. - ()) - C:\WINDOWS\Installer\15ff670.msp [10/02/2016 11:39:10] - [3665920] - (.().-. - ()) - C:\WINDOWS\Installer\15ff684.msp [10/02/2016 11:39:52] - [2584576] - (.().-. - ()) - C:\WINDOWS\Installer\15ff698.msp [18/02/2016 07:40:12] - [11165696] - (.().-. - ()) - C:\WINDOWS\Installer\15ff6ad.msp [18/02/2016 07:40:00] - [4337664] - (.().-. - ()) - C:\WINDOWS\Installer\15ff6c1.msp [16/08/2019 09:08:46] - [9048064] - (.().-. - ()) - C:\WINDOWS\Installer\162500f.msp [20/10/2018 14:18:40] - [774144] - (.().-. - ()) - C:\WINDOWS\Installer\16dfcb17.msp [20/10/2018 14:19:32] - [2023424] - (.().-. - ()) - C:\WINDOWS\Installer\1703ecb9.msp [20/10/2018 14:18:48] - [8818688] - (.().-. - ()) - C:\WINDOWS\Installer\1703ecc1.msp [03/01/2019 10:17:04] - [1720320] - (.().-. - ()) - C:\WINDOWS\Installer\17afa6d.msp [12/02/2019 22:30:56] - [8757248] - (.().-. - ()) - C:\WINDOWS\Installer\184558f.msp [26/03/2018 18:15:06] - [9060352] - (.().-. - ()) - C:\WINDOWS\Installer\184e9e.msp [24/03/2018 14:17:44] - [10461184] - (.().-. - ()) - C:\WINDOWS\Installer\184eb2.msp [24/03/2018 14:18:34] - [9695232] - (.().-. - ()) - C:\WINDOWS\Installer\184ec6.msp [24/03/2018 14:18:30] - [4341760] - (.().-. - ()) - C:\WINDOWS\Installer\184eda.msp [24/03/2018 14:18:34] - [10539008] - (.().-. - ()) - C:\WINDOWS\Installer\184eef.msp [28/06/2011 21:21:32] - [4637184] - (.().-. - ()) - C:\WINDOWS\Installer\18a1f.msp [13/08/2015 06:59:22] - [9687040] - (.().-. - ()) - C:\WINDOWS\Installer\18a555.msp [02/09/2015 15:00:04] - [1118208] - (.().-. - ()) - C:\WINDOWS\Installer\18a55d.msp [13/08/2015 06:57:10] - [10039296] - (.().-. - ()) - C:\WINDOWS\Installer\18a571.msp [19/08/2015 04:52:56] - [9801728] - (.().-. - ()) - C:\WINDOWS\Installer\18a585.msp [13/08/2015 06:58:40] - [4984832] - (.().-. - ()) - C:\WINDOWS\Installer\18a599.msp [26/10/2017 14:21:46] - [5144576] - (.().-. - ()) - C:\WINDOWS\Installer\1a6536.msp [29/10/2017 17:11:36] - [8907776] - (.().-. - ()) - C:\WINDOWS\Installer\1a653e.msp [04/10/2017 12:35:44] - [10547200] - (.().-. - ()) - C:\WINDOWS\Installer\1a9d9c.msp [04/10/2017 12:36:24] - [4341760] - (.().-. - ()) - C:\WINDOWS\Installer\1a9db0.msp [28/12/2018 20:28:00] - [7995392] - (.().-. - ()) - C:\WINDOWS\Installer\1bea53.msp [12/10/2016 16:19:59] - [53345280] - (.().-. - ()) - C:\WINDOWS\Installer\1df9d0e.msp [22/05/2015 11:58:06] - [8036352] - (.().-. - ()) - C:\WINDOWS\Installer\1e1551.msp [15/05/2015 16:12:56] - [4984832] - (.().-. - ()) - C:\WINDOWS\Installer\1e1565.msp [18/05/2015 13:56:08] - [1118208] - (.().-. - ()) - C:\WINDOWS\Installer\1e156e.msp [22/05/2015 11:57:58] - [9068032] - (.().-. - ()) - C:\WINDOWS\Installer\1e1576.msp [22/05/2015 11:58:38] - [5877248] - (.().-. - ()) - C:\WINDOWS\Installer\1e157e.msp [23/09/2016 09:42:52] - [11177984] - (.().-. - ()) - C:\WINDOWS\Installer\1e6866d.msp [23/09/2016 09:42:50] - [4337664] - (.().-. - ()) - C:\WINDOWS\Installer\1e68681.msp [03/09/2016 20:43:22] - [9809920] - (.().-. - ()) - C:\WINDOWS\Installer\1e68695.msp [16/04/2014 07:43:24] - [22920192] - (.().-. - ()) - C:\WINDOWS\Installer\1f119b9b.msp [16/04/2014 07:41:38] - [7844864] - (.().-. - ()) - C:\WINDOWS\Installer\1f119baf.msp [16/04/2014 07:40:26] - [7900672] - (.().-. - ()) - C:\WINDOWS\Installer\1f119bc3.msp [29/04/2014 10:55:14] - [5006848] - (.().-. - ()) - C:\WINDOWS\Installer\1f119bd7.msp [02/04/2014 01:54:52] - [3246592] - (.().-. - ()) - C:\WINDOWS\Installer\1f119be1.msp [19/03/2014 12:11:50] - [11222528] - (.().-. - ()) - C:\WINDOWS\Installer\21549b.msp [29/01/2014 02:37:28] - [13148160] - (.().-. - ()) - C:\WINDOWS\Installer\2154af.msp [12/03/2014 01:04:02] - [5196288] - (.().-. - ()) - C:\WINDOWS\Installer\2154c3.msp [13/03/2014 10:38:28] - [8914432] - (.().-. - ()) - C:\WINDOWS\Installer\2154cb.msp [19/03/2014 12:11:48] - [4347392] - (.().-. - ()) - C:\WINDOWS\Installer\2154df.msp [25/03/2014 04:59:44] - [756224] - (.().-. - ()) - C:\WINDOWS\Installer\2154e7.msp [12/03/2014 01:03:54] - [5005824] - (.().-. - ()) - C:\WINDOWS\Installer\2154fb.msp [28/08/2017 17:40:46] - [2424832] - (.().-. - ()) - C:\WINDOWS\Installer\2310f05.msp [16/05/2014 04:06:18] - [9850368] - (.().-. - ()) - C:\WINDOWS\Installer\240c9e02.msp [16/05/2014 04:07:12] - [5002752] - (.().-. - ()) - C:\WINDOWS\Installer\240c9e16.msp [16/05/2014 04:10:46] - [11215360] - (.().-. - ()) - C:\WINDOWS\Installer\240c9e2b.msp [16/05/2014 04:10:50] - [4346880] - (.().-. - ()) - C:\WINDOWS\Installer\240c9e3f.msp [16/05/2014 04:08:36] - [8179200] - (.().-. - ()) - C:\WINDOWS\Installer\240c9e53.msp [16/07/2015 07:19:54] - [758784] - (.().-. - ()) - C:\WINDOWS\Installer\246930.msp [22/07/2015 08:09:24] - [16433152] - (.().-. - ()) - C:\WINDOWS\Installer\246944.msp [14/07/2015 13:59:14] - [8818688] - (.().-. - ()) - C:\WINDOWS\Installer\246958.msp [16/07/2015 07:20:48] - [1110528] - (.().-. - ()) - C:\WINDOWS\Installer\246960.msp [01/07/2015 22:37:38] - [9801728] - (.().-. - ()) - C:\WINDOWS\Installer\246974.msp [16/07/2015 07:19:56] - [7955456] - (.().-. - ()) - C:\WINDOWS\Installer\24697c.msp [18/03/2015 03:08:56] - [9019392] - (.().-. - ()) - C:\WINDOWS\Installer\246990.msp [14/07/2015 14:00:26] - [4939776] - (.().-. - ()) - C:\WINDOWS\Installer\2469a4.msp [14/07/2015 14:04:30] - [4333568] - (.().-. - ()) - C:\WINDOWS\Installer\2469b8.msp [14/07/2015 13:56:40] - [10444800] - (.().-. - ()) - C:\WINDOWS\Installer\2469cc.msp [22/07/2015 08:07:40] - [5079040] - (.().-. - ()) - C:\WINDOWS\Installer\2469e0.msp [14/07/2015 13:58:24] - [4984832] - (.().-. - ()) - C:\WINDOWS\Installer\2469f4.msp [14/07/2015 14:04:18] - [11120640] - (.().-. - ()) - C:\WINDOWS\Installer\246a09.msp [22/07/2015 08:10:44] - [10031104] - (.().-. - ()) - C:\WINDOWS\Installer\246a1f.msp [13/11/2017 05:26:16] - [23506944] - (.().-. - ()) - C:\WINDOWS\Installer\247218.msp [18/08/2016 06:26:02] - [8467968] - (.().-. - ()) - C:\WINDOWS\Installer\25f4d2.msp [23/01/2019 15:45:21] - [53014528] - (.().-. - ()) - C:\WINDOWS\Installer\2a188.msp [16/01/2019 21:22:30] - [9031680] - (.().-. - ()) - C:\WINDOWS\Installer\2a18e.msp [11/11/2015 22:31:42] - [10461184] - (.().-. - ()) - C:\WINDOWS\Installer\2a4a8ae.msp [11/11/2015 22:33:00] - [4984832] - (.().-. - ()) - C:\WINDOWS\Installer\2a4a8c2.msp [11/11/2015 09:59:14] - [8869376] - (.().-. - ()) - C:\WINDOWS\Installer\2a4a8ca.msp [19/11/2015 10:34:30] - [11161600] - (.().-. - ()) - C:\WINDOWS\Installer\2a4a8df.msp [11/11/2015 22:32:20] - [16424960] - (.().-. - ()) - C:\WINDOWS\Installer\2a4a8f3.msp [11/11/2015 09:58:48] - [758784] - (.().-. - ()) - C:\WINDOWS\Installer\2a4a8fb.msp [11/11/2015 22:32:34] - [8818688] - (.().-. - ()) - C:\WINDOWS\Installer\2a4a90f.msp [04/11/2015 16:11:08] - [9715712] - (.().-. - ()) - C:\WINDOWS\Installer\2a4a923.msp [19/11/2015 10:34:14] - [4333568] - (.().-. - ()) - C:\WINDOWS\Installer\2a4a945.msp [11/11/2015 22:34:28] - [9691136] - (.().-. - ()) - C:\WINDOWS\Installer\2a4a959.msp [19/01/2017 11:28:55] - [1937408] - (.().-. - ()) - C:\WINDOWS\Installer\2a8e47f.msp [13/11/2018 05:24:12] - [3485696] - (.().-. - ()) - C:\WINDOWS\Installer\2b4517.msp [16/08/2016 22:51:56] - [5308416] - (.().-. - ()) - C:\WINDOWS\Installer\2bb2e6.msp [15/09/2016 21:16:47] - [53339648] - (.().-. - ()) - C:\WINDOWS\Installer\2bb2f5.msp [16/08/2016 23:18:52] - [13074432] - (.().-. - ()) - C:\WINDOWS\Installer\2bb308.msp [18/08/2016 06:26:32] - [5889536] - (.().-. - ()) - C:\WINDOWS\Installer\2bb310.msp [16/08/2016 23:15:28] - [9695232] - (.().-. - ()) - C:\WINDOWS\Installer\2bb324.msp [16/08/2016 23:15:52] - [16412672] - (.().-. - ()) - C:\WINDOWS\Installer\2bb338.msp [16/08/2016 23:18:00] - [10465280] - (.().-. - ()) - C:\WINDOWS\Installer\2bb34c.msp [10/02/2016 11:40:10] - [4984832] - (.().-. - ()) - C:\WINDOWS\Installer\2d00c2.msp [07/07/2015 11:36:08] - [4726784] - (.().-. - ()) - C:\WINDOWS\Installer\2f5dcd.msp [07/07/2015 11:39:32] - [10043392] - (.().-. - ()) - C:\WINDOWS\Installer\2f5de2.msp [20/06/2015 02:57:10] - [4984832] - (.().-. - ()) - C:\WINDOWS\Installer\2f5df6.msp [20/06/2015 02:56:20] - [10444800] - (.().-. - ()) - C:\WINDOWS\Installer\2f5e0a.msp [17/06/2015 14:23:24] - [8835072] - (.().-. - ()) - C:\WINDOWS\Installer\2f5e12.msp [17/06/2015 14:23:30] - [432128] - (.().-. - ()) - C:\WINDOWS\Installer\2f5e18.msp [20/06/2015 02:57:20] - [13508608] - (.().-. - ()) - C:\WINDOWS\Installer\2f5e2c.msp [20/06/2015 02:57:58] - [9691136] - (.().-. - ()) - C:\WINDOWS\Installer\2f5e40.msp [13/01/2016 07:51:02] - [9699328] - (.().-. - ()) - C:\WINDOWS\Installer\2fb7e4.msp [13/01/2016 07:42:14] - [4988928] - (.().-. - ()) - C:\WINDOWS\Installer\2fb7f8.msp [13/01/2016 07:47:38] - [4337664] - (.().-. - ()) - C:\WINDOWS\Installer\2fb80c.msp [13/01/2016 07:46:56] - [11177984] - (.().-. - ()) - C:\WINDOWS\Installer\2fb821.msp [27/01/2016 18:03:14] - [8910848] - (.().-. - ()) - C:\WINDOWS\Installer\2fb829.msp [13/01/2016 07:41:26] - [16441344] - (.().-. - ()) - C:\WINDOWS\Installer\2fb83d.msp [13/01/2016 07:39:14] - [10461184] - (.().-. - ()) - C:\WINDOWS\Installer\2fb851.msp [13/06/2019 13:38:00] - [2260992] - (.().-. - ()) - C:\WINDOWS\Installer\306f7.msp [14/08/2014 18:38:44] - [4976640] - (.().-. - ()) - C:\WINDOWS\Installer\32466b4.msp [10/04/2017 06:34:32] - [57815040] - (.().-. - ()) - C:\WINDOWS\Installer\334f5.msp [12/04/2017 11:25:28] - [9121280] - (.().-. - ()) - C:\WINDOWS\Installer\33f0e6.msp [11/04/2017 22:27:48] - [11177984] - (.().-. - ()) - C:\WINDOWS\Installer\33f0fb.msp [11/04/2017 22:25:56] - [4337664] - (.().-. - ()) - C:\WINDOWS\Installer\33f10f.msp [11/04/2017 22:25:46] - [9420800] - (.().-. - ()) - C:\WINDOWS\Installer\33f123.msp [11/04/2017 22:25:26] - [16441344] - (.().-. - ()) - C:\WINDOWS\Installer\33f137.msp [18/03/2015 03:09:52] - [4988928] - (.().-. - ()) - C:\WINDOWS\Installer\34a7b5d.msp [18/03/2015 03:08:20] - [11128832] - (.().-. - ()) - C:\WINDOWS\Installer\34a7b72.msp [22/03/2015 22:15:56] - [8028672] - (.().-. - ()) - C:\WINDOWS\Installer\34a7b7a.msp [25/03/2015 07:24:06] - [8896512] - (.().-. - ()) - C:\WINDOWS\Installer\34a7b82.msp [18/03/2015 03:08:56] - [4333568] - (.().-. - ()) - C:\WINDOWS\Installer\34a7b96.msp [11/07/2017 05:57:12] - [1732608] - (.().-. - ()) - C:\WINDOWS\Installer\36201.msp [13/07/2016 00:06:16] - [4984832] - (.().-. - ()) - C:\WINDOWS\Installer\3fd939.msp [13/05/2019 07:57:34] - [59400192] - (.().-. - ()) - C:\WINDOWS\Installer\410f5.msp [16/10/2015 21:27:14] - [3657728] - (.().-. - ()) - C:\WINDOWS\Installer\4834d1.msp [16/10/2015 21:29:18] - [4333568] - (.().-. - ()) - C:\WINDOWS\Installer\4834e5.msp [14/10/2015 09:45:58] - [9075200] - (.().-. - ()) - C:\WINDOWS\Installer\4834ed.msp [29/10/2015 03:25:12] - [1122304] - (.().-. - ()) - C:\WINDOWS\Installer\4834f5.msp [16/10/2015 21:27:36] - [16429056] - (.().-. - ()) - C:\WINDOWS\Installer\483509.msp [16/10/2015 21:28:16] - [10457088] - (.().-. - ()) - C:\WINDOWS\Installer\48351d.msp [16/10/2015 21:28:00] - [4984832] - (.().-. - ()) - C:\WINDOWS\Installer\483531.msp [16/10/2015 21:29:12] - [5173248] - (.().-. - ()) - C:\WINDOWS\Installer\483545.msp [16/10/2015 21:30:46] - [9687040] - (.().-. - ()) - C:\WINDOWS\Installer\483559.msp [16/10/2015 21:29:26] - [11161600] - (.().-. - ()) - C:\WINDOWS\Installer\48356e.msp [16/10/2015 21:28:26] - [5300224] - (.().-. - ()) - C:\WINDOWS\Installer\483582.msp [16/10/2015 21:26:34] - [8691712] - (.().-. - ()) - C:\WINDOWS\Installer\483598.msp [16/02/2017 12:26:24] - [10465280] - (.().-. - ()) - C:\WINDOWS\Installer\4fee6ff.msp [15/03/2017 10:24:24] - [53348864] - (.().-. - ()) - C:\WINDOWS\Installer\4fee70e.msp [16/02/2017 12:27:46] - [11173888] - (.().-. - ()) - C:\WINDOWS\Installer\4fee722.msp [16/02/2017 12:28:36] - [9695232] - (.().-. - ()) - C:\WINDOWS\Installer\4fee736.msp [16/02/2017 12:27:26] - [8134656] - (.().-. - ()) - C:\WINDOWS\Installer\4fee74a.msp [07/02/2017 12:39:54] - [9805824] - (.().-. - ()) - C:\WINDOWS\Installer\4fee75e.msp [16/02/2017 12:27:56] - [4337664] - (.().-. - ()) - C:\WINDOWS\Installer\4fee772.msp [16/02/2017 17:11:28] - [638976] - (.().-. - ()) - C:\WINDOWS\Installer\4fee77a.msp [10/12/2015 12:00:52] - [11157504] - (.().-. - ()) - C:\WINDOWS\Installer\5455e6d.msp [10/12/2015 11:59:00] - [5300224] - (.().-. - ()) - C:\WINDOWS\Installer\5455e81.msp [11/12/2015 15:06:40] - [8866816] - (.().-. - ()) - C:\WINDOWS\Installer\5455e89.msp [23/12/2015 18:00:14] - [10461184] - (.().-. - ()) - C:\WINDOWS\Installer\5455e9d.msp [10/12/2015 11:58:30] - [4968448] - (.().-. - ()) - C:\WINDOWS\Installer\5455eb1.msp [10/12/2015 11:57:20] - [16433152] - (.().-. - ()) - C:\WINDOWS\Installer\5455ec5.msp [10/12/2015 11:57:36] - [24256512] - (.().-. - ()) - C:\WINDOWS\Installer\5455ee7.msp [23/12/2015 18:00:18] - [9687040] - (.().-. - ()) - C:\WINDOWS\Installer\5455efb.msp [11/10/2016 20:17:00] - [11165696] - (.().-. - ()) - C:\WINDOWS\Installer\54f9636.msp [11/10/2016 20:17:18] - [16416768] - (.().-. - ()) - C:\WINDOWS\Installer\54f964a.msp [11/10/2016 20:16:58] - [4337664] - (.().-. - ()) - C:\WINDOWS\Installer\54f965e.msp [11/10/2016 20:17:00] - [10461184] - (.().-. - ()) - C:\WINDOWS\Installer\54f9672.msp [27/10/2016 15:43:22] - [9019392] - (.().-. - ()) - C:\WINDOWS\Installer\54f9686.msp [11/10/2016 20:17:14] - [9695232] - (.().-. - ()) - C:\WINDOWS\Installer\54f969a.msp [12/10/2016 02:59:04] - [5893120] - (.().-. - ()) - C:\WINDOWS\Installer\54f96a2.msp [23/11/2017 09:31:16] - [282624] - (.().-. - ()) - C:\WINDOWS\Installer\551e6.msp [25/01/2018 18:59:52] - [17022976] - (.().-. - ()) - C:\WINDOWS\Installer\5969532.msp [19/01/2018 14:22:44] - [5892608] - (.().-. - ()) - C:\WINDOWS\Installer\596953a.msp [19/01/2018 14:18:12] - [9095168] - (.().-. - ()) - C:\WINDOWS\Installer\5969542.msp [07/08/2017 09:20:05] - [70610944] - (.().-. - ()) - C:\WINDOWS\Installer\59beb.msp [24/10/2019 13:03:06] - [4616192] - (.().-. - ()) - C:\WINDOWS\Installer\5ab848.msp [22/01/2019 16:38:42] - [8855552] - (.().-. - ()) - C:\WINDOWS\Installer\5c5230d.msp [14/02/2018 09:26:58] - [4337664] - (.().-. - ()) - C:\WINDOWS\Installer\5d53ea3.msp [14/02/2018 09:26:46] - [10469376] - (.().-. - ()) - C:\WINDOWS\Installer\5d53eb7.msp [14/02/2018 09:26:48] - [10543104] - (.().-. - ()) - C:\WINDOWS\Installer\5d53ecc.msp [19/12/2017 21:58:10] - [9076224] - (.().-. - ()) - C:\WINDOWS\Installer\5d9b23c.msp [22/03/2017 05:57:52] - [13086720] - (.().-. - ()) - C:\WINDOWS\Installer\5ebeb.msp [02/04/2017 00:41:10] - [8898048] - (.().-. - ()) - C:\WINDOWS\Installer\5ebf3.msp [14/03/2017 13:50:38] - [10469376] - (.().-. - ()) - C:\WINDOWS\Installer\5ec07.msp [14/03/2017 13:51:16] - [16433152] - (.().-. - ()) - C:\WINDOWS\Installer\5ec1e.msp [14/03/2017 13:51:36] - [9691136] - (.().-. - ()) - C:\WINDOWS\Installer\5ec32.msp [13/04/2017 16:44:29] - [53348864] - (.().-. - ()) - C:\WINDOWS\Installer\5ec41.msp [22/01/2019 16:39:00] - [7778304] - (.().-. - ()) - C:\WINDOWS\Installer\60c941d.msp [26/03/2018 18:16:24] - [5918720] - (.().-. - ()) - C:\WINDOWS\Installer\6214c.msp [26/03/2018 18:15:46] - [761856] - (.().-. - ()) - C:\WINDOWS\Installer\62154.msp [17/02/2017 23:02:01] - [77639680] - (.().-. - ()) - C:\WINDOWS\Installer\62175.msp [20/07/2017 11:43:32] - [13115392] - (.().-. - ()) - C:\WINDOWS\Installer\67f2f.msp [23/02/2018 14:25:19] - [1343488] - (.().-. - ()) - C:\WINDOWS\Installer\6a1620b.msp [13/11/2019 12:16:36] - [1527808] - (.().-. - ()) - C:\WINDOWS\Installer\6e21d27.msp [05/05/2016 20:34:47] - [53338112] - (.().-. - ()) - C:\WINDOWS\Installer\71a246.msp [14/12/2017 15:32:40] - [10469376] - (.().-. - ()) - C:\WINDOWS\Installer\72877.msp [14/12/2017 15:35:44] - [11165696] - (.().-. - ()) - C:\WINDOWS\Installer\7288c.msp [14/12/2017 15:34:48] - [16977920] - (.().-. - ()) - C:\WINDOWS\Installer\728a0.msp [14/12/2017 15:36:22] - [9699328] - (.().-. - ()) - C:\WINDOWS\Installer\728b4.msp [14/12/2017 15:49:20] - [4337664] - (.().-. - ()) - C:\WINDOWS\Installer\728c8.msp [14/12/2017 15:50:44] - [102400] - (.().-. - ()) - C:\WINDOWS\Installer\728d4.msp [19/12/2017 21:58:10] - [9076224] - (.().-. - ()) - C:\WINDOWS\Installer\728d6.msp [14/12/2017 15:35:16] - [12849152] - (.().-. - ()) - C:\WINDOWS\Installer\728ee.msp [08/10/2018 12:11:44] - [2174976] - (.().-. - ()) - C:\WINDOWS\Installer\7c3c757.msp [11/08/2017 11:04:59] - [2031616] - (.().-. - ()) - C:\WINDOWS\Installer\834ac.msp [10/12/2018 07:52:51] - [44044288] - (.().-. - ()) - C:\WINDOWS\Installer\8cf1df1.msp [03/09/2017 01:09:12] - [12152832] - (.().-. - ()) - C:\WINDOWS\Installer\8f0da.msp [03/09/2017 00:58:32] - [10063872] - (.().-. - ()) - C:\WINDOWS\Installer\93dbb1.msp [25/08/2017 11:21:18] - [5895168] - (.().-. - ()) - C:\WINDOWS\Installer\93dbb9.msp [27/08/2017 10:25:28] - [638976] - (.().-. - ()) - C:\WINDOWS\Installer\93dbc1.msp [05/09/2017 17:21:32] - [17059840] - (.().-. - ()) - C:\WINDOWS\Installer\93dbd5.msp [03/09/2017 01:12:06] - [9691136] - (.().-. - ()) - C:\WINDOWS\Installer\93dbe9.msp [03/09/2017 01:08:26] - [9703424] - (.().-. - ()) - C:\WINDOWS\Installer\93dbfd.msp [03/09/2017 01:09:52] - [5218304] - (.().-. - ()) - C:\WINDOWS\Installer\93dc12.msp [03/09/2017 01:10:26] - [4997120] - (.().-. - ()) - C:\WINDOWS\Installer\93dc28.msp [03/09/2017 01:07:04] - [1142784] - (.().-. - ()) - C:\WINDOWS\Installer\93dc31.msp [05/09/2017 17:24:04] - [8134656] - (.().-. - ()) - C:\WINDOWS\Installer\93dc45.msp [04/09/2017 13:07:34] - [9108480] - (.().-. - ()) - C:\WINDOWS\Installer\93dc4d.msp [14/03/2019 10:49:28] - [8896512] - (.().-. - ()) - C:\WINDOWS\Installer\9a7f1.msp [15/01/2014 10:26:12] - [9456640] - (.().-. - ()) - C:\WINDOWS\Installer\9a9e9a.msp [20/02/2014 09:23:06] - [5006848] - (.().-. - ()) - C:\WINDOWS\Installer\9a9ebc.msp [04/09/2015 22:34:00] - [8987648] - (.().-. - ()) - C:\WINDOWS\Installer\9ae2c.msp [04/09/2015 22:32:46] - [5976064] - (.().-. - ()) - C:\WINDOWS\Installer\9ae34.msp [16/09/2015 20:29:04] - [9687040] - (.().-. - ()) - C:\WINDOWS\Installer\9ae48.msp [02/10/2015 20:33:12] - [16429056] - (.().-. - ()) - C:\WINDOWS\Installer\9ae5c.msp [16/09/2015 20:23:46] - [10035200] - (.().-. - ()) - C:\WINDOWS\Installer\9ae70.msp [16/09/2015 20:26:46] - [4984832] - (.().-. - ()) - C:\WINDOWS\Installer\9ae83.msp [23/09/2015 09:48:26] - [7851008] - (.().-. - ()) - C:\WINDOWS\Installer\9ae8b.msp [30/11/2018 13:32:46] - [2023424] - (.().-. - ()) - C:\WINDOWS\Installer\9ddd2be.msp [03/06/2017 19:26:12] - [4337664] - (.().-. - ()) - C:\WINDOWS\Installer\a0cf2.msp [03/06/2017 19:23:08] - [17035264] - (.().-. - ()) - C:\WINDOWS\Installer\a0d06.msp [09/05/2017 13:34:04] - [9809920] - (.().-. - ()) - C:\WINDOWS\Installer\a0d1a.msp [09/05/2017 13:35:10] - [1126400] - (.().-. - ()) - C:\WINDOWS\Installer\a0d22.msp [03/06/2017 19:25:10] - [8134656] - (.().-. - ()) - C:\WINDOWS\Installer\a0d36.msp [03/06/2017 19:25:46] - [11177984] - (.().-. - ()) - C:\WINDOWS\Installer\a0d4b.msp [05/06/2017 14:00:54] - [637952] - (.().-. - ()) - C:\WINDOWS\Installer\a0d53.msp [05/06/2017 13:53:32] - [8860672] - (.().-. - ()) - C:\WINDOWS\Installer\a0d5b.msp [03/06/2017 19:24:38] - [5312512] - (.().-. - ()) - C:\WINDOWS\Installer\a0d6f.msp [20/06/2017 07:59:37] - [53350400] - (.().-. - ()) - C:\WINDOWS\Installer\a0d7e.msp [26/06/2018 11:38:18] - [761856] - (.().-. - ()) - C:\WINDOWS\Installer\a191b8f.msp [17/05/2016 16:56:42] - [2978304] - (.().-. - ()) - C:\WINDOWS\Installer\a528bac.msp [19/05/2016 03:10:58] - [4988928] - (.().-. - ()) - C:\WINDOWS\Installer\a528bc5.msp [19/05/2016 03:14:28] - [4030464] - (.().-. - ()) - C:\WINDOWS\Installer\a528bda.msp [19/05/2016 03:10:16] - [10465280] - (.().-. - ()) - C:\WINDOWS\Installer\a528bee.msp [19/05/2016 03:19:50] - [9699328] - (.().-. - ()) - C:\WINDOWS\Installer\a528c02.msp [19/05/2016 03:19:22] - [4337664] - (.().-. - ()) - C:\WINDOWS\Installer\a528c16.msp [19/05/2016 03:18:12] - [10534912] - (.().-. - ()) - C:\WINDOWS\Installer\a528c2b.msp [15/11/2016 22:18:50] - [4337664] - (.().-. - ()) - C:\WINDOWS\Installer\a5626cd.msp [16/11/2016 09:17:48] - [638464] - (.().-. - ()) - C:\WINDOWS\Installer\a5626d5.msp [15/11/2016 22:17:40] - [8134656] - (.().-. - ()) - C:\WINDOWS\Installer\a5626e9.msp [15/11/2016 22:18:24] - [11169792] - (.().-. - ()) - C:\WINDOWS\Installer\a5626fe.msp [14/10/2014 09:25:02] - [4980736] - (.().-. - ()) - C:\WINDOWS\Installer\a5a3541.msp [07/10/2014 16:44:32] - [4333568] - (.().-. - ()) - C:\WINDOWS\Installer\a5a3555.msp [07/10/2014 16:44:08] - [11153408] - (.().-. - ()) - C:\WINDOWS\Installer\a5a356a.msp [29/10/2014 07:00:18] - [4931584] - (.().-. - ()) - C:\WINDOWS\Installer\a5a357e.msp [15/10/2014 20:12:06] - [5946880] - (.().-. - ()) - C:\WINDOWS\Installer\a5a3586.msp [19/11/2014 08:45:32] - [11059200] - (.().-. - ()) - C:\WINDOWS\Installer\a7d6f.msp [05/11/2014 19:55:34] - [745984] - (.().-. - ()) - C:\WINDOWS\Installer\a7d77.msp [25/11/2014 10:16:04] - [11124736] - (.().-. - ()) - C:\WINDOWS\Installer\a7d8c.msp [12/11/2014 20:12:46] - [10436608] - (.().-. - ()) - C:\WINDOWS\Installer\a7da0.msp [25/11/2014 07:01:14] - [9079296] - (.().-. - ()) - C:\WINDOWS\Installer\a7da8.msp [25/11/2014 10:17:26] - [9691136] - (.().-. - ()) - C:\WINDOWS\Installer\a7dbc.msp [12/11/2014 05:23:48] - [1054720] - (.().-. - ()) - C:\WINDOWS\Installer\a7dc4.msp [25/11/2014 10:15:40] - [4984832] - (.().-. - ()) - C:\WINDOWS\Installer\a7dd8.msp [25/11/2014 10:15:34] - [4333568] - (.().-. - ()) - C:\WINDOWS\Installer\a7dec.msp [26/10/2017 14:22:16] - [10547200] - (.().-. - ()) - C:\WINDOWS\Installer\a951e.msp [26/10/2017 14:22:16] - [4341760] - (.().-. - ()) - C:\WINDOWS\Installer\a9532.msp [26/10/2017 14:22:14] - [9691136] - (.().-. - ()) - C:\WINDOWS\Installer\a9546.msp [26/10/2017 14:21:36] - [10465280] - (.().-. - ()) - C:\WINDOWS\Installer\a955a.msp [14/01/2015 22:36:26] - [4333568] - (.().-. - ()) - C:\WINDOWS\Installer\a99c50b.msp [13/01/2015 15:16:20] - [8894464] - (.().-. - ()) - C:\WINDOWS\Installer\a99c513.msp [05/12/2014 05:42:54] - [5876736] - (.().-. - ()) - C:\WINDOWS\Installer\a99c51b.msp [14/01/2015 22:34:40] - [10444800] - (.().-. - ()) - C:\WINDOWS\Installer\a99c52f.msp [14/01/2015 22:35:00] - [2576384] - (.().-. - ()) - C:\WINDOWS\Installer\a99c545.msp [14/01/2015 22:35:04] - [10158080] - (.().-. - ()) - C:\WINDOWS\Installer\a99c55c.msp [14/01/2015 22:35:00] - [11120640] - (.().-. - ()) - C:\WINDOWS\Installer\a99c578.msp [14/01/2015 22:34:58] - [4980736] - (.().-. - ()) - C:\WINDOWS\Installer\a99c58c.msp [14/01/2015 22:36:46] - [9691136] - (.().-. - ()) - C:\WINDOWS\Installer\a99c5a0.msp [13/09/2018 19:25:16] - [9035776] - (.().-. - ()) - C:\WINDOWS\Installer\ae6a227.msp [13/09/2018 19:24:58] - [5918720] - (.().-. - ()) - C:\WINDOWS\Installer\ae6a22f.msp [15/06/2016 22:57:14] - [4984832] - (.().-. - ()) - C:\WINDOWS\Installer\b772a0c.msp [15/06/2016 23:18:16] - [9699328] - (.().-. - ()) - C:\WINDOWS\Installer\b772a20.msp [01/07/2016 07:32:08] - [11137024] - (.().-. - ()) - C:\WINDOWS\Installer\b772a35.msp [15/06/2016 22:27:32] - [10461184] - (.().-. - ()) - C:\WINDOWS\Installer\b772a49.msp [01/07/2016 07:32:56] - [4341760] - (.().-. - ()) - C:\WINDOWS\Installer\b772a5d.msp [12/05/2018 07:05:37] - [7094272] - (.().-. - ()) - C:\WINDOWS\Installer\ba1d9.msp [18/09/2018 09:10:59] - [4706304] - (.().-. - ()) - C:\WINDOWS\Installer\bbe05.msp [09/07/2018 06:47:48] - [27000832] - (.().-. - ()) - C:\WINDOWS\Installer\bd18a.msp [30/07/2018 15:13:26] - [9052160] - (.().-. - ()) - C:\WINDOWS\Installer\c6ba6af.msp [29/11/2017 11:42:28] - [1355776] - (.().-. - ()) - C:\WINDOWS\Installer\cbcb77.msp [17/10/2019 10:30:59] - [2490368] - (.().-. - ()) - C:\WINDOWS\Installer\cbdcff.msp [22/08/2019 12:14:18] - [2002944] - (.().-. - ()) - C:\WINDOWS\Installer\cc015f.msp [16/11/2017 03:34:24] - [10555392] - (.().-. - ()) - C:\WINDOWS\Installer\cf8ef.msp [20/10/2012 23:32:14] - [9590272] - (.().-. - ()) - C:\WINDOWS\Installer\d87c5d.msp [25/07/2012 16:57:08] - [2532864] - (.().-. - ()) - C:\WINDOWS\Installer\d87c71.msp [23/01/2013 18:05:40] - [9765376] - (.().-. - ()) - C:\WINDOWS\Installer\d87c78.msp [25/09/2012 12:39:54] - [1794560] - (.().-. - ()) - C:\WINDOWS\Installer\d87c82.msp [25/09/2012 12:38:52] - [11885568] - (.().-. - ()) - C:\WINDOWS\Installer\d87cb3.msp [20/10/2012 23:32:14] - [2830848] - (.().-. - ()) - C:\WINDOWS\Installer\d87cc7.msp [18/07/2012 15:53:36] - [10937344] - (.().-. - ()) - C:\WINDOWS\Installer\d87cdb.msp [01/11/2013 18:17:42] - [5009920] - (.().-. - ()) - C:\WINDOWS\Installer\d87cef.msp [17/02/2012 08:45:24] - [2299392] - (.().-. - ()) - C:\WINDOWS\Installer\d87d02.msp [18/11/2013 06:05:00] - [5006336] - (.().-. - ()) - C:\WINDOWS\Installer\d87d16.msp [15/09/2011 18:34:14] - [8499712] - (.().-. - ()) - C:\WINDOWS\Installer\d87df3.msp [01/11/2011 13:34:30] - [2531840] - (.().-. - ()) - C:\WINDOWS\Installer\d87e07.msp [15/03/2012 02:24:28] - [1795584] - (.().-. - ()) - C:\WINDOWS\Installer\d87e1b.msp [01/11/2011 13:34:58] - [4225536] - (.().-. - ()) - C:\WINDOWS\Installer\d87e34.msp [26/10/2011 23:23:32] - [8821760] - (.().-. - ()) - C:\WINDOWS\Installer\d87e3e.msp [26/10/2011 23:22:30] - [1071616] - (.().-. - ()) - C:\WINDOWS\Installer\d87e3f.msp [25/09/2012 12:35:18] - [9101824] - (.().-. - ()) - C:\WINDOWS\Installer\d87e53.msp [27/06/2013 22:13:14] - [40314880] - (.().-. - ()) - C:\WINDOWS\Installer\d87e69.msp [25/09/2012 12:35:46] - [4285952] - (.().-. - ()) - C:\WINDOWS\Installer\d87e7d.msp [18/07/2012 15:46:48] - [593408] - (.().-. - ()) - C:\WINDOWS\Installer\d87e91.msp [01/11/2011 13:34:26] - [1169920] - (.().-. - ()) - C:\WINDOWS\Installer\d87ea5.msp [01/11/2011 13:34:28] - [2247168] - (.().-. - ()) - C:\WINDOWS\Installer\d87eb9.msp [14/04/2009 04:56:48] - [10826752] - (.().-. - ()) - C:\WINDOWS\Installer\d87ec0.msp [04/04/2012 22:38:16] - [3620864] - (.().-. - ()) - C:\WINDOWS\Installer\d87ed4.msp [25/07/2012 16:59:06] - [11032064] - (.().-. - ()) - C:\WINDOWS\Installer\d87ee7.msp [25/02/2009 19:08:18] - [8311808] - (.().-. - ()) - C:\WINDOWS\Installer\d87efa.msp [07/05/2009 09:04:18] - [10289664] - (.().-. - ()) - C:\WINDOWS\Installer\d87f01.msp [25/09/2012 12:35:30] - [7695360] - (.().-. - ()) - C:\WINDOWS\Installer\d87f15.msp [14/04/2009 03:46:40] - [7391744] - (.().-. - ()) - C:\WINDOWS\Installer\d87f1c.msp [25/07/2012 16:57:06] - [3157504] - (.().-. - ()) - C:\WINDOWS\Installer\d87f33.msp [25/09/2012 12:36:20] - [8465408] - (.().-. - ()) - C:\WINDOWS\Installer\d87f47.msp [21/07/2011 12:34:34] - [3456000] - (.().-. - ()) - C:\WINDOWS\Installer\d87f51.msp [14/04/2009 04:22:04] - [7532544] - (.().-. - ()) - C:\WINDOWS\Installer\d87f57.msp [19/06/2012 12:54:40] - [2239488] - (.().-. - ()) - C:\WINDOWS\Installer\d87f6b.msp [17/11/2012 09:36:10] - [3865600] - (.().-. - ()) - C:\WINDOWS\Installer\d87f73.msp [22/10/2013 06:10:14] - [1111552] - (.().-. - ()) - C:\WINDOWS\Installer\d87f8f.msp [01/11/2011 13:34:56] - [4250112] - (.().-. - ()) - C:\WINDOWS\Installer\d87fa3.msp [26/06/2016 14:03:14] - [53339648] - (.().-. - ()) - C:\WINDOWS\Installer\dad74.msp [15/04/2015 11:18:14] - [9088512] - (.().-. - ()) - C:\WINDOWS\Installer\ddd3202.msp [01/04/2015 11:30:34] - [5764096] - (.().-. - ()) - C:\WINDOWS\Installer\ddd320a.msp [14/04/2015 07:53:02] - [4984832] - (.().-. - ()) - C:\WINDOWS\Installer\ddd321e.msp [10/03/2015 10:26:44] - [9801728] - (.().-. - ()) - C:\WINDOWS\Installer\ddd3232.msp [15/04/2015 11:18:14] - [8030208] - (.().-. - ()) - C:\WINDOWS\Installer\ddd323a.msp [14/04/2015 07:53:04] - [15880192] - (.().-. - ()) - C:\WINDOWS\Installer\ddd324e.msp [15/04/2015 11:18:52] - [5877248] - (.().-. - ()) - C:\WINDOWS\Installer\ddd3256.msp [18/12/2013 18:07:16] - [9454592] - (.().-. - ()) - C:\WINDOWS\Installer\de8a0e.msp [17/05/2018 11:40:20] - [7991296] - (.().-. - ()) - C:\WINDOWS\Installer\e07e0e.msp [18/06/2014 04:15:58] - [5001728] - (.().-. - ()) - C:\WINDOWS\Installer\e9cfd1f.msp [11/06/2014 16:25:04] - [8407552] - (.().-. - ()) - C:\WINDOWS\Installer\e9cfd27.msp [11/06/2014 16:25:16] - [9457152] - (.().-. - ()) - C:\WINDOWS\Installer\e9cfd2f.msp [22/06/2017 04:41:28] - [10461184] - (.().-. - ()) - C:\WINDOWS\Installer\eed8a.msp [22/06/2017 04:41:40] - [9695232] - (.().-. - ()) - C:\WINDOWS\Installer\eed9e.msp [03/07/2017 15:22:36] - [16998400] - (.().-. - ()) - C:\WINDOWS\Installer\eedb2.msp [05/07/2017 14:37:52] - [9083904] - (.().-. - ()) - C:\WINDOWS\Installer\eedba.msp [13/07/2016 00:07:32] - [13078528] - (.().-. - ()) - C:\WINDOWS\Installer\ffc3905.msp [13/07/2016 00:04:54] - [1126400] - (.().-. - ()) - C:\WINDOWS\Installer\ffc390d.msp [29/06/2016 02:24:56] - [9805824] - (.().-. - ()) - C:\WINDOWS\Installer\ffc3921.msp [12/07/2016 20:22:26] - [8464384] - (.().-. - ()) - C:\WINDOWS\Installer\ffc3929.msp [21/07/2016 04:24:44] - [4337664] - (.().-. - ()) - C:\WINDOWS\Installer\ffc393d.msp [21/07/2016 04:15:16] - [16433152] - (.().-. - ()) - C:\WINDOWS\Installer\ffc3951.msp [21/07/2016 04:18:58] - [11169792] - (.().-. - ()) - C:\WINDOWS\Installer\ffc3966.msp ---------- | %System%\*.in* [19/03/2019 05:45:40] - [3329] - C:\WINDOWS\System32\ieuinit.inf [26/09/2019 21:13:32] - [284] - C:\WINDOWS\System32\InstallUtil.InstallLog [22/08/2013 13:36:58] - [1490] - C:\WINDOWS\System32\LXAA3FactoryPresets.ini [22/08/2013 13:37:07] - [466] - C:\WINDOWS\System32\LXAA3ScabConfig.ini [07/08/2019 15:51:05] - [1773290] - C:\WINDOWS\System32\PerfStringBackup.INI [19/03/2019 05:45:00] - [60124] - C:\WINDOWS\System32\tcpmon.ini [19/03/2019 05:44:30] - [2404] - C:\WINDOWS\System32\WimBootCompress.ini [04/06/2014 14:41:10] - [2278] - C:\WINDOWS\Syswow64\Cam122.ini [19/03/2019 05:46:01] - [3329] - C:\WINDOWS\Syswow64\ieuinit.inf [30/01/2014 17:38:46] - [1766590] - C:\WINDOWS\Syswow64\PerfStringBackup.INI [19/03/2019 05:45:19] - [2404] - C:\WINDOWS\Syswow64\WimBootCompress.ini ---------- | Listing no Microsoft signed files (Not necessary Malwares) | system32 | Syswow64 | General scan [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:44] - [0 Ko] - C:\WINDOWS\AppPatch\Custom\Custom64 [MD5.00000000000000000000000000000000] - |D| - [18/11/2019 18:54:21] - [0.71 Ko] - C:\WINDOWS\Temp\avast_ash2 [MD5.00000000000000000000000000000000] - |D| - [11/12/2019 17:35:14] - [0 Ko] - C:\WINDOWS\Temp\C3B7845B-1F9D-4513-9197-509BFD9350A8-Sigs [MD5.641626FC729CB1250AEB415F8E0BDAAF] - |A| - [11/12/2019 17:01:56] - (.-.) - [17.92 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\chrome_installer.log [MD5.00000000000000000000000000000000] - |D| - [11/12/2019 17:01:56] - [0.04 Ko] - C:\WINDOWS\Temp\Crashpad [MD5.00000000000000000000000000000000] - |D| - [11/12/2019 17:01:56] - [2274.59 Ko] - C:\WINDOWS\Temp\CR_16EF2.tmp [MD5.00000000000000000000000000000000] - |D| - [17/12/2019 08:39:17] - [0 Ko] - C:\WINDOWS\Temp\DiagTrack_alternativeTrace [MD5.00000000000000000000000000000000] - |D| - [17/12/2019 08:39:17] - [0 Ko] - C:\WINDOWS\Temp\DiagTrack_aot [MD5.00000000000000000000000000000000] - |D| - [17/12/2019 08:39:17] - [0 Ko] - C:\WINDOWS\Temp\DiagTrack_diag [MD5.00000000000000000000000000000000] - |D| - [17/12/2019 08:39:17] - [0 Ko] - C:\WINDOWS\Temp\DiagTrack_miniTrace [MD5.558A5C77250F05DCFA27B434EACAA6A2] - |A| - [12/12/2019 13:45:15] - (.-.) - [4.29 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\lpksetup-20191212-134515-0.log [MD5.714E3177E6246C0DCC8AFD258249B3EB] - |A| - [15/12/2019 08:40:00] - (.-.) - [4.29 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\lpksetup-20191215-084000-0.log [MD5.E4CADA090FD4EE9DF965173BAED431EC] - |A| - [16/12/2019 11:51:29] - (.-.) - [4.29 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\lpksetup-20191216-115129-0.log [MD5.AEF396A62707075AB7B0D95938E31354] - |A| - [16/12/2019 12:00:17] - (.-.) - [4.29 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\lpksetup-20191216-120017-0.log [MD5.3D4B372D46CC222E0912ED5C7007B255] - |A| - [17/12/2019 08:39:31] - (.-.) - [4.29 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\lpksetup-20191217-083931-0.log [MD5.A1899AFD8098F410E38417D286CB60AF] - |A| - [11/12/2019 17:32:37] - (.-.) - [46.74 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MpCmdRun.log [MD5.F41E64A018C8672F00F92A6117E3AE3C] - |A| - [11/12/2019 17:35:14] - (.-.) - [64.15 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MpSigStub.log [MD5.EBF433A684927239BED7E92483FCE3C3] - |A| - [12/12/2019 13:45:04] - (.-.) - [3.92 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\print.xml [MD5.5591A23B3244A26B6CEF6EFB61E09A07] - |A| - [07/08/2019 15:48:58] - (.-.) - [10.24 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\spdsvc.exe.log [MD5.00000000000000000000000000000000] - |D| - [12/12/2019 14:30:37] - [0 Ko] - C:\WINDOWS\Temp\tw-12f0-25dc-2a7bc9.tmp [MD5.00000000000000000000000000000000] - |D| - [12/12/2019 14:30:37] - [0 Ko] - C:\WINDOWS\Temp\tw-12f0-25dc-2a7bcb.tmp [MD5.00000000000000000000000000000000] - |D| - [12/12/2019 14:30:37] - [0 Ko] - C:\WINDOWS\Temp\tw-12f0-25dc-2a7bcd.tmp [MD5.00000000000000000000000000000000] - |D| - [12/12/2019 14:30:37] - [0 Ko] - C:\WINDOWS\Temp\tw-12f0-25dc-2a7bcf.tmp [MD5.00000000000000000000000000000000] - |D| - [12/12/2019 14:30:37] - [0 Ko] - C:\WINDOWS\Temp\tw-12f0-25dc-2a7be0.tmp [MD5.00000000000000000000000000000000] - |D| - [12/12/2019 14:30:37] - [0 Ko] - C:\WINDOWS\Temp\tw-12f0-25dc-2a7be2.tmp [MD5.00000000000000000000000000000000] - |D| - [12/12/2019 14:30:37] - [0 Ko] - C:\WINDOWS\Temp\tw-12f0-25dc-2a7be4.tmp [MD5.00000000000000000000000000000000] - |D| - [12/12/2019 14:30:37] - [0 Ko] - C:\WINDOWS\Temp\tw-12f0-25dc-2a7bf6.tmp [MD5.00000000000000000000000000000000] - |D| - [12/12/2019 14:30:37] - [0 Ko] - C:\WINDOWS\Temp\tw-12f0-25dc-2a7bf8.tmp [MD5.00000000000000000000000000000000] - |D| - [12/12/2019 14:30:37] - [0 Ko] - C:\WINDOWS\Temp\tw-12f0-25dc-2a7bfa.tmp [MD5.00000000000000000000000000000000] - |D| - [12/12/2019 14:30:37] - [0 Ko] - C:\WINDOWS\Temp\tw-12f0-25dc-2a7bfc.tmp [MD5.00000000000000000000000000000000] - |D| - [12/12/2019 14:30:37] - [0 Ko] - C:\WINDOWS\Temp\tw-12f0-25dc-2a7bfe.tmp [MD5.00000000000000000000000000000000] - |D| - [12/12/2019 14:30:37] - [0 Ko] - C:\WINDOWS\Temp\tw-12f0-25dc-2a7c0f.tmp [MD5.00000000000000000000000000000000] - |D| - [12/12/2019 14:30:37] - [0 Ko] - C:\WINDOWS\Temp\tw-12f0-25dc-2a7c11.tmp [MD5.00000000000000000000000000000000] - |D| - [12/12/2019 14:30:37] - [0 Ko] - C:\WINDOWS\Temp\tw-12f0-25dc-2a7c13.tmp [MD5.00000000000000000000000000000000] - |D| - [12/12/2019 14:30:37] - [0 Ko] - C:\WINDOWS\Temp\tw-12f0-25dc-2a7c25.tmp [MD5.00000000000000000000000000000000] - |D| - [12/12/2019 14:30:37] - [0 Ko] - C:\WINDOWS\Temp\tw-12f0-25dc-2a7c27.tmp [MD5.00000000000000000000000000000000] - |D| - [12/12/2019 14:30:37] - [0 Ko] - C:\WINDOWS\Temp\tw-12f0-25dc-2a7c29.tmp [MD5.00000000000000000000000000000000] - |D| - [12/12/2019 14:30:37] - [0 Ko] - C:\WINDOWS\Temp\tw-12f0-25dc-2a7c2b.tmp [MD5.00000000000000000000000000000000] - |D| - [15/12/2019 09:08:25] - [0 Ko] - C:\WINDOWS\Temp\tw-2858-2e50-1aeadc.tmp [MD5.00000000000000000000000000000000] - |D| - [15/12/2019 09:08:25] - [0 Ko] - C:\WINDOWS\Temp\tw-2858-2e50-1aeb7a.tmp [MD5.00000000000000000000000000000000] - |D| - [15/12/2019 09:08:25] - [0 Ko] - C:\WINDOWS\Temp\tw-2858-2e50-1aebab.tmp [MD5.00000000000000000000000000000000] - |D| - [15/12/2019 09:08:25] - [0 Ko] - C:\WINDOWS\Temp\tw-2858-2e50-1aebfb.tmp [MD5.00000000000000000000000000000000] - |D| - [15/12/2019 09:08:25] - [0 Ko] - C:\WINDOWS\Temp\tw-2858-2e50-1aec3c.tmp [MD5.00000000000000000000000000000000] - |D| - [15/12/2019 09:08:25] - [0 Ko] - C:\WINDOWS\Temp\tw-2858-2e50-1aec6d.tmp [MD5.00000000000000000000000000000000] - |D| - [15/12/2019 09:08:25] - [0 Ko] - C:\WINDOWS\Temp\tw-2858-2e50-1aec7e.tmp [MD5.00000000000000000000000000000000] - |D| - [15/12/2019 09:08:25] - [0 Ko] - C:\WINDOWS\Temp\tw-2858-2e50-1aec90.tmp [MD5.00000000000000000000000000000000] - |D| - [15/12/2019 09:08:25] - [0 Ko] - C:\WINDOWS\Temp\tw-2858-2e50-1aeca1.tmp [MD5.00000000000000000000000000000000] - |D| - [15/12/2019 09:08:25] - [0 Ko] - C:\WINDOWS\Temp\tw-2858-2e50-1aecb3.tmp [MD5.00000000000000000000000000000000] - |D| - [15/12/2019 09:08:25] - [0 Ko] - C:\WINDOWS\Temp\tw-2858-2e50-1aecc5.tmp [MD5.00000000000000000000000000000000] - |D| - [15/12/2019 09:08:25] - [0 Ko] - C:\WINDOWS\Temp\tw-2858-2e50-1aecd6.tmp [MD5.00000000000000000000000000000000] - |D| - [15/12/2019 09:08:25] - [0 Ko] - C:\WINDOWS\Temp\tw-2858-2e50-1aed07.tmp [MD5.00000000000000000000000000000000] - |D| - [15/12/2019 09:08:25] - [0 Ko] - C:\WINDOWS\Temp\tw-2858-2e50-1aed28.tmp [MD5.00000000000000000000000000000000] - |D| - [15/12/2019 09:08:25] - [0 Ko] - C:\WINDOWS\Temp\tw-2858-2e50-1aed3a.tmp [MD5.00000000000000000000000000000000] - |D| - [15/12/2019 09:08:25] - [0 Ko] - C:\WINDOWS\Temp\tw-2858-2e50-1aed5b.tmp [MD5.00000000000000000000000000000000] - |D| - [15/12/2019 09:08:25] - [0 Ko] - C:\WINDOWS\Temp\tw-2858-2e50-1aed5d.tmp [MD5.00000000000000000000000000000000] - |D| - [15/12/2019 09:08:25] - [0 Ko] - C:\WINDOWS\Temp\tw-2858-2e50-1aed8e.tmp [MD5.00000000000000000000000000000000] - |D| - [15/12/2019 09:08:26] - [0 Ko] - C:\WINDOWS\Temp\tw-2858-2e50-1aed90.tmp [MD5.00000000000000000000000000000000] - |D| - [11/12/2019 09:17:00] - [0 Ko] - C:\WINDOWS\Temp\tw-3e90-35a0-5766a50.tmp [MD5.00000000000000000000000000000000] - |D| - [11/12/2019 09:17:00] - [0 Ko] - C:\WINDOWS\Temp\tw-3e90-35a0-5766a52.tmp [MD5.00000000000000000000000000000000] - |D| - [11/12/2019 09:17:00] - [0 Ko] - C:\WINDOWS\Temp\tw-3e90-35a0-5766a64.tmp [MD5.00000000000000000000000000000000] - |D| - [11/12/2019 09:17:00] - [0 Ko] - C:\WINDOWS\Temp\tw-3e90-35a0-5766a66.tmp [MD5.00000000000000000000000000000000] - |D| - [11/12/2019 09:17:00] - [0 Ko] - C:\WINDOWS\Temp\tw-3e90-35a0-5766a68.tmp [MD5.00000000000000000000000000000000] - |D| - [11/12/2019 09:17:00] - [0 Ko] - C:\WINDOWS\Temp\tw-3e90-35a0-5766a6a.tmp [MD5.00000000000000000000000000000000] - |D| - [11/12/2019 09:17:00] - [0 Ko] - C:\WINDOWS\Temp\tw-3e90-35a0-5766a6c.tmp [MD5.00000000000000000000000000000000] - |D| - [11/12/2019 09:17:00] - [0 Ko] - C:\WINDOWS\Temp\tw-3e90-35a0-5766a6e.tmp [MD5.00000000000000000000000000000000] - |D| - [11/12/2019 09:17:00] - [0 Ko] - C:\WINDOWS\Temp\tw-3e90-35a0-5766a80.tmp [MD5.00000000000000000000000000000000] - |D| - [11/12/2019 09:17:00] - [0 Ko] - C:\WINDOWS\Temp\tw-3e90-35a0-5766a82.tmp [MD5.00000000000000000000000000000000] - |D| - [11/12/2019 09:17:00] - [0 Ko] - C:\WINDOWS\Temp\tw-3e90-35a0-5766a84.tmp [MD5.00000000000000000000000000000000] - |D| - [11/12/2019 09:17:00] - [0 Ko] - C:\WINDOWS\Temp\tw-3e90-35a0-5766a95.tmp [MD5.00000000000000000000000000000000] - |D| - [11/12/2019 09:17:00] - [0 Ko] - C:\WINDOWS\Temp\tw-3e90-35a0-5766a97.tmp [MD5.00000000000000000000000000000000] - |D| - [11/12/2019 09:17:00] - [0 Ko] - C:\WINDOWS\Temp\tw-3e90-35a0-5766a99.tmp [MD5.00000000000000000000000000000000] - |D| - [11/12/2019 09:17:00] - [0 Ko] - C:\WINDOWS\Temp\tw-3e90-35a0-5766aab.tmp [MD5.00000000000000000000000000000000] - |D| - [11/12/2019 09:17:00] - [0 Ko] - C:\WINDOWS\Temp\tw-3e90-35a0-5766aad.tmp [MD5.00000000000000000000000000000000] - |D| - [11/12/2019 09:17:00] - [0 Ko] - C:\WINDOWS\Temp\tw-3e90-35a0-5766aaf.tmp [MD5.00000000000000000000000000000000] - |D| - [11/12/2019 09:17:00] - [0 Ko] - C:\WINDOWS\Temp\tw-3e90-35a0-5766ab1.tmp [MD5.00000000000000000000000000000000] - |D| - [11/12/2019 09:17:00] - [0 Ko] - C:\WINDOWS\Temp\tw-3e90-35a0-5766ab3.tmp [MD5.00000000000000000000000000000000] - |D| - [17/12/2019 08:49:19] - [0 Ko] - C:\WINDOWS\Temp\tw-ff0-1298-9c8b1.tmp [MD5.00000000000000000000000000000000] - |D| - [17/12/2019 08:49:19] - [0 Ko] - C:\WINDOWS\Temp\tw-ff0-1298-9c8b3.tmp [MD5.00000000000000000000000000000000] - |D| - [17/12/2019 08:49:19] - [0 Ko] - C:\WINDOWS\Temp\tw-ff0-1298-9c8b5.tmp [MD5.00000000000000000000000000000000] - |D| - [17/12/2019 08:49:19] - [0 Ko] - C:\WINDOWS\Temp\tw-ff0-1298-9c8c6.tmp [MD5.00000000000000000000000000000000] - |D| - [17/12/2019 08:49:19] - [0 Ko] - C:\WINDOWS\Temp\tw-ff0-1298-9c8c8.tmp [MD5.00000000000000000000000000000000] - |D| - [17/12/2019 08:49:19] - [0 Ko] - C:\WINDOWS\Temp\tw-ff0-1298-9c8ca.tmp [MD5.00000000000000000000000000000000] - |D| - [17/12/2019 08:49:19] - [0 Ko] - C:\WINDOWS\Temp\tw-ff0-1298-9c8cc.tmp [MD5.00000000000000000000000000000000] - |D| - [17/12/2019 08:49:19] - [0 Ko] - C:\WINDOWS\Temp\tw-ff0-1298-9c8de.tmp [MD5.00000000000000000000000000000000] - |D| - [17/12/2019 08:49:19] - [0 Ko] - C:\WINDOWS\Temp\tw-ff0-1298-9c8e0.tmp [MD5.00000000000000000000000000000000] - |D| - [17/12/2019 08:49:19] - [0 Ko] - C:\WINDOWS\Temp\tw-ff0-1298-9c8e2.tmp [MD5.00000000000000000000000000000000] - |D| - [17/12/2019 08:49:19] - [0 Ko] - C:\WINDOWS\Temp\tw-ff0-1298-9c8e4.tmp [MD5.00000000000000000000000000000000] - |D| - [17/12/2019 08:49:19] - [0 Ko] - C:\WINDOWS\Temp\tw-ff0-1298-9c8f5.tmp [MD5.00000000000000000000000000000000] - |D| - [17/12/2019 08:49:19] - [0 Ko] - C:\WINDOWS\Temp\tw-ff0-1298-9c8f7.tmp [MD5.00000000000000000000000000000000] - |D| - [17/12/2019 08:49:19] - [0 Ko] - C:\WINDOWS\Temp\tw-ff0-1298-9c8f9.tmp [MD5.00000000000000000000000000000000] - |D| - [17/12/2019 08:49:19] - [0 Ko] - C:\WINDOWS\Temp\tw-ff0-1298-9c8fb.tmp [MD5.00000000000000000000000000000000] - |D| - [17/12/2019 08:49:19] - [0 Ko] - C:\WINDOWS\Temp\tw-ff0-1298-9c91d.tmp [MD5.00000000000000000000000000000000] - |D| - [17/12/2019 08:49:19] - [0 Ko] - C:\WINDOWS\Temp\tw-ff0-1298-9c91f.tmp [MD5.00000000000000000000000000000000] - |D| - [17/12/2019 08:49:19] - [0 Ko] - C:\WINDOWS\Temp\tw-ff0-1298-9c96f.tmp [MD5.00000000000000000000000000000000] - |D| - [17/12/2019 08:49:19] - [0 Ko] - C:\WINDOWS\Temp\tw-ff0-1298-9c980.tmp [MD5.00000000000000000000000000000000] - |D| - [07/08/2019 15:48:57] - [0 Ko] - C:\WINDOWS\Temp\_avast_ [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 13:00:40] - [0 Ko] - C:\WINDOWS\System32\0409 [MD5.C652A5EA6545C98CE71684018E0640E7] - |A| - [19/03/2019 05:44:33] - (.-.) - [3.1 Ko] - (0.0.0.0) - C:\WINDOWS\System32\@AdvancedKeySettingsNotification.png [MD5.D6F8DD9F561B8A67FFAC2BAD7E989770] - |A| - [19/03/2019 05:44:28] - (.-.) - [0.23 Ko] - (0.0.0.0) - C:\WINDOWS\System32\@AppHelpToast.png [MD5.82C37C3E27020AF6C2E018E944284676] - |A| - [19/03/2019 05:44:28] - (.-.) - [0.3 Ko] - (0.0.0.0) - C:\WINDOWS\System32\@AudioToastIcon.png [MD5.8E4B25CC8E98F63DBD54176DFAB539E0] - |A| - [19/03/2019 05:44:03] - (.-.) - [0.44 Ko] - (0.0.0.0) - C:\WINDOWS\System32\@BackgroundAccessToastIcon.png [MD5.3937359E324E15F6A7A7092D4DAEBD64] - |A| - [19/03/2019 05:44:47] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\System32\@bitlockertoastimage.png [MD5.495C1F072039B434827A5FE0D9761E4D] - |A| - [19/03/2019 05:44:47] - (.-.) - [0.32 Ko] - (0.0.0.0) - C:\WINDOWS\System32\@EnrollmentToastIcon.png [MD5.C2A332DE50FE519DA21AFB8BD6E134F4] - |A| - [19/03/2019 05:44:52] - (.-.) - [0.55 Ko] - (0.0.0.0) - C:\WINDOWS\System32\@language_notification_icon.png [MD5.A119D69B4C29845D3F8CE2E5638C8E65] - |A| - [19/03/2019 05:45:47] - (.-.) - [0.47 Ko] - (0.0.0.0) - C:\WINDOWS\System32\@optionalfeatures.png [MD5.1622DE67156496C78D6B7BE9B471645B] - |A| - [19/03/2019 05:45:02] - (.-.) - [0.39 Ko] - (0.0.0.0) - C:\WINDOWS\System32\@VpnToastIcon.png [MD5.79166EAF65485F1432DD72B72870026B] - |A| - [19/03/2019 05:45:32] - (.-.) - [190.86 Ko] - (0.0.0.0) - C:\WINDOWS\System32\@windows-hello-V4.1.gif [MD5.13EF2C8D799F7B6E9D8E3D6BACB9C779] - |A| - [19/03/2019 05:45:32] - (.-.) - [0.7 Ko] - (0.0.0.0) - C:\WINDOWS\System32\@WindowsHelloFaceToastIcon.png [MD5.F553B252FEC3134D4F5303D9B25298B3] - |A| - [19/03/2019 05:44:21] - (.-.) - [0.51 Ko] - (0.0.0.0) - C:\WINDOWS\System32\@WindowsUpdateToastIcon.contrast-black.png [MD5.DAD405CBDE259DE527EBF71BCC28099C] - |A| - [19/03/2019 05:44:21] - (.-.) - [0.79 Ko] - (0.0.0.0) - C:\WINDOWS\System32\@WindowsUpdateToastIcon.contrast-white.png [MD5.F553B252FEC3134D4F5303D9B25298B3] - |A| - [19/03/2019 05:44:21] - (.-.) - [0.51 Ko] - (0.0.0.0) - C:\WINDOWS\System32\@WindowsUpdateToastIcon.png [MD5.DB71001FC261F6685BE410527DAE3942] - |A| - [19/03/2019 05:44:01] - (.-.) - [0.67 Ko] - (0.0.0.0) - C:\WINDOWS\System32\@WirelessDisplayToast.png [MD5.D0FCF781D0801ABF5F74B54E98076A5B] - |A| - [19/03/2019 05:44:12] - (.-.) - [0.15 Ko] - (0.0.0.0) - C:\WINDOWS\System32\@WwanNotificationIcon.png [MD5.85D91E478AF18125007C531227FF6E59] - |A| - [19/03/2019 05:44:12] - (.-.) - [0.34 Ko] - (0.0.0.0) - C:\WINDOWS\System32\@WwanSimLockIcon.png [MD5.59683D1E4CD0B1AD6AE32E1D627AE25F] - |A| - [25/01/2018 15:31:32] - (.Copyright © 2003 by fccHandler - AC-3 ACM Decompressor.) - [80 Ko] - (0.7.0.0) - C:\WINDOWS\System32\AC3ACM.acm [MD5.F2CF417EF502555B139EDCD9FEBF9CD3] - |A| - [30/01/2014 17:35:11] - (.-.) - [107.27 Ko] - (0.0.0.0) - C:\WINDOWS\System32\AcpiServiceVnA64.dll [MD5.31A16C523B62500F83C82217F056A538] - |A| - [19/03/2019 05:44:21] - (.-.) - [8.13 Ko] - (0.0.0.0) - C:\WINDOWS\System32\ActiveHours.png [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [2751.51 Ko] - C:\WINDOWS\System32\AdvancedInstallers [MD5.0724FA8BCAF2725746F9BB4264989D96] - |A| - [19/03/2019 05:43:47] - (.-.) - [13 Ko] - (0.0.0.0) - C:\WINDOWS\System32\agentactivationruntimestarter.exe [MD5.8210141840CE237FBF40B6E26E2DD11D] - |A| - [25/01/2018 15:31:32] - (.NCT Company Copyright 1999 - 2001 - NCT ALF2CD Audio CODEC.) - [38 Ko] - (2.3.1.0) - C:\WINDOWS\System32\alf2cd.acm [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [5.97 Ko] - C:\WINDOWS\System32\am-et [MD5.D03124A92936B3B1D38AC31D9B5582F8] - |A| - [05/08/2019 14:33:25] - (.-.) - [49.92 Ko] - (0.0.0.0) - C:\WINDOWS\System32\ambakdrv.sys [MD5.98B78382C46541F2FFBFFB4CB3C709A2] - |A| - [05/08/2019 14:33:25] - (.-.) - [167.92 Ko] - (0.0.0.0) - C:\WINDOWS\System32\ammntdrv.sys [MD5.D0C50C113FE59C21AD59932E6B9C202F] - |A| - [31/10/2019 22:37:18] - (.-.) - [37.42 Ko] - (0.0.0.0) - C:\WINDOWS\System32\ampa.sys [MD5.301167E69BDE24CE24FB53376C422B3B] - |A| - [05/08/2019 14:33:25] - (.-.) - [37.42 Ko] - (0.0.0.0) - C:\WINDOWS\System32\amwrtdrv.sys [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [0 Ko] - C:\WINDOWS\System32\AppLocker [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [2728.29 Ko] - C:\WINDOWS\System32\appraiser [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [355 Ko] - C:\WINDOWS\System32\ar-SA [MD5.A3FA2DD7B000AE0964395512E9C37E41] - |A| - [19/03/2019 05:45:35] - (.Copyright (c) libarchive authors - Windows-internal libarchive library.) - [607 Ko] - (3.3.2.0) - C:\WINDOWS\System32\archiveint.dll [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\as-IN [MD5.42FE37B90A47609B7A362660BCA5F3C4] - |A| - [20/09/2019 20:16:04] - (.Copyright (c) 2019 AVAST Software - Avast Antivirus start-up scanner.) - [347.38 Ko] - (19.8.4793.0) - C:\WINDOWS\System32\aswBoot.exe [MD5.2D0895BED270D1A8CADD981A5BFC0AE5] - |A| - [30/01/2014 17:35:47] - (.-.) - [591.3 Ko] - (0.0.0.0) - C:\WINDOWS\System32\audioLibVc.dll [MD5.C03F0062C0749CDB59A4D60862C3E83E] - |A| - [19/03/2019 05:43:47] - (.-.) - [134.86 Ko] - (0.0.0.0) - C:\WINDOWS\System32\AverageRoom.bin [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\az-Latn-AZ [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\be-BY [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [348 Ko] - C:\WINDOWS\System32\bg-BG [MD5.705628497C0012302212A46ADD463E6E] - |A| - [19/03/2019 05:43:45] - (.-.) - [8.3 Ko] - (0.0.0.0) - C:\WINDOWS\System32\BluetoothPairingSystemToastIcon.contrast-black.png [MD5.F63C615733A3337BF2BEA96C6EE9B568] - |A| - [19/03/2019 05:43:45] - (.-.) - [8.53 Ko] - (0.0.0.0) - C:\WINDOWS\System32\BluetoothPairingSystemToastIcon.contrast-high.png [MD5.705628497C0012302212A46ADD463E6E] - |A| - [19/03/2019 05:43:45] - (.-.) - [8.3 Ko] - (0.0.0.0) - C:\WINDOWS\System32\BluetoothPairingSystemToastIcon.contrast-white.png [MD5.DAF1DCB4AEE839A1965F4CC160C49A53] - |A| - [19/03/2019 05:43:45] - (.-.) - [8.34 Ko] - (0.0.0.0) - C:\WINDOWS\System32\BluetoothPairingSystemToastIcon.png [MD5.28ECA83D7F9D10D69E969675D1FF6725] - |A| - [19/03/2019 05:43:45] - (.-.) - [1.29 Ko] - (0.0.0.0) - C:\WINDOWS\System32\BluetoothSystemToastIcon.contrast-white.png [MD5.A620186FF1CDE4EE117FC4CAD648B9CC] - |A| - [19/03/2019 05:43:45] - (.-.) - [1.2 Ko] - (0.0.0.0) - C:\WINDOWS\System32\BluetoothSystemToastIcon.png [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\bn-BD [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\bn-IN [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [5789.2 Ko] - C:\WINDOWS\System32\Boot [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\bs-Latn-BA [MD5.6CC5FAF5A7B51609D0D2A90AC1202918] - |A| - [19/03/2019 05:44:29] - (.Copyright (C) 2008 - Gestionnaire de contexte pour réseau personnel Bluetooth.) - [182 Ko] - (1.0.0.1) - C:\WINDOWS\System32\BthpanContextHandler.dll [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [0.1 Ko] - C:\WINDOWS\System32\Bthprops [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\ca-ES [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\ca-ES-valencia [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:37:22] - [59324.87 Ko] - C:\WINDOWS\System32\CatRoot [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [84344.55 Ko] - C:\WINDOWS\System32\catroot2 [MD5.2E53389E559CAA5168DAE23E1D38A08D] - |A| - [08/09/2014 12:37:32] - (.Copyright © 2010. - CDA Print Provider.) - [70.5 Ko] - (1.62.0.0) - C:\WINDOWS\System32\CDASpl.dll [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\chr-CHER-US [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [11.19 Ko] - C:\WINDOWS\System32\CodeIntegrity [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [370 Ko] - C:\WINDOWS\System32\Com [MD5.535884123FABC2C15AA7DEC9834B55D4] - |A| - [19/03/2019 05:43:45] - (.-.) - [0.67 Ko] - (0.0.0.0) - C:\WINDOWS\System32\ComputerToastIcon.contrast-white.png [MD5.89F92266DFC6F93961DFFBB2D6C61A15] - |A| - [19/03/2019 05:43:45] - (.-.) - [0.38 Ko] - (0.0.0.0) - C:\WINDOWS\System32\ComputerToastIcon.png [MD5.227758E8590A84AC7888FF3B8554DBA8] - |A| - [30/01/2014 17:35:11] - (.2013 © Real Sound Lab SIA, iSoft Solutions - CONEQ™ Media Suite APO GUI Library.) - [110.91 Ko] - (1.0.0.4) - C:\WINDOWS\System32\CONEQMSAPOGUILibrary.dll [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:37:22] - [306974.47 Ko] - C:\WINDOWS\System32\config [MD5.00000000000000000000000000000000] - |SD| - [19/03/2019 05:52:45] - [53.11 Ko] - C:\WINDOWS\System32\Configuration [MD5.FDCF1790F100879ADF8F8684018FAAC0] - |A| - [17/09/2019 16:26:23] - (.-.) - [232.3 Ko] - (0.0.0.0) - C:\WINDOWS\System32\containerdevicemanagement.dll [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [405.5 Ko] - C:\WINDOWS\System32\cs-CZ [MD5.2419907A0BB9A14F1871F0BDA7F65578] - |A| - [07/08/2019 16:21:11] - (.© 1996 - 2017 Daniel Stenberg, . - The curl executable.) - [411.5 Ko] - (7.55.1.0) - C:\WINDOWS\System32\curl.exe [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\cy-GB [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [401.5 Ko] - C:\WINDOWS\System32\da-DK [MD5.B3E4FEC7C8AD9291722B49D0D63E6550] - |A| - [17/09/2019 16:26:07] - (.-.) - [146 Ko] - (0.0.0.0) - C:\WINDOWS\System32\DataStoreCacheDumpTool.exe [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [277.94 Ko] - C:\WINDOWS\System32\DDFs [MD5.DF6465F349C9CBDF3FCEB3F198E8FCB6] - |A| - [31/10/2019 22:37:24] - (.-.) - [34.92 Ko] - (0.0.0.0) - C:\WINDOWS\System32\ddmdrv.sys [MD5.A5DAFFCF476186B1F9F2DDB1EFCB1A92] - |A| - [30/01/2014 17:35:12] - (.©2013 Dolby Laboratories. - Dolby Digital Plus API x86.) - [255.34 Ko] - (7.3.2.2) - C:\WINDOWS\System32\DDPA64.dll [MD5.B19439EBBD6BB5379EC1AEF360F4BD53] - |A| - [30/01/2014 17:35:12] - (.©2013 Dolby Laboratories. - Dolby Digital Plus COM DLL x86.) - [1863.84 Ko] - (7.3.2.2) - C:\WINDOWS\System32\DDPD64A.dll [MD5.C9DEFD6C0B76B13419FD9692625A912A] - |A| - [30/01/2014 17:35:12] - (.©2013 Dolby Laboratories. - Dolby Digital Plus APO x86.) - [304.84 Ko] - (7.3.2.2) - C:\WINDOWS\System32\DDPO64A.dll [MD5.91D8E07AF1B0D861E352FA42DB23CE91] - |A| - [30/01/2014 17:35:13] - (.©2012 Dolby Laboratories. - Dolby DS1PC Control Panel x86.) - [6073.34 Ko] - (7.3.2.2) - C:\WINDOWS\System32\DDPP64A.dll [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [456 Ko] - C:\WINDOWS\System32\de-DE [MD5.C04ED7B2794D40E8E777FD44ED44FC50] - |A| - [19/03/2019 05:44:03] - (.-.) - [0.36 Ko] - (0.0.0.0) - C:\WINDOWS\System32\DefaultAccountTile.png [MD5.618BA9E529EAB7E11DBA43469481835F] - |A| - [19/03/2019 05:43:47] - (.-.) - [4128.04 Ko] - (0.0.0.0) - C:\WINDOWS\System32\DefaultHrtfs.bin [MD5.664AA698FC0106A2B075A641E8DC6302] - |A| - [19/03/2019 05:49:38] - (.-.) - [0.84 Ko] - (0.0.0.0) - C:\WINDOWS\System32\DefaultQuestions.json [MD5.9F21C110A9F6E001D2A13A35F8351570] - |A| - [06/08/2019 11:04:31] - (.-.) - [1.4 Ko] - (0.0.0.0) - C:\WINDOWS\System32\default_error_stack-000000-000000.txt [MD5.6C22EC440786D5E1EA69E0D53C4F3B4B] - |A| - [19/03/2019 05:44:45] - (.-.) - [35 Ko] - (0.0.0.0) - C:\WINDOWS\System32\deploymentcsphelper.exe [MD5.851A9305E14B348CA0D9C7FB75391FDB] - |A| - [19/03/2019 05:44:21] - (.-.) - [272.34 Ko] - (0.0.0.0) - C:\WINDOWS\System32\DesktopKeepOnToastImg.gif [MD5.4A6FA3C0EFD237F104E09A22883D9388] - |A| - [19/03/2019 05:44:25] - (.-.) - [3.85 Ko] - (0.0.0.0) - C:\WINDOWS\System32\DetailedReading-Default.xml [MD5.DCF2510E0745720E543E84F5E921FCC0] - |A| - [23/04/2014 09:10:51] - (.-.) - [256.19 Ko] - (0.0.0.0) - C:\WINDOWS\System32\dfpinc.dat [MD5.00000000000000000000000000000000] - |SD| - [19/03/2019 05:52:45] - [914.5 Ko] - C:\WINDOWS\System32\DiagSvcs [MD5.173D1EB779621B66784DCABEDF9AFB4F] - |A| - [19/03/2019 05:44:18] - (.-.) - [82.77 Ko] - (0.0.0.0) - C:\WINDOWS\System32\DiskSnapshot.conf [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [9441.1 Ko] - C:\WINDOWS\System32\Dism [MD5.6AB2B935BF38EB13CFCB9506223FD6E7] - |A| - [19/03/2019 05:43:45] - (.-.) - [0.59 Ko] - (0.0.0.0) - C:\WINDOWS\System32\DisplaySystemToastIcon.contrast-white.png [MD5.FF004E0B30E5E4EC747B3D8EF6E3B89E] - |A| - [19/03/2019 05:43:45] - (.-.) - [0.34 Ko] - (0.0.0.0) - C:\WINDOWS\System32\DisplaySystemToastIcon.png [MD5.902179013800F311AFF57CD5F29BE346] - |A| - [25/01/2018 15:31:32] - (.Copyright (C) DivXNetworks 2001-2003 - DivX Video for Windows Codec.) - [624 Ko] - (5.0.5.830) - C:\WINDOWS\System32\divx.dll [MD5.EFF71E68DD8F9DC0BBD89CD83153C336] - |A| - [25/01/2018 15:31:32] - (.Copyright © DivXNetworks, 2001-2003 - DivX (TM) Decoder Filter.) - [216.03 Ko] - (5.0.5.830) - C:\WINDOWS\System32\divxdec.ax [MD5.F5E58ACC172EDEFCD8AD458621D63121] - |A| - [17/08/2015 17:29:34] - (.© PoINT Software & Systems GmbH 1994-2015 - API of PoINT CD/DVD Audio/Video SDK.) - [950.32 Ko] - (13.0.0.244) - C:\WINDOWS\System32\DLLAV64.dll [MD5.0BB9FBE0BE20AA0990053EC748CC8A3B] - |A| - [17/08/2015 17:29:34] - (.© PoINT Software & Systems GmbH 1994-2015 - PoINT Shared DLL.) - [168.82 Ko] - (4.1.0.173) - C:\WINDOWS\System32\DLLCPY64.dll [MD5.F0674300C325ED17647A632D0404BCB8] - |A| - [17/08/2015 17:29:34] - (.© PoINT Software & Systems GmbH 1994-2015 - PoINT Shared DLL.) - [253.82 Ko] - (4.0.0.309) - C:\WINDOWS\System32\DLLDEV64.dll [MD5.097FDB81269D70086B24A7C7C361F7D4] - |A| - [17/08/2015 17:29:34] - (.© PoINT Software & Systems GmbH 1994-2015 - PoINT Shared DLL.) - [235.32 Ko] - (4.0.0.406) - C:\WINDOWS\System32\DLLDRV64.dll [MD5.E5CF84F091A4FA3931442E08B0A8AA98] - |A| - [17/08/2015 17:29:34] - (.© PoINT Software & Systems GmbH 1994-2015 - PoINT Shared DLL.) - [109.82 Ko] - (3.2.0.116) - C:\WINDOWS\System32\DLLIO64.dll [MD5.6BB9BEAACBF6C21E44D73FD6E95C66EE] - |A| - [17/08/2015 17:29:32] - (.Copyright © PoINT Software & Systems GmbH 1994-2013 - PoINT Shared DLL.) - [79.82 Ko] - (3.3.0.62) - C:\WINDOWS\System32\DLLPNT64.dll [MD5.86E6F69FAFD56CCBEF4269CA5B8352F5] - |A| - [17/08/2015 17:29:32] - (.PoINT Software & Systems GmbH 1994-2015 - PoINT Shared DLL.) - [309.82 Ko] - (3.3.0.222) - C:\WINDOWS\System32\DLLRES64.dll [MD5.C3F8294852FB20F1E03F4A0867100D4C] - |A| - [09/10/2019 11:08:30] - (.-.) - [0.31 Ko] - (0.0.0.0) - C:\WINDOWS\System32\DrtmAuth1.bin [MD5.DC1864D247977386E3046B21B238728F] - |A| - [09/10/2019 11:08:30] - (.-.) - [0.31 Ko] - (0.0.0.0) - C:\WINDOWS\System32\DrtmAuth10.bin [MD5.F5E7B12404FD058E87FFACC4D8ADBFF5] - |A| - [09/10/2019 11:08:30] - (.-.) - [0.31 Ko] - (0.0.0.0) - C:\WINDOWS\System32\DrtmAuth11.bin [MD5.3B7F5ED89ED8860BE5480890010CFE48] - |A| - [09/10/2019 11:08:30] - (.-.) - [0.31 Ko] - (0.0.0.0) - C:\WINDOWS\System32\DrtmAuth12.bin [MD5.ACA932E837044CCD3F76534E85B5E4FA] - |A| - [09/10/2019 11:08:30] - (.-.) - [0.31 Ko] - (0.0.0.0) - C:\WINDOWS\System32\DrtmAuth2.bin [MD5.A1E025AD5275E77BE562B7FADFEF9A6D] - |A| - [09/10/2019 11:08:30] - (.-.) - [0.31 Ko] - (0.0.0.0) - C:\WINDOWS\System32\DrtmAuth3.bin [MD5.1465663694A2FEE2631840D7D1244FB4] - |A| - [09/10/2019 11:08:30] - (.-.) - [0.31 Ko] - (0.0.0.0) - C:\WINDOWS\System32\DrtmAuth4.bin [MD5.B616A3727148474D13AD0AC6508015CC] - |A| - [09/10/2019 11:08:30] - (.-.) - [0.31 Ko] - (0.0.0.0) - C:\WINDOWS\System32\DrtmAuth5.bin [MD5.4E07AC9E6D18F2AF157498A6F33573B0] - |A| - [09/10/2019 11:08:30] - (.-.) - [0.31 Ko] - (0.0.0.0) - C:\WINDOWS\System32\DrtmAuth6.bin [MD5.E13AFE8490D5272FE7D36148609390B3] - |A| - [09/10/2019 11:08:30] - (.-.) - [0.31 Ko] - (0.0.0.0) - C:\WINDOWS\System32\DrtmAuth7.bin [MD5.25D97861D9C814B7E89A1DAF9E71C499] - |A| - [09/10/2019 11:08:30] - (.-.) - [0.31 Ko] - (0.0.0.0) - C:\WINDOWS\System32\DrtmAuth8.bin [MD5.6944755C4B18463F32F9E9A0A9623475] - |A| - [09/10/2019 11:08:30] - (.-.) - [0.31 Ko] - (0.0.0.0) - C:\WINDOWS\System32\DrtmAuth9.bin [MD5.00000000000000000000000000000000] - |SD| - [19/03/2019 05:52:45] - [161.5 Ko] - C:\WINDOWS\System32\dsc [MD5.8B5A737AD11EF45D9B1AEB4ED6884968] - |A| - [30/01/2014 17:35:13] - (.(c) DTS. - DTS Bass Enhancement COM DLL.) - [711.6 Ko] - (1.0.0.1) - C:\WINDOWS\System32\DTSBassEnhancementDLL64.dll [MD5.21B38D4D86A87909491F690883AE6D1E] - |A| - [30/01/2014 17:35:13] - (.(c) DTS. - DTS Boost COM DLL.) - [1452.1 Ko] - (1.0.0.1) - C:\WINDOWS\System32\DTSBoostDLL64.dll [MD5.FF31A2F57AAAB58DB78FCC961A58B206] - |A| - [30/01/2014 17:35:13] - (.(c) DTS. - DTS Gain Compensator COM DLL.) - [418.6 Ko] - (1.0.0.1) - C:\WINDOWS\System32\DTSGainCompensatorDLL64.dll [MD5.BC0474E5476E5EA0D0E1AA5AC41E2061] - |A| - [30/01/2014 17:35:13] - (.(c) DTS. - DTS GFX APO.) - [237.1 Ko] - (1.0.0.3) - C:\WINDOWS\System32\DTSGFXAPO64.dll [MD5.3B8FB5376F5431C0101747D5138BCB9B] - |A| - [30/01/2014 17:35:13] - (.(c) DTS. - DTS GFX APO.) - [236.1 Ko] - (1.0.0.3) - C:\WINDOWS\System32\DTSGFXAPONS64.dll [MD5.B3977C8BA77559F4F8752AE8EB724C87] - |A| - [30/01/2014 17:35:13] - (.(c) DTS. - DTS LFX APO.) - [237.1 Ko] - (1.0.0.3) - C:\WINDOWS\System32\DTSLFXAPO64.dll [MD5.192A03A21636D3775CEE4C049C3BEB2A] - |A| - [30/01/2014 17:35:13] - (.(c) DTS. - DTS Limiter COM DLL.) - [422.6 Ko] - (1.0.0.1) - C:\WINDOWS\System32\DTSLimiterDLL64.dll [MD5.2EF5442E8E7ED20F7634EEFB09640C8F] - |A| - [30/01/2014 17:35:14] - (.(c) DTS. - DTS NEO:PC COM DLL.) - [479.6 Ko] - (1.0.0.1) - C:\WINDOWS\System32\DTSNeoPCDLL64.dll [MD5.F7C357462077156DC211AC2112FC8C53] - |A| - [30/01/2014 17:35:14] - (.(c) DTS. - DTS Surround Sensation Headphone COM DLL.) - [1531.6 Ko] - (1.0.0.1) - C:\WINDOWS\System32\DTSS2HeadphoneDLL64.dll [MD5.F132C08BD8C58579B400DFAA71F34CFB] - |A| - [30/01/2014 17:35:14] - (.(c) DTS. - DTS Surround Sensation Speaker COM DLL.) - [1715.1 Ko] - (1.0.0.1) - C:\WINDOWS\System32\DTSS2SpeakerDLL64.dll [MD5.9948969B2C1987B1D64789EFEB284A84] - |A| - [30/01/2014 17:35:14] - (.(c) DTS. - DTS Symmetry COM DLL.) - [695.6 Ko] - (1.0.0.1) - C:\WINDOWS\System32\DTSSymmetryDLL64.dll [MD5.505537E71CD0905219513BFAC882FDBA] - |A| - [30/01/2014 17:35:14] - (.(c) DTS. - DTS GFX APO.) - [475.95 Ko] - (2.1.0.0) - C:\WINDOWS\System32\DTSU2PGFX64.dll [MD5.50A91915D086C44D9E60904B08110048] - |A| - [30/01/2014 17:35:14] - (.(c) DTS. - DTS LFX APO.) - [489.45 Ko] - (2.1.0.0) - C:\WINDOWS\System32\DTSU2PLFX64.dll [MD5.5C06256211319BF61AE9665A2713E021] - |A| - [30/01/2014 17:35:14] - (.(c) DTS. - DTS LFX APO.) - [405.95 Ko] - (2.1.0.0) - C:\WINDOWS\System32\DTSU2PREC64.dll [MD5.DE32448E6B40141C80DAABFF6FBE1744] - |A| - [30/01/2014 17:35:14] - (.(c) DTS. - DTS Voice Clarity COM DLL.) - [677.1 Ko] - (1.0.0.1) - C:\WINDOWS\System32\DTSVoiceClarityDLL64.dll [MD5.1394A49F087BE158119BDC01965E7E6E] - |A| - [09/10/2019 11:08:05] - (.-.) - [2529.5 Ko] - (0.0.0.0) - C:\WINDOWS\System32\dwmscene.dll [MD5.DF84EB7B44D1414284BA384F0061D1DC] - |A| - [19/03/2019 05:43:47] - (.-.) - [728.08 Ko] - (0.0.0.0) - C:\WINDOWS\System32\DynamicLong.bin [MD5.346870077DFD18867A9693C7A59AA3E6] - |A| - [19/03/2019 05:43:47] - (.-.) - [503.08 Ko] - (0.0.0.0) - C:\WINDOWS\System32\DynamicMedium.bin [MD5.2BEC13D68312ADE8C0065D8BCC146D2F] - |A| - [19/03/2019 05:43:47] - (.-.) - [315.58 Ko] - (0.0.0.0) - C:\WINDOWS\System32\DynamicShort.bin [MD5.1AEC452250C459B163D2B2F9A9AB17D2] - |A| - [09/05/2018 09:00:07] - (.-.) - [1805 Ko] - (1.10.63.1) - C:\WINDOWS\System32\eed_ec.dll [MD5.E61B9708AE9C5623C79B0E933897F8A5] - |A| - [09/05/2018 09:00:08] - (.Copyright (C) 2011 Samsung Electronics Co., Ltd. - Samsung Easy Eco Driver.) - [672.27 Ko] - (1.10.63.1) - C:\WINDOWS\System32\eed_sl.exe [MD5.983B32C79C9EDB7024682A1A69C8CB26] - |A| - [09/05/2018 09:00:20] - (.-.) - [0.27 Ko] - (0.0.0.0) - C:\WINDOWS\System32\eed_sl.exe.config [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [461 Ko] - C:\WINDOWS\System32\el-GR [MD5.2F208FEADAFE77BADD9624200EBBC2F9] - |A| - [01/05/2016 22:28:43] - (.-.) - [22.66 Ko] - (0.0.0.0) - C:\WINDOWS\System32\emptyregdb.dat [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 13:00:40] - [0 Ko] - C:\WINDOWS\System32\en [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [326 Ko] - C:\WINDOWS\System32\en-GB [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [1657.03 Ko] - C:\WINDOWS\System32\en-US [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [436 Ko] - C:\WINDOWS\System32\es-ES [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [361.5 Ko] - C:\WINDOWS\System32\es-MX [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [320 Ko] - C:\WINDOWS\System32\et-EE [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\eu-ES [MD5.00000000000000000000000000000000] - |SD| - [19/03/2019 05:52:45] - [16908.14 Ko] - C:\WINDOWS\System32\F12 [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\fa-IR [MD5.4DED57BD7ACB9B0EBBE82034EC44645A] - |A| - [19/03/2019 05:44:39] - (.-.) - [43.22 Ko] - (0.0.0.0) - C:\WINDOWS\System32\FeatureToastBulldogImg.png [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [7.11 Ko] - C:\WINDOWS\System32\ff-Adlm-SN [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [406.5 Ko] - C:\WINDOWS\System32\fi-FI [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\fil-PH [MD5.3F291F1387F2B316E86570EDDBA978F7] - |A| - [02/12/2019 22:54:44] - (.-.) - [907.94 Ko] - (0.0.0.0) - C:\WINDOWS\System32\FNTCACHE.DAT [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 13:00:40] - [3403.5 Ko] - C:\WINDOWS\System32\fr [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [371.5 Ko] - C:\WINDOWS\System32\fr-CA [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [46624.41 Ko] - C:\WINDOWS\System32\fr-FR [MD5.3C402FA88BB488B77A73428623B7825B] - |A| - [19/03/2019 05:45:49] - (.-.) - [167 Ko] - (0.0.0.0) - C:\WINDOWS\System32\FsNVSDeviceSource.dll [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [0 Ko] - C:\WINDOWS\System32\FxsTmp [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\ga-IE [MD5.41FD64AE28A0C932CA7B2A250993D675] - |A| - [19/03/2019 05:43:45] - (.-.) - [1.45 Ko] - (0.0.0.0) - C:\WINDOWS\System32\GameSystemToastIcon.contrast-white.png [MD5.6DC77FD8B062264AF1C6DA325ABB7010] - |A| - [19/03/2019 05:43:45] - (.-.) - [1.11 Ko] - (0.0.0.0) - C:\WINDOWS\System32\GameSystemToastIcon.png [MD5.2E6AF4D5BF6E31E728F409984C3045D4] - |A| - [19/03/2019 05:45:50] - (.-.) - [86.7 Ko] - (0.0.0.0) - C:\WINDOWS\System32\gatherNetworkInfo.vbs [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\gd-GB [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\gl-ES [MD5.00000000000000000000000000000000] - |HD| - [22/08/2013 16:36:31] - [0.27 Ko] - C:\WINDOWS\System32\GroupPolicy [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 16:36:31] - [0 Ko] - C:\WINDOWS\System32\GroupPolicyUsers [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\gu-IN [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\ha-Latn-NG [MD5.EA99A87E98D995DE6E280CF85CEAD413] - |A| - [19/03/2019 05:43:45] - (.-.) - [1.21 Ko] - (0.0.0.0) - C:\WINDOWS\System32\HandwritingSystemToastIcon.contrast-white.png [MD5.B8E586ED92DB703FFA480E254996160E] - |A| - [19/03/2019 05:43:45] - (.-.) - [0.89 Ko] - (0.0.0.0) - C:\WINDOWS\System32\HandwritingSystemToastIcon.png [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [329.5 Ko] - C:\WINDOWS\System32\he-IL [MD5.6E9E9D56B192B2995493E529CFF2BBFE] - |A| - [19/03/2019 05:43:45] - (.-.) - [1.43 Ko] - (0.0.0.0) - C:\WINDOWS\System32\HeadphoneSystemToastIcon.contrast-white.png [MD5.7F1E9502267F778F3A8139C35A352190] - |A| - [19/03/2019 05:43:45] - (.-.) - [1.09 Ko] - (0.0.0.0) - C:\WINDOWS\System32\HeadphoneSystemToastIcon.png [MD5.202A07E4526B050E22624328E64E0470] - |A| - [19/03/2019 05:43:45] - (.-.) - [1.52 Ko] - (0.0.0.0) - C:\WINDOWS\System32\HeadsetSystemToastIcon.contrast-white.png [MD5.1892ACC10CAC009BCAC146AD650ABA58] - |A| - [19/03/2019 05:43:45] - (.-.) - [1.17 Ko] - (0.0.0.0) - C:\WINDOWS\System32\HeadsetSystemToastIcon.png [MD5.031713BFD5F30E63336D3CA5D2767BE9] - |A| - [19/03/2019 05:43:45] - (.-.) - [1.79 Ko] - (0.0.0.0) - C:\WINDOWS\System32\HealthSystemToastIcon.contrast-white.png [MD5.C1BD7976C99830E33A713D02374054EC] - |A| - [19/03/2019 05:43:45] - (.-.) - [1.62 Ko] - (0.0.0.0) - C:\WINDOWS\System32\HealthSystemToastIcon.png [MD5.D6F7FB7B9386E0A029DCCD11DD84B15A] - |A| - [19/03/2019 05:44:11] - (.-.) - [260 Ko] - (0.0.0.0) - C:\WINDOWS\System32\HeatCore.dll [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\hi-IN [MD5.B4DE48A0333CD63B62CDC63B516D9902] - |A| - [19/03/2019 05:45:54] - (.-.) - [37.8 Ko] - (0.0.0.0) - C:\WINDOWS\System32\HvSocket.dll [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\hy-AM [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 13:02:58] - [158.57 Ko] - C:\WINDOWS\System32\Hydrogen [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [5.36 Ko] - C:\WINDOWS\System32\ias [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [36.27 Ko] - C:\WINDOWS\System32\icsxml [MD5.2E977573411A099BD0213832B7442F0E] - |A| - [07/08/2019 16:20:44] - (.Copyright (C) 2016 and later: Unicode, Inc. and others. License & terms of use: http://www.unicode.org/copyright.html - ICU Combined Library.) - [2267 Ko] - (63.1.0.0) - C:\WINDOWS\System32\icu.dll [MD5.D2A4919E61E99157AD2DE994795C0F83] - |RA| - [19/03/2019 05:44:15] - (.Copyright (C) 2016 and later: Unicode, Inc. and others. License & terms of use: http://www.unicode.org/copyright.html - ICU I18N DLL.) - [24.5 Ko] - (63.1.0.0) - C:\WINDOWS\System32\icuin.dll [MD5.003EEDD728E2952E23DB9F6516B9194A] - |RA| - [19/03/2019 05:44:15] - (.Copyright (C) 2016 and later: Unicode, Inc. and others. License & terms of use: http://www.unicode.org/copyright.html - ICU Common DLL.) - [29 Ko] - (63.1.0.0) - C:\WINDOWS\System32\icuuc.dll [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\id-ID [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\ig-NG [MD5.8CE43FCE353B86A81F67014B6EEE5143] - |A| - [19/03/2019 05:43:45] - (.-.) - [195.5 Ko] - (0.0.0.0) - C:\WINDOWS\System32\IHDS.dll [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [25976.08 Ko] - C:\WINDOWS\System32\IME [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [0 Ko] - C:\WINDOWS\System32\inetsrv [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [6869.5 Ko] - C:\WINDOWS\System32\InputMethod [MD5.8DE9AE82152650C178BF1E24014E8503] - |A| - [19/03/2019 05:43:45] - (.-.) - [1.25 Ko] - (0.0.0.0) - C:\WINDOWS\System32\InputSystemToastIcon.contrast-white.png [MD5.0B9FBD6F3ED617CD36D042D3422F1C2B] - |A| - [19/03/2019 05:43:45] - (.-.) - [0.9 Ko] - (0.0.0.0) - C:\WINDOWS\System32\InputSystemToastIcon.png [MD5.BDE76D83C3A1356C7DE6008FA6BC5103] - |A| - [26/09/2019 21:13:32] - (.-.) - [0.28 Ko] - (0.0.0.0) - C:\WINDOWS\System32\InstallUtil.InstallLog [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [0 Ko] - C:\WINDOWS\System32\Ipmi [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\is-IS [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [435 Ko] - C:\WINDOWS\System32\it-IT [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [325.09 Ko] - C:\WINDOWS\System32\ja-jp [MD5.38AD1993FD9D5997F5ED7CBA79CF39FB] - |A| - [01/09/2015 08:15:11] - (.Copyright © 2015 - Java(TM) Web Start Launcher.) - [314.59 Ko] - (11.60.2.27) - C:\WINDOWS\System32\javaws.exe [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\ka-GE [MD5.6F7D1601DA55BBE5C7A79E01E236D7B9] - |A| - [30/01/2014 17:35:19] - (.© Knowles Electronics. - Knowles HD Audio APO.) - [589.83 Ko] - (4.1105.6000.53) - C:\WINDOWS\System32\KAAPORT64.dll [MD5.23AC7515B6D8A794BCC01B582F044078] - |A| - [19/03/2019 05:43:45] - (.-.) - [0.82 Ko] - (0.0.0.0) - C:\WINDOWS\System32\KeyboardSystemToastIcon.contrast-white.png [MD5.3DF873E16CCEA9B42857FB5FA085CB00] - |A| - [19/03/2019 05:43:45] - (.-.) - [0.51 Ko] - (0.0.0.0) - C:\WINDOWS\System32\KeyboardSystemToastIcon.png [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [532.61 Ko] - C:\WINDOWS\System32\Keywords [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\kk-KZ [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\km-KH [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\kn-IN [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [298 Ko] - C:\WINDOWS\System32\ko-KR [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\kok-IN [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\ku-Arab-IQ [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\ky-KG [MD5.69A0628BBE1A404B1BA0B6DCA7610A06] - |A| - [25/01/2018 15:31:32] - (.Copyright (C) 1997 Fraunhofer IIS - MPEG Layer-3 Audio Decoder.) - [96 Ko] - (1.9.0.311) - C:\WINDOWS\System32\L3CODECX.AX [MD5.FA425C74CE2EB719B2A77A7A2ADDAE32] - |A| - [25/01/2018 15:31:32] - (.Copyright © 2011 - Lagarith.) - [211 Ko] - (1.3.27.0) - C:\WINDOWS\System32\Lagarith.dll [MD5.5E6F49F657A509D079C60D08A2EE33A7] - |A| - [25/01/2018 15:31:32] - (.Copyright © 2005 Elecard Ltd. - LAME Audio Encoder.) - [240 Ko] - (1.0.54.50801) - C:\WINDOWS\System32\lame.ax [MD5.9451D4436E2EA67EB33FCC764E4AABED] - |A| - [19/03/2019 05:44:21] - (.-.) - [186.29 Ko] - (0.0.0.0) - C:\WINDOWS\System32\LaptopPlugInToastImg.gif [MD5.F0CC83E1BA7E24F9B3292160C28AECD7] - |A| - [19/03/2019 05:43:47] - (.-.) - [145.56 Ko] - (0.0.0.0) - C:\WINDOWS\System32\LargeRoom.bin [MD5.D41D8CD98F00B204E9800998ECF8427E] - |A| - [12/02/2019 15:00:12] - (.-.) - [0 Ko] - (0.0.0.0) - C:\WINDOWS\System32\last.dump [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\lb-LU [MD5.5C0DA7DF022E0BFB08C68A6BE0AFCFAC] - |A| - [05/02/2014 20:36:53] - (.-.) - [159.53 Ko] - (0.0.0.0) - C:\WINDOWS\System32\LexFiles.ulf [MD5.91DC7E6E0A58BDBFA7442672BAF1626C] - |A| - [05/02/2014 20:38:40] - (.- Install Logging DLL.) - [816.5 Ko] - (14.0.43.0) - C:\WINDOWS\System32\lexlog.dll [MD5.157FB82D7141B18624FF2D42190C97E1] - |A| - [19/03/2019 13:01:40] - (.-.) - [1572 Ko] - (2.6.5.1) - C:\WINDOWS\System32\libcrypto.dll [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [625.17 Ko] - C:\WINDOWS\System32\Licenses [MD5.A1297C30E7D6DAF489B187890CF2993C] - |A| - [12/02/2014 10:27:14] - (.-.) - [502.03 Ko] - (0.0.0.0) - C:\WINDOWS\System32\Listing.txt [MD5.44B98DFE9C020142D35B7C5FF1F59FF7] - |A| - [06/09/2012 09:17:58] - (.- Printer Communication System.) - [712.5 Ko] - (12.1.36.0) - C:\WINDOWS\System32\LMADHQcomc.dll [MD5.D784E06F7D4B5F5BB490B29B0DF0F100] - |A| - [06/09/2012 09:17:52] - (.- Printer Communication System.) - [282.5 Ko] - (12.1.36.0) - C:\WINDOWS\System32\LMADHQinpa.dll [MD5.81AF0150D3B02EFD23E5BF6A1EABAEB8] - |A| - [06/09/2012 09:20:36] - (.- Printer Communication System.) - [2876 Ko] - (12.1.36.0) - C:\WINDOWS\System32\LMADHQlang.dll [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\lo-LA [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [31209.72 Ko] - C:\WINDOWS\System32\LogFiles [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [335.5 Ko] - C:\WINDOWS\System32\lt-LT [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [333.5 Ko] - C:\WINDOWS\System32\lv-LV [MD5.B3A6E4A15E72BEEE5EA2C23DD92A7A52] - |A| - [22/08/2013 13:37:05] - (.-.) - [43.87 Ko] - (0.0.0.0) - C:\WINDOWS\System32\LXAA3DeviceDescription.xml [MD5.0D7D67C5D0344AD9C24546CD8CE65C52] - |A| - [22/08/2013 13:37:09] - (.Copyright 2010-2012 Lexmark International, Inc. - Data Retrieval Library.) - [1009 Ko] - (1.0.0.0) - C:\WINDOWS\System32\LXAA3drs.dll [MD5.E50B87C1B134F13937764FFB077CFB68] - |A| - [22/08/2013 13:36:58] - (.-.) - [1.46 Ko] - (0.0.0.0) - C:\WINDOWS\System32\LXAA3FactoryPresets.ini [MD5.A594A3045B8FEDC3D795E1304AAA3E2C] - |A| - [22/08/2013 13:30:09] - (.Copyright 2010-2012 Lexmark International, Inc. - WIA Mini Driver.) - [267 Ko] - (1.0.0.0) - C:\WINDOWS\System32\LXAA3mini.dll [MD5.20B821478DC989211EA8D5407A5EFA1C] - |A| - [22/08/2013 13:37:07] - (.-.) - [0.46 Ko] - (0.0.0.0) - C:\WINDOWS\System32\LXAA3ScabConfig.ini [MD5.CB016152D81D76C0E7BBDF38F8989D0D] - |A| - [22/08/2013 13:37:09] - (.-.) - [1.23 Ko] - (0.0.0.0) - C:\WINDOWS\System32\LXAA3scancfg.xml [MD5.E61B542F6D2D6093DE22D66BD0F64E1C] - |A| - [22/08/2013 13:37:02] - (.Copyright 2001-2012 Lexmark International, Inc. - Lexmark Communication System.) - [206 Ko] - (1.0.0.0) - C:\WINDOWS\System32\LXAA3_iesc.dll [MD5.76EFAFE7676AB2B829FD2B5BC073EEC5] - |A| - [22/08/2013 13:37:06] - (.Copyright 2001-2012 Lexmark International, Inc. - Lexmark Communication System.) - [955.5 Ko] - (1.0.0.0) - C:\WINDOWS\System32\LXAA3_serv.dll [MD5.54180A00E135EDE4B17C3FC09C1F8004] - |A| - [22/08/2013 13:37:08] - (.Copyright 2001-2012 Lexmark International, Inc. - Lexmark Communication System.) - [549.5 Ko] - (1.0.0.0) - C:\WINDOWS\System32\LXAA3_usb1.dll [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [90844.97 Ko] - C:\WINDOWS\System32\Macromed [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 13:02:25] - [32.68 Ko] - C:\WINDOWS\System32\MailContactsCalendarSync [MD5.75616F8DB5C092A8A50AFEC273859DD7] - |A| - [30/01/2014 17:35:21] - (.© Waves Audio Ltd. - MaxxAudio APO.) - [311.34 Ko] - (2.2.9.0) - C:\WINDOWS\System32\MaxxAudioAPO20.dll [MD5.06080807E61471A18AD99F3E6FF3C9B5] - |A| - [30/01/2014 17:35:21] - (.© Waves Audio Ltd. - MaxxAudio APO.) - [647.75 Ko] - (3.6.0.0) - C:\WINDOWS\System32\MaxxAudioAPO30.dll [MD5.315AEF22E309E724AD0575C75E7EF5F3] - |A| - [30/01/2014 17:35:21] - (.© Waves Audio Ltd. - MaxxAudio APO.) - [1058.75 Ko] - (4.4.0.0) - C:\WINDOWS\System32\MaxxAudioAPO4064.dll [MD5.0625C989F27DEBF1E31901D0F6ABC738] - |A| - [30/01/2014 17:35:21] - (.© Waves Audio Ltd. - MaxxAudio APO.) - [1312.75 Ko] - (5.3.0.0) - C:\WINDOWS\System32\MaxxAudioAPO5064.dll [MD5.B9D6BC6503777449A0E796FFCAE9B5CF] - |A| - [30/01/2014 17:35:21] - (.Copyright (C) 2010-2013 - MaxxAudio APO Shell.) - [988.25 Ko] - (4.11.0.0) - C:\WINDOWS\System32\MaxxAudioAPOShell64.dll [MD5.20789ECD893A520F7D426ECA96C08E12] - |A| - [30/01/2014 17:35:22] - (.Copyright © 1996-2012 -.) - [1989.25 Ko] - (4.1.0.0) - C:\WINDOWS\System32\MaxxAudioEQ64.dll [MD5.F703D35A9E40E10550E648E214F1AA0B] - |A| - [30/01/2014 17:35:23] - (.- Waves Realtek App.) - [1876.75 Ko] - (5.2.16.0) - C:\WINDOWS\System32\MaxxAudioRealtek264.dll [MD5.AB60799D5AED4E53F125EB2543C324B3] - |A| - [30/01/2014 17:35:25] - (.Copyright © 1996-2013 -.) - [13820.25 Ko] - (4.5.0.0) - C:\WINDOWS\System32\MaxxAudioRealtek64.dll [MD5.EA85CB193FC8ACBD51181B2C1FC8CA1C] - |A| - [30/01/2014 17:35:26] - (.Copyright © 1996-2013 -.) - [26995.75 Ko] - (1.7.1.0) - C:\WINDOWS\System32\MaxxAudioVnA64.dll [MD5.B66B1DD7DD5332D2CAF07FF03ABAE289] - |A| - [30/01/2014 17:35:30] - (.Copyright © 1996-2013 -.) - [3626.25 Ko] - (1.3.0.0) - C:\WINDOWS\System32\MaxxAudioVnN64.dll [MD5.DC28052EC08D623C7419AD2DBC497EC8] - |A| - [30/01/2014 17:35:31] - (.© Waves Audio Ltd. - MaxxSpeech APO.) - [747.25 Ko] - (1.0.24.0) - C:\WINDOWS\System32\MaxxSpeechAPO64.dll [MD5.32E91908A319CF4FDDE18C6F5699E0E0] - |A| - [30/01/2014 17:35:31] - (.© Waves Audio Ltd. - MaxxVoice APO.) - [885.75 Ko] - (2.4.0.0) - C:\WINDOWS\System32\MaxxVoiceAPO2064.dll [MD5.587A8CF457604D84266FF858CEB60223] - |A| - [30/01/2014 17:35:31] - (.© Waves Audio Ltd. - MaxxVolumeSD APO.) - [647.25 Ko] - (3.6.0.0) - C:\WINDOWS\System32\MaxxVolumeSDAPO.dll [MD5.B178DCBF725D542401B36B708409F959] - |A| - [09/10/2019 11:08:20] - (.-.) - [836.5 Ko] - (0.0.0.0) - C:\WINDOWS\System32\MBR2GPT.EXE [MD5.521F1463E9733FD867E097727DD90177] - |A| - [25/01/2018 15:31:32] - (.Main Concept Ltd. 1999-2001 - MainConcept DV Codec.) - [255.5 Ko] - (2.0.0.0) - C:\WINDOWS\System32\mcdvd_32.dll [MD5.F23EB28468FC8B62AF941308EC30387F] - |A| - [19/03/2019 05:43:45] - (.-.) - [1.25 Ko] - (0.0.0.0) - C:\WINDOWS\System32\MediaSystemToastIcon.contrast-white.png [MD5.6E27512E38D598E0A60F8E5ADCF032CD] - |A| - [19/03/2019 05:43:45] - (.-.) - [0.83 Ko] - (0.0.0.0) - C:\WINDOWS\System32\MediaSystemToastIcon.png [MD5.69D04DE701CF1E8CE69C65D1671D2B3F] - |A| - [19/03/2019 05:43:47] - (.-.) - [107.46 Ko] - (0.0.0.0) - C:\WINDOWS\System32\MediumRoom.bin [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\mi-NZ [MD5.00000000000000000000000000000000] - |D| - [07/08/2019 16:24:17] - [1129.21 Ko] - C:\WINDOWS\System32\Microsoft [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [5312.7 Ko] - C:\WINDOWS\System32\migration [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [46626.32 Ko] - C:\WINDOWS\System32\migwiz [MD5.08749DCC252AE1148E3BEA32B3FFFBFC] - |A| - [19/03/2019 05:46:18] - (.-.) - [0.11 Ko] - (0.0.0.0) - C:\WINDOWS\System32\MixedRealityRuntime.json [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\mk-MK [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\ml-IN [MD5.C8BF077B236ED2803347BD95DE29BF68] - |A| - [19/03/2019 05:49:39] - (.-.) - [3.03 Ko] - (0.0.0.0) - C:\WINDOWS\System32\mmc.exe.config [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\mn-MN [MD5.B43E43FFFDD0F06A6925C7C89594042B] - |A| - [19/03/2019 05:43:45] - (.-.) - [1.35 Ko] - (0.0.0.0) - C:\WINDOWS\System32\MouseSystemToastIcon.contrast-white.png [MD5.5D2F0D3E50BF1129D260AC1405FF2A18] - |A| - [19/03/2019 05:43:45] - (.-.) - [1.06 Ko] - (0.0.0.0) - C:\WINDOWS\System32\MouseSystemToastIcon.png [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\mr-IN [MD5.00000000000000000000000000000000] - |D| - [30/01/2014 18:50:45] - [0 Ko] - C:\WINDOWS\System32\MRT [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\ms-MY [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [45.5 Ko] - C:\WINDOWS\System32\MSDRM [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:50] - [4324.28 Ko] - C:\WINDOWS\System32\MsDtc [MD5.57EA9479AA42EFEC084B51BC07E1442C] - |A| - [25/01/2018 15:31:34] - (.Copyright (c) Flash-Integro LLC, 2011-2019. - mslvddsfilter4 ActiveX DLL.) - [74.86 Ko] - (4.0.1.191) - C:\WINDOWS\System32\mslvddsfilter4.ax [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\mt-MT [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [19.16 Ko] - C:\WINDOWS\System32\MUI [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [45.64 Ko] - C:\WINDOWS\System32\my-mm [MD5.6B1E196C4E5CB30D6FF99CFA8F1F071D] - |A| - [19/03/2019 05:44:28] - (.-.) - [28.7 Ko] - (0.0.0.0) - C:\WINDOWS\System32\NarratorControlTemplates.xml [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [396.5 Ko] - C:\WINDOWS\System32\nb-NO [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [640 Ko] - C:\WINDOWS\System32\NDF [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\ne-NP [MD5.902A73D5EE2E0C30DEE47B1CD152888A] - |A| - [10/04/2017 17:52:08] - (.-.) - [225.85 Ko] - (0.0.0.0) - C:\WINDOWS\System32\NetSetupMig.log [MD5.C146E873B22C3B300B21A859FE66C27A] - |A| - [19/03/2019 05:45:50] - (.-.) - [21.15 Ko] - (0.0.0.0) - C:\WINDOWS\System32\NetTrace.PLA.Diagnostics.xml [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [51 Ko] - C:\WINDOWS\System32\networklist [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [431.5 Ko] - C:\WINDOWS\System32\nl-NL [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\nn-NO [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\nso-ZA [MD5.00000000000000000000000000000000] - |SD| - [19/03/2019 05:52:45] - [3781.5 Ko] - C:\WINDOWS\System32\Nui [MD5.CA73C8321216E19F093B84CB6593B8B0] - |A| - [10/04/2017 17:53:08] - (.-.) - [8593.82 Ko] - (0.0.0.0) - C:\WINDOWS\System32\nvcoproc.bin [MD5.BACFD032AAF507CDF1AC6B5706235208] - |A| - [15/12/2019 21:00:48] - (.-.) - [54.38 Ko] - (0.0.0.0) - C:\WINDOWS\System32\nvinfo.pb [MD5.E04972DEEC18D6D82DA9C7E2E51F3100] - |A| - [15/12/2019 21:00:48] - (.-.) - [660.75 Ko] - (0.0.0.0) - C:\WINDOWS\System32\nvofapi64.dll [MD5.2145E8D9F059A01AD670A8A0FE3B74BF] - |A| - [19/03/2019 13:02:58] - (.-.) - [18.46 Ko] - (0.0.0.0) - C:\WINDOWS\System32\OEMDefaultAssociations.xml [MD5.F3DC097E834C1A11F2BEDFD429C644A9] - |A| - [19/03/2019 05:44:21] - (.-.) - [0.41 Ko] - (0.0.0.0) - C:\WINDOWS\System32\OkDone_80.contrast-black.png [MD5.BFE1CCA08FEFC8A3422F7DA615567D75] - |A| - [19/03/2019 05:44:21] - (.-.) - [0.43 Ko] - (0.0.0.0) - C:\WINDOWS\System32\OkDone_80.contrast-white.png [MD5.F3DC097E834C1A11F2BEDFD429C644A9] - |A| - [19/03/2019 05:44:21] - (.-.) - [0.41 Ko] - (0.0.0.0) - C:\WINDOWS\System32\OkDone_80.png [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [16122.6 Ko] - C:\WINDOWS\System32\oobe [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 13:01:40] - [3554.5 Ko] - C:\WINDOWS\System32\OpenSSH [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\or-IN [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [3.81 Ko] - C:\WINDOWS\System32\osa-Osge-001 [MD5.459FB33AA2114A28C5932FEAA115B072] - |A| - [19/03/2019 05:43:47] - (.-.) - [45.82 Ko] - (0.0.0.0) - C:\WINDOWS\System32\OutdoorAudioEnvironment.bin [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\pa-Arab-PK [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\pa-IN [MD5.652F1F54E573AF4D59E0AE658376D077] - |A| - [11/02/2011 22:23:34] - (.Copyright © 2005-2010 CACE Technologies. Copyright © 1999-2005 NetGroup, Politecnico di Torino. - packet.dll (Vista) Dynamic Link Library.) - [103.52 Ko] - (4.1.0.2001) - C:\WINDOWS\System32\packet.dll [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [1728.68 Ko] - C:\WINDOWS\System32\PerceptionSimulation [MD5.A821A094FD06EF79C56D467E30C6644D] - |A| - [19/03/2019 05:55:38] - (.-.) - [130.71 Ko] - (0.0.0.0) - C:\WINDOWS\System32\perfc009.dat [MD5.7FF4ED3B7629DA18AB985775D56BA519] - |A| - [19/03/2019 13:00:42] - (.-.) - [146.49 Ko] - (0.0.0.0) - C:\WINDOWS\System32\perfc00C.dat [MD5.1E60BC5E525063B96078DF17FBD3C4E1] - |A| - [19/03/2019 05:55:38] - (.-.) - [32.64 Ko] - (0.0.0.0) - C:\WINDOWS\System32\perfd009.dat [MD5.9F9AF8517189B0D61B2615007E071084] - |A| - [19/03/2019 13:00:42] - (.-.) - [39.74 Ko] - (0.0.0.0) - C:\WINDOWS\System32\perfd00C.dat [MD5.E5BB32372EB6D56F560BD7B1DD2A40FD] - |A| - [19/03/2019 05:55:38] - (.-.) - [686.14 Ko] - (0.0.0.0) - C:\WINDOWS\System32\perfh009.dat [MD5.79F09D42231CF4E4AF725FD14DA309C8] - |A| - [19/03/2019 13:00:42] - (.-.) - [773.38 Ko] - (0.0.0.0) - C:\WINDOWS\System32\perfh00C.dat [MD5.79E26B97E000008D346E0FE9F9680F01] - |A| - [07/08/2019 15:51:05] - (.-.) - [1731.73 Ko] - (0.0.0.0) - C:\WINDOWS\System32\PerfStringBackup.INI [MD5.79D34E3B62076D4C875C748F5BE71ECA] - |A| - [19/03/2019 05:43:45] - (.-.) - [2.21 Ko] - (0.0.0.0) - C:\WINDOWS\System32\PhoneSystemToastIcon.contrast-white.png [MD5.4D9495349D00D9AD907F227FF51F289F] - |A| - [19/03/2019 05:43:45] - (.-.) - [1.92 Ko] - (0.0.0.0) - C:\WINDOWS\System32\PhoneSystemToastIcon.png [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [430 Ko] - C:\WINDOWS\System32\pl-PL [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [448 Ko] - C:\WINDOWS\System32\PointOfService [MD5.77D96999819206E9208DF12819E5DBA7] - |A| - [19/03/2019 05:44:12] - (.-.) - [42.5 Ko] - (0.0.0.0) - C:\WINDOWS\System32\pospaymentsworker.exe [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 13:00:41] - [420.74 Ko] - C:\WINDOWS\System32\Printing_Admin_Scripts [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [0 Ko] - C:\WINDOWS\System32\ProximityToast [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\prs-AF [MD5.007893E8374C766471239EB291BA8C17] - |A| - [19/03/2019 05:44:00] - (.-.) - [4.05 Ko] - (0.0.0.0) - C:\WINDOWS\System32\psmodulediscoveryprovider.mof [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [424 Ko] - C:\WINDOWS\System32\pt-BR [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [426.5 Ko] - C:\WINDOWS\System32\pt-PT [MD5.C32ECB99AD25E9A04F01C8665DF29EF8] - |A| - [22/10/2017 17:22:06] - (.-.) - [18.7 Ko] - (0.0.0.0) - C:\WINDOWS\System32\pwdrvio.sys [MD5.D619356B955EEFA642F5FF72755E8B3C] - |A| - [22/10/2017 17:22:06] - (.-.) - [12.21 Ko] - (0.0.0.0) - C:\WINDOWS\System32\pwdspio.sys [MD5.CC2BDE8319ED1C3BC60513E0A6037549] - |A| - [22/10/2017 17:22:31] - (.-.) - [3516.5 Ko] - (0.0.0.0) - C:\WINDOWS\System32\pwNative.exe [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\quc-Latn-GT [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\quz-PE [MD5.8882AD10853E45402CABD3BAF48A7EFC] - |A| - [30/01/2014 17:35:31] - (.©2012 Dolby Laboratories. - Dolby PCEE4 ASL Analog x64.) - [121.27 Ko] - (7.2.8000.17) - C:\WINDOWS\System32\R4EEA64A.dll [MD5.0B5EF50E26CFD1E7BF01E32E053532B2] - |A| - [30/01/2014 17:35:31] - (.©2012 Dolby Laboratories. - Dolby PCEE4 COM DLL x64.) - [424.77 Ko] - (7.2.8000.17) - C:\WINDOWS\System32\R4EED64A.dll [MD5.01096663377134C41D618AF0E53A953E] - |A| - [30/01/2014 17:35:31] - (.©2012 Dolby Laboratories. - Dolby PCEE4 GFX APO x64.) - [73.27 Ko] - (7.2.8000.17) - C:\WINDOWS\System32\R4EEG64A.dll [MD5.D0EB28022A91A5C084E8A7DEBB08D8D2] - |A| - [30/01/2014 17:35:31] - (.©2012 Dolby Laboratories. - Dolby PCEE4 LFX APO x64.) - [138.27 Ko] - (7.2.8000.17) - C:\WINDOWS\System32\R4EEL64A.dll [MD5.03625A179B27362D3A90E3331AEBE95E] - |A| - [30/01/2014 17:35:32] - (.©2012 Dolby Laboratories. - Dolby PCEE4 Control Panel x64.) - [6996.27 Ko] - (7.2.8000.17) - C:\WINDOWS\System32\R4EEP64A.dll [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [23.75 Ko] - C:\WINDOWS\System32\ras [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [0 Ko] - C:\WINDOWS\System32\RasToast [MD5.2210F24EDC6E80B1D311B2C3641DE9FA] - |A| - [14/08/2019 16:06:49] - (.-.) - [1983.5 Ko] - (1.0.1907.17001) - C:\WINDOWS\System32\rdpnano.dll [MD5.D8D02FD6073373A537FC0C1024E7C6DA] - |A| - [19/03/2019 05:43:47] - (.-.) - [60.5 Ko] - (0.0.0.0) - C:\WINDOWS\System32\rdsxvmaudio.dll [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [2.18 Ko] - C:\WINDOWS\System32\Recovery [MD5.953D6BA53592F631F09CC61AAAD0606C] - |A| - [08/01/2019 22:23:37] - (.-.) - [0.32 Ko] - (0.0.0.0) - C:\WINDOWS\System32\RegDefragNT 2019-01-08 22-08-08.log [MD5.826549DF7B1333179BA8CA939B12DAD3] - |A| - [19/03/2019 05:43:45] - (.-.) - [1.58 Ko] - (0.0.0.0) - C:\WINDOWS\System32\RemoteSystemToastIcon.contrast-white.png [MD5.B4DEEC96F9DF6961D5DE054F11BF9C2B] - |A| - [19/03/2019 05:43:45] - (.-.) - [1.1 Ko] - (0.0.0.0) - C:\WINDOWS\System32\RemoteSystemToastIcon.png [MD5.1B7341B9AAFB4925790B5C37C10F285A] - |A| - [09/10/2019 11:08:30] - (.-.) - [107.5 Ko] - (0.0.0.0) - C:\WINDOWS\System32\ResBParser.dll [MD5.1FB4B6A26FEEF4A99B7D0ECD2ADDF075] - |A| - [19/03/2019 05:45:56] - (.-.) - [9.19 Ko] - (0.0.0.0) - C:\WINDOWS\System32\ResPriHMImageList [MD5.93915F385A4EED6C0FBEE364EA90CE56] - |A| - [19/03/2019 05:45:56] - (.-.) - [9.09 Ko] - (0.0.0.0) - C:\WINDOWS\System32\ResPriHMImageListLowCost [MD5.39BB5D2A5EC1CBDD722CAB7BDCEC41F5] - |A| - [19/03/2019 05:45:56] - (.-.) - [8.64 Ko] - (0.0.0.0) - C:\WINDOWS\System32\ResPriImageList [MD5.39A2449AFF6ABAD80B97EA7C7CEB3F8E] - |A| - [19/03/2019 05:45:56] - (.-.) - [8.53 Ko] - (0.0.0.0) - C:\WINDOWS\System32\ResPriImageListLowCost [MD5.831C579709F4761E4AB7053FCF4176EC] - |A| - [19/03/2019 05:44:21] - (.-.) - [0.74 Ko] - (0.0.0.0) - C:\WINDOWS\System32\RestartNowPower_80.contrast-black.png [MD5.DF286186041C6BF73C5DC21CEEEFFED5] - |A| - [19/03/2019 05:44:21] - (.-.) - [0.77 Ko] - (0.0.0.0) - C:\WINDOWS\System32\RestartNowPower_80.contrast-white.png [MD5.831C579709F4761E4AB7053FCF4176EC] - |A| - [19/03/2019 05:44:21] - (.-.) - [0.74 Ko] - (0.0.0.0) - C:\WINDOWS\System32\RestartNowPower_80.png [MD5.AE9FE55FED83149715734CB83339055A] - |A| - [19/03/2019 05:44:21] - (.-.) - [1.07 Ko] - (0.0.0.0) - C:\WINDOWS\System32\RestartTonight_80.png [MD5.AE9FE55FED83149715734CB83339055A] - |A| - [19/03/2019 05:44:21] - (.-.) - [1.07 Ko] - (0.0.0.0) - C:\WINDOWS\System32\RestartTonight_80_contrast-black.png [MD5.891AD355AB777A95695FC8A8A623A614] - |A| - [19/03/2019 05:44:21] - (.-.) - [0.98 Ko] - (0.0.0.0) - C:\WINDOWS\System32\RestartTonight_80_contrast-white.png [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [0.07 Ko] - C:\WINDOWS\System32\restore [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [351 Ko] - C:\WINDOWS\System32\ro-RO [MD5.E9D4A333DF15D06C68AC4BFB9B6581CB] - |A| - [30/01/2014 17:35:39] - (.© 2008,2009 Dolby Laboratories, Inc. - PCEE3 DAA Control Panel x64.) - [302.84 Ko] - (6.0.6001.18) - C:\WINDOWS\System32\RP3DAA64.dll [MD5.B6FE01558CC03F3866C9AD0ED19261D8] - |A| - [30/01/2014 17:35:39] - (.© 2008,2009 Dolby Laboratories, Inc. - PCEE3 DHT Control Panel x64.) - [302.84 Ko] - (6.0.6001.18) - C:\WINDOWS\System32\RP3DHT64.dll [MD5.A6286A6C7A1BBFCBA17AA54384A21D1C] - |A| - [30/01/2014 17:35:39] - (.©2009 Dolby Laboratories, Inc. - Dolby PCEE3 COM DLL x64.) - [199.34 Ko] - (6.1.6001.33) - C:\WINDOWS\System32\RTEED64A.dll [MD5.6F4CD493196100EEF349D7132CECAFD9] - |A| - [30/01/2014 17:35:39] - (.©2009 Dolby Laboratories, Inc. - Dolby PCEE3 GFX APO x64.) - [76.84 Ko] - (6.1.6001.33) - C:\WINDOWS\System32\RTEEG64A.dll [MD5.ECAEC5FBBBEF8612AF0A866AFA5F7EF2] - |A| - [30/01/2014 17:35:39] - (.©2009 Dolby Laboratories, Inc. - Dolby PCEE3 LFX APO x64.) - [98.84 Ko] - (6.1.6001.33) - C:\WINDOWS\System32\RTEEL64A.dll [MD5.D0D0D82B7366E691275E433CD34F89B2] - |A| - [30/01/2014 17:35:39] - (.©2009 Dolby Laboratories, Inc. - Dolby PCEE3 Control Panel x64.) - [366.34 Ko] - (6.1.6001.33) - C:\WINDOWS\System32\RTEEP64A.dll [MD5.96152E718069C25B655A36C82302CF65] - |A| - [30/01/2014 17:35:40] - (.Copyright © 2013 ASUSTeKcomputer.Inc Inc. All rights reserved - Nahimic APO lfx dll.) - [4817.7 Ko] - (6.3.9431.0) - C:\WINDOWS\System32\RTKSMlfx.dll [MD5.6E45F7A007A8848A9C0C3D0CC5DD1A21] - |A| - [30/01/2014 17:35:39] - (.Copyright © 2013 ASUSTeKcomputer.Inc Inc. All rights reserved - Nahimic APO Settings Communication Dll.) - [828.3 Ko] - (1.1.0.13528) - C:\WINDOWS\System32\RTKSMSettingsIPC.dll [MD5.AA694008D3068ED546D9DF920BF5300D] - |A| - [19/03/2019 05:44:35] - (.-.) - [57.5 Ko] - (0.0.0.0) - C:\WINDOWS\System32\runexehelper.exe [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\rw-RW [MD5.FDAA0481952E2154C77D5A9D133975D6] - |A| - [09/05/2018 09:00:46] - (.-.) - [54 Ko] - (1.8.3.0) - C:\WINDOWS\System32\SaErHdlr.dll [MD5.76C637C04F7193F56305AEA076A43D76] - |A| - [09/05/2018 09:00:46] - (.-.) - [109.5 Ko] - (1.8.3.0) - C:\WINDOWS\System32\SaImgFlt.dll [MD5.43DDD5F5176A2F31E91D777B9B8321DD] - |A| - [09/05/2018 09:00:46] - (.-.) - [357 Ko] - (1.8.3.0) - C:\WINDOWS\System32\SaMinDrv.dll [MD5.2CF34465F8DE12B1BF00CD8B9C22846E] - |A| - [09/05/2018 09:00:19] - (.Copyright 2012 - Samsung Electronics.) - [221.12 Ko] - (1.0.0.6) - C:\WINDOWS\System32\SBuySupplies.exe [MD5.5C18CD22BE4628865FCB63337A6E5EF6] - |A| - [19/03/2019 05:46:39] - (.-.) - [10.18 Ko] - (0.0.0.0) - C:\WINDOWS\System32\ScavengeSpace.xml [MD5.2F24BC74DCB28FE032C1596755385917] - |A| - [19/03/2019 05:44:21] - (.-.) - [0.53 Ko] - (0.0.0.0) - C:\WINDOWS\System32\ScheduleTime_80.contrast-black.png [MD5.E72B1B6800DE45AA9AE7E10F899E5999] - |A| - [19/03/2019 05:44:21] - (.-.) - [0.54 Ko] - (0.0.0.0) - C:\WINDOWS\System32\ScheduleTime_80.contrast-white.png [MD5.2F24BC74DCB28FE032C1596755385917] - |A| - [19/03/2019 05:44:21] - (.-.) - [0.53 Ko] - (0.0.0.0) - C:\WINDOWS\System32\ScheduleTime_80.png [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\sd-Arab-PK [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [6.92 Ko] - C:\WINDOWS\System32\SecureBootUpdates [MD5.A8308D2F3DDE0745E8B678BF69A2ECD0] - |A| - [19/03/2019 05:44:01] - (.-.) - [8 Ko] - (0.0.0.0) - C:\WINDOWS\System32\settings.dat [MD5.17ABCAD44A75C635583A238ED6333357] - |A| - [30/01/2014 17:35:44] - (.Copyright (c) 2006-2011 Synopsys, Inc. All Rights Reserved - SFAPO.DLL.) - [76.84 Ko] - (3.0.0.16) - C:\WINDOWS\System32\SFAPO64.dll [MD5.2C25AF115BDDC05D9A84D26227A08E63] - |A| - [30/01/2014 17:35:44] - (.Copyright (c) 2006-2011 Synopsys, Inc. All Rights Reserved - SFCOM.DLL.) - [79.34 Ko] - (3.0.0.16) - C:\WINDOWS\System32\SFCOM64.dll [MD5.7B3E9344FB43D799C6462227A0E65877] - |A| - [30/01/2014 17:35:44] - (.Copyright (c) 2006-2011 Synopsys, Inc. All Rights Reserved - SFNHK.DLL.) - [215.84 Ko] - (3.0.0.16) - C:\WINDOWS\System32\SFNHK64.dll [MD5.D1A3064BD95D337804EFCF6D8C03B406] - |A| - [30/01/2014 17:35:48] - (.Copyright (C) 2013 DTS, Inc. - DTS Studio Sound.) - [876.75 Ko] - (3.1.10.0) - C:\WINDOWS\System32\sl3apo64.dll [MD5.CC0434CBB00ECF7B4FDD072A4101AC60] - |A| - [30/01/2014 17:35:49] - (.Copyright (C) 2011 SRS Labs, Inc. - SRS Labs.) - [990.25 Ko] - (3.1.10.0) - C:\WINDOWS\System32\slcnt64.dll [MD5.00000000000000000000000000000000] - |D| - [07/08/2019 15:44:33] - [102201.94 Ko] - C:\WINDOWS\System32\SleepStudy [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 13:00:41] - [52.14 Ko] - C:\WINDOWS\System32\slmgr [MD5.D29D34D0AF33EDD9D604816154CBFE6A] - |A| - [30/01/2014 17:35:49] - (.TODO: (c) . - TODO: .) - [238.75 Ko] - (1.0.0.1) - C:\WINDOWS\System32\slprp64.dll [MD5.43B0E62B728A04A73FE6FAE3274FFEE7] - |A| - [30/01/2014 17:35:49] - (.Copyright (C) 2013 DTS, Inc. - DTS Studio Sound.) - [705.75 Ko] - (3.1.10.0) - C:\WINDOWS\System32\sltech64.dll [MD5.DAC275ABAAD2B689D7BB3685E4032072] - |A| - [19/03/2019 05:43:47] - (.-.) - [68.15 Ko] - (0.0.0.0) - C:\WINDOWS\System32\SmallRoom.bin [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:37:22] - [16445.02 Ko] - C:\WINDOWS\System32\SMI [MD5.55121989BE7B289813D419BA0FDEE8B7] - |A| - [19/03/2019 05:44:21] - (.-.) - [0.9 Ko] - (0.0.0.0) - C:\WINDOWS\System32\Snooze_80.contrast-black.png [MD5.E30B7D226E7B5B0EC2B9FC2316694ECC] - |A| - [19/03/2019 05:44:21] - (.-.) - [0.88 Ko] - (0.0.0.0) - C:\WINDOWS\System32\Snooze_80.contrast-white.png [MD5.55121989BE7B289813D419BA0FDEE8B7] - |A| - [19/03/2019 05:44:21] - (.-.) - [0.9 Ko] - (0.0.0.0) - C:\WINDOWS\System32\Snooze_80.png [MD5.DE3EAAF17BC934C77C4FC0C626EEA03B] - |A| - [19/03/2019 05:43:45] - (.-.) - [1.48 Ko] - (0.0.0.0) - C:\WINDOWS\System32\SpeakersSystemToastIcon.contrast-white.png [MD5.3308374DB8D20CFDA4D4204E2B5E559E] - |A| - [19/03/2019 05:43:45] - (.-.) - [0.88 Ko] - (0.0.0.0) - C:\WINDOWS\System32\SpeakersSystemToastIcon.png [MD5.CEDAB194F8B9DADA895371B4560B97F0] - |A| - [19/03/2019 05:45:54] - (.-.) - [38 Ko] - (0.0.0.0) - C:\WINDOWS\System32\SpectrumSyncClient.dll [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [7558.3 Ko] - C:\WINDOWS\System32\Speech [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [12411.23 Ko] - C:\WINDOWS\System32\Speech_OneCore [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [247933.78 Ko] - C:\WINDOWS\System32\spool [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [5982 Ko] - C:\WINDOWS\System32\spp [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [23.61 Ko] - C:\WINDOWS\System32\sppui [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\sq-AL [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\sr-Cyrl-BA [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\sr-Cyrl-RS [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 12:47:48] - [0 Ko] - C:\WINDOWS\System32\sr-Latn-CS [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [339 Ko] - C:\WINDOWS\System32\sr-Latn-RS [MD5.DC9450258D80F46AEF8EF063A7C629B0] - |A| - [19/03/2019 05:45:56] - (.-.) - [19.03 Ko] - (0.0.0.0) - C:\WINDOWS\System32\srms-apr.dat [MD5.763BCEE61F573235E1C60E80438AC301] - |A| - [07/08/2019 16:21:14] - (.-.) - [57.45 Ko] - (0.0.0.0) - C:\WINDOWS\System32\srms.dat [MD5.A88BE9A6C4E646A2B2A1BD3A7F4B58E7] - |A| - [30/01/2014 17:35:44] - (.(c) 2007 SRS Labs, Inc. - COM object implementing SRS Headphone 360.) - [194.23 Ko] - (1.1.0.0) - C:\WINDOWS\System32\SRSHP64.dll [MD5.A028717B791416182959B325D5B40679] - |A| - [30/01/2014 17:35:44] - (.Copyright (c) 2006 SRS Labs, Inc.. - TruSurround HD and HD4 COM object for Windows.) - [206.23 Ko] - (1.1.4.0) - C:\WINDOWS\System32\SRSTSH64.dll [MD5.018D3D2478754AA411DE6DA6DE5F8F21] - |A| - [30/01/2014 17:35:45] - (.Copyright 2002 SRS Labs, Inc. - TruSurroundXT Module.) - [506.73 Ko] - (3.2.0.0) - C:\WINDOWS\System32\SRSTSX64.dll [MD5.2FCADCC14F8E540F6ADE4BF92BD8AEDD] - |A| - [30/01/2014 17:35:45] - (.(c) 2006 SRS Labs, Inc. - WOW HD COM object for Windows.) - [152.23 Ko] - (1.1.3.0) - C:\WINDOWS\System32\SRSWOW64.dll [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [84184 Ko] - C:\WINDOWS\System32\sru [MD5.4A0E4F3F234BF24F7657CF184AE77437] - |A| - [09/05/2018 09:00:46] - (.- Device Monitor.) - [85.5 Ko] - (1.6.2.0) - C:\WINDOWS\System32\Ssdevm64.dll [MD5.EBF15D23B92DE845AC8C952AE9153492] - |A| - [19/03/2019 05:43:47] - (.-.) - [443 Ko] - (0.0.0.0) - C:\WINDOWS\System32\ssdm.dll [MD5.FC21BF5A1667FC745FE53D05DA4CB8A2] - |A| - [09/05/2018 09:00:03] - (.Copyright (C) 2004 Co., Ltd. - SSCoInst.) - [87.5 Ko] - (1.0.0.4) - C:\WINDOWS\System32\ssm4mci.dll [MD5.627C52B757CA8C3F02F917D85172759B] - |A| - [09/05/2018 09:00:19] - (.Copyright © 2006 - SSCoInstExe.) - [154.34 Ko] - (1.0.1.1) - C:\WINDOWS\System32\ssm4mci.exe [MD5.DBAB523742E598670B37A65B16528CE1] - |A| - [09/05/2018 09:00:09] - (.- Language Monitor for Status Monitor.) - [22 Ko] - (1.4.9.0) - C:\WINDOWS\System32\ssm4mlm.dll [MD5.6E11B91919B819CBE7E9FE211D9E8149] - |A| - [09/05/2018 09:00:46] - (.- USB Device.) - [48 Ko] - (1.0.1.0) - C:\WINDOWS\System32\Ssusbp64.dll [MD5.012C220E771B242FE60726CA618B3904] - |A| - [17/08/2015 17:29:32] - (.© PoINT Software & Systems GmbH 1994-2012 - PoINT Shared DLL.) - [70.82 Ko] - (3.0.0.25) - C:\WINDOWS\System32\STRING64.dll [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [403.5 Ko] - C:\WINDOWS\System32\sv-SE [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\sw-KE [MD5.8F7C05071687E36B92D9A5C11490DD21] - |A| - [16/11/2019 18:10:50] - (.-.) - [0.31 Ko] - (0.0.0.0) - C:\WINDOWS\System32\swhealthex.log [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:43] - [1389.13 Ko] - C:\WINDOWS\System32\Sysprep [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [939.78 Ko] - C:\WINDOWS\System32\SystemResetPlatform [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [10.73 Ko] - C:\WINDOWS\System32\ta-in [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [10.73 Ko] - C:\WINDOWS\System32\ta-lk [MD5.5F6B04A0EC5FE46FEEEC887406F63E57] - |A| - [19/03/2019 05:45:35] - (.Copyright (c) libarchive authors - bsdtar archive tool.) - [49.5 Ko] - (3.3.2.0) - C:\WINDOWS\System32\tar.exe [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [757.76 Ko] - C:\WINDOWS\System32\Tasks [MD5.00000000000000000000000000000000] - |D| - [15/09/2018 08:33:50] - [734.96 Ko] - C:\WINDOWS\System32\Tasks_Migrated [MD5.D602CA245CC6774A0981B607F0675609] - |A| - [19/03/2019 05:45:00] - (.-.) - [58.71 Ko] - (0.0.0.0) - C:\WINDOWS\System32\tcpmon.ini [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\te-IN [MD5.364B8B76EBB95762632341E49F26144D] - |A| - [07/08/2019 16:20:43] - (.-.) - [1798 Ko] - (0.0.0.0) - C:\WINDOWS\System32\TextInputMethodFormatter.dll [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\tg-Cyrl-TJ [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [310.5 Ko] - C:\WINDOWS\System32\th-TH [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [5.97 Ko] - C:\WINDOWS\System32\ti-et [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\tk-TM [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\tn-ZA [MD5.B88B8D017386A00D7724519F475317A0] - |A| - [19/03/2019 05:43:54] - (.-.) - [10.33 Ko] - (0.0.0.0) - C:\WINDOWS\System32\TransformPPSToWlan.xslt [MD5.2F05390B798363D51EBE65D6320CD45E] - |A| - [19/03/2019 05:43:54] - (.-.) - [1.65 Ko] - (0.0.0.0) - C:\WINDOWS\System32\TransformPPSToWlanCredentials.xslt [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\tt-RU [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\ug-CN [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [337 Ko] - C:\WINDOWS\System32\uk-UA [MD5.B9A75ED4500DD953DF172FE6F63578E8] - |A| - [19/03/2019 05:43:49] - (.-.) - [53.67 Ko] - (0.0.0.0) - C:\WINDOWS\System32\umpdc.dll [MD5.00000000000000000000000000000000] - |SD| - [19/03/2019 05:52:45] - [1917.6 Ko] - C:\WINDOWS\System32\UNP [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\ur-PK [MD5.C5051D8BC14B8A4C3C1F4F8CDA648C3F] - |A| - [09/10/2019 11:07:59] - (.-.) - [46.5 Ko] - (0.0.0.0) - C:\WINDOWS\System32\UsbPmApi.dll [MD5.BAB4BA3C107F89955FABD06688B232F0] - |A| - [07/08/2019 16:20:45] - (.-.) - [37 Ko] - (0.0.0.0) - C:\WINDOWS\System32\usocoreps.dll [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\uz-Latn-UZ [MD5.00000000000000000000000000000000] - |D| - [24/11/2014 18:41:03] - [10686.42 Ko] - C:\WINDOWS\System32\vbox [MD5.83A083A42F97BCF3F8E016820178DDE2] - |A| - [25/01/2018 15:31:32] - (.Copyright © 1998, Voxware, Inc. - Voxware Audio Compression Manager Driver.) - [81 Ko] - (1.6.0.17) - C:\WINDOWS\System32\vct3216.acm [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\vi-VN [MD5.E9A66CB07CCDB9B99F084315E04FCBC7] - |A| - [19/03/2019 05:59:03] - (.-.) - [92.5 Ko] - (0.0.0.0) - C:\WINDOWS\System32\VirtualMonitorManager.dll [MD5.FAC0D5B16EFA7376CA81047490187D0D] - |A| - [25/01/2018 15:31:32] - (.Copyright © 2000-3 ON2 Technologies - VP6 VIDEO FOR WINDOWS CODEC.) - [428 Ko] - (6.4.2.0) - C:\WINDOWS\System32\vp6vfw.dll [MD5.6651B57DA6B6740436A021419900FC00] - |A| - [15/12/2019 21:00:51] - (.Copyright (C) 2015-2019 - Vulkan Loader.) - [1053.91 Ko] - (1.1.126.0) - C:\WINDOWS\System32\vulkan-1-999-0-0-0.dll [MD5.6651B57DA6B6740436A021419900FC00] - |A| - [15/12/2019 21:00:51] - (.Copyright (C) 2015-2019 - Vulkan Loader.) - [1053.91 Ko] - (1.1.126.0) - C:\WINDOWS\System32\vulkan-1.dll [MD5.39FCE1BD81E0395909E2A43087076EC9] - |A| - [15/12/2019 21:00:51] - (.Copyright (C) 2015-2019 - Vulkan Info.) - [1688.91 Ko] - (1.1.126.0) - C:\WINDOWS\System32\vulkaninfo-1-999-0-0-0.exe [MD5.39FCE1BD81E0395909E2A43087076EC9] - |A| - [15/12/2019 21:00:51] - (.Copyright (C) 2015-2019 - Vulkan Info.) - [1688.91 Ko] - (1.1.126.0) - C:\WINDOWS\System32\vulkaninfo.exe [MD5.251B5B37D9ED5E66E3D632F588D91829] - |A| - [30/01/2014 17:35:45] - (.Copyright © 1996-2012 - General Library for Plug-Ins.) - [2053.75 Ko] - (4.4.3.0) - C:\WINDOWS\System32\WavesGUILib64.dll [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [139003.16 Ko] - C:\WINDOWS\System32\wbem [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 13:00:41] - [0 Ko] - C:\WINDOWS\System32\WCN [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [136800.81 Ko] - C:\WINDOWS\System32\WDI [MD5.6EDD021A8B6457DDE09DE7B7FA4E8C8B] - |A| - [19/03/2019 05:44:30] - (.-.) - [0.6 Ko] - (0.0.0.0) - C:\WINDOWS\System32\WdsUnattendTemplate.xml [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 16:36:30] - [0 Ko] - C:\WINDOWS\System32\wfp [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [1.12 Ko] - C:\WINDOWS\System32\WinBioDatabase [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [49316.93 Ko] - C:\WINDOWS\System32\WinBioPlugIns [MD5.081B2511702120CAD13D4AE66E309956] - |A| - [26/08/2016 15:54:00] - (.Copyright © 2018 - Java(TM) Platform SE binary.) - [141.87 Ko] - (10.0.2.0) - C:\WINDOWS\System32\WindowsAccessBridge-64.dll [MD5.8B956E4F6378335CC19BE3296A6C9B7E] - |A| - [19/03/2019 05:44:11] - (.-.) - [122 Ko] - (0.0.0.0) - C:\WINDOWS\System32\WindowsDefaultHeatProcessor.dll [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 16:36:31] - [14.53 Ko] - C:\WINDOWS\System32\WindowsInternal.Inbox.Media.Shared [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 16:36:31] - [27.59 Ko] - C:\WINDOWS\System32\WindowsInternal.Inbox.Shared [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [10589.58 Ko] - C:\WINDOWS\System32\WindowsPowerShell [MD5.28E98ED0B6B08B7F1D163FFD184B28AF] - |A| - [19/03/2019 05:44:39] - (.-.) - [0.74 Ko] - (0.0.0.0) - C:\WINDOWS\System32\WindowsSecurityIcon.png [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [177788 Ko] - C:\WINDOWS\System32\winevt [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [6163.84 Ko] - C:\WINDOWS\System32\WinMetadata [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 13:00:41] - [107.56 Ko] - C:\WINDOWS\System32\winrm [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\wo-SN [MD5.A2473CC88ABA67391CE7929E5C69E767] - |A| - [11/02/2011 22:23:34] - (.Copyright © 2005-2010 CACE Technologies. Copyright © 1999-2005 NetGroup, Politecnico di Torino. - wpcap.dll Dynamic Link Library - based on libpcap 1.0rel0b branch (20091008).) - [360.52 Ko] - (4.1.0.2001) - C:\WINDOWS\System32\wpcap.dll [MD5.1B46E2E85D401A629966A8F62D9B0775] - |A| - [19/03/2019 05:43:52] - (.-.) - [9.91 Ko] - (0.0.0.0) - C:\WINDOWS\System32\wpcatltoast.png [MD5.C30C621748C66CE751B19B2788559A3E] - |A| - [19/03/2019 05:43:52] - (.-.) - [4.58 Ko] - (0.0.0.0) - C:\WINDOWS\System32\wpcmon.png [MD5.69FEC1494F4C454E994D27CA6750832B] - |A| - [19/03/2019 05:44:35] - (.-.) - [0.71 Ko] - (0.0.0.0) - C:\WINDOWS\System32\wpr.config.xml [MD5.2DE2D263D2C5739AB4A37C5616ABA671] - |A| - [19/03/2019 05:44:03] - (.-.) - [97 Ko] - (0.0.0.0) - C:\WINDOWS\System32\xboxgipsynthetic.dll [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\xh-ZA [MD5.1D9FB9784F32276EFB43512A81217753] - |A| - [25/01/2018 15:31:32] - (.-.) - [52 Ko] - (0.0.0.0) - C:\WINDOWS\System32\xvid.ax [MD5.0B86EF053161AA4AC3F973FE370EED96] - |A| - [25/01/2018 15:31:32] - (.-.) - [512 Ko] - (0.0.0.0) - C:\WINDOWS\System32\xvidcore.dll [MD5.E8F602CA1E700496240CF07D9681D040] - |A| - [25/01/2018 15:31:32] - (.-.) - [136 Ko] - (0.0.0.0) - C:\WINDOWS\System32\xvidvfw.dll [MD5.F7B865265606C41B0E07779D3317E0A8] - |A| - [19/03/2019 05:44:21] - (.-.) - [0.61 Ko] - (0.0.0.0) - C:\WINDOWS\System32\X_80.contrast-black.png [MD5.6FF92221AF9D6CDF0966C4E44C367975] - |A| - [19/03/2019 05:44:21] - (.-.) - [0.57 Ko] - (0.0.0.0) - C:\WINDOWS\System32\X_80.contrast-white.png [MD5.F7B865265606C41B0E07779D3317E0A8] - |A| - [19/03/2019 05:44:21] - (.-.) - [0.61 Ko] - (0.0.0.0) - C:\WINDOWS\System32\X_80.png [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\yo-NG [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [287.99 Ko] - C:\WINDOWS\System32\zh-CN [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 12:47:48] - [3 Ko] - C:\WINDOWS\System32\zh-HK [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:45] - [258 Ko] - C:\WINDOWS\System32\zh-TW [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\System32\zu-ZA [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 13:00:41] - [0 Ko] - C:\WINDOWS\SysWOW64\0409 [MD5.D6F8DD9F561B8A67FFAC2BAD7E989770] - |A| - [19/03/2019 05:45:19] - (.-.) - [0.23 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\@AppHelpToast.png [MD5.82C37C3E27020AF6C2E018E944284676] - |A| - [19/03/2019 05:45:19] - (.-.) - [0.3 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\@AudioToastIcon.png [MD5.495C1F072039B434827A5FE0D9761E4D] - |A| - [19/03/2019 05:45:22] - (.-.) - [0.32 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\@EnrollmentToastIcon.png [MD5.1622DE67156496C78D6B7BE9B471645B] - |A| - [19/03/2019 05:45:30] - (.-.) - [0.39 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\@VpnToastIcon.png [MD5.DB71001FC261F6685BE410527DAE3942] - |A| - [19/03/2019 05:45:13] - (.-.) - [0.67 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\@WirelessDisplayToast.png [MD5.6A4AD03E8F28AF407EB21C848726A446] - |A| - [26/03/2019 15:54:52] - (.-.) - [0.3 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\AbBakConfig.dat [MD5.59683D1E4CD0B1AD6AE32E1D627AE25F] - |A| - [18/08/2017 08:57:50] - (.Copyright © 2003 by fccHandler - AC-3 ACM Decompressor.) - [80 Ko] - (0.7.0.0) - C:\WINDOWS\SysWOW64\AC3ACM.acm [MD5.00000000000000000000000000000000] - |AD| - [12/02/2014 14:34:38] - [25604.89 Ko] - C:\WINDOWS\SysWOW64\Adobe [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:46] - [1856.8 Ko] - C:\WINDOWS\SysWOW64\AdvancedInstallers [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\af-ZA [MD5.8210141840CE237FBF40B6E26E2DD11D] - |A| - [18/08/2017 08:57:50] - (.NCT Company Copyright 1999 - 2001 - NCT ALF2CD Audio CODEC.) - [38 Ko] - (2.3.1.0) - C:\WINDOWS\SysWOW64\alf2cd.acm [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\am-ET [MD5.12F9554C965A20215596F42DA0BE8B1F] - |A| - [31/10/2019 22:37:18] - (.-.) - [34.92 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\ampa.sys [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:46] - [0 Ko] - C:\WINDOWS\SysWOW64\AppLocker [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:46] - [174 Ko] - C:\WINDOWS\SysWOW64\ar-SA [MD5.7230E04E6BD86FFE4E1034D9B3B893A3] - |A| - [19/03/2019 05:45:59] - (.Copyright (c) libarchive authors - Windows-internal libarchive library.) - [520 Ko] - (3.3.2.0) - C:\WINDOWS\SysWOW64\archiveint.dll [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\as-IN [MD5.8128B54EAA48F9C06B19A86C87752996] - |A| - [10/04/2017 17:52:38] - (.Copyright (C) 2010 - AsIO DLL.) - [28 Ko] - (1.0.0.4) - C:\WINDOWS\SysWOW64\AsIO.dll [MD5.66DA00F60B7D8A9B2490024B79F33077] - |A| - [06/02/2014 19:27:15] - (.-.) - [6.9 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\audiopid.vxd [MD5.095D51E19AA5887A6218641AF6694FF0] - |A| - [21/03/2014 22:33:37] - (.Copyright AVerMedia TECHNOLOGIES, Inc. 2005 - AVerIO.) - [48 Ko] - (2.1.0.1) - C:\WINDOWS\SysWOW64\AVerIO.dll [MD5.59DCD600DBC998C4CCAEBAC1B98C7805] - |A| - [21/03/2014 22:33:37] - (.-.) - [3.38 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\AVerIO.sys [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\az-Latn-AZ [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\be-BY [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:46] - [147.5 Ko] - C:\WINDOWS\SysWOW64\bg-BG [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\bn-BD [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\bn-IN [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\bs-Latn-BA [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:46] - [0.1 Ko] - C:\WINDOWS\SysWOW64\Bthprops [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\ca-ES [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\ca-ES-valencia [MD5.D3A86DD6E4CA49228F7416013D966482] - |A| - [04/06/2014 14:41:10] - (.-.) - [2.22 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\Cam122.ini [MD5.361F47233F9447A3905593817A6E2BFA] - |A| - [21/03/2014 22:33:37] - (.Copyright c 2006 -.) - [108 Ko] - (1.1.1.1) - C:\WINDOWS\SysWOW64\CardID.dll [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:46] - [0 Ko] - C:\WINDOWS\SysWOW64\catroot [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\chr-CHER-US [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:46] - [317 Ko] - C:\WINDOWS\SysWOW64\Com [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:46] - [161717.45 Ko] - C:\WINDOWS\SysWOW64\config [MD5.00000000000000000000000000000000] - |SD| - [19/03/2019 05:52:46] - [53.11 Ko] - C:\WINDOWS\SysWOW64\Configuration [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:46] - [206 Ko] - C:\WINDOWS\SysWOW64\cs-CZ [MD5.FDEF330575C8C8EAD815F58BB7A93ED3] - |A| - [30/01/2014 17:33:53] - (.Copyright 2011 - CSVer.) - [52 Ko] - (9.4.0.1026) - C:\WINDOWS\SysWOW64\CSVer.dll [MD5.1E02A122FE09272058FC1EF0B1B6265E] - |A| - [07/08/2019 16:21:19] - (.© 1996 - 2017 Daniel Stenberg, . - The curl executable.) - [377 Ko] - (7.55.1.0) - C:\WINDOWS\SysWOW64\curl.exe [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\cy-GB [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:46] - [207 Ko] - C:\WINDOWS\SysWOW64\da-DK [MD5.877B7E3E7C3574DE6A4C4E890EABDC4F] - |A| - [31/10/2019 22:37:24] - (.-.) - [32.42 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\ddmdrv.sys [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:46] - [229 Ko] - C:\WINDOWS\SysWOW64\de-DE [MD5.4626B01E39A69D0F7F9ADD0A3B044FC0] - |A| - [27/03/2016 22:13:26] - (.-.) - [0.43 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\debug.log [MD5.C04ED7B2794D40E8E777FD44ED44FC50] - |A| - [19/03/2019 05:45:13] - (.-.) - [0.36 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\DefaultAccountTile.png [MD5.00000000000000000000000000000000] - |SD| - [19/03/2019 05:52:46] - [186 Ko] - C:\WINDOWS\SysWOW64\DiagSvcs [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:46] - [7413.23 Ko] - C:\WINDOWS\SysWOW64\Dism [MD5.902179013800F311AFF57CD5F29BE346] - |A| - [18/08/2017 08:57:50] - (.Copyright (C) DivXNetworks 2001-2003 - DivX Video for Windows Codec.) - [624 Ko] - (5.0.5.830) - C:\WINDOWS\SysWOW64\divx.dll [MD5.EFF71E68DD8F9DC0BBD89CD83153C336] - |A| - [18/08/2017 08:57:50] - (.Copyright © DivXNetworks, 2001-2003 - DivX (TM) Decoder Filter.) - [216.03 Ko] - (5.0.5.830) - C:\WINDOWS\SysWOW64\divxdec.ax [MD5.69DA041EE00FBB2855BE8D496799C485] - |A| - [29/10/2018 11:44:54] - (.Copyright (C) 2014 - DlgSearchEngine Dynamic Link Library.) - [2046.57 Ko] - (1.1.0.31) - C:\WINDOWS\SysWOW64\DlgSearchEngine.dll [MD5.F5E1F4E75B9F83862539C6720BC47FB2] - |A| - [17/08/2015 17:29:18] - (.© PoINT Software & Systems GmbH 1994-2015 - API of PoINT CD/DVD Audio/Video SDK.) - [698.32 Ko] - (13.0.0.244) - C:\WINDOWS\SysWOW64\DLLAV32.dll [MD5.68B30AA0871B2940356A6C974293C4F8] - |A| - [08/02/2014 11:50:24] - (.-.) - [37.59 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\DLLAV32.lib [MD5.3CF5D6F462D385BF3A26BA60A0459F67] - |A| - [08/02/2014 11:50:24] - (.© PoINT Software & Systems GmbH 1994-2002 - API of PoINT CDarchive.) - [112 Ko] - (3.3.0.70) - C:\WINDOWS\SysWOW64\DLLCDA32.dll [MD5.435EBFA51632D4ACC7368F751597A86C] - |A| - [08/02/2014 11:50:24] - (.Copyright © PoINT Software & Systems GmbH 1994-2002 - PoINT Shared DLL.) - [60 Ko] - (3.0.0.24) - C:\WINDOWS\SysWOW64\DLLCDF32.dll [MD5.76698A4AF0B2E7E4FF73101676B0EB0C] - |A| - [17/08/2015 17:29:18] - (.© PoINT Software & Systems GmbH 1994-2015 - PoINT Shared DLL.) - [158.32 Ko] - (4.1.0.173) - C:\WINDOWS\SysWOW64\DLLCPY32.dll [MD5.E7C573FCA80135FCE8C7012B369C3EA7] - |A| - [17/08/2015 17:29:18] - (.© PoINT Software & Systems GmbH 1994-2015 - PoINT Shared DLL.) - [222.32 Ko] - (4.0.0.309) - C:\WINDOWS\SysWOW64\DLLDEV32.dll [MD5.C077944A11DFF7F60A8E68A345158343] - |A| - [08/02/2014 11:50:12] - (.-.) - [117.38 Ko] - (3.7.0.12) - C:\WINDOWS\SysWOW64\DLLDEV32i.dll [MD5.9B108B6A630027763CD9EB28AB06992B] - |A| - [08/02/2014 11:50:24] - (.© PoINT Software & Systems GmbH 1994-2001 - PoINT Shared DLL.) - [32 Ko] - (3.0.0.10) - C:\WINDOWS\SysWOW64\DLLDIR32.dll [MD5.DAF26BF9024AFF8D39D6C91EFE82EC8B] - |A| - [17/08/2015 17:29:18] - (.© PoINT Software & Systems GmbH 1994-2015 - PoINT Shared DLL.) - [214.32 Ko] - (4.0.0.406) - C:\WINDOWS\SysWOW64\DLLDRV32.dll [MD5.1903B46D93ED6E1ED5A41954FA21870F] - |A| - [08/02/2014 11:50:24] - (.Copyright © PoINT Software & Systems GmbH 1994-2001 - PoINT Shared DLL.) - [44 Ko] - (3.0.0.10) - C:\WINDOWS\SysWOW64\DLLIMG32.dll [MD5.D515497625D56CCC1A82F0CFE74D3F53] - |A| - [17/08/2015 17:29:18] - (.© PoINT Software & Systems GmbH 1994-2015 - PoINT Shared DLL.) - [98.32 Ko] - (3.2.0.116) - C:\WINDOWS\SysWOW64\DLLIO32.dll [MD5.D41CD97D3A7B3DAF632C9335710162A0] - |A| - [08/02/2014 11:50:24] - (.Copyright © PoINT Software & Systems GmbH 1994-2002 - PoINT Shared DLL.) - [32 Ko] - (3.0.0.11) - C:\WINDOWS\SysWOW64\DLLISO32.dll [MD5.82D1CAC671A80EB542B4428F072D7548] - |A| - [08/02/2014 11:50:24] - (.© PoINT Software & Systems GmbH 1995-2000 - PoINT Shared DLL.) - [24 Ko] - (3.0.0.7) - C:\WINDOWS\SysWOW64\DLLIX.dll [MD5.69C3A42D62622DC14200D2F0531B7171] - |A| - [08/02/2014 11:50:24] - (.© PoINT Software & Systems GmbH 1995-2000 - PoINT Shared DLL.) - [32 Ko] - (3.0.0.11) - C:\WINDOWS\SysWOW64\DLLMSC32.dll [MD5.784C395DF97ACAC1A55A3425B8B4F039] - |A| - [17/08/2015 17:29:18] - (.Copyright © PoINT Software & Systems GmbH 1994-2013 - PoINT Shared DLL.) - [82.32 Ko] - (3.3.0.62) - C:\WINDOWS\SysWOW64\DLLPNT32.dll [MD5.97077B3F882D82EC6C8F9624B5BC076A] - |A| - [30/06/2013 21:46:54] - (.© PoINT Software & Systems GmbH 1994-2010 - PoINT Shared DLL.) - [94.32 Ko] - (3.1.0.40) - C:\WINDOWS\SysWOW64\DLLPRF32.dll [MD5.B4455EF6F773C790ECBAAD93F719C1FE] - |A| - [08/02/2014 11:50:24] - (.Copyright © PoINT Software & Systems GmbH 1994-2001 - PoINT Shared DLL.) - [52 Ko] - (3.0.0.17) - C:\WINDOWS\SysWOW64\DLLPRJ32.dll [MD5.BE5E9E3646D1EC21B9CD75895FE90B36] - |A| - [08/02/2014 11:50:24] - (.Copyright © PoINT Software & Systems GmbH 1994-2002 - PoINT Shared DLL.) - [64 Ko] - (3.0.0.23) - C:\WINDOWS\SysWOW64\DLLPTL32.dll [MD5.8EF0C1253D47A158D3023F1292A5E293] - |A| - [08/02/2014 11:50:24] - (.© PoINT Software & Systems GmbH 1994-2003 - PoINT CDread API.) - [40 Ko] - (2.1.0.104) - C:\WINDOWS\SysWOW64\DLLRD32.dll [MD5.C1CBA95F091BE37EAFB3577851D31CC6] - |A| - [17/08/2015 17:29:18] - (.PoINT Software & Systems GmbH 1994-2015 - PoINT Shared DLL.) - [298.32 Ko] - (3.3.0.222) - C:\WINDOWS\SysWOW64\DLLRES32.dll [MD5.B2BCA1AAACFD7C7656F58ECF5C6569AC] - |A| - [08/02/2014 11:50:24] - (.Copyright © PoINT Software & Systems GmbH 1994-2002 - PoINT Shared DLL.) - [56 Ko] - (3.1.0.31) - C:\WINDOWS\SysWOW64\DLLTPO32.dll [MD5.F114BDA21F525131CB2D12AFC054593B] - |A| - [03/12/2019 13:45:34] - (.Copyright © MyHeritage 2009 - MyHeritage Family Screen Saver.) - [16903.61 Ko] - (1.2.0.0) - C:\WINDOWS\SysWOW64\FTBSaver.scr [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:46] - [0 Ko] - C:\WINDOWS\SysWOW64\FxsTmp [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\ga-IE [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\gd-GB [MD5.BFB470A60E7BE7842B4CFD768BC5E185] - |A| - [27/01/2016 10:19:48] - (.-.) - [140.56 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\generic_uninstaller.log [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\gl-ES [MD5.B873A5ABCFBC42B1BAC9EBE8741C6162] - |A| - [16/11/2019 17:03:42] - (.Copyright (C) 2019 - Gracenote SDK component.) - [244 Ko] - (3.9.511.0) - C:\WINDOWS\SysWOW64\gnsdk_fp.dll [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:46] - [0.01 Ko] - C:\WINDOWS\SysWOW64\GroupPolicy [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:46] - [0 Ko] - C:\WINDOWS\SysWOW64\GroupPolicyUsers [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\gu-IN [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\ha-Latn-NG [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:46] - [166 Ko] - C:\WINDOWS\SysWOW64\he-IL [MD5.791F8E1C60E6466F93D792D375D8F1B5] - |A| - [19/03/2019 05:45:13] - (.-.) - [203.5 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\HeatCore.dll [MD5.FB23C632BE3EECB4E1F59857EFAB857B] - |A| - [09/02/2014 18:30:01] - (.Lorenzi Davide - Hexagora Unicode RTF Box 1.0.) - [592 Ko] - (3.1.0.17) - C:\WINDOWS\SysWOW64\HexUniRTFBox.ocx [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\hi-IN [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:46] - [142.5 Ko] - C:\WINDOWS\SysWOW64\hr-HR [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:46] - [212.5 Ko] - C:\WINDOWS\SysWOW64\hu-HU [MD5.6386E449D473501F191456DF1D12E434] - |A| - [04/06/2014 14:41:11] - (.-.) - [9.5 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\HWLMSET2PS.dll [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\hy-AM [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:46] - [36.27 Ko] - C:\WINDOWS\SysWOW64\icsxml [MD5.659B216490380FBE2DC77DECC203E5ED] - |A| - [07/08/2019 16:21:01] - (.Copyright (C) 2016 and later: Unicode, Inc. and others. License & terms of use: http://www.unicode.org/copyright.html - ICU Combined Library.) - [1849.5 Ko] - (63.1.0.0) - C:\WINDOWS\SysWOW64\icu.dll [MD5.1EAD0C642EF0B2692D44A206CAD63C74] - |RA| - [19/03/2019 05:45:16] - (.Copyright (C) 2016 and later: Unicode, Inc. and others. License & terms of use: http://www.unicode.org/copyright.html - ICU I18N DLL.) - [24 Ko] - (63.1.0.0) - C:\WINDOWS\SysWOW64\icuin.dll [MD5.9D459E0C31117F3A841D2EA00F7BC99C] - |RA| - [19/03/2019 05:45:16] - (.Copyright (C) 2016 and later: Unicode, Inc. and others. License & terms of use: http://www.unicode.org/copyright.html - ICU Common DLL.) - [28.5 Ko] - (63.1.0.0) - C:\WINDOWS\SysWOW64\icuuc.dll [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\id-ID [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\ig-NG [MD5.A4001C78F2806662B3BD91ACB44E6330] - |A| - [31/12/2015 10:27:53] - (.-.) - [0.04 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\initdebug.nfo [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:46] - [213 Ko] - C:\WINDOWS\SysWOW64\InputMethod [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:46] - [1160 Ko] - C:\WINDOWS\SysWOW64\InstallShield [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:46] - [0 Ko] - C:\WINDOWS\SysWOW64\Ipmi [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\is-IS [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:46] - [216.5 Ko] - C:\WINDOWS\SysWOW64\it-IT [MD5.5FBEEDB06CCCA5C9A07A289EFD24ED27] - |A| - [11/05/2013 17:17:52] - (.-.) - [1.5 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\IusEventLog.dll [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:46] - [154 Ko] - C:\WINDOWS\SysWOW64\ja-JP [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\ka-GE [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\kk-KZ [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\km-KH [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\kn-IN [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:46] - [154.5 Ko] - C:\WINDOWS\SysWOW64\ko-KR [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\kok-IN [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\ku-Arab-IQ [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\ky-KG [MD5.69A0628BBE1A404B1BA0B6DCA7610A06] - |A| - [18/08/2017 08:57:50] - (.Copyright (C) 1997 Fraunhofer IIS - MPEG Layer-3 Audio Decoder.) - [96 Ko] - (1.9.0.311) - C:\WINDOWS\SysWOW64\L3CODECX.AX [MD5.FA425C74CE2EB719B2A77A7A2ADDAE32] - |A| - [18/08/2017 08:57:50] - (.Copyright © 2011 - Lagarith.) - [211 Ko] - (1.3.27.0) - C:\WINDOWS\SysWOW64\Lagarith.dll [MD5.5E6F49F657A509D079C60D08A2EE33A7] - |A| - [18/08/2017 08:57:50] - (.Copyright © 2005 Elecard Ltd. - LAME Audio Encoder.) - [240 Ko] - (1.0.54.50801) - C:\WINDOWS\SysWOW64\lame.ax [MD5.D41D8CD98F00B204E9800998ECF8427E] - |A| - [11/11/2017 14:04:32] - (.-.) - [0 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\last.dump [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\lb-LU [MD5.0C803C6BDFD099D987B8F6E34CF61379] - |A| - [28/09/2015 19:26:06] - (.- Install Logging DLL.) - [412 Ko] - (14.0.43.0) - C:\WINDOWS\SysWOW64\lexlog.dll [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:46] - [625.17 Ko] - C:\WINDOWS\SysWOW64\Licenses [MD5.028448A8BAFEC2BF1A7E932D88B6B63C] - |A| - [28/09/2015 19:23:15] - (.- Printer Communication System.) - [420 Ko] - (12.1.36.0) - C:\WINDOWS\SysWOW64\LMADHQ32comc.dll [MD5.0DB4139A0FA96FE638A355A0DD9BFA67] - |A| - [28/09/2015 19:48:44] - (.- Printer Communication System.) - [420 Ko] - (12.1.34.0) - C:\WINDOWS\SysWOW64\LMFX1N32comc.dll [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\lo-LA [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:46] - [0 Ko] - C:\WINDOWS\SysWOW64\LogFiles [MD5.20B12D6941D54269FEA2264EDE736CCE] - |A| - [07/04/2019 18:06:36] - (.-.) - [0.11 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\LogInfo.log [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:46] - [145.5 Ko] - C:\WINDOWS\SysWOW64\lt-LT [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:46] - [142 Ko] - C:\WINDOWS\SysWOW64\lv-LV [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:46] - [90300.79 Ko] - C:\WINDOWS\SysWOW64\Macromed [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 13:02:25] - [32.68 Ko] - C:\WINDOWS\SysWOW64\MailContactsCalendarSync [MD5.99DE7F0838685CE9F4C39E58FEE6F48B] - |A| - [30/01/2014 17:35:21] - (.Copyright (C) 2010-2013 - MaxxAudio APO Shell.) - [771.75 Ko] - (4.10.8.0) - C:\WINDOWS\SysWOW64\MaxxAudioAPOShell.dll [MD5.521F1463E9733FD867E097727DD90177] - |A| - [18/08/2017 08:57:50] - (.Main Concept Ltd. 1999-2001 - MainConcept DV Codec.) - [255.5 Ko] - (2.0.0.0) - C:\WINDOWS\SysWOW64\mcdvd_32.dll [MD5.1F552EC27C24A82850A568107E376E7A] - |A| - [08/02/2014 11:50:24] - (.-.) - [27.16 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\mgxcdr.txt [MD5.4FA7ABCFC41651D3C1FEC51F141804C8] - |A| - [08/02/2014 11:53:00] - (.Copyright © 2003-2006 MAGIX AG - mgxoschk.) - [648 Ko] - (1.32.1.180) - C:\WINDOWS\SysWOW64\mgxoschk.dll [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\mi-NZ [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:46] - [2839.89 Ko] - C:\WINDOWS\SysWOW64\migration [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:46] - [812.8 Ko] - C:\WINDOWS\SysWOW64\migwiz [MD5.08749DCC252AE1148E3BEA32B3FFFBFC] - |A| - [19/03/2019 05:46:21] - (.-.) - [0.11 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\MixedRealityRuntime.json [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\mk-MK [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\ml-IN [MD5.C8BF077B236ED2803347BD95DE29BF68] - |A| - [19/03/2019 05:49:45] - (.-.) - [3.03 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\mmc.exe.config [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\mn-MN [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\mr-IN [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\ms-MY [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:46] - [45.5 Ko] - C:\WINDOWS\SysWOW64\MSDRM [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:46] - [52.28 Ko] - C:\WINDOWS\SysWOW64\Msdtc [MD5.C50ABE3E7DC1F3BF1177DAE027588C18] - |A| - [18/08/2017 08:57:52] - (.Copyright (c) Flash-Integro LLC, 2011-2017. - mslvddsfilter3 ActiveX DLL.) - [69.8 Ko] - (2.2.0.21) - C:\WINDOWS\SysWOW64\mslvddsfilter3.ax [MD5.E52B0AC11AD28092565DDFEA453E4CCE] - |A| - [18/11/2017 11:30:56] - (.Copyright (c) Flash-Integro LLC, 2011-2018. - mslvddsfilter4 ActiveX DLL.) - [64.13 Ko] - (4.0.1.146) - C:\WINDOWS\SysWOW64\mslvddsfilter4.ax [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\mt-MT [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:46] - [19.15 Ko] - C:\WINDOWS\SysWOW64\MUI [MD5.4C821BC94355B8FE538E7CDA7DDA3513] - |A| - [08/02/2014 11:50:24] - (.Copyright (C) 2008 - MAGIX Restore.) - [972 Ko] - (6.0.2.10) - C:\WINDOWS\SysWOW64\MXRestore.exe [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:46] - [205.5 Ko] - C:\WINDOWS\SysWOW64\nb-NO [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:46] - [0 Ko] - C:\WINDOWS\SysWOW64\NDF [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\ne-NP [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:46] - [51 Ko] - C:\WINDOWS\SysWOW64\networklist [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:46] - [215.5 Ko] - C:\WINDOWS\SysWOW64\nl-NL [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\nn-NO [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\nso-ZA [MD5.00000000000000000000000000000000] - |SD| - [19/03/2019 05:52:46] - [3781.5 Ko] - C:\WINDOWS\SysWOW64\Nui [MD5.7373A9E3AAFA0967C13B6101D0BEA127] - |A| - [15/12/2019 21:00:48] - (.-.) - [532.52 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\nvofapi.dll [MD5.B3B9C8925432FDA674ACCA908FE3CFDE] - |A| - [19/03/2019 06:00:31] - (.-.) - [36.79 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\OneDrive.ico [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:46] - [752.52 Ko] - C:\WINDOWS\SysWOW64\oobe [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\or-IN [MD5.88D7E9EB2311AF8797F5254475AE1064] - |A| - [06/02/2014 19:26:42] - (.Copyright (c) Creative Technology Ltd., 2005-2006 - Add-on Registation module.) - [24 Ko] - (1.0.3.0) - C:\WINDOWS\SysWOW64\P1370Aor.dll [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\pa-Arab-PK [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\pa-IN [MD5.1250BEF11BFA086F772CD2A273BC036E] - |A| - [11/02/2011 22:23:34] - (.Copyright © 2005-2010 CACE Technologies. Copyright © 1999-2005 NetGroup, Politecnico di Torino. - packet.dll (Vista) Dynamic Link Library.) - [94.52 Ko] - (4.1.0.2001) - C:\WINDOWS\SysWOW64\packet.dll [MD5.F04ADF34F2D3C589D2E5635C68FA8B3D] - |A| - [09/02/2014 18:30:01] - (.Contains paintlib code. paintlib is copyright (c) 1996-2000 Ulrich von Zadow - PaintX Module.) - [444 Ko] - (1.0.5.0) - C:\WINDOWS\SysWOW64\PaintX.dll [MD5.59609ED124D91AFE76B131615DFCB326] - |A| - [09/02/2014 18:30:01] - (.Bytescout - PDFDoc Scout library can be used to generate PDF documents, convert WMF, EMF, HTML into PDF.) - [1981.5 Ko] - (1.38.64.0) - C:\WINDOWS\SysWOW64\PDFDocScout.DLL [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:46] - [79 Ko] - C:\WINDOWS\SysWOW64\PerceptionSimulation [MD5.35B176450CC2E3E692AE5B49C4ED08FC] - |A| - [30/01/2014 17:38:46] - (.-.) - [1725.19 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\PerfStringBackup.INI [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:46] - [216.5 Ko] - C:\WINDOWS\SysWOW64\pl-PL [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 13:00:41] - [420.74 Ko] - C:\WINDOWS\SysWOW64\Printing_Admin_Scripts [MD5.A1EAF0705D1B8D5F19449F29535778B7] - |A| - [26/04/2014 17:43:58] - (.Copyright (C) 2008-2011 - Video-Codec by proDAD.) - [494.95 Ko] - (1.0.16.0) - C:\WINDOWS\SysWOW64\prodad-codec.dll [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\prs-AF [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:46] - [214.5 Ko] - C:\WINDOWS\SysWOW64\pt-BR [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:46] - [215.5 Ko] - C:\WINDOWS\SysWOW64\pt-PT [MD5.F04A90F917BA10AE2DCBE859870F4DEA] - |A| - [11/02/2011 22:23:34] - (.-.) - [52.05 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\pthreadVC.dll [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\quc-Latn-GT [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\quz-PE [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:46] - [23.75 Ko] - C:\WINDOWS\SysWOW64\ras [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:46] - [0 Ko] - C:\WINDOWS\SysWOW64\RasToast [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:46] - [0.82 Ko] - C:\WINDOWS\SysWOW64\Recovery [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:46] - [0 Ko] - C:\WINDOWS\SysWOW64\restore [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:46] - [147.5 Ko] - C:\WINDOWS\SysWOW64\ro-RO [MD5.00000000000000000000000000000000] - |D| - [10/04/2017 17:52:44] - [5027.27 Ko] - C:\WINDOWS\SysWOW64\RTCOM [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:46] - [214 Ko] - C:\WINDOWS\SysWOW64\ru-RU [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\rw-RW [MD5.0EBFA44D636CCDB1E747010829B713AA] - |A| - [29/10/2018 11:44:54] - (.-.) - [18.2 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\spddata.xml [MD5.1C5A20642D8ED5311CF49445508DD9F3] - |A| - [29/10/2018 11:44:54] - (.Copyright (C) 2015 - SPDSvc Application.) - [496.57 Ko] - (1.0.0.4) - C:\WINDOWS\SysWOW64\spdsvc.exe [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:46] - [4039.3 Ko] - C:\WINDOWS\SysWOW64\Speech [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:46] - [8875.62 Ko] - C:\WINDOWS\SysWOW64\Speech_OneCore [MD5.0FFE35F0B0CD5A324BBE22F02569AE3B] - |A| - [29/12/2012 21:59:38] - (.Copyright © Almico Software 2001-2013 - SpeedFan x64 Driver.) - [27.99 Ko] - (2.3.11.0) - C:\WINDOWS\SysWOW64\speedfan.sys [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:46] - [1306.25 Ko] - C:\WINDOWS\SysWOW64\spp [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:46] - [23.61 Ko] - C:\WINDOWS\SysWOW64\sppui [MD5.741361E0EF9F83BD8CFF0CF1909B0BD2] - |A| - [21/03/2014 22:33:26] - (.-.) - [304 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\sptlib01.dll [MD5.B2B9981BCC569B8412B1C936B6DC6EA6] - |A| - [21/03/2014 22:33:26] - (.-.) - [412 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\sptlib02.dll [MD5.DA2049875D793A618ECAE352AE9372A1] - |A| - [21/03/2014 22:33:26] - (.-.) - [300 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\sptlib03.dll [MD5.4C4C734E6DB228220AA3ACBA246F7EB9] - |A| - [21/03/2014 22:33:26] - (.-.) - [288 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\sptlib11.dll [MD5.1114A22F8D91D5A2256D61445F15DEA7] - |A| - [21/03/2014 22:33:26] - (.-.) - [132 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\sptlib12.dll [MD5.6BD8239E2B3D5FB9EA46B8CB6775856E] - |A| - [21/03/2014 22:33:26] - (.-.) - [608 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\sptlib21.dll [MD5.9147693EB1278F9A332E077FCF0E7496] - |A| - [21/03/2014 22:33:26] - (.-.) - [300 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\sptlib22.dll [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\sq-AL [MD5.0DC5AF80D059DEC792B665ED598C6567] - |A| - [21/05/2014 10:50:06] - (.2000-2010 Public Domain - SQLite Dynamic Link Library (No TCL).) - [524 Ko] - (3.7.2.0) - C:\WINDOWS\SysWOW64\sqlite3.dll [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\sr-Cyrl-BA [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\sr-Cyrl-RS [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 12:47:48] - [0 Ko] - C:\WINDOWS\SysWOW64\sr-Latn-CS [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:46] - [142 Ko] - C:\WINDOWS\SysWOW64\sr-Latn-RS [MD5.DC9450258D80F46AEF8EF063A7C629B0] - |A| - [19/03/2019 05:46:09] - (.-.) - [19.03 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\srms-apr.dat [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:46] - [0 Ko] - C:\WINDOWS\SysWOW64\sru [MD5.A96D4F5EE92301ABCF9B614B6359D2AF] - |A| - [09/05/2018 09:00:46] - (.- Device Monitor.) - [92 Ko] - (1.6.2.0) - C:\WINDOWS\SysWOW64\Ssdevm.dll [MD5.EC1C75518F1AFF370C27B0EB8B09E932] - |A| - [19/03/2019 05:45:07] - (.-.) - [323 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\ssdm.dll [MD5.957BD9F8B9A68B79792F5A6F4512507B] - |A| - [09/05/2018 09:00:46] - (.- USB Device.) - [52 Ko] - (1.0.1.0) - C:\WINDOWS\SysWOW64\Ssusbpn.dll [MD5.DEEAA7E52C0D72BF01CCA0E5474ED335] - |A| - [17/08/2015 17:29:16] - (.© PoINT Software & Systems GmbH 1994-2012 - PoINT Shared DLL.) - [70.32 Ko] - (3.0.0.25) - C:\WINDOWS\SysWOW64\STRING32.dll [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:46] - [207.5 Ko] - C:\WINDOWS\SysWOW64\sv-SE [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\sw-KE [MD5.5A1BB867BBB963042DA6D7A7D99DA924] - |A| - [23/11/2018 10:38:58] - (.-.) - [0.61 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\swhealthex.log [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 13:00:41] - [0 Ko] - C:\WINDOWS\SysWOW64\sysprep [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\ta-IN [MD5.A3487FD8447683A4F74645C99E7CB255] - |A| - [19/03/2019 05:45:59] - (.Copyright (c) libarchive authors - bsdtar archive tool.) - [42.5 Ko] - (3.3.2.0) - C:\WINDOWS\SysWOW64\tar.exe [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:46] - [0 Ko] - C:\WINDOWS\SysWOW64\Tasks [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\te-IN [MD5.1FB0F1D8E25846CBDE0C5291890C08DC] - |A| - [28/10/2019 22:29:09] - (.-.) - [86.85 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\TempList.txt [MD5.21C60C44D0511D809DD8A381C4CE4E4D] - |A| - [07/08/2019 16:21:01] - (.-.) - [1075.5 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\TextInputMethodFormatter.dll [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\tg-Cyrl-TJ [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:46] - [129 Ko] - C:\WINDOWS\SysWOW64\th-TH [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\ti-ET [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\tk-TM [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\tn-ZA [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:46] - [201 Ko] - C:\WINDOWS\SysWOW64\tr-TR [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\tt-RU [MD5.1DA32728F808D41F380193B6B21B14C2] - |A| - [08/02/2014 11:50:24] - (.Copyright © PoINT Software & Systems GmbH 1994-2000 - PoINT Shared DLL.) - [24 Ko] - (3.0.0.2) - C:\WINDOWS\SysWOW64\TTI32.dll [MD5.AB024EFED92D5A91DDCC9577FD5A3A9C] - |A| - [08/02/2014 11:50:24] - (.Copyright © PoINT Software & Systems GmbH 1994-2000 - PoINT Shared DLL.) - [24 Ko] - (3.0.0.2) - C:\WINDOWS\SysWOW64\TTIC32.dll [MD5.C357BF9CE80DDB0269FF8C3BF6689A35] - |A| - [22/03/2014 11:31:13] - (.Copyright © 1997-2000 - TWNLIB20.) - [104 Ko] - (2.0.2.10) - C:\WINDOWS\SysWOW64\TwnLib20.dll [MD5.9121702322CBEE1957D1617A6A38CD55] - |A| - [22/03/2014 11:31:13] - (.Copyright © 1997-2004 - TwnLib4.) - [356 Ko] - (4.0.14.0) - C:\WINDOWS\SysWOW64\TwnLib4.dll [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\ug-CN [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:46] - [145 Ko] - C:\WINDOWS\SysWOW64\uk-UA [MD5.6C0B99BB629982510C1DA46E47AE6F6D] - |A| - [19/03/2019 05:45:16] - (.-.) - [45.56 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\umpdc.dll [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\ur-PK [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\uz-Latn-UZ [MD5.CC7C694B2BD1510C5AAE7374A5B52B92] - |A| - [03/02/1999 07:45:42] - (.-.) - [26.46 Ko] - (2.0.0.5215) - C:\WINDOWS\SysWOW64\VBAFR32.OLB [MD5.00000000000000000000000000000000] - |D| - [24/11/2014 18:41:03] - [7975.26 Ko] - C:\WINDOWS\SysWOW64\vbox [MD5.83A083A42F97BCF3F8E016820178DDE2] - |A| - [18/08/2017 08:57:50] - (.Copyright © 1998, Voxware, Inc. - Voxware Audio Compression Manager Driver.) - [81 Ko] - (1.6.0.17) - C:\WINDOWS\SysWOW64\vct3216.acm [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\vi-VN [MD5.FAC0D5B16EFA7376CA81047490187D0D] - |A| - [18/08/2017 08:57:50] - (.Copyright © 2000-3 ON2 Technologies - VP6 VIDEO FOR WINDOWS CODEC.) - [428 Ko] - (6.4.2.0) - C:\WINDOWS\SysWOW64\vp6vfw.dll [MD5.9C85E3073E01230C3DA6DE4D5263A795] - |A| - [15/12/2019 21:00:51] - (.Copyright (C) 2015-2019 - Vulkan Loader.) - [915.91 Ko] - (1.1.126.0) - C:\WINDOWS\SysWOW64\vulkan-1-999-0-0-0.dll [MD5.9C85E3073E01230C3DA6DE4D5263A795] - |A| - [15/12/2019 21:00:51] - (.Copyright (C) 2015-2019 - Vulkan Loader.) - [915.91 Ko] - (1.1.126.0) - C:\WINDOWS\SysWOW64\vulkan-1.dll [MD5.0D422CD5761872B06D176DA6D5FA14FE] - |A| - [15/12/2019 21:00:51] - (.Copyright (C) 2015-2019 - Vulkan Info.) - [1298.41 Ko] - (1.1.126.0) - C:\WINDOWS\SysWOW64\vulkaninfo-1-999-0-0-0.exe [MD5.0D422CD5761872B06D176DA6D5FA14FE] - |A| - [15/12/2019 21:00:51] - (.Copyright (C) 2015-2019 - Vulkan Info.) - [1298.41 Ko] - (1.1.126.0) - C:\WINDOWS\SysWOW64\vulkaninfo.exe [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:46] - [15755.88 Ko] - C:\WINDOWS\SysWOW64\wbem [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 13:00:41] - [0 Ko] - C:\WINDOWS\SysWOW64\WCN [MD5.69E4DB68C3968DF92346FDF8477A3D1B] - |A| - [19/03/2019 05:45:13] - (.-.) - [104.5 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\WindowsDefaultHeatProcessor.dll [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:46] - [9158.15 Ko] - C:\WINDOWS\SysWOW64\WindowsPowerShell [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 13:00:41] - [107.56 Ko] - C:\WINDOWS\SysWOW64\winrm [MD5.C24E81CF17B041F64226B6E849B53070] - |A| - [26/03/2019 15:53:55] - (.-.) - [0.15 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\winsevr.dat [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\wo-SN [MD5.190FB481D293D85B507D071E75BCB05C] - |A| - [11/02/2011 22:23:34] - (.Copyright © 2005-2010 CACE Technologies. Copyright © 1999-2005 NetGroup, Politecnico di Torino. - wpcap.dll Dynamic Link Library - based on libpcap 1.0rel0b branch (20091008).) - [274.52 Ko] - (4.1.0.2001) - C:\WINDOWS\SysWOW64\wpcap.dll [MD5.246C62BF8A69AF9A9D1783F4548652BF] - |A| - [19/03/2019 05:45:13] - (.-.) - [62.5 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\xboxgipsynthetic.dll [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\xh-ZA [MD5.00000000000000000000000000000000] - |D| - [07/08/2019 16:18:16] - [10.16 Ko] - C:\WINDOWS\SysWOW64\XPSViewer [MD5.1D9FB9784F32276EFB43512A81217753] - |A| - [18/08/2017 08:57:50] - (.-.) - [52 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\xvid.ax [MD5.0B86EF053161AA4AC3F973FE370EED96] - |A| - [18/08/2017 08:57:50] - (.-.) - [512 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\xvidcore.dll [MD5.E8F602CA1E700496240CF07D9681D040] - |A| - [18/08/2017 08:57:50] - (.-.) - [136 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\xvidvfw.dll [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\yo-NG [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:46] - [135.5 Ko] - C:\WINDOWS\SysWOW64\zh-CN [MD5.00000000000000000000000000000000] - |D| - [16/07/2016 12:47:48] - [0 Ko] - C:\WINDOWS\SysWOW64\zh-HK [MD5.00000000000000000000000000000000] - |D| - [19/03/2019 05:52:46] - [136 Ko] - C:\WINDOWS\SysWOW64\zh-TW [MD5.00000000000000000000000000000000] - |D| - [12/04/2018 17:22:49] - [0 Ko] - C:\WINDOWS\SysWOW64\zu-ZA ---------- | [EVRARD] [03/09/2019 21:59:42] - |D| - [2446] - C:\Users\EVRARD\.android [09/04/2018 16:27:08] - |D| - [4598] - C:\Users\EVRARD\.Icecream PDF Converter [26/05/2018 14:52:59] - |D| - [11781] - C:\Users\EVRARD\.Icecream PDF Split and Merge [21/02/2018 18:52:59] - |D| - [68244] - C:\Users\EVRARD\.Icecream Slideshow Maker [05/01/2019 10:12:05] - |D| - [0] - C:\Users\EVRARD\.MAGIX Vidéo deluxe Premium [05/01/2019 10:12:05] - |D| - [0] - C:\Users\EVRARD\.QtWebEngineProcess [04/11/2019 22:42:10] - |A| - [194] - C:\Users\EVRARD\.vivaldi_reporting_data [20/10/2017 17:10:40] - |RD| - [1044] - C:\Users\EVRARD\3D Objects [09/02/2018 18:42:11] - |D| - [0] - C:\Users\EVRARD\ansel [07/08/2019 15:47:33] - |HD| - [10498177736] - C:\Users\EVRARD\AppData [07/08/2019 15:47:33] - |SHD| - [0] - C:\Users\EVRARD\Application Data [07/08/2019 15:47:33] - |SHD| - [0] - C:\Users\EVRARD\Cookies [29/10/2016 09:52:41] - |RDC| - [282] - C:\Users\EVRARD\Desktop [25/01/2016 17:23:54] - |A| - [438] - C:\Users\EVRARD\Desktop.lnk [09/12/2019 21:31:24] - |D| - [47016082] - C:\Users\EVRARD\Doctor Web [25/05/2018 18:57:23] - |RDC| - [282] - C:\Users\EVRARD\Documents [25/05/2018 18:57:23] - |RD| - [282] - C:\Users\EVRARD\Downloads [20/12/2017 18:45:42] - |D| - [3192197] - C:\Users\EVRARD\Intel [07/08/2019 15:47:33] - |SHD| - [0] - C:\Users\EVRARD\Local Settings [21/02/2018 18:52:59] - |D| - [638] - C:\Users\EVRARD\log [10/12/2018 13:42:13] - |SHD| - [0] - C:\Users\EVRARD\Menu Démarrer [10/12/2018 13:42:13] - |SHD| - [0] - C:\Users\EVRARD\Mes documents [14/11/2017 19:19:28] - |HD| - [4735301] - C:\Users\EVRARD\MicrosoftEdgeBackups [10/12/2018 13:42:13] - |SHD| - [0] - C:\Users\EVRARD\Modèles [25/05/2018 18:57:23] - |RD| - [384] - C:\Users\EVRARD\Music [07/08/2019 15:47:33] - |SHD| - [0] - C:\Users\EVRARD\My Documents [07/08/2019 15:47:33] - |SHD| - [0] - C:\Users\EVRARD\NetHood [07/08/2019 15:47:33] - |AH| - [13107200] - C:\Users\EVRARD\NTUSER.DAT [07/08/2019 15:47:33] - |ASH| - [475136] - C:\Users\EVRARD\ntuser.dat.LOG1 [07/08/2019 15:47:33] - |ASH| - [3407872] - C:\Users\EVRARD\ntuser.dat.LOG2 [07/08/2019 15:47:33] - |ASH| - [65536] - C:\Users\EVRARD\NTUSER.DAT{3bd39eff-b92a-11e9-b9b2-d850e63f6f91}.TM.blf [07/08/2019 15:47:33] - |ASH| - [524288] - C:\Users\EVRARD\NTUSER.DAT{3bd39eff-b92a-11e9-b9b2-d850e63f6f91}.TMContainer00000000000000000001.regtrans-ms [07/08/2019 15:47:33] - |ASH| - [524288] - C:\Users\EVRARD\NTUSER.DAT{3bd39eff-b92a-11e9-b9b2-d850e63f6f91}.TMContainer00000000000000000002.regtrans-ms [07/08/2019 15:55:06] - |SH| - [20] - C:\Users\EVRARD\ntuser.ini [25/05/2018 18:57:23] - |RD| - [384] - C:\Users\EVRARD\Pictures [07/08/2019 15:47:33] - |SHD| - [0] - C:\Users\EVRARD\PrintHood [07/08/2019 15:47:33] - |SHD| - [0] - C:\Users\EVRARD\Recent [25/01/2016 17:24:19] - |A| - [383] - C:\Users\EVRARD\RecentPlaces.lnk [11/02/2016 18:12:41] - |RD| - [282] - C:\Users\EVRARD\Saved Games [07/08/2019 15:47:33] - |SHD| - [0] - C:\Users\EVRARD\SendTo [07/08/2019 15:47:33] - |SHD| - [0] - C:\Users\EVRARD\Start Menu [07/08/2019 15:47:33] - |SHD| - [0] - C:\Users\EVRARD\Templates [30/01/2016 14:52:38] - |D| - [67051520] - C:\Users\EVRARD\Tracing [25/05/2018 18:57:23] - |RD| - [384] - C:\Users\EVRARD\Videos [10/12/2018 13:42:13] - |SHD| - [0] - C:\Users\EVRARD\Voisinage d'impression [10/12/2018 13:42:13] - |SHD| - [0] - C:\Users\EVRARD\Voisinage réseau [07/08/2019 15:47:33] - |D| - [5753069574] - C:\Users\EVRARD\AppData\Local [30/01/2014 17:24:48] - |DC| - [1621509477] - C:\Users\EVRARD\AppData\LocalLow [27/12/2015 16:43:39] - |AC| - [11553] - C:\Users\EVRARD\AppData\Localtransition_695d023943ae953cd599497f44e981eb.ini [07/08/2019 15:47:33] - |D| - [3123587132] - C:\Users\EVRARD\AppData\Roaming [20/11/2015 08:44:57] - |DC| - [3212] - C:\Users\EVRARD\AppData\Local\2BrightSparks [19/01/2018 15:21:49] - |DC| - [324050] - C:\Users\EVRARD\AppData\Local\4kdownload.com [05/02/2014 20:37:52] - |DC| - [1822038] - C:\Users\EVRARD\AppData\Local\ABBYY [10/12/2019 09:22:48] - |D| - [97081] - C:\Users\EVRARD\AppData\Local\Abelssoft [05/09/2016 15:49:33] - |DC| - [22356] - C:\Users\EVRARD\AppData\Local\Acer [01/05/2016 22:33:48] - |DC| - [0] - C:\Users\EVRARD\AppData\Local\ActiveSync [31/01/2014 10:24:24] - |DC| - [99135447] - C:\Users\EVRARD\AppData\Local\Adobe [27/03/2014 22:18:51] - |DC| - [1950597] - C:\Users\EVRARD\AppData\Local\Ahead [27/12/2015 16:43:38] - |DC| - [15570218] - C:\Users\EVRARD\AppData\Local\Ankama [04/06/2014 16:05:39] - |DC| - [0] - C:\Users\EVRARD\AppData\Local\Apple [04/06/2014 21:35:05] - |DC| - [0] - C:\Users\EVRARD\AppData\Local\Apple Computer [07/08/2019 15:47:33] - |SHD| - [0] - C:\Users\EVRARD\AppData\Local\Application Data [22/06/2018 14:45:05] - |DC| - [90448] - C:\Users\EVRARD\AppData\Local\AVAST Software [21/03/2014 22:35:02] - |DC| - [1372] - C:\Users\EVRARD\AppData\Local\AVerMedia [24/07/2014 16:53:26] - |DC| - [4479] - C:\Users\EVRARD\AppData\Local\AVG [27/12/2015 14:19:28] - |DC| - [15434702] - C:\Users\EVRARD\AppData\Local\Battle.net [27/12/2015 14:31:54] - |DC| - [23222] - C:\Users\EVRARD\AppData\Local\Blizzard [27/12/2015 14:19:34] - |DC| - [264] - C:\Users\EVRARD\AppData\Local\Blizzard Entertainment [07/11/2019 22:24:37] - |D| - [38104] - C:\Users\EVRARD\AppData\Local\cache [16/12/2015 21:38:55] - |DC| - [9078763] - C:\Users\EVRARD\AppData\Local\CEF [20/12/2016 11:43:10] - |DC| - [40] - C:\Users\EVRARD\AppData\Local\Chromium [05/02/2018 18:52:46] - |DC| - [8795] - C:\Users\EVRARD\AppData\Local\Chronoplex_Software [01/05/2016 22:31:52] - |DC| - [75789486] - C:\Users\EVRARD\AppData\Local\Comms [22/09/2016 14:40:58] - |DC| - [14497662] - C:\Users\EVRARD\AppData\Local\ConnectedDevicesPlatform [09/08/2016 19:04:10] - |DC| - [49113873] - C:\Users\EVRARD\AppData\Local\CrashDumps [05/04/2017 14:43:25] - |DC| - [0] - C:\Users\EVRARD\AppData\Local\CrashRpt [26/05/2018 15:58:00] - |DC| - [342724] - C:\Users\EVRARD\AppData\Local\D3DSCache [12/01/2019 17:10:23] - |D| - [681184] - C:\Users\EVRARD\AppData\Local\Datastead [11/04/2017 14:06:14] - |DC| - [0] - C:\Users\EVRARD\AppData\Local\DBG [16/03/2015 17:25:46] - |AC| - [6144] - C:\Users\EVRARD\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [04/02/2014 08:24:26] - |DC| - [0] - C:\Users\EVRARD\AppData\Local\Diagnostics [14/03/2019 19:33:48] - |D| - [4210688] - C:\Users\EVRARD\AppData\Local\Downloaded Installations [06/02/2014 20:29:54] - |DC| - [0] - C:\Users\EVRARD\AppData\Local\ElevatedDiagnostics [20/11/2014 09:07:12] - |SHDC| - [0] - C:\Users\EVRARD\AppData\Local\EmieBrowserModeList [26/04/2014 09:14:13] - |SHDC| - [0] - C:\Users\EVRARD\AppData\Local\EmieSiteList [26/04/2014 09:14:13] - |SHDC| - [0] - C:\Users\EVRARD\AppData\Local\EmieUserList [26/01/2018 23:12:37] - |DC| - [55] - C:\Users\EVRARD\AppData\Local\Eraser 6 [27/02/2017 09:58:53] - |DC| - [765] - C:\Users\EVRARD\AppData\Local\FastReport [19/05/2019 10:27:07] - |D| - [84067] - C:\Users\EVRARD\AppData\Local\FileConverter [31/01/2014 10:24:40] - |DC| - [1425192] - C:\Users\EVRARD\AppData\Local\fontconfig [27/02/2014 18:48:54] - |DC| - [7351] - C:\Users\EVRARD\AppData\Local\FreemakeVideoConverter [11/12/2019 21:42:36] - |A| - [198584] - C:\Users\EVRARD\AppData\Local\GDIPFONTCACHEV1.DAT [31/01/2014 10:24:39] - |DC| - [660] - C:\Users\EVRARD\AppData\Local\gegl-0.2 [13/10/2016 16:18:29] - |DC| - [682207965] - C:\Users\EVRARD\AppData\Local\Google [13/02/2014 17:44:52] - |DC| - [165912241] - C:\Users\EVRARD\AppData\Local\Google.old [01/06/2015 21:03:28] - |DC| - [71] - C:\Users\EVRARD\AppData\Local\GWX [28/01/2019 10:33:34] - |D| - [1790] - C:\Users\EVRARD\AppData\Local\Hekasoft [10/12/2018 13:42:13] - |SHD| - [0] - C:\Users\EVRARD\AppData\Local\Historique [07/08/2019 15:47:33] - |SHD| - [0] - C:\Users\EVRARD\AppData\Local\History [03/09/2019 21:35:55] - |D| - [40992769] - C:\Users\EVRARD\AppData\Local\HiSuite [14/10/2015 18:19:23] - |DC| - [1136] - C:\Users\EVRARD\AppData\Local\Icecream [02/12/2019 22:53:50] - |AH| - [192455] - C:\Users\EVRARD\AppData\Local\IconCache.db [04/12/2019 14:24:42] - |D| - [1216] - C:\Users\EVRARD\AppData\Local\Karen's Power Tools [28/04/2015 17:21:07] - |DC| - [0] - C:\Users\EVRARD\AppData\Local\Macromedia [26/04/2014 16:42:21] - |DC| - [124463] - C:\Users\EVRARD\AppData\Local\Magix [27/04/2014 20:06:24] - |DC| - [1756] - C:\Users\EVRARD\AppData\Local\MAGIX_AG [05/02/2015 18:10:57] - |DC| - [3914] - C:\Users\EVRARD\AppData\Local\MAGIX_Software_GmbH [01/10/2018 09:04:46] - |DC| - [1779788] - C:\Users\EVRARD\AppData\Local\mbam [01/10/2018 09:04:34] - |DC| - [272972] - C:\Users\EVRARD\AppData\Local\mbamtray [07/08/2019 15:47:33] - |D| - [1049728871] - C:\Users\EVRARD\AppData\Local\Microsoft [25/05/2018 18:49:43] - |DC| - [310032] - C:\Users\EVRARD\AppData\Local\Microsoft Help [01/05/2016 22:35:57] - |DC| - [67532] - C:\Users\EVRARD\AppData\Local\MicrosoftEdge [20/06/2019 14:56:41] - |D| - [7618] - C:\Users\EVRARD\AppData\Local\Mirillis [28/11/2019 12:15:35] - |D| - [237122544] - C:\Users\EVRARD\AppData\Local\Molotov [22/04/2015 07:27:02] - |DC| - [855651329] - C:\Users\EVRARD\AppData\Local\Mozilla [01/05/2016 22:33:51] - |DC| - [0] - C:\Users\EVRARD\AppData\Local\NetworkTiles [02/05/2014 19:08:47] - |DC| - [175561096] - C:\Users\EVRARD\AppData\Local\NVIDIA [09/11/2015 18:15:26] - |DC| - [100298544] - C:\Users\EVRARD\AppData\Local\NVIDIA Corporation [02/10/2018 09:53:46] - |AC| - [0] - C:\Users\EVRARD\AppData\Local\oobelibMkey.log [20/10/2017 17:02:33] - |DC| - [808219267] - C:\Users\EVRARD\AppData\Local\Packages [01/05/2016 22:49:05] - |DC| - [846] - C:\Users\EVRARD\AppData\Local\PackageStaging [23/02/2018 09:37:36] - |DC| - [30548] - C:\Users\EVRARD\AppData\Local\Patch_My_PC,_LLC [09/05/2018 08:50:48] - |DC| - [10897] - C:\Users\EVRARD\AppData\Local\PlaceholderTileLogoFolder [31/01/2014 10:24:15] - |DC| - [0] - C:\Users\EVRARD\AppData\Local\Programs [01/05/2016 22:32:08] - |DC| - [963032] - C:\Users\EVRARD\AppData\Local\Publishers [08/03/2016 08:37:02] - |DC| - [13777692] - C:\Users\EVRARD\AppData\Local\RadioSure [13/10/2018 16:41:54] - |DC| - [3327] - C:\Users\EVRARD\AppData\Local\Restore_Point_Creator [25/07/2017 17:35:21] - |DC| - [472] - C:\Users\EVRARD\AppData\Local\scandir64 [03/02/2014 18:24:05] - |DC| - [0] - C:\Users\EVRARD\AppData\Local\Skype [05/06/2015 16:01:41] - |AC| - [280982] - C:\Users\EVRARD\AppData\Local\SquareClock.Production_CuisinePlus_WebIcon.ico [15/03/2017 11:13:07] - |DC| - [43882006] - C:\Users\EVRARD\AppData\Local\SquirrelTemp [27/12/2015 14:54:15] - |DC| - [65] - C:\Users\EVRARD\AppData\Local\SWTORPerf [07/08/2019 15:47:33] - |D| - [46716423] - C:\Users\EVRARD\AppData\Local\Temp [07/08/2019 15:47:33] - |SHD| - [0] - C:\Users\EVRARD\AppData\Local\Temporary Internet Files [03/01/2017 19:03:23] - |DC| - [612641649] - C:\Users\EVRARD\AppData\Local\Thunderbird [01/05/2016 22:31:48] - |DC| - [15948111] - C:\Users\EVRARD\AppData\Local\TileDataLayer [30/05/2015 16:13:34] - |DC| - [0] - C:\Users\EVRARD\AppData\Local\TuneUp Software [27/12/2015 18:59:08] - |DC| - [843] - C:\Users\EVRARD\AppData\Local\Ubisoft [05/01/2019 10:19:24] - |D| - [7091538] - C:\Users\EVRARD\AppData\Local\Videodeluxe [30/01/2014 17:24:49] - |DC| - [15302268] - C:\Users\EVRARD\AppData\Local\VirtualStore [25/08/2017 11:24:33] - |DC| - [586418159] - C:\Users\EVRARD\AppData\Local\Vivaldi [22/02/2014 09:01:13] - |DC| - [57344] - C:\Users\EVRARD\AppData\Local\Windows Live [10/03/2014 15:04:46] - |DC| - [650003] - C:\Users\EVRARD\AppData\Local\Windows Live Writer [26/04/2014 16:42:20] - |DC| - [9191] - C:\Users\EVRARD\AppData\Local\Xara [08/08/2017 21:04:29] - |DC| - [861186] - C:\Users\EVRARD\AppData\Local\ZHP [31/01/2014 10:24:24] - |DC| - [6392617] - C:\Users\EVRARD\AppData\LocalLow\Adobe [04/06/2014 16:04:53] - |DC| - [9384] - C:\Users\EVRARD\AppData\LocalLow\Apple Computer [20/11/2014 09:07:11] - |SHDC| - [0] - C:\Users\EVRARD\AppData\LocalLow\EmieBrowserModeList [25/04/2014 11:57:35] - |SHDC| - [0] - C:\Users\EVRARD\AppData\LocalLow\EmieSiteList [26/04/2014 16:42:35] - |SHDC| - [0] - C:\Users\EVRARD\AppData\LocalLow\EmieUserList [13/02/2014 17:45:14] - |DC| - [681693319] - C:\Users\EVRARD\AppData\LocalLow\Google [02/09/2018 20:40:05] - |DC| - [371] - C:\Users\EVRARD\AppData\LocalLow\IObit [30/01/2014 17:25:03] - |SDC| - [2920225] - C:\Users\EVRARD\AppData\LocalLow\Microsoft [06/11/2019 10:33:55] - |DC| - [0] - C:\Users\EVRARD\AppData\LocalLow\Mozilla [22/04/2014 13:06:09] - |DC| - [229928960] - C:\Users\EVRARD\AppData\LocalLow\Oracle [08/02/2014 18:59:08] - |D| - [14989652] - C:\Users\EVRARD\AppData\LocalLow\PlayReady [31/01/2014 10:25:14] - |DC| - [479011207] - C:\Users\EVRARD\AppData\LocalLow\Sun [04/12/2019 14:29:11] - |DC| - [0] - C:\Users\EVRARD\AppData\LocalLow\Temp [27/12/2015 16:33:34] - |DC| - [206562046] - C:\Users\EVRARD\AppData\LocalLow\Unity [15/12/2014 19:18:07] - |DC| - [0] - C:\Users\EVRARD\AppData\LocalLow\VDownloader [21/09/2016 14:19:00] - |AC| - [1696] - C:\Users\EVRARD\AppData\LocalLow\wbk7AE1.tmp [26/12/2015 14:23:12] - |DC| - [224417725] - C:\Users\EVRARD\AppData\Roaming\.minecraft [20/11/2015 08:45:07] - |DC| - [0] - C:\Users\EVRARD\AppData\Roaming\2BrightSparks [25/01/2018 15:48:55] - |DC| - [0] - C:\Users\EVRARD\AppData\Roaming\4kdownload.com [30/01/2014 17:24:49] - |DC| - [914944] - C:\Users\EVRARD\AppData\Roaming\Adobe [26/01/2017 18:15:04] - |DC| - [6997689] - C:\Users\EVRARD\AppData\Roaming\Anvsoft [05/06/2014 13:44:29] - |DC| - [0] - C:\Users\EVRARD\AppData\Roaming\Apple Computer [31/01/2014 11:13:36] - |DC| - [35670449] - C:\Users\EVRARD\AppData\Roaming\AVAST Software [24/07/2014 16:53:26] - |DC| - [0] - C:\Users\EVRARD\AppData\Roaming\AVG [27/12/2015 14:19:28] - |DC| - [2811] - C:\Users\EVRARD\AppData\Roaming\Battle.net [11/06/2018 15:47:59] - |DC| - [75] - C:\Users\EVRARD\AppData\Roaming\BlankAndSecure [09/05/2014 15:24:15] - |DC| - [433] - C:\Users\EVRARD\AppData\Roaming\Canneverbe Limited [25/01/2017 08:34:30] - |DC| - [11134034] - C:\Users\EVRARD\AppData\Roaming\Correo [18/02/2017 14:29:24] - |DC| - [38432] - C:\Users\EVRARD\AppData\Roaming\Digiarty [16/04/2015 14:43:36] - |DC| - [1309696] - C:\Users\EVRARD\AppData\Roaming\DigitalVolcano [24/11/2017 10:46:42] - |DC| - [5670] - C:\Users\EVRARD\AppData\Roaming\DirectoryListPrintPro [23/05/2015 15:57:38] - |DC| - [0] - C:\Users\EVRARD\AppData\Roaming\DiskDefrag [04/07/2014 19:31:33] - |DC| - [1359] - C:\Users\EVRARD\AppData\Roaming\dvdcss [30/04/2018 20:55:37] - |DC| - [19144395] - C:\Users\EVRARD\AppData\Roaming\DVDVideoSoft [27/07/2015 20:13:45] - |DC| - [0] - C:\Users\EVRARD\AppData\Roaming\EncryptStick [01/05/2018 18:54:20] - |DC| - [13937786] - C:\Users\EVRARD\AppData\Roaming\FlashIntegro [26/10/2019 20:55:10] - |D| - [12] - C:\Users\EVRARD\AppData\Roaming\Foxit AgentInformation [17/12/2014 19:27:57] - |DC| - [12840756] - C:\Users\EVRARD\AppData\Roaming\Foxit Software [23/05/2015 15:57:38] - |DC| - [228696947] - C:\Users\EVRARD\AppData\Roaming\GlarySoft [07/03/2015 18:18:57] - |DC| - [0] - C:\Users\EVRARD\AppData\Roaming\Google [28/01/2019 10:40:34] - |D| - [2862] - C:\Users\EVRARD\AppData\Roaming\Hard Disk Sentinel [26/05/2018 14:53:58] - |DC| - [133] - C:\Users\EVRARD\AppData\Roaming\Icecream [04/02/2014 16:44:25] - |DC| - [0] - C:\Users\EVRARD\AppData\Roaming\Identities [06/04/2015 16:17:42] - |DC| - [0] - C:\Users\EVRARD\AppData\Roaming\ImgBurn [04/06/2014 14:40:20] - |DC| - [0] - C:\Users\EVRARD\AppData\Roaming\InstallShield [30/01/2014 17:38:46] - |DC| - [678] - C:\Users\EVRARD\AppData\Roaming\Intel Corporation [02/09/2018 20:39:22] - |DC| - [5212991] - C:\Users\EVRARD\AppData\Roaming\IObit [02/05/2015 20:28:22] - |DC| - [0] - C:\Users\EVRARD\AppData\Roaming\java [24/11/2017 10:11:46] - |ADC| - [91050] - C:\Users\EVRARD\AppData\Roaming\KC Softwares [03/02/2014 18:10:05] - |DC| - [7571] - C:\Users\EVRARD\AppData\Roaming\KeePass [05/12/2018 15:44:01] - |DC| - [2429377] - C:\Users\EVRARD\AppData\Roaming\LibreOffice [18/07/2016 10:00:38] - |DC| - [81] - C:\Users\EVRARD\AppData\Roaming\livestreamer [27/12/2015 20:16:42] - |DC| - [0] - C:\Users\EVRARD\AppData\Roaming\LolClient [18/08/2017 18:23:33] - |DC| - [4791988] - C:\Users\EVRARD\AppData\Roaming\lossless-cut [05/03/2018 15:44:02] - |DC| - [558057] - C:\Users\EVRARD\AppData\Roaming\LosslessCut [25/05/2018 18:49:43] - |DC| - [317949] - C:\Users\EVRARD\AppData\Roaming\Macromedia [08/02/2014 11:50:55] - |DC| - [13334396] - C:\Users\EVRARD\AppData\Roaming\MAGIX [03/02/2014 18:19:04] - |DC| - [0] - C:\Users\EVRARD\AppData\Roaming\Malwarebytes [07/08/2019 15:47:33] - |SD| - [188318883] - C:\Users\EVRARD\AppData\Roaming\Microsoft [20/06/2019 14:56:41] - |D| - [20] - C:\Users\EVRARD\AppData\Roaming\Mirillis [21/05/2017 17:59:12] - |DC| - [250372166] - C:\Users\EVRARD\AppData\Roaming\Molotov [22/04/2015 07:27:02] - |DC| - [120872464] - C:\Users\EVRARD\AppData\Roaming\Mozilla [05/02/2018 20:21:48] - |DC| - [637153529] - C:\Users\EVRARD\AppData\Roaming\MyHeritage [22/03/2014 11:38:07] - |DC| - [519004] - C:\Users\EVRARD\AppData\Roaming\NVIDIA [18/08/2017 09:18:23] - |DC| - [11886627] - C:\Users\EVRARD\AppData\Roaming\obs-studio [22/02/2014 22:18:49] - |DC| - [51736904] - C:\Users\EVRARD\AppData\Roaming\OpenOffice [03/02/2014 16:24:27] - |DC| - [12951605] - C:\Users\EVRARD\AppData\Roaming\OpenOffice.org [04/02/2014 18:04:38] - |DC| - [4270] - C:\Users\EVRARD\AppData\Roaming\PhotoFiltre 7 [26/04/2014 17:43:52] - |DC| - [10041256] - C:\Users\EVRARD\AppData\Roaming\proDAD [30/05/2015 13:09:00] - |DC| - [17242] - C:\Users\EVRARD\AppData\Roaming\Q-Dir [27/12/2015 18:25:26] - |DC| - [0] - C:\Users\EVRARD\AppData\Roaming\Riot Games [09/05/2018 09:01:28] - |DC| - [191996] - C:\Users\EVRARD\AppData\Roaming\Samsung [03/02/2014 18:24:04] - |DC| - [250427549] - C:\Users\EVRARD\AppData\Roaming\Skype [29/04/2016 17:21:39] - |DC| - [121640519] - C:\Users\EVRARD\AppData\Roaming\soft2base [01/09/2015 07:39:32] - |DC| - [0] - C:\Users\EVRARD\AppData\Roaming\Sun [05/02/2018 20:21:59] - |DC| - [317] - C:\Users\EVRARD\AppData\Roaming\The Complete Genealogy Reporter - FTB [03/01/2017 19:03:23] - |DC| - [856476155] - C:\Users\EVRARD\AppData\Roaming\Thunderbird [30/05/2015 16:13:34] - |DC| - [59581] - C:\Users\EVRARD\AppData\Roaming\TuneUp Software [04/01/2019 09:29:18] - |D| - [21172063] - C:\Users\EVRARD\AppData\Roaming\VideoProc [13/11/2019 08:28:42] - |D| - [424302] - C:\Users\EVRARD\AppData\Roaming\vlc [10/03/2014 15:04:46] - |DC| - [295] - C:\Users\EVRARD\AppData\Roaming\Windows Live Writer [11/05/2019 18:28:52] - |D| - [12] - C:\Users\EVRARD\AppData\Roaming\WinRAR [08/09/2018 14:53:23] - |DC| - [300] - C:\Users\EVRARD\AppData\Roaming\WinScan2PDF [20/12/2017 17:59:04] - |DC| - [7459727] - C:\Users\EVRARD\AppData\Roaming\ZHP [03/09/2018 10:18:45] - |AC| - [2009] - C:\Users\EVRARD\AppData\Roaming\Microsoft\Windows\Start Menu\Avast Passwords.lnk [30/01/2014 17:24:50] - |SHC| - [174] - C:\Users\EVRARD\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini [10/12/2018 13:42:13] - |SHD| - [0] - C:\Users\EVRARD\AppData\Roaming\Microsoft\Windows\Start Menu\Programmes [22/09/2016 14:33:03] - |RDC| - [159215] - C:\Users\EVRARD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs [07/08/2019 15:47:33] - |RD| - [3888] - C:\Users\EVRARD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility [07/08/2019 15:47:33] - |RD| - [2925] - C:\Users\EVRARD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories [30/01/2014 17:24:50] - |RDC| - [174] - C:\Users\EVRARD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools [18/01/2016 09:18:39] - |DC| - [100882] - C:\Users\EVRARD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Applications Chrome [25/01/2016 18:25:52] - |AC| - [537] - C:\Users\EVRARD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bibliothèques.lnk [07/08/2019 15:47:33] - |SH| - [264] - C:\Users\EVRARD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\desktop.ini [05/11/2017 16:32:48] - |DC| - [1507] - C:\Users\EVRARD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Freemake [03/12/2015 18:43:24] - |DC| - [2389] - C:\Users\EVRARD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome [13/10/2016 16:18:33] - |AC| - [2389] - C:\Users\EVRARD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk [04/12/2019 14:23:54] - |DC| - [2533] - C:\Users\EVRARD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Karen's Power Tools [07/08/2019 15:47:33] - |D| - [170] - C:\Users\EVRARD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance [20/06/2019 14:21:51] - |DC| - [2113] - C:\Users\EVRARD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mirillis [21/05/2017 17:59:12] - |DC| - [2296] - C:\Users\EVRARD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Molotov [25/05/2018 18:49:43] - |AC| - [2404] - C:\Users\EVRARD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive (1).lnk [19/04/2016 20:22:37] - |AC| - [2345] - C:\Users\EVRARD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive Entreprise.lnk [07/08/2019 15:47:33] - |AC| - [2404] - C:\Users\EVRARD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk [04/02/2014 18:04:36] - |DC| - [0] - C:\Users\EVRARD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PhotoFiltre 7 [12/05/2015 08:50:49] - |AC| - [373] - C:\Users\EVRARD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Périphériques et imprimantes.lnk [08/03/2016 08:37:03] - |DC| - [2356] - C:\Users\EVRARD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RadioSure [30/01/2014 17:24:50] - |RDC| - [174] - C:\Users\EVRARD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup [07/08/2019 15:47:33] - |RD| - [6469] - C:\Users\EVRARD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools [23/06/2014 18:10:12] - |DC| - [3532] - C:\Users\EVRARD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Unlocker [25/08/2017 11:24:40] - |AC| - [2388] - C:\Users\EVRARD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Vivaldi.lnk [07/08/2019 15:47:33] - |RD| - [10302] - C:\Users\EVRARD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell [04/05/2019 18:11:02] - |DC| - [4401] - C:\Users\EVRARD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR [30/01/2014 17:24:50] - |SHC| - [174] - C:\Users\EVRARD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini ---------- | [Public] [25/02/2014 12:04:25] - |RHD| - [209936] - C:\Users\Public\AccountPictures [07/02/2018 13:59:31] - |RHD| - [174] - C:\Users\Public\Desktop [19/03/2019 05:49:35] - |ASH| - [174] - C:\Users\Public\desktop.ini [22/08/2013 16:36:30] - |RD| - [4253] - C:\Users\Public\Documents [22/08/2013 16:36:30] - |RD| - [174] - C:\Users\Public\Downloads [31/01/2016 21:16:21] - |D| - [16292394] - C:\Users\Public\Foxit Software [19/03/2019 05:52:44] - |RHD| - [1135] - C:\Users\Public\Libraries [22/08/2013 16:36:30] - |RD| - [380] - C:\Users\Public\Music [22/08/2013 16:36:30] - |RD| - [380] - C:\Users\Public\Pictures [22/08/2013 16:36:30] - |RD| - [380] - C:\Users\Public\Videos ---------- | C:\ProgramData [05/02/2014 20:37:42] - |D| - [373508] - C:\ProgramData\ABBYY [10/12/2019 09:22:45] - |D| - [18143939] - C:\ProgramData\Abelssoft [05/02/2014 18:59:37] - |D| - [743] - C:\ProgramData\ADH [31/01/2014 10:23:32] - |D| - [526989468] - C:\ProgramData\Adobe [26/03/2019 15:54:52] - |D| - [312] - C:\ProgramData\Aomei [30/08/2017 13:29:59] - |D| - [462] - C:\ProgramData\AomeiBR [04/06/2014 16:05:38] - |D| - [0] - C:\ProgramData\Apple [04/06/2014 21:23:50] - |D| - [0] - C:\ProgramData\Apple Computer [07/08/2019 15:54:55] - |SHD| - [0] - C:\ProgramData\Application Data [31/01/2014 11:09:46] - |D| - [536974088] - C:\ProgramData\AVAST Software [21/03/2014 22:35:17] - |D| - [903962] - C:\ProgramData\AVerTV 3D [24/07/2014 16:53:18] - |D| - [73075] - C:\ProgramData\AVG [09/05/2018 10:09:33] - |D| - [12] - C:\ProgramData\boost_interprocess [30/01/2014 17:16:29] - |SHD| - [0] - C:\ProgramData\Bureau [09/05/2014 15:24:18] - |D| - [0] - C:\ProgramData\Canneverbe Limited [24/07/2014 16:53:16] - |HD| - [96] - C:\ProgramData\Common Files [16/07/2016 12:47:48] - |D| - [0] - C:\ProgramData\Comms [07/08/2019 15:54:55] - |SHD| - [0] - C:\ProgramData\Desktop [10/10/2017 16:14:36] - |D| - [0] - C:\ProgramData\DigitalWave.ApplicationUpdater_files [09/12/2019 21:31:27] - |D| - [5214170] - C:\ProgramData\Doctor Web [07/08/2019 15:54:55] - |SHD| - [0] - C:\ProgramData\Documents [10/04/2017 17:52:49] - |A| - [0] - C:\ProgramData\DP45977C.lfl [24/03/2016 12:09:28] - |D| - [29] - C:\ProgramData\Foxit ContentPlatform [28/06/2016 17:08:26] - |D| - [0] - C:\ProgramData\Foxit Software [27/02/2014 18:48:45] - |D| - [46534809] - C:\ProgramData\Freemake [23/05/2015 16:14:00] - |D| - [0] - C:\ProgramData\GlarySoft [05/02/2014 19:03:01] - |D| - [3309106] - C:\ProgramData\gn_Logs [20/07/2014 20:05:20] - |D| - [12722] - C:\ProgramData\Google [30/01/2014 17:38:15] - |D| - [41337830] - C:\ProgramData\Intel [02/09/2018 20:39:42] - |D| - [46633411] - C:\ProgramData\IObit [29/04/2018 19:09:05] - |D| - [2042870] - C:\ProgramData\IperiusBackup [04/12/2019 14:23:37] - |D| - [0] - C:\ProgramData\Karen's Power Tools [28/09/2015 19:20:36] - |D| - [127000648] - C:\ProgramData\LexmarkUpdate [22/04/2016 09:31:20] - |A| - [248551] - C:\ProgramData\LMADHscan.log [29/08/2018 16:36:07] - |D| - [0] - C:\ProgramData\lx_CATS [08/02/2014 11:50:14] - |D| - [16306486921] - C:\ProgramData\MAGIX [03/02/2014 18:18:50] - |D| - [56429232] - C:\ProgramData\Malwarebytes [17/04/2017 13:47:26] - |D| - [4983346] - C:\ProgramData\ManiaPlanet [25/06/2017 09:30:26] - |D| - [981179] - C:\ProgramData\McAfee [30/01/2014 17:16:29] - |SHD| - [0] - C:\ProgramData\Menu Démarrer [19/03/2019 05:52:44] - |SD| - [1663511387] - C:\ProgramData\Microsoft [03/02/2014 19:09:56] - |D| - [65262] - C:\ProgramData\Microsoft Help [07/08/2019 15:57:00] - |D| - [0] - C:\ProgramData\Microsoft OneDrive [20/06/2019 14:56:41] - |D| - [20] - C:\ProgramData\Mirillis [30/01/2014 17:16:29] - |SHD| - [0] - C:\ProgramData\Modèles [27/04/2014 19:32:13] - |D| - [694005094] - C:\ProgramData\MotionStudios [22/04/2015 07:26:57] - |D| - [58610] - C:\ProgramData\Mozilla [05/02/2018 20:21:48] - |D| - [0] - C:\ProgramData\MyHeritage [03/02/2018 16:13:24] - |D| - [533] - C:\ProgramData\Nero [04/06/2018 08:44:51] - |RASH| - [290] - C:\ProgramData\ntuser.pol [10/04/2017 17:52:59] - |D| - [13980506] - C:\ProgramData\NVIDIA [10/04/2017 17:52:57] - |D| - [872337158] - C:\ProgramData\NVIDIA Corporation [20/12/2016 11:43:08] - |A| - [5110] - C:\ProgramData\NvTelemetryContainer.log [20/12/2016 11:43:08] - |A| - [129227] - C:\ProgramData\NvTelemetryContainer.log_backup1 [19/09/2014 14:09:49] - |D| - [162043857] - C:\ProgramData\Oracle [27/12/2015 16:33:27] - |D| - [78179970] - C:\ProgramData\Package Cache [16/07/2018 08:46:07] - |D| - [303104] - C:\ProgramData\Packages [26/04/2014 17:43:59] - |D| - [7643] - C:\ProgramData\proDAD [02/09/2018 20:40:10] - |D| - [1171] - C:\ProgramData\ProductData [19/03/2019 05:52:44] - |D| - [999] - C:\ProgramData\regid.1991-06.com.microsoft [12/12/2019 20:35:24] - |A| - [106264] - C:\ProgramData\Restore Point Creator.log [27/12/2015 18:28:57] - |D| - [39] - C:\ProgramData\Riot Games [09/05/2018 08:50:36] - |D| - [18519578] - C:\ProgramData\Samsung [05/01/2019 10:04:18] - |D| - [3116] - C:\ProgramData\simplitec [03/02/2014 18:24:00] - |D| - [199326960] - C:\ProgramData\Skype [19/03/2019 05:52:44] - |D| - [0] - C:\ProgramData\SoftwareDistribution [07/08/2019 15:54:55] - |SHD| - [0] - C:\ProgramData\Start Menu [07/02/2018 10:53:01] - |D| - [0] - C:\ProgramData\SWCUTemp [07/08/2019 15:54:55] - |SHD| - [0] - C:\ProgramData\Templates [06/04/2015 10:12:18] - |HD| - [0] - C:\ProgramData\tks [30/05/2015 16:13:21] - |D| - [972633] - C:\ProgramData\TuneUp Software [19/03/2019 05:52:44] - |D| - [16612] - C:\ProgramData\USOPrivate [07/08/2019 15:46:53] - |D| - [22118400] - C:\ProgramData\USOShared [19/03/2019 13:02:58] - |D| - [0] - C:\ProgramData\WindowsHolographicDevices ---------- | C:\ProgramData\Microsoft\Windows\Start Menu [19/03/2019 05:49:34] - |ASH| - [174] - C:\ProgramData\Microsoft\Windows\Start Menu\desktop.ini [30/01/2014 17:16:29] - |SHD| - [0] - C:\ProgramData\Microsoft\Windows\Start Menu\Programmes [19/03/2019 05:52:44] - |RD| - [326365] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs ---------- | C:\ProgramData\Microsoft\Windows\Start Menu\Programs [09/01/2019 09:59:03] - |D| - [1557] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip [19/03/2019 05:52:44] - |RD| - [1614] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility [19/03/2019 05:52:44] - |RD| - [14299] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories [10/12/2019 18:34:41] - |A| - [2457] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk [16/12/2015 19:32:07] - |A| - [2457] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk [19/03/2019 05:52:44] - |RD| - [22954] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools [20/01/2016 14:56:17] - |D| - [0] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Alinéa [21/08/2019 17:05:48] - |D| - [3275] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AlterPDF [30/07/2015 10:46:51] - |A| - [1033] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Anti-Twin.lnk [31/10/2019 22:37:26] - |D| - [2564] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AOMEI Partition Assistant Standard Edition 8.5 [04/06/2014 16:05:38] - |A| - [2535] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk [31/01/2014 10:26:46] - |A| - [1787] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Arrêter.lnk [20/10/2017 15:03:51] - |A| - [731] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Assistant Mise à jour de Windows 10.lnk [10/02/2017 18:18:41] - |A| - [731] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Assistant Mise à niveau de Windows 10.lnk [11/03/2019 16:24:16] - |A| - [2088] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Antivirus Gratuit.lnk [21/03/2014 22:34:58] - |D| - [12859] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVerMedia [27/12/2015 14:19:26] - |D| - [0] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battle.net [24/05/2018 21:57:05] - |D| - [963] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner [28/10/2017 22:20:54] - |D| - [1993] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CPUID [18/12/2015 18:09:54] - |D| - [1867] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Defraggler [19/03/2019 05:49:34] - |SH| - [400] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\desktop.ini [18/11/2019 11:29:00] - |D| - [0] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Booster 7 [16/04/2015 14:43:32] - |D| - [8470] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Duplicate Cleaner Free [26/07/2018 16:54:40] - |D| - [7265] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft [27/12/2015 14:52:19] - |D| - [0] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA [19/05/2019 10:27:05] - |D| - [5120] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\File Converter [18/03/2016 18:29:54] - |A| - [1005] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk [11/12/2019 17:02:54] - |D| - [9996] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FlashIntegro [26/10/2019 20:55:05] - |D| - [2908] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Foxit Reader [18/11/2015 15:54:25] - |D| - [2095] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free JPG To PDF Converter [13/12/2017 09:59:20] - |D| - [2230] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Video Joiner [05/11/2017 16:32:48] - |D| - [1425] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Freemake [29/11/2018 21:55:01] - |D| - [3462] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glary Utilities 5 [29/11/2018 21:55:01] - |A| - [1161] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glary Utilities 5.lnk [22/10/2016 20:57:59] - |A| - [2299] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk [13/03/2019 18:36:02] - |A| - [2253] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth Pro.lnk [28/01/2019 10:40:29] - |D| - [4678] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hard Disk Sentinel [27/12/2015 14:31:34] - |D| - [0] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hearthstone [04/06/2014 14:41:41] - |D| - [14516] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hercules [10/10/2019 10:47:59] - |D| - [1880] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HiSuite [15/07/2015 21:12:13] - |D| - [1314] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Icecream Media Converter [03/11/2015 15:49:17] - |D| - [1277] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Icecream PDF Converter [14/10/2015 18:19:03] - |D| - [1298] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Icecream PDF Split and Merge [16/12/2017 14:36:01] - |D| - [1303] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Icecream Slideshow Maker [06/04/2015 16:15:46] - |D| - [5739] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ImgBurn [06/04/2015 16:15:46] - |A| - [1889] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ImgBurn.lnk [19/03/2019 05:46:39] - |RAS| - [2349] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Immersive Control Panel.lnk [30/01/2014 17:38:23] - |RD| - [3995] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel [18/10/2019 07:14:17] - |A| - [1510] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel Driver & Support Assistant.lnk [02/09/2018 20:40:03] - |D| - [2697] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Uninstaller [02/09/2018 20:40:03] - |A| - [1424] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Uninstaller.lnk [29/04/2018 19:09:07] - |D| - [2338] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Iperius Backup [16/01/2016 18:32:11] - |D| - [6702] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java [06/05/2019 08:06:10] - |A| - [1186] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\KeePass 2.lnk [12/12/2019 18:12:02] - |D| - [9058] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LibreOffice 6.3 [08/02/2014 11:50:18] - |D| - [2517] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MAGIX [19/03/2019 05:52:44] - |D| - [170] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance [07/11/2019 22:24:28] - |D| - [4150] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes [04/02/2014 14:45:26] - |D| - [32512] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office [05/05/2016 20:34:49] - |D| - [2338] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight [05/07/2019 18:22:15] - |D| - [2113] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MiniTool Partition Wizard 11 [27/04/2014 19:32:14] - |D| - [4233] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MotionStudios [03/01/2017 19:03:18] - |A| - [1278] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Thunderbird.lnk [07/03/2018 16:24:29] - |D| - [3541] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MP4Tools [05/02/2018 20:22:00] - |D| - [1212] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MyHeritage.com [09/11/2015 18:14:53] - |D| - [1461] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation [18/08/2017 09:18:15] - |D| - [3719] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OBS Studio [26/01/2019 10:18:18] - |D| - [1149] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDFTK Builder [03/09/2019 13:39:35] - |D| - [5810] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PersoApps Adresses [03/09/2019 13:42:20] - |D| - [5873] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PersoApps Calendrier [04/02/2014 18:04:36] - |D| - [7660] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PhotoFiltre 7 [11/12/2015 17:59:23] - |A| - [2210] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerpointImageExtractor V1.2b.lnk [28/07/2015 20:55:33] - |D| - [3786] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\proDAD [06/06/2017 15:05:57] - |D| - [3426] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller [09/05/2018 09:01:28] - |RD| - [20491] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung Printers [14/03/2019 19:34:21] - |D| - [2742] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SD Association [29/07/2018 21:21:19] - |D| - [1397] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype [04/02/2014 12:08:07] - |D| - [2134] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SoftChris [23/11/2016 17:00:49] - |D| - [935] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Speccy [10/12/2019 09:22:45] - |D| - [3141] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SSDFresh [19/03/2019 05:52:44] - |RD| - [174] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp [19/03/2019 05:52:44] - |RD| - [1458] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools [04/01/2019 09:29:18] - |D| - [2492] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoProc [31/01/2014 10:26:28] - |A| - [2573] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Visionneuse Microsoft PowerPoint .lnk [24/02/2014 09:37:03] - |D| - [1381] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Kits [27/08/2016 08:13:26] - |D| - [906] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinPcap [04/05/2019 18:11:02] - |D| - [4329] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR [20/05/2019 10:40:01] - |D| - [48] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Xiph.Org ---------- | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup [19/03/2019 05:49:34] - |ASH| - [174] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini ---------- | C:\Program Files (x86) [31/01/2014 10:23:57] - |D| - [356555348] - C:\Program Files (x86)\Adobe [22/03/2014 11:31:12] - |D| - [22038920] - C:\Program Files (x86)\Ahead [20/01/2016 14:55:26] - |D| - [4935627] - C:\Program Files (x86)\Alinea [21/08/2019 17:05:47] - |D| - [44650461] - C:\Program Files (x86)\AlterPDF [30/07/2015 10:46:50] - |D| - [1130518] - C:\Program Files (x86)\AntiTwin [26/01/2017 18:15:02] - |D| - [0] - C:\Program Files (x86)\Anvsoft [31/10/2019 22:37:16] - |D| - [113098979] - C:\Program Files (x86)\AOMEI Partition Assistant [04/06/2014 21:23:08] - |AD| - [2428606] - C:\Program Files (x86)\Apple Software Update [10/04/2017 17:52:38] - |D| - [2261416] - C:\Program Files (x86)\ASUS [21/03/2014 22:33:06] - |AD| - [90024404] - C:\Program Files (x86)\AVerMedia [19/03/2019 05:52:44] - |D| - [958068287] - C:\Program Files (x86)\Common Files [27/12/2015 20:17:45] - |D| - [16665] - C:\Program Files (x86)\Config [19/03/2019 05:49:34] - |ASH| - [174] - C:\Program Files (x86)\desktop.ini [04/01/2019 09:29:15] - |D| - [157542473] - C:\Program Files (x86)\Digiarty [16/04/2015 14:43:32] - |D| - [11531306] - C:\Program Files (x86)\Duplicate Cleaner [26/07/2018 16:54:20] - |D| - [1057360219] - C:\Program Files (x86)\DVDVideoSoft [03/09/2019 13:39:35] - |D| - [75404340] - C:\Program Files (x86)\EuroSoft Software Development [26/10/2019 20:54:53] - |D| - [343413013] - C:\Program Files (x86)\Foxit Software [13/12/2017 09:59:20] - |D| - [21350469] - C:\Program Files (x86)\Free Video Joiner [16/02/2017 09:30:46] - |D| - [18483812] - C:\Program Files (x86)\FreeCodecPack [18/11/2015 15:54:25] - |AD| - [7194131] - C:\Program Files (x86)\FreeJPG2PDF [05/11/2017 16:32:36] - |D| - [140302579] - C:\Program Files (x86)\Freemake [29/11/2018 21:54:53] - |D| - [56134107] - C:\Program Files (x86)\Glary Utilities 5 [23/05/2015 16:34:55] - |D| - [0] - C:\Program Files (x86)\Glarysoft [13/02/2014 17:44:51] - |D| - [515929070] - C:\Program Files (x86)\Google [13/03/2019 18:36:06] - |D| - [0] - C:\Program Files (x86)\GUM65D4.tmp [28/01/2019 10:40:27] - |D| - [67019339] - C:\Program Files (x86)\Hard Disk Sentinel [04/06/2014 14:41:10] - |D| - [99592624] - C:\Program Files (x86)\Hercules [10/10/2019 10:47:48] - |D| - [81981943] - C:\Program Files (x86)\HiSuite [15/07/2015 21:12:10] - |AD| - [106008080] - C:\Program Files (x86)\Icecream Media Converter [03/11/2015 15:49:02] - |AD| - [622806259] - C:\Program Files (x86)\Icecream PDF Converter [14/10/2015 18:19:01] - |AD| - [77946517] - C:\Program Files (x86)\Icecream PDF Split and Merge [16/12/2017 14:36:00] - |D| - [55103828] - C:\Program Files (x86)\Icecream Slideshow Maker [06/04/2015 16:15:46] - |AD| - [3367492] - C:\Program Files (x86)\ImgBurn [30/01/2014 17:35:10] - |HD| - [138958977] - C:\Program Files (x86)\InstallShield Installation Information [30/01/2014 17:33:53] - |D| - [34619290] - C:\Program Files (x86)\Intel [19/03/2019 05:52:44] - |D| - [2261331] - C:\Program Files (x86)\Internet Explorer [02/09/2018 20:39:40] - |D| - [81676370] - C:\Program Files (x86)\IObit [29/04/2018 19:09:05] - |D| - [87519525] - C:\Program Files (x86)\Iperius Backup [04/12/2019 14:23:54] - |D| - [1499939] - C:\Program Files (x86)\Karen's Power Tools [06/05/2019 08:06:10] - |D| - [7194191] - C:\Program Files (x86)\KeePass Password Safe 2 [14/01/2017 10:57:36] - |D| - [12679459] - C:\Program Files (x86)\LenovoUsbDriver [28/09/2015 19:24:09] - |D| - [0] - C:\Program Files (x86)\Lexmark S510 Series [27/12/2015 18:27:51] - |D| - [18492955] - C:\Program Files (x86)\Logs [08/02/2014 11:50:12] - |D| - [1110689478] - C:\Program Files (x86)\MAGIX [03/02/2014 18:18:49] - |D| - [0] - C:\Program Files (x86)\Malwarebytes' Anti-Malware [29/07/2018 21:21:13] - |D| - [257108841] - C:\Program Files (x86)\Microsoft [10/11/2015 09:22:06] - |D| - [1670519] - C:\Program Files (x86)\Microsoft ASP.NET [31/01/2014 10:26:27] - |AD| - [617589788] - C:\Program Files (x86)\Microsoft Office [05/05/2016 20:34:48] - |D| - [42894550] - C:\Program Files (x86)\Microsoft Silverlight [04/02/2014 14:45:15] - |D| - [14904] - C:\Program Files (x86)\Microsoft Visual Studio [04/02/2014 14:45:18] - |D| - [3726168] - C:\Program Files (x86)\Microsoft Works [19/03/2019 05:52:44] - |D| - [23935] - C:\Program Files (x86)\Microsoft.NET [20/06/2019 14:21:48] - |D| - [266532303] - C:\Program Files (x86)\Mirillis [27/04/2014 19:32:13] - |D| - [128293600] - C:\Program Files (x86)\MotionStudios [26/08/2016 11:54:49] - |D| - [502583] - C:\Program Files (x86)\Mozilla Firefox [18/03/2016 18:29:54] - |D| - [605408] - C:\Program Files (x86)\Mozilla Maintenance Service [17/12/2019 14:30:07] - |D| - [174568380] - C:\Program Files (x86)\Mozilla Thunderbird [07/03/2018 16:24:27] - |D| - [119446079] - C:\Program Files (x86)\MP4Tools [07/08/2019 16:18:15] - |D| - [26521] - C:\Program Files (x86)\MSBuild [31/01/2014 10:26:24] - |D| - [71881160] - C:\Program Files (x86)\MSECache [26/04/2014 16:34:01] - |AD| - [154033] - C:\Program Files (x86)\MSXML 4.0 [05/02/2018 20:21:45] - |D| - [324796289] - C:\Program Files (x86)\MyHeritage [12/07/2017 10:55:23] - |D| - [995679] - C:\Program Files (x86)\NetRatingsNetSight [10/04/2017 17:52:54] - |D| - [289877359] - C:\Program Files (x86)\NVIDIA Corporation [18/08/2017 09:17:59] - |D| - [470664976] - C:\Program Files (x86)\obs-studio [26/01/2019 10:18:18] - |D| - [5627061] - C:\Program Files (x86)\PDFTK Builder [04/02/2014 18:04:35] - |D| - [12072346] - C:\Program Files (x86)\PhotoFiltre 7 [11/12/2015 17:59:23] - |AD| - [2372851] - C:\Program Files (x86)\PowerpointImageExtractor_V1_2 [26/04/2014 17:43:50] - |AD| - [1083886192] - C:\Program Files (x86)\proDAD [30/01/2014 17:35:10] - |D| - [6685980] - C:\Program Files (x86)\Realtek [07/08/2019 16:18:15] - |D| - [38462721] - C:\Program Files (x86)\Reference Assemblies [09/05/2018 08:59:50] - |D| - [335375419] - C:\Program Files (x86)\Samsung [09/05/2018 09:30:33] - |D| - [7159572] - C:\Program Files (x86)\Samsung Printers [09/05/2018 09:00:45] - |D| - [2154446] - C:\Program Files (x86)\SamsungPrinterLiveUpdate [09/05/2018 09:00:45] - |D| - [3424277] - C:\Program Files (x86)\SamsungPrinterLiveUpdateInstaller [14/03/2019 19:34:21] - |D| - [4771488] - C:\Program Files (x86)\SDA [04/02/2014 12:08:07] - |D| - [2373724] - C:\Program Files (x86)\SoftChris [10/12/2019 09:22:45] - |D| - [1777036] - C:\Program Files (x86)\SSDFresh [09/02/2015 16:32:19] - |D| - [107856] - C:\Program Files (x86)\stinger [30/01/2014 17:35:09] - |HD| - [0] - C:\Program Files (x86)\Temp [10/04/2017 17:52:38] - |HD| - [0] - C:\Program Files (x86)\Uninstall Information [07/06/2018 13:38:55] - |D| - [16012] - C:\Program Files (x86)\VulkanRT [19/03/2019 05:52:44] - |D| - [1741328] - C:\Program Files (x86)\Windows Defender [24/02/2014 09:37:01] - |D| - [1660593283] - C:\Program Files (x86)\Windows Kits [22/02/2014 09:01:30] - |AD| - [2207632] - C:\Program Files (x86)\Windows Live [19/03/2019 05:52:44] - |D| - [4077240] - C:\Program Files (x86)\Windows Mail [19/03/2019 13:02:58] - |D| - [3238765] - C:\Program Files (x86)\Windows Media Player [19/03/2019 13:02:58] - |D| - [39720] - C:\Program Files (x86)\Windows Multimedia Platform [19/03/2019 05:52:44] - |D| - [7559512] - C:\Program Files (x86)\Windows NT [19/03/2019 13:02:58] - |D| - [5276616] - C:\Program Files (x86)\Windows Photo Viewer [19/03/2019 13:02:58] - |D| - [39720] - C:\Program Files (x86)\Windows Portable Devices [19/03/2019 05:52:44] - |SHD| - [350731] - C:\Program Files (x86)\Windows Sidebar [19/03/2019 05:52:44] - |D| - [2250183] - C:\Program Files (x86)\WindowsPowerShell [20/05/2019 10:39:57] - |D| - [13976351] - C:\Program Files (x86)\Xiph.Org ---------- | C:\Program Files [09/01/2019 09:59:02] - |D| - [5204927] - C:\Program Files\7-Zip [10/04/2017 17:52:38] - |D| - [3048639] - C:\Program Files\ASUS [31/01/2014 11:09:56] - |D| - [1426864860] - C:\Program Files\AVAST Software [24/05/2018 21:57:04] - |D| - [50472088] - C:\Program Files\CCleaner [19/03/2019 05:52:43] - |D| - [147074444] - C:\Program Files\Common Files [28/10/2017 22:20:54] - |D| - [3246382] - C:\Program Files\CPUID [18/12/2015 18:09:53] - |AD| - [15476466] - C:\Program Files\Defraggler [19/03/2019 05:49:34] - |ASH| - [174] - C:\Program Files\desktop.ini [30/01/2014 17:16:29] - |SHD| - [0] - C:\Program Files\Fichiers communs [19/05/2019 10:27:04] - |D| - [70197420] - C:\Program Files\File Converter [11/12/2019 17:02:45] - |D| - [222537722] - C:\Program Files\FlashIntegro [20/07/2014 20:05:24] - |D| - [220065863] - C:\Program Files\Google [30/01/2014 17:38:10] - |D| - [79548430] - C:\Program Files\Intel [24/11/2017 14:32:54] - |D| - [0] - C:\Program Files\Intel Driver and Support Assistant [19/03/2019 05:52:44] - |D| - [3448438] - C:\Program Files\Internet Explorer [26/08/2016 15:53:48] - |D| - [237356704] - C:\Program Files\Java [22/09/2016 14:31:15] - |D| - [1691717] - C:\Program Files\Lexmark [05/02/2014 20:36:35] - |D| - [189840080] - C:\Program Files\Lexmark S510 Series [12/12/2019 18:11:36] - |D| - [609396513] - C:\Program Files\LibreOffice [05/01/2019 09:28:11] - |D| - [1249483415] - C:\Program Files\MAGIX [07/11/2019 22:23:21] - |D| - [208699906] - C:\Program Files\Malwarebytes [29/08/2018 15:33:25] - |D| - [61404710] - C:\Program Files\McAfee [04/02/2014 14:43:54] - |D| - [593814] - C:\Program Files\Microsoft Office [05/05/2016 20:34:48] - |AD| - [55728894] - C:\Program Files\Microsoft Silverlight [28/01/2018 16:15:07] - |D| - [0] - C:\Program Files\MiniTool Partition Wizard 10 [05/07/2019 18:22:12] - |D| - [85668887] - C:\Program Files\MiniTool Partition Wizard 11 [19/03/2019 05:52:44] - |D| - [0] - C:\Program Files\ModifiableWindowsApps [31/10/2019 22:05:25] - |D| - [201232728] - C:\Program Files\Mozilla Firefox [07/08/2019 16:18:15] - |D| - [25757] - C:\Program Files\MSBuild [10/04/2017 17:52:54] - |D| - [1986938864] - C:\Program Files\NVIDIA Corporation [10/04/2017 17:52:44] - |D| - [42224616] - C:\Program Files\Realtek [07/08/2019 16:18:15] - |D| - [36867241] - C:\Program Files\Reference Assemblies [16/11/2018 18:54:02] - |D| - [15790278] - C:\Program Files\rempl [23/11/2016 17:00:48] - |AD| - [15516312] - C:\Program Files\Speccy [09/02/2015 16:31:11] - |D| - [0] - C:\Program Files\stinger [22/08/2013 15:47:10] - |HD| - [0] - C:\Program Files\Uninstall Information [23/06/2014 18:10:12] - |D| - [269199] - C:\Program Files\Unlocker [18/06/2019 15:12:17] - |D| - [13107200] - C:\Program Files\UNP [06/02/2014 10:37:15] - |D| - [0] - C:\Program Files\VideoLAN [06/06/2017 15:05:56] - |D| - [22681412] - C:\Program Files\VS Revo Group [19/03/2019 05:52:44] - |D| - [15852398] - C:\Program Files\Windows Defender [19/03/2019 05:52:44] - |D| - [4294328] - C:\Program Files\Windows Mail [19/03/2019 13:02:58] - |D| - [4710289] - C:\Program Files\Windows Media Player [19/03/2019 13:02:58] - |D| - [47720] - C:\Program Files\Windows Multimedia Platform [19/03/2019 05:52:44] - |D| - [7895896] - C:\Program Files\Windows NT [19/03/2019 13:02:58] - |D| - [6093976] - C:\Program Files\Windows Photo Viewer [19/03/2019 13:02:58] - |D| - [47720] - C:\Program Files\Windows Portable Devices [19/03/2019 05:52:44] - |D| - [110373] - C:\Program Files\Windows Security [19/03/2019 05:52:44] - |SHD| - [0] - C:\Program Files\Windows Sidebar [19/03/2019 05:52:44] - |HD| - [2743206238] - C:\Program Files\WindowsApps [19/03/2019 05:52:44] - |D| - [2545983] - C:\Program Files\WindowsPowerShell [05/07/2019 18:14:41] - |D| - [189003] - C:\Program Files\WinPcap [11/02/2014 14:54:25] - |AD| - [7397969] - C:\Program Files\WinRAR ---------- | C:\Program Files (x86)\Common Files [16/12/2015 19:32:01] - |AD| - [126794583] - C:\Program Files (x86)\Common Files\Adobe [15/06/2015 14:35:35] - |AD| - [30866266] - C:\Program Files (x86)\Common Files\Adobe AIR [22/03/2014 11:31:13] - |D| - [26610111] - C:\Program Files (x86)\Common Files\Ahead [04/06/2014 16:05:41] - |D| - [66303118] - C:\Program Files (x86)\Common Files\Apple [03/12/2015 17:15:17] - |D| - [0] - C:\Program Files (x86)\Common Files\AV [21/03/2014 22:33:11] - |D| - [56740694] - C:\Program Files (x86)\Common Files\AVerMedia [27/12/2015 14:52:18] - |D| - [905920] - C:\Program Files (x86)\Common Files\BioWare [09/05/2018 09:43:15] - |D| - [402656] - C:\Program Files (x86)\Common Files\Common Desktop Agent [15/05/2014 14:46:45] - |AD| - [99992] - C:\Program Files (x86)\Common Files\DESIGNER [16/02/2017 09:30:46] - |D| - [133689780] - C:\Program Files (x86)\Common Files\DVDVideoSoft [18/08/2017 08:57:50] - |D| - [7987536] - C:\Program Files (x86)\Common Files\FlashIntegro [15/05/2018 16:57:49] - |D| - [4736627] - C:\Program Files (x86)\Common Files\Freemake Shared [30/01/2014 17:35:04] - |D| - [5015831] - C:\Program Files (x86)\Common Files\InstallShield [30/01/2014 17:39:29] - |D| - [249740] - C:\Program Files (x86)\Common Files\Intel Corporation [02/09/2018 20:40:04] - |D| - [0] - C:\Program Files (x86)\Common Files\IObit [08/02/2014 11:48:43] - |AD| - [53782553] - C:\Program Files (x86)\Common Files\MAGIX Services [05/01/2019 09:29:39] - |D| - [94720] - C:\Program Files (x86)\Common Files\MAGIX Shared [19/03/2019 05:52:44] - |D| - [371133330] - C:\Program Files (x86)\Common Files\Microsoft Shared [24/07/2018 21:02:46] - |D| - [1630416] - C:\Program Files (x86)\Common Files\Oracle [30/01/2014 17:37:38] - |D| - [196972] - C:\Program Files (x86)\Common Files\postureAgent [09/05/2018 09:01:57] - |D| - [12680455] - C:\Program Files (x86)\Common Files\Scan Process Machine [19/03/2019 05:52:44] - |D| - [2702] - C:\Program Files (x86)\Common Files\Services [27/12/2015 16:18:43] - |D| - [3727424] - C:\Program Files (x86)\Common Files\Steam [19/03/2019 05:52:44] - |D| - [47027549] - C:\Program Files (x86)\Common Files\System [14/02/2017 15:25:13] - |D| - [7389312] - C:\Program Files (x86)\Common Files\WebM Project [22/02/2014 09:00:45] - |D| - [0] - C:\Program Files (x86)\Common Files\Windows Live ---------- | C:\Program Files\Common files [03/12/2015 17:15:17] - |D| - [2] - C:\Program Files\Common files\AV [06/12/2017 22:00:43] - |D| - [1873288] - C:\Program Files\Common files\Avast Software [09/05/2018 09:43:15] - |D| - [515808] - C:\Program Files\Common files\Common Desktop Agent [25/01/2018 15:31:32] - |D| - [63369912] - C:\Program Files\Common files\FlashIntegro [08/01/2019 15:07:57] - |D| - [11264] - C:\Program Files\Common files\MAGIX Services [05/01/2019 09:29:39] - |D| - [112128] - C:\Program Files\Common files\MAGIX Shared [19/03/2019 05:52:43] - |D| - [69910097] - C:\Program Files\Common files\microsoft shared [19/03/2019 05:52:44] - |D| - [2702] - C:\Program Files\Common files\Services [19/03/2019 05:52:44] - |D| - [10282891] - C:\Program Files\Common files\System [10/09/2018 17:41:34] - |D| - [996352] - C:\Program Files\Common files\WebM Project ---------- | Tasks [MD5.00000000000000000000000000000000] - [27/01/2019 19:32:48] - |D| - [0] - C:\WINDOWS\Tasks\ImCleanDisabled [MD5.F1A6CD5ADAAB953A6764EA364E17BFB8] - [07/08/2019 15:54:53] - |AH| - [6] - C:\WINDOWS\Tasks\SA.DAT [MD5.00000000000000000000000000000000] - [07/08/2019 15:54:53] - |D| - [0] - C:\WINDOWS\System32\Tasks\2BrightSparks [MD5.2FFEB9621E36D1C5D45C8916B019C24B] - [10/12/2019 18:34:55] - |A| - [3482] - C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task : C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [MD5.D6E1A9CC3248FB3635C93F32C9B98D66] - [07/08/2019 15:54:53] - |A| - [3922] - C:\WINDOWS\System32\Tasks\Adobe Flash Player NPAPI Notifier : C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_303_Plugin.exe [MD5.54710B6220C8A4A06C17F7E5A2CB5518] - [13/10/2019 21:28:07] - |A| - [3892] - C:\WINDOWS\System32\Tasks\Adobe Flash Player PPAPI Notifier : C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_303_pepper.exe [MD5.166515B1233DEB1BCBA08450FCB676C3] - [13/10/2019 21:32:35] - |A| - [3576] - C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater : C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [MD5.802AAF1FA6821E0685E2359379C948E3] - [07/08/2019 15:54:53] - |A| - [2818] - C:\WINDOWS\System32\Tasks\AdobeGCInvoker-1.0-MicrosoftAccount-miclau.evrard@sfr.fr : C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [MD5.BEC9D3A3CC64916BC80BB3CE4E885C5D] - [07/08/2019 15:54:53] - |A| - [4264] - C:\WINDOWS\System32\Tasks\Avast Emergency Update : C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [MD5.00000000000000000000000000000000] - [07/08/2019 15:54:53] - |D| - [6872] - C:\WINDOWS\System32\Tasks\AVAST Software [MD5.DCFE8C1EA3EDB3532E5978569A453472] - [07/08/2019 15:54:53] - |A| - [2988] - C:\WINDOWS\System32\Tasks\CCleaner Update : C:\Program Files\CCleaner\CCUpdate.exe [MD5.D9B401B3EE19311633315B0847CC7109] - [07/08/2019 15:54:53] - |A| - [2218] - C:\WINDOWS\System32\Tasks\CCleanerSkipUAC : "C:\Program Files\CCleaner\CCleaner.exe" [MD5.385951BBC5DD54DB479D7114B3C62DB8] - [07/08/2019 15:54:53] - |A| - [2376] - C:\WINDOWS\System32\Tasks\CreateChoiceProcessTask : C:\Windows\BrowserChoice\browserchoice.exe [MD5.D62FEACC403DA7CD01DEAAF2606206DA] - [07/08/2019 15:54:53] - |A| - [2786] - C:\WINDOWS\System32\Tasks\EPM Preload : C:\Program Files (x86)\Samsung\Easy Printer Manager\EPM2DotNetHandler.exe [MD5.A457ACC9B20380ACE2FA303383CBE8C0] - [07/08/2019 15:54:53] - |A| - [3294] - C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore : C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [MD5.98C86E48BA62094CDC66D2387C7DD3D4] - [07/08/2019 15:54:53] - |A| - [3518] - C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA : C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [MD5.C4291B5119D4DF88ED8D1C3D08AED9FF] - [07/08/2019 15:54:53] - |A| - [3424] - C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-548730727-4139670515-3000484307-1001Core : C:\Users\EVRARD\AppData\Local\Google\Update\GoogleUpdate.exe [MD5.AE313DE0EB87BF895466114A12282E06] - [07/08/2019 15:54:53] - |A| - [3692] - C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-548730727-4139670515-3000484307-1001UA : C:\Users\EVRARD\AppData\Local\Google\Update\GoogleUpdate.exe [MD5.00000000000000000000000000000000] - [07/08/2019 15:54:53] - |D| - [3064] - C:\WINDOWS\System32\Tasks\HardDiskSentinel [MD5.0B681080710490B52A65DFDB9E0FE9C7] - [07/08/2019 15:54:53] - |A| - [2970] - C:\WINDOWS\System32\Tasks\IntelSURQC-Upgrade-86621605-2a0b-4128-8ffc-15514c247132 : "C:\Program Files\Intel\SUR\QUEENCREEK\Updater\bin\IntelSoftwareAssetManagerService.exe" [MD5.9F593DCC2CC17E75E839120471883180] - [07/08/2019 15:54:53] - |A| - [2604] - C:\WINDOWS\System32\Tasks\IntelSURQC-Upgrade-86621605-2a0b-4128-8ffc-15514c247132-Logon : "C:\Program Files\Intel\SUR\QUEENCREEK\Updater\bin\IntelSoftwareAssetManagerService.exe" [MD5.D4C1A100A0CE0B44EC12F053462493A7] - [07/08/2019 15:54:53] - |A| - [3042] - C:\WINDOWS\System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 : C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [MD5.00000000000000000000000000000000] - [19/03/2019 05:52:45] - |D| - [652692] - C:\WINDOWS\System32\Tasks\Microsoft [MD5.CE0E61838C45A2197B7A48BA49DEC62C] - [07/08/2019 15:54:53] - |A| - [3196] - C:\WINDOWS\System32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} : C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [MD5.5CCEDECCAB4A4BABE835AFF322904A5D] - [07/08/2019 15:54:53] - |A| - [3398] - C:\WINDOWS\System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} : C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [MD5.D6E7E563512D61018992A38D791ADD11] - [07/08/2019 15:54:53] - |A| - [3152] - C:\WINDOWS\System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} : "C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe" [MD5.4C16A7D7D4E05C74CF806CADB99C4205] - [07/08/2019 15:54:53] - |A| - [2914] - C:\WINDOWS\System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} : C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [MD5.BB8B15777BD41ED0AB359706D930F81C] - [07/08/2019 15:54:53] - |A| - [2984] - C:\WINDOWS\System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} : C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [MD5.A416713998B405C15DF29DC980393AF6] - [07/08/2019 15:54:53] - |A| - [2744] - C:\WINDOWS\System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} : C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [MD5.0CED69610453D2A1B3E3CABB26607109] - [07/08/2019 15:54:53] - |A| - [2948] - C:\WINDOWS\System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} : C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [MD5.BF80322BA70BC6D19C34DF08CB9841D6] - [07/08/2019 15:54:53] - |A| - [2948] - C:\WINDOWS\System32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} : C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [MD5.3256E562FD8D5B7D2BD75B52949B873F] - [07/08/2019 15:54:53] - |A| - [2948] - C:\WINDOWS\System32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} : C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [MD5.20F85B7495B3F9E235E4B669B9CB9D47] - [07/08/2019 15:54:53] - |A| - [2948] - C:\WINDOWS\System32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} : C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [MD5.C47A10015F78D7289F4F6049F0218F3C] - [07/08/2019 15:54:53] - |A| - [2858] - C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-548730727-4139670515-3000484307-1001 : %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe [MD5.7C76A8AA67688ABFBD31A632B3A044B5] - [07/08/2019 15:54:53] - |A| - [2810] - C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-548730727-4139670515-3000484307-1001 : %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe [MD5.00000000000000000000000000000000] - [07/08/2019 15:54:53] - |D| - [0] - C:\WINDOWS\System32\Tasks\Restore Point Creator [MD5.D126DCFD602358F8BAB329C8927192C0] - [07/08/2019 15:54:53] - |A| - [2936] - C:\WINDOWS\System32\Tasks\RunAsStdUser_MyComGames : C:\Users\EVRARD\AppData\Local\MyComGames\MyComGames.exe [MD5.00000000000000000000000000000000] - [07/08/2019 15:54:53] - |D| - [2928] - C:\WINDOWS\System32\Tasks\S-1-5-21-548730727-4139670515-3000484307-1001 [MD5.54E9C4CC9044C142875F639071BF2AB2] - [07/08/2019 15:54:53] - |A| - [2546] - C:\WINDOWS\System32\Tasks\UpdateDetector : C:\Program Files (x86)\Glarysoft\Update Detector 5\UpdateDetector.exe [MD5.00000000000000000000000000000000] - [07/08/2019 15:54:53] - |D| - [0] - C:\WINDOWS\System32\Tasks\WPD [MD5.BDAC67B70EFC58094504943E89153490] - [07/08/2019 15:54:53] - |A| - [2386] - C:\WINDOWS\System32\Tasks\{0353A36E-2228-4EA6-9EE1-3FB9C487BB33} : "c:\program files (x86)\google\chrome\application\chrome.exe" [MD5.F84B6E018AA1BBEF08541997BC3CEC86] - [07/08/2019 15:54:53] - |A| - [2324] - C:\WINDOWS\System32\Tasks\{1DFD0248-92C4-4C94-8007-AB87138DABAF} : "c:\program files (x86)\google\chrome\application\chrome.exe" [MD5.054A1AF2D54DFE0346D9020CDF7C35D6] - [07/08/2019 15:54:53] - |A| - [2386] - C:\WINDOWS\System32\Tasks\{31FFAB5B-29AE-4308-8E14-1BFD84347BC1} : "c:\program files (x86)\google\chrome\application\chrome.exe" [MD5.A3C10355A67FBC22A866A48C4BF31505] - [07/08/2019 15:54:53] - |A| - [2324] - C:\WINDOWS\System32\Tasks\{5EDF5B38-0831-4D63-AECF-94FBACA04B2F} : "c:\program files (x86)\google\chrome\application\chrome.exe" [MD5.B50E83285F3BE871DD8161AE5F172799] - [07/08/2019 15:54:53] - |A| - [2386] - C:\WINDOWS\System32\Tasks\{8CB99EC3-4940-420E-A1D3-2A2092A6EB89} : "c:\program files (x86)\google\chrome\application\chrome.exe" [MD5.92FC71B5D65438A978AF8978C9D248BF] - [07/08/2019 15:54:53] - |A| - [2386] - C:\WINDOWS\System32\Tasks\{CC4E43D2-EEFA-4757-8C8D-1B73B880D344} : "c:\program files (x86)\google\chrome\application\chrome.exe" [MD5.00000000000000000000000000000000] - [19/03/2019 05:52:46] - |D| - [0] - C:\WINDOWS\Syswow64\Tasks\Microsoft ---------- | Firewall [HKLM\SYSTEM\CurrentControlSet\Services\sharedaccess\Parameters\FirewallPolicy\FirewallRules] "WiFiDirect-KM-Driver-In-TCP"=v2.30|Action=Allow|Active=TRUE|Dir=In|Protocol=6|App=System|Name=@wlansvc.dll,-37378|Desc=@wlansvc.dll,-37890|EmbedCtxt=@wlansvc.dll,-36865|TTK2_27=WFDKmDriver| "WiFiDirect-KM-Driver-Out-TCP"=v2.30|Action=Allow|Active=TRUE|Dir=Out|Protocol=6|App=System|Name=@wlansvc.dll,-37379|Desc=@wlansvc.dll,-37891|EmbedCtxt=@wlansvc.dll,-36865|TTK2_27=WFDKmDriver| "WiFiDirect-KM-Driver-In-UDP"=v2.30|Action=Allow|Active=TRUE|Dir=In|Protocol=17|App=System|Name=@wlansvc.dll,-37380|Desc=@wlansvc.dll,-37892|EmbedCtxt=@wlansvc.dll,-36865|TTK2_27=WFDKmDriver| "WiFiDirect-KM-Driver-Out-UDP"=v2.30|Action=Allow|Active=TRUE|Dir=Out|Protocol=17|App=System|Name=@wlansvc.dll,-37381|Desc=@wlansvc.dll,-37893|EmbedCtxt=@wlansvc.dll,-36865|TTK2_27=WFDKmDriver| "DeliveryOptimization-TCP-In"=v2.30|Action=Allow|Active=TRUE|Dir=In|Protocol=6|LPort=7680|App=%SystemRoot%\system32\svchost.exe|Svc=dosvc|Name=@%systemroot%\system32\dosvc.dll,-102|Desc=@%systemroot%\system32\dosvc.dll,-104|EmbedCtxt=@%systemroot%\system32\dosvc.dll,-100|Edge=TRUE| "DeliveryOptimization-UDP-In"=v2.30|Action=Allow|Active=TRUE|Dir=In|Protocol=17|LPort=7680|App=%SystemRoot%\system32\svchost.exe|Svc=dosvc|Name=@%systemroot%\system32\dosvc.dll,-103|Desc=@%systemroot%\system32\dosvc.dll,-104|EmbedCtxt=@%systemroot%\system32\dosvc.dll,-100|Edge=TRUE| "Netlogon-NamedPipe-In"=v2.30|Action=Allow|Active=FALSE|Dir=In|Protocol=6|LPort=445|App=System|Name=@netlogon.dll,-1003|Desc=@netlogon.dll,-1006|EmbedCtxt=@netlogon.dll,-1010| "Netlogon-TCP-RPC-In"=v2.30|Action=Allow|Active=FALSE|Dir=In|Protocol=6|LPort=RPC|App=%SystemRoot%\System32\lsass.exe|Name=@netlogon.dll,-1008|Desc=@netlogon.dll,-1009|EmbedCtxt=@netlogon.dll,-1010| "WirelessDisplay-In-TCP"=v2.30|Action=Allow|Active=TRUE|Dir=In|Protocol=6|App=%systemroot%\system32\WUDFHost.exe|Name=@wifidisplay.dll,-10200|Desc=@wifidisplay.dll,-10201|LUAuth=O:LSD:(A;;CC;;;S-1-5-84-0-0-0-0-0)|EmbedCtxt=@wifidisplay.dll,-100|TTK2_22=WFDDisplay| "WirelessDisplay-Out-TCP"=v2.30|Action=Allow|Active=TRUE|Dir=Out|Protocol=6|App=%systemroot%\system32\WUDFHost.exe|Name=@wifidisplay.dll,-10202|Desc=@wifidisplay.dll,-10203|LUAuth=O:LSD:(A;;CC;;;S-1-5-84-0-0-0-0-0)|EmbedCtxt=@wifidisplay.dll,-100|TTK2_22=WFDDisplay| "WirelessDisplay-Out-UDP"=v2.30|Action=Allow|Active=TRUE|Dir=Out|Protocol=17|App=%systemroot%\system32\WUDFHost.exe|Name=@wifidisplay.dll,-10204|Desc=@wifidisplay.dll,-10205|LUAuth=O:LSD:(A;;CC;;;S-1-5-84-0-0-0-0-0)|EmbedCtxt=@wifidisplay.dll,-100|TTK2_22=WFDDisplay| "WirelessDisplay-Infra-In-TCP"=v2.30|Action=Allow|Active=TRUE|Dir=In|Protocol=6|LPort=7250|App=%systemroot%\system32\CastSrv.exe|Name=@wifidisplay.dll,-10206|Desc=@wifidisplay.dll,-10207|EmbedCtxt=@wifidisplay.dll,-100| "{623B4117-44A9-4947-93CB-4971F60901E2}"=v2.29|Action=Allow|Active=TRUE|Dir=In|App=C:\Program Files (x86)\Samsung\Samsung Printer Diagnostics\SEInstall\SPD\ESM.exe|Name=Diagnostics d'imprimante Samsung|Desc=Diagnostics d'imprimante Samsung|EmbedCtxt=Diagnostics d'imprimante Samsung| "{4C9F1664-006B-453D-BC92-0FE609D5C140}"=v2.29|Action=Allow|Active=TRUE|Dir=Out|App=C:\Program Files (x86)\DVDVideoSoft\Free Torrent Download\FreeTorrentDownload.exe|Name=Free Torrent Download (ANY)|Desc=Free Torrent Download (ANY)|EmbedCtxt=Free Torrent Download (ANY)| "{F0AA2399-ECA5-4FED-BD90-2E004DC5BB4E}"=v2.29|Action=Allow|Active=TRUE|Dir=In|App=C:\Program Files (x86)\DVDVideoSoft\Free Torrent Download\FreeTorrentDownload.exe|Name=Free Torrent Download (ANY)|Desc=Free Torrent Download (ANY)|EmbedCtxt=Free Torrent Download (ANY)|Edge=TRUE| "{0C935990-C9BE-497A-89F6-A2C541772BB1}"=v2.29|Action=Allow|Active=TRUE|Dir=In|Profile=Domain|Profile=Private|Name=Print 3D|Desc=Print 3D|LUOwn=S-1-5-21-548730727-4139670515-3000484307-1001|AppPkgId=S-1-15-2-4177018473-2823706547-3652141868-2730301309-560159678-43221128-488844051|EmbedCtxt=Print 3D|Platform=2:6:2|Platform2=GTEQ| "{6BF40422-0527-4459-AD42-00A009346FEE}"=v2.29|Action=Allow|Active=TRUE|Dir=Out|Name=Print 3D|Desc=Print 3D|LUOwn=S-1-5-21-548730727-4139670515-3000484307-1001|AppPkgId=S-1-15-2-4177018473-2823706547-3652141868-2730301309-560159678-43221128-488844051|EmbedCtxt=Print 3D|Platform=2:6:2|Platform2=GTEQ| "{EE2ABF7E-AD57-44ED-97C8-7E041F3E1D44}"=v2.29|Action=Allow|Active=TRUE|Dir=Out|Name=windows_ie_ac_001|Desc=Created by IE|LUOwn=S-1-5-21-548730727-4139670515-3000484307-1001|AppPkgId=S-1-15-2-1430448594-2639229838-973813799-439329657-1197984847-4069167804-1277922394|EmbedCtxt=windows_ie_ac_001|Platform=2:6:2|Platform2=GTEQ| "{C66E0023-3076-445C-B174-0F26A0C72506}"=v2.28|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Program Files\CCleaner\CCUpdate.exe|Name=CCleaner Update| "{2A9C9281-5707-4413-AA69-BE0B6646F772}"=v2.28|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Program Files\CCleaner\CCUpdate.exe|Name=CCleaner Update| "{B7CC0C63-AF2D-46D4-A389-EA49A6F2D4C6}"=v2.29|Action=Allow|Active=TRUE|Dir=In|RA4=LocalSubnet|RA6=LocalSubnet|App=C:\Program Files\MAGIX\Video deluxe Premium\2017\Videodeluxe.exe|Name=MAGIX Vidéo deluxe Premium|Edge=TRUE| "{F96F8ADC-66A4-49CE-9D39-A30B27054EF2}"=v2.29|Action=Allow|Active=TRUE|Dir=Out|Name=Xbox TCUI|Desc=Xbox TCUI|LUOwn=S-1-5-21-548730727-4139670515-3000484307-1001|AppPkgId=S-1-15-2-2603511428-3224021693-1028932517-3941269705-3349582775-2312504883-4057327947|EmbedCtxt=Xbox TCUI|Platform=2:6:2|Platform2=GTEQ| "{6B2C3DEC-00D4-4B59-88C3-C27D6C9A1E90}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe|Name=CDA Server| "{B0E751D6-97F3-4993-8FA9-9E5B58A35F3E}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe|Name=CDA Server| "{59A421CD-174A-46D2-B893-C0EDBC3C5064}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Profile=Public|App=C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe|Name=CDA Server| "{D046EADF-BC99-4B81-ABCC-944921D7BC65}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Profile=Public|App=C:\Program Files (x86)\Samsung\Easy Printer Manager\EPM2Migrator.exe|Name=EPM2Migrator| "{E690B089-1C62-4834-AFD8-666015554B96}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Profile=Public|App=C:\Program Files (x86)\Samsung\Easy Printer Manager\EPM2AlertList.exe|Name=EPM2AlertList| "{A7A56189-3DCF-4E80-8E7D-4238E9C71057}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Profile=Public|App=C:\Program Files (x86)\Samsung\Easy Printer Manager\OrderSupplies.exe|Name=EPM2OrderSupply| "{2E473B22-BB8F-461B-9B3A-D18498C09432}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Profile=Public|App=C:\Program Files (x86)\Samsung\Easy Printer Manager\EasyPrinterManagerV2.exe|Name=EasyPrinterManagerV2| "{12A6A636-894F-4E13-A4B5-9513CE030CF5}"=v2.27|Action=Allow|Active=TRUE|Dir=In|App=C:\Program Files (x86)\Samsung\Samsung Printer Diagnostics\SEInstall\SPD\WebInstallAgent\SPNTInst.exe|Name=C:\Program Files (x86)\Samsung\Samsung Printer Diagnostics\SEInstall\SPD\WebInstallAgent\SPNTInst.exe|Desc=C:\Program Files (x86)\Samsung\Samsung Printer Diagnostics\SEInstall\SPD\WebInstallAgent\SPNTInst.exe|EmbedCtxt=C:\Program Files (x86)\Samsung\Samsung Printer Diagnostics\SEInstall\SPD\WebInstallAgent\SPNTInst.exe| "{DAAF3085-769A-475D-B439-7A98EC71E834}"=v2.27|Action=Allow|Active=TRUE|Dir=In|App=C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe|Name=CDA Server|Desc=CDA Server|EmbedCtxt=CDA Server| "{0F36FC8C-B6AC-4BB3-8C2D-C81D51410C22}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Profile=Public|App=C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe|Name=CDA Server| "{90F7E726-60F0-4AA3-8364-8325471949F7}"=v2.27|Action=Allow|Active=TRUE|Dir=In|App=C:\Program Files (x86)\Samsung\Samsung Printer Diagnostics\SEInstall\SPD\WebInstallAgent\SPNTInst.exe|Name=C:\Program Files (x86)\Samsung\Samsung Printer Diagnostics\SEInstall\SPD\WebInstallAgent\SPNTInst.exe|Desc=C:\Program Files (x86)\Samsung\Samsung Printer Diagnostics\SEInstall\SPD\WebInstallAgent\SPNTInst.exe|EmbedCtxt=C:\Program Files (x86)\Samsung\Samsung Printer Diagnostics\SEInstall\SPD\WebInstallAgent\SPNTInst.exe| "{3876C0B2-1F39-40A3-A851-BBF7D5CDFF4E}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Program Files (x86)\Samsung\Easy Document Creator\EDC.exe|Name=Samsung Easy Document Creator| "{DB378708-EFC4-4270-9F37-C35CE19394BD}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Program Files (x86)\Samsung\Easy Document Creator\EDC.exe|Name=Samsung Easy Document Creator| "{52497427-B64D-4544-956E-EC2D1C72E3AF}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Windows\twain_32\Samsung\SLM2070\ScanCDLM\ScanCDLM.exe|Name=Samsung Scanner Discovery Module V3| "{47A1EA4A-089D-4473-8276-8FC22B896D87}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Windows\twain_32\Samsung\SLM2070\ScanCDLM\ScanCDLM.exe|Name=Samsung Scanner Discovery Module V3| "{F1D54364-501D-4664-92AF-81CCBDA25881}"=v2.27|Action=Allow|Active=TRUE|Dir=Out|Profile=Public|IFType=Wireless|Name=Samsung Printer Experience|Desc=Samsung Printer Experience|LUOwn=S-1-5-21-548730727-4139670515-3000484307-1001|AppPkgId=S-1-15-2-199443308-783181745-3731900621-737618142-274797140-2538204478-2503832961|EmbedCtxt=Samsung Printer Experience|Platform=2:6:2|Platform2=GTEQ|TTK2_22=WFDDevices| "{5D57AB15-FE00-4E6B-854F-A49B59EA9242}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Profile=Public|IFType=Wireless|Name=Samsung Printer Experience|Desc=Samsung Printer Experience|LUOwn=S-1-5-21-548730727-4139670515-3000484307-1001|AppPkgId=S-1-15-2-199443308-783181745-3731900621-737618142-274797140-2538204478-2503832961|EmbedCtxt=Samsung Printer Experience|Platform=2:6:2|Platform2=GTEQ|TTK2_22=WFDDevices| "{AD62ADD9-D56E-4BCB-B3E8-F8D291958F52}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Name=Samsung Printer Experience|Desc=Samsung Printer Experience|LUOwn=S-1-5-21-548730727-4139670515-3000484307-1001|AppPkgId=S-1-15-2-199443308-783181745-3731900621-737618142-274797140-2538204478-2503832961|EmbedCtxt=Samsung Printer Experience|Platform=2:6:2|Platform2=GTEQ|Edge=TRUE| "{3DD899FB-A5E8-4F75-97F8-9A5B53310494}"=v2.27|Action=Allow|Active=TRUE|Dir=Out|Name=Samsung Printer Experience|Desc=Samsung Printer Experience|LUOwn=S-1-5-21-548730727-4139670515-3000484307-1001|AppPkgId=S-1-15-2-199443308-783181745-3731900621-737618142-274797140-2538204478-2503832961|EmbedCtxt=Samsung Printer Experience|Platform=2:6:2|Platform2=GTEQ| "{655D80E3-2EE3-4F2D-8BA3-4B95F2FD117B}"=v2.27|Action=Allow|Active=TRUE|Dir=Out|Protocol=6|Profile=Private|Profile=Public|App=C:\Program Files (x86)\Iperius Backup\IperiusService.exe|Name=Iperius Backup Service|Desc=Iperius Backup Service| "{3D53DFA6-DCA2-4C5B-86EC-414DB6F3C5A3}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|Profile=Public|App=C:\Program Files (x86)\Iperius Backup\IperiusService.exe|Name=Iperius Backup Service|Desc=Iperius Backup Service| "{8F8A3BB8-B020-4E8B-99E2-CA97280F06D9}"=v2.27|Action=Allow|Active=TRUE|Dir=Out|Protocol=6|Profile=Private|Profile=Public|App=C:\Program Files (x86)\Iperius Backup\Iperius.exe|Name=Iperius Backup|Desc=Iperius Backup| "{A298B9C4-E6D1-4FEC-AD72-0AF8BC0CBF84}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|Profile=Public|App=C:\Program Files (x86)\Iperius Backup\Iperius.exe|Name=Iperius Backup|Desc=Iperius Backup| "{6A58B55D-1ACF-4C35-9DA2-6A7293EA7615}"=v2.27|Action=Allow|Active=TRUE|Dir=In|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|App=%systemroot%\system32\alg.exe|Name=@ipnathlp.dll,-140|Desc=@ipnathlp.dll,-140|EmbedCtxt=@ipnathlp.dll,-140| "{77AB7ADE-4F17-4D60-BAEB-53FA264249B1}"=v2.27|Action=Allow|Active=TRUE|Dir=Out|Protocol=6|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|App=%systemroot%\system32\svchost.exe|Svc=upnphost|Name=@ipnathlp.dll,-149|Desc=@ipnathlp.dll,-10148|EmbedCtxt=@ipnathlp.dll,-140| "{4DA83184-F8FF-48A2-A970-D2109F9D08F1}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=58|ICMP6=133:0|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|Name=@ipnathlp.dll,-148|Desc=@ipnathlp.dll,-10147|EmbedCtxt=@ipnathlp.dll,-140| "{4576377D-14BF-4FA7-ACE2-1BFBCE30C6DA}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=17|LPort=547|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|App=%systemroot%\system32\svchost.exe|Svc=SharedAccess|Name=@ipnathlp.dll,-142|Desc=@ipnathlp.dll,-10141|EmbedCtxt=@ipnathlp.dll,-140| "{23C5663A-4F5C-42CE-9555-E5CF5F00F281}"=v2.27|Action=Allow|Active=TRUE|Dir=Out|Protocol=6|RPort=2869|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|App=System|Name=@ipnathlp.dll,-152|Desc=@ipnathlp.dll,-10151|EmbedCtxt=@ipnathlp.dll,-140| "{9F8DB628-E15F-45CE-B1BB-E22FC3F5EBBD}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=6|LPort=2869|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|App=System|Name=@ipnathlp.dll,-146|Desc=@ipnathlp.dll,-10145|EmbedCtxt=@ipnathlp.dll,-140| "{7050586B-403B-4A2E-A7DE-190E13E70A33}"=v2.27|Action=Allow|Active=TRUE|Dir=Out|Protocol=17|RPort=1900|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|App=%systemroot%\system32\svchost.exe|Svc=ssdpsrv|Name=@ipnathlp.dll,-150|Desc=@ipnathlp.dll,-10150|EmbedCtxt=@ipnathlp.dll,-140| "{E2DBFD2E-BC1E-428B-97E3-B9F156E93AFD}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=17|LPort=1900|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|App=%systemroot%\system32\svchost.exe|Svc=ssdpsrv|Name=@ipnathlp.dll,-147|Desc=@ipnathlp.dll,-10146|EmbedCtxt=@ipnathlp.dll,-140| "{4D233FBD-19EA-4862-AD4A-164C7BA951E9}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=17|LPort=53|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|App=%systemroot%\system32\svchost.exe|Svc=SharedAccess|Name=@ipnathlp.dll,-143|Desc=@ipnathlp.dll,-10142|EmbedCtxt=@ipnathlp.dll,-140| "{3B1A3260-17AE-4824-B134-D8000225E582}"=v2.27|Action=Allow|Active=TRUE|Dir=In|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|App=%systemroot%\system32\alg.exe|Name=@ipnathlp.dll,-140|Desc=@ipnathlp.dll,-140|EmbedCtxt=@ipnathlp.dll,-140| "{A85D7470-0E75-435B-92B0-EB272728F9D1}"=v2.27|Action=Allow|Active=TRUE|Dir=Out|Protocol=6|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|App=%systemroot%\system32\svchost.exe|Svc=upnphost|Name=@ipnathlp.dll,-149|Desc=@ipnathlp.dll,-10148|EmbedCtxt=@ipnathlp.dll,-140| "{75CCBECF-C38B-460A-AF97-C98A0322C137}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=58|ICMP6=133:0|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|Name=@ipnathlp.dll,-148|Desc=@ipnathlp.dll,-10147|EmbedCtxt=@ipnathlp.dll,-140| "{49510091-0B86-42F6-8896-A8A4D4216CD0}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=17|LPort=547|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|App=%systemroot%\system32\svchost.exe|Svc=SharedAccess|Name=@ipnathlp.dll,-142|Desc=@ipnathlp.dll,-10141|EmbedCtxt=@ipnathlp.dll,-140| "{B9D62D04-FB5C-4370-9813-77D78EC801F5}"=v2.27|Action=Allow|Active=TRUE|Dir=Out|Protocol=6|RPort=2869|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|App=System|Name=@ipnathlp.dll,-152|Desc=@ipnathlp.dll,-10151|EmbedCtxt=@ipnathlp.dll,-140| "{18B9C858-0C01-499B-8DC0-51CDFE094122}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=6|LPort=2869|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|App=System|Name=@ipnathlp.dll,-146|Desc=@ipnathlp.dll,-10145|EmbedCtxt=@ipnathlp.dll,-140| "{D17222CC-5E38-460F-9AF7-9F6352D68046}"=v2.27|Action=Allow|Active=TRUE|Dir=Out|Protocol=17|RPort=1900|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|App=%systemroot%\system32\svchost.exe|Svc=ssdpsrv|Name=@ipnathlp.dll,-150|Desc=@ipnathlp.dll,-10150|EmbedCtxt=@ipnathlp.dll,-140| "{F7D9EF50-CD38-4277-9193-650C4A599B14}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=17|LPort=1900|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|App=%systemroot%\system32\svchost.exe|Svc=ssdpsrv|Name=@ipnathlp.dll,-147|Desc=@ipnathlp.dll,-10146|EmbedCtxt=@ipnathlp.dll,-140| "{2C4514A1-EB90-4F5A-AE30-1095CA4BAEC9}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=17|LPort=53|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|App=%systemroot%\system32\svchost.exe|Svc=SharedAccess|Name=@ipnathlp.dll,-143|Desc=@ipnathlp.dll,-10142|EmbedCtxt=@ipnathlp.dll,-140| "UDP Query User{BB9DFDC0-7CA2-48BF-B791-4882B664A438}C:\program files (x86)\hercules\webcam station evolution\stationev.exe"=v2.10|Action=Block|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\program files (x86)\hercules\webcam station evolution\stationev.exe|Name=Hercules Webcam Station Evolution|Desc=Hercules Webcam Station Evolution| "TCP Query User{1E6C989B-9F4B-4C39-AB6D-9579CAA7B91E}C:\program files (x86)\hercules\webcam station evolution\stationev.exe"=v2.10|Action=Block|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\program files (x86)\hercules\webcam station evolution\stationev.exe|Name=Hercules Webcam Station Evolution|Desc=Hercules Webcam Station Evolution| "{D9028024-6D0D-4C55-8BCF-E844DBCE62E9}"=v2.26|Action=Allow|Active=TRUE|Dir=Out|Name=ASUS Welcome|Desc=ASUS Welcome|LUOwn=S-1-5-21-548730727-4139670515-3000484307-1001|AppPkgId=S-1-15-2-1791334737-3644637894-912171476-726613620-3748997741-2897954968-3492054033|EmbedCtxt=ASUS Welcome|Platform=2:6:2|Platform2=GTEQ| "UDP Query User{ADE941DC-21E7-45AF-8B41-DFC81AF132F9}C:\program files (x86)\magix\video deluxe 2014 premium\videodeluxe.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\program files (x86)\magix\video deluxe 2014 premium\videodeluxe.exe|Name=MAGIX Video deluxe 2014 Plus|Desc=MAGIX Video deluxe 2014 Plus|Defer=User| "TCP Query User{798B619E-C63D-4F81-BF9A-620287A1B9C3}C:\program files (x86)\magix\video deluxe 2014 premium\videodeluxe.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\program files (x86)\magix\video deluxe 2014 premium\videodeluxe.exe|Name=MAGIX Video deluxe 2014 Plus|Desc=MAGIX Video deluxe 2014 Plus|Defer=User| "UDP Query User{0F2F530B-4358-4F9A-8CD2-4D3DDEC59512}C:\program files (x86)\magix\video deluxe 2014 premium\videodeluxe.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\program files (x86)\magix\video deluxe 2014 premium\videodeluxe.exe|Name=MAGIX Video deluxe 2014 Plus|Desc=MAGIX Video deluxe 2014 Plus|Defer=User| "TCP Query User{6C06B46A-6DB4-4EDD-A768-5386F28EBD98}C:\program files (x86)\magix\video deluxe 2014 premium\videodeluxe.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\program files (x86)\magix\video deluxe 2014 premium\videodeluxe.exe|Name=MAGIX Video deluxe 2014 Plus|Desc=MAGIX Video deluxe 2014 Plus|Defer=User| "{17BB5B95-499E-42FA-B6FE-795A1EA39D35}"=v2.22|Action=Allow|Active=TRUE|Dir=In|App=C:\Program Files (x86)\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe|Name=WebKit|Edge=TRUE| "UDP Query User{47413CDB-5527-463D-BE15-9286101CFAAA}D:\fscommand\updater.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=D:\fscommand\updater.exe|Name=Hercules Updater|Desc=Hercules Updater|Defer=User| "TCP Query User{C99E2300-0A6A-47FC-8D2D-DAEBE8D2F02E}D:\fscommand\updater.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=D:\fscommand\updater.exe|Name=Hercules Updater|Desc=Hercules Updater|Defer=User| "{07B98692-2945-4E76-84CC-A4141956E223}"=v2.22|Action=Allow|Active=TRUE|Dir=In|Profile=Domain|Profile=Private|Name=@{BrowserChoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://BrowserChoice/resources/DisplayName}|Desc=@{BrowserChoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://BrowserChoice/resources/DisplayName}|LUOwn=S-1-5-21-548730727-4139670515-3000484307-1001|AppPkgId=S-1-15-2-2540836248-1980176511-1686232796-3610252712-3450814159-2925262043-1011558333|EmbedCtxt=@{BrowserChoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://BrowserChoice/resources/DisplayName}|Platform=2:6:2|Platform2=GTEQ| "{71B2AC7F-6F54-4ECA-BA50-4EB664F67A23}"=v2.22|Action=Allow|Active=TRUE|Dir=Out|Name=@{BrowserChoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://BrowserChoice/resources/DisplayName}|Desc=@{BrowserChoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://BrowserChoice/resources/DisplayName}|LUOwn=S-1-5-21-548730727-4139670515-3000484307-1001|AppPkgId=S-1-15-2-2540836248-1980176511-1686232796-3610252712-3450814159-2925262043-1011558333|EmbedCtxt=@{BrowserChoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://BrowserChoice/resources/DisplayName}|Platform=2:6:2|Platform2=GTEQ| "{4282FE99-8560-4BC7-9576-5F3ED84E263F}"=v2.22|Action=Allow|Active=TRUE|Dir=In|Name=CheckPoint.VPN|Desc=CheckPoint.VPN|LUOwn=S-1-1-0|AppPkgId=S-1-15-2-3676279713-3632409675-756843784-3388909659-2454753834-4233625902-1413163418|EmbedCtxt=CheckPoint.VPN|Platform=2:6:2|Platform2=GTEQ|Edge=TRUE| "{DB59588E-ED90-4C47-A7B5-7929DD0C0BD2}"=v2.22|Action=Allow|Active=TRUE|Dir=Out|Name=CheckPoint.VPN|Desc=CheckPoint.VPN|LUOwn=S-1-1-0|AppPkgId=S-1-15-2-3676279713-3632409675-756843784-3388909659-2454753834-4233625902-1413163418|EmbedCtxt=CheckPoint.VPN|Platform=2:6:2|Platform2=GTEQ| "{548DCF8C-BFF2-4BA4-AA88-FBAF9AC8BCC6}"=v2.22|Action=Allow|Active=TRUE|Dir=In|Profile=Domain|Profile=Private|Name=@{C:\Windows\WinStore\resources.pri?ms-resource://WinStore/resources/DisplayName}|Desc=@{C:\Windows\WinStore\resources.pri?ms-resource://WinStore/resources/Description}|LUOwn=S-1-1-0|AppPkgId=S-1-15-2-2608634532-1453884237-1118350049-1925931850-670756941-1603938316-3764965493|EmbedCtxt=@{C:\Windows\WinStore\resources.pri?ms-resource://WinStore/resources/DisplayName}|Platform=2:6:2|Platform2=GTEQ| "{9E3D57FC-7C37-4424-9352-4831E97D029D}"=v2.22|Action=Allow|Active=TRUE|Dir=Out|Name=@{C:\Windows\WinStore\resources.pri?ms-resource://WinStore/resources/DisplayName}|Desc=@{C:\Windows\WinStore\resources.pri?ms-resource://WinStore/resources/Description}|LUOwn=S-1-1-0|AppPkgId=S-1-15-2-2608634532-1453884237-1118350049-1925931850-670756941-1603938316-3764965493|EmbedCtxt=@{C:\Windows\WinStore\resources.pri?ms-resource://WinStore/resources/DisplayName}|Platform=2:6:2|Platform2=GTEQ| "{F77E5446-4378-4E99-8B7A-7061AAAEA193}"=v2.22|Action=Allow|Active=TRUE|Dir=In|Name=f5.vpn.client|Desc=f5.vpn.client|LUOwn=S-1-1-0|AppPkgId=S-1-15-2-3873129616-3864902477-3117653462-838095904-2337665935-1018217662-2152729480|EmbedCtxt=f5.vpn.client|Platform=2:6:2|Platform2=GTEQ|Edge=TRUE| "{F64300AD-D559-4000-BD45-0997BCC8E70A}"=v2.22|Action=Allow|Active=TRUE|Dir=Out|Name=f5.vpn.client|Desc=f5.vpn.client|LUOwn=S-1-1-0|AppPkgId=S-1-15-2-3873129616-3864902477-3117653462-838095904-2337665935-1018217662-2152729480|EmbedCtxt=f5.vpn.client|Platform=2:6:2|Platform2=GTEQ| "{EC799E33-72BA-42D7-9127-DEFE68F9799D}"=v2.22|Action=Allow|Active=TRUE|Dir=In|Name=JuniperNetworks.JunosPulseVpn|Desc=JuniperNetworks.JunosPulseVpn|LUOwn=S-1-1-0|AppPkgId=S-1-15-2-413786399-3497379642-531169432-1175633435-3083429259-2317590812-1892764672|EmbedCtxt=JuniperNetworks.JunosPulseVpn|Platform=2:6:2|Platform2=GTEQ|Edge=TRUE| "{D6980480-941A-4DF6-AB81-3734ECD3D779}"=v2.22|Action=Allow|Active=TRUE|Dir=Out|Name=JuniperNetworks.JunosPulseVpn|Desc=JuniperNetworks.JunosPulseVpn|LUOwn=S-1-1-0|AppPkgId=S-1-15-2-413786399-3497379642-531169432-1175633435-3083429259-2317590812-1892764672|EmbedCtxt=JuniperNetworks.JunosPulseVpn|Platform=2:6:2|Platform2=GTEQ| "{560448D6-095C-4907-B046-AC7F710701A7}"=v2.22|Action=Allow|Active=TRUE|Dir=In|Name=SonicWALL.MobileConnect|Desc=SonicWALL.MobileConnect|LUOwn=S-1-1-0|AppPkgId=S-1-15-2-1141404472-3582312691-3771565717-2155153689-4284170330-1053580937-782359393|EmbedCtxt=SonicWALL.MobileConnect|Platform=2:6:2|Platform2=GTEQ|Edge=TRUE| "{5F4632C0-D5B1-40C3-B0D9-E3A759C81B9E}"=v2.22|Action=Allow|Active=TRUE|Dir=Out|Name=SonicWALL.MobileConnect|Desc=SonicWALL.MobileConnect|LUOwn=S-1-1-0|AppPkgId=S-1-15-2-1141404472-3582312691-3771565717-2155153689-4284170330-1053580937-782359393|EmbedCtxt=SonicWALL.MobileConnect|Platform=2:6:2|Platform2=GTEQ| "{64312295-FF72-4557-AF85-76C1289D1BC6}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=17|LPort=53|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|App=%systemroot%\system32\svchost.exe|Svc=SharedAccess|Name=@ipnathlp.dll,-143|Desc=@ipnathlp.dll,-10142|EmbedCtxt=@ipnathlp.dll,-140| "{C3152DF4-B1D2-40CD-B55E-05BFD2F6AF1E}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=17|LPort=1900|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|App=%systemroot%\system32\svchost.exe|Svc=ssdpsrv|Name=@ipnathlp.dll,-147|Desc=@ipnathlp.dll,-10146|EmbedCtxt=@ipnathlp.dll,-140| "{AFEB2B28-9F64-4AAC-938F-40B90770DC34}"=v2.27|Action=Allow|Active=TRUE|Dir=Out|Protocol=17|RPort=1900|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|App=%systemroot%\system32\svchost.exe|Svc=ssdpsrv|Name=@ipnathlp.dll,-150|Desc=@ipnathlp.dll,-10150|EmbedCtxt=@ipnathlp.dll,-140| "{9E3BC57E-9C95-48DA-A806-ADD9FF727EEA}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=6|LPort=2869|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|App=System|Name=@ipnathlp.dll,-146|Desc=@ipnathlp.dll,-10145|EmbedCtxt=@ipnathlp.dll,-140| "{60B0F231-786A-4934-AEAF-A7B0AF934305}"=v2.27|Action=Allow|Active=TRUE|Dir=Out|Protocol=6|RPort=2869|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|App=System|Name=@ipnathlp.dll,-152|Desc=@ipnathlp.dll,-10151|EmbedCtxt=@ipnathlp.dll,-140| "{88C2A908-0CBD-4B20-9CE7-5E4BA4995904}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=17|LPort=547|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|App=%systemroot%\system32\svchost.exe|Svc=SharedAccess|Name=@ipnathlp.dll,-142|Desc=@ipnathlp.dll,-10141|EmbedCtxt=@ipnathlp.dll,-140| "{E6B16A5C-72BC-42DE-A928-3547D691CF9B}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=58|ICMP6=133:0|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|Name=@ipnathlp.dll,-148|Desc=@ipnathlp.dll,-10147|EmbedCtxt=@ipnathlp.dll,-140| "{4A9886F8-902D-4729-87BB-0AB874567CE4}"=v2.27|Action=Allow|Active=TRUE|Dir=Out|Protocol=6|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|App=%systemroot%\system32\svchost.exe|Svc=upnphost|Name=@ipnathlp.dll,-149|Desc=@ipnathlp.dll,-10148|EmbedCtxt=@ipnathlp.dll,-140| "{1F953F33-6A0D-4C66-82F4-0674F0163E09}"=v2.27|Action=Allow|Active=TRUE|Dir=In|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|App=%systemroot%\system32\alg.exe|Name=@ipnathlp.dll,-140|Desc=@ipnathlp.dll,-140|EmbedCtxt=@ipnathlp.dll,-140| "{291ECB0A-70C1-4A61-8EE6-D5A0BE7C0E3C}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=17|LPort=53|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|App=%systemroot%\system32\svchost.exe|Svc=SharedAccess|Name=@ipnathlp.dll,-143|Desc=@ipnathlp.dll,-10142|EmbedCtxt=@ipnathlp.dll,-140| "{0AF2AAB0-795F-496B-8487-DE5F2987755B}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=17|LPort=1900|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|App=%systemroot%\system32\svchost.exe|Svc=ssdpsrv|Name=@ipnathlp.dll,-147|Desc=@ipnathlp.dll,-10146|EmbedCtxt=@ipnathlp.dll,-140| "{A40D3E46-D0AD-46B4-9B08-A3FB9133104F}"=v2.27|Action=Allow|Active=TRUE|Dir=Out|Protocol=17|RPort=1900|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|App=%systemroot%\system32\svchost.exe|Svc=ssdpsrv|Name=@ipnathlp.dll,-150|Desc=@ipnathlp.dll,-10150|EmbedCtxt=@ipnathlp.dll,-140| "{218D969F-F49B-433F-98B2-87852A38E551}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=6|LPort=2869|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|App=System|Name=@ipnathlp.dll,-146|Desc=@ipnathlp.dll,-10145|EmbedCtxt=@ipnathlp.dll,-140| "{626AB78A-330F-47A3-94EA-FC469686EDF0}"=v2.27|Action=Allow|Active=TRUE|Dir=Out|Protocol=6|RPort=2869|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|App=System|Name=@ipnathlp.dll,-152|Desc=@ipnathlp.dll,-10151|EmbedCtxt=@ipnathlp.dll,-140| "{32256DF1-B50D-42E6-BAFE-2A83277400DF}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=17|LPort=547|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|App=%systemroot%\system32\svchost.exe|Svc=SharedAccess|Name=@ipnathlp.dll,-142|Desc=@ipnathlp.dll,-10141|EmbedCtxt=@ipnathlp.dll,-140| "{71561636-A98C-4545-8E42-D62B9AC11440}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=58|ICMP6=133:0|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|Name=@ipnathlp.dll,-148|Desc=@ipnathlp.dll,-10147|EmbedCtxt=@ipnathlp.dll,-140| "{83E0F968-879F-44C1-874D-49CFAF711FE9}"=v2.27|Action=Allow|Active=TRUE|Dir=Out|Protocol=6|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|App=%systemroot%\system32\svchost.exe|Svc=upnphost|Name=@ipnathlp.dll,-149|Desc=@ipnathlp.dll,-10148|EmbedCtxt=@ipnathlp.dll,-140| "{C69BB01F-1E1A-42AB-B3D1-2AF0866B5646}"=v2.27|Action=Allow|Active=TRUE|Dir=In|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|App=%systemroot%\system32\alg.exe|Name=@ipnathlp.dll,-140|Desc=@ipnathlp.dll,-140|EmbedCtxt=@ipnathlp.dll,-140| "{98BAE3C0-DB1B-4D7F-9BFC-CCF2903C1B7E}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=17|LPort=53|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|App=%systemroot%\system32\svchost.exe|Svc=SharedAccess|Name=@ipnathlp.dll,-143|Desc=@ipnathlp.dll,-10142|EmbedCtxt=@ipnathlp.dll,-140| "{F7108CB2-4715-4F87-8E0F-D4F737544B7E}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=17|LPort=1900|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|App=%systemroot%\system32\svchost.exe|Svc=ssdpsrv|Name=@ipnathlp.dll,-147|Desc=@ipnathlp.dll,-10146|EmbedCtxt=@ipnathlp.dll,-140| "{C7D92E62-F83E-4CF1-8BCE-30882D5B9AF1}"=v2.27|Action=Allow|Active=TRUE|Dir=Out|Protocol=17|RPort=1900|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|App=%systemroot%\system32\svchost.exe|Svc=ssdpsrv|Name=@ipnathlp.dll,-150|Desc=@ipnathlp.dll,-10150|EmbedCtxt=@ipnathlp.dll,-140| "{DB3C928E-6CA0-424A-B24B-CA0FEEBA0EAB}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=6|LPort=2869|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|App=System|Name=@ipnathlp.dll,-146|Desc=@ipnathlp.dll,-10145|EmbedCtxt=@ipnathlp.dll,-140| "{072441F9-37DD-45DC-85F2-19FBE7523044}"=v2.27|Action=Allow|Active=TRUE|Dir=Out|Protocol=6|RPort=2869|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|App=System|Name=@ipnathlp.dll,-152|Desc=@ipnathlp.dll,-10151|EmbedCtxt=@ipnathlp.dll,-140| "{825D85A7-291B-4AC1-91EC-664B844D990A}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=17|LPort=547|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|App=%systemroot%\system32\svchost.exe|Svc=SharedAccess|Name=@ipnathlp.dll,-142|Desc=@ipnathlp.dll,-10141|EmbedCtxt=@ipnathlp.dll,-140| "{8A9128CC-55C8-4EE4-A893-73DD41A140B7}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=58|ICMP6=133:0|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|Name=@ipnathlp.dll,-148|Desc=@ipnathlp.dll,-10147|EmbedCtxt=@ipnathlp.dll,-140| "{FA60C5F2-BA04-4D59-A402-5F6402649337}"=v2.27|Action=Allow|Active=TRUE|Dir=Out|Protocol=6|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|App=%systemroot%\system32\svchost.exe|Svc=upnphost|Name=@ipnathlp.dll,-149|Desc=@ipnathlp.dll,-10148|EmbedCtxt=@ipnathlp.dll,-140| "{B96701F2-2FF2-4670-B7BB-E46BBABCD775}"=v2.27|Action=Allow|Active=TRUE|Dir=In|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|App=%systemroot%\system32\alg.exe|Name=@ipnathlp.dll,-140|Desc=@ipnathlp.dll,-140|EmbedCtxt=@ipnathlp.dll,-140| "{37A62C2C-8342-4CF5-9265-D82739ECFBCD}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=17|LPort=53|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|App=%systemroot%\system32\svchost.exe|Svc=SharedAccess|Name=@ipnathlp.dll,-143|Desc=@ipnathlp.dll,-10142|EmbedCtxt=@ipnathlp.dll,-140| "{2430E28E-33CB-410F-AFBB-78C4C1C08A3B}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=17|LPort=1900|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|App=%systemroot%\system32\svchost.exe|Svc=ssdpsrv|Name=@ipnathlp.dll,-147|Desc=@ipnathlp.dll,-10146|EmbedCtxt=@ipnathlp.dll,-140| "{E2DD403A-BE1A-4616-8D61-EDBE18A4F51A}"=v2.27|Action=Allow|Active=TRUE|Dir=Out|Protocol=17|RPort=1900|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|App=%systemroot%\system32\svchost.exe|Svc=ssdpsrv|Name=@ipnathlp.dll,-150|Desc=@ipnathlp.dll,-10150|EmbedCtxt=@ipnathlp.dll,-140| "{A9854ACA-F515-4962-9C2E-C2A5D468D992}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=6|LPort=2869|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|App=System|Name=@ipnathlp.dll,-146|Desc=@ipnathlp.dll,-10145|EmbedCtxt=@ipnathlp.dll,-140| "{CCB78C72-B958-48B0-87E0-B8E01F61739D}"=v2.27|Action=Allow|Active=TRUE|Dir=Out|Protocol=6|RPort=2869|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|App=System|Name=@ipnathlp.dll,-152|Desc=@ipnathlp.dll,-10151|EmbedCtxt=@ipnathlp.dll,-140| "{A9901871-6BDD-4EC8-A33A-AD8234DF46A9}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=17|LPort=547|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|App=%systemroot%\system32\svchost.exe|Svc=SharedAccess|Name=@ipnathlp.dll,-142|Desc=@ipnathlp.dll,-10141|EmbedCtxt=@ipnathlp.dll,-140| "{1354E405-6312-4A68-915C-5B70B79FD966}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=58|ICMP6=133:0|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|Name=@ipnathlp.dll,-148|Desc=@ipnathlp.dll,-10147|EmbedCtxt=@ipnathlp.dll,-140| "{C4FAE1D1-F9A5-43A7-A92F-8977754FABC3}"=v2.27|Action=Allow|Active=TRUE|Dir=Out|Protocol=6|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|App=%systemroot%\system32\svchost.exe|Svc=upnphost|Name=@ipnathlp.dll,-149|Desc=@ipnathlp.dll,-10148|EmbedCtxt=@ipnathlp.dll,-140| "{AE37DFF7-3D4A-4264-BCD0-A963E3AF71C8}"=v2.27|Action=Allow|Active=TRUE|Dir=In|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|App=%systemroot%\system32\alg.exe|Name=@ipnathlp.dll,-140|Desc=@ipnathlp.dll,-140|EmbedCtxt=@ipnathlp.dll,-140| "{149E9915-30EF-4D56-89CD-6DB5815ACB1F}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=17|LPort=53|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|App=%systemroot%\system32\svchost.exe|Svc=SharedAccess|Name=@ipnathlp.dll,-143|Desc=@ipnathlp.dll,-10142|EmbedCtxt=@ipnathlp.dll,-140| "{92BE4246-B038-4BC9-8C49-3ED54B34A60F}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=17|LPort=1900|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|App=%systemroot%\system32\svchost.exe|Svc=ssdpsrv|Name=@ipnathlp.dll,-147|Desc=@ipnathlp.dll,-10146|EmbedCtxt=@ipnathlp.dll,-140| "{FAE8BCAC-AC31-49B6-819D-66FA5A263539}"=v2.27|Action=Allow|Active=TRUE|Dir=Out|Protocol=17|RPort=1900|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|App=%systemroot%\system32\svchost.exe|Svc=ssdpsrv|Name=@ipnathlp.dll,-150|Desc=@ipnathlp.dll,-10150|EmbedCtxt=@ipnathlp.dll,-140| "{BC9BADA4-293E-4F0C-8A4E-FCAD59FA111C}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=6|LPort=2869|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|App=System|Name=@ipnathlp.dll,-146|Desc=@ipnathlp.dll,-10145|EmbedCtxt=@ipnathlp.dll,-140| "{E29DFF28-4194-4BB3-BF7F-9162D93FAF1D}"=v2.27|Action=Allow|Active=TRUE|Dir=Out|Protocol=6|RPort=2869|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|App=System|Name=@ipnathlp.dll,-152|Desc=@ipnathlp.dll,-10151|EmbedCtxt=@ipnathlp.dll,-140| "{EFEEDB76-0D95-47C4-BF18-55957B554DE5}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=17|LPort=547|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|App=%systemroot%\system32\svchost.exe|Svc=SharedAccess|Name=@ipnathlp.dll,-142|Desc=@ipnathlp.dll,-10141|EmbedCtxt=@ipnathlp.dll,-140| "{849C12C5-4319-4E82-B070-5B81C1842187}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=58|ICMP6=133:0|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|Name=@ipnathlp.dll,-148|Desc=@ipnathlp.dll,-10147|EmbedCtxt=@ipnathlp.dll,-140| "{AE4E7CFC-FB04-48F9-A694-B0410FC45D8D}"=v2.27|Action=Allow|Active=TRUE|Dir=Out|Protocol=6|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|App=%systemroot%\system32\svchost.exe|Svc=upnphost|Name=@ipnathlp.dll,-149|Desc=@ipnathlp.dll,-10148|EmbedCtxt=@ipnathlp.dll,-140| "{22E7429B-2BFD-421C-B48E-3AB8FC709DE2}"=v2.27|Action=Allow|Active=TRUE|Dir=In|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|App=%systemroot%\system32\alg.exe|Name=@ipnathlp.dll,-140|Desc=@ipnathlp.dll,-140|EmbedCtxt=@ipnathlp.dll,-140| "{59A0FD1B-5B0C-48E0-A4DC-62D5B51B5C2C}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=17|LPort=53|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|App=%systemroot%\system32\svchost.exe|Svc=SharedAccess|Name=@ipnathlp.dll,-143|Desc=@ipnathlp.dll,-10142|EmbedCtxt=@ipnathlp.dll,-140| "{92E3B5F5-5492-4161-B5E5-834DC6F9F2D3}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=17|LPort=1900|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|App=%systemroot%\system32\svchost.exe|Svc=ssdpsrv|Name=@ipnathlp.dll,-147|Desc=@ipnathlp.dll,-10146|EmbedCtxt=@ipnathlp.dll,-140| "{D98C6FAA-1CFE-4FE8-926C-C44A42A0CE19}"=v2.27|Action=Allow|Active=TRUE|Dir=Out|Protocol=17|RPort=1900|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|App=%systemroot%\system32\svchost.exe|Svc=ssdpsrv|Name=@ipnathlp.dll,-150|Desc=@ipnathlp.dll,-10150|EmbedCtxt=@ipnathlp.dll,-140| "{83286A82-8600-47C8-A7F0-5CF3366FE3A7}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=6|LPort=2869|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|App=System|Name=@ipnathlp.dll,-146|Desc=@ipnathlp.dll,-10145|EmbedCtxt=@ipnathlp.dll,-140| "{782FC999-5710-4C2D-8CA6-62C58715381D}"=v2.27|Action=Allow|Active=TRUE|Dir=Out|Protocol=6|RPort=2869|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|App=System|Name=@ipnathlp.dll,-152|Desc=@ipnathlp.dll,-10151|EmbedCtxt=@ipnathlp.dll,-140| "{966E07EA-7080-43D4-96D9-78349BB24EE1}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=17|LPort=547|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|App=%systemroot%\system32\svchost.exe|Svc=SharedAccess|Name=@ipnathlp.dll,-142|Desc=@ipnathlp.dll,-10141|EmbedCtxt=@ipnathlp.dll,-140| "{CB38F6B7-5B84-4521-8668-F519A7A0BBCD}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=58|ICMP6=133:0|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|Name=@ipnathlp.dll,-148|Desc=@ipnathlp.dll,-10147|EmbedCtxt=@ipnathlp.dll,-140| "{888B48C7-81CC-4CE7-B004-7E07FB3974C7}"=v2.27|Action=Allow|Active=TRUE|Dir=Out|Protocol=6|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|App=%systemroot%\system32\svchost.exe|Svc=upnphost|Name=@ipnathlp.dll,-149|Desc=@ipnathlp.dll,-10148|EmbedCtxt=@ipnathlp.dll,-140| "{3DE4A8FD-33D5-4E20-A8E5-C1111B4E9E20}"=v2.27|Action=Allow|Active=TRUE|Dir=In|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|App=%systemroot%\system32\alg.exe|Name=@ipnathlp.dll,-140|Desc=@ipnathlp.dll,-140|EmbedCtxt=@ipnathlp.dll,-140| "{F916EAE4-C96F-410A-80D8-8E87FA5E19D2}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=17|LPort=53|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|App=%systemroot%\system32\svchost.exe|Svc=SharedAccess|Name=@ipnathlp.dll,-143|Desc=@ipnathlp.dll,-10142|EmbedCtxt=@ipnathlp.dll,-140| "{F6633C7C-7236-402B-AD3D-78CA69AEF7B2}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=17|LPort=1900|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|App=%systemroot%\system32\svchost.exe|Svc=ssdpsrv|Name=@ipnathlp.dll,-147|Desc=@ipnathlp.dll,-10146|EmbedCtxt=@ipnathlp.dll,-140| "{81A07505-AFB1-4DE2-9F8D-5F4DF47794C3}"=v2.27|Action=Allow|Active=TRUE|Dir=Out|Protocol=17|RPort=1900|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|App=%systemroot%\system32\svchost.exe|Svc=ssdpsrv|Name=@ipnathlp.dll,-150|Desc=@ipnathlp.dll,-10150|EmbedCtxt=@ipnathlp.dll,-140| "{865CE9E3-BB18-4DD9-8625-17D1D277781C}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=6|LPort=2869|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|App=System|Name=@ipnathlp.dll,-146|Desc=@ipnathlp.dll,-10145|EmbedCtxt=@ipnathlp.dll,-140| "{01628E78-B3D4-43CB-8288-85590B60B7BF}"=v2.27|Action=Allow|Active=TRUE|Dir=Out|Protocol=6|RPort=2869|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|App=System|Name=@ipnathlp.dll,-152|Desc=@ipnathlp.dll,-10151|EmbedCtxt=@ipnathlp.dll,-140| "{7C2BB14B-3D53-438B-B34B-0E9393BB1C71}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=17|LPort=547|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|App=%systemroot%\system32\svchost.exe|Svc=SharedAccess|Name=@ipnathlp.dll,-142|Desc=@ipnathlp.dll,-10141|EmbedCtxt=@ipnathlp.dll,-140| "{1F53CF2B-05EF-467C-A314-13960155C2A6}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=58|ICMP6=133:0|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|Name=@ipnathlp.dll,-148|Desc=@ipnathlp.dll,-10147|EmbedCtxt=@ipnathlp.dll,-140| "{F5458F7B-7C52-42ED-B812-0DCCB86DBD31}"=v2.27|Action=Allow|Active=TRUE|Dir=Out|Protocol=6|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|App=%systemroot%\system32\svchost.exe|Svc=upnphost|Name=@ipnathlp.dll,-149|Desc=@ipnathlp.dll,-10148|EmbedCtxt=@ipnathlp.dll,-140| "{DAC4C389-0104-45BF-85FD-025B64A5A943}"=v2.27|Action=Allow|Active=TRUE|Dir=In|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|App=%systemroot%\system32\alg.exe|Name=@ipnathlp.dll,-140|Desc=@ipnathlp.dll,-140|EmbedCtxt=@ipnathlp.dll,-140| "{FF7EEA78-4500-406C-877C-32A1FB47CC12}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=17|LPort=53|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|App=%systemroot%\system32\svchost.exe|Svc=SharedAccess|Name=@ipnathlp.dll,-143|Desc=@ipnathlp.dll,-10142|EmbedCtxt=@ipnathlp.dll,-140| "{CBBBA58E-8225-4864-A76E-32784E042513}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=17|LPort=1900|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|App=%systemroot%\system32\svchost.exe|Svc=ssdpsrv|Name=@ipnathlp.dll,-147|Desc=@ipnathlp.dll,-10146|EmbedCtxt=@ipnathlp.dll,-140| "{70A79291-02BA-457D-B6CC-A5601AD3AA6F}"=v2.27|Action=Allow|Active=TRUE|Dir=Out|Protocol=17|RPort=1900|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|App=%systemroot%\system32\svchost.exe|Svc=ssdpsrv|Name=@ipnathlp.dll,-150|Desc=@ipnathlp.dll,-10150|EmbedCtxt=@ipnathlp.dll,-140| "{BCAF3F5D-0A5D-41B3-A1D6-13261996A1D8}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=6|LPort=2869|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|App=System|Name=@ipnathlp.dll,-146|Desc=@ipnathlp.dll,-10145|EmbedCtxt=@ipnathlp.dll,-140| "{E4F5B7CB-4927-453E-8D7B-9901254EFA4E}"=v2.27|Action=Allow|Active=TRUE|Dir=Out|Protocol=6|RPort=2869|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|App=System|Name=@ipnathlp.dll,-152|Desc=@ipnathlp.dll,-10151|EmbedCtxt=@ipnathlp.dll,-140| "{E2F65C4E-E744-41F1-87BC-1E00933E8AF6}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=17|LPort=547|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|App=%systemroot%\system32\svchost.exe|Svc=SharedAccess|Name=@ipnathlp.dll,-142|Desc=@ipnathlp.dll,-10141|EmbedCtxt=@ipnathlp.dll,-140| "{04F8FDC3-1DB8-48E2-9BA1-FFE21DE543EE}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=58|ICMP6=133:0|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|Name=@ipnathlp.dll,-148|Desc=@ipnathlp.dll,-10147|EmbedCtxt=@ipnathlp.dll,-140| "{6B202B0F-C192-43FB-93E4-3A2A11DAA33C}"=v2.27|Action=Allow|Active=TRUE|Dir=Out|Protocol=6|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|App=%systemroot%\system32\svchost.exe|Svc=upnphost|Name=@ipnathlp.dll,-149|Desc=@ipnathlp.dll,-10148|EmbedCtxt=@ipnathlp.dll,-140| "{B8D1F74A-8020-4469-B3C6-3B9001D6334D}"=v2.27|Action=Allow|Active=TRUE|Dir=In|IF={F2536711-BE8D-4649-8955-0357C04E7F61}|App=%systemroot%\system32\alg.exe|Name=@ipnathlp.dll,-140|Desc=@ipnathlp.dll,-140|EmbedCtxt=@ipnathlp.dll,-140| "{BB7521E8-0B91-48A6-9F39-6530354F2905}"=v2.28|Action=Allow|Active=TRUE|Dir=Out|Name=Twitter|Desc=Twitter|LUOwn=S-1-5-21-548730727-4139670515-3000484307-1001|AppPkgId=S-1-15-2-1063257880-1914585122-1954150059-946145533-116938067-416079064-1690466945|EmbedCtxt=Twitter|Platform=2:6:2|Platform2=GTEQ| "{36116FAC-1E17-4015-9346-8C66521AD315}"=v2.30|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=windows_ie_ac_001|Desc=Created by IE|LUOwn=S-1-5-18|AppPkgId=S-1-15-2-1430448594-2639229838-973813799-439329657-1197984847-4069167804-1277922394|EmbedCtxt=windows_ie_ac_001|Platform=2:6:2|Platform2=GTEQ| "{128E66F5-2931-4246-AC0B-03724AADBE56}"=v2.30|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=Microsoft Pay|Desc=Microsoft Pay|LUOwn=S-1-5-21-548730727-4139670515-3000484307-1001|AppPkgId=S-1-15-2-567501097-281763132-502764112-1855211022-3143306454-2372101908-561929011|EmbedCtxt=Microsoft Pay|Platform=2:6:2|Platform2=GTEQ| "{CBA04D3D-4535-43E0-8E69-FC584BF9F20D}"=v2.30|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=3D Builder|Desc=3D Builder|LUOwn=S-1-5-21-548730727-4139670515-3000484307-1001|AppPkgId=S-1-15-2-3995430443-3719053022-3339397951-2895237338-2437516106-1575886070-2755610054|EmbedCtxt=3D Builder|Platform=2:6:2|Platform2=GTEQ| "{0CB234E4-C0B8-424E-B509-FBA5CA4EFE61}"=v2.30|Action=Allow|Active=TRUE|Dir=In|Profile=Domain|Profile=Private|Name=3D Builder|Desc=3D Builder|LUOwn=S-1-5-21-548730727-4139670515-3000484307-1001|AppPkgId=S-1-15-2-3995430443-3719053022-3339397951-2895237338-2437516106-1575886070-2755610054|EmbedCtxt=3D Builder|Platform=2:6:2|Platform2=GTEQ| "{53B0A1C1-E559-47C3-A59C-41A075F96AFB}"=v2.30|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=Sway|Desc=Sway|LUOwn=S-1-5-21-548730727-4139670515-3000484307-1001|AppPkgId=S-1-15-2-584073948-3292409011-2882754242-2237763630-1999038865-1049037702-4080706152|EmbedCtxt=Sway|Platform=2:6:2|Platform2=GTEQ| "{EB9C3805-54C2-4B37-A49F-F567410919FF}"=v2.30|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=Shell Input Application|Desc=Shell Input Application|LUOwn=S-1-5-21-548730727-4139670515-3000484307-1001|AppPkgId=S-1-15-2-3945102849-3632965805-3846928828-240845225-3300287824-62672950-817265009|EmbedCtxt=Shell Input Application|Platform=2:6:2|Platform2=GTEQ| "{989C1CB6-6490-443B-9D1B-BA156B147630}"=v2.30|Action=Allow|Active=TRUE|Dir=In|Protocol=17|LPort=5353|App=C:\Program Files (x86)\Google\Chrome\Application\chrome.exe|Name=Google Chrome (mDNS-In)|Desc=Règle de trafic entrant pour Google Chrome autorisant le trafic mDNS|EmbedCtxt=Google Chrome| "{CDE4520D-784B-4FA1-AC77-C12D60A7653D}"=v2.30|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Program Files\FlashIntegro\VideoEditor\VideoEditor.exe|Name=VSDC Free Video Editor| "{275A3718-BAF3-4593-9E0E-E462074FE367}"=v2.30|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Program Files\FlashIntegro\VideoEditor\VideoEditor.exe|Name=VSDC Free Video Editor| "{A7F2C447-818D-4284-B3E9-8D77236FBC8F}"=v2.30|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Program Files\FlashIntegro\VideoEditor\Activation.exe|Name=VSDC Free Video Editor Activater| "{5F4A7EB2-2330-4941-B935-87EE0EB164C2}"=v2.30|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Program Files\FlashIntegro\VideoEditor\Activation.exe|Name=VSDC Free Video Editor Activater| "{2C7C6511-50B1-4D80-93DF-FEB459EC3BA1}"=v2.30|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Program Files\FlashIntegro\VideoEditor\Updater.exe|Name=VSDC Free Video Editor Updater| "{B5B13DA0-06F9-4429-8D1E-09F86AC45032}"=v2.30|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Program Files\FlashIntegro\VideoEditor\Updater.exe|Name=VSDC Free Video Editor Updater| "{94DC2370-20B6-4852-8DDD-D88454A153D3}"=v2.30|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=Microsoft Solitaire Collection|Desc=Microsoft Solitaire Collection|LUOwn=S-1-5-21-548730727-4139670515-3000484307-1001|AppPkgId=S-1-15-2-1985198343-3186790915-4047221937-1969271670-3792558349-1325541827-400269725|EmbedCtxt=Microsoft Solitaire Collection|Platform=2:6:2|Platform2=GTEQ| "{4E85CE85-B20E-4210-A44F-ADE64C51BDB1}"=v2.30|Action=Allow|Active=TRUE|Dir=In|Profile=Domain|Profile=Private|Name=Microsoft Solitaire Collection|Desc=Microsoft Solitaire Collection|LUOwn=S-1-5-21-548730727-4139670515-3000484307-1001|AppPkgId=S-1-15-2-1985198343-3186790915-4047221937-1969271670-3792558349-1325541827-400269725|EmbedCtxt=Microsoft Solitaire Collection|Platform=2:6:2|Platform2=GTEQ| "{F8015FB5-F99C-4CE0-8F4C-B1FE2C29DF9C}"=v2.30|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=Xbox Game Bar Plugin|Desc=Xbox Game Bar Plugin|LUOwn=S-1-5-21-548730727-4139670515-3000484307-1001|AppPkgId=S-1-15-2-1823635404-1364722122-2170562666-1762391777-2399050872-3465541734-3732476201|EmbedCtxt=Xbox Game Bar Plugin|Platform=2:6:2|Platform2=GTEQ| "{765C7DAA-10CD-4B60-A75E-841B79F1FE75}"=v2.30|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=Xbox Game Bar|Desc=Xbox Game Bar|LUOwn=S-1-5-21-548730727-4139670515-3000484307-1001|AppPkgId=S-1-15-2-1714399563-1326177402-2048222277-143663168-2151391019-765408921-4098702777|EmbedCtxt=Xbox Game Bar|Platform=2:6:2|Platform2=GTEQ| "{4690BAEE-6CCD-4CF9-A242-1DC4145421A2}"=v2.30|Action=Allow|Active=TRUE|Dir=In|Profile=Domain|Profile=Private|Profile=Public|Name=Xbox Game Bar|Desc=Xbox Game Bar|LUOwn=S-1-5-21-548730727-4139670515-3000484307-1001|AppPkgId=S-1-15-2-1714399563-1326177402-2048222277-143663168-2151391019-765408921-4098702777|EmbedCtxt=Xbox Game Bar|Platform=2:6:2|Platform2=GTEQ|Edge=TRUE| "{3E1BFB21-37AF-4C82-A45D-11E46C78EC13}"=v2.30|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=OneNote|Desc=OneNote|LUOwn=S-1-5-21-548730727-4139670515-3000484307-1001|AppPkgId=S-1-15-2-3445883232-1224167743-206467785-1580939083-2750001491-3097792036-3019341970|EmbedCtxt=OneNote|Platform=2:6:2|Platform2=GTEQ| "{281D5F4E-46AE-4A0F-A1E3-C43C190094EF}"=v2.30|Action=Allow|Active=TRUE|Dir=In|Profile=Domain|Profile=Private|Name=OneNote|Desc=OneNote|LUOwn=S-1-5-21-548730727-4139670515-3000484307-1001|AppPkgId=S-1-15-2-3445883232-1224167743-206467785-1580939083-2750001491-3097792036-3019341970|EmbedCtxt=OneNote|Platform=2:6:2|Platform2=GTEQ| [HKLM\SYSTEM\CurrentControlSet\Services\sharedaccess\Parameters\FirewallPolicy\standardprofile\authorizedapplications\list] "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe"=C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe:*:Enabled:Spybot - Search & Destroy tray access "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe"=C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe:*:Enabled:Spybot-S&D 2 Scanner Service "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe"=C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe:*:Enabled:Spybot-S&D 2 Updater "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe"=C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe:*:Enabled:Spybot-S&D 2 Background update service ---------- | Control\Class [HKLM\SYSTEM\CurrentControlSet\Control\Class\{05f5cfe2-4733-4950-a6bb-07aad01a3a84}] : (XboxComposite) [] -> @dc1-controller.inf,%ClassName%;Xbox Peripherals [HKLM\SYSTEM\CurrentControlSet\Control\Class\{1264760F-A5C8-4BFE-B314-D56A7B44A362}] : (DXGKrnl) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{13e42dfa-85d9-424d-8646-28a70f864f9c}] : (RemotePosDevice) [] -> @remoteposdrv.inf,%ClassName%;POS Remote Device [HKLM\SYSTEM\CurrentControlSet\Control\Class\{14b62f50-3f15-11dd-ae16-0800200c9a66}] : (DigitalMediaDevices) [] -> @digitalmediadevice.inf,%ClassName%;Digital Media Devices [HKLM\SYSTEM\CurrentControlSet\Control\Class\{1ed2bbf9-11f0-4084-b21f-ad83a8e6dcdc}] : (PrintQueue) [] -> @printqueue.inf,%ClassName%;Print queues [HKLM\SYSTEM\CurrentControlSet\Control\Class\{25dbce51-6c8f-4a72-8a6d-b54c2b4fc835}] : (WCEUSBS) [] -> @%SystemRoot%\System32\SysClass.Dll,-3026 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{268c95a1-edfe-11d3-95c3-0010dc4050a5}] : (SecurityAccelerator) [] -> @c_sslaccel.inf,%ClassName%;Security accelerators [HKLM\SYSTEM\CurrentControlSet\Control\Class\{2a9fe532-0cdc-44f9-9827-76192f2ca2fb}] : (HidMsr) [] -> @c_magneticstripereader.inf,%ClassName%;POS HID Magnetic Stripe Reader [HKLM\SYSTEM\CurrentControlSet\Control\Class\{2db15374-706e-4131-a0c7-d7c78eb0289a}] : (SystemRecovery) [] -> @c_fssystemrecovery.inf,%ClassDesc%;FS System recovery filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{3163C566-D381-4467-87BC-A65A18D5B648}] : (fvevol) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{3163C566-D381-4467-87BC-A65A18D5B649}] : (fvevol) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{36fc9e60-c465-11cf-8056-444553540000}] : (USB) [] -> @%SystemRoot%\System32\SysClass.Dll,-3025 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{3e3f0674-c83c-4558-bb26-9820e1eba5c5}] : (ContentScreener) [] -> @c_fscontentscreener.inf,%ClassDesc%;FS Content screener filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{3f966bd9-fa04-4ec5-991c-d326973b5128}] : (AndroidUsbDeviceClass) [] -> @oem51.inf,%ClassName%;Android Phone [HKLM\SYSTEM\CurrentControlSet\Control\Class\{43675d81-502a-4a82-9f84-b75f418c5dea}] : (Media Center Extender) [] -> @c_mcx.inf,%ClassDesc%;Media Center Extenders [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4658ee7e-f050-11d1-b6bd-00c04fa372a7}] : (PnpPrinters) [] -> @%SystemRoot%\system32\ntprint.dll,-1300 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{48721b56-6795-11d2-b1a8-0080c72e74a2}] : (Dot4) [] -> @%SystemRoot%\system32\sysclass.dll,-3023 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{48d3ebc4-4cf8-48ff-b869-9c68ad42eb9f}] : (Replication) [] -> @c_fsreplication.inf,%ClassDesc%;FS Replication filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{49ce6ac8-6f86-11d2-b1e5-0080c72e74a2}] : (Dot4Print) [] -> @%SystemRoot%\system32\sysclass.dll,-3024 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e965-e325-11ce-bfc1-08002be10318}] : (CDROM) [] -> @%SystemRoot%\System32\StorProp.dll,-17001 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e966-e325-11ce-bfc1-08002be10318}] : (Computer) [] -> @%SystemRoot%\System32\SysClass.dll,-3000 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e967-e325-11ce-bfc1-08002be10318}] : (DiskDrive) [] -> @c_diskdrive.inf,%ClassDesc%;Disk drives [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e968-e325-11ce-bfc1-08002be10318}] : (Display) [] -> @c_display.inf,%ClassDesc%;Display adapters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e969-e325-11ce-bfc1-08002be10318}] : (FDC) [] -> @%SystemRoot%\System32\SysClass.Dll,-3013 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e96a-e325-11ce-bfc1-08002be10318}] : (HDC) [] -> @%SystemRoot%\System32\SysClass.Dll,-3001 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e96b-e325-11ce-bfc1-08002be10318}] : (Keyboard) [] -> @%SystemRoot%\System32\SysClass.Dll,-3002 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e96c-e325-11ce-bfc1-08002be10318}] : (MEDIA) [] -> @c_media.inf,%ClassDesc%;Sound, video and game controllers [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}] : (Modem) [] -> @%SystemRoot%\System32\mdminst.dll,-14100 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e96e-e325-11ce-bfc1-08002be10318}] : (Monitor) [] -> @c_monitor.inf,%ClassDesc%;Monitors [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e96f-e325-11ce-bfc1-08002be10318}] : (Mouse) [] -> @%SystemRoot%\System32\SysClass.Dll,-3004 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e970-e325-11ce-bfc1-08002be10318}] : (MTD) [] -> @%SystemRoot%\System32\SysClass.Dll,-3021 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e971-e325-11ce-bfc1-08002be10318}] : (MultiFunction) [] -> @%SystemRoot%\System32\SysClass.Dll,-3014 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e972-e325-11ce-bfc1-08002be10318}] : (Net) [] -> @%SystemRoot%\System32\NetCfgx.dll,-1502 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e973-e325-11ce-bfc1-08002be10318}] : (NetClient) [] -> @%SystemRoot%\System32\NetCfgx.dll,-1504 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e974-e325-11ce-bfc1-08002be10318}] : (NetService) [] -> @%SystemRoot%\System32\NetCfgx.dll,-1505 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e975-e325-11ce-bfc1-08002be10318}] : (NetTrans) [] -> @%SystemRoot%\System32\NetCfgx.dll,-1503 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e977-e325-11ce-bfc1-08002be10318}] : (PCMCIA) [] -> @%SystemRoot%\System32\SysClass.Dll,-3010 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e978-e325-11ce-bfc1-08002be10318}] : (Ports) [] -> @%SystemRoot%\System32\msports.dll,-10000 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e979-e325-11ce-bfc1-08002be10318}] : (Printer) [] -> @%SystemRoot%\system32\ntprint.dll,-1004 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e97b-e325-11ce-bfc1-08002be10318}] : (SCSIAdapter) [] -> @%SystemRoot%\System32\SysClass.Dll,-3005 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e97d-e325-11ce-bfc1-08002be10318}] : (System) [] -> @%SystemRoot%\System32\SysClass.Dll,-3008 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e97e-e325-11ce-bfc1-08002be10318}] : (Unknown) [] -> @%SystemRoot%\System32\SysClass.Dll,-3009 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e980-e325-11ce-bfc1-08002be10318}] : (FloppyDisk) [] -> @%SystemRoot%\System32\SysClass.Dll,-3015 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4fc9541c-0fe6-4480-a4f6-9495a0d17cd2}] : (HidLineDisplay) [] -> @c_linedisplay.inf,%ClassName%;POS Line Display [HKLM\SYSTEM\CurrentControlSet\Control\Class\{50127dc3-0f36-415e-a6cc-4cb3be910b65}] : (Processor) [] -> @c_processor.inf,%ClassDesc%;Processors [HKLM\SYSTEM\CurrentControlSet\Control\Class\{50906cb8-ba12-11d1-bf5d-0000f805f530}] : (MultiPortSerial) [] -> @%SystemRoot%\system32\sysclass.dll,-3022 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{5099944a-f6b9-4057-a056-8c550228544c}] : (Memory) [] -> @%SystemRoot%\System32\SysClass.Dll,-3018 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{50dd5230-ba8a-11d1-bf5d-0000f805f530}] : (SmartCardReader) [] -> @%SystemRoot%\System32\StorProp.dll,-17002 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{5175d334-c371-4806-b3ba-71fd53c9258d}] : (Sensor) [] -> @%SystemRoot%\system32\SensorsCpl.dll,-10000 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{533c5b84-ec70-11d2-9505-00c04f79deaf}] : (VolumeSnapshot) [] -> @%SystemRoot%\System32\SysClass.Dll,-3011 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{53487c23-680f-4585-acc3-1f10d6777e82}] : (SmrDisk) [] -> @c_smrdisk.inf,%ClassDesc%;Shingled magnetic recording disks [HKLM\SYSTEM\CurrentControlSet\Control\Class\{53966cb1-4d46-4166-bf23-c522403cd495}] : (ScmDisk) [] -> @c_scmdisk.inf,%ClassDesc%;Persistent memory disks [HKLM\SYSTEM\CurrentControlSet\Control\Class\{53b3cf03-8f5a-4788-91b6-d19ed9fcccbf}] : (SmrVolume) [] -> @c_smrvolume.inf,%ClassDesc%;Shingled magnetic recording volumes [HKLM\SYSTEM\CurrentControlSet\Control\Class\{53ccb149-e543-4c84-b6e0-bce4f6b7e806}] : (ScmVolume) [] -> @c_scmvolume.inf,%ClassDesc%;Storage Class Memory volumes [HKLM\SYSTEM\CurrentControlSet\Control\Class\{53d29ef7-377c-4d14-864b-eb3a85769359}] : (Biometric) [] -> @%SystemRoot%\System32\SysClass.DLL,-3028 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{5630831c-06c9-4856-b327-f5d32586e060}] : (Proximity) [] -> @c_proximity.inf,%ClassDesc%;Proximity devices [HKLM\SYSTEM\CurrentControlSet\Control\Class\{5989fce8-9cd0-467d-8a6a-5419e31529d4}] : (AudioProcessingObject) [] -> @c_apo.inf,%ClassDesc%;Audio Processing Objects (APOs) [HKLM\SYSTEM\CurrentControlSet\Control\Class\{5aea001d-9372-4ed7-97f3-b79bf15a53c5}] : (OposLegacyDevice) [] -> @oposdrv.inf,%ClassName%;OPOS Legacy Device [HKLM\SYSTEM\CurrentControlSet\Control\Class\{5c4c3332-344d-483c-8739-259e934c9cc8}] : (SoftwareComponent) [] -> @c_swcomponent.inf,%ClassDesc%;Software components [HKLM\SYSTEM\CurrentControlSet\Control\Class\{5d1b9aaa-01e2-46af-849f-272b3f324c46}] : (FSFilterSystem) [] -> @c_fssystem.inf,%ClassDesc%;FS System filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{62f9c741-b25a-46ce-b54c-9bccce08b6f2}] : (SoftwareDevice) [] -> @c_swdevice.inf,%ClassDesc%;Software devices [HKLM\SYSTEM\CurrentControlSet\Control\Class\{645ad99b-1344-4316-837a-08a3e73db222}] : (PerceptionSimulation) [] -> @PerceptionSimulationSixDof.inf,%ClassName%;Perception Simulation Controllers [HKLM\SYSTEM\CurrentControlSet\Control\Class\{6a0a8e78-bba6-4fc4-a709-1e33cd09d67e}] : (PhysicalQuotaManagement) [] -> @c_fsphysicalquotamgmt.inf,%ClassDesc%;FS Physical quota management filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{6bdd1fc1-810f-11d0-bec7-08002be2092f}] : (1394) [] -> @%SystemRoot%\System32\SysClass.Dll,-3016 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{6bdd1fc5-810f-11d0-bec7-08002be2092f}] : (Infrared) [] -> @%SystemRoot%\System32\NetCfgx.dll,-1501 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{6bdd1fc6-810f-11d0-bec7-08002be2092f}] : (Image) [] -> @%SystemRoot%\system32\sti_ci.dll,-52 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{6d807884-7d21-11cf-801c-08002be10318}] : (TapeDrive) [] -> @%SystemRoot%\System32\SysClass.Dll,-3006 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{6FAE73B7-B735-4B50-A0DA-0DC2484B1F1A}] : (BasicDisplay) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{71a27cdd-812a-11d0-bec7-08002be2092f}] : (Volume) [] -> @c_volume.inf,%ClassDesc%;Storage volumes [HKLM\SYSTEM\CurrentControlSet\Control\Class\{71aa14f8-6fad-4622-ad77-92bb9d7e6947}] : (ContinuousBackup) [] -> @c_fscontinuousbackup.inf,%ClassDesc%;FS Continuous backup filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{72631e54-78a4-11d0-bcf7-00aa00b7b32a}] : (Battery) [] -> @%SystemRoot%\system32\powrprof.dll,-611 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{745a17a0-74d3-11d0-b6fe-00a0c90f57da}] : (HIDClass) [] -> @%SystemRoot%\System32\hid.dll,-101 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{772e18f2-8925-4229-a5ac-6453cb482fda}] : (HidCashDrawer) [] -> @c_cashdrawer.inf,%ClassName%;POS Cash Drawer [HKLM\SYSTEM\CurrentControlSet\Control\Class\{7ebefbc0-3200-11d2-b4c2-00a0c9697d07}] : (61883) [] -> @%SystemRoot%\System32\SysClass.Dll,-3019 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{81C87465-DE07-4EFC-9D93-61E891D52FD2}] : (RdpVideoMiniport) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{8496e87e-c0a1-4102-9d8d-bd9a9b8b07a9}] : (WDC_SAM) [] -> @oem5.inf,%WDC_SAM_ClassName%;WD Drive Management devices [HKLM\SYSTEM\CurrentControlSet\Control\Class\{8503c911-a6c7-4919-8f79-5028f5866b0c}] : (QuotaManagement) [] -> @c_fsquotamgmt.inf,%ClassDesc%;FS Quota management filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{87ef9ad1-8f70-49ee-b215-ab1fcadcbe3c}] : (NetDriver) [] -> @c_netdriver.inf,%ClassDesc%;Universal Network Drivers [HKLM\SYSTEM\CurrentControlSet\Control\Class\{88a1c342-4539-11d3-b88d-00c04fad5171}] : (TS_Generic) [] -> @ts_generic.inf,%TSClassName%;Generic Remote Desktop devices [HKLM\SYSTEM\CurrentControlSet\Control\Class\{88bae032-5a81-49f0-bc3d-a4ff138216d6}] : (USBDevice) [] -> @%SystemRoot%\System32\SysClass.Dll,-3029 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{89786ff1-9c12-402f-9c9e-17753c7f4375}] : (CopyProtection) [] -> @c_fscopyprotection.inf,%ClassDesc%;FS Copy protection filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{8ecc055d-047f-11d1-a537-0000f8753ed1}] : (LegacyDriver) [] -> @%SystemRoot%\System32\SysClass.Dll,-3003 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{990a2bd7-e738-46c7-b26f-1cf8fb9f1391}] : (SmartCard) [] -> @%SystemRoot%\System32\SysClass.DLL,-3031 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{9da2b80f-f89f-4a49-a5c2-511b085b9e8a}] : (EhStorSilo) [] -> @rawsilo.inf,%ClassName%;IEEE 1667 silo and control devices [HKLM\SYSTEM\CurrentControlSet\Control\Class\{a0a588a4-c46f-4b37-b7ea-c82fe89870c6}] : (SDHost) [] -> @%SystemRoot%\System32\SysClass.Dll,-3012 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{a0a701c0-a511-42ff-aa6c-06dc0395576f}] : (Encryption) [] -> @c_fsencryption.inf,%ClassDesc%;FS Encryption filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{A3E32DBA-BA89-4F17-8386-2D0127FBD4CC}] : (rdpbus) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{A73C93F1-9727-4D1D-ACE1-0E333BA4E7DB}] : (nvlddmkm) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{b1d1a169-c54f-4379-81db-bee7d88d7454}] : (AntiVirus) [] -> @c_fsantivirus.inf,%ClassDesc%;FS Anti-virus filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{b2728d24-ac56-42db-9e02-8edaf5db652f}] : (RDCamera) [] -> @rdcameradriver.inf,%ClassName%;Remote Desktop Camera devices [HKLM\SYSTEM\CurrentControlSet\Control\Class\{b86dff51-a31e-4bac-b3cf-e8cfe75c9fc2}] : (ActivityMonitor) [] -> @c_fsactivitymonitor.inf,%ClassDesc%;FS Activity monitor filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{bbbe8734-08fa-4966-b6a6-4e5ad010cdd7}] : (USBFunctionController) [] -> @%SystemRoot%\System32\SysClass.Dll,-3030 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{c06ff265-ae09-48f0-812c-16753d7cba83}] : (AVC) [] -> @%SystemRoot%\System32\SysClass.Dll,-3027 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{c166523c-fe0c-4a94-a586-f1a80cfbbf3e}] : (AudioEndpoint) [] -> @audioendpoint.inf,%ClassName%;Audio inputs and outputs [HKLM\SYSTEM\CurrentControlSet\Control\Class\{c243ffbd-3afc-45e9-b3d3-2ba18bc7ebc5}] : (BarcodeScanner) [] -> @c_barcodescanner.inf,%ClassName%;POS Barcode Scanner [HKLM\SYSTEM\CurrentControlSet\Control\Class\{c30ecea0-11ef-4ef9-b02e-6af81e6e65c0}] : (WSDPrintDevice) [] -> @wsdprint.inf,%ClassName%;WSD Print Provider [HKLM\SYSTEM\CurrentControlSet\Control\Class\{c7bc9b22-21f0-4f0d-9bb6-66c229b8cd33}] : (POSPrinter) [] -> @c_receiptprinter.inf,%ClassName%;POS Receipt Printer [HKLM\SYSTEM\CurrentControlSet\Control\Class\{ca3e7ab9-b4c3-4ae6-8251-579ef933890f}] : (Camera) [] -> @c_camera.inf,%ClassDesc%;Cameras [HKLM\SYSTEM\CurrentControlSet\Control\Class\{cdcf0939-b75b-4630-bf76-80f7ba655884}] : (CFSMetadataServer) [] -> @c_fscfsmetadataserver.inf,%ClassDesc%;FS CFS metadata server filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{ce5939ae-ebde-11d0-b181-0000f8753ec4}] : (MediumChanger) [] -> @%SystemRoot%\System32\StorProp.dll,-17003 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{d02bc3da-0c8e-4945-9bd5-f1883c226c8c}] : (SecurityEnhancer) [] -> @c_fssecurityenhancer.inf,%ClassDesc%;FS Security enhancer filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{d421b08e-6d16-41ca-9c4d-9147e5ac98e0}] : (Miracast) [] -> @miradisp.inf,%ClassName%;Miracast display devices [HKLM\SYSTEM\CurrentControlSet\Control\Class\{d48179be-ec20-11d1-b6b8-00c04fa372a7}] : (SBP2) [] -> @%SystemRoot%\System32\SysClass.Dll,-3017 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{d546500a-2aeb-45f6-9482-f4b1799c3177}] : (HSM) [] -> @c_fshsm.inf,%ClassDesc%;FS HSM filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{d612553d-06b1-49ca-8938-e39ef80eb16f}] : (Holographic) [] -> @c_holographic.inf,%ClassName%;Mixed Reality devices [HKLM\SYSTEM\CurrentControlSet\Control\Class\{d61ca365-5af4-4486-998b-9db4734c6ca3}] : (XnaComposite) [] -> @xusb22.inf,%XUSB22.ClassName%;Xbox 360 Peripherals [HKLM\SYSTEM\CurrentControlSet\Control\Class\{d94ee5d8-d189-4994-83d2-f68d7d41b0e6}] : (SecurityDevices) [] -> @%SystemRoot%\System32\SysClass.Dll,-3020 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{db4f6ddd-9c0e-45e4-9597-78dbbad0f412}] : (SmartCardFilter) [] -> @%SystemRoot%\System32\SysClass.DLL,-3032 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{e0cbf06c-cd8b-4647-bb8a-263b43f0f974}] : (Bluetooth) [] -> @%SystemRoot%\system32\bthci.dll,-4001 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{e2f84ce7-8efa-411c-aa69-97454ca4cb57}] : (Extension) [] -> @c_extension.inf,%ClassDesc%;Extensions [HKLM\SYSTEM\CurrentControlSet\Control\Class\{e55fa6f9-128c-4d04-abab-630c74b1453a}] : (Infrastructure) [] -> @c_fsinfrastructure.inf,%ClassDesc%;FS Infrastructure filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{e6f1aa1c-7f3b-4473-b2e8-c97d8ac71d53}] : (UCM) [] -> @c_ucm.inf,%ClassDesc%;USB Connector Managers [HKLM\SYSTEM\CurrentControlSet\Control\Class\{eec5ad98-8080-425f-922a-dabf3de3f69a}] : (WPD) [] -> @%SystemRoot%\System32\wpd_ci.dll,-101 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{f2e7dd72-6468-4e36-b6f1-6488f42c1b52}] : (Firmware) [] -> @c_firmware.inf,%ClassDesc%;Firmware [HKLM\SYSTEM\CurrentControlSet\Control\Class\{f3586baf-b5aa-49b5-8d6c-0569284c639f}] : (Compression) [] -> @c_fscompression.inf,%ClassDesc%;FS Compression filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{f75a86c0-10d8-4c3a-b233-ed60e4cdfaac}] : (Virtualization) [] -> @c_fsvirtualization.inf,%ClassDesc%;FS Virtualization filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{f8ecafa6-66d1-41a5-899b-66585d7216b7}] : (OpenFileBackup) [] -> @c_fsopenfilebackup.inf,%ClassDesc%;FS Open file backup filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{fe8f1572-c67a-48c0-bbac-0b5c6d66cafb}] : (Undelete) [] -> @c_fsundelete.inf,%ClassDesc%;FS Undelete filters [HKLM\SYSTEM\CurrentControlSet\Control\Els\Services\{2D64B439-6CAF-4f6b-B688-E5D0F4FAA7D7}] : (Script Detection) [@elscore.dll,-2] -> ElsLad.dll (Copyright (c) Microsoft Corporation.) [HKLM\SYSTEM\CurrentControlSet\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}] : (Transliteration) [@elscore.dll,-5] -> elstrans.dll (Copyright (c) Microsoft Corporation.) [HKLM\SYSTEM\CurrentControlSet\Control\Els\Services\{CF7E00B1-909B-4d95-A8F4-611F7C377702}] : (Language Detection) [@elscore.dll,-1] -> ElsLad.dll (Copyright (c) Microsoft Corporation.) ---------- | Loaded modules (whitelist) [22/10/2017 17:22:06] - (0.0.0.0) - ( -) - C:\WINDOWS\system32\pwdrvio.sys [08/08/2019 14:40:21] - (8.98.0.0) - (REALiX(tm) - HWiNFO AMD64 Kernel Driver) - C:\WINDOWS\SysWOW64\drivers\HWiNFO64A.SYS [29/11/2018 21:55:00] - (1.2.0.264) - (Glarysoft Ltd - The driver for the Startup Manager tool) - C:\WINDOWS\System32\drivers\GUBootStartup.sys [10/04/2017 17:52:38] - (0.0.0.0) - ( -) - C:\WINDOWS\SysWow64\drivers\AsIO.sys [15/12/2019 21:00:48] - (26.21.14.4166) - (NVIDIA Corporation - NVIDIA Windows Kernel Mode Driver, Version 441.66) - C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_77e6900053c33f6f\nvlddmkm.sys [15/11/2019 17:28:42] - (19.5.10.20) - (Synaptics Incorporated - Synaptics SMBus Driver) - C:\WINDOWS\System32\drivers\Smb_driver_Intel.sys [24/04/2019 17:32:26] - (4.13.0.0) - (NVIDIA Corporation - NVIDIA Virtual Audio Driver) - C:\WINDOWS\system32\drivers\nvvad64v.sys [18/07/2019 21:14:44] - (303.0.0.0) - (NVIDIA Corporation - Virtual USB Host Controller driver) - C:\WINDOWS\System32\drivers\nvvhci.sys [18/07/2019 21:14:44] - (1.3.38.21) - (NVIDIA Corporation - NVIDIA HDMI Audio Driver) - C:\WINDOWS\system32\drivers\nvhda64v.sys [21/03/2014 22:35:12] - (2.3.64.28) - (AVerMedia TECHNOLOGIES, Inc. - AVerMedia IT13x Series Driver) - C:\WINDOWS\System32\Drivers\AVerIT13x_x64.sys [04/06/2014 14:41:11] - (6.0.0.2) - (NTK - 96610 PC Camera mini Driver) - C:\WINDOWS\System32\Drivers\nvtcam.sys [04/06/2014 14:41:11] - (6.0.6000.16386) - (Windows (R) Codename Longhorn DDK provider - Universal Serial Bus Camera Driver) - C:\WINDOWS\System32\Drivers\NVTCAMD2.SYS [04/06/2014 14:41:11] - (2.0.0.89) - (Guillemot Corporation - Filter Driver for the Hercules Webcams (MJPG)) - C:\WINDOWS\System32\Drivers\hxctlflt.sys [04/06/2014 14:41:11] - (1.0.1.8) - (Guillemot Corp S.A. - Guillemot USB Audio Processing Filter) - C:\WINDOWS\System32\drivers\guillflt.sys [11/02/2011 22:23:34] - (4.1.0.2001) - (CACE Technologies, Inc. - npf.sys (NT5/6 AMD64) Kernel Driver) - C:\WINDOWS\system32\drivers\npf.sys [29/12/2012 21:59:38] - (2.3.11.0) - (Almico Software - SpeedFan x64 Driver) - C:\WINDOWS\SysWOW64\speedfan.sys [09/05/2018 09:00:46] - (1.0.0.0) - (Samsung Electronics - Port Contention Driver) - C:\WINDOWS\system32\Drivers\SSPORT.sys ---------- | Services | 0 : Starting up | 1 : System | 2 : Automatic | 3 : Manual | 4 : Disabled | R : Running service | S : Stopped service S0 - [Kernel Driver] - 3ware () -> System32\drivers\3ware.sys - AcceptPause: False - AcceptStop: False R0 - [Kernel Driver] - ACPI (@acpi.inf,%ACPI.SvcDesc%;Microsoft ACPI Driver) -> System32\drivers\ACPI.sys - AcceptPause: False - AcceptStop: True R0 - [Kernel Driver] - acpiex (Microsoft ACPIEx Driver) -> System32\Drivers\acpiex.sys - AcceptPause: False - AcceptStop: True S0 - [Kernel Driver] - ADP80XX () -> System32\drivers\ADP80XX.SYS - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - amdsata () -> System32\drivers\amdsata.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - amdsbs () -> System32\drivers\amdsbs.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - amdxata () -> System32\drivers\amdxata.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - arcsas (@arcsas.inf,%arcsas_ServiceName%;Adaptec SAS/SATA-II RAID Storport's Miniport Driver) -> System32\drivers\arcsas.sys - AcceptPause: False - AcceptStop: False R0 - [Kernel Driver] - aswArDisk (aswArDisk) -> system32\drivers\aswArDisk.sys - AcceptPause: False - AcceptStop: True R0 - [File System Driver] - aswbidsh (aswbidsh) -> system32\drivers\aswbidsh.sys - AcceptPause: False - AcceptStop: True R0 - [File System Driver] - aswbuniv (aswbuniv) -> system32\drivers\aswbuniv.sys - AcceptPause: False - AcceptStop: True R0 - [Kernel Driver] - aswElam (aswElam) -> system32\drivers\aswElam.sys - AcceptPause: False - AcceptStop: True R0 - [Kernel Driver] - aswRvrt (aswRvrt) -> system32\drivers\aswRvrt.sys - AcceptPause: False - AcceptStop: True R0 - [Kernel Driver] - aswVmm (aswVmm) -> system32\drivers\aswVmm.sys - AcceptPause: False - AcceptStop: True S0 - [Kernel Driver] - atapi (@mshdc.inf,%idechannel.DeviceDesc%;IDE Channel) -> System32\drivers\atapi.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - b06bdrv (@netbvbda.inf,%vbd_srv_desc%;QLogic Network Adapter VBD) -> System32\drivers\bxvbda.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - bttflt (@virtdisk.inf,%service_desc%;Microsoft Hyper-V VHDPMEM BTT Filter) -> System32\drivers\bttflt.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - cht4iscsi () -> System32\drivers\cht4sx64.sys - AcceptPause: False - AcceptStop: False R0 - [Kernel Driver] - CLFS (@%SystemRoot%\system32\drivers\clfs.sys,-100) -> System32\drivers\CLFS.sys - AcceptPause: False - AcceptStop: True R0 - [Kernel Driver] - CNG () -> System32\Drivers\cng.sys - AcceptPause: False - AcceptStop: True R0 - [Kernel Driver] - disk (@disk.inf,%disk_ServiceDesc%;Pilote de disque) -> System32\drivers\disk.sys - AcceptPause: False - AcceptStop: True S0 - [Kernel Driver] - ebdrv (@netevbda.inf,%vbd_srv_desc%;QLogic 10 Gigabit Ethernet Adapter VBD) -> System32\drivers\evbda.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - EhStorClass (@%SystemRoot%\system32\drivers\EhStorClass.sys,-100) -> System32\drivers\EhStorClass.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - EhStorTcgDrv (@ehstortcgdrv.inf,%EhStorTcgDrv.Desc%;Microsoft driver for storage devices supporting IEEE 1667 and TCG protocols) -> System32\drivers\EhStorTcgDrv.sys - AcceptPause: False - AcceptStop: False R0 - [File System Driver] - FileInfo (@%SystemRoot%\system32\drivers\fileinfo.sys,-100) -> System32\drivers\fileinfo.sys - AcceptPause: False - AcceptStop: True R0 - [File System Driver] - FltMgr (@%SystemRoot%\system32\drivers\fltmgr.sys,-10001) -> system32\drivers\fltmgr.sys - AcceptPause: False - AcceptStop: True R0 - [Kernel Driver] - fvevol (@%SystemRoot%\system32\drivers\fvevol.sys,-100) -> System32\DRIVERS\fvevol.sys - AcceptPause: False - AcceptStop: True S0 - [Kernel Driver] - HpSAMD () -> System32\drivers\HpSAMD.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - hwpolicy (@%systemroot%\system32\drivers\hwpolicy.sys,-101) -> System32\drivers\hwpolicy.sys - AcceptPause: False - AcceptStop: False R0 - [Kernel Driver] - iaStorA () -> System32\drivers\iaStorA.sys - AcceptPause: False - AcceptStop: True S0 - [Kernel Driver] - iaStorAVC (@iastorav.inf,%iaStorAVC.DeviceDesc%;Intel Chipset SATA RAID Controller) -> System32\drivers\iaStorAVC.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - iaStorV (@iastorv.inf,%*PNP0600.DeviceDesc%;Intel RAID Controller Windows 7) -> System32\drivers\iaStorV.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - intelide () -> System32\drivers\intelide.sys - AcceptPause: False - AcceptStop: False R0 - [Kernel Driver] - intelpep (@intelpep.inf,%INTELPEP.SVCDESC%;Intel(R) Power Engine Plug-in Driver) -> System32\drivers\intelpep.sys - AcceptPause: False - AcceptStop: True R0 - [Kernel Driver] - iorate (@%SystemRoot%\system32\drivers\iorate.sys,-101) -> system32\drivers\iorate.sys - AcceptPause: False - AcceptStop: True S0 - [Kernel Driver] - isapnp () -> System32\drivers\isapnp.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - ItSas35i () -> System32\drivers\ItSas35i.sys - AcceptPause: False - AcceptStop: False R0 - [Kernel Driver] - KSecDD () -> System32\Drivers\ksecdd.sys - AcceptPause: False - AcceptStop: True R0 - [Kernel Driver] - KSecPkg () -> System32\Drivers\ksecpkg.sys - AcceptPause: False - AcceptStop: True S0 - [Kernel Driver] - LSI_SAS () -> System32\drivers\lsi_sas.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - LSI_SAS2i () -> System32\drivers\lsi_sas2i.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - LSI_SAS3i () -> System32\drivers\lsi_sas3i.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - LSI_SSS () -> System32\drivers\lsi_sss.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - MbamElam (MbamElam) -> system32\DRIVERS\MbamElam.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - megasas () -> System32\drivers\megasas.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - megasas2i () -> System32\drivers\MegaSas2i.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - megasas35i () -> System32\drivers\megasas35i.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - megasr () -> System32\drivers\megasr.sys - AcceptPause: False - AcceptStop: False R0 - [Kernel Driver] - mountmgr (@%SystemRoot%\system32\drivers\mountmgr.sys,-100) -> System32\drivers\mountmgr.sys - AcceptPause: False - AcceptStop: True R0 - [Kernel Driver] - msisadrv () -> System32\drivers\msisadrv.sys - AcceptPause: False - AcceptStop: True R0 - [File System Driver] - Mup (@%systemroot%\system32\drivers\mup.sys,-101) -> System32\Drivers\mup.sys - AcceptPause: False - AcceptStop: True S0 - [Kernel Driver] - mvumis () -> System32\drivers\mvumis.sys - AcceptPause: False - AcceptStop: False R0 - [Kernel Driver] - NDIS (@%SystemRoot%\system32\drivers\ndis.sys,-200) -> system32\drivers\ndis.sys - AcceptPause: False - AcceptStop: True S0 - [Kernel Driver] - nvraid () -> System32\drivers\nvraid.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - nvstor () -> System32\drivers\nvstor.sys - AcceptPause: False - AcceptStop: False R0 - [Kernel Driver] - partmgr (@%SystemRoot%\system32\drivers\partmgr.sys,-100) -> System32\drivers\partmgr.sys - AcceptPause: False - AcceptStop: True R0 - [Kernel Driver] - pci (@pci.inf,%pci_svcdesc%;Pilote de bus PCI) -> System32\drivers\pci.sys - AcceptPause: False - AcceptStop: True S0 - [Kernel Driver] - pciide () -> System32\drivers\pciide.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - pcmcia () -> System32\drivers\pcmcia.sys - AcceptPause: False - AcceptStop: False R0 - [Kernel Driver] - pcw (Performance Counters for Windows Driver) -> System32\drivers\pcw.sys - AcceptPause: False - AcceptStop: True R0 - [Kernel Driver] - pdc (@%SystemRoot%\system32\drivers\pdc.sys,-100) -> system32\drivers\pdc.sys - AcceptPause: False - AcceptStop: True S0 - [Kernel Driver] - percsas2i () -> System32\drivers\percsas2i.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - percsas3i () -> System32\drivers\percsas3i.sys - AcceptPause: False - AcceptStop: False R0 - [Kernel Driver] - pwdrvio (pwdrvio) -> system32\pwdrvio.sys - AcceptPause: False - AcceptStop: True S0 - [Kernel Driver] - Ramdisk (Windows RAM Disk Driver) -> system32\DRIVERS\ramdisk.sys - AcceptPause: False - AcceptStop: False R0 - [Kernel Driver] - rdyboost (ReadyBoost) -> System32\drivers\rdyboost.sys - AcceptPause: False - AcceptStop: True S0 - [Kernel Driver] - sbp2port (@sbp2.inf,%sbp2_ServiceDesc%;SBP-2 Transport/Protocol Bus Driver) -> System32\drivers\sbp2port.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - scmbus (@scmbus.inf,%scmbus.SvcDesc%;Microsoft Storage Class Memory Bus Driver) -> System32\drivers\scmbus.sys - AcceptPause: False - AcceptStop: False R0 - [Kernel Driver] - SgrmAgent (@%SystemRoot%\System32\Drivers\SgrmAgent.sys,-1001) -> system32\drivers\SgrmAgent.sys - AcceptPause: False - AcceptStop: True S0 - [Kernel Driver] - SiSRaid2 () -> System32\drivers\SiSRaid2.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - SiSRaid4 () -> System32\drivers\sisraid4.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - SmartSAMD () -> System32\drivers\SmartSAMD.sys - AcceptPause: False - AcceptStop: False R0 - [Kernel Driver] - spaceport (@spaceport.inf,%Spaceport_ServiceDesc%;Storage Spaces Driver) -> System32\drivers\spaceport.sys - AcceptPause: False - AcceptStop: True S0 - [Kernel Driver] - stexstor () -> System32\drivers\stexstor.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - storahci (@mshdc.inf,%storahci_ServiceDescription%;Microsoft Standard SATA AHCI Driver) -> System32\drivers\storahci.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - storflt (@wstorflt.inf,%service_desc%;Microsoft Hyper-V Storage Accelerator) -> System32\drivers\vmstorfl.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - stornvme (@stornvme.inf,%StorNVMe_ServiceDesc%;Microsoft Standard NVM Express Driver) -> System32\drivers\stornvme.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - storufs (@storufs.inf,%UfsServiceDesc%;Microsoft Universal Flash Storage (UFS) Driver) -> System32\drivers\storufs.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - storvsc () -> System32\drivers\storvsc.sys - AcceptPause: False - AcceptStop: False R0 - [Kernel Driver] - Tcpip (@%SystemRoot%\system32\drivers\tcpip.sys,-10001) -> System32\drivers\tcpip.sys - AcceptPause: False - AcceptStop: True R0 - [Kernel Driver] - vdrvroot (@vdrvroot.inf,%vdrvroot_svcdesc%;Microsoft Virtual Drive Enumerator) -> System32\drivers\vdrvroot.sys - AcceptPause: False - AcceptStop: True S0 - [Kernel Driver] - vmbus (@wvmbus.inf,%vmbus.SVCDESC%;Virtual Machine Bus) -> System32\drivers\vmbus.sys - AcceptPause: False - AcceptStop: False R0 - [Kernel Driver] - volmgr (@volmgr.inf,%volmgr_svcdesc%;Volume Manager Driver) -> System32\drivers\volmgr.sys - AcceptPause: False - AcceptStop: True R0 - [Kernel Driver] - volmgrx (@%SystemRoot%\system32\drivers\volmgrx.sys,-100) -> System32\drivers\volmgrx.sys - AcceptPause: False - AcceptStop: True R0 - [Kernel Driver] - volsnap (@%SystemRoot%\system32\drivers\volsnap.sys,-100) -> System32\drivers\volsnap.sys - AcceptPause: False - AcceptStop: True R0 - [Kernel Driver] - volume (@volume.inf,%VolumeServiceDesc%;Volume driver) -> System32\drivers\volume.sys - AcceptPause: False - AcceptStop: True S0 - [Kernel Driver] - vsmraid () -> System32\drivers\vsmraid.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - VSTXRAID (@vstxraid.inf,%Driver.DeviceDesc%;VIA StorX Storage RAID Controller Windows Driver) -> System32\drivers\vstxraid.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - WdBoot (@%ProgramFiles%\Windows Defender\MpAsDesc.dll,-390) -> system32\drivers\wd\WdBoot.sys - AcceptPause: False - AcceptStop: False R0 - [Kernel Driver] - Wdf01000 (@%SystemRoot%\system32\drivers\Wdf01000.sys,-1000) -> system32\drivers\Wdf01000.sys - AcceptPause: False - AcceptStop: True R0 - [File System Driver] - WdFilter (@%ProgramFiles%\Windows Defender\MpAsDesc.dll,-330) -> system32\drivers\wd\WdFilter.sys - AcceptPause: False - AcceptStop: True R0 - [Kernel Driver] - WFPLWFS (@%SystemRoot%\System32\drivers\wfplwfs.sys,-6000) -> System32\drivers\wfplwfs.sys - AcceptPause: False - AcceptStop: True R0 - [Kernel Driver] - WindowsTrustedRT (Windows Trusted Execution Environment Class Extension) -> system32\drivers\WindowsTrustedRT.sys - AcceptPause: False - AcceptStop: True R0 - [Kernel Driver] - WindowsTrustedRTProxy (@WindowsTrustedRTProxy.inf,%WindowsTrustedRTProxy.SVCDESC%;Microsoft Windows Trusted Runtime Secure Service) -> System32\drivers\WindowsTrustedRTProxy.sys - AcceptPause: False - AcceptStop: True R0 - [File System Driver] - Wof (Windows Overlay File System Filter Driver) -> (?) - AcceptPause: False - AcceptStop: True R1 - [Kernel Driver] - AFD (@%systemroot%\system32\drivers\afd.sys,-1000) -> \SystemRoot\system32\drivers\afd.sys - AcceptPause: False - AcceptStop: True R1 - [Kernel Driver] - afunix (afunix) -> \SystemRoot\system32\drivers\afunix.sys - AcceptPause: False - AcceptStop: True R1 - [Kernel Driver] - ahcache (@%systemroot%\system32\drivers\ahcache.sys,-102) -> system32\DRIVERS\ahcache.sys - AcceptPause: False - AcceptStop: True R1 - [Kernel Driver] - aswArPot (aswArPot) -> system32\drivers\aswArPot.sys - AcceptPause: False - AcceptStop: True R1 - [File System Driver] - aswbidsdriver (aswbidsdriver) -> system32\drivers\aswbidsdriver.sys - AcceptPause: False - AcceptStop: True R1 - [Kernel Driver] - aswHdsKe (aswHdsKe) -> system32\drivers\aswHdsKe.sys - AcceptPause: False - AcceptStop: True R1 - [Kernel Driver] - aswKbd (aswKbd) -> system32\drivers\aswKbd.sys - AcceptPause: False - AcceptStop: True R1 - [Kernel Driver] - aswRdr (aswRdr) -> system32\drivers\aswRdr2.sys - AcceptPause: False - AcceptStop: True R1 - [File System Driver] - aswSnx (aswSnx) -> system32\drivers\aswSnx.sys - AcceptPause: False - AcceptStop: True R1 - [File System Driver] - aswSP (aswSP) -> system32\drivers\aswSP.sys - AcceptPause: False - AcceptStop: True R1 - [Kernel Driver] - bam (@%SystemRoot%\system32\drivers\bam.sys,-100) -> system32\drivers\bam.sys - AcceptPause: False - AcceptStop: True R1 - [Kernel Driver] - BasicDisplay () -> \SystemRoot\System32\DriverStore\FileRepository\basicdisplay.inf_amd64_307898c750ba9e44\BasicDisplay.sys - AcceptPause: False - AcceptStop: True R1 - [Kernel Driver] - BasicRender () -> \SystemRoot\System32\DriverStore\FileRepository\basicrender.inf_amd64_ba2a8de08ea0d469\BasicRender.sys - AcceptPause: False - AcceptStop: True R1 - [Kernel Driver] - Beep (Beep) -> (?) - AcceptPause: False - AcceptStop: True R1 - [Kernel Driver] - cdrom (@cdrom.inf,%cdrom_ServiceDesc%;CD-ROM Driver) -> \SystemRoot\System32\drivers\cdrom.sys - AcceptPause: False - AcceptStop: True S1 - [Kernel Driver] - dam (@%SystemRoot%\system32\drivers\dam.sys,-100) -> system32\drivers\dam.sys - AcceptPause: False - AcceptStop: False R1 - [File System Driver] - Dfsc (@%systemroot%\system32\wkssvc.dll,-1008) -> System32\Drivers\dfsc.sys - AcceptPause: False - AcceptStop: True R1 - [Kernel Driver] - DXGKrnl (LDDM Graphics Subsystem) -> \SystemRoot\System32\drivers\dxgkrnl.sys - AcceptPause: False - AcceptStop: True R1 - [File System Driver] - FileCrypt (@%systemroot%\system32\drivers\filecrypt.sys,-100) -> system32\drivers\filecrypt.sys - AcceptPause: False - AcceptStop: True R1 - [Kernel Driver] - GpuEnergyDrv (@%SystemRoot%\system32\drivers\gpuenergydrv.sys,-100) -> System32\drivers\gpuenergydrv.sys - AcceptPause: False - AcceptStop: True R1 - [Kernel Driver] - GUBootStartup (GUBootStartup) -> \??\C:\WINDOWS\System32\drivers\GUBootStartup.sys - AcceptPause: False - AcceptStop: True R1 - [Kernel Driver] - HWiNFO32 (HWiNFO32/64 Kernel Driver) -> \??\C:\WINDOWS\SysWOW64\drivers\HWiNFO64A.SYS - AcceptPause: False - AcceptStop: True R1 - [File System Driver] - Msfs () -> (?) - AcceptPause: False - AcceptStop: True R1 - [Kernel Driver] - mssmbios (@mssmbios.inf,%mssmbios_svcdesc%;Microsoft System Management BIOS Driver) -> \SystemRoot\System32\drivers\mssmbios.sys - AcceptPause: False - AcceptStop: True R1 - [File System Driver] - NetBIOS (@%windir%\system32\drivers\netbios.sys,-503) -> system32\drivers\netbios.sys - AcceptPause: False - AcceptStop: True R1 - [Kernel Driver] - NetBT (@%SystemRoot%\system32\drivers\netbt.sys,-2) -> System32\DRIVERS\netbt.sys - AcceptPause: False - AcceptStop: True R1 - [File System Driver] - Npfs () -> (?) - AcceptPause: False - AcceptStop: True R1 - [Kernel Driver] - npsvctrig (@npsvctrig.inf,%NPSVCTRIG.SvcDisplayName%;Named pipe service trigger provider) -> \SystemRoot\System32\drivers\npsvctrig.sys - AcceptPause: False - AcceptStop: True R1 - [Kernel Driver] - nsiproxy (@%SystemRoot%\system32\drivers\nsiproxy.sys,-2) -> system32\drivers\nsiproxy.sys - AcceptPause: False - AcceptStop: True R1 - [Kernel Driver] - Null () -> (?) - AcceptPause: False - AcceptStop: True R1 - [Kernel Driver] - Psched (@%windir%\System32\drivers\pacer.sys,-101) -> System32\drivers\pacer.sys - AcceptPause: False - AcceptStop: True R1 - [File System Driver] - rdbss (@%systemroot%\system32\wkssvc.dll,-1000) -> system32\DRIVERS\rdbss.sys - AcceptPause: False - AcceptStop: True R1 - [Kernel Driver] - tdx (@%SystemRoot%\system32\tcpipcfg.dll,-50004) -> \SystemRoot\system32\DRIVERS\tdx.sys - AcceptPause: False - AcceptStop: True R1 - [Kernel Driver] - vwififlt (@%SystemRoot%\System32\drivers\vwififlt.sys,-259) -> System32\drivers\vwififlt.sys - AcceptPause: False - AcceptStop: True R2 - [File System Driver] - aswMonFlt (aswMonFlt) -> system32\drivers\aswMonFlt.sys - AcceptPause: False - AcceptStop: True S2 - [Kernel Driver] - aswStm (aswStm) -> system32\drivers\aswStm.sys - AcceptPause: False - AcceptStop: False R2 - [File System Driver] - CldFlt (Windows Cloud Files Filter Driver) -> system32\drivers\cldflt.sys - AcceptPause: False - AcceptStop: True R2 - [Kernel Driver] - lltdio (@%SystemRoot%\system32\lltdres.dll,-6) -> system32\drivers\lltdio.sys - AcceptPause: False - AcceptStop: True R2 - [File System Driver] - luafv (@%systemroot%\system32\drivers\luafv.sys,-100) -> \SystemRoot\system32\drivers\luafv.sys - AcceptPause: False - AcceptStop: True R2 - [Kernel Driver] - MMCSS (@%systemroot%\system32\drivers\mmcss.sys,-100) -> \SystemRoot\system32\drivers\mmcss.sys - AcceptPause: False - AcceptStop: True R2 - [Kernel Driver] - MsLldp (@%SystemRoot%\system32\drivers\mslldp.sys,-200) -> system32\drivers\mslldp.sys - AcceptPause: False - AcceptStop: True R2 - [Kernel Driver] - Ndu (@%SystemRoot%\system32\drivers\Ndu.sys,-10001) -> system32\drivers\Ndu.sys - AcceptPause: False - AcceptStop: True R2 - [Kernel Driver] - NPF (NetGroup Packet Filter Driver) -> \??\C:\WINDOWS\system32\drivers\npf.sys - AcceptPause: False - AcceptStop: True R2 - [Kernel Driver] - PEAUTH (PEAUTH) -> system32\drivers\peauth.sys - AcceptPause: False - AcceptStop: True R2 - [Kernel Driver] - rspndr (@%SystemRoot%\system32\lltdres.dll,-5) -> system32\drivers\rspndr.sys - AcceptPause: False - AcceptStop: True R2 - [Kernel Driver] - speedfan (speedfan) -> \??\C:\WINDOWS\SysWOW64\speedfan.sys - AcceptPause: False - AcceptStop: True R2 - [File System Driver] - srv (@%systemroot%\system32\srvsvc.dll,-102) -> System32\DRIVERS\srv.sys - AcceptPause: False - AcceptStop: True R2 - [Kernel Driver] - SSPORT (SSPORT) -> \??\C:\WINDOWS\system32\Drivers\SSPORT.sys - AcceptPause: False - AcceptStop: True R2 - [File System Driver] - storqosflt (@%SystemRoot%\System32\drivers\storqosflt.sys,-101) -> system32\drivers\storqosflt.sys - AcceptPause: False - AcceptStop: True R2 - [Kernel Driver] - tcpipreg (TCP/IP Registry Compatibility) -> System32\drivers\tcpipreg.sys - AcceptPause: False - AcceptStop: True R2 - [Kernel Driver] - wanarp (@%systemroot%\system32\mprmsg.dll,-32011) -> System32\DRIVERS\wanarp.sys - AcceptPause: False - AcceptStop: True R2 - [File System Driver] - wcifs (@%systemroot%\system32\drivers\wcifs.sys,-100) -> \SystemRoot\system32\drivers\wcifs.sys - AcceptPause: False - AcceptStop: True R2 - [File System Driver] - MBAMChameleon (MBAMChameleon) -> \SystemRoot\System32\Drivers\MbamChameleon.sys - AcceptPause: False - AcceptStop: True ---------- | System files (Microsoft|Avast|Atheros|Adaptec|Brother|Intel Files whitelisted) ---------- | Uninstall (Whitelist) [HKU\S-1-5-21-548730727-4139670515-3000484307-1001\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\RadioSure] : (RadioSure.-.) -> C:\Users\EVRARD\AppData\Local\RadioSure\uninstall.exe ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\Connection Manager] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\Unlocker] : (Unlocker 1.9.2.-.Cedrick Collomb) -> C:\Program Files\Unlocker\uninst.exe [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\VSDC Free Video Editor_is1] : (VSDC Free Video Editor version 6.4.1.71.-.Flash-Integro LLC) -> "C:\Program Files\FlashIntegro\unins000.exe" ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{031A0E14-0413-4C97-9772-2639B782F46F}] : (Common Desktop Agent.-.OEM) -> MsiExec.exe /X{031A0E14-0413-4C97-9772-2639B782F46F} [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{191F4D69-B671-4163-BB01-901B89A20D04}] : (LibreOffice 6.3.4.2.-.The Document Foundation) -> MsiExec.exe /I{191F4D69-B671-4163-BB01-901B89A20D04} ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{1E16E008-51D4-4641-A6D1-DDA8E914E40F}] : (MAGIX Vidéo deluxe Premium (Styles Photoshow Maker 1).-.MAGIX Software GmbH) -> MsiExec.exe /I{1E16E008-51D4-4641-A6D1-DDA8E914E40F} ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{27648BBB-4F73-4B04-B352-6E684A526D75}] : (MAGIX Vidéo deluxe Premium (Effets de transition).-.MAGIX Software GmbH) -> MsiExec.exe /I{27648BBB-4F73-4B04-B352-6E684A526D75} ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{2EC3F0A7-C79D-4228-84AF-CA0E12389D97}] : (MAGIX Video deluxe 2014 Premium Update.-.MAGIX AG) -> MsiExec.exe /X{2EC3F0A7-C79D-4228-84AF-CA0E12389D97} ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{3A826CCB-0FF2-4196-97FE-6DDCD739CF5E}] : (MAGIX Video deluxe 2014 Premium Update.-.MAGIX AG) -> MsiExec.exe /X{3A826CCB-0FF2-4196-97FE-6DDCD739CF5E} ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{3FC82B15-D74F-38DB-B76F-1A36F7AC3F3A}] : (MAGIX Vidéo deluxe Premium (Update Service 5.7.29.73).-.MAGIX Software GmbH) -> MsiExec.exe /X{3FC82B15-D74F-38DB-B76F-1A36F7AC3F3A} [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{43774DE9-8122-46C4-BD03-F59CA4410E82}] : (File Converter (64 bit).-.Adrien Allard) -> MsiExec.exe /X{43774DE9-8122-46C4-BD03-F59CA4410E82} ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{4A982522-D918-4E81-AD33-73C9E3C0BFE2}] : (MAGIX Vidéo deluxe Premium (effets de titres).-.MAGIX Software GmbH) -> MsiExec.exe /I{4A982522-D918-4E81-AD33-73C9E3C0BFE2} ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{51191082-901A-40D6-9C36-88501E60E9DD}] : (MAGIX Vidéo deluxe Premium Update.-.MAGIX Software GmbH) -> MsiExec.exe /X{51191082-901A-40D6-9C36-88501E60E9DD} ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{6A4BAF09-805C-45A3-A17D-214BA648C366}] : (MAGIX Vidéo deluxe Premium Update.-.MAGIX Software GmbH) -> MsiExec.exe /X{6A4BAF09-805C-45A3-A17D-214BA648C366} [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{70A0F34E-564B-4F93-ADD6-3BAEC6E44075}] : (Google Earth Pro.-.Google) -> MsiExec.exe /I{70A0F34E-564B-4F93-ADD6-3BAEC6E44075} ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{7369E8F3-BD7C-4F15-BC7B-BC37C3CE2354}] : (MAGIX Vidéo deluxe Premium (Éléments de design).-.MAGIX Software GmbH) -> MsiExec.exe /I{7369E8F3-BD7C-4F15-BC7B-BC37C3CE2354} [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{85B6BF0F-EF1B-4F0F-892D-E68BD798950C}] : (Intel(R) Computing Improvement Program.-.Intel Corporation) -> MsiExec.exe /X{85B6BF0F-EF1B-4F0F-892D-E68BD798950C} ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{883EE456-67C7-4891-BCF7-FD197E0E4F9D}] : (MAGIX Vidéo deluxe Premium.-.MAGIX Software GmbH) -> MsiExec.exe /I{883EE456-67C7-4891-BCF7-FD197E0E4F9D} ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{89AFB053-A343-46EF-97E4-D593AD7184E6}] : (Intel® Trusted Connect Service Client.-.Intel Corporation) -> MsiExec.exe /I{89AFB053-A343-46EF-97E4-D593AD7184E6} ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{9503AD68-6198-4081-9F57-1F346D7B58D4}] : (Intel(R) Rapid Storage Technology.-.Intel Corporation) -> MsiExec.exe /I{9503AD68-6198-4081-9F57-1F346D7B58D4} ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{95ED6413-2094-450C-8561-87EA8BA1D06A}] : (MAGIX Vidéo deluxe Premium (modèles de films 7).-.MAGIX Software GmbH) -> MsiExec.exe /I{95ED6413-2094-450C-8561-87EA8BA1D06A} ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{9AF04633-AA10-49EC-8969-2792531D34BA}] : (MAGIX Vidéo deluxe 2014 Premium.-.MAGIX Software GmbH) -> MsiExec.exe /I{9AF04633-AA10-49EC-8969-2792531D34BA} ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{A3C88E0B-0C3D-4CD2-8D7F-A9E0CD848506}] : (MAGIX Vidéo deluxe Premium Update.-.MAGIX Software GmbH) -> MsiExec.exe /X{A3C88E0B-0C3D-4CD2-8D7F-A9E0CD848506} ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Ansel] : (NVIDIA Ansel.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel] : (Panneau de configuration NVIDIA 441.66.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Optimus] : (NVIDIA Optimus Update 38.0.2.0.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update] : (Mises à jour NVIDIA 38.0.2.0.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GFExperience.NvStreamSrv] : (NVIDIA SHIELD Streaming.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer] : (NVIDIA Install Application.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvAbHub] : (NVIDIA ABHub.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvBackend] : (NVIDIA Backend.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer] : (NVIDIA Container.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.ContainerTelemetryApiHelper] : (NVIDIA TelemetryApi helper for NvContainer.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.LocalSystem] : (NVIDIA LocalSystem Container.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.MessageBus] : (NVIDIA Message Bus for NvContainer.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.NetworkService] : (NVIDIA NetworkService Container.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.NvapiMonitor] : (NVAPI Monitor plugin for NvContainer.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.Session] : (NVIDIA Session Container.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.User] : (NVIDIA User Container.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVDisplayContainer] : (NVIDIA Display Container.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVDisplayContainerLS] : (NVIDIA Display Container LS.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVDisplayPluginWatchdog] : (NVIDIA Display Watchdog Plugin.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVDisplaySessionContainer] : (NVIDIA Display Session Container.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvNodejs] : (NVIDIA NodeJS.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvPlugin.Watchdog] : (NVIDIA Watchdog Plugin for NvContainer.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvTelemetry] : (NVIDIA Telemetry Client.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvvHci] : (NVIDIA Virtual Host Controller.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_OSC] : (Nvidia Share.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_ShadowPlay] : (NVIDIA ShadowPlay 3.20.1.57.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_ShieldWirelessController] : (NVIDIA SHIELD Wireless Controller Driver.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Update.Core] : (NVIDIA Update Core.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_VirtualAudio.Driver] : (NVIDIA Virtual Audio 4.13.0.0.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{CF7A1CD3-26CF-4295-8AA6-3250D3C37878}] : (MAGIX Speed burnR.-.MAGIX Software GmbH) -> MsiExec.exe /I{CF7A1CD3-26CF-4295-8AA6-3250D3C37878} [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{EECB2736-D013-5AC5-9917-7656712F6931}] : (Java 10.0.2 (64-bit).-.Oracle Corporation) -> MsiExec.exe /X{EECB2736-D013-5AC5-9917-7656712F6931} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\AlterPDF_is1] : (AlterPDF 3.8.-.Alternative PDF Solutions) -> "C:\Program Files (x86)\AlterPDF\unins000.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Anti-Twin 2015-07-30 11.46.50] : (Anti-Twin (Installation 30/07/2015).-.Joerg Rosenthal, Germany) -> "C:\Program Files (x86)\AntiTwin\uninstall.exe" /uninst "UninstallKey=Anti-Twin 2015-07-30 11.46.50" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\AVerMedia A835 USB DVB-T] : (AVerMedia A835 USB DVB-T 8.2.64.64.-.AVerMedia TECHNOLOGIES, Inc.) -> C:\Program Files (x86)\AVerMedia\AVerMedia A835 USB DVB-T\uninst.exe ----------[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Connection Manager] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Finance 2003_is1] : (Finance 2003 version 10.05.-.) -> "C:\Program Files (x86)\SoftChris\Finance 2003\unins000.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Free JPG To PDF Converter_is1] : (Free JPG To PDF Converter 1.0.-.JPG2PDF Developer Team) -> "C:\Program Files (x86)\FreeJPG2PDF\unins000.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Glary Utilities 5] : (Glary Utilities 5.133.-.Glarysoft Ltd) -> C:\Program Files (x86)\Glary Utilities 5\uninst.exe [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\IObitUninstall] : (IObit Uninstaller 9.-.IObit) -> "C:\Program Files (x86)\IObit\IObit Uninstaller\unins000.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Karen's Directory Printer] : (Karen's Directory Printer.-.KarenWare.com) -> C:\Program Files (x86)\Karen's Power Tools\Directory Printer\uninstall.exe [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\League of Legends 4.2.1] : (League of Legends.-.Riot Games) -> msiexec.exe /x {11B73856-A062-4E6B-A80E-A3F380BBAB65} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\MP4Tools_is1] : (MP4Tools v3.7.-.Thüring IT-Consulting) -> "C:\Program Files (x86)\MP4Tools\unins000.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\OBS Studio] : (OBS Studio.-.OBS Project) -> C:\Program Files (x86)\obs-studio\uninstall.exe [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\PDFTK Builder_is1] : (PDFTK Builder 3.10.0.-.) -> "C:\Program Files (x86)\PDFTK Builder\unins000.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\PersoApps Adresses 1.31_is1] : (PersoApps Adresses.-.PersoApps Software) -> "C:\Program Files (x86)\EuroSoft Software Development\PersoApps Adresses\unins000.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\PersoApps Calendrier_is1] : (PersoApps Calendrier.-.PersoApps Software) -> "C:\Program Files (x86)\EuroSoft Software Development\PersoApps Calendrier\unins000.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\proDAD-Vitascene-1.0] : (proDAD Vitascene StarterKit 1.0.-.) -> "C:\Program Files (x86)\proDAD\Vitascene-1.0\uninstall.exe" uninstall spcp PATHVERSION 1.0 MAINNAME Vitascene [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Samsung Easy Printer Manager] : (Samsung Easy Printer Manager.-.Samsung Electronics Co., Ltd.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\VideoProc] : (VideoProc.-.Digiarty, Inc.) -> C:\Program Files (x86)\Digiarty\VideoProc\uninstaller.exe [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\View User Guide] : (Afficher le Mode d’emploi.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WIC] : (.-.) -> ----------[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{10E33ABF-D7FB-4F47-900A-7973854AB45A}] : (Adobe AIR.-.Adobe) -> MsiExec.exe /I{10E33ABF-D7FB-4F47-900A-7973854AB45A} ----------[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{11B73856-A062-4E6B-A80E-A3F380BBAB65}] : (League of Legends.-.Riot Games) -> MsiExec.exe /X{11B73856-A062-4E6B-A80E-A3F380BBAB65} ----------[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{18455581-E099-4BA8-BC6B-F34B2F06600C}] : (Google Toolbar for Internet Explorer.-.Google Inc.) -> MsiExec.exe /I{18455581-E099-4BA8-BC6B-F34B2F06600C} ----------[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{31990087-E845-4714-B8D2-750497D90341}] : (Intel Driver && Support Assistant.-.Intel) -> MsiExec.exe /X{31990087-E845-4714-B8D2-750497D90341} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{39AB2E37-1A55-4292-A5D3-971E9F70D0F8}] : (Firebird SQL Server - MAGIX Edition.-.MAGIX AG) -> MsiExec.exe /X{39AB2E37-1A55-4292-A5D3-971E9F70D0F8} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{4487064C-F31E-4499-A1EF-9B8E809A0358}] : (Adobe Shockwave Player 12.3.-.Adobe, Inc) -> MsiExec.exe /X{4487064C-F31E-4499-A1EF-9B8E809A0358} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{46F044A5-CE8B-4196-984E-5BD6525E361D}] : (Apple Application Support.-.Apple Inc.) -> MsiExec.exe /I{46F044A5-CE8B-4196-984E-5BD6525E361D} ----------[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{5016185F-05AF-455F-AA70-6B6E5D6D4E70}] : (AVerTV 3D.-.AVerMedia Technologies, Inc.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{5C3CDFD0-45B3-48D0-941F-E3F76F343765}] : (Vasco da Gama 7 HDPro.-.MotionStudios) -> MsiExec.exe /I{5C3CDFD0-45B3-48D0-941F-E3F76F343765} ----------[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}] : (Google Update Helper.-.Google LLC) -> MsiExec.exe /I{60EC980A-BDA2-4CB6-A427-B07A5498B4CA} ----------[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{612C34C7-5E90-47D8-9B5C-0F717DD82726}] : (swMSM.-.Adobe Systems, Inc) -> MsiExec.exe /I{612C34C7-5E90-47D8-9B5C-0F717DD82726} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{71149886-0AA3-4F31-81F9-CC90EA0D55EF}_is1] : (SSDFresh 2019.-.Abelssoft) -> "C:\Program Files (x86)\SSDFresh\unins000.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}] : (Apple Software Update.-.Apple Inc.) -> MsiExec.exe /I{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{A61131DC-B92D-4AD8-A925-E2D6D5FE217C}] : (SD Card Formatter.-.SD Association) -> MsiExec.exe /X{A61131DC-B92D-4AD8-A925-E2D6D5FE217C} ----------[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{AC76BA86-0804-1033-1959-001824341201}] : (Adobe Refresh Manager.-.Adobe Systems Incorporated) -> MsiExec.exe /I{AC76BA86-0804-1033-1959-001824341201} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{AC76BA86-7AD7-1036-7B44-AC0F074E4100}] : (Adobe Acrobat Reader DC - Français.-.Adobe Systems Incorporated) -> MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-AC0F074E4100} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{B6B5F07C-88D5-49D3-A1A7-A6D4BC37DCCC}] : (SNS Upload for Easy Document Creator.-.Samsung Electronics Co.,Ltd) -> MsiExec.exe /I{B6B5F07C-88D5-49D3-A1A7-A6D4BC37DCCC} ---------- | Ports ---------- | Installer [HKCR\Installer\Products\0DFDC3C53B540D8449F13E7FF6437356] : Vasco da Gama 7 HDPro -> C:\Windows\Installer\{5C3CDFD0-45B3-48D0-941F-E3F76F343765}\ARPPRODUCTICON.exe [HKCR\Installer\Products\18555481990E8AB4CBB63FB4F26006C0] : Google Toolbar for Internet Explorer [HKCR\Installer\Products\1BCA4F58CD7E6C3C4FDFBB39D62F96E5] : Windows PE x86 x64 wims [HKCR\Installer\Products\1F764691F11C67F458B88521DA8CB349] : MSXML 4.0 SP3 Parser [HKCR\Installer\Products\225289A4819D18E4DA33379C3E0CFB2E] : MAGIX Vidéo deluxe Premium (effets de titres) [HKCR\Installer\Products\28019115A1096D04C9638805E1069EDD] : MAGIX Vidéo deluxe Premium Update -> C:\WINDOWS\Installer\{51191082-901A-40D6-9C36-88501E60E9DD}\ProgramIcon.exe [HKCR\Installer\Products\3146DE594902C054581678AEB81A0DA6] : MAGIX Vidéo deluxe Premium (modèles de films 7) [HKCR\Installer\Products\33640FA901AACE949896722935D143AB] : MAGIX Vidéo deluxe 2014 Premium [HKCR\Installer\Products\350BFA98343AFE64794E5D39DA17486E] : Intel® Trusted Connect Service Client [HKCR\Installer\Products\3DC1A7FCFC625924A86A23053D3C8787] : MAGIX Speed burnR [HKCR\Installer\Products\3F27D17F972168C4FA2E9183610D7B26] : Intel Driver && Support Assistant -> C:\WINDOWS\Installer\{F71D72F3-1279-4C86-AFE2-193816D0B762}\Icon.exe [HKCR\Installer\Products\3F8E9637C7DB51F4CBB7CB733CEC3245] : MAGIX Vidéo deluxe Premium (Éléments de design) [HKCR\Installer\Products\46B5A9879DD95AB419A50FCFA0B1B7EF] : Apple Software Update -> C:\Windows\Installer\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}\Installer.ico [HKCR\Installer\Products\51B28CF3F47DBD837BF6A1637FCAF3A3] : MAGIX Vidéo deluxe Premium (Update Service 5.7.29.73) -> C:\WINDOWS\Installer\{3FC82B15-D74F-38DB-B76F-1A36F7AC3F3A}\ProgramIcon.exe [HKCR\Installer\Products\5A440F64B8EC691489E4B56D25E563D1] : Apple Application Support -> C:\Windows\Installer\{46F044A5-CE8B-4196-984E-5BD6525E361D}\WinInstall.ico [HKCR\Installer\Products\6372BCEE310D5CA59971676517F29613] : Java 10.0.2 (64-bit) -> C:\Program Files\Java\jre-10.0.2\\bin\javaws.exe [HKCR\Installer\Products\654EE3887C761984CB7FDF91E7E0F4D9] : MAGIX Vidéo deluxe Premium [HKCR\Installer\Products\65837B11260AB6E48AE03A3F08BBBA56] : League of Legends -> C:\WINDOWS\Installer\{11B73856-A062-4E6B-A80E-A3F380BBAB65}\lol.launcher_1.exe [HKCR\Installer\Products\68AB67CA408033019195008142432110] : Adobe Refresh Manager -> C:\WINDOWS\Installer\{AC76BA86-0804-1033-1959-001824341201}\ARPPRODUCTICON.exe [HKCR\Installer\Products\68AB67CA7DA76301B744CAF070E41400] : Adobe Acrobat Reader DC - Français -> C:\Windows\Installer\{AC76BA86-7AD7-1036-7B44-AC0F074E4100}\SC_Reader.ico [HKCR\Installer\Products\73E2BA9355A129245A3D79E1F9070D8F] : Firebird SQL Server - MAGIX Edition -> C:\Windows\Installer\{39AB2E37-1A55-4292-A5D3-971E9F70D0F8}\ProgramIcon.exe [HKCR\Installer\Products\78009913548E41748B2D5740799D3014] : Intel Driver && Support Assistant -> C:\WINDOWS\Installer\{31990087-E845-4714-B8D2-750497D90341}\Icon.exe [HKCR\Installer\Products\7A0F3CE2D97C822448FAACE02183D979] : MAGIX Video deluxe 2014 Premium Update -> C:\Windows\Installer\{2EC3F0A7-C79D-4228-84AF-CA0E12389D97}\ProgramIcon.exe [HKCR\Installer\Products\7C43C21609E58D74B9C5F017D78D7262] : swMSM -> C:\Windows\Installer\{612C34C7-5E90-47D8-9B5C-0F717DD82726}\ARPPRODUCTICON.exe [HKCR\Installer\Products\800E61E14D1514646A1DDD8A9E414EF0] : MAGIX Vidéo deluxe Premium (Styles Photoshow Maker 1) [HKCR\Installer\Products\86DA305989161804F975F143D6B7854D] : Intel(R) Rapid Storage Technology [HKCR\Installer\Products\90FAB4A6C5083A541AD712B46A843C66] : MAGIX Vidéo deluxe Premium Update -> C:\WINDOWS\Installer\{6A4BAF09-805C-45A3-A17D-214BA648C366}\ProgramIcon.exe [HKCR\Installer\Products\96D4F191176B3614BB1009B1982AD040] : LibreOffice 6.3.4.2 -> C:\WINDOWS\Installer\{191F4D69-B671-4163-BB01-901B89A20D04}\soffice.ico [HKCR\Installer\Products\9ED4773422184C64DB305FC94A14E028] : File Converter (64 bit) -> C:\WINDOWS\Installer\{43774DE9-8122-46C4-BD03-F59CA4410E82}\icon.ico [HKCR\Installer\Products\A089CE062ADB6BC44A720BA745894BAC] : Google Update Helper [HKCR\Installer\Products\AC96D98F1EE6730EDDB380DCEDB1DEC1] : Windows PE x86 x64 [HKCR\Installer\Products\B0E88C3AD3C02DC4D8F79A0EDC485860] : MAGIX Vidéo deluxe Premium Update -> C:\WINDOWS\Installer\{A3C88E0B-0C3D-4CD2-8D7F-A9E0CD848506}\ProgramIcon.exe [HKCR\Installer\Products\BBB8467237F440B43B25E686A425D657] : MAGIX Vidéo deluxe Premium (Effets de transition) [HKCR\Installer\Products\BCC628A32FF0691479EFD6CD7D93FCE5] : MAGIX Video deluxe 2014 Premium Update -> C:\WINDOWS\Installer\{3A826CCB-0FF2-4196-97FE-6DDCD739CF5E}\ProgramIcon.exe [HKCR\Installer\Products\C4607844E13F99441AFEB9E808A93085] : Adobe Shockwave Player 12.3 -> C:\WINDOWS\Installer\{4487064C-F31E-4499-A1EF-9B8E809A0358}\ARPPRODUCTICON.exe [HKCR\Installer\Products\C70F5B6B5D883D941A7A6A4DCB73CDCC] : SNS Upload for Easy Document Creator [HKCR\Installer\Products\CD13116AD29B8DA49A522E6D5DEF12C7] : SD Card Formatter -> C:\WINDOWS\Installer\{A61131DC-B92D-4AD8-A925-E2D6D5FE217C}\ARPPRODUCTICON.exe [HKCR\Installer\Products\E43F0A07B46539F4DA6DB3EA6C4E0457] : Google Earth Pro -> C:\WINDOWS\Installer\{70A0F34E-564B-4F93-ADD6-3BAEC6E44075}\MainIcon.ico [HKCR\Installer\Products\E8779CFB5679C49C0C282C15F4D8BEB9] : Windows Deployment Tools [HKCR\Installer\Products\F068ABC9734757A449C1E85F952F1D54] : Update for Windows 10 for x64-based Systems (KB4023057) [HKCR\Installer\Products\F0FB6B58B1FEF0F498D26EB87D8959C0] : Intel(R) Computing Improvement Program -> C:\WINDOWS\Installer\{85B6BF0F-EF1B-4F0F-892D-E68BD798950C}\vmp [HKCR\Installer\Products\F5816105FA50F554AA07B6E6D5D6E407] : AVerTV 3D -> C:\Windows\Installer\{5016185F-05AF-455F-AA70-6B6E5D6D4E70}\ARPPRODUCTICON.exe [HKCR\Installer\Products\FBA33E01BF7D74F409A0973758A44BA5] : Adobe AIR ---------- | ADS ---------- | Drives ---------- | MBR 64 bits not supported by MBR.exe, Dump : C:\QuickDiag\MBR.Bin ---------- | 20 LastEventLog svchost (10284,R,98) TILEREPOSITORYS-1-5-18: L’erreur -1023 (0xfffffc01) s’est produite lors de l’ouverture d’un fichier journal C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log. ------------ svchost (5724,R,98) TILEREPOSITORYS-1-5-18: L’erreur -1023 (0xfffffc01) s’est produite lors de l’ouverture d’un fichier journal C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log. ------------ svchost (11552,R,98) TILEREPOSITORYS-1-5-18: L’erreur -1023 (0xfffffc01) s’est produite lors de l’ouverture d’un fichier journal C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log. ------------ svchost (4832,R,98) TILEREPOSITORYS-1-5-18: L’erreur -1023 (0xfffffc01) s’est produite lors de l’ouverture d’un fichier journal C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log. ------------ svchost (4332,R,98) TILEREPOSITORYS-1-5-18: L’erreur -1023 (0xfffffc01) s’est produite lors de l’ouverture d’un fichier journal C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log. ------------ svchost (12940,R,98) TILEREPOSITORYS-1-5-18: L’erreur -1023 (0xfffffc01) s’est produite lors de l’ouverture d’un fichier journal C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log. ------------ svchost (5308,R,98) TILEREPOSITORYS-1-5-18: L’erreur -1023 (0xfffffc01) s’est produite lors de l’ouverture d’un fichier journal C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log. ------------ svchost (13056,R,98) TILEREPOSITORYS-1-5-18: L’erreur -1023 (0xfffffc01) s’est produite lors de l’ouverture d’un fichier journal C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log. ------------ svchost (3860,R,98) TILEREPOSITORYS-1-5-18: L’erreur -1023 (0xfffffc01) s’est produite lors de l’ouverture d’un fichier journal C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log. ------------ svchost (3212,R,98) TILEREPOSITORYS-1-5-18: L’erreur -1023 (0xfffffc01) s’est produite lors de l’ouverture d’un fichier journal C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log. ------------ svchost (388,R,98) TILEREPOSITORYS-1-5-18: L’erreur -1023 (0xfffffc01) s’est produite lors de l’ouverture d’un fichier journal C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log. ------------ svchost (11268,R,98) TILEREPOSITORYS-1-5-18: L’erreur -1023 (0xfffffc01) s’est produite lors de l’ouverture d’un fichier journal C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log. ------------ svchost (2088,R,98) TILEREPOSITORYS-1-5-18: L’erreur -1023 (0xfffffc01) s’est produite lors de l’ouverture d’un fichier journal C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log. ------------ svchost (11932,R,98) TILEREPOSITORYS-1-5-18: L’erreur -1023 (0xfffffc01) s’est produite lors de l’ouverture d’un fichier journal C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log. ------------ svchost (12592,R,98) TILEREPOSITORYS-1-5-18: L’erreur -1023 (0xfffffc01) s’est produite lors de l’ouverture d’un fichier journal C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log. ------------ svchost (6244,R,98) TILEREPOSITORYS-1-5-18: L’erreur -1023 (0xfffffc01) s’est produite lors de l’ouverture d’un fichier journal C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log. ------------ Nom de l’application défaillante IAStorDataMgrSvc.exe, version : 14.8.16.1063, horodatage : 0x58eb8338 Nom du module défaillant : ntdll.dll, version : 10.0.18362.387, horodatage : 0xa4208572 Code d’exception : 0xc0000374 Décalage d’erreur : 0x000df94d ID du processus défaillant : 0x2af8 Heure de début de l’application défaillante : 0x01d5b4ad5dfc8b8d Chemin d’accès de l’application défaillante : C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe Chemin d’accès du module défaillant: C:\WINDOWS\SYSTEM32\ntdll.dll ID de rapport : 5d340837-129f-4ea7-86fa-ff0fd8de3dc1 Nom complet du package défaillant : ID de l’application relative au package défaillant : ------------ Erreur du service de cliché instantané des volumes : erreur lors de l’appel de la routine CoCreateInstance. hr = 0x8007045b, Un arrêt système est en cours. . ------------ Informations du service de cliché instantané de volumes : impossible de démarrer le serveur COM de CLSID {4e14fba2-2e22-11d1-9964-00c04fbbb345} et de nom CEventSystem. [0x8007045b, Un arrêt système est en cours. ] ------------ ----------( EOF)---------- - 7156 | 14:50:08