C'est bon, j'ai trouvé les fichiers du centre de sécurité ("gdiplace.dll";"wscui.cpl" ainsi que "rundll32.exe")
Et voilà les clé qu'ils on chargé lorsque j'ai lancé le centre de securité(je devrait bientôt lister les fichiers qu'il ont chargé):
1 23:54:22 explorer.exe:856 QueryValue HKCR\cplfile\shell\cplopen\command\(Default) SUCCESS "rundll32.exe shell32.dll,Control_RunDLL "%1",%*"
2 23:54:22 explorer.exe:856 QueryValue HKCR\cplfile\shell\cplopen\command\(Default) SUCCESS "rundll32.exe shell32.dll,Control_RunDLL "%1",%*"
3 23:54:22 explorer.exe:856 QueryValue HKCR\cplfile\shell\cplopen\command\(Default) SUCCESS "rundll32.exe shell32.dll,Control_RunDLL "%1",%*"
4 23:54:22 explorer.exe:856 QueryValue HKCR\cplfile\shell\cplopen\command\(Default) SUCCESS "rundll32.exe shell32.dll,Control_RunDLL "%1",%*"
5 23:54:22 rundll32.exe:3472 QueryValue HKLM\System\CurrentControlSet\Control\Terminal Server\TSAppCompat SUCCESS 0x0
6 23:54:22 rundll32.exe:3472 QueryValue HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\TransparentEnabled SUCCESS 0x1
7 23:54:22 rundll32.exe:3472 QueryValue HKLM\SYSTEM\WPA\MediaCenter\Installed SUCCESS 0x0
8 23:54:22 rundll32.exe:3472 QueryValue HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs SUCCESS "C:\PROGRA~1\KASPER~1\KASPER~2.0\adialhk.dll"
9 23:54:22 rundll32.exe:3472 QueryValue HKLM\Software\Microsoft\Windows NT\CurrentVersion\DRIVERS32\wave SUCCESS "wdmaud.drv"
10 23:54:22 rundll32.exe:3472 QueryValue HKLM\Software\Microsoft\Windows NT\CurrentVersion\DRIVERS32\wave SUCCESS "wdmaud.drv"
11 23:54:22 rundll32.exe:3472 QueryValue HKLM\Software\Microsoft\Windows NT\CurrentVersion\DRIVERS32\midi SUCCESS "wdmaud.drv"
12 23:54:22 rundll32.exe:3472 QueryValue HKLM\Software\Microsoft\Windows NT\CurrentVersion\DRIVERS32\midi SUCCESS "wdmaud.drv"
13 23:54:22 rundll32.exe:3472 QueryValue HKLM\System\CurrentControlSet\Control\MediaProperties\PrivateProperties\Joystick\Winmm\wheel SUCCESS 0x1
14 23:54:22 rundll32.exe:3472 QueryValue HKLM\Software\Microsoft\Windows NT\CurrentVersion\DRIVERS32\mixer SUCCESS "wdmaud.drv"
15 23:54:22 rundll32.exe:3472 QueryValue HKLM\Software\Microsoft\Windows NT\CurrentVersion\DRIVERS32\mixer SUCCESS "wdmaud.drv"
16 23:54:22 rundll32.exe:3472 QueryValue HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\CriticalSectionTimeout SUCCESS 0x278D00
17 23:54:22 rundll32.exe:3472 QueryValue HKCU\Software\Microsoft\Multimedia\Audio\SystemFormats SUCCESS "Qualité CD,Qualité radio,Qualité téléphonique"
18 23:54:22 rundll32.exe:3472 EnumerateValue HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32\midimapper SUCCESS Type: SZ Name: midimapper
19 23:54:22 rundll32.exe:3472 EnumerateValue HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32\msacm.imaadpcm SUCCESS Type: SZ Name: msacm.imaadpcm
20 23:54:22 rundll32.exe:3472 EnumerateValue HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32\msacm.msadpcm SUCCESS Type: SZ Name: msacm.msadpcm
21 23:54:22 rundll32.exe:3472 EnumerateValue HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32\msacm.msg711 SUCCESS Type: SZ Name: msacm.msg711
22 23:54:22 rundll32.exe:3472 EnumerateValue HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32\msacm.msgsm610 SUCCESS Type: SZ Name: msacm.msgsm610
23 23:54:22 rundll32.exe:3472 EnumerateValue HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32\msacm.trspch SUCCESS Type: SZ Name: msacm.trspch
24 23:54:22 rundll32.exe:3472 EnumerateValue HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32\vidc.cvid SUCCESS Type: SZ Name: vidc.cvid
25 23:54:22 rundll32.exe:3472 EnumerateValue HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32\vidc.I420 SUCCESS Type: SZ Name: vidc.I420
26 23:54:22 rundll32.exe:3472 EnumerateValue HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32\vidc.iv31 SUCCESS Type: SZ Name: vidc.iv31
27 23:54:22 rundll32.exe:3472 EnumerateValue HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32\vidc.iv32 SUCCESS Type: SZ Name: vidc.iv32
28 23:54:22 rundll32.exe:3472 EnumerateValue HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32\vidc.iv41 SUCCESS Type: SZ Name: vidc.iv41
29 23:54:22 rundll32.exe:3472 EnumerateValue HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32\vidc.iyuv SUCCESS Type: SZ Name: vidc.iyuv
30 23:54:22 rundll32.exe:3472 EnumerateValue HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32\vidc.mrle SUCCESS Type: SZ Name: vidc.mrle
31 23:54:22 rundll32.exe:3472 EnumerateValue HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32\vidc.msvc SUCCESS Type: SZ Name: vidc.msvc
32 23:54:22 rundll32.exe:3472 EnumerateValue HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32\vidc.uyvy SUCCESS Type: SZ Name: vidc.uyvy
33 23:54:22 rundll32.exe:3472 EnumerateValue HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32\vidc.yuy2 SUCCESS Type: SZ Name: vidc.yuy2
34 23:54:22 rundll32.exe:3472 EnumerateValue HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32\vidc.yvu9 SUCCESS Type: SZ Name: vidc.yvu9
35 23:54:22 rundll32.exe:3472 EnumerateValue HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32\vidc.yvyu SUCCESS Type: SZ Name: vidc.yvyu
36 23:54:22 rundll32.exe:3472 EnumerateValue HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32\wavemapper SUCCESS Type: SZ Name: wavemapper
37 23:54:22 rundll32.exe:3472 EnumerateValue HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32\msacm.msg723 SUCCESS Type: SZ Name: msacm.msg723
38 23:54:22 rundll32.exe:3472 EnumerateValue HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32\vidc.M263 SUCCESS Type: SZ Name: vidc.M263
39 23:54:22 rundll32.exe:3472 EnumerateValue HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32\vidc.M261 SUCCESS Type: SZ Name: vidc.M261
40 23:54:22 rundll32.exe:3472 EnumerateValue HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32\msacm.msaudio1 SUCCESS Type: SZ Name: msacm.msaudio1
41 23:54:22 rundll32.exe:3472 EnumerateValue HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\midimapper SUCCESS Type: SZ Name: midimapper
42 23:54:22 rundll32.exe:3472 EnumerateValue HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\msacm.imaadpcm SUCCESS Type: SZ Name: msacm.imaadpcm
43 23:54:22 rundll32.exe:3472 EnumerateValue HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\msacm.msadpcm SUCCESS Type: SZ Name: msacm.msadpcm
44 23:54:22 rundll32.exe:3472 EnumerateValue HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\msacm.msg711 SUCCESS Type: SZ Name: msacm.msg711
45 23:54:22 rundll32.exe:3472 EnumerateValue HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\msacm.msgsm610 SUCCESS Type: SZ Name: msacm.msgsm610
46 23:54:22 rundll32.exe:3472 EnumerateValue HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\msacm.trspch SUCCESS Type: SZ Name: msacm.trspch
47 23:54:22 rundll32.exe:3472 EnumerateValue HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\vidc.cvid SUCCESS Type: SZ Name: vidc.cvid
48 23:54:22 rundll32.exe:3472 EnumerateValue HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\vidc.I420 SUCCESS Type: SZ Name: vidc.I420
49 23:54:22 rundll32.exe:3472 EnumerateValue HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\vidc.iv31 SUCCESS Type: SZ Name: vidc.iv31
50 23:54:22 rundll32.exe:3472 EnumerateValue HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\vidc.iv32 SUCCESS Type: SZ Name: vidc.iv32
51 23:54:22 rundll32.exe:3472 EnumerateValue HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\vidc.iv41 SUCCESS Type: SZ Name: vidc.iv41
52 23:54:22 rundll32.exe:3472 EnumerateValue HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\vidc.iyuv SUCCESS Type: SZ Name: vidc.iyuv
53 23:54:22 rundll32.exe:3472 EnumerateValue HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\vidc.mrle SUCCESS Type: SZ Name: vidc.mrle
54 23:54:22 rundll32.exe:3472 EnumerateValue HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\vidc.msvc SUCCESS Type: SZ Name: vidc.msvc
55 23:54:22 rundll32.exe:3472 EnumerateValue HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\vidc.uyvy SUCCESS Type: SZ Name: vidc.uyvy
56 23:54:22 rundll32.exe:3472 EnumerateValue HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\vidc.yuy2 SUCCESS Type: SZ Name: vidc.yuy2
57 23:54:22 rundll32.exe:3472 EnumerateValue HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\vidc.yvu9 SUCCESS Type: SZ Name: vidc.yvu9
58 23:54:22 rundll32.exe:3472 EnumerateValue HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\vidc.yvyu SUCCESS Type: SZ Name: vidc.yvyu
59 23:54:22 rundll32.exe:3472 EnumerateValue HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\wavemapper SUCCESS Type: SZ Name: wavemapper
60 23:54:22 rundll32.exe:3472 EnumerateValue HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\msacm.msg723 SUCCESS Type: SZ Name: msacm.msg723
61 23:54:22 rundll32.exe:3472 EnumerateValue HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\vidc.M263 SUCCESS Type: SZ Name: vidc.M263
62 23:54:22 rundll32.exe:3472 EnumerateValue HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\vidc.M261 SUCCESS Type: SZ Name: vidc.M261
63 23:54:22 rundll32.exe:3472 EnumerateValue HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\msacm.msaudio1 SUCCESS Type: SZ Name: msacm.msaudio1
64 23:54:22 rundll32.exe:3472 EnumerateValue HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\msacm.sl_anet SUCCESS Type: SZ Name: msacm.sl_anet
65 23:54:22 rundll32.exe:3472 EnumerateValue HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\msacm.iac2 SUCCESS Type: SZ Name: msacm.iac2
66 23:54:22 rundll32.exe:3472 EnumerateValue HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\vidc.iv50 SUCCESS Type: SZ Name: vidc.iv50
67 23:54:22 rundll32.exe:3472 EnumerateValue HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\msacm.l3acm SUCCESS Type: SZ Name: msacm.l3acm
68 23:54:22 rundll32.exe:3472 EnumerateValue HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\vidc.DIVX SUCCESS Type: SZ Name: vidc.DIVX
69 23:54:22 rundll32.exe:3472 EnumerateValue HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\vidc.yv12 SUCCESS Type: SZ Name: vidc.yv12
70 23:54:22 rundll32.exe:3472 EnumerateValue HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\msacm.siren SUCCESS Type: SZ Name: msacm.siren
71 23:54:22 rundll32.exe:3472 EnumerateValue HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\wave SUCCESS Type: SZ Name: wave
72 23:54:22 rundll32.exe:3472 EnumerateValue HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\midi SUCCESS Type: SZ Name: midi
73 23:54:22 rundll32.exe:3472 EnumerateValue HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\mixer SUCCESS Type: SZ Name: mixer
74 23:54:22 rundll32.exe:3472 QueryValue HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\msacm.imaadpcm SUCCESS "imaadp32.acm"
75 23:54:22 rundll32.exe:3472 QueryValue HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.imaadpcm\fdwSupport SUCCESS 0x1
76 23:54:22 rundll32.exe:3472 QueryValue HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.imaadpcm\cFormatTags SUCCESS 0x2
77 23:54:22 rundll32.exe:3472 QueryValue HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.imaadpcm\aFormatTagCache SUCCESS 01 00 00 00 10 00 00 00 ...
78 23:54:22 rundll32.exe:3472 QueryValue HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.imaadpcm\cFilterTags SUCCESS 0x0
79 23:54:22 rundll32.exe:3472 QueryValue HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\msacm.msadpcm SUCCESS "msadp32.acm"
80 23:54:22 rundll32.exe:3472 QueryValue HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msadpcm\fdwSupport SUCCESS 0x1
81 23:54:22 rundll32.exe:3472 QueryValue HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msadpcm\cFormatTags SUCCESS 0x2
82 23:54:22 rundll32.exe:3472 QueryValue HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msadpcm\aFormatTagCache SUCCESS 01 00 00 00 10 00 00 00 ...
83 23:54:22 rundll32.exe:3472 QueryValue HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msadpcm\cFilterTags SUCCESS 0x0
84 23:54:22 rundll32.exe:3472 QueryValue HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\msacm.msg711 SUCCESS "msg711.acm"
85 23:54:22 rundll32.exe:3472 QueryValue HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msg711\fdwSupport SUCCESS 0x1
86 23:54:22 rundll32.exe:3472 QueryValue HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msg711\cFormatTags SUCCESS 0x3
87 23:54:22 rundll32.exe:3472 QueryValue HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msg711\aFormatTagCache SUCCESS 01 00 00 00 10 00 00 00 ...
88 23:54:22 rundll32.exe:3472 QueryValue HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msg711\cFilterTags SUCCESS 0x0
89 23:54:22 rundll32.exe:3472 QueryValue HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\msacm.msgsm610 SUCCESS "msgsm32.acm"
90 23:54:22 rundll32.exe:3472 QueryValue HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msgsm610\fdwSupport SUCCESS 0x1
91 23:54:22 rundll32.exe:3472 QueryValue HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msgsm610\cFormatTags SUCCESS 0x2
92 23:54:22 rundll32.exe:3472 QueryValue HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msgsm610\aFormatTagCache SUCCESS 01 00 00 00 10 00 00 00 ...
93 23:54:22 rundll32.exe:3472 QueryValue HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msgsm610\cFilterTags SUCCESS 0x0
94 23:54:22 rundll32.exe:3472 QueryValue HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\msacm.trspch SUCCESS "tssoft32.acm"
95 23:54:22 rundll32.exe:3472 QueryValue HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.trspch\fdwSupport SUCCESS 0x1
96 23:54:22 rundll32.exe:3472 QueryValue HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.trspch\cFormatTags SUCCESS 0x2
97 23:54:22 rundll32.exe:3472 QueryValue HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.trspch\aFormatTagCache SUCCESS 01 00 00 00 10 00 00 00 ...
98 23:54:22 rundll32.exe:3472 QueryValue HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.trspch\cFilterTags SUCCESS 0x0
99 23:54:22 rundll32.exe:3472 QueryValue HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\msacm.msg723 SUCCESS "msg723.acm"
100 23:54:22 rundll32.exe:3472 QueryValue HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msg723\fdwSupport SUCCESS 0x1
101 23:54:22 rundll32.exe:3472 QueryValue HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msg723\cFormatTags SUCCESS 0x2
102 23:54:22 rundll32.exe:3472 QueryValue HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msg723\aFormatTagCache SUCCESS 01 00 00 00 10 00 00 00 ...
103 23:54:22 rundll32.exe:3472 QueryValue HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msg723\cFilterTags SUCCESS 0x0
104 23:54:22 rundll32.exe:3472 QueryValue HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\msacm.msaudio1 SUCCESS "msaud32.acm"
105 23:54:22 rundll32.exe:3472 QueryValue HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msaudio1\fdwSupport SUCCESS 0x1
106 23:54:22 rundll32.exe:3472 QueryValue HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msaudio1\cFormatTags SUCCESS 0x3
107 23:54:22 rundll32.exe:3472 QueryValue HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msaudio1\aFormatTagCache SUCCESS 01 00 00 00 12 00 00 00 ...
108 23:54:22 rundll32.exe:3472 QueryValue HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msaudio1\cFilterTags SUCCESS 0x0
109 23:54:22 rundll32.exe:3472 QueryValue HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\msacm.sl_anet SUCCESS "sl_anet.acm"
110 23:54:22 rundll32.exe:3472 QueryValue HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.sl_anet\fdwSupport SUCCESS 0x1
111 23:54:22 rundll32.exe:3472 QueryValue HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.sl_anet\cFormatTags SUCCESS 0x2
112 23:54:22 rundll32.exe:3472 QueryValue HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.sl_anet\aFormatTagCache SUCCESS 01 00 00 00 10 00 00 00 ...
113 23:54:22 rundll32.exe:3472 QueryValue HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.sl_anet\cFilterTags SUCCESS 0x0
114 23:54:22 rundll32.exe:3472 QueryValue HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\msacm.iac2 SUCCESS "C:\WINDOWS\system32\iac25_32.ax"
115 23:54:22 rundll32.exe:3472 QueryValue HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.iac2\fdwSupport SUCCESS 0x1
116 23:54:22 rundll32.exe:3472 QueryValue HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.iac2\cFormatTags SUCCESS 0x2
117 23:54:22 rundll32.exe:3472 QueryValue HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.iac2\aFormatTagCache SUCCESS 01 00 00 00 10 00 00 00 ...
118 23:54:22 rundll32.exe:3472 QueryValue HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.iac2\cFilterTags SUCCESS 0x0
119 23:54:22 rundll32.exe:3472 QueryValue HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\msacm.l3acm SUCCESS "C:\WINDOWS\system32\l3codeca.acm"
120 23:54:22 rundll32.exe:3472 QueryValue HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.l3acm\fdwSupport SUCCESS 0x1
121 23:54:22 rundll32.exe:3472 QueryValue HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.l3acm\cFormatTags SUCCESS 0x2
122 23:54:22 rundll32.exe:3472 QueryValue HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.l3acm\aFormatTagCache SUCCESS 01 00 00 00 10 00 00 00 ...
123 23:54:22 rundll32.exe:3472 QueryValue HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.l3acm\cFilterTags SUCCESS 0x0
124 23:54:22 rundll32.exe:3472 QueryValue HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\msacm.siren SUCCESS "sirenacm.dll"
125 23:54:22 rundll32.exe:3472 QueryValue HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.siren\fdwSupport SUCCESS 0x1
126 23:54:22 rundll32.exe:3472 QueryValue HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.siren\cFormatTags SUCCESS 0x2
127 23:54:22 rundll32.exe:3472 QueryValue HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.siren\aFormatTagCache SUCCESS 01 00 00 00 10 00 00 00 ...
128 23:54:22 rundll32.exe:3472 QueryValue HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.siren\cFilterTags SUCCESS 0x0
129 23:54:22 rundll32.exe:3472 QueryValue HKLM\SYSTEM\Setup\SystemSetupInProgress SUCCESS 0x0
130 23:54:22 rundll32.exe:3472 QueryValue HKCU\Control Panel\Desktop\SmoothScroll SUCCESS 0x1
131 23:54:22 rundll32.exe:3472 EnumerateValue HKLM\Software\Microsoft\Windows NT\CurrentVersion\LanguagePack\THAI SUCCESS 0x1
132 23:54:22 rundll32.exe:3472 EnumerateValue HKLM\Software\Microsoft\Windows NT\CurrentVersion\LanguagePack\HEBREW SUCCESS 0x0
133 23:54:22 rundll32.exe:3472 EnumerateValue HKLM\Software\Microsoft\Windows NT\CurrentVersion\LanguagePack\ARABIC SUCCESS 0x0
134 23:54:22 rundll32.exe:3472 EnumerateValue HKLM\Software\Microsoft\Windows NT\CurrentVersion\LanguagePack\VIETNAMESE SUCCESS 0x3
135 23:54:22 rundll32.exe:3472 EnumerateValue HKLM\Software\Microsoft\Windows NT\CurrentVersion\LanguagePack\INDIAN SUCCESS 0x4
136 23:54:22 rundll32.exe:3472 EnumerateValue HKLM\Software\Microsoft\Windows NT\CurrentVersion\LanguagePack\SURROGATE SUCCESS 0x2
137 23:54:22 rundll32.exe:3472 QueryValue HKCU\Control Panel\Desktop\SmoothScroll SUCCESS 0x1
138 23:54:22 rundll32.exe:3472 QueryValue HKLM\System\CurrentControlSet\Control\ProductOptions\ProductType SUCCESS "WinNT"
139 23:54:22 rundll32.exe:3472 QueryValue HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Personal SUCCESS "%USERPROFILE%\Mes documents"
140 23:54:22 rundll32.exe:3472 QueryValue HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local Settings SUCCESS "%USERPROFILE%\Local Settings"
141 23:54:22 rundll32.exe:3472 QueryValue HKLM\System\CurrentControlSet\Control\ComputerName\ActiveComputerName\ComputerName SUCCESS "GANIBARD-A3F22B"
142 23:54:23 rundll32.exe:3472 QueryValue HKLM\System\CurrentControlSet\Services\LDAP\LdapClientIntegrity SUCCESS 0x1
143 23:54:23 rundll32.exe:3472 QueryValue HKLM\SOFTWARE\Microsoft\CTF\SystemShared\CUAS SUCCESS 0x0
144 23:54:23 rundll32.exe:3472 QueryValue HKCU\Keyboard Layout\Toggle\Language Hotkey SUCCESS "1"
145 23:54:23 rundll32.exe:3472 QueryValue HKCU\Keyboard Layout\Toggle\Language Hotkey SUCCESS "1"
146 23:54:23 rundll32.exe:3472 QueryValue HKCU\Keyboard Layout\Toggle\Layout Hotkey SUCCESS "2"
147 23:54:23 rundll32.exe:3472 QueryValue HKCU\Keyboard Layout\Toggle\Layout Hotkey SUCCESS "2"
148 23:54:23 rundll32.exe:3472 QueryValue HKLM\Software\Microsoft\Windows NT\CurrentVersion\IMM\Ime File SUCCESS "msctfime.ime"
149 23:54:23 rundll32.exe:3472 QueryValue HKLM\Software\Microsoft\CTF\SystemShared\CUAS SUCCESS 0x0
150 23:54:23 rundll32.exe:3472 QueryValue HKLM\SYSTEM\WPA\MediaCenter\Installed SUCCESS 0x0
151 23:54:23 rundll32.exe:3472 QueryValue HKLM\Hardware\DeviceMap\VIDEO\MaxObjectNumber SUCCESS 0x3
152 23:54:23 rundll32.exe:3472 QueryValue HKLM\SYSTEM\CURRENTCONTROLSET\ENUM\PCI\VEN_10DE&DEV_0185&SUBSYS_20181682&REV_C1\4&1affaa3d&0&0008\HardwareID SUCCESS "PCI\VEN_10DE&DEV_0185&SUBSYS_20181682&REV_C1"
153 23:54:23 rundll32.exe:3472 QueryValue HKLM\SYSTEM\CURRENTCONTROLSET\ENUM\PCI\VEN_10DE&DEV_0185&SUBSYS_20181682&REV_C1\4&1affaa3d&0&0008\HardwareID SUCCESS "PCI\VEN_10DE&DEV_0185&SUBSYS_20181682&REV_C1"
154 23:54:23 rundll32.exe:3472 QueryValue HKLM\Hardware\DeviceMap\Video\\Device\Video0 SUCCESS "\Registry\Machine\System\CurrentControlSet\Control\Video\{CDC5B952-8FD8-4BBA-9A32-444F483AE1D8}\0000"
155 23:54:23 rundll32.exe:2748 QueryKey HKCU\Software\Classes SUCCESS Name: \REGISTRY\USER\S-1-5-21-1757981266-1390067357-725345543-1003_CLASSES
156 23:54:23 rundll32.exe:2748 QueryKey HKCR\CLSID\{1CDB2949-8F65-4355-8456-263E7C208A5D} SUCCESS Name: \REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{1CDB2949-8F65-4355-8456-263E7C208A5D}
157 23:54:23 rundll32.exe:3472 QueryValue HKLM\Software\Microsoft\CTF\SystemShared\CUAS SUCCESS 0x0
158 23:54:23 rundll32.exe:3472 QueryKey HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts SUCCESS Subkeys = 0
159 23:54:23 rundll32.exe:3472 QueryValue HKCU\Software\Microsoft\GDIPlus\FontCachePath SUCCESS "C:\Documents and Settings\GANIBARDI\Local Settings\Application Data"
160 23:54:23 rundll32.exe:2748 QueryKey HKCU\Software\Classes SUCCESS Name: \REGISTRY\USER\S-1-5-21-1757981266-1390067357-725345543-1003_CLASSES
161 23:54:23 rundll32.exe:2748 QueryKey HKCR\CLSID\{1CDB2949-8F65-4355-8456-263E7C208A5D} SUCCESS Name: \REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{1CDB2949-8F65-4355-8456-263E7C208A5D}
162 23:54:23 rundll32.exe:2748 QueryKey HKCU\Software\Classes SUCCESS Name: \REGISTRY\USER\S-1-5-21-1757981266-1390067357-725345543-1003_CLASSES
163 23:54:23 rundll32.exe:2748 QueryKey HKCR\CLSID\{1CDB2949-8F65-4355-8456-263E7C208A5D}\InProcServer32 SUCCESS Name: \REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{1CDB2949-8F65-4355-8456-263E7C208A5D}\InprocServer32
164 23:54:23 rundll32.exe:2748 QueryValue HKCR\CLSID\{1CDB2949-8F65-4355-8456-263E7C208A5D}\InProcServer32\(Default) SUCCESS "C:\WINDOWS\system32\nvshell.dll"
165 23:54:23 rundll32.exe:2748 QueryKey HKCR\CLSID\{1CDB2949-8F65-4355-8456-263E7C208A5D}\InProcServer32 SUCCESS Name: \REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{1CDB2949-8F65-4355-8456-263E7C208A5D}\InprocServer32
166 23:54:23 rundll32.exe:2748 QueryValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached\{1CDB2949-8F65-4355-8456-263E7C208A5D} {000214E6-0000-0000-C000-000000000046} 0x401 SUCCESS 0x1
167 23:54:23 rundll32.exe:2748 QueryValue HKCR\CLSID\{1cdb2949-8f65-4355-8456-263e7c208a5d}\InProcServer32\(Default) SUCCESS "C:\WINDOWS\system32\nvshell.dll"
168 23:54:23 rundll32.exe:2748 QueryValue HKLM\Software\Microsoft\COM3\REGDBVersion SUCCESS 1C 00 00 00 00 00 00 00
169 23:54:23 rundll32.exe:2748 QueryValue HKLM\Software\Microsoft\COM3\REGDBVersion SUCCESS 1C 00 00 00 00 00 00 00
170 23:54:23 rundll32.exe:2748 QueryKey HKCU\Software\Classes SUCCESS Name: \REGISTRY\USER\S-1-5-21-1757981266-1390067357-725345543-1003_CLASSES
171 23:54:23 rundll32.exe:2748 QueryKey HKCR\CLSID\{1CDB2949-8F65-4355-8456-263E7C208A5D} SUCCESS Name: \REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{1CDB2949-8F65-4355-8456-263E7C208A5D}
172 23:54:23 rundll32.exe:2748 QueryKey HKCU\Software\Classes SUCCESS Name: \REGISTRY\USER\S-1-5-21-1757981266-1390067357-725345543-1003_CLASSES
173 23:54:23 rundll32.exe:2748 QueryKey HKCU\Software\Classes SUCCESS Name: \REGISTRY\USER\S-1-5-21-1757981266-1390067357-725345543-1003_CLASSES
174 23:54:23 rundll32.exe:2748 QueryKey HKCR\CLSID\{1CDB2949-8F65-4355-8456-263E7C208A5D} SUCCESS Name: \REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{1CDB2949-8F65-4355-8456-263E7C208A5D}
175 23:54:23 rundll32.exe:2748 QueryKey HKCR\CLSID\{1CDB2949-8F65-4355-8456-263E7C208A5D}\InprocServer32 SUCCESS Name: \REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{1CDB2949-8F65-4355-8456-263E7C208A5D}\InprocServer32
176 23:54:23 rundll32.exe:2748 QueryKey HKCR\CLSID\{1CDB2949-8F65-4355-8456-263E7C208A5D} SUCCESS Name: \REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{1CDB2949-8F65-4355-8456-263E7C208A5D}
177 23:54:23 rundll32.exe:2748 QueryKey HKCR\CLSID\{1CDB2949-8F65-4355-8456-263E7C208A5D} SUCCESS Name: \REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{1CDB2949-8F65-4355-8456-263E7C208A5D}
178 23:54:23 rundll32.exe:2748 QueryKey HKCR\CLSID\{1CDB2949-8F65-4355-8456-263E7C208A5D} SUCCESS Name: \REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{1CDB2949-8F65-4355-8456-263E7C208A5D}
179 23:54:23 rundll32.exe:2748 QueryKey HKCR\CLSID\{1CDB2949-8F65-4355-8456-263E7C208A5D}\InprocServer32 SUCCESS Name: \REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{1CDB2949-8F65-4355-8456-263E7C208A5D}\InprocServer32
180 23:54:23 rundll32.exe:2748 QueryValue HKCR\CLSID\{1CDB2949-8F65-4355-8456-263E7C208A5D}\InprocServer32\(Default) SUCCESS "C:\WINDOWS\system32\nvshell.dll"
181 23:54:23 rundll32.exe:2748 QueryKey HKCR\CLSID\{1CDB2949-8F65-4355-8456-263E7C208A5D} SUCCESS Name: \REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{1CDB2949-8F65-4355-8456-263E7C208A5D}
182 23:54:23 rundll32.exe:2748 QueryKey HKCR\CLSID\{1CDB2949-8F65-4355-8456-263E7C208A5D} SUCCESS Name: \REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{1CDB2949-8F65-4355-8456-263E7C208A5D}
183 23:54:23 rundll32.exe:2748 QueryKey HKCR\CLSID\{1CDB2949-8F65-4355-8456-263E7C208A5D} SUCCESS Name: \REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{1CDB2949-8F65-4355-8456-263E7C208A5D}
184 23:54:23 rundll32.exe:2748 QueryKey HKCR\CLSID\{1CDB2949-8F65-4355-8456-263E7C208A5D} SUCCESS Name: \REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{1CDB2949-8F65-4355-8456-263E7C208A5D}
185 23:54:23 rundll32.exe:2748 QueryKey HKCU\Software\Classes SUCCESS Name: \REGISTRY\USER\S-1-5-21-1757981266-1390067357-725345543-1003_CLASSES
186 23:54:23 rundll32.exe:2748 QueryKey HKCR\CLSID\{1CDB2949-8F65-4355-8456-263E7C208A5D} SUCCESS Name: \REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{1CDB2949-8F65-4355-8456-263E7C208A5D}
187 23:54:23 rundll32.exe:2748 QueryValue HKCU\Software\NVIDIA Corporation\Global\nView\nViewLoaded SUCCESS 0x1
188 23:54:23 rundll32.exe:3472 QueryValue HKLM\System\CurrentControlSet\Control\Nls\Locale\0000040C SUCCESS "1"
189 23:54:23 rundll32.exe:3472 QueryValue HKLM\System\CurrentControlSet\Control\Nls\Language Groups\1 SUCCESS "1"
190 23:54:23 rundll32.exe:2748 QueryValue HKCU\Software\NVIDIA Corporation\Global\nView\Shell SUCCESS 0x0
191 23:54:23 rundll32.exe:3472 QueryKey HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink SUCCESS Subkeys = 0
192 23:54:23 rundll32.exe:3472 EnumerateValue HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink\Lucida Sans Unicode SUCCESS "MSGOTHIC.TTC,MS UI Gothic"
193 23:54:23 rundll32.exe:3472 EnumerateValue HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink\Tahoma SUCCESS "MSGOTHIC.TTC,MS UI Gothic"
194 23:54:23 rundll32.exe:3472 EnumerateValue HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink\Microsoft Sans Serif SUCCESS "MSGOTHIC.TTC,MS UI Gothic"
195 23:54:23 rundll32.exe:3472 QueryKey HKCU\Software\Classes SUCCESS Name: \REGISTRY\USER\S-1-5-21-1757981266-1390067357-725345543-1003_CLASSES
196 23:54:23 rundll32.exe:3472 QueryKey HKCR\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32 SUCCESS Name: \REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32
197 23:54:23 rundll32.exe:3472 QueryValue HKCR\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32\(Default) SUCCESS "%SystemRoot%\system32\SHELL32.dll"
198 23:54:23 rundll32.exe:3472 QueryValue HKCU\Control Panel\don't load\ncpa.cpl SUCCESS "No"
199 23:54:23 rundll32.exe:3472 QueryValue HKCU\Control Panel\don't load\odbccp32.cpl SUCCESS "No"
200 23:54:23 rundll32.exe:3472 EnumerateValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\CPLs\Internet Connection Firewall SUCCESS "Firewall.cpl"
201 23:54:23 rundll32.exe:3472 EnumerateValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\CPLs\NetSetupWizard SUCCESS "NetSetup.cpl"
202 23:54:23 rundll32.exe:3472 EnumerateValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\CPLs\Speech SUCCESS "C:\Program Files\Fichiers communs\Microsoft Shared\Speech\sapi.cpl"
203 23:54:23 rundll32.exe:3472 EnumerateValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\CPLs\Cmcpls SUCCESS "C:\WINDOWS\System\cmicnfg.cpl"
204 23:54:23 rundll32.exe:3472 EnumerateValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\CPLs\ SUCCESS ""
205 23:54:23 rundll32.exe:3472 EnumerateValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\CPLs\Nero BurnRights SUCCESS "C:\Program Files\Nero\Nero 7\Nero Toolkit\NeroBurnRights.cpl"
206 23:54:23 rundll32.exe:3472 EnumerateValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\CPLs\mlcfg32.cpl SUCCESS "C:\PROGRA~1\MICROS~2\Office12\MLCFG32.CPL"
207 23:54:23 rundll32.exe:3472 QueryValue HKCU\Software\Microsoft\Windows\CurrentVersion\Controls Folder\Presentation LCID SUCCESS 0x40C
208 23:54:23 rundll32.exe:3472 QueryValue HKCU\Software\Microsoft\Windows\CurrentVersion\Controls Folder\Presentation Cache SUCCESS 48 01 00 00 03 00 00 00 ...
209 23:54:23 rundll32.exe:3472 EnumerateKey HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel\NameSpace SUCCESS Name: Accessibility_Options
210 23:54:23 rundll32.exe:3472 EnumerateKey HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel\NameSpace SUCCESS Name: Add-Remove_Programs
211 23:54:23 rundll32.exe:3472 EnumerateKey HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel\NameSpace SUCCESS Name: Date-Time
212 23:54:23 rundll32.exe:3472 EnumerateKey HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel\NameSpace SUCCESS Name: Dialing_Options
213 23:54:23 rundll32.exe:3472 EnumerateKey HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel\NameSpace SUCCESS Name: Display_Properties
214 23:54:23 rundll32.exe:3472 EnumerateKey HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel\NameSpace SUCCESS Name: Internet_Options
215 23:54:23 rundll32.exe:3472 EnumerateKey HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel\NameSpace SUCCESS Name: Printers
216 23:54:23 rundll32.exe:3472 QueryValue HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel\NameSpace\Printers\(Default) SUCCESS "{2227A280-3AEA-1069-A2DE-08002B30309D}"
217 23:54:23 rundll32.exe:3472 EnumerateKey HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel\NameSpace SUCCESS Name: {0DF44EAA-FF21-4412-828E-260A8728E7F1}
218 23:54:23 rundll32.exe:3472 EnumerateKey HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel\NameSpace SUCCESS Name: {6DFD7C5C-2451-11d3-A299-00C04F8EF6AF}
219 23:54:23 rundll32.exe:3472 EnumerateKey HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel\NameSpace SUCCESS Name: {7007ACC7-3202-11D1-AAD2-00805FC1270E}
220 23:54:23 rundll32.exe:3472 EnumerateKey HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel\NameSpace SUCCESS Name: {D20EA4E1-3957-11d2-A40B-0C5020524152}
221 23:54:23 rundll32.exe:3472 EnumerateKey HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel\NameSpace SUCCESS Name: {D20EA4E1-3957-11d2-A40B-0C5020524153}
222 23:54:23 rundll32.exe:3472 EnumerateKey HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel\NameSpace SUCCESS Name: {D6277990-4C6A-11CF-8D87-00AA0060F5BF}
223 23:54:23 rundll32.exe:3472 EnumerateKey HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel\NameSpace SUCCESS Name: {E211B736-43FD-11D1-9EFB-0000F8757FCD}
224 23:54:23 rundll32.exe:3472 QueryKey HKCU\Software\Classes SUCCESS Name: \REGISTRY\USER\S-1-5-21-1757981266-1390067357-725345543-1003_CLASSES
225 23:54:23 rundll32.exe:3472 QueryKey HKCU\Software\Classes\CLSID SUCCESS Name: \REGISTRY\USER\S-1-5-21-1757981266-1390067357-725345543-1003_CLASSES\CLSID
226 23:54:23 rundll32.exe:3472 QueryKey HKCU\Software\Classes\CLSID\{2227A280-3AEA-1069-A2DE-08002B30309D} SUCCESS Name: \REGISTRY\USER\S-1-5-21-1757981266-1390067357-725345543-1003_CLASSES\CLSID\{2227A280-3AEA-1069-A2DE-08002B30309D}
227 23:54:23 rundll32.exe:3472 QueryValue HKCR\CLSID\{2227A280-3AEA-1069-A2DE-08002B30309D}\LocalizedString SUCCESS "@%SystemRoot%\system32\SHELL32.dll,-9319"
228 23:54:23 rundll32.exe:3472 QueryValue HKLM\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1757981266-1390067357-725345543-1003\Flags SUCCESS 0x0
229 23:54:23 rundll32.exe:3472 QueryValue HKLM\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1757981266-1390067357-725345543-1003\State SUCCESS 0x100
230 23:54:23 rundll32.exe:3472 QueryValue HKLM\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1757981266-1390067357-725345543-1003\CentralProfile SUCCESS ""
231 23:54:23 rundll32.exe:3472 QueryValue HKLM\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1757981266-1390067357-725345543-1003\ProfileImagePath SUCCESS "%SystemDrive%\Documents and Settings\GANIBARDI"
232 23:54:23 rundll32.exe:3472 QueryValue HKLM\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1757981266-1390067357-725345543-1003\ProfileLoadTimeLow SUCCESS 0x245C9702
233 23:54:23 rundll32.exe:3472 QueryValue HKLM\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1757981266-1390067357-725345543-1003\ProfileLoadTimeHigh SUCCESS 0x1C7B841
234 23:54:23 rundll32.exe:3472 QueryValue HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\LangID SUCCESS 0C 04
235 23:54:23 rundll32.exe:3472 QueryValue HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\@C:\WINDOWS\system32\SHELL32.dll,-9319 SUCCESS "Imprimantes et télécopieurs"
236 23:54:23 rundll32.exe:3472 QueryKey HKCU\Software\Classes SUCCESS Name: \REGISTRY\USER\S-1-5-21-1757981266-1390067357-725345543-1003_CLASSES
237 23:54:23 rundll32.exe:3472 QueryKey HKCR\CLSID\{2227A280-3AEA-1069-A2DE-08002B30309D}\ShellFolder SUCCESS Name: \REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{2227A280-3AEA-1069-A2DE-08002B30309D}\ShellFolder
238 23:54:23 rundll32.exe:3472 QueryValue HKCR\CLSID\{2227A280-3AEA-1069-A2DE-08002B30309D}\ShellFolder\Attributes SUCCESS 0x20000004
239 23:54:23 rundll32.exe:3472 QueryKey HKCR\CLSID\{2227A280-3AEA-1069-A2DE-08002B30309D}\ShellFolder SUCCESS Name: \REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{2227A280-3AEA-1069-A2DE-08002B30309D}\ShellFolder
240 23:54:23 rundll32.exe:3472 QueryKey HKCU\Software\Classes SUCCESS Name: \REGISTRY\USER\S-1-5-21-1757981266-1390067357-725345543-1003_CLASSES
241 23:54:23 rundll32.exe:3472 QueryKey HKCU\Software\Classes\CLSID SUCCESS Name: \REGISTRY\USER\S-1-5-21-1757981266-1390067357-725345543-1003_CLASSES\CLSID
242 23:54:23 rundll32.exe:3472 QueryKey HKCU\Software\Classes\CLSID\{0DF44EAA-FF21-4412-828E-260A8728E7F1} SUCCESS Name: \REGISTRY\USER\S-1-5-21-1757981266-1390067357-725345543-1003_CLASSES\CLSID\{0DF44EAA-FF21-4412-828E-260A8728E7F1}
243 23:54:23 rundll32.exe:3472 QueryValue HKCR\CLSID\{0DF44EAA-FF21-4412-828E-260A8728E7F1}\LocalizedString SUCCESS "@%SystemRoot%\system32\SHELL32.dll,-32517"
244 23:54:23 rundll32.exe:3472 QueryValue HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\@C:\WINDOWS\system32\SHELL32.dll,-32517 SUCCESS "Barre des tâches et menu Démarrer"
245 23:54:23 rundll32.exe:3472 QueryKey HKCU\Software\Classes SUCCESS Name: \REGISTRY\USER\S-1-5-21-1757981266-1390067357-725345543-1003_CLASSES
246 23:54:23 rundll32.exe:3472 QueryKey HKCU\Software\Classes\CLSID\{0DF44EAA-FF21-4412-828E-260A8728E7F1} SUCCESS Name: \REGISTRY\USER\S-1-5-21-1757981266-1390067357-725345543-1003_CLASSES\CLSID\{0DF44EAA-FF21-4412-828E-260A8728E7F1}
247 23:54:23 rundll32.exe:3472 QueryKey HKCU\Software\Classes SUCCESS Name: \REGISTRY\USER\S-1-5-21-1757981266-1390067357-725345543-1003_CLASSES
248 23:54:23 rundll32.exe:3472 QueryKey HKCR\CLSID\{0DF44EAA-FF21-4412-828E-260A8728E7F1}\ShellFolder SUCCESS Name: \REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{0DF44EAA-FF21-4412-828E-260A8728E7F1}\ShellFolder
249 23:54:23 rundll32.exe:3472 QueryValue HKCR\CLSID\{0DF44EAA-FF21-4412-828E-260A8728E7F1}\ShellFolder\Attributes SUCCESS 0x0
250 23:54:23 rundll32.exe:3472 QueryKey HKCR\CLSID\{0DF44EAA-FF21-4412-828E-260A8728E7F1}\ShellFolder SUCCESS Name: \REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{0DF44EAA-FF21-4412-828E-260A8728E7F1}\ShellFolder
251 23:54:23 rundll32.exe:3472 QueryValue HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{0DF44EAA-FF21-4412-828E-260A8728E7F1} SUCCESS 0x20
252 23:54:23 rundll32.exe:3472 QueryKey HKCU\Software\Classes SUCCESS Name: \REGISTRY\USER\S-1-5-21-1757981266-1390067357-725345543-1003_CLASSES
253 23:54:23 rundll32.exe:3472 QueryKey HKCU\Software\Classes\CLSID\{0DF44EAA-FF21-4412-828E-260A8728E7F1} SUCCESS Name: \REGISTRY\USER\S-1-5-21-1757981266-1390067357-725345543-1003_CLASSES\CLSID\{0DF44EAA-FF21-4412-828E-260A8728E7F1}
254 23:54:23 rundll32.exe:3472 QueryKey HKCU\Software\Classes\CLSID\{0DF44EAA-FF21-4412-828E-260A8728E7F1} SUCCESS Name: \REGISTRY\USER\S-1-5-21-1757981266-1390067357-725345543-1003_CLASSES\CLSID\{0DF44EAA-FF21-4412-828E-260A8728E7F1}
255 23:54:23 rundll32.exe:3472 QueryValue HKCR\CLSID\{0DF44EAA-FF21-4412-828E-260A8728E7F1}\{305CA226-D286-468E-B848-2B2E8E697B74} 2 SUCCESS 0x1
256 23:54:23 rundll32.exe:3472 QueryKey HKCU\Software\Classes SUCCESS Name: \REGISTRY\USER\S-1-5-21-1757981266-1390067357-725345543-1003_CLASSES
257 23:54:23 rundll32.exe:3472 QueryKey HKCU\Software\Classes\CLSID SUCCESS Name: \REGISTRY\USER\S-1-5-21-1757981266-1390067357-725345543-1003_CLASSES\CLSID
258 23:54:23 rundll32.exe:3472 QueryKey HKCU\Software\Classes\CLSID\{6DFD7C5C-2451-11D3-A299-00C04F8EF6AF} SUCCESS Name: \REGISTRY\USER\S-1-5-21-1757981266-1390067357-725345543-1003_CLASSES\CLSID\{6DFD7C5C-2451-11d3-A299-00C04F8EF6AF}
259 23:54:23 rundll32.exe:3472 QueryValue HKCR\CLSID\{6DFD7C5C-2451-11d3-A299-00C04F8EF6AF}\LocalizedString SUCCESS "@%SystemRoot%\system32\SHELL32.dll,-22985"
260 23:54:23 rundll32.exe:3472 QueryValue HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\@C:\WINDOWS\system32\SHELL32.dll,-22985 SUCCESS "Options des dossiers"
261 23:54:23 rundll32.exe:3472 QueryKey HKCU\Software\Classes SUCCESS Name: \REGISTRY\USER\S-1-5-21-1757981266-1390067357-725345543-1003_CLASSES
262 23:54:23 rundll32.exe:3472 QueryKey HKCU\Software\Classes\CLSID\{6DFD7C5C-2451-11D3-A299-00C04F8EF6AF} SUCCESS Name: \REGISTRY\USER\S-1-5-21-1757981266-1390067357-725345543-1003_CLASSES\CLSID\{6DFD7C5C-2451-11d3-A299-00C04F8EF6AF}
263 23:54:23 rundll32.exe:3472 QueryKey HKCU\Software\Classes SUCCESS Name: \REGISTRY\USER\S-1-5-21-1757981266-1390067357-725345543-1003_CLASSES
264 23:54:23 rundll32.exe:3472 QueryKey HKCR\CLSID\{6DFD7C5C-2451-11D3-A299-00C04F8EF6AF}\ShellFolder SUCCESS Name: \REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{6DFD7C5C-2451-11d3-A299-00C04F8EF6AF}\ShellFolder
265 23:54:23 rundll32.exe:3472 QueryValue HKCR\CLSID\{6DFD7C5C-2451-11D3-A299-00C04F8EF6AF}\ShellFolder\Attributes SUCCESS 0x0
266 23:54:23 rundll32.exe:3472 QueryKey HKCR\CLSID\{6DFD7C5C-2451-11D3-A299-00C04F8EF6AF}\ShellFolder SUCCESS Name: \REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{6DFD7C5C-2451-11d3-A299-00C04F8EF6AF}\ShellFolder
267 23:54:23 rundll32.exe:3472 QueryValue HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{6DFD7C5C-2451-11D3-A299-00C04F8EF6AF} SUCCESS 0x40000021
268 23:54:23 rundll32.exe:3472 QueryKey HKCU\Software\Classes SUCCESS Name: \REGISTRY\USER\S-1-5-21-1757981266-1390067357-725345543-1003_CLASSES
269 23:54:23 rundll32.exe:3472 QueryKey HKCU\Software\Classes\CLSID\{6DFD7C5C-2451-11D3-A299-00C04F8EF6AF} SUCCESS Name: \REGISTRY\USER\S-1-5-21-1757981266-1390067357-725345543-1003_CLASSES\CLSID\{6DFD7C5C-2451-11d3-A299-00C04F8EF6AF}
270 23:54:23 rundll32.exe:3472 QueryKey HKCU\Software\Classes\CLSID\{6DFD7C5C-2451-11D3-A299-00C04F8EF6AF} SUCCESS Name: \REGISTRY\USER\S-1-5-21-1757981266-1390067357-725345543-1003_CLASSES\CLSID\{6DFD7C5C-2451-11d3-A299-00C04F8EF6AF}
271 23:54:23 rundll32.exe:3472 QueryValue HKCR\CLSID\{6DFD7C5C-2451-11d3-A299-00C04F8EF6AF}\{305CA226-D286-468E-B848-2B2E8E697B74} 2 SUCCESS 0x1
272 23:54:23 rundll32.exe:3472 QueryKey HKCU\Software\Classes SUCCESS Name: \REGISTRY\USER\S-1-5-21-1757981266-1390067357-725345543-1003_CLASSES
273 23:54:23 rundll32.exe:3472 QueryKey HKCU\Software\Classes\CLSID SUCCESS Name: \REGISTRY\USER\S-1-5-21-1757981266-1390067357-725345543-1003_CLASSES\CLSID
274 23:54:23 rundll32.exe:3472 QueryKey HKCU\Software\Classes\CLSID\{7007ACC7-3202-11D1-AAD2-00805FC1270E} SUCCESS Name: \REGISTRY\USER\S-1-5-21-1757981266-1390067357-725345543-1003_CLASSES\CLSID\{7007ACC7-3202-11D1-AAD2-00805FC1270E}
275 23:54:23 rundll32.exe:3472 QueryValue HKCR\CLSID\{7007ACC7-3202-11D1-AAD2-00805FC1270E}\LocalizedString SUCCESS "@C:\WINDOWS\system32\netshell.dll,-1200"
276 23:54:23 rundll32.exe:3472 QueryValue HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\@C:\WINDOWS\system32\netshell.dll,-1200 SUCCESS "Connexions réseau"
277 23:54:23 rundll32.exe:3472 QueryKey HKCU\Software\Classes SUCCESS Name: \REGISTRY\USER\S-1-5-21-1757981266-1390067357-725345543-1003_CLASSES
278 23:54:23 rundll32.exe:3472 QueryKey HKCU\Software\Classes\CLSID\{7007ACC7-3202-11D1-AAD2-00805FC1270E} SUCCESS Name: \REGISTRY\USER\S-1-5-21-1757981266-1390067357-725345543-1003_CLASSES\CLSID\{7007ACC7-3202-11D1-AAD2-00805FC1270E}
279 23:54:23 rundll32.exe:3472 QueryKey HKCU\Software\Classes SUCCESS Name: \REGISTRY\USER\S-1-5-21-1757981266-1390067357-725345543-1003_CLASSES
280 23:54:23 rundll32.exe:3472 QueryKey HKCR\CLSID\{7007ACC7-3202-11D1-AAD2-00805FC1270E}\ShellFolder SUCCESS Name: \REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{7007ACC7-3202-11D1-AAD2-00805FC1270E}\ShellFolder
281 23:54:23 rundll32.exe:3472 QueryValue HKCR\CLSID\{7007ACC7-3202-11D1-AAD2-00805FC1270E}\ShellFolder\Attributes SUCCESS 00 00 00 20
282 23:54:23 rundll32.exe:3472 QueryKey HKCR\CLSID\{7007ACC7-3202-11D1-AAD2-00805FC1270E}\ShellFolder SUCCESS Name: \REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{7007ACC7-3202-11D1-AAD2-00805FC1270E}\ShellFolder
283 23:54:23 rundll32.exe:3472 QueryKey HKCU\Software\Classes SUCCESS Name: \REGISTRY\USER\S-1-5-21-1757981266-1390067357-725345543-1003_CLASSES
284 23:54:23 rundll32.exe:3472 QueryKey HKCU\Software\Classes\CLSID SUCCESS Name: \REGISTRY\USER\S-1-5-21-1757981266-1390067357-725345543-1003_CLASSES\CLSID
285 23:54:23 rundll32.exe:3472 QueryKey HKCU\Software\Classes\CLSID\{D20EA4E1-3957-11D2-A40B-0C5020524152} SUCCESS Name: \REGISTRY\USER\S-1-5-21-1757981266-1390067357-725345543-1003_CLASSES\CLSID\{D20EA4E1-3957-11d2-A40B-0C5020524152}
286 23:54:23 rundll32.exe:3472 QueryValue HKCR\CLSID\{D20EA4E1-3957-11d2-A40B-0C5020524152}\LocalizedString SUCCESS "@%SystemRoot%\system32\SHELL32.dll,-22981"
287 23:54:23 rundll32.exe:3472 QueryValue HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\@C:\WINDOWS\system32\SHELL32.dll,-22981 SUCCESS "Polices"
288 23:54:23 rundll32.exe:3472 QueryKey HKCU\Software\Classes SUCCESS Name: \REGISTRY\USER\S-1-5-21-1757981266-1390067357-725345543-1003_CLASSES
289 23:54:23 rundll32.exe:3472 QueryKey HKCU\Software\Classes\CLSID\{D20EA4E1-3957-11D2-A40B-0C5020524152} SUCCESS Name: \REGISTRY\USER\S-1-5-21-1757981266-1390067357-725345543-1003_CLASSES\CLSID\{D20EA4E1-3957-11d2-A40B-0C5020524152}
290 23:54:23 rundll32.exe:3472 QueryKey HKCU\Software\Classes SUCCESS Name: \REGISTRY\USER\S-1-5-21-1757981266-1390067357-725345543-1003_CLASSES
291 23:54:23 rundll32.exe:3472 QueryKey HKCR\CLSID\{D20EA4E1-3957-11D2-A40B-0C5020524152}\ShellFolder SUCCESS Name: \REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{D20EA4E1-3957-11d2-A40B-0C5020524152}\ShellFolder
292 23:54:23 rundll32.exe:3472 QueryValue HKCR\CLSID\{D20EA4E1-3957-11D2-A40B-0C5020524152}\ShellFolder\Attributes SUCCESS 0x60000000
293 23:54:23 rundll32.exe:3472 QueryKey HKCR\CLSID\{D20EA4E1-3957-11D2-A40B-0C5020524152}\ShellFolder SUCCESS Name: \REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{D20EA4E1-3957-11d2-A40B-0C5020524152}\ShellFolder
294 23:54:23 rundll32.exe:3472 QueryKey HKCU\Software\Classes SUCCESS Name: \REGISTRY\USER\S-1-5-21-1757981266-1390067357-725345543-1003_CLASSES
295 23:54:23 rundll32.exe:3472 QueryKey HKCU\Software\Classes\CLSID SUCCESS Name: \REGISTRY\USER\S-1-5-21-1757981266-1390067357-725345543-1003_CLASSES\CLSID
296 23:54:23 rundll32.exe:3472 QueryKey HKCU\Software\Classes\CLSID\{D20EA4E1-3957-11D2-A40B-0C5020524153} SUCCESS Name: \REGISTRY\USER\S-1-5-21-1757981266-1390067357-725345543-1003_CLASSES\CLSID\{D20EA4E1-3957-11d2-A40B-0C5020524153}
297 23:54:23 rundll32.exe:3472 QueryValue HKCR\CLSID\{D20EA4E1-3957-11d2-A40B-0C5020524153}\LocalizedString SUCCESS "@%SystemRoot%\system32\SHELL32.dll,-22982"
298 23:54:23 rundll32.exe:3472 QueryValue HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\@C:\WINDOWS\system32\SHELL32.dll,-22982 SUCCESS "Outils d'administration"
299 23:54:23 rundll32.exe:3472 QueryKey HKCU\Software\Classes SUCCESS Name: \REGISTRY\USER\S-1-5-21-1757981266-1390067357-725345543-1003_CLASSES
300 23:54:23 rundll32.exe:3472 QueryKey HKCU\Software\Classes\CLSID\{D20EA4E1-3957-11D2-A40B-0C5020524153} SUCCESS Name: \REGISTRY\USER\S-1-5-21-1757981266-1390067357-725345543-1003_CLASSES\CLSID\{D20EA4E1-3957-11d2-A40B-0C5020524153}
301 23:54:23 rundll32.exe:3472 QueryKey HKCU\Software\Classes SUCCESS Name: \REGISTRY\USER\S-1-5-21-1757981266-1390067357-725345543-1003_CLASSES
302 23:54:23 rundll32.exe:3472 QueryKey HKCR\CLSID\{D20EA4E1-3957-11D2-A40B-0C5020524153}\ShellFolder SUCCESS Name: \REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{D20EA4E1-3957-11d2-A40B-0C5020524153}\ShellFolder
303 23:54:23 rundll32.exe:3472 QueryValue HKCR\CLSID\{D20EA4E1-3957-11D2-A40B-0C5020524153}\ShellFolder\Attributes SUCCESS 0x60000100
304 23:54:23 rundll32.exe:3472 QueryKey HKCR\CLSID\{D20EA4E1-3957-11D2-A40B-0C5020524153}\ShellFolder SUCCESS Name: \REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{D20EA4E1-3957-11d2-A40B-0C5020524153}\ShellFolder
305 23:54:23 rundll32.exe:3472 QueryKey HKCU\Software\Classes SUCCESS Name: \REGISTRY\USER\S-1-5-21-1757981266-1390067357-725345543-1003_CLASSES
306 23:54:23 rundll32.exe:3472 QueryKey HKCU\Software\Classes\CLSID SUCCESS Name: \REGISTRY\USER\S-1-5-21-1757981266-1390067357-725345543-1003_CLASSES\CLSID
307 23:54:23 rundll32.exe:3472 QueryKey HKCU\Software\Classes\CLSID\{D6277990-4C6A-11CF-8D87-00AA0060F5BF} SUCCESS Name: \REGISTRY\USER\S-1-5-21-1757981266-1390067357-725345543-1003_CLASSES\CLSID\{D6277990-4C6A-11CF-8D87-00AA0060F5BF}
308 23:54:23 rundll32.exe:3472 QueryValue HKCR\CLSID\{D6277990-4C6A-11CF-8D87-00AA0060F5BF}\LocalizedString SUCCESS "@C:\WINDOWS\system32\mstask.dll,-3408"
309 23:54:23 rundll32.exe:3472 QueryValue HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\@C:\WINDOWS\system32\mstask.dll,-3408 SUCCESS "Tâches planifiées"
310 23:54:23 rundll32.exe:3472 QueryKey HKCU\Software\Classes SUCCESS Name: \REGISTRY\USER\S-1-5-21-1757981266-1390067357-725345543-1003_CLASSES
311 23:54:23 rundll32.exe:3472 QueryKey HKCU\Software\Classes\CLSID\{D6277990-4C6A-11CF-8D87-00AA0060F5BF} SUCCESS Name: \REGISTRY\USER\S-1-5-21-1757981266-1390067357-725345543-1003_CLASSES\CLSID\{D6277990-4C6A-11CF-8D87-00AA0060F5BF}
312 23:54:23 rundll32.exe:3472 QueryKey HKCU\Software\Classes SUCCESS Name: \REGISTRY\USER\S-1-5-21-1757981266-1390067357-725345543-1003_CLASSES
313 23:54:23 rundll32.exe:3472 QueryKey HKCR\CLSID\{D6277990-4C6A-11CF-8D87-00AA0060F5BF}\ShellFolder SUCCESS Name: \REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{D6277990-4C6A-11CF-8D87-00AA0060F5BF}\ShellFolder
314 23:54:23 rundll32.exe:3472 QueryValue HKCR\CLSID\{D6277990-4C6A-11CF-8D87-00AA0060F5BF}\ShellFolder\Attributes SUCCESS 00 00 00 21
315 23:54:23 rundll32.exe:3472 QueryKey HKCR\CLSID\{D6277990-4C6A-11CF-8D87-00AA0060F5BF}\ShellFolder SUCCESS Name: \REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{D6277990-4C6A-11CF-8D87-00AA0060F5BF}\ShellFolder
316 23:54:23 rundll32.exe:3472 QueryKey HKCU\Software\Classes SUCCESS Name: \REGISTRY\USER\S-1-5-21-1757981266-1390067357-725345543-1003_CLASSES
317 23:54:23 rundll32.exe:3472 QueryKey HKCU\Software\Classes\CLSID SUCCESS Name: \REGISTRY\USER\S-1-5-21-1757981266-1390067357-725345543-1003_CLASSES\CLSID
318 23:54:23 rundll32.exe:3472 QueryKey HKCU\Software\Classes\CLSID\{E211B736-43FD-11D1-9EFB-0000F8757FCD} SUCCESS Name: \REGISTRY\USER\S-1-5-21-1757981266-1390067357-725345543-1003_CLASSES\CLSID\{E211B736-43FD-11D1-9EFB-0000F8757FCD}
319 23:54:23 rundll32.exe:3472 QueryValue HKCR\CLSID\{E211B736-43FD-11D1-9EFB-0000F8757FCD}\LocalizedString SUCCESS "@%SystemRoot%\system32\wiashext.dll,-331"
320 23:54:23 rundll32.exe:3472 QueryValue HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\@C:\WINDOWS\system32\wiashext.dll,-331 SUCCESS "Scanneurs et appareils photo"
321 23:54:23 rundll32.exe:3472 QueryKey HKCU\Software\Classes SUCCESS Name: \REGISTRY\USER\S-1-5-21-1757981266-1390067357-725345543-1003_CLASSES
322 23:54:23 rundll32.exe:3472 QueryKey HKCU\Software\Classes\CLSID\{E211B736-43FD-11D1-9EFB-0000F8757FCD} SUCCESS Name: \REGISTRY\USER\S-1-5-21-1757981266-1390067357-725345543-1003_CLASSES\CLSID\{E211B736-43FD-11D1-9EFB-0000F8757FCD}
323 23:54:23 rundll32.exe:3472 QueryKey HKCU\Software\Classes SUCCESS Name: \REGISTRY\USER\S-1-5-21-1757981266-1390067357-725345543-1003_CLASSES
324 23:54:23 rundll32.exe:3472 QueryKey HKCR\CLSID\{E211B736-43FD-11D1-9EFB-0000F8757FCD}\ShellFolder SUCCESS Name: \REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{E211B736-43FD-11D1-9EFB-0000F8757FCD}\ShellFolder
325 23:54:23 rundll32.exe:3472 QueryValue HKCR\CLSID\{E211B736-43FD-11D1-9EFB-0000F8757FCD}\ShellFolder\Attributes SUCCESS 0x20400004
326 23:54:23 rundll32.exe:3472 QueryKey HKCR\CLSID\{E211B736-43FD-11D1-9EFB-0000F8757FCD}\ShellFolder SUCCESS Name: \REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{E211B736-43FD-11D1-9EFB-0000F8757FCD}\ShellFolder
327 23:54:23 rundll32.exe:3472 QueryValue HKCR\CLSID\{E211B736-43FD-11D1-9EFB-0000F8757FCD}\ShellFolder\CallForAttributes SUCCESS 0x0
328 23:54:23 rundll32.exe:3472 EnumerateValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Extended Properties\{305CA226-D286-468E-B848-2B2E8E697B74} 2\%SystemRoot%\system32\Firewall.cpl SUCCESS "3,10"
329 23:54:23 rundll32.exe:3472 EnumerateValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Extended Properties\{305CA226-D286-468E-B848-2B2E8E697B74} 2\%SystemRoot%\system32\wscui.cpl SUCCESS 0xFFFFFFFF
330 23:54:23 rundll32.exe:3472 EnumerateValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Extended Properties\{305CA226-D286-468E-B848-2B2E8E697B74} 2\%SystemRoot%\system32\NetSetup.cpl SUCCESS 0x3
331 23:54:23 rundll32.exe:3472 EnumerateValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Extended Properties\{305CA226-D286-468E-B848-2B2E8E697B74} 2\C:\Program Files\Fichiers communs\Microsoft Shared\Speech\sapi.cpl SUCCESS 0x4
332 23:54:23 rundll32.exe:3472 EnumerateValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Extended Properties\{305CA226-D286-468E-B848-2B2E8E697B74} 2\%SystemRoot%\System32\wuaucpl.cpl SUCCESS 0xA
333 23:54:23 rundll32.exe:3472 EnumerateValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Extended Properties\{305CA226-D286-468E-B848-2B2E8E697B74} 2\%SystemRoot%\system32\appwiz.cpl SUCCESS 0x8
334 23:54:23 rundll32.exe:3472 EnumerateValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Extended Properties\{305CA226-D286-468E-B848-2B2E8E697B74} 2\%SystemRoot%\system32\access.cpl SUCCESS 0x7
335 23:54:23 rundll32.exe:3472 EnumerateValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Extended Properties\{305CA226-D286-468E-B848-2B2E8E697B74} 2\%SystemRoot%\system32\bthprops.cpl SUCCESS "2,3"
336 23:54:23 rundll32.exe:3472 EnumerateValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Extended Properties\{305CA226-D286-468E-B848-2B2E8E697B74} 2\%SystemRoot%\system32\desk.cpl SUCCESS 0x1
337 23:54:23 rundll32.exe:3472 EnumerateValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Extended Properties\{305CA226-D286-468E-B848-2B2E8E697B74} 2\%SystemRoot%\system32\hdwwiz.cpl SUCCESS 0xFFFFFFFF
338 23:54:23 rundll32.exe:3472 EnumerateValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Extended Properties\{305CA226-D286-468E-B848-2B2E8E697B74} 2\%SystemRoot%\system32\inetcpl.cpl SUCCESS "3,10"
339 23:54:23 rundll32.exe:3472 EnumerateValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Extended Properties\{305CA226-D286-468E-B848-2B2E8E697B74} 2\%SystemRoot%\system32\intl.cpl SUCCESS 0x6
340 23:54:23 rundll32.exe:3472 EnumerateValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Extended Properties\{305CA226-D286-468E-B848-2B2E8E697B74} 2\%SystemRoot%\system32\irprops.cpl SUCCESS 0x2
341 23:54:23 rundll32.exe:3472 EnumerateValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Extended Properties\{305CA226-D286-468E-B848-2B2E8E697B74} 2\%SystemRoot%\system32\joy.cpl SUCCESS 0x2
342 23:54:23 rundll32.exe:3472 EnumerateValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Extended Properties\{305CA226-D286-468E-B848-2B2E8E697B74} 2\%SystemRoot%\system32\main.cpl SUCCESS 0x2
343 23:54:23 rundll32.exe:3472 EnumerateValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Extended Properties\{305CA226-D286-468E-B848-2B2E8E697B74} 2\%SystemRoot%\system32\mmsys.cpl SUCCESS 0x4
344 23:54:23 rundll32.exe:3472 EnumerateValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Extended Properties\{305CA226-D286-468E-B848-2B2E8E697B74} 2\%SystemRoot%\system32\ncpa.cpl SUCCESS 0x3
345 23:54:23 rundll32.exe:3472 EnumerateValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Extended Properties\{305CA226-D286-468E-B848-2B2E8E697B74} 2\%SystemRoot%\system32\nwc.cpl SUCCESS 0x0
346 23:54:23 rundll32.exe:3472 EnumerateValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Extended Properties\{305CA226-D286-468E-B848-2B2E8E697B74} 2\%SystemRoot%\system32\nusrmgr.cpl SUCCESS 0x9
347 23:54:23 rundll32.exe:3472 EnumerateValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Extended Properties\{305CA226-D286-468E-B848-2B2E8E697B74} 2\%SystemRoot%\system32\odbccp32.cpl SUCCESS 0x0
348 23:54:23 rundll32.exe:3472 EnumerateValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Extended Properties\{305CA226-D286-468E-B848-2B2E8E697B74} 2\%SystemRoot%\system32\powercfg.cpl SUCCESS 0x5
349 23:54:23 rundll32.exe:3472 EnumerateValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Extended Properties\{305CA226-D286-468E-B848-2B2E8E697B74} 2\%SystemRoot%\system32\sticpl.cpl SUCCESS 0x2
350 23:54:23 rundll32.exe:3472 EnumerateValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Extended Properties\{305CA226-D286-468E-B848-2B2E8E697B74} 2\%SystemRoot%\system32\sysdm.cpl SUCCESS "5"
351 23:54:23 rundll32.exe:3472 EnumerateValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Extended Properties\{305CA226-D286-468E-B848-2B2E8E697B74} 2\%SystemRoot%\system32\telephon.cpl SUCCESS 0x2
352 23:54:23 rundll32.exe:3472 EnumerateValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Extended Properties\{305CA226-D286-468E-B848-2B2E8E697B74} 2\%SystemRoot%\system32\timedate.cpl SUCCESS 0x6
353 23:54:23 rundll32.exe:3472 EnumerateValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Extended Properties\{305CA226-D286-468E-B848-2B2E8E697B74} 2\C:\Program Files\Sony Ericsson\Mobile\Mobile Phone Monitor\ecsepm.cpl SUCCESS 0x2
354 23:54:23 rundll32.exe:3472 EnumerateValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Extended Properties\{305CA226-D286-468E-B848-2B2E8E697B74} 2\ SUCCESS ""
355 23:54:23 rundll32.exe:3472 EnumerateValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Extended Properties\{305CA226-D286-468E-B848-2B2E8E697B74} 2\C:\Program Files\Microsoft Office\Office12\MLCFG32.CPL SUCCESS 0x9
356 23:54:23 rundll32.exe:3472 QueryValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Extended Properties\{305CA226-D286-468E-B848-2B2E8E697B74} 2\%SystemRoot%\system32\access.cpl SUCCESS 0x7
357 23:54:23 rundll32.exe:3472 QueryValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Extended Properties\{305CA226-D286-468E-B848-2B2E8E697B74} 2\C:\Program Files\Fichiers communs\Microsoft Shared\Speech\sapi.cpl SUCCESS 0x4
358 23:54:23 rundll32.exe:3472 QueryValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Extended Properties\{305CA226-D286-468E-B848-2B2E8E697B74} 2\(Default) SUCCESS ""
359 23:54:23 rundll32.exe:3472 QueryValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Extended Properties\{305CA226-D286-468E-B848-2B2E8E697B74} 2\%SystemRoot%\system32\appwiz.cpl SUCCESS 0x8
360 23:54:23 rundll32.exe:3472 QueryValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Extended Properties\{305CA226-D286-468E-B848-2B2E8E697B74} 2\%SystemRoot%\system32\desk.cpl SUCCESS 0x1
361 23:54:23 rundll32.exe:3472 QueryValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Extended Properties\{305CA226-D286-468E-B848-2B2E8E697B74} 2\%SystemRoot%\system32\hdwwiz.cpl SUCCESS 0xFFFFFFFF
362 23:54:23 rundll32.exe:3472 QueryValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Extended Properties\{305CA226-D286-468E-B848-2B2E8E697B74} 2\%SystemRoot%\system32\intl.cpl SUCCESS 0x6
363 23:54:23 rundll32.exe:3472 QueryValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Extended Properties\{305CA226-D286-468E-B848-2B2E8E697B74} 2\%SystemRoot%\system32\joy.cpl SUCCESS 0x2
364 23:54:23 rundll32.exe:3472 QueryValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Extended Properties\{305CA226-D286-468E-B848-2B2E8E697B74} 2\%SystemRoot%\system32\main.cpl SUCCESS 0x2
365 23:54:23 rundll32.exe:3472 QueryValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Extended Properties\{305CA226-D286-468E-B848-2B2E8E697B74} 2\%SystemRoot%\system32\main.cpl SUCCESS 0x2
366 23:54:23 rundll32.exe:3472 QueryValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Extended Properties\{305CA226-D286-468E-B848-2B2E8E697B74} 2\%SystemRoot%\system32\mmsys.cpl SUCCESS 0x4
367 23:54:23 rundll32.exe:3472 QueryValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Extended Properties\{305CA226-D286-468E-B848-2B2E8E697B74} 2\%SystemRoot%\system32\nusrmgr.cpl SUCCESS 0x9
368 23:54:23 rundll32.exe:3472 QueryValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Extended Properties\{305CA226-D286-468E-B848-2B2E8E697B74} 2\%SystemRoot%\system32\powercfg.cpl SUCCESS 0x5
369 23:54:23 rundll32.exe:3472 QueryValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Extended Properties\{305CA226-D286-468E-B848-2B2E8E697B74} 2\%SystemRoot%\system32\sysdm.cpl SUCCESS "5"
370 23:54:23 rundll32.exe:3472 QueryValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Extended Properties\{305CA226-D286-468E-B848-2B2E8E697B74} 2\%SystemRoot%\system32\telephon.cpl SUCCESS 0x2
371 23:54:23 rundll32.exe:3472 QueryValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Extended Properties\{305CA226-D286-468E-B848-2B2E8E697B74} 2\%SystemRoot%\system32\timedate.cpl SUCCESS 0x6
372 23:54:23 rundll32.exe:3472 QueryValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Extended Properties\{305CA226-D286-468E-B848-2B2E8E697B74} 2\%SystemRoot%\system32\wscui.cpl SUCCESS 0xFFFFFFFF
373 23:54:23 rundll32.exe:3472 QueryValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Extended Properties\{305CA226-D286-468E-B848-2B2E8E697B74} 2\(Default) SUCCESS ""
374 23:54:23 rundll32.exe:3472 QueryValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Extended Properties\{305CA226-D286-468E-B848-2B2E8E697B74} 2\C:\Program Files\Microsoft Office\Office12\MLCFG32.CPL SUCCESS 0x9
375 23:54:23 rundll32.exe:3472 QueryValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Extended Properties\{305CA226-D286-468E-B848-2B2E8E697B74} 2\%SystemRoot%\system32\inetcpl.cpl SUCCESS "3,10"
376 23:54:23 rundll32.exe:3472 QueryValue HKLM\SYSTEM\WPA\MediaCenter\Installed SUCCESS 0x0
377 23:54:23 rundll32.exe:3472 QueryValue HKLM\System\Setup\SystemSetupInProgress SUCCESS 0x0
378 23:54:23 rundll32.exe:3472 QueryValue HKLM\System\WPA\PnP\seed SUCCESS 0xD7CA2224
379 23:54:23 rundll32.exe:3472 QueryValue HKLM\SYSTEM\Setup\OsLoaderPath SUCCESS "\"
380 23:54:23 rundll32.exe:3472 QueryValue HKLM\SYSTEM\Setup\OsLoaderPath SUCCESS "\"
381 23:54