• Hi there and welcome to PC Help Forum (PCHF), a more effective way to get the Tech Support you need!
    We have Experts in all areas of Tech, including Malware Removal, Crash Fixing and BSOD's , Microsoft Windows, Computer DIY and PC Hardware, Networking, Gaming, Tablets and iPads, General and Specific Software Support and so much more.

    Why not Click Here To Sign Up and start enjoying great FREE Tech Support.

    This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

Apps and files temporarily gone

Status
Not open for further replies.
Hey,
Today when i turned on my computer it took a little longer than the usual. While loading it said "preparing windows" and once I got to the desktop I found out that not everything was in there: some apps that i've had installed for a long time were there, but some others were not. Chrome, for example, was installed, but it was not on the bottom personalizable bar (like it had always been), but what's worse is that not only they were not on the desktop, they just weren't anywhere on the computer, as if I've never installed them. The download (and many other) folders were empty, in fact many files (videos, images, etc.) were gone too, but not all!
Once I restarted everything went back to normal: all apps and files were there, safe and installed. Should I be worried? Could this be caused by a virus/dying hard disk/windows 10/something faulty hardware-wise? What would you advise me to do? I've had this version of win 10 installed for quite some months. I run crystal disk info, and this is its report.
Thanks a lot in advance!
 
I just checked the updates' chronology and no, I haven't! The last attempt to install an update was three days ago, I've used the computer in the meantime and I've only had this problem showing up today
 
A couple of quick scans will tell us if there is malware on your machine.





Adware Cleaner Scan.

Please download AdwCleaner by Xplode onto your desktop.


  • Close all open programs and internet browsers.
  • Right Click on adwcleaner.exe and run as admin to run the tool.
  • Click on Scan button.
  • When the scan has finished click on Clean button.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please Attach the contents of that logfile with your next reply.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.

Quick Diag Scan.
===================================================================


Download Quick Diag to your desktop.
Very Important!! -- Make sure program is on your desktop.
Disable your Antivirus/Antispyware prior to scanning.
Right Click Run as Administrator.
Select the Quick Scan.


upload_2017-2-23_9-27-51-png.1654




Post the log that is generated in your next post.
You should attach this file as it is rather large, you can click on attach files when you reply.
 
  • Like
Reactions: Rucky
Hey, I've already done a complete scan with the windows defender security center and a quick scan with malwarebytes, both updated to their latest versions and they both found nothing
 
Not one tool can find all malware, the Quick Diag Scan will tell me for sure if there is no malware. Adware cleaner usually finds a bit of trash as well if you have never run it.
 
  • Like
Reactions: Rucky
If you have issues with Quick Diag, then this tool will be fine for diagnostics....

Site is in French so the download button is the same as the picture below..



4848





ZHP Diag Scan Click here to download.


1. Right Click Run as Admin.

2. Click the Options button.

Click on Check All
Then Click Validate
Then click close.



upload_2017-4-26_17-16-39-png.2074






2. Click the Scanner button.




upload_2017-2-23_3-32-26-png.1647



When complete please push the report button.
A notepad will open... copy and paste the report in your next reply.
 
  • Like
Reactions: Rucky
Okay, I'll start by pasting the report of adwcleaner

# -------------------------------
# Malwarebytes AdwCleaner 7.3.0.0
# -------------------------------
# Build: 04-04-2019
# Database: 2019-06-28.1 (Cloud)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start: 07-14-2019
# Duration: 00:00:00
# OS: Windows 10 Pro
# Cleaned: 1
# Failed: 0


***** [ Services ] *****

No malicious services cleaned.

***** [ Folders ] *****

No malicious folders cleaned.

***** [ Files ] *****

Deleted C:\Users\Luca\AppData\Local\Temp\Utils.dll

***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

No malicious shortcuts cleaned.

***** [ Tasks ] *****

No malicious tasks cleaned.

***** [ Registry ] *****

No malicious registry entries cleaned.

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries cleaned.

***** [ Chromium URLs ] *****

No malicious Chromium URLs cleaned.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries cleaned.

***** [ Firefox URLs ] *****

No malicious Firefox URLs cleaned.


*************************

[+] Delete Tracing Keys
[+] Reset Winsock

*************************

AdwCleaner[S00].txt - [1298 octets] - [14/07/2019 09:42:57]

########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C00].txt ##########
 
I now have the report of quickdiag too, but it's in Italian. Please tell me if that's a problem. Could you tell me what does this report mean? Like, if any problems have been detected or not, things like that. Thanks a lot!

Code:
--------------- QuickDiag | g3n-h@ckm@n | V5_27.02.19.1 ---------------

----- XP | Vista | 7 | 8 | 8.1 | 10 - 32/64 bits ----- - Start 14/07/2019 10:07:25

Updated 27/02/2019 | 11:10 (GMT) by g3n-h@ckm@n
Contact : http://www.sosvirus.net/

Time Zone : (UTC+01:00) Amsterdam, Berlino, Berna, Roma, Stoccolma, Vienna
[Luca (Administrator)] - [BUGCODE-USB-DRI] (S-1-5-21-2971312339-4097301404-2670616240-1001)

System: Microsoft Windows 10 Pro - - (10.0.15063) -  BuildType: Multiprocessor Free - OSLanguage: 1040 (0410) -> (1703)
System: AutoReboot: True - DebugFilePath: %SystemRoot%\MEMORY.DMP - KernelDumpOnly: False - OverwriteExistingDebugFile: True - WriteDebugInfo: True - WriteToSystemLog: True
Boot : Microsoft Windows 10 Pro|C:\Windows|\Device\Harddisk0\Partition1
Boot : Normal boot
PC: To be filled by O.E.M. - Gigabyte Technology Co., Ltd. - IdNumber: To be filled by O.E.M. - UUID: 032B0290-0434-05D2-F806-780700080009
Processor : X64 - 3403 Mhz - Intel(R) Core(TM) i5-3570K CPU @ 3.40GHz
BIOS Date: 01/06/14 13:03:08 Ver: 04.06.05 - en|US|iso8859-1 - American Megatrends Inc. - S/N: To be filled by O.E.M. - F18i - ALASKA - 1072009
CoreTemp : 29.8 Celsius

----------| Quick


---------- | SoundDevice

Dispositivo High Definition Audio - Status: OK - Manufacturer: Microsoft - PNPDeviceID: HDAUDIO\FUNC_01&VEN_1106&DEV_0441&SUBSYS_1458A014&REV_1001\4&36B8CB0&0&0201
AMD High Definition Audio Device - Status: OK - Manufacturer: Advanced Micro Devices - PNPDeviceID: HDAUDIO\FUNC_01&VEN_1002&DEV_AA01&SUBSYS_00AA0100&REV_1007\5&3B18104A&0&0001

---------- | Video

Radeon RX 580 Series - Resolution: 1920x1080 - Colors: 4294967296 - RefreshRate: 59 - 32 Bits Per Pixel - DeviceID: VideoController1 - Drivers: aticfx64.dll,aticfx64.dll,aticfx64.dll,amdxc64.dll,aticfx32,aticfx32,aticfx32,amdxc32,atiumd64,atidxx64.dll,atidxx64.dll,atiumdag,atidxx32,atidxx32,atiumdva,atiumd6a.cap,atitmm64 - PNPDeviceID: PCI\VEN_1002&DEV_67DF&SUBSYS_E3661DA2&REV_E7\4&B77C4C1&0&0008 - AdapterCompatibility: Advanced Micro Devices, Inc. - RAM: -1048576
Inegrated Video Chipset DeviceName: Radeon RX 580 Series - DriverVersion: 8.14.1.6543 - SpecificationVersion: 1025

---------- | Codecs

c:\windows\system32\tsbyuv.dll - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 16896 -  Manufacturer: Microsoft Corporation - Status: OK
c:\windows\system32\msadp32.acm - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 35208 -  Manufacturer: Microsoft Corporation - Status: OK
c:\windows\system32\msyuv.dll - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 28160 -  Manufacturer: Microsoft Corporation - Status: OK
c:\windows\system32\msrle32.dll - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 17920 -  Manufacturer: Microsoft Corporation - Status: OK
c:\windows\system32\msgsm32.acm - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 42488 -  Manufacturer: Microsoft Corporation - Status: OK
c:\windows\system32\msvidc32.dll - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 38912 -  Manufacturer: Microsoft Corporation - Status: OK
c:\windows\system32\iyuv_32.dll - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 53760 -  Manufacturer: Microsoft Corporation - Status: OK
c:\windows\system32\msg711.acm - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 25920 -  Manufacturer: Microsoft Corporation - Status: OK
c:\windows\system32\rtvcvfw64.dll - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 246272 -  Manufacturer: - Status: OK
c:\windows\system32\l3codeca.acm - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 84992 -  Manufacturer: Fraunhofer Institut Integrierte Schaltungen IIS - Status: OK
c:\windows\system32\imaadp32.acm - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 35760 -  Manufacturer: Microsoft Corporation - Status: OK

---------- | CPU

CPU #1 value:3 %
CPU #2 value:0 %
CPU #3 value:0 %
CPU #4 value:3 %
Total Overall CPU Usage value:0 %

---------- | Network

Qualcomm Atheros AR8161 PCI-E Gigabit Ethernet Controller [NDIS 6.30] : SENT:40,171 bytes/sec / RECVD:40,171 bytes/sec
Teredo Tunneling Pseudo-Interface : SENT:0 bytes/sec / RECVD:0 bytes/sec

Overall -> SEND Maxium:40,171 bytes/sec,  /  RECEIVE Maximum:40,171 bytes/sec

Microsoft Kernel Debug Network Adapter - - Microsoft - Status: - PnPID : ROOT\KDNIC\0000
Qualcomm Atheros AR8161 PCI-E Gigabit Ethernet Controller (NDIS 6.30) - Ethernet 802.3 - Qualcomm Atheros - Status: - PnPID : PCI\VEN_1969&DEV_1091&SUBSYS_E0001458&REV_10\4&841E55&0&00E6
Teredo Tunneling Pseudo-Interface - Tunnel - Microsoft - Status: - PnPID : SWD\IP_TUNNEL_VBUS\TEREDO_TUNNEL_DEVICE
WAN Miniport (SSTP) - - - Status: - PnPID :
WAN Miniport (IKEv2) - - - Status: - PnPID :
WAN Miniport (L2TP) - - - Status: - PnPID :
WAN Miniport (PPTP) - - - Status: - PnPID :
WAN Miniport (PPPOE) - - - Status: - PnPID :
WAN Miniport (IP) - - - Status: - PnPID :
WAN Miniport (IPv6) - - - Status: - PnPID :
WAN Miniport (Network Monitor) - - - Status: - PnPID :
Bluetooth Device (RFCOMM Protocol TDI) - - - Status: - PnPID :
Bluetooth Device (Personal Area Network) - - - Status: - PnPID :
Realtek RTL8187 Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter - - - Status: - PnPID :
Realtek RTL8187 Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter - - - Status: - PnPID :

---------- | Memory

RAM = Total (MB) : 8345 | Free (MB) : 5846
Pagefile = Total (MB) : 9656 | Free (MB) : 7005
Virtual = Total (MB) : 4194 | Free (MB) : 3886

Physical Memory 0 : Capacity: 2147483648 - ChannelB-DIMM1 - Posit.: 2 - Manufacturer: Kingston - PartNumber: 9905403-151.A00LF - S/N: 6C120D3D
Physical Memory 1 : Capacity: 4294967296 - ChannelA-DIMM1 - Posit.: 1 - Manufacturer: 029E - PartNumber: CMZ8GX3M2A1600C9  - S/N: 00000000
Physical Memory 2 : Capacity: 2147483648 - ChannelB-DIMM0 - Posit.: 1 - Manufacturer: Kingston - PartNumber: 9905403-151.A00LF - S/N: 6D12DB3C

---------- | SID Users

Administrator : [S-1-5-21-2971312339-4097301404-2670616240-500]
DefaultAccount : [S-1-5-21-2971312339-4097301404-2670616240-503]
Guest : [S-1-5-21-2971312339-4097301404-2670616240-501]
Luca : [S-1-5-21-2971312339-4097301404-2670616240-1001]
Administrators : [S-1-5-32-544]
Amministratori Hyper-V : [S-1-5-32-578]
Backup Operators : [S-1-5-32-551]
Cryptographic Operators : [S-1-5-32-569]
Distributed COM Users : [S-1-5-32-562]
Guests : [S-1-5-32-546]
IIS_IUSRS : [S-1-5-32-568]
Lettori registri eventi : [S-1-5-32-573]
Network Configuration Operators : [S-1-5-32-556]
Operatori assistenza controllo di accesso : [S-1-5-32-579]
Performance Log Users : [S-1-5-32-559]
Performance Monitor Users : [S-1-5-32-558]
Power Users : [S-1-5-32-547]
Replicator : [S-1-5-32-552]
System Managed Accounts Group : [S-1-5-32-581]
Users : [S-1-5-32-545]
Utenti desktop remoto : [S-1-5-32-555]
Utenti gestione remota : [S-1-5-32-580]

---------- | SystemAccounts

Name: Everyone - SID: S-1-1-0 - SIDType: 5 - Status: OK
Name: LOCALE - SID: S-1-2-0 - SIDType: 5 - Status: OK
Name: CREATOR OWNER - SID: S-1-3-0 - SIDType: 5 - Status: OK
Name: GRUPPO CREATORE - SID: S-1-3-1 - SIDType: 5 - Status: OK
Name: CREATOR OWNER SERVER - SID: S-1-3-2 - SIDType: 5 - Status: OK
Name: CREATOR GROUP SERVER - SID: S-1-3-3 - SIDType: 5 - Status: OK
Name: DIRITTI PROPRIETARIO - SID: S-1-3-4 - SIDType: 5 - Status: OK
Name: REMOTO - SID: S-1-5-1 - SIDType: 5 - Status: OK
Name: NETWORK - SID: S-1-5-2 - SIDType: 5 - Status: OK
Name: BATCH - SID: S-1-5-3 - SIDType: 5 - Status: OK
Name: INTERACTIVE - SID: S-1-5-4 - SIDType: 5 - Status: OK
Name: SERVIZIO - SID: S-1-5-6 - SIDType: 5 - Status: OK
Name: ACCESSO ANONIMO - SID: S-1-5-7 - SIDType: 5 - Status: OK
Name: PROXY - SID: S-1-5-8 - SIDType: 5 - Status: OK
Name: SYSTEM - SID: S-1-5-18 - SIDType: 5 - Status: OK
Name: CONTROLLER DI DOMINIO ORGANIZZAZIONE - SID: S-1-5-9 - SIDType: 5 - Status: OK
Name: SELF - SID: S-1-5-10 - SIDType: 5 - Status: OK
Name: Authenticated Users - SID: S-1-5-11 - SIDType: 5 - Status: OK
Name: RESTRIZIONI - SID: S-1-5-12 - SIDType: 5 - Status: OK
Name: UTENTE DI TERMINAL SERVER - SID: S-1-5-13 - SIDType: 5 - Status: OK
Name: REMOTE INTERACTIVE LOGON - SID: S-1-5-14 - SIDType: 5 - Status: OK
Name: IUSR - SID: S-1-5-17 - SIDType: 5 - Status: OK
Name: SERVIZIO LOCALE - SID: S-1-5-19 - SIDType: 5 - Status: OK
Name: SERVIZIO DI RETE - SID: S-1-5-20 - SIDType: 5 - Status: OK
Name: BUILTIN - SID: S-1-5-32 - SIDType: 3 - Status: OK

---------- | Drives

C:\ -> [Fixed] | [] | Total : 390.19 Go | Free : 113.31 Go -> NTFS [SATA]
D:\ -> [Fixed] | [] | Total : 540.88 Go | Free : 198.45 Go -> NTFS [SATA]

Disk Usage Information [2 total Physical Disks]

Physical Drive #0 [C:, D:] : Read:0 bytes/sec, Written:0 bytes/sec Max Read:0 bytes/sec, Max Write:0 bytes/sec
Physical Drive #1 [F:] : Read:0 bytes/sec, Written:0 bytes/sec Max Read:0 bytes/sec, Max Write:0 bytes/sec

Overall - Read Maximum:0 bytes/sec, Write Maximum:0 bytes/sec

DeviceID: \\.\PHYSICALDRIVE0 - Status: OK - IDE - Fixed hard disk media - 3 Part. - PnPID : SCSI\DISK&VEN_WDC&PROD_WD10EZEX-00WN4A0\4&4DDA929&0&000000
DeviceID: \\.\PHYSICALDRIVE1 - Status: OK - USB - - 0 Part. - PnPID : USBSTOR\DISK&VEN_GENERIC&PROD_STORAGE_DEVICE&REV_0.00\00000000000006&0

---------- | Windows updates - Activation - License


W.A.T : :)

Test 1 : Windows Is Activated
Test 2 : Windows Is Activated

Volume License


---------- | Browsers

IE : 11.0.15063.850     (© Microsoft Corporation. Tutti i diritti riservati.)
GC : 75.0.3770.100     (Copyright 2019 Google LLC.)

Default : "C:\Program Files\Internet Explorer\iexplore.exe"

---------- | FlashPlayer

FlashPlayer ActiveX : 31.0.0.153

---------- | Security

AV : Windows Defender Enabled
AS : Windows Defender Enabled
FW : WINDOWS Firewall
WMI : OK
WU: Windows Update Service [Manual(3)] = Running
AS: Windows Defender [Auto(2)] = Running
WMI: Windows Management Instrumentation [Auto(2)] = Running



---------- | Running processes

388 | [Owner : SYSTEM | Parent : 4(System) | ?????] - (.Microsoft Corporation - Gestione sessioni di Windows.) - (10.0.15063.0) = C:\Windows\System32\smss.exe     [18/03/2017 22:57:38]    CPU Usage:0 %
488 | [Owner : SYSTEM | Parent : 472() | ?????] - (.Microsoft Corporation - Processo runtime client server.) - (10.0.15063.0) = C:\Windows\System32\csrss.exe     [18/03/2017 22:57:38]    CPU Usage:0 %
604 | [Owner : SYSTEM | Parent : 472() | ?????] - (.Microsoft Corporation - Applicazione di avvio di Windows.) - (10.0.15063.502) = C:\Windows\System32\wininit.exe     [04/09/2017 19:42:57]    CPU Usage:0 %
616 | [Owner : SYSTEM | Parent : 596() | ?????] - (.Microsoft Corporation - Processo runtime client server.) - (10.0.15063.0) = C:\Windows\System32\csrss.exe     [18/03/2017 22:57:38]    CPU Usage:0 %
684 | [Owner : SYSTEM | Parent : 604(wininit.exe) | ?????] - (.Microsoft Corporation - App Servizi e Controller.) - (10.0.15063.1356) = C:\Windows\System32\services.exe     [25/12/2018 20:15:46]    CPU Usage:0 %
692 | [Owner : SYSTEM | Parent : 604(wininit.exe) | 14.34 Mo] - (.Microsoft Corporation - Local Security Authority Process.) - (10.0.15063.1266) = C:\Windows\System32\lsass.exe     [24/09/2018 21:20:47]    CPU Usage:0 %
808 | [Owner : SYSTEM | Parent : 684(services.exe) | 3.71 Mo] - (.Microsoft Corporation - Processo host per servizi di Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe     [18/03/2017 22:58:21]    CPU Usage:0 %
828 | [Owner : UMFD-0 | Parent : 604(wininit.exe) | 3.64 Mo] - (.Microsoft Corporation - Usermode Font Driver Host.) - (10.0.15063.994) = C:\Windows\System32\fontdrvhost.exe     [30/04/2018 21:23:15]    CPU Usage:0 %
844 | [Owner : SYSTEM | Parent : 684(services.exe) | 23.64 Mo] - (.Microsoft Corporation - Processo host per servizi di Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe     [18/03/2017 22:58:21]    CPU Usage:0 %
920 | [Owner : SYSTEM | Parent : 596() | 9.44 Mo] - (.Microsoft Corporation - Applicazione Accesso a Windows.) - (10.0.15063.1206) = C:\Windows\System32\winlogon.exe     [10/08/2018 16:14:32]    CPU Usage:0 %
964 | [Owner : UMFD-1 | Parent : 920(winlogon.exe) | 5.85 Mo] - (.Microsoft Corporation - Usermode Font Driver Host.) - (10.0.15063.994) = C:\Windows\System32\fontdrvhost.exe     [30/04/2018 21:23:15]    CPU Usage:0 %
980 | [Owner : SERVIZIO DI RETE | Parent : 684(services.exe) | 10.85 Mo] - (.Microsoft Corporation - Processo host per servizi di Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe     [18/03/2017 22:58:21]    CPU Usage:0 %
424 | [Owner : SYSTEM | Parent : 684(services.exe) | 6.3 Mo] - (.Microsoft Corporation - Processo host per servizi di Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe     [18/03/2017 22:58:21]    CPU Usage:0 %
764 | [Owner : DWM-1 | Parent : 920(winlogon.exe) | 51.05 Mo] - (.Microsoft Corporation - Gestione finestre desktop.) - (10.0.15063.0) = C:\Windows\System32\dwm.exe     [18/03/2017 22:58:21]    CPU Usage:0 %
1028 | [Owner : SERVIZIO LOCALE | Parent : 684(services.exe) | 5.35 Mo] - (.Microsoft Corporation - Processo host per servizi di Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe     [18/03/2017 22:58:21]    CPU Usage:0 %
1092 | [Owner : SYSTEM | Parent : 684(services.exe) | 9.12 Mo] - (.Microsoft Corporation - Processo host per servizi di Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe     [18/03/2017 22:58:21]    CPU Usage:0 %
1104 | [Owner : SERVIZIO LOCALE | Parent : 684(services.exe) | 10.38 Mo] - (.Microsoft Corporation - Processo host per servizi di Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe     [18/03/2017 22:58:21]    CPU Usage:0 %
1136 | [Owner : SYSTEM | Parent : 684(services.exe) | 14.71 Mo] - (.Microsoft Corporation - Processo host per servizi di Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe     [18/03/2017 22:58:21]    CPU Usage:0 %
1220 | [Owner : SYSTEM | Parent : 684(services.exe) | 5.81 Mo] - (.Microsoft Corporation - Processo host per servizi di Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe     [18/03/2017 22:58:21]    CPU Usage:0 %
1252 | [Owner : SERVIZIO LOCALE | Parent : 684(services.exe) | 21.36 Mo] - (.Microsoft Corporation - Processo host per servizi di Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe     [18/03/2017 22:58:21]    CPU Usage:0 %
1288 | [Owner : SERVIZIO LOCALE | Parent : 684(services.exe) | 16.56 Mo] - (.Microsoft Corporation - Processo host per servizi di Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe     [18/03/2017 22:58:21]    CPU Usage:0 %
1368 | [Owner : SYSTEM | Parent : 684(services.exe) | 10.28 Mo] - (.Microsoft Corporation - Processo host per servizi di Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe     [18/03/2017 22:58:21]    CPU Usage:0 %
1412 | [Owner : SERVIZIO LOCALE | Parent : 684(services.exe) | 8.18 Mo] - (.Microsoft Corporation - Processo host per servizi di Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe     [18/03/2017 22:58:21]    CPU Usage:0 %
1512 | [Owner : SYSTEM | Parent : 684(services.exe) | 8.02 Mo] - (.Microsoft Corporation - Processo host per servizi di Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe     [18/03/2017 22:58:21]    CPU Usage:0 %
1520 | [Owner : SYSTEM | Parent : 684(services.exe) | 5.84 Mo] - (.Microsoft Corporation - Processo host per servizi di Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe     [18/03/2017 22:58:21]    CPU Usage:0 %
1532 | [Owner : SYSTEM | Parent : 684(services.exe) | 5.66 Mo] - (.Microsoft Corporation - Processo host per servizi di Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe     [18/03/2017 22:58:21]    CPU Usage:0 %
1540 | [Owner : SERVIZIO LOCALE | Parent : 684(services.exe) | 7.32 Mo] - (.Microsoft Corporation - Processo host per servizi di Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe     [18/03/2017 22:58:21]    CPU Usage:0 %
1552 | [Owner : SERVIZIO LOCALE | Parent : 684(services.exe) | 7.28 Mo] - (.Microsoft Corporation - Processo host per servizi di Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe     [18/03/2017 22:58:21]    CPU Usage:0 %
1676 | [Owner : SERVIZIO LOCALE | Parent : 1520(svchost.exe) | 7.8 Mo] - (.Microsoft Corporation - Windows Driver Foundation - Processo host Framework driver modalità utente.) - (10.0.15063.0) = C:\Windows\System32\WUDFHost.exe     [18/03/2017 22:57:38]    CPU Usage:0 %
1728 | [Owner : SYSTEM | Parent : 684(services.exe) | 7.66 Mo] - (.Microsoft Corporation - Processo host per servizi di Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe     [18/03/2017 22:58:21]    CPU Usage:0 %
1764 | [Owner : SERVIZIO DI RETE | Parent : 684(services.exe) | 10.82 Mo] - (.Microsoft Corporation - Processo host per servizi di Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe     [18/03/2017 22:58:21]    CPU Usage:0 %
1796 | [Owner : SYSTEM | Parent : 684(services.exe) | 7.73 Mo] - (.Microsoft Corporation - Processo host per servizi di Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe     [18/03/2017 22:58:21]    CPU Usage:0 %
1804 | [Owner : SERVIZIO LOCALE | Parent : 684(services.exe) | 6.28 Mo] - (.Microsoft Corporation - Processo host per servizi di Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe     [18/03/2017 22:58:21]    CPU Usage:0 %
1980 | [Owner : SYSTEM | Parent : 684(services.exe) | 9.05 Mo] - (.Microsoft Corporation - Processo host per servizi di Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe     [18/03/2017 22:58:21]    CPU Usage:0 %
1988 | [Owner : SERVIZIO DI RETE | Parent : 684(services.exe) | 7.61 Mo] - (.Microsoft Corporation - Processo host per servizi di Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe     [18/03/2017 22:58:21]    CPU Usage:0 %
2000 | [Owner : SERVIZIO LOCALE | Parent : 684(services.exe) | 8.63 Mo] - (.Microsoft Corporation - Processo host per servizi di Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe     [18/03/2017 22:58:21]    CPU Usage:0 %
2132 | [Owner : SERVIZIO LOCALE | Parent : 684(services.exe) | 6.96 Mo] - (.Microsoft Corporation - Processo host per servizi di Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe     [18/03/2017 22:58:21]    CPU Usage:0 %
2144 | [Owner : SERVIZIO LOCALE | Parent : 684(services.exe) | 12.24 Mo] - (.Microsoft Corporation - Processo host per servizi di Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe     [18/03/2017 22:58:21]    CPU Usage:0 %
2192 | [Owner : SERVIZIO LOCALE | Parent : 684(services.exe) | 8.97 Mo] - (.Microsoft Corporation - Processo host per servizi di Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe     [18/03/2017 22:58:21]    CPU Usage:0 %
2248 | [Owner : SERVIZIO LOCALE | Parent : 684(services.exe) | 12.09 Mo] - (.Microsoft Corporation - Processo host per servizi di Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe     [18/03/2017 22:58:21]    CPU Usage:0 %
2292 | [Owner : SERVIZIO LOCALE | Parent : 684(services.exe) | 6.08 Mo] - (.Microsoft Corporation - Processo host per servizi di Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe     [18/03/2017 22:58:21]    CPU Usage:0 %
2300 | [Owner : SERVIZIO LOCALE | Parent : 684(services.exe) | 11.25 Mo] - (.Microsoft Corporation - Processo host per servizi di Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe     [18/03/2017 22:58:21]    CPU Usage:0 %
2312 | [Owner : SERVIZIO LOCALE | Parent : 684(services.exe) | 9.4 Mo] - (.Microsoft Corporation - Processo host per servizi di Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe     [18/03/2017 22:58:21]    CPU Usage:0 %
2496 | [Owner : SYSTEM | Parent : 684(services.exe) | 12.72 Mo] - (.Microsoft Corporation - Processo host per servizi di Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe     [18/03/2017 22:58:21]    CPU Usage:0 %
2568 | [Owner : SYSTEM | Parent : 684(services.exe) | 18.14 Mo] - (.Microsoft Corporation - Processo host per servizi di Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe     [18/03/2017 22:58:21]    CPU Usage:0 %
2616 | [Owner : SYSTEM | Parent : 684(services.exe) | 10.96 Mo] - (.Microsoft Corporation - Processo host per servizi di Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe     [18/03/2017 22:58:21]    CPU Usage:0 %
2664 | [Owner : SYSTEM | Parent : 684(services.exe) | 15.92 Mo] - (.Microsoft Corporation - Applicazione sottosistema spooler.) - (10.0.15063.1155) = C:\Windows\System32\spoolsv.exe     [25/07/2018 19:52:12]    CPU Usage:0 %
2808 | [Owner : SERVIZIO DI RETE | Parent : 684(services.exe) | 7.49 Mo] - (.Microsoft Corporation - Processo host per servizi di Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe     [18/03/2017 22:58:21]    CPU Usage:0 %
2980 | [Owner : SERVIZIO LOCALE | Parent : 684(services.exe) | 11.14 Mo] - (.Microsoft Corporation - Processo host per servizi di Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe     [18/03/2017 22:58:21]    CPU Usage:0 %
2528 | [Owner : SYSTEM | Parent : 684(services.exe) | 19.69 Mo] - (.Microsoft Corporation - Microsoft Windows Search Indexer.) - (7.0.15063.1292) = C:\Windows\System32\SearchIndexer.exe     [13/10/2018 17:50:41]    CPU Usage:0 %
3156 | [Owner : SYSTEM | Parent : 684(services.exe) | 6.55 Mo] - (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) - (1.824.31.1644) = C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe     [16/12/2018 20:29:48]    CPU Usage:0 %
3164 | [Owner : SYSTEM | Parent : 684(services.exe) | 10.69 Mo] - (.Adobe Systems, Incorporated - Adobe Genuine Software Integrity Service.) - (6.3.1.77) = C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe     [27/02/2017 09:55:02]    CPU Usage:0 %
3172 | [Owner : SYSTEM | Parent : 684(services.exe) | 9.75 Mo] - (.Adobe Systems, Incorporated - Adobe Genuine Software Service.) - (6.3.1.77) = C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe     [11/05/2018 12:50:52]    CPU Usage:0 %
3188 | [Owner : SYSTEM | Parent : 684(services.exe) | 6.88 Mo] - (.Adobe Systems Incorporated - Adobe Update Service.) - (4.1.1.202) = C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe     [04/06/2017 07:19:38]    CPU Usage:0 %
3200 | [Owner : SERVIZIO DI RETE | Parent : 684(services.exe) | 11.09 Mo] - (.Microsoft Corporation - Processo host per servizi di Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe     [18/03/2017 22:58:21]    CPU Usage:0 %
3216 | [Owner : SYSTEM | Parent : 684(services.exe) | 6.77 Mo] - (.Microsoft Corporation - Processo host per servizi di Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe     [18/03/2017 22:58:21]    CPU Usage:0 %
3256 | [Owner : SERVIZIO LOCALE | Parent : 684(services.exe) | 11.57 Mo] - (.Microsoft Corporation - Processo host per servizi di Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe     [18/03/2017 22:58:21]    CPU Usage:0 %
3288 | [Owner : SYSTEM | Parent : 684(services.exe) | 20.16 Mo] - (.Microsoft Corporation - Processo host per servizi di Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe     [18/03/2017 22:58:21]    CPU Usage:0 %
3296 | [Owner : SYSTEM | Parent : 684(services.exe) | ?????] - (.Malwarebytes - Malwarebytes Service.) - (3.2.0.845) = C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe     [11/07/2019 20:10:56]    CPU Usage:0 %
3332 | [Owner : SYSTEM | Parent : 684(services.exe) | 6.21 Mo] - (.Microsoft Corporation - Processo host per servizi di Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe     [18/03/2017 22:58:21]    CPU Usage:0 %
3344 | [Owner : SYSTEM | Parent : 684(services.exe) | 13.81 Mo] - (.Microsoft Corporation - Processo host per servizi di Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe     [18/03/2017 22:58:21]    CPU Usage:0 %
3356 | [Owner : SYSTEM | Parent : 684(services.exe) | 8.84 Mo] - (.Microsoft Corporation - Processo host per servizi di Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe     [18/03/2017 22:58:21]    CPU Usage:0 %
3368 | [Owner : SYSTEM | Parent : 684(services.exe) | 96.45 Mo] - (.SeriousBit - SeriousBit.NetBalancer.Service.) - (9.4.1.0) = C:\Program Files\NetBalancer\SeriousBit.NetBalancer.Service.exe     [06/07/2017 15:21:12]    CPU Usage:0 %
3380 | [Owner : SYSTEM | Parent : 684(services.exe) | 8.28 Mo] - (.Microsoft Corporation - Processo host per servizi di Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe     [18/03/2017 22:58:21]    CPU Usage:0 %
3400 | [Owner : SYSTEM | Parent : 684(services.exe) | 5.86 Mo] - (.Realtek - RtlService MFC Application.) - (700.1006.416.2010) = C:\Program Files (x86)\REALTEK\Wireless LAN Utility\RtlService.exe     [25/12/2018 13:12:31]    CPU Usage:0 %
3416 | [Owner : SYSTEM | Parent : 684(services.exe) | ?????] - (.Microsoft Corporation - Windows Security Health Service.) - (4.11.15063.1155) = C:\Windows\System32\SecurityHealthService.exe     [25/07/2018 19:53:21]    CPU Usage:0 %
3444 | [Owner : SERVIZIO LOCALE | Parent : 684(services.exe) | 8.34 Mo] - (.Microsoft Corporation - Processo host per servizi di Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe     [18/03/2017 22:58:21]    CPU Usage:0 %
3460 | [Owner : SYSTEM | Parent : 684(services.exe) | 100.11 Mo] - (.Microsoft Corporation - Processo host per servizi di Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe     [18/03/2017 22:58:21]    CPU Usage:0 %
3468 | [Owner : SYSTEM | Parent : 684(services.exe) | 14.9 Mo] - (.Microsoft Corporation - Processo host per servizi di Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe     [18/03/2017 22:58:21]    CPU Usage:0 %
3492 | [Owner : SYSTEM | Parent : 684(services.exe) | 5.51 Mo] - (.Microsoft Corporation - Processo host per servizi di Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe     [18/03/2017 22:58:21]    CPU Usage:0 %
3512 | [Owner : SYSTEM | Parent : 684(services.exe) | 5.68 Mo] - (.VIA Technologies, Inc. - Service binary.) - (0.1.0.0) = C:\Windows\System32\ViakaraokeSrv.exe     [27/10/2016 03:53:12]    CPU Usage:0 %
3540 | [Owner : SYSTEM | Parent : 684(services.exe) | 18.9 Mo] - (.Microsoft Corporation - Processo host per servizi di Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe     [18/03/2017 22:58:21]    CPU Usage:0 %
3560 | [Owner : SYSTEM | Parent : 684(services.exe) | ?????] - (.Microsoft Corporation - Antimalware Service Executable.) - (4.18.1906.3) = C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1906.3-0\MsMpEng.exe     [09/07/2019 00:15:09]    CPU Usage:0 %
3572 | [Owner : SYSTEM | Parent : 684(services.exe) | 29.38 Mo] - (.Wondershare - Wondershare Passport.) - (2.4.3.236) = C:\Program Files (x86)\Wondershare\WAF\2.4.3.236\WsAppService.exe     [26/07/2018 22:29:37]    CPU Usage:0 %
3880 | [Owner : SERVIZIO LOCALE | Parent : 684(services.exe) | 5.33 Mo] - (.Microsoft Corporation - Processo host per servizi di Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe     [18/03/2017 22:58:21]    CPU Usage:0 %
3888 | [Owner : SERVIZIO LOCALE | Parent : 3332(svchost.exe) | 12.53 Mo] - (.Microsoft Corporation - Device Association Framework Provider Host.) - (10.0.15063.994) = C:\Windows\System32\dasHost.exe     [25/07/2018 19:51:52]    CPU Usage:0 %
4136 | [Owner : SYSTEM | Parent : 844(svchost.exe) | 6.12 Mo] - (.Microsoft Corporation - Sink to receive asynchronous callbacks for WMI client application.) - (10.0.15063.994) = C:\Windows\System32\wbem\unsecapp.exe     [25/07/2018 19:50:15]    CPU Usage:0 %
4304 | [Owner : SERVIZIO DI RETE | Parent : 844(svchost.exe) | 22.8 Mo] - (.Microsoft Corporation - WMI Provider Host.) - (10.0.15063.1155) = C:\Windows\System32\wbem\WmiPrvSE.exe     [25/07/2018 19:50:26]    CPU Usage:0 %
4664 | [Owner : SERVIZIO DI RETE | Parent : 684(services.exe) | 6.72 Mo] - (.Microsoft Corporation - Processo host per servizi di Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe     [18/03/2017 22:58:21]    CPU Usage:0 %
4724 | [Owner : SERVIZIO LOCALE | Parent : 684(services.exe) | 7.46 Mo] - (.Microsoft Corporation - Processo host per servizi di Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe     [18/03/2017 22:58:21]    CPU Usage:0 %
5204 | [Owner : SERVIZIO LOCALE | Parent : 684(services.exe) | 19.17 Mo] - (.Microsoft Corporation - Processo host per servizi di Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe     [18/03/2017 22:58:21]    CPU Usage:0 %
5948 | [Owner : SERVIZIO LOCALE | Parent : 684(services.exe) | ?????] - (.Microsoft Corporation - Microsoft Network Realtime Inspection Service.) - (4.18.1906.3) = C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1906.3-0\NisSrv.exe     [09/07/2019 00:15:09]    CPU Usage:0 %
7124 | [Owner : Luca | Parent : 3296(MBAMService.exe) | 36.56 Mo] - (.Malwarebytes - Malwarebytes Tray Application.) - (3.1.0.1838) = C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe     [26/07/2018 22:58:42]    CPU Usage:0 %
5668 | [Owner : Luca | Parent : 684(services.exe) | 18.45 Mo] - (.Microsoft Corporation - Processo host per servizi di Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe     [18/03/2017 22:58:21]    CPU Usage:0 %
5780 | [Owner : Luca | Parent : 1512(svchost.exe) | 21.56 Mo] - (.Microsoft Corporation - Shell Infrastructure Host.) - (10.0.15063.0) = C:\Windows\System32\sihost.exe     [18/03/2017 22:58:10]    CPU Usage:0 %
6168 | [Owner : Luca | Parent : 684(services.exe) | 21.99 Mo] - (.Microsoft Corporation - Processo host per servizi di Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe     [18/03/2017 22:58:21]    CPU Usage:0 %
6504 | [Owner : Luca | Parent : 1136(svchost.exe) | 18.01 Mo] - (.Microsoft Corporation - Processo host per attività di Windows.) - (10.0.15063.0) = C:\Windows\System32\taskhostw.exe     [18/03/2017 22:57:57]    CPU Usage:0 %
3896 | [Owner : Luca | Parent : 6368() | 1.05 Mo] - (.Advanced Micro Devices, Inc. - Radeon Settings: Host Application.) - (10.1.1.1682) = C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe     [24/04/2017 21:34:32]    CPU Usage:0 %
1996 | [Owner : SYSTEM | Parent : 684(services.exe) | 14.09 Mo] - (.Microsoft Corporation - Processo host per servizi di Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe     [18/03/2017 22:58:21]    CPU Usage:0 %
6276 | [Owner : Luca | Parent : 6252() | 115.67 Mo] - (.Microsoft Corporation - Esplora risorse.) - (10.0.15063.1206) = C:\Windows\explorer.exe     [10/08/2018 16:14:32]    CPU Usage:0 %
6296 | [Owner : SYSTEM | Parent : 3400(RtlService.exe) | 14.82 Mo] - (.Realtek Semiconductor Corp. - RtWLan ( For Vista / Win7) Application(External Registrar).) - (700.1631.107.2011) = C:\Program Files (x86)\REALTEK\Wireless LAN Utility\RtWLan.exe     [25/12/2018 13:12:31]    CPU Usage:0 %
3140 | [Owner : Luca | Parent : 844(svchost.exe) | 85.96 Mo] - (.Microsoft Corporation - Search and Cortana application.) - (10.0.15063.1324) = C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe     [13/10/2018 17:50:16]    CPU Usage:0 %
3280 | [Owner : Luca | Parent : 844(svchost.exe) | 53.33 Mo] - (.Microsoft Corporation - Windows Shell Experience Host.) - (10.0.15063.909) = C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe     [30/04/2018 21:24:21]    CPU Usage:0 %
5188 | [Owner : Luca | Parent : 844(svchost.exe) | 31.89 Mo] - (.Microsoft Corporation - Runtime Broker.) - (10.0.15063.0) = C:\Windows\System32\RuntimeBroker.exe     [18/03/2017 22:58:01]    CPU Usage:0 %
7152 | [Owner : SERVIZIO LOCALE | Parent : 684(services.exe) | 9.89 Mo] - (.Microsoft Corporation - Processo host per servizi di Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe     [18/03/2017 22:58:21]    CPU Usage:0 %
1008 | [Owner : Luca | Parent : 844(svchost.exe) | 57.04 Mo] - (.-.) - (12.1815.210.0) = C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.210.1000_x64__kzf8qxf38zg5c\SkypeHost.exe     [23/07/2018 10:47:07]    CPU Usage:0 %
7680 | [Owner : Luca | Parent : 6276(explorer.exe) | 8.91 Mo] - (.Microsoft Corporation - Windows Defender notification icon.) - (4.11.15063.0) = C:\Program Files\Windows Defender\MSASCuiL.exe     [18/03/2017 22:56:44]    CPU Usage:0 %
7932 | [Owner : SYSTEM | Parent : 684(services.exe) | 23.71 Mo] - (.Microsoft Corporation - Processo host per servizi di Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe     [18/03/2017 22:58:21]    CPU Usage:0 %
8064 | [Owner : Luca | Parent : 6276(explorer.exe) | 41.66 Mo] - (.SeriousBit - SeriousBit.NetBalancer.Tray.) - (9.4.1.0) = C:\Program Files\NetBalancer\SeriousBit.NetBalancer.Tray.exe     [06/07/2017 15:21:12]    CPU Usage:0 %
4868 | [Owner : SYSTEM | Parent : 684(services.exe) | 9.52 Mo] - (.Microsoft Corporation - sedsvc.) - (10.0.17134.10059) = C:\Program Files\rempl\sedsvc.exe     [11/05/2019 08:02:16]    CPU Usage:0 %
8012 | [Owner : SERVIZIO LOCALE | Parent : 684(services.exe) | 8.37 Mo] - (.Microsoft Corporation - Processo host per servizi di Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe     [18/03/2017 22:58:21]    CPU Usage:0 %
1560 | [Owner : Luca | Parent : 684(services.exe) | 28.25 Mo] - (.Microsoft Corporation - Processo host per servizi di Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe     [18/03/2017 22:58:21]    CPU Usage:0 %
9940 | [Owner : SYSTEM | Parent : 684(services.exe) | 61.7 Mo] - (.Microsoft Corporation - Processo host per servizi di Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe     [18/03/2017 22:58:21]    CPU Usage:0 %
10164 | [Owner : SYSTEM | Parent : 684(services.exe) | 9.26 Mo] - (.Microsoft Corporation - Processo host per servizi di Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe     [18/03/2017 22:58:21]    CPU Usage:0 %
1820 | [Owner : SYSTEM | Parent : 684(services.exe) | 11.07 Mo] - (.Microsoft Corporation - Processo host per servizi di Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe     [18/03/2017 22:58:21]    CPU Usage:0 %
3236 | [Owner : SERVIZIO DI RETE | Parent : 1264() | 7.62 Mo] - (.Microsoft Corporation - Microsoft Malware Protection Command Line Utility.) - (4.18.1906.3) = C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1906.3-0\MpCmdRun.exe     [09/07/2019 00:15:09]    CPU Usage:0 %
9876 | [Owner : SYSTEM | Parent : 3560(MsMpEng.exe) | 9.22 Mo] - (.Microsoft Corporation - Microsoft Malware Protection Command Line Utility.) - (4.18.1906.3) = C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1906.3-0\MpCmdRun.exe     [09/07/2019 00:15:09]    CPU Usage:0 %
6660 | [Owner : SYSTEM | Parent : 9876(MpCmdRun.exe) | 6.91 Mo] - (.Microsoft Corporation - Console Window Host.) - (10.0.15063.0) = C:\Windows\System32\conhost.exe     [18/03/2017 22:57:35]    CPU Usage:0 %
8256 | [Owner : SYSTEM | Parent : 684(services.exe) | 5.96 Mo] - (.Microsoft Corporation - Processo host per servizi di Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe     [18/03/2017 22:58:21]    CPU Usage:0 %
9588 | [Owner : SYSTEM | Parent : 684(services.exe) | 5.6 Mo] - (.Microsoft Corporation - Processo host per servizi di Windows.) - (10.0.15063.0) = C:\Windows\System32\svchost.exe     [18/03/2017 22:58:21]    CPU Usage:0 %
6704 | [Owner : SYSTEM | Parent : 844(svchost.exe) | 77.39 Mo] - (.Microsoft Corporation - WMI Provider Host.) - (10.0.15063.1155) = C:\Windows\System32\wbem\WmiPrvSE.exe     [25/07/2018 19:50:26]    CPU Usage:0 %
2384 | [Owner : SERVIZIO LOCALE | Parent : 2144(svchost.exe) | 11 Mo] - (.Microsoft Corporation - Isolamento grafico dispositivo audio Windows.) - (10.0.15063.1155) = C:\Windows\System32\audiodg.exe     [25/07/2018 19:51:13]    CPU Usage:0 %
9016 | [Owner : Luca | Parent : 6276(explorer.exe) | 63.11 Mo] - (.SosVirus - QuickDiag.) - (27.2.19.1) = C:\Users\Luca\Desktop\quickdiag_V5_27.02.19.1.exe     [14/07/2019 09:55:03]    CPU Usage:0 %
9780 | [Owner : SERVIZIO DI RETE | Parent : 844(svchost.exe) | 9.6 Mo] - (.Microsoft Corporation - WMI Provider Host.) - (10.0.15063.994) = C:\Windows\SysWOW64\wbem\WmiPrvSE.exe     [25/07/2018 19:52:49]    CPU Usage:0 %

---------- | Locked Applications


---------- | Explorer.exe Modules (Microsoft Files Whitelisted)

(.Advanced Micro Devices, Inc. .-.aticfx64.dll.) - (22.19.162.4) -- C:\Windows\System32\DriverStore\FileRepository\c0313676.inf_amd64_96bbc33bec5c7fae\aticfx64.dll
(.Advanced Micro Devices, Inc. .-.atiuxpag.dll.) - (22.19.162.4) -- C:\Windows\System32\DriverStore\FileRepository\c0313676.inf_amd64_96bbc33bec5c7fae\atiuxp64.dll
(.Advanced Micro Devices, Inc. .-.atidxx64.dll.) - (22.19.162.4) -- C:\Windows\System32\DriverStore\FileRepository\c0313676.inf_amd64_96bbc33bec5c7fae\atidxx64.dll
(..-.Core Sync.) - (2.4.1.525) -- C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll
(..-.SeriousBit.NetBalancer.DeskBand.) - (1.0.0.0) -- C:\Windows\assembly\NativeImages_v4.0.30319_64\SeriousBit.3cb6c405#\009444591bc94fc074dbe36d9a5de433\SeriousBit.NetBalancer.DeskBand.ni.dll
(.Alexander Roshal.-.WinRAR shell extension.) - (5.40.0.0) -- C:\Program Files\WinRAR\rarext.dll
(.Malwarebytes.-.Malwarebytes.) - (3.0.0.79) -- C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll

---------- | Winlogon.exe Modules (Microsoft Files Whitelisted)


---------- | svchost.exe Modules (Microsoft Files Whitelisted)

(.SQLite Development Team.-.SQLite is a software library that implements a self-contained, serverless, zero-configuration, transactional SQL database engine..) - (3.15.2.0) -- C:\Windows\System32\winsqlite3.dll

---------- | ZeroAccess Check

[HKLM\Software\Classes\CLSID\{1108BE51-F58A-4CDA-BB99-7A0227D11D5E}\InProcServer32] : %systemroot%\system32\wbem\fastprox.dll
[HKLM\Software\Classes\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] : %SystemRoot%\system32\windows.storage.dll
[HKLM\Software\Classes\CLSID\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] : %systemroot%\system32\wbem\fastprox.dll
[HKLM\Software\Classes\CLSID\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] : %systemroot%\system32\wbem\wbemess.dll
[HKLM\Software\Classes\CLSID\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] : %SystemRoot%\system32\shell32.dll
[HKLM\Software\WOW6432Node\Classes\CLSID\{1108BE51-F58A-4CDA-BB99-7A0227D11D5E}\InProcServer32] : %systemroot%\system32\wbem\fastprox.dll
[HKLM\Software\WOW6432Node\Classes\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] : %SystemRoot%\system32\windows.storage.dll
[HKLM\Software\WOW6432Node\Classes\CLSID\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] : %systemroot%\system32\wbem\fastprox.dll
[HKLM\Software\WOW6432Node\Classes\CLSID\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] : %SystemRoot%\system32\shell32.dll

---------- | Startings up

script_fcbd - ("D:\far cry 3\Far Cry 3 Blood Dragon\fcbd.bat" [HKU\S-1-5-18\SOFTWARE\...\Run]) - User: NT AUTHORITY\SYSTEM
OneDriveSetup - (C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup [HKU\S-1-5-19\SOFTWARE\...\Run]) - User: NT AUTHORITY\SERVIZIO LOCALE
OneDriveSetup - (C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup [HKU\S-1-5-20\SOFTWARE\...\Run]) - User: NT AUTHORITY\SERVIZIO DI RETE
OneDrive - ("C:\Users\Luca\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background [HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\SOFTWARE\...\Run]) - User: BUGCODE-USB-DRI\Luca
Steam - ("D:\Steam\steam.exe" -silent [HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\SOFTWARE\...\Run]) - User: BUGCODE-USB-DRI\Luca
NetBalancer - (C:\Program Files\NetBalancer\SeriousBit.NetBalancer.Tray.exe [HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\SOFTWARE\...\Run]) - User: BUGCODE-USB-DRI\Luca
script_fcbd - ("D:\far cry 3\Far Cry 3 Blood Dragon\fcbd.bat" [HKU\.DEFAULT\SOFTWARE\...\Run]) - User: .DEFAULT
fcbd - (fcbd.bat [Common Startup]) - User: Public
SecurityHealth - (%ProgramFiles%\Windows Defender\MSASCuiL.exe [HKLM\SOFTWARE\...\Run]) - User: Public
AdobeAAMUpdater-1.0 - ("C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [HKLM\SOFTWARE\...\Run]) - User: Public
AdobeGCInvoker-1.0 - ("C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe" [HKLM\SOFTWARE\...\Run]) - User: Public

[HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\Software\Microsoft\Command Processor]
"CompletionChar"=9  
"DefaultColor"=0  
"EnableExtensions"=1  
"PathCompletionChar"=9  

[HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\Software\Microsoft\Windows\CurrentVersion\Run]
"OneDrive"="C:\Users\Luca\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background  
"Steam"="D:\Steam\steam.exe" -silent  
"NetBalancer"=C:\Program Files\NetBalancer\SeriousBit.NetBalancer.Tray.exe   [06/07/2017 15:21:12]

[HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run]
"OneDrive"=0x03000000AA3424FF58F6D201  
"Steam"=0x0300000026CAC4FC58F6D201  
"NetBalancer"=0x020000000000000000000000  

[HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\RunMRU]
"a"=services.msc\1  
"MRUList"=a  

[HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"Device"=Samsung ML-2160 Series,winspool,Ne00:  
"IsMRUEstablished"=1  
"LegacyDefaultPrinterMode"=0  

[HKLM\Software\Microsoft\Command Processor]
"CompletionChar"=64  
"DefaultColor"=0  
"EnableExtensions"=1  
"PathCompletionChar"=64  

[HKLM\Software\Microsoft\Windows\CurrentVersion\Run]
"SecurityHealth"=%ProgramFiles%\Windows Defender\MSASCuiL.exe  
"AdobeAAMUpdater-1.0"="C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"  
"AdobeGCInvoker-1.0"="C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe"  

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run]
"SecurityHealth"=0x060000000000000000000000  
"AdobeAAMUpdater-1.0"=0x020000000000000000000000  
"Malwarebytes TrayApp"=0x03000000BA4EAB5ECEFCD201  

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32]
"Adobe Creative Cloud"=0x030000006BC6CCFA58F6D201  

[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
""=mnmsrvc  
"AppInit_DLLs"=  
"DdeSendTimeout"=0  
"DesktopHeapLogging"=1  
"DeviceNotSelectedTimeout"=15  
"DwmInputUsesIoCompletionPort"=1  
"EnableDwmInputProcessing"=7  
"EnableMitInputProcessing"=7  
"GDIProcessHandleQuota"=10000  
"IconServiceLib"=IconCodecService.dll  
"LoadAppInit_DLLs"=0  
"NaturalInputHandler"=Ninput.dll  
"ShutdownWarningDialogTimeout"=4294967295  
"Spooler"=yes  
"ThreadUnresponsiveLogTimeout"=500  
"TransmissionRetryTimeout"=90  
"USERNestedWindowLimit"=50  
"USERPostMessageLimit"=10000  
"USERProcessHandleQuota"=10000  
"Win32kLastWriteTime"=1D325FFA9F5E74C  

[HKLM\Software\WOW6432Node\Microsoft\Command Processor]
"CompletionChar"=64  
"DefaultColor"=0  
"EnableExtensions"=1  
"PathCompletionChar"=64  

[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run]
"Adobe Creative Cloud"="C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" --showwindow=false --onOSstartup=true  

[HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Windows]
""=mnmsrvc  
"AppInit_DLLs"=  
"DdeSendTimeout"=0  
"DesktopHeapLogging"=1  
"DeviceNotSelectedTimeout"=15  
"DwmInputUsesIoCompletionPort"=1  
"EnableDwmInputProcessing"=7  
"EnableMitInputProcessing"=7  
"GDIProcessHandleQuota"=10000  
"IconServiceLib"=IconCodecService.dll  
"LoadAppInit_DLLs"=0  
"NaturalInputHandler"=Ninput.dll  
"ShutdownWarningDialogTimeout"=4294967295  
"Spooler"=yes  
"ThreadUnresponsiveLogTimeout"=500  
"TransmissionRetryTimeout"=90  
"USERNestedWindowLimit"=50  
"USERPostMessageLimit"=10000  
"USERProcessHandleQuota"=10000  

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"WebCheck"={E6FB5E20-DE35-11CF-9C87-00AA005127ED}  


---------- | Win.ini :



---------- | System.ini :



---------- | Tasks List

Adobe Acrobat Update Task
AdobeGCInvoker-1.0-BUGCODE-USB-DRI-Luca
AutoKMS
GoogleUpdateTaskMachineCore
GoogleUpdateTaskMachineUA
OneDrive Standalone Update Task-S-1-5-21-2971312339-4097301404-2670616240-1001
StartCN

---------- | Startings up registry ¦ Folder


---------- | Control - lsa - SecurityProviders - Session Manager - Terminal Server


[HKLM\System\CurrentControlSet\Control]
"BootDriverFlags"=28  
"CurrentUser"=USERNAME  
"EarlyStartServices"=RpcSs
Power
BrokerInfrastructure
SystemEventsBroker
DcomLaunch
RpcEpMapper
LSM
AppIdSvc  
"PreshutdownOrder"=UsoSvc
DeviceInstall
gpsvc
trustedinstaller  
"SvcHostSplitThresholdInKB"=3670016  
"WaitToKillServiceTimeout"=2000  
"SystemStartOptions"= NOEXECUTE=OPTIN  
"SystemBootDevice"=multi(0)disk(0)rdisk(0)partition(1)  
"FirmwareBootDevice"=multi(0)disk(0)rdisk(0)partition(1)  
"LastBootSucceeded"=1  
"LastBootShutdown"=1  
"DirtyShutdownCount"=39  

[HKLM\System\CurrentControlSet\Control\lsa]
"auditbasedirectories"=0  
"auditbaseobjects"=0  
"Bounds"=0x0030000000200000  
"crashonauditfail"=0  
"fullprivilegeauditing"=0x00  
"LimitBlankPasswordUse"=1  
"NoLmHash"=1  
"Security Packages"=""   [05/07/2017 18:28:21]
"Notification Packages"=scecli  
"Authentication Packages"=msv1_0  
"LsaPid"=692  
"SecureBoot"=1  
"ProductType"=6  
"disabledomaincreds"=0  
"everyoneincludesanonymous"=0  
"forceguest"=0  
"restrictanonymous"=0  
"restrictanonymoussam"=1  

[HKLM\System\CurrentControlSet\Control\SecurityProviders]
"SecurityProviders"=credssp.dll  

[HKLM\System\CurrentControlSet\Control\Session Manager]
"AutoChkTimeout"=8  
"BootExecute"=autocheck autochk *  
"BootShell"=%SystemRoot%\system32\bootim.exe  
"CriticalSectionTimeout"=2592000  
"ExcludeFromKnownDlls"=  
"GlobalFlag"=0  
"HeapDeCommitFreeBlockThreshold"=0  
"HeapDeCommitTotalFreeThreshold"=0  
"HeapSegmentCommit"=0  
"HeapSegmentReserve"=0  
"InitConsoleFlags"=0  
"NumberOfInitialSessions"=2  
"ObjectDirectories"=\Windows
\RPC Control  
"ProcessorControl"=2  
"ProtectionMode"=1  
"ResourceTimeoutCount"=648000  
"RunLevelExecute"=WinInit
ServiceControlManager  
"RunLevelValidate"=ServiceControlManager  
"SETUPEXECUTE"=  
"AutoChkSkipSystemPartition"=0  

[HKLM\System\CurrentControlSet\Control\Terminal Server]
"AllowRemoteRPC"=0  
"DelayConMgrTimeout"=0  
"DeleteTempDirsOnExit"=1  
"fDenyTSConnections"=1  
"fSingleSessionPerUser"=1  
"NotificationTimeOut"=0  
"PerSessionTempDir"=0  
"ProductVersion"=5.1  
"RCDependentServices"=CertPropSvc
SessionEnv  
"SnapshotMonitors"=1  
"StartRCM"=0  
"TSUserEnabled"=0  
"RailShowallNotifyIcons"=1  
"RDPVGCInstalled"=1  
"InstanceID"=7779ec53-5b5b-46db-8346-799183f  
"GlassSessionId"=1  


---------- | .LNK with Arguments


---------- | AppCertDlls


---------- | Dnsapi.dll

C:\Windows\System32\dnsapi.dll -> OK : \drivers\etc\hosts
C:\Windows\SysWOW64\dnsapi.dll -> OK : \drivers\etc\hosts

---------- | Policies | Registry

[HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\Control Panel\Desktop]
"ActiveWndTrackTimeout"=0  
"BlockSendInputResets"=0  
"CaretWidth"=1  
"ClickLockTime"=1200  
"CoolSwitchColumns"=7  
"CoolSwitchRows"=3  
"CursorBlinkRate"=530  
"DockMoving"=1  
"DragFromMaximize"=1  
"DragFullWindows"=1  
"DragHeight"=4  
"DragWidth"=4  
"FocusBorderHeight"=1  
"FocusBorderWidth"=1  
"FontSmoothing"=2  
"FontSmoothingGamma"=0  
"FontSmoothingOrientation"=1  
"FontSmoothingType"=2  
"ForegroundFlashCount"=7  
"ForegroundLockTimeout"=200000  
"LeftOverlapChars"=3  
"MenuShowDelay"=400  
"MouseWheelRouting"=2  
"PaintDesktopVersion"=0  
"Pattern"=0  
"RightOverlapChars"=3  
"ScreenSaveActive"=1  
"SnapSizing"=1  
"TileWallpaper"=0  
"WallPaper"=C:\Windows\web\wallpaper\Windows\img0.jpg   [18/03/2017 22:56:56]
"WallpaperOriginX"=0  
"WallpaperOriginY"=0  
"WallpaperStyle"=10  
"WheelScrollChars"=3  
"WheelScrollLines"=3  
"WindowArrangementActive"=1  
"Win8DpiScaling"=0  
"DpiScalingVer"=4096  
"UserPreferencesMask"=0x9E1E078012000000  
"MaxVirtualDesktopDimension"=1920  
"MaxMonitorDimension"=1920  
"TranscodedImageCount"=1  
"LastUpdated"=4294967295  
"TranscodedImageCache"=0x7AC301000A480100000400000003000008258A2D2AA0D20143003A005C00570069006E0064006F00770073005C007700650062005C00770061006C006C00700061007000650072005C00570069006E0064006F00770073005C0069006D00670030002E006A007000670000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000  
"WaitToKillAppTimeout"=2000  
"HungAppTimeout"=2000  

[HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel]
"{0E270DAA-1BE6-48F2-AC49-CB66C537038C}"=1  
"{018D5C66-4533-4307-9B53-224DE2ED1FE6}"=1  

[HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\Software\Microsoft\Windows\CurrentVersion\Explorer]
"ExplorerStartupTraceRecorded"=1  
"ShellState"=0x240000003D28000000000000000000000000000001000000130000000000000062000000  
"UserSignedIn"=1  
"SIDUpdatedOnLibraries"=1  
"LocalKnownFoldersMigrated"=1  
"TelemetrySalt"=3  
"GlobalAssocChangedCounter"=1643  
"FirstRunTelemetryComplete"=1  
"AppReadinessLogonComplete"=1  
"SlowContextMenuEntries"=0xEE21215E0003D4118D3B444553540000830C0000631A79D6E2E7EE4FBF525DED8E86E9B89F1700006078A409B011A54DAFA526D86198A780FD0A00000114020000000000C00000000000004663210000BD0E0C47735D584D9CEDE91E22E232826C080000  
"Browse For Folder Width"=318  
"Browse For Folder Height"=288  
"Reason Setting"=255  
"ScreenshotIndex"=53  
"link"=0x17000000  

[HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"Start_SearchFiles"=2  
"ServerAdminUI"=0  
"Hidden"=1  
"ShowCompColor"=1  
"HideFileExt"=1  
"DontPrettyPath"=0  
"ShowInfoTip"=1  
"HideIcons"=0  
"MapNetDrvBtn"=0  
"WebView"=1  
"Filter"=0  
"ShowSuperHidden"=0  
"SeparateProcess"=0  
"AutoCheckSelect"=0  
"IconsOnly"=0  
"ShowTypeOverlay"=1  
"ShowStatusBar"=1  
"StoreAppsOnTaskbar"=1  
"ListviewAlphaSelect"=1  
"ListviewShadow"=1  
"TaskbarAnimations"=1  
"StartMenuInit"=13  
"TaskbarStateLastRun"=0x8CDF285D00000000  
"ReindexedProfile"=1  
"TaskbarSizeMove"=0  

[HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\WordWheelQuery]
"MRUListEx"=0x25000000040000000100000063000000620000006100000060000000550000005F0000005E0000005D0000005C0000004F0000005A0000005B0000005900000058000000570000005600000054000000520000005300000051000000500000001C000000120000004E000000320000004D0000004C0000004B0000000F0000004A0000004900000031000000480000004700000046000000030000004500000044000000430000004200000041000000400000003F0000003E0000003D0000003C0000003B0000003A00000039000000380000003500000037000000360000003400000033000000300000002F0000002E0000002D000000220000002C0000002B0000002A00000029000000280000002700000026000000240000002300000021000000200000001F0000001E0000001D0000001B0000001A0000001900000018000000170000001600000015000000140000001300000011000000100000000E0000000D000000000000000C0000000B0000000A000000090000000200000008000000070000000600000005000000FFFFFFFF  
"5"=0x630061006F0073000000  
"6"=0x300035000000  
"7"=0x7300300037000000  
"8"=0x6D0075007300690063000000  
"2"=0x6D00750073000000  
"9"=0x650070006F006E0061000000  
"10"=0x64006F006E00270074000000  
"11"=0x7300300037006500300036000000  
"12"=0x7300300037006500300037000000  
"0"=0x2E006D00700033000000  
"13"=0x75006E00640065007200740061006C0065000000  
"14"=0x770069000000  
"16"=0x7300300037006500300032000000  
"17"=0x6D00730069000000  
"19"=0x6500300037000000  
"20"=0x7300300031006500300037000000  
"21"=0x6500310030000000  
"22"=0x73006500610073006F006E00200032000000  
"23"=0x7300300032006500300036000000  
"24"=0x7300300032006500300037000000  
"25"=0x7300650020006D00690020006C0061007300630069000000  
"26"=0x7300650020006D0069000000  
"27"=0x73003000330065000000  
"29"=0x6400610072006B000000  
"30"=0x670061006D00650020006F00660020007400680072006F006E00650073000000  
"31"=0x64006F006E006E0069000000  
"32"=0x7000690072006100740069000000  
"33"=0x64006F006E006E00690065000000  
"35"=0x6C006F0067006F000000  
"36"=0x700068006F0074006F00730068006F0070000000  
"38"=0x620069006F00730068006F0063006B000000  
"39"=0x6400650076000000  
"40"=0x69007000640074000000  
"41"=0x740068006F0072000000  
"42"=0x61006D006F00720065000000  
"43"=0x720069006D000000  
"44"=0x6F006800200077006F006E006400650072000000  
"34"=0x6D0061006D006D0061000000  
"45"=0x6C006F00670061000000  
"46"=0x6F0072006100720069006F000000  
"47"=0x66006F0072006D000000  
"48"=0x66006F0072006D0061000000  
"51"=0x74006F00700061007A000000  
"52"=0x69006E0066006F0072006D00610074006900630061000000  
"54"=0x720065006C0061000000  
"55"=0x720065006C0061007A0069006F006E0065000000  
"53"=0x620065006E0063006900760065006E00670061000000  
"56"=0x65007100750061007A000000  
"57"=0x70006500690020006E0075006F0076000000  
"58"=0x6300680069006D0069000000  
"59"=0x6300680069006D006900630061000000  
"60"=0x730063007200650065006E00730068000000  
"61"=0x730063007200650065006E000000  
"62"=0x73007400650061006D000000  
"63"=0x2E007400780074000000  
"64"=0x630061007200740061000000  
"65"=0x670069006E00740061006D0061000000  
"66"=0x6F006C0064000000  
"67"=0x72006F0067000000  
"68"=0x7200690063006B00200061006E0064000000  
"69"=0x74006800650020006F00660066006900630065000000  
"3"=0x6F00660066006900630065000000  
"70"=0x2E007300720074000000  
"71"=0x32007800300034000000  
"72"=0x7200690063006B000000  
"49"=0x7000640066000000  
"73"=0x6300610070006100720065007A007A0061000000  
"74"=0x3200300031003800300039000000  
"15"=0x6C006F00670061006E000000  
"75"=0x73006E0069007000700069006E0067000000  
"76"=0x2E0064006F0063000000  
"77"=0x66006F0072006D006500200069006E00640065007400650072006D0069006E006100740065000000  
"50"=0x2E007000640066000000  
"78"=0x670061006D00650020006F0066000000  
"18"=0x62006F006A00610063006B000000  
"28"=0x2E006D00700034000000  
"80"=0x65006C0065006D0065006E0074000000  
"81"=0x6C006100200070006100720061006E007A0061000000  
"83"=0x70006F007700650072000000  
"82"=0x70006F0077006500720070006F0069006E0074000000  
"84"=0x6E0061007200720061007A0069006F006E0065000000  
"86"=0x660069006E0061006C0065000000  
"87"=0x72006900630068006100720064000000  
"88"=0x640061002000750073006100720065000000  
"89"=0x75006E00200070006F006C006C006F000000  
"91"=0x6E00650072006F000000  
"90"=0x6100760065006E0067006500720073000000  
"79"=0x6E006700610061000000  
"92"=0x660069006C006D00610074006F000000  
"93"=0x770068006100740073000000  
"94"=0x760069000000  
"95"=0x69006E0070007300690065006D0065000000  
"85"=0x76006900640065006F000000  
"96"=0x660069006E00690074006F000000  
"97"=0x7300300038000000  
"98"=0x650034000000  
"99"=0x6C0069006D006900740065000000  
"1"=0x64006500660069006E0069000000  
"4"=0x6400650063006B000000  
"37"=0x6200610063006B00750070000000  

[HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers]
"authenticodeenabled"=0  

[HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5  
"ConsentPromptBehaviorUser"=3  
"DSCAutomationHostEnabled"=2  
"EnableCursorSuppression"=1  
"EnableInstallerDetection"=1  
"EnableLUA"=1  
"EnableSecureUIAPaths"=1  
"EnableUIADesktopToggle"=0  
"EnableVirtualization"=1  
"PromptOnSecureDesktop"=1  
"ValidateAdminCodeSignatures"=0  
"dontdisplaylastusername"=0  
"legalnoticecaption"=  
"legalnoticetext"=  
"scforceoption"=0  
"shutdownwithoutlogon"=1  
"undockwithoutlogon"=1  

[HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]
"ForceActiveDesktopOn"=0  
"NoActiveDesktop"=1  
"NoActiveDesktopChanges"=1  
"NoRecentDocsHistory"=0  

[HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop]
"NoAddingComponents"=1  
"NoComponents"=1  

[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel]
"{031E4825-7B94-4dc3-B131-E946B44C8DD5}"=1  
"{208D2C60-3AEA-1069-A2D7-08002B30309D}"=1  
"{20D04FE0-3AEA-1069-A2D8-08002B30309D}"=1  
"{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}"=1  
"{59031a47-3f72-44a7-89c5-5595fe6b30ee}"=1  
"{871C5380-42A0-1069-A2EA-08002B30309D}"=1  
"{9343812e-1c37-4a49-a12e-4b2d810d956b}"=1  
"{B4FB3F98-C1EA-428d-A78A-D1F5659CBA93}"=1  
"{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}"=1  

[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu]
"{871C5380-42A0-1069-A2EA-08002B30309D}.default"=0  
"{9343812e-1c37-4a49-a12e-4b2d810d956b}"=1  

[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL]
"CheckedValue"=1  
"DefaultValue"=2  
"HKeyRoot"=2147483649  
"Id"=2  
"RegPath"=Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced  
"Text"=@shell32.dll,-30500  
"Type"=radio  
"ValueName"=Hidden  

[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer]
"ActiveSetupDisabled"=0  
"ActiveSetupTaskOverride"=1  
"AsyncRunOnce"=1  
"AsyncUpdatePCSettings"=1  
"DisableAppInstallsOnFirstLogon"=1  
"DisableResolveStoreCategories"=1  
"DisableUpgradeCleanup"=1  
"EarlyAppResolverStart"=1  
"FileOpenDialog"={DC1C5A9C-E88A-4dde-A5A1-60F82A20AEF7}  
"FSIASleepTimeInMs"=60000  
"GlobalFolderSettings"={EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}  
"IconUnderline"=2  
"ListViewPopupControl"={8be9f5ea-e746-4e47-ad57-3fb191ca1eed}  
"LVPopupSearchControl"={fccf70c8-f4d7-4d8b-8c17-cd6715e37fff}  
"MachineOobeUpdates"=1  
"NoWaitOnRoamingPayloads"=1  
"TaskScheduler"={0f87369f-a4e5-4cfc-bd3e-73e6154572dd}  
"AccessDeniedDialog"={100B4FC8-74C1-470F-B1B7-DD7B6BAE79BD}  
"GlobalAssocChangedCounter"=12  

[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"Start_TrackDocs"=1  
"TaskbarSizeMove"=0  

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations]
"Application"=http://go.microsoft.com/fwlink/?LinkId=57426&Ext=%s  

[HKLM\Software\WOW6432Node\Policies\Microsoft\Windows\Safer\CodeIdentifiers]
"authenticodeenabled"=0  

[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5  
"ConsentPromptBehaviorUser"=3  
"DSCAutomationHostEnabled"=2  
"EnableCursorSuppression"=1  
"EnableInstallerDetection"=1  
"EnableLUA"=1  
"EnableSecureUIAPaths"=1  
"EnableUIADesktopToggle"=0  
"EnableVirtualization"=1  
"PromptOnSecureDesktop"=1  
"ValidateAdminCodeSignatures"=0  
"dontdisplaylastusername"=0  
"legalnoticecaption"=  
"legalnoticetext"=  
"scforceoption"=0  
"shutdownwithoutlogon"=1  
"undockwithoutlogon"=1  

[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer]
"ForceActiveDesktopOn"=0  
"NoActiveDesktop"=1  
"NoActiveDesktopChanges"=1  
"NoRecentDocsHistory"=0  

[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop]
"NoAddingComponents"=1  
"NoComponents"=1  

[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel]
"{031E4825-7B94-4dc3-B131-E946B44C8DD5}"=1  
"{208D2C60-3AEA-1069-A2D7-08002B30309D}"=1  
"{20D04FE0-3AEA-1069-A2D8-08002B30309D}"=1  
"{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}"=1  
"{59031a47-3f72-44a7-89c5-5595fe6b30ee}"=1  
"{871C5380-42A0-1069-A2EA-08002B30309D}"=1  
"{9343812e-1c37-4a49-a12e-4b2d810d956b}"=1  
"{B4FB3F98-C1EA-428d-A78A-D1F5659CBA93}"=1  
"{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}"=1  

[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu]
"{871C5380-42A0-1069-A2EA-08002B30309D}.default"=0  
"{9343812e-1c37-4a49-a12e-4b2d810d956b}"=1  

[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL]
"CheckedValue"=1  
"DefaultValue"=2  
"HKeyRoot"=2147483649  
"Id"=2  
"RegPath"=Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced  
"Text"=@shell32.dll,-30500  
"Type"=radio  
"ValueName"=Hidden  

[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer]
"ActiveSetupDisabled"=0  
"ActiveSetupTaskOverride"=1  
"AsyncRunOnce"=1  
"AsyncUpdatePCSettings"=1  
"DisableAppInstallsOnFirstLogon"=1  
"DisableResolveStoreCategories"=1  
"DisableUpgradeCleanup"=1  
"EarlyAppResolverStart"=1  
"FileOpenDialog"={DC1C5A9C-E88A-4dde-A5A1-60F82A20AEF7}  
"FSIASleepTimeInMs"=60000  
"GlobalFolderSettings"={EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}  
"IconUnderline"=2  
"ListViewPopupControl"={8be9f5ea-e746-4e47-ad57-3fb191ca1eed}  
"LVPopupSearchControl"={fccf70c8-f4d7-4d8b-8c17-cd6715e37fff}  
"MachineOobeUpdates"=1  
"NoWaitOnRoamingPayloads"=1  
"TaskScheduler"={0f87369f-a4e5-4cfc-bd3e-73e6154572dd}  
"AccessDeniedDialog"={100B4FC8-74C1-470F-B1B7-DD7B6BAE79BD}  
"GlobalAssocChangedCounter"=31  

[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"Start_TrackDocs"=1  
"TaskbarSizeMove"=0  

[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Associations]
"Application"=http://go.microsoft.com/fwlink/?LinkId=57426&Ext=%s  


---------- | Winlogon

[HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
"ExcludeProfileDirs"=AppData\Local;AppData\LocalLow;$Recycle.Bin;OneDrive;Work Folders  
"BuildNumber"=15063  
"FirstLogon"=0  
"PUUActive"=0x3A3934BC01001A003504C010EF50D20001F3FA0009A05801D100000001006204028FD23F88286D017F286D01F7366C0006D141006E160700000000004E4959012D68030052BD0000E9A904E0173AD501EF50D200000000000100000000000000  
"DP"=0xCE00580009061A00380400003A3934BCE1C2140000000000E9A904E0173AD501EC4108B5143AD5014939150000000000000000003ABD05000000000000000000000000000000000000000000000000000000000000000000  
"ParseAutoexec"=1  

[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
"AutoRestartShell"=1  
"Background"=0 0 0  
"CachedLogonsCount"=10  
"DebugServerCommand"=no  
"DefaultDomainName"=  
"DefaultUserName"=Luca  
"DisableBackButton"=1  
"EnableSIHostIntegration"=1  
"ForceUnlockLogon"=0  
"LegalNoticeCaption"=  
"LegalNoticeText"=  
"PasswordExpiryWarning"=5  
"PowerdownAfterShutdown"=0  
"PreCreateKnownFolders"={A520A1A4-1780-4FF6-BD18-167343C5AF16}  
"ReportBootOk"=1  
"Shell"=explorer.exe  
"ShellCritical"=0  
"ShellInfrastructure"=sihost.exe  
"SiHostCritical"=0  
"SiHostReadyTimeOut"=0  
"SiHostRestartCountLimit"=0  
"SiHostRestartTimeGap"=0  
"Userinit"=C:\Windows\system32\userinit.exe,  
"VMApplet"=SystemPropertiesPerformance.exe /pagefile  
"WinStationsDisabled"=0  
"scremoveoption"=0  
"DisableCAD"=1  
"LastLogOffEndTimePerfCounter"=4720492982  
"ShutdownFlags"=2147483687  
"AutoAdminLogon"=0  
"DisableLockWorkstation"=0  
"EnableFirstLogonAnimation"=1  
"AutoLogonSID"=S-1-5-21-2971312339-4097301404-2670616240-1001  
"LastUsedUsername"=Luca  

[HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon]
"DefaultDomainName"=  
"DefaultUserName"=  
"EnableSIHostIntegration"=1  
"PreCreateKnownFolders"={A520A1A4-1780-4FF6-BD18-167343C5AF16}  
"Shell"=explorer.exe  
"ShellCritical"=0  
"SiHostCritical"=0  
"SiHostReadyTimeOut"=0  
"SiHostRestartCountLimit"=0  
"SiHostRestartTimeGap"=0  
"Userinit"=C:\Windows\system32\userinit.exe,  


---------- | Associations

[HKLM\Software\Classes\.exe]
""=exefile  
"Content Type"=application/x-msdownload  

[HKLM\Software\Classes\exefile\Shell\Open\Command]
""="%1" %*  
"IsolatedCommand"="%1" %*  

[HKLM\Software\Classes\.com]
""=comfile  

[HKLM\Software\Classes\comfile\Shell\Open\Command]
""="%1" %*  

[HKLM\Software\Classes\.reg]
""=regfile  

[HKLM\Software\Classes\regfile\Shell\Open\Command]
""=regedit.exe "%1"  

[HKLM\Software\Classes\.scr]
""=scrfile  

[HKLM\Software\Classes\scrfile\Shell\Open\Command]
""="%1" /S  

[HKLM\Software\Classes\.bat]
""=batfile  

[HKLM\Software\Classes\batfile\Shell\Open\Command]
""="%1" %*  

[HKLM\Software\Classes\.cmd]
""=cmdfile  

[HKLM\Software\Classes\cmdfile\Shell\Open\Command]
""="%1" %*  

[HKLM\Software\Classes\.pif]
""=piffile  

[HKLM\Software\Classes\piffile\Shell\Open\Command]
""="%1" %*  

[HKLM\Software\Classes\.inf]
""=inffile  

[HKLM\Software\Classes\inffile\Shell\Open\Command]
""=%SystemRoot%\system32\NOTEPAD.EXE %1  

[HKLM\Software\Classes\.url]
""=InternetShortcut  

[HKLM\Software\Classes\.lnk]
""=lnkfile  

[HKLM\Software\Classes\.hta]
""=htafile  
"Content Type"=application/hta  
"PerceivedType"=text  

[HKLM\Software\Classes\htafile\Shell\Open\Command]
""=C:\Windows\SysWOW64\mshta.exe "%1" {1E460BD7-F1C3-4B2E-88BF-4E770A288AF5}%U{1E460BD7-F1C3-4B2E-88BF-4E770A288AF5} %*  

[HKLM\Software\Classes\InternetShortcut]
"EditFlags"=2  
"FriendlyTypeName"=@C:\Windows\System32\ieframe.dll,-10046  
"FullDetails"=prop:System.Link.TargetUrl;System.Rating;System.Link.Description;System.Link.Comment  
"InfoTip"=prop:System.Link.TargetUrl;System.Rating;System.Link.Description;System.Link.Comment  
"IsShortcut"=  
"NeverShowExt"=  
"PreviewDetails"=prop:System.Link.TargetUrl;System.Rating;System.History.VisitCount;System.History.DateChanged;System.Link.DateVisited;System.Link.Description;System.Link.Comment  

[HKLM\Software\Classes\Application.Manifest]
""=Application Manifest  
"BrowserFlags"=4096  
"EditFlags"=4259840  
"FriendlyTypeName"=@C:\Windows\System32\dfshim.dll,-200  

[HKLM\Software\Classes\Application.Reference]
""=Application Reference  
"EditFlags"=131072  
"FriendlyTypeName"=@C:\Windows\System32\dfshim.dll,-201  
"IsShortcut"=  
"NeverShowExt"=  

[HKLM\Software\Classes\Folder]
""=Folder  
"ContentViewModeForBrowse"=prop:~System.ItemNameDisplay;~System.LayoutPattern.PlaceHolder;~System.LayoutPattern.PlaceHolder;~System.LayoutPattern.PlaceHolder;System.DateModified  
"ContentViewModeForSearch"=prop:~System.ItemNameDisplay;System.DateModified;~System.ItemFolderPathDisplay  
"ContentViewModeLayoutPatternForBrowse"=delta  
"ContentViewModeLayoutPatternForSearch"=alpha  
"EditFlags"=0xD2030000  
"FullDetails"=prop:System.PropGroup.Description;System.ItemNameDisplay;System.ItemTypeText;System.Size;System.HomeGroupSharingStatus  
"NoRecentDocs"=  
"ThumbnailCutoff"=0  
"TileInfo"=prop:System.Title;System.HomeGroupSharingStatus  

[HKLM\Software\WOW6432Node\Classes\.exe]
""=exefile  
"Content Type"=application/x-msdownload  

[HKLM\Software\WOW6432Node\Classes\exefile\Shell\Open\Command]
""="%1" %*  
"IsolatedCommand"="%1" %*  

[HKLM\Software\WOW6432Node\Classes\.com]
""=comfile  

[HKLM\Software\WOW6432Node\Classes\comfile\Shell\Open\Command]
""="%1" %*  

[HKLM\Software\WOW6432Node\Classes\.reg]
""=regfile  

[HKLM\Software\WOW6432Node\Classes\regfile\Shell\Open\Command]
""=regedit.exe "%1"  

[HKLM\Software\WOW6432Node\Classes\.scr]
""=scrfile  

[HKLM\Software\WOW6432Node\Classes\scrfile\Shell\Open\Command]
""="%1" /S  

[HKLM\Software\WOW6432Node\Classes\.bat]
""=batfile  

[HKLM\Software\WOW6432Node\Classes\batfile\Shell\Open\Command]
""="%1" %*  

[HKLM\Software\WOW6432Node\Classes\.cmd]
""=cmdfile  

[HKLM\Software\WOW6432Node\Classes\cmdfile\Shell\Open\Command]
""="%1" %*  

[HKLM\Software\WOW6432Node\Classes\.pif]
""=piffile  

[HKLM\Software\WOW6432Node\Classes\piffile\Shell\Open\Command]
""="%1" %*  

[HKLM\Software\WOW6432Node\Classes\.inf]
""=inffile  

[HKLM\Software\WOW6432Node\Classes\inffile\Shell\Open\Command]
""=%SystemRoot%\system32\NOTEPAD.EXE %1  

[HKLM\Software\WOW6432Node\Classes\.url]
""=InternetShortcut  

[HKLM\Software\WOW6432Node\Classes\.lnk]
""=lnkfile  

[HKLM\Software\WOW6432Node\Classes\.hta]
""=htafile  
"Content Type"=application/hta  
"PerceivedType"=text  

[HKLM\Software\WOW6432Node\Classes\htafile\Shell\Open\Command]
""=C:\Windows\SysWOW64\mshta.exe "%1" {1E460BD7-F1C3-4B2E-88BF-4E770A288AF5}%U{1E460BD7-F1C3-4B2E-88BF-4E770A288AF5} %*  

[HKLM\Software\WOW6432Node\Classes\InternetShortcut]
"EditFlags"=2  
"FriendlyTypeName"=@C:\Windows\System32\ieframe.dll,-10046  
"FullDetails"=prop:System.Link.TargetUrl;System.Rating;System.Link.Description;System.Link.Comment  
"InfoTip"=prop:System.Link.TargetUrl;System.Rating;System.Link.Description;System.Link.Comment  
"IsShortcut"=  
"NeverShowExt"=  
"PreviewDetails"=prop:System.Link.TargetUrl;System.Rating;System.History.VisitCount;System.History.DateChanged;System.Link.DateVisited;System.Link.Description;System.Link.Comment  

[HKLM\Software\WOW6432Node\Classes\Application.Manifest]
""=Application Manifest  
"BrowserFlags"=4096  
"EditFlags"=4259840  
"FriendlyTypeName"=@C:\Windows\System32\dfshim.dll,-200  

[HKLM\Software\WOW6432Node\Classes\Application.Reference]
""=Application Reference  
"EditFlags"=131072  
"FriendlyTypeName"=@C:\Windows\System32\dfshim.dll,-201  
"IsShortcut"=  
"NeverShowExt"=  

[HKLM\Software\WOW6432Node\Classes\Folder]
""=Folder  
"ContentViewModeForBrowse"=prop:~System.ItemNameDisplay;~System.LayoutPattern.PlaceHolder;~System.LayoutPattern.PlaceHolder;~System.LayoutPattern.PlaceHolder;System.DateModified  
"ContentViewModeForSearch"=prop:~System.ItemNameDisplay;System.DateModified;~System.ItemFolderPathDisplay  
"ContentViewModeLayoutPatternForBrowse"=delta  
"ContentViewModeLayoutPatternForSearch"=alpha  
"EditFlags"=0xD2030000  
"FullDetails"=prop:System.PropGroup.Description;System.ItemNameDisplay;System.ItemTypeText;System.Size;System.HomeGroupSharingStatus  
"NoRecentDocs"=  
"ThumbnailCutoff"=0  
"TileInfo"=prop:System.Title;System.HomeGroupSharingStatus  

[HKLM\Software\Clients\StartMenuInternet\Google Chrome\Shell\open\Command]
""="C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"  
[HKLM\Software\Clients\StartMenuInternet\Google Chrome\InstallInfo]
"ReinstallCommand"="C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --make-default-browser

[HKLM\Software\Clients\StartMenuInternet\IEXPLORE.EXE\Shell\open\Command]
""=C:\Program Files\Internet Explorer\iexplore.exe   [30/04/2018 21:24:17]
[HKLM\Software\Clients\StartMenuInternet\IEXPLORE.EXE\InstallInfo]
"ReinstallCommand"="C:\Windows\System32\ie4uinit.exe" -reinstall

[HKLM\Software\WOW6432Node\Clients\StartMenuInternet\Google Chrome\Shell\open\Command]
""="C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"  
[HKLM\Software\WOW6432Node\Clients\StartMenuInternet\Google Chrome\InstallInfo]
"ReinstallCommand"="C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --make-default-browser

[HKLM\Software\WOW6432Node\Clients\StartMenuInternet\IEXPLORE.EXE\Shell\open\Command]
""=C:\Program Files\Internet Explorer\iexplore.exe   [30/04/2018 21:24:17]
[HKLM\Software\WOW6432Node\Clients\StartMenuInternet\IEXPLORE.EXE\InstallInfo]
"ReinstallCommand"="C:\Windows\System32\ie4uinit.exe" -reinstall


---------- | AppcompatFlags

[HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Persisted]
"C:\Users\Luca\Downloads\VIA_HD_Audio_v11_1100f_Win10RS1_logo_11012016\v11_1100f_Win10RS1_logo_11012016\SETUP.EXE"=1
"C:\Program Files (x86)\Common Files\InstallShield\Driver\7\Intel 32\IDriver.EXE"=33
"C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\Uplay.exe"=32
"C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\upc.exe"=32

[HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store]
"C:\Users\Luca\AppData\Local\Microsoft\OneDrive\17.3.6816.0313\FileSyncConfig.exe"=0x5341435001000000000000000700000028000000787C03003765040001000000000000000000000A00210000E63F486B2AA0D2010000000100000000
"C:\Users\Luca\Desktop\ChromeSetup.exe"=0x5341435001000000000000000700000028000000583F11002342110001000000000000000000000A00210000E63F486B2AA0D2010000008100000000
"C:\Users\Luca\AppData\Local\Temp\GUMB566.tmp\GoogleUpdateSetup.exe"=0x5341435001000000000000000700000028000000583F11002342110001000000000000000000000A00210000E63F486B2AA0D2010000008000000000020000002800000000000000000000400000000000000000000000000000000053B20100000000000100000001000000
"C:\Users\Luca\Downloads\Hearthstone-Setup.exe"=0x5341435001000000000000000700000028000000F0FB3200B9A8330001000000000000000000000A00210000E63F486B2AA0D2010000000000000000020000002800000000000000000000400000000000000000000000000000000031D6AA00000000000100000001000000
"C:\Users\Luca\Downloads\MPC-HC.1.7.11.x64.exe"=0x53414350010000000000000007000000280000002865D7002169D70001000000000000000000000A00210000E63F486B2AA0D201000000000000000002000000280000000000000000000040000000000000000000000000000000001B760000000000000100000001000000
"C:\Program Files\MPC-HC\mpc-hc64.exe"=0x5341435001000000000000000700000028000000F002C60039DBC60001000000000000000000000A00210000E78E163C2AA0D20100000000000000000200000028000000000000000000000000000000000000000000000000000000F076D10100000000D1010000D1010000
"C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_17.8312.7601.0_x64__8wekyb3d8bbwe\Office16\OfficeHubWin32.exe"=0x5341435001000000000000000700000028000000C8F41E00529E1F0001000000000000000000000A00210000E78E163C2AA0D2010000000000000000020000002800000000000000000000000000000000000000000000000000000046680F00000000000100000001000000
"C:\Users\Luca\Downloads\CrystalDiskInfo7_0_5\DiskInfo64.exe"=0x5341435001000000000000000700000028000000B08B3C00EE4C3D0001000000000000000000000A00210000E78E163C2AA0D20100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000004000000000000000000000000000000000A050FA00000000002C0000002C000000
"SIGN.MEDIA=13C9F4 SW_DVD5_Office_Professional_Plus_2016_64Bit_English_MLF_X20-42432\setup.exe"=0x5341435001000000000000000700000028000000C000040022CD040001000000000000000000000A00210000E78E163C2AA0D20100000000000000000200000028000000000000000000004000000000000000000000000000000000FB6A0E00000000000200000002000000
"C:\Users\Luca\Downloads\SteamSetup.exe"=0x534143500100000000000000070000002800000088131600052B160001000000000000000000000A00210000E63F486B2AA0D20100000000000000000200000028000000000000000000004000000000000000000000000000000000B2B80000000000000100000001000000
"C:\Users\Luca\Downloads\Photoshop_Set-Up.exe"=0x5341435001000000000000000700000028000000389921005C4D220001000000000000000000000A00210000E63F486B2AA0D201000000000000000002000000280000000000000000000040000000000000000000000000000000001CDD6502000000000100000001000000
"C:\Users\Luca\AppData\Local\Microsoft\OneDrive\17.3.6917.0607\FileSyncConfig.exe"=0x5341435001000000000000000700000028000000D09A0300AA58040001000000000000000000000A71200000E63F486B2AA0D2010000000100000000
"SIGN.MEDIA=387D200 MTKV262\Microsoft Toolkit.exe"=0x534143500100000000000000070000002800000000D287030000000001000000000000000000000A80210000E78E163C2AA0D201000000000000000005000000100000000000000000000000000000000000000002000000280000000000000000000040000000000000000000000000000000002DE20B00000000000100000001000000
"SIGN.MEDIA=63B4B8 SeriousBit.NetBalancer.9.4.1.Multilingual\NetBalancerSetup_v9.4.1.905.exe"=0x5341435001000000000000000700000028000000B8B46300DCE7630001000000000000000000000A00210000E63F486B2AA0D201000000000000000002000000280000000000000000000000000000000000000000000000000000004EED0000000000000100000001000000
"C:\Program Files\NetBalancer\SeriousBit.NetBalancer.UI.exe"=0x534143500100000000000000070000002800000078D50C0050B30D0001000000000000000000000AF5220000E78E163C2AA0D20100000000000000000200000050000000000000000000000000000000000000000000000000000000F2A0630600000000FC000000F3000000000000000000004000000000000000000000000000000000F7030000000000000100000000000000
"C:\Program Files\NetBalancer\SeriousBit.NetBalancer.Tray.exe"=0x534143500100000000000000070000002800000078391D00A9E41D0001000000000000000000000AF5220000E78E163C2AA0D2010000000000000000020000002800000000000000000000000000000000000000000000000000000068060000000000000200000002000000
"C:\Users\Luca\Downloads\qbittorrent_3.3.13_x64_setup.exe"=0x5341435001000000000000000700000028000000A81D2B010000000001000000000000000000000A00210000E63F486B2AA0D20100000000000000000200000028000000000000000000004000000000000000000000000000000000CC8F0000000000000100000001000000
"SIGN.MEDIA=967280 LG_PC_Programs.exe"=0x5341435001000000000000000700000028000000F80609000D54090001000000000000000000030671000000E63F486B2AA0D20100000000000000000200000028000000000000008000000000000000000000000000000000000000B59D0700000000000200000002000000
"C:\Users\Luca\Downloads\adwcleaner_6.047.exe"=0x5341435001000000000000000700000028000000C8B73E0077C63E0001000000000000000000000A00210000E63F486B2AA0D201000000000000000002000000280000000000000000000040000000000000000000000000000000007D500100000000000100000001000000
"C:\Users\Luca\Downloads\WinRAR 5.40 [EN] 32bit + 64bit + Patch - _ingpatching.com\WinRAR 5.40 [EN] 32bit + 64bit + Patch - Crackingpatching.com\winrar-x64-540.exe"=0x534143500100000000000000070000002800000010432100DEE9210001000000000000000000000A00210000E78E163C2AA0D201000000000000000002000000280000000000000000000040000000000000000000000000000000003F270000000000000100000001000000
"C:\Users\Luca\Downloads\WinRAR 5.40 [EN] 32bit + 64bit + Patch - _ingpatching.com\WinRAR 5.40 [EN] 32bit + 64bit + Patch - Crackingpatching.com\Patch Winrar 64bit Universal Patch.exe"=0x5341435001000000000000000700000028000000D9450700B0AB070001000000000000000000000A61220000E63F486B2AA0D2010000008000000000020000002800000000000000000000400000000000000000000000000000000022310000000000000100000001000000
"C:\Users\Luca\Downloads\mb3-setup-35891.35891-3.1.2.1733-1.0.139-1.0.2060.exe"=0x534143500100000000000000070000002800000088F5D003E57BD10301000000000000000000000A00210000E63F486B2AA0D2010000000000000000020000002800000000000000000000400000000000000000000000000000000093890000000000000100000001000000
"C:\Program Files\WinRAR\WinRAR.exe"=0x534143500100000000000000070000002800000090AB1700BE9B180001000000000000000000000A00210000E78E163C2AA0D20100000000000000000200000028000000000000000000000000000000000000000000000000000000A7780400000000009700000097000000
"C:\Program Files\qBittorrent\qbittorrent.exe"=0x534143500100000000000000070000002800000000C658010000000001000000000000000000000A00210000E78E163C2AA0D2010000000000000000020000002800000000000000000000000000000000000000000000000000000067639B04000000002400000024000000
"C:\Users\Luca\Downloads\setuplanguagepack.x64.it-it_.exe"=0x5341435001000000000000000700000028000000308D69002CEC690001000000000000000000000A00210000E78E163C2AA0D20100000000000000000500000010000000000000000000000000000000000000000200000050000000000000000000000000000000000000000000000000000000C12F2300000000000400000004000000000000000000004000000000000000000000000000000000A34D0000000000000100000000000000
"SIGN.MEDIA=13CC04 OSid16Italian64\it-it\setup.exe"=0x5341435001000000000000000700000028000000C000040022CD040001000000000000000000000A00210000E78E163C2AA0D2010000000000000000020000002800000000000000000000400000000000000000000000000000000069905200000000000100000001000000
"C:\Users\Luca\Downloads\IGG-TitananaiaSoulsGOG\IGG-TitananaiaSoulsGOG\setup_titan_souls_2.0.0.1.exe"=0x5341435001000000000000000700000028000000F854920BDD0B930B01000000000000000000030600010000E63F486B2AA0D20100000000000000000200000028000000000000000000000000000000000000000000000000000000B27D0200000000000100000001000000
"C:\GOG Games\Titan Souls\TITAN.exe"=0x534143500100000000000000070000002800000000CE31003A52320001000000000000000000000A71200000E63F486B2AA0D201000000000000000002000000280000000000000010000020000000000000000000000000000000000E162D00000000000700000007000000
"C:\Users\Luca\Downloads\VIA_HD_Audio_v11_1100f_Win10RS1_logo_11012016\v11_1100f_Win10RS1_logo_11012016\SETUP.EXE"=0x5341435001000000000000000700000028000000F86D03005972030001000000000000000000010571000000E63F486B2AA0D2010000000000000000020000002800000000000000000800D00000000000000000000000000000000084E40000000000000100000001000000
"C:\Users\Luca\AppData\Local\Microsoft\OneDrive\17.3.6943.0625\FileSyncConfig.exe"=0x5341435001000000000000000700000028000000D0960300F48A040001000000000000000000000A71200000E63F486B2AA0D2010000000100000000
"D:\Hearthstone\Hearthstone.exe"=0x5341435001000000000000000700000028000000E8C7010169BE020101000000000000000000000A00210000E63F486B2AA0D20100000000000000000200000028000000000000000000000000000000000000000000000000000000EB410000000000000100000001000000
"C:\Users\Luca\Downloads\HearthArena-OverwolfInstaller.exe"=0x534143500100000000000000070000002800000068200E00AB540E0001000000000000000000030600010000E63F486B2AA0D2010000000000000000050000001000000000000000000000000000000000000000020000002800000000000000000000400000000000000000000000000000000029420000000000000100000001000000
"C:\Users\Luca\Downloads\qbittorrent_3.3.15_x64_setup.exe"=0x534143500100000000000000070000002800000031822D010000000001000000000000000000000A00210000E63F486B2AA0D201000000000000000002000000500000000000000000000000000000000000000000000000000000007348000000000000010000000100000000000000000000400000000000000000000000000000000005500000000000000100000000000000
"C:\Users\Luca\AppData\Local\Temp\Samsung_MonSetup_091006.exe"=0x534143500100000000000000070000002800000005C98E0046F2060001000000000000000000000671020000E63F486B2AA0D20100000000000000000200000028000000000000008000004000000000000000000000000000000000ECB60000000000000100000001000000
"C:\Users\Luca\Downloads\radeon-crimson-relive-17.8.2-minimalsetup-170824_web.exe"=0x534143500100000000000000070000002800000068E118038D39190301000000000000000000000A00210000E63F486B2AA0D2010000000000000000
"C:\Program Files (x86)\MonitorDriver\MonSetup.exe"=0x534143500100000000000000070000002800000000BA00007C87010001000000000000000000000673220000E78E163C2AA0D20100000000000000000200000028000000000000000000004000000200000000000000000000000000EE0F0000000000000100000001000000
"C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe"=0x534143500100000000000000070000002800000088ED8E0030F28E0001000000000000000000000A00210000E78E163C2AA0D201000000000000000002000000280000000000000000000000000000000000000000000000000000002C7B0000000000000200000002000000
"C:\Users\Luca\Downloads\MSIAfterburnerSetup\MSIAfterburnerSetup430.exe"=0x5341435001000000000000000700000028000000F05B5902A31B5A0201000000000000000000010600010000E63F486B2AA0D20100000000000000000200000028000000000000000000004000000000000000000000000000000000AF520B00000000000100000001000000
"C:\Users\Luca\Downloads\[Guru3D.com]-RTSSSetup700Beta19\Guru3D.com RTSS\RTSSSetup700Beta19.exe"=0x5341435001000000000000000700000028000000AE0952010000000001000000000000000000010600010000E63F486B2AA0D20100000000000000000200000028000000000000000000004000000000000000000000000000000000E9AC0000000000000100000001000000
"C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe"=0x5341435001000000000000000700000028000000C8FE08009DAC090001000000000000000000000A71220000E63F486B2AA0D2010000000000000000020000002800000000000000000000400000000000000000000000000000000036BBE002000000000C0000000C000000
"C:\Users\Luca\Downloads\tft.exe"=0x534143500100000000000000070000002800000000DC02000000000001000000000000000000000A61200000E63F486B2AA0D2010000000000000000020000002800000000000000000000000000000000000000000000000000000072210000000000000200000002000000
"C:\Users\Luca\Downloads\LGPCSuite_Setup.exe"=0x5341435001000000000000000700000028000000F017020E598F020E01000000000000000000010600010000E63F486B2AA0D201000000000000000002000000280000000000000000000040000000000000000000000000000000001FBE0000000000000100000001000000
"C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe"=0x534143500100000000000000070000002800000018BFAF005844B00001000000000000000000000A71200000E63F486B2AA0D20100000000000000000200000028000000000000000000000000000000000000000000000000000000BBB40300000000000200000002000000
"C:\Users\Luca\AppData\Local\Microsoft\OneDrive\17.3.6966.0824\FileSyncConfig.exe"=0x5341435001000000000000000700000028000000D0B00300CDA9040001000000000000000000000A71200000E63F486B2AA0D2010000000100000000
"C:\Users\Luca\Downloads\wlsetup-all-it-winaero.exe"=0x5341435001000000000000000700000028000000B0785508F27A550801000000000000000000030671020000E63F486B2AA0D2010000000000000000020000002800000000000000000000400000000000000000000000000000000089350300000000000100000001000000
"C:\Users\Luca\Downloads\OBS-Studio-20.0.1-Full-Installer.exe"=0x534143500100000000000000070000002800000060DB12065ECC130601000000000000000000000A00210000E63F486B2AA0D2010000000000000000020000002800000000000000000000400000000000000000000000000000000033770000000000000100000001000000
"C:\Program Files (x86)\Windows Live\Photo Gallery\MovieMaker.exe"=0x5341435001000000000000000700000028000000C0DC010044B6020001000000000000000000030671220000E63F486B2AA0D2010000000000000000020000002800000000000000000000100000000000000000000000000000000080DB6901000000003300000033000000
"SIGN.MEDIA=2EB3657D software\Dev-Cpp 5.4.1 TDM-GCC x64 4.7.1 Setup.exe"=0x534143500100000000000000070000002800000014AD99020000000001000000000000000000000671000000E63F486B2AA0D20100000000000000000500000010000000000000000000000000000000000800000200000028000000000000000008004000000000000000000000000000000000AB220000000000000100000001000000
"SIGN.MEDIA=2EB3657D software\Dev-Cpp 5.4.1 MinGW 4.7.2 Setup.exe"=0x5341435001000000000000000700000028000000FCBB7B010000000001000000000000000000000671000000E63F486B2AA0D201000000000000000002000000280000000000000000080040000000000000000000000000000000008B850000000000000100000001000000
"C:\Adobe Photoshop CC15.2+CamR.9+Bridge6.1.Por.[NAMP14.05.2015]ita\Adobe Photoshop CC v15.2.0.230 Portable\Adobe Photoshop CC15.2 Portable.exe"=0x534143500100000000000000070000002800000050A7288FAF87000001000000000000000000030600010000E63F486B2AA0D201000000000000000002000000280000000000000000000000000000000000000000000000000000001C933B01000000000200000002000000
"C:\Users\Luca\Downloads\Inkscape-0.92.1-x64-1.exe"=0x534143500100000000000000070000002800000052D89D030000000001000000000000000000000A00210000E63F486B2AA0D2010000000000000000020000002800000000000000000000400000000000000000000000000000000045030800000000000100000001000000
"C:\Program Files\Inkscape\inkscape.exe"=0x5341435001000000000000000700000028000000C18C07001982080001000000000000000000000A73200000E78E163C2AA0D2010000000000000000020000002800000000000000000000000000000000000000000000000000000002670100000000000100000001000000
"C:\Program Files (x86)\Dev-Cpp\devcpp.exe"=0x5341435001000000000000000700000028000000004831000000000001000000000000000000020661200000E63F486B2AA0D20100000000000000000200000028000000000000000000000010000000000000000000000000000000D4806802000000003C0000003C000000
"C:\Users\Luca\AppData\Local\Microsoft\OneDrive\17.3.6998.0830\FileSyncConfig.exe"=0x5341435001000000000000000700000028000000D0E20300117A040001000000000000000000000A71200000E63F486B2AA0D2010000000100000000
"C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\Uninstall.exe"=0x5341435001000000000000000700000028000000801407000CA0070001000000000000000000010600010000E63F486B2AA0D20100000000000000000200000028000000000000000000004000000000000000000000000000000000DA220000000000000100000001000000
"C:\Users\Luca\Downloads\UplayInstaller.exe"=0x534143500100000000000000070000002800000090AD8A04980D8B0401000000000000000000000A00210000E63F486B2AA0D20100000000000000000200000028000000000000000000004000000000000000000000000000000000EF0E0100000000000100000001000000
"C:\Users\Luca\Documents\scanf di campi.exe"=0x53414350010000000000000007000000280000007B5E0000E365000001000000000000000000000A71200000E63F486B2AA0D201000000000000000002000000280000000000000000000000000000000000000000000000000000003E000000000000000300000003000000
"C:\Users\Luca\AppData\Local\Microsoft\OneDrive\17.3.7076.1026\FileSyncConfig.exe"=0x5341435001000000000000000700000028000000C80E040067ED040001000000000000000000000A71200000E63F486B2AA0D2010000000100000000
"C:\Users\Luca\Downloads\tcmdpocketarm.exe"=0x5341435001000000000000000700000028000000E02C06008569060001000000000000000000000A41220000E63F486B2AA0D20100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000004000000000000000000000000000000000EC1F0000000000000100000001000000
"C:\Users\Luca\Downloads\BooktabZSetup64.exe"=0x53414350010000000000000007000000280000004EC557080000000001000000000000000000000A00210000E63F486B2AA0D201000000000000000002000000280000000000000000000040000000000000000000000000000000009F600000000000000100000001000000
"C:\Program Files\Common Files\microsoft shared\OFFICE16\MSOXMLED.EXE"=0x5341435001000000000000000700000028000000C8840300CBCA030001000000000000000000000A73220000E78E163C2AA0D20100000000000000000200000028000000000000000000000000000000000000000000000000000000AC8A0000000000000400000004000000
"C:\Program Files\Microsoft Office\Office16\POWERPNT.EXE"=0x5341435001000000000000000700000028000000B03E1C00607C1C0001000000000000000000000A00210000E78E163C2AA0D2010000009100000000
"C:\Users\Luca\Desktop\Powerpoint Ed. Fis\Gopher.exe"=0x534143500100000000000000070000002800000000300000174B000001000000000000000000000A71220000E63F486B2AA0D2010000000000000000020000002800000000000000000000000000000000000000000000000000000011B10000000000000300000003000000
"C:\Users\Luca\Desktop\Gopher.exe"=0x534143500100000000000000070000002800000000300000174B000001000000000000000000000A71220000E63F486B2AA0D2010000000000000000020000002800000000000000000000000000000000000000000000000000000019901400000000000200000002000000
"C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UplayService.exe"=0x5341435001000000000000000700000028000000585736004980360001000000000000000000000A71220000E63F486B2AA0D20100000000000000000200000028000000000000008000000000000000000000000000000000000000C4090000000000000100000001000000
"C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\upc.exe"=0x5341435001000000000000000700000028000000582389007B178A0001000000000000000000000A71220000E63F486B2AA0D20100000000000000000200000028000000000000000000000000000000000000000000000000000000F16C9F01000000000100000001000000
"C:\Users\Luca\Desktop\mie risposte mat\Geekbench-4.2.0-WindowsSetup.exe"=0x534143500100000000000000070000002800000088D7B6041A59B70401000000000000000000010600010000E63F486B2AA0D20100000000000000000200000028000000000000000000004000000000000000000000000000000000E6637400000000000100000001000000
"C:\Users\Luca\AppData\Local\Microsoft\OneDrive\17.3.7131.1115\FileSyncConfig.exe"=0x5341435001000000000000000700000028000000C89C0300B381040001000000000000000000000A71200000E63F486B2AA0D2010000000100000000
"C:\Program Files\Common Files\microsoft shared\ink\mip.exe"=0x5341435001000000000000000700000028000000008217002788170001000000010000000000000A73200000E78E163C2AA0D2010000000000000000
"SIGN.MEDIA=166A4DDC start.exe"=0x5341435001000000000000000700000028000000A6765802801F590201000000000000000000030600010000E63F486B2AA0D2010000000000000000020000002800000000000000000000000000000000000000000000000000000050FB7800000000000100000001000000
"C:\Users\Luca\AppData\Local\Microsoft\OneDrive\17.3.7294.0108\FileSyncConfig.exe"=0x5341435001000000000000000700000028000000A0A203006855040001000000000000000000000A71200000E63F486B2AA0D2010000000100000000
"C:\Users\Luca\Documents\ST PLUS Scienze della Terra\start.exe"=0x5341435001000000000000000700000028000000A6765802801F590201000000000000000000030600010000E63F486B2AA0D201000000000000000002000000280000000000000000000000000000000000000000000000000000002A678A01000000000300000003000000
"C:\Users\Luca\Desktop\Dead.Cells.v09.02.2018\Dead.Cells.v09.02.2018\deadcells.exe"=0x5341435001000000000000000700000028000000A8CA79000B437A0001000000000000000000000A71220000E63F486B2AA0D2010000000000000000050000001000000000000000000000000000000000000000020000005000000000000000000000000000000000000000000000000000000069954F0000000000110000000C0000000000000000000040000000000000000000000000000000005D080000000000000100000000000000
"C:\Users\Luca\Desktop\Dead.Cells.v09.02.2018\Dead.Cells.v09.02.2018\deadcells_gl.exe"=0x5341435001000000000000000700000028000000A8AE790041967A0001000000000000000000000A71220000E63F486B2AA0D20100000000000000000200000028000000000000000000000000000000000000000000000000000000B3040000000000000100000001000000
"D:\Fortnite\Epic Games\Launcher\Portal\SelfUpdateStaging\Install\Portal\Extras\Redist\LauncherPrereqSetup_x64.exe"=0x5341435001000000000000000700000028000000509AB200EA66B30001000000000000000000030600010000E63F486B2AA0D20100000000000000000200000028000000000000008000004000000000000000000000000000000000B5300000000000000100000001000000
"D:\Fortnite\Epic Games\Launcher\Portal\Binaries\Win32\EpicGamesLauncher.exe"=0x5341435001000000000000000700000028000000C0872E00586A2F0001000000000000000000000A71220000E63F486B2AA0D201000000000000000002000000280000000000000080000000000000000000000000000000000000002A692C02000000000300000003000000
"C:\Users\Luca\AppData\Local\Microsoft\OneDrive\18.025.0204.0009\FileSyncConfig.exe"=0x5341435001000000000000000700000028000000A0AE0300F24D040001000000000000000000000A71200000E63F486B2AA0D2010000000100000000
"C:\ProgramData\Malwarebytes\MBAMService\instlrupdate\mb3-setup-consumer-3.4.5.2467-1.0.342-1.0.4514.exe"=0x534143500100000000000000070000002800000008C149046F384A0401000000000000000000000A00210000E63F486B2AA0D201000000000000000005000000100000000000000000000000000000000000000002000000280000000000000000000040000000000000000000000000000000002E2F0000000000000100000001000000
"C:\ProgramData\Malwarebytes\MBAMService\instlrupdate\mb3-setup-consumer-3.4.5.2467-1.0.342-1.0.4756.exe"=0x534143500100000000000000070000002800000080B26004AF87610401000000000000000000000A00210000E63F486B2AA0D20100000000000000000200000028000000000000000000004000000000000000000000000000000000E3DC0000000000000100000001000000
"C:\Program Files (x86)\Google\Chrome\Application\66.0.3359.139\Installer\setup.exe"=0x534143500100000000000000070000002800000058811D00F0F81D0001000000000000000000000A00210000E78E163C2AA0D2010000000000000000020000002800000000000000000000400000000000000000000000000000000012390000000000000100000001000000
"C:\Users\Luca\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\TempState\Downloads\ChromeSetup.exe"=0x5341435001000000000000000700000028000000583D1100C0A5110001000000000000000000000A00210000E63F486B2AA0D2010000008100000000
"C:\Users\Luca\AppData\Local\Temp\GUMFE5C.tmp\GoogleUpdateSetup.exe"=0x5341435001000000000000000700000028000000583D1100C0A5110001000000000000000000000A00210000E63F486B2AA0D2010000008000000000020000002800000000000000000000400000000000000000000000000000000084C40100000000000100000001000000
"C:\Program Files\Malwarebytes\Anti-Malware\malwarebytes_assistant.exe"=0x5341435001000000000000000700000028000000205B0D009A190E0001000000000000000000000A71220000E63F486B2AA0D201000000000000000002000000280000000000000000000040000000000000000000000000000000008D000000000000000100000001000000
"C:\Users\Luca\AppData\Local\Microsoft\OneDrive\18.065.0329.0002\FileSyncConfig.exe"=0x5341435001000000000000000700000028000000A0E00300017A040001000000000000000000000A00210000E63F486B2AA0D2010000000100000000
"C:\Program Files\Microsoft Office\Office16\MSACCESS.EXE"=0x5341435001000000000000000700000028000000B0923B01942C3C0101000000000000000000000A00210000E78E163C2AA0D2010000009100000000
"C:\Windows\System32\spool\drivers\x64\3\us008a.exe"=0x534143500100000000000000070000002800000060730500D7F9050001000000000000000000000A73220000E78E163C2AA0D201000000000000000005000000100000000000000000000000000000000000000002000000280000000000000000000040000000000000000000000000000000002B060000000000000100000001000000
"C:\Users\Luca\Desktop\ML-2160_Series_WIN_SPL_V3.13.12.02.35_CDV1.26.exe"=0x534143500100000000000000070000002800000028631C02A2221D0201000000000000000000010600010000E63F486B2AA0D20100000000000000000200000028000000000000000000004000000000000000000000000000000000B2060100000000000100000001000000
"C:\Program Files (x86)\Samsung\Samsung Printer Diagnostics\SEInstall\SPD\ESM.exe"=0x534143500100000000000000070000002800000040311D00D0461D0001000000000000000000010600010000E63F486B2AA0D2010000000000000000020000002800000000000000000000400000020000000000000000000000000018000800000000000200000002000000
"D:\Steam\steamapps\common\Tomb Raider\TombRaider.exe"=0x5341435001000000000000000700000028000000002A2901D4222A0101000000000000000000020671020000E63F486B2AA0D2010000000000000000020000002800000000000000000000D000000000000000000000000000000000F9490000000000000100000001000000
"C:\Users\Luca\AppData\Local\Microsoft\OneDrive\18.091.0506.0007\FileSyncConfig.exe"=0x5341435001000000000000000700000028000000A8E003002796040001000000000000000000000A00210000E63F486B2AA0D2010000000100000000
"C:\Users\Luca\Downloads\DRAGON.BALL.FighterZ-VOKSI\DRAGON BALL FighterZ\RED\Binaries\Win64\RED-Win64-Shipping.exe"=0x53414350010000000000000007000000280000000060B10A0000000001000000000000000000000A73220000E78E163C2AA0D2010000000000000000050000001000000000000000000000000000000000000000020000005000000000000000000000400000000000000000000000000000000073DDC90200000000190000000A0000000000000000000000000000000000000000000000000000003D080000000000000A00000000000000
"C:\Users\Luca\AppData\Local\Microsoft\OneDrive\18.111.0603.0006\FileSyncConfig.exe"=0x5341435001000000000000000700000028000000A0F60300D140040001000000000000000000000A00210000E63F486B2AA0D2010000000100000000
"C:\Users\Luca\Desktop\Electric light orchestra\DrFoneForAndroid.exe"=0x534143500100000000000000070000002800000060DACF033119D00301000000000000000000000A00210000E63F486B2AA0D201000000000000000002000000280000000000000000000000000000000000000000000000000000002B6B0700000000000100000001000000
"C:\Program Files (x86)\Wondershare\dr.fone\unins000.exe"=0x53414350010000000000000007000000280000005F9612000000000001000000000000000000000A00210000E63F486B2AA0D20100000000000000000200000028000000000000000000004000000000000000000000000000000000B4160000000000000100000001000000
"SIGN.MEDIA=30DCE90 setup.exe"=0x534143500100000000000000070000002800000000A00600A61A070001000000000000000000020671000000E63F486B2AA0D2010000000000000000050000001000000000000000000000000000000000080000020000002800000000000000000800400000200000000000000020000000000044960000000000000200000002000000010000000400000001000000
"C:\Users\Luca\Desktop\readerdc_it_xa_crd_install.exe"=0x5341435001000000000000000700000028000000F86D120090D2120001000000000000000000000A00210000E63F486B2AA0D2010000000000000000020000002800000000000000000000000000000000000000000000000000000060260E00000000000100000001000000
"C:\Users\Luca\Desktop\h2testw_1.4\h2testw.exe"=0x5341435001000000000000000700000028000000006406003092060001000000000000000000000671220000E63F486B2AA0D201000000000000000002000000280000000000000000000000000000000000000000000000000000008928D200000000000200000002000000
"C:\Users\Luca\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\FileSyncConfig.exe"=0x5341435001000000000000000700000028000000A80204003EA4040001000000000000000000000A00210000E63F486B2AA0D2010000000100000000
"C:\Users\Luca\Desktop\Frogger_Win_EN_RIP-Version\Frogger_1997\frogger.exe"=0x534143500100000000000000070000002800000000240B000000000001000000000000000000010571200000E63F486B2AA0D20100000000000000000500000010000000000000000000000000000A040280000002000000A000000000000A040280006000000040000000000000000000000000ECF94600000000000D0000000D00000000000A040200006000000040000000000000000000000000C6081B0000000000010000000000000000030105000000600000000000000000000000000000000019350000000000000600000000000000000000000000000000000000000000000000000000000000E70B0000000000000200000000000000
"C:\Users\Luca\Desktop\Frogger_Win_EN_RIP-Version\Frogger_1997\VideoSetup.exe"=0x5341435001000000000000000700000028000000000A04000000000001000000000000000000010571200000E63F486B2AA0D20100000000000000000500000010000000000000000000000000000000000800000200000028000000000000000008004000002040000000000000200000000000FF2E0000000000000100000001000000010000000400000001000000
"C:\Program Files (x86)\Windows Media Player\wmplayer.exe"=0x5341435001000000000000000700000028000000008C02009493020001000000010000000000000A71220000E63F486B2AA0D2010000000000000000
"C:\Users\Luca\Desktop\MAGIXVEGASPro15\MAGIX.VEGAS.Pro.Edit.v15.0.177\VEGAS_Pro_15.0.0.177_INT_Trial.exe"=0x53414350010000000000000007000000280000003046741B03DA741B01000000000000000000030600010000E78E163C2AA0D2010000000000000000020000002800000000000000000000400000000000000000000000000000000060110100000000000100000001000000
"C:\Users\Luca\Desktop\MAGIXVEGASPro15\MAGIX.VEGAS.Pro.Edit.v15.0.177\Sony Vegas Pro 15 Patch.exe"=0x53414350010000000000000007000000280000009D4097000000000001000000000000000000000A00210000E63F486B2AA0D201000000800000000002000000280000000000000000000000000000000000000000000000000000009D270000000000000100000001000000
"C:\Program Files\VEGAS\VEGAS Pro 15.0\vegas150.exe"=0x534143500100000000000000070000002800000040839A0185B59A0101000000000000000000000A00210000E78E163C2AA0D20100000000000000000200000028000000000000000000000000000000000000000000000000000000466D2300000000000600000006000000
"C:\Users\Luca\Desktop\www.GoodOldDownloads.com-Enter.the.Gungeon.Advanced.Gungeons.and.Draguns.X64.RIP-Unleashed\Unleashed.exe"=0x53414350010000000000000007000000280000007CBDB70B0000000001000000000000000000010671000000E63F486B2AA0D20100000000000000000200000028000000000000000000000000000000000000000000000000000000BF580000000000000100000001000000
"C:\Users\Luca\Desktop\www.GoodOldDownloads.com-Enter.the.Gungeon.Advanced.Gungeons.and.Draguns.X64.RIP-Unleashed\Unleashed\EtG.exe"=0x534143500100000000000000070000002800000000EE09000000000001000000000000000000000A00210000E78E163C2AA0D20100000000000000000200000028000000000000000000000000000000000000000000000000000000E70D1B00000000000200000002000000
"C:\Users\Luca\AppData\Local\Microsoft\OneDrive\18.151.0729.0006\FileSyncConfig.exe"=0x534143500100000000000000070000002800000020F80300EE6C040001000000000000000000000A00210000E63F486B2AA0D2010000000100000000
"C:\Users\Luca\AppData\Local\Microsoft\OneDrive\18.151.0729.0012\FileSyncConfig.exe"=0x534143500100000000000000070000002800000020F30300A795040001000000000000000000000A00210000E63F486B2AA0D2010000000100000000
"C:\Users\Luca\Desktop\De moviemaker e delle pene\BooktabZSetup64.exe"=0x53414350010000000000000007000000280000008440F2060000000001000000000000000000000A00210000E63F486B2AA0D20100000000000000000200000028000000000000000000000000000000000000000000000000000000056C4900000000000100000001000000
"C:\Program Files (x86)\BooktabZ\BooktabZ.exe"=0x534143500100000000000000070000002800000000B0B5000000000001000000000000000000000A73220000E78E163C2AA0D201000000000000000002000000280000000000000000000000000000000000000000000000000000003920CA02000000001100000011000000
"D:\Hearthstone\Hearthstone Beta Launcher.exe"=0x5341435001000000000000000700000028000000E8FF490009124A0001000000000000000000000A00210000E63F486B2AA0D20100000000000000000200000028000000000000008000000000000000000000000000000000000000A1AFD202000000009400000094000000
"C:\Users\Luca\Desktop\De moviemaker e delle pene\SmartView.msi"=0x5341435001000000000000000700000028000000000201004065010001000000000000000000010500100000E78E163C2AA0D201000000000000000002000000280000000000000000000000000000000000000000000000000000000D370000000000000100000001000000
"C:\Program Files (x86)\Smart View\Smart View.exe"=0x534143500100000000000000070000002800000000C230000000000001000000000000000000000AF1200000E63F486B2AA0D2010000000000000000020000002800000000000000000000000000000000000000000000000000000083BA5300000000000100000001000000
"C:\Users\Luca\Downloads\www.GoodOldDownloads.com-DRAGON.BALL.FighterZ.Crackfix-VOKSI\Crack\RED\Binaries\Win64\RED-Win64-Shipping.exe"=0x53414350010000000000000007000000280000000060B10A0000000001000000000000000000000A73220000E78E163C2AA0D201000000000000000005000000100000000000000000000000000000000000000002000000500000000000000000000040000000000000000000000000000000008B44000000000000020000000100000000000000000000000000000000000000000000000000000050050000000000000100000000000000
"C:\Users\Luca\AppData\Local\Microsoft\OneDrive\18.172.0826.0010\FileSyncConfig.exe"=0x53414350010000000000000007000000280000006010040082C7040001000000000000000000000A00210000E63F486B2AA0D2010000000100000000
"C:\Users\Luca\Desktop\Runequalcosa\SURVEY_PROGRAM_WINDOWS_ENGLISH.exe"=0x534143500100000000000000070000002800000066EBD3040000000001000000000000000000010600010000E63F486B2AA0D201000000000000000002000000280000000000000000000040000000000000000000000000000000007A789100000000000100000001000000
"C:\Program Files (x86)\SURVEY_PROGRAM\DELTARUNE.exe"=0x5341435001000000000000000700000028000000009E4A005BD2490001000000000000000000000A71220000E63F486B2AA0D20100000000000000000200000028000000000000000000000000000000000000000000000000000000C0857200000000000400000004000000
"C:\Users\Luca\AppData\Local\Microsoft\OneDrive\18.192.0920.0015\FileSyncConfig.exe"=0x534143500100000000000000070000002800000060340400A607050001000000000000000000000A00210000E63F486B2AA0D2010000000100000000
"C:\Users\Luca\AppData\Local\Microsoft\OneDrive\18.212.1021.0008\FileSyncConfig.exe"=0x53414350010000000000000007000000280000002031040026BC040001000000000000000000000A00210000E63F486B2AA0D2010000000100000000
"C:\Users\Luca\Desktop\0001-RTL8187L_AutoInstallPackage(Beta)\RTL8187L_XP_5.1313.0613.2008_Win7_6.1316.1209.2009_UI_1.00.0179.L\Setup.exe"=0x5341435001000000000000000700000028000000681A06002981060001000000000000000000000671020000E63F486B2AA0D20100000000000000000200000028000000000000000000004000000000000000000000000000000000FB5B0000000000000100000001000000
"C:\Users\Luca\AppData\Local\Microsoft\OneDrive\18.222.1104.0007\FileSyncConfig.exe"=0x534143500100000000000000070000002800000020570400F14C050001000000000000000000000A00210000E63F486B2AA0D2010000000100000000
"D:\fifa 19\Setup\FIFA19.exe"=0x5341435001000000000000000700000028000000003075116103761101000000000000000000000A00210000E78E163C2AA0D20100000000000000000500000010000000000000000000000000000000000000000200000050000000000000000000004000000000000000000000000000000000BB2B1C000000000001000000010000000000000000000000000000000000000000000000000000001C7D3200000000000C00000000000000
"D:\fifa 19\Setup\FIFASetup\fifaconfig.exe"=0x534143500100000000000000070000002800000040790900691F0A0001000000000000000000010680010000E78E163C2AA0D201000000000000000002000000280000000000000000000000000000000000000000000000000000005D780000000000000200000002000000
"C:\Users\Luca\Downloads\PowerLineUtility_Win_180816\PowerLineUtility.exe"=0x53414350010000000000000007000000280000005EF02E010000000001000000000000000000000A00210000E63F486B2AA0D20100000000000000000200000028000000000000000000004000000000000000000000000000000000BB160200000000000100000001000000
"C:\Program Files (x86)\TP-Link\TP-Link PLC Utility\tpPLC.exe"=0x5341435001000000000000000700000028000000009031000000000001000000000000000000000A71220000E63F486B2AA0D201000000000000000002000000280000000000000000000040040000000000000000000000000000000CA30200000000000100000001000000
"C:\Users\Luca\AppData\Local\Microsoft\OneDrive\18.240.1202.0004\FileSyncConfig.exe"=0x5341435001000000000000000700000028000000386B0400903D050001000000000000000000000A00210000E63F486B2AA0D2010000000100000000
"C:\Users\Luca\Desktop\xampp-win32-7.3.1-0-VC15-installer.exe"=0x5341435001000000000000000700000028000000B8FEC107C39FC20701000000000000000000000A00210000E63F486B2AA0D201000000000000000002000000280000000000000000000040000000000000000000000000000000006C6D0400000000000100000001000000
"C:\xampp\xampp-control.exe"=0x5341435001000000000000000700000028000000006233000000000001000000000000000000000A71220000E63F486B2AA0D201000000000000000002000000280000000000000000000000000000000000000000000000000000006B2E2702000000000400000004000000
"C:\Users\Luca\AppData\Local\Microsoft\OneDrive\19.002.0107.0008\FileSyncConfig.exe"=0x5341435001000000000000000700000028000000308104006ACC040001000000000000000000000A00210000E63F486B2AA0D2010000000100000000
"C:\Users\Luca\Desktop\paint.net.4.1.5.install.exe"=0x5341435001000000000000000700000028000000006678009338790001000000000000000000010600010000E63F486B2AA0D20100000000000000000200000028000000000000000000004000000000000000000000000000000000E6840200000000000100000001000000
"C:\Users\Luca\AppData\Local\Microsoft\OneDrive\19.012.0121.0011\FileSyncConfig.exe"=0x5341435001000000000000000700000028000000308D04008E97040001000000000000000000000A00210000E63F486B2AA0D2010000000100000000
"C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe"=0x5341435001000000000000000700000028000000F0892600DACB260001000000000000000000000A00210000E63F486B2AA0D20100000000000000000200000028000000000000000000001000000000000000000000000000000000522C0600000000000100000001000000
"C:\Program Files\paint.net\PaintDotNet.exe"=0x5341435001000000000000000700000028000000D8501C00E27F1C0001000000000000000000000A80210000E78E163C2AA0D20100000000000000000200000028000000000000000000000000000000000000000000000000000000036A3500000000001300000013000000
"C:\Users\Luca\AppData\Local\Microsoft\OneDrive\19.033.0218.0011\FileSyncConfig.exe"=0x534143500100000000000000070000002800000060AA0400777F050001000000000000000000000A00210000E63F486B2AA0D2010000000100000000
"C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\Uplay.exe"=0x534143500100000000000000070000002800000058CD0600A229070001000000000000000000000A71220000E63F486B2AA0D2010000000000000000
"C:\Users\Luca\AppData\Local\Microsoft\OneDrive\19.043.0304.0007\FileSyncConfig.exe"=0x534143500100000000000000070000002800000030AF0400A4BA040001000000000000000000000A00210000E63F486B2AA0D2010000000100000000
"C:\Program Files (x86)\obs-studio\bin\64bit\obs64.exe"=0x534143500100000000000000070000002800000010223100946E310001000000000000000000000A73220000E78E163C2AA0D2010000000000000000020000002800000000000000000000000000000000000000000000000000000085102C00000000000400000004000000
"C:\Users\Luca\Desktop\Video Gaetano\qbittorrent_4.1.5_x64_setup.exe"=0x534143500100000000000000070000002800000079A565010000000001000000000000000000000A00210000E63F486B2AA0D20100000000000000000200000028000000000000000000000000000000000000000000000000000000468E2801000000000100000001000000
"C:\Users\Luca\AppData\Local\Microsoft\OneDrive\19.062.0331.0006\FileSyncConfig.exe"=0x534143500100000000000000070000002800000060BC0400AE33050001000000000000000000000A00210000E63F486B2AA0D2010000000100000000
"C:\Program Files\Microsoft Office\Office16\EXCEL.EXE"=0x5341435001000000000000000700000028000000502C0E02B0090F0201000000000000000000000A00210000E78E163C2AA0D2010000009100000000
"C:\Users\Luca\AppData\Local\Microsoft\OneDrive\19.070.0410.0005\FileSyncConfig.exe"=0x534143500100000000000000070000002800000060BC04002A69050001000000000000000000000A00210000E63F486B2AA0D2010000000100000000
"C:\Users\Luca\AppData\Local\Microsoft\OneDrive\19.070.0410.0007\FileSyncConfig.exe"=0x534143500100000000000000070000002800000060BC0400100C050001000000000000000000000A00210000E63F486B2AA0D2010000000100000000
"C:\Program Files\Microsoft Office\Office16\WINWORD.EXE"=0x534143500100000000000000070000002800000020971D00D2A61D0001000000000000000000000A00210000E78E163C2AA0D2010000009100000000
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"=0x5341435001000000000000000700000028000000F0BD1700B2B1180001000000000000000000000A00210000E78E163C2AA0D2010000000000000000020000002800000000000000000000000000000000000000000000000000000076922403000000000E0000000E000000
"C:\Users\Luca\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe"=0x534143500100000000000000070000002800000038C7F901DA35FA0101000000000000000000000A00210000E63F486B2AA0D2010000000100000000
"C:\Users\Luca\AppData\Local\Microsoft\OneDrive\19.086.0502.0006\FileSyncConfig.exe"=0x534143500100000000000000070000002800000038C904002188050001000000000000000000000A00210000E63F486B2AA0D2010000000100000000
"D:\Blizzard App\Battle.net Launcher.exe"=0x5341435001000000000000000700000028000000E85D03008CD9030001000000000000000000000A00210000E63F486B2AA0D20100000000000000000200000028000000000000008000000000000000000000000000000000000000ACC42B02000000000D0000000D000000
"C:\Users\Luca\AppData\Local\HearthstoneDeckTracker\HearthstoneDeckTracker.exe"=0x53414350010000000000000007000000280000002067070076B4070001000000000000000000000A71220000E63F486B2AA0D2010000000000000000020000002800000000000000000000000000000000000000000000000000000058E01602000000000C0000000C000000
"D:\Steam\Steam.exe"=0x5341435001000000000000000700000028000000200B3000368A300001000000000000000000000A00210000E63F486B2AA0D201000000000000000002000000280000000000000000000000000000000000000000000000000000006D000000000000000200000002000000
"C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe"=0x5341435001000000000000000700000028000000D04086000918870001000000000000000000000A71220000E63F486B2AA0D201000000000000000002000000280000000000000000000000000000000000000000000000000000006650C800000000000200000002000000
"C:\Users\Luca\Desktop\adwcleaner_7.3.exe"=0x5341435001000000000000000700000028000000D0326B00387A6B0001000000000000000000000A00210000E63F486B2AA0D201000000000000000005000000100000000000000000000000000000000000000002000000280000000000000000000040000000000000000000000000000000003E650100000000000100000001000000
"C:\Users\Luca\Desktop\quickdiag_V5_27.02.19.1.exe"=0x534143500100000000000000070000002800000098F74E00B9194F0001000000000000000000000A00210000E63F486B2AA0D2010000000000000000


---------- | IFEO


---------- | Mountpoints2

[HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\Mountpoints2\{1e6a43dd-9123-11e8-80ed-902b34d2f878}] : "G:\Setup.exe"      (AutoRun)
[HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\Mountpoints2\{9864ca16-687f-11e7-bebf-902b34d2f878}] : "H:\LG_PC_Programs.exe"      (AutoRun)

---------- | Windows

[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\win.ini\Windows]
""=USR:Software\Microsoft\Windows NT\CurrentVersion\Windows  
"APPINIT_DLLS"=SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS  
"Beep"=#USR:Control Panel\Sound  
"CoolSwitch"=USR:Control Panel\Desktop  
"DEFAULTSEPARATEVDM"=\\REGISTRY\\MACHINE\\SYSTEM\\CURRENTCONTROLSET\\CONTROL\\WOW  
"DEVICENOTSELECTEDTIMEOUT"=#SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS  
"DoubleClickHeight"=#USR:Control Panel\Mouse  
"DoubleClickSpeed"=#USR:Control Panel\Mouse  
"DoubleClickWidth"=#USR:Control Panel\Mouse  
"DragFullWindows"=USR:Control Panel\Desktop  
"InitialKeyboardIndicators"=USR:Control Panel\Keyboard  
"LowPowerActive"=#USR:Control Panel\Desktop  
"LowPowerTimeOut"=#USR:Control Panel\Desktop  
"MouseSpeed"=#USR:Control Panel\Mouse  
"MouseThreshold1"=#USR:Control Panel\Mouse  
"MouseThreshold2"=#USR:Control Panel\Mouse  
"PowerOffActive"=#USR:Control Panel\Desktop  
"PowerOffTimeOut"=#USR:Control Panel\Desktop  
"ScreenSaveActive"=#USR:Control Panel\Desktop  
"ScreenSaveTimeOut"=#USR:Control Panel\Desktop  
"SnapToDefaultButton"=#USR:Control Panel\Mouse  
"Spooler"=#SYS:Microsoft\Windows NT\CurrentVersion\Windows  
"SWAPDISK"=SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS  
"SwapMouseButtons"=#USR:Control Panel\Mouse  
"TRANSMISSIONRETRYTIMEOUT"=#SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS  

[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\system.ini\Boot]
""=SYS:Microsoft\Windows NT\CurrentVersion\WOW\boot  
"ScreenSaverActive"=USR:Control Panel\Desktop  
"ScreenSaverIsSecure"=USR:Control Panel\Desktop  
"SCRNSAVE.EXE"=USR:Control Panel\Desktop  
"Shell"=SYS:Microsoft\Windows NT\CurrentVersion\Winlogon  

[HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\IniFileMapping\win.ini\Windows]
"APPINIT_DLLS"=SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS  
"Beep"=#USR:Control Panel\Sound  
"CoolSwitch"=USR:Control Panel\Desktop  
"DEFAULTSEPARATEVDM"=\\REGISTRY\\MACHINE\\SYSTEM\\CURRENTCONTROLSET\\CONTROL\\WOW  
"DEVICENOTSELECTEDTIMEOUT"=#SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS  
"DoubleClickHeight"=#USR:Control Panel\Mouse  
"DoubleClickSpeed"=#USR:Control Panel\Mouse  
"DoubleClickWidth"=#USR:Control Panel\Mouse  
"DragFullWindows"=USR:Control Panel\Desktop  
"InitialKeyboardIndicators"=USR:Control Panel\Keyboard  
"LowPowerActive"=#USR:Control Panel\Desktop  
"LowPowerTimeOut"=#USR:Control Panel\Desktop  
"MouseSpeed"=#USR:Control Panel\Mouse  
"MouseThreshold1"=#USR:Control Panel\Mouse  
"MouseThreshold2"=#USR:Control Panel\Mouse  
"PowerOffActive"=#USR:Control Panel\Desktop  
"PowerOffTimeOut"=#USR:Control Panel\Desktop  
"ScreenSaveActive"=#USR:Control Panel\Desktop  
"ScreenSaveTimeOut"=#USR:Control Panel\Desktop  
"SnapToDefaultButton"=#USR:Control Panel\Mouse  
"SWAPDISK"=SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS  
"SwapMouseButtons"=#USR:Control Panel\Mouse  
"TRANSMISSIONRETRYTIMEOUT"=#SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS  

[HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\IniFileMapping\system.ini\Boot]
""=SYS:Microsoft\Windows NT\CurrentVersion\WOW\boot  
"ScreenSaverActive"=USR:Control Panel\Desktop  
"ScreenSaverIsSecure"=USR:Control Panel\Desktop  
"SCRNSAVE.EXE"=USR:Control Panel\Desktop  
"Shell"=SYS:Microsoft\Windows NT\CurrentVersion\Winlogon  

[HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems]
"windows"=%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16

---------- | Security center

[HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\SOFTWARE\Microsoft\Windows Defender]
"UIFirstRun"=0

[HKLM\SOFTWARE\Microsoft\Security Center]
"cval"=1

[HKLM\SOFTWARE\Microsoft\Security Center\svc]
"VistaSp1"=131437454892136076

[HKLM\SOFTWARE\Microsoft\Windows Defender]
"ProductAppDataPath"=C:\ProgramData\Microsoft\Windows Defender
"ProductIcon"=@%ProgramFiles%\Windows Defender\EppManifest.dll,-100
"ProductLocalizedName"=@%ProgramFiles%\Windows Defender\EppManifest.dll,-1000
"RemediationExe"=%ProgramFiles%\Windows Defender\MSASCui.exe
"ProductType"=2
"InstallTime"=0xD8C1C3ECAAF5D201
"InstallLocation"=C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1906.3-0\
"ProductStatus"=0
"OOBEInstallTime"=0xEC30D2F0ABF5D201
"ManagedDefenderProductType"=0
"OneTimeSqmDataSent"=1
"DisableAntiSpyware"=0
"DisableAntiVirus"=0
"LastEnabledTime"=0xDCDC6FDAE491D301
"BackupLocation"=C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1905.4-0

[HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall"=1

[HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall"=1

[HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall"=1


---------- | Safeboot

[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ahcache.sys]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppInfo]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppMgmt]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Base]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BasicDisplay.sys]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BasicRender.sys]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Boot Bus Extender]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Boot file system]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BrokerInfrastructure]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CoreMessagingRegistrar]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CryptSvc]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\DcomLaunch]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\DeviceInstall]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dxgkrnl.sys]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EFS]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EventLog]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\File system]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Filter]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\FsDepends.sys]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HelpSvc]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\iai2c.sys]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\KeyIso]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\LSM]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Netlogon]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NTDS]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PCI Configuration]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PlugPlay]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PNP Filter]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Power]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Primary disk]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ProfSvc]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcEptMapper]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcSs]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SCSI Class]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sermouse.sys]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SpbCx.sys]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\StateRepository]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SWPRV]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\System Bus Extender]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SystemEventsBroker]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TabletInputService]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TBS]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TileDataModelSvc]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TrustedInstaller]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\uefi.sys]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\UserManager]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\VDS]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vmms]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgr.sys]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgrx.sys]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinMgmt]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{36FC9E60-C465-11CF-8056-444553540000}]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E965-E325-11CE-BFC1-08002BE10318}]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E969-E325-11CE-BFC1-08002BE10318}]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96A-E325-11CE-BFC1-08002BE10318}]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96B-E325-11CE-BFC1-08002BE10318}]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96F-E325-11CE-BFC1-08002BE10318}]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E977-E325-11CE-BFC1-08002BE10318}]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97B-E325-11CE-BFC1-08002BE10318}]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97D-E325-11CE-BFC1-08002BE10318}]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E980-E325-11CE-BFC1-08002BE10318}]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{71A27CDD-812A-11D0-BEC7-08002BE2092F}]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{9DA2B80F-F89F-4A49-A5C2-511B085B9E8A}]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{A0A588A4-C46F-4B37-B7EA-C82FE89870C6}]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AFD]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Ahcache.sys]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AppInfo]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AppMgmt]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Base]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\BasicDisplay.sys]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\BasicRender.sys]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\BFE]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Boot Bus Extender]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Boot file system]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\bowser]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\BrokerInfrastructure]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Browser]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CoreMessagingRegistrar]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CryptSvc]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\DcomLaunch]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\DeviceInstall]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\dfsc]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Dhcp]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\DnsCache]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Dot3Svc]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\dxgkrnl.sys]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Eaphost]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\EFS]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\EventLog]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\File system]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Filter]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\FsDepends.sys]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\HelpSvc]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\IKEEXT]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ipnat.sys]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\KeyIso]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\LanmanServer]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\LanmanWorkstation]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\LmHosts]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\LSM]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Messenger]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MPSDrv]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MPSSvc]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mrxsmb]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mrxsmb10]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mrxsmb20]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NativeWifiP]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NDIS]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NDIS Wrapper]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ndiscap]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Ndisuio]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetBIOS]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetBIOSGroup]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetBT]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetDDEGroup]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Netlogon]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetMan]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\netprofm]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetSetupSvc]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Network]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetworkProvider]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NlaSvc]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Nsi]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\nsiproxy.sys]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NTDS]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PCI Configuration]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PlugPlay]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PNP Filter]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PNP_TDI]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PolicyAgent]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Power]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Primary disk]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ProfSvc]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\rdbss]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\rdpencdd.sys]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\rdsessmgr]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\RpcEptMapper]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\RpcSs]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\sacsvr]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SCardSvr]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SCSI Class]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\sermouse.sys]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SharedAccess]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SmartcardSimulator]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SpbCx.sys]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\StateRepository]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Streams Drivers]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SWPRV]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\System Bus Extender]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SystemEventsBroker]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TabletInputService]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TBS]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Tcpip]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TDI]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TileDataModelSvc]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TrustedInstaller]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\uefi.sys]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\UserManager]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\VaultSvc]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\VDS]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\VirtualSmartcardReader]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\vmms]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\volmgr.sys]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\volmgrx.sys]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wcmsvc]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WinDefend]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WinMgmt]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wlansvc]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WudfPf]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WudfRd]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WudfSvc]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WudfUsbccidDriver]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{36FC9E60-C465-11CF-8056-444553540000}]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E965-E325-11CE-BFC1-08002BE10318}]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E967-E325-11CE-BFC1-08002BE10318}]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E969-E325-11CE-BFC1-08002BE10318}]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E96A-E325-11CE-BFC1-08002BE10318}]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E96B-E325-11CE-BFC1-08002BE10318}]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E96F-E325-11CE-BFC1-08002BE10318}]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E973-E325-11CE-BFC1-08002BE10318}]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E974-E325-11CE-BFC1-08002BE10318}]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E975-E325-11CE-BFC1-08002BE10318}]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E977-E325-11CE-BFC1-08002BE10318}]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E97B-E325-11CE-BFC1-08002BE10318}]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E97D-E325-11CE-BFC1-08002BE10318}]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E980-E325-11CE-BFC1-08002BE10318}]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{50DD5230-BA8A-11D1-BF5D-0000F805F530}]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{71A27CDD-812A-11D0-BEC7-08002BE2092F}]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{9DA2B80F-F89F-4A49-A5C2-511B085B9E8A}]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{A0A588A4-C46F-4B37-B7EA-C82FE89870C6}]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]

---------- | Winsock (Whitelist)


---------- | Hosts


---------- | Ping

Esecuzione di Ping google.com [216.58.205.110] con 32 byte di dati:
Risposta da 216.58.205.110: byte=32 durata=23ms TTL=53
Risposta da 216.58.205.110: byte=32 durata=22ms TTL=53
Risposta da 216.58.205.110: byte=32 durata=22ms TTL=53
Risposta da 216.58.205.110: byte=32 durata=22ms TTL=53

Statistiche Ping per 216.58.205.110:
    Pacchetti: Trasmessi = 4, Ricevuti = 4,
    Persi = 0 (0% persi),
Tempo approssimativo percorsi andata/ritorno in millisecondi:
    Minimo = 22ms, Massimo =  23ms, Medio =  22ms

---------- | @

[HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\Software\Microsoft\Internet Explorer\Main]
"Anchor Underline"=yes
"Cache_Update_Frequency"=yes
"Disable Script Debugger"=yes
"DisableScriptDebuggerIE"=yes
"Display Inline Images"=yes
"Do404Search"=0x01000000
"Local Page"=%11%\blank.htm
"Save_Session_History_On_Exit"=no
"Search Page"=http://go.microsoft.com/fwlink/?LinkId=54896
"Show_FullURL"=no
"Show_StatusBar"=yes
"Show_ToolBar"=yes
"Show_URLinStatusBar"=yes
"Show_URLToolBar"=yes
"Use_DlgBox_Colors"=yes
"UseClearType"=no
"XMLHTTP"=1
"Enable Browser Extensions"=yes
"Play_Background_Sounds"=yes
"Play_Animations"=yes
"Start Page"=http://go.microsoft.com/fwlink/p/?LinkId=255141
"ImageStoreRandomFolder"=gm3rfz7
"OperationalData"=13
"CompatibilityFlags"=0
"FullScreen"=no
"Window_Placement"=0x2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF2400000024000000A80300007C020000
"Start Page_TIMESTAMP"=0x3D043EFD4E14D301
"SyncHomePage Protected - It is a violation of Windows Policy to modify. See aka.ms/browserpolicy"=
"IE10RunOnceLastShown"=1
"IE10RunOnceLastShown_TIMESTAMP"=0x6D0B9B56C4F5D401
"IE10TourShown"=1
"IE10TourShownTime"=0x41E9C8D9BFE0D301
"AutoHide"=yes
"SearchBandMigrationVersion"=1

[HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\Software\Microsoft\Windows\CurrentVersion\Internet settings]
"DisableCachingOfSSLPages"=0
"IE5_UA_Backup_Flag"=5.0
"PrivacyAdvanced"=1
"SecureProtocols"=2688
"User Agent"=Mozilla/4.0 (compatible; MSIE 8.0; Win32)
"CertificateRevocation"=1
"ZonesSecurityUpgrade"=0x41E9C8D9BFE0D301
"WarnonZoneCrossing"=0
"EnableNegotiate"=1
"MigrateProxy"=1
"ProxyEnable"=0

[HKLM\Software\Microsoft\Internet Explorer\Main]
"ApplicationTileImmersiveActivation"=1
"AssociationActivationMode"=0
"AutoHide"=yes
"Start Page"=http://go.microsoft.com/fwlink/p/?LinkId=255141
"Anchor_Visitation_Horizon"=0x01000000
"Cache_Percent_of_Disk"=0x0A000000
"Default_Page_URL"=http://go.microsoft.com/fwlink/p/?LinkId=255141
"Default_Search_URL"=http://go.microsoft.com/fwlink/?LinkId=54896
"Default_Secondary_Page_URL"=
"Delete_Temp_Files_On_Exit"=yes
"Enable_Disk_Cache"=yes
"Extensions Off Page"=about:NoAdd-ons
"Local Page"=C:\Windows\System32\blank.htm
"Placeholder_Height"=0x1A000000
"Placeholder_Width"=0x1A000000
"Search Page"=http://go.microsoft.com/fwlink/?LinkId=54896
"Security Risk Page"=about:SecurityRisk
"Use_Async_DNS"=yes
"x86AppPath"=C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE

[HKLM\Software\Microsoft\Internet Explorer\AboutURLs]
"blank"=res://mshtml.dll/blank.htm
"DesktopItemNavigationFailure"=res://ieframe.dll/navcancl.htm
"Home"=270
"InPrivate"=res://ieframe.dll/inprivate.htm
"NavigationCanceled"=res://ieframe.dll/navcancl.htm
"NavigationFailure"=res://ieframe.dll/navcancl.htm
"NoAdd-ons"=res://ieframe.dll/noaddon.htm
"NoAdd-onsInfo"=res://ieframe.dll/noaddoninfo.htm
"PostNotCached"=res://ieframe.dll/repost.htm
"SecurityRisk"=res://ieframe.dll/securityatrisk.htm

[HKLM\Software\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix]
""=http://

[HKLM\Software\Microsoft\Windows\CurrentVersion\URL\Prefixes]
"ftp"=ftp://
"home"=http://
"mosaic"=http://
"www"=http://

[HKLM\Software\Microsoft\Windows\CurrentVersion\Internet settings]
"ActiveXCache"=C:\Windows\Downloaded Program Files
"CodeBaseSearchPath"=CODEBASE
"EnablePunycode"=1
"MinorVersion"=0
"WarnOnIntranet"=1

[HKLM\Software\WOW6432Node\Microsoft\Internet Explorer\Main]
"ApplicationTileImmersiveActivation"=1
"AssociationActivationMode"=0
"AutoHide"=yes
"Start Page"=http://go.microsoft.com/fwlink/p/?LinkId=255141
"Anchor_Visitation_Horizon"=0x01000000
"Cache_Percent_of_Disk"=0x0A000000
"Default_Page_URL"=http://go.microsoft.com/fwlink/p/?LinkId=255141
"Default_Search_URL"=http://go.microsoft.com/fwlink/?LinkId=54896
"Default_Secondary_Page_URL"=
"Delete_Temp_Files_On_Exit"=yes
"Enable_Disk_Cache"=yes
"Extensions Off Page"=about:NoAdd-ons
"Local Page"=C:\Windows\SysWOW64\blank.htm
"Placeholder_Height"=0x1A000000
"Placeholder_Width"=0x1A000000
"Search Page"=http://go.microsoft.com/fwlink/?LinkId=54896
"Security Risk Page"=about:SecurityRisk
"Use_Async_DNS"=yes
"x86AppPath"=C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE

[HKLM\Software\WOW6432Node\Microsoft\Internet Explorer\AboutURLs]
"blank"=res://mshtml.dll/blank.htm
"DesktopItemNavigationFailure"=res://ieframe.dll/navcancl.htm
"Home"=270
"InPrivate"=res://ieframe.dll/inprivate.htm
"NavigationCanceled"=res://ieframe.dll/navcancl.htm
"NavigationFailure"=res://ieframe.dll/navcancl.htm
"NoAdd-ons"=res://ieframe.dll/noaddon.htm
"NoAdd-onsInfo"=res://ieframe.dll/noaddoninfo.htm
"PostNotCached"=res://ieframe.dll/repost.htm
"SecurityRisk"=res://ieframe.dll/securityatrisk.htm

[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix]
""=http://

[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\URL\Prefixes]
"ftp"=ftp://
"home"=http://
"mosaic"=http://
"www"=http://

[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Internet settings]
"ActiveXCache"=C:\Windows\Downloaded Program Files
"CodeBaseSearchPath"=CODEBASE
"EnablePunycode"=1
"MinorVersion"=0
"WarnOnIntranet"=1


---------- | Proxy


---------- | reparsepoint


---------- | Detection of offsets


---------- | Notify


---------- | Execution FileExts








---------- | SIOI | SEH | URLSH

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ AccExtIco1] - {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} --  C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll   [26/05/2017 03:18:36]
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ AccExtIco2] - {853B7E05-C47D-4985-909A-D0DC5C6D7303} --  C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll   [26/05/2017 03:18:36]
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ AccExtIco3] - {42D38F2E-98E9-4382-B546-E24E4D6D04BB} --  C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll   [26/05/2017 03:18:36]
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive1] - {BBACC218-34EA-4666-9D7A-C78F2274A524} --    
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive2] - {5AB7172C-9C11-405C-8DD5-AF20F3606282} --    
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive3] - {A78ED123-AB77-406B-9962-2A5D9D2F7F30} --    
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive4] - {F241C880-6982-4CE5-8CF7-7085BA96DA5A} --    
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive5] - {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} --    
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive6] - {9AA2F32D-362A-42D9-9328-24A483E2CCC3} --    
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ SkyDrivePro1 (ErrorConflict)] - {8BA85C75-763B-4103-94EB-9470F12FE0F7} --  C:\PROGRA~1\MICROS~1\Office16\GROOVEEX.DLL   [20/07/2018 18:04:28]
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ SkyDrivePro2 (SyncInProgress)] - {CD55129A-B1A1-438E-A425-CEBC7DC684EE} --  C:\PROGRA~1\MICROS~1\Office16\GROOVEEX.DLL   [20/07/2018 18:04:28]
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ SkyDrivePro3 (InSync)] - {E768CD3B-BDDC-436D-9C13-E1B39CA257B1} --  C:\PROGRA~1\MICROS~1\Office16\GROOVEEX.DLL   [20/07/2018 18:04:28]
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\EnhancedStorageShell] - {D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D} --  C:\Windows\System32\EhStorShell.dll   [18/03/2017 22:57:23]
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\Offline Files] - {4E77131D-3629-431c-9818-C5679DC83E81} --  %SystemRoot%\System32\cscui.dll  
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive1] - {BBACC218-34EA-4666-9D7A-C78F2274A524} --    
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive2] - {5AB7172C-9C11-405C-8DD5-AF20F3606282} --    
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive3] - {A78ED123-AB77-406B-9962-2A5D9D2F7F30} --    
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive4] - {F241C880-6982-4CE5-8CF7-7085BA96DA5A} --    
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive5] - {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} --    
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive6] - {9AA2F32D-362A-42D9-9328-24A483E2CCC3} --    
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ SkyDrivePro1 (ErrorConflict)] - {8BA85C75-763B-4103-94EB-9470F12FE0F7} --  C:\PROGRA~2\MICROS~1\Office16\GROOVEEX.DLL   [22/07/2018 13:55:02]
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ SkyDrivePro2 (SyncInProgress)] - {CD55129A-B1A1-438E-A425-CEBC7DC684EE} --  C:\PROGRA~2\MICROS~1\Office16\GROOVEEX.DLL   [22/07/2018 13:55:02]
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ SkyDrivePro3 (InSync)] - {E768CD3B-BDDC-436D-9C13-E1B39CA257B1} --  C:\PROGRA~2\MICROS~1\Office16\GROOVEEX.DLL   [22/07/2018 13:55:02]

[HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"=  


---------- | Toolbar

[HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"Locked"=1  
"ShowDiscussionButton"=Yes  

[HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"={0633EE93-D776-472f-A0FF-E1416B8B2E3A}  
"KnownProvidersUpgradeTime"=0x41E9C8D9BFE0D301  
"Version"=5  
"UpgradeTime"=0x41E9C8D9BFE0D301  

[HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"={0633EE93-D776-472f-A0FF-E1416B8B2E3A}  

[HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"={0633EE93-D776-472f-A0FF-E1416B8B2E3A}  


---------- | Extensions

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{2670000A-7350-4f3c-8081-5663EE0C6C49}] : (Se&nd to OneNote) -       []
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}] : (@%CommonProgramFiles%\Microsoft Shared\Office16\oregres.dll,-430) -       []
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}] : (OneNote Lin&ked Notes) -       []
[HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Extensions\{2670000A-7350-4f3c-8081-5663EE0C6C49}] : (Se&nd to OneNote) -       []
[HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Extensions\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}] : (@%CommonProgramFiles%\Microsoft Shared\Office16\oregres.dll,-430) -       []
[HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Extensions\{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}] : (OneNote Lin&ked Notes) -       []

---------- | SearchScopes

[HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}] - (Bing) - http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02 :
[HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}] - (@ieframe.dll,-12512) - http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC :
[HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}] - (@ieframe.dll,-12512) - http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC :

---------- | Browser Helper Objects

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}] -> (Skype for Business Browser Helper) : C:\Program Files (x86)\Microsoft Office\Office16\OCHelper.dll  [24/05/2019 04:46:32]
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}] -> (Microsoft OneDrive for Business Browser Helper) : C:\PROGRA~2\MICROS~1\Office16\GROOVEEX.DLL  [22/07/2018 13:55:02]
[HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}] -> (Skype for Business Browser Helper) : C:\Program Files (x86)\Microsoft Office\Office16\OCHelper.dll  [24/05/2019 04:46:32]
[HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}] -> (Microsoft OneDrive for Business Browser Helper) : C:\PROGRA~2\MICROS~1\Office16\GROOVEEX.DLL  [22/07/2018 13:55:02]

---------- | Chrome

C:\Users\Luca\AppData\Local\Google\Chrome\User Data\Default\extensions\aapocclcgogkmnckokdopfmhonfmgoek =  : Google & co - Google & co - https://clients2.google.com/service/update2/crx
C:\Users\Luca\AppData\Local\Google\Chrome\User Data\Default\extensions\aohghmighlieiainnegkcijnfilokake =  : Google & co - Google & co - https://clients2.google.com/service/update2/crx
C:\Users\Luca\AppData\Local\Google\Chrome\User Data\Default\extensions\apdfllckaahabafndbhieahigkjlhalf =  : Google & co - https://drive.google.com/?usp=chrome_app - Google & co - [http://docs.google.com/http://drive.google.com/https://docs.google.com/https://drive.google.com/] - https://clients2.google.com/service/update2/crx
C:\Users\Luca\AppData\Local\Google\Chrome\User Data\Default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo =  : Google & co - http://www.youtube.com - http://www.youtube.com - Google & co - http://clients2.google.com/service/update2/crx
C:\Users\Luca\AppData\Local\Google\Chrome\User Data\Default\extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm =  :     __MSG_extShortDesc__ -    name: uBlock Origin -    short_name: uBlock₀ - permissions:[contextMenusprivacystoragetabsunlimitedStoragewebNavigationwebRequestwebRequestBlocking\u003Call_urls>] - https://clients2.google.com/service/update2/crx
C:\Users\Luca\AppData\Local\Google\Chrome\User Data\Default\extensions\felcaaldnbdncclmgdcncolpebgiejap =  : Google & co - Google & co - https://clients2.google.com/service/update2/crx
C:\Users\Luca\AppData\Local\Google\Chrome\User Data\Default\extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi =  :     __MSG_extDesc__ -     __MSG_extName__ - https://clients2.google.com/service/update2/crx
C:\Users\Luca\AppData\Local\Google\Chrome\User Data\Default\extensions\nmmhkkegccagdldgiimedpiccmgmieda =  : Google & co - Google & co - 203784468217.apps.googleusercontent.com - https://clients2.google.com/service/update2/crx
C:\Users\Luca\AppData\Local\Google\Chrome\User Data\Default\extensions\oeopbcgkkoapgobdbedcemjljbihmemj =  :     __MSG_description__ -     Checker Plus for Gmail™ - client_id_PROD:450788627700-b4u9la88b9jii904fet8l7p20c0iotv5.apps.googleusercontent.com - https://clients2.google.com/service/update2/crx
C:\Users\Luca\AppData\Local\Google\Chrome\User Data\Default\extensions\pjkljhegncpnkpknbcohdijeoejaedia =  : Google & co - https://mail.google.com/mail - Google & co - [*://mail.google.com/mail] - https://clients2.google.com/service/update2/crx
C:\Users\Luca\AppData\Local\Google\Chrome\User Data\Default\extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm =  :     Provider for discovery and services for mirroring of Chrome Media Router -     Chrome Media Router - 919648714761-55j965o0km033psv3i9qls5mo3qtdrb0.apps.googleusercontent.com - https://clients2.google.com/service/update2/crx


---------- | Opera


---------- | Firefox


[HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0] - (Microsoft SharePoint Plug-in for Firefox) : C:\PROGRA~1\MICROS~1\Office16\NPSPWRAP.DLL
[HKLM\Software\MozillaPlugins\adobe.com/AdobeAAMDetect] - () : C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll
[HKLM\Software\WOW6432Node\MozillaPlugins\@microsoft.com/Lync,version=15.0] - (Skype for Business Plug-in for Firefox) : C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll
[HKLM\Software\WOW6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0] - (Microsoft SharePoint Plug-in for Firefox) : C:\PROGRA~2\MICROS~1\Office16\NPSPWRAP.DLL
[HKLM\Software\WOW6432Node\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3528.0331] - (WLPG Install MIME type) : C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
[HKLM\Software\WOW6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3] - (Google Update) : C:\Program Files (x86)\Google\Update\1.3.34.11\npGoogleUpdate3.dll
[HKLM\Software\WOW6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9] - (Google Update) : C:\Program Files (x86)\Google\Update\1.3.34.11\npGoogleUpdate3.dll
[HKLM\Software\WOW6432Node\MozillaPlugins\Adobe Reader] - (Handles PDFs in-place in Firefox) : C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll
[HKLM\Software\WOW6432Node\MozillaPlugins\adobe.com/AdobeAAMDetect] - () : C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll



---------- | DNS

[HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters]
"DhcpNameServer"=8.8.8.8 8.8.4.4
[HKLM\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{83e8d3d2-8a69-4637-b8d7-5882a149a8d0}]
"DhcpNameServer"=8.8.8.8 8.8.4.4
[HKLM\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{83e8d3d2-8a69-4637-b8d7-5882a149a8d0}]
"NameServer"=8.8.8.8,8.8.4.4
[HKLM\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{ee1c03f3-5321-4d3d-8fef-e87165c52fb6}]
"DhcpNameServer"=8.8.8.8 8.8.4.4
[HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{83e8d3d2-8a69-4637-b8d7-5882a149a8d0}]
"DhcpNameServer"=8.8.8.8 8.8.4.4
[HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{83e8d3d2-8a69-4637-b8d7-5882a149a8d0}]
"NameServer"=8.8.8.8,8.8.4.4
[HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{ee1c03f3-5321-4d3d-8fef-e87165c52fb6}]
"DhcpNameServer"=8.8.8.8 8.8.4.4

---------- | Applications

[HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\SOFTWARE\Classes\Applications\mpc-hc64.exe] : "C:\Program Files\MPC-HC\mpc-hc64.exe" "%1"
[HKLM\SOFTWARE\Classes\Applications\iexplore.exe] : "C:\Program Files\Internet Explorer\iexplore.exe" %1
[HKLM\SOFTWARE\Classes\Applications\MovieMaker.exe] : "C:\Program Files (x86)\Windows Live\Photo Gallery\MovieMaker.exe" "%1"
[HKLM\SOFTWARE\Classes\Applications\notepad.exe] : %SystemRoot%\system32\NOTEPAD.EXE %1
[HKLM\SOFTWARE\Classes\Applications\provtool.exe] : "%SystemRoot%\System32\provtool.exe" "%1" /source ShellOpen
[HKLM\SOFTWARE\Classes\Applications\WLXPhotoViewer.dll] : "C:\Program Files (x86)\Windows Live\Photo Gallery\WLXPhotoGallery.exe" /LaunchPhotoViewer /v "%1"
[HKLM\SOFTWARE\Classes\Applications\wmplayer.exe] : "%ProgramFiles(x86)%\Windows Media Player\wmplayer.exe" /Open "%L"
[HKLM\SOFTWARE\Classes\Applications\wordpad.exe] : "%ProgramFiles%\Windows NT\Accessories\WORDPAD.EXE" "%1"
[HKLM\SOFTWARE\WOW6432Node\Classes\Applications\iexplore.exe] : "C:\Program Files\Internet Explorer\iexplore.exe" %1
[HKLM\SOFTWARE\WOW6432Node\Classes\Applications\MovieMaker.exe] : "C:\Program Files (x86)\Windows Live\Photo Gallery\MovieMaker.exe" "%1"
[HKLM\SOFTWARE\WOW6432Node\Classes\Applications\notepad.exe] : %SystemRoot%\system32\NOTEPAD.EXE %1
[HKLM\SOFTWARE\WOW6432Node\Classes\Applications\provtool.exe] : "%SystemRoot%\System32\provtool.exe" "%1" /source ShellOpen
[HKLM\SOFTWARE\WOW6432Node\Classes\Applications\WLXPhotoViewer.dll] : "C:\Program Files (x86)\Windows Live\Photo Gallery\WLXPhotoGallery.exe" /LaunchPhotoViewer /v "%1"
[HKLM\SOFTWARE\WOW6432Node\Classes\Applications\wmplayer.exe] : "%ProgramFiles(x86)%\Windows Media Player\wmplayer.exe" /Open "%L"
[HKLM\SOFTWARE\WOW6432Node\Classes\Applications\wordpad.exe] : "%ProgramFiles%\Windows NT\Accessories\WORDPAD.EXE" "%1"

---------- | SvcHost (Whitelist)

[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost]
"DcomLaunch"=Power
LSM
BrokerInfrastructure
PlugPlay
DcomLaunch
DeviceInstall
SystemEventsBroker
"rdxgroup"=RetailDemo
"Camera"=FrameS
"DevicesFlow"=DevicesFlowUserSvc
"smbsvcs"=lanmanserver
browser
"PeerDist"=PeerDistSvc

[HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost]
"DcomLaunch"=PlugPlay
DcomLaunch
DeviceInstall
"smbsvcs"=lanmanserver


---------- | SvcHost - Netsvcs (Whitelist)


---------- | Software

[HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\Software\Adobe]
[HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\Software\AMD]
[HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\Software\AppDataLow]
[HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\Software\ATI]
[HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\Software\Blizzard Entertainment]
[HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\Software\BlueRippleSound]
[HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\Software\CD Projekt RED]
[HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\Software\Chromium]
[HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\Software\Crystal Dynamics]
[HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\Software\DirectShow]
[HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\Software\Dodge Roll]
[HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\Software\Epic Games]
[HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\Software\g3n-h@ckm@n]
[HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\Software\GOG.com]
[HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\Software\Google]
[HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\Software\IM Providers]
[HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\Software\LG Electronics]
[HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\Software\LowRegistry]
[HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\Software\Magix]
[HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\Software\Malwarebytes]
[HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\Software\Microsoft]
[HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\Software\MozillaPlugins]
[HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\Software\MPC-HC]
[HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\Software\MSI]
[HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\Software\Netscape]
[HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\Software\ODBC]
[HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\Software\paint.net]
[HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\Software\Policies]
[HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\Software\QtProject]
[HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\Software\RegisteredApplications]
[HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\Software\Sam Barlow]
[HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\Software\SAMSUNG]
[HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\Software\Samsung ]
[HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\Software\SeriousBit]
[HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\Software\Sony Creative Software]
[HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\Software\Spoon]
[HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\Software\SSPrint]
[HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\Software\sysinternals]
[HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\Software\Team Cherry]
[HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\Software\Terraria]
[HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\Software\The Creative Assembly]
[HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\Software\Trolltech]
[HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\Software\ubisoft]
[HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\Software\Unity]
[HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\Software\Unwinder]
[HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\Software\Valve]
[HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\Software\VIA]
[HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\Software\WinRAR]
[HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\Software\WinRAR SFX]
[HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\Software\Wondershare]
[HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\Software\Wow6432Node]
[HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\Software\zeckensack]
[HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\SOFTWARE\AppDataLow\Software\Microsoft]
[HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\Software\Microsoft\Windows\CurrentVersion]
[HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\Software\Microsoft\Windows\DWM]
[HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\Software\Microsoft\Windows\Roaming]
[HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\Software\Microsoft\Windows\Shell]
[HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\Software\Microsoft\Windows\TabletPC]
[HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\Software\Microsoft\Windows\Windows Error Reporting]
[HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\Software\Microsoft\Windows\Winlogon]
[HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\Software\Microsoft\Windows NT\CurrentVersion]
[HKLM\Software\AMD]
[HKLM\Software\ATI]
[HKLM\Software\ATI Technologies]
[HKLM\Software\Clients]
[HKLM\Software\g3n-h@ckm@n]
[HKLM\Software\Google]
[HKLM\Software\IM Providers]
[HKLM\Software\INextUUID]
[HKLM\Software\Intel]
[HKLM\Software\Khronos]
[HKLM\Software\Macromedia]
[HKLM\Software\Microsoft]
[HKLM\Software\MozillaPlugins]
[HKLM\Software\ODBC]
[HKLM\Software\OEM]
[HKLM\Software\paint.net]
[HKLM\Software\Partner]
[HKLM\Software\Policies]
[HKLM\Software\RegisteredApplications]
[HKLM\Software\Samsung]
[HKLM\Software\Sony Creative Software]
[HKLM\Software\SSPrint]
[HKLM\Software\SyncIntegrationClients]
[HKLM\Software\sysinternals]
[HKLM\Software\WinRAR]
[HKLM\Software\WOW6432Node]
[HKLM\Software\Microsoft\Windows\ClickNote]
[HKLM\Software\Microsoft\Windows\CurrentVersion]
[HKLM\Software\Microsoft\Windows\Dwm]
[HKLM\Software\Microsoft\Windows\DynamicManagement]
[HKLM\Software\Microsoft\Windows\EnterpriseResourceManager]
[HKLM\Software\Microsoft\Windows\Heat]
[HKLM\Software\Microsoft\Windows\Help]
[HKLM\Software\Microsoft\Windows\HTML Help]
[HKLM\Software\Microsoft\Windows\ITStorage]
[HKLM\Software\Microsoft\Windows\ScheduledDiagnostics]
[HKLM\Software\Microsoft\Windows\ScriptedDiagnosticsProvider]
[HKLM\Software\Microsoft\Windows\Shell]
[HKLM\Software\Microsoft\Windows\Tablet PC]
[HKLM\Software\Microsoft\Windows\TabletPC]
[HKLM\Software\Microsoft\Windows\Windows Error Reporting]
[HKLM\Software\Microsoft\Windows\Windows Search]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion]
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\appmodel]
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\Camera]
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\defragsvc]
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\DevicesFlow]
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\ICService]
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalService]
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceAndNoImpersonation]
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceHttp]
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceNetworkRestricted]
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceNetworkRestrictedDhcpLmHosts]
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceNoNetwork]
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceNoNetworkFirewall]
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalSystemNetworkRestricted]
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\netsvcs]
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\NetworkService]
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\NetworkServiceDnsNla]
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\NetworkServiceRemoteDesktopHyperVAgent]
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\NetworkServiceRemoteDesktopPublishing]
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\print]
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\rdxgroup]
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\SDRSVC]
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\swprv]
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\termsvcs]
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\UnistackSvcGroup]
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\utcsvc]
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\WepHostSvcGroup]
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\wercplsupport]
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\wsappx]
[HKLM\Software\WOW6432Node\Adobe]
[HKLM\Software\WOW6432Node\AGEIA Technologies]
[HKLM\Software\WOW6432Node\ATI]
[HKLM\Software\WOW6432Node\ATI Technologies]
[HKLM\Software\WOW6432Node\bethesda softworks]
[HKLM\Software\WOW6432Node\Blizzard Entertainment]
[HKLM\Software\WOW6432Node\BlueRippleSound]
[HKLM\Software\WOW6432Node\cd projekt red]
[HKLM\Software\WOW6432Node\CDDB]
[HKLM\Software\WOW6432Node\Epic Games]
[HKLM\Software\WOW6432Node\EpicGames]
[HKLM\Software\WOW6432Node\GOG.com]
[HKLM\Software\WOW6432Node\Google]
[HKLM\Software\WOW6432Node\Hasbro Interactive]
[HKLM\Software\WOW6432Node\InstallShield]
[HKLM\Software\WOW6432Node\Intel]
[HKLM\Software\WOW6432Node\Khronos]
[HKLM\Software\WOW6432Node\LG Electronics]
[HKLM\Software\WOW6432Node\Macromedia]
[HKLM\Software\WOW6432Node\Magix]
[HKLM\Software\WOW6432Node\Microsoft]
[HKLM\Software\WOW6432Node\MozillaPlugins]
[HKLM\Software\WOW6432Node\MSI]
[HKLM\Software\WOW6432Node\OBS Studio]
[HKLM\Software\WOW6432Node\ODBC]
[HKLM\Software\WOW6432Node\OpenAL]
[HKLM\Software\WOW6432Node\PowerPivot]
[HKLM\Software\WOW6432Node\qBittorrent]
[HKLM\Software\WOW6432Node\re-logic]
[HKLM\Software\WOW6432Node\REALTEK Semiconductor Corp.]
[HKLM\Software\WOW6432Node\rocksteadyltd]
[HKLM\Software\WOW6432Node\RtWLan]
[HKLM\Software\WOW6432Node\Samsung]
[HKLM\Software\WOW6432Node\Sony Creative Software]
[HKLM\Software\WOW6432Node\square enix limited]
[HKLM\Software\WOW6432Node\ubisoft]
[HKLM\Software\WOW6432Node\Unwinder]
[HKLM\Software\WOW6432Node\Valve]
[HKLM\Software\WOW6432Node\VIA Technologies, Inc]
[HKLM\Software\WOW6432Node\WafCX]
[HKLM\Software\WOW6432Node\WinPcap]
[HKLM\Software\WOW6432Node\Wondershare]
[HKLM\Software\WOW6432Node\xampp]
[HKLM\Software\WOW6432Node\Clients]
[HKLM\Software\WOW6432Node\Policies]
[HKLM\Software\WOW6432Node\RegisteredApplications]
[HKLM\Software\WOW6432Node\Microsoft\Windows\ClickNote]
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion]
[HKLM\Software\WOW6432Node\Microsoft\Windows\Dwm]
[HKLM\Software\WOW6432Node\Microsoft\Windows\EnterpriseResourceManager]
[HKLM\Software\WOW6432Node\Microsoft\Windows\Heat]
[HKLM\Software\WOW6432Node\Microsoft\Windows\HTML Help]
[HKLM\Software\WOW6432Node\Microsoft\Windows\ITStorage]
[HKLM\Software\WOW6432Node\Microsoft\Windows\ScriptedDiagnosticsProvider]
[HKLM\Software\WOW6432Node\Microsoft\Windows\Tablet PC]
[HKLM\Software\WOW6432Node\Microsoft\Windows\Windows Error Reporting]
[HKLM\Software\WOW6432Node\Microsoft\Windows\Windows Search]
[HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion]
[HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\appmodel]
[HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalService]
[HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceAndNoImpersonation]
[HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceHttp]
[HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceNetworkRestricted]
[HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceNetworkRestrictedDhcpLmHosts]
[HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceNoNetwork]
[HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceNoNetworkFirewall]
[HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalSystemNetworkRestricted]
[HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\netsvcs]
[HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\NetworkService]
[HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\NetworkServiceDnsNla]
[HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\NetworkServiceRemoteDesktopHyperVAgent]
[HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\NetworkServiceRemoteDesktopPublishing]
[HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\termsvcs]

---------- | Drives


D:

[07/11/2007 09:03:18] - |A| - (.(C) Microsoft Corporation. - UI Wrapper Resource DLL.) - [76304] - (9.0.21022.8) - D:\install.res.1028.dll
[07/11/2007 09:03:18] - |A| - (.© Microsoft Corporation. Alle Rechte vorbehalten. - Ressourcen-DLL für UI-Wrapper.) - [96272] - (9.0.21022.8) - D:\install.res.1031.dll
[07/11/2007 09:03:18] - |A| - (.© Microsoft Corporation. - UI Wrapper Resource DLL.) - [91152] - (9.0.21022.8) - D:\install.res.1033.dll
[07/11/2007 09:03:18] - |A| - (.© Microsoft Corporation. Tous droits réservés. - UI Wrapper Resource DLL.) - [97296] - (9.0.21022.8) - D:\install.res.1036.dll
[07/11/2007 09:03:18] - |A| - (.© Microsoft Corporation. Tutti i diritti riservati. - DLL di risorse del wrapper dell'interfaccia utente.) - [95248] - (9.0.21022.8) - D:\install.res.1040.dll
[07/11/2007 09:03:18] - |A| - (.(C) Copyright Microsoft Corporation. - UI Wrapper Resource DLL.) - [81424] - (9.0.21022.8) - D:\install.res.1041.dll
[07/11/2007 09:03:18] - |A| - (.(C) Microsoft Corporation. - UI 래퍼 리소스 DLL.) - [79888] - (9.0.21022.8) - D:\install.res.1042.dll
[07/11/2007 09:03:18] - |A| - (.(C) Microsoft Corporation。保留所有权利。 - 用户界面包装资源 DLL.) - [75792] - (9.0.21022.8) - D:\install.res.2052.dll
[07/11/2007 09:03:18] - |A| - (.© Microsoft Corporation. Reservados todos los derechos. - Archivo DLL de recursos del contenedor de la interfaz de usuario.) - [96272] - (9.0.21022.8) - D:\install.res.3082.dll
[01/12/2006 23:37:14] - |A| - (.© Microsoft Corporation. - Microsoft® Debug Information Accessor.) - [904704] - (8.0.50727.762) - D:\msdia80.dll
[07/11/2007 09:03:18] - |A| - (.© Microsoft Corporation. - External Installer.) - [562688] - (9.0.21022.8) - D:\install.exe
[07/11/2007 09:00:40] - |A| - (.-.) - [1110] - (0.0.0.0) - D:\globdata.ini
[07/11/2007 09:00:40] - |A| - (.-.) - [843] - (0.0.0.0) - D:\install.ini

---------- | C:

[18/03/2017 23:03:28] - |SHD| - [433975] - C:\$Recycle.Bin
[01/05/2019 11:12:55] - |HD| - [163475813] - C:\$WINDOWS.~BT
[26/09/2017 16:31:14] - |D| - [2439773924] - C:\Adobe Photoshop CC15.2+CamR.9+Bridge6.1.Por.[NAMP14.05.2015]ita
[14/07/2017 18:06:33] - |D| - [5657680] - C:\AdwCleaner
[05/07/2017 18:48:23] - |D| - [1613960847] - C:\AMD
[MD5.F3B25701FE362EC84616A93A45CE9998] - [20/04/2019 12:31:50] - |A| - (.-.) - [2] - (0.0.0.0) - C:\AMFTrace.log
[05/07/2017 19:21:39] - |SHD| - [18499608] - C:\Boot
[MD5.91072B86EA8CB149C3CA9772A2E5B4EE] - [05/07/2017 19:21:39] - |RASH| - (.-.) - [394984] - (0.0.0.0) - C:\bootmgr
[MD5.93B885ADFE0DA089CDF634904FD59F71] - [05/07/2017 19:21:40] - |ASH| - (.-.) - [1] - (0.0.0.0) - C:\BOOTNXT
[MD5.BCB0D79B3EA44D3A32F5C8A50262DDAD] - [05/07/2017 19:21:41] - |RASH| - (.-.) - [8192] - (0.0.0.0) - C:\BOOTSECT.BAK
[04/09/2017 18:52:47] - |SHD| - [7171784] - C:\Config.Msi
[05/07/2017 18:25:40] - |SHD| - [0] - C:\Documents and Settings
[05/08/2017 16:25:16] - |D| - [217133345] - C:\GOG Games
[MD5.D41D8CD98F00B204E9800998ECF8427E] - [05/07/2017 18:25:23] - |ASH| - (.-.) - [3418103808] - (0.0.0.0) - C:\hiberfil.sys
[MD5.3DFE61A16E9D2FE6CACD6FCCF1154514] - [18/05/2018 16:12:34] - |A| - (.-.) - [730] - (0.0.0.0) - C:\host.xml
[17/09/2018 14:27:25] - |D| - [470517868] - C:\MAGIXVEGASPro15
[05/07/2017 23:23:26] - |RHD| - [1172522447] - C:\MSOCache
[MD5.D41D8CD98F00B204E9800998ECF8427E] - [05/07/2017 18:22:19] - |ASH| - (.-.) - [1342177280] - (0.0.0.0) - C:\pagefile.sys
[18/03/2017 23:03:28] - |D| - [0] - C:\PerfLogs
[18/03/2017 23:03:28] - |RD| - [7304714054] - C:\Program Files
[18/03/2017 23:03:28] - |RD| - [4765617548] - C:\Program Files (x86)
[18/03/2017 23:03:29] - |HD| - [2297336728] - C:\ProgramData
[05/07/2017 18:25:40] - |SHD| - [0] - C:\Programmi
[14/07/2019 09:55:27] - |D| - [208473] - C:\QuickDiag
[MD5.C2FCB7F890144C9A29878FE94AA4705A] - [14/07/2019 10:07:25] - |A| - (.-.) - [176181] - (0.0.0.0) - C:\QuickDiag.txt
[MD5.CF3E63888AB858E3287E82367092B1D1] - [14/07/2019 10:05:35] - |RAST| - (.-.) - [126466] - (0.0.0.0) - C:\QuickDiag_14_07_2019_10_05_35.txt
[05/07/2017 18:24:37] - |SHD| - [359789596] - C:\Recovery
[MD5.E0DCF21CC0F023FBEDD797BDF86FEF9A] - [18/05/2018 16:12:34] - |A| - (.-.) - [10992] - (0.0.0.0) - C:\SM.xml
[MD5.D41D8CD98F00B204E9800998ECF8427E] - [05/07/2017 18:22:19] - |ASH| - (.-.) - [268435456] - (0.0.0.0) - C:\swapfile.sys
[05/07/2017 18:22:17] - |SHD| - [0] - C:\System Volume Information
[07/08/2018 13:48:15] - |D| - [432728] - C:\Testare microsd
[18/03/2017 13:40:20] - |RD| - [246611552860] - C:\Users
[18/03/2017 13:40:20] - |D| - [50677898716] - C:\Windows
[04/02/2019 23:08:36] - |D| - [788629950] - C:\xampp

---------- | C:\Windows

[18/03/2017 23:03:29] - |D| - [802] - C:\Windows\addins
[18/03/2017 23:03:29] - |D| - [11147749] - C:\Windows\appcompat
[18/03/2017 23:03:29] - |D| - [12490488] - C:\Windows\AppPatch
[18/03/2017 23:03:29] - |D| - [0] - C:\Windows\AppReadiness
[18/03/2017 23:03:28] - |RSD| - [1107618811] - C:\Windows\assembly
[06/07/2017 14:47:15] - |D| - [6781696] - C:\Windows\AutoKMS
[18/03/2017 23:03:29] - |D| - [639657] - C:\Windows\bcastdvr
[MD5.AF776BE7C8AA682173A472094BB1CC6F] - [25/07/2018 19:50:49] - |A| - (.© Microsoft Corporation. Tutti i diritti riservati. - Utilità di servizio file di avvio.) - [64512] - (10.0.15063.1112) - C:\Windows\bfsvc.exe
[20/03/2017 06:07:27] - |SHD| - [581203] - C:\Windows\BitLockerDiscoveryVolumeContents
[18/03/2017 23:03:29] - |D| - [38063782] - C:\Windows\Boot
[MD5.7C8F6BDEAF81D67F8548254BB359B332] - [05/07/2017 18:23:04] - |AS| - (.-.) - [67584] - (0.0.0.0) - C:\Windows\bootstat.dat
[18/03/2017 23:03:29] - |D| - [2447448] - C:\Windows\Branding
[18/03/2017 22:51:24] - |D| - [0] - C:\Windows\CbsTemp
[05/07/2017 18:27:10] - |D| - [0] - C:\Windows\CSC
[18/03/2017 23:03:29] - |D| - [8970858] - C:\Windows\Cursors
[18/03/2017 23:03:29] - |D| - [27855] - C:\Windows\debug
[18/03/2017 23:03:29] - |D| - [4449558] - C:\Windows\diagnostics
[MD5.0E21133A8CD4C1220961DD9ABD3CDF91] - [05/08/2017 19:41:58] - |N| - (.© Microsoft Corporation. - Driver Install Frameworks for API library module.) - [414632] - (2.0.1.0) - C:\Windows\difxapi.dll
[20/03/2017 06:06:15] - |D| - [0] - C:\Windows\DigitalLocker
[MD5.5D45E95BF841020272080CB6C4D6F620] - [04/08/2017 12:13:15] - |A| - (.-.) - [132349] - (0.0.0.0) - C:\Windows\DirectX.log
[18/03/2017 23:03:29] - |SD| - [65] - C:\Windows\Downloaded Program Files
[MD5.94F6CE419762595A8923791B721A13DA] - [18/03/2017 23:05:44] - |A| - (.-.) - [2595] - (0.0.0.0) - C:\Windows\DtcInstall.log
[18/03/2017 23:03:29] - |HD| - [65568] - C:\Windows\ELAMBKUP
[20/03/2017 06:06:15] - |D| - [0] - C:\Windows\en-US
[MD5.D2AF87B360DB77E076881938C91FA276] - [10/08/2018 16:14:32] - |A| - (.© Microsoft Corporation. Tutti i diritti riservati. - Esplora risorse.) - [4848952] - (10.0.15063.1206) - C:\Windows\explorer.exe
[18/03/2017 23:03:29] - |RSD| - [376309904] - C:\Windows\Fonts
[18/03/2017 23:03:29] - |D| - [0] - C:\Windows\GameBarPresenceWriter
[18/03/2017 23:03:29] - |D| - [46953607] - C:\Windows\Globalization
[18/03/2017 23:03:29] - |D| - [1593607] - C:\Windows\Help
[MD5.591202C71052A230CD7C60141FAAA072] - [15/06/2018 18:00:49] - |A| - (.© Microsoft Corporation. Tutti i diritti riservati. - Guida e supporto tecnico Microsoft.) - [975872] - (10.0.15063.1058) - C:\Windows\HelpPane.exe
[MD5.40CBB6FF53388188A2CDA538D5F26A59] - [18/03/2017 22:57:33] - |A| - (.© Microsoft Corporation. Tutti i diritti riservati. - Eseguibile di Guida HTML Microsoft®.) - [18432] - (10.0.15063.0) - C:\Windows\hh.exe
[20/03/2017 06:07:27] - |D| - [14071050] - C:\Windows\HoloShell
[18/03/2017 23:03:29] - |D| - [173056368] - C:\Windows\IME
[18/03/2017 23:03:29] - |RD| - [8336352] - C:\Windows\ImmersiveControlPanel
[18/03/2017 23:01:21] - |D| - [56738264] - C:\Windows\INF
[18/03/2017 23:03:29] - |D| - [1169806390] - C:\Windows\InfusedApps
[18/03/2017 23:03:29] - |D| - [38340109] - C:\Windows\InputMethod
[18/03/2017 23:03:29] - |SHD| - [17873457904] - C:\Windows\Installer
[23/09/2017 15:34:28] - |D| - [116928] - C:\Windows\it
[20/03/2017 06:06:15] - |D| - [106496] - C:\Windows\it-IT
[18/03/2017 23:03:29] - |D| - [94096] - C:\Windows\L2Schemas
[18/03/2017 23:03:29] - |D| - [1587491404] - C:\Windows\LiveKernelReports
[18/03/2017 13:40:24] - |D| - [110382365] - C:\Windows\Logs
[MD5.72CFC8B7EDE5CD643ED1369574692CA3] - [05/07/2017 18:22:24] - |A| - (.-.) - [1344] - (0.0.0.0) - C:\Windows\lsasetup.log
[18/03/2017 23:03:29] - |RSD| - [20316123] - C:\Windows\Media
[MD5.DE845B545E0A829B81BE018DB3C59862] - [19/10/2017 19:45:35] - |A| - (.-.) - [647024686] - (0.0.0.0) - C:\Windows\MEMORY.DMP
[MD5.23AF90D2355D8C83AA4567EF1763B467] - [18/03/2017 22:57:03] - |A| - (.-.) - [43131] - (0.0.0.0) - C:\Windows\mib.bin
[06/10/2017 18:56:01] - |D| - [114646418] - C:\Windows\Microsoft Antimalware
[18/03/2017 23:03:28] - |RD| - [835589304] - C:\Windows\Microsoft.NET
[18/03/2017 23:03:29] - |D| - [3293] - C:\Windows\Migration
[19/10/2017 19:45:39] - |D| - [2304596] - C:\Windows\Minidump
[18/03/2017 23:03:29] - |RD| - [487312] - C:\Windows\MiracastView
[18/03/2017 23:03:29] - |D| - [0] - C:\Windows\ModemLogs
[MD5.F60A9D3A9461F68DE0FCCEBB0C6CB31A] - [18/03/2017 22:58:25] - |A| - (.© Microsoft Corporation. Tutti i diritti riservati. - Blocco note.) - [246784] - (10.0.15063.0) - C:\Windows\notepad.exe
[20/03/2017 06:06:56] - |D| - [228848] - C:\Windows\OCR
[18/03/2017 23:03:29] - |RD| - [65] - C:\Windows\Offline Web Pages
[05/07/2017 19:21:52] - |D| - [12034216] - C:\Windows\Panther
[05/07/2017 23:24:37] - |D| - [0] - C:\Windows\PCHEALTH
[18/03/2017 23:03:29] - |D| - [29526715] - C:\Windows\Performance
[MD5.8517D40B6B82E08F82ACC066C306D481] - [06/07/2017 15:06:53] - |A| - (.-.) - [99526] - (0.0.0.0) - C:\Windows\PFRO.log
[18/03/2017 23:03:29] - |D| - [1129165] - C:\Windows\PLA
[18/03/2017 23:03:29] - |D| - [6823761] - C:\Windows\PolicyDefinitions
[05/07/2017 18:22:40] - |D| - [24724475] - C:\Windows\Prefetch
[18/03/2017 23:03:29] - |RD| - [2168604] - C:\Windows\PrintDialog
[MD5.ED055B221E70C084FF205EBCD1124A08] - [20/03/2017 06:07:45] - |A| - (.-.) - [34774] - (0.0.0.0) - C:\Windows\Professional.xml
[18/03/2017 23:03:29] - |D| - [2879892] - C:\Windows\Provisioning
[MD5.A3B1FC6C72EA944C2E1B359A19CB40AB] - [18/03/2017 22:57:08] - |A| - (.© Microsoft Corporation. Tutti i diritti riservati. - Editor del Registro di sistema.) - [321024] - (10.0.15063.0) - C:\Windows\regedit.exe
[18/03/2017 23:03:29] - |D| - [1071164] - C:\Windows\Registration
[20/03/2017 06:07:27] - |D| - [0] - C:\Windows\RemotePackages
[18/03/2017 23:03:29] - |D| - [17496895] - C:\Windows\rescache
[18/03/2017 23:03:29] - |D| - [3660232] - C:\Windows\Resources
[MD5.DA256F9F53336B560201CDEFEAE35320] - [25/12/2018 13:12:31] - |A| - (.2008: (c) Realtek. - CCX Diagnostics.) - [380928] - (700.1002.311.2009) - C:\Windows\RtlUI2.exe
[MD5.678C7EA24776534FF6DDF491A4F86005] - [25/12/2018 13:12:31] - |A| - (.-.) - [901] - (0.0.0.0) - C:\Windows\RtlUI2.exe.manifest
[18/03/2017 23:03:29] - |D| - [0] - C:\Windows\SchCache
[18/03/2017 23:03:29] - |D| - [142904] - C:\Windows\schemas
[18/03/2017 23:03:29] - |D| - [5351573] - C:\Windows\security
[05/07/2017 18:22:25] - |D| - [91608461] - C:\Windows\ServiceProfiles
[18/03/2017 13:40:20] - |D| - [311829500] - C:\Windows\servicing
[18/03/2017 23:06:43] - |D| - [42] - C:\Windows\Setup
[MD5.C961B3CEAF0F791593D6D923E29A3F0D] - [05/07/2017 18:22:48] - |A| - (.-.) - [61111] - (0.0.0.0) - C:\Windows\setupact.log
[MD5.39B6ABE63409061C66189F4715A15B8F] - [05/07/2017 18:22:48] - |A| - (.-.) - [102] - (0.0.0.0) - C:\Windows\setuperr.log
[MD5.13DE8A3E20CA586E76467B1AF4EADB5A] - [05/08/2017 19:42:15] - |A| - (.-.) - [24] - (0.0.0.0) - C:\Windows\SetupTemp.ini
[18/03/2017 23:03:29] - |D| - [41924608] - C:\Windows\ShellExperiences
[05/07/2017 23:23:47] - |D| - [66025] - C:\Windows\SHELLNEW
[20/03/2017 06:06:47] - |D| - [1311536] - C:\Windows\SKB
[05/07/2017 18:26:26] - |D| - [7003904986] - C:\Windows\SoftwareDistribution
[18/03/2017 23:03:29] - |D| - [15504633] - C:\Windows\Speech
[18/03/2017 23:03:29] - |D| - [52672346] - C:\Windows\Speech_OneCore
[MD5.636EFCA1E43AAA111587618477D41D0E] - [30/04/2018 21:23:33] - |A| - (.© Microsoft Corporation. - Print driver host for applications.) - [130560] - (10.0.15063.850) - C:\Windows\splwow64.exe
[MD5.CEDF9BF9B4547771AA57C19309BFFD93] - [18/05/2018 16:08:27] - |N| - (.-.) - [147249] - (0.0.0.0) - C:\Windows\ssj1mA4.prn
[MD5.419F845E872D64613C3B7E58453479D3] - [18/05/2018 16:08:27] - |N| - (.-.) - [158425] - (0.0.0.0) - C:\Windows\ssj1mLTR.prn
[18/03/2017 23:03:29] - |D| - [31039] - C:\Windows\System
[MD5.286A9EDB379DC3423A528B0864A0F111] - [18/03/2017 23:03:33] - |A| - (.-.) - [219] - (0.0.0.0) - C:\Windows\system.ini
[18/03/2017 13:40:20] - |D| - [6546185586] - C:\Windows\System32
[18/03/2017 23:03:29] - |D| - [191499612] - C:\Windows\SystemApps
[18/03/2017 23:03:29] - |D| - [19432735] - C:\Windows\SystemResources
[18/03/2017 13:40:24] - |D| - [1436720175] - C:\Windows\SysWOW64
[18/03/2017 23:03:29] - |D| - [0] - C:\Windows\TAPI
[18/03/2017 23:03:29] - |D| - [6] - C:\Windows\Tasks
[18/03/2017 23:03:29] - |D| - [3378876606] - C:\Windows\Temp
[18/03/2017 23:03:29] - |D| - [0] - C:\Windows\tracing
[18/03/2017 23:03:29] - |D| - [7680] - C:\Windows\twain_32
[MD5.C0792EA1BA08CA6E6420C9BB8E14CB3E] - [18/03/2017 22:58:54] - |A| - (.- Twain_32 Source Manager (Image Acquisition Interface).) - [65536] - (1.7.1.3) - C:\Windows\twain_32.dll
[09/03/2018 22:50:59] - |D| - [6946332] - C:\Windows\UpdateAssistant
[12/01/2018 01:14:10] - |SD| - [6266272] - C:\Windows\UpdateAssistantV2
[18/03/2017 23:03:29] - |D| - [12420] - C:\Windows\Vss
[18/03/2017 23:03:30] - |D| - [15729830] - C:\Windows\Web
[MD5.DAA6AAD525D12F8985695B882301336F] - [18/03/2017 23:03:33] - |A| - (.-.) - [167] - (0.0.0.0) - C:\Windows\win.ini
[MD5.C844CA459F3B209329984772269B6E56] - [18/03/2017 22:58:27] - |RAH| - (.-.) - [670] - (0.0.0.0) - C:\Windows\WindowsShell.Manifest
[MD5.038356387332650843BCB352BB89A101] - [05/07/2017 18:26:26] - |A| - (.-.) - [275] - (0.0.0.0) - C:\Windows\WindowsUpdate.log
[MD5.6E6947D6368FA11E9146C4767F31286E] - [18/03/2017 22:58:42] - |A| - (.© Microsoft Corporation. Tutti i diritti riservati. - Stub di Windows Winhlp32.) - [10240] - (10.0.15063.0) - C:\Windows\winhlp32.exe
[18/03/2017 13:40:20] - |D| - [7170739591] - C:\Windows\WinSxS
[MD5.907AE50A03DEEC4CFFDC70EA3D5AD4D8] - [31/03/2014 21:34:22] - |A| - (.© 2012 Microsoft Corporation. Tutti i diritti riservati. - Screen saver di Raccolta foto.) - [322248] - (16.4.3528.331) - C:\Windows\WLXPGSS.SCR
[MD5.E7E4D8D7340DA6934B9EA81CBB21374C] - [18/03/2017 22:56:51] - |A| - (.-.) - [316640] - (0.0.0.0) - C:\Windows\WMSysPr9.prx
[MD5.ECEB16331FDDE0EBD7BE30BE085AD3D9] - [18/03/2017 22:58:25] - |A| - (.© Microsoft Corporation. - Windows Write.) - [11264] - (10.0.15063.0) - C:\Windows\write.exe

---------- | C:\Windows\System32\GroupPolicy


---------- | Systemroot\System


---------- | Systemroot\Installer (Microsoft Files Whitelisted)

[05/01/2019 18:06:39] - C:\Windows\Installer\1061209.msi : (TP-Link PLC Utility - TP-Link)          [Offsets ok ! : D0CF11E0A1B11AE10000000000000000]
[17/08/2016 17:46:44] - C:\Windows\Installer\119261.msi : (VIA Universal Setup Program - VIA Technologies, Inc.)          [Offsets ok ! : D0CF11E0A1B11AE10000000000000000]
[17/03/2015 10:41:34] - C:\Windows\Installer\1425e0.msi : ( - Adobe Systems Incorporated)          [Offsets ok ! : D0CF11E0A1B11AE10000000000000000]
[25/04/2017 03:42:18] - C:\Windows\Installer\156ce5.msi : (Catalyst Control Center Next - Advanced Micro Devices, Inc.)          [Offsets ok ! : D0CF11E0A1B11AE10000000000000000]
[25/04/2017 03:42:46] - C:\Windows\Installer\156cea.msi : (Catalyst Control Center Next - Advanced Micro Devices, Inc.)          [Offsets ok ! : D0CF11E0A1B11AE10000000000000000]
[25/04/2017 03:43:16] - C:\Windows\Installer\156cef.msi : (Catalyst Control Center Next - Advanced Micro Devices, Inc.)          [Offsets ok ! : D0CF11E0A1B11AE10000000000000000]
[25/04/2017 03:43:44] - C:\Windows\Installer\156cf4.msi : (Catalyst Control Center Next - Advanced Micro Devices, Inc.)          [Offsets ok ! : D0CF11E0A1B11AE10000000000000000]
[25/04/2017 03:44:14] - C:\Windows\Installer\156cf9.msi : (Catalyst Control Center Next - Advanced Micro Devices, Inc.)          [Offsets ok ! : D0CF11E0A1B11AE10000000000000000]
[25/04/2017 03:44:42] - C:\Windows\Installer\156cfe.msi : (Catalyst Control Center next - Advanced Micro Devices, Inc.)          [Offsets ok ! : D0CF11E0A1B11AE10000000000000000]
[25/04/2017 03:45:10] - C:\Windows\Installer\156d03.msi : (Catalyst Control Center Next - Advanced Micro Devices, Inc.)          [Offsets ok ! : D0CF11E0A1B11AE10000000000000000]
[25/04/2017 03:45:38] - C:\Windows\Installer\156d08.msi : (Catalyst Control Center Next - Advanced Micro Devices, Inc.)          [Offsets ok ! : D0CF11E0A1B11AE10000000000000000]
[25/04/2017 03:46:06] - C:\Windows\Installer\156d0d.msi : (Catalyst Control Center Next - Advanced Micro Devices, Inc.)          [Offsets ok ! : D0CF11E0A1B11AE10000000000000000]
[25/04/2017 03:46:36] - C:\Windows\Installer\156d12.msi : (Catalyst Control Center Next - Advanced Micro Devices, Inc.)          [Offsets ok ! : D0CF11E0A1B11AE10000000000000000]
[25/04/2017 03:47:04] - C:\Windows\Installer\156d17.msi : (Catalyst Control Center Next - Advanced Micro Devices, Inc.)          [Offsets ok ! : D0CF11E0A1B11AE10000000000000000]
[25/04/2017 03:47:34] - C:\Windows\Installer\156d1c.msi : (Catalyst Control Center Next - Advanced Micro Devices, Inc.)          [Offsets ok ! : D0CF11E0A1B11AE10000000000000000]
[25/04/2017 03:48:04] - C:\Windows\Installer\156d21.msi : (Catalyst Control Center Next - Advanced Micro Devices, Inc.)          [Offsets ok ! : D0CF11E0A1B11AE10000000000000000]
[25/04/2017 03:48:32] - C:\Windows\Installer\156d26.msi : (Catalyst Control Center Next - Advanced Micro Devices, Inc.)          [Offsets ok ! : D0CF11E0A1B11AE10000000000000000]
[25/04/2017 03:49:02] - C:\Windows\Installer\156d2b.msi : (Catalyst Control Center Next - Advanced Micro Devices, Inc.)          [Offsets ok ! : D0CF11E0A1B11AE10000000000000000]
[25/04/2017 03:49:30] - C:\Windows\Installer\156d30.msi : (Catalyst Control Center Next - Advanced Micro Devices, Inc.)          [Offsets ok ! : D0CF11E0A1B11AE10000000000000000]
[25/04/2017 03:50:00] - C:\Windows\Installer\156d35.msi : (Catalyst Control Center Next - Advanced Micro Devices, Inc.)          [Offsets ok ! : D0CF11E0A1B11AE10000000000000000]
[25/04/2017 03:50:32] - C:\Windows\Installer\156d3a.msi : (Catalyst Control Center Next - Advanced Micro Devices, Inc.)          [Offsets ok ! : D0CF11E0A1B11AE10000000000000000]
[25/04/2017 03:51:02] - C:\Windows\Installer\156d3f.msi : (Catalyst Control Center Next - Advanced Micro Devices, Inc.)          [Offsets ok ! : D0CF11E0A1B11AE10000000000000000]
[25/04/2017 03:51:30] - C:\Windows\Installer\156d44.msi : (Catalyst Control Center Next - Advanced Micro Devices, Inc.)          [Offsets ok ! : D0CF11E0A1B11AE10000000000000000]
[25/04/2017 03:51:58] - C:\Windows\Installer\156d49.msi : (Catalyst Control Center Next - Advanced Micro Devices, Inc.)          [Offsets ok ! : D0CF11E0A1B11AE10000000000000000]
[05/12/2018 02:12:40] - C:\Windows\Installer\1a67426.msi : ( - dotPDN LLC)          [Offsets ok ! : D0CF11E0A1B11AE10000000000000000]
[25/04/2017 03:44:14] - C:\Windows\Installer\1b729.msi : (AMD Settings - Advanced Micro Devices, Inc.)          [Offsets ok ! : D0CF11E0A1B11AE10000000000000000]
[25/04/2017 03:48:28] - C:\Windows\Installer\1b72e.msi : (AMD Settings - Advanced Micro Devices, Inc.)          [Offsets ok ! : D0CF11E0A1B11AE10000000000000000]
[23/05/2017 14:15:32] - C:\Windows\Installer\307e5.msi : ( - Nokia)          [Offsets ok ! : D0CF11E0A1B11AE10000000000000000]
[15/05/2019 14:23:48] - C:\Windows\Installer\58be2.msi : (Google Update Helper - Google LLC)          [Offsets ok ! : D0CF11E0A1B11AE10000000000000000]
[18/10/2018 20:47:15] - C:\Windows\Installer\77dcb.msi : (Smart View - Samsung)          [Offsets ok ! : D0CF11E0A1B11AE10000000000000000]
[26/07/2017 21:19:02] - C:\Windows\Installer\9382a.msi : (AMD Software (64 bit) - Advanced Micro Devices, Inc.)          [Offsets ok ! : D0CF11E0A1B11AE10000000000000000]
[27/02/2018 23:39:34] - C:\Windows\Installer\94eebf.msi : (Install/UnInstall PhysX Driver + Engines: 2.3.1/2/3; 2.4.0/1/4; 2.5.0/1/2/3/4; 2.6.0/1/2/3/4; 2.7.0/1/2/3/4/5/6; 2.8.0/1 - NVIDIA Corporation)          [Offsets ok ! : D0CF11E0A1B11AE10000000000000000]
[13/08/2017 03:34:54] - C:\Windows\Installer\a47e6d.msi : (MSVCRT Redists - MAGIX Computer Products Intl. Co.)          [Offsets ok ! : D0CF11E0A1B11AE10000000000000000]
[17/09/2018 19:22:10] - C:\Windows\Installer\a47e72.msi : (VEGAS Pro 15.0 - VEGAS)          [Offsets ok ! : D0CF11E0A1B11AE10000000000000000]
[13/02/2019 21:03:36] - C:\Windows\Installer\a8ad4.msi : (Adobe ARM Installer - Adobe Systems Incorporated)          [Offsets ok ! : D0CF11E0A1B11AE10000000000000000]
[28/02/2018 00:15:11] - C:\Windows\Installer\b700c3.msi : (Epic Games Launcher - Epic Games, Inc.)          [Offsets ok ! : D0CF11E0A1B11AE10000000000000000]
[19/11/2015 11:56:58] - C:\Windows\Installer\b700c8.msi : (Epic Games Launcher Prerequisites (x64) - Epic Games, Inc.)          [Offsets ok ! : D0CF11E0A1B11AE10000000000000000]
[06/11/2014 06:45:18] - C:\Windows\Installer\e6b597.msi : (LG United Mobile Drivers - LG Electronics)          [Offsets ok ! : D0CF11E0A1B11AE10000000000000000]
[18/01/2018 12:34:50] - [6074368] - (.().-. - ()) - C:\Windows\Installer\10200ec.msp
[13/05/2019 08:57:34] - [59400192] - (.().-. - ()) - C:\Windows\Installer\107c3a0.msp
[13/08/2018 08:19:45] - [1441792] - (.().-. - ()) - C:\Windows\Installer\11a03d.msp
[18/01/2018 12:24:42] - [4894720] - (.().-. - ()) - C:\Windows\Installer\122d872.msp
[14/02/2018 23:30:16] - [37269504] - (.().-. - ()) - C:\Windows\Installer\1252b1.msp
[17/04/2019 21:50:54] - [3919872] - (.().-. - ()) - C:\Windows\Installer\12fe7f3.msp
[17/04/2019 22:06:06] - [49782784] - (.().-. - ()) - C:\Windows\Installer\12fe7f9.msp
[18/01/2018 12:36:04] - [31596544] - (.().-. - ()) - C:\Windows\Installer\1356a78.msp
[18/01/2018 12:36:10] - [37158912] - (.().-. - ()) - C:\Windows\Installer\1356aa1.msp
[28/06/2011 21:27:28] - [4028928] - (.().-. - ()) - C:\Windows\Installer\139c8f5.msp
[28/06/2011 21:21:32] - [4637184] - (.().-. - ()) - C:\Windows\Installer\13ab6de.msp
[15/11/2018 00:20:32] - [99041280] - (.().-. - ()) - C:\Windows\Installer\13caa2e.msp
[22/07/2018 16:05:24] - [84144128] - (.().-. - ()) - C:\Windows\Installer\13d67e0.msp
[22/07/2018 16:15:56] - [31600640] - (.().-. - ()) - C:\Windows\Installer\13d6815.msp
[22/07/2018 16:16:54] - [37339136] - (.().-. - ()) - C:\Windows\Installer\13d683f.msp
[22/07/2018 16:14:48] - [41574400] - (.().-. - ()) - C:\Windows\Installer\13d684c.msp
[22/07/2018 16:04:44] - [4894720] - (.().-. - ()) - C:\Windows\Installer\13d688c.msp
[22/07/2018 16:13:20] - [98992128] - (.().-. - ()) - C:\Windows\Installer\13d6894.msp
[22/07/2018 16:19:42] - [49643520] - (.().-. - ()) - C:\Windows\Installer\13d68cf.msp
[16/08/2017 09:33:52] - [25968640] - (.().-. - ()) - C:\Windows\Installer\14134ea.msp
[16/08/2017 09:44:30] - [31535104] - (.().-. - ()) - C:\Windows\Installer\1413501.msp
[16/08/2017 09:43:26] - [12054528] - (.().-. - ()) - C:\Windows\Installer\141352e.msp
[12/12/2018 10:59:22] - [3330048] - (.().-. - ()) - C:\Windows\Installer\14477e.msp
[23/12/2018 13:10:34] - [99041280] - (.().-. - ()) - C:\Windows\Installer\144785.msp
[12/12/2018 11:08:38] - [12103680] - (.().-. - ()) - C:\Windows\Installer\1447c1.msp
[12/12/2018 11:09:20] - [2945024] - (.().-. - ()) - C:\Windows\Installer\1447e0.msp
[12/12/2018 11:09:56] - [6111232] - (.().-. - ()) - C:\Windows\Installer\1447fe.msp
[12/12/2018 11:11:44] - [37302272] - (.().-. - ()) - C:\Windows\Installer\14482d.msp
[13/11/2018 06:24:12] - [3485696] - (.().-. - ()) - C:\Windows\Installer\144cdb.msp
[12/07/2017 11:10:12] - [84115456] - (.().-. - ()) - C:\Windows\Installer\152cacb.msp
[16/08/2017 09:43:28] - [12271616] - (.().-. - ()) - C:\Windows\Installer\152cb16.msp
[08/04/2019 08:22:42] - [7155712] - (.().-. - ()) - C:\Windows\Installer\15de49.msp
[14/03/2018 18:36:32] - [98914304] - (.().-. - ()) - C:\Windows\Installer\169cb6.msp
[14/03/2018 18:39:52] - [37294080] - (.().-. - ()) - C:\Windows\Installer\169d19.msp
[14/03/2018 18:36:34] - [4079616] - (.().-. - ()) - C:\Windows\Installer\169d26.msp
[14/03/2018 18:38:54] - [31604736] - (.().-. - ()) - C:\Windows\Installer\169d52.msp
[14/03/2018 18:37:58] - [6090752] - (.().-. - ()) - C:\Windows\Installer\169d7d.msp
[11/02/2019 08:36:53] - [8757248] - (.().-. - ()) - C:\Windows\Installer\16d538.msp
[12/12/2018 11:14:14] - [69316608] - (.().-. - ()) - C:\Windows\Installer\192dd1.msp
[25/05/2019 08:04:26] - [99254272] - (.().-. - ()) - C:\Windows\Installer\1b43033.msp
[16/05/2019 08:52:48] - [37376000] - (.().-. - ()) - C:\Windows\Installer\1b43098.msp
[19/12/2018 17:12:50] - [49598464] - (.().-. - ()) - C:\Windows\Installer\1d598b3.msp
[12/12/2018 11:08:38] - [700416] - (.().-. - ()) - C:\Windows\Installer\1d598f6.msp
[13/02/2019 09:58:38] - [4870144] - (.().-. - ()) - C:\Windows\Installer\1db0f.msp
[17/05/2018 11:22:46] - [37298176] - (.().-. - ()) - C:\Windows\Installer\244764a.msp
[17/05/2018 11:20:40] - [41521152] - (.().-. - ()) - C:\Windows\Installer\2447658.msp
[17/05/2018 11:20:42] - [6103040] - (.().-. - ()) - C:\Windows\Installer\244768e.msp
[17/05/2018 11:11:02] - [84140032] - (.().-. - ()) - C:\Windows\Installer\24476f7.msp
[17/05/2018 11:19:50] - [12103680] - (.().-. - ()) - C:\Windows\Installer\244772e.msp
[17/05/2018 11:26:16] - [49586176] - (.().-. - ()) - C:\Windows\Installer\244774b.msp
[17/05/2018 11:19:56] - [438272] - (.().-. - ()) - C:\Windows\Installer\244779b.msp
[17/05/2018 11:18:48] - [98918400] - (.().-. - ()) - C:\Windows\Installer\24477a2.msp
[15/06/2017 20:16:54] - [1650688] - (.().-. - ()) - C:\Windows\Installer\2462dfd.msp
[12/09/2018 23:32:52] - [31600640] - (.().-. - ()) - C:\Windows\Installer\29541c.msp
[12/09/2018 23:36:54] - [49594368] - (.().-. - ()) - C:\Windows\Installer\295443.msp
[16/01/2019 14:39:28] - [4222976] - (.().-. - ()) - C:\Windows\Installer\29aa17.msp
[16/01/2019 14:45:02] - [1933312] - (.().-. - ()) - C:\Windows\Installer\29aa53.msp
[14/03/2018 18:27:04] - [4898816] - (.().-. - ()) - C:\Windows\Installer\29fe94.msp
[22/03/2018 12:06:30] - [49586176] - (.().-. - ()) - C:\Windows\Installer\29fe9a.msp
[14/03/2018 18:37:22] - [12271616] - (.().-. - ()) - C:\Windows\Installer\29feed.msp
[17/10/2018 12:51:48] - [31600640] - (.().-. - ()) - C:\Windows\Installer\2d9322.msp
[17/10/2018 12:49:32] - [12107776] - (.().-. - ()) - C:\Windows\Installer\2d934b.msp
[15/11/2018 00:24:22] - [31604736] - (.().-. - ()) - C:\Windows\Installer\2fd009.msp
[17/05/2017 12:51:54] - [1843200] - (.().-. - ()) - C:\Windows\Installer\32fdac.msp
[17/05/2017 12:47:52] - [2674688] - (.().-. - ()) - C:\Windows\Installer\32fdb4.msp
[15/06/2017 20:03:30] - [10870784] - (.().-. - ()) - C:\Windows\Installer\32fdd4.msp
[16/01/2019 14:27:38] - [20013056] - (.().-. - ()) - C:\Windows\Installer\339a4.msp
[16/01/2019 14:42:32] - [31604736] - (.().-. - ()) - C:\Windows\Installer\339c8.msp
[16/01/2019 14:46:00] - [49598464] - (.().-. - ()) - C:\Windows\Installer\339ef.msp
[17/05/2018 11:11:00] - [2674688] - (.().-. - ()) - C:\Windows\Installer\3430c.msp
[17/10/2018 12:54:54] - [69316608] - (.().-. - ()) - C:\Windows\Installer\370c1.msp
[17/10/2018 12:49:26] - [4218880] - (.().-. - ()) - C:\Windows\Installer\37113.msp
[25/08/2017 01:32:36] - [97505280] - (.().-. - ()) - C:\Windows\Installer\3ad70.msp
[08/09/2017 06:18:20] - [4018176] - (.().-. - ()) - C:\Windows\Installer\3adc3.msp
[10/02/2016 20:06:02] - [1249280] - (.().-. - ()) - C:\Windows\Installer\3b502.msp
[11/12/2015 18:59:02] - [30990336] - (.().-. - ()) - C:\Windows\Installer\3b537.msp
[20/09/2015 19:01:38] - [614400] - (.().-. - ()) - C:\Windows\Installer\3b562.msp
[18/05/2016 11:00:48] - [409600] - (.().-. - ()) - C:\Windows\Installer\3b591.msp
[16/03/2016 20:03:46] - [573440] - (.().-. - ()) - C:\Windows\Installer\3b5a9.msp
[15/03/2017 16:30:18] - [16248832] - (.().-. - ()) - C:\Windows\Installer\3b5ef.msp
[29/10/2015 03:25:16] - [8155136] - (.().-. - ()) - C:\Windows\Installer\3b5f6.msp
[02/02/2017 04:30:04] - [17297408] - (.().-. - ()) - C:\Windows\Installer\3b616.msp
[12/11/2015 06:55:28] - [806912] - (.().-. - ()) - C:\Windows\Installer\3b658.msp
[19/11/2015 15:23:48] - [4931584] - (.().-. - ()) - C:\Windows\Installer\3b671.msp
[14/09/2016 20:35:12] - [520192] - (.().-. - ()) - C:\Windows\Installer\3b689.msp
[17/08/2016 23:00:50] - [4857856] - (.().-. - ()) - C:\Windows\Installer\3b6a3.msp
[19/10/2016 05:53:56] - [2363392] - (.().-. - ()) - C:\Windows\Installer\3b6bb.msp
[13/07/2016 07:44:42] - [37457920] - (.().-. - ()) - C:\Windows\Installer\3b6c4.msp
[13/07/2016 07:44:44] - [3735552] - (.().-. - ()) - C:\Windows\Installer\3b70c.msp
[29/10/2015 03:33:42] - [34533376] - (.().-. - ()) - C:\Windows\Installer\3b713.msp
[29/10/2015 03:33:16] - [35745792] - (.().-. - ()) - C:\Windows\Installer\3b73c.msp
[13/01/2016 18:58:50] - [729088] - (.().-. - ()) - C:\Windows\Installer\3b754.msp
[14/09/2016 20:49:26] - [1052672] - (.().-. - ()) - C:\Windows\Installer\3b76e.msp
[12/11/2015 06:56:16] - [1179648] - (.().-. - ()) - C:\Windows\Installer\3b775.msp
[16/03/2016 20:03:48] - [30339072] - (.().-. - ()) - C:\Windows\Installer\3b792.msp
[14/09/2016 20:49:32] - [753664] - (.().-. - ()) - C:\Windows\Installer\3b7aa.msp
[13/04/2016 22:00:32] - [8724480] - (.().-. - ()) - C:\Windows\Installer\3b7b3.msp
[10/12/2018 08:52:51] - [44044288] - (.().-. - ()) - C:\Windows\Installer\3f4073.msp
[15/08/2018 08:01:48] - [3256320] - (.().-. - ()) - C:\Windows\Installer\419d4.msp
[15/08/2018 08:10:58] - [4218880] - (.().-. - ()) - C:\Windows\Installer\419db.msp
[15/08/2018 08:13:30] - [31600640] - (.().-. - ()) - C:\Windows\Installer\41a06.msp
[15/08/2018 08:01:44] - [4894720] - (.().-. - ()) - C:\Windows\Installer\41a3f.msp
[15/08/2018 08:10:58] - [8851456] - (.().-. - ()) - C:\Windows\Installer\41a47.msp
[15/08/2018 08:10:56] - [2723840] - (.().-. - ()) - C:\Windows\Installer\41a66.msp
[12/09/2018 23:33:32] - [37298176] - (.().-. - ()) - C:\Windows\Installer\41a7e.msp
[15/08/2018 08:11:02] - [12107776] - (.().-. - ()) - C:\Windows\Installer\41a85.msp
[12/09/2018 23:34:14] - [1658880] - (.().-. - ()) - C:\Windows\Installer\41a9c.msp
[20/09/2018 04:34:24] - [8847360] - (.().-. - ()) - C:\Windows\Installer\41aa4.msp
[12/09/2018 23:30:26] - [99041280] - (.().-. - ()) - C:\Windows\Installer\41ac3.msp
[12/09/2018 23:36:18] - [69316608] - (.().-. - ()) - C:\Windows\Installer\41b00.msp
[12/09/2018 23:30:38] - [12107776] - (.().-. - ()) - C:\Windows\Installer\41b1e.msp
[15/11/2018 00:24:24] - [37302272] - (.().-. - ()) - C:\Windows\Installer\4531f2.msp
[18/12/2017 23:49:06] - [8835072] - (.().-. - ()) - C:\Windows\Installer\469de7.msp
[18/12/2017 23:51:28] - [31588352] - (.().-. - ()) - C:\Windows\Installer\469e05.msp
[15/11/2017 19:24:20] - [46501888] - (.().-. - ()) - C:\Windows\Installer\59279e.msp
[15/11/2017 19:36:00] - [62767104] - (.().-. - ()) - C:\Windows\Installer\5927fe.msp
[15/11/2017 19:33:30] - [8835072] - (.().-. - ()) - C:\Windows\Installer\592806.msp
[15/11/2017 19:24:56] - [2674688] - (.().-. - ()) - C:\Windows\Installer\592835.msp
[15/11/2017 19:33:22] - [2723840] - (.().-. - ()) - C:\Windows\Installer\59283d.msp
[15/11/2017 19:33:28] - [4067328] - (.().-. - ()) - C:\Windows\Installer\592995.msp
[15/11/2017 19:33:32] - [12103680] - (.().-. - ()) - C:\Windows\Installer\5929c1.msp
[15/11/2017 19:35:52] - [37154816] - (.().-. - ()) - C:\Windows\Installer\5929df.msp
[15/11/2017 19:32:48] - [98758656] - (.().-. - ()) - C:\Windows\Installer\5929ec.msp
[15/11/2017 19:24:18] - [10878976] - (.().-. - ()) - C:\Windows\Installer\592a2b.msp
[15/11/2017 19:34:14] - [12275712] - (.().-. - ()) - C:\Windows\Installer\592a5b.msp
[13/06/2018 11:26:48] - [6103040] - (.().-. - ()) - C:\Windows\Installer\5ae9b.msp
[13/06/2018 11:29:00] - [1347584] - (.().-. - ()) - C:\Windows\Installer\5aeda.msp
[13/06/2018 11:31:32] - [69316608] - (.().-. - ()) - C:\Windows\Installer\5aee1.msp
[13/06/2018 11:28:58] - [37298176] - (.().-. - ()) - C:\Windows\Installer\5aeff.msp
[13/06/2018 11:27:36] - [716800] - (.().-. - ()) - C:\Windows\Installer\5af1d.msp
[13/06/2018 11:25:58] - [8847360] - (.().-. - ()) - C:\Windows\Installer\5af26.msp
[18/12/2017 22:39:56] - [1130496] - (.().-. - ()) - C:\Windows\Installer\60f6e.msp
[17/04/2019 22:06:00] - [69316608] - (.().-. - ()) - C:\Windows\Installer\61fd3.msp
[17/04/2019 22:03:12] - [37306368] - (.().-. - ()) - C:\Windows\Installer\61ff0.msp
[17/04/2019 22:00:16] - [4222976] - (.().-. - ()) - C:\Windows\Installer\61ffc.msp
[17/04/2019 22:00:56] - [2940928] - (.().-. - ()) - C:\Windows\Installer\62028.msp
[17/04/2019 22:00:54] - [790528] - (.().-. - ()) - C:\Windows\Installer\62058.msp
[17/04/2019 22:00:14] - [2723840] - (.().-. - ()) - C:\Windows\Installer\62096.msp
[17/04/2019 22:03:20] - [20144128] - (.().-. - ()) - C:\Windows\Installer\620e7.msp
[17/04/2019 22:03:10] - [31608832] - (.().-. - ()) - C:\Windows\Installer\6210d.msp
[17/04/2019 22:00:46] - [8851456] - (.().-. - ()) - C:\Windows\Installer\62136.msp
[17/04/2019 21:59:34] - [98816000] - (.().-. - ()) - C:\Windows\Installer\62153.msp
[22/10/2018 15:33:19] - [2584576] - (.().-. - ()) - C:\Windows\Installer\68466.msp
[14/02/2018 23:17:24] - [4894720] - (.().-. - ()) - C:\Windows\Installer\68d936.msp
[14/02/2018 23:27:24] - [12001280] - (.().-. - ()) - C:\Windows\Installer\68d93f.msp
[14/02/2018 23:27:24] - [8818688] - (.().-. - ()) - C:\Windows\Installer\68d960.msp
[14/02/2018 23:18:06] - [2674688] - (.().-. - ()) - C:\Windows\Installer\68d990.msp
[13/02/2019 10:07:16] - [98689024] - (.().-. - ()) - C:\Windows\Installer\6c3300.msp
[13/02/2019 10:07:56] - [4222976] - (.().-. - ()) - C:\Windows\Installer\6c336e.msp
[13/02/2019 10:08:30] - [12103680] - (.().-. - ()) - C:\Windows\Installer\6c339a.msp
[13/02/2019 10:09:28] - [716800] - (.().-. - ()) - C:\Windows\Installer\6c33c9.msp
[13/02/2019 10:10:20] - [31604736] - (.().-. - ()) - C:\Windows\Installer\6c3405.msp
[13/02/2019 10:11:20] - [37306368] - (.().-. - ()) - C:\Windows\Installer\6c342d.msp
[13/02/2019 10:14:00] - [49602560] - (.().-. - ()) - C:\Windows\Installer\6c343a.msp
[13/02/2019 09:58:38] - [20017152] - (.().-. - ()) - C:\Windows\Installer\6c347a.msp
[18/01/2018 12:24:44] - [3444736] - (.().-. - ()) - C:\Windows\Installer\6d1cd5.msp
[14/02/2018 23:26:10] - [98902016] - (.().-. - ()) - C:\Windows\Installer\6d1d52.msp
[14/02/2018 23:28:12] - [41410560] - (.().-. - ()) - C:\Windows\Installer\6d1da1.msp
[14/02/2018 23:28:14] - [6078464] - (.().-. - ()) - C:\Windows\Installer\6d1ddb.msp
[14/02/2018 23:32:50] - [69320704] - (.().-. - ()) - C:\Windows\Installer\6d1e48.msp
[14/02/2018 23:33:06] - [49545216] - (.().-. - ()) - C:\Windows\Installer\6d1e65.msp
[14/02/2018 23:17:26] - [20004864] - (.().-. - ()) - C:\Windows\Installer\6d2095.msp
[16/01/2019 14:27:38] - [3911680] - (.().-. - ()) - C:\Windows\Installer\76341.msp
[18/12/2017 23:49:08] - [12103680] - (.().-. - ()) - C:\Windows\Installer\777a5.msp
[18/12/2017 23:54:42] - [69320704] - (.().-. - ()) - C:\Windows\Installer\777c3.msp
[16/01/2019 14:38:50] - [98689024] - (.().-. - ()) - C:\Windows\Installer\7c2b40.msp
[16/01/2019 14:43:00] - [37302272] - (.().-. - ()) - C:\Windows\Installer\7c2b7c.msp
[17/10/2018 12:51:52] - [37298176] - (.().-. - ()) - C:\Windows\Installer\7db30.msp
[17/10/2018 12:48:54] - [99041280] - (.().-. - ()) - C:\Windows\Installer\7db3c.msp
[17/10/2018 12:55:16] - [49594368] - (.().-. - ()) - C:\Windows\Installer\7db6e.msp
[17/10/2018 12:40:56] - [2674688] - (.().-. - ()) - C:\Windows\Installer\7dbc0.msp
[13/03/2019 11:17:54] - [716800] - (.().-. - ()) - C:\Windows\Installer\7e2ba.msp
[13/03/2019 11:17:30] - [6115328] - (.().-. - ()) - C:\Windows\Installer\7e2c2.msp
[13/03/2019 11:22:26] - [49602560] - (.().-. - ()) - C:\Windows\Installer\7e2f1.msp
[13/03/2019 11:19:38] - [19963904] - (.().-. - ()) - C:\Windows\Installer\7e36f.msp
[13/03/2019 11:15:18] - [98856960] - (.().-. - ()) - C:\Windows\Installer\7e395.msp
[13/03/2019 11:19:34] - [37302272] - (.().-. - ()) - C:\Windows\Installer\7e3d0.msp
[13/03/2019 11:06:12] - [3915776] - (.().-. - ()) - C:\Windows\Installer\7e3f1.msp
[13/03/2019 11:06:12] - [4866048] - (.().-. - ()) - C:\Windows\Installer\7e43c.msp
[13/03/2019 11:18:46] - [31604736] - (.().-. - ()) - C:\Windows\Installer\7e443.msp
[13/03/2019 11:16:58] - [12271616] - (.().-. - ()) - C:\Windows\Installer\7e47e.msp
[15/11/2017 19:39:26] - [49553408] - (.().-. - ()) - C:\Windows\Installer\9c924.msp
[15/11/2017 19:24:16] - [4890624] - (.().-. - ()) - C:\Windows\Installer\9c976.msp
[13/07/2016 08:42:36] - [81145856] - (.().-. - ()) - C:\Windows\Installer\a30193.msp
[18/10/2017 23:53:38] - [49483776] - (.().-. - ()) - C:\Windows\Installer\a30199.msp
[25/10/2017 08:50:10] - [1474560] - (.().-. - ()) - C:\Windows\Installer\a301db.msp
[18/12/2017 23:39:54] - [4894720] - (.().-. - ()) - C:\Windows\Installer\a9243.msp
[18/12/2017 23:50:26] - [6074368] - (.().-. - ()) - C:\Windows\Installer\a924e.msp
[22/12/2017 05:00:18] - [20008960] - (.().-. - ()) - C:\Windows\Installer\a9281.msp
[18/12/2017 23:52:38] - [1654784] - (.().-. - ()) - C:\Windows\Installer\a92b6.msp
[13/06/2018 11:16:22] - [20004864] - (.().-. - ()) - C:\Windows\Installer\ac734c.msp
[13/06/2018 11:26:46] - [1523712] - (.().-. - ()) - C:\Windows\Installer\ac7371.msp
[13/06/2018 11:26:46] - [4653056] - (.().-. - ()) - C:\Windows\Installer\ac7394.msp
[13/06/2018 11:24:44] - [98930688] - (.().-. - ()) - C:\Windows\Installer\ac73b3.msp
[13/06/2018 11:31:40] - [49590272] - (.().-. - ()) - C:\Windows\Installer\ac73ec.msp
[15/08/2018 08:17:04] - [49618944] - (.().-. - ()) - C:\Windows\Installer\b42860.msp
[11/04/2018 12:46:00] - [4653056] - (.().-. - ()) - C:\Windows\Installer\be6980.msp
[11/04/2018 12:50:38] - [49586176] - (.().-. - ()) - C:\Windows\Installer\be699c.msp
[11/04/2018 12:46:00] - [1523712] - (.().-. - ()) - C:\Windows\Installer\be69dd.msp
[11/04/2018 12:35:54] - [2674688] - (.().-. - ()) - C:\Windows\Installer\be6a11.msp
[14/09/2017 04:09:40] - [19980288] - (.().-. - ()) - C:\Windows\Installer\be75a6.msp
[14/09/2017 04:26:04] - [69296128] - (.().-. - ()) - C:\Windows\Installer\be75cc.msp
[14/09/2017 04:23:06] - [62742528] - (.().-. - ()) - C:\Windows\Installer\be772b.msp
[14/09/2017 04:20:32] - [1470464] - (.().-. - ()) - C:\Windows\Installer\be7733.msp
[14/09/2017 04:20:34] - [4648960] - (.().-. - ()) - C:\Windows\Installer\be7756.msp
[14/09/2017 04:21:46] - [99979264] - (.().-. - ()) - C:\Windows\Installer\be7775.msp
[16/05/2019 08:39:38] - [4878336] - (.().-. - ()) - C:\Windows\Installer\c6638.msp
[16/05/2019 08:50:06] - [12115968] - (.().-. - ()) - C:\Windows\Installer\c6640.msp
[14/09/2017 04:09:42] - [46477312] - (.().-. - ()) - C:\Windows\Installer\c6934.msp
[14/09/2017 04:23:48] - [1650688] - (.().-. - ()) - C:\Windows\Installer\c697a.msp
[14/09/2017 04:19:20] - [97521664] - (.().-. - ()) - C:\Windows\Installer\c6982.msp
[18/10/2017 23:49:00] - [12275712] - (.().-. - ()) - C:\Windows\Installer\c69d2.msp
[18/10/2017 23:50:10] - [37126144] - (.().-. - ()) - C:\Windows\Installer\c69da.msp
[18/10/2017 23:49:08] - [41512960] - (.().-. - ()) - C:\Windows\Installer\c69e7.msp
[18/10/2017 23:50:08] - [31563776] - (.().-. - ()) - C:\Windows\Installer\c6a15.msp
[18/10/2017 23:47:56] - [8802304] - (.().-. - ()) - C:\Windows\Installer\c6a40.msp
[18/10/2017 23:39:32] - [548864] - (.().-. - ()) - C:\Windows\Installer\c6a6f.msp
[03/01/2019 11:17:04] - [1720320] - (.().-. - ()) - C:\Windows\Installer\ce71b6.msp
[20/02/2019 14:28:20] - [1986560] - (.().-. - ()) - C:\Windows\Installer\d162a2.msp
[18/09/2018 10:10:59] - [4706304] - (.().-. - ()) - C:\Windows\Installer\e0402.msp
[13/06/2019 14:38:00] - [2260992] - (.().-. - ()) - C:\Windows\Installer\e2b4e.msp
[16/08/2017 09:33:52] - [3387392] - (.().-. - ()) - C:\Windows\Installer\e4ba5f.msp
[16/08/2017 09:43:32] - [41496576] - (.().-. - ()) - C:\Windows\Installer\e4ba68.msp
[16/08/2017 09:43:36] - [6066176] - (.().-. - ()) - C:\Windows\Installer\e4baa6.msp
[18/01/2018 12:34:48] - [41541632] - (.().-. - ()) - C:\Windows\Installer\e62294.msp
[17/05/2017 12:53:48] - [49520640] - (.().-. - ()) - C:\Windows\Installer\ea109c.msp
[12/07/2017 10:24:42] - [557056] - (.().-. - ()) - C:\Windows\Installer\ea10de.msp
[12/07/2017 10:22:06] - [36016128] - (.().-. - ()) - C:\Windows\Installer\ea10fe.msp
[18/12/2017 23:51:32] - [19640320] - (.().-. - ()) - C:\Windows\Installer\f1931.msp
[18/12/2017 23:51:30] - [37150720] - (.().-. - ()) - C:\Windows\Installer\f1957.msp
[15/06/2017 20:14:00] - [12050432] - (.().-. - ()) - C:\Windows\Installer\f3b9f.msp
[17/05/2017 12:48:58] - [12267520] - (.().-. - ()) - C:\Windows\Installer\f3bd1.msp
[17/05/2017 12:40:30] - [278528] - (.().-. - ()) - C:\Windows\Installer\f3bd8.msp
[18/05/2016 11:04:14] - [46460928] - (.().-. - ()) - C:\Windows\Installer\f3bdf.msp
[17/05/2017 12:49:00] - [2887680] - (.().-. - ()) - C:\Windows\Installer\f3bfe.msp
[15/03/2017 16:32:20] - [688128] - (.().-. - ()) - C:\Windows\Installer\f3c2d.msp
[12/04/2017 11:14:12] - [4890624] - (.().-. - ()) - C:\Windows\Installer\f3c45.msp
[18/12/2017 23:49:06] - [4071424] - (.().-. - ()) - C:\Windows\Installer\f4fa20.msp
[18/12/2017 23:49:04] - [2723840] - (.().-. - ()) - C:\Windows\Installer\f4fa4c.msp
[08/10/2018 13:11:44] - [2174976] - (.().-. - ()) - C:\Windows\Installer\f6313.msp
[11/04/2018 12:44:00] - [98918400] - (.().-. - ()) - C:\Windows\Installer\f6932f.msp
[11/04/2018 12:47:34] - [37294080] - (.().-. - ()) - C:\Windows\Installer\f6939f.msp
[11/04/2018 12:35:14] - [10878976] - (.().-. - ()) - C:\Windows\Installer\f693ae.msp
[11/04/2018 12:48:40] - [1921024] - (.().-. - ()) - C:\Windows\Installer\f693de.msp
[11/04/2018 12:46:02] - [6098944] - (.().-. - ()) - C:\Windows\Installer\f693ea.msp
[11/04/2018 12:45:14] - [41410560] - (.().-. - ()) - C:\Windows\Installer\f6941a.msp
[11/04/2018 12:45:12] - [417792] - (.().-. - ()) - C:\Windows\Installer\f69447.msp
[11/04/2018 12:45:12] - [12103680] - (.().-. - ()) - C:\Windows\Installer\f69466.msp

---------- | %System%\*.in*

[11/01/2018 21:18:55] - [3329] - C:\Windows\System32\ieuinit.inf
[05/07/2017 18:30:54] - [33986944] - C:\Windows\System32\PerfStringBackup.INI
[18/03/2017 22:58:24] - [60124] - C:\Windows\System32\tcpmon.ini
[18/03/2017 22:57:50] - [2307] - C:\Windows\System32\WimBootCompress.ini
[11/01/2018 21:18:55] - [3329] - C:\Windows\Syswow64\ieuinit.inf
[18/03/2017 22:58:48] - [2307] - C:\Windows\Syswow64\WimBootCompress.ini

---------- | Listing no Microsoft signed files (Not necessary Malwares) | system32 | Syswow64 | General scan

[MD5.A681527B9F23DD5F1A6C8D3F621E814E] - |A| - [18/03/2017 22:57:20] - (.-.) - [14.73 Ko] - (0.0.0.0) - C:\Windows\AppPatch\AppPatch64\pcamain.sdb
[MD5.6427748423679B4077A08D6191649132] - |A| - [13/10/2018 17:50:02] - (.-.) - [555.75 Ko] - (0.0.0.0) - C:\Windows\AppPatch\AppPatch64\sysmain.sdb
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [2.06 Ko] - C:\Windows\AppPatch\Custom\Custom64
[MD5.00000000000000000000000000000000] - |D| - [24/01/2019 09:09:54] - [13717.63 Ko] - C:\Windows\Temp\4EC757FE-6BEA-4045-8EBF-1645AAA8D3E9
[MD5.00000000000000000000000000000000] - |D| - [10/07/2019 09:36:23] - [0 Ko] - C:\Windows\Temp\77FF6413-8F24-443C-9EB3-F9F1D8286E29-Sigs
[MD5.25F79C6C9EBB2D8FFCF6567BB204B2B4] - |A| - [02/08/2018 23:52:20] - (.-.) - [25.1 Ko] - (0.0.0.0) - C:\Windows\Temp\AdobeARM.log
[MD5.1EFA0B4E931082DF291C98C30F12FFA8] - |A| - [03/08/2018 13:17:02] - (.-.) - [0.17 Ko] - (0.0.0.0) - C:\Windows\Temp\AdobeARM_NotLocked.log
[MD5.3D6477A0DC864C81E5FDDAC8353E1C09] - |A| - [06/07/2017 00:53:25] - (.-.) - [9283.83 Ko] - (0.0.0.0) - C:\Windows\Temp\adobegc.log
[MD5.FD3BB4B42EBDA8C908309C9F406DC52C] - |AT| - [07/03/2019 11:01:03] - (.-.) - [0.79 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.0a0wpz903gngdbz3y5wjkrovc.tmp
[MD5.C3EE0969ABF25DDD95AE2542AA53F586] - |AT| - [22/09/2018 23:15:10] - (.-.) - [266.42 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.0aq7yzzejm0el4rmdbe5b6f7b.tmp
[MD5.75FD04C5E88238B00565F3C7B63B27EC] - |AT| - [16/09/2018 18:53:05] - (.-.) - [10.82 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.0b4q07vt72p_8irjqv58b1j2b.tmp
[MD5.151AEB3A86BD2E32421E6079CFB02849] - |AT| - [22/01/2019 23:43:51] - (.-.) - [10.91 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.0b96wqd4w_47uwgsyhzkelb0f.tmp
[MD5.86FAB998BD8FCA91D12B47611A01AF49] - |AT| - [26/01/2018 00:09:59] - (.-.) - [5.49 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.0dhjd731cufws30e14vwyfvud.tmp
[MD5.F278077C78E392B38FA160E6482ED8D8] - |AT| - [21/04/2019 23:29:32] - (.-.) - [5.05 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.0dwlto9rpbe2g4hd_gqfrixrd.tmp
[MD5.B42EE9C2387BC518D3C38AEA91F5C23A] - |AT| - [07/03/2019 10:58:25] - (.-.) - [71.17 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.0g6yxe37wofm54op2snfty4fh.tmp
[MD5.4122ADEEE45828BBFC8DAD94AFDC06E2] - |AT| - [04/07/2019 07:49:34] - (.-.) - [86.96 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.0taoas7zn5b2bz6v5yynodrwc.tmp
[MD5.0AFE90047113C402A3D2887C98F5C21A] - |AT| - [05/03/2019 21:50:30] - (.-.) - [11.03 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.0wat3zqnrk2vjg7p_i30g9s0h.tmp
[MD5.916BD992B0213E44F1A4D33EFF7582E2] - |AT| - [22/03/2019 23:15:20] - (.-.) - [20.25 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.0x2s4stbvs0y2yd4m14l60kdh.tmp
[MD5.7547FFFDDDC48BC61C4D3C7E2A5CEC2D] - |AT| - [13/03/2019 21:59:00] - (.-.) - [10.82 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.0yz1fp_ilwlhlv33ieehuk3od.tmp
[MD5.0DDE79431064EA7A43B8C9DB775F057D] - |AT| - [26/06/2019 13:25:38] - (.-.) - [0.33 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.10_0_wqln2s4qht4zsbcjag7d.tmp
[MD5.3E6178143B1197FAA2E37313AFB3124D] - |AT| - [03/07/2019 08:36:50] - (.-.) - [0.33 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.17wi7z9kk_vxsp7zpnqnnmfrc.tmp
[MD5.C9ECC0BA638EF260B56F96AF65C8B2FE] - |AT| - [12/12/2018 16:36:27] - (.-.) - [17.82 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.1c02in_zf9kkmvldscftbbimd.tmp
[MD5.280C940C05B2E5D5F5465B0B0AD30B7E] - |AT| - [01/07/2019 16:55:30] - (.-.) - [0.85 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.1h4wf8amjxt_fk1d6lhy3rjac.tmp
[MD5.A1E2DE3222755EA3907CFDCB107F8519] - |AT| - [29/01/2019 20:11:38] - (.-.) - [0.33 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.1ji3rjuc2cycosd0r0tgh8phh.tmp
[MD5.0C7833B41DD6B199B24FD4FC25D0A459] - |AT| - [14/03/2019 23:52:13] - (.-.) - [11.45 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.1lqrmp0ao58fibotedhkgm9g.tmp
[MD5.82E746F8A8281A21B51D7656051AE8E5] - |AT| - [07/03/2019 11:01:03] - (.-.) - [11.85 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.1qjc1blkghl7lj9aocjln7csh.tmp
[MD5.B8EB39DB00B3C6B3D29DB20069BDEFB6] - |AT| - [05/03/2019 21:42:44] - (.-.) - [20.06 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.1ssbk6d1xtobkk69o5dz8929f.tmp
[MD5.449570DA3330888FDA971B7E7DDFB40D] - |AT| - [18/06/2019 19:13:38] - (.-.) - [34.8 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.1trl40ag3nxtxin2tsgb7aacg.tmp
[MD5.8FEB58336CF5950FA48D2C8CFF8BDEDF] - |AT| - [21/02/2019 15:41:15] - (.-.) - [15.94 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.21dzq6ny3nz8u1mjlk3yt5kgd.tmp
[MD5.F01C775869051B31DF75BABB1A427A4C] - |AT| - [07/07/2019 10:46:39] - (.-.) - [15.09 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.24396iyhhghn0u4lyd0opjy5g.tmp
[MD5.EF725609E7462B6E60F24C4C42497729] - |AT| - [26/01/2018 00:20:11] - (.-.) - [4.24 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.25anqxeenm0zix_dyzzoif2l.tmp
[MD5.3131C3141B63DC3A10484AB0074C3871] - |AT| - [22/03/2019 23:15:20] - (.-.) - [84.94 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.28obx1ori82_6kgbgl4wtojtg.tmp
[MD5.2D6F338F03BC9C4253AF088E01440E4A] - |AT| - [12/11/2018 19:26:00] - (.-.) - [274.89 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.2eoqhbe3call9dtnyw825m9sd.tmp
[MD5.0DDE79431064EA7A43B8C9DB775F057D] - |AT| - [18/06/2019 19:13:45] - (.-.) - [0.33 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.2j26f_meke7okzh7ox0lhy4kd.tmp
[MD5.5E089BEDBC5739FC1225906D2DCAA4EC] - |AT| - [15/03/2019 23:30:09] - (.-.) - [26.78 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.2q0gi_kb7a0twfs_23jh9uoqc.tmp
[MD5.BD232B3DBA652BDD5440E01304D06F63] - |AT| - [08/08/2017 19:34:25] - (.-.) - [882.83 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.2uigp_aecyueln5u0abrcjogf.tmp
[MD5.FCA1B09A9B9D8189D36D72AC73483525] - |AT| - [17/04/2019 22:39:39] - (.-.) - [0.44 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.30szba3otpsii6f4ebk60fuzh.tmp
[MD5.9D9AD2B98F79CF7ABC4547299FAFD504] - |AT| - [08/09/2017 23:30:42] - (.-.) - [0.99 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.32yhfwwc9pwc3gmoct34ip4qd.tmp
[MD5.2B7107E35BAC443A003BAA151DBB4B09] - |AT| - [11/02/2019 16:11:42] - (.-.) - [0.79 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.3522ola873sii35jcnrzziy5b.tmp
[MD5.4B4A4C6A33DBB24F3F00C43EABE7EFEC] - |AT| - [28/05/2019 17:23:14] - (.-.) - [11.83 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.39eiy9ar_2b9gne04fiwc7abf.tmp
[MD5.0DC96D0FA85518729FDA0917D8ED81A2] - |AT| - [11/02/2019 16:11:42] - (.-.) - [11.84 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.3bsrkj05w52vmqbu2s4lmpr3d.tmp
[MD5.4A11A5C3BA94934B66E539170D3E339C] - |AT| - [20/03/2019 21:03:47] - (.-.) - [0.99 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.3hsgyw2c9zeo2mz0szmcbkf5c.tmp
[MD5.F9500A059773463FCEC793C0EE0FB141] - |AT| - [22/09/2018 23:15:10] - (.-.) - [10.93 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.3iwd7pis60jalik5zwr3dz2mg.tmp
[MD5.FE9CCEB424AE4632CF3A176526135B61] - |AT| - [17/04/2019 22:34:34] - (.-.) - [31.2 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.3q36l3l9da6cay5ysoo8rio9g.tmp
[MD5.485EA3756A782304FDDDC0405641D572] - |AT| - [14/03/2019 23:52:13] - (.-.) - [4.97 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.3wh2r1ai7g1_funnwojvwvug.tmp
[MD5.AF4E570DEC539368C8C923F5906F662B] - |AT| - [08/09/2017 23:03:05] - (.-.) - [0.51 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.3yt08os6muqtt2wu1p28f0t_f.tmp
[MD5.082BEB1754666D56D3F7C2F84F48BB3A] - |AT| - [28/05/2019 17:21:55] - (.-.) - [10.79 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.44f_cn10jtv1d2nqokf258lfc.tmp
[MD5.27242A01C46E33B13EE54EDAA4ADD86E] - |AT| - [24/02/2019 01:04:40] - (.-.) - [0.33 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.46r5n5kklsx07lgz4gkk9lf5b.tmp
[MD5.371A459478F8D8D77E063D78464DBE9E] - |AT| - [04/04/2019 18:57:47] - (.-.) - [0.79 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.49mpbsyruh24i74vcudldmoye.tmp
[MD5.D41D8CD98F00B204E9800998ECF8427E] - |AT| - [23/09/2018 21:24:15] - (.-.) - [0 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.4cs3vh089c2p6ebq5ji62kfef.tmp
[MD5.418CE0D06AE283D77A7419CE2E4AED62] - |AT| - [21/02/2019 15:42:57] - (.-.) - [10.78 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.4dngerpc44c97hh50erw0o1sd.tmp
[MD5.01DD87663574059854A9344684DAF598] - |AT| - [13/03/2019 21:59:00] - (.-.) - [7.19 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.4sljhf8xg9471erkkycfm3and.tmp
[MD5.EA2DA44B624CE2E2190CE938F2005FB0] - |AT| - [08/08/2017 19:34:25] - (.-.) - [10.81 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.4t3two6q9nblzo3_x2lrpu5vb.tmp
[MD5.7D54F416CB6A6C1C5BEDD24010DF3971] - |AT| - [20/03/2019 21:09:40] - (.-.) - [10.78 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.4vt8ggpzzs68k0pe3j29h5puf.tmp
[MD5.114EFCA19415C9EDA39AAF69B9CE1841] - |AT| - [22/01/2019 20:20:26] - (.-.) - [18.12 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.4w3nqz1_fr_oahiaxis956sec.tmp
[MD5.8B02802142CE4E2C7CFD703805FED21F] - |AT| - [10/04/2019 16:24:47] - (.-.) - [261.34 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.4xzepbvrwjz1k1p_9ted7wske.tmp
[MD5.40BEC54309ACC459F5DCCD90439F745E] - |AT| - [05/08/2017 18:26:32] - (.-.) - [10.39 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.52mkmullstxj8gdmrg9bcraab.tmp
[MD5.90B53E31485F3E8421A7C40902C38704] - |AT| - [06/02/2019 20:53:50] - (.-.) - [5.7 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.583gos47tm6z6wibuv1uy8ong.tmp
[MD5.3CBC0BD7FB4834BAF7F249DD9C57F1FD] - |AT| - [21/02/2019 15:41:15] - (.-.) - [10.79 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.5h12mdr0692zf2lrdia_dgavb.tmp
[MD5.5A34E3A0FB3A388135F19B6C625F1FCA] - |AT| - [07/07/2019 10:46:39] - (.-.) - [23.31 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.5hmq2m_9w6fridg94wdxzwzrc.tmp
[MD5.D98EA73B09AEAFBD4282DDD420CD4E21] - |AT| - [28/01/2018 19:57:12] - (.-.) - [10.39 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.5lm5ya01wn89psm5wkz3zdczc.tmp
[MD5.604D312D676286C29A82C531DAED5177] - |AT| - [18/06/2019 19:13:38] - (.-.) - [10.79 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.5r8qbsnycorebz5ry0bp0bk0h.tmp
[MD5.B7FD13D18E76E28692F99B1A2C22DDC0] - |AT| - [28/01/2018 20:02:38] - (.-.) - [10.39 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.5ty8ze25tp7xsrrsrrhvogh8b.tmp
[MD5.3F052646EDEC71B7FD382F233D5E01BE] - |AT| - [17/04/2019 22:34:34] - (.-.) - [10.82 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.5up5bx_3e_4xwh44foboj2qrc.tmp
[MD5.690D6C4A9B1D945B58C3F1427E27E3F2] - |AT| - [14/03/2019 23:52:13] - (.-.) - [5.22 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.5upyv38q15fyexjwogito8had.tmp
[MD5.151AEB3A86BD2E32421E6079CFB02849] - |AT| - [25/01/2019 21:03:57] - (.-.) - [10.91 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.5ypnuuefeqk4c1e2ai2vj4fge.tmp
[MD5.3C93125508E30FE30FB14AB0C0273EF9] - |AT| - [25/01/2019 21:05:44] - (.-.) - [0.33 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.5zv71rcqx0_yqytp0te3jut4g.tmp
[MD5.49AB499FCFC79C613B8FD961693F4C6D] - |AT| - [06/06/2019 15:29:12] - (.-.) - [34.29 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.5_0dfb517o2jmpaog8px6j71g.tmp
[MD5.49AB499FCFC79C613B8FD961693F4C6D] - |AT| - [19/04/2019 14:32:47] - (.-.) - [34.29 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.60fm2q4eorejtn3hjz7s6i7ic.tmp
[MD5.151AEB3A86BD2E32421E6079CFB02849] - |AT| - [08/02/2019 22:41:51] - (.-.) - [10.91 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.6e2p135myzay31co20unvjdpg.tmp
[MD5.6E080A528ECDD98FDBCD743628B81EF0] - |AT| - [11/02/2019 15:49:18] - (.-.) - [20.08 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.6h1sl1q1a7ex5uwb_t_yb5vdd.tmp
[MD5.FAC1A7340C3FA26267B9D06C070EEE08] - |AT| - [22/09/2018 23:15:10] - (.-.) - [7 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.6h6p7wp6surb6w164352ac40d.tmp
[MD5.CE3D047FED95370C8AC5B321246C3A0B] - |AT| - [28/05/2019 17:23:14] - (.-.) - [39.91 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.6ron6u4e2ghy635yoxaiq4np.tmp
[MD5.886A6C0576C42C01BAE8805F0DC40A20] - |AT| - [10/02/2019 20:39:56] - (.-.) - [10.99 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.6_fs9334hkjplhg672sugdk6b.tmp
[MD5.90B53E31485F3E8421A7C40902C38704] - |AT| - [08/02/2019 22:41:51] - (.-.) - [5.7 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.707ces1_do0fkaggv0te8qg4e.tmp
[MD5.EF9F581DE8839E2112D74A878A62EE6F] - |AT| - [11/02/2019 15:49:18] - (.-.) - [70.52 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.707jhgls9djg4m78lll8gre3e.tmp
[MD5.F27741756A3568F057B24FE6525D25C1] - |AT| - [22/03/2019 23:20:25] - (.-.) - [10.78 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.73m3oub218l6er1t9eib3_p_c.tmp
[MD5.C226228352D96506D5F61DBEF173623E] - |AT| - [07/03/2019 11:01:03] - (.-.) - [4.85 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.74ma41i7pw7hy11xxdq_3_s4d.tmp
[MD5.F27741756A3568F057B24FE6525D25C1] - |AT| - [15/03/2019 23:30:09] - (.-.) - [10.78 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.77ujm81em3q_y3df2xnk3qycg.tmp
[MD5.239E08440A6ABBD3D251C846F18E57B3] - |AT| - [22/03/2019 23:20:25] - (.-.) - [0.33 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.7nxim2ob5eqixh46w4jzic7ne.tmp
[MD5.8D6A3FA84F9AA1ED5094E9E8AD1D9FDD] - |AT| - [17/04/2019 22:34:34] - (.-.) - [11.45 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.7parq6hjd5gv_5bv9zmekwove.tmp
[MD5.23D3B5772AC937A557233470A97E5A44] - |AT| - [27/06/2019 19:40:00] - (.-.) - [31.2 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.7rio_98uqqkj4ly2_kqxoq8qg.tmp
[MD5.7809950892ADF420C181E2E756B67844] - |AT| - [04/12/2018 18:36:08] - (.-.) - [7.12 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.7urkar57ekbk5v3fmx10bdvhf.tmp
[MD5.27242A01C46E33B13EE54EDAA4ADD86E] - |AT| - [21/02/2019 15:41:15] - (.-.) - [0.33 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.7vcpzbdtoh0iks5ej1lhj_1md.tmp
[MD5.935CE960B20FB8AB3C2D35E07502601E] - |AT| - [16/09/2018 18:53:05] - (.-.) - [3.94 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.85nlfoe3v9e2kjhvzyhfyqrff.tmp
[MD5.DE1ACD0C94BC9E0A479FCDF910EF43AC] - |AT| - [04/12/2018 18:36:08] - (.-.) - [10.92 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.8kno0xj5clya46888i7f17dpd.tmp
[MD5.A1E2DE3222755EA3907CFDCB107F8519] - |AT| - [11/02/2019 16:11:42] - (.-.) - [0.33 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.8mgyunhund2ejpzq0nszs5wvb.tmp
[MD5.151AEB3A86BD2E32421E6079CFB02849] - |AT| - [21/01/2019 21:26:54] - (.-.) - [10.91 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.8pkvikln1xex9zdcw0fdpd8n.tmp
[MD5.5A6C358D8B0707136C46DFCD4D70E448] - |AT| - [07/07/2019 10:46:39] - (.-.) - [10.82 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.8qjyhyr_xk2gwbofqzashq2y.tmp
[MD5.95CE31BAA459178496B52FF949BDC025] - |AT| - [05/08/2017 18:26:32] - (.-.) - [120.62 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.8u01dr1nrmeu8ty612xb8sioh.tmp
[MD5.EF9F581DE8839E2112D74A878A62EE6F] - |AT| - [08/02/2019 20:42:33] - (.-.) - [70.52 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.936smuaaoixx7x8eyf8q7ugfc.tmp
[MD5.DAAACACBDE19B659FCC12BC86E6FA2C7] - |AT| - [20/03/2019 21:01:20] - (.-.) - [601.85 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.93e8322fym682wwhs3i92ezq.tmp
[MD5.4D36CFBA868DCDD78D3F19F9859A6340] - |AT| - [23/09/2018 21:27:35] - (.-.) - [0.33 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.93m1qqfri1vm274pa4wtdinvb.tmp
[MD5.708687F112F74C5CA9A38C0E54AE0351] - |AT| - [24/02/2019 01:04:21] - (.-.) - [4.78 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.9a1ax2nwi03tbedvs_xfbe81b.tmp
[MD5.A671B53B718F21E826F46D0C3BEA4D7D] - |AT| - [05/03/2019 21:42:44] - (.-.) - [261.98 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.9u3k9h20ubp2qn0kqwadfejrb.tmp
[MD5.AEE7C50C8904365F6A18D835B3AF91AD] - |AT| - [17/04/2019 15:13:26] - (.-.) - [14.24 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.9wcv5uybjauoert2dobxut6fb.tmp
[MD5.3F052646EDEC71B7FD382F233D5E01BE] - |AT| - [19/04/2019 14:34:08] - (.-.) - [10.82 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.9wtpbuhylar0mjrds24mbqck.tmp
[MD5.21838DDC9F00018945ED5600DB9710C8] - |AT| - [22/03/2019 23:20:27] - (.-.) - [0.99 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.9y37fbgorkklnfkk1fy13wfxf.tmp
[MD5.151AEB3A86BD2E32421E6079CFB02849] - |AT| - [18/01/2019 23:31:47] - (.-.) - [10.91 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.a4mdwx5xt3dajxrchlo434bre.tmp
[MD5.3E9207925506078A01EADF89191030B6] - |AT| - [08/05/2019 14:46:15] - (.-.) - [31.2 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.a7hw83jex6zi_gtqzgbvgbxsf.tmp
[MD5.E2834E2E30B4274B70F85D367581D0F9] - |AT| - [11/02/2019 16:11:42] - (.-.) - [4.85 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.a8vqc7pvj4kouhv0wdyqqanvf.tmp
[MD5.3748431D7FAC8EF6117B3490CE74E7DC] - |AT| - [10/02/2018 14:14:53] - (.-.) - [17.02 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.a8ywdszj1mp9ngirhnbg4b4eg.tmp
[MD5.90B53E31485F3E8421A7C40902C38704] - |AT| - [21/01/2019 21:26:54] - (.-.) - [5.7 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.a98uz01ce4zucpjv6_56qleeh.tmp
[MD5.479074D67AC96371120505CEBB9B661E] - |AT| - [04/04/2019 18:37:01] - (.-.) - [10.82 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.a9ts3uhuh97r0hyr92qj0zh3e.tmp
[MD5.5A34E3A0FB3A388135F19B6C625F1FCA] - |AT| - [03/07/2019 08:38:32] - (.-.) - [23.31 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.a9zk8m8roph_2gdcwh47b6sig.tmp
[MD5.50EAEE707B457BFD185B19674A11241C] - |AT| - [30/01/2019 14:57:20] - (.-.) - [1.54 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.ah1_li9ebxnaqruaqg6eqpj3b.tmp
[MD5.17C9CCFFCF1DD1EC4424509058CDB7C3] - |AT| - [01/07/2019 16:50:16] - (.-.) - [17.07 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.aj22d018ci2zsvll76j31ydvf.tmp
[MD5.F8590137CF277895F4EB0FA4F0F69EAF] - |AT| - [18/06/2019 19:13:38] - (.-.) - [0.33 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.ak86bwop58425e1gq3qi8ebff.tmp
[MD5.A1E2DE3222755EA3907CFDCB107F8519] - |AT| - [22/01/2019 23:43:51] - (.-.) - [0.33 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.akmn04n0v8b6dak8gy2bzl1jg.tmp
[MD5.90B53E31485F3E8421A7C40902C38704] - |AT| - [30/01/2019 14:57:09] - (.-.) - [5.7 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.ane3mnqqpojp9ga76shvyf89b.tmp
[MD5.114EFCA19415C9EDA39AAF69B9CE1841] - |AT| - [21/01/2019 21:27:44] - (.-.) - [18.12 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.aqsn03rdk_zletkgf2nxf32rf.tmp
[MD5.74454FD32C5038A915EF01BF046E2BB4] - |AT| - [21/02/2019 15:42:57] - (.-.) - [26.66 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.at9xrzbgrudz_7y3v4tctetrb.tmp
[MD5.21838DDC9F00018945ED5600DB9710C8] - |AT| - [20/03/2019 21:09:40] - (.-.) - [0.99 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.awoj2sbj90oquvxdkshf601ed.tmp
[MD5.AEE7C50C8904365F6A18D835B3AF91AD] - |AT| - [10/04/2019 16:24:47] - (.-.) - [14.24 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.axcnoqvj9pst9inhknkvc_tkg.tmp
[MD5.90B53E31485F3E8421A7C40902C38704] - |AT| - [25/01/2019 21:03:57] - (.-.) - [5.7 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.ay0cfb0ij3sj1z3z90gx9b6wh.tmp
[MD5.3AD13BB1573074051E2BF9CE438D4F24] - |AT| - [17/04/2019 15:13:26] - (.-.) - [10.94 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.a_9ni3ifimz6b3i7m90_5h_9b.tmp
[MD5.4A27F35E65B42DFA0BBD92E202B674A3] - |AT| - [11/02/2019 16:11:42] - (.-.) - [11.03 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.a_se6q5i584l6j3rj2rbqtpwg.tmp
[MD5.C18049B07461BF20A6DB2F51908EF673] - |AT| - [28/01/2018 19:57:12] - (.-.) - [22.12 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.b0bep6_v0h5zkzvr86f6f2xih.tmp
[MD5.8AB773C6345F750354783DD5CF338489] - |AT| - [16/09/2018 18:53:05] - (.-.) - [11.83 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.b1dqs2u813jicb9wl7qpre98.tmp
[MD5.A052365BCB72296EB119D9D7488E167F] - |AT| - [18/12/2017 15:35:19] - (.-.) - [10.4 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.b3y47gdd2qfbh2dic4ph1bfdh.tmp
[MD5.C9AE851A3769935907E84397C484F124] - |AT| - [05/08/2017 18:26:32] - (.-.) - [19.25 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.b5by4fk0fthvc53407d7_wbld.tmp
[MD5.14C3A9942E13F6E71552E0F943D599AB] - |AT| - [28/05/2019 17:21:55] - (.-.) - [26.36 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.bikn_xo2tf209tn3vsmswwnmh.tmp
[MD5.78505619F9B00C7F0D5F0AA302C30855] - |AT| - [18/01/2019 23:31:45] - (.-.) - [10.82 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.bk6aeiynrfyzfbtxt3ww4harc.tmp
[MD5.5D2E070CE0CE7577D313AB1BF3662BD2] - |AT| - [11/07/2019 23:36:31] - (.-.) - [8.12 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.blsrjff7wma_aujyxnqwnis1b.tmp
[MD5.5F268231FDDEBF471B0E0911A940B8F9] - |AT| - [28/05/2019 17:23:14] - (.-.) - [7.33 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.bp5it1voio1crdtb6f3v_fz8e.tmp
[MD5.AA41ACCCCAE112EFAE005848341AE42F] - |AT| - [04/04/2019 18:57:47] - (.-.) - [11.85 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.bqcszm7pzc2m04b3twccnl4bc.tmp
[MD5.D41D8CD98F00B204E9800998ECF8427E] - |AT| - [23/09/2018 21:24:15] - (.-.) - [0 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.brpgi4g00cn13edshri45nvgc.tmp
[MD5.CC97E73EA5455E7DC57D568D799EBACD] - |AT| - [22/03/2019 21:50:39] - (.-.) - [35.47 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.bsdg6_4stxyvrvrc7u_7ovo_.tmp
[MD5.0D678C406061953BB8FC3B97A4D2C438] - |AT| - [04/04/2019 18:56:21] - (.-.) - [10.82 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.c0926sxidbk3ldzsafg4pzkud.tmp
[MD5.23B205D66622A59C9CB7AB1A4C147F84] - |AT| - [24/02/2019 01:04:21] - (.-.) - [11.27 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.c99_8dnwrdc2o8srmsqj_340d.tmp
[MD5.328080A177E324FF23DA18182C4D9622] - |AT| - [13/03/2019 21:59:00] - (.-.) - [1.15 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.cef1t90k93kxdvjrt8yfom29g.tmp
[MD5.D41D8CD98F00B204E9800998ECF8427E] - |AT| - [23/09/2018 21:24:15] - (.-.) - [0 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.cfk79t_drffxc4od25pnq7zvb.tmp
[MD5.6AABE9D3762D7BE2C0604820C82F7DEF] - |AT| - [22/09/2018 23:15:10] - (.-.) - [13.28 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.chvpkvavnitpvw64w28pmxl7e.tmp
[MD5.5A34E3A0FB3A388135F19B6C625F1FCA] - |AT| - [04/07/2019 07:49:34] - (.-.) - [23.31 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.cjbgc3xjocfsfp8pu7jj7u9_c.tmp
[MD5.21909A34D58D63FB95BDB5107C682B42] - |AT| - [12/11/2018 19:26:00] - (.-.) - [14.23 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.clwa4mx5sve_l6t5fgjrp5i_c.tmp
[MD5.679F37D0EF70632A9F360B1406337885] - |AT| - [17/04/2019 22:39:39] - (.-.) - [0.93 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.cpoowe7d0alx_zq5sq6dwkmue.tmp
[MD5.95F1F992FC9872B933CBA26014FF849A] - |AT| - [27/06/2019 19:29:46] - (.-.) - [10.94 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.ctgangxts7iyiqdlgk4vlsrfe.tmp
[MD5.9502BE9D2F903EB920F5A07671BA3041] - |AT| - [08/09/2017 23:03:05] - (.-.) - [10.36 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.cwehv83qusb8ub3lqio2g0v4c.tmp
[MD5.90B53E31485F3E8421A7C40902C38704] - |AT| - [11/02/2019 16:11:42] - (.-.) - [5.7 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.cx0fb6a8u0l1gxk7kp9hfr6ue.tmp
[MD5.C817FE0AB90F12E4CD922D5C4ECAAA47] - |AT| - [07/02/2019 23:11:51] - (.-.) - [0.33 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.ddep0c9pe8s3s7ax1pnet869g.tmp
[MD5.DE197305DB11D8EBD215F92F520A17C3] - |AT| - [26/06/2019 13:25:37] - (.-.) - [14.24 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.dgyh78pep18lzgfejo9f3md8b.tmp
[MD5.D41D8CD98F00B204E9800998ECF8427E] - |AT| - [23/09/2018 21:27:35] - (.-.) - [0 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.dm8200z2wwrf1l35_z8y0sprg.tmp
[MD5.64C03122D8C82CCD46703ED0862D3810] - |AT| - [19/04/2019 14:32:05] - (.-.) - [34.8 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.dmp8z80rzqdfkdxfu4fz0635f.tmp
[MD5.472AACE8412A6962B5A7E6D0B54C0B8E] - |AT| - [07/07/2019 10:42:34] - (.-.) - [27.58 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.dzt53439qg1ip73kvptr8cy0.tmp
[MD5.D0913BF914A152971FB7E4EB42197A93] - |AT| - [22/03/2019 23:20:27] - (.-.) - [0.58 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.d_5mbkhn7vmm5d3vq75eevd8.tmp
[MD5.B42EE9C2387BC518D3C38AEA91F5C23A] - |AT| - [05/03/2019 21:42:44] - (.-.) - [71.17 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.eairebxblqi79fg3tkrbsac1h.tmp
[MD5.D207ADC973F6B98347C536523C1469E1] - |AT| - [04/04/2019 18:56:21] - (.-.) - [14.7 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.ejlcu2jialpk2h884yc392wac.tmp
[MD5.DE197305DB11D8EBD215F92F520A17C3] - |AT| - [27/06/2019 19:29:46] - (.-.) - [14.24 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.el9meygkdeog5dv02olmyo19g.tmp
[MD5.7EFA0C948F8EAA5B92963947B1F1CB7A] - |AT| - [13/06/2019 09:20:55] - (.-.) - [0.33 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.ela02mqod7p3uqgezl61a1ihg.tmp
[MD5.955C5076FF66B95CC22E2C7F19E4C54B] - |AT| - [13/03/2019 21:59:00] - (.-.) - [10.87 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.erhf9o26_xy3w8j5pcx_g1dmf.tmp
[MD5.4122ADEEE45828BBFC8DAD94AFDC06E2] - |AT| - [03/07/2019 08:38:32] - (.-.) - [86.96 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.f0w9xmeqfaqpnr46f4ymnbu2h.tmp
[MD5.3700CD07408A4E0B8D6D6EBC48FE2B2E] - |AT| - [04/04/2019 18:37:01] - (.-.) - [14.51 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.f0_gpe9t19bt61nfb8uo8602h.tmp
[MD5.3C11D97FA657C7C033A42FAEA0288EE5] - |AT| - [07/02/2019 23:11:51] - (.-.) - [27.18 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.f18iy8ug67tigfpm_k6c747sg.tmp
[MD5.F2526FD13A6542ACB0A64099E31B2471] - |AT| - [04/04/2019 18:57:47] - (.-.) - [11.03 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.f5xcbbs7zj2p_xjc1_bwds4uc.tmp
[MD5.3C11D97FA657C7C033A42FAEA0288EE5] - |AT| - [11/02/2019 16:11:42] - (.-.) - [27.18 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.f981b_w42a_bf735v0b3af4sg.tmp
[MD5.574BAB1FD5F12B109A220E8EE3E01A97] - |AT| - [04/12/2018 18:36:08] - (.-.) - [277.31 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.fllhqay1q_5bu15iflevif8bc.tmp
[MD5.3B6382F973BD4A6A97DCD25C92F5FAD9] - |AT| - [05/03/2019 21:51:43] - (.-.) - [5.22 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.fo3dzb0bwkm_9xkxorff_f_vg.tmp
[MD5.114EFCA19415C9EDA39AAF69B9CE1841] - |AT| - [25/01/2019 21:05:44] - (.-.) - [18.12 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.fw18bmernewjvk_kjzair0tqg.tmp
[MD5.5AB90371D6EFA3A49C163A3D050E06E1] - |AT| - [20/03/2019 21:03:47] - (.-.) - [7.48 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.fw5viq41a_oxx5nj44nl1kqcg.tmp
[MD5.4DF569E9D6D35FA8D22DA87EF06C7781] - |AT| - [30/01/2019 14:57:20] - (.-.) - [10.78 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.fx3s4ofl72rkb2w9v84uv2vv.tmp
[MD5.114EFCA19415C9EDA39AAF69B9CE1841] - |AT| - [18/01/2019 20:57:57] - (.-.) - [18.12 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.fyr09b138a5w7e67veiw55ywd.tmp
[MD5.7CF99616D5F84EEF34F4B2225A025E9A] - |AT| - [09/01/2019 15:10:31] - (.-.) - [12.79 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.fzcbmclhsl10c2nit303puy6.tmp
[MD5.AD42EEED8258B866A0FD480CD4E7A078] - |AT| - [28/01/2018 19:57:12] - (.-.) - [442.97 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.g1pemsb_yx82v1oy48_55zp1h.tmp
[MD5.FC2CE552F341687E83639596B849F05B] - |AT| - [18/06/2019 19:13:45] - (.-.) - [28.13 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.g6vmb6pnsng1r24jrnej6vldf.tmp
[MD5.0ECCCA45CC3FE62591654AE33F8961A9] - |AT| - [14/08/2017 20:47:32] - (.-.) - [118.91 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.g78p3hnwzpaj0_q4z_ce42x4b.tmp
[MD5.57834323BC7E43D747DD187733FABF22] - |AT| - [18/01/2019 23:31:45] - (.-.) - [20.25 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.gf0tpzqwhyfyye0sk_q3vljoh.tmp
[MD5.AEE7C50C8904365F6A18D835B3AF91AD] - |AT| - [04/04/2019 18:36:52] - (.-.) - [14.24 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.gi2zgfn2agthg61f7uqkb1d_.tmp
[MD5.D41D8CD98F00B204E9800998ECF8427E] - |AT| - [23/09/2018 21:29:47] - (.-.) - [0 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.gigjtrcobtpxdjhba2jszsigd.tmp
[MD5.CC616CEB6188AD8731678331F846D558] - |AT| - [16/09/2018 18:47:34] - (.-.) - [10.82 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.gig_yre9lbulxmyj4oft1v7dg.tmp
[MD5.87C3116E3C8BDCF20FCA892F777F3A81] - |AT| - [27/06/2019 19:40:00] - (.-.) - [10.82 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.gup7bv4m0oer_avj0ghg0wreg.tmp
[MD5.AE97DF760577126EBD3962774214DD73] - |AT| - [04/07/2019 07:58:24] - (.-.) - [10.79 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.g_u0zd7o6g3g00tkcyc9uosbe.tmp
[MD5.83A57F68049491BDC026AB77D92B9CC8] - |AT| - [08/09/2017 23:30:42] - (.-.) - [4.96 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.h4yjleax4gwo84as4apmct1rb.tmp
[MD5.2060EC045F86A58C348387D138D27416] - |AT| - [21/04/2019 23:29:32] - (.-.) - [10.95 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.h9jqui5fpeqi9ahptwzzaw92d.tmp
[MD5.95F361D949DAD6EFE76C105C6B8AB702] - |AT| - [28/05/2019 17:23:14] - (.-.) - [10.82 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.hibom1wyuw0o2ssh62edv6a5c.tmp
[MD5.D41D8CD98F00B204E9800998ECF8427E] - |AT| - [23/09/2018 21:29:47] - (.-.) - [0 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.hmhlout36_9zw3zpmxz3ddz2b.tmp
[MD5.7643D643BB6806B595F03C3A116B34EF] - |AT| - [13/03/2019 21:59:00] - (.-.) - [1.15 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.hnne_4cvgrr7id9bdftafix5g.tmp
[MD5.3FEEF84BE45CB05D263C8A4D4D213F22] - |AT| - [17/04/2019 22:41:37] - (.-.) - [10.79 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.hpjiphr_vbae4sz1oj2uijikh.tmp
[MD5.BC2F68F0DED63F3B7D190CF139F8A9F0] - |AT| - [22/03/2019 23:15:20] - (.-.) - [10.82 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.hva2q78x1ohxn7hgjea6hygwg.tmp
[MD5.0571BD180B2502D2DC6146B092DA3B00] - |AT| - [12/09/2017 22:30:18] - (.-.) - [29.66 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.hyqo2314jx5dmeupcprj0gpee.tmp
[MD5.8647F04503DB20064121F5CED4E74B00] - |AT| - [26/01/2018 00:20:11] - (.-.) - [10.93 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.i7h1n5yob8xxjxybxuwat2p2f.tmp
[MD5.9D2213782EC408F76A295526FBC4E5DF] - |AT| - [15/03/2019 00:15:18] - (.-.) - [10.79 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.idn00m04c539attn6r3ahup2.tmp
[MD5.C8E199EB2E8DAFBD9F3DD91F56A8B49A] - |AT| - [18/01/2019 23:31:45] - (.-.) - [630.02 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.igukp8tj06hb50j_zcf9zpsob.tmp
[MD5.2D9FED77EDBA1EFD23D41CFA4B8CE182] - |AT| - [18/06/2019 19:13:45] - (.-.) - [10.98 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.ijy6bj7j5_ngpoywsa6ytgzpd.tmp
[MD5.67D2E186D38AF0A514165D92ACED951C] - |AT| - [26/01/2018 00:20:11] - (.-.) - [47.22 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.ikenzz6ukl40d88_0ebo3up1c.tmp
[MD5.909E01026B90D1B918DEF495EF29CE64] - |AT| - [12/11/2018 19:23:33] - (.-.) - [15.68 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.io026ip4sjgt01zs_wbxv80uh.tmp
[MD5.449570DA3330888FDA971B7E7DDFB40D] - |AT| - [27/06/2019 19:29:47] - (.-.) - [34.8 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.ixvcneml1te9qr1jo44rzpotc.tmp
[MD5.6869A4219B163E99B51F63B7FA7A45C9] - |AT| - [12/11/2018 19:23:33] - (.-.) - [10.99 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.iy62yuxyz9k1abvhwcbibkebd.tmp
[MD5.88BF0A46A21D685B2C9E58BA06DFB8D7] - |AT| - [12/12/2018 19:07:34] - (.-.) - [72.46 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.iy_dz0iactmx6b09v00fj36md.tmp
[MD5.21E36F2E8A364A3D281E5F8ABA58D108] - |AT| - [12/09/2017 22:15:04] - (.-.) - [0.33 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.j599dyc1a1hvgskpub9oht6ad.tmp
[MD5.D63A91DE8E164EC41C603A7819E875BB] - |AT| - [14/08/2017 20:47:32] - (.-.) - [10.4 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.j6vk1dporqr2af1pcd18hgwme.tmp
[MD5.A1E2DE3222755EA3907CFDCB107F8519] - |AT| - [18/01/2019 23:31:47] - (.-.) - [0.33 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.j810r1t6c_226j5_0uuxbd92e.tmp
[MD5.A578CBE1FCBFBCA54ACF267C93213E63] - |AT| - [01/07/2019 16:50:16] - (.-.) - [11.01 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.j8vq_0j5x9kiztirdl3thnpyb.tmp
[MD5.239E08440A6ABBD3D251C846F18E57B3] - |AT| - [15/03/2019 23:30:09] - (.-.) - [0.33 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.jdoisw84vk3yjpi2_nw4gwbif.tmp
[MD5.C226228352D96506D5F61DBEF173623E] - |AT| - [05/03/2019 21:50:30] - (.-.) - [4.85 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.jdr1ngo5x1c4b440et7mqso9e.tmp
[MD5.C817FE0AB90F12E4CD922D5C4ECAAA47] - |AT| - [10/02/2019 20:39:56] - (.-.) - [0.33 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.je5da441kiy6ytif9a0twsbve.tmp
[MD5.2B7107E35BAC443A003BAA151DBB4B09] - |AT| - [08/02/2019 20:44:37] - (.-.) - [0.79 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.jfl4_w8tizhsmbmk47wm3j5qd.tmp
[MD5.4C681240D2C2D908BA841422DDE0E498] - |AT| - [28/01/2018 20:02:38] - (.-.) - [3.51 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.jfstde9t54qnrpguu91v1d37f.tmp
[MD5.4122ADEEE45828BBFC8DAD94AFDC06E2] - |AT| - [07/07/2019 10:46:39] - (.-.) - [86.96 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.ji2idw8w787rksyyyka1tc9re.tmp
[MD5.1B1402A9BE4C0F8530AD39818E568DAF] - |AT| - [21/01/2019 21:27:44] - (.-.) - [10.79 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.jkqirxrz8ho7uwg53523t0a7.tmp
[MD5.3C7B7C2BAD50C6DD4B0C9F46660F779A] - |AT| - [12/09/2017 22:15:04] - (.-.) - [10.36 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.jl4ysitja3n8fcls4or3cf9xh.tmp
[MD5.8ABC74A72BF4F58C479576BE1E406F5C] - |AT| - [09/01/2019 15:10:31] - (.-.) - [8.12 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.jmpesq930ztboaahu84srtnxb.tmp
[MD5.D5401CBAA0450D2553CD2695BD6A899E] - |AT| - [26/06/2019 13:25:37] - (.-.) - [270.68 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.jmyxbyue72edze8z5koxufkyf.tmp
[MD5.886A6C0576C42C01BAE8805F0DC40A20] - |AT| - [07/02/2019 23:11:51] - (.-.) - [10.99 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.jwb7r0_2kakjh9tnij5gusstc.tmp
[MD5.143A7F1D637465DFD2248689865E927F] - |AT| - [17/04/2019 15:13:26] - (.-.) - [7.12 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.jwcb8pdb1uosb7b2bytsltf4h.tmp
[MD5.449570DA3330888FDA971B7E7DDFB40D] - |AT| - [17/06/2019 23:48:23] - (.-.) - [34.8 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.jxkmz9sdhezdt7ymanw257vmb.tmp
[MD5.151AEB3A86BD2E32421E6079CFB02849] - |AT| - [30/01/2019 14:57:09] - (.-.) - [10.91 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.jyvpqgtnjhb4ghlg56mup910c.tmp
[MD5.C2311ABFC599386CF0FDAB3920771306] - |AT| - [26/06/2019 13:25:37] - (.-.) - [7.12 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.j_m897sxdn6p0d1jgqriacc2f.tmp
[MD5.82E746F8A8281A21B51D7656051AE8E5] - |AT| - [05/03/2019 21:50:30] - (.-.) - [11.85 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.k39msl_464jxram4pcn2kqzng.tmp
[MD5.90B53E31485F3E8421A7C40902C38704] - |AT| - [22/01/2019 23:43:51] - (.-.) - [5.7 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.k5g82rlfb7xfbn5c2e1ugulyc.tmp
[MD5.7D54F416CB6A6C1C5BEDD24010DF3971] - |AT| - [22/03/2019 23:20:27] - (.-.) - [10.78 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.k67pzb1o3ncofi8h05wjg4a2c.tmp
[MD5.604D312D676286C29A82C531DAED5177] - |AT| - [27/06/2019 19:29:47] - (.-.) - [10.79 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.khowpn_mflu4267id3frgh0tb.tmp
[MD5.90B53E31485F3E8421A7C40902C38704] - |AT| - [18/01/2019 23:31:47] - (.-.) - [5.7 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.krwh9gv2evene5eyxhk9jrirg.tmp
[MD5.88A5A6ECE465898AE25EB371667360D4] - |AT| - [17/04/2019 22:39:39] - (.-.) - [10.79 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.ktxetiy1ti3xd9qj9tjc0lqqg.tmp
[MD5.5E089BEDBC5739FC1225906D2DCAA4EC] - |AT| - [22/03/2019 23:20:25] - (.-.) - [26.78 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.ky9d3n27aao7cmqhi_qs6587g.tmp
[MD5.ECCC9721C9EEFCEC5E9032A5D66BE1E6] - |AT| - [01/07/2019 16:55:30] - (.-.) - [0.58 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.l6fxcuqdi83zzun1w_4cp593c.tmp
[MD5.3DDF2FA23C9940D4CDC9E0B650A8337D] - |AT| - [13/03/2019 21:59:00] - (.-.) - [10.82 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.l8ihrer0hrmr_p3z_58yezz2.tmp
[MD5.F8590137CF277895F4EB0FA4F0F69EAF] - |AT| - [17/06/2019 23:48:23] - (.-.) - [0.33 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.lemyntkrren5fk304pf61rbeh.tmp
[MD5.0B5EB7C3E5D4C798292F44E2E7B32263] - |AT| - [28/12/2018 11:35:55] - (.-.) - [0.33 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.lknxi47f9hmkcnrpcyrcwthje.tmp
[MD5.CFD322FDCFD3DA6E3D32465B8B9B5B93] - |AT| - [10/02/2018 14:14:53] - (.-.) - [0.33 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.ll2bmy8wx895_dmsz42j8rhgg.tmp
[MD5.88CDBF0ADA259F09304F0964D02BAFDF] - |AT| - [18/12/2017 15:35:19] - (.-.) - [1.24 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.lr2eunpyqqqwx8x3hucur9df.tmp
[MD5.BC2F68F0DED63F3B7D190CF139F8A9F0] - |AT| - [20/03/2019 21:01:21] - (.-.) - [10.82 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.lsalw1evl4uipdo95q8t3sjse.tmp
[MD5.0CF7345C09E6B33788F755428469FF69] - |AT| - [14/08/2017 20:47:32] - (.-.) - [21.93 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.lspkvve9u53sqf9jouy1sezad.tmp
[MD5.2334E7A3657A02342B6F6B0EFC3318FF] - |AT| - [26/01/2018 00:09:59] - (.-.) - [10.26 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.lsvzqxg9vaw2dxshparll6x6g.tmp
[MD5.601EA41C1C2CE0B536C631C12DBBC6D7] - |AT| - [14/03/2019 23:52:13] - (.-.) - [10.82 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.lvpj_war_yljbrl95bp88sqdd.tmp
[MD5.4E9F45DA53848DD0B209973513D71D8A] - |AT| - [04/04/2019 18:55:13] - (.-.) - [72.25 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.lxpnva9x19uv085k6wr1fsm6f.tmp
[MD5.604D312D676286C29A82C531DAED5177] - |AT| - [17/06/2019 23:48:23] - (.-.) - [10.79 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.lxtbah9pnt8ank5_nctor1xcf.tmp
[MD5.9CD81C2A381B3CDB5243ECD3F1268EAE] - |AT| - [12/11/2018 19:26:00] - (.-.) - [7.12 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.lyyy5zbl9_e074_n2y67twk7e.tmp
[MD5.B30EDF207838C4645651DAF724323702] - |AT| - [01/07/2019 16:50:16] - (.-.) - [79.43 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.m09v6y153aaemyl890hsci8y.tmp
[MD5.6237E96BDE9CC2D03E0261C28CE9B939] - |AT| - [15/03/2019 00:15:18] - (.-.) - [1.44 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.m150amuo7k0muxg764bbms2oc.tmp
[MD5.239E08440A6ABBD3D251C846F18E57B3] - |AT| - [14/03/2019 23:51:01] - (.-.) - [0.33 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.mdl93d9s09gvt19b_09_q_dhh.tmp
[MD5.8D0C02124284B49C39A4F5472596C1FF] - |AT| - [27/06/2019 19:40:00] - (.-.) - [8.78 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.ml3l_j2_dm4872herjumrn4ch.tmp
[MD5.5DCD8DD57AC969F5F8982D3F198DBBE9] - |AT| - [12/11/2018 19:23:33] - (.-.) - [0.33 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.mq9dr13ekedoduiapd19ge6pf.tmp
[MD5.E2834E2E30B4274B70F85D367581D0F9] - |AT| - [08/02/2019 20:44:37] - (.-.) - [4.85 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.mrilzyp_gxu475t3r4mz05jze.tmp
[MD5.4DBA909A465C1E921188221C81471C8E] - |AT| - [16/09/2018 18:47:34] - (.-.) - [23.32 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.mwp7zszdtuv__z0c87cm6ifqf.tmp
[MD5.E031EA53F46B5F90577709F0BA5D2CA8] - |AT| - [07/07/2019 10:42:34] - (.-.) - [10.78 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.mztae8vwcblq687rvac9425sh.tmp
[MD5.C817FE0AB90F12E4CD922D5C4ECAAA47] - |AT| - [11/02/2019 16:11:42] - (.-.) - [0.33 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.n1hfirxs1ivxexp00arfnx0sg.tmp
[MD5.D0913BF914A152971FB7E4EB42197A93] - |AT| - [20/03/2019 21:09:40] - (.-.) - [0.58 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.n3svn8j57scw1e9777jax3ele.tmp
[MD5.563C7EC74F7F21B1CC0732903B440113] - |AT| - [12/09/2017 22:30:18] - (.-.) - [0.33 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.n427daei4_njxzbl59kbpabhg.tmp
[MD5.B1E74AB20E63BCE8481F9647E9D052A2] - |AT| - [17/04/2019 22:34:34] - (.-.) - [8.78 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.n5aqa_9sh_w79wzdlukpx6_1f.tmp
[MD5.9D755E4BC80EEC67C8164705D426D82B] - |AT| - [20/03/2019 21:03:47] - (.-.) - [10.78 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.n64zxr7jmgllvpcxck3a2mgze.tmp
[MD5.692EC20FCC56BC07D5E8D5B10FE802BF] - |AT| - [06/06/2019 15:29:12] - (.-.) - [10.99 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.n8w2madr4be_ofxwy2y12v9i.tmp
[MD5.B6B9DCCA6D41554CE648CF515CE7DBF3] - |AT| - [13/03/2019 21:59:00] - (.-.) - [8.61 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.nehr697j__1hn1o8j477vm17d.tmp
[MD5.2D9FED77EDBA1EFD23D41CFA4B8CE182] - |AT| - [26/06/2019 13:25:38] - (.-.) - [10.98 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.niemc4gq577j1jby0u9mxmbrg.tmp
[MD5.3B9E45518161628BCCB7CA467E2D07DD] - |AT| - [28/05/2019 17:24:26] - (.-.) - [0.44 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.nmi4163qbkzj6iukvbn51rhcd.tmp
[MD5.A1E2DE3222755EA3907CFDCB107F8519] - |AT| - [08/02/2019 22:41:51] - (.-.) - [0.33 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.nqt0giw2lvtnnoc64gv92eodd.tmp
[MD5.E870CF87571A006298A4C960A1342568] - |AT| - [21/02/2019 15:42:57] - (.-.) - [0.33 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.nr4dxermyhw184m7e2z55jfl.tmp
[MD5.C0EEED0BB69A58EAB8FF631CC06F5776] - |AT| - [28/01/2018 19:57:12] - (.-.) - [122.09 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.nsfyayuowfd_01qm680m81z_h.tmp
[MD5.FAE2F3D28C88FC66EE2DF1655D9853B0] - |AT| - [09/01/2019 15:10:31] - (.-.) - [435.34 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.nyl93aq7hgkaqvtrmt75lzk7c.tmp
[MD5.F8590137CF277895F4EB0FA4F0F69EAF] - |AT| - [27/06/2019 19:29:47] - (.-.) - [0.33 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.o0xu4rgqd6k4hva7sw9ayp0hf.tmp
[MD5.C2311ABFC599386CF0FDAB3920771306] - |AT| - [27/06/2019 19:29:46] - (.-.) - [7.12 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.of2yoxiidq3yrvi__frpaty6e.tmp
[MD5.DFFAC982974B3CD3ECD4F93CB70869F4] - |AT| - [16/09/2018 18:53:05] - (.-.) - [0.89 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.og3410dlptmh5j2r19r8hhwue.tmp
[MD5.33E8BFE544CDB88D3CB6112BE475B4D1] - |AT| - [04/12/2018 18:36:08] - (.-.) - [14.22 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.olxph8ww8udcpn33ukafbnv2.tmp
[MD5.1B1402A9BE4C0F8530AD39818E568DAF] - |AT| - [25/01/2019 21:05:44] - (.-.) - [10.79 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.om8k1et26mj2g21f2t3c_f1b.tmp
[MD5.FC2CE552F341687E83639596B849F05B] - |AT| - [26/06/2019 13:25:38] - (.-.) - [28.13 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.ow46w66ecesv0ery7obg6quwg.tmp
[MD5.756B5A88D255196815D1930576E1AFEA] - |AT| - [19/04/2019 14:32:05] - (.-.) - [10.79 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.o_kzjs13dnmxd25mscw3jpp3h.tmp
[MD5.3C93125508E30FE30FB14AB0C0273EF9] - |AT| - [21/01/2019 21:27:44] - (.-.) - [0.33 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.o__h2h9xyktni3og0veg2yt8d.tmp
[MD5.0693A22E830A4D86E9EBCAAE1C9772A5] - |AT| - [04/04/2019 18:55:13] - (.-.) - [266.85 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.p721ts3jdtdft29ksq4tip7bd.tmp
[MD5.CDE735F6C4E93BBE7D3833BECB4DB33A] - |AT| - [08/05/2019 14:44:29] - (.-.) - [0.33 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.p9xj4tjmj8qq9huwj4hln6fhg.tmp
[MD5.143A7F1D637465DFD2248689865E927F] - |AT| - [10/04/2019 16:24:47] - (.-.) - [7.12 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.pghkncd0l_dgp2zg8h9qvlt9g.tmp
[MD5.F27741756A3568F057B24FE6525D25C1] - |AT| - [14/03/2019 23:51:01] - (.-.) - [10.78 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.prviwnraf9itu_oty4uizjyse.tmp
[MD5.3AD13BB1573074051E2BF9CE438D4F24] - |AT| - [04/04/2019 18:36:52] - (.-.) - [10.94 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.pubbgw5l4ij0pw4bsx9_d7c8c.tmp
[MD5.D41D8CD98F00B204E9800998ECF8427E] - |AT| - [23/09/2018 21:29:47] - (.-.) - [0 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.q1mtg8je9ukqon9q0u4h2xmkg.tmp
[MD5.5A6C358D8B0707136C46DFCD4D70E448] - |AT| - [04/07/2019 07:49:34] - (.-.) - [10.82 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.q391b5wxseg_wahn6fe53c6fh.tmp
[MD5.804AE512F34ABED86FA4FC0BFE7B4FD0] - |AT| - [08/05/2019 14:44:29] - (.-.) - [34.8 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.q6swu9o4v0d_fvzqcn53www7d.tmp
[MD5.E08B90F3A5F4A5FEBBE83733262361C0] - |AT| - [16/09/2018 18:47:34] - (.-.) - [459.72 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.q6v8sa1v6o_muotxpiydk2hkf.tmp
[MD5.7C19048423BCF6BF146CE45961B109B1] - |AT| - [08/09/2017 23:30:42] - (.-.) - [10.36 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.q7bt2i4o05eekzaxvrglm82kg.tmp
[MD5.12A2A8DA31DE2DE26BDE7802C5B200CC] - |AT| - [24/02/2019 01:04:21] - (.-.) - [6.2 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.q8kkyg6l9zv9pfw194pt6wv1h.tmp
[MD5.E283D312CAB4E1112A6F9F89D3E2D792] - |AT| - [08/02/2019 20:42:33] - (.-.) - [262.2 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.qm0ca4i0tho6z08qrr3cs64.tmp
[MD5.0AFE90047113C402A3D2887C98F5C21A] - |AT| - [07/03/2019 11:01:03] - (.-.) - [11.03 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.qnfvdhpp5lo4nmyp10ph0w_rd.tmp
[MD5.945C7C3D94AA5F0C92E4EB55561DD336] - |AT| - [08/08/2017 19:34:25] - (.-.) - [6.87 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.qresjv0w5y1lq2z8ks9_lws7e.tmp
[MD5.42A6451D639C83F63FA6E131ADD4E50F] - |AT| - [08/05/2019 14:46:15] - (.-.) - [8.78 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.qzn108w9uza6_4dgi3uwdcnxf.tmp
[MD5.46312F218866F23524D34C3E42DB5B82] - |AT| - [08/09/2017 21:59:14] - (.-.) - [10.4 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.r6kdk16_ep_rln6hluir7s4jf.tmp
[MD5.3C93125508E30FE30FB14AB0C0273EF9] - |AT| - [18/01/2019 20:57:57] - (.-.) - [0.33 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.r8se6g1274aswh1mnfbirsnaf.tmp
[MD5.916BD992B0213E44F1A4D33EFF7582E2] - |AT| - [20/03/2019 21:01:21] - (.-.) - [20.25 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.regevniro7xcvv9svsifj4h_b.tmp
[MD5.A671B53B718F21E826F46D0C3BEA4D7D] - |AT| - [07/03/2019 10:58:25] - (.-.) - [261.98 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.rkiua68xoj6mhb0papjztl1o.tmp
[MD5.1A818C5413DDD75C3DA71B384FCEDCD1] - |AT| - [04/04/2019 18:56:21] - (.-.) - [1.26 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.rnupmbf0uez03cybpo0znp62b.tmp
[MD5.A1E2DE3222755EA3907CFDCB107F8519] - |AT| - [21/01/2019 21:26:54] - (.-.) - [0.33 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.rps_6aqm9082abg0updku8beg.tmp
[MD5.347E2773648409C3B1324E64DEC75755] - |AT| - [08/09/2017 21:59:14] - (.-.) - [256.88 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.ryesqnwmu36ajpwwm_lum48xf.tmp
[MD5.41C1AF8548FB1927132A693EBCCA16C8] - |AT| - [21/04/2019 23:29:31] - (.-.) - [1258.16 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.rz1myq_5ren5bx07hxk90xgn.tmp
[MD5.BAC2140F270C08F16E81DD417E10F6CB] - |AT| - [12/12/2018 19:07:34] - (.-.) - [13.56 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.rzldnx1d1m3imt7tcvd9rhf6b.tmp
[MD5.03D034DC9B73A397042BD8D7376C4FD4] - |AT| - [12/11/2018 19:26:00] - (.-.) - [10.92 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.s4ddape1qeyoz_o33pf2ax7pb.tmp
[MD5.E63B0B8FD747A1DAA374577A74148CC7] - |AT| - [04/07/2019 07:58:24] - (.-.) - [0.51 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.sgxeor0cuur2_hl6dhroi1lp.tmp
[MD5.BF45694DC3B57F8C27EE48DCA7BACA4B] - |AT| - [04/04/2019 18:37:01] - (.-.) - [15.7 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.skf_9ruf73oz5y_a3vxcstzwf.tmp
[MD5.DAAACACBDE19B659FCC12BC86E6FA2C7] - |AT| - [22/03/2019 23:15:20] - (.-.) - [601.85 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.sltvffgr5hv909ikg1hj7xztb.tmp
[MD5.0515288539AEA830A0E53357A68E40A2] - |AT| - [28/12/2018 11:35:55] - (.-.) - [10.98 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.slzcbi_6dshxy3hunwyg08ide.tmp
[MD5.A999800CCDDC031288DB0C09FCE69622] - |AT| - [08/05/2019 14:46:15] - (.-.) - [10.82 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.soirw588eu74g__kwc2gdf8kg.tmp
[MD5.F01C775869051B31DF75BABB1A427A4C] - |AT| - [04/07/2019 07:49:34] - (.-.) - [15.09 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.su1tsvlh1bv34sxlxnip88lph.tmp
[MD5.7796139ED8D10D8542B96A1F9B578437] - |AT| - [16/09/2018 18:47:34] - (.-.) - [146.03 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.t7zs2l8ulypygj98z21qpfmdc.tmp
[MD5.5A6C358D8B0707136C46DFCD4D70E448] - |AT| - [03/07/2019 08:38:32] - (.-.) - [10.82 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.te5ywhwbn1icnagq0vb2q19v.tmp
[MD5.8D6A3FA84F9AA1ED5094E9E8AD1D9FDD] - |AT| - [19/04/2019 14:34:08] - (.-.) - [11.45 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.tkfguiurqm6l41mjtrzslypfc.tmp
[MD5.3ECB3D0BAF04A2443AA86FB14E7A29C0] - |AT| - [17/04/2019 22:41:37] - (.-.) - [0.92 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.tml72px6u3taagkswy7pxt2ae.tmp
[MD5.2209C3B0CB2CAE701E4C40431A6151EF] - |AT| - [28/01/2018 20:02:38] - (.-.) - [0.89 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.tqlhkw6jd1xc7mtxzt7pe_u3c.tmp
[MD5.5D4000E6B25D59224F44E76C084C8CEE] - |AT| - [15/03/2019 00:15:18] - (.-.) - [0.81 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.tsxxuul54bihwgzjyzrnivwh.tmp
[MD5.5482CC75CFC24F648B4BDC761B5BCE5A] - |AT| - [04/04/2019 18:57:47] - (.-.) - [4.99 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.twse2mq86xti9tama225d09ec.tmp
[MD5.FF46FEC68806DE5D4A19288061C7C7B2] - |AT| - [11/07/2019 23:36:31] - (.-.) - [11.02 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.tyw20_l1d1_2tz5dkm2xszq5c.tmp
[MD5.C1D9A2C0A7026201C1092A7F5282F455] - |AT| - [30/01/2019 14:57:20] - (.-.) - [0.33 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.u2rw6ia336x7ea00alqozguhf.tmp
[MD5.1B77401118D6182BD50D97DF3ADCEC56] - |AT| - [13/06/2019 09:20:55] - (.-.) - [10.79 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.u2sa5g6qhg9wn99nsncsk2cke.tmp
[MD5.74EFE60E3DD1401B71103658785358F6] - |AT| - [14/08/2017 20:47:32] - (.-.) - [441.54 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.u5tfexmjf2c23s45p_6ksx4ff.tmp
[MD5.126FA298F95750D2F7C522292CD94C1B] - |AT| - [06/06/2019 15:29:12] - (.-.) - [0.33 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.u6w86mjo9any29djpjrbrk4ic.tmp
[MD5.21E170CB549D6B8201C341CF31F33D30] - |AT| - [08/09/2017 23:03:05] - (.-.) - [0.99 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.u7ck2mrq6ff4qbldaa12_zglg.tmp
[MD5.4A27F35E65B42DFA0BBD92E202B674A3] - |AT| - [08/02/2019 20:44:37] - (.-.) - [11.03 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.ub8p6eiy4m7wv1pnhzmtu4h0c.tmp
[MD5.3CBC0BD7FB4834BAF7F249DD9C57F1FD] - |AT| - [24/02/2019 01:04:40] - (.-.) - [10.79 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.uem_slqqex0m1sfcws0vy2awd.tmp
[MD5.53DF2FCA232A44D27E15A554F0577F10] - |AT| - [04/04/2019 18:37:01] - (.-.) - [1.26 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.umjbtkv3ne4lq60h15vvivxff.tmp
[MD5.7FAB0D2EDE23C62F19635D6354175D2B] - |AT| - [10/02/2018 14:14:53] - (.-.) - [10.36 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.uwb3qypx2pspn6a1a9or3j2lc.tmp
[MD5.3C11D97FA657C7C033A42FAEA0288EE5] - |AT| - [10/02/2019 20:39:56] - (.-.) - [27.18 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.uy_68gb5fz6jhjqhsatb3krif.tmp
[MD5.3131C3141B63DC3A10484AB0074C3871] - |AT| - [20/03/2019 21:01:21] - (.-.) - [84.94 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.v09tm1od8pa50qbfu5eryfrzg.tmp
[MD5.2D1AA03504E1B33E7A98D1DB62CF7AAC] - |AT| - [28/05/2019 17:24:26] - (.-.) - [0.83 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.v20wdbqddpyz9f80b5l5jev1d.tmp
[MD5.FD3BB4B42EBDA8C908309C9F406DC52C] - |AT| - [05/03/2019 21:50:30] - (.-.) - [0.79 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.v30mjrd3271k_1p9icdggs9uc.tmp
[MD5.8FEB58336CF5950FA48D2C8CFF8BDEDF] - |AT| - [24/02/2019 01:04:40] - (.-.) - [15.94 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.v64p5n3zog8uzk5xksdgx3mwh.tmp
[MD5.886A6C0576C42C01BAE8805F0DC40A20] - |AT| - [11/02/2019 16:11:42] - (.-.) - [10.99 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.vf67nnxb4zv5f8exsjq8pqh0f.tmp
[MD5.A2C336F4DEB6B19CAAC3373894AAA220] - |AT| - [01/07/2019 16:50:16] - (.-.) - [13.55 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.vfo_oljc__a324esvy7_pyiwd.tmp
[MD5.1B2C1C0A05FA5887215B368243AA3113] - |AT| - [21/04/2019 23:29:32] - (.-.) - [12.34 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.vpzef6w22emwm3mw3vrud2wjc.tmp
[MD5.7A95EA1528B7E6550E12D004C27DE96F] - |AT| - [05/03/2019 21:51:43] - (.-.) - [4.97 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.vr0buib4iu51_qhpyyuu4t5be.tmp
[MD5.81240CF3C129CCC74C29D65412F9C018] - |AT| - [28/05/2019 17:24:26] - (.-.) - [10.79 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.vrr_uz1gtzrnq7p7poa5jpawe.tmp
[MD5.126FA298F95750D2F7C522292CD94C1B] - |AT| - [19/04/2019 14:32:47] - (.-.) - [0.33 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.vuwrf85khap2miweko9o0e8ch.tmp
[MD5.21974EF734956AE496DFA5345C69EF09] - |AT| - [08/08/2017 19:34:25] - (.-.) - [10.38 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.vw45zgy4yod0_jrwfb8m2rzoe.tmp
[MD5.1079A6F154E849CE0BBE55435405F4D2] - |AT| - [24/02/2019 01:04:21] - (.-.) - [11.03 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.vwdtxgk8tyhcvo7ohr_156crb.tmp
[MD5.BEF5D253A3C2F1EA501B6D0622E7BCCE] - |AT| - [26/01/2018 00:20:11] - (.-.) - [10.3 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.w6001hkehpye67e72w_r7dx8e.tmp
[MD5.6B5904F58AF0FF87067FAE01907459C7] - |AT| - [08/09/2017 21:59:14] - (.-.) - [16.58 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.w86kpzy6hqvz9hqa3gd_dr2y.tmp
[MD5.06E846B1A43B95A90F911C5812B26F6A] - |AT| - [18/01/2019 23:31:46] - (.-.) - [84.94 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.wa0fknexasdlz35qdsh7vg0yd.tmp
[MD5.A0F0E3AFF43DC06060DC05B1B426E4F0] - |AT| - [18/12/2017 15:35:19] - (.-.) - [11.41 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.wahz1f2gigmgu1ejisrj262sg.tmp
[MD5.55D85CB1552AA5D14CCE8B35D03A1390] - |AT| - [26/01/2018 00:09:59] - (.-.) - [0.33 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.wc88cdvm_6acgr6ugn8oe_fae.tmp
[MD5.143A7F1D637465DFD2248689865E927F] - |AT| - [04/04/2019 18:36:52] - (.-.) - [7.12 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.wihlrkxwy6bthbgrqg2aqz1f.tmp
[MD5.D41D8CD98F00B204E9800998ECF8427E] - |AT| - [23/09/2018 21:24:15] - (.-.) - [0 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.wjy6w8hwanl4mlq9ubw03fm_d.tmp
[MD5.1722D18D68DE7935D608608076685481] - |AT| - [28/01/2018 20:02:38] - (.-.) - [11.4 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.wnp_83v9nh_5cl8bp926d3zbg.tmp
[MD5.497D1B32864E11F41EB2D9F0EA718BB5] - |AT| - [11/02/2019 15:49:18] - (.-.) - [11.03 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.x3vzpv583wjq2_v6c2xqtkhtd.tmp
[MD5.90B53E31485F3E8421A7C40902C38704] - |AT| - [29/01/2019 20:11:38] - (.-.) - [5.7 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.xaukb781_egzlhxtmxirgxarg.tmp
[MD5.65D242697B8E6CF8133BDC38833BD987] - |AT| - [08/09/2017 21:59:14] - (.-.) - [95.02 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.xcn5fd3c2t1r1rlhz94wttddh.tmp
[MD5.151AEB3A86BD2E32421E6079CFB02849] - |AT| - [11/02/2019 16:11:42] - (.-.) - [10.91 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.xee_lx6x33auaz68dcsngb1d.tmp
[MD5.AED5CD62580E3FD2A7D4548396273578] - |AT| - [19/04/2019 14:32:05] - (.-.) - [0.33 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.xgab8hwqgp6ac5e4m84typ1_b.tmp
[MD5.D5401CBAA0450D2553CD2695BD6A899E] - |AT| - [27/06/2019 19:29:46] - (.-.) - [270.68 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.xikdygvo2ihhmum5al9c7dl1b.tmp
[MD5.E40AB7D00C64CE6F1683AD4C6DB93F4B] - |AT| - [18/12/2017 15:35:19] - (.-.) - [3.08 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.xiourgpejbyndj9yv76nrpvyg.tmp
[MD5.D41D8CD98F00B204E9800998ECF8427E] - |AT| - [23/09/2018 21:27:35] - (.-.) - [0 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.xj_dru5x_av1kuc8lnr62ayub.tmp
[MD5.E12F0648AC462C1B04DA8D9493940E63] - |AT| - [11/07/2019 23:36:31] - (.-.) - [12.98 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.xllsqvgyb7pqla_7asrvz6m3g.tmp
[MD5.692EC20FCC56BC07D5E8D5B10FE802BF] - |AT| - [19/04/2019 14:32:47] - (.-.) - [10.99 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.xlrare_491si_ldp93gwu6o7c.tmp
[MD5.1B1402A9BE4C0F8530AD39818E568DAF] - |AT| - [18/01/2019 20:57:57] - (.-.) - [10.79 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.xmazyd3lkaxudo_2lmthkhgvf.tmp
[MD5.A4E1229847E0DB128FBA24926666FAA7] - |AT| - [08/05/2019 14:46:15] - (.-.) - [11.45 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.xr17gy_kbumabfnvfj_bxr7df.tmp
[MD5.A1E2DE3222755EA3907CFDCB107F8519] - |AT| - [25/01/2019 21:03:57] - (.-.) - [0.33 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.xx08qf9clhn4f19jzn0dzu64f.tmp
[MD5.9784C3D080DE1D0F424B2913D86636F6] - |AT| - [11/07/2019 23:36:31] - (.-.) - [1607.54 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.y0u525ai1iayhhnxdwayjaaeg.tmp
[MD5.12216AD9371D751523A62E7E8F3C8202] - |AT| - [13/03/2019 21:59:00] - (.-.) - [10.87 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.y38emef26zo4f015ia6l1kldh.tmp
[MD5.C9ECC0BA638EF260B56F96AF65C8B2FE] - |AT| - [28/12/2018 11:35:55] - (.-.) - [17.82 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.y574vif7enrbundk4tz1hoic.tmp
[MD5.3C93125508E30FE30FB14AB0C0273EF9] - |AT| - [22/01/2019 20:20:26] - (.-.) - [0.33 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.y6xeyu7z363or__57v4b9bvng.tmp
[MD5.8B02802142CE4E2C7CFD703805FED21F] - |AT| - [04/04/2019 18:36:52] - (.-.) - [261.34 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.y9o0y1_u8_z6fo26a82l9mvng.tmp
[MD5.0A1FB504018951DD5A09DF2672796824] - |AT| - [13/06/2019 09:20:55] - (.-.) - [2.39 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.y9v3uehmc1p_dfve1eae9qiwb.tmp
[MD5.FE9CCEB424AE4632CF3A176526135B61] - |AT| - [19/04/2019 14:34:08] - (.-.) - [31.2 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.yd1g1k3roc58dymc7u24zqwkd.tmp
[MD5.5D81FADB4E500B5AEF23D0FE91331C25] - |AT| - [12/09/2017 22:30:18] - (.-.) - [10.36 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.yjnsg7ratx4hf183kee96_qic.tmp
[MD5.8B02802142CE4E2C7CFD703805FED21F] - |AT| - [17/04/2019 15:13:26] - (.-.) - [261.34 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.ylii9m0odnmnhr8sv104d7hmd.tmp
[MD5.939EE0001358E2BEFBEFF17FB4F234DB] - |AT| - [09/01/2019 15:10:31] - (.-.) - [11.01 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.ym1g_nqv6ttm_7a1jsp8fzrmb.tmp
[MD5.0DC96D0FA85518729FDA0917D8ED81A2] - |AT| - [08/02/2019 20:44:37] - (.-.) - [11.84 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.ynr4zfpwo0mgh0gsy5vwrtm4g.tmp
[MD5.BFAA6DC22251C91C8ED3440CCEF1DA48] - |AT| - [27/06/2019 19:40:00] - (.-.) - [11.45 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.yoppielre8c4gk5oys56_93mb.tmp
[MD5.4E182A95E4B70325A60CCA50234E6026] - |AT| - [05/08/2017 18:26:32] - (.-.) - [30.66 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.ysc70dpy2u8pj1419qfghnctg.tmp
[MD5.5164E5AEA90D359D681EDD91929FC625] - |AT| - [04/04/2019 18:56:21] - (.-.) - [18.39 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.yvkvwh2se5ensupb1tlqtl27f.tmp
[MD5.B1E74AB20E63BCE8481F9647E9D052A2] - |AT| - [19/04/2019 14:34:08] - (.-.) - [8.78 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.yvrp8ahtda0seklb582_sn2rb.tmp
[MD5.3AD13BB1573074051E2BF9CE438D4F24] - |AT| - [10/04/2019 16:24:47] - (.-.) - [10.94 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.yzkpqei96oz000dsgmjwqbygh.tmp
[MD5.95F1F992FC9872B933CBA26014FF849A] - |AT| - [26/06/2019 13:25:37] - (.-.) - [10.94 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.z8bmc9874d_n4b7epfv9up58b.tmp
[MD5.151AEB3A86BD2E32421E6079CFB02849] - |AT| - [29/01/2019 20:11:38] - (.-.) - [10.91 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.zafsli9ymay6wwwm62q8rbyod.tmp
[MD5.E283D312CAB4E1112A6F9F89D3E2D792] - |AT| - [11/02/2019 15:49:18] - (.-.) - [262.2 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.zaviceev5qirhk31aif7uscvg.tmp
[MD5.4587588AC2B711B0105516BD938F0F37] - |AT| - [05/03/2019 21:42:44] - (.-.) - [10.82 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.zln65rwwochq_z4u3nu8dmylg.tmp
[MD5.A1E2DE3222755EA3907CFDCB107F8519] - |AT| - [06/02/2019 20:53:50] - (.-.) - [0.33 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.zp8iag1xysb9z8gidz63tb0qc.tmp
[MD5.B8CC65C7E8F89A722434FAD57F51C5C3] - |AT| - [12/12/2018 19:07:34] - (.-.) - [11.02 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.zpwcf3mi9bi3iwr2xnfruh00h.tmp
[MD5.A1E2DE3222755EA3907CFDCB107F8519] - |AT| - [30/01/2019 14:57:09] - (.-.) - [0.33 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.zrlxpp64zc5bugv0fdv47m68e.tmp
[MD5.696B17B7C225B478E37CEC2607E2F271] - |AT| - [12/09/2017 22:15:04] - (.-.) - [27.18 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.zrybe2whavfssek05_0y2ng3d.tmp
[MD5.00171F22F322DCB3C726F9ADD6E79037] - |AT| - [22/03/2019 21:50:39] - (.-.) - [0.33 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.zrzu_mlhh4s0xagdplcyqw3ah.tmp
[MD5.F01C775869051B31DF75BABB1A427A4C] - |AT| - [03/07/2019 08:38:32] - (.-.) - [15.09 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX.zts9uglioflarvkw99ham24jg.tmp
[MD5.85614290178DA9C97A6FC77884A9FA81] - |AT| - [22/03/2019 21:50:39] - (.-.) - [10.78 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX._33mm03jjj_o4989o3fidi01e.tmp
[MD5.09BCF439155E1F9CEF8E7919137A3565] - |AT| - [12/12/2018 19:07:35] - (.-.) - [17.07 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX._5vdx_qq703ravc5f9_l84t5d.tmp
[MD5.B7A61DB61566D1E20656E469B597EFF9] - |AT| - [04/07/2019 07:58:24] - (.-.) - [0.86 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX._dsord3zo_9pl6w9t5at_siac.tmp
[MD5.3E6178143B1197FAA2E37313AFB3124D] - |AT| - [07/07/2019 10:42:34] - (.-.) - [0.33 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX._e6o62kz8r02r5wtmh1uptl2c.tmp
[MD5.0B5EB7C3E5D4C798292F44E2E7B32263] - |AT| - [12/12/2018 16:36:27] - (.-.) - [0.33 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX._nbfsegeec6yj9xkqa3nius3.tmp
[MD5.D033240AB7F663DE8E51F5E654DFF94F] - |AT| - [28/05/2019 17:21:55] - (.-.) - [0.33 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX._ra4koxg4_2ri_g4w_85geke.tmp
[MD5.5E089BEDBC5739FC1225906D2DCAA4EC] - |AT| - [14/03/2019 23:51:01] - (.-.) - [26.78 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX._tkqp_etrz_kjtbb7jcr8hfuf.tmp
[MD5.1B1402A9BE4C0F8530AD39818E568DAF] - |AT| - [22/01/2019 20:20:26] - (.-.) - [10.79 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX._wyy6qt7t8_igut68fvuleg6f.tmp
[MD5.EB913E9C3CDB46A5FBD917E5461F0E99] - |AT| - [17/04/2019 22:41:37] - (.-.) - [2.62 Ko] - (0.0.0.0) - C:\Windows\Temp\APPX._z05o4q14xjnev_9vrcwl96ie.tmp
[MD5.5EE0FF0E8947682E5101D764E1323C3D] - |A| - [06/07/2017 21:07:45] - (.-.) - [0.93 Ko] - (0.0.0.0) - C:\Windows\Temp\ASPNETSetup_00000.log
[MD5.F94FC09198269AB7F43225A7A99F78C7] - |A| - [06/07/2017 21:07:47] - (.-.) - [0.94 Ko] - (0.0.0.0) - C:\Windows\Temp\ASPNETSetup_00001.log
[MD5.9D4239ADA6B0F0DBC73AB91D314D4FA5] - |A| - [08/08/2017 11:13:03] - (.-.) - [479.65 Ko] - (0.0.0.0) - C:\Windows\Temp\chrome_installer.log
[MD5.00000000000000000000000000000000] - |D| - [05/01/2018 22:25:26] - [47.81 Ko] - C:\Windows\Temp\cpuz143
[MD5.00000000000000000000000000000000] - |D| - [05/07/2017 19:16:52] - [0.04 Ko] - C:\Windows\Temp\Crashpad
[MD5.00000000000000000000000000000000] - |D| - [06/07/2017 00:53:27] - [16823.43 Ko] - C:\Windows\Temp\CreativeCloud
[MD5.00000000000000000000000000000000] - |D| - [18/06/2019 19:30:09] - [2185.41 Ko] - C:\Windows\Temp\CR_10D29.tmp
[MD5.BDA99AC0F5CE563B153C33574FEB5CD0] - |A| - [05/07/2017 18:48:45] - (.-.) - [8.83 Ko] - (0.0.0.0) - C:\Windows\Temp\dd_vcredist_amd64_20170705184845.log
[MD5.38FA715517C02DC527AE532ECADA3712] - |A| - [05/07/2017 18:48:45] - (.-.) - [167.46 Ko] - (0.0.0.0) - C:\Windows\Temp\dd_vcredist_amd64_20170705184845_0_vcRuntimeMinimum_x64.log
[MD5.118F0AF754A88B20EAE4B33B51DDFC3C] - |A| - [05/07/2017 18:48:45] - (.-.) - [188.09 Ko] - (0.0.0.0) - C:\Windows\Temp\dd_vcredist_amd64_20170705184845_1_vcRuntimeAdditional_x64.log
[MD5.E4183BC9D8919475398C7BE1EC75DCB2] - |A| - [04/09/2017 18:53:24] - (.-.) - [4.63 Ko] - (0.0.0.0) - C:\Windows\Temp\dd_vcredist_amd64_20170904185324.log
[MD5.A996B26C88C6AABBBE9E8E55D61A46D1] - |A| - [05/07/2017 18:48:41] - (.-.) - [8.3 Ko] - (0.0.0.0) - C:\Windows\Temp\dd_vcredist_x86_20170705184841.log
[MD5.C5B42F0577936322686DAFC5C3D4567C] - |A| - [05/07/2017 18:48:43] - (.-.) - [171.5 Ko] - (0.0.0.0) - C:\Windows\Temp\dd_vcredist_x86_20170705184841_0_vcRuntimeMinimum_x86.log
[MD5.722F76D62B0CD7B0B50923D8FC5527D5] - |A| - [05/07/2017 18:48:44] - (.-.) - [199.79 Ko] - (0.0.0.0) - C:\Windows\Temp\dd_vcredist_x86_20170705184841_1_vcRuntimeAdditional_x86.log
[MD5.37801932E4EFF5D040FF0E19771C9586] - |A| - [04/09/2017 18:52:51] - (.-.) - [4.5 Ko] - (0.0.0.0) - C:\Windows\Temp\dd_vcredist_x86_20170904185251.log
[MD5.D41D8CD98F00B204E9800998ECF8427E] - |A| - [05/07/2017 18:49:33] - (.-.) - [0 Ko] - (0.0.0.0) - C:\Windows\Temp\DMI3148.tmp
[MD5.D41D8CD98F00B204E9800998ECF8427E] - |A| - [14/07/2017 16:42:21] - (.-.) - [0 Ko] - (0.0.0.0) - C:\Windows\Temp\DMIAFCE.tmp
[MD5.F9B95EEF19D56EC51ECBEFC27B314B41] - |AHT| - [09/04/2018 18:01:15] - (.-.) - [22290 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_05M2wz7qzUo6pPG
[MD5.7288F0FFE2B0EE87493ABEF8922189A7] - |AHT| - [24/01/2019 09:10:02] - (.-.) - [6628 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_0eX1MKYddfZEQ9U
[MD5.1910A167DC77FB0153D07C8CEE1AB29A] - |AHT| - [29/08/2018 00:20:59] - (.-.) - [0.5 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_0fcdf4p4R92FElE
[MD5.6892271C82D9DC7D8277F70989553CD8] - |AHT| - [19/02/2019 18:07:10] - (.-.) - [3.01 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_0I6qOKlPxHv2XLg
[MD5.65D458015AF62B6D443D42996462F3F8] - |AHT| - [25/05/2018 12:29:20] - (.-.) - [1 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_0VL9msMXatJJXrT
[MD5.66A8AD3E288916786FEE25CC94ECFD3E] - |AHT| - [20/02/2018 18:21:51] - (.-.) - [5.02 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_1A40iLNfMMHDC7B
[MD5.D49CDDEEE7414B124C0BA935E2342A62] - |AHT| - [03/08/2017 00:18:19] - (.-.) - [5.02 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_1b7XDzyuvd6b9zB
[MD5.6892271C82D9DC7D8277F70989553CD8] - |AHT| - [04/08/2018 00:25:07] - (.-.) - [3.01 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_1BoqTSFKXZdfHLM
[MD5.EB1948FF76814F3F74BDD21EE3F34456] - |AHT| - [04/08/2018 00:25:08] - (.-.) - [25715 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_1ERljvgkLiXtChH
[MD5.A06E3490C1B4808B0F919EF47E3ABED6] - |AHT| - [17/04/2018 00:02:35] - (.-.) - [0.5 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_1jZYzEXJYDaijYh
[MD5.177F15476D2C5EBF598B25AEBD6E36F8] - |AHT| - [12/09/2018 23:15:41] - (.-.) - [32101 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_1lOZ3EZh3nm4akw
[MD5.76EA9E1FC723654B5BE6E5C6918DCF7D] - |AHT| - [12/05/2018 00:06:16] - (.-.) - [0.5 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_1W4JelksHJdp4pg
[MD5.586283ED9336C58FA68F4F24F81242F5] - |AHT| - [10/02/2018 01:41:29] - (.-.) - [1 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_1XFf7d5JqwGDCMo
[MD5.676D65363DDBF3CBB3616D1DA82668E8] - |AHT| - [30/12/2018 17:34:23] - (.-.) - [2.01 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_22Aweivd2hVLqjn
[MD5.66A8AD3E288916786FEE25CC94ECFD3E] - |AHT| - [12/09/2018 23:15:41] - (.-.) - [5.02 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_2aymrSzgWt7biRQ
[MD5.A97B6F0CD616241610AA5675AFF2A22A] - |AHT| - [22/08/2018 00:13:30] - (.-.) - [3.01 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_2H5uYWOQqLj9D0j
[MD5.88F6A6675AD5F0DA0EA37EE0CDA448AA] - |AHT| - [12/09/2017 00:13:11] - (.-.) - [25676 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_2NCkKMRbkaQOzFv
[MD5.CC060114FFEDB68BED62E0B651B438E9] - |AHT| - [28/05/2019 23:07:23] - (.-.) - [1 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_2NPvAqtbuoJRawV
[MD5.3FC39FD8BE5B9DF0A636C51FBBC00627] - |AHT| - [30/10/2017 00:50:09] - (.-.) - [0.5 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_2OGhGwKiIvkIysa
[MD5.88C52AEDF976FAE71B4F79A2A79CEEA0] - |AHT| - [11/10/2017 17:04:58] - (.-.) - [1 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_2pUEuexKPOUMXic
[MD5.A97B6F0CD616241610AA5675AFF2A22A] - |AHT| - [09/11/2017 00:56:51] - (.-.) - [3.01 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_3BLNb8HtuDv2Sjj
[MD5.A97B6F0CD616241610AA5675AFF2A22A] - |AHT| - [06/07/2018 22:58:53] - (.-.) - [3.01 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_3BYf5zDUCkX0Z7d
[MD5.890868F34F8E0519B23D8088583953C6] - |AHT| - [02/08/2018 22:58:49] - (.-.) - [1 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_3GewNHUhWHwWArC
[MD5.D0D12FFE8B9A373C9FE100057A5A40E7] - |AHT| - [04/09/2017 19:25:42] - (.-.) - [16.06 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_3OynRNpmKQC3ceX
[MD5.1DD809BD5C54EEA882D2B30542A121A6] - |AHT| - [27/12/2017 02:46:22] - (.-.) - [0.5 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_3syCwm8GUvvtCj9
[MD5.45AA6D94D59323D917B3F06802B399B0] - |AHT| - [10/10/2018 23:00:37] - (.-.) - [57756 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_3T7I5aGhBcr9Z1M
[MD5.A97B6F0CD616241610AA5675AFF2A22A] - |AHT| - [20/12/2017 01:42:57] - (.-.) - [3.01 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_3zgFyRLhqlx7WKk
[MD5.66A8AD3E288916786FEE25CC94ECFD3E] - |AHT| - [06/02/2019 15:34:14] - (.-.) - [5.02 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_41S2KGZ5lacgq0Q
[MD5.B812A120D245B07F9C62EBFEF2F1D656] - |AHT| - [28/01/2018 02:00:02] - (.-.) - [9716 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_44MNeomzeUTs8K3
[MD5.59CD8F02AE9882C706DE305E3868A21A] - |AHT| - [20/01/2019 23:58:38] - (.-.) - [0.5 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_4DYAnB1v3YAbh7i
[MD5.A97B6F0CD616241610AA5675AFF2A22A] - |AHT| - [16/11/2017 01:15:52] - (.-.) - [3.01 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_4mKByxK5X8Og9Of
[MD5.F559A143597F363E25D794C7FA7420EC] - |AHT| - [29/08/2018 00:21:00] - (.-.) - [10009 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_4t6TH58G82qrUxG
[MD5.ADD0217E0C8E9FAFFE0084A7BB9FDC2F] - |AHT| - [12/05/2018 00:06:17] - (.-.) - [9630 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_4uDiAmyK55WBos7
[MD5.A97B6F0CD616241610AA5675AFF2A22A] - |AHT| - [30/10/2018 23:47:58] - (.-.) - [3.01 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_4w9xxVCBzMgd7Jl
[MD5.F5F952F06C1F6059C5983D3B05DA437A] - |AHT| - [07/03/2018 01:12:43] - (.-.) - [25036 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_5aajQEG0Ir1mTua
[MD5.6892271C82D9DC7D8277F70989553CD8] - |AHT| - [07/03/2018 01:12:43] - (.-.) - [3.01 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_5DH8pF3jUE2uRw6
[MD5.37CD458069900B32C75B85E01104ED3E] - |AHT| - [21/03/2018 23:52:33] - (.-.) - [0.5 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_5iRVWG39ERiB4js
[MD5.8B37CCB6567CC75616E647F031237758] - |AHT| - [19/09/2018 23:26:16] - (.-.) - [21558 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_62nL9cumNqr0r7s
[MD5.045E03B19B5FB677976E6DA08833354D] - |AHT| - [08/11/2017 22:42:59] - (.-.) - [1 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_6ddp9kp9ed2VjkT
[MD5.B10200C864EC0416C4238D0526ADFD10] - |AHT| - [20/12/2017 01:42:57] - (.-.) - [16660 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_6fJUhC3KXXNcKKd
[MD5.02676AB47C0BE739E43D8E63F8826C45] - |AHT| - [17/10/2017 07:19:46] - (.-.) - [1 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_6j8if74bznxymDY
[MD5.66A8AD3E288916786FEE25CC94ECFD3E] - |AHT| - [04/01/2018 19:30:39] - (.-.) - [5.02 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_6KMzm9Riz3nOwPa
[MD5.A43BB4AE0ADFEF60E0A29B66A34AD07A] - |AHT| - [22/01/2019 00:38:50] - (.-.) - [7688 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_6LR0oOZX02yrhIL
[MD5.9D471CE1DDF814948122A7C046F1B422] - |AHT| - [16/12/2017 12:55:20] - (.-.) - [1 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_6XgUvK89OT6fo3o
[MD5.A97B6F0CD616241610AA5675AFF2A22A] - |AHT| - [14/12/2018 16:22:08] - (.-.) - [3.01 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_75mRAQRdmH0rPLn
[MD5.A97B6F0CD616241610AA5675AFF2A22A] - |AHT| - [28/11/2018 16:49:55] - (.-.) - [3.01 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_7Cy7ehZ5P7Zg8yK
[MD5.F0889F0BF38D626E578A0558C9C25F2D] - |AHT| - [18/08/2017 01:26:58] - (.-.) - [0.5 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_7rWkka1qq29dHjE
[MD5.75A2009DFF7113427E330DE92E752464] - |AHT| - [06/07/2018 22:58:53] - (.-.) - [0.5 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_7tVr0OAef7k2816
[MD5.14EB9703B9C7F146DFEA00802E5D41DF] - |AHT| - [28/08/2017 23:22:19] - (.-.) - [12.05 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_8BF5pvAJxNVMMoo
[MD5.68309152465FCBEE49CFC49452AF3842] - |AHT| - [12/09/2018 23:15:41] - (.-.) - [0.5 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_8HfwVzdYrkDZqeS
[MD5.D1B06892A5AE27C25940883040D66638] - |AHT| - [31/03/2018 00:08:01] - (.-.) - [0.5 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_8i12O2RAVewDQor
[MD5.6DEA23EC6B884851F27776E36A776BDD] - |AHT| - [02/01/2019 18:10:16] - (.-.) - [0.5 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_8RDHm9vEjtsL78l
[MD5.A97B6F0CD616241610AA5675AFF2A22A] - |AHT| - [27/05/2019 19:31:01] - (.-.) - [3.01 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_8Sdqjjz6EF0RgD2
[MD5.B6973C04F8299C181A859725ED9AEE86] - |AHT| - [31/01/2019 08:57:51] - (.-.) - [1 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_8UT2p0uamRloxg3
[MD5.66A8AD3E288916786FEE25CC94ECFD3E] - |AHT| - [05/10/2018 14:46:12] - (.-.) - [5.02 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_90thu5WgF53fBde
[MD5.7E9F00560F21FD859C651D0AF88282A8] - |AHT| - [15/10/2017 00:26:11] - (.-.) - [23961 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_9SEdeFvIPBtMjfY
[MD5.1A845C3CEBAD454380D6D13D183FC51C] - |AHT| - [21/01/2018 00:16:53] - (.-.) - [28855 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_9TsgNMEmGSPLmR7
[MD5.C5938013A9096CAD633853CDB624D879] - |AHT| - [05/02/2018 01:17:53] - (.-.) - [1 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_9UIN6BPlHJ2dNjv
[MD5.A618639F359C44E464D9FE4A961F3884] - |AHT| - [04/08/2018 00:25:07] - (.-.) - [0.5 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_9v04Lku4DeCXu3Z
[MD5.B15C993520BE622CCCA6C01499E6F8CD] - |AHT| - [28/04/2018 00:48:41] - (.-.) - [101344 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_9VC1M6H0H3IvQe4
[MD5.88D25C43B96D7EA5DEADC2DD1C4F4C8D] - |AHT| - [10/01/2019 08:56:56] - (.-.) - [115956 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_9wcJ6FFqq3EE5bV
[MD5.A228080A9CF9F40719132BD04B3D2E23] - |AHT| - [03/08/2017 00:18:19] - (.-.) - [0.5 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_9ygvpsDbosRA4yJ
[MD5.A97B6F0CD616241610AA5675AFF2A22A] - |AHT| - [28/01/2018 02:00:00] - (.-.) - [3.01 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_a2jZ3tpzPrpTqpy
[MD5.1B5EBEB92B4CC8E48AF34D97323936A0] - |AHT| - [08/03/2019 19:41:22] - (.-.) - [9796 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_a4UV3Aiow5akfen
[MD5.7DA1663D13C0648F2489927755941196] - |AHT| - [26/08/2017 00:48:36] - (.-.) - [5.02 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_a61vpjWPAB9AMVg
[MD5.7509059498F5AB409F89115A44226A5C] - |AHT| - [27/06/2018 16:38:15] - (.-.) - [0.5 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_A9h8v5jNJgaIZxA
[MD5.2AA9B06D2DB37E0FE6CA479CAEDA63B8] - |AHT| - [10/04/2019 22:33:08] - (.-.) - [96420 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_AakelVPiaYCW04C
[MD5.4166464BDFBE14CD6AE2F1D9D4C4F2A7] - |AHT| - [06/10/2017 22:55:45] - (.-.) - [1 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_Aasw96PIodagY2q
[MD5.4D541025F5E950BE4DF5E764A6B9946F] - |AHT| - [11/08/2018 00:28:36] - (.-.) - [0.5 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_AaVuFncF2JDCTlb
[MD5.8D6D8E3CDA0BEBD46E40E3300C4B9681] - |AHT| - [14/03/2018 18:42:56] - (.-.) - [31663 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_abJhyds3KDvGXcK
[MD5.BD77CE71FC2CF64D1E3372B06FE3C4D2] - |AHT| - [20/02/2018 18:21:51] - (.-.) - [35358 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_ATO4cqfMUchlSWd
[MD5.84FA79AB72767AF83F1DE3F3EE8C94C0] - |AHT| - [22/12/2018 00:58:56] - (.-.) - [0.5 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_ausCKqb15jA7vGy
[MD5.CF7826A1BBE7BAF8D5A98A061CE865FC] - |AHT| - [16/06/2019 12:51:24] - (.-.) - [18709 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_b1vlL4lqd0acT9h
[MD5.2F0EC5A586C4FBE9C53717BFDD4A526A] - |AHT| - [03/08/2017 00:18:19] - (.-.) - [5632 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_B7P7J8rj7hg6QDd
[MD5.852D916C78BAFEE9E001E33F2DBE2C56] - |AHT| - [06/07/2018 22:58:54] - (.-.) - [9656 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_bBkBdbEI6IzDCzh
[MD5.A97B6F0CD616241610AA5675AFF2A22A] - |AHT| - [09/04/2018 18:01:15] - (.-.) - [3.01 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_benj0iXn56mBzQZ
[MD5.9A8A972B7174415874FFF124DE167DE5] - |AHT| - [04/01/2018 19:30:39] - (.-.) - [27857 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_bHivq1q7ih0Y7EL
[MD5.A97B6F0CD616241610AA5675AFF2A22A] - |AHT| - [15/10/2017 00:26:11] - (.-.) - [3.01 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_bjgfdlh8tOxgcWs
[MD5.4D0848C0C1B2005C65857FA1322FA48B] - |AHT| - [26/03/2018 17:39:57] - (.-.) - [1 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_BPCtJsdfp2rB12X
[MD5.AF7D0E83927A80EA52034096EA346856] - |AHT| - [27/07/2018 21:28:38] - (.-.) - [30594 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_bpI44cVkwIU8TRJ
[MD5.F5C1428DFE46666E5B87FA2915EA3A66] - |AHT| - [16/11/2017 01:15:52] - (.-.) - [13297 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_BqYQXYQxdn7SDbR
[MD5.527FD23C38AEDFD2CE00C70A1672D933] - |AHT| - [27/07/2018 21:28:37] - (.-.) - [0.5 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_BsZGSv0bTPI42PZ
[MD5.66A8AD3E288916786FEE25CC94ECFD3E] - |AHT| - [05/09/2018 00:49:07] - (.-.) - [5.02 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_bV8se4YsUVvHyJ1
[MD5.1444A02DEB464B4429B286A8BAEB478D] - |AHT| - [28/05/2019 07:57:19] - (.-.) - [1 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_bYdyU1vwb517mSV
[MD5.D2CDFAC7759BC2EA4971AA35D4485577] - |AHT| - [20/06/2018 01:34:30] - (.-.) - [0.5 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_c0yeIoGtuJtNP1g
[MD5.BEECCF11B64235371FC489C12257F1E5] - |AHT| - [22/10/2017 11:19:47] - (.-.) - [22311 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_cDfIYBYQi2Qarqr
[MD5.A97B6F0CD616241610AA5675AFF2A22A] - |AHT| - [30/10/2017 00:50:09] - (.-.) - [3.01 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_CHgQ5umqXCUksvN
[MD5.746F36AC6E2F5E4244709B287CF22C34] - |AHT| - [27/09/2018 18:11:48] - (.-.) - [25688 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_cismD3LQvfsadcf
[MD5.4C074C3DB4404757073E7EB5014DC480] - |AHT| - [02/12/2017 00:43:05] - (.-.) - [0.5 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_cJil68uFeF7Rdgg
[MD5.212F9EC541CE4985F4C46EBE6FF9BCCD] - |AHT| - [20/05/2018 12:51:37] - (.-.) - [0.5 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_cV2mFdwZcAS0d77
[MD5.2EEC4AA01F7889D1EA81A1B0C39CB373] - |AHT| - [18/08/2017 01:26:58] - (.-.) - [5.02 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_cvl8QmmL1WfCKPH
[MD5.A97B6F0CD616241610AA5675AFF2A22A] - |AHT| - [19/09/2017 21:42:50] - (.-.) - [3.01 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_CWYqPEbNVtdX1JP
[MD5.589C3D41F3D7595BBF4746D5BF32EEA1] - |AHT| - [26/04/2018 18:07:57] - (.-.) - [0.5 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_CXKdd0Ml11rYBas
[MD5.ACBAD75F37892611BB22987533A3C265] - |AHT| - [27/05/2019 19:31:01] - (.-.) - [0.5 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_CYFRUOsuolPM1k5
[MD5.2DE370F20C4655092DBE9E545A3C006C] - |AHT| - [14/09/2017 00:01:12] - (.-.) - [1 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_CyR4FvyfbmrlnyW
[MD5.73A7EDA9DAA3F799E086BAC36F09B522] - |AHT| - [28/01/2019 00:11:51] - (.-.) - [16470 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_cZK7OBaD6R8ZeZl
[MD5.040303BF71EF6234A30D28F3B9791FBB] - |AHT| - [30/03/2019 15:29:24] - (.-.) - [111476 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_D08WgOcSv2rONCQ
[MD5.A97B6F0CD616241610AA5675AFF2A22A] - |AHT| - [20/05/2018 12:51:37] - (.-.) - [3.01 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_D1q7KvyZTLsNyeD
[MD5.7D7DCC1D15C04664C2050F947CCF920E] - |AHT| - [11/01/2019 00:08:14] - (.-.) - [11653 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_dfdeSJgQvxoHZCm
[MD5.A97B6F0CD616241610AA5675AFF2A22A] - |AHT| - [21/10/2018 23:34:13] - (.-.) - [3.01 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_DLrcDZdLBe2q6pw
[MD5.159B360604A7BAAC71172CC5A5190E4C] - |AHT| - [20/09/2017 22:48:36] - (.-.) - [1 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_DMXrcSsTVbUILUi
[MD5.BF6191D463CBDF6357027220756F0D1E] - |AHT| - [12/11/2018 16:11:56] - (.-.) - [1 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_DOB2Oh8VhGQpXhz
[MD5.A97B6F0CD616241610AA5675AFF2A22A] - |AHT| - [19/09/2018 23:26:15] - (.-.) - [3.01 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_dRTcm0jQhK7M3Ul
[MD5.DC47096059E95B9E37C3B7083BC3973C] - |AHT| - [27/09/2018 18:11:48] - (.-.) - [0.5 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_Ds8AiYUDkB7OH5r
[MD5.97271D5EEA2FD54DD13BF48043E59EB3] - |AHT| - [24/11/2017 01:42:41] - (.-.) - [32705 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_dsYPr2QBiMDVdOX
[MD5.70A778EDB682BA46133F7E38B27DD2FB] - |AHT| - [07/03/2018 22:40:25] - (.-.) - [1 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_Dt5A3k7PaShqUf7
[MD5.446EA7F8886348C71194AAE6E52E4C2A] - |AHT| - [06/12/2017 14:54:48] - (.-.) - [1 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_DY224juOeIJmssA
[MD5.A97B6F0CD616241610AA5675AFF2A22A] - |AHT| - [28/01/2019 00:11:51] - (.-.) - [3.01 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_DZc4gtFg5717sRj
[MD5.2AC969426E3435CA8F83A989681C4284] - |AHT| - [30/11/2017 23:50:11] - (.-.) - [1160 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_E5lDdXRjW7aoiS5
[MD5.66A8AD3E288916786FEE25CC94ECFD3E] - |AHT| - [20/06/2018 01:34:30] - (.-.) - [5.02 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_e94IXLUU9uCavdk
[MD5.77317B0D6C04536F2D05A1E0E2405F94] - |AHT| - [09/04/2018 18:01:15] - (.-.) - [0.5 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_Eb68FbHs9rKd8ye
[MD5.3F1B9FE66D6101546FEEEADF98ADD2B8] - |AHT| - [20/11/2017 01:14:19] - (.-.) - [1 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_ebEwEXFqJMjQXAd
[MD5.0FC51C86EA5A568D9FB4249D42364093] - |AHT| - [17/04/2019 23:39:46] - (.-.) - [0.5 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_eMcbNLI2cr4ESfy
[MD5.55A8CA8AB195DC169B923686782CC94A] - |AHT| - [31/12/2017 00:12:12] - (.-.) - [103804 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_er4kEJcFksMEARc
[MD5.A61BC38B90E779BA35E466479B8AF1E3] - |AHT| - [18/02/2018 17:28:57] - (.-.) - [1 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_EWeG6ljUJgKFDhl
[MD5.66A8AD3E288916786FEE25CC94ECFD3E] - |AHT| - [22/12/2018 00:58:56] - (.-.) - [5.02 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_Ez3gDjfrUUrcHuM
[MD5.F7505F5DB7ED00FD871B6422C458120C] - |AHT| - [03/05/2018 23:46:09] - (.-.) - [27334 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_F8wNQCDgmX5O4LT
[MD5.A97B6F0CD616241610AA5675AFF2A22A] - |AHT| - [29/04/2019 15:29:06] - (.-.) - [3.01 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_fGCMBURrQ04Nvna
[MD5.2280C18F045ABE96EAEB0783E0FBAE79] - |AHT| - [26/08/2017 00:48:36] - (.-.) - [0.5 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_FH1clL2WMhuPecN
[MD5.A97B6F0CD616241610AA5675AFF2A22A] - |AHT| - [06/10/2017 00:03:24] - (.-.) - [3.01 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_FHQQb99zf7xJ6Av
[MD5.AA4FD56C44B0232AFC8A06CB804B6877] - |AHT| - [18/05/2018 16:21:11] - (.-.) - [1 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_FMIFELKxKGVg9t9
[MD5.D9F9B8122598A12B6F2655B4EC698DDB] - |AHT| - [19/09/2017 21:42:50] - (.-.) - [21173 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_FriHDcqIYOQZEZf
[MD5.E7BAE4169219A56DEED2DFE78E3D51AB] - |AHT| - [29/04/2019 15:29:06] - (.-.) - [22606 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_ftbtFqUisarmh9V
[MD5.CC6BF259BA2706A58EF7946720D23486] - |AHT| - [09/07/2019 00:18:09] - (.-.) - [3488 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_fuhWfslLt7D0oDI
[MD5.6892271C82D9DC7D8277F70989553CD8] - |AHT| - [02/12/2017 00:43:05] - (.-.) - [3.01 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_FuIolpBAXILb6Zj
[MD5.A97B6F0CD616241610AA5675AFF2A22A] - |AHT| - [27/12/2017 02:46:22] - (.-.) - [3.01 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_FvUBpaO1gx3iPMI
[MD5.7A379291D7325A442DDCC835C5EB2AAE] - |AHT| - [24/11/2017 01:42:41] - (.-.) - [0.5 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_FZnsaMB8lHJJWyi
[MD5.E1C2E10E89DDEBFCE9BE08EADB7E2BF9] - |AHT| - [20/12/2017 01:42:57] - (.-.) - [0.5 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_FZT9ZZXFsslI0F4
[MD5.8F88D74A3421771C07CB5F80EEBF4409] - |AHT| - [17/05/2019 23:03:22] - (.-.) - [26384 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_g7ZiTbwTgycYuHQ
[MD5.957CD1E75DF1EB64009F1DB41DF29AEF] - |AHT| - [05/10/2018 14:46:12] - (.-.) - [53724 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_GaCP6swNAvyR2AB
[MD5.A97B6F0CD616241610AA5675AFF2A22A] - |AHT| - [17/04/2018 00:02:35] - (.-.) - [3.01 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_geORIgWeqcPag0v
[MD5.036F9E7FBE94CF5C3E3574C797B19FE9] - |AHT| - [06/10/2017 00:03:24] - (.-.) - [0.5 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_gJqBdhjefprpjND
[MD5.25952EE060695D9B4B38203E14157BB9] - |AHT| - [22/10/2017 11:19:47] - (.-.) - [0.5 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_Gjrn6owocxKNXU5
[MD5.91C5F36945651034D4EBB6D185C65BF0] - |AHT| - [12/10/2018 23:13:23] - (.-.) - [5.02 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_GV6l1CKcy3XJ3MP
[MD5.B92642CE2EB3DCB4D06AFABA5DEC3BF1] - |AHT| - [27/05/2019 19:31:01] - (.-.) - [20336 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_GXRlk65XRa1udUe
[MD5.3029F3C7D768562449494748E20455F4] - |AHT| - [26/08/2017 00:48:37] - (.-.) - [43537 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_HbgWqd3WHkPoAyf
[MD5.4E3E07E1F0CB7F94007F327D2AD621D3] - |AHT| - [06/11/2017 00:43:09] - (.-.) - [1 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_HcapOaIqo9UpuGB
[MD5.D0CD6C25A2AE9370CFD2DB8F195DB2AB] - |AHT| - [06/12/2017 14:50:24] - (.-.) - [1 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_HfgHHNSPlhYSfjD
[MD5.E0D8961C9737E0CEA497D86EE6F89AF0] - |AHT| - [04/06/2018 17:00:27] - (.-.) - [0.5 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_hjSx801ZgM5LqFs
[MD5.B02CDEBA8EF3049E2BB9455E22465DE5] - |AHT| - [20/02/2018 18:21:51] - (.-.) - [0.5 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_Hn8DcsDpZv8xK4Q
[MD5.5D8DE60D1468B248D24A056267D18484] - |AHT| - [18/12/2018 16:55:48] - (.-.) - [1 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_hnccJrlL5a0dA6i
[MD5.31559B3A54AF78AB8CB32D1BAA90DC77] - |AHT| - [14/07/2017 00:42:02] - (.-.) - [0.5 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_hqp2Mx1sP5QL64V
[MD5.A97B6F0CD616241610AA5675AFF2A22A] - |AHT| - [24/03/2019 01:45:35] - (.-.) - [3.01 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_hRKuEsbXeRNd2bG
[MD5.9F88C84C7790978160DC79FB58706649] - |AHT| - [12/09/2017 00:13:11] - (.-.) - [0.5 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_hrpkGbqqSdqCAC9
[MD5.7C86443442D6D883997B692639B44C82] - |AHT| - [02/09/2017 17:21:09] - (.-.) - [3.01 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_htXTHtCehuCUT02
[MD5.CD09828705E9348ABFBC71CDD079114D] - |AHT| - [17/05/2019 23:03:22] - (.-.) - [4.02 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_HU3Z3MYydFxPGbH
[MD5.66A8AD3E288916786FEE25CC94ECFD3E] - |AHT| - [12/01/2018 01:14:31] - (.-.) - [5.02 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_hVx4JAQ5s9fZzOd
[MD5.A97B6F0CD616241610AA5675AFF2A22A] - |AHT| - [16/06/2019 12:51:24] - (.-.) - [3.01 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_I8ayr9pVphc5vLo
[MD5.0D8E8DD07D63970CE04C5267188106C6] - |AHT| - [12/10/2018 23:13:23] - (.-.) - [26801 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_iHseaB4XyRuyeTk
[MD5.5107241E06D7A6EB62EA1E3B96D4D746] - |AHT| - [28/01/2018 02:00:00] - (.-.) - [0.5 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_IVrieAOrmma6hVa
[MD5.F8766513141990A0AD35379DF85568E1] - |AHT| - [29/12/2018 14:43:00] - (.-.) - [97644 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_IZa7LQMexDKHNp5
[MD5.8EFB1E066C53FE47524EB0FF3C22C080] - |AHT| - [30/10/2018 23:47:58] - (.-.) - [0.5 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_J4IlEOk3oTiz7PM
[MD5.22DF21C323B7733FFF0907E25EA531EF] - |AHT| - [24/03/2019 01:45:35] - (.-.) - [20324 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_JdKOmedkASOqHcv
[MD5.2AFCEF5F846EF05143777313B06A31D7] - |AHT| - [22/08/2018 00:13:30] - (.-.) - [0.5 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_JGPwGcZI1hqhqN0
[MD5.19B9FBEE28C50DCD775D1ED95B63BE01] - |AHT| - [02/09/2017 17:21:10] - (.-.) - [12756 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_JhcGguWGh0NPWrd
[MD5.E1E74A54C8B0D32E4691071C019232FB] - |AHT| - [19/02/2019 18:07:10] - (.-.) - [25358 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_jldRdUo7F9BgYRD
[MD5.66A8AD3E288916786FEE25CC94ECFD3E] - |AHT| - [26/04/2018 18:07:57] - (.-.) - [5.02 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_jLSh7LrXWU3KZp0
[MD5.61DEC8584C2B9299F8233FF40AABE459] - |AHT| - [22/12/2018 00:58:56] - (.-.) - [33396 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_JMDwvFsYj96wqfO
[MD5.E93A3272B7DD10C10E4EE1B58FDE2B4C] - |AHT| - [18/05/2018 15:53:27] - (.-.) - [1 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_JnkEaCE91QcEOXc
[MD5.8A3BB3924FB4FB6D8EBAE26E2E7CFFB4] - |AHT| - [20/04/2019 11:38:00] - (.-.) - [1 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_Jou59ZSg2NK3N5o
[MD5.8972296C317CA57DA122C37857FA7F9C] - |AHT| - [03/06/2019 23:11:59] - (.-.) - [0.5 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_JPolodM9BcuIe7Q
[MD5.66A8AD3E288916786FEE25CC94ECFD3E] - |AHT| - [20/01/2019 23:58:38] - (.-.) - [5.02 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_JvBMt3ZXkk7sd6B
[MD5.66A8AD3E288916786FEE25CC94ECFD3E] - |AHT| - [24/11/2017 01:42:41] - (.-.) - [5.02 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_jvNKOAxtlaj1gpN
[MD5.7281A451BAC0051816AE681C10C31F64] - |AHT| - [23/04/2019 11:17:34] - (.-.) - [91508 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_K2AvaP1yTZR4s9d
[MD5.785BCDC25DF66FDDE86C1B300F7F4505] - |AHT| - [04/01/2018 19:30:39] - (.-.) - [0.5 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_k6RxBZesJF2seOA
[MD5.4579268D752DD0642677EDABEF808363] - |AHT| - [05/10/2018 14:46:12] - (.-.) - [0.5 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_KfqOsLQQx3TN7jY
[MD5.3BC29847C95963EAE588A8FF2ECCC2DB] - |AHT| - [11/08/2018 00:28:37] - (.-.) - [9581 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_KkPnOtiK7gBbrz4
[MD5.8421B1BC5B068D74344CF935E1C31F25] - |AHT| - [28/04/2019 19:08:28] - (.-.) - [1 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_KKRr53aLnoKqFLR
[MD5.7E02A70CA6EA31AC209D373F815E86A5] - |AHT| - [06/02/2019 15:34:14] - (.-.) - [0.5 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_kQPtUQbghcX9FCt
[MD5.A97B6F0CD616241610AA5675AFF2A22A] - |AHT| - [10/07/2019 12:12:23] - (.-.) - [3.01 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_KrwiTQZQ9Kj1VaD
[MD5.081E59816DD2C5852024140C92504B6D] - |AHT| - [31/12/2017 01:07:56] - (.-.) - [1 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_KwSIg6CD4qzeokB
[MD5.072F02BD63102A0D34BE7D399590D97A] - |AHT| - [28/01/2019 00:11:51] - (.-.) - [0.5 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_kYMfBJ42wRgOwVD
[MD5.3187F530981AD9CC0BCACD6A80E29DF1] - |AHT| - [01/04/2019 18:37:13] - (.-.) - [1 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_L01cNZGE1CWXW9H
[MD5.A97B6F0CD616241610AA5675AFF2A22A] - |AHT| - [22/10/2017 11:19:47] - (.-.) - [3.01 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_l0puZQBlcRbFTcO
[MD5.B2D36292ACE1179DF44AB1FD6E3BFC97] - |AHT| - [06/07/2019 18:54:37] - (.-.) - [1 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_L1jTYBd0qLxSYml
[MD5.F8766513141990A0AD35379DF85568E1] - |AHT| - [22/09/2018 09:53:55] - (.-.) - [97644 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_leRhFqOc7v9Hpqm
[MD5.53BCFD5408472F6DEF162DEADB0DFDC3] - |AHT| - [31/12/2017 12:23:24] - (.-.) - [101344 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_LgaX7IzdgtPxEuy
[MD5.F51DB88843C6D0F3E446B1C397BC66DE] - |AHT| - [30/09/2018 12:48:25] - (.-.) - [1 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_LnaufTIZib5Go9L
[MD5.3E2B40AD29E51EB89D3628EFA9933BE0] - |AHT| - [18/05/2018 16:10:05] - (.-.) - [8132 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_lsF0ddBIHS3u8WL
[MD5.091B6238EC1FB23949F9E26958FD0BD0] - |AHT| - [17/04/2019 23:39:46] - (.-.) - [11480 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_lUNzCc1RxZaSIU8
[MD5.A97B6F0CD616241610AA5675AFF2A22A] - |AHT| - [11/08/2018 00:28:36] - (.-.) - [3.01 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_m0efyOM9Bg9cy0R
[MD5.C372BF556F1720BAA218E3F963610AEF] - |AHT| - [26/04/2018 18:07:57] - (.-.) - [27733 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_m6ni0DgGBA8DP8p
[MD5.FAEC578BC3DFD2E8F83EA6D5A81C1766] - |AHT| - [31/03/2018 00:08:01] - (.-.) - [9934 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_M9bxAWTsd2Ntv2A
[MD5.1BB2AA8EC3FA62D6CA200C2FCD24719F] - |AHT| - [01/06/2019 01:17:02] - (.-.) - [1 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_mbFsLfbKxKK3PCx
[MD5.5804BDA7657223CF833310016CC171C9] - |AHT| - [09/11/2017 00:56:51] - (.-.) - [0.5 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_mlHwb25kokLiGTF
[MD5.E1AC9296274E93008D554FF8C055C918] - |AHT| - [15/06/2018 20:28:53] - (.-.) - [1 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_MUDYaCjGkLMN1pE
[MD5.8E2BF5471C68F495BAA979D5DFF80C0A] - |AHT| - [28/02/2019 00:47:01] - (.-.) - [1 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_N0cr6OOsZZhgXrE
[MD5.114A8C0F28E58BC3124C9B99CBD7DCBD] - |AHT| - [15/10/2017 00:26:11] - (.-.) - [0.5 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_n6Pbbqto8UdsPVb
[MD5.95E6B69E07D4FA9461AAAD35274C329C] - |AHT| - [11/12/2017 02:01:43] - (.-.) - [0.5 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_nez7enZIWWvakka
[MD5.99CEFB3F10834710E17B0AA0A07FA3C6] - |AHT| - [24/12/2017 12:14:50] - (.-.) - [1 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_nFQywFseI2fLNMn
[MD5.F7570F1352087488370B12538FA98385] - |AHT| - [02/12/2017 00:43:05] - (.-.) - [25342 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_nGhSGWB7NzyjM4M
[MD5.468B4D7C275884405A38353A203B308C] - |AHT| - [08/06/2018 20:15:32] - (.-.) - [1 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_nGptOSoQzynSNZg
[MD5.A97B6F0CD616241610AA5675AFF2A22A] - |AHT| - [02/01/2019 18:10:16] - (.-.) - [3.01 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_NHRbvoLnRk6jLxQ
[MD5.6892271C82D9DC7D8277F70989553CD8] - |AHT| - [27/09/2018 18:11:48] - (.-.) - [3.01 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_nhRcEk4b91vQF0w
[MD5.32371AC6559CD17D2B17B3609C4471BA] - |AHT| - [27/12/2017 02:46:22] - (.-.) - [21972 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_nINpaffoInMzz8u
[MD5.BB8D9358368037403723ABE33170E243] - |AHT| - [30/09/2018 00:14:29] - (.-.) - [1 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_Nm8MlPcoaA9H0de
[MD5.66A8AD3E288916786FEE25CC94ECFD3E] - |AHT| - [28/05/2018 16:28:13] - (.-.) - [5.02 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_NmPaFvmIHj36iZB
[MD5.E6D7691F6C9E02EE5BE6FC4961A32BE8] - |AHT| - [06/10/2017 00:03:25] - (.-.) - [16914 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_ntj59nQfAJu8D2L
[MD5.66A8AD3E288916786FEE25CC94ECFD3E] - |AHT| - [27/07/2018 21:28:37] - (.-.) - [5.02 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_o6OFn3Y9cDb5WqV
[MD5.2A5AE2D010336BEF5049E3A35991EFBD] - |AHT| - [13/02/2018 01:34:12] - (.-.) - [0.5 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_O8ejABOuqn1JlRo
[MD5.7107FD9AD8C0E97918E0A44A42B07C77] - |AHT| - [06/02/2018 00:34:49] - (.-.) - [3.01 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_OatzuJvbvXtWRa8
[MD5.53394809D40DC17BD1FB4F97189303AA] - |AHT| - [13/06/2018 01:06:39] - (.-.) - [0.5 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_OCeEU7RoI1jmwBY
[MD5.278AE7E1F64ED1B37D4AA48E68A54FC7] - |AHT| - [11/08/2017 00:06:40] - (.-.) - [5.02 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_ochcFUbLaxwatOZ
[MD5.A4C17CC2D8B57B8F4248B53236BD3A35] - |AHT| - [01/10/2018 17:46:26] - (.-.) - [106848 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_oe2Nxq0oTZgCv7O
[MD5.CA6007B1EE429B9CDD69993587E5CB61] - |AHT| - [07/03/2018 01:12:43] - (.-.) - [0.5 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_OFCSRKmtJDOqIEe
[MD5.4B83541BC2048C0E09402DF07CF0A44F] - |AHT| - [19/09/2017 21:42:50] - (.-.) - [0.5 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_ohokjD1EIt6sS85
[MD5.99F4A1214DD64F9975E0C26461A94F22] - |AHT| - [14/12/2018 16:22:08] - (.-.) - [24665 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_OJtusZasSkn0JoA
[MD5.19D90C7B5FEE6EA15A8EF0F39EB2989D] - |AHT| - [21/01/2018 00:16:53] - (.-.) - [0.5 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_OjVAQUaHSJTtDOB
[MD5.2D31CB4CBF258C3C8AAFCB5F518E7528] - |AHT| - [19/03/2018 00:13:27] - (.-.) - [1 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_OLNxm2TGY8AEBij
[MD5.E8D01A079600A173ED62890E9F9698B1] - |AHT| - [03/09/2018 18:16:52] - (.-.) - [1 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_oLulBFVQ7NmMMYE
[MD5.64FF4CE73C34F855E399FAC72DF89787] - |AHT| - [22/08/2018 00:13:30] - (.-.) - [22100 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_Onc04m2lIsfgb64
[MD5.66A8AD3E288916786FEE25CC94ECFD3E] - |AHT| - [20/07/2018 01:15:38] - (.-.) - [5.02 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_OsmHxXPtX5PcKSe
[MD5.1A69E4A52FE9690AC985E11C1A5D9D54] - |AHT| - [27/02/2018 18:35:59] - (.-.) - [0.5 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_Ou5gUseW70TBTTn
[MD5.66A8AD3E288916786FEE25CC94ECFD3E] - |AHT| - [04/06/2018 17:00:27] - (.-.) - [5.02 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_oVFB0SHY45Fa674
[MD5.C4793A72CB0979A8EDB9866226AA6191] - |AHT| - [12/01/2018 01:14:31] - (.-.) - [37137 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_ovheJ4Rog18jHJM
[MD5.F7B893259D261717D9B130BA5FD828A7] - |AHT| - [27/06/2018 16:38:15] - (.-.) - [26338 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_p0stX4LDMJF5vMz
[MD5.A846691C9B2A6BBCF173D2DACD3BCCDC] - |AHT| - [11/08/2017 00:06:41] - (.-.) - [16508 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_p78fAKsqVJDMfdl
[MD5.A97B6F0CD616241610AA5675AFF2A22A] - |AHT| - [27/02/2018 18:35:59] - (.-.) - [3.01 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_pceLHmcKlWRfRot
[MD5.57E549B438159E7A6E98E03BF202ECCD] - |AHT| - [10/07/2019 12:12:24] - (.-.) - [11393 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_PnUhO9f9MInemi0
[MD5.1E390256A4A57939A0691E976D696C77] - |AHT| - [24/03/2019 01:45:35] - (.-.) - [0.5 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_PrsCy6dYCmAdPKW
[MD5.B0FF324367E95D5539BDCB975F932659] - |AHT| - [08/11/2017 08:53:46] - (.-.) - [1 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_PSpCD5JBDeOhVPR
[MD5.70FF14DA7C8C00460BD9551979F57884] - |AHT| - [30/10/2018 23:47:58] - (.-.) - [22162 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_ptA5CWroJyRuv0W
[MD5.CD09828705E9348ABFBC71CDD079114D] - |AHT| - [27/06/2018 16:38:15] - (.-.) - [4.02 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_PTFCnHRkvN8Oe2a
[MD5.4F7F4EC8575AF8FEFC51E99B45A2F239] - |AHT| - [21/10/2018 23:34:13] - (.-.) - [0.5 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_q7ApQHoYqWiH1j8
[MD5.786BD4F68BA03E845F0610CD995E288E] - |AHT| - [28/06/2019 22:44:41] - (.-.) - [0.5 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_QcAFuXG4d6RBc3b
[MD5.CDE17A7145A4CE60CB65046F6598C557] - |AHT| - [29/04/2019 15:29:06] - (.-.) - [0.5 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_qCI3KupknXhzR5U
[MD5.ACC07EE3ED51AD36ABA4E99362250D8E] - |AHT| - [05/09/2018 00:49:07] - (.-.) - [36847 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_qHB8IPY25F1Rb4m
[MD5.6892271C82D9DC7D8277F70989553CD8] - |AHT| - [12/09/2017 00:13:11] - (.-.) - [3.01 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_QJD8kTyBz0Rgdxa
[MD5.5885C42971B9FB44FAD9AF140EA429A5] - |AHT| - [21/11/2018 00:57:52] - (.-.) - [0.5 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_qKGjV5bgYJxp0sh
[MD5.8B6577378895AD5AB6E6B884D00053C0] - |AHT| - [06/02/2019 15:34:14] - (.-.) - [28320 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_QNiHJdWW5PUOEAR
[MD5.A97B6F0CD616241610AA5675AFF2A22A] - |AHT| - [17/04/2019 23:39:46] - (.-.) - [3.01 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_qReblfPpagGeXzC
[MD5.638FE4FE18284789DD9C3A94946862EE] - |AHT| - [23/11/2018 11:48:29] - (.-.) - [1 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_qxq7XFWudOrnw33
[MD5.1937D055453B538529B965EA0AC5DCEC] - |AHT| - [21/10/2018 23:34:13] - (.-.) - [10229 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_QXWBEfNSgBD4uko
[MD5.3A9E5DFBD8B801F3D9DEA9FC533050A9] - |AHT| - [19/09/2018 23:26:15] - (.-.) - [0.5 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_R0aXTaTt9cUhza8
[MD5.17976AFE5D3000B3C6FF8E0D778AF3CE] - |AHT| - [14/07/2017 00:42:02] - (.-.) - [2701 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_R2Oe7au9ez3e6FE
[MD5.4392E4DC00B3683977F1F4EF3AA30833] - |AHT| - [21/11/2018 01:18:01] - (.-.) - [1 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_r3eSp2E8FiVSU7y
[MD5.40E76309BE7CB793ACFF31B4674CAFCB] - |AHT| - [30/10/2017 00:50:09] - (.-.) - [9857 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_RDD7dZaIZWO4SHS
[MD5.256610DEE1BD78046B7A9B033EDDF198] - |AHT| - [23/12/2017 14:09:35] - (.-.) - [3336 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_rfWOq3aKbWEDzGE
[MD5.AC7C3232964C33A8D6B38EA33A300EB9] - |AHT| - [06/02/2018 00:34:48] - (.-.) - [0.5 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_RJVe1IzWUJcuBpe
[MD5.11DB20C96CFB5C4A719A0C8B9A7510F3] - |AHT| - [17/04/2018 00:02:35] - (.-.) - [14750 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_RwrWda4F4znrwMC
[MD5.A97B6F0CD616241610AA5675AFF2A22A] - |AHT| - [13/11/2018 00:43:31] - (.-.) - [3.01 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_RwwYd5IvK4pAlJY
[MD5.B2AE5C1A8A6717CDB3B578DE95182807] - |AHT| - [20/07/2018 01:15:38] - (.-.) - [0.5 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_RzyLeYdxOseqsWX
[MD5.8109956D782B5E53EAE3C5E12F37F7D3] - |AHT| - [17/05/2019 23:03:22] - (.-.) - [0.5 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_segoVEuXzx8WKyu
[MD5.A3222FCDA742C930D7D18A9C373FA0B4] - |AHT| - [12/10/2018 23:13:23] - (.-.) - [0.5 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_SFdPIQcgLgZI8AA
[MD5.7DE07B4A88C8334A103FF2102F4A0336] - |AHT| - [10/07/2019 12:12:23] - (.-.) - [0.5 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_sICn5I1aADQ1mr9
[MD5.A97B6F0CD616241610AA5675AFF2A22A] - |AHT| - [03/06/2019 23:11:59] - (.-.) - [3.01 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_sikVqyfO47KLk9m
[MD5.90C36A01AFA8A7EE9D60BA115303DD48] - |AHT| - [31/03/2019 11:02:33] - (.-.) - [0.5 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_SLeQApS5m8VevVF
[MD5.B5BD77B79D65B1A80232399DF2E22951] - |AHT| - [28/11/2018 16:49:56] - (.-.) - [11946 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_sRHAz7ayofyedal
[MD5.A4ED8A2C47714419843D2C1977763646] - |AHT| - [13/06/2018 01:06:39] - (.-.) - [11653 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_steae4yXnFaFoe3
[MD5.D9A24B9DDFA3E9F07356F3F419657FBE] - |AHT| - [01/06/2019 01:11:09] - (.-.) - [1 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_sUzNGpQJv3ExnXo
[MD5.C38102D58A4E45A16306BF79C831B94A] - |AHT| - [11/04/2018 09:31:40] - (.-.) - [1 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_t7c62o2GgGhoIMK
[MD5.7D980E52ECB3573E4106B99417190F4C] - |AHT| - [20/01/2019 23:58:38] - (.-.) - [30991 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_TahmZzMQhxGbFIH
[MD5.0495F8CFC810EC691654102BE6FAAF38] - |AHT| - [06/11/2017 14:54:36] - (.-.) - [1 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_TcqueASQVmykIjx
[MD5.B1DC0BFDF68CDF4C655942075CCE1A97] - |AHT| - [05/02/2018 01:09:28] - (.-.) - [1 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_tEx7U3mUEa2C6Wh
[MD5.CFB993DEA844B78E4AAA85A7E503497A] - |AHT| - [16/11/2017 01:15:52] - (.-.) - [0.5 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_tHPjZAwrqJhJe9c
[MD5.A97B6F0CD616241610AA5675AFF2A22A] - |AHT| - [21/03/2018 23:52:33] - (.-.) - [3.01 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_tK8tqDcB60TT6LQ
[MD5.EC51DA607B611580F5061D4948F07BBB] - |AHT| - [09/11/2017 00:56:52] - (.-.) - [12961 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_tLMm9dMJRciXKIS
[MD5.A97B6F0CD616241610AA5675AFF2A22A] - |AHT| - [11/12/2017 02:01:43] - (.-.) - [3.01 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_TpbE69n3Uyby6Es
[MD5.66A8AD3E288916786FEE25CC94ECFD3E] - |AHT| - [03/05/2018 23:46:09] - (.-.) - [5.02 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_tRDs09OU3hMF1HO
[MD5.5FCE471BA22AFAED0932944C9C006E31] - |AHT| - [19/01/2019 13:46:22] - (.-.) - [1 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_ttTfNfICgWtjvfI
[MD5.A996690FDCE1797FCF4B4F025E6FFF8B] - |AHT| - [14/07/2017 00:42:02] - (.-.) - [5.02 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_tYRmd9m5aW7U5K3
[MD5.16355CB8DA2A11E197EABBE03C530692] - |AHT| - [11/12/2017 02:01:43] - (.-.) - [10219 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_TyZ96tugZMVSC0F
[MD5.FC60427474B864A3281F82CB97C68BA3] - |AHT| - [31/01/2019 17:17:05] - (.-.) - [1 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_u33dvFjxDx9RQ0i
[MD5.5C100618F6A7CDA3CA8E3C893F2B8908] - |AHT| - [28/04/2018 00:19:04] - (.-.) - [1 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_u7ZBJP2qgHz2vCC
[MD5.A97B6F0CD616241610AA5675AFF2A22A] - |AHT| - [29/08/2018 00:20:59] - (.-.) - [3.01 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_UfhXNS5mBCccxVX
[MD5.9D6565AE0C72E3B28086EDBB715488C1] - |AHT| - [12/11/2017 23:30:12] - (.-.) - [1 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_Uhl6x1NVpDJTxzY
[MD5.7C9A95777C9B9CE3513A2D1C206FBD04] - |AHT| - [31/03/2019 11:02:33] - (.-.) - [21138 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_Um18D6eUAk1h1cY
[MD5.4207445B602B57A28D07B189764DC004] - |AHT| - [05/09/2018 00:49:07] - (.-.) - [0.5 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_uQn7ARZ440PrlN6
[MD5.8B5FD19FFB29C08FF1F00D381932791F] - |AHT| - [28/11/2018 16:49:55] - (.-.) - [0.5 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_urbuyaVSSHJak3w
[MD5.9A7EF107122D5C0E335216F4731E2B1A] - |AHT| - [06/11/2017 00:44:21] - (.-.) - [1 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_UsAuRar5aCh0xlN
[MD5.E1C147914D70030C8BAFB09EBC88CF98] - |AHT| - [12/01/2018 01:14:31] - (.-.) - [0.5 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_usMXFXB0dFzqYjE
[MD5.09DACA7D067FDC79A9061B54EDB301AB] - |AHT| - [11/08/2017 00:06:40] - (.-.) - [0.5 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_UttaIffXHEsbvAZ
[MD5.A1E322E7AD1198E2B70CC4C48B473E8B] - |AHT| - [17/12/2018 19:30:02] - (.-.) - [1 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_UVZKt4AlUQlPVzS
[MD5.E282B06EBA7575E253E589C798D52106] - |AHT| - [18/05/2018 16:22:03] - (.-.) - [1 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_VA4tjjKsp9dFQjY
[MD5.66A8AD3E288916786FEE25CC94ECFD3E] - |AHT| - [14/03/2018 18:42:56] - (.-.) - [5.02 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_vd2RliAYbOtAxAs
[MD5.66A8AD3E288916786FEE25CC94ECFD3E] - |AHT| - [21/01/2018 00:16:53] - (.-.) - [5.02 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_VgQEa2DpahZCbus
[MD5.D3EF857470FAB097466BAD1AC89B905C] - |AHT| - [04/06/2018 17:00:27] - (.-.) - [34946 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_vkhGnETyEd64vWa
[MD5.48F5E62BAAD903FE3DC3B71AA7E20DD4] - |AHT| - [20/04/2018 00:02:02] - (.-.) - [1 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_vrLQjzH7GCfKBhb
[MD5.45B47B9A85D82D572FE9771916DD7C3E] - |AHT| - [11/01/2019 00:08:14] - (.-.) - [0.5 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_vVdjJMjrWL8i91O
[MD5.A97B6F0CD616241610AA5675AFF2A22A] - |AHT| - [13/02/2018 01:34:12] - (.-.) - [3.01 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_VwiwHUNOvWQMJcs
[MD5.66A8AD3E288916786FEE25CC94ECFD3E] - |AHT| - [28/06/2019 22:44:41] - (.-.) - [5.02 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_VYdLAEFecXjDpDu
[MD5.A67505B8DB8390E544DF094DF84CCE16] - |AHT| - [27/02/2018 18:35:59] - (.-.) - [21089 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_W04RmTyHVA2FeKX
[MD5.885FAEFF3D459EDD50AFB21C4AB77D51] - |AHT| - [02/09/2017 17:21:09] - (.-.) - [0.5 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_W6ukpvwbmlhFcrF
[MD5.A97B6F0CD616241610AA5675AFF2A22A] - |AHT| - [31/03/2018 00:08:01] - (.-.) - [3.01 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_W9gYAIsAU2voehU
[MD5.F3AF25945883F0E63748D2533BA2B16B] - |AHT| - [03/06/2019 23:12:00] - (.-.) - [9506 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_Wa35Frdqi7QwreR
[MD5.A97B6F0CD616241610AA5675AFF2A22A] - |AHT| - [08/03/2019 19:41:22] - (.-.) - [3.01 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_Wa6iTS0bdHTIxYq
[MD5.A24AB322D08A2064E7AE7E20B354D3BA] - |AHT| - [23/02/2018 18:56:19] - (.-.) - [1 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_WACegvRjMUr7SVQ
[MD5.002E84B58CB37794A5E08C19CBB25785] - |AHT| - [21/11/2018 00:57:53] - (.-.) - [11036 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_WBEhKKGiNuKqhWO
[MD5.A97B6F0CD616241610AA5675AFF2A22A] - |AHT| - [12/05/2018 00:06:16] - (.-.) - [3.01 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_WIldwdvbTo3nR16
[MD5.F890559DE9C0D6965A0C6FF0385136C8] - |AHT| - [13/02/2018 01:34:12] - (.-.) - [20314 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_WLK7w1eEczafDXe
[MD5.6ACE47B5EE423DBD0CA8FFC9D720A41B] - |AHT| - [14/03/2018 18:42:56] - (.-.) - [0.5 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_woH7atE6Qe5dV8l
[MD5.B01ABF77818A16667DD82C55F16F6A43] - |AHT| - [24/12/2017 13:21:19] - (.-.) - [1 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_wYItL3vInLqzvdi
[MD5.0C2F6B07792F1BD04091C630389C344F] - |AHT| - [28/06/2019 22:44:41] - (.-.) - [29648 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_xc3rSavmt9csxZO
[MD5.4253A0CAE3F982288914C0BA0D1330EB] - |AHT| - [21/03/2018 23:52:33] - (.-.) - [22808 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_xcbH9kLBhadX01I
[MD5.6B1A015856684C62B30419F2DE5A4F3A] - |AHT| - [20/06/2018 01:34:30] - (.-.) - [29775 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_xcCx2emzVAc9Vg5
[MD5.7269EE16E0A7EDD6DFF36E3C9E8E2215] - |AHT| - [03/05/2018 23:46:09] - (.-.) - [0.5 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_XNnZ8NXb7IqIRrL
[MD5.C7A20F8C195F2CE8D83E07146F29D49C] - |AHT| - [26/09/2018 18:31:19] - (.-.) - [9284 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_xnY3RBlCaZv2Hpx
[MD5.CC890BE0ACDD60DE163CE33AE9B64AE2] - |AHT| - [28/05/2018 16:28:13] - (.-.) - [36602 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_XSVBPhXRXdmJaar
[MD5.2E068BD57DFD586BD881E2AB26097158] - |AHT| - [20/05/2018 12:51:37] - (.-.) - [20385 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_xuhhST26QFN98Tg
[MD5.5329167910256A6A1AC3E8F66F6B743A] - |AHT| - [18/08/2017 01:26:58] - (.-.) - [246344 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_YabIG1DkdVufDxC
[MD5.4F678E51CE3A084883196A310AA96539] - |AHT| - [14/08/2017 23:20:59] - (.-.) - [24.09 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_YB4TPOpH1yH5XVO
[MD5.A97B6F0CD616241610AA5675AFF2A22A] - |AHT| - [31/03/2019 11:02:33] - (.-.) - [3.01 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_yBdbHQJFT3OxP5l
[MD5.0C30B9C936F03AFF09AF6848612FCD9E] - |AHT| - [04/09/2017 19:20:20] - (.-.) - [16.06 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_YCf0Fqx7YThshvM
[MD5.A97B6F0CD616241610AA5675AFF2A22A] - |AHT| - [13/06/2018 01:06:39] - (.-.) - [3.01 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_ycrsZCNRJpGmqS6
[MD5.7DD4E014DE06E06AC2B9569FF293FBDF] - |AHT| - [08/03/2019 19:41:22] - (.-.) - [0.5 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_yjKAOeNmO8vWRLa
[MD5.F44DD467F86DD207144134E6CC6DE449] - |AHT| - [02/01/2019 18:10:16] - (.-.) - [10614 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_YqcKkOTm7e1pd8v
[MD5.0DCA2AA8AA3219B4FD1880653BE0273A] - |AHT| - [14/12/2018 16:22:08] - (.-.) - [0.5 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_yQjRi0AHEbZ0reT
[MD5.F343CFF9B338447BCCE1717DF222E7D6] - |AHT| - [11/12/2018 15:43:44] - (.-.) - [87804 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_yRd9HR735UQAV9z
[MD5.A97B6F0CD616241610AA5675AFF2A22A] - |AHT| - [21/11/2018 00:57:52] - (.-.) - [3.01 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_yrVvhmP14Pn2cVU
[MD5.7EF7A627018309DAE4E83EA20C97F5BC] - |AHT| - [13/11/2018 00:43:31] - (.-.) - [0.5 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_yTeQBQkIt0EnMmb
[MD5.6FE947C830D95692899C691C9604912F] - |AHT| - [07/03/2018 22:30:42] - (.-.) - [1 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_Yw58m2AqzOLhp5S
[MD5.EF7C6A3902ABFC26E71730B6DE8C6721] - |AHT| - [16/06/2019 12:51:24] - (.-.) - [0.5 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_yy0k1CUaVrqzEl4
[MD5.1ED9D5BBF28B5652F89F8FE312D495E4] - |AHT| - [01/11/2018 02:16:51] - (.-.) - [93960 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_Yzkkigdr2Kq2Sad
[MD5.D9272CED7B8CC233823D64D72B25FCC1] - |AHT| - [19/02/2019 18:07:10] - (.-.) - [0.5 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_yZRa52MEovnLB4d
[MD5.000C9C82CFBB1FEB40A7B452002AC92C] - |AHT| - [22/02/2019 09:07:12] - (.-.) - [1 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_Z8OQPQSHvBRl04i
[MD5.4FA1969EE2386CD359E6BBBE7312D079] - |AHT| - [05/08/2017 18:56:11] - (.-.) - [19.07 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_zCjokoLdX5M1P22
[MD5.41E6368AAEDAA64B0D0D6ADA9FE31CC7] - |AHT| - [13/11/2018 00:43:31] - (.-.) - [23628 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_ZGGnUYCyVqVl93W
[MD5.A97B6F0CD616241610AA5675AFF2A22A] - |AHT| - [11/01/2019 00:08:14] - (.-.) - [3.01 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_ZnCjR3LQRcttaNN
[MD5.DACADC4B16EF419F57D6713DD0DFA5B5] - |AHT| - [20/07/2018 01:15:38] - (.-.) - [38540 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_ZtkwttNrzD8SYUq
[MD5.4311601150188128D36310901B2247B5] - |AHT| - [28/05/2018 16:28:13] - (.-.) - [0.5 Ko] - (0.0.0.0) - C:\Windows\Temp\etilqs_ZvXrW7bNeJjzNEb
[MD5.00000000000000000000000000000000] - |D| - [27/02/2018 21:44:32] - [8649.08 Ko] - C:\Windows\Temp\F9AB5B8C-3CEE-4635-A989-0FEEDE2D244D
[MD5.D41D8CD98F00B204E9800998ECF8427E] - |A| - [05/07/2017 18:27:10] - (.-.) - [0 Ko] - (0.0.0.0) - C:\Windows\Temp\FXSAPIDebugLogFile.txt
[MD5.D41D8CD98F00B204E9800998ECF8427E] - |A| - [05/07/2017 18:27:10] - (.-.) - [0 Ko] - (0.0.0.0) - C:\Windows\Temp\FXSTIFFDebugLogFile.txt
[MD5.D41D8CD98F00B204E9800998ECF8427E] - |A| - [18/02/2019 16:49:16] - (.-.) - [0 Ko] - (0.0.0.0) - C:\Windows\Temp\GUR9064.tmp
[MD5.E81BC96E36DF4C297086C58BDA89435B] - |A| - [10/03/2018 10:08:47] - (.-.) - [17.54 Ko] - (0.0.0.0) - C:\Windows\Temp\HighPerformancePlan.log
[MD5.432E96B218375D76B87D4C622F65BD8C] - |A| - [11/03/2018 11:20:01] - (.-.) - [0.01 Ko] - (0.0.0.0) - C:\Windows\Temp\ipconfig.out
[MD5.2166BD90356070778BA696115AAC2A2A] - |A| - [18/05/2018 16:08:27] - (.(c) <Samsung Electronics>. - Samsung Printer Live Update.) - [1825.57 Ko] - (1.0.0.19) - C:\Windows\Temp\lusetup.exe
[MD5.2864296D23446436B5680B8447F9D29A] - |A| - [26/07/2018 22:58:16] - (.-.) - [3.91 Ko] - (0.0.0.0) - C:\Windows\Temp\mb_setup.log
[MD5.821811E19AD7AD98B1F9C08ACEDE814A] - |A| - [05/07/2017 18:23:04] - (.-.) - [6444.56 Ko] - (0.0.0.0) - C:\Windows\Temp\MpCmdRun.log
[MD5.74942E0F895B02ADE67AB1A63B45774F] - |A| - [05/07/2017 19:01:08] - (.-.) - [368.87 Ko] - (0.0.0.0) - C:\Windows\Temp\MpSigStub.log
[MD5.00000000000000000000000000000000] - |D| - [20/01/2018 13:40:44] - [0 Ko] - C:\Windows\Temp\MPTelemetrySubmit
[MD5.7705B971CF7904628BE2985484118485] - |A| - [10/03/2018 10:08:47] - (.-.) - [0.08 Ko] - (0.0.0.0) - C:\Windows\Temp\PowerPlan.log
[MD5.00000000000000000000000000000000] - |D| - [13/08/2017 19:57:21] - [29 Ko] - C:\Windows\Temp\SDIAG_4f495c04-0518-44e5-8350-74fd1eb8877b
[MD5.00000000000000000000000000000000] - |D| - [05/08/2017 19:44:27] - [29 Ko] - C:\Windows\Temp\SDIAG_e32c1c89-5295-45fe-841b-a524cd0fc3aa
[MD5.00000000000000000000000000000000] - |D| - [15/11/2017 18:31:06] - [29 Ko] - C:\Windows\Temp\SDIAG_f7fdb732-d066-439c-b5b2-e66ad87bcd32
[MD5.D41D8CD98F00B204E9800998ECF8427E] - |A| - [12/12/2018 14:36:34] - (.-.) - [0 Ko] - (0.0.0.0) - C:\Windows\Temp\sed3951.tmp
[MD5.D41D8CD98F00B204E9800998ECF8427E] - |A| - [19/04/2019 11:00:01] - (.-.) - [0 Ko] - (0.0.0.0) - C:\Windows\Temp\sed8F68.tmp
[MD5.D41D8CD98F00B204E9800998ECF8427E] - |A| - [16/12/2018 13:58:07] - (.-.) - [0 Ko] - (0.0.0.0) - C:\Windows\Temp\sedA35D.tmp
[MD5.D41D8CD98F00B204E9800998ECF8427E] - |A| - [08/05/2019 18:44:21] - (.-.) - [0 Ko] - (0.0.0.0) - C:\Windows\Temp\sedB393.tmp
[MD5.500131611986B1FA3DA02D56F3400065] - |A| - [26/07/2018 22:58:15] - (.-.) - [60.25 Ko] - (0.0.0.0) - C:\Windows\Temp\Setup Log 2018-07-26 #001.txt
[MD5.32F437229A70CD4E901D1B9AC47F99B9] - |A| - [05/07/2017 18:26:21] - (.-.) - [0.3 Ko] - (0.0.0.0) - C:\Windows\Temp\temF30A.tmp
[MD5.2D81F7324F73D0F1FD71AA6D803992C6] - |A| - [06/03/2018 20:46:02] - (.-.) - [1.61 Ko] - (0.0.0.0) - C:\Windows\Temp\tpm2CFB.tmp
[MD5.D41D8CD98F00B204E9800998ECF8427E] - |A| - [09/12/2017 15:22:53] - (.-.) - [0 Ko] - (0.0.0.0) - C:\Windows\Temp\tpm33D1.tmp
[MD5.5B3B5AD826E3B95FD1EE0B798CB3E094] - |A| - [18/06/2018 12:18:53] - (.-.) - [1.6 Ko] - (0.0.0.0) - C:\Windows\Temp\tpm6519.tmp
[MD5.011CCC854ED29E0411D2C85D5CE2828F] - |A| - [28/12/2018 11:55:33] - (.-.) - [1.59 Ko] - (0.0.0.0) - C:\Windows\Temp\tpmAFC3.tmp
[MD5.86E43147AD09AC125671F8719BB33CF3] - |A| - [18/04/2019 10:08:32] - (.-.) - [1.58 Ko] - (0.0.0.0) - C:\Windows\Temp\tpmC566.tmp
[MD5.E8029081A942F71D66DF453F5F7EF740] - |A| - [06/01/2018 12:10:34] - (.-.) - [192 Ko] - (0.0.0.0) - C:\Windows\Temp\TS_368C.tmp
[MD5.EB4D3D64C07318CB1F47D84EA5A2ACB9] - |A| - [06/01/2018 12:10:35] - (.-.) - [192 Ko] - (0.0.0.0) - C:\Windows\Temp\TS_3729.tmp
[MD5.295AA25D90DA6AC0ED0269E4985C5E90] - |A| - [04/09/2017 20:02:11] - (.-.) - [320 Ko] - (0.0.0.0) - C:\Windows\Temp\TS_8170.tmp
[MD5.C89C3FCFF3C9D591E3737D72461924B3] - |A| - [19/03/2018 00:08:32] - (.-.) - [256 Ko] - (0.0.0.0) - C:\Windows\Temp\TS_8BB5.tmp
[MD5.3B4EA52AFB38B25F67E04AC72018802D] - |A| - [19/03/2018 00:08:32] - (.-.) - [256 Ko] - (0.0.0.0) - C:\Windows\Temp\TS_8C81.tmp
[MD5.A03CB2D77EB6CEC7E21296CC6EB3E277] - |A| - [19/03/2018 00:08:32] - (.-.) - [256 Ko] - (0.0.0.0) - C:\Windows\Temp\TS_8CA2.tmp
[MD5.FE4E80CA33508B042B2045E8EFFE7091] - |A| - [19/03/2018 00:08:33] - (.-.) - [320 Ko] - (0.0.0.0) - C:\Windows\Temp\TS_8F91.tmp
[MD5.939907B55ADD3E543FE8E2E25676D0CF] - |A| - [04/09/2017 20:01:18] - (.-.) - [320 Ko] - (0.0.0.0) - C:\Windows\Temp\TS_B2A6.tmp
[MD5.6197C761FB58C1D3E56368FDDBC9F788] - |A| - [06/01/2018 12:12:19] - (.-.) - [256 Ko] - (0.0.0.0) - C:\Windows\Temp\TS_CED3.tmp
[MD5.99B5EF6B98BF3DA19A3A0A902FF5B8BB] - |A| - [06/01/2018 12:12:19] - (.-.) - [192 Ko] - (0.0.0.0) - C:\Windows\Temp\TS_CF51.tmp
[MD5.5112B8AE4EDD01B46B98703490D2A834] - |A| - [14/06/2018 20:57:01] - (.-.) - [256 Ko] - (0.0.0.0) - C:\Windows\Temp\TS_FB1C.tmp
[MD5.00000000000000000000000000000000] - |D| - [29/06/2019 08:44:25] - [0 Ko] - C:\Windows\Temp\tw10C9.tmp
[MD5.00000000000000000000000000000000] - |D| - [18/10/2018 09:50:15] - [0 Ko] - C:\Windows\Temp\tw12A0.tmp
[MD5.00000000000000000000000000000000] - |D| - [09/12/2017 15:18:23] - [0 Ko] - C:\Windows\Temp\tw13EA.tmp
[MD5.00000000000000000000000000000000] - |D| - [31/03/2018 13:16:18] - [0 Ko] - C:\Windows\Temp\tw14E9.tmp
[MD5.00000000000000000000000000000000] - |D| - [27/07/2018 21:51:03] - [0 Ko] - C:\Windows\Temp\tw1619.tmp
[MD5.00000000000000000000000000000000] - |D| - [18/10/2018 09:50:16] - [0 Ko] - C:\Windows\Temp\tw164B.tmp
[MD5.00000000000000000000000000000000] - |D| - [29/06/2019 08:44:27] - [0 Ko] - C:\Windows\Temp\tw1659.tmp
[MD5.00000000000000000000000000000000] - |D| - [23/03/2019 15:09:50] - [0 Ko] - C:\Windows\Temp\tw1757.tmp
[MD5.00000000000000000000000000000000] - |D| - [13/05/2019 16:21:47] - [0 Ko] - C:\Windows\Temp\tw1904.tmp
[MD5.00000000000000000000000000000000] - |D| - [13/05/2019 16:22:53] - [0 Ko] - C:\Windows\Temp\tw193E.tmp
[MD5.00000000000000000000000000000000] - |D| - [08/06/2019 11:27:49] - [0 Ko] - C:\Windows\Temp\tw195F.tmp
[MD5.00000000000000000000000000000000] - |D| - [09/12/2017 15:19:30] - [0 Ko] - C:\Windows\Temp\tw1A68.tmp
[MD5.00000000000000000000000000000000] - |D| - [18/10/2018 09:50:17] - [0 Ko] - C:\Windows\Temp\tw1A93.tmp
[MD5.00000000000000000000000000000000] - |D| - [31/03/2018 13:16:21] - [0 Ko] - C:\Windows\Temp\tw1D19.tmp
[MD5.00000000000000000000000000000000] - |D| - [23/08/2017 17:48:06] - [0 Ko] - C:\Windows\Temp\tw1D8D.tmp
[MD5.00000000000000000000000000000000] - |D| - [18/10/2018 09:50:18] - [0 Ko] - C:\Windows\Temp\tw1E2F.tmp
[MD5.00000000000000000000000000000000] - |D| - [21/06/2018 19:20:33] - [0 Ko] - C:\Windows\Temp\tw1EC3.tmp
[MD5.00000000000000000000000000000000] - |D| - [29/06/2019 08:44:29] - [0 Ko] - C:\Windows\Temp\tw203E.tmp
[MD5.00000000000000000000000000000000] - |D| - [18/10/2018 09:50:19] - [0 Ko] - C:\Windows\Temp\tw20FF.tmp
[MD5.00000000000000000000000000000000] - |D| - [09/12/2017 15:18:26] - [0 Ko] - C:\Windows\Temp\tw211B.tmp
[MD5.00000000000000000000000000000000] - |D| - [21/06/2018 19:20:34] - [0 Ko] - C:\Windows\Temp\tw2463.tmp
[MD5.00000000000000000000000000000000] - |D| - [21/06/2018 19:20:34] - [0 Ko] - C:\Windows\Temp\tw2540.tmp
[MD5.00000000000000000000000000000000] - |D| - [21/06/2018 19:20:35] - [0 Ko] - C:\Windows\Temp\tw25CE.tmp
[MD5.00000000000000000000000000000000] - |D| - [18/10/2018 09:50:20] - [0 Ko] - C:\Windows\Temp\tw2612.tmp
[MD5.00000000000000000000000000000000] - |D| - [21/06/2018 19:20:35] - [0 Ko] - C:\Windows\Temp\tw2757.tmp
[MD5.00000000000000000000000000000000] - |D| - [06/03/2018 20:46:01] - [0 Ko] - C:\Windows\Temp\tw27CE.tmp
[MD5.00000000000000000000000000000000] - |D| - [21/06/2018 19:20:35] - [0 Ko] - C:\Windows\Temp\tw2824.tmp
[MD5.00000000000000000000000000000000] - |D| - [27/07/2018 21:51:07] - [0 Ko] - C:\Windows\Temp\tw285B.tmp
[MD5.00000000000000000000000000000000] - |D| - [06/03/2018 20:46:01] - [0 Ko] - C:\Windows\Temp\tw288B.tmp
[MD5.00000000000000000000000000000000] - |D| - [21/06/2018 19:20:35] - [0 Ko] - C:\Windows\Temp\tw28A3.tmp
[MD5.00000000000000000000000000000000] - |D| - [31/03/2018 13:16:24] - [0 Ko] - C:\Windows\Temp\tw2921.tmp
[MD5.00000000000000000000000000000000] - |D| - [06/03/2018 20:46:01] - [0 Ko] - C:\Windows\Temp\tw2939.tmp
[MD5.00000000000000000000000000000000] - |D| - [09/12/2017 15:18:28] - [0 Ko] - C:\Windows\Temp\tw295B.tmp
[MD5.00000000000000000000000000000000] - |D| - [18/10/2018 09:50:21] - [0 Ko] - C:\Windows\Temp\tw297F.tmp
[MD5.00000000000000000000000000000000] - |D| - [21/06/2018 19:20:35] - [0 Ko] - C:\Windows\Temp\tw298F.tmp
[MD5.00000000000000000000000000000000] - |D| - [29/06/2019 08:44:31] - [0 Ko] - C:\Windows\Temp\tw29D5.tmp
[MD5.00000000000000000000000000000000] - |D| - [21/06/2018 19:20:36] - [0 Ko] - C:\Windows\Temp\tw29FF.tmp
[MD5.00000000000000000000000000000000] - |D| - [21/06/2018 19:20:36] - [0 Ko] - C:\Windows\Temp\tw2A3F.tmp
[MD5.00000000000000000000000000000000] - |D| - [06/03/2018 20:46:01] - [0 Ko] - C:\Windows\Temp\tw2A74.tmp
[MD5.00000000000000000000000000000000] - |D| - [21/06/2018 19:20:36] - [0 Ko] - C:\Windows\Temp\tw2ABE.tmp
[MD5.00000000000000000000000000000000] - |D| - [21/06/2018 19:20:36] - [0 Ko] - C:\Windows\Temp\tw2B0E.tmp
[MD5.00000000000000000000000000000000] - |D| - [06/03/2018 20:46:01] - [0 Ko] - C:\Windows\Temp\tw2B12.tmp
[MD5.00000000000000000000000000000000] - |D| - [21/06/2018 19:20:36] - [0 Ko] - C:\Windows\Temp\tw2B7E.tmp
[MD5.00000000000000000000000000000000] - |D| - [21/06/2018 19:20:36] - [0 Ko] - C:\Windows\Temp\tw2BCE.tmp
[MD5.00000000000000000000000000000000] - |D| - [18/10/2018 09:50:21] - [0 Ko] - C:\Windows\Temp\tw2C12.tmp
[MD5.00000000000000000000000000000000] - |D| - [21/06/2018 19:20:36] - [0 Ko] - C:\Windows\Temp\tw2C2E.tmp
[MD5.00000000000000000000000000000000] - |D| - [06/03/2018 20:46:02] - [0 Ko] - C:\Windows\Temp\tw2C6C.tmp
[MD5.00000000000000000000000000000000] - |D| - [21/06/2018 19:20:36] - [0 Ko] - C:\Windows\Temp\tw2C7E.tmp
[MD5.00000000000000000000000000000000] - |D| - [21/06/2018 19:20:36] - [0 Ko] - C:\Windows\Temp\tw2CCE.tmp
[MD5.00000000000000000000000000000000] - |D| - [06/03/2018 20:46:02] - [0 Ko] - C:\Windows\Temp\tw2CFA.tmp
[MD5.00000000000000000000000000000000] - |D| - [18/10/2018 09:50:22] - [0 Ko] - C:\Windows\Temp\tw2EE2.tmp
[MD5.00000000000000000000000000000000] - |D| - [08/06/2019 11:27:55] - [0 Ko] - C:\Windows\Temp\tw2FD7.tmp
[MD5.00000000000000000000000000000000] - |D| - [09/12/2017 15:18:30] - [0 Ko] - C:\Windows\Temp\tw30BF.tmp
[MD5.00000000000000000000000000000000] - |D| - [18/10/2018 09:50:23] - [0 Ko] - C:\Windows\Temp\tw3146.tmp
[MD5.00000000000000000000000000000000] - |D| - [21/06/2018 19:20:38] - [0 Ko] - C:\Windows\Temp\tw31A2.tmp
[MD5.00000000000000000000000000000000] - |D| - [15/09/2018 20:16:37] - [0 Ko] - C:\Windows\Temp\tw31CE.tmp
[MD5.00000000000000000000000000000000] - |D| - [23/03/2019 15:09:57] - [0 Ko] - C:\Windows\Temp\tw31F5.tmp
[MD5.00000000000000000000000000000000] - |D| - [15/09/2018 20:16:37] - [0 Ko] - C:\Windows\Temp\tw320E.tmp
[MD5.00000000000000000000000000000000] - |D| - [15/09/2018 20:16:37] - [0 Ko] - C:\Windows\Temp\tw323F.tmp
[MD5.00000000000000000000000000000000] - |D| - [13/05/2019 16:23:00] - [0 Ko] - C:\Windows\Temp\tw32E3.tmp
[MD5.00000000000000000000000000000000] - |D| - [29/06/2019 08:44:34] - [0 Ko] - C:\Windows\Temp\tw3447.tmp
[MD5.00000000000000000000000000000000] - |D| - [18/10/2018 09:50:24] - [0 Ko] - C:\Windows\Temp\tw3465.tmp
[MD5.00000000000000000000000000000000] - |D| - [07/10/2017 20:07:14] - [0 Ko] - C:\Windows\Temp\tw34C6.tmp
[MD5.00000000000000000000000000000000] - |D| - [15/09/2018 20:16:38] - [0 Ko] - C:\Windows\Temp\tw352F.tmp
[MD5.00000000000000000000000000000000] - |D| - [20/01/2019 10:45:27] - [0 Ko] - C:\Windows\Temp\tw35F1.tmp
[MD5.00000000000000000000000000000000] - |D| - [20/01/2019 10:45:27] - [0 Ko] - C:\Windows\Temp\tw3631.tmp
[MD5.00000000000000000000000000000000] - |D| - [13/05/2019 16:21:55] - [0 Ko] - C:\Windows\Temp\tw36A0.tmp
[MD5.00000000000000000000000000000000] - |D| - [20/01/2019 10:45:27] - [0 Ko] - C:\Windows\Temp\tw36B0.tmp
[MD5.00000000000000000000000000000000] - |D| - [20/01/2019 10:45:27] - [0 Ko] - C:\Windows\Temp\tw36F1.tmp
[MD5.00000000000000000000000000000000] - |D| - [15/09/2018 20:16:38] - [0 Ko] - C:\Windows\Temp\tw3745.tmp
[MD5.00000000000000000000000000000000] - |D| - [20/01/2019 10:45:28] - [0 Ko] - C:\Windows\Temp\tw3760.tmp
[MD5.00000000000000000000000000000000] - |D| - [18/10/2018 09:50:24] - [0 Ko] - C:\Windows\Temp\tw3764.tmp
[MD5.00000000000000000000000000000000] - |D| - [20/01/2019 10:45:28] - [0 Ko] - C:\Windows\Temp\tw3791.tmp
[MD5.00000000000000000000000000000000] - |D| - [20/01/2019 10:45:28] - [0 Ko] - C:\Windows\Temp\tw37B2.tmp
[MD5.00000000000000000000000000000000] - |D| - [23/03/2019 15:08:53] - [0 Ko] - C:\Windows\Temp\tw37B8.tmp
[MD5.00000000000000000000000000000000] - |D| - [20/01/2019 10:45:28] - [0 Ko] - C:\Windows\Temp\tw37D4.tmp
[MD5.00000000000000000000000000000000] - |D| - [20/01/2019 10:45:28] - [0 Ko] - C:\Windows\Temp\tw3814.tmp
[MD5.00000000000000000000000000000000] - |D| - [20/01/2019 10:45:28] - [0 Ko] - C:\Windows\Temp\tw3864.tmp
[MD5.00000000000000000000000000000000] - |D| - [20/01/2019 10:45:28] - [0 Ko] - C:\Windows\Temp\tw38A5.tmp
[MD5.00000000000000000000000000000000] - |D| - [31/03/2018 13:16:28] - [0 Ko] - C:\Windows\Temp\tw38B3.tmp
[MD5.00000000000000000000000000000000] - |D| - [20/01/2019 10:45:28] - [0 Ko] - C:\Windows\Temp\tw38F5.tmp
[MD5.00000000000000000000000000000000] - |D| - [20/01/2019 10:45:28] - [0 Ko] - C:\Windows\Temp\tw3926.tmp
[MD5.00000000000000000000000000000000] - |D| - [20/01/2019 10:45:28] - [0 Ko] - C:\Windows\Temp\tw3985.tmp
[MD5.00000000000000000000000000000000] - |D| - [20/01/2019 10:45:28] - [0 Ko] - C:\Windows\Temp\tw39F5.tmp
[MD5.00000000000000000000000000000000] - |D| - [20/01/2019 10:45:28] - [0 Ko] - C:\Windows\Temp\tw3A45.tmp
[MD5.00000000000000000000000000000000] - |D| - [20/01/2019 10:45:28] - [0 Ko] - C:\Windows\Temp\tw3AA5.tmp
[MD5.00000000000000000000000000000000] - |D| - [18/10/2018 09:50:25] - [0 Ko] - C:\Windows\Temp\tw3AD1.tmp
[MD5.00000000000000000000000000000000] - |D| - [29/06/2018 20:57:42] - [0 Ko] - C:\Windows\Temp\tw3B2D.tmp
[MD5.00000000000000000000000000000000] - |D| - [20/01/2019 10:45:29] - [0 Ko] - C:\Windows\Temp\tw3BA1.tmp
[MD5.00000000000000000000000000000000] - |D| - [15/09/2018 20:16:40] - [0 Ko] - C:\Windows\Temp\tw3BDA.tmp
[MD5.00000000000000000000000000000000] - |D| - [29/06/2019 08:44:36] - [0 Ko] - C:\Windows\Temp\tw3BFA.tmp
[MD5.00000000000000000000000000000000] - |D| - [27/07/2018 21:50:58] - [0 Ko] - C:\Windows\Temp\tw3D5.tmp
[MD5.00000000000000000000000000000000] - |D| - [09/12/2017 15:18:33] - [0 Ko] - C:\Windows\Temp\tw3E00.tmp
[MD5.00000000000000000000000000000000] - |D| - [18/10/2018 09:50:26] - [0 Ko] - C:\Windows\Temp\tw3E01.tmp
[MD5.00000000000000000000000000000000] - |D| - [23/08/2017 17:48:14] - [0 Ko] - C:\Windows\Temp\tw3EA4.tmp
[MD5.00000000000000000000000000000000] - |D| - [23/03/2019 15:08:55] - [0 Ko] - C:\Windows\Temp\tw4084.tmp
[MD5.00000000000000000000000000000000] - |D| - [18/10/2018 09:50:27] - [0 Ko] - C:\Windows\Temp\tw40E0.tmp
[MD5.00000000000000000000000000000000] - |D| - [07/10/2017 20:07:18] - [0 Ko] - C:\Windows\Temp\tw41B8.tmp
[MD5.00000000000000000000000000000000] - |D| - [15/09/2018 20:16:41] - [0 Ko] - C:\Windows\Temp\tw439D.tmp
[MD5.00000000000000000000000000000000] - |D| - [08/06/2019 11:28:00] - [0 Ko] - C:\Windows\Temp\tw43AF.tmp
[MD5.00000000000000000000000000000000] - |D| - [09/12/2017 15:18:35] - [0 Ko] - C:\Windows\Temp\tw43CE.tmp
[MD5.00000000000000000000000000000000] - |D| - [27/07/2018 21:51:14] - [0 Ko] - C:\Windows\Temp\tw4403.tmp
[MD5.00000000000000000000000000000000] - |D| - [18/10/2018 09:50:28] - [0 Ko] - C:\Windows\Temp\tw447C.tmp
[MD5.00000000000000000000000000000000] - |D| - [29/06/2018 20:57:45] - [0 Ko] - C:\Windows\Temp\tw44D4.tmp
[MD5.00000000000000000000000000000000] - |D| - [29/06/2019 08:44:39] - [0 Ko] - C:\Windows\Temp\tw45CF.tmp
[MD5.00000000000000000000000000000000] - |D| - [23/03/2019 15:08:57] - [0 Ko] - C:\Windows\Temp\tw470E.tmp
[MD5.00000000000000000000000000000000] - |D| - [15/09/2018 20:16:42] - [0 Ko] - C:\Windows\Temp\tw4748.tmp
[MD5.00000000000000000000000000000000] - |D| - [23/03/2019 15:10:02] - [0 Ko] - C:\Windows\Temp\tw4793.tmp
[MD5.00000000000000000000000000000000] - |D| - [13/05/2019 16:23:06] - [0 Ko] - C:\Windows\Temp\tw4A84.tmp
[MD5.00000000000000000000000000000000] - |D| - [07/10/2017 20:07:19] - [0 Ko] - C:\Windows\Temp\tw4AC3.tmp
[MD5.00000000000000000000000000000000] - |D| - [18/10/2018 09:50:29] - [0 Ko] - C:\Windows\Temp\tw4AE7.tmp
[MD5.00000000000000000000000000000000] - |D| - [15/09/2018 20:16:44] - [0 Ko] - C:\Windows\Temp\tw4B71.tmp
[MD5.00000000000000000000000000000000] - |D| - [29/06/2018 20:57:47] - [0 Ko] - C:\Windows\Temp\tw4CB6.tmp
[MD5.00000000000000000000000000000000] - |D| - [23/03/2019 15:08:59] - [0 Ko] - C:\Windows\Temp\tw4EFF.tmp
[MD5.00000000000000000000000000000000] - |D| - [23/08/2017 17:47:13] - [0 Ko] - C:\Windows\Temp\tw4F2F.tmp
[MD5.00000000000000000000000000000000] - |D| - [29/06/2019 08:44:41] - [0 Ko] - C:\Windows\Temp\tw4FD4.tmp
[MD5.00000000000000000000000000000000] - |D| - [31/03/2018 13:16:34] - [0 Ko] - C:\Windows\Temp\tw5229.tmp
[MD5.00000000000000000000000000000000] - |D| - [15/09/2018 20:16:46] - [0 Ko] - C:\Windows\Temp\tw53CF.tmp
[MD5.00000000000000000000000000000000] - |D| - [28/06/2019 19:48:19] - [0 Ko] - C:\Windows\Temp\tw547F.tmp
[MD5.D41D8CD98F00B204E9800998ECF8427E] - |A| - [29/06/2018 20:57:49] - (.-.) - [0 Ko] - (0.0.0.0) - C:\Windows\Temp\tw54E5.tmp
[MD5.00000000000000000000000000000000] - |D| - [28/06/2019 19:48:19] - [0 Ko] - C:\Windows\Temp\tw54EF.tmp
[MD5.00000000000000000000000000000000] - |D| - [28/06/2019 19:48:19] - [0 Ko] - C:\Windows\Temp\tw556E.tmp
[MD5.00000000000000000000000000000000] - |D| - [23/03/2019 15:09:00] - [0 Ko] - C:\Windows\Temp\tw55A8.tmp
[MD5.00000000000000000000000000000000] - |D| - [28/06/2019 19:48:19] - [0 Ko] - C:\Windows\Temp\tw55BE.tmp
[MD5.00000000000000000000000000000000] - |D| - [09/12/2017 15:18:39] - [0 Ko] - C:\Windows\Temp\tw566E.tmp
[MD5.00000000000000000000000000000000] - |D| - [28/06/2019 19:48:20] - [0 Ko] - C:\Windows\Temp\tw569B.tmp
[MD5.00000000000000000000000000000000] - |D| - [08/03/2019 21:18:22] - [0 Ko] - C:\Windows\Temp\tw56C5.tmp
[MD5.00000000000000000000000000000000] - |D| - [09/02/2018 22:48:24] - [0 Ko] - C:\Windows\Temp\tw5727.tmp
[MD5.00000000000000000000000000000000] - |D| - [29/06/2019 08:44:43] - [0 Ko] - C:\Windows\Temp\tw58BF.tmp
[MD5.00000000000000000000000000000000] - |D| - [31/03/2018 13:17:20] - [0 Ko] - C:\Windows\Temp\tw58D.tmp
[MD5.00000000000000000000000000000000] - |D| - [13/05/2019 16:22:04] - [0 Ko] - C:\Windows\Temp\tw5A09.tmp
[MD5.00000000000000000000000000000000] - |D| - [08/06/2019 11:28:06] - [0 Ko] - C:\Windows\Temp\tw5B7F.tmp
[MD5.00000000000000000000000000000000] - |D| - [27/07/2018 21:51:20] - [0 Ko] - C:\Windows\Temp\tw5BB3.tmp
[MD5.00000000000000000000000000000000] - |D| - [23/03/2019 15:09:02] - [0 Ko] - C:\Windows\Temp\tw5C23.tmp
[MD5.00000000000000000000000000000000] - |D| - [15/09/2018 20:16:48] - [0 Ko] - C:\Windows\Temp\tw5CDA.tmp
[MD5.00000000000000000000000000000000] - |D| - [28/06/2019 19:48:22] - [0 Ko] - C:\Windows\Temp\tw5EAB.tmp
[MD5.00000000000000000000000000000000] - |D| - [18/06/2018 12:18:51] - [0 Ko] - C:\Windows\Temp\tw5F36.tmp
[MD5.00000000000000000000000000000000] - |D| - [29/06/2019 08:44:45] - [0 Ko] - C:\Windows\Temp\tw6024.tmp
[MD5.00000000000000000000000000000000] - |D| - [18/06/2018 12:18:52] - [0 Ko] - C:\Windows\Temp\tw60BF.tmp
[MD5.00000000000000000000000000000000] - |D| - [13/05/2019 16:23:12] - [0 Ko] - C:\Windows\Temp\tw6244.tmp
[MD5.00000000000000000000000000000000] - |D| - [18/06/2018 12:18:52] - [0 Ko] - C:\Windows\Temp\tw6296.tmp
[MD5.00000000000000000000000000000000] - |D| - [09/12/2017 15:21:59] - [0 Ko] - C:\Windows\Temp\tw62B4.tmp
[MD5.00000000000000000000000000000000] - |D| - [15/09/2018 20:16:49] - [0 Ko] - C:\Windows\Temp\tw62C8.tmp
[MD5.00000000000000000000000000000000] - |D| - [23/03/2019 15:09:04] - [0 Ko] - C:\Windows\Temp\tw632A.tmp
[MD5.00000000000000000000000000000000] - |D| - [09/02/2018 22:48:27] - [0 Ko] - C:\Windows\Temp\tw639D.tmp
[MD5.00000000000000000000000000000000] - |D| - [31/03/2018 13:16:39] - [0 Ko] - C:\Windows\Temp\tw641D.tmp
[MD5.00000000000000000000000000000000] - |D| - [18/06/2018 12:18:53] - [0 Ko] - C:\Windows\Temp\tw6509.tmp
[MD5.00000000000000000000000000000000] - |D| - [08/06/2019 11:27:44] - [0 Ko] - C:\Windows\Temp\tw652.tmp
[MD5.00000000000000000000000000000000] - |D| - [02/12/2018 15:02:14] - [0 Ko] - C:\Windows\Temp\tw660.tmp
[MD5.00000000000000000000000000000000] - |D| - [07/10/2017 20:07:27] - [0 Ko] - C:\Windows\Temp\tw68FB.tmp
[MD5.00000000000000000000000000000000] - |D| - [29/06/2019 08:44:48] - [0 Ko] - C:\Windows\Temp\tw694D.tmp
[MD5.00000000000000000000000000000000] - |D| - [28/06/2019 19:48:25] - [0 Ko] - C:\Windows\Temp\tw69C9.tmp
[MD5.00000000000000000000000000000000] - |D| - [15/09/2018 20:16:51] - [0 Ko] - C:\Windows\Temp\tw69DE.tmp
[MD5.00000000000000000000000000000000] - |D| - [09/12/2017 15:18:20] - [0 Ko] - C:\Windows\Temp\tw6B9.tmp
[MD5.00000000000000000000000000000000] - |D| - [09/12/2017 15:18:45] - [0 Ko] - C:\Windows\Temp\tw6C79.tmp
[MD5.00000000000000000000000000000000] - |D| - [23/03/2019 15:09:06] - [0 Ko] - C:\Windows\Temp\tw6C82.tmp
[MD5.00000000000000000000000000000000] - |D| - [08/12/2018 13:36:29] - [0 Ko] - C:\Windows\Temp\tw6CD5.tmp
[MD5.00000000000000000000000000000000] - |D| - [08/12/2018 13:36:29] - [0 Ko] - C:\Windows\Temp\tw6D16.tmp
[MD5.00000000000000000000000000000000] - |D| - [08/12/2018 13:36:29] - [0 Ko] - C:\Windows\Temp\tw6D66.tmp
[MD5.00000000000000000000000000000000] - |D| - [09/02/2018 22:48:30] - [0 Ko] - C:\Windows\Temp\tw6DFF.tmp
[MD5.00000000000000000000000000000000] - |D| - [08/12/2018 13:36:30] - [0 Ko] - C:\Windows\Temp\tw6E33.tmp
[MD5.00000000000000000000000000000000] - |D| - [08/12/2018 13:36:30] - [0 Ko] - C:\Windows\Temp\tw6E54.tmp
[MD5.00000000000000000000000000000000] - |D| - [08/12/2018 13:36:30] - [0 Ko] - C:\Windows\Temp\tw6E95.tmp
[MD5.00000000000000000000000000000000] - |D| - [08/12/2018 13:36:30] - [0 Ko] - C:\Windows\Temp\tw6EC5.tmp
[MD5.00000000000000000000000000000000] - |D| - [08/12/2018 13:36:30] - [0 Ko] - C:\Windows\Temp\tw6F06.tmp
[MD5.00000000000000000000000000000000] - |D| - [08/12/2018 13:36:30] - [0 Ko] - C:\Windows\Temp\tw6F75.tmp
[MD5.00000000000000000000000000000000] - |D| - [08/12/2018 13:36:30] - [0 Ko] - C:\Windows\Temp\tw6FA6.tmp
[MD5.00000000000000000000000000000000] - |D| - [15/09/2018 20:16:53] - [0 Ko] - C:\Windows\Temp\tw7058.tmp
[MD5.00000000000000000000000000000000] - |D| - [27/07/2018 21:51:26] - [0 Ko] - C:\Windows\Temp\tw718F.tmp
[MD5.00000000000000000000000000000000] - |D| - [29/06/2019 08:44:50] - [0 Ko] - C:\Windows\Temp\tw71CB.tmp
[MD5.00000000000000000000000000000000] - |D| - [08/03/2019 21:17:22] - [0 Ko] - C:\Windows\Temp\tw725E.tmp
[MD5.00000000000000000000000000000000] - |D| - [08/12/2018 13:36:31] - [0 Ko] - C:\Windows\Temp\tw7342.tmp
[MD5.00000000000000000000000000000000] - |D| - [31/03/2018 13:16:43] - [0 Ko] - C:\Windows\Temp\tw73DE.tmp
[MD5.00000000000000000000000000000000] - |D| - [08/03/2019 21:17:22] - [0 Ko] - C:\Windows\Temp\tw7405.tmp
[MD5.00000000000000000000000000000000] - |D| - [08/03/2019 21:17:22] - [0 Ko] - C:\Windows\Temp\tw7456.tmp
[MD5.00000000000000000000000000000000] - |D| - [08/06/2019 11:28:13] - [0 Ko] - C:\Windows\Temp\tw7497.tmp
[MD5.00000000000000000000000000000000] - |D| - [28/06/2019 19:48:28] - [0 Ko] - C:\Windows\Temp\tw74A8.tmp
[MD5.00000000000000000000000000000000] - |D| - [26/08/2017 12:10:57] - [0 Ko] - C:\Windows\Temp\tw7624.tmp
[MD5.00000000000000000000000000000000] - |D| - [15/09/2018 20:16:54] - [0 Ko] - C:\Windows\Temp\tw76A4.tmp
[MD5.00000000000000000000000000000000] - |D| - [26/08/2017 12:10:57] - [0 Ko] - C:\Windows\Temp\tw76D2.tmp
[MD5.00000000000000000000000000000000] - |D| - [08/03/2019 21:17:24] - [0 Ko] - C:\Windows\Temp\tw76D8.tmp
[MD5.00000000000000000000000000000000] - |D| - [26/08/2017 12:10:57] - [0 Ko] - C:\Windows\Temp\tw7703.tmp
[MD5.00000000000000000000000000000000] - |D| - [26/08/2017 12:10:57] - [0 Ko] - C:\Windows\Temp\tw77D0.tmp
[MD5.00000000000000000000000000000000] - |D| - [26/08/2017 12:10:57] - [0 Ko] - C:\Windows\Temp\tw7820.tmp
[MD5.00000000000000000000000000000000] - |D| - [26/08/2017 12:10:57] - [0 Ko] - C:\Windows\Temp\tw78EE.tmp
[MD5.00000000000000000000000000000000] - |D| - [13/05/2019 16:22:12] - [0 Ko] - C:\Windows\Temp\tw7999.tmp
[MD5.00000000000000000000000000000000] - |D| - [26/08/2017 12:10:58] - [0 Ko] - C:\Windows\Temp\tw79AB.tmp
[MD5.00000000000000000000000000000000] - |D| - [08/12/2018 13:36:33] - [0 Ko] - C:\Windows\Temp\tw79BC.tmp
[MD5.00000000000000000000000000000000] - |D| - [13/05/2019 16:23:18] - [0 Ko] - C:\Windows\Temp\tw79E5.tmp
[MD5.00000000000000000000000000000000] - |D| - [09/02/2018 22:48:33] - [0 Ko] - C:\Windows\Temp\tw79E8.tmp
[MD5.00000000000000000000000000000000] - |D| - [26/08/2017 12:10:58] - [0 Ko] - C:\Windows\Temp\tw7A1A.tmp
[MD5.00000000000000000000000000000000] - |D| - [26/08/2017 12:10:58] - [0 Ko] - C:\Windows\Temp\tw7A8A.tmp
[MD5.00000000000000000000000000000000] - |D| - [29/06/2019 08:44:52] - [0 Ko] - C:\Windows\Temp\tw7AD6.tmp
[MD5.00000000000000000000000000000000] - |D| - [26/08/2017 12:10:58] - [0 Ko] - C:\Windows\Temp\tw7B38.tmp
[MD5.00000000000000000000000000000000] - |D| - [26/08/2017 12:10:58] - [0 Ko] - C:\Windows\Temp\tw7B97.tmp
[MD5.00000000000000000000000000000000] - |D| - [26/08/2017 12:10:58] - [0 Ko] - C:\Windows\Temp\tw7C26.tmp
[MD5.00000000000000000000000000000000] - |D| - [26/08/2017 12:10:58] - [0 Ko] - C:\Windows\Temp\tw7C57.tmp
[MD5.00000000000000000000000000000000] - |D| - [26/08/2017 12:10:58] - [0 Ko] - C:\Windows\Temp\tw7C97.tmp
[MD5.00000000000000000000000000000000] - |D| - [26/08/2017 12:10:59] - [0 Ko] - C:\Windows\Temp\tw7D36.tmp
[MD5.00000000000000000000000000000000] - |D| - [23/03/2019 15:09:10] - [0 Ko] - C:\Windows\Temp\tw7D8C.tmp
[MD5.00000000000000000000000000000000] - |D| - [15/09/2018 20:16:57] - [0 Ko] - C:\Windows\Temp\tw7D9B.tmp
[MD5.00000000000000000000000000000000] - |D| - [28/06/2019 19:48:30] - [0 Ko] - C:\Windows\Temp\tw7DD2.tmp
[MD5.00000000000000000000000000000000] - |D| - [08/12/2018 13:36:35] - [0 Ko] - C:\Windows\Temp\tw8065.tmp
[MD5.00000000000000000000000000000000] - |D| - [26/08/2017 12:11:00] - [0 Ko] - C:\Windows\Temp\tw815E.tmp
[MD5.00000000000000000000000000000000] - |D| - [27/07/2018 21:51:30] - [0 Ko] - C:\Windows\Temp\tw818F.tmp
[MD5.00000000000000000000000000000000] - |D| - [29/06/2019 08:44:54] - [0 Ko] - C:\Windows\Temp\tw8269.tmp
[MD5.00000000000000000000000000000000] - |D| - [31/03/2018 13:16:47] - [0 Ko] - C:\Windows\Temp\tw839F.tmp
[MD5.00000000000000000000000000000000] - |D| - [13/01/2018 19:41:18] - [0 Ko] - C:\Windows\Temp\tw83B1.tmp
[MD5.00000000000000000000000000000000] - |D| - [15/09/2018 20:16:58] - [0 Ko] - C:\Windows\Temp\tw8492.tmp
[MD5.00000000000000000000000000000000] - |D| - [08/03/2019 21:17:58] - [0 Ko] - C:\Windows\Temp\tw85.tmp
[MD5.00000000000000000000000000000000] - |D| - [08/03/2019 21:17:27] - [0 Ko] - C:\Windows\Temp\tw864B.tmp
[MD5.00000000000000000000000000000000] - |D| - [09/02/2018 22:48:36] - [0 Ko] - C:\Windows\Temp\tw867D.tmp
[MD5.00000000000000000000000000000000] - |D| - [08/12/2018 13:36:36] - [0 Ko] - C:\Windows\Temp\tw87F9.tmp
[MD5.00000000000000000000000000000000] - |D| - [09/12/2017 15:18:52] - [0 Ko] - C:\Windows\Temp\tw8821.tmp
[MD5.00000000000000000000000000000000] - |D| - [28/06/2019 19:48:33] - [0 Ko] - C:\Windows\Temp\tw898C.tmp
[MD5.00000000000000000000000000000000] - |D| - [26/08/2017 12:11:02] - [0 Ko] - C:\Windows\Temp\tw898E.tmp
[MD5.00000000000000000000000000000000] - |D| - [23/03/2019 15:09:14] - [0 Ko] - C:\Windows\Temp\tw8CA1.tmp
[MD5.00000000000000000000000000000000] - |D| - [29/06/2019 08:44:57] - [0 Ko] - C:\Windows\Temp\tw8D29.tmp
[MD5.00000000000000000000000000000000] - |D| - [09/02/2018 22:48:38] - [0 Ko] - C:\Windows\Temp\tw8E3F.tmp
[MD5.00000000000000000000000000000000] - |D| - [13/01/2018 19:41:21] - [0 Ko] - C:\Windows\Temp\tw8EFE.tmp
[MD5.00000000000000000000000000000000] - |D| - [08/06/2019 11:28:20] - [0 Ko] - C:\Windows\Temp\tw8F35.tmp
[MD5.00000000000000000000000000000000] - |D| - [13/05/2019 16:23:23] - [0 Ko] - C:\Windows\Temp\tw8FA1.tmp
[MD5.00000000000000000000000000000000] - |D| - [08/12/2018 13:36:39] - [0 Ko] - C:\Windows\Temp\tw8FFA.tmp
[MD5.00000000000000000000000000000000] - |D| - [28/06/2019 19:48:36] - [0 Ko] - C:\Windows\Temp\tw92C5.tmp
[MD5.00000000000000000000000000000000] - |D| - [31/03/2018 13:16:51] - [0 Ko] - C:\Windows\Temp\tw9351.tmp
[MD5.00000000000000000000000000000000] - |D| - [08/03/2019 21:17:31] - [0 Ko] - C:\Windows\Temp\tw938C.tmp
[MD5.00000000000000000000000000000000] - |D| - [15/09/2018 20:17:02] - [0 Ko] - C:\Windows\Temp\tw93B7.tmp
[MD5.00000000000000000000000000000000] - |D| - [29/06/2019 08:44:59] - [0 Ko] - C:\Windows\Temp\tw950B.tmp
[MD5.00000000000000000000000000000000] - |D| - [26/08/2017 12:11:05] - [0 Ko] - C:\Windows\Temp\tw95E4.tmp
[MD5.00000000000000000000000000000000] - |D| - [13/05/2019 16:22:20] - [0 Ko] - C:\Windows\Temp\tw9735.tmp
[MD5.00000000000000000000000000000000] - |D| - [13/01/2018 19:41:23] - [0 Ko] - C:\Windows\Temp\tw97DA.tmp
[MD5.00000000000000000000000000000000] - |D| - [31/03/2018 13:16:16] - [0 Ko] - C:\Windows\Temp\tw987.tmp
[MD5.00000000000000000000000000000000] - |D| - [27/07/2018 21:51:37] - [0 Ko] - C:\Windows\Temp\tw9930.tmp
[MD5.00000000000000000000000000000000] - |D| - [09/02/2018 22:48:41] - [0 Ko] - C:\Windows\Temp\tw99EA.tmp
[MD5.00000000000000000000000000000000] - |D| - [08/12/2018 13:36:42] - [0 Ko] - C:\Windows\Temp\tw9B56.tmp
[MD5.00000000000000000000000000000000] - |D| - [31/03/2018 13:16:16] - [0 Ko] - C:\Windows\Temp\tw9C7.tmp
[MD5.00000000000000000000000000000000] - |D| - [23/08/2017 17:47:33] - [0 Ko] - C:\Windows\Temp\tw9D31.tmp
[MD5.00000000000000000000000000000000] - |D| - [09/12/2017 15:18:58] - [0 Ko] - C:\Windows\Temp\tw9EB8.tmp
[MD5.00000000000000000000000000000000] - |D| - [29/06/2019 08:45:02] - [0 Ko] - C:\Windows\Temp\tw9ED1.tmp
[MD5.00000000000000000000000000000000] - |D| - [23/03/2019 15:09:19] - [0 Ko] - C:\Windows\Temp\tw9F02.tmp
[MD5.00000000000000000000000000000000] - |D| - [31/03/2018 13:16:16] - [0 Ko] - C:\Windows\Temp\tw9F8.tmp
[MD5.00000000000000000000000000000000] - |D| - [13/01/2018 19:41:25] - [0 Ko] - C:\Windows\Temp\tw9FFA.tmp
[MD5.00000000000000000000000000000000] - |D| - [08/03/2019 21:17:34] - [0 Ko] - C:\Windows\Temp\twA040.tmp
[MD5.00000000000000000000000000000000] - |D| - [31/03/2018 13:16:16] - [0 Ko] - C:\Windows\Temp\twA29.tmp
[MD5.00000000000000000000000000000000] - |D| - [31/03/2018 13:16:55] - [0 Ko] - C:\Windows\Temp\twA370.tmp
[MD5.00000000000000000000000000000000] - |D| - [04/09/2017 19:37:37] - [0 Ko] - C:\Windows\Temp\twA58E.tmp
[MD5.00000000000000000000000000000000] - |D| - [28/06/2019 19:48:41] - [0 Ko] - C:\Windows\Temp\twA5B3.tmp
[MD5.00000000000000000000000000000000] - |D| - [04/09/2017 19:37:37] - [0 Ko] - C:\Windows\Temp\twA65B.tmp
[MD5.00000000000000000000000000000000] - |D| - [04/09/2017 19:37:37] - [0 Ko] - C:\Windows\Temp\twA69C.tmp
[MD5.00000000000000000000000000000000] - |D| - [04/09/2017 19:37:37] - [0 Ko] - C:\Windows\Temp\twA769.tmp
[MD5.00000000000000000000000000000000] - |D| - [08/12/2018 13:36:45] - [0 Ko] - C:\Windows\Temp\twA7CC.tmp
[MD5.00000000000000000000000000000000] - |D| - [29/06/2019 08:45:04] - [0 Ko] - C:\Windows\Temp\twA80A.tmp
[MD5.00000000000000000000000000000000] - |D| - [04/09/2017 19:37:37] - [0 Ko] - C:\Windows\Temp\twA817.tmp
[MD5.00000000000000000000000000000000] - |D| - [04/09/2017 19:37:37] - [0 Ko] - C:\Windows\Temp\twA838.tmp
[MD5.00000000000000000000000000000000] - |D| - [04/09/2017 19:37:37] - [0 Ko] - C:\Windows\Temp\twA8F5.tmp
[MD5.00000000000000000000000000000000] - |D| - [08/03/2019 21:17:36] - [0 Ko] - C:\Windows\Temp\twA8FC.tmp
[MD5.00000000000000000000000000000000] - |D| - [08/06/2019 11:28:26] - [0 Ko] - C:\Windows\Temp\twA966.tmp
[MD5.00000000000000000000000000000000] - |D| - [04/09/2017 19:37:38] - [0 Ko] - C:\Windows\Temp\twA9D2.tmp
[MD5.00000000000000000000000000000000] - |D| - [04/09/2017 19:37:38] - [0 Ko] - C:\Windows\Temp\twAA13.tmp
[MD5.00000000000000000000000000000000] - |D| - [04/09/2017 19:37:38] - [0 Ko] - C:\Windows\Temp\twAAD0.tmp
[MD5.00000000000000000000000000000000] - |D| - [04/09/2017 19:37:38] - [0 Ko] - C:\Windows\Temp\twAB5F.tmp
[MD5.00000000000000000000000000000000] - |D| - [04/09/2017 19:37:38] - [0 Ko] - C:\Windows\Temp\twABBE.tmp
[MD5.00000000000000000000000000000000] - |D| - [04/09/2017 19:37:38] - [0 Ko] - C:\Windows\Temp\twACCA.tmp
[MD5.00000000000000000000000000000000] - |D| - [28/12/2018 11:55:32] - [0 Ko] - C:\Windows\Temp\twAD09.tmp
[MD5.00000000000000000000000000000000] - |D| - [28/12/2018 11:55:33] - [0 Ko] - C:\Windows\Temp\twAD39.tmp
[MD5.00000000000000000000000000000000] - |D| - [28/12/2018 11:55:33] - [0 Ko] - C:\Windows\Temp\twAD7A.tmp
[MD5.00000000000000000000000000000000] - |D| - [28/12/2018 11:55:33] - [0 Ko] - C:\Windows\Temp\twADAB.tmp
[MD5.00000000000000000000000000000000] - |D| - [28/12/2018 11:55:33] - [0 Ko] - C:\Windows\Temp\twADDC.tmp
[MD5.00000000000000000000000000000000] - |D| - [28/12/2018 11:55:33] - [0 Ko] - C:\Windows\Temp\twAE0D.tmp
[MD5.00000000000000000000000000000000] - |D| - [28/12/2018 11:55:33] - [0 Ko] - C:\Windows\Temp\twAE2E.tmp
[MD5.00000000000000000000000000000000] - |D| - [28/12/2018 11:55:33] - [0 Ko] - C:\Windows\Temp\twAE5F.tmp
[MD5.00000000000000000000000000000000] - |D| - [28/12/2018 11:55:33] - [0 Ko] - C:\Windows\Temp\twAEBE.tmp
[MD5.00000000000000000000000000000000] - |D| - [13/05/2019 16:22:26] - [0 Ko] - C:\Windows\Temp\twAED6.tmp
[MD5.00000000000000000000000000000000] - |D| - [28/12/2018 11:55:33] - [0 Ko] - C:\Windows\Temp\twAEEF.tmp
[MD5.00000000000000000000000000000000] - |D| - [28/12/2018 11:55:33] - [0 Ko] - C:\Windows\Temp\twAF20.tmp
[MD5.00000000000000000000000000000000] - |D| - [28/12/2018 11:55:33] - [0 Ko] - C:\Windows\Temp\twAF41.tmp
[MD5.00000000000000000000000000000000] - |D| - [28/12/2018 11:55:33] - [0 Ko] - C:\Windows\Temp\twAF63.tmp
[MD5.00000000000000000000000000000000] - |D| - [28/06/2019 19:48:43] - [0 Ko] - C:\Windows\Temp\twAF69.tmp
[MD5.00000000000000000000000000000000] - |D| - [28/12/2018 11:55:33] - [0 Ko] - C:\Windows\Temp\twAFB3.tmp
[MD5.00000000000000000000000000000000] - |D| - [23/08/2017 17:47:38] - [0 Ko] - C:\Windows\Temp\twAFE1.tmp
[MD5.00000000000000000000000000000000] - |D| - [17/03/2019 18:28:55] - [0 Ko] - C:\Windows\Temp\twB124.tmp
[MD5.00000000000000000000000000000000] - |D| - [04/09/2017 19:37:41] - [0 Ko] - C:\Windows\Temp\twB1FC.tmp
[MD5.00000000000000000000000000000000] - |D| - [17/03/2019 18:28:55] - [0 Ko] - C:\Windows\Temp\twB201.tmp
[MD5.00000000000000000000000000000000] - |D| - [17/03/2019 18:28:55] - [0 Ko] - C:\Windows\Temp\twB280.tmp
[MD5.00000000000000000000000000000000] - |D| - [13/01/2018 19:41:29] - [0 Ko] - C:\Windows\Temp\twB299.tmp
[MD5.00000000000000000000000000000000] - |D| - [17/03/2019 18:28:55] - [0 Ko] - C:\Windows\Temp\twB2DF.tmp
[MD5.00000000000000000000000000000000] - |D| - [08/03/2019 21:17:39] - [0 Ko] - C:\Windows\Temp\twB2E2.tmp
[MD5.00000000000000000000000000000000] - |D| - [13/05/2019 16:23:33] - [0 Ko] - C:\Windows\Temp\twB30A.tmp
[MD5.00000000000000000000000000000000] - |D| - [31/03/2018 13:16:59] - [0 Ko] - C:\Windows\Temp\twB312.tmp
[MD5.00000000000000000000000000000000] - |D| - [17/03/2019 18:28:56] - [0 Ko] - C:\Windows\Temp\twB39D.tmp
[MD5.00000000000000000000000000000000] - |D| - [17/03/2019 18:28:56] - [0 Ko] - C:\Windows\Temp\twB3FD.tmp
[MD5.00000000000000000000000000000000] - |D| - [17/03/2019 18:28:56] - [0 Ko] - C:\Windows\Temp\twB49B.tmp
[MD5.00000000000000000000000000000000] - |D| - [17/03/2019 18:28:56] - [0 Ko] - C:\Windows\Temp\twB539.tmp
[MD5.00000000000000000000000000000000] - |D| - [09/12/2017 15:19:04] - [0 Ko] - C:\Windows\Temp\twB54F.tmp
[MD5.00000000000000000000000000000000] - |D| - [17/03/2019 18:28:56] - [0 Ko] - C:\Windows\Temp\twB5A8.tmp
[MD5.00000000000000000000000000000000] - |D| - [17/03/2019 18:28:56] - [0 Ko] - C:\Windows\Temp\twB618.tmp
[MD5.00000000000000000000000000000000] - |D| - [17/03/2019 18:28:56] - [0 Ko] - C:\Windows\Temp\twB6C6.tmp
[MD5.00000000000000000000000000000000] - |D| - [17/03/2019 18:28:57] - [0 Ko] - C:\Windows\Temp\twB764.tmp
[MD5.00000000000000000000000000000000] - |D| - [23/08/2017 17:47:40] - [0 Ko] - C:\Windows\Temp\twB7C2.tmp
[MD5.00000000000000000000000000000000] - |D| - [17/03/2019 18:28:57] - [0 Ko] - C:\Windows\Temp\twB7C4.tmp
[MD5.00000000000000000000000000000000] - |D| - [17/03/2019 18:28:57] - [0 Ko] - C:\Windows\Temp\twB823.tmp
[MD5.00000000000000000000000000000000] - |D| - [08/06/2019 11:27:23] - [0 Ko] - C:\Windows\Temp\twB82F.tmp
[MD5.00000000000000000000000000000000] - |D| - [17/03/2019 18:28:57] - [0 Ko] - C:\Windows\Temp\twB893.tmp
[MD5.00000000000000000000000000000000] - |D| - [27/07/2018 21:51:44] - [0 Ko] - C:\Windows\Temp\twB8FE.tmp
[MD5.00000000000000000000000000000000] - |D| - [17/03/2019 18:28:57] - [0 Ko] - C:\Windows\Temp\twB950.tmp
[MD5.00000000000000000000000000000000] - |D| - [28/06/2019 19:48:46] - [0 Ko] - C:\Windows\Temp\twB9AC.tmp
[MD5.00000000000000000000000000000000] - |D| - [17/03/2019 18:28:57] - [0 Ko] - C:\Windows\Temp\twB9DF.tmp
[MD5.00000000000000000000000000000000] - |D| - [23/03/2019 15:09:26] - [0 Ko] - C:\Windows\Temp\twBAAA.tmp
[MD5.00000000000000000000000000000000] - |D| - [17/03/2019 18:28:58] - [0 Ko] - C:\Windows\Temp\twBB29.tmp
[MD5.00000000000000000000000000000000] - |D| - [23/08/2017 17:47:42] - [0 Ko] - C:\Windows\Temp\twBF94.tmp
[MD5.00000000000000000000000000000000] - |D| - [08/03/2019 21:17:42] - [0 Ko] - C:\Windows\Temp\twC090.tmp
[MD5.00000000000000000000000000000000] - |D| - [27/07/2018 21:50:41] - [0 Ko] - C:\Windows\Temp\twC0E2.tmp
[MD5.00000000000000000000000000000000] - |D| - [08/12/2018 13:36:51] - [0 Ko] - C:\Windows\Temp\twC112.tmp
[MD5.00000000000000000000000000000000] - |D| - [08/06/2019 11:27:25] - [0 Ko] - C:\Windows\Temp\twC198.tmp
[MD5.00000000000000000000000000000000] - |D| - [26/07/2018 21:01:42] - [0 Ko] - C:\Windows\Temp\twC1BC.tmp
[MD5.00000000000000000000000000000000] - |D| - [26/07/2018 21:01:43] - [0 Ko] - C:\Windows\Temp\twC2E6.tmp
[MD5.00000000000000000000000000000000] - |D| - [18/04/2019 10:08:32] - [0 Ko] - C:\Windows\Temp\twC2ED.tmp
[MD5.00000000000000000000000000000000] - |D| - [31/03/2018 13:17:03] - [0 Ko] - C:\Windows\Temp\twC302.tmp
[MD5.00000000000000000000000000000000] - |D| - [18/04/2019 10:08:32] - [0 Ko] - C:\Windows\Temp\twC31E.tmp
[MD5.00000000000000000000000000000000] - |D| - [26/07/2018 21:01:43] - [0 Ko] - C:\Windows\Temp\twC375.tmp
[MD5.00000000000000000000000000000000] - |D| - [18/04/2019 10:08:32] - [0 Ko] - C:\Windows\Temp\twC3BC.tmp
[MD5.00000000000000000000000000000000] - |D| - [18/04/2019 10:08:32] - [0 Ko] - C:\Windows\Temp\twC3DE.tmp
[MD5.00000000000000000000000000000000] - |D| - [18/04/2019 10:08:32] - [0 Ko] - C:\Windows\Temp\twC41E.tmp
[MD5.00000000000000000000000000000000] - |D| - [26/07/2018 21:01:43] - [0 Ko] - C:\Windows\Temp\twC423.tmp
[MD5.00000000000000000000000000000000] - |D| - [18/04/2019 10:08:32] - [0 Ko] - C:\Windows\Temp\twC44F.tmp
[MD5.00000000000000000000000000000000] - |D| - [18/04/2019 10:08:32] - [0 Ko] - C:\Windows\Temp\twC470.tmp
[MD5.00000000000000000000000000000000] - |D| - [18/04/2019 10:08:32] - [0 Ko] - C:\Windows\Temp\twC4A1.tmp
[MD5.00000000000000000000000000000000] - |D| - [28/06/2019 19:48:48] - [0 Ko] - C:\Windows\Temp\twC4BB.tmp
[MD5.00000000000000000000000000000000] - |D| - [18/04/2019 10:08:32] - [0 Ko] - C:\Windows\Temp\twC4C2.tmp
[MD5.00000000000000000000000000000000] - |D| - [18/04/2019 10:08:32] - [0 Ko] - C:\Windows\Temp\twC4E4.tmp
[MD5.00000000000000000000000000000000] - |D| - [26/07/2018 21:01:43] - [0 Ko] - C:\Windows\Temp\twC500.tmp
[MD5.00000000000000000000000000000000] - |D| - [18/04/2019 10:08:32] - [0 Ko] - C:\Windows\Temp\twC534.tmp
[MD5.00000000000000000000000000000000] - |D| - [18/04/2019 10:08:32] - [0 Ko] - C:\Windows\Temp\twC565.tmp
[MD5.00000000000000000000000000000000] - |D| - [26/07/2018 21:01:43] - [0 Ko] - C:\Windows\Temp\twC61B.tmp
[MD5.00000000000000000000000000000000] - |D| - [26/07/2018 21:01:44] - [0 Ko] - C:\Windows\Temp\twC68A.tmp
[MD5.00000000000000000000000000000000] - |D| - [13/01/2018 19:41:35] - [0 Ko] - C:\Windows\Temp\twC70E.tmp
[MD5.00000000000000000000000000000000] - |D| - [26/07/2018 21:01:44] - [0 Ko] - C:\Windows\Temp\twC786.tmp
[MD5.00000000000000000000000000000000] - |D| - [26/07/2018 21:01:44] - [0 Ko] - C:\Windows\Temp\twC805.tmp
[MD5.00000000000000000000000000000000] - |D| - [08/06/2019 11:27:27] - [0 Ko] - C:\Windows\Temp\twC831.tmp
[MD5.00000000000000000000000000000000] - |D| - [26/07/2018 21:01:44] - [0 Ko] - C:\Windows\Temp\twC865.tmp
[MD5.00000000000000000000000000000000] - |D| - [08/03/2019 21:17:44] - [0 Ko] - C:\Windows\Temp\twC871.tmp
[MD5.00000000000000000000000000000000] - |D| - [26/07/2018 21:01:44] - [0 Ko] - C:\Windows\Temp\twC8D4.tmp
[MD5.00000000000000000000000000000000] - |D| - [23/08/2017 17:47:45] - [0 Ko] - C:\Windows\Temp\twC9E7.tmp
[MD5.00000000000000000000000000000000] - |D| - [13/05/2019 16:22:33] - [0 Ko] - C:\Windows\Temp\twCA7E.tmp
[MD5.00000000000000000000000000000000] - |D| - [27/07/2018 21:50:44] - [0 Ko] - C:\Windows\Temp\twCD29.tmp
[MD5.00000000000000000000000000000000] - |D| - [08/06/2019 11:27:30] - [0 Ko] - C:\Windows\Temp\twCF19.tmp
[MD5.00000000000000000000000000000000] - |D| - [28/06/2019 19:48:51] - [0 Ko] - C:\Windows\Temp\twCF6B.tmp
[MD5.00000000000000000000000000000000] - |D| - [08/03/2019 21:17:46] - [0 Ko] - C:\Windows\Temp\twCFF5.tmp
[MD5.00000000000000000000000000000000] - |D| - [23/03/2019 15:09:32] - [0 Ko] - C:\Windows\Temp\twD047.tmp
[MD5.00000000000000000000000000000000] - |D| - [31/03/2018 13:17:07] - [0 Ko] - C:\Windows\Temp\twD43A.tmp
[MD5.00000000000000000000000000000000] - |D| - [23/08/2017 17:47:48] - [0 Ko] - C:\Windows\Temp\twD4A7.tmp
[MD5.00000000000000000000000000000000] - |D| - [09/12/2017 15:19:12] - [0 Ko] - C:\Windows\Temp\twD4B0.tmp
[MD5.00000000000000000000000000000000] - |D| - [27/07/2018 21:50:46] - [0 Ko] - C:\Windows\Temp\twD5B6.tmp
[MD5.00000000000000000000000000000000] - |D| - [23/03/2019 15:10:39] - [0 Ko] - C:\Windows\Temp\twD732.tmp
[MD5.00000000000000000000000000000000] - |D| - [08/03/2019 21:17:48] - [0 Ko] - C:\Windows\Temp\twD75A.tmp
[MD5.00000000000000000000000000000000] - |D| - [08/06/2019 11:27:32] - [0 Ko] - C:\Windows\Temp\twDAA4.tmp
[MD5.00000000000000000000000000000000] - |D| - [28/06/2019 19:48:54] - [0 Ko] - C:\Windows\Temp\twDC2F.tmp
[MD5.00000000000000000000000000000000] - |D| - [27/07/2018 21:50:49] - [0 Ko] - C:\Windows\Temp\twDE73.tmp
[MD5.00000000000000000000000000000000] - |D| - [13/01/2018 19:41:41] - [0 Ko] - C:\Windows\Temp\twDEBE.tmp
[MD5.00000000000000000000000000000000] - |D| - [08/03/2019 21:17:50] - [0 Ko] - C:\Windows\Temp\twDF5B.tmp
[MD5.00000000000000000000000000000000] - |D| - [08/06/2019 11:27:34] - [0 Ko] - C:\Windows\Temp\twE286.tmp
[MD5.00000000000000000000000000000000] - |D| - [27/07/2018 21:52:06] - [0 Ko] - C:\Windows\Temp\twE45.tmp
[MD5.00000000000000000000000000000000] - |D| - [15/04/2018 08:49:28] - [0 Ko] - C:\Windows\Temp\twE680.tmp
[MD5.00000000000000000000000000000000] - |D| - [09/12/2017 15:18:11] - [0 Ko] - C:\Windows\Temp\twE6C9.tmp
[MD5.00000000000000000000000000000000] - |D| - [23/08/2017 17:47:52] - [0 Ko] - C:\Windows\Temp\twE6D9.tmp
[MD5.00000000000000000000000000000000] - |D| - [08/03/2019 21:17:52] - [0 Ko] - C:\Windows\Temp\twE7B9.tmp
[MD5.00000000000000000000000000000000] - |D| - [27/07/2018 21:50:51] - [0 Ko] - C:\Windows\Temp\twE7BC.tmp
[MD5.00000000000000000000000000000000] - |D| - [15/04/2018 08:49:28] - [0 Ko] - C:\Windows\Temp\twE7E9.tmp
[MD5.D41D8CD98F00B204E9800998ECF8427E] - |A| - [08/06/2019 11:28:41] - (.-.) - [0 Ko] - (0.0.0.0) - C:\Windows\Temp\twEAC7.tmp
[MD5.00000000000000000000000000000000] - |D| - [28/06/2019 19:48:58] - [0 Ko] - C:\Windows\Temp\twEB54.tmp
[MD5.00000000000000000000000000000000] - |D| - [15/04/2018 08:49:29] - [0 Ko] - C:\Windows\Temp\twECBE.tmp
[MD5.00000000000000000000000000000000] - |D| - [15/04/2018 08:49:29] - [0 Ko] - C:\Windows\Temp\twEDAA.tmp
[MD5.00000000000000000000000000000000] - |D| - [15/04/2018 08:49:30] - [0 Ko] - C:\Windows\Temp\twEE48.tmp
[MD5.00000000000000000000000000000000] - |D| - [08/06/2019 11:27:37] - [0 Ko] - C:\Windows\Temp\twEE4F.tmp
[MD5.00000000000000000000000000000000] - |D| - [15/04/2018 08:49:30] - [0 Ko] - C:\Windows\Temp\twEF25.tmp
[MD5.00000000000000000000000000000000] - |D| - [08/03/2019 21:17:55] - [0 Ko] - C:\Windows\Temp\twEFAA.tmp
[MD5.00000000000000000000000000000000] - |D| - [15/04/2018 08:49:30] - [0 Ko] - C:\Windows\Temp\twF031.tmp
[MD5.00000000000000000000000000000000] - |D| - [15/04/2018 08:49:30] - [0 Ko] - C:\Windows\Temp\twF090.tmp
[MD5.00000000000000000000000000000000] - |D| - [15/04/2018 08:49:30] - [0 Ko] - C:\Windows\Temp\twF10F.tmp
[MD5.00000000000000000000000000000000] - |D| - [27/07/2018 21:51:01] - [0 Ko] - C:\Windows\Temp\twF12.tmp
[MD5.00000000000000000000000000000000] - |D| - [15/04/2018 08:49:30] - [0 Ko] - C:\Windows\Temp\twF150.tmp
[MD5.00000000000000000000000000000000] - |D| - [15/04/2018 08:49:30] - [0 Ko] - C:\Windows\Temp\twF1A0.tmp
[MD5.00000000000000000000000000000000] - |D| - [15/04/2018 08:49:30] - [0 Ko] - C:\Windows\Temp\twF1D1.tmp
[MD5.00000000000000000000000000000000] - |D| - [13/05/2019 16:22:43] - [0 Ko] - C:\Windows\Temp\twF1EE.tmp
[MD5.00000000000000000000000000000000] - |D| - [23/03/2019 15:09:40] - [0 Ko] - C:\Windows\Temp\twF1FA.tmp
[MD5.00000000000000000000000000000000] - |D| - [27/07/2018 21:50:54] - [0 Ko] - C:\Windows\Temp\twF20E.tmp
[MD5.00000000000000000000000000000000] - |D| - [02/12/2018 15:02:08] - [0 Ko] - C:\Windows\Temp\twF4D1.tmp
[MD5.00000000000000000000000000000000] - |D| - [02/12/2018 15:02:09] - [0 Ko] - C:\Windows\Temp\twF56F.tmp
[MD5.00000000000000000000000000000000] - |D| - [18/10/2018 09:50:14] - [0 Ko] - C:\Windows\Temp\twF61.tmp
[MD5.00000000000000000000000000000000] - |D| - [02/12/2018 15:02:09] - [0 Ko] - C:\Windows\Temp\twF61D.tmp
[MD5.00000000000000000000000000000000] - |D| - [02/12/2018 15:02:09] - [0 Ko] - C:\Windows\Temp\twF67D.tmp
[MD5.00000000000000000000000000000000] - |D| - [09/12/2017 15:19:20] - [0 Ko] - C:\Windows\Temp\twF6E0.tmp
[MD5.00000000000000000000000000000000] - |D| - [02/12/2018 15:02:09] - [0 Ko] - C:\Windows\Temp\twF6FC.tmp
[MD5.00000000000000000000000000000000] - |D| - [08/06/2019 11:27:39] - [0 Ko] - C:\Windows\Temp\twF7B7.tmp
[MD5.00000000000000000000000000000000] - |D| - [02/12/2018 15:02:09] - [0 Ko] - C:\Windows\Temp\twF7B9.tmp
[MD5.00000000000000000000000000000000] - |D| - [02/12/2018 15:02:09] - [0 Ko] - C:\Windows\Temp\twF7DB.tmp
[MD5.00000000000000000000000000000000] - |D| - [02/12/2018 15:02:09] - [0 Ko] - C:\Windows\Temp\twF83A.tmp
[MD5.00000000000000000000000000000000] - |D| - [02/12/2018 15:02:09] - [0 Ko] - C:\Windows\Temp\twF89A.tmp
[MD5.00000000000000000000000000000000] - |D| - [02/12/2018 15:02:10] - [0 Ko] - C:\Windows\Temp\twF8FA.tmp
[MD5.00000000000000000000000000000000] - |D| - [02/12/2018 15:02:10] - [0 Ko] - C:\Windows\Temp\twFA05.tmp
[MD5.00000000000000000000000000000000] - |D| - [02/12/2018 15:02:10] - [0 Ko] - C:\Windows\Temp\twFA56.tmp
[MD5.00000000000000000000000000000000] - |D| - [27/07/2018 21:50:56] - [0 Ko] - C:\Windows\Temp\twFAAB.tmp
[MD5.00000000000000000000000000000000] - |D| - [09/12/2017 15:18:16] - [0 Ko] - C:\Windows\Temp\twFB5D.tmp
[MD5.00000000000000000000000000000000] - |D| - [08/06/2019 11:27:41] - [0 Ko] - C:\Windows\Temp\twFCAB.tmp
[MD5.00000000000000000000000000000000] - |D| - [23/08/2017 17:47:57] - [0 Ko] - C:\Windows\Temp\twFCE4.tmp
[MD5.00000000000000000000000000000000] - |D| - [02/12/2018 15:02:11] - [0 Ko] - C:\Windows\Temp\twFDB3.tmp
[MD5.00000000000000000000000000000000] - |D| - [15/04/2018 08:49:35] - [0 Ko] - C:\Windows\Temp\twFE56.tmp
[MD5.BBFA862233DEEAD75F01998F91EEF20F] - |A| - [20/10/2017 17:02:27] - (.-.) - [3 Ko] - (0.0.0.0) - C:\Windows\Temp\us008ci.exe.log
[MD5.107D6425C4FD643500DA0FF5D08D1E95] - |A| - [10/03/2018 10:01:55] - (.-.) - [5.48 Ko] - (0.0.0.0) - C:\Windows\Temp\UsoStoreFile.xml
[MD5.833AE6D8920BD43DD3237F8C11037976] - |A| - [18/04/2018 13:41:19] - (.-.) - [0.5 Ko] - (0.0.0.0) - C:\Windows\Temp\WER-37640-0.sysdata.xml
[MD5.00000000000000000000000000000000] - |D| - [20/03/2017 06:06:15] - [0 Ko] - C:\Windows\System32\0409
[MD5.82C37C3E27020AF6C2E018E944284676] - |A| - [18/03/2017 22:57:42] - (.-.) - [0.3 Ko] - (0.0.0.0) - C:\Windows\System32\@AudioToastIcon.png
[MD5.8E4B25CC8E98F63DBD54176DFAB539E0] - |A| - [18/03/2017 22:58:18] - (.-.) - [0.44 Ko] - (0.0.0.0) - C:\Windows\System32\@BackgroundAccessToastIcon.png
[MD5.3937359E324E15F6A7A7092D4DAEBD64] - |A| - [18/03/2017 22:57:25] - (.-.) - [0.19 Ko] - (0.0.0.0) - C:\Windows\System32\@bitlockertoastimage.png
[MD5.495C1F072039B434827A5FE0D9761E4D] - |A| - [18/03/2017 22:58:17] - (.-.) - [0.32 Ko] - (0.0.0.0) - C:\Windows\System32\@EnrollmentToastIcon.png
[MD5.373CF57FF3DAAEEB629F90CE7226B30D] - |A| - [18/03/2017 22:58:29] - (.-.) - [0.59 Ko] - (0.0.0.0) - C:\Windows\System32\@language_notification_icon.png
[MD5.2B7002E9C7EA6B436F3A0F7C305AACD8] - |A| - [14/06/2018 13:19:07] - (.-.) - [0.5 Ko] - (0.0.0.0) - C:\Windows\System32\@NotifierToastIcon.png
[MD5.46DACDA5036EBECEDF08427407E3017C] - |A| - [18/03/2017 22:58:29] - (.-.) - [0.51 Ko] - (0.0.0.0) - C:\Windows\System32\@optionalfeatures.png
[MD5.1622DE67156496C78D6B7BE9B471645B] - |A| - [18/03/2017 22:58:21] - (.-.) - [0.39 Ko] - (0.0.0.0) - C:\Windows\System32\@VpnToastIcon.png
[MD5.7AC3EA1A5175106ED6467FF0C5315541] - |A| - [18/03/2017 22:58:18] - (.-.) - [14.75 Ko] - (0.0.0.0) - C:\Windows\System32\@WiFiNotificationIcon.png
[MD5.13EF2C8D799F7B6E9D8E3D6BACB9C779] - |A| - [18/03/2017 22:57:53] - (.-.) - [0.7 Ko] - (0.0.0.0) - C:\Windows\System32\@WindowsHelloFaceToastIcon.png
[MD5.F553B252FEC3134D4F5303D9B25298B3] - |A| - [18/03/2017 22:56:40] - (.-.) - [0.51 Ko] - (0.0.0.0) - C:\Windows\System32\@WindowsUpdateToastIcon.png
[MD5.D0FCF781D0801ABF5F74B54E98076A5B] - |A| - [18/03/2017 22:58:13] - (.-.) - [0.15 Ko] - (0.0.0.0) - C:\Windows\System32\@WwanNotificationIcon.png
[MD5.85D91E478AF18125007C531227FF6E59] - |A| - [18/03/2017 22:58:13] - (.-.) - [0.34 Ko] - (0.0.0.0) - C:\Windows\System32\@WwanSimLockIcon.png
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 13:40:24] - [2979.4 Ko] - C:\Windows\System32\AdvancedInstallers
[MD5.68CF4C147C95C7E6A1E5A6EE6DC7A185] - |A| - [16/12/2015 21:06:10] - (.-.) - [0.14 Ko] - (0.0.0.0) - C:\Windows\System32\amd-vulkan64.json
[MD5.C11A213062C0A41C9531C64A287877EE] - |A| - [16/05/2017 18:05:56] - (.Copyright (c) 2009 Advanced Micro Devices, Inc. - Radeon AMD AVE Driver Component.) - [145.72 Ko] - (22.19.662.4) - C:\Windows\System32\amdave64.dll
[MD5.CDDC40AB7FDA1B8B0D7E1A295C702242] - |A| - [16/05/2017 18:06:42] - (.-.) - [510.91 Ko] - (0.0.0.0) - C:\Windows\System32\amdgfxinfo64.dll
[MD5.763F34C925767695837110CA755DB506] - |A| - [16/05/2017 18:05:56] - (.Copyright (C) 2013 - Universal Adapter for Adobe.) - [201.94 Ko] - (22.19.662.4) - C:\Windows\System32\amdhcp64.dll
[MD5.6FB5582E1415B9889CB3C24B873A51C0] - |A| - [26/07/2017 21:35:04] - (.-.) - [30.31 Ko] - (0.0.0.0) - C:\Windows\System32\AMDKernelEvents.man
[MD5.3386A630DFECF67237D6661B7820C755] - |A| - [16/05/2017 18:06:42] - (.Advanced Micro Devices, Inc. Copyright (C) 2015 - LiquidVR SDK 1.0.) - [852.41 Ko] - (1.0.11.0) - C:\Windows\System32\amdlvr64.dll
[MD5.B323243FA8AB5EE21C52249B779AD9EB] - |A| - [16/05/2017 18:06:42] - (.Copyright (c) 2013 Advanced Micro Devices, Inc. - Radeon MCL Universal Driver.) - [97.91 Ko] - (1.6.0.0) - C:\Windows\System32\amdmcl64.dll
[MD5.C8BDA61ACED770B1E14A7ACB5F30BCB5] - |A| - [16/05/2017 18:05:56] - (.-.) - [573.88 Ko] - (0.0.0.0) - C:\Windows\System32\amdmiracast.dll
[MD5.D57264B3CC3DE11A727E3BB6B7F8EB4A] - |A| - [16/05/2017 18:05:56] - (.Copyright (c) 2009 Advanced Micro Devices, Inc. - Radeon PCOM Universal Driver.) - [138.03 Ko] - (22.19.662.4) - C:\Windows\System32\amdpcom64.dll
[MD5.C6C2D213B62F40CE8C23858C1F6A56D8] - |A| - [16/05/2017 18:06:44] - (.Copyright (C) 2015 AMD Inc. - Vulkan driver, support for SI family and above.) - [12209.91 Ko] - (1.0.51.0) - C:\Windows\System32\amdvlk64.dll
[MD5.F8F03AE37169D8E2ED23BB7B7F54B57E] - |A| - [16/05/2017 18:06:44] - (.Copyright (C) 2014-2015 AMD Inc. - amdxcstub64.dll.) - [118.41 Ko] - (8.18.10.195) - C:\Windows\System32\amdxc64.dll
[MD5.A1D7401AC0B22EA5F6BBBB937DE38131] - |A| - [16/05/2017 18:06:46] - (.Advanced Micro Devices, Inc. Copyright (C) 2017 - Advanced Media Framework.) - [2851.91 Ko] - (1.4.4.0) - C:\Windows\System32\amfrt64.dll
[MD5.E21E74D118E16FF9BA42A6F87F34E9B0] - |A| - [18/03/2017 22:57:00] - (.-.) - [435.67 Ko] - (0.0.0.0) - C:\Windows\System32\ApnDatabase.xml
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [0 Ko] - C:\Windows\System32\AppLocker
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [2591.88 Ko] - C:\Windows\System32\appraiser
[MD5.00000000000000000000000000000000] - |SD| - [20/03/2017 06:07:27] - [287.09 Ko] - C:\Windows\System32\AppV
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [273.5 Ko] - C:\Windows\System32\ar-SA
[MD5.A8EEF8A9702448DB60B9A1037467B327] - |A| - [16/05/2017 18:06:46] - (.© 2004 Advanced Micro Devices, Inc. - eRecord Message Resource File.) - [75.91 Ko] - (22.19.662.4) - C:\Windows\System32\ati2erec.dll
[MD5.027E1DC24ABA01BFFDD33A5DD7E27C3F] - |A| - [16/05/2017 18:06:46] - (.Copyright (C) 2008-2016 Advanced Micro Devices, Inc. - ADL.) - [1506.41 Ko] - (22.19.662.4) - C:\Windows\System32\atiadlxx.dll
[MD5.81AF51277D9FB5030D80E0157303BA17] - |A| - [25/04/2017 01:06:40] - (.-.) - [795.77 Ko] - (0.0.0.0) - C:\Windows\System32\atiapfxx.blb
[MD5.1693948AA16996812A8E949D2DD5C872] - |A| - [16/05/2017 18:06:46] - (.Copyright (C) 2009 Advanced Micro Devices, Inc. - atiapfxx Application.) - [658.91 Ko] - (22.19.662.4) - C:\Windows\System32\atiapfxx.exe
[MD5.804534244E9C8AF1A01AC54BCC35D1BA] - |A| - [16/05/2017 18:06:46] - (.Copyright (C) 1998-2012 AMD Inc. - aticfxstub64.dll.) - [161.56 Ko] - (8.17.10.1560) - C:\Windows\System32\aticfx64.dll
[MD5.C15B7677156865B1B0D8883DDA87A4D7] - |A| - [16/05/2017 18:06:46] - (.2002-2012 - Graphics DEM.) - [464.91 Ko] - (4.5.6410.31840) - C:\Windows\System32\atidemgy.dll
[MD5.7C3D067E646B29EEBBBF00B9CCD15226] - |A| - [16/05/2017 18:06:46] - (.-.) - [120.91 Ko] - (0.0.0.0) - C:\Windows\System32\atidxx64.dll
[MD5.329EA483B445C4949501FB50D5E3511B] - |A| - [16/05/2017 18:06:46] - (.-.) - [480.91 Ko] - (0.0.0.0) - C:\Windows\System32\atieah64.exe
[MD5.807965C80A80B6424CA54FEC091C802C] - |A| - [16/05/2017 18:06:46] - (.Copyright © 2008-2009 AMD - AMD External Events Client Module.) - [771.41 Ko] - (22.19.662.4) - C:\Windows\System32\atieclxx.exe
[MD5.99892C7128F6B4AC0493A78E5CA09E9B] - |A| - [16/05/2017 18:06:46] - (.Copyright © 2008-2009 AMD - AMD External Events Service Module.) - [547.41 Ko] - (22.19.662.4) - C:\Windows\System32\atiesrxx.exe
[MD5.658083C8ADE4019400F333685278E569] - |A| - [16/05/2017 18:06:46] - (.Copyright (C) 2007 Advanced Micro Devices, Inc. - atigktxx.dll.) - [247.91 Ko] - (22.19.662.4) - C:\Windows\System32\atig6txx.dll
[MD5.1CF58E3E0838F03404D09F8B7D42CBD3] - |A| - [16/05/2017 18:05:58] - (.Copyright (c) 2009 Advanced Micro Devices, Inc. - Radeon PCOM Universal Driver.) - [138.03 Ko] - (22.19.662.4) - C:\Windows\System32\atimpc64.dll
[MD5.A0A002EB027B83BCCEDD1D3BA9B37177] - |A| - [16/05/2017 18:06:46] - (.Copyright ฉ 2009 AMD - Multi-language DPPE DLL.) - [129.91 Ko] - (22.19.662.4) - C:\Windows\System32\atimuixx.dll
[MD5.6D495F51DF030A31902CC7FFB0E46E90] - |A| - [16/05/2017 18:06:46] - (.Copyright (c) 2010 Advanced Micro Devices, Inc. - Radeon spu api dll.) - [172.41 Ko] - (22.19.662.4) - C:\Windows\System32\atisamu64.dll
[MD5.A0A0F6FF440FC3855C022892FBF55E56] - |A| - [25/04/2017 00:56:36] - (.-.) - [3357.06 Ko] - (0.0.0.0) - C:\Windows\System32\atiumd6a.cap
[MD5.7C163EDE63854539828F5B2C1BC529FD] - |A| - [25/04/2017 00:55:26] - (.-.) - [153.46 Ko] - (0.0.0.0) - C:\Windows\System32\ativvsva.dat
[MD5.219D7091DD1D93728392337FE9C7ADD6] - |A| - [25/04/2017 00:55:26] - (.-.) - [200.15 Ko] - (0.0.0.0) - C:\Windows\System32\ativvsvl.dat
[MD5.EFFD0ABB4DDD2CCDD511F903D042AD5B] - |A| - [18/03/2017 22:57:05] - (.-.) - [77.65 Ko] - (0.0.0.0) - C:\Windows\System32\AverageRoom.bin
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [255.5 Ko] - C:\Windows\System32\bg-BG
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [4550.68 Ko] - C:\Windows\System32\Boot
[MD5.B13766AFE48C3CF775F53CE90488F7DE] - |A| - [18/03/2017 22:57:03] - (.Copyright (C) 2008 - Gestore contesto PAN Bluetooth.) - [90.5 Ko] - (1.0.0.1) - C:\Windows\System32\BthpanContextHandler.dll
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [0.93 Ko] - C:\Windows\System32\Bthprops
[MD5.1DD6C208249B1687642269C376303ADF] - |R| - [25/12/2018 20:15:38] - (.-.) - [116.23 Ko] - (0.0.0.0) - C:\Windows\System32\CaptureBrackets.hcp
[MD5.7018BCBE1442881631D11B38071DD4E6] - |R| - [25/12/2018 20:15:40] - (.-.) - [122.08 Ko] - (0.0.0.0) - C:\Windows\System32\CaptureCountdown.hcp
[MD5.CD113347D48F4F1CDD6F1B40F7A0B44B] - |R| - [25/12/2018 20:15:40] - (.-.) - [17.39 Ko] - (0.0.0.0) - C:\Windows\System32\CaptureToast.hcp
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 13:40:20] - [55096.19 Ko] - C:\Windows\System32\CatRoot
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [51572.02 Ko] - C:\Windows\System32\catroot2
[MD5.1A7726B28A2E3BAB27C43B50ECAB79E4] - |A| - [16/05/2017 18:06:46] - (.-.) - [369.41 Ko] - (0.0.0.0) - C:\Windows\System32\clinfo.exe
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [2892.6 Ko] - C:\Windows\System32\CodeIntegrity
[MD5.94E5C2F2E3ABF9DD03EE0C26C1E64311] - |A| - [16/05/2017 18:06:48] - (.AMD. - CoInstaller DLL.) - [902.88 Ko] - (1.0.5.9) - C:\Windows\System32\coinst_17.10.dll
[MD5.D86306E0DC601E89E31E52B1D929B9C8] - |A| - [27/07/2017 01:05:50] - (.AMD. - CoInstaller DLL.) - [911.41 Ko] - (1.0.5.9) - C:\Windows\System32\coinst_17.30.dll
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [357.5 Ko] - C:\Windows\System32\Com
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 13:40:20] - [388060.18 Ko] - C:\Windows\System32\config
[MD5.00000000000000000000000000000000] - |SD| - [18/03/2017 23:03:29] - [50.29 Ko] - C:\Windows\System32\Configuration
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [305 Ko] - C:\Windows\System32\cs-CZ
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [299.5 Ko] - C:\Windows\System32\da-DK
[MD5.75BC227ACD70C906785DB11F853165E4] - |A| - [18/03/2017 22:58:29] - (.-.) - [84 Ko] - (0.0.0.0) - C:\Windows\System32\DataStoreCacheDumpTool.exe
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [190.86 Ko] - C:\Windows\System32\DDFs
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [338 Ko] - C:\Windows\System32\de-DE
[MD5.618BA9E529EAB7E11DBA43469481835F] - |A| - [18/03/2017 22:57:05] - (.-.) - [4128.04 Ko] - (0.0.0.0) - C:\Windows\System32\DefaultHrtfs.bin
[MD5.664AA698FC0106A2B075A641E8DC6302] - |A| - [18/03/2017 23:03:37] - (.-.) - [0.84 Ko] - (0.0.0.0) - C:\Windows\System32\DefaultQuestions.json
[MD5.B5975F7F2CFAE8FF7817342F3CE311ED] - |A| - [12/12/2016 08:11:28] - (.Advanced Micro Devices. - Delay Audio Processing Object.) - [110.73 Ko] - (1.0.0.1) - C:\Windows\System32\DelayAPO.dll
[MD5.B1BF3694EC15D173C1DF74046A0115A6] - |A| - [16/05/2017 18:06:48] - (.-.) - [547.91 Ko] - (0.0.0.0) - C:\Windows\System32\dgtrayicon.exe
[MD5.00000000000000000000000000000000] - |SD| - [18/03/2017 23:03:29] - [870 Ko] - C:\Windows\System32\DiagSvcs
[MD5.E82380D30048D73E4D4CB8C925F6E721] - |A| - [18/03/2017 22:57:58] - (.-.) - [90.03 Ko] - (0.0.0.0) - C:\Windows\System32\DiskSnapshot.conf
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 13:40:22] - [7523.02 Ko] - C:\Windows\System32\Dism
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 13:40:22] - [1126.54 Ko] - C:\Windows\System32\downlevel
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:02:55] - [81569.4 Ko] - C:\Windows\System32\drivers
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 13:40:20] - [2436447.48 Ko] - C:\Windows\System32\DriverStore
[MD5.00000000000000000000000000000000] - |SD| - [18/03/2017 23:03:29] - [156 Ko] - C:\Windows\System32\dsc
[MD5.14996F92188DFE0C532C6B4BE0E47574] - |A| - [22/06/2015 02:49:50] - (.(c) VIA Technologies, Inc. - DTS Surround Sensation Control Page.) - [98.65 Ko] - (1.0.0.1) - C:\Windows\System32\Dts2PropPageExt.dll
[MD5.580440DB5255D163F835FD4EC982C44F] - |A| - [05/01/2018 14:00:21] - (.-.) - [31.18 Ko] - (0.0.0.0) - C:\Windows\System32\edgehtmlpluginpolicy.bin
[MD5.BD76ED39C8D04EC228D2CED63528F581] - |A| - [22/06/2015 02:51:26] - (.©2011 Dolby Laboratories. - Dolby PCEE4 ASL Analog x64.) - [127.09 Ko] - (7.2.7000.11) - C:\Windows\System32\EEA64A.dll
[MD5.C599243708A54946C3F1AC89921AF178] - |A| - [22/06/2015 02:51:26] - (.©2011 Dolby Laboratories. - Dolby PCEE4 ASL HDMI x64.) - [127.09 Ko] - (7.2.7000.11) - C:\Windows\System32\EEA64H.dll
[MD5.86F7F15051F0C4ABAED7323A04C1DD40] - |A| - [22/06/2015 02:51:26] - (.©2011 Dolby Laboratories. - Dolby PCEE4 COM DLL x64.) - [435.77 Ko] - (7.2.7000.11) - C:\Windows\System32\EED64A.dll
[MD5.A467834825D429EA8F3EB258222298BD] - |A| - [22/06/2015 02:51:26] - (.©2011 Dolby Laboratories. - Dolby PCEE4 HDMI COM DLL x64.) - [435.77 Ko] - (7.2.7000.11) - C:\Windows\System32\EED64H.dll
[MD5.1AEC452250C459B163D2B2F9A9AB17D2] - |A| - [18/05/2018 16:08:27] - (.-.) - [1805 Ko] - (1.10.63.1) - C:\Windows\System32\eed_ec.dll
[MD5.E61B9708AE9C5623C79B0E933897F8A5] - |A| - [18/05/2018 16:08:27] - (.Copyright (C) 2011 Samsung Electronics Co., Ltd. - Samsung Easy Eco Driver.) - [672.27 Ko] - (1.10.63.1) - C:\Windows\System32\eed_sl.exe
[MD5.983B32C79C9EDB7024682A1A69C8CB26] - |A| - [18/05/2018 16:08:27] - (.-.) - [0.27 Ko] - (0.0.0.0) - C:\Windows\System32\eed_sl.exe.config
[MD5.86992AD3E6F73094D59B9088C4D3FFE2] - |A| - [22/06/2015 02:51:26] - (.©2011 Dolby Laboratories. - Dolby PCEE4 GFX APO x64.) - [82.7 Ko] - (7.2.7000.11) - C:\Windows\System32\EEG64A.dll
[MD5.7E92DEFD7BE92FB074209546882F6D18] - |A| - [22/06/2015 02:51:26] - (.©2011 Dolby Laboratories. - Dolby PCEE4 HDMI GFX APO x64.) - [82.7 Ko] - (7.2.7000.11) - C:\Windows\System32\EEG64H.dll
[MD5.19322E8036AF874B11B5951DB1DF7F54] - |A| - [22/06/2015 02:51:26] - (.©2011 Dolby Laboratories. - Dolby PCEE4 LFX APO x64.) - [143.77 Ko] - (7.2.7000.11) - C:\Windows\System32\EEL64A.dll
[MD5.FDDEB262C668DBFC5FB1FFE14FEE5611] - |A| - [22/06/2015 02:51:26] - (.©2011 Dolby Laboratories. - Dolby PCEE4 HDMI LFX APO x64.) - [143.77 Ko] - (7.2.7000.11) - C:\Windows\System32\EEL64H.dll
[MD5.158149482870EFED2DC03502BF2AD996] - |A| - [22/06/2015 02:51:26] - (.©2011 Dolby Laboratories. - Dolby PCEE4 Control Panel x64.) - [7066 Ko] - (7.2.7000.11) - C:\Windows\System32\EEP64A.dll
[MD5.4DD73C7FA523C5CD2EFDC3A915D9855E] - |A| - [22/06/2015 02:51:28] - (.©2011 Dolby Laboratories. - Dolby PCEE4 HDMI Control Panel x64.) - [7066 Ko] - (7.2.7000.11) - C:\Windows\System32\EEP64H.dll
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [334.5 Ko] - C:\Windows\System32\el-GR
[MD5.00000000000000000000000000000000] - |D| - [20/03/2017 06:06:15] - [0 Ko] - C:\Windows\System32\en
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [242.5 Ko] - C:\Windows\System32\en-GB
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [3052 Ko] - C:\Windows\System32\en-US
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [327 Ko] - C:\Windows\System32\es-ES
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [266 Ko] - C:\Windows\System32\es-MX
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [239 Ko] - C:\Windows\System32\et-EE
[MD5.00000000000000000000000000000000] - |SD| - [18/03/2017 23:03:29] - [28250.66 Ko] - C:\Windows\System32\F12
[MD5.E65D2A37B6D4445D0CD9234BA933475B] - |A| - [05/01/2018 14:01:08] - (.-.) - [72.96 Ko] - (0.0.0.0) - C:\Windows\System32\FeatureToastHeroImg.jpg
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [305 Ko] - C:\Windows\System32\fi-FI
[MD5.BD9E768E24BAB255B4591F39CB423E73] - |A| - [31/07/2015 09:57:08] - (.- Microsoft® Forms DLL.) - [1607.66 Ko] - (16.0.4266.1001) - C:\Windows\System32\FM20.DLL
[MD5.A9BB252693AE466724F3BAEB34C6907D] - |A| - [31/07/2015 10:01:26] - (.- Microsoft® Forms International DLL.) - [31.2 Ko] - (16.0.4266.1001) - C:\Windows\System32\FM20ENU.DLL
[MD5.15D54104D901C4AF6A864FFF55B9823F] - |A| - [31/07/2015 10:29:46] - (.- DLL internazionale Microsoft® Forms.) - [35.2 Ko] - (16.0.4266.1001) - C:\Windows\System32\FM20ITA.DLL
[MD5.B989B5E556B4967BBADB1351DFAE3E54] - |A| - [05/07/2017 18:22:22] - (.-.) - [377.26 Ko] - (0.0.0.0) - C:\Windows\System32\FNTCACHE.DAT
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [273 Ko] - C:\Windows\System32\fr-CA
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [335 Ko] - C:\Windows\System32\fr-FR
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [0 Ko] - C:\Windows\System32\FxsTmp
[MD5.C7EB955B722C2764154DA0D696D8E0E5] - |A| - [16/05/2017 18:06:48] - (.-.) - [527.41 Ko] - (0.0.0.0) - C:\Windows\System32\GameManager64.dll
[MD5.D07F2281427BD098356EE74B6CB26B86] - |A| - [18/03/2017 22:57:02] - (.-.) - [89 Ko] - (0.0.0.0) - C:\Windows\System32\gatherNetworkInfo.vbs
[MD5.44A8F60A38C87271B582FE4DEEAF73E0] - |A| - [24/09/2018 21:20:56] - (.Copyright (C) 2017 - Gracenote SDK component.) - [4762.5 Ko] - (3.10.5.5585) - C:\Windows\System32\gnsdk_fp.dll
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [0 Ko] - C:\Windows\System32\GroupPolicy
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [0 Ko] - C:\Windows\System32\GroupPolicyUsers
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [260.5 Ko] - C:\Windows\System32\he-IL
[MD5.762F865F75F21FCB260E7C95404B5110] - |A| - [18/03/2017 22:58:18] - (.-.) - [122.5 Ko] - (0.0.0.0) - C:\Windows\System32\HeatCore.dll
[MD5.7B7859030FF4D38A912A7BCC4A1B3B5E] - |A| - [18/03/2017 22:59:09] - (.-.) - [14 Ko] - (0.0.0.0) - C:\Windows\System32\HolographicShareInterop.ProxyStub.dll
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [249 Ko] - C:\Windows\System32\hr-HR
[MD5.A9389CE5D5C8F605D7AB84DC549955BE] - |A| - [16/05/2017 18:06:48] - (.-.) - [278.41 Ko] - (0.0.0.0) - C:\Windows\System32\hsa-thunk64.dll
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [309.5 Ko] - C:\Windows\System32\hu-HU
[MD5.9D50BBD777C5BB9D2F348404F43A863C] - |A| - [18/03/2017 22:59:04] - (.-.) - [88 Ko] - (0.0.0.0) - C:\Windows\System32\hvsievaluator.exe
[MD5.05D356275A90F5F8CEDA076FEFF03430] - |A| - [18/03/2017 22:59:04] - (.-.) - [89 Ko] - (0.0.0.0) - C:\Windows\System32\hvsigpext.dll
[MD5.00000000000000000000000000000000] - |D| - [20/03/2017 06:07:27] - [31.52 Ko] - C:\Windows\System32\Hydrogen
[MD5.A565537F1580872AE5B95D0CA457D780] - |A| - [18/03/2017 22:58:01] - (.-.) - [44.4 Ko] - (0.0.0.0) - C:\Windows\System32\hypervisor.mof
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [5.36 Ko] - C:\Windows\System32\ias
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [36.27 Ko] - C:\Windows\System32\icsxml
[MD5.6DF9BA3AD0CD866EE939C4C49CEA7B30] - |A| - [18/03/2017 22:57:35] - (.-.) - [188.5 Ko] - (0.0.0.0) - C:\Windows\System32\IHDS.dll
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [25849.67 Ko] - C:\Windows\System32\IME
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [0 Ko] - C:\Windows\System32\inetsrv
[MD5.479B7966309A411BF4FC34898AC96557] - |A| - [18/03/2017 22:58:10] - (.-.) - [134.77 Ko] - (0.0.0.0) - C:\Windows\System32\InputHost.dll
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [6446.5 Ko] - C:\Windows\System32\InputMethod
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [0 Ko] - C:\Windows\System32\Ipmi
[MD5.00000000000000000000000000000000] - |D| - [20/03/2017 06:06:15] - [3454.5 Ko] - C:\Windows\System32\it
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [44160.7 Ko] - C:\Windows\System32\it-IT
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [240 Ko] - C:\Windows\System32\ja-jp
[MD5.D8F45BD2596E35E20A32EA3334A38171] - |A| - [26/07/2017 21:35:16] - (.-.) - [118.05 Ko] - (0.0.0.0) - C:\Windows\System32\kapp_ci.sbin
[MD5.DA921F39CCD51EA50E74C53426A3D674] - |A| - [02/09/2016 22:30:16] - (.-.) - [112.02 Ko] - (0.0.0.0) - C:\Windows\System32\kapp_si.sbin
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [237.5 Ko] - C:\Windows\System32\ko-KR
[MD5.050BC9351A3386458B696F8BCA78B27B] - |A| - [18/03/2017 22:57:05] - (.-.) - [145.55 Ko] - (0.0.0.0) - C:\Windows\System32\LargeRoom.bin
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [79.18 Ko] - C:\Windows\System32\Licenses
[MD5.10DA7720D2B8A683930DF25B9CAE4AA0] - |A| - [18/03/2017 22:59:09] - (.-.) - [30 Ko] - (0.0.0.0) - C:\Windows\System32\LockdownUtil.dll
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [18308.38 Ko] - C:\Windows\System32\LogFiles
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [244.5 Ko] - C:\Windows\System32\lt-LT
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [246.5 Ko] - C:\Windows\System32\lv-LV
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [30072.3 Ko] - C:\Windows\System32\Macromed
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [32.68 Ko] - C:\Windows\System32\MailContactsCalendarSync
[MD5.7A495CA1402C2F9F5D035092AD808669] - |A| - [18/03/2017 22:59:55] - (.-.) - [0.85 Ko] - (0.0.0.0) - C:\Windows\System32\manage-bde.wsf
[MD5.849F16A3B47653EC49ECCFD2083B8232] - |A| - [16/05/2017 18:06:48] - (.Copyright (C) 2013 AMD Inc. - Mantle loader.) - [195.41 Ko] - (22.19.662.4) - C:\Windows\System32\mantle64.dll
[MD5.B71A2A868EF3A00BE635E7F0D0DBF2AA] - |A| - [16/05/2017 18:06:48] - (.Copyright (C) 2013 AMD Inc. - Mantle extension library.) - [174.41 Ko] - (22.19.662.4) - C:\Windows\System32\mantleaxl64.dll
[MD5.3F0C67A297DF11A7E07026B3B8BB5A0C] - |A| - [22/06/2015 02:51:26] - (.© Waves Audio Ltd. - MaxxAudio APO.) - [662.28 Ko] - (3.6.0.0) - C:\Windows\System32\MaxxAudioAPO30.dll
[MD5.574258BF8B82C6283E6C41EBABDC1CC0] - |A| - [22/06/2015 02:51:26] - (.Copyright (C) 2010-2013 - MaxxAudio APO Shell.) - [1007.2 Ko] - (4.12.5.0) - C:\Windows\System32\MaxxAudioAPOShell64.dll
[MD5.DF28C4E10D2581DFAE8140EF29BB7E52] - |A| - [22/06/2015 02:51:28] - (.Copyright © 1996-2013 -.) - [27244.8 Ko] - (1.7.3.0) - C:\Windows\System32\MaxxAudioVnA64.dll
[MD5.65120A3575DA1536567A9CB77B8821B0] - |A| - [25/07/2018 19:50:45] - (.-.) - [760 Ko] - (0.0.0.0) - C:\Windows\System32\MBR2GPT.EXE
[MD5.BC74BDA8DC53F722C2CA686071600AE2] - |A| - [18/03/2017 22:57:05] - (.-.) - [107.45 Ko] - (0.0.0.0) - C:\Windows\System32\MediumRoom.bin
[MD5.00000000000000000000000000000000] - |SD| - [05/07/2017 18:22:24] - [8.73 Ko] - C:\Windows\System32\Microsoft
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [6714.81 Ko] - C:\Windows\System32\migration
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [47459.21 Ko] - C:\Windows\System32\migwiz
[MD5.00000000000000000000000000000000] - |D| - [05/07/2017 19:00:16] - [0 Ko] - C:\Windows\System32\MRT
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [45.5 Ko] - C:\Windows\System32\MSDRM
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [4180.28 Ko] - C:\Windows\System32\MsDtc
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [18.65 Ko] - C:\Windows\System32\MUI
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [294.5 Ko] - C:\Windows\System32\nb-NO
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [640 Ko] - C:\Windows\System32\NDF
[MD5.C146E873B22C3B300B21A859FE66C27A] - |A| - [18/03/2017 22:57:02] - (.-.) - [21.15 Ko] - (0.0.0.0) - C:\Windows\System32\NetTrace.PLA.Diagnostics.xml
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [51 Ko] - C:\Windows\System32\networklist
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [316 Ko] - C:\Windows\System32\nl-NL
[MD5.BE6A4E612B29E0EDE7FF437E99C32DCF] - |A| - [22/06/2015 02:51:26] - (.© QSound Labs, Inc. - nQ APO.) - [91.52 Ko] - (6.0.0.0) - C:\Windows\System32\nQAPO.dll
[MD5.B21696CAC01541D46A6E125F7973EA51] - |A| - [22/06/2015 02:49:50] - (.(c) QSound Labs, Inc. -.) - [92.5 Ko] - (6.0.6001.1) - C:\Windows\System32\nQPropPageExt.dll
[MD5.00000000000000000000000000000000] - |SD| - [18/03/2017 23:03:29] - [16570.66 Ko] - C:\Windows\System32\Nui
[MD5.C9246EF96F14CB2F0C393F73A20590D8] - |A| - [18/03/2017 23:03:38] - (.-.) - [15.57 Ko] - (0.0.0.0) - C:\Windows\System32\OEMDefaultAssociations.xml
[MD5.F3DC097E834C1A11F2BEDFD429C644A9] - |A| - [05/01/2018 14:00:56] - (.-.) - [0.41 Ko] - (0.0.0.0) - C:\Windows\System32\OkDone_80.contrast-black.png
[MD5.BFE1CCA08FEFC8A3422F7DA615567D75] - |A| - [05/01/2018 14:00:56] - (.-.) - [0.43 Ko] - (0.0.0.0) - C:\Windows\System32\OkDone_80.contrast-white.png
[MD5.F3DC097E834C1A11F2BEDFD429C644A9] - |A| - [05/01/2018 14:00:56] - (.-.) - [0.41 Ko] - (0.0.0.0) - C:\Windows\System32\OkDone_80.png
[MD5.2901049544FDF863362FABA2363EB647] - |A| - [18/03/2017 22:57:12] - (.-.) - [0.82 Ko] - (0.0.0.0) - C:\Windows\System32\onlinesetup.cmd
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [13283.52 Ko] - C:\Windows\System32\oobe
[MD5.2AD7B4F3C8D2BB686D231EDFF404B7A4] - |A| - [06/07/2017 21:04:33] - (.Copyright (C) 2000-2006 - Standard OpenAL(TM) Implementation.) - [120.02 Ko] - (6.14.357.24) - C:\Windows\System32\OpenAL32.dll
[MD5.42D2360079B1DF3230024AE920737367] - |A| - [18/03/2017 22:57:05] - (.-.) - [45.81 Ko] - (0.0.0.0) - C:\Windows\System32\OutdoorAudioEnvironment.bin
[MD5.899A5BF1669610CDB78D322AC8D9358B] - |A| - [01/03/2013 03:49:36] - (.Copyright © 2010-2013 Riverbed Technology, Inc. Copyright © 2005-2010 CACE Technologies. Copyright © 1999-2005 NetGroup, Politecnico di Torino. - packet.dll (Vista) Dynamic Link Library.) - [105.24 Ko] - (4.1.0.2980) - C:\Windows\System32\Packet.dll
[MD5.409368398735FB84299B47E1A68AE59D] - |A| - [18/03/2017 23:05:34] - (.-.) - [4663.87 Ko] - (0.0.0.0) - C:\Windows\System32\perfc009.dat
[MD5.65D896A1ACC6687F2276F83B7B9890F5] - |A| - [20/03/2017 06:06:17] - (.-.) - [5329.68 Ko] - (0.0.0.0) - C:\Windows\System32\perfc010.dat
[MD5.1E60BC5E525063B96078DF17FBD3C4E1] - |A| - [18/03/2017 23:05:34] - (.-.) - [32.64 Ko] - (0.0.0.0) - C:\Windows\System32\perfd009.dat
[MD5.4F32511BD6124C1B65C8F7FCD244A82B] - |A| - [20/03/2017 06:06:17] - (.-.) - [38.93 Ko] - (0.0.0.0) - C:\Windows\System32\perfd010.dat
[MD5.25FD4D42FCA43190D7773865D3F86D9E] - |A| - [18/03/2017 23:05:34] - (.-.) - [5460.39 Ko] - (0.0.0.0) - C:\Windows\System32\perfh009.dat
[MD5.E4EF3201D4F64369E2F42C058328A321] - |A| - [20/03/2017 06:06:17] - (.-.) - [17007.64 Ko] - (0.0.0.0) - C:\Windows\System32\perfh010.dat
[MD5.A378921CA78A0BB3E5BA4F1658CAC399] - |A| - [05/07/2017 18:30:54] - (.-.) - [33190.38 Ko] - (0.0.0.0) - C:\Windows\System32\PerfStringBackup.INI
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [314.5 Ko] - C:\Windows\System32\pl-PL
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [634.5 Ko] - C:\Windows\System32\PointOfService
[MD5.00000000000000000000000000000000] - |D| - [20/03/2017 06:06:16] - [419.04 Ko] - C:\Windows\System32\Printing_Admin_Scripts
[MD5.107C6385F62993C7F37A43043FEF4656] - |A| - [27/10/2016 03:50:30] - (.TODO: (c) <Company name>. - TODO: <File description>.) - [67.97 Ko] - (1.0.0.1) - C:\Windows\System32\PropPageExt.dll
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [0 Ko] - C:\Windows\System32\ProximityToast
[MD5.007893E8374C766471239EB291BA8C17] - |A| - [18/03/2017 22:57:54] - (.-.) - [4.05 Ko] - (0.0.0.0) - C:\Windows\System32\psmodulediscoveryprovider.mof
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [316.5 Ko] - C:\Windows\System32\pt-BR
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [311.5 Ko] - C:\Windows\System32\pt-PT
[MD5.B0949EAACB18D3ACD8F8551AE9AB0CD7] - |A| - [16/05/2017 18:06:48] - (.(c) Advanced Micro Devices, Inc. - AMD RapidFire.) - [542.41 Ko] - (1.1.0.22) - C:\Windows\System32\Rapidfire64.dll
[MD5.F07F0B87052AAB8F02CAB384F68715DA] - |A| - [16/05/2017 18:06:48] - (.(c) Advanced Micro Devices, Inc. - AMD Rapid Fire Server.) - [52.41 Ko] - (1.1.0.19) - C:\Windows\System32\RapidFireServer64.dll
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [23.75 Ko] - C:\Windows\System32\ras
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [0 Ko] - C:\Windows\System32\RasToast
[MD5.DF98B824D9FA64358198283A97F453E3] - |A| - [18/03/2017 22:59:08] - (.Copyright (C) 2009 - RemoteFX Helper.) - [104 Ko] - (1.1.0.0) - C:\Windows\System32\RDVGHelper.exe
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [1.05 Ko] - C:\Windows\System32\Recovery
[MD5.692DC6EF573FFCDD9DFB55D1C783DB93] - |A| - [18/03/2017 22:58:01] - (.-.) - [0.16 Ko] - (0.0.0.0) - C:\Windows\System32\removehypervisor.mof
[MD5.D9DF00023703568AE6B4303E3C5C90BB] - |A| - [18/03/2017 22:57:47] - (.-.) - [8.84 Ko] - (0.0.0.0) - C:\Windows\System32\ResPriHMImageList
[MD5.99C7924C7268BABB5C4E3CFD2EE03331] - |A| - [18/03/2017 22:57:47] - (.-.) - [8.28 Ko] - (0.0.0.0) - C:\Windows\System32\ResPriImageList
[MD5.831C579709F4761E4AB7053FCF4176EC] - |A| - [05/01/2018 14:00:57] - (.-.) - [0.74 Ko] - (0.0.0.0) - C:\Windows\System32\RestartNowPower_80.contrast-black.png
[MD5.DF286186041C6BF73C5DC21CEEEFFED5] - |A| - [05/01/2018 14:00:57] - (.-.) - [0.77 Ko] - (0.0.0.0) - C:\Windows\System32\RestartNowPower_80.contrast-white.png
[MD5.831C579709F4761E4AB7053FCF4176EC] - |A| - [05/01/2018 14:00:57] - (.-.) - [0.74 Ko] - (0.0.0.0) - C:\Windows\System32\RestartNowPower_80.png
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [0.07 Ko] - C:\Windows\System32\restore
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [251.5 Ko] - C:\Windows\System32\ro-RO
[MD5.AF47D6660569DFA46BC4E1CD21E1624B] - |A| - [28/09/2012 21:45:18] - (.-.) - [240.5 Ko] - (0.0.0.0) - C:\Windows\System32\rtvcvfw64.dll
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [309.5 Ko] - C:\Windows\System32\ru-RU
[MD5.56B23318DE09559AE0A7EA51F068AC3B] - |A| - [02/09/2016 15:24:22] - (.-.) - [150.77 Ko] - (0.0.0.0) - C:\Windows\System32\samu_krnl_ci.sbin
[MD5.A769B352B827590EA4CCAC16E6269E33] - |A| - [12/12/2013 13:53:56] - (.-.) - [135.58 Ko] - (0.0.0.0) - C:\Windows\System32\samu_krnl_isv_ci.sbin
[MD5.BE4936FC24948E7900778C41D5F24DD3] - |A| - [15/02/2016 21:02:16] - (.Copyright 2012 - Samsung Electronics.) - [228.87 Ko] - (1.0.0.6) - C:\Windows\System32\SBuySupplies.exe
[MD5.5C18CD22BE4628865FCB63337A6E5EF6] - |A| - [18/03/2017 22:59:52] - (.-.) - [10.18 Ko] - (0.0.0.0) - C:\Windows\System32\ScavengeSpace.xml
[MD5.2F24BC74DCB28FE032C1596755385917] - |A| - [05/01/2018 14:00:56] - (.-.) - [0.53 Ko] - (0.0.0.0) - C:\Windows\System32\ScheduleTime_80.contrast-black.png
[MD5.E72B1B6800DE45AA9AE7E10F899E5999] - |A| - [05/01/2018 14:00:56] - (.-.) - [0.54 Ko] - (0.0.0.0) - C:\Windows\System32\ScheduleTime_80.contrast-white.png
[MD5.2F24BC74DCB28FE032C1596755385917] - |A| - [05/01/2018 14:00:56] - (.-.) - [0.53 Ko] - (0.0.0.0) - C:\Windows\System32\ScheduleTime_80.png
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [6.92 Ko] - C:\Windows\System32\SecureBootUpdates
[MD5.D3E9EEDC0128DD1FB9E45D85E7E21F0B] - |A| - [16/05/2017 18:06:46] - (.Copyright © 2008-2009 AMD - AMD External Events Service Module.) - [538.88 Ko] - (22.19.162.4) - C:\Windows\System32\SETAF3E.tmp
[MD5.4AF08E2098886544DDCD0B301E15EA81] - |A| - [16/05/2017 18:06:46] - (.Copyright (C) 2008-2016 Advanced Micro Devices, Inc. - ADL.) - [1480.88 Ko] - (22.19.162.4) - C:\Windows\System32\SETC848.tmp
[MD5.94E5C2F2E3ABF9DD03EE0C26C1E64311] - |A| - [16/05/2017 18:06:48] - (.AMD. - CoInstaller DLL.) - [902.88 Ko] - (1.0.5.9) - C:\Windows\System32\SETEEBA.tmp
[MD5.D86306E0DC601E89E31E52B1D929B9C8] - |A| - [27/07/2017 01:05:50] - (.AMD. - CoInstaller DLL.) - [911.41 Ko] - (1.0.5.9) - C:\Windows\System32\SETFDF1.tmp
[MD5.A8308D2F3DDE0745E8B678BF69A2ECD0] - |A| - [18/03/2017 22:58:03] - (.-.) - [8 Ko] - (0.0.0.0) - C:\Windows\System32\settings.dat
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [253 Ko] - C:\Windows\System32\sk-SK
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [249 Ko] - C:\Windows\System32\sl-SI
[MD5.00000000000000000000000000000000] - |D| - [05/07/2017 18:22:25] - [149335.58 Ko] - C:\Windows\System32\SleepStudy
[MD5.00000000000000000000000000000000] - |D| - [20/03/2017 06:06:16] - [52.62 Ko] - C:\Windows\System32\slmgr
[MD5.1C6F12AA3D178A0A953E8005B3CD4CDE] - |A| - [18/03/2017 22:57:05] - (.-.) - [68.14 Ko] - (0.0.0.0) - C:\Windows\System32\SmallRoom.bin
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 13:40:20] - [13385.02 Ko] - C:\Windows\System32\SMI
[MD5.55121989BE7B289813D419BA0FDEE8B7] - |A| - [05/01/2018 14:00:57] - (.-.) - [0.9 Ko] - (0.0.0.0) - C:\Windows\System32\Snooze_80.contrast-black.png
[MD5.E30B7D226E7B5B0EC2B9FC2316694ECC] - |A| - [05/01/2018 14:00:57] - (.-.) - [0.88 Ko] - (0.0.0.0) - C:\Windows\System32\Snooze_80.contrast-white.png
[MD5.55121989BE7B289813D419BA0FDEE8B7] - |A| - [05/01/2018 14:00:57] - (.-.) - [0.9 Ko] - (0.0.0.0) - C:\Windows\System32\Snooze_80.png
[MD5.51B22297C36F12C2311FDC7D9337C207] - |A| - [30/04/2018 21:24:17] - (.-.) - [36.5 Ko] - (0.0.0.0) - C:\Windows\System32\SpectrumSyncClient.dll
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [7418.91 Ko] - C:\Windows\System32\Speech
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [11620.29 Ko] - C:\Windows\System32\Speech_OneCore
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [200812.19 Ko] - C:\Windows\System32\spool
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [9565.53 Ko] - C:\Windows\System32\spp
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [31.88 Ko] - C:\Windows\System32\sppui
[MD5.4A9518520953F746C1A705DE58D4F075] - |A| - [05/07/2017 18:48:22] - (.-.) - [64 Ko] - (0.0.0.0) - C:\Windows\System32\spu_storage.bin
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [251.5 Ko] - C:\Windows\System32\sr-Latn-RS
[MD5.5128BC123224124D67397A1BE698431C] - |A| - [18/03/2017 22:57:16] - (.-.) - [56.63 Ko] - (0.0.0.0) - C:\Windows\System32\srms.dat
[MD5.00000000000000000000000000000000] - |D| - [05/07/2017 18:49:13] - [2140.42 Ko] - C:\Windows\System32\SRSLabs
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [19672 Ko] - C:\Windows\System32\sru
[MD5.4A0E4F3F234BF24F7657CF184AE77437] - |N| - [18/05/2018 16:08:27] - (.- Device Monitor.) - [85.5 Ko] - (1.6.2.0) - C:\Windows\System32\ssdevm64.dll
[MD5.E042A078EDE878E1F489D08F045D2205] - |A| - [18/03/2017 22:57:05] - (.-.) - [368.5 Ko] - (0.0.0.0) - C:\Windows\System32\ssdm.dll
[MD5.FC21BF5A1667FC745FE53D05DA4CB8A2] - |A| - [18/05/2018 16:08:27] - (.Copyright (C) 2004  Co., Ltd. - SSCoInst.) - [87.5 Ko] - (1.0.0.4) - C:\Windows\System32\ssj1mci.dll
[MD5.627C52B757CA8C3F02F917D85172759B] - |A| - [18/05/2018 16:08:27] - (.Copyright © 2006 - SSCoInstExe.) - [154.34 Ko] - (1.0.1.1) - C:\Windows\System32\ssj1mci.exe
[MD5.DBAB523742E598670B37A65B16528CE1] - |A| - [18/05/2018 16:08:27] - (.- Language Monitor for Status Monitor.) - [22 Ko] - (1.4.9.0) - C:\Windows\System32\ssj1mlm.dll
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [300.5 Ko] - C:\Windows\System32\sv-SE
[MD5.A60E4472A8D8743CE3435062099C07EF] - |A| - [25/12/2018 20:15:32] - (.-.) - [34.47 Ko] - (0.0.0.0) - C:\Windows\System32\SyncAppvPublishingServer.exe
[MD5.20C4FE2B130D9F0C92D7629E71AFBB66] - |A| - [18/03/2017 22:59:03] - (.-.) - [1.68 Ko] - (0.0.0.0) - C:\Windows\System32\SyncAppvPublishingServer.vbs
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 13:40:22] - [1595.88 Ko] - C:\Windows\System32\Sysprep
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [906.28 Ko] - C:\Windows\System32\SystemResetPlatform
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [565.3 Ko] - C:\Windows\System32\Tasks
[MD5.D602CA245CC6774A0981B607F0675609] - |A| - [18/03/2017 22:58:24] - (.-.) - [58.71 Ko] - (0.0.0.0) - C:\Windows\System32\tcpmon.ini
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [234 Ko] - C:\Windows\System32\th-TH
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [297.5 Ko] - C:\Windows\System32\tr-TR
[MD5.B88B8D017386A00D7724519F475317A0] - |A| - [18/03/2017 22:58:18] - (.-.) - [10.33 Ko] - (0.0.0.0) - C:\Windows\System32\TransformPPSToWlan.xslt
[MD5.2F05390B798363D51EBE65D6320CD45E] - |A| - [18/03/2017 22:58:18] - (.-.) - [1.65 Ko] - (0.0.0.0) - C:\Windows\System32\TransformPPSToWlanCredentials.xslt
[MD5.D200497DD3A24F138123F0EB6C385D1D] - |A| - [18/03/2017 22:59:03] - (.-.) - [0.14 Ko] - (0.0.0.0) - C:\Windows\System32\UevAppMonitor.exe.config
[MD5.4AAEE8D86EC81DA2A1514ABC77E71F57] - |A| - [18/03/2017 22:59:04] - (.-.) - [3.34 Ko] - (0.0.0.0) - C:\Windows\System32\UevCustomActionTypes.tlb
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [247 Ko] - C:\Windows\System32\uk-UA
[MD5.87D70CBC98FE1DD581712EB999BFF276] - |A| - [15/02/2016 21:01:40] - (.Copyright (C) 2004  Co., Ltd. - SSCoInst.) - [96.02 Ko] - (1.0.0.4) - C:\Windows\System32\us008ci.dll
[MD5.0D7EFDE2DDE7D2D4EAF1EF406F483206] - |A| - [15/02/2016 21:02:16] - (.- UPD Co-Installer.) - [162.87 Ko] - (3.0.0.2) - C:\Windows\System32\us008ci.exe
[MD5.6E4186AAF7E33C57E93EA3B02C4B5E79] - |A| - [15/02/2016 21:01:54] - (.- Language Monitor for Status Monitor.) - [30.52 Ko] - (1.4.9.0) - C:\Windows\System32\us008lm.dll
[MD5.360A03DA4800FEB04AFBA812F4CF4F70] - |A| - [27/10/2016 03:54:26] - (.(c) VIA Technologies, Inc. - ViaKaraoke APO.) - [1171 Ko] - (0.1.0.0) - C:\Windows\System32\ViaKaraokeApo.dll
[MD5.E0773F9C412B839441077A92E6925862] - |A| - [27/10/2016 03:53:10] - (.(c)VIA Technologies,Inc. - VIA APO for MicArray Applications..) - [137.13 Ko] - (0.2.0.0) - C:\Windows\System32\ViaKaraokePropPageExt.dll
[MD5.26F9E6EC387A35B9C0543F10A0E8E798] - |A| - [27/10/2016 03:53:12] - (.(c) VIA Technologies, Inc. - Service binary.) - [40.97 Ko] - (0.1.0.0) - C:\Windows\System32\ViakaraokeSrv.exe
[MD5.81B0D2D39DAD47599BE4610F55B738F8] - |A| - [27/10/2016 03:54:32] - (.(c)Copyright Reserved. VIA Technologies,Inc. - ViaMicArray APO.) - [1997.27 Ko] - (0.5.0.0) - C:\Windows\System32\ViaMicArrayAPO.dll
[MD5.106F9C5B6B226A36D8CFEF9836A69D1A] - |A| - [27/10/2016 03:53:12] - (.VIA Technologies,Inc. - VIA APO for MicArray Applications..) - [109.63 Ko] - (0.5.0.0) - C:\Windows\System32\ViaMicArrayPropPageExt.dll
[MD5.FBAC467B17EB4F728C8A0EB97E34835D] - |A| - [27/10/2016 03:53:20] - (.VIA Technologies, Inc. - VIA LFX/GFX DSP UI component.) - [3237.63 Ko] - (11.5.0.20) - C:\Windows\System32\VIAPropPageExt.dll
[MD5.1A61D143A9FAC65DEE177B661C764985] - |A| - [22/06/2015 02:51:28] - (.Copyright (c) VIA Technologies, Inc. All Rights Reserved - VIA LFX/GFX DSP Component.) - [603.02 Ko] - (1.0.0.0) - C:\Windows\System32\VIASysFx.dll
[MD5.6278F7F2E8383CC53D06591BF0DCA342] - |A| - [27/10/2016 03:55:00] - (.Copyright (c) 2006-2013 Creative Technology Ltd. - Creative Audio Processing Object Module.) - [2002.91 Ko] - (1.2.16.73) - C:\Windows\System32\VMAPO264.DLL
[MD5.1E01A83EE85DA20037034F3D82ADB4B3] - |A| - [27/10/2016 03:55:08] - (.Copyright (c) 2006-2011 Creative Technology Ltd. - Creative Audio Processing Object Module.) - [897.79 Ko] - (1.0.54.0) - C:\Windows\System32\VMAPO64.DLL
[MD5.81A4366735058225FCACAF3ED0209E12] - |A| - [27/10/2016 03:55:10] - (.Copyright (c) 2006-2010 Creative Technology Ltd. - Creative Chaining Property Page Loader Module.) - [76.95 Ko] - (1.0.0.180) - C:\Windows\System32\VMPPCN64.DLL
[MD5.D790A951F4E0EE1BDCC9AD363C9C0D6E] - |A| - [27/10/2016 03:55:10] - (.Copyright (c) 2006-2011 Creative Technology Ltd. - Creative Property Page Loader Module.) - [81.02 Ko] - (1.0.54.0) - C:\Windows\System32\VMPPLD64.DLL
[MD5.9721698CBCE6B98639914FA9EEDD99CA] - |A| - [27/10/2016 03:55:18] - (.Copyright (c) 2006-2011 Creative Technology Ltd. - Creative Audio Processing Object Module.) - [639.22 Ko] - (1.0.15.150) - C:\Windows\System32\VMTHX64.DLL
[MD5.E5226CB399E1B325AB4D0C010DF607B5] - |A| - [27/10/2016 03:55:20] - (.Copyright (c) 2006-2010 Creative Technology Ltd. - Audio Processing Object Chaining Module.) - [409.35 Ko] - (1.0.0.270) - C:\Windows\System32\VMWRP64.DLL
[MD5.C23C0F64BDADC37701B6BBE1769456DE] - |A| - [15/06/2017 21:32:44] - (.Copyright (C) 2015-2017 - Vulkan Loader.) - [529.28 Ko] - (1.0.51.0) - C:\Windows\System32\vulkan-1-1-0-51-0.dll
[MD5.C23C0F64BDADC37701B6BBE1769456DE] - |A| - [04/09/2017 19:08:30] - (.Copyright (C) 2015-2017 - Vulkan Loader.) - [529.28 Ko] - (1.0.51.0) - C:\Windows\System32\vulkan-1.dll
[MD5.E195CD6393DFC309CF3CFB3CF17865EC] - |A| - [15/06/2017 21:32:40] - (.-.) - [248.28 Ko] - (0.0.0.0) - C:\Windows\System32\vulkaninfo-1-1-0-51-0.exe
[MD5.E195CD6393DFC309CF3CFB3CF17865EC] - |A| - [04/09/2017 19:08:30] - (.-.) - [248.28 Ko] - (0.0.0.0) - C:\Windows\System32\vulkaninfo.exe
[MD5.63A673FB3E0FD1B30D7994ABD7F13E49] - |A| - [22/06/2015 02:51:28] - (.Copyright © 1996-2012 - General Library for Plug-Ins.) - [2080.52 Ko] - (4.4.3.0) - C:\Windows\System32\WavesGUILib64.dll
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [82651.51 Ko] - C:\Windows\System32\wbem
[MD5.00000000000000000000000000000000] - |D| - [20/03/2017 06:06:16] - [0 Ko] - C:\Windows\System32\WCN
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [50600.82 Ko] - C:\Windows\System32\WDI
[MD5.6EDD021A8B6457DDE09DE7B7FA4E8C8B] - |A| - [18/03/2017 22:57:19] - (.-.) - [0.6 Ko] - (0.0.0.0) - C:\Windows\System32\WdsUnattendTemplate.xml
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [1.12 Ko] - C:\Windows\System32\WinBioDatabase
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [76234.65 Ko] - C:\Windows\System32\WinBioPlugIns
[MD5.558D9282D5CEA82B2253B88017552F33] - |A| - [18/03/2017 22:58:18] - (.-.) - [96 Ko] - (0.0.0.0) - C:\Windows\System32\WindowsDefaultHeatProcessor.dll
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [10650.14 Ko] - C:\Windows\System32\WindowsPowerShell
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [228148 Ko] - C:\Windows\System32\winevt
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [4753.58 Ko] - C:\Windows\System32\WinMetadata
[MD5.00000000000000000000000000000000] - |D| - [20/03/2017 06:06:16] - [106.24 Ko] - C:\Windows\System32\winrm
[MD5.A672F1CF00FA5AC3F4F59577F77D8C86] - |A| - [01/03/2013 03:49:22] - (.Copyright © 2010-2013 Riverbed Technology, Inc. Copyright © 2005-2010 CACE Technologies. Copyright © 1999-2005 NetGroup, Politecnico di Torino. - wpcap.dll Dynamic Link Library - based on libpcap 1.0rel0b branch (20091008).) - [361.74 Ko] - (4.1.0.2980) - C:\Windows\System32\wpcap.dll
[MD5.C30C621748C66CE751B19B2788559A3E] - |A| - [18/03/2017 22:58:17] - (.-.) - [4.58 Ko] - (0.0.0.0) - C:\Windows\System32\wpcmon.png
[MD5.B6B479B04C64AF5EF36C24EBDF278302] - |A| - [18/03/2017 22:58:01] - (.-.) - [0.71 Ko] - (0.0.0.0) - C:\Windows\System32\wpr.config.xml
[MD5.549347BCD4AACD63243D78E8F869DBB1] - |A| - [06/07/2017 21:04:33] - (.Copyright © 2008 - OpenAL32.) - [455.52 Ko] - (2.2.0.5) - C:\Windows\System32\wrap_oal.dll
[MD5.19820EEC2D1A4D264F051B789F79D51A] - |A| - [11/05/2018 16:20:03] - (.-.) - [84 Ko] - (0.0.0.0) - C:\Windows\System32\xboxgipsynthetic.dll
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [211.5 Ko] - C:\Windows\System32\zh-CN
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [206.5 Ko] - C:\Windows\System32\zh-TW
[MD5.00000000000000000000000000000000] - |D| - [20/03/2017 06:06:16] - [0 Ko] - C:\Windows\SysWOW64\0409
[MD5.82C37C3E27020AF6C2E018E944284676] - |A| - [18/03/2017 22:58:44] - (.-.) - [0.3 Ko] - (0.0.0.0) - C:\Windows\SysWOW64\@AudioToastIcon.png
[MD5.495C1F072039B434827A5FE0D9761E4D] - |A| - [18/03/2017 22:58:54] - (.-.) - [0.32 Ko] - (0.0.0.0) - C:\Windows\SysWOW64\@EnrollmentToastIcon.png
[MD5.1622DE67156496C78D6B7BE9B471645B] - |A| - [18/03/2017 22:58:51] - (.-.) - [0.39 Ko] - (0.0.0.0) - C:\Windows\SysWOW64\@VpnToastIcon.png
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 13:40:24] - [1998.91 Ko] - C:\Windows\SysWOW64\AdvancedInstallers
[MD5.98851BABE0ADD4E79B86433151DD2AF1] - |A| - [03/08/2009 01:21:52] - (.-.) - [57.27 Ko] - (8.9.25.0) - C:\Windows\SysWOW64\AgCPanelFrench.dll
[MD5.143EC9C7D18154DBB0760C3FB653EF31] - |A| - [03/08/2009 01:21:52] - (.-.) - [57.27 Ko] - (8.9.26.0) - C:\Windows\SysWOW64\AgCPanelGerman.dll
[MD5.7F816BA97FE0CE01ACB51D9DDC0F188A] - |A| - [03/08/2009 01:21:54] - (.-.) - [57.27 Ko] - (8.9.25.0) - C:\Windows\SysWOW64\AgCPanelJapanese.dll
[MD5.D5BD2F5CE4CD83935B54C37E9CB47F22] - |A| - [03/08/2009 01:21:54] - (.-.) - [57.27 Ko] - (8.9.18.0) - C:\Windows\SysWOW64\AgCPanelKorean.dll
[MD5.905386712352370426133C0CE0E428A5] - |A| - [03/08/2009 01:21:54] - (.-.) - [57.27 Ko] - (8.9.25.0) - C:\Windows\SysWOW64\AgCPanelPortugese.dll
[MD5.FF6BCD4B9B2DEF42289341EB7C200599] - |A| - [03/08/2009 01:21:54] - (.-.) - [57.27 Ko] - (8.9.25.0) - C:\Windows\SysWOW64\AgCPanelSimplifiedChinese.dll
[MD5.2733F70228CCA6D0E3162CF5E1DD5716] - |A| - [03/08/2009 01:21:54] - (.-.) - [57.27 Ko] - (8.9.25.0) - C:\Windows\SysWOW64\AgCPanelSpanish.dll
[MD5.76AA46B94C490518412FBA431515EF9C] - |A| - [03/08/2009 01:21:54] - (.-.) - [57.27 Ko] - (8.9.25.0) - C:\Windows\SysWOW64\AgCPanelSwedish.dll
[MD5.3EB00E82E0A3339E0B31220628E3D49D] - |A| - [03/08/2009 01:21:54] - (.-.) - [57.27 Ko] - (8.9.25.0) - C:\Windows\SysWOW64\AgCPanelTraditionalChinese.dll
[MD5.00000000000000000000000000000000] - |D| - [27/02/2018 23:39:36] - [635.71 Ko] - C:\Windows\SysWOW64\AGEIA
[MD5.68CF4C147C95C7E6A1E5A6EE6DC7A185] - |A| - [15/12/2015 17:54:08] - (.-.) - [0.14 Ko] - (0.0.0.0) - C:\Windows\SysWOW64\amd-vulkan32.json
[MD5.8F08BFA772CE5C1DB1244AE7EDD26EFD] - |A| - [16/05/2017 18:05:56] - (.Copyright (c) 2009 Advanced Micro Devices, Inc. - Radeon AMD AVE Driver Component.) - [122.97 Ko] - (22.19.662.4) - C:\Windows\SysWOW64\amdave32.dll
[MD5.5D69ED07B649C77B47C53A3D772C0068] - |A| - [16/05/2017 18:06:42] - (.-.) - [360.41 Ko] - (0.0.0.0) - C:\Windows\SysWOW64\amdgfxinfo32.dll
[MD5.91AAF85C6DB5C5B18078B2DE92CA4565] - |A| - [16/05/2017 18:05:56] - (.Copyright (C) 2013 - Universal Adapter for Adobe.) - [170.59 Ko] - (22.19.662.4) - C:\Windows\SysWOW64\amdhcp32.dll
[MD5.1807ABC9E57D70AA830E306B753E8634] - |A| - [16/05/2017 18:06:42] - (.Advanced Micro Devices, Inc. Copyright (C) 2015 - LiquidVR SDK 1.0.) - [687.91 Ko] - (1.0.11.0) - C:\Windows\SysWOW64\amdlvr32.dll
[MD5.03D0391DC8AD08492F7AD26CCDACDD6D] - |A| - [16/05/2017 18:06:42] - (.Copyright (c) 2013 Advanced Micro Devices, Inc. - Radeon MCL Universal Driver.) - [81.91 Ko] - (1.6.0.0) - C:\Windows\SysWOW64\amdmcl32.dll
[MD5.E1698BEE10D0F1BEA99EC30CAD2ED069] - |A| - [16/05/2017 18:05:56] - (.Copyright (c) 2009 Advanced Micro Devices, Inc. - Radeon PCOM Universal Driver.) - [109.59 Ko] - (22.19.662.4) - C:\Windows\SysWOW64\amdpcom32.dll
[MD5.AFACD807E42701342A745635A567BADB] - |A| - [16/05/2017 18:06:44] - (.Copyright (C) 2015 AMD Inc. - Vulkan driver, support for SI family and above.) - [10042.41 Ko] - (1.0.51.0) - C:\Windows\SysWOW64\amdvlk32.dll
[MD5.174EBE61A4443C7089660F964A82C8D0] - |A| - [16/05/2017 18:06:44] - (.Copyright (C) 2014-2015 AMD Inc. - amdxcstub32.dll.) - [105.41 Ko] - (8.18.10.195) - C:\Windows\SysWOW64\amdxc32.dll
[MD5.636136D5036C4BD9DB50BDECBBC84696] - |A| - [16/05/2017 18:06:46] - (.Advanced Micro Devices, Inc. Copyright (C) 2017 - Advanced Media Framework.) - [2475.91 Ko] - (1.4.4.0) - C:\Windows\SysWOW64\amfrt32.dll
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [0 Ko] - C:\Windows\SysWOW64\AppLocker
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [255 Ko] - C:\Windows\SysWOW64\ar-SA
[MD5.FD6825120CB221197727001462355167] - |A| - [27/07/2017 01:04:40] - (.Copyright (C) 2008-2016 Advanced Micro Devices, Inc. - ADL.) - [1036.91 Ko] - (22.19.662.4) - C:\Windows\SysWOW64\atiadlxx.dll
[MD5.FD6825120CB221197727001462355167] - |A| - [16/05/2017 18:06:46] - (.Copyright (C) 2008-2016 Advanced Micro Devices, Inc. - ADL.) - [1036.91 Ko] - (22.19.662.4) - C:\Windows\SysWOW64\atiadlxy.dll
[MD5.81AF51277D9FB5030D80E0157303BA17] - |A| - [25/04/2017 01:06:40] - (.-.) - [795.77 Ko] - (0.0.0.0) - C:\Windows\SysWOW64\atiapfxx.blb
[MD5.035DF8F635F98A4FC5BB3EE38CB1DBF7] - |A| - [16/05/2017 18:06:46] - (.Copyright (C) 1998-2012 AMD Inc. - aticfxstub32.dll.) - [153.49 Ko] - (8.17.10.1560) - C:\Windows\SysWOW64\aticfx32.dll
[MD5.2DA159018286069BCE0C12D688772744] - |A| - [16/05/2017 18:06:46] - (.-.) - [107.91 Ko] - (0.0.0.0) - C:\Windows\SysWOW64\atidxx32.dll
[MD5.62DF7A3B6AFCF9FCD41A86819BE47B61] - |A| - [16/05/2017 18:06:46] - (.-.) - [334.91 Ko] - (0.0.0.0) - C:\Windows\SysWOW64\atieah32.exe
[MD5.F48265A3C2A5A1166BA0817EF8124B26] - |A| - [16/05/2017 18:06:46] - (.Copyright (C) 2007 Advanced Micro Devices, Inc. - atigktxx.dll.) - [207.41 Ko] - (22.19.662.4) - C:\Windows\SysWOW64\atigktxx.dll
[MD5.87E8E840542E3875723E1DA4F3041E6A] - |A| - [16/05/2017 18:05:58] - (.Copyright (c) 2009 Advanced Micro Devices, Inc. - Radeon PCOM Universal Driver.) - [109.59 Ko] - (22.19.662.4) - C:\Windows\SysWOW64\atimpc32.dll
[MD5.3FBE6EA52D2CE01466CAAD0C05934FCC] - |A| - [16/05/2017 18:06:46] - (.Copyright (c) 2010 Advanced Micro Devices, Inc. - Radeon spu api dll.) - [138.91 Ko] - (22.19.662.4) - C:\Windows\SysWOW64\atisamu32.dll
[MD5.2AA981D39FC689E0B04624992DC9244A] - |A| - [25/04/2017 00:51:58] - (.-.) - [3390.02 Ko] - (0.0.0.0) - C:\Windows\SysWOW64\atiumdva.cap
[MD5.7C163EDE63854539828F5B2C1BC529FD] - |A| - [25/04/2017 00:55:26] - (.-.) - [153.46 Ko] - (0.0.0.0) - C:\Windows\SysWOW64\ativvsva.dat
[MD5.219D7091DD1D93728392337FE9C7ADD6] - |A| - [25/04/2017 00:55:26] - (.-.) - [200.15 Ko] - (0.0.0.0) - C:\Windows\SysWOW64\ativvsvl.dat
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [234 Ko] - C:\Windows\SysWOW64\bg-BG
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [0.93 Ko] - C:\Windows\SysWOW64\Bthprops
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [0 Ko] - C:\Windows\SysWOW64\catroot
[MD5.57741342CB514072D26EF56B9EF95C86] - |A| - [16/02/2017 16:15:22] - (.Copyright 1999 - 2007 - CDDBControl Core Module.) - [777.49 Ko] - (2.5.0.104) - C:\Windows\SysWOW64\CDDBControl.dll
[MD5.99A44759C589DF319376B29724DFBAEB] - |A| - [16/02/2017 16:15:22] - (.Copyright © 2003-2007 - CddbLangDE.) - [101.49 Ko] - (2.5.0.104) - C:\Windows\SysWOW64\CddbLangDE.dll
[MD5.889293D30D3F7A459EA4C00FAF006B1B] - |A| - [16/02/2017 16:15:22] - (.Copyright © 2003-2007 - CddbLangES.) - [101.49 Ko] - (2.5.0.104) - C:\Windows\SysWOW64\CddbLangES.dll
[MD5.C69B5427BCCA7BD1ABEE933B9CD41989] - |A| - [16/02/2017 16:15:22] - (.Copyright © 2003-2007 - CddbLangFR.) - [101.49 Ko] - (2.5.0.104) - C:\Windows\SysWOW64\CddbLangFR.dll
[MD5.1E4ADA579CF04AAE901F14970604078E] - |A| - [16/02/2017 16:15:22] - (.Copyright © 2003-2007 - CddbLangJA.) - [81.49 Ko] - (2.5.0.104) - C:\Windows\SysWOW64\CddbLangJA.dll
[MD5.CDF4D8D1717F22F9BD5DFA9E44842757] - |A| - [16/02/2017 16:15:22] - (.Copyright © 2003-2007 - CddbLangRU.) - [165.49 Ko] - (2.5.0.104) - C:\Windows\SysWOW64\CddbLangRU.dll
[MD5.F525176D64D23A4C4B27DD6BCCD96F4E] - |A| - [16/02/2017 16:15:22] - (.Copyright 2001 - 2007 - CDDBUIControl Module.) - [789.49 Ko] - (2.5.0.104) - C:\Windows\SysWOW64\CDDBUI.dll
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [314 Ko] - C:\Windows\SysWOW64\Com
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [6.82 Ko] - C:\Windows\SysWOW64\config
[MD5.00000000000000000000000000000000] - |SD| - [18/03/2017 23:03:29] - [50.29 Ko] - C:\Windows\SysWOW64\Configuration
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [279.5 Ko] - C:\Windows\SysWOW64\cs-CZ
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [275 Ko] - C:\Windows\SysWOW64\da-DK
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [311 Ko] - C:\Windows\SysWOW64\de-DE
[MD5.00000000000000000000000000000000] - |SD| - [18/03/2017 23:03:29] - [201.5 Ko] - C:\Windows\SysWOW64\DiagSvcs
[MD5.00000000000000000000000000000000] - |D| - [06/09/2017 17:06:58] - [0 Ko] - C:\Windows\SysWOW64\directx
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [5927.98 Ko] - C:\Windows\SysWOW64\Dism
[MD5.42620A8647D90509543FED00AB7A745F] - |A| - [27/04/2007 10:43:58] - (.-.) - [117.38 Ko] - (3.7.0.12) - C:\Windows\SysWOW64\DLLDEV32i.dll
[MD5.0902754B4F3041FD31673CB63B34012D] - |A| - [26/07/2018 22:29:37] - (.-.) - [0.23 Ko] - (0.0.0.0) - C:\Windows\SysWOW64\dllhost.exe.config
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [1077.55 Ko] - C:\Windows\SysWOW64\downlevel
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [3392.15 Ko] - C:\Windows\SysWOW64\drivers
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [0 Ko] - C:\Windows\SysWOW64\DriverStore
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [306.5 Ko] - C:\Windows\SysWOW64\el-GR
[MD5.00000000000000000000000000000000] - |D| - [20/03/2017 06:06:16] - [0 Ko] - C:\Windows\SysWOW64\en
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [223 Ko] - C:\Windows\SysWOW64\en-GB
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [2432 Ko] - C:\Windows\SysWOW64\en-US
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [300 Ko] - C:\Windows\SysWOW64\es-ES
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [244.5 Ko] - C:\Windows\SysWOW64\es-MX
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [220 Ko] - C:\Windows\SysWOW64\et-EE
[MD5.00000000000000000000000000000000] - |SD| - [18/03/2017 23:03:29] - [23999.16 Ko] - C:\Windows\SysWOW64\F12
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [279.5 Ko] - C:\Windows\SysWOW64\fi-FI
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [250.5 Ko] - C:\Windows\SysWOW64\fr-CA
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [307 Ko] - C:\Windows\SysWOW64\fr-FR
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [0 Ko] - C:\Windows\SysWOW64\FxsTmp
[MD5.EA4BE0F462A81BADC198F5361D0A3871] - |A| - [16/05/2017 18:06:48] - (.-.) - [365.41 Ko] - (0.0.0.0) - C:\Windows\SysWOW64\GameManager32.dll
[MD5.1E91815C329345AD54FE08BF7A98F749] - |A| - [24/09/2018 21:28:03] - (.Copyright (C) 2017 - Gracenote SDK component.) - [4073.5 Ko] - (3.10.5.5585) - C:\Windows\SysWOW64\gnsdk_fp.dll
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [0 Ko] - C:\Windows\SysWOW64\GroupPolicy
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [0 Ko] - C:\Windows\SysWOW64\GroupPolicyUsers
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [243 Ko] - C:\Windows\SysWOW64\he-IL
[MD5.2927ADFC93821B344BA524BCF9889A51] - |A| - [18/03/2017 22:58:54] - (.-.) - [109.5 Ko] - (0.0.0.0) - C:\Windows\SysWOW64\HeatCore.dll
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [229 Ko] - C:\Windows\SysWOW64\hr-HR
[MD5.EF6A36A4E971F8A29B01D8F6BC04847F] - |A| - [16/05/2017 18:06:48] - (.-.) - [244.91 Ko] - (0.0.0.0) - C:\Windows\SysWOW64\hsa-thunk.dll
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [283 Ko] - C:\Windows\SysWOW64\hu-HU
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [36.27 Ko] - C:\Windows\SysWOW64\icsxml
[MD5.24E1434E899B3EC4E3CD4CA56AA63BC6] - |A| - [18/03/2017 22:58:54] - (.-.) - [114.09 Ko] - (0.0.0.0) - C:\Windows\SysWOW64\InputHost.dll
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [221.5 Ko] - C:\Windows\SysWOW64\InputMethod
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [1160 Ko] - C:\Windows\SysWOW64\InstallShield
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [0 Ko] - C:\Windows\SysWOW64\Ipmi
[MD5.EDD400CC92C6D43F98D3D3AFC97C2559] - |A| - [25/12/2018 13:12:31] - (.-.) - [440.5 Ko] - (0.0.0.0) - C:\Windows\SysWOW64\ISSRemoveSP.exe
[MD5.00000000000000000000000000000000] - |D| - [20/03/2017 06:06:16] - [3115.5 Ko] - C:\Windows\SysWOW64\it
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [36176.73 Ko] - C:\Windows\SysWOW64\it-IT
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [222.5 Ko] - C:\Windows\SysWOW64\ja-JP
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [220.5 Ko] - C:\Windows\SysWOW64\ko-KR
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [79.18 Ko] - C:\Windows\SysWOW64\Licenses
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [0 Ko] - C:\Windows\SysWOW64\LogFiles
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [224.5 Ko] - C:\Windows\SysWOW64\lt-LT
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [226.5 Ko] - C:\Windows\SysWOW64\lv-LV
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [24628.69 Ko] - C:\Windows\SysWOW64\Macromed
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [32.68 Ko] - C:\Windows\SysWOW64\MailContactsCalendarSync
[MD5.930B23B52321D4C353C66CBEBC46DA02] - |A| - [16/05/2017 18:06:48] - (.Copyright (C) 2013 AMD Inc. - Mantle loader.) - [155.91 Ko] - (22.19.662.4) - C:\Windows\SysWOW64\mantle32.dll
[MD5.CE088898C25D7C039F08D39153053EB7] - |A| - [16/05/2017 18:06:48] - (.Copyright (C) 2013 AMD Inc. - Mantle extension library.) - [140.91 Ko] - (22.19.662.4) - C:\Windows\SysWOW64\mantleaxl32.dll
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [2979.88 Ko] - C:\Windows\SysWOW64\migration
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [814.41 Ko] - C:\Windows\SysWOW64\migwiz
[MD5.007FFA3BEBCFEECEB28F0CE144C16232] - |A| - [06/07/2017 21:04:36] - (.- Custom Math Kernel Library.) - [18640 Ko] - (1.0.2.0) - C:\Windows\SysWOW64\mkl_blueripple.dll
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [45.5 Ko] - C:\Windows\SysWOW64\MSDRM
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [52.28 Ko] - C:\Windows\SysWOW64\MsDtc
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [18.65 Ko] - C:\Windows\SysWOW64\MUI
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [271 Ko] - C:\Windows\SysWOW64\nb-NO
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [0 Ko] - C:\Windows\SysWOW64\NDF
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [51 Ko] - C:\Windows\SysWOW64\networklist
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [290 Ko] - C:\Windows\SysWOW64\nl-NL
[MD5.00000000000000000000000000000000] - |SD| - [18/03/2017 23:03:29] - [3781.5 Ko] - C:\Windows\SysWOW64\Nui
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [635.19 Ko] - C:\Windows\SysWOW64\oobe
[MD5.235355A8DD26903E75D5E812ECF50E53] - |A| - [06/07/2017 21:04:33] - (.Copyright (C) 2000-2006 - Standard OpenAL(TM) Implementation.) - [106.52 Ko] - (6.14.357.24) - C:\Windows\SysWOW64\OpenAL32.dll
[MD5.86316BE34481C1ED5B792169312673FD] - |A| - [01/03/2013 03:49:40] - (.Copyright © 2010-2013 Riverbed Technology, Inc. Copyright © 2005-2010 CACE Technologies. Copyright © 1999-2005 NetGroup, Politecnico di Torino. - packet.dll (Vista) Dynamic Link Library.) - [95.74 Ko] - (4.1.0.2980) - C:\Windows\SysWOW64\Packet.dll
[MD5.EE21928C80012525513D4D942248CA79] - |A| - [03/08/2009 01:21:54] - (.-.) - [193.27 Ko] - (0.0.0.0) - C:\Windows\SysWOW64\physxcudart_20.dll
[MD5.32C5FBD93A8BE38D8F7F49EA5FB427AD] - |A| - [03/08/2009 01:21:54] - (.Copyright (C) 2009 - NVIDIA PhysX Device Module.) - [22.77 Ko] - (9.7.30.0) - C:\Windows\SysWOW64\PhysXDevice.dll
[MD5.F04A90F917BA10AE2DCBE859870F4DEA] - |A| - [01/03/2013 03:47:36] - (.-.) - [52.05 Ko] - (0.0.0.0) - C:\Windows\SysWOW64\pthreadVC.dll
[MD5.4AEC114B79E076F2EAD73850312D6C1B] - |A| - [16/05/2017 18:06:48] - (.(c) Advanced Micro Devices, Inc. - AMD RapidFire.) - [475.41 Ko] - (1.1.0.22) - C:\Windows\SysWOW64\Rapidfire.dll
[MD5.672FEE9CC38B50D0C03313A9788AE30C] - |A| - [16/05/2017 18:06:48] - (.(c) Advanced Micro Devices, Inc. - AMD Rapid Fire Server.) - [49.91 Ko] - (1.1.0.19) - C:\Windows\SysWOW64\RapidFireServer.dll
[MD5.0B2D34CAEBF64E2EE7E9CD934758FF6D] - |A| - [06/07/2017 21:04:36] - (.Copyright © 2007-2011 Richard W.E. Furse - Rapture3D OpenAL Renderer.) - [1276 Ko] - (2.4.11.0) - C:\Windows\SysWOW64\rapture3d_oal.dll
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [23.75 Ko] - C:\Windows\SysWOW64\ras
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [0 Ko] - C:\Windows\SysWOW64\RasToast
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [0.82 Ko] - C:\Windows\SysWOW64\Recovery
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [0 Ko] - C:\Windows\SysWOW64\restore
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [230.5 Ko] - C:\Windows\SysWOW64\ro-RO
[MD5.03944ABAE856DC164BD167526E07E953] - |A| - [28/09/2012 21:45:08] - (.-.) - [241.5 Ko] - (0.0.0.0) - C:\Windows\SysWOW64\rtvcvfw32.dll
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [283.5 Ko] - C:\Windows\SysWOW64\ru-RU
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [231 Ko] - C:\Windows\SysWOW64\sk-SK
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [228.5 Ko] - C:\Windows\SysWOW64\sl-SI
[MD5.00000000000000000000000000000000] - |D| - [20/03/2017 06:06:16] - [52.62 Ko] - C:\Windows\SysWOW64\slmgr
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [0 Ko] - C:\Windows\SysWOW64\SMI
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [4127.91 Ko] - C:\Windows\SysWOW64\Speech
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [8208.92 Ko] - C:\Windows\SysWOW64\Speech_OneCore
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [1731.46 Ko] - C:\Windows\SysWOW64\spp
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [31.88 Ko] - C:\Windows\SysWOW64\sppui
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [231.5 Ko] - C:\Windows\SysWOW64\sr-Latn-RS
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [0 Ko] - C:\Windows\SysWOW64\sru
[MD5.A96D4F5EE92301ABCF9B614B6359D2AF] - |N| - [18/05/2018 16:08:27] - (.- Device Monitor.) - [92 Ko] - (1.6.2.0) - C:\Windows\SysWOW64\ssdevm.dll
[MD5.1291A61F0F4A49E5F4C869E677F67C57] - |A| - [18/03/2017 22:58:39] - (.-.) - [300 Ko] - (0.0.0.0) - C:\Windows\SysWOW64\ssdm.dll
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [276.5 Ko] - C:\Windows\SysWOW64\sv-SE
[MD5.00000000000000000000000000000000] - |D| - [20/03/2017 06:06:16] - [0 Ko] - C:\Windows\SysWOW64\sysprep
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [0 Ko] - C:\Windows\SysWOW64\Tasks
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [215 Ko] - C:\Windows\SysWOW64\th-TH
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [273.5 Ko] - C:\Windows\SysWOW64\tr-TR
[MD5.01E96A85B337B702AE2BC7F838AE7B65] - |A| - [18/03/2017 22:59:09] - (.-.) - [3.34 Ko] - (0.0.0.0) - C:\Windows\SysWOW64\UevCustomActionTypes.tlb
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [226.5 Ko] - C:\Windows\SysWOW64\uk-UA
[MD5.58F83E24DFC1ED7248F93F80F4ABD1F7] - |A| - [15/06/2017 21:32:56] - (.Copyright (C) 2015-2017 - Vulkan Loader.) - [512.78 Ko] - (1.0.51.0) - C:\Windows\SysWOW64\vulkan-1-1-0-51-0.dll
[MD5.58F83E24DFC1ED7248F93F80F4ABD1F7] - |A| - [04/09/2017 19:08:30] - (.Copyright (C) 2015-2017 - Vulkan Loader.) - [512.78 Ko] - (1.0.51.0) - C:\Windows\SysWOW64\vulkan-1.dll
[MD5.AEFDC0721352319F655F4B49A3CB7825] - |A| - [15/06/2017 21:32:50] - (.-.) - [228.28 Ko] - (0.0.0.0) - C:\Windows\SysWOW64\vulkaninfo-1-1-0-51-0.exe
[MD5.AEFDC0721352319F655F4B49A3CB7825] - |A| - [04/09/2017 19:08:30] - (.-.) - [228.28 Ko] - (0.0.0.0) - C:\Windows\SysWOW64\vulkaninfo.exe
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [16847 Ko] - C:\Windows\SysWOW64\wbem
[MD5.00000000000000000000000000000000] - |D| - [20/03/2017 06:06:16] - [0 Ko] - C:\Windows\SysWOW64\WCN
[MD5.D676BC75BD566BC91BFEC3D4EDA42655] - |A| - [18/03/2017 22:58:54] - (.-.) - [84.5 Ko] - (0.0.0.0) - C:\Windows\SysWOW64\WindowsDefaultHeatProcessor.dll
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [8602.64 Ko] - C:\Windows\SysWOW64\WindowsPowerShell
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [4753.59 Ko] - C:\Windows\SysWOW64\WinMetadata
[MD5.00000000000000000000000000000000] - |D| - [20/03/2017 06:06:16] - [106.24 Ko] - C:\Windows\SysWOW64\winrm
[MD5.4633B298D57014627831CCAC89A2C50B] - |A| - [01/03/2013 03:49:08] - (.Copyright © 2010-2013 Riverbed Technology, Inc. Copyright © 2005-2010 CACE Technologies. Copyright © 1999-2005 NetGroup, Politecnico di Torino. - wpcap.dll Dynamic Link Library - based on libpcap 1.0rel0b branch (20091008).) - [275.74 Ko] - (4.1.0.2980) - C:\Windows\SysWOW64\wpcap.dll
[MD5.D494267BC169604FAC5E3679B9A97FED] - |A| - [06/07/2017 21:04:33] - (.Copyright © 2008 - OpenAL32.) - [434.52 Ko] - (2.2.0.5) - C:\Windows\SysWOW64\wrap_oal.dll
[MD5.B6F89F4C37052969C0E5A8CF47C103D5] - |A| - [05/07/2017 18:43:27] - (.-.) - [58.5 Ko] - (0.0.0.0) - C:\Windows\SysWOW64\xboxgipsynthetic.dll
[MD5.00000000000000000000000000000000] - |D| - [06/07/2017 21:07:22] - [10.16 Ko] - C:\Windows\SysWOW64\XPSViewer
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [197.5 Ko] - C:\Windows\SysWOW64\zh-CN
[MD5.00000000000000000000000000000000] - |D| - [18/03/2017 23:03:29] - [192 Ko] - C:\Windows\SysWOW64\zh-TW

---------- | [Luca]

[26/07/2018 22:31:03] - |D| - [2420] - C:\Users\Luca\.android
[29/10/2018 15:49:59] - |RD| - [298] - C:\Users\Luca\3D Objects
[05/07/2017 18:28:21] - |HD| - [10369430238] - C:\Users\Luca\AppData
[05/07/2017 18:28:44] - |RD| - [412] - C:\Users\Luca\Contacts
[05/07/2017 18:28:21] - |SHD| - [0] - C:\Users\Luca\Cookies
[06/07/2017 15:08:34] - |RD| - [159] - C:\Users\Luca\Creative Cloud Files
[05/07/2017 18:28:21] - |SHD| - [0] - C:\Users\Luca\Dati applicazioni
[05/07/2017 18:28:21] - |RD| - [12699084776] - C:\Users\Luca\Desktop
[05/07/2017 18:28:21] - |SHD| - [0] - C:\Users\Luca\Documenti
[05/07/2017 18:28:20] - |RD| - [39017391454] - C:\Users\Luca\Documents
[05/07/2017 18:28:20] - |RD| - [172158566188] - C:\Users\Luca\Downloads
[05/07/2017 18:28:20] - |RD| - [618] - C:\Users\Luca\Favorites
[05/07/2017 18:28:21] - |SHD| - [0] - C:\Users\Luca\Impostazioni locali
[05/07/2017 18:28:20] - |RD| - [1935] - C:\Users\Luca\Links
[05/07/2017 18:28:21] - |SHD| - [0] - C:\Users\Luca\Menu Avvio
[05/07/2017 18:28:21] - |SHD| - [0] - C:\Users\Luca\Modelli
[05/07/2017 18:28:20] - |RD| - [755230980] - C:\Users\Luca\Music
[05/07/2017 18:28:20] - |AH| - [4980736] - C:\Users\Luca\NTUSER.DAT
[05/07/2017 18:28:21] - |ASH| - [163840] - C:\Users\Luca\ntuser.dat.LOG1
[05/07/2017 18:28:21] - |ASH| - [1712128] - C:\Users\Luca\ntuser.dat.LOG2
[14/07/2019 09:49:54] - |ASH| - [1048576] - C:\Users\Luca\NTUSER.DAT{4e074667-0c1c-11e7-a943-e41d2d718a20}.TxR.0.regtrans-ms
[14/07/2019 09:49:54] - |ASH| - [1048576] - C:\Users\Luca\NTUSER.DAT{4e074667-0c1c-11e7-a943-e41d2d718a20}.TxR.1.regtrans-ms
[14/07/2019 09:49:54] - |ASH| - [1048576] - C:\Users\Luca\NTUSER.DAT{4e074667-0c1c-11e7-a943-e41d2d718a20}.TxR.2.regtrans-ms
[14/07/2019 09:49:54] - |ASH| - [65536] - C:\Users\Luca\NTUSER.DAT{4e074667-0c1c-11e7-a943-e41d2d718a20}.TxR.blf
[05/07/2017 18:28:21] - |ASH| - [65536] - C:\Users\Luca\NTUSER.DAT{4e074668-0c1c-11e7-a943-e41d2d718a20}.TM.blf
[05/07/2017 18:28:21] - |ASH| - [524288] - C:\Users\Luca\NTUSER.DAT{4e074668-0c1c-11e7-a943-e41d2d718a20}.TMContainer00000000000000000001.regtrans-ms
[05/07/2017 18:28:21] - |ASH| - [524288] - C:\Users\Luca\NTUSER.DAT{4e074668-0c1c-11e7-a943-e41d2d718a20}.TMContainer00000000000000000002.regtrans-ms
[05/07/2017 18:28:21] - |SH| - [20] - C:\Users\Luca\ntuser.ini
[05/07/2017 18:31:06] - |RD| - [95] - C:\Users\Luca\OneDrive
[05/07/2017 18:28:20] - |RD| - [591277745] - C:\Users\Luca\Pictures
[05/07/2017 18:28:21] - |SHD| - [0] - C:\Users\Luca\Recenti
[05/07/2017 18:28:21] - |SHD| - [0] - C:\Users\Luca\Risorse di rete
[05/07/2017 18:28:21] - |SHD| - [0] - C:\Users\Luca\Risorse di stampa
[05/07/2017 18:28:20] - |RD| - [282] - C:\Users\Luca\Saved Games
[05/07/2017 18:28:44] - |RD| - [1879] - C:\Users\Luca\Searches
[05/07/2017 18:28:21] - |SHD| - [0] - C:\Users\Luca\SendTo
[05/07/2017 18:28:20] - |RD| - [8710513363] - C:\Users\Luca\Videos
[05/07/2017 18:28:21] - |D| - [10050147481] - C:\Users\Luca\AppData\Local
[05/07/2017 18:28:21] - |D| - [5729169] - C:\Users\Luca\AppData\LocalLow
[05/07/2017 18:28:21] - |D| - [313553588] - C:\Users\Luca\AppData\Roaming
[06/07/2017 00:42:51] - |D| - [19927180] - C:\Users\Luca\AppData\Local\Adobe
[05/07/2017 18:48:24] - |D| - [121941269] - C:\Users\Luca\AppData\Local\AMD
[04/09/2017 19:00:48] - |D| - [0] - C:\Users\Luca\AppData\Local\ATI
[05/07/2017 20:02:07] - |D| - [230774075] - C:\Users\Luca\AppData\Local\Battle.net
[05/07/2017 22:17:11] - |D| - [1212937] - C:\Users\Luca\AppData\Local\Blizzard
[05/07/2017 20:08:15] - |D| - [342] - C:\Users\Luca\AppData\Local\Blizzard Entertainment
[05/07/2017 20:08:09] - |D| - [4063662] - C:\Users\Luca\AppData\Local\CEF
[16/03/2019 12:21:42] - |D| - [0] - C:\Users\Luca\AppData\Local\Chromium
[05/07/2017 18:46:02] - |D| - [23672943] - C:\Users\Luca\AppData\Local\Comms
[05/07/2017 18:28:41] - |D| - [1084272] - C:\Users\Luca\AppData\Local\ConnectedDevicesPlatform
[05/07/2017 18:28:21] - |SHD| - [0] - C:\Users\Luca\AppData\Local\Cronologia
[05/07/2017 18:28:21] - |SHD| - [0] - C:\Users\Luca\AppData\Local\Dati applicazioni
[18/07/2018 23:46:40] - |D| - [11289] - C:\Users\Luca\AppData\Local\DBFighterZ
[05/07/2017 20:08:13] - |D| - [0] - C:\Users\Luca\AppData\Local\DBG
[01/11/2018 22:33:26] - |D| - [124215] - C:\Users\Luca\AppData\Local\DELTARUNE
[15/11/2017 15:19:39] - |D| - [0] - C:\Users\Luca\AppData\Local\Diagnostics
[05/01/2019 18:06:39] - |D| - [15087202] - C:\Users\Luca\AppData\Local\Downloaded Installations
[28/09/2018 13:34:50] - |D| - [975732949] - C:\Users\Luca\AppData\Local\duDat
[04/08/2017 20:57:02] - |D| - [0] - C:\Users\Luca\AppData\Local\ElevatedDiagnostics
[28/02/2018 00:16:38] - |D| - [886555] - C:\Users\Luca\AppData\Local\EpicGamesLauncher
[04/08/2017 12:13:50] - |D| - [0] - C:\Users\Luca\AppData\Local\FalloutNV
[26/09/2017 16:41:58] - |D| - [1834388] - C:\Users\Luca\AppData\Local\fontconfig
[28/02/2018 11:20:04] - |D| - [3027401] - C:\Users\Luca\AppData\Local\FortniteGame
[05/07/2017 19:14:53] - |D| - [1163949302] - C:\Users\Luca\AppData\Local\Google
[12/08/2017 19:15:10] - |D| - [19516] - C:\Users\Luca\AppData\Local\HearthSim
[12/08/2017 17:08:27] - |D| - [200515824] - C:\Users\Luca\AppData\Local\HearthstoneDeckTracker
[05/07/2017 18:52:05] - |AH| - [56016] - C:\Users\Luca\AppData\Local\IconCache.db
[10/09/2017 21:28:36] - |D| - [5190733] - C:\Users\Luca\AppData\Local\LG Electronics
[17/09/2018 19:23:59] - |D| - [0] - C:\Users\Luca\AppData\Local\MAGIX
[24/09/2018 19:49:38] - |D| - [776360] - C:\Users\Luca\AppData\Local\mbam
[11/07/2019 20:11:15] - |D| - [235676] - C:\Users\Luca\AppData\Local\mbamtray
[05/07/2017 18:28:21] - |D| - [1935087615] - C:\Users\Luca\AppData\Local\Microsoft
[05/07/2017 23:23:32] - |D| - [126472] - C:\Users\Luca\AppData\Local\Microsoft Help
[05/07/2017 18:55:48] - |D| - [76341] - C:\Users\Luca\AppData\Local\MicrosoftEdge
[28/02/2018 11:20:37] - |D| - [6521] - C:\Users\Luca\AppData\Local\NVIDIA Corporation
[27/09/2018 20:28:51] - |A| - [0] - C:\Users\Luca\AppData\Local\oobelibMkey.log
[11/08/2017 16:36:48] - |D| - [258822] - C:\Users\Luca\AppData\Local\Overwolf
[05/07/2017 18:28:43] - |D| - [596221095] - C:\Users\Luca\AppData\Local\Packages
[23/02/2019 18:02:21] - |D| - [128] - C:\Users\Luca\AppData\Local\paint.net
[06/07/2017 14:45:07] - |D| - [0] - C:\Users\Luca\AppData\Local\PeerDistRepub
[05/07/2017 20:03:24] - |D| - [0] - C:\Users\Luca\AppData\Local\Programs
[05/07/2017 18:28:51] - |D| - [841473] - C:\Users\Luca\AppData\Local\Publishers
[10/07/2017 21:02:30] - |D| - [5292863] - C:\Users\Luca\AppData\Local\qBittorrent
[26/09/2017 16:47:48] - |A| - [741] - C:\Users\Luca\AppData\Local\recently-used.xbel
[10/07/2017 13:20:18] - |D| - [9000] - C:\Users\Luca\AppData\Local\Recovery
[05/02/2018 21:23:54] - |D| - [1653708] - C:\Users\Luca\AppData\Local\SEI
[18/10/2018 20:47:38] - |D| - [261973] - C:\Users\Luca\AppData\Local\SmartView2
[17/09/2018 19:24:06] - |D| - [1862] - C:\Users\Luca\AppData\Local\Sony
[12/08/2017 17:08:25] - |D| - [3580] - C:\Users\Luca\AppData\Local\SquirrelTemp
[06/07/2017 00:23:20] - |D| - [383255736] - C:\Users\Luca\AppData\Local\Steam
[05/07/2017 18:28:21] - |AD| - [4337394781] - C:\Users\Luca\AppData\Local\Temp
[05/07/2017 18:28:21] - |SHD| - [0] - C:\Users\Luca\AppData\Local\Temporary Internet Files
[08/09/2017 12:13:24] - |D| - [0] - C:\Users\Luca\AppData\Local\The Witcher 2
[05/07/2017 18:28:41] - |D| - [16211968] - C:\Users\Luca\AppData\Local\TileDataLayer
[30/09/2017 18:13:34] - |D| - [4559] - C:\Users\Luca\AppData\Local\Ubisoft Game Launcher
[28/02/2018 00:16:38] - |D| - [81] - C:\Users\Luca\AppData\Local\UnrealEngine
[28/02/2018 00:16:39] - |D| - [0] - C:\Users\Luca\AppData\Local\UnrealEngineLauncher
[17/09/2018 19:22:48] - |D| - [0] - C:\Users\Luca\AppData\Local\VEGAS
[17/09/2018 19:23:53] - |D| - [3273234] - C:\Users\Luca\AppData\Local\VEGAS Pro
[05/07/2017 18:28:43] - |D| - [8054] - C:\Users\Luca\AppData\Local\VirtualStore
[23/09/2017 15:32:36] - |D| - [32768] - C:\Users\Luca\AppData\Local\Windows Live
[18/02/2019 16:49:32] - |A| - [0] - C:\Users\Luca\AppData\Local\{BE20DF31-2125-4A41-B233-2A5FB28E2CDA}
[02/08/2018 23:21:46] - |D| - [1110139] - C:\Users\Luca\AppData\LocalLow\Adobe
[04/09/2017 19:09:14] - |D| - [0] - C:\Users\Luca\AppData\LocalLow\AMD
[05/07/2017 22:17:15] - |D| - [2939] - C:\Users\Luca\AppData\LocalLow\Blizzard Entertainment
[17/09/2018 19:58:05] - |D| - [598081] - C:\Users\Luca\AppData\LocalLow\Dodge Roll
[05/07/2017 18:29:04] - |SD| - [170940] - C:\Users\Luca\AppData\LocalLow\Microsoft
[27/08/2017 16:49:40] - |D| - [2949] - C:\Users\Luca\AppData\LocalLow\Sam Barlow
[26/02/2018 23:56:58] - |D| - [3844121] - C:\Users\Luca\AppData\LocalLow\Team Cherry
[02/08/2018 23:05:08] - |D| - [0] - C:\Users\Luca\AppData\LocalLow\Temp
[05/07/2017 22:17:13] - |D| - [0] - C:\Users\Luca\AppData\Roaming\.mono
[05/07/2017 18:28:43] - |D| - [12229664] - C:\Users\Luca\AppData\Roaming\Adobe
[23/09/2017 15:44:54] - |D| - [40114] - C:\Users\Luca\AppData\Roaming\AMD
[04/09/2017 19:00:48] - |D| - [0] - C:\Users\Luca\AppData\Roaming\ATI
[05/07/2017 20:01:59] - |D| - [5126] - C:\Users\Luca\AppData\Roaming\Battle.net
[13/12/2017 20:01:36] - |D| - [8253578] - C:\Users\Luca\AppData\Roaming\DarkSoulsII
[29/09/2017 15:10:00] - |D| - [16782325] - C:\Users\Luca\AppData\Roaming\Dev-Cpp
[09/09/2018 12:49:22] - |A| - [231] - C:\Users\Luca\AppData\Roaming\glide_wrapper.zbag.ini
[17/04/2019 20:47:34] - |D| - [0] - C:\Users\Luca\AppData\Roaming\Google
[12/08/2017 17:08:29] - |D| - [88663545] - C:\Users\Luca\AppData\Roaming\HearthstoneDeckTracker
[26/09/2017 16:41:24] - |D| - [25490] - C:\Users\Luca\AppData\Roaming\inkscape
[04/09/2017 17:43:45] - |D| - [0] - C:\Users\Luca\AppData\Roaming\InstallShield
[10/09/2017 21:30:27] - |D| - [2686] - C:\Users\Luca\AppData\Roaming\LG Electronics
[26/09/2017 16:33:15] - |D| - [2503] - C:\Users\Luca\AppData\Roaming\Macromedia
[17/09/2018 19:23:53] - |D| - [0] - C:\Users\Luca\AppData\Roaming\MAGIX
[05/07/2017 18:28:21] - |SD| - [100015999] - C:\Users\Luca\AppData\Roaming\Microsoft
[05/07/2017 20:10:34] - |D| - [193] - C:\Users\Luca\AppData\Roaming\MPC-HC
[23/09/2017 15:42:58] - |D| - [8304255] - C:\Users\Luca\AppData\Roaming\obs-studio
[10/07/2017 21:02:38] - |D| - [6100] - C:\Users\Luca\AppData\Roaming\qBittorrent
[07/04/2018 19:44:39] - |D| - [734] - C:\Users\Luca\AppData\Roaming\Rogue Legacy
[20/10/2017 17:02:49] - |D| - [2532] - C:\Users\Luca\AppData\Roaming\Samsung
[06/07/2017 09:44:45] - |D| - [76] - C:\Users\Luca\AppData\Roaming\Skype
[17/09/2018 19:22:10] - |D| - [203980] - C:\Users\Luca\AppData\Roaming\Sony
[16/03/2019 12:00:33] - |D| - [77908795] - C:\Users\Luca\AppData\Roaming\The Creative Assembly
[17/09/2018 19:24:05] - |D| - [40] - C:\Users\Luca\AppData\Roaming\VEGAS
[17/09/2018 19:23:53] - |D| - [0] - C:\Users\Luca\AppData\Roaming\VEGAS Pro
[14/07/2017 20:25:29] - |D| - [12] - C:\Users\Luca\AppData\Roaming\WinRAR
[26/07/2018 22:30:00] - |D| - [1105610] - C:\Users\Luca\AppData\Roaming\Wondershare
[05/07/2017 18:28:44] - |SH| - [174] - C:\Users\Luca\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini
[05/07/2017 18:28:21] - |SHD| - [0] - C:\Users\Luca\AppData\Roaming\Microsoft\Windows\Start Menu\Programmi
[05/07/2017 18:28:21] - |RD| - [47184] - C:\Users\Luca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs
[05/07/2017 18:28:21] - |RD| - [3888] - C:\Users\Luca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
[05/07/2017 18:28:21] - |RD| - [2929] - C:\Users\Luca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[05/07/2017 18:28:44] - |RD| - [174] - C:\Users\Luca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[05/07/2017 18:28:44] - |SH| - [174] - C:\Users\Luca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\desktop.ini
[05/01/2018 22:25:23] - |D| - [1152] - C:\Users\Luca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Geekbench 4
[12/08/2017 17:08:33] - |D| - [2582] - C:\Users\Luca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HearthSim
[05/07/2017 18:28:21] - |D| - [170] - C:\Users\Luca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[06/09/2017 17:05:17] - |D| - [7671] - C:\Users\Luca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MSI Afterburner
[05/07/2017 18:31:06] - |A| - [2422] - C:\Users\Luca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
[06/09/2017 17:06:35] - |D| - [8121] - C:\Users\Luca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RivaTuner Statistics Server
[05/07/2017 18:28:44] - |RD| - [174] - C:\Users\Luca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[05/07/2017 18:28:21] - |RD| - [3496] - C:\Users\Luca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
[30/09/2017 18:31:45] - |D| - [2664] - C:\Users\Luca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft
[05/07/2017 18:28:21] - |RD| - [7238] - C:\Users\Luca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell
[14/07/2017 19:35:28] - |D| - [4329] - C:\Users\Luca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
[05/07/2017 18:28:44] - |SH| - [174] - C:\Users\Luca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini

---------- | [Public]

[05/07/2017 18:28:44] - |RHD| - [196] - C:\Users\Public\AccountPictures
[28/02/2018 11:24:10] - |AHD| - [0] - C:\Users\Public\AppData
[18/03/2017 23:03:29] - |RHD| - [24272] - C:\Users\Public\Desktop
[18/03/2017 23:03:33] - |ASH| - [174] - C:\Users\Public\desktop.ini
[18/03/2017 23:03:29] - |RD| - [1413] - C:\Users\Public\Documents
[18/03/2017 23:03:29] - |RD| - [174] - C:\Users\Public\Downloads
[18/03/2017 23:03:29] - |RHD| - [1174] - C:\Users\Public\Libraries
[28/02/2018 11:24:10] - |SH| - [235] - C:\Users\Public\Libraries.ini
[18/03/2017 23:03:29] - |RD| - [380] - C:\Users\Public\Music
[18/03/2017 23:03:29] - |RD| - [380] - C:\Users\Public\Pictures
[18/03/2017 23:03:29] - |RD| - [380] - C:\Users\Public\Videos

---------- | C:\ProgramData

[05/07/2017 22:17:13] - |D| - [0] - C:\ProgramData\.mono
[06/07/2017 00:53:25] - |D| - [287666312] - C:\ProgramData\Adobe
[04/09/2017 19:00:48] - |D| - [0] - C:\ProgramData\ATI
[05/07/2017 20:01:34] - |D| - [16627646] - C:\ProgramData\Battle.net
[05/07/2017 20:08:24] - |D| - [500437] - C:\ProgramData\Blizzard Entertainment
[06/07/2017 21:04:58] - |D| - [0] - C:\ProgramData\Codemasters
[05/07/2017 18:25:40] - |SHD| - [0] - C:\ProgramData\Dati applicazioni
[05/07/2017 18:25:40] - |SHD| - [0] - C:\ProgramData\Desktop
[05/07/2017 18:25:40] - |SHD| - [0] - C:\ProgramData\Documenti
[28/02/2018 00:16:30] - |D| - [10187651] - C:\ProgramData\Epic
[17/09/2018 19:23:11] - |D| - [505] - C:\ProgramData\Magix
[14/07/2017 19:42:22] - |D| - [75589191] - C:\ProgramData\Malwarebytes
[05/07/2017 18:25:40] - |SHD| - [0] - C:\ProgramData\Menu Avvio
[18/03/2017 23:03:29] - |SD| - [1362190631] - C:\ProgramData\Microsoft
[05/07/2017 23:23:31] - |D| - [26168] - C:\ProgramData\Microsoft Help
[05/07/2017 18:30:12] - |D| - [0] - C:\ProgramData\Microsoft OneDrive
[06/07/2017 14:43:48] - |D| - [2684] - C:\ProgramData\Microsoft Toolkit
[05/07/2017 18:25:40] - |SHD| - [0] - C:\ProgramData\Modelli
[05/07/2017 18:48:42] - |D| - [56739813] - C:\ProgramData\Package Cache
[27/07/2018 22:30:09] - |D| - [0] - C:\ProgramData\Packages
[18/03/2017 23:03:29] - |AD| - [2058] - C:\ProgramData\regid.1991-06.com.microsoft
[20/10/2017 17:01:25] - |D| - [335] - C:\ProgramData\Samsung
[06/07/2017 15:21:22] - |D| - [458066237] - C:\ProgramData\SeriousBit
[18/03/2017 23:03:29] - |D| - [0] - C:\ProgramData\SoftwareDistribution
[18/03/2017 23:03:29] - |D| - [50197] - C:\ProgramData\USOPrivate
[05/07/2017 18:31:40] - |D| - [3788800] - C:\ProgramData\USOShared
[17/09/2018 19:22:48] - |D| - [3194491] - C:\ProgramData\VEGAS
[17/09/2018 19:24:13] - |D| - [0] - C:\ProgramData\VEGAS Pro
[20/03/2017 06:07:27] - |D| - [0] - C:\ProgramData\WindowsHolographicDevices
[26/07/2018 22:29:08] - |D| - [25337892] - C:\ProgramData\Wondershare
[26/07/2018 22:35:47] - |D| - [0] - C:\ProgramData\wsr

---------- | C:\ProgramData\Microsoft\Windows\Start Menu

[18/03/2017 23:03:33] - |ASH| - [174] - C:\ProgramData\Microsoft\Windows\Start Menu\desktop.ini
[05/07/2017 18:25:40] - |SHD| - [0] - C:\ProgramData\Microsoft\Windows\Start Menu\Programmi
[18/03/2017 23:03:29] - |RD| - [163707] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs

---------- | C:\ProgramData\Microsoft\Windows\Start Menu\Programs

[04/08/2017 21:24:55] - |A| - [2656] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access 2016.lnk
[18/03/2017 23:03:29] - |RD| - [1614] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility
[18/03/2017 23:03:29] - |RD| - [14299] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
[02/08/2018 23:21:22] - |A| - [2457] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
[18/03/2017 23:03:29] - |RD| - [23012] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[06/07/2017 00:54:55] - |A| - [1302] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Creative Cloud.lnk
[04/09/2017 18:54:10] - |D| - [2003] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Settings
[05/07/2017 20:07:50] - |D| - [397] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Applicazione Blizzard
[24/09/2017 13:31:47] - |D| - [3253] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bloodshed Dev-C++
[06/07/2017 21:04:37] - |D| - [2095] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Blue Ripple Sound
[28/09/2018 13:34:38] - |D| - [2196] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BooktabZ
[18/03/2017 23:03:33] - |SH| - [1278] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\desktop.ini
[28/02/2018 00:16:32] - |A| - [893] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Epic Games Launcher.lnk
[04/08/2017 21:24:55] - |A| - [2648] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel 2016.lnk
[30/04/2018 19:47:31] - |A| - [2299] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
[05/07/2017 21:00:26] - |D| - [409] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hearthstone
[18/03/2017 22:59:54] - |RAS| - [2349] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Immersive Control Panel.lnk
[26/09/2017 16:40:49] - |A| - [873] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Inkscape.lnk
[10/09/2017 21:28:37] - |D| - [2602] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LG PC Suite
[18/03/2017 23:03:29] - |D| - [170] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance
[11/07/2019 20:11:00] - |D| - [3896] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
[04/08/2017 21:24:55] - |RD| - [19427] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2016 Tools
[18/03/2017 22:57:42] - |RAS| - [2219] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MiracastView.lnk
[23/09/2017 15:34:22] - |A| - [1378] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Movie Maker.lnk
[05/07/2017 20:03:33] - |D| - [3603] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MPC-HC x64
[06/07/2017 15:21:14] - |D| - [2904] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NetBalancer
[27/02/2018 23:39:37] - |D| - [1853] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
[23/09/2017 15:38:24] - |D| - [3731] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OBS Studio
[05/07/2017 23:25:16] - |A| - [2662] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneDrive for Business.lnk
[04/08/2017 21:24:55] - |A| - [2648] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote 2016.lnk
[04/08/2017 21:24:55] - |A| - [2729] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook 2016.lnk
[23/02/2019 18:03:03] - |A| - [1114] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\paint.net.lnk
[23/09/2017 15:34:20] - |A| - [1447] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Photo Gallery.lnk
[04/08/2017 21:24:55] - |A| - [2642] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint 2016.lnk
[18/03/2017 22:58:04] - |RAS| - [2199] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PrintDialog.lnk
[04/08/2017 21:24:55] - |A| - [2628] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Publisher 2016.lnk
[29/04/2019 10:05:44] - |D| - [1787] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\qBittorrent
[25/12/2018 13:12:44] - |D| - [4883] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\REALTEK Wireless LAN Utility
[18/05/2018 16:08:41] - |RD| - [4810] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung Printers
[04/08/2017 21:24:55] - |A| - [2656] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype for Business 2016.lnk
[18/03/2017 23:03:29] - |RD| - [479] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
[06/07/2017 00:16:31] - |D| - [607] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
[18/03/2017 23:03:29] - |RD| - [1458] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools
[05/08/2017 16:25:28] - |D| - [2639] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Titan Souls [GOG.com]
[05/01/2019 18:08:08] - |D| - [4762] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TP-Link
[17/09/2018 19:23:04] - |D| - [3711] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VEGAS
[05/01/2019 18:07:00] - |D| - [847] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinPcap
[14/07/2017 19:35:28] - |D| - [4257] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
[26/07/2018 22:30:07] - |D| - [0] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wondershare
[04/08/2017 21:24:55] - |A| - [2656] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word 2016.lnk
[04/02/2019 23:11:45] - |D| - [2270] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XAMPP

---------- | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup

[18/03/2017 23:03:33] - |ASH| - [174] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
[25/11/2017 18:00:57] - |A| - [305] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\fcbd.bat

---------- | C:\Program Files (x86)

[06/07/2017 00:53:06] - |D| - [674287651] - C:\Program Files (x86)\Adobe
[27/02/2018 23:39:36] - |AD| - [123382454] - C:\Program Files (x86)\AGEIA Technologies
[04/09/2017 18:54:06] - |AD| - [56223681] - C:\Program Files (x86)\AMD
[07/03/2019 14:17:07] - |D| - [177] - C:\Program Files (x86)\Battle.net
[28/09/2018 13:34:17] - |AD| - [304764149] - C:\Program Files (x86)\BooktabZ
[06/07/2017 21:04:35] - |AD| - [16423642] - C:\Program Files (x86)\BRS
[18/03/2017 23:03:28] - |D| - [905715680] - C:\Program Files (x86)\Common Files
[18/03/2017 23:03:33] - |ASH| - [174] - C:\Program Files (x86)\desktop.ini
[24/09/2017 13:31:39] - |D| - [171576394] - C:\Program Files (x86)\Dev-Cpp
[05/01/2018 22:25:22] - |D| - [119450199] - C:\Program Files (x86)\Geekbench 4
[05/07/2017 19:15:08] - |D| - [480722176] - C:\Program Files (x86)\Google
[05/08/2017 19:42:33] - |HD| - [35033302] - C:\Program Files (x86)\InstallShield Installation Information
[18/03/2017 23:03:28] - |D| - [2007147] - C:\Program Files (x86)\Internet Explorer
[14/07/2017 16:43:35] - |D| - [367909805] - C:\Program Files (x86)\LG Electronics
[05/07/2017 23:23:42] - |D| - [94520305] - C:\Program Files (x86)\Microsoft Analysis Services
[04/08/2017 21:22:26] - |D| - [108060041] - C:\Program Files (x86)\Microsoft Office
[05/07/2017 23:24:38] - |D| - [21696] - C:\Program Files (x86)\Microsoft SQL Server
[23/09/2017 15:34:17] - |AD| - [1829877] - C:\Program Files (x86)\Microsoft SQL Server Compact Edition
[06/07/2017 15:46:30] - |D| - [6076507] - C:\Program Files (x86)\Microsoft XNA
[18/03/2017 23:03:28] - |AD| - [8929119] - C:\Program Files (x86)\Microsoft.NET
[27/07/2018 00:31:05] - |D| - [14107653] - C:\Program Files (x86)\Mobile
[04/09/2017 17:43:46] - |AD| - [5115246] - C:\Program Files (x86)\MonitorDriver
[31/05/2018 17:52:59] - |D| - [48528] - C:\Program Files (x86)\Mozilla Firefox
[06/07/2017 21:07:17] - |D| - [25757] - C:\Program Files (x86)\MSBuild
[06/09/2017 17:04:57] - |D| - [50558945] - C:\Program Files (x86)\MSI Afterburner
[23/09/2017 15:38:10] - |D| - [417788172] - C:\Program Files (x86)\obs-studio
[06/07/2017 21:04:33] - |D| - [809496] - C:\Program Files (x86)\OpenAL
[25/12/2018 13:12:31] - |D| - [6671486] - C:\Program Files (x86)\REALTEK
[06/07/2017 21:07:17] - |D| - [38421249] - C:\Program Files (x86)\Reference Assemblies
[06/09/2017 17:06:26] - |D| - [60573504] - C:\Program Files (x86)\RivaTuner Statistics Server
[18/05/2018 16:08:27] - |D| - [110481967] - C:\Program Files (x86)\Samsung
[18/05/2018 16:08:37] - |D| - [2144768] - C:\Program Files (x86)\SamsungPrinterLiveUpdate
[18/05/2018 16:08:37] - |D| - [3424277] - C:\Program Files (x86)\SamsungPrinterLiveUpdateInstaller
[18/10/2018 20:47:31] - |AD| - [13156942] - C:\Program Files (x86)\Smart View
[01/11/2018 22:04:27] - |D| - [82765775] - C:\Program Files (x86)\SURVEY_PROGRAM
[27/07/2018 00:30:32] - |D| - [14491435] - C:\Program Files (x86)\Switcher
[05/01/2019 18:08:07] - |D| - [24204592] - C:\Program Files (x86)\TP-Link
[30/09/2017 18:13:33] - |D| - [262014954] - C:\Program Files (x86)\Ubisoft
[17/09/2018 19:22:48] - |D| - [53485239] - C:\Program Files (x86)\VEGAS
[05/08/2017 19:41:58] - |D| - [7261821] - C:\Program Files (x86)\VIA
[04/09/2017 19:08:30] - |D| - [1099146] - C:\Program Files (x86)\VulkanRT
[18/03/2017 23:03:28] - |D| - [1993176] - C:\Program Files (x86)\Windows Defender
[23/09/2017 15:34:01] - |AD| - [85163787] - C:\Program Files (x86)\Windows Live
[18/03/2017 23:03:28] - |D| - [5924864] - C:\Program Files (x86)\Windows Mail
[20/03/2017 06:06:38] - |D| - [3253913] - C:\Program Files (x86)\Windows Media Player
[18/03/2017 23:03:28] - |D| - [42960] - C:\Program Files (x86)\Windows Multimedia Platform
[18/03/2017 23:03:28] - |D| - [7568578] - C:\Program Files (x86)\Windows NT
[18/03/2017 23:03:28] - |D| - [5364544] - C:\Program Files (x86)\Windows Photo Viewer
[18/03/2017 23:03:28] - |D| - [42960] - C:\Program Files (x86)\Windows Portable Devices
[18/03/2017 23:03:28] - |SHD| - [0] - C:\Program Files (x86)\Windows Sidebar
[18/03/2017 23:03:28] - |D| - [2179960] - C:\Program Files (x86)\WindowsPowerShell
[05/01/2019 18:06:59] - |D| - [240048] - C:\Program Files (x86)\WinPcap
[26/07/2018 22:29:09] - |D| - [8257630] - C:\Program Files (x86)\Wondershare

---------- | C:\Program Files

[05/07/2017 18:48:16] - |AD| - [360621644] - C:\Program Files\AMD
[18/03/2017 23:03:28] - |D| - [494376927] - C:\Program Files\Common Files
[18/03/2017 23:03:33] - |ASH| - [174] - C:\Program Files\desktop.ini
[05/07/2017 18:25:40] - |SHD| - [0] - C:\Program Files\File comuni
[26/09/2017 16:40:33] - |AD| - [239708193] - C:\Program Files\Inkscape
[18/03/2017 23:03:28] - |D| - [2633814] - C:\Program Files\Internet Explorer
[14/07/2017 19:42:22] - |D| - [173132632] - C:\Program Files\Malwarebytes
[05/07/2017 23:23:42] - |D| - [109612529] - C:\Program Files\Microsoft Analysis Services
[04/08/2017 21:22:24] - |AD| - [1911790438] - C:\Program Files\Microsoft Office
[05/07/2017 23:24:37] - |D| - [26304] - C:\Program Files\Microsoft SQL Server
[05/07/2017 23:24:56] - |D| - [719000] - C:\Program Files\Microsoft.NET
[05/07/2017 20:03:31] - |AD| - [49420041] - C:\Program Files\MPC-HC
[06/07/2017 21:07:17] - |D| - [25757] - C:\Program Files\MSBuild
[06/07/2017 15:21:12] - |AD| - [20708630] - C:\Program Files\NetBalancer
[23/02/2019 18:02:55] - |AD| - [68510491] - C:\Program Files\paint.net
[29/04/2019 10:05:44] - |D| - [119046316] - C:\Program Files\qBittorrent
[06/07/2017 21:07:17] - |D| - [36767401] - C:\Program Files\Reference Assemblies
[24/02/2018 20:00:34] - |AD| - [42496473] - C:\Program Files\rempl
[05/07/2017 18:23:05] - |HD| - [0] - C:\Program Files\Uninstall Information
[17/09/2018 19:22:48] - |D| - [1195368109] - C:\Program Files\VEGAS
[05/07/2017 18:49:13] - |D| - [2924000] - C:\Program Files\VIA
[18/03/2017 23:03:28] - |RD| - [16313762] - C:\Program Files\Windows Defender
[20/03/2017 06:07:27] - |D| - [7565872] - C:\Program Files\Windows Defender Advanced Threat Protection
[18/03/2017 23:03:28] - |D| - [6145536] - C:\Program Files\Windows Mail
[20/03/2017 06:06:38] - |D| - [4779709] - C:\Program Files\Windows Media Player
[18/03/2017 23:03:28] - |D| - [49688] - C:\Program Files\Windows Multimedia Platform
[18/03/2017 23:03:28] - |D| - [7834818] - C:\Program Files\Windows NT
[18/03/2017 23:03:28] - |D| - [6167872] - C:\Program Files\Windows Photo Viewer
[18/03/2017 23:03:28] - |D| - [49696] - C:\Program Files\Windows Portable Devices
[18/03/2017 23:03:28] - |D| - [95413] - C:\Program Files\Windows Security
[18/03/2017 23:03:28] - |SHD| - [0] - C:\Program Files\Windows Sidebar
[18/03/2017 23:03:28] - |HD| - [2419380429] - C:\Program Files\WindowsApps
[18/03/2017 23:03:28] - |D| - [2428706] - C:\Program Files\WindowsPowerShell
[14/07/2017 19:35:23] - |AD| - [6013680] - C:\Program Files\WinRAR

---------- | C:\Program Files (x86)\Common Files

[06/07/2017 00:53:05] - |AD| - [555790316] - C:\Program Files (x86)\Common Files\Adobe
[28/02/2018 11:19:46] - |D| - [13942800] - C:\Program Files (x86)\Common Files\BattlEye
[05/08/2017 19:41:39] - |D| - [1708032] - C:\Program Files (x86)\Common Files\InstallShield
[18/03/2017 23:03:28] - |AD| - [172533837] - C:\Program Files (x86)\Common Files\Microsoft Shared
[18/03/2017 23:03:28] - |D| - [2702] - C:\Program Files (x86)\Common Files\Services
[06/07/2017 00:16:32] - |D| - [4019264] - C:\Program Files (x86)\Common Files\Steam
[18/03/2017 23:03:28] - |D| - [9980083] - C:\Program Files (x86)\Common Files\System
[23/09/2017 15:31:54] - |D| - [113563158] - C:\Program Files (x86)\Common Files\Windows Live
[27/02/2018 23:39:33] - |D| - [34175488] - C:\Program Files (x86)\Common Files\Wise Installation Wizard

---------- | C:\Program Files\Common files

[05/07/2017 18:48:18] - |D| - [40136928] - C:\Program Files\Common files\ATI Technologies
[05/07/2017 23:24:45] - |AD| - [14552] - C:\Program Files\Common files\DESIGNER
[18/03/2017 23:03:28] - |AD| - [443322726] - C:\Program Files\Common files\microsoft shared
[18/03/2017 23:03:28] - |D| - [2702] - C:\Program Files\Common files\Services
[18/03/2017 23:03:28] - |D| - [10900019] - C:\Program Files\Common files\System

---------- | Tasks

[MD5.F1A6CD5ADAAB953A6764EA364E17BFB8] - [05/07/2017 18:22:38] - |AH| - [6] - C:\Windows\Tasks\SA.DAT
[MD5.03218B198F7E6A70D610E3DDABCCDC1D] - [02/08/2018 23:21:38] - |A| - [4562] - C:\Windows\System32\Tasks\Adobe Acrobat Update Task         :   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
[MD5.4CE8A6B8234F70EE0EF9CBADC8059858] - [04/02/2018 11:45:23] - |A| - [3676] - C:\Windows\System32\Tasks\AdobeGCInvoker-1.0-BUGCODE-USB-DRI-Luca         :   C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe
[MD5.00000000000000000000000000000000] - [09/08/2017 17:37:05] - |D| - [0] - C:\Windows\System32\Tasks\Attività del Visualizzatore eventi
[MD5.C0C71E84CF7175F43CC7AA4AB8A68985] - [06/07/2017 14:47:40] - |A| - [3656] - C:\Windows\System32\Tasks\AutoKMS         :   C:\Windows\AutoKMS\AutoKMS.exe
[MD5.B930F842589A621F861C5BF2C830A611] - [30/04/2018 19:45:39] - |A| - [3546] - C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore         :   C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
[MD5.717A409D4C47B2641C8A69ECE7BC63D4] - [30/04/2018 19:45:39] - |A| - [3670] - C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA         :   C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
[MD5.00000000000000000000000000000000] - [18/03/2017 23:03:29] - |D| - [549850] - C:\Windows\System32\Tasks\Microsoft
[MD5.F355C64992E97B643A7ADA7152FDD67A] - [07/08/2017 07:49:06] - |A| - [3378] - C:\Windows\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2971312339-4097301404-2670616240-1001         :   %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe
[MD5.00000000000000000000000000000000] - [06/07/2017 15:32:21] - |D| - [3374] - C:\Windows\System32\Tasks\S-1-5-21-2971312339-4097301404-2670616240-1001
[MD5.EE0FBCAB1EBD4284B0A421757B1F6BD0] - [04/09/2017 18:54:11] - |A| - [3160] - C:\Windows\System32\Tasks\StartCN         :   "C:\Program Files\AMD\CNext\CNext\cncmd.exe"
[MD5.00000000000000000000000000000000] - [18/03/2017 23:03:29] - |D| - [0] - C:\Windows\Syswow64\Tasks\Microsoft

---------- | Firewall

[HKLM\SYSTEM\CurrentControlSet\Services\sharedaccess\Parameters\FirewallPolicy\FirewallRules]
"WiFiDirect-KM-Driver-In-TCP"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=6|App=System|Name=@wlansvc.dll,-37378|Desc=@wlansvc.dll,-37890|EmbedCtxt=@wlansvc.dll,-36865|TTK2_27=WFDKmDriver|
"WiFiDirect-KM-Driver-Out-TCP"=v2.27|Action=Allow|Active=TRUE|Dir=Out|Protocol=6|App=System|Name=@wlansvc.dll,-37379|Desc=@wlansvc.dll,-37891|EmbedCtxt=@wlansvc.dll,-36865|TTK2_27=WFDKmDriver|
"WiFiDirect-KM-Driver-In-UDP"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=17|App=System|Name=@wlansvc.dll,-37380|Desc=@wlansvc.dll,-37892|EmbedCtxt=@wlansvc.dll,-36865|TTK2_27=WFDKmDriver|
"WiFiDirect-KM-Driver-Out-UDP"=v2.27|Action=Allow|Active=TRUE|Dir=Out|Protocol=17|App=System|Name=@wlansvc.dll,-37381|Desc=@wlansvc.dll,-37893|EmbedCtxt=@wlansvc.dll,-36865|TTK2_27=WFDKmDriver|
"DeliveryOptimization-TCP-In"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=6|LPort=7680|App=%SystemRoot%\system32\svchost.exe|Svc=dosvc|Name=@%systemroot%\system32\dosvc.dll,-102|Desc=@%systemroot%\system32\dosvc.dll,-104|EmbedCtxt=@%systemroot%\system32\dosvc.dll,-100|Edge=TRUE|
"DeliveryOptimization-UDP-In"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=17|LPort=7680|App=%SystemRoot%\system32\svchost.exe|Svc=dosvc|Name=@%systemroot%\system32\dosvc.dll,-103|Desc=@%systemroot%\system32\dosvc.dll,-104|EmbedCtxt=@%systemroot%\system32\dosvc.dll,-100|Edge=TRUE|
"Netlogon-NamedPipe-In"=v2.27|Action=Allow|Active=FALSE|Dir=In|Protocol=6|LPort=445|App=System|Name=@netlogon.dll,-1003|Desc=@netlogon.dll,-1006|EmbedCtxt=@netlogon.dll,-1010|
"Netlogon-TCP-RPC-In"=v2.27|Action=Allow|Active=FALSE|Dir=In|Protocol=6|LPort=RPC|App=%SystemRoot%\System32\lsass.exe|Name=@netlogon.dll,-1008|Desc=@netlogon.dll,-1009|EmbedCtxt=@netlogon.dll,-1010|
"WirelessDisplay-In-TCP"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=6|App=%systemroot%\system32\WUDFHost.exe|Name=@wifidisplay.dll,-10200|Desc=@wifidisplay.dll,-10201|LUAuth=O:LSD:(A;;CC;;;S-1-5-84-0-0-0-0-0)|EmbedCtxt=@wifidisplay.dll,-100|TTK2_22=WFDDisplay|
"WirelessDisplay-Out-TCP"=v2.27|Action=Allow|Active=TRUE|Dir=Out|Protocol=6|App=%systemroot%\system32\WUDFHost.exe|Name=@wifidisplay.dll,-10202|Desc=@wifidisplay.dll,-10203|LUAuth=O:LSD:(A;;CC;;;S-1-5-84-0-0-0-0-0)|EmbedCtxt=@wifidisplay.dll,-100|TTK2_22=WFDDisplay|
"WirelessDisplay-Out-UDP"=v2.27|Action=Allow|Active=TRUE|Dir=Out|Protocol=17|App=%systemroot%\system32\WUDFHost.exe|Name=@wifidisplay.dll,-10204|Desc=@wifidisplay.dll,-10205|LUAuth=O:LSD:(A;;CC;;;S-1-5-84-0-0-0-0-0)|EmbedCtxt=@wifidisplay.dll,-100|TTK2_22=WFDDisplay|
"WirelessDisplay-Infra-In-TCP"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=6|LPort=7250|App=%systemroot%\system32\CastSrv.exe|Name=@wifidisplay.dll,-10206|Desc=@wifidisplay.dll,-10207|EmbedCtxt=@wifidisplay.dll,-100|
"{CA8CA25C-2D41-43A6-A610-EF03FB36801E}"=v2.27|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=Holographic Item Player|Desc=Holographic Item Player|LUOwn=S-1-5-21-2971312339-4097301404-2670616240-1001|AppPkgId=S-1-15-2-2848169271-1944770290-2690789639-3499139168-2840136067-3338101526-125811250|EmbedCtxt=Holographic Item Player|Platform=2:6:2|Platform2=GTEQ|
"{B2B73606-B31E-46DA-A76C-B22533A6F8E4}"=v2.27|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=Wallet|Desc=Wallet|LUOwn=S-1-5-21-2971312339-4097301404-2670616240-1001|AppPkgId=S-1-15-2-567501097-281763132-502764112-1855211022-3143306454-2372101908-561929011|EmbedCtxt=Wallet|Platform=2:6:2|Platform2=GTEQ|
"TCP Query User{33CE16EC-C3D4-4389-AC3D-0B4AD398753D}D:\hearthstone\hearthstone.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|Profile=Public|App=D:\hearthstone\hearthstone.exe|Name=hearthstone|Desc=hearthstone|Defer=User|
"UDP Query User{B9F03BDA-1553-4EBD-ACA7-51CE3D2F1A0D}D:\hearthstone\hearthstone.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|Profile=Public|App=D:\hearthstone\hearthstone.exe|Name=hearthstone|Desc=hearthstone|Defer=User|
"{E8780359-651D-4F55-AAB3-0949A4156E3D}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Program Files\qBittorrent\qbittorrent.exe|Name=qBittorrent|
"{F9AAFB4C-9525-459F-979F-DFB690C034F1}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Program Files\qBittorrent\qbittorrent.exe|Name=qBittorrent|
"{4A1880B6-5A30-437A-B69F-38B0B52D6771}"=v2.27|Action=Allow|Active=TRUE|Dir=In|App=C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe|Name=Windows Live Communications Platform|Edge=TRUE|
"{FE6A2E14-7F9A-4402-ACE4-0F0C79BEA5BF}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=6|LPort=2869|RA4=LocalSubnet|RA6=LocalSubnet|Name=Windows Live Communications Platform (UPnP)|
"{9C0111F8-763A-4036-BAA8-074B8D4D3FBE}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=17|LPort=1900|RA4=LocalSubnet|RA6=LocalSubnet|Name=Windows Live Communications Platform (SSDP)|
"{56FBF901-BF24-4029-9549-F50149EE04DE}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=D:\far cry 3\Far Cry 3 Blood Dragon\bin\fc3_blooddragon.exe|Name= FC3 Blood Dragon |
"{3991E0F7-4591-4821-B423-786A2EA10316}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=D:\far cry 3\Far Cry 3 Blood Dragon\bin\fc3_blooddragon.exe|Name= FC3 Blood Dragon |
"{7B7EB5DB-4F36-48CA-A456-614DA32E86F3}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=D:\far cry 3\Far Cry 3 Blood Dragon\bin\fc3_blooddragon_d3d11_b.exe|Name= FC3 Blood Dragon 11 |
"{56A41D98-BEE8-4B2A-A956-43D38211069D}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=D:\far cry 3\Far Cry 3 Blood Dragon\bin\fc3_blooddragon_d3d11_b.exe|Name= FC3 Blood Dragon 11 |
"{E7D81A6A-F438-41E6-BF18-A24797301C5A}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=D:\far cry 3\Far Cry 3 Blood Dragon\bin\fc3_blooddragon_d3d11.exe|Name= FC3 Blood Dragon 11 l |
"{96192B78-5CDA-4300-8481-62451B911C21}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=D:\far cry 3\Far Cry 3 Blood Dragon\bin\fc3_blooddragon_d3d11.exe|Name= FC3 Blood Dragon 11 l |
"{BF106FC3-894A-4531-9BEB-37A78296F371}"=v2.27|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=Samsung Printer Experience|Desc=Samsung Printer Experience|LUOwn=S-1-5-21-2971312339-4097301404-2670616240-1001|AppPkgId=S-1-15-2-199443308-783181745-3731900621-737618142-274797140-2538204478-2503832961|EmbedCtxt=Samsung Printer Experience|Platform=2:6:2|Platform2=GTEQ|
"{502E6C48-FA7C-4D9C-98C8-FE309B3EA267}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Profile=Domain|Profile=Private|Profile=Public|Name=Samsung Printer Experience|Desc=Samsung Printer Experience|LUOwn=S-1-5-21-2971312339-4097301404-2670616240-1001|AppPkgId=S-1-15-2-199443308-783181745-3731900621-737618142-274797140-2538204478-2503832961|EmbedCtxt=Samsung Printer Experience|Platform=2:6:2|Platform2=GTEQ|Edge=TRUE|
"{F9B8B161-DF65-4062-ACFE-47E20E6E25DB}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Profile=Public|IFType=Wireless|Name=Samsung Printer Experience|Desc=Samsung Printer Experience|LUOwn=S-1-5-21-2971312339-4097301404-2670616240-1001|AppPkgId=S-1-15-2-199443308-783181745-3731900621-737618142-274797140-2538204478-2503832961|EmbedCtxt=Samsung Printer Experience|Platform=2:6:2|Platform2=GTEQ|TTK2_22=WFDDevices|
"{F1306A98-A21C-460A-9BCE-060E63E3A00B}"=v2.27|Action=Allow|Active=TRUE|Dir=Out|Profile=Public|IFType=Wireless|Name=Samsung Printer Experience|Desc=Samsung Printer Experience|LUOwn=S-1-5-21-2971312339-4097301404-2670616240-1001|AppPkgId=S-1-15-2-199443308-783181745-3731900621-737618142-274797140-2538204478-2503832961|EmbedCtxt=Samsung Printer Experience|Platform=2:6:2|Platform2=GTEQ|TTK2_22=WFDDevices|
"TCP Query User{A0507C62-F86E-46A4-AB15-B25EFE90F72A}D:\fortnite\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=D:\fortnite\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe|Name=EpicGamesLauncher|Desc=EpicGamesLauncher|Defer=User|
"UDP Query User{7D4ADFA5-1DCE-45DB-AA53-AEFAB0B3D20A}D:\fortnite\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=D:\fortnite\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe|Name=EpicGamesLauncher|Desc=EpicGamesLauncher|Defer=User|
"{BA3051E0-AC0A-4E8F-BCE1-2B0BE1719A6D}"=v2.27|Action=Block|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=D:\fortnite\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe|Name=EpicGamesLauncher|Desc=EpicGamesLauncher|
"{8AEB32A6-CEB4-4B47-995A-75CE4E4C5FDC}"=v2.27|Action=Block|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=D:\fortnite\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe|Name=EpicGamesLauncher|Desc=EpicGamesLauncher|
"TCP Query User{89BD774F-F5BC-481E-8130-7F10DB9D9902}D:\fortnite\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=D:\fortnite\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe|Name=EpicGamesLauncher|Desc=EpicGamesLauncher|Defer=User|
"UDP Query User{4F792B11-FD0C-4B02-8231-6A5510730FCD}D:\fortnite\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=D:\fortnite\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe|Name=EpicGamesLauncher|Desc=EpicGamesLauncher|Defer=User|
"TCP Query User{77F8624D-EE68-4B54-9873-38B4C7616750}D:\fortnite\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=D:\fortnite\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe|Name=Fortnite|Desc=Fortnite|Defer=User|
"UDP Query User{987713DD-83E9-482C-A7DF-9A9B3E0DFE0D}D:\fortnite\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=D:\fortnite\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe|Name=Fortnite|Desc=Fortnite|Defer=User|
"{C5416F47-4DF5-4FDE-920D-840FA3390FFB}"=v2.27|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=Microsoft Sticky Notes|Desc=Microsoft Sticky Notes|LUOwn=S-1-5-21-2971312339-4097301404-2670616240-1001|AppPkgId=S-1-15-2-3539788797-2700867667-1432428195-1581642-2885308443-3834444517-2495346167|EmbedCtxt=Microsoft Sticky Notes|Platform=2:6:2|Platform2=GTEQ|
"{168797A5-142E-4C20-B244-DE68F21BF949}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Profile=Domain|Profile=Private|Name=Microsoft Sticky Notes|Desc=Microsoft Sticky Notes|LUOwn=S-1-5-21-2971312339-4097301404-2670616240-1001|AppPkgId=S-1-15-2-3539788797-2700867667-1432428195-1581642-2885308443-3834444517-2495346167|EmbedCtxt=Microsoft Sticky Notes|Platform=2:6:2|Platform2=GTEQ|
"{CC41FF64-8FFA-492C-8726-E8C95D365299}"=v2.27|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=Phototastic Collage|Desc=Phototastic Collage|LUOwn=S-1-5-21-2971312339-4097301404-2670616240-1001|AppPkgId=S-1-15-2-2502358608-583759769-2409807134-3449801485-999338879-2502503695-2304874636|EmbedCtxt=Phototastic Collage|Platform=2:6:2|Platform2=GTEQ|
"{D31A5383-2914-40AE-863E-F8CED2619C86}"=v2.27|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=Twitter|Desc=Twitter|LUOwn=S-1-5-21-2971312339-4097301404-2670616240-1001|AppPkgId=S-1-15-2-1063257880-1914585122-1954150059-946145533-116938067-416079064-1690466945|EmbedCtxt=Twitter|Platform=2:6:2|Platform2=GTEQ|
"TCP Query User{C909C915-85D1-46EB-BD8C-184B80EE8883}C:\program files (x86)\smart view\smart view.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\program files (x86)\smart view\smart view.exe|Name=Smart View|Desc=Smart View|Defer=User|
"UDP Query User{24D57120-109F-4748-9EE9-6BA4EAAAE448}C:\program files (x86)\smart view\smart view.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\program files (x86)\smart view\smart view.exe|Name=Smart View|Desc=Smart View|Defer=User|
"{BC685151-0DB2-483C-8970-34E0C517DD05}"=v2.27|Action=Block|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\program files (x86)\smart view\smart view.exe|Name=Smart View|Desc=Smart View|
"{47983C35-A302-4307-9BE6-76426D541C8B}"=v2.27|Action=Block|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\program files (x86)\smart view\smart view.exe|Name=Smart View|Desc=Smart View|
"{01195B9B-500A-4168-B1F1-25CE35B7FFA2}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Program Files (x86)\REALTEK\Wireless LAN Utility\RtWLan.exe|Name=RtWlan|
"{D0D44C44-5E60-46E1-8E95-D5C773FCCD09}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Program Files (x86)\REALTEK\Wireless LAN Utility\RtWLan.exe|Name=RtWlan|
"{BFBD4889-A15E-477A-A3C0-1F9FB2CD9CB3}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|LPort=1542|Name=Realtek WPS TCP Prot|
"{EDE87F44-F1F9-4284-BC71-68884F10B289}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|LPort=1542|Name=Realtek WPS UDP Prot|
"{3D50B46A-93AA-4D56-82BF-2751789E79FA}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|LPort=53|Name=Realtek AP UDP Prot|
"{16C53CA3-A413-44AB-9479-A291233A1C3C}"=v2.27|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=@{EnvironmentsApp_10.0.15063.1387_neutral__cw5n1h2txyewy?ms-resource://EnvironmentsApp/resources/DisplayName}|Desc=@{EnvironmentsApp_10.0.15063.1387_neutral__cw5n1h2txyewy?ms-resource://EnvironmentsApp/resources/Description}|LUOwn=S-1-5-21-2971312339-4097301404-2670616240-1001|AppPkgId=S-1-15-2-968169919-1126953557-685195956-86120492-1320233397-643893155-1374718203|EmbedCtxt=@{EnvironmentsApp_10.0.15063.1387_neutral__cw5n1h2txyewy?ms-resource://EnvironmentsApp/resources/DisplayName}|Platform=2:6:2|Platform2=GTEQ|
"TCP Query User{E8E16E1E-D918-4812-8702-C70BF47A9E8B}C:\program files (x86)\tp-link\tp-link plc utility\tpplc.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\program files (x86)\tp-link\tp-link plc utility\tpplc.exe|Name=TP-Link PLC Utility|Desc=TP-Link PLC Utility|Defer=User|
"UDP Query User{E3157B91-BAF6-464E-9201-8011414B2227}C:\program files (x86)\tp-link\tp-link plc utility\tpplc.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\program files (x86)\tp-link\tp-link plc utility\tpplc.exe|Name=TP-Link PLC Utility|Desc=TP-Link PLC Utility|Defer=User|
"TCP Query User{90A0DF89-ACC0-414B-9CDA-2AEF748DF40B}C:\xampp\apache\bin\httpd.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\xampp\apache\bin\httpd.exe|Name=Apache HTTP Server|Desc=Apache HTTP Server|Defer=User|
"UDP Query User{DD3A113C-BDE5-428E-8CA3-EFBD4AA43430}C:\xampp\apache\bin\httpd.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\xampp\apache\bin\httpd.exe|Name=Apache HTTP Server|Desc=Apache HTTP Server|Defer=User|
"TCP Query User{ACA084BE-239D-48C7-BB55-96AC35C60790}C:\xampp\mysql\bin\mysqld.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\xampp\mysql\bin\mysqld.exe|Name=mysqld|Desc=mysqld|Defer=User|
"UDP Query User{F699B18A-FE2C-4607-8839-DC92922E661A}C:\xampp\mysql\bin\mysqld.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\xampp\mysql\bin\mysqld.exe|Name=mysqld|Desc=mysqld|Defer=User|
"{500ABC32-A290-4523-B4D7-E83AB54ABD54}"=v2.27|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=Keeper - Password Manager & Secure File Storage|Desc=Keeper - Password Manager & Secure File Storage|LUOwn=S-1-5-21-2971312339-4097301404-2670616240-1001|AppPkgId=S-1-15-2-1693445186-3345176799-2248129915-4000651515-812732840-1010160964-1868342332|EmbedCtxt=Keeper - Password Manager & Secure File Storage|Platform=2:6:2|Platform2=GTEQ|
"{EB854093-3E79-493F-B4E6-CAFD51E0FBAB}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Profile=Domain|Profile=Private|Profile=Public|Name=Keeper - Password Manager & Secure File Storage|Desc=Keeper - Password Manager & Secure File Storage|LUOwn=S-1-5-21-2971312339-4097301404-2670616240-1001|AppPkgId=S-1-15-2-1693445186-3345176799-2248129915-4000651515-812732840-1010160964-1868342332|EmbedCtxt=Keeper - Password Manager & Secure File Storage|Platform=2:6:2|Platform2=GTEQ|Edge=TRUE|
"{A5A125B3-1D6F-44A6-A2DB-E1A68FC54C5B}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Program Files\qBittorrent\qbittorrent.exe|Name=qBittorrent|
"{069E128D-4EA7-4423-9F1A-7A1FCE9EE971}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Program Files\qBittorrent\qbittorrent.exe|Name=qBittorrent|
"{0EAA0E11-8AFD-4E30-9931-CD8206655FB2}"=v2.27|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=Minecraft for Windows 10|Desc=Minecraft for Windows 10|LUOwn=S-1-5-21-2971312339-4097301404-2670616240-1001|AppPkgId=S-1-15-2-1958404141-86561845-1752920682-3514627264-368642714-62675701-733520436|EmbedCtxt=Minecraft for Windows 10|Platform=2:6:2|Platform2=GTEQ|
"{37D59B1C-1D86-4EFE-8671-4A11DD989245}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Profile=Domain|Profile=Private|Profile=Public|Name=Minecraft for Windows 10|Desc=Minecraft for Windows 10|LUOwn=S-1-5-21-2971312339-4097301404-2670616240-1001|AppPkgId=S-1-15-2-1958404141-86561845-1752920682-3514627264-368642714-62675701-733520436|EmbedCtxt=Minecraft for Windows 10|Platform=2:6:2|Platform2=GTEQ|Edge=TRUE|
"{032001AC-5E50-41B1-9AEF-5FAD472BEA7F}"=v2.27|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=3D Builder|Desc=3D Builder|LUOwn=S-1-5-21-2971312339-4097301404-2670616240-1001|AppPkgId=S-1-15-2-3995430443-3719053022-3339397951-2895237338-2437516106-1575886070-2755610054|EmbedCtxt=3D Builder|Platform=2:6:2|Platform2=GTEQ|
"{1334C843-24CA-4740-B081-03447E64E84F}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=17|LPort=5353|App=C:\Program Files (x86)\Google\Chrome\Application\chrome.exe|Name=Google Chrome (mDNS-In)|Desc=Regola inbound per consentire il traffico mDNS in Google Chrome.|EmbedCtxt=Google Chrome|
"{255EF511-D946-4EBB-AFDF-D182292418EA}"=v2.27|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=OneNote|Desc=OneNote|LUOwn=S-1-5-21-2971312339-4097301404-2670616240-1001|AppPkgId=S-1-15-2-3445883232-1224167743-206467785-1580939083-2750001491-3097792036-3019341970|EmbedCtxt=OneNote|Platform=2:6:2|Platform2=GTEQ|
"{89DE1AAA-3BEB-4736-8EE8-57EF3C8EE220}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Profile=Domain|Profile=Private|Name=OneNote|Desc=OneNote|LUOwn=S-1-5-21-2971312339-4097301404-2670616240-1001|AppPkgId=S-1-15-2-3445883232-1224167743-206467785-1580939083-2750001491-3097792036-3019341970|EmbedCtxt=OneNote|Platform=2:6:2|Platform2=GTEQ|
"{81CB7B7C-B97D-47C3-998A-38AD1804610B}"=v2.27|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=Microsoft Solitaire Collection|Desc=Microsoft Solitaire Collection|LUOwn=S-1-5-21-2971312339-4097301404-2670616240-1001|AppPkgId=S-1-15-2-1985198343-3186790915-4047221937-1969271670-3792558349-1325541827-400269725|EmbedCtxt=Microsoft Solitaire Collection|Platform=2:6:2|Platform2=GTEQ|
"{3C7F299E-AB99-4320-99C4-B9C81BB0F12D}"=v2.27|Action=Allow|Active=TRUE|Dir=In|Profile=Domain|Profile=Private|Name=Microsoft Solitaire Collection|Desc=Microsoft Solitaire Collection|LUOwn=S-1-5-21-2971312339-4097301404-2670616240-1001|AppPkgId=S-1-15-2-1985198343-3186790915-4047221937-1969271670-3792558349-1325541827-400269725|EmbedCtxt=Microsoft Solitaire Collection|Platform=2:6:2|Platform2=GTEQ|
"{EA61F491-C62D-47F6-A08C-AB02945E0AEB}"=v2.27|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=Xbox Game Bar Plugin|Desc=Xbox Game Bar Plugin|LUOwn=S-1-5-21-2971312339-4097301404-2670616240-1001|AppPkgId=S-1-15-2-1823635404-1364722122-2170562666-1762391777-2399050872-3465541734-3732476201|EmbedCtxt=Xbox Game Bar Plugin|Platform=2:6:2|Platform2=GTEQ|





---------- | Control\Class

[HKLM\SYSTEM\CurrentControlSet\Control\Class\{05f5cfe2-4733-4950-a6bb-07aad01a3a84}] : (XboxComposite) [] -> @dc1-controller.inf,%ClassName%;Xbox Peripherals
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{1264760F-A5C8-4BFE-B314-D56A7B44A362}] : (DXGKrnl) [] ->
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{13e42dfa-85d9-424d-8646-28a70f864f9c}] : (RemotePosDevice) [] -> @remoteposdrv.inf,%ClassName%;POS Remote Device
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{14b62f50-3f15-11dd-ae16-0800200c9a66}] : (DigitalMediaDevices) [] -> @digitalmediadevice.inf,%ClassName%;Digital Media Devices
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{1ed2bbf9-11f0-4084-b21f-ad83a8e6dcdc}] : (PrintQueue) [] -> @printqueue.inf,%ClassName%;Print queues
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{25dbce51-6c8f-4a72-8a6d-b54c2b4fc835}] : (WCEUSBS) [] -> @%SystemRoot%\System32\SysClass.Dll,-3026
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{268c95a1-edfe-11d3-95c3-0010dc4050a5}] : (Security Accelerator) [] -> @c_sslaccel.inf,%ClassName%;Security accelerators
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{2a9fe532-0cdc-44f9-9827-76192f2ca2fb}] : (HidMsr) [] -> @c_magneticstripereader.inf,%ClassName%;POS HID Magnetic Stripe Reader
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{2db15374-706e-4131-a0c7-d7c78eb0289a}] : (SystemRecovery) [] -> @c_fssystemrecovery.inf,%ClassDesc%;FS System recovery filters
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{2EA9B43F-3045-43B5-80F2-FD06C55FBB90}] : (vhdmp) [] ->
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{3163C566-D381-4467-87BC-A65A18D5B648}] : (fvevol) [] ->
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{3163C566-D381-4467-87BC-A65A18D5B649}] : (fvevol) [] ->
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{36fc9e60-c465-11cf-8056-444553540000}] : (USB) [] -> @%SystemRoot%\System32\SysClass.Dll,-3025
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{3e3f0674-c83c-4558-bb26-9820e1eba5c5}] : (ContentScreener) [] -> @c_fscontentscreener.inf,%ClassDesc%;FS Content screener filters
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{3f966bd9-fa04-4ec5-991c-d326973b5128}] : (AndroidUsbDeviceClass) [] -> @oem13.inf,%ClassName%;Android Device
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{43675d81-502a-4a82-9f84-b75f418c5dea}] : (Media Center Extender) [] -> @c_mcx.inf,%ClassDesc%;Media Center Extenders
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{4658ee7e-f050-11d1-b6bd-00c04fa372a7}] : (PnpPrinters) [] -> @%SystemRoot%\system32\ntprint.dll,-1300
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{48721b56-6795-11d2-b1a8-0080c72e74a2}] : (Dot4) [] -> @%SystemRoot%\system32\sysclass.dll,-3023
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{48d3ebc4-4cf8-48ff-b869-9c68ad42eb9f}] : (Replication) [] -> @c_fsreplication.inf,%ClassDesc%;FS Replication filters
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{49ce6ac8-6f86-11d2-b1e5-0080c72e74a2}] : (Dot4Print) [] -> @%SystemRoot%\system32\sysclass.dll,-3024
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e965-e325-11ce-bfc1-08002be10318}] : (CDROM) [] -> @%SystemRoot%\System32\StorProp.dll,-17001
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e966-e325-11ce-bfc1-08002be10318}] : (Computer) [] -> @%SystemRoot%\System32\SysClass.dll,-3000
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e967-e325-11ce-bfc1-08002be10318}] : (DiskDrive) [] -> @c_diskdrive.inf,%ClassDesc%;Disk drives
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e968-e325-11ce-bfc1-08002be10318}] : (Display) [] -> @%SystemRoot%\System32\DispCI.dll,-3100
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e969-e325-11ce-bfc1-08002be10318}] : (FDC) [] -> @%SystemRoot%\System32\SysClass.Dll,-3013
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e96a-e325-11ce-bfc1-08002be10318}] : (HDC) [] -> @%SystemRoot%\System32\SysClass.Dll,-3001
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e96b-e325-11ce-bfc1-08002be10318}] : (Keyboard) [] -> @%SystemRoot%\System32\SysClass.Dll,-3002
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e96c-e325-11ce-bfc1-08002be10318}] : (MEDIA) [] -> @%SystemRoot%\System32\mmci.dll,-3000
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}] : (Modem) [] -> @%SystemRoot%\System32\mdminst.dll,-14100
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e96e-e325-11ce-bfc1-08002be10318}] : (Monitor) [] -> @c_monitor.inf,%ClassDesc%;Monitors
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e96f-e325-11ce-bfc1-08002be10318}] : (Mouse) [] -> @%SystemRoot%\System32\SysClass.Dll,-3004
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e970-e325-11ce-bfc1-08002be10318}] : (MTD) [] -> @%SystemRoot%\System32\SysClass.Dll,-3021
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e971-e325-11ce-bfc1-08002be10318}] : (MultiFunction) [] -> @%SystemRoot%\System32\SysClass.Dll,-3014
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e972-e325-11ce-bfc1-08002be10318}] : (Net) [] -> @%SystemRoot%\System32\NetCfgx.dll,-1502
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e973-e325-11ce-bfc1-08002be10318}] : (NetClient) [] -> @%SystemRoot%\System32\NetCfgx.dll,-1504
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e974-e325-11ce-bfc1-08002be10318}] : (NetService) [] -> @%SystemRoot%\System32\NetCfgx.dll,-1505
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e975-e325-11ce-bfc1-08002be10318}] : (NetTrans) [] -> @%SystemRoot%\System32\NetCfgx.dll,-1503
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e977-e325-11ce-bfc1-08002be10318}] : (PCMCIA) [] -> @%SystemRoot%\System32\SysClass.Dll,-3010
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e978-e325-11ce-bfc1-08002be10318}] : (Ports) [] -> @%SystemRoot%\System32\msports.dll,-10000
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e979-e325-11ce-bfc1-08002be10318}] : (Printer) [] -> @%SystemRoot%\system32\ntprint.dll,-1004
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e97b-e325-11ce-bfc1-08002be10318}] : (SCSIAdapter) [] -> @%SystemRoot%\System32\SysClass.Dll,-3005
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e97d-e325-11ce-bfc1-08002be10318}] : (System) [] -> @%SystemRoot%\System32\SysClass.Dll,-3008
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e97e-e325-11ce-bfc1-08002be10318}] : (Unknown) [] -> @%SystemRoot%\System32\SysClass.Dll,-3009
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e980-e325-11ce-bfc1-08002be10318}] : (FloppyDisk) [] -> @%SystemRoot%\System32\SysClass.Dll,-3015
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{4fc9541c-0fe6-4480-a4f6-9495a0d17cd2}] : (HidLineDisplay) [] -> @c_linedisplay.inf,%ClassName%;POS Line Display
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{50127dc3-0f36-415e-a6cc-4cb3be910b65}] : (Processor) [] -> @c_processor.inf,%ClassDesc%;Processors
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{50906cb8-ba12-11d1-bf5d-0000f805f530}] : (MultiPortSerial) [] -> @%SystemRoot%\system32\sysclass.dll,-3022
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{5099944a-f6b9-4057-a056-8c550228544c}] : (Memory) [] -> @%SystemRoot%\System32\SysClass.Dll,-3018
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{50dd5230-ba8a-11d1-bf5d-0000f805f530}] : (SmartCardReader) [] -> @%SystemRoot%\System32\StorProp.dll,-17002
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{5175d334-c371-4806-b3ba-71fd53c9258d}] : (Sensor) [] -> @%SystemRoot%\system32\SensorsCpl.dll,-10000
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{533c5b84-ec70-11d2-9505-00c04f79deaf}] : (VolumeSnapshot) [] -> @%SystemRoot%\System32\SysClass.Dll,-3011
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{53966cb1-4d46-4166-bf23-c522403cd495}] : (ScmDisk) [] -> @c_scmdisk.inf,%ClassDesc%;Persistent memory disks
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{53ccb149-e543-4c84-b6e0-bce4f6b7e806}] : (ScmVolume) [] -> @c_scmvolume.inf,%ClassDesc%;Storage Class Memory volumes
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{53d29ef7-377c-4d14-864b-eb3a85769359}] : (Biometric) [] -> @%SystemRoot%\System32\SysClass.DLL,-3028
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{5630831c-06c9-4856-b327-f5d32586e060}] : (Proximity) [] -> @c_proximity.inf,%ClassDesc%;Proximity devices
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{5989fce8-9cd0-467d-8a6a-5419e31529d4}] : (AudioProcessingObject) [] -> @c_apo.inf,%ClassDesc%;Audio Processing Objects (APOs)
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{5aea001d-9372-4ed7-97f3-b79bf15a53c5}] : (OposLegacyDevice) [] -> @oposdrv.inf,%ClassName%;OPOS Legacy Device
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{5c4c3332-344d-483c-8739-259e934c9cc8}] : (SoftwareComponent) [] -> @c_swcomponent.inf,%ClassDesc%;Software components
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{5d1b9aaa-01e2-46af-849f-272b3f324c46}] : (FSFilterSystem) [] -> @c_fssystem.inf,%ClassDesc%;FS System filters
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{62f9c741-b25a-46ce-b54c-9bccce08b6f2}] : (SoftwareDevice) [] -> @c_swdevice.inf,%ClassDesc%;Software devices
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{645ad99b-1344-4316-837a-08a3e73db222}] : (PerceptionSimulation) [] -> @perceptionsimulationsixdof.inf,%ClassName%;Perception Simulation Controllers
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{6a0a8e78-bba6-4fc4-a709-1e33cd09d67e}] : (PhysicalQuotaManagement) [] -> @c_fsphysicalquotamgmt.inf,%ClassDesc%;FS Physical quota management filters
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{6bdd1fc1-810f-11d0-bec7-08002be2092f}] : (1394) [] -> @%SystemRoot%\System32\SysClass.Dll,-3016
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{6bdd1fc5-810f-11d0-bec7-08002be2092f}] : (Infrared) [] -> @%SystemRoot%\System32\NetCfgx.dll,-1501
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{6bdd1fc6-810f-11d0-bec7-08002be2092f}] : (Image) [] -> @%SystemRoot%\system32\sti_ci.dll,-52
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{6d807884-7d21-11cf-801c-08002be10318}] : (TapeDrive) [] -> @%SystemRoot%\System32\SysClass.Dll,-3006
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{6FAE73B7-B735-4B50-A0DA-0DC2484B1F1A}] : (BasicDisplay) [] ->
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{71a27cdd-812a-11d0-bec7-08002be2092f}] : (Volume) [] -> @c_volume.inf,%ClassDesc%;Storage volumes
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{71aa14f8-6fad-4622-ad77-92bb9d7e6947}] : (ContinuousBackup) [] -> @c_fscontinuousbackup.inf,%ClassDesc%;FS Continuous backup filters
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{72631e54-78a4-11d0-bcf7-00aa00b7b32a}] : (Battery) [] -> @%SystemRoot%\system32\powrprof.dll,-611
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{745a17a0-74d3-11d0-b6fe-00a0c90f57da}] : (HIDClass) [] -> @%SystemRoot%\System32\hid.dll,-101
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{772e18f2-8925-4229-a5ac-6453cb482fda}] : (HidCashDrawer) [] -> @c_cashdrawer.inf,%ClassName%;POS Cash Drawer
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{7ebefbc0-3200-11d2-b4c2-00a0c9697d07}] : (61883) [] -> @%SystemRoot%\System32\SysClass.Dll,-3019
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{8503c911-a6c7-4919-8f79-5028f5866b0c}] : (QuotaManagement) [] -> @c_fsquotamgmt.inf,%ClassDesc%;FS Quota management filters
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{87ef9ad1-8f70-49ee-b215-ab1fcadcbe3c}] : (NetDriver) [] -> @c_netdriver.inf,%ClassDesc%;Universal Network Drivers
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{88a1c342-4539-11d3-b88d-00c04fad5171}] : (TS_Generic) [] -> @ts_generic.inf,%TSClassName%;Generic Remote Desktop devices
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{88bae032-5a81-49f0-bc3d-a4ff138216d6}] : (USBDevice) [] -> @%SystemRoot%\System32\SysClass.Dll,-3029
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{89786ff1-9c12-402f-9c9e-17753c7f4375}] : (CopyProtection) [] -> @c_fscopyprotection.inf,%ClassDesc%;FS Copy protection filters
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{8ecc055d-047f-11d1-a537-0000f8753ed1}] : (LegacyDriver) [] -> @%SystemRoot%\System32\SysClass.Dll,-3003
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{990a2bd7-e738-46c7-b26f-1cf8fb9f1391}] : (SmartCard) [] -> @%SystemRoot%\System32\SysClass.DLL,-3031
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{9d6d66a6-0b0c-4563-9077-a0e9a7955ae4}] : (Ramdisk) [] -> @ramdisk.inf,%ClassName%;RAM Disk drives
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{9da2b80f-f89f-4a49-a5c2-511b085b9e8a}] : (EhStorSilo) [] -> @rawsilo.inf,%ClassName%;IEEE 1667 silo and control devices
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{a0a588a4-c46f-4b37-b7ea-c82fe89870c6}] : (SDHost) [] -> @%SystemRoot%\System32\SysClass.Dll,-3012
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{a0a701c0-a511-42ff-aa6c-06dc0395576f}] : (Encryption) [] -> @c_fsencryption.inf,%ClassDesc%;FS Encryption filters
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{A3E32DBA-BA89-4F17-8386-2D0127FBD4CC}] : (rdpbus) [] ->
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{b1d1a169-c54f-4379-81db-bee7d88d7454}] : (AntiVirus) [] -> @c_fsantivirus.inf,%ClassDesc%;FS Anti-virus filters
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{b86dff51-a31e-4bac-b3cf-e8cfe75c9fc2}] : (ActivityMonitor) [] -> @c_fsactivitymonitor.inf,%ClassDesc%;FS Activity monitor filters
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{bbbe8734-08fa-4966-b6a6-4e5ad010cdd7}] : (USBFunctionController) [] -> @%SystemRoot%\System32\SysClass.Dll,-3030
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{c06ff265-ae09-48f0-812c-16753d7cba83}] : (AVC) [] -> @%SystemRoot%\System32\SysClass.Dll,-3027
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{c166523c-fe0c-4a94-a586-f1a80cfbbf3e}] : (AudioEndpoint) [] -> @audioendpoint.inf,%ClassName%;Audio inputs and outputs
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{c243ffbd-3afc-45e9-b3d3-2ba18bc7ebc5}] : (BarcodeScanner) [] -> @c_barcodescanner.inf,%ClassName%;POS Barcode Scanner
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{c30ecea0-11ef-4ef9-b02e-6af81e6e65c0}] : (WSDPrintDevice) [] -> @wsdprint.inf,%ClassName%;WSD Print Provider
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{c7bc9b22-21f0-4f0d-9bb6-66c229b8cd33}] : (POSPrinter) [] -> @c_receiptprinter.inf,%ClassName%;POS Receipt Printer
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{cdcf0939-b75b-4630-bf76-80f7ba655884}] : (CFSMetadataServer) [] -> @c_fscfsmetadataserver.inf,%ClassDesc%;FS CFS metadata server filters
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{ce5939ae-ebde-11d0-b181-0000f8753ec4}] : (MediumChanger) [] -> @%SystemRoot%\System32\StorProp.dll,-17003
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{d02bc3da-0c8e-4945-9bd5-f1883c226c8c}] : (SecurityEnhancer) [] -> @c_fssecurityenhancer.inf,%ClassDesc%;FS Security enhancer filters
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{d421b08e-6d16-41ca-9c4d-9147e5ac98e0}] : (Miracast) [] -> @miradisp.inf,%ClassName%;Miracast display devices
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{d48179be-ec20-11d1-b6b8-00c04fa372a7}] : (SBP2) [] -> @%SystemRoot%\System32\SysClass.Dll,-3017
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{d546500a-2aeb-45f6-9482-f4b1799c3177}] : (HSM) [] -> @c_fshsm.inf,%ClassDesc%;FS HSM filters
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{d612553d-06b1-49ca-8938-e39ef80eb16f}] : (Holographic) [] -> @c_holographic.inf,%ClassName%;Mixed Reality devices
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{d61ca365-5af4-4486-998b-9db4734c6ca3}] : (XnaComposite) [] -> @xusb22.inf,%XUSB22.ClassName%;Xbox 360 Peripherals
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{d94ee5d8-d189-4994-83d2-f68d7d41b0e6}] : (SecurityDevices) [] -> @%SystemRoot%\System32\SysClass.Dll,-3020
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{db4f6ddd-9c0e-45e4-9597-78dbbad0f412}] : (SmartCardFilter) [] -> @%SystemRoot%\System32\SysClass.DLL,-3032
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{e0cbf06c-cd8b-4647-bb8a-263b43f0f974}] : (Bluetooth) [] -> @%SystemRoot%\system32\bthci.dll,-4001
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{e2f84ce7-8efa-411c-aa69-97454ca4cb57}] : (Extension) [] -> @c_extension.inf,%ClassDesc%;Extensions
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{e55fa6f9-128c-4d04-abab-630c74b1453a}] : (Infrastructure) [] -> @c_fsinfrastructure.inf,%ClassDesc%;FS Infrastructure filters
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{eec5ad98-8080-425f-922a-dabf3de3f69a}] : (WPD) [] -> @%SystemRoot%\System32\wpd_ci.dll,-101
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{f2e7dd72-6468-4e36-b6f1-6488f42c1b52}] : (Firmware) [] -> @c_firmware.inf,%ClassDesc%;Firmware
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{f3586baf-b5aa-49b5-8d6c-0569284c639f}] : (Compression) [] -> @c_fscompression.inf,%ClassDesc%;FS Compression filters
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{f75a86c0-10d8-4c3a-b233-ed60e4cdfaac}] : (Virtualization) [] -> @c_fsvirtualization.inf,%ClassDesc%;FS Virtualization filters
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{f8ecafa6-66d1-41a5-899b-66585d7216b7}] : (OpenFileBackup) [] -> @c_fsopenfilebackup.inf,%ClassDesc%;FS Open file backup filters
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{fe8f1572-c67a-48c0-bbac-0b5c6d66cafb}] : (Undelete) [] -> @c_fsundelete.inf,%ClassDesc%;FS Undelete filters
[HKLM\SYSTEM\CurrentControlSet\Control\Els\Services\{2D64B439-6CAF-4f6b-B688-E5D0F4FAA7D7}] : (Script Detection) [@elscore.dll,-2] -> ElsLad.dll (Copyright (c) Microsoft Corporation.)
[HKLM\SYSTEM\CurrentControlSet\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}] : (Transliteration) [@elscore.dll,-5] -> elstrans.dll (Copyright (c) Microsoft Corporation.)
[HKLM\SYSTEM\CurrentControlSet\Control\Els\Services\{CF7E00B1-909B-4d95-A8F4-611F7C377702}] : (Language Detection) [@elscore.dll,-1] -> ElsLad.dll (Copyright (c) Microsoft Corporation.)

---------- | Loaded modules (whitelist)

[06/07/2017 15:21:14] - (3.1.2.1) - (SeriousBit - nbdrv helper driver) - C:\Windows\system32\DRIVERS\nbdrv.sys
[18/03/2017 22:56:25] - (2.1.0.16) - (Qualcomm Atheros Co., Ltd. - Qualcomm Atheros Ar81xx series PCI-E Gigabit Ethernet Controller) - C:\Windows\System32\drivers\L1C63x64.sys
[01/03/2013 03:49:12] - (4.1.0.2980) - (Riverbed Technology, Inc. - npf.sys (NT5/6 AMD64) Kernel Driver) - C:\Windows\system32\drivers\npf.sys
[18/05/2018 16:08:04] - (1.0.0.0) - (Samsung Electronics - Port Contention Driver) - C:\Windows\system32\Drivers\SSPORT.sys

---------- | Services | 0 : Starting up | 1 : System | 2 : Automatic | 3 : Manual | 4 : Disabled | R : Running service | S : Stopped service

S0 - [Kernel Driver] - 3ware () -> System32\drivers\3ware.sys - AcceptPause: False - AcceptStop: False
R0 - [Kernel Driver] - ACPI (@acpi.inf,%ACPI.SvcDesc%;Microsoft ACPI Driver) -> System32\drivers\ACPI.sys - AcceptPause: False - AcceptStop: True
R0 - [Kernel Driver] - acpiex (Microsoft ACPIEx Driver) -> System32\Drivers\acpiex.sys - AcceptPause: False - AcceptStop: True
S0 - [Kernel Driver] - ADP80XX () -> System32\drivers\ADP80XX.SYS - AcceptPause: False - AcceptStop: False
S0 - [Kernel Driver] - amdkmafd (@oem5.inf,%AMDKMAFD_svcdesc%;AMD Audio Bus Lower Filter) -> System32\drivers\amdkmafd.sys - AcceptPause: False - AcceptStop: False
S0 - [Kernel Driver] - amdsata () -> System32\drivers\amdsata.sys - AcceptPause: False - AcceptStop: False
S0 - [Kernel Driver] - amdsbs () -> System32\drivers\amdsbs.sys - AcceptPause: False - AcceptStop: False
S0 - [Kernel Driver] - amdxata () -> System32\drivers\amdxata.sys - AcceptPause: False - AcceptStop: False
S0 - [Kernel Driver] - arcsas (@arcsas.inf,%arcsas_ServiceName%;Adaptec SAS/SATA-II RAID Storport's Miniport Driver) -> System32\drivers\arcsas.sys - AcceptPause: False - AcceptStop: False
R0 - [Kernel Driver] - atapi (@mshdc.inf,%idechannel.DeviceDesc%;IDE Channel) -> System32\drivers\atapi.sys - AcceptPause: False - AcceptStop: True
S0 - [Kernel Driver] - b06bdrv (@netbvbda.inf,%vbd_srv_desc%;QLogic Network Adapter VBD) -> System32\drivers\bxvbda.sys - AcceptPause: False - AcceptStop: False
R0 - [Kernel Driver] - CLFS (@%SystemRoot%\system32\drivers\clfs.sys,-100) -> System32\drivers\CLFS.sys - AcceptPause: False - AcceptStop: True
R0 - [Kernel Driver] - CNG () -> System32\Drivers\cng.sys - AcceptPause: False - AcceptStop: True
R0 - [Kernel Driver] - Disk (@disk.inf,%disk_ServiceDesc%;Disk Driver) -> System32\drivers\disk.sys - AcceptPause: False - AcceptStop: True
S0 - [Kernel Driver] - ebdrv (@netevbda.inf,%vbd_srv_desc%;QLogic 10 Gigabit Ethernet Adapter VBD) -> System32\drivers\evbda.sys - AcceptPause: False - AcceptStop: False
S0 - [Kernel Driver] - EhStorClass (@%SystemRoot%\system32\drivers\EhStorClass.sys,-100) -> System32\drivers\EhStorClass.sys - AcceptPause: False - AcceptStop: False
S0 - [Kernel Driver] - EhStorTcgDrv (@ehstortcgdrv.inf,%EhStorTcgDrv.Desc%;Microsoft driver for storage devices supporting IEEE 1667 and TCG protocols) -> System32\drivers\EhStorTcgDrv.sys - AcceptPause: False - AcceptStop: False
R0 - [File System Driver] - FileInfo (@%SystemRoot%\system32\drivers\fileinfo.sys,-100) -> System32\drivers\fileinfo.sys - AcceptPause: False - AcceptStop: True
R0 - [File System Driver] - FltMgr (@%SystemRoot%\system32\drivers\fltmgr.sys,-10001) -> system32\drivers\fltmgr.sys - AcceptPause: False - AcceptStop: True
R0 - [Kernel Driver] - fvevol (@%SystemRoot%\system32\drivers\fvevol.sys,-100) -> System32\DRIVERS\fvevol.sys - AcceptPause: False - AcceptStop: True
S0 - [Kernel Driver] - HpSAMD () -> System32\drivers\HpSAMD.sys - AcceptPause: False - AcceptStop: False
S0 - [Kernel Driver] - hwpolicy (@%systemroot%\system32\drivers\hwpolicy.sys,-101) -> System32\drivers\hwpolicy.sys - AcceptPause: False - AcceptStop: False
S0 - [Kernel Driver] - iaStorAV (@iastorav.inf,%iaStorAV.DeviceDesc%;Intel(R) SATA RAID Controller Windows) -> System32\drivers\iaStorAV.sys - AcceptPause: False - AcceptStop: False
S0 - [Kernel Driver] - iaStorV (@iastorv.inf,%*PNP0600.DeviceDesc%;Intel RAID Controller Windows 7) -> System32\drivers\iaStorV.sys - AcceptPause: False - AcceptStop: False
S0 - [Kernel Driver] - intelide () -> System32\drivers\intelide.sys - AcceptPause: False - AcceptStop: False
R0 - [Kernel Driver] - intelpep (@intelpep.inf,%INTELPEP.SVCDESC%;Intel(R) Power Engine Plug-in Driver) -> System32\drivers\intelpep.sys - AcceptPause: False - AcceptStop: True
R0 - [Kernel Driver] - iorate (@%SystemRoot%\system32\drivers\iorate.sys,-101) -> system32\drivers\iorate.sys - AcceptPause: False - AcceptStop: True
S0 - [Kernel Driver] - isapnp () -> System32\drivers\isapnp.sys - AcceptPause: False - AcceptStop: False
R0 - [Kernel Driver] - KSecDD () -> System32\Drivers\ksecdd.sys - AcceptPause: False - AcceptStop: True
R0 - [Kernel Driver] - KSecPkg () -> System32\Drivers\ksecpkg.sys - AcceptPause: False - AcceptStop: True
S0 - [Kernel Driver] - LSI_SAS () -> System32\drivers\lsi_sas.sys - AcceptPause: False - AcceptStop: False
S0 - [Kernel Driver] - LSI_SAS2i () -> System32\drivers\lsi_sas2i.sys - AcceptPause: False - AcceptStop: False
S0 - [Kernel Driver] - LSI_SAS3i () -> System32\drivers\lsi_sas3i.sys - AcceptPause: False - AcceptStop: False
S0 - [Kernel Driver] - LSI_SSS () -> System32\drivers\lsi_sss.sys - AcceptPause: False - AcceptStop: False
S0 - [Kernel Driver] - MbamElam (MbamElam) -> system32\DRIVERS\MbamElam.sys - AcceptPause: False - AcceptStop: False
S0 - [Kernel Driver] - megasas () -> System32\drivers\megasas.sys - AcceptPause: False - AcceptStop: False
S0 - [Kernel Driver] - megasas2i () -> System32\drivers\MegaSas2i.sys - AcceptPause: False - AcceptStop: False
S0 - [Kernel Driver] - megasr () -> System32\drivers\megasr.sys - AcceptPause: False - AcceptStop: False
R0 - [Kernel Driver] - mountmgr (@%SystemRoot%\system32\drivers\mountmgr.sys,-100) -> System32\drivers\mountmgr.sys - AcceptPause: False - AcceptStop: True
R0 - [Kernel Driver] - msisadrv () -> System32\drivers\msisadrv.sys - AcceptPause: False - AcceptStop: True
R0 - [File System Driver] - Mup (@%systemroot%\system32\drivers\mup.sys,-101) -> System32\Drivers\mup.sys - AcceptPause: False - AcceptStop: True
S0 - [Kernel Driver] - mvumis () -> System32\drivers\mvumis.sys - AcceptPause: False - AcceptStop: False
R0 - [Kernel Driver] - NDIS (@%SystemRoot%\system32\drivers\ndis.sys,-200) -> system32\drivers\ndis.sys - AcceptPause: False - AcceptStop: True
S0 - [Kernel Driver] - nvraid () -> System32\drivers\nvraid.sys - AcceptPause: False - AcceptStop: False
S0 - [Kernel Driver] - nvstor () -> System32\drivers\nvstor.sys - AcceptPause: False - AcceptStop: False
R0 - [Kernel Driver] - partmgr (@%SystemRoot%\system32\drivers\partmgr.sys,-100) -> System32\drivers\partmgr.sys - AcceptPause: False - AcceptStop: True
R0 - [Kernel Driver] - pci (@pci.inf,%pci_svcdesc%;Driver bus PCI) -> System32\drivers\pci.sys - AcceptPause: False - AcceptStop: True
R0 - [Kernel Driver] - pciide () -> System32\drivers\pciide.sys - AcceptPause: False - AcceptStop: True
S0 - [Kernel Driver] - pcmcia () -> System32\drivers\pcmcia.sys - AcceptPause: False - AcceptStop: False
R0 - [Kernel Driver] - pcw (Performance Counters for Windows Driver) -> System32\drivers\pcw.sys - AcceptPause: False - AcceptStop: True
R0 - [Kernel Driver] - pdc (@%SystemRoot%\system32\drivers\pdc.sys,-100) -> system32\drivers\pdc.sys - AcceptPause: False - AcceptStop: True
S0 - [Kernel Driver] - percsas2i () -> System32\drivers\percsas2i.sys - AcceptPause: False - AcceptStop: False
S0 - [Kernel Driver] - percsas3i () -> System32\drivers\percsas3i.sys - AcceptPause: False - AcceptStop: False
R0 - [Kernel Driver] - rdyboost (ReadyBoost) -> System32\drivers\rdyboost.sys - AcceptPause: False - AcceptStop: True
S0 - [Kernel Driver] - sbp2port (@sbp2.inf,%sbp2_ServiceDesc%;SBP-2 Transport/Protocol Bus Driver) -> System32\drivers\sbp2port.sys - AcceptPause: False - AcceptStop: False
S0 - [Kernel Driver] - scmbus (@scmbus.inf,%scmbus.SvcDesc%;Microsoft Storage Class Memory Bus Driver) -> System32\drivers\scmbus.sys - AcceptPause: False - AcceptStop: False
S0 - [Kernel Driver] - SiSRaid2 () -> System32\drivers\SiSRaid2.sys - AcceptPause: False - AcceptStop: False
S0 - [Kernel Driver] - SiSRaid4 () -> System32\drivers\sisraid4.sys - AcceptPause: False - AcceptStop: False
R0 - [Kernel Driver] - spaceport (@spaceport.inf,%Spaceport_ServiceDesc%;Storage Spaces Driver) -> System32\drivers\spaceport.sys - AcceptPause: False - AcceptStop: True
S0 - [Kernel Driver] - stexstor () -> System32\drivers\stexstor.sys - AcceptPause: False - AcceptStop: False
R0 - [Kernel Driver] - storahci (@mshdc.inf,%storahci_ServiceDescription%;Microsoft Standard SATA AHCI Driver) -> System32\drivers\storahci.sys - AcceptPause: False - AcceptStop: True
S0 - [Kernel Driver] - storflt (@wstorflt.inf,%service_desc%;Microsoft Hyper-V Storage Accelerator) -> System32\drivers\vmstorfl.sys - AcceptPause: False - AcceptStop: False
S0 - [Kernel Driver] - stornvme (@stornvme.inf,%StorNVMe_ServiceDesc%;Microsoft Standard NVM Express Driver) -> System32\drivers\stornvme.sys - AcceptPause: False - AcceptStop: False
S0 - [Kernel Driver] - storufs (@storufs.inf,%UfsServiceDesc%;Microsoft Universal Flash Storage (UFS) Driver) -> System32\drivers\storufs.sys - AcceptPause: False - AcceptStop: False
S0 - [Kernel Driver] - storvsc () -> System32\drivers\storvsc.sys - AcceptPause: False - AcceptStop: False
R0 - [Kernel Driver] - Tcpip (@%SystemRoot%\system32\tcpipcfg.dll,-50003) -> System32\drivers\tcpip.sys - AcceptPause: False - AcceptStop: True
R0 - [Kernel Driver] - vdrvroot (@vdrvroot.inf,%vdrvroot_svcdesc%;Microsoft Virtual Drive Enumerator) -> System32\drivers\vdrvroot.sys - AcceptPause: False - AcceptStop: True
S0 - [Kernel Driver] - vmbus (@wvmbus.inf,%vmbus.SVCDESC%;Virtual Machine Bus) -> System32\drivers\vmbus.sys - AcceptPause: False - AcceptStop: False
R0 - [Kernel Driver] - volmgr (@volmgr.inf,%volmgr_svcdesc%;Volume Manager Driver) -> System32\drivers\volmgr.sys - AcceptPause: False - AcceptStop: True
R0 - [Kernel Driver] - volmgrx (@%SystemRoot%\system32\drivers\volmgrx.sys,-100) -> System32\drivers\volmgrx.sys - AcceptPause: False - AcceptStop: True
R0 - [Kernel Driver] - volsnap (@%SystemRoot%\system32\drivers\volsnap.sys,-100) -> System32\drivers\volsnap.sys - AcceptPause: False - AcceptStop: True
R0 - [Kernel Driver] - volume (@volume.inf,%VolumeServiceDesc%;Volume driver) -> System32\drivers\volume.sys - AcceptPause: False - AcceptStop: True
S0 - [Kernel Driver] - vsmraid () -> System32\drivers\vsmraid.sys - AcceptPause: False - AcceptStop: False
S0 - [Kernel Driver] - VSTXRAID (@vstxraid.inf,%Driver.DeviceDesc%;VIA StorX Storage RAID Controller Windows Driver) -> System32\drivers\vstxraid.sys - AcceptPause: False - AcceptStop: False
S0 - [Kernel Driver] - WdBoot (@%ProgramFiles%\Windows Defender\MpAsDesc.dll,-390) -> system32\drivers\wd\WdBoot.sys - AcceptPause: False - AcceptStop: False
R0 - [Kernel Driver] - Wdf01000 (@%SystemRoot%\system32\drivers\Wdf01000.sys,-1000) -> system32\drivers\Wdf01000.sys - AcceptPause: False - AcceptStop: True
R0 - [File System Driver] - WdFilter (@%ProgramFiles%\Windows Defender\MpAsDesc.dll,-330) -> system32\drivers\wd\WdFilter.sys - AcceptPause: False - AcceptStop: True
R0 - [Kernel Driver] - WFPLWFS (@%SystemRoot%\System32\drivers\wfplwfs.sys,-6000) -> System32\drivers\wfplwfs.sys - AcceptPause: False - AcceptStop: True
R0 - [Kernel Driver] - WindowsTrustedRT (Windows Trusted Execution Environment Class Extension) -> system32\drivers\WindowsTrustedRT.sys - AcceptPause: False - AcceptStop: True
R0 - [Kernel Driver] - WindowsTrustedRTProxy (@WindowsTrustedRTProxy.inf,%WindowsTrustedRTProxy.SVCDESC%;Microsoft Windows Trusted Runtime Secure Service) -> System32\drivers\WindowsTrustedRTProxy.sys - AcceptPause: False - AcceptStop: True
R0 - [File System Driver] - Wof (Windows Overlay File System Filter Driver) -> (?) - AcceptPause: False - AcceptStop: True
R1 - [Kernel Driver] - AFD (@%systemroot%\system32\drivers\afd.sys,-1000) -> \SystemRoot\system32\drivers\afd.sys - AcceptPause: False - AcceptStop: True
R1 - [Kernel Driver] - ahcache (@%systemroot%\system32\drivers\ahcache.sys,-102) -> system32\DRIVERS\ahcache.sys - AcceptPause: False - AcceptStop: True
R1 - [Kernel Driver] - BasicDisplay () -> \SystemRoot\System32\drivers\BasicDisplay.sys - AcceptPause: False - AcceptStop: True
R1 - [Kernel Driver] - BasicRender () -> \SystemRoot\System32\drivers\BasicRender.sys - AcceptPause: False - AcceptStop: True
R1 - [Kernel Driver] - Beep (Beep) -> (?) - AcceptPause: False - AcceptStop: True
R1 - [Kernel Driver] - cdrom (@cdrom.inf,%cdrom_ServiceDesc%;CD-ROM Driver) -> \SystemRoot\System32\drivers\cdrom.sys - AcceptPause: False - AcceptStop: True
R1 - [Kernel Driver] - CSC (@%systemroot%\system32\cscsvc.dll,-202) -> system32\drivers\csc.sys - AcceptPause: False - AcceptStop: True
S1 - [Kernel Driver] - dam (@%SystemRoot%\system32\drivers\dam.sys,-100) -> system32\drivers\dam.sys - AcceptPause: False - AcceptStop: False
R1 - [File System Driver] - Dfsc (@%systemroot%\system32\wkssvc.dll,-1008) -> System32\Drivers\dfsc.sys - AcceptPause: False - AcceptStop: True
R1 - [File System Driver] - FileCrypt (@%systemroot%\system32\drivers\filecrypt.sys,-100) -> system32\drivers\filecrypt.sys - AcceptPause: False - AcceptStop: True
R1 - [Kernel Driver] - GpuEnergyDrv (@%SystemRoot%\system32\drivers\gpuenergydrv.sys,-100) -> System32\drivers\gpuenergydrv.sys - AcceptPause: False - AcceptStop: True
R1 - [File System Driver] - Msfs () -> (?) - AcceptPause: False - AcceptStop: True
R1 - [Kernel Driver] - mssmbios (@mssmbios.inf,%mssmbios_svcdesc%;Microsoft System Management BIOS Driver) -> \SystemRoot\System32\drivers\mssmbios.sys - AcceptPause: False - AcceptStop: True
R1 - [Kernel Driver] - nbdrv (@oem8.inf,%nbdrv_Desc%;NetBalancer Filter) -> \SystemRoot\system32\DRIVERS\nbdrv.sys - AcceptPause: False - AcceptStop: True
R1 - [File System Driver] - NetBIOS (@%windir%\system32\drivers\netbios.sys,-503) -> system32\drivers\netbios.sys - AcceptPause: False - AcceptStop: True
R1 - [Kernel Driver] - NetBT (@%SystemRoot%\system32\drivers\netbt.sys,-2) -> System32\DRIVERS\netbt.sys - AcceptPause: False - AcceptStop: True
R1 - [File System Driver] - Npfs () -> (?) - AcceptPause: False - AcceptStop: True
R1 - [Kernel Driver] - npsvctrig (@npsvctrig.inf,%NPSVCTRIG.SvcDisplayName%;Named pipe service trigger provider) -> \SystemRoot\System32\drivers\npsvctrig.sys - AcceptPause: False - AcceptStop: True
R1 - [Kernel Driver] - nsiproxy (@%SystemRoot%\system32\drivers\nsiproxy.sys,-2) -> system32\drivers\nsiproxy.sys - AcceptPause: False - AcceptStop: True
R1 - [Kernel Driver] - Null () -> (?) - AcceptPause: False - AcceptStop: True
R1 - [Kernel Driver] - Psched (@%windir%\System32\drivers\pacer.sys,-101) -> System32\drivers\pacer.sys - AcceptPause: False - AcceptStop: True
R1 - [File System Driver] - rdbss (@%systemroot%\system32\wkssvc.dll,-1000) -> system32\DRIVERS\rdbss.sys - AcceptPause: False - AcceptStop: True
R1 - [Kernel Driver] - tdx (@%SystemRoot%\system32\tcpipcfg.dll,-50004) -> \SystemRoot\system32\DRIVERS\tdx.sys - AcceptPause: False - AcceptStop: True
R1 - [Kernel Driver] - vwififlt (@%SystemRoot%\System32\drivers\vwififlt.sys,-259) -> System32\drivers\vwififlt.sys - AcceptPause: False - AcceptStop: True
R1 - [Kernel Driver] - ESProtectionDriver (Malwarebytes Anti-Exploit) -> \??\C:\Windows\system32\drivers\mbae64.sys - AcceptPause: False - AcceptStop: True
S2 - [File System Driver] - CldFlt (Windows Cloud Files Filter Driver) -> system32\drivers\cldflt.sys - AcceptPause: False - AcceptStop: False
R2 - [Kernel Driver] - clreg (@%SystemRoot%\system32\drivers\registry.sys,-100) -> \SystemRoot\System32\drivers\registry.sys - AcceptPause: False - AcceptStop: True
R2 - [Kernel Driver] - lltdio (@%SystemRoot%\system32\lltdres.dll,-6) -> system32\drivers\lltdio.sys - AcceptPause: False - AcceptStop: True
R2 - [File System Driver] - luafv (@%systemroot%\system32\drivers\luafv.sys,-100) -> \SystemRoot\system32\drivers\luafv.sys - AcceptPause: False - AcceptStop: True
R2 - [File System Driver] - MBAMChameleon (MBAMChameleon) -> \SystemRoot\System32\Drivers\MbamChameleon.sys - AcceptPause: False - AcceptStop: True
R2 - [Kernel Driver] - MMCSS (@%systemroot%\system32\drivers\mmcss.sys,-100) -> \SystemRoot\system32\drivers\mmcss.sys - AcceptPause: False - AcceptStop: True
R2 - [File System Driver] - mrxsmb10 (@%systemroot%\system32\wkssvc.dll,-1004) -> system32\DRIVERS\mrxsmb10.sys - AcceptPause: False - AcceptStop: True
R2 - [Kernel Driver] - MsLldp (@%SystemRoot%\system32\drivers\mslldp.sys,-200) -> system32\drivers\mslldp.sys - AcceptPause: False - AcceptStop: True
R2 - [Kernel Driver] - Ndu (@%SystemRoot%\system32\drivers\Ndu.sys,-10001) -> system32\drivers\Ndu.sys - AcceptPause: False - AcceptStop: True
R2 - [Kernel Driver] - NPF (NetGroup Packet Filter Driver) -> system32\drivers\npf.sys - AcceptPause: False - AcceptStop: True
R2 - [Kernel Driver] - PEAUTH (PEAUTH) -> system32\drivers\peauth.sys - AcceptPause: False - AcceptStop: True
R2 - [Kernel Driver] - rspndr (@%SystemRoot%\system32\lltdres.dll,-5) -> system32\drivers\rspndr.sys - AcceptPause: False - AcceptStop: True
R2 - [File System Driver] - srv (@%systemroot%\system32\srvsvc.dll,-102) -> System32\DRIVERS\srv.sys - AcceptPause: False - AcceptStop: True
R2 - [Kernel Driver] - SSPORT (SSPORT) -> \??\C:\Windows\system32\Drivers\SSPORT.sys - AcceptPause: False - AcceptStop: True
R2 - [File System Driver] - storqosflt (@%SystemRoot%\System32\drivers\storqosflt.sys,-101) -> system32\drivers\storqosflt.sys - AcceptPause: False - AcceptStop: True
R2 - [Kernel Driver] - tcpipreg (TCP/IP Registry Compatibility) -> System32\drivers\tcpipreg.sys - AcceptPause: False - AcceptStop: True
R2 - [Kernel Driver] - wanarp (@%systemroot%\system32\mprmsg.dll,-32011) -> System32\DRIVERS\wanarp.sys - AcceptPause: False - AcceptStop: True
R2 - [File System Driver] - wcifs (@%systemroot%\system32\drivers\wcifs.sys,-100) -> \SystemRoot\system32\drivers\wcifs.sys - AcceptPause: False - AcceptStop: True

---------- | System files (Microsoft|Avast|Atheros|Adaptec|Brother|Intel Files whitelisted)


---------- | Uninstall (Whitelist)

[HKU\S-1-5-21-2971312339-4097301404-2670616240-1001\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\SURVEY_PROGRAM] : (SURVEY_PROGRAM.-.) -> "C:\Program Files (x86)\SURVEY_PROGRAM\uninstall.exe"
[HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\AddressBook] : (.-.) ->
----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\Connection Manager] : (.-.) ->
[HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\DirectDrawEx] : (.-.) ->
[HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\DXM_Runtime] : (.-.) ->
[HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\Fontcore] : (.-.) ->
[HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\IE40] : (.-.) ->
[HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\IE4Data] : (.-.) ->
[HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\IE5BAKEX] : (.-.) ->
[HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\IEData] : (.-.) ->
[HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\MobileOptionPack] : (.-.) ->
[HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\MPlayer2] : (.-.) ->
[HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\SchedulingAgent] : (.-.) ->
[HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\WIC] : (.-.) ->
----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{05B6A133-2E68-1700-950A-1B8D85B8ACB8}] : (AMD Settings.-.Advanced Micro Devices, Inc.) ->
----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{07BFBD5C-2F63-6828-1B61-B41A44113F3B}] : (Catalyst Control Center Next Localization KO.-.Advanced Micro Devices, Inc.) ->
----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{1DBACFDB-5E43-7882-36BD-53526D34BD22}] : (Catalyst Control Center Next Localization HU.-.Advanced Micro Devices, Inc.) ->
----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{20D46801-147B-30AD-7C5A-AC4560A79096}] : (Catalyst Control Center Next Localization FI.-.Advanced Micro Devices, Inc.) ->
----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{22C39711-2747-D264-319A-1550BEEAAEC6}] : (Catalyst Control Center Next Localization FR.-.Advanced Micro Devices, Inc.) ->
----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{24DF617A-CD23-6E6A-126B-23630D2781CE}] : (Catalyst Control Center Next Localization TH.-.Advanced Micro Devices, Inc.) ->
----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{36EDC500-E4C0-371C-9865-08450415C1E9}] : (Catalyst Control Center Next Localization CS.-.Advanced Micro Devices, Inc.) ->
----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{4C2FB7FD-89FD-BA5C-585A-3811F326AD34}] : (Catalyst Control Center Next Localization DA.-.Advanced Micro Devices, Inc.) ->
----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{4D1D5407-9B69-6422-629C-8518A26004A4}] : (Catalyst Control Center Next Localization RU.-.Advanced Micro Devices, Inc.) ->
----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{66C5838F-B854-4A55-89E6-A6138747A4DF}] : (Epic Games Launcher Prerequisites (x64).-.Epic Games, Inc.) -> MsiExec.exe /X{66C5838F-B854-4A55-89E6-A6138747A4DF}
----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{83DDDFD8-AD42-72F9-E4F1-5456FDB304C9}] : (Catalyst Control Center Next Localization TR.-.Advanced Micro Devices, Inc.) ->
----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{949F125B-A6CC-5A5E-EEE7-4AC50305C1FA}] : (Catalyst Control Center Next Localization ES.-.Advanced Micro Devices, Inc.) ->
----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{A8379BAB-59A9-C0A3-8BCC-4852EA403692}] : (Catalyst Control Center Next Localization SV.-.Advanced Micro Devices, Inc.) ->
----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{A91FC4BF-C1EC-ADCA-79D1-F4F0671F1D60}] : (Catalyst Control Center Next Localization IT.-.Advanced Micro Devices, Inc.) ->
----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B26D75B8-FAB7-6F8B-767F-BAF975383D91}] : (Catalyst Control Center Next Localization CHT.-.Advanced Micro Devices, Inc.) ->
----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{D74218A3-C503-57EF-AC9F-2220082E7ADE}] : (Catalyst Control Center Next Localization DE.-.Advanced Micro Devices, Inc.) ->
----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{DA433FCF-90A1-19A5-65A7-FDF82DE4826D}] : (Catalyst Control Center Next Localization EL.-.Advanced Micro Devices, Inc.) ->
----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{DFAD9DAC-4768-C8BB-4E0E-5239605A9BEA}] : (Catalyst Control Center Next Localization NO.-.Advanced Micro Devices, Inc.) ->
[HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{E0F91FB0-7FC4-11E7-B8E9-95BE57594EAC}] : (VEGAS Pro 15.0.-.VEGAS) -> MsiExec.exe /X{E0F91FB0-7FC4-11E7-B8E9-95BE57594EAC}
----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{E5637EB0-7FC4-11E7-B61D-95BE57594EAC}] : (MSVCRT Redists.-.MAGIX Computer Products Intl. Co.) -> MsiExec.exe /I{E5637EB0-7FC4-11E7-B61D-95BE57594EAC}
----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{E6038D3E-5D87-8DF7-6D05-BE7532C3E73E}] : (Catalyst Control Center Next Localization NL.-.Advanced Micro Devices, Inc.) ->
[HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{E637E0EF-6EB3-44C4-97B8-6F9EA444D649}] : (paint.net.-.dotPDN LLC) -> MsiExec.exe /X{E637E0EF-6EB3-44C4-97B8-6F9EA444D649}
----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{E7AA1A02-575C-14C6-FBEF-4BE6D46A5B74}] : (Catalyst Control Center Next Localization BR.-.Advanced Micro Devices, Inc.) ->
----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{EB6C44F1-0F78-FE10-BC63-90BA50AB0CE9}] : (Catalyst Control Center Next Localization CHS.-.Advanced Micro Devices, Inc.) ->
----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{ED75A775-03A7-F214-868D-497748707968}] : (Catalyst Control Center Next Localization JA.-.Advanced Micro Devices, Inc.) ->
----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{EDF66320-A8A5-967C-1B69-484DAD822143}] : (AMD Software.-.Advanced Micro Devices, Inc.) -> msiexec /q/x{EDF66320-A8A5-967C-1B69-484DAD822143} REBOOT=ReallySuppress
----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{FFBFBD1F-B160-A119-7C43-8584FA2E5665}] : (Catalyst Control Center Next Localization PL.-.Advanced Micro Devices, Inc.) ->
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\1427985242_is1] : (Titan Souls.-.GOG.com) -> "C:\GOG Games\Titan Souls\unins000.exe"
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\AddressBook] : (.-.) ->
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\booktab_is1] : (BooktabZ.-.duDAT) -> "C:\Program Files (x86)\BooktabZ\unins000.exe"
----------[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Connection Manager] : (.-.) ->
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\DirectDrawEx] : (.-.) ->
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\DXM_Runtime] : (.-.) ->
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Fontcore] : (.-.) ->
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\IE40] : (.-.) ->
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\IE4Data] : (.-.) ->
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\IE5BAKEX] : (.-.) ->
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\IEData] : (.-.) ->
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\InstallShield Uninstall Information] : (.-.) ->
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\MobileOptionPack] : (.-.) ->
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\MPlayer2] : (.-.) ->
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\OBS Studio] : (OBS Studio.-.OBS Project) -> C:\Program Files (x86)\obs-studio\uninstall.exe
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\SchedulingAgent] : (.-.) ->
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WIC] : (.-.) ->
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\xampp] : (XAMPP.-.Bitnami) -> "C:\xampp\uninstall.exe"
----------[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{20D4A895-748C-4D88-871C-FDB1695B0169}] : (Platform.-.VIA Technologies, Inc.) ->
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{2D5218EB-6992-46E3-8ECE-76C79AB955CE}] : (LG United Mobile Drivers.-.LG Electronics) -> MsiExec.exe /X{2D5218EB-6992-46E3-8ECE-76C79AB955CE}
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{4A268F17-0301-4E5E-BAD5-97F845F82119}] : (.-.) ->
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{4D0DDB4D-1BF6-40BE-9F27-4F08EC3AAB6E}] : (Smart View.-.Samsung) -> MsiExec.exe /X{4D0DDB4D-1BF6-40BE-9F27-4F08EC3AAB6E}
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{582876EC-A178-44D4-9823-C10D6C62EAFF}] : (.-.) -> MsiExec /X{C5C1C0F0-D62F-4DBF-81D4-D7EF397C228B}
----------[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}] : (Google Update Helper.-.Google LLC) -> MsiExec.exe /I{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{7F1C627F-7F07-4B51-B50F-FF8C64881D6E}] : (Phone Nokia USB Driver.-.Mobile) -> MsiExec.exe /I{7F1C627F-7F07-4B51-B50F-FF8C64881D6E}
----------[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{A79B7C66-DC26-417A-8BB5-B48721B45623}] : (TP-Link PLC Utility.-.TP-Link) -> MsiExec.exe /I{A79B7C66-DC26-417A-8BB5-B48721B45623}
----------[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{AC76BA86-0804-1033-1959-001824311644}] : (Adobe Refresh Manager.-.Adobe Systems Incorporated) -> MsiExec.exe /I{AC76BA86-0804-1033-1959-001824311644}
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{AC76BA86-7AD7-1040-7B44-AC0F074E4100}] : (Adobe Acrobat Reader DC - Italiano.-.Adobe Systems Incorporated) -> MsiExec.exe /I{AC76BA86-7AD7-1040-7B44-AC0F074E4100}
----------[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{C05C6BCE-5E35-9885-11B6-4A743A142B7F}] : (AMD Settings.-.Advanced Micro Devices, Inc.) ->
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{C5C1C0F0-D62F-4DBF-81D4-D7EF397C228B}] : (NVIDIA PhysX.-.NVIDIA Corporation) -> MsiExec.exe /X{C5C1C0F0-D62F-4DBF-81D4-D7EF397C228B}
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{D1026349-BD01-43AA-A851-9757F63F9011}] : (Epic Games Launcher.-.Epic Games, Inc.) -> MsiExec.exe /X{D1026349-BD01-43AA-A851-9757F63F9011}
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{D2FCA41E-AC01-4DCD-B3A7-DC9E32363065}}_is1] : (Rapture3D 2.4.11 Game.-.Blue Ripple Sound) -> "C:\Program Files (x86)\BRS\unins000.exe"

---------- | Ports


---------- | Installer

[HKCR\Installer\Products\005CDE630C4EC1738956805440511C9E] : Catalyst Control Center Next Localization CS -> C:\Windows\Installer\{36EDC500-E4C0-371C-9865-08450415C1E9}\ARPPRODUCTICON.exe
[HKCR\Installer\Products\02366FDE5A8AC769B19684D4DA281234] : AMD Software -> C:\Windows\Installer\{EDF66320-A8A5-967C-1B69-484DAD822143}\ARPPRODUCTICON.exe
[HKCR\Installer\Products\0BE7365E4CF77E116BD159EB7595E4CA] : MSVCRT Redists
[HKCR\Installer\Products\0BF19F0E4CF77E118B9E59EB7595E4CA] : VEGAS Pro 15.0 -> C:\Windows\Installer\{E0F91FB0-7FC4-11E7-B8E9-95BE57594EAC}\vegas.ico
[HKCR\Installer\Products\0F0C1C5CF26DFBD4184D7DFE93C722B8] : NVIDIA PhysX
[HKCR\Installer\Products\10864D02B741DA03C7A5CA54067A0969] : Catalyst Control Center Next Localization FI -> C:\Windows\Installer\{20D46801-147B-30AD-7C5A-AC4560A79096}\ARPPRODUCTICON.exe
[HKCR\Installer\Products\11793C227472462D13A95105EBAEEA6C] : Catalyst Control Center Next Localization FR -> C:\Windows\Installer\{22C39711-2747-D264-319A-1550BEEAAEC6}\ARPPRODUCTICON.exe
[HKCR\Installer\Products\1F44C6BE87F001EFCB3609AB05BAC09E] : Catalyst Control Center Next Localization CHS -> C:\Windows\Installer\{EB6C44F1-0F78-FE10-BC63-90BA50AB0CE9}\ARPPRODUCTICON.exe
[HKCR\Installer\Products\20A1AA7EC5756C41BFFEB46E4DA6B547] : Catalyst Control Center Next Localization BR -> C:\Windows\Installer\{E7AA1A02-575C-14C6-FBEF-4BE6D46A5B74}\ARPPRODUCTICON.exe
[HKCR\Installer\Products\331A6B5086E2007159A0B1D8588BCA8B] : AMD Settings -> C:\Windows\Installer\{05B6A133-2E68-1700-950A-1B8D85B8ACB8}\ARPPRODUCTICON.exe
[HKCR\Installer\Products\3A81247D305CFE75CAF9220280E2A7ED] : Catalyst Control Center Next Localization DE -> C:\Windows\Installer\{D74218A3-C503-57EF-AC9F-2220082E7ADE}\ARPPRODUCTICON.exe
[HKCR\Installer\Products\3F427E579DEA1E344BD5CFC03F9230DD] : Photo Common
[HKCR\Installer\Products\40E10B8B39352094896EE072780FC308] : UpdateAssistant
[HKCR\Installer\Products\577A57DE7A30412F68D8947784079786] : Catalyst Control Center Next Localization JA -> C:\Windows\Installer\{ED75A775-03A7-F214-868D-497748707968}\ARPPRODUCTICON.exe
[HKCR\Installer\Products\598A4D02C84788D478C1DF1B96B51096] : Platform
[HKCR\Installer\Products\66C7B97A62CDA714B85B4B78124B6532] : TP-Link PLC Utility -> C:\Windows\Installer\{A79B7C66-DC26-417A-8BB5-B48721B45623}\ARPPRODUCTICON.exe
[HKCR\Installer\Products\68AB67CA408033019195008142136144] : Adobe Refresh Manager -> C:\Windows\Installer\{AC76BA86-0804-1033-1959-001824311644}\ARPPRODUCTICON.exe
[HKCR\Installer\Products\68AB67CA7DA70401B744CAF070E41400] : Adobe Acrobat Reader DC - Italiano -> C:\Windows\Installer\{AC76BA86-7AD7-1040-7B44-AC0F074E4100}\SC_Reader.ico
[HKCR\Installer\Products\7045D1D496B9224626C958812A06404A] : Catalyst Control Center Next Localization RU -> C:\Windows\Installer\{4D1D5407-9B69-6422-629C-8518A26004A4}\ARPPRODUCTICON.exe
[HKCR\Installer\Products\7BD4C90EC03660F46A13E87A329932FA] : D3DX10
[HKCR\Installer\Products\7EE7F2130D73D4849B47C01E8B65C097] : Movie Maker
[HKCR\Installer\Products\8B57D62B7BAFB8F667F7AB9F5783D319] : Catalyst Control Center Next Localization CHT -> C:\Windows\Installer\{B26D75B8-FAB7-6F8B-767F-BAF975383D91}\ARPPRODUCTICON.exe
[HKCR\Installer\Products\8CDD41E806AE81E43B3E917301D4B5AD] : MSVCRT110
[HKCR\Installer\Products\8DFDDD3824DA9F274E1F4565DF3B409C] : Catalyst Control Center Next Localization TR -> C:\Windows\Installer\{83DDDFD8-AD42-72F9-E4F1-5456FDB304C9}\ARPPRODUCTICON.exe
[HKCR\Installer\Products\9436201D10DBAA348A1579756FF30911] : Epic Games Launcher -> C:\Windows\Installer\{D1026349-BD01-43AA-A851-9757F63F9011}\Installer.ico
[HKCR\Installer\Products\A089CE062ADB6BC44A720BA745894BAC] : Google Update Helper
[HKCR\Installer\Products\A6C64DD86500CEF47BA082BB611A1FF1] : MSVCRT
[HKCR\Installer\Products\A716FD4232DCA6E621B63236D07218EC] : Catalyst Control Center Next Localization TH -> C:\Windows\Installer\{24DF617A-CD23-6E6A-126B-23630D2781CE}\ARPPRODUCTICON.exe
[HKCR\Installer\Products\AECFCA3CF042CCD40A3CDD55EF6E3C2C] : Update for Windows 10 for x64-based Systems (KB4023057)
[HKCR\Installer\Products\B4EB76DD26E75124FA3A1F328A003A98] : Movie Maker
[HKCR\Installer\Products\B521F949CC6AE5A5EE7EA45C30501CAF] : Catalyst Control Center Next Localization ES -> C:\Windows\Installer\{949F125B-A6CC-5A5E-EEE7-4AC50305C1FA}\ARPPRODUCTICON.exe
[HKCR\Installer\Products\BAB9738A9A953A0CB8CC8425AE046329] : Catalyst Control Center Next Localization SV -> C:\Windows\Installer\{A8379BAB-59A9-C0A3-8BCC-4852EA403692}\ARPPRODUCTICON.exe
[HKCR\Installer\Products\BDFCABD134E5288763DB3525D643DB22] : Catalyst Control Center Next Localization HU -> C:\Windows\Installer\{1DBACFDB-5E43-7882-36BD-53526D34BD22}\ARPPRODUCTICON.exe
[HKCR\Installer\Products\BE8125D229963E64E8EC677CA99B55EC] : LG United Mobile Drivers -> C:\Windows\Installer\{2D5218EB-6992-46E3-8ECE-76C79AB955CE}\ARPPRODUCTICON.exe
[HKCR\Installer\Products\C5DBFB7036F28286B1164BA14411F3B3] : Catalyst Control Center Next Localization KO -> C:\Windows\Installer\{07BFBD5C-2F63-6828-1B61-B41A44113F3B}\ARPPRODUCTICON.exe
[HKCR\Installer\Products\CAD9DAFD8674BB8CE4E0259306A5B9AE] : Catalyst Control Center Next Localization NO -> C:\Windows\Installer\{DFAD9DAC-4768-C8BB-4E0E-5239605A9BEA}\ARPPRODUCTICON.exe
[HKCR\Installer\Products\D4BDD0D46FB1EB04F972F480CEA3BAE6] : Smart View -> C:\Windows\Installer\{4D0DDB4D-1BF6-40BE-9F27-4F08EC3AAB6E}\icon.ico
[HKCR\Installer\Products\DAEC1A6874FEBB74EA97ADC8901E3528] : Raccolta foto
[HKCR\Installer\Products\DF7BF2C4DF98C5AB85A583113F62DA43] : Catalyst Control Center Next Localization DA -> C:\Windows\Installer\{4C2FB7FD-89FD-BA5C-585A-3811F326AD34}\ARPPRODUCTICON.exe
[HKCR\Installer\Products\E3D8306E78D57FD8D650EB57233C7EE3] : Catalyst Control Center Next Localization NL -> C:\Windows\Installer\{E6038D3E-5D87-8DF7-6D05-BE7532C3E73E}\ARPPRODUCTICON.exe
[HKCR\Installer\Products\E66BAA708174D2242981A4BFC329A217] : Photo Gallery
[HKCR\Installer\Products\ECB6C50C53E55889116BA447A341B2F7] : AMD Settings -> C:\Windows\Installer\{C05C6BCE-5E35-9885-11B6-4A743A142B7F}\ARPPRODUCTICON.exe
[HKCR\Installer\Products\F187AF9E08E3993428A5DAE3112CC877] : MSVCRT110_amd64
[HKCR\Installer\Products\F1DBFBFF061B911AC7345848AFE26556] : Catalyst Control Center Next Localization PL -> C:\Windows\Installer\{FFBFBD1F-B160-A119-7C43-8584FA2E5665}\ARPPRODUCTICON.exe
[HKCR\Installer\Products\F726C1F770F715B45BF0FFC84688D1E6] : Phone Nokia USB Driver
[HKCR\Installer\Products\F8385C66458B55A4986E6A3178744AFD] : Epic Games Launcher Prerequisites (x64) -> C:\Windows\Installer\{66C5838F-B854-4A55-89E6-A6138747A4DF}\UnrealEngineLauncher.ico
[HKCR\Installer\Products\FB4CF19ACE1CACDA971D4F0F76F1D106] : Catalyst Control Center Next Localization IT -> C:\Windows\Installer\{A91FC4BF-C1EC-ADCA-79D1-F4F0671F1D60}\ARPPRODUCTICON.exe
[HKCR\Installer\Products\FCF334AD1A095A91567ADF8FD24E28D6] : Catalyst Control Center Next Localization EL -> C:\Windows\Installer\{DA433FCF-90A1-19A5-65A7-FDF82DE4826D}\ARPPRODUCTICON.exe
[HKCR\Installer\Products\FE0E736E3BE64C44798BF6E94A446D94] : paint.net -> C:\Windows\Installer\{E637E0EF-6EB3-44C4-97B8-6F9EA444D649}\_853F67D554F05449430E7E.exe

---------- | Drives


---------- | MBR


64 bits not supported by MBR.exe, Dump : C:\QuickDiag\MBR.Bin

---------- | 20 LastEventLog

Nome dell'applicazione che ha generato l'errore: Shogun2.exe, versione: 1.1.0.0, timestamp: 0x507716b8
Nome del modulo che ha generato l'errore: Shogun2.dll, versione: 1.0.0.0, timestamp: 0x515eb206
Codice eccezione: 0xc0000005
Offset errore 0x010bc600
ID processo che ha generato l'errore: 0x610
Ora di avvio dell'applicazione che ha generato l'errore: 0x01d539b049dc3a83
Percorso dell'applicazione che ha generato l'errore: D:\Steam\steamapps\common\Total War SHOGUN 2\Shogun2.exe
Percorso del modulo che ha generato l'errore: D:\Steam\steamapps\common\Total War SHOGUN 2\Shogun2.dll
ID segnalazione: 182b54c3-90da-4dc9-9493-0745f9dabc58
Nome completo pacchetto che ha generato l'errore:
ID applicazione relativo al pacchetto che ha generato l'errore:
------------

Nome dell'applicazione che ha generato l'errore: Shogun2.exe, versione: 1.1.0.0, timestamp: 0x507716b8
Nome del modulo che ha generato l'errore: Shogun2.dll, versione: 1.0.0.0, timestamp: 0x515eb206
Codice eccezione: 0xc0000005
Offset errore 0x010bc600
ID processo che ha generato l'errore: 0x610
Ora di avvio dell'applicazione che ha generato l'errore: 0x01d539b049dc3a83
Percorso dell'applicazione che ha generato l'errore: D:\Steam\steamapps\common\Total War SHOGUN 2\Shogun2.exe
Percorso del modulo che ha generato l'errore: D:\Steam\steamapps\common\Total War SHOGUN 2\Shogun2.dll
ID segnalazione: ecd8a7e7-56ed-4546-87fa-96d75c1b67e8
Nome completo pacchetto che ha generato l'errore:
ID applicazione relativo al pacchetto che ha generato l'errore:
------------

La procedura Open per il servizio "BITS" nella DLL "C:\Windows\System32\bitsperf.dll" non è riuscita. I dati delle prestazioni per questo servizio non saranno disponibili. I primi quattro byte (DWORD) della sezione Data contengono il codice di errore.
------------

Generazione del contesto di attivazione non riuscita per "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe". Errore nel file manifesto o dei criteri "", alla riga . Una versione del componente richiesta dall'applicazione è in conflitto con un'altra versione del componente già attiva. Componenti in conflitto:. Componente 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.15063.1155_none_8874c8f83e239b31.manifest. Componente 2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.15063.1155_none_40c7922129a7722b.manifest.
------------

Nome dell'applicazione che ha generato l'errore: MicrosoftEdgeCP.exe, versione: 11.0.15063.674, timestamp: 0x59cdf479
Nome del modulo che ha generato l'errore: ntdll.dll, versione: 10.0.15063.1324, timestamp: 0x28af0ac0
Codice eccezione: 0xcfffffff
Offset errore 0x00000000000a5e54
ID processo che ha generato l'errore: 0x2278
Ora di avvio dell'applicazione che ha generato l'errore: 0x01d539546ea6a54d
Percorso dell'applicazione che ha generato l'errore: C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
Percorso del modulo che ha generato l'errore: C:\Windows\SYSTEM32\ntdll.dll
ID segnalazione: 61f30932-bcb8-4dbf-9bbe-c8a678183eae
Nome completo pacchetto che ha generato l'errore: Microsoft.MicrosoftEdge_40.15063.674.0_neutral__8wekyb3d8bbwe
ID applicazione relativo al pacchetto che ha generato l'errore: ContentProcess
------------

Impossibile trovare il profilo locale. Per l'accesso sarà utilizzato un profilo temporaneo. I cambiamenti apportati al profilo andranno persi dopo la disconnessione.
------------

È stato effettuato il backup del profilo utente. Al prossimo accesso dell'utente Windows tenterà di utilizzare automaticamente il profilo di backup.
------------

Impossibile caricare il profilo archiviato nel computer locale. L'errore può essere dovuto a diritti di sicurezza insufficienti o a un profilo locale danneggiato.

DETTAGLI - Impossibile accedere al file. Il file è utilizzato da un altro processo.

------------

Impossibile caricare il Registro di sistema. Questo problema è spesso dovuto a memoria insufficiente o a diritti di sicurezza insufficienti.

DETTAGLI - Impossibile accedere al file. Il file è utilizzato da un altro processo.
per C:\Users\Luca\ntuser.dat
------------

La procedura Open per il servizio "BITS" nella DLL "C:\Windows\System32\bitsperf.dll" non è riuscita. I dati delle prestazioni per questo servizio non saranno disponibili. I primi quattro byte (DWORD) della sezione Data contengono il codice di errore.
------------

La procedura Open per il servizio "BITS" nella DLL "C:\Windows\System32\bitsperf.dll" non è riuscita. I dati delle prestazioni per questo servizio non saranno disponibili. I primi quattro byte (DWORD) della sezione Data contengono il codice di errore.
------------

qmgr.dll (7876) QmgrDatabaseInstance: Il motore di database ha interrotto l'istanza (0) con l'errore (-1090)).

Sequenza temporale interna:
[1] 0.000006 +J(0)
[2] 0.000031 +J(0) +M(C:0K, Fs:1, WS:4K # 0K, PF:0K # 0K, P:0K)
[3] 0.000003 +J(0)
[4] 0.000007 +J(0)
[5] 0.0 +J(0)
[6] 0.000071 +J(0) +M(C:0K, Fs:2, WS:-24K # 0K, PF:-32K # 0K, P:-32K)
[7] -
[8] 0.000010 +J(0) +M(C:0K, Fs:1, WS:4K # 0K, PF:0K # 0K, P:0K)
[9] 0.002703 +J(0) +M(C:0K, Fs:4, WS:-32K # 0K, PF:-40K # 0K, P:-40K)
[10] -
[11] 0.000015 +J(0) +M(C:0K, Fs:1, WS:4K # 0K, PF:0K # 0K, P:0K)
[12] -
[13] 0.000042 +J(0) +M(C:0K, Fs:0, WS:-4K # 0K, PF:-4K # 0K, P:-4K)
[14] 0.000675 +J(0) +M(C:0K, Fs:0, WS:-8K # 0K, PF:-8K # 0K, P:-8K)
[15] 0.000022 +J(0) +M(C:0K, Fs:0, WS:-8K # 0K, PF:-12K # 0K, P:-12K)
[16] 0.000004 +J(0).
------------

qmgr.dll (7876) QmgrDatabaseInstance: Non è possibile ripristinare l'operazione n.-75 sul database C:\ProgramData\Microsoft\Network\Downloader\qmgr.db. Errore: -510. Tutti i futuri aggiornamenti del database saranno rifiutati.
------------

qmgr.dll (7876) QmgrDatabaseInstance: La sequenza del file di log in "C:\ProgramData\Microsoft\Network\Downloader\" è stata interrotta a causa di un errore irreversibile.  Non sarà possibile effettuare ulteriori aggiornamenti per i database che usano questa sequenza del file di log. Risolvere il problema e riavviare o effettuare un ripristino da backup.
------------

qmgr.dll (7876) QmgrDatabaseInstance: Non è possibile creare un nuovo file di log. Il database non è in grado di scrivere sull'unità del log. È possibile che l'unità sia di sola lettura, sia configurata in modo errato o danneggiata oppure che lo spazio su disco non sia sufficiente. Errore -1032.
------------

qmgr.dll (7876) QmgrDatabaseInstance: Un tentativo di creazione del file "C:\ProgramData\Microsoft\Network\Downloader\edbtmp.log" non è riuscito con l'errore di sistema 80 (0x00000050): "File esistente. ".  L'operazione di creazione del file non verrà eseguita con l'errore -1814 (0xfffff8ea).
------------

La procedura Open per il servizio "BITS" nella DLL "C:\Windows\System32\bitsperf.dll" non è riuscita. I dati delle prestazioni per questo servizio non saranno disponibili. I primi quattro byte (DWORD) della sezione Data contengono il codice di errore.
------------

Nome dell'applicazione che ha generato l'errore: Shogun2.exe, versione: 1.1.0.0, timestamp: 0x507716b8
Nome del modulo che ha generato l'errore: Shogun2.dll, versione: 1.0.0.0, timestamp: 0x515eb206
Codice eccezione: 0xc0000005
Offset errore 0x010270ba
ID processo che ha generato l'errore: 0x157c
Ora di avvio dell'applicazione che ha generato l'errore: 0x01d5362a8361c3c9
Percorso dell'applicazione che ha generato l'errore: D:\Steam\steamapps\common\Total War SHOGUN 2\Shogun2.exe
Percorso del modulo che ha generato l'errore: D:\Steam\steamapps\common\Total War SHOGUN 2\Shogun2.dll
ID segnalazione: 0125efc0-2744-4f5b-b079-3b1aa2695a32
Nome completo pacchetto che ha generato l'errore:
ID applicazione relativo al pacchetto che ha generato l'errore:
------------

Nome dell'applicazione che ha generato l'errore: Shogun2.exe, versione: 1.1.0.0, timestamp: 0x507716b8
Nome del modulo che ha generato l'errore: Shogun2.dll, versione: 1.0.0.0, timestamp: 0x515eb206
Codice eccezione: 0xc0000005
Offset errore 0x010270ba
ID processo che ha generato l'errore: 0x157c
Ora di avvio dell'applicazione che ha generato l'errore: 0x01d5362a8361c3c9
Percorso dell'applicazione che ha generato l'errore: D:\Steam\steamapps\common\Total War SHOGUN 2\Shogun2.exe
Percorso del modulo che ha generato l'errore: D:\Steam\steamapps\common\Total War SHOGUN 2\Shogun2.dll
ID segnalazione: 24862e85-0386-4164-a51a-9ac02b0145be
Nome completo pacchetto che ha generato l'errore:
ID applicazione relativo al pacchetto che ha generato l'errore:
------------


----------( EOF)---------- - 5402 | 10:15:06
 
Last edited by a moderator:
Status
Not open for further replies.