--------------- QuickDiag | g3n-h@ckm@n | V8.028.22.1 --------------- ----- XP | Vista | 7 | 8 | 8.1 | 10 - 32/64 bits ----- - Start 10/02/2022 22:53:00 Updated 28/01/2022 | 10:00 (GMT) by g3n-h@ckm@n Contact : http://www.sosvirus.net/ Time Zone : (UTC+00:00) Monrovia, Reykjavik [gband (Administrator)] - [DESKTOP-F6GKAHG] (S-1-5-21-3835695913-52790398-83466441-1001) PC : System manufacturer System Product Name x64-based PC System: Microsoft Windows 10 Professionnel - X64 - (10.0.19043) - BuildType: Multiprocessor Free - OSLanguage: 1036 (040c) -> (21H1) System: AutoReboot: True - DebugFilePath: %SystemRoot%\MEMORY.DMP - KernelDumpOnly: False - OverwriteExistingDebugFile: True - WriteDebugInfo: True - WriteToSystemLog: True Boot : Microsoft Windows 10 Professionnel|C:\WINDOWS|\Device\Harddisk0\Partition3 Boot : Normal boot PC: System Product Name - System manufacturer - IdNumber: System Serial Number - UUID: 739E4233-7B8F-5476-F83D-04D9F583B9CC Processor : AMD Ryzen 5 3600 6-Core Processor (AuthenticAMD) - Clock Speed : 3600 - Socket : AM4 - Stauts : OK BIOS : American Megatrends Inc. 2807 - SN : System Serial Number - Status : OK - Version : ALASKA - 1072009 - PrimaryBios : True - CurrentLanguage : fr|FR|iso8859-1 - OtherTargetOS : CoreTemp : ? Celsius ----------| Quick ---------- | SoundDevice NVIDIA High Definition Audio - Status: OK - Manufacturer: NVIDIA - PNPDeviceID: HDAUDIO\FUNC_01&VEN_10DE&DEV_0093&SUBSYS_145837D9&REV_1001\5&11B57491&0&0001 AMD Streaming Audio Device - Status: OK - Manufacturer: AMD - PNPDeviceID: ROOT\AMDSAFD&FUN_01&REV_01\0000 NVIDIA Virtual Audio Device (Wave Extensible) (WDM) - Status: OK - Manufacturer: NVIDIA - PNPDeviceID: ROOT\UNNAMED_DEVICE\0000 Realtek High Definition Audio - Status: OK - Manufacturer: Realtek - PNPDeviceID: HDAUDIO\FUNC_01&VEN_10EC&DEV_0887&SUBSYS_104386C7&REV_1003\5&319E220&0&0001 ---------- | Video NVIDIA GeForce RTX 2060 - Resolution: 1920x1080 - Colors: 4294967296 - RefreshRate: 60 - 32 Bits Per Pixel - DeviceID: VideoController1 - Drivers: C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_31a2adf8c49e7799\nvldumdx.dll,C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_31a2adf8c49e7799\nvldumdx.dll,C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_31a2adf8c49e7799\nvldumdx.dll,C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_31a2adf8c49e7799\nvldumdx.dll - PNPDeviceID: PCI\VEN_10DE&DEV_1F08&SUBSYS_37D91458&REV_A1\4&1FC990D7&0&0019 - AdapterCompatibility: NVIDIA - RAM: -1048576 Inegrated Video Chipset DeviceName: NVIDIA GeForce RTX 2060 - DriverVersion: 30.0.15.1165 - SpecificationVersion: 1025 ---------- | Codecs C:\WINDOWS\system32\MSRLE32.DLL - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 18432 - Manufacturer: Microsoft Corporation - Status: OK C:\WINDOWS\system32\MSYUV.DLL - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 27648 - Manufacturer: Microsoft Corporation - Status: OK C:\WINDOWS\system32\L3CODECA.ACM - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 93184 - Manufacturer: Fraunhofer Institut Integrierte Schaltungen IIS - Status: OK C:\WINDOWS\system32\RTVCVFW64.DLL - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 246272 - Manufacturer: - Status: OK C:\WINDOWS\system32\MSVIDC32.DLL - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 39936 - Manufacturer: Microsoft Corporation - Status: OK C:\WINDOWS\system32\MSG711.ACM - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 25824 - Manufacturer: Microsoft Corporation - Status: OK C:\WINDOWS\system32\MSGSM32.ACM - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 42904 - Manufacturer: Microsoft Corporation - Status: OK C:\WINDOWS\system32\TSBYUV.DLL - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 16896 - Manufacturer: Microsoft Corporation - Status: OK C:\WINDOWS\system32\MSADP32.ACM - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 34600 - Manufacturer: Microsoft Corporation - Status: OK C:\WINDOWS\system32\IMAADP32.ACM - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 37440 - Manufacturer: Microsoft Corporation - Status: OK C:\WINDOWS\system32\IYUV_32.DLL - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 54272 - Manufacturer: Microsoft Corporation - Status: OK ---------- | Memory Pagefile = Total (MB) : 43160 | Free (MB) : 24353 Virtual = Total (MB) : 4194 | Free (MB) : 3882 Physical Memory (MB) -------------------- Total: 24487 Available: 13355 Cached: 9280 Free: 858 System ------ Handles: 114996 Processes: 262 Threads: 3514 ---------- | Drives C:\ -> [Fixed] | [] | Total : 237.85 Go | Free : 68.03 Go -> NTFS (SSD) [SATA] D:\ -> [Fixed] | [MFS] | Total : 238.47 Go | Free : 13.59 Go -> NTFS (SSD) [SATA] E:\ -> [Fixed] | [Nouveau nom] | Total : 931.51 Go | Free : 74.14 Go -> NTFS [SATA] Drive: 0 Cylinders: 31130 Tracks per Cylinder: 255 Sectors per Track: 63 Bytes per Sector: 512 Total Space: 256060514304 bytes Drive: 1 Cylinders: 121601 Tracks per Cylinder: 255 Sectors per Track: 63 Bytes per Sector: 512 Total Space: 1000203804160 bytes Drive: 2 Cylinders: 31130 Tracks per Cylinder: 255 Sectors per Track: 63 Bytes per Sector: 512 Total Space: 256060514304 bytes ---------- | Windows updates - Activation - License W.A.T : :) Test 1 : Possible Fixed Windows Volume License ---------- | Browsers IE : 11.0.19041.1202 (© Microsoft Corporation. Tous droits réservés.) Default : "C:\Program Files\Internet Explorer\iexplore.exe" ---------- | FlashPlayer ---------- | Security AV : Windows Defender Enabled AS : FW : WINDOWS Firewall WMI : OK WU: Windows Update Service [Manual(3)] = stopped AS: Windows Defender [Auto(2)] = Running WMI: Windows Management Instrumentation [Auto(2)] = Running ---------- | Running processes 532 | [Owner : Système | Parent : 4(System) | ?????] - (.Microsoft Corporation - Gestionnaire de sessions Windows.) - (10.0.19041.964) = C:\Windows\System32\smss.exe [29/06/2021 13:10:58] 724 | [Owner : Système | Parent : 708(svchost.exe) | ?????] - (.Microsoft Corporation - Processus d’exécution client-serveur.) - (10.0.19041.546) = C:\Windows\System32\csrss.exe [29/06/2021 13:10:58] 816 | [Owner : Système | Parent : 708(svchost.exe) | ?????] - (.Microsoft Corporation - Application de démarrage de Windows.) - (10.0.19041.1202) = C:\Windows\System32\wininit.exe [17/09/2021 02:24:39] 888 | [Owner : Système | Parent : 816(wininit.exe) | ?????] - (.Microsoft Corporation - Applications Services et Contrôleur.) - (10.0.19041.928) = C:\Windows\System32\services.exe [29/06/2021 13:10:58] 908 | [Owner : Système | Parent : 816(wininit.exe) | 22.13 Mo] - (.Microsoft Corporation - Local Security Authority Process.) - (10.0.19041.1266) = C:\Windows\System32\lsass.exe [08/10/2021 21:32:06] 708 | [Owner : Système | Parent : 888(services.exe) | 29.55 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.19041.546) = C:\Windows\System32\svchost.exe [29/06/2021 13:10:56] 1020 | [Owner : UMFD-0 | Parent : 816(wininit.exe) | 2.32 Mo] - (.Microsoft Corporation - Usermode Font Driver Host.) - (10.0.19041.1387) = C:\Windows\System32\fontdrvhost.exe [18/12/2021 11:59:26] 1124 | [Owner : SERVICE RÉSEAU | Parent : 888(services.exe) | 17.43 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.19041.546) = C:\Windows\System32\svchost.exe [29/06/2021 13:10:56] 1172 | [Owner : Système | Parent : 888(services.exe) | 7.96 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.19041.546) = C:\Windows\System32\svchost.exe [29/06/2021 13:10:56] 1356 | [Owner : Système | Parent : 888(services.exe) | 8.94 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.19041.546) = C:\Windows\System32\svchost.exe [29/06/2021 13:10:56] 1404 | [Owner : Système | Parent : 888(services.exe) | 5.15 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.19041.546) = C:\Windows\System32\svchost.exe [29/06/2021 13:10:56] 1412 | [Owner : Système | Parent : 888(services.exe) | 13.8 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.19041.546) = C:\Windows\System32\svchost.exe [29/06/2021 13:10:56] 1480 | [Owner : Système | Parent : 888(services.exe) | 13.13 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.19041.546) = C:\Windows\System32\svchost.exe [29/06/2021 13:10:56] 1616 | [Owner : Système | Parent : 888(services.exe) | 9.98 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.19041.546) = C:\Windows\System32\svchost.exe [29/06/2021 13:10:56] 1624 | [Owner : SERVICE LOCAL | Parent : 888(services.exe) | 10.7 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.19041.546) = C:\Windows\System32\svchost.exe [29/06/2021 13:10:56] 1632 | [Owner : SERVICE LOCAL | Parent : 888(services.exe) | 17.94 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.19041.546) = C:\Windows\System32\svchost.exe [29/06/2021 13:10:56] 1648 | [Owner : SERVICE LOCAL | Parent : 888(services.exe) | 4.86 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.19041.546) = C:\Windows\System32\svchost.exe [29/06/2021 13:10:56] 1800 | [Owner : Système | Parent : 888(services.exe) | 19.72 Mo] - (.NVIDIA Corporation - NVIDIA Container.) - (1.35.3033.8148) = C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_31a2adf8c49e7799\Display.NvContainer\NVDisplay.Container.exe [09/02/2022 23:56:01] 1824 | [Owner : SERVICE LOCAL | Parent : 888(services.exe) | 8.37 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.19041.546) = C:\Windows\System32\svchost.exe [29/06/2021 13:10:56] 1868 | [Owner : SERVICE LOCAL | Parent : 888(services.exe) | 6.24 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.19041.546) = C:\Windows\System32\svchost.exe [29/06/2021 13:10:56] 1972 | [Owner : SERVICE RÉSEAU | Parent : 888(services.exe) | 11.63 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.19041.546) = C:\Windows\System32\svchost.exe [29/06/2021 13:10:56] 1992 | [Owner : Système | Parent : 888(services.exe) | 5.76 Mo] - (.Advanced Micro Devices, Inc. - AMD Crash Defender Service.) - (21.20.0.103) = C:\Windows\System32\amdfendrsr.exe [22/06/2021 19:29:28] 1576 | [Owner : SERVICE LOCAL | Parent : 888(services.exe) | 8.21 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.19041.546) = C:\Windows\System32\svchost.exe [29/06/2021 13:10:56] 2064 | [Owner : SERVICE LOCAL | Parent : 888(services.exe) | 5.93 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.19041.546) = C:\Windows\System32\svchost.exe [29/06/2021 13:10:56] 2164 | [Owner : Système | Parent : 888(services.exe) | 4.41 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.19041.546) = C:\Windows\System32\svchost.exe [29/06/2021 13:10:56] 2172 | [Owner : Système | Parent : 888(services.exe) | 13.22 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.19041.546) = C:\Windows\System32\svchost.exe [29/06/2021 13:10:56] 2180 | [Owner : SERVICE LOCAL | Parent : 888(services.exe) | 6.63 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.19041.546) = C:\Windows\System32\svchost.exe [29/06/2021 13:10:56] 2264 | [Owner : Système | Parent : 888(services.exe) | 7.58 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.19041.546) = C:\Windows\System32\svchost.exe [29/06/2021 13:10:56] 2336 | [Owner : Système | Parent : 888(services.exe) | 7.76 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.19041.546) = C:\Windows\System32\svchost.exe [29/06/2021 13:10:56] 2344 | [Owner : SERVICE LOCAL | Parent : 888(services.exe) | 6.77 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.19041.546) = C:\Windows\System32\svchost.exe [29/06/2021 13:10:56] 2544 | [Owner : Système | Parent : 888(services.exe) | 18.55 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.19041.546) = C:\Windows\System32\svchost.exe [29/06/2021 13:10:56] 2588 | [Owner : SERVICE LOCAL | Parent : 888(services.exe) | 56.54 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.19041.546) = C:\Windows\System32\svchost.exe [29/06/2021 13:10:56] 2696 | [Owner : SERVICE LOCAL | Parent : 888(services.exe) | 5.17 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.19041.546) = C:\Windows\System32\svchost.exe [29/06/2021 13:10:56] 2704 | [Owner : SERVICE RÉSEAU | Parent : 888(services.exe) | 8.25 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.19041.546) = C:\Windows\System32\svchost.exe [29/06/2021 13:10:56] 2712 | [Owner : SERVICE LOCAL | Parent : 888(services.exe) | 8 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.19041.546) = C:\Windows\System32\svchost.exe [29/06/2021 13:10:56] 2864 | [Owner : Système | Parent : 888(services.exe) | 23.17 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.19041.546) = C:\Windows\System32\svchost.exe [29/06/2021 13:10:56] 2908 | [Owner : SERVICE LOCAL | Parent : 888(services.exe) | 6.35 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.19041.546) = C:\Windows\System32\svchost.exe [29/06/2021 13:10:56] 2972 | [Owner : Système | Parent : 888(services.exe) | 13.24 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.19041.546) = C:\Windows\System32\svchost.exe [29/06/2021 13:10:56] 2232 | [Owner : Système | Parent : 888(services.exe) | 11.22 Mo] - (.Microsoft Corporation - Application sous-système spouleur.) - (10.0.19041.1415) = C:\Windows\System32\spoolsv.exe [18/12/2021 11:59:14] 3092 | [Owner : SERVICE LOCAL | Parent : 888(services.exe) | 18.74 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.19041.546) = C:\Windows\System32\svchost.exe [29/06/2021 13:10:56] 3168 | [Owner : SERVICE RÉSEAU | Parent : 888(services.exe) | 6.32 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.19041.546) = C:\Windows\System32\svchost.exe [29/06/2021 13:10:56] 3524 | [Owner : Système | Parent : 888(services.exe) | 5.3 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.19041.546) = C:\Windows\System32\svchost.exe [29/06/2021 13:10:56] 3532 | [Owner : Système | Parent : 888(services.exe) | 30.1 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.19041.546) = C:\Windows\System32\svchost.exe [29/06/2021 13:10:56] 3540 | [Owner : SERVICE LOCAL | Parent : 888(services.exe) | 35.98 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.19041.546) = C:\Windows\System32\svchost.exe [29/06/2021 13:10:56] 3548 | [Owner : SERVICE RÉSEAU | Parent : 888(services.exe) | 13.64 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.19041.546) = C:\Windows\System32\svchost.exe [29/06/2021 13:10:56] 3564 | [Owner : SERVICE LOCAL | Parent : 888(services.exe) | 6.87 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.19041.546) = C:\Windows\System32\svchost.exe [29/06/2021 13:10:56] 3556 | [Owner : Système | Parent : 888(services.exe) | 9.37 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.19041.546) = C:\Windows\System32\svchost.exe [29/06/2021 13:10:56] 3572 | [Owner : SERVICE LOCAL | Parent : 888(services.exe) | 4.72 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.19041.546) = C:\Windows\System32\svchost.exe [29/06/2021 13:10:56] 3580 | [Owner : Système | Parent : 888(services.exe) | 4.75 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.19041.546) = C:\Windows\System32\svchost.exe [29/06/2021 13:10:56] 3592 | [Owner : Système | Parent : 888(services.exe) | 19.78 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.19041.546) = C:\Windows\System32\svchost.exe [29/06/2021 13:10:56] 3668 | [Owner : Système | Parent : 888(services.exe) | 6.57 Mo] - (.Microsoft Corporation - SQL Server VSS Writer - 64 Bit.) - (2014.120.2000.8) = C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [21/02/2014 05:25:30] 3680 | [Owner : Système | Parent : 888(services.exe) | 37.03 Mo] - (.NVIDIA Corporation - NVIDIA Container.) - (1.35.3033.8148) = C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [10/07/2021 17:44:43] 3704 | [Owner : Système | Parent : 888(services.exe) | 5.64 Mo] - (.Thrustmaster® - Thrustmaster® Hotas Service.) - (1.2.5.0) = C:\Program Files\Thrustmaster\TM Flight Series\drivers\amd64\tmHInstall.exe [14/01/2022 17:02:18] 3916 | [Owner : SERVICE LOCAL | Parent : 888(services.exe) | 4.76 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.19041.546) = C:\Windows\System32\svchost.exe [29/06/2021 13:10:56] 3944 | [Owner : Système | Parent : 888(services.exe) | 7.61 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.19041.546) = C:\Windows\System32\svchost.exe [29/06/2021 13:10:56] 3992 | [Owner : SERVICE LOCAL | Parent : 3524(svchost.exe) | 15.16 Mo] - (.Microsoft Corporation - Device Association Framework Provider Host.) - (10.0.19041.1) = C:\Windows\System32\dasHost.exe [07/12/2019 09:08:37] 4108 | [Owner : Système | Parent : 888(services.exe) | 10.7 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.19041.546) = C:\Windows\System32\svchost.exe [29/06/2021 13:10:56] 4620 | [Owner : SERVICE LOCAL | Parent : 888(services.exe) | 5.42 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.19041.546) = C:\Windows\System32\svchost.exe [29/06/2021 13:10:56] 4624 | [Owner : SERVICE LOCAL | Parent : 888(services.exe) | 7.13 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.19041.546) = C:\Windows\System32\svchost.exe [29/06/2021 13:10:56] 4736 | [Owner : SERVICE LOCAL | Parent : 888(services.exe) | 6.35 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.19041.546) = C:\Windows\System32\svchost.exe [29/06/2021 13:10:56] 4812 | [Owner : SERVICE LOCAL | Parent : 888(services.exe) | 8.14 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.19041.546) = C:\Windows\System32\svchost.exe [29/06/2021 13:10:56] 5092 | [Owner : SERVICE LOCAL | Parent : 888(services.exe) | 7.05 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.19041.546) = C:\Windows\System32\svchost.exe [29/06/2021 13:10:56] 5488 | [Owner : SERVICE LOCAL | Parent : 888(services.exe) | 8.34 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.19041.546) = C:\Windows\System32\svchost.exe [29/06/2021 13:10:56] 4840 | [Owner : SERVICE LOCAL | Parent : 888(services.exe) | 20.52 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.19041.546) = C:\Windows\System32\svchost.exe [29/06/2021 13:10:56] 6296 | [Owner : Système | Parent : 888(services.exe) | 17.31 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.19041.546) = C:\Windows\System32\svchost.exe [29/06/2021 13:10:56] 6716 | [Owner : SERVICE LOCAL | Parent : 888(services.exe) | 17.89 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.19041.546) = C:\Windows\System32\svchost.exe [29/06/2021 13:10:56] 7028 | [Owner : Système | Parent : 6992() | 1.14 Mo] - (.Google LLC - Google Crash Handler.) - (1.3.36.121) = C:\Program Files (x86)\Google\Update\1.3.36.122\GoogleCrashHandler.exe [20/01/2022 23:30:49] 7036 | [Owner : Système | Parent : 6992() | 1.08 Mo] - (.Google LLC - Google Crash Handler.) - (1.3.36.121) = C:\Program Files (x86)\Google\Update\1.3.36.122\GoogleCrashHandler64.exe [20/01/2022 23:30:49] 6108 | [Owner : Système | Parent : 888(services.exe) | ?????] - (.Microsoft Corporation - Service Broker du moniteur d'exécution System Guard.) - (10.0.19041.546) = C:\Windows\System32\SgrmBroker.exe [29/06/2021 13:11:18] 5724 | [Owner : Système | Parent : 888(services.exe) | 10.25 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.19041.546) = C:\Windows\System32\svchost.exe [29/06/2021 13:10:56] 1656 | [Owner : Système | Parent : 888(services.exe) | 19.55 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.19041.546) = C:\Windows\System32\svchost.exe [29/06/2021 13:10:56] 2524 | [Owner : SERVICE LOCAL | Parent : 888(services.exe) | ?????] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.19041.546) = C:\Windows\System32\svchost.exe [29/06/2021 13:10:56] 2276 | [Owner : Système | Parent : 888(services.exe) | 49.15 Mo] - (.Microsoft Corporation - Indexeur Microsoft Windows Search.) - (7.0.19041.1387) = C:\Windows\System32\SearchIndexer.exe [18/12/2021 11:59:20] 5788 | [Owner : Système | Parent : 888(services.exe) | 6.8 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.19041.546) = C:\Windows\System32\svchost.exe [29/06/2021 13:10:56] 9928 | [Owner : Système | Parent : 888(services.exe) | ?????] - (.Microsoft Corporation - Windows Security Health Service.) - (4.18.1907.16384) = C:\Windows\System32\SecurityHealthService.exe [08/10/2021 21:32:05] 7112 | [Owner : Système | Parent : 888(services.exe) | 8.27 Mo] - (.NVIDIA -.) - (1.2.4923.0) = C:\Program Files\NVIDIA Corporation\FrameViewSDK\nvfvsdksvc_x64.exe [10/07/2021 17:44:51] 14280 | [Owner : Système | Parent : 888(services.exe) | 9.92 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.19041.546) = C:\Windows\System32\svchost.exe [29/06/2021 13:10:56] 13860 | [Owner : Système | Parent : 888(services.exe) | 11.34 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.19041.546) = C:\Windows\System32\svchost.exe [29/06/2021 13:10:56] 14500 | [Owner : SERVICE LOCAL | Parent : 888(services.exe) | 10.48 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.19041.546) = C:\Windows\System32\svchost.exe [29/06/2021 13:10:56] 14940 | [Owner : Système | Parent : 888(services.exe) | 11.4 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.19041.546) = C:\Windows\System32\svchost.exe [29/06/2021 13:10:56] 6172 | [Owner : Système | Parent : 888(services.exe) | ?????] - (.Microsoft Corporation - Antimalware Service Executable.) - (4.18.2201.10) = C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2201.10-0\MsMpEng.exe [10/02/2022 12:00:58] 3788 | [Owner : SERVICE LOCAL | Parent : 888(services.exe) | ?????] - (.Microsoft Corporation - Microsoft Network Realtime Inspection Service.) - (4.18.2201.10) = C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2201.10-0\NisSrv.exe [10/02/2022 12:00:58] 8876 | [Owner : Système | Parent : 6172(MsMpEng.exe) | ?????] - (.Microsoft Corporation - Microsoft Malware Protection Copy Accelerator Utility.) - (4.18.2201.10) = C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2201.10-0\MpCopyAccelerator.exe [10/02/2022 12:00:58] 13512 | [Owner : Système | Parent : 888(services.exe) | 18.05 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.19041.546) = C:\Windows\System32\svchost.exe [29/06/2021 13:10:56] 11736 | [Owner : Système | Parent : 888(services.exe) | 11.78 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.19041.546) = C:\Windows\System32\svchost.exe [29/06/2021 13:10:56] 11676 | [Owner : Système | Parent : 888(services.exe) | 6.2 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.19041.546) = C:\Windows\System32\svchost.exe [29/06/2021 13:10:56] 7344 | [Owner : Système | Parent : 11928() | ?????] - (.Microsoft Corporation - Processus d’exécution client-serveur.) - (10.0.19041.546) = C:\Windows\System32\csrss.exe [29/06/2021 13:10:58] 19784 | [Owner : Système | Parent : 11928() | 11.09 Mo] - (.Microsoft Corporation - Application d’ouverture de session Windows.) - (10.0.19041.1387) = C:\Windows\System32\winlogon.exe [18/12/2021 11:59:26] 16592 | [Owner : UMFD-3 | Parent : 19784(winlogon.exe) | 15.15 Mo] - (.Microsoft Corporation - Usermode Font Driver Host.) - (10.0.19041.1387) = C:\Windows\System32\fontdrvhost.exe [18/12/2021 11:59:26] 6860 | [Owner : DWM-3 | Parent : 19784(winlogon.exe) | 74.52 Mo] - (.Microsoft Corporation - Gestionnaire de fenêtres du Bureau.) - (10.0.19041.746) = C:\Windows\System32\dwm.exe [29/06/2021 13:10:55] 15792 | [Owner : Système | Parent : 1800(NVDisplay.Container.exe) | 53.83 Mo] - (.NVIDIA Corporation - NVIDIA Container.) - (1.35.3033.8148) = C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_31a2adf8c49e7799\Display.NvContainer\NVDisplay.Container.exe [09/02/2022 23:56:01] 12024 | [Owner : SERVICE LOCAL | Parent : 888(services.exe) | 5.92 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.19041.546) = C:\Windows\System32\svchost.exe [29/06/2021 13:10:56] 5340 | [Owner : gband | Parent : 3680(nvcontainer.exe) | 31.14 Mo] - (.NVIDIA Corporation - NVIDIA Container.) - (1.35.3033.8148) = C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [10/07/2021 17:44:43] 7260 | [Owner : gband | Parent : 3680(nvcontainer.exe) | 61.16 Mo] - (.NVIDIA Corporation - NVIDIA Container.) - (1.35.3033.8148) = C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [10/07/2021 17:44:43] 14540 | [Owner : gband | Parent : 1616(svchost.exe) | 30.76 Mo] - (.Microsoft Corporation - Shell Infrastructure Host.) - (10.0.19041.746) = C:\Windows\System32\sihost.exe [29/06/2021 13:10:49] 14920 | [Owner : gband | Parent : 888(services.exe) | 24.14 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.19041.546) = C:\Windows\System32\svchost.exe [29/06/2021 13:10:56] 8332 | [Owner : gband | Parent : 888(services.exe) | 38.93 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.19041.546) = C:\Windows\System32\svchost.exe [29/06/2021 13:10:56] 3384 | [Owner : Système | Parent : 7112(nvfvsdksvc_x64.exe) | 12.12 Mo] - (.NVIDIA - PresentMon.) - (1.2.4923.0) = C:\Program Files\NVIDIA Corporation\FrameViewSDK\bin\PresentMon_x64.exe [10/07/2021 17:44:50] 11448 | [Owner : Système | Parent : 3384(PresentMon_x64.exe) | 10.45 Mo] - (.Microsoft Corporation - Hôte de la fenêtre de la console.) - (10.0.19041.1320) = C:\Windows\System32\conhost.exe [11/11/2021 23:33:48] 15160 | [Owner : gband | Parent : 7112(nvfvsdksvc_x64.exe) | 13.73 Mo] - (.NVIDIA - PresentMon.) - (1.2.4923.0) = C:\Program Files\NVIDIA Corporation\FrameViewSDK\bin\PresentMon_x64.exe [10/07/2021 17:44:50] 15120 | [Owner : gband | Parent : 1412(svchost.exe) | 22.66 Mo] - (.Microsoft Corporation - Processus hôte pour Tâches Windows.) - (10.0.19041.906) = C:\Windows\System32\taskhostw.exe [29/06/2021 13:11:01] 5944 | [Owner : gband | Parent : 15160(PresentMon_x64.exe) | 14.12 Mo] - (.Microsoft Corporation - Hôte de la fenêtre de la console.) - (10.0.19041.1320) = C:\Windows\System32\conhost.exe [11/11/2021 23:33:48] 10208 | [Owner : gband | Parent : 7112(nvfvsdksvc_x64.exe) | 10.13 Mo] - (.NVIDIA - NVRLA.) - (1.2.4923.0) = C:\Program Files\NVIDIA Corporation\FrameViewSDK\bin\nvrla.exe [10/07/2021 17:44:50] 6288 | [Owner : gband | Parent : 13276() | 167.37 Mo] - (.Microsoft Corporation - Explorateur Windows.) - (10.0.19041.1415) = C:\Windows\explorer.exe [18/12/2021 11:59:14] 19492 | [Owner : gband | Parent : 5788(svchost.exe) | 21.16 Mo] - (.Microsoft Corporation - Chargeur CTF.) - (10.0.19041.1) = C:\Windows\System32\ctfmon.exe [07/12/2019 09:09:00] 13696 | [Owner : Système | Parent : 888(services.exe) | 8.46 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.19041.546) = C:\Windows\System32\svchost.exe [29/06/2021 13:10:56] 16576 | [Owner : gband | Parent : 888(services.exe) | 17.96 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.19041.546) = C:\Windows\System32\svchost.exe [29/06/2021 13:10:56] 15172 | [Owner : gband | Parent : 1412(svchost.exe) | 3.95 Mo] - (.- RTSS.) - (7.3.3.26004) = C:\Program Files (x86)\RivaTuner Statistics Server\RTSS.exe [03/12/2021 13:34:04] 1584 | [Owner : gband | Parent : 2764(chrome.exe) | 17.12 Mo] - (.Node.js - NVIDIA Web Helper Service.) - (11.13.0.0) = C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe [10/07/2021 17:44:48] 8972 | [Owner : gband | Parent : 1584(NVIDIA Web Helper.exe) | 1.4 Mo] - (.Microsoft Corporation - Hôte de la fenêtre de la console.) - (10.0.19041.1320) = C:\Windows\System32\conhost.exe [11/11/2021 23:33:48] 10552 | [Owner : gband | Parent : 708(svchost.exe) | 78.08 Mo] - (.-.) - (0.0.0.0) = C:\Windows\SystemApps\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\StartMenuExperienceHost.exe [29/06/2021 13:10:52] 1612 | [Owner : gband | Parent : 708(svchost.exe) | 26.1 Mo] - (.Microsoft Corporation - Runtime Broker.) - (10.0.19041.746) = C:\Windows\System32\RuntimeBroker.exe [29/06/2021 13:10:43] 5084 | [Owner : gband | Parent : 708(svchost.exe) | 159.03 Mo] - (.Microsoft Corporation - Search application.) - (10.0.19041.1387) = C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe [18/12/2021 11:59:43] 9916 | [Owner : gband | Parent : 708(svchost.exe) | 30.9 Mo] - (.Microsoft Corporation - Runtime Broker.) - (10.0.19041.746) = C:\Windows\System32\RuntimeBroker.exe [29/06/2021 13:10:43] 2792 | [Owner : gband | Parent : 15172(RTSS.exe) | 0.93 Mo] - (.- RTSS Encoder Server.) - (2.3.0.0) = C:\Program Files (x86)\RivaTuner Statistics Server\EncoderServer.exe [03/12/2021 13:34:06] 14992 | [Owner : gband | Parent : 15172(RTSS.exe) | 1.08 Mo] - (.- RTSS Hooks Loader.) - (1.1.0.0) = C:\Program Files (x86)\RivaTuner Statistics Server\RTSSHooksLoader64.exe [03/12/2021 13:34:06] 18812 | [Owner : gband | Parent : 708(svchost.exe) | 3.27 Mo] - (.Microsoft Corporation -.) - (1.21121.256.0) = C:\Program Files\WindowsApps\Microsoft.YourPhone_1.21121.256.0_x64__8wekyb3d8bbwe\YourPhone.exe [07/02/2022 23:20:33] 18080 | [Owner : gband | Parent : 708(svchost.exe) | 5.86 Mo] - (.Microsoft Corporation - Host Process for Setting Synchronization.) - (10.0.19041.1320) = C:\Windows\System32\SettingSyncHost.exe [11/11/2021 23:33:51] 11116 | [Owner : gband | Parent : 708(svchost.exe) | 55.79 Mo] - (.Microsoft Corporation - LockApp.exe.) - (10.0.19041.1320) = C:\Windows\SystemApps\Microsoft.LockApp_cw5n1h2txyewy\LockApp.exe [11/11/2021 23:33:50] 4788 | [Owner : gband | Parent : 708(svchost.exe) | 33.04 Mo] - (.Microsoft Corporation - Runtime Broker.) - (10.0.19041.746) = C:\Windows\System32\RuntimeBroker.exe [29/06/2021 13:10:43] 8200 | [Owner : gband | Parent : 708(svchost.exe) | 19.81 Mo] - (.Microsoft Corporation - Runtime Broker.) - (10.0.19041.746) = C:\Windows\System32\RuntimeBroker.exe [29/06/2021 13:10:43] 9380 | [Owner : gband | Parent : 3680(nvcontainer.exe) | 14.22 Mo] - (.NVIDIA Corporation - NVIDIA ShadowPlay Helper.) - (3.25.0.84) = C:\Program Files\NVIDIA Corporation\ShadowPlay\nvsphelper64.exe [10/07/2021 17:44:51] 1692 | [Owner : gband | Parent : 5340(nvcontainer.exe) | 91.5 Mo] - (.NVIDIA Corporation - NVIDIA Share.) - (73.3683.1933.5) = C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe [10/07/2021 17:44:50] 5444 | [Owner : gband | Parent : 1692(NVIDIA Share.exe) | 60.89 Mo] - (.NVIDIA Corporation - NVIDIA Share.) - (73.3683.1933.5) = C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe [10/07/2021 17:44:50] 5708 | [Owner : gband | Parent : 1692(NVIDIA Share.exe) | 91.98 Mo] - (.NVIDIA Corporation - NVIDIA Share.) - (73.3683.1933.5) = C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe [10/07/2021 17:44:50] 8928 | [Owner : gband | Parent : 708(svchost.exe) | 50.25 Mo] - (.Microsoft Corporation -.) - (2001.22012.0.3920) = C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\InputApp\TextInputHost.exe [08/10/2021 21:32:23] 20424 | [Owner : gband | Parent : 708(svchost.exe) | 23.52 Mo] - (.Microsoft Corporation - Runtime Broker.) - (10.0.19041.746) = C:\Windows\System32\RuntimeBroker.exe [29/06/2021 13:10:43] 17448 | [Owner : gband | Parent : 6288(explorer.exe) | 14.74 Mo] - (.Microsoft Corporation - Windows Security notification icon.) - (10.0.19041.1) = C:\Windows\System32\SecurityHealthSystray.exe [07/12/2019 09:08:41] 5800 | [Owner : gband | Parent : 6288(explorer.exe) | 72.36 Mo] - (.Microsoft Corporation - Microsoft OneDrive.) - (22.2.103.4) = C:\Users\gband\AppData\Local\Microsoft\OneDrive\OneDrive.exe [29/06/2021 13:56:33] 18284 | [Owner : gband | Parent : 6288(explorer.exe) | 83.3 Mo] - (.Valve Corporation - Steam.) - (7.0.91.85) = C:\Program Files (x86)\Steam\steam.exe [04/02/2021 23:13:58] 16220 | [Owner : gband | Parent : 6288(explorer.exe) | 41.22 Mo] - (.Navigraph - Navigraph Simlink.) - (1.1.25.120) = C:\Program Files\Navigraph\Simlink\NavigraphSimlink.exe [29/06/2021 16:07:07] 17744 | [Owner : gband | Parent : 18284(steam.exe) | 71.39 Mo] - (.Valve Corporation - Steam Client WebHelper.) - (7.0.91.85) = C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe [29/06/2021 14:05:51] 10732 | [Owner : Système | Parent : 888(services.exe) | 12.44 Mo] - (.Valve Corporation - Steam Client Service.) - (7.0.91.85) = C:\Program Files (x86)\Common Files\Steam\steamservice.exe [29/06/2021 14:04:55] 17956 | [Owner : gband | Parent : 17744(steamwebhelper.exe) | 15.16 Mo] - (.Valve Corporation - Steam Client WebHelper.) - (7.0.91.85) = C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe [29/06/2021 14:05:51] 7748 | [Owner : gband | Parent : 17744(steamwebhelper.exe) | 83.16 Mo] - (.Valve Corporation - Steam Client WebHelper.) - (7.0.91.85) = C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe [29/06/2021 14:05:51] 15356 | [Owner : gband | Parent : 17744(steamwebhelper.exe) | 28.41 Mo] - (.Valve Corporation - Steam Client WebHelper.) - (7.0.91.85) = C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe [29/06/2021 14:05:51] 6948 | [Owner : gband | Parent : 7372() | 78.38 Mo] - (.Discord Inc. - Discord.) - (1.0.9003.0) = C:\Users\gband\AppData\Local\Discord\app-1.0.9003\Discord.exe [22/09/2021 22:34:55] 16816 | [Owner : gband | Parent : 6288(explorer.exe) | 66.12 Mo] - (.SimBrief - SimBrief Downloader.) - (1.6.3.0) = C:\Users\gband\AppData\Local\Programs\SimBrief Downloader\SimBrief Downloader.exe [21/10/2021 16:10:04] 18040 | [Owner : gband | Parent : 16816(SimBrief Downloader.exe) | 103.78 Mo] - (.SimBrief - SimBrief Downloader.) - (1.6.3.0) = C:\Users\gband\AppData\Local\Programs\SimBrief Downloader\SimBrief Downloader.exe [21/10/2021 16:10:04] 17116 | [Owner : gband | Parent : 6948(Discord.exe) | 26.51 Mo] - (.Discord Inc. - Discord.) - (1.0.9003.0) = C:\Users\gband\AppData\Local\Discord\app-1.0.9003\Discord.exe [22/09/2021 22:34:55] 20176 | [Owner : gband | Parent : 6948(Discord.exe) | 90.21 Mo] - (.Discord Inc. - Discord.) - (1.0.9003.0) = C:\Users\gband\AppData\Local\Discord\app-1.0.9003\Discord.exe [22/09/2021 22:34:55] 16356 | [Owner : gband | Parent : 6948(Discord.exe) | 38.67 Mo] - (.Discord Inc. - Discord.) - (1.0.9003.0) = C:\Users\gband\AppData\Local\Discord\app-1.0.9003\Discord.exe [22/09/2021 22:34:55] 10164 | [Owner : gband | Parent : 6288(explorer.exe) | 59.47 Mo] - (.BitTorrent Inc. - µTorrent Web.) - (1.2.7.4186) = C:\Users\gband\AppData\Roaming\uTorrent Web\utweb.exe [30/11/2021 22:43:38] 12572 | [Owner : gband | Parent : 16816(SimBrief Downloader.exe) | 41.66 Mo] - (.SimBrief - SimBrief Downloader.) - (1.6.3.0) = C:\Users\gband\AppData\Local\Programs\SimBrief Downloader\SimBrief Downloader.exe [21/10/2021 16:10:04] 12172 | [Owner : gband | Parent : 16816(SimBrief Downloader.exe) | 79.15 Mo] - (.SimBrief - SimBrief Downloader.) - (1.6.3.0) = C:\Users\gband\AppData\Local\Programs\SimBrief Downloader\SimBrief Downloader.exe [21/10/2021 16:10:04] 17136 | [Owner : gband | Parent : 10164(utweb.exe) | 15.44 Mo] - (.BitTorrent Inc. - µTorrent Helper.) - (2.1.3.1957) = C:\Users\gband\AppData\Roaming\uTorrent Web\helper\helper.exe [11/10/2021 21:11:01] 11644 | [Owner : gband | Parent : 6948(Discord.exe) | 188.96 Mo] - (.Discord Inc. - Discord.) - (1.0.9003.0) = C:\Users\gband\AppData\Local\Discord\app-1.0.9003\Discord.exe [22/09/2021 22:34:55] 11412 | [Owner : gband | Parent : 6288(explorer.exe) | 126.22 Mo] - (.Navigraph - Navigraph Navdata Center.) - (1.0.5.207) = C:\Users\gband\AppData\Local\Programs\Navigraph Navdata Center\Navigraph Navdata Center.exe [28/01/2022 02:24:28] 17880 | [Owner : gband | Parent : 11412(Navigraph Navdata Center.exe) | 77.76 Mo] - (.Navigraph - Navigraph Navdata Center.) - (1.0.5.207) = C:\Users\gband\AppData\Local\Programs\Navigraph Navdata Center\Navigraph Navdata Center.exe [28/01/2022 02:24:28] 19976 | [Owner : gband | Parent : 11412(Navigraph Navdata Center.exe) | 42.22 Mo] - (.Navigraph - Navigraph Navdata Center.) - (1.0.5.207) = C:\Users\gband\AppData\Local\Programs\Navigraph Navdata Center\Navigraph Navdata Center.exe [28/01/2022 02:24:28] 3724 | [Owner : gband | Parent : 11412(Navigraph Navdata Center.exe) | 86.22 Mo] - (.Navigraph - Navigraph Navdata Center.) - (1.0.5.207) = C:\Users\gband\AppData\Local\Programs\Navigraph Navdata Center\Navigraph Navdata Center.exe [28/01/2022 02:24:28] 9120 | [Owner : gband | Parent : 17744(steamwebhelper.exe) | 113.42 Mo] - (.Valve Corporation - Steam Client WebHelper.) - (7.0.91.85) = C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe [29/06/2021 14:05:51] 19580 | [Owner : gband | Parent : 17744(steamwebhelper.exe) | 45.4 Mo] - (.Valve Corporation - Steam Client WebHelper.) - (7.0.91.85) = C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe [29/06/2021 14:05:51] 17248 | [Owner : gband | Parent : 17744(steamwebhelper.exe) | 88.97 Mo] - (.Valve Corporation - Steam Client WebHelper.) - (7.0.91.85) = C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe [29/06/2021 14:05:51] 8360 | [Owner : gband | Parent : 6948(Discord.exe) | 59.06 Mo] - (.Discord Inc. - Discord.) - (1.0.9003.0) = C:\Users\gband\AppData\Local\Discord\app-1.0.9003\Discord.exe [22/09/2021 22:34:55] 15512 | [Owner : gband | Parent : 6288(explorer.exe) | 76.39 Mo] - (.Skype Technologies S.A. - Skype.) - (8.79.0.95) = C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.79.95.0_x86__kzf8qxf38zg5c\Skype\Skype.exe [20/12/2021 08:11:20] 13852 | [Owner : gband | Parent : 15512(Skype.exe) | 26.38 Mo] - (.Skype Technologies S.A. - Skype.) - (8.79.0.95) = C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.79.95.0_x86__kzf8qxf38zg5c\Skype\Skype.exe [20/12/2021 08:11:20] 20040 | [Owner : gband | Parent : 15512(Skype.exe) | 62.88 Mo] - (.Skype Technologies S.A. - Skype.) - (8.79.0.95) = C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.79.95.0_x86__kzf8qxf38zg5c\Skype\Skype.exe [20/12/2021 08:11:20] 17236 | [Owner : gband | Parent : 15512(Skype.exe) | 34.25 Mo] - (.Skype Technologies S.A. - Skype.) - (8.79.0.95) = C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.79.95.0_x86__kzf8qxf38zg5c\Skype\Skype.exe [20/12/2021 08:11:20] 2576 | [Owner : gband | Parent : 15512(Skype.exe) | 90.76 Mo] - (.Skype Technologies S.A. - Skype.) - (8.79.0.95) = C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.79.95.0_x86__kzf8qxf38zg5c\Skype\Skype.exe [20/12/2021 08:11:20] 6620 | [Owner : gband | Parent : 708(svchost.exe) | 84.66 Mo] - (.Microsoft Corporation - Cortana.) - (3.2111.12605.0) = C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_3.2111.12605.0_x64__8wekyb3d8bbwe\Cortana.exe [08/01/2022 00:07:03] 2252 | [Owner : gband | Parent : 708(svchost.exe) | 28.98 Mo] - (.Microsoft Corporation - Runtime Broker.) - (10.0.19041.746) = C:\Windows\System32\RuntimeBroker.exe [29/06/2021 13:10:43] 5680 | [Owner : gband | Parent : 888(services.exe) | 22.6 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.19041.546) = C:\Windows\System32\svchost.exe [29/06/2021 13:10:56] 16124 | [Owner : gband | Parent : 2252(RuntimeBroker.exe) | 28.08 Mo] - (.Microsoft Corporation - Cortana System Service.) - (3.2111.12605.0) = C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_3.2111.12605.0_x64__8wekyb3d8bbwe\Win32Bridge.Server.exe [08/01/2022 00:07:03] 9404 | [Owner : gband | Parent : 14572() | 8.71 Mo] - (.Oracle Corporation - Java Update Scheduler.) - (2.8.321.7) = C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [15/12/2021 12:36:42] 11884 | [Owner : gband | Parent : 708(svchost.exe) | 32.78 Mo] - (.Microsoft Corporation - Application Frame Host.) - (10.0.19041.746) = C:\Windows\System32\ApplicationFrameHost.exe [29/06/2021 13:10:52] 11732 | [Owner : gband | Parent : 708(svchost.exe) | 2.15 Mo] - (.-.) - (10.2103.8.0) = C:\Program Files\WindowsApps\microsoft.windowscalculator_10.2103.8.0_x64__8wekyb3d8bbwe\Calculator.exe [29/04/2021 22:44:33] 10956 | [Owner : gband | Parent : 708(svchost.exe) | 6.94 Mo] - (.Microsoft Corporation - Runtime Broker.) - (10.0.19041.746) = C:\Windows\System32\RuntimeBroker.exe [29/06/2021 13:10:43] 2432 | [Owner : gband | Parent : 888(services.exe) | 21.2 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.19041.546) = C:\Windows\System32\svchost.exe [29/06/2021 13:10:56] 12656 | [Owner : gband | Parent : 6288(explorer.exe) | 77.12 Mo] - (.He Sicong - MSFS2020 Map Enhancement.) - (3.2.2.0) = C:\Program Files\MSFS2020 Map Enhancement\MSFS2020 Map Enhancement.exe [02/02/2022 22:38:30] 17696 | [Owner : gband | Parent : 12656(MSFS2020 Map Enhancement.exe) | 82.02 Mo] - (.He Sicong - MSFS2020 Map Enhancement.) - (3.2.2.0) = C:\Program Files\MSFS2020 Map Enhancement\MSFS2020 Map Enhancement.exe [02/02/2022 22:38:30] 17688 | [Owner : gband | Parent : 12656(MSFS2020 Map Enhancement.exe) | 43.35 Mo] - (.He Sicong - MSFS2020 Map Enhancement.) - (3.2.2.0) = C:\Program Files\MSFS2020 Map Enhancement\MSFS2020 Map Enhancement.exe [02/02/2022 22:38:30] 12764 | [Owner : gband | Parent : 12656(MSFS2020 Map Enhancement.exe) | 78.92 Mo] - (.He Sicong - MSFS2020 Map Enhancement.) - (3.2.2.0) = C:\Program Files\MSFS2020 Map Enhancement\MSFS2020 Map Enhancement.exe [02/02/2022 22:38:30] 11336 | [Owner : gband | Parent : 12656(MSFS2020 Map Enhancement.exe) | 115.46 Mo] - (.He Sicong - MSFS2020 Map Enhancement.) - (3.2.2.0) = C:\Program Files\MSFS2020 Map Enhancement\MSFS2020 Map Enhancement.exe [02/02/2022 22:38:30] 2236 | [Owner : gband | Parent : 12656(MSFS2020 Map Enhancement.exe) | 9.35 Mo] - (.-.) - (0.0.0.0) = C:\Program Files\MSFS2020 Map Enhancement\resources\extra\nginx\nginx.exe [02/02/2022 22:38:31] 8932 | [Owner : gband | Parent : 2236(nginx.exe) | 11.68 Mo] - (.-.) - (0.0.0.0) = C:\Program Files\MSFS2020 Map Enhancement\resources\extra\nginx\nginx.exe [02/02/2022 22:38:31] 8452 | [Owner : gband | Parent : 8932(nginx.exe) | 10.72 Mo] - (.Microsoft Corporation - Hôte de la fenêtre de la console.) - (10.0.19041.1320) = C:\Windows\System32\conhost.exe [11/11/2021 23:33:48] 14784 | [Owner : gband | Parent : 2236(nginx.exe) | 9.64 Mo] - (.-.) - (0.0.0.0) = C:\Program Files\MSFS2020 Map Enhancement\resources\extra\nginx\nginx.exe [02/02/2022 22:38:31] 4340 | [Owner : gband | Parent : 14784(nginx.exe) | 10.74 Mo] - (.Microsoft Corporation - Hôte de la fenêtre de la console.) - (10.0.19041.1320) = C:\Windows\System32\conhost.exe [11/11/2021 23:33:48] 2488 | [Owner : gband | Parent : 2236(nginx.exe) | 9.64 Mo] - (.-.) - (0.0.0.0) = C:\Program Files\MSFS2020 Map Enhancement\resources\extra\nginx\nginx.exe [02/02/2022 22:38:31] 2080 | [Owner : gband | Parent : 2488(nginx.exe) | 10.72 Mo] - (.Microsoft Corporation - Hôte de la fenêtre de la console.) - (10.0.19041.1320) = C:\Windows\System32\conhost.exe [11/11/2021 23:33:48] 15276 | [Owner : gband | Parent : 2236(nginx.exe) | 9.66 Mo] - (.-.) - (0.0.0.0) = C:\Program Files\MSFS2020 Map Enhancement\resources\extra\nginx\nginx.exe [02/02/2022 22:38:31] 7284 | [Owner : gband | Parent : 15276(nginx.exe) | 10.73 Mo] - (.Microsoft Corporation - Hôte de la fenêtre de la console.) - (10.0.19041.1320) = C:\Windows\System32\conhost.exe [11/11/2021 23:33:48] 10712 | [Owner : gband | Parent : 2236(nginx.exe) | 9.64 Mo] - (.-.) - (0.0.0.0) = C:\Program Files\MSFS2020 Map Enhancement\resources\extra\nginx\nginx.exe [02/02/2022 22:38:31] 14132 | [Owner : gband | Parent : 10712(nginx.exe) | 10.72 Mo] - (.Microsoft Corporation - Hôte de la fenêtre de la console.) - (10.0.19041.1320) = C:\Windows\System32\conhost.exe [11/11/2021 23:33:48] 18092 | [Owner : gband | Parent : 2236(nginx.exe) | 9.66 Mo] - (.-.) - (0.0.0.0) = C:\Program Files\MSFS2020 Map Enhancement\resources\extra\nginx\nginx.exe [02/02/2022 22:38:31] 18036 | [Owner : gband | Parent : 18092(nginx.exe) | 10.74 Mo] - (.Microsoft Corporation - Hôte de la fenêtre de la console.) - (10.0.19041.1320) = C:\Windows\System32\conhost.exe [11/11/2021 23:33:48] 5032 | [Owner : gband | Parent : 2236(nginx.exe) | 9.64 Mo] - (.-.) - (0.0.0.0) = C:\Program Files\MSFS2020 Map Enhancement\resources\extra\nginx\nginx.exe [02/02/2022 22:38:31] 240 | [Owner : gband | Parent : 5032(nginx.exe) | 10.72 Mo] - (.Microsoft Corporation - Hôte de la fenêtre de la console.) - (10.0.19041.1320) = C:\Windows\System32\conhost.exe [11/11/2021 23:33:48] 17636 | [Owner : gband | Parent : 2236(nginx.exe) | 9.64 Mo] - (.-.) - (0.0.0.0) = C:\Program Files\MSFS2020 Map Enhancement\resources\extra\nginx\nginx.exe [02/02/2022 22:38:31] 19096 | [Owner : gband | Parent : 17636(nginx.exe) | 10.72 Mo] - (.Microsoft Corporation - Hôte de la fenêtre de la console.) - (10.0.19041.1320) = C:\Windows\System32\conhost.exe [11/11/2021 23:33:48] 14260 | [Owner : gband | Parent : 708(svchost.exe) | 9.6 Mo] - (.Microsoft Corporation - User OOBE Broker.) - (10.0.19041.746) = C:\Windows\System32\oobe\UserOOBEBroker.exe [29/06/2021 13:11:03] 9108 | [Owner : gband | Parent : 18284(steam.exe) | 4138.02 Mo] - (.Asobo Studio -.) - (1.22.2.0) = C:\Program Files (x86)\Steam\steamapps\common\MicrosoftFlightSimulator\FlightSimulator.exe [31/12/2021 13:16:50] 14404 | [Owner : gband | Parent : 18284(steam.exe) | 32.38 Mo] - (.Valve Corporation - gameoverlayui.exe.) - (7.0.91.85) = C:\Program Files (x86)\Steam\GameOverlayUI.exe [29/06/2021 14:05:53] 15268 | [Owner : gband | Parent : 17744(steamwebhelper.exe) | 45.54 Mo] - (.Valve Corporation - Steam Client WebHelper.) - (7.0.91.85) = C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe [29/06/2021 14:05:51] 18208 | [Owner : SERVICE LOCAL | Parent : 2588(svchost.exe) | 35.49 Mo] - (.Microsoft Corporation - Isolation graphique de périphérique audio Windows.) - (10.0.19041.1387) = C:\Windows\System32\audiodg.exe [18/12/2021 11:59:14] 4756 | [Owner : gband | Parent : 708(svchost.exe) | 17.63 Mo] - (.Microsoft Corporation - Gamebar Presence Writer.) - (10.0.19041.1202) = C:\Windows\System32\GameBarPresenceWriter.exe [17/09/2021 02:24:49] 1396 | [Owner : Système | Parent : 888(services.exe) | 16.92 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.19041.546) = C:\Windows\System32\svchost.exe [29/06/2021 13:10:56] 14256 | [Owner : Système | Parent : 888(services.exe) | 17.7 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.19041.546) = C:\Windows\System32\svchost.exe [29/06/2021 13:10:56] 15304 | [Owner : Système | Parent : 888(services.exe) | ?????] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.19041.546) = C:\Windows\System32\svchost.exe [29/06/2021 13:10:56] 12752 | [Owner : gband | Parent : 888(services.exe) | 38.53 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.19041.546) = C:\Windows\System32\svchost.exe [29/06/2021 13:10:56] 14324 | [Owner : Système | Parent : 888(services.exe) | ?????] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.19041.546) = C:\Windows\System32\svchost.exe [29/06/2021 13:10:56] 12636 | [Owner : gband | Parent : 708(svchost.exe) | 28.24 Mo] - (.Microsoft Corporation - Windows Defender SmartScreen.) - (10.0.19041.1052) = C:\Windows\System32\smartscreen.exe [29/06/2021 13:10:42] 11008 | [Owner : gband | Parent : 6288(explorer.exe) | 256.79 Mo] - (.Google LLC - Google Chrome.) - (98.0.4758.82) = C:\Program Files\Google\Chrome\Application\chrome.exe [29/06/2021 14:35:55] 19952 | [Owner : gband | Parent : 11008(chrome.exe) | 8.84 Mo] - (.Google LLC - Google Chrome.) - (98.0.4758.82) = C:\Program Files\Google\Chrome\Application\chrome.exe [29/06/2021 14:35:55] 19788 | [Owner : gband | Parent : 11008(chrome.exe) | 147.68 Mo] - (.Google LLC - Google Chrome.) - (98.0.4758.82) = C:\Program Files\Google\Chrome\Application\chrome.exe [29/06/2021 14:35:55] 2116 | [Owner : gband | Parent : 11008(chrome.exe) | 54.72 Mo] - (.Google LLC - Google Chrome.) - (98.0.4758.82) = C:\Program Files\Google\Chrome\Application\chrome.exe [29/06/2021 14:35:55] 7724 | [Owner : gband | Parent : 11008(chrome.exe) | 17.57 Mo] - (.Google LLC - Google Chrome.) - (98.0.4758.82) = C:\Program Files\Google\Chrome\Application\chrome.exe [29/06/2021 14:35:55] 4716 | [Owner : gband | Parent : 11008(chrome.exe) | 124.39 Mo] - (.Google LLC - Google Chrome.) - (98.0.4758.82) = C:\Program Files\Google\Chrome\Application\chrome.exe [29/06/2021 14:35:55] 8800 | [Owner : gband | Parent : 11008(chrome.exe) | 39.2 Mo] - (.Google LLC - Google Chrome.) - (98.0.4758.82) = C:\Program Files\Google\Chrome\Application\chrome.exe [29/06/2021 14:35:55] 18996 | [Owner : gband | Parent : 11008(chrome.exe) | 45.78 Mo] - (.Google LLC - Google Chrome.) - (98.0.4758.82) = C:\Program Files\Google\Chrome\Application\chrome.exe [29/06/2021 14:35:55] 3252 | [Owner : gband | Parent : 11008(chrome.exe) | 64.92 Mo] - (.Google LLC - Google Chrome.) - (98.0.4758.82) = C:\Program Files\Google\Chrome\Application\chrome.exe [29/06/2021 14:35:55] 3400 | [Owner : gband | Parent : 11008(chrome.exe) | 163.27 Mo] - (.Google LLC - Google Chrome.) - (98.0.4758.82) = C:\Program Files\Google\Chrome\Application\chrome.exe [29/06/2021 14:35:55] 13472 | [Owner : gband | Parent : 11008(chrome.exe) | 158.32 Mo] - (.Google LLC - Google Chrome.) - (98.0.4758.82) = C:\Program Files\Google\Chrome\Application\chrome.exe [29/06/2021 14:35:55] 18096 | [Owner : Système | Parent : 888(services.exe) | 7.54 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.19041.546) = C:\Windows\System32\svchost.exe [29/06/2021 13:10:56] 1420 | [Owner : gband | Parent : 11008(chrome.exe) | 49.34 Mo] - (.Google LLC - Google Chrome.) - (98.0.4758.82) = C:\Program Files\Google\Chrome\Application\chrome.exe [29/06/2021 14:35:55] 19560 | [Owner : gband | Parent : 11008(chrome.exe) | 127.34 Mo] - (.Google LLC - Google Chrome.) - (98.0.4758.82) = C:\Program Files\Google\Chrome\Application\chrome.exe [29/06/2021 14:35:55] 18356 | [Owner : gband | Parent : 11008(chrome.exe) | 49.18 Mo] - (.Google LLC - Google Chrome.) - (98.0.4758.82) = C:\Program Files\Google\Chrome\Application\chrome.exe [29/06/2021 14:35:55] 2764 | [Owner : gband | Parent : 11008(chrome.exe) | 19.94 Mo] - (.Google LLC - Google Chrome.) - (98.0.4758.82) = C:\Program Files\Google\Chrome\Application\chrome.exe [29/06/2021 14:35:55] 10016 | [Owner : gband | Parent : 11008(chrome.exe) | 30.66 Mo] - (.Google LLC - Google Chrome.) - (98.0.4758.82) = C:\Program Files\Google\Chrome\Application\chrome.exe [29/06/2021 14:35:55] 18276 | [Owner : gband | Parent : 11008(chrome.exe) | 63.36 Mo] - (.Google LLC - Google Chrome.) - (98.0.4758.82) = C:\Program Files\Google\Chrome\Application\chrome.exe [29/06/2021 14:35:55] 11272 | [Owner : gband | Parent : 11008(chrome.exe) | 71.17 Mo] - (.Google LLC - Google Chrome.) - (98.0.4758.82) = C:\Program Files\Google\Chrome\Application\chrome.exe [29/06/2021 14:35:55] 14340 | [Owner : gband | Parent : 11008(chrome.exe) | 111.39 Mo] - (.Google LLC - Google Chrome.) - (98.0.4758.82) = C:\Program Files\Google\Chrome\Application\chrome.exe [29/06/2021 14:35:55] 12644 | [Owner : gband | Parent : 11008(chrome.exe) | 82.1 Mo] - (.Google LLC - Google Chrome.) - (98.0.4758.82) = C:\Program Files\Google\Chrome\Application\chrome.exe [29/06/2021 14:35:55] 17572 | [Owner : gband | Parent : 11008(chrome.exe) | 153.66 Mo] - (.Google LLC - Google Chrome.) - (98.0.4758.82) = C:\Program Files\Google\Chrome\Application\chrome.exe [29/06/2021 14:35:55] 16548 | [Owner : gband | Parent : 11008(chrome.exe) | 99.4 Mo] - (.Google LLC - Google Chrome.) - (98.0.4758.82) = C:\Program Files\Google\Chrome\Application\chrome.exe [29/06/2021 14:35:55] 5300 | [Owner : gband | Parent : 13388() | 49.99 Mo] - (.Microsoft Corporation - ClickOnce.) - (4.8.4084.0) = C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe [07/12/2019 09:10:34] 15448 | [Owner : gband | Parent : 5300(dfsvc.exe) | 386.7 Mo] - (.- NeoFly.) - (2.3.0.0) = C:\Users\gband\AppData\Local\Apps\2.0\LK0QAA7C.X1D\6W48N25K.TVN\neof..tion_0000000000000000_0003.000d_9b30a95929896b03\NeoFly.exe [18/12/2021 12:38:10] 13944 | [Owner : gband | Parent : 11008(chrome.exe) | 152.14 Mo] - (.Google LLC - Google Chrome.) - (98.0.4758.82) = C:\Program Files\Google\Chrome\Application\chrome.exe [29/06/2021 14:35:55] 9872 | [Owner : Système | Parent : 888(services.exe) | 6.14 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.19041.546) = C:\Windows\System32\svchost.exe [29/06/2021 13:10:56] 17684 | [Owner : gband | Parent : 11008(chrome.exe) | 16 Mo] - (.Google LLC - Google Chrome.) - (98.0.4758.82) = C:\Program Files\Google\Chrome\Application\chrome.exe [29/06/2021 14:35:55] 4404 | [Owner : gband | Parent : 708(svchost.exe) | 47.31 Mo] - (.-.) - (10.21111.1051.0) = C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.21111.10511.0_x64__8wekyb3d8bbwe\Video.UI.exe [13/12/2021 13:42:13] 19388 | [Owner : gband | Parent : 708(svchost.exe) | 8.56 Mo] - (.Microsoft Corporation - Runtime Broker.) - (10.0.19041.746) = C:\Windows\System32\RuntimeBroker.exe [29/06/2021 13:10:43] 9300 | [Owner : gband | Parent : 708(svchost.exe) | 56.43 Mo] - (.Microsoft Corporation - Windows Shell Experience Host.) - (10.0.19041.1320) = C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe [11/11/2021 23:34:07] 16508 | [Owner : gband | Parent : 708(svchost.exe) | 16.53 Mo] - (.Microsoft Corporation - Runtime Broker.) - (10.0.19041.746) = C:\Windows\System32\RuntimeBroker.exe [29/06/2021 13:10:43] 13116 | [Owner : gband | Parent : 9108(FlightSimulator.exe) | 35.41 Mo] - (.John L. Dowson - IPC Interface and More, for MSFS.) - (7.2.1.4) = C:\FSUIPC7\FSUIPC7.exe [21/12/2021 12:43:34] 17324 | [Owner : gband | Parent : 9108(FlightSimulator.exe) | 259.26 Mo] - (.-.) - (0.0.0.0) = C:\Users\gband\Documents\FSRealistic\FSRealistic.exe [02/02/2022 23:30:27] 8752 | [Owner : gband | Parent : 18284(steam.exe) | 32.55 Mo] - (.Valve Corporation - gameoverlayui.exe.) - (7.0.91.85) = C:\Program Files (x86)\Steam\GameOverlayUI.exe [29/06/2021 14:05:53] 17012 | [Owner : gband | Parent : 17744(steamwebhelper.exe) | 45.59 Mo] - (.Valve Corporation - Steam Client WebHelper.) - (7.0.91.85) = C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe [29/06/2021 14:05:51] 4148 | [Owner : Système | Parent : 888(services.exe) | 9.2 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.19041.546) = C:\Windows\System32\svchost.exe [29/06/2021 13:10:56] 7252 | [Owner : gband | Parent : 11008(chrome.exe) | 115.92 Mo] - (.Google LLC - Google Chrome.) - (98.0.4758.82) = C:\Program Files\Google\Chrome\Application\chrome.exe [29/06/2021 14:35:55] 8004 | [Owner : gband | Parent : 11008(chrome.exe) | 42.38 Mo] - (.Google LLC - Google Chrome.) - (98.0.4758.82) = C:\Program Files\Google\Chrome\Application\chrome.exe [29/06/2021 14:35:55] 9840 | [Owner : gband | Parent : 11008(chrome.exe) | 83.22 Mo] - (.Google LLC - Google Chrome.) - (98.0.4758.82) = C:\Program Files\Google\Chrome\Application\chrome.exe [29/06/2021 14:35:55] 19636 | [Owner : gband | Parent : 11008(chrome.exe) | 44.86 Mo] - (.Google LLC - Google Chrome.) - (98.0.4758.82) = C:\Program Files\Google\Chrome\Application\chrome.exe [29/06/2021 14:35:55] 5536 | [Owner : gband | Parent : 11008(chrome.exe) | 44.48 Mo] - (.Google LLC - Google Chrome.) - (98.0.4758.82) = C:\Program Files\Google\Chrome\Application\chrome.exe [29/06/2021 14:35:55] 16096 | [Owner : gband | Parent : 11008(chrome.exe) | 61.59 Mo] - (.Google LLC - Google Chrome.) - (98.0.4758.82) = C:\Program Files\Google\Chrome\Application\chrome.exe [29/06/2021 14:35:55] 15152 | [Owner : gband | Parent : 11008(chrome.exe) | 45.22 Mo] - (.Google LLC - Google Chrome.) - (98.0.4758.82) = C:\Program Files\Google\Chrome\Application\chrome.exe [29/06/2021 14:35:55] 16196 | [Owner : gband | Parent : 11008(chrome.exe) | 43.39 Mo] - (.Google LLC - Google Chrome.) - (98.0.4758.82) = C:\Program Files\Google\Chrome\Application\chrome.exe [29/06/2021 14:35:55] 10464 | [Owner : gband | Parent : 11008(chrome.exe) | 42.72 Mo] - (.Google LLC - Google Chrome.) - (98.0.4758.82) = C:\Program Files\Google\Chrome\Application\chrome.exe [29/06/2021 14:35:55] 18580 | [Owner : gband | Parent : 11008(chrome.exe) | 71.39 Mo] - (.Google LLC - Google Chrome.) - (98.0.4758.82) = C:\Program Files\Google\Chrome\Application\chrome.exe [29/06/2021 14:35:55] 6760 | [Owner : gband | Parent : 6288(explorer.exe) | 50.88 Mo] - (.SosVirus - QuickDiag.) - (8.28.22.1) = C:\Users\gband\Downloads\QuickDiag.exe [10/02/2022 22:52:13] 15804 | [Owner : Système | Parent : 708(svchost.exe) | 9.86 Mo] - (.Microsoft Corporation - WMI Provider Host.) - (10.0.19041.546) = C:\Windows\System32\wbem\WmiPrvSE.exe [29/06/2021 13:10:52] 13584 | [Owner : SERVICE RÉSEAU | Parent : 708(svchost.exe) | 11.69 Mo] - (.Microsoft Corporation - WMI Provider Host.) - (10.0.19041.546) = C:\Windows\SysWOW64\wbem\WmiPrvSE.exe [29/06/2021 13:11:09] ---------- | Locked Applications ---------- | Policy Restrictions ---------- | Explorer.exe Modules (Microsoft Files Whitelisted) (..-..) - (0.0.0.0) -- C:\WINDOWS\SYSTEM32\UMPDC.dll (..-..) - (0.0.0.0) -- C:\WINDOWS\SYSTEM32\TextShaping.dll (.NVIDIA Corporation.-.NVIDIA Driver Loader, Version 511.65.) - (30.0.15.1165) -- C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_31a2adf8c49e7799\nvldumdx.dll (.NVIDIA Corporation.-.NVIDIA D3D10 Driver, Version 511.65.) - (30.0.15.1165) -- C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_31a2adf8c49e7799\nvwgf2umx_cfg.dll (..-..) - (0.0.0.0) -- C:\Windows\System32\WindowManagementAPI.dll (..-..) - (0.0.0.0) -- C:\Windows\System32\VirtualMonitorManager.dll (..-..) - (0.0.0.0) -- C:\Windows\System32\Windows.Internal.UI.Shell.WindowTabManager.dll (.The ICU Project.-.ICU Combined Library.) - (64.2.0.0) -- C:\Windows\System32\icu.dll (..-..) - (0.0.0.0) -- C:\Program Files (x86)\RivaTuner Statistics Server\RTSSHooks64.dll (..-..) - (0.0.0.0) -- C:\Windows\ShellExperiences\TileControl.dll (..-..) - (0.0.0.0) -- C:\Windows\ShellComponents\TaskFlowUI.dll (.NVIDIA Corporation.-.NVIDIA Display Shell Extension.) - (1.2.0.1) -- C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_31a2adf8c49e7799\nvshext.dll (.NVIDIA Corporation.-.NVIDIA NVAPI Library, Version 511.65.) - (30.0.15.1165) -- C:\WINDOWS\SYSTEM32\nvapi64.dll ---------- | Winlogon.exe Modules (Microsoft Files Whitelisted) (..-..) - (0.0.0.0) -- C:\WINDOWS\System32\UMPDC.dll ---------- | svchost.exe Modules (Microsoft Files Whitelisted) (..-..) - (0.0.0.0) -- c:\windows\system32\UMPDC.dll (..-..) - (0.0.0.0) -- c:\windows\system32\TextShaping.dll (..-..) - (0.0.0.0) -- c:\windows\system32\SSDM.dll (.SQLite Development Team.-.SQLite is a software library that implements a self-contained, serverless, zero-configuration, transactional SQL database engine..) - (3.29.0.0) -- c:\windows\system32\winsqlite3.dll (..-..) - (0.0.0.0) -- C:\Windows\System32\usocoreps.dll (..-..) - (0.0.0.0) -- C:\WINDOWS\SYSTEM32\WINBIOPLUGINS\FACEBOOTSTRAPADAPTER.DLL (..-..) - (0.0.0.0) -- C:\Program Files (x86)\RivaTuner Statistics Server\RTSSHooks64.dll (..-..) - (0.0.0.0) -- C:\Windows\System32\windows.applicationmodel.conversationalagent.internal.proxystub.dll (.The ICU Project.-.ICU Combined Library.) - (64.2.0.0) -- C:\Windows\System32\icu.dll (..-..) - (0.0.0.0) -- C:\Windows\System32\WindowManagementAPI.dll (.NVIDIA Corporation.-.NVIDIA H.264 Encoder MFT, Version 511.65.) - (30.0.15.1165) -- C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_31a2adf8c49e7799\nvEncMFTH264x.dll ---------- | Windows Installer Installations (Lanilogic) Self Loading Cargo - Install. : 29/06/2021 - Package : C:\WINDOWS\Installer\49ac3c.msi (Microsoft Corporation) Windows PC Health Check - Install. : 08/10/2021 - Package : C:\WINDOWS\Installer\9d85b9d.msi (Microsoft Corporation) Microsoft Visual C++ 2019 X86 Additional Runtime - 14.28.29913 - Install. : 29/06/2021 - Package : C:\WINDOWS\Installer\3753ae.msi (Advanced Micro Devices, Inc.) AMD Ryzen Balanced Driver - Install. : 29/06/2021 - Package : C:\WINDOWS\Installer\25b3b3.msi (Intel Corporation) Intel(R) C++ Redistributables on Intel(R) 64 - Install. : 02/09/2021 - Package : C:\WINDOWS\Installer\88fbff.msi (Microsoft Corporation) Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.40660 - Install. : 14/07/2021 - Package : C:\WINDOWS\Installer\f699f3e.msi (Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 - Install. : 20/10/2021 - Package : C:\WINDOWS\Installer\3d336ab.msi (Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 - Install. : 20/10/2021 - Package : C:\WINDOWS\Installer\3d3482f.msi (Advanced Micro Devices, Inc.) Branding64 - Install. : 06/07/2021 - Package : C:\WINDOWS\Installer\127536e9.msi (Microsoft Corporation) Microsoft Visual C++ 2019 X64 Additional Runtime - 14.28.29913 - Install. : 29/06/2021 - Package : C:\WINDOWS\Installer\a988b.msi (Microsoft Corporation) Microsoft .NET Runtime - 5.0.12 (x64) - Install. : 01/02/2022 - Package : C:\WINDOWS\Installer\3eb78ef.msi (Amazon Web Services Developer Relations) AWS Command Line Interface - Install. : 30/01/2022 - Package : C:\WINDOWS\Installer\62e83b9.msi (Microsoft Corporation) Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.40660 - Install. : 14/07/2021 - Package : C:\WINDOWS\Installer\f699f50.msi (Microsoft Corporation) Microsoft Flight Simulator SimConnect Client v10.0.61259.0 - Install. : 18/12/2021 - Package : C:\WINDOWS\Installer\1e67a3.msi (Advanced Micro Devices, Inc.) AMD_Chipset_Drivers - Install. : 29/06/2021 - Package : C:\WINDOWS\Installer\25b38f.msi (Oracle Corporation) Java 8 Update 321 (64-bit) - Install. : 06/02/2022 - Package : C:\WINDOWS\Installer\65329.msi (REX Game Studios, LLC.) REX Weather Force 2020 - Install. : 12/01/2022 - Package : C:\WINDOWS\Installer\e044a40.msi (Advanced Micro Devices, Inc.) RyzenMasterSDK - Install. : 06/07/2021 - Package : C:\WINDOWS\Installer\127536fb.msi (Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 - Install. : 29/06/2021 - Package : c:\WINDOWS\Installer\3aa78b.msi (Microsoft Corporation) Microsoft Flight Simulator SimConnect Client v10.0.61242.0 - Install. : 06/01/2022 - Package : C:\WINDOWS\Installer\461209d.msi (Advanced Micro Devices, Inc.) AMD WVR64 - Install. : 06/07/2021 - Package : C:\WINDOWS\Installer\127536f5.msi (Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 - Install. : 29/06/2021 - Package : c:\WINDOWS\Installer\3aa785.msi (Microsoft Corporation) Microsoft Visual C++ 2019 X64 Minimum Runtime - 14.28.29913 - Install. : 29/06/2021 - Package : C:\WINDOWS\Installer\a9873.msi (Microsoft Corporation) Microsoft .NET Host - 5.0.12 (x64) - Install. : 01/02/2022 - Package : C:\WINDOWS\Installer\3eb78fb.msi (Microsoft Corporation) Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030 - Install. : 02/09/2021 - Package : C:\WINDOWS\Installer\88fbf9.msi (Microsoft Corporation) Microsoft Windows Desktop Runtime - 5.0.12 (x64) - Install. : 01/02/2022 - Package : C:\WINDOWS\Installer\3eb7901.msi (Microsoft Corporation) Microsoft Update Health Tools - Install. : 04/10/2021 - Package : C:\WINDOWS\Installer\58617e9.msi (Microsoft Corporation) Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.40660 - Install. : 14/07/2021 - Package : C:\WINDOWS\Installer\f699f44.msi (Advanced Micro Devices, Inc.) AMD PSP Driver - Install. : 29/06/2021 - Package : C:\WINDOWS\Installer\25b3a7.msi (REX Game Studios, LLC.) REX File Transfer Manager - Install. : 01/08/2021 - Package : C:\WINDOWS\Installer\64a15c.msi (Advanced Micro Devices, Inc.) AMD DVR64 - Install. : 06/07/2021 - Package : C:\WINDOWS\Installer\127536ef.msi (Microsoft Corporation) Microsoft SQL Server 2014 Express LocalDB - Install. : 11/07/2021 - Package : C:\WINDOWS\Installer\236ba38.msi (Microsoft Corporation) Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030 - Install. : 20/10/2021 - Package : C:\WINDOWS\Installer\3d37fc0.msi (Microsoft Corporation) Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030 - Install. : 02/09/2021 - Package : C:\WINDOWS\Installer\88fbf3.msi (Advanced Micro Devices, Inc.) Promontory_GPIO Driver - Install. : 29/06/2021 - Package : C:\WINDOWS\Installer\25b3ad.msi (Microsoft Corporation) Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.40660 - Install. : 14/07/2021 - Package : C:\WINDOWS\Installer\f699f4a.msi (Bijan Season) Bijan Season Installer - Install. : 07/02/2022 - Package : C:\WINDOWS\Installer\cfec28.msi (Advanced Micro Devices, Inc.) AMD Settings - Install. : 06/07/2021 - Package : C:\WINDOWS\Installer\127536e3.msi (Microsoft) Microsoft Flight Simulator SDK 0.16.0.0 (Core) - Install. : 01/02/2022 - Package : C:\WINDOWS\Installer\484c5ac.msi (Advanced Micro Devices, Inc.) AMD SBxxx SMBus Driver Alpha - Install. : 29/06/2021 - Package : C:\WINDOWS\Installer\25b3a1.msi (Microsoft Corporation) Microsoft Visual C++ 2019 X86 Minimum Runtime - 14.28.29913 - Install. : 29/06/2021 - Package : C:\WINDOWS\Installer\375396.msi (Microsoft Corporation) Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030 - Install. : 20/10/2021 - Package : C:\WINDOWS\Installer\3d37fba.msi (TFDi Design) PACX - Install. : 12/07/2021 - Package : C:\WINDOWS\Installer\9885960.msi (Advanced Micro Devices, Inc.) AMD PCI Driver - Install. : 29/06/2021 - Package : C:\WINDOWS\Installer\25b39b.msi (Oracle Corporation) Java Auto Updater - Install. : 06/02/2022 - Package : C:\WINDOWS\Installer\65336.msi (Microsoft Corporation) Microsoft .NET Host FX Resolver - 5.0.12 (x64) - Install. : 01/02/2022 - Package : C:\WINDOWS\Installer\3eb78f5.msi (Advanced Micro Devices, Inc.) AMD GPIO2 Driver - Install. : 29/06/2021 - Package : C:\WINDOWS\Installer\25b395.msi ---------- | Windows Updates KB5008876 - Installed On : 01/14/2022 - [Update] KB5000736 - Installed On : 06/29/2021 - [Update] KB5009543 - Installed On : 01/14/2022 - [Security Update] KB5006753 - Installed On : 11/11/2021 - [Update] KB5007273 - Installed On : 12/18/2021 - [Update] KB5005699 - Installed On : 09/17/2021 - [Security Update] ---------- | ZeroAccess Check [HKLM\Software\Classes\CLSID\{1108BE51-F58A-4CDA-BB99-7A0227D11D5E}\InProcServer32] : %systemroot%\system32\wbem\fastprox.dll [HKLM\Software\Classes\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] : %SystemRoot%\system32\windows.storage.dll [HKLM\Software\Classes\CLSID\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] : %systemroot%\system32\wbem\fastprox.dll [HKLM\Software\Classes\CLSID\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] : %systemroot%\system32\wbem\wbemess.dll [HKLM\Software\Classes\CLSID\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] : %SystemRoot%\system32\shell32.dll [HKLM\Software\WOW6432Node\Classes\CLSID\{1108BE51-F58A-4CDA-BB99-7A0227D11D5E}\InProcServer32] : %systemroot%\system32\wbem\fastprox.dll [HKLM\Software\WOW6432Node\Classes\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] : %SystemRoot%\system32\windows.storage.dll [HKLM\Software\WOW6432Node\Classes\CLSID\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] : %systemroot%\system32\wbem\fastprox.dll [HKLM\Software\WOW6432Node\Classes\CLSID\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] : %SystemRoot%\system32\shell32.dll ---------- | Startings up [HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]|[OneDriveSetup] : C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup [HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]|[OneDriveSetup] : C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]|[OneDrive] : "C:\Users\gband\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]|[Steam] : "C:\Program Files (x86)\Steam\steam.exe" -silent [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]|[Navigraph Simlink] : C:\Program Files\Navigraph\Simlink\NavigraphSimlink.exe [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]|[Discord] : C:\Users\gband\AppData\Local\Discord\Update.exe --processStart Discord.exe [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]|[SimBrief Downloader] : "C:\Users\gband\AppData\Local\Programs\SimBrief Downloader\SimBrief Downloader.exe" --hidden [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]|[Web Companion] : C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe --minimize [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]|[utweb] : "C:\Users\gband\AppData\Roaming\uTorrent Web\utweb.exe" /MINIMIZED [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]|[Navigraph Navdata Center] : "C:\Users\gband\AppData\Local\Programs\Navigraph Navdata Center\Navigraph Navdata Center.exe" --hidden [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]|[SecurityHealth] : %windir%\system32\SecurityHealthSystray.exe [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]|[RTHDVCPL] : "C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s [HKU\S-1-5-21-3835695913-52790398-83466441-1001\Software\Microsoft\Windows\CurrentVersion\Run] "OneDrive"="C:\Users\gband\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background "Steam"="C:\Program Files (x86)\Steam\steam.exe" -silent "Navigraph Simlink"=C:\Program Files\Navigraph\Simlink\NavigraphSimlink.exe [29/06/2021 16:07:07] "Discord"=C:\Users\gband\AppData\Local\Discord\Update.exe --processStart Discord.exe "SimBrief Downloader"="C:\Users\gband\AppData\Local\Programs\SimBrief Downloader\SimBrief Downloader.exe" --hidden "Web Companion"=C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe --minimize "utweb"="C:\Users\gband\AppData\Roaming\uTorrent Web\utweb.exe" /MINIMIZED "Navigraph Navdata Center"="C:\Users\gband\AppData\Local\Programs\Navigraph Navdata Center\Navigraph Navdata Center.exe" --hidden [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run] "OneDrive"=0x020000000000000000000000 "Steam"=0x020000000000000000000000 "Navigraph Simlink"=0x020000000000000000000000 "Discord"=0x020000000000000000000000 "SimBrief Downloader"=0x020000000000000000000000 "Web Companion"=0x020000000000000000000000 "Opera Browser Assistant"=0x020000000000000000000000 [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\RunMRU] "a"=%appdata%\Microsoft Flight Simulator\SimObjects\1 "MRUList"=ba "b"=cmd\1 [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "Device"=Microsoft Print to PDF,winspool,Ne01: "IsMRUEstablished"=0 "LegacyDefaultPrinterMode"=0 "MenuDropAlignment"=1 [HKLM\Software\Microsoft\Command Processor] "CompletionChar"=9 "DefaultColor"=0 "EnableExtensions"=1 "PathCompletionChar"=9 [HKLM\Software\Microsoft\Windows\CurrentVersion\Run] "SecurityHealth"=%windir%\system32\SecurityHealthSystray.exe "RTHDVCPL"="C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run] "SecurityHealth"=0x040000000000000000000000 "RTHDVCPL"=0x020000000000000000000000 "AvastUI.exe"=0x020000000000000000000000 [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] ""=mnmsrvc "AppInit_DLLs"= "DdeSendTimeout"=0 "DesktopHeapLogging"=1 "DeviceNotSelectedTimeout"=15 "DwmInputUsesIoCompletionPort"=1 "EnableDwmInputProcessing"=7 "GDIProcessHandleQuota"=10000 "IconServiceLib"=IconCodecService.dll "LoadAppInit_DLLs"=0 "NaturalInputHandler"=Ninput.dll "ShutdownWarningDialogTimeout"=4294967295 "Spooler"=yes "ThreadUnresponsiveLogTimeout"=500 "TransmissionRetryTimeout"=90 "USERNestedWindowLimit"=50 "USERPostMessageLimit"=10000 "USERProcessHandleQuota"=10000 "Win32kLastWriteTime"=1D808E3DAEC8AA3 [HKLM\Software\WOW6432Node\Microsoft\Command Processor] "CompletionChar"=9 "DefaultColor"=0 "EnableExtensions"=1 "PathCompletionChar"=9 [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] "SunJavaUpdateSched"="C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Windows] ""=mnmsrvc "AppInit_DLLs"= "DdeSendTimeout"=0 "DesktopHeapLogging"=1 "DeviceNotSelectedTimeout"=15 "DwmInputUsesIoCompletionPort"=1 "EnableDwmInputProcessing"=7 "GDIProcessHandleQuota"=10000 "IconServiceLib"=IconCodecService.dll "LoadAppInit_DLLs"=0 "NaturalInputHandler"=Ninput.dll "ShutdownWarningDialogTimeout"=4294967295 "Spooler"=yes "ThreadUnresponsiveLogTimeout"=500 "TransmissionRetryTimeout"=90 "USERNestedWindowLimit"=50 "USERPostMessageLimit"=10000 "USERProcessHandleQuota"=10000 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] "WebCheck"={E6FB5E20-DE35-11CF-9C87-00AA005127ED} ---------- | Win.ini : ---------- | System.ini : ---------- | Tasks List AMDInstallLauncher AMDLinkUpdate AMDRyzenMasterSDKTask GoogleUpdateTaskMachineCore GoogleUpdateTaskMachineUA MicrosoftEdgeUpdateTaskMachineCore MicrosoftEdgeUpdateTaskMachineUA NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} OneDrive Reporting Task-S-1-5-21-3835695913-52790398-83466441-1001 OneDrive Standalone Update Task-S-1-5-21-3835695913-52790398-83466441-1001 RTSS StartCN StartDVR User_Feed_Synchronization-{1E9D9B31-A466-4D4E-B3D9-978405AC9684} ---------- | Startings up registry ¦ Folder ---------- | Control - lsa - SecurityProviders - Session Manager - Terminal Server [HKLM\System\CurrentControlSet\Control] "BootDriverFlags"=28 "CurrentUser"=USERNAME "EarlyStartServices"=RpcSs Power BrokerInfrastructure SystemEventsBroker DcomLaunch RpcEpMapper LSM AppIdSvc "PreshutdownOrder"=DeviceInstall UsoSvc gpsvc trustedinstaller "SvcHostSplitThresholdInKB"=3670016 "WaitToKillServiceTimeout"=2000 "SystemStartOptions"= NOEXECUTE=OPTIN NOVGA "SystemBootDevice"=multi(0)disk(0)rdisk(0)partition(3) "FirmwareBootDevice"=multi(0)disk(0)rdisk(0)partition(1) "LastBootSucceeded"=1 "LastBootShutdown"=0 "DirtyShutdownCount"=150 [HKLM\System\CurrentControlSet\Control\lsa] "auditbasedirectories"=0 "auditbaseobjects"=0 "Bounds"=0x0030000000200000 "crashonauditfail"=0 "fullprivilegeauditing"=0x00 "LimitBlankPasswordUse"=1 "NoLmHash"=1 "Security Packages"="" [29/06/2021 13:52:31] "Notification Packages"=scecli "Authentication Packages"=msv1_0 "LsaPid"=908 "LsaCfgFlagsDefault"=0 "SecureBoot"=1 "ProductType"=6 "disabledomaincreds"=0 "everyoneincludesanonymous"=0 "forceguest"=0 "restrictanonymous"=0 "restrictanonymoussam"=1 "SamConnectedAccountsExist"=1 [HKLM\System\CurrentControlSet\Control\SecurityProviders] "SecurityProviders"=credssp.dll [HKLM\System\CurrentControlSet\Control\Session Manager] "AutoChkTimeout"=8 "BootExecute"=autocheck autochk * "BootShell"=%SystemRoot%\system32\bootim.exe "CriticalSectionTimeout"=2592000 "ExcludeFromKnownDlls"= "GlobalFlag"=0 "GlobalFlag2"=0 "HeapDeCommitFreeBlockThreshold"=0 "HeapDeCommitTotalFreeThreshold"=0 "HeapSegmentCommit"=0 "HeapSegmentReserve"=0 "InitConsoleFlags"=0 "NumberOfInitialSessions"=2 "ObjectDirectories"=\Windows \RPC Control "ProcessorControl"=2 "ProtectionMode"=1 "ResourceTimeoutCount"=150 "RunLevelExecute"=WinInit ServiceControlManager "RunLevelValidate"=ServiceControlManager "SETUPEXECUTE"= "AutoChkSkipSystemPartition"=0 "PendingFileRenameOperations"=\??\C:\Windows\Temp\6f6a16a1-821b-4952-bec5-3a66dd709eff.tmp [HKLM\System\CurrentControlSet\Control\Terminal Server] "AllowRemoteRPC"=0 "DelayConMgrTimeout"=0 "DeleteTempDirsOnExit"=1 "fDenyTSConnections"=1 "fSingleSessionPerUser"=1 "NotificationTimeOut"=0 "PerSessionTempDir"=0 "ProductVersion"=5.1 "RCDependentServices"=CertPropSvc SessionEnv "SnapshotMonitors"=1 "StartRCM"=0 "TSUserEnabled"=0 "RailShowallNotifyIcons"=1 "RDPVGCInstalled"=1 "InstanceID"=81df6615-23cb-4949-9a8a-a66b804 "GlassSessionId"=3 ---------- | .LNK with Arguments ---------- | AppCertDlls ---------- | Dnsapi.dll C:\WINDOWS\System32\dnsapi.dll -> OK : \drivers\etc\hosts C:\WINDOWS\SysWOW64\dnsapi.dll -> /!\ : hijacked ---------- | Policies | Registry [HKU\S-1-5-21-3835695913-52790398-83466441-1001\Control Panel\Desktop] "ActiveWndTrackTimeout"=0 "BlockSendInputResets"=0 "CaretTimeout"=5000 "CaretWidth"=1 "ClickLockTime"=1200 "CoolSwitchColumns"=7 "CoolSwitchRows"=3 "CursorBlinkRate"=530 "DockMoving"=1 "DragFromMaximize"=1 "DragFullWindows"=1 "DragHeight"=4 "DragWidth"=4 "FocusBorderHeight"=1 "FocusBorderWidth"=1 "FontSmoothing"=2 "FontSmoothingGamma"=0 "FontSmoothingOrientation"=1 "FontSmoothingType"=2 "ForegroundFlashCount"=7 "ForegroundLockTimeout"=200000 "LeftOverlapChars"=3 "MenuShowDelay"=400 "MouseWheelRouting"=2 "PaintDesktopVersion"=0 "RightOverlapChars"=3 "ScreenSaveActive"=1 "SnapSizing"=1 "TileWallpaper"=0 "WallPaper"=C:\WINDOWS\web\wallpaper\Windows\img0.jpg [07/12/2019 09:09:54] "WallpaperOriginX"=0 "WallpaperOriginY"=0 "WallpaperStyle"=10 "WheelScrollChars"=3 "WheelScrollLines"=3 "WindowArrangementActive"=1 "Win8DpiScaling"=0 "DpiScalingVer"=4096 "UserPreferencesMask"=0x9E1E078012000000 "MaxVirtualDesktopDimension"=3840 "MaxMonitorDimension"=3840 "TranscodedImageCount"=1 "LastUpdated"=4294967295 "TranscodedImageCache"=0x7AC301009E01060080070000B0040000BED52517DEACD50143003A005C00570049004E0044004F00570053005C007700650062005C00770061006C006C00700061007000650072005C00570069006E0064006F00770073005C0069006D00670030002E006A007000670000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 "Pattern Upgrade"=TRUE "PreviousPreferredUILanguages"=fr-FR "PreferredUILanguages"=fr-FR "WaitToKillAppTimeout"=2000 "HungAppTimeout"=2000 [HKU\S-1-5-21-3835695913-52790398-83466441-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel] "{018D5C66-4533-4307-9B53-224DE2ED1FE6}"=1 "{20D04FE0-3AEA-1069-A2D8-08002B30309D}"=0 [HKU\S-1-5-21-3835695913-52790398-83466441-1001\Software\Microsoft\Windows\CurrentVersion\Explorer] "ExplorerStartupTraceRecorded"=1 "ShellState"=0x240000003D28000000000000000000000000000001000000130000000000000062000000 "UserSignedIn"=1 "SIDUpdatedOnLibraries"=1 "LocalKnownFoldersMigrated"=1 "TelemetrySalt"=7 "GlobalAssocChangedCounter"=332 "FirstRunTelemetryComplete"=1 "AppReadinessLogonComplete"=1 "PostAppInstallTasksCompleted"=1 "SlowContextMenuEntries"=0x6024B221EA3A6910A2DC08002B30309DA33300000114020000000000C0000000000000466E05000062B06A59D2B415429F74E9109B0A8153F10400004E3AAA90BA1C3342B8BB535773D48449173300005D54A9A2C2A0B4429708A0B2BADD77C8D20C0000 "Browse For Folder Width"=347 "Browse For Folder Height"=346 "link"=0x18000000 "ExcludedFromStableAnaheimDownloadPromotionSL"=1 [HKU\S-1-5-21-3835695913-52790398-83466441-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced] "Start_SearchFiles"=2 "ServerAdminUI"=0 "Hidden"=1 "ShowCompColor"=1 "HideFileExt"=1 "DontPrettyPath"=0 "ShowInfoTip"=1 "HideIcons"=0 "MapNetDrvBtn"=0 "WebView"=1 "Filter"=0 "ShowSuperHidden"=0 "SeparateProcess"=0 "AutoCheckSelect"=0 "IconsOnly"=0 "ShowTypeOverlay"=1 "ShowStatusBar"=1 "StoreAppsOnTaskbar"=1 "ListviewAlphaSelect"=1 "ListviewShadow"=1 "TaskbarAnimations"=1 "ShowCortanaButton"=1 "StartMenuInit"=13 "TaskbarStateLastRun"=0x2498056200000000 "ReindexedProfile"=1 "NavPaneExpandToCurrentFolder"=0 "TaskbarSizeMove"=0 [HKU\S-1-5-21-3835695913-52790398-83466441-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\WordWheelQuery] "MRUListEx"=0x1700000016000000150000001400000013000000120000001100000001000000100000000F0000000E0000000D0000000C0000000B0000000A000000090000000800000007000000060000000500000004000000030000000200000000000000FFFFFFFF "0"=0x66007300200062006100730065000000 "2"=0x61007300730061007300730069006E00270073000000 "3"=0x700075007300680062000000 "4"=0x64006E00630061000000 "5"=0x70007500730068000000 "6"=0x370033000000 "7"=0x610073006F0062006F000000 "8"=0x610073006F0062006F00200061006900720070006F00720074000000 "9"=0x730069006400650072002E0069006E0069000000 "10"=0x66006900660061000000 "11"=0x6600690066006100320031000000 "12"=0x66006900660061002000320031000000 "13"=0x650066006F006F007400620061006C000000 "14"=0x7200650061006C00690073007400690063000000 "15"=0x6300610070007400610069006E000000 "16"=0x6C0073007A0068000000 "1"=0x0000 "17"=0x61006900720074006F006F006C000000 "18"=0x6C00650062006C000000 "19"=0x630061006D006500720061000000 "20"=0x63003200300038000000 "21"=0x63007500730074006F006D000000 "22"=0x63007500730074006F006D002000630061006D0065007200610073000000 "23"=0x67006D006D006E000000 [HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers] "authenticodeenabled"=0 [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System] "ConsentPromptBehaviorAdmin"=5 "ConsentPromptBehaviorUser"=3 "DSCAutomationHostEnabled"=2 "EnableCursorSuppression"=1 "EnableFullTrustStartupTasks"=2 "EnableInstallerDetection"=1 "EnableLUA"=1 "EnableSecureUIAPaths"=1 "EnableUIADesktopToggle"=0 "EnableUwpStartupTasks"=2 "EnableVirtualization"=1 "PromptOnSecureDesktop"=1 "SupportFullTrustStartupTasks"=1 "SupportUwpStartupTasks"=1 "ValidateAdminCodeSignatures"=0 "dontdisplaylastusername"=0 "legalnoticecaption"= "legalnoticetext"= "scforceoption"=0 "shutdownwithoutlogon"=1 "undockwithoutlogon"=1 [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "ForceActiveDesktopOn"=0 "NoActiveDesktop"=1 "NoActiveDesktopChanges"=1 "NoRecentDocsHistory"=0 [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop] "NoAddingComponents"=1 "NoComponents"=1 [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel] "{031E4825-7B94-4dc3-B131-E946B44C8DD5}"=1 "{208D2C60-3AEA-1069-A2D7-08002B30309D}"=1 "{20D04FE0-3AEA-1069-A2D8-08002B30309D}"=1 "{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}"=1 "{59031a47-3f72-44a7-89c5-5595fe6b30ee}"=1 "{871C5380-42A0-1069-A2EA-08002B30309D}"=1 "{9343812e-1c37-4a49-a12e-4b2d810d956b}"=1 "{B4FB3F98-C1EA-428d-A78A-D1F5659CBA93}"=1 "{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}"=1 [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu] "{871C5380-42A0-1069-A2EA-08002B30309D}.default"=0 "{9343812e-1c37-4a49-a12e-4b2d810d956b}"=1 [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] "CheckedValue"=1 "DefaultValue"=2 "HKeyRoot"=2147483649 "Id"=2 "RegPath"=Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced "Text"=@shell32.dll,-30500 "Type"=radio "ValueName"=Hidden [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer] "ActiveSetupDisabled"=0 "ActiveSetupTaskOverride"=1 "AsyncRunOnce"=1 "AsyncUpdatePCSettings"=1 "DisableAppInstallsOnFirstLogon"=1 "DisableResolveStoreCategories"=1 "DisableUpgradeCleanup"=1 "EarlyAppResolverStart"=1 "FileOpenDialog"={DC1C5A9C-E88A-4dde-A5A1-60F82A20AEF7} "FSIASleepTimeInMs"=60000 "GlobalFolderSettings"={EF8AD2D1-AE36-11D1-B2D2-006097DF8C11} "IconUnderline"=2 "ListViewPopupControl"={8be9f5ea-e746-4e47-ad57-3fb191ca1eed} "LVPopupSearchControl"={fccf70c8-f4d7-4d8b-8c17-cd6715e37fff} "MachineOobeUpdates"=1 "NoWaitOnRoamingPayloads"=1 "TaskScheduler"={0f87369f-a4e5-4cfc-bd3e-73e6154572dd} "AccessDeniedDialog"={100B4FC8-74C1-470F-B1B7-DD7B6BAE79BD} "GlobalAssocChangedCounter"=1 [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced] "Start_TrackDocs"=1 "TaskbarSizeMove"=0 [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] "Application"=http://go.microsoft.com/fwlink/?LinkId=57426&Ext=%s [HKLM\Software\WOW6432Node\Policies\Microsoft\Windows\Safer\CodeIdentifiers] "authenticodeenabled"=0 [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\System] "ConsentPromptBehaviorAdmin"=5 "ConsentPromptBehaviorUser"=3 "DSCAutomationHostEnabled"=2 "EnableCursorSuppression"=1 "EnableFullTrustStartupTasks"=2 "EnableInstallerDetection"=1 "EnableLUA"=1 "EnableSecureUIAPaths"=1 "EnableUIADesktopToggle"=0 "EnableUwpStartupTasks"=2 "EnableVirtualization"=1 "PromptOnSecureDesktop"=1 "SupportFullTrustStartupTasks"=1 "SupportUwpStartupTasks"=1 "ValidateAdminCodeSignatures"=0 "dontdisplaylastusername"=0 "legalnoticecaption"= "legalnoticetext"= "scforceoption"=0 "shutdownwithoutlogon"=1 "undockwithoutlogon"=1 [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer] "ForceActiveDesktopOn"=0 "NoActiveDesktop"=1 "NoActiveDesktopChanges"=1 "NoRecentDocsHistory"=0 [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop] "NoAddingComponents"=1 "NoComponents"=1 [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel] "{031E4825-7B94-4dc3-B131-E946B44C8DD5}"=1 "{208D2C60-3AEA-1069-A2D7-08002B30309D}"=1 "{20D04FE0-3AEA-1069-A2D8-08002B30309D}"=1 "{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}"=1 "{59031a47-3f72-44a7-89c5-5595fe6b30ee}"=1 "{871C5380-42A0-1069-A2EA-08002B30309D}"=1 "{9343812e-1c37-4a49-a12e-4b2d810d956b}"=1 "{B4FB3F98-C1EA-428d-A78A-D1F5659CBA93}"=1 "{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}"=1 [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu] "{871C5380-42A0-1069-A2EA-08002B30309D}.default"=0 "{9343812e-1c37-4a49-a12e-4b2d810d956b}"=1 [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] "CheckedValue"=1 "DefaultValue"=2 "HKeyRoot"=2147483649 "Id"=2 "RegPath"=Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced "Text"=@shell32.dll,-30500 "Type"=radio "ValueName"=Hidden [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer] "ActiveSetupDisabled"=0 "ActiveSetupTaskOverride"=1 "AsyncRunOnce"=1 "AsyncUpdatePCSettings"=1 "DisableAppInstallsOnFirstLogon"=1 "DisableResolveStoreCategories"=1 "DisableUpgradeCleanup"=1 "EarlyAppResolverStart"=1 "FileOpenDialog"={DC1C5A9C-E88A-4dde-A5A1-60F82A20AEF7} "FSIASleepTimeInMs"=60000 "GlobalFolderSettings"={EF8AD2D1-AE36-11D1-B2D2-006097DF8C11} "IconUnderline"=2 "ListViewPopupControl"={8be9f5ea-e746-4e47-ad57-3fb191ca1eed} "LVPopupSearchControl"={fccf70c8-f4d7-4d8b-8c17-cd6715e37fff} "MachineOobeUpdates"=1 "NoWaitOnRoamingPayloads"=1 "TaskScheduler"={0f87369f-a4e5-4cfc-bd3e-73e6154572dd} "AccessDeniedDialog"={100B4FC8-74C1-470F-B1B7-DD7B6BAE79BD} "GlobalAssocChangedCounter"=63 [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Advanced] "Start_TrackDocs"=1 "TaskbarSizeMove"=0 [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Associations] "Application"=http://go.microsoft.com/fwlink/?LinkId=57426&Ext=%s ---------- | Winlogon [HKU\S-1-5-21-3835695913-52790398-83466441-1001\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] "ExcludeProfileDirs"=AppData\Local;AppData\LocalLow;$Recycle.Bin;OneDrive;Work Folders "BuildNumber"=19043 "FirstLogon"=0 "ParseAutoexec"=1 "PUUActive"=0x23E86B5701008B007E01EA04E95846004B9B46004B9B4600D20000000200DB000764B25596C100014133470088713C00AAD913005F0E0100000000000000000000000000B3D44500ADA701007A030000D2DE570ED01ED801E95846000000000001000000E9584600634A0000E051000059618C0000000000 "DP"=0xD200E8004C018B007D01000023E86B57284E770000000000F61483BDBA1ED8014C1B2489A81ED801B49E7900000000000000000075D509000000000000000000000000000000000000000000000000000000000000000000000000000000F03F805101001D1B01C00908CC48490ACC4809BD0080C2C00D10D2C00D1024B400002414083524150C35225700C0824C042086CC26247333018021060A1A71C61B1A1A0201C0148579401585796BF5580040306092213D6892210171000002D2392882D6392B48590080410A0D08C72A8D081B91008000C3300200C730027E1B0080A3868546F7A68D66 [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] "AutoRestartShell"=1 "Background"=0 0 0 "CachedLogonsCount"=10 "DebugServerCommand"=no "DisableBackButton"=1 "EnableSIHostIntegration"=1 "ForceUnlockLogon"=0 "LegalNoticeCaption"= "LegalNoticeText"= "PasswordExpiryWarning"=5 "PowerdownAfterShutdown"=0 "PreCreateKnownFolders"={A520A1A4-1780-4FF6-BD18-167343C5AF16} "ReportBootOk"=1 "Shell"=explorer.exe "ShellCritical"=0 "ShellInfrastructure"=sihost.exe "SiHostCritical"=0 "SiHostReadyTimeOut"=0 "SiHostRestartCountLimit"=0 "SiHostRestartTimeGap"=0 "Userinit"=C:\WINDOWS\system32\userinit.exe, "VMApplet"=SystemPropertiesPerformance.exe /pagefile "WinStationsDisabled"=0 "scremoveoption"=0 "DisableCAD"=1 "LastLogOffEndTimePerfCounter"=298403180579 "ShutdownFlags"=2147483687 "DisableLockWorkstation"=0 "EnableFirstLogonAnimation"=1 "AutoLogonSID"=S-1-5-21-3835695913-52790398-83466441-1001 "LastUsedUsername"=gband [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon] "DefaultDomainName"= "DefaultUserName"= "PreCreateKnownFolders"={A520A1A4-1780-4FF6-BD18-167343C5AF16} "Shell"=explorer.exe "ShellCritical"=0 "SiHostCritical"=0 "SiHostReadyTimeOut"=0 "SiHostRestartCountLimit"=0 "SiHostRestartTimeGap"=0 ---------- | Associations [HKLM\Software\Classes\.exe] ""=exefile "Content Type"=application/x-msdownload [HKLM\Software\Classes\exefile\Shell\Open\Command] ""="%1" %* "IsolatedCommand"="%1" %* [HKLM\Software\Classes\.com] ""=comfile [HKLM\Software\Classes\comfile\Shell\Open\Command] ""="%1" %* [HKLM\Software\Classes\.reg] ""=regfile [HKLM\Software\Classes\regfile\Shell\Open\Command] ""=regedit.exe "%1" [HKLM\Software\Classes\.scr] ""=scrfile [HKLM\Software\Classes\scrfile\Shell\Open\Command] ""="%1" /S [HKLM\Software\Classes\.bat] ""=batfile [HKLM\Software\Classes\batfile\Shell\Open\Command] ""="%1" %* [HKLM\Software\Classes\.cmd] ""=cmdfile [HKLM\Software\Classes\cmdfile\Shell\Open\Command] ""="%1" %* [HKLM\Software\Classes\.pif] ""=piffile [HKLM\Software\Classes\piffile\Shell\Open\Command] ""="%1" %* [HKLM\Software\Classes\.inf] ""=inffile [HKLM\Software\Classes\inffile\Shell\Open\Command] ""=%SystemRoot%\system32\NOTEPAD.EXE %1 [HKLM\Software\Classes\.url] ""=InternetShortcut [HKLM\Software\Classes\.lnk] ""=lnkfile [HKLM\Software\Classes\.hta] ""=htafile "Content Type"=application/hta "PerceivedType"=text [HKLM\Software\Classes\htafile\Shell\Open\Command] ""=C:\Windows\SysWOW64\mshta.exe "%1" {1E460BD7-F1C3-4B2E-88BF-4E770A288AF5}%U{1E460BD7-F1C3-4B2E-88BF-4E770A288AF5} %* [HKLM\Software\Classes\InternetShortcut] "EditFlags"=2 "FriendlyTypeName"=@C:\Windows\System32\ieframe.dll,-10046 "FullDetails"=prop:System.Link.TargetUrl;System.Rating;System.Link.Description;System.Link.Comment "InfoTip"=prop:System.Link.TargetUrl;System.Rating;System.Link.Description;System.Link.Comment "IsShortcut"= "NeverShowExt"= "PreviewDetails"=prop:System.Link.TargetUrl;System.Rating;System.History.VisitCount;System.History.DateChanged;System.Link.DateVisited;System.Link.Description;System.Link.Comment [HKLM\Software\Classes\Application.Manifest] ""=Application Manifest "BrowserFlags"=4096 "EditFlags"=4259840 "FriendlyTypeName"=@C:\Windows\System32\dfshim.dll,-200 [HKLM\Software\Classes\Application.Reference] ""=Application Reference "EditFlags"=131072 "FriendlyTypeName"=@C:\Windows\System32\dfshim.dll,-201 "IsShortcut"= "NeverShowExt"= [HKLM\Software\Classes\Folder] ""=Folder "AppUserModelID"=Microsoft.Windows.Explorer "ContentViewModeForBrowse"=prop:~System.ItemNameDisplay;~System.LayoutPattern.PlaceHolder;~System.LayoutPattern.PlaceHolder;~System.LayoutPattern.PlaceHolder;System.DateModified "ContentViewModeForSearch"=prop:~System.ItemNameDisplay;System.DateModified;~System.ItemFolderPathDisplay "ContentViewModeLayoutPatternForBrowse"=delta "ContentViewModeLayoutPatternForSearch"=alpha "EditFlags"=0xD2030000 "FullDetails"=prop:System.PropGroup.Description;System.ItemNameDisplay;System.ItemTypeText;System.Size;System.HomeGroupSharingStatus "NoRecentDocs"= "ThumbnailCutoff"=0 "TileInfo"=prop:System.Title;System.HomeGroupSharingStatus [HKLM\Software\WOW6432Node\Classes\.exe] ""=exefile "Content Type"=application/x-msdownload [HKLM\Software\WOW6432Node\Classes\exefile\Shell\Open\Command] ""="%1" %* "IsolatedCommand"="%1" %* [HKLM\Software\WOW6432Node\Classes\.com] ""=comfile [HKLM\Software\WOW6432Node\Classes\comfile\Shell\Open\Command] ""="%1" %* [HKLM\Software\WOW6432Node\Classes\.reg] ""=regfile [HKLM\Software\WOW6432Node\Classes\regfile\Shell\Open\Command] ""=regedit.exe "%1" [HKLM\Software\WOW6432Node\Classes\.scr] ""=scrfile [HKLM\Software\WOW6432Node\Classes\scrfile\Shell\Open\Command] ""="%1" /S [HKLM\Software\WOW6432Node\Classes\.bat] ""=batfile [HKLM\Software\WOW6432Node\Classes\batfile\Shell\Open\Command] ""="%1" %* [HKLM\Software\WOW6432Node\Classes\.cmd] ""=cmdfile [HKLM\Software\WOW6432Node\Classes\cmdfile\Shell\Open\Command] ""="%1" %* [HKLM\Software\WOW6432Node\Classes\.pif] ""=piffile [HKLM\Software\WOW6432Node\Classes\piffile\Shell\Open\Command] ""="%1" %* [HKLM\Software\WOW6432Node\Classes\.inf] ""=inffile [HKLM\Software\WOW6432Node\Classes\inffile\Shell\Open\Command] ""=%SystemRoot%\system32\NOTEPAD.EXE %1 [HKLM\Software\WOW6432Node\Classes\.url] ""=InternetShortcut [HKLM\Software\WOW6432Node\Classes\.lnk] ""=lnkfile [HKLM\Software\WOW6432Node\Classes\.hta] ""=htafile "Content Type"=application/hta "PerceivedType"=text [HKLM\Software\WOW6432Node\Classes\htafile\Shell\Open\Command] ""=C:\Windows\SysWOW64\mshta.exe "%1" {1E460BD7-F1C3-4B2E-88BF-4E770A288AF5}%U{1E460BD7-F1C3-4B2E-88BF-4E770A288AF5} %* [HKLM\Software\WOW6432Node\Classes\InternetShortcut] "EditFlags"=2 "FriendlyTypeName"=@C:\Windows\System32\ieframe.dll,-10046 "FullDetails"=prop:System.Link.TargetUrl;System.Rating;System.Link.Description;System.Link.Comment "InfoTip"=prop:System.Link.TargetUrl;System.Rating;System.Link.Description;System.Link.Comment "IsShortcut"= "NeverShowExt"= "PreviewDetails"=prop:System.Link.TargetUrl;System.Rating;System.History.VisitCount;System.History.DateChanged;System.Link.DateVisited;System.Link.Description;System.Link.Comment [HKLM\Software\WOW6432Node\Classes\Application.Manifest] ""=Application Manifest "BrowserFlags"=4096 "EditFlags"=4259840 "FriendlyTypeName"=@C:\Windows\System32\dfshim.dll,-200 [HKLM\Software\WOW6432Node\Classes\Application.Reference] ""=Application Reference "EditFlags"=131072 "FriendlyTypeName"=@C:\Windows\System32\dfshim.dll,-201 "IsShortcut"= "NeverShowExt"= [HKLM\Software\WOW6432Node\Classes\Folder] ""=Folder "AppUserModelID"=Microsoft.Windows.Explorer "ContentViewModeForBrowse"=prop:~System.ItemNameDisplay;~System.LayoutPattern.PlaceHolder;~System.LayoutPattern.PlaceHolder;~System.LayoutPattern.PlaceHolder;System.DateModified "ContentViewModeForSearch"=prop:~System.ItemNameDisplay;System.DateModified;~System.ItemFolderPathDisplay "ContentViewModeLayoutPatternForBrowse"=delta "ContentViewModeLayoutPatternForSearch"=alpha "EditFlags"=0xD2030000 "FullDetails"=prop:System.PropGroup.Description;System.ItemNameDisplay;System.ItemTypeText;System.Size;System.HomeGroupSharingStatus "NoRecentDocs"= "ThumbnailCutoff"=0 "TileInfo"=prop:System.Title;System.HomeGroupSharingStatus [HKLM\Software\Clients\StartMenuInternet\Google Chrome\Shell\open\Command] ""="C:\Program Files\Google\Chrome\Application\chrome.exe" [HKLM\Software\Clients\StartMenuInternet\Google Chrome\InstallInfo] "ReinstallCommand"="C:\Program Files\Google\Chrome\Application\chrome.exe" --make-default-browser [HKLM\Software\Clients\StartMenuInternet\IEXPLORE.EXE\Shell\open\Command] ""=C:\Program Files\Internet Explorer\iexplore.exe [17/09/2021 02:25:03] [HKLM\Software\Clients\StartMenuInternet\IEXPLORE.EXE\InstallInfo] "ReinstallCommand"="C:\Windows\System32\ie4uinit.exe" -reinstall [HKLM\Software\Clients\StartMenuInternet\Microsoft Edge\Shell\open\Command] ""="C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" [HKLM\Software\Clients\StartMenuInternet\Microsoft Edge\InstallInfo] "ReinstallCommand"="C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --make-default-browser [HKLM\Software\WOW6432Node\Clients\StartMenuInternet\Google Chrome\Shell\open\Command] ""="C:\Program Files\Google\Chrome\Application\chrome.exe" [HKLM\Software\WOW6432Node\Clients\StartMenuInternet\Google Chrome\InstallInfo] "ReinstallCommand"="C:\Program Files\Google\Chrome\Application\chrome.exe" --make-default-browser [HKLM\Software\WOW6432Node\Clients\StartMenuInternet\IEXPLORE.EXE\Shell\open\Command] ""=C:\Program Files\Internet Explorer\iexplore.exe [17/09/2021 02:25:03] [HKLM\Software\WOW6432Node\Clients\StartMenuInternet\IEXPLORE.EXE\InstallInfo] "ReinstallCommand"="C:\Windows\System32\ie4uinit.exe" -reinstall [HKLM\Software\WOW6432Node\Clients\StartMenuInternet\Microsoft Edge\Shell\open\Command] ""="C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" [HKLM\Software\WOW6432Node\Clients\StartMenuInternet\Microsoft Edge\InstallInfo] "ReinstallCommand"="C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --make-default-browser ---------- | AppcompatFlags [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Persisted] "C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\upc.exe"=32 [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store] "C:\Users\gband\AppData\Local\Microsoft\OneDrive\19.043.0304.0013\FileSyncConfig.exe"=0x534143500100000000000000070000002800000060AE040085EF040001000000000000000000000A0021000050BB64EDDDACD5010000000100000000 "C:\Users\gband\AppData\Local\Microsoft\OneDrive\21.109.0530.0001\FileSyncConfig.exe"=0x5341435001000000000000000700000028000000789B070044B2070001000000000000000000000A0021000050BB64EDDDACD5010000000100000000 "C:\Users\gband\Downloads\radeon-software-adrenalin-2020-21.6.1-minimalsetup-210621_web.exe"=0x5341435001000000000000000700000028000000C0C81B028C871C0201000000000000000000000A0021000050BB64EDDDACD5010000000000000000 "C:\Users\gband\Downloads\SteamSetup.exe"=0x5341435001000000000000000700000028000000F8041B000A691B0001000000000000000000000A0021000050BB64EDDDACD50100000000000000000200000028000000000000000000004000000000000000000000000000000000071E0000000000000100000001000000 "C:\Users\gband\AppData\Local\Temp\Temp1_MSIAfterburnerSetup.zip\MSIAfterburnerSetup464Beta3.exe"=0x5341435001000000000000000700000028000000F0374003601D41030100000000000000000001060001000050BB64EDDDACD5010000000000000000 "C:\Users\gband\Downloads\ChromeSetup.exe"=0x534143500100000000000000070000002800000070001400E52D140001000000000000000000000A0021000050BB64EDDDACD50100000000000000000200000028000000000000000000000000000000000000000000000000000000108A0000000000000100000001000000 "C:\Users\gband\AppData\Local\Temp\Temp1_self-loading-cargo-1.55.zip\setup.exe"=0x534143500100000000000000070000002800000000340C00851F080001000000000000000000000A0021000050BB64EDDDACD5010000000000000000020000002800000000000000000000000000000000000000000000000000000057230000000000000100000001000000 "C:\Users\gband\AppData\Local\Temp\Temp1_Update MSFS2020 - FSUIPC7 Download - 8.06.2021.zip\Install_FSUIPC7\Install_FSUIPC7.exe"=0x5341435001000000000000000700000028000000EFFBA1000000000001000000000000000000000A0021000050BB64EDDDACD501000000000000000002000000280000000000000000000040000000000000000000000000000000005E270000000000000100000001000000 "C:\Program Files\WindowsApps\64343GTDocStudio.OfficeDocOpener_3.2.22.0_x86__3h5nez1g3qt2c\program\soffice.exe"=0x5341435001000000000000000700000028000000001A01007C6F010001000000000000000000000A0021000050BB64EDDDACD5010000000000000000020000002800000000000000000000000000000000000000000000000000000099120100000000000400000004000000 "C:\Program Files\AMD\CNext\CNext\RadeonSoftware.exe"=0x534143500100000000000000070000002800000020157F01F8F37F0101000000000000000000000A0021000050BB64EDDDACD501000000000000000002000000280000000000000000000000000000000000000000000000000000008C000000000000000100000001000000 "C:\AMD\AMD_Radeon_Installer_21.6.1\Setup.exe"=0x5341435001000000000000000700000028000000D83111009C3E110001000000000000000000000A7322000050BB64EDDDACD50100000000000000000200000028000000000000000000004000000000000000000000000000000000832D0100000000000100000001000000 "C:\Users\gband\AppData\Local\Temp\Temp1_pbrsetup1.0.2_HZ52m.zip\pbrsetup1.0.2.exe"=0x53414350010000000000000007000000280000003219A6000000000001000000000000000000000A0021000050BB64EDDDACD50100000000000000000200000028000000000000000000000000000000000000000000000000000000E8C00800000000000100000001000000 "C:\Users\gband\AppData\Local\Programs\Push Back Recorder\pbr.exe"=0x5341435001000000000000000700000028000000898622000000000001000000000000000000000A7320000050BB64EDDDACD50100000000000000000200000028000000000000000000000000000000000000000000000000000000B63C0100000000000300000003000000 "C:\Program Files\WindowsApps\HaukeGtze.7-ZipFileManagerUnofficial_1.1900.3.0_x64__6bk20wvc8rfx2\7zFM.exe"=0x5341435001000000000000000700000028000000003E0D000000000001000000000000000000000A0021000050BB64EDDDACD50100000000000000000200000028000000000000000000000000000000000000000000000000000000EB3A9D00000000004501000045010000 "C:\Users\gband\Downloads\Addons linker\MSFS_AddonsLinker.exe"=0x534143500100000000000000070000002800000000A812000000000001000000000000000000000A7322000050BB64EDDDACD5010000000000000000050000001000000000000000000000000000000000000000020000005000000000000000000000000000000000000000000000000000000039780100000000000700000007000000000000000000004000000000000000000000000000000000FDC11600000000000100000000000000 "C:\Users\gband\AppData\Local\Temp\7zO0451089E\ModManFX64.exe"=0x534143500100000000000000070000002800000000004500AD552F0001000000000000000000000A0021000050BB64EDDDACD5010000000000000000020000002800000000000000000000000000000000000000000000000000000075A80000000000000100000001000000 "C:\Users\gband\AppData\Local\Temp\7zOC63F1D9F\pbrsetup1.0.2.exe"=0x53414350010000000000000007000000280000003219A6000000000001000000000000000000000A0021000050BB64EDDDACD501000000000000000002000000280000000000000000000000000000000000000000000000000000000D100000000000000100000001000000 "C:\Users\gband\Downloads\setup.exe"=0x534143500100000000000000070000002800000000942D05000000000100000000000000000003060001000050BB64EDDDACD5010000000000000000 "D:\Microsoft Flight Simulator\steamapps\common\MicrosoftFlightSimulator\FlightSimulator.exe"=0x5341435001000000000000000700000028000000001AC2100000000001000000000000000000000A0021000050BB64EDDDACD5010000000000000000020000002800000000000000000000000000000000000000000000000000000038980000000000000600000006000000 "C:\Users\gband\Downloads\Navigraph Navdata Center 1.0.0-beta.26.exe"=0x534143500100000000000000070000002800000018BAB105354CB20501000000000000000000000A0021000050BB64EDDDACD5010000000000000000020000002800000000000000000000000000000000000000000000000000000054070300000000000400000004000000 "C:\Users\gband\Downloads\setup (1).exe"=0x5341435001000000000000000700000028000000E0150C0023520C0001000000000000000000000A0021000050BB64EDDDACD501000000000000000002000000280000000000000000000000000000000000000000000000000000007B030000000000000100000001000000 "C:\Users\gband\AppData\Local\Apps\2.0\LK0QAA7C.X1D\6W48N25K.TVN\skac..tion_62396b27c2c60a41_0001.0001_e182734b1fe96b80\SKACARS.exe"=0x5341435001000000000000000700000028000000E06D0400DB49050001000000000000000000000A6322000050BB64EDDDACD501000000000000000002000000280000000000000000000040000000000000000000000000000000007CE98601000000000600000006000000 "C:\Users\gband\AppData\Local\Temp\7zO053FAFAF\Install_FSUIPC7.exe"=0x53414350010000000000000007000000280000008DFBA1000000000001000000000000000000000A0021000050BB64EDDDACD501000000000000000005000000100000000000000000000000000000000000000002000000280000000000000000000040000000000000000000000000000000008E120000000000000100000001000000 "C:\Program Files (x86)\Lanilogic\Self Loading Cargo\SLC.exe"=0x5341435001000000000000000700000028000000003C11000000000001000000000000000000000A7522000050BB64EDDDACD501000000000000000002000000280000000000000000000000940002000000000000000000000000008D38550200000000EB000000EB000000 "C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe"=0x534143500100000000000000070000002800000038160C00AC740C0001000000000000000000000A0021000050BB64EDDDACD50100000000000000000200000028000000000000000000004000000000000000000000000000000000B0A5B300000000000300000003000000 "C:\Users\gband\AppData\Local\fbw_installer\FlyByWire Installer.exe"=0x5341435001000000000000000700000028000000008604000000000001000000000000000000000A0021000050BB64EDDDACD5010000000000000000020000002800000000000000000000000000000000000000000000000000000075DC1700000000000900000009000000 "E:\Games\Nouveau dossier\Assassins Creed Origins The Curse of the Pharaohs\ACOrigins.exe"=0x534143500100000000000000070000002800000000629A0A21FE920A01000000000000000000000A0021000050BB64EDDDACD501000000000000000002000000280000000000000000000000000000000000000000000000000000004F619D00000000001400000014000000 "C:\Users\gband\AppData\Local\Temp\7zO063148C9\FS2Crew Pushback Express v2.1.exe"=0x534143500100000000000000070000002800000077FAC203000000000100000000000000000001060001000050BB64EDDDACD5010000000000000000020000002800000000000000000000400000000000000000000000000000000085450000000000000100000001000000 "C:\Users\gband\AppData\Local\Temp\7zO0A344B45\IVAO_Pilot_MSFS2020_1.10.4b.exe"=0x5341435001000000000000000700000028000000ACC406040000000001000000000000000000000A0021000050BB64EDDDACD501000000000000000002000000280000000000000000000040000000000000000000000000000000003F270000000000000100000001000000 "C:\Users\gband\AppData\Local\Temp\7zO0A33EF85\IVAO_Pilot_MSFS2020_1.10.4b.exe"=0x5341435001000000000000000700000028000000ACC406040000000001000000000000000000000A0021000050BB64EDDDACD50100000000000000000200000028000000000000000000004000000000000000000000000000000000F8D80400000000000100000001000000 "C:\Program Files\WindowsApps\WuhanNetPowerTechnologyCo.3322537A536FD_2.8.2.0_x86__63m8b6nby1dvp\NetPowerZip\NetPowerZip.exe"=0x534143500100000000000000070000002800000000B43E000000000001000000000000000000000A6122000050BB64EDDDACD501000000000000000002000000280000000000000000000000000000000000000000000000000000004B4C0000000000000500000005000000 "C:\Program Files (x86)\Navigraph\FMS Data Manager\NGFMSAgent.exe"=0x534143500100000000000000070000002800000058200F000508100001000000000000000000000A7122000050BB64EDDDACD50100000000000000000200000028000000000000000000000000000000000000000000000000000000CE380100000000000200000002000000 "C:\Users\gband\AppData\Local\Temp\7zO4F99ECDE\DS4Windows.exe"=0x5341435001000000000000000700000028000000005830000000000001000000000000000000000A0021000050BB64EDDDACD5010000000000000000050000001000000000000000000000000000000000000000020000002800000000000000000000000000000000000000000000000000000007670000000000000100000001000000 "C:\Users\gband\AppData\Local\Temp\7zO4F9945FE\DS4Updater.exe"=0x534143500100000000000000070000002800000000C208000000000001000000000000000000000A7522000050BB64EDDDACD501000000000000000002000000280000000000000000000000000000000000000000000000000000008D410000000000000100000001000000 "C:\Users\gband\AppData\Local\Temp\7zO4F9E1E7F\DS4Windows.exe"=0x5341435001000000000000000700000028000000005830000000000001000000000000000000000A0021000050BB64EDDDACD501000000000000000005000000100000000000000000000000000000000000000002000000280000000000000000000000000000000000000000000000000000008CF4F800000000001500000015000000 "C:\Program Files (x86)\Football Manager 2021\Football Manager 2021.exe"=0x534143500100000000000000070000002800000087CA11000000000001000000000000000000000A0021000050BB64EDDDACD50100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000004000000000000000000000000000000000D4320400000000000200000002000000 "C:\Users\gband\AppData\Local\Temp\7zO0CED1AF2\fm4764.exe"=0x534143500100000000000000070000002800000000F6FD220000000001000000000000000000000A0021000050BB64EDDDACD5010000000000000000020000002800000000000000000000000000000000000000000000000000000075110000000000000100000001000000 "C:\Users\gband\Documents\pmdg-ops-center\OpsCenterUpdater.exe"=0x5341435001000000000000000700000028000000001413000000000001000000000000000000000A7322000050BB64EDDDACD50100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000000000000200000000000000000000000000F8790C00000000000100000001000000 "E:\Games\Nouveau dossier\Football Manager 2021\fm4764.exe"=0x534143500100000000000000070000002800000000F6FD220000000001000000000000000000000A0021000050BB64EDDDACD501000000000000000002000000280000000000000000000000000000000000000000000000000000008DAC0300000000000200000002000000 "E:\Games\Nouveau dossier\Football Manager 2021\fm.exe"=0x534143500100000000000000070000002800000000589F220000000001000000000000000000000A0021000050BB64EDDDACD50100000000000000000500000010000000000000000000000000000000000000000200000050000000000000000000000000000000000000000000000000000000C3610400000000000300000002000000000000000000004000000000000000000000000000000000BAE20100000000000100000000000000 "E:\Games\Nouveau dossier\Football Manager 2021\fm213EDITORMKDEV.exe"=0x534143500100000000000000070000002800000000589F220000000001000000000000000000000A0021000050BB64EDDDACD5010000000000000000020000002800000000000000000000000000000000000000000000000000000015DC0400000000000200000002000000 "E:\Games\Nouveau dossier\Football.Manager.2021\fm.exe"=0x534143500100000000000000070000002800000000589F220000000001000000000000000000000A0021000050BB64EDDDACD5010000000000000000020000002800000000000000000000000000000000000000000000000000000098B70000000000000700000007000000 "C:\Users\gband\AppData\Local\Apps\2.0\LK0QAA7C.X1D\6W48N25K.TVN\prem..tion_0000000000000000_0001.0001_0410799fac980250\PremCARS.exe"=0x534143500100000000000000070000002800000000E211000000000001000000000000000000000A7522000050BB64EDDDACD50100000000000000000200000028000000000000000000000000000000000000000000000000000000FE380400000000000100000001000000 "C:\Users\gband\AppData\Local\Microsoft\OneDrive\21.119.0613.0001\FileSyncConfig.exe"=0x5341435001000000000000000700000028000000786509006FC0090001000000000000000000000A0021000050BB64EDDDACD5010000000100000000 "C:\Users\gband\AppData\Local\Temp\7zOC3AC89C4\RTSSSetup731.exe"=0x534143500100000000000000070000002800000058616801B32069010100000000000000000001060001000050BB64EDDDACD501000000000000000002000000280000000000000000000040000000000000000000000000000000006C920000000000000100000001000000 "C:\AMD\AMD_Radeon_Installer_21.6.2\Setup.exe"=0x5341435001000000000000000700000028000000902F11006FCB110001000000000000000000000A7322000050BB64EDDDACD50100000000000000000200000028000000000000000000004000000000000000000000000000000000D0FB0100000000000200000002000000 "C:\Program Files\AMD\CNext\CNext\AMDRSServ.exe"=0x5341435001000000000000000700000028000000908326009362270001000000000000000000000A0021000050BB64EDDDACD5010000000000000000 "C:\Users\gband\AppData\Local\Apps\2.0\LK0QAA7C.X1D\6W48N25K.TVN\skac..tion_62396b27c2c60a41_0001.0001_e182734c20687b40\SKACARS.exe"=0x5341435001000000000000000700000028000000E06D04000591040001000000000000000000000A6322000050BB64EDDDACD50100000000000000000500000010000000000000000000000000000000000000000200000050000000000000000000004000000000000000000000000000000000C693EA0700000000330000000700000000000000000000000000000000000000000000000000000024B6B100000000000200000000000000 "C:\Users\gband\AppData\Local\Temp\7zO489A2327\471.11-desktop-win10-64bit-international-dch-whql.exe"=0x534143500100000000000000070000002800000040FCFF2C0283002D0100000000000000000002060001000050BB64EDDDACD5010000000000000000020000002800000000000000000000400000000000000000000000000000000096EF0200000000000100000001000000 "C:\Users\gband\AppData\Local\Temp\7zOC5A4685B\[Guru3D.com]-Unigine_Superposition.exe"=0x53414350010000000000000007000000280000009039D24FA8EFD24F01000000000000000000000A0021000050BB64EDDDACD5010000000000000000020000002800000000000000000000000000000000000000000000000000000096290C00000000000100000001000000 "C:\Users\gband\Desktop\stickandrudderstudios-fs-atc-chatter-v2021-03\FS-ATC-Chatter.exe"=0x5341435001000000000000000700000028000000004415000000000001000000000000000000000A6122000050BB64EDDDACD501000000000000000005000000100000000000000000000000000000000000000002000000500000000000000000000000000000000000000000000000000000002B923F00000000000400000003000000000000000000004000000000000000000000000000000000B39F0500000000000200000000000000 "C:\Users\gband\Downloads\325289AEDD75.TorrentRTFREE_qtx9tqphctw9r!App\Downloads\P2ATC 2.5.0.3\P2A_2503_x64_with_Navigraph_1705 v2.5.0.3.exe"=0x5341435001000000000000000700000028000000D357700A0000000001000000000000000000000A0021000050BB64EDDDACD5010000000000000000020000002800000000000000000000000000000000000000000000000000000077D40000000000000200000002000000 "C:\Pilot2ATC_2018_x64\Pilot2ATC_2018.exe"=0x534143500100000000000000070000002800000000D644000000000001000000000000000000000A7322000050BB64EDDDACD50100000000000000000200000050000000000000000000004004000000000000000000000000000000423910000000000002000000010000000000000000000000040000000000000000000000000000006BD3070000000000010000000000000006000000080000000400000000000000 "C:\Users\gband\Downloads\PACX_Installer.exe"=0x5341435001000000000000000700000028000000903F251A5422261A01000000000000000000000A0021000050BB64EDDDACD5010000000000000000020000002800000000000000000000000000000000000000000000000000000010050000000000000100000001000000 "C:\Program Files (x86)\TFDi Design\PACX\PACX.exe"=0x534143500100000000000000070000002800000018B47000E487710001000000000000000000000A7522000050BB64EDDDACD5010000000000000000020000002800000000000000000000000400000000000000000000000000000055A0C900000000001300000013000000 "C:\Users\gband\Documents\Luke Air\launcher.exe"=0x53414350010000000000000007000000280000000086D4070000000001000000000000000000000A0021000050BB64EDDDACD5010000000000000000 "C:\Users\gband\Downloads\Nouveau dossier\Setup.exe"=0x534143500100000000000000070000002800000000DC0000000000000100000000000000000001057100000050BB64EDDDACD5010000000000000000020000002800000000000000000800400000000000000000000000000000000009300000000000000100000001000000 "C:\Users\gband\Documents\Traffic Liive\Enhanced Live Traffic.exe"=0x534143500100000000000000070000002800000000F80000DF6C010001000000000000000000000A7322000050BB64EDDDACD501000000000000000002000000280000000000000000000000000000000000000000000000000000000CD2D902000000000600000006000000 "C:\Users\gband\AppData\Local\Temp\7zO8D9588EB\setup_PSXT_MSFS_v24.5.exe"=0x5341435001000000000000000700000028000000DBBA38000000000001000000000000000000000A0021000050BB64EDDDACD501000000000000000002000000280000000000000000000000000000000000000000000000000000005E270000000000000100000001000000 "C:\Users\gband\AppData\Local\Temp\7zOC69726DA\setup_AILG_MSFS_v1.8_beta.exe"=0x534143500100000000000000070000002800000093B31F000000000001000000000000000000000A0021000050BB64EDDDACD5010000000000000000020000002800000000000000000000000000000000000000000000000000000033360000000000000100000001000000 "C:\Users\gband\AppData\Local\Temp\7zOCA17275D\setup_PPG_MSFS_v3.2_beta.exe"=0x534143500100000000000000070000002800000046D81E000000000001000000000000000000000A0021000050BB64EDDDACD50100000000000000000200000028000000000000000000000000000000000000000000000000000000651E0000000000000100000001000000 "C:\PPG_MSFS\PPG_MSFS.exe"=0x534143500100000000000000070000002800000000080A000000000001000000000000000000000A7322000050BB64EDDDACD5010000000000000000020000002800000000000000000000000000000000000000000000000000000022643600000000000200000002000000 "C:\Users\gband\AppData\Local\Temp\7zOCC95D890\setup_PSXT_MSFS_v24.5.exe"=0x5341435001000000000000000700000028000000DBBA38000000000001000000000000000000000A0021000050BB64EDDDACD50100000000000000000200000028000000000000000000000000000000000000000000000000000000FE360000000000000100000001000000 "C:\Users\gband\AppData\Local\Temp\7zOCB0EE6A3\setup_PSXT_MSFS_v24.5.exe"=0x5341435001000000000000000700000028000000DBBA38000000000001000000000000000000000A0021000050BB64EDDDACD50100000000000000000200000028000000000000000000000000000000000000000000000000000000B4CF0000000000000100000001000000 "C:\Users\gband\AppData\Local\Temp\7zO05423716\PSXseecon.exe"=0x534143500100000000000000070000002800000000980B000000000001000000000000000000000A7322000050BB64EDDDACD50100000000000000000200000028000000000000000000000000000000000000000000000000000000DB132D00000000000500000005000000 "C:\Users\gband\AppData\Local\Temp\7zO0057A266\setup_PSXT_MSFS_v24.5.exe"=0x5341435001000000000000000700000028000000DBBA38000000000001000000000000000000000A0021000050BB64EDDDACD5010000000000000000020000002800000000000000000000000000000000000000000000000000000084260000000000000100000001000000 "C:\Users\gband\AppData\Local\Temp\7zO4506CE03\setup_lekseecon_v10.6.4.exe"=0x534143500100000000000000070000002800000014BE70000000000001000000000000000000000A0021000050BB64EDDDACD50100000000000000000200000028000000000000000000000000000000000000000000000000000000983A0000000000000100000001000000 "C:\Users\gband\AppData\Local\Temp\7zOCE8D5B25\setup_lekseecon_v10.6.4.exe"=0x534143500100000000000000070000002800000014BE70000000000001000000000000000000000A0021000050BB64EDDDACD5010000000000000000020000002800000000000000000000000000000000000000000000000000000087350000000000000100000001000000 "C:\Program Files (x86)\lekseecon\lekseecon.exe"=0x5341435001000000000000000700000028000000005E0A000000000001000000000000000000000A7122000050BB64EDDDACD5010000000000000000020000002800000000000000000000000000000000000000000000000000000082A50100000000000700000007000000 "C:\Users\gband\AppData\Local\Temp\7zO0EA6C0F9\setup.exe"=0x53414350010000000000000007000000280000008A1C0E010000000001000000000000000000000A0021000050BB64EDDDACD50100000000000000000200000028000000000000000000000000000000000000000000000000000000E16F0000000000000100000001000000 "C:\Users\gband\AppData\Local\Temp\7zO499794F2\setup_PSXT_MSFS_v24.5.exe"=0x5341435001000000000000000700000028000000DBBA38000000000001000000000000000000000A0021000050BB64EDDDACD5010000000000000000020000002800000000000000000000800000000000000000000000000000000006260000000000000100000001000000 "C:\Users\gband\AppData\Local\Apps\2.0\LK0QAA7C.X1D\6W48N25K.TVN\prem..tion_0000000000000000_0001.0001_070ad8049f315910\PremCARS.exe"=0x5341435001000000000000000700000028000000008213000000000001000000000000000000000A7522000050BB64EDDDACD50100000000000000000200000028000000000000000000000000000200000000000000000000000000B69B1000000000000200000002000000 "C:\Users\gband\AppData\Local\Microsoft\OneDrive\21.129.0627.0002\FileSyncConfig.exe"=0x5341435001000000000000000700000028000000687B090032F9090001000000000000000000000A0021000050BB64EDDDACD5010000000100000000 "C:\Users\gband\AppData\Local\Programs\VASystem\VAS-ACARS\app-3.0.5\vendor\electron\VAS-ACARS-UI.exe"=0x534143500100000000000000070000002800000000B886070000000001000000000000000000000A0021000050BB64EDDDACD5010000000000000000 "C:\Users\gband\AppData\Local\Programs\VASystem\VAS-ACARS\vas-acars-updater.exe"=0x5341435001000000000000000700000028000000007088010000000001000000000000000000000A6320000050BB64EDDDACD5010000000000000000020000002800000000000000000000000000000000000000000000000000000045F44800000000000400000004000000 "C:\Users\gband\AppData\Local\Temp\7zO015476BD\FS2Crew Pushback Express v2.1.exe"=0x534143500100000000000000070000002800000077FAC203000000000100000000000000000001060001000050BB64EDDDACD5010000000000000000020000002800000000000000000000400000000000000000000000000000000093400000000000000100000001000000 "C:\Users\gband\AppData\Local\Programs\Push Back Recorder\unins000.exe"=0x53414350010000000000000007000000280000003D5C2E000000000003000000000000000000000A0021000050BB64EDDDACD501000000000000000005000000100000000000000000000000000000000000000002000000280000000000000000000000000000000000000000000000000000002C100000000000000100000001000000 "C:\Program Files\RealTrafficLauncher\unins000.exe"=0x5341435001000000000000000700000028000000A5260B000000000003000000000000000000000A0021000050BB64EDDDACD501000000000000000002000000280000000000000000000000000000000000000000000000000000002D100000000000000100000001000000 "C:\PSXT_MSFS\unins000.exe"=0x53414350010000000000000007000000280000004DB327000000000003000000000000000000000A0021000050BB64EDDDACD5010000000000000000020000002800000000000000000000000000000000000000000000000000000046110000000000000100000001000000 "C:\Pilot2ATC_2018_x64\unins000.exe"=0x53414350010000000000000007000000280000004B5912000000000003000000000000000000000A0021000050BB64EDDDACD50100000000000000000200000028000000000000000000000000000000000000000000000000000000230F0000000000000200000002000000 "C:\PPG_MSFS\unins000.exe"=0x53414350010000000000000007000000280000004DB327000000000003000000000000000000000A0021000050BB64EDDDACD5010000000000000000050000001000000000000000000000000000000000000000020000002800000000000000000000000000000000000000000000000000000027110000000000000100000001000000 "C:\Users\gband\AppData\Local\Temp\7zO0A836C4F\FS2Crew Pushback Express v2.1.exe"=0x534143500100000000000000070000002800000077FAC203000000000100000000000000000001060001000050BB64EDDDACD50100000000000000000200000028000000000000000000004000000000000000000000000000000000C2330000000000000100000001000000 "C:\Users\gband\AppData\Local\Discord\Update.exe"=0x5341435001000000000000000700000028000000A81217003785170001000000000000000000000A7522000050BB64EDDDACD50100000000000000000200000028000000000000000000000000000000000000000000000000000000E2040000000000000400000004000000 "C:\Users\gband\AppData\Local\Temp\7zO88E49F50\MSFSLayoutGenerator.exe"=0x5341435001000000000000000700000028000000009005000000000001000000000000000000000A6322000050BB64EDDDACD50100000000000000000200000028000000000000000000000000000000000000000000000000000000A3400000000000000100000001000000 "D:\MFS2020\Community\captainsim-aircraft-m772\MSFSLayoutGenerator.exe"=0x5341435001000000000000000700000028000000009005000000000001000000000000000000000A6322000050BB64EDDDACD50100000000000000000500000010000000000000000000000000000000000000000200000050000000000000000000000000000000000000000000000000000000A50900000000000008000000070000000000000000000040000000000000000000000000000000004F1A0000000000000100000000000000 "C:\REX Download Manager\rexdownloadmanagerlite.exe"=0x534143500100000000000000070000002800000000820C000000000001000000000000000000000A7122000050BB64EDDDACD50100000000000000000200000028000000000000000000004000000000000000000000000000000000A3620300000000000100000001000000 "C:\rexdownload\install\rexinstaller.exe"=0x5341435001000000000000000700000028000000026622000000000001000000000000000000000A0021000050BB64EDDDACD50100000000000000000200000028000000000000000000004000000000000000000000000000000000EA5D0100000000000100000001000000 "C:\Users\gband\AppData\Local\Temp\7zO08A6A857\rexinstaller.exe"=0x5341435001000000000000000700000028000000027023000000000001000000000000000000000A0021000050BB64EDDDACD501000000000000000005000000100000000000000000000000000000000000000002000000280000000000000000000040000000000000000000000000000000001A010000000000000100000001000000 "C:\Users\gband\AppData\Local\Temp\7zO08A6C998\rexinstaller.exe"=0x5341435001000000000000000700000028000000027023000000000001000000000000000000000A0021000050BB64EDDDACD501000000000000000005000000100000000000000000000000000000000000000002000000280000000000000000000040000000000000000000000000000000007D000000000000000100000001000000 "C:\Users\gband\AppData\Local\Temp\7zO08A83359\rexinstaller.exe"=0x5341435001000000000000000700000028000000027023000000000001000000000000000000000A0021000050BB64EDDDACD50100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000004000000000000000000000000000000000BC000000000000000100000001000000 "C:\Users\gband\AppData\Local\Temp\7zO08A2D1CA\rexinstaller.exe"=0x5341435001000000000000000700000028000000027023000000000001000000000000000000000A0021000050BB64EDDDACD501000000000000000005000000100000000000000000000000000000000000000002000000280000000000000000000040000000000000000000000000000000007D000000000000000100000001000000 "C:\Users\gband\Desktop\rexinstaller.exe"=0x5341435001000000000000000700000028000000027023000000000001000000000000000000000A0021000050BB64EDDDACD501000000000000000002000000280000000000000000000040000000000000000000000000000000003C250000000000000100000001000000 "C:\Users\gband\Desktop\parallel42-skypark-v2021-28-4-2\Transponder\Launcher.exe"=0x534143500100000000000000070000002800000020F90200234F030001000000000000000000000A7522000050BB64EDDDACD501000000000000000005000000100000000000000000000000000000000000000002000000500000000000000000000040000000000000000000000000000000001A280000000000000100000001000000000000000000000000000000000000000000000000000000D9370000000000000400000000000000 "C:\Users\gband\Desktop\parallel42-skypark-v2021-28-4-2\Transponder\Transponder.exe"=0x53414350010000000000000007000000280000000046E6020000000001000000000000000000000A6322000050BB64EDDDACD501000000000000000005000000100000000000000000000000000000000000000002000000500000000000000000000000000000000000000000000000000000001CB60100000000001A00000017000000000000000000004000000000000000000000000000000000FA000000000000000100000000000000 "C:\Users\gband\Desktop\parallel42-skypark-v2021-28-4-2\Skypad\Skypad.exe"=0x534143500100000000000000070000002800000020C11E0860DB1E0801000000000000000000000A0021000050BB64EDDDACD5010000000000000000 "C:\Users\gband\Downloads\PACX_Installer (1).exe"=0x5341435001000000000000000700000028000000903F251A5422261A01000000000000000000000A0021000050BB64EDDDACD5010000000000000000020000002800000000000000000000000000000000000000000000000000000002050000000000000100000001000000 "C:\Users\gband\AppData\Local\Microsoft\OneDrive\21.139.0711.0001\FileSyncConfig.exe"=0x53414350010000000000000007000000280000008075090045E2090001000000000000000000000A0021000050BB64EDDDACD5010000000100000000 "C:\Program Files\WindowsApps\microsoft.549981c3f5f10_3.2106.14307.0_x64__8wekyb3d8bbwe\Win32Bridge.Server.exe"=0x5341435001000000000000000700000028000000008406000000000001000000000000000000000A7322000050BB64EDDDACD501000000000000000002000000280000000000000000000000000000000000000000000000000000006639A701000000002100000021000000 "C:\Users\gband\Downloads\325289AEDD75.TorrentRTFREE_qtx9tqphctw9r!App\Downloads\P2ATC 2.5.0.3\Cracked EXE\Pilot2ATC_2018.exe"=0x534143500100000000000000070000002800000000D644000000000001000000000000000000000A7322000050BB64EDDDACD50100000000000000000200000028000000000000000000000000020000000000000000000000000000671B0000000000000300000003000000 "C:\ProgramData\NVIDIA Corporation\Downloader\04888dcd5471a13b5963ce4794b207b2_extracted\setup.exe"=0x534143500100000000000000070000002800000080DC070061AA080001000000000000000000000A0021000050BB64EDDDACD5010000000000000000020000002800000000000000800000400000000000000000000000000000000042C90200000000000100000001000000 "C:\Users\gband\AppData\Local\Apps\2.0\LK0QAA7C.X1D\6W48N25K.TVN\prem..tion_0000000000000000_0001.0001_0808f77b9ab9cb50\PremCARS.exe"=0x5341435001000000000000000700000028000000008213000000000001000000000000000000000A7522000050BB64EDDDACD5010000000000000000020000002800000000000000000000000000000000000000000000000000000055380000000000000100000001000000 "C:\Users\gband\Documents\Luke Air\AirTool\AirTool.exe"=0x53414350010000000000000007000000280000000028DE000000000001000000000000000000000A6522000050BB64EDDDACD5010000000000000000020000002800000000000000000000000000000000000000000000000000000071B74A00000000000200000002000000 "C:\Program Files (x86)\lekseecon\unins000.exe"=0x5341435001000000000000000700000028000000211E0B000000000003000000000000000000000A0021000050BB64EDDDACD501000000000000000002000000280000000000000000000000000000000000000000000000000000007A100000000000000100000001000000 "C:\Users\gband\Desktop\pilot2atc-pilot2atc-v2-6-2-3\setupP2A_2623_x64_R2_with_Navigraph_1801.exe"=0x5341435001000000000000000700000028000000C7A53D0B0000000001000000000000000000000A0021000050BB64EDDDACD50100000000000000000200000028000000000000000000004000000000000000000000000000000000C0770000000000000100000001000000 "C:\Program Files\WindowsApps\64343GTDocStudio.OfficeDocOpener_3.2.23.0_x86__3h5nez1g3qt2c\program\soffice.exe"=0x5341435001000000000000000700000028000000001A0100FC8C010001000000000000000000000A0021000050BB64EDDDACD50100000000000000000200000028000000000000000000000000000000000000000000000000000000D54F0000000000000100000001000000 "C:\Users\gband\Desktop\Parallel 42\The Skypark\Transponder\Transponder.exe"=0x534143500100000000000000070000002800000000BCE9020000000001000000000000000000000A6322000050BB64EDDDACD50100000000000000000500000010000000000000000000000000000000000000000200000050000000000000000000000000000000000000000000000000000000BBE0D001000000000200000002000000000000000000004000000000000000000000000000000000553BC500000000000100000000000000 "C:\Users\gband\Desktop\Parallel 42\The Skypark\Transponder\Launcher.exe"=0x534143500100000000000000070000002800000020F902009814030001000000000000000000000A7522000050BB64EDDDACD50100000000000000000500000010000000000000000000000000000000000000000200000050000000000000000000000000000000000000000000000000000000EBE26000000000000100000001000000000000000000004000000000000000000000000000000000E4516700000000000200000000000000 "C:\Users\gband\Desktop\Parallel 42\The Skypark\Skypad\Skypad.exe"=0x534143500100000000000000070000002800000020C11E0860DB1E0801000000000000000000000A0021000050BB64EDDDACD5010000000000000000 "C:\Users\gband\AppData\Local\Temp\7zO476A08B7\FS2Crew Pushback Express v2.1.exe"=0x534143500100000000000000070000002800000077FAC203000000000100000000000000000001060001000050BB64EDDDACD5010000000000000000020000002800000000000000000000400000000000000000000000000000000081360000000000000100000001000000 "C:\Program Files\WindowsApps\WuhanNetPowerTechnologyCo.3322537A536FD_2.9.0.0_x86__63m8b6nby1dvp\NetPowerZip\NetPowerZip.exe"=0x5341435001000000000000000700000028000000004A44000000000001000000000000000000000A6122000050BB64EDDDACD501000000000000000002000000280000000000000000000000000000000000000000000000000000007CBB0100000000000200000002000000 "C:\Users\gband\AppData\Local\Microsoft\OneDrive\21.150.0725.0001\FileSyncConfig.exe"=0x534143500100000000000000070000002800000068810900284F0A0001000000000000000000000A0021000050BB64EDDDACD5010000000100000000 "C:\Users\gband\Desktop\Install_FSUIPC7\Install_FSUIPC7.exe"=0x53414350010000000000000007000000280000005CA20A020000000001000000000000000000000A0021000050BB64EDDDACD5010000000000000000020000002800000000000000000000400000000000000000000000000000000013720000000000000300000003000000 "C:\Users\gband\AppData\Local\Temp\7zOCC9952B5\FS2Crew FBW A32NX.exe"=0x5341435001000000000000000700000028000000FA7EB60C000000000100000000000000000001060001000050BB64EDDDACD50100000000000000000200000028000000000000000000004000000000000000000000000000000000E9020100000000000100000001000000 "C:\Users\gband\AppData\Local\Temp\7zO0035CD36\FS2Crew Pushback Express.exe"=0x53414350010000000000000007000000280000004B6C6804000000000100000000000000000001060001000050BB64EDDDACD50100000000000000000200000028000000000000000000004000000000000000000000000000000000194A0000000000000100000001000000 "C:\Users\gband\Downloads\vas-acars-setup (2).exe"=0x5341435001000000000000000700000028000000007088010000000001000000000000000000000A6320000050BB64EDDDACD50100000000000000000200000050000000000000000000000000000000000000000000000000000000F8C20200000000000100000001000000000000000000004000000000000000000000000000000000C3FE0000000000000100000000000000 "C:\Program Files\Windows NT\Accessories\wordpad.exe"=0x534143500100000000000000070000002800000000B02E008C762F0001000000010000000000000A6322000050BB64EDDDACD5010000000000000000 "C:\Users\gband\Downloads\fs2crew-fbw-a32nx-v1-0-0-fixed-crack\FS2Crew FBW A32NX.exe"=0x5341435001000000000000000700000028000000FA7EB60C000000000100000000000000000001060001000050BB64EDDDACD5010000000000000000020000002800000000000000000000400000000000000000000000000000000022720000000000000100000001000000 "C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_3.2108.25001.0_x64__8wekyb3d8bbwe\Win32Bridge.Server.exe"=0x5341435001000000000000000700000028000000008406000000000001000000000000000000000A7322000050BB64EDDDACD50100000000000000000200000028000000000000000000000000000000000000000000000000000000DE6FEE01000000003500000035000000 "C:\Users\gband\AppData\Local\Apps\2.0\LK0QAA7C.X1D\6W48N25K.TVN\prem..tion_0000000000000000_0001.0001_f051bff25919ed50\PremCARS.exe"=0x5341435001000000000000000700000028000000008213000000000001000000000000000000000A7522000050BB64EDDDACD50100000000000000000200000028000000000000000000008000000000000000000000000000000000BD1F0000000000000100000001000000 "C:\Users\gband\Desktop\FS2Crew FBW A32NX.exe"=0x5341435001000000000000000700000028000000FA7EB60C000000000100000000000000000001060001000050BB64EDDDACD50100000000000000000200000028000000000000000000004000000000000000000000000000000000765F0000000000000100000001000000 "C:\Users\gband\AppData\Local\Temp\7zO051A5498\FS2Crew Pushback Express v2.1.exe"=0x534143500100000000000000070000002800000077FAC203000000000100000000000000000001060001000050BB64EDDDACD5010000000000000000020000002800000000000000000000400000000000000000000000000000000023360000000000000100000001000000 "C:\Users\gband\AppData\Local\Temp\7zO051B2C6A\FS2Crew Pushback Express v2.1.exe"=0x534143500100000000000000070000002800000077FAC203000000000100000000000000000001060001000050BB64EDDDACD5010000000000000000 "C:\Users\gband\AppData\Local\Temp\7zO43B395A1\FS2Crew Pushback Express v2.1.exe"=0x534143500100000000000000070000002800000077FAC203000000000100000000000000000001060001000050BB64EDDDACD5010000000000000000020000002800000000000000000000400000000000000000000000000000000029300000000000000100000001000000 "C:\Users\gband\AppData\Local\Temp\7zO4F963A52\FS2Crew FBW A32NX.exe"=0x5341435001000000000000000700000028000000FA7EB60C000000000100000000000000000001060001000050BB64EDDDACD501000000000000000002000000280000000000000000000040000000000000000000000000000000009B020100000000000100000001000000 "C:\Users\gband\AppData\Local\Temp\7zO84327993\FS2Crew Pushback Express.exe"=0x53414350010000000000000007000000280000004B6C6804000000000100000000000000000001060001000050BB64EDDDACD50100000000000000000200000028000000000000000000004000000000000000000000000000000000793A0000000000000100000001000000 "C:\Users\gband\AppData\Local\Temp\7zOCB569F67\Setup.exe"=0x53414350010000000000000007000000280000003825941F8C7F941F01000000000000000000000A0021000050BB64EDDDACD50100000000000000000200000028000000000000000000004000000000000000000000000000000000FA850300000000000100000001000000 "C:\Users\gband\AppData\Local\Temp\7zOC46790B6\MarvelousDesigner10_Personal_6_0_617_Installer_x64.exe"=0x534143500100000000000000070000002800000028C57D4BFC177E4B0100000000000000000001060001000050BB64EDDDACD50100000000000000000200000028000000000000000000004000000000000000000000000000000000889D0000000000000100000001000000 "C:\Program Files\Marvelous Designer 10 Personal\MarvelousDesigner10_Personal_x64.exe"=0x5341435001000000000000000700000028000000D5E089029AE4890201000000000000000000000A7322000050BB64EDDDACD50100000000000000000200000028000000000000000000000000000000000000000000000000000000168A0200000000000100000001000000 "C:\Users\gband\AppData\Local\Microsoft\OneDrive\21.160.0808.0002\FileSyncConfig.exe"=0x5341435001000000000000000700000028000000808F09005D90090001000000000000000000000A0021000050BB64EDDDACD5010000000100000000 "C:\Users\gband\Downloads\utweb_installer.exe"=0x5341435001000000000000000700000028000000783F42019575420101000000000000000000000A0021000050BB64EDDDACD50100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000004000000000000000000000000000000000BACE0000000000000200000002000000 "E:\Games\Nouveau dossier\JEUX\Tropico 6 [FitGirl Repack]\setup.exe"=0x5341435001000000000000000700000028000000A4CC5A00000000000100000000000000000001060001000050BB64EDDDACD501000000000000000002000000280000000000000000000040000000000000000000000000000000009E5A2200000000000100000001000000 "E:\Games\Nouveau dossier\JEUX\murder\setup.exe"=0x5341435001000000000000000700000028000000B8A33B00000000000100000000000000000001060001000050BB64EDDDACD50100000000000000000200000028000000000000000000004000000000000000000000000000000000C4DB0B00000000000100000001000000 "E:\Games\Nouveau dossier\Murder Mystery Machine\Murder Mystery Machine.exe"=0x534143500100000000000000070000002800000000CA09000000000001000000000000000000000A0021000050BB64EDDDACD5010000000000000000020000002800000000000000000000000000000000000000000000000000000088A22B00000000000200000002000000 "SIGN.MEDIA=C03D1B1E setup.exe"=0x5341435001000000000000000700000028000000A9B93800000000000100000000000000000001060001000050BB64EDDDACD50100000000000000000200000028000000000000000000004000000000000000000000000000000000D58E1D00000000000100000001000000 "E:\Games\Nouveau dossier\JEUX\Life is Strange - True Colors [FitGirl Repack]\setup.exe"=0x5341435001000000000000000700000028000000A4CA4D00000000000100000000000000000001060001000050BB64EDDDACD50100000000000000000200000028000000000000000000004000000000000000000000000000000000C2900E00000000000100000001000000 "E:\Games\Nouveau dossier\JEUX\Cyberpunk 2077 [FitGirl Repack]\setup.exe"=0x53414350010000000000000007000000280000003CE35700000000000100000000000000000001060001000050BB64EDDDACD50100000000000000000200000028000000000000000000004000000000000000000000000000000000B998B100000000000100000001000000 "E:\Games\Nouveau dossier\Cyberpunk 2077\bin\x64\Cyberpunk2077.exe"=0x5341435001000000000000000700000028000000C894EA03CE07EB0301000000000000000000000A7320000050BB64EDDDACD501000000000000000002000000280000000000000020000060000000000000000000000000000000006179BA01000000001200000012000000 "C:\Users\gband\AppData\Local\Apps\2.0\LK0QAA7C.X1D\6W48N25K.TVN\prem..tion_0000000000000000_0001.0001_e385e285e656f810\PremCARS.exe"=0x534143500100000000000000070000002800000000E811000000000001000000000000000000000A7522000050BB64EDDDACD5010000000000000000 "C:\Users\gband\AppData\Local\Microsoft\OneDrive\21.170.0822.0002\FileSyncConfig.exe"=0x534143500100000000000000070000002800000078B50900B6220A0001000000000000000000000A0021000050BB64EDDDACD5010000000100000000 "C:\Users\gband\AppData\Local\Apps\2.0\LK0QAA7C.X1D\6W48N25K.TVN\neof..tion_0000000000000000_0003.000b_53b5cd216c4f9983\NeoFly.exe"=0x534143500100000000000000070000002800000000C21A020000000001000000000000000000000A7322000050BB64EDDDACD50100000000000000000200000028000000000000000000000000000000000000000000000000000000625D0000000000000100000001000000 "C:\Users\gband\AppData\Local\Microsoft\OneDrive\21.180.0905.0007\FileSyncConfig.exe"=0x534143500100000000000000070000002800000070A90900B1100A0001000000000000000000000A0021000050BB64EDDDACD5010000000100000000 "C:\Users\gband\Downloads\rexwxforce_20210921\rexinstaller.exe"=0x5341435001000000000000000700000028000000024E23000000000001000000000000000000000A0021000050BB64EDDDACD501000000000000000002000000280000000000000000000040000000000000000000000000000000007DA40000000000000100000001000000 "C:\ProgramData\NVIDIA Corporation\Downloader\bf294bf950055034992a1d638969ff91_extracted\setup.exe"=0x534143500100000000000000070000002800000080DC07006660080001000000000000000000000A0021000050BB64EDDDACD5010000000000000000020000002800000000000000800000400000000000000000000000000000000075950100000000000100000001000000 "C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_3.2109.6305.0_x64__8wekyb3d8bbwe\Win32Bridge.Server.exe"=0x5341435001000000000000000700000028000000008406000000000001000000000000000000000A7322000050BB64EDDDACD50100000000000000000200000028000000000000000000000000000000000000000000000000000000B6499302000000003200000032000000 "C:\Users\gband\AppData\Local\Apps\2.0\LK0QAA7C.X1D\6W48N25K.TVN\prem..tion_0000000000000000_0001.0001_d2c1873d857239d0\PremCARS.exe"=0x534143500100000000000000070000002800000000E611000000000001000000000000000000000A7522000050BB64EDDDACD501000000000000000002000000280000000000000000000000100002000000000000000000000000002B6ABE01000000001F0000001F000000 "D:\MFS2020\Community\virtualcol-aircraft-emb170\SimObjects\Airplanes\Vcolemb175_aircraft\panel\MSFSLayoutGenerator.exe"=0x5341435001000000000000000700000028000000009005000000000001000000000000000000000A6322000050BB64EDDDACD50100000000000000000200000028000000000000000000000000000000000000000000000000000000C31E0000000000000300000003000000 "D:\MFS2020\Community\virtualcol-aircraft-emb170\MSFSLayoutGenerator.exe"=0x5341435001000000000000000700000028000000009005000000000001000000000000000000000A6322000050BB64EDDDACD5010000000000000000020000002800000000000000000000000000000000000000000000000000000033020000000000000100000001000000 "C:\Users\gband\Desktop\PES\eFootball PES 2021 [FitGirl Repack]\setup.exe"=0x5341435001000000000000000700000028000000FC276700000000000100000000000000000001060001000050BB64EDDDACD5010000000000000000020000002800000000000000000000400000020000000000000000000000000027511F00000000000200000002000000 "E:\Games\Nouveau dossier\eFootball PES 2021\PES2021.exe"=0x534143500100000000000000070000002800000000CE571B0000000001000000000000000000000A0021000050BB64EDDDACD501000000000000000005000000100000000000000000000000000000002000000002000000280000000000000020000060000000000000000000000000000000004A7C5B00000000002000000020000000 "C:\Users\gband\AppData\Local\Temp\Temp1_sider-7.1.4.zip\sider-7.1.4\sider.exe"=0x5341435001000000000000000700000028000000009607000000000001000000000000000000000A7320000050BB64EDDDACD50100000000000000000200000028000000000000000000000000000000000000000000000000000000BC0D0000000000000100000001000000 "E:\Games\Nouveau dossier\eFootball PES 2021\sider.exe"=0x5341435001000000000000000700000028000000009607000000000001000000000000000000000A7320000050BB64EDDDACD50100000000000000000500000010000000000000000000000000000000200000000200000078000000000000002000006000000000000000000000000000000000A152DD000000000062000000620000000000000000000040000000000000000000000000000000000B23100000000000040000000000000000000000000000000000000000000000000000000000000061471C00000000000C00000000000000 "E:\Games\Nouveau dossier\eFootball PES 2021\eFootball PES2021 DpFileList Generator.exe"=0x534143500100000000000000070000002800000000B075010000000001000000000000000000000A7522000050BB64EDDDACD50100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000004000000000000000000000000000000000CFCE0200000000000700000007000000 "C:\Users\gband\Documents\sider-7.1.4\sider.exe"=0x5341435001000000000000000700000028000000009607000000000001000000000000000000000A7320000050BB64EDDDACD50100000000000000000500000010000000000000000000000000000000200000000200000078000000000000002000006000000000000000000000000000000000A7115500000000001500000015000000000000000000004000000000000000000000000000000000E6760000000000000C000000000000000000000000000000000000000000000000000000000000007B7A0100000000000300000000000000 "C:\Users\gband\Documents\sider-6.4.1\sider.exe"=0x5341435001000000000000000700000028000000009607000000000001000000000000000000000A7320000050BB64EDDDACD50100000000000000000500000010000000000000000000000000000000000000000200000050000000000000000000004000000000000000000000000000000000CFE1010000000000030000000100000000000000000000000000000000000000000000000000000015280100000000000100000000000000 "C:\Users\gband\AppData\Local\Microsoft\OneDrive\21.196.0921.0007\FileSyncConfig.exe"=0x534143500100000000000000070000002800000068B909002C4B0A0001000000000000000000000A0021000050BB64EDDDACD5010000000100000000 "E:\Games\Nouveau dossier\eFootball PES 2021\_Redist\QuickSFV.EXE"=0x534143500100000000000000070000002800000000940100A82B02000100000000000000000000067102000050BB64EDDDACD50100000000000000000200000028000000000000000000000000000000000000000000000000000000F60B0000000000000100000001000000 "F:\eFootball PES 2021 [FitGirl Repack]\setup.exe"=0x5341435001000000000000000700000028000000FC276700000000000100000000000000000001060001000050BB64EDDDACD501000000000000000002000000280000000000000000000040000000000000000000000000000000009B271E00000000000100000001000000 "C:\Users\gband\Downloads\Far.Cry.6.Ultimate.Edition.Uplay.Rip-InsaneRamZes\Far Cry 6\bin\FarCry6.exe"=0x5341435001000000000000000700000028000000501B02000958020001000000000000000000000A7320000050BB64EDDDACD5010000000000000000020000002800000000000000000000001000000000000000000000000000000019280000000000000200000002000000 "C:\Users\gband\Downloads\Far.Cry.6.Ultimate.Edition.Uplay.Rip-InsaneRamZes\Far Cry 6\bin_plus\FarCry6.exe"=0x5341435001000000000000000700000028000000501B0200BCED020001000000000000000000000A7320000050BB64EDDDACD5010000000000000000020000002800000000000000000000001000000000000000000000000000000012170000000000000500000005000000 "C:\Users\gband\Downloads\Far.Cry.6.Ultimate.Edition.Uplay.Rip-InsaneRamZes\Far Cry 6\FarCry6.exe"=0x5341435001000000000000000700000028000000501B0200BCED020001000000000000000000000A7320000050BB64EDDDACD50100000000000000000200000028000000000000000000000000000000000000000000000000000000FD0F0000000000000200000002000000 "C:\Users\gband\Downloads\Far.Cry.6.Ultimate.Edition.Uplay.Rip-InsaneRamZes\Far Cry 6\Support\Software\GameLauncher\UplayInstaller.exe"=0x5341435001000000000000000700000028000000706316079A48170701000000000000000000000A0021000050BB64EDDDACD5010000000000000000 "C:\Users\gband\AppData\Local\Microsoft\OneDrive\21.196.0921.0007\Microsoft.SharePoint.exe"=0x534143500100000000000000070000002800000068110B00656E0B0001000000000000000000000A0021000050BB64EDDDACD50100000000000000000200000028000000000000000000000000000000000000000000000000000000B32B0000000000000B0000000B000000 "C:\ProgramData\Origin\SelfUpdate\Staged\OriginThinSetupInternal.exe"=0x5341435001000000000000000700000028000000D09C5B018B925C0101000000000000000000000A0021000050BB64EDDDACD50100000000000000000200000028000000000000000000008000000000000000000000000000000000E8510000000000000100000001000000 "C:\Users\gband\AppData\Local\Temp\7zO0CF171FA\FIFA Mod Manager v1.0.8.exe"=0x5341435001000000000000000700000028000000C5800F0D0000000001000000000000000000000A0021000050BB64EDDDACD501000000000000000002000000280000000000000000000000000000000000000000000000000000006F120000000000000300000003000000 "C:\Users\gband\Downloads\FIFA Editor Tool v1.0.8\FIFA Editor Tool v1.0.8.exe"=0x5341435001000000000000000700000028000000CA4379120000000001000000000000000000000A0021000050BB64EDDDACD501000000000000000002000000280000000000000000000000000000000000000000000000000000003A2B1300000000000100000001000000 "E:\SteamLibrary\steamapps\common\FIFA 21\FIFA21.exe"=0x534143500100000000000000070000002800000030631722ABA9172201000000000000000000000A0021000050BB64EDDDACD50100000000000000000200000028000000000000000000000000000000000000000000000000000000C5010000000000000300000003000000 "C:\Users\gband\Documents\Paulv2k4 FMT - v12.3\FMT.exe"=0x534143500100000000000000070000002800000000DF120B0000000001000000000000000000000A7322000050BB64EDDDACD501000000000000000002000000280000000000000000000040000000000000000000000000000000008AD6FE01000000000300000003000000 "C:\Users\gband\Downloads\FarCry6_updated\Far Cry 6.exe"=0x5341435001000000000000000700000028000000FC334E003FD24E0001000000000000000000000A6122000050BB64EDDDACD501000000000000000002000000280000000000000000000000000000000000000000000000000000002F040800000000000100000001000000 "C:\Users\gband\AppData\Roaming\SimBrief Downloader\simbrief_updater.exe"=0x5341435001000000000000000700000028000000806D750717FE750701000000000000000000000A0021000050BB64EDDDACD50100000000000000000200000028000000000000000000004000000000000000000000000000000000063B0000000000000100000001000000 "C:\Users\gband\AppData\Local\Programs\SimBrief Downloader\SimBrief Downloader.exe"=0x5341435001000000000000000700000028000000D034D60704F9D60701000000000000000000000A0021000050BB64EDDDACD50100000000000000000200000028000000000000000000000000000000000000000000000000000000EA0DB500000000000200000002000000 "C:\Users\gband\AppData\Local\Temp\7zOCBE4118D\FS2Crew Pushback Express v1.5.exe"=0x53414350010000000000000007000000280000008F49A203000000000100000000000000000001060001000050BB64EDDDACD501000000000000000002000000280000000000000000000040000000000000000000000000000000001D370000000000000100000001000000 "C:\Users\gband\Downloads\rexwxforce_20211020\rexinstaller.exe"=0x5341435001000000000000000700000028000000025223000000000001000000000000000000000A0021000050BB64EDDDACD50100000000000000000200000028000000000000000000004000000000000000000000000000000000BA510000000000000100000001000000 "C:\Users\gband\AppData\Local\Programs\molotov\Molotov.exe"=0x5341435001000000000000000700000028000000E0DF8A07E5C58B0701000000000000000000000A0021000050BB64EDDDACD5010000000000000000 "C:\ProgramData\NVIDIA Corporation\Downloader\889b65b3c6fb71aa1a373ea9b048bec6_extracted\setup.exe"=0x534143500100000000000000070000002800000090DE0700748D080001000000000000000000000A0021000050BB64EDDDACD50100000000000000000200000028000000000000008000004000000000000000000000000000000000BDE91200000000000100000001000000 "C:\Program Files (x86)\Steam\steamapps\common\eFootball PES 2021\sider.exe"=0x5341435001000000000000000700000028000000009607000000000001000000000000000000000A7320000050BB64EDDDACD5010000000000000000050000001000000000000000000000000000000020000000020000002800000000000000200000600000000000000000000000000000000071EC1E00000000000600000006000000 "C:\Users\gband\Downloads\SmokePatch21.3.6\smokepatch21.3.6.exe"=0x5341435001000000000000000700000028000000030D6D3A000000000100000000000000000001060001000050BB64EDDDACD501000000000000000002000000280000000000000000000040000000000000000000000000000000004EDB0300000000000100000001000000 "C:\Users\gband\Documents\SmokePatch17.3.6\smokepatch17.3.6.exe"=0x53414350010000000000000007000000280000001543FD19000000000100000000000000000001060001000050BB64EDDDACD50100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000004000000000000000000000000000000000C8760300000000000100000001000000 "C:\Program Files\VS Revo Group\Revo Uninstaller\unins000.exe"=0x5341435001000000000000000700000028000000C9C514000000000003000000000000000000000A0021000050BB64EDDDACD50100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000000000000000000000000000000000000000E8250000000000000100000001000000 "C:\Users\gband\AppData\Local\Microsoft\OneDrive\21.205.1003.0005\FileSyncConfig.exe"=0x534143500100000000000000070000002800000078BF090060CF090001000000000000000000000A0021000050BB64EDDDACD5010000000100000000 "C:\Users\gband\AppData\Local\Microsoft\OneDrive\21.205.1003.0005\Microsoft.SharePoint.exe"=0x5341435001000000000000000700000028000000780F0B002EE80B0001000000000000000000000A0021000050BB64EDDDACD501000000000000000002000000280000000000000000000000000000000000000000000000000000002B250000000000000600000006000000 "E:\Games\Nouveau dossier\eFootball PES 2021\Settings.exe"=0x534143500100000000000000070000002800000000C209000000000001000000000000000000000A0021000050BB64EDDDACD501000000000000000005000000100000000000000000000000000000002000000002000000280000000000000020000060000000000000000000000000000000005D2F0000000000000100000001000000 "C:\Program Files (x86)\Steam\steamapps\common\eFootball\eFootball\Binaries\Win64\eFootball.exe"=0x5341435001000000000000000700000028000000006AD21E0000000001000000000000000000000A7320000050BB64EDDDACD501000000000000000002000000280000000000000000000000000000000000000000000000000000002D2A0000000000000A0000000A000000 "C:\Users\gband\Downloads\FSRealistic\FSRealistic.exe"=0x5341435001000000000000000700000028000000000411000000000001000000000000000000000A7322000050BB64EDDDACD50100000000000000000200000028000000000000000000000000000000000000000000000000000000BAF80300000000000300000003000000 "C:\Program Files\WindowsApps\WuhanNetPowerTechnologyCo.3322537A536FD_2.9.7.0_x86__63m8b6nby1dvp\NetPowerZip\NetPowerZip.exe"=0x534143500100000000000000070000002800000000B064000000000001000000000000000000000A6122000050BB64EDDDACD501000000000000000002000000280000000000000000000000000000000000000000000000000000009DD80000000000000200000002000000 "C:\Program Files (x86)\Steam\steamapps\common\eFootball PES 2021\PES2021.exe"=0x534143500100000000000000070000002800000000CE4B1C0000000001000000000000000000000A0021000050BB64EDDDACD5010000000000000000 "C:\Users\gband\AppData\Local\Microsoft\OneDrive\21.220.1024.0005\FileSyncConfig.exe"=0x534143500100000000000000070000002800000078BB090004430A0001000000000000000000000A0021000050BB64EDDDACD5010000000100000000 "C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.78.159.0_x86__kzf8qxf38zg5c\Skype\Skype.exe"=0x53414350010000000000000007000000280000008081CB066BB2CB0601000000000000000000000A0021000050BB64EDDDACD501000000000000000002000000280000000000000000000010000000000000000000000000000000008660F302000000000800000008000000 "C:\Users\gband\AppData\Local\Microsoft\OneDrive\21.220.1024.0005\Microsoft.SharePoint.exe"=0x5341435001000000000000000700000028000000788F0E002BE30E0001000000000000000000000A0021000050BB64EDDDACD5010000000000000000020000002800000000000000000000000000000000000000000000000000000064260000000000000E0000000E000000 "C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_3.2110.13603.0_x64__8wekyb3d8bbwe\Win32Bridge.Server.exe"=0x534143500100000000000000070000002800000000A006000000000001000000000000000000000A7322000050BB64EDDDACD5010000000000000000020000002800000000000000000000000000000000000000000000000000000090BAD101000000007C0000007C000000 "C:\Program Files\WindowsApps\HaukeGtze.7-ZipFileManagerUnofficial_1.2105.1.0_x64__6bk20wvc8rfx2\7zFM.exe"=0x534143500100000000000000070000002800000000660E000000000001000000000000000000000A0021000050BB64EDDDACD501000000000000000002000000280000000000000000000000000000000000000000000000000000006F320900000000000400000004000000 "C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exe"=0x534143500100000000000000070000002800000070C9E5004231E60001000000000000000000000A7322000050BB64EDDDACD5010000000000000000050000001000000000000000000000000000000000000000020000002800000000000000000000400000000000000000000000000000000066DA2000000000001E0000001E000000 "C:\ProgramData\NVIDIA Corporation\Downloader\eb5c0faac2ea9053fd003af47b326086\GeForce_Experience_Update_v3.24.0.123_Official_83C182.exe"=0x5341435001000000000000000700000028000000C8E4CB07F840CC070100000000000000000002060001000050BB64EDDDACD5010000000000000000020000002800000000000000000000000000000000000000000000000000000047CF0000000000000100000001000000 "C:\Users\gband\Documents\Little Navmap\littlenavmap.exe"=0x5341435001000000000000000700000028000000004A02018FE1020101000000000000000000000A7120000050BB64EDDDACD5010000000000000000050000001000000000000000000000000000000000000000020000005000000000000000000000400000000000000000000000000000000014FD020000000000010000000100000000000000000000000000000000000000000000000000000020D40500000000000300000000000000 "C:\Program Files\WindowsApps\HaukeGtze.7-ZipFileManagerUnofficial_1.2106.1.0_x64__6bk20wvc8rfx2\7zFM.exe"=0x534143500100000000000000070000002800000000680E000000000001000000000000000000000A0021000050BB64EDDDACD50100000000000000000200000028000000000000000000000000000000000000000000000000000000EA935E00000000006F0000006F000000 "C:\Program Files\WindowsApps\64343GTDocStudio.OfficeDocOpener_3.2.24.0_x86__3h5nez1g3qt2c\program\soffice.exe"=0x5341435001000000000000000700000028000000001A0100FC8C010001000000000000000000000A0021000050BB64EDDDACD5010000000000000000020000002800000000000000000000000000000000000000000000000000000038D38500000000000300000003000000 "C:\Users\gband\AppData\Roaming\uTorrent Web\utweb.exe"=0x534143500100000000000000070000002800000020B65A0082F85A0001000000000000000000000A7122000050BB64EDDDACD501000000000000000002000000280000000000000000000000000000000000000000000000000000001107B301000000000A0000000A000000 "C:\Users\gband\AppData\Local\Programs\Opera\opera.exe"=0x5341435001000000000000000700000028000000D0981F007DF61F0001000000000000000000000A0021000050BB64EDDDACD5010000000100000000 "C:\Users\gband\AppData\Local\Programs\orbx-central\Orbx Central.exe"=0x5341435001000000000000000700000028000000B88F3406561D350601000000000000000000000A0021000050BB64EDDDACD501000000000000000005000000100000000000000000000000000000000000000002000000280000000000000000000040000000000000000000000000000000005EEB2A00000000000400000004000000 "C:\Users\gband\AppData\Local\Microsoft\OneDrive\21.230.1107.0004\FileSyncConfig.exe"=0x534143500100000000000000070000002800000068C10900A94D0A0001000000000000000000000A0021000050BB64EDDDACD5010000000100000000 "C:\Users\gband\AppData\Local\Microsoft\OneDrive\21.230.1107.0004\Microsoft.SharePoint.exe"=0x534143500100000000000000070000002800000078950E0084F30E0001000000000000000000000A0021000050BB64EDDDACD501000000000000000002000000280000000000000000000000000000000000000000000000000000004C2A0000000000001F0000001F000000 "C:\Users\gband\Downloads\FS2Crew - Pushback Express v2.2.3\FS2CrewPushbackExpress_2.2.3.exe"=0x53414350010000000000000007000000280000007D640505000000000100000000000000000001060001000050BB64EDDDACD5010000000000000000020000002800000000000000000000400000000000000000000000000000000017670000000000000200000002000000 "C:\Users\gband\Downloads\FS2Crew - FBW A32NX v1.1.1\FS2CrewFlybywireA32NXProjectEdition_1.1.1.exe"=0x53414350010000000000000007000000280000009CDB740D000000000100000000000000000001060001000050BB64EDDDACD50100000000000000000200000028000000000000000000004000000000000000000000000000000000D7A20000000000000100000001000000 "C:\Users\gband\Documents\Just Flight - Air Hauler 2 for MSFS v3.00.11\AirHauler2.exe"=0x53414350010000000000000007000000280000000040A8000000000001000000000000000000000A7122000050BB64EDDDACD5010000000000000000020000002800000000000000000000400000000000000000000000000000000068CB0B00000000000100000001000000 "C:\Users\gband\AppData\Local\Apps\2.0\LK0QAA7C.X1D\6W48N25K.TVN\neof..tion_0000000000000000_0003.000d_9b30a95929896b03\NeoFly.exe"=0x53414350010000000000000007000000280000000062FC030000000001000000000000000000000A7322000050BB64EDDDACD5010000000000000000020000002800000000000000000000000000000000000000000000000000000075AB0600000000000100000001000000 "C:\Users\gband\AppData\Local\Temp\Temp1_Altitude_MSFS_2020.zip\IVAO_Pilot_MSFS2020_1.10.5b.exe"=0x534143500100000000000000070000002800000015512D060000000001000000000000000000000A0021000050BB64EDDDACD501000000000000000002000000280000000000000000000040000000000000000000000000000000007DF10800000000000300000003000000 "C:\Users\gband\AppData\Local\Temp\Temp2_Altitude_MSFS_2020.zip\IVAO_Pilot_MSFS2020_1.10.5b.exe"=0x534143500100000000000000070000002800000015512D060000000001000000000000000000000A0021000050BB64EDDDACD5010000000000000000 "C:\Users\gband\AppData\Local\Temp\Temp3_Altitude_MSFS_2020.zip\IVAO_Pilot_MSFS2020_1.10.5b.exe"=0x534143500100000000000000070000002800000015512D060000000001000000000000000000000A0021000050BB64EDDDACD50100000000000000000200000028000000000000000000004000000000000000000000000000000000815E0C00000000000100000001000000 "D:\MFS2020\IVAO\PilotUI\PilotUI.exe"=0x534143500100000000000000070000002800000000AC44000000000001000000000000000000000A7322000050BB64EDDDACD501000000000000000002000000280000000000000000000000000000000000000000000000000000002975A001000000001600000016000000 "D:\MFS2020\IVAO\PilotCore\pilot_core_fs2020.exe"=0x5341435001000000000000000700000028000000002611000000000001000000000000000000000A7322000050BB64EDDDACD50100000000000000000500000010000000000000000000000000000000000000000200000050000000000000000000000000000000000000000000000000000000CF76A0010000000018000000180000000000000000000040000000000000000000000000000000001E16C100000000000100000000000000 "C:\Users\gband\Documents\FSO\FSFO_NEXT.exe"=0x5341435001000000000000000700000028000000BDE496150000000001000000000000000000000A0021000050BB64EDDDACD501000000000000000002000000280000000000000000000040000000000000000000000000000000005C659500000000000100000001000000 "C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.79.95.0_x86__kzf8qxf38zg5c\Skype\Skype.exe"=0x5341435001000000000000000700000028000000A0E9AF060D3BB00601000000000000000000000A0021000050BB64EDDDACD5010000000000000000020000002800000000000000000000100000000000000000000000000000000078ABF307000000001400000014000000 "C:\ProgramData\NVIDIA Corporation\Downloader\a2e41ed0c293e98b896712ead86be174\GeForce_Experience_Update_v3.24.0.126_Official_BEDA87.exe"=0x53414350010000000000000007000000280000006810CB0751ADCB070100000000000000000002060001000050BB64EDDDACD5010000000000000000020000002800000000000000000000000000000000000000000000000000000087D40000000000000100000001000000 "C:\Users\gband\AppData\Local\Apps\2.0\LK0QAA7C.X1D\6W48N25K.TVN\prem..tion_0000000000000000_0001.0001_d5bbe5a2780b9090\PremCARS.exe"=0x534143500100000000000000070000002800000000E811000000000001000000000000000000000A7522000050BB64EDDDACD501000000000000000002000000280000000000000000000000000000000000000000000000000000007DC88100000000000900000009000000 "C:\ProgramData\NVIDIA Corporation\Downloader\94096d43150b862afeb41c373dffb1f7_extracted\setup.exe"=0x5341435001000000000000000700000028000000A8E20700AC43080001000000000000000000000A0021000050BB64EDDDACD50100000000000000000200000028000000000000008000004000000000000000000000000000000000EBC50100000000000100000001000000 "C:\Users\gband\Documents\Parallel 42\The Skypark\Skypad\Skypad.exe"=0x534143500100000000000000070000002800000020C11E0860DB1E0801000000000000000000000A0021000050BB64EDDDACD5010000000000000000 "C:\Users\gband\Documents\Parallel 42\The Skypark\Transponder\Transponder.exe"=0x534143500100000000000000070000002800000000BCE9020000000001000000000000000000000A6322000050BB64EDDDACD5010000000000000000 "C:\Users\gband\Downloads\ve6b\setup.exe"=0x534143500100000000000000070000002800000000260200000000000100000000000000000001057100000050BB64EDDDACD501000000C100000000 "C:\Program Files (x86)\Virtual E6-B\Ve6b.exe"=0x534143500100000000000000070000002800000000B00500643006000100000000000000000001057120000050BB64EDDDACD50100000000000000000200000028000000000000000000000000000000000000000000000000000000F9510000000000000100000001000000 "C:\Program Files (x86)\Common Files\Steam\steamservice.exe"=0x5341435001000000000000000700000028000000A8E72A00B3152B0001000000000000000000000A0021000050BB64EDDDACD50100000000000000000200000028000000000000000000004000000000000000000000000000000000F1A30000000000000400000004000000 "C:\Users\gband\AppData\Local\Programs\Navigraph Charts\Navigraph Charts.exe"=0x5341435001000000000000000700000028000000607DF605AB37F70501000000000000000000000A0021000050BB64EDDDACD5010000000000000000 "C:\Users\gband\AppData\Roaming\Microsoft Flight Simulator\Packages\IVAO\PilotCore\pilot_core_fs2020.exe"=0x5341435001000000000000000700000028000000002611000000000001000000000000000000000A7322000050BB64EDDDACD50100000000000000000200000028000000000000000000000000000000000000000000000000000000D5B9C102000000002400000024000000 "C:\Users\gband\AppData\Roaming\Microsoft Flight Simulator\Packages\IVAO\PilotUI\PilotUI.exe"=0x534143500100000000000000070000002800000000AC44000000000001000000000000000000000A7322000050BB64EDDDACD50100000000000000000200000028000000000000000000000000000000000000000000000000000000C6A7B301000000002500000025000000 "C:\Users\gband\Documents\Install_FSUIPC7\Install_FSUIPC7.exe"=0x5341435001000000000000000700000028000000B3BF48020000000001000000000000000000000A0021000050BB64EDDDACD50100000000000000000200000028000000000000000000004000000000000000000000000000000000C2B00000000000000300000003000000 "C:\Users\gband\Downloads\FSUIPC7\Install_FSUIPC7\Install_FSUIPC7.exe"=0x5341435001000000000000000700000028000000C0BC48020000000001000000000000000000000A0021000050BB64EDDDACD50100000000000000000200000028000000000000000000004000000000000000000000000000000000B83F0000000000000100000001000000 "C:\Users\gband\Downloads\rexwxforce_20211119\rexinstaller.exe"=0x534143500100000000000000070000002800000002D62F000000000001000000000000000000000A0021000050BB64EDDDACD50100000000000000000200000028000000000000000000004000000000000000000000000000000000E6F80000000000000300000003000000 "C:\Users\gband\Downloads\rexwxforce_20211217\rexinstaller.exe"=0x534143500100000000000000070000002800000002D62F000000000001000000000000000000000A0021000050BB64EDDDACD50100000000000000000200000028000000000000000000004000000000000000000000000000000000D5690000000000000100000001000000 "C:\Users\gband\Documents\FSRealistic\FSRealistic.exe"=0x5341435001000000000000000700000028000000003A11000000000001000000000000000000000A7322000050BB64EDDDACD50100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000004000000000000000000000000000000000CC6BFA01000000000300000003000000 "C:\Users\gband\AppData\Local\Temp\Temp1_MSFS2020 Map Enhancement Setup 0.0.1.exe_f1v6q.zip\MSFS2020 Map Enhancement Setup 0.0.1.exe"=0x53414350010000000000000007000000280000009E26B2050000000001000000000000000000000A0021000050BB64EDDDACD501000000000000000002000000280000000000000000000040000000000000000000000000000000003F270000000000000100000001000000 "C:\Users\gband\Downloads\FS2Crew - Pushback Express v2.2.3\FS2CrewPushbackExpressforMSFS_2.2.8.exe"=0x5341435001000000000000000700000028000000A7060604000000000100000000000000000001060001000050BB64EDDDACD501000000000000000002000000280000000000000000000040000000000000000000000000000000006A250000000000000200000002000000 "C:\Users\gband\AppData\Local\Temp\7zO80291376\FS2CrewFlybywireA32NXProjectEditionforMSFS_1.1.8.exe"=0x534143500100000000000000070000002800000021E9740D000000000100000000000000000001060001000050BB64EDDDACD50100000000000000000200000028000000000000000000004000000000000000000000000000000000EF360000000000000100000001000000 "C:\Users\gband\Downloads\FlyByWire_Installer_Setup.exe"=0x5341435001000000000000000700000028000000A8D429050000000001000000000000000000000A0021000050BB64EDDDACD50100000000000000000200000028000000000000000000000000000000000000000000000000000000E81D0000000000000100000001000000 "C:\Users\gband\AppData\Local\Programs\fbw-installer\FlyByWire Installer.exe"=0x5341435001000000000000000700000028000000007060080000000001000000000000000000000A0021000050BB64EDDDACD5010000000000000000 "C:\Users\gband\Downloads\Navigraph Navdata Center 1.0.4.exe"=0x534143500100000000000000070000002800000020B62C06660B2D0601000000000000000000000A0021000050BB64EDDDACD50100000000000000000200000028000000000000000000000000000000000000000000000000000000B1140000000000000100000001000000 "C:\Users\gband\Downloads\navigraph fms data manager.exe"=0x534143500100000000000000070000002800000010E2B30131E8B30101000000000000000000000A0021000050BB64EDDDACD50100000000000000000200000028000000000000000000000000000000000000000000000000000000674CAF00000000000200000002000000 "C:\Program Files\Navigraph\Simlink\NavigraphSimlinkSettings.exe"=0x53414350010000000000000007000000280000003055090059A7090001000000000000000000000A7322000050BB64EDDDACD501000000000000000005000000100000000000000000000000000000000000000002000000280000000000000000000040000000000000000000000000000000004C2A0000000000000100000001000000 "C:\Users\gband\AppData\Local\Temp\Temp1_MSFS2020 Map Enhancement Setup 0.1.0.exe_8M_Io.zip\MSFS2020 Map Enhancement Setup 0.1.0.exe"=0x5341435001000000000000000700000028000000BD93B3050000000001000000000000000000000A0021000050BB64EDDDACD501000000000000000002000000280000000000000000000040000000000000000000000000000000000F3C0000000000000100000001000000 "C:\Users\gband\AppData\Local\Temp\Temp1_MSFS2020 Map Enhancement Setup 3.0.0.exe_HXO8N.zip\MSFS2020 Map Enhancement Setup 3.0.0.exe"=0x53414350010000000000000007000000280000004294B3050000000001000000000000000000000A0021000050BB64EDDDACD501000000000000000002000000280000000000000000000040000000000000000000000000000000003D440000000000000100000001000000 "C:\Users\gband\AppData\Local\Apps\2.0\LK0QAA7C.X1D\6W48N25K.TVN\fsec..tion_110e3500b3fd2937_0001.0003_3da458988171929d\FSEconomy.exe"=0x5341435001000000000000000700000028000000C0DB0B00C9460C0001000000000000000000000A7122000050BB64EDDDACD501000000000000000002000000280000000000000000000000000000000000000000000000000000008E120000000000000100000001000000 "C:\Users\gband\Downloads\[ OxTorrent.pe ] ccsetup Version 5.83.9050\CCleaner64.exe"=0x53414350010000000000000007000000280000008004170226B0170201000000000000000000000A0021000050BB64EDDDACD501000000000000000002000000280000000000000000000040000000000000000000000000000000009D8B0200000000000100000001000000 "C:\Users\gband\AppData\Local\Temp\Temp1_MSFS2020 Map Enhancement Setup 3.0.1.exe_waiO1.zip\MSFS2020 Map Enhancement Setup 3.0.1.exe"=0x53414350010000000000000007000000280000009E97B3050000000001000000000000000000000A0021000050BB64EDDDACD501000000000000000002000000280000000000000000000040000000000000000000000000000000000F3C0000000000000100000001000000 "C:\Users\gband\Downloads\TOPCAT_2.74_Setup.exe"=0x534143500100000000000000070000002800000098A14A0183B24A010100000000000000000000067100000050BB64EDDDACD501000000000000000002000000280000000000000000080000000000000000000000000000000000007B240100000000000100000001000000 "C:\Users\gband\AppData\Local\Temp\Temp1_MSFS2020 Map Enhancement Setup 3.0.3.exe_Rurk5.zip\MSFS2020 Map Enhancement Setup 3.0.3.exe"=0x53414350010000000000000007000000280000005358C5050000000001000000000000000000000A0021000050BB64EDDDACD501000000000000000002000000280000000000000000000040000000000000000000000000000000007B590000000000000100000001000000 "C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_3.2111.12605.0_x64__8wekyb3d8bbwe\Win32Bridge.Server.exe"=0x534143500100000000000000070000002800000000A806000000000001000000000000000000000A7322000050BB64EDDDACD50100000000000000000200000028000000000000000000000000000000000000000000000000000000EF948102000000004100000041000000 "C:\Users\gband\Downloads\MSFS2020 Map Enhancement Setup 3.0.5.exe"=0x5341435001000000000000000700000028000000BE27CA050000000001000000000000000000000A0021000050BB64EDDDACD501000000000000000002000000280000000000000000000040000000000000000000000000000000006E5B0000000000000100000001000000 "C:\Program Files\MSFS2020 Map Enhancement\MSFS2020 Map Enhancement.exe"=0x534143500100000000000000070000002800000000021E080000000001000000000000000000000A0021000050BB64EDDDACD501000000000000000002000000280000000000000020000060000000000000000000000000000000000B4B4802000000000500000005000000 "C:\Users\gband\Downloads\[ OxTorrent.pe ] ccsetup Version 5.83.9050\CCleaner.exe"=0x53414350010000000000000007000000280000008094BC01F4BDBC0101000000000000000000000A0021000050BB64EDDDACD50100000000000000000200000028000000000000000000000000000000000000000000000000000000468E0000000000000100000001000000 "C:\Users\gband\Documents\Addons linker\MSFS_AddonsLinker.exe"=0x5341435001000000000000000700000028000000006415000000000001000000000000000000000A7322000050BB64EDDDACD501000000000000000005000000100000000000000000000000000000002000000002000000280000000000000020000060000000000000000000000000000000008E547C00000000001000000010000000 "C:\Users\gband\AppData\Local\Temp\7zO86C55340\FS2CrewRAASProfessionalforMSFS_1.0.8.exe"=0x534143500100000000000000070000002800000078B68B02000000000100000000000000000001060001000050BB64EDDDACD50100000000000000000200000028000000000000000000004000000000000000000000000000000000C8180000000000000100000001000000 "C:\Users\gband\AppData\Local\Temp\7zO86C01F41\FS2CrewRAASProfessionalforMSFS_1.0.8.exe"=0x534143500100000000000000070000002800000078B68B02000000000100000000000000000001060001000050BB64EDDDACD5010000000000000000020000002800000000000000000000400000000000000000000000000000000059200000000000000100000001000000 "C:\Users\gband\AppData\Local\Temp\7zO42F350F7\FS2CrewFlybywireA32NXProjectEditionforMSFS_1.1.9.exe"=0x5341435001000000000000000700000028000000E0EA740D000000000100000000000000000001060001000050BB64EDDDACD50100000000000000000200000028000000000000000000004000000000000000000000000000000000AF8C0000000000000100000001000000 "C:\Users\gband\AppData\Local\Temp\7zO8EC8AD1A\FS2CrewPushbackExpressforMSFS_2.2.12.exe"=0x534143500100000000000000070000002800000071150604000000000100000000000000000001060001000050BB64EDDDACD50100000000000000000200000028000000000000000000004000000000000000000000000000000000CD2C0000000000000100000001000000 "C:\Users\gband\Documents\NeoFly\NeoFly.exe"=0x53414350010000000000000007000000280000000062FC030000000001000000000000000000000A7322000050BB64EDDDACD50100000000000000000500000010000000000000000000000000000000000000000200000050000000000000000000000000000000000000000000000000000000C901790000000000340000003200000000000000000000400000000000000000000000000000000024B10900000000000200000000000000 "C:\Users\gband\Downloads\Installer_SWS_Kodiak_Wheels_MSFS_20211224.exe"=0x5341435001000000000000000700000028000000298BD828000000000100000000000000000001060001000050BB64EDDDACD50100000000000000000200000028000000000000000000004000000000000000000000000000000000690D0100000000000100000001000000 "C:\Users\gband\Downloads\fseconomy\FSeconomy.exe"=0x5341435001000000000000000700000028000000009002000000000001000000000000000000000A7122000050BB64EDDDACD50100000000000000000200000028000000000000000000000000000000000000000000000000000000BAEA0400000000000100000001000000 "C:\Users\gband\Downloads\Navdatareader\navdatareader.exe"=0x5341435001000000000000000700000028000000006C61007005620001000000000000000000000A7120000050BB64EDDDACD50100000000000000000200000028000000000000000000000000000000000000000000000000000000AC000000000000000100000001000000 "C:\Users\gband\Downloads\rexwxforce_20220107\rexinstaller.exe"=0x5341435001000000000000000700000028000000D0373000CD76300001000000000000000000000A0021000050BB64EDDDACD501000000000000000002000000280000000000000000000040000000000000000000000000000000009F650000000000000100000001000000 "C:\REX Weather Force 2020\rexwxforceapp.exe"=0x5341435001000000000000000700000028000000704107003D56070001000000000000000000000A6322000050BB64EDDDACD5010000000000000000020000002800000000000000000000400000000000000000000000000000000040171400000000000500000005000000 "C:\Users\gband\AppData\Local\Temp\Temp1_MSFS2020 Map Enhancement Setup 3.0.6.exe_OVvLP.zip\MSFS2020 Map Enhancement Setup 3.0.6.exe"=0x534143500100000000000000070000002800000055FBC9050000000001000000000000000000000A0021000050BB64EDDDACD50100000000000000000200000028000000000000000000004000000000000000000000000000000000F5350000000000000200000002000000 "C:\Users\gband\AppData\Local\Microsoft\OneDrive\21.245.1128.0002\FileSyncConfig.exe"=0x534143500100000000000000070000002800000068570A00507C0A0001000000000000000000000A0021000050BB64EDDDACD5010000000100000000 "C:\Users\gband\AppData\Local\Microsoft\OneDrive\21.245.1128.0002\Microsoft.SharePoint.exe"=0x5341435001000000000000000700000028000000A0470F000ED70F0001000000000000000000000A0021000050BB64EDDDACD501000000000000000002000000280000000000000000000000000000000000000000000000000000009C270000000000000C0000000C000000 "C:\Users\gband\Downloads\[Guru3D.com]-RTSS\RTSSSetup733.exe"=0x534143500100000000000000070000002800000028A46A01F00E6B0101000000000000000000000A0021000050BB64EDDDACD50100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000004000000000000000000000000000000000E2450000000000000100000001000000 "C:\Program Files\Guillemot\tmfwupdater\TMFirmwareUpdater.exe"=0x534143500100000000000000070000002800000018B97200601A730001000000000000000000000A7322000050BB64EDDDACD501000000000000000002000000280000000000000000000000000000000000000000000000000000007F8E0100000000000100000001000000 "C:\ProgramData\NVIDIA Corporation\Downloader\latest\setup.exe"=0x534143500100000000000000070000002800000070B10700EE0A080001000000000000000000000A0021000050BB64EDDDACD5010000000000000000050000001000000000000000000000000000000000000000020000002800000000000000000000000000000000000000000000000000000030280200000000000200000002000000 "C:\ProgramData\NVIDIA Corporation\Downloader\62e0d3938ecd62e0062d1fce4be5ed16_extracted\setup.exe"=0x534143500100000000000000070000002800000080DE0700F4DE070001000000000000000000000A0021000050BB64EDDDACD50100000000000000000200000028000000000000008000004000000000000000000000000000000000F1B67200000000000100000001000000 "C:\Users\gband\Documents\Enhanced Live Traffic\Enhanced Live Traffic.exe"=0x534143500100000000000000070000002800000000F8000090B4010001000000000000000000000A7322000050BB64EDDDACD5010000000000000000050000001000000000000000000000000000000000000000020000002800000000000000000000400000000000000000000000000000000034609401000000000700000007000000 "C:\Users\gband\Documents\modelchecker_setup.exe"=0x5341435001000000000000000700000028000000891444000000000001000000000000000000000A0021000050BB64EDDDACD5010000000000000000020000002800000000000000000000400000000000000000000000000000000094980400000000000300000003000000 "C:\Program Files\WindowsApps\WuhanNetPowerTechnologyCo.3322537A536FD_3.6.0.0_x86__63m8b6nby1dvp\NetPowerZip\NetPowerZip.exe"=0x5341435001000000000000000700000028000000000067000000000001000000000000000000000A6122000050BB64EDDDACD50100000000000000000200000028000000000000000000000000000000000000000000000000000000FB2C0000000000000300000003000000 "C:\Users\gband\Music\FS2CrewPushbackExpressforMSFS_2.2.16.exe"=0x534143500100000000000000070000002800000092F63004000000000100000000000000000001060001000050BB64EDDDACD501000000000000000002000000280000000000000000000040000000000000000000000000000000000D1D0000000000000100000001000000 "C:\Users\gband\Music\FS2CrewFlybywireA32NXProjectEditionforMSFS_1.1.13.exe"=0x53414350010000000000000007000000280000002FB69F0D000000000100000000000000000001060001000050BB64EDDDACD50100000000000000000200000028000000000000000000004000000000000000000000000000000000A1360000000000000100000001000000 "C:\Users\gband\Music\FS2CrewRAASProfessionalforMSFS_1.2.2.exe"=0x53414350010000000000000007000000280000009AB52203000000000100000000000000000001060001000050BB64EDDDACD50100000000000000000200000028000000000000000000004000000000000000000000000000000000041C0000000000000100000001000000 "C:\Users\gband\AppData\Local\Temp\7zOCEA8BE9E\FM-FlightControlReplayv4.5.2112.23(CameraManagerUpdate).exe"=0x534143500100000000000000070000002800000046CDD8000000000001000000000000000000000A0021000050BB64EDDDACD5010000000000000000020000002800000000000000000000000000000000000000000000000000000044AC0200000000000100000001000000 "C:\Program Files\WindowsApps\HaukeGtze.7-ZipFileManagerUnofficial_1.2107.2.0_x64__6bk20wvc8rfx2\7zFM.exe"=0x5341435001000000000000000700000028000000006E0E000000000001000000000000000000000A0021000050BB64EDDDACD50100000000000000000200000028000000000000000000000000000000000000000000000000000000E0035400000000004700000047000000 "C:\Users\gband\AppData\Local\Temp\7zOC482419C\FM-FlightControlReplayv4.5.2112.23(CameraManagerUpdate).exe"=0x534143500100000000000000070000002800000046CDD8000000000001000000000000000000000A0021000050BB64EDDDACD501000000000000000002000000280000000000000000000080000000000000000000000000000000006F670B00000000000100000001000000 "C:\Program Files (x86)\SimMarket\FlightControlReplay\FlightControlReplayP3DX\FlightControlReplayP3DX.exe"=0x5341435001000000000000000200000028000000000000000000000000000000000000000000000000000000B8EB0000000000000100000001000000 "C:\Users\gband\AppData\Local\Temp\7zO8C6E5926\FS2CrewPushbackExpressforMSFS_2.2.16.exe"=0x534143500100000000000000070000002800000092F63004000000000100000000000000000001060001000050BB64EDDDACD501000000000000000002000000280000000000000000000040000000000000000000000000000000006A250000000000000100000001000000 "C:\Users\gband\Downloads\Install_FSUIPC7\Install_FSUIPC7\Install_FSUIPC7.exe"=0x5341435001000000000000000700000028000000C4DB48020000000001000000000000000000000A0021000050BB64EDDDACD5010000000000000000020000002800000000000000000000400000000000000000000000000000000013310000000000000100000001000000 "C:\Users\gband\Downloads\installer.exe"=0x5341435001000000000000000700000028000000181434008C58340001000000000000000000000A7522000050BB64EDDDACD50100000000000000000200000028000000000000000000004000000000000000000000000000000000C9962600000000000100000001000000 "C:\Program Files (x86)\smartCARS\94\en-US\smartCARS.exe"=0x5341435001000000000000000700000028000000200837003802380001000000000000000000000A0021000050BB64EDDDACD501000000000000000002000000280000000000000000000040000000000000000000000000000000005022D200000000000700000007000000 "C:\Users\gband\Downloads\Navigraph+Simlink.exe"=0x5341435001000000000000000700000028000000F829B402710AB50201000000000000000000000A0021000050BB64EDDDACD501000000000000000002000000280000000000000000000000000000000000000000000000000000008D38B701000000000100000001000000 "C:\Users\gband\AppData\Local\Temp\Temp1_MSFS2020 Map Enhancement Setup 3.0.8.exe_unaS5.zip\MSFS2020 Map Enhancement Setup 3.0.8.exe"=0x53414350010000000000000007000000280000001CFEC9050000000001000000000000000000000A0021000050BB64EDDDACD501000000000000000002000000280000000000000000000040000000000000000000000000000000000F490000000000000100000001000000 "C:\Users\gband\Downloads\FSFO_NEXT.exe"=0x5341435001000000000000000700000028000000D4379A150000000001000000000000000000000A0021000050BB64EDDDACD50100000000000000000200000028000000000000000000004000000000000000000000000000000000B72D0A00000000000200000002000000 "C:\Users\gband\Downloads\bijanstudio-misc-four-season-pack-v7-0-0\Bijan_Seasons.exe"=0x5341435001000000000000000700000028000000A2EE72010000000001000000000000000000000A7320000050BB64EDDDACD50100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000004000020200000000000000000000000000C7DE0000000000000300000003000000 "C:\Users\gband\Downloads\bijanstudio-misc-four-season-pack-v7-0-0\jre-8u311-windows-x64.exe"=0x5341435001000000000000000700000028000000404F1B050DE11B0501000000000000000000000A7322000050BB64EDDDACD501000000000000000002000000280000000000000000000040000000000000000000000000000000000D8D0000000000000100000001000000 "C:\Users\gband\Downloads\Navigraph+Simlink (2).exe"=0x53414350010000000000000007000000280000005824B402527CB40201000000000000000000000A0021000050BB64EDDDACD50100000000000000000200000028000000000000000000000000000000000000000000000000000000891B1A00000000000100000001000000 "C:\Users\gband\AppData\Local\Temp\7zO8E025740\FM-FlightControlReplayv4.5.2201.12CameraManagerUpdate.exe"=0x5341435001000000000000000700000028000000C774DC000000000001000000000000000000000A0021000050BB64EDDDACD5010000000000000000 "C:\Users\gband\Documents\Stick and Rudder Studios - FS-ATC-Chatter v1.2.1\FS-ATC-Chatter.exe"=0x534143500100000000000000070000002800000000801A000000000001000000000000000000000A6122000050BB64EDDDACD501000000000000000005000000100000000000000000000000000000000000000002000000500000000000000000000000000000000000000000000000000000006FDE7C00000000000600000006000000000000000000004000000000000000000000000000000000BA1C8800000000000200000000000000 "C:\Program Files (x86)\SimMarket\FlightControlReplay\FlightControlReplay.exe"=0x534143500100000000000000070000002800000000120D000000000001000000000000000000000A7122000050BB64EDDDACD50100000000000000000500000010000000000000000000000000000000200000000200000028000000000000002000006000000000000000000000000000000000E37B4900000000000600000006000000 "C:\Program Files (x86)\SimMarket\FlightControlReplay\FlightControlReplayMSFS\FlightControlReplay.exe"=0x534143500100000000000000070000002800000000C212000000000001000000000000000000000A7322000050BB64EDDDACD5010000000000000000020000002800000000000000000000001000000000000000000000000000000024A60000000000000400000004000000 "C:\Users\gband\Downloads\FSAirlinesSetup-v2.5.0.exe"=0x534143500100000000000000070000002800000055836700000000000100000000000000000001060001000050BB64EDDDACD50100000000000000000200000028000000000000000000004000000000000000000000000000000000B892A500000000000100000001000000 "C:\Program Files (x86)\FSAirlines\FSAirlines.exe"=0x5341435001000000000000000700000028000000004E1900F6A5190001000000000000000000000A7122000050BB64EDDDACD501000000000000000002000000280000000000000000000000000200000000000000000000000000005DA78000000000000400000004000000 "C:\Users\gband\Documents\Traffic\AIG Taffic controler\AIGTech - Traffic Controller.exe"=0x534143500100000000000000070000002800000000923B000000000001000000000000000000000A0021000050BB64EDDDACD501000000000000000005000000100000000000000000000000000000002000000002000000280000000000000020000060000000000000000000000000000000006BB0D004000000002A0000002A000000 "C:\Users\gband\AppData\Local\Apps\2.0\LK0QAA7C.X1D\6W48N25K.TVN\onai..tion_be94ab6a893479c5_0001.0005_f7b29d0185e98b38\OnAir Company.exe"=0x5341435001000000000000000700000028000000E0089C0194939C0101000000000000000000000A7322000050BB64EDDDACD5010000000000000000020000002800000000000000000000000400000000000000000000000000000021750D00000000000100000001000000 "C:\Users\gband\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe"=0x5341435001000000000000000700000028000000685BF402090AF50201000000000000000000000A0021000050BB64EDDDACD5010000000100000000 "C:\Users\gband\AppData\Local\Microsoft\OneDrive\22.002.0103.0004\FileSyncConfig.exe"=0x5341435001000000000000000700000028000000A0870A00AA290B0001000000000000000000000A0021000050BB64EDDDACD5010000000100000000 "C:\Users\gband\Documents\Football.Manager.2022\fm.exe"=0x534143500100000000000000070000002800000000C0831F0000000001000000000000000000000A0021000050BB64EDDDACD50100000000000000000200000028000000000000000000000000000000000000000000000000000000440C0000000000000100000001000000 "C:\Users\gband\Downloads\Cities - Skylines [FitGirl Repack]\setup.exe"=0x534143500100000000000000070000002800000020305700000000000100000000000000000001060001000050BB64EDDDACD50100000000000000000200000028000000000000000000004000000000000000000000000000000000F9CE3B00000000000100000001000000 "C:\Users\gband\Downloads\Navigraph+Charts.exe"=0x534143500100000000000000070000002800000000534905796C490501000000000000000000000A0021000050BB64EDDDACD5010000000000000000020000002800000000000000000000000000000000000000000000000000000006690100000000000100000001000000 "C:\Users\gband\Downloads\Navigraph Navdata Center 1.0.5.exe"=0x5341435001000000000000000700000028000000002131066521310601000000000000000000000A0021000050BB64EDDDACD501000000000000000002000000280000000000000000000000000000000000000000000000000000005C8D0000000000000100000001000000 "C:\Users\gband\AppData\Local\Programs\Navigraph Navdata Center\Navigraph Navdata Center.exe"=0x534143500100000000000000070000002800000070F78607CCF5870701000000000000000000000A0021000050BB64EDDDACD5010000000000000000 "C:\Users\gband\OneDrive\Documents\FS2Crew - Pushback Express v2.2.17\Crack\Pushback Express_x64.exe"=0x534143500100000000000000070000002800000000B21A0079EF1A0001000000000000000000000A7322000050BB64EDDDACD5010000000000000000050000001000000000000000000000000000000000000000020000002800000000000000000000400000000000000000000000000000000066090000000000000100000001000000 "C:\Users\gband\OneDrive\Documents\FS2Crew - Pushback Express v2.2.17\FS2CrewPushbackExpressforMSFS_2.2.17.exe"=0x53414350010000000000000007000000280000000D0E3104000000000100000000000000000001060001000050BB64EDDDACD50100000000000000000200000028000000000000000000004000000000000000000000000000000000342E0000000000000100000001000000 "C:\Program Files (x86)\Pushback Express MSFS\Pushback Express_x64.exe"=0x534143500100000000000000070000002800000000B21A0079EF1A0001000000000000000000000A7322000050BB64EDDDACD501000000000000000002000000280000000000000020000060000000000000000000000000000000005AC10700000000000300000003000000 "C:\Users\gband\Downloads\Pilot2ATC v2.6.2.3\setupP2A_2623_x64_R2_with_Navigraph_1801.exe"=0x5341435001000000000000000700000028000000C7A53D0B0000000001000000000000000000000A0021000050BB64EDDDACD5010000000000000000020000002800000000000000000000400000000000000000000000000000000063150200000000000100000001000000 "C:\Pilot2ATC_2020_x64\Pilot2ATC_2020.exe"=0x534143500100000000000000070000002800000000AC57000000000001000000000000000000000A7322000050BB64EDDDACD50100000000000000000200000050000000000000000000000084000000000000000000000000000000F9A00C000000000003000000010000000000000000000040040000000000000000000000000000003FE9BA00000000000300000000000000 "C:\Users\gband\Downloads\AmazonPollyForWindowsSetup\AmazonPollyForWindowsSetup.exe"=0x534143500100000000000000070000002800000082B6E9000000000001000000000000000000000A0021000050BB64EDDDACD501000000000000000002000000280000000000000000000000000000000000000000000000000000005EB10000000000000100000001000000 "C:\Program Files\Amazon Polly TTS for Windows\PollyPlayer.exe"=0x5341435001000000000000000700000028000000005201000000000001000000000000000000000A6322000050BB64EDDDACD50100000000000000000200000028000000000000000000000004000000000000000000000000000000AE7A0000000000000600000006000000 "C:\Users\gband\AppData\Local\Temp\Temp1_MSFS2020 Map Enhancement Setup 3.1.1.exe_RtX2O.zip\MSFS2020 Map Enhancement Setup 3.1.1.exe"=0x5341435001000000000000000700000028000000E1A435060000000001000000000000000000000A0021000050BB64EDDDACD5010000000000000000020000002800000000000000000000400000000000000000000000000000000018CF0000000000000100000001000000 "C:\Users\gband\Documents\Luke Air\AirTool.exe"=0x534143500100000000000000070000002800000000C800010000000001000000000000000000000A6522000050BB64EDDDACD501000000000000000005000000100000000000000000000000000000000000000002000000280000000000000000000000000000000000000000000000000000006AE37A00000000000300000003000000 "C:\Users\gband\AppData\Local\Temp\Temp1_MSFS2020 Map Enhancement Setup 3.2.1.exe_RrCz9.zip\MSFS2020 Map Enhancement Setup 3.2.1.exe"=0x5341435001000000000000000700000028000000B6A835060000000001000000000000000000000A0021000050BB64EDDDACD50100000000000000000200000028000000000000000000004000000000000000000000000000000000DD870000000000000100000001000000 "C:\Program Files (x86)\opentrack\opentrack.exe"=0x534143500100000000000000070000002800000000240400067A040001000000000000000000000A7122000050BB64EDDDACD501000000000000000002000000280000000000000000000000000000000000000000000000000000000DB34D00000000000600000006000000 "C:\Users\gband\Documents\aitrack-v0.6.4-alpha\AITrack.exe"=0x534143500100000000000000070000002800000000C40C000000000001000000000000000000000A7322000050BB64EDDDACD50100000000000000000500000010000000000000000000000000000000000000000200000050000000000000000000000000000000000000000000000000000000C65C0000000000000300000003000000000000000000004000000000000000000000000000000000D5980000000000000100000000000000 "C:\Users\gband\Documents\aitrack-v0.6.5-alpha\AITrack.exe"=0x534143500100000000000000070000002800000000F80C000000000001000000000000000000000A7322000050BB64EDDDACD5010000000000000000050000001000000000000000000000000000000000000000020000002800000000000000000000400000000000000000000000000000000012A10000000000000100000001000000 "C:\Program Files (x86)\Steam\steamapps\common\MicrosoftFlightSimulator\FlightSimulator.exe"=0x534143500100000000000000070000002800000000F24A150000000001000000000000000000000A0021000050BB64EDDDACD501000000000000000002000000280000000000000000000000000000000000000000000000000000001B150400000000002900000029000000 "C:\Users\gband\Downloads\Not For Broadcast [FitGirl Repack]\setup.exe"=0x5341435001000000000000000700000028000000974D4000000000000100000000000000000001060001000050BB64EDDDACD501000000000000000002000000280000000000000000000040000000000000000000000000000000005796A400000000000100000001000000 "C:\Users\gband\AppData\Local\Temp\7zO04344B3A\sky4simPad.exe"=0x5341435001000000000000000700000028000000E8C6F8010000000001000000000000000000000A0021000050BB64EDDDACD50100000000000000000200000028000000000000000000000000000000000000000000000000000000E8660000000000000100000001000000 "C:\Users\gband\AppData\Local\Temp\7zO043F01BB\windowsdesktop-runtime-5.0.12-win-x64.exe"=0x5341435001000000000000000700000028000000D05E46032A30470301000000000000000000000A0021000050BB64EDDDACD501000000000000000002000000280000000000000000000000000000000000000000000000000000008B2A0000000000000100000001000000 "C:\Users\gband\AppData\Local\Programs\Sky4Sim Pad\Sky4Sim Pad.exe"=0x534143500100000000000000070000002800000000FC01000000000001000000000000000000000A7322000050BB64EDDDACD501000000000000000002000000280000000000000000000000000000000000000000000000000000008F5C8C00000000000600000006000000 "C:\Program Files\WindowsApps\WuhanNetPowerTechnologyCo.3322537A536FD_5.1.0.0_x86__63m8b6nby1dvp\NetPowerZip\NetPowerZip.exe"=0x5341435001000000000000000700000028000000007467000000000001000000000000000000000A6122000050BB64EDDDACD501000000000000000002000000280000000000000000000000000000000000000000000000000000009FA10000000000000100000001000000 "C:\Users\gband\Documents\Nouveau dossier\Layout Tools\MSFSLayoutGenerator.exe"=0x5341435001000000000000000700000028000000009005000000000001000000000000000000000A6322000050BB64EDDDACD501000000000000000002000000280000000000000000000000000000000000000000000000000000003F0D0000000000000100000001000000 "C:\Users\gband\AppData\Local\Temp\Temp1_MSFS2020 Map Enhancement Setup 3.2.2.exe_DpuMQ.zip\MSFS2020 Map Enhancement Setup 3.2.2.exe"=0x534143500100000000000000070000002800000001A935060000000001000000000000000000000A0021000050BB64EDDDACD50100000000000000000200000028000000000000000000004000000000000000000000000000000000A4450000000000000100000001000000 "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe"=0x5341435001000000000000000700000028000000883D3600B61F370001000000000000000000000A0021000050BB64EDDDACD501000000000000000002000000280000000000000000000000000000000000000000000000000000006DFE8F00000000000600000006000000 "C:\Users\gband\Documents\Traffic\AIG MManager\AIGTech - AI Manager.exe"=0x534143500100000000000000070000002800000000503F000000000001000000000000000000000A7320000050BB64EDDDACD50100000000000000000500000010000000000000000000000000000000200000000200000028000000000000002000006000000000000000000000000000000000B35F1400000000000200000002000000 "C:\Users\gband\AppData\Local\Temp\jre-8u321-windows-au.exe"=0x5341435001000000000000000700000028000000C8782200CC75230001000000000000000000000A7122000050BB64EDDDACD50100000000000000000200000028000000000000000000004000000000000000000000000000000000F3400600000000000100000001000000 "C:\Users\gband\Documents\opentrack-2.3\vPilot-Setup-3.0.7.exe"=0x5341435001000000000000000700000028000000BA9ED800000000000100000000000000000001060001000050BB64EDDDACD5010000000000000000 "C:\Users\gband\AppData\Local\Programs\Volanta\Volanta.exe"=0x5341435001000000000000000700000028000000985353087E9A530801000000000000000000000A0021000050BB64EDDDACD5010000000000000000 "C:\Program Files\RealTrafficLauncher\RealTrafficLauncher.exe"=0x5341435001000000000000000700000028000000905F1500A9DA150001000000000000000000000A7120000050BB64EDDDACD501000000000000000002000000280000000000000080000000000000000000000000000000000000000CF0E701000000000200000002000000 "C:\Users\gband\AppData\Local\simtoolkitpro\app-0.8.12\SimToolkitPro.exe"=0x534143500100000000000000070000002800000000181D080000000001000000000000000000000A0021000050BB64EDDDACD5010000000000000000 "C:\Users\gband\AppData\Local\simtoolkitpro\SimToolkitPro.exe"=0x5341435001000000000000000700000028000000009804000000000001000000000000000000000A0021000050BB64EDDDACD5010000000000000000 "C:\Users\gband\Documents\opentrack-2.3\Bijan_Season_Installer_V1.1\setup.exe"=0x5341435001000000000000000700000028000000006E08002789080001000000000000000000000A0021000050BB64EDDDACD50100000000000000000200000028000000000000000000000000000000000000000000000000000000D0210000000000000100000001000000 "C:\Program Files (x86)\Bijan Season\Bijan Season Installer\Bijan Seasons.exe"=0x5341435001000000000000000700000028000000003204000000000001000000000000000000000A6522000050BB64EDDDACD50100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000004000000000000000000000000000000000F0C6AD00000000000100000001000000 "C:\Users\gband\Downloads\Just Flight - Air Hauler 2 for MSFS v3.00.11\AirHauler2.exe"=0x53414350010000000000000007000000280000000040A8000000000001000000000000000000000A7122000050BB64EDDDACD5010000000000000000050000001000000000000000000000000000000000000000020000002800000000000000000000400000000000000000000000000000000015970C00000000000100000001000000 "C:\Program Files (x86)\Steam\steam.exe"=0x5341435001000000000000000700000028000000A82141000F60410001000000000000000000000A0021000050BB64EDDDACD5010000000100000000 "C:\Users\gband\AppData\Roaming\Telegram Desktop\Telegram.exe"=0x5341435001000000000000000700000028000000680284061319840601000000000000000000000A0021000050BB64EDDDACD50100000000000000000200000028000000000000000000000000000000000000000000000000000000D6E52C00000000000100000001000000 "C:\Users\gband\AppData\Local\vPilot\vPilot.exe"=0x5341435001000000000000000700000028000000005E12000000000001000000000000000000000A7122000050BB64EDDDACD50100000000000000000200000028000000000000000000000000000000000000000000000000000000D4DB5A00000000000100000001000000 "C:\Program Files\Google\Chrome\Application\chrome.exe"=0x5341435001000000000000000700000028000000584F280034DD280001000000000000000000000A0021000050BB64EDDDACD501000000000000000002000000280000000000000000000000000000000000000000000000000000004F000000000000000100000001000000 "C:\ProgramData\NVIDIA Corporation\Downloader\7bdd1c9de7d5b89fbbeea7029776fbdb\GeForce_Experience_Update_v3.25.0.84_Beta_7DCD72.exe"=0x534143500100000000000000070000002800000060AED50768FCD5070100000000000000000002060001000050BB64EDDDACD50100000000000000000200000028000000000000000000000000000000000000000000000000000000AFBB0000000000000100000001000000 "C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe"=0x534143500100000000000000070000002800000000E8090082B30A0001000000000000000000000A7120000050BB64EDDDACD501000000000000000002000000280000000000000080000000000000000000000000000000000000001D030000000000000100000001000000 "C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe"=0x5341435001000000000000000700000028000000D0F4320027FE320001000000000000000000000A0021000050BB64EDDDACD5010000000000000000020000002800000000000000000000000000000000000000000000000000000088530800000000000200000002000000 "C:\ProgramData\NVIDIA Corporation\Downloader\ca698ad259e50e6c4e4d57f96345ec95_extracted\setup.exe"=0x5341435001000000000000000700000028000000C0E907004D54080001000000000000000000000A0021000050BB64EDDDACD50100000000000000000200000028000000000000008000004000000000000000000000000000000000A72E0200000000000100000001000000 "SIGN.MEDIA=A3917CC0 Setup\bfv.exe"=0x534143500100000000000000070000002800000040E99A0E5D769B0E01000000000000000000000A7322000050BB64EDDDACD50100000000000000000200000028000000000000000000000000000000000000000000000000000000410A0000000000000100000001000000 "SIGN.MEDIA=F951B1 Setup\__Installer\Cleanup.exe"=0x5341435001000000000000000700000028000000282F0E008D110F000100000000000000000002060001000050BB64EDDDACD5010000000000000000020000002800000000000000000000400000000000000000000000000000000000000000000000000100000001000000 "SIGN.MEDIA=333982E OriginSetup.exe"=0x5341435001000000000000000700000028000000007067000000000001000000000000000000000A6120000050BB64EDDDACD5010000000000000000020000002800000000000000000800400000000000000000000000000000000007130E00000000000100000001000000 "E:\Games\Nouveau dossier\bfv.exe"=0x534143500100000000000000070000002800000000C69A0E5D769B0E01000000000000000000000A7322000050BB64EDDDACD5010000000000000000020000002800000000000000000000000000000000000000000000000000000087326D00000000000400000004000000 "C:\Users\gband\Downloads\QuickDiag.exe"=0x5341435001000000000000000700000028000000F0444500FEBC450001000000000000000000000A0021000050BB64EDDDACD5010000000000000000 ---------- | IFEO ---------- | Mountpoints2 [HKU\S-1-5-21-3835695913-52790398-83466441-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\Mountpoints2\{457e8e91-d8d4-11eb-ab8a-04d9f583b9cc}] : "F:\HiSuiteDownLoader.exe" (AutoRun) ---------- | Windows [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\win.ini\Windows] ""=USR:Software\Microsoft\Windows NT\CurrentVersion\Windows "APPINIT_DLLS"=SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS "Beep"=#USR:Control Panel\Sound "CoolSwitch"=USR:Control Panel\Desktop "DEFAULTSEPARATEVDM"=\\REGISTRY\\MACHINE\\SYSTEM\\CURRENTCONTROLSET\\CONTROL\\WOW "DEVICENOTSELECTEDTIMEOUT"=#SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS "DoubleClickHeight"=#USR:Control Panel\Mouse "DoubleClickSpeed"=#USR:Control Panel\Mouse "DoubleClickWidth"=#USR:Control Panel\Mouse "DragFullWindows"=USR:Control Panel\Desktop "InitialKeyboardIndicators"=USR:Control Panel\Keyboard "LowPowerActive"=#USR:Control Panel\Desktop "LowPowerTimeOut"=#USR:Control Panel\Desktop "MouseSpeed"=#USR:Control Panel\Mouse "MouseThreshold1"=#USR:Control Panel\Mouse "MouseThreshold2"=#USR:Control Panel\Mouse "PowerOffActive"=#USR:Control Panel\Desktop "PowerOffTimeOut"=#USR:Control Panel\Desktop "ScreenSaveActive"=#USR:Control Panel\Desktop "ScreenSaveTimeOut"=#USR:Control Panel\Desktop "SnapToDefaultButton"=#USR:Control Panel\Mouse "Spooler"=#SYS:Microsoft\Windows NT\CurrentVersion\Windows "SWAPDISK"=SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS "SwapMouseButtons"=#USR:Control Panel\Mouse "TRANSMISSIONRETRYTIMEOUT"=#SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\system.ini\Boot] ""=SYS:Microsoft\Windows NT\CurrentVersion\WOW\boot "ScreenSaverActive"=USR:Control Panel\Desktop "ScreenSaverIsSecure"=USR:Control Panel\Desktop "SCRNSAVE.EXE"=USR:Control Panel\Desktop "Shell"=SYS:Microsoft\Windows NT\CurrentVersion\Winlogon [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\IniFileMapping\win.ini\Windows] "APPINIT_DLLS"=SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS "Beep"=#USR:Control Panel\Sound "CoolSwitch"=USR:Control Panel\Desktop "DEFAULTSEPARATEVDM"=\\REGISTRY\\MACHINE\\SYSTEM\\CURRENTCONTROLSET\\CONTROL\\WOW "DEVICENOTSELECTEDTIMEOUT"=#SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS "DoubleClickHeight"=#USR:Control Panel\Mouse "DoubleClickSpeed"=#USR:Control Panel\Mouse "DoubleClickWidth"=#USR:Control Panel\Mouse "DragFullWindows"=USR:Control Panel\Desktop "InitialKeyboardIndicators"=USR:Control Panel\Keyboard "LowPowerActive"=#USR:Control Panel\Desktop "LowPowerTimeOut"=#USR:Control Panel\Desktop "MouseSpeed"=#USR:Control Panel\Mouse "MouseThreshold1"=#USR:Control Panel\Mouse "MouseThreshold2"=#USR:Control Panel\Mouse "PowerOffActive"=#USR:Control Panel\Desktop "PowerOffTimeOut"=#USR:Control Panel\Desktop "ScreenSaveActive"=#USR:Control Panel\Desktop "ScreenSaveTimeOut"=#USR:Control Panel\Desktop "SnapToDefaultButton"=#USR:Control Panel\Mouse "SWAPDISK"=SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS "SwapMouseButtons"=#USR:Control Panel\Mouse "TRANSMISSIONRETRYTIMEOUT"=#SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\IniFileMapping\system.ini\Boot] ""=SYS:Microsoft\Windows NT\CurrentVersion\WOW\boot "ScreenSaverActive"=USR:Control Panel\Desktop "ScreenSaverIsSecure"=USR:Control Panel\Desktop "SCRNSAVE.EXE"=USR:Control Panel\Desktop "Shell"=SYS:Microsoft\Windows NT\CurrentVersion\Winlogon [HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems] "windows"=%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16 ---------- | Security center [HKLM\SOFTWARE\Microsoft\Security Center] "cval"=1 [HKLM\SOFTWARE\Microsoft\Security Center\svc] "VistaSp1"=132694465192836499 [HKLM\SOFTWARE\Microsoft\Windows Defender] "ProductAppDataPath"=C:\ProgramData\Microsoft\Windows Defender "ProductIcon"=@%ProgramFiles%\Windows Defender\EppManifest.dll,-100 "ProductLocalizedName"=@%ProgramFiles%\Windows Defender\EppManifest.dll,-1000 "RemediationExe"=windowsdefender:// "ProductType"=2 "InstallTime"=0x6C1940CBE06CD701 "InstallLocation"=C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2201.10-0\ "ManagedDefenderProductType"=0 "ProductStatus"=0 "OOBEInstallTime"=0xAED80B84EE6CD701 "DisableAntiSpyware"=0 "DisableAntiVirus"=0 "PUAProtection"=1 "BackupLocation"=C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2111.5-0 "LastEnabledTime"=0xE480A652F2B3D701 "HybridModeEnabled"=0 "VerifiedAndReputableTrustModeEnabled"=0 "IsServiceRunning"=1 [HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall"=1 [HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall"=1 [HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall"=1 ---------- | Safeboot [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ahcache.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppInfo] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppMgmt] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AudioEndpointBuilder] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AudioSrv] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Base] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BasicDisplay.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BasicRender.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Boot Bus Extender] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Boot file system] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BrokerInfrastructure] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CBDHSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CoreMessagingRegistrar] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CryptSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\DcomLaunch] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\DeviceInstall] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dxgkrnl.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EFS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EventLog] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\File system] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Filter] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\FsDepends.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HdAudAddService.Sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HdAudBus.Sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HelpSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\iai2c.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\KeyIso] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\LSM] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Netlogon] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NgcCtnrSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NgcSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NTDS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PCI Configuration] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PlugPlay] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PNP Filter] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Power] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Primary disk] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ProfSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcEptMapper] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcSs] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SCSI Class] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SerCx2.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sermouse.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SpbCx.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\StateRepository] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SWPRV] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\System Bus Extender] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SystemEventsBroker] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TabletInputService] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TBS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TrustedInstaller] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\uefi.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\usbaudio.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\UserManager] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\VDS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vmms] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgr.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgrx.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinMgmt] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{36FC9E60-C465-11CF-8056-444553540000}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E965-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E969-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96A-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96B-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96C-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96F-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E977-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97B-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97D-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E980-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{71A27CDD-812A-11D0-BEC7-08002BE2092F}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{9DA2B80F-F89F-4A49-A5C2-511B085B9E8A}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{A0A588A4-C46F-4B37-B7EA-C82FE89870C6}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AFD] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Ahcache.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AppInfo] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AppMgmt] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AudioEndpointBuilder] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AudioSrv] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Base] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\BasicDisplay.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\BasicRender.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\BFE] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Boot Bus Extender] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Boot file system] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\bowser] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\BrokerInfrastructure] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Browser] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CBDHSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CoreMessagingRegistrar] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CryptSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\DcomLaunch] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\DeviceInstall] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\dfsc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Dhcp] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\DnsCache] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Dot3Svc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\dxgkrnl.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Eaphost] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\EFS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\EventLog] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\File system] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Filter] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\FsDepends.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\HdAudAddService.Sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\HdAudBus.Sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\HelpSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\IKEEXT] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ipnat.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\KeyIso] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\LanmanServer] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\LanmanWorkstation] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\LmHosts] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\LSM] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Messenger] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MPSDrv] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MPSSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mrxsmb] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mrxsmb10] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mrxsmb20] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MsQuic] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NativeWifiP] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NDIS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NDIS Wrapper] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ndiscap] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Ndisuio] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetBIOS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetBIOSGroup] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetBT] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetDDEGroup] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Netlogon] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetMan] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\netprofm] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetSetupSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Network] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetworkProvider] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NgcCtnrSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NgcSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NlaSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Nsi] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\nsiproxy.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NTDS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PCI Configuration] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PlugPlay] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PNP Filter] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PNP_TDI] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PolicyAgent] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Power] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Primary disk] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ProfSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\rdbss] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\rdpencdd.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\rdsessmgr] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\RpcEptMapper] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\RpcSs] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\sacsvr] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SCardSvr] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SCSI Class] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SerCx2.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\sermouse.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SharedAccess] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SmartcardSimulator] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SpbCx.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\StateRepository] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Streams Drivers] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SWPRV] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\System Bus Extender] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SystemEventsBroker] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TabletInputService] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TBS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Tcpip] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TDI] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TrustedInstaller] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\uefi.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\usbaudio.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\UserManager] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\VaultSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\VDS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\VirtualSmartcardReader] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\vmms] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\volmgr.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\volmgrx.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wcmsvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WinDefend] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WinMgmt] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wlansvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WudfPf] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WudfRd] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WudfUsbccidDriver] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{36FC9E60-C465-11CF-8056-444553540000}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E965-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E967-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E969-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E96A-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E96B-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E96C-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E96F-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E973-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E974-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E975-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E977-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E97B-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E97D-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E980-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{50DD5230-BA8A-11D1-BF5D-0000F805F530}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{533C5B84-EC70-11D2-9505-00C04F79DEAF}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{71A27CDD-812A-11D0-BEC7-08002BE2092F}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{9DA2B80F-F89F-4A49-A5C2-511B085B9E8A}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{A0A588A4-C46F-4B37-B7EA-C82FE89870C6}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}] ---------- | Winsock (Whitelist) ---------- | Hosts 109.94.209.70 *.fitgirl-repacks.xyz # Fake FitGirl site 109.94.209.70 *.fitgirl-repacks.xyz # Fake FitGirl site 109.94.209.70 *.fitgirl-repacks.xyz # Fake FitGirl site 109.94.209.70 fitgirl-repack.org # Fake FitGirl site 109.94.209.70 www.fitgirl-repack.org # Fake FitGirl site 109.94.209.70 fitgirlrepacks.in # Fake FitGirl site 109.94.209.70 www.fitgirlrepacks.in # Fake FitGirl site 109.94.209.70 fitgirlrepacks.co # Fake FitGirl site 109.94.209.70 fitgirl-repacks.to # Fake FitGirl site [69] More lines ---------- | Ping Envoi d'une requ?te 'ping' sur google.com [172.217.169.78] avec 32 octets de donn?es?: R?ponse de 172.217.169.78?: octets=32 temps=171 ms TTL=116 R?ponse de 172.217.169.78?: octets=32 temps=174 ms TTL=116 R?ponse de 172.217.169.78?: octets=32 temps=173 ms TTL=116 R?ponse de 172.217.169.78?: octets=32 temps=169 ms TTL=116 Statistiques Ping pour 172.217.169.78: Paquets?: envoy?s = 4, re?us = 4, perdus = 0 (perte 0%), Dur?e approximative des boucles en millisecondes : Minimum = 169ms, Maximum = 174ms, Moyenne = 171ms ---------- | @ [HKU\S-1-5-21-3835695913-52790398-83466441-1001\Software\Microsoft\Internet Explorer\Main] "Anchor Underline"=yes "Cache_Update_Frequency"=yes "Disable Script Debugger"=yes "DisableScriptDebuggerIE"=yes "Display Inline Images"=yes "Do404Search"=0x01000000 "Local Page"=%11%\blank.htm "Save_Session_History_On_Exit"=no "Search Page"=http://go.microsoft.com/fwlink/?LinkId=54896 "Show_FullURL"=no "Show_StatusBar"=yes "Show_ToolBar"=yes "Show_URLinStatusBar"=yes "Show_URLToolBar"=yes "Use_DlgBox_Colors"=yes "UseClearType"=no "XMLHTTP"=1 "Enable Browser Extensions"=yes "Play_Background_Sounds"=yes "Play_Animations"=yes "Start Page"=http://go.microsoft.com/fwlink/p/?LinkId=255141 "ImageStoreRandomFolder"=7fay7kn "NotifyDownloadComplete"=yes "OperationalData"=13 "CompatibilityFlags"=0 "SearchBandMigrationVersion"=1 "FullScreen"=no "Window_Placement"=0x2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFED020000660000009D07000009030000 "Start Page_TIMESTAMP"=0x23859000ED9DD701 "SyncHomePage Protected - It is a violation of Windows Policy to modify. See aka.ms/browserpolicy"=0x0100000033000000C1E67519E85A27C9793C281F951E95DBB60141142BB1AA529447E96FB8C80CBD473CBA0567424439852D65AD3F040C098CB0E8020000000E000000565236694C4F4A496E7A6F253364 "IE10RunOnceLastShown"=1 "IE10RunOnceLastShown_TIMESTAMP"=0xC44E3703ED9DD701 "IE10TourShown"=1 "IE10TourShownTime"=0x502925CDE690D701 "IE11EdgeNotifyTime"=0x51D75842ED9DD701 "EdgeReminderRemainingCount"=5 "IE10RunOncePerInstallCompleted"=1 "IE10RunOnceCompletionTime"=0x502925CDE690D701 "DownloadWindowPlacement"=0x0000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 "News Feed First Run Experience"=0 "Use FormSuggest"=yes [HKU\S-1-5-21-3835695913-52790398-83466441-1001\Software\Microsoft\Windows\CurrentVersion\Internet settings] "CertificateRevocation"=1 "DisableCachingOfSSLPages"=0 "IE5_UA_Backup_Flag"=5.0 "PrivacyAdvanced"=1 "SecureProtocols"=2688 "User Agent"=Mozilla/4.0 (compatible; MSIE 8.0; Win32) "ZonesSecurityUpgrade"=0x0452AA1069ABD701 "WarnonZoneCrossing"=0 "EnableNegotiate"=1 "ProxyEnable"=0 "MigrateProxy"=1 "LockDatabase"=132694485706916802 [HKLM\Software\Microsoft\Internet Explorer\Main] "ApplicationTileImmersiveActivation"=1 "AssociationActivationMode"=0 "AutoHide"=yes "Start Page"=http://go.microsoft.com/fwlink/p/?LinkId=255141 "Anchor_Visitation_Horizon"=0x01000000 "Cache_Percent_of_Disk"=0x0A000000 "Default_Page_URL"=http://go.microsoft.com/fwlink/p/?LinkId=255141 "Default_Search_URL"=http://go.microsoft.com/fwlink/?LinkId=54896 "Default_Secondary_Page_URL"= "Delete_Temp_Files_On_Exit"=yes "Enable_Disk_Cache"=yes "Extensions Off Page"=about:NoAdd-ons "Local Page"=C:\Windows\System32\blank.htm "Placeholder_Height"=0x1A000000 "Placeholder_Width"=0x1A000000 "Search Page"=http://go.microsoft.com/fwlink/?LinkId=54896 "Security Risk Page"=about:SecurityRisk "Use_Async_DNS"=yes "x86AppPath"=C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE [HKLM\Software\Microsoft\Internet Explorer\AboutURLs] "blank"=res://mshtml.dll/blank.htm "DesktopItemNavigationFailure"=res://ieframe.dll/navcancl.htm "Home"=270 "InPrivate"=res://ieframe.dll/inprivate.htm "NavigationCanceled"=res://ieframe.dll/navcancl.htm "NavigationFailure"=res://ieframe.dll/navcancl.htm "NoAdd-ons"=res://ieframe.dll/noaddon.htm "NoAdd-onsInfo"=res://ieframe.dll/noaddoninfo.htm "PostNotCached"=res://ieframe.dll/repost.htm "SecurityRisk"=res://ieframe.dll/securityatrisk.htm [HKLM\Software\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix] ""=http:// [HKLM\Software\Microsoft\Windows\CurrentVersion\URL\Prefixes] "ftp"=ftp:// "home"=http:// "mosaic"=http:// "www"=http:// [HKLM\Software\Microsoft\Windows\CurrentVersion\Internet settings] "ActiveXCache"=C:\Windows\Downloaded Program Files "CodeBaseSearchPath"=CODEBASE "EnablePunycode"=1 "MinorVersion"=0 "WarnOnIntranet"=1 [HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings] "CallLegacyWCMPolicies"=0 [HKLM\Software\WOW6432Node\Microsoft\Internet Explorer\Main] "ApplicationTileImmersiveActivation"=1 "AssociationActivationMode"=0 "AutoHide"=yes "Start Page"=http://go.microsoft.com/fwlink/p/?LinkId=255141 "Anchor_Visitation_Horizon"=0x01000000 "Cache_Percent_of_Disk"=0x0A000000 "Default_Page_URL"=http://go.microsoft.com/fwlink/p/?LinkId=255141 "Default_Search_URL"=http://go.microsoft.com/fwlink/?LinkId=54896 "Default_Secondary_Page_URL"= "Delete_Temp_Files_On_Exit"=yes "Enable_Disk_Cache"=yes "Extensions Off Page"=about:NoAdd-ons "Local Page"=C:\Windows\SysWOW64\blank.htm "Placeholder_Height"=0x1A000000 "Placeholder_Width"=0x1A000000 "Search Page"=http://go.microsoft.com/fwlink/?LinkId=54896 "Security Risk Page"=about:SecurityRisk "Use_Async_DNS"=yes "x86AppPath"=C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE [HKLM\Software\WOW6432Node\Microsoft\Internet Explorer\AboutURLs] "blank"=res://mshtml.dll/blank.htm "DesktopItemNavigationFailure"=res://ieframe.dll/navcancl.htm "Home"=270 "InPrivate"=res://ieframe.dll/inprivate.htm "NavigationCanceled"=res://ieframe.dll/navcancl.htm "NavigationFailure"=res://ieframe.dll/navcancl.htm "NoAdd-ons"=res://ieframe.dll/noaddon.htm "NoAdd-onsInfo"=res://ieframe.dll/noaddoninfo.htm "PostNotCached"=res://ieframe.dll/repost.htm "SecurityRisk"=res://ieframe.dll/securityatrisk.htm [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix] ""=http:// [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\URL\Prefixes] "ftp"=ftp:// "home"=http:// "mosaic"=http:// "www"=http:// [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Internet settings] "ActiveXCache"=C:\Windows\Downloaded Program Files "CodeBaseSearchPath"=CODEBASE "EnablePunycode"=1 "MinorVersion"=0 "WarnOnIntranet"=1 [HKLM\Software\WOW6432Node\Policies\Microsoft\Windows\CurrentVersion\Internet Settings] "CallLegacyWCMPolicies"=0 ---------- | Proxy ---------- | reparsepoint ---------- | Detection of offsets ---------- | Notify ---------- | Execution FileExts ---------- | SIOI | SEH | URLSH [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive1] - {BBACC218-34EA-4666-9D7A-C78F2274A524} -- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive2] - {5AB7172C-9C11-405C-8DD5-AF20F3606282} -- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive3] - {A78ED123-AB77-406B-9962-2A5D9D2F7F30} -- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive4] - {F241C880-6982-4CE5-8CF7-7085BA96DA5A} -- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive5] - {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} -- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive6] - {9AA2F32D-362A-42D9-9328-24A483E2CCC3} -- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive7] - {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} -- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\EnhancedStorageShell] - {D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D} -- C:\Windows\System32\EhStorShell.dll [29/06/2021 13:10:59] [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\Offline Files] - {4E77131D-3629-431c-9818-C5679DC83E81} -- %SystemRoot%\System32\cscui.dll [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive1] - {BBACC218-34EA-4666-9D7A-C78F2274A524} -- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive2] - {5AB7172C-9C11-405C-8DD5-AF20F3606282} -- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive3] - {A78ED123-AB77-406B-9962-2A5D9D2F7F30} -- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive4] - {F241C880-6982-4CE5-8CF7-7085BA96DA5A} -- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive5] - {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} -- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive6] - {9AA2F32D-362A-42D9-9328-24A483E2CCC3} -- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive7] - {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} -- [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks] "{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"= ---------- | Toolbar [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "Locked"=1 [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"={0633EE93-D776-472f-A0FF-E1416B8B2E3A} "KnownProvidersUpgradeTime"=0x502925CDE690D701 "Version"=5 "UpgradeTime"=0x502925CDE690D701 [HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"={0633EE93-D776-472f-A0FF-E1416B8B2E3A} [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"={0633EE93-D776-472f-A0FF-E1416B8B2E3A} ---------- | Extensions ---------- | SearchScopes [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}] - (Bing) - http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02 : [HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}] - (@ieframe.dll,-12512) - http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}] - (@ieframe.dll,-12512) - http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC : ---------- | Browser Helper Objects [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1FD49718-1D00-4B19-AF5F-070AF6D5D54C}] -> (IEToEdge BHO) : C:\Program Files (x86)\Microsoft\Edge\Application\98.0.1108.50\BHO\ie_to_edge_bho.dll [10/02/2022 22:49:35] [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}] -> () : [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}] -> () : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1FD49718-1D00-4B19-AF5F-070AF6D5D54C}] -> (IEToEdge BHO) : C:\Program Files (x86)\Microsoft\Edge\Application\98.0.1108.50\BHO\ie_to_edge_bho.dll [10/02/2022 22:49:35] ---------- | Chrome C:\Users\gband\AppData\Local\Google\Chrome\User Data\Default\extensions\aapocclcgogkmnckokdopfmhonfmgoek = : Google & co - Google & co - https://clients2.google.com/service/update2/crx C:\Users\gband\AppData\Local\Google\Chrome\User Data\Default\extensions\aegnopegbbhjeeiganiajffnalhlkkjb = : __MSG_extShortDesc__ - short_name: Safe Torrent Scanner - https://clients2.google.com/service/update2/crx C:\Users\gband\AppData\Local\Google\Chrome\User Data\Default\extensions\bigefpfhnfcobdlfbedofhhaibnlghod = : Secure Cloud Storage and Chat - MEGA - https://clients2.google.com/service/update2/crx C:\Users\gband\AppData\Local\Google\Chrome\User Data\Default\extensions\cfhdojbkjhnklbpkdaibdccddilifddb = : __MSG_description__ - short_name: __MSG_name__ - permissions:[tabs\u003Call_urls>contextMenuswebRequestwebRequestBlockingwebNavigationstorageunlimitedStoragenotifications] - https://clients2.google.com/service/update2/crx C:\Users\gband\AppData\Local\Google\Chrome\User Data\Default\extensions\ddgilliopjknmglnpkegbjpoilgachlm = : Easily and safely install local CRX files in Chrome - WebCRX - https://clients2.google.com/service/update2/crx C:\Users\gband\AppData\Local\Google\Chrome\User Data\Default\extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo = : The world's most popular userscript manager - short_name: Tampermonkey - permissions:[notificationsunlimitedStoragetabsidlewebNavigationwebRequestwebRequestBlockingstoragecontextMenuschrome://favicon/clipboardWritecookiesdeclarativeContent\u003Call_urls>] - https://clients2.google.com/service/update2/crx C:\Users\gband\AppData\Local\Google\Chrome\User Data\Default\extensions\dmgkiikdlhmpikkhpiplldicbnicmboc = : Google & co - Google & co - matches:[\u003Call_urls>] - https://clients2.google.com/service/update2/crx C:\Users\gband\AppData\Local\Google\Chrome\User Data\Default\extensions\egeneelmedfcnakdkkpoflpfiogmgjhk = : It goes through the html page content searching for magnet links. - Torrent magnet finder - https://clients2.google.com/service/update2/crx C:\Users\gband\AppData\Local\Google\Chrome\User Data\Default\extensions\elicpjhcidhpjomhibiffojpinpmmpil = : Google & co - short_name: VDP - https://clients2.google.com/service/update2/crx C:\Users\gband\AppData\Local\Google\Chrome\User Data\Default\extensions\felcaaldnbdncclmgdcncolpebgiejap = : Google & co - Google & co - https://clients2.google.com/service/update2/crx C:\Users\gband\AppData\Local\Google\Chrome\User Data\Default\extensions\fngmhnnpilhplaeedifhccceomclgfbg = : __MSG_editThis_description__ - EditThisCookie - permissions:[tabs\u003Call_urls>cookiescontextMenusnotificationsclipboardWritewebRequestwebRequestBlocking] - http://clients2.google.com/service/update2/crx C:\Users\gband\AppData\Local\Google\Chrome\User Data\Default\extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi = : __MSG_extDesc__ - __MSG_extName__ - https://clients2.google.com/service/update2/crx C:\Users\gband\AppData\Local\Google\Chrome\User Data\Default\extensions\gighmmpiobklfepjocnamgkkbiglidom = : __MSG_description__ - short_name: __MSG_name__ - permissions:[tabs\u003Call_urls>contextMenuswebRequestwebRequestBlockingwebNavigationstorageunlimitedStoragenotificationsidlealarms] - https://clients2.google.com/service/update2/crx C:\Users\gband\AppData\Local\Google\Chrome\User Data\Default\extensions\hfamgdphmadpbopjpnjeclijgabhmeml = : Provides music-themed new tab page - short_name: Music New Tab - https://clients2.google.com/service/update2/crx C:\Users\gband\AppData\Local\Google\Chrome\User Data\Default\extensions\jmfikkaogpplgnfjmbjdpalkhclendgd = : Save things you want to come back to later. - Save to Facebook - https://clients2.google.com/service/update2/crx C:\Users\gband\AppData\Local\Google\Chrome\User Data\Default\extensions\nmmhkkegccagdldgiimedpiccmgmieda = : Google & co - Google & co - 203784468217.apps.googleusercontent.com - https://clients2.google.com/service/update2/crx C:\Users\gband\AppData\Local\Google\Chrome\User Data\Default\extensions\onhiacboedfinnofagfgoaanfedhmfab = : Google & co - short_name: Reverso Context - permissions:[\u003Call_urls>tabscontextMenusbackgroundnotificationscookies] - https://clients2.google.com/service/update2/crx C:\Users\gband\AppData\Local\Google\Chrome\User Data\Profile 1\extensions\aapocclcgogkmnckokdopfmhonfmgoek = : Google & co - Google & co - https://clients2.google.com/service/update2/crx C:\Users\gband\AppData\Local\Google\Chrome\User Data\Profile 1\extensions\felcaaldnbdncclmgdcncolpebgiejap = : Google & co - Google & co - https://clients2.google.com/service/update2/crx C:\Users\gband\AppData\Local\Google\Chrome\User Data\Profile 1\extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi = : __MSG_extDesc__ - __MSG_extName__ - https://clients2.google.com/service/update2/crx C:\Users\gband\AppData\Local\Google\Chrome\User Data\Profile 1\extensions\nmmhkkegccagdldgiimedpiccmgmieda = : Google & co - Google & co - 203784468217.apps.googleusercontent.com - https://clients2.google.com/service/update2/crx ---------- | Opera C:\Users\gband\AppData\Roaming\Opera Software\Opera Stable\extensions\enegjkbbakeegngfapepobipndnebkdk = - Rich Hints Agent - https://extension-updates.opera.com/api/omaha/update/ C:\Users\gband\AppData\Roaming\Opera Software\Opera Stable\extensions\kbmoiomgmchbpihhdpabemajcbjpcijk = - Amazon Assistant Promotion - https://extension-updates.opera.com/api/omaha/update/ ---------- | Firefox [HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=11.321.2] - (Java™ Deployment Toolkit) : C:\Program Files\Java\jre1.8.0_321\bin\dtplugin\npDeployJava1.dll [HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=11.321.2] - (Oracle® Next Generation Java™ Plug-In) : C:\Program Files\Java\jre1.8.0_321\bin\plugin2\npjp2.dll ---------- | DNS [HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters] "DhcpNameServer"=192.168.1.254 [HKLM\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{1eb69300-99a4-4fc5-a262-82e7990e9a80}] "DhcpNameServer"=192.168.1.254 [HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{1eb69300-99a4-4fc5-a262-82e7990e9a80}] "DhcpNameServer"=192.168.1.254 ---------- | Applications [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Classes\Applications\ACOrigins.exe] : "E:\Games\Nouveau dossier\Assassins Creed Origins The Curse of the Pharaohs\ACOrigins.exe" "%1" [HKLM\SOFTWARE\Classes\Applications\iexplore.exe] : "C:\Program Files\Internet Explorer\iexplore.exe" %1 [HKLM\SOFTWARE\Classes\Applications\notepad.exe] : %SystemRoot%\system32\NOTEPAD.EXE %1 [HKLM\SOFTWARE\Classes\Applications\provtool.exe] : "%SystemRoot%\System32\provtool.exe" "%1" /source ShellOpen [HKLM\SOFTWARE\Classes\Applications\wmplayer.exe] : "%ProgramFiles(x86)%\Windows Media Player\wmplayer.exe" /Open "%L" [HKLM\SOFTWARE\Classes\Applications\wordpad.exe] : "%ProgramFiles%\Windows NT\Accessories\WORDPAD.EXE" "%1" [HKLM\SOFTWARE\WOW6432Node\Classes\Applications\iexplore.exe] : "C:\Program Files\Internet Explorer\iexplore.exe" %1 [HKLM\SOFTWARE\WOW6432Node\Classes\Applications\notepad.exe] : %SystemRoot%\system32\NOTEPAD.EXE %1 [HKLM\SOFTWARE\WOW6432Node\Classes\Applications\provtool.exe] : "%SystemRoot%\System32\provtool.exe" "%1" /source ShellOpen [HKLM\SOFTWARE\WOW6432Node\Classes\Applications\wmplayer.exe] : "%ProgramFiles(x86)%\Windows Media Player\wmplayer.exe" /Open "%L" [HKLM\SOFTWARE\WOW6432Node\Classes\Applications\wordpad.exe] : "%ProgramFiles%\Windows NT\Accessories\WORDPAD.EXE" "%1" ---------- | SvcHost (Whitelist) [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost] "DcomLaunch"=Power LSM BrokerInfrastructure PlugPlay DcomLaunch SystemEventsBroker DeviceInstall "rdxgroup"=RetailDemo "Camera"=FrameS "LocalServiceNoNetworkFirewall"=BFE mpssvc "diagnostics"=DiagSvc "AarSvcGroup"=AarSvc "PrintWorkflow"=PrintWorkflowUserSvc "wusvcs"=WaaSMedicSvc "BcastDVRUserService"=BcastDVRUserService "GraphicsPerfSvcGroup"=GraphicsPerfSvc "autoTimeSvc"=autoTimeSvc "ClipboardSvcGroup"=cbdhsvc "BthAppGroup"=BluetoothUserService "smbsvcs"=lanmanserver "UdkSvcGroup"=UdkUserSvc "DevicesFlow"=DeviceAssociationBrokerSvc DevicesFlowUserSvc ConsentUxUserSvc DevicePickerUserSvc "PeerDist"=PeerDistSvc "AssignedAccessManagerSvc"=AssignedAccessManagerSvc "DialogBlockingService"=DialogBlockingService "CloudIdServiceGroup"=cloudidsvc [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost] "DcomLaunch"=DcomLaunch DeviceInstall "PrintWorkflow"=PrintWorkflowUserSvc "AarSvcGroup"=AarSvc "DevicesFlow"=DeviceAssociationBrokerSvc "smbsvcs"=lanmanserver ---------- | SvcHost - Netsvcs (Whitelist) ---------- | Software [HKU\S-1-5-21-3835695913-52790398-83466441-1001\Software\32e4cdf1-1f8f-586a-9551-9c0929bc3c38] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\Software\55f042a9-1285-5a7a-abcd-4e2044c5b51b] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\Software\7-Zip] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\Software\796ea1b6-958a-57f0-828f-ddc0351d9ae7] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\Software\7cf15176-b7c3-5704-8319-ddca84b92c9a] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\Software\80b9efbf-2017-5d38-8868-3afd67a5a47d] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\Software\AMD] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\Software\AppDataLow] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\Software\ATI] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\Software\c489a901-bdfb-5fb7-8139-68385c3d78d8] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\Software\Chromium] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\Software\Clients] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\Software\Discord] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\Software\Epic Games] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\Software\Football Manager 2021] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\Software\Freetrack] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\Software\FSAirlines Client] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\Software\Google] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\Software\Guna] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\Software\JavaSoft] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\Software\Khronos] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\Software\Lavasoft] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\Software\MaxonApps] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\Software\Microsoft] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\Software\MSI] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\Software\NaturalPoint] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\Software\NotGames] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\Software\NVIDIA Corporation] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\Software\opentrack-2.3] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\Software\Opera Software] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\Software\Opera Stable Offer] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\Software\Parallel 42] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\Software\PES2020 Generator v1.0] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\Software\PilotClient] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\Software\Piriform] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\Software\Policies] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\Software\PushbackExpress] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\Software\QtProject] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\Software\Realtek] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\Software\RegisteredApplications] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\Software\REX Game Studios] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\Software\smartCARS] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\Software\SyncEngines] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\Software\TelegramDesktop] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\Software\Ubisoft] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\Software\Unwinder] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\Software\Valve] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\Software\VB and VBA Program Settings] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\Software\vPilot] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\Software\VS Revo Group] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\Software\WixSharp] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\Software\Wow6432Node] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\AppDataLow\Software\Microsoft] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\Accessibility] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\Active Setup] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\ActiveMovie] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\ActiveSync] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\Assistance] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\AuthCookies] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\Avalon.Graphics] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\Clipboard] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\Common] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\CommsAPHost] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\CTF] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\DeviceDirectory] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\DirectInput] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\DirectX Diagnostic Tool] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\Edge] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\EdgeUpdate] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\EventSystem] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\F12] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\Fax] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\Feeds] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\FTP] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\GameBar] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\GameBarApi] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\IdentityCRL] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\IME] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\Input] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\InputMethod] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\InputPersonalization] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\Installer] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\Internet Connection Wizard] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\Internet Explorer] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\Keyboard] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\LanguageOverlay] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\MediaPlayer] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\Microsoft Management Console] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\Microsoft SQL Server] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\MobilePC] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\MPEG2Demultiplexer] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\MSF] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\Multimedia] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\MVA] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\Narrator] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\NGC] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\Notepad] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\Office] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\OneDrive] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\Osk] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\PCHC] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\PCHealthCheck] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\PeerNet] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\Personalization] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\Phone] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\Pim] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\Poom] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\RAS AutoDial] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\RAS Phonebook] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\Remote Assistance] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\ResKit] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\ScreenMagnifier] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\Sensors] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\SkyDrive] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\Speech] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\Speech Virtual] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\Speech_OneCore] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\Spelling] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\SQMClient] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\SystemCertificates] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\TabletTip] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\TPG] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\UEV] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\Unified Store] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\Unistore] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\UserData] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\WAB] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\WcmSvc] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\wfs] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\Windows] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\Windows Defender Security Center] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\Windows Media] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\Windows Media Foundation] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\Windows NT] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\Windows Script] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\Windows Script Host] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\Windows Search] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\Windows Security Health] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\Wisp] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\XboxLive] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\Software\Microsoft\Windows\AssignedAccessConfiguration] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\Software\Microsoft\Windows\CurrentVersion] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\Software\Microsoft\Windows\DWM] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\Software\Microsoft\Windows\Shell] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\Software\Microsoft\Windows\TabletPC] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\Software\Microsoft\Windows\Windows Error Reporting] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\Software\Microsoft\Windows\Winlogon] [HKU\S-1-5-21-3835695913-52790398-83466441-1001\Software\Microsoft\Windows NT\CurrentVersion] [HKLM\Software\6fd47695-9ae0-492c-a3a2-db9be0a547d4] [HKLM\Software\AGEIA Technologies] [HKLM\Software\AIX INSTALLER] [HKLM\Software\AMD] [HKLM\Software\AMDLOG] [HKLM\Software\Apple Inc.] [HKLM\Software\ATI] [HKLM\Software\ATI Technologies] [HKLM\Software\AUEP] [HKLM\Software\Clients] [HKLM\Software\CVSM] [HKLM\Software\DefaultUserEnvironment] [HKLM\Software\Dolby] [HKLM\Software\dotnet] [HKLM\Software\DTS] [HKLM\Software\EA Games] [HKLM\Software\EA Sports] [HKLM\Software\Fortemedia] [HKLM\Software\g3n-h@ckm@n] [HKLM\Software\Google] [HKLM\Software\Guillemot] [HKLM\Software\INextUUID] [HKLM\Software\Intel] [HKLM\Software\IPS] [HKLM\Software\JavaSoft] [HKLM\Software\JreMetrics] [HKLM\Software\Khronos] [HKLM\Software\Knowles] [HKLM\Software\Maxon] [HKLM\Software\Microsoft] [HKLM\Software\MozillaPlugins] [HKLM\Software\Nahimic] [HKLM\Software\Nuance] [HKLM\Software\NVIDIA Corporation] [HKLM\Software\ODBC] [HKLM\Software\OEM] [HKLM\Software\OpenSSH] [HKLM\Software\Oracle] [HKLM\Software\Partner] [HKLM\Software\Piriform] [HKLM\Software\Policies] [HKLM\Software\Realtek] [HKLM\Software\RegisteredApplications] [HKLM\Software\SonicFocus] [HKLM\Software\SoundResearch] [HKLM\Software\SRS Labs] [HKLM\Software\Thrustmaster] [HKLM\Software\Waves Audio] [HKLM\Software\Windows] [HKLM\Software\WOW6432Node] [HKLM\Software\Yamaha APO] [HKLM\SOFTWARE\Microsoft\.NETFramework] [HKLM\SOFTWARE\Microsoft\AccountsControl] [HKLM\SOFTWARE\Microsoft\Active Setup] [HKLM\SOFTWARE\Microsoft\ActiveSync] [HKLM\SOFTWARE\Microsoft\ADs] [HKLM\SOFTWARE\Microsoft\Advanced INF Setup] [HKLM\SOFTWARE\Microsoft\ALG] [HKLM\SOFTWARE\Microsoft\AllUserInstallAgent] [HKLM\SOFTWARE\Microsoft\AMSI] [HKLM\SOFTWARE\Microsoft\Analog] [HKLM\SOFTWARE\Microsoft\AppServiceProtocols] [HKLM\SOFTWARE\Microsoft\AppV] [HKLM\SOFTWARE\Microsoft\ASP.NET] [HKLM\SOFTWARE\Microsoft\Assistance] [HKLM\SOFTWARE\Microsoft\AudioCompressionManager] [HKLM\SOFTWARE\Microsoft\AuthHost] [HKLM\SOFTWARE\Microsoft\BidInterface] [HKLM\SOFTWARE\Microsoft\BitLockerCsp] [HKLM\SOFTWARE\Microsoft\CallAndMessagingEnhancement] [HKLM\SOFTWARE\Microsoft\Cellular] [HKLM\SOFTWARE\Microsoft\Chkdsk] [HKLM\SOFTWARE\Microsoft\Clipboard] [HKLM\SOFTWARE\Microsoft\ClipboardServer] [HKLM\SOFTWARE\Microsoft\CloudManagedUpdate] [HKLM\SOFTWARE\Microsoft\COM3] [HKLM\SOFTWARE\Microsoft\Command Processor] [HKLM\SOFTWARE\Microsoft\CommsAPHost] [HKLM\SOFTWARE\Microsoft\CoreShell] [HKLM\SOFTWARE\Microsoft\Cryptography] [HKLM\SOFTWARE\Microsoft\CTF] [HKLM\SOFTWARE\Microsoft\DataAccess] [HKLM\SOFTWARE\Microsoft\DataCollection] [HKLM\SOFTWARE\Microsoft\DataSharing] [HKLM\SOFTWARE\Microsoft\DDDS] [HKLM\SOFTWARE\Microsoft\DevDiv] [HKLM\SOFTWARE\Microsoft\Device Association Framework] [HKLM\SOFTWARE\Microsoft\DeviceReg] [HKLM\SOFTWARE\Microsoft\Dfrg] [HKLM\SOFTWARE\Microsoft\DFS] [HKLM\SOFTWARE\Microsoft\DiagnosticLogCSP] [HKLM\SOFTWARE\Microsoft\DirectDraw] [HKLM\SOFTWARE\Microsoft\DirectInput] [HKLM\SOFTWARE\Microsoft\DirectMusic] [HKLM\SOFTWARE\Microsoft\DirectPlay8] [HKLM\SOFTWARE\Microsoft\DirectPlayNATHelp] [HKLM\SOFTWARE\Microsoft\DirectShow] [HKLM\SOFTWARE\Microsoft\DirectX] [HKLM\SOFTWARE\Microsoft\DownloadManager] [HKLM\SOFTWARE\Microsoft\Driver Signing] [HKLM\SOFTWARE\Microsoft\DRM] [HKLM\SOFTWARE\Microsoft\DusmSvc] [HKLM\SOFTWARE\Microsoft\DVDNavigator] [HKLM\SOFTWARE\Microsoft\DVR] [HKLM\SOFTWARE\Microsoft\DXP] [HKLM\SOFTWARE\Microsoft\EAPSIMMethods] [HKLM\SOFTWARE\Microsoft\Edge] [HKLM\SOFTWARE\Microsoft\Enrollment] [HKLM\SOFTWARE\Microsoft\Enrollments] [HKLM\SOFTWARE\Microsoft\EnterpriseCertificates] [HKLM\SOFTWARE\Microsoft\EnterpriseResourceManager] [HKLM\SOFTWARE\Microsoft\EventSounds] [HKLM\SOFTWARE\Microsoft\EventSystem] [HKLM\SOFTWARE\Microsoft\F12] [HKLM\SOFTWARE\Microsoft\FamilyStore] [HKLM\SOFTWARE\Microsoft\Fax] [HKLM\SOFTWARE\Microsoft\FaxServer] [HKLM\SOFTWARE\Microsoft\Feeds] [HKLM\SOFTWARE\Microsoft\FilePicker] [HKLM\SOFTWARE\Microsoft\FilterDS] [HKLM\SOFTWARE\Microsoft\FingerKB] [HKLM\SOFTWARE\Microsoft\FTH] [HKLM\SOFTWARE\Microsoft\Function Discovery] [HKLM\SOFTWARE\Microsoft\Fusion] [HKLM\SOFTWARE\Microsoft\FuzzyDS] [HKLM\SOFTWARE\Microsoft\GameOverlay] [HKLM\SOFTWARE\Microsoft\HTMLHelp] [HKLM\SOFTWARE\Microsoft\Hvsi] [HKLM\SOFTWARE\Microsoft\IdentityCRL] [HKLM\SOFTWARE\Microsoft\IdentityStore] [HKLM\SOFTWARE\Microsoft\IHDS] [HKLM\SOFTWARE\Microsoft\ImageTimeSettings] [HKLM\SOFTWARE\Microsoft\IMAPI] [HKLM\SOFTWARE\Microsoft\IME] [HKLM\SOFTWARE\Microsoft\IMEJP] [HKLM\SOFTWARE\Microsoft\IMEKR] [HKLM\SOFTWARE\Microsoft\IMETC] [HKLM\SOFTWARE\Microsoft\InProcLogger] [HKLM\SOFTWARE\Microsoft\Input] [HKLM\SOFTWARE\Microsoft\InputMethod] [HKLM\SOFTWARE\Microsoft\InputPersonalization] [HKLM\SOFTWARE\Microsoft\Internet Account Manager] [HKLM\SOFTWARE\Microsoft\Internet Domains] [HKLM\SOFTWARE\Microsoft\Internet Explorer] [HKLM\SOFTWARE\Microsoft\IsoBurn] [HKLM\SOFTWARE\Microsoft\KGL] [HKLM\SOFTWARE\Microsoft\LanguageOverlay] [HKLM\SOFTWARE\Microsoft\LexiconUpdate] [HKLM\SOFTWARE\Microsoft\Managed Desktop] [HKLM\SOFTWARE\Microsoft\MdmCommon] [HKLM\SOFTWARE\Microsoft\MdmDiagnostics] [HKLM\SOFTWARE\Microsoft\MediaEngine] [HKLM\SOFTWARE\Microsoft\MediaPlayer] [HKLM\SOFTWARE\Microsoft\MemoryDiagnostic] [HKLM\SOFTWARE\Microsoft\Messaging] [HKLM\SOFTWARE\Microsoft\MessengerService] [HKLM\SOFTWARE\Microsoft\Microsoft Camera Codec Pack] [HKLM\SOFTWARE\Microsoft\Microsoft SQL Server] [HKLM\SOFTWARE\Microsoft\Microsoft SQL Server 2014 Redist] [HKLM\SOFTWARE\Microsoft\Microsoft SQL Server Local DB] [HKLM\SOFTWARE\Microsoft\MiracastReceiver] [HKLM\SOFTWARE\Microsoft\MMC] [HKLM\SOFTWARE\Microsoft\Mobile] [HKLM\SOFTWARE\Microsoft\MpSigStub] [HKLM\SOFTWARE\Microsoft\MSBuild] [HKLM\SOFTWARE\Microsoft\MSDE] [HKLM\SOFTWARE\Microsoft\MSDRM] [HKLM\SOFTWARE\Microsoft\MSDTC] [HKLM\SOFTWARE\Microsoft\MSF] [HKLM\SOFTWARE\Microsoft\MSIME] [HKLM\SOFTWARE\Microsoft\MSLicensing] [HKLM\SOFTWARE\Microsoft\MSMQ] [HKLM\SOFTWARE\Microsoft\MSN Apps] [HKLM\SOFTWARE\Microsoft\MTF] [HKLM\SOFTWARE\Microsoft\MTFFuzzyFactors] [HKLM\SOFTWARE\Microsoft\MTFInputType] [HKLM\SOFTWARE\Microsoft\MTFKeyboardMappings] [HKLM\SOFTWARE\Microsoft\Multimedia] [HKLM\SOFTWARE\Microsoft\Multivariant] [HKLM\SOFTWARE\Microsoft\NET Framework Setup] [HKLM\SOFTWARE\Microsoft\NetSh] [HKLM\SOFTWARE\Microsoft\Network] [HKLM\SOFTWARE\Microsoft\Non-Driver Signing] [HKLM\SOFTWARE\Microsoft\Notepad] [HKLM\SOFTWARE\Microsoft\ODBC] [HKLM\SOFTWARE\Microsoft\OEM] [HKLM\SOFTWARE\Microsoft\OfficeCSP] [HKLM\SOFTWARE\Microsoft\Ole] [HKLM\SOFTWARE\Microsoft\OnlineProviders] [HKLM\SOFTWARE\Microsoft\Outlook Express] [HKLM\SOFTWARE\Microsoft\Palm] [HKLM\SOFTWARE\Microsoft\Personalization] [HKLM\SOFTWARE\Microsoft\Phone] [HKLM\SOFTWARE\Microsoft\Photos] [HKLM\SOFTWARE\Microsoft\Pim] [HKLM\SOFTWARE\Microsoft\PLA] [HKLM\SOFTWARE\Microsoft\PlayToReceiver] [HKLM\SOFTWARE\Microsoft\PointOfService] [HKLM\SOFTWARE\Microsoft\Policies] [HKLM\SOFTWARE\Microsoft\PolicyManager] [HKLM\SOFTWARE\Microsoft\Poom] [HKLM\SOFTWARE\Microsoft\PowerShell] [HKLM\SOFTWARE\Microsoft\Print] [HKLM\SOFTWARE\Microsoft\Provisioning] [HKLM\SOFTWARE\Microsoft\PushRouter] [HKLM\SOFTWARE\Microsoft\RADAR] [HKLM\SOFTWARE\Microsoft\Ras] [HKLM\SOFTWARE\Microsoft\RcsPresence] [HKLM\SOFTWARE\Microsoft\Reliability Analysis] [HKLM\SOFTWARE\Microsoft\Remediation] [HKLM\SOFTWARE\Microsoft\RemovalTools] [HKLM\SOFTWARE\Microsoft\RendezvousApps] [HKLM\SOFTWARE\Microsoft\Router] [HKLM\SOFTWARE\Microsoft\Rpc] [HKLM\SOFTWARE\Microsoft\SchedulingAgent] [HKLM\SOFTWARE\Microsoft\Security Center] [HKLM\SOFTWARE\Microsoft\SecurityManager] [HKLM\SOFTWARE\Microsoft\SEMgr] [HKLM\SOFTWARE\Microsoft\Sensors] [HKLM\SOFTWARE\Microsoft\Shared Tools] [HKLM\SOFTWARE\Microsoft\Shared Tools Location] [HKLM\SOFTWARE\Microsoft\Shell] [HKLM\SOFTWARE\Microsoft\SIH] [HKLM\SOFTWARE\Microsoft\Siuf] [HKLM\SOFTWARE\Microsoft\SoftGrid] [HKLM\SOFTWARE\Microsoft\Software] [HKLM\SOFTWARE\Microsoft\Speec] [HKLM\SOFTWARE\Microsoft\Speech] [HKLM\SOFTWARE\Microsoft\Speech_OneCore] [HKLM\SOFTWARE\Microsoft\SQMClient] [HKLM\SOFTWARE\Microsoft\Sync Framework] [HKLM\SOFTWARE\Microsoft\Sysprep] [HKLM\SOFTWARE\Microsoft\SystemCertificates] [HKLM\SOFTWARE\Microsoft\SystemSettings] [HKLM\SOFTWARE\Microsoft\TableTextService] [HKLM\SOFTWARE\Microsoft\TabletTip] [HKLM\SOFTWARE\Microsoft\TaskFlowDataEngine] [HKLM\SOFTWARE\Microsoft\Tcpip] [HKLM\SOFTWARE\Microsoft\TelemetryClient] [HKLM\SOFTWARE\Microsoft\Terminal Server Client] [HKLM\SOFTWARE\Microsoft\TermServLicensing] [HKLM\SOFTWARE\Microsoft\TouchPrediction] [HKLM\SOFTWARE\Microsoft\TPG] [HKLM\SOFTWARE\Microsoft\Tpm] [HKLM\SOFTWARE\Microsoft\Tracing] [HKLM\SOFTWARE\Microsoft\Transaction Server] [HKLM\SOFTWARE\Microsoft\TV System Services] [HKLM\SOFTWARE\Microsoft\uDRM] [HKLM\SOFTWARE\Microsoft\UEV] [HKLM\SOFTWARE\Microsoft\Unified Store] [HKLM\SOFTWARE\Microsoft\UNP] [HKLM\SOFTWARE\Microsoft\UPnP Control Point] [HKLM\SOFTWARE\Microsoft\UPnP Device Host] [HKLM\SOFTWARE\Microsoft\UserData] [HKLM\SOFTWARE\Microsoft\UserManager] [HKLM\SOFTWARE\Microsoft\Virtual Machine] [HKLM\SOFTWARE\Microsoft\VisualStudio] [HKLM\SOFTWARE\Microsoft\WAB] [HKLM\SOFTWARE\Microsoft\Wallet] [HKLM\SOFTWARE\Microsoft\Wbem] [HKLM\SOFTWARE\Microsoft\WcmSvc] [HKLM\SOFTWARE\Microsoft\WIMMount] [HKLM\SOFTWARE\Microsoft\Windows] [HKLM\SOFTWARE\Microsoft\Windows Advanced Threat Protection] [HKLM\SOFTWARE\Microsoft\Windows Defender] [HKLM\SOFTWARE\Microsoft\Windows Defender Security Center] [HKLM\SOFTWARE\Microsoft\Windows Desktop Search] [HKLM\SOFTWARE\Microsoft\Windows Embedded] [HKLM\SOFTWARE\Microsoft\Windows Mail] [HKLM\SOFTWARE\Microsoft\Windows Media Device Manager] [HKLM\SOFTWARE\Microsoft\Windows Media Foundation] [HKLM\SOFTWARE\Microsoft\Windows Media Player NSS] [HKLM\SOFTWARE\Microsoft\Windows Messaging Subsystem] [HKLM\SOFTWARE\Microsoft\Windows NT] [HKLM\SOFTWARE\Microsoft\Windows Photo Viewer] [HKLM\SOFTWARE\Microsoft\Windows Portable Devices] [HKLM\SOFTWARE\Microsoft\Windows Script Host] [HKLM\SOFTWARE\Microsoft\Windows Search] [HKLM\SOFTWARE\Microsoft\Windows Security Health] [HKLM\SOFTWARE\Microsoft\WindowsRuntime] [HKLM\SOFTWARE\Microsoft\WindowsSelfHost] [HKLM\SOFTWARE\Microsoft\WindowsUpdate] [HKLM\SOFTWARE\Microsoft\Wisp] [HKLM\SOFTWARE\Microsoft\WlanSvc] [HKLM\SOFTWARE\Microsoft\Wlpasvc] [HKLM\SOFTWARE\Microsoft\Wow64] [HKLM\SOFTWARE\Microsoft\WSDAPI] [HKLM\SOFTWARE\Microsoft\WwanSvc] [HKLM\SOFTWARE\Microsoft\XAML] [HKLM\SOFTWARE\Microsoft\XboxLive] [HKLM\Software\Microsoft\Windows\AssignedAccessConfiguration] [HKLM\Software\Microsoft\Windows\AssignedAccessCsp] [HKLM\Software\Microsoft\Windows\Autopilot] [HKLM\Software\Microsoft\Windows\ClickNote] [HKLM\Software\Microsoft\Windows\CurrentVersion] [HKLM\Software\Microsoft\Windows\DeviceUpdateCenter] [HKLM\Software\Microsoft\Windows\Dwm] [HKLM\Software\Microsoft\Windows\DynamicManagement] [HKLM\Software\Microsoft\Windows\EnterpriseResourceManager] [HKLM\Software\Microsoft\Windows\Heat] [HKLM\Software\Microsoft\Windows\HTML Help] [HKLM\Software\Microsoft\Windows\ITStorage] [HKLM\Software\Microsoft\Windows\NcsiUwpApp] [HKLM\Software\Microsoft\Windows\Notepad] [HKLM\Software\Microsoft\Windows\ScheduledDiagnostics] [HKLM\Software\Microsoft\Windows\ScriptedDiagnosticsProvider] [HKLM\Software\Microsoft\Windows\Shell] [HKLM\Software\Microsoft\Windows\Tablet PC] [HKLM\Software\Microsoft\Windows\TabletPC] [HKLM\Software\Microsoft\Windows\TenantRestrictions] [HKLM\Software\Microsoft\Windows\UpdateApi] [HKLM\Software\Microsoft\Windows\Windows Error Reporting] [HKLM\Software\Microsoft\Windows\Windows Search] [HKLM\Software\Microsoft\Windows NT\CurrentVersion] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\AarSvc] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\appmodel] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\AssignedAccessManagerSvc] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\autotimesvc] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\BcastDVRUserService] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\btagservice] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\BthAppGroup] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\Camera] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\ClipboardSvcGroup] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\defragsvc] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\DevicesFlow] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\diagnostics] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\DialogBlockingService] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\GraphicsPerfSvcGroup] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\ICService] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalService] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceAndNoImpersonation] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceHttp] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceNetworkRestricted] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceNetworkRestrictedDhcpLmHosts] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceNoNetwork] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceNoNetworkFirewall] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalSystemNetworkRestricted] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\netsvcs] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\NetworkService] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\NetworkServiceDnsNla] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\NetworkServiceRemoteDesktopHyperVAgent] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\NetworkServiceRemoteDesktopPublishing] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\print] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\PrintWorkflow] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\rdxgroup] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\RmSvc] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\SDRSVC] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\swprv] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\termsvcs] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\UdkSvcGroup] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\UnistackSvcGroup] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\utcsvc] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\WepHostSvcGroup] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\wercplsupport] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\wsappx] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\wusvcs] [HKLM\Software\WOW6432Node\7-Zip] [HKLM\Software\WOW6432Node\AGEIA Technologies] [HKLM\Software\WOW6432Node\AMD] [HKLM\Software\WOW6432Node\ATI Technologies] [HKLM\Software\WOW6432Node\Avast Software] [HKLM\Software\WOW6432Node\Caphyon] [HKLM\Software\WOW6432Node\dotnet] [HKLM\Software\WOW6432Node\EA Games] [HKLM\Software\WOW6432Node\EA Sports] [HKLM\Software\WOW6432Node\Google] [HKLM\Software\WOW6432Node\Intel] [HKLM\Software\WOW6432Node\IObit] [HKLM\Software\WOW6432Node\JavaSoft] [HKLM\Software\WOW6432Node\JreMetrics] [HKLM\Software\WOW6432Node\Khronos] [HKLM\Software\WOW6432Node\Lavasoft] [HKLM\Software\WOW6432Node\Microsoft] [HKLM\Software\WOW6432Node\MSI] [HKLM\Software\WOW6432Node\Nuance] [HKLM\Software\WOW6432Node\NVIDIA Corporation] [HKLM\Software\WOW6432Node\ODBC] [HKLM\Software\WOW6432Node\Origin Games] [HKLM\Software\WOW6432Node\SRS Labs] [HKLM\Software\WOW6432Node\TFDi Design] [HKLM\Software\WOW6432Node\Thrustmaster] [HKLM\Software\WOW6432Node\Ubisoft] [HKLM\Software\WOW6432Node\Unwinder] [HKLM\Software\WOW6432Node\Valve] [HKLM\Software\WOW6432Node\Volatile] [HKLM\Software\WOW6432Node\WOW6432Node] [HKLM\Software\WOW6432Node\Clients] [HKLM\Software\WOW6432Node\Policies] [HKLM\Software\WOW6432Node\RegisteredApplications] [HKLM\Software\WOW6432Node\Microsoft\.NETFramework] [HKLM\Software\WOW6432Node\Microsoft\Active Setup] [HKLM\Software\WOW6432Node\Microsoft\ADs] [HKLM\Software\WOW6432Node\Microsoft\Advanced INF Setup] [HKLM\Software\WOW6432Node\Microsoft\AMSI] [HKLM\Software\WOW6432Node\Microsoft\AppServiceProtocols] [HKLM\Software\WOW6432Node\Microsoft\AppV] [HKLM\Software\WOW6432Node\Microsoft\ASP.NET] [HKLM\Software\WOW6432Node\Microsoft\Assistance] [HKLM\Software\WOW6432Node\Microsoft\AudioCompressionManager] [HKLM\Software\WOW6432Node\Microsoft\AuthHost] [HKLM\Software\WOW6432Node\Microsoft\BidInterface] [HKLM\Software\WOW6432Node\Microsoft\BitLockerCsp] [HKLM\Software\WOW6432Node\Microsoft\ClipboardServer] [HKLM\Software\WOW6432Node\Microsoft\Command Processor] [HKLM\Software\WOW6432Node\Microsoft\Cryptography] [HKLM\Software\WOW6432Node\Microsoft\CTF] [HKLM\Software\WOW6432Node\Microsoft\DataAccess] [HKLM\Software\WOW6432Node\Microsoft\DevDiv] [HKLM\Software\WOW6432Node\Microsoft\Device Association Framework] [HKLM\Software\WOW6432Node\Microsoft\Direct3D] [HKLM\Software\WOW6432Node\Microsoft\DirectDraw] [HKLM\Software\WOW6432Node\Microsoft\DirectInput] [HKLM\Software\WOW6432Node\Microsoft\DirectMusic] [HKLM\Software\WOW6432Node\Microsoft\DirectPlay] [HKLM\Software\WOW6432Node\Microsoft\DirectPlay8] [HKLM\Software\WOW6432Node\Microsoft\DirectPlayNATHelp] [HKLM\Software\WOW6432Node\Microsoft\DirectShow] [HKLM\Software\WOW6432Node\Microsoft\DirectX] [HKLM\Software\WOW6432Node\Microsoft\DownloadManager] [HKLM\Software\WOW6432Node\Microsoft\DRM] [HKLM\Software\WOW6432Node\Microsoft\DVDNavigator] [HKLM\Software\WOW6432Node\Microsoft\DVR] [HKLM\Software\WOW6432Node\Microsoft\EAPSIMMethods] [HKLM\Software\WOW6432Node\Microsoft\Edge] [HKLM\Software\WOW6432Node\Microsoft\EdgeUpdate] [HKLM\Software\WOW6432Node\Microsoft\ENROLLMENTS] [HKLM\Software\WOW6432Node\Microsoft\EnterpriseResourceManager] [HKLM\Software\WOW6432Node\Microsoft\Exchange] [HKLM\Software\WOW6432Node\Microsoft\F12] [HKLM\Software\WOW6432Node\Microsoft\Fax] [HKLM\Software\WOW6432Node\Microsoft\Feeds] [HKLM\Software\WOW6432Node\Microsoft\FilePicker] [HKLM\Software\WOW6432Node\Microsoft\Function Discovery] [HKLM\Software\WOW6432Node\Microsoft\Fusion] [HKLM\Software\WOW6432Node\Microsoft\GameOverlay] [HKLM\Software\WOW6432Node\Microsoft\HTMLHelp] [HKLM\Software\WOW6432Node\Microsoft\IdentityCRL] [HKLM\Software\WOW6432Node\Microsoft\IdentityStore] [HKLM\Software\WOW6432Node\Microsoft\IMAPI] [HKLM\Software\WOW6432Node\Microsoft\IME] [HKLM\Software\WOW6432Node\Microsoft\IMEJP] [HKLM\Software\WOW6432Node\Microsoft\IMEKR] [HKLM\Software\WOW6432Node\Microsoft\IMETC] [HKLM\Software\WOW6432Node\Microsoft\InputMethod] [HKLM\Software\WOW6432Node\Microsoft\InputPersonalization] [HKLM\Software\WOW6432Node\Microsoft\Internet Account Manager] [HKLM\Software\WOW6432Node\Microsoft\Internet Domains] [HKLM\Software\WOW6432Node\Microsoft\Internet Explorer] [HKLM\Software\WOW6432Node\Microsoft\IsoBurn] [HKLM\Software\WOW6432Node\Microsoft\Jet] [HKLM\Software\WOW6432Node\Microsoft\MediaEngine] [HKLM\Software\WOW6432Node\Microsoft\MediaPlayer] [HKLM\Software\WOW6432Node\Microsoft\MessengerService] [HKLM\Software\WOW6432Node\Microsoft\Microsoft Camera Codec Pack] [HKLM\Software\WOW6432Node\Microsoft\Microsoft SQL Server Local DB] [HKLM\Software\WOW6432Node\Microsoft\MiracastReceiver] [HKLM\Software\WOW6432Node\Microsoft\MMC] [HKLM\Software\WOW6432Node\Microsoft\MSBuild] [HKLM\Software\WOW6432Node\Microsoft\MSDE] [HKLM\Software\WOW6432Node\Microsoft\MSDRM] [HKLM\Software\WOW6432Node\Microsoft\MSDTC] [HKLM\Software\WOW6432Node\Microsoft\MSF] [HKLM\Software\WOW6432Node\Microsoft\MSLicensing] [HKLM\Software\WOW6432Node\Microsoft\MSN Apps] [HKLM\Software\WOW6432Node\Microsoft\Multimedia] [HKLM\Software\WOW6432Node\Microsoft\NET Framework Setup] [HKLM\Software\WOW6432Node\Microsoft\NetSh] [HKLM\Software\WOW6432Node\Microsoft\Network] [HKLM\Software\WOW6432Node\Microsoft\Notepad] [HKLM\Software\WOW6432Node\Microsoft\ODBC] [HKLM\Software\WOW6432Node\Microsoft\OEM] [HKLM\Software\WOW6432Node\Microsoft\Office Server] [HKLM\Software\WOW6432Node\Microsoft\OnlineProviders] [HKLM\Software\WOW6432Node\Microsoft\Outlook Express] [HKLM\Software\WOW6432Node\Microsoft\Palm] [HKLM\Software\WOW6432Node\Microsoft\Personalization] [HKLM\Software\WOW6432Node\Microsoft\Photos] [HKLM\Software\WOW6432Node\Microsoft\PLA] [HKLM\Software\WOW6432Node\Microsoft\Policies] [HKLM\Software\WOW6432Node\Microsoft\PowerShell] [HKLM\Software\WOW6432Node\Microsoft\Print] [HKLM\Software\WOW6432Node\Microsoft\Provisioning] [HKLM\Software\WOW6432Node\Microsoft\RADAR] [HKLM\Software\WOW6432Node\Microsoft\RendezvousApps] [HKLM\Software\WOW6432Node\Microsoft\SchedulingAgent] [HKLM\Software\WOW6432Node\Microsoft\Security Center] [HKLM\Software\WOW6432Node\Microsoft\Sensors] [HKLM\Software\WOW6432Node\Microsoft\Shared Tools] [HKLM\Software\WOW6432Node\Microsoft\Shared Tools Location] [HKLM\Software\WOW6432Node\Microsoft\Software] [HKLM\Software\WOW6432Node\Microsoft\SPEECH] [HKLM\Software\WOW6432Node\Microsoft\Speech_OneCore] [HKLM\Software\WOW6432Node\Microsoft\SQMClient] [HKLM\Software\WOW6432Node\Microsoft\Sync Framework] [HKLM\Software\WOW6432Node\Microsoft\SystemSettings] [HKLM\Software\WOW6432Node\Microsoft\TableTextService] [HKLM\Software\WOW6432Node\Microsoft\TabletTip] [HKLM\Software\WOW6432Node\Microsoft\Tcpip] [HKLM\Software\WOW6432Node\Microsoft\Terminal Server Client] [HKLM\Software\WOW6432Node\Microsoft\TouchPrediction] [HKLM\Software\WOW6432Node\Microsoft\TPG] [HKLM\Software\WOW6432Node\Microsoft\Tpm] [HKLM\Software\WOW6432Node\Microsoft\Tracing] [HKLM\Software\WOW6432Node\Microsoft\TV System Services] [HKLM\Software\WOW6432Node\Microsoft\uDRM] [HKLM\Software\WOW6432Node\Microsoft\UEV] [HKLM\Software\WOW6432Node\Microsoft\Updates] [HKLM\Software\WOW6432Node\Microsoft\UPnP Control Point] [HKLM\Software\WOW6432Node\Microsoft\UPnP Device Host] [HKLM\Software\WOW6432Node\Microsoft\VisualStudio] [HKLM\Software\WOW6432Node\Microsoft\WAB] [HKLM\Software\WOW6432Node\Microsoft\WBEM] [HKLM\Software\WOW6432Node\Microsoft\WIMMount] [HKLM\Software\WOW6432Node\Microsoft\Windows] [HKLM\Software\WOW6432Node\Microsoft\Windows Desktop Search] [HKLM\Software\WOW6432Node\Microsoft\Windows Mail] [HKLM\Software\WOW6432Node\Microsoft\Windows Media Device Manager] [HKLM\Software\WOW6432Node\Microsoft\Windows Media Foundation] [HKLM\Software\WOW6432Node\Microsoft\Windows Media Player NSS] [HKLM\Software\WOW6432Node\Microsoft\Windows Messaging Subsystem] [HKLM\Software\WOW6432Node\Microsoft\Windows NT] [HKLM\Software\WOW6432Node\Microsoft\Windows Photo Viewer] [HKLM\Software\WOW6432Node\Microsoft\Windows Portable Devices] [HKLM\Software\WOW6432Node\Microsoft\Windows Script Host] [HKLM\Software\WOW6432Node\Microsoft\WindowsRuntime] [HKLM\Software\WOW6432Node\Microsoft\WindowsUpdate] [HKLM\Software\WOW6432Node\Microsoft\Wisp] [HKLM\Software\WOW6432Node\Microsoft\WlanSvc] [HKLM\Software\WOW6432Node\Microsoft\WSDAPI] [HKLM\Software\WOW6432Node\Microsoft\Cellular] [HKLM\Software\WOW6432Node\Microsoft\COM3] [HKLM\Software\WOW6432Node\Microsoft\DeviceReg] [HKLM\Software\WOW6432Node\Microsoft\DFS] [HKLM\Software\WOW6432Node\Microsoft\Driver Signing] [HKLM\Software\WOW6432Node\Microsoft\EnterpriseCertificates] [HKLM\Software\WOW6432Node\Microsoft\EventSystem] [HKLM\Software\WOW6432Node\Microsoft\FingerKB] [HKLM\Software\WOW6432Node\Microsoft\FuzzyDS] [HKLM\Software\WOW6432Node\Microsoft\Input] [HKLM\Software\WOW6432Node\Microsoft\LanguageOverlay] [HKLM\Software\WOW6432Node\Microsoft\Messaging] [HKLM\Software\WOW6432Node\Microsoft\MSMQ] [HKLM\Software\WOW6432Node\Microsoft\MTF] [HKLM\Software\WOW6432Node\Microsoft\MTFFuzzyFactors] [HKLM\Software\WOW6432Node\Microsoft\MTFInputType] [HKLM\Software\WOW6432Node\Microsoft\MTFKeyboardMappings] [HKLM\Software\WOW6432Node\Microsoft\Non-Driver Signing] [HKLM\Software\WOW6432Node\Microsoft\Ole] [HKLM\Software\WOW6432Node\Microsoft\Phone] [HKLM\Software\WOW6432Node\Microsoft\Pim] [HKLM\Software\WOW6432Node\Microsoft\Poom] [HKLM\Software\WOW6432Node\Microsoft\Ras] [HKLM\Software\WOW6432Node\Microsoft\Rpc] [HKLM\Software\WOW6432Node\Microsoft\SecurityManager] [HKLM\Software\WOW6432Node\Microsoft\Semgr] [HKLM\Software\WOW6432Node\Microsoft\Shell] [HKLM\Software\WOW6432Node\Microsoft\SystemCertificates] [HKLM\Software\WOW6432Node\Microsoft\TermServLicensing] [HKLM\Software\WOW6432Node\Microsoft\Transaction Server] [HKLM\Software\WOW6432Node\Microsoft\Unified Store] [HKLM\Software\WOW6432Node\Microsoft\UserData] [HKLM\Software\WOW6432Node\Microsoft\Windows Search] [HKLM\Software\WOW6432Node\Microsoft\XAML] [HKLM\Software\WOW6432Node\Microsoft\Windows\ClickNote] [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion] [HKLM\Software\WOW6432Node\Microsoft\Windows\Dwm] [HKLM\Software\WOW6432Node\Microsoft\Windows\EnterpriseResourceManager] [HKLM\Software\WOW6432Node\Microsoft\Windows\Heat] [HKLM\Software\WOW6432Node\Microsoft\Windows\HTML Help] [HKLM\Software\WOW6432Node\Microsoft\Windows\ITStorage] [HKLM\Software\WOW6432Node\Microsoft\Windows\ScriptedDiagnosticsProvider] [HKLM\Software\WOW6432Node\Microsoft\Windows\Tablet PC] [HKLM\Software\WOW6432Node\Microsoft\Windows\UpdateApi] [HKLM\Software\WOW6432Node\Microsoft\Windows\Windows Error Reporting] [HKLM\Software\WOW6432Node\Microsoft\Windows\Windows Search] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\AarSvc] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\appmodel] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalService] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceAndNoImpersonation] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceHttp] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceNetworkRestricted] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceNetworkRestrictedDhcpLmHosts] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceNoNetwork] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceNoNetworkFirewall] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalSystemNetworkRestricted] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\netsvcs] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\NetworkService] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\NetworkServiceDnsNla] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\NetworkServiceRemoteDesktopHyperVAgent] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\NetworkServiceRemoteDesktopPublishing] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\PrintWorkflow] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\termsvcs] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\wusvcs] ---------- | Drives D: E: [07/11/2007 08:03:18] - |A| - (.(C) Microsoft Corporation. - UI Wrapper Resource DLL.) - [76304] - (9.0.21022.8) - E:\install.res.1028.dll [07/11/2007 08:03:18] - |A| - (.© Microsoft Corporation. Alle Rechte vorbehalten. - Ressourcen-DLL für UI-Wrapper.) - [96272] - (9.0.21022.8) - E:\install.res.1031.dll [07/11/2007 08:03:18] - |A| - (.© Microsoft Corporation. - UI Wrapper Resource DLL.) - [91152] - (9.0.21022.8) - E:\install.res.1033.dll [07/11/2007 08:03:18] - |A| - (.© Microsoft Corporation. Tous droits réservés. - UI Wrapper Resource DLL.) - [97296] - (9.0.21022.8) - E:\install.res.1036.dll [07/11/2007 08:03:18] - |A| - (.© Microsoft Corporation. Tutti i diritti riservati. - DLL di risorse del wrapper dell'interfaccia utente.) - [95248] - (9.0.21022.8) - E:\install.res.1040.dll [07/11/2007 08:03:18] - |A| - (.(C) Copyright Microsoft Corporation. - UI Wrapper Resource DLL.) - [81424] - (9.0.21022.8) - E:\install.res.1041.dll [07/11/2007 08:03:18] - |A| - (.(C) Microsoft Corporation. - UI ?? ??? DLL.) - [79888] - (9.0.21022.8) - E:\install.res.1042.dll [07/11/2007 08:03:18] - |A| - (.(C) Microsoft Corporation???????? - ???????? DLL.) - [75792] - (9.0.21022.8) - E:\install.res.2052.dll [07/11/2007 08:03:18] - |A| - (.© Microsoft Corporation. Reservados todos los derechos. - Archivo DLL de recursos del contenedor de la interfaz de usuario.) - [96272] - (9.0.21022.8) - E:\install.res.3082.dll [07/11/2007 08:03:18] - |A| - (.© Microsoft Corporation. - External Installer.) - [562688] - (9.0.21022.8) - E:\install.exe [07/11/2007 08:00:40] - |A| - (.-.) - [1110] - (0.0.0.0) - E:\globdata.ini [07/11/2007 08:00:40] - |A| - (.-.) - [843] - (0.0.0.0) - E:\install.ini ---------- | C: [07/12/2019 09:14:52] - |SHD| - [387] - C:\$Recycle.Bin [29/06/2021 12:44:41] - |HD| - [26603221] - C:\$SysReset [10/02/2022 23:00:45] - |HD| - [0] - C:\$WinREAgent [18/07/2021 19:43:38] - |D| - [0] - C:\AILG_MSFS [29/06/2021 14:00:10] - |D| - [4814783667] - C:\AMD [29/06/2021 14:01:17] - |SHD| - [0] - C:\Config.Msi [29/06/2021 12:19:56] - |SHD| - [0] - C:\Documents and Settings [MD5.C0748DA4EE34B14D8C7CF355D576791B] - [29/06/2021 12:17:44] - |ASH| - (.-.) - [8192] - (0.0.0.0) - C:\DumpStack.log [MD5.D41D8CD98F00B204E9800998ECF8427E] - [29/06/2021 12:17:44] - |ASH| - (.-.) - [8192] - (0.0.0.0) - C:\DumpStack.log.tmp [29/06/2021 14:41:31] - |D| - [36240375] - C:\FSUIPC7 [30/06/2021 20:19:54] - |D| - [9464832] - C:\gstreamer-ivao [MD5.D41D8CD98F00B204E9800998ECF8427E] - [25/08/2020 19:35:44] - |ASH| - (.-.) - [10270801920] - (0.0.0.0) - C:\hiberfil.sys [01/02/2022 20:52:26] - |D| - [387911482] - C:\MSFS SDK [29/06/2021 13:57:08] - |HD| - [0] - C:\OneDriveTemp [MD5.D41D8CD98F00B204E9800998ECF8427E] - [09/01/2022 08:07:48] - |ASH| - (.-.) - [18519187456] - (0.0.0.0) - C:\pagefile.sys [07/12/2019 09:14:52] - |D| - [0] - C:\PerfLogs [11/07/2021 11:12:25] - |D| - [1548288] - C:\Pilot2ATC_2018_x64 [14/08/2021 23:55:43] - |D| - [3265030096] - C:\Pilot2ATC_2020_x64 [18/07/2021 19:44:01] - |D| - [57368476] - C:\PPG_MSFS [07/12/2019 09:14:52] - |RD| - [8142576481] - C:\Program Files [07/12/2019 09:14:52] - |RD| - [6075973566] - C:\Program Files (x86) [07/12/2019 09:14:52] - |HD| - [6157884848] - C:\ProgramData [10/02/2022 22:52:46] - |D| - [34] - C:\QuickDiag [MD5.FF4DA11C9B64E6DBB28D947322ABF5AF] - [10/02/2022 22:53:00] - |A| - (.-.) - [294937] - (0.0.0.0) - C:\QuickDiag.txt [29/06/2021 13:15:17] - |SHD| - [1040] - C:\Recovery [01/08/2021 22:59:22] - |D| - [852612] - C:\REX Download Manager [12/01/2022 01:28:35] - |D| - [42412481] - C:\REX Weather Force 2020 [01/08/2021 23:02:16] - |D| - [26403426] - C:\rexdownload [MD5.D41D8CD98F00B204E9800998ECF8427E] - [25/08/2020 19:34:14] - |ASH| - (.-.) - [16777216] - (0.0.0.0) - C:\swapfile.sys [25/08/2020 19:34:13] - |SHD| - [0] - C:\System Volume Information [07/12/2019 09:03:44] - |RD| - [97572456423] - C:\Users [07/12/2019 09:03:44] - |D| - [28197868053] - C:\Windows ---------- | C:\WINDOWS [07/12/2019 14:51:43] - |D| - [802] - C:\WINDOWS\addins [07/12/2019 09:14:52] - |D| - [20331811] - C:\WINDOWS\appcompat [07/12/2019 09:14:52] - |D| - [10239582] - C:\WINDOWS\apppatch [07/12/2019 09:14:52] - |D| - [0] - C:\WINDOWS\AppReadiness [07/12/2019 09:14:52] - |RSD| - [1165923515] - C:\WINDOWS\assembly [07/12/2019 09:14:52] - |D| - [785153] - C:\WINDOWS\bcastdvr [MD5.820B97429E4153A743708B376807EE69] - [17/09/2021 02:24:28] - |A| - (.© Microsoft Corporation. Tous droits réservés. - Utilitaire de service de fichier de démarrage.) - [81408] - (10.0.19041.1237) - C:\WINDOWS\bfsvc.exe [07/12/2019 14:53:51] - |SHD| - [578547] - C:\WINDOWS\BitLockerDiscoveryVolumeContents [07/12/2019 09:14:52] - |D| - [40903422] - C:\WINDOWS\Boot [MD5.DE22301FB846EE1AA9351763418AAF04] - [29/06/2021 13:14:24] - |AS| - (.-.) - [67584] - (0.0.0.0) - C:\WINDOWS\bootstat.dat [07/12/2019 09:14:52] - |D| - [2476032] - C:\WINDOWS\Branding [07/12/2019 09:03:44] - |D| - [1333700252] - C:\WINDOWS\CbsTemp [07/12/2019 09:14:52] - |D| - [69079106] - C:\WINDOWS\Containers [29/06/2021 12:19:49] - |D| - [0] - C:\WINDOWS\CSC [07/12/2019 09:14:52] - |D| - [11501377] - C:\WINDOWS\Cursors [07/12/2019 09:14:52] - |D| - [2116] - C:\WINDOWS\debug [07/12/2019 09:14:52] - |D| - [5165122] - C:\WINDOWS\diagnostics [07/12/2019 09:14:52] - |D| - [1702804] - C:\WINDOWS\DiagTrack [07/12/2019 14:50:20] - |D| - [0] - C:\WINDOWS\DigitalLocker [07/12/2019 09:14:52] - |SD| - [65] - C:\WINDOWS\Downloaded Program Files [07/12/2019 09:14:52] - |HD| - [68624] - C:\WINDOWS\ELAMBKUP [30/01/2022 05:03:38] - |D| - [49152] - C:\WINDOWS\en-GB [07/12/2019 14:50:20] - |D| - [98816] - C:\WINDOWS\en-US [MD5.744F2D2E4AF2C1C64643FDBC60A21B27] - [18/12/2021 11:59:14] - |A| - (.© Microsoft Corporation. Tous droits réservés. - Explorateur Windows.) - [4971808] - (10.0.19041.1415) - C:\WINDOWS\explorer.exe [07/12/2019 09:14:52] - |RSD| - [360995166] - C:\WINDOWS\Fonts [30/01/2022 05:06:08] - |D| - [54784] - C:\WINDOWS\fr-CA [07/12/2019 14:50:20] - |D| - [111616] - C:\WINDOWS\fr-FR [07/12/2019 09:14:52] - |D| - [0] - C:\WINDOWS\GameBarPresenceWriter [07/12/2019 09:14:52] - |D| - [100651527] - C:\WINDOWS\Globalization [07/12/2019 09:14:52] - |D| - [1893706] - C:\WINDOWS\Help [MD5.7E8FAEC2E175C8B45B6D380A6A4C9503] - [01/08/2021 15:20:05] - |A| - (.© Microsoft Corporation. Tous droits réservés. - Aide et support Microsoft.) - [1075712] - (10.0.19041.1151) - C:\WINDOWS\HelpPane.exe [MD5.2C8FE78D53C8CA27523A71DFD2938241] - [07/12/2019 09:09:39] - |A| - (.© Microsoft Corporation. Tous droits réservés. - Exécutable de l’aide HTML Microsoft®.) - [18432] - (10.0.19041.1) - C:\WINDOWS\hh.exe [07/12/2019 09:14:52] - |D| - [30327] - C:\WINDOWS\IdentityCRL [07/12/2019 09:14:52] - |D| - [28830662] - C:\WINDOWS\IME [07/12/2019 09:14:52] - |RD| - [8201357] - C:\WINDOWS\ImmersiveControlPanel [07/12/2019 09:13:02] - |D| - [80773631] - C:\WINDOWS\INF [MD5.4B79275DF4A345034CE478F1823096C5] - [25/05/2021 10:06:54] - |A| - (.-.) - [3816] - (0.0.0.0) - C:\WINDOWS\Info.xml [07/12/2019 09:14:52] - |D| - [38193580] - C:\WINDOWS\InputMethod [07/12/2019 09:14:52] - |SHD| - [603357917] - C:\WINDOWS\Installer [07/12/2019 09:14:52] - |D| - [109650] - C:\WINDOWS\L2Schemas [07/12/2019 09:14:52] - |HD| - [0] - C:\WINDOWS\LanguageOverlayCache [07/12/2019 09:14:52] - |D| - [0] - C:\WINDOWS\LiveKernelReports [07/12/2019 09:14:52] - |D| - [22164931] - C:\WINDOWS\Logs [07/12/2019 09:14:52] - |RSD| - [20063519] - C:\WINDOWS\Media [MD5.1A40E2B5E1B63BCEDA91C996137006F5] - [09/02/2022 06:24:39] - |A| - (.-.) - [1684068103] - (0.0.0.0) - C:\WINDOWS\MEMORY.DMP [MD5.23AF90D2355D8C83AA4567EF1763B467] - [07/12/2019 09:08:58] - |A| - (.-.) - [43131] - (0.0.0.0) - C:\WINDOWS\mib.bin [07/12/2019 09:14:52] - |RD| - [862473472] - C:\WINDOWS\Microsoft.NET [07/12/2019 09:14:52] - |D| - [3323] - C:\WINDOWS\Migration [29/06/2021 18:31:28] - |D| - [1663700] - C:\WINDOWS\Minidump [07/12/2019 09:14:52] - |D| - [0] - C:\WINDOWS\ModemLogs [MD5.8003F61648CB72F9F647D44A95FE788A] - [11/11/2021 23:34:08] - |A| - (.© Microsoft Corporation. Tous droits réservés. - Bloc-notes.) - [208384] - (10.0.19041.1320) - C:\WINDOWS\notepad.exe [MD5.74F28574BB8F61FFC7DD419FE6B6E0D5] - [10/07/2021 17:44:47] - |A| - (.-.) - [1951] - (0.0.0.0) - C:\WINDOWS\NvContainerRecovery.bat [07/12/2019 14:52:32] - |D| - [838452] - C:\WINDOWS\OCR [07/12/2019 09:14:52] - |RD| - [65] - C:\WINDOWS\Offline Web Pages [29/06/2021 13:15:07] - |D| - [115744091] - C:\WINDOWS\Panther [07/12/2019 09:14:52] - |D| - [509624] - C:\WINDOWS\Performance [MD5.9D3C3267CA1C7E86E5B3E38245EDADBF] - [29/06/2021 14:43:23] - |A| - (.-.) - [1190470] - (0.0.0.0) - C:\WINDOWS\PFRO.log [07/12/2019 09:14:52] - |D| - [1409080] - C:\WINDOWS\PLA [07/12/2019 09:14:52] - |D| - [10478952] - C:\WINDOWS\PolicyDefinitions [29/06/2021 12:17:41] - |D| - [16491485] - C:\WINDOWS\Prefetch [07/12/2019 09:14:52] - |RD| - [2234380] - C:\WINDOWS\PrintDialog [MD5.C186EF70E6825D333E0077831C58BAAA] - [07/12/2019 14:54:16] - |A| - (.-.) - [30831] - (0.0.0.0) - C:\WINDOWS\Professional.xml [07/12/2019 09:14:52] - |D| - [6083225] - C:\WINDOWS\Provisioning [MD5.999A30979F6195BF562068639FFC4426] - [29/06/2021 13:11:23] - |A| - (.© Microsoft Corporation. Tous droits réservés. - Éditeur du Registre.) - [370176] - (10.0.19041.746) - C:\WINDOWS\regedit.exe [07/12/2019 09:14:52] - |D| - [22588] - C:\WINDOWS\Registration [07/12/2019 14:53:51] - |D| - [0] - C:\WINDOWS\RemotePackages [07/12/2019 09:14:52] - |D| - [15460720] - C:\WINDOWS\rescache [07/12/2019 09:14:52] - |D| - [4003347] - C:\WINDOWS\Resources [07/12/2019 09:14:52] - |D| - [0] - C:\WINDOWS\SchCache [07/12/2019 09:14:52] - |D| - [195539] - C:\WINDOWS\schemas [07/12/2019 09:14:52] - |D| - [5354101] - C:\WINDOWS\security [29/06/2021 12:17:48] - |D| - [77850971] - C:\WINDOWS\ServiceProfiles [07/12/2019 09:14:52] - |D| - [4466] - C:\WINDOWS\ServiceState [07/12/2019 09:03:44] - |D| - [2523646047] - C:\WINDOWS\servicing [07/12/2019 09:18:25] - |D| - [42] - C:\WINDOWS\Setup [MD5.E40041E0CA436C712332EDAA9DB7DF08] - [30/12/2021 19:05:43] - |N| - (.Copyright (c) 1987-1998 Microsoft Corporation - Visual Basic 6.0 Setup Toolkit.) - [286720] - (6.0.0.8171) - C:\WINDOWS\Setup1.exe [MD5.68E4A21FD55BAA1DBB0940DB440EBA2F] - [14/01/2022 17:59:45] - |A| - (.-.) - [48779] - (0.0.0.0) - C:\WINDOWS\setupact.log [MD5.D41D8CD98F00B204E9800998ECF8427E] - [14/01/2022 17:59:45] - |A| - (.-.) - [0] - (0.0.0.0) - C:\WINDOWS\setuperr.log [07/12/2019 09:14:52] - |D| - [5526016] - C:\WINDOWS\ShellComponents [07/12/2019 09:14:52] - |D| - [19040768] - C:\WINDOWS\ShellExperiences [07/12/2019 09:14:52] - |D| - [6828144] - C:\WINDOWS\SKB [29/06/2021 13:20:13] - |D| - [1028214287] - C:\WINDOWS\SoftwareDistribution [07/12/2019 09:14:52] - |D| - [267012831] - C:\WINDOWS\Speech [07/12/2019 09:14:52] - |D| - [307324931] - C:\WINDOWS\Speech_OneCore [MD5.74EEC977273BEB6F80B3BB3887B78A33] - [18/12/2021 11:59:14] - |A| - (.© Microsoft Corporation. - Print driver host for applications.) - [136192] - (10.0.19041.1415) - C:\WINDOWS\splwow64.exe [MD5.996F83E516552CA3B51445BB994A6D38] - [30/12/2021 19:05:42] - |A| - (.Copyright © 1987-1998 Microsoft Corp. - Visual Basic Setup Toolkit Uninstaller.) - [73216] - (6.0.81.69) - C:\WINDOWS\ST6UNST.EXE [07/12/2019 09:14:52] - |D| - [31039] - C:\WINDOWS\System [MD5.286A9EDB379DC3423A528B0864A0F111] - [07/12/2019 09:14:54] - |A| - (.-.) - [219] - (0.0.0.0) - C:\WINDOWS\system.ini [07/12/2019 09:03:44] - |D| - [6804569731] - C:\WINDOWS\System32 [07/12/2019 09:14:52] - |D| - [150610667] - C:\WINDOWS\SystemApps [07/12/2019 09:14:52] - |D| - [174006649] - C:\WINDOWS\SystemResources [18/12/2021 14:34:53] - |D| - [0] - C:\WINDOWS\SystemTemp [07/12/2019 09:14:52] - |D| - [1268998599] - C:\WINDOWS\SysWOW64 [07/12/2019 09:14:52] - |D| - [0] - C:\WINDOWS\TAPI [07/12/2019 09:14:52] - |D| - [6] - C:\WINDOWS\Tasks [07/12/2019 09:14:52] - |D| - [5004440] - C:\WINDOWS\Temp [07/12/2019 09:14:52] - |D| - [0] - C:\WINDOWS\tracing [07/12/2019 09:14:52] - |D| - [7680] - C:\WINDOWS\twain_32 [MD5.AFE119DD4E17891B227684F38AA25D4D] - [07/12/2019 09:10:00] - |A| - (.- Gestionnaire de sources Twain_32 (Image Acquisition Interface).) - [65024] - (1.7.1.3) - C:\WINDOWS\twain_32.dll [07/12/2019 09:14:52] - |D| - [12420] - C:\WINDOWS\Vss [07/12/2019 09:14:52] - |D| - [33198] - C:\WINDOWS\WaaS [07/12/2019 09:14:52] - |D| - [16568315] - C:\WINDOWS\Web [MD5.23CF8138F49416231807E6DE371FB9E6] - [07/12/2019 09:14:54] - |A| - (.-.) - [92] - (0.0.0.0) - C:\WINDOWS\win.ini [MD5.C844CA459F3B209329984772269B6E56] - [07/12/2019 09:09:09] - |RAH| - (.-.) - [670] - (0.0.0.0) - C:\WINDOWS\WindowsShell.Manifest [MD5.2CC83D93DD1DDE691158CF5E9882420B] - [09/01/2022 07:50:38] - |A| - (.-.) - [276] - (0.0.0.0) - C:\WINDOWS\WindowsUpdate.log [MD5.0629E6D130F226C009EA9AB329F37ACC] - [07/12/2019 09:10:00] - |A| - (.© Microsoft Corporation. Tous droits réservés. - Relais Windows Winhlp32.) - [11776] - (10.0.19041.1) - C:\WINDOWS\winhlp32.exe [07/12/2019 09:03:44] - |D| - [8943317533] - C:\WINDOWS\WinSxS [MD5.E7E4D8D7340DA6934B9EA81CBB21374C] - [07/12/2019 09:10:11] - |A| - (.-.) - [316640] - (0.0.0.0) - C:\WINDOWS\WMSysPr9.prx [MD5.B947CCA7F485F6C1156F4D02E8C9874F] - [07/12/2019 14:52:57] - |A| - (.© Microsoft Corporation. - Windows Write.) - [11264] - (10.0.19041.1) - C:\WINDOWS\write.exe ---------- | C:\WINDOWS\System32\GroupPolicy ---------- | Systemroot\System ---------- | Systemroot\Installer (Microsoft Files Whitelisted) [09/06/2021 08:22:26] - C:\WINDOWS\Installer\127536e9.msi : (Branding64 - Advanced Micro Devices, Inc.) [Header ok : D0CF11E0A1B11AE10000000000000000] [28/06/2021 14:24:24] - C:\WINDOWS\Installer\127536f5.msi : (AMD WVR64 - Advanced Micro Devices, Inc.) [Header ok : D0CF11E0A1B11AE10000000000000000] [28/06/2021 17:31:34] - C:\WINDOWS\Installer\127536fb.msi : (RyzenMasterSDK - Advanced Micro Devices, Inc.) [Header ok : D0CF11E0A1B11AE10000000000000000] [29/06/2021 14:01:16] - C:\WINDOWS\Installer\25b38f.msi : (AMD_Chipset_Drivers - Advanced Micro Devices, Inc.) [Header ok : D0CF11E0A1B11AE10000000000000000] [25/05/2021 05:06:56] - C:\WINDOWS\Installer\25b395.msi : (AMD GPIO2 Driver - Advanced Micro Devices, Inc.) [Header ok : D0CF11E0A1B11AE10000000000000000] [25/05/2021 05:06:56] - C:\WINDOWS\Installer\25b39b.msi : (AMD PCI Driver - Advanced Micro Devices, Inc.) [Header ok : D0CF11E0A1B11AE10000000000000000] [25/05/2021 05:06:58] - C:\WINDOWS\Installer\25b3a1.msi : (AMD SBxxxSMBus Driver - Advanced Micro Devices, Inc.) [Header ok : D0CF11E0A1B11AE10000000000000000] [25/05/2021 05:06:56] - C:\WINDOWS\Installer\25b3a7.msi : (AMD PSP Driver - Advanced Micro Devices, Inc.) [Header ok : D0CF11E0A1B11AE10000000000000000] [25/05/2021 05:06:58] - C:\WINDOWS\Installer\25b3ad.msi : (Promontory GPIO Driver - Advanced Micro Devices, Inc.) [Header ok : D0CF11E0A1B11AE10000000000000000] [25/05/2021 05:06:58] - C:\WINDOWS\Installer\25b3b3.msi : (AMD Ryzen Balanced Driver - Advanced Micro Devices, Inc.) [Header ok : D0CF11E0A1B11AE10000000000000000] [01/08/2021 22:59:12] - C:\WINDOWS\Installer\64a15c.msi : (REX File Transfer Manager - REX Game Studios, LLC.) [Header ok : D0CF11E0A1B11AE10000000000000000] [06/02/2022 12:48:14] - C:\WINDOWS\Installer\65336.msi : (Java Auto Updater - Oracle Corporation) [Header ok : D0CF11E0A1B11AE10000000000000000] [08/02/2021 19:34:16] - C:\WINDOWS\Installer\88fbff.msi : (Intel(R) C++ Redistributables on Intel(R) 64 - Intel Corporation) [Header ok : D0CF11E0A1B11AE10000000000000000] [30/04/2021 20:04:46] - C:\WINDOWS\Installer\9885960.msi : (PACX - TFDi Design) [Header ok : D0CF11E0A1B11AE10000000000000000] [30/01/2022 01:49:40] - C:\WINDOWS\Installer\cfec28.msi : ( - Bijan Season) [Header ok : D0CF11E0A1B11AE10000000000000000] [12/01/2022 01:27:59] - C:\WINDOWS\Installer\e044a40.msi : (REX Weather Force 2020 - REX Game Studios, LLC.) [Header ok : D0CF11E0A1B11AE10000000000000000] ---------- | %System%\*.in* [07/12/2019 09:09:39] - [3329] - C:\WINDOWS\System32\ieuinit.inf [29/06/2021 13:24:12] - [1767554] - C:\WINDOWS\System32\PerfStringBackup.INI [07/12/2019 09:09:05] - [60124] - C:\WINDOWS\System32\tcpmon.ini [07/12/2019 09:08:46] - [2404] - C:\WINDOWS\System32\WimBootCompress.ini [07/12/2019 09:10:00] - [3329] - C:\WINDOWS\Syswow64\ieuinit.inf [07/12/2019 09:09:22] - [2404] - C:\WINDOWS\Syswow64\WimBootCompress.ini ---------- | Listing no Microsoft signed files (Not necessary Malwares) | system32 | Syswow64 | General scan [MD5.37A80BF674D8374738C11C91DC47628D] - |A| - [20/01/2022 23:36:06] - (.-.) - [55.09 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\chrome_installer.log [MD5.00000000000000000000000000000000] - |D| - [20/01/2022 23:36:06] - [0.04 Ko] - C:\WINDOWS\Temp\Crashpad [MD5.92DE01E9D84032CA233A6783CB0E1004] - |A| - [29/06/2021 12:18:01] - (.-.) - [892.24 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MpCmdRun.log [MD5.19B27C0CBC948B15D6E4F967B9FBC8EB] - |A| - [09/01/2022 08:07:20] - (.-.) - [10.73 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MpCopyAccelerator.log [MD5.ED0301739A049CD4BDC3CE53EACC29A6] - |A| - [27/09/2021 22:52:40] - (.-.) - [566.45 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\MpSigStub.log [MD5.EEB4D4391F6A7F0F2B808287C267F9BB] - |A| - [13/01/2022 22:54:00] - (.-.) - [241.41 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\msedge_installer.log [MD5.20FBB4379823736D770998A2039A0F52] - |A| - [06/02/2022 01:23:56] - (.-.) - [0.3 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\WERF79C.tmp.WERDataCollectionStatus.txt [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 14:50:21] - [0 Ko] - C:\WINDOWS\System32\0409 [MD5.C652A5EA6545C98CE71684018E0640E7] - |A| - [07/12/2019 09:09:00] - (.-.) - [3.1 Ko] - (0.0.0.0) - C:\WINDOWS\System32\@AdvancedKeySettingsNotification.png [MD5.D6F8DD9F561B8A67FFAC2BAD7E989770] - |A| - [07/12/2019 09:08:44] - (.-.) - [0.23 Ko] - (0.0.0.0) - C:\WINDOWS\System32\@AppHelpToast.png [MD5.82C37C3E27020AF6C2E018E944284676] - |A| - [07/12/2019 09:08:45] - (.-.) - [0.3 Ko] - (0.0.0.0) - C:\WINDOWS\System32\@AudioToastIcon.png [MD5.8E4B25CC8E98F63DBD54176DFAB539E0] - |A| - [07/12/2019 09:08:21] - (.-.) - [0.44 Ko] - (0.0.0.0) - C:\WINDOWS\System32\@BackgroundAccessToastIcon.png [MD5.3937359E324E15F6A7A7092D4DAEBD64] - |A| - [07/12/2019 09:08:52] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\WINDOWS\System32\@bitlockertoastimage.png [MD5.495C1F072039B434827A5FE0D9761E4D] - |A| - [07/12/2019 09:08:52] - (.-.) - [0.32 Ko] - (0.0.0.0) - C:\WINDOWS\System32\@EnrollmentToastIcon.png [MD5.C2A332DE50FE519DA21AFB8BD6E134F4] - |A| - [07/12/2019 09:08:58] - (.-.) - [0.55 Ko] - (0.0.0.0) - C:\WINDOWS\System32\@language_notification_icon.png [MD5.A119D69B4C29845D3F8CE2E5638C8E65] - |A| - [07/12/2019 09:09:45] - (.-.) - [0.47 Ko] - (0.0.0.0) - C:\WINDOWS\System32\@optionalfeatures.png [MD5.A3437673F5766635A8378F67645B81C0] - |A| - [07/12/2019 09:09:37] - (.-.) - [0.35 Ko] - (0.0.0.0) - C:\WINDOWS\System32\@StorageSenseToastIcon.png [MD5.1622DE67156496C78D6B7BE9B471645B] - |A| - [07/12/2019 09:09:07] - (.-.) - [0.39 Ko] - (0.0.0.0) - C:\WINDOWS\System32\@VpnToastIcon.png [MD5.79166EAF65485F1432DD72B72870026B] - |A| - [07/12/2019 09:09:32] - (.-.) - [190.86 Ko] - (0.0.0.0) - C:\WINDOWS\System32\@windows-hello-V4.1.gif [MD5.13EF2C8D799F7B6E9D8E3D6BACB9C779] - |A| - [07/12/2019 09:09:32] - (.-.) - [0.7 Ko] - (0.0.0.0) - C:\WINDOWS\System32\@WindowsHelloFaceToastIcon.png [MD5.F553B252FEC3134D4F5303D9B25298B3] - |A| - [07/12/2019 09:08:39] - (.-.) - [0.51 Ko] - (0.0.0.0) - C:\WINDOWS\System32\@WindowsUpdateToastIcon.contrast-black.png [MD5.DAD405CBDE259DE527EBF71BCC28099C] - |A| - [07/12/2019 09:08:39] - (.-.) - [0.79 Ko] - (0.0.0.0) - C:\WINDOWS\System32\@WindowsUpdateToastIcon.contrast-white.png [MD5.F553B252FEC3134D4F5303D9B25298B3] - |A| - [07/12/2019 09:08:39] - (.-.) - [0.51 Ko] - (0.0.0.0) - C:\WINDOWS\System32\@WindowsUpdateToastIcon.png [MD5.DB71001FC261F6685BE410527DAE3942] - |A| - [07/12/2019 09:08:19] - (.-.) - [0.67 Ko] - (0.0.0.0) - C:\WINDOWS\System32\@WirelessDisplayToast.png [MD5.147B047B46B79A91CC34499D4F89119E] - |A| - [07/12/2019 09:09:05] - (.-.) - [0.39 Ko] - (0.0.0.0) - C:\WINDOWS\System32\@WLOGO_48x48.png [MD5.ECFB47321D759AC6015E613AEAF2BDCC] - |A| - [29/06/2021 12:02:42] - (.-.) - [115.8 Ko] - (0.0.0.0) - C:\WINDOWS\System32\AcpiServiceVnA64.dll [MD5.31A16C523B62500F83C82217F056A538] - |A| - [07/12/2019 09:08:39] - (.-.) - [8.13 Ko] - (0.0.0.0) - C:\WINDOWS\System32\ActiveHours.png [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [2786.8 Ko] - C:\WINDOWS\System32\AdvancedInstallers [MD5.A49C26AA0CADD994DE158F51CB7EEFBC] - |A| - [29/06/2021 13:10:37] - (.-.) - [13 Ko] - (0.0.0.0) - C:\WINDOWS\System32\agentactivationruntimestarter.exe [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [5.97 Ko] - C:\WINDOWS\System32\am-et [MD5.00000000000000000000000000000000] - |D| - [29/06/2021 12:17:39] - [0 Ko] - C:\WINDOWS\System32\AMD [MD5.BEBBB626F732A01172D9610230AD4A2C] - |A| - [22/06/2021 19:29:28] - (.Copyright (C) 2020 Advanced Micro Devices, Inc. - AMD Crash Defender Service.) - [571.42 Ko] - (21.20.0.103) - C:\WINDOWS\System32\amdfendrsr.exe [MD5.1263C12E8B63EE05514E0486F8DF527A] - |A| - [17/06/2021 00:37:42] - (.Copyright (c) 2013 - 2021 Advanced Micro Devices, Inc. - amdtee_api dll.) - [432.8 Ko] - (5.17.0.0) - C:\WINDOWS\System32\amdtee_api.dll [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [0 Ko] - C:\WINDOWS\System32\AppLocker [MD5.00000000000000000000000000000000] - |D| - [01/08/2021 23:24:52] - [0 Ko] - C:\WINDOWS\System32\appmgmt [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [2894.13 Ko] - C:\WINDOWS\System32\appraiser [MD5.00000000000000000000000000000000] - |SD| - [07/12/2019 14:53:51] - [287.51 Ko] - C:\WINDOWS\System32\AppV [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [279.5 Ko] - C:\WINDOWS\System32\ar-SA [MD5.7605725C6464C7272BF3115901DF5776] - |A| - [14/01/2022 01:13:04] - (.Copyright (c) libarchive authors - Windows-internal libarchive library.) - [665.5 Ko] - (3.5.1.0) - C:\WINDOWS\System32\archiveint.dll [MD5.C4E526D30AA8F2534BBCEDA89D8F9820] - |A| - [29/06/2021 13:11:32] - (.-.) - [469 Ko] - (0.0.0.0) - C:\WINDOWS\System32\AssignedAccessCsp.dll [MD5.DC2AE009029AABE06996A37C2B729EFD] - |A| - [29/06/2021 12:02:42] - (.-.) - [102.84 Ko] - (0.0.0.0) - C:\WINDOWS\System32\audioLibVc.dll [MD5.C03F0062C0749CDB59A4D60862C3E83E] - |A| - [07/12/2019 09:08:07] - (.-.) - [134.86 Ko] - (0.0.0.0) - C:\WINDOWS\System32\AverageRoom.bin [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [258.5 Ko] - C:\WINDOWS\System32\bg-BG [MD5.705628497C0012302212A46ADD463E6E] - |A| - [07/12/2019 09:08:05] - (.-.) - [8.3 Ko] - (0.0.0.0) - C:\WINDOWS\System32\BluetoothPairingSystemToastIcon.contrast-black.png [MD5.F63C615733A3337BF2BEA96C6EE9B568] - |A| - [07/12/2019 09:08:05] - (.-.) - [8.53 Ko] - (0.0.0.0) - C:\WINDOWS\System32\BluetoothPairingSystemToastIcon.contrast-high.png [MD5.705628497C0012302212A46ADD463E6E] - |A| - [07/12/2019 09:08:05] - (.-.) - [8.3 Ko] - (0.0.0.0) - C:\WINDOWS\System32\BluetoothPairingSystemToastIcon.contrast-white.png [MD5.DAF1DCB4AEE839A1965F4CC160C49A53] - |A| - [07/12/2019 09:08:05] - (.-.) - [8.34 Ko] - (0.0.0.0) - C:\WINDOWS\System32\BluetoothPairingSystemToastIcon.png [MD5.28ECA83D7F9D10D69E969675D1FF6725] - |A| - [07/12/2019 09:08:05] - (.-.) - [1.29 Ko] - (0.0.0.0) - C:\WINDOWS\System32\BluetoothSystemToastIcon.contrast-white.png [MD5.A620186FF1CDE4EE117FC4CAD648B9CC] - |A| - [07/12/2019 09:08:05] - (.-.) - [1.2 Ko] - (0.0.0.0) - C:\WINDOWS\System32\BluetoothSystemToastIcon.png [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [6045.64 Ko] - C:\WINDOWS\System32\Boot [MD5.3149A16CF39B9A49BD9A1EF98A1C527B] - |A| - [29/06/2021 13:10:55] - (.Copyright (C) 2008 - Gestionnaire de contexte pour réseau personnel Bluetooth.) - [186.5 Ko] - (1.0.0.1) - C:\WINDOWS\System32\BthpanContextHandler.dll [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [0.1 Ko] - C:\WINDOWS\System32\Bthprops [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:03:44] - [79977.28 Ko] - C:\WINDOWS\System32\CatRoot [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [58598.95 Ko] - C:\WINDOWS\System32\catroot2 [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [25.49 Ko] - C:\WINDOWS\System32\CodeIntegrity [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [382.5 Ko] - C:\WINDOWS\System32\Com [MD5.535884123FABC2C15AA7DEC9834B55D4] - |A| - [07/12/2019 09:08:05] - (.-.) - [0.67 Ko] - (0.0.0.0) - C:\WINDOWS\System32\ComputerToastIcon.contrast-white.png [MD5.89F92266DFC6F93961DFFBB2D6C61A15] - |A| - [07/12/2019 09:08:05] - (.-.) - [0.38 Ko] - (0.0.0.0) - C:\WINDOWS\System32\ComputerToastIcon.png [MD5.755BFC56892C3ECCA0F02AAC5E0BD3B1] - |A| - [29/06/2021 12:02:42] - (.2013 © Real Sound Lab SIA, iSoft Solutions - CONEQ™ Media Suite APO GUI Library.) - [119.45 Ko] - (1.0.0.4) - C:\WINDOWS\System32\CONEQMSAPOGUILibrary.dll [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:03:44] - [302154.46 Ko] - C:\WINDOWS\System32\config [MD5.00000000000000000000000000000000] - |SD| - [07/12/2019 09:14:52] - [154.3 Ko] - C:\WINDOWS\System32\Configuration [MD5.C113EC3ABF481A1B41F99BD721B513C3] - |A| - [29/06/2021 13:10:51] - (.-.) - [225.83 Ko] - (0.0.0.0) - C:\WINDOWS\System32\containerdevicemanagement.dll [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [0.34 Ko] - C:\WINDOWS\System32\ContainerSettingsProviders [MD5.A41C1754A956E37B5E7D06D5167548E7] - |A| - [29/06/2021 13:10:37] - (.-.) - [280.5 Ko] - (0.0.0.0) - C:\WINDOWS\System32\CoreMas.dll [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [322.5 Ko] - C:\WINDOWS\System32\cs-CZ [MD5.05DE2EB0889D77D447BCA7BD597819CF] - |A| - [14/01/2022 01:13:04] - (.© 1996 - 2021 Daniel Stenberg, . - The curl executable.) - [511.5 Ko] - (7.79.1.0) - C:\WINDOWS\System32\curl.exe [MD5.707DBFA069D1A078D5FC6CB57A9BB707] - |A| - [29/06/2021 12:02:42] - (.©Conexant Systems Inc. - Conexant APO.) - [1578.79 Ko] - (1.74.0.0) - C:\WINDOWS\System32\CX64APO.dll [MD5.42403C608F1EB6A3A003ED8949C3CE04] - |A| - [29/06/2021 12:02:42] - (.©Conexant Systems Inc. - Conexant MFX APO Proxy.) - [1493.3 Ko] - (1.2.0.0) - C:\WINDOWS\System32\CX64Proxy.dll [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [326 Ko] - C:\WINDOWS\System32\da-DK [MD5.2476074BEE004F1F505A772A677AD2B3] - |A| - [18/12/2021 11:59:15] - (.-.) - [159 Ko] - (0.0.0.0) - C:\WINDOWS\System32\DataStoreCacheDumpTool.exe [MD5.00000000000000000000000000000000] - |D| - [29/06/2021 12:18:10] - [14215.07 Ko] - C:\WINDOWS\System32\DAX2 [MD5.00000000000000000000000000000000] - |D| - [29/06/2021 12:18:10] - [6813.54 Ko] - C:\WINDOWS\System32\DAX3 [MD5.92C3142A5BEC25CE8654EB352A5478AF] - |A| - [29/06/2021 12:02:42] - (.© 2017 Dolby Laboratories, Inc. - Dolby DAX APO Property Page.) - [1518.16 Ko] - (1.1.3.10) - C:\WINDOWS\System32\DAX3APOProp.dll [MD5.B9B70D4B7C9C6F69AB32CCCA70FD28B8] - |A| - [29/06/2021 12:02:42] - (.© 2017 Dolby Laboratories, Inc. - Dolby DAX APO.) - [1295.34 Ko] - (1.1.3.10) - C:\WINDOWS\System32\DAX3APOv251.dll [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [272.44 Ko] - C:\WINDOWS\System32\DDFs [MD5.526525479C2067A0DB7977621CB81BD7] - |A| - [29/06/2021 12:02:42] - (.©2014 Dolby Laboratories. - Dolby Digital Plus API x86.) - [266.32 Ko] - (7.6.5.1) - C:\WINDOWS\System32\DDPA64.dll [MD5.B7B98448D3DE173C5B876C3C26425964] - |A| - [29/06/2021 12:02:42] - (.©2014 Dolby Laboratories. - Dolby Digital Plus API x86.) - [303.14 Ko] - (7.6.7.2) - C:\WINDOWS\System32\DDPA64F3.dll [MD5.95FAE6EFF9C33FB1CFEDE2092C9A4DC0] - |A| - [29/06/2021 12:02:42] - (.©2014 Dolby Laboratories. - Dolby Digital Plus COM DLL x86.) - [1919.73 Ko] - (7.6.5.1) - C:\WINDOWS\System32\DDPD64A.dll [MD5.25B22A8DC47F5830BF7993A5867A0916] - |A| - [29/06/2021 12:02:42] - (.©2014 Dolby Laboratories. - Dolby Digital Plus COM DLL x86.) - [1913.67 Ko] - (7.6.7.2) - C:\WINDOWS\System32\DDPD64AF3.dll [MD5.C53816D19E425CA42401D7D5FC7D3B53] - |A| - [29/06/2021 12:02:42] - (.©2014 Dolby Laboratories. - Dolby Digital Plus APO x86.) - [319.77 Ko] - (7.6.5.1) - C:\WINDOWS\System32\DDPO64A.dll [MD5.EF6633D2F868EAE614066951DC792354] - |A| - [29/06/2021 12:02:42] - (.©2014 Dolby Laboratories. - Dolby Digital Plus APO x86.) - [353.56 Ko] - (7.6.7.2) - C:\WINDOWS\System32\DDPO64AF3.dll [MD5.5CDE868D75C55F02896641E9162BF097] - |A| - [29/06/2021 12:02:42] - (.©2014 Dolby Laboratories. - Dolby DS1PC Control Panel x86.) - [6929.87 Ko] - (7.6.5.1) - C:\WINDOWS\System32\DDPP64A.dll [MD5.073D5834B13473388226817CA6E73179] - |A| - [29/06/2021 12:02:42] - (.©2014 Dolby Laboratories. - Dolby DS1PC Control Panel x86.) - [6117.8 Ko] - (7.6.7.2) - C:\WINDOWS\System32\DDPP64AF3.dll [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [363.5 Ko] - C:\WINDOWS\System32\de-DE [MD5.C1684AACAAD62889ACFCA988AA46562D] - |A| - [07/12/2019 09:08:21] - (.-.) - [28.83 Ko] - (0.0.0.0) - C:\WINDOWS\System32\DefaultAccountTile.png [MD5.057C75B5735EEF2A75ABF8F6770BCA34] - |A| - [29/06/2021 13:10:37] - (.-.) - [4128.04 Ko] - (0.0.0.0) - C:\WINDOWS\System32\DefaultHrtfs.bin [MD5.664AA698FC0106A2B075A641E8DC6302] - |A| - [07/12/2019 09:14:56] - (.-.) - [0.84 Ko] - (0.0.0.0) - C:\WINDOWS\System32\DefaultQuestions.json [MD5.041A7B079E9776721847031A7CF533E1] - |A| - [07/12/2019 09:09:34] - (.-.) - [15.97 Ko] - (0.0.0.0) - C:\WINDOWS\System32\DeliveryOptimizationMIProv.mof [MD5.59D5500F74109D59522F5A9457B8D9A2] - |A| - [07/12/2019 09:09:34] - (.-.) - [0.89 Ko] - (0.0.0.0) - C:\WINDOWS\System32\DeliveryOptimizationMIProvUninstall.mof [MD5.B924F1A7DE5ED8331B3375A778B3FE38] - |A| - [07/12/2019 09:08:52] - (.-.) - [35.5 Ko] - (0.0.0.0) - C:\WINDOWS\System32\deploymentcsphelper.exe [MD5.851A9305E14B348CA0D9C7FB75391FDB] - |A| - [07/12/2019 09:08:39] - (.-.) - [272.34 Ko] - (0.0.0.0) - C:\WINDOWS\System32\DesktopKeepOnToastImg.gif [MD5.4A6FA3C0EFD237F104E09A22883D9388] - |A| - [07/12/2019 09:08:43] - (.-.) - [3.85 Ko] - (0.0.0.0) - C:\WINDOWS\System32\DetailedReading-Default.xml [MD5.4B0DA098F52E1DDDB3169B30477E22C8] - |A| - [17/09/2021 02:24:57] - (.-.) - [166.5 Ko] - (0.0.0.0) - C:\WINDOWS\System32\DeviceUpdateCenterCsp.dll [MD5.00000000000000000000000000000000] - |SD| - [07/12/2019 09:14:52] - [889 Ko] - C:\WINDOWS\System32\DiagSvcs [MD5.037DF43BCC9F9A4DF6548FED8F4503AF] - |A| - [07/12/2019 09:08:37] - (.-.) - [82.96 Ko] - (0.0.0.0) - C:\WINDOWS\System32\DiskSnapshot.conf [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [10164.77 Ko] - C:\WINDOWS\System32\Dism [MD5.6AB2B935BF38EB13CFCB9506223FD6E7] - |A| - [07/12/2019 09:08:05] - (.-.) - [0.59 Ko] - (0.0.0.0) - C:\WINDOWS\System32\DisplaySystemToastIcon.contrast-white.png [MD5.FF004E0B30E5E4EC747B3D8EF6E3B89E] - |A| - [07/12/2019 09:08:05] - (.-.) - [0.34 Ko] - (0.0.0.0) - C:\WINDOWS\System32\DisplaySystemToastIcon.png [MD5.5A6ADA2567E9CC98810A0842EE514718] - |A| - [29/06/2021 12:02:42] - (.© 2017 Dolby Laboratories, Inc. - Dolby DAX2 APO Property Page.) - [1106.51 Ko] - (0.8.0.32) - C:\WINDOWS\System32\DolbyDAX2APOProp.dll [MD5.FF87D35C07681C667841C4BCD61013D2] - |A| - [29/06/2021 12:02:42] - (.© 2017 Dolby Laboratories, Inc. - Dolby DAX2 APO.) - [2387.38 Ko] - (0.8.0.32) - C:\WINDOWS\System32\DolbyDAX2APOv201.dll [MD5.4CB48D6B52F03356196E95DF0BE20338] - |A| - [29/06/2021 12:02:42] - (.© 2017 Dolby Laboratories, Inc. - Dolby DAX2 APO.) - [5221.67 Ko] - (0.8.0.32) - C:\WINDOWS\System32\DolbyDAX2APOv211.dll [MD5.039378EE24108BE26F5DC926EBC9A799] - |A| - [29/06/2021 12:02:42] - (.© 2016 Dolby Laboratories, Inc. - Dolby DAX2 APO.) - [1143.43 Ko] - (1.6.0.47) - C:\WINDOWS\System32\DolbyDAX2APOvlldp.dll [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [2435.36 Ko] - C:\WINDOWS\System32\downlevel [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:17] - [127139.37 Ko] - C:\WINDOWS\System32\drivers [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [0 Ko] - C:\WINDOWS\System32\DriverState [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:03:44] - [2316992.02 Ko] - C:\WINDOWS\System32\DriverStore [MD5.D1DDD8C39F19CC99AD730FDC6274625C] - |A| - [14/01/2022 01:13:03] - (.-.) - [11.52 Ko] - (0.0.0.0) - C:\WINDOWS\System32\DrtmAuthTxt.wim [MD5.00000000000000000000000000000000] - |SD| - [07/12/2019 09:14:52] - [214.5 Ko] - C:\WINDOWS\System32\dsc [MD5.A36AAA3325FA3B4A08053B8E6FB3E45B] - |A| - [29/06/2021 12:02:42] - (.(c) DTS. - DTS Bass Enhancement COM DLL.) - [726.52 Ko] - (1.0.0.1) - C:\WINDOWS\System32\DTSBassEnhancementDLL64.dll [MD5.4E610EB60940886825AAB3F7DA7C9D9A] - |A| - [29/06/2021 12:02:42] - (.(c) DTS. - DTS Boost COM DLL.) - [1473.56 Ko] - (1.0.0.1) - C:\WINDOWS\System32\DTSBoostDLL64.dll [MD5.754C35EA52199530DB9485E815C9B3D6] - |A| - [29/06/2021 12:02:42] - (.(c) DTS. - DTS Gain Compensator COM DLL.) - [430.92 Ko] - (1.0.0.1) - C:\WINDOWS\System32\DTSGainCompensatorDLL64.dll [MD5.A3325218C8899607B5D3351286B4B471] - |A| - [29/06/2021 12:02:42] - (.(c) DTS. - DTS GFX APO.) - [247.95 Ko] - (1.0.0.3) - C:\WINDOWS\System32\DTSGFXAPO64.dll [MD5.4342C6A1C77DBB341E1F99F8D2B9FC3B] - |A| - [29/06/2021 12:02:42] - (.(c) DTS. - DTS GFX APO.) - [246.95 Ko] - (1.0.0.3) - C:\WINDOWS\System32\DTSGFXAPONS64.dll [MD5.091DFDF1332B8C2ECB5CC0761985B956] - |A| - [29/06/2021 12:02:42] - (.(c) DTS. - DTS LFX APO.) - [247.91 Ko] - (1.0.0.3) - C:\WINDOWS\System32\DTSLFXAPO64.dll [MD5.9589B136B601D2F9BC5D2DE3FE5B0EBE] - |A| - [29/06/2021 12:02:42] - (.(c) DTS. - DTS Limiter COM DLL.) - [434.95 Ko] - (1.0.0.1) - C:\WINDOWS\System32\DTSLimiterDLL64.dll [MD5.8B202E32B31BF1D4F3651C63903C5DC3] - |A| - [29/06/2021 12:02:42] - (.(c) DTS. - DTS NEO:PC COM DLL.) - [492.48 Ko] - (1.0.0.1) - C:\WINDOWS\System32\DTSNeoPCDLL64.dll [MD5.07AF75397E44A7CDBF07C32CD9DAF6E5] - |A| - [29/06/2021 12:02:42] - (.(c) DTS. - DTS Surround Sensation Headphone COM DLL.) - [1553.77 Ko] - (1.0.0.1) - C:\WINDOWS\System32\DTSS2HeadphoneDLL64.dll [MD5.99028F53A66576A21563B7B899CA0D6B] - |A| - [29/06/2021 12:02:42] - (.(c) DTS. - DTS Surround Sensation Speaker COM DLL.) - [1738.88 Ko] - (1.0.0.1) - C:\WINDOWS\System32\DTSS2SpeakerDLL64.dll [MD5.6618E4A4FE4E285478FADF5197F7FEBF] - |A| - [29/06/2021 12:02:42] - (.(c) DTS. - DTS Symmetry COM DLL.) - [710.38 Ko] - (1.0.0.1) - C:\WINDOWS\System32\DTSSymmetryDLL64.dll [MD5.B692F28F37DEFAA40086C2F347207BEE] - |A| - [29/06/2021 12:02:42] - (.(c) DTS. - DTS GFX APO.) - [488.82 Ko] - (2.1.1.0) - C:\WINDOWS\System32\DTSU2PGFX64.dll [MD5.7505A31B570656C12AE138B3B015BF20] - |A| - [29/06/2021 12:02:42] - (.(c) DTS. - DTS LFX APO.) - [502.46 Ko] - (2.1.1.0) - C:\WINDOWS\System32\DTSU2PLFX64.dll [MD5.A0C71F41AF8714B176E1B671A0451EAE] - |A| - [29/06/2021 12:02:42] - (.(c) DTS. - DTS LFX APO.) - [418.19 Ko] - (2.1.1.0) - C:\WINDOWS\System32\DTSU2PREC64.dll [MD5.5A46D7F2E8FA660F46C2EDB2F21FE4C2] - |A| - [29/06/2021 12:02:42] - (.(c) DTS. - DTS Voice Clarity COM DLL.) - [691.71 Ko] - (1.0.0.1) - C:\WINDOWS\System32\DTSVoiceClarityDLL64.dll [MD5.64E652DC979CB9EF1AEE91DBD4F8C624] - |A| - [29/06/2021 13:10:56] - (.-.) - [2201.5 Ko] - (0.0.0.0) - C:\WINDOWS\System32\dwmscene.dll [MD5.DF84EB7B44D1414284BA384F0061D1DC] - |A| - [07/12/2019 09:08:07] - (.-.) - [728.08 Ko] - (0.0.0.0) - C:\WINDOWS\System32\DynamicLong.bin [MD5.346870077DFD18867A9693C7A59AA3E6] - |A| - [07/12/2019 09:08:07] - (.-.) - [503.08 Ko] - (0.0.0.0) - C:\WINDOWS\System32\DynamicMedium.bin [MD5.2BEC13D68312ADE8C0065D8BCC146D2F] - |A| - [07/12/2019 09:08:07] - (.-.) - [315.58 Ko] - (0.0.0.0) - C:\WINDOWS\System32\DynamicShort.bin [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [366.5 Ko] - C:\WINDOWS\System32\el-GR [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 14:50:21] - [3455 Ko] - C:\WINDOWS\System32\en [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [18508.96 Ko] - C:\WINDOWS\System32\en-GB [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [43950.68 Ko] - C:\WINDOWS\System32\en-US [MD5.1D0A840D731A2C1F2E1FB5B8596B4C34] - |A| - [29/06/2021 13:10:54] - (.-.) - [148.5 Ko] - (0.0.0.0) - C:\WINDOWS\System32\EoAExperiences.exe [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [348.5 Ko] - C:\WINDOWS\System32\es-ES [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [271 Ko] - C:\WINDOWS\System32\es-MX [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [238 Ko] - C:\WINDOWS\System32\et-EE [MD5.00000000000000000000000000000000] - |SD| - [07/12/2019 09:14:52] - [17000.64 Ko] - C:\WINDOWS\System32\F12 [MD5.4DED57BD7ACB9B0EBBE82034EC44645A] - |A| - [07/12/2019 09:08:41] - (.-.) - [43.22 Ko] - (0.0.0.0) - C:\WINDOWS\System32\FeatureToastBulldogImg.png [MD5.7F65C93283F31EB39E311DDDC00DFBA6] - |A| - [29/06/2021 13:10:56] - (.-.) - [16.54 Ko] - (0.0.0.0) - C:\WINDOWS\System32\FeatureToastDlpImg.png [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [7.11 Ko] - C:\WINDOWS\System32\ff-Adlm-SN [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [330.5 Ko] - C:\WINDOWS\System32\fi-FI [MD5.BA76A73CDFB33221F97E984EC2F8439E] - |A| - [29/06/2021 12:17:47] - (.-.) - [251.95 Ko] - (0.0.0.0) - C:\WINDOWS\System32\FNTCACHE.DAT [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 14:50:21] - [3490.5 Ko] - C:\WINDOWS\System32\fr [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [20585.01 Ko] - C:\WINDOWS\System32\fr-CA [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [48322.8 Ko] - C:\WINDOWS\System32\fr-FR [MD5.EB37DB663DC19E7C4D7F23A12DA07E99] - |A| - [17/09/2021 02:24:53] - (.-.) - [657 Ko] - (0.0.0.0) - C:\WINDOWS\System32\FsNVSDeviceSource.dll [MD5.287BFB8FB79B50B3042E4D350326373F] - |A| - [10/07/2021 17:44:51] - (.-.) - [80.5 Ko] - (0.0.0.0) - C:\WINDOWS\System32\FvSDK_x64.dll [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 14:51:43] - [0 Ko] - C:\WINDOWS\System32\FxsTmp [MD5.41FD64AE28A0C932CA7B2A250993D675] - |A| - [07/12/2019 09:08:05] - (.-.) - [1.45 Ko] - (0.0.0.0) - C:\WINDOWS\System32\GameSystemToastIcon.contrast-white.png [MD5.6DC77FD8B062264AF1C6DA325ABB7010] - |A| - [07/12/2019 09:08:05] - (.-.) - [1.11 Ko] - (0.0.0.0) - C:\WINDOWS\System32\GameSystemToastIcon.png [MD5.2E6AF4D5BF6E31E728F409984C3045D4] - |A| - [07/12/2019 09:09:48] - (.-.) - [86.7 Ko] - (0.0.0.0) - C:\WINDOWS\System32\gatherNetworkInfo.vbs [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [0 Ko] - C:\WINDOWS\System32\GroupPolicy [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [0 Ko] - C:\WINDOWS\System32\GroupPolicyUsers [MD5.EA99A87E98D995DE6E280CF85CEAD413] - |A| - [07/12/2019 09:08:05] - (.-.) - [1.21 Ko] - (0.0.0.0) - C:\WINDOWS\System32\HandwritingSystemToastIcon.contrast-white.png [MD5.B8E586ED92DB703FFA480E254996160E] - |A| - [07/12/2019 09:08:05] - (.-.) - [0.89 Ko] - (0.0.0.0) - C:\WINDOWS\System32\HandwritingSystemToastIcon.png [MD5.85B5676772E1DB9A85799814DA26B493] - |A| - [29/06/2021 12:02:42] - (.(c) 2016 Harman. - Harman APO Interface.) - [150.74 Ko] - (1.2.0.0) - C:\WINDOWS\System32\HarmanAudioInterface.dll [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [256.5 Ko] - C:\WINDOWS\System32\he-IL [MD5.6E9E9D56B192B2995493E529CFF2BBFE] - |A| - [07/12/2019 09:08:05] - (.-.) - [1.43 Ko] - (0.0.0.0) - C:\WINDOWS\System32\HeadphoneSystemToastIcon.contrast-white.png [MD5.7F1E9502267F778F3A8139C35A352190] - |A| - [07/12/2019 09:08:05] - (.-.) - [1.09 Ko] - (0.0.0.0) - C:\WINDOWS\System32\HeadphoneSystemToastIcon.png [MD5.202A07E4526B050E22624328E64E0470] - |A| - [07/12/2019 09:08:05] - (.-.) - [1.52 Ko] - (0.0.0.0) - C:\WINDOWS\System32\HeadsetSystemToastIcon.contrast-white.png [MD5.1892ACC10CAC009BCAC146AD650ABA58] - |A| - [07/12/2019 09:08:05] - (.-.) - [1.17 Ko] - (0.0.0.0) - C:\WINDOWS\System32\HeadsetSystemToastIcon.png [MD5.031713BFD5F30E63336D3CA5D2767BE9] - |A| - [07/12/2019 09:08:05] - (.-.) - [1.79 Ko] - (0.0.0.0) - C:\WINDOWS\System32\HealthSystemToastIcon.contrast-white.png [MD5.C1BD7976C99830E33A713D02374054EC] - |A| - [07/12/2019 09:08:05] - (.-.) - [1.62 Ko] - (0.0.0.0) - C:\WINDOWS\System32\HealthSystemToastIcon.png [MD5.6D2BA2902199292D57806E3C53C587BF] - |A| - [29/06/2021 13:10:48] - (.-.) - [299.5 Ko] - (0.0.0.0) - C:\WINDOWS\System32\HeatCore.dll [MD5.C8CB6826619639276ACC4B90592417EF] - |A| - [29/06/2021 12:02:43] - (.© 2017 Dolby Laboratories, Inc. - Dolby DAX2 HiFi API.) - [369.52 Ko] - (0.8.0.74) - C:\WINDOWS\System32\HiFiDAX2API.dll [MD5.9971D36102C982A5BA3D4E9AA690129A] - |A| - [29/06/2021 12:02:43] - (.© 2016 Dolby Laboratories, Inc. - Dolby DAX2 HiFi API.) - [396.92 Ko] - (1.6.0.47) - C:\WINDOWS\System32\HiFiDAX2APIPCLL.dll [MD5.648B40EAD09C4572DB5E054431B463F6] - |A| - [29/06/2021 12:02:43] - (.© Harman. - Audio by Harman APO.) - [351.9 Ko] - (1.4.0.0) - C:\WINDOWS\System32\HMClariFi.dll [MD5.5AD3CC191BCC9170D161CD450CC139E8] - |A| - [29/06/2021 12:02:43] - (.© Harman. - Audio by Harman APO.) - [186.45 Ko] - (1.4.0.0) - C:\WINDOWS\System32\HMEQ.dll [MD5.50E0C4C5588523932609713541EB797D] - |A| - [29/06/2021 12:02:43] - (.© Harman. - Audio by Harman APO.) - [186.45 Ko] - (1.4.0.0) - C:\WINDOWS\System32\HMEQ_Voice.dll [MD5.4E75D9541F21B990973C5328B91E0E2B] - |A| - [29/06/2021 12:02:43] - (.© Harman. - Audio by Harman APO.) - [199.06 Ko] - (1.4.0.0) - C:\WINDOWS\System32\HMHVS.dll [MD5.80780DB83A4F98EC2E3266C341650249] - |A| - [29/06/2021 12:02:43] - (.© Harman. - Audio by Harman APO.) - [175.38 Ko] - (1.4.0.0) - C:\WINDOWS\System32\HMLimiter.dll [MD5.0243AF29EA835E1C7FA83DC4553209D0] - |A| - [29/06/2021 12:02:43] - (.?Harman. - Audio by Harman APO UI.) - [406.74 Ko] - (1.4.0.0) - C:\WINDOWS\System32\HMUI.dll [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [250 Ko] - C:\WINDOWS\System32\hr-HR [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [329.5 Ko] - C:\WINDOWS\System32\hu-HU [MD5.B6037A4AD99A567A34F7A014F8B42069] - |A| - [29/06/2021 13:11:32] - (.-.) - [134.82 Ko] - (0.0.0.0) - C:\WINDOWS\System32\HvsiManagementApi.dll [MD5.871CA2345825E86D1D2D2A2E9E475D4F] - |A| - [29/06/2021 13:11:25] - (.-.) - [44.8 Ko] - (0.0.0.0) - C:\WINDOWS\System32\HvSocket.dll [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 14:53:51] - [149.55 Ko] - C:\WINDOWS\System32\Hydrogen [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [5.36 Ko] - C:\WINDOWS\System32\ias [MD5.3B4CFC9344B29B3B17F322A91AC97BA1] - |A| - [29/06/2021 12:02:43] - (.Copyright (c) 2017, ICEpower a/s - ICEpower ICEsound APO.) - [664.59 Ko] - (1.0.0.29) - C:\WINDOWS\System32\ICEsoundAPO64.dll [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [36.27 Ko] - C:\WINDOWS\System32\icsxml [MD5.947D07FA32ABB13DB520016769EB901B] - |A| - [29/06/2021 13:10:49] - (.Copyright (C) 2016 and later: Unicode, Inc. and others. License & terms of use: http://www.unicode.org/copyright.html - ICU Combined Library.) - [2207.5 Ko] - (64.2.0.0) - C:\WINDOWS\System32\icu.dll [MD5.A7B574704574F326B92DCEA872F1E9E1] - |A| - [29/06/2021 13:10:49] - (.Copyright (C) 2016 and later: Unicode, Inc. and others. License & terms of use: http://www.unicode.org/copyright.html - ICU I18N Forwarder DLL.) - [24.5 Ko] - (64.2.0.0) - C:\WINDOWS\System32\icuin.dll [MD5.4A85A9DEA3D47D95CEF5525586756EA6] - |A| - [29/06/2021 13:10:49] - (.Copyright (C) 2016 and later: Unicode, Inc. and others. License & terms of use: http://www.unicode.org/copyright.html - ICU Common Forwarder DLL.) - [29 Ko] - (64.2.0.0) - C:\WINDOWS\System32\icuuc.dll [MD5.388BE35F952EC7F057CDD79E8EDF9A18] - |A| - [29/06/2021 13:10:36] - (.-.) - [193 Ko] - (0.0.0.0) - C:\WINDOWS\System32\IHDS.dll [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [26857.92 Ko] - C:\WINDOWS\System32\IME [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [0 Ko] - C:\WINDOWS\System32\inetsrv [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [6943 Ko] - C:\WINDOWS\System32\InputMethod [MD5.8DE9AE82152650C178BF1E24014E8503] - |A| - [07/12/2019 09:08:05] - (.-.) - [1.25 Ko] - (0.0.0.0) - C:\WINDOWS\System32\InputSystemToastIcon.contrast-white.png [MD5.0B9FBD6F3ED617CD36D042D3422F1C2B] - |A| - [07/12/2019 09:08:05] - (.-.) - [0.9 Ko] - (0.0.0.0) - C:\WINDOWS\System32\InputSystemToastIcon.png [MD5.4B50A976673054965C8D75832DD01FB6] - |A| - [29/06/2021 12:02:43] - (.© Knowles Electronics. - Knowles HD Audio APO.) - [603.7 Ko] - (4.1105.6000.53) - C:\WINDOWS\System32\KAAPORT64.dll [MD5.23AC7515B6D8A794BCC01B582F044078] - |A| - [07/12/2019 09:08:05] - (.-.) - [0.82 Ko] - (0.0.0.0) - C:\WINDOWS\System32\KeyboardSystemToastIcon.contrast-white.png [MD5.3DF873E16CCEA9B42857FB5FA085CB00] - |A| - [07/12/2019 09:08:05] - (.-.) - [0.51 Ko] - (0.0.0.0) - C:\WINDOWS\System32\KeyboardSystemToastIcon.png [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [10192.95 Ko] - C:\WINDOWS\System32\Keywords [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [239 Ko] - C:\WINDOWS\System32\ko-KR [MD5.9451D4436E2EA67EB33FCC764E4AABED] - |A| - [07/12/2019 09:08:39] - (.-.) - [186.29 Ko] - (0.0.0.0) - C:\WINDOWS\System32\LaptopPlugInToastImg.gif [MD5.F0CC83E1BA7E24F9B3292160C28AECD7] - |A| - [07/12/2019 09:08:07] - (.-.) - [145.56 Ko] - (0.0.0.0) - C:\WINDOWS\System32\LargeRoom.bin [MD5.14BE6A1C21780D85AD3F1D09283C56DA] - |A| - [29/06/2021 13:11:38] - (.-.) - [1647.5 Ko] - (3.0.2.0) - C:\WINDOWS\System32\libcrypto.dll [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [454.91 Ko] - C:\WINDOWS\System32\Licenses [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [29853.44 Ko] - C:\WINDOWS\System32\LogFiles [MD5.00000000000000000000000000000000] - |D| - [01/07/2021 22:34:59] - [512 Ko] - C:\WINDOWS\System32\Logs [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [246.5 Ko] - C:\WINDOWS\System32\lt-LT [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [247.5 Ko] - C:\WINDOWS\System32\lv-LV [MD5.00000000000000000000000000000000] - |D| - [10/07/2021 17:44:37] - [93777.68 Ko] - C:\WINDOWS\System32\lxss [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 14:52:40] - [32.68 Ko] - C:\WINDOWS\System32\MailContactsCalendarSync [MD5.7A495CA1402C2F9F5D035092AD808669] - |A| - [07/12/2019 09:10:41] - (.-.) - [0.85 Ko] - (0.0.0.0) - C:\WINDOWS\System32\manage-bde.wsf [MD5.6C3157FD2E850739EDEA659D40D0977D] - |A| - [29/06/2021 12:02:43] - (.© Waves Audio Ltd. - MaxxAudio APO.) - [322.8 Ko] - (2.2.9.0) - C:\WINDOWS\System32\MaxxAudioAPO20.dll [MD5.84E57F29ADF92B001C5EB4DB2AB2F7B1] - |A| - [29/06/2021 12:02:43] - (.© Waves Audio Ltd. - MaxxAudio APO.) - [662.28 Ko] - (3.6.0.0) - C:\WINDOWS\System32\MaxxAudioAPO30.dll [MD5.963A8F89B0CC40B14F27FCAD30BE8CA3] - |A| - [29/06/2021 12:02:43] - (.© Waves Audio Ltd. - MaxxAudio APO.) - [1138.82 Ko] - (4.5.8.0) - C:\WINDOWS\System32\MaxxAudioAPO4064.dll [MD5.CD896175B887ACCD27F789A2998D0774] - |A| - [29/06/2021 12:02:43] - (.© Waves Audio Ltd. - MaxxAudio APO.) - [1185.21 Ko] - (5.6.5.0) - C:\WINDOWS\System32\MaxxAudioAPO5064.dll [MD5.CBDFB5557D482AD114B501A3FE4541BF] - |A| - [29/06/2021 12:02:43] - (.© Waves Audio Ltd. - MaxxAudio APO.) - [1389.57 Ko] - (6.1.17.0) - C:\WINDOWS\System32\MaxxAudioAPO6064.dll [MD5.B48DE64266518A9CD20B826F595ED469] - |A| - [29/06/2021 12:02:43] - (.© Waves Audio Ltd. - MaxxAudio APO.) - [2237.6 Ko] - (7.0.24.0) - C:\WINDOWS\System32\MaxxAudioAPO7064.dll [MD5.8DD9C5774067C9BE2D3A0E935D135420] - |A| - [29/06/2021 12:02:43] - (.Copyright (C) 2010-2013 - MaxxAudio APO Shell.) - [909.78 Ko] - (4.10.8.0) - C:\WINDOWS\System32\MaxxAudioAPOShell64.dll [MD5.82244FEFCFEB8B4D7CBC8212A614AB5A] - |A| - [29/06/2021 12:02:43] - (.Copyright © 1996-2014 -.) - [2002.13 Ko] - (4.1.1.0) - C:\WINDOWS\System32\MaxxAudioEQ64.dll [MD5.1076EC14B45D3AC6E2A0194844C9EFDD] - |A| - [29/06/2021 12:02:43] - (.Copyright © 1996-2013 -.) - [13727.78 Ko] - (4.4.10.0) - C:\WINDOWS\System32\MaxxAudioRealtek64.dll [MD5.D5F1490A24F91E838C1ECBD601619D4F] - |A| - [29/06/2021 12:02:44] - (.© Waves Audio Ltd. - MaxxSpeech APO.) - [1303.1 Ko] - (1.1.4.0) - C:\WINDOWS\System32\MaxxSpeechAPO64.dll [MD5.CFE357DBB63E9B936E88253A2BA99326] - |A| - [29/06/2021 12:02:44] - (.© Waves Audio Ltd. - MaxxVoice APO.) - [976.41 Ko] - (2.6.2.0) - C:\WINDOWS\System32\MaxxVoiceAPO2064.dll [MD5.B820ED6498F8246F8BB1D4496A80EA8D] - |A| - [29/06/2021 12:02:44] - (.© Waves Audio Ltd. - MaxxVoice APO.) - [12815.02 Ko] - (3.1.14.0) - C:\WINDOWS\System32\MaxxVoiceAPO3064.dll [MD5.76E6BD12233C8CD59524A2B5685D46BD] - |A| - [29/06/2021 12:02:44] - (.© Waves Audio Ltd. - MaxxVoice APO.) - [12683.92 Ko] - (4.0.19.0) - C:\WINDOWS\System32\MaxxVoiceAPO4064.dll [MD5.ADFBDA58D830421CBF456CAAED17BBAD] - |A| - [29/06/2021 12:02:44] - (.© Waves Audio Ltd. - MaxxVolumeSD APO.) - [661.78 Ko] - (3.6.0.0) - C:\WINDOWS\System32\MaxxVolumeSDAPO.dll [MD5.4BFD587C99FE34EEA0E74622C798B3BE] - |A| - [17/09/2021 02:24:44] - (.-.) - [1137 Ko] - (0.0.0.0) - C:\WINDOWS\System32\MBR2GPT.EXE [MD5.F23EB28468FC8B62AF941308EC30387F] - |A| - [07/12/2019 09:08:05] - (.-.) - [1.25 Ko] - (0.0.0.0) - C:\WINDOWS\System32\MediaSystemToastIcon.contrast-white.png [MD5.6E27512E38D598E0A60F8E5ADCF032CD] - |A| - [07/12/2019 09:08:05] - (.-.) - [0.83 Ko] - (0.0.0.0) - C:\WINDOWS\System32\MediaSystemToastIcon.png [MD5.69D04DE701CF1E8CE69C65D1671D2B3F] - |A| - [07/12/2019 09:08:07] - (.-.) - [107.46 Ko] - (0.0.0.0) - C:\WINDOWS\System32\MediumRoom.bin [MD5.00000000000000000000000000000000] - |SD| - [29/06/2021 12:17:47] - [1107.7 Ko] - C:\WINDOWS\System32\Microsoft [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [6875.59 Ko] - C:\WINDOWS\System32\migration [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [45422.87 Ko] - C:\WINDOWS\System32\migwiz [MD5.08749DCC252AE1148E3BEA32B3FFFBFC] - |A| - [07/12/2019 09:10:11] - (.-.) - [0.11 Ko] - (0.0.0.0) - C:\WINDOWS\System32\MixedRealityRuntime.json [MD5.C8BF077B236ED2803347BD95DE29BF68] - |A| - [07/12/2019 09:14:56] - (.-.) - [3.03 Ko] - (0.0.0.0) - C:\WINDOWS\System32\mmc.exe.config [MD5.B43E43FFFDD0F06A6925C7C89594042B] - |A| - [07/12/2019 09:08:05] - (.-.) - [1.35 Ko] - (0.0.0.0) - C:\WINDOWS\System32\MouseSystemToastIcon.contrast-white.png [MD5.5D2F0D3E50BF1129D260AC1405FF2A18] - |A| - [07/12/2019 09:08:05] - (.-.) - [1.06 Ko] - (0.0.0.0) - C:\WINDOWS\System32\MouseSystemToastIcon.png [MD5.00000000000000000000000000000000] - |D| - [01/07/2021 22:33:18] - [0 Ko] - C:\WINDOWS\System32\MRT [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [45.5 Ko] - C:\WINDOWS\System32\MSDRM [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [4148.28 Ko] - C:\WINDOWS\System32\MsDtc [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [21.37 Ko] - C:\WINDOWS\System32\MUI [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [45.64 Ko] - C:\WINDOWS\System32\my-mm [MD5.02E55C4A660269C15F755CC2FF58F073] - |A| - [29/06/2021 12:02:44] - (.Copyright © 2013 Nahimic Inc. All rights reserved - Nahimic APO lfx dll.) - [5462.51 Ko] - (6.3.9600.17246) - C:\WINDOWS\System32\NAHIMICAPOlfx.dll [MD5.EB92FCA946E009B8DC614D9ED2B0CB2E] - |A| - [29/06/2021 12:02:44] - (.Copyright © 2013 Nahimic Inc. All rights reserved - Nahimic APO Settings Communication Dll.) - [980.33 Ko] - (1.0.0.14866) - C:\WINDOWS\System32\NahimicAPONSControl.dll [MD5.0537CFE215E65ADB1C41E5E7DA827187] - |A| - [29/06/2021 12:02:44] - (.Copyright © 2013 Nahimic Inc. All rights reserved - Nahimic APO lfx dll.) - [5799.71 Ko] - (6.3.9600.17246) - C:\WINDOWS\System32\NAHIMICV2apo.dll [MD5.5E9B64A64CE70799C2A71413ABF8E076] - |A| - [29/06/2021 12:02:44] - (.Copyright © 2013 Nahimic Inc. All rights reserved - Nahimic APO lfx dll.) - [6259.85 Ko] - (6.3.9600.17336) - C:\WINDOWS\System32\NAHIMICV3apo.dll [MD5.74FDEEAC0C0C0F62F4D0D484A36DA23A] - |A| - [07/12/2019 09:08:44] - (.-.) - [30.09 Ko] - (0.0.0.0) - C:\WINDOWS\System32\NarratorControlTemplates.xml [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [319 Ko] - C:\WINDOWS\System32\nb-NO [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [1024 Ko] - C:\WINDOWS\System32\NDF [MD5.C146E873B22C3B300B21A859FE66C27A] - |A| - [07/12/2019 09:09:48] - (.-.) - [21.15 Ko] - (0.0.0.0) - C:\WINDOWS\System32\NetTrace.PLA.Diagnostics.xml [MD5.0E2D5DA1C7A1A97E46172AC33AD354EC] - |A| - [07/12/2019 09:09:48] - (.-.) - [70.5 Ko] - (0.0.0.0) - C:\WINDOWS\System32\nettraceex.dll [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [51 Ko] - C:\WINDOWS\System32\networklist [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [343 Ko] - C:\WINDOWS\System32\nl-NL [MD5.00000000000000000000000000000000] - |SD| - [07/12/2019 09:14:52] - [3781.5 Ko] - C:\WINDOWS\System32\Nui [MD5.EDAFFAC0FA9FBF59262404453D6FF786] - |A| - [09/02/2022 23:55:57] - (.-.) - [87.09 Ko] - (0.0.0.0) - C:\WINDOWS\System32\nvinfo.pb [MD5.AD4C984EB0D134A7524C1FE70F312ECF] - |A| - [09/02/2022 23:55:57] - (.-.) - [777.66 Ko] - (0.0.0.0) - C:\WINDOWS\System32\nvofapi64.dll [MD5.D55B689DF6269B40E170EAFBCC0C34C4] - |A| - [07/12/2019 14:53:51] - (.-.) - [20.42 Ko] - (0.0.0.0) - C:\WINDOWS\System32\OEMDefaultAssociations.xml [MD5.F3DC097E834C1A11F2BEDFD429C644A9] - |A| - [07/12/2019 09:08:39] - (.-.) - [0.41 Ko] - (0.0.0.0) - C:\WINDOWS\System32\OkDone_80.contrast-black.png [MD5.BFE1CCA08FEFC8A3422F7DA615567D75] - |A| - [07/12/2019 09:08:39] - (.-.) - [0.43 Ko] - (0.0.0.0) - C:\WINDOWS\System32\OkDone_80.contrast-white.png [MD5.F3DC097E834C1A11F2BEDFD429C644A9] - |A| - [07/12/2019 09:08:39] - (.-.) - [0.41 Ko] - (0.0.0.0) - C:\WINDOWS\System32\OkDone_80.png [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [16635.71 Ko] - C:\WINDOWS\System32\oobe [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 14:51:31] - [3625 Ko] - C:\WINDOWS\System32\OpenSSH [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [3.81 Ko] - C:\WINDOWS\System32\osa-Osge-001 [MD5.459FB33AA2114A28C5932FEAA115B072] - |A| - [07/12/2019 09:08:07] - (.-.) - [45.82 Ko] - (0.0.0.0) - C:\WINDOWS\System32\OutdoorAudioEnvironment.bin [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [1775.23 Ko] - C:\WINDOWS\System32\PerceptionSimulation [MD5.9CB731AFDA9254C2A1658C3C1F490AF3] - |A| - [07/12/2019 09:17:25] - (.-.) - [130.07 Ko] - (0.0.0.0) - C:\WINDOWS\System32\perfc009.dat [MD5.ABF813870537D0796C3DFD29811760C7] - |A| - [07/12/2019 14:50:23] - (.-.) - [144.54 Ko] - (0.0.0.0) - C:\WINDOWS\System32\perfc00C.dat [MD5.1E60BC5E525063B96078DF17FBD3C4E1] - |A| - [07/12/2019 09:17:25] - (.-.) - [32.64 Ko] - (0.0.0.0) - C:\WINDOWS\System32\perfd009.dat [MD5.9F9AF8517189B0D61B2615007E071084] - |A| - [07/12/2019 14:50:23] - (.-.) - [39.74 Ko] - (0.0.0.0) - C:\WINDOWS\System32\perfd00C.dat [MD5.35A56F3540B886F696D14DB1994FE67E] - |A| - [07/12/2019 09:17:25] - (.-.) - [684.92 Ko] - (0.0.0.0) - C:\WINDOWS\System32\perfh009.dat [MD5.E5D297B2E471DA478A22446524CE7DEF] - |A| - [07/12/2019 14:50:23] - (.-.) - [771.72 Ko] - (0.0.0.0) - C:\WINDOWS\System32\perfh00C.dat [MD5.643B95707336AEDDDCF2CC1A39FC66D3] - |A| - [29/06/2021 13:24:12] - (.-.) - [1726.13 Ko] - (0.0.0.0) - C:\WINDOWS\System32\PerfStringBackup.INI [MD5.79D34E3B62076D4C875C748F5BE71ECA] - |A| - [07/12/2019 09:08:05] - (.-.) - [2.21 Ko] - (0.0.0.0) - C:\WINDOWS\System32\PhoneSystemToastIcon.contrast-white.png [MD5.4D9495349D00D9AD907F227FF51F289F] - |A| - [07/12/2019 09:08:05] - (.-.) - [1.92 Ko] - (0.0.0.0) - C:\WINDOWS\System32\PhoneSystemToastIcon.png [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [343 Ko] - C:\WINDOWS\System32\pl-PL [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [464.5 Ko] - C:\WINDOWS\System32\PointOfService [MD5.7700A1F5ECACFB07A92C5960448AFAB8] - |A| - [07/12/2019 09:08:28] - (.-.) - [43 Ko] - (0.0.0.0) - C:\WINDOWS\System32\pospaymentsworker.exe [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 14:50:21] - [969.13 Ko] - C:\WINDOWS\System32\Printing_Admin_Scripts [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [0 Ko] - C:\WINDOWS\System32\ProximityToast [MD5.007893E8374C766471239EB291BA8C17] - |A| - [07/12/2019 09:08:19] - (.-.) - [4.05 Ko] - (0.0.0.0) - C:\WINDOWS\System32\psmodulediscoveryprovider.mof [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [337 Ko] - C:\WINDOWS\System32\pt-BR [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [339.5 Ko] - C:\WINDOWS\System32\pt-PT [MD5.59F0C73AE88A5D08E0A6CCA3FCF08729] - |A| - [29/06/2021 12:02:44] - (.©2012 Dolby Laboratories. - Dolby PCEE4 ASL Analog x64.) - [131.05 Ko] - (7.2.8000.17) - C:\WINDOWS\System32\R4EEA64A.dll [MD5.AB1AFE42BF151B1FC53AED21B7DDDB17] - |A| - [29/06/2021 12:02:44] - (.©2012 Dolby Laboratories. - Dolby PCEE4 COM DLL x64.) - [437.22 Ko] - (7.2.8000.17) - C:\WINDOWS\System32\R4EED64A.dll [MD5.722C6D13A588E834600081CF688021DB] - |A| - [29/06/2021 12:02:44] - (.©2012 Dolby Laboratories. - Dolby PCEE4 GFX APO x64.) - [82.63 Ko] - (7.2.8000.17) - C:\WINDOWS\System32\R4EEG64A.dll [MD5.90DC19A7075B3653C432D922A284352F] - |A| - [29/06/2021 12:02:44] - (.©2012 Dolby Laboratories. - Dolby PCEE4 LFX APO x64.) - [148.23 Ko] - (7.2.8000.17) - C:\WINDOWS\System32\R4EEL64A.dll [MD5.603A80AA2463F995C2C3805AC3B536B7] - |A| - [29/06/2021 12:02:44] - (.©2012 Dolby Laboratories. - Dolby PCEE4 Control Panel x64.) - [7004.8 Ko] - (7.2.8000.17) - C:\WINDOWS\System32\R4EEP64A.dll [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [23.75 Ko] - C:\WINDOWS\System32\ras [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [0 Ko] - C:\WINDOWS\System32\RasToast [MD5.75BCC7E07D8CE1C6C52C60279658C1A7] - |A| - [20/10/2020 22:31:58] - (.Copyright © 2017 Razer Inc. All rights reserved - RazerS3Coinstaller.) - [77.52 Ko] - (0.0.0.3) - C:\WINDOWS\System32\RazerS3Coinstaller.dll [MD5.7852D37790807E55BD71A65183E0F1ED] - |A| - [10/07/2021 15:04:03] - (.-.) - [2315.5 Ko] - (1.0.2104.14003) - C:\WINDOWS\System32\rdpnano.dll [MD5.42577ED1BA5199ADD53E1186EC4E28A4] - |A| - [29/06/2021 13:10:37] - (.-.) - [72.5 Ko] - (0.0.0.0) - C:\WINDOWS\System32\rdsxvmaudio.dll [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [1.04 Ko] - C:\WINDOWS\System32\Recovery [MD5.826549DF7B1333179BA8CA939B12DAD3] - |A| - [07/12/2019 09:08:05] - (.-.) - [1.58 Ko] - (0.0.0.0) - C:\WINDOWS\System32\RemoteSystemToastIcon.contrast-white.png [MD5.B4DEEC96F9DF6961D5DE054F11BF9C2B] - |A| - [07/12/2019 09:08:05] - (.-.) - [1.1 Ko] - (0.0.0.0) - C:\WINDOWS\System32\RemoteSystemToastIcon.png [MD5.19B5EEEC29F044451D5E8E89B1BE6F5E] - |A| - [07/12/2019 09:09:33] - (.-.) - [110.5 Ko] - (0.0.0.0) - C:\WINDOWS\System32\ResBParser.dll [MD5.31924C8E78CDBD81DA7905E87B185387] - |A| - [07/12/2019 09:09:54] - (.-.) - [9.35 Ko] - (0.0.0.0) - C:\WINDOWS\System32\ResPriHMImageList [MD5.5504F7F27D0AB178346D643D444A612C] - |A| - [07/12/2019 09:09:54] - (.-.) - [8.98 Ko] - (0.0.0.0) - C:\WINDOWS\System32\ResPriHMImageListLowCost [MD5.85CF16AF388AE12AAE3E48A883C17A06] - |A| - [07/12/2019 09:09:54] - (.-.) - [8.77 Ko] - (0.0.0.0) - C:\WINDOWS\System32\ResPriImageList [MD5.1391FB4E005C208A35E77DF6F3F055E2] - |A| - [07/12/2019 09:09:54] - (.-.) - [8.49 Ko] - (0.0.0.0) - C:\WINDOWS\System32\ResPriImageListLowCost [MD5.831C579709F4761E4AB7053FCF4176EC] - |A| - [07/12/2019 09:08:39] - (.-.) - [0.74 Ko] - (0.0.0.0) - C:\WINDOWS\System32\RestartNowPower_80.contrast-black.png [MD5.DF286186041C6BF73C5DC21CEEEFFED5] - |A| - [07/12/2019 09:08:39] - (.-.) - [0.77 Ko] - (0.0.0.0) - C:\WINDOWS\System32\RestartNowPower_80.contrast-white.png [MD5.831C579709F4761E4AB7053FCF4176EC] - |A| - [07/12/2019 09:08:39] - (.-.) - [0.74 Ko] - (0.0.0.0) - C:\WINDOWS\System32\RestartNowPower_80.png [MD5.AE9FE55FED83149715734CB83339055A] - |A| - [07/12/2019 09:08:39] - (.-.) - [1.07 Ko] - (0.0.0.0) - C:\WINDOWS\System32\RestartTonight_80.png [MD5.AE9FE55FED83149715734CB83339055A] - |A| - [07/12/2019 09:08:39] - (.-.) - [1.07 Ko] - (0.0.0.0) - C:\WINDOWS\System32\RestartTonight_80_contrast-black.png [MD5.891AD355AB777A95695FC8A8A623A614] - |A| - [07/12/2019 09:08:39] - (.-.) - [0.98 Ko] - (0.0.0.0) - C:\WINDOWS\System32\RestartTonight_80_contrast-white.png [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [0.07 Ko] - C:\WINDOWS\System32\restore [MD5.D518E801551E975B26ECA37E7E1D3086] - |A| - [29/06/2021 12:02:45] - (.© 2008,2009 Dolby Laboratories, Inc. - PCEE3 DAA Control Panel x64.) - [314.17 Ko] - (6.0.6001.18) - C:\WINDOWS\System32\RP3DAA64.dll [MD5.23212C53F5D8DE747F86463B3B5A183F] - |A| - [29/06/2021 12:02:45] - (.© 2008,2009 Dolby Laboratories, Inc. - PCEE3 DHT Control Panel x64.) - [314.17 Ko] - (6.0.6001.18) - C:\WINDOWS\System32\RP3DHT64.dll [MD5.AC1AA9F3B1D8FDF8882DC6AB8A10D64A] - |A| - [29/06/2021 12:02:45] - (.©2009 Dolby Laboratories, Inc. - Dolby PCEE3 COM DLL x64.) - [209.8 Ko] - (6.1.6001.33) - C:\WINDOWS\System32\RTEED64A.dll [MD5.FFE5A1AD38CFF13815D962F228C237C8] - |A| - [29/06/2021 12:02:45] - (.©2009 Dolby Laboratories, Inc. - Dolby PCEE3 GFX APO x64.) - [86.27 Ko] - (6.1.6001.33) - C:\WINDOWS\System32\RTEEG64A.dll [MD5.A75237F8A8BA4F19A7A8712FEE428A84] - |A| - [29/06/2021 12:02:45] - (.©2009 Dolby Laboratories, Inc. - Dolby PCEE3 LFX APO x64.) - [108.38 Ko] - (6.1.6001.33) - C:\WINDOWS\System32\RTEEL64A.dll [MD5.44BAE5798495ADF0E3006DFCFD35373F] - |A| - [29/06/2021 12:02:45] - (.©2009 Dolby Laboratories, Inc. - Dolby PCEE3 Control Panel x64.) - [378.23 Ko] - (6.1.6001.33) - C:\WINDOWS\System32\RTEEP64A.dll [MD5.AF47D6660569DFA46BC4E1CD21E1624B] - |A| - [28/09/2012 19:45:18] - (.-.) - [240.5 Ko] - (0.0.0.0) - C:\WINDOWS\System32\rtvcvfw64.dll [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [334.5 Ko] - C:\WINDOWS\System32\ru-RU [MD5.8BB7F1C55F4DF7CEFF9291FDB77F780B] - |A| - [11/11/2021 23:33:49] - (.-.) - [59.5 Ko] - (0.0.0.0) - C:\WINDOWS\System32\runexehelper.exe [MD5.5C18CD22BE4628865FCB63337A6E5EF6] - |A| - [07/12/2019 09:10:32] - (.-.) - [10.18 Ko] - (0.0.0.0) - C:\WINDOWS\System32\ScavengeSpace.xml [MD5.2F24BC74DCB28FE032C1596755385917] - |A| - [07/12/2019 09:08:39] - (.-.) - [0.53 Ko] - (0.0.0.0) - C:\WINDOWS\System32\ScheduleTime_80.contrast-black.png [MD5.E72B1B6800DE45AA9AE7E10F899E5999] - |A| - [07/12/2019 09:08:39] - (.-.) - [0.54 Ko] - (0.0.0.0) - C:\WINDOWS\System32\ScheduleTime_80.contrast-white.png [MD5.2F24BC74DCB28FE032C1596755385917] - |A| - [07/12/2019 09:08:39] - (.-.) - [0.53 Ko] - (0.0.0.0) - C:\WINDOWS\System32\ScheduleTime_80.png [MD5.A8308D2F3DDE0745E8B678BF69A2ECD0] - |A| - [07/12/2019 09:08:41] - (.-.) - [8 Ko] - (0.0.0.0) - C:\WINDOWS\System32\settings.dat [MD5.7A28F829585136B3572BC6F749461070] - |A| - [29/06/2021 12:02:45] - (.Copyright (c) 2006-2011 Synopsys, Inc. All Rights Reserved - SFAPO.DLL.) - [86.24 Ko] - (3.0.0.16) - C:\WINDOWS\System32\SFAPO64.dll [MD5.0976675DADFFFF05707F841B72418975] - |A| - [29/06/2021 12:02:45] - (.Copyright (c) 2006-2011 Synopsys, Inc. All Rights Reserved - SFCOM.DLL.) - [88.78 Ko] - (3.0.0.16) - C:\WINDOWS\System32\SFCOM64.dll [MD5.57DBB8DDDDABBDF1E66F3707E1264E2D] - |A| - [29/06/2021 12:02:45] - (.Copyright (c) 2006-2011 Synopsys, Inc. All Rights Reserved - SFNHK.DLL.) - [226.48 Ko] - (3.0.0.16) - C:\WINDOWS\System32\SFNHK64.dll [MD5.4F9374F4BA6E7C1766D92FFF7B460513] - |A| - [29/06/2021 12:02:45] - (.Copyright (C) 2016 DTS, Inc. - DTS Universal APO DLL.) - [961.83 Ko] - (3.5.14.0) - C:\WINDOWS\System32\sl3apo64.dll [MD5.80DC05FEC7BA483A27D1B6187329A18A] - |A| - [29/06/2021 12:02:45] - (.Copyright (C) 2016 DTS, Inc. - DTS APO Controller DLL.) - [3330.89 Ko] - (3.5.14.0) - C:\WINDOWS\System32\slcnt64.dll [MD5.00000000000000000000000000000000] - |D| - [29/06/2021 12:17:48] - [166723 Ko] - C:\WINDOWS\System32\SleepStudy [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 14:50:21] - [98.06 Ko] - C:\WINDOWS\System32\slmgr [MD5.ACBA21E0914B0E4B01C02AD2798877DB] - |A| - [29/06/2021 12:02:45] - (.TODO: (c) . - TODO: .) - [252.79 Ko] - (1.0.0.1) - C:\WINDOWS\System32\slprp64.dll [MD5.FF5082EAF6259F5F4BE3A6C750DA0203] - |A| - [29/06/2021 12:02:45] - (.Copyright (C) 2016 DTS, Inc. - DTS APO Technology DLL.) - [3049.47 Ko] - (3.5.14.0) - C:\WINDOWS\System32\sltech64.dll [MD5.DAC275ABAAD2B689D7BB3685E4032072] - |A| - [07/12/2019 09:08:07] - (.-.) - [68.15 Ko] - (0.0.0.0) - C:\WINDOWS\System32\SmallRoom.bin [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:03:44] - [13385.02 Ko] - C:\WINDOWS\System32\SMI [MD5.55121989BE7B289813D419BA0FDEE8B7] - |A| - [07/12/2019 09:08:39] - (.-.) - [0.9 Ko] - (0.0.0.0) - C:\WINDOWS\System32\Snooze_80.contrast-black.png [MD5.E30B7D226E7B5B0EC2B9FC2316694ECC] - |A| - [07/12/2019 09:08:39] - (.-.) - [0.88 Ko] - (0.0.0.0) - C:\WINDOWS\System32\Snooze_80.contrast-white.png [MD5.55121989BE7B289813D419BA0FDEE8B7] - |A| - [07/12/2019 09:08:39] - (.-.) - [0.9 Ko] - (0.0.0.0) - C:\WINDOWS\System32\Snooze_80.png [MD5.DE3EAAF17BC934C77C4FC0C626EEA03B] - |A| - [07/12/2019 09:08:05] - (.-.) - [1.48 Ko] - (0.0.0.0) - C:\WINDOWS\System32\SpeakersSystemToastIcon.contrast-white.png [MD5.3308374DB8D20CFDA4D4204E2B5E559E] - |A| - [07/12/2019 09:08:05] - (.-.) - [0.88 Ko] - (0.0.0.0) - C:\WINDOWS\System32\SpeakersSystemToastIcon.png [MD5.6DB032025BD266E5A3A52259F57F9247] - |A| - [07/12/2019 09:09:51] - (.-.) - [40 Ko] - (0.0.0.0) - C:\WINDOWS\System32\SpectrumSyncClient.dll [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [8160.8 Ko] - C:\WINDOWS\System32\Speech [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [16321.9 Ko] - C:\WINDOWS\System32\Speech_OneCore [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [38647.44 Ko] - C:\WINDOWS\System32\spool [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [19617.04 Ko] - C:\WINDOWS\System32\spp [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [23.6 Ko] - C:\WINDOWS\System32\sppui [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [253.5 Ko] - C:\WINDOWS\System32\sr-Latn-RS [MD5.1EC2635E831C845E2ECC3D3340AC7797] - |A| - [29/06/2021 12:02:45] - (.Copyright (c) 2006-2012 Synopsys, Inc. All Rights Reserved - SRAPO.DLL.) - [456.2 Ko] - (4.0.0.59) - C:\WINDOWS\System32\SRAPO64.dll [MD5.09DB317084AD30C69391BF95BF44664C] - |A| - [29/06/2021 12:02:45] - (.Copyright (c) 2006-2012 Synopsys, Inc. All Rights Reserved - SRCOM.DLL.) - [333.15 Ko] - (4.0.0.59) - C:\WINDOWS\System32\SRCOM.dll [MD5.F5FE279435F4593A1F6869FD08EAB55F] - |A| - [29/06/2021 12:02:45] - (.Copyright (c) 2006-2012 Synopsys, Inc. All Rights Reserved - SRCOM.DLL.) - [372.47 Ko] - (4.0.0.59) - C:\WINDOWS\System32\SRCOM64.dll [MD5.BA7D4E5FAE64BD0403C7F7E91CD93F77] - |A| - [07/12/2019 09:09:54] - (.-.) - [11.03 Ko] - (0.0.0.0) - C:\WINDOWS\System32\srms-apr-v.dat [MD5.DC9450258D80F46AEF8EF063A7C629B0] - |A| - [07/12/2019 09:09:54] - (.-.) - [19.03 Ko] - (0.0.0.0) - C:\WINDOWS\System32\srms-apr.dat [MD5.67894C70461ABD4EF6C116637EBB218A] - |A| - [07/12/2019 09:09:45] - (.-.) - [58.16 Ko] - (0.0.0.0) - C:\WINDOWS\System32\srms.dat [MD5.6BFB992D7EED2D1CAD7F28968B98976B] - |A| - [29/06/2021 12:02:45] - (.Copyright (c) 2006-2012 Synopsys, Inc. All Rights Reserved - SRRPTR.DLL.) - [1401.5 Ko] - (4.0.0.59) - C:\WINDOWS\System32\SRRPTR64.dll [MD5.D5CBFC2DCAB04A9B3D0CDE38D65A3F9B] - |A| - [29/06/2021 12:02:45] - (.(c) 2007 SRS Labs, Inc. - COM object implementing SRS Headphone 360.) - [204.62 Ko] - (1.1.0.0) - C:\WINDOWS\System32\SRSHP64.dll [MD5.E219852B87D0634EDE3B3B61C520B450] - |A| - [29/06/2021 12:02:45] - (.Copyright (c) 2006 SRS Labs, Inc.. - TruSurround HD and HD4 COM object for Windows.) - [216.76 Ko] - (1.1.4.0) - C:\WINDOWS\System32\SRSTSH64.dll [MD5.0F4A688E07D9905E0EF9A3BB0D1E9A60] - |A| - [29/06/2021 12:02:45] - (.Copyright 2002 SRS Labs, Inc. - TruSurroundXT Module.) - [519.9 Ko] - (3.2.0.0) - C:\WINDOWS\System32\SRSTSX64.dll [MD5.4F443A11503A87786D1B0FA818F70D07] - |A| - [29/06/2021 12:02:45] - (.(c) 2006 SRS Labs, Inc. - WOW HD COM object for Windows.) - [162.3 Ko] - (1.1.3.0) - C:\WINDOWS\System32\SRSWOW64.dll [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [37976 Ko] - C:\WINDOWS\System32\sru [MD5.862E9C75593E9BB1A90961975276F7FE] - |A| - [29/06/2021 13:10:37] - (.-.) - [444.5 Ko] - (0.0.0.0) - C:\WINDOWS\System32\ssdm.dll [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [324.5 Ko] - C:\WINDOWS\System32\sv-SE [MD5.26D2D82E2DD08761EAACF5BB5099D65B] - |A| - [17/09/2021 02:24:34] - (.-.) - [1265.67 Ko] - (0.0.0.0) - C:\WINDOWS\System32\SvBannerBackground.png [MD5.20C4FE2B130D9F0C92D7629E71AFBB66] - |A| - [07/12/2019 09:10:18] - (.-.) - [1.68 Ko] - (0.0.0.0) - C:\WINDOWS\System32\SyncAppvPublishingServer.vbs [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [1428.62 Ko] - C:\WINDOWS\System32\Sysprep [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [961.28 Ko] - C:\WINDOWS\System32\SystemResetPlatform [MD5.4A2EF58B63D33AF5E62B5EE526184D67] - |A| - [23/03/2021 15:57:56] - (.Copyright (c) 2013 - 2021 Advanced Micro Devices, Inc. - t-base_client_api dll.) - [424.2 Ko] - (4.16.0.0) - C:\WINDOWS\System32\t-base_client_api.dll [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [8.16 Ko] - C:\WINDOWS\System32\ta-in [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [10.73 Ko] - C:\WINDOWS\System32\ta-lk [MD5.3596DC15B6F6CBBB6EC8B143CBD57F24] - |A| - [14/01/2022 01:13:04] - (.Copyright (c) libarchive authors - bsdtar archive tool.) - [53.5 Ko] - (3.5.1.0) - C:\WINDOWS\System32\tar.exe [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [678.57 Ko] - C:\WINDOWS\System32\Tasks [MD5.D948DC6104B522222A2F2F942B316558] - |A| - [23/03/2021 15:57:58] - (.Copyright (c) 2013 - 2018 Advanced Micro Devices, Inc. - tbaseregistry dll.) - [471.7 Ko] - (4.6.1.1) - C:\WINDOWS\System32\tbaseregistry64.dll [MD5.D602CA245CC6774A0981B607F0675609] - |A| - [07/12/2019 09:09:05] - (.-.) - [58.71 Ko] - (0.0.0.0) - C:\WINDOWS\System32\tcpmon.ini [MD5.A6563B8909ED33D2F70B3C9103862268] - |A| - [17/09/2021 02:24:32] - (.-.) - [2208 Ko] - (0.0.0.0) - C:\WINDOWS\System32\TextInputMethodFormatter.dll [MD5.4C528AE5D512E3901BACAA5D75240381] - |A| - [18/10/2021 21:53:56] - (.-.) - [689.98 Ko] - (0.0.0.0) - C:\WINDOWS\System32\TextShaping.dll [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [240 Ko] - C:\WINDOWS\System32\th-TH [MD5.CF7677327BE3C6395B9F3333CC0F1C15] - |A| - [29/06/2021 13:10:56] - (.-.) - [1.34 Ko] - (0.0.0.0) - C:\WINDOWS\System32\ThirdPartyNoticesBySHS.txt [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [5.97 Ko] - C:\WINDOWS\System32\ti-et [MD5.A63A6FA2218EA23DDBBA7A490710AFC7] - |A| - [14/01/2022 17:02:18] - (.Copyright (C) 2015-2021 - Thrustmaster Flight Control Panel.) - [1689 Ko] - (3.2.0.0) - C:\WINDOWS\System32\tmhotascpl.dll [MD5.4D25244E3885264E2A0EAD5BDD85D1F8] - |A| - [29/06/2021 12:02:45] - (.Copyright © 2016 Toshiba Client Solutions Co., Ltd. - TOSHIBA Audio Source Filtering APO.) - [832.16 Ko] - (2.1.1.0) - C:\WINDOWS\System32\tosasfapo64.dll [MD5.DA4DA5C6F7BB9CF07702D1D3031097CD] - |A| - [29/06/2021 12:02:45] - (.Copyright © 2016 Toshiba Client Solutions Co., Ltd. - TOSHIBA Earphone Audio Enhancement APO.) - [436.7 Ko] - (2.1.0.0) - C:\WINDOWS\System32\toseaeapo64.dll [MD5.88F38C964DEF4EE7355064723BC097EF] - |A| - [29/06/2021 12:02:45] - (.Copyright © 2016 Toshiba Client Solutions Co., Ltd. - TOSHIBA Speaker Audio Enhancement APO.) - [1306.29 Ko] - (2.1.1.0) - C:\WINDOWS\System32\tossaeapo64.dll [MD5.1FA1724F6FFFED0EF4834E5E2967E6AB] - |A| - [29/06/2021 12:02:45] - (.Copyright © 2016 Toshiba Client Solutions Co., Ltd. - TOSHIBA Speaker Audio Enhancement Maximizer.) - [590.62 Ko] - (1.1.2.0) - C:\WINDOWS\System32\tossaemaxapo64.dll [MD5.18304425F7AFD566D129BC3FD2DCBDAD] - |A| - [18/12/2021 11:59:14] - (.-.) - [266 Ko] - (0.0.0.0) - C:\WINDOWS\System32\TpmTool.exe [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [312.5 Ko] - C:\WINDOWS\System32\tr-TR [MD5.B88B8D017386A00D7724519F475317A0] - |A| - [07/12/2019 09:08:13] - (.-.) - [10.33 Ko] - (0.0.0.0) - C:\WINDOWS\System32\TransformPPSToWlan.xslt [MD5.2F05390B798363D51EBE65D6320CD45E] - |A| - [07/12/2019 09:08:13] - (.-.) - [1.65 Ko] - (0.0.0.0) - C:\WINDOWS\System32\TransformPPSToWlanCredentials.xslt [MD5.D200497DD3A24F138123F0EB6C385D1D] - |A| - [07/12/2019 09:10:19] - (.-.) - [0.14 Ko] - (0.0.0.0) - C:\WINDOWS\System32\UevAppMonitor.exe.config [MD5.4AAEE8D86EC81DA2A1514ABC77E71F57] - |A| - [07/12/2019 09:10:19] - (.-.) - [3.34 Ko] - (0.0.0.0) - C:\WINDOWS\System32\UevCustomActionTypes.tlb [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [249 Ko] - C:\WINDOWS\System32\uk-UA [MD5.8CDD866E0707A71952FBA8BE899B7512] - |A| - [29/06/2021 13:10:37] - (.-.) - [63.04 Ko] - (0.0.0.0) - C:\WINDOWS\System32\umpdc.dll [MD5.00000000000000000000000000000000] - |SD| - [07/12/2019 09:14:52] - [2204.14 Ko] - C:\WINDOWS\System32\UNP [MD5.8ADD5935D83D0A425C39E369520C4095] - |A| - [07/12/2019 09:08:37] - (.-.) - [48 Ko] - (0.0.0.0) - C:\WINDOWS\System32\UsbPmApi.dll [MD5.46A6DF60907700A148D42CCF1219522E] - |A| - [07/12/2019 09:08:39] - (.-.) - [38.5 Ko] - (0.0.0.0) - C:\WINDOWS\System32\usocoreps.dll [MD5.940617371796597C2ADB198C8CA6607E] - |A| - [08/10/2021 21:32:20] - (.-.) - [198.5 Ko] - (0.0.0.0) - C:\WINDOWS\System32\uwfcfgmgmt.dll [MD5.16719E1C38A003C40783E7528421AA3B] - |A| - [08/10/2021 21:32:20] - (.-.) - [154.5 Ko] - (0.0.0.0) - C:\WINDOWS\System32\uwfcsp.dll [MD5.9F5C9E33D356A3EC62EBD5046B5EFD46] - |A| - [08/10/2021 21:32:20] - (.-.) - [40 Ko] - (0.0.0.0) - C:\WINDOWS\System32\uwfservicingapi.dll [MD5.1E630731AFDFC63DEC4074301D342E4B] - |A| - [07/12/2019 09:08:09] - (.-.) - [36.5 Ko] - (0.0.0.0) - C:\WINDOWS\System32\VhfUm.dll [MD5.A10725A4632FFFEAE250E09ADA553F94] - |A| - [29/06/2021 13:11:34] - (.-.) - [93.5 Ko] - (0.0.0.0) - C:\WINDOWS\System32\VirtualMonitorManager.dll [MD5.573A9AD45193FC865BBE474F3DD062F1] - |A| - [09/02/2022 23:55:59] - (.Copyright (C) 2015-2021 - Vulkan Loader.) - [1398.73 Ko] - (1.3.198.1) - C:\WINDOWS\System32\vulkan-1-999-0-0-0.dll [MD5.573A9AD45193FC865BBE474F3DD062F1] - |A| - [14/01/2022 17:39:21] - (.Copyright (C) 2015-2021 - Vulkan Loader.) - [1398.73 Ko] - (1.3.198.1) - C:\WINDOWS\System32\vulkan-1.dll [MD5.4C38F34E6AFDB52833FABB8CBAF77A49] - |A| - [09/02/2022 23:55:59] - (.Copyright (C) 2015-2021 - Vulkan Loader.) - [1861.24 Ko] - (1.3.198.1) - C:\WINDOWS\System32\vulkaninfo-1-999-0-0-0.exe [MD5.4C38F34E6AFDB52833FABB8CBAF77A49] - |A| - [09/02/2022 23:55:59] - (.Copyright (C) 2015-2021 - Vulkan Loader.) - [1861.24 Ko] - (1.3.198.1) - C:\WINDOWS\System32\vulkaninfo.exe [MD5.2A2446E35A9747E2CD9AF1552F876281] - |A| - [29/06/2021 12:02:45] - (.Copyright © 1996-2012 - General Library for Plug-Ins.) - [2061.13 Ko] - (4.4.5.0) - C:\WINDOWS\System32\WavesGUILib64.dll [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [148537.82 Ko] - C:\WINDOWS\System32\wbem [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 14:50:22] - [0 Ko] - C:\WINDOWS\System32\WCN [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [175317.29 Ko] - C:\WINDOWS\System32\WDI [MD5.6EDD021A8B6457DDE09DE7B7FA4E8C8B] - |A| - [07/12/2019 09:08:46] - (.-.) - [0.6 Ko] - (0.0.0.0) - C:\WINDOWS\System32\WdsUnattendTemplate.xml [MD5.1D64ACF3675288CC086E6361EAC748C4] - |A| - [07/12/2019 09:08:52] - (.-.) - [144.51 Ko] - (0.0.0.0) - C:\WINDOWS\System32\Win32AppSettingsProvider.dll [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [1.12 Ko] - C:\WINDOWS\System32\WinBioDatabase [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [53500.9 Ko] - C:\WINDOWS\System32\WinBioPlugIns [MD5.3F376202BE6A0EC0C866D97ED2E0F16D] - |A| - [29/06/2021 13:10:49] - (.-.) - [642.05 Ko] - (0.0.0.0) - C:\WINDOWS\System32\WindowManagementAPI.dll [MD5.F325CA18EC8C68871FABE1707C65AFC8] - |A| - [21/01/2022 00:41:21] - (.Copyright © 2021 - Java(TM) Platform SE binary.) - [188.22 Ko] - (8.0.3210.7) - C:\WINDOWS\System32\WindowsAccessBridge-64.dll [MD5.E9CA21D71E952448B75C45B2467E4DE7] - |A| - [07/12/2019 09:08:27] - (.-.) - [123 Ko] - (0.0.0.0) - C:\WINDOWS\System32\WindowsDefaultHeatProcessor.dll [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [12454.18 Ko] - C:\WINDOWS\System32\WindowsPowerShell [MD5.28E98ED0B6B08B7F1D163FFD184B28AF] - |A| - [07/12/2019 09:08:41] - (.-.) - [0.74 Ko] - (0.0.0.0) - C:\WINDOWS\System32\WindowsSecurityIcon.png [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [258676 Ko] - C:\WINDOWS\System32\winevt [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [6281.34 Ko] - C:\WINDOWS\System32\WinMetadata [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 14:50:22] - [207.67 Ko] - C:\WINDOWS\System32\winrm [MD5.1B46E2E85D401A629966A8F62D9B0775] - |A| - [07/12/2019 09:08:12] - (.-.) - [9.91 Ko] - (0.0.0.0) - C:\WINDOWS\System32\wpcatltoast.png [MD5.C30C621748C66CE751B19B2788559A3E] - |A| - [07/12/2019 09:08:12] - (.-.) - [4.58 Ko] - (0.0.0.0) - C:\WINDOWS\System32\wpcmon.png [MD5.69FEC1494F4C454E994D27CA6750832B] - |A| - [07/12/2019 09:08:49] - (.-.) - [0.71 Ko] - (0.0.0.0) - C:\WINDOWS\System32\wpr.config.xml [MD5.C8A7EAA0B83E05DDD11F37A833F754AC] - |A| - [07/12/2019 09:08:21] - (.-.) - [83 Ko] - (0.0.0.0) - C:\WINDOWS\System32\xboxgipsynthetic.dll [MD5.F7B865265606C41B0E07779D3317E0A8] - |A| - [07/12/2019 09:08:39] - (.-.) - [0.61 Ko] - (0.0.0.0) - C:\WINDOWS\System32\X_80.contrast-black.png [MD5.6FF92221AF9D6CDF0966C4E44C367975] - |A| - [07/12/2019 09:08:39] - (.-.) - [0.57 Ko] - (0.0.0.0) - C:\WINDOWS\System32\X_80.contrast-white.png [MD5.F7B865265606C41B0E07779D3317E0A8] - |A| - [07/12/2019 09:08:39] - (.-.) - [0.61 Ko] - (0.0.0.0) - C:\WINDOWS\System32\X_80.png [MD5.D6F8DD9F561B8A67FFAC2BAD7E989770] - |A| - [07/12/2019 09:09:21] - (.-.) - [0.23 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\@AppHelpToast.png [MD5.82C37C3E27020AF6C2E018E944284676] - |A| - [07/12/2019 09:09:21] - (.-.) - [0.3 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\@AudioToastIcon.png [MD5.495C1F072039B434827A5FE0D9761E4D] - |A| - [07/12/2019 09:09:26] - (.-.) - [0.32 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\@EnrollmentToastIcon.png [MD5.1622DE67156496C78D6B7BE9B471645B] - |A| - [07/12/2019 09:09:32] - (.-.) - [0.39 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\@VpnToastIcon.png [MD5.DB71001FC261F6685BE410527DAE3942] - |A| - [07/12/2019 09:09:15] - (.-.) - [0.67 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\@WirelessDisplayToast.png [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [1864.83 Ko] - C:\WINDOWS\SysWOW64\AdvancedInstallers [MD5.E556115BD4E751178310F842E457CA22] - |A| - [29/06/2021 13:11:06] - (.-.) - [10.5 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\agentactivationruntimestarter.exe [MD5.F9622B23868C9A0C0FE7B0874E9BEA8A] - |A| - [29/06/2021 14:04:18] - (.AMD Inc. - AMD Bug Report Tool.) - [2432.25 Ko] - (1.6.0.14) - C:\WINDOWS\SysWOW64\AMDBugReportTool.exe [MD5.D9CC256B6A9920AC8EA7E43A1517A820] - |A| - [17/06/2021 00:37:40] - (.Copyright (c) 2013 - 2021 Advanced Micro Devices, Inc. - amdtee_api dll.) - [348.3 Ko] - (5.17.0.0) - C:\WINDOWS\SysWOW64\amdtee_api.dll [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [0 Ko] - C:\WINDOWS\SysWOW64\AppLocker [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [97.5 Ko] - C:\WINDOWS\SysWOW64\ar-SA [MD5.DD0F04B43362A7C7660C1DF405D416F0] - |A| - [14/01/2022 01:13:06] - (.Copyright (c) libarchive authors - Windows-internal libarchive library.) - [563 Ko] - (3.5.1.0) - C:\WINDOWS\SysWOW64\archiveint.dll [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [58.5 Ko] - C:\WINDOWS\SysWOW64\bg-BG [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [0.1 Ko] - C:\WINDOWS\SysWOW64\Bthprops [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [0 Ko] - C:\WINDOWS\SysWOW64\catroot [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [321.5 Ko] - C:\WINDOWS\SysWOW64\Com [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [7 Ko] - C:\WINDOWS\SysWOW64\config [MD5.00000000000000000000000000000000] - |SD| - [07/12/2019 09:14:52] - [154.3 Ko] - C:\WINDOWS\SysWOW64\Configuration [MD5.6545DE4EF5217AA2FFC7FFD27725A971] - |A| - [29/06/2021 13:11:06] - (.-.) - [235 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\CoreMas.dll [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [118.5 Ko] - C:\WINDOWS\SysWOW64\cs-CZ [MD5.A2F18DAD6F7BE95ED9FC7A37B7D94FF7] - |A| - [14/01/2022 01:13:06] - (.© 1996 - 2021 Daniel Stenberg, . - The curl executable.) - [453.5 Ko] - (7.79.1.0) - C:\WINDOWS\SysWOW64\curl.exe [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [119.5 Ko] - C:\WINDOWS\SysWOW64\da-DK [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [131 Ko] - C:\WINDOWS\SysWOW64\de-DE [MD5.C1684AACAAD62889ACFCA988AA46562D] - |A| - [07/12/2019 09:09:15] - (.-.) - [28.83 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\DefaultAccountTile.png [MD5.00000000000000000000000000000000] - |SD| - [07/12/2019 09:14:52] - [188 Ko] - C:\WINDOWS\SysWOW64\DiagSvcs [MD5.00000000000000000000000000000000] - |D| - [29/06/2021 14:24:26] - [0 Ko] - C:\WINDOWS\SysWOW64\directx [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [7872.55 Ko] - C:\WINDOWS\SysWOW64\Dism [MD5.9E02FBDBB86794441E31031B992F2573] - |A| - [10/07/2021 17:44:51] - (.-.) - [69.5 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\FvSDK_x86.dll [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 14:51:43] - [0 Ko] - C:\WINDOWS\SysWOW64\FxsTmp [MD5.B873A5ABCFBC42B1BAC9EBE8741C6162] - |A| - [07/12/2019 14:51:24] - (.Copyright (C) 2019 - Gracenote SDK component.) - [244 Ko] - (3.9.511.0) - C:\WINDOWS\SysWOW64\gnsdk_fp.dll [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [0 Ko] - C:\WINDOWS\SysWOW64\GroupPolicy [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [0 Ko] - C:\WINDOWS\SysWOW64\GroupPolicyUsers [MD5.DF0C9C776F8367E213210FB256AC30EC] - |A| - [29/06/2021 13:11:10] - (.-.) - [230 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\HeatCore.dll [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [55.5 Ko] - C:\WINDOWS\SysWOW64\hr-HR [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [123 Ko] - C:\WINDOWS\SysWOW64\hu-HU [MD5.AD15BB3A8973A1118386B87289E22322] - |A| - [29/06/2021 13:11:33] - (.-.) - [99.32 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\HvsiManagementApi.dll [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [36.27 Ko] - C:\WINDOWS\SysWOW64\icsxml [MD5.8226A1A91F01432A0CB10CAABF1B9C6D] - |A| - [29/06/2021 13:11:12] - (.Copyright (C) 2016 and later: Unicode, Inc. and others. License & terms of use: http://www.unicode.org/copyright.html - ICU Combined Library.) - [1820.5 Ko] - (64.2.0.0) - C:\WINDOWS\SysWOW64\icu.dll [MD5.FB475B41189AACF1C607C1E9DC0EBB0B] - |RA| - [07/12/2019 09:09:18] - (.Copyright (C) 2016 and later: Unicode, Inc. and others. License & terms of use: http://www.unicode.org/copyright.html - ICU I18N Forwarder DLL.) - [24 Ko] - (64.2.0.0) - C:\WINDOWS\SysWOW64\icuin.dll [MD5.B17445D0DF2C22C924899B5DF8E84475] - |RA| - [07/12/2019 09:09:18] - (.Copyright (C) 2016 and later: Unicode, Inc. and others. License & terms of use: http://www.unicode.org/copyright.html - ICU Common Forwarder DLL.) - [28.5 Ko] - (64.2.0.0) - C:\WINDOWS\SysWOW64\icuuc.dll [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [21637.64 Ko] - C:\WINDOWS\SysWOW64\IME [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [0 Ko] - C:\WINDOWS\SysWOW64\inetsrv [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [215 Ko] - C:\WINDOWS\SysWOW64\InputMethod [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [1160 Ko] - C:\WINDOWS\SysWOW64\InstallShield [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [0 Ko] - C:\WINDOWS\SysWOW64\Ipmi [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [125 Ko] - C:\WINDOWS\SysWOW64\it-IT [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [89 Ko] - C:\WINDOWS\SysWOW64\ja-JP [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [10192.95 Ko] - C:\WINDOWS\SysWOW64\Keywords [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [91 Ko] - C:\WINDOWS\SysWOW64\ko-KR [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [454.91 Ko] - C:\WINDOWS\SysWOW64\Licenses [MD5.21414FD81773E61D9B16A2F6AAF899C1] - |A| - [29/06/2021 14:01:55] - (.-.) - [0.16 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\log.txt [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [0 Ko] - C:\WINDOWS\SysWOW64\LogFiles [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [56.5 Ko] - C:\WINDOWS\SysWOW64\lt-LT [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [56 Ko] - C:\WINDOWS\SysWOW64\lv-LV [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 14:52:40] - [32.68 Ko] - C:\WINDOWS\SysWOW64\MailContactsCalendarSync [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [2864.09 Ko] - C:\WINDOWS\SysWOW64\migration [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [816.8 Ko] - C:\WINDOWS\SysWOW64\migwiz [MD5.08749DCC252AE1148E3BEA32B3FFFBFC] - |A| - [07/12/2019 09:10:14] - (.-.) - [0.11 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\MixedRealityRuntime.json [MD5.C8BF077B236ED2803347BD95DE29BF68] - |A| - [07/12/2019 09:15:00] - (.-.) - [3.03 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\mmc.exe.config [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [45.5 Ko] - C:\WINDOWS\SysWOW64\MSDRM [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [52.28 Ko] - C:\WINDOWS\SysWOW64\Msdtc [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [21.37 Ko] - C:\WINDOWS\SysWOW64\MUI [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [116 Ko] - C:\WINDOWS\SysWOW64\nb-NO [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [0 Ko] - C:\WINDOWS\SysWOW64\NDF [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [51 Ko] - C:\WINDOWS\SysWOW64\networklist [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [122 Ko] - C:\WINDOWS\SysWOW64\nl-NL [MD5.00000000000000000000000000000000] - |SD| - [07/12/2019 09:14:52] - [3781.5 Ko] - C:\WINDOWS\SysWOW64\Nui [MD5.5EB12B036B255FBA366786F31FEABEBD] - |A| - [09/02/2022 23:55:57] - (.-.) - [623.96 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\nvofapi.dll [MD5.B3B9C8925432FDA674ACCA908FE3CFDE] - |A| - [07/12/2019 09:10:14] - (.-.) - [36.79 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\OneDrive.ico [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [773.83 Ko] - C:\WINDOWS\SysWOW64\oobe [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [79.5 Ko] - C:\WINDOWS\SysWOW64\PerceptionSimulation [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [124 Ko] - C:\WINDOWS\SysWOW64\pl-PL [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 14:50:22] - [974.02 Ko] - C:\WINDOWS\SysWOW64\Printing_Admin_Scripts [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [122 Ko] - C:\WINDOWS\SysWOW64\pt-BR [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [123 Ko] - C:\WINDOWS\SysWOW64\pt-PT [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [23.75 Ko] - C:\WINDOWS\SysWOW64\ras [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [0 Ko] - C:\WINDOWS\SysWOW64\RasToast [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [0.82 Ko] - C:\WINDOWS\SysWOW64\Recovery [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [0 Ko] - C:\WINDOWS\SysWOW64\restore [MD5.03944ABAE856DC164BD167526E07E953] - |A| - [28/09/2012 19:45:08] - (.-.) - [241.5 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\rtvcvfw32.dll [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [121.5 Ko] - C:\WINDOWS\SysWOW64\ru-RU [MD5.09DB317084AD30C69391BF95BF44664C] - |A| - [29/06/2021 12:02:45] - (.Copyright (c) 2006-2012 Synopsys, Inc. All Rights Reserved - SRCOM.DLL.) - [333.15 Ko] - (4.0.0.59) - C:\WINDOWS\SysWOW64\SRCOM.dll [MD5.BA7D4E5FAE64BD0403C7F7E91CD93F77] - |A| - [07/12/2019 09:10:05] - (.-.) - [11.03 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\srms-apr-v.dat [MD5.DC9450258D80F46AEF8EF063A7C629B0] - |A| - [07/12/2019 09:10:05] - (.-.) - [19.03 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\srms-apr.dat [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [0 Ko] - C:\WINDOWS\SysWOW64\sru [MD5.BDC53957962AFBEBE6A25EF941C261B3] - |A| - [29/06/2021 13:11:06] - (.-.) - [323 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\ssdm.dll [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [117 Ko] - C:\WINDOWS\SysWOW64\sv-SE [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 14:50:22] - [0 Ko] - C:\WINDOWS\SysWOW64\sysprep [MD5.E1B0E399DABCBCAB7320B4232573431E] - |A| - [23/03/2021 15:57:54] - (.Copyright (c) 2013 - 2021 Advanced Micro Devices, Inc. - t-base_client_api dll.) - [339.7 Ko] - (4.16.0.0) - C:\WINDOWS\SysWOW64\t-base_client_api.dll [MD5.D7128869A4759CCBDC5D4BC55A40D4CC] - |A| - [14/01/2022 01:13:06] - (.Copyright (c) libarchive authors - bsdtar archive tool.) - [43.5 Ko] - (3.5.1.0) - C:\WINDOWS\SysWOW64\tar.exe [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [0 Ko] - C:\WINDOWS\SysWOW64\Tasks [MD5.98330E758D85B4E4AE465BCA2AA779A6] - |A| - [23/03/2021 15:57:58] - (.Copyright (c) 2013 - 2018 Advanced Micro Devices, Inc. - tbaseregistry dll.) - [375.7 Ko] - (4.6.1.1) - C:\WINDOWS\SysWOW64\tbaseregistry32.dll [MD5.1D2D564BC91E46A54533B8ABBEF460DD] - |A| - [17/09/2021 02:24:45] - (.-.) - [1302.5 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\TextInputMethodFormatter.dll [MD5.4C58C812BB19C065CB0ED7FC8FBBAC12] - |A| - [18/10/2021 21:53:58] - (.-.) - [597.62 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\TextShaping.dll [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [50.5 Ko] - C:\WINDOWS\SysWOW64\th-TH [MD5.63A96EFDD0047DC2834925A17098ADFA] - |A| - [14/01/2022 17:02:18] - (.Copyright (C) 2015-2021 - Thrustmaster Flight Control Panel.) - [1659 Ko] - (3.2.0.0) - C:\WINDOWS\SysWOW64\tmhotascpl.dll [MD5.1CA2E8BC68011E59C51E34C5D1C41A7B] - |A| - [18/12/2021 11:59:29] - (.-.) - [218.5 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\TpmTool.exe [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [115 Ko] - C:\WINDOWS\SysWOW64\tr-TR [MD5.01E96A85B337B702AE2BC7F838AE7B65] - |A| - [07/12/2019 09:10:22] - (.-.) - [3.34 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\UevCustomActionTypes.tlb [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [57 Ko] - C:\WINDOWS\SysWOW64\uk-UA [MD5.7E0273A51BDD51DFB58F905C8F501061] - |A| - [29/06/2021 13:11:12] - (.-.) - [46.36 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\umpdc.dll [MD5.AB77E34564667CAA737328F192019663] - |A| - [09/02/2022 23:55:59] - (.Copyright (C) 2015-2021 - Vulkan Loader.) - [1118.74 Ko] - (1.3.198.1) - C:\WINDOWS\SysWOW64\vulkan-1-999-0-0-0.dll [MD5.AB77E34564667CAA737328F192019663] - |A| - [09/02/2022 23:55:59] - (.Copyright (C) 2015-2021 - Vulkan Loader.) - [1118.74 Ko] - (1.3.198.1) - C:\WINDOWS\SysWOW64\vulkan-1.dll [MD5.5AA2926C71E4353011FF971434505C28] - |A| - [09/02/2022 23:55:59] - (.Copyright (C) 2015-2021 - Vulkan Loader.) - [1443.74 Ko] - (1.3.198.1) - C:\WINDOWS\SysWOW64\vulkaninfo-1-999-0-0-0.exe [MD5.5AA2926C71E4353011FF971434505C28] - |A| - [09/02/2022 23:55:59] - (.Copyright (C) 2015-2021 - Vulkan Loader.) - [1443.74 Ko] - (1.3.198.1) - C:\WINDOWS\SysWOW64\vulkaninfo.exe [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [25870.54 Ko] - C:\WINDOWS\SysWOW64\wbem [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 14:50:22] - [0 Ko] - C:\WINDOWS\SysWOW64\WCN [MD5.A22B636328327A4EA6F6AB3F48A5B5B1] - |A| - [29/06/2021 13:11:11] - (.-.) - [457.46 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\WindowManagementAPI.dll [MD5.BEDEDB102316C696D36F0D4331E1C2AE] - |A| - [07/12/2019 09:09:17] - (.-.) - [104.5 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\WindowsDefaultHeatProcessor.dll [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [10969.85 Ko] - C:\WINDOWS\SysWOW64\WindowsPowerShell [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [6281.07 Ko] - C:\WINDOWS\SysWOW64\WinMetadata [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 14:50:22] - [207.67 Ko] - C:\WINDOWS\SysWOW64\winrm [MD5.7A015A6F199516A06C5AFB56FEE7AC51] - |A| - [07/12/2019 09:09:17] - (.-.) - [59 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\xboxgipsynthetic.dll [MD5.00000000000000000000000000000000] - |D| - [29/06/2021 13:06:50] - [10.16 Ko] - C:\WINDOWS\SysWOW64\XPSViewer [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [82 Ko] - C:\WINDOWS\SysWOW64\zh-CN [MD5.00000000000000000000000000000000] - |D| - [07/12/2019 09:14:52] - [82 Ko] - C:\WINDOWS\SysWOW64\zh-TW ---------- | [gband] [21/12/2021 13:37:07] - |D| - [4] - C:\Users\gband\.guna [20/10/2021 15:59:16] - |D| - [0] - C:\Users\gband\.QtWebEngineProcess [29/06/2021 13:55:02] - |RD| - [298] - C:\Users\gband\3D Objects [10/07/2021 17:46:20] - |D| - [0] - C:\Users\gband\ansel [29/06/2021 13:52:31] - |HD| - [21411560791] - C:\Users\gband\AppData [29/06/2021 13:52:31] - |SHD| - [0] - C:\Users\gband\Application Data [29/06/2021 13:55:02] - |RD| - [412] - C:\Users\gband\Contacts [29/06/2021 13:52:31] - |SHD| - [0] - C:\Users\gband\Cookies [29/06/2021 13:52:31] - |RD| - [7562469] - C:\Users\gband\Desktop [29/06/2021 13:52:31] - |RD| - [23852598579] - C:\Users\gband\Documents [29/06/2021 13:52:31] - |RD| - [44677046450] - C:\Users\gband\Downloads [29/06/2021 13:52:31] - |RD| - [690] - C:\Users\gband\Favorites [29/06/2021 13:52:31] - |RD| - [1945] - C:\Users\gband\Links [29/06/2021 13:52:31] - |SHD| - [0] - C:\Users\gband\Local Settings [29/06/2021 13:52:31] - |SHD| - [0] - C:\Users\gband\Menu Démarrer [29/06/2021 13:52:31] - |SHD| - [0] - C:\Users\gband\Mes documents [29/06/2021 13:52:31] - |SHD| - [0] - C:\Users\gband\Modèles [29/06/2021 13:52:31] - |RD| - [52607065] - C:\Users\gband\Music [29/06/2021 13:52:31] - |AH| - [4194304] - C:\Users\gband\NTUSER.DAT [29/06/2021 13:52:31] - |ASH| - [1057792] - C:\Users\gband\ntuser.dat.LOG1 [29/06/2021 13:52:31] - |ASH| - [385024] - C:\Users\gband\ntuser.dat.LOG2 [29/06/2021 13:52:31] - |ASH| - [65536] - C:\Users\gband\NTUSER.DAT{457e8c6c-d8d4-11eb-ab8a-04d9f583b9cc}.TM.blf [29/06/2021 13:52:31] - |ASH| - [524288] - C:\Users\gband\NTUSER.DAT{457e8c6c-d8d4-11eb-ab8a-04d9f583b9cc}.TMContainer00000000000000000001.regtrans-ms [29/06/2021 13:52:31] - |ASH| - [524288] - C:\Users\gband\NTUSER.DAT{457e8c6c-d8d4-11eb-ab8a-04d9f583b9cc}.TMContainer00000000000000000002.regtrans-ms [29/06/2021 13:52:31] - |SH| - [20] - C:\Users\gband\ntuser.ini [29/06/2021 13:56:34] - |RAD| - [197737930] - C:\Users\gband\OneDrive [29/06/2021 13:52:31] - |RD| - [459432677] - C:\Users\gband\Pictures [29/06/2021 13:52:31] - |SHD| - [0] - C:\Users\gband\Recent [29/06/2021 13:52:31] - |RD| - [121229484] - C:\Users\gband\Saved Games [29/06/2021 13:55:02] - |RD| - [1864] - C:\Users\gband\Searches [29/06/2021 13:52:31] - |SHD| - [0] - C:\Users\gband\SendTo [18/11/2021 20:08:31] - |D| - [16384] - C:\Users\gband\Tracing [29/06/2021 13:52:31] - |RD| - [28313035] - C:\Users\gband\Videos [29/06/2021 13:52:31] - |SHD| - [0] - C:\Users\gband\Voisinage d'impression [29/06/2021 13:52:31] - |SHD| - [0] - C:\Users\gband\Voisinage réseau [29/06/2021 13:52:31] - |D| - [10663109216] - C:\Users\gband\AppData\Local [29/06/2021 13:52:31] - |D| - [19478918] - C:\Users\gband\AppData\LocalLow [29/06/2021 13:52:31] - |D| - [10728961959] - C:\Users\gband\AppData\Roaming [01/12/2021 23:08:40] - |D| - [14363750] - C:\Users\gband\AppData\Local\.marble [29/08/2021 09:45:39] - |D| - [718] - C:\Users\gband\AppData\Local\A [22/11/2021 15:28:49] - |D| - [5848] - C:\Users\gband\AppData\Local\AIGTech [12/07/2021 21:55:03] - |D| - [27284104] - C:\Users\gband\AppData\Local\AirTool [29/06/2021 13:55:05] - |D| - [37949884] - C:\Users\gband\AppData\Local\AMD [29/06/2021 14:00:21] - |D| - [11965] - C:\Users\gband\AppData\Local\AMD_Common [29/06/2021 13:52:31] - |SHD| - [0] - C:\Users\gband\AppData\Local\Application Data [29/06/2021 16:15:17] - |D| - [709263884] - C:\Users\gband\AppData\Local\Apps [29/06/2021 17:13:23] - |D| - [8000] - C:\Users\gband\AppData\Local\ATI [07/02/2022 23:53:05] - |D| - [347] - C:\Users\gband\AppData\Local\Bijan_Seasons [12/09/2021 01:07:13] - |D| - [543172] - C:\Users\gband\AppData\Local\BitTorrentHelper [29/06/2021 14:01:14] - |D| - [339108] - C:\Users\gband\AppData\Local\cache [14/09/2021 02:24:17] - |D| - [40787] - C:\Users\gband\AppData\Local\CD Projekt Red [29/06/2021 14:06:01] - |D| - [2997199] - C:\Users\gband\AppData\Local\CEF [02/09/2021 23:21:52] - |D| - [94983534] - C:\Users\gband\AppData\Local\CLO [26/01/2022 03:07:48] - |D| - [550] - C:\Users\gband\AppData\Local\Colossal Order [29/06/2021 14:12:24] - |D| - [21716996] - C:\Users\gband\AppData\Local\Comms [29/06/2021 13:55:02] - |D| - [7264909] - C:\Users\gband\AppData\Local\ConnectedDevicesPlatform [11/01/2022 02:06:56] - |D| - [1155] - C:\Users\gband\AppData\Local\Copyright_©_FS2Crew_2021 [10/07/2021 21:24:44] - |D| - [815084449] - C:\Users\gband\AppData\Local\CrashDumps [29/06/2021 13:55:03] - |D| - [8596096] - C:\Users\gband\AppData\Local\D3DSCache [29/06/2021 16:15:17] - |D| - [0] - C:\Users\gband\AppData\Local\Deployment [24/11/2021 13:48:39] - |D| - [0] - C:\Users\gband\AppData\Local\Diagnostics [13/07/2021 17:34:05] - |D| - [372645622] - C:\Users\gband\AppData\Local\Discord [18/07/2021 20:15:52] - |D| - [14776320] - C:\Users\gband\AppData\Local\Downloaded Installations [29/06/2021 14:19:37] - |D| - [0] - C:\Users\gband\AppData\Local\ElevatedDiagnostics [24/08/2021 22:28:11] - |D| - [173255167] - C:\Users\gband\AppData\Local\fbw-installer-updater [01/08/2021 21:34:44] - |D| - [0] - C:\Users\gband\AppData\Local\fbw_installer [20/10/2021 16:47:36] - |D| - [3222] - C:\Users\gband\AppData\Local\FIFA Editor Tool [29/06/2021 16:22:21] - |D| - [736200] - C:\Users\gband\AppData\Local\FlightSimulator [11/07/2021 11:14:04] - |D| - [66397698] - C:\Users\gband\AppData\Local\GMap.NET [14/09/2021 02:23:53] - |D| - [2401] - C:\Users\gband\AppData\Local\GOG.com [29/06/2021 14:35:21] - |D| - [956618289] - C:\Users\gband\AppData\Local\Google [29/06/2021 13:52:31] - |SHD| - [0] - C:\Users\gband\AppData\Local\Historique [29/06/2021 14:43:00] - |AH| - [134186] - C:\Users\gband\AppData\Local\IconCache.db [24/09/2021 23:35:40] - |D| - [6959] - C:\Users\gband\AppData\Local\IsolatedStorage [24/09/2021 23:19:17] - |D| - [30230] - C:\Users\gband\AppData\Local\LukeAirTool_LTD [29/06/2021 13:52:31] - |D| - [571990086] - C:\Users\gband\AppData\Local\Microsoft [02/01/2022 22:09:40] - |D| - [4391] - C:\Users\gband\AppData\Local\mkcert [23/10/2021 10:12:33] - |D| - [57345008] - C:\Users\gband\AppData\Local\molotov-updater [02/01/2022 22:09:17] - |D| - [95561374] - C:\Users\gband\AppData\Local\msfs2020-electron-updater [03/01/2022 17:38:21] - |D| - [208360124] - C:\Users\gband\AppData\Local\msfs2020-map-enhancement-updater [29/06/2021 16:16:56] - |D| - [207766196] - C:\Users\gband\AppData\Local\navigraph-desktop-updater [29/06/2021 16:06:06] - |D| - [177379988] - C:\Users\gband\AppData\Local\navigraph_charts-updater [10/07/2021 17:46:15] - |D| - [1355284430] - C:\Users\gband\AppData\Local\NVIDIA [10/07/2021 17:46:16] - |D| - [115838109] - C:\Users\gband\AppData\Local\NVIDIA Corporation [18/08/2021 11:49:12] - |D| - [56044] - C:\Users\gband\AppData\Local\OneDrive [01/12/2021 22:50:06] - |D| - [6099312] - C:\Users\gband\AppData\Local\Opera Software [06/12/2021 04:47:09] - |D| - [82639982] - C:\Users\gband\AppData\Local\orbx-central-updater [29/06/2021 13:55:02] - |D| - [131368029] - C:\Users\gband\AppData\Local\Packages [12/07/2021 21:19:32] - |D| - [1023116] - C:\Users\gband\AppData\Local\PACX [08/10/2021 21:12:16] - |D| - [11778354] - C:\Users\gband\AppData\Local\PCHealthCheck [29/06/2021 16:07:00] - |D| - [0] - C:\Users\gband\AppData\Local\PeerDistRepub [30/06/2021 20:29:37] - |D| - [829680] - C:\Users\gband\AppData\Local\PilotUI [29/06/2021 13:56:59] - |D| - [38697] - C:\Users\gband\AppData\Local\PlaceholderTileLogoFolder [03/07/2021 08:52:01] - |D| - [700] - C:\Users\gband\AppData\Local\PMDG [10/10/2021 02:17:20] - |D| - [3432] - C:\Users\gband\AppData\Local\Premier_Virtual_Airlines [29/06/2021 15:19:28] - |D| - [2716904114] - C:\Users\gband\AppData\Local\Programs [29/06/2021 13:55:06] - |D| - [1080973] - C:\Users\gband\AppData\Local\Publishers [01/07/2021 00:02:19] - |D| - [719] - C:\Users\gband\AppData\Local\PushbackExpress [29/06/2021 14:00:13] - |D| - [131896] - C:\Users\gband\AppData\Local\RadeonInstaller [14/09/2021 02:23:50] - |D| - [26912605] - C:\Users\gband\AppData\Local\REDEngine [29/06/2021 14:01:00] - |D| - [442836] - C:\Users\gband\AppData\Local\setup [21/10/2021 16:10:04] - |D| - [125136256] - C:\Users\gband\AppData\Local\simbrief-downloader-updater [07/02/2022 02:47:59] - |D| - [807153221] - C:\Users\gband\AppData\Local\simtoolkitpro [12/09/2021 12:51:29] - |D| - [2350531] - C:\Users\gband\AppData\Local\Siren [11/07/2021 11:14:04] - |D| - [85540] - C:\Users\gband\AppData\Local\speech [29/06/2021 15:59:04] - |D| - [29238] - C:\Users\gband\AppData\Local\SquirrelTemp [29/06/2021 14:06:01] - |D| - [164811529] - C:\Users\gband\AppData\Local\Steam [29/06/2021 13:52:31] - |D| - [327648669] - C:\Users\gband\AppData\Local\Temp [29/06/2021 13:52:31] - |SHD| - [0] - C:\Users\gband\AppData\Local\Temporary Internet Files [17/10/2021 08:25:38] - |D| - [3627] - C:\Users\gband\AppData\Local\Ubisoft Game Launcher [12/09/2021 12:51:29] - |D| - [50] - C:\Users\gband\AppData\Local\UnrealEngine [12/09/2021 01:04:59] - |D| - [3196] - C:\Users\gband\AppData\Local\UTW008 [18/12/2021 12:38:59] - |D| - [2100] - C:\Users\gband\AppData\Local\V1_Software [21/07/2021 22:33:15] - |D| - [31995198] - C:\Users\gband\AppData\Local\VASystem [29/06/2021 13:55:02] - |D| - [0] - C:\Users\gband\AppData\Local\VirtualStore [06/02/2022 17:44:13] - |D| - [85954441] - C:\Users\gband\AppData\Local\volanta-updater [01/08/2021 10:54:54] - |D| - [24034235] - C:\Users\gband\AppData\Local\vPilot [06/12/2021 00:20:46] - |D| - [799] - C:\Users\gband\AppData\Local\_ [06/07/2021 23:09:14] - |D| - [0] - C:\Users\gband\AppData\LocalLow\AMD [12/09/2021 01:40:58] - |D| - [0] - C:\Users\gband\AppData\LocalLow\Blazing Griffin [29/06/2021 13:55:04] - |SD| - [765347] - C:\Users\gband\AppData\LocalLow\Microsoft [01/02/2022 06:02:57] - |D| - [18549016] - C:\Users\gband\AppData\LocalLow\NotGames [06/02/2022 12:47:54] - |D| - [145408] - C:\Users\gband\AppData\LocalLow\Oracle [21/01/2022 00:41:03] - |D| - [19147] - C:\Users\gband\AppData\LocalLow\Sun [15/08/2021 00:27:50] - |D| - [0] - C:\Users\gband\AppData\Roaming\A [01/12/2021 23:08:34] - |D| - [1101876017] - C:\Users\gband\AppData\Roaming\ABarthel [29/06/2021 13:55:02] - |D| - [0] - C:\Users\gband\AppData\Roaming\Adobe [18/07/2021 19:45:55] - |D| - [922] - C:\Users\gband\AppData\Roaming\AILG_MSFS [18/12/2021 12:26:14] - |D| - [139460696] - C:\Users\gband\AppData\Roaming\AirHauler2FS [29/06/2021 14:01:16] - |D| - [320086378] - C:\Users\gband\AppData\Roaming\AMD [11/10/2021 21:49:00] - |D| - [0] - C:\Users\gband\AppData\Roaming\CPY_SAVES [13/07/2021 17:34:08] - |D| - [190872477] - C:\Users\gband\AppData\Roaming\discord [12/09/2021 02:00:41] - |D| - [29] - C:\Users\gband\AppData\Roaming\DOGE [01/07/2021 12:48:37] - |D| - [6520] - C:\Users\gband\AppData\Roaming\DS4Windows [12/09/2021 02:30:09] - |D| - [846] - C:\Users\gband\AppData\Roaming\EMPRESS [18/07/2021 20:19:06] - |D| - [57] - C:\Users\gband\AppData\Roaming\Flight Sim Technologies [12/09/2021 01:40:59] - |D| - [177] - C:\Users\gband\AppData\Roaming\FLT [02/01/2022 22:47:57] - |D| - [154269239] - C:\Users\gband\AppData\Roaming\FlyByWire Installer [18/01/2022 00:46:58] - |D| - [1834] - C:\Users\gband\AppData\Roaming\FS2Crew Pushback Express [12/09/2021 02:30:44] - |D| - [463008] - C:\Users\gband\AppData\Roaming\Goldberg UplayEmu Saves [18/07/2021 20:09:14] - |D| - [177126133] - C:\Users\gband\AppData\Roaming\InsideSystems [05/12/2021 19:16:07] - |D| - [28] - C:\Users\gband\AppData\Roaming\IObit [12/09/2021 01:59:57] - |D| - [1907] - C:\Users\gband\AppData\Roaming\Kalypso Media [12/07/2021 21:53:04] - |D| - [7130779] - C:\Users\gband\AppData\Roaming\launcher [02/09/2021 22:32:43] - |D| - [16033009] - C:\Users\gband\AppData\Roaming\Maxon [29/06/2021 13:52:31] - |SD| - [3797181] - C:\Users\gband\AppData\Roaming\Microsoft [17/01/2022 23:42:51] - |D| - [2317946903] - C:\Users\gband\AppData\Roaming\Microsoft Flight Simulator [02/01/2022 22:09:20] - |D| - [582365] - C:\Users\gband\AppData\Roaming\msfs2020-electron [03/01/2022 17:38:26] - |D| - [312912016] - C:\Users\gband\AppData\Roaming\msfs2020-map-enhancement [29/06/2021 16:07:11] - |D| - [304329370] - C:\Users\gband\AppData\Roaming\Navigraph [29/06/2021 16:17:18] - |D| - [396364966] - C:\Users\gband\AppData\Roaming\navigraph-desktop [29/06/2021 16:07:30] - |D| - [155363065] - C:\Users\gband\AppData\Roaming\navigraph_charts [02/09/2021 23:22:46] - |D| - [0] - C:\Users\gband\AppData\Roaming\NVIDIA [01/12/2021 22:49:36] - |D| - [39267583] - C:\Users\gband\AppData\Roaming\Opera Software [06/12/2021 04:47:15] - |D| - [2571496620] - C:\Users\gband\AppData\Roaming\Orbx [11/07/2021 11:12:25] - |D| - [494803] - C:\Users\gband\AppData\Roaming\P2A_200 [04/08/2021 00:08:36] - |D| - [505428610] - C:\Users\gband\AppData\Roaming\Parallel 42 [03/07/2021 08:38:33] - |D| - [493889337] - C:\Users\gband\AppData\Roaming\PMDG [18/07/2021 19:47:14] - |D| - [1061] - C:\Users\gband\AppData\Roaming\PPG_MSFS [14/07/2021 00:43:09] - |D| - [82404587] - C:\Users\gband\AppData\Roaming\SimBrief Downloader [07/02/2022 02:48:11] - |D| - [412061336] - C:\Users\gband\AppData\Roaming\simtoolkitpro [04/08/2021 00:09:19] - |D| - [0] - C:\Users\gband\AppData\Roaming\Skypad [21/01/2022 00:41:25] - |D| - [0] - C:\Users\gband\AppData\Roaming\Sun [19/07/2021 00:16:04] - |D| - [993512105] - C:\Users\gband\AppData\Roaming\Telegram Desktop [12/07/2021 21:16:40] - |D| - [4869120] - C:\Users\gband\AppData\Roaming\TFDi Design [12/09/2021 01:06:30] - |D| - [26913594] - C:\Users\gband\AppData\Roaming\uTorrent Web [21/07/2021 22:34:21] - |D| - [0] - C:\Users\gband\AppData\Roaming\VAS ACARS [06/02/2022 17:44:15] - |D| - [0] - C:\Users\gband\AppData\Roaming\Volanta [29/06/2021 13:55:02] - |SH| - [174] - C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini [03/07/2021 08:38:30] - |A| - [1304] - C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\PMDG Operations Center v2.lnk [29/06/2021 13:52:31] - |SHD| - [0] - C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programmes [29/06/2021 13:52:31] - |RD| - [104271] - C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs [29/06/2021 13:52:31] - |RD| - [3888] - C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility [29/06/2021 13:52:31] - |RD| - [1670] - C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories [29/06/2021 13:55:02] - |RD| - [174] - C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools [18/08/2021 01:54:11] - |D| - [2673] - C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Applications Chrome [29/06/2021 13:52:31] - |SH| - [420] - C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\desktop.ini [13/07/2021 17:34:09] - |D| - [2237] - C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Discord Inc [02/01/2022 22:47:56] - |A| - [2519] - C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FlyByWire Installer.lnk [29/06/2021 15:59:09] - |D| - [0] - C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FlyByWire Simulations [02/07/2021 23:13:17] - |D| - [2194] - C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Football Manager 2021 [07/02/2022 02:48:10] - |D| - [2310] - C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GitHub [29/06/2021 13:52:31] - |D| - [170] - C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance [29/06/2021 14:23:41] - |D| - [7623] - C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MSI Afterburner [28/01/2022 02:24:44] - |D| - [2445] - C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Navigraph [28/01/2022 02:24:31] - |D| - [2543] - C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Navigraph Navdata Center [24/09/2021 23:30:27] - |D| - [328] - C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NeoFly [24/01/2022 18:10:40] - |D| - [511] - C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OnAir Company [29/06/2021 13:52:31] - |A| - [2413] - C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk [06/12/2021 04:47:09] - |A| - [2417] - C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Orbx Central.lnk [08/10/2021 21:12:16] - |A| - [1341] - C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PC Health Check.lnk [03/07/2021 21:58:22] - |D| - [342] - C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Premier Virtual Airlines [29/06/2021 14:24:21] - |D| - [8073] - C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RivaTuner Statistics Server [29/06/2021 14:40:09] - |A| - [3057] - C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Self-Loading Cargo.lnk [14/07/2021 00:43:11] - |A| - [2513] - C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SimBrief Downloader.lnk [07/02/2022 02:48:09] - |D| - [2377] - C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SimToolkitPro [01/02/2022 18:04:37] - |A| - [1300] - C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Sky4Sim Pad.lnk [31/01/2022 13:05:34] - |D| - [473] - C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\skyalliance-va.com [29/06/2021 13:55:02] - |RD| - [174] - C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup [29/06/2021 14:08:54] - |D| - [1219] - C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam [29/06/2021 13:52:31] - |RD| - [4913] - C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools [19/07/2021 00:16:06] - |D| - [2225] - C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Telegram Desktop [18/01/2022 02:21:35] - |D| - [1331] - C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TFDi Design [17/10/2021 08:25:38] - |D| - [4831] - C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft [12/09/2021 01:06:31] - |A| - [1865] - C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\uTorrent Web.lnk [21/07/2021 22:34:20] - |D| - [2425] - C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VASystem [30/12/2021 19:05:50] - |A| - [1132] - C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Virtual E6-B.LNK [06/02/2022 17:44:14] - |A| - [2325] - C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Volanta.lnk [01/08/2021 10:54:55] - |D| - [20233] - C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\vPilot [29/06/2021 13:52:31] - |D| - [5078] - C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell [06/01/2022 13:40:00] - |D| - [509] - C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\www.fseconomy.net [29/06/2021 13:55:02] - |SH| - [174] - C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini ---------- | [Public] [29/06/2021 13:55:02] - |RHD| - [82507] - C:\Users\Public\AccountPictures [07/12/2019 09:14:52] - |RHD| - [27940] - C:\Users\Public\Desktop [07/12/2019 09:14:54] - |ASH| - [174] - C:\Users\Public\desktop.ini [07/12/2019 09:14:52] - |RD| - [597739800] - C:\Users\Public\Documents [07/12/2019 09:14:52] - |RD| - [174] - C:\Users\Public\Downloads [07/12/2019 09:14:52] - |RHD| - [1174] - C:\Users\Public\Libraries [07/12/2019 09:14:52] - |RD| - [380] - C:\Users\Public\Music [07/12/2019 09:14:52] - |RD| - [380] - C:\Users\Public\Pictures [07/12/2019 09:14:52] - |RD| - [380] - C:\Users\Public\Videos ---------- | C:\ProgramData [22/11/2021 15:29:14] - |D| - [876919408] - C:\ProgramData\AIGTech [29/06/2021 14:00:13] - |D| - [5725] - C:\ProgramData\AMD [29/06/2021 12:19:56] - |SHD| - [0] - C:\ProgramData\Application Data [29/06/2021 12:19:56] - |SHD| - [0] - C:\ProgramData\Bureau [01/08/2021 22:59:23] - |D| - [2405172] - C:\ProgramData\Caphyon [29/06/2021 12:19:56] - |SHD| - [0] - C:\ProgramData\Documents [29/06/2021 12:18:13] - |AH| - [0] - C:\ProgramData\DP45977C.lfl [20/10/2021 16:12:50] - |D| - [6818] - C:\ProgramData\Electronic Arts [30/09/2021 01:45:25] - |D| - [47618602] - C:\ProgramData\KONAMI [29/06/2021 12:19:56] - |SHD| - [0] - C:\ProgramData\Menu Démarrer [07/12/2019 09:14:52] - |SD| - [2891304589] - C:\ProgramData\Microsoft [29/06/2021 13:56:21] - |D| - [25] - C:\ProgramData\Microsoft OneDrive [29/06/2021 12:19:56] - |SHD| - [0] - C:\ProgramData\Modèles [29/06/2021 15:38:00] - |D| - [2798] - C:\ProgramData\MSFS Addons Linker [29/06/2021 16:06:59] - |D| - [174688] - C:\ProgramData\Navigraph [24/09/2021 23:30:36] - |D| - [155606314] - C:\ProgramData\NeoFly [10/07/2021 17:44:38] - |D| - [368945957] - C:\ProgramData\NVIDIA [10/07/2021 17:44:39] - |D| - [1628398582] - C:\ProgramData\NVIDIA Corporation [18/07/2021 20:09:13] - |D| - [82552033] - C:\ProgramData\Oracle [10/02/2022 12:01:48] - |D| - [5778] - C:\ProgramData\Origin [29/06/2021 14:00:49] - |D| - [101737530] - C:\ProgramData\Package Cache [29/06/2021 13:55:04] - |D| - [188416] - C:\ProgramData\Packages [02/09/2021 22:31:04] - |D| - [1617] - C:\ProgramData\Red Giant [07/12/2019 09:14:52] - |D| - [999] - C:\ProgramData\regid.1991-06.com.microsoft [29/06/2021 16:23:14] - |D| - [7045] - C:\ProgramData\SLC [07/12/2019 09:14:52] - |D| - [0] - C:\ProgramData\SoftwareDistribution [29/06/2021 13:13:51] - |D| - [0] - C:\ProgramData\ssh [17/10/2021 08:25:44] - |D| - [0] - C:\ProgramData\Ubisoft [07/12/2019 09:14:52] - |D| - [8368128] - C:\ProgramData\USOPrivate [07/12/2019 09:14:52] - |D| - [10600448] - C:\ProgramData\USOShared [07/12/2019 14:53:51] - |D| - [0] - C:\ProgramData\WindowsHolographicDevices ---------- | C:\ProgramData\Microsoft\Windows\Start Menu [07/12/2019 09:14:54] - |ASH| - [174] - C:\ProgramData\Microsoft\Windows\Start Menu\desktop.ini [29/06/2021 12:19:56] - |SHD| - [0] - C:\ProgramData\Microsoft\Windows\Start Menu\Programmes [07/12/2019 09:14:52] - |RD| - [111532] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs ---------- | C:\ProgramData\Microsoft\Windows\Start Menu\Programs [29/06/2021 15:11:10] - |D| - [1971] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip [07/12/2019 09:14:52] - |RD| - [1614] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility [07/12/2019 09:14:52] - |RD| - [14467] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories [07/12/2019 09:14:52] - |RD| - [25497] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools [06/07/2021 23:07:35] - |D| - [1874] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Bug Report Tool [06/07/2021 23:07:35] - |D| - [2092] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Link For Windows [06/07/2021 23:07:30] - |D| - [2125] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Radeon Software [10/02/2022 12:14:49] - |D| - [2719] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battlefield™ V [07/02/2022 23:52:25] - |D| - [2667] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bijan Season [07/12/2019 09:14:54] - |ASH| - [400] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\desktop.ini [20/01/2022 16:53:33] - |A| - [1278] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Flight Simulator First Officer Next.lnk [30/01/2022 01:09:39] - |D| - [1241] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FS2Crew Pushback Express [29/06/2021 14:35:55] - |A| - [2245] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk [07/12/2019 09:10:31] - |RAS| - [2349] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Immersive Control Panel.lnk [21/01/2022 00:41:21] - |D| - [6752] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java [07/12/2019 09:14:52] - |D| - [170] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance [29/06/2021 12:18:00] - |A| - [2442] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk [02/02/2022 22:38:32] - |A| - [2218] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MSFS2020 Map Enhancement.lnk [29/06/2021 16:06:59] - |D| - [2586] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Navigraph FMS Data Manager [29/06/2021 16:07:10] - |A| - [1038] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Navigraph Simlink.lnk [10/07/2021 17:44:50] - |D| - [1457] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation [31/01/2022 13:40:51] - |D| - [1102] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\opentrack [12/07/2021 21:19:36] - |A| - [1177] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PACX User Guide.lnk [12/07/2021 21:19:36] - |A| - [1178] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PACX.lnk [30/01/2022 02:21:59] - |D| - [1537] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Pilot2ATC_2020_x64 [06/02/2022 18:31:14] - |D| - [1951] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RealTraffic Launcher [30/08/2021 22:46:27] - |D| - [3414] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller [01/08/2021 23:27:49] - |D| - [0] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\REX 6 [01/08/2021 22:59:22] - |D| - [1947] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\REX Game Studios [12/01/2022 01:28:35] - |D| - [3441] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\REX Weather Force 2020 [22/01/2022 01:24:38] - |D| - [7477] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SimMarket [07/12/2019 09:14:52] - |RD| - [174] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp [29/06/2021 14:04:55] - |D| - [1104] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam [07/12/2019 09:14:52] - |RD| - [1458] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools [14/01/2022 17:02:18] - |D| - [3570] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Thrustmaster TM Flight Series [07/12/2019 14:53:04] - |RD| - [2800] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows PowerShell ---------- | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup [07/12/2019 09:14:54] - |ASH| - [174] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini ---------- | C:\Program Files (x86) [29/06/2021 15:11:10] - |D| - [3863487] - C:\Program Files (x86)\7-Zip [29/06/2021 14:01:31] - |D| - [117554877] - C:\Program Files (x86)\AMD [07/02/2022 23:52:25] - |D| - [3365888] - C:\Program Files (x86)\Bijan Season [07/12/2019 09:14:52] - |D| - [148868988] - C:\Program Files (x86)\Common Files [07/12/2019 09:14:54] - |ASH| - [174] - C:\Program Files (x86)\desktop.ini [20/01/2022 16:53:00] - |D| - [462833251] - C:\Program Files (x86)\Flight Simulator First Officer Next [18/01/2022 00:47:04] - |D| - [40102001] - C:\Program Files (x86)\FS2Crew Command Center [22/01/2022 17:10:48] - |D| - [3635258] - C:\Program Files (x86)\FSAirlines [29/06/2021 14:35:24] - |D| - [33818440] - C:\Program Files (x86)\Google [14/01/2022 17:02:18] - |D| - [3999804] - C:\Program Files (x86)\Guillemot [14/01/2022 17:02:18] - |HD| - [5628761] - C:\Program Files (x86)\InstallShield Installation Information [07/12/2019 09:14:52] - |D| - [2028111] - C:\Program Files (x86)\Internet Explorer [29/06/2021 14:40:08] - |D| - [341842134] - C:\Program Files (x86)\Lanilogic [29/06/2021 13:14:00] - |D| - [937262430] - C:\Program Files (x86)\Microsoft [11/07/2021 11:12:51] - |D| - [1335746] - C:\Program Files (x86)\Microsoft SQL Server [07/12/2019 09:14:52] - |D| - [23935] - C:\Program Files (x86)\Microsoft.NET [29/06/2021 13:06:49] - |D| - [25757] - C:\Program Files (x86)\MSBuild [29/06/2021 14:23:33] - |D| - [71858229] - C:\Program Files (x86)\MSI Afterburner [29/06/2021 16:06:58] - |D| - [53233983] - C:\Program Files (x86)\Navigraph [10/07/2021 17:44:43] - |D| - [288393057] - C:\Program Files (x86)\NVIDIA Corporation [31/01/2022 13:40:45] - |D| - [116227097] - C:\Program Files (x86)\opentrack [18/01/2022 00:46:58] - |D| - [111534469] - C:\Program Files (x86)\Pushback Express MSFS [29/06/2021 13:04:44] - |D| - [5791304] - C:\Program Files (x86)\Razer [29/06/2021 13:06:49] - |D| - [38479105] - C:\Program Files (x86)\Reference Assemblies [29/06/2021 14:24:17] - |D| - [64813335] - C:\Program Files (x86)\RivaTuner Statistics Server [17/01/2022 22:50:40] - |D| - [226389188] - C:\Program Files (x86)\SimMarket [18/01/2022 02:21:30] - |D| - [180400659] - C:\Program Files (x86)\smartCARS [29/06/2021 14:04:54] - |D| - [2111031621] - C:\Program Files (x86)\Steam [12/07/2021 21:19:31] - |D| - [380052039] - C:\Program Files (x86)\TFDi Design [17/10/2021 08:25:36] - |D| - [300913297] - C:\Program Files (x86)\Ubisoft [30/12/2021 19:05:50] - |D| - [379719] - C:\Program Files (x86)\Virtual E6-B [07/12/2019 09:14:52] - |D| - [1996064] - C:\Program Files (x86)\Windows Defender [07/12/2019 09:14:52] - |D| - [625664] - C:\Program Files (x86)\Windows Mail [07/12/2019 14:53:51] - |D| - [3465069] - C:\Program Files (x86)\Windows Media Player [07/12/2019 14:53:51] - |D| - [40232] - C:\Program Files (x86)\Windows Multimedia Platform [07/12/2019 09:14:52] - |D| - [6329176] - C:\Program Files (x86)\Windows NT [07/12/2019 14:53:51] - |D| - [5400512] - C:\Program Files (x86)\Windows Photo Viewer [07/12/2019 14:53:51] - |D| - [40232] - C:\Program Files (x86)\Windows Portable Devices [07/12/2019 09:14:52] - |SHD| - [0] - C:\Program Files (x86)\Windows Sidebar [07/12/2019 09:14:52] - |D| - [2390473] - C:\Program Files (x86)\WindowsPowerShell ---------- | C:\Program Files [30/01/2022 03:46:23] - |D| - [108368690] - C:\Program Files\Amazon [29/06/2021 12:18:18] - |D| - [540679185] - C:\Program Files\AMD [07/12/2019 09:14:52] - |D| - [64650137] - C:\Program Files\Common Files [07/12/2019 09:14:54] - |ASH| - [174] - C:\Program Files\desktop.ini [01/02/2022 18:04:46] - |D| - [156164906] - C:\Program Files\dotnet [29/06/2021 12:19:56] - |SHD| - [0] - C:\Program Files\Fichiers communs [29/06/2021 14:35:48] - |D| - [552539535] - C:\Program Files\Google [14/01/2022 17:02:18] - |D| - [9333020] - C:\Program Files\Guillemot [07/12/2019 09:14:52] - |D| - [2710130] - C:\Program Files\Internet Explorer [21/01/2022 00:41:10] - |D| - [216543664] - C:\Program Files\Java [02/09/2021 23:20:22] - |D| - [44143563] - C:\Program Files\Marvelous Designer 10 Personal [11/07/2021 11:12:51] - |D| - [231849254] - C:\Program Files\Microsoft SQL Server [01/07/2021 22:34:59] - |D| - [1961616] - C:\Program Files\Microsoft Update Health Tools [07/12/2019 09:14:52] - |D| - [0] - C:\Program Files\ModifiableWindowsApps [29/06/2021 13:06:49] - |D| - [25757] - C:\Program Files\MSBuild [02/01/2022 22:09:12] - |D| - [690606256] - C:\Program Files\MSFS2020 Map Enhancement [29/06/2021 16:07:07] - |D| - [99368922] - C:\Program Files\Navigraph [10/07/2021 17:43:31] - |D| - [787575733] - C:\Program Files\NVIDIA Corporation [29/06/2021 12:18:08] - |D| - [56383576] - C:\Program Files\Realtek [06/02/2022 18:31:09] - |D| - [191342277] - C:\Program Files\RealTrafficLauncher [02/09/2021 22:30:55] - |D| - [205579648] - C:\Program Files\Red Giant [29/06/2021 13:06:49] - |D| - [36883625] - C:\Program Files\Reference Assemblies [14/01/2022 17:02:18] - |D| - [5813724] - C:\Program Files\Thrustmaster [29/06/2021 12:18:01] - |HD| - [0] - C:\Program Files\Uninstall Information [30/08/2021 22:46:26] - |D| - [23086556] - C:\Program Files\VS Revo Group [07/12/2019 09:14:52] - |D| - [14527334] - C:\Program Files\Windows Defender [07/12/2019 14:53:51] - |D| - [47994079] - C:\Program Files\Windows Defender Advanced Threat Protection [07/12/2019 09:14:52] - |D| - [639488] - C:\Program Files\Windows Mail [07/12/2019 14:53:51] - |D| - [4935057] - C:\Program Files\Windows Media Player [07/12/2019 14:53:51] - |D| - [48536] - C:\Program Files\Windows Multimedia Platform [07/12/2019 09:14:52] - |D| - [6674264] - C:\Program Files\Windows NT [07/12/2019 14:53:51] - |D| - [6318536] - C:\Program Files\Windows Photo Viewer [07/12/2019 14:53:51] - |D| - [48528] - C:\Program Files\Windows Portable Devices [07/12/2019 09:14:52] - |D| - [112213] - C:\Program Files\Windows Security [07/12/2019 09:14:52] - |SHD| - [0] - C:\Program Files\Windows Sidebar [07/12/2019 09:14:52] - |HD| - [4032951505] - C:\Program Files\WindowsApps [07/12/2019 09:14:52] - |D| - [2716993] - C:\Program Files\WindowsPowerShell ---------- | C:\Program Files (x86)\Common Files [30/12/2021 19:05:50] - |D| - [137216] - C:\Program Files (x86)\Common Files\designer [02/09/2021 22:30:38] - |D| - [92168976] - C:\Program Files (x86)\Common Files\Intel [06/02/2022 12:48:41] - |D| - [2367528] - C:\Program Files (x86)\Common Files\Java [07/12/2019 09:14:52] - |D| - [15668562] - C:\Program Files (x86)\Common Files\Microsoft Shared [06/02/2022 12:48:51] - |D| - [2017600] - C:\Program Files (x86)\Common Files\Oracle [07/12/2019 09:14:52] - |D| - [2702] - C:\Program Files (x86)\Common Files\Services [29/06/2021 14:04:55] - |D| - [26449817] - C:\Program Files (x86)\Common Files\Steam [07/12/2019 09:14:52] - |D| - [10056587] - C:\Program Files (x86)\Common Files\System ---------- | C:\Program Files\Common files [10/02/2022 12:14:41] - |HD| - [1012139] - C:\Program Files\Common files\EAInstaller [07/12/2019 09:14:52] - |D| - [52578773] - C:\Program Files\Common files\microsoft shared [07/12/2019 09:14:52] - |D| - [2702] - C:\Program Files\Common files\Services [07/12/2019 09:14:52] - |D| - [11056523] - C:\Program Files\Common files\System ---------- | Links to files C:\FSUIPC7\Documents.lnk -> C:\Users\gband\Documents\FSUIPC7 - Status : OK C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip\7-Zip File Manager.lnk -> C:\Program Files (x86)\7-Zip\7zFM.exe - Status : OK C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip\7-Zip Help.lnk -> C:\Program Files (x86)\7-Zip\7-zip.chm - Status : OK C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility\Speech Recognition.lnk -> C:\WINDOWS\Speech\Common\sapisvr.exe - Status : OK C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Math Input Panel.lnk -> C:\Program Files\Common Files\Microsoft Shared\Ink\mip.exe - Status : OK C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Notepad.lnk -> C:\WINDOWS\system32\notepad.exe - Status : OK C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Paint.lnk -> C:\WINDOWS\system32\mspaint.exe - Status : OK C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Quick Assist.lnk -> C:\WINDOWS\system32\quickassist.exe - Status : OK C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Remote Desktop Connection.lnk -> C:\WINDOWS\system32\mstsc.exe - Status : OK C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Snipping Tool.lnk -> C:\WINDOWS\system32\SnippingTool.exe - Status : OK C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Steps Recorder.lnk -> C:\WINDOWS\system32\psr.exe - Status : OK C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Character Map.lnk -> C:\WINDOWS\system32\charmap.exe - Status : OK C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Fax and Scan.lnk -> C:\WINDOWS\system32\WFS.exe - Status : OK C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Media Player.lnk -> C:\Program Files (x86)\Windows Media Player\wmplayer.exe - Status : OK C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Wordpad.lnk -> C:\Program Files\Windows NT\Accessories\wordpad.exe - Status : OK C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Component Services.lnk -> C:\WINDOWS\system32\comexp.msc - Status : OK C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Computer Management.lnk -> C:\WINDOWS\system32\compmgmt.msc - Status : OK C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\dfrgui.lnk -> C:\WINDOWS\system32\dfrgui.exe - Status : OK C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Disk Cleanup.lnk -> C:\WINDOWS\system32\cleanmgr.exe - Status : OK C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Event Viewer.lnk -> C:\WINDOWS\system32\eventvwr.msc - Status : OK C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\iSCSI Initiator.lnk -> C:\WINDOWS\system32\iscsicpl.exe - Status : OK C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Memory Diagnostics Tool.lnk -> C:\WINDOWS\system32\MdSched.exe - Status : OK C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\ODBC Data Sources (32-bit).lnk -> C:\WINDOWS\syswow64\odbcad32.exe - Status : OK C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\ODBC Data Sources (64-bit).lnk -> C:\WINDOWS\system32\odbcad32.exe - Status : OK C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Performance Monitor.lnk -> C:\WINDOWS\system32\perfmon.msc - Status : OK C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Print Management.lnk -> C:\WINDOWS\system32\printmanagement.msc - Status : OK C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\RecoveryDrive.lnk -> C:\WINDOWS\system32\RecoveryDrive.exe - Status : OK C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Registry Editor.lnk -> C:\WINDOWS\regedit.exe - Status : OK C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Resource Monitor.lnk -> C:\WINDOWS\system32\perfmon.exe - Status : OK C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Security Configuration Management.lnk -> C:\WINDOWS\system32\secpol.msc - Status : OK C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk -> C:\WINDOWS\system32\services.msc - Status : OK C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\System Configuration.lnk -> C:\WINDOWS\system32\msconfig.exe - Status : OK C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\System Information.lnk -> C:\WINDOWS\system32\msinfo32.exe - Status : OK C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Task Scheduler.lnk -> C:\WINDOWS\system32\taskschd.msc - Status : OK C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Windows Defender Firewall with Advanced Security.lnk -> C:\WINDOWS\system32\WF.msc - Status : OK C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Bug Report Tool\AMD Bug Report Tool.lnk -> C:\Windows\SysWOW64\AMDBugReportTool.exe - Status : OK C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Link For Windows\AMD Link For Windows.lnk -> C:\Program Files\AMD\CNext\CNext\AMDLink.exe - Status : OK C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Radeon Software\AMD Radeon Software.lnk -> C:\Program Files\AMD\CNext\CNext\RadeonSoftware.exe - Status : OK C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battlefield™ V\Assistance technique.lnk -> E:\Games\Nouveau dossier\Support\EA Help\Assistance technique.fr_FR.rtf - Status : OK C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battlefield™ V\Battlefield™ V.lnk -> E:\Games\Nouveau dossier\bfv.exe - Status : OK C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battlefield™ V\Contrat Utilisateur d'Electronic Arts.lnk -> E:\Games\Nouveau dossier\Support\User Agreement\fr_FR.html - Status : OK C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bijan Season\Bijan Season.lnk -> C:\WINDOWS\Installer\{44154D5D-4127-4905-A8BC-56DB793FE874}\_4D5DEC1CC4EA868A849D91.exe - Status : OK C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Flight Simulator First Officer Next.lnk -> C:\Program Files (x86)\Flight Simulator First Officer Next\FSFO_NEXT.exe - Status : OK C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FS2Crew Pushback Express\Pushback Express MSFS Version.lnk -> C:\Program Files (x86)\Pushback Express MSFS\Pushback Express_x64.exe - Status : OK C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk -> C:\Program Files\Google\Chrome\Application\chrome.exe - Status : OK C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Immersive Control Panel.lnk -> C:\WINDOWS\System32\Control.exe - Status : OK C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\A propos de Java.lnk -> C:\Program Files\Java\jre1.8.0_321\bin\javacpl.exe - Status : OK C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Configurer Java.lnk -> C:\Program Files\Java\jre1.8.0_321\bin\javacpl.exe - Status : OK C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Rechercher les mises à jour.lnk -> C:\Program Files\Java\jre1.8.0_321\bin\javacpl.exe - Status : OK C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk -> C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe - Status : OK C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MSFS2020 Map Enhancement.lnk -> C:\Program Files\MSFS2020 Map Enhancement\MSFS2020 Map Enhancement.exe - Status : OK C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Navigraph FMS Data Manager\Navigraph FMS Data Manager.lnk -> C:\Program Files (x86)\Navigraph\FMS Data Manager\NGFMSAgent.exe - Status : OK C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Navigraph FMS Data Manager\Uninstall Navigraph FMS Data Manager.lnk -> C:\Program Files (x86)\Navigraph\FMS Data Manager\unins000.exe - Status : OK C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Navigraph Simlink.lnk -> C:\Program Files\Navigraph\Simlink\NavigraphSimlink.exe - Status : OK C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation\GeForce Experience.lnk -> C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe - Status : OK C:\ProgramData\Microsoft\Windows\Start Menu\Programs\opentrack\opentrack.lnk -> C:\Program Files (x86)\opentrack\opentrack.exe - Status : OK C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PACX User Guide.lnk -> C:\Program Files (x86)\TFDi Design\PACX\PACX User Guide.pdf - Status : OK C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PACX.lnk -> C:\Program Files (x86)\TFDi Design\PACX\PACX.exe - Status : OK C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Pilot2ATC_2020_x64\Pilot2ATC_200.lnk -> C:\Pilot2ATC_2020_x64\Pilot2ATC_2020.exe - Status : OK C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Pilot2ATC_2020_x64\Uninstall Pilot2ATC_2020.lnk -> C:\Pilot2ATC_2020_x64\unins000.exe - Status : OK C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RealTraffic Launcher\RealTraffic Launcher.lnk -> C:\Program Files\RealTrafficLauncher\RealTrafficLauncher.exe - Status : OK C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RealTraffic Launcher\Uninstall RealTraffic.lnk -> C:\Program Files\RealTrafficLauncher\unins000.exe - Status : OK C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller\Désinstaller Revo Uninstaller.lnk -> C:\Program Files\VS Revo Group\Revo Uninstaller\unins000.exe - Status : OK C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller\Revo Uninstaller Help.lnk -> C:\Program Files\VS Revo Group\Revo Uninstaller\Revo Uninstaller Help.pdf - Status : OK C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller\Revo Uninstaller.lnk -> C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exe - Status : OK C:\ProgramData\Microsoft\Windows\Start Menu\Programs\REX Game Studios\REX Download Manager\REX File Transfer Manager.lnk -> C:\REX Download Manager\rexdownloadmanagerlite.exe - Status : OK C:\ProgramData\Microsoft\Windows\Start Menu\Programs\REX Weather Force 2020\REX Updater.lnk -> C:\REX Weather Force 2020\rexupdater.exe - Status : OK C:\ProgramData\Microsoft\Windows\Start Menu\Programs\REX Weather Force 2020\REX Weather Force 2022.lnk -> C:\REX Weather Force 2020\rexwxforceapp.exe - Status : OK C:\ProgramData\Microsoft\Windows\Start Menu\Programs\REX Weather Force 2020\User Manual Weather Force.lnk -> C:\REX Weather Force 2020\User Manual Weather Force.pdf - Status : OK C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SimMarket\Flight Control Replay\Flight Control Replay Microsoft Flight Simulator Version.lnk -> C:\Program Files (x86)\SimMarket\FlightControlReplay\FlightControlReplayMSFS\FlightControlReplay.exe - Status : OK C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SimMarket\Flight Control Replay\Flight Control Replay P3DX Enhanced Version.lnk -> C:\Program Files (x86)\SimMarket\FlightControlReplay\FlightControlReplayP3DX\FlightControlReplayP3DX.exe - Status : OK C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SimMarket\Flight Control Replay\Flight Control Replay.lnk -> C:\Program Files (x86)\SimMarket\FlightControlReplay\FlightControlReplay.exe - Status : OK C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SimMarket\Flight Control Replay\Read Me.lnk -> C:\Program Files (x86)\SimMarket\FlightControlReplay\Docs\ReadMev4.5.pdf - Status : OK C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SimMarket\Flight Control Replay\Uninstall or Repair Flight Control Replay.lnk -> C:\Program Files (x86)\SimMarket\FlightControlReplay\UninsHs.exe - Status : OK C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam\Steam.lnk -> C:\Program Files (x86)\Steam\Steam.exe - Status : OK C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools\Task Manager.lnk -> C:\WINDOWS\system32\taskmgr.exe - Status : OK C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Thrustmaster TM Flight Series\Control Panel.lnk -> C:\Windows\System32\control.exe - Status : OK C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Thrustmaster TM Flight Series\Firmware Update.lnk -> C:\Program Files\Guillemot\tmfwupdater\TMFirmwareUpdater.exe - Status : OK C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE (x86).lnk -> C:\WINDOWS\syswow64\WindowsPowerShell\v1.0\PowerShell_ISE.exe - Status : OK C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE.lnk -> C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell_ISE.exe - Status : OK C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group1\1 - Desktop.lnk -> C:\WINDOWS\explorer.exe - Status : OK C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group2\1 - Run.lnk -> C:\WINDOWS\explorer.exe - Status : OK C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group2\2 - Search.lnk -> C:\WINDOWS\explorer.exe - Status : OK C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group2\3 - Windows Explorer.lnk -> C:\WINDOWS\explorer.exe - Status : OK C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group2\4 - Control Panel.lnk -> - Status : OK C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group2\5 - Task Manager.lnk -> C:\WINDOWS\system32\taskmgr.exe - Status : OK C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\01 - Command Prompt.lnk -> C:\WINDOWS\system32\cmd.exe - Status : OK C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\01a - Windows PowerShell.lnk -> C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe - Status : OK C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\02 - Command Prompt.lnk -> C:\WINDOWS\system32\cmd.exe - Status : OK C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\02a - Windows PowerShell.lnk -> C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe - Status : OK C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\03 - Computer Management.lnk -> C:\WINDOWS\system32\compmgmt.msc - Status : OK C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\04 - Disk Management.lnk -> C:\WINDOWS\system32\diskmgmt.msc - Status : OK C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\04-1 - NetworkStatus.lnk -> - Status : OK C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\05 - Device Manager.lnk -> C:\WINDOWS\system32\control.exe - Status : OK C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\06 - SystemAbout.lnk -> - Status : OK C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\07 - Event Viewer.lnk -> C:\WINDOWS\system32\eventvwr.exe - Status : OK C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\08 - PowerAndSleep.lnk -> - Status : OK C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\09 - Mobility Center.lnk -> C:\WINDOWS\system32\mblctr.exe - Status : OK C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\10 - AppsAndFeatures.lnk -> - Status : OK C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -> - Status : OK C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -> - Status : OK C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk -> C:\WINDOWS\system32\WFS.exe - Status : OK C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Magnify.lnk -> C:\WINDOWS\system32\magnify.exe - Status : OK C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Narrator.lnk -> C:\WINDOWS\system32\narrator.exe - Status : OK C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\On-Screen Keyboard.lnk -> C:\WINDOWS\system32\osk.exe - Status : OK C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk -> C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\OneDrive\OneDrive.exe - Status : OK C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Administrative Tools.lnk -> C:\WINDOWS\system32\control.exe - Status : OK C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Command Prompt.lnk -> C:\WINDOWS\system32\cmd.exe - Status : OK C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\computer.lnk -> - Status : OK C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Control Panel.lnk -> - Status : OK C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\File Explorer.lnk -> - Status : OK C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Run.lnk -> - Status : OK C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell (x86).lnk -> C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe - Status : OK C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe - Status : OK C:\Users\gband\AppData\Local\Microsoft\Windows\WinX\Group1\1 - Desktop.lnk -> C:\WINDOWS\explorer.exe - Status : OK C:\Users\gband\AppData\Local\Microsoft\Windows\WinX\Group2\1 - Run.lnk -> C:\WINDOWS\explorer.exe - Status : OK C:\Users\gband\AppData\Local\Microsoft\Windows\WinX\Group2\2 - Search.lnk -> C:\WINDOWS\explorer.exe - Status : OK C:\Users\gband\AppData\Local\Microsoft\Windows\WinX\Group2\3 - Windows Explorer.lnk -> C:\WINDOWS\explorer.exe - Status : OK C:\Users\gband\AppData\Local\Microsoft\Windows\WinX\Group2\4 - Control Panel.lnk -> - Status : OK C:\Users\gband\AppData\Local\Microsoft\Windows\WinX\Group2\5 - Task Manager.lnk -> C:\WINDOWS\system32\taskmgr.exe - Status : OK C:\Users\gband\AppData\Local\Microsoft\Windows\WinX\Group3\01 - Command Prompt.lnk -> C:\WINDOWS\system32\cmd.exe - Status : OK C:\Users\gband\AppData\Local\Microsoft\Windows\WinX\Group3\01a - Windows PowerShell.lnk -> C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe - Status : OK C:\Users\gband\AppData\Local\Microsoft\Windows\WinX\Group3\02 - Command Prompt.lnk -> C:\WINDOWS\system32\cmd.exe - Status : OK C:\Users\gband\AppData\Local\Microsoft\Windows\WinX\Group3\02a - Windows PowerShell.lnk -> C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe - Status : OK C:\Users\gband\AppData\Local\Microsoft\Windows\WinX\Group3\03 - Computer Management.lnk -> C:\WINDOWS\system32\compmgmt.msc - Status : OK C:\Users\gband\AppData\Local\Microsoft\Windows\WinX\Group3\04 - Disk Management.lnk -> C:\WINDOWS\system32\diskmgmt.msc - Status : OK C:\Users\gband\AppData\Local\Microsoft\Windows\WinX\Group3\04-1 - NetworkStatus.lnk -> - Status : OK C:\Users\gband\AppData\Local\Microsoft\Windows\WinX\Group3\05 - Device Manager.lnk -> C:\WINDOWS\system32\control.exe - Status : OK C:\Users\gband\AppData\Local\Microsoft\Windows\WinX\Group3\06 - SystemAbout.lnk -> - Status : OK C:\Users\gband\AppData\Local\Microsoft\Windows\WinX\Group3\07 - Event Viewer.lnk -> C:\WINDOWS\system32\eventvwr.exe - Status : OK C:\Users\gband\AppData\Local\Microsoft\Windows\WinX\Group3\08 - PowerAndSleep.lnk -> - Status : OK C:\Users\gband\AppData\Local\Microsoft\Windows\WinX\Group3\09 - Mobility Center.lnk -> C:\WINDOWS\system32\mblctr.exe - Status : OK C:\Users\gband\AppData\Local\Microsoft\Windows\WinX\Group3\10 - AppsAndFeatures.lnk -> - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files\Google\Chrome\Application\chrome.exe - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Microsoft Edge.lnk -> C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -> - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\AIGTech - Traffic Controller.lnk -> C:\Users\gband\Documents\Traffic\AIG Taffic controler\AIGTech - Traffic Controller.exe - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\AirTool.lnk -> C:\Users\gband\Documents\Luke Air\AirTool.exe - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Discord.lnk -> C:\Users\gband\AppData\Local\Discord\Update.exe - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\File Explorer.lnk -> - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\FlightSimulator (2).lnk -> C:\Program Files (x86)\Steam\steamapps\common\MicrosoftFlightSimulator\FlightSimulator.exe - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\FSAirlines.lnk -> C:\Program Files (x86)\FSAirlines\FSAirlines.exe - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk -> C:\Program Files\Google\Chrome\Application\chrome.exe - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Microsoft Edge.lnk -> C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\MSFS Addons Linker.lnk -> C:\Users\gband\Documents\Addons linker\MSFS_AddonsLinker.exe - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\MSFS2020 Map Enhancement.lnk -> C:\Program Files\MSFS2020 Map Enhancement\MSFS2020 Map Enhancement.exe - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Not For Broadcast.lnk -> E:\Games\Nouveau dossier\Not For Broadcast\NotForBroadcast.exe - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\PilotUI.lnk -> D:\MFS2020\IVAO\PilotUI\PilotUI.exe - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\pilot_core_fs2020.lnk -> D:\MFS2020\IVAO\PilotCore\pilot_core_fs2020.exe - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\PremCARS.lnk -> C:\Users\gband\AppData\Local\Apps\2.0\LK0QAA7C.X1D\6W48N25K.TVN\prem..tion_0000000000000000_0001.0001_d5bbe5a2780b9090\PremCARS.exe - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Self-Loading Cargo.lnk -> C:\Users\gband\AppData\Roaming\Microsoft\Installer\{5713AEF3-C475-4F46-BB95-56DE1D6AF49F}\_C87008B0128B75A373CEF7.exe - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\sider.lnk -> E:\Games\Nouveau dossier\eFootball PES 2021\sider.exe - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\SimToolkitPro.lnk -> C:\Users\gband\AppData\Local\simtoolkitpro\app-0.8.12\SimToolkitPro.exe - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\smartCARS - AirFrance Virtuel (en-US).lnk -> C:\Program Files (x86)\smartCARS\94\en-US\smartCARS.exe - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Telegram.lnk -> C:\Users\gband\AppData\Roaming\Telegram Desktop\Telegram.exe - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Volanta.lnk -> C:\Users\gband\AppData\Local\Programs\Volanta\Volanta.exe - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\vPilot.lnk -> C:\Users\gband\AppData\Local\vPilot\vPilot.exe - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -> - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\202229221.fcr.lnk -> C:\Program Files (x86)\SimMarket\FlightControlReplay\202229221.fcr - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\47e838e9e309e10fe84295ad2908372e7DK44u-V-CjvTfaojeV7uIlt92-5kDJk2XUCZg.lnk -> C:\Users\gband\Downloads\47e838e9e309e10fe84295ad2908372e7DK44u-V-CjvTfaojeV7uIlt92-5kDJk2XUCZg.htm - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\A-Guide-to-Flight-Simulator-Extended-Edition-v1.50-Feb-2022-SPREAD.lnk -> C:\Users\gband\Documents\A-Guide-to-Flight-Simulator-Extended-Edition-v1.50-Feb-2022-SPREAD.pdf - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\a320-livery-AIR TRANSAT C-GCKU_a32nx_3vGNm.lnk -> C:\Users\gband\Documents\opentrack-2.3\a320-livery-AIR TRANSAT C-GCKU_a32nx_3vGNm.zip - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\aerosoft-aircraft-twin-otter-v1-0-3-0 (2).lnk -> C:\Users\gband\Documents\opentrack-2.3\aerosoft-aircraft-twin-otter-v1-0-3-0.torrent - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\aerosoft-aircraft-twin-otter-v1-0-3-0.lnk -> C:\Users\gband\Downloads\aerosoft-aircraft-twin-otter-v1-0-3-0.rar - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\AIG Taffic controler.lnk -> C:\Users\gband\Documents\Traffic\AIG Taffic controler - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\AIGTC_Manual_0.5.lnk -> C:\Users\gband\Documents\Traffic\AIG Taffic controler\AIGTC_Manual_0.5.pdf - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\AIGTech - Traffic Controller.exe.lnk -> C:\Users\gband\Documents\Traffic\AIG Taffic controler\AIGTech - Traffic Controller.exe.config - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\air hauler.lnk -> C:\Users\gband\Documents\air hauler - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\aircraft.lnk -> D:\MFS2020\Community\sws-aircraft-kodiak-wheels\SimObjects\Airplanes\SWS_Kodiak_tundra\aircraft.cfg - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\airtooltoolbar_sM12e.lnk -> C:\Users\gband\Documents\opentrack-2.3\airtooltoolbar_sM12e.zip - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\aitrack-v0.6.4-alpha (2).lnk -> C:\Users\gband\Documents\aitrack-v0.6.4-alpha - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\asobo-airport-ksfo-sanfrancisco-v1-12-6 (2).lnk -> C:\Users\gband\Downloads\asobo-airport-ksfo-sanfrancisco-v1-12-6.rar - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\asobo-airport-ksfo-sanfrancisco-v1-12-6.lnk -> C:\Users\gband\Documents\opentrack-2.3\asobo-airport-ksfo-sanfrancisco-v1-12-6.torrent - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\Asobo_A320_NEO_AirBlueFox_a32nx.lnk -> C:\Users\gband\Documents\opentrack-2.3\Asobo_A320_NEO_AirBlueFox_a32nx.zip - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\Asobo_A320_NEO_INTERJET_a32nx_QM19P.lnk -> C:\Users\gband\Documents\opentrack-2.3\Asobo_A320_NEO_INTERJET_a32nx_QM19P.zip - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\banditsim-airport-oerk-riyadh-0.4.3_RNfca.lnk -> C:\Users\gband\Documents\opentrack-2.3\banditsim-airport-oerk-riyadh-0.4.3_RNfca.zip - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\Battlefield.V-CPY (2).lnk -> C:\Users\gband\Downloads\Battlefield.V-CPY - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\Battlefield.V-CPY.lnk -> C:\Users\gband\Downloads\Battlefield.V-CPY.torrent - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\BijanSeasonsV7.1.lnk -> C:\Users\gband\Documents\opentrack-2.3\BijanSeasonsV7.1.zip - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\bijanstudio-misc-four-season-pack-v7-1-0.lnk -> C:\Users\gband\Documents\opentrack-2.3\bijanstudio-misc-four-season-pack-v7-1-0.rar - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\Bijan_Season_Installer_V1.1.lnk -> C:\Users\gband\Documents\opentrack-2.3\Bijan_Season_Installer_V1.1.zip - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\Ce PC.lnk -> - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\cloudsurfasiasimulations-airport-rpll-ninoy-aquino-v1-1-0 (2).lnk -> C:\Users\gband\Downloads\cloudsurfasiasimulations-airport-rpll-ninoy-aquino-v1-1-0.rar - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\cloudsurfasiasimulations-airport-rpll-ninoy-aquino-v1-1-0.lnk -> C:\Users\gband\Documents\opentrack-2.3\cloudsurfasiasimulations-airport-rpll-ninoy-aquino-v1-1-0.torrent - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\cpy-b5.lnk -> C:\Users\gband\Downloads\Battlefield.V-CPY\cpy-b5.iso - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\CPY.lnk -> E:\Games\Nouveau dossier\CPY.ini - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\CRJ_SP.lnk -> C:\Users\gband\Documents\Nouveau dossier\CRJ_SP - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\CS_B773_Air France 2021 LR All_fmNew.lnk -> C:\Users\gband\Documents\opentrack-2.3\CS_B773_Air France 2021 LR All_fmNew.zip - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\Default.fpl.lnk -> C:\Users\gband\Documents\IVAO\Default.fpl - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\Documents.lnk -> C:\Users\gband\Documents - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\EIDW-EGCC.pln.lnk -> C:\Users\gband\AppData\Roaming\Microsoft Flight Simulator\plan\EIDW-EGCC.pln - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\events.lnk -> C:\Users\gband\Downloads\events.zip - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\FIFA 22 SKIDROW - C.P.YGAEMS.SITE.lnk -> C:\Users\gband\Downloads\FIFA 22 SKIDROW - C.P.YGAEMS.SITE.zip - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\fifa-ultimate-editio_404658147.lnk -> C:\Users\gband\Downloads\fifa-ultimate-editio_404658147.zip - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\FIFA.22.Ultimate.Edition.lnk -> C:\Users\gband\Downloads\FIFA.22.Ultimate.Edition.torrent - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\flightbeam-airport-kden-denver-v1-0-8.lnk -> C:\Users\gband\Documents\opentrack-2.3\flightbeam-airport-kden-denver-v1-0-8.torrent - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\FlightControlReplay.lnk -> C:\Program Files (x86)\SimMarket\FlightControlReplay - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\flytampa-city-las-vegas-v1-6-0 (2).lnk -> C:\Users\gband\Downloads\flytampa-city-las-vegas-v1-6-0.rar - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\flytampa-city-las-vegas-v1-6-0.lnk -> C:\Users\gband\Documents\opentrack-2.3\flytampa-city-las-vegas-v1-6-0.torrent - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\fsimstudios-airport-cyvr-vancouver-v1-2-1 (2).lnk -> C:\Users\gband\Downloads\fsimstudios-airport-cyvr-vancouver-v1-2-1.rar - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\fsimstudios-airport-cyvr-vancouver-v1-2-1.lnk -> C:\Users\gband\Documents\opentrack-2.3\fsimstudios-airport-cyvr-vancouver-v1-2-1.torrent - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\god-of-war-flt_429409526.lnk -> C:\Users\gband\Downloads\god-of-war-flt_429409526.zip - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\homasim-airport-oiie-tehran-imam-khomeini-v1-1-4 (2).lnk -> C:\Users\gband\Downloads\homasim-airport-oiie-tehran-imam-khomeini-v1-1-4.rar - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\homasim-airport-oiie-tehran-imam-khomeini-v1-1-4.lnk -> C:\Users\gband\Documents\opentrack-2.3\homasim-airport-oiie-tehran-imam-khomeini-v1-1-4.torrent - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\Internet.lnk -> - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\irissimulations-aircraft-jabiru-v1-5-6 (2).lnk -> C:\Users\gband\Downloads\irissimulations-aircraft-jabiru-v1-5-6.rar - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\irissimulations-aircraft-jabiru-v1-5-6.lnk -> C:\Users\gband\Documents\opentrack-2.3\irissimulations-aircraft-jabiru-v1-5-6.torrent - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\IVAO.lnk -> C:\Users\gband\Documents\IVAO - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\justflight-air-hauler-2-v3-0-0-11 (2).lnk -> C:\Users\gband\Documents\opentrack-2.3\justflight-air-hauler-2-v3-0-0-11.rar - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\justflight-air-hauler-2-v3-0-0-11.lnk -> C:\Users\gband\Documents\opentrack-2.3\justflight-air-hauler-2-v3-0-0-11.torrent - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\justsim-airport-lmml-malta-v1-0-0 (2).lnk -> C:\Users\gband\Downloads\justsim-airport-lmml-malta-v1-0-0.rar - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\justsim-airport-lmml-malta-v1-0-0.lnk -> C:\Users\gband\Documents\opentrack-2.3\justsim-airport-lmml-malta-v1-0-0.torrent - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\kalman fast response.lnk -> C:\Users\gband\Documents\opentrack-2.3\kalman fast response.ini - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\kapi-rjcc-beta_vcpsd.lnk -> C:\Users\gband\Documents\opentrack-2.3\kapi-rjcc-beta_vcpsd.zip - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\layout.lnk -> C:\Users\gband\Documents\Nouveau dossier\CRJ_SP\layout.json - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\LFPGGMMN_MFS_01Feb22.pln.lnk -> C:\Users\gband\AppData\Roaming\Microsoft Flight Simulator\plan\LFPGGMMN_MFS_01Feb22.pln - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\masterrob94-salty-777_Z3GAB.lnk -> C:\Users\gband\Documents\opentrack-2.3\masterrob94-salty-777_Z3GAB.zip - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\maxx2504_Captain Sim B777-X Physics Mod v3.2_C3wdT.lnk -> C:\Users\gband\Documents\opentrack-2.3\maxx2504_Captain Sim B777-X Physics Mod v3.2_C3wdT.zip - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\microsoft-edgehttps--www.microsoft.com-p-xbox-game-pass-ultimate-cfq7ttc0khs0.lnk -> - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\mkstudios-airport-efhk-helsinki-vantaa-v1-0-1 (2).lnk -> C:\Users\gband\Downloads\mkstudios-airport-efhk-helsinki-vantaa-v1-0-1.rar - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\mkstudios-airport-efhk-helsinki-vantaa-v1-0-1.lnk -> C:\Users\gband\Documents\opentrack-2.3\mkstudios-airport-efhk-helsinki-vantaa-v1-0-1.torrent - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\MMMX-KIAH.vfp.lnk -> C:\Users\gband\Documents\vPilot Files\MMMX-KIAH.vfp - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\Modifier les paramètres de la synthèse vocale.lnk -> - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\ms-gamingoverlay--- (2).lnk -> - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\ms-gamingoverlay--- (3).lnk -> - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\ms-gamingoverlay---.lnk -> - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\ms-gamingoverlay--kglcheck-.lnk -> - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\ms-gamingoverlay--startuptips-TitleId=1661555040&ProcessId=10804&WindowId=656616.lnk -> - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\ms-gamingoverlay--startuptips-TitleId=1661555040&ProcessId=11144&WindowId=1770468.lnk -> - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\ms-gamingoverlay--startuptips-TitleId=1661555040&ProcessId=11420&WindowId=262354.lnk -> - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\ms-gamingoverlay--startuptips-TitleId=1661555040&ProcessId=13032&WindowId=263146.lnk -> - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\ms-gamingoverlay--startuptips-TitleId=1661555040&ProcessId=13368&WindowId=1049440.lnk -> - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\ms-gamingoverlay--startuptips-TitleId=1661555040&ProcessId=15280&WindowId=984816.lnk -> - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\ms-gamingoverlay--startuptips-TitleId=1661555040&ProcessId=15316&WindowId=786456.lnk -> - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\ms-gamingoverlay--startuptips-TitleId=1661555040&ProcessId=16440&WindowId=853664.lnk -> - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\ms-gamingoverlay--startuptips-TitleId=1661555040&ProcessId=17372&WindowId=95486152.lnk -> - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\ms-gamingoverlay--startuptips-TitleId=1661555040&ProcessId=17440&WindowId=197724.lnk -> - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\ms-gamingoverlay--startuptips-TitleId=1661555040&ProcessId=19860&WindowId=3082582.lnk -> - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\ms-gamingoverlay--startuptips-TitleId=1661555040&ProcessId=19860&WindowId=528052.lnk -> - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\ms-gamingoverlay--startuptips-TitleId=1661555040&ProcessId=19892&WindowId=591568.lnk -> - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\ms-gamingoverlay--startuptips-TitleId=1661555040&ProcessId=20580&WindowId=918242.lnk -> - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\ms-gamingoverlay--startuptips-TitleId=1661555040&ProcessId=22296&WindowId=328334.lnk -> - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\ms-gamingoverlay--startuptips-TitleId=1661555040&ProcessId=23652&WindowId=460368.lnk -> - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\ms-gamingoverlay--startuptips-TitleId=1661555040&ProcessId=23992&WindowId=1245628.lnk -> - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\ms-gamingoverlay--startuptips-TitleId=1661555040&ProcessId=37484&WindowId=3606616.lnk -> - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\ms-gamingoverlay--startuptips-TitleId=1661555040&ProcessId=37532&WindowId=1312576.lnk -> - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\ms-gamingoverlay--startuptips-TitleId=1661555040&ProcessId=37532&WindowId=132644.lnk -> - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\ms-gamingoverlay--startuptips-TitleId=1661555040&ProcessId=37532&WindowId=2230572.lnk -> - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\ms-gamingoverlay--startuptips-TitleId=1661555040&ProcessId=37532&WindowId=329682.lnk -> - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\ms-gamingoverlay--startuptips-TitleId=1661555040&ProcessId=37532&WindowId=395306.lnk -> - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\ms-gamingoverlay--startuptips-TitleId=1661555040&ProcessId=37532&WindowId=460936.lnk -> - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\ms-gamingoverlay--startuptips-TitleId=1661555040&ProcessId=37980&WindowId=3998704.lnk -> - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\ms-gamingoverlay--startuptips-TitleId=1661555040&ProcessId=3840&WindowId=132778.lnk -> - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\ms-gamingoverlay--startuptips-TitleId=1661555040&ProcessId=5432&WindowId=2622950.lnk -> - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\ms-gamingoverlay--startuptips-TitleId=1661555040&ProcessId=6040&WindowId=1115930.lnk -> - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\ms-gamingoverlay--startuptips-TitleId=1661555040&ProcessId=6300&WindowId=657256.lnk -> - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\ms-gamingoverlay--startuptips-TitleId=1661555040&ProcessId=7076&WindowId=263996.lnk -> - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\ms-gamingoverlay--startuptips-TitleId=1661555040&ProcessId=7576&WindowId=198250.lnk -> - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\ms-gamingoverlay--startuptips-TitleId=1661555040&ProcessId=7804&WindowId=1310742.lnk -> - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\ms-gamingoverlay--startuptips-TitleId=1661555040&ProcessId=8184&WindowId=394932.lnk -> - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\ms-gamingoverlay--startuptips-TitleId=1661555040&ProcessId=8196&WindowId=460336.lnk -> - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\ms-gamingoverlay--startuptips-TitleId=1661555040&ProcessId=832&WindowId=1443404.lnk -> - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\ms-gamingoverlay--startuptips-TitleId=1661555040&ProcessId=8900&WindowId=1050500.lnk -> - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\ms-gamingoverlay--startuptips-TitleId=1661555040&ProcessId=8900&WindowId=197178.lnk -> - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\ms-gamingoverlay--startuptips-TitleId=1661555040&ProcessId=8900&WindowId=198614.lnk -> - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\ms-gamingoverlay--startuptips-TitleId=1661555040&ProcessId=8900&WindowId=265042.lnk -> - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\ms-gamingoverlay--startuptips-TitleId=1661555040&ProcessId=8900&WindowId=461710.lnk -> - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\ms-gamingoverlay--startuptips-TitleId=1661555040&ProcessId=9108&WindowId=590360.lnk -> - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\ms-gamingoverlay--startuptips-TitleId=1661555040&ProcessId=9240&WindowId=132804.lnk -> - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\ms-gamingoverlay--startuptips-TitleId=1661555040&ProcessId=9428&WindowId=328326.lnk -> - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\ms-gamingoverlay--startuptips-TitleId=1661555040&ProcessId=9900&WindowId=198280.lnk -> - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\ms-gamingoverlay--startuptips-TitleId=1691306427&ProcessId=10980&WindowId=1903282.lnk -> - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\ms-gamingoverlay--startuptips-TitleId=1691306427&ProcessId=13116&WindowId=985778.lnk -> - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\ms-gamingoverlay--startuptips-TitleId=1691306427&ProcessId=13356&WindowId=590610.lnk -> - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\ms-gamingoverlay--startuptips-TitleId=1691306427&ProcessId=13628&WindowId=919226.lnk -> - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\ms-gamingoverlay--startuptips-TitleId=1691306427&ProcessId=19620&WindowId=917552.lnk -> - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\ms-gamingoverlay--startuptips-TitleId=1691306427&ProcessId=2912&WindowId=330400.lnk -> - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\ms-gamingoverlay--startuptips-TitleId=1691306427&ProcessId=7668&WindowId=1247882.lnk -> - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\ms-gamingoverlay--startuptips-TitleId=1820448821&ProcessId=4392&WindowId=1575626.lnk -> - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\ms-gamingoverlay--startuptips-TitleId=1873496909&ProcessId=11704&WindowId=1181588.lnk -> - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\MSFS SDK.lnk -> C:\MSFS SDK - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\MSFS2020 Map Enhancement Setup 3.2.2.exe_DpuMQ.lnk -> C:\Users\gband\Documents\opentrack-2.3\MSFS2020 Map Enhancement Setup 3.2.2.exe_DpuMQ.zip - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\neopad2.1 (1).lnk -> C:\Users\gband\Downloads\neopad2.1 (1).zip - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\NF3.13installer (2).lnk -> C:\Users\gband\Downloads\NF3.13installer (2).zip - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\Nouveau dossier.lnk -> E:\Games\Nouveau dossier - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\opentrack-2.3.lnk -> C:\Users\gband\Documents\opentrack-2.3 - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\Options d’ergonomie.lnk -> - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\orbx-mesh-alaska-v1-1-0 (2).lnk -> C:\Users\gband\Downloads\orbx-mesh-alaska-v1-1-0.rar - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\orbx-mesh-alaska-v1-1-0.lnk -> C:\Users\gband\Documents\opentrack-2.3\orbx-mesh-alaska-v1-1-0.torrent - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\pilots-airport-leal-alicante-v1-1-0 (2).lnk -> C:\Users\gband\Downloads\pilots-airport-leal-alicante-v1-1-0.rar - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\pilots-airport-leal-alicante-v1-1-0.lnk -> C:\Users\gband\Documents\opentrack-2.3\pilots-airport-leal-alicante-v1-1-0.torrent - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\plan.lnk -> C:\Users\gband\AppData\Roaming\Microsoft Flight Simulator\plan - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\prefs.lnk -> C:\Users\gband\Documents\aitrack-v0.6.4-alpha\prefs.ini - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\pyreeguedevco-airport-ukbb-boryspil-v1-0-1 (2).lnk -> C:\Users\gband\Downloads\pyreeguedevco-airport-ukbb-boryspil-v1-0-1.rar - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\pyreeguedevco-airport-ukbb-boryspil-v1-0-1.lnk -> C:\Users\gband\Documents\opentrack-2.3\pyreeguedevco-airport-ukbb-boryspil-v1-0-1.torrent - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\RARBG.lnk -> C:\Users\gband\Downloads\Battlefield.V-CPY\RARBG.txt - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\rksi_UOA9I.lnk -> C:\Users\gband\Documents\opentrack-2.3\rksi_UOA9I.zip - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\rusd-airport-uhpp-elizovo-v1-0-1 (2).lnk -> C:\Users\gband\Downloads\rusd-airport-uhpp-elizovo-v1-0-1.rar - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\rusd-airport-uhpp-elizovo-v1-0-1.lnk -> C:\Users\gband\Documents\opentrack-2.3\rusd-airport-uhpp-elizovo-v1-0-1.torrent - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\samscene-airport-vmmc-macau-v2-0-0 (2).lnk -> C:\Users\gband\Downloads\samscene-airport-vmmc-macau-v2-0-0.rar - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\samscene-airport-vmmc-macau-v2-0-0.lnk -> C:\Users\gband\Documents\opentrack-2.3\samscene-airport-vmmc-macau-v2-0-0.torrent - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\scenicroutes-airport-ljlj-ljubljana-v1-1-0 (2).lnk -> C:\Users\gband\Downloads\scenicroutes-airport-ljlj-ljubljana-v1-1-0.rar - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\scenicroutes-airport-ljlj-ljubljana-v1-1-0.lnk -> C:\Users\gband\Documents\opentrack-2.3\scenicroutes-airport-ljlj-ljubljana-v1-1-0.torrent - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\secretstudio-airport-wbkk-kota-kinabalu-v1-0-0 (2).lnk -> C:\Users\gband\Downloads\secretstudio-airport-wbkk-kota-kinabalu-v1-0-0.rar - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\secretstudio-airport-wbkk-kota-kinabalu-v1-0-0.lnk -> C:\Users\gband\Documents\opentrack-2.3\secretstudio-airport-wbkk-kota-kinabalu-v1-0-0.torrent - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\SWS_Kodiak_tundra.lnk -> D:\MFS2020\Community\sws-aircraft-kodiak-wheels\SimObjects\Airplanes\SWS_Kodiak_tundra - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\Téléchargements.lnk -> C:\Users\gband\Downloads - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\version.lnk -> C:\MSFS SDK\version.txt - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\vomm-vommV2_mQjB9.lnk -> C:\Users\gband\Documents\opentrack-2.3\vomm-vommV2_mQjB9.zip - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\vPilot Files.lnk -> C:\Users\gband\Documents\vPilot Files - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\Winter Transfer 2021-2022 Bola Calcio.lnk -> C:\Users\gband\Downloads\Winter Transfer 2021-2022 Bola Calcio.rar - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Recent\z_kingair_mod_JDUZI.lnk -> C:\Users\gband\Documents\opentrack-2.3\z_kingair_mod_JDUZI.rar - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk -> C:\WINDOWS\system32\WFS.exe - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\SendTo\Transfert de fichiers Bluetooth.LNK -> C:\Windows\System32\fsquirt.exe - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\PMDG Operations Center v2.lnk -> C:\Users\gband\AppData\Roaming\PMDG\PMDG Operations Center\PMDG Operations Center.exe - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Magnify.lnk -> C:\WINDOWS\system32\magnify.exe - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Narrator.lnk -> C:\WINDOWS\system32\narrator.exe - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\On-Screen Keyboard.lnk -> C:\WINDOWS\system32\osk.exe - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Applications Chrome\YouTube.lnk -> C:\Program Files\Google\Chrome\Application\chrome_proxy.exe - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Discord Inc\Discord.lnk -> C:\Users\gband\AppData\Local\Discord\Update.exe - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FlyByWire Installer.lnk -> C:\Users\gband\AppData\Local\Programs\fbw-installer\FlyByWire Installer.exe - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Football Manager 2021\Désinstallation.lnk -> C:\Program Files (x86)\Football Manager 2021\Football Manager 2021.exe - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GitHub\Update.lnk -> C:\Users\gband\AppData\Local\simtoolkitpro\Update.exe - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MSI Afterburner\MSI Afterburner.lnk -> C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MSI Afterburner\ReadMe.lnk -> C:\Program Files (x86)\MSI Afterburner\Doc\ReadMe.pdf - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MSI Afterburner\SDK\MSI Afterburner localization reference.lnk -> C:\Program Files (x86)\MSI Afterburner\SDK\Doc\Localization reference.pdf - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MSI Afterburner\SDK\MSI Afterburner skin format reference.lnk -> C:\Program Files (x86)\MSI Afterburner\SDK\Doc\USF skin format reference.pdf - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MSI Afterburner\SDK\Samples.lnk -> C:\Program Files (x86)\MSI Afterburner\SDK\Samples - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MSI Afterburner\Uninstall.lnk -> C:\Program Files (x86)\MSI Afterburner\Uninstall.exe - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Navigraph\Navigraph Charts.lnk -> C:\Users\gband\AppData\Local\Programs\Navigraph Charts\Navigraph Charts.exe - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Navigraph Navdata Center\Navigraph Navdata Center.lnk -> C:\Users\gband\AppData\Local\Programs\Navigraph Navdata Center\Navigraph Navdata Center.exe - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk -> C:\Users\gband\AppData\Local\Microsoft\OneDrive\OneDrive.exe - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Orbx Central.lnk -> C:\Users\gband\AppData\Local\Programs\orbx-central\Orbx Central.exe - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PC Health Check.lnk -> C:\Users\gband\AppData\Local\PCHealthCheck\PCHealthCheck.exe - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RivaTuner Statistics Server\ReadMe.lnk -> C:\Program Files (x86)\RivaTuner Statistics Server\Doc\ReadMe.pdf - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RivaTuner Statistics Server\RivaTuner Statistics Server.lnk -> C:\Program Files (x86)\RivaTuner Statistics Server\RTSS.exe - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RivaTuner Statistics Server\SDK\RivaTuner Statistics Server localization reference.lnk -> C:\Program Files (x86)\RivaTuner Statistics Server\SDK\Doc\Localization reference.pdf - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RivaTuner Statistics Server\SDK\RivaTuner Statistics Server skin format reference.lnk -> C:\Program Files (x86)\RivaTuner Statistics Server\SDK\Doc\USF skin format reference.pdf - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RivaTuner Statistics Server\SDK\Samples.lnk -> C:\Program Files (x86)\RivaTuner Statistics Server\SDK\Samples - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RivaTuner Statistics Server\Uninstall.lnk -> C:\Program Files (x86)\RivaTuner Statistics Server\Uninstall.exe - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Self-Loading Cargo.lnk -> C:\Users\gband\AppData\Roaming\Microsoft\Installer\{5713AEF3-C475-4F46-BB95-56DE1D6AF49F}\_2A92C44EB775C75BC5F758.exe - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SimBrief Downloader.lnk -> C:\Users\gband\AppData\Local\Programs\SimBrief Downloader\SimBrief Downloader.exe - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SimToolkitPro\SimToolkitPro.lnk -> C:\Users\gband\AppData\Local\simtoolkitpro\SimToolkitPro.exe - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Sky4Sim Pad.lnk -> C:\Users\gband\AppData\Local\Programs\Sky4Sim Pad\Sky4Sim Pad.exe - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam\Steam.lnk -> C:\Program Files (x86)\Steam\steam.exe - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Administrative Tools.lnk -> C:\WINDOWS\system32\control.exe - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Command Prompt.lnk -> C:\WINDOWS\system32\cmd.exe - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\computer.lnk -> - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Control Panel.lnk -> - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\File Explorer.lnk -> - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Run.lnk -> - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Telegram Desktop\Désinstaller Telegram.lnk -> C:\Users\gband\AppData\Roaming\Telegram Desktop\unins000.exe - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Telegram Desktop\Telegram.lnk -> C:\Users\gband\AppData\Roaming\Telegram Desktop\Telegram.exe - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TFDi Design\smartCARS\94\smartCARS - AirFrance Virtuel (en-US).lnk -> C:\Program Files (x86)\smartCARS\94\en-US\smartCARS.exe - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft\UbisoftConnect\Ubisoft Connect.lnk -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UbisoftConnect.exe - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft\UbisoftConnect\Uninstall.lnk -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\Uninstall.exe - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft\Uplay\Uninstall.lnk -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\Uninstall.exe - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft\Uplay\Uplay.lnk -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\Uplay.exe - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\uTorrent Web.lnk -> C:\Users\gband\AppData\Roaming\uTorrent Web\utweb.exe - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VASystem\VAS ACARS.lnk -> C:\Users\gband\AppData\Local\Programs\VASystem\VAS-ACARS\vas-acars-updater.exe - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Virtual E6-B.LNK -> C:\Program Files (x86)\Virtual E6-B\Ve6b.exe - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Volanta.lnk -> C:\Users\gband\AppData\Local\Programs\Volanta\Volanta.exe - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\vPilot\Debug\vPilot Host Mode (Debug).lnk -> C:\Users\gband\AppData\Local\vPilot\vPilot.exe - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\vPilot\Debug\vPilot Host Mode with Voice (Debug).lnk -> C:\Users\gband\AppData\Local\vPilot\vPilot.exe - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\vPilot\Debug\vPilot Remote Mode (Debug).lnk -> C:\Users\gband\AppData\Local\vPilot\vPilot.exe - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\vPilot\Debug\vPilot Remote Mode with Voice (Debug).lnk -> C:\Users\gband\AppData\Local\vPilot\vPilot.exe - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\vPilot\Uninstall vPilot.lnk -> C:\Users\gband\AppData\Local\vPilot\Uninstall.exe - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\vPilot\vPilot Host Mode with Voice.lnk -> C:\Users\gband\AppData\Local\vPilot\vPilot.exe - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\vPilot\vPilot Host Mode.lnk -> C:\Users\gband\AppData\Local\vPilot\vPilot.exe - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\vPilot\vPilot Remote Mode with Voice.lnk -> C:\Users\gband\AppData\Local\vPilot\vPilot.exe - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\vPilot\vPilot Remote Mode.lnk -> C:\Users\gband\AppData\Local\vPilot\vPilot.exe - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\vPilot\vPilot.lnk -> C:\Users\gband\AppData\Local\vPilot\vPilot.exe - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell (x86).lnk -> C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe - Status : OK C:\Users\gband\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe - Status : OK C:\Users\gband\Desktop\Discord.lnk -> C:\Users\gband\AppData\Local\Discord\Update.exe - Status : OK C:\Users\gband\Desktop\FlyByWire Installer.lnk -> C:\Users\gband\AppData\Local\Programs\fbw-installer\FlyByWire Installer.exe - Status : OK C:\Users\gband\Desktop\FSAirlines.lnk -> C:\Program Files (x86)\FSAirlines\FSAirlines.exe - Status : OK C:\Users\gband\Desktop\Gafard - Chrome.lnk -> C:\Program Files\Google\Chrome\Application\chrome.exe - Status : OK C:\Users\gband\Desktop\IVAO Pilot Client.lnk -> C:\Users\gband\AppData\Roaming\Microsoft Flight Simulator\Packages\IVAO\PilotUI\PilotUI.exe - Status : OK C:\Users\gband\Desktop\Microsoft Edge.lnk -> C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe - Status : OK C:\Users\gband\Desktop\MSFS.lnk -> C:\FSUIPC7\MSFS.bat - Status : OK C:\Users\gband\Desktop\MSI Afterburner.lnk -> C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe - Status : OK C:\Users\gband\Desktop\Navigraph Charts.lnk -> C:\Users\gband\AppData\Local\Programs\Navigraph Charts\Navigraph Charts.exe - Status : OK C:\Users\gband\Desktop\Navigraph Navdata Center.lnk -> C:\Users\gband\AppData\Local\Programs\Navigraph Navdata Center\Navigraph Navdata Center.exe - Status : OK C:\Users\gband\Desktop\Orbx Central.lnk -> C:\Users\gband\AppData\Local\Programs\orbx-central\Orbx Central.exe - Status : OK C:\Users\gband\Desktop\Self-Loading Cargo.lnk -> C:\Users\gband\AppData\Roaming\Microsoft\Installer\{5713AEF3-C475-4F46-BB95-56DE1D6AF49F}\_C87008B0128B75A373CEF7.exe - Status : OK C:\Users\gband\Desktop\SimBrief Downloader.lnk -> C:\Users\gband\AppData\Local\Programs\SimBrief Downloader\SimBrief Downloader.exe - Status : OK C:\Users\gband\Desktop\SimToolkitPro.lnk -> C:\Users\gband\AppData\Local\simtoolkitpro\SimToolkitPro.exe - Status : OK C:\Users\gband\Desktop\Sky4Sim Pad.lnk -> C:\Users\gband\AppData\Local\Programs\Sky4Sim Pad\Sky4Sim Pad.exe - Status : OK C:\Users\gband\Desktop\smartCARS - AirFrance Virtuel (en-US).lnk -> C:\Program Files (x86)\smartCARS\94\en-US\smartCARS.exe - Status : OK C:\Users\gband\Desktop\SWS Kodiak 100 Wheels Manual.lnk -> D:\MFS2020\Community\sws-aircraft-kodiak-wheels\Manual\SWS_Kodiak100_Wheeled_Manual.pdf - Status : OK C:\Users\gband\Desktop\Telegram.lnk -> C:\Users\gband\AppData\Roaming\Telegram Desktop\Telegram.exe - Status : OK C:\Users\gband\Desktop\Ubisoft Connect.lnk -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UbisoftConnect.exe - Status : OK C:\Users\gband\Desktop\Update.lnk -> C:\Users\gband\AppData\Local\simtoolkitpro\Update.exe - Status : OK C:\Users\gband\Desktop\uTorrent Web.lnk -> C:\Users\gband\AppData\Roaming\uTorrent Web\utweb.exe - Status : OK C:\Users\gband\Desktop\VAS ACARS.lnk -> C:\Users\gband\AppData\Local\Programs\VASystem\VAS-ACARS\vas-acars-updater.exe - Status : OK C:\Users\gband\Desktop\Volanta.lnk -> C:\Users\gband\AppData\Local\Programs\Volanta\Volanta.exe - Status : OK C:\Users\gband\Desktop\vPilot.lnk -> C:\Users\gband\AppData\Local\vPilot\vPilot.exe - Status : OK C:\Users\gband\Desktop\YouTube.lnk -> C:\Program Files\Google\Chrome\Application\chrome_proxy.exe - Status : OK C:\Users\gband\Documents\Traffic\AIG Taffic controler\AIGTech - Traffic Controller - Raccourci.lnk -> C:\Users\gband\Documents\Traffic\AIG Taffic controler\AIGTech - Traffic Controller.exe - Status : OK C:\Users\gband\Links\Desktop.lnk -> C:\Users\gband\Desktop - Status : OK C:\Users\gband\Links\Downloads.lnk -> C:\Users\gband\Downloads - Status : OK C:\Users\Public\Desktop\Bijan Season.lnk -> C:\WINDOWS\Installer\{44154D5D-4127-4905-A8BC-56DB793FE874}\_78C7BD26826C27A097015D.exe - Status : OK C:\Users\Public\Desktop\Cyberpunk 2077.lnk -> E:\Games\Nouveau dossier\Cyberpunk 2077\bin\x64\Cyberpunk2077.exe - Status : OK C:\Users\Public\Desktop\eFootball PES 2021 Settings.lnk -> E:\Games\Nouveau dossier\eFootball PES 2021\Settings.exe - Status : OK C:\Users\Public\Desktop\eFootball PES 2021.lnk -> E:\Games\Nouveau dossier\eFootball PES 2021\PES2021.exe - Status : OK C:\Users\Public\Desktop\Football Manager 2021.lnk -> C:\Program Files (x86)\Football Manager 2021\Football Manager 2021.exe - Status : OK C:\Users\Public\Desktop\GeForce Experience.lnk -> C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe - Status : OK C:\Users\Public\Desktop\Google Chrome.lnk -> C:\Program Files\Google\Chrome\Application\chrome.exe - Status : OK C:\Users\Public\Desktop\MSFS2020 Map Enhancement.lnk -> C:\Program Files\MSFS2020 Map Enhancement\MSFS2020 Map Enhancement.exe - Status : OK C:\Users\Public\Desktop\Navigraph FMS Data Manager.lnk -> C:\Program Files (x86)\Navigraph\FMS Data Manager\NGFMSAgent.exe - Status : OK C:\Users\Public\Desktop\Not For Broadcast.lnk -> E:\Games\Nouveau dossier\Not For Broadcast\NotForBroadcast.exe - Status : OK C:\Users\Public\Desktop\PACX.lnk -> C:\Program Files (x86)\TFDi Design\PACX\PACX.exe - Status : OK C:\Users\Public\Desktop\PBE MSFS.lnk -> C:\Program Files (x86)\Pushback Express MSFS\Pushback Express_x64.exe - Status : OK C:\Users\Public\Desktop\Pilot2ATC_200.lnk -> C:\Pilot2ATC_2020_x64\Pilot2ATC_2020.exe - Status : OK C:\Users\Public\Desktop\Pushback Express Docs.lnk -> C:\Program Files (x86)\Pushback Express MSFS\docs\FS2Crew PBE Docs.url - Status : OK C:\Users\Public\Desktop\Revo Uninstaller.lnk -> C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exe - Status : OK C:\Users\Public\Desktop\REX File Transfer Manager.lnk -> C:\REX Download Manager\rexdownloadmanagerlite.exe - Status : OK C:\Users\Public\Desktop\REX Weather Force 2022.lnk -> C:\REX Weather Force 2020\rexwxforceapp.exe - Status : OK C:\Users\Public\Desktop\Steam.lnk -> C:\Program Files (x86)\Steam\Steam.exe - Status : OK C:\Users\Public\Desktop\User Manual Weather Force.lnk -> C:\REX Weather Force 2020\User Manual Weather Force.pdf - Status : OK C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\WinX\Group1\1 - Desktop.lnk -> C:\WINDOWS\explorer.exe - Status : OK C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\WinX\Group2\1 - Run.lnk -> C:\WINDOWS\explorer.exe - Status : OK C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\WinX\Group2\2 - Search.lnk -> C:\WINDOWS\explorer.exe - Status : OK C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\WinX\Group2\3 - Windows Explorer.lnk -> C:\WINDOWS\explorer.exe - Status : OK C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\WinX\Group2\4 - Control Panel.lnk -> - Status : OK C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\WinX\Group2\5 - Task Manager.lnk -> C:\WINDOWS\system32\taskmgr.exe - Status : OK C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\WinX\Group3\01 - Command Prompt.lnk -> C:\WINDOWS\system32\cmd.exe - Status : OK C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\WinX\Group3\01a - Windows PowerShell.lnk -> C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe - Status : OK C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\WinX\Group3\02 - Command Prompt.lnk -> C:\WINDOWS\system32\cmd.exe - Status : OK C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\WinX\Group3\02a - Windows PowerShell.lnk -> C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe - Status : OK C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\WinX\Group3\03 - Computer Management.lnk -> C:\WINDOWS\system32\compmgmt.msc - Status : OK C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\WinX\Group3\04 - Disk Management.lnk -> C:\WINDOWS\system32\diskmgmt.msc - Status : OK C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\WinX\Group3\04-1 - NetworkStatus.lnk -> - Status : OK C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\WinX\Group3\05 - Device Manager.lnk -> C:\WINDOWS\system32\control.exe - Status : OK C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\WinX\Group3\06 - SystemAbout.lnk -> - Status : OK C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\WinX\Group3\07 - Event Viewer.lnk -> C:\WINDOWS\system32\eventvwr.exe - Status : OK C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\WinX\Group3\08 - PowerAndSleep.lnk -> - Status : OK C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\WinX\Group3\09 - Mobility Center.lnk -> C:\WINDOWS\system32\mblctr.exe - Status : OK C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\WinX\Group3\10 - AppsAndFeatures.lnk -> - Status : OK C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -> - Status : OK C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -> - Status : OK C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\SendTo\Destinataire de télécopie.lnk -> C:\Windows\System32\WFS.exe - Status : OK C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk -> C:\WINDOWS\system32\WFS.exe - Status : OK C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Magnify.lnk -> C:\WINDOWS\system32\magnify.exe - Status : OK C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Narrator.lnk -> C:\WINDOWS\system32\narrator.exe - Status : OK C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\On-Screen Keyboard.lnk -> C:\WINDOWS\system32\osk.exe - Status : OK C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk -> C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\OneDrive\OneDrive.exe - Status : OK C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Administrative Tools.lnk -> C:\WINDOWS\system32\control.exe - Status : OK C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Command Prompt.lnk -> C:\WINDOWS\system32\cmd.exe - Status : OK C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\computer.lnk -> - Status : OK C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Control Panel.lnk -> - Status : OK C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\File Explorer.lnk -> - Status : OK C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Run.lnk -> - Status : OK C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell (x86).lnk -> C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe - Status : OK C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe - Status : OK C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\WinX\Group1\1 - Desktop.lnk -> C:\WINDOWS\explorer.exe - Status : OK C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\WinX\Group2\1 - Run.lnk -> C:\WINDOWS\explorer.exe - Status : OK C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\WinX\Group2\2 - Search.lnk -> C:\WINDOWS\explorer.exe - Status : OK C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\WinX\Group2\3 - Windows Explorer.lnk -> C:\WINDOWS\explorer.exe - Status : OK C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\WinX\Group2\4 - Control Panel.lnk -> - Status : OK C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\WinX\Group2\5 - Task Manager.lnk -> C:\WINDOWS\system32\taskmgr.exe - Status : OK C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\WinX\Group3\01 - Command Prompt.lnk -> C:\WINDOWS\system32\cmd.exe - Status : OK C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\WinX\Group3\01a - Windows PowerShell.lnk -> C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe - Status : OK C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\WinX\Group3\02 - Command Prompt.lnk -> C:\WINDOWS\system32\cmd.exe - Status : OK C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\WinX\Group3\02a - Windows PowerShell.lnk -> C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe - Status : OK C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\WinX\Group3\03 - Computer Management.lnk -> C:\WINDOWS\system32\compmgmt.msc - Status : OK C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\WinX\Group3\04 - Disk Management.lnk -> C:\WINDOWS\system32\diskmgmt.msc - Status : OK C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\WinX\Group3\04-1 - NetworkStatus.lnk -> - Status : OK C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\WinX\Group3\05 - Device Manager.lnk -> C:\WINDOWS\system32\control.exe - Status : OK C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\WinX\Group3\06 - SystemAbout.lnk -> - Status : OK C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\WinX\Group3\07 - Event Viewer.lnk -> C:\WINDOWS\system32\eventvwr.exe - Status : OK C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\WinX\Group3\08 - PowerAndSleep.lnk -> - Status : OK C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\WinX\Group3\09 - Mobility Center.lnk -> C:\WINDOWS\system32\mblctr.exe - Status : OK C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\WinX\Group3\10 - AppsAndFeatures.lnk -> - Status : OK C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -> - Status : OK C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -> - Status : OK C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\SendTo\Destinataire de télécopie.lnk -> C:\Windows\System32\WFS.exe - Status : OK C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk -> C:\WINDOWS\system32\WFS.exe - Status : OK C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Magnify.lnk -> C:\WINDOWS\system32\magnify.exe - Status : OK C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Narrator.lnk -> C:\WINDOWS\system32\narrator.exe - Status : OK C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\On-Screen Keyboard.lnk -> C:\WINDOWS\system32\osk.exe - Status : OK C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk -> C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\OneDrive\OneDrive.exe - Status : OK C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Administrative Tools.lnk -> C:\WINDOWS\system32\control.exe - Status : OK C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Command Prompt.lnk -> C:\WINDOWS\system32\cmd.exe - Status : OK C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\computer.lnk -> - Status : OK C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Control Panel.lnk -> - Status : OK C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\File Explorer.lnk -> - Status : OK C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Run.lnk -> - Status : OK C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell (x86).lnk -> C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe - Status : OK C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe - Status : OK C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Microsoft Edge.lnk -> C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe - Status : OK C:\Windows\WinSxS\amd64_eventviewersettings_31bf3856ad364e35_10.0.19041.1_none_aae8e58aa310aa7d\Event Viewer.lnk -> C:\WINDOWS\system32\eventvwr.msc - Status : OK C:\Windows\WinSxS\amd64_microsoft-hyper-v-management-clients_31bf3856ad364e35_10.0.19041.1_none_a87cce111f2d21d5\Hyper-V Manager.lnk -> C:\WINDOWS\System32\mmc.exe - Status : OK C:\Windows\WinSxS\amd64_microsoft-windows-a..roblemstepsrecorder_31bf3856ad364e35_10.0.19041.746_none_b8eadbf8a9c907b3\Steps Recorder.lnk -> C:\WINDOWS\system32\psr.exe - Status : OK C:\Windows\WinSxS\amd64_microsoft-windows-advancedtaskmanager_31bf3856ad364e35_10.0.19041.1202_none_23a707c9a0b5a8e1\Task Manager.lnk -> C:\WINDOWS\system32\taskmgr.exe - Status : OK C:\Windows\WinSxS\amd64_microsoft-windows-c..-disposableclientvm_31bf3856ad364e35_10.0.19041.985_none_c3639a9e3ab1a351\Windows Sandbox.lnk -> C:\WINDOWS\system32\WindowsSandbox.exe - Status : OK C:\Windows\WinSxS\amd64_microsoft-windows-c..s-admin-compsvclink_31bf3856ad364e35_10.0.19041.1_none_88835f4d79d6a242\Component Services.lnk -> C:\WINDOWS\system32\comexp.msc - Status : OK C:\Windows\WinSxS\amd64_microsoft-windows-c..termanagementsnapin_31bf3856ad364e35_10.0.19041.746_none_290f6af7d5263efa\Computer Management.lnk -> C:\WINDOWS\system32\compmgmt.msc - Status : OK C:\Windows\WinSxS\amd64_microsoft-windows-charmap_31bf3856ad364e35_10.0.19041.1_none_a84acae243b8ad63\Character Map.lnk -> C:\WINDOWS\system32\charmap.exe - Status : OK C:\Windows\WinSxS\amd64_microsoft-windows-cleanmgr_31bf3856ad364e35_10.0.19041.1266_none_e20a09e712bd275c\Disk Cleanup.lnk -> C:\WINDOWS\system32\cleanmgr.exe - Status : OK C:\Windows\WinSxS\amd64_microsoft-windows-commandprompt-shortcut_31bf3856ad364e35_10.0.19041.1_none_efaf63248e6d4479\Command Prompt.lnk -> C:\WINDOWS\system32\cmd.exe - Status : OK C:\Windows\WinSxS\amd64_microsoft-windows-d..-tools-mmc-adsiedit_31bf3856ad364e35_10.0.19041.1466_none_27d69d4b8f185d67\ADSIEdit.lnk -> C:\WINDOWS\system32\adsiedit.msc - Status : OK C:\Windows\WinSxS\amd64_microsoft-windows-d..-tools-mmc-adsiedit_31bf3856ad364e35_10.0.19041.746_none_911fb46a38a61421\ADSIEdit.lnk -> C:\WINDOWS\system32\adsiedit.msc - Status : OK C:\Windows\WinSxS\amd64_microsoft-windows-d..mc-sitesandservices_31bf3856ad364e35_10.0.19041.746_none_7d35d325c812757b\Active Directory Sites and Services.lnk -> C:\WINDOWS\system32\dssite.msc - Status : OK C:\Windows\WinSxS\amd64_microsoft-windows-d..services-adam-setup_31bf3856ad364e35_10.0.19041.746_none_1a1e8292dcf10728\ADAM Install.lnk -> C:\WINDOWS\ADAM\adaminstall.exe - Status : OK C:\Windows\WinSxS\amd64_microsoft-windows-defrag-adminui_31bf3856ad364e35_10.0.19041.746_none_770f598aef14382e\dfrgui.lnk -> C:\WINDOWS\system32\dfrgui.exe - Status : OK C:\Windows\WinSxS\amd64_microsoft-windows-e..er-server-shortcuts_31bf3856ad364e35_10.0.19041.1_none_5e85a7ed6f490164\Administrative Tools.lnk -> C:\WINDOWS\system32\control.exe - Status : OK C:\Windows\WinSxS\amd64_microsoft-windows-explorer-shortcuts_31bf3856ad364e35_10.0.19041.1_none_6da8f779b049952c\01 - Command Prompt.lnk -> C:\WINDOWS\system32\cmd.exe - Status : OK C:\Windows\WinSxS\amd64_microsoft-windows-explorer-shortcuts_31bf3856ad364e35_10.0.19041.1_none_6da8f779b049952c\01a - Windows PowerShell.lnk -> C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe - Status : OK C:\Windows\WinSxS\amd64_microsoft-windows-explorer-shortcuts_31bf3856ad364e35_10.0.19041.1_none_6da8f779b049952c\02 - Command Prompt.lnk -> C:\WINDOWS\system32\cmd.exe - Status : OK C:\Windows\WinSxS\amd64_microsoft-windows-explorer-shortcuts_31bf3856ad364e35_10.0.19041.1_none_6da8f779b049952c\02a - Windows PowerShell.lnk -> C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe - Status : OK C:\Windows\WinSxS\amd64_microsoft-windows-explorer-shortcuts_31bf3856ad364e35_10.0.19041.1_none_6da8f779b049952c\03 - Computer Management.lnk -> C:\WINDOWS\system32\compmgmt.msc - Status : OK C:\Windows\WinSxS\amd64_microsoft-windows-explorer-shortcuts_31bf3856ad364e35_10.0.19041.1_none_6da8f779b049952c\04 - Disk Management.lnk -> C:\WINDOWS\system32\diskmgmt.msc - Status : OK C:\Windows\WinSxS\amd64_microsoft-windows-explorer-shortcuts_31bf3856ad364e35_10.0.19041.1_none_6da8f779b049952c\04-1 - NetworkStatus.lnk -> - Status : OK C:\Windows\WinSxS\amd64_microsoft-windows-explorer-shortcuts_31bf3856ad364e35_10.0.19041.1_none_6da8f779b049952c\05 - Device Manager.lnk -> C:\WINDOWS\system32\control.exe - Status : OK C:\Windows\WinSxS\amd64_microsoft-windows-explorer-shortcuts_31bf3856ad364e35_10.0.19041.1_none_6da8f779b049952c\06 - SystemAbout.lnk -> - Status : OK C:\Windows\WinSxS\amd64_microsoft-windows-explorer-shortcuts_31bf3856ad364e35_10.0.19041.1_none_6da8f779b049952c\07 - Event Viewer.lnk -> C:\WINDOWS\system32\eventvwr.exe - Status : OK C:\Windows\WinSxS\amd64_microsoft-windows-explorer-shortcuts_31bf3856ad364e35_10.0.19041.1_none_6da8f779b049952c\08 - PowerAndSleep.lnk -> - Status : OK C:\Windows\WinSxS\amd64_microsoft-windows-explorer-shortcuts_31bf3856ad364e35_10.0.19041.1_none_6da8f779b049952c\09 - Mobility Center.lnk -> C:\WINDOWS\system32\mblctr.exe - Status : OK C:\Windows\WinSxS\amd64_microsoft-windows-explorer-shortcuts_31bf3856ad364e35_10.0.19041.1_none_6da8f779b049952c\1 - Desktop.lnk -> C:\WINDOWS\explorer.exe - Status : OK C:\Windows\WinSxS\amd64_microsoft-windows-explorer-shortcuts_31bf3856ad364e35_10.0.19041.1_none_6da8f779b049952c\1 - Run.lnk -> C:\WINDOWS\explorer.exe - Status : OK C:\Windows\WinSxS\amd64_microsoft-windows-explorer-shortcuts_31bf3856ad364e35_10.0.19041.1_none_6da8f779b049952c\10 - AppsAndFeatures.lnk -> - Status : OK C:\Windows\WinSxS\amd64_microsoft-windows-explorer-shortcuts_31bf3856ad364e35_10.0.19041.1_none_6da8f779b049952c\2 - Search.lnk -> C:\WINDOWS\explorer.exe - Status : OK C:\Windows\WinSxS\amd64_microsoft-windows-explorer-shortcuts_31bf3856ad364e35_10.0.19041.1_none_6da8f779b049952c\3 - Windows Explorer.lnk -> C:\WINDOWS\explorer.exe - Status : OK C:\Windows\WinSxS\amd64_microsoft-windows-explorer-shortcuts_31bf3856ad364e35_10.0.19041.1_none_6da8f779b049952c\4 - Control Panel.lnk -> - Status : OK C:\Windows\WinSxS\amd64_microsoft-windows-explorer-shortcuts_31bf3856ad364e35_10.0.19041.1_none_6da8f779b049952c\5 - Task Manager.lnk -> C:\WINDOWS\system32\taskmgr.exe - Status : OK C:\Windows\WinSxS\amd64_microsoft-windows-explorer-shortcuts_31bf3856ad364e35_10.0.19041.1_none_6da8f779b049952c\computer.lnk -> - Status : OK C:\Windows\WinSxS\amd64_microsoft-windows-explorer-shortcuts_31bf3856ad364e35_10.0.19041.1_none_6da8f779b049952c\Control Panel.lnk -> - Status : OK C:\Windows\WinSxS\amd64_microsoft-windows-explorer-shortcuts_31bf3856ad364e35_10.0.19041.1_none_6da8f779b049952c\File Explorer.lnk -> - Status : OK C:\Windows\WinSxS\amd64_microsoft-windows-explorer-shortcuts_31bf3856ad364e35_10.0.19041.1_none_6da8f779b049952c\Run.lnk -> - Status : OK C:\Windows\WinSxS\amd64_microsoft-windows-explorer-shortcuts_31bf3856ad364e35_10.0.19041.1_none_6da8f779b049952c\Shows Desktop.lnk -> - Status : OK C:\Windows\WinSxS\amd64_microsoft-windows-explorer-shortcuts_31bf3856ad364e35_10.0.19041.1_none_6da8f779b049952c\Window Switcher.lnk -> - Status : OK C:\Windows\WinSxS\amd64_microsoft-windows-f..client-applications_31bf3856ad364e35_10.0.19041.1415_none_eda4f56addac5a98\Fax Recipient.lnk -> C:\WINDOWS\system32\WFS.exe - Status : OK C:\Windows\WinSxS\amd64_microsoft-windows-f..client-applications_31bf3856ad364e35_10.0.19041.1415_none_eda4f56addac5a98\Windows Fax and Scan.lnk -> C:\WINDOWS\system32\WFS.exe - Status : OK C:\Windows\WinSxS\amd64_microsoft-windows-i..ntrolpanel.appxmain_31bf3856ad364e35_10.0.19041.1387_none_8f7af7ce4c3f80e1\Immersive Control Panel.lnk -> C:\WINDOWS\System32\Control.exe - Status : OK C:\Windows\WinSxS\amd64_microsoft-windows-iis-clientshortcuts_31bf3856ad364e35_10.0.19041.1_none_9f9e4023b60d2433\IIS Client Manager.lnk -> C:\WINDOWS\system32\inetsrv\InetMgr.exe - Status : OK C:\Windows\WinSxS\amd64_microsoft-windows-iis-legacysnapin_31bf3856ad364e35_10.0.19041.906_none_5f45625010b4cd19\IIS6 Manager.lnk -> C:\WINDOWS\system32\inetsrv\InetMgr6.exe - Status : OK C:\Windows\WinSxS\amd64_microsoft-windows-iis-managementconsole_31bf3856ad364e35_10.0.19041.906_none_65f82ba919c64b11\IIS Manager.lnk -> C:\WINDOWS\system32\inetsrv\InetMgr.exe - Status : OK C:\Windows\WinSxS\amd64_microsoft-windows-iscsi_initiator_ui_31bf3856ad364e35_10.0.19041.1_none_8ddc3834fb6f659f\iSCSI Initiator.lnk -> C:\WINDOWS\system32\iscsicpl.exe - Status : OK C:\Windows\WinSxS\amd64_microsoft-windows-m..-odbc-administrator_31bf3856ad364e35_10.0.19041.1_none_fa40f4e1dd1492a8\ODBC Data Sources (64-bit).lnk -> C:\WINDOWS\system32\odbcad32.exe - Status : OK C:\Windows\WinSxS\amd64_microsoft-windows-m..diagnostic-schedule_31bf3856ad364e35_10.0.19041.1_none_49c7a9c019150ac4\Memory Diagnostics Tool.lnk -> C:\WINDOWS\system32\MdSched.exe - Status : OK C:\Windows\WinSxS\amd64_microsoft-windows-magnify_31bf3856ad364e35_10.0.19041.1266_none_e2f3aaf24de135ec\Magnify.lnk -> C:\WINDOWS\system32\magnify.exe - Status : OK C:\Windows\WinSxS\amd64_microsoft-windows-mediaplayer-shortcut_31bf3856ad364e35_10.0.19041.1_none_64c27fc7ed12e401\Windows Media Player.lnk -> C:\Program Files (x86)\Windows Media Player\wmplayer.exe - Status : OK C:\Windows\WinSxS\amd64_microsoft-windows-msconfig-exe_31bf3856ad364e35_10.0.19041.1110_none_4f46693352ed3250\System Configuration.lnk -> C:\WINDOWS\system32\msconfig.exe - Status : OK C:\Windows\WinSxS\amd64_microsoft-windows-msinfo32-exe_31bf3856ad364e35_10.0.19041.1110_none_20a89186aedb6af7\System Information.lnk -> C:\WINDOWS\system32\msinfo32.exe - Status : OK C:\Windows\WinSxS\amd64_microsoft-windows-mspaint_31bf3856ad364e35_10.0.19041.746_none_6c16d1714d60fddf\Paint.lnk -> C:\WINDOWS\system32\mspaint.exe - Status : OK C:\Windows\WinSxS\amd64_microsoft-windows-narrator_31bf3856ad364e35_10.0.19041.789_none_9beee4eb02a5f8c7\Narrator.lnk -> C:\WINDOWS\system32\narrator.exe - Status : OK C:\Windows\WinSxS\amd64_microsoft-windows-nfs-adminmmc_31bf3856ad364e35_10.0.19041.1_none_9da8f6be034114e3\Services For Network File System.lnk -> C:\WINDOWS\system32\nfsmgmt.msc - Status : OK C:\Windows\WinSxS\amd64_microsoft-windows-notepad_31bf3856ad364e35_10.0.19041.1320_none_e3d2189d253c2e6b\Notepad.lnk -> C:\WINDOWS\system32\notepad.exe - Status : OK C:\Windows\WinSxS\amd64_microsoft-windows-osk_31bf3856ad364e35_10.0.19041.1_none_60ade0eff94c37fc\On-Screen Keyboard.lnk -> C:\WINDOWS\system32\osk.exe - Status : OK C:\Windows\WinSxS\amd64_microsoft-windows-p..erandprintui-pmcppc_31bf3856ad364e35_10.0.19041.1_none_c1594f70200f2c03\Print Management.lnk -> C:\WINDOWS\system32\printmanagement.msc - Status : OK C:\Windows\WinSxS\amd64_microsoft-windows-performancetoolsgui_31bf3856ad364e35_10.0.19041.746_none_7a0308f7ffc334d5\Performance Monitor.lnk -> C:\WINDOWS\system32\perfmon.msc - Status : OK C:\Windows\WinSxS\amd64_microsoft-windows-performancetoolsgui_31bf3856ad364e35_10.0.19041.746_none_7a0308f7ffc334d5\Resource Monitor.lnk -> C:\WINDOWS\system32\perfmon.exe - Status : OK C:\Windows\WinSxS\amd64_microsoft-windows-powershell-ise_31bf3856ad364e35_10.0.19041.1_none_1ed6cb15a1b51b10\Windows PowerShell ISE (x86).lnk -> C:\WINDOWS\syswow64\WindowsPowerShell\v1.0\PowerShell_ISE.exe - Status : OK C:\Windows\WinSxS\amd64_microsoft-windows-powershell-ise_31bf3856ad364e35_10.0.19041.1_none_1ed6cb15a1b51b10\Windows PowerShell ISE.lnk -> C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell_ISE.exe - Status : OK C:\Windows\WinSxS\amd64_microsoft-windows-quickassist_31bf3856ad364e35_10.0.19041.1387_none_72bdb9e123faa487\Quick Assist.lnk -> C:\WINDOWS\system32\quickassist.exe - Status : OK C:\Windows\WinSxS\amd64_microsoft-windows-recoverydrive_31bf3856ad364e35_10.0.19041.1237_none_9d556cf140e198b4\RecoveryDrive.lnk -> C:\WINDOWS\system32\RecoveryDrive.exe - Status : OK C:\Windows\WinSxS\amd64_microsoft-windows-registry-editor_31bf3856ad364e35_10.0.19041.746_none_d22800313aa7eb5c\Registry Editor.lnk -> C:\WINDOWS\regedit.exe - Status : OK C:\Windows\WinSxS\amd64_microsoft-windows-s..ment-policytools-ex_31bf3856ad364e35_10.0.19041.1_none_0f506321e073254e\Security Configuration Management.lnk -> C:\WINDOWS\system32\secpol.msc - Status : OK C:\Windows\WinSxS\amd64_microsoft-windows-servicessnapin_31bf3856ad364e35_10.0.19041.1_none_8554f027e5186b5e\services.lnk -> C:\WINDOWS\system32\services.msc - Status : OK C:\Windows\WinSxS\amd64_microsoft-windows-snippingtool-app_31bf3856ad364e35_10.0.19041.746_none_77bd4cfbe87238a7\Snipping Tool.lnk -> C:\WINDOWS\system32\SnippingTool.exe - Status : OK C:\Windows\WinSxS\amd64_microsoft-windows-speech-userexperience_31bf3856ad364e35_10.0.19041.746_none_fa033ad7aa9be481\Speech Recognition.lnk -> C:\WINDOWS\Speech\Common\sapisvr.exe - Status : OK C:\Windows\WinSxS\amd64_microsoft-windows-t..etpc-mathinputpanel_31bf3856ad364e35_10.0.19041.746_none_a89acde4afbab635\Math Input Panel.lnk -> C:\Program Files\Common Files\Microsoft Shared\Ink\mip.exe - Status : OK C:\Windows\WinSxS\amd64_microsoft-windows-t..minalservicesclient_31bf3856ad364e35_10.0.19041.1266_none_c2a2211ad648e627\Remote Desktop Connection.lnk -> C:\WINDOWS\system32\mstsc.exe - Status : OK C:\Windows\WinSxS\amd64_microsoft-windows-wordpad_31bf3856ad364e35_10.0.19041.1202_none_a27aa61d221bdc5c\Wordpad.lnk -> C:\Program Files\Windows NT\Accessories\wordpad.exe - Status : OK C:\Windows\WinSxS\amd64_microsoft.windows.powershell.common_31bf3856ad364e35_10.0.19041.1_none_e6d05ddbba96a35b\Windows PowerShell (x86).lnk -> C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe - Status : OK C:\Windows\WinSxS\amd64_microsoft.windows.powershell.common_31bf3856ad364e35_10.0.19041.1_none_e6d05ddbba96a35b\Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe - Status : OK C:\Windows\WinSxS\amd64_multipoint-logcollector_31bf3856ad364e35_10.0.19041.1_none_56138d203a7fc4cf\MultiPoint Log Collector.lnk -> C:\Program Files\Windows MultiPoint Server\LogCollector.exe - Status : OK C:\Windows\WinSxS\amd64_multipoint-wmsmanager_31bf3856ad364e35_10.0.19041.1_none_d1ffdc3927836528\MultiPoint Manager.lnk -> C:\Program Files\Windows MultiPoint Server\WmsManager.exe - Status : OK C:\Windows\WinSxS\amd64_networking-mpssvc-shortcut_31bf3856ad364e35_10.0.19041.1_none_3b48028dac22b3be\Windows Defender Firewall with Advanced Security.lnk -> C:\WINDOWS\system32\WF.msc - Status : OK C:\Windows\WinSxS\amd64_taskschedulersettings_31bf3856ad364e35_10.0.19041.1_none_00dc114da3ba6b01\Task Scheduler.lnk -> C:\WINDOWS\system32\taskschd.msc - Status : OK C:\Windows\WinSxS\msil_hyperv-ux-ui-vmcreate_31bf3856ad364e35_10.0.19041.1_none_8d387dde0a6c6d14\VMCreate.lnk -> C:\Program Files\Hyper-V\VMCreate.exe - Status : OK C:\Windows\WinSxS\msil_multipoint-wmsdashboard_31bf3856ad364e35_10.0.19041.1_none_061d84508b376f80\MultiPoint Dashboard.lnk -> C:\Program Files\Windows MultiPoint Server\WmsDashboard.exe - Status : OK C:\Windows\WinSxS\wow64_microsoft-windows-m..-odbc-administrator_31bf3856ad364e35_10.0.19041.1_none_04959f34117554a3\ODBC Data Sources (32-bit).lnk -> C:\WINDOWS\syswow64\odbcad32.exe - Status : OK C:\Windows\WinSxS\wow64_microsoft-windows-onedrive-setup_31bf3856ad364e35_10.0.19041.1_none_e585f901f9ce93e6\OneDrive.lnk -> C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\OneDrive\OneDrive.exe - Status : OK E:\Traffic\AIG Taffic controler\AIGTech - Traffic Controller - Raccourci.lnk -> C:\Users\gband\Documents\Traffic\AIG Taffic controler\AIGTech - Traffic Controller.exe - Status : OK ---------- | Tasks [MD5.F1A6CD5ADAAB953A6764EA364E17BFB8] - [29/06/2021 12:17:56] - |AH| - [6] - C:\WINDOWS\Tasks\SA.DAT [MD5.00000000000000000000000000000000] - [06/08/2021 14:01:22] - |D| - [2608] - C:\WINDOWS\System32\Tasks\Agent Activation Runtime [MD5.661FB52B4EC558CBC3C815DA7DEA0CC3] - [06/07/2021 23:07:51] - |A| - [2510] - C:\WINDOWS\System32\Tasks\AMDInstallLauncher : C:\Program Files\AMD\CIM\Bin64\InstallManagerApp.exe [MD5.0393A824A3E66A5B401E29A290F0C4D9] - [06/07/2021 23:07:36] - |A| - [2412] - C:\WINDOWS\System32\Tasks\AMDLinkUpdate : C:\Program Files\AMD\CIM\Bin64\InstallManagerApp.exe [MD5.0A590D3C554A9202E268DC39630FEF2E] - [06/07/2021 23:07:34] - |A| - [2396] - C:\WINDOWS\System32\Tasks\AMDRyzenMasterSDKTask : "C:\Program Files\AMD\CNext\CNext\cpumetricsserver.exe" [MD5.0D02C9ABE54355E9517A2F65023BB8BD] - [29/06/2021 14:35:28] - |A| - [3296] - C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore : C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [MD5.D34411D39BADF1A0C44CB139630B9CB2] - [29/06/2021 14:35:28] - |A| - [3420] - C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA : C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [MD5.00000000000000000000000000000000] - [07/12/2019 09:14:52] - |D| - [617606] - C:\WINDOWS\System32\Tasks\Microsoft [MD5.B8C9E671956CFC77238A4044E0005447] - [29/06/2021 12:17:59] - |A| - [3356] - C:\WINDOWS\System32\Tasks\MicrosoftEdgeUpdateTaskMachineCore : C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe [MD5.89E740389B6BD8FFA6974E7D2A74DD18] - [29/06/2021 12:17:59] - |A| - [3480] - C:\WINDOWS\System32\Tasks\MicrosoftEdgeUpdateTaskMachineUA : C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe [MD5.EE9E1A10C2D9C235CECE2F6673A10772] - [10/07/2021 17:44:47] - |A| - [4308] - C:\WINDOWS\System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} : C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [MD5.F55B2F72E563AB4B2C6F011BD0C0A3BC] - [10/07/2021 17:44:50] - |A| - [3976] - C:\WINDOWS\System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} : "C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe" [MD5.9200A7AEAD4C78C61F5CA9964667C70D] - [10/07/2021 17:44:50] - |A| - [3940] - C:\WINDOWS\System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} : C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [MD5.7D8B0CE7470048B275750396EB52C49F] - [10/07/2021 17:44:47] - |A| - [3894] - C:\WINDOWS\System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} : C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [MD5.4C1943F7A098FE04B84E9B3BDC3715BF] - [10/07/2021 17:44:46] - |A| - [3654] - C:\WINDOWS\System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} : C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [MD5.6F17CE5B0E5807813ACD9FCCE8E5BC46] - [10/07/2021 17:44:47] - |A| - [3858] - C:\WINDOWS\System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} : C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [MD5.BCAE170FDD234F9F0917A18E0B3B7C20] - [10/07/2021 17:44:47] - |A| - [3858] - C:\WINDOWS\System32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} : C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [MD5.9CB1FB08276C4651C03889CF7029F7E3] - [10/07/2021 17:44:47] - |A| - [3858] - C:\WINDOWS\System32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} : C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [MD5.045D43E676BA67F262F051FB787CE844] - [10/07/2021 17:44:47] - |A| - [3858] - C:\WINDOWS\System32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} : C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [MD5.8057325E364A8624B435E53FCA6A3C96] - [13/12/2021 13:39:58] - |A| - [3576] - C:\WINDOWS\System32\Tasks\OneDrive Reporting Task-S-1-5-21-3835695913-52790398-83466441-1001 : %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe [MD5.B5E44824F2AF054595B20CD81AD808E4] - [29/06/2021 13:56:33] - |A| - [3372] - C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3835695913-52790398-83466441-1001 : %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe [MD5.1D7B30F104E6AA5BEF36185FA3C4C83D] - [06/07/2021 23:05:28] - |A| - [3126] - C:\WINDOWS\System32\Tasks\RTSS : C:\Program Files (x86)\RivaTuner Statistics Server\RTSS.exe [MD5.51096542EB265E6DF7FC8690E17B6F71] - [29/06/2021 14:04:31] - |A| - [2202] - C:\WINDOWS\System32\Tasks\StartCN : "C:\Program Files\AMD\CNext\CNext\cncmd.exe" [MD5.A67270D9E199763FFB98FE44D479E5AB] - [29/06/2021 14:04:34] - |A| - [2122] - C:\WINDOWS\System32\Tasks\StartDVR : "C:\Program Files\AMD\CNext\CNext\RSServCmd.exe" [MD5.725C9F0E98679D22540EC81D4D206653] - [30/08/2021 22:18:51] - |A| - [4170] - C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{1E9D9B31-A466-4D4E-B3D9-978405AC9684} : C:\WINDOWS\system32\msfeedssync.exe [MD5.00000000000000000000000000000000] - [07/12/2019 09:14:52] - |D| - [0] - C:\WINDOWS\Syswow64\Tasks\Microsoft ---------- | Firewall [HKLM\SYSTEM\CurrentControlSet\Services\sharedaccess\Parameters\FirewallPolicy\FirewallRules] "WiFiDirect-KM-Driver-In-TCP"=v2.30|Action=Allow|Active=TRUE|Dir=In|Protocol=6|App=System|Name=@wlansvc.dll,-37378|Desc=@wlansvc.dll,-37890|EmbedCtxt=@wlansvc.dll,-36865|TTK2_27=WFDKmDriver| "WiFiDirect-KM-Driver-Out-TCP"=v2.30|Action=Allow|Active=TRUE|Dir=Out|Protocol=6|App=System|Name=@wlansvc.dll,-37379|Desc=@wlansvc.dll,-37891|EmbedCtxt=@wlansvc.dll,-36865|TTK2_27=WFDKmDriver| "WiFiDirect-KM-Driver-In-UDP"=v2.30|Action=Allow|Active=TRUE|Dir=In|Protocol=17|App=System|Name=@wlansvc.dll,-37380|Desc=@wlansvc.dll,-37892|EmbedCtxt=@wlansvc.dll,-36865|TTK2_27=WFDKmDriver| "WiFiDirect-KM-Driver-Out-UDP"=v2.30|Action=Allow|Active=TRUE|Dir=Out|Protocol=17|App=System|Name=@wlansvc.dll,-37381|Desc=@wlansvc.dll,-37893|EmbedCtxt=@wlansvc.dll,-36865|TTK2_27=WFDKmDriver| "DeliveryOptimization-TCP-In"=v2.30|Action=Allow|Active=TRUE|Dir=In|Protocol=6|LPort=7680|App=%SystemRoot%\system32\svchost.exe|Svc=dosvc|Name=@%systemroot%\system32\dosvc.dll,-102|Desc=@%systemroot%\system32\dosvc.dll,-104|EmbedCtxt=@%systemroot%\system32\dosvc.dll,-100|Edge=TRUE| "DeliveryOptimization-UDP-In"=v2.30|Action=Allow|Active=TRUE|Dir=In|Protocol=17|LPort=7680|App=%SystemRoot%\system32\svchost.exe|Svc=dosvc|Name=@%systemroot%\system32\dosvc.dll,-103|Desc=@%systemroot%\system32\dosvc.dll,-104|EmbedCtxt=@%systemroot%\system32\dosvc.dll,-100|Edge=TRUE| "WirelessDisplay-In-TCP"=v2.30|Action=Allow|Active=TRUE|Dir=In|Protocol=6|App=%systemroot%\system32\WUDFHost.exe|Name=@wifidisplay.dll,-10200|Desc=@wifidisplay.dll,-10201|LUAuth=O:LSD:(A;;CC;;;S-1-5-84-0-0-0-0-0)|EmbedCtxt=@wifidisplay.dll,-100|TTK2_22=WFDDisplay| "WirelessDisplay-Out-TCP"=v2.30|Action=Allow|Active=TRUE|Dir=Out|Protocol=6|App=%systemroot%\system32\WUDFHost.exe|Name=@wifidisplay.dll,-10202|Desc=@wifidisplay.dll,-10203|LUAuth=O:LSD:(A;;CC;;;S-1-5-84-0-0-0-0-0)|EmbedCtxt=@wifidisplay.dll,-100|TTK2_22=WFDDisplay| "WirelessDisplay-Out-UDP"=v2.30|Action=Allow|Active=TRUE|Dir=Out|Protocol=17|App=%systemroot%\system32\WUDFHost.exe|Name=@wifidisplay.dll,-10204|Desc=@wifidisplay.dll,-10205|LUAuth=O:LSD:(A;;CC;;;S-1-5-84-0-0-0-0-0)|EmbedCtxt=@wifidisplay.dll,-100|TTK2_22=WFDDisplay| "WirelessDisplay-Infra-In-TCP"=v2.30|Action=Allow|Active=TRUE|Dir=In|Protocol=6|LPort=7250|App=%systemroot%\system32\CastSrv.exe|Name=@wifidisplay.dll,-10206|Desc=@wifidisplay.dll,-10207|EmbedCtxt=@wifidisplay.dll,-100| "{8797A5E2-9145-414B-853F-B9C7B38CEB85}"=v2.30|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=NcsiUwpApp|Desc=NcsiUwpApp|LUOwn=S-1-5-21-3835695913-52790398-83466441-1001|AppPkgId=S-1-15-2-138780814-3997110584-2874353029-2041838810-3659441231-3169655024-3643974355|EmbedCtxt=NcsiUwpApp|Platform=2:6:2|Platform2=GTEQ| "{1825D799-7E4D-4F7C-80CA-CE8FF1B26547}"=v2.30|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=Xbox Game Bar Plugin|Desc=Xbox Game Bar Plugin|LUOwn=S-1-5-21-3835695913-52790398-83466441-1001|AppPkgId=S-1-15-2-1823635404-1364722122-2170562666-1762391777-2399050872-3465541734-3732476201|EmbedCtxt=Xbox Game Bar Plugin|Platform=2:6:2|Platform2=GTEQ| "{1F1DDD2A-C66F-4ACE-B4A4-E516E5B91EFA}"=v2.30|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=Xbox TCUI|Desc=Xbox TCUI|LUOwn=S-1-5-21-3835695913-52790398-83466441-1001|AppPkgId=S-1-15-2-2603511428-3224021693-1028932517-3941269705-3349582775-2312504883-4057327947|EmbedCtxt=Xbox TCUI|Platform=2:6:2|Platform2=GTEQ| "{693DC1A8-9F03-48EA-BD31-46C028D91CE8}"=v2.30|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=Microsoft Pay|Desc=Microsoft Pay|LUOwn=S-1-5-21-3835695913-52790398-83466441-1001|AppPkgId=S-1-15-2-567501097-281763132-502764112-1855211022-3143306454-2372101908-561929011|EmbedCtxt=Microsoft Pay|Platform=2:6:2|Platform2=GTEQ| "TCP Query User{4FF49E4B-64AC-4D64-92EF-4B2FF4F996CA}D:\mfs2020\ivao\pilotcore\pilot_core_fs2020.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=D:\mfs2020\ivao\pilotcore\pilot_core_fs2020.exe|Name=pilot_core_fs2020|Desc=pilot_core_fs2020|Defer=User| "UDP Query User{2E082A21-09ED-4D3A-BB3B-70DEC4BC6E6C}D:\mfs2020\ivao\pilotcore\pilot_core_fs2020.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=D:\mfs2020\ivao\pilotcore\pilot_core_fs2020.exe|Name=pilot_core_fs2020|Desc=pilot_core_fs2020|Defer=User| "TCP Query User{F45FD34C-292E-4EA5-A4A4-ECC249217C5C}C:\program files (x86)\tfdi design\pacx\pacx.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\program files (x86)\tfdi design\pacx\pacx.exe|Name=PACX|Desc=PACX|Defer=User| "UDP Query User{66A0D9BF-1FBE-44AA-9404-E87A6600692B}C:\program files (x86)\tfdi design\pacx\pacx.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\program files (x86)\tfdi design\pacx\pacx.exe|Name=PACX|Desc=PACX|Defer=User| "TCP Query User{1D6F65FE-1162-4B24-A2C9-9832CFB626D7}C:\users\gband\desktop\parallel42-skypark-v2021-28-4-2\transponder\transponder.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\users\gband\desktop\parallel42-skypark-v2021-28-4-2\transponder\transponder.exe|Name=transponder.exe|Desc=transponder.exe|Defer=User| "UDP Query User{C8BA05A7-AB3B-47FF-8D48-8ADA4D8E2F84}C:\users\gband\desktop\parallel42-skypark-v2021-28-4-2\transponder\transponder.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\users\gband\desktop\parallel42-skypark-v2021-28-4-2\transponder\transponder.exe|Name=transponder.exe|Desc=transponder.exe|Defer=User| "TCP Query User{F690BE34-2E58-4B8E-829E-F592957B6967}C:\users\gband\desktop\parallel 42\the skypark\transponder\transponder.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\users\gband\desktop\parallel 42\the skypark\transponder\transponder.exe|Name=transponder.exe|Desc=transponder.exe|Defer=User| "UDP Query User{2EB7512A-B3EB-4E31-92DE-8B6E9F8AD5CD}C:\users\gband\desktop\parallel 42\the skypark\transponder\transponder.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\users\gband\desktop\parallel 42\the skypark\transponder\transponder.exe|Name=transponder.exe|Desc=transponder.exe|Defer=User| "TCP Query User{0254B2AB-5D55-4233-B988-EAEFFE2D34E1}E:\games\nouveau dossier\cyberpunk 2077\bin\x64\cyberpunk2077.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=E:\games\nouveau dossier\cyberpunk 2077\bin\x64\cyberpunk2077.exe|Name=Cyberpunk 2077|Desc=Cyberpunk 2077|Defer=User| "UDP Query User{F37B198A-4F77-42C1-BD38-82378EFDD538}E:\games\nouveau dossier\cyberpunk 2077\bin\x64\cyberpunk2077.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=E:\games\nouveau dossier\cyberpunk 2077\bin\x64\cyberpunk2077.exe|Name=Cyberpunk 2077|Desc=Cyberpunk 2077|Defer=User| "TCP Query User{5FA0BEC0-E574-4CA3-9008-9AD44EEDCD22}C:\users\gband\appdata\local\apps\2.0\lk0qaa7c.x1d\6w48n25k.tvn\neof..tion_0000000000000000_0003.000b_53b5cd216c4f9983\neofly.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\users\gband\appdata\local\apps\2.0\lk0qaa7c.x1d\6w48n25k.tvn\neof..tion_0000000000000000_0003.000b_53b5cd216c4f9983\neofly.exe|Name=neofly.exe|Desc=neofly.exe|Defer=User| "UDP Query User{2199D9EC-4A33-4DBB-B6AB-0CE1E93ED915}C:\users\gband\appdata\local\apps\2.0\lk0qaa7c.x1d\6w48n25k.tvn\neof..tion_0000000000000000_0003.000b_53b5cd216c4f9983\neofly.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\users\gband\appdata\local\apps\2.0\lk0qaa7c.x1d\6w48n25k.tvn\neof..tion_0000000000000000_0003.000b_53b5cd216c4f9983\neofly.exe|Name=neofly.exe|Desc=neofly.exe|Defer=User| "{85CA3E56-2801-4737-AB7C-A87FE4DA330E}"=v2.30|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=Microsoft Edge|Desc=Microsoft Edge|LUOwn=S-1-5-21-3835695913-52790398-83466441-1001|AppPkgId=S-1-15-2-3624051433-2125758914-1423191267-1740899205-1073925389-3782572162-737981194|EmbedCtxt=Microsoft Edge|Platform=2:6:2|Platform2=GTEQ| "{BD8EE524-6F01-4456-BB03-5C91CABDDBC7}"=v2.30|Action=Allow|Active=TRUE|Dir=In|Profile=Domain|Profile=Private|Name=Microsoft Edge|Desc=Microsoft Edge|LUOwn=S-1-5-21-3835695913-52790398-83466441-1001|AppPkgId=S-1-15-2-3624051433-2125758914-1423191267-1740899205-1073925389-3782572162-737981194|EmbedCtxt=Microsoft Edge|Platform=2:6:2|Platform2=GTEQ| "TCP Query User{93960463-B117-49D2-95EA-9BC458A6481D}E:\games\nouveau dossier\efootball pes 2021\pes2021.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=E:\games\nouveau dossier\efootball pes 2021\pes2021.exe|Name=eFootball PES 2021|Desc=eFootball PES 2021|Defer=User| "UDP Query User{65DA8C02-FD92-4C11-A8C1-F3FCA4A9023B}E:\games\nouveau dossier\efootball pes 2021\pes2021.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=E:\games\nouveau dossier\efootball pes 2021\pes2021.exe|Name=eFootball PES 2021|Desc=eFootball PES 2021|Defer=User| "TCP Query User{B9CE9798-D581-47AF-9CD8-1D75E88058B3}C:\users\gband\downloads\msfs2020-google-map-2021-11-06_sfwil\python39\python.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\users\gband\downloads\msfs2020-google-map-2021-11-06_sfwil\python39\python.exe|Name=python.exe|Desc=python.exe|Defer=User| "UDP Query User{646951C5-6DE7-47A4-9377-26E701C4A599}C:\users\gband\downloads\msfs2020-google-map-2021-11-06_sfwil\python39\python.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\users\gband\downloads\msfs2020-google-map-2021-11-06_sfwil\python39\python.exe|Name=python.exe|Desc=python.exe|Defer=User| "TCP Query User{41B51924-AD3E-4BDB-9449-98E1B47FEAE9}C:\users\gband\downloads\msfs2020-google-map-2021-11-06_sfwil\nginx\nginx.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\users\gband\downloads\msfs2020-google-map-2021-11-06_sfwil\nginx\nginx.exe|Name=nginx.exe|Desc=nginx.exe|Defer=User| "UDP Query User{1FFE1A4C-0DE6-43AE-9FC2-2AB0B764F2F1}C:\users\gband\downloads\msfs2020-google-map-2021-11-06_sfwil\nginx\nginx.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\users\gband\downloads\msfs2020-google-map-2021-11-06_sfwil\nginx\nginx.exe|Name=nginx.exe|Desc=nginx.exe|Defer=User| "TCP Query User{373B76CF-3BB2-455B-9E40-E94D4B094256}C:\users\gband\documents\msfs2020-google-map-2021-11-06_sfwil\nginx\nginx.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\users\gband\documents\msfs2020-google-map-2021-11-06_sfwil\nginx\nginx.exe|Name=nginx.exe|Desc=nginx.exe|Defer=User| "UDP Query User{C3330EA6-5180-42A8-B9EA-C92144E0F852}C:\users\gband\documents\msfs2020-google-map-2021-11-06_sfwil\nginx\nginx.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\users\gband\documents\msfs2020-google-map-2021-11-06_sfwil\nginx\nginx.exe|Name=nginx.exe|Desc=nginx.exe|Defer=User| "TCP Query User{C3D11A79-8B77-48D7-9E90-CA6BE723C5F4}C:\users\gband\documents\msfs2020-google-map-2021-11-06_sfwil\python39\python.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\users\gband\documents\msfs2020-google-map-2021-11-06_sfwil\python39\python.exe|Name=python.exe|Desc=python.exe|Defer=User| "UDP Query User{4ED66CD9-5943-4D0B-B286-5FC9CBC60E63}C:\users\gband\documents\msfs2020-google-map-2021-11-06_sfwil\python39\python.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\users\gband\documents\msfs2020-google-map-2021-11-06_sfwil\python39\python.exe|Name=python.exe|Desc=python.exe|Defer=User| "{0C9F6139-F5E0-4EF4-A920-877BD4B704EF}"=v2.30|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=Windows Feature Experience Pack|Desc=Windows Feature Experience Pack|LUOwn=S-1-5-21-3835695913-52790398-83466441-1001|AppPkgId=S-1-15-2-283421221-3183566570-1718213290-751554359-3541592344-2312209569-3374928651|EmbedCtxt=Windows Feature Experience Pack|Platform=2:6:2|Platform2=GTEQ| "{1D7CA2E9-4C93-45A9-92DE-B9B383FD8DD3}"=v2.30|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Users\gband\AppData\Roaming\uTorrent Web\utweb.exe|Name=uTorrent Web| "{F394FF21-5A6B-4BD5-AB41-981AB8166203}"=v2.30|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Users\gband\AppData\Roaming\uTorrent Web\utweb.exe|Name=uTorrent Web| "{8CEE949E-3F2A-40F8-A21D-2AC8D9598658}"=v2.30|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=Microsoft Store|Desc=Microsoft Store|LUOwn=S-1-5-21-3835695913-52790398-83466441-1001|AppPkgId=S-1-15-2-1609473798-1231923017-684268153-4268514328-882773646-2760585773-1760938157|EmbedCtxt=Microsoft Store|Platform=2:6:2|Platform2=GTEQ| "{8EE1A590-FF94-44E5-AAC2-F2711466D5C7}"=v2.30|Action=Allow|Active=TRUE|Dir=In|Profile=Domain|Profile=Private|Profile=Public|Name=Microsoft Store|Desc=Microsoft Store|LUOwn=S-1-5-21-3835695913-52790398-83466441-1001|AppPkgId=S-1-15-2-1609473798-1231923017-684268153-4268514328-882773646-2760585773-1760938157|EmbedCtxt=Microsoft Store|Platform=2:6:2|Platform2=GTEQ|Edge=TRUE| "TCP Query User{611AA301-8C9B-4193-827C-14A8BA734D96}C:\users\gband\appdata\local\apps\2.0\lk0qaa7c.x1d\6w48n25k.tvn\neof..tion_0000000000000000_0003.000d_9b30a95929896b03\neofly.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\users\gband\appdata\local\apps\2.0\lk0qaa7c.x1d\6w48n25k.tvn\neof..tion_0000000000000000_0003.000d_9b30a95929896b03\neofly.exe|Name=neofly.exe|Desc=neofly.exe|Defer=User| "UDP Query User{CF202E48-AFCB-4EC1-807E-7734D168B545}C:\users\gband\appdata\local\apps\2.0\lk0qaa7c.x1d\6w48n25k.tvn\neof..tion_0000000000000000_0003.000d_9b30a95929896b03\neofly.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\users\gband\appdata\local\apps\2.0\lk0qaa7c.x1d\6w48n25k.tvn\neof..tion_0000000000000000_0003.000d_9b30a95929896b03\neofly.exe|Name=neofly.exe|Desc=neofly.exe|Defer=User| "TCP Query User{3CA6C327-DB16-47E8-A205-BC24C8FA4BEA}C:\users\gband\documents\parallel 42\the skypark\transponder\transponder.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\users\gband\documents\parallel 42\the skypark\transponder\transponder.exe|Name=transponder.exe|Desc=transponder.exe|Defer=User| "UDP Query User{2B781B41-B46A-48B6-B701-55DD20DE0B29}C:\users\gband\documents\parallel 42\the skypark\transponder\transponder.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\users\gband\documents\parallel 42\the skypark\transponder\transponder.exe|Name=transponder.exe|Desc=transponder.exe|Defer=User| "TCP Query User{259F0456-2BA0-4370-98EB-A0941B737E67}C:\users\gband\appdata\roaming\microsoft flight simulator\packages\ivao\pilotcore\pilot_core_fs2020.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|Profile=Public|App=C:\users\gband\appdata\roaming\microsoft flight simulator\packages\ivao\pilotcore\pilot_core_fs2020.exe|Name=pilot_core_fs2020.exe|Desc=pilot_core_fs2020.exe|Defer=User| "UDP Query User{9EBE114A-5224-4C54-BCB3-49E1D84B9413}C:\users\gband\appdata\roaming\microsoft flight simulator\packages\ivao\pilotcore\pilot_core_fs2020.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|Profile=Public|App=C:\users\gband\appdata\roaming\microsoft flight simulator\packages\ivao\pilotcore\pilot_core_fs2020.exe|Name=pilot_core_fs2020.exe|Desc=pilot_core_fs2020.exe|Defer=User| "TCP Query User{90B5090B-798A-461F-B544-11C10E7DF3C4}C:\program files\msfs2020 map enhancement\msfs2020 map enhancement.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\program files\msfs2020 map enhancement\msfs2020 map enhancement.exe|Name=MSFS2020 Map Enhancement|Desc=MSFS2020 Map Enhancement|Defer=User| "UDP Query User{68F8D9E3-A817-43A3-9AEE-A25CE6758CB3}C:\program files\msfs2020 map enhancement\msfs2020 map enhancement.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\program files\msfs2020 map enhancement\msfs2020 map enhancement.exe|Name=MSFS2020 Map Enhancement|Desc=MSFS2020 Map Enhancement|Defer=User| "TCP Query User{D5A9D307-27E2-406E-ABB0-8AB1A6B07A27}C:\program files\msfs2020 map enhancement\resources\extra\nginx\nginx.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|Profile=Public|App=C:\program files\msfs2020 map enhancement\resources\extra\nginx\nginx.exe|Name=nginx|Desc=nginx|Defer=User| "UDP Query User{3B955544-D566-4967-8ABC-FB7F9DECCD28}C:\program files\msfs2020 map enhancement\resources\extra\nginx\nginx.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|Profile=Public|App=C:\program files\msfs2020 map enhancement\resources\extra\nginx\nginx.exe|Name=nginx|Desc=nginx|Defer=User| "TCP Query User{C0471E63-B436-432B-BD64-8BB5D38D480A}C:\users\gband\appdata\roaming\utorrent web\utweb.exe"=v2.10|Action=Block|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\users\gband\appdata\roaming\utorrent web\utweb.exe|Name=utweb.exe|Desc=utweb.exe| "UDP Query User{E0061E74-435F-460B-BF9A-92DBD32C23DB}C:\users\gband\appdata\roaming\utorrent web\utweb.exe"=v2.10|Action=Block|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\users\gband\appdata\roaming\utorrent web\utweb.exe|Name=utweb.exe|Desc=utweb.exe| "{6B1EE71F-7727-4C08-81F3-FF55D6B21D7A}"=v2.30|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=Cortana|Desc=Cortana|LUOwn=S-1-5-21-3835695913-52790398-83466441-1001|AppPkgId=S-1-15-2-1880626798-2296700190-2192216202-2581987570-949377748-777141861-2889999867|EmbedCtxt=Cortana|Platform=2:6:2|Platform2=GTEQ| "{5E609D58-7B14-49DF-80F9-198869AE6BAA}"=v2.30|Action=Allow|Active=TRUE|Dir=In|Profile=Domain|Profile=Private|Profile=Public|Name=Cortana|Desc=Cortana|LUOwn=S-1-5-21-3835695913-52790398-83466441-1001|AppPkgId=S-1-15-2-1880626798-2296700190-2192216202-2581987570-949377748-777141861-2889999867|EmbedCtxt=Cortana|Platform=2:6:2|Platform2=GTEQ|Edge=TRUE| "TCP Query User{51173492-9B93-4845-B90D-9885DEDDAF3E}C:\users\gband\documents\neofly\neofly.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\users\gband\documents\neofly\neofly.exe|Name=neofly.exe|Desc=neofly.exe|Defer=User| "UDP Query User{57C621D9-1A87-429F-A711-82CA87DF32CC}C:\users\gband\documents\neofly\neofly.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\users\gband\documents\neofly\neofly.exe|Name=neofly.exe|Desc=neofly.exe|Defer=User| "TCP Query User{D825CC5A-BE5B-4035-834E-DA12D8772EF6}C:\program files\guillemot\tools\giwebupdater.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\program files\guillemot\tools\giwebupdater.exe|Name=Guillemot Web Updater|Desc=Guillemot Web Updater|Defer=User| "UDP Query User{4DF00F9A-58F8-4123-A195-4CF9613FFBC1}C:\program files\guillemot\tools\giwebupdater.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\program files\guillemot\tools\giwebupdater.exe|Name=Guillemot Web Updater|Desc=Guillemot Web Updater|Defer=User| "TCP Query User{01A07D8D-DE5C-4E3D-8B29-4FF2DDAFB3CB}C:\program files (x86)\pushback express msfs\pushback express_x64.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\program files (x86)\pushback express msfs\pushback express_x64.exe|Name=Pushback Express|Desc=Pushback Express|Defer=User| "UDP Query User{74F2038E-C8C6-4F96-AA52-F891B8A5FA9C}C:\program files (x86)\pushback express msfs\pushback express_x64.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\program files (x86)\pushback express msfs\pushback express_x64.exe|Name=Pushback Express|Desc=Pushback Express|Defer=User| "{903BA800-F477-47DA-B903-86B323072A95}"=v2.30|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=GamePlan|Desc=GamePlan|LUOwn=S-1-5-21-3835695913-52790398-83466441-1001|AppPkgId=S-1-15-2-3855111717-1676473748-1376300881-3470076168-1759877233-4221398247-3903046974|EmbedCtxt=GamePlan|Platform=2:6:2|Platform2=GTEQ| "{E7A10E94-16F4-4965-904B-0F3EE6553AC6}"=v2.30|Action=Allow|Active=TRUE|Dir=In|Profile=Domain|Profile=Private|Profile=Public|Name=GamePlan|Desc=GamePlan|LUOwn=S-1-5-21-3835695913-52790398-83466441-1001|AppPkgId=S-1-15-2-3855111717-1676473748-1376300881-3470076168-1759877233-4221398247-3903046974|EmbedCtxt=GamePlan|Platform=2:6:2|Platform2=GTEQ|Edge=TRUE| "{0DF5C789-B839-4F47-94B3-F78F7E14A68B}"=v2.30|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=Notepads App|Desc=Notepads App|LUOwn=S-1-5-21-3835695913-52790398-83466441-1001|AppPkgId=S-1-15-2-3296458188-2139961315-982196074-915428501-519263677-2181409070-1149121189|EmbedCtxt=Notepads App|Platform=2:6:2|Platform2=GTEQ| "{8AA081FF-59B3-4FEB-87F8-5F68A453AE8C}"=v2.30|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=LiveATC|Desc=LiveATC|LUOwn=S-1-5-21-3835695913-52790398-83466441-1001|AppPkgId=S-1-15-2-130155746-145473254-2198393264-1840592572-4233107901-305780857-2350925407|EmbedCtxt=LiveATC|Platform=2:6:2|Platform2=GTEQ| "{DBA3C509-A56A-4F9C-93B7-E6A8DFE0B4EC}"=v2.30|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=Microsoft Solitaire Collection|Desc=Microsoft Solitaire Collection|LUOwn=S-1-5-21-3835695913-52790398-83466441-1001|AppPkgId=S-1-15-2-1985198343-3186790915-4047221937-1969271670-3792558349-1325541827-400269725|EmbedCtxt=Microsoft Solitaire Collection|Platform=2:6:2|Platform2=GTEQ| "{25ABD68D-4D98-44B8-8CD8-16C85CA940F3}"=v2.30|Action=Allow|Active=TRUE|Dir=In|Profile=Domain|Profile=Private|Name=Microsoft Solitaire Collection|Desc=Microsoft Solitaire Collection|LUOwn=S-1-5-21-3835695913-52790398-83466441-1001|AppPkgId=S-1-15-2-1985198343-3186790915-4047221937-1969271670-3792558349-1325541827-400269725|EmbedCtxt=Microsoft Solitaire Collection|Platform=2:6:2|Platform2=GTEQ| "{1AFA0B1D-BB76-4B73-8398-2CDE68017C91}"=v2.30|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=Unzip.|Desc=Unzip.|LUOwn=S-1-5-21-3835695913-52790398-83466441-1001|AppPkgId=S-1-15-2-960289390-2804611831-934594800-212976069-3525903231-3955037429-2444813503|EmbedCtxt=Unzip.|Platform=2:6:2|Platform2=GTEQ| "{294FBA43-75C7-4D90-BCB1-774A2898D583}"=v2.30|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=Dolby Access|Desc=Dolby Access|LUOwn=S-1-5-21-3835695913-52790398-83466441-1001|AppPkgId=S-1-15-2-864892550-682355956-3667821578-694357232-3878941086-3291980491-2900429266|EmbedCtxt=Dolby Access|Platform=2:6:2|Platform2=GTEQ| "{7BB12969-4496-4490-B49E-6817803CA8CB}"=v2.30|Action=Allow|Active=TRUE|Dir=In|Profile=Domain|Profile=Private|Name=Dolby Access|Desc=Dolby Access|LUOwn=S-1-5-21-3835695913-52790398-83466441-1001|AppPkgId=S-1-15-2-864892550-682355956-3667821578-694357232-3878941086-3291980491-2900429266|EmbedCtxt=Dolby Access|Platform=2:6:2|Platform2=GTEQ| "TCP Query User{5A12FD3F-866A-4ABE-AA59-B96A41951216}C:\program files\msfs2020 map enhancement\msfs2020 map enhancement.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\program files\msfs2020 map enhancement\msfs2020 map enhancement.exe|Name=MSFS2020 Map Enhancement|Desc=MSFS2020 Map Enhancement|Defer=User| "UDP Query User{28422A20-FB39-4425-AF18-CA14AC88E5CD}C:\program files\msfs2020 map enhancement\msfs2020 map enhancement.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\program files\msfs2020 map enhancement\msfs2020 map enhancement.exe|Name=MSFS2020 Map Enhancement|Desc=MSFS2020 Map Enhancement|Defer=User| "{FBA858C0-808A-4B17-A482-28B76C25933F}"=v2.30|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=Xbox Game Bar|Desc=Xbox Game Bar|LUOwn=S-1-5-21-3835695913-52790398-83466441-1001|AppPkgId=S-1-15-2-1714399563-1326177402-2048222277-143663168-2151391019-765408921-4098702777|EmbedCtxt=Xbox Game Bar|Platform=2:6:2|Platform2=GTEQ| "{B01AD76E-62EF-4FC7-A6AF-14997CFD0EA8}"=v2.30|Action=Allow|Active=TRUE|Dir=In|Profile=Domain|Profile=Private|Profile=Public|Name=Xbox Game Bar|Desc=Xbox Game Bar|LUOwn=S-1-5-21-3835695913-52790398-83466441-1001|AppPkgId=S-1-15-2-1714399563-1326177402-2048222277-143663168-2151391019-765408921-4098702777|EmbedCtxt=Xbox Game Bar|Platform=2:6:2|Platform2=GTEQ|Edge=TRUE| "TCP Query User{8F457BE4-F0E6-4EA5-809A-4FD4CDA618FF}E:\games\nouveau dossier\efootball pes 2021\pes2021.exe"=v2.10|Action=Block|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=E:\games\nouveau dossier\efootball pes 2021\pes2021.exe|Name=eFootball PES 2021 SEASON UPDATE|Desc=eFootball PES 2021 SEASON UPDATE| "UDP Query User{047114C0-2B1E-4C26-B8AB-79033177D163}E:\games\nouveau dossier\efootball pes 2021\pes2021.exe"=v2.10|Action=Block|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=E:\games\nouveau dossier\efootball pes 2021\pes2021.exe|Name=eFootball PES 2021 SEASON UPDATE|Desc=eFootball PES 2021 SEASON UPDATE| "{2F303062-183A-43E2-A8EB-3A1FE128A421}"=v2.30|Action=Allow|Active=TRUE|Dir=In|App=C:\Program Files (x86)\Navigraph\FMS Data Manager\NGFMSAgent.exe|Name=Navigraph FMS Data Agent| "{53AC295F-8001-4955-8C3F-C1F4E7BBE1F0}"=v2.30|Action=Allow|Active=TRUE|Dir=In|App=C:\Program Files (x86)\Navigraph\FMS Data Manager\NGFMSManager.exe|Name=Navigraph FMS Data Manager| "TCP Query User{26405FD8-EC6E-4E23-B30C-5B1A5A7F6820}C:\users\gband\documents\neofly\neofly.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\users\gband\documents\neofly\neofly.exe|Name=neofly.exe|Desc=neofly.exe|Defer=User| "UDP Query User{5EC8CEC9-B3E2-4525-B05D-F7610D67EB69}C:\users\gband\documents\neofly\neofly.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\users\gband\documents\neofly\neofly.exe|Name=neofly.exe|Desc=neofly.exe|Defer=User| "TCP Query User{EF1E29AC-4320-4753-8EFC-2489927CD20A}C:\program files (x86)\pushback express msfs\pushback express_x64.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\program files (x86)\pushback express msfs\pushback express_x64.exe|Name=Pushback Express|Desc=Pushback Express|Defer=User| "UDP Query User{EBE7EA7D-B832-453E-BDE4-A1066DB4A311}C:\program files (x86)\pushback express msfs\pushback express_x64.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\program files (x86)\pushback express msfs\pushback express_x64.exe|Name=Pushback Express|Desc=Pushback Express|Defer=User| "{B3D1BAEA-1A75-4FCD-9CAB-EEE4E30C84D8}"=v2.30|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=OneNote for Windows 10|Desc=OneNote for Windows 10|LUOwn=S-1-5-21-3835695913-52790398-83466441-1001|AppPkgId=S-1-15-2-3445883232-1224167743-206467785-1580939083-2750001491-3097792036-3019341970|EmbedCtxt=OneNote for Windows 10|Platform=2:6:2|Platform2=GTEQ| "{5E6C4A41-7B37-4812-9761-6F4B1F3EA15E}"=v2.30|Action=Allow|Active=TRUE|Dir=In|Profile=Domain|Profile=Private|Name=OneNote for Windows 10|Desc=OneNote for Windows 10|LUOwn=S-1-5-21-3835695913-52790398-83466441-1001|AppPkgId=S-1-15-2-3445883232-1224167743-206467785-1580939083-2750001491-3097792036-3019341970|EmbedCtxt=OneNote for Windows 10|Platform=2:6:2|Platform2=GTEQ| "TCP Query User{24599342-A4A1-49F3-89F3-92909DBF8F45}C:\program files (x86)\opentrack\opentrack.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\program files (x86)\opentrack\opentrack.exe|Name=opentrack|Desc=opentrack|Defer=User| "UDP Query User{6DA80F49-EA8F-463B-B242-66609A260CD4}C:\program files (x86)\opentrack\opentrack.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\program files (x86)\opentrack\opentrack.exe|Name=opentrack|Desc=opentrack|Defer=User| "TCP Query User{5C4BC53E-6025-49D7-B3C0-9FFDD73B2B1F}C:\users\gband\appdata\local\programs\sky4sim pad\sky4sim pad.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\users\gband\appdata\local\programs\sky4sim pad\sky4sim pad.exe|Name=sky4sim pad.exe|Desc=sky4sim pad.exe|Defer=User| "UDP Query User{E68E0486-730E-4E39-9952-3BDCEB606D43}C:\users\gband\appdata\local\programs\sky4sim pad\sky4sim pad.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\users\gband\appdata\local\programs\sky4sim pad\sky4sim pad.exe|Name=sky4sim pad.exe|Desc=sky4sim pad.exe|Defer=User| "TCP Query User{62BBE2A8-A42A-43BA-9589-C867A5985604}D:\mfs2020\ivao\pilotcore\pilot_core_fs2020.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=D:\mfs2020\ivao\pilotcore\pilot_core_fs2020.exe|Name=pilot_core_fs2020|Desc=pilot_core_fs2020|Defer=User| "UDP Query User{197AE013-03C1-4BA3-AE50-BB6D97E79C6C}D:\mfs2020\ivao\pilotcore\pilot_core_fs2020.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=D:\mfs2020\ivao\pilotcore\pilot_core_fs2020.exe|Name=pilot_core_fs2020|Desc=pilot_core_fs2020|Defer=User| "TCP Query User{DDDEB0F5-BC26-4D1A-BF05-FC2D843AF49B}C:\users\gband\appdata\local\programs\volanta\volanta.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\users\gband\appdata\local\programs\volanta\volanta.exe|Name=volanta.exe|Desc=volanta.exe|Defer=User| "UDP Query User{81BF60D0-521D-4ADF-87AC-BCD991149B8E}C:\users\gband\appdata\local\programs\volanta\volanta.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\users\gband\appdata\local\programs\volanta\volanta.exe|Name=volanta.exe|Desc=volanta.exe|Defer=User| "TCP Query User{AB650137-83EC-4518-9376-13F213EEAA04}C:\users\gband\appdata\local\simtoolkitpro\app-0.8.12\simtoolkitpro.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\users\gband\appdata\local\simtoolkitpro\app-0.8.12\simtoolkitpro.exe|Name=simtoolkitpro.exe|Desc=simtoolkitpro.exe|Defer=User| "UDP Query User{45895506-9D36-4521-85FD-B576C7111984}C:\users\gband\appdata\local\simtoolkitpro\app-0.8.12\simtoolkitpro.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\users\gband\appdata\local\simtoolkitpro\app-0.8.12\simtoolkitpro.exe|Name=simtoolkitpro.exe|Desc=simtoolkitpro.exe|Defer=User| "TCP Query User{EAED144A-40CD-42B2-BD71-C47FAF902DBB}C:\users\gband\appdata\local\apps\2.0\lk0qaa7c.x1d\6w48n25k.tvn\neof..tion_0000000000000000_0003.000d_9b30a95929896b03\neofly.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\users\gband\appdata\local\apps\2.0\lk0qaa7c.x1d\6w48n25k.tvn\neof..tion_0000000000000000_0003.000d_9b30a95929896b03\neofly.exe|Name=neofly.exe|Desc=neofly.exe|Defer=User| "UDP Query User{D4EFB63B-6C2B-4FEB-8236-218E5C45C2C0}C:\users\gband\appdata\local\apps\2.0\lk0qaa7c.x1d\6w48n25k.tvn\neof..tion_0000000000000000_0003.000d_9b30a95929896b03\neofly.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\users\gband\appdata\local\apps\2.0\lk0qaa7c.x1d\6w48n25k.tvn\neof..tion_0000000000000000_0003.000d_9b30a95929896b03\neofly.exe|Name=neofly.exe|Desc=neofly.exe|Defer=User| "{CAD61E49-8DE9-49E2-B9BF-3D5D032F00EE}"=v2.30|Action=Allow|Active=TRUE|Dir=In|Protocol=17|LPort=5353|App=C:\Program Files\Google\Chrome\Application\chrome.exe|Name=Google Chrome (mDNS-In)|Desc=Règle de trafic entrant pour Google Chrome autorisant le trafic mDNS|EmbedCtxt=Google Chrome| "TCP Query User{15AD865E-9320-48A5-831E-D24EB39AD280}E:\games\nouveau dossier\cyberpunk 2077\bin\x64\cyberpunk2077.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=E:\games\nouveau dossier\cyberpunk 2077\bin\x64\cyberpunk2077.exe|Name=Cyberpunk 2077|Desc=Cyberpunk 2077|Defer=User| "UDP Query User{BD7E6D92-FC26-4F7E-B9C2-A6EAFDC8B7F8}E:\games\nouveau dossier\cyberpunk 2077\bin\x64\cyberpunk2077.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=E:\games\nouveau dossier\cyberpunk 2077\bin\x64\cyberpunk2077.exe|Name=Cyberpunk 2077|Desc=Cyberpunk 2077|Defer=User| "{9137F8DA-96B8-4EBC-84F6-A242DC4305A8}"=v2.30|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=E:\Games\Nouveau dossier\bfvTrial.exe|Name=Battlefield™ V Trial (x64)| "{7B891185-E3C9-460A-A5A6-66D5F3624A65}"=v2.30|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=E:\Games\Nouveau dossier\bfvTrial.exe|Name=Battlefield™ V Trial (x64)| "{10591A27-1758-4881-AB1D-D4296BA86343}"=v2.30|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=E:\Games\Nouveau dossier\bfv.exe|Name=Battlefield™ V (x64)| "{320EA5D1-AD86-4276-9ADF-9DD601B0691F}"=v2.30|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=E:\Games\Nouveau dossier\bfv.exe|Name=Battlefield™ V (x64)| "{E93B808C-C49B-4A37-B8DB-201A4EA29F3E}"=v2.30|Action=Allow|Active=TRUE|Dir=In|Protocol=17|LPort=5353|App=C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe|Name=Microsoft Edge (mDNS-In)|Desc=Règle de trafic entrant pour Microsoft Edge pour autoriser le trafic mDNS.|EmbedCtxt=Microsoft Edge| ---------- | Control\Class [HKLM\SYSTEM\CurrentControlSet\Control\Class\{05f5cfe2-4733-4950-a6bb-07aad01a3a84}] : (XboxComposite) [] -> @dc1-controller.inf,%ClassName%;Xbox Peripherals [HKLM\SYSTEM\CurrentControlSet\Control\Class\{1264760f-a5c8-4bfe-b314-d56a7b44a362}] : (DXGKrnl) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{13e42dfa-85d9-424d-8646-28a70f864f9c}] : (RemotePosDevice) [] -> @remoteposdrv.inf,%ClassName%;POS Remote Device [HKLM\SYSTEM\CurrentControlSet\Control\Class\{14b62f50-3f15-11dd-ae16-0800200c9a66}] : (DigitalMediaDevices) [] -> @digitalmediadevice.inf,%ClassName%;Digital Media Devices [HKLM\SYSTEM\CurrentControlSet\Control\Class\{152cecc0-ae87-4fb2-811f-f20a0f636b7b}] : (THRUSTMASTER) [] -> @oem41.inf,%ClassName%;Thrustmaster Devices [HKLM\SYSTEM\CurrentControlSet\Control\Class\{1ed2bbf9-11f0-4084-b21f-ad83a8e6dcdc}] : (PrintQueue) [] -> @printqueue.inf,%ClassName%;Print queues [HKLM\SYSTEM\CurrentControlSet\Control\Class\{25dbce51-6c8f-4a72-8a6d-b54c2b4fc835}] : (WCEUSBS) [] -> @%SystemRoot%\System32\SysClass.Dll,-3026 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{268c95a1-edfe-11d3-95c3-0010dc4050a5}] : (SecurityAccelerator) [] -> @c_sslaccel.inf,%ClassName%;Security accelerators [HKLM\SYSTEM\CurrentControlSet\Control\Class\{2a9fe532-0cdc-44f9-9827-76192f2ca2fb}] : (HidMsr) [] -> @c_magneticstripereader.inf,%ClassName%;POS HID Magnetic Stripe Reader [HKLM\SYSTEM\CurrentControlSet\Control\Class\{2db15374-706e-4131-a0c7-d7c78eb0289a}] : (SystemRecovery) [] -> @c_fssystemrecovery.inf,%ClassDesc%;FS System recovery filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{2ea9b43f-3045-43b5-80f2-fd06c55fbb90}] : (vhdmp) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{3163c566-d381-4467-87bc-a65a18d5b648}] : (fvevol) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{3163c566-d381-4467-87bc-a65a18d5b649}] : (fvevol) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{33be9c2f-85f3-4f17-8487-34f9d1f5f229}] : (GuiHidUsbDevLowerTFH) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{36fc9e60-c465-11cf-8056-444553540000}] : (USB) [] -> @%SystemRoot%\System32\SysClass.Dll,-3025 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{3e3f0674-c83c-4558-bb26-9820e1eba5c5}] : (ContentScreener) [] -> @c_fscontentscreener.inf,%ClassDesc%;FS Content screener filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{43675d81-502a-4a82-9f84-b75f418c5dea}] : (Media Center Extender) [] -> @c_mcx.inf,%ClassDesc%;Media Center Extenders [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4658ee7e-f050-11d1-b6bd-00c04fa372a7}] : (PnpPrinters) [] -> @%SystemRoot%\system32\ntprint.dll,-1300 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{48721b56-6795-11d2-b1a8-0080c72e74a2}] : (Dot4) [] -> @%SystemRoot%\system32\sysclass.dll,-3023 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{48d3ebc4-4cf8-48ff-b869-9c68ad42eb9f}] : (Replication) [] -> @c_fsreplication.inf,%ClassDesc%;FS Replication filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{49ce6ac8-6f86-11d2-b1e5-0080c72e74a2}] : (Dot4Print) [] -> @%SystemRoot%\system32\sysclass.dll,-3024 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e965-e325-11ce-bfc1-08002be10318}] : (CDROM) [] -> @%SystemRoot%\System32\StorProp.dll,-17001 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e966-e325-11ce-bfc1-08002be10318}] : (Computer) [] -> @%SystemRoot%\System32\SysClass.dll,-3000 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e967-e325-11ce-bfc1-08002be10318}] : (DiskDrive) [] -> @c_diskdrive.inf,%ClassDesc%;Disk drives [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e968-e325-11ce-bfc1-08002be10318}] : (Display) [] -> @c_display.inf,%ClassDesc%;Display adapters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e969-e325-11ce-bfc1-08002be10318}] : (FDC) [] -> @%SystemRoot%\System32\SysClass.Dll,-3013 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e96a-e325-11ce-bfc1-08002be10318}] : (HDC) [] -> @%SystemRoot%\System32\SysClass.Dll,-3001 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e96b-e325-11ce-bfc1-08002be10318}] : (Keyboard) [] -> @%SystemRoot%\System32\SysClass.Dll,-3002 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e96c-e325-11ce-bfc1-08002be10318}] : (MEDIA) [] -> @c_media.inf,%ClassDesc%;Sound, video and game controllers [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}] : (Modem) [] -> @%SystemRoot%\System32\mdminst.dll,-14100 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e96e-e325-11ce-bfc1-08002be10318}] : (Monitor) [] -> @c_monitor.inf,%ClassDesc%;Monitors [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e96f-e325-11ce-bfc1-08002be10318}] : (Mouse) [] -> @%SystemRoot%\System32\SysClass.Dll,-3004 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e970-e325-11ce-bfc1-08002be10318}] : (MTD) [] -> @%SystemRoot%\System32\SysClass.Dll,-3021 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e971-e325-11ce-bfc1-08002be10318}] : (MultiFunction) [] -> @%SystemRoot%\System32\SysClass.Dll,-3014 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e972-e325-11ce-bfc1-08002be10318}] : (Net) [] -> @%SystemRoot%\System32\NetCfgx.dll,-1502 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e973-e325-11ce-bfc1-08002be10318}] : (NetClient) [] -> @%SystemRoot%\System32\NetCfgx.dll,-1504 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e974-e325-11ce-bfc1-08002be10318}] : (NetService) [] -> @%SystemRoot%\System32\NetCfgx.dll,-1505 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e975-e325-11ce-bfc1-08002be10318}] : (NetTrans) [] -> @%SystemRoot%\System32\NetCfgx.dll,-1503 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e977-e325-11ce-bfc1-08002be10318}] : (PCMCIA) [] -> @%SystemRoot%\System32\SysClass.Dll,-3010 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e978-e325-11ce-bfc1-08002be10318}] : (Ports) [] -> @%SystemRoot%\System32\msports.dll,-10000 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e979-e325-11ce-bfc1-08002be10318}] : (Printer) [] -> @%SystemRoot%\system32\ntprint.dll,-1004 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e97b-e325-11ce-bfc1-08002be10318}] : (SCSIAdapter) [] -> @%SystemRoot%\System32\SysClass.Dll,-3005 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e97d-e325-11ce-bfc1-08002be10318}] : (System) [] -> @%SystemRoot%\System32\SysClass.Dll,-3008 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e97e-e325-11ce-bfc1-08002be10318}] : (Unknown) [] -> @%SystemRoot%\System32\SysClass.Dll,-3009 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e980-e325-11ce-bfc1-08002be10318}] : (FloppyDisk) [] -> @%SystemRoot%\System32\SysClass.Dll,-3015 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4fc9541c-0fe6-4480-a4f6-9495a0d17cd2}] : (HidLineDisplay) [] -> @c_linedisplay.inf,%ClassName%;POS Line Display [HKLM\SYSTEM\CurrentControlSet\Control\Class\{50127dc3-0f36-415e-a6cc-4cb3be910b65}] : (Processor) [] -> @c_processor.inf,%ClassDesc%;Processors [HKLM\SYSTEM\CurrentControlSet\Control\Class\{50906cb8-ba12-11d1-bf5d-0000f805f530}] : (MultiPortSerial) [] -> @%SystemRoot%\system32\sysclass.dll,-3022 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{5099944a-f6b9-4057-a056-8c550228544c}] : (Memory) [] -> @%SystemRoot%\System32\SysClass.Dll,-3018 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{50dd5230-ba8a-11d1-bf5d-0000f805f530}] : (SmartCardReader) [] -> @%SystemRoot%\System32\StorProp.dll,-17002 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{5175d334-c371-4806-b3ba-71fd53c9258d}] : (Sensor) [] -> @%SystemRoot%\system32\SensorsCpl.dll,-10000 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{533c5b84-ec70-11d2-9505-00c04f79deaf}] : (VolumeSnapshot) [] -> @%SystemRoot%\System32\SysClass.Dll,-3011 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{53487c23-680f-4585-acc3-1f10d6777e82}] : (SmrDisk) [] -> @c_smrdisk.inf,%ClassDesc%;Shingled magnetic recording disks [HKLM\SYSTEM\CurrentControlSet\Control\Class\{53966cb1-4d46-4166-bf23-c522403cd495}] : (ScmDisk) [] -> @c_scmdisk.inf,%ClassDesc%;Persistent memory disks [HKLM\SYSTEM\CurrentControlSet\Control\Class\{53b3cf03-8f5a-4788-91b6-d19ed9fcccbf}] : (SmrVolume) [] -> @c_smrvolume.inf,%ClassDesc%;Shingled magnetic recording volumes [HKLM\SYSTEM\CurrentControlSet\Control\Class\{53ccb149-e543-4c84-b6e0-bce4f6b7e806}] : (ScmVolume) [] -> @c_scmvolume.inf,%ClassDesc%;Storage Class Memory volumes [HKLM\SYSTEM\CurrentControlSet\Control\Class\{53d29ef7-377c-4d14-864b-eb3a85769359}] : (Biometric) [] -> @%SystemRoot%\System32\SysClass.DLL,-3028 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{5630831c-06c9-4856-b327-f5d32586e060}] : (Proximity) [] -> @c_proximity.inf,%ClassDesc%;Proximity devices [HKLM\SYSTEM\CurrentControlSet\Control\Class\{5989fce8-9cd0-467d-8a6a-5419e31529d4}] : (AudioProcessingObject) [] -> @c_apo.inf,%ClassDesc%;Audio Processing Objects (APOs) [HKLM\SYSTEM\CurrentControlSet\Control\Class\{5aea001d-9372-4ed7-97f3-b79bf15a53c5}] : (OposLegacyDevice) [] -> @oposdrv.inf,%ClassName%;OPOS Legacy Device [HKLM\SYSTEM\CurrentControlSet\Control\Class\{5c4c3332-344d-483c-8739-259e934c9cc8}] : (SoftwareComponent) [] -> @c_swcomponent.inf,%ClassDesc%;Software components [HKLM\SYSTEM\CurrentControlSet\Control\Class\{5d1b9aaa-01e2-46af-849f-272b3f324c46}] : (FSFilterSystem) [] -> @c_fssystem.inf,%ClassDesc%;FS System filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{62f9c741-b25a-46ce-b54c-9bccce08b6f2}] : (SoftwareDevice) [] -> @c_swdevice.inf,%ClassDesc%;Software devices [HKLM\SYSTEM\CurrentControlSet\Control\Class\{645ad99b-1344-4316-837a-08a3e73db222}] : (PerceptionSimulation) [] -> @PerceptionSimulationSixDof.inf,%ClassName%;Perception Simulation Controllers [HKLM\SYSTEM\CurrentControlSet\Control\Class\{6a0a8e78-bba6-4fc4-a709-1e33cd09d67e}] : (PhysicalQuotaManagement) [] -> @c_fsphysicalquotamgmt.inf,%ClassDesc%;FS Physical quota management filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{6bdd1fc1-810f-11d0-bec7-08002be2092f}] : (1394) [] -> @%SystemRoot%\System32\SysClass.Dll,-3016 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{6bdd1fc5-810f-11d0-bec7-08002be2092f}] : (Infrared) [] -> @%SystemRoot%\System32\NetCfgx.dll,-1501 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{6bdd1fc6-810f-11d0-bec7-08002be2092f}] : (Image) [] -> @%SystemRoot%\system32\sti_ci.dll,-52 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{6d807884-7d21-11cf-801c-08002be10318}] : (TapeDrive) [] -> @%SystemRoot%\System32\SysClass.Dll,-3006 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{6fae73b7-b735-4b50-a0da-0dc2484b1f1a}] : (BasicDisplay) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{71a27cdd-812a-11d0-bec7-08002be2092f}] : (Volume) [] -> @c_volume.inf,%ClassDesc%;Storage volumes [HKLM\SYSTEM\CurrentControlSet\Control\Class\{71aa14f8-6fad-4622-ad77-92bb9d7e6947}] : (ContinuousBackup) [] -> @c_fscontinuousbackup.inf,%ClassDesc%;FS Continuous backup filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{72631e54-78a4-11d0-bcf7-00aa00b7b32a}] : (Battery) [] -> @%SystemRoot%\system32\powrprof.dll,-611 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{745a17a0-74d3-11d0-b6fe-00a0c90f57da}] : (HIDClass) [] -> @%SystemRoot%\System32\hid.dll,-101 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{772e18f2-8925-4229-a5ac-6453cb482fda}] : (HidCashDrawer) [] -> @c_cashdrawer.inf,%ClassName%;POS Cash Drawer [HKLM\SYSTEM\CurrentControlSet\Control\Class\{7ebefbc0-3200-11d2-b4c2-00a0c9697d07}] : (61883) [] -> @%SystemRoot%\System32\SysClass.Dll,-3019 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{81c87465-de07-4efc-9d93-61e891d52fd2}] : (RdpVideoMiniport) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{8503c911-a6c7-4919-8f79-5028f5866b0c}] : (QuotaManagement) [] -> @c_fsquotamgmt.inf,%ClassDesc%;FS Quota management filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{87ef9ad1-8f70-49ee-b215-ab1fcadcbe3c}] : (NetDriver) [] -> @c_netdriver.inf,%ClassDesc%;Universal Network Drivers [HKLM\SYSTEM\CurrentControlSet\Control\Class\{88a1c342-4539-11d3-b88d-00c04fad5171}] : (TS_Generic) [] -> @ts_generic.inf,%TSClassName%;Generic Remote Desktop devices [HKLM\SYSTEM\CurrentControlSet\Control\Class\{88bae032-5a81-49f0-bc3d-a4ff138216d6}] : (USBDevice) [] -> @%SystemRoot%\System32\SysClass.Dll,-3029 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{89786ff1-9c12-402f-9c9e-17753c7f4375}] : (CopyProtection) [] -> @c_fscopyprotection.inf,%ClassDesc%;FS Copy protection filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{8ecc055d-047f-11d1-a537-0000f8753ed1}] : (LegacyDriver) [] -> @%SystemRoot%\System32\SysClass.Dll,-3003 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{990a2bd7-e738-46c7-b26f-1cf8fb9f1391}] : (SmartCard) [] -> @%SystemRoot%\System32\SysClass.DLL,-3031 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{9da2b80f-f89f-4a49-a5c2-511b085b9e8a}] : (EhStorSilo) [] -> @rawsilo.inf,%ClassName%;IEEE 1667 silo and control devices [HKLM\SYSTEM\CurrentControlSet\Control\Class\{a0a588a4-c46f-4b37-b7ea-c82fe89870c6}] : (SDHost) [] -> @%SystemRoot%\System32\SysClass.Dll,-3012 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{a0a701c0-a511-42ff-aa6c-06dc0395576f}] : (Encryption) [] -> @c_fsencryption.inf,%ClassDesc%;FS Encryption filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{a3e32dba-ba89-4f17-8386-2d0127fbd4cc}] : (rdpbus) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{a73c93f1-9727-4d1d-ace1-0e333ba4e7db}] : (nvlddmkm) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{aa018edf-4915-415e-9c17-d7ebec8917d2}] : (NvModuleTracker) [] -> @oem48.inf,%ClassName%;NvModuleTracker [HKLM\SYSTEM\CurrentControlSet\Control\Class\{b1d1a169-c54f-4379-81db-bee7d88d7454}] : (AntiVirus) [] -> @c_fsantivirus.inf,%ClassDesc%;FS Anti-virus filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{b2728d24-ac56-42db-9e02-8edaf5db652f}] : (RDCamera) [] -> @rdcameradriver.inf,%ClassName%;Remote Desktop Camera devices [HKLM\SYSTEM\CurrentControlSet\Control\Class\{b86dff51-a31e-4bac-b3cf-e8cfe75c9fc2}] : (ActivityMonitor) [] -> @c_fsactivitymonitor.inf,%ClassDesc%;FS Activity monitor filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{bbbe8734-08fa-4966-b6a6-4e5ad010cdd7}] : (USBFunctionController) [] -> @%SystemRoot%\System32\SysClass.Dll,-3030 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{c06ff265-ae09-48f0-812c-16753d7cba83}] : (AVC) [] -> @%SystemRoot%\System32\SysClass.Dll,-3027 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{c166523c-fe0c-4a94-a586-f1a80cfbbf3e}] : (AudioEndpoint) [] -> @audioendpoint.inf,%ClassName%;Audio inputs and outputs [HKLM\SYSTEM\CurrentControlSet\Control\Class\{c243ffbd-3afc-45e9-b3d3-2ba18bc7ebc5}] : (BarcodeScanner) [] -> @c_barcodescanner.inf,%ClassName%;POS Barcode Scanner [HKLM\SYSTEM\CurrentControlSet\Control\Class\{c30ecea0-11ef-4ef9-b02e-6af81e6e65c0}] : (WSDPrintDevice) [] -> @wsdprint.inf,%ClassName%;WSD Print Provider [HKLM\SYSTEM\CurrentControlSet\Control\Class\{c7bc9b22-21f0-4f0d-9bb6-66c229b8cd33}] : (POSPrinter) [] -> @c_receiptprinter.inf,%ClassName%;POS Receipt Printer [HKLM\SYSTEM\CurrentControlSet\Control\Class\{ca3e7ab9-b4c3-4ae6-8251-579ef933890f}] : (Camera) [] -> @c_camera.inf,%ClassDesc%;Cameras [HKLM\SYSTEM\CurrentControlSet\Control\Class\{cdcf0939-b75b-4630-bf76-80f7ba655884}] : (CFSMetadataServer) [] -> @c_fscfsmetadataserver.inf,%ClassDesc%;FS CFS metadata server filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{ce5939ae-ebde-11d0-b181-0000f8753ec4}] : (MediumChanger) [] -> @%SystemRoot%\System32\StorProp.dll,-17003 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{d02bc3da-0c8e-4945-9bd5-f1883c226c8c}] : (SecurityEnhancer) [] -> @c_fssecurityenhancer.inf,%ClassDesc%;FS Security enhancer filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{d421b08e-6d16-41ca-9c4d-9147e5ac98e0}] : (Miracast) [] -> @miradisp.inf,%ClassName%;Miracast display devices [HKLM\SYSTEM\CurrentControlSet\Control\Class\{d48179be-ec20-11d1-b6b8-00c04fa372a7}] : (SBP2) [] -> @%SystemRoot%\System32\SysClass.Dll,-3017 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{d546500a-2aeb-45f6-9482-f4b1799c3177}] : (HSM) [] -> @c_fshsm.inf,%ClassDesc%;FS HSM filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{d612553d-06b1-49ca-8938-e39ef80eb16f}] : (Holographic) [] -> @c_holographic.inf,%ClassName%;Mixed Reality devices [HKLM\SYSTEM\CurrentControlSet\Control\Class\{d61ca365-5af4-4486-998b-9db4734c6ca3}] : (XnaComposite) [] -> @xusb22.inf,%XUSB22.ClassName%;Xbox 360 Peripherals [HKLM\SYSTEM\CurrentControlSet\Control\Class\{d94ee5d8-d189-4994-83d2-f68d7d41b0e6}] : (SecurityDevices) [] -> @%SystemRoot%\System32\SysClass.Dll,-3020 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{db4f6ddd-9c0e-45e4-9597-78dbbad0f412}] : (SmartCardFilter) [] -> @%SystemRoot%\System32\SysClass.DLL,-3032 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{e0cbf06c-cd8b-4647-bb8a-263b43f0f974}] : (Bluetooth) [] -> @%SystemRoot%\system32\bthci.dll,-4001 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{e2f84ce7-8efa-411c-aa69-97454ca4cb57}] : (Extension) [] -> @c_extension.inf,%ClassDesc%;Extensions [HKLM\SYSTEM\CurrentControlSet\Control\Class\{e55fa6f9-128c-4d04-abab-630c74b1453a}] : (Infrastructure) [] -> @c_fsinfrastructure.inf,%ClassDesc%;FS Infrastructure filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{e6f1aa1c-7f3b-4473-b2e8-c97d8ac71d53}] : (UCM) [] -> @c_ucm.inf,%ClassDesc%;USB Connector Managers [HKLM\SYSTEM\CurrentControlSet\Control\Class\{eec5ad98-8080-425f-922a-dabf3de3f69a}] : (WPD) [] -> @%SystemRoot%\System32\wpd_ci.dll,-101 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{f01a9d53-3ff6-48d2-9f97-c8a7004be10c}] : (ComputeAccelerator) [] -> @c_computeaccelerator.inf,%ClassDesc%;Compute accelerators [HKLM\SYSTEM\CurrentControlSet\Control\Class\{f2e7dd72-6468-4e36-b6f1-6488f42c1b52}] : (Firmware) [] -> @c_firmware.inf,%ClassDesc%;Firmware [HKLM\SYSTEM\CurrentControlSet\Control\Class\{f3586baf-b5aa-49b5-8d6c-0569284c639f}] : (Compression) [] -> @c_fscompression.inf,%ClassDesc%;FS Compression filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{f75a86c0-10d8-4c3a-b233-ed60e4cdfaac}] : (Virtualization) [] -> @c_fsvirtualization.inf,%ClassDesc%;FS Virtualization filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{f8ecafa6-66d1-41a5-899b-66585d7216b7}] : (OpenFileBackup) [] -> @c_fsopenfilebackup.inf,%ClassDesc%;FS Open file backup filters [HKLM\SYSTEM\CurrentControlSet\Control\Class\{fe8f1572-c67a-48c0-bbac-0b5c6d66cafb}] : (Undelete) [] -> @c_fsundelete.inf,%ClassDesc%;FS Undelete filters [HKLM\SYSTEM\CurrentControlSet\Control\Els\Services\{2D64B439-6CAF-4f6b-B688-E5D0F4FAA7D7}] : (Script Detection) [@elscore.dll,-2] -> ElsLad.dll (Copyright (c) Microsoft Corporation.) [HKLM\SYSTEM\CurrentControlSet\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}] : (Transliteration) [@elscore.dll,-5] -> elstrans.dll (Copyright (c) Microsoft Corporation.) [HKLM\SYSTEM\CurrentControlSet\Control\Els\Services\{CF7E00B1-909B-4d95-A8F4-611F7C377702}] : (Language Detection) [@elscore.dll,-1] -> ElsLad.dll (Copyright (c) Microsoft Corporation.) ---------- | Loaded modules (whitelist) [08/10/2021 21:32:01] - (0.0.0.0) - ( -) - C:\WINDOWS\System32\Drivers\CimFS.SYS [09/02/2022 23:55:57] - (30.0.15.1165) - (NVIDIA Corporation - NVIDIA Windows Kernel Mode Driver, Version 511.65) - C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_31a2adf8c49e7799\nvlddmkm.sys [10/02/2022 00:02:25] - (1.46.831.832) - (NVIDIA Corporation - NVIDIA PPC Function Driver.) - C:\WINDOWS\System32\DriverStore\FileRepository\nvppc.inf_amd64_25fb711132593303\UcmCxUcsiNvppc.sys [10/07/2021 17:43:44] - (4.39.0.0) - (NVIDIA Corporation - NVIDIA Virtual Audio Driver) - C:\WINDOWS\system32\drivers\nvvad64v.sys [10/07/2021 17:43:45] - (100.0.0.0) - (NVIDIA Corporation - Process and module monitoring driver) - C:\WINDOWS\System32\drivers\NvModuleTracker.sys [10/07/2021 17:43:45] - (304.0.0.0) - (NVIDIA Corporation - Virtual USB Host Controller driver) - C:\WINDOWS\System32\drivers\nvvhci.sys [14/09/2015 18:58:36] - (1.0.0.103) - (Scarlet.Crush Productions - Scp Virtual Bus Driver) - C:\WINDOWS\System32\drivers\ScpVBus.sys [10/07/2021 17:43:44] - (1.3.39.3) - (NVIDIA Corporation - NVIDIA HDMI Audio Driver) - C:\WINDOWS\system32\drivers\nvhda64v.sys [14/01/2022 17:02:18] - (1.1.5.0) - (© Guillemot R&D, 2020. - Guillemot Hid Usb Lower Filter Driver (TFH Series)) - C:\WINDOWS\System32\Drivers\GuiHidUsbDevLowerTFH.sys ---------- | Services | 0 : Starting up | 1 : System | 2 : Automatic | 3 : Manual | 4 : Disabled | R : Running service | S : Stopped service S0 - [Kernel Driver] - 3ware (3ware) -> C:\WINDOWS\system32\drivers\3ware.sys - AcceptPause : False - AcceptStop : False - DesktopInteract : False R0 - [Kernel Driver] - ACPI (Pilote ACPI Microsoft) -> C:\WINDOWS\system32\drivers\ACPI.sys - AcceptPause : False - AcceptStop : True - DesktopInteract : False R0 - [Kernel Driver] - acpiex (Microsoft ACPIEx Driver) -> C:\WINDOWS\system32\Drivers\acpiex.sys - AcceptPause : False - AcceptStop : True - DesktopInteract : False S0 - [Kernel Driver] - ADP80XX (ADP80XX) -> C:\WINDOWS\system32\drivers\ADP80XX.SYS - AcceptPause : False - AcceptStop : False - DesktopInteract : False R0 - [Kernel Driver] - amdkmpfd (AMD PCI Root Bus Lower Filter) -> C:\WINDOWS\system32\drivers\amdkmpfd.sys - AcceptPause : False - AcceptStop : True - DesktopInteract : False R0 - [Kernel Driver] - amdpsp (AMD PSP Service) -> C:\WINDOWS\system32\drivers\amdpsp.sys - AcceptPause : False - AcceptStop : True - DesktopInteract : False S0 - [Kernel Driver] - amdsata (amdsata) -> C:\WINDOWS\system32\drivers\amdsata.sys - AcceptPause : False - AcceptStop : False - DesktopInteract : False S0 - [Kernel Driver] - amdsbs (amdsbs) -> C:\WINDOWS\system32\drivers\amdsbs.sys - AcceptPause : False - AcceptStop : False - DesktopInteract : False S0 - [Kernel Driver] - amdxata (amdxata) -> C:\WINDOWS\system32\drivers\amdxata.sys - AcceptPause : False - AcceptStop : False - DesktopInteract : False S0 - [Kernel Driver] - arcsas (Pilote miniport Storport Adaptec SAS/SATA-II RAID) -> C:\WINDOWS\system32\drivers\arcsas.sys - AcceptPause : False - AcceptStop : False - DesktopInteract : False S0 - [Kernel Driver] - atapi (Canal IDE) -> C:\WINDOWS\system32\drivers\atapi.sys - AcceptPause : False - AcceptStop : False - DesktopInteract : False S0 - [Kernel Driver] - b06bdrv (Carte réseau QLogic VBD) -> C:\WINDOWS\system32\drivers\bxvbda.sys - AcceptPause : False - AcceptStop : False - DesktopInteract : False S0 - [Kernel Driver] - bttflt (Filtre Microsoft Hyper-V VHDPMEM BTT) -> C:\WINDOWS\system32\drivers\bttflt.sys - AcceptPause : False - AcceptStop : False - DesktopInteract : False S0 - [Kernel Driver] - cht4iscsi (cht4iscsi) -> C:\WINDOWS\system32\drivers\cht4sx64.sys - AcceptPause : False - AcceptStop : False - DesktopInteract : False R0 - [Kernel Driver] - CLFS (Common Log (CLFS)) -> C:\WINDOWS\system32\drivers\CLFS.sys - AcceptPause : False - AcceptStop : True - DesktopInteract : False R0 - [Kernel Driver] - CNG (CNG) -> C:\WINDOWS\system32\Drivers\cng.sys - AcceptPause : False - AcceptStop : True - DesktopInteract : False R0 - [Kernel Driver] - disk (Pilote de disque) -> C:\WINDOWS\system32\drivers\disk.sys - AcceptPause : False - AcceptStop : True - DesktopInteract : False S0 - [Kernel Driver] - ebdrv (Carte QLogic 10 Gigabit Ethernet VBD) -> C:\WINDOWS\system32\drivers\evbda.sys - AcceptPause : False - AcceptStop : False - DesktopInteract : False R0 - [Kernel Driver] - EhStorClass (Enhanced Storage Filter Driver) -> C:\WINDOWS\system32\drivers\EhStorClass.sys - AcceptPause : False - AcceptStop : True - DesktopInteract : False S0 - [Kernel Driver] - EhStorTcgDrv (Pilote Microsoft pour dispositif de stockage prenant en charge les protocoles IEEE 1667 et TCG) -> C:\WINDOWS\system32\drivers\EhStorTcgDrv.sys - AcceptPause : False - AcceptStop : False - DesktopInteract : False R0 - [File System Driver] - FileInfo (File Information FS MiniFilter) -> C:\WINDOWS\system32\drivers\fileinfo.sys - AcceptPause : False - AcceptStop : True - DesktopInteract : False R0 - [File System Driver] - FltMgr (FltMgr) -> C:\WINDOWS\system32\drivers\fltmgr.sys - AcceptPause : False - AcceptStop : True - DesktopInteract : False R0 - [Kernel Driver] - fvevol (Pilote de filtre de chiffrement de lecteur BitLocker) -> C:\WINDOWS\system32\DRIVERS\fvevol.sys - AcceptPause : False - AcceptStop : True - DesktopInteract : False S0 - [Kernel Driver] - HpSAMD (HpSAMD) -> C:\WINDOWS\system32\drivers\HpSAMD.sys - AcceptPause : False - AcceptStop : False - DesktopInteract : False S0 - [Kernel Driver] - hwpolicy (Hardware Policy Driver) -> C:\WINDOWS\system32\drivers\hwpolicy.sys - AcceptPause : False - AcceptStop : False - DesktopInteract : False S0 - [Kernel Driver] - iaStorAVC (Contrôleur RAID SATA de circuit microprogrammé Intel) -> C:\WINDOWS\system32\drivers\iaStorAVC.sys - AcceptPause : False - AcceptStop : False - DesktopInteract : False S0 - [Kernel Driver] - iaStorV (Contrôleur RAID Intel Windows 7) -> C:\WINDOWS\system32\drivers\iaStorV.sys - AcceptPause : False - AcceptStop : False - DesktopInteract : False S0 - [Kernel Driver] - intelide (intelide) -> C:\WINDOWS\system32\drivers\intelide.sys - AcceptPause : False - AcceptStop : False - DesktopInteract : False R0 - [Kernel Driver] - intelpep (Pilote de plug-in du moteur d’alimentation Intel(R)) -> C:\WINDOWS\system32\drivers\intelpep.sys - AcceptPause : False - AcceptStop : True - DesktopInteract : False R0 - [Kernel Driver] - iorate (Pilote du filtre du taux d’E/S du disque) -> C:\WINDOWS\system32\drivers\iorate.sys - AcceptPause : False - AcceptStop : True - DesktopInteract : False S0 - [Kernel Driver] - isapnp (isapnp) -> C:\WINDOWS\system32\drivers\isapnp.sys - AcceptPause : False - AcceptStop : False - DesktopInteract : False S0 - [Kernel Driver] - ItSas35i (ItSas35i) -> C:\WINDOWS\system32\drivers\ItSas35i.sys - AcceptPause : False - AcceptStop : False - DesktopInteract : False R0 - [Kernel Driver] - KSecDD (KSecDD) -> C:\WINDOWS\system32\Drivers\ksecdd.sys - AcceptPause : False - AcceptStop : True - DesktopInteract : False R0 - [Kernel Driver] - KSecPkg (KSecPkg) -> C:\WINDOWS\system32\Drivers\ksecpkg.sys - AcceptPause : False - AcceptStop : True - DesktopInteract : False S0 - [Kernel Driver] - LSI_SAS (LSI_SAS) -> C:\WINDOWS\system32\drivers\lsi_sas.sys - AcceptPause : False - AcceptStop : False - DesktopInteract : False S0 - [Kernel Driver] - LSI_SAS2i (LSI_SAS2i) -> C:\WINDOWS\system32\drivers\lsi_sas2i.sys - AcceptPause : False - AcceptStop : False - DesktopInteract : False S0 - [Kernel Driver] - LSI_SAS3i (LSI_SAS3i) -> C:\WINDOWS\system32\drivers\lsi_sas3i.sys - AcceptPause : False - AcceptStop : False - DesktopInteract : False S0 - [Kernel Driver] - LSI_SSS (LSI_SSS) -> C:\WINDOWS\system32\drivers\lsi_sss.sys - AcceptPause : False - AcceptStop : False - DesktopInteract : False S0 - [Kernel Driver] - megasas (megasas) -> C:\WINDOWS\system32\drivers\megasas.sys - AcceptPause : False - AcceptStop : False - DesktopInteract : False S0 - [Kernel Driver] - megasas2i (megasas2i) -> C:\WINDOWS\system32\drivers\MegaSas2i.sys - AcceptPause : False - AcceptStop : False - DesktopInteract : False S0 - [Kernel Driver] - megasas35i (megasas35i) -> C:\WINDOWS\system32\drivers\megasas35i.sys - AcceptPause : False - AcceptStop : False - DesktopInteract : False S0 - [Kernel Driver] - megasr (megasr) -> C:\WINDOWS\system32\drivers\megasr.sys - AcceptPause : False - AcceptStop : False - DesktopInteract : False R0 - [Kernel Driver] - mountmgr (Gestionnaire des points de montage) -> C:\WINDOWS\system32\drivers\mountmgr.sys - AcceptPause : False - AcceptStop : True - DesktopInteract : False R0 - [Kernel Driver] - msisadrv (msisadrv) -> C:\WINDOWS\system32\drivers\msisadrv.sys - AcceptPause : False - AcceptStop : True - DesktopInteract : False R0 - [Kernel Driver] - MsSecFlt (Minifiltre du composant Événements de sécurité de Microsoft) -> C:\WINDOWS\system32\drivers\mssecflt.sys - AcceptPause : False - AcceptStop : True - DesktopInteract : False R0 - [File System Driver] - Mup (Mup) -> C:\WINDOWS\system32\Drivers\mup.sys - AcceptPause : False - AcceptStop : True - DesktopInteract : False S0 - [Kernel Driver] - mvumis (mvumis) -> C:\WINDOWS\system32\drivers\mvumis.sys - AcceptPause : False - AcceptStop : False - DesktopInteract : False R0 - [Kernel Driver] - NDIS (Pilote système NDIS) -> C:\WINDOWS\system32\drivers\ndis.sys - AcceptPause : False - AcceptStop : True - DesktopInteract : False S0 - [Kernel Driver] - nvdimm (Pilote de périphérique NVDIMM Microsoft) -> C:\WINDOWS\system32\drivers\nvdimm.sys - AcceptPause : False - AcceptStop : False - DesktopInteract : False S0 - [Kernel Driver] - nvraid (nvraid) -> C:\WINDOWS\system32\drivers\nvraid.sys - AcceptPause : False - AcceptStop : False - DesktopInteract : False S0 - [Kernel Driver] - nvstor (nvstor) -> C:\WINDOWS\system32\drivers\nvstor.sys - AcceptPause : False - AcceptStop : False - DesktopInteract : False R0 - [Kernel Driver] - partmgr (Gestionnaire de partitions) -> C:\WINDOWS\system32\drivers\partmgr.sys - AcceptPause : False - AcceptStop : True - DesktopInteract : False R0 - [Kernel Driver] - pci (Pilote de bus PCI) -> C:\WINDOWS\system32\drivers\pci.sys - AcceptPause : False - AcceptStop : True - DesktopInteract : False S0 - [Kernel Driver] - pciide (pciide) -> C:\WINDOWS\system32\drivers\pciide.sys - AcceptPause : False - AcceptStop : False - DesktopInteract : False S0 - [Kernel Driver] - pcmcia (pcmcia) -> C:\WINDOWS\system32\drivers\pcmcia.sys - AcceptPause : False - AcceptStop : False - DesktopInteract : False R0 - [Kernel Driver] - pcw (Performance Counters for Windows Driver) -> C:\WINDOWS\system32\drivers\pcw.sys - AcceptPause : False - AcceptStop : True - DesktopInteract : False R0 - [Kernel Driver] - pdc (CDP) -> C:\WINDOWS\system32\drivers\pdc.sys - AcceptPause : False - AcceptStop : True - DesktopInteract : False S0 - [Kernel Driver] - percsas2i (percsas2i) -> C:\WINDOWS\system32\drivers\percsas2i.sys - AcceptPause : False - AcceptStop : False - DesktopInteract : False S0 - [Kernel Driver] - percsas3i (percsas3i) -> C:\WINDOWS\system32\drivers\percsas3i.sys - AcceptPause : False - AcceptStop : False - DesktopInteract : False S0 - [Kernel Driver] - pmem (Pilote de disque de mémoire persistante Microsoft) -> C:\WINDOWS\system32\drivers\pmem.sys - AcceptPause : False - AcceptStop : False - DesktopInteract : False S0 - [Kernel Driver] - Ramdisk (Windows RAM Disk Driver) -> C:\WINDOWS\system32\DRIVERS\ramdisk.sys - AcceptPause : False - AcceptStop : False - DesktopInteract : False R0 - [Kernel Driver] - rdyboost (ReadyBoost) -> C:\WINDOWS\system32\drivers\rdyboost.sys - AcceptPause : False - AcceptStop : True - DesktopInteract : False S0 - [Kernel Driver] - sbp2port (Pilote de bus de transport/protocole SBP-2) -> C:\WINDOWS\system32\drivers\sbp2port.sys - AcceptPause : False - AcceptStop : False - DesktopInteract : False S0 - [Kernel Driver] - scmbus (Pilote de bus de mémoire de classe stockage Microsoft) -> C:\WINDOWS\system32\drivers\scmbus.sys - AcceptPause : False - AcceptStop : False - DesktopInteract : False R0 - [Kernel Driver] - SgrmAgent (System Guard Runtime Monitor Agent) -> C:\WINDOWS\system32\drivers\SgrmAgent.sys - AcceptPause : False - AcceptStop : True - DesktopInteract : False S0 - [Kernel Driver] - SiSRaid2 (SiSRaid2) -> C:\WINDOWS\system32\drivers\SiSRaid2.sys - AcceptPause : False - AcceptStop : False - DesktopInteract : False S0 - [Kernel Driver] - SiSRaid4 (SiSRaid4) -> C:\WINDOWS\system32\drivers\sisraid4.sys - AcceptPause : False - AcceptStop : False - DesktopInteract : False S0 - [Kernel Driver] - SmartSAMD (SmartSAMD) -> C:\WINDOWS\system32\drivers\SmartSAMD.sys - AcceptPause : False - AcceptStop : False - DesktopInteract : False R0 - [Kernel Driver] - spaceport (Pilote des espaces de stockage) -> C:\WINDOWS\system32\drivers\spaceport.sys - AcceptPause : False - AcceptStop : True - DesktopInteract : False S0 - [Kernel Driver] - stexstor (stexstor) -> C:\WINDOWS\system32\drivers\stexstor.sys - AcceptPause : False - AcceptStop : False - DesktopInteract : False R0 - [Kernel Driver] - storahci (Lecteur AHCI SATA Microsoft standard) -> C:\WINDOWS\system32\drivers\storahci.sys - AcceptPause : False - AcceptStop : True - DesktopInteract : False S0 - [Kernel Driver] - storflt (Accélérateur de stockage Microsoft Hyper-V) -> C:\WINDOWS\system32\drivers\vmstorfl.sys - AcceptPause : False - AcceptStop : False - DesktopInteract : False S0 - [Kernel Driver] - stornvme (Pilote NVM Express standard de Microsoft) -> C:\WINDOWS\system32\drivers\stornvme.sys - AcceptPause : False - AcceptStop : False - DesktopInteract : False S0 - [Kernel Driver] - storufs (Pilote Universal Flash Storage (UFS) Microsoft) -> C:\WINDOWS\system32\drivers\storufs.sys - AcceptPause : False - AcceptStop : False - DesktopInteract : False S0 - [Kernel Driver] - storvsc (storvsc) -> C:\WINDOWS\system32\drivers\storvsc.sys - AcceptPause : False - AcceptStop : False - DesktopInteract : False R0 - [Kernel Driver] - Tcpip (Pilote pour protocole TCP/IP) -> C:\WINDOWS\system32\drivers\tcpip.sys - AcceptPause : False - AcceptStop : True - DesktopInteract : False R0 - [Kernel Driver] - Telemetry (Service de télémétrie Intel(R)) -> C:\WINDOWS\system32\drivers\IntelTA.sys - AcceptPause : False - AcceptStop : True - DesktopInteract : False R0 - [Kernel Driver] - vdrvroot (Énumérateur de lecteur virtuel Microsoft) -> C:\WINDOWS\system32\drivers\vdrvroot.sys - AcceptPause : False - AcceptStop : True - DesktopInteract : False S0 - [Kernel Driver] - vmbus (Bus VMBus) -> C:\WINDOWS\system32\drivers\vmbus.sys - AcceptPause : False - AcceptStop : False - DesktopInteract : False R0 - [Kernel Driver] - volmgr (Pilote du gestionnaire de volumes) -> C:\WINDOWS\system32\drivers\volmgr.sys - AcceptPause : False - AcceptStop : True - DesktopInteract : False R0 - [Kernel Driver] - volmgrx (Gestionnaire de volumes dynamiques) -> C:\WINDOWS\system32\drivers\volmgrx.sys - AcceptPause : False - AcceptStop : True - DesktopInteract : False R0 - [Kernel Driver] - volsnap (Pilote de cliché instantané du volume) -> C:\WINDOWS\system32\drivers\volsnap.sys - AcceptPause : False - AcceptStop : True - DesktopInteract : False R0 - [Kernel Driver] - volume (Pilote de volume) -> C:\WINDOWS\system32\drivers\volume.sys - AcceptPause : False - AcceptStop : True - DesktopInteract : False S0 - [Kernel Driver] - vpci (Bus PCI virtuel Microsoft Hyper-V) -> C:\WINDOWS\system32\drivers\vpci.sys - AcceptPause : False - AcceptStop : False - DesktopInteract : False S0 - [Kernel Driver] - vsmraid (vsmraid) -> C:\WINDOWS\system32\drivers\vsmraid.sys - AcceptPause : False - AcceptStop : False - DesktopInteract : False S0 - [Kernel Driver] - VSTXRAID (Pilote Windows du contrôleur RAID de stockage VIA StorX) -> C:\WINDOWS\system32\drivers\vstxraid.sys - AcceptPause : False - AcceptStop : False - DesktopInteract : False S0 - [Kernel Driver] - WdBoot (Pilote de démarrage de l’antivirus Microsoft Defender) -> C:\WINDOWS\system32\drivers\wd\WdBoot.sys - AcceptPause : False - AcceptStop : False - DesktopInteract : False R0 - [Kernel Driver] - Wdf01000 (Service Infrastructure de pilote en mode noyau) -> C:\WINDOWS\system32\drivers\Wdf01000.sys - AcceptPause : False - AcceptStop : True - DesktopInteract : False R0 - [File System Driver] - WdFilter (Pilote du mini-filtre de l’antivirus Microsoft Defender) -> C:\WINDOWS\system32\drivers\wd\WdFilter.sys - AcceptPause : False - AcceptStop : True - DesktopInteract : False R0 - [Kernel Driver] - WFPLWFS (Plateforme de filtrage Microsoft Windows) -> C:\WINDOWS\system32\drivers\wfplwfs.sys - AcceptPause : False - AcceptStop : True - DesktopInteract : False R0 - [Kernel Driver] - WindowsTrustedRT (Windows Trusted Execution Environment Class Extension) -> C:\WINDOWS\system32\drivers\WindowsTrustedRT.sys - AcceptPause : False - AcceptStop : True - DesktopInteract : False R0 - [Kernel Driver] - WindowsTrustedRTProxy (Service sécurisé d'exécution approuvée Microsoft Windows) -> C:\WINDOWS\system32\drivers\WindowsTrustedRTProxy.sys - AcceptPause : False - AcceptStop : True - DesktopInteract : False R0 - [File System Driver] - Wof (Windows Overlay File System Filter Driver) -> C:\WINDOWS\system32\drivers\Wof.sys - AcceptPause : False - AcceptStop : True - DesktopInteract : False R1 - [Kernel Driver] - AFD (Pilote de fonction connexe pour Winsock) -> C:\WINDOWS\system32\drivers\afd.sys - AcceptPause : False - AcceptStop : True - DesktopInteract : False R1 - [Kernel Driver] - afunix (afunix) -> C:\WINDOWS\system32\drivers\afunix.sys - AcceptPause : False - AcceptStop : True - DesktopInteract : False R1 - [Kernel Driver] - ahcache (Application Compatibility Cache) -> C:\WINDOWS\system32\DRIVERS\ahcache.sys - AcceptPause : False - AcceptStop : True - DesktopInteract : False R1 - [Kernel Driver] - bam (Background Activity Moderator Driver) -> C:\WINDOWS\system32\drivers\bam.sys - AcceptPause : False - AcceptStop : True - DesktopInteract : False R1 - [Kernel Driver] - BasicDisplay (BasicDisplay) -> C:\WINDOWS\system32\DriverStore\FileRepository\basicdisplay.inf_amd64_65ab9a260dbf7467\BasicDisplay.sys - AcceptPause : False - AcceptStop : True - DesktopInteract : False R1 - [Kernel Driver] - BasicRender (BasicRender) -> C:\WINDOWS\system32\DriverStore\FileRepository\basicrender.inf_amd64_df49c4daa6251397\BasicRender.sys - AcceptPause : False - AcceptStop : True - DesktopInteract : False R1 - [Kernel Driver] - Beep (Beep) -> C:\WINDOWS\system32\drivers\Beep.sys - AcceptPause : False - AcceptStop : True - DesktopInteract : False S1 - [Kernel Driver] - cdrom (Pilote de CD-ROM) -> C:\WINDOWS\system32\drivers\cdrom.sys - AcceptPause : False - AcceptStop : False - DesktopInteract : False R1 - [File System Driver] - CimFS (CimFS) -> C:\WINDOWS\system32\drivers\CimFS.sys - AcceptPause : False - AcceptStop : True - DesktopInteract : False R1 - [Kernel Driver] - CSC (Pilote Fichiers hors connexion) -> C:\WINDOWS\system32\drivers\csc.sys - AcceptPause : False - AcceptStop : True - DesktopInteract : False S1 - [Kernel Driver] - dam (Desktop Activity Moderator Driver) -> C:\WINDOWS\system32\drivers\dam.sys - AcceptPause : False - AcceptStop : False - DesktopInteract : False R1 - [File System Driver] - Dfsc (Pilote du client de l’espace de noms DFS) -> C:\WINDOWS\system32\Drivers\dfsc.sys - AcceptPause : False - AcceptStop : True - DesktopInteract : False R1 - [Kernel Driver] - DXGKrnl (LDDM Graphics Subsystem) -> C:\WINDOWS\system32\drivers\dxgkrnl.sys - AcceptPause : False - AcceptStop : True - DesktopInteract : False R1 - [File System Driver] - FileCrypt (FileCrypt) -> C:\WINDOWS\system32\drivers\filecrypt.sys - AcceptPause : False - AcceptStop : True - DesktopInteract : False R1 - [Kernel Driver] - GpuEnergyDrv (GPU Energy Driver) -> C:\WINDOWS\system32\drivers\gpuenergydrv.sys - AcceptPause : False - AcceptStop : True - DesktopInteract : False R1 - [File System Driver] - Msfs (Msfs) -> C:\WINDOWS\system32\drivers\Msfs.sys - AcceptPause : False - AcceptStop : True - DesktopInteract : False R1 - [Kernel Driver] - mssmbios (Microsoft System Management BIOS Driver) -> C:\WINDOWS\system32\drivers\mssmbios.sys - AcceptPause : False - AcceptStop : True - DesktopInteract : False R1 - [Kernel Driver] - NdisCap (Capture NDIS Microsoft) -> C:\WINDOWS\system32\drivers\ndiscap.sys - AcceptPause : False - AcceptStop : True - DesktopInteract : False R1 - [File System Driver] - NetBIOS (NetBIOS Interface) -> C:\WINDOWS\system32\drivers\netbios.sys - AcceptPause : False - AcceptStop : True - DesktopInteract : False R1 - [Kernel Driver] - NetBT (NetBT) -> C:\WINDOWS\system32\DRIVERS\netbt.sys - AcceptPause : False - AcceptStop : True - DesktopInteract : False R1 - [File System Driver] - Npfs (Npfs) -> C:\WINDOWS\system32\drivers\Npfs.sys - AcceptPause : False - AcceptStop : True - DesktopInteract : False R1 - [Kernel Driver] - npsvctrig (Named pipe service trigger provider) -> C:\WINDOWS\system32\drivers\npsvctrig.sys - AcceptPause : False - AcceptStop : True - DesktopInteract : False R1 - [Kernel Driver] - nsiproxy (NSI Proxy Service Driver) -> C:\WINDOWS\system32\drivers\nsiproxy.sys - AcceptPause : False - AcceptStop : True - DesktopInteract : False R1 - [Kernel Driver] - Null (Null) -> C:\WINDOWS\system32\drivers\Null.sys - AcceptPause : False - AcceptStop : True - DesktopInteract : False R1 - [Kernel Driver] - Psched (Planificateur de paquets QoS) -> C:\WINDOWS\system32\drivers\pacer.sys - AcceptPause : False - AcceptStop : True - DesktopInteract : False R1 - [File System Driver] - rdbss (Sous-système de mise en mémoire tampon redirigée) -> C:\WINDOWS\system32\DRIVERS\rdbss.sys - AcceptPause : False - AcceptStop : True - DesktopInteract : False R1 - [Kernel Driver] - tdx (Pilote de prise en charge TDI héritée NetIO) -> C:\WINDOWS\system32\DRIVERS\tdx.sys - AcceptPause : False - AcceptStop : True - DesktopInteract : False R1 - [Kernel Driver] - Vid (Vid) -> C:\WINDOWS\system32\drivers\Vid.sys - AcceptPause : False - AcceptStop : True - DesktopInteract : False R1 - [Kernel Driver] - vwififlt (Virtual WiFi Filter Driver) -> C:\WINDOWS\system32\drivers\vwififlt.sys - AcceptPause : False - AcceptStop : True - DesktopInteract : False R2 - [Kernel Driver] - AMDRyzenMasterDriverV17 (AMDRyzenMasterDriverV17) -> \??\C:\Program Files\AMD\CNext\CNext\AMDRyzenMasterDriver.sys - AcceptPause : False - AcceptStop : True - DesktopInteract : False R2 - [File System Driver] - bindflt (Windows Bind Filter Driver) -> C:\WINDOWS\system32\drivers\bindflt.sys - AcceptPause : False - AcceptStop : True - DesktopInteract : False R2 - [File System Driver] - CldFlt (Windows Cloud Files Filter Driver) -> C:\WINDOWS\system32\drivers\cldflt.sys - AcceptPause : False - AcceptStop : True - DesktopInteract : False R2 - [Own Process] - AMD Crash Defender Service (AMD Crash Defender Service) -> C:\WINDOWS\System32\amdfendrsr.exe - AcceptPause : False - AcceptStop : True - DesktopInteract : False R2 - [Share Process] - AudioEndpointBuilder (Générateur de points de terminaison du service Audio Windows) -> C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -p - AcceptPause : False - AcceptStop : True - DesktopInteract : False R2 - [Own Process] - Audiosrv (Audio Windows) -> C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted -p - AcceptPause : False - AcceptStop : True - DesktopInteract : False R2 - [Share Process] - BFE (Moteur de filtrage de base) -> C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetworkFirewall -p - AcceptPause : False - AcceptStop : True - DesktopInteract : False R2 - [Share Process] - BITS (Service de transfert intelligent en arrière-plan) -> C:\WINDOWS\System32\svchost.exe -k netsvcs -p - AcceptPause : False - AcceptStop : True - DesktopInteract : False R2 - [Share Process] - BrokerInfrastructure (Service d’infrastructure des tâches en arrière-plan) -> C:\WINDOWS\system32\svchost.exe -k DcomLaunch -p - AcceptPause : False - AcceptStop : False - DesktopInteract : False R2 - [Share Process] - CDPSvc (Service de plateforme des appareils connectés) -> C:\WINDOWS\system32\svchost.exe -k LocalService -p - AcceptPause : False - AcceptStop : True - DesktopInteract : False R2 - [Share Process] - CoreMessagingRegistrar (CoreMessaging) -> C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork -p - AcceptPause : False - AcceptStop : False - DesktopInteract : False R2 - [Share Process] - CryptSvc (Services de chiffrement) -> C:\WINDOWS\system32\svchost.exe -k NetworkService -p - AcceptPause : False - AcceptStop : True - DesktopInteract : False R2 - [Share Process] - DcomLaunch (Lanceur de processus serveur DCOM) -> C:\WINDOWS\system32\svchost.exe -k DcomLaunch -p - AcceptPause : False - AcceptStop : False - DesktopInteract : False R2 - [Share Process] - DeviceAssociationService (Service d’association de périphérique) -> C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted -p - AcceptPause : False - AcceptStop : True - DesktopInteract : False R2 - [Share Process] - Dhcp (Client DHCP) -> C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted -p - AcceptPause : False - AcceptStop : True - DesktopInteract : False R2 - [Own Process] - DiagTrack (Expériences des utilisateurs connectés et télémétrie) -> C:\WINDOWS\System32\svchost.exe -k utcsvc -p - AcceptPause : False - AcceptStop : True - DesktopInteract : False R2 - [Kernel Driver] - lltdio (Pilote E/S de mappage de découverte de topologie de la couche de liaison) -> C:\WINDOWS\system32\drivers\lltdio.sys - AcceptPause : False - AcceptStop : True - DesktopInteract : False R2 - [File System Driver] - luafv (Virtualisation de fichier UAC) -> C:\WINDOWS\system32\drivers\luafv.sys - AcceptPause : False - AcceptStop : True - DesktopInteract : False R2 - [Kernel Driver] - MMCSS (Multimedia Class Scheduler) -> C:\WINDOWS\system32\drivers\mmcss.sys - AcceptPause : False - AcceptStop : True - DesktopInteract : False R2 - [Kernel Driver] - MsLldp (Protocole LLDP (Link Layer Discovery Protocol) Microsoft) -> C:\WINDOWS\system32\drivers\mslldp.sys - AcceptPause : False - AcceptStop : True - DesktopInteract : False R2 - [Kernel Driver] - Ndu (Windows Network Data Usage Monitoring Driver) -> C:\WINDOWS\system32\drivers\Ndu.sys - AcceptPause : False - AcceptStop : True - DesktopInteract : False R2 - [Kernel Driver] - PEAUTH (PEAUTH) -> C:\WINDOWS\system32\drivers\peauth.sys - AcceptPause : False - AcceptStop : True - DesktopInteract : False R2 - [Kernel Driver] - rspndr (Répondeur de découverte de la topologie de la couche de liaison) -> C:\WINDOWS\system32\drivers\rspndr.sys - AcceptPause : False - AcceptStop : True - DesktopInteract : False R2 - [Share Process] - DispBrokerDesktopSvc (Service de stratégie d'affichage) -> C:\WINDOWS\system32\svchost.exe -k LocalService -p - AcceptPause : False - AcceptStop : True - DesktopInteract : False R2 - [Share Process] - Dnscache (Client DNS) -> C:\WINDOWS\system32\svchost.exe -k NetworkService -p - AcceptPause : False - AcceptStop : False - DesktopInteract : False S2 - [Share Process] - DoSvc (Optimisation de livraison) -> C:\WINDOWS\System32\svchost.exe -k NetworkService -p - AcceptPause : False - AcceptStop : False - DesktopInteract : False R2 - [Share Process] - DPS (Service de stratégie de diagnostic) -> C:\WINDOWS\System32\svchost.exe -k LocalServiceNoNetwork -p - AcceptPause : False - AcceptStop : True - DesktopInteract : False R2 - [Own Process] - DusmSvc (Consommation des données) -> C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted -p - AcceptPause : False - AcceptStop : True - DesktopInteract : False S2 - [Own Process] - edgeupdate (Microsoft Edge Update Service (edgeupdate)) -> "C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /svc - AcceptPause : False - AcceptStop : False - DesktopInteract : False R2 - [Share Process] - EventLog (Journal d’événements Windows) -> C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted -p - AcceptPause : False - AcceptStop : True - DesktopInteract : False R2 - [Share Process] - EventSystem (Système d’événement COM+) -> C:\WINDOWS\system32\svchost.exe -k LocalService -p - AcceptPause : False - AcceptStop : True - DesktopInteract : False R2 - [Share Process] - FontCache (Service de cache de police Windows) -> C:\WINDOWS\system32\svchost.exe -k LocalService -p - AcceptPause : False - AcceptStop : True - DesktopInteract : False S2 - [Share Process] - gpsvc (Client de stratégie de groupe) -> C:\WINDOWS\system32\svchost.exe -k netsvcs -p - AcceptPause : False - AcceptStop : False - DesktopInteract : False S2 - [Own Process] - gupdate (Google Update Service (gupdate)) -> "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc - AcceptPause : False - AcceptStop : False - DesktopInteract : False R2 - [Share Process] - iphlpsvc (Assistance IP) -> C:\WINDOWS\System32\svchost.exe -k NetSvcs -p - AcceptPause : False - AcceptStop : True - DesktopInteract : False R2 - [File System Driver] - storqosflt (Pilote de filtre de qualité de service de stockage) -> C:\WINDOWS\system32\drivers\storqosflt.sys - AcceptPause : False - AcceptStop : True - DesktopInteract : False R2 - [Kernel Driver] - tcpipreg (TCP/IP Registry Compatibility) -> C:\WINDOWS\system32\drivers\tcpipreg.sys - AcceptPause : False - AcceptStop : True - DesktopInteract : False R2 - [Kernel Driver] - wanarp (Pilote ARP IP d’accès à distance) -> C:\WINDOWS\system32\DRIVERS\wanarp.sys - AcceptPause : False - AcceptStop : True - DesktopInteract : False R2 - [File System Driver] - wcifs (Windows Container Isolation) -> C:\WINDOWS\system32\drivers\wcifs.sys - AcceptPause : False - AcceptStop : True - DesktopInteract : False R2 - [Share Process] - LanmanServer (Serveur) -> C:\WINDOWS\system32\svchost.exe -k netsvcs -p - AcceptPause : False - AcceptStop : True - DesktopInteract : False R2 - [Share Process] - LanmanWorkstation (Station de travail) -> C:\WINDOWS\System32\svchost.exe -k NetworkService -p - AcceptPause : True - AcceptStop : True - DesktopInteract : False R2 - [Share Process] - LSM (Gestionnaire de session locale) -> C:\WINDOWS\system32\svchost.exe -k DcomLaunch -p - AcceptPause : False - AcceptStop : False - DesktopInteract : False S2 - [Own Process] - MapsBroker (Gestionnaire des cartes téléchargées) -> C:\WINDOWS\System32\svchost.exe -k NetworkService -p - AcceptPause : False - AcceptStop : False - DesktopInteract : False R2 - [Share Process] - mpssvc (Pare-feu Windows Defender) -> C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetworkFirewall -p - AcceptPause : False - AcceptStop : False - DesktopInteract : False R2 - [Share Process] - NlaSvc (Connaissance des emplacements réseau) -> C:\WINDOWS\System32\svchost.exe -k NetworkService -p - AcceptPause : False - AcceptStop : True - DesktopInteract : False R2 - [Share Process] - nsi (Service Interface du magasin réseau) -> C:\WINDOWS\system32\svchost.exe -k LocalService -p - AcceptPause : False - AcceptStop : True - DesktopInteract : False R2 - [Own Process] - NvContainerLocalSystem (NVIDIA LocalSystem Container) -> "C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe" -s NvContainerLocalSystem -f "C:\ProgramData\NVIDIA\NvContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\NvContainer\plugins\LocalSystem" -r -p 30000 -st "C:\Program Files\NVIDIA Corporation\NvContainer\NvContainerTelemetryApi.dll" - AcceptPause : False - AcceptStop : True - DesktopInteract : False R2 - [Own Process] - NVDisplay.ContainerLocalSystem (NVIDIA Display Container LS) -> C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_31a2adf8c49e7799\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log -l 3 -d C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_31a2adf8c49e7799\Display.NvContainer\plugins\LocalSystem -r -p 30000 -cfg NVDisplay.ContainerLocalSystem\LocalSystem - AcceptPause : False - AcceptStop : True - DesktopInteract : False R2 - [Share Process] - Power (Alimentation) -> C:\WINDOWS\system32\svchost.exe -k DcomLaunch -p - AcceptPause : False - AcceptStop : False - DesktopInteract : False R2 - [Share Process] - ProfSvc (Service de profil utilisateur) -> C:\WINDOWS\system32\svchost.exe -k netsvcs -p - AcceptPause : False - AcceptStop : True - DesktopInteract : False R2 - [Share Process] - RasMan (Gestionnaire des connexions d’accès à distance) -> C:\WINDOWS\System32\svchost.exe -k netsvcs - AcceptPause : False - AcceptStop : True - DesktopInteract : False R2 - [Share Process] - RpcEptMapper (Mappeur de point de terminaison RPC) -> C:\WINDOWS\system32\svchost.exe -k RPCSS -p - AcceptPause : False - AcceptStop : False - DesktopInteract : False R2 - [Share Process] - RpcSs (Appel de procédure distante (RPC)) -> C:\WINDOWS\system32\svchost.exe -k rpcss -p - AcceptPause : False - AcceptStop : False - DesktopInteract : False R2 - [Share Process] - SamSs (Gestionnaire de comptes de sécurité) -> C:\WINDOWS\system32\lsass.exe - AcceptPause : False - AcceptStop : False - DesktopInteract : False R2 - [Share Process] - Schedule (Planificateur de tâches) -> C:\WINDOWS\system32\svchost.exe -k netsvcs -p - AcceptPause : False - AcceptStop : True - DesktopInteract : False R2 - [Share Process] - SENS (Service de notification d’événements système) -> C:\WINDOWS\system32\svchost.exe -k netsvcs -p - AcceptPause : False - AcceptStop : True - DesktopInteract : False R2 - [Own Process] - SgrmBroker (Service Broker du moniteur d'exécution System Guard) -> C:\WINDOWS\system32\SgrmBroker.exe - AcceptPause : False - AcceptStop : False - DesktopInteract : False R2 - [Share Process] - ShellHWDetection (Détection matériel noyau) -> C:\WINDOWS\System32\svchost.exe -k netsvcs -p - AcceptPause : False - AcceptStop : True - DesktopInteract : False R2 - [Own Process] - Spooler (Spouleur d’impression) -> C:\WINDOWS\System32\spoolsv.exe - AcceptPause : False - AcceptStop : True - DesktopInteract : True S2 - [Own Process] - sppsvc (Protection logicielle) -> C:\WINDOWS\system32\sppsvc.exe - AcceptPause : False - AcceptStop : False - DesktopInteract : False R2 - [Own Process] - SQLWriter (SQL Server VSS Writer) -> "C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe" - AcceptPause : False - AcceptStop : True - DesktopInteract : False R2 - [Own Process] - stisvc (Acquisition d’image Windows (WIA)) -> C:\WINDOWS\system32\svchost.exe -k imgsvc - AcceptPause : True - AcceptStop : True - DesktopInteract : False R2 - [Share Process] - StorSvc (Service de stockage) -> C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -p - AcceptPause : False - AcceptStop : True - DesktopInteract : False R2 - [Share Process] - SysMain (SysMain) -> C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted -p - AcceptPause : False - AcceptStop : True - DesktopInteract : False R2 - [Share Process] - SystemEventsBroker (Service Broker des événements système) -> C:\WINDOWS\system32\svchost.exe -k DcomLaunch -p - AcceptPause : False - AcceptStop : True - DesktopInteract : False R2 - [Share Process] - Themes (Thèmes) -> C:\WINDOWS\System32\svchost.exe -k netsvcs -p - AcceptPause : False - AcceptStop : True - DesktopInteract : False R2 - [Own Process] - tmHInstall (Thrustmaster® Hotas Service) -> C:\Program Files\Thrustmaster\TM Flight Series\drivers\amd64\tmHInstall.exe - AcceptPause : False - AcceptStop : True - DesktopInteract : False R2 - [Share Process] - TrkWks (Client de suivi de lien distribué) -> C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -p - AcceptPause : False - AcceptStop : True - DesktopInteract : False R2 - [Own Process] - TrustedInstaller (Programme d’installation pour les modules Windows) -> C:\WINDOWS\servicing\TrustedInstaller.exe - AcceptPause : False - AcceptStop : False - DesktopInteract : False R2 - [Share Process] - UserManager (Gestionnaire des utilisateurs) -> C:\WINDOWS\system32\svchost.exe -k netsvcs -p - AcceptPause : False - AcceptStop : True - DesktopInteract : False R2 - [Share Process] - UsoSvc (Mettre à jour le service Orchestrator) -> C:\WINDOWS\system32\svchost.exe -k netsvcs -p - AcceptPause : False - AcceptStop : True - DesktopInteract : False R2 - [Own Process] - Wcmsvc (Gestionnaire des connexions Windows) -> C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted -p - AcceptPause : False - AcceptStop : True - DesktopInteract : False R2 - [Own Process] - WinDefend (Service antivirus Microsoft Defender) -> "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2201.10-0\MsMpEng.exe" - AcceptPause : False - AcceptStop : True - DesktopInteract : False R2 - [Share Process] - Winmgmt (Infrastructure de gestion Windows) -> C:\WINDOWS\system32\svchost.exe -k netsvcs -p - AcceptPause : True - AcceptStop : True - DesktopInteract : False R2 - [Share Process] - WpnService (Service du système de notifications Push Windows) -> C:\WINDOWS\system32\svchost.exe -k netsvcs -p - AcceptPause : False - AcceptStop : True - DesktopInteract : False R2 - [Share Process] - wscsvc (Centre de sécurité) -> C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted -p - AcceptPause : False - AcceptStop : True - DesktopInteract : False R2 - [Own Process] - WSearch (Windows Search) -> C:\WINDOWS\system32\SearchIndexer.exe /Embedding - AcceptPause : False - AcceptStop : True - DesktopInteract : False R2 - [Unknown] - CDPUserSvc_8057178 (Service pour utilisateur de plateforme d’appareils connectés_8057178) -> C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup - AcceptPause : False - AcceptStop : True - DesktopInteract : False R2 - [Unknown] - OneSyncSvc_8057178 (Hôte de synchronisation_8057178) -> C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup - AcceptPause : False - AcceptStop : True - DesktopInteract : False R2 - [Unknown] - WpnUserService_8057178 (Service utilisateur de notifications Push Windows_8057178) -> C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup - AcceptPause : False - AcceptStop : True - DesktopInteract : False ---------- | System files (Microsoft|Avast|Atheros|Adaptec|Brother|Intel Files whitelisted) ---------- | Uninstall (Whitelist) [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\28f016e7e7550fff] : (PremCARS.-.Premier Virtual Airlines) -> rundll32.exe dfshim.dll,ShArpMaintain PremCARS.application, Culture=neutral, PublicKeyToken=0000000000000000, processorArchitecture=msil [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\2eedfbc2cc1a251c] : (NeoFly.-.NeoFly) -> rundll32.exe dfshim.dll,ShArpMaintain NeoFly.application, Culture=neutral, PublicKeyToken=0000000000000000, processorArchitecture=amd64 [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\32e4cdf1-1f8f-586a-9551-9c0929bc3c38] : (SimBrief Downloader 1.6.3.-.SimBrief) -> "C:\Users\gband\AppData\Local\Programs\SimBrief Downloader\Uninstall SimBrief Downloader.exe" /currentuser [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\479eda5b2a2f8b79] : (FSEconomy SimConnect Client.-.www.fseconomy.net) -> rundll32.exe dfshim.dll,ShArpMaintain FSEconomy.application, Culture=neutral, PublicKeyToken=110e3500b3fd2937, processorArchitecture=x86 [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\55f042a9-1285-5a7a-abcd-4e2044c5b51b] : (Navigraph Navdata Center 1.0.5.-.Navigraph) -> "C:\Users\gband\AppData\Local\Programs\Navigraph Navdata Center\Uninstall Navigraph Navdata Center.exe" /currentuser [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\567dfc6a2d97de59] : (OnAir Company.-.OnAir Company) -> rundll32.exe dfshim.dll,ShArpMaintain OnAir Company.application, Culture=neutral, PublicKeyToken=be94ab6a893479c5, processorArchitecture=amd64 [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\796ea1b6-958a-57f0-828f-ddc0351d9ae7] : (Volanta 1.2.5.-.Orbx Simulation Systems Pty Ltd) -> "C:\Users\gband\AppData\Local\Programs\Volanta\Uninstall Volanta.exe" /currentuser [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\7cf15176-b7c3-5704-8319-ddca84b92c9a] : (Orbx Central 4.1.40.-.Orbx Simulation Systems Pty Ltd) -> "C:\Users\gband\AppData\Local\Programs\orbx-central\Uninstall Orbx Central.exe" /currentuser [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\80b9efbf-2017-5d38-8868-3afd67a5a47d] : (FlyByWire Installer 2.2.2.-.FlyByWire Simulations) -> "C:\Users\gband\AppData\Local\Programs\fbw-installer\Uninstall FlyByWire Installer.exe" /currentuser [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\a907b7cadbe85427] : (SKACARS.-.skyalliance-va.com) -> rundll32.exe dfshim.dll,ShArpMaintain SKACARS.application, Culture=en, PublicKeyToken=62396b27c2c60a41, processorArchitecture=amd64 [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\de9b7d1c-e2fe-4d7f-8fdd-b36629baf4ff] : (VAS ACARS.-.VASystem) -> "C:\Users\gband\AppData\Local\Programs\VASystem\VAS-ACARS\vas-acars-updater.exe" uninstall [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\Discord] : (Discord.-.Discord Inc.) -> C:\Users\gband\AppData\Local\Discord\Update.exe --uninstall [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\simtoolkitpro] : (SimToolkitPro.-.SimToolkitPro) -> "C:\Users\gband\AppData\Local\simtoolkitpro\Update.exe" --uninstall [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\utweb] : (uTorrent Web.-.BitTorrent, Inc.) -> "C:\Users\gband\AppData\Roaming\uTorrent Web\Uninstall.exe" [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\vPilot] : (vPilot.-.Ross Alan Carlson) -> C:\Users\gband\AppData\Local\vPilot\Uninstall.exe [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{53F49750-6209-4FBF-9CA8-7A333C87D1ED}_is1] : (Telegram Desktop version 3.5.1.-.Telegram FZ-LLC) -> "C:\Users\gband\AppData\Roaming\Telegram Desktop\unins000.exe" [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{74530ECC-37A9-4000-936B-9CA8332CA44E}_is1] : (Sky4Sim Pad version 1.2.0.-.Sky4Sim) -> "C:\Users\gband\AppData\Local\Programs\Sky4Sim Pad\unins000.exe" [HKU\S-1-5-21-3835695913-52790398-83466441-1001\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{c489a901-bdfb-5fb7-8139-68385c3d78d8}] : (Navigraph Charts 7.6.1.-.Navigraph) -> "C:\Users\gband\AppData\Local\Programs\Navigraph Charts\Uninstall Navigraph Charts.exe" /currentuser [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\6fd47695-9ae0-492c-a3a2-db9be0a547d4] : (MSFS2020 Map Enhancement 3.2.2.-.He Sicong) -> "C:\Program Files\MSFS2020 Map Enhancement\Uninstall MSFS2020 Map Enhancement.exe" /allusers [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\AddressBook] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\AMD Catalyst Install Manager] : (AMD Software.-.Advanced Micro Devices, Inc.) -> "C:\Program Files\AMD\CIM\BIN64\RadeonInstaller.exe" /EXPRESS_UNINSTALL /IGNORE_UPGRADE /ON_REBOOT_MESSAGE:NO ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\Connection Manager] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\DirectDrawEx] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\DXM_Runtime] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\Fontcore] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\IE40] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\IE4Data] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\IE5BAKEX] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\IEData] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\MobileOptionPack] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\MPlayer2] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\RealTraffic Launcher_is1] : (RealTraffic Launcher.-.Inside Systems Pty Ltd) -> "C:\Program Files\RealTrafficLauncher\unins000.exe" [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\SchedulingAgent] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\Steam App 1250410] : (Microsoft Flight Simulator.-.Asobo Studio) -> "C:\Program Files (x86)\Steam\steam.exe" steam://uninstall/1250410 [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\WIC] : (.-.) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{040CD326-7042-4872-9F3D-A6683EB668F4}] : (RyzenMasterSDK.-.Advanced Micro Devices, Inc.) -> MsiExec.exe /I{040CD326-7042-4872-9F3D-A6683EB668F4} [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{1244B745-C8F0-4B3A-A9B6-90C8888974E3}] : (REX Weather Force 2020.-.REX Game Studios, LLC.) -> MsiExec.exe /I{1244B745-C8F0-4B3A-A9B6-90C8888974E3} ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{126FFB6D-F609-461F-8355-72EA725E64D5}] : (AMD Settings.-.Advanced Micro Devices, Inc.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{26A24AE4-039D-4CA4-87B4-2F64180321F0}] : (Java 8 Update 321 (64-bit).-.Oracle Corporation) -> MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F64180321F0} [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{2D73A914-0002-4463-A278-19026BEDD53A}] : (AWS Command Line Interface.-.Amazon Web Services Developer Relations) -> MsiExec.exe /I{2D73A914-0002-4463-A278-19026BEDD53A} ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{4B3B3839-1FC1-4065-8220-142476F2A1FC}] : (AMD DVR64.-.Advanced Micro Devices, Inc.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{7A568DEF-6E47-33D5-6098-A59DF2EF0D1F_en-US}] : (smartCARS - AirFrance Virtuel (en-US).-.TFDi Design) -> C:\Program Files (x86)\smartCARS\94\en-US\installer.exe /allownoinstall [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{A28DBDA2-3CC7-4ADC-8BFE-66D7743C6C97}_is1] : (Revo Uninstaller 2.3.5.-.VS Revo Group, Ltd.) -> "C:\Program Files\VS Revo Group\Revo Uninstaller\unins000.exe" [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver] : (NVIDIA Pilote graphique 511.65.-.NVIDIA Corporation) -> "C:\WINDOWS\SysWOW64\RunDll32.EXE" "C:\Program Files\NVIDIA Corporation\Installer2\InstallerCore\NVI2.DLL",UninstallPackage Display.Driver [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience] : (NVIDIA GeForce Experience 3.25.0.84.-.NVIDIA Corporation) -> "C:\WINDOWS\SysWOW64\RunDll32.EXE" "C:\Program Files\NVIDIA Corporation\Installer2\InstallerCore\NVI2.DLL",UninstallPackage Display.GFExperience ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Optimus] : (NVIDIA Optimus Update 39.3.0.0.-.NVIDIA Corporation) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX] : (NVIDIA Logiciel système PhysX 9.21.0713.-.NVIDIA Corporation) -> "C:\WINDOWS\SysWOW64\RunDll32.EXE" "C:\Program Files\NVIDIA Corporation\Installer2\InstallerCore\NVI2.DLL",UninstallPackage Display.PhysX ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update] : (Mises à jour NVIDIA 39.3.0.0.-.NVIDIA Corporation) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_FrameViewSdk] : (NVIDIA FrameView SDK 1.2.7321.30900954.-.NVIDIA Corporation) -> "C:\WINDOWS\SysWOW64\RunDll32.EXE" "C:\Program Files\NVIDIA Corporation\Installer2\InstallerCore\NVI2.DLL",UninstallPackage FrameViewSdk ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GFExperience.NvStreamSrv] : (NVIDIA SHIELD Streaming.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GpxCommon.Oss] : (NVIDIA GPX Common OSS binaries (POCO, OpenSSL, libprotobuf).-.NVIDIA Corporation) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver] : (NVIDIA Pilote audio HD : 1.3.39.3.-.NVIDIA Corporation) -> "C:\WINDOWS\SysWOW64\RunDll32.EXE" "C:\Program Files\NVIDIA Corporation\Installer2\InstallerCore\NVI2.DLL",UninstallPackage HDAudio.Driver ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer] : (NVIDIA Install Application.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvBackend] : (NVIDIA Backend.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer] : (NVIDIA Container.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.ContainerTelemetryApiHelper] : (NVIDIA TelemetryApi helper for NvContainer.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.LocalSystem] : (NVIDIA LocalSystem Container.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.MessageBus] : (NVIDIA Message Bus for NvContainer.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.NvapiMonitor] : (NVIDIA NVAPI Monitor plugin for NvContainer.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.ServiceUser] : (NVIDIA NetworkService Container.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.Session] : (NVIDIA Session Container.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.User] : (NVIDIA User Container.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvModuleTracker.Driver] : (NvModuleTracker.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvNodejs] : (NVIDIA NodeJS.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvPlugin.Watchdog] : (NVIDIA Watchdog Plugin for NvContainer.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvTelemetry] : (NVIDIA Telemetry Client.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvVHCI] : (NVIDIA Virtual Host Controller.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_OSC] : (Nvidia Share.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_ShadowPlay] : (NVIDIA ShadowPlay 3.25.0.84.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_ShieldWirelessController] : (NVIDIA SHIELD Wireless Controller Driver.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Update.Core] : (NVIDIA Update Core.-.NVIDIA Corporation) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_USBC] : (NVIDIA USBC Driver 1.46.831.832.-.NVIDIA Corporation) -> "C:\WINDOWS\SysWOW64\RunDll32.EXE" "C:\Program Files\NVIDIA Corporation\Installer2\InstallerCore\NVI2.DLL",UninstallPackage USBC ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_VirtualAudio.Driver] : (NVIDIA Virtual Audio 4.39.0.0.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{C871FC62-0186-40ED-BAEA-7C65BE367755}] : (Branding64.-.Advanced Micro Devices, Inc.) -> MsiExec.exe /I{C871FC62-0186-40ED-BAEA-7C65BE367755} ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{E4BA15C6-5F83-4AF4-B5BB-66FADCC341F0}] : (AMD WVR64.-.Advanced Micro Devices, Inc.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{E5431A0D-8735-4E89-9E41-D820334B2909}}_is1] : (Navigraph Simlink 1.1.25.0120.-.Navigraph) -> "C:\Program Files\Navigraph\Simlink\unins000.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\05E1EA0F-A436-4E30-A305-D83071663708_is1] : (Pilot2ATC 2.6.2.3_x64_R2.-.Pilot2ATC) -> "C:\Pilot2ATC_2020_x64\unins000.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\7-Zip] : (7-Zip 19.00.-.Igor Pavlov) -> C:\Program Files (x86)\7-Zip\Uninstall.exe [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\AddressBook] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Afterburner] : (MSI Afterburner 4.6.4 Beta 3.-.MSI Co., LTD) -> "C:\Program Files (x86)\MSI Afterburner\uninstall.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\AMD_Chipset_IODrivers] : (AMD Chipset Software.-.Advanced Micro Devices, Inc.) -> "C:\Program Files (x86)\AMD\Chipset_IODrivers\Setup.exe" /U {9bbdaa84-1315-4bcf-ac55-57449b4228f1} ----------[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Connection Manager] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Cyberpunk 2077_is1] : (Cyberpunk 2077.-.) -> "E:\Games\Nouveau dossier\Cyberpunk 2077\unins000.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\DirectDrawEx] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\DXM_Runtime] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Fontcore] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\FS2Crew Command Center] : (FS2Crew Command Center.-.) -> C:\Program Files (x86)\FS2Crew Command Center\unFS2Crew_Command_Center_MSFS.exe [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\FS2Crew: Pushback Express] : (FS2Crew: Pushback Express.-.) -> C:\Program Files (x86)\Pushback Express MSFS\unFS2Crew_Pushback_Express_MSFS.exe [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\FSAirlines Client] : (FSAirlines Client.-.) -> "C:\Program Files (x86)\FSAirlines\Uninstall.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\FSUIPC7] : (FSUIPC7 v7.2.14.-.John L. Dowson) -> C:\FSUIPC7\uninstallFSUIPC7.exe [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Google Chrome] : (Google Chrome.-.Google LLC) -> "C:\Program Files\Google\Chrome\Application\98.0.4758.82\Installer\setup.exe" --uninstall --channel=stable --system-level --verbose-logging [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\IE40] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\IE4Data] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\IE5BAKEX] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\IEData] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Microsoft Edge Update] : (Microsoft Edge Update.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\MobileOptionPack] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\MPlayer2] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Not For Broadcast_is1] : (Not For Broadcast.-.) -> "E:\Games\Nouveau dossier\Not For Broadcast\unins000.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\REX File Transfer Manager 1.13.2020.0319] : (REX File Transfer Manager.-.REX Game Studios, LLC.) -> C:\ProgramData\Caphyon\Advanced Installer\{DA9012D8-82F6-4231-803C-345B05F5C675}\rexsetup.exe /i {DA9012D8-82F6-4231-803C-345B05F5C675} AI_UNINSTALLER_CTP=1 [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\RTSS] : (RivaTuner Statistics Server 7.3.3.-.Unwinder) -> "C:\Program Files (x86)\RivaTuner Statistics Server\uninstall.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\SchedulingAgent] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\ST6UNST #1] : (Virtual E6-B 1.4.-.) -> C:\WINDOWS\st6unst.exe -n "C:\Program Files (x86)\Virtual E6-B\ST6UNST.LOG" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Steam] : (Steam.-.Valve Corporation) -> C:\Program Files (x86)\Steam\uninstall.exe [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Uplay] : (Ubisoft Connect.-.Ubisoft) -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\Uninstall.exe [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WIC] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{3E1C36F0-C3A2-4137-9DA4-8580CF6191E1}] : (Intel(R) C++ Redistributables on Intel(R) 64.-.Intel Corporation) -> MsiExec.exe /X{3E1C36F0-C3A2-4137-9DA4-8580CF6191E1} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{40777858-E458-4551-9EEC-BB926D9DB72F}_is1] : (Flight Simulator First Officer Next version 1.0.3.0.-.Flight Simulator Innovative Addons) -> "C:\Program Files (x86)\Flight Simulator First Officer Next\unins000.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{44154D5D-4127-4905-A8BC-56DB793FE874}] : (Bijan Season Installer.-.Bijan Season) -> MsiExec.exe /I{44154D5D-4127-4905-A8BC-56DB793FE874} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{45E5EB84-9C5E-4EB3-B251-BBB0E12E1727}_is1] : (Flight Control Replay Professional Edition for MICROSOFT FLIGHT SIMULATOR -PREPAR3D -FSX -ESP version 4.5.2201.12.-.SimMarket) -> "C:\Program Files (x86)\SimMarket\FlightControlReplay\UninsHs.exe" /u0={45E5EB84-9C5E-4EB3-B251-BBB0E12E1727} ----------[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{4A03706F-666A-4037-7777-5F2748764D10}] : (Java Auto Updater.-.Oracle Corporation) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{5713AEF3-C475-4F46-BB95-56DE1D6AF49F}] : (Self Loading Cargo.-.Lanilogic) -> MsiExec.exe /I{5713AEF3-C475-4F46-BB95-56DE1D6AF49F} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{63F53541-A29E-4B53-825A-9B6F876A2BD6}_is1] : (opentrack version opentrack-2022.1.1.-.opentrack) -> "C:\Program Files (x86)\opentrack\unins000.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{7E4D5716-374A-4DB6-90CF-D2AEB67362CE}_is1] : (Navigraph FMS Data Manager 1.8.9.0421.-.Navigraph) -> "C:\Program Files (x86)\Navigraph\FMS Data Manager\unins000.exe" ----------[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{80EC3CEE-2940-42A1-A776-B5D810D39F1E}] : (AMD PCI Driver.-.Advanced Micro Devices, Inc.) -> MsiExec.exe /X{80EC3CEE-2940-42A1-A776-B5D810D39F1E} ----------[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{988F14B8-79A8-475D-BAC7-83F96AD3D821}] : (AMD PSP Driver.-.Advanced Micro Devices, Inc.) -> MsiExec.exe /X{988F14B8-79A8-475D-BAC7-83F96AD3D821} ----------[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{9bbdaa84-1315-4bcf-ac55-57449b4228f1}] : (AMD_Chipset_Drivers.-.Advanced Micro Devices, Inc.) -> MsiExec.exe /X{9bbdaa84-1315-4bcf-ac55-57449b4228f1} ----------[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{A171D320-C42C-4F3B-A2D8-C6A09F6788CC}] : (AMD Ryzen Balanced Driver.-.Advanced Micro Devices, Inc.) -> MsiExec.exe /X{A171D320-C42C-4F3B-A2D8-C6A09F6788CC} ----------[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{AAE0E27D-C88A-49BA-8715-77ADCD4286A3}] : (AMD SBxxx SMBus Driver Alpha.-.Advanced Micro Devices, Inc.) -> MsiExec.exe /X{AAE0E27D-C88A-49BA-8715-77ADCD4286A3} ----------[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{B5512BCC-F4CD-4159-86A4-B2AD7D38FFA9}] : (Promontory_GPIO Driver.-.Advanced Micro Devices, Inc.) -> MsiExec.exe /X{B5512BCC-F4CD-4159-86A4-B2AD7D38FFA9} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{C8DDAEED-3F7E-4B0F-921B-5C319A1E82F5}] : (PACX.-.TFDi Design) -> MsiExec.exe /X{C8DDAEED-3F7E-4B0F-921B-5C319A1E82F5} ----------[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{DA9012D8-82F6-4231-803C-345B05F5C675}] : (REX File Transfer Manager.-.REX Game Studios, LLC.) -> MsiExec.exe /I{DA9012D8-82F6-4231-803C-345B05F5C675} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{E08E6F77-E66C-47FC-8565-0AA3389D48C8}] : (T.Flight Hotas drivers.-.Thrustmaster) -> "C:\Program Files (x86)\InstallShield Installation Information\{E08E6F77-E66C-47FC-8565-0AA3389D48C8}\setup.exe" -runfromtemp -l0x0409 -removeonly [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{e26b382f-e945-4f70-9318-121b683f1d61}] : (Battlefield™ V.-.Electronic Arts) -> "C:\Program Files\Common Files\EAInstaller\Battlefield V\Cleanup.exe" uninstall_game -autologging ----------[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{E9DD399F-21A3-479E-A7DF-D6CF4B2ADBF3}] : (AMD GPIO2 Driver.-.Advanced Micro Devices, Inc.) -> MsiExec.exe /X{E9DD399F-21A3-479E-A7DF-D6CF4B2ADBF3} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}] : (Realtek High Definition Audio Driver.-.Realtek Semiconductor Corp.) -> C:\Program Files\Realtek\Audio\HDA\RtlUpd64.exe -r -m -nrg2709 ---------- | Ports ---------- | Installer [HKCR\Installer\Products\023D171AC24CB3F42A8D6C0AF97688CC] : AMD Ryzen Balanced Driver -> C:\WINDOWS\Installer\{A171D320-C42C-4F3B-A2D8-C6A09F6788CC}\ARPPRODUCTICON.exe [HKCR\Installer\Products\0F63C1E32A3C7314D94A5808FC16191E] : Intel(R) C++ Redistributables on Intel(R) 64 [HKCR\Installer\Products\26CF178C6810DE04ABAEC756EB637755] : Branding64 -> C:\WINDOWS\Installer\{C871FC62-0186-40ED-BAEA-7C65BE367755}\ARPPRODUCTICON.exe [HKCR\Installer\Products\419A37D2200036442A879120B6DE5DA3] : AWS Command Line Interface -> C:\WINDOWS\Installer\{2D73A914-0002-4463-A278-19026BEDD53A}\awsicon [HKCR\Installer\Products\48aadbb95131fcb4ca557544b924821f] : AMD_Chipset_Drivers -> C:\WINDOWS\Installer\{9bbdaa84-1315-4bcf-ac55-57449b4228f1}\ARPPRODUCTICON.exe [HKCR\Installer\Products\4EA42A62D9304AC4784BF2468130120F] : Java 8 Update 321 (64-bit) -> C:\Program Files\Java\jre1.8.0_321\\bin\javaws.exe [HKCR\Installer\Products\547B44210F8CA3B49A6B098C8898473E] : REX Weather Force 2020 -> C:\WINDOWS\Installer\{1244B745-C8F0-4B3A-A9B6-90C8888974E3}\icowf.exe [HKCR\Installer\Products\623DC04024072784F9D36A86E36B864F] : RyzenMasterSDK -> C:\WINDOWS\Installer\{040CD326-7042-4872-9F3D-A6683EB668F4}\ARPPRODUCTICON.exe [HKCR\Installer\Products\6C51AB4E38F54FA45BBB66AFCD3C140F] : AMD WVR64 -> C:\WINDOWS\Installer\{E4BA15C6-5F83-4AF4-B5BB-66FADCC341F0}\ARPPRODUCTICON.exe [HKCR\Installer\Products\8B41F8898A97D574AB7C389FA63D8D12] : AMD PSP Driver -> C:\WINDOWS\Installer\{988F14B8-79A8-475D-BAC7-83F96AD3D821}\ARPPRODUCTICON.exe [HKCR\Installer\Products\8D2109AD6F28132408C343B5505F6C57] : REX File Transfer Manager -> C:\WINDOWS\Installer\{DA9012D8-82F6-4231-803C-345B05F5C675}\REXAutoUpdater.exe [HKCR\Installer\Products\9383B3B41CF1560428024142672F1ACF] : AMD DVR64 -> C:\WINDOWS\Installer\{4B3B3839-1FC1-4065-8220-142476F2A1FC}\ARPPRODUCTICON.exe [HKCR\Installer\Products\CCB2155BDC4F9514684A2BDAD783FF9A] : Promontory_GPIO Driver -> C:\WINDOWS\Installer\{B5512BCC-F4CD-4159-86A4-B2AD7D38FFA9}\ARPPRODUCTICON.exe [HKCR\Installer\Products\D5D45144721450948ACB65BD97F38E47] : Bijan Season Installer [HKCR\Installer\Products\D6BFF621906FF164385527AE27E5465D] : AMD Settings -> C:\WINDOWS\Installer\{126FFB6D-F609-461F-8355-72EA725E64D5}\ARPPRODUCTICON.exe [HKCR\Installer\Products\D72E0EAAA88CAB94785177DADC24683A] : AMD SBxxx SMBus Driver Alpha -> C:\WINDOWS\Installer\{AAE0E27D-C88A-49BA-8715-77ADCD4286A3}\ARPPRODUCTICON.exe [HKCR\Installer\Products\DEEADD8CE7F3F0B429B1C513A9E1285F] : PACX -> C:\WINDOWS\Installer\{C8DDAEED-3F7E-4B0F-921B-5C319A1E82F5}\icon.exe [HKCR\Installer\Products\EEC3CE0804921A247A675B8D013DF9E1] : AMD PCI Driver -> C:\WINDOWS\Installer\{80EC3CEE-2940-42A1-A776-B5D810D39F1E}\ARPPRODUCTICON.exe [HKCR\Installer\Products\F60730A4A66673047777F5728467D401] : Java Auto Updater [HKCR\Installer\Products\F993DD9E3A12E9747AFD6DFCB4A2BD3F] : AMD GPIO2 Driver -> C:\WINDOWS\Installer\{E9DD399F-21A3-479E-A7DF-D6CF4B2ADBF3}\ARPPRODUCTICON.exe ---------- | UserSettings [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Power\User\PowerSchemes\381b4222-f694-41f0-9685-ff5bb260df2e]~[Description] : @%SystemRoot%\system32\powrprof.dll,-14,Automatically balances performance with energy consumption on capable hardware. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Power\User\PowerSchemes\381b4222-f694-41f0-9685-ff5bb260df2e]~[FriendlyName] : @%SystemRoot%\system32\powrprof.dll,-15,Balanced (recommended) [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Power\User\PowerSchemes\3af9B8d9-7c97-431d-ad78-34a8bfea439f]~[Description] : @%SystemRoot%\system32\powrprof.dll,-1400,Favor performance instead of energy savings. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Power\User\PowerSchemes\3af9B8d9-7c97-431d-ad78-34a8bfea439f]~[FriendlyName] : @%SystemRoot%\system32\powrprof.dll,-1401,High Performance Overlay [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Power\User\PowerSchemes\8c5e7fda-e8bf-4a96-9a85-a6e23a8c635c]~[Description] : @%SystemRoot%\system32\powrprof.dll,-12,Favors performance, but may use more energy. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Power\User\PowerSchemes\8c5e7fda-e8bf-4a96-9a85-a6e23a8c635c]~[FriendlyName] : @%SystemRoot%\system32\powrprof.dll,-13,High Performance [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Power\User\PowerSchemes\961cc777-2547-4f9d-8174-7d86181b8a7a]~[Description] : @%SystemRoot%\system32\powrprof.dll,-1404,Favor energy savings over performance. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Power\User\PowerSchemes\961cc777-2547-4f9d-8174-7d86181b8a7a]~[FriendlyName] : @%SystemRoot%\system32\powrprof.dll,-1405,Better Battery-life Overlay [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Power\User\PowerSchemes\9897998c-92de-4669-853f-b7cd3ecb2790]~[Description] : Balanced power plan customized for AMD Ryzen™ processors. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Power\User\PowerSchemes\9897998c-92de-4669-853f-b7cd3ecb2790]~[FriendlyName] : AMD Ryzen™ Balanced [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Power\User\PowerSchemes\9935e61f-1661-40c5-ae2f-8495027d5d5d]~[Description] : High performance power plan customized for AMD Ryzen™ processors. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Power\User\PowerSchemes\9935e61f-1661-40c5-ae2f-8495027d5d5d]~[FriendlyName] : AMD Ryzen™ High Performance [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Power\User\PowerSchemes\a1841308-3541-4fab-bc81-f71556f20b4a]~[Description] : @%SystemRoot%\system32\powrprof.dll,-10,Saves energy by reducing your computer performance where possible. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Power\User\PowerSchemes\a1841308-3541-4fab-bc81-f71556f20b4a]~[FriendlyName] : @%SystemRoot%\system32\powrprof.dll,-11,Power Saver [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Power\User\PowerSchemes\ded574b5-45a0-4f42-8737-46345c09c238]~[Description] : @%SystemRoot%\system32\powrprof.dll,-1402,Maximize bias towards performance instead of energy savings. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Power\User\PowerSchemes\ded574b5-45a0-4f42-8737-46345c09c238]~[FriendlyName] : @%SystemRoot%\system32\powrprof.dll,-1403,Max Performance Overlay [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Power\User\PowerSchemes\e9a42b02-d5df-448d-aa00-03f14749eb61]~[Description] : @%SystemRoot%\system32\powrprof.dll,-18,Provides ultimate performance on higher end PCs. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Power\User\PowerSchemes\e9a42b02-d5df-448d-aa00-03f14749eb61]~[FriendlyName] : @%SystemRoot%\system32\powrprof.dll,-19,Ultimate Performance [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|Version [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|SequenceNumber [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|Microsoft.Windows.Search_cw5n1h2txyewy [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|Microsoft.Windows.ShellExperienceHost_cw5n1h2txyewy [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|windows.immersivecontrolpanel_cw5n1h2txyewy [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|MicrosoftWindows.Client.CBS_cw5n1h2txyewy [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|Microsoft.WindowsStore_8wekyb3d8bbwe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|Microsoft.Windows.Apprep.ChxApp_cw5n1h2txyewy [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|Microsoft.XboxGamingOverlay_8wekyb3d8bbwe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|64343GTDocStudio.OfficeDocOpener_3h5nez1g3qt2c [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|HaukeGtze.7-ZipFileManagerUnofficial_6bk20wvc8rfx2 [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|Microsoft.ZuneMusic_8wekyb3d8bbwe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|Microsoft.LockApp_cw5n1h2txyewy [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|DolbyLaboratories.DolbyAccess_rz1tebttyb220 [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|Microsoft.StorePurchaseApp_8wekyb3d8bbwe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|325289AEDD75.TorrentRTFREE_qtx9tqphctw9r [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|Microsoft.Windows.SecHealthUI_cw5n1h2txyewy [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|WuhanNetPowerTechnologyCo.3322537A536FD_63m8b6nby1dvp [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|NVIDIACorp.NVIDIAControlPanel_56jybvy8sckqj [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|microsoft.windowscommunicationsapps_8wekyb3d8bbwe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|19282JackieLiu.Notepads-Beta_echhpq9pdbte8 [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|Microsoft.549981C3F5F10_8wekyb3d8bbwe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|LiveATC.net.LiveATC_0yfybvjjn1ddw [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|Microsoft.Windows.Photos_8wekyb3d8bbwe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|Microsoft.BingWeather_8wekyb3d8bbwe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|Windows.PrintDialog_cw5n1h2txyewy [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|Microsoft.ZuneVideo_8wekyb3d8bbwe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|Microsoft.MicrosoftSolitaireCollection_8wekyb3d8bbwe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|GlobalApptitude.GamePlan_1ksr0nz5tnfmg [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|50930OliverNeuschl.NotepadT_r8m9wmyz3tx4m [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|Microsoft.SkypeApp_kzf8qxf38zg5c [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|Microsoft.WindowsCalculator_8wekyb3d8bbwe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|Microsoft.YourPhone_8wekyb3d8bbwe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume2\Games\Nouveau dossier\Cyberpunk 2077\bin\x64\Cyberpunk2077.exe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume2\Games\Nouveau dossier\eFootball PES 2021\sider.exe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume2\Games\Nouveau dossier\eFootball PES 2021\PES2021.exe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Windows\explorer.exe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Program Files (x86)\Steam\steam.exe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Users\gband\AppData\Local\Discord\app-1.0.9003\Discord.exe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Users\gband\AppData\Local\Programs\SimBrief Downloader\SimBrief Downloader.exe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Windows\System32\rundll32.exe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Windows\System32\ApplicationFrameHost.exe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Program Files (x86)\Steam\steamapps\common\MicrosoftFlightSimulator\FlightSimulator.exe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Program Files\Google\Chrome\Application\chrome.exe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Program Files\MSFS2020 Map Enhancement\MSFS2020 Map Enhancement.exe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\FSUIPC7\FSUIPC7.exe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Users\gband\Documents\FSRealistic\FSRealistic.exe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Program Files\Navigraph\Simlink\NavigraphSimlink.exe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Program Files (x86)\FS2Crew Command Center\FS2CrewCommandCenter.exe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Users\gband\Documents\Traffic\AIG Taffic controler\AIGTech - Traffic Controller.exe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Program Files (x86)\Lanilogic\Self Loading Cargo\SLC.exe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Users\gband\AppData\Local\Programs\fbw-installer\FlyByWire Installer.exe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Users\gband\Documents\Addons linker\MSFS_AddonsLinker.exe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Program Files (x86)\Microsoft\Edge\Application\msedge.exe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Program Files (x86)\RivaTuner Statistics Server\RTSS.exe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Windows\System32\notepad.exe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Windows\System32\cmd.exe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Users\gband\AppData\Local\Apps\2.0\LK0QAA7C.X1D\6W48N25K.TVN\skac..tion_62396b27c2c60a41_0001.0001_e182734c20687b40\SKACARS.exe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Users\gband\AppData\Local\Microsoft\OneDrive\OneDrive.exe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Program Files (x86)\FSAirlines\FSAirlines.exe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Users\gband\AppData\Local\Programs\Navigraph Navdata Center\Navigraph Navdata Center.exe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Users\gband\AppData\Roaming\Telegram Desktop\Telegram.exe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Windows\System32\msiexec.exe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Users\gband\Documents\Enhanced Live Traffic\Enhanced Live Traffic.exe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Users\gband\Documents\Luke Air\AirTool.exe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Users\gband\AppData\Local\Temp\ZipExtractor.exe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Users\gband\AppData\Local\Programs\Sky4Sim Pad\Sky4Sim Pad.exe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume6\MFS2020\IVAO\PilotCore\pilot_core_fs2020.exe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume6\MFS2020\IVAO\PilotUI\PilotUI.exe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\REX Weather Force 2020\rexwxforceapp.exe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Users\gband\Documents\Traffic\AIG MManager\AIGTech - AI Manager.exe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Users\gband\AppData\Local\Apps\2.0\LK0QAA7C.X1D\6W48N25K.TVN\prem..tion_0000000000000000_0001.0001_d5bbe5a2780b9090\PremCARS.exe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Users\gband\Documents\opentrack-2.3\vPilot-Setup-3.0.7.exe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Users\gband\AppData\Local\vPilot\vPilot.exe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Users\gband\Documents\opentrack-2.3\volanta-1.2.5.exe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Users\gband\AppData\Local\Programs\Volanta\Volanta.exe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Program Files\RealTrafficLauncher\jre\bin\javaw.exe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Program Files\RealTrafficLauncher\jre\bin\java.exe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Users\gband\AppData\Local\simtoolkitpro\app-0.8.12\Update.exe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Users\gband\AppData\Local\simtoolkitpro\app-0.8.12\SimToolkitPro.exe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Users\gband\AppData\Local\simtoolkitpro\app-0.8.12\resources\static\p3d\SimConnectServer.exe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume5\Games\Nouveau dossier\eFootball PES 2021\sider.exe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume5\Games\Nouveau dossier\eFootball PES 2021\PES2021.exe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Users\gband\Documents\NeoFly\NeoFly.exe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Users\gband\Documents\opentrack-2.3\Bijan_Season_Installer_V1.1\setup.exe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Windows\SysWOW64\msiexec.exe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Program Files (x86)\Bijan Season\Bijan Season Installer\Bijan Seasons.exe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Users\gband\Downloads\Just Flight - Air Hauler 2 for MSFS v3.00.11\AirHauler2.exe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Users\gband\Downloads\Just Flight - Air Hauler 2 for MSFS v3.00.11\FindPkgs.exe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Windows\System32\WerFault.exe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Users\gband\AppData\Local\Apps\2.0\LK0QAA7C.X1D\6W48N25K.TVN\neof..tion_0000000000000000_0003.000d_9b30a95929896b03\NeoFly.exe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Program Files (x86)\SimMarket\FlightControlReplay\FlightControlReplay.exe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Windows\System32\Taskmgr.exe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume5\Games\Nouveau dossier\Cyberpunk 2077\bin\x64\Cyberpunk2077.exe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\ProgramData\NVIDIA Corporation\Downloader\7bdd1c9de7d5b89fbbeea7029776fbdb\GeForce_Experience_Update_v3.25.0.84_Beta_7DCD72.exe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Program Files\AMD\CNext\CNext\RadeonSoftware.exe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume5\Games\Nouveau dossier\__Installer\vc\vc2015\redist\vc_redist.x86.exe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume5\Games\Nouveau dossier\__Installer\vc\vc2015\redist\vc_redist.x64.exe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume5\Games\Nouveau dossier\bfv.exe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Windows\System32\dllhost.exe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Users\gband\Downloads\QuickDiag.exe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Power\User\PowerSchemes\381b4222-f694-41f0-9685-ff5bb260df2e]~[Description] : @%SystemRoot%\system32\powrprof.dll,-14,Automatically balances performance with energy consumption on capable hardware. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Power\User\PowerSchemes\381b4222-f694-41f0-9685-ff5bb260df2e]~[FriendlyName] : @%SystemRoot%\system32\powrprof.dll,-15,Balanced (recommended) [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Power\User\PowerSchemes\3af9B8d9-7c97-431d-ad78-34a8bfea439f]~[Description] : @%SystemRoot%\system32\powrprof.dll,-1400,Favor performance instead of energy savings. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Power\User\PowerSchemes\3af9B8d9-7c97-431d-ad78-34a8bfea439f]~[FriendlyName] : @%SystemRoot%\system32\powrprof.dll,-1401,High Performance Overlay [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Power\User\PowerSchemes\8c5e7fda-e8bf-4a96-9a85-a6e23a8c635c]~[Description] : @%SystemRoot%\system32\powrprof.dll,-12,Favors performance, but may use more energy. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Power\User\PowerSchemes\8c5e7fda-e8bf-4a96-9a85-a6e23a8c635c]~[FriendlyName] : @%SystemRoot%\system32\powrprof.dll,-13,High Performance [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Power\User\PowerSchemes\961cc777-2547-4f9d-8174-7d86181b8a7a]~[Description] : @%SystemRoot%\system32\powrprof.dll,-1404,Favor energy savings over performance. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Power\User\PowerSchemes\961cc777-2547-4f9d-8174-7d86181b8a7a]~[FriendlyName] : @%SystemRoot%\system32\powrprof.dll,-1405,Better Battery-life Overlay [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Power\User\PowerSchemes\9897998c-92de-4669-853f-b7cd3ecb2790]~[Description] : Balanced power plan customized for AMD Ryzen™ processors. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Power\User\PowerSchemes\9897998c-92de-4669-853f-b7cd3ecb2790]~[FriendlyName] : AMD Ryzen™ Balanced [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Power\User\PowerSchemes\9935e61f-1661-40c5-ae2f-8495027d5d5d]~[Description] : High performance power plan customized for AMD Ryzen™ processors. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Power\User\PowerSchemes\9935e61f-1661-40c5-ae2f-8495027d5d5d]~[FriendlyName] : AMD Ryzen™ High Performance [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Power\User\PowerSchemes\a1841308-3541-4fab-bc81-f71556f20b4a]~[Description] : @%SystemRoot%\system32\powrprof.dll,-10,Saves energy by reducing your computer performance where possible. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Power\User\PowerSchemes\a1841308-3541-4fab-bc81-f71556f20b4a]~[FriendlyName] : @%SystemRoot%\system32\powrprof.dll,-11,Power Saver [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Power\User\PowerSchemes\ded574b5-45a0-4f42-8737-46345c09c238]~[Description] : @%SystemRoot%\system32\powrprof.dll,-1402,Maximize bias towards performance instead of energy savings. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Power\User\PowerSchemes\ded574b5-45a0-4f42-8737-46345c09c238]~[FriendlyName] : @%SystemRoot%\system32\powrprof.dll,-1403,Max Performance Overlay [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Power\User\PowerSchemes\e9a42b02-d5df-448d-aa00-03f14749eb61]~[Description] : @%SystemRoot%\system32\powrprof.dll,-18,Provides ultimate performance on higher end PCs. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Power\User\PowerSchemes\e9a42b02-d5df-448d-aa00-03f14749eb61]~[FriendlyName] : @%SystemRoot%\system32\powrprof.dll,-19,Ultimate Performance [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|Version [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|SequenceNumber [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|Microsoft.Windows.Search_cw5n1h2txyewy [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|Microsoft.Windows.ShellExperienceHost_cw5n1h2txyewy [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|windows.immersivecontrolpanel_cw5n1h2txyewy [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|MicrosoftWindows.Client.CBS_cw5n1h2txyewy [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|Microsoft.WindowsStore_8wekyb3d8bbwe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|Microsoft.Windows.Apprep.ChxApp_cw5n1h2txyewy [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|Microsoft.XboxGamingOverlay_8wekyb3d8bbwe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|64343GTDocStudio.OfficeDocOpener_3h5nez1g3qt2c [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|HaukeGtze.7-ZipFileManagerUnofficial_6bk20wvc8rfx2 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|Microsoft.ZuneMusic_8wekyb3d8bbwe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|Microsoft.LockApp_cw5n1h2txyewy [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|DolbyLaboratories.DolbyAccess_rz1tebttyb220 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|Microsoft.StorePurchaseApp_8wekyb3d8bbwe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|325289AEDD75.TorrentRTFREE_qtx9tqphctw9r [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|Microsoft.Windows.SecHealthUI_cw5n1h2txyewy [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|WuhanNetPowerTechnologyCo.3322537A536FD_63m8b6nby1dvp [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|NVIDIACorp.NVIDIAControlPanel_56jybvy8sckqj [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|microsoft.windowscommunicationsapps_8wekyb3d8bbwe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|19282JackieLiu.Notepads-Beta_echhpq9pdbte8 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|Microsoft.549981C3F5F10_8wekyb3d8bbwe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|LiveATC.net.LiveATC_0yfybvjjn1ddw [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|Microsoft.Windows.Photos_8wekyb3d8bbwe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|Microsoft.BingWeather_8wekyb3d8bbwe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|Windows.PrintDialog_cw5n1h2txyewy [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|Microsoft.ZuneVideo_8wekyb3d8bbwe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|Microsoft.MicrosoftSolitaireCollection_8wekyb3d8bbwe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|GlobalApptitude.GamePlan_1ksr0nz5tnfmg [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|50930OliverNeuschl.NotepadT_r8m9wmyz3tx4m [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|Microsoft.SkypeApp_kzf8qxf38zg5c [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|Microsoft.WindowsCalculator_8wekyb3d8bbwe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|Microsoft.YourPhone_8wekyb3d8bbwe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume2\Games\Nouveau dossier\Cyberpunk 2077\bin\x64\Cyberpunk2077.exe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume2\Games\Nouveau dossier\eFootball PES 2021\sider.exe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume2\Games\Nouveau dossier\eFootball PES 2021\PES2021.exe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Windows\explorer.exe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Program Files (x86)\Steam\steam.exe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Users\gband\AppData\Local\Discord\app-1.0.9003\Discord.exe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Users\gband\AppData\Local\Programs\SimBrief Downloader\SimBrief Downloader.exe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Windows\System32\rundll32.exe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Windows\System32\ApplicationFrameHost.exe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Program Files (x86)\Steam\steamapps\common\MicrosoftFlightSimulator\FlightSimulator.exe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Program Files\Google\Chrome\Application\chrome.exe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Program Files\MSFS2020 Map Enhancement\MSFS2020 Map Enhancement.exe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\FSUIPC7\FSUIPC7.exe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Users\gband\Documents\FSRealistic\FSRealistic.exe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Program Files\Navigraph\Simlink\NavigraphSimlink.exe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Program Files (x86)\FS2Crew Command Center\FS2CrewCommandCenter.exe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Users\gband\Documents\Traffic\AIG Taffic controler\AIGTech - Traffic Controller.exe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Program Files (x86)\Lanilogic\Self Loading Cargo\SLC.exe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Users\gband\AppData\Local\Programs\fbw-installer\FlyByWire Installer.exe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Users\gband\Documents\Addons linker\MSFS_AddonsLinker.exe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Program Files (x86)\Microsoft\Edge\Application\msedge.exe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Program Files (x86)\RivaTuner Statistics Server\RTSS.exe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Windows\System32\notepad.exe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Windows\System32\cmd.exe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Users\gband\AppData\Local\Apps\2.0\LK0QAA7C.X1D\6W48N25K.TVN\skac..tion_62396b27c2c60a41_0001.0001_e182734c20687b40\SKACARS.exe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Users\gband\AppData\Local\Microsoft\OneDrive\OneDrive.exe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Program Files (x86)\FSAirlines\FSAirlines.exe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Users\gband\AppData\Local\Programs\Navigraph Navdata Center\Navigraph Navdata Center.exe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Users\gband\AppData\Roaming\Telegram Desktop\Telegram.exe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Windows\System32\msiexec.exe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Users\gband\Documents\Enhanced Live Traffic\Enhanced Live Traffic.exe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Users\gband\Documents\Luke Air\AirTool.exe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Users\gband\AppData\Local\Temp\ZipExtractor.exe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Users\gband\AppData\Local\Programs\Sky4Sim Pad\Sky4Sim Pad.exe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume6\MFS2020\IVAO\PilotCore\pilot_core_fs2020.exe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume6\MFS2020\IVAO\PilotUI\PilotUI.exe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\REX Weather Force 2020\rexwxforceapp.exe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Users\gband\Documents\Traffic\AIG MManager\AIGTech - AI Manager.exe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Users\gband\AppData\Local\Apps\2.0\LK0QAA7C.X1D\6W48N25K.TVN\prem..tion_0000000000000000_0001.0001_d5bbe5a2780b9090\PremCARS.exe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Users\gband\Documents\opentrack-2.3\vPilot-Setup-3.0.7.exe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Users\gband\AppData\Local\vPilot\vPilot.exe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Users\gband\Documents\opentrack-2.3\volanta-1.2.5.exe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Users\gband\AppData\Local\Programs\Volanta\Volanta.exe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Program Files\RealTrafficLauncher\jre\bin\javaw.exe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Program Files\RealTrafficLauncher\jre\bin\java.exe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Users\gband\AppData\Local\simtoolkitpro\app-0.8.12\Update.exe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Users\gband\AppData\Local\simtoolkitpro\app-0.8.12\SimToolkitPro.exe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Users\gband\AppData\Local\simtoolkitpro\app-0.8.12\resources\static\p3d\SimConnectServer.exe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume5\Games\Nouveau dossier\eFootball PES 2021\sider.exe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume5\Games\Nouveau dossier\eFootball PES 2021\PES2021.exe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Users\gband\Documents\NeoFly\NeoFly.exe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Users\gband\Documents\opentrack-2.3\Bijan_Season_Installer_V1.1\setup.exe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Windows\SysWOW64\msiexec.exe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Program Files (x86)\Bijan Season\Bijan Season Installer\Bijan Seasons.exe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Users\gband\Downloads\Just Flight - Air Hauler 2 for MSFS v3.00.11\AirHauler2.exe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Users\gband\Downloads\Just Flight - Air Hauler 2 for MSFS v3.00.11\FindPkgs.exe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Windows\System32\WerFault.exe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Users\gband\AppData\Local\Apps\2.0\LK0QAA7C.X1D\6W48N25K.TVN\neof..tion_0000000000000000_0003.000d_9b30a95929896b03\NeoFly.exe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Program Files (x86)\SimMarket\FlightControlReplay\FlightControlReplay.exe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Windows\System32\Taskmgr.exe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume5\Games\Nouveau dossier\Cyberpunk 2077\bin\x64\Cyberpunk2077.exe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\ProgramData\NVIDIA Corporation\Downloader\7bdd1c9de7d5b89fbbeea7029776fbdb\GeForce_Experience_Update_v3.25.0.84_Beta_7DCD72.exe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Program Files\AMD\CNext\CNext\RadeonSoftware.exe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume5\Games\Nouveau dossier\__Installer\vc\vc2015\redist\vc_redist.x86.exe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume5\Games\Nouveau dossier\__Installer\vc\vc2015\redist\vc_redist.x64.exe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume5\Games\Nouveau dossier\bfv.exe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Windows\System32\dllhost.exe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3835695913-52790398-83466441-1001]|\Device\HarddiskVolume3\Users\gband\Downloads\QuickDiag.exe ---------- | ADS ---------- | 20 LastEventLog Nom de l’application défaillante AIGTech - Traffic Controller.exe, version : 0.5.0.24, horodatage : 0x8fe69d05 Nom du module défaillant : KERNELBASE.dll, version : 10.0.19041.1466, horodatage : 0xe01c7650 Code d’exception : 0xe0434352 Décalage d’erreur : 0x0000000000034f69 ID du processus défaillant : 0x3c28 Heure de début de l’application défaillante : 0x01d81ed028d80326 Chemin d’accès de l’application défaillante : C:\Users\gband\Documents\Traffic\AIG Taffic controler\AIGTech - Traffic Controller.exe Chemin d’accès du module défaillant: C:\WINDOWS\System32\KERNELBASE.dll ID de rapport : 63d16646-ada1-4166-ad4b-31c2d1060cb8 Nom complet du package défaillant : ID de l’application relative au package défaillant : ------------ Application : AIGTech - Traffic Controller.exe Version du Framework : v4.0.30319 Description : le processus a été arrêté en raison d'une exception non gérée. Informations sur l'exception : System.Xml.XmlException à System.Xml.XmlTextReaderImpl.Throw(System.Exception) à System.Xml.XmlTextReaderImpl.ParseText(Int32 ByRef, Int32 ByRef, Int32 ByRef) à System.Xml.XmlTextReaderImpl.ParseText() à System.Xml.XmlTextReaderImpl.ParseElementContent() à System.Xml.XmlTextReaderImpl.Skip() à System.Configuration.XmlUtil.StrictSkipToNextElement(System.Configuration.ExceptionAction) à System.Configuration.BaseConfigurationRecord.ScanSectionsRecursive(System.Configuration.XmlUtil, System.String, Boolean, System.String, System.Configuration.OverrideModeSetting, Boolean) à System.Configuration.BaseConfigurationRecord.ScanSectionsRecursive(System.Configuration.XmlUtil, System.String, Boolean, System.String, System.Configuration.OverrideModeSetting, Boolean) à System.Configuration.BaseConfigurationRecord.ScanSections(System.Configuration.XmlUtil) à System.Configuration.BaseConfigurationRecord.InitConfigFromFile() Informations sur l'exception : System.Configuration.ConfigurationErrorsException à System.Configuration.ConfigurationSchemaErrors.ThrowIfErrors(Boolean) à System.Configuration.BaseConfigurationRecord.ThrowIfParseErrors(System.Configuration.ConfigurationSchemaErrors) à System.Configuration.ClientConfigurationSystem.OnConfigRemoved(System.Object, System.Configuration.Internal.InternalConfigEventArgs) Informations sur l'exception : System.Configuration.ConfigurationErrorsException à System.Configuration.ConfigurationManager.PrepareConfigSystem() à System.Configuration.ConfigurationManager.GetSection(System.String) à System.Configuration.PrivilegedConfigurationManager.GetSection(System.String) à System.Diagnostics.DiagnosticsConfiguration.GetConfigSection() à System.Diagnostics.DiagnosticsConfiguration.Initialize() à System.Diagnostics.DiagnosticsConfiguration.get_Sources() à System.Diagnostics.TraceSource.Initialize() à System.Net.Logging.InitializeLogging() à System.Net.Logging.get_On() à System.Net.ComNetOS..cctor() Informations sur l'exception : System.TypeInitializationException à System.Net.ServicePointManager..cctor() Informations sur l'exception : System.TypeInitializationException à System.Net.ServicePointManager.set_InternalConnectionLimit(Int32) à System.Net.ServicePointManager.set_DefaultConnectionLimit(Int32) à GMap.NET.GMaps..cctor() Informations sur l'exception : System.TypeInitializationException à GMap.NET.GMaps.get_Instance() à GMap.NET.WindowsPresentation.GMapControl..cctor() Informations sur l'exception : System.TypeInitializationException à GMap.NET.WindowsPresentation.GMapControl..ctor() Informations sur l'exception : System.Windows.Markup.XamlParseException à System.Windows.Markup.XamlReader.RewrapException(System.Exception, System.Xaml.IXamlLineInfo, System.Uri) à System.Windows.Markup.WpfXamlLoader.Load(System.Xaml.XamlReader, System.Xaml.IXamlObjectWriterFactory, Boolean, System.Object, System.Xaml.XamlObjectWriterSettings, System.Uri) à System.Windows.Markup.WpfXamlLoader.LoadBaml(System.Xaml.XamlReader, Boolean, System.Object, System.Xaml.Permissions.XamlAccessLevel, System.Uri) à System.Windows.Markup.XamlReader.LoadBaml(System.IO.Stream, System.Windows.Markup.ParserContext, System.Object, Boolean) à AIGTech.TrafficController.View.MainWindow..ctor(System.String) à AIGTech.TrafficController.App.Application_Startup(System.Object, System.Windows.StartupEventArgs) à System.Windows.Application.OnStartup(System.Windows.StartupEventArgs) à System.Windows.Application.<.ctor>b__1_0(System.Object) à System.Windows.Threading.ExceptionWrapper.InternalRealCall(System.Delegate, System.Object, Int32) à System.Windows.Threading.ExceptionWrapper.TryCatchWhen(System.Object, System.Delegate, System.Object, Int32, System.Delegate) à System.Windows.Threading.DispatcherOperation.InvokeImpl() à MS.Internal.CulturePreservingExecutionContext.CallbackWrapper(System.Object) à System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) à System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) à System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object) à MS.Internal.CulturePreservingExecutionContext.Run(MS.Internal.CulturePreservingExecutionContext, System.Threading.ContextCallback, System.Object) à System.Windows.Threading.DispatcherOperation.Invoke() à System.Windows.Threading.Dispatcher.ProcessQueue() à System.Windows.Threading.Dispatcher.WndProcHook(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef) à MS.Win32.HwndWrapper.WndProc(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef) à MS.Win32.HwndSubclass.DispatcherCallbackOperation(System.Object) à System.Windows.Threading.ExceptionWrapper.InternalRealCall(System.Delegate, System.Object, Int32) à System.Windows.Threading.ExceptionWrapper.TryCatchWhen(System.Object, System.Delegate, System.Object, Int32, System.Delegate) à System.Windows.Threading.Dispatcher.LegacyInvokeImpl(System.Windows.Threading.DispatcherPriority, System.TimeSpan, System.Delegate, System.Object, Int32) à MS.Win32.HwndSubclass.SubclassWndProc(IntPtr, Int32, IntPtr, IntPtr) à MS.Win32.UnsafeNativeMethods.DispatchMessage(System.Windows.Interop.MSG ByRef) à System.Windows.Threading.Dispatcher.PushFrameImpl(System.Windows.Threading.DispatcherFrame) à System.Windows.Application.RunDispatcher(System.Object) à System.Windows.Application.RunInternal(System.Windows.Window) à AIGTech.TrafficController.App.Main() ------------ Nom de l’application défaillante FlightSimulator.exe, version : 1.22.2.0, horodatage : 0x00000000 Nom du module défaillant : ntdll.dll, version : 10.0.19041.1466, horodatage : 0xe2f8ca76 Code d’exception : 0xc0000409 Décalage d’erreur : 0x00000000000923df ID du processus défaillant : 0x398c Heure de début de l’application défaillante : 0x01d81ece281509d4 Chemin d’accès de l’application défaillante : C:\Program Files (x86)\Steam\steamapps\common\MicrosoftFlightSimulator\FlightSimulator.exe Chemin d’accès du module défaillant: C:\WINDOWS\SYSTEM32\ntdll.dll ID de rapport : c78b5fb5-89e9-4681-adba-fa49de48d83f Nom complet du package défaillant : ID de l’application relative au package défaillant : ------------ Nom de l’application défaillante AIGTech - Traffic Controller.exe, version : 0.5.0.24, horodatage : 0x8fe69d05 Nom du module défaillant : KERNELBASE.dll, version : 10.0.19041.1466, horodatage : 0xe01c7650 Code d’exception : 0xe0434352 Décalage d’erreur : 0x0000000000034f69 ID du processus défaillant : 0x48d8 Heure de début de l’application défaillante : 0x01d81ec63baba00a Chemin d’accès de l’application défaillante : C:\Users\gband\Documents\Traffic\AIG Taffic controler\AIGTech - Traffic Controller.exe Chemin d’accès du module défaillant: C:\WINDOWS\System32\KERNELBASE.dll ID de rapport : ce15a3f5-8ea3-4cc4-9f78-adb8abf7aaaa Nom complet du package défaillant : ID de l’application relative au package défaillant : ------------ Application : AIGTech - Traffic Controller.exe Version du Framework : v4.0.30319 Description : le processus a été arrêté en raison d'une exception non gérée. Informations sur l'exception : System.Xml.XmlException à System.Xml.XmlTextReaderImpl.Throw(System.Exception) à System.Xml.XmlTextReaderImpl.ParseText(Int32 ByRef, Int32 ByRef, Int32 ByRef) à System.Xml.XmlTextReaderImpl.ParseText() à System.Xml.XmlTextReaderImpl.ParseElementContent() à System.Xml.XmlTextReaderImpl.Skip() à System.Configuration.XmlUtil.StrictSkipToNextElement(System.Configuration.ExceptionAction) à System.Configuration.BaseConfigurationRecord.ScanSectionsRecursive(System.Configuration.XmlUtil, System.String, Boolean, System.String, System.Configuration.OverrideModeSetting, Boolean) à System.Configuration.BaseConfigurationRecord.ScanSectionsRecursive(System.Configuration.XmlUtil, System.String, Boolean, System.String, System.Configuration.OverrideModeSetting, Boolean) à System.Configuration.BaseConfigurationRecord.ScanSections(System.Configuration.XmlUtil) à System.Configuration.BaseConfigurationRecord.InitConfigFromFile() Informations sur l'exception : System.Configuration.ConfigurationErrorsException à System.Configuration.ConfigurationSchemaErrors.ThrowIfErrors(Boolean) à System.Configuration.BaseConfigurationRecord.ThrowIfParseErrors(System.Configuration.ConfigurationSchemaErrors) à System.Configuration.ClientConfigurationSystem.OnConfigRemoved(System.Object, System.Configuration.Internal.InternalConfigEventArgs) Informations sur l'exception : System.Configuration.ConfigurationErrorsException à System.Configuration.ConfigurationManager.PrepareConfigSystem() à System.Configuration.ConfigurationManager.GetSection(System.String) à System.Configuration.PrivilegedConfigurationManager.GetSection(System.String) à System.Diagnostics.DiagnosticsConfiguration.GetConfigSection() à System.Diagnostics.DiagnosticsConfiguration.Initialize() à System.Diagnostics.DiagnosticsConfiguration.get_Sources() à System.Diagnostics.TraceSource.Initialize() à System.Net.Logging.InitializeLogging() à System.Net.Logging.get_On() à System.Net.ComNetOS..cctor() Informations sur l'exception : System.TypeInitializationException à System.Net.ServicePointManager..cctor() Informations sur l'exception : System.TypeInitializationException à System.Net.ServicePointManager.set_InternalConnectionLimit(Int32) à System.Net.ServicePointManager.set_DefaultConnectionLimit(Int32) à GMap.NET.GMaps..cctor() Informations sur l'exception : System.TypeInitializationException à GMap.NET.GMaps.get_Instance() à GMap.NET.WindowsPresentation.GMapControl..cctor() Informations sur l'exception : System.TypeInitializationException à GMap.NET.WindowsPresentation.GMapControl..ctor() Informations sur l'exception : System.Windows.Markup.XamlParseException à System.Windows.Markup.XamlReader.RewrapException(System.Exception, System.Xaml.IXamlLineInfo, System.Uri) à System.Windows.Markup.WpfXamlLoader.Load(System.Xaml.XamlReader, System.Xaml.IXamlObjectWriterFactory, Boolean, System.Object, System.Xaml.XamlObjectWriterSettings, System.Uri) à System.Windows.Markup.WpfXamlLoader.LoadBaml(System.Xaml.XamlReader, Boolean, System.Object, System.Xaml.Permissions.XamlAccessLevel, System.Uri) à System.Windows.Markup.XamlReader.LoadBaml(System.IO.Stream, System.Windows.Markup.ParserContext, System.Object, Boolean) à AIGTech.TrafficController.View.MainWindow..ctor(System.String) à AIGTech.TrafficController.App.Application_Startup(System.Object, System.Windows.StartupEventArgs) à System.Windows.Application.OnStartup(System.Windows.StartupEventArgs) à System.Windows.Application.<.ctor>b__1_0(System.Object) à System.Windows.Threading.ExceptionWrapper.InternalRealCall(System.Delegate, System.Object, Int32) à System.Windows.Threading.ExceptionWrapper.TryCatchWhen(System.Object, System.Delegate, System.Object, Int32, System.Delegate) à System.Windows.Threading.DispatcherOperation.InvokeImpl() à MS.Internal.CulturePreservingExecutionContext.CallbackWrapper(System.Object) à System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) à System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) à System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object) à MS.Internal.CulturePreservingExecutionContext.Run(MS.Internal.CulturePreservingExecutionContext, System.Threading.ContextCallback, System.Object) à System.Windows.Threading.DispatcherOperation.Invoke() à System.Windows.Threading.Dispatcher.ProcessQueue() à System.Windows.Threading.Dispatcher.WndProcHook(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef) à MS.Win32.HwndWrapper.WndProc(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef) à MS.Win32.HwndSubclass.DispatcherCallbackOperation(System.Object) à System.Windows.Threading.ExceptionWrapper.InternalRealCall(System.Delegate, System.Object, Int32) à System.Windows.Threading.ExceptionWrapper.TryCatchWhen(System.Object, System.Delegate, System.Object, Int32, System.Delegate) à System.Windows.Threading.Dispatcher.LegacyInvokeImpl(System.Windows.Threading.DispatcherPriority, System.TimeSpan, System.Delegate, System.Object, Int32) à MS.Win32.HwndSubclass.SubclassWndProc(IntPtr, Int32, IntPtr, IntPtr) à MS.Win32.UnsafeNativeMethods.DispatchMessage(System.Windows.Interop.MSG ByRef) à System.Windows.Threading.Dispatcher.PushFrameImpl(System.Windows.Threading.DispatcherFrame) à System.Windows.Application.RunDispatcher(System.Object) à System.Windows.Application.RunInternal(System.Windows.Window) à AIGTech.TrafficController.App.Main() ------------ Échec de l’activation des licences (slui.exe) avec le code d’erreur suivant : hr=0x803F7001 Arguments de la ligne de commande : RuleId=31e71c49-8da7-4a2f-ad92-45d98a1c79ba;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=UserLogon;SessionId=3 ------------ Échec de l’activation des licences (slui.exe) avec le code d’erreur suivant : hr=0x8007139F Arguments de la ligne de commande : RuleId=31e71c49-8da7-4a2f-ad92-45d98a1c79ba;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=NetworkAvailable ------------ Nom de l’application défaillante AIGTech - Traffic Controller.exe, version : 0.5.0.24, horodatage : 0x8fe69d05 Nom du module défaillant : KERNELBASE.dll, version : 10.0.19041.1466, horodatage : 0xe01c7650 Code d’exception : 0xe0434352 Décalage d’erreur : 0x0000000000034f69 ID du processus défaillant : 0x2090 Heure de début de l’application défaillante : 0x01d81eb259dd8e71 Chemin d’accès de l’application défaillante : C:\Users\gband\Documents\Traffic\AIG Taffic controler\AIGTech - Traffic Controller.exe Chemin d’accès du module défaillant: C:\WINDOWS\System32\KERNELBASE.dll ID de rapport : 59c0375a-5af8-4c0c-8569-2ce33ef73471 Nom complet du package défaillant : ID de l’application relative au package défaillant : ------------ Application : AIGTech - Traffic Controller.exe Version du Framework : v4.0.30319 Description : le processus a été arrêté en raison d'une exception non gérée. Informations sur l'exception : System.Xml.XmlException à System.Xml.XmlTextReaderImpl.Throw(System.Exception) à System.Xml.XmlTextReaderImpl.ParseText(Int32 ByRef, Int32 ByRef, Int32 ByRef) à System.Xml.XmlTextReaderImpl.ParseText() à System.Xml.XmlTextReaderImpl.ParseElementContent() à System.Xml.XmlTextReaderImpl.Skip() à System.Configuration.XmlUtil.StrictSkipToNextElement(System.Configuration.ExceptionAction) à System.Configuration.BaseConfigurationRecord.ScanSectionsRecursive(System.Configuration.XmlUtil, System.String, Boolean, System.String, System.Configuration.OverrideModeSetting, Boolean) à System.Configuration.BaseConfigurationRecord.ScanSectionsRecursive(System.Configuration.XmlUtil, System.String, Boolean, System.String, System.Configuration.OverrideModeSetting, Boolean) à System.Configuration.BaseConfigurationRecord.ScanSections(System.Configuration.XmlUtil) à System.Configuration.BaseConfigurationRecord.InitConfigFromFile() Informations sur l'exception : System.Configuration.ConfigurationErrorsException à System.Configuration.ConfigurationSchemaErrors.ThrowIfErrors(Boolean) à System.Configuration.BaseConfigurationRecord.ThrowIfParseErrors(System.Configuration.ConfigurationSchemaErrors) à System.Configuration.ClientConfigurationSystem.OnConfigRemoved(System.Object, System.Configuration.Internal.InternalConfigEventArgs) Informations sur l'exception : System.Configuration.ConfigurationErrorsException à System.Configuration.ConfigurationManager.PrepareConfigSystem() à System.Configuration.ConfigurationManager.GetSection(System.String) à System.Configuration.PrivilegedConfigurationManager.GetSection(System.String) à System.Diagnostics.DiagnosticsConfiguration.GetConfigSection() à System.Diagnostics.DiagnosticsConfiguration.Initialize() à System.Diagnostics.DiagnosticsConfiguration.get_Sources() à System.Diagnostics.TraceSource.Initialize() à System.Net.Logging.InitializeLogging() à System.Net.Logging.get_On() à System.Net.ComNetOS..cctor() Informations sur l'exception : System.TypeInitializationException à System.Net.ServicePointManager..cctor() Informations sur l'exception : System.TypeInitializationException à System.Net.ServicePointManager.set_InternalConnectionLimit(Int32) à System.Net.ServicePointManager.set_DefaultConnectionLimit(Int32) à GMap.NET.GMaps..cctor() Informations sur l'exception : System.TypeInitializationException à GMap.NET.GMaps.get_Instance() à GMap.NET.WindowsPresentation.GMapControl..cctor() Informations sur l'exception : System.TypeInitializationException à GMap.NET.WindowsPresentation.GMapControl..ctor() Informations sur l'exception : System.Windows.Markup.XamlParseException à System.Windows.Markup.XamlReader.RewrapException(System.Exception, System.Xaml.IXamlLineInfo, System.Uri) à System.Windows.Markup.WpfXamlLoader.Load(System.Xaml.XamlReader, System.Xaml.IXamlObjectWriterFactory, Boolean, System.Object, System.Xaml.XamlObjectWriterSettings, System.Uri) à System.Windows.Markup.WpfXamlLoader.LoadBaml(System.Xaml.XamlReader, Boolean, System.Object, System.Xaml.Permissions.XamlAccessLevel, System.Uri) à System.Windows.Markup.XamlReader.LoadBaml(System.IO.Stream, System.Windows.Markup.ParserContext, System.Object, Boolean) à AIGTech.TrafficController.View.MainWindow..ctor(System.String) à AIGTech.TrafficController.App.Application_Startup(System.Object, System.Windows.StartupEventArgs) à System.Windows.Application.OnStartup(System.Windows.StartupEventArgs) à System.Windows.Application.<.ctor>b__1_0(System.Object) à System.Windows.Threading.ExceptionWrapper.InternalRealCall(System.Delegate, System.Object, Int32) à System.Windows.Threading.ExceptionWrapper.TryCatchWhen(System.Object, System.Delegate, System.Object, Int32, System.Delegate) à System.Windows.Threading.DispatcherOperation.InvokeImpl() à MS.Internal.CulturePreservingExecutionContext.CallbackWrapper(System.Object) à System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) à System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) à System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object) à MS.Internal.CulturePreservingExecutionContext.Run(MS.Internal.CulturePreservingExecutionContext, System.Threading.ContextCallback, System.Object) à System.Windows.Threading.DispatcherOperation.Invoke() à System.Windows.Threading.Dispatcher.ProcessQueue() à System.Windows.Threading.Dispatcher.WndProcHook(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef) à MS.Win32.HwndWrapper.WndProc(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef) à MS.Win32.HwndSubclass.DispatcherCallbackOperation(System.Object) à System.Windows.Threading.ExceptionWrapper.InternalRealCall(System.Delegate, System.Object, Int32) à System.Windows.Threading.ExceptionWrapper.TryCatchWhen(System.Object, System.Delegate, System.Object, Int32, System.Delegate) à System.Windows.Threading.Dispatcher.LegacyInvokeImpl(System.Windows.Threading.DispatcherPriority, System.TimeSpan, System.Delegate, System.Object, Int32) à MS.Win32.HwndSubclass.SubclassWndProc(IntPtr, Int32, IntPtr, IntPtr) à MS.Win32.UnsafeNativeMethods.DispatchMessage(System.Windows.Interop.MSG ByRef) à System.Windows.Threading.Dispatcher.PushFrameImpl(System.Windows.Threading.DispatcherFrame) à System.Windows.Application.RunDispatcher(System.Object) à System.Windows.Application.RunInternal(System.Windows.Window) à AIGTech.TrafficController.App.Main() ------------ Nom de l’application défaillante AIGTech - Traffic Controller.exe, version : 0.5.0.24, horodatage : 0x8fe69d05 Nom du module défaillant : KERNELBASE.dll, version : 10.0.19041.1466, horodatage : 0xe01c7650 Code d’exception : 0xe0434352 Décalage d’erreur : 0x0000000000034f69 ID du processus défaillant : 0x4b98 Heure de début de l’application défaillante : 0x01d81eac1287f8aa Chemin d’accès de l’application défaillante : C:\Users\gband\Documents\Traffic\AIG Taffic controler\AIGTech - Traffic Controller.exe Chemin d’accès du module défaillant: C:\WINDOWS\System32\KERNELBASE.dll ID de rapport : 6e1f0953-2205-4ccd-9ffb-06a901ed1d17 Nom complet du package défaillant : ID de l’application relative au package défaillant : ------------ Application : AIGTech - Traffic Controller.exe Version du Framework : v4.0.30319 Description : le processus a été arrêté en raison d'une exception non gérée. Informations sur l'exception : System.Xml.XmlException à System.Xml.XmlTextReaderImpl.Throw(System.Exception) à System.Xml.XmlTextReaderImpl.ParseText(Int32 ByRef, Int32 ByRef, Int32 ByRef) à System.Xml.XmlTextReaderImpl.ParseText() à System.Xml.XmlTextReaderImpl.ParseElementContent() à System.Xml.XmlTextReaderImpl.Skip() à System.Configuration.XmlUtil.StrictSkipToNextElement(System.Configuration.ExceptionAction) à System.Configuration.BaseConfigurationRecord.ScanSectionsRecursive(System.Configuration.XmlUtil, System.String, Boolean, System.String, System.Configuration.OverrideModeSetting, Boolean) à System.Configuration.BaseConfigurationRecord.ScanSectionsRecursive(System.Configuration.XmlUtil, System.String, Boolean, System.String, System.Configuration.OverrideModeSetting, Boolean) à System.Configuration.BaseConfigurationRecord.ScanSections(System.Configuration.XmlUtil) à System.Configuration.BaseConfigurationRecord.InitConfigFromFile() Informations sur l'exception : System.Configuration.ConfigurationErrorsException à System.Configuration.ConfigurationSchemaErrors.ThrowIfErrors(Boolean) à System.Configuration.BaseConfigurationRecord.ThrowIfParseErrors(System.Configuration.ConfigurationSchemaErrors) à System.Configuration.ClientConfigurationSystem.OnConfigRemoved(System.Object, System.Configuration.Internal.InternalConfigEventArgs) Informations sur l'exception : System.Configuration.ConfigurationErrorsException à System.Configuration.ConfigurationManager.PrepareConfigSystem() à System.Configuration.ConfigurationManager.GetSection(System.String) à System.Configuration.PrivilegedConfigurationManager.GetSection(System.String) à System.Diagnostics.DiagnosticsConfiguration.GetConfigSection() à System.Diagnostics.DiagnosticsConfiguration.Initialize() à System.Diagnostics.DiagnosticsConfiguration.get_Sources() à System.Diagnostics.TraceSource.Initialize() à System.Net.Logging.InitializeLogging() à System.Net.Logging.get_On() à System.Net.ComNetOS..cctor() Informations sur l'exception : System.TypeInitializationException à System.Net.ServicePointManager..cctor() Informations sur l'exception : System.TypeInitializationException à System.Net.ServicePointManager.set_InternalConnectionLimit(Int32) à System.Net.ServicePointManager.set_DefaultConnectionLimit(Int32) à GMap.NET.GMaps..cctor() Informations sur l'exception : System.TypeInitializationException à GMap.NET.GMaps.get_Instance() à GMap.NET.WindowsPresentation.GMapControl..cctor() Informations sur l'exception : System.TypeInitializationException à GMap.NET.WindowsPresentation.GMapControl..ctor() Informations sur l'exception : System.Windows.Markup.XamlParseException à System.Windows.Markup.XamlReader.RewrapException(System.Exception, System.Xaml.IXamlLineInfo, System.Uri) à System.Windows.Markup.WpfXamlLoader.Load(System.Xaml.XamlReader, System.Xaml.IXamlObjectWriterFactory, Boolean, System.Object, System.Xaml.XamlObjectWriterSettings, System.Uri) à System.Windows.Markup.WpfXamlLoader.LoadBaml(System.Xaml.XamlReader, Boolean, System.Object, System.Xaml.Permissions.XamlAccessLevel, System.Uri) à System.Windows.Markup.XamlReader.LoadBaml(System.IO.Stream, System.Windows.Markup.ParserContext, System.Object, Boolean) à AIGTech.TrafficController.View.MainWindow..ctor(System.String) à AIGTech.TrafficController.App.Application_Startup(System.Object, System.Windows.StartupEventArgs) à System.Windows.Application.OnStartup(System.Windows.StartupEventArgs) à System.Windows.Application.<.ctor>b__1_0(System.Object) à System.Windows.Threading.ExceptionWrapper.InternalRealCall(System.Delegate, System.Object, Int32) à System.Windows.Threading.ExceptionWrapper.TryCatchWhen(System.Object, System.Delegate, System.Object, Int32, System.Delegate) à System.Windows.Threading.DispatcherOperation.InvokeImpl() à MS.Internal.CulturePreservingExecutionContext.CallbackWrapper(System.Object) à System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) à System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) à System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object) à MS.Internal.CulturePreservingExecutionContext.Run(MS.Internal.CulturePreservingExecutionContext, System.Threading.ContextCallback, System.Object) à System.Windows.Threading.DispatcherOperation.Invoke() à System.Windows.Threading.Dispatcher.ProcessQueue() à System.Windows.Threading.Dispatcher.WndProcHook(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef) à MS.Win32.HwndWrapper.WndProc(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef) à MS.Win32.HwndSubclass.DispatcherCallbackOperation(System.Object) à System.Windows.Threading.ExceptionWrapper.InternalRealCall(System.Delegate, System.Object, Int32) à System.Windows.Threading.ExceptionWrapper.TryCatchWhen(System.Object, System.Delegate, System.Object, Int32, System.Delegate) à System.Windows.Threading.Dispatcher.LegacyInvokeImpl(System.Windows.Threading.DispatcherPriority, System.TimeSpan, System.Delegate, System.Object, Int32) à MS.Win32.HwndSubclass.SubclassWndProc(IntPtr, Int32, IntPtr, IntPtr) à MS.Win32.UnsafeNativeMethods.DispatchMessage(System.Windows.Interop.MSG ByRef) à System.Windows.Threading.Dispatcher.PushFrameImpl(System.Windows.Threading.DispatcherFrame) à System.Windows.Application.RunDispatcher(System.Object) à System.Windows.Application.RunInternal(System.Windows.Window) à AIGTech.TrafficController.App.Main() ------------ Nom de l’application défaillante AIGTech - Traffic Controller.exe, version : 0.5.0.24, horodatage : 0x8fe69d05 Nom du module défaillant : KERNELBASE.dll, version : 10.0.19041.1466, horodatage : 0xe01c7650 Code d’exception : 0xe0434352 Décalage d’erreur : 0x0000000000034f69 ID du processus défaillant : 0x35f4 Heure de début de l’application défaillante : 0x01d81eabf18fa00e Chemin d’accès de l’application défaillante : C:\Users\gband\Documents\Traffic\AIG Taffic controler\AIGTech - Traffic Controller.exe Chemin d’accès du module défaillant: C:\WINDOWS\System32\KERNELBASE.dll ID de rapport : 2b49beb1-c6aa-4e50-9b26-dce290679fc9 Nom complet du package défaillant : ID de l’application relative au package défaillant : ------------ Application : AIGTech - Traffic Controller.exe Version du Framework : v4.0.30319 Description : le processus a été arrêté en raison d'une exception non gérée. Informations sur l'exception : System.Xml.XmlException à System.Xml.XmlTextReaderImpl.Throw(System.Exception) à System.Xml.XmlTextReaderImpl.ParseText(Int32 ByRef, Int32 ByRef, Int32 ByRef) à System.Xml.XmlTextReaderImpl.ParseText() à System.Xml.XmlTextReaderImpl.ParseElementContent() à System.Xml.XmlTextReaderImpl.Skip() à System.Configuration.XmlUtil.StrictSkipToNextElement(System.Configuration.ExceptionAction) à System.Configuration.BaseConfigurationRecord.ScanSectionsRecursive(System.Configuration.XmlUtil, System.String, Boolean, System.String, System.Configuration.OverrideModeSetting, Boolean) à System.Configuration.BaseConfigurationRecord.ScanSectionsRecursive(System.Configuration.XmlUtil, System.String, Boolean, System.String, System.Configuration.OverrideModeSetting, Boolean) à System.Configuration.BaseConfigurationRecord.ScanSections(System.Configuration.XmlUtil) à System.Configuration.BaseConfigurationRecord.InitConfigFromFile() Informations sur l'exception : System.Configuration.ConfigurationErrorsException à System.Configuration.ConfigurationSchemaErrors.ThrowIfErrors(Boolean) à System.Configuration.BaseConfigurationRecord.ThrowIfParseErrors(System.Configuration.ConfigurationSchemaErrors) à System.Configuration.ClientConfigurationSystem.OnConfigRemoved(System.Object, System.Configuration.Internal.InternalConfigEventArgs) Informations sur l'exception : System.Configuration.ConfigurationErrorsException à System.Configuration.ConfigurationManager.PrepareConfigSystem() à System.Configuration.ConfigurationManager.GetSection(System.String) à System.Configuration.PrivilegedConfigurationManager.GetSection(System.String) à System.Diagnostics.DiagnosticsConfiguration.GetConfigSection() à System.Diagnostics.DiagnosticsConfiguration.Initialize() à System.Diagnostics.DiagnosticsConfiguration.get_Sources() à System.Diagnostics.TraceSource.Initialize() à System.Net.Logging.InitializeLogging() à System.Net.Logging.get_On() à System.Net.ComNetOS..cctor() Informations sur l'exception : System.TypeInitializationException à System.Net.ServicePointManager..cctor() Informations sur l'exception : System.TypeInitializationException à System.Net.ServicePointManager.set_InternalConnectionLimit(Int32) à System.Net.ServicePointManager.set_DefaultConnectionLimit(Int32) à GMap.NET.GMaps..cctor() Informations sur l'exception : System.TypeInitializationException à GMap.NET.GMaps.get_Instance() à GMap.NET.WindowsPresentation.GMapControl..cctor() Informations sur l'exception : System.TypeInitializationException à GMap.NET.WindowsPresentation.GMapControl..ctor() Informations sur l'exception : System.Windows.Markup.XamlParseException à System.Windows.Markup.XamlReader.RewrapException(System.Exception, System.Xaml.IXamlLineInfo, System.Uri) à System.Windows.Markup.WpfXamlLoader.Load(System.Xaml.XamlReader, System.Xaml.IXamlObjectWriterFactory, Boolean, System.Object, System.Xaml.XamlObjectWriterSettings, System.Uri) à System.Windows.Markup.WpfXamlLoader.LoadBaml(System.Xaml.XamlReader, Boolean, System.Object, System.Xaml.Permissions.XamlAccessLevel, System.Uri) à System.Windows.Markup.XamlReader.LoadBaml(System.IO.Stream, System.Windows.Markup.ParserContext, System.Object, Boolean) à AIGTech.TrafficController.View.MainWindow..ctor(System.String) à AIGTech.TrafficController.App.Application_Startup(System.Object, System.Windows.StartupEventArgs) à System.Windows.Application.OnStartup(System.Windows.StartupEventArgs) à System.Windows.Application.<.ctor>b__1_0(System.Object) à System.Windows.Threading.ExceptionWrapper.InternalRealCall(System.Delegate, System.Object, Int32) à System.Windows.Threading.ExceptionWrapper.TryCatchWhen(System.Object, System.Delegate, System.Object, Int32, System.Delegate) à System.Windows.Threading.DispatcherOperation.InvokeImpl() à MS.Internal.CulturePreservingExecutionContext.CallbackWrapper(System.Object) à System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) à System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) à System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object) à MS.Internal.CulturePreservingExecutionContext.Run(MS.Internal.CulturePreservingExecutionContext, System.Threading.ContextCallback, System.Object) à System.Windows.Threading.DispatcherOperation.Invoke() à System.Windows.Threading.Dispatcher.ProcessQueue() à System.Windows.Threading.Dispatcher.WndProcHook(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef) à MS.Win32.HwndWrapper.WndProc(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef) à MS.Win32.HwndSubclass.DispatcherCallbackOperation(System.Object) à System.Windows.Threading.ExceptionWrapper.InternalRealCall(System.Delegate, System.Object, Int32) à System.Windows.Threading.ExceptionWrapper.TryCatchWhen(System.Object, System.Delegate, System.Object, Int32, System.Delegate) à System.Windows.Threading.Dispatcher.LegacyInvokeImpl(System.Windows.Threading.DispatcherPriority, System.TimeSpan, System.Delegate, System.Object, Int32) à MS.Win32.HwndSubclass.SubclassWndProc(IntPtr, Int32, IntPtr, IntPtr) à MS.Win32.UnsafeNativeMethods.DispatchMessage(System.Windows.Interop.MSG ByRef) à System.Windows.Threading.Dispatcher.PushFrameImpl(System.Windows.Threading.DispatcherFrame) à System.Windows.Application.RunDispatcher(System.Object) à System.Windows.Application.RunInternal(System.Windows.Window) à AIGTech.TrafficController.App.Main() ------------ Nom de l’application défaillante AIGTech - Traffic Controller.exe, version : 0.5.0.24, horodatage : 0x8fe69d05 Nom du module défaillant : KERNELBASE.dll, version : 10.0.19041.1466, horodatage : 0xe01c7650 Code d’exception : 0xe0434352 Décalage d’erreur : 0x0000000000034f69 ID du processus défaillant : 0x411c Heure de début de l’application défaillante : 0x01d81eaadebee660 Chemin d’accès de l’application défaillante : C:\Users\gband\Documents\Traffic\AIG Taffic controler\AIGTech - Traffic Controller.exe Chemin d’accès du module défaillant: C:\WINDOWS\System32\KERNELBASE.dll ID de rapport : aad5d835-c4a9-4c7f-b1ea-7fec50f80cf4 Nom complet du package défaillant : ID de l’application relative au package défaillant : ------------ Application : AIGTech - Traffic Controller.exe Version du Framework : v4.0.30319 Description : le processus a été arrêté en raison d'une exception non gérée. Informations sur l'exception : System.Xml.XmlException à System.Xml.XmlTextReaderImpl.Throw(System.Exception) à System.Xml.XmlTextReaderImpl.ParseText(Int32 ByRef, Int32 ByRef, Int32 ByRef) à System.Xml.XmlTextReaderImpl.ParseText() à System.Xml.XmlTextReaderImpl.ParseElementContent() à System.Xml.XmlTextReaderImpl.Skip() à System.Configuration.XmlUtil.StrictSkipToNextElement(System.Configuration.ExceptionAction) à System.Configuration.BaseConfigurationRecord.ScanSectionsRecursive(System.Configuration.XmlUtil, System.String, Boolean, System.String, System.Configuration.OverrideModeSetting, Boolean) à System.Configuration.BaseConfigurationRecord.ScanSectionsRecursive(System.Configuration.XmlUtil, System.String, Boolean, System.String, System.Configuration.OverrideModeSetting, Boolean) à System.Configuration.BaseConfigurationRecord.ScanSections(System.Configuration.XmlUtil) à System.Configuration.BaseConfigurationRecord.InitConfigFromFile() Informations sur l'exception : System.Configuration.ConfigurationErrorsException à System.Configuration.ConfigurationSchemaErrors.ThrowIfErrors(Boolean) à System.Configuration.BaseConfigurationRecord.ThrowIfParseErrors(System.Configuration.ConfigurationSchemaErrors) à System.Configuration.ClientConfigurationSystem.OnConfigRemoved(System.Object, System.Configuration.Internal.InternalConfigEventArgs) Informations sur l'exception : System.Configuration.ConfigurationErrorsException à System.Configuration.ConfigurationManager.PrepareConfigSystem() à System.Configuration.ConfigurationManager.GetSection(System.String) à System.Configuration.PrivilegedConfigurationManager.GetSection(System.String) à System.Diagnostics.DiagnosticsConfiguration.GetConfigSection() à System.Diagnostics.DiagnosticsConfiguration.Initialize() à System.Diagnostics.DiagnosticsConfiguration.get_Sources() à System.Diagnostics.TraceSource.Initialize() à System.Net.Logging.InitializeLogging() à System.Net.Logging.get_On() à System.Net.ComNetOS..cctor() Informations sur l'exception : System.TypeInitializationException à System.Net.ServicePointManager..cctor() Informations sur l'exception : System.TypeInitializationException à System.Net.ServicePointManager.set_InternalConnectionLimit(Int32) à System.Net.ServicePointManager.set_DefaultConnectionLimit(Int32) à GMap.NET.GMaps..cctor() Informations sur l'exception : System.TypeInitializationException à GMap.NET.GMaps.get_Instance() à GMap.NET.WindowsPresentation.GMapControl..cctor() Informations sur l'exception : System.TypeInitializationException à GMap.NET.WindowsPresentation.GMapControl..ctor() Informations sur l'exception : System.Windows.Markup.XamlParseException à System.Windows.Markup.XamlReader.RewrapException(System.Exception, System.Xaml.IXamlLineInfo, System.Uri) à System.Windows.Markup.WpfXamlLoader.Load(System.Xaml.XamlReader, System.Xaml.IXamlObjectWriterFactory, Boolean, System.Object, System.Xaml.XamlObjectWriterSettings, System.Uri) à System.Windows.Markup.WpfXamlLoader.LoadBaml(System.Xaml.XamlReader, Boolean, System.Object, System.Xaml.Permissions.XamlAccessLevel, System.Uri) à System.Windows.Markup.XamlReader.LoadBaml(System.IO.Stream, System.Windows.Markup.ParserContext, System.Object, Boolean) à AIGTech.TrafficController.View.MainWindow..ctor(System.String) à AIGTech.TrafficController.App.Application_Startup(System.Object, System.Windows.StartupEventArgs) à System.Windows.Application.OnStartup(System.Windows.StartupEventArgs) à System.Windows.Application.<.ctor>b__1_0(System.Object) à System.Windows.Threading.ExceptionWrapper.InternalRealCall(System.Delegate, System.Object, Int32) à System.Windows.Threading.ExceptionWrapper.TryCatchWhen(System.Object, System.Delegate, System.Object, Int32, System.Delegate) à System.Windows.Threading.DispatcherOperation.InvokeImpl() à MS.Internal.CulturePreservingExecutionContext.CallbackWrapper(System.Object) à System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) à System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) à System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object) à MS.Internal.CulturePreservingExecutionContext.Run(MS.Internal.CulturePreservingExecutionContext, System.Threading.ContextCallback, System.Object) à System.Windows.Threading.DispatcherOperation.Invoke() à System.Windows.Threading.Dispatcher.ProcessQueue() à System.Windows.Threading.Dispatcher.WndProcHook(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef) à MS.Win32.HwndWrapper.WndProc(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef) à MS.Win32.HwndSubclass.DispatcherCallbackOperation(System.Object) à System.Windows.Threading.ExceptionWrapper.InternalRealCall(System.Delegate, System.Object, Int32) à System.Windows.Threading.ExceptionWrapper.TryCatchWhen(System.Object, System.Delegate, System.Object, Int32, System.Delegate) à System.Windows.Threading.Dispatcher.LegacyInvokeImpl(System.Windows.Threading.DispatcherPriority, System.TimeSpan, System.Delegate, System.Object, Int32) à MS.Win32.HwndSubclass.SubclassWndProc(IntPtr, Int32, IntPtr, IntPtr) à MS.Win32.UnsafeNativeMethods.DispatchMessage(System.Windows.Interop.MSG ByRef) à System.Windows.Threading.Dispatcher.PushFrameImpl(System.Windows.Threading.DispatcherFrame) à System.Windows.Application.RunDispatcher(System.Object) à System.Windows.Application.RunInternal(System.Windows.Window) à AIGTech.TrafficController.App.Main() ------------ Nom de l’application défaillante AIGTech - Traffic Controller.exe, version : 0.5.0.24, horodatage : 0x8fe69d05 Nom du module défaillant : KERNELBASE.dll, version : 10.0.19041.1466, horodatage : 0xe01c7650 Code d’exception : 0xe0434352 Décalage d’erreur : 0x0000000000034f69 ID du processus défaillant : 0x361c Heure de début de l’application défaillante : 0x01d81eaaa93d15d1 Chemin d’accès de l’application défaillante : C:\Users\gband\Documents\Traffic\AIG Taffic controler\AIGTech - Traffic Controller.exe Chemin d’accès du module défaillant: C:\WINDOWS\System32\KERNELBASE.dll ID de rapport : 978b1007-975f-4a0a-be3f-51db97819165 Nom complet du package défaillant : ID de l’application relative au package défaillant : ------------ Application : AIGTech - Traffic Controller.exe Version du Framework : v4.0.30319 Description : le processus a été arrêté en raison d'une exception non gérée. Informations sur l'exception : System.Xml.XmlException à System.Xml.XmlTextReaderImpl.Throw(System.Exception) à System.Xml.XmlTextReaderImpl.ParseText(Int32 ByRef, Int32 ByRef, Int32 ByRef) à System.Xml.XmlTextReaderImpl.ParseText() à System.Xml.XmlTextReaderImpl.ParseElementContent() à System.Xml.XmlTextReaderImpl.Skip() à System.Configuration.XmlUtil.StrictSkipToNextElement(System.Configuration.ExceptionAction) à System.Configuration.BaseConfigurationRecord.ScanSectionsRecursive(System.Configuration.XmlUtil, System.String, Boolean, System.String, System.Configuration.OverrideModeSetting, Boolean) à System.Configuration.BaseConfigurationRecord.ScanSectionsRecursive(System.Configuration.XmlUtil, System.String, Boolean, System.String, System.Configuration.OverrideModeSetting, Boolean) à System.Configuration.BaseConfigurationRecord.ScanSections(System.Configuration.XmlUtil) à System.Configuration.BaseConfigurationRecord.InitConfigFromFile() Informations sur l'exception : System.Configuration.ConfigurationErrorsException à System.Configuration.ConfigurationSchemaErrors.ThrowIfErrors(Boolean) à System.Configuration.BaseConfigurationRecord.ThrowIfParseErrors(System.Configuration.ConfigurationSchemaErrors) à System.Configuration.ClientConfigurationSystem.OnConfigRemoved(System.Object, System.Configuration.Internal.InternalConfigEventArgs) Informations sur l'exception : System.Configuration.ConfigurationErrorsException à System.Configuration.ConfigurationManager.PrepareConfigSystem() à System.Configuration.ConfigurationManager.GetSection(System.String) à System.Configuration.PrivilegedConfigurationManager.GetSection(System.String) à System.Diagnostics.DiagnosticsConfiguration.GetConfigSection() à System.Diagnostics.DiagnosticsConfiguration.Initialize() à System.Diagnostics.DiagnosticsConfiguration.get_Sources() à System.Diagnostics.TraceSource.Initialize() à System.Net.Logging.InitializeLogging() à System.Net.Logging.get_On() à System.Net.ComNetOS..cctor() Informations sur l'exception : System.TypeInitializationException à System.Net.ServicePointManager..cctor() Informations sur l'exception : System.TypeInitializationException à System.Net.ServicePointManager.set_InternalConnectionLimit(Int32) à System.Net.ServicePointManager.set_DefaultConnectionLimit(Int32) à GMap.NET.GMaps..cctor() Informations sur l'exception : System.TypeInitializationException à GMap.NET.GMaps.get_Instance() à GMap.NET.WindowsPresentation.GMapControl..cctor() Informations sur l'exception : System.TypeInitializationException à GMap.NET.WindowsPresentation.GMapControl..ctor() Informations sur l'exception : System.Windows.Markup.XamlParseException à System.Windows.Markup.XamlReader.RewrapException(System.Exception, System.Xaml.IXamlLineInfo, System.Uri) à System.Windows.Markup.WpfXamlLoader.Load(System.Xaml.XamlReader, System.Xaml.IXamlObjectWriterFactory, Boolean, System.Object, System.Xaml.XamlObjectWriterSettings, System.Uri) à System.Windows.Markup.WpfXamlLoader.LoadBaml(System.Xaml.XamlReader, Boolean, System.Object, System.Xaml.Permissions.XamlAccessLevel, System.Uri) à System.Windows.Markup.XamlReader.LoadBaml(System.IO.Stream, System.Windows.Markup.ParserContext, System.Object, Boolean) à AIGTech.TrafficController.View.MainWindow..ctor(System.String) à AIGTech.TrafficController.App.Application_Startup(System.Object, System.Windows.StartupEventArgs) à System.Windows.Application.OnStartup(System.Windows.StartupEventArgs) à System.Windows.Application.<.ctor>b__1_0(System.Object) à System.Windows.Threading.ExceptionWrapper.InternalRealCall(System.Delegate, System.Object, Int32) à System.Windows.Threading.ExceptionWrapper.TryCatchWhen(System.Object, System.Delegate, System.Object, Int32, System.Delegate) à System.Windows.Threading.DispatcherOperation.InvokeImpl() à MS.Internal.CulturePreservingExecutionContext.CallbackWrapper(System.Object) à System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) à System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) à System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object) à MS.Internal.CulturePreservingExecutionContext.Run(MS.Internal.CulturePreservingExecutionContext, System.Threading.ContextCallback, System.Object) à System.Windows.Threading.DispatcherOperation.Invoke() à System.Windows.Threading.Dispatcher.ProcessQueue() à System.Windows.Threading.Dispatcher.WndProcHook(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef) à MS.Win32.HwndWrapper.WndProc(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef) à MS.Win32.HwndSubclass.DispatcherCallbackOperation(System.Object) à System.Windows.Threading.ExceptionWrapper.InternalRealCall(System.Delegate, System.Object, Int32) à System.Windows.Threading.ExceptionWrapper.TryCatchWhen(System.Object, System.Delegate, System.Object, Int32, System.Delegate) à System.Windows.Threading.Dispatcher.LegacyInvokeImpl(System.Windows.Threading.DispatcherPriority, System.TimeSpan, System.Delegate, System.Object, Int32) à MS.Win32.HwndSubclass.SubclassWndProc(IntPtr, Int32, IntPtr, IntPtr) à MS.Win32.UnsafeNativeMethods.DispatchMessage(System.Windows.Interop.MSG ByRef) à System.Windows.Threading.Dispatcher.PushFrameImpl(System.Windows.Threading.DispatcherFrame) à System.Windows.Application.RunDispatcher(System.Object) à System.Windows.Application.RunInternal(System.Windows.Window) à AIGTech.TrafficController.App.Main() ------------ Nom de l’application défaillante FlightSimulator.exe, version : 1.22.2.0, horodatage : 0x00000000 Nom du module défaillant : ntdll.dll, version : 10.0.19041.1466, horodatage : 0xe2f8ca76 Code d’exception : 0xc0000409 Décalage d’erreur : 0x00000000000923df ID du processus défaillant : 0x2798 Heure de début de l’application défaillante : 0x01d81ea9fbfaf23a Chemin d’accès de l’application défaillante : C:\Program Files (x86)\Steam\steamapps\common\MicrosoftFlightSimulator\FlightSimulator.exe Chemin d’accès du module défaillant: C:\WINDOWS\SYSTEM32\ntdll.dll ID de rapport : 21c668b7-9687-463f-993c-38fafb10d6c0 Nom complet du package défaillant : ID de l’application relative au package défaillant : ------------ Échec de l’activation des licences (slui.exe) avec le code d’erreur suivant : hr=0x803F7001 Arguments de la ligne de commande : RuleId=31e71c49-8da7-4a2f-ad92-45d98a1c79ba;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=UserLogon;SessionId=2 ------------ ----------( EOF)---------- - 6513 | 23:05:02