Sei sulla pagina 1di 176

SpyHolesList Version:13.6 Build:9.30.0.

630-64b
19.10.2017 11:37:26 AM Geo: US-English
WinDir=C:\WINDOWS
Startup=C:\Users\USER\AppData\Roaming\Microsoft\Windows\Start
Menu\Programs\Startup\
Common Startup=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Windows 10 Pro (10.0.14393)
Internet Explorer 9.11.14393.0
DBS Version: 2.081
[Internet Explorer]
[Default Home Page] :HKLM Default_Page_URL=http://go.microsoft.com/fwlink/p/?
LinkId=255141
[Current Home Page] :HKCU Start Page=http://go.microsoft.com/fwlink/p/?
LinkId=255141
[Current Home Page] :HKCU HOMEOldSP=""
[Current Home Page] :HKCU Default_Page_URL=""
[Current Home Page] :HKLM Start Page=http://go.microsoft.com/fwlink/p/?
LinkId=255141
[Current Home Page] :HKLM HOMEOldSP=""
[All Users Search] :HKLM Default_Search_URL=http://go.microsoft.com/fwlink/?
LinkId=54896
[All Users Search] :HKLM Search Page=http://go.microsoft.com/fwlink/?LinkId=54896
[Current Home Page(x64)] :HKLM Start Page=http://go.microsoft.com/fwlink/p/?
LinkId=255141
[Current Home Page(x64)] :HKLM HOMEOldSP=""
[All Users Search(x64)] :HKLM Default_Search_URL=http://go.microsoft.com/fwlink/?
LinkId=54896
[All Users Search(x64)] :HKLM Search Page=http://go.microsoft.com/fwlink/?
LinkId=54896
[Current Users Search] :HKCU Default_Search_URL=""
[Current Users Search] :HKCU Search Page=http://go.microsoft.com/fwlink/?
LinkId=54896
[Current Users Search] :HKCU Search Bar=""
[IE Local Blank Page] :HKCU Local Page=%11%\blank.htm
[IE Local Blank Page] :HKLM Local Page=C:\Windows\SysWOW64\blank.htm
[Browser Helper Objects] {0055C089-8582-441B-A0BF-17B458C2A3A8}=C:\PROGRAM FILES
(X86)\INTERNET DOWNLOAD MANAGER\IDMIECC.DLL
### IDM Browser Helper Object Internet Download Manager, Tonec Inc. Internet
Download Manager Module 6, 28, 14, 1
[Browser Helper Objects] {18DF081C-E8AD-4283-A596-FA578C2EBDC3}=C:\PROGRAM FILES
(X86)\COMMON FILES\ADOBE\ACROBAT\ACTIVEX\ACROIEHELPERSHIM.DLL
### Adobe PDF Helper for Internet Explorer Adobe Systems Incorporated
AcroIEHelperShim Library 10.1.1.33
[Browser Helper Objects] {31D09BA0-12F5-4CCE-BE8A-2923E76605DA}=C:\PROGRAM FILES
(X86)\MICROSOFT OFFICE\OFFICE15\OCHELPER.DLL
### Microsoft Lync Microsoft Corporation Microsoft Office 2013 15.0.4420.1017
[Browser Helper Objects] {B4F3A835-0E21-4959-BA22-
42B3008E02FF}=C:\PROGRA~2\MICROS~1\OFFICE15\URLREDIR.DLL
### Microsoft Office Document Cache Handler Microsoft Corporation Microsoft
Office 2010 15.0.4420.1017
[Browser Helper Objects] {D0498E0A-45B7-42AE-A9AA-
ABA463DBD3BF}=C:\PROGRA~2\MICROS~1\OFFICE15\GROOVEEX.DLL
### Microsoft SkyDrive Pro Extensions Microsoft Corporation Microsoft Office 2013
15.0.4420.1017
[Browser Helper Objects(x64)] {0055C089-8582-441B-A0BF-17B458C2A3A8}=C:\PROGRAM
FILES (X86)\INTERNET DOWNLOAD MANAGER\IDMIECC64.DLL
### IDM Browser Helper Object Internet Download Manager, Tonec Inc. Internet
Download Manager Module 6, 28, 14, 1
[Browser Helper Objects(x64)] {31D09BA0-12F5-4CCE-BE8A-2923E76605DA}=C:\PROGRAM
FILES\MICROSOFT OFFICE\OFFICE15\OCHELPER.DLL
### Microsoft Lync Microsoft Corporation Microsoft Office 2013 15.0.4420.1017
[Browser Helper Objects(x64)] {B4F3A835-0E21-4959-BA22-
42B3008E02FF}=C:\PROGRA~1\MICROS~1\OFFICE15\URLREDIR.DLL
### Microsoft Office Document Cache Handler Microsoft Corporation Microsoft
Office 2010 15.0.4420.1017
[Browser Helper Objects(x64)] {D0498E0A-45B7-42AE-A9AA-
ABA463DBD3BF}=C:\PROGRA~1\MICROS~1\OFFICE15\GROOVEEX.DLL
### Microsoft SkyDrive Pro Extensions Microsoft Corporation Microsoft Office 2013
15.0.4420.1017
[Auto Search URL] :HKCU provider=""
[Auto Search URL] :HKCU "Default Value"=""
[Search Assistant] :HKCU SearchAssistant=""
[Search Assistant] :HKLM SearchAssistant=""
[Search Assistant] :HKCU CustomizeSearch=""
[Search Assistant] :HKLM CustomizeSearch=""
[Search Provider] {0633EE93-D776-472f-A0FF-
E1416B8B2E3A}=http://www.bing.com/search?q={searchTerms}&src=IE-
SearchBox&FORM=IESR02
### Bing
[Search Provider] DefaultScope={0633EE93-D776-472f-A0FF-E1416B8B2E3A}
[Search Provider for All Users] {0633EE93-D776-472f-A0FF-
E1416B8B2E3A}=http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
### Bing
[Search Provider for All Users] DefaultScope={0633EE93-D776-472f-A0FF-
E1416B8B2E3A}
[Search Provider for All Users(x64)] {0633EE93-D776-472f-A0FF-
E1416B8B2E3A}=http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
### Bing
[Search Provider for All Users(x64)] DefaultScope={0633EE93-D776-472f-A0FF-
E1416B8B2E3A}
[Search Provider(x64)] {0633EE93-D776-472f-A0FF-
E1416B8B2E3A}=http://www.bing.com/search?q={searchTerms}&src=IE-
SearchBox&FORM=IESR02
### Bing
[Search Provider(x64)] DefaultScope={0633EE93-D776-472f-A0FF-E1416B8B2E3A}
[CustomizeSearch] :HKLM CustomizeSearch=""
[URLSearchHook] :HKCU {CFBFAE00-17A6-11D0-99CB-
00C04FD64497}=C:\WINDOWS\SYSWOW64\IEFRAME.DLL
### Internet Browser Microsoft Corporation Internet Explorer 11.00.14393.1715
[Search URL Template] :HKLM 1=""
[Search URL Template] :HKLM 2=""
[Search URL Template] :HKLM 3=""
[Search URL Template] :HKLM 4=""
[Default Prefix] :HKLM "Default Value"=http://
[URL Default Prefixes] :HKLM ftp=ftp://
[URL Default Prefixes] :HKLM home=http://
[URL Default Prefixes] :HKLM mosaic=http://
[URL Default Prefixes] :HKLM www=http://
[AboutURLs] :HKLM blank=res://mshtml.dll/blank.htm
[AboutURLs] :HKLM DesktopItemNavigationFailure=res://ieframe.dll/navcancl.htm
[AboutURLs] :HKLM Home=270
[AboutURLs] :HKLM InPrivate=res://ieframe.dll/inprivate.htm
[AboutURLs] :HKLM NavigationCanceled=res://ieframe.dll/navcancl.htm
[AboutURLs] :HKLM NavigationFailure=res://ieframe.dll/navcancl.htm
[AboutURLs] :HKLM NoAdd-ons=res://ieframe.dll/noaddon.htm
[AboutURLs] :HKLM NoAdd-onsInfo=res://ieframe.dll/noaddoninfo.htm
[AboutURLs] :HKLM PostNotCached=res://ieframe.dll/repost.htm
[AboutURLs] :HKLM SecurityRisk=res://ieframe.dll/securityatrisk.htm
[User Style Sheet] :HKCU User Stylesheet=""
[User Style Sheet] :HKCU Use My Stylesheet=0
[Execute unsigned ActiveX in My Computer Zone] :HKCU 1201=0
[Execute unsigned ActiveX in My Computer Zone] :HKLM 1201=1
[Execute unsigned ActiveX in Local Intranet Zone] :HKCU 1201=0
[Execute unsigned ActiveX in Local Intranet Zone] :HKLM 1201=3
[Execute unsigned ActiveX in Internet Zone] :HKCU 1201=3
[Execute unsigned ActiveX in Internet Zone] :HKLM 1201=3
[Links Toolbar] :HKCU LinksFolderName=""
[IE Extensions - All Users] :HKLM {2670000A-7350-4f3c-8081-5663EE0C6C49}
### File is missing.
[IE Extensions - All Users] :HKLM {31D09BA0-12F5-4CCE-BE8A-
2923E76605DA}=C:\PROGRAM FILES (X86)\MICROSOFT OFFICE\OFFICE15\OCHELPER.DLL
### Microsoft Lync Microsoft Corporation Microsoft Office 2013 15.0.4420.1017
[IE Extensions - All Users] :HKLM {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}
### File is missing.
[Context menu items] :HKCU Download all links with IDM=C:\PROGRAM FILES
(X86)\INTERNET DOWNLOAD MANAGER\IEGETALL.HTM
[Context menu items] :HKCU Download with IDM=C:\PROGRAM FILES (X86)\INTERNET
DOWNLOAD MANAGER\IEEXT.HTM
[Context menu items] :HKCU E&xport to Microsoft Excel=res://C:\Program Files
(x86)\Microsoft Office\Office15\EXCEL.EXE/3000
### File is missing.
[Context menu items] :HKCU Se&nd to OneNote=res://C:\Program Files
(x86)\Microsoft Office\Office15\ONBttnIE.dll/105
### File is missing.
[AutoConfigURL] :HKCU AutoConfigURL=""
[Protocols Filter] :HKLM text/xml=C:\PROGRAM FILES (X86)\COMMON FILES\MICROSOFT
SHARED\OFFICE15\MSOXMLMF.DLL
### Microsoft Office XML MIME Filter Microsoft Corporation Microsoft Office
InfoPath 15.0.4420.1017
[Protocols Handler] :HKLM about=C:\WINDOWS\SYSWOW64\MSHTML.DLL
### Microsoft (R) HTML Viewer Microsoft Corporation Internet Explorer
11.00.14393.447
[Protocols Handler] :HKLM cdl=C:\WINDOWS\SYSWOW64\URLMON.DLL
### OLE32 Extensions for Win32 Microsoft Corporation Internet Explorer
11.00.14393.0
[Protocols Handler] :HKLM dvd=C:\WINDOWS\SYSWOW64\MSVIDCTL.DLL
### ActiveX control for streaming video Microsoft Corporation DirectShow
6.5.14393.0
[Protocols Handler] :HKLM file=C:\WINDOWS\SYSWOW64\URLMON.DLL
### OLE32 Extensions for Win32 Microsoft Corporation Internet Explorer
11.00.14393.0
[Protocols Handler] :HKLM ftp=C:\WINDOWS\SYSWOW64\URLMON.DLL
### OLE32 Extensions for Win32 Microsoft Corporation Internet Explorer
11.00.14393.0
[Protocols Handler] :HKLM http=C:\WINDOWS\SYSWOW64\URLMON.DLL
### OLE32 Extensions for Win32 Microsoft Corporation Internet Explorer
11.00.14393.0
[Protocols Handler] :HKLM https=C:\WINDOWS\SYSWOW64\URLMON.DLL
### OLE32 Extensions for Win32 Microsoft Corporation Internet Explorer
11.00.14393.0
[Protocols Handler] :HKLM its=C:\WINDOWS\SYSWOW64\ITSS.DLL
### Microsoft� InfoTech Storage System Library Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0
[Protocols Handler] :HKLM javascript=C:\WINDOWS\SYSWOW64\MSHTML.DLL
### Microsoft (R) HTML Viewer Microsoft Corporation Internet Explorer
11.00.14393.447
[Protocols Handler] :HKLM local=C:\WINDOWS\SYSWOW64\URLMON.DLL
### OLE32 Extensions for Win32 Microsoft Corporation Internet Explorer
11.00.14393.0
[Protocols Handler] :HKLM mailto=C:\WINDOWS\SYSWOW64\MSHTML.DLL
### Microsoft (R) HTML Viewer Microsoft Corporation Internet Explorer
11.00.14393.447
[Protocols Handler] :HKLM mhtml=C:\WINDOWS\SYSWOW64\INETCOMM.DLL
### Microsoft Internet Messaging API Resources Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.953
[Protocols Handler] :HKLM mk=C:\WINDOWS\SYSWOW64\URLMON.DLL
### OLE32 Extensions for Win32 Microsoft Corporation Internet Explorer
11.00.14393.0
[Protocols Handler] :HKLM ms-help=C:\PROGRAM FILES (X86)\COMMON FILES\MICROSOFT
SHARED\HELP\HXDS.DLL
### Microsoft� Help Data Services Module Microsoft Corporation Microsoft � Help
2.7 5.70.51021.0
[Protocols Handler] :HKLM ms-its=C:\WINDOWS\SYSWOW64\ITSS.DLL
### Microsoft� InfoTech Storage System Library Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0
[Protocols Handler] :HKLM osf=C:\PROGRAM FILES (X86)\MICROSOFT
OFFICE\OFFICE15\MSOSB.DLL
### Microsoft Office 2013 component Microsoft Corporation Microsoft Office 2013
15.0.4420.1017
[Protocols Handler] :HKLM res=C:\WINDOWS\SYSWOW64\MSHTML.DLL
### Microsoft (R) HTML Viewer Microsoft Corporation Internet Explorer
11.00.14393.447
[Protocols Handler] :HKLM tbauth=C:\WINDOWS\SYSWOW64\TBAUTH.DLL
### TBAuth protocol handler Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.953
[Protocols Handler] :HKLM tv=C:\WINDOWS\SYSWOW64\MSVIDCTL.DLL
### ActiveX control for streaming video Microsoft Corporation DirectShow
6.5.14393.0
[Protocols Handler] :HKLM vbscript=C:\WINDOWS\SYSWOW64\MSHTML.DLL
### Microsoft (R) HTML Viewer Microsoft Corporation Internet Explorer
11.00.14393.447
[Protocols Handler] :HKLM windows.tbauth=C:\WINDOWS\SYSWOW64\TBAUTH.DLL
### TBAuth protocol handler Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.953
[Proxy] :HKCU ProxyServer=http=127.0.0.1:8080;https=127.0.0.1:8080
[Proxy] :HKCU ProxyEnable=1
[Network Settings]
[Hosts File Path] :HKLM DataBasePath=%SystemRoot%\System32\drivers\etc
[Hosts File Contents] :HKLM 127.0.0.1 cpm.paneladmin.pro
[Hosts File Contents] :HKLM 127.0.0.1 publisher.hmdiadmingate.xyz
[Hosts File Contents] :HKLM 127.0.0.1 hmdicrewtracksystem.xyz
[Hosts File Contents] :HKLM 127.0.0.1 linkmate.space
[Hosts File Contents] :HKLM 127.0.0.1 space1.adminpressure.space
[Hosts File Contents] :HKLM 127.0.0.1 trackpressure.website
[Hosts File Contents] :HKLM 127.0.0.1 doctorlink.space
[Hosts File Contents] :HKLM 127.0.0.1 plugpackdownload.net
[Hosts File Contents] :HKLM 127.0.0.1 texttotalk.org
[Hosts File Contents] :HKLM 127.0.0.1 gambling577.xyz
[Hosts File Contents] :HKLM 127.0.0.1 htagdownload.space
[Hosts File Contents] :HKLM 127.0.0.1 mybcnmonetize.com
[Hosts File Contents] :HKLM 127.0.0.1 360devtraking.website
[Hosts File Contents] :HKLM 127.0.0.1 dscdn.pw
[Hosts File Contents] :HKLM 127.0.0.1 install.rgbcjfir.com
[Hosts File Contents] :HKLM 127.0.0.1 beautifllink.xyz
[Hosts File Contents] :HKLM 0.0.0.0 hao123.com
[Hosts File Contents] :HKLM 0.0.0.0 internetquickaccess.com
[Hosts File Contents] :HKLM 0.0.0.0 mypcbackup.com
[Hosts File Contents] :HKLM 0.0.0.0 12kotov.ru
[Hosts File Contents] :HKLM 0.0.0.0 hao.169x.cn
[Hosts File Contents] :HKLM 0.0.0.0 launchpage.org
[Hosts File Contents] :HKLM 0.0.0.0 onclkds.com
[Hosts File Contents] :HKLM 0.0.0.0 pcopysy.ru
[Hosts File Contents] :HKLM 0.0.0.0 ucozucoznet.ucoz.net
[Hosts File Contents] :HKLM 0.0.0.0 workno.ru
[Hosts File Contents] :HKLM 0.0.0.0 xvidvideocodecs.com
[Hosts File Contents] :HKLM 0.0.0.0 traffic-media.co
[Hosts File Contents] :HKLM 0.0.0.0 ladomainadeserver.com
[Hosts File Contents] :HKLM 0.0.0.0 laserveradedomaina.com
[Hosts File Contents] :HKLM 0.0.0.0 roastfiles2017.com
[Hosts File Contents] :HKLM 0.0.0.0 adsrvr.org
[Hosts File Contents] :HKLM 0.0.0.0 advertising.com
[Hosts File Contents] :HKLM 0.0.0.0 asedownloadgate.com
[Hosts File Contents] :HKLM 0.0.0.0 backupcdn.com
[Hosts File Contents] :HKLM 0.0.0.0 d3jx96othz2l8y.cloudfront.net
[Hosts File Contents] :HKLM 0.0.0.0 directdownloader.com
[Hosts File Contents] :HKLM 0.0.0.0 exelator.com
[Hosts File Contents] :HKLM 0.0.0.0 krxd.net
[Hosts File Contents] :HKLM 0.0.0.0 notatolol2.com
[Hosts File Contents] :HKLM 0.0.0.0 reimageplus.com
[Hosts File Contents] :HKLM 0.0.0.0 systemhealerhost.net
[Hosts File Contents] :HKLM 0.0.0.0 technologievimy.com
[Hosts File Contents] :HKLM 0.0.0.0 tremorhub.com
[Hosts File Contents] :HKLM 0.0.0.0 yeawindows.com
[Hosts File Contents] :HKLM 0.0.0.0 altocloudmedia.com
[Hosts File Contents] :HKLM 0.0.0.0 securestudies.com
[Hosts File Contents] :HKLM 0.0.0.0 coupplayoffgame.com
[Hosts File Contents] :HKLM 0.0.0.0 bestapps4ever161.download
[Hosts File Contents] :HKLM 0.0.0.0 cdndepot.com
[Hosts File Contents] :HKLM 0.0.0.0 samplehighz.net
[Hosts File Contents] :HKLM 0.0.0.0 reportsmaxis.com
[Hosts File Contents] :HKLM 0.0.0.0 azvjudwr.info
[Hosts File Contents] :HKLM 0.0.0.0 cnhv.co
[Hosts File Contents] :HKLM 0.0.0.0 coin-hive.com
[Hosts File Contents] :HKLM 0.0.0.0 gus.host
[Hosts File Contents] :HKLM 0.0.0.0 jroqvbvw.info
[Hosts File Contents] :HKLM 0.0.0.0 jsecoin.com
[Hosts File Contents] :HKLM 0.0.0.0 jyhfuqoh.info
[Hosts File Contents] :HKLM 0.0.0.0 kdowqlpt.info
[Hosts File Contents] :HKLM 0.0.0.0 listat.biz
[Hosts File Contents] :HKLM 0.0.0.0 lmodr.biz
[Hosts File Contents] :HKLM 0.0.0.0 mataharirama.xyz
[Hosts File Contents] :HKLM 0.0.0.0 minecrunch.co
[Hosts File Contents] :HKLM 0.0.0.0 minemytraffic.com
[Hosts File Contents] :HKLM 0.0.0.0 miner.pr0gramm.com
[Hosts File Contents] :HKLM 0.0.0.0 reasedoper.pw
[Hosts File Contents] :HKLM 0.0.0.0 xbasfbno.info
[Hosts File Contents] :HKLM 0.0.0.0 coinhive.com
[Hosts File Contents] :HKLM 0.0.0.0 crypto-loot.com
[Hosts File Contents] :HKLM 0.0.0.0 edgeno.de
[Hosts File Contents] :HKLM 0.0.0.0 2giga.link
[Hosts File Contents] :HKLM 0.0.0.0 ppoi.org
[Hosts File Contents] :HKLM 0.0.0.0 fbcdnxy.net
[Hosts File Contents] :HKLM 0.0.0.0 coinerra.com
[Hosts File Contents] :HKLM 0.0.0.0 kisshentai.net
[Hosts File Contents] :HKLM 0.0.0.0 kiwifarms.net
[Hosts File Contents] :HKLM 0.0.0.0 pr0gramm.com
[Hosts File Contents] :HKLM 0.0.0.0 minero.pw
[Hosts File Contents] :HKLM 0.0.0.0 anime.reactor.cc
[Hosts File Contents] :HKLM 0.0.0.0 goodolddownloads.com
[Hosts File Contents] :HKLM 0.0.0.0 hashforcash.us
[Hosts File Contents] :HKLM 0.0.0.0 joyreactor.cc
[Hosts File Contents] :HKLM 0.0.0.0 kissdoujin.com
[Hosts File Contents] :HKLM 0.0.0.0 oload.info
[Hosts File Contents] :HKLM 0.0.0.0 projectpoi.com
[Browsers]
[Installed Browsers] FIREFOX.EXE=C:\PROGRAM FILES (X86)\MOZILLA
FIREFOX\FIREFOX.EXE
### Default Browser
Firefox Mozilla Corporation Firefox 56.0
[Installed Browsers] IEXPLORE.EXE=C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
### Internet Explorer Microsoft Corporation Internet Explorer 11.00.14393.0
[FireFox Components and Extensions] idmmzcc3=C:\Program Files (x86)\Internet
Download Manager\idmmzcc3.xpi
### idmmzcc3
[FireFox Browser Features] activity-stream@mozilla.org=C:\Program Files
(x86)\Mozilla Firefox\browser\features\activity-stream@mozilla.org.xpi
### activity-stream@mozilla.org
[FireFox Browser Features] aushelper@mozilla.org=C:\Program Files (x86)\Mozilla
Firefox\browser\features\aushelper@mozilla.org.xpi
### aushelper@mozilla.org
[FireFox Browser Features] clicktoplay-rollout@mozilla.org=C:\Program Files
(x86)\Mozilla Firefox\browser\features\clicktoplay-rollout@mozilla.org.xpi
### clicktoplay-rollout@mozilla.org
[FireFox Browser Features] e10srollout@mozilla.org=C:\Program Files (x86)\Mozilla
Firefox\browser\features\e10srollout@mozilla.org.xpi
### e10srollout@mozilla.org
[FireFox Browser Features] firefox@getpocket.com=C:\Program Files (x86)\Mozilla
Firefox\browser\features\firefox@getpocket.com.xpi
### firefox@getpocket.com
[FireFox Browser Features] followonsearch@mozilla.com=C:\Program Files
(x86)\Mozilla Firefox\browser\features\followonsearch@mozilla.com.xpi
### followonsearch@mozilla.com
[FireFox Browser Features] formautofill@mozilla.org=C:\Program Files
(x86)\Mozilla Firefox\browser\features\formautofill@mozilla.org.xpi
### formautofill@mozilla.org
[FireFox Browser Features] onboarding@mozilla.org=C:\Program Files (x86)\Mozilla
Firefox\browser\features\onboarding@mozilla.org.xpi
### onboarding@mozilla.org
[FireFox Browser Features] screenshots@mozilla.org=C:\Program Files (x86)\Mozilla
Firefox\browser\features\screenshots@mozilla.org.xpi
### screenshots@mozilla.org
[FireFox Browser Features] shield-recipe-client@mozilla.org=C:\Program Files
(x86)\Mozilla Firefox\browser\features\shield-recipe-client@mozilla.org.xpi
### shield-recipe-client@mozilla.org
[FireFox Browser Features] webcompat@mozilla.org=C:\Program Files (x86)\Mozilla
Firefox\browser\features\webcompat@mozilla.org.xpi
### webcompat@mozilla.org
[Google Chrome Settings] :HKLM backup.homepage=""
[Google Chrome Settings] :HKLM backup.session.urls_to_restore_on_startup=""
[Google Chrome Settings] :HKLM session.startup_urls=""
[Google Chrome Settings] :HKLM default_search_provider.icon_url=""
[Google Chrome Settings] :HKLM default_search_provider.keyword=""
[Google Chrome Settings] :HKLM default_search_provider.name=""
[Google Chrome Settings] :HKLM default_search_provider.search_url=""
[Google Chrome Settings] :HKLM default_search_provider.suggest_url=""
[Google Chrome Settings] :HKLM
default_search_provider_data.template_url_data.alternate_urls=""
[Google Chrome Settings] :HKLM
default_search_provider_data.template_url_data.favicon_url=""
[Google Chrome Settings] :HKLM
default_search_provider_data.template_url_data.keyword=""
[Google Chrome Settings] :HKLM
default_search_provider_data.template_url_data.short_name=""
[Google Chrome Settings] :HKLM
default_search_provider_data.template_url_data.url=""
[Google Chrome Settings] :HKLM
default_search_provider_data.template_url_data.suggest_url=""
[Google Chrome Settings] :HKLM
default_search_provider_data.template_url_data.new_tab_url=""
[Google Chrome Settings] :HKLM
default_search_provider_data.template_url_data.instant_url=""
[Google Chrome Settings] :HKLM
default_search_provider_data.template_url_data.image_url=""
[Google Chrome Settings] :HKLM homepage=""
[Google Chrome Settings] :HKLM session.urls_to_restore_on_startup=""
[Google Chrome Addons]
aohghmighlieiainnegkcijnfilokake=C:\Users\USER\AppData\Local\Google\Chrome\User
Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.0.0.6_0
### Docs: Disabled
update_url: http://clients2.google.com/service/update2/crx
[Google Chrome Addons]
apdfllckaahabafndbhieahigkjlhalf=C:\Users\USER\AppData\Local\Google\Chrome\User
Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0
### : Disabled
update_url: http://clients2.google.com/service/update2/crx
[Google Chrome Addons]
blpcfgokakmgnkcojhhkbfbldkacnbeo=C:\Users\USER\AppData\Local\Google\Chrome\User
Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0
### : Disabled
update_url: http://clients2.google.com/service/update2/crx
[Google Chrome Addons]
coobgpohoikkiipiblmjeljniedjpjpf=C:\Users\USER\AppData\Local\Google\Chrome\User
Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0
### : Disabled
update_url: http://clients2.google.com/service/update2/crx
[Google Chrome Addons]
fngmhnnpilhplaeedifhccceomclgfbg=C:\Users\USER\AppData\Local\Google\Chrome\User
Data\Default\Extensions\fngmhnnpilhplaeedifhccceomclgfbg\78.0_0
### Tables: Disabled
update_url: https://clients2.google.com/service/update2/crx
[Google Chrome Addons]
pjkljhegncpnkpknbcohdijeoejaedia=C:\Users\USER\AppData\Local\Google\Chrome\User
Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0
### : Disabled
update_url: http://clients2.google.com/service/update2/crx
[Google Chrome Addons] ngpampappnmepgilojfohadhhmbhlaek=C:\PROGRAM FILES
(X86)\INTERNET DOWNLOAD MANAGER\IDMGCEXT.CRX
[Pre-installed extensions] :HKLM ngpampappnmepgilojfohadhhmbhlaek=C:\Program
Files (x86)\Internet Download Manager\IDMGCExt.crx
### 6.28.15 !$*C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx
[Network Settings]
[Domain Name] :HKLM Domain=""
[Name Server] {49893035-8668-4ce4-8892-55bb0b1b8cea}=192.168.43.1
### DHCPNameServer:192.168.43.1 DhcpDefaultGateway:192.168.43.1
DhcpServer:192.168.43.1
[WinSock2 Components] napinsp.dll=C:\WINDOWS\SYSWOW64\NAPINSP.DLL
### E-mail Naming Shim Provider Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SystemRoot%\SYSWOW64\napinsp.dll
[WinSock2 Components] pnrpnsp.dll=C:\WINDOWS\SYSWOW64\PNRPNSP.DLL
### PNRP Name Space Provider Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%SystemRoot%\SYSWOW64\pnrpnsp.dll
[WinSock2 Components] NLAapi.dll=C:\WINDOWS\SYSWOW64\NLAAPI.DLL
### Network Location Awareness 2 Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SystemRoot%\SYSWOW64\NLAapi.dll
[WinSock2 Components] mswsock.dll=C:\WINDOWS\SYSWOW64\MSWSOCK.DLL
### Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation
Microsoft� Windows� Operating System 10.0.14393.0 !$*%SystemRoot
%\SYSWOW64\mswsock.dll
[WinSock2 Components] winrnr.dll=C:\WINDOWS\SYSWOW64\WINRNR.DLL
### LDAP RnR Provider DLL Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%SystemRoot%\SYSWOW64\winrnr.dll
[WinSock2 Components] wshbth.dll=C:\WINDOWS\SYSWOW64\WSHBTH.DLL
### Windows Sockets Helper DLL Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SystemRoot%\SYSWOW64\wshbth.dll
[WinSock2 Components (x64)]
Mswapi64.dll=C:\ProgramData\Windows\SYSNATIVE\Mswapi64.dll
### File is missing.
[WinSock2 Components (x64)] napinsp.dll=C:\WINDOWS\SYSNATIVE\NAPINSP.DLL
### E-mail Naming Shim Provider Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SystemRoot%\SYSNATIVE\napinsp.dll
[WinSock2 Components (x64)] pnrpnsp.dll=C:\WINDOWS\SYSNATIVE\PNRPNSP.DLL
### PNRP Name Space Provider Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%SystemRoot%\SYSNATIVE\pnrpnsp.dll
[WinSock2 Components (x64)] NLAapi.dll=C:\WINDOWS\SYSNATIVE\NLAAPI.DLL
### Network Location Awareness 2 Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SystemRoot%\SYSNATIVE\NLAapi.dll
[WinSock2 Components (x64)] mswsock.dll=C:\WINDOWS\SYSNATIVE\MSWSOCK.DLL
### Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation
Microsoft� Windows� Operating System 10.0.14393.0 !$*%SystemRoot
%\SYSNATIVE\mswsock.dll
[WinSock2 Components (x64)] winrnr.dll=C:\WINDOWS\SYSNATIVE\WINRNR.DLL
### LDAP RnR Provider DLL Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%SystemRoot%\SYSNATIVE\winrnr.dll
[WinSock2 Components (x64)] wshbth.dll=C:\WINDOWS\SYSNATIVE\WSHBTH.DLL
### Windows Sockets Helper DLL Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SystemRoot%\SYSNATIVE\wshbth.dll
[Windows Shell]
[Display Scrap's Extensions] :HKLM NeverShowExt=""
[ScreenSaver] :HKCU SCRNSAVE.EXE=""
### File is missing.
[System.ini] shell=explorer.exe
[User Shell] :HKCU shell=""
[Internet Shortcuts] :HKLM C:\Users\USER\Desktop\Play
Warframe.lnk=HTTP://WAIT3SEC.ORG/WARFRAMEWW
### C:\Users\USER\Desktop\PLAYWA~1.LNK
[User Shortcuts] :HKLM C:\Users\USER\Desktop\Excel 2013.lnk=C:\WINDOWS\INSTALLER\
{90150000-0011-0000-0000-0000000FF1CE}\XLICONS.EXE
### !$*C:\Users\USER\Desktop\EXCEL2~1.LNK
[User Shortcuts] :HKLM C:\Users\USER\Desktop\Google
Chrome.lnk=C:\USERS\USER\APPDATA\LOCAL\GOOGLE\CHROME\APPLICATION\CHROME.EXE
### Google Chrome Google Inc. Google Chrome 28.0.1500.72 !
$*C:\Users\USER\Desktop\GOOGLE~1.LNK ?--disable-quic
[User Shortcuts] :HKLM C:\Users\USER\Desktop\Internet Download
Manager.lnk=C:\PROGRAM FILES (X86)\INTERNET DOWNLOAD MANAGER\IDMAN.EXE
### Internet Download Manager (IDM) Tonec Inc. Internet Download Manager (IDM) 6,
28, 15, 3 !$*C:\Users\USER\Desktop\INTERN~1.LNK
[User Shortcuts] :HKLM C:\Users\USER\Desktop\KeyboardTest.lnk=C:\PROGRAM
FILES\KEYBOARDTEST\KEYBOARDTEST.EXE
### KeyboardTest PassMark Software (www.passmark.com) PassMark Software filter
3.1.0.1000 !$*C:\Users\USER\Desktop\KEYBOA~1.LNK
[User Shortcuts] :HKLM
C:\Users\USER\Desktop\KMPlayer.lnk=C:\KMPLAYER\KMPLAYER.EXE
### The KMPlayer PandoraTV The KMPlayer 4.0.0.0 !
$*C:\Users\USER\Desktop\KMPlayer.lnk
[User Shortcuts] :HKLM C:\Users\USER\Desktop\Plumbytes Anti-
Malware.lnk=C:\PROGRAM FILES\PLUMBYTES SOFTWARE\PLUMBYTES ANTI-
MALWARE\PLUMBYTES.EXE
### Anti-Malware Anti-Malware Anti-Malware 1.0.0.0 !
$*C:\Users\USER\Desktop\PLUMBY~1.LNK
[User Shortcuts] :HKLM C:\Users\USER\Desktop\Start Tor
Browser.lnk=C:\USERS\USER\DESKTOP\TOR BROWSER\BROWSER\FIREFOX.EXE
### Tor Browser Mozilla Corporation Tor Browser 45.8.0 !
$*C:\Users\USER\Desktop\STARTT~1.LNK
[User Shortcuts] :HKLM C:\Users\USER\Desktop\Tor Browser\Start Tor
Browser.lnk=C:\USERS\USER\DESKTOP\TOR BROWSER\BROWSER\FIREFOX.EXE
### Tor Browser Mozilla Corporation Tor Browser 45.8.0 !
$*C:\Users\USER\Desktop\TORBRO~1\STARTT~1.LNK
[User Shortcuts] :HKLM C:\Users\USER\Desktop\UnHackMe.lnk=C:\PROGRAM FILES
(X86)\UNHACKME\UNHACKME.EXE
### Detects and removes rootkits Greatis Software UnHackMe 9.30 !
$*C:\Users\USER\Desktop\UnHackMe.lnk
[User Shortcuts] :HKLM C:\Users\USER\Desktop\Windows 10 Upgrade
Assistant.lnk=C:\WINDOWS10UPGRADE\WINDOWS10UPGRADERAPP.EXE
### Windows 10 Upgrade Assistant Microsoft Corporation Windows 10 Upgrade
Assistant 1.4.9200.17364 !$*C:\Users\USER\Desktop\WINDOW~1.LNK ?/ClientID
"Win10Upgrade:VNL:Hadron5:{}"
[User Shortcuts] :HKLM C:\Users\Public\Desktop\Adobe Photoshop CS5.lnk=C:\PROGRAM
FILES (X86)\FOROOZANI SOFTWARE\ADOBE PHOTOSHOP CS5\PHOTOSHOP.EXE
### Adobe Photoshop CS5 Adobe Systems, Incorporated Adobe Photoshop CS5 CS5 !
$*C:\Users\Public\Desktop\ADOBEP~1.LNK
[User Shortcuts] :HKLM C:\Users\Public\Desktop\Adobe Reader X.lnk=C:\PROGRAM
FILES (X86)\ADOBE\READER 10.0\READER\ACRORD32.EXE
### Adobe Reader Adobe Systems Incorporated Adobe Reader 10.1.1.33 !
$*C:\Users\Public\Desktop\ADOBER~1.LNK
[User Shortcuts] :HKLM C:\Users\Public\Desktop\CyberLink YouCam.lnk=C:\PROGRAM
FILES (X86)\CYBERLINK\YOUCAM\YOUCAM.EXE
### YouCam CyberLink Corp. YouCam 4.0.0.0820 !
$*C:\Users\Public\Desktop\CYBERL~1.LNK
[User Shortcuts] :HKLM C:\Users\Public\Desktop\GOM Player.lnk=C:\PROGRAM FILES
(X86)\GRETECH\GOMPLAYER\GOM.EXE
### GOM Player Gretech Corp. GOM Player 2, 2, 62 5207 !
$*C:\Users\Public\Desktop\GOMPLA~1.LNK
[User Shortcuts] :HKLM C:\Users\Public\Desktop\Mozilla Firefox.lnk=C:\PROGRAM
FILES (X86)\MOZILLA FIREFOX\FIREFOX.EXE
### Firefox Mozilla Corporation Firefox 56.0 !
$*C:\Users\Public\Desktop\MOZILL~1.LNK
[User Shortcuts] :HKLM C:\Users\Public\Desktop\Nero Home.lnk=C:\PROGRAM FILES
(X86)\NERO\NERO 7\NERO HOME\NEROHOME.EXE
### Nero Home Nero AG Nero Home 2,0,16,0 !
$*C:\Users\Public\Desktop\NEROHO~1.LNK ?-ScParameter=8
[User Shortcuts] :HKLM C:\Users\Public\Desktop\Nero StartSmart.lnk=C:\PROGRAM
FILES (X86)\NERO\NERO 7\NERO STARTSMART\NEROSTARTSMART.EXE
### Nero StartSmart Nero AG Nero StartSmart 3, 10, 1, 0 !
$*C:\Users\Public\Desktop\NEROST~1.LNK ?-ScParameter=8
[User Shortcuts] :HKLM C:\Users\Public\Desktop\TELKOMSELFlash.lnk=C:\PROGRAM
FILES (X86)\TELKOMSELFLASH\TELKOMSELFLASH.EXE
### !$*C:\Users\Public\Desktop\TELKOM~1.LNK
[User Shortcuts] :HKLM C:\Users\Public\Desktop\VLC media player.lnk=C:\PROGRAM
FILES (X86)\VIDEOLAN\VLC\VLC.EXE
### !$*C:\Users\Public\Desktop\VLCMED~1.LNK
[User Shortcuts] :HKLM C:\Users\Public\Desktop\Winamp.lnk=C:\PROGRAM FILES
(X86)\WINAMP\WINAMP.EXE
### Winamp Nullsoft, Inc. Winamp 5.5.8.2985 !$*C:\Users\Public\Desktop\Winamp.lnk
[User Shortcuts] :HKLM C:\Users\USER\AppData\Roaming\Microsoft\Internet
Explorer\Quick Launch\GOM Player.lnk=C:\PROGRAM FILES
(X86)\GRETECH\GOMPLAYER\GOM.EXE
### GOM Player Gretech Corp. GOM Player 2, 2, 62 5207 !
$*C:\Users\USER\AppData\Roaming\MICROS~1\INTERN~1\QUICKL~1\GOMPLA~1.LNK
[User Shortcuts] :HKLM C:\Users\USER\AppData\Roaming\Microsoft\Internet
Explorer\Quick Launch\Google
Chrome.lnk=C:\USERS\USER\APPDATA\LOCAL\GOOGLE\CHROME\APPLICATION\CHROME.EXE
### Google Chrome Google Inc. Google Chrome 28.0.1500.72 !
$*C:\Users\USER\AppData\Roaming\MICROS~1\INTERN~1\QUICKL~1\GOOGLE~1.LNK ?--disable-
quic
[User Shortcuts] :HKLM C:\Users\USER\AppData\Roaming\Microsoft\Internet
Explorer\Quick Launch\Nero Home.lnk=C:\PROGRAM FILES (X86)\NERO\NERO 7\NERO
HOME\NEROHOME.EXE
### Nero Home Nero AG Nero Home 2,0,16,0 !
$*C:\Users\USER\AppData\Roaming\MICROS~1\INTERN~1\QUICKL~1\NEROHO~1.LNK ?-
ScParameter=8
[User Shortcuts] :HKLM C:\Users\USER\AppData\Roaming\Microsoft\Internet
Explorer\Quick Launch\Nero StartSmart.lnk=C:\PROGRAM FILES (X86)\NERO\NERO 7\NERO
STARTSMART\NEROSTARTSMART.EXE
### Nero StartSmart Nero AG Nero StartSmart 3, 10, 1, 0 !
$*C:\Users\USER\AppData\Roaming\MICROS~1\INTERN~1\QUICKL~1\NEROST~1.LNK ?-
ScParameter=8
[User Shortcuts] :HKLM C:\Users\USER\AppData\Roaming\Microsoft\Internet
Explorer\Quick Launch\User Pinned\StartMenu\Mozilla Firefox.lnk=C:\PROGRAM FILES
(X86)\MOZILLA FIREFOX\FIREFOX.EXE
### Firefox Mozilla Corporation Firefox 56.0 !
$*C:\Users\USER\AppData\Roaming\MICROS~1\INTERN~1\QUICKL~1\USERPI~1\STARTM~1\MOZILL
~1.LNK
[User Shortcuts] :HKLM C:\Users\USER\AppData\Roaming\Microsoft\Internet
Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk=C:\PROGRAM FILES
(X86)\MOZILLA FIREFOX\FIREFOX.EXE
### Firefox Mozilla Corporation Firefox 56.0 !
$*C:\Users\USER\AppData\Roaming\MICROS~1\INTERN~1\QUICKL~1\USERPI~1\TaskBar\MOZILL~
1.LNK
[User Shortcuts] :HKLM C:\Users\USER\AppData\Roaming\Microsoft\Internet
Explorer\Quick Launch\Winamp.lnk=C:\PROGRAM FILES (X86)\WINAMP\WINAMP.EXE
### Winamp Nullsoft, Inc. Winamp 5.5.8.2985 !
$*C:\Users\USER\AppData\Roaming\MICROS~1\INTERN~1\QUICKL~1\Winamp.lnk
[User Shortcuts] :HKLM C:\ProgramData\Microsoft\Windows\Start
Menu\Programs\Internet Download Manager\Internet Download Manager.lnk=C:\PROGRAM
FILES (X86)\INTERNET DOWNLOAD MANAGER\IDMAN.EXE
### Internet Download Manager (IDM) Tonec Inc. Internet Download Manager (IDM) 6,
28, 15, 3 !$*C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\INTERN~1\INTERN~1.LNK
[User Shortcuts] :HKLM C:\ProgramData\Microsoft\Windows\Start
Menu\Programs\Mozilla Firefox.lnk=C:\PROGRAM FILES (X86)\MOZILLA
FIREFOX\FIREFOX.EXE
### Firefox Mozilla Corporation Firefox 56.0 !
$*C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\MOZILL~1.LNK
[Main File Extensions] :HKLM .exe=""
[Main File Extensions] :HKLM .com=""
[Main File Extensions] :HKLM .pif=""
[Main File Extensions] :HKLM .bat=""
[Main File Extensions] :HKLM .cmd=""
[Main File Extensions] :HKLM .scr=""
[Main File Extensions] :HKLM .txt=""
[Main File Extensions] :HKLM .reg=""
[Main File Extensions] :HKLM .inf=""
[Main File Extensions] :HKLM .ini=""
[Main File Extensions] :HKLM .js=""
[Main File Extensions] :HKLM .vbs=""
[Main File Extensions] :HKLM .vbe=""
[Main File Extensions] :HKLM .msc=""
[Main File Extensions] :HKLM .jpg=""
[Main File Extensions] :HKLM .jpeg=""
[Main File Extensions] :HKLM .gif=""
[Main File Extensions] :HKLM .png=""
[UserInit Value] UserInit=C:\WINDOWS\system32\userinit.exe,
### Userinit Logon Application Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0
[UserInit Value(x64)] UserInit=C:\Windows\system32\userinit.exe,
### Userinit Logon Application Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0
[Shell Services DelayLoad] :HKLM WebCheck={E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[System Shell Policies ] :HKCU shell=""
[System Shell Policies ] :HKLM shell=""
[System Shell Policies ] :HKCU run=""
[System Shell Policies ] :HKLM run=""
[Prevents Display in Control Panel from running.] :HKCU NoDispCpl=0
[Disable Registry Tools] :HKCU DisableRegistryTools =0
[Print Monitors] :HKLM Canon BJ Language Monitor iP2700
series=C:\WINDOWS\SYSTEM32\CNMLMA4.DLL
### IJ Language Monitor CANON INC. Canon IJ Printer Driver 2.56.2.10 !
$*CNMLMA4.DLL
[Print Monitors] :HKLM EPSON L210 Series
64MonitorBE=C:\WINDOWS\SYSTEM32\E_YLMI2E.DLL
### EPSON Bi-directional Monitor AMD64 SEIKO EPSON CORPORATION EPSON Bi-
directional Printer 3,03, 0, 0 !$*E_YLMI2E.DLL
[Print Monitors] :HKLM Local Port=C:\WINDOWS\SYSTEM32\LOCALSPL.DLL
### Local Spooler DLL Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.1715 !$*localspl.dll
[Print Monitors] :HKLM Microsoft Shared Fax
Monitor=C:\WINDOWS\SYSTEM32\FXSMON.DLL
### Microsoft Fax Print Monitor Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*FXSMON.DLL
[Print Monitors] :HKLM Standard TCP/IP Port=C:\WINDOWS\SYSTEM32\TCPMON.DLL
### Standard TCP/IP Port Monitor DLL Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*tcpmon.dll
[Print Monitors] :HKLM USB Monitor=C:\WINDOWS\SYSTEM32\USBMON.DLL
### Standard Dynamic Printing Port Monitor DLL Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 !$*usbmon.dll
[Print Monitors] :HKLM WSD Port=C:\WINDOWS\SYSTEM32\WSDMON.DLL
### WSD Printer Port Monitor Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*WSDMon.dll
[Shell Icon Overlay Handlers] :HKLM OneDrive1={BBACC218-34EA-4666-9D7A-
C78F2274A524}
[Shell Icon Overlay Handlers] :HKLM OneDrive2={5AB7172C-9C11-405C-8DD5-
AF20F3606282}
[Shell Icon Overlay Handlers] :HKLM OneDrive3={A78ED123-AB77-406B-9962-
2A5D9D2F7F30}
[Shell Icon Overlay Handlers] :HKLM OneDrive4={F241C880-6982-4CE5-8CF7-
7085BA96DA5A}
[Shell Icon Overlay Handlers] :HKLM OneDrive5={A0396A93-DC06-4AEF-BEE9-
95FFCCAEF20E}
[Shell Icon Overlay Handlers] :HKLM SkyDrivePro1
(ErrorConflict)=C:\PROGRA~2\MICROS~1\OFFICE15\GROOVEEX.DLL
### Microsoft SkyDrive Pro Extensions Microsoft Corporation Microsoft Office 2013
15.0.4420.1017
[Shell Icon Overlay Handlers] :HKLM SkyDrivePro2
(SyncInProgress)=C:\PROGRA~2\MICROS~1\OFFICE15\GROOVEEX.DLL
### Microsoft SkyDrive Pro Extensions Microsoft Corporation Microsoft Office 2013
15.0.4420.1017
[Shell Icon Overlay Handlers] :HKLM SkyDrivePro3
(InSync)=C:\PROGRA~2\MICROS~1\OFFICE15\GROOVEEX.DLL
### Microsoft SkyDrive Pro Extensions Microsoft Corporation Microsoft Office 2013
15.0.4420.1017
[Context Menu Handlers] :HKLM BriefcaseMenu=C:\WINDOWS\SYSTEM32\SYNCUI.DLL
### Windows Briefcase Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*%SystemRoot%\system32\syncui.dll
[Context Menu Handlers] :HKLM Cover Designer=C:\PROGRAM FILES (X86)\NERO\NERO
7\NERO COVERDESIGNER\COVEREDEXTENSION.DLL
### Cover Designer Nero AG Cover Designer 2, 10, 1, 1
[Context Menu Handlers] :HKLM EPP={09A47860-11B0-4DA5-AFA5-26D86198A780}
[Context Menu Handlers] :HKLM Open With=C:\WINDOWS\SYSTEM32\SHELL32.DLL
### Windows Shell Common Dll Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%SystemRoot%\system32\shell32.dll
[Context Menu Handlers] :HKLM Open With
EncryptionMenu=C:\WINDOWS\SYSTEM32\SHELL32.DLL
### Windows Shell Common Dll Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%SystemRoot%\system32\shell32.dll
[Context Menu Handlers] :HKLM Sharing=C:\WINDOWS\SYSTEM32\NTSHRUI.DLL
### Shell extensions for sharing Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SystemRoot%\system32\ntshrui.dll
[Context Menu Handlers] :HKLM WinRAR={B41DB860-64E4-11D2-9906-E49FADC173CA}
[Context Menu Handlers] :HKLM WorkFolders={E61BF828-5E63-4287-BEF1-60B1A4FDE0E3}
[Context Menu Handlers] :HKLM {90AA3A4E-1CBA-4233-B8BB-
535773D48449}=C:\WINDOWS\SYSTEM32\SHELL32.DLL
### Windows Shell Common Dll Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%SystemRoot%\system32\shell32.dll
[Context Menu Handlers] :HKLM {a2a9545d-a0c2-42b4-9708-
a0b2badd77c8}=C:\WINDOWS\SYSTEM32\SHELL32.DLL
### Windows Shell Common Dll Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%SystemRoot%\system32\shell32.dll
[Context Menu Handlers] :HKLM {EB4D3CFE-E2AA-4C6E-B2FE-2A749F95D208}=C:\PROGRAM
FILES (X86)\NERO\NERO 7\NERO BACKITUP\NBSHELL.DLL
### Nero BackItUp Nero AG Nero BackItUp 2, 10, 3, 2
[App Paths] :HKLM AcroRd32.exe=C:\Program Files (x86)\Adobe\Reader
10.0\Reader\AcroRd32.exe
### AcroRd32.exe Adobe Reader Adobe Systems Incorporated Adobe Reader 10.1.1.33
[App Paths] :HKLM BackItUp.exe=C:\Program Files (x86)\Nero\Nero 7\Nero
BackItUp\BackItUp.exe
### BackItUp.exe Nero BackItUp Nero AG Nero BackItUp 2, 10, 3, 2
[App Paths] :HKLM cmmgr32.exe
### cmmgr32.exe
[App Paths] :HKLM dfshim.dll
### dfshim.dll
[App Paths] :HKLM excel.exe=C:\PROGRA~2\MICROS~1\Office15\EXCEL.EXE
### excel.exe Microsoft Excel Microsoft Corporation Microsoft Office 2013
15.0.4420.1017
[App Paths] :HKLM firefox.exe=C:\Program Files (x86)\Mozilla Firefox\firefox.exe
### firefox.exe Firefox Mozilla Corporation Firefox 56.0
[App Paths] :HKLM fsquirt.exe
### fsquirt.exe
[App Paths] :HKLM GOM.EXE=C:\Program Files (x86)\GRETECH\GomPlayer\GOM.EXE
### GOM.EXE GOM Player Gretech Corp. GOM Player 2, 2, 62 5207
[App Paths] :HKLM GROOVE.EXE=C:\PROGRA~2\MICROS~1\Office15\GROOVE.EXE
### GROOVE.EXE Microsoft SkyDrive Pro Microsoft Corporation Microsoft Office 2013
15.0.4420.1017
[App Paths] :HKLM IEDIAG.EXE=C:\Program Files\Internet Explorer\IEDIAGCMD.EXE
### IEDIAG.EXE Diagnostics utility for Internet Explorer Microsoft Corporation
Internet Explorer 11.00.14393.479
[App Paths] :HKLM IEDIAGCMD.EXE=C:\Program Files\Internet Explorer\IEDIAGCMD.EXE
### IEDIAGCMD.EXE Diagnostics utility for Internet Explorer Microsoft Corporation
Internet Explorer 11.00.14393.479
[App Paths] :HKLM IEXPLORE.EXE=C:\Program Files\Internet Explorer\IEXPLORE.EXE
### IEXPLORE.EXE Internet Explorer Microsoft Corporation Internet Explorer
11.00.14393.0
[App Paths] :HKLM infopath.exe=C:\PROGRA~2\MICROS~1\Office15\INFOPATH.EXE
### infopath.exe Microsoft InfoPath Microsoft Corporation Microsoft Office
InfoPath 15.0.4420.1017
[App Paths] :HKLM install.exe
### install.exe
[App Paths] :HKLM KMPlayer.exe=C:\KMPlayer\KMPlayer.exe
### KMPlayer.exe The KMPlayer PandoraTV The KMPlayer 4.0.0.0
[App Paths] :HKLM licensemanagershellext.exe=%SystemRoot
%\System32\licensemanagershellext.exe
### licensemanagershellext.exe
[App Paths] :HKLM Lync.exe=C:\Program Files (x86)\Microsoft
Office\Office15\Lync.exe
### Lync.exe Microsoft Lync Microsoft Corporation Microsoft Office 2013
15.0.4420.1017
[App Paths] :HKLM mip.exe=%CommonProgramFiles%\Microsoft Shared\Ink\mip.exe
### mip.exe
[App Paths] :HKLM mplayer2.exe=%ProgramFiles(x86)%\Windows Media
Player\wmplayer.exe
### mplayer2.exe
[App Paths] :HKLM MSACCESS.EXE=C:\PROGRA~2\MICROS~1\Office15\MSACCESS.EXE
### MSACCESS.EXE Microsoft Access Microsoft Corporation Microsoft Office 2013
15.0.4420.1017
[App Paths] :HKLM MsoHtmEd.exe
### MsoHtmEd.exe
[App Paths] :HKLM msoxmled.exe=C:\Program Files (x86)\Common Files\Microsoft
Shared\OFFICE15\MSOXMLED.EXE
### msoxmled.exe Office XML Handler Microsoft Corporation Microsoft Office
InfoPath 15.0.4420.1017
[App Paths] :HKLM MSPUB.EXE=C:\PROGRA~2\MICROS~1\Office15\MSPUB.EXE
### MSPUB.EXE Microsoft Publisher Microsoft Corporation Microsoft Office 2013
15.0.4420.1017
[App Paths] :HKLM NCoverEd.exe=C:\Program Files (x86)\Nero\Nero 7\Nero
CoverDesigner\CoverDes.exe
### NCoverEd.exe Cover Designer Nero AG Cover Designer 2, 10, 1, 1
[App Paths] :HKLM Nero.exe=C:\Program Files (x86)\Nero\Nero 7\Core\Nero.exe
### Nero.exe Nero Burning ROM Nero AG Nero Burning ROM 7, 10, 1, 0
[App Paths] :HKLM NeroBurnRights.exe=C:\Program Files (x86)\Nero\Nero 7\Nero
Toolkit\NeroBurnRights.exe
### NeroBurnRights.exe Nero BurnRights Control Panel Nero AG Nero BurnRights
2.1.0.10
[App Paths] :HKLM NeroHome.exe=C:\Program Files (x86)\Nero\Nero 7\Nero
Home\NeroHome.exe
### NeroHome.exe Nero Home Nero AG Nero Home 2,0,16,0
[App Paths] :HKLM NeroMediaHome.exe=C:\Program Files (x86)\Nero\Nero 7\Nero
MediaHome\NeroMediaHome.exe
### NeroMediaHome.exe Nero MediaHome Nero AG Nero MediaHome 2,5,16,0
[App Paths] :HKLM NeroVision.exe=C:\Program Files (x86)\Nero\Nero 7\Nero
Vision\NeroVision.exe
### NeroVision.exe Nero Vision Nero AG Nero Vision 4,9,7,2
[App Paths] :HKLM OneNote.exe=C:\PROGRA~2\MICROS~1\Office15\ONENOTE.EXE
### OneNote.exe Microsoft OneNote Microsoft Corporation Microsoft OneNote
15.0.4420.1017
[App Paths] :HKLM OUTLOOK.EXE=C:\PROGRA~2\MICROS~1\Office15\OUTLOOK.EXE
### OUTLOOK.EXE Microsoft Outlook Microsoft Corporation Microsoft Outlook
15.0.4420.1017
[App Paths] :HKLM pbrush.exe=%SystemRoot%\System32\mspaint.exe
### pbrush.exe
[App Paths] :HKLM PhotoSnapViewer.exe=C:\Program Files (x86)\Nero\Nero 7\Nero
PhotoSnap\PhotoSnapViewer.exe
### PhotoSnapViewer.exe Nero Photosnap Image Viewer Nero AG Nero Photosnap Viewer
1, 2, 0, 25
[App Paths] :HKLM powerpnt.exe=C:\PROGRA~2\MICROS~1\Office15\POWERPNT.EXE
### powerpnt.exe Microsoft PowerPoint Microsoft Corporation Microsoft Office 2013
15.0.4420.1017
[App Paths] :HKLM PowerShell.exe=%SystemRoot
%\system32\WindowsPowerShell\v1.0\PowerShell.exe
### PowerShell.exe
[App Paths] :HKLM Recode.exe=C:\Program Files (x86)\Nero\Nero 7\Nero
Recode\Recode.exe
### Recode.exe Nero Recode 2 Nero AG Nero Recode 2 2, 5, 5, 0
[App Paths] :HKLM setup.exe
### setup.exe
[App Paths] :HKLM ShowTime.exe=C:\Program Files (x86)\Nero\Nero 7\Nero
ShowTime\ShowTime.exe
### ShowTime.exe Nero ShowTime Nero AG Nero ShowTime 3, 10, 1, 0
[App Paths] :HKLM SnippingTool.exe=%SystemRoot%\system32\SnippingTool.exe
### SnippingTool.exe
[App Paths] :HKLM SoundTrax.exe=C:\Program Files (x86)\Nero\Nero 7\Nero
SoundTrax\SoundTrax.exe
### SoundTrax.exe Nero SoundTrax Nero AG Nero SoundTrax 2, 10, 1, 0
[App Paths] :HKLM table30.exe
### table30.exe
[App Paths] :HKLM TabTip.exe=%CommonProgramFiles%\microsoft shared\ink\TabTip.exe
### TabTip.exe
[App Paths] :HKLM TELKOMSELFlash.exe=C:\Program Files
(x86)\TELKOMSELFlash\TELKOMSELFlash.exe
### TELKOMSELFlash.exe
[App Paths] :HKLM vstoee.dll
### vstoee.dll
[App Paths] :HKLM wab.exe=%ProgramFiles%\Windows Mail\wab.exe
### wab.exe
[App Paths] :HKLM wabmig.exe=%ProgramFiles%\Windows Mail\wabmig.exe
### wabmig.exe
[App Paths] :HKLM waveedit.exe=C:\Program Files (x86)\Nero\Nero 7\Nero
WaveEditor\waveedit.exe
### waveedit.exe Wave Editor Nero AG Nero WaveEditor 3, 10, 1, 0
[App Paths] :HKLM winamp.exe=C:\Program Files (x86)\Winamp\winamp.exe
### winamp.exe Winamp Nullsoft, Inc. Winamp 5.5.8.2985
[App Paths] :HKLM WinRAR.exe=C:\Program Files (x86)\WinRAR\WinRAR.exe
### WinRAR.exe WinRAR archiver Tamer Zorba
[App Paths] :HKLM Winword.exe=C:\PROGRA~2\MICROS~1\Office15\WINWORD.EXE
### Winword.exe Microsoft Word Microsoft Corporation Microsoft Office 2013
15.0.4420.1017
[App Paths] :HKLM wmplayer.exe=%ProgramFiles(x86)%\Windows Media
Player\wmplayer.exe
### wmplayer.exe
[App Paths] :HKLM WORDPAD.EXE=C:\PROGRAM FILES\WINDOWS NT\ACCESSORIES\WORDPAD.EXE
### WORDPAD.EXE Windows Wordpad Application Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 !$*"%ProgramFiles%\Windows
NT\Accessories\WORDPAD.EXE"
[App Paths] :HKLM WRITE.EXE="%ProgramFiles%\Windows NT\Accessories\WORDPAD.EXE"
### WRITE.EXE
[App Paths] :HKLM YouCam=C:\Program Files (x86)\CyberLink\YouCam\YouCam.exe
### YouCam YouCam CyberLink Corp. YouCam 4.0.0.0820
[Kernel Auto Boot]
[ActiveSetup] >{22d6f312-b0f6-11d0-94ab-
0080c74c7e95}=C:\WINDOWS\SYSTEM32\UNREGMP2.EXE
### Microsoft Windows Media Player Setup Utility Microsoft Corporation Microsoft�
Windows� Operating System 12.0.14393.0 !$*%SystemRoot%\system32\unregmp2.exe
/ShowWMP
[Auto Services] :HKLM AdobeARMservice
### Service: Adobe Acrobat Update Service Status: Start Type: loaded
automatically by Server Manager Actual File: C:\PROGRAM FILES (X86)\COMMON
FILES\ADOBE\ARM\1.0\ARMSVC.EXE * Adobe Acrobat Updater keeps your Adobe software up
to date. Adobe Acrobat Update Service Adobe Systems Incorporated Adobe Acrobat
Update Service 1, 5, 5, 0 !$*"C:\PROGRAM FILES (X86)\COMMON
FILES\ADOBE\ARM\1.0\ARMSVC.EXE"
[Auto Services] :HKLM AJRouter
### Service: AllJoyn Router Service Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Routes AllJoyn messages for the
local AllJoyn clients. If this service is stopped the AllJoyn clients that do not
have their own bundled routers will be unable to run. Host Process for Windows
Services Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0 !
$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICENETWORKRESTRICTED
[Auto Services] :HKLM ALG
### Service: Application Layer Gateway Service Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\ALG.EXE * Provides support for
3rd party protocol plug-ins for Internet Connection Sharing Application Layer
Gateway Service Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\ALG.EXE
[Auto Services] :HKLM AppIDSvc
### Service: Application Identity Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Determines and verifies the identity
of an application. Disabling this service will prevent AppLocker from being
enforced. Host Process for Windows Services Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
LOCALSERVICENETWORKRESTRICTED
[Auto Services] :HKLM Appinfo
### Service: Application Information Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Facilitates the running of
interactive applications with additional administrative privileges. If this
service is stopped, users will be unable to launch applications with the additional
administrative privileges they may require to perform desired user tasks. Host
Process for Windows Services Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS
[Auto Services] :HKLM AppMgmt
### Service: Application Management Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Processes installation, removal, and
enumeration requests for software deployed through Group Policy. If the service is
disabled, users will be unable to install, remove, or enumerate software deployed
through Group Policy. If this service is disabled, any services that explicitly
depend on it will fail to start. Host Process for Windows Services Microsoft
Corporation Microsoft� Windows� Operating System 10.0.14393.0 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K NETSVCS
[Auto Services] :HKLM AppReadiness
### Service: App Readiness Status: Start Type: loaded manually on demand Actual
File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Gets apps ready for use the first time a
user signs in to this PC and when adding new apps. Host Process for Windows
Services Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0 !
$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K APPREADINESS
[Auto Services] :HKLM AppXSvc
### Service: AppX Deployment Service (AppXSVC) Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Provides
infrastructure support for deploying Store applications. This service is started on
demand and if disabled Store applications will not be deployed to the system, and
may not function properly. Host Process for Windows Services Microsoft Corporation
Microsoft� Windows� Operating System 10.0.14393.0 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K WSAPPX
[Auto Services] :HKLM ASLDRService
### Service: ASLDR Service Status: Start Type: loaded automatically by Server
Manager Actual File: C:\PROGRAM FILES (X86)\ASUS\ATK PACKAGE\ATK
HOTKEY\ASLDRSRV.EXE * ASLDR Service ASUSTek Computer Inc. ATK Hotkey 1, 0, 81, 0
[Auto Services] :HKLM ATKGFNEXSrv
### Service: ATKGFNEX Service Status: Start Type: loaded automatically by Server
Manager Actual File: C:\PROGRAM FILES (X86)\ASUS\ATK PACKAGE\ATKGFNEX\GFNEXSRV.EXE
* GFNEXSrv ASUS ATK Generic Function Service 1, 0, 11, 0
[Auto Services] :HKLM AudioEndpointBuilder
### Service: Windows Audio Endpoint Builder Status: Start Type: loaded
automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE *
Manages audio devices for the Windows Audio service. If this service is stopped,
audio devices and effects will not function properly. If this service is disabled,
any services that explicitly depend on it will fail to start Host Process for
Windows Services Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED
[Auto Services] :HKLM Audiosrv
### Service: Windows Audio Status: Start Type: loaded automatically by Server
Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Manages audio for Windows-
based programs. If this service is stopped, audio devices and effects will not
function properly. If this service is disabled, any services that explicitly
depend on it will fail to start Host Process for Windows Services Microsoft
Corporation Microsoft� Windows� Operating System 10.0.14393.0 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICENETWORKRESTRICTED
[Auto Services] :HKLM AxInstSV
### Service: ActiveX Installer (AxInstSV) Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Provides User Account Control
validation for the installation of ActiveX controls from the Internet and enables
management of ActiveX control installation based on Group Policy settings. This
service is started on demand and if disabled the installation of ActiveX controls
will behave according to default browser settings. Host Process for Windows
Services Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0 !
$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K AXINSTSVGROUP
[Auto Services] :HKLM BDESVC
### Service: BitLocker Drive Encryption Service Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * BDESVC hosts the
BitLocker Drive Encryption service. BitLocker Drive Encryption provides secure
startup for the operating system, as well as full volume encryption for OS, fixed
or removable volumes. This service allows BitLocker to prompt users for various
actions related to their volumes when mounted, and unlocks volumes automatically
without user interaction. Additionally, it stores recovery information to Active
Directory, if available, and, if necessary, ensures the most recent recovery
certificates are used. Stopping or disabling the service would prevent users from
leveraging this functionality. Host Process for Windows Services Microsoft
Corporation Microsoft� Windows� Operating System 10.0.14393.0 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K NETSVCS
[Auto Services] :HKLM BFE
### Service: Base Filtering Engine Status: Start Type: loaded automatically by
Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * The Base Filtering
Engine (BFE) is a service that manages firewall and Internet Protocol security
(IPsec) policies and implements user mode filtering. Stopping or disabling the BFE
service will significantly reduce the security of the system. It will also result
in unpredictable behavior in IPsec management and firewall applications. Host
Process for Windows Services Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICENONETWORK
[Auto Services] :HKLM BITS
### Service: Background Intelligent Transfer Service Status: Start Type: loaded
automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE *
Transfers files in the background using idle network bandwidth. If the service is
disabled, then any applications that depend on BITS, such as Windows Update or MSN
Explorer, will be unable to automatically download programs and other information.
Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS
[Auto Services] :HKLM BrokerInfrastructure
### Service: Background Tasks Infrastructure Service Status: Start Type: loaded
automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE *
Windows infrastructure service that controls which background tasks can run on the
system. Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K DCOMLAUNCH
[Auto Services] :HKLM Browser
### Service: Computer Browser Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Maintains an updated list of
computers on the network and supplies this list to computers designated as
browsers. If this service is stopped, this list will not be updated or maintained.
If this service is disabled, any services that explicitly depend on it will fail to
start. Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS
[Auto Services] :HKLM BthHFSrv
### Service: Bluetooth Handsfree Service Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Enables wireless Bluetooth
headsets to run on this computer. If this service is stopped or disabled, then
Bluetooth headsets will not function properly with this machine. Host Process for
Windows Services Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICEANDNOIMPERSONATION
[Auto Services] :HKLM bthserv
### Service: Bluetooth Support Service Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * The Bluetooth service
supports discovery and association of remote Bluetooth devices. Stopping or
disabling this service may cause already installed Bluetooth devices to fail to
operate properly and prevent new devices from being discovered or associated. Host
Process for Windows Services Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE
[Auto Services] :HKLM CDPSvc
### Service: Connected Devices Platform Service Status: Start Type: loaded
automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * This
service is used for Connected Devices and Universal Glass scenarios Host Process
for Windows Services Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE
[Auto Services] :HKLM CDPUserSvc
### Service: @%SystemRoot%\system32\cdpusersvc.dll,-100 Status: Start Type:
loaded automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE
* @%SystemRoot%\system32\cdpusersvc.dll,-101 Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K UNISTACKSVCGROUP
[Auto Services] :HKLM CDPUserSvc_2e64c
### Service: CDPUserSvc_2e64c Status: Start Type: loaded automatically by Server
Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * @%SystemRoot
%\system32\cdpusersvc.dll,-101 Host Process for Windows Services Microsoft
Corporation Microsoft� Windows� Operating System 10.0.14393.0 !
$*C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K UNISTACKSVCGROUP
[Auto Services] :HKLM CertPropSvc
### Service: Certificate Propagation Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Copies user certificates and
root certificates from smart cards into the current user's certificate store,
detects when a smart card is inserted into a smart card reader, and, if needed,
installs the smart card Plug and Play minidriver. Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS
[Auto Services] :HKLM ClipSVC
### Service: Client License Service (ClipSVC) Status: Start Type: loaded manually
on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Provides infrastructure
support for the Microsoft Store. This service is started on demand and if disabled
applications bought using Windows Store will not behave correctly. Host Process for
Windows Services Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K WSAPPX
[Auto Services] :HKLM COMSysApp
### Service: COM+ System Application Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\DLLHOST.EXE * Manages the configuration and
tracking of Component Object Model (COM)+-based components. If the service is
stopped, most COM+-based components will not function properly. If this service is
disabled, any services that explicitly depend on it will fail to start. COM
Surrogate Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0 !
$*%SYSTEMROOT%\SYSTEM32\DLLHOST.EXE /PROCESSID:{02D4B3F1-FD88-11D1-960D-
00805FC79235}
[Auto Services] :HKLM CoreMessagingRegistrar
### Service: CoreMessaging Status: Start Type: loaded automatically by Server
Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Manages communication
between system components. Host Process for Windows Services Microsoft Corporation
Microsoft� Windows� Operating System 10.0.14393.0 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICENONETWORK
[Auto Services] :HKLM cphs
### Service: Intel(R) Content Protection HECI Service Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSWOW64\INTELCPHECISVC.EXE * Intel(R)
Content Protection HECI Service - enables communication with the Content Protection
FW IntelCpHeciSvc Executable Intel Corporation IntelCpHeciSvc Executable
9.0.31.9015 !$*%SYSTEMROOT%\SYSWOW64\INTELCPHECISVC.EXE
[Auto Services] :HKLM CryptSvc
### Service: Cryptographic Services Status: Start Type: loaded automatically by
Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Provides three
management services: Catalog Database Service, which confirms the signatures of
Windows files and allows new programs to be installed; Protected Root Service,
which adds and removes Trusted Root Certification Authority certificates from this
computer; and Automatic Root Certificate Update Service, which retrieves root
certificates from Windows Update and enable scenarios such as SSL. If this service
is stopped, these management services will not function properly. If this service
is disabled, any services that explicitly depend on it will fail to start. Host
Process for Windows Services Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETWORKSERVICE
[Auto Services] :HKLM CscService
### Service: Offline Files Status: Start Type: loaded manually on demand Actual
File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * The Offline Files service performs
maintenance activities on the Offline Files cache, responds to user logon and
logoff events, implements the internals of the public API, and dispatches
interesting events to those interested in Offline Files activities and changes in
cache state. Host Process for Windows Services Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
LOCALSYSTEMNETWORKRESTRICTED
[Auto Services] :HKLM DcomLaunch
### Service: DCOM Server Process Launcher Status: Start Type: loaded
automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * The
DCOMLAUNCH service launches COM and DCOM servers in response to object activation
requests. If this service is stopped or disabled, programs using COM or DCOM will
not function properly. It is strongly recommended that you have the DCOMLAUNCH
service running. Host Process for Windows Services Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
DCOMLAUNCH
[Auto Services] :HKLM DcpSvc
### Service: DataCollectionPublishingService Status: Start Type: loaded manually
on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * The DCP (Data Collection
and Publishing) service supports first party apps to upload data to cloud. Host
Process for Windows Services Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS
[Auto Services] :HKLM defragsvc
### Service: Optimize drives Status: Start Type: loaded manually on demand Actual
File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Helps the computer run more efficiently by
optimizing files on storage drives. Host Process for Windows Services Microsoft
Corporation Microsoft� Windows� Operating System 10.0.14393.0 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K DEFRAGSVC
[Auto Services] :HKLM DeviceAssociationService
### Service: Device Association Service Status: Start Type: loaded automatically
by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Enables pairing
between the system and wired or wireless devices. Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED
[Auto Services] :HKLM DeviceInstall
### Service: Device Install Service Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Enables a computer to recognize and
adapt to hardware changes with little or no user input. Stopping or disabling this
service will result in system instability. Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K DCOMLAUNCH
[Auto Services] :HKLM DevQueryBroker
### Service: DevQuery Background Discovery Broker Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Enables apps to
discover devices with a backgroud task Host Process for Windows Services Microsoft
Corporation Microsoft� Windows� Operating System 10.0.14393.0 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED
[Auto Services] :HKLM Dhcp
### Service: DHCP Client Status: Start Type: loaded automatically by Server
Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Registers and updates IP
addresses and DNS records for this computer. If this service is stopped, this
computer will not receive dynamic IP addresses and DNS updates. If this service is
disabled, any services that explicitly depend on it will fail to start. Host
Process for Windows Services Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
LOCALSERVICENETWORKRESTRICTED
[Auto Services] :HKLM diagnosticshub.standardcollector.service
### Service: Microsoft (R) Diagnostics Hub Standard Collector Service Status:
Start Type: loaded manually on demand Actual File:
C:\WINDOWS\SYSTEM32\DIAGSVCS\DIAGNOSTICSHUB.STANDARDCOLLECTOR.SERVICE.EXE *
Diagnostics Hub Standard Collector Service. When running, this service collects
real time ETW events and processes them. Microsoft (R) Diagnostics Hub Standard
Collector Microsoft Corporation Internet Explorer 11.00.14393.0 !$*%SYSTEMROOT
%\SYSTEM32\DIAGSVCS\DIAGNOSTICSHUB.STANDARDCOLLECTOR.SERVICE.EXE
[Auto Services] :HKLM DiagTrack
### Service: Connected User Experiences and Telemetry Status: Start Type: loaded
automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * The
Connected User Experiences and Telemetry service enables features that support in-
application and connected user experiences. Additionally, this service manages the
event driven collection and transmission of diagnostic and usage information (used
to improve the experience and quality of the Windows Platform) when the diagnostics
and usage privacy option settings are enabled under Feedback and Diagnostics. Host
Process for Windows Services Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K UTCSVC
[Auto Services] :HKLM DmEnrollmentSvc
### Service: Device Management Enrollment Service Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Performs Device
Enrollment Activities for Device Management Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS
[Auto Services] :HKLM dmwappushservice
### Service: dmwappushsvc Status: Start Type: loaded manually on demand Actual
File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * WAP Push Message Routing Service Host
Process for Windows Services Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS
[Auto Services] :HKLM Dnscache
### Service: DNS Client Status: Start Type: loaded automatically by Server
Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * The DNS Client service
(dnscache) caches Domain Name System (DNS) names and registers the full computer
name for this computer. If the service is stopped, DNS names will continue to be
resolved. However, the results of DNS name queries will not be cached and the
computer's name will not be registered. If the service is disabled, any services
that explicitly depend on it will fail to start. Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETWORKSERVICE
[Auto Services] :HKLM DoSvc
### Service: Delivery Optimization Status: Start Type: loaded automatically by
Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Performs content
delivery optimization tasks Host Process for Windows Services Microsoft Corporation
Microsoft� Windows� Operating System 10.0.14393.0 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K NETSVCS
[Auto Services] :HKLM dot3svc
### Service: Wired AutoConfig Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * The Wired AutoConfig (DOT3SVC)
service is responsible for performing IEEE 802.1X authentication on Ethernet
interfaces. If your current wired network deployment enforces 802.1X
authentication, the DOT3SVC service should be configured to run for establishing
Layer 2 connectivity and/or providing access to network resources. Wired networks
that do not enforce 802.1X authentication are unaffected by the DOT3SVC service.
Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
LOCALSYSTEMNETWORKRESTRICTED
[Auto Services] :HKLM DPS
### Service: Diagnostic Policy Service Status: Start Type: loaded automatically
by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * The Diagnostic
Policy Service enables problem detection, troubleshooting and resolution for
Windows components. If this service is stopped, diagnostics will no longer
function. Host Process for Windows Services Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
LOCALSERVICENONETWORK
[Auto Services] :HKLM DptfParticipantProcessorService
### Service: @oem24.inf,%WIN32_DPTF_PARTICIPANT_PROC_SERVICE_DISPLAY_NAME
%;Intel(R) Dynamic Platform and Thermal Framework Processor Participant Service
Application Status: Start Type: loaded automatically by Server Manager Actual File:
C:\WINDOWS\SYSTEM32\DPTFPARTICIPANTPROCESSORSERVICE.EXE * @oem24.inf,
%WIN32_DPTF_PARTICIPANT_PROC_SERVICE_DESCRIPTION%;Intel(R) Dynamic Platform and
Thermal Framework Processor Participant Service Application Intel(R) Dynamic
Platform and Thermal Framework Processor Participant Service Intel Corporation
Intel(R) Dynamic Platform and Thermal Framework 7.1.0.2106 !$*%SYSTEMROOT
%\SYSTEM32\DPTFPARTICIPANTPROCESSORSERVICE.EXE
[Auto Services] :HKLM DptfPolicyConfigTDPService
### Service: @oem24.inf,%WIN32_DPTF_POLICY_CONFIGTDP_SERVICE_DISPLAY_NAME
%;Intel(R) Dynamic Platform and Thermal Framework Config TDP Service Application
Status: Start Type: loaded automatically by Server Manager Actual File:
C:\WINDOWS\SYSTEM32\DPTFPOLICYCONFIGTDPSERVICE.EXE * @oem24.inf,
%WIN32_DPTF_POLICY_CONFIGTDP_SERVICE_DESCRIPTION%;Intel(R) Dynamic Platform and
Thermal Framework Config TDP Service Application Intel(R) Dynamic Platform and
Thermal Framework Config TDP Policy Service Intel Corporation Intel(R) Dynamic
Platform and Thermal Framework 7.1.0.2106 !$*%SYSTEMROOT
%\SYSTEM32\DPTFPOLICYCONFIGTDPSERVICE.EXE
[Auto Services] :HKLM DptfPolicyLpmService
### Service: @oem24.inf,%WIN32_DPTF_POLICY_LPM_SERVICE_DISPLAY_NAME%;Intel(R)
Dynamic Platform and Thermal Framework Low Power Mode Service Application Status:
Start Type: loaded automatically by Server Manager Actual File:
C:\WINDOWS\SYSTEM32\DPTFPOLICYLPMSERVICE.EXE * @oem24.inf,
%WIN32_DPTF_POLICY_LPM_SERVICE_DESCRIPTION%;Intel(R) Dynamic Platform and Thermal
Framework Low Power Mode Service Application Intel(R) Dynamic Platform and Thermal
Framework LPM Policy Service Intel Corporation Intel(R) Dynamic Platform and
Thermal Framework 7.1.0.2106 !$*%SYSTEMROOT%\SYSTEM32\DPTFPOLICYLPMSERVICE.EXE
[Auto Services] :HKLM DsmSvc
### Service: Device Setup Manager Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Enables the detection, download and
installation of device-related software. If this service is disabled, devices may
be configured with outdated software, and may not work correctly. Host Process for
Windows Services Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS
[Auto Services] :HKLM DsSvc
### Service: Data Sharing Service Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Provides data brokering between
applications. Host Process for Windows Services Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
LOCALSYSTEMNETWORKRESTRICTED
[Auto Services] :HKLM EapHost
### Service: Extensible Authentication Protocol Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * The Extensible
Authentication Protocol (EAP) service provides network authentication in such
scenarios as 802.1x wired and wireless, VPN, and Network Access Protection (NAP).
EAP also provides application programming interfaces (APIs) that are used by
network access clients, including wireless and VPN clients, during the
authentication process. If you disable this service, this computer is prevented
from accessing networks that require EAP authentication. Host Process for Windows
Services Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0 !
$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS
[Auto Services] :HKLM EFS
### Service: Encrypting File System (EFS) Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\LSASS.EXE * Provides the core file
encryption technology used to store encrypted files on NTFS file system volumes. If
this service is stopped or disabled, applications will be unable to access
encrypted files. Local Security Authority Process Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.1770 !$*%SYSTEMROOT%\SYSTEM32\LSASS.EXE
[Auto Services] :HKLM embeddedmode
### Service: Embedded Mode Status: Start Type: loaded manually on demand Actual
File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * The Embedded Mode service enables scenarios
related to Background Applications. Disabling this service will prevent Background
Applications from being activated. Host Process for Windows Services Microsoft
Corporation Microsoft� Windows� Operating System 10.0.14393.0 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED
[Auto Services] :HKLM EntAppSvc
### Service: Enterprise App Management Service Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE *
@EnterpriseAppMgmtSvc.dll,-2 Host Process for Windows Services Microsoft
Corporation Microsoft� Windows� Operating System 10.0.14393.0 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K APPMODEL
[Auto Services] :HKLM EventLog
### Service: Windows Event Log Status: Start Type: loaded automatically by Server
Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * This service manages events
and event logs. It supports logging events, querying events, subscribing to events,
archiving event logs, and managing event metadata. It can display events in both
XML and plain text format. Stopping this service may compromise security and
reliability of the system. Host Process for Windows Services Microsoft Corporation
Microsoft� Windows� Operating System 10.0.14393.0 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICENETWORKRESTRICTED
[Auto Services] :HKLM EventSystem
### Service: COM+ Event System Status: Start Type: loaded automatically by Server
Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Supports System Event
Notification Service (SENS), which provides automatic distribution of events to
subscribing Component Object Model (COM) components. If the service is stopped,
SENS will close and will not be able to provide logon and logoff notifications. If
this service is disabled, any services that explicitly depend on it will fail to
start. Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE
[Auto Services] :HKLM Fax
### Service: Fax Status: Start Type: loaded manually on demand Actual File:
C:\WINDOWS\SYSTEM32\FXSSVC.EXE * Enables you to send and receive faxes, utilizing
fax resources available on this computer or on the network. Fax Service Microsoft
Corporation Microsoft� Windows� Operating System 10.0.14393.0 !$*%SYSTEMROOT
%\SYSTEM32\FXSSVC.EXE
[Auto Services] :HKLM fdPHost
### Service: Function Discovery Provider Host Status: Start Type: loaded manually
on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * The FDPHOST service hosts
the Function Discovery (FD) network discovery providers. These FD providers supply
network discovery services for the Simple Services Discovery Protocol (SSDP) and
Web Services � Discovery (WS-D) protocol. Stopping or disabling the FDPHOST service
will disable network discovery for these protocols when using FD. When this service
is unavailable, network services using FD and relying on these discovery protocols
will be unable to find network devices or resources. Host Process for Windows
Services Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0 !
$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE
[Auto Services] :HKLM FDResPub
### Service: Function Discovery Resource Publication Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Publishes this
computer and resources attached to this computer so they can be discovered over the
network. If this service is stopped, network resources will no longer be published
and they will not be discovered by other computers on the network. Host Process for
Windows Services Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICEANDNOIMPERSONATION
[Auto Services] :HKLM fhsvc
### Service: File History Service Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Protects user files from accidental
loss by copying them to a backup location Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED
[Auto Services] :HKLM FontCache
### Service: Windows Font Cache Service Status: Start Type: loaded automatically
by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Optimizes
performance of applications by caching commonly used font data. Applications will
start this service if it is not already running. It can be disabled, though doing
so will degrade application performance. Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE
[Auto Services] :HKLM FrameServer
### Service: Windows Camera Frame Server Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Enables multiple clients to
access video frames from camera devices. Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K CAMERA
[Auto Services] :HKLM gpsvc
### Service: Group Policy Client Status: Start Type: loaded automatically by
Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * The service is
responsible for applying settings configured by administrators for the computer and
users through the Group Policy component. If the service is disabled, the settings
will not be applied and applications and components will not be manageable through
Group Policy. Any components or applications that depend on the Group Policy
component might not be functional if the service is disabled. Host Process for
Windows Services Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS
[Auto Services] :HKLM hidserv
### Service: Human Interface Device Service Status: Start Type: loaded manually
on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Activates and maintains
the use of hot buttons on keyboards, remote controls, and other multimedia devices.
It is recommended that you keep this service running. Host Process for Windows
Services Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0 !
$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED
[Auto Services] :HKLM HomeGroupListener
### Service: HomeGroup Listener Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Makes local computer changes
associated with configuration and maintenance of the homegroup-joined computer. If
this service is stopped or disabled, your computer will not work properly in a
homegroup and your homegroup might not work properly. It is recommended that you
keep this service running. Host Process for Windows Services Microsoft Corporation
Microsoft� Windows� Operating System 10.0.14393.0 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED
[Auto Services] :HKLM HomeGroupProvider
### Service: HomeGroup Provider Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Performs networking tasks associated
with configuration and maintenance of homegroups. If this service is stopped or
disabled, your computer will be unable to detect other homegroups and your
homegroup might not work properly. It is recommended that you keep this service
running. Host Process for Windows Services Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
LOCALSERVICENETWORKRESTRICTED
[Auto Services] :HKLM HvHost
### Service: HV Host Service Status: Start Type: loaded manually on demand Actual
File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Provides an interface for the Hyper-V
hypervisor to provide per-partition performance counters to the host operating
system. Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
LOCALSYSTEMNETWORKRESTRICTED
[Auto Services] :HKLM HWDeviceService64.exe
### Service: HWDeviceService64.exe Status: Start Type: loaded automatically by
Server Manager Actual File: C:\PROGRAMDATA\DATACARDSERVICE\HWDEVICESERVICE64.EXE *
Service for runing Mobile applications autorun. DCSHOST HWDeviceService 2, 0, 0, 47
!$*"C:\PROGRAMDATA\DATACARDSERVICE\HWDEVICESERVICE64.EXE" -/SERVICE
[Auto Services] :HKLM icssvc
### Service: Windows Mobile Hotspot Service Status: Start Type: loaded manually
on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Provides the ability to
share a cellular data connection with another device. Host Process for Windows
Services Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0 !
$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICENETWORKRESTRICTED
[Auto Services] :HKLM igfxCUIService2.0.0.0
### Service: Intel(R) HD Graphics Control Panel Service Status: Start Type:
loaded automatically by Server Manager Actual File:
C:\WINDOWS\SYSTEM32\IGFXCUISERVICE.EXE * Service for Intel(R) HD Graphics Control
Panel igfxCUIService Module Intel Corporation Intel(R) Common User Interface
6.15.10.4549 !$*%SYSTEMROOT%\SYSTEM32\IGFXCUISERVICE.EXE
[Auto Services] :HKLM IKEEXT
### Service: IKE and AuthIP IPsec Keying Modules Status: Start Type: loaded
automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * The
IKEEXT service hosts the Internet Key Exchange (IKE) and Authenticated Internet
Protocol (AuthIP) keying modules. These keying modules are used for authentication
and key exchange in Internet Protocol security (IPsec). Stopping or disabling the
IKEEXT service will disable IKE and AuthIP key exchange with peer computers. IPsec
is typically configured to use IKE or AuthIP; therefore, stopping or disabling the
IKEEXT service might result in an IPsec failure and might compromise the security
of the system. It is strongly recommended that you have the IKEEXT service running.
Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS
[Auto Services] :HKLM iphlpsvc
### Service: IP Helper Status: Start Type: loaded automatically by Server Manager
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Provides tunnel connectivity using
IPv6 transition technologies (6to4, ISATAP, Port Proxy, and Teredo), and IP-HTTPS.
If this service is stopped, the computer will not have the enhanced connectivity
benefits that these technologies offer. Host Process for Windows Services Microsoft
Corporation Microsoft� Windows� Operating System 10.0.14393.0 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K NETSVCS
[Auto Services] :HKLM irmon
### Service: Infrared monitor service Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Detects other Infrared
devices that are in range and launches the file transfer application. Stopping the
service will prevent file transfer from working Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED
[Auto Services] :HKLM KeyIso
### Service: CNG Key Isolation Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\LSASS.EXE * The CNG key isolation service is
hosted in the LSA process. The service provides key process isolation to private
keys and associated cryptographic operations as required by the Common Criteria.
The service stores and uses long-lived keys in a secure process complying with
Common Criteria requirements. Local Security Authority Process Microsoft
Corporation Microsoft� Windows� Operating System 10.0.14393.1770 !$*%SYSTEMROOT
%\SYSTEM32\LSASS.EXE
[Auto Services] :HKLM KtmRm
### Service: KtmRm for Distributed Transaction Coordinator Status: Start Type:
loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE *
Coordinates transactions between the Distributed Transaction Coordinator (MSDTC)
and the Kernel Transaction Manager (KTM). If it is not needed, it is recommended
that this service remain stopped. If it is needed, both MSDTC and KTM will start
this service automatically. If this service is disabled, any MSDTC transaction
interacting with a Kernel Resource Manager will fail and any services that
explicitly depend on it will fail to start. Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETWORKSERVICEANDNOIMPERSONATION
[Auto Services] :HKLM LanmanServer
### Service: Server Status: Start Type: loaded automatically by Server Manager
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Supports file, print, and named-pipe
sharing over the network for this computer. If this service is stopped, these
functions will be unavailable. If this service is disabled, any services that
explicitly depend on it will fail to start. Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS
[Auto Services] :HKLM LanmanWorkstation
### Service: Workstation Status: Start Type: loaded automatically by Server
Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Creates and maintains client
network connections to remote servers using the SMB protocol. If this service is
stopped, these connections will be unavailable. If this service is disabled, any
services that explicitly depend on it will fail to start. Host Process for Windows
Services Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0 !
$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETWORKSERVICE
[Auto Services] :HKLM lfsvc
### Service: Geolocation Service Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * This service monitors the current
location of the system and manages geofences (a geographical location with
associated events). If you turn off this service, applications will be unable to
use or receive notifications for geolocation or geofences. Host Process for Windows
Services Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0 !
$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS
[Auto Services] :HKLM LicenseManager
### Service: Windows License Manager Service Status: Start Type: loaded manually
on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Provides infrastructure
support for the Windows Store. This service is started on demand and if disabled
then content acquired through the Windows Store will not function properly. Host
Process for Windows Services Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE
[Auto Services] :HKLM lltdsvc
### Service: Link-Layer Topology Discovery Mapper Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Creates a Network
Map, consisting of PC and device topology (connectivity) information, and metadata
describing each PC and device. If this service is disabled, the Network Map will
not function properly. Host Process for Windows Services Microsoft Corporation
Microsoft� Windows� Operating System 10.0.14393.0 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE
[Auto Services] :HKLM lmhosts
### Service: TCP/IP NetBIOS Helper Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Provides support for the NetBIOS
over TCP/IP (NetBT) service and NetBIOS name resolution for clients on the network,
therefore enabling users to share files, print, and log on to the network. If this
service is stopped, these functions might be unavailable. If this service is
disabled, any services that explicitly depend on it will fail to start. Host
Process for Windows Services Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
LOCALSERVICENETWORKRESTRICTED
[Auto Services] :HKLM LSM
### Service: Local Session Manager Status: Start Type: loaded automatically by
Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Core Windows Service
that manages local user sessions. Stopping or disabling this service will result in
system instability. Host Process for Windows Services Microsoft Corporation
Microsoft� Windows� Operating System 10.0.14393.0 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K DCOMLAUNCH
[Auto Services] :HKLM MapsBroker
### Service: Downloaded Maps Manager Status: Start Type: loaded automatically by
Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Windows service for
application access to downloaded maps. This service is started on-demand by
application accessing downloaded maps. Disabling this service will prevent apps
from accessing maps. Host Process for Windows Services Microsoft Corporation
Microsoft� Windows� Operating System 10.0.14393.0 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K NETWORKSERVICE
[Auto Services] :HKLM MessagingService
### Service: MessagingService Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Service supporting text messaging
and related functionality. Host Process for Windows Services Microsoft Corporation
Microsoft� Windows� Operating System 10.0.14393.0 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K UNISTACKSVCGROUP
[Auto Services] :HKLM MessagingService_2e64c
### Service: MessagingService_2e64c Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Service supporting text messaging
and related functionality. Host Process for Windows Services Microsoft Corporation
Microsoft� Windows� Operating System 10.0.14393.0 !
$*C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K UNISTACKSVCGROUP
[Auto Services] :HKLM MozillaMaintenance
### Service: Mozilla Maintenance Service Status: Start Type: loaded manually on
demand Actual File: C:\PROGRAM FILES (X86)\MOZILLA MAINTENANCE
SERVICE\MAINTENANCESERVICE.EXE * The Mozilla Maintenance Service ensures that you
have the latest and most secure version of Mozilla Firefox on your computer.
Keeping Firefox up to date is very important for your online security, and Mozilla
strongly recommends that you keep this service enabled. Mozilla Foundation Firefox
56.0 !$*"C:\PROGRAM FILES (X86)\MOZILLA MAINTENANCE SERVICE\MAINTENANCESERVICE.EXE"
[Auto Services] :HKLM MpsSvc
### Service: Windows Firewall Status: Start Type: loaded automatically by Server
Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Windows Firewall helps
protect your computer by preventing unauthorized users from gaining access to your
computer through the Internet or a network. Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICENONETWORK
[Auto Services] :HKLM MSDTC
### Service: Distributed Transaction Coordinator Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\MSDTC.EXE * Coordinates
transactions that span multiple resource managers, such as databases, message
queues, and file systems. If this service is stopped, these transactions will fail.
If this service is disabled, any services that explicitly depend on it will fail to
start. Microsoft Distributed Transaction Coordinator Service Microsoft Corporation
Microsoft� Windows� Operating System 10.0.14393.0 !$*%SYSTEMROOT
%\SYSTEM32\MSDTC.EXE
[Auto Services] :HKLM MSiSCSI
### Service: Microsoft iSCSI Initiator Service Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Manages Internet
SCSI (iSCSI) sessions from this computer to remote iSCSI target devices. If this
service is stopped, this computer will not be able to login or access iSCSI
targets. If this service is disabled, any services that explicitly depend on it
will fail to start. Host Process for Windows Services Microsoft Corporation
Microsoft� Windows� Operating System 10.0.14393.0 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K NETSVCS
[Auto Services] :HKLM msiserver
### Service: Windows Installer Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\MSIEXEC.EXE * Adds, modifies, and removes
applications provided as a Windows Installer (*.msi, *.msp) package. If this
service is disabled, any services that explicitly depend on it will fail to start.
Windows� installer Microsoft Corporation Windows Installer - Unicode 5.0.14393.0 !
$*%SYSTEMROOT%\SYSTEM32\MSIEXEC.EXE /V
[Auto Services] :HKLM NBService
### Service: NBService Status: Start Type: loaded manually on demand Actual File:
C:\PROGRAM FILES (X86)\NERO\NERO 7\NERO BACKITUP\NBSERVICE.EXE * Nero BackItUp
Service is responsible to control all jobs created using Nero BackItUp. These jobs
can create backups of selected files/folders/partitions or complete hard disk to
hard disk, network drive, disc or FTP. Nero BackItUp Nero AG Nero BackItUp 2, 10,
3, 2
[Auto Services] :HKLM NcaSvc
### Service: Network Connectivity Assistant Status: Start Type: loaded manually
on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Provides DirectAccess
status notification for UI components Host Process for Windows Services Microsoft
Corporation Microsoft� Windows� Operating System 10.0.14393.0 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K NETSVCS
[Auto Services] :HKLM NcbService
### Service: Network Connection Broker Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Brokers connections that
allow Windows Store Apps to receive notifications from the internet. Host Process
for Windows Services Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED
[Auto Services] :HKLM NcdAutoSetup
### Service: Network Connected Devices Auto-Setup Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Network Connected
Devices Auto-Setup service monitors and installs qualified devices that connect to
a qualified network. Stopping or disabling this service will prevent Windows from
discovering and installing qualified network connected devices automatically. Users
can still manually add network connected devices to a PC through the user
interface. Host Process for Windows Services Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
LOCALSERVICENONETWORK
[Auto Services] :HKLM Netlogon
### Service: Netlogon Status: Start Type: loaded manually on demand Actual File:
C:\WINDOWS\SYSTEM32\LSASS.EXE * Maintains a secure channel between this computer
and the domain controller for authenticating users and services. If this service is
stopped, the computer may not authenticate users and services and the domain
controller cannot register DNS records. If this service is disabled, any services
that explicitly depend on it will fail to start. Local Security Authority Process
Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.1770 !$*
%SYSTEMROOT%\SYSTEM32\LSASS.EXE
[Auto Services] :HKLM Netman
### Service: Network Connections Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Manages objects in the Network and
Dial-Up Connections folder, in which you can view both local area network and
remote connections. Host Process for Windows Services Microsoft Corporation
Microsoft� Windows� Operating System 10.0.14393.0 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED
[Auto Services] :HKLM netprofm
### Service: Network List Service Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Identifies the networks to which the
computer has connected, collects and stores properties for these networks, and
notifies applications when these properties change. Host Process for Windows
Services Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0 !
$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE
[Auto Services] :HKLM NetSetupSvc
### Service: Network Setup Service Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * The Network Setup Service manages
the installation of network drivers and permits the configuration of low-level
network settings. If this service is stopped, any driver installations that are
in-progress may be cancelled. Host Process for Windows Services Microsoft
Corporation Microsoft� Windows� Operating System 10.0.14393.0 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K NETSVCS
[Auto Services] :HKLM NgcCtnrSvc
### Service: Microsoft Passport Container Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Manages local user identity
keys used to authenticate user to identity providers as well as TPM virtual smart
cards. If this service is disabled, local user identity keys and TPM virtual smart
cards will not be accessible. It is recommended that you do not reconfigure this
service. Host Process for Windows Services Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
LOCALSERVICENETWORKRESTRICTED
[Auto Services] :HKLM NgcSvc
### Service: Microsoft Passport Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Provides process isolation for
cryptographic keys used to authenticate to a user�s associated identity providers.
If this service is disabled, all uses and management of these keys will not be
available, which includes machine logon and single-sign on for apps and websites.
This service starts and stops automatically. It is recommended that you do not
reconfigure this service. Host Process for Windows Services Microsoft Corporation
Microsoft� Windows� Operating System 10.0.14393.0 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED
[Auto Services] :HKLM NlaSvc
### Service: Network Location Awareness Status: Start Type: loaded automatically
by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Collects and
stores configuration information for the network and notifies programs when this
information is modified. If this service is stopped, configuration information
might be unavailable. If this service is disabled, any services that explicitly
depend on it will fail to start. Host Process for Windows Services Microsoft
Corporation Microsoft� Windows� Operating System 10.0.14393.0 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K NETWORKSERVICE
[Auto Services] :HKLM NMIndexingService
### Service: NMIndexingService Status: Start Type: loaded manually on demand
Actual File: C:\PROGRAM FILES (X86)\COMMON FILES\AHEAD\LIB\NMINDEXINGSERVICE.EXE *
Nero Home Nero AG Nero Home 2,0,16,0 !$*"C:\PROGRAM FILES (X86)\COMMON
FILES\AHEAD\LIB\NMINDEXINGSERVICE.EXE"
[Auto Services] :HKLM nsi
### Service: Network Store Interface Service Status: Start Type: loaded
automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * This
service delivers network notifications (e.g. interface addition/deleting etc) to
user mode clients. Stopping this service will cause loss of network connectivity.
If this service is disabled, any other services that explicitly depend on this
service will fail to start. Host Process for Windows Services Microsoft Corporation
Microsoft� Windows� Operating System 10.0.14393.0 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE
[Auto Services] :HKLM nvsvc
### Service: NVIDIA Display Driver Service Status: Start Type: loaded
automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\NVVSVC.EXE *
Provides system and desktop level support to the NVIDIA display driver NVIDIA
Driver Helper Service, Version 359.46 NVIDIA Corporation NVIDIA Driver Helper
Service, Version 359.46 8.17.13.5946 !$*"C:\WINDOWS\SYSTEM32\NVVSVC.EXE"
[Auto Services] :HKLM OneSyncSvc
### Service: Sync Host Status: Start Type: loaded automatically by Server Manager
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * This service synchronizes mail,
contacts, calendar and various other user data. Mail and other applications
dependent on this functionality will not work properly when this service is not
running. Host Process for Windows Services Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
UNISTACKSVCGROUP
[Auto Services] :HKLM OneSyncSvc_2e64c
### Service: Sync Host_2e64c Status: Start Type: loaded automatically by Server
Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * This service synchronizes
mail, contacts, calendar and various other user data. Mail and other applications
dependent on this functionality will not work properly when this service is not
running. Host Process for Windows Services Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 !$*C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K
UNISTACKSVCGROUP
[Auto Services] :HKLM ose
### Service: Office Source Engine Status: Start Type: loaded manually on demand
Actual File: C:\PROGRAM FILES (X86)\COMMON FILES\MICROSOFT SHARED\SOURCE
ENGINE\OSE.EXE * Saves installation files used for updates and repairs and is
required for the downloading of Setup updates and Watson error reports. Office
Source Engine Microsoft Corporation Office Source Engine 15.0.4420.1017 !
$*"C:\PROGRAM FILES (X86)\COMMON FILES\MICROSOFT SHARED\SOURCE ENGINE\OSE.EXE"
[Auto Services] :HKLM p2pimsvc
### Service: Peer Networking Identity Manager Status: Start Type: loaded manually
on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Provides identity services
for the Peer Name Resolution Protocol (PNRP) and Peer-to-Peer Grouping services.
If disabled, the Peer Name Resolution Protocol (PNRP) and Peer-to-Peer Grouping
services may not function, and some applications, such as HomeGroup and Remote
Assistance, may not function correctly. Host Process for Windows Services Microsoft
Corporation Microsoft� Windows� Operating System 10.0.14393.0 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICEPEERNET
[Auto Services] :HKLM p2psvc
### Service: Peer Networking Grouping Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Enables multi-party
communication using Peer-to-Peer Grouping. If disabled, some applications, such as
HomeGroup, may not function. Host Process for Windows Services Microsoft
Corporation Microsoft� Windows� Operating System 10.0.14393.0 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICEPEERNET
[Auto Services] :HKLM pbamw_service
### Service: AMW Service Status: Start Type: loaded automatically by Server
Manager Actual File: C:\PROGRAM FILES\PLUMBYTES SOFTWARE\PLUMBYTES ANTI-
MALWARE\AMWSERVICE.EXE * Plumbytes Anti-Malware Service Antimalware service
PLUMBYTES PLUMBYTES Anti malware 0.9.0.634 !$*"C:\PROGRAM FILES\PLUMBYTES
SOFTWARE\PLUMBYTES ANTI-MALWARE\AMWSERVICE.EXE" RUN
[Auto Services] :HKLM PcaSvc
### Service: Program Compatibility Assistant Service Status: Start Type: loaded
automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * This
service provides support for the Program Compatibility Assistant (PCA). PCA
monitors programs installed and run by the user and detects known compatibility
problems. If this service is stopped, PCA will not function properly. Host Process
for Windows Services Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED
[Auto Services] :HKLM PeerDistSvc
### Service: BranchCache Status: Start Type: loaded manually on demand Actual
File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * This service caches network content from
peers on the local subnet. Host Process for Windows Services Microsoft Corporation
Microsoft� Windows� Operating System 10.0.14393.0 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K PEERDIST
[Auto Services] :HKLM PerfHost
### Service: Performance Counter DLL Host Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSWOW64\PERFHOST.EXE * Enables remote users and 64-
bit processes to query performance counters provided by 32-bit DLLs. If this
service is stopped, only local users and 32-bit processes will be able to query
performance counters provided by 32-bit DLLs. x86 Performance Counter Host
Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0 !$*
%SYSTEMROOT%\SYSWOW64\PERFHOST.EXE
[Auto Services] :HKLM PhoneSvc
### Service: Phone Service Status: Start Type: loaded manually on demand Actual
File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Manages the telephony state on the device
Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE
[Auto Services] :HKLM PimIndexMaintenanceSvc
### Service: Contact Data Status: Start Type: loaded manually on demand Actual
File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Indexes contact data for fast contact
searching. If you stop or disable this service, contacts might be missing from your
search results. Host Process for Windows Services Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
UNISTACKSVCGROUP
[Auto Services] :HKLM PimIndexMaintenanceSvc_2e64c
### Service: Contact Data_2e64c Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Indexes contact data for fast
contact searching. If you stop or disable this service, contacts might be missing
from your search results. Host Process for Windows Services Microsoft Corporation
Microsoft� Windows� Operating System 10.0.14393.0 !
$*C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K UNISTACKSVCGROUP
[Auto Services] :HKLM pla
### Service: Performance Logs & Alerts Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Performance Logs and Alerts
Collects performance data from local or remote computers based on preconfigured
schedule parameters, then writes the data to a log or triggers an alert. If this
service is stopped, performance information will not be collected. If this service
is disabled, any services that explicitly depend on it will fail to start. Host
Process for Windows Services Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICENONETWORK
[Auto Services] :HKLM PlugPlay
### Service: Plug and Play Status: Start Type: loaded manually on demand Actual
File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Enables a computer to recognize and adapt
to hardware changes with little or no user input. Stopping or disabling this
service will result in system instability. Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K DCOMLAUNCH
[Auto Services] :HKLM PNRPAutoReg
### Service: PNRP Machine Name Publication Service Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * This service
publishes a machine name using the Peer Name Resolution Protocol. Configuration is
managed via the netsh context 'p2p pnrp peer' Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICEPEERNET
[Auto Services] :HKLM PNRPsvc
### Service: Peer Name Resolution Protocol Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Enables serverless peer name
resolution over the Internet using the Peer Name Resolution Protocol (PNRP). If
disabled, some peer-to-peer and collaborative applications, such as Remote
Assistance, may not function. Host Process for Windows Services Microsoft
Corporation Microsoft� Windows� Operating System 10.0.14393.0 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICEPEERNET
[Auto Services] :HKLM PolicyAgent
### Service: IPsec Policy Agent Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Internet Protocol security (IPsec)
supports network-level peer authentication, data origin authentication, data
integrity, data confidentiality (encryption), and replay protection. This service
enforces IPsec policies created through the IP Security Policies snap-in or the
command-line tool "netsh ipsec". If you stop this service, you may experience
network connectivity issues if your policy requires that connections use IPsec.
Also,remote management of Windows Firewall is not available when this service is
stopped. Host Process for Windows Services Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
NETWORKSERVICENETWORKRESTRICTED
[Auto Services] :HKLM Power
### Service: Power Status: Start Type: loaded automatically by Server Manager
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Manages power policy and power
policy notification delivery. Host Process for Windows Services Microsoft
Corporation Microsoft� Windows� Operating System 10.0.14393.0 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K DCOMLAUNCH
[Auto Services] :HKLM PrintNotify
### Service: Printer Extensions and Notifications Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * This service
opens custom printer dialog boxes and handles notifications from a remote print
server or a printer. If you turn off this service, you won�t be able to see printer
extensions or notifications. Host Process for Windows Services Microsoft
Corporation Microsoft� Windows� Operating System 10.0.14393.0 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K PRINT
[Auto Services] :HKLM ProfSvc
### Service: User Profile Service Status: Start Type: loaded automatically by
Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * This service is
responsible for loading and unloading user profiles. If this service is stopped or
disabled, users will no longer be able to successfully sign in or sign out, apps
might have problems getting to users' data, and components registered to receive
profile event notifications won't receive them. Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS
[Auto Services] :HKLM QWAVE
### Service: Quality Windows Audio Video Experience Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Quality Windows
Audio Video Experience (qWave) is a networking platform for Audio Video (AV)
streaming applications on IP home networks. qWave enhances AV streaming performance
and reliability by ensuring network quality-of-service (QoS) for AV applications.
It provides mechanisms for admission control, run time monitoring and enforcement,
application feedback, and traffic prioritization. Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0 !$*%WINDIR
%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICEANDNOIMPERSONATION
[Auto Services] :HKLM RasAuto
### Service: Remote Access Auto Connection Manager Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Creates a
connection to a remote network whenever a program references a remote DNS or
NetBIOS name or address. Host Process for Windows Services Microsoft Corporation
Microsoft� Windows� Operating System 10.0.14393.0 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K NETSVCS
[Auto Services] :HKLM RasMan
### Service: Remote Access Connection Manager Status: Start Type: loaded manually
on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Manages dial-up and
virtual private network (VPN) connections from this computer to the Internet or
other remote networks. If this service is disabled, any services that explicitly
depend on it will fail to start. Host Process for Windows Services Microsoft
Corporation Microsoft� Windows� Operating System 10.0.14393.0 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K NETSVCS
[Auto Services] :HKLM RetailDemo
### Service: Retail Demo Service Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * The Retail Demo service controls
device activity while the device is in retail demo mode. Host Process for Windows
Services Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0 !
$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS
[Auto Services] :HKLM RmSvc
### Service: Radio Management Service Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Radio Management and Airplane
Mode Service Host Process for Windows Services Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
LOCALSERVICENETWORKRESTRICTED
[Auto Services] :HKLM RpcEptMapper
### Service: RPC Endpoint Mapper Status: Start Type: loaded automatically by
Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Resolves RPC
interfaces identifiers to transport endpoints. If this service is stopped or
disabled, programs using Remote Procedure Call (RPC) services will not function
properly. Host Process for Windows Services Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
RPCSS
[Auto Services] :HKLM RpcLocator
### Service: Remote Procedure Call (RPC) Locator Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\LOCATOR.EXE * In Windows 2003
and earlier versions of Windows, the Remote Procedure Call (RPC) Locator service
manages the RPC name service database. In Windows Vista and later versions of
Windows, this service does not provide any functionality and is present for
application compatibility. Rpc Locator Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\LOCATOR.EXE
[Auto Services] :HKLM RpcSs
### Service: Remote Procedure Call (RPC) Status: Start Type: loaded automatically
by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * The RPCSS service
is the Service Control Manager for COM and DCOM servers. It performs object
activations requests, object exporter resolutions and distributed garbage
collection for COM and DCOM servers. If this service is stopped or disabled,
programs using COM or DCOM will not function properly. It is strongly recommended
that you have the RPCSS service running. Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K RPCSS
[Auto Services] :HKLM SamSs
### Service: Security Accounts Manager Status: Start Type: loaded automatically
by Server Manager Actual File: C:\WINDOWS\SYSTEM32\LSASS.EXE * The startup of this
service signals other services that the Security Accounts Manager (SAM) is ready to
accept requests. Disabling this service will prevent other services in the system
from being notified when the SAM is ready, which may in turn cause those services
to fail to start correctly. This service should not be disabled. Local Security
Authority Process Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.1770 !$*%SYSTEMROOT%\SYSTEM32\LSASS.EXE
[Auto Services] :HKLM ScDeviceEnum
### Service: Smart Card Device Enumeration Service Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Creates software
device nodes for all smart card readers accessible to a given session. If this
service is disabled, WinRT APIs will not be able to enumerate smart card readers.
Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
LOCALSYSTEMNETWORKRESTRICTED
[Auto Services] :HKLM Schedule
### Service: Task Scheduler Status: Start Type: loaded automatically by Server
Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Enables a user to configure
and schedule automated tasks on this computer. The service also hosts multiple
Windows system-critical tasks. If this service is stopped or disabled, these tasks
will not be run at their scheduled times. If this service is disabled, any services
that explicitly depend on it will fail to start. Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS
[Auto Services] :HKLM SCPolicySvc
### Service: Smart Card Removal Policy Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Allows the system to be
configured to lock the user desktop upon smart card removal. Host Process for
Windows Services Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS
[Auto Services] :HKLM SDRSVC
### Service: Windows Backup Status: Start Type: loaded manually on demand Actual
File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Provides Windows Backup and Restore
capabilities. Host Process for Windows Services Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
SDRSVC
[Auto Services] :HKLM seclogon
### Service: Secondary Logon Status: Start Type: loaded manually on demand Actual
File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Enables starting processes under alternate
credentials. If this service is stopped, this type of logon access will be
unavailable. If this service is disabled, any services that explicitly depend on it
will fail to start. Host Process for Windows Services Microsoft Corporation
Microsoft� Windows� Operating System 10.0.14393.0 !$*%WINDIR%\SYSTEM32\SVCHOST.EXE
-K NETSVCS
[Auto Services] :HKLM SENS
### Service: System Event Notification Service Status: Start Type: loaded
automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE *
Monitors system events and notifies subscribers to COM+ Event System of these
events. Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS
[Auto Services] :HKLM Sense
### Service: Windows Defender Advanced Threat Protection Service Status: Start
Type: loaded manually on demand Actual File: C:\PROGRAM FILES\WINDOWS DEFENDER
ADVANCED THREAT PROTECTION\MSSENSE.EXE * @%ProgramFiles%\Windows Defender Advanced
Threat Protection\MsSense.exe,-1002 Windows Defender Advanced Threat Protection
Service Executable Microsoft Corporation Microsoft� Windows� Operating System
10.1407.14393.0 !$*"%PROGRAMFILES%\WINDOWS DEFENDER ADVANCED THREAT
PROTECTION\MSSENSE.EXE"
[Auto Services] :HKLM SensorDataService
### Service: Sensor Data Service Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\SENSORDATASERVICE.EXE * Delivers data from a
variety of sensors Sensor Data Service Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\SENSORDATASERVICE.EXE
[Auto Services] :HKLM SensorService
### Service: Sensor Service Status: Start Type: loaded manually on demand Actual
File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * A service for sensors that manages
different sensors' functionality. Manages Simple Device Orientation (SDO) and
History for sensors. Loads the SDO sensor that reports device orientation changes.
If this service is stopped or disabled, the SDO sensor will not be loaded and so
auto-rotation will not occur. History collection from Sensors will also be stopped.
Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
LOCALSYSTEMNETWORKRESTRICTED
[Auto Services] :HKLM SensrSvc
### Service: Sensor Monitoring Service Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Monitors various sensors in
order to expose data and adapt to system and user state. If this service is
stopped or disabled, the display brightness will not adapt to lighting conditions.
Stopping this service may affect other system functionality and features as well.
Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
LOCALSERVICEANDNOIMPERSONATION
[Auto Services] :HKLM SessionEnv
### Service: Remote Desktop Configuration Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Remote Desktop Configuration
service (RDCS) is responsible for all Remote Desktop Services and Remote Desktop
related configuration and session maintenance activities that require SYSTEM
context. These include per-session temporary folders, RD themes, and RD
certificates. Host Process for Windows Services Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
NETSVCS
[Auto Services] :HKLM SharedAccess
### Service: Internet Connection Sharing (ICS) Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Provides network
address translation, addressing, name resolution and/or intrusion prevention
services for a home or small office network. Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS
[Auto Services] :HKLM ShellHWDetection
### Service: Shell Hardware Detection Status: Start Type: loaded automatically by
Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Provides
notifications for AutoPlay hardware events. Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS
[Auto Services] :HKLM smphost
### Service: Microsoft Storage Spaces SMP Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Host service for the
Microsoft Storage Spaces management provider. If this service is stopped or
disabled, Storage Spaces cannot be managed. Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K SMPHOST
[Auto Services] :HKLM SmsRouter
### Service: Microsoft Windows SMS Router Service. Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Routes messages
based on rules to appropriate clients. Host Process for Windows Services Microsoft
Corporation Microsoft� Windows� Operating System 10.0.14393.0 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED
[Auto Services] :HKLM SNMPTRAP
### Service: SNMP Trap Status: Start Type: loaded manually on demand Actual File:
C:\WINDOWS\SYSTEM32\SNMPTRAP.EXE * Receives trap messages generated by local or
remote Simple Network Management Protocol (SNMP) agents and forwards the messages
to SNMP management programs running on this computer. If this service is stopped,
SNMP-based programs on this computer will not receive SNMP trap messages. If this
service is disabled, any services that explicitly depend on it will fail to start.
SNMP Trap Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0 !
$*%SYSTEMROOT%\SYSTEM32\SNMPTRAP.EXE
[Auto Services] :HKLM Spooler
### Service: Print Spooler Status: Start Type: loaded automatically by Server
Manager Actual File: C:\WINDOWS\SYSTEM32\SPOOLSV.EXE * This service spools print
jobs and handles interaction with the printer. If you turn off this service, you
won�t be able to print or see your printers. Spooler SubSystem App Microsoft
Corporation Microsoft� Windows� Operating System 10.0.14393.0 !$*%SYSTEMROOT
%\SYSTEM32\SPOOLSV.EXE
[Auto Services] :HKLM sppsvc
### Service: Software Protection Status: Start Type: loaded automatically by
Server Manager Actual File: C:\WINDOWS\SYSTEM32\SPPSVC.EXE * Enables the download,
installation and enforcement of digital licenses for Windows and Windows
applications. If the service is disabled, the operating system and licensed
applications may run in a notification mode. It is strongly recommended that you
not disable the Software Protection service. Microsoft Software Protection Platform
Service Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0 !$*
%SYSTEMROOT%\SYSTEM32\SPPSVC.EXE
[Auto Services] :HKLM SSDPSRV
### Service: SSDP Discovery Status: Start Type: loaded manually on demand Actual
File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Discovers networked devices and services
that use the SSDP discovery protocol, such as UPnP devices. Also announces SSDP
devices and services running on the local computer. If this service is stopped,
SSDP-based devices will not be discovered. If this service is disabled, any
services that explicitly depend on it will fail to start. Host Process for Windows
Services Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0 !
$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICEANDNOIMPERSONATION
[Auto Services] :HKLM SstpSvc
### Service: Secure Socket Tunneling Protocol Service Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Provides support
for the Secure Socket Tunneling Protocol (SSTP) to connect to remote computers
using VPN. If this service is disabled, users will not be able to use SSTP to
access remote servers. Host Process for Windows Services Microsoft Corporation
Microsoft� Windows� Operating System 10.0.14393.0 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE
[Auto Services] :HKLM StateRepository
### Service: State Repository Service Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Provides required
infrastructure support for the application model. Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K APPMODEL
[Auto Services] :HKLM stisvc
### Service: Windows Image Acquisition (WIA) Status: Start Type: loaded
automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE *
Provides image acquisition services for scanners and cameras Host Process for
Windows Services Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K IMGSVC
[Auto Services] :HKLM StorSvc
### Service: Storage Service Status: Start Type: loaded manually on demand Actual
File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Provides enabling services for storage
settings and external storage expansion Host Process for Windows Services Microsoft
Corporation Microsoft� Windows� Operating System 10.0.14393.0 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED
[Auto Services] :HKLM svsvc
### Service: Spot Verifier Status: Start Type: loaded manually on demand Actual
File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Verifies potential file system corruptions.
Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
LOCALSYSTEMNETWORKRESTRICTED
[Auto Services] :HKLM swprv
### Service: Microsoft Software Shadow Copy Provider Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Manages software-
based volume shadow copies taken by the Volume Shadow Copy service. If this service
is stopped, software-based volume shadow copies cannot be managed. If this service
is disabled, any services that explicitly depend on it will fail to start. Host
Process for Windows Services Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K SWPRV
[Auto Services] :HKLM SysMain
### Service: Superfetch Status: Start Type: loaded automatically by Server
Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Maintains and improves
system performance over time. Host Process for Windows Services Microsoft
Corporation Microsoft� Windows� Operating System 10.0.14393.0 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED
[Auto Services] :HKLM SystemEventsBroker
### Service: System Events Broker Status: Start Type: loaded automatically by
Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Coordinates execution
of background work for WinRT application. If this service is stopped or disabled,
then background work might not be triggered. Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K DCOMLAUNCH
[Auto Services] :HKLM TabletInputService
### Service: Touch Keyboard and Handwriting Panel Service Status: Start Type:
loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Enables
Touch Keyboard and Handwriting Panel pen and ink functionality Host Process for
Windows Services Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED
[Auto Services] :HKLM TapiSrv
### Service: Telephony Status: Start Type: loaded manually on demand Actual File:
C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Provides Telephony API (TAPI) support for
programs that control telephony devices on the local computer and, through the LAN,
on servers that are also running the service. Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETWORKSERVICE
[Auto Services] :HKLM TELKOMSELFlash. RunOuc
### Service: TELKOMSELFlash. OUC Status: Start Type: loaded automatically by
Server Manager Actual File: C:\PROGRAM FILES (X86)\TELKOMSELFLASH\UPDATEDOG\OUC.EXE
*
[Auto Services] :HKLM TermService
### Service: Remote Desktop Services Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Allows users to connect
interactively to a remote computer. Remote Desktop and Remote Desktop Session Host
Server depend on this service. To prevent remote use of this computer, clear the
checkboxes on the Remote tab of the System properties control panel item. Host
Process for Windows Services Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETWORKSERVICE
[Auto Services] :HKLM Themes
### Service: Themes Status: Start Type: loaded automatically by Server Manager
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Provides user experience theme
management. Host Process for Windows Services Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
NETSVCS
[Auto Services] :HKLM TieringEngineService
### Service: Storage Tiers Management Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\TIERINGENGINESERVICE.EXE * Optimizes the
placement of data in storage tiers on all tiered storage spaces in the system.
Storage Tiers Management Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\TIERINGENGINESERVICE.EXE
[Auto Services] :HKLM tiledatamodelsvc
### Service: Tile Data model server Status: Start Type: loaded automatically by
Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Tile Server for tile
updates. Host Process for Windows Services Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
APPMODEL
[Auto Services] :HKLM TimeBrokerSvc
### Service: Time Broker Status: Start Type: loaded manually on demand Actual
File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Coordinates execution of background work
for WinRT application. If this service is stopped or disabled, then background work
might not be triggered. Host Process for Windows Services Microsoft Corporation
Microsoft� Windows� Operating System 10.0.14393.0 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICENETWORKRESTRICTED
[Auto Services] :HKLM TrkWks
### Service: Distributed Link Tracking Client Status: Start Type: loaded
automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE *
Maintains links between NTFS files within a computer or across computers in a
network. Host Process for Windows Services Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
LOCALSYSTEMNETWORKRESTRICTED
[Auto Services] :HKLM TrustedInstaller
### Service: Windows Modules Installer Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SERVICING\TRUSTEDINSTALLER.EXE * Enables
installation, modification, and removal of Windows updates and optional components.
If this service is disabled, install or uninstall of Windows updates might fail for
this computer. Windows Modules Installer Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SYSTEMROOT%\SERVICING\TRUSTEDINSTALLER.EXE
[Auto Services] :HKLM UI0Detect
### Service: Interactive Services Detection Status: Start Type: loaded manually
on demand Actual File: C:\WINDOWS\SYSTEM32\UI0DETECT.EXE * Enables user
notification of user input for interactive services, which enables access to
dialogs created by interactive services when they appear. If this service is
stopped, notifications of new interactive service dialogs will no longer function
and there might not be access to interactive service dialogs. If this service is
disabled, both notifications of and access to new interactive service dialogs will
no longer function. Interactive services detection Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\UI0DETECT.EXE
[Auto Services] :HKLM UmRdpService
### Service: Remote Desktop Services UserMode Port Redirector Status: Start Type:
loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Allows the
redirection of Printers/Drives/Ports for RDP connections Host Process for Windows
Services Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0 !
$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED
[Auto Services] :HKLM UnistoreSvc
### Service: User Data Storage Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Handles storage of structured user
data, including contact info, calendars, messages, and other content. If you stop
or disable this service, apps that use this data might not work correctly. Host
Process for Windows Services Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K UNISTACKSVCGROUP
[Auto Services] :HKLM UnistoreSvc_2e64c
### Service: User Data Storage_2e64c Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Handles storage of structured
user data, including contact info, calendars, messages, and other content. If you
stop or disable this service, apps that use this data might not work correctly.
Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K
UNISTACKSVCGROUP
[Auto Services] :HKLM upnphost
### Service: UPnP Device Host Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Allows UPnP devices to be hosted on
this computer. If this service is stopped, any hosted UPnP devices will stop
functioning and no additional hosted devices can be added. If this service is
disabled, any services that explicitly depend on it will fail to start. Host
Process for Windows Services Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
LOCALSERVICEANDNOIMPERSONATION
[Auto Services] :HKLM UserDataSvc
### Service: User Data Access Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Provides apps access to structured
user data, including contact info, calendars, messages, and other content. If you
stop or disable this service, apps that use this data might not work correctly.
Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
UNISTACKSVCGROUP
[Auto Services] :HKLM UserDataSvc_2e64c
### Service: User Data Access_2e64c Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Provides apps access to structured
user data, including contact info, calendars, messages, and other content. If you
stop or disable this service, apps that use this data might not work correctly.
Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K
UNISTACKSVCGROUP
[Auto Services] :HKLM UserManager
### Service: User Manager Status: Start Type: loaded automatically by Server
Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * User Manager provides the
runtime components required for multi-user interaction. If this service is
stopped, some applications may not operate correctly. Host Process for Windows
Services Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0 !
$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS
[Auto Services] :HKLM UsoSvc
### Service: Update Orchestrator Service for Windows Update Status: Start Type:
loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * UsoSvc
Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS
[Auto Services] :HKLM VaultSvc
### Service: Credential Manager Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\LSASS.EXE * Provides secure storage and retrieval
of credentials to users, applications and security service packages. Local Security
Authority Process Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.1770 !$*%SYSTEMROOT%\SYSTEM32\LSASS.EXE
[Auto Services] :HKLM vds
### Service: Virtual Disk Status: Start Type: loaded manually on demand Actual
File: C:\WINDOWS\SYSTEM32\VDS.EXE * Provides management services for disks,
volumes, file systems, and storage arrays. Virtual Disk Service Microsoft
Corporation Microsoft� Windows� Operating System 10.0.14393.0 !$*%SYSTEMROOT
%\SYSTEM32\VDS.EXE
[Auto Services] :HKLM vmicguestinterface
### Service: Hyper-V Guest Service Interface Status: Start Type: loaded manually
on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Provides an interface for
the Hyper-V host to interact with specific services running inside the virtual
machine. Host Process for Windows Services Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
LOCALSYSTEMNETWORKRESTRICTED
[Auto Services] :HKLM vmicheartbeat
### Service: Hyper-V Heartbeat Service Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Monitors the state of this
virtual machine by reporting a heartbeat at regular intervals. This service helps
you identify running virtual machines that have stopped responding. Host Process
for Windows Services Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K ICSERVICE
[Auto Services] :HKLM vmickvpexchange
### Service: Hyper-V Data Exchange Service Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Provides a mechanism to
exchange data between the virtual machine and the operating system running on the
physical computer. Host Process for Windows Services Microsoft Corporation
Microsoft� Windows� Operating System 10.0.14393.0 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED
[Auto Services] :HKLM vmicrdv
### Service: Hyper-V Remote Desktop Virtualization Service Status: Start Type:
loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Provides a
platform for communication between the virtual machine and the operating system
running on the physical computer. Host Process for Windows Services Microsoft
Corporation Microsoft� Windows� Operating System 10.0.14393.0 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K ICSERVICE
[Auto Services] :HKLM vmicshutdown
### Service: Hyper-V Guest Shutdown Service Status: Start Type: loaded manually
on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Provides a mechanism to
shut down the operating system of this virtual machine from the management
interfaces on the physical computer. Host Process for Windows Services Microsoft
Corporation Microsoft� Windows� Operating System 10.0.14393.0 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED
[Auto Services] :HKLM vmictimesync
### Service: Hyper-V Time Synchronization Service Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Synchronizes the
system time of this virtual machine with the system time of the physical computer.
Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
LOCALSERVICENETWORKRESTRICTED
[Auto Services] :HKLM vmicvmsession
### Service: Hyper-V PowerShell Direct Service Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Provides a
mechanism to manage virtual machine with PowerShell via VM session without a
virtual network. Host Process for Windows Services Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
LOCALSYSTEMNETWORKRESTRICTED
[Auto Services] :HKLM vmicvss
### Service: Hyper-V Volume Shadow Copy Requestor Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Coordinates the
communications that are required to use Volume Shadow Copy Service to back up
applications and data on this virtual machine from the operating system on the
physical computer. Host Process for Windows Services Microsoft Corporation
Microsoft� Windows� Operating System 10.0.14393.0 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED
[Auto Services] :HKLM VSS
### Service: Volume Shadow Copy Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\VSSVC.EXE * Manages and implements Volume Shadow
Copies used for backup and other purposes. If this service is stopped, shadow
copies will be unavailable for backup and the backup may fail. If this service is
disabled, any services that explicitly depend on it will fail to start. Microsoft�
Volume Shadow Copy Service Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\VSSVC.EXE
[Auto Services] :HKLM W32Time
### Service: Windows Time Status: Start Type: loaded manually on demand Actual
File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Maintains date and time synchronization on
all clients and servers in the network. If this service is stopped, date and time
synchronization will be unavailable. If this service is disabled, any services that
explicitly depend on it will fail to start. Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE
[Auto Services] :HKLM WalletService
### Service: WalletService Status: Start Type: loaded manually on demand Actual
File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Hosts objects used by clients of the wallet
Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K APPMODEL
[Auto Services] :HKLM wbengine
### Service: Block Level Backup Engine Service Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\WBENGINE.EXE * The WBENGINE
service is used by Windows Backup to perform backup and recovery operations. If
this service is stopped by a user, it may cause the currently running backup or
recovery operation to fail. Disabling this service may disable backup and recovery
operations using Windows Backup on this computer. Microsoft� Block Level Backup
Engine Service EXE Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*"%SYSTEMROOT%\SYSTEM32\WBENGINE.EXE"
[Auto Services] :HKLM WbioSrvc
### Service: Windows Biometric Service Status: Start Type: loaded automatically
by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * The Windows
biometric service gives client applications the ability to capture, compare,
manipulate, and store biometric data without gaining direct access to any biometric
hardware or samples. The service is hosted in a privileged SVCHOST process. Host
Process for Windows Services Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K WBIOSVCGROUP
[Auto Services] :HKLM Wcmsvc
### Service: Windows Connection Manager Status: Start Type: loaded automatically
by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Makes automatic
connect/disconnect decisions based on the network connectivity options currently
available to the PC and enables management of network connectivity based on Group
Policy settings. Host Process for Windows Services Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
LOCALSERVICENETWORKRESTRICTED
[Auto Services] :HKLM wcncsvc
### Service: Windows Connect Now - Config Registrar Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * WCNCSVC hosts the
Windows Connect Now Configuration which is Microsoft's Implementation of Wireless
Protected Setup (WPS) protocol. This is used to configure Wireless LAN settings for
an Access Point (AP) or a Wireless Device. The service is started programmatically
as needed. Host Process for Windows Services Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
LOCALSERVICEANDNOIMPERSONATION
[Auto Services] :HKLM WdiServiceHost
### Service: Diagnostic Service Host Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * The Diagnostic Service Host
is used by the Diagnostic Policy Service to host diagnostics that need to run in a
Local Service context. If this service is stopped, any diagnostics that depend on
it will no longer function. Host Process for Windows Services Microsoft Corporation
Microsoft� Windows� Operating System 10.0.14393.0 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE
[Auto Services] :HKLM WdiSystemHost
### Service: Diagnostic System Host Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * The Diagnostic System Host is used
by the Diagnostic Policy Service to host diagnostics that need to run in a Local
System context. If this service is stopped, any diagnostics that depend on it will
no longer function. Host Process for Windows Services Microsoft Corporation
Microsoft� Windows� Operating System 10.0.14393.0 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED
[Auto Services] :HKLM WdNisSvc
### Service: Windows Defender Network Inspection Service Status: Start Type:
loaded manually on demand Actual File: C:\PROGRAM FILES\WINDOWS DEFENDER\NISSRV.EXE
* Helps guard against intrusion attempts targeting known and newly discovered
vulnerabilities in network protocols Microsoft Network Realtime Inspection Service
Microsoft Corporation Microsoft� Windows� Operating System 4.10.14393.1198 !
$*"%PROGRAMFILES%\WINDOWS DEFENDER\NISSRV.EXE"
[Auto Services] :HKLM WebClient
### Service: WebClient Status: Start Type: loaded manually on demand Actual File:
C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Enables Windows-based programs to create, access,
and modify Internet-based files. If this service is stopped, these functions will
not be available. If this service is disabled, any services that explicitly depend
on it will fail to start. Host Process for Windows Services Microsoft Corporation
Microsoft� Windows� Operating System 10.0.14393.0 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE
[Auto Services] :HKLM Wecsvc
### Service: Windows Event Collector Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * This service manages
persistent subscriptions to events from remote sources that support WS-Management
protocol. This includes Windows Vista event logs, hardware and IPMI-enabled event
sources. The service stores forwarded events in a local Event Log. If this service
is stopped or disabled event subscriptions cannot be created and forwarded events
cannot be accepted. Host Process for Windows Services Microsoft Corporation
Microsoft� Windows� Operating System 10.0.14393.0 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K NETWORKSERVICE
[Auto Services] :HKLM WEPHOSTSVC
### Service: Windows Encryption Provider Host Service Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Windows
Encryption Provider Host Service brokers encryption related functionalities from
3rd Party Encryption Providers to processes that need to evaluate and apply EAS
policies. Stopping this will compromise EAS compliancy checks that have been
established by the connected Mail Accounts Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K WEPHOSTSVCGROUP
[Auto Services] :HKLM wercplsupport
### Service: Problem Reports and Solutions Control Panel Support Status: Start
Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * This
service provides support for viewing, sending and deletion of system-level problem
reports for the Problem Reports and Solutions control panel. Host Process for
Windows Services Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS
[Auto Services] :HKLM WerSvc
### Service: Windows Error Reporting Service Status: Start Type: loaded manually
on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Allows errors to be
reported when programs stop working or responding and allows existing solutions to
be delivered. Also allows logs to be generated for diagnostic and repair services.
If this service is stopped, error reporting might not work correctly and results of
diagnostic services and repairs might not be displayed. Host Process for Windows
Services Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0 !
$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K WERSVCGROUP
[Auto Services] :HKLM WiaRpc
### Service: Still Image Acquisition Events Status: Start Type: loaded manually
on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Launches applications
associated with still image acquisition events. Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED
[Auto Services] :HKLM WinDefend
### Service: Windows Defender Service Status: Start Type: loaded automatically by
Server Manager Actual File: C:\PROGRAM FILES\WINDOWS DEFENDER\MSMPENG.EXE * Helps
protect users from malware and other potentially unwanted software Antimalware
Service Executable Microsoft Corporation Microsoft� Windows� Operating System
4.10.14393.1613 !$*"%PROGRAMFILES%\WINDOWS DEFENDER\MSMPENG.EXE"
[Auto Services] :HKLM WinHttpAutoProxySvc
### Service: WinHTTP Web Proxy Auto-Discovery Service Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * WinHTTP
implements the client HTTP stack and provides developers with a Win32 API and COM
Automation component for sending HTTP requests and receiving responses. In
addition, WinHTTP provides support for auto-discovering a proxy configuration via
its implementation of the Web Proxy Auto-Discovery (WPAD) protocol. Host Process
for Windows Services Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE
[Auto Services] :HKLM Winmgmt
### Service: Windows Management Instrumentation Status: Start Type: loaded
automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE *
Provides a common interface and object model to access management information about
operating system, devices, applications and services. If this service is stopped,
most Windows-based software will not function properly. If this service is
disabled, any services that explicitly depend on it will fail to start. Host
Process for Windows Services Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS
[Auto Services] :HKLM WinRM
### Service: Windows Remote Management (WS-Management) Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Windows Remote
Management (WinRM) service implements the WS-Management protocol for remote
management. WS-Management is a standard web services protocol used for remote
software and hardware management. The WinRM service listens on the network for WS-
Management requests and processes them. The WinRM Service needs to be configured
with a listener using winrm.cmd command line tool or through Group Policy in order
for it to listen over the network. The WinRM service provides access to WMI data
and enables event collection. Event collection and subscription to events require
that the service is running. WinRM messages use HTTP and HTTPS as transports. The
WinRM service does not depend on IIS but is preconfigured to share a port with IIS
on the same machine. The WinRM service reserves the /wsman URL prefix. To prevent
conflicts with IIS, administrators should ensure that any websites hosted on IIS do
not use the /wsman URL prefix. Host Process for Windows Services Microsoft
Corporation Microsoft� Windows� Operating System 10.0.14393.0 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K NETWORKSERVICE
[Auto Services] :HKLM wisvc
### Service: Windows Insider Service Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * wisvc Host Process for
Windows Services Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS
[Auto Services] :HKLM WlanSvc
### Service: WLAN AutoConfig Status: Start Type: loaded automatically by Server
Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * The WLANSVC service provides
the logic required to configure, discover, connect to, and disconnect from a
wireless local area network (WLAN) as defined by IEEE 802.11 standards. It also
contains the logic to turn your computer into a software access point so that other
devices or computers can connect to your computer wirelessly using a WLAN adapter
that can support this. Stopping or disabling the WLANSVC service will make all WLAN
adapters on your computer inaccessible from the Windows networking UI. It is
strongly recommended that you have the WLANSVC service running if your computer has
a WLAN adapter. Host Process for Windows Services Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
LOCALSYSTEMNETWORKRESTRICTED
[Auto Services] :HKLM wlidsvc
### Service: Microsoft Account Sign-in Assistant Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Enables user
sign-in through Microsoft account identity services. If this service is stopped,
users will not be able to logon to the computer with their Microsoft account. Host
Process for Windows Services Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS
[Auto Services] :HKLM wmiApSrv
### Service: WMI Performance Adapter Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\WBEM\WMIAPSRV.EXE * Provides performance
library information from Windows Management Instrumentation (WMI) providers to
clients on the network. This service only runs when Performance Data Helper is
activated. WMI Performance Reverse Adapter Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\WBEM\WMIAPSRV.EXE
[Auto Services] :HKLM WMPNetworkSvc
### Service: Windows Media Player Network Sharing Service Status: Start Type:
loaded manually on demand Actual File: C:\PROGRAM FILES\WINDOWS MEDIA
PLAYER\WMPNETWK.EXE * @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-102
Windows Media Player Network Sharing Service Microsoft Corporation Microsoft�
Windows� Operating System 12.0.14393.0 !$*"%PROGRAMFILES%\WINDOWS MEDIA
PLAYER\WMPNETWK.EXE"
[Auto Services] :HKLM workfolderssvc
### Service: Work Folders Status: Start Type: loaded manually on demand Actual
File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * This service syncs files with the Work
Folders server, enabling you to use the files on any of the PCs and devices on
which you've set up Work Folders. Host Process for Windows Services Microsoft
Corporation Microsoft� Windows� Operating System 10.0.14393.0 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE
[Auto Services] :HKLM WPDBusEnum
### Service: Portable Device Enumerator Service Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Enforces group
policy for removable mass-storage devices. Enables applications such as Windows
Media Player and Image Import Wizard to transfer and synchronize content using
removable mass-storage devices. Host Process for Windows Services Microsoft
Corporation Microsoft� Windows� Operating System 10.0.14393.0 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED
[Auto Services] :HKLM WpnService
### Service: Windows Push Notifications System Service Status: Start Type: loaded
automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * This
service runs in session 0 and hosts the notification platform and connection
provider which handles the connection between the device and WNS server. Host
Process for Windows Services Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS
[Auto Services] :HKLM WpnUserService
### Service: Windows Push Notifications User Service Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * This service
hosts Windows notification platform which provides support for local and push
notifications. Supported notifications are tile, toast and raw. Host Process for
Windows Services Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K UNISTACKSVCGROUP
[Auto Services] :HKLM WpnUserService_2e64c
### Service: Windows Push Notifications User Service_2e64c Status: Start Type:
loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * This
service hosts Windows notification platform which provides support for local and
push notifications. Supported notifications are tile, toast and raw. Host Process
for Windows Services Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K UNISTACKSVCGROUP
[Auto Services] :HKLM WsAppService
### Service: Wondershare Application Framework Service Status: Start Type: loaded
automatically by Server Manager Actual File: C:\PROGRAM FILES
(X86)\WONDERSHARE\WAF\2.3.0.5\WSAPPSERVICE.EXE * Wondershare Application Framework
Service Wondershare AppService Wondershare Wondershare App Framework 2.3.0.5
[Auto Services] :HKLM WsDrvInst
### Service: Wondershare Driver Install Service Status: Start Type: loaded
manually on demand Actual File: C:\PROGRAM FILES (X86)\WONDERSHARE\DRFONE FOR
IOS\DRIVERINSTALL.EXE * Wondershare Driver Install Service File is missing.
[Auto Services] :HKLM WSearch
### Service: Windows Search Status: Start Type: loaded automatically by Server
Manager Actual File: C:\WINDOWS\SYSTEM32\SEARCHINDEXER.EXE * Provides content
indexing, property caching, and search results for files, e-mail, and other
content. Microsoft Windows Search Indexer Microsoft Corporation Windows� Search
7.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\SEARCHINDEXER.EXE /EMBEDDING
[Auto Services] :HKLM wuauserv
### Service: Windows Update Status: Start Type: loaded manually on demand Actual
File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Enables the detection, download, and
installation of updates for Windows and other programs. If this service is
disabled, users of this computer will not be able to use Windows Update or its
automatic updating feature, and programs will not be able to use the Windows Update
Agent (WUA) API. Host Process for Windows Services Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
NETSVCS
[Auto Services] :HKLM wudfsvc
### Service: Windows Driver Foundation - User-mode Driver Framework Status: Start
Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE *
Creates and manages user-mode driver processes. This service cannot be stopped.
Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
LOCALSYSTEMNETWORKRESTRICTED
[Auto Services] :HKLM WwanSvc
### Service: WWAN AutoConfig Status: Start Type: loaded manually on demand Actual
File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * This service manages mobile broadband (GSM
& CDMA) data card/embedded module adapters and connections by auto-configuring the
networks. It is strongly recommended that this service be kept running for best
user experience of mobile broadband devices. Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICENONETWORK
[Auto Services] :HKLM XblAuthManager
### Service: Xbox Live Auth Manager Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Provides authentication and
authorization services for interacting with Xbox Live. If this service is stopped,
some applications may not operate correctly. Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS
[Auto Services] :HKLM XblGameSave
### Service: Xbox Live Game Save Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * This service syncs save data for
Xbox Live save enabled games. If this service is stopped, game save data will not
upload to or download from Xbox Live. Host Process for Windows Services Microsoft
Corporation Microsoft� Windows� Operating System 10.0.14393.0 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K NETSVCS
[Auto Services] :HKLM XboxNetApiSvc
### Service: Xbox Live Networking Service Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * This service supports the
Windows.Networking.XboxLive application programming interface. Host Process for
Windows Services Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS
[Auto Services] :HKLM ZipService
### Service: ZipService Status: Start Type: loaded automatically by Server
Manager Actual File: C:\PROGRAMDATA\ZIPSERVICE.EXE * Adobe Installer Adobe Systems
Incorporated Adobe Installer 4.2.0.215
[Svchost DLLs] :HKLM CertPropSvc=C:\WINDOWS\SYSTEM32\CERTPROP.DLL
### Microsoft Smartcard Certificate Propagation Service Microsoft Corporation
Microsoft� Windows� Operating System 10.0.14393.0 !$*%SystemRoot
%\System32\certprop.dll
[Svchost DLLs] :HKLM SCPolicySvc=C:\WINDOWS\SYSTEM32\CERTPROP.DLL
### Microsoft Smartcard Certificate Propagation Service Microsoft Corporation
Microsoft� Windows� Operating System 10.0.14393.0 !$*%SystemRoot
%\System32\certprop.dll
[Svchost DLLs] :HKLM gpsvc=C:\WINDOWS\SYSTEM32\GPSVC.DLL
### Group Policy Client Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%SystemRoot%\System32\gpsvc.dll
[Svchost DLLs] :HKLM iphlpsvc=C:\WINDOWS\SYSTEM32\IPHLPSVC.DLL
### Service that offers IPv6 connectivity over an IPv4 network. Microsoft
Corporation Microsoft� Windows� Operating System 10.0.14393.0 !$*%SystemRoot
%\System32\iphlpsvc.dll
[Svchost DLLs] :HKLM msiscsi=C:\WINDOWS\SYSTEM32\ISCSIEXE.DLL
### iSCSI Discovery service Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%systemroot%\system32\iscsiexe.dll
[Svchost DLLs] :HKLM schedule=C:\WINDOWS\SYSTEM32\SCHEDSVC.DLL
### Task Scheduler Service Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%systemroot%\system32\schedsvc.dll
[Svchost DLLs] :HKLM winmgmt=C:\WINDOWS\SYSTEM32\WBEM\WMISVC.DLL
### WMI Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0 !
$*%SystemRoot%\system32\wbem\WMIsvc.dll
[Svchost DLLs] :HKLM SessionEnv=C:\WINDOWS\SYSTEM32\SESSENV.DLL
### Remote Desktop Configuration service Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 !$*%SystemRoot%\system32\sessenv.dll
[Svchost DLLs] :HKLM FastUserSwitchingCompatibility
[Svchost DLLs] :HKLM Ias
[Svchost DLLs] :HKLM Irmon=C:\WINDOWS\SYSTEM32\IRMON.DLL
### Infrared Monitor Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*%SystemRoot%\System32\irmon.dll
[Svchost DLLs] :HKLM Nla
[Svchost DLLs] :HKLM Ntmssvc
[Svchost DLLs] :HKLM NWCWorkstation
[Svchost DLLs] :HKLM Nwsapagent
[Svchost DLLs] :HKLM Rasauto=C:\WINDOWS\SYSTEM32\RASAUTO.DLL
### Remote Access AutoDial Manager Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SystemRoot%\System32\rasauto.dll
[Svchost DLLs] :HKLM Rasman=C:\WINDOWS\SYSTEM32\RASMANS.DLL
### Remote Access Connection Manager Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SystemRoot%\System32\rasmans.dll
[Svchost DLLs] :HKLM Remoteaccess=C:\WINDOWS\SYSTEM32\MPRDIM.DLL
### Dynamic Interface Manager Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%SystemRoot%\System32\mprdim.dll
[Svchost DLLs] :HKLM SENS=C:\WINDOWS\SYSTEM32\SENS.DLL
### System Event Notification Service (SENS) Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 !$*%SystemRoot%\System32\sens.dll
[Svchost DLLs] :HKLM Sharedaccess=C:\WINDOWS\SYSTEM32\IPNATHLP.DLL
### Microsoft NAT Helper Components Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SystemRoot%\System32\ipnathlp.dll
[Svchost DLLs] :HKLM SRService
[Svchost DLLs] :HKLM Tapisrv=C:\WINDOWS\SYSTEM32\TAPISRV.DLL
### Microsoft� Windows(TM) Telephony Server Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 !$*%SystemRoot%\System32\tapisrv.dll
[Svchost DLLs] :HKLM Wmi
[Svchost DLLs] :HKLM WmdmPmSp
[Svchost DLLs] :HKLM wuauserv=C:\WINDOWS\SYSTEM32\WUAUENG.DLL
### Windows Update Agent Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%systemroot%\system32\wuaueng.dll
[Svchost DLLs] :HKLM BITS=C:\WINDOWS\SYSTEM32\QMGR.DLL
### Background Intelligent Transfer Service Microsoft Corporation Microsoft�
Windows� Operating System 7.8.14393.0 !$*%SystemRoot%\System32\qmgr.dll
[Svchost DLLs] :HKLM ShellHWDetection=C:\WINDOWS\SYSTEM32\SHSVCS.DLL
### Windows Shell Services Dll Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SystemRoot%\System32\shsvcs.dll
[Svchost DLLs] :HKLM LogonHours
[Svchost DLLs] :HKLM PCAudit
[Svchost DLLs] :HKLM helpsvc
[Svchost DLLs] :HKLM uploadmgr
[Svchost DLLs] :HKLM AppMgmt=C:\WINDOWS\SYSTEM32\APPMGMTS.DLL
### Software installation Service Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SystemRoot%\System32\appmgmts.dll
[Svchost DLLs] :HKLM UserManager=C:\WINDOWS\SYSTEM32\USERMGR.DLL
### UserMgr Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*%SystemRoot%\System32\usermgr.dll
[Svchost DLLs] :HKLM NetSetupSvc=C:\WINDOWS\SYSTEM32\NETSETUPSVC.DLL
### Network Setup Service Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%SystemRoot%\System32\NetSetupSvc.dll
[Svchost DLLs] :HKLM lanmanserver=C:\WINDOWS\SYSTEM32\SRVSVC.DLL
### Server Service DLL Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*%SystemRoot%\system32\srvsvc.dll
[Svchost DLLs] :HKLM ScDeviceEnum=C:\WINDOWS\SYSTEM32\SCDEVICEENUM.DLL
### Smart Card Device Enumeration Service Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 !$*%SystemRoot%\System32\ScDeviceEnum.dll
[Svchost DLLs] :HKLM WiaRpc=C:\WINDOWS\SYSTEM32\WIARPC.DLL
### Windows Image Acquisition RPC client DLL Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 !$*%SystemRoot%\System32\wiarpc.dll
[Svchost DLLs] :HKLM dot3svc=C:\WINDOWS\SYSTEM32\DOT3SVC.DLL
### Wired AutoConfig Service Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%SystemRoot%\System32\dot3svc.dll
[Svchost DLLs] :HKLM Netman=C:\WINDOWS\SYSTEM32\NETMAN.DLL
### Network Connections Manager Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SystemRoot%\System32\netman.dll
[Svchost DLLs] :HKLM WPDBusEnum=C:\WINDOWS\SYSTEM32\WPDBUSENUM.DLL
### Portable Device Enumerator Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SystemRoot%\system32\wpdbusenum.dll
[Svchost DLLs] :HKLM NcbService=C:\WINDOWS\SYSTEM32\NCBSERVICE.DLL
### Network Connection Broker Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%SystemRoot%\System32\ncbservice.dll
[Svchost DLLs] :HKLM wlansvc=C:\WINDOWS\SYSTEM32\WLANSVC.DLL
### Windows WLAN AutoConfig Service DLL Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SystemRoot%\System32\wlansvc.dll
[Svchost DLLs] :HKLM
AudioEndpointBuilder=C:\WINDOWS\SYSTEM32\AUDIOENDPOINTBUILDER.DLL
### Windows Audio Endpoint Builder Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SystemRoot%\System32\AudioEndpointBuilder.dll
[Svchost DLLs] :HKLM DeviceAssociationService=C:\WINDOWS\SYSTEM32\DAS.DLL
### Device Association Service Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SystemRoot%\system32\das.dll
[Svchost DLLs] :HKLM netprofm=C:\WINDOWS\SYSTEM32\NETPROFMSVC.DLL
### Network List Manager Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%SystemRoot%\System32\netprofmsvc.dll
[Svchost DLLs] :HKLM WebClient=C:\WINDOWS\SYSTEM32\WEBCLNT.DLL
### Web DAV Service DLL Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%SystemRoot%\System32\webclnt.dll
[Svchost DLLs] :HKLM WinHttpAutoProxySvc=C:\WINDOWS\SYSTEM32\WINHTTP.DLL
### Windows HTTP Services Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%SystemRoot%\system32\winhttp.dll
[Svchost DLLs] :HKLM StiSvc=C:\WINDOWS\SYSTEM32\WIASERVC.DLL
### Still Image Devices Service Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SystemRoot%\System32\wiaservc.dll
[Svchost DLLs] :HKLM PLA=C:\WINDOWS\SYSTEM32\PLA.DLL
### Performance Logs & Alerts Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%systemroot%\system32\pla.dll
[Svchost DLLs] :HKLM smphost=C:\WINDOWS\SYSTEM32\SMPHOST.DLL
### Storage Management Provider (SMP) host service Microsoft Corporation
Microsoft� Windows� Operating System 10.0.14393.0 !$*%Systemroot
%\System32\smphost.dll
[Svchost DLLs] :HKLM RpcSs=C:\WINDOWS\SYSTEM32\RPCSS.DLL
### Distributed COM Services Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.1198 !$*%SystemRoot%\system32\rpcss.dll
[Svchost DLLs] :HKLM wscsvc=C:\WINDOWS\SYSTEM32\WSCSVC.DLL
### Windows Security Center Service Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SystemRoot%\System32\wscsvc.dll
[Svchost DLLs] :HKLM LmHosts=C:\WINDOWS\SYSTEM32\LMHSVC.DLL
### TCPIP NetBios Transport Services DLL Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 !$*%SystemRoot%\System32\lmhsvc.dll
[Svchost DLLs] :HKLM AudioSrv=C:\WINDOWS\SYSTEM32\AUDIOSRV.DLL
### Windows Audio Service Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%SystemRoot%\System32\Audiosrv.dll
[Svchost DLLs] :HKLM DHCP=C:\WINDOWS\SYSTEM32\DHCPCORE.DLL
### DHCP Client Service Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%SystemRoot%\system32\dhcpcore.dll
[Svchost DLLs] :HKLM
StateRepository=C:\WINDOWS\SYSTEM32\WINDOWS.STATEREPOSITORY.DLL
### Windows StateRepository API Server Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SystemRoot%\system32\windows.staterepository.dll
[Svchost DLLs] :HKLM SSDPSRV=C:\WINDOWS\SYSTEM32\SSDPSRV.DLL
### SSDP Service DLL Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*%SystemRoot%\System32\ssdpsrv.dll
[Svchost DLLs] :HKLM upnphost=C:\WINDOWS\SYSTEM32\UPNPHOST.DLL
### UPnP Device Host Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*%SystemRoot%\System32\upnphost.dll
[Svchost DLLs] :HKLM SCardSvr=C:\WINDOWS\SYSTEM32\SCARDSVR.DLL
### Smart Card Resource Management Server Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 !$*%SystemRoot%\System32\SCardSvr.dll
[Svchost DLLs] :HKLM QWAVE=C:\WINDOWS\SYSTEM32\QWAVE.DLL
### Windows NT Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*%windir%\system32\qwave.dll
[Svchost DLLs] :HKLM wcncsvc=C:\WINDOWS\SYSTEM32\WCNCSVC.DLL
### Windows Connect Now - Config Registrar Service Microsoft Corporation
Microsoft� Windows� Operating System 10.0.14393.0 !$*%SystemRoot
%\System32\wcncsvc.dll
[Svchost DLLs] :HKLM BthHFSrv=C:\WINDOWS\SYSTEM32\BTHHFSRV.DLL
### Bluetooth Handsfree Service Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SystemRoot%\System32\BthHFSrv.dll
[Svchost DLLs] :HKLM PlugPlay=C:\WINDOWS\SYSTEM32\UMPNPMGR.DLL
### User-mode Plug-and-Play Service Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SystemRoot%\system32\umpnpmgr.dll
[Svchost DLLs] :HKLM DeviceInstall=C:\WINDOWS\SYSTEM32\UMPNPMGR.DLL
### User-mode Plug-and-Play Service Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SystemRoot%\system32\umpnpmgr.dll
[Svchost DLLs] :HKLM DcomLaunch=C:\WINDOWS\SYSTEM32\RPCSS.DLL
### Distributed COM Services Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.1198 !$*%SystemRoot%\system32\rpcss.dll
[Svchost DLLs] :HKLM CryptSvc=C:\WINDOWS\SYSTEM32\CRYPTSVC.DLL
### Cryptographic Services Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%SystemRoot%\system32\cryptsvc.dll
[Svchost DLLs] :HKLM WECSVC=C:\WINDOWS\SYSTEM32\WECSVC.DLL
### Event Collector Service Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%SystemRoot%\system32\wecsvc.dll
[Svchost DLLs] :HKLM TermService=C:\WINDOWS\SYSTEM32\TERMSRV.DLL
### Remote Desktop Session Host Server Remote Connections Manager Microsoft
Corporation Microsoft� Windows� Operating System 10.0.14393.0 !$*%SystemRoot
%\System32\termsrv.dll
[Svchost DLLs] :HKLM WinRM=C:\WINDOWS\SYSTEM32\WSMSVC.DLL
### WSMan Service Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*%SystemRoot%\system32\WsmSvc.dll
[Svchost DLLs] :HKLM DNSCache=C:\WINDOWS\SYSTEM32\DNSRSLVR.DLL
### DNS Caching Resolver Service Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SystemRoot%\System32\dnsrslvr.dll
[Svchost DLLs] :HKLM AJRouter=C:\WINDOWS\SYSTEM32\AJROUTER.DLL
### AllJoyn Router Service DLL Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SystemRoot%\System32\AJRouter.dll
[Svchost DLLs] :HKLM AppIDSvc=C:\WINDOWS\SYSTEM32\APPIDSVC.DLL
### Application Identity Service Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SystemRoot%\System32\appidsvc.dll
[Svchost DLLs] :HKLM Appinfo=C:\WINDOWS\SYSTEM32\APPINFO.DLL
### Application Information Service Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SystemRoot%\System32\appinfo.dll
[Svchost DLLs] :HKLM AppReadiness=C:\WINDOWS\SYSTEM32\APPREADINESS.DLL
### AppReadiness Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*%SystemRoot%\system32\AppReadiness.dll
[Svchost DLLs] :HKLM AxInstSV=C:\WINDOWS\SYSTEM32\AXINSTSV.DLL
### ActiveX Installer Service Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%SystemRoot%\System32\AxInstSV.dll
[Svchost DLLs] :HKLM BDESVC=C:\WINDOWS\SYSTEM32\BDESVC.DLL
### BDE Service Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*%SystemRoot%\System32\bdesvc.dll
[Svchost DLLs] :HKLM BFE=C:\WINDOWS\SYSTEM32\BFE.DLL
### Base Filtering Engine Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%SystemRoot%\System32\bfe.dll
[Svchost DLLs] :HKLM BrokerInfrastructure=C:\WINDOWS\SYSTEM32\BISRV.DLL
### Background Tasks Infrastructure Service Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 !$*%SystemRoot%\System32\bisrv.dll
[Svchost DLLs] :HKLM Browser=C:\WINDOWS\SYSTEM32\BROWSER.DLL
### Computer Browser Service DLL Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SystemRoot%\System32\browser.dll
[Svchost DLLs] :HKLM bthserv=C:\WINDOWS\SYSTEM32\BTHSERV.DLL
### Bluetooth Support Service Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%SystemRoot%\system32\bthserv.dll
[Svchost DLLs] :HKLM CDPSvc=C:\WINDOWS\SYSTEM32\CDPSVC.DLL
### Microsoft (R) CDP Service Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%SystemRoot%\System32\CDPSvc.dll
[Svchost DLLs] :HKLM CDPUserSvc=C:\WINDOWS\SYSTEM32\CDPUSERSVC.DLL
### Microsoft (R) CDP User Components Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.479 !$*%SystemRoot%\System32\CDPUserSvc.dll
[Svchost DLLs] :HKLM ClipSVC=C:\WINDOWS\SYSTEM32\CLIPSVC.DLL
### Client License Service Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%SystemRoot%\System32\ClipSVC.dll
[Svchost DLLs] :HKLM CoreMessagingRegistrar=C:\WINDOWS\SYSTEM32\COREMESSAGING.DLL
### Microsoft CoreMessaging Dll Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SystemRoot%\system32\coremessaging.dll
[Svchost DLLs] :HKLM CscService=C:\WINDOWS\SYSTEM32\CSCSVC.DLL
### CSC Service DLL Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*%SystemRoot%\System32\cscsvc.dll
[Svchost DLLs] :HKLM DcpSvc=C:\WINDOWS\SYSTEM32\DCPSVC.DLL
### dcpsvc Task Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*%SystemRoot%\system32\dcpsvc.dll
[Svchost DLLs] :HKLM defragsvc=C:\WINDOWS\SYSTEM32\DEFRAGSVC.DLL
### Microsoft\Drive Optimizer Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%Systemroot%\System32\defragsvc.dll
[Svchost DLLs] :HKLM DevQueryBroker=C:\WINDOWS\SYSTEM32\DEVQUERYBROKER.DLL
### DevQuery Background Discovery Broker Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 !$*%SystemRoot%\system32\DevQueryBroker.dll
[Svchost DLLs] :HKLM DiagTrack=C:\WINDOWS\SYSTEM32\DIAGTRACK.DLL
### Microsoft Windows Diagnostics Tracking Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 !$*%SystemRoot%\system32\diagtrack.dll
[Svchost DLLs] :HKLM
DmEnrollmentSvc=C:\WINDOWS\SYSTEM32\WINDOWS.INTERNAL.MANAGEMENT.DLL
### Windows Managent Service DLL Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%systemroot
%\system32\Windows.Internal.Management.dll
[Svchost DLLs] :HKLM dmwappushservice=C:\WINDOWS\SYSTEM32\DMWAPPUSHSVC.DLL
### dmwappushsvc Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*%SystemRoot%\system32\dmwappushsvc.dll
[Svchost DLLs] :HKLM DPS=C:\WINDOWS\SYSTEM32\DPS.DLL
### WDI Diagnostic Policy Service Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SystemRoot%\system32\dps.dll
[Svchost DLLs] :HKLM DsmSvc=C:\WINDOWS\SYSTEM32\DEVICESETUPMANAGER.DLL
### Device Setup Manager Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%SystemRoot%\System32\DeviceSetupManager.dll
[Svchost DLLs] :HKLM DsSvc=C:\WINDOWS\SYSTEM32\DSSVC.DLL
### Data Sharing Service NT Service DLL Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SystemRoot%\System32\DsSvc.dll
[Svchost DLLs] :HKLM EapHost=C:\WINDOWS\SYSTEM32\EAPSVC.DLL
### Microsoft EAPHost service Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%SystemRoot%\System32\eapsvc.dll
[Svchost DLLs] :HKLM EFS=C:\WINDOWS\SYSTEM32\EFSSVC.DLL
### EFS Service Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*%SystemRoot%\system32\efssvc.dll
[Svchost DLLs] :HKLM embeddedmode=C:\WINDOWS\SYSTEM32\EMBEDDEDMODESVC.DLL
### Debug Register Service Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%SystemRoot%\System32\embeddedmodesvc.dll
[Svchost DLLs] :HKLM EventSystem=C:\WINDOWS\SYSTEM32\ES.DLL
### COM+ Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*%systemroot%\system32\es.dll
[Svchost DLLs] :HKLM fdPHost=C:\WINDOWS\SYSTEM32\FDPHOST.DLL
### Function Discovery Provider host service Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 !$*%SystemRoot%\system32\fdPHost.dll
[Svchost DLLs] :HKLM FDResPub=C:\WINDOWS\SYSTEM32\FDRESPUB.DLL
### Function Discovery Resource Publication Service Microsoft Corporation
Microsoft� Windows� Operating System 10.0.14393.0 !$*%SystemRoot
%\system32\fdrespub.dll
[Svchost DLLs] :HKLM fhsvc=C:\WINDOWS\SYSTEM32\FHSVC.DLL
### File History Service Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%SystemRoot%\system32\fhsvc.dll
[Svchost DLLs] :HKLM FontCache=C:\WINDOWS\SYSTEM32\FNTCACHE.DLL
### Windows Font Cache Service Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SystemRoot%\system32\FntCache.dll
[Svchost DLLs] :HKLM hidserv=C:\WINDOWS\SYSTEM32\HIDSERV.DLL
### Human Interface Device Service Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SystemRoot%\system32\hidserv.dll
[Svchost DLLs] :HKLM HomeGroupListener=C:\WINDOWS\SYSTEM32\LISTSVC.DLL
### Windows HomeGroup Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*%SystemRoot%\system32\ListSvc.dll
[Svchost DLLs] :HKLM HomeGroupProvider=C:\WINDOWS\SYSTEM32\PROVSVC.DLL
### Windows HomeGroup Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*%SystemRoot%\system32\provsvc.dll
[Svchost DLLs] :HKLM HvHost=C:\WINDOWS\SYSTEM32\HVHOSTSVC.DLL
### Microsoft Hypervisor Host Service Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SystemRoot%\System32\hvhostsvc.dll
[Svchost DLLs] :HKLM icssvc=C:\WINDOWS\SYSTEM32\TETHERINGSERVICE.DLL
### Tethering Service Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*%SystemRoot%\System32\tetheringservice.dll
[Svchost DLLs] :HKLM IKEEXT=C:\WINDOWS\SYSTEM32\IKEEXT.DLL
### IKE extension Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*%SystemRoot%\System32\ikeext.dll
[Svchost DLLs] :HKLM KeyIso=C:\WINDOWS\SYSTEM32\KEYISO.DLL
### CNG Key Isolation Service Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%SystemRoot%\system32\keyiso.dll
[Svchost DLLs] :HKLM KtmRm=C:\WINDOWS\SYSTEM32\MSDTCKRM.DLL
### Microsoft Distributed Transaction Coordinator OLE Transactions KTM Resource
Manager DLL Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0
!$*%systemroot%\system32\msdtckrm.dll
[Svchost DLLs] :HKLM LanmanWorkstation=C:\WINDOWS\SYSTEM32\WKSSVC.DLL
### Workstation Service DLL Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%SystemRoot%\System32\wkssvc.dll
[Svchost DLLs] :HKLM lfsvc=C:\WINDOWS\SYSTEM32\LFSVC.DLL
### Geolocation Service Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%SystemRoot%\System32\lfsvc.dll
[Svchost DLLs] :HKLM LicenseManager=C:\WINDOWS\SYSTEM32\LICENSEMANAGERSVC.DLL
### LicenseManagerSvc Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*%SystemRoot%\system32\LicenseManagerSvc.dll
[Svchost DLLs] :HKLM lltdsvc=C:\WINDOWS\SYSTEM32\LLTDSVC.DLL
### Link-Layer Topology Mapper Service Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SystemRoot%\System32\lltdsvc.dll
[Svchost DLLs] :HKLM LSM=C:\WINDOWS\SYSTEM32\LSM.DLL
### Local Session Manager Service Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SystemRoot%\System32\lsm.dll
[Svchost DLLs] :HKLM MapsBroker=C:\WINDOWS\SYSTEM32\MOSHOST.DLL
### Downloaded Maps Manager Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%SystemRoot%\System32\moshost.dll
[Svchost DLLs] :HKLM MessagingService=C:\WINDOWS\SYSTEM32\MESSAGINGSERVICE.DLL
### Messaging Service Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*%SystemRoot%\System32\MessagingService.dll
[Svchost DLLs] :HKLM MpsSvc=C:\WINDOWS\SYSTEM32\MPSSVC.DLL
### Microsoft Protection Service Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SystemRoot%\system32\mpssvc.dll
[Svchost DLLs] :HKLM NcaSvc=C:\WINDOWS\SYSTEM32\NCASVC.DLL
### Microsoft Network Connectivity Assistant Service Microsoft Corporation
Microsoft� Windows� Operating System 10.0.14393.0 !$*%SystemRoot
%\System32\ncasvc.dll
[Svchost DLLs] :HKLM NcdAutoSetup=C:\WINDOWS\SYSTEM32\NCDAUTOSETUP.DLL
### Network Connected Devices Auto-Setup service DLL Microsoft Corporation
Microsoft� Windows� Operating System 10.0.14393.0 !$*%SystemRoot
%\System32\NcdAutoSetup.dll
[Svchost DLLs] :HKLM Netlogon=C:\WINDOWS\SYSTEM32\NETLOGON.DLL
### Net Logon Services DLL Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%SystemRoot%\system32\netlogon.dll
[Svchost DLLs] :HKLM NgcCtnrSvc=C:\WINDOWS\SYSTEM32\NGCCTNRSVC.DLL
### Microsoft Passport Container Service Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 !$*%SystemRoot%\System32\NgcCtnrSvc.dll
[Svchost DLLs] :HKLM NgcSvc=C:\WINDOWS\SYSTEM32\NGCSVC.DLL
### Microsoft Passport Service Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SystemRoot%\system32\ngcsvc.dll
[Svchost DLLs] :HKLM NlaSvc=C:\WINDOWS\SYSTEM32\NLASVC.DLL
### Network Location Awareness 2 Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SystemRoot%\System32\nlasvc.dll
[Svchost DLLs] :HKLM nsi=C:\WINDOWS\SYSTEM32\NSISVC.DLL
### Network Store Interface RPC server Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%systemroot%\system32\nsisvc.dll
[Svchost DLLs] :HKLM OneSyncSvc=C:\WINDOWS\SYSTEM32\APHOSTSERVICE.DLL
### Accounts Host Service Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%SystemRoot%\System32\APHostService.dll
[Svchost DLLs] :HKLM p2pimsvc=C:\WINDOWS\SYSTEM32\PNRPSVC.DLL
### PNRP Service Dll Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*%SystemRoot%\system32\pnrpsvc.dll
[Svchost DLLs] :HKLM p2psvc=C:\WINDOWS\SYSTEM32\P2PSVC.DLL
### Peer-to-Peer Services Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%SystemRoot%\system32\p2psvc.dll
[Svchost DLLs] :HKLM PcaSvc=C:\WINDOWS\SYSTEM32\PCASVC.DLL
### Program Compatibility Assistant Service Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 !$*%SystemRoot%\System32\pcasvc.dll
[Svchost DLLs] :HKLM PhoneSvc=C:\WINDOWS\SYSTEM32\PHONESERVICE.DLL
### The service used to manage phone calls and other telephony related
functionality Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*%SystemRoot%\System32\PhoneService.dll
[Svchost DLLs] :HKLM
PimIndexMaintenanceSvc=C:\WINDOWS\SYSTEM32\PIMINDEXMAINTENANCE.DLL
### Service responsible for contacts indexing and other user data related tasks
Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0 !$*
%SystemRoot%\System32\PimIndexMaintenance.dll
[Svchost DLLs] :HKLM PolicyAgent=C:\WINDOWS\SYSTEM32\IPSECSVC.DLL
### Windows IPsec SPD Server DLL Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SystemRoot%\System32\ipsecsvc.dll
[Svchost DLLs] :HKLM Power=C:\WINDOWS\SYSTEM32\UMPO.DLL
### User-mode Power Service Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%SystemRoot%\system32\umpo.dll
[Svchost DLLs] :HKLM
PrintNotify=C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\X64\3\PRINTCONFIG.DLL
### PrintConfig User Interface Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0
[Svchost DLLs] :HKLM ProfSvc=C:\WINDOWS\SYSTEM32\PROFSVC.DLL
### ProfSvc Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*%systemroot%\system32\profsvc.dll
[Svchost DLLs] :HKLM RemoteRegistry=C:\WINDOWS\SYSTEM32\REGSVC.DLL
### Remote Registry Service Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%SystemRoot%\system32\regsvc.dll
[Svchost DLLs] :HKLM RetailDemo=C:\WINDOWS\SYSTEM32\RDXSERVICE.DLL
### RDXService Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*%SystemRoot%\system32\RDXService.dll
[Svchost DLLs] :HKLM RmSvc=C:\WINDOWS\SYSTEM32\RMAPI.DLL
### Radio Manager API Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*%SystemRoot%\System32\RMapi.dll
[Svchost DLLs] :HKLM RpcEptMapper=C:\WINDOWS\SYSTEM32\RPCEPMAP.DLL
### RPC Endpoint Mapper Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%SystemRoot%\System32\RpcEpMap.dll
[Svchost DLLs] :HKLM SDRSVC=C:\WINDOWS\SYSTEM32\SDRSVC.DLL
### Microsoft� Windows Backup Service Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%Systemroot%\System32\SDRSVC.dll
[Svchost DLLs] :HKLM seclogon=C:\WINDOWS\SYSTEM32\SECLOGON.DLL
### Secondary Logon Service DLL Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%windir%\system32\seclogon.dll
[Svchost DLLs] :HKLM SensorService=C:\WINDOWS\SYSTEM32\SENSORSERVICE.DLL
### Sensor Service Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*%SystemRoot%\system32\SensorService.dll
[Svchost DLLs] :HKLM SensrSvc=C:\WINDOWS\SYSTEM32\SENSRSVC.DLL
### Microsoft Windows Sensor Monitoring Service Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 !$*%SystemRoot%\system32\sensrsvc.dll
[Svchost DLLs] :HKLM
shpamsvc=C:\WINDOWS\SYSTEM32\WINDOWS.SHAREDPC.ACCOUNTMANAGER.DLL
### SharedPC.AccountManager Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%systemroot%\system32\Windows.SharedPC.AccountManager.dll
[Svchost DLLs] :HKLM SmsRouter=C:\WINDOWS\SYSTEM32\SMSROUTERSVC.DLL
### Windows SMS Router Service Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SystemRoot%\system32\SmsRouterSvc.dll
[Svchost DLLs] :HKLM SstpSvc=C:\WINDOWS\SYSTEM32\SSTPSVC.DLL
### Provides the facility of using Secure Socket Tunneling Protocol (SSTP) to
connect to remote computers (using VPN). Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SystemRoot%\system32\sstpsvc.dll
[Svchost DLLs] :HKLM StorSvc=C:\WINDOWS\SYSTEM32\STORSVC.DLL
### Storage Services Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*%SystemRoot%\system32\storsvc.dll
[Svchost DLLs] :HKLM svsvc=C:\WINDOWS\SYSTEM32\SVSVC.DLL
### Microsoft\Spot Verifier Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%SystemRoot%\system32\svsvc.dll
[Svchost DLLs] :HKLM swprv=C:\WINDOWS\SYSTEM32\SWPRV.DLL
### Microsoft� Volume Shadow Copy Service software provider Microsoft Corporation
Microsoft� Windows� Operating System 10.0.14393.0 !$*%Systemroot
%\System32\swprv.dll
[Svchost DLLs] :HKLM SysMain=C:\WINDOWS\SYSTEM32\SYSMAIN.DLL
### Superfetch Service Host Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%systemroot%\system32\sysmain.dll
[Svchost DLLs] :HKLM
SystemEventsBroker=C:\WINDOWS\SYSTEM32\SYSTEMEVENTSBROKERSERVER.DLL
### System Events Broker Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%SystemRoot%\System32\SystemEventsBrokerServer.dll
[Svchost DLLs] :HKLM TabletInputService=C:\WINDOWS\SYSTEM32\TABSVC.DLL
### Microsoft Touch Keyboard and Handwriting Panel Service Microsoft Corporation
Microsoft� Windows� Operating System 10.0.14393.0 !$*%SystemRoot
%\System32\TabSvc.dll
[Svchost DLLs] :HKLM Themes=C:\WINDOWS\SYSTEM32\THEMESERVICE.DLL
### Windows Shell Theme Service Dll Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SystemRoot%\system32\themeservice.dll
[Svchost DLLs] :HKLM TimeBrokerSvc=C:\WINDOWS\SYSTEM32\TIMEBROKERSERVER.DLL
### Time Event Broker Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*%SystemRoot%\System32\TimeBrokerServer.dll
[Svchost DLLs] :HKLM TrkWks=C:\WINDOWS\SYSTEM32\TRKWKS.DLL
### Distributed Link Tracking Client Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SystemRoot%\System32\trkwks.dll
[Svchost DLLs] :HKLM tzautoupdate=C:\WINDOWS\SYSTEM32\TZAUTOUPDATE.DLL
### Auto Time Zone Updater Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%SystemRoot%\system32\tzautoupdate.dll
[Svchost DLLs] :HKLM UmRdpService=C:\WINDOWS\SYSTEM32\UMRDP.DLL
### Remote Desktop Services Device Redirector Service Microsoft Corporation
Microsoft� Windows� Operating System 10.0.14393.0 !$*%SystemRoot
%\System32\umrdp.dll
[Svchost DLLs] :HKLM UnistoreSvc=C:\WINDOWS\SYSTEM32\UNISTORE.DLL
### Unified Store Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*%SystemRoot%\System32\unistore.dll
[Svchost DLLs] :HKLM UserDataSvc=C:\WINDOWS\SYSTEM32\USERDATASERVICE.DLL
### The endpoint for 3rd party APIs to read/write user data Microsoft Corporation
Microsoft� Windows� Operating System 10.0.14393.0 !$*%SystemRoot
%\System32\userdataservice.dll
[Svchost DLLs] :HKLM UsoSvc=C:\WINDOWS\SYSTEM32\USOCORE.DLL
### Update Session Orchestrator Core Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%systemroot%\system32\usocore.dll
[Svchost DLLs] :HKLM VaultSvc=C:\WINDOWS\SYSTEM32\VAULTSVC.DLL
### Credential Manager Service Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0
[Svchost DLLs] :HKLM vmicguestinterface=C:\WINDOWS\SYSTEM32\ICSVC.DLL
### Virtual Machine Integration Component Service Microsoft Corporation
Microsoft� Windows� Operating System 10.0.14393.0 !$*%SystemRoot
%\System32\icsvc.dll
[Svchost DLLs] :HKLM vmicheartbeat=C:\WINDOWS\SYSTEM32\ICSVC.DLL
### Virtual Machine Integration Component Service Microsoft Corporation
Microsoft� Windows� Operating System 10.0.14393.0 !$*%SystemRoot
%\System32\icsvc.dll
[Svchost DLLs] :HKLM vmickvpexchange=C:\WINDOWS\SYSTEM32\ICSVC.DLL
### Virtual Machine Integration Component Service Microsoft Corporation
Microsoft� Windows� Operating System 10.0.14393.0 !$*%SystemRoot
%\System32\icsvc.dll
[Svchost DLLs] :HKLM vmicrdv=C:\WINDOWS\SYSTEM32\ICSVCEXT.DLL
### Virtual Machine Integration Component Service Microsoft Corporation
Microsoft� Windows� Operating System 10.0.14393.0 !$*%SystemRoot
%\System32\icsvcext.dll
[Svchost DLLs] :HKLM vmicshutdown=C:\WINDOWS\SYSTEM32\ICSVC.DLL
### Virtual Machine Integration Component Service Microsoft Corporation
Microsoft� Windows� Operating System 10.0.14393.0 !$*%SystemRoot
%\System32\icsvc.dll
[Svchost DLLs] :HKLM vmictimesync=C:\WINDOWS\SYSTEM32\ICSVC.DLL
### Virtual Machine Integration Component Service Microsoft Corporation
Microsoft� Windows� Operating System 10.0.14393.0 !$*%SystemRoot
%\System32\icsvc.dll
[Svchost DLLs] :HKLM vmicvmsession=C:\WINDOWS\SYSTEM32\ICSVC.DLL
### Virtual Machine Integration Component Service Microsoft Corporation
Microsoft� Windows� Operating System 10.0.14393.0 !$*%SystemRoot
%\System32\icsvc.dll
[Svchost DLLs] :HKLM vmicvss=C:\WINDOWS\SYSTEM32\ICSVCEXT.DLL
### Virtual Machine Integration Component Service Microsoft Corporation
Microsoft� Windows� Operating System 10.0.14393.0 !$*%SystemRoot
%\System32\icsvcext.dll
[Svchost DLLs] :HKLM W32Time=C:\WINDOWS\SYSTEM32\W32TIME.DLL
### Windows Time Service Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%systemroot%\system32\w32time.dll
[Svchost DLLs] :HKLM WalletService=C:\WINDOWS\SYSTEM32\WALLETSERVICE.DLL
### Wallet Service Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*%SystemRoot%\system32\WalletService.dll
[Svchost DLLs] :HKLM WbioSrvc=C:\WINDOWS\SYSTEM32\WBIOSRVC.DLL
### Windows Biometric Service Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%SystemRoot%\System32\wbiosrvc.dll
[Svchost DLLs] :HKLM Wcmsvc=C:\WINDOWS\SYSTEM32\WCMSVC.DLL
### Windows Connection Manager Service DLL Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 !$*%SystemRoot%\System32\wcmsvc.dll
[Svchost DLLs] :HKLM WdiServiceHost=C:\WINDOWS\SYSTEM32\WDI.DLL
### Windows Diagnostic Infrastructure Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SystemRoot%\system32\wdi.dll
[Svchost DLLs] :HKLM WdiSystemHost=C:\WINDOWS\SYSTEM32\WDI.DLL
### Windows Diagnostic Infrastructure Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SystemRoot%\system32\wdi.dll
[Svchost DLLs] :HKLM WEPHOSTSVC=C:\WINDOWS\SYSTEM32\WEPHOSTSVC.DLL
### WEP Host Service Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*%systemroot%\system32\wephostsvc.dll
[Svchost DLLs] :HKLM wercplsupport=C:\WINDOWS\SYSTEM32\WERCPLSUPPORT.DLL
### Problem Reports and Solutions Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SystemRoot%\System32\wercplsupport.dll
[Svchost DLLs] :HKLM WerSvc=C:\WINDOWS\SYSTEM32\WERSVC.DLL
### Windows Error Reporting Service Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SystemRoot%\System32\WerSvc.dll
[Svchost DLLs] :HKLM wisvc=C:\WINDOWS\SYSTEM32\FLIGHTSETTINGS.DLL
### Flight Settings Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*%systemroot%\system32\flightsettings.dll
[Svchost DLLs] :HKLM wlidsvc=C:\WINDOWS\SYSTEM32\WLIDSVC.DLL
### Microsoft� Account Service Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SystemRoot%\system32\wlidsvc.dll
[Svchost DLLs] :HKLM workfolderssvc=C:\WINDOWS\SYSTEM32\WORKFOLDERSSVC.DLL
### Microsoft (C) Work Folders Service Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%systemroot%\system32\workfolderssvc.dll
[Svchost DLLs] :HKLM WpnUserService=C:\WINDOWS\SYSTEM32\WPNUSERSERVICE.DLL
### Windows Push Notification User Service Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 !$*%SystemRoot%\System32\WpnUserService.dll
[Svchost DLLs] :HKLM wudfsvc=C:\WINDOWS\SYSTEM32\WUDFSVC.DLL
### Windows Driver Foundation - User-mode Driver Framework Service Microsoft
Corporation Microsoft� Windows� Operating System 10.0.14393.0 !$*%SystemRoot
%\System32\WUDFSvc.dll
[Svchost DLLs] :HKLM WwanSvc=C:\WINDOWS\SYSTEM32\WWANSVC.DLL
### WWAN Auto Config Service Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%SystemRoot%\System32\wwansvc.dll
[Svchost DLLs] :HKLM XblAuthManager=C:\WINDOWS\SYSTEM32\XBLAUTHMANAGER.DLL
### Xbox Live Auth Manager Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.103 !$*%SystemRoot%\System32\XblAuthManager.dll
[Svchost DLLs] :HKLM XblGameSave=C:\WINDOWS\SYSTEM32\XBLGAMESAVE.DLL
### Xbox Live Game Save Service Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SystemRoot%\System32\XblGameSave.dll
[Svchost DLLs] :HKLM XboxNetApiSvc=C:\WINDOWS\SYSTEM32\XBOXNETAPISVC.DLL
### Xbox Live Networking Service Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SystemRoot%\system32\XboxNetApiSvc.dll
[Bootexecute] :HKLM BootExecute=autocheck autochk *

[Winlogon System] :HKLM system=""


### File is missing.
[Winlogon System] :HKLM taskman=""
### File is missing.
[Winlogon System] :HKLM UIHost=""
### File is missing.
[Winlogon Autostart] :HKLM VmApplet=""
[Winlogon Autostart] :HKLM AppSetup=""
[KnownDLLs] :HKLM _Wow64=Wow64.dll
[KnownDLLs] :HKLM _Wow64cpu=Wow64cpu.dll
[KnownDLLs] :HKLM _Wow64win=Wow64win.dll
[KnownDLLs] :HKLM advapi32=advapi32.dll
[KnownDLLs] :HKLM clbcatq=clbcatq.dll
[KnownDLLs] :HKLM combase=combase.dll
[KnownDLLs] :HKLM COMDLG32=COMDLG32.dll
[KnownDLLs] :HKLM coml2=coml2.dll
[KnownDLLs] :HKLM DifxApi=difxapi.dll
[KnownDLLs] :HKLM gdi32=gdi32.dll
[KnownDLLs] :HKLM gdiplus=gdiplus.dll
[KnownDLLs] :HKLM IMAGEHLP=IMAGEHLP.dll
[KnownDLLs] :HKLM IMM32=IMM32.dll
[KnownDLLs] :HKLM kernel32=kernel32.dll
[KnownDLLs] :HKLM LPK=LPK.dll
[KnownDLLs] :HKLM MSCTF=MSCTF.dll
[KnownDLLs] :HKLM MSVCRT=MSVCRT.dll
[KnownDLLs] :HKLM NORMALIZ=NORMALIZ.dll
[KnownDLLs] :HKLM NSI=NSI.dll
[KnownDLLs] :HKLM ole32=ole32.dll
[KnownDLLs] :HKLM OLEAUT32=OLEAUT32.dll
[KnownDLLs] :HKLM PSAPI=PSAPI.DLL
[KnownDLLs] :HKLM rpcrt4=rpcrt4.dll
[KnownDLLs] :HKLM sechost=sechost.dll
[KnownDLLs] :HKLM Setupapi=Setupapi.dll
[KnownDLLs] :HKLM SHELL32=SHELL32.dll
[KnownDLLs] :HKLM SHLWAPI=SHLWAPI.dll
[KnownDLLs] :HKLM user32=user32.dll
[KnownDLLs] :HKLM WLDAP32=WLDAP32.dll
[KnownDLLs] :HKLM WS2_32=WS2_32.dll
[Environment - Path] :HKLM Path=%SystemRoot%\system32;%SystemRoot%;%SystemRoot
%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\
[List of Injected DLLs] :HKLM AppInit_DLLs=""
[LSA Notification Packages] :HKLM scecli=C:\WINDOWS\SYSTEM32\SCECLI.DLL
### scecli Windows Security Configuration Editor Client Engine Microsoft
Corporation Microsoft� Windows� Operating System 10.0.14393.0 !$*scecli.dll
[Print Providers] :HKLM Internet Print Provider=C:\WINDOWS\SYSTEM32\INETPP.DLL
### Display Name: HTTP Print Services * Internet Print Provider DLL Microsoft
Corporation Microsoft� Windows� Operating System 10.0.14393.0 !$*inetpp.dll
[Print Providers] :HKLM LanMan Print Services=C:\WINDOWS\SYSTEM32\WIN32SPL.DLL
### Display Name: LanMan Print Services * Client Side Rendering Print Provider
Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0 !
$*win32spl.dll
[Eventlog Application DLL] :HKLM .NET Runtime=C:\WINDOWS\SYSTEM32\MSCOREE.DLL
### Microsoft .NET Runtime Execution Engine Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0
[Eventlog Application DLL] :HKLM .NET Runtime Optimization
Service=C:\WINDOWS\SYSTEM32\MSCOREE.DLL
### Microsoft .NET Runtime Execution Engine Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0
[Eventlog Application DLL] :HKLM Application Error=C:\WINDOWS\SYSTEM32\WER.DLL
### Windows Error Reporting DLL Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SystemRoot%\System32\wer.dll
[Eventlog Application DLL] :HKLM Application Hang=C:\WINDOWS\SYSTEM32\WERSVC.DLL
### Windows Error Reporting Service Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SystemRoot%\System32\wersvc.dll
[Eventlog Application DLL] :HKLM Application
Management=C:\WINDOWS\SYSTEM32\APPMGMTS.DLL
### Software installation Service Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SystemRoot%\System32\appmgmts.dll
[Eventlog Application DLL] :HKLM Application-Addon-Event-
Provider=C:\WINDOWS\SYSTEM32\IEFRAME.DLL
### Internet Browser Microsoft Corporation Internet Explorer 11.00.14393.1715 !$*
%SystemRoot%\system32\ieframe.dll
[Eventlog Application DLL] :HKLM ASP.NET
2.0.50727.0=C:\Windows\Microsoft.NET\Framework64\v2.0.50727\aspnet_rc.dll
### File is missing.
[Eventlog Application DLL] :HKLM Bonjour Service=C:\Program
Files\Bonjour\mDNSResponder.exe
### File is missing.
[Eventlog Application DLL] :HKLM Business Connectivity Services(Legacy
Provider)=C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V4.0.30319\EVENTLOGMESSAGES.DLL
### EventLogMessages.dll Microsoft Corporation Microsoft� .NET Framework
4.7.2053.0 !$*%windir%\Microsoft.NET\Framework\v4.0.30319\EventLogMessages.dll
[Eventlog Application DLL] :HKLM CardSpace
4.0.0.0=C:\WINDOWS\MICROSOFT.NET\FRAMEWORK64\V4.0.30319\SERVICEMODELEVENTS.DLL
### ServiceModel related event descriptions Microsoft Corporation Microsoft� .NET
Framework 4.7.2053.0
[Eventlog Application DLL] :HKLM CardSpace
4.0.0.0=C:\Windows\System32\icardres.dll
### File is missing.
[Eventlog Application DLL] :HKLM Chkdsk=C:\WINDOWS\SYSTEM32\ULIB.DLL
### File Utilities Support DLL Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.1532 !$*%SystemRoot%\System32\ulib.dll
[Eventlog Application DLL] :HKLM Desktop Window
Manager=C:\WINDOWS\SYSTEM32\DWM.EXE
### Desktop Window Manager Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%SystemRoot%\system32\dwm.exe
[Eventlog Application DLL] :HKLM DiskQuota=C:\WINDOWS\SYSTEM32\DSKQUOTA.DLL
### Windows Shell Disk Quota Support DLL Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 !$*%SystemRoot%\System32\dskquota.dll
[Eventlog Application DLL] :HKLM
DptfEvent=C:\WINDOWS\SYSTEM32\DPTFEVENTLOGMESSAGE.DLL
### Intel(R) Dynamic Platform and Thermal Framework Event Log Message DLL Intel
Corporation Intel(R) Dynamic Platform and Thermal Framework 7.1.0.2106
[Eventlog Application DLL] :HKLM Dwminit=C:\WINDOWS\SYSTEM32\DWMINIT.DLL
### DWMInit Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*%SystemRoot%\system32\dwminit.dll
[Eventlog Application DLL] :HKLM Error Instrument=C:\WINDOWS\SYSTEM32\USER32.DLL
### Multi-User Windows USER API Client DLL Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 !$*%SystemRoot%\system32\user32.dll
[Eventlog Application DLL] :HKLM ESENT=C:\WINDOWS\SYSTEM32\ESENT.DLL
### Extensible Storage Engine for Microsoft(R) Windows(R) Microsoft Corporation
Microsoft� Windows� Operating System 10.0.14393.0 !$*%systemroot
%\system32\esent.dll
[Eventlog Application DLL] :HKLM Folder
Redirection=C:\WINDOWS\SYSTEM32\FDEPLOY.DLL
### Folder Redirection Group Policy Extension Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 !$*%SystemRoot%\System32\fdeploy.dll
[Eventlog Application DLL] :HKLM Group Policy
Applications=C:\WINDOWS\SYSTEM32\GPPREFCL.DLL
### Group Policy Preference Client Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0
[Eventlog Application DLL] :HKLM Group Policy
Client=C:\WINDOWS\SYSTEM32\GPPREFCL.DLL
### Group Policy Preference Client Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0
[Eventlog Application DLL] :HKLM Group Policy Data
Sources=C:\WINDOWS\SYSTEM32\GPPREFCL.DLL
### Group Policy Preference Client Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0
[Eventlog Application DLL] :HKLM Group Policy Device
Settings=C:\WINDOWS\SYSTEM32\GPPREFCL.DLL
### Group Policy Preference Client Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0
[Eventlog Application DLL] :HKLM Group Policy Drive
Maps=C:\WINDOWS\SYSTEM32\GPPREFCL.DLL
### Group Policy Preference Client Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0
[Eventlog Application DLL] :HKLM Group Policy
Environment=C:\WINDOWS\SYSTEM32\GPPREFCL.DLL
### Group Policy Preference Client Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0
[Eventlog Application DLL] :HKLM Group Policy
Files=C:\WINDOWS\SYSTEM32\GPPREFCL.DLL
### Group Policy Preference Client Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0
[Eventlog Application DLL] :HKLM Group Policy Folder
Options=C:\WINDOWS\SYSTEM32\GPPREFCL.DLL
### Group Policy Preference Client Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0
[Eventlog Application DLL] :HKLM Group Policy
Folders=C:\WINDOWS\SYSTEM32\GPPREFCL.DLL
### Group Policy Preference Client Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0
[Eventlog Application DLL] :HKLM Group Policy Ini
Files=C:\WINDOWS\SYSTEM32\GPPREFCL.DLL
### Group Policy Preference Client Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0
[Eventlog Application DLL] :HKLM Group Policy Internet
Settings=C:\WINDOWS\SYSTEM32\GPPREFCL.DLL
### Group Policy Preference Client Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0
[Eventlog Application DLL] :HKLM Group Policy Local Users and
Groups=C:\WINDOWS\SYSTEM32\GPPREFCL.DLL
### Group Policy Preference Client Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0
[Eventlog Application DLL] :HKLM Group Policy Mail
Profiles=C:\WINDOWS\SYSTEM32\GPPREFCL.DLL
### Group Policy Preference Client Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0
[Eventlog Application DLL] :HKLM Group Policy Network
Options=C:\WINDOWS\SYSTEM32\GPPREFCL.DLL
### Group Policy Preference Client Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0
[Eventlog Application DLL] :HKLM Group Policy Network
Shares=C:\WINDOWS\SYSTEM32\GPPREFCL.DLL
### Group Policy Preference Client Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0
[Eventlog Application DLL] :HKLM Group Policy Power
Options=C:\WINDOWS\SYSTEM32\GPPREFCL.DLL
### Group Policy Preference Client Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0
[Eventlog Application DLL] :HKLM Group Policy
Printers=C:\WINDOWS\SYSTEM32\GPPREFCL.DLL
### Group Policy Preference Client Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0
[Eventlog Application DLL] :HKLM Group Policy Regional
Options=C:\WINDOWS\SYSTEM32\GPPREFCL.DLL
### Group Policy Preference Client Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0
[Eventlog Application DLL] :HKLM Group Policy
Registry=C:\WINDOWS\SYSTEM32\GPPREFCL.DLL
### Group Policy Preference Client Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0
[Eventlog Application DLL] :HKLM Group Policy Scheduled
Tasks=C:\WINDOWS\SYSTEM32\GPPREFCL.DLL
### Group Policy Preference Client Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0
[Eventlog Application DLL] :HKLM Group Policy
Services=C:\WINDOWS\SYSTEM32\GPPREFCL.DLL
### Group Policy Preference Client Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0
[Eventlog Application DLL] :HKLM Group Policy
Shortcuts=C:\WINDOWS\SYSTEM32\GPPREFCL.DLL
### Group Policy Preference Client Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0
[Eventlog Application DLL] :HKLM Group Policy Standard
Edition=C:\WINDOWS\SYSTEM32\GPPREFCL.DLL
### Group Policy Preference Client Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0
[Eventlog Application DLL] :HKLM Group Policy Start Menu
Settings=C:\WINDOWS\SYSTEM32\GPPREFCL.DLL
### Group Policy Preference Client Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0
[Eventlog Application DLL] :HKLM GroupPolicy=C:\WINDOWS\SYSTEM32\GPAPI.DLL
### Group Policy Client API Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%SystemRoot%\System32\gpapi.dll
[Eventlog Application DLL] :HKLM Handwriting Recognition=%CommonProgramFiles
%\Microsoft Shared\Ink\IPSEventLogMsg.dll
### !$*%CommonProgramFiles%\Microsoft Shared\Ink\IPSEventLogMsg.dll File is
missing.
[Eventlog Application DLL] :HKLM Interactive Services
detection=C:\WINDOWS\SYSTEM32\UI0DETECT.EXE
### Interactive services detection Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SystemRoot%\System32\UI0Detect.exe
[Eventlog Application DLL] :HKLM ipmiprv=C:\WINDOWS\SYSTEM32\WBEM\IPMIPRR.DLL
### IPMI Provider Resource Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%windir%\system32\wbem\ipmiprr.dll
[Eventlog Application DLL] :HKLM Microsoft Fax=C:\WINDOWS\SYSTEM32\FXSEVENT.DLL
### Microsoft Fax EventLog Support DLL Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0
[Eventlog Application DLL] :HKLM Microsoft Office
15=C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE15\MSORES.DLL
### Microsoft Office 2013 component Microsoft Corporation Microsoft Office 2013
15.0.4420.1017
[Eventlog Application DLL] :HKLM Microsoft Office
15=C:\PROGRA~2\COMMON~1\MICROS~1\DW\DW20.EXE
### Microsoft Application Error Reporting Microsoft Corporation Microsoft
Application Error Reporting 15.0.4420.1017
[Eventlog Application DLL] :HKLM Microsoft-Office-Business Connectivity
Services=C:\PROGRAM FILES (X86)\MICROSOFT OFFICE\OFFICE15\BCSCLIENT.MSG.DLL
[Eventlog Application DLL] :HKLM Microsoft-Windows-
ApplicationExperienceInfrastructure=C:\WINDOWS\SYSTEM32\APPHELP.DLL
### Application Compatibility Client Library Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 !$*%SystemRoot%\system32\apphelp.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-AppModel-
Runtime=C:\WINDOWS\SYSTEM32\MICROSOFT-WINDOWS-SYSTEM-EVENTS.DLL
### Microsoft-Windows-System-Events Resources Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.447 !$*%SystemRoot%\system32\Microsoft-
Windows-System-Events.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-AppModel-
State=C:\WINDOWS\SYSTEM32\MICROSOFT-WINDOWS-SYSTEM-EVENTS.DLL
### Microsoft-Windows-System-Events Resources Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.447 !$*%SystemRoot%\system32\Microsoft-
Windows-System-Events.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-
Audio=C:\WINDOWS\SYSTEM32\AUDIOSES.DLL
### Audio Session Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*%SystemRoot%\System32\audioses.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-Audit-
CVE=C:\WINDOWS\SYSTEM32\MICROSOFT-WINDOWS-SYSTEM-EVENTS.DLL
### Microsoft-Windows-System-Events Resources Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.447 !$*%SystemRoot%\system32\Microsoft-
Windows-System-Events.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-
AxInstallService=C:\WINDOWS\SYSTEM32\AXINSTSV.DLL
### ActiveX Installer Service Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%SystemRoot%\System32\AxInstSv.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-
Backup=C:\WINDOWS\SYSTEM32\BLBEVENTS.DLL
### Blb Publisher Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*%windir%\system32\BlbEvents.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-
CAPI2=C:\WINDOWS\SYSTEM32\CRYPT32.DLL
### Crypto API32 Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*%SystemRoot%\System32\crypt32.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-
CertificateServicesClient=C:\WINDOWS\SYSTEM32\DIMSJOB.DLL
### DIMS Job DLL Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*%SystemRoot%\system32\dimsjob.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-CertificateServicesClient-
AutoEnrollment=C:\WINDOWS\SYSTEM32\PAUTOENR.DLL
### Auto Enrollment DLL Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%SystemRoot%\system32\pautoenr.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-CertificateServicesClient-
CertEnroll=C:\WINDOWS\SYSTEM32\CERTENROLL.DLL
### Microsoft� Active Directory Certificate Services Enrollment Client Microsoft
Corporation Microsoft� Windows� Operating System 10.0.14393.0 !$*%SystemRoot
%\system32\certenroll.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-CertificateServicesClient-
CredentialRoaming=C:\WINDOWS\SYSTEM32\DIMSROAM.DLL
### Key Roaming DIMS Provider DLL Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SystemRoot%\system32\dimsroam.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-CertificationAuthorityClient-
CertCli=C:\WINDOWS\SYSTEM32\CERTCLI.DLL
### Microsoft� Active Directory Certificate Services Client Microsoft Corporation
Microsoft� Windows� Operating System 10.0.14393.0 !$*%SystemRoot
%\system32\certcli.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-
COMRuntime=C:\WINDOWS\SYSTEM32\COMBASE.DLL
### Microsoft COM for Windows Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.1198 !$*%systemroot%\system32\combase.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-
Deduplication=C:\WINDOWS\SYSTEM32\DDPUTILS.DLL
### Microsoft Data Deduplication Common Library Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 !$*%SystemRoot%\System32\ddputils.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-
Defrag=C:\WINDOWS\SYSTEM32\DEFRAGSVC.DLL
### Microsoft\Drive Optimizer Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%systemroot%\system32\defragsvc.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-DirectShow-
Core=C:\WINDOWS\SYSTEM32\QUARTZ.DLL
### DirectShow Runtime. Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%SystemRoot%\system32\quartz.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-DirectShow-
KernelSupport=C:\WINDOWS\SYSTEM32\KSPROXY.AX
### WDM Streaming ActiveMovie Proxy Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SystemRoot%\System32\ksproxy.ax
[Eventlog Application DLL] :HKLM Microsoft-Windows-
EapHost=C:\WINDOWS\SYSTEM32\EAPSVC.DLL
### Microsoft EAPHost service Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%systemroot%\system32\eapsvc.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-
EFS=C:\WINDOWS\SYSTEM32\EFSCORE.DLL
### EFS Core Library Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*%SystemRoot%\system32\efscore.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-
EventCollector=C:\WINDOWS\SYSTEM32\WECSVC.DLL
### Event Collector Service Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%SystemRoot%\system32\wecsvc.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-Folder
Redirection=C:\WINDOWS\SYSTEM32\FDEPLOY.DLL
### Folder Redirection Group Policy Extension Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 !$*%SystemRoot%\System32\fdeploy.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-Immersive-
Shell=C:\WINDOWS\SYSTEM32\TWINUI.APPCORE.DLL
### TWINUI.APPCORE Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*%SystemRoot%\system32\twinui.appcore.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-
LoadPerf=C:\WINDOWS\SYSTEM32\LOADPERF.DLL
### Load & Unload Performance Counters Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SystemRoot%\system32\loadperf.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-
PerfCtrs=C:\WINDOWS\SYSTEM32\PERFCTRS.DLL
### Performance Counters Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%SystemRoot%\system32\perfctrs.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-
PerfNet=C:\WINDOWS\SYSTEM32\PERFNET.DLL
### Windows Network Service Performance Objects DLL Microsoft Corporation
Microsoft� Windows� Operating System 10.0.14393.0 !$*%SystemRoot
%\system32\perfnet.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-
PerfOS=C:\WINDOWS\SYSTEM32\PERFOS.DLL
### Windows System Performance Objects DLL Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 !$*%SystemRoot%\system32\perfos.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-
PerfProc=C:\WINDOWS\SYSTEM32\PERFPROC.DLL
### Windows System Process Performance Objects DLL Microsoft Corporation
Microsoft� Windows� Operating System 10.0.14393.0 !$*%SystemRoot
%\system32\perfproc.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-
propsys=C:\WINDOWS\SYSTEM32\PROPSYS.DLL
### Microsoft Property System Microsoft Corporation Windows� Search 7.0.14393.0 !
$*%SystemRoot%\system32\propsys.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-RemoteApp and Desktop
Connections=C:\WINDOWS\SYSTEM32\TSWORKSPACE.DLL
### RemoteApp and Desktop Connection Component Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 !$*%SystemRoot%\system32\TSWorkspace.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-
RemoteAssistance=C:\WINDOWS\SYSTEM32\MSRA.EXE
### Windows Remote Assistance Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%systemroot%\system32\msra.exe
[Eventlog Application DLL] :HKLM Microsoft-Windows-
RestartManager=C:\WINDOWS\SYSTEM32\RSTRTMGR.DLL
### Restart Manager Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*%SystemRoot%\System32\RstrtMgr.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-RPC-
Events=C:\WINDOWS\SYSTEM32\RPCRT4.DLL
### Remote Procedure Call Runtime Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SystemRoot%\system32\rpcrt4.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-Security-EnterpriseData-
FileRevocationManager=C:\WINDOWS\SYSTEM32\EFSWRT.DLL
### Storage Protection Windows Runtime DLL Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 !$*%SystemRoot%\system32\efswrt.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-
SoftwareRestrictionPolicies=C:\WINDOWS\SYSTEM32\MICROSOFT-WINDOWS-SYSTEM-EVENTS.DLL
### Microsoft-Windows-System-Events Resources Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.447 !$*%SystemRoot%\system32\Microsoft-
Windows-System-Events.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-Spell-
Checking=C:\WINDOWS\SYSTEM32\MSSPELLCHECKINGFACILITY.DLL
### Microsoft Spell Checking Facility Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%systemroot%\System32\MsSpellCheckingFacility.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-
SpellChecker=C:\WINDOWS\SYSTEM32\MSSPELLCHECKINGFACILITY.DLL
### Microsoft Spell Checking Facility Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%systemroot%\System32\MsSpellCheckingFacility.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-Spellchecking-
Host=C:\WINDOWS\SYSTEM32\MSSPELLCHECKINGHOST.EXE
### Microsoft Spell Checking Host Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%systemroot%\System32\MsSpellCheckingHost.exe
[Eventlog Application DLL] :HKLM Microsoft-Windows-System-
Restore=C:\WINDOWS\SYSTEM32\SREVENTS.DLL
### SrEvents Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*%windir%\system32\SrEvents.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-TerminalServices-
ClientActiveXCore=C:\WINDOWS\SYSTEM32\MSTSCAX.DLL
### Remote Desktop Services ActiveX Client Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 !$*%SystemRoot%\system32\mstscax.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-User Profiles
General=C:\WINDOWS\SYSTEM32\USERENV.DLL
### Userenv Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*%SystemRoot%\System32\userenv.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-User Profiles
Service=C:\WINDOWS\SYSTEM32\PROFSVC.DLL
### ProfSvc Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*%SystemRoot%\System32\profsvc.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-User-
Loader=C:\WINDOWS\SYSTEM32\MICROSOFT-WINDOWS-SYSTEM-EVENTS.DLL
### Microsoft-Windows-System-Events Resources Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.447 !$*%SystemRoot%\system32\Microsoft-
Windows-System-Events.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-Video-For-
Windows=C:\WINDOWS\SYSTEM32\MCIAVI32.DLL
### Video For Windows MCI driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SystemRoot%\system32\mciavi32.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-
WindowsSystemAssessmentTool=C:\WINDOWS\SYSTEM32\WINSAT.EXE
### Windows System Assessment Tool Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SystemRoot%\system32\WINSAT.EXE
[Eventlog Application DLL] :HKLM Microsoft-Windows-
Winsrv=C:\WINDOWS\SYSTEM32\WINSRV.DLL
### Multi-User Windows Server DLL Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SystemRoot%\system32\winsrv.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-
WMI=C:\WINDOWS\SYSTEM32\WBEM\WINMGMTR.DLL
### WMI Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0 !
$*%SystemRoot%\system32\wbem\WinMgmtR.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-
XWizards=C:\WINDOWS\SYSTEM32\XWIZARDS.DLL
### Extensible Wizards Manager Module Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%windir%\system32\xwizards.dll
[Eventlog Application DLL] :HKLM Microsoft.Transactions.Bridge
3.0.0.0=C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication
Foundation\ServiceModelEvents.dll
### File is missing.
[Eventlog Application DLL] :HKLM Microsoft.Transactions.Bridge
4.0.0.0=C:\WINDOWS\MICROSOFT.NET\FRAMEWORK64\V4.0.30319\SERVICEMODELEVENTS.DLL
### ServiceModel related event descriptions Microsoft Corporation Microsoft� .NET
Framework 4.7.2053.0
[Eventlog Application DLL] :HKLM MsiInstaller=C:\WINDOWS\SYSTEM32\MSIMSG.DLL
### Windows� Installer International Messages Microsoft Corporation Windows
Installer - Unicode 5.0.14393.0
[Eventlog Application DLL] :HKLM MSSOAP=C:\PROGRAM FILES (X86)\COMMON
FILES\MICROSOFT SHARED\OFFICE15\MSSOAP30.DLL
### Microsoft Office Soap SDK Microsoft Corporation Microsoft Office Soap SDK
15.0.4420.1017
[Eventlog Application DLL] :HKLM NVIDIA Update Service=C:\PROGRAM FILES
(X86)\NVIDIA CORPORATION\UPDATE CORE\NVBACKEND.EXE
### NVIDIA Update Backend NVIDIA Corporation NVIDIA Update 10.4.0.6
[Eventlog Application DLL] :HKLM
Outlook=C:\PROGRA~2\MICROS~1\OFFICE15\1033\MAPIR.DLL
### ExOlk Intl Pluggable UI Microsoft Corporation Microsoft Outlook
15.0.4420.1017
[Eventlog Application DLL] :HKLM Profsvc=C:\WINDOWS\SYSTEM32\PROFSVC.DLL
### ProfSvc Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*%SystemRoot%\System32\profsvc.dll
[Eventlog Application DLL] :HKLM RasClient=C:\WINDOWS\SYSTEM32\MPRMSG.DLL
### Multi-Protocol Router Service Messages DLL Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 !$*%SystemRoot%\System32\mprmsg.dll
[Eventlog Application DLL] :HKLM SceCli=C:\WINDOWS\SYSTEM32\SCECLI.DLL
### Windows Security Configuration Editor Client Engine Microsoft Corporation
Microsoft� Windows� Operating System 10.0.14393.0 !$*%SystemRoot
%\System32\scecli.dll
[Eventlog Application DLL] :HKLM SceSrv=C:\WINDOWS\SYSTEM32\SCESRV.DLL
### Windows Security Configuration Editor Engine Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 !$*%SystemRoot%\System32\scesrv.dll
[Eventlog Application DLL] :HKLM SecurityCenter=C:\WINDOWS\SYSTEM32\WSCSVC.DLL
### Windows Security Center Service Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SystemRoot%\System32\wscsvc.dll
[Eventlog Application DLL] :HKLM
Service1=C:\WINDOWS\MICROSOFT.NET\FRAMEWORK64\V4.0.30319\EVENTLOGMESSAGES.DLL
### EventLogMessages.dll Microsoft Corporation Microsoft� .NET Framework
4.7.2053.0
[Eventlog Application DLL] :HKLM ServiceModel Audit
3.0.0.0=C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication
Foundation\ServiceModelEvents.dll
### File is missing.
[Eventlog Application DLL] :HKLM ServiceModel Audit
4.0.0.0=C:\WINDOWS\MICROSOFT.NET\FRAMEWORK64\V4.0.30319\SERVICEMODELEVENTS.DLL
### ServiceModel related event descriptions Microsoft Corporation Microsoft� .NET
Framework 4.7.2053.0
[Eventlog Application DLL] :HKLM SideBySide=C:\WINDOWS\SYSTEM32\SXS.DLL
### Fusion 2.5 Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*%SystemRoot%\System32\sxs.dll
[Eventlog Application DLL] :HKLM Software
Installation=C:\WINDOWS\SYSTEM32\APPMGR.DLL
### Software Installation Snapin Extenstion Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 !$*%SystemRoot%\System32\appmgr.dll
[Eventlog Application DLL] :HKLM Software Protection Platform
Service=C:\WINDOWS\SYSTEM32\SPPSVC.EXE
### Microsoft Software Protection Platform Service Microsoft Corporation
Microsoft� Windows� Operating System 10.0.14393.0 !$*%SystemRoot
%\system32\sppsvc.exe
[Eventlog Application DLL] :HKLM
SpeechRuntime=C:\WINDOWS\SYSTEM32\SPEECH_ONECORE\COMMON\SAPI_ONECORE.DLL
### Speech API Microsoft Corporation Microsoft� Speech Recognizer 11.1
5.3.14393.1770
[Eventlog Application DLL] :HKLM SPP=C:\WINDOWS\SYSTEM32\SXPROXY.DLL
### Microsoft� Windows System Protection Proxy Library Microsoft Corporation
Microsoft� Windows� Operating System 10.0.14393.0 !$*%systemroot
%\system32\sxproxy.dll
[Eventlog Application DLL] :HKLM SrmSvc=C:\WINDOWS\SYSTEM32\SRM.DLL
### Microsoft� File Server Resource Manager Common Library Microsoft Corporation
Microsoft� Windows� Operating System 10.0.14393.0 !$*%SystemRoot%\System32\srm.dll
[Eventlog Application DLL] :HKLM System Restore=C:\WINDOWS\SYSTEM32\SRCORE.DLL
### Microsoft� Windows System Restore Core Library Microsoft Corporation
Microsoft� Windows� Operating System 10.0.14393.0 !$*%systemroot
%\system32\srcore.dll
[Eventlog Application DLL] :HKLM System.IdentityModel
3.0.0.0=C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication
Foundation\ServiceModelEvents.dll
### File is missing.
[Eventlog Application DLL] :HKLM System.IdentityModel
4.0.0.0=C:\WINDOWS\MICROSOFT.NET\FRAMEWORK64\V4.0.30319\SERVICEMODELEVENTS.DLL
### ServiceModel related event descriptions Microsoft Corporation Microsoft� .NET
Framework 4.7.2053.0
[Eventlog Application DLL] :HKLM System.IO.Log
3.0.0.0=C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication
Foundation\ServiceModelEvents.dll
### File is missing.
[Eventlog Application DLL] :HKLM System.IO.Log
4.0.0.0=C:\WINDOWS\MICROSOFT.NET\FRAMEWORK64\V4.0.30319\SERVICEMODELEVENTS.DLL
### ServiceModel related event descriptions Microsoft Corporation Microsoft� .NET
Framework 4.7.2053.0
[Eventlog Application DLL] :HKLM System.Runtime.Serialization
3.0.0.0=C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication
Foundation\ServiceModelEvents.dll
### File is missing.
[Eventlog Application DLL] :HKLM System.Runtime.Serialization
4.0.0.0=C:\WINDOWS\MICROSOFT.NET\FRAMEWORK64\V4.0.30319\SERVICEMODELEVENTS.DLL
### ServiceModel related event descriptions Microsoft Corporation Microsoft� .NET
Framework 4.7.2053.0
[Eventlog Application DLL] :HKLM System.ServiceModel
3.0.0.0=C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication
Foundation\ServiceModelEvents.dll
### File is missing.
[Eventlog Application DLL] :HKLM System.ServiceModel
4.0.0.0=C:\WINDOWS\MICROSOFT.NET\FRAMEWORK64\V4.0.30319\SERVICEMODELEVENTS.DLL
### ServiceModel related event descriptions Microsoft Corporation Microsoft� .NET
Framework 4.7.2053.0
[Eventlog Application DLL] :HKLM usbperf=C:\WINDOWS\SYSTEM32\USBPERF.DLL
### USB Performance Objects DLL Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SystemRoot%\system32\usbperf.dll
[Eventlog Application DLL] :HKLM Userenv=C:\WINDOWS\SYSTEM32\USERENV.DLL
### Userenv Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*%SystemRoot%\System32\userenv.dll
[Eventlog Application DLL] :HKLM VBRuntime=C:\WINDOWS\SYSWOW64\MSVBVM60.DLL
### Visual Basic Virtual Machine Microsoft Corporation Visual Basic 6.00.9815
[Eventlog Application DLL] :HKLM VSS=C:\WINDOWS\SYSTEM32\VSSVC.EXE
### Microsoft� Volume Shadow Copy Service Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 !$*%SystemRoot%\System32\VSSVC.EXE
[Eventlog Application DLL] :HKLM VSTO 4.0=C:\PROGRAM FILES (X86)\COMMON
FILES\MICROSOFT SHARED\VSTO\10.0\VSTOMESSAGEPROVIDER.DLL
### Visual Studio Tools for Office Message Provider Microsoft Corporation
Microsoft� Visual Studio� 2010 10.0.31129.0
[Eventlog Application DLL] :HKLM WerSvc=C:\WINDOWS\SYSTEM32\WERSVC.DLL
### Windows Error Reporting Service Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SystemRoot%\System32\wersvc.dll
[Eventlog Application DLL] :HKLM Windows Backup=C:\WINDOWS\SYSTEM32\SDENGIN2.DLL
### Microsoft� Windows Backup Engine Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%systemroot%\system32\sdengin2.dll
[Eventlog Application DLL] :HKLM Windows Error
Reporting=C:\WINDOWS\SYSTEM32\WER.DLL
### Windows Error Reporting DLL Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SystemRoot%\System32\wer.dll
[Eventlog Application DLL] :HKLM Windows Search
Service=C:\WINDOWS\SYSTEM32\TQUERY.DLL
### Microsoft Tripoli Query Microsoft Corporation Windows� Search 7.0.14393.0 !$*
%systemroot%\system32\tquery.dll
[Eventlog Application DLL] :HKLM Windows Search Service Profile
Notification=C:\WINDOWS\SYSTEM32\WSEPNO.DLL
### Profile notification support for Windows Search Service Microsoft Corporation
Windows� Search 7.0.14393.0 !$*%SystemRoot%\system32\wsepno.dll
[Eventlog Application DLL] :HKLM Wininit=C:\WINDOWS\SYSTEM32\WININIT.EXE
### Windows Start-Up Application Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*%SystemRoot%\System32\wininit.exe
[Eventlog Application DLL] :HKLM Winlogon=C:\WINDOWS\SYSTEM32\WINLOGON.EXE
### Windows Logon Application Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%SystemRoot%\System32\winlogon.exe
[Eventlog Application DLL] :HKLM Wlclntfy=C:\WINDOWS\SYSTEM32\WINLOGON.EXE
### Windows Logon Application Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%SystemRoot%\System32\winlogon.exe
[Eventlog Application DLL] :HKLM WMI.NET Provider
Extension=C:\WINDOWS\MICROSOFT.NET\FRAMEWORK64\V4.0.30319\EVENTLOGMESSAGES.DLL
### EventLogMessages.dll Microsoft Corporation Microsoft� .NET Framework
4.7.2053.0
[Eventlog Application DLL] :HKLM Wow64 Emulation
Layer=C:\WINDOWS\SYSTEM32\NTVDM64.DLL
### 16-bit Emulation on NT64 Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*%SystemRoot%\System32\ntvdm64.dll
[Eventlog Application DLL] :HKLM
WsAppService=C:\Windows\Microsoft.NET\Framework\v2.0.50727\EventLogMessages.dll
### File is missing.
[Eventlog Application DLL] :HKLM
WsDrvInst=C:\Windows\Microsoft.NET\Framework\v2.0.50727\EventLogMessages.dll
### File is missing.
[Eventlog Application DLL] :HKLM WSH=C:\WINDOWS\SYSTEM32\WSHEXT.DLL
### Microsoft � Shell Extension for Windows Script Host Microsoft Corporation
Microsoft � Windows Script Host 5.812.10240.16384 !$*%SystemRoot
%\System32\wshext.dll
[Drivers] :HKLM 1394ohci=C:\WINDOWS\SYSTEM32\DRIVERS\1394OHCI.SYS
### 1394 OpenHCI Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*\SystemRoot\System32\drivers\1394ohci.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM 3ware=C:\WINDOWS\SYSTEM32\DRIVERS\3WARE.SYS
### LSI 3ware SCSI Storport Driver LSI LSI 3ware RAID Controller WindowsBlue
Service registry key doesn't exist or hidden.
[Drivers] :HKLM ACPI=C:\WINDOWS\SYSTEM32\DRIVERS\ACPI.SYS
### ACPI Driver for NT Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM AcpiDev=C:\WINDOWS\SYSTEM32\DRIVERS\ACPIDEV.SYS
### ACPI Devices Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*\SystemRoot\System32\drivers\AcpiDev.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM acpiex=C:\WINDOWS\SYSTEM32\DRIVERS\ACPIEX.SYS
### ACPIEx Driver Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM acpipagr=C:\WINDOWS\SYSTEM32\DRIVERS\ACPIPAGR.SYS
### ACPI Processor Aggregator Device Driver Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 !$*\SystemRoot\System32\drivers\acpipagr.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM AcpiPmi=C:\WINDOWS\SYSTEM32\DRIVERS\ACPIPMI.SYS
### ACPI Power Metering Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*\SystemRoot\System32\drivers\acpipmi.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM acpitime=C:\WINDOWS\SYSTEM32\DRIVERS\ACPITIME.SYS
### ACPI Wake Alarm Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*\SystemRoot\System32\drivers\acpitime.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM ADP80XX=C:\WINDOWS\SYSTEM32\DRIVERS\ADP80XX.SYS
### PMC-Sierra Storport Driver For SPC8x6G SAS/SATA controller PMC-Sierra PMC-
Sierra HBA Controller 1.3.0.10769 Service registry key doesn't exist or hidden.
[Drivers] :HKLM AFD=C:\WINDOWS\SYSTEM32\DRIVERS\AFD.SYS
### Ancillary Function Driver for WinSock Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 !$*\SystemRoot\system32\drivers\afd.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM ahcache=C:\WINDOWS\SYSTEM32\DRIVERS\AHCACHE.SYS
### Application Compatibility Cache Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.351 Service registry key doesn't exist or hidden.
[Drivers] :HKLM AmdK8=C:\WINDOWS\SYSTEM32\DRIVERS\AMDK8.SYS
### Processor Device Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*\SystemRoot\System32\drivers\amdk8.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM AmdPPM=C:\WINDOWS\SYSTEM32\DRIVERS\AMDPPM.SYS
### Processor Device Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*\SystemRoot\System32\drivers\amdppm.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM amdsata=C:\WINDOWS\SYSTEM32\DRIVERS\AMDSATA.SYS
### AHCI 1.3 Device Driver Advanced Micro Devices AHCI 1.3 Device Driver
1.1.3.277 Service registry key doesn't exist or hidden.
[Drivers] :HKLM amdsbs=C:\WINDOWS\SYSTEM32\DRIVERS\AMDSBS.SYS
### AMD Technology AHCI Compatible Controller Driver for Windows - AMD64 platform
AMD Technologies Inc. AMD Technology AHCI Compatible Controller 3.7.1540.43
Service registry key doesn't exist or hidden.
[Drivers] :HKLM amdxata=C:\WINDOWS\SYSTEM32\DRIVERS\AMDXATA.SYS
### Storage Filter Driver Advanced Micro Devices Storage Filter Driver 1.1.3.277
Service registry key doesn't exist or hidden.
[Drivers] :HKLM AppID=C:\WINDOWS\SYSTEM32\DRIVERS\APPID.SYS
### AppID Driver Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM applockerfltr=C:\WINDOWS\SYSTEM32\DRIVERS\APPLOCKERFLTR.SYS
### Applocker Filter Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM AppvStrm=C:\WINDOWS\SYSTEM32\DRIVERS\APPVSTRM.SYS
### Microsoft Application Virtualization Streaming Driver Microsoft Corporation
Microsoft� Windows� Operating System 10.0.14393.206 !
$*\SystemRoot\system32\drivers\AppvStrm.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM AppvVemgr=C:\WINDOWS\SYSTEM32\DRIVERS\APPVVEMGR.SYS
### Microsoft Application Virtualization VE Manager Driver Microsoft Corporation
Microsoft� Windows� Operating System 10.0.14393.0 !
$*\SystemRoot\system32\drivers\AppvVemgr.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM AppvVfs=C:\WINDOWS\SYSTEM32\DRIVERS\APPVVFS.SYS
### Microsoft Application Virtualization VFS Filter Driver Microsoft Corporation
Microsoft� Windows� Operating System 10.0.14393.0 !
$*\SystemRoot\system32\drivers\AppvVfs.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM arcsas=C:\WINDOWS\SYSTEM32\DRIVERS\ARCSAS.SYS
### Adaptec SAS RAID WS03 Driver PMC-Sierra, Inc. Adaptec RAID Controller
7.5.0.32048 Service registry key doesn't exist or hidden.
[Drivers] :HKLM AsusTP=C:\WINDOWS\SYSTEM32\DRIVERS\ASUSTP.SYS
### Asus TP Filter Driver(X64) ASUS Corporation Asus TP Filter Driver 6.0.0.83 !
$*\SystemRoot\System32\drivers\AsusTP.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM AsyncMac=C:\WINDOWS\SYSTEM32\DRIVERS\ASYNCMAC.SYS
### MS Remote Access serial network driver Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 !$*\SystemRoot\System32\drivers\asyncmac.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM atapi=C:\WINDOWS\SYSTEM32\DRIVERS\ATAPI.SYS
### ATAPI IDE Miniport Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM athr=C:\WINDOWS\SYSTEM32\DRIVERS\ATHW8X.SYS
### Qualcomm Atheros Extensible Wireless LAN device driver Qualcomm Atheros
Communications, Inc. Driver for Qualcomm Atheros CB42/CB43/MB42/MB43 Network
Adapter 3.0.2.201 !$*\SystemRoot\System32\drivers\athw8x.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM ATKWMIACPIIO_=C:\PROGRAM FILES (X86)\ASUS\ATK PACKAGE\ATK
WMIACPI\ATKWMIACPI64.SYS
### ATK WMIACPI Utility ASUSTek Computer Inc. ATK WMIACPI Utility 1, 0, 6, 0 !
$*\??\C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM b06bdrv=C:\WINDOWS\SYSTEM32\DRIVERS\BXVBDA.SYS
### QLogic Gigabit Ethernet VBD QLogic Corporation QLogic Gigabit Ethernet
7.12.31.105 Service registry key doesn't exist or hidden.
[Drivers] :HKLM BasicDisplay=C:\WINDOWS\SYSTEM32\DRIVERS\BASICDISPLAY.SYS
### Microsoft Basic Display Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.1066 !$*\SystemRoot\System32\drivers\BasicDisplay.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM BasicRender=C:\WINDOWS\SYSTEM32\DRIVERS\BASICRENDER.SYS
### Microsoft Basic Render Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.1770 !$*\SystemRoot\System32\drivers\BasicRender.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM bcmfn=C:\WINDOWS\SYSTEM32\DRIVERS\BCMFN.SYS
### BCM Function 2 Device Driver Windows (R) Win 7 DDK provider Windows (R) Win
7 DDK driver 6.3.9477.0 !$*\SystemRoot\System32\drivers\bcmfn.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM bcmfn2=C:\WINDOWS\SYSTEM32\DRIVERS\BCMFN2.SYS
### BCM Function 2 Device Driver Windows (R) Win 7 DDK provider Windows (R) Win
7 DDK driver 6.3.9391.6 !$*\SystemRoot\System32\drivers\bcmfn2.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM bcmsmbsp=C:\WINDOWS\SYSTEM32\DRIVERS\BCMSMBSP.SYS
### Broadcom SMBus Controller Driver Broadcom Corporation. SMBus Controller
Device 1.3.0.180 !$*\SystemRoot\System32\drivers\bcmsmbsp.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM bowser=C:\WINDOWS\SYSTEM32\DRIVERS\BOWSER.SYS
### NT Lan Manager Datagram Receiver Driver Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.447 Service registry key doesn't exist or
hidden.
[Drivers] :HKLM BtFilter=C:\WINDOWS\SYSTEM32\DRIVERS\BTFILTER.SYS
### Qualcomm Atheros BtFilter Driver Qualcomm Atheros Windows (R) Win 7 DDK
driver 10.0.1.1 !$*\SystemRoot\system32\DRIVERS\btfilter.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM BthAvrcpTg=C:\WINDOWS\SYSTEM32\DRIVERS\BTHAVRCPTG.SYS
### Bluetooth Audio/Video Remote Control HID Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 !
$*\SystemRoot\System32\drivers\BthAvrcpTg.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM BthEnum=C:\WINDOWS\SYSTEM32\DRIVERS\BTHENUM.SYS
### Bluetooth Bus Extender Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*\SystemRoot\System32\drivers\BthEnum.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM BthHFEnum=C:\WINDOWS\SYSTEM32\DRIVERS\BTHHFENUM.SYS
### Bluetooth Hands-Free Audio and Call Control HID Enumerator Microsoft
Corporation Microsoft� Windows� Operating System 10.0.14393.0 !
$*\SystemRoot\System32\drivers\bthhfenum.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM bthhfhid=C:\WINDOWS\SYSTEM32\DRIVERS\BTHHFHID.SYS
### Bluetooth Hands-free HID Minidriver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*\SystemRoot\System32\drivers\BthHFHid.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM BthLEEnum=C:\WINDOWS\SYSTEM32\DRIVERS\BTHLEENUM.SYS
### Bluetooth LE Bus Enumerator Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*\SystemRoot\System32\drivers\BthLEEnum.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM BTHMODEM=C:\WINDOWS\SYSTEM32\DRIVERS\BTHMODEM.SYS
### Bluetooth Communications Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*\SystemRoot\System32\drivers\bthmodem.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM BthPan=C:\WINDOWS\SYSTEM32\DRIVERS\BTHPAN.SYS
### Bluetooth Personal Area Networking Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*\SystemRoot\System32\drivers\bthpan.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM BTHPORT=C:\WINDOWS\SYSTEM32\DRIVERS\BTHPORT.SYS
### Bluetooth Bus Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*\SystemRoot\System32\drivers\BTHport.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM BTHUSB=C:\WINDOWS\SYSTEM32\DRIVERS\BTHUSB.SYS
### Bluetooth Miniport Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*\SystemRoot\System32\drivers\BTHUSB.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM buttonconverter=C:\WINDOWS\SYSTEM32\DRIVERS\BUTTONCONVERTER.SYS
### Button Converter Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*\SystemRoot\System32\drivers\buttonconverter.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM CapImg=C:\WINDOWS\SYSTEM32\DRIVERS\CAPIMG.SYS
### CapImg HID Driver Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.320 !$*\SystemRoot\System32\drivers\capimg.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM cdfs=C:\WINDOWS\SYSTEM32\DRIVERS\CDFS.SYS
### CD-ROM File System Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM cdrom=C:\WINDOWS\SYSTEM32\DRIVERS\CDROM.SYS
### SCSI CD-ROM Driver Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*\SystemRoot\System32\drivers\cdrom.sys Service registry key doesn't
exist or hidden.
[Drivers] :HKLM cht4iscsi=C:\WINDOWS\SYSTEM32\DRIVERS\CHT4SX64.SYS
### Chelsio iSCSI VMiniport Driver Chelsio Communications Chelsio Communications
iSCSI Controller 10.0.10011.16384 Service registry key doesn't exist or hidden.
[Drivers] :HKLM cht4vbd=C:\WINDOWS\SYSTEM32\DRIVERS\CHT4VX64.SYS
### Virtual Bus Driver for Chelsio � T4 Chipset Chelsio Communications Chelsio
Communications 10Gb Unified Network I/O Controller 10.0.10011.16384 !
$*\SystemRoot\System32\drivers\cht4vx64.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM circlass=C:\WINDOWS\SYSTEM32\DRIVERS\CIRCLASS.SYS
### Consumer IR Class Driver for eHome Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*\SystemRoot\System32\drivers\circlass.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM CLFS=C:\WINDOWS\SYSTEM32\DRIVERS\CLFS.SYS
### Common Log File System Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.1613 Service registry key doesn't exist or hidden.
[Drivers] :HKLM clreg=C:\WINDOWS\SYSTEM32\DRIVERS\REGISTRY.SYS
### Registry Containment Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*\SystemRoot\System32\drivers\registry.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM clwvd=C:\WINDOWS\SYSTEM32\DRIVERS\CLWVD.SYS
### CyberLink WebCam Virtual Driver CyberLink Corporation CyberLink WebCam
Virtual Driver 1. 0. 0. 1 !$*\SystemRoot\system32\DRIVERS\clwvd.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM CmBatt=C:\WINDOWS\SYSTEM32\DRIVERS\CMBATT.SYS
### Control Method Battery Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*\SystemRoot\System32\drivers\CmBatt.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM CNG=C:\WINDOWS\SYSTEM32\DRIVERS\CNG.SYS
### Kernel Cryptography, Next Generation Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.1770 Service registry key doesn't exist or
hidden.
[Drivers] :HKLM cnghwassist=C:\WINDOWS\SYSTEM32\DRIVERS\CNGHWASSIST.SYS
### CNG Hardware Assist algorithm provider Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 Service registry key doesn't exist or
hidden.
[Drivers] :HKLM CnxtHdAudService=C:\WINDOWS\SYSTEM32\DRIVERS\CHDRT64.SYS
### 64-bit High Definition Audio Function Driver Conexant Systems Inc. Conexant
HDAudio Driver 8.66.16.0 !$*\SystemRoot\system32\drivers\CHDRT64.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM
CompositeBus=C:\WINDOWS\SYSTEM32\DRIVERSTORE\FILEREPOSITORY\COMPOSITEBUS.INF_AMD64_
A140581A8F8B58B7\COMPOSITEBUS.SYS
### Multi-Transport Composite Bus Enumerator Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 !
$*\SystemRoot\System32\DriverStore\FileRepository\compositebus.inf_amd64_a140581a8f
8b58b7\CompositeBus.sys Service registry key doesn't exist or hidden.
[Drivers] :HKLM condrv=C:\WINDOWS\SYSTEM32\DRIVERS\CONDRV.SYS
### Console Driver Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM CSC=C:\WINDOWS\SYSTEM32\DRIVERS\CSC.SYS
### Windows Client Side Caching Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.953 Service registry key doesn't exist or hidden.
[Drivers] :HKLM dam=C:\WINDOWS\SYSTEM32\DRIVERS\DAM.SYS
### DAM Kernel Driver Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.953 Service registry key doesn't exist or hidden.
[Drivers] :HKLM Dfsc=C:\WINDOWS\SYSTEM32\DRIVERS\DFSC.SYS
### DFS Namespace Client Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.1378 Service registry key doesn't exist or hidden.
[Drivers] :HKLM dg_ssudbus=C:\WINDOWS\SYSTEM32\DRIVERS\SSUDBUS.SYS
### SAMSUNG USB Composite Device Driver Samsung Electronics Co., Ltd. SAMSUNG USB
Composite Device Driver 2.12.5.0 !$*\SystemRoot\system32\DRIVERS\ssudbus.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM disk=C:\WINDOWS\SYSTEM32\DRIVERS\DISK.SYS
### PnP Disk Driver Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM dmvsc=C:\WINDOWS\SYSTEM32\DRIVERS\DMVSC.SYS
### Dynamic Memory Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*\SystemRoot\System32\drivers\dmvsc.sys Service registry key doesn't
exist or hidden.
[Drivers] :HKLM DptfDevProc=C:\WINDOWS\SYSTEM32\DRIVERS\DPTFDEVPROC.SYS
### Intel(R) Dynamic Platform and Thermal Framework Processor Participant Driver
Intel Corporation Intel(R) Dynamic Platform and Thermal Framework 7.1.0.2106 !
$*\SystemRoot\system32\DRIVERS\DptfDevProc.sys Service registry key doesn't exist
or hidden.
[Drivers] :HKLM DptfManager=C:\WINDOWS\SYSTEM32\DRIVERS\DPTFMANAGER.SYS
### Intel(R) Dynamic Platform and Thermal Framework Manager Driver Intel
Corporation Intel(R) Dynamic Platform and Thermal Framework 7.1.0.2106 !
$*\SystemRoot\system32\DRIVERS\DptfManager.sys Service registry key doesn't exist
or hidden.
[Drivers] :HKLM drmkaud=C:\WINDOWS\SYSTEM32\DRIVERS\DRMKAUD.SYS
### Microsoft Trusted Audio Drivers Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*\SystemRoot\system32\DRIVERS\drmkaud.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM DXGKrnl=C:\WINDOWS\SYSTEM32\DRIVERS\DXGKRNL.SYS
### DirectX Graphics Kernel Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.1715 !$*\SystemRoot\System32\drivers\dxgkrnl.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM ebdrv=C:\WINDOWS\SYSTEM32\DRIVERS\EVBDA.SYS
### QLogic 10 GigE VBD QLogic Corporation QLogic 10 GigE 7.13.65.105 Service
registry key doesn't exist or hidden.
[Drivers] :HKLM EhStorClass=C:\WINDOWS\SYSTEM32\DRIVERS\EHSTORCLASS.SYS
### Enhanced Storage Class driver for IEEE 1667 devices Microsoft Corporation
Microsoft� Windows� Operating System 10.0.14393.0 Service registry key doesn't
exist or hidden.
[Drivers] :HKLM EhStorTcgDrv=C:\WINDOWS\SYSTEM32\DRIVERS\EHSTORTCGDRV.SYS
### Microsoft driver for storage devices supporting IEEE 1667 and TCG protocols
Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0 Service
registry key doesn't exist or hidden.
[Drivers] :HKLM ErrDev=C:\WINDOWS\SYSTEM32\DRIVERS\ERRDEV.SYS
### Error Device Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*\SystemRoot\System32\drivers\errdev.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM ewusbmbb=C:\WINDOWS\SYSTEM32\DRIVERS\EWUSBWWAN.SYS
### USB NDIS Miniport Driver Huawei Technologies Co., Ltd. Huawei Technologies
Co., Ltd. USB NDIS Miniport Driver 6,0,1,314 !
$*\SystemRoot\System32\drivers\ewusbwwan.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM ew_hwusbdev=C:\WINDOWS\SYSTEM32\DRIVERS\EW_HWUSBDEV.SYS
### USB Modem/Serial Device Driver Huawei Technologies Co., Ltd. Huawei
Technologies Co., Ltd. USB Modem/Serial Device Driver 1. 0. 1. 4. SP00 !
$*\SystemRoot\system32\DRIVERS\ew_hwusbdev.sys Service registry key doesn't exist
or hidden.
[Drivers] :HKLM fdc=C:\WINDOWS\SYSTEM32\DRIVERS\FDC.SYS
### Floppy Disk Controller Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*\SystemRoot\System32\drivers\fdc.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM FileCrypt=C:\WINDOWS\SYSTEM32\DRIVERS\FILECRYPT.SYS
### Windows sandboxing and encryption filter Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 Service registry key doesn't exist or
hidden.
[Drivers] :HKLM FileInfo=C:\WINDOWS\SYSTEM32\DRIVERS\FILEINFO.SYS
### FileInfo Filter Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM Filetrace=C:\WINDOWS\SYSTEM32\DRIVERS\FILETRACE.SYS
### File Trace Filter Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM flpydisk=C:\WINDOWS\SYSTEM32\DRIVERS\FLPYDISK.SYS
### Floppy Driver Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*\SystemRoot\System32\drivers\flpydisk.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM FltMgr=C:\WINDOWS\SYSTEM32\DRIVERS\FLTMGR.SYS
### Microsoft Filesystem Filter Manager Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM FsDepends=C:\WINDOWS\SYSTEM32\DRIVERS\FSDEPENDS.SYS
### File System Dependency Manager Mini Filter Driver Microsoft Corporation
Microsoft� Windows� Operating System 10.0.14393.1198 Service registry key doesn't
exist or hidden.
[Drivers] :HKLM fvevol=C:\WINDOWS\SYSTEM32\DRIVERS\FVEVOL.SYS
### BitLocker Drive Encryption Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM gencounter=C:\WINDOWS\SYSTEM32\DRIVERS\VMGENCOUNTER.SYS
### Virtual Machine Generation Counter Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*\SystemRoot\System32\drivers\vmgencounter.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM genericusbfn=C:\WINDOWS\SYSTEM32\DRIVERS\GENERICUSBFN.SYS
### Generic USB Function Class Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*\SystemRoot\System32\drivers\genericusbfn.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM GPIOClx0101=C:\WINDOWS\SYSTEM32\DRIVERS\MSGPIOCLX.SYS
### GPIO Class Extension Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM GpuEnergyDrv=C:\WINDOWS\SYSTEM32\DRIVERS\GPUENERGYDRV.SYS
### GPU Energy Kernel Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM HDAudBus=C:\WINDOWS\SYSTEM32\DRIVERS\HDAUDBUS.SYS
### High Definition Audio Bus Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*\SystemRoot\System32\drivers\HDAudBus.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM HidBatt=C:\WINDOWS\SYSTEM32\DRIVERS\HIDBATT.SYS
### Hid Battery Driver Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*\SystemRoot\System32\drivers\HidBatt.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM HidBth=C:\WINDOWS\SYSTEM32\DRIVERS\HIDBTH.SYS
### Bluetooth Miniport Driver for HID Devices Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 !$*\SystemRoot\System32\drivers\hidbth.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM hidi2c=C:\WINDOWS\SYSTEM32\DRIVERS\HIDI2C.SYS
### I2C HID Miniport Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*\SystemRoot\System32\drivers\hidi2c.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM hidinterrupt=C:\WINDOWS\SYSTEM32\DRIVERS\HIDINTERRUPT.SYS
### HID Button over Interrupt Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*\SystemRoot\System32\drivers\hidinterrupt.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM HidIr=C:\WINDOWS\SYSTEM32\DRIVERS\HIDIR.SYS
### Infrared Miniport Driver for Input Devices Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 !$*\SystemRoot\System32\drivers\hidir.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM HIDSwitch=C:\WINDOWS\SYSTEM32\DRIVERS\ASHIDSWITCH64.SYS
### HID driver for ASUS Wireless Radio Control ASUS ASUS Wireless Radio Control
1.0.0.5 !$*\SystemRoot\System32\drivers\AsHIDSwitch64.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM HidUsb=C:\WINDOWS\SYSTEM32\DRIVERS\HIDUSB.SYS
### USB Miniport Driver for Input Devices Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.82 !$*\SystemRoot\System32\drivers\hidusb.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM HpSAMD=C:\WINDOWS\SYSTEM32\DRIVERS\HPSAMD.SYS
### Smart Array SAS/SATA Controller Media Driver Hewlett-Packard Company Smart
Array SAS/SATA Controller Media Driver 8.0.4.0 Build 1 Media Driver (x86-64)
Service registry key doesn't exist or hidden.
[Drivers] :HKLM HTTP=C:\WINDOWS\SYSTEM32\DRIVERS\HTTP.SYS
### HTTP Protocol Stack Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.1532 Service registry key doesn't exist or hidden.
[Drivers] :HKLM huawei_enumerator=C:\WINDOWS\SYSTEM32\DRIVERS\EW_JUBUSENUM.SYS
### ew_jubusenum Driver Huawei Technologies Co., Ltd. ew_jubusenum Driver (x64)
2.6.2.3129 !$*\SystemRoot\System32\drivers\ew_jubusenum.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM hvservice=C:\WINDOWS\SYSTEM32\DRIVERS\HVSERVICE.SYS
### Hypervisor Boot Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM hwdatacard=C:\WINDOWS\SYSTEM32\DRIVERS\EWUSBMDM.SYS
### USB Modem/Serial Device Driver Huawei Technologies Co., Ltd. Huawei
Technologies Co., Ltd. USB Modem/Serial Device Driver 2. 0. 6. 718 !
$*\SystemRoot\system32\DRIVERS\ewusbmdm.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM hwpolicy=C:\WINDOWS\SYSTEM32\DRIVERS\HWPOLICY.SYS
### Hardware Policy Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM hyperkbd=C:\WINDOWS\SYSTEM32\DRIVERS\HYPERKBD.SYS
### Microsoft VMBus Synthetic Keyboard Driver Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 !$*\SystemRoot\System32\drivers\hyperkbd.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM HyperVideo=C:\WINDOWS\SYSTEM32\DRIVERS\HYPERVIDEO.SYS
### Microsoft VMBus Video Device Miniport Driver Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 !
$*\SystemRoot\system32\DRIVERS\HyperVideo.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM i8042prt=C:\WINDOWS\SYSTEM32\DRIVERS\I8042PRT.SYS
### i8042 Port Driver Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*\SystemRoot\System32\drivers\i8042prt.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM iagpio=C:\WINDOWS\SYSTEM32\DRIVERS\IAGPIO.SYS
### Intel(R) Serial IO GPIO Controller Driver Intel(R) Corporation Intel(R)
Serial IO GPIO Controller Driver 604.10146.3023.12819 !
$*\SystemRoot\System32\drivers\iagpio.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM iai2c=C:\WINDOWS\SYSTEM32\DRIVERS\IAI2C.SYS
### Intel(R) Serial IO I2C Driver Intel(R) Corporation Intel(R) Serial IO I2C
Driver 604.10146.2643.68354 !$*\SystemRoot\System32\drivers\iai2c.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM iaLPSS2i_GPIO2=C:\WINDOWS\SYSTEM32\DRIVERS\IALPSS2I_GPIO2.SYS
### Intel(R) Serial IO GPIO Driver v2 Intel Corporation Intel(R) Serial IO Driver
30.63.1610.08 !$*\SystemRoot\System32\drivers\iaLPSS2i_GPIO2.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM iaLPSS2i_I2C=C:\WINDOWS\SYSTEM32\DRIVERS\IALPSS2I_I2C.SYS
### Intel(R) Serial IO I2C Driver v2 Intel Corporation Intel(R) Serial IO Driver
30.63.1610.08 !$*\SystemRoot\System32\drivers\iaLPSS2i_I2C.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM iaLPSSi_GPIO=C:\WINDOWS\SYSTEM32\DRIVERS\IALPSSI_GPIO.SYS
### Intel(R) Serial IO GPIO Controller Driver Intel Corporation Intel(R) Serial
IO Driver 1.1.250.0 !$*\SystemRoot\System32\drivers\iaLPSSi_GPIO.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM iaLPSSi_I2C=C:\WINDOWS\SYSTEM32\DRIVERS\IALPSSI_I2C.SYS
### Intel(R) Serial IO I2C Controller Driver Intel Corporation Intel(R) Serial IO
Driver 1.1.253.0 !$*\SystemRoot\System32\drivers\iaLPSSi_I2C.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM iaStorAV=C:\WINDOWS\SYSTEM32\DRIVERS\IASTORAV.SYS
### Intel(R) Rapid Storage Technology driver (inbox) - x64 Intel Corporation
Intel(R) Rapid Storage Technology driver (inbox) 13.2.0.1022 Service registry key
doesn't exist or hidden.
[Drivers] :HKLM iaStorV=C:\WINDOWS\SYSTEM32\DRIVERS\IASTORV.SYS
### Intel Matrix Storage Manager driver - x64 Intel Corporation Intel Matrix
Storage Manager driver 8.6.2.1019 Service registry key doesn't exist or hidden.
[Drivers] :HKLM ibbus=C:\WINDOWS\SYSTEM32\DRIVERS\IBBUS.SYS
### InfiniBand Fabric Bus Driver Mellanox OpenFabrics Windows 6.3.9600.16384 !
$*\SystemRoot\System32\drivers\ibbus.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM IDMWFP=C:\WINDOWS\SYSTEM32\DRIVERS\IDMWFP.SYS
### Internet Download Manager WFP Driver Tonec Inc. Internet Download Manager
6.28.12.0 !$*\SystemRoot\system32\DRIVERS\idmwfp.sys Service registry key doesn't
exist or hidden.
[Drivers] :HKLM igfx=C:\WINDOWS\SYSTEM32\DRIVERS\IGDKMD64.SYS
### Intel Graphics Kernel Mode Driver Intel Corporation Intel HD Graphics Drivers
for Windows(R) 20.19.15.4549 !$*\SystemRoot\system32\DRIVERS\igdkmd64.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM IndirectKmd=C:\WINDOWS\SYSTEM32\DRIVERS\INDIRECTKMD.SYS
### Indirect displays kernel-mode filter driver Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 !
$*\SystemRoot\System32\drivers\IndirectKmd.sys Service registry key doesn't exist
or hidden.
[Drivers] :HKLM IntcDAud=C:\WINDOWS\SYSTEM32\DRIVERS\INTCDAUD.SYS
### Intel(R) Display Audio Driver Intel(R) Corporation Intel(R) Display Audio
6.16.00.3197 !$*\SystemRoot\system32\DRIVERS\IntcDAud.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM intelide=C:\WINDOWS\SYSTEM32\DRIVERS\INTELIDE.SYS
### Intel PCI IDE Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM intelpep=C:\WINDOWS\SYSTEM32\DRIVERS\INTELPEP.SYS
### Intel Power Engine Plugin Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM intelppm=C:\WINDOWS\SYSTEM32\DRIVERS\INTELPPM.SYS
### Processor Device Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*\SystemRoot\System32\drivers\intelppm.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM iorate=C:\WINDOWS\SYSTEM32\DRIVERS\IORATE.SYS
### I/O rate control Filter Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM IpFilterDriver=C:\WINDOWS\SYSTEM32\DRIVERS\IPFLTDRV.SYS
### IP FILTER DRIVER Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM IPMIDRV=C:\WINDOWS\SYSTEM32\DRIVERS\IPMIDRV.SYS
### WMI IPMI DRIVER Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*\SystemRoot\System32\drivers\IPMIDrv.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM IPNAT=C:\WINDOWS\SYSTEM32\DRIVERS\IPNAT.SYS
### IP Network Address Translator Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM irda=C:\WINDOWS\SYSTEM32\DRIVERS\IRDA.SYS
### IRDA Protocol Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*\SystemRoot\system32\drivers\irda.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM IRENUM=C:\WINDOWS\SYSTEM32\DRIVERS\IRENUM.SYS
### Infra-Red Bus Enumerator Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM isapnp=C:\WINDOWS\SYSTEM32\DRIVERS\ISAPNP.SYS
### PNP ISA Bus Driver Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM iScsiPrt=C:\WINDOWS\SYSTEM32\DRIVERS\MSISCSI.SYS
### Microsoft iSCSI Initiator Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.1532 !$*\SystemRoot\System32\drivers\msiscsi.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM kbdclass=C:\WINDOWS\SYSTEM32\DRIVERS\KBDCLASS.SYS
### Keyboard Class Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*\SystemRoot\System32\drivers\kbdclass.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM kbdhid=C:\WINDOWS\SYSTEM32\DRIVERS\KBDHID.SYS
### HID Keyboard Filter Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*\SystemRoot\System32\drivers\kbdhid.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM kdnic=C:\WINDOWS\SYSTEM32\DRIVERS\KDNIC.SYS
### Microsoft Kernel Debugger Network Miniport Microsoft Corporation Microsoft
Kernel Debugger Network Adapter (NDIS 6.20 Miniport) 6.01.00.0000 !
$*\SystemRoot\System32\drivers\kdnic.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM KSecDD=C:\WINDOWS\SYSTEM32\DRIVERS\KSECDD.SYS
### Kernel Security Support Provider Interface Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.1770 Service registry key doesn't exist or
hidden.
[Drivers] :HKLM KSecPkg=C:\WINDOWS\SYSTEM32\DRIVERS\KSECPKG.SYS
### Kernel Security Support Provider Interface Packages Microsoft Corporation
Microsoft� Windows� Operating System 10.0.14393.1770 Service registry key doesn't
exist or hidden.
[Drivers] :HKLM ksthunk=C:\WINDOWS\SYSTEM32\DRIVERS\KSTHUNK.SYS
### Kernel Streaming WOW Thunk Service Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*\SystemRoot\system32\drivers\ksthunk.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM lltdio=C:\WINDOWS\SYSTEM32\DRIVERS\LLTDIO.SYS
### Link-Layer Topology Mapper I/O Driver Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 Service registry key doesn't exist or
hidden.
[Drivers] :HKLM LSI_SAS=C:\WINDOWS\SYSTEM32\DRIVERS\LSI_SAS.SYS
### LSI Fusion-MPT SAS Driver (StorPort) LSI Corporation LSI Fusion-MPT SAS
Driver (StorPort) 1.34.03.83 Service registry key doesn't exist or hidden.
[Drivers] :HKLM LSI_SAS2i=C:\WINDOWS\SYSTEM32\DRIVERS\LSI_SAS2I.SYS
### LSI SAS Gen2 Driver (StorPort) LSI Corporation Microsoft� Windows� Operating
System 10.0.14304.1001 Service registry key doesn't exist or hidden.
[Drivers] :HKLM LSI_SAS3i=C:\WINDOWS\SYSTEM32\DRIVERS\LSI_SAS3I.SYS
### Avago SAS Gen3 Driver (StorPort) Avago Technologies Microsoft� Windows�
Operating System 10.0.14304.1001 Service registry key doesn't exist or hidden.
[Drivers] :HKLM LSI_SSS=C:\WINDOWS\SYSTEM32\DRIVERS\LSI_SSS.SYS
### LSI SSS PCIe/Flash Driver (StorPort) LSI Corporation LSI SSS PCIe/Flash
Driver (StorPort) 2.10.61.81 Service registry key doesn't exist or hidden.
[Drivers] :HKLM luafv=C:\WINDOWS\SYSTEM32\DRIVERS\LUAFV.SYS
### LUA File Virtualization Filter Driver Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 !$*\SystemRoot\system32\drivers\luafv.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM massfilter=\SystemRoot\System32\drivers\massfilter.sys
### !$*\SystemRoot\System32\drivers\massfilter.sys File is missing. Service
registry key doesn't exist or hidden.
[Drivers] :HKLM megasas=C:\WINDOWS\SYSTEM32\DRIVERS\MEGASAS.SYS
### MEGASAS RAID Controller Driver for Windows Avago Technologies MEGASAS RAID
Controller Driver for Windows 6.706.06.00 Service registry key doesn't exist or
hidden.
[Drivers] :HKLM megasas2i=C:\WINDOWS\SYSTEM32\DRIVERS\MEGASAS2I.SYS
### MEGASAS RAID Controller Driver for Windows Avago Technologies MEGASAS RAID
Controller Driver for Windows 6.711.10.11 Service registry key doesn't exist or
hidden.
[Drivers] :HKLM megasr=C:\WINDOWS\SYSTEM32\DRIVERS\MEGASR.SYS
### LSI MegaRAID Software RAID Driver LSI Corporation, Inc. MegaRAID Software
RAID 15.02.2013.0129 Service registry key doesn't exist or hidden.
[Drivers] :HKLM MEIx64=C:\WINDOWS\SYSTEM32\DRIVERS\TEEDRIVERW8X64.SYS
### Intel(R) Management Engine Interface Intel Corporation Intel(R) Management
Engine Interface 11.0.0.1160 !$*\SystemRoot\System32\drivers\TeeDriverW8x64.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM mlx4_bus=C:\WINDOWS\SYSTEM32\DRIVERS\MLX4_BUS.SYS
### MLX4 Bus Driver Mellanox OpenFabrics Windows 6.3.9600.16384 !
$*\SystemRoot\System32\drivers\mlx4_bus.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM MMCSS=C:\WINDOWS\SYSTEM32\DRIVERS\MMCSS.SYS
### MMCSS Driver Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*\SystemRoot\system32\drivers\mmcss.sys Service registry key doesn't
exist or hidden.
[Drivers] :HKLM Modem=C:\WINDOWS\SYSTEM32\DRIVERS\MODEM.SYS
### Modem Device Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM monitor=C:\WINDOWS\SYSTEM32\DRIVERS\MONITOR.SYS
### Monitor Driver Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*\SystemRoot\System32\drivers\monitor.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM mouclass=C:\WINDOWS\SYSTEM32\DRIVERS\MOUCLASS.SYS
### Mouse Class Driver Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*\SystemRoot\System32\drivers\mouclass.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM mouhid=C:\WINDOWS\SYSTEM32\DRIVERS\MOUHID.SYS
### HID Mouse Filter Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*\SystemRoot\System32\drivers\mouhid.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM mountmgr=C:\WINDOWS\SYSTEM32\DRIVERS\MOUNTMGR.SYS
### Mount Point Manager Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM MpKslbab3842b=\??\C:\ProgramData\Microsoft\Windows
Defender\Definition Updates\{002DD7E9-BD89-4D24-B582-
AF6C6E4300A1}\MpKslbab3842b.sys
### !$*\??\C:\ProgramData\Microsoft\Windows Defender\Definition Updates\
{002DD7E9-BD89-4D24-B582-AF6C6E4300A1}\MpKslbab3842b.sys File is missing. Service
registry key doesn't exist or hidden.
[Drivers] :HKLM mpsdrv=C:\WINDOWS\SYSTEM32\DRIVERS\MPSDRV.SYS
### Microsoft Protection Service Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM MRxDAV=C:\WINDOWS\SYSTEM32\DRIVERS\MRXDAV.SYS
### Windows NT WebDav Minirdr Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.321 !$*\SystemRoot\system32\drivers\mrxdav.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM mrxsmb=C:\WINDOWS\SYSTEM32\DRIVERS\MRXSMB.SYS
### Windows NT SMB Minirdr Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM mrxsmb10=C:\WINDOWS\SYSTEM32\DRIVERS\MRXSMB10.SYS
### Longhorn SMB Downlevel SubRdr Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.1770 Service registry key doesn't exist or hidden.
[Drivers] :HKLM mrxsmb20=C:\WINDOWS\SYSTEM32\DRIVERS\MRXSMB20.SYS
### Longhorn SMB 2.0 Redirector Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.1770 Service registry key doesn't exist or hidden.
[Drivers] :HKLM MsBridge=C:\WINDOWS\SYSTEM32\DRIVERS\BRIDGE.SYS
### MAC Bridge Driver Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.1480 Service registry key doesn't exist or hidden.
[Drivers] :HKLM msgpiowin32=C:\WINDOWS\SYSTEM32\DRIVERS\MSGPIOWIN32.SYS
### GPIO Button Driver Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*\SystemRoot\System32\drivers\msgpiowin32.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM mshidkmdf=C:\WINDOWS\SYSTEM32\DRIVERS\MSHIDKMDF.SYS
### Pass-through HID to KMDF Filter Driver Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 !
$*\SystemRoot\System32\drivers\mshidkmdf.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM mshidumdf=C:\WINDOWS\SYSTEM32\DRIVERS\MSHIDUMDF.SYS
### Pass-through Driver for HID-UMDF Interface Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 !
$*\SystemRoot\System32\drivers\mshidumdf.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM msisadrv=C:\WINDOWS\SYSTEM32\DRIVERS\MSISADRV.SYS
### ISA Driver Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM MSKSSRV=C:\WINDOWS\SYSTEM32\DRIVERS\MSKSSRV.SYS
### MS KS Server Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.953 !$*\SystemRoot\system32\DRIVERS\MSKSSRV.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM MsLldp=C:\WINDOWS\SYSTEM32\DRIVERS\MSLLDP.SYS
### Microsoft Link-Layer Discovery Protocol Driver Microsoft Corporation
Microsoft� Windows� Operating System 10.0.14393.0 Service registry key doesn't
exist or hidden.
[Drivers] :HKLM MSPCLOCK=C:\WINDOWS\SYSTEM32\DRIVERS\MSPCLOCK.SYS
### MS Proxy Clock Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*\SystemRoot\system32\DRIVERS\MSPCLOCK.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM MSPQM=C:\WINDOWS\SYSTEM32\DRIVERS\MSPQM.SYS
### MS Proxy Quality Manager Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*\SystemRoot\system32\DRIVERS\MSPQM.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM MsSecFlt=C:\WINDOWS\SYSTEM32\DRIVERS\MSSECFLT.SYS
### Microsoft Security Events Component file system filter driver Microsoft
Corporation Microsoft� Windows� Operating System 10.0.14393.0 Service registry key
doesn't exist or hidden.
[Drivers] :HKLM mssmbios=C:\WINDOWS\SYSTEM32\DRIVERS\MSSMBIOS.SYS
### System Management BIOS Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*\SystemRoot\System32\drivers\mssmbios.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM MSTEE=C:\WINDOWS\SYSTEM32\DRIVERS\MSTEE.SYS
### WDM Tee/Communication Transform Filter Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 !$*\SystemRoot\system32\DRIVERS\MSTEE.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM MTConfig=C:\WINDOWS\SYSTEM32\DRIVERS\MTCONFIG.SYS
### Microsoft Multi-Touch HID Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*\SystemRoot\System32\drivers\MTConfig.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM Mup=C:\WINDOWS\SYSTEM32\DRIVERS\MUP.SYS
### Multiple UNC Provider Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM mvumis=C:\WINDOWS\SYSTEM32\DRIVERS\MVUMIS.SYS
### Marvell Flash Controller Driver Marvell Semiconductor, Inc. Marvell Flash
Controller 1.0.5.1016 Service registry key doesn't exist or hidden.
[Drivers] :HKLM NativeWifiP=C:\WINDOWS\SYSTEM32\DRIVERS\NWIFI.SYS
### NativeWiFi Miniport Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM ndfltr=C:\WINDOWS\SYSTEM32\DRIVERS\NDFLTR.SYS
### NetworkDirect Support Filter Driver Mellanox OpenFabrics Windows
6.3.9600.16384 !$*\SystemRoot\System32\drivers\ndfltr.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM NDIS=C:\WINDOWS\SYSTEM32\DRIVERS\NDIS.SYS
### Network Driver Interface Specification (NDIS) Microsoft Corporation
Microsoft� Windows� Operating System 10.0.14393.953 Service registry key doesn't
exist or hidden.
[Drivers] :HKLM NdisCap=C:\WINDOWS\SYSTEM32\DRIVERS\NDISCAP.SYS
### Microsoft NDIS Packet Capture Filter Driver Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 Service registry key doesn't exist or
hidden.
[Drivers] :HKLM NdisImPlatform=C:\WINDOWS\SYSTEM32\DRIVERS\NDISIMPLATFORM.SYS
### Microsoft Network Adapter Multiplexor Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 Service registry key doesn't exist or
hidden.
[Drivers] :HKLM NdisTapi=C:\WINDOWS\SYSTEM32\DRIVERS\NDISTAPI.SYS
### NDIS 3.0 connection wrapper driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM Ndisuio=C:\WINDOWS\SYSTEM32\DRIVERS\NDISUIO.SYS
### NDIS User mode I/O driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM NdisVirtualBus=C:\WINDOWS\SYSTEM32\DRIVERS\NDISVIRTUALBUS.SYS
### Microsoft Virtual Network Adapter Enumerator Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 !
$*\SystemRoot\System32\drivers\NdisVirtualBus.sys Service registry key doesn't
exist or hidden.
[Drivers] :HKLM NdisWan=C:\WINDOWS\SYSTEM32\DRIVERS\NDISWAN.SYS
### MS PPP Framing Driver (Strong Encryption) Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 !$*\SystemRoot\System32\drivers\ndiswan.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM ndiswanlegacy=C:\WINDOWS\SYSTEM32\DRIVERS\NDISWAN.SYS
### MS PPP Framing Driver (Strong Encryption) Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 Service registry key doesn't exist or
hidden.
[Drivers] :HKLM ndproxy=C:\WINDOWS\SYSTEM32\DRIVERS\NDPROXY.SYS
### NDIS Proxy Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM Ndu=C:\WINDOWS\SYSTEM32\DRIVERS\NDU.SYS
### Windows Network Data Usage Monitoring Driver Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 Service registry key doesn't exist or
hidden.
[Drivers] :HKLM NetAdapterCx=C:\WINDOWS\SYSTEM32\DRIVERS\NETADAPTERCX.SYS
### Service registry key doesn't exist or hidden.
[Drivers] :HKLM NetBIOS=C:\WINDOWS\SYSTEM32\DRIVERS\NETBIOS.SYS
### NetBIOS interface driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM NetBT=C:\WINDOWS\SYSTEM32\DRIVERS\NETBT.SYS
### MBT Transport driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.1715 Service registry key doesn't exist or hidden.
[Drivers] :HKLM netvsc=C:\WINDOWS\SYSTEM32\DRIVERS\NETVSC.SYS
### Virtual NDIS Miniport Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*\SystemRoot\System32\drivers\netvsc.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM npsvctrig=C:\WINDOWS\SYSTEM32\DRIVERS\NPSVCTRIG.SYS
### Named pipe service triggers Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*\SystemRoot\System32\drivers\npsvctrig.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM nsiproxy=C:\WINDOWS\SYSTEM32\DRIVERS\NSIPROXY.SYS
### NSI Proxy Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.1715 Service registry key doesn't exist or hidden.
[Drivers] :HKLM nvlddmkm=C:\WINDOWS\SYSTEM32\DRIVERS\NVLDDMKM.SYS
### NVIDIA Windows Kernel Mode Driver, Version 359.46 NVIDIA Corporation NVIDIA
Windows Kernel Mode Driver, Version 359.46 10.18.13.5946 !
$*\SystemRoot\system32\DRIVERS\nvlddmkm.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM nvraid=C:\WINDOWS\SYSTEM32\DRIVERS\NVRAID.SYS
### NVIDIA� nForce(TM) RAID Driver NVIDIA Corporation NVIDIA nForce(TM) RAID
Driver 10.6.0.23 Service registry key doesn't exist or hidden.
[Drivers] :HKLM nvstor=C:\WINDOWS\SYSTEM32\DRIVERS\NVSTOR.SYS
### NVIDIA� nForce(TM) Sata Performance Driver NVIDIA Corporation NVIDIA
nForce(TM) SATA Driver 10.6.0.23 Service registry key doesn't exist or hidden.
[Drivers] :HKLM Parport=C:\WINDOWS\SYSTEM32\DRIVERS\PARPORT.SYS
### Parallel Port Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*\SystemRoot\System32\drivers\parport.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM Partizan=C:\WINDOWS\system32\drivers\Partizan.sys
### File is missing. Service registry key doesn't exist or hidden.
[Drivers] :HKLM partmgr=C:\WINDOWS\SYSTEM32\DRIVERS\PARTMGR.SYS
### Partition driver Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM pci=C:\WINDOWS\SYSTEM32\DRIVERS\PCI.SYS
### NT Plug and Play PCI Enumerator Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM pciide=C:\WINDOWS\SYSTEM32\DRIVERS\PCIIDE.SYS
### Generic PCI IDE Bus Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM pcmcia=C:\WINDOWS\SYSTEM32\DRIVERS\PCMCIA.SYS
### PCMCIA Bus Driver Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM pcw=C:\WINDOWS\SYSTEM32\DRIVERS\PCW.SYS
### Performance Counters for Windows Driver Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 Service registry key doesn't exist or
hidden.
[Drivers] :HKLM pdc=C:\WINDOWS\SYSTEM32\DRIVERS\PDC.SYS
### Power Dependency Coordinator Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM PEAUTH=C:\WINDOWS\SYSTEM32\DRIVERS\PEAUTH.SYS
### Protected Environment Authentication and Authorization Export Driver
Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0 Service
registry key doesn't exist or hidden.
[Drivers] :HKLM percsas2i=C:\WINDOWS\SYSTEM32\DRIVERS\PERCSAS2I.SYS
### MEGASAS RAID Controller Driver for Windows Avago Technologies MEGASAS RAID
Controller Driver for Windows 6.805.03.00 Service registry key doesn't exist or
hidden.
[Drivers] :HKLM percsas3i=C:\WINDOWS\SYSTEM32\DRIVERS\PERCSAS3I.SYS
### MEGASAS RAID Controller Driver for Windows Avago Technologies MEGASAS RAID
Controller Driver for Windows 6.603.06.00 Service registry key doesn't exist or
hidden.
[Drivers] :HKLM PptpMiniport=C:\WINDOWS\SYSTEM32\DRIVERS\RASPPTP.SYS
### Peer-to-Peer Tunneling Protocol Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*\SystemRoot\System32\drivers\raspptp.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM Processor=C:\WINDOWS\SYSTEM32\DRIVERS\PROCESSR.SYS
### Processor Device Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*\SystemRoot\System32\drivers\processr.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM Psched=C:\WINDOWS\SYSTEM32\DRIVERS\PACER.SYS
### QoS Packet Scheduler Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM QWAVEdrv=C:\WINDOWS\SYSTEM32\DRIVERS\QWAVEDRV.SYS
### Microsoft Quality Windows Audio Video Experience (qWave) Support Driver
Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0 !
$*\SystemRoot\system32\drivers\qwavedrv.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM RasAcd=C:\WINDOWS\SYSTEM32\DRIVERS\RASACD.SYS
### RAS Automatic Connection Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM RasAgileVpn=C:\WINDOWS\SYSTEM32\DRIVERS\AGILEVPN.SYS
### RAS Agile Vpn Miniport Call Manager Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*\SystemRoot\System32\drivers\AgileVpn.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM Rasl2tp=C:\WINDOWS\SYSTEM32\DRIVERS\RASL2TP.SYS
### RAS L2TP mini-port/call-manager driver Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 !$*\SystemRoot\System32\drivers\rasl2tp.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM RasPppoe=C:\WINDOWS\SYSTEM32\DRIVERS\RASPPPOE.SYS
### RAS PPPoE mini-port/call-manager driver Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.1198 !
$*\SystemRoot\System32\drivers\raspppoe.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM RasSstp=C:\WINDOWS\SYSTEM32\DRIVERS\RASSSTP.SYS
### RAS SSTP Miniport Call Manager Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*\SystemRoot\System32\drivers\rassstp.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM rdbss=C:\WINDOWS\SYSTEM32\DRIVERS\RDBSS.SYS
### Redirected Drive Buffering SubSystem Driver Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 Service registry key doesn't exist or
hidden.
[Drivers] :HKLM rdpbus=C:\WINDOWS\SYSTEM32\DRIVERS\RDPBUS.SYS
### Microsoft RDP Bus Device driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*\SystemRoot\System32\drivers\rdpbus.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM RDPDR=C:\WINDOWS\SYSTEM32\DRIVERS\RDPDR.SYS
### Microsoft RDP Device redirector Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM RdpVideoMiniport=C:\WINDOWS\SYSTEM32\DRIVERS\RDPVIDEOMINIPORT.SYS
### Microsoft RDP Video Miniport driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM rdyboost=C:\WINDOWS\SYSTEM32\DRIVERS\RDYBOOST.SYS
### ReadyBoost Driver Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM RFCOMM=C:\WINDOWS\SYSTEM32\DRIVERS\RFCOMM.SYS
### Bluetooth RFCOMM Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*\SystemRoot\System32\drivers\rfcomm.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM rspndr=C:\WINDOWS\SYSTEM32\DRIVERS\RSPNDR.SYS
### Link-Layer Topology Responder Driver for NDIS 6 Microsoft Corporation
Microsoft� Windows� Operating System 10.0.14393.0 Service registry key doesn't
exist or hidden.
[Drivers] :HKLM rt640x64=C:\WINDOWS\SYSTEM32\DRIVERS\RT640X64.SYS
### Realtek 8101E/8168/8169 NDIS 6.40 64-bit Driver Realtek
Realtek 8136/8168/8169 PCI/PCIe Adapters 10.001.0505.2015 !
$*\SystemRoot\System32\drivers\rt640x64.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM RtkBtFilter=C:\WINDOWS\SYSTEM32\DRIVERS\RTKBTFILTER.SYS
### Realtek Bluetooth Filter Driver Realtek Semiconductor Corporation Bluetooth
Software 1.3.871.3 !$*\SystemRoot\system32\DRIVERS\RtkBtfilter.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM RTSPER=C:\WINDOWS\SYSTEM32\DRIVERS\RTSPER.SYS
### RTS PCIE READER Driver Realsil Semiconductor Corporation Windows (R) Win 7
DDK driver 6.3.9600.17038 !$*\SystemRoot\system32\DRIVERS\RtsPer.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM s3cap=C:\WINDOWS\SYSTEM32\DRIVERS\VMS3CAP.SYS
### Microsoft S3 Emulated Device Cap Driver Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 !$*\SystemRoot\System32\drivers\vms3cap.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM sbp2port=C:\WINDOWS\SYSTEM32\DRIVERS\SBP2PORT.SYS
### SBP-2 Protocol Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM scfilter=C:\WINDOWS\SYSTEM32\DRIVERS\SCFILTER.SYS
### Microsoft Smart Card Reader Filter Driver Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 Service registry key doesn't exist or
hidden.
[Drivers] :HKLM scmbus=C:\WINDOWS\SYSTEM32\DRIVERS\SCMBUS.SYS
### Storage Class Memory Bus Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM scmdisk0101=C:\WINDOWS\SYSTEM32\DRIVERS\SCMDISK0101.SYS
### NVDIMM-N disk driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*\SystemRoot\System32\drivers\scmdisk0101.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM sdbus=C:\WINDOWS\SYSTEM32\DRIVERS\SDBUS.SYS
### SecureDigital Bus Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*\SystemRoot\System32\drivers\sdbus.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM sdstor=C:\WINDOWS\SYSTEM32\DRIVERS\SDSTOR.SYS
### SD Storage Class Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*\SystemRoot\System32\drivers\sdstor.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM SerCx=C:\WINDOWS\SYSTEM32\DRIVERS\SERCX.SYS
### Serial Class Extension Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM SerCx2=C:\WINDOWS\SYSTEM32\DRIVERS\SERCX2.SYS
### Serial Class Extension V2 Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM Serenum=C:\WINDOWS\SYSTEM32\DRIVERS\SERENUM.SYS
### Serial Port Enumerator Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*\SystemRoot\System32\drivers\serenum.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM Serial=C:\WINDOWS\SYSTEM32\DRIVERS\SERIAL.SYS
### Serial Device Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*\SystemRoot\System32\drivers\serial.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM sermouse=C:\WINDOWS\SYSTEM32\DRIVERS\SERMOUSE.SYS
### Serial Mouse Filter Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*\SystemRoot\System32\drivers\sermouse.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM sfloppy=C:\WINDOWS\SYSTEM32\DRIVERS\SFLOPPY.SYS
### SCSI Floppy Driver Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*\SystemRoot\System32\drivers\sfloppy.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM SiSRaid2=C:\WINDOWS\SYSTEM32\DRIVERS\SISRAID2.SYS
### SiS RAID Stor Miniport Driver Silicon Integrated Systems Corp. Microsoft�
Windows� Operating System 2.60.01 Service registry key doesn't exist or hidden.
[Drivers] :HKLM SiSRaid4=C:\WINDOWS\SYSTEM32\DRIVERS\SISRAID4.SYS
### SiS AHCI Stor-Miniport Driver Silicon Integrated Systems Microsoft� Windows�
Operating System 6.1.6918.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM SmbDrvI=C:\WINDOWS\SYSTEM32\DRIVERS\SMB_DRIVER_INTEL.SYS
### Synaptics SMBus Driver Synaptics Incorporated Synaptics SMBus Driver 19.0.9.4
27May15 !$*\SystemRoot\system32\DRIVERS\Smb_driver_Intel.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM spaceport=C:\WINDOWS\SYSTEM32\DRIVERS\SPACEPORT.SYS
### Storage Spaces Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.206 Service registry key doesn't exist or hidden.
[Drivers] :HKLM SpbCx=C:\WINDOWS\SYSTEM32\DRIVERS\SPBCX.SYS
### SPB Class Extension Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM srv=C:\WINDOWS\SYSTEM32\DRIVERS\SRV.SYS
### Server driver Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM srv2=C:\WINDOWS\SYSTEM32\DRIVERS\SRV2.SYS
### Smb 2.0 Server driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM srvnet=C:\WINDOWS\SYSTEM32\DRIVERS\SRVNET.SYS
### Server Network driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.1715 Service registry key doesn't exist or hidden.
[Drivers] :HKLM ssudmdm=C:\WINDOWS\SYSTEM32\DRIVERS\SSUDMDM.SYS
### SAMSUNG Android Modem Device Driver Samsung Electronics Co., Ltd. SAMSUNG
Android Modem Device Driver 2.12.5.0 !$*\SystemRoot\system32\DRIVERS\ssudmdm.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM ssudserd=C:\WINDOWS\SYSTEM32\DRIVERS\SSUDSERD.SYS
### SAMSUNG USB Mobile Logging Device Driver (MSS Ver.3) DEVGURU Co., LTD.
(www.devguru.co.kr) SAMSUNG USB Mobile Logging Device Driver (MSS Ver.3) 2.11.7.0 !
$*\SystemRoot\system32\DRIVERS\ssudserd.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM stexstor=C:\WINDOWS\SYSTEM32\DRIVERS\STEXSTOR.SYS
### Promise SuperTrak EX Series Driver for Windows x64 Promise Technology, Inc.
Promise� SuperTrak EX Series 5.1.0000.10 Service registry key doesn't exist or
hidden.
[Drivers] :HKLM storahci=C:\WINDOWS\SYSTEM32\DRIVERS\STORAHCI.SYS
### MS AHCI Storport Miniport Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.953 Service registry key doesn't exist or hidden.
[Drivers] :HKLM storflt=C:\WINDOWS\SYSTEM32\DRIVERS\VMSTORFL.SYS
### Virtual Storage Filter Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM stornvme=C:\WINDOWS\SYSTEM32\DRIVERS\STORNVME.SYS
### Microsoft NVM Express Storport Miniport Driver Microsoft Corporation
Microsoft� Windows� Operating System 10.0.14393.1532 Service registry key doesn't
exist or hidden.
[Drivers] :HKLM storqosflt=C:\WINDOWS\SYSTEM32\DRIVERS\STORQOSFLT.SYS
### Storage QoS Filter Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM storufs=C:\WINDOWS\SYSTEM32\DRIVERS\STORUFS.SYS
### MS UFS Storport Miniport Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM storvsc=C:\WINDOWS\SYSTEM32\DRIVERS\STORVSC.SYS
### Storage VSC Driver Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM swenum=C:\WINDOWS\SYSTEM32\DRIVERS\SWENUM.SYS
### Plug and Play Software Device Enumerator Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 !$*\SystemRoot\System32\drivers\swenum.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM Synth3dVsc=C:\WINDOWS\SYSTEM32\DRIVERS\SYNTH3DVSC.SYS
### Microsoft RemoteFX Synth3D Video VSC Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 !
$*\SystemRoot\System32\drivers\Synth3dVsc.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM tap0901=C:\WINDOWS\SYSTEM32\DRIVERS\TAP0901.SYS
### TAP-Windows Virtual Network Driver The OpenVPN Project TAP-Windows Virtual
Network Driver 9.9.2 9/9 !$*\SystemRoot\System32\drivers\tap0901.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM Tcpip=C:\WINDOWS\SYSTEM32\DRIVERS\TCPIP.SYS
### TCP/IP Driver Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM Tcpip6=C:\WINDOWS\SYSTEM32\DRIVERS\TCPIP.SYS
### TCP/IP Driver Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM tcpipreg=C:\WINDOWS\SYSTEM32\DRIVERS\TCPIPREG.SYS
### TCP/IP Registry Compatibility Driver Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.1480 Service registry key doesn't exist or
hidden.
[Drivers] :HKLM tdx=C:\WINDOWS\SYSTEM32\DRIVERS\TDX.SYS
### TDI Translation Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.1613 !$*\SystemRoot\system32\DRIVERS\tdx.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM terminpt=C:\WINDOWS\SYSTEM32\DRIVERS\TERMINPT.SYS
### Terminal Server Input Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*\SystemRoot\System32\drivers\terminpt.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM TPM=C:\WINDOWS\SYSTEM32\DRIVERS\TPM.SYS
### TPM Device Driver Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*\SystemRoot\System32\drivers\tpm.sys Service registry key doesn't
exist or hidden.
[Drivers] :HKLM tsusbflt=C:\WINDOWS\SYSTEM32\DRIVERS\TSUSBFLT.SYS
### Remote Desktop USB Hub Filter Driver Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 Service registry key doesn't exist or
hidden.
[Drivers] :HKLM TsUsbGD=C:\WINDOWS\SYSTEM32\DRIVERS\TSUSBGD.SYS
### Remote Desktop Generic USB Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*\SystemRoot\System32\drivers\TsUsbGD.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM tsusbhub=C:\WINDOWS\SYSTEM32\DRIVERS\TSUSBHUB.SYS
### Remote Desktop USB Hub Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*\SystemRoot\System32\drivers\tsusbhub.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM tunnel=C:\WINDOWS\SYSTEM32\DRIVERS\TUNNEL.SYS
### Microsoft Tunnel Interface Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*\SystemRoot\System32\drivers\tunnel.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM UASPStor=C:\WINDOWS\SYSTEM32\DRIVERS\UASPSTOR.SYS
### Microsoft Uasp Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*\SystemRoot\System32\drivers\uaspstor.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM UcmCx0101=C:\WINDOWS\SYSTEM32\DRIVERS\UCMCX.SYS
### USB Connector Manager KMDF Class Extension Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 Service registry key doesn't exist or
hidden.
[Drivers] :HKLM UcmTcpciCx0101=C:\WINDOWS\SYSTEM32\DRIVERS\UCMTCPCICX.SYS
### UCM-TCPCI KMDF Class Extension Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM UcmUcsi=C:\WINDOWS\SYSTEM32\DRIVERS\UCMUCSI.SYS
### USB Connector Manager UCSI Client Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*\SystemRoot\System32\drivers\UcmUcsi.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM Ucx01000=C:\WINDOWS\SYSTEM32\DRIVERS\UCX01000.SYS
### USB Controller Extension Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM UdeCx=C:\WINDOWS\SYSTEM32\DRIVERS\UDECX.SYS
### "udecx.DRIVER" Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM udfs=C:\WINDOWS\SYSTEM32\DRIVERS\UDFS.SYS
### UDF File System Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM UEFI=C:\WINDOWS\SYSTEM32\DRIVERS\UEFI.SYS
### UEFI Driver for NT Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*\SystemRoot\System32\drivers\UEFI.sys Service registry key doesn't
exist or hidden.
[Drivers] :HKLM UevAgentDriver=C:\WINDOWS\SYSTEM32\DRIVERS\UEVAGENTDRIVER.SYS
### Microsoft User Experience Virtualization Agent Driver Microsoft Corporation
Microsoft� Windows� Operating System 10.0.14393.0 !
$*\SystemRoot\system32\drivers\UevAgentDriver.sys Service registry key doesn't
exist or hidden.
[Drivers] :HKLM Ufx01000=C:\WINDOWS\SYSTEM32\DRIVERS\UFX01000.SYS
### USB Function Driver Class Extension Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM UfxChipidea=C:\WINDOWS\SYSTEM32\DRIVERS\UFXCHIPIDEA.SYS
### UFX Chipidea Client Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*\SystemRoot\System32\drivers\UfxChipidea.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM ufxsynopsys=C:\WINDOWS\SYSTEM32\DRIVERS\UFXSYNOPSYS.SYS
### UFX Synopsys Client Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*\SystemRoot\System32\drivers\ufxsynopsys.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM umbus=C:\WINDOWS\SYSTEM32\DRIVERS\UMBUS.SYS
### User-Mode Bus Enumerator Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*\SystemRoot\System32\drivers\umbus.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM UmPass=C:\WINDOWS\SYSTEM32\DRIVERS\UMPASS.SYS
### Generic pass-through driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*\SystemRoot\System32\drivers\umpass.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM UrsChipidea=C:\WINDOWS\SYSTEM32\DRIVERS\URSCHIPIDEA.SYS
### USB Role-Switch Driver for Chipidea Core Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 !
$*\SystemRoot\System32\drivers\urschipidea.sys Service registry key doesn't exist
or hidden.
[Drivers] :HKLM UrsCx01000=C:\WINDOWS\SYSTEM32\DRIVERS\URSCX01000.SYS
### USB Role-Switch Class Extension Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM UrsSynopsys=C:\WINDOWS\SYSTEM32\DRIVERS\URSSYNOPSYS.SYS
### USB Role-Switch Driver for Synopsys Core Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 !
$*\SystemRoot\System32\drivers\urssynopsys.sys Service registry key doesn't exist
or hidden.
[Drivers] :HKLM USBAAPL64=C:\WINDOWS\SYSTEM32\DRIVERS\USBAAPL64.SYS
### Apple Mobile Device USB Driver Apple, Inc. Apple Mobile Device USB Driver
1.67.0.0 !$*\SystemRoot\System32\Drivers\usbaapl64.sys Service registry key doesn't
exist or hidden.
[Drivers] :HKLM usbccgp=C:\WINDOWS\SYSTEM32\DRIVERS\USBCCGP.SYS
### USB Common Class Generic Parent Driver Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 !$*\SystemRoot\System32\drivers\usbccgp.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM usbcir=C:\WINDOWS\SYSTEM32\DRIVERS\USBCIR.SYS
### USB Consumer IR Driver for eHome Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*\SystemRoot\System32\drivers\usbcir.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM usbehci=C:\WINDOWS\SYSTEM32\DRIVERS\USBEHCI.SYS
### EHCI eUSB Miniport Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*\SystemRoot\System32\drivers\usbehci.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM usbhub=C:\WINDOWS\SYSTEM32\DRIVERS\USBHUB.SYS
### Default Hub Driver for USB Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*\SystemRoot\System32\drivers\usbhub.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM USBHUB3=C:\WINDOWS\SYSTEM32\DRIVERS\USBHUB3.SYS
### USB3 HUB Driver Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*\SystemRoot\System32\drivers\UsbHub3.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM usbohci=C:\WINDOWS\SYSTEM32\DRIVERS\USBOHCI.SYS
### OHCI USB Miniport Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*\SystemRoot\System32\drivers\usbohci.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM usbprint=C:\WINDOWS\SYSTEM32\DRIVERS\USBPRINT.SYS
### USB Printer driver Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*\SystemRoot\System32\drivers\usbprint.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM usbscan=C:\WINDOWS\SYSTEM32\DRIVERS\USBSCAN.SYS
### USB Scanner Driver Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*\SystemRoot\system32\DRIVERS\usbscan.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM usbser=C:\WINDOWS\SYSTEM32\DRIVERS\USBSER.SYS
### USB Serial Driver Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*\SystemRoot\System32\drivers\usbser.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM USBSTOR=C:\WINDOWS\SYSTEM32\DRIVERS\USBSTOR.SYS
### USB Mass Storage Class Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*\SystemRoot\System32\drivers\USBSTOR.SYS Service
registry key doesn't exist or hidden.
[Drivers] :HKLM usbuhci=C:\WINDOWS\SYSTEM32\DRIVERS\USBUHCI.SYS
### UHCI USB Miniport Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*\SystemRoot\System32\drivers\usbuhci.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM usbvideo=C:\WINDOWS\SYSTEM32\DRIVERS\USBVIDEO.SYS
### USB Video Class Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*\SystemRoot\System32\Drivers\usbvideo.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM USBXHCI=C:\WINDOWS\SYSTEM32\DRIVERS\USBXHCI.SYS
### USB XHCI Driver Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*\SystemRoot\System32\drivers\USBXHCI.SYS Service registry key
doesn't exist or hidden.
[Drivers] :HKLM vdrvroot=C:\WINDOWS\SYSTEM32\DRIVERS\VDRVROOT.SYS
### Virtual Drive Root Enumerator Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM VerifierExt=C:\WINDOWS\SYSTEM32\DRIVERS\VERIFIEREXT.SYS
### Driver Verifier Extension Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM vhdmp=C:\WINDOWS\SYSTEM32\DRIVERS\VHDMP.SYS
### VHD Miniport Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*\SystemRoot\System32\drivers\vhdmp.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM vhf=C:\WINDOWS\SYSTEM32\DRIVERS\VHF.SYS
### Virtual HID Framework (VHF) Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*\SystemRoot\System32\drivers\vhf.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM vmbus=C:\WINDOWS\SYSTEM32\DRIVERS\VMBUS.SYS
### Microsoft Hyper-V Virtual Machine Bus Child Driver Microsoft Corporation
Microsoft� Windows� Operating System 10.0.14393.0 Service registry key doesn't
exist or hidden.
[Drivers] :HKLM VMBusHID=C:\WINDOWS\SYSTEM32\DRIVERS\VMBUSHID.SYS
### Microsoft VMBus HID Miniport Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*\SystemRoot\System32\drivers\VMBusHID.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM vmgid=C:\WINDOWS\SYSTEM32\DRIVERS\VMGID.SYS
### Virtual Machine Guest Infrastructure Driver Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 !$*\SystemRoot\System32\drivers\vmgid.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM volmgr=C:\WINDOWS\SYSTEM32\DRIVERS\VOLMGR.SYS
### Volume Manager Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM volmgrx=C:\WINDOWS\SYSTEM32\DRIVERS\VOLMGRX.SYS
### Volume Manager Extension Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM volsnap=C:\WINDOWS\SYSTEM32\DRIVERS\VOLSNAP.SYS
### Volume Shadow Copy driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM volume=C:\WINDOWS\SYSTEM32\DRIVERS\VOLUME.SYS
### Volume driver Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM vpci=C:\WINDOWS\SYSTEM32\DRIVERS\VPCI.SYS
### Virtual PCI Bus Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.206 !$*\SystemRoot\System32\drivers\vpci.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM vsmraid=C:\WINDOWS\SYSTEM32\DRIVERS\VSMRAID.SYS
### VIA RAID DRIVER FOR AMD-X86-64 VIA Technologies Inc.,Ltd VIA RAID driver
7.0.9600,6352 Service registry key doesn't exist or hidden.
[Drivers] :HKLM VSTXRAID=C:\WINDOWS\SYSTEM32\DRIVERS\VSTXRAID.SYS
### VIA StorX RAID Controller Driver VIA Corporation VIA StorX RAID Controller
Driver 8.0.9200.8110 Service registry key doesn't exist or hidden.
[Drivers] :HKLM vwifibus=C:\WINDOWS\SYSTEM32\DRIVERS\VWIFIBUS.SYS
### Virtual Wireless Bus Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*\SystemRoot\System32\drivers\vwifibus.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM vwififlt=C:\WINDOWS\SYSTEM32\DRIVERS\VWIFIFLT.SYS
### Virtual WiFi Filter Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM vwifimp=C:\WINDOWS\SYSTEM32\DRIVERS\VWIFIMP.SYS
### Virtual WiFi Miniport Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.1198 !$*\SystemRoot\System32\drivers\vwifimp.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM WacomPen=C:\WINDOWS\SYSTEM32\DRIVERS\WACOMPEN.SYS
### Wacom Serial Pen Tablet HID Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*\SystemRoot\System32\drivers\wacompen.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM wanarp=C:\WINDOWS\SYSTEM32\DRIVERS\WANARP.SYS
### MS Remote Access and Routing ARP Driver Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 Service registry key doesn't exist or
hidden.
[Drivers] :HKLM wanarpv6=C:\WINDOWS\SYSTEM32\DRIVERS\WANARP.SYS
### MS Remote Access and Routing ARP Driver Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 Service registry key doesn't exist or
hidden.
[Drivers] :HKLM wcifs=C:\WINDOWS\SYSTEM32\DRIVERS\WCIFS.SYS
### Windows Container Isolation FS Filter Driver Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.206 !$*\SystemRoot\system32\drivers\wcifs.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM wcnfs=C:\WINDOWS\SYSTEM32\DRIVERS\WCNFS.SYS
### Windows Container Name Virtualization FS Filter Driver Microsoft Corporation
Microsoft� Windows� Operating System 10.0.14393.1532 !
$*\SystemRoot\system32\drivers\wcnfs.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM WdBoot=C:\WINDOWS\SYSTEM32\DRIVERS\WDBOOT.SYS
### Microsoft antimalware boot driver Microsoft Corporation Microsoft� Windows�
Operating System 4.10.14393.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM Wdf01000=C:\WINDOWS\SYSTEM32\DRIVERS\WDF01000.SYS
### Kernel Mode Driver Framework Runtime Microsoft Corporation Microsoft�
Windows� Operating System 1.19.14393.0 Service registry key doesn't exist or
hidden.
[Drivers] :HKLM WdFilter=C:\WINDOWS\SYSTEM32\DRIVERS\WDFILTER.SYS
### Microsoft antimalware file system filter driver Microsoft Corporation
Microsoft� Windows� Operating System 4.10.14393.0 Service registry key doesn't
exist or hidden.
[Drivers] :HKLM wdiwifi=C:\WINDOWS\SYSTEM32\DRIVERS\WDIWIFI.SYS
### WDI Driver Framework Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.1770 Service registry key doesn't exist or hidden.
[Drivers] :HKLM WdNisDrv=C:\WINDOWS\SYSTEM32\DRIVERS\WDNISDRV.SYS
### Microsoft Network Realtime Inspection Driver Microsoft Corporation Microsoft�
Windows� Operating System 4.10.14393.0 Service registry key doesn't exist or
hidden.
[Drivers] :HKLM WFPLWFS=C:\WINDOWS\SYSTEM32\DRIVERS\WFPLWFS.SYS
### WFP NDIS 6.30 Lightweight Filter Driver Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 Service registry key doesn't exist or
hidden.
[Drivers] :HKLM WIMMount=C:\WINDOWS\SYSTEM32\DRIVERS\WIMMOUNT.SYS
### Wim file system Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM WindowsTrustedRT=C:\WINDOWS\SYSTEM32\DRIVERS\WINDOWSTRUSTEDRT.SYS
### Windows Trusted Runtime Interface Driver Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 Service registry key doesn't exist or
hidden.
[Drivers] :HKLM
WindowsTrustedRTProxy=C:\WINDOWS\SYSTEM32\DRIVERS\WINDOWSTRUSTEDRTPROXY.SYS
### Windows Trusted Runtime Service Proxy Driver Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 Service registry key doesn't exist or
hidden.
[Drivers] :HKLM WinMad=C:\WINDOWS\SYSTEM32\DRIVERS\WINMAD.SYS
### Kernel WinMad Mellanox OpenFabrics Windows 6.3.9600.16384 !
$*\SystemRoot\System32\drivers\winmad.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM WINUSB=C:\WINDOWS\SYSTEM32\DRIVERS\WINUSB.SYS
### Windows WinUSB Class Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*\SystemRoot\System32\drivers\WinUSB.SYS Service
registry key doesn't exist or hidden.
[Drivers] :HKLM WinVerbs=C:\WINDOWS\SYSTEM32\DRIVERS\WINVERBS.SYS
### Kernel WinVerbs Mellanox OpenFabrics Windows 6.3.9600.16384 !
$*\SystemRoot\System32\drivers\winverbs.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM WmiAcpi=C:\WINDOWS\SYSTEM32\DRIVERS\WMIACPI.SYS
### Windows Management Interface for ACPI Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 !$*\SystemRoot\System32\drivers\wmiacpi.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM WpdUpFltr=C:\WINDOWS\SYSTEM32\DRIVERS\WPDUPFLTR.SYS
### Windows Portable Device Upper Class Filter Driver Microsoft Corporation
Microsoft� Windows� Operating System 10.0.14393.0 Service registry key doesn't
exist or hidden.
[Drivers] :HKLM ws2ifsl=C:\WINDOWS\SYSTEM32\DRIVERS\WS2IFSL.SYS
### Winsock2 IFS Layer Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*\SystemRoot\system32\drivers\ws2ifsl.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM WudfPf=C:\WINDOWS\SYSTEM32\DRIVERS\WUDFPF.SYS
### Windows Driver Foundation - User-mode Driver Framework Platform Driver
Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0 Service
registry key doesn't exist or hidden.
[Drivers] :HKLM WUDFRd=C:\WINDOWS\SYSTEM32\DRIVERS\WUDFRD.SYS
### Windows Driver Foundation - User-mode Driver Framework Reflector Microsoft
Corporation Microsoft� Windows� Operating System 10.0.14393.0 !
$*\SystemRoot\System32\drivers\WUDFRd.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM WUDFWpdFs=C:\WINDOWS\SYSTEM32\DRIVERS\WUDFRD.SYS
### Windows Driver Foundation - User-mode Driver Framework Reflector Microsoft
Corporation Microsoft� Windows� Operating System 10.0.14393.0 !
$*\SystemRoot\system32\DRIVERS\WUDFRd.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM WUDFWpdMtp=C:\WINDOWS\SYSTEM32\DRIVERS\WUDFRD.SYS
### Windows Driver Foundation - User-mode Driver Framework Reflector Microsoft
Corporation Microsoft� Windows� Operating System 10.0.14393.0 !
$*\SystemRoot\system32\DRIVERS\WUDFRd.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM xboxgip=C:\WINDOWS\SYSTEM32\DRIVERS\XBOXGIP.SYS
### Game Input Protocol Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.953 !$*\SystemRoot\System32\drivers\xboxgip.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM xinputhid=C:\WINDOWS\SYSTEM32\DRIVERS\XINPUTHID.SYS
### XINPUT filter driver for HID Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.103 !$*\SystemRoot\System32\drivers\xinputhid.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM ZTEusbmdm6k=C:\WINDOWS\SYSTEM32\DRIVERS\ZTEUSBMDM6K.SYS
### USB Modem/Serial Device Driver ZTE Incorporated ZTE USB Modem/Serial Device
Driver 1.2059.0.7 !$*\SystemRoot\system32\DRIVERS\ZTEusbmdm6k.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM ZTEusbnmea=C:\WINDOWS\SYSTEM32\DRIVERS\ZTEUSBNMEA.SYS
### USB Modem/Serial Device Driver ZTE Incorporated ZTE USB Modem/Serial Device
Driver 1.2059.0.7 !$*\SystemRoot\system32\DRIVERS\ZTEusbnmea.sys Service registry
key doesn't exist or hidden.
[Codecs] :HKLM midimapper=C:\WINDOWS\SYSTEM32\MIDIMAP.DLL
### Microsoft MIDI Mapper Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*midimap.dll
[Codecs] :HKLM msacm.imaadpcm=C:\WINDOWS\SYSTEM32\IMAADP32.ACM
### IMA ADPCM CODEC for MSACM Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*imaadp32.acm
[Codecs] :HKLM msacm.l3acm=C:\WINDOWS\SYSWOW64\L3CODECA.ACM
### MPEG Layer-3 Audio Codec for MSACM Fraunhofer Institut Integrierte
Schaltungen IIS MPEG Layer-3 Audio Codec for MSACM 1, 0, 0, 0
[Codecs] :HKLM msacm.msadpcm=C:\WINDOWS\SYSTEM32\MSADP32.ACM
### Microsoft ADPCM CODEC for MSACM Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*msadp32.acm
[Codecs] :HKLM msacm.msg711=C:\WINDOWS\SYSTEM32\MSG711.ACM
### Microsoft CCITT G.711 (A-Law and u-Law) CODEC for MSACM Microsoft Corporation
Microsoft� Windows� Operating System 10.0.14393.0 !$*msg711.acm
[Codecs] :HKLM msacm.msgsm610=C:\WINDOWS\SYSTEM32\MSGSM32.ACM
### Microsoft GSM 6.10 Audio CODEC for MSACM Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0 !$*msgsm32.acm
[Codecs] :HKLM vidc.cvid=C:\WINDOWS\Syswow64\ICCVID.DLL
### Cinepak� Codec Radius Inc. Cinepak for Windows 32 1.10.0.0 !$*iccvid.dll
[Codecs] :HKLM vidc.i420=C:\WINDOWS\SYSTEM32\IYUV_32.DLL
### Intel Indeo(R) Video YUV Codec Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*iyuv_32.dll
[Codecs] :HKLM vidc.iyuv=C:\WINDOWS\SYSTEM32\IYUV_32.DLL
### Intel Indeo(R) Video YUV Codec Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*iyuv_32.dll
[Codecs] :HKLM vidc.mrle=C:\WINDOWS\SYSTEM32\MSRLE32.DLL
### Microsoft RLE Compressor Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*msrle32.dll
[Codecs] :HKLM vidc.msvc=C:\WINDOWS\SYSTEM32\MSVIDC32.DLL
### Microsoft Video 1 Compressor Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*msvidc32.dll
[Codecs] :HKLM vidc.uyvy=C:\WINDOWS\SYSTEM32\MSYUV.DLL
### Microsoft UYVY Video Decompressor Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*msyuv.dll
[Codecs] :HKLM vidc.yuy2=C:\WINDOWS\SYSTEM32\MSYUV.DLL
### Microsoft UYVY Video Decompressor Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*msyuv.dll
[Codecs] :HKLM vidc.yvu9=C:\WINDOWS\SYSTEM32\TSBYUV.DLL
### Toshiba Video Codec Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*tsbyuv.dll
[Codecs] :HKLM vidc.yvyu=C:\WINDOWS\SYSTEM32\MSYUV.DLL
### Microsoft UYVY Video Decompressor Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*msyuv.dll
[Codecs] :HKLM wavemapper=C:\WINDOWS\SYSTEM32\MSACM32.DRV
### Microsoft Sound Mapper Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*msacm32.drv
[Codecs] :HKLM wave1=C:\WINDOWS\SYSTEM32\WDMAUD.DRV
### Winmm audio system driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*wdmaud.drv
[Codecs] :HKLM midi1=C:\WINDOWS\SYSTEM32\WDMAUD.DRV
### Winmm audio system driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*wdmaud.drv
[Codecs] :HKLM mixer1=C:\WINDOWS\SYSTEM32\WDMAUD.DRV
### Winmm audio system driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*wdmaud.drv
[Codecs] :HKLM aux1=C:\WINDOWS\SYSTEM32\WDMAUD.DRV
### Winmm audio system driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*wdmaud.drv
[Codecs] :HKLM vidc.XVID=xvidvfw.dll
### File is missing.
[Codecs] :HKLM VIDC.VP80=vp8vfw.dll
### File is missing.
[Codecs] :HKLM wave=C:\WINDOWS\SYSTEM32\WDMAUD.DRV
### Winmm audio system driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*wdmaud.drv
[Codecs] :HKLM midi=C:\WINDOWS\SYSTEM32\WDMAUD.DRV
### Winmm audio system driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*wdmaud.drv
[Codecs] :HKLM mixer=C:\WINDOWS\SYSTEM32\WDMAUD.DRV
### Winmm audio system driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*wdmaud.drv
[Codecs] :HKLM aux=C:\WINDOWS\SYSTEM32\WDMAUD.DRV
### Winmm audio system driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*wdmaud.drv
[DCOM Components] :HKLM {F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}=""
[DCOM Components] :HKLM {5839FCA9-774D-42A1-ACDA-
D6A79037F57F}=C:\WINDOWS\SYSTEM32\WBEM\FASTPROX.DLL
### WMI Custom Marshaller Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0
[DCOM Components] :HKLM {42AEDC87-2188-41FD-B9A3-
0C966FEABEC1}=C:\WINDOWS\SYSTEM32\WINDOWS.STORAGE.DLL
### Microsoft WinRT Storage API Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0
[DCOM User Components] :HKCU {F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}=""
[DCOM User Components] :HKCU {FBEB8A05-BEEE-4442-804E-409D6C4515E9}=""
[DCOM User Components] :HKCU {42AEDC87-2188-41FD-B9A3-0C966FEABEC1}=""
[Auto Start Apps]
[Registry Run] :HKCU
OneDrive=C:\USERS\USER\APPDATA\LOCAL\MICROSOFT\ONEDRIVE\ONEDRIVE.EXE
### Microsoft OneDrive Microsoft Corporation Microsoft OneDrive 17.3.6998.0830 !
$*"C:\Users\USER\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
[Registry Run] :HKCU BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}=C:\PROGRAM
FILES (X86)\COMMON FILES\AHEAD\LIB\NMBGMONITOR.EXE
### Nero Home Nero AG Nero Home 2,0,16,0 !$*"C:\Program Files (x86)\Common
Files\Ahead\Lib\NMBgMonitor.exe"
[Registry Run] :HKCU IDMan=C:\PROGRAM FILES (X86)\INTERNET DOWNLOAD
MANAGER\IDMAN.EXE
### Internet Download Manager (IDM) Tonec Inc. Internet Download Manager (IDM) 6,
28, 15, 3 !$*C:\Program Files (x86)\Internet Download Manager\IDMan.exe /onboot
[Registry Run] :HKCU
ShellExperienceHost=C:\USERS\USER\APPDATA\LOCAL\TEMP\SYSTEM32\LOGS\SHELLEXPERIENCEH
OST.EXE
### Application Frame Host Application Frame Host Application Frame Host 1.0.0.0
[Registry Run] :HKCU
7229912=C:\USERS\USER\APPDATA\ROAMING\B40I5J0RX13\DKLTX5ANUBP.EXE
### eCadeauHedi Setup Tounsi
eCadeauHedi 6.9
!$*"C:\Users\USER\AppData\Roaming\b40i5j0rx13\dkltx5anubp.exe" /VERYSILENT
[Registry Run] :HKCU T98U10MLHQYVN13=C:\PROGRAM FILES\M3ULPE53ML\M3ULPE53M.EXE
### 5MTOVYFS 5MTO 5MTOVY 1.4.8.0 !$*"C:\Program Files\M3ULPE53ML\M3ULPE53M.exe"
[Registry Run] :HKCU
7186694=C:\USERS\USER\APPDATA\ROAMING\W43JJDYZMS2\2BBFEQRERM1.EXE
### eCadeauHedi Setup Tounsi
eCadeauHedi 6.9
!$*"C:\Users\USER\AppData\Roaming\w43jjdyzms2\2bbfeqrerm1.exe" /VERYSILENT
[Registry Run] :HKCU CWBRGSATHDUN0OG=C:\PROGRAM FILES\WLFJ5AXNNW\WLFJ5AXNN.EXE
### 5MTOVYFS 5MTO 5MTOVY 1.4.8.0 !$*"C:\Program Files\WLFJ5AXNNW\WLFJ5AXNN.exe"
[Registry Run] :HKCU TEUK3X4SPNNMOFC="C:\Program Files
(x86)\SDownloader\QFIIN.exe"
### !$*"C:\Program Files (x86)\SDownloader\QFIIN.exe" File is missing.
[Registry Run] :HKCU HRVITLU7X0O59A5=C:\PROGRAM FILES\OPB8PQV6BW\OPB8PQV6B.EXE
### 65CDWHMAU 6 65CDWH 1.2.5.7 !$*"C:\Program Files\OPB8PQV6BW\OPB8PQV6B.exe"
[Registry Run] :HKCU WH2QO1VVQRU2QGA=C:\PROGRAM FILES\P12NB3RVK8\0PFCRCRK1.EXE
### O0K4 O0K4@99G 6.5.8.5 !$*"C:\Program Files\P12NB3RVK8\0PFCRCRK1.exe"
[Registry Run] :HKCU
7059963=C:\USERS\USER\APPDATA\ROAMING\UGIOAUUJ2GG\SSXTK4J2TIJ.EXE
### eCadeauHedi Setup Tounsi
eCadeauHedi 6.9
!$*"C:\Users\USER\AppData\Roaming\ugioauuj2gg\ssxtk4j2tij.exe" /VERYSILENT
[Registry Run] :HKLM WinampAgent=C:\PROGRAM FILES (X86)\WINAMP\WINAMPA.EXE
### Winamp Agent Nullsoft, Inc. Winamp Agent 5.5.8.2985 !$*"C:\Program Files
(x86)\Winamp\winampa.exe"
[Registry Run] :HKLM Adobe ARM=C:\PROGRAM FILES (X86)\COMMON
FILES\ADOBE\ARM\1.0\ADOBEARM.EXE
### Adobe Reader and Acrobat Manager Adobe Systems Incorporated Adobe Reader and
Acrobat Manager 1.5.5.0 !$*"C:\Program Files (x86)\Common
Files\Adobe\ARM\1.0\AdobeARM.exe"
[Registry Run] :HKLM YouCam Mirage=C:\PROGRAM FILES
(X86)\CYBERLINK\YOUCAM\YCMMIRAGE.EXE
### YouCam Mirage CyberLink YCMMirag Application 1.0.0.629 !$*"C:\Program Files
(x86)\CyberLink\YouCam\YCMMirage.exe"
[Registry Run] :HKLM YouCam Tray=C:\PROGRAM FILES
(X86)\CYBERLINK\YOUCAM\YOUCAMTRAY.EXE
### CyberLink YouCam Tray CyberLink Corp. CyberLink YouCam Tray 4.0.0.0820 !
$*"C:\Program Files (x86)\CyberLink\YouCam\YouCamTray.exe" /s
[Registry Run] :HKLM booster="C:\Users\USER\AppData\Local\PCBooster\booster.exe"
-o pool.supportxmr.com:3333 -u
49YfoE2xWHG1vywX2xTV8XZzBzB1E2QHEF9GtzPKSPRdK5TEkxXGRxVdAq8LwbA2Pz7jNQ9gYBxeFPHcqii
qaGJM2QyW64C -p x -k -o pool.minemonero.pro:3333 -u
49YfoE2xWHG1vywX2xTV8XZzBzB1E2QHEF9GtzPKSPRdK5TEkxXGRxVdAq8LwbA2Pz7jNQ9gYBxeFPHcqii
qaGJM2QyW64C -p WORKER-backup -k --retries=2 --retry-pause=1 --background --donate-
level=1
### !$*"C:\Users\USER\AppData\Local\PCBooster\booster.exe" -o
pool.supportxmr.com:3333 -u
49YfoE2xWHG1vywX2xTV8XZzBzB1E2QHEF9GtzPKSPRdK5TEkxXGRxVdAq8LwbA2Pz7jNQ9gYBxeFPHcqii
qaGJM2QyW64C -p x -k -o pool.minemonero.pro:3333 -u
49YfoE2xWHG1vywX2xTV8XZzBzB1E2QHEF9GtzPKSPRdK5TEkxXGRxVdAq8LwbA2Pz7jNQ9gYBxeFPHcqii
qaGJM2QyW64C -p WORKER-backup -k --retries=2 --retry-pause=1 --background --donate-
level=1 File is missing.
[Registry Run(x64)] :HKLM WindowsDefender=C:\PROGRAM FILES\WINDOWS
DEFENDER\MSASCUIL.EXE
### Windows Defender notification icon Microsoft Corporation Microsoft� Windows�
Operating System 4.10.14393.1198 !$*"%ProgramFiles%\Windows Defender\MSASCuiL.exe"
[Registry Run(x64)] :HKLM
DptfPolicyLpmServiceHelper=C:\WINDOWS\SYSTEM32\DPTFPOLICYLPMSERVICEHELPER.EXE
### Intel(R) Dynamic Platform and Thermal Framework LPM Policy Service Helper
Intel Corporation Intel(R) Dynamic Platform and Thermal Framework 7.1.0.2106
[Registry Run(x64)] :HKLM NvBackend=C:\PROGRAM FILES (X86)\NVIDIA
CORPORATION\UPDATE CORE\NVBACKEND.EXE
### NVIDIA Update Backend NVIDIA Corporation NVIDIA Update 10.4.0.6 !
$*"C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
[Registry Run(x64)] :HKLM Plumbytes Anti-Malware=C:\PROGRAM FILES\PLUMBYTES
SOFTWARE\PLUMBYTES ANTI-MALWARE\PLUMBYTES.EXE
### Anti-Malware Anti-Malware Anti-Malware 1.0.0.0 !$*"C:\Program Files\Plumbytes
Software\Plumbytes Anti-Malware\Plumbytes.exe" /tray
[Win.ini] :HKCU load=""
### File is missing.
[Win.ini] :HKCU run=""
### File is missing.
[Startup Folder] Send to OneNote.lnk=C:\PROGRAM FILES (X86)\MICROSOFT
OFFICE\OFFICE15\ONENOTEM.EXE
### Send to OneNote Tool Microsoft Corporation Microsoft OneNote 15.0.4420.1017
[Startup Folder] upd.lnk=C:\USERS\USER\APPDATA\ROAMING\SYSTEM\WINLOG.VBS
[Scheduled Tasks] Driver Easy Scheduled Scan=C:\Program
Files\Easeware\DriverEasy\DriverEasy.exe
### File is missing.
[Scheduled Tasks] CreateExplorerShellUnelevatedTask=C:\WINDOWS\EXPLORER.EXE
### Windows Explorer Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0
[Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\ASUS Smart Gesture
Launcher=C:\PROGRAM FILES (X86)\ASUS\ASUS SMART
GESTURE\ASTPCENTER\X64\ASUSTPLAUNCHER.EXE
### ASUS Smart Gesture Launcher AsusTek ASUS Smart Gesture Launcher 1.0.3.1 !
$*"C:\Program Files (x86)\ASUS\ASUS Smart
Gesture\AsTPCenter\x64\AsusTPLauncher.exe" Description: ASUS Smart Gesture
Launcher
[Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\ATK Package
36D18D69AFC3=C:\PROGRAM FILES (X86)\ASUS\ATK PACKAGE\ATK HOTKEY\SIMAPPEXEC.EXE
### Simulate Store App Execution Application ASUSTek Computer Inc. ATK Hotkey
1.0.85.0 !$*"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\SimAppExec.exe"
Parameters: -CancelShutdown
[Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\ATK Package
A22126881260=C:\PROGRAM FILES (X86)\ASUS\ATK PACKAGE\ATK HOTKEY\SIMAPPEXEC.EXE
### Simulate Store App Execution Application ASUSTek Computer Inc. ATK Hotkey
1.0.85.0 !$*"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\SimAppExec.exe"
[Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\AutoPico Daily Restart=C:\PROGRAM
FILES\KMSPICO\AUTOPICO.EXE
### AutoPico AutoPico 10.0.0.0 !$*"C:\Program Files\KMSpico\AutoPico.exe"
Parameters: /silent
[Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Bridge Lease Manager=C:\PROGRAM
FILES\BRIDGE LEASE MANAGER\BRIDGE LEASE MANAGER.DLL
### !$*C:\WINDOWS\system32\rundll32.exe "C:\Program Files\Bridge Lease
Manager\Bridge Lease Manager.dll",xOZDuamTRnF Parameters: "C:\Program Files\Bridge
Lease Manager\Bridge Lease Manager.dll",xOZDuamTRnF
[Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\OneDrive Standalone Update Task
v2=C:\USERS\USER\APPDATA\LOCAL\MICROSOFT\ONEDRIVE\ONEDRIVESTANDALONEUPDATER.EXE
### Standalone Updater Microsoft Corporation Microsoft OneDrive 17.3.6998.0830 !
$*%localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe
[Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\OneDrive Standalone Update Task-S-
1-5-21-3874959377-2970451630-3046827342-
1002=C:\USERS\USER\APPDATA\LOCAL\MICROSOFT\ONEDRIVE\ONEDRIVESTANDALONEUPDATER.EXE
### Standalone Updater Microsoft Corporation Microsoft OneDrive 17.3.6998.0830 !
$*%localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe Parameters: {}
[Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\UnHackMe Task Scheduler=C:\PROGRAM
FILES (X86)\UNHACKME\HACKMON.EXE
### Detects Rootkits in background Greatis Software UnHackMe 8.50 Description:
Part of RegRun Suite/UnHackMe software. http://www Parameters: $(Arg0)
[Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\User_Feed_Synchronization-
{A079620E-4FCC-49E3-88B7-F371F8403965}=C:\WINDOWS\SYSTEM32\MSFEEDSSYNC.EXE
### Microsoft Feeds Synchronization Microsoft Corporation Internet Explorer
11.00.14393.0 Description: Updates out-of-date system feeds. Parameters: sync
[Scheduled Tasks 2.0 Cached] :HKLM ASUS Smart Gesture Launcher=C:\PROGRAM FILES
(X86)\ASUS\ASUS SMART GESTURE\ASTPCENTER\X64\ASUSTPLAUNCHER.EXE
### ASUS Smart Gesture Launcher AsusTek ASUS Smart Gesture Launcher 1.0.3.1 !
$*"C:\Program Files (x86)\ASUS\ASUS Smart
Gesture\AsTPCenter\x64\AsusTPLauncher.exe" ASUS Smart Gesture Launcher
[Scheduled Tasks 2.0 Cached] :HKLM ATK Package 36D18D69AFC3=C:\PROGRAM FILES
(X86)\ASUS\ATK PACKAGE\ATK HOTKEY\SIMAPPEXEC.EXE
### Simulate Store App Execution Application ASUSTek Computer Inc. ATK Hotkey
1.0.85.0 !$*"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\SimAppExec.exe"
Parameters: -CancelShutdown
[Scheduled Tasks 2.0 Cached] :HKLM ATK Package A22126881260=C:\PROGRAM FILES
(X86)\ASUS\ATK PACKAGE\ATK HOTKEY\SIMAPPEXEC.EXE
### Simulate Store App Execution Application ASUSTek Computer Inc. ATK Hotkey
1.0.85.0 !$*"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\SimAppExec.exe"
[Scheduled Tasks 2.0 Cached] :HKLM AutoPico Daily Restart=C:\PROGRAM
FILES\KMSPICO\AUTOPICO.EXE
### AutoPico AutoPico 10.0.0.0 !$*"C:\Program Files\KMSpico\AutoPico.exe"
Parameters: /silent
[Scheduled Tasks 2.0 Cached] :HKLM Bridge Lease Manager=C:\PROGRAM FILES\BRIDGE
LEASE MANAGER\BRIDGE LEASE MANAGER.DLL
### !$*C:\WINDOWS\system32\rundll32.exe "C:\Program Files\Bridge Lease
Manager\Bridge Lease Manager.dll",xOZDuamTRnF Parameters: "C:\Program Files\Bridge
Lease Manager\Bridge Lease Manager.dll",xOZDuamTRnF
[Scheduled Tasks 2.0 Cached] :HKLM OneDrive Standalone Update Task
v2=C:\USERS\USER\APPDATA\LOCAL\MICROSOFT\ONEDRIVE\ONEDRIVESTANDALONEUPDATER.EXE
### Standalone Updater Microsoft Corporation Microsoft OneDrive 17.3.6998.0830 !
$*%localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe
[Scheduled Tasks 2.0 Cached] :HKLM OneDrive Standalone Update Task-S-1-5-21-
3874959377-2970451630-3046827342-
1002=C:\USERS\USER\APPDATA\LOCAL\MICROSOFT\ONEDRIVE\ONEDRIVESTANDALONEUPDATER.EXE
### Standalone Updater Microsoft Corporation Microsoft OneDrive 17.3.6998.0830 !
$*%localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe
[Scheduled Tasks 2.0 Cached] :HKLM UnHackMe Task Scheduler=C:\PROGRAM FILES
(X86)\UNHACKME\HACKMON.EXE
### Detects Rootkits in background Greatis Software UnHackMe 8.50 Part of
RegRun Suite/UnHackMe software. http://www.greatis.com Parameters: $(Arg0)
[Scheduled Tasks 2.0 Cached] :HKLM User_Feed_Synchronization-{A079620E-4FCC-49E3-
88B7-F371F8403965}=C:\WINDOWS\SYSTEM32\MSFEEDSSYNC.EXE
### Microsoft Feeds Synchronization Microsoft Corporation Internet Explorer
11.00.14393.0 Updates out-of-date system feeds. Parameters: sync
[Unwanted Software Files] :HKLM SECOH-QAD.EXE=C:\WINDOWS\SECOH-QAD.EXE
[Unwanted Software Files] :HKLM
C:\ProgramData\MICROSOFT\NETWORK\DSQ\BROWSER\=C:\ProgramData\MICROSOFT\NETWORK\DSQ\
BROWSER\
[Unwanted Software Files] :HKLM
SYSNETWK.EXE=C:\PROGRAMDATA\MICROSOFT\NETWORK\DSQ\NETWORK\SYSNETWK.EXE
### Windows System Network Core Module Microsoft Corporation Microsoft Windows
Operating System 5.8
[Unwanted Software Files] :HKLM
C:\ProgramData\MICROSOFT\NETWORK\DSQ\=C:\ProgramData\MICROSOFT\NETWORK\DSQ\
[Unwanted Software Files] :HKLM C:\PROGRAM FILES (X86)\\UNZIPPER\=C:\PROGRAM
FILES (X86)\\UNZIPPER\
[Unwanted Software Files] :HKLM
MSWAPI64.DLL=C:\PROGRAMDATA\WINDOWS\SYSTEM32\MSWAPI64.DLL
### 2.2.0.3
[Unwanted Software Files] :HKLM C:\ProgramData\WINDOWS\=C:\ProgramData\WINDOWS\
[Unwanted Software Files] :HKLM
MSTOOLS.EXE=C:\USERS\USER\APPDATA\LOCAL\TEMP\MSTOOLS.EXE
### Adobe Installer Adobe Systems Incorporated Adobe Installer 4.2.0.215
[Unwanted Software Files] :HKLM 64.EXE=C:\USERS\USER\APPDATA\ROAMING\64.EXE
[Unwanted Software Files] :HKLM
DRIVEREASYSETUP.EXE=C:\USERS\USER\APPDATA\LOCAL\TEMP\DRIVEREASYSETUP.EXE
[Unwanted Software Files] :HKLM Easeware=C:\USERS\USER\APPDATA\ROAMING\EASEWARE\
[Detected using Heuristic Algorithm] :HKLM DR.FONE_TEMP=C:\PROGRAM FILES
(X86)\DR.FONE_TEMP\
[Detected using Heuristic Algorithm] :HKLM FOXIT SOFTWARE=C:\PROGRAM FILES
(X86)\FOXIT SOFTWARE\
[Detected using Heuristic Algorithm] :HKLM SMADAV=C:\PROGRAM FILES (X86)\SMADAV\
### "README.TXT" "SMADAV-UPDATER.EXE" "SMADAV.LOG" "SMADAV.LOOV"
"SMADENGINE.DLL" "SMADEXTC64.DLL" "SM|CE|94RTP.EXE" "UNINS000.DAT" "UNINS000.EXE"
[Detected using Heuristic Algorithm] :HKLM UNHACKME=C:\PROGRAM FILES
(X86)\UNHACKME\
### "7ZA.EXE" "DATABASE.RDB" "DBS.DB" "DBSWWW.INI" "HACKMON.EXE" "JSONFAST.DLL"
"LICENSE.TXT" "LOGO.BMP" "MOZLZ4D.EXE" "ORDER.TXT" "PARSER.DLL"
[Detected using Heuristic Algorithm] :HKLM UNZIPPER=C:\PROGRAM FILES
(X86)\UNZIPPER\
[Detected using Heuristic Algorithm] :HKLM WINDOWS MAIL=C:\PROGRAM FILES
(X86)\WINDOWS MAIL\
### "EN-US\" "MSOE.DLL" "MSOERES.DLL" "OEIMPORT.DLL" "WAB.EXE" "WABIMP.DLL"
"WABMIG.EXE" "WINMAIL.EXE" "en-US: MSOERES.DLL.MUI" "WINMAIL.EXE.MUI"
[Detected using Heuristic Algorithm] :HKLM KMSPICO=C:\PROGRAM FILES\KMSPICO\
### "AUTOPICO.EXE" "CERT\" "DEVCOMPONENTS.DOTNETBAR2.DLL" "DRIVER\" "ICONS\"
"LOGS\" "SCRIPTS\" "SOUNDS\" "TOKENSBACKUP\" "UNINS000.DAT" "UNINS000.EXE"
[Detected using Heuristic Algorithm] :HKLM M3ULPE53ML=C:\PROGRAM
FILES\M3ULPE53ML\
### "CAST.CONFIG" "M3ULPE53M.EXE" "M3ULPE53M.EXE.CONFIG" "UNINSTALLER.EXE"
"UNINSTALLER.EXE.CONFIG"
[Detected using Heuristic Algorithm] :HKLM OPB8PQV6BW=C:\PROGRAM
FILES\OPB8PQV6BW\
### "CAST.CONFIG" "OPB8PQV6B.EXE" "OPB8PQV6B.EXE.CONFIG" "UNINSTALLER.EXE"
"UNINSTALLER.EXE.CONFIG"
[Detected using Heuristic Algorithm] :HKLM P12NB3RVK8=C:\PROGRAM
FILES\P12NB3RVK8\
### "0PFCRCRK1.EXE" "0PFCRCRK1.EXE.CONFIG" "CAST.CONFIG" "UNINSTALLER.EXE"
"UNINSTALLER.EXE.CONFIG"
[Detected using Heuristic Algorithm] :HKLM PLUMBYTES SOFTWARE=C:\PROGRAM
FILES\PLUMBYTES SOFTWARE\
### "PLUMBYTES ANTI-MALWARE\" "Plumbytes Anti-Malware: AMWSERVICE.EXE"
"AMWSERVICE.EXE.LOG" "ANTIMALWARE.CONTROLS.DLL" "CMDPROXY.DLL" "DB.DLL"
"DOTNETZIP.DLL" "GALASOFT.MVVMLIGHT.DLL" "GALASOFT.MVVMLIGHT.EXTRAS.DLL"
"HARDCODET.WPF.TASKBARNOTIFICATION.DLL" "IN
[Detected using Heuristic Algorithm] :HKLM REMPL=C:\PROGRAM FILES\REMPL\
### "DRVDBFIX.EXE" "LOGS\" "REMPL.XML" "REMSH.EXE" "UNLOCK.XML" "Logs:
REMEDIATION.001.ETL" "REMEDIATION.002.ETL" "REMEDIATION.003.ETL"
"REMEDIATION.004.ETL" "REMEDIATION.005.ETL" "REMEDIATION.006.ETL"
"REMEDIATION.007.ETL" "REMEDIATION.008.ETL" "REMEDIATION.
[Detected using Heuristic Algorithm] :HKLM WINDOWS MAIL=C:\PROGRAM FILES\WINDOWS
MAIL\
### "EN-US\" "MSOE.DLL" "MSOERES.DLL" "OEIMPORT.DLL" "WAB.EXE" "WABIMP.DLL"
"WABMIG.EXE" "WINMAIL.EXE" "en-US: MSOERES.DLL.MUI" "WINMAIL.EXE.MUI"
[Detected using Heuristic Algorithm] :HKLM WINDOWSAPPS=C:\PROGRAM
FILES\WINDOWSAPPS\
### "DELETED\" "MICROSOFT.3DBUILDER_14.1.1302.0_NEUTRAL_~_8WEKYB3D8BBWE\"
"MICROSOFT.3DBUILDER_14.1.1302.0_X64__8WEKYB3D8BBWE\"
"MICROSOFT.ADVERTISING.XAML_10.1709.1.0_X64__8WEKYB3D8BBWE\"
"MICROSOFT.ADVERTISING.XAML_10.1709.1.0_X86__8WEKYB3D8BBWE\" "MICROSOF
[Detected using Heuristic Algorithm] :HKLM WLFJ5AXNNW=C:\PROGRAM
FILES\WLFJ5AXNNW\
### "CAST.CONFIG" "UNINSTALLER.EXE.CONFIG" "WLFJ5AXNN.EXE"
"WLFJ5AXNN.EXE.CONFIG"
[Detected using Heuristic Algorithm] :HKLM ASUS SMART GESTURE=C:\PROGRAMDATA\ASUS
SMART GESTURE\
### "ASUSTPAPI.LOG" "ASUSTPLOADER.LOG" "OK.LOG"
[Detected using Heuristic Algorithm] :HKLM CONEXANT=C:\PROGRAMDATA\CONEXANT\
### "UCILOGS\" "UNINSTALLERLOGS\" "UCILogs\COINST: DIF_INSTALLDEVICE_POST.LOG"
"DIF_INSTALLDEVICE_PRE.LOG" "DIF_INSTALLINTERFACES.LOG"
"DIF_NEWDEVICEWIZARD_FINISHINSTALL.LOG" "DIF_UNSUPPORTED_12.LOG"
"DIF_UNSUPPORTED_21.LOG" "UninstallerLogs: CONEXANT_UNINSTA
[Detected using Heuristic Algorithm] :HKLM REGRUN=C:\PROGRAMDATA\REGRUN\
[Detected using Heuristic Algorithm] :HKLM WINDOWS=C:\PROGRAMDATA\WINDOWS\
### "SYSTEM32\" "System32: MSWAPI64.DLL"
[Detected using Heuristic Algorithm] :HKLM {12A8CCFE-3C33-4995-BAD8-
074E4C5B22FD}=C:\USERS\USER\APPDATA\LOCAL\{12A8CCFE-3C33-4995-BAD8-074E4C5B22FD}\
### "SCANLOGS.XML"
[Detected using Heuristic Algorithm] :HKLM
DIAGNOSTICS=C:\USERS\USER\APPDATA\LOCAL\DIAGNOSTICS\
### "938563667\" "938563667: LATEST.CAB" "938563667\2017101915.000:
NETWORKDIAGNOSTICS.DEBUGREPORT.XML" "RESULTREPORT.XML" "RESULTS.XML" "RESULTS.XSL"
[Detected using Heuristic Algorithm] :HKLM
MOZILLA=C:\USERS\USER\APPDATA\LOCAL\MOZILLA\
[Detected using Heuristic Algorithm] :HKLM
PACKAGES=C:\USERS\USER\APPDATA\LOCAL\PACKAGES\
### "ACTIVESYNC\" "MICROSOFT.3DBUILDER_8WEKYB3D8BBWE\"
"MICROSOFT.AAD.BROKERPLUGIN_CW5N1H2TXYEWY\"
"MICROSOFT.ACCOUNTSCONTROL_CW5N1H2TXYEWY\"
"MICROSOFT.ADVERTISING.XAML_8WEKYB3D8BBWE\" "MICROSOFT.APPCONNECTOR_8WEKYB3D8BBWE\"
"MICROSOFT.BINGFINANCE_8WEKYB3D8B
[Detected using Heuristic Algorithm] :HKLM TEMP=C:\USERS\USER\APPDATA\LOCAL\TEMP\
### "01F6F272-814F-4DD1-AFBE-0075B8B52753\" "0AEBF3F6-E882-4D22-9469-
B496F5AFBE60\" "0B7731D8-E410-4AB9-B1FC-C5DC19BCC4C5\" "0GRDEPXTO\"
"109DA755F7DC4693A16C436191D60F04\" "113E0995-D52F-4A58-A5EE-36E4EB74C6FB\"
"119614671.CVR" "1E417497-9909-4186-A0F0-A06AF
[Detected using Heuristic Algorithm] :HKLM
MOZILLA=C:\USERS\USER\APPDATA\LOCALLOW\MOZILLA\
### "TEMP-{123A7923-ECCD-4927-AA64-1B05CB442311}\" "TEMP-{2B89D4B2-07A6-4F16-
B096-5296F933C32C}\" "TEMP-{2FB10396-CDD2-4BBD-A0C0-9399F57CF913}\" "TEMP-
{7FB1A72C-69F6-4F36-B1BA-AF4FF7D45C8D}\" "TEMP-{A146A24E-6982-4489-8557-
14D42B2A4A27}\" "TEMP-{DA0A3B9A-F248
[Detected using Heuristic Algorithm] :HKLM
1337=C:\USERS\USER\APPDATA\ROAMING\1337\
### "SETUP-LOGGER.EXE" "SETUPQW.EXE"
[Detected using Heuristic Algorithm] :HKLM
ADOBE=C:\USERS\USER\APPDATA\ROAMING\ADOBE\
### "ACROBAT\" "ADOBE PDF\" "ADOBE PHOTOSHOP CS5\" "COLOR\" "FLASH PLAYER\"
"HEADLIGHTS\" "LINGUISTICS\" "LOGTRANSPORT2\" "Acrobat\10.0: TMDOCS.SAV"
"TMGRPPRM.SAV" "Acrobat\10.0\JSCache: GLOBDATA" "Acrobat\10.0\Preferences:
AUTOFILLDEFAULTS.DAT" "DEFAULTHEUR
[Detected using Heuristic Algorithm] :HKLM
B40I5J0RX13=C:\USERS\USER\APPDATA\ROAMING\B40I5J0RX13\
### "DKLTX5ANUBP.EXE"
[Detected using Heuristic Algorithm] :HKLM
MOZILLA=C:\USERS\USER\APPDATA\ROAMING\MOZILLA\
### "FIREFOX\" "Firefox\Profiles\hkbg8pd9.default: CONTENT-PREFS.SQLITE"
"COOKIES.SQLITE" "PARENT.LOCK" "PERMISSIONS.SQLITE" "PREFS.JS"
"WEBAPPSSTORE.SQLITE" "WEBAPPSSTORE.SQLITE-SHM" "WEBAPPSSTORE.SQLITE-WAL"
"XULSTORE.JSON"
[Detected using Heuristic Algorithm] :HKLM
NVIDIA=C:\USERS\USER\APPDATA\ROAMING\NVIDIA\
### "COMPUTECACHE\" "ComputeCache: INDEX" "ComputeCache\5\0: 38FAE92F5C6663"
"ComputeCache\7\8: 71A3017558AE9D" "ComputeCache\d\5: FAEF7173FC1A9F"
"ComputeCache\f\5: 892DB1E3450CA4"
[Detected using Heuristic Algorithm] :HKLM
SYSTEM=C:\USERS\USER\APPDATA\ROAMING\SYSTEM\
### "1.CMD" "2.CMD" "2.PEP5" "SYSTEMCARE-PPI-UL5.DLL" "SYSTEMCARE.EXE"
"WIN.PEP5" "WINDOWS-PPI-UL5.DLL" "WINDOWS.EXE" "WINLOG.VBS"
[Detected using Heuristic Algorithm] :HKLM
UGIOAUUJ2GG=C:\USERS\USER\APPDATA\ROAMING\UGIOAUUJ2GG\
### "SSXTK4J2TIJ.EXE"
[Detected using Heuristic Algorithm] :HKLM
W43JJDYZMS2=C:\USERS\USER\APPDATA\ROAMING\W43JJDYZMS2\
### "2BBFEQRERM1.EXE"
[Detected using Heuristic Algorithm] :HKLM
WONDERSHARE=C:\USERS\USER\APPDATA\ROAMING\WONDERSHARE\
[Detected using Heuristic Algorithm] :HKLM CONTACTS=C:\USERS\USER\CONTACTS\
### "DESKTOP.INI"
[Detected using Heuristic Algorithm] :HKLM DESKTOP=C:\USERS\USER\DESKTOP\
### "ARTICLE 3.DOCX" "BAB I.DOCX" "DESKTOP.INI" "DOCUMENTS - SHORTCUT.LNK"
"DOWNLOAD.TXT" "DRAFT.XPS" "EXCEL 2013.LNK" "GOOGLE CHROME.LNK" "INTERNET DOWNLOAD
MANAGER.LNK" "KEYBOARDTEST.LNK" "KMPLAYER.LNK"
[Detected using Heuristic Algorithm] :HKLM DOCUMENTS=C:\USERS\USER\DOCUMENTS\
### "AIRDROID\" "ASNI PERJIN.DOCX" "AVATAR\" "BIOGRAFI TOKOH.DOCX" "CUSTOM
OFFICE TEMPLATES\" "DATA CAMPURAN\" "DATA CAMPURAN 2\" "DESKTOP.INI" "FILE ARGUMEN
UII\" "FIMOSIS.DOCX" "GOMPLAYER\"
[Detected using Heuristic Algorithm] :HKLM DOWNLOADS=C:\USERS\USER\DOWNLOADS\
### "009114140.PDF" "027375307X.PDF" "04PN51.DOC" "06.1099.PDF"
"08.20.0036%20DIAS%20YITIKA%20RAHMAWARNO%20COVER - SHORTCUT.LNK" "08.20.0036%20DIAS
%20YITIKA%20RAHMAWARNO%20COVER.PDF" "09E02105(1).PDF" "09E02105.PDF" "10502-11878-
1-SM.PDF" "11664-13184-1-PB.PD
[Detected using Heuristic Algorithm] :HKLM FAVORITES=C:\USERS\USER\FAVORITES\
### "BING.URL" "DESKTOP.INI" "LINKS\" "Links: DESKTOP.INI"
[Detected using Heuristic Algorithm] :HKLM
INTELGRAPHICSPROFILES=C:\USERS\USER\INTELGRAPHICSPROFILES\
### "BRIGHTEN VIDEO.MAN.IGPI" "DARKEN VIDEO.MAN.IGPI" "ENHANCE VIDEO
COLORS.MAN.IGPI"
[Detected using Heuristic Algorithm] :HKLM LINKS=C:\USERS\USER\LINKS\
### "DESKTOP.INI" "DESKTOP.LNK" "DOWNLOADS.LNK" "ONEDRIVE.LNK"
[Detected using Heuristic Algorithm] :HKLM MUSIC=C:\USERS\USER\MUSIC\
### "DESKTOP.INI" "ITUNES\" "iTunes: ITUNES LIBRARY EXTRAS.ITDB" "ITUNES LIBRARY
GENIUS.ITDB" "ITUNES LIBRARY.ITL" "SENTINEL" "iTunes\iTunes Media: .ITUNES
PREFERENCES.PLIST"
[Detected using Heuristic Algorithm] :HKLM PICTURES=C:\USERS\USER\PICTURES\
### "1505273102371.JPG" "ANDI ADEWINARNI.JPG" "CAMERA ROLL\" "DESKTOP.INI" "FV
DFG.JPG" "IMAGE_7D7D44A.JPG" "IMAGE_D8AE2AC.JPG" "JJJ.JPG" "NEW FOLDER\" "SAVED
PICTURES\" "UNHACKMEB.ZIP"
[Detected using Heuristic Algorithm] :HKLM SAVED GAMES=C:\USERS\USER\SAVED GAMES\
### "DESKTOP.INI"
[Detected using Heuristic Algorithm] :HKLM SEARCHES=C:\USERS\USER\SEARCHES\
### "DESKTOP.INI" "EVERYWHERE.SEARCH-MS" "INDEXED LOCATIONS.SEARCH-MS"
"MICROSOFT ONENOTE.SEARCHCONNECTOR-MS" "WINRT--{S-1-5-21-3874959377-2970451630-
3046827342-1002}-.SEARCHCONNECTOR-MS"
[Detected using Heuristic Algorithm] :HKLM VIDEOS=C:\USERS\USER\VIDEOS\
### "DESKTOP.INI" "~$ALAT ADALAH SARANA KOMUNIKASI KITA UNTUK LEBIH DEKAT KEPADA
SANG MAHA PENCIPTA.DOCX" "~$GAS FINAL.DOCX" "~$MBEBANAN TARIF PAJAK TERHADAP BEA
MASUK IMPOR.DOCX"
[Detected using Heuristic Algorithm] :HKLM
64.exe=C:\USERS\USER\APPDATA\ROAMING\64.EXE
[Detected using Heuristic Algorithm] :HKLM
BITAF5B.tmp=C:\USERS\USER\APPDATA\LOCAL\TEMP\BITAF5B.TMP
[Detected using Heuristic Algorithm] :HKLM
D71D.tmp.exe=C:\USERS\USER\APPDATA\LOCAL\TEMP\D71D.TMP.EXE
### Driver Easy Setup Easeware
Driver Easy 5.5.4

[Detected using Heuristic Algorithm] :HKLM


DriverEasySetup.exe=C:\USERS\USER\APPDATA\LOCAL\TEMP\DRIVEREASYSETUP.EXE
[Detected using Heuristic Algorithm] :HKLM
FastDataX.exe=C:\USERS\USER\APPDATA\LOCAL\TEMP\FASTDATAX.EXE
### FastDataX Setup
FastDataX 1.20
[Detected using Heuristic Algorithm] :HKLM
Ins2348.tmp=C:\USERS\USER\APPDATA\LOCAL\TEMP\INS2348.TMP
### Custom action that tracks analytics data. Caphyon LTD Advanced Installer
14.0.2.0
[Detected using Heuristic Algorithm] :HKLM
InsFDA.tmp=C:\USERS\USER\APPDATA\LOCAL\TEMP\INSFDA.TMP
### Custom action that tracks analytics data. Caphyon LTD Advanced Installer
14.0.2.0
[Detected using Heuristic Algorithm] :HKLM
installer.exe=C:\USERS\USER\APPDATA\LOCAL\TEMP\INSTALLER.EXE
### uB2rNt3lrFW6v90Yx9vb
uB2rNt3lrFW6v90Yx9vb uB2rNt3lrFW6v90Yx9vb
22.11.56
[Detected using Heuristic Algorithm] :HKLM
installer_campaign_20539.exe=C:\USERS\USER\APPDATA\LOCAL\TEMP\INSTALLER_CAMPAIGN_20
539.EXE
[Detected using Heuristic Algorithm] :HKLM
mstools.exe=C:\USERS\USER\APPDATA\LOCAL\TEMP\MSTOOLS.EXE
### Adobe Installer Adobe Systems Incorporated Adobe Installer 4.2.0.215
[Detected using Heuristic Algorithm] :HKLM
pai5BD3.tmp=C:\USERS\USER\APPDATA\LOCAL\TEMP\PAI5BD3.TMP
### Plumbytes Anti-Malware Plumbytes Software Plumbytes Anti-Malware
[Detected using Heuristic Algorithm] :HKLM
paiAD7C.tmp=C:\USERS\USER\APPDATA\LOCAL\TEMP\PAIAD7C.TMP
### Plumbytes Anti-Malware Plumbytes Software Plumbytes Anti-Malware
[Detected using Heuristic Algorithm] :HKLM
s2s.exe=C:\USERS\USER\APPDATA\LOCAL\TEMP\S2S.EXE
### Museum of Fine Arts, Boston Konrad [24] He may hav We have very li 1, 9, 7,
39
[Detected using Heuristic Algorithm] :HKLM setup
(1).exe=C:\USERS\USER\APPDATA\LOCAL\TEMP\SETUP (1).EXE
### Throne Kingdom at War Throne Kingdom at War Installation Throne Kingdom
at War
[Detected using Heuristic Algorithm] :HKLM
Setup.exe=C:\USERS\USER\APPDATA\LOCAL\TEMP\SETUP.EXE
[Detected using Heuristic Algorithm] :HKLM
setupQW.exe=C:\USERS\USER\APPDATA\LOCAL\TEMP\SETUPQW.EXE
### description
[Detected using Heuristic Algorithm] :HKLM
speedownloader.exe=C:\USERS\USER\APPDATA\LOCAL\TEMP\SPEEDOWNLOADER.EXE
### KafonGF Setup rabiysahel
KafonGF 5.6

[Detected using Heuristic Algorithm] :HKLM


Uninstall.exe=C:\USERS\USER\APPDATA\LOCAL\TEMP\UNINSTALL.EXE
[Detected using Heuristic Algorithm] :HKLM
wct31F4.tmp=C:\USERS\USER\APPDATA\LOCAL\TEMP\WCT31F4.TMP
### Microsoft OneDrive Setup Microsoft Corporation Windows Live 17.3.6799.0327
[Detected using Heuristic Algorithm] :HKLM
wct895A.tmp=C:\USERS\USER\APPDATA\LOCAL\TEMP\WCT895A.TMP
### Microsoft OneDrive Setup Microsoft Corporation Windows Live 17.3.6917.0607
[Detected using Heuristic Algorithm] :HKLM
wct9D24.tmp=C:\USERS\USER\APPDATA\LOCAL\TEMP\WCT9D24.TMP
### Microsoft OneDrive Setup Microsoft Corporation Windows Live 17.3.6798.0207
[Detected using Heuristic Algorithm] :HKLM
wctA171.tmp=C:\USERS\USER\APPDATA\LOCAL\TEMP\WCTA171.TMP
### Microsoft OneDrive Setup Microsoft Corporation Windows Live 17.3.6998.0830
[Detected using Heuristic Algorithm] :HKLM
wctAE24.tmp=C:\USERS\USER\APPDATA\LOCAL\TEMP\WCTAE24.TMP
### Microsoft OneDrive Setup Microsoft Corporation Windows Live 17.3.6943.0625
[Detected using Heuristic Algorithm] :HKLM
wctD2C7.tmp=C:\USERS\USER\APPDATA\LOCAL\TEMP\WCTD2C7.TMP
### Microsoft OneDrive Setup Microsoft Corporation Windows Live 17.3.6966.0824
[Detected using Heuristic Algorithm] :HKLM
Z@SE3B2.tmp=C:\USERS\USER\APPDATA\LOCAL\TEMP\Z@SE3B2.TMP
[Detected using Heuristic Algorithm] :HKLM
Z@SE6D1.tmp=C:\USERS\USER\APPDATA\LOCAL\TEMP\Z@SE6D1.TMP
[Detected using Heuristic Algorithm] :HKLM
Z@SE7ED.tmp=C:\USERS\USER\APPDATA\LOCAL\TEMP\Z@SE7ED.TMP
[Detected using Heuristic Algorithm] :HKLM
Z@SE8F8.tmp=C:\USERS\USER\APPDATA\LOCAL\TEMP\Z@SE8F8.TMP
[In memory]
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\LSASS.EXE
### Local Security Authority Process Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.1770 !$*C:\WINDOWS\system32\lsass.exe
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*C:\WINDOWS\system32\svchost.exe -k DcomLaunch
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*C:\WINDOWS\system32\svchost.exe -k RPCSS
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\WINLOGON.EXE
### Windows Logon Application Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*winlogon.exe
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*C:\WINDOWS\system32\svchost.exe -k LocalService
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\DWM.EXE
### Desktop Window Manager Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*"dwm.exe"
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*C:\WINDOWS\System32\svchost.exe -k
LocalSystemNetworkRestricted
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*C:\WINDOWS\system32\svchost.exe -k
LocalServiceNetworkRestricted
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*C:\WINDOWS\system32\svchost.exe -k netsvcs
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*C:\WINDOWS\system32\svchost.exe -k
LocalServiceNoNetwork
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\DASHOST.EXE
### Device Association Framework Provider Host Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.82 !$*dashost.exe {049d1f9a-3dbb-4cdc-
ab1ba40c8a811652}
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*C:\WINDOWS\System32\svchost.exe -k NetworkService
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\NVVSVC.EXE
### NVIDIA Driver Helper Service, Version 359.46 NVIDIA Corporation NVIDIA Driver
Helper Service, Version 359.46 8.17.13.5946 !$*"C:\WINDOWS\system32\nvvsvc.exe"
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\IGFXCUISERVICE.EXE
### igfxCUIService Module Intel Corporation Intel(R) Common User Interface
6.15.10.4549 !$*C:\WINDOWS\system32\igfxCUIService.exe
[Running Processes] :HKLM C:\PROGRAM FILES\NVIDIA
CORPORATION\DISPLAY\NVXDSYNC.EXE
### NVIDIA User Experience Driver Component NVIDIA Corporation NVIDIA User
Experience Driver Component 8.17.13.5946 !$*"C:\Program Files\NVIDIA
Corporation\Display\nvxdsync.exe"
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\NVVSVC.EXE
### NVIDIA Driver Helper Service, Version 359.46 NVIDIA Corporation NVIDIA Driver
Helper Service, Version 359.46 8.17.13.5946 !$*C:\WINDOWS\system32\nvvsvc.exe
-session -first
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*C:\WINDOWS\System32\svchost.exe -k
LocalServiceNetworkRestricted
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*C:\WINDOWS\system32\svchost.exe -k
LocalServiceNetworkRestricted
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*C:\WINDOWS\system32\svchost.exe -k
LocalSystemNetworkRestricted
[Running Processes] :HKLM C:\PROGRAM FILES (X86)\ASUS\ATK PACKAGE\ATK
HOTKEY\ASLDRSRV.EXE
### ASLDR Service ASUSTek Computer Inc. ATK Hotkey 1, 0, 81, 0 !$*"C:\Program
Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe"
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SPOOLSV.EXE
### Spooler SubSystem App Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*C:\WINDOWS\System32\spoolsv.exe
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*C:\WINDOWS\system32\svchost.exe -k appmodel
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*C:\WINDOWS\system32\svchost.exe -k
NetworkServiceNetworkRestricted
[Running Processes] :HKLM C:\PROGRAM FILES (X86)\COMMON
FILES\ADOBE\ARM\1.0\ARMSVC.EXE
### Adobe Acrobat Update Service Adobe Systems Incorporated Adobe Acrobat Update
Service 1, 5, 5, 0 !$*"C:\Program Files (x86)\Common
Files\Adobe\ARM\1.0\armsvc.exe"
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*C:\WINDOWS\System32\svchost.exe -k utcsvc
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\DPTFPARTICIPANTPROCESSORSERVICE.EXE
### Intel(R) Dynamic Platform and Thermal Framework Processor Participant Service
Intel Corporation Intel(R) Dynamic Platform and Thermal Framework 7.1.0.2106 !
$*C:\WINDOWS\system32\DptfParticipantProcessorService.exe
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\DPTFPOLICYCONFIGTDPSERVICE.EXE
### Intel(R) Dynamic Platform and Thermal Framework Config TDP Policy Service
Intel Corporation Intel(R) Dynamic Platform and Thermal Framework 7.1.0.2106 !
$*C:\WINDOWS\system32\DptfPolicyConfigTDPService.exe
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\DPTFPOLICYLPMSERVICE.EXE
### Intel(R) Dynamic Platform and Thermal Framework LPM Policy Service Intel
Corporation Intel(R) Dynamic Platform and Thermal Framework 7.1.0.2106 !
$*C:\WINDOWS\system32\DptfPolicyLpmService.exe
[Running Processes] :HKLM C:\PROGRAMDATA\DATACARDSERVICE\HWDEVICESERVICE64.EXE
### DCSHOST HWDeviceService 2, 0, 0, 47 !
$*"C:\ProgramData\DatacardService\HWDeviceService64.exe" -/service
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*C:\WINDOWS\system32\svchost.exe -k
LocalSystemNetworkRestricted
[Running Processes] :HKLM C:\PROGRAM FILES
(X86)\WONDERSHARE\WAF\2.3.0.5\WSAPPSERVICE.EXE
### Wondershare AppService Wondershare Wondershare App Framework 2.3.0.5 !
$*"C:\Program Files (x86)\Wondershare\WAF\2.3.0.5\WsAppService.exe"
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*C:\WINDOWS\system32\svchost.exe -k imgsvc
[Running Processes] :HKLM C:\PROGRAM FILES\PLUMBYTES SOFTWARE\PLUMBYTES ANTI-
MALWARE\AMWSERVICE.EXE
### Antimalware service PLUMBYTES PLUMBYTES Anti malware 0.9.0.634 !
$*"C:\Program Files\Plumbytes Software\Plumbytes Anti-Malware\AmwService.exe" run
[Running Processes] :HKLM C:\PROGRAMDATA\TELKOMSELFLASH\ONLINEUPDATE\OUC.EXE
### !$*C:\ProgramData\TELKOMSELFlash\OnlineUpdate\ouc.exe "C:/Program Files
(x86)/TELKOMSELFlash/UpdateDog/"
[Running Processes] :HKLM C:\PROGRAM FILES (X86)\ASUS\ATK PACKAGE\ATK
HOTKEY\HCONTROL.EXE
### HControl ASUSTek Computer Inc. ATK Hotkey 1, 0, 86, 0 !$*"C:\Program Files
(x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe"
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SIHOST.EXE
### Shell Infrastructure Host Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*sihost.exe
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\IGFXEM.EXE
### igfxEM Module Intel Corporation Intel(R) Common User Interface
6.15.10.4549 !$*igfxEM.exe
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\IGFXHK.EXE
### igfxHK Module Intel Corporation Intel(R) Common User Interface
6.15.10.4549 !$*igfxHK.exe
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\IGFXTRAY.EXE
### !$*igfxTray.exe
[Running Processes] :HKLM C:\PROGRAM FILES (X86)\ASUS\ATK
PACKAGE\ATKOSD2\ATKOSD2.EXE
### ATKOSD2 ASUSTek Computer Inc. ATKOSD2 7, 0, 32, 0 !$*"C:\Program Files
(x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe"
[Running Processes] :HKLM C:\PROGRAM FILES (X86)\ASUS\ATK PACKAGE\ATK
MEDIA\DMEDIA.EXE
### ATK Media ASUSTek Computer Inc. ATK Media 2, 0, 21, 0 !$*"C:\Program Files
(x86)\ASUS\ATK Package\ATK Media\DMedia.exe"
[Running Processes] :HKLM C:\WINDOWS\EXPLORER.EXE
### Windows Explorer Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*C:\WINDOWS\Explorer.EXE
[Running Processes] :HKLM C:\PROGRAMDATA\DATACARDSERVICE\DCSHELPER.EXE
### DataCardMonitor MFC Application Huawei Technologies Co., Ltd. Huawei
Technologies Co., Ltd. DataCardMonitor 2, 0, 0, 47 !
$*"C:\ProgramData\DatacardService\DCSHelper.exe"
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*C:\WINDOWS\system32\svchost.exe -k
UnistackSvcGroup
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*C:\WINDOWS\system32\svchost.exe -k
LocalServiceAndNoImpersonation
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\RUNTIMEBROKER.EXE
### Runtime Broker Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*C:\Windows\System32\RuntimeBroker.exe -Embedding
[Running Processes] :HKLM
C:\WINDOWS\SYSTEMAPPS\SHELLEXPERIENCEHOST_CW5N1H2TXYEWY\SHELLEXPERIENCEHOST.EXE
### Windows Shell Experience Host Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.447 !
$*"C:\WINDOWS\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe"
-ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca
[Running Processes] :HKLM
C:\PROGRAMDATA\MICROSOFT\NETWORK\DSQ\NETWORK\SYSNETWK.EXE
### Windows System Network Core Module Microsoft Corporation Microsoft Windows
Operating System 5.8 !
$*"C:\ProgramData\Microsoft\Network\Dsq\network\sysnetwk.exe" -ds
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\TASKHOSTW.EXE
### Host Process for Windows Tasks Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*taskhostw.exe {222A245B-E637-4AE9-A93F-
A59CA119A75E}
[Running Processes] :HKLM
C:\WINDOWS\SYSTEMAPPS\MICROSOFT.WINDOWS.CORTANA_CW5N1H2TXYEWY\SEARCHUI.EXE
### Search and Cortana application Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.953 !
$*"C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe"
-ServerName:CortanaUI.AppXa50dqqa5gqv4a428c9y1jjw7m3btvepj.mca
[Running Processes] :HKLM
C:\PROGRAMDATA\MICROSOFT\NETWORK\DSQ\BROWSER\SYSHOSTCTL.EXE
### Microsoft Network Microsoft Corporation Microsoft Windows Operating System
5.8.0.213 !$*"C:\ProgramData\Microsoft\Network\Dsq\browser\syshostctl.exe"
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SEARCHINDEXER.EXE
### Microsoft Windows Search Indexer Microsoft Corporation Windows� Search
7.0.14393.0 !$*C:\WINDOWS\system32\SearchIndexer.exe /Embedding
[Running Processes] :HKLM C:\PROGRAM FILES\NVIDIA CORPORATION\DISPLAY\NVTRAY.EXE
### NVIDIA Settings NVIDIA Corporation NVIDIA Settings 7.17.13.5946 !
$*"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1"
[Running Processes] :HKLM C:\PROGRAM FILES (X86)\NVIDIA CORPORATION\UPDATE
CORE\NVBACKEND.EXE
### NVIDIA Update Backend NVIDIA Corporation NVIDIA Update 10.4.0.6 !
$*"C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
[Running Processes] :HKLM C:\PROGRAM FILES\WINDOWS DEFENDER\MSASCUIL.EXE
### Windows Defender notification icon Microsoft Corporation Microsoft� Windows�
Operating System 4.10.14393.1198 !$*"C:\Program Files\Windows
Defender\MSASCuiL.exe"
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\DPTFPOLICYLPMSERVICEHELPER.EXE
### Intel(R) Dynamic Platform and Thermal Framework LPM Policy Service Helper
Intel Corporation Intel(R) Dynamic Platform and Thermal Framework 7.1.0.2106 !
$*"C:\Windows\System32\DptfPolicyLpmServiceHelper.exe"
[Running Processes] :HKLM C:\PROGRAM FILES\PLUMBYTES SOFTWARE\PLUMBYTES ANTI-
MALWARE\PLUMBYTES.EXE
### Anti-Malware Anti-Malware Anti-Malware 1.0.0.0 !$*"C:\Program
Files\Plumbytes Software\Plumbytes Anti-Malware\Plumbytes.exe" /tray
[Running Processes] :HKLM
C:\USERS\USER\APPDATA\LOCAL\MICROSOFT\ONEDRIVE\ONEDRIVE.EXE
### Microsoft OneDrive Microsoft Corporation Microsoft OneDrive 17.3.6998.0830 !
$*"C:\Users\USER\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
[Running Processes] :HKLM C:\PROGRAM FILES (X86)\COMMON
FILES\AHEAD\LIB\NMBGMONITOR.EXE
### Nero Home Nero AG Nero Home 2,0,16,0 !$*"C:\Program Files (x86)\Common
Files\Ahead\Lib\NMBgMonitor.exe"
[Running Processes] :HKLM C:\PROGRAM FILES (X86)\COMMON
FILES\AHEAD\LIB\NMINDEXINGSERVICE.EXE
### Nero Home Nero AG Nero Home 2,0,16,0 !$*"C:\Program Files (x86)\Common
Files\Ahead\Lib\NMIndexingService.exe"
[Running Processes] :HKLM C:\PROGRAM FILES (X86)\COMMON
FILES\AHEAD\LIB\NMINDEXSTORESVR.EXE
### Nero Home Nero AG Nero Home 2,0,16,0 !$*"C:\Program Files (x86)\Common
Files\Ahead\Lib\NMIndexStoreSvr.exe" -Embedding
[Running Processes] :HKLM
C:\USERS\USER\APPDATA\LOCAL\TEMP\SYSTEM32\LOGS\SHELLEXPERIENCEHOST.EXE
### Application Frame Host Application Frame Host Application Frame Host 1.0.0.0
!$*"C:\Users\USER\AppData\Local\Temp\System32\Logs\ShellExperienceHost.exe"
[Running Processes] :HKLM
C:\USERS\USER\APPDATA\ROAMING\B40I5J0RX13\DKLTX5ANUBP.EXE
### eCadeauHedi Setup Tounsi
eCadeauHedi 6.9
!$*"C:\Users\USER\AppData\Roaming\b40i5j0rx13\dkltx5anubp.exe" /VERYSILENT
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\CMD.EXE
### Windows Command Processor Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*C:\WINDOWS\system32\cmd.exe /c
C:\Users\USER\AppData\Local\Temp\WindowsTask\MicrosoftShellHost.exe -o
stratum+tcp://xmr.pool.minergate.com:45560 -u tuzem1017@ya.ru -p x -t 2
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\CONHOST.EXE
### Console Window Host Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*\??\C:\WINDOWS\system32\conhost.exe 0x4
[Running Processes] :HKLM C:\USERS\USER\APPDATA\LOCAL\TEMP\IS-
R89CC.TMP\DKLTX5ANUBP.TMP
### Setup/Uninstall !$*"C:\Users\USER\AppData\Local\Temp\is-
R89CC.tmp\dkltx5anubp.tmp"
/SL5="$1036A,556304,72192,C:\Users\USER\AppData\Roaming\b40i5j0rx13\dkltx5anubp.exe
" /VERYSILENT
[Running Processes] :HKLM C:\PROGRAM FILES\M3ULPE53ML\M3ULPE53M.EXE
### 5MTOVYFS 5MTO 5MTOVY 1.4.8.0 !$*"C:\Program Files\M3ULPE53ML\M3ULPE53M.exe"
[Running Processes] :HKLM
C:\USERS\USER\APPDATA\LOCAL\TEMP\WINDOWSTASK\MICROSOFTSHELLHOST.EXE
### MicrosoftShellHost MicrosoftShellHost MicrosoftShellHost 2.4.0.1 !
$*C:\Users\USER\AppData\Local\Temp\WindowsTask\MicrosoftShellHost.exe -o
stratum+tcp://xmr.pool.minergate.com:45560 -u tuzem1017@ya.ru -p x -t 2
[Running Processes] :HKLM
C:\USERS\USER\APPDATA\ROAMING\W43JJDYZMS2\2BBFEQRERM1.EXE
### eCadeauHedi Setup Tounsi
eCadeauHedi 6.9
!$*"C:\Users\USER\AppData\Roaming\w43jjdyzms2\2bbfeqrerm1.exe" /VERYSILENT
[Running Processes] :HKLM C:\USERS\USER\APPDATA\LOCAL\TEMP\IS-
ST85D.TMP\2BBFEQRERM1.TMP
### Setup/Uninstall !$*"C:\Users\USER\AppData\Local\Temp\is-
ST85D.tmp\2bbfeqrerm1.tmp"
/SL5="$2020C,556304,72192,C:\Users\USER\AppData\Roaming\w43jjdyzms2\2bbfeqrerm1.exe
" /VERYSILENT
[Running Processes] :HKLM C:\PROGRAM FILES\WLFJ5AXNNW\WLFJ5AXNN.EXE
### 5MTOVYFS 5MTO 5MTOVY 1.4.8.0 !$*"C:\Program Files\WLFJ5AXNNW\WLFJ5AXNN.exe"
[Running Processes] :HKLM C:\PROGRAM FILES\OPB8PQV6BW\OPB8PQV6B.EXE
### 65CDWHMAU 6 65CDWH 1.2.5.7 !$*"C:\Program Files\OPB8PQV6BW\OPB8PQV6B.exe"
[Running Processes] :HKLM C:\PROGRAM FILES (X86)\ASUS\ASUS SMART
GESTURE\ASTPCENTER\X64\ASUSTPLOADER.EXE
### ASUS Smart Gesture Loader AsusTek ASUS Smart Gesture 1.0.51.0 !$*"C:\Program
Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe"
[Running Processes] :HKLM C:\PROGRAM FILES\P12NB3RVK8\0PFCRCRK1.EXE
### O0K4 O0K4@99G 6.5.8.5 !$*"C:\Program Files\P12NB3RVK8\0PFCRCRK1.exe"
[Running Processes] :HKLM
C:\USERS\USER\APPDATA\ROAMING\UGIOAUUJ2GG\SSXTK4J2TIJ.EXE
### eCadeauHedi Setup Tounsi
eCadeauHedi 6.9
!$*"C:\Users\USER\AppData\Roaming\ugioauuj2gg\ssxtk4j2tij.exe" /VERYSILENT
[Running Processes] :HKLM C:\USERS\USER\APPDATA\LOCAL\TEMP\IS-
HSERE.TMP\SSXTK4J2TIJ.TMP
### Setup/Uninstall !$*"C:\Users\USER\AppData\Local\Temp\is-
HSERE.tmp\ssxtk4j2tij.tmp"
/SL5="$30260,556304,72192,C:\Users\USER\AppData\Roaming\ugioauuj2gg\ssxtk4j2tij.exe
" /VERYSILENT
[Running Processes] :HKLM C:\PROGRAM FILES (X86)\MICROSOFT
OFFICE\OFFICE15\ONENOTEM.EXE
### Send to OneNote Tool Microsoft Corporation Microsoft OneNote
15.0.4420.1017 !$*"C:\Program Files (x86)\Microsoft
Office\Office15\ONENOTEM.EXE" /tsr
[Running Processes] :HKLM C:\PROGRAM FILES (X86)\WINAMP\WINAMPA.EXE
### Winamp Agent Nullsoft, Inc. Winamp Agent 5.5.8.2985 !$*"C:\Program Files
(x86)\Winamp\winampa.exe"
[Running Processes] :HKLM C:\PROGRAM FILES (X86)\CYBERLINK\YOUCAM\YCMMIRAGE.EXE
### YouCam Mirage CyberLink YCMMirag Application 1.0.0.629 !$*"C:\Program Files
(x86)\CyberLink\YouCam\YCMMirage.exe"
[Running Processes] :HKLM C:\PROGRAM FILES (X86)\CYBERLINK\YOUCAM\YOUCAMTRAY.EXE
### CyberLink YouCam Tray CyberLink Corp. CyberLink YouCam Tray 4.0.0.0820 !
$*"C:\Program Files (x86)\CyberLink\YouCam\YouCamTray.exe" /s
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\CMD.EXE
### Windows Command Processor Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*C:\WINDOWS\system32\cmd.exe /c
""C:\Users\USER\AppData\Roaming\system\2.cmd" "
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\CONHOST.EXE
### Console Window Host Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*\??\C:\WINDOWS\system32\conhost.exe 0x4
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\CMD.EXE
### Windows Command Processor Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*C:\WINDOWS\system32\cmd.exe /c
""C:\Users\USER\AppData\Roaming\system\1.cmd" "
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\CONHOST.EXE
### Console Window Host Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0 !$*\??\C:\WINDOWS\system32\conhost.exe 0x4
[Running Processes] :HKLM C:\USERS\USER\APPDATA\ROAMING\SYSTEM\SYSTEMCARE.EXE
### !$*systemcare.exe -I 20 -H sia-eu1.nanopool.org:9980 -Q
"address=e86d24e388b2c1668569c2b867d1790f0fb529d1a77c7ec4116ae14adef3a2e9797c757688
2f"
[Running Processes] :HKLM C:\USERS\USER\APPDATA\ROAMING\SYSTEM\WINDOWS.EXE
### system updater windows windows.exe 2.4.0 !$*windows -a cryptonight -o
stratum+tcp://xmr-usa.dwarfpool.com:8005 -u
47Q6vnXonJP2NY81etbgKu1VaeQcB3qPQebFQtvsz7ZrjQqrhmqp9oCA1vjH1QRXLKGgRCuxi8UExRVbtGs
iqUSb6LA7Pjp -p x -t 2
[Running Processes] :HKLM C:\PROGRAM FILES (X86)\ASUS\ASUS SMART
GESTURE\ASTPCENTER\X64\ASUSTPCENTER.EXE
### ASUS Smart Gesture Center AsusTek ASUS Smart Gesture 1.0.0.87 !$*"C:\Program
Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe"
[Running Processes] :HKLM C:\PROGRAM FILES (X86)\ASUS\ASUS SMART
GESTURE\ASTPCENTER\X64\ASUSTPHELPER.EXE
### ASUS Smart Gesture Helper AsusTek ASUS Smart Gesture Helper 1.0.22.0 !
$*"C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe"
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SEARCHPROTOCOLHOST.EXE
### Microsoft Windows Search Protocol Host Microsoft Corporation Windows� Search
7.0.14393.1770 !$*"C:\WINDOWS\system32\SearchProtocolHost.exe"
Global\UsGthrFltPipeMssGthrPipe3_ Global\UsGthrCtrlFltPipeMssGthrPipe3 1
-2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0;
Windows NT; MS Search 4.0 Robot)"
"C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
[Running Processes] :HKLM C:\PROGRAM FILES (X86)\UNHACKME\UNHACKME.EXE
### Detects and removes rootkits Greatis Software UnHackMe 9.30 !$*"C:\Program
Files (x86)\UnHackMe\Unhackme.exe"
[Running Processes] :HKLM C:\PROGRAM FILES (X86)\UNHACKME\HACKMON.EXE
### Detects Rootkits in background Greatis Software UnHackMe 8.50 !$*"C:\Program
Files (x86)\UnHackMe\hackmon.exe"
[Running Processes] :HKLM C:\PROGRAM FILES (X86)\UNHACKME\REANIMATOR.EXE
### RegRun Start Control Greatis Software RegRun Security Suite 9.30 !
$*"C:\Program Files (x86)\UnHackMe\reanimator.exe" /wiz /full /malw
[Running Processes] :HKLM C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\FIREFOX.EXE
### Firefox Mozilla Corporation Firefox 56.0 !$*"C:\Program Files (x86)\Mozilla
Firefox\firefox.exe" -osint -url
"http://laserveradedomaina.com/redirect/57a764d042bf8/"
[Running Processes] :HKLM C:\PROGRAM FILES (X86)\UNHACKME\REANIMATOR.EXE
### RegRun Start Control Greatis Software RegRun Security Suite 9.30 !
$*"C:\Program Files (x86)\UnHackMe\reanimator.exe" /wiz /full /malw
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\TASKHOSTW.EXE
### Host Process for Windows Tasks Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0 !$*taskhostw.exe
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SEARCHFILTERHOST.EXE
### Microsoft Windows Search Filter Host Microsoft Corporation Windows� Search
7.0.14393.953 !$*"C:\WINDOWS\system32\SearchFilterHost.exe" 0 676 680 688 8192 684

[Running Processes] :HKLM C:\PROGRAM FILES (X86)\UNHACKME\REGRUNINFO.EXE


### Module for retrieving file info from Internet Greatis Software RegRun
Security Suite 9.30 !$*"C:\Program Files (x86)\UnHackMe\regruninfo.exe"
C:\Users\USER\DOCUME~1\RegRun2\regrunlog.txt /hid: "2017-10-19-11:30:05 On-line
Multi-Antivirus Scanning...." /mal: C:\Users\USER\DOCUME~1\RegRun2\
[Running Processes] :HKLM C:\PROGRAM FILES (X86)\UNHACKME\REGRUNINFO.EXE
### Module for retrieving file info from Internet Greatis Software RegRun
Security Suite 9.30 !$*"C:\Program Files (x86)\UnHackMe\regruninfo.exe"
C:\Users\USER\DOCUME~1\RegRun2\regrunlog.txt /hid: "2017-10-19-11:29:57 On-line
Multi-Antivirus Scanning...." /mal: C:\Users\USER\DOCUME~1\RegRun2\
[Running Processes] :HKLM C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\FIREFOX.EXE
### Firefox Mozilla Corporation Firefox 56.0 !$*"C:\Program Files (x86)\Mozilla
Firefox\firefox.exe" -contentproc --channel="6028.6.492914391\787385869" -childID 2
-isForBrowser -intPrefs 5:50|6:-1|28:1000|33:20|34:10|43:128|44:10000|49:0|51:400|
52:1|53:0|54:0|59:0|60:120|61:120|92:2|93:1|107:5000|118:0|120:0|131:10000|143:-1|
148:128|149:10000|150:0|156:24|157:32768|159:0|160:0|168:5|172:1048576|173:100|
174:5000|176:600|178:1|187:3|191:0|201:60000| -boolPrefs 1:0|2:0|4:0|26:1|27:1|
30:0|35:1|36:0|37:0|38:0|41:1|42:1|45:0|46:0|47:0|48:0|50:0|55:1|56:1|57:0|58:1|
62:1|63:1|64:0|65:1|66:1|67:0|68:1|71:0|72:0|75:1|76:1|80:1|81:1|82:1|83:0|84:0|
86:0|87:0|88:1|89:0|94:1|95:0|101:0|106:0|109:1|110:1|113:1|115:1|119:0|122:1|
125:1|126:1|132:0|133:0|134:1|136:0|142:0|144:1|145:0|146:1|147:0|154:0|155:0|
158:1|161:0|163:1|165:1|166:0|171:0|175:1|180:0|181:0|182:0|183:1|184:0|185:0|
186:1|189:0|193:0|194:0|195:1|196:1|197:0|198:1|199:1|200:1|202:0|203:0|205:0|
213:1|214:1|215:0|216:0|217:0| -stringPrefs "3:7;release|135:3;1.0|152:332;
����!???:?????%???????? ???????-��?????????
��?/???????????????/:?????????????????? ???????????????????./???????|
153:8;moderate|188:38;{2fb10396-cdd2-4bbd-a0c0-9399f57cf913}|" -greomni "C:\Program
Files (x86)\Mozilla Firefox\omni.ja" -appomni "C:\Program Files (x86)\Mozilla
Firefox\browser\omni.ja" -appdir "C:\Program Files (x86)\Mozilla Firefox\browser"
6028 "\\.\pipe\gecko-crash-server-pipe.6028" tab
[Running Processes] :HKLM C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\FIREFOX.EXE
### Firefox Mozilla Corporation Firefox 56.0 !$*"C:\Program Files (x86)\Mozilla
Firefox\firefox.exe" -contentproc --channel="6028.12.755016541\1779534691" -childID
3 -isForBrowser -intPrefs 5:50|6:-1|28:1000|33:20|34:10|43:128|44:10000|49:0|
51:400|52:1|53:0|54:0|59:0|60:120|61:120|92:2|93:1|107:5000|118:0|120:0|131:10000|
143:-1|148:128|149:10000|150:0|156:24|157:32768|159:0|160:0|168:5|172:1048576|
173:100|174:5000|176:600|178:1|187:3|191:0|201:60000| -boolPrefs 1:0|2:0|4:0|26:1|
27:1|30:0|35:1|36:0|37:0|38:0|41:1|42:1|45:0|46:0|47:0|48:0|50:0|55:1|56:1|57:0|
58:1|62:1|63:1|64:0|65:1|66:1|67:0|68:1|71:0|72:0|75:1|76:1|80:1|81:1|82:1|83:0|
84:0|86:0|87:0|88:1|89:0|94:1|95:0|101:0|106:0|109:1|110:1|113:1|115:1|119:0|122:1|
125:1|126:1|132:0|133:0|134:1|136:0|142:0|144:1|145:0|146:1|147:0|154:0|155:0|
158:1|161:0|163:1|165:1|166:0|171:0|175:1|180:0|181:0|182:0|183:1|184:0|185:0|
186:1|189:0|193:0|194:0|195:1|196:1|197:0|198:1|199:1|200:1|202:0|203:0|205:0|
213:1|214:1|215:0|216:0|217:0| -stringPrefs "3:7;release|135:3;1.0|152:332;
����!???:?????%???????? ???????-��?????????
��?/???????????????/:?????????????????? ???????????????????./???????|
153:8;moderate|188:38;{2fb10396-cdd2-4bbd-a0c0-9399f57cf913}|" -greomni "C:\Program
Files (x86)\Mozilla Firefox\omni.ja" -appomni "C:\Program Files (x86)\Mozilla
Firefox\browser\omni.ja" -appdir "C:\Program Files (x86)\Mozilla Firefox\browser"
6028 "\\.\pipe\gecko-crash-server-pipe.6028" tab
[Running Processes] :HKLM C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\FIREFOX.EXE
### Firefox Mozilla Corporation Firefox 56.0 !$*"C:\Program Files (x86)\Mozilla
Firefox\firefox.exe" -contentproc --channel="6028.18.519968372\2034278413" -childID
4 -isForBrowser -intPrefs 5:50|6:-1|28:1000|33:20|34:10|43:128|44:10000|49:0|
51:400|52:1|53:0|54:0|59:0|60:120|61:120|92:2|93:1|107:5000|118:0|120:0|131:10000|
143:-1|148:128|149:10000|150:0|156:24|157:32768|159:0|160:0|168:5|172:1048576|
173:100|174:5000|176:600|178:1|187:3|191:0|201:60000| -boolPrefs 1:0|2:0|4:0|26:1|
27:1|30:0|35:1|36:0|37:0|38:0|41:1|42:1|45:0|46:0|47:0|48:0|50:0|55:1|56:1|57:0|
58:1|62:1|63:1|64:0|65:1|66:1|67:0|68:1|71:0|72:0|75:1|76:1|80:1|81:1|82:1|83:0|
84:0|86:0|87:0|88:1|89:0|94:1|95:0|101:0|106:0|109:1|110:1|113:1|115:1|119:0|122:1|
125:1|126:1|132:0|133:0|134:1|136:0|142:0|144:1|145:0|146:1|147:0|154:0|155:0|
158:1|161:0|163:1|165:1|166:0|171:0|175:1|180:0|181:0|182:0|183:1|184:0|185:0|
186:1|189:0|193:0|194:0|195:1|196:1|197:0|198:1|199:1|200:1|202:0|203:0|205:0|
213:1|214:1|215:0|216:0|217:0| -stringPrefs "3:7;release|135:3;1.0|152:332;
����!???:?????%???????? ???????-��?????????
��?/???????????????/:?????????????????? ???????????????????./???????|
153:8;moderate|188:38;{2fb10396-cdd2-4bbd-a0c0-9399f57cf913}|" -greomni "C:\Program
Files (x86)\Mozilla Firefox\omni.ja" -appomni "C:\Program Files (x86)\Mozilla
Firefox\browser\omni.ja" -appdir "C:\Program Files (x86)\Mozilla Firefox\browser"
6028 "\\.\pipe\gecko-crash-server-pipe.6028" tab
[Running Processes] :HKLM C:\PROGRAM FILES (X86)\UNHACKME\REANIMATOR.EXE
### RegRun Start Control Greatis Software RegRun Security Suite 9.30 !
$*"C:\Program Files (x86)\UnHackMe\reanimator.exe" /help
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\WBEM\WMIPRVSE.EXE
### WMI Provider Host Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0 !$*C:\WINDOWS\system32\wbem\wmiprvse.exe
[Running Services] AdobeARMservice
### Internal Name: AdobeARMservice. Status: service is running. Actual File:
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe" * Adobe Acrobat
Updater keeps your Adobe software up to date. Adobe Acrobat Update Service Adobe
Systems Incorporated Adobe Acrobat Update Service 1, 5, 5, 0
[Running Services] Appinfo
### Internal Name: Appinfo. Status: service is running. Actual File:
C:\WINDOWS\system32\svchost.exe -k netsvcs * Facilitates the running of interactive
applications with additional administrative privileges. If this service is
stopped, users will be unable to launch applications with the additional
administrative privileges they may require to perform desired user tasks. Host
Process for Windows Services Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0
[Running Services] ASLDRService
### Internal Name: ASLDRService. Status: service is running. Actual File:
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe * ASLDR Service
ASUSTek Computer Inc. ATK Hotkey 1, 0, 81, 0
[Running Services] AudioEndpointBuilder
### Internal Name: AudioEndpointBuilder. Status: service is running. Actual File:
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted * Manages audio
devices for the Windows Audio service. If this service is stopped, audio devices
and effects will not function properly. If this service is disabled, any services
that explicitly depend on it will fail to start Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0
[Running Services] Audiosrv
### Internal Name: Audiosrv. Status: service is running. Actual File:
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted * Manages audio
for Windows-based programs. If this service is stopped, audio devices and effects
will not function properly. If this service is disabled, any services that
explicitly depend on it will fail to start Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0
[Running Services] BFE
### Internal Name: BFE. Status: service is running. Actual File:
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork * The Base Filtering
Engine (BFE) is a service that manages firewall and Internet Protocol security
(IPsec) policies and implements user mode filtering. Stopping or disabling the BFE
service will significantly reduce the security of the system. It will also result
in unpredictable behavior in IPsec management and firewall applications. Host
Process for Windows Services Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0
[Running Services] BITS
### Internal Name: BITS. Status: service is running. Actual File:
C:\WINDOWS\System32\svchost.exe -k netsvcs * Transfers files in the background
using idle network bandwidth. If the service is disabled, then any applications
that depend on BITS, such as Windows Update or MSN Explorer, will be unable to
automatically download programs and other information. Host Process for Windows
Services Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0
[Running Services] BrokerInfrastructure
### Internal Name: BrokerInfrastructure. Status: service is running. Actual File:
C:\WINDOWS\system32\svchost.exe -k DcomLaunch * Windows infrastructure service that
controls which background tasks can run on the system. Host Process for Windows
Services Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0
[Running Services] Browser
### Internal Name: Browser. Status: service is running. Actual File:
C:\WINDOWS\System32\svchost.exe -k netsvcs * Maintains an updated list of computers
on the network and supplies this list to computers designated as browsers. If this
service is stopped, this list will not be updated or maintained. If this service is
disabled, any services that explicitly depend on it will fail to start. Host
Process for Windows Services Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0
[Running Services] bthserv
### Internal Name: bthserv. Status: service is running. Actual File:
C:\WINDOWS\system32\svchost.exe -k LocalService * The Bluetooth service supports
discovery and association of remote Bluetooth devices. Stopping or disabling this
service may cause already installed Bluetooth devices to fail to operate properly
and prevent new devices from being discovered or associated. Host Process for
Windows Services Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0
[Running Services] CDPSvc
### Internal Name: CDPSvc. Status: service is running. Actual File:
C:\WINDOWS\system32\svchost.exe -k LocalService * This service is used for
Connected Devices and Universal Glass scenarios Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0
[Running Services] CoreMessagingRegistrar
### Internal Name: CoreMessagingRegistrar. Status: service is running. Actual
File: C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork * Manages
communication between system components. Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0
[Running Services] CryptSvc
### Internal Name: CryptSvc. Status: service is running. Actual File:
C:\WINDOWS\system32\svchost.exe -k NetworkService * Provides three management
services: Catalog Database Service, which confirms the signatures of Windows files
and allows new programs to be installed; Protected Root Service, which adds and
removes Trusted Root Certification Authority certificates from this computer; and
Automatic Root Certificate Update Service, which retrieves root certificates from
Windows Update and enable scenarios such as SSL. If this service is stopped, these
management services will not function properly. If this service is disabled, any
services that explicitly depend on it will fail to start. Host Process for Windows
Services Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0
[Running Services] DcomLaunch
### Internal Name: DcomLaunch. Status: service is running. Actual File:
C:\WINDOWS\system32\svchost.exe -k DcomLaunch * The DCOMLAUNCH service launches COM
and DCOM servers in response to object activation requests. If this service is
stopped or disabled, programs using COM or DCOM will not function properly. It is
strongly recommended that you have the DCOMLAUNCH service running. Host Process for
Windows Services Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0
[Running Services] DeviceAssociationService
### Internal Name: DeviceAssociationService. Status: service is running. Actual
File: C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted * Enables
pairing between the system and wired or wireless devices. Host Process for Windows
Services Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0
[Running Services] Dhcp
### Internal Name: Dhcp. Status: service is running. Actual File:
C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted * Registers and
updates IP addresses and DNS records for this computer. If this service is stopped,
this computer will not receive dynamic IP addresses and DNS updates. If this
service is disabled, any services that explicitly depend on it will fail to start.
Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0
[Running Services] DiagTrack
### Internal Name: DiagTrack. Status: service is running. Actual File:
C:\WINDOWS\System32\svchost.exe -k utcsvc * The Connected User Experiences and
Telemetry service enables features that support in-application and connected user
experiences. Additionally, this service manages the event driven collection and
transmission of diagnostic and usage information (used to improve the experience
and quality of the Windows Platform) when the diagnostics and usage privacy option
settings are enabled under Feedback and Diagnostics. Host Process for Windows
Services Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0
[Running Services] Dnscache
### Internal Name: Dnscache. Status: service is running. Actual File:
C:\WINDOWS\system32\svchost.exe -k NetworkService * The DNS Client service
(dnscache) caches Domain Name System (DNS) names and registers the full computer
name for this computer. If the service is stopped, DNS names will continue to be
resolved. However, the results of DNS name queries will not be cached and the
computer's name will not be registered. If the service is disabled, any services
that explicitly depend on it will fail to start. Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0
[Running Services] DPS
### Internal Name: DPS. Status: service is running. Actual File:
C:\WINDOWS\System32\svchost.exe -k LocalServiceNoNetwork * The Diagnostic Policy
Service enables problem detection, troubleshooting and resolution for Windows
components. If this service is stopped, diagnostics will no longer function. Host
Process for Windows Services Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0
[Running Services] DptfParticipantProcessorService
### Internal Name: DptfParticipantProcessorService. Status: service is running.
Actual File: C:\WINDOWS\system32\DptfParticipantProcessorService.exe * Intel(R)
Dynamic Platform and Thermal Framework Processor Participant Service Application
Intel(R) Dynamic Platform and Thermal Framework Processor Participant Service Intel
Corporation Intel(R) Dynamic Platform and Thermal Framework 7.1.0.2106
[Running Services] DptfPolicyConfigTDPService
### Internal Name: DptfPolicyConfigTDPService. Status: service is running. Actual
File: C:\WINDOWS\system32\DptfPolicyConfigTDPService.exe * Intel(R) Dynamic
Platform and Thermal Framework Config TDP Service Application Intel(R) Dynamic
Platform and Thermal Framework Config TDP Policy Service Intel Corporation Intel(R)
Dynamic Platform and Thermal Framework 7.1.0.2106
[Running Services] DptfPolicyLpmService
### Internal Name: DptfPolicyLpmService. Status: service is running. Actual File:
C:\WINDOWS\system32\DptfPolicyLpmService.exe * Intel(R) Dynamic Platform and
Thermal Framework Low Power Mode Service Application Intel(R) Dynamic Platform and
Thermal Framework LPM Policy Service Intel Corporation Intel(R) Dynamic Platform
and Thermal Framework 7.1.0.2106
[Running Services] EventLog
### Internal Name: EventLog. Status: service is running. Actual File:
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted * This service
manages events and event logs. It supports logging events, querying events,
subscribing to events, archiving event logs, and managing event metadata. It can
display events in both XML and plain text format. Stopping this service may
compromise security and reliability of the system. Host Process for Windows
Services Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0
[Running Services] EventSystem
### Internal Name: EventSystem. Status: service is running. Actual File:
C:\WINDOWS\system32\svchost.exe -k LocalService * Supports System Event
Notification Service (SENS), which provides automatic distribution of events to
subscribing Component Object Model (COM) components. If the service is stopped,
SENS will close and will not be able to provide logon and logoff notifications. If
this service is disabled, any services that explicitly depend on it will fail to
start. Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0
[Running Services] FontCache
### Internal Name: FontCache. Status: service is running. Actual File:
C:\WINDOWS\system32\svchost.exe -k LocalService * Optimizes performance of
applications by caching commonly used font data. Applications will start this
service if it is not already running. It can be disabled, though doing so will
degrade application performance. Host Process for Windows Services Microsoft
Corporation Microsoft� Windows� Operating System 10.0.14393.0
[Running Services] HWDeviceService64.exe
### Internal Name: HWDeviceService64.exe. Status: service is running. Actual
File: "C:\ProgramData\DatacardService\HWDeviceService64.exe" -/service * Service
for runing Mobile applications autorun. DCSHOST HWDeviceService 2, 0, 0, 47
[Running Services] igfxCUIService2.0.0.0
### Internal Name: igfxCUIService2.0.0.0. Status: service is running. Actual
File: C:\WINDOWS\system32\igfxCUIService.exe * Service for Intel(R) HD Graphics
Control Panel igfxCUIService Module Intel Corporation Intel(R) Common User
Interface 6.15.10.4549
[Running Services] IKEEXT
### Internal Name: IKEEXT. Status: service is running. Actual File:
C:\WINDOWS\system32\svchost.exe -k netsvcs * The IKEEXT service hosts the Internet
Key Exchange (IKE) and Authenticated Internet Protocol (AuthIP) keying modules.
These keying modules are used for authentication and key exchange in Internet
Protocol security (IPsec). Stopping or disabling the IKEEXT service will disable
IKE and AuthIP key exchange with peer computers. IPsec is typically configured to
use IKE or AuthIP; therefore, stopping or disabling the IKEEXT service might result
in an IPsec failure and might compromise the security of the system. It is strongly
recommended that you have the IKEEXT service running. Host Process for Windows
Services Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0
[Running Services] iphlpsvc
### Internal Name: iphlpsvc. Status: service is running. Actual File:
C:\WINDOWS\System32\svchost.exe -k NetSvcs * Provides tunnel connectivity using
IPv6 transition technologies (6to4, ISATAP, Port Proxy, and Teredo), and IP-HTTPS.
If this service is stopped, the computer will not have the enhanced connectivity
benefits that these technologies offer. Host Process for Windows Services Microsoft
Corporation Microsoft� Windows� Operating System 10.0.14393.0
[Running Services] KeyIso
### Internal Name: KeyIso. Status: service is running. Actual File:
C:\WINDOWS\system32\lsass.exe * The CNG key isolation service is hosted in the LSA
process. The service provides key process isolation to private keys and associated
cryptographic operations as required by the Common Criteria. The service stores and
uses long-lived keys in a secure process complying with Common Criteria
requirements. Local Security Authority Process Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.1770
[Running Services] LanmanServer
### Internal Name: LanmanServer. Status: service is running. Actual File:
C:\WINDOWS\system32\svchost.exe -k netsvcs * Supports file, print, and named-pipe
sharing over the network for this computer. If this service is stopped, these
functions will be unavailable. If this service is disabled, any services that
explicitly depend on it will fail to start. Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0
[Running Services] LanmanWorkstation
### Internal Name: LanmanWorkstation. Status: service is running. Actual File:
C:\WINDOWS\System32\svchost.exe -k NetworkService * Creates and maintains client
network connections to remote servers using the SMB protocol. If this service is
stopped, these connections will be unavailable. If this service is disabled, any
services that explicitly depend on it will fail to start. Host Process for Windows
Services Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0
[Running Services] LicenseManager
### Internal Name: LicenseManager. Status: service is running. Actual File:
C:\WINDOWS\System32\svchost.exe -k LocalService * Provides infrastructure support
for the Windows Store. This service is started on demand and if disabled then
content acquired through the Windows Store will not function properly. Host Process
for Windows Services Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0
[Running Services] LSM
### Internal Name: LSM. Status: service is running. Actual File:
C:\WINDOWS\system32\svchost.exe -k DcomLaunch * Core Windows Service that manages
local user sessions. Stopping or disabling this service will result in system
instability. Host Process for Windows Services Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0
[Running Services] MpsSvc
### Internal Name: MpsSvc. Status: service is running. Actual File:
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork * Windows Firewall helps
protect your computer by preventing unauthorized users from gaining access to your
computer through the Internet or a network. Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0
[Running Services] NcbService
### Internal Name: NcbService. Status: service is running. Actual File:
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted * Brokers
connections that allow Windows Store Apps to receive notifications from the
internet. Host Process for Windows Services Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0
[Running Services] Netman
### Internal Name: Netman. Status: service is running. Actual File:
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted * Manages objects
in the Network and Dial-Up Connections folder, in which you can view both local
area network and remote connections. Host Process for Windows Services Microsoft
Corporation Microsoft� Windows� Operating System 10.0.14393.0
[Running Services] netprofm
### Internal Name: netprofm. Status: service is running. Actual File:
C:\WINDOWS\System32\svchost.exe -k LocalService * Identifies the networks to which
the computer has connected, collects and stores properties for these networks, and
notifies applications when these properties change. Host Process for Windows
Services Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0
[Running Services] NlaSvc
### Internal Name: NlaSvc. Status: service is running. Actual File:
C:\WINDOWS\System32\svchost.exe -k NetworkService * Collects and stores
configuration information for the network and notifies programs when this
information is modified. If this service is stopped, configuration information
might be unavailable. If this service is disabled, any services that explicitly
depend on it will fail to start. Host Process for Windows Services Microsoft
Corporation Microsoft� Windows� Operating System 10.0.14393.0
[Running Services] NMIndexingService
### Internal Name: NMIndexingService. Status: service is running. Actual File:
"C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe" * Nero Home
Nero AG Nero Home 2,0,16,0
[Running Services] nsi
### Internal Name: nsi. Status: service is running. Actual File:
C:\WINDOWS\system32\svchost.exe -k LocalService * This service delivers network
notifications (e.g. interface addition/deleting etc) to user mode clients. Stopping
this service will cause loss of network connectivity. If this service is disabled,
any other services that explicitly depend on this service will fail to start. Host
Process for Windows Services Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0
[Running Services] nvsvc
### Internal Name: nvsvc. Status: service is running. Actual File:
"C:\WINDOWS\system32\nvvsvc.exe" * Provides system and desktop level support to the
NVIDIA display driver NVIDIA Driver Helper Service, Version 359.46 NVIDIA
Corporation NVIDIA Driver Helper Service, Version 359.46 8.17.13.5946
[Running Services] pbamw_service
### Internal Name: pbamw_service. Status: service is running. Actual File:
"C:\Program Files\Plumbytes Software\Plumbytes Anti-Malware\AmwService.exe" run *
Plumbytes Anti-Malware Service Antimalware service PLUMBYTES PLUMBYTES Anti malware
0.9.0.634
[Running Services] PcaSvc
### Internal Name: PcaSvc. Status: service is running. Actual File:
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted * This service
provides support for the Program Compatibility Assistant (PCA). PCA monitors
programs installed and run by the user and detects known compatibility problems. If
this service is stopped, PCA will not function properly. Host Process for Windows
Services Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0
[Running Services] PlugPlay
### Internal Name: PlugPlay. Status: service is running. Actual File:
C:\WINDOWS\system32\svchost.exe -k DcomLaunch * Enables a computer to recognize and
adapt to hardware changes with little or no user input. Stopping or disabling this
service will result in system instability. Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0
[Running Services] PolicyAgent
### Internal Name: PolicyAgent. Status: service is running. Actual File:
C:\WINDOWS\system32\svchost.exe -k NetworkServiceNetworkRestricted * Internet
Protocol security (IPsec) supports network-level peer authentication, data origin
authentication, data integrity, data confidentiality (encryption), and replay
protection. This service enforces IPsec policies created through the IP Security
Policies snap-in or the command-line tool "netsh ipsec". If you stop this service,
you may experience network connectivity issues if your policy requires that
connections use IPsec. Also,remote management of Windows Firewall is not available
when this service is stopped. Host Process for Windows Services Microsoft
Corporation Microsoft� Windows� Operating System 10.0.14393.0
[Running Services] Power
### Internal Name: Power. Status: service is running. Actual File:
C:\WINDOWS\system32\svchost.exe -k DcomLaunch * Manages power policy and power
policy notification delivery. Host Process for Windows Services Microsoft
Corporation Microsoft� Windows� Operating System 10.0.14393.0
[Running Services] ProfSvc
### Internal Name: ProfSvc. Status: service is running. Actual File:
C:\WINDOWS\system32\svchost.exe -k netsvcs * This service is responsible for
loading and unloading user profiles. If this service is stopped or disabled, users
will no longer be able to successfully sign in or sign out, apps might have
problems getting to users' data, and components registered to receive profile event
notifications won't receive them. Host Process for Windows Services Microsoft
Corporation Microsoft� Windows� Operating System 10.0.14393.0
[Running Services] RpcEptMapper
### Internal Name: RpcEptMapper. Status: service is running. Actual File:
C:\WINDOWS\system32\svchost.exe -k RPCSS * Resolves RPC interfaces identifiers to
transport endpoints. If this service is stopped or disabled, programs using Remote
Procedure Call (RPC) services will not function properly. Host Process for Windows
Services Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0
[Running Services] RpcSs
### Internal Name: RpcSs. Status: service is running. Actual File:
C:\WINDOWS\system32\svchost.exe -k rpcss * The RPCSS service is the Service Control
Manager for COM and DCOM servers. It performs object activations requests, object
exporter resolutions and distributed garbage collection for COM and DCOM servers.
If this service is stopped or disabled, programs using COM or DCOM will not
function properly. It is strongly recommended that you have the RPCSS service
running. Host Process for Windows Services Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0
[Running Services] SamSs
### Internal Name: SamSs. Status: service is running. Actual File:
C:\WINDOWS\system32\lsass.exe * The startup of this service signals other services
that the Security Accounts Manager (SAM) is ready to accept requests. Disabling
this service will prevent other services in the system from being notified when the
SAM is ready, which may in turn cause those services to fail to start correctly.
This service should not be disabled. Local Security Authority Process Microsoft
Corporation Microsoft� Windows� Operating System 10.0.14393.1770
[Running Services] Schedule
### Internal Name: Schedule. Status: service is running. Actual File:
C:\WINDOWS\system32\svchost.exe -k netsvcs * Enables a user to configure and
schedule automated tasks on this computer. The service also hosts multiple Windows
system-critical tasks. If this service is stopped or disabled, these tasks will not
be run at their scheduled times. If this service is disabled, any services that
explicitly depend on it will fail to start. Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0
[Running Services] SENS
### Internal Name: SENS. Status: service is running. Actual File:
C:\WINDOWS\system32\svchost.exe -k netsvcs * Monitors system events and notifies
subscribers to COM+ Event System of these events. Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0
[Running Services] ShellHWDetection
### Internal Name: ShellHWDetection. Status: service is running. Actual File:
C:\WINDOWS\System32\svchost.exe -k netsvcs * Provides notifications for AutoPlay
hardware events. Host Process for Windows Services Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0
[Running Services] Spooler
### Internal Name: Spooler. Status: service is running. Actual File:
C:\WINDOWS\System32\spoolsv.exe * This service spools print jobs and handles
interaction with the printer. If you turn off this service, you won�t be able to
print or see your printers. Spooler SubSystem App Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0
[Running Services] SSDPSRV
### Internal Name: SSDPSRV. Status: service is running. Actual File:
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation * Discovers
networked devices and services that use the SSDP discovery protocol, such as UPnP
devices. Also announces SSDP devices and services running on the local computer. If
this service is stopped, SSDP-based devices will not be discovered. If this service
is disabled, any services that explicitly depend on it will fail to start. Host
Process for Windows Services Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0
[Running Services] StateRepository
### Internal Name: StateRepository. Status: service is running. Actual File:
C:\WINDOWS\system32\svchost.exe -k appmodel * Provides required infrastructure
support for the application model. Host Process for Windows Services Microsoft
Corporation Microsoft� Windows� Operating System 10.0.14393.0
[Running Services] stisvc
### Internal Name: stisvc. Status: service is running. Actual File:
C:\WINDOWS\system32\svchost.exe -k imgsvc * Provides image acquisition services for
scanners and cameras Host Process for Windows Services Microsoft Corporation
Microsoft� Windows� Operating System 10.0.14393.0
[Running Services] SysMain
### Internal Name: SysMain. Status: service is running. Actual File:
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted * Maintains and
improves system performance over time. Host Process for Windows Services Microsoft
Corporation Microsoft� Windows� Operating System 10.0.14393.0
[Running Services] SystemEventsBroker
### Internal Name: SystemEventsBroker. Status: service is running. Actual File:
C:\WINDOWS\system32\svchost.exe -k DcomLaunch * Coordinates execution of background
work for WinRT application. If this service is stopped or disabled, then background
work might not be triggered. Host Process for Windows Services Microsoft
Corporation Microsoft� Windows� Operating System 10.0.14393.0
[Running Services] Themes
### Internal Name: Themes. Status: service is running. Actual File:
C:\WINDOWS\System32\svchost.exe -k netsvcs * Provides user experience theme
management. Host Process for Windows Services Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0
[Running Services] tiledatamodelsvc
### Internal Name: tiledatamodelsvc. Status: service is running. Actual File:
C:\WINDOWS\system32\svchost.exe -k appmodel * Tile Server for tile updates. Host
Process for Windows Services Microsoft Corporation Microsoft� Windows� Operating
System 10.0.14393.0
[Running Services] TimeBrokerSvc
### Internal Name: TimeBrokerSvc. Status: service is running. Actual File:
C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted * Coordinates
execution of background work for WinRT application. If this service is stopped or
disabled, then background work might not be triggered. Host Process for Windows
Services Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0
[Running Services] TrkWks
### Internal Name: TrkWks. Status: service is running. Actual File:
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted * Maintains links
between NTFS files within a computer or across computers in a network. Host Process
for Windows Services Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0
[Running Services] UserManager
### Internal Name: UserManager. Status: service is running. Actual File:
C:\WINDOWS\system32\svchost.exe -k netsvcs * User Manager provides the runtime
components required for multi-user interaction. If this service is stopped, some
applications may not operate correctly. Host Process for Windows Services Microsoft
Corporation Microsoft� Windows� Operating System 10.0.14393.0
[Running Services] VaultSvc
### Internal Name: VaultSvc. Status: service is running. Actual File:
C:\WINDOWS\system32\lsass.exe * Provides secure storage and retrieval of
credentials to users, applications and security service packages. Local Security
Authority Process Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.1770
[Running Services] Wcmsvc
### Internal Name: Wcmsvc. Status: service is running. Actual File:
C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted * Makes automatic
connect/disconnect decisions based on the network connectivity options currently
available to the PC and enables management of network connectivity based on Group
Policy settings. Host Process for Windows Services Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0
[Running Services] WdiServiceHost
### Internal Name: WdiServiceHost. Status: service is running. Actual File:
C:\WINDOWS\System32\svchost.exe -k LocalService * The Diagnostic Service Host is
used by the Diagnostic Policy Service to host diagnostics that need to run in a
Local Service context. If this service is stopped, any diagnostics that depend on
it will no longer function. Host Process for Windows Services Microsoft Corporation
Microsoft� Windows� Operating System 10.0.14393.0
[Running Services] WdiSystemHost
### Internal Name: WdiSystemHost. Status: service is running. Actual File:
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted * The Diagnostic
System Host is used by the Diagnostic Policy Service to host diagnostics that need
to run in a Local System context. If this service is stopped, any diagnostics that
depend on it will no longer function. Host Process for Windows Services Microsoft
Corporation Microsoft� Windows� Operating System 10.0.14393.0
[Running Services] WdNisSvc
### Internal Name: WdNisSvc. Status: service is running. Actual File: "C:\Program
Files\Windows Defender\NisSrv.exe" * Helps guard against intrusion attempts
targeting known and newly discovered vulnerabilities in network protocols Microsoft
Network Realtime Inspection Service Microsoft Corporation Microsoft� Windows�
Operating System 4.10.14393.1198
[Running Services] WinDefend
### Internal Name: WinDefend. Status: service is running. Actual File:
"C:\Program Files\Windows Defender\MsMpEng.exe" * Helps protect users from malware
and other potentially unwanted software Antimalware Service Executable Microsoft
Corporation Microsoft� Windows� Operating System 4.10.14393.1613
[Running Services] WinHttpAutoProxySvc
### Internal Name: WinHttpAutoProxySvc. Status: service is running. Actual File:
C:\WINDOWS\system32\svchost.exe -k LocalService * WinHTTP implements the client
HTTP stack and provides developers with a Win32 API and COM Automation component
for sending HTTP requests and receiving responses. In addition, WinHTTP provides
support for auto-discovering a proxy configuration via its implementation of the
Web Proxy Auto-Discovery (WPAD) protocol. Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0
[Running Services] Winmgmt
### Internal Name: Winmgmt. Status: service is running. Actual File:
C:\WINDOWS\system32\svchost.exe -k netsvcs * Provides a common interface and object
model to access management information about operating system, devices,
applications and services. If this service is stopped, most Windows-based software
will not function properly. If this service is disabled, any services that
explicitly depend on it will fail to start. Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0
[Running Services] WlanSvc
### Internal Name: WlanSvc. Status: service is running. Actual File:
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted * The WLANSVC
service provides the logic required to configure, discover, connect to, and
disconnect from a wireless local area network (WLAN) as defined by IEEE 802.11
standards. It also contains the logic to turn your computer into a software access
point so that other devices or computers can connect to your computer wirelessly
using a WLAN adapter that can support this. Stopping or disabling the WLANSVC
service will make all WLAN adapters on your computer inaccessible from the Windows
networking UI. It is strongly recommended that you have the WLANSVC service running
if your computer has a WLAN adapter. Host Process for Windows Services Microsoft
Corporation Microsoft� Windows� Operating System 10.0.14393.0
[Running Services] wlidsvc
### Internal Name: wlidsvc. Status: service is running. Actual File:
C:\WINDOWS\system32\svchost.exe -k netsvcs * Enables user sign-in through Microsoft
account identity services. If this service is stopped, users will not be able to
logon to the computer with their Microsoft account. Host Process for Windows
Services Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0
[Running Services] WpnService
### Internal Name: WpnService. Status: service is running. Actual File:
C:\WINDOWS\system32\svchost.exe -k netsvcs * This service runs in session 0 and
hosts the notification platform and connection provider which handles the
connection between the device and WNS server. Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0
[Running Services] WsAppService
### Internal Name: WsAppService. Status: service is running. Actual File:
C:\Program Files (x86)\Wondershare\WAF\2.3.0.5\WsAppService.exe * Wondershare
Application Framework Service Wondershare AppService Wondershare Wondershare App
Framework 2.3.0.5
[Running Services] WSearch
### Internal Name: WSearch. Status: service is running. Actual File:
C:\WINDOWS\system32\SearchIndexer.exe /Embedding * Provides content indexing,
property caching, and search results for files, e-mail, and other content.
Microsoft Windows Search Indexer Microsoft Corporation Windows� Search 7.0.14393.0
[Running Services] wudfsvc
### Internal Name: wudfsvc. Status: service is running. Actual File:
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted * Creates and
manages user-mode driver processes. This service cannot be stopped. Host Process
for Windows Services Microsoft Corporation Microsoft� Windows� Operating System
10.0.14393.0
[Running Services] CDPUserSvc_2e64c
### Internal Name: CDPUserSvc_2e64c. Status: service is running. Actual File:
C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup * Host Process for Windows
Services Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0
[Running Services] OneSyncSvc_2e64c
### Internal Name: OneSyncSvc_2e64c. Status: service is running. Actual File:
C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup * This service synchronizes
mail, contacts, calendar and various other user data. Mail and other applications
dependent on this functionality will not work properly when this service is not
running. Host Process for Windows Services Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0
[Running Services] PimIndexMaintenanceSvc_2e64c
### Internal Name: PimIndexMaintenanceSvc_2e64c. Status: service is running.
Actual File: C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup * Indexes contact
data for fast contact searching. If you stop or disable this service, contacts
might be missing from your search results. Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.14393.0
[Running Services] UnistoreSvc_2e64c
### Internal Name: UnistoreSvc_2e64c. Status: service is running. Actual File:
C:\WINDOWS\System32\svchost.exe -k UnistackSvcGroup * Handles storage of structured
user data, including contact info, calendars, messages, and other content. If you
stop or disable this service, apps that use this data might not work correctly.
Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.14393.0
[Running Services] UserDataSvc_2e64c
### Internal Name: UserDataSvc_2e64c. Status: service is running. Actual File:
C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup * Provides apps access to
structured user data, including contact info, calendars, messages, and other
content. If you stop or disable this service, apps that use this data might not
work correctly. Host Process for Windows Services Microsoft Corporation Microsoft�
Windows� Operating System 10.0.14393.0
[Uninstall]
[Applications] :HKLM UnHackMe_is1="C:\Program Files
(x86)\UnHackMe\unins000.exe" /SILENT
### UnHackMe 9.30 - (19) 10-2017
[Applications] :HKLM Plumbytes Anti-Malware 2017=C:\Program Files\Plumbytes
Software\Plumbytes Anti-Malware\uninstall.exe
### Plumbytes Anti-Malware 2017 - (19) 10-2017
[Applications] :HKLM {0C050BEE-16BE-4998-8959-2A421433DB6E}=MsiExec.exe
/X{0C050BEE-16BE-4998-8959-2A421433DB6E}
### KB4023057 - (19) 10-2017
[Applications] :HKLM
90008f55188b074dfb22b9033f0aae5f=C:\WINDOWS\a93e0bcad6ce0dc5fe3d6cc013ead8ba.exe
### SearchAwesome - (19) 10-2017
[Applications] :HKLM 32183dddab8cbc8b
### - (19) 10-2017
[Applications] :HKLM 20cea4fc503d647c
### - (19) 10-2017
[Applications] :HKLM Mozilla Firefox 56.0 (x86 en-US)="C:\Program Files
(x86)\Mozilla Firefox\uninstall\helper.exe"
### Mozilla Firefox 56.0 (x86 en-US) - (06) 10-2017
[Applications] :HKLM {90150000-0011-0000-0000-0000000FF1CE}=MsiExec.exe
/X{90150000-0011-0000-0000-0000000FF1CE}
### Microsoft Office Professional Plus 2013 - (06) 10-2017
[Applications] :HKCU
OneDriveSetup.exe=C:\Users\USER\AppData\Local\Microsoft\OneDrive\17.3.6998.0830\One
DriveSetup.exe /uninstall
### Microsoft OneDrive - (29) 09-2017
[Applications] :HKLM Instagram Hacker=C:\Program Files (x86)\Instagram
Hacker\Uninstall Instagram Hacker v3.7.2.exe
### Instagram Hacker - (11) 09-2017
[Applications] :HKLM {4D3286A6-F6AB-498A-82A4-E4F040529F3D}=MsiExec.exe
/I{4D3286A6-F6AB-498A-82A4-E4F040529F3D}
### ASUS Smart Gesture - (26) 07-2017
[Applications] :HKLM {4DFCD818-036A-4229-A67D-CF17DC461D92}=MsiExec.exe
/X{4DFCD818-036A-4229-A67D-CF17DC461D92}
### Windows 10 Update and Privacy Settings - (15) 07-2017
[Applications] :HKLM MozillaMaintenanceService="C:\Program Files (x86)\Mozilla
Maintenance Service\uninstall.exe"
### Mozilla Maintenance Service - (13) 07-2017
[Applications] :HKLM EPSON L210
Series=C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YINSI2E.EXE /R /APD /P:"EPSON L210
Series"
### EPSON L210 Series Printer Uninstall - (12) 05-2017
[Applications] :HKLM {FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}=MsiExec.exe
/X{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}
### Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 - (05) 04-2017
[Applications] :HKLM {90150000-006E-0409-0000-0000000FF1CE}=MsiExec.exe
/X{90150000-006E-0409-0000-0000000FF1CE}
### Microsoft Office Shared MUI (English) 2013 - (04) 04-2017
[Applications] :HKLM {90150000-0018-0409-0000-0000000FF1CE}=MsiExec.exe
/X{90150000-0018-0409-0000-0000000FF1CE}
### Microsoft PowerPoint MUI (English) 2013 - (04) 04-2017
[Applications] :HKLM Internet Download Manager 6.26 Build
8=C:\Users\USER\AppData\Local\Temp\Uninstall.exe
### Internet Download Manager 6.26 Build 8 - (02) 04-2017
[Applications] :HKLM {90150000-0090-0409-0000-0000000FF1CE}=MsiExec.exe
/X{90150000-0090-0409-0000-0000000FF1CE}
### Microsoft DCF MUI (English) 2013 - (28) 03-2017
[Applications] :HKLM {90150000-00A1-0409-0000-0000000FF1CE}=MsiExec.exe
/X{90150000-00A1-0409-0000-0000000FF1CE}
### Microsoft OneNote MUI (English) 2013 - (28) 03-2017
[Applications] :HKLM {90150000-00E2-0409-0000-0000000FF1CE}=MsiExec.exe
/X{90150000-00E2-0409-0000-0000000FF1CE}
### Microsoft Office OSM UX MUI (English) 2013 - (28) 03-2017
[Applications] :HKLM {90150000-001A-0409-0000-0000000FF1CE}=MsiExec.exe
/X{90150000-001A-0409-0000-0000000FF1CE}
### Microsoft Outlook MUI (English) 2013 - (28) 03-2017
[Applications] :HKLM {90150000-00BA-0409-0000-0000000FF1CE}=MsiExec.exe
/X{90150000-00BA-0409-0000-0000000FF1CE}
### Microsoft Groove MUI (English) 2013 - (28) 03-2017
[Applications] :HKLM {90150000-00E1-0409-0000-0000000FF1CE}=MsiExec.exe
/X{90150000-00E1-0409-0000-0000000FF1CE}
### Microsoft Office OSM MUI (English) 2013 - (28) 03-2017
[Applications] :HKLM {90150000-001F-0C0A-0000-0000000FF1CE}=MsiExec.exe
/X{90150000-001F-0C0A-0000-0000000FF1CE}
### Microsoft Office Proofing Tools 2013 - Espa�ol - (28) 03-2017
[Applications] :HKLM {90150000-002C-0409-0000-0000000FF1CE}=MsiExec.exe
/X{90150000-002C-0409-0000-0000000FF1CE}
### Microsoft Office Proofing (English) 2013 - (28) 03-2017
[Applications] :HKLM {90150000-0044-0409-0000-0000000FF1CE}=MsiExec.exe
/X{90150000-0044-0409-0000-0000000FF1CE}
### Microsoft InfoPath MUI (English) 2013 - (28) 03-2017
[Applications] :HKLM {90150000-001B-0409-0000-0000000FF1CE}=MsiExec.exe
/X{90150000-001B-0409-0000-0000000FF1CE}
### Microsoft Word MUI (English) 2013 - (28) 03-2017
[Applications] :HKLM {90150000-001F-0409-0000-0000000FF1CE}=MsiExec.exe
/X{90150000-001F-0409-0000-0000000FF1CE}
### Microsoft Office Proofing Tools 2013 - English - (28) 03-2017
[Applications] :HKLM {90150000-001F-040C-0000-0000000FF1CE}=MsiExec.exe
/X{90150000-001F-040C-0000-0000000FF1CE}
### Outils de v�rification linguistique 2013 de Microsoft Office�- Fran�ais -
(28) 03-2017
[Applications] :HKLM {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel
### NVIDIA Control Panel 359.46 - (28) 03-2017
[Applications] :HKLM {B2FE1952-0186-46C3-BAEC-
A80AA35AC5B8}_Display.Driver="C:\WINDOWS\SysWOW64\RunDll32.EXE" "C:\Program
Files\NVIDIA Corporation\Installer2\InstallerCore\NVI2.DLL",UninstallPackage
Display.Driver
### NVIDIA Graphics Driver 359.46 - (28) 03-2017
[Applications] :HKLM {90150000-002A-0409-1000-0000000FF1CE}=MsiExec.exe
/X{90150000-002A-0409-1000-0000000FF1CE}
### Microsoft Office Shared 64-bit MUI (English) 2013 - (28) 03-2017
[Applications] :HKLM {90150000-0116-0409-1000-0000000FF1CE}=MsiExec.exe
/X{90150000-0116-0409-1000-0000000FF1CE}
### Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2013 - (28) 03-
2017
[Applications] :HKLM {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer
### NVIDIA Install Application - (28) 03-2017
[Applications] :HKLM {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Update.Core
### NVIDIA Update Core - (28) 03-2017
[Applications] :HKLM {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Optimus
### NVIDIA Optimus Update 10.4.0 - (28) 03-2017
[Applications] :HKLM {B2FE1952-0186-46C3-BAEC-
A80AA35AC5B8}_Display.Update="C:\WINDOWS\SysWOW64\RunDll32.EXE" "C:\Program
Files\NVIDIA Corporation\Installer2\InstallerCore\NVI2.DLL",UninstallPackage
Display.Update
### NVIDIA Update 10.4.0 - (28) 03-2017
[Applications] :HKLM {90150000-002A-0000-1000-0000000FF1CE}=MsiExec.exe
/X{90150000-002A-0000-1000-0000000FF1CE}
### Microsoft Office 64-bit Components 2013 - (28) 03-2017
[Applications] :HKLM {90150000-012B-0409-0000-0000000FF1CE}=MsiExec.exe
/X{90150000-012B-0409-0000-0000000FF1CE}
### Microsoft Lync MUI (English) 2013 - (28) 03-2017
[Applications] :HKLM {AB5C933E-5C7D-4D30-B314-9C83A49B94BE}=MsiExec.exe
/I{AB5C933E-5C7D-4D30-B314-9C83A49B94BE}
### ATK Package - (28) 03-2017
[Applications] :HKLM {90150000-0115-0409-0000-0000000FF1CE}=MsiExec.exe
/X{90150000-0115-0409-0000-0000000FF1CE}
### Microsoft Office Shared Setup Metadata MUI (English) 2013 - (28) 03-2017
[Applications] :HKLM {90150000-0117-0409-0000-0000000FF1CE}=MsiExec.exe
/X{90150000-0117-0409-0000-0000000FF1CE}
### Microsoft Access Setup Metadata MUI (English) 2013 - (28) 03-2017
[Applications] :HKLM {F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}="C:\Program Files
(x86)\Intel\Intel(R) Processor Graphics\Uninstall\setup.exe" -uninstall
### Intel(R) Processor Graphics - (28) 03-2017
[Applications] :HKLM KeyboardTest_is1="C:\Program
Files\KeyboardTest\unins000.exe" /SILENT
### KeyboardTest V3.1 - (28) 03-2017
[Applications] :HKLM {AC76BA86-7AD7-1033-7B44-AA1000000001}=MsiExec.exe
/I{AC76BA86-7AD7-1033-7B44-AA1000000001}
### Adobe Reader X (10.1.1) - (28) 03-2017
[Applications] :HKLM {CF097717-F174-4144-954A-FBC4BF301033}=MsiExec.exe
/X{CF097717-F174-4144-954A-FBC4BF301033}
### Nero 7 Ultra Edition - (28) 03-2017
[Applications] :HKLM GOM Player="C:\Program Files
(x86)\GRETECH\GomPlayer\Uninstall.exe"
### GOM Player - (28) 03-2017
[Applications] :HKLM {01FB4998-33C4-4431-85ED-079E3EEFE75D}="C:\Program Files
(x86)\InstallShield Installation Information\{01FB4998-33C4-4431-85ED-
079E3EEFE75D}\Setup.exe" /z-uninstall
### CyberLink YouCam - (28) 03-2017
[Applications] :HKLM {4E67FF7F-C24E-4279-9AB2-C26D57B53742}=MsiExec.exe
/I{4E67FF7F-C24E-4279-9AB2-C26D57B53742}
### UpdateAssistant - (28) 03-2017
[Applications] :HKLM Office15.PROPLUS="C:\Program Files (x86)\Common
Files\Microsoft Shared\OFFICE15\Office Setup Controller\setup.exe" /uninstall
PROPLUS /dll OSETUP.DLL
### Microsoft Office Professional Plus 2013 - (28) 03-2017
[Applications] :HKLM The KMPlayer="C:\KMPlayer\uninstall.exe"
### KMPlayer (remove only) - (28) 03-2017
[Applications] :HKLM VLC media player=C:\Program Files
(x86)\VideoLAN\VLC\uninstall.exe
### VLC media player 1.1.9 - (28) 03-2017
[Applications] :HKLM {50B00A1F-CB20-4AAB-A448-66B24B1E83A9}=MsiExec.exe
/X{50B00A1F-CB20-4AAB-A448-66B24B1E83A9}
### Adobe Photoshop CS5 - (28) 03-2017
[Applications] :HKLM {90150000-0015-0409-0000-0000000FF1CE}=MsiExec.exe
/X{90150000-0015-0409-0000-0000000FF1CE}
### Microsoft Access MUI (English) 2013 - (28) 03-2017
[Applications] :HKLM {8B9FA5FF-3E61-4658-B0DA-E6DDB46D6BAD}_is1="C:\Program Files
(x86)\SMADAV\unins000.exe" /SILENT
### SMADAV versi 10.0.1 - (28) 03-2017
[Applications] :HKLM {90150000-0019-0409-0000-0000000FF1CE}=MsiExec.exe
/X{90150000-0019-0409-0000-0000000FF1CE}
### Microsoft Publisher MUI (English) 2013 - (28) 03-2017
[Applications] :HKLM {90150000-0016-0409-0000-0000000FF1CE}=MsiExec.exe
/X{90150000-0016-0409-0000-0000000FF1CE}
### Microsoft Excel MUI (English) 2013 - (28) 03-2017
[Applications] :HKLM {7299052b-02a4-4627-81f2-1818da5d550d}=MsiExec.exe
/X{7299052b-02a4-4627-81f2-1818da5d550d}
### Microsoft Visual C++ 2005 Redistributable - (28) 03-2017
[Applications] :HKLM InstallShield_{01FB4998-33C4-4431-85ED-
079E3EEFE75D}="C:\Program Files (x86)\InstallShield Installation Information\
{01FB4998-33C4-4431-85ED-079E3EEFE75D}\Setup.exe" /z-uninstall
### CyberLink YouCam - (28) 03-2017
[Applications] :HKLM {D5C69738-B486-402E-85AC-
2456D98A64E4}="C:\Windows10Upgrade\Windows10UpgraderApp.exe" /Uninstall
### Windows 10 Upgrade Assistant - (22) 03-2017
[Applications] :HKLM {E399A5B3-ED53-4DEA-AF04-8011E1EB1EAC}
### - (22) 03-2017
[Applications] :HKLM NeroMediaHome!UninstallKey=C:\Windows\UNNeroMediaHome.exe
/UNINSTALL
### - (22) 03-2017
[Applications] :HKLM NeroRecode!UninstallKey=C:\Windows\UNRecode.exe /UNINSTALL
### - (22) 03-2017
[Applications] :HKLM Internet Download Manager=C:\Program Files (x86)\Internet
Download Manager\Uninstall.exe
### Internet Download Manager - (22) 03-2017
[Applications] :HKLM InstallShield Uninstall Information
### - (22) 03-2017
[Applications] :HKLM NeroBackItUp!UninstallKey=C:\Windows\UNNeroBackItUp.exe
/UNINSTALL
### - (22) 03-2017
[Applications] :HKLM Nero - Burning Rom!UninstallKey=C:\Program Files
(x86)\Nero\Nero 7\\nero\uninstall\UNNERO.exe /UNINSTALL
### - (22) 03-2017
[Applications] :HKLM TELKOMSELFlash=C:\Program Files
(x86)\TELKOMSELFlash\uninst.exe
### TELKOMSELFlash - (22) 03-2017
[Applications] :HKLM WinRAR archiver=C:\Program Files (x86)\WinRAR\uninstall.exe
### WinRAR archiver - (22) 03-2017
[Applications] :HKLM Winamp="C:\Program Files (x86)\Winamp\UninstWA.exe"
### Winamp - (22) 03-2017
[Applications] :HKLM {56C049BE-79E9-4502-BEA7-9754A3E60F9B}=MsiExec.exe
/I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
### neroxml - (22) 03-2017
[Applications] :HKLM NeroVision!UninstallKey=C:\Windows\UNNeroVision.exe
/UNINSTALL
### - (22) 03-2017
[Applications] :HKLM NeroShowTime!UninstallKey=C:\Windows\UNNeroShowTime.exe
/UNINSTALL
### - (22) 03-2017
[Applications] :HKCU Winamp Detect=C:\Program Files (x86)\Winamp
Detect\UninstWaDetect.exe
### Winamp Detector Plug-in - (22) 03-2017
[Applications] :HKCU Google
Chrome="C:\Users\USER\AppData\Local\Google\Chrome\Application\28.0.1500.72\Installe
r\setup.exe" --uninstall
### Google Chrome - (22) 03-2017
[Applications] :HKLM CNXT_AUDIO_HDA=C:\Program
Files\CONEXANT\CNXT_AUDIO_HDA\UIU64a.exe -U -G -IX40Plmwa.inf
### Conexant HD Audio - (22) 03-2017
[Applications] :HKLM IE4Data
### - (22) 03-2017
[Applications] :HKLM IE40
### - (22) 03-2017
[Applications] :HKLM IE5BAKEX
### - (22) 03-2017
[Applications] :HKLM IEData
### - (22) 03-2017
[Applications] :HKLM MobileOptionPack
### - (22) 03-2017
[Applications] :HKLM Connection Manager
### - (22) 03-2017
[Applications] :HKLM DirectDrawEx
### - (22) 03-2017
[Applications] :HKLM SchedulingAgent
### - (22) 03-2017
[Applications] :HKLM AddressBook
### - (22) 03-2017
[Applications] :HKLM Fontcore
### - (22) 03-2017
[Applications] :HKLM WIC
### - (22) 03-2017
[Applications] :HKLM DXM_Runtime
### - (22) 03-2017
[Applications] :HKLM MPlayer2
### - (22) 03-2017
[Applications] :HKLM WIC
### - (22) 03-2017
[Applications] :HKLM DXM_Runtime
### - (22) 03-2017
[Applications] :HKLM Fontcore
### - (22) 03-2017
[Applications] :HKLM IE40
### - (22) 03-2017
[Applications] :HKLM AddressBook
### - (22) 03-2017
[Applications] :HKLM Connection Manager
### - (22) 03-2017
[Applications] :HKLM DirectDrawEx
### - (22) 03-2017
[Applications] :HKLM MobileOptionPack
### - (22) 03-2017
[Applications] :HKLM MPlayer2
### - (22) 03-2017
[Applications] :HKLM SchedulingAgent
### - (22) 03-2017
[Applications] :HKLM IE4Data
### - (22) 03-2017
[Applications] :HKLM IE5BAKEX
### - (22) 03-2017
[Applications] :HKLM IEData
### - (22) 03-2017
[MD5]
[07425A267D27F9F30408E546E589A980][2 15716616
4006A411369C5BFD91319A5B004554584BECA3CA ]C:\KMPLAYER\KMPLAYER.EXE
[726798E8D852FC48746850E3B1FB1066][1 2322576
]C:\PROGRA~1\MICROS~1\OFFICE15\GROOVEEX.DLL
[8F4B3BADC32F153D6722205E7C10FC31][6 877720
]C:\PROGRA~1\MICROS~1\OFFICE15\URLREDIR.DLL
[4861404A4249372CD2D528A9F2056D0B][1 838312
B43433B8FB3C496BCBD35EE5C236FC8C1BE35F17 ]
C:\PROGRA~2\COMMON~1\MICROS~1\DW\DW20.EXE
[4BB1A5813F35E391044A9694060AC0E8][1 60526728
2E9B7B2180E1E5E3D0068C039250696527234977 ]
C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE15\MSORES.DLL
[FC8EC7040A6BC0150F194440C75B3E39][1 1218680
0E979F28F014CEE0A46485A73464A533D377D993 ]
C:\PROGRA~2\MICROS~1\OFFICE15\1033\MAPIR.DLL
[34ACE6E837F846CF72AA2D445C0C6E2D][1 1720976
]C:\PROGRA~2\MICROS~1\OFFICE15\GROOVEEX.DLL
[B3810DE6BBED550B7F503A75681C7FBA][1 704664
]C:\PROGRA~2\MICROS~1\OFFICE15\URLREDIR.DLL
[5AA237EAF522154183AB8E95F2099827][1 1489304
5768548FD067677ABE5EFFD567DE5050D6993304 ]C:\PROGRAM FILES (X86)\ADOBE\READER
10.0\READER\ACRORD32.EXE
[47C77C53C41E3797046A04AFB6468ABE][1 311776
D198B566F924123DAD34CF630C45FEFEE18E0A83 ]C:\PROGRAM FILES (X86)\ASUS\ASUS SMART
GESTURE\ASTPCENTER\X64\ASUSTPCENTER.EXE
[0F5EF3F836D2E449FE01FCAF17DBD9CF][1 179680
290D626611A8D22E524336ED2FE90F59312D19FC ]C:\PROGRAM FILES (X86)\ASUS\ASUS SMART
GESTURE\ASTPCENTER\X64\ASUSTPHELPER.EXE
[3363222F80843B2F180C38DAB2D925C4][1 18400
86CF4F3B12078B02E32456F38CB3B64CBA2ED8D4 ]C:\PROGRAM FILES (X86)\ASUS\ASUS SMART
GESTURE\ASTPCENTER\X64\ASUSTPLAUNCHER.EXE
[EEAC360113AFCC4EA16A7372212235C6][1 366048
6DAA4640792049D0D097BFD5283D8F0E66F42E02 ]C:\PROGRAM FILES (X86)\ASUS\ASUS SMART
GESTURE\ASTPCENTER\X64\ASUSTPLOADER.EXE
[564CB886D1A968B9798C1AB03F4EB54F][1 115512
5BF83A533E70C33DBB315E7CC67AB820352E00A6 ]C:\PROGRAM FILES (X86)\ASUS\ATK
PACKAGE\ATK HOTKEY\ASLDRSRV.EXE
[D248FB4E0D6C4EBABB1593A35353D16B][1 283448
7A69595D5E920D414F9F4D13A2B20462B4D1D3E1 ]C:\PROGRAM FILES (X86)\ASUS\ATK
PACKAGE\ATK HOTKEY\HCONTROL.EXE
[F19CAC58C0DF486984D446FB52A3A8DA][1 122168
C79F1189E4CACFACBBF4B7DD30AD8FA0B2ACBD77 ]C:\PROGRAM FILES (X86)\ASUS\ATK
PACKAGE\ATK HOTKEY\SIMAPPEXEC.EXE
[FDC95B0F0D94CB62954C56EA6E1CC179][1 213816
A8D9E5C2E7C708E71C8F1851AE022485DA48816D ]C:\PROGRAM FILES (X86)\ASUS\ATK
PACKAGE\ATK MEDIA\DMEDIA.EXE
[C435191FAD19B43E5C3082E4275DCE75][1 19768
]C:\PROGRAM FILES (X86)\ASUS\ATK PACKAGE\ATK WMIACPI\ATKWMIACPI64.SYS
[DBC598E47E7A382E60E2A4745D41FEF9][1 96896
]C:\PROGRAM FILES (X86)\ASUS\ATK PACKAGE\ATKGFNEX\GFNEXSRV.EXE
[360D693A81527213D30D45676C3477E1][1 406328
AE080C684DD4795B298C17160D44C675BAFD88A4 ]C:\PROGRAM FILES (X86)\ASUS\ATK
PACKAGE\ATKOSD2\ATKOSD2.EXE
[8C4AC22616E77925135C221C46DC6307][1 63912
]C:\PROGRAM FILES (X86)\COMMON FILES\ADOBE\ACROBAT\ACTIVEX\ACROIEHELPERSHIM.DLL
[47C1DE0A890613FFCFF1D67648EEDF90][1 937920
]C:\PROGRAM FILES (X86)\COMMON FILES\ADOBE\ARM\1.0\ADOBEARM.EXE
[11A52CF7B265631DEEB24C6149309EFF][1 64952
]C:\PROGRAM FILES (X86)\COMMON FILES\ADOBE\ARM\1.0\ARMSVC.EXE
[86F0D0B3A07C142C81DAB47E8495A822][1 152872
]C:\PROGRAM FILES (X86)\COMMON FILES\AHEAD\LIB\NMBGMONITOR.EXE
[A328A46D87BB92CE4D8A4528E9D84787][1 279848
]C:\PROGRAM FILES (X86)\COMMON FILES\AHEAD\LIB\NMINDEXINGSERVICE.EXE
[FFBD5650348D4F9E0AA8E72938DC6478][1 1213736
]C:\PROGRAM FILES (X86)\COMMON FILES\AHEAD\LIB\NMINDEXSTORESVR.EXE
[7DE2E1AB0B5DA45A136FD7499B4C64C7][1 13976
F648C360DE66E690890AB37ECF0EFB6887DE473B ]C:\PROGRAM FILES (X86)\COMMON
FILES\DESIGNER\MSADDNDR.OLB
[0B3EEAD619B72692ECEEC2D05E1FE2C4][1 957072
]C:\PROGRAM FILES (X86)\COMMON FILES\MICROSOFT SHARED\HELP\HXDS.DLL
[792400B8F2DD55C943BCB18EE6002AE9][1 2560
F02912666596345F385CDEFA6B4343E959B41F69 ]C:\PROGRAM FILES (X86)\COMMON
FILES\MICROSOFT SHARED\INK\IPSEVENTLOGMSG.DLL
[DCBE32AE2E460CDFC667BD8E2DFE76BE][1 45712
]C:\PROGRAM FILES (X86)\COMMON FILES\MICROSOFT SHARED\OFFICE15\MSOXMLMF.DLL
[1BA584DEEC9A600A4697522E1D2F1E9A][1 471168
BF8BDF3DCAEE0527A1A211A09D26A220879B1236 ]C:\PROGRAM FILES (X86)\COMMON
FILES\MICROSOFT SHARED\OFFICE15\MSSOAP30.DLL
[2B8E4C792BED0E5882702720BC528AE5][1 150648
]C:\PROGRAM FILES (X86)\COMMON FILES\MICROSOFT SHARED\SOURCE ENGINE\OSE.EXE
[DA2E580E51232D5C81989B1A2FD9CF47][1 49776
ACF5FBC6FDE451617DD46B4CD652767790AFBD03 ]C:\PROGRAM FILES (X86)\COMMON
FILES\MICROSOFT SHARED\VSTO\10.0\VSTOMESSAGEPROVIDER.DLL
[174D2EB772E843B6175EED45D8FA11E7][1 670192
]C:\PROGRAM FILES (X86)\COMMON FILES\PX STORAGE ENGINE\PX.DLL
[9555982C980B760398C09EEFAE6FCF01][1 129520
D16C29B64FA1C9761EA6CD009C57F209183DD38C ]C:\PROGRAM FILES (X86)\COMMON FILES\PX
STORAGE ENGINE\PXAFS.DLL
[09132A1DA77EF78D06421C871B3B92C5][1 66544
]C:\PROGRAM FILES (X86)\COMMON FILES\PX STORAGE ENGINE\PXCPYA64.EXE
[B248A451721CF86A6CDBA18B379EC80C][1 551408
]C:\PROGRAM FILES (X86)\COMMON FILES\PX STORAGE ENGINE\PXDRV.DLL
[51598A4CD5BFC25C8D4FB1A740A43583][1 72176
]C:\PROGRAM FILES (X86)\COMMON FILES\PX STORAGE ENGINE\PXHPINST.EXE
[B36F01A58631341310C6D4116F2EDF5F][1 66032
]C:\PROGRAM FILES (X86)\COMMON FILES\PX STORAGE ENGINE\PXINSA64.EXE
[D4BFF8B48CD9A212B45C425F2A1C9B77][1 219632
]C:\PROGRAM FILES (X86)\COMMON FILES\PX STORAGE ENGINE\PXMAS.DLL
[5420BAFE4BEFBC64452DEE6AF8782A20][1 1858032
]C:\PROGRAM FILES (X86)\COMMON FILES\PX STORAGE ENGINE\PXSFS.DLL
[DFC64F80CBC171FB0631E7F15D79C998][1 436720
]C:\PROGRAM FILES (X86)\COMMON FILES\PX STORAGE ENGINE\PXWAVE.DLL
[23C98662461CA549487676E3E4E16C4F][1 96752
]C:\PROGRAM FILES (X86)\COMMON FILES\PX STORAGE ENGINE\VXBLOCK.DLL
[0181815874F0D68BCE2FF4DB1655DC04][1 28160
B5872051F92A486C9FD564414EACDA667A9C86B8 ]C:\PROGRAM FILES (X86)\COMMON
FILES\SYSTEM\DIRECTDB.DLL
[C71925849D278D7E9415C1C4B373F3AB][1 753152
0F625454A23F36D4F5491A20BEDC11A5295835DD ]C:\PROGRAM FILES (X86)\COMMON
FILES\SYSTEM\WAB32.DLL
[E9B4B2FE508E5F1995665BF170977C7C][1 964096
126D968FE5E9F4807F465D00053A712B87872CB6 ]C:\PROGRAM FILES (X86)\COMMON
FILES\SYSTEM\WAB32RES.DLL
[A1741C3B79F9DF8895E05EF43579E74B][1 136488
]C:\PROGRAM FILES (X86)\CYBERLINK\YOUCAM\YCMMIRAGE.EXE
[AA7564D89AE7E5D930F3A75A01230B7F][2 175200
81CF0B7730B93A2A7956C24AEECBD4516689287A ]C:\PROGRAM FILES
(X86)\CYBERLINK\YOUCAM\YOUCAM.EXE
[7A14226EA967021C42EC17E506B0A6CE][2 162912
]C:\PROGRAM FILES (X86)\CYBERLINK\YOUCAM\YOUCAMTRAY.EXE
[B3FEA901BC7A1DD3324B35D1C69697F8][2 35836360
40357A7DA0F479D1B16D20EDB1D7EA6C3F1273BD ]C:\PROGRAM FILES (X86)\FOROOZANI
SOFTWARE\ADOBE PHOTOSHOP CS5\PHOTOSHOP.EXE
[08053E610C778572920DD52E4CAB4BAA][1 8400992
]C:\PROGRAM FILES (X86)\GRETECH\GOMPLAYER\GOM.EXE
[F8E22F7612B37F113DA5700C9C23554A][2 1256960
96E2BE5CC20DE195DB5530C07E28A18A864C915C ]C:\PROGRAM FILES (X86)\INSTAGRAM
HACKER\INSTAGRAM HACKER.EXE
[7AE89C6074B7CF3D03081EA6616D873B][2 119808
7294758911932FF6885521103BAF631ACBDA21BC ]C:\PROGRAM FILES (X86)\INSTAGRAM
HACKER\UNINSTALL INSTAGRAM HACKER V3.7.2.EXE
[50C2E62660C7C1D26C60D320CC61F8A6][1 97816
]C:\PROGRAM FILES (X86)\INTERNET DOWNLOAD MANAGER\DOWNLWITHIDM.DLL
[B06190AF451B2037FF075AEB5D21E26F][1 150552
]C:\PROGRAM FILES (X86)\INTERNET DOWNLOAD MANAGER\DOWNLWITHIDM64.DLL
[C75F3BF8FAABBA3EED8FEE27256C6E46][1 4019312
]C:\PROGRAM FILES (X86)\INTERNET DOWNLOAD MANAGER\IDMAN.EXE
[A4B9EB733D753DD8D700B47551AA6B00][1 240088
]C:\PROGRAM FILES (X86)\INTERNET DOWNLOAD MANAGER\IDMBRBTN.DLL
[01188C6E88C451ADA0FF2715F882F730][1 253128
]C:\PROGRAM FILES (X86)\INTERNET DOWNLOAD MANAGER\IDMBRBTN64.DLL
[85D34E4F4EB601666C411645731E2BBF][1 75320
]C:\PROGRAM FILES (X86)\INTERNET DOWNLOAD MANAGER\IDMBROKER.EXE
[36B618F848D6DDA620BF0B151EACF02D][1 333848
]C:\PROGRAM FILES (X86)\INTERNET DOWNLOAD MANAGER\IDMCCHANDLER2.DLL
[A4B65C82ED0DD6BC96EAB520BF2E5651][2 81269
E5946E039B34FB9833068495F190C604AEE345B7 ]C:\PROGRAM FILES (X86)\INTERNET
DOWNLOAD MANAGER\IDMGCEXT.CRX
[FE82C6F8416FB9645B6DBAD037AC5479][1 453688
]C:\PROGRAM FILES (X86)\INTERNET DOWNLOAD MANAGER\IDMIECC.DLL
[2ECBD0616A07D7B0DA79CA0BD8B9AFB6][1 527928
]C:\PROGRAM FILES (X86)\INTERNET DOWNLOAD MANAGER\IDMIECC64.DLL
[B0DB7C748AF3EF055447DB522239BC68][1 32256
4BF1C4E0D8389FE9067A5735C71540508F218312 ]C:\PROGRAM FILES (X86)\INTERNET
EXPLORER\EXTEXPORT.EXE
[91C3863162B85B564D0F76B7D2C49AE6][1 50688
68B7C23204C6D49B16EBB970C4DBCCCF56361F1A ]C:\PROGRAM FILES (X86)\INTERNET
EXPLORER\HMMAPI.DLL
[4459AAD5DA99EF5BF12D18D1FA0D1EC0][1 478720
57B11599C0050225E3A38CD1608A411996B0D623 ]C:\PROGRAM FILES (X86)\INTERNET
EXPLORER\IEINSTAL.EXE
[6A1337363C6EA5851302C928E05AE60D][1 221696
09DDB2F01435E082547214BE99FAC365EDF91717 ]C:\PROGRAM FILES (X86)\INTERNET
EXPLORER\IELOWUTIL.EXE
[A4F0806BDBA10FE2F16302928C428F99][1 331776
3EC357F61F12C41F33F4FD938A8B31D25F232890 ]C:\PROGRAM FILES (X86)\INTERNET
EXPLORER\IESHIMS.DLL
[27D8231B9DA1B46F9D3FA238A096A24D][1 825536
78C2734D70708E2DEE0EDE5C468171A3DDBE2E0E ]C:\PROGRAM FILES (X86)\INTERNET
EXPLORER\IEXPLORE.EXE
[E567AEE9682F4DBE9251C68EFB5E00E1][1 34128
C009029F47FE55144C8ABADCE619EAEC93EAC466 ]C:\PROGRAM FILES (X86)\INTERNET
EXPLORER\SQMAPI.DLL
[769B45EB90B2F04104B7D34818E4B1F6][2 26234256
EE340D035FD7ED8EB80312640EB818FA7AF84F6B ]C:\PROGRAM FILES
(X86)\ITUNES\ITUNES.DLL
[F2E0B22B58F90CE86621C9B53D5C6B8D][1 1180048
]C:\PROGRAM FILES (X86)\ITUNES\UNINS000.EXE
[7D3453A5641CB146EB5F19B176AC9929][1 41072
4CC0C0155947E478EE7E515BCCB928EFB70BE024 ]C:\PROGRAM FILES (X86)\MICROSOFT
OFFICE\OFFICE15\BCSCLIENT.MSG.DLL
[C6472164E8467E73857E6FA4EB31D4EF][1 57992
]C:\PROGRAM FILES (X86)\MICROSOFT OFFICE\OFFICE15\MSOSB.DLL
[436FF18AB0E57A8D6A7EB2C9BD477291][1 139368
]C:\PROGRAM FILES (X86)\MICROSOFT OFFICE\OFFICE15\OCHELPER.DLL
[80FF9262DF9370D120EEB52508249E5A][1 158344
]C:\PROGRAM FILES (X86)\MICROSOFT OFFICE\OFFICE15\ONENOTEM.EXE
[ED43CEF838A79C09A88DC43E26D1B60C][1 112592
ABC5FEF23300DB72EC9F7E0D1A5B42E0AE1896CB ]C:\PROGRAM FILES (X86)\MOZILLA
FIREFOX\ACCESSIBLEHANDLER.DLL
[3381F3FA4AEEF9F737FE934227F837E9][1 26576
E728293B62141069D2331BEE3372C05F523E9AC7 ]C:\PROGRAM FILES (X86)\MOZILLA
FIREFOX\ACCESSIBLEMARSHAL.DLL
[F4604E259459F5A0D5BE6914A6D4C5FB][1 18624
E17011A4C93F88D558A3DD606D99E78FC58837E2 ]C:\PROGRAM FILES (X86)\MOZILLA
FIREFOX\API-MS-WIN-CORE-CONSOLE-L1-1-0.DLL
[E205DE17A85B0C3352A6857EF9B3C6DD][1 17600
5FE8A292A9D6653136F612FE2C9B45F2F1B08C96 ]C:\PROGRAM FILES (X86)\MOZILLA
FIREFOX\API-MS-WIN-CORE-DATETIME-L1-1-0.DLL
[405BB6A7CD56CBF5276C3A8DC631963D][1 17600
B4CF791ACE3F6790D45B54A0E6AEB6EBAC748C97 ]C:\PROGRAM FILES (X86)\MOZILLA
FIREFOX\API-MS-WIN-CORE-DEBUG-L1-1-0.DLL
[9A4FC3727AAF02C3285B47DF5EE56244][1 18104
F88E1EA0BA66D1615D7E1D53C95D8E8DBE6BEBE0 ]C:\PROGRAM FILES (X86)\MOZILLA
FIREFOX\API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL
[6B937FE1EFF0E440B124BBB9334DF34D][1 21696
AB3982AB9D46BAA67B1D59728BC6E93C45872B2B ]C:\PROGRAM FILES (X86)\MOZILLA
FIREFOX\API-MS-WIN-CORE-FILE-L1-1-0.DLL
[EA4AE42721460002DC31515F295AD1C4][1 18112
8A970D589AA4C178083EE8FB65798A6DDECDC1CF ]C:\PROGRAM FILES (X86)\MOZILLA
FIREFOX\API-MS-WIN-CORE-FILE-L1-2-0.DLL
[AD895B2A99A3EC18F1690BBAC1E2037A][1 18112
19FAB11CA8D2AB4A3C1A863209CBDC77A69E1AED ]C:\PROGRAM FILES (X86)\MOZILLA
FIREFOX\API-MS-WIN-CORE-FILE-L2-1-0.DLL
[0A0084D4B3635E4D8EBAB587DCFCC16C][1 18112
5619483328D58AD6B4D2A8A860DABED1BBDB8091 ]C:\PROGRAM FILES (X86)\MOZILLA
FIREFOX\API-MS-WIN-CORE-HANDLE-L1-1-0.DLL
[52FFABA4273678BAE75442F2BC85B470][1 531408
66A4C6CF92A4190A1480FD2B19AC84952FA715BD ]C:\PROGRAM FILES (X86)\MOZILLA
FIREFOX\FIREFOX.EXE
[363D3B5EE2B394089A7CEEEE6A74A263][1 175568
1CFF81BA1E0B769F40C6A3DA38B850FFB9FEB1E1 ]C:\PROGRAM FILES (X86)\MOZILLA
MAINTENANCE SERVICE\MAINTENANCESERVICE.EXE
[C0A19BD59A525199D5318F73D7B97031][2 89698
31966D303730952FD3E06EB8A848330ED070E68E ]C:\PROGRAM FILES (X86)\MOZILLA
MAINTENANCE SERVICE\UNINSTALL.EXE
[B498A14133BD09AD0817590ACE4470AD][1 800040
]C:\PROGRAM FILES (X86)\NERO\NERO 7\NERO BACKITUP\NBSERVICE.EXE
[57B941BC9AF99E03ECC1E2BEF753782A][1 99624
]C:\PROGRAM FILES (X86)\NERO\NERO 7\NERO BACKITUP\NBSHELL.DLL
[B08BE238F67339373207C29E12EDDF4C][1 1967400
]C:\PROGRAM FILES (X86)\NERO\NERO 7\NERO COVERDESIGNER\COVEREDEXTENSION.DLL
[7F471D168B27E4FD7005F42D5449BDD6][1 697640
]C:\PROGRAM FILES (X86)\NERO\NERO 7\NERO HOME\NEROHOME.EXE
[55835DA201C86563BA49F045A90ABB3D][1 7116072
]C:\PROGRAM FILES (X86)\NERO\NERO 7\NERO STARTSMART\NEROSTARTSMART.EXE
[99BF09D43D2963F8EC0F830C4B6A6286][1 1804360
EF1BD410ADE84EFAD55D8E8DA309291F0576C98C ]C:\PROGRAM FILES (X86)\NVIDIA
CORPORATION\UPDATE CORE\NVBACKEND.EXE
[ -2][0 -1
]C:\PROGRAM FILES (X86)\SDOWNLOADER\QFIIN.EXE
[92380D8293B6F28323BAE9B002F8BC69][2 73728
534DD8719D6D0EB9BAC28FB39CAE007229CCD504 ]C:\PROGRAM FILES (X86)\SMADAV\SMADAV-
UPDATER.EXE
[B9DB20886E682C56E22847975AF6B524][2 110080
B11F6255109C2E58EF6B15950D99EE91B1DE14C6 ]C:\PROGRAM FILES
(X86)\SMADAV\SMADENGINE.DLL
[D54DFE1332564AF9133847C4C43608C3][2 105984
1F6944D781FC4256CF9D4D0CE899D07688169763 ]C:\PROGRAM FILES
(X86)\SMADAV\SMADEXTC64.DLL
[49771A02FA68334AC5290D4E32C4FB27][2 1213921
1C8ED6060B369FEE15AC01221C249520F40B2AF1 ]C:\PROGRAM FILES
(X86)\SMADAV\UNINS000.EXE
[7E1D27FC64D9E11ED4DD4614550DFA14][2 80384
D0A3B811582EACDA491D1F99BCA0D6D9857B4C15 ]C:\PROGRAM FILES
(X86)\TELKOMSELFLASH\ABOUTPLUGIN.DLL
[D0141DBF9B2E3AB0A326CE05194CC28D][1 607584
5374D172B8962AF7EF3756DFF732B58E0DB0420D ]C:\PROGRAM FILES
(X86)\TELKOMSELFLASH\ADDPBK.EXE
[F6B56224AC19D87DD468030E47A07CA0][2 1124352
37C85382FD6AA591D1CC72492054F0D9F5FB0C79 ]C:\PROGRAM FILES
(X86)\TELKOMSELFLASH\ADDRBOOKPLUGIN.DLL
[4A4D71525CB24EA923F313FD4D7FA1B2][2 672768
F8806F108636593E867B340978504D0FBA9BF019 ]C:\PROGRAM FILES
(X86)\TELKOMSELFLASH\ADDRBOOKSRVPLUGIN.DLL
[84353BCED960A1957ACB366EBEDCC3CD][2 818688
8AA9F905201D1B170BF854BEE3F152EE6161CE3B ]C:\PROGRAM FILES
(X86)\TELKOMSELFLASH\ADDRBOOKUIPLUGIN.DLL
[85922DBDCB27C9C77111E554044362B4][2 646144
485B3993A287DE06A8EA00CB43397CE285951C73 ]C:\PROGRAM FILES
(X86)\TELKOMSELFLASH\ATCODEC.DLL
[159943E0B33BEA694F73DD451723DF40][2 168960
89CD884AD69B47126683E3F2C4A31035A7621CDB ]C:\PROGRAM FILES
(X86)\TELKOMSELFLASH\ATR2SMGR.DLL
[6EE165A6CB40D4AE31E00381D97F9BB9][2 187392
6BBF5D8AA6E826B266C7CC888E1289169206BAC1 ]C:\PROGRAM FILES
(X86)\TELKOMSELFLASH\CALLAPPPLUGIN.DLL
[E8B9AF7B4D76211F6DD5BAE593F7651F][2 569344
043D1156ED070ED6F5286FDCF27CFA4A43714592 ]C:\PROGRAM FILES
(X86)\TELKOMSELFLASH\CALLLOGSRVPLUGIN.DLL
[BFA7F5D9236BF7C36D39E7551E382EBF][2 416256
C8A71B1476959C25A9B95EA3262F954AF032E61F ]C:\PROGRAM FILES
(X86)\TELKOMSELFLASH\CALLLOGUIPLUGIN.DLL
[17745CD0D22F695DDA55F8DDF8C11955][2 515072
6887005EE5A8E84BBD575AD89C7A11714504FBA6 ]C:\PROGRAM FILES
(X86)\TELKOMSELFLASH\TELKOMSELFLASH.EXE
[66AAE701A787E4BDF73116B79274DC86][1 655744
12964FCF07BEE5B39D1CE20026066092080548FA ]C:\PROGRAM FILES
(X86)\TELKOMSELFLASH\UPDATEDOG\OUC.EXE
[E92604E043F51C604B6D1AC3BCD3A202][6 536064
]C:\PROGRAM FILES (X86)\UNHACKME\7ZA.EXE
[3A4072C8D36CEF6A82D4221C56DDDD74][1 1202072
F171D3268C5C5AD5C3F6D6C0AA63FEDD122DC171 ]C:\PROGRAM FILES
(X86)\UNHACKME\HACKMON.EXE
[8B4BA6F39B9E07D553704CD0F1DBA46B][1 776120
AA2804EEFBA8D843813CE2359E281E0401A8DDEE ]C:\PROGRAM FILES
(X86)\UNHACKME\JSONFAST.DLL
[FD7732EB1925A06AE2B38A1C3D05CBD5][1 217016
7D1461EAC1AC6BB4530971313D746037CF107129 ]C:\PROGRAM FILES
(X86)\UNHACKME\MOZLZ4D.EXE
[333961BB8AB2055AF0D69A3D812D1D21][1 224664
56E3D2DBB2CCE5102CF40667BCE7F2897C2FAC62 ]C:\PROGRAM FILES
(X86)\UNHACKME\PARSER.DLL
[764374A75D93A06CD36A818A2F2A7E45][1 11328408
3278660C9A118ECD09E036C7AF19E5CADC4E1ABD ]C:\PROGRAM FILES
(X86)\UNHACKME\REANIMATOR.EXE
[717CAD2011E934039AB977D863914190][1 3344280
60431B5EA3696911C43E686D05CB0EC5E4A7B6F3 ]C:\PROGRAM FILES
(X86)\UNHACKME\REGRUNINFO.EXE
[015E878DFF62E4E77A81A39D64FDA529][1 2857368
5531DA51EC90B0EB35F64B559019A345FADE8BB3 ]C:\PROGRAM FILES
(X86)\UNHACKME\UNHACKME.EXE
[89984415BF772D2C8595EEBC475BCFDB][2 107520
]C:\PROGRAM FILES (X86)\VIDEOLAN\VLC\VLC.EXE
[82AFA6D0AF5D654E9E8AB49917B2FA3C][2 65024
A67076CCACD96D865C2D4A099A0F82B284FE0DEC ]C:\PROGRAM FILES (X86)\WINAMP
DETECT\IEWACHK.DLL
[CDCEAA1B50BDAE2A974DBEE09A64B834][2 67260
81C02BDD680F9BD75EEB943CDBE09F76B92B7CAD ]C:\PROGRAM FILES (X86)\WINAMP
DETECT\UNINSTWADETECT.EXE
[8ACA7794401FC430B220F763E2C70DB9][2 83456
C4B61061F7C85B877B7E4FA56DE4CE8E4C345B3A ]C:\PROGRAM FILES
(X86)\WINAMP\BURNLIB.DLL
[A9DE7FF6141FABC0C6677E571F3BD9A1][1 28000
]C:\PROGRAM FILES (X86)\WINAMP\ELEVATOR.EXE
[9D1B20A1D0F2295FB9FB64AF9DA1EDA2][2 46080
7EE2B126C7572E7E71F4DFB864106A3E216D222F ]C:\PROGRAM FILES
(X86)\WINAMP\ELEVATORPS.DLL
[80C489DA9B1E849118F16EDF585A7CE1][2 136192
B0E8778A2E90F0169B89AA13E4CE78C6213F70A2 ]C:\PROGRAM FILES
(X86)\WINAMP\LIBFLAC.DLL
[7B7ADC1441083A5B3425FE219CD634E6][2 179712
FE1DE294E5C9C177A7070D403F914D494A6FC158 ]C:\PROGRAM FILES
(X86)\WINAMP\LIBMP4V2.DLL
[B40B1318348283645241156F4A334D9B][2 252928
0EEE1076E781A6BDFB47D1B2771EE63CFA88BB2C ]C:\PROGRAM FILES
(X86)\WINAMP\LIBSNDFILE.DLL
[1C3F539488C54913454F2D551251709E][2 75776
4425F415B67826241801FD7DE97206F7A47DB878 ]C:\PROGRAM FILES (X86)\WINAMP\NDE.DLL
[8BF4FB5E880A20FC23224A346AB65F71][2 53248
335D535782285271A434C84AD4113534ABD796F6 ]C:\PROGRAM FILES
(X86)\WINAMP\NSUTIL.DLL
[E77899573470873FD7B9B0E717794886][1 1592672
]C:\PROGRAM FILES (X86)\WINAMP\WINAMP.EXE
[895A62970833575772FA21B0C54C158D][2 74752
]C:\PROGRAM FILES (X86)\WINAMP\WINAMPA.EXE
[95A97A8A9DD7E4FA1EBC2FBE7B039C47][1 724480
2F35E502125B338C4CEDC8ADF17D56165278A697 ]C:\PROGRAM FILES (X86)\WINDOWS
DEFENDER\EPPMANIFEST.DLL
[3BAA8E3BAC846451DFADB48C18FB8E4D][1 86528
EDD7178A0115E70EC18675E568B408A5DBB54260 ]C:\PROGRAM FILES (X86)\WINDOWS
DEFENDER\MPASDESC.DLL
[64C468F111B9DEB401A4336B6366DEA6][1 700928
C59ECBB47668D9D313FE3CCB14BF3DBDFEC80F5D ]C:\PROGRAM FILES (X86)\WINDOWS
DEFENDER\MPCLIENT.DLL
[2CAB4EA393A5B893CDDACB595A930A5B][1 79360
EF9392D83577E4B30695041562122F3028049A8B ]C:\PROGRAM FILES (X86)\WINDOWS
DEFENDER\MPOAV.DLL
[44300EB58F3E2271F3B271E9843E5589][1 4608
6712FBD4FD62879377788034D52984F5DC8C52D4 ]C:\PROGRAM FILES (X86)\WINDOWS
DEFENDER\MSMPLICS.DLL
[FC88FE6E28CA6973819E25A13630A59A][1 241664
E2E6AC8CFE59F827929F0A8DE26D843B02FA813A ]C:\PROGRAM FILES (X86)\WINDOWS
DEFENDER\SHELLEXT.DLL
[A7ECC7A0FADDADF34ED063B8C7BDB0D2][1 1873408
7D45D298D3D37B974CC7E8E2EDA010165D96A229 ]C:\PROGRAM FILES (X86)\WINDOWS
MAIL\MSOE.DLL
[15EEBFECC6A3B6A8352CD90B3E24736F][1 2487296
EC0D28E23B74611DE8DA3E945ACCE03C80569C5E ]C:\PROGRAM FILES (X86)\WINDOWS
MAIL\MSOERES.DLL
[16C8EC7D893F88A06EAEF45DB75CBE64][1 57856
CADF9FD69F61EB2C9A688E1C56E602D36AD0778C ]C:\PROGRAM FILES (X86)\WINDOWS
MAIL\OEIMPORT.DLL
[2781E6EF593909A8B73FE1AD397F778A][1 515072
B46924E63841333249DA832323AAAF720A0880A2 ]C:\PROGRAM FILES (X86)\WINDOWS
MAIL\WAB.EXE
[D926F5805CCE007EDCAA57E165C2D14B][1 43520
891579ADD3BFE2AA5B5C6A9806930AB54492B698 ]C:\PROGRAM FILES (X86)\WINDOWS
MAIL\WABIMP.DLL
[20F8EC18219B9A6043C4EA46F6D015FB][1 65536
D5FA5F1A2B9989580E56B8E20785D3730F5042C5 ]C:\PROGRAM FILES (X86)\WINDOWS
MAIL\WABMIG.EXE
[EE82204845B5CA903A82F3D88EF1D8A7][1 410112
C52D6C9D91D5E3D5489CBBBAB6BE7B2BCF305A20 ]C:\PROGRAM FILES (X86)\WINDOWS
MAIL\WINMAIL.EXE
[C03B3489E0B6DDE2EA794BE1ADF3045D][1 167424
DE2727FB48F8F0E78D222AA61579EF83B0951F8A ]C:\PROGRAM FILES (X86)\WINDOWS MEDIA
PLAYER\MPVIS.DLL
[C4B56C14C70B324FCF50AA857733A0B0][1 1810944
F5EB8368EA1C8A9CC424B03500F3EF36C4416671 ]C:\PROGRAM FILES (X86)\WINDOWS MEDIA
PLAYER\SETUP_WM.EXE
[08D16561E6724637D887F451A896F7F0][1 73216
40BAA59589BA1C7CBFEE98833F14A1370B826763 ]C:\PROGRAM FILES (X86)\WINDOWS MEDIA
PLAYER\WMLAUNCH.EXE
[ADB4E49FA88CFE2D6CD1AB0C798114E8][1 102400
A7F8407191C9FF3C0A201AF5D569F0594C9DA4C2 ]C:\PROGRAM FILES (X86)\WINDOWS MEDIA
PLAYER\WMPCONFIG.EXE
[B1419B38FBD14C65CB73D26D5577BD99][1 166912
EE0DA9807E136E9AB1029E649CC01FBC3EB2C4D3 ]C:\PROGRAM FILES (X86)\WINDOWS MEDIA
PLAYER\WMPLAYER.EXE
[AC4E70ECF1F6A0B4372954EB655ADB03][1 34128
61570802A0DF87A87C86996A7FDF28FB4E8AF484 ]C:\PROGRAM FILES (X86)\WINDOWS
MULTIMEDIA PLATFORM\SQMAPI.DLL
[523CCD263FE87516AF05886E4CE80D1E][1 103104
FD5FBF98773B881F29737AE01C352042E069E2F3 ]C:\PROGRAM FILES (X86)\WINDOWS PHOTO
VIEWER\IMAGINGDEVICES.EXE
[8BFE40DA68F6F2CF6542C9A97859F0EB][1 1993216
C6BE20092D5A0C705FAE47D9DFD002AA93270CFE ]C:\PROGRAM FILES (X86)\WINDOWS PHOTO
VIEWER\IMAGINGENGINE.DLL
[522CE924B8FAE4DF3E888350BA45747D][1 1669120
FD018B0A40606DA4254010118984F8C9C010D401 ]C:\PROGRAM FILES (X86)\WINDOWS PHOTO
VIEWER\PHOTOACQ.DLL
[DAD2758A806A22B9EC1956218C040741][1 38400
763CDF2714C232317F320EEA605925FFFA64C451 ]C:\PROGRAM FILES (X86)\WINDOWS PHOTO
VIEWER\PHOTOBASE.DLL
[0742F93AE13FC5AEAB07AC268FDB82F1][1 1570304
38E10A300DFBC67BAF5347D16121D0059024A349 ]C:\PROGRAM FILES (X86)\WINDOWS PHOTO
VIEWER\PHOTOVIEWER.DLL
[F831AA40EECB5821EFA15916996BC72C][1 34128
60B8B16460849664598FE6602965B9399D8107E3 ]C:\PROGRAM FILES (X86)\WINDOWS
PORTABLE DEVICES\SQMAPI.DLL
[FF3D7C02DFF751B615B0CDF15FF6C06A][2 332800
6049940C07C612F4BE9759852803EC9D10C037A2 ]C:\PROGRAM FILES (X86)\WINRAR\DEFAULT
TEMP.SFX
[AB0FE590A3BB3C448C823D2753AC58ED][2 332800
2FE80C5644BF9A7D62057ED2F7129FF863922888 ]C:\PROGRAM FILES
(X86)\WINRAR\DEFAULT.SFX
[03B704218D7D4FD365E2A5019D22A5BC][2 298496
3029EB836308848441BB0C99926EB2C4962F7532 ]C:\PROGRAM FILES (X86)\WINRAR\RAR.EXE
[3B42317C8A22B82B04BF8C4E13B27CF0][2 125440
]C:\PROGRAM FILES (X86)\WINRAR\RAREXT.DLL
[3E5D078EBF7820978331D2A5EA6D0F1D][2 43008
1277ED469D6543502CF9323D3D4C6541A0FBDDC2 ]C:\PROGRAM FILES
(X86)\WINRAR\RAREXT64.DLL
[ -2][0 -1
]C:\PROGRAM FILES (X86)\WONDERSHARE\DRFONE FOR IOS\DRIVERINSTALL.EXE
[04F75064637D7409519DD52B61E8BB43][2 415232
E205913D6E351234D74EAD91BBF03341143BB14D ]C:\PROGRAM FILES
(X86)\WONDERSHARE\WAF\2.3.0.5\WSAPPSERVICE.EXE
[ -2][0 -1
]C:\PROGRAM FILES\BONJOUR\MDNSRESPONDER.EXE
[8774F9E5316FA659244EC5D383F8A056][2 2448384
15558D2EA553DD4DD32994CFADC3C77A8B4E253C ]C:\PROGRAM FILES\BRIDGE LEASE
MANAGER\BRIDGE LEASE MANAGER.DLL
[D5EAA06A5CEE340672E5665B7793EC64][1 32256
D95191ECEE2D4BB82D4EAB521D7498C6A2164461 ]C:\PROGRAM FILES\COMMON
FILES\SYSTEM\DIRECTDB.DLL
[A674491AF23EF2D9D8044D02144DE909][1 867840
2897F44B313FA6FEEA680F1BD4A2DAE0C14D28CA ]C:\PROGRAM FILES\COMMON
FILES\SYSTEM\WAB32.DLL
[470F753937B2BC3EF76EE5F6FB66BB94][1 964096
9B5007AA5556018F4777741D85C88F7A8052C658 ]C:\PROGRAM FILES\COMMON
FILES\SYSTEM\WAB32RES.DLL
[ -2][0 -1
]C:\PROGRAM FILES\EASEWARE\DRIVEREASY\DRIVEREASY.EXE
[0576C439AE1BFD6B2048D5CD2DD4B509][1 53760
2A52125B40AF72B55845041E83A2573BC7DAA65E ]C:\PROGRAM FILES\INTERNET
EXPLORER\HMMAPI.DLL
[01A7F0EB0FA2E15BE8F6B84316F95DA3][1 512000
50F3C9EEF73F6C5B179790C680BB8C3C77B2EEE9 ]C:\PROGRAM FILES\INTERNET
EXPLORER\IEDIAGCMD.EXE
[9BE821EB9BD18ED241A926B5DDAC6D18][1 495616
F7237B456934963662A36A7E3F8300687292D1DB ]C:\PROGRAM FILES\INTERNET
EXPLORER\IEINSTAL.EXE
[547020D1093BAFD405855F065560C901][1 223232
26AC6771E1AAF9A7C159EFEB434C05847D362DB9 ]C:\PROGRAM FILES\INTERNET
EXPLORER\IELOWUTIL.EXE
[AEC841B454F9B7EDEB2E719F6B19D5ED][1 417280
AF81914198F1D7581EB5B3051A842C5E66CFC59C ]C:\PROGRAM FILES\INTERNET
EXPLORER\IESHIMS.DLL
[2B328FEB08F104F1973C230D6C25356E][1 825536
A063C082F7DCB31B7BD25D24C9318A7D9AC62A1D ]C:\PROGRAM FILES\INTERNET
EXPLORER\IEXPLORE.EXE
[F4A0FA76204E19468465F1164631AA77][1 37784
348892FC67FA9D8758DDB15836C3FC4AF374BDAA ]C:\PROGRAM FILES\INTERNET
EXPLORER\SQMAPI.DLL
[6A874F47AC63B6B909CBFD1D79527A29][1 1099640
]C:\PROGRAM FILES\KEYBOARDTEST\KEYBOARDTEST.EXE
[E3FEA8060978EAB6FA5D40E74DE6308B][2 1051416
565B047C9230E7DAEC470E097DF2E68940BDABEB ]C:\PROGRAM FILES\KMSPICO\AUTOPICO.EXE
[67115DFDA5935F743CBF81F85C5E763C][2 4947968
FE629777E67B07B34FF0F470F8D2CD8A5EF001BD ]C:\PROGRAM
FILES\KMSPICO\DEVCOMPONENTS.DOTNETBAR2.DLL
[30C7E8E918403B9247315249A8842CE5][2 731809
66A13CA78ADF460AFA366C66178DF05A2466CB0D ]C:\PROGRAM FILES\KMSPICO\UNINS000.EXE
[68A08B7E269F75EC288F72BF76D715B1][2 990208
F2150ADB8E14EB42B8510478DE6E870F0D5F9B10 ]C:\PROGRAM
FILES\M3ULPE53ML\M3ULPE53M.EXE
[AC9A844878E180B59EC2293692BDBA32][2 382464
680DA88CD2300106FF0D05068403B53BBE594012 ]C:\PROGRAM
FILES\M3ULPE53ML\UNINSTALLER.EXE
[635B37E964C3454BA38D669C7521B627][1 205416
]C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE15\OCHELPER.DLL
[3C7CF966C13F5081A05CAAED5304950C][1 2454976
8EC6B35E623E60BD18D5EFC45BC3BDEF0DDB8084 ]C:\PROGRAM FILES\NVIDIA
CORPORATION\DISPLAY\NVTRAY.EXE
[EF5ADA88F01635A0F8CE5222CEEBC2D2][1 1259968
8D67CC97AFC5A8B88268C670BAB83C8329F67C6A ]C:\PROGRAM FILES\NVIDIA
CORPORATION\DISPLAY\NVXDSYNC.EXE
[68BCDFEC4C930095187CF36196360C4D][2 990208
B3995A0F122EBDE05C3A31F42303BC3C6FD6A80D ]C:\PROGRAM
FILES\OPB8PQV6BW\OPB8PQV6B.EXE
[5840ADDA0A52F539D3AE690BD6E2107A][2 382464
280B411D3FC48D853104BD8345ECE4B899BC37D8 ]C:\PROGRAM
FILES\OPB8PQV6BW\UNINSTALLER.EXE
[61618D4236DB6FB82A8DE6A54D70AC34][2 990208
DE8EA08174896DB267CBF3F4B97943F5A172FBF2 ]C:\PROGRAM
FILES\P12NB3RVK8\0PFCRCRK1.EXE
[E4958E23005838E3B38E5A22353F69D6][2 382464
AD3DEF0798822CA63A3930969FD7337572AF76F1 ]C:\PROGRAM
FILES\P12NB3RVK8\UNINSTALLER.EXE
[CC4A5098095A918FD0E6BE01EE07646A][1 126192
]C:\PROGRAM FILES\PLUMBYTES SOFTWARE\PLUMBYTES ANTI-MALWARE\AMWSERVICE.EXE
[6F820B6B9A6649AFE84D9F2C72B7BA37][1 1928944
]C:\PROGRAM FILES\PLUMBYTES SOFTWARE\PLUMBYTES ANTI-MALWARE\PLUMBYTES.EXE
[BEA7C958B57607ACEDA85C515D8F1936][1 370168
047100E7926360EC76EB6B586C3BBB713D0789F7 ]C:\PROGRAM FILES\REMPL\DRVDBFIX.EXE
[501EE9F49000480AE903FE4B9C620551][1 707064
73FFF5CEB494CB3F020289151291050619D2BE44 ]C:\PROGRAM FILES\REMPL\REMSH.EXE
[E0DC497C2B77E24418A9DD06E4E127F8][1 2889896
4C7D63E591696999B76AEDC9691CFF55C38FDBF7 ]C:\PROGRAM FILES\WINDOWS DEFENDER
ADVANCED THREAT PROTECTION\MSSENSE.EXE
[39D76F7C72B5C41089C8FD7BB8F44417][1 754688
43717F03F4A93AD57D2E49E31B38316A08822448 ]C:\PROGRAM FILES\WINDOWS DEFENDER
ADVANCED THREAT PROTECTION\SENSECNCPROXY.EXE
[F74D9F48969D1EAEC92773972C7277AD][1 32160
679DCE87EC0A05A98876E7113821D2405EFFD075 ]C:\PROGRAM FILES\WINDOWS DEFENDER
ADVANCED THREAT PROTECTION\SENSECNCPS.DLL
[3CE78583DF803541F907DEA625F24DBC][1 2465792
B7D6D940A6AED558881CD371713290D52C8C388C ]C:\PROGRAM FILES\WINDOWS DEFENDER
ADVANCED THREAT PROTECTION\SENSESAMPLEUPLOADER.EXE
[D9DA25006DF709013818EF18D8CC6257][1 124928
3421AD0686E8E7E52B956C2601DD23A6D7EE9636 ]C:\PROGRAM FILES\WINDOWS DEFENDER
ADVANCED THREAT PROTECTION\WATPCSP.DLL
[B3A583725D3DF22C65241FCF7820312C][1 188928
87BF7ED7181CCC45F1A8B27A221C44E29377B643 ]C:\PROGRAM FILES\WINDOWS
DEFENDER\AMMONITORINGPROVIDER.DLL
[83EDE17A1087F8D5779A6C023B5B490A][1 306176
26C25BF7E2877EF97B7E988B6CFB195C93A872F0 ]C:\PROGRAM FILES\WINDOWS
DEFENDER\CONFIGSECURITYPOLICY.EXE
[E351D93D81B404C4264A3B892CDE5F63][1 224256
B409DC470B0278BF003166E6F6B969E48B60C1FF ]C:\PROGRAM FILES\WINDOWS
DEFENDER\DATALAYER.DLL
[39E4335CEE44BC72B051D507A96C6D3C][1 1514688
24DFE29595C84DE0116BC4E38B01DFD9B5057EB6 ]C:\PROGRAM FILES\WINDOWS
DEFENDER\DBGHELP.DLL
[8778AB3D6B4F621F9169BC6A329543A3][1 74240
2788CD5BF7CA8C3BA8704F4443B04C1FEB1FB4E1 ]C:\PROGRAM FILES\WINDOWS
DEFENDER\DEFENDERCSP.DLL
[0691E383B177676EED882A9B6993A821][1 724480
F3ED0902D0133BD0521E18DB578ACD464A367E01 ]C:\PROGRAM FILES\WINDOWS
DEFENDER\EPPMANIFEST.DLL
[19FABBE4C1DDC6417C3029A508D4827F][1 631808
0F55135DFDD30FFC76E9C70D7F94AF5097A4D8A8 ]C:\PROGRAM FILES\WINDOWS
DEFENDER\MSASCUIL.EXE
[6172D16FF17620FD9F0121A7C8E148CE][1 103720
57E15F8D323F716542C631942A472C93F7B01EBB ]C:\PROGRAM FILES\WINDOWS
DEFENDER\MSMPENG.EXE
[80F04680CB078F6DB5ED42A5F9C412DC][1 347320
E09114D22506FDFC4474E47B69676C62CC78DA6F ]C:\PROGRAM FILES\WINDOWS
DEFENDER\NISSRV.EXE
[4596B539E05DA555E5DCC1619D94383C][1 2069504
D1E74E09316F7AE9C5ED2EFB01074ED24422C0EA ]C:\PROGRAM FILES\WINDOWS MAIL\MSOE.DLL
[DA8F93E3FE82595E59D3C7F37423C0C8][1 2487296
29881E47692E051B5A05D7C728610B438CB1B95F ]C:\PROGRAM FILES\WINDOWS
MAIL\MSOERES.DLL
[05D159B05709E110075587FADB51EDA7][1 64512
645EF3BAF006B54B4FA722E657E3DCD472EFC806 ]C:\PROGRAM FILES\WINDOWS
MAIL\OEIMPORT.DLL
[DFD024A0B4BDD920DA9EBEC7B0ECE9EF][1 516608
AC09AE965C7FD17E4B162B51970F8F1BE3CACCA2 ]C:\PROGRAM FILES\WINDOWS MAIL\WAB.EXE
[26E0B4CE4FEBD882391625C5CA4F7EF5][1 49664
26E069CA404F9F4A5C1FDA09CF9195ADCBF75A08 ]C:\PROGRAM FILES\WINDOWS
MAIL\WABIMP.DLL
[C5A69100E505265FA73C6B8F288F75F9][1 68608
67AD90BBB03FECCBA5100BBE3501EBD129883E4F ]C:\PROGRAM FILES\WINDOWS
MAIL\WABMIG.EXE
[C5F5E02254B53EEC94402EFFDB89AE05][1 419840
0CFD518ABE4865415FFB96901C211E260E30343C ]C:\PROGRAM FILES\WINDOWS
MAIL\WINMAIL.EXE
[D359FFFE85645585694A96AA8D0C628F][1 184832
A58A717064DFA50F7F07AA445D0A058A761B7B9F ]C:\PROGRAM FILES\WINDOWS MEDIA
PLAYER\MPVIS.DLL
[13C398101A5ED0CE80ADBEBA857314A8][1 1842176
95F38898FA6FE8544A6DFDD8B79F5C0B87B21882 ]C:\PROGRAM FILES\WINDOWS MEDIA
PLAYER\SETUP_WM.EXE
[21E5561A3B3B7A9A32E84C15D1E4F7A4][1 90112
BBB42897A7978FA47B74600A195917C54D9927D4 ]C:\PROGRAM FILES\WINDOWS MEDIA
PLAYER\WMLAUNCH.EXE
[0E95DAD7FC69B2BDE60B7DFFFAAF6BB1][1 103424
CD9AD321487E5FD66020E7C28695538D374B3B62 ]C:\PROGRAM FILES\WINDOWS MEDIA
PLAYER\WMPCONFIG.EXE
[7F44C62301131DC4235B978DD9012F29][1 169984
23211CA642402C2EE17747599BD8AEC57096211F ]C:\PROGRAM FILES\WINDOWS MEDIA
PLAYER\WMPLAYER.EXE
[B3F74E43A73504F3C1D2B10948E67EC4][1 1184256
67CF711B311F0B408BB1F5310A2A28C8797AD5F4 ]C:\PROGRAM FILES\WINDOWS MEDIA
PLAYER\WMPNETWK.EXE
[B398A9122434C379F3737197EB2DD5C9][1 37784
BCE9E7CA5C230A2CAA9B725125CC63EFE9AC9653 ]C:\PROGRAM FILES\WINDOWS MULTIMEDIA
PLATFORM\SQMAPI.DLL
[24BA34EFBD7CE7DC20D0A2C7596E0044][1 4499968
F854C904E9B3AF105B7FBB5186BF2275CCAFA7C4 ]C:\PROGRAM FILES\WINDOWS
NT\ACCESSORIES\WORDPAD.EXE
[EA85193143D6B3E418931C3346ED5181][1 104640
19E96C3A51C73090C1D331CF0D75B5D148FE856E ]C:\PROGRAM FILES\WINDOWS PHOTO
VIEWER\IMAGINGDEVICES.EXE
[E120A034B508051B00D05C98306334F4][1 2311168
00DBF59B255F11B413E703324FE89D82D3EA5051 ]C:\PROGRAM FILES\WINDOWS PHOTO
VIEWER\IMAGINGENGINE.DLL
[8FF5003A798BC97556E56652BAE742CF][1 1959936
365E999BDECA2B3893C5F8A3569FBBA19E8074DA ]C:\PROGRAM FILES\WINDOWS PHOTO
VIEWER\PHOTOACQ.DLL
[91C265D9C7BFF499B8745DC4B3F9CB67][1 46080
EB628EC7B1DE81138101BB6197E93A8E15008A99 ]C:\PROGRAM FILES\WINDOWS PHOTO
VIEWER\PHOTOBASE.DLL
[F46A42D9AD47A273F9B3DB2F1AA91F7A][1 1751040
996BB50A5A73836213C15365BB8DD9F2BDCB6EEE ]C:\PROGRAM FILES\WINDOWS PHOTO
VIEWER\PHOTOVIEWER.DLL
[DD83C6FD509052A50C2432ACC4656C4E][1 37784
7CC0186375424516B8B51AA7EA3EA315956AC2EF ]C:\PROGRAM FILES\WINDOWS PORTABLE
DEVICES\SQMAPI.DLL
[68A08B7E269F75EC288F72BF76D715B1][2 990208
F2150ADB8E14EB42B8510478DE6E870F0D5F9B10 ]C:\PROGRAM
FILES\WLFJ5AXNNW\WLFJ5AXNN.EXE
[903930192DCD755910CA5F8E188CF10F][1 142688
]C:\PROGRAMDATA\DATACARDSERVICE\DCSERVICE.EXE
[349AB4F70E2AC44970894E7F03E1576E][1 236384
]C:\PROGRAMDATA\DATACARDSERVICE\DCSHELPER.EXE
[5EF3427AE503B5C03A48F7C9FF458B69][1 271712
]C:\PROGRAMDATA\DATACARDSERVICE\HWDEVICESERVICE.EXE
[E90DA42B87D684DEBFB73B38A718A006][1 346976
]C:\PROGRAMDATA\DATACARDSERVICE\HWDEVICESERVICE64.EXE
[614A840588E8461B582DBB1A14B9EC45][2 215552
ECDE813BB9BA0B6FFC96FC1C916F581AD551A4FD ]
C:\PROGRAMDATA\MICROSOFT\NETWORK\DSQ\BROWSER\SYSHOSTCTL.EXE
[276694C17A5140572727B370149D4B1C][2 7906816
9667088B4AAF60560D0AC3370F409640A482A4A5 ]
C:\PROGRAMDATA\MICROSOFT\NETWORK\DSQ\NETWORK\SYSNETWK.EXE
[ -2][0 -1
]C:\PROGRAMDATA\MICROSOFT\WINDOWS DEFENDER\DEFINITION UPDATES\{002DD7E9-BD89-4D24-
B582-AF6C6E4300A1}\MPKSLBAB3842B.SYS
[C856C9308A3F6E4328CDFF0C360ADB74][1 224848
B047B360958D24E9D116B57471EBE519599518FB ]
C:\PROGRAMDATA\SETUPTPDRIVER\CHECK_HWID.EXE
[67849862DC4CA6A8A34C1FA703F67AF4][1 60184
B6EF8B81B5F3598E48BFF4BDD6FFEF73DC51C138 ]
C:\PROGRAMDATA\SETUPTPDRIVER\SETUPSYNC.EXE
[66AAE701A787E4BDF73116B79274DC86][1 655744
12964FCF07BEE5B39D1CE20026066092080548FA ]
C:\PROGRAMDATA\TELKOMSELFLASH\ONLINEUPDATE\OUC.EXE
[ -2][0 -1
]C:\PROGRAMDATA\WINDOWS\SYSNATIVE\MSWAPI64.DLL
[C3EE5331CC073F001D4C849398C90D5D][2 3302400
2D27D225EEEA034EF4BBC415F522AC65026B09EB ]
C:\PROGRAMDATA\WINDOWS\SYSTEM32\MSWAPI64.DLL
[858B3009ED26E924913CC5A2FA537A27][2 304640
04A1A8CF11C334D78BDC9538C2AE94310477E421 ]C:\PROGRAMDATA\ZIPSERVICE.EXE
[CB037F03178E31BA2985ADD15879CA56][1 846288
]C:\USERS\USER\APPDATA\LOCAL\GOOGLE\CHROME\APPLICATION\CHROME.EXE
[EE2826CAAF139688445D93C7C6613EE3][1 1686736
C689184A1944FB5BCD29DB8430105E4E767D29EA ]
C:\USERS\USER\APPDATA\LOCAL\MICROSOFT\ONEDRIVE\ONEDRIVE.EXE
[4C1E83ABF727837F6E99100D49A24719][1 2811088
A7567F82C6CA48FE2C48D68E97C21E7367499F93 ]
C:\USERS\USER\APPDATA\LOCAL\MICROSOFT\ONEDRIVE\ONEDRIVESTANDALONEUPDATER.EXE
[ -2][0 -1
]C:\USERS\USER\APPDATA\LOCAL\PCBOOSTER\BOOSTER.EXE
[9E9EDBC373699E82956CCBF7F6683789][2 24421584
6B725A45A9F0C1DC6B2D0D624C4AD5D54F7EFF03 ]
C:\USERS\USER\APPDATA\LOCAL\TEMP\BITAF5B.TMP
[7322B961D7FB3E14C26F131AAC1F093A][2 4029848
1C8352412D889D81DD277168BC27AC2965E0FD5D ]
C:\USERS\USER\APPDATA\LOCAL\TEMP\D71D.TMP.EXE
[865AF113F8B831D1D92980B92C359D88][2 97280
A3A4849D34A04581280B13B9E644E9CA513B9479 ]
C:\USERS\USER\APPDATA\LOCAL\TEMP\DRIVEREASYSETUP.EXE
[5C5213ADEACB4FAFA3AEFB434D995484][2 1021168
5A40FD5BEB117D381177071B686B5DC1764FDF0E ]
C:\USERS\USER\APPDATA\LOCAL\TEMP\FASTDATAX.EXE
[A7DF60B14578045DD07E0965D8DB6D0C][1 497312
]C:\USERS\USER\APPDATA\LOCAL\TEMP\INS2348.TMP
[A7DF60B14578045DD07E0965D8DB6D0C][1 497312
]C:\USERS\USER\APPDATA\LOCAL\TEMP\INSFDA.TMP
[DC3C90BE05EE2DF50D6C5E2982D8F741][2 662914
0740F1A094A829EA5662B5591A6FEE936C64AECF ]
C:\USERS\USER\APPDATA\LOCAL\TEMP\INSTALLER.EXE
[9E262DB9A442E262F35A3A925C53CF1D][2 3678526
F8B51ADE754606A2058993B868D29A926CEA9AF7 ]
C:\USERS\USER\APPDATA\LOCAL\TEMP\INSTALLER_CAMPAIGN_20539.EXE
[9A68A47E6E78E12B200D8A293B3653D8][2 726528
99788E6FFF6FD5B4911966A637DFD651C629CEAC ]C:\USERS\USER\APPDATA\LOCAL\TEMP\IS-
HSERE.TMP\SSXTK4J2TIJ.TMP
[9A68A47E6E78E12B200D8A293B3653D8][2 726528
99788E6FFF6FD5B4911966A637DFD651C629CEAC ]C:\USERS\USER\APPDATA\LOCAL\TEMP\IS-
R89CC.TMP\DKLTX5ANUBP.TMP
[9A68A47E6E78E12B200D8A293B3653D8][2 726528
99788E6FFF6FD5B4911966A637DFD651C629CEAC ]C:\USERS\USER\APPDATA\LOCAL\TEMP\IS-
ST85D.TMP\2BBFEQRERM1.TMP
[858B3009ED26E924913CC5A2FA537A27][2 304640
04A1A8CF11C334D78BDC9538C2AE94310477E421 ]
C:\USERS\USER\APPDATA\LOCAL\TEMP\MSTOOLS.EXE
[7EBC0298B305CDA6D4D23DC247F5CFB3][2 5669275
DD9A8566871ED59284ECACFDA48EA3A9A3CE4000 ]
C:\USERS\USER\APPDATA\LOCAL\TEMP\PAI5BD3.TMP
[AFDBB9D68320CFD5B9789FF0F248B685][1 21414896
]C:\USERS\USER\APPDATA\LOCAL\TEMP\PAIAD7C.TMP
[77DF6B779436CC0CD141A9877C804DB3][2 5648384
288F744F4B28D570260A26F77E1A771C8C5D72AA ]
C:\USERS\USER\APPDATA\LOCAL\TEMP\S2S.EXE
[58834134BF1C3A9E72D479A94FE14151][2 289663
DBCF999E0E8BBACB602C056636FB5D8C9C9AD836 ]C:\USERS\USER\APPDATA\LOCAL\TEMP\SETUP
(1).EXE
[A3B48A1734E7ADCC9FCCBBA99604522C][2 863232
2FA8AE2C2B4E1B43B022CAB34F5AE52863B97255 ]
C:\USERS\USER\APPDATA\LOCAL\TEMP\SETUP.EXE
[4EEECE48A0D996061EFC931AA4670CE8][2 8113298
49245D2176C0707634C5A3235D4A6C95B9BCDD08 ]
C:\USERS\USER\APPDATA\LOCAL\TEMP\SETUPQW.EXE
[AEDAB730F8C7AA5043070BBC595A2802][2 798629
02BDE08B473FA4F2BA75E98DC6DF8299ED7EE8FC ]
C:\USERS\USER\APPDATA\LOCAL\TEMP\SPEEDOWNLOADER.EXE
[3C76D7A940EF8728F891312D3EBDBA26][2 5915136
DE1176351206D376010E1382940B01678B1483C6 ]
C:\USERS\USER\APPDATA\LOCAL\TEMP\SYSTEM32\LOGS\SHELLEXPERIENCEHOST.EXE
[6267502F251DE122487DD44A499299FD][2 104129
0A1CC4F00AA29335202C678C920D754407E7501E ]
C:\USERS\USER\APPDATA\LOCAL\TEMP\UNINSTALL.EXE
[422AA91F542B07C6D5668B711A844F18][1 20479704
47FA7BCF1FFC7F93F6C52A0C79788AC7CBB41CC2 ]
C:\USERS\USER\APPDATA\LOCAL\TEMP\WCT31F4.TMP
[9D85CD8E245989DE49CB1A7FF89EF320][1 26435280
13413B8C3D2AC7775624D5AF25A46108F8C38CAA ]
C:\USERS\USER\APPDATA\LOCAL\TEMP\WCT895A.TMP
[EE0F39935189F6F2B749651A5843EB5A][1 20478176
CED38E7077DDD1BB010E6E76BE017196FF2CE5FA ]
C:\USERS\USER\APPDATA\LOCAL\TEMP\WCT9D24.TMP
[4CC103AC942998CF807361F73D2129E1][1 24421584
5CFB090D19D296355F6FF361C39848446C39AF9A ]
C:\USERS\USER\APPDATA\LOCAL\TEMP\WCTA171.TMP
[AE0A7D1C63482A6C3754BBA061F4437A][1 27718352
81B8E0BE8C4DF8DBF729B33184F414D34D955216 ]
C:\USERS\USER\APPDATA\LOCAL\TEMP\WCTAE24.TMP
[7D9FBEE2B835D139FA9519873BAAF4C2][1 24648912
D9C0D75C372B303EB82063E28CCD247854602263 ]
C:\USERS\USER\APPDATA\LOCAL\TEMP\WCTD2C7.TMP
[E32E3B345C54C90B2AE01ED6C7561C68][2 848896
91B56099A4EC0720075E110DD32E490DC3BCE4F4 ]
C:\USERS\USER\APPDATA\LOCAL\TEMP\WINDOWSTASK\MICROSOFTSHELLHOST.EXE
[9B4DEA23F81C7961CA3B9F40F210EB18][2 1409
0E24D672EBC2F995017D2362C6546753818CA3CC ]
C:\USERS\USER\APPDATA\LOCAL\TEMP\Z@SE3B2.TMP
[CDFDE64D4A5DD28FE36F2220DB9EEAE2][2 1409
5DCAA3B5D255D941C3375CA32EE648DA706FD343 ]
C:\USERS\USER\APPDATA\LOCAL\TEMP\Z@SE6D1.TMP
[439914C4D36A3ACF701C118D8DA6317E][2 1409
36AF7A6B07BEB8EA742FB79FA08E900097349E3B ]
C:\USERS\USER\APPDATA\LOCAL\TEMP\Z@SE7ED.TMP
[B2B8F554753FA4334A0EC9122AB82A8B][2 1409
8F96FACFE47F987486C95DAD7B514101ABDB7B5C ]
C:\USERS\USER\APPDATA\LOCAL\TEMP\Z@SE8F8.TMP
[0F739F54DB2D8E0761FF0045400395E4][2 7918080
DC521644F688B4D708757ADCB5A7837B4DE62712 ]
C:\USERS\USER\APPDATA\ROAMING\1337\SETUP-LOGGER.EXE
[AA5F1CFFDDD5C0AC8E1ECCA4BAC343BB][2 636162
7509E305D0C6AD9F49A8F12977FC6D01729EAC07 ]
C:\USERS\USER\APPDATA\ROAMING\1337\SETUPQW.EXE
[4CDD5BBD09DCE682CD595B027D84B248][2 3600015
7EA2B2B1B8559A1C9C2886CC1AC3BADB6A576C99 ]C:\USERS\USER\APPDATA\ROAMING\64.EXE
[309ECEAD9BBEC69706B52624E2A34DFC][2 811193
50BFE4CCE893CBBC791E68089D590C5CDC77A6B1 ]
C:\USERS\USER\APPDATA\ROAMING\B40I5J0RX13\DKLTX5ANUBP.EXE
[6A2BD1A3D350DA0A0CBE276A34103A13][1 7191176
]C:\USERS\USER\APPDATA\ROAMING\IDM\IDMUPDT.EXE
[105CCAFC5CD1373BBAEE2FE1F0F1B104][2 501192
D5D2B5CCA49CDEB237789BF463CA020FE509E020 ]
C:\USERS\USER\APPDATA\ROAMING\SYSTEM\SYSTEMCARE.EXE
[71417FB9C2CB2B8FEC66B33052E462D1][2 2195868
BC5AA1F4CF59C08871D7E8CD559FC3D9797A0660 ]
C:\USERS\USER\APPDATA\ROAMING\SYSTEM\SYSTEMCARE-PPI-UL5.DLL
[95C38686E22E6F4384F6C8552056CE84][2 801792
83E8D228B467D0709B2561A44BBFD1FE13159434 ]
C:\USERS\USER\APPDATA\ROAMING\SYSTEM\WINDOWS.EXE
[F743E06C09EE224BBA0C949C4DE0943A][2 758502
96A4D081E3AF7C2A39B14D740858B91534F8EDB2 ]
C:\USERS\USER\APPDATA\ROAMING\SYSTEM\WINDOWS-PPI-UL5.DLL
[629628E33FA04E90F1D7B4FB00505F9F][2 118
B4B5B412B557B93CF859B186840089C307A03C80 ]
C:\USERS\USER\APPDATA\ROAMING\SYSTEM\WINLOG.VBS
[309ECEAD9BBEC69706B52624E2A34DFC][2 811193
50BFE4CCE893CBBC791E68089D590C5CDC77A6B1 ]
C:\USERS\USER\APPDATA\ROAMING\UGIOAUUJ2GG\SSXTK4J2TIJ.EXE
[309ECEAD9BBEC69706B52624E2A34DFC][2 811193
50BFE4CCE893CBBC791E68089D590C5CDC77A6B1 ]
C:\USERS\USER\APPDATA\ROAMING\W43JJDYZMS2\2BBFEQRERM1.EXE
[4CDD5BBD09DCE682CD595B027D84B248][2 3600015
7EA2B2B1B8559A1C9C2886CC1AC3BADB6A576C99 ]C:\USERS\USER\APPLICATION DATA\64.EXE
[B54F757845528B73D74126981B0F6672][2 336896
DC648F68E4E2DB34E49BF7EE23F16D332C168A7B ]C:\USERS\USER\DESKTOP\TOR
BROWSER\BROWSER\FIREFOX.EXE
[E675C7006BDC625BC4EE9CF5BB1F7677][1 12090776
]C:\USERS\USER\TEMPLATES\ITUNES12X64PATCH.EXE
[577119EC77525D3F80FFB03BFACC17D4][1 4674872
7FC69FB9A44B1BDF800205B58A17324D778FC19B ]C:\WINDOWS\EXPLORER.EXE
[AE96BFE60A23845475156F6C189C9CF3][1 3685504
FC12F1589BE8F0B276CEC1AE9998BB956E13F216 ]C:\WINDOWS\INSTALLER\{90150000-0011-
0000-0000-0000000FF1CE}\XLICONS.EXE
[ -2][0 -1
]C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V2.0.50727\EVENTLOGMESSAGES.DLL
[E3DDF6A11B872AF1F959038DAB9DAE8A][1 805568
0E4C1670B48E36ADA242332176619BF3B6DB2BBE ]
C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V4.0.30319\EVENTLOGMESSAGES.DLL
[ -2][0 -1
]C:\WINDOWS\MICROSOFT.NET\FRAMEWORK64\V2.0.50727\ASPNET_RC.DLL
[ -2][0 -1
]C:\WINDOWS\MICROSOFT.NET\FRAMEWORK64\V3.0\WINDOWS COMMUNICATION
FOUNDATION\SERVICEMODELEVENTS.DLL
[2223D97FCF5E77A75D81EC732B8CFE1F][1 805568
BEFEE1F91A0BEB51E2A1185C77DFAE5326DCE049 ]
C:\WINDOWS\MICROSOFT.NET\FRAMEWORK64\V4.0.30319\EVENTLOGMESSAGES.DLL
[1080AFA8B42F9542CBB13BD5A53F0443][1 19144
A9540C1013766A21AFE88D69E992FAB0B4C1D7E8 ]
C:\WINDOWS\MICROSOFT.NET\FRAMEWORK64\V4.0.30319\SERVICEMODELEVENTS.DLL
[10D5997E2F5F16FE3BC3BD1A4BF31EA8][1 136312
E16C4A83A56C4DA4F3CCD922234EED02D60EE382 ]
C:\WINDOWS\MICROSOFT.NET\FRAMEWORK64\V4.0.30319\SMSVCHOST.EXE
[38DE5B216C33833AF710E88F7F64FC98][2 4608
66C72019EAFA41BBF3E708CC3824C7C4447BDAB6 ]C:\WINDOWS\SECOH-QAD.EXE
[09440FA30C020B4443391FAFCF4876E3][1 122880
7485B2CFFDF2778A0C8E055714DFABA62811A50E ]
C:\WINDOWS\SERVICING\TRUSTEDINSTALLER.EXE
[76A12AC673B0F8A607ACDD0583C247D4][1 197632
5A774803406BBBED5269B01E8BF1EF0BADC5E964 ]C:\WINDOWS\SYSNATIVE\APPMGMTS.DLL
[1B6BA244B378EFEAB72AB9982BE56960][1 1295360
52F83ABA95FECE7DF5C2FF094B6F5E9F848106FE ]C:\WINDOWS\SYSNATIVE\COMRES.DLL
[31D327F410B68F23E2616C5383F2E022][1 13824
A9F12B21268FE27DEC35385769B2438ADAD6924F ]C:\WINDOWS\SYSNATIVE\D3D8THK.DLL
[833C77070F107248F17F90E6E7416A5F][1 579072
0D56BA39648EB91726F448BDCD07811B487F74D5 ]C:\WINDOWS\SYSNATIVE\DDRAW.DLL
[2DA9DA17F0FE6C0A8598EBBB1E59E320][1 646688
8CA03643CBB920BA534B765AE3CC48BB7EBAC238 ]C:\WINDOWS\SYSNATIVE\DNSAPI.DLL
[AD732A06645E88A1BE604BD9802901B0][1 603136
D1C5D0D187BB61C421F0295ECAACFA6328BF58C6 ]C:\WINDOWS\SYSNATIVE\DSOUND.DLL
[FB30AD7EAD9E77C61778DE7E27E30C59][1 351744
A9B01590E0595E9F809A7DDA7B5C3FA690C01E5A ]C:\WINDOWS\SYSNATIVE\HNETCFG.DLL
[E1024CF2E35DD3467F52BC83F7FEDA3F][1 175672
BECD026FFBAA428FA50056A7BA0A990F009175A1 ]C:\WINDOWS\SYSNATIVE\IMM32.DLL
[D0ACFE08DAE3996DA1A6C8EAF5E0953F][1 219040
486431E6C8EC2C57C14A03C5E2262A54A05DD5C0 ]C:\WINDOWS\SYSNATIVE\IPHLPAPI.DLL
[725F5C26331AE8F24BAD8BC2AB99DB9E][1 23816
48E24A66EB9FF83DBDF26BEAB5E39F9257CBC757 ]C:\WINDOWS\SYSNATIVE\KSUSER.DLL
[44BEC97BD0CED39125993D75BE728D80][1 3072
6F685B46F419A1DA5CB401CD2D2E527B74762F1C ]C:\WINDOWS\SYSNATIVE\LPK.DLL
[DAB20111EE99BCA4019A6D285FF2EA0E][1 25088
7B3A90B6D663704539E2E5FAFA5C81530FCB6D4D ]C:\WINDOWS\SYSNATIVE\MIDIMAP.DLL
[E7C0E7F21AF69FE20FB697DCE66AD255][1 10240
69313A045FDD0174F8D115663AE8869A7C3A2FB2 ]C:\WINDOWS\SYSNATIVE\MSCTFIME.IME
[A7F056E77075FE6D380E92C07273D7B6][1 23677952
661A0DCA0035FFFF16508EB150AA8B6F65BE1F4C ]C:\WINDOWS\SYSNATIVE\MSHTML.DLL
[78DA58DF85F86CA61E5EAFB9EF0A83BE][1 8192
A01DC7A9ED2E4B9C3A6E05290A8B108F0E379498 ]C:\WINDOWS\SYSNATIVE\MSIMG32.DLL
[10A6561536EC8ECC53BE5EABC40177A1][1 357216
7D4121D28AD092536917DB56F5575AAEF857B756 ]C:\WINDOWS\SYSNATIVE\MSWSOCK.DLL
[71514D9A6350A37B4F0BAA6ACB751771][1 67584
45A74F5464E3D151463A76F6B8FDEAE6226D6A7C ]C:\WINDOWS\SYSNATIVE\NAPINSP.DLL
[3BB593E36F3D8ADBCF63649C4DA5FB79][1 80896
F45D73F218F23B93E8E9CC3A3A5C3B3BD45248EC ]C:\WINDOWS\SYSNATIVE\NLAAPI.DLL
[B7CB8C4C89239FF52907E470A8AEAF84][1 86016
1C79C7192EAB16C9695DF409F66A0D53D823BFCF ]C:\WINDOWS\SYSNATIVE\PNRPNSP.DLL
[FAE8D0480BDD905EEA453D3A57C8D5C6][1 16896
2455EA8F056E5E394F887ECD49C50B7B32DDB4C1 ]C:\WINDOWS\SYSNATIVE\RASADHLP.DLL
[ACB36AD75A7DF5E5E8222EC02818D534][1 632320
55EDFED444185545982A7971D57365DBAE391C2D ]C:\WINDOWS\SYSNATIVE\RASAPI32.DLL
[4A7015195E49A3BA7DB967B277B21E9D][1 890368
D8DED357E1BAD6215CB4E01058F4E7A122B2562F ]C:\WINDOWS\SYSNATIVE\RPCSS.DLL
[7ED53A9C37AE7ADE2A72A1C2EE86879B][1 270336
F4E687A3434C481ADBED17B684D313DEBA91F881 ]C:\WINDOWS\SYSNATIVE\SCECLI.DLL
[29C7C9F0FE9F048FB47DEE5F66134940][1 453544
136B637CDC1528613BD88D995B0AC8E7293D05F3 ]C:\WINDOWS\SYSNATIVE\SERVICES.EXE
[36638CF94B685EB9298E53327B64B4EC][1 1259720
69A0FD8A67DF419EC8EC1E900FA42F98B9C12D45 ]C:\WINDOWS\SYSNATIVE\TASKMGR.EXE
[BAB449E496892494C1E8152A25A1E867][1 1460696
A35CF87C22E33FA33D80D2AA7B052C831721CB87 ]C:\WINDOWS\SYSNATIVE\USER32.DLL
[DB390129C210F39926A28AE5DF146DCA][1 587264
D92038FA74BD3CA0E22D9937A06DC43C6D903FD2 ]C:\WINDOWS\SYSNATIVE\UXTHEME.DLL
[CB440E1C4EC9C369EC9DD07B48A83F36][1 673792
5216DEC07642D8C2CC6EB105674DA2A8C2917F8F ]C:\WINDOWS\SYSNATIVE\WINLOGON.EXE
[B0DE13ABF238AB28E963629B977A012F][1 31744
46E094186FCCEC5243053B312B63F7E5CA4F4D79 ]C:\WINDOWS\SYSNATIVE\WINRNR.DLL
[ED864F0617F9D4925CB99A3755E91FB5][1 4608
6286D421D4400C2F33C0920335706B4CEE77834C ]C:\WINDOWS\SYSNATIVE\WS2HELP.DLL
[D305B1E69D5647854F22EE2ED1FD81E4][1 62976
99757B02BF5ED623898CDCF0622B54990CBD5A98 ]C:\WINDOWS\SYSNATIVE\WSHBTH.DLL
[D9546C1D46352D55704A3696C8DFF19A][1 1227264
7A9B1728983B37EE2BF4C5ABE28EC271390EC59E ]C:\WINDOWS\SYSTEM32\AGENTSERVICE.EXE
[D0905D4A945D01D4B28DB9E1BD5985F7][1 24576
2785F49D0CD53A3503F89452BB68DE4201CEE4ED ]C:\WINDOWS\SYSTEM32\AJROUTER.DLL
[8FD51B3B35707A66080D7C8CB05E792D][1 95744
7D3F39EDAB05CD0C3CF112D47008116BCB306B92 ]C:\WINDOWS\SYSTEM32\ALG.EXE
[17997DC2441F7E29CDFC6458E0392764][1 366592
E75F76D8E2D033AA39086D792B6677E63EC844F3 ]C:\WINDOWS\SYSTEM32\APHOSTSERVICE.DLL
[64479503F983B5A15FA8948E64484EAD][1 481280
365D71481237447EC69F47E68E25206ED8727F7F ]C:\WINDOWS\SYSTEM32\APPHELP.DLL
[0A7C202CDBFD295363A09DE1A2C05F45][1 124416
57022465579DDE207D412C06CD6375317EB4D138 ]C:\WINDOWS\SYSTEM32\APPIDSVC.DLL
[79A87DD43331290A276C02DC396BF530][1 125952
DF2DAE65BEBC5495D63FD2802B6454B825EEE461 ]C:\WINDOWS\SYSTEM32\APPINFO.DLL
[76A12AC673B0F8A607ACDD0583C247D4][1 197632
5A774803406BBBED5269B01E8BF1EF0BADC5E964 ]C:\WINDOWS\SYSTEM32\APPMGMTS.DLL
[03ACBF443DD7DCDCF7D9F783F8C676F0][1 453632
EF522D2757838C13B4DA6AE9794587F3D54F478E ]C:\WINDOWS\SYSTEM32\APPMGR.DLL
[96EA35C8FB0862772B9D3BA5BFAE4345][1 560128
9E56363D813CE0236576E5CCA833B80EA19B679A ]C:\WINDOWS\SYSTEM32\APPREADINESS.DLL
[64F968FD1AA5C3D8979D90CB562C05F9][1 825696
1AF5A76D7EE8AF004F337F221986BC08A210E2B0 ]C:\WINDOWS\SYSTEM32\APPVCLIENT.EXE
[CBFCE3D7C013B8C06C758278F646A110][1 337920
323DAEF1AF67BE5E33B6734AF630592776A4A3F1 ]
C:\WINDOWS\SYSTEM32\AUDIOENDPOINTBUILDER.DLL
[08877BD788DA2F263169CE878BB3DBBA][1 590952
560FDB069923CB6DCCF761C56D5EF0AD847414CD ]C:\WINDOWS\SYSTEM32\AUDIOSES.DLL
[179FF6D2853E9925157D47E283C3CAB9][1 942080
19E31EA51974211AFC741055419A21B5FD5F97FE ]C:\WINDOWS\SYSTEM32\AUDIOSRV.DLL
[6D90FDA2DC364B8EA1420F2F81585CC3][1 113664
2B81C170C45EB31426B958DB97877AE094429C22 ]C:\WINDOWS\SYSTEM32\AXINSTSV.DLL
[2B4D3AEAAD02954F8C191BC2D67949AD][1 361472
810F3DBC633289B5A4666FC4C00172A77E949702 ]C:\WINDOWS\SYSTEM32\BDESVC.DLL
[5125CBB61AC81168366BEB290399CB8E][1 795648
D44BDDB159B22E9914D9F2DBE17BFC8384C77D36 ]C:\WINDOWS\SYSTEM32\BFE.DLL
[82A93A0772A29EB6E41438D9AE5ECDBD][1 770560
006C123D29B1B5D7044C6C053829F81E436B9DD7 ]C:\WINDOWS\SYSTEM32\BISRV.DLL
[7E53588ABEE2DFE330203772FBE6ACC0][1 77824
A69401792FB6370BDD3CF0F7762265A94FB868DF ]C:\WINDOWS\SYSTEM32\BLBEVENTS.DLL
[B3F32C630DD3F2F6A6091B89CFF13641][1 134656
6410C5F2024499186B67AD3AAB0FB99229A86451 ]C:\WINDOWS\SYSTEM32\BROWSER.DLL
[B157D72BDA6A6DD6E9DC6BF338CD0CF8][1 321536
33C6A66E2649E14638F64040EB092635CB7A0154 ]C:\WINDOWS\SYSTEM32\BTHHFSRV.DLL
[577FFA2B0B8572587FEB825F42453E81][1 157184
C68363725D87A908CDB666D008AD1A3EB298DD3B ]C:\WINDOWS\SYSTEM32\BTHSERV.DLL
[2E6612376D257F74781F2EF1F869D8C3][1 411648
4FA1F933F97BC9E6E9F480A5693E0C5366C57916 ]C:\WINDOWS\SYSTEM32\CDPSVC.DLL
[A93C9B9EBE2FDE5A536000D72CC17F7F][1 339456
BD66E3D3E61490ABD08C2EE2D02C65B0198A1B3E ]C:\WINDOWS\SYSTEM32\CDPUSERSVC.DLL
[E723468DB8B986D2C7F2441FE9CB4A6E][1 451072
55B97FB07FD94687D0F46EC4D0A639FDCBF584B3 ]C:\WINDOWS\SYSTEM32\CERTCLI.DLL
[5F630B2EB47C3DC8DE3C405677069D66][1 2919936
929A4069C63DE6F0B35AD734918C3FC77D117AE6 ]C:\WINDOWS\SYSTEM32\CERTENROLL.DLL
[F99E6C664A3D503878DAD628088AF855][1 193536
A9B5DBD814BF8025B0F6F5A127FD38B7169E305E ]C:\WINDOWS\SYSTEM32\CERTPROP.DLL
[E133CFCBFABB3CB517BE9F42FEA5887C][1 729328
3C3F75E24457067E18916D2E03F11426F9C5C3F5 ]C:\WINDOWS\SYSTEM32\CLIPSVC.DLL
[F4F684066175B77E0C3A000549D2922C][1 232960
99AE9C73E9BEE6F9C76D6F4093A9882DF06832CF ]C:\WINDOWS\SYSTEM32\CMD.EXE
[93B9E4D0B7BD601372C5B50FE0381533][2 385024
]C:\WINDOWS\SYSTEM32\CNMLMA4.DLL
[642C70214A0310F3C92EBF5FEFBC5570][1 2915704
8D87CDDFAC0B0FDCFC92416BA5C1C8F99223A798 ]C:\WINDOWS\SYSTEM32\COMBASE.DLL
[D752C96401E2540A443C599154FC6FA9][1 47104
00667A0F0C0D5E9DA697E9FF54ECDDD449259354 ]C:\WINDOWS\SYSTEM32\CONHOST.EXE
[6BA7D72D00D3E7A4BFFAFC8002E0E28A][1 764392
89ED96C98125B26CB8F149280E4C464BEB2FD009 ]C:\WINDOWS\SYSTEM32\COREMESSAGING.DLL
[A00EF88CB0CE0DB24251B5266BCD1973][1 1852200
FDD0B3A4FAA8FBDE257BF90BC532F37A1A261CC4 ]C:\WINDOWS\SYSTEM32\CRYPT32.DLL
[5F06CAC4B09250CDDDD0180A08162924][1 81920
90CC13C98F184B6F7080705AAF88BFDFB95E51AC ]C:\WINDOWS\SYSTEM32\CRYPTSVC.DLL
[BE35D1BAC3F18C9EB1C1CFBA31ED95E3][1 735744
25BAA853AAE5725ADF4A55BCBDB05671C65F92A6 ]C:\WINDOWS\SYSTEM32\CSCSVC.DLL
[DD74F18227ACC837D9856E24282D446D][1 447488
38341609E140B5859BEF100446F4D15ACA3ED9A2 ]C:\WINDOWS\SYSTEM32\DAS.DLL
[6F12B244B6BAC8EEEB506C0BEE04F8CB][1 94720
38F69F685B774C1F965D2A9E8070AD7ABF0D8526 ]C:\WINDOWS\SYSTEM32\DASHOST.EXE
[AE9F09F87755C18904656CB4F59F351D][1 183808
5629A4A947A3725B05A51EB8250026A7619183DB ]C:\WINDOWS\SYSTEM32\DCPSVC.DLL
[3C212EF64653D92DACD4F181F3EC0CE8][1 274944
565153E2119DDFFEDB160429AF614BBFE690F967 ]C:\WINDOWS\SYSTEM32\DDPUTILS.DLL
[ABBD3EE724117242E28D31F19FBCFF03][1 511488
5BF26F409739111093B25B9B037CF1D6CDE17F79 ]C:\WINDOWS\SYSTEM32\DEFRAGSVC.DLL
[7433474BE77F065D2FA628671FE31A3E][1 197632
BB250A4903D3CA4406E23ABF2E8151C7FA4B1A34 ]
C:\WINDOWS\SYSTEM32\DEVICESETUPMANAGER.DLL
[CDF1B1B5C5951111791C236B2696C7F8][1 34304
36301520648D22C3E7AEE75EDE609688B43F4D02 ]C:\WINDOWS\SYSTEM32\DEVQUERYBROKER.DLL
[F0D4400BA0F08610D9A551B15BF10B76][1 360960
30F32D4C8881180328FFD05C68CBF11A41A2B01C ]C:\WINDOWS\SYSTEM32\DHCPCORE.DLL
[CA7FEDDFCF61EF15A09C54DA2C07C49F][1 93184
896FCB18AEA40636E2BEE8D6F6EC7BA119703F69 ]
C:\WINDOWS\SYSTEM32\DIAGSVCS\DIAGNOSTICSHUB.STANDARDCOLLECTOR.SERVICE.EXE
[5BEE714B23F24C2FE8DDDDF3D936CAEB][1 1984000
2756FDC335A9AC881F5D85FAC1DFE7DAD0F6DBB3 ]C:\WINDOWS\SYSTEM32\DIAGTRACK.DLL
[F2F2FED1EAE5A089D959D1D6DBFD7DD4][1 43520
1C0737691B3BE856BAC1FE2686A0E7CF7B9A8CD2 ]C:\WINDOWS\SYSTEM32\DIMSJOB.DLL
[706E1428017BF2667368457199343745][1 46592
8875873BF12B76E771E4233BE389338517F8A74F ]C:\WINDOWS\SYSTEM32\DIMSROAM.DLL
[DA63852A2B0340E94D74EAF0CD444979][1 21344
0E33FA9CE0074155F361DB9CB36183431C8FC266 ]C:\WINDOWS\SYSTEM32\DLLHOST.EXE
[6E5EE6E420FECD64DE463C5F01CBFE71][1 57344
52CD3BC24C8A620F028E889296FC912B146C796F ]C:\WINDOWS\SYSTEM32\DMWAPPUSHSVC.DLL
[DBF8AEF8F3573B9D5A5BCE68A2442487][1 265216
DEFCB4C1F6040A0771233E6A2FF5AF0F99327D95 ]C:\WINDOWS\SYSTEM32\DNSRSLVR.DLL
[8F46B4C3F9BA19C26A26D0A11137B20B][1 262144
29CF52449DB88274A886C019701E1CB4D9B21C48 ]C:\WINDOWS\SYSTEM32\DOT3SVC.DLL
[CA09EAEE92C6FDDC6B05057F11A0372D][1 172032
394E9ED9DF732674F3F74397D72267D39B597F9E ]C:\WINDOWS\SYSTEM32\DPS.DLL
[80208B7892BEC1ACA6409383F193E860][1 12232
6AB06C7D3C9F67DD3A2B77C054138645C3C621CB ]
C:\WINDOWS\SYSTEM32\DPTFEVENTLOGMESSAGE.DLL
[D46558489473E42271DECF7D914A0375][1 115656
]C:\WINDOWS\SYSTEM32\DPTFPARTICIPANTPROCESSORSERVICE.EXE
[BC5F74FE1451C10C4AF32EF441DB72F1][1 118728
]C:\WINDOWS\SYSTEM32\DPTFPOLICYCONFIGTDPSERVICE.EXE
[F27686F62321BBB8246D468A2F8F42E1][1 124904
]C:\WINDOWS\SYSTEM32\DPTFPOLICYLPMSERVICE.EXE
[09B7C685A35DFB954BD2C7FE30268C0A][1 111488
758AF86768352623F693AB1BA2DEC0F8E73508DF ]
C:\WINDOWS\SYSTEM32\DPTFPOLICYLPMSERVICEHELPER.EXE
[A7901875F89D011C38CF52C98ACF5B29][1 235520
895407CB018368E62FC360B972A8B0DA7E729662 ]
C:\WINDOWS\SYSTEM32\DRIVERS\1394OHCI.SYS
[EE1CCC54F75C24727A218F98FC5349DA][1 107360
1D670E2C8594733506375D2DA1C37452189D37D3 ]C:\WINDOWS\SYSTEM32\DRIVERS\3WARE.SYS
[73C73E1AA0D4D727A04AAAB120B7F56A][1 705888
F7DE80E50DCEA40B389D39005A84039D8FE07C41 ]C:\WINDOWS\SYSTEM32\DRIVERS\ACPI.SYS
[0935496EF9624B46B935CB35ECE1F205][1 18432
5AF567A52A010553901ABE347F191628E8785E6D ]
C:\WINDOWS\SYSTEM32\DRIVERS\ACPIDEV.SYS
[D6794C31F4077B71433988787BAA926E][1 126816
]C:\WINDOWS\SYSTEM32\DRIVERS\ACPIEX.SYS
[FE5F656D6B35089DA39112E74EC6A85A][1 12288
B563EFCB44EBC623C6C995FDD9B99A7A15BCF274 ]
C:\WINDOWS\SYSTEM32\DRIVERS\ACPIPAGR.SYS
[2F242941E4DFF69B883D77A16F039557][1 14336
FDE1B95D7165DB9A41D74C85087E998DDCC21BC2 ]
C:\WINDOWS\SYSTEM32\DRIVERS\ACPIPMI.SYS
[C247E35A21682DA8D0DC3AF9F025FCC5][1 13312
F386096754166B5FE85F2C5C25240610E3272D47 ]
C:\WINDOWS\SYSTEM32\DRIVERS\ACPITIME.SYS
[49B9DB97AFC85DCCBDACDAB2E90085B7][1 1135456
6E08310A63BC538D49E196AF07E52B50BE438C24 ]
C:\WINDOWS\SYSTEM32\DRIVERS\ADP80XX.SYS
[323AA1953ED9C01E23F740FA891FE064][1 584032
62D034F2A2FAEBBACB7393ED73BED5EC466F0832 ]C:\WINDOWS\SYSTEM32\DRIVERS\AFD.SYS
[28C2EA278070EE12701D0EDF8CB0EC36][1 107520
C9E8DD9385F49970D2FD187FFD8936EAA8ABBCC4 ]
C:\WINDOWS\SYSTEM32\DRIVERS\AGILEVPN.SYS
[23522E5D581F7722B1B5B86737CAE39C][1 227328
8B2820B3D65DAF1C34B41746B64775095BA8CEA8 ]
C:\WINDOWS\SYSTEM32\DRIVERS\AHCACHE.SYS
[DF21E05E41E5AC3F13F304D91457649A][1 123392
F80AA304C3B17EFF476E751ACBE8240FD5B1BA6C ]C:\WINDOWS\SYSTEM32\DRIVERS\AMDK8.SYS
[45D0AA4BB90B821DF92E8F19ABED0C5E][1 120832
C7EE072DEA40E0FD1AF517B18C8314AF644D0429 ]C:\WINDOWS\SYSTEM32\DRIVERS\AMDPPM.SYS
[74FFBC43B4B899C9A8CA06A892F2CE73][1 83296
928091DB5A9EDEF638C5C7BDDE179BDCD5BBBD08 ]
C:\WINDOWS\SYSTEM32\DRIVERS\AMDSATA.SYS
[AAB0F1D8D7E54761ABAB13AF161F1680][1 259424
D61F30E3F0C50AF00260863AA9B44C89E7005BD6 ]C:\WINDOWS\SYSTEM32\DRIVERS\AMDSBS.SYS
[F91BAAC4237C40352A807000F3B716F9][1 26976
9C8E5F11678BE54888CB7DEA95D816E6CCA06AA0 ]
C:\WINDOWS\SYSTEM32\DRIVERS\AMDXATA.SYS
[BC121C099C6C659126AD2102AFDFF8CF][1 172896
D538A483BD79A78B12943F41769EA1B13CF46B32 ]C:\WINDOWS\SYSTEM32\DRIVERS\APPID.SYS
[68190E2BADF23BD782344970E5B5DE9E][1 15360
202EFCCC37EDD1DF26C71ECBA166F6C30C4E6C70 ]
C:\WINDOWS\SYSTEM32\DRIVERS\APPLOCKERFLTR.SYS
[B66ED2CB37F7E4696A51612AFBA08834][1 127328
18C266EAD2DACBAAFFF1E3F7166DB64B4F043C87 ]
C:\WINDOWS\SYSTEM32\DRIVERS\APPVSTRM.SYS
[8DC924848E20F890BEFC6B31136D46BE][1 157024
E5B0BCD1D3ACFD3290E727745F684725B06269EE ]
C:\WINDOWS\SYSTEM32\DRIVERS\APPVVEMGR.SYS
[9ADC5A8BEE10E174F95349E9232D8E76][1 141152
F2E740A01EF88CB1CF76AEE3BE15F7563BF1FF51 ]
C:\WINDOWS\SYSTEM32\DRIVERS\APPVVFS.SYS
[E6AB1F0B4C3D4E0D2A88332D76FECD03][1 131936
E580E83F322D4B622AC44E9F616C403F596781E6 ]C:\WINDOWS\SYSTEM32\DRIVERS\ARCSAS.SYS
[38DA94B6DD8022DA43810E4328608E54][1 27872
8319F00D9F4C0AC7716436D57FA7608C4C591C5F ]
C:\WINDOWS\SYSTEM32\DRIVERS\ASHIDSWITCH64.SYS
[CB9C9479F43A3C1C9DC8F16E71C0AA6B][1 124928
121FE8675DFB8B20CE75AB20FC15C475F28299BD ]C:\WINDOWS\SYSTEM32\DRIVERS\ASUSTP.SYS
[61C5A480C43E7E8E49C42869F49D0D3E][1 28160
6B793017A6C71FBFBFB13B28BDBBE15D0A1861A5 ]
C:\WINDOWS\SYSTEM32\DRIVERS\ASYNCMAC.SYS
[A10F989A812B57B9695F6C305907C9C6][1 28512
24FACE5B5CA39CE04CF462ADD690AC401051AF97 ]C:\WINDOWS\SYSTEM32\DRIVERS\ATAPI.SYS
[835E2C1A3D32492E2B90BD4FE5527CB6][1 4233728
E649EAC3D9680CD11D26C2F4C8EAC60040889BC6 ]C:\WINDOWS\SYSTEM32\DRIVERS\ATHW8X.SYS
[94D6B95485BFA35D81524B0EBA0F7569][1 56320
F5B988A81B4E7FF88B88040E62C4AAC572149D3F ]
C:\WINDOWS\SYSTEM32\DRIVERS\BASICDISPLAY.SYS
[8CE702B1F8BB3C2A9702A4F3742D6216][1 41472
06A22CF2E29B0EE8573BBE8029584BE32013D65D ]
C:\WINDOWS\SYSTEM32\DRIVERS\BASICRENDER.SYS
[3F5523DCEFE42B385659C5CB46A6B810][1 9728
B682D88DAFB083EFE74A6853F6B90C7B8753CE73 ]C:\WINDOWS\SYSTEM32\DRIVERS\BCMFN.SYS
[0B750A6A6D847E73CA48ADD7A0F5A393][1 9728
4A5A71A74E9A0E1138B805DFBCF4A12D46D2C0E5 ]C:\WINDOWS\SYSTEM32\DRIVERS\BCMFN2.SYS
[7A3593DC24D0030CD4B0D92355768D63][1 53024
F8CF98A30291B4902753D128A97F903D2CFBCCD1 ]
C:\WINDOWS\SYSTEM32\DRIVERS\BCMSMBSP.SYS
[9CD2A4821DE379305CACB2E99AD8953A][1 101888
C0F35195AEC23E18C1B553824D5A4DEA187C438A ]C:\WINDOWS\SYSTEM32\DRIVERS\BOWSER.SYS
[85669C51BA3BBD4CF6457C280BFAEA0C][1 115200
325817D4F2031F74F102B3DEF763D6D67DDEDD9D ]C:\WINDOWS\SYSTEM32\DRIVERS\BRIDGE.SYS
[06E525D9DFEEA87BB69FCAADF21013E1][1 609992
59C4821499CA2BC7AB075F3622C424CF4B0A9C93 ]
C:\WINDOWS\SYSTEM32\DRIVERS\BTFILTER.SYS
[722036C26D2C4E50EC2A2EC5FD678846][1 43008
2A0645CA65864E1AE07003969047ED3D869DE528 ]
C:\WINDOWS\SYSTEM32\DRIVERS\BTHAVRCPTG.SYS
[77630A51FAF6A07922FEE835F4DED8F6][1 114176
062913AFDEA3906F27A5AE2432283AA2E4539C2C ]
C:\WINDOWS\SYSTEM32\DRIVERS\BTHENUM.SYS
[C2E31BE025D46D189E38DD1EDF07837A][1 65536
18374BB789088E154686ECCBA9E4A644B2DA1CE2 ]
C:\WINDOWS\SYSTEM32\DRIVERS\BTHHFENUM.SYS
[F7CD605FC0B0B22F3F6F247595E3A655][1 31232
3D476CD50DF7B3E6BD6F0472132D98018CD62AA7 ]
C:\WINDOWS\SYSTEM32\DRIVERS\BTHHFHID.SYS
[B887F6536B6F6566E1B6794878E8FBA6][1 250880
046BDE7E9F3B6580BBAEABD976C5EE232C721999 ]
C:\WINDOWS\SYSTEM32\DRIVERS\BTHLEENUM.SYS
[535DC41A33630AE4C262406F9E981C03][1 66048
9F832E7C18EBC7CDDEDB2ABED587A449ACC9A2EA ]
C:\WINDOWS\SYSTEM32\DRIVERS\BTHMODEM.SYS
[09A2E0DF0ED1D5D3F8C6779A0CC19529][1 128512
C12511C242495FBC1A444892697AB4E280CA854F ]C:\WINDOWS\SYSTEM32\DRIVERS\BTHPAN.SYS
[34C35293F5A3DEFEC59DBCD7BD4C17D0][1 967680
A2A413242283F6686B0FB2C74AEB5F8D3E4A585C ]
C:\WINDOWS\SYSTEM32\DRIVERS\BTHPORT.SYS
[DC5955E589C55E2313D69B64E1A183F3][1 84992
7923F24A992CC8149FCDDB5C2CE6BA1207C2B6A6 ]C:\WINDOWS\SYSTEM32\DRIVERS\BTHUSB.SYS
[23F9EF739F685E07482116425E7879AA][1 38912
632CA3BE2724309394A8BFBC5616D0F4E2EEF06B ]
C:\WINDOWS\SYSTEM32\DRIVERS\BUTTONCONVERTER.SYS
[61BAC67048CA5C1D08C48FCC8012B613][1 533856
9A5D36DA65E7B5399BF36CD7DFA6DC7775F3CDAD ]C:\WINDOWS\SYSTEM32\DRIVERS\BXVBDA.SYS
[60EB6A4CE3E21887D302350631C16F26][1 118272
D1E43EA9912D5296E1C0B6059D29AD85785E7FBC ]C:\WINDOWS\SYSTEM32\DRIVERS\CAPIMG.SYS
[F8FB51B9EF6372610E9B31A1D86B62FC][1 92160
E92ABC77441C3CD78500006D5AEF42576AAABDB4 ]C:\WINDOWS\SYSTEM32\DRIVERS\CDFS.SYS
[613D0137C269187FA298A157E3D14A18][1 173056
EA734E696B4F439890F41E31A537108CF3E230CB ]C:\WINDOWS\SYSTEM32\DRIVERS\CDROM.SYS
[1219A31A19E13524F9F73D59B01A478F][1 1553032
E47FDBEC989543D634EEF9C3EC9C00E4F1F9EED5 ]
C:\WINDOWS\SYSTEM32\DRIVERS\CHDRT64.SYS
[0AED948DA8D5F08B3D6F12E4E2089736][1 346976
0CB11022B6BCAB5F88D22FC51D101D9BF83BFC7D ]
C:\WINDOWS\SYSTEM32\DRIVERS\CHT4SX64.SYS
[0002A0FDE087C1657AB31CE73077539C][1 2104160
350F6FF955A3B1B338DF07FC1AE3040523008D78 ]
C:\WINDOWS\SYSTEM32\DRIVERS\CHT4VX64.SYS
[6B4F90A287D75CCD78694F6790C911B2][1 48640
7E762DEB806EF2ABE7236854A65DE8D670F6A607 ]
C:\WINDOWS\SYSTEM32\DRIVERS\CIRCLASS.SYS
[D9B1D367ED0852AD2BEBB58848995CBC][1 376672
FF6BAB9797E006A085772218313FA30715F3A861 ]C:\WINDOWS\SYSTEM32\DRIVERS\CLFS.SYS
[50F92C943F18B070F166D019DFAB3D9A][1 31088
]C:\WINDOWS\SYSTEM32\DRIVERS\CLWVD.SYS
[429623E266EF067A44E8CF148E9DFB9B][1 29696
93DBF8738680D5F3AF888C427D1264287BDEDB3A ]C:\WINDOWS\SYSTEM32\DRIVERS\CMBATT.SYS
[572F57487C4CFC0EDE2682F41D0AD424][1 624048
68CFE0373FF4FF1DFAB828CB9428E34439EFF30A ]C:\WINDOWS\SYSTEM32\DRIVERS\CNG.SYS
[3DB10C59405931E2C72EFB82C1AF97D1][1 38752
4D20216CF1583D9310A9E0DF643BBF61F0AC53B1 ]
C:\WINDOWS\SYSTEM32\DRIVERS\CNGHWASSIST.SYS
[44EEEB2382F566999287E13F2067693C][1 53088
EDFF2F63DF20625C9DB5DC6254B822E4AA7EE820 ]C:\WINDOWS\SYSTEM32\DRIVERS\CONDRV.SYS
[EC2EA2F6C6D23315C20B4829F00D0440][1 552960
E305F7AB289E64BF6CD3EE5A3FECDFCED9B0E3B7 ]C:\WINDOWS\SYSTEM32\DRIVERS\CSC.SYS
[3BBD0073265DA6D3EFBA54B26E5D8236][1 63328
92EBF9F56043C14A3775F6356BBD84E1BD638E5D ]C:\WINDOWS\SYSTEM32\DRIVERS\DAM.SYS
[385E6F76E684E7EEEECBBB156C45D191][1 144896
2BD9D6803E574E3A263DAAFE7C396F3E3B53199F ]C:\WINDOWS\SYSTEM32\DRIVERS\DFSC.SYS
[630A3DA76BAC02E678AD0C3EF77CCDE3][1 102240
8CACEED07D60CA9A8D30AC330082E83C50E57A43 ]C:\WINDOWS\SYSTEM32\DRIVERS\DISK.SYS
[815F45161A4571C2C44491564F3D5968][1 35840
7FCFA363262EF452A39A9A513D13A0233BB2EA47 ]C:\WINDOWS\SYSTEM32\DRIVERS\DMVSC.SYS
[620D90C4AB9091FECB3103BDD9165284][1 290256
]C:\WINDOWS\SYSTEM32\DRIVERS\DPTFDEVPROC.SYS
[C092B887E61D5A85FA891BF1D48C678E][1 494808
]C:\WINDOWS\SYSTEM32\DRIVERS\DPTFMANAGER.SYS
[AE6BD4C879A8C849E53947C92DF3B3A0][1 16168
0FF93E83326A7E8AA1111C756BFB75ADF1AB19B2 ]
C:\WINDOWS\SYSTEM32\DRIVERS\DRMKAUD.SYS
[0B729AE130D2EC2953865A09497F9F43][1 2188128
77A44DAC8436D34983687653F1E8518DDED32992 ]
C:\WINDOWS\SYSTEM32\DRIVERS\DXGKRNL.SYS
[8D74B8B5D6F7C5BC4C525BAF2B083FF1][1 88416
032405D089F656834158D5CCB9E3A20355031012 ]
C:\WINDOWS\SYSTEM32\DRIVERS\EHSTORCLASS.SYS
[2A9817B5A9260D8F60D52E36BEF10443][1 118112
1333167A9CC997A96C574438B6FBF689CB9E643B ]
C:\WINDOWS\SYSTEM32\DRIVERS\EHSTORTCGDRV.SYS
[77B60DEC7DCB4233E4A69D3F52E5DB24][1 13312
B0329FA3642392D44B4C5A095D57D5055E62E555 ]C:\WINDOWS\SYSTEM32\DRIVERS\ERRDEV.SYS
[7EC6FC0266D74BD47ABB130A328B70EC][1 3418976
B59DC9BE6694DF748047E18273AEAE164C5CCDF7 ]C:\WINDOWS\SYSTEM32\DRIVERS\EVBDA.SYS
[86F7951BBCEE4A86E79A97306BD14318][1 117248
]C:\WINDOWS\SYSTEM32\DRIVERS\EW_HWUSBDEV.SYS
[F6C1661C55EAAD2DD9FBB37D5DF1A011][1 90112
]C:\WINDOWS\SYSTEM32\DRIVERS\EW_JUBUSENUM.SYS
[24FA6177FE55C4BC045EC87E39F90688][1 225920
]C:\WINDOWS\SYSTEM32\DRIVERS\EWUSBMDM.SYS
[2FF4826C4BC5AAFC3F579E2063F76BCA][1 451072
33F091C397BFA2E1BB30F638AFE35C1D1EDD6074 ]
C:\WINDOWS\SYSTEM32\DRIVERS\EWUSBWWAN.SYS
[99598ECA5E41996E005D5B9D9FF1EFA2][1 32256
8FE1CD556C2CB76B4161FC7B849BD0E2525EED85 ]C:\WINDOWS\SYSTEM32\DRIVERS\FDC.SYS
[F44F666B0EACC3181544FFCF8CA0FFC7][1 88576
8FADE7A0924B180F8E1F4E8AB53918E8ECA25FBF ]
C:\WINDOWS\SYSTEM32\DRIVERS\FILECRYPT.SYS
[78A210DDFDF2C9EC884631D2DAA573F0][1 85344
D4A4A045AC9110A9070F4B0DAB601FA1114C823A ]
C:\WINDOWS\SYSTEM32\DRIVERS\FILEINFO.SYS
[1A97DB5E701A186989F3795223C3BE39][1 35840
47C5F44D0FE2E2FA69BE10BF653F56808503A019 ]
C:\WINDOWS\SYSTEM32\DRIVERS\FILETRACE.SYS
[46626665F0E5906E45619B4EFD6186B8][1 26112
6501B869922236BB987C4BC3150CEFAF21E2C624 ]
C:\WINDOWS\SYSTEM32\DRIVERS\FLPYDISK.SYS
[FDA72ACA14D516D18C33AFCD0FD9260F][1 377696
F2B5BC04C6FE8FFB16541350F3612362AA93456A ]C:\WINDOWS\SYSTEM32\DRIVERS\FLTMGR.SYS
[B07A40B5A7A58B8C75663A572A46084C][1 62816
5AE9A8F60BB4F4FC6B987C3AE5413CF9B881610C ]
C:\WINDOWS\SYSTEM32\DRIVERS\FSDEPENDS.SYS
[3807CB07B3A446B87004240B1D7BD4F8][1 649568
C725E50373BD2374CC7BC27ABE6856FB7C8D71AC ]C:\WINDOWS\SYSTEM32\DRIVERS\FVEVOL.SYS
[B55FEBC6A00DAA1FE074F020B6907516][1 20480
0EFD2810265196B10A4D3336465AF038D7441CEF ]
C:\WINDOWS\SYSTEM32\DRIVERS\GENERICUSBFN.SYS
[7ACD8F69B5D6EC97E6D2C006E19BED88][1 8192
C59965AA1BD5EE541307323FB516ECBC0A98A150 ]
C:\WINDOWS\SYSTEM32\DRIVERS\GPUENERGYDRV.SYS
[10E3515FE5DBA6656FA62C29342EC4A1][1 83456
C704B58C9AC92CB2F3CDD1A05BAA133827339AA1 ]
C:\WINDOWS\SYSTEM32\DRIVERS\HDAUDBUS.SYS
[B90D284B97CD4CA9DE7430AAAD887A56][1 36704
53710202BDFEF8D82CC35D3E656C5C44E6E1D147 ]
C:\WINDOWS\SYSTEM32\DRIVERS\HIDBATT.SYS
[6B6E527B24F0D76F17E7DBD6D4059B22][1 108544
FF89A65EF09460111EFC68280C1F7413FBF20602 ]C:\WINDOWS\SYSTEM32\DRIVERS\HIDBTH.SYS
[D24355488A2D4D2323518EC1AC7A6D9E][1 51200
ECDEE174E8996A7D29AEE71AB7A31161CE62A4CD ]C:\WINDOWS\SYSTEM32\DRIVERS\HIDI2C.SYS
[0AF9ABBA4F3F55C6C803890D64BC3C29][1 50016
86436F8EE2CE1F354F5A355E52E706E2C7927CDE ]
C:\WINDOWS\SYSTEM32\DRIVERS\HIDINTERRUPT.SYS
[CDBCF8E9AB06D88A1E1191D32F320C5D][1 46592
E50FC98BE8BBD5F32E7EE17B7B66FA8F1B2177E7 ]C:\WINDOWS\SYSTEM32\DRIVERS\HIDIR.SYS
[D8536CB438CC4CCDAE047B768EED22B2][1 38400
00B82E1C84D1BF8AA71FB1C0965EE8513DB1048A ]C:\WINDOWS\SYSTEM32\DRIVERS\HIDUSB.SYS
[F5CA18197B4646E04DB9EB2D6642CC4D][1 64352
00BFDC73947CD278FFACB926CA13D8A1E62AA93D ]C:\WINDOWS\SYSTEM32\DRIVERS\HPSAMD.SYS
[AB91AF050B5FFFE25BEEEDE8AB6ED035][1 1102176
5B40CD4DAE3EF322E04FE653A72D70AD061BEF95 ]C:\WINDOWS\SYSTEM32\DRIVERS\HTTP.SYS
[74FC79C52395B10FFD0B55CF22CF88FC][1 73568
0AD6D0416CB097F25D7CCA3FDF2017341192C9D8 ]
C:\WINDOWS\SYSTEM32\DRIVERS\HVSERVICE.SYS
[771EDDA9830A3079F996F34D681FB6E5][1 29536
EC73286FF09F07C72DEB3EBEFA63AA42061DF891 ]
C:\WINDOWS\SYSTEM32\DRIVERS\HWPOLICY.SYS
[3B9F315E7FA72CC25228EB097DD9C694][1 16384
188630EAC17D987590C8221C9166AC7F98C2294C ]
C:\WINDOWS\SYSTEM32\DRIVERS\HYPERKBD.SYS
[6A0B9F5662598D229F62CD317292E8F3][1 25088
236F0037EA6D1269E2F3D1CA9423BFB3A3E392B9 ]
C:\WINDOWS\SYSTEM32\DRIVERS\HYPERVIDEO.SYS
[B54B30992620C97230013A74461C8517][1 114176
270F6E9FBFC668DD1239F0CF57A805773F87BF65 ]
C:\WINDOWS\SYSTEM32\DRIVERS\I8042PRT.SYS
[C6B8743B213F06AA60943D8366FE968F][1 33280
69EB2EC403271FC42CF858508B7E4C96B9916BAD ]C:\WINDOWS\SYSTEM32\DRIVERS\IAGPIO.SYS
[9A2A2F3C69B9A30B6E78536F6D258BAD][1 81408
C5C81A8D87A58E144408BB89D2AA557391385770 ]C:\WINDOWS\SYSTEM32\DRIVERS\IAI2C.SYS
[5A0E850F8CD17791A3E6A3CF81D0CA28][1 64512
D2D489E29A7229130C5CAEDADD4B24E9D9F84FBF ]
C:\WINDOWS\SYSTEM32\DRIVERS\IALPSS2I_GPIO2.SYS
[7508F1096803385D6376BFD0BD473AC4][1 176384
149D005A993FE3E2E1A1258D3035FF5D3956DCF5 ]
C:\WINDOWS\SYSTEM32\DRIVERS\IALPSS2I_I2C.SYS
[16A10CCEDCF5AC4CAAE43DC9FC40392F][1 38128
F9C70BDC52A485F1577372D828DCC75824A52711 ]
C:\WINDOWS\SYSTEM32\DRIVERS\IALPSSI_GPIO.SYS
[EB82A11613326691508D9ED9A4FE29E7][1 113152
B226F7E4189BF32E6159BBF54C304753E6610633 ]
C:\WINDOWS\SYSTEM32\DRIVERS\IALPSSI_I2C.SYS
[97E553D03219D3D51705C7235D9EAEBD][1 673120
5EF6F253608F9042942DF7A1233F82A59902D411 ]
C:\WINDOWS\SYSTEM32\DRIVERS\IASTORAV.SYS
[8350FE3BCDE3428BC040877BB7E9EAEB][1 412000
AFF524B66A2038B2410D0F1CCD9F88AAFC74C677 ]
C:\WINDOWS\SYSTEM32\DRIVERS\IASTORV.SYS
[3BA03F7C7700DDF4C383DDE9252F5817][1 526176
F528C413E1A6AC445B42DDF9F5FAE854BA4F3F17 ]C:\WINDOWS\SYSTEM32\DRIVERS\IBBUS.SYS
[025868A34E359A5F49D2324C0B14D537][1 223432
]C:\WINDOWS\SYSTEM32\DRIVERS\IDMWFP.SYS
[7BA5F6FEAA79BB7C7A635E6B3982A0D3][1 7969760
31252D4FD7161D04FFDFCC8CF153634FF0E6305A ]
C:\WINDOWS\SYSTEM32\DRIVERS\IGDKMD64.SYS
[2A01C96DF5802D3434634E55C91232D8][1 35840
55254BC59EDC4C03DC49819BEC49D8AADF8F51DC ]
C:\WINDOWS\SYSTEM32\DRIVERS\INDIRECTKMD.SYS
[E300D1E37B737ED14F7A08CD5604E5D9][1 481768
A7D9098F8153AB20951A9CEC6C0B51D8E422B6EF ]
C:\WINDOWS\SYSTEM32\DRIVERS\INTCDAUD.SYS
[9F7E87F6595D065A8A200A291043045E][1 19296
8192F7668247917451567B1D19884F3BDDDE7347 ]
C:\WINDOWS\SYSTEM32\DRIVERS\INTELIDE.SYS
[A6BD2E20AE1BC5CB2776C87C28E4F4CA][1 48152
863C00642BF0ADC1386199BCC8F6227C165640CA ]
C:\WINDOWS\SYSTEM32\DRIVERS\INTELPEP.SYS
[2A48DA39542636DB0FA3BA915385D1B3][1 134144
6F8337DB6E0734A114059516EC75796720A99E63 ]
C:\WINDOWS\SYSTEM32\DRIVERS\INTELPPM.SYS
[DB32758F3A7F6CCE81A5430080A2EA65][1 48992
C8DD998DCCFF8C68B8FAC6583116A367CDFFB3AA ]C:\WINDOWS\SYSTEM32\DRIVERS\IORATE.SYS
[FE85D0A86CA7A5A99CF8CD04DE7F80AE][1 85504
71E9B348A8A33CE9EC24752E04FF66E96D6D0B00 ]
C:\WINDOWS\SYSTEM32\DRIVERS\IPFLTDRV.SYS
[10D01A3657AC8E8004C83D613163DE1E][1 90976
D7B3190C87B6111C40DCA9DB95E28DD756A80FB5 ]
C:\WINDOWS\SYSTEM32\DRIVERS\IPMIDRV.SYS
[F1DAECC3B3D6399875D4F10529D6A77C][1 212480
B308670E2966C738242E45703DEFBE7CAB958D18 ]C:\WINDOWS\SYSTEM32\DRIVERS\IPNAT.SYS
[7475A2903BB704B446AA6309E34D3362][1 120320
6E69A8FEE82BB353940C1AAC2055B1E1E064CB79 ]C:\WINDOWS\SYSTEM32\DRIVERS\IRDA.SYS
[9725E7F0C64CE9916A5CDABE8D6E13C3][1 19456
858C8320FEB251D462A773AF508EFAEF4E8ED4AE ]C:\WINDOWS\SYSTEM32\DRIVERS\IRENUM.SYS
[58040898883A96160D41739C80328BBF][1 22880
BCE887AEF0D3E67D4DEDB6B887DBBC7C6326F3F0 ]C:\WINDOWS\SYSTEM32\DRIVERS\ISAPNP.SYS
[210808437570BDDEE71A43535E3A2D30][1 62304
2258AC516577A5A46A30F8FC949115C34B33DA40 ]
C:\WINDOWS\SYSTEM32\DRIVERS\KBDCLASS.SYS
[0B779E9FC426CA2268D28181FA6C222F][1 39424
70B03AE40BC4D441D9B29C9B04E5A89637730940 ]C:\WINDOWS\SYSTEM32\DRIVERS\KBDHID.SYS
[813BA3EB2CE038F2A5382DDD75CAD60B][1 25088
5B5ED10B0AE7F5BE29FEC114A0438304F983C101 ]C:\WINDOWS\SYSTEM32\DRIVERS\KDNIC.SYS
[251F05F5F617C88DF7491441671720DA][1 133984
D8B6158258BAB344A2355A71035ACC8C262522DA ]C:\WINDOWS\SYSTEM32\DRIVERS\KSECDD.SYS
[B88617822DA473114DE754A2A312A8C5][1 168800
9E6011FC72E42756ADA333BC29845BFC79138F53 ]
C:\WINDOWS\SYSTEM32\DRIVERS\KSECPKG.SYS
[4ED115CD1A1099705F56B5E0FFF97CC6][1 26112
5DA2F0BDA966CB8573764DD805F6EFEB371AE93E ]
C:\WINDOWS\SYSTEM32\DRIVERS\KSTHUNK.SYS
[5933A6673F00D8255C52957E40C2D601][1 66048
D7FA676CA036F153E95F26A019C2FDF58BE94B85 ]C:\WINDOWS\SYSTEM32\DRIVERS\LLTDIO.SYS
[8E1B0946948CCC0BC1FA3CB70374A795][1 108896
6F252BCC6706CFB30E237C67025634614CCBA3C9 ]
C:\WINDOWS\SYSTEM32\DRIVERS\LSI_SAS.SYS
[4F68163FC04C973500DC4DA0946917B0][1 105824
451B4F0234DD012D87872EC9309649E4CB4CA861 ]
C:\WINDOWS\SYSTEM32\DRIVERS\LSI_SAS2I.SYS
[E5AC5F2815938651CDCC27F425474673][1 101216
668D6CE91B7A68E1A803326B506E9F4C791D94E5 ]
C:\WINDOWS\SYSTEM32\DRIVERS\LSI_SAS3I.SYS
[CCF6EC9FB9B8F18E05B4253E81013E48][1 82776
AD6D88B78EED5DC0A3BB0BEE30FBF90C3388AD72 ]
C:\WINDOWS\SYSTEM32\DRIVERS\LSI_SSS.SYS
[C9579D32219E5B936AC3A48D470117EC][1 125952
E415E877B24AE256FF9328B7DBA527142DE62E33 ]C:\WINDOWS\SYSTEM32\DRIVERS\LUAFV.SYS
[ -2][0 -1
]C:\WINDOWS\SYSTEM32\DRIVERS\MASSFILTER.SYS
[C3CDCCF07486BD2616A7B82946E07AC0][1 59744
970548C552748641E375D68054C900BB5C841762 ]
C:\WINDOWS\SYSTEM32\DRIVERS\MEGASAS.SYS
[2CF0CB2A0ED68C5455371E84C16F9627][1 64352
224341D247BBFECD2FD9B86377EBEECD2217E578 ]
C:\WINDOWS\SYSTEM32\DRIVERS\MEGASAS2I.SYS
[FADB2FE017E69EECE0E1BA78661C2E8C][1 575840
7C39A048BF6B333D800D51F4AE45650653FCD434 ]C:\WINDOWS\SYSTEM32\DRIVERS\MEGASR.SYS
[FD60818B66B2E8A5415EA840E99A9D8F][1 842584
56CB9E33989A44F0D4B2F47F7F1CA9385F281C80 ]
C:\WINDOWS\SYSTEM32\DRIVERS\MLX4_BUS.SYS
[68F6977F1CFBAAC770D940A8C0326FA1][1 48128
E1C49A1F92B226602BF64AFEA29D3BBA37D506B4 ]C:\WINDOWS\SYSTEM32\DRIVERS\MMCSS.SYS
[0D50B3F3AB32D416786B58D4553859CE][1 42496
01F9B74AB041AEB173F4F8B4590E875830CBDF63 ]C:\WINDOWS\SYSTEM32\DRIVERS\MODEM.SYS
[9CCCB7FC3EDADEBA461D78615A6011A6][1 38400
7C1D36522FA2A8FDAFC73FA980F63D646DF4159E ]
C:\WINDOWS\SYSTEM32\DRIVERS\MONITOR.SYS
[27A07B2FB2E3057DA8DAEA4F25D843C7][1 59232
3CFF953104A52A46A0F06C1B9D67AAAA6744FED8 ]
C:\WINDOWS\SYSTEM32\DRIVERS\MOUCLASS.SYS
[7BD6E7F7C9001AB21B8362CFFEE80B25][1 32256
D2641222FF0D29C86E689BEA61854EBD889CB77D ]C:\WINDOWS\SYSTEM32\DRIVERS\MOUHID.SYS
[F5BDAEE4B7D369D4C74668DCFBA3FF10][1 104800
01CFF4298017F0D51C385C593CF426943EF7B78C ]
C:\WINDOWS\SYSTEM32\DRIVERS\MOUNTMGR.SYS
[30844BD376F9D01E62C820BEF446F1F8][1 75776
05F38EE7898ABCDC0D6307BFCE4D1E50E0C90131 ]C:\WINDOWS\SYSTEM32\DRIVERS\MPSDRV.SYS
[25D32BE04FE0A23FDF57FD5382757672][1 143872
851312B536C3E0383A5FA76033033145D919C779 ]C:\WINDOWS\SYSTEM32\DRIVERS\MRXDAV.SYS
[F4A3EFC57F7A5406565E6519B25A4C31][1 450400
DC0DA78B92DF14D8F4F60B0022A87D7261FBB809 ]C:\WINDOWS\SYSTEM32\DRIVERS\MRXSMB.SYS
[E0AC54C9EEF2C8B14363B256CB0B281C][1 283136
5BD7CE422533C42B5EB0F46701D500A58FA4C261 ]
C:\WINDOWS\SYSTEM32\DRIVERS\MRXSMB10.SYS
[87B9D4998D9CA0DBB6CA01BB2C28857D][1 223072
0B3C165DFF89BA07003FE2C707FF2AA3ABC988E3 ]
C:\WINDOWS\SYSTEM32\DRIVERS\MRXSMB20.SYS
[DDD8A8CDDC7F13EF57D1DAAE71865936][1 168800
5B0E9F0137B3BAA08AED803C06F133D207C5ACC4 ]
C:\WINDOWS\SYSTEM32\DRIVERS\MSGPIOCLX.SYS
[22ECD8F5D1DFADF2011BBB1700CB871D][1 50528
4F6B172B8BF99E06CB8772752C4224CB65D241E3 ]
C:\WINDOWS\SYSTEM32\DRIVERS\MSGPIOWIN32.SYS
[FD870F6968A145E4D2BA8A8842686B03][1 8704
25803F01F3E5675F0B9CC0B8636E7097635B8420 ]
C:\WINDOWS\SYSTEM32\DRIVERS\MSHIDKMDF.SYS
[30364757963A028CE5DF0FBAAC270173][1 11776
B18A0DE1C69CA675DC23AE4E4D28EF63B1D29C05 ]
C:\WINDOWS\SYSTEM32\DRIVERS\MSHIDUMDF.SYS
[6BB0FEDDAE7135FA37FFAFF4D9E0E876][1 18784
F96C0F40FE87A5A6D813F25ED8BD40E14D575FDD ]
C:\WINDOWS\SYSTEM32\DRIVERS\MSISADRV.SYS
[3C97BBD57E92F76A079338DE6F8317C6][1 277856
54D4F4EF7EDFCD61258948C5B1F67637130B69F8 ]
C:\WINDOWS\SYSTEM32\DRIVERS\MSISCSI.SYS
[4586CDA25B7866DD9505CEECF9DB3C74][1 27136
70A6AD8C705EF80ECB5D9E5BD682904C04E9730F ]
C:\WINDOWS\SYSTEM32\DRIVERS\MSKSSRV.SYS
[642CDE46351D5D2D90311E77072AB46D][1 78336
CA22F609646FB73F32FDEBD0D697D6B2E2D435C9 ]C:\WINDOWS\SYSTEM32\DRIVERS\MSLLDP.SYS
[F2302A5CE63CA7673200FAFCEEEDB6AF][1 10752
A1123FFC441265E33435ACBDF454BA96EA035CD7 ]
C:\WINDOWS\SYSTEM32\DRIVERS\MSPCLOCK.SYS
[6114512EA26E835BA522C63635429DB5][1 10752
A95B2E630BAE5FA95331285B451810D7059F00CF ]C:\WINDOWS\SYSTEM32\DRIVERS\MSPQM.SYS
[7ACFE7435317E791FF9EED2F49B402F2][1 179040
9453F86C703EFBA59C296BB4E90EBD25545B5432 ]
C:\WINDOWS\SYSTEM32\DRIVERS\MSSECFLT.SYS
[0543BEFD41EC4D25C7F7CF36409CEC7D][1 43360
C0D3A3CC48FCD5111925C42ABFA968E746E636A3 ]
C:\WINDOWS\SYSTEM32\DRIVERS\MSSMBIOS.SYS
[C1569E4DB8EFE3617847BF041A3C842F][1 12800
A3C7C734658D407AF6659E67BA67959604E195B7 ]C:\WINDOWS\SYSTEM32\DRIVERS\MSTEE.SYS
[130B16970154BA9876B09E5C4BAC63BE][1 15872
C0668772C2B16F9D7D13FF0544990AB3A489F3F3 ]
C:\WINDOWS\SYSTEM32\DRIVERS\MTCONFIG.SYS
[A2A906C0D38BFE1D780251D044BDBD4D][1 126304
7E4B002F6189D829F2409A26A1844D677303DC62 ]C:\WINDOWS\SYSTEM32\DRIVERS\MUP.SYS
[3D2C5B4995CA0751D32DEA0DE9FDFE44][1 63840
D84B3CCA455EA46EC10CBAA8F8DCEAB2C651F4BC ]C:\WINDOWS\SYSTEM32\DRIVERS\MVUMIS.SYS
[629CB21AC49C8867E0F29DF1C16DB7B4][1 108896
3E56B16E1ECB28B8D4623E402A7A4A6CEA0CE312 ]C:\WINDOWS\SYSTEM32\DRIVERS\NDFLTR.SYS
[42A3B76320D483D443A60661FE1FEF14][1 1181024
90484DD450ABC7149D4A43A365CAED9B3BA7F34C ]C:\WINDOWS\SYSTEM32\DRIVERS\NDIS.SYS
[6DD605338FAAF6BA17662AA874E0D162][1 50176
3F145BA879AB27E0CFD72027610922724B16D610 ]
C:\WINDOWS\SYSTEM32\DRIVERS\NDISCAP.SYS
[E34196F285F8B8879E1FF36C31F7179E][1 126464
AAB27C60EBAC26539DFB28BAE6912DB61B1EBB63 ]
C:\WINDOWS\SYSTEM32\DRIVERS\NDISIMPLATFORM.SYS
[1FAD2398673F30CEC616B89C46B7DCBA][1 26112
B6D7343F3D34ECE42FA9969E608735497179D436 ]
C:\WINDOWS\SYSTEM32\DRIVERS\NDISTAPI.SYS
[AEB8ECBE66CC46854066CB1F5623E179][1 63488
3580745A0B43773BAAC096948FED8558A1C14877 ]
C:\WINDOWS\SYSTEM32\DRIVERS\NDISUIO.SYS
[7340104C2BF2F126714F7CDE85E63610][1 20480
154B76642C6E2F3225AA95A598D54FD91F10B8DE ]
C:\WINDOWS\SYSTEM32\DRIVERS\NDISVIRTUALBUS.SYS
[07ADC1F8DCBEB8104D75129B11584B8C][1 189440
D4F9AF2E8305DAC6C96601A8B74EE63AFC47ECE1 ]
C:\WINDOWS\SYSTEM32\DRIVERS\NDISWAN.SYS
[78A12E3DF035B5D054986949B19BE43C][1 60928
84FEF77B3813181A38BF610192AE7C818E70FC79 ]
C:\WINDOWS\SYSTEM32\DRIVERS\NDPROXY.SYS
[04C8859355C1DC9C0FA198D1894D71C2][1 125440
C783FA412E247C311ABDDB9E014B71C0DF89757E ]C:\WINDOWS\SYSTEM32\DRIVERS\NDU.SYS
[6C76780A01FC2B885BD6E957B5C36B02][1 90624
F3CF299C901648218F2C38FBB723B50F8B96DA63 ]
C:\WINDOWS\SYSTEM32\DRIVERS\NETADAPTERCX.SYS
[5D1513BD6430307C9DB86C6E351372ED][1 57184
CC486AA97891945F0F19EFFE6B52F4D441C917A1 ]
C:\WINDOWS\SYSTEM32\DRIVERS\NETBIOS.SYS
[C2B9D1E69B332210E87C22CD94665BA3][1 279040
70CFD0608692EC43C676D239EBB1C200FC161CFB ]C:\WINDOWS\SYSTEM32\DRIVERS\NETBT.SYS
[1DDA483F4BD657C36B26B3791118E9B7][1 114176
E69513E92845D51F0EE76E881ED2751956721993 ]C:\WINDOWS\SYSTEM32\DRIVERS\NETVSC.SYS
[90F5DC9802AAA00CD0B6E2AD9E7FFADC][1 26624
F5374D88690C0F04511F8E2B1BF46A4EFDD202AB ]
C:\WINDOWS\SYSTEM32\DRIVERS\NPSVCTRIG.SYS
[7C6C3B9E771A7BE2924FEF1A42942841][1 77824
E92AB3A59A4B46BD2F45411C73F7E2558E05E126 ]
C:\WINDOWS\SYSTEM32\DRIVERS\NSIPROXY.SYS
[C9A2046A3B749CFD7E485B6FB1FB3A6C][1 11228608
4BD871C7C0D47C3900F6979131EDE3B373E0BEA7 ]
C:\WINDOWS\SYSTEM32\DRIVERS\NVLDDMKM.SYS
[D261DF41F0840F734856A2B4F5E072C7][1 150368
293C3DD8C36E5AD28CE260CB17D33F35F77A2285 ]C:\WINDOWS\SYSTEM32\DRIVERS\NVRAID.SYS
[23B702B555EB0436B9DAA0BC63DA65CE][1 166240
F91632F934CB243175E58BA9D03AC7D79165714F ]C:\WINDOWS\SYSTEM32\DRIVERS\NVSTOR.SYS
[10200887FD2B3BDCEAA9453B939BB643][1 536064
25B36D35814958B07D763CFAF72430AA92D17FCA ]C:\WINDOWS\SYSTEM32\DRIVERS\NWIFI.SYS
[B621114B8D1E9256DC1BFD6BA2F4DE69][1 160608
A855C780F1FD98ED197E8A3586736BC9426682C3 ]C:\WINDOWS\SYSTEM32\DRIVERS\PACER.SYS
[6B81BF7853D161DB8AC62CD8B9C2DE6B][1 96768
55685D18E3FAD6447C82E905DD61E576D060F88B ]
C:\WINDOWS\SYSTEM32\DRIVERS\PARPORT.SYS
[032F1C32A6A97C317AEFF9D64D2A1D8A][1 40304
50D027EB8240A4C0D4610E47A912DC8E4D6D88E5 ]
C:\WINDOWS\SYSTEM32\DRIVERS\PARTIZAN.SYS
[0553ECB742278C8F4CFA28B43FF20EAD][1 128352
AD3AD7D2A4E7D4845750AEBCF2DE572BE81C5441 ]
C:\WINDOWS\SYSTEM32\DRIVERS\PARTMGR.SYS
[29AF16726F4DD84376ECA85AB6AFF2C6][1 335712
58B0CDE053EF34977E2BE4D3D3626C775A8C2A4C ]C:\WINDOWS\SYSTEM32\DRIVERS\PCI.SYS
[214DCC87E3898F738075D1341252A552][1 16224
4267E9ECA82C8D96F5BF8DF51C98F8351F4D374C ]C:\WINDOWS\SYSTEM32\DRIVERS\PCIIDE.SYS
[AED76A3333B3A31536E430020E0226FC][1 118112
BB7093EFF567FFDC9742874301857AA49094D07B ]C:\WINDOWS\SYSTEM32\DRIVERS\PCMCIA.SYS
[E63FB38B6E75B39467492FBAD2CD512A][1 51552
B1D626B95326207577C411F8BC2803D8F372F682 ]C:\WINDOWS\SYSTEM32\DRIVERS\PCW.SYS
[382D493B91B816D12C6F775E7896ED29][1 108896
C1A329056F22B8A7327581FC53AC05A4E4F8DCF6 ]C:\WINDOWS\SYSTEM32\DRIVERS\PDC.SYS
[1509A77F840AA9E72CF8247D0CF2FBDE][1 723968
34D094347AFBE2CB496D15DC9F6C285960DD0E10 ]C:\WINDOWS\SYSTEM32\DRIVERS\PEAUTH.SYS
[540116170E2135FCD5DDE77702166B67][1 58720
B99A46EB5BE84FCC7F2D192CD23CB819BB7BC65A ]
C:\WINDOWS\SYSTEM32\DRIVERS\PERCSAS2I.SYS
[8356F87553BF49C703CF382033815898][1 61792
510505DD08A1AF53E918774766F0D8CEA2EEA127 ]
C:\WINDOWS\SYSTEM32\DRIVERS\PERCSAS3I.SYS
[372913E12677A8CBBBABDD8311894F9D][1 119808
8765C402A971F5714A80C0E1F733BE754BC8EB90 ]
C:\WINDOWS\SYSTEM32\DRIVERS\PROCESSR.SYS
[819602BBBFDB0BD46DEA3715BF0DD452][1 48640
86744A610A672794E4D86D6752ECA23300505C40 ]
C:\WINDOWS\SYSTEM32\DRIVERS\QWAVEDRV.SYS
[CDF47037A0939F56D11F699629C276AD][1 17408
D45E8258CA8E7C11D1F051FB9321D61EA6BE1A2C ]C:\WINDOWS\SYSTEM32\DRIVERS\RASACD.SYS
[17E565710172ED71B8531D8822E1C5D1][1 104960
67F03CAFCE60AC0F11DCE1E56E7974FC38848944 ]
C:\WINDOWS\SYSTEM32\DRIVERS\RASL2TP.SYS
[726857E441D1D67F57694A1B613ABD34][1 81408
26F9BF8030D3FFB597D7131D4A00FD4C17D92E52 ]
C:\WINDOWS\SYSTEM32\DRIVERS\RASPPPOE.SYS
[5645B9D9788CCA2C88B9534996ED2D6D][1 96256
3F620956AF8D74977F1F71C3F21F8EA75EB3C4B5 ]
C:\WINDOWS\SYSTEM32\DRIVERS\RASPPTP.SYS
[F0F4EEDEEBEE7A4244FAFB96A16B5712][1 77824
7D0CF62E47E6D0FF5A5BAAFBF5DB4E82C9E97865 ]
C:\WINDOWS\SYSTEM32\DRIVERS\RASSSTP.SYS
[3B80AAAEC3A3DD308DBE7B0775013E10][1 431456
8F651616DCD880691A33B58A4A3A010F91C78CD3 ]C:\WINDOWS\SYSTEM32\DRIVERS\RDBSS.SYS
[79A415E6FA915EFC00297DAB16EC2635][1 26112
29A8A099EDBA697DD7F1489FF16D9374059E6B4B ]C:\WINDOWS\SYSTEM32\DRIVERS\RDPBUS.SYS
[7135785C21CA79D270D11037C43D3F19][1 177152
886EE6D704469FD429B1942FFD1DE98C2B6297AA ]C:\WINDOWS\SYSTEM32\DRIVERS\RDPDR.SYS
[97A61A3CB2B5CB4FC32B3224EF333448][1 29536
2EEC2F84B6EBAD2F52D384C13137C9E18D0D4BCE ]
C:\WINDOWS\SYSTEM32\DRIVERS\RDPVIDEOMINIPORT.SYS
[69BB204AE07EE84ECFAB1BF13C4BD04B][1 267104
A0D2791105B79CE3C85E9B07D95D4118FA799D98 ]
C:\WINDOWS\SYSTEM32\DRIVERS\RDYBOOST.SYS
[EEC3A4A98AE1A337E3CD1483AD6F2E15][1 70144
326B8468B1466ACF76011966AC4C949C3273B5A3 ]
C:\WINDOWS\SYSTEM32\DRIVERS\REGISTRY.SYS
[E82F3B1918C6A5FE6EB761CDF1E772AF][1 183808
6946D1F002E269711187FEF444A0E6199010F97E ]C:\WINDOWS\SYSTEM32\DRIVERS\RFCOMM.SYS
[5FF28F097C9699097B473F8FC7C1AA7D][1 81408
A965A2877659EF8A203C9A215C79EF5C34E2D83A ]C:\WINDOWS\SYSTEM32\DRIVERS\RSPNDR.SYS
[DFE1602D6A08A0C27C48DD8C4EFB11CA][1 895256
4A6769200FB05FF76DFEC87A79BD51D8A4F1CEEB ]
C:\WINDOWS\SYSTEM32\DRIVERS\RT640X64.SYS
[C6431D29271C5952CBC4FCEE97BDE256][1 600832
90F0E20BBB8496A18A2F21CEBE1E6FD967A3A885 ]
C:\WINDOWS\SYSTEM32\DRIVERS\RTKBTFILTER.SYS
[FEAB5D20ECE485D6C0BD9FC9846F32B8][1 752856
D17C1171A8A671C1226FD940D978733DB63BF51B ]C:\WINDOWS\SYSTEM32\DRIVERS\RTSPER.SYS
[5E73FB63E2DBC75FE0C17DEB0010CE0E][1 110432
C3F62D8DA0A5B25801E073402BBD336F44F57B14 ]
C:\WINDOWS\SYSTEM32\DRIVERS\SBP2PORT.SYS
[3D9A82B03C92D1FEC42CB171D6F57778][1 43008
3BD1CC2F8D12C0C618AF2AC3417CC5055CC429EC ]
C:\WINDOWS\SYSTEM32\DRIVERS\SCFILTER.SYS
[227A7AAD04CB11116F8B935CA31F0D04][1 88416
E3B87AFC33FACD182B4741661CCB79A3E4F487E3 ]C:\WINDOWS\SYSTEM32\DRIVERS\SCMBUS.SYS
[50FCAD2051E6DD313393437DE6D7C049][1 124928
14FB58A44356CA073F88A34FA9E2D874D5F0237C ]
C:\WINDOWS\SYSTEM32\DRIVERS\SCMDISK0101.SYS
[08ED027CD8A43E3412BDD134A43B13E8][1 279904
58D453E1AE93B69DD8987D69B7B06FB5D582D5B8 ]C:\WINDOWS\SYSTEM32\DRIVERS\SDBUS.SYS
[4DFEC463DD018EC4EC47F9E94128EFDC][1 95584
EFA8835FA7E673C7EDC8991959F9180744B31206 ]C:\WINDOWS\SYSTEM32\DRIVERS\SDSTOR.SYS
[401D706DDC0A7AF18C3DD228ADF74551][1 74592
F5224AD3A7A7249C6F15AF879424CFC4B3399BE9 ]C:\WINDOWS\SYSTEM32\DRIVERS\SERCX.SYS
[7084D11083F0CDCA8B5C76F9846ABF5D][1 151904
2201921638398E868B22F9A1597C2CAB48B94D02 ]C:\WINDOWS\SYSTEM32\DRIVERS\SERCX2.SYS
[3FF478A8ED32A83C36581425F6282B6C][1 25088
5EBDAD05ABDDA28214EE0703891D63F6AB4EB027 ]
C:\WINDOWS\SYSTEM32\DRIVERS\SERENUM.SYS
[92509187AA171A80521528B36F753E1D][1 83968
A788DCEF811F0FFD01CB8ACB568EC055ECCC5CDE ]C:\WINDOWS\SYSTEM32\DRIVERS\SERIAL.SYS
[433D38FF6D08B993847EA2A10EB8CB52][1 27648
E41E4CDE68ED827C1243E7A8ACEDA8A0867FD155 ]
C:\WINDOWS\SYSTEM32\DRIVERS\SERMOUSE.SYS
[697D3EE0740AEAB62B66ABCA1C83D13B][1 18432
2BEF5AAC286F73A982AA10B0BD3B99931099ECD3 ]
C:\WINDOWS\SYSTEM32\DRIVERS\SFLOPPY.SYS
[A34CE1830E45DA98932295FDE4B7908A][1 44896
0EC41E4ACFC4115065FA095BA56876B0B6A312A1 ]
C:\WINDOWS\SYSTEM32\DRIVERS\SISRAID2.SYS
[A7B5C670770E908DA5FEF5BF1136E933][1 81760
66EA98326B923026A1A3891891565F9A32FFCC5B ]
C:\WINDOWS\SYSTEM32\DRIVERS\SISRAID4.SYS
[D88FC13079D14E5403AED5F7D33A2015][1 33960
D1252933BA7C0AE321B44CE05153B8C93FF1DE16 ]
C:\WINDOWS\SYSTEM32\DRIVERS\SMB_DRIVER_INTEL.SYS
[1A5F733CD6705C805BA09244B3E0E442][1 557408
E88910D234B7A831BB19875FFCF4494BEBD0D255 ]
C:\WINDOWS\SYSTEM32\DRIVERS\SPACEPORT.SYS
[E03264C4C25B568F92ED1656AD541E64][1 79200
41CC072A23C713F33D860915EDF27014F432D39E ]C:\WINDOWS\SYSTEM32\DRIVERS\SPBCX.SYS
[7765EF139A8744ABE297EFA6A7390677][1 409600
FEF4D2BEF7DB5D965609D301CA77F564AEFB66D8 ]C:\WINDOWS\SYSTEM32\DRIVERS\SRV.SYS
[8B4A7F1BC1CF7FC83A305F4B0F979155][1 713216
96815B0A732C353660C0DC711801FC6CAD0E9804 ]C:\WINDOWS\SYSTEM32\DRIVERS\SRV2.SYS
[EF2D84A9E1ED7CA32FC15E33FD235B65][1 248320
52797F213CF47CDDDF50DB122BB6650B83F9B63E ]C:\WINDOWS\SYSTEM32\DRIVERS\SRVNET.SYS
[5F78930AAB3900102EA8ACDD38F97324][1 131984
6A57981E6DC01E9808D9B9DA1ECE0AFC2D74285C ]
C:\WINDOWS\SYSTEM32\DRIVERS\SSUDBUS.SYS
[F0B59ADCD06BCEB9D47311B7041CA2C9][1 166288
32F4CB414643CA955A0AE3063536D41EEE39B296 ]
C:\WINDOWS\SYSTEM32\DRIVERS\SSUDMDM.SYS
[76F7D7217FBDAB77798A2A244ACD641F][1 206080
]C:\WINDOWS\SYSTEM32\DRIVERS\SSUDSERD.SYS
[29D26E1347AE1BBD4201014E19880B2C][1 31072
2239F87D273975F928D0C31735AA094D8555E733 ]
C:\WINDOWS\SYSTEM32\DRIVERS\STEXSTOR.SYS
[6BC6023E866489D22CE30E18846B80D9][1 130912
EEC3EF282CB3D8A0335598D937EC5F02356F4C3C ]
C:\WINDOWS\SYSTEM32\DRIVERS\STORAHCI.SYS
[9886ECF5D6142DD2EE30D2C23F411E60][1 81760
8E96995A5347C54D993F11128801214A688DB179 ]
C:\WINDOWS\SYSTEM32\DRIVERS\STORNVME.SYS
[BEBF85EB4D90E6996047DA027D0ED26E][1 78336
B6801C13F4030338619E87A303C1B3258E07A310 ]
C:\WINDOWS\SYSTEM32\DRIVERS\STORQOSFLT.SYS
[8E73037A6F8938475692FFCC26EBF385][1 32096
346FFE7A98BE589C516211A9F09DE4FD57D66743 ]
C:\WINDOWS\SYSTEM32\DRIVERS\STORUFS.SYS
[9D9DED47DA10E845EFF2DD57C94C809B][1 36192
280B431CB071D602C20DB321818FF2956A700480 ]
C:\WINDOWS\SYSTEM32\DRIVERS\STORVSC.SYS
[505E0C40B5D0ADDCBB414640F59BD2E0][1 17760
C5DC3CC751CCE7B0FACCC3181C969D454A1FA3CA ]C:\WINDOWS\SYSTEM32\DRIVERS\SWENUM.SYS
[32F46FB0F290D16DAA452B289C985795][1 64000
6B2BB86280EEDCA8D4D4D29B3E9AC818914883C5 ]
C:\WINDOWS\SYSTEM32\DRIVERS\SYNTH3DVSC.SYS
[3C32FF010F869BC184DF71290477384E][1 40664
]C:\WINDOWS\SYSTEM32\DRIVERS\TAP0901.SYS
[03B9DF5A59B5A201D9B7409EF1C50F6B][1 2532704
EC63242652C7B5C89A6400D164221F02C6804B2B ]C:\WINDOWS\SYSTEM32\DRIVERS\TCPIP.SYS
[14A6ED9AD702CE1F1CE34756EB41834F][1 52224
730341DF1EC416CBBAE233D2CE61A9E118FD58E8 ]
C:\WINDOWS\SYSTEM32\DRIVERS\TCPIPREG.SYS
[3CE84BB06DB5FD6ABF2DE88294E56EDE][1 118112
CFAA379190954A8958534DA4D21FD115A443E2E7 ]C:\WINDOWS\SYSTEM32\DRIVERS\TDX.SYS
[296C443FCC228EA643ED310465772820][1 184608
14F34C2F4C8B5F33A97EA1FA1FE411DBBEFA0496 ]
C:\WINDOWS\SYSTEM32\DRIVERS\TEEDRIVERW8X64.SYS
[06130AFFECEB94525FC2352936576B70][1 38752
763500549E528DE8A8A6CD29EF3F3A41E3CEE9A7 ]
C:\WINDOWS\SYSTEM32\DRIVERS\TERMINPT.SYS
[46171262D0E806779DEEDFCAB2F830CC][1 219488
627F36EE6F794837DDCA441123F5BAE2A7A628B9 ]C:\WINDOWS\SYSTEM32\DRIVERS\TPM.SYS
[A6F4025664C9D4BC2A9EDAB4092706D7][1 61440
C4D3D043CEB4201721DD298A203E45791B7AAE57 ]
C:\WINDOWS\SYSTEM32\DRIVERS\TSUSBFLT.SYS
[37A96AD493E110C0BF1EE0AC0F9E7DBD][1 34304
4926BE38FA4D2A44725A4416855F2B2046CE2EA2 ]
C:\WINDOWS\SYSTEM32\DRIVERS\TSUSBGD.SYS
[E9503E60345EEDFB9C11E74063E03E2E][1 124928
89E0CD467E329495483C8847425D7C0529BEB536 ]
C:\WINDOWS\SYSTEM32\DRIVERS\TSUSBHUB.SYS
[79E264287F17D56D768440B0270466DE][1 158208
022D77C53B516B7963AAC0C3BBE4CA7B041F3C29 ]C:\WINDOWS\SYSTEM32\DRIVERS\TUNNEL.SYS
[AA65954F512BA097DD190790876DD991][1 77152
5B8A9F83872437A81ADB1C14B0B7B5EB215C1B89 ]
C:\WINDOWS\SYSTEM32\DRIVERS\UASPSTOR.SYS
[AB6268022C3A5B529075A39C33904DA6][1 95744
B29B595E734C1F61D0E3ED34C0CBE18ED4514634 ]C:\WINDOWS\SYSTEM32\DRIVERS\UCMCX.SYS
[7ED2EDA43D21C7A5F589A7960E265C52][1 108544
DBD737AE64B93ED51CA272A247BF4F8B4A2673E2 ]
C:\WINDOWS\SYSTEM32\DRIVERS\UCMTCPCICX.SYS
[169351463039B45F5CDED9768879F712][1 50688
C6D4B605C386BC1A52D19F05F091D0CDEE3BFF04 ]
C:\WINDOWS\SYSTEM32\DRIVERS\UCMUCSI.SYS
[08A9E3AD29B215484FBB68CDC175DF3A][1 210272
1C6D8F0F292C3B9B798B3F931919A4421F95574B ]
C:\WINDOWS\SYSTEM32\DRIVERS\UCX01000.SYS
[DA70AEE267491AA56BC63AA0C0C96CA2][1 45568
061A172B3CB4B53948A6639F5176104AB9B06BB3 ]C:\WINDOWS\SYSTEM32\DRIVERS\UDECX.SYS
[FBC5ECF6D5A868D0B116C2DBB02B8168][1 320000
FAF78ED0896E59734C96EDE5617E58EF96047566 ]C:\WINDOWS\SYSTEM32\DRIVERS\UDFS.SYS
[B918E40FAA9CD118CCA4AD388B748C98][1 28512
C08DC216EB5B7F184619BE49667CD3EBA3C230F2 ]C:\WINDOWS\SYSTEM32\DRIVERS\UEFI.SYS
[166B17AE1DD24D8BA8CA474C7C31148F][1 40288
F86E62A88D981BE5D0F412C97689E8C62F784694 ]
C:\WINDOWS\SYSTEM32\DRIVERS\UEVAGENTDRIVER.SYS
[0FD75222C1AD2687AB365BEBEA400DD4][1 263008
5BDCAAA2A1C9679430E433A405F98995C93535A7 ]
C:\WINDOWS\SYSTEM32\DRIVERS\UFX01000.SYS
[C1A78C53E01C641AE41BFA65797819F5][1 96608
93556471490DB1A3046C38315AF86A7C0AD539C8 ]
C:\WINDOWS\SYSTEM32\DRIVERS\UFXCHIPIDEA.SYS
[767307212110EBEFB93EC9A5BE9E85B9][1 137056
F005D1A6E9D203277CCA9BFC1762675B54E07D17 ]
C:\WINDOWS\SYSTEM32\DRIVERS\UFXSYNOPSYS.SYS
[DC460AAA18CA2342FBBFB2DF9B044472][1 56832
1BA486130BC87AA26B5AD929860DC5D14FDE5978 ]C:\WINDOWS\SYSTEM32\DRIVERS\UMBUS.SYS
[C3CF0377917ECE6D65D7623E1E61568F][1 13824
25958FB450563786CE86931A9624A1E55726CE25 ]C:\WINDOWS\SYSTEM32\DRIVERS\UMPASS.SYS
[049CF5376EF87B39DC5CF3D776605422][1 14984
7F9EE88E686B62B596A50108AD1AAE6464C2D34D ]
C:\WINDOWS\SYSTEM32\DRIVERS\UnHackMeDrv.sys
[6B46FC140C9AF68E6E7697D66D59CB4D][1 28512
0E6A959AB1C2D156BE2F3F01762CC82282121F55 ]
C:\WINDOWS\SYSTEM32\DRIVERS\URSCHIPIDEA.SYS
[B4402E7F0923F660270442CE76877ABE][1 57696
B5CE869F8C4EAB7604145D4E14EB5286BAC4A566 ]
C:\WINDOWS\SYSTEM32\DRIVERS\URSCX01000.SYS
[9DD431F1B94789CFB527E5D19261F124][1 27488
28A9A2A053A586757D50A04F9126935DF61E5D81 ]
C:\WINDOWS\SYSTEM32\DRIVERS\URSSYNOPSYS.SYS
[F957092C63CD71D85903CA0D8370F473][2 54784
9D76D3DF84CA8B3B384577CB87B7ABA0EE33F08D ]
C:\WINDOWS\SYSTEM32\DRIVERS\USBAAPL64.SYS
[C87E32B90F085970D9637FBAD45EF6FE][1 169312
69A98C6F535597FFA0745E3D9649DD021FE7BEF7 ]
C:\WINDOWS\SYSTEM32\DRIVERS\USBCCGP.SYS
[0B663856474AC41924D9E9112203858F][1 102400
A1D78A31C92F614F9E542C375A58DC2EAC7A2E83 ]C:\WINDOWS\SYSTEM32\DRIVERS\USBCIR.SYS
[F83D2250256203AC5DA5E8601C1AFDD7][1 96096
8CBDA19205FFD6C4F066E0AB17F9C7687D4A2C44 ]
C:\WINDOWS\SYSTEM32\DRIVERS\USBEHCI.SYS
[7FFD26742321919590ED77FCA556D65F][1 501088
18E451BC0E6907EA3906266EB40928010F0322A3 ]C:\WINDOWS\SYSTEM32\DRIVERS\USBHUB.SYS
[7A749B2863B5561BE34B39E8E249AD8F][1 535904
04CF275D652F46FB69BB51CC8FE2B28834388121 ]
C:\WINDOWS\SYSTEM32\DRIVERS\USBHUB3.SYS
[D2109F1F4FEBF1DAC415CDC5DE876479][1 30208
8AA02E2DBEB4CB47D1833996D3E63E10CC17A4BF ]
C:\WINDOWS\SYSTEM32\DRIVERS\USBOHCI.SYS
[29C9572F2D061CFC3C0BD48A3163E343][1 27648
AC53E277355F00603B8B26EFFD6874096E6C2CE1 ]
C:\WINDOWS\SYSTEM32\DRIVERS\USBPRINT.SYS
[2EC7B2C8123236B1233A77281D378DF7][1 46592
3ED6D7938E2A5AE4FDF8F794D4E8CF981949543D ]
C:\WINDOWS\SYSTEM32\DRIVERS\USBSCAN.SYS
[429477D6DEF3321FF7D3EF23CAAADA00][1 69120
029BFC7EBDF9E462886373194A5792FF6D3C08B1 ]C:\WINDOWS\SYSTEM32\DRIVERS\USBSER.SYS
[529634743FB9D72BDC27F2AF02F3260C][1 129888
DBDF926344AA90F45DACF66C1E91455722BDBAEC ]
C:\WINDOWS\SYSTEM32\DRIVERS\USBSTOR.SYS
[C917D09064CDBD18F75ADC9B2C48F847][1 35328
9F5218C35F6827B5105F7555F52542F01D6E6458 ]
C:\WINDOWS\SYSTEM32\DRIVERS\USBUHCI.SYS
[B4F448F2424492F99F83D3676A453553][1 226816
F0696A595446815E0585A096D56D342167539FA2 ]
C:\WINDOWS\SYSTEM32\DRIVERS\USBVIDEO.SYS
[58827BEFC54D4396D3FD191F5DD31C1D][1 381792
69B77DDDFB5B6C2DBA30BA23A65F4F03AD4D5E57 ]
C:\WINDOWS\SYSTEM32\DRIVERS\USBXHCI.SYS
[0CBDE344FB48E42D78E29469F202ADBC][1 53088
2F27B8F284AEC7FB25717AA3D7C9F11C1C92BBE8 ]
C:\WINDOWS\SYSTEM32\DRIVERS\VDRVROOT.SYS
[723195568C8755CAD57F7933C5F2C5C2][1 201056
8C0A9D010DFFBABFD7D3EC5813290F218371C95D ]
C:\WINDOWS\SYSTEM32\DRIVERS\VERIFIEREXT.SYS
[BB742D3DAA0A186618BF2B7C13446004][1 715104
5BECFFE6C5C700EA845F21FA1C29BB8831626CB5 ]C:\WINDOWS\SYSTEM32\DRIVERS\VHDMP.SYS
[7929228F0E8B0C2FA0495A17A4FC27F6][1 32256
1D3C9466FE46D331BE7A36B54D4435C141B199EA ]C:\WINDOWS\SYSTEM32\DRIVERS\VHF.SYS
[AEE432ED868831B1F068E373598F6D93][1 104288
C14CE98A89BD1DC884F668A4FAEC775DC10BA9DD ]C:\WINDOWS\SYSTEM32\DRIVERS\VMBUS.SYS
[9444B23FC694B5F90F21B0FC7F10D8DD][1 25088
EFCBE30C7061284EDE4F02EE754A2E730DFC155B ]
C:\WINDOWS\SYSTEM32\DRIVERS\VMBUSHID.SYS
[EF78034773CE506323655A868C949144][1 13312
01703A19605E9A190A1D3960E0865DC23046AA16 ]
C:\WINDOWS\SYSTEM32\DRIVERS\VMGENCOUNTER.SYS
[4D0287F566B36536DD812A54C015FC4A][1 10240
83B200F45B0F76CB7A09F3D4EDBDC9477863679F ]C:\WINDOWS\SYSTEM32\DRIVERS\VMGID.SYS
[B5DAEE69BACA64D2BB004568E22D8756][1 9216
FA4BA1BD75205162B4A5E7B3C738BD00CEAF19FE ]
C:\WINDOWS\SYSTEM32\DRIVERS\VMS3CAP.SYS
[C5E0ACE4771F5575D9D5B457ABF3AD03][1 46944
1995400E52CC0931A3DBBE50938F5A98250BBF29 ]
C:\WINDOWS\SYSTEM32\DRIVERS\VMSTORFL.SYS
[29075915F9BDC3437F8BED71C067D399][1 80224
113ED76C6FD4EB4DF16126B60DC024887F1E2723 ]C:\WINDOWS\SYSTEM32\DRIVERS\VOLMGR.SYS
[6BDB6CE6D2D9E3D3F28F1C97E12B62E2][1 367456
99FF41306BE8420860335CE771CA7C2507103997 ]
C:\WINDOWS\SYSTEM32\DRIVERS\VOLMGRX.SYS
[BF2546583BB75F01DDA60A7921DFB230][1 391520
1422E7E69EE02940A157B7F866A85FE9B6DB13FB ]
C:\WINDOWS\SYSTEM32\DRIVERS\VOLSNAP.SYS
[AC2E20A74D09D24485BE8396CE04F07B][1 16224
627D7AB08B1865BCEED6CAD3551B36E0771678F0 ]C:\WINDOWS\SYSTEM32\DRIVERS\VOLUME.SYS
[92F6E3E6D3F1795263EB34B37F74AEF7][1 74080
F004A18C21555633A7B96ED9ACC65FBCBAEB199A ]C:\WINDOWS\SYSTEM32\DRIVERS\VPCI.SYS
[FD9BCB8920973CEAD4D49DC7A6D8A618][1 166752
48074CD00B6C2164A0004C264A5D0A97B32E536D ]
C:\WINDOWS\SYSTEM32\DRIVERS\VSMRAID.SYS
[0C111F220798CCE80484026E06822379][1 305504
214364D2933C6D2909ED35D70E6DD9292F65D3C3 ]
C:\WINDOWS\SYSTEM32\DRIVERS\VSTXRAID.SYS
[607639716E9DB1CEF4E18B5B229293B4][1 26624
FA0CAF2AF76E44E4F6B36A5302FC4C7492648CAF ]
C:\WINDOWS\SYSTEM32\DRIVERS\VWIFIBUS.SYS
[B1ED64E628763148BF84FBE23F2AD711][1 73216
374048757E6DC80581F4E083E359C99D22CEBAA8 ]
C:\WINDOWS\SYSTEM32\DRIVERS\VWIFIFLT.SYS
[B1133B813E4CBF258A392CA08255BA24][1 40448
6D2015151E4F45C55362763BC09C3D4242601446 ]
C:\WINDOWS\SYSTEM32\DRIVERS\VWIFIMP.SYS
[55D00B785A7587F4263D125817871283][1 30208
2A6E802BABC97B04DF215AD9AD587C716F477F9A ]
C:\WINDOWS\SYSTEM32\DRIVERS\WACOMPEN.SYS
[CEF3D306C09BEC1A800E9B4A06F859F6][1 79872
502825E459C9AA92C1E67B600D36C269C756817A ]C:\WINDOWS\SYSTEM32\DRIVERS\WANARP.SYS
[E330144B97D493AA886000DCAAA8DAF5][1 119648
9D7BB0A2FDBEE5D5C880945305D70341D29198B2 ]C:\WINDOWS\SYSTEM32\DRIVERS\WCIFS.SYS
[8FE13674424DE8438F1A81A02BA2D423][1 66560
7A0548DCFEDE49D9A245B7C9C6D2CD73BCE0B25B ]C:\WINDOWS\SYSTEM32\DRIVERS\WCNFS.SYS
[D520B1B849B6D4D707AB31722B952C2D][1 44056
F352FD59019381F4BD201853FFE13A814D3D77FC ]C:\WINDOWS\SYSTEM32\DRIVERS\WDBOOT.SYS
[5030C76047D756263093A47B82970868][1 861296
0CF682DD28E613CA12CE3266D9632815D84B4E19 ]
C:\WINDOWS\SYSTEM32\DRIVERS\WDF01000.SYS
[29FF9199EDEB4F5470BB134D1A2563D2][1 290144
AC840EF6F272BD4C9D6847F9AB6199218330F435 ]
C:\WINDOWS\SYSTEM32\DRIVERS\WDFILTER.SYS
[E02A8693904E87398663D01C0CCE3AD9][1 719872
8BA07A6F8B838C6C29144DC0CD9CD2F7AAEC3C52 ]
C:\WINDOWS\SYSTEM32\DRIVERS\WDIWIFI.SYS
[17CF416CFF408190F5A4CBD79AB12E55][1 123232
6854442919FCEB79C3D5AE427856695D597277FD ]
C:\WINDOWS\SYSTEM32\DRIVERS\WDNISDRV.SYS
[0A9985727EC057BBAE4C1615CD93938C][1 156000
29AEBF9CB5545AED284B8F5F724A0F75DE70FB18 ]
C:\WINDOWS\SYSTEM32\DRIVERS\WFPLWFS.SYS
[0CF79A0EACFFBB75A50A469A27696D02][1 35680
CF2C7415E60FBA7978C7C58C0B1BC97C37ADBEB4 ]
C:\WINDOWS\SYSTEM32\DRIVERS\WIMMOUNT.SYS
[0DE131733317EB4BE67028366B0CAAC6][1 107032
93F66CB291F29341CF5B40150FCC12382C6C5AC9 ]
C:\WINDOWS\SYSTEM32\DRIVERS\WINDOWSTRUSTEDRT.SYS
[92EB5D38BDF10C790450F3E46BF93A0E][1 17944
CED256175F93089AD1FBF9FE801ADCDA44B73869 ]
C:\WINDOWS\SYSTEM32\DRIVERS\WINDOWSTRUSTEDRTPROXY.SYS
[F95DE20312ACCA7761446DE152BD1F7C][1 32096
9DCDC81BDDDE976C5FAAB7AFACC555033F943B9A ]C:\WINDOWS\SYSTEM32\DRIVERS\WINMAD.SYS
[4EFB346BFDAEEB29316AA52BBB9852B1][1 89088
66C4AB1668E05FD1EF424F9ACC59FB768165946B ]C:\WINDOWS\SYSTEM32\DRIVERS\WINUSB.SYS
[8B9AFF5F08E66A6F1F1063DEC9457FB6][1 64864
A9DDA3E20A81B8FAE415819E7DF947C6A6D5F273 ]
C:\WINDOWS\SYSTEM32\DRIVERS\WINVERBS.SYS
[6F4F4F5A007D1710BD76FB311DA97C07][1 18432
887FAE2968C438C3A459F4931D47A854F31B96BE ]
C:\WINDOWS\SYSTEM32\DRIVERS\WMIACPI.SYS
[75A9284F01FE7CB1A7D5EAE5C1EB4F33][1 30560
C037224AD676F0C36327816FE7B4B9DA8C1DF55F ]
C:\WINDOWS\SYSTEM32\DRIVERS\WPDUPFLTR.SYS
[36D7B73ADC3E10607ED6EC874AFB5D1E][1 22528
99A29750A67E821EE9476EB8E2B0C611827CB809 ]
C:\WINDOWS\SYSTEM32\DRIVERS\WS2IFSL.SYS
[AED7FE551E8672B824A56324076183EB][1 99328
1113F404B95B5ACDAA10A1AE32CE416E9AC26011 ]C:\WINDOWS\SYSTEM32\DRIVERS\WUDFPF.SYS
[CEFAB17FD7DFCFA515626C306262E89D][1 216064
D868717130C1FF830EA907558BB779A3BB21CE70 ]C:\WINDOWS\SYSTEM32\DRIVERS\WUDFRD.SYS
[DB77764B46D02DCB9777D9E00A3F7D63][1 258560
97B005434E944FCB738B0DAC30E0F628D4470AD5 ]
C:\WINDOWS\SYSTEM32\DRIVERS\XBOXGIP.SYS
[63088A3361D9A308F328F11E9099DD87][1 43520
C52397B8A148164AE72022542AD271F87C652FFD ]
C:\WINDOWS\SYSTEM32\DRIVERS\XINPUTHID.SYS
[F98415E5B83742C901D0A336972509A0][1 119680
]C:\WINDOWS\SYSTEM32\DRIVERS\ZTEUSBMDM6K.SYS
[F98415E5B83742C901D0A336972509A0][1 119680
]C:\WINDOWS\SYSTEM32\DRIVERS\ZTEUSBNMEA.SYS
[34C935AF2A414572B412B3556586D783][1 39936
208E32D15C6B0B0BEA3453E71FE516C548D45BBF ]
C:\WINDOWS\SYSTEM32\DRIVERSTORE\FILEREPOSITORY\COMPOSITEBUS.INF_AMD64_A140581A8F8B5
8B7\COMPOSITEBUS.SYS
[D53844D90420BC73DC151EE1C9E45C08][1 132608
B546BADF8A6EE01F67A4D1A5511A6EB4C35A384B ]C:\WINDOWS\SYSTEM32\DSKQUOTA.DLL
[5FCA45C24501DA7390065D3706A9FC3F][1 152576
454F64576870B4F44380FC196216AC0FFC76EF02 ]C:\WINDOWS\SYSTEM32\DSSVC.DLL
[C89F159A577F19F7F03C73C98D29D841][1 46592
DE60075CB979D655256F2DB447A22BD366AAEB6B ]C:\WINDOWS\SYSTEM32\DWM.EXE
[A8895E416EABF23C07D559DD2B03FC1C][1 59232
1D3FCF1F9B583E01AF600ACFC27CB5494C227989 ]C:\WINDOWS\SYSTEM32\DWMINIT.DLL
[EC03B2D63A9A3AB25A7062CC9036F453][1 120320
]C:\WINDOWS\SYSTEM32\E_YLMI2E.DLL
[9FCE4EF7D5E274F862D9A2526B5F4779][1 112128
1F8199531968F2AE8A83122BE8125DD27A3765FA ]C:\WINDOWS\SYSTEM32\EAPSVC.DLL
[31BFADFB13EBC9CB06D6E250FEA0FD36][1 856064
8F1F9521FDBDA9307FA668019354FC2AD16A99EB ]C:\WINDOWS\SYSTEM32\EFSCORE.DLL
[7A2FB2DB4F7772DD4C0ED41011B5FB8B][1 55296
30826D75FE64C2BC69782770BBC0E78D578D7B50 ]C:\WINDOWS\SYSTEM32\EFSSVC.DLL
[0043AD6FF21DA011F05C33790875635F][1 590336
8EF475627A0504CB4941C69888A83FCA0BE60640 ]C:\WINDOWS\SYSTEM32\EFSWRT.DLL
[80A7999DE02CE678B865832E1CE78CD6][1 140800
80F5DF14A6033DBECF4016DB9D7D9EC05CDF3DA8 ]
C:\WINDOWS\SYSTEM32\EMBEDDEDMODESVC.DLL
[F89083AB8B9F51C0031C1CBD0A9A7E35][1 453632
57F90A0F691CB700860A828D5EEF8A737081C99E ]C:\WINDOWS\SYSTEM32\ES.DLL
[BCB9F3F5C67DAF7FCA462CB7F63C4376][1 3054080
03E432D60EF1442EE39B3DC9B472D3A2644F5D6F ]C:\WINDOWS\SYSTEM32\ESENT.DLL
[2B9F2151617798C967B90451F26BD364][1 156160
A345ED44D9B3E078107E903960F0F6A12F6D9D3B ]C:\WINDOWS\SYSTEM32\FDEPLOY.DLL
[EF0DD43A4CBAB367BCA1AFBDC9971E4F][1 20992
744292B1E84FF8A4E7E9988754B43666191ED487 ]C:\WINDOWS\SYSTEM32\FDPHOST.DLL
[34DAC585994CD3B4E910DE11C584EF3D][1 35328
FA9A8BFD868FC8570839A5488BE58BDC895EE1CD ]C:\WINDOWS\SYSTEM32\FDRESPUB.DLL
[B68DA1FE3CA2311AFD38DD6905CA7F71][1 122368
830C20BEC069E7971C288F543CCED5C286D516EE ]C:\WINDOWS\SYSTEM32\FHSVC.DLL
[15F0990B7C101163FE27D9B19FEB3D43][1 635904
C625FBDEC09E7D7FD0FA2E2239D7BC88869077C2 ]C:\WINDOWS\SYSTEM32\FLIGHTSETTINGS.DLL
[5070B37B20DDC257AF93EB0BE8AB5690][1 1845248
0E17DF4700523F6CFF0090F7B042057F98681BA1 ]C:\WINDOWS\SYSTEM32\FNTCACHE.DLL
[6B4604F08F18FF986A5BB411049B7230][1 8192
1323770AF18B454C5778B3E999412559435D854E ]C:\WINDOWS\SYSTEM32\FXSEVENT.DLL
[3ED36FD05013F4E77E5861FECD4DFB3D][1 46592
11DF422333F7A1300BE0E1A01BAA1384D01102DF ]C:\WINDOWS\SYSTEM32\FXSMON.DLL
[77CE56471AF984800F318F3734D768C7][1 644608
A20E760B85BCA3EF3D4203A181422FD7EC656685 ]C:\WINDOWS\SYSTEM32\FXSSVC.EXE
[39A3A7E108ECFDEE421CACCA06C99BA9][1 128648
A1A442C96BDD8D6E66AC7792D7136ED84C532741 ]C:\WINDOWS\SYSTEM32\GPAPI.DLL
[D299735117D7DF61A083878C96A3099A][1 675328
0C818441A51BE38E4DF53AFC504D70521778B8FE ]C:\WINDOWS\SYSTEM32\GPPREFCL.DLL
[8997353398C8466ECD183942D5FCC65B][1 1227264
3873376C966FB52CA327708E2A99A9951B5CA5CD ]C:\WINDOWS\SYSTEM32\GPSVC.DLL
[C900FE0DD6A1E2220084B8F1C427790C][1 36864
F4ECA42480C335AEDC7D4C32996640D7F753B5E7 ]C:\WINDOWS\SYSTEM32\HIDSERV.DLL
[0C84C250F80EAEC2C9768464CC1A9626][1 67584
0ADFEE8C1B47B3B3E9703472EFB5E670935515ED ]C:\WINDOWS\SYSTEM32\HVHOSTSVC.DLL
[ -2][0 -1
]C:\WINDOWS\SYSTEM32\ICARDRES.DLL
[F5D67749BCB061C4E108DB5E7C4B12CE][1 305152
9A45456708A998B30FEB49F5FCF3915400AD0E84 ]C:\WINDOWS\SYSTEM32\ICSVC.DLL
[F70DCCE72343449F0D12A0A92282B019][1 349696
04492DD075C4D86D23C31D5D9D66B94DE777C215 ]C:\WINDOWS\SYSTEM32\ICSVCEXT.DLL
[A674BF4F3A8A995DD816CD83B9358AD4][1 13107712
2356E08917E6AEC9BABC3999E2DBF082EAB9B93D ]C:\WINDOWS\SYSTEM32\IEFRAME.DLL
[AFDAB46F7D47A5D298A4F956A3C18116][1 373728
111EEAF4A99FAF373F35A6365E7AE12F926C8E62 ]C:\WINDOWS\SYSTEM32\IGFXCUISERVICE.EXE
[40F9C1B354C0B70B9D5FB3E540977B66][1 354784
8C27529BF2A7469E926CDC1FBFC765BA265AD70B ]C:\WINDOWS\SYSTEM32\IGFXEM.EXE
[A92D14C1240FC998075456D5475351FF][1 268768
55C4F349688FB90A8307C5C13249D65E9610C59E ]C:\WINDOWS\SYSTEM32\IGFXHK.EXE
[63C36E3D97A3EA6B3A89B6075BD77925][1 401888
7AF3DE03E261AB3A50E614E7E341E0EB3AD3B2CF ]C:\WINDOWS\SYSTEM32\IGFXTRAY.EXE
[F2934208C0E50C0B971A7981AB90BED2][1 932352
1C40F84AE8A5D88A3BDDF74925D7E5FADF2A2389 ]C:\WINDOWS\SYSTEM32\IKEEXT.DLL
[A5538EE91A10A7520A69AB855DC61183][1 35696
541BB1CCA616DF038AC71D15B0B2BA6B23BBC98C ]C:\WINDOWS\SYSTEM32\IMAADP32.ACM
[F798F225C38510BE4085EB19524861FD][1 174592
D0B841359FCA37F843E3EF441BAEA1ADC6C3C5C4 ]C:\WINDOWS\SYSTEM32\INETPP.DLL
[DB5F6C68E345268B56D635EA13699413][1 945664
08C033BAC8881CD20E11CF2E004B54E92725CFCE ]C:\WINDOWS\SYSTEM32\IPHLPSVC.DLL
[E38BE81F0F6D9C74E420A82BC6A02AFE][1 541696
A21E473D5BABE386324EFBDC20BCE2204D7B90C9 ]C:\WINDOWS\SYSTEM32\IPNATHLP.DLL
[F70CAC34B455D05EAA04B2F8FB58E1CB][1 391168
CA291617B4F8E102888CBEFCEEBF4CC4A2DFF4E4 ]C:\WINDOWS\SYSTEM32\IPSECSVC.DLL
[8C604213A2E73088BFFE6CD2E6F1AE53][1 25088
BF182CAEA7AE8EED36313577E3F6F52533CDA33D ]C:\WINDOWS\SYSTEM32\IRMON.DLL
[07E3E54734B14F43A4A95A849C0A0DE2][1 151552
03F7B755BE5A99F67595F145CD483210FC80E060 ]C:\WINDOWS\SYSTEM32\ISCSIEXE.DLL
[557AF00E0FF6FB1D9EFF95ABCFD67B1C][1 54272
219678814515592C0A6CDF0E6D047B72ADA48231 ]C:\WINDOWS\SYSTEM32\IYUV_32.DLL
[1C0CF1ADBA19E1CD3CB4FAEAE78E86C2][1 96768
BC5B61C27A6421FBDE3F7CD03BC7FDDB38862C38 ]C:\WINDOWS\SYSTEM32\KEYISO.DLL
[B9C54CDB8779423E2E3C4865D544939C][1 283136
AAC6EDB24B97FEED15637484B1B1D3539BD4E525 ]C:\WINDOWS\SYSTEM32\KSPROXY.AX
[F8EBAA1FE6D3BF84752931DE1BFA0E2A][1 37376
95C430F40C0FEAEB5315DB1EA34F1B02CCA7B4F7 ]C:\WINDOWS\SYSTEM32\LFSVC.DLL
[5A23E4BE0CCF49663C4CF7EB74C20278][1 26112
399B7BA337AC607B9A95B71BB6178378373980DF ]
C:\WINDOWS\SYSTEM32\LICENSEMANAGERSVC.DLL
[0AC1BD5A28FAA371EF34859FE703E515][1 274432
C369107421369068D52A77F8020BED59F777523D ]C:\WINDOWS\SYSTEM32\LISTSVC.DLL
[88A3C935725FA6EA1A228DCC26CF9C6F][1 275456
B897F395997962E6957D32B44C7EFA2750AB6388 ]C:\WINDOWS\SYSTEM32\LLTDSVC.DLL
[3F858E28AEE6545FA1B64134DFD5C2CE][1 27136
5954EF2451DBBF356EFAF2309CE174ACAFC406F7 ]C:\WINDOWS\SYSTEM32\LMHSVC.DLL
[4A1EC99F1D9F2AC8B96937FC65DE7E16][1 122880
0B3E80426E67FD6EE50A3EB7607047DF1ED57DF6 ]C:\WINDOWS\SYSTEM32\LOADPERF.DLL
[E8728C29BA67AD5B9F917001FC347271][1 1131520
3F5B057F1CE9101476810FACE5E4AB1C3CE01057 ]C:\WINDOWS\SYSTEM32\LOCALSPL.DLL
[109C1D609951E886D3643B15C1EDD1C2][1 11264
20E9173558D9B594D40D5EBB4A7C4019BFF0BF3A ]C:\WINDOWS\SYSTEM32\LOCATOR.EXE
[5C6553D5E541E15C18BBD59E0FABF2F4][1 57408
AC51E0ED679A315171CDB289B5A5F3F4600A752D ]C:\WINDOWS\SYSTEM32\LSASS.EXE
[D5EFC0BAEC21EDE6FE03D377D403B421][1 691712
299DDB4AE61D4C602C67CACA58051AD1B51D3FCB ]C:\WINDOWS\SYSTEM32\LSM.DLL
[916AF28E2A7B5EB4328623A5BE960D79][1 98304
D98C8C13C4377815B45C4A2B4DEB1132F52381F2 ]C:\WINDOWS\SYSTEM32\MCIAVI32.DLL
[55A417C3E41F2A98666CF929EC19108E][1 52224
2449E42DF94C010A6B4A4C3E13DE45B3E3DD4D30 ]
C:\WINDOWS\SYSTEM32\MESSAGINGSERVICE.DLL
[46357DDCA2C795B63DE0FFA00F2C33D4][1 327168
C028F4882C74E88BDEF6C8CD29C465FAB0EE1144 ]C:\WINDOWS\SYSTEM32\MICROSOFT-WINDOWS-
SYSTEM-EVENTS.DLL
[DAB20111EE99BCA4019A6D285FF2EA0E][1 25088
7B3A90B6D663704539E2E5FAFA5C81530FCB6D4D ]C:\WINDOWS\SYSTEM32\MIDIMAP.DLL
[9F699136FA1A8A170C2C05D7790A5FC0][1 82944
86C310A5C6D12C09B1EF5E77E5DEBD5996E8C01B ]C:\WINDOWS\SYSTEM32\MOSHOST.DLL
[13F6B64235C60167052364BF7D99E4CA][1 496128
C36F1B432A40A52DAB6000FEB9BEAA0EC099C0A1 ]C:\WINDOWS\SYSTEM32\MPRDIM.DLL
[70F9352EF3D91058486BE638948E0CD0][1 115200
2D5C9457E1E8A40F1E652B85CA7AD55BA52987B9 ]C:\WINDOWS\SYSTEM32\MPRMSG.DLL
[8FC71447AC1D835A0DD2D12EF03D95A7][1 893952
C35423D97E5E01BFED049888C83588FAA8238024 ]C:\WINDOWS\SYSTEM32\MPSSVC.DLL
[D71EF631D3EEA14FBAE8C8EDF7BEE307][1 29184
BD31F7E16D86CFB4DB274334DF414FA37A47F3CE ]C:\WINDOWS\SYSTEM32\MSACM32.DRV
[198B34F7ACCDEA764A508D9B86A8AAC1][1 34640
E653CB2566C31A2FB764D150D2B6AB4F4B79C68B ]C:\WINDOWS\SYSTEM32\MSADP32.ACM
[5ECE402D7E12EC3750D044BF3D878DF6][1 387072
633704576029BE229D7AB7283F0262E3D918C94B ]C:\WINDOWS\SYSTEM32\MSCOREE.DLL
[308F08347923DEEDE7BC03EC7D485841][1 147456
0406220A6B6839D6C8156AFA6CD8FCA9C3381F80 ]C:\WINDOWS\SYSTEM32\MSDTC.EXE
[8125BDF7ADC261F75EF0CAD92456E350][1 376320
A04930C22AA0C48DE977248B75926CD8E70A830A ]C:\WINDOWS\SYSTEM32\MSDTCKRM.DLL
[CD8F44AD342C9633C58B3917ADC06F3F][1 15360
99D078CE95DC2359F5E7733BD1DCED6545BD7B3B ]C:\WINDOWS\SYSTEM32\MSFEEDSSYNC.EXE
[BCC8C24184252E88F455FA4E893BFF20][1 25352
AA5DFE06BFA3929D5082B5D5BBDDF46C7A2A4663 ]C:\WINDOWS\SYSTEM32\MSG711.ACM
[196F849F8C3FAD6A70A77790D55242E1][1 42936
F9C6A4EBA0D1E0BE3D7E4F5F5E86E6BD7B9F5B16 ]C:\WINDOWS\SYSTEM32\MSGSM32.ACM
[FB9843FDF519FF36C520DC6BB3D520C8][1 65024
2540933DCEEBD601FDF172BB87F037A367476208 ]C:\WINDOWS\SYSTEM32\MSIEXEC.EXE
[068361A7A9EFA2111F58A7B6A7F09FB6][1 25600
B06CC709F5BF9F81EA1D3F66FA7E1BE7AA784708 ]C:\WINDOWS\SYSTEM32\MSIMSG.DLL
[4D12DA6749429B2178C7A9EEF867DA9A][1 606720
C0169FF3916982814CA2FEDADA060F9883EF935E ]C:\WINDOWS\SYSTEM32\MSRA.EXE
[E7CDD4C7C8DC34A6CA536825042F7946][1 17920
CFCF134C06611BC35BF3A89D6683AFED755E6F5A ]C:\WINDOWS\SYSTEM32\MSRLE32.DLL
[6130E5C1F51B75CA0B39241DAC5BA6F9][1 881152
C9C8B798370463832565B3E1FDFC0B2373613354 ]
C:\WINDOWS\SYSTEM32\MSSPELLCHECKINGFACILITY.DLL
[EAA0B5A766E8FABB40F5D2DB226CD58E][1 76800
9C03308004D7A32C68B9074E4A790E8601AD1136 ]
C:\WINDOWS\SYSTEM32\MSSPELLCHECKINGHOST.EXE
[C1FF79BDD477989AE6A82DDB9520F7EE][1 8077312
E897159FE941BBFC239DF3197772C50B034DAD4A ]C:\WINDOWS\SYSTEM32\MSTSCAX.DLL
[E4FF0CC27BE9672E4902DE05EFD17D30][1 38912
51775348B81D059C7C7375CAE2AF3E84891222D4 ]C:\WINDOWS\SYSTEM32\MSVIDC32.DLL
[5918AA7EA238D7C79DF3EA19A327539F][1 27648
C24449D575605EC42056E5DE900FAE981BB358AC ]C:\WINDOWS\SYSTEM32\MSYUV.DLL
[C3D9870E680D9D843B18F4626C3858FE][1 167936
85C92A0CDC1B08765C87EDDEF1D19DCB04CBF64C ]C:\WINDOWS\SYSTEM32\NCASVC.DLL
[04CE2C0F0759EACD886BA4B658B60D5D][1 339968
1D164F05E8B844C533799000895D9103782EB468 ]C:\WINDOWS\SYSTEM32\NCBSERVICE.DLL
[E6094065008FE423377294050E7CEA2D][1 88576
83434F3ED2CD2027B0580F303AC45C44A214848A ]C:\WINDOWS\SYSTEM32\NCDAUTOSETUP.DLL
[DDCDCAE28069AEDD21F25558FE3F549E][1 820736
2C3EC53B65F37AC0138D1F3CA6FE5C43F8ACF461 ]C:\WINDOWS\SYSTEM32\NETLOGON.DLL
[D3BF2DA9216A4CF22A97820A50A67EFF][1 259072
DDBABF6B6C7743CDB18E1496E606D44DFD8BBB13 ]C:\WINDOWS\SYSTEM32\NETMAN.DLL
[ABAA5AB84E420F3C478B0591D3CF5E26][1 519168
DE5DFDD8C9DE01BD768E518E57B82F1E4CD7ABCD ]C:\WINDOWS\SYSTEM32\NETPROFMSVC.DLL
[C24EB837E1CF8500BBE6BD282AAA840C][1 266752
F364716CA00F5B40E177640429EFEDE4956447A1 ]C:\WINDOWS\SYSTEM32\NETSETUPSVC.DLL
[DD248F485177E78F4737A0A3242B2D9D][1 330752
A0471AD1D23F85D8EB6BCD51DAA954B9552723CB ]C:\WINDOWS\SYSTEM32\NGCCTNRSVC.DLL
[427A0DE4C03B890604AACFF941B57C34][1 983552
17AC1D839730D690CB76FCBD83CE50A27B19CE1A ]C:\WINDOWS\SYSTEM32\NGCSVC.DLL
[9B9F520C72EE33EAEC857124BB800243][1 368640
0482CCADA470F1E53FA59AF3FEB2847BD60D7C36 ]C:\WINDOWS\SYSTEM32\NLASVC.DLL
[1993C85962692EF7024501E7FE92D466][1 30720
126F4BC42408EB491380FBD43428F102D9B21D68 ]C:\WINDOWS\SYSTEM32\NSISVC.DLL
[9E3202DD11964FE4B05D89D7095BBD4B][1 842240
69BEAB82B3DFB04C88EBABA7DC813B1498846620 ]C:\WINDOWS\SYSTEM32\NTSHRUI.DLL
[F8A52513028AC950346CEED6DD771719][1 18432
E4D40BAEF99D00EECBBF69BC6C09BECCFE233B1F ]C:\WINDOWS\SYSTEM32\NTVDM64.DLL
[19382F6C0FFD6ABB340527BB4B8EDA55][1 945600
03F518BD023EEC9861612C4918F360E592AC8937 ]C:\WINDOWS\SYSTEM32\NVVSVC.EXE
[2BBCED66D7AFC968BDBB0E4D8524DF0A][1 425472
EBBB274E4F973BB271253EAD1E56F60A2A9FAB0F ]C:\WINDOWS\SYSTEM32\P2PSVC.DLL
[9886F4C8026D37BEFAFF2B99EAC136B0][1 64000
54521DB9CB5019A54BF258D0F54BB2DE93601A12 ]C:\WINDOWS\SYSTEM32\PAUTOENR.DLL
[CDD8EDF4C35BE6D6137112F5CC7A70DA][1 500064
73302E76C486B486E0192CE4637794B9788DF431 ]C:\WINDOWS\SYSTEM32\PCASVC.DLL
[31E6E5EB5DADCC96EF14B224E787EBEA][1 45568
B364EB6E439F14183AFFF1FDDD458F2DF1D798BC ]C:\WINDOWS\SYSTEM32\PERFCTRS.DLL
[4E951BCE60A6E22D34180489AF322E53][1 25088
D199C68384EAD6D02B072F41200C5121508B8615 ]C:\WINDOWS\SYSTEM32\PERFNET.DLL
[6192765AF80C0519F8CD3DDD5166AD95][1 40960
CD6EE8CC9C9FA0F5A6552F4ECF45318882717308 ]C:\WINDOWS\SYSTEM32\PERFOS.DLL
[D11B7FC326EEA4D412FD4D7E5117190F][1 40960
F08683BAFA369BCC7DE82DF4A521A2087993EFD7 ]C:\WINDOWS\SYSTEM32\PERFPROC.DLL
[928B1EF93EB20E8DF05D01BF0DE41AC8][1 781824
28D5FB0F5E679A6E272F84BC7F5BC20879CF0EDB ]C:\WINDOWS\SYSTEM32\PHONESERVICE.DLL
[C7A94D99CDF054248EFBD9B93D096DA6][1 203264
16D2A667B1AF8085CB9970ACE71BD83AD60E53BD ]
C:\WINDOWS\SYSTEM32\PIMINDEXMAINTENANCE.DLL
[F931F21E4287FE3ECCF09B54A232BBA2][1 1457152
E2C1393E8C137262E03F484DDB1334A86214BDB4 ]C:\WINDOWS\SYSTEM32\PLA.DLL
[4578ECA1FCEF4E7C787D84F78625143B][1 345088
A2C9417F3676DB74BEB95DC84BC4BFD1D16BDA38 ]C:\WINDOWS\SYSTEM32\PNRPSVC.DLL
[D419FCF2AC6BD928B2383A4FFF15A692][1 358400
02C4CF7EBB69EFDBD4CBD1C1C84F9872529BE0E8 ]C:\WINDOWS\SYSTEM32\PROFSVC.DLL
[8E91463B087FBAB49E42049F3BE0E1B3][1 1599608
D0F7690096BD58BA8062B4901E8174DC5D80DF1A ]C:\WINDOWS\SYSTEM32\PROPSYS.DLL
[86161A89F16851728802590EC7C92608][1 447488
B012CA2C9EBDD5BD05494A92E78EC20C31E452BC ]C:\WINDOWS\SYSTEM32\PROVSVC.DLL
[A344054D9965A116EC99C9AE63729782][1 1054208
1203A773DB6EC77D048FCFA361929E6CB93ACA36 ]C:\WINDOWS\SYSTEM32\QMGR.DLL
[8C97BD85FAFA22D2483DE56FBF7298ED][1 1633792
E6C2B1F2AA1EDAC5373D89B03895E75DB86F33EF ]C:\WINDOWS\SYSTEM32\QUARTZ.DLL
[7A68710BAC9B6809314B86C0CB1CBC4A][1 275456
F22AF2FF2B8FBC37C8E6E9B940D82A1EE4512AC7 ]C:\WINDOWS\SYSTEM32\QWAVE.DLL
[7B82197BF35CC3BE59AEF8B706AB8A16][1 105472
408B7B80DD2D9207AB473258BC37A8F9A954F4A5 ]C:\WINDOWS\SYSTEM32\RASAUTO.DLL
[5286CC0599ED8837322E6546C578047A][1 658432
2AB76B43FCB5067E47A2132240B4D71FA32D1E90 ]C:\WINDOWS\SYSTEM32\RASMANS.DLL
[D298D9224AE66A5E50BA55877F2B3EA9][1 650752
83D23CDCCAE9712451E8C8A5DCEDD9C2C1D5C991 ]C:\WINDOWS\SYSTEM32\RDXSERVICE.DLL
[3183B161B1F05333F6C325577FEF3596][1 155648
9D898E48CCC05CB926E60F517534FE8010FF4D55 ]C:\WINDOWS\SYSTEM32\REGSVC.DLL
[5DAA644F17780FC4E3F4820A46D38FEC][1 140800
81CA2E6DEC099C48733B080235CECEDEEA7BC0E3 ]C:\WINDOWS\SYSTEM32\RMAPI.DLL
[672724C8B21B7DC56646045DE4D5B860][1 79360
2B954E70DB5D924733DDC42DB936A9EFC8AE1F9A ]C:\WINDOWS\SYSTEM32\RPCEPMAP.DLL
[F66BFFD863C4397A88242C3206FB63DC][1 1177688
FE682B0F9D2D0AF147DD85C70D68C219765193A3 ]C:\WINDOWS\SYSTEM32\RPCRT4.DLL
[4A7015195E49A3BA7DB967B277B21E9D][1 890368
D8DED357E1BAD6215CB4E01058F4E7A122B2562F ]C:\WINDOWS\SYSTEM32\RPCSS.DLL
[C79CF9814E18D13BB77F74D40F06DEBE][1 201728
09905C0A340956B82ED4203D971FDEA8B2B23D0E ]C:\WINDOWS\SYSTEM32\RSTRTMGR.DLL
[1E03C94933E088D9FAB00B49D46CC370][1 33616
1DFE5C08B6C640833FD1B2D0761E074E3CE6AEC2 ]C:\WINDOWS\SYSTEM32\RUNTIMEBROKER.EXE
[3CD0130FFDEAEACF0905B482F3934EA3][1 250880
65448BEAF4151D1C569852291D33B8C1F13EA027 ]C:\WINDOWS\SYSTEM32\SCARDSVR.DLL
[3FE129F92033059B84885E1F5D458EF3][1 201728
0B71BACACC40E015060BA55B492B1309ED5A3163 ]C:\WINDOWS\SYSTEM32\SCDEVICEENUM.DLL
[7ED53A9C37AE7ADE2A72A1C2EE86879B][1 270336
F4E687A3434C481ADBED17B684D313DEBA91F881 ]C:\WINDOWS\SYSTEM32\SCECLI.DLL
[93718CA7CD59170FA994FEBBD87C8182][1 502272
CAC50F6B11D80BE2A0467166E0BA108D07410860 ]C:\WINDOWS\SYSTEM32\SCESRV.DLL
[D4DB6B318A0A0C74A90260725A228C0B][1 948224
5DD0C97784F4D4B859E3E7323823542BC01EAB4E ]C:\WINDOWS\SYSTEM32\SCHEDSVC.DLL
[0A0C06D77839AC86EFF2CC0250A7C53F][1 1189376
89E98A8BF6D3AB322E9B6EAA9B87A573F16C81A1 ]C:\WINDOWS\SYSTEM32\SDENGIN2.DLL
[F3714DBAA42C15F78FFCDFE4273214EB][1 147968
04A54DB2F4203E63517CF242491FE5EE748DD0A0 ]C:\WINDOWS\SYSTEM32\SDRSVC.DLL
[6D994905C62A6F295D1C2460FCF86D9A][1 206336
4DF241B1C926F2B1EEE81F7F4C4F8A4BB6E924A1 ]
C:\WINDOWS\SYSTEM32\SEARCHFILTERHOST.EXE
[5F5FC52A4CE1B1C3890268EA46EB06D4][1 903680
B9E1CE8A6F5D8D5B3E70DB04B3AC26A1F5E70A6E ]C:\WINDOWS\SYSTEM32\SEARCHINDEXER.EXE
[C9B18904B4F50506E8A621B15666221A][1 349184
6F76D0C433D5F44ABA79EE96A07FC871089AEB3D ]
C:\WINDOWS\SYSTEM32\SEARCHPROTOCOLHOST.EXE
[EFD644DD091E1D94555FC3BBC95EA66D][1 31232
49B5B3BD14495E9EA51E5F5143CBC5EA8539795B ]C:\WINDOWS\SYSTEM32\SECLOGON.DLL
[F48535714BED7DD784853889B4594B26][1 70656
0A07DAC9A8B0ED5EB6A94D0E401A1D93FE5CF560 ]C:\WINDOWS\SYSTEM32\SENS.DLL
[CF2AEB951CFC56D4F6CF2D66218B673C][1 1312768
F6D92F9E61705212EBE5D64F54B33265A06B2F5D ]
C:\WINDOWS\SYSTEM32\SENSORDATASERVICE.EXE
[C09A42163878A082C3F0D0A3DFE95714][1 417792
4BF44C3491102BEA2DD9ADE9089CE387790D09C5 ]C:\WINDOWS\SYSTEM32\SENSORSERVICE.DLL
[E6F00415DADCEEC860E7AB42BFD19A65][1 179200
648A325931D493A16BBB0BA8107E720ACC1916D3 ]C:\WINDOWS\SYSTEM32\SENSRSVC.DLL
[82CF273F0E8F243789683DEB40757569][1 387072
EB7296006D4E0FD1F243AD80C58FA1A8C37B9AF6 ]C:\WINDOWS\SYSTEM32\SESSENV.DLL
[E4AC8A0D5FDCF8EA075C514FDE912098][1 22220864
2D2E283EFD8C18120FF1E79CC023DF5635BB31F6 ]C:\WINDOWS\SYSTEM32\SHELL32.DLL
[482E6BE8A07832E824080D352075ACA1][1 617472
FB966202299732E20EAD7F579C2DA8C967D5E67F ]C:\WINDOWS\SYSTEM32\SHSVCS.DLL
[57C78F5EB4D7D6427F5A43137683A245][1 78848
B7F3E6395F369B98B5DD7BEE93BEAA02FFB843F0 ]C:\WINDOWS\SYSTEM32\SIHOST.EXE
[D233EAE2A9D48485321816486ED635EF][1 23552
CA6D10F908DFA9D2994CD46B02FB80A51D48BD88 ]C:\WINDOWS\SYSTEM32\SMPHOST.DLL
[0B217141AC1283655402CDB356577735][1 590848
DF7EE4EC15204C6E318A629912DFE0733D92712B ]C:\WINDOWS\SYSTEM32\SMSROUTERSVC.DLL
[01275E832DB5A5159379A9C67AF51BBF][1 15872
D38294BAFA1E0A3E00141AF20AB4ED8E9107392E ]C:\WINDOWS\SYSTEM32\SNMPTRAP.EXE
[E320E11DE8152CC0EC1425FF986FE5E1][1 3077632
8A3098AB937E49D42569D52DE3B99820FDBBD87C ]
C:\WINDOWS\SYSTEM32\SPEECH_ONECORE\COMMON\SAPI_ONECORE.DLL
[30AA256A85C1A7B17A590B1C5244D28E][1 3318784
AD390B93B236F4D3608F25C382191CD9172DCA68 ]
C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\X64\3\PRINTCONFIG.DLL
[1DFE222F8D6A422B7ADC909E0C8840DA][1 792576
585D3E21AA1A26E12CF83ADAB1EB5F7258EB2E83 ]C:\WINDOWS\SYSTEM32\SPOOLSV.EXE
[23529A00195CE71252FEBF647E56E27D][1 5622088
2669972AB3821A289C646C8C5144F31B05194F53 ]C:\WINDOWS\SYSTEM32\SPPSVC.EXE
[F106D2960A93059701F35243DEF6421B][1 473600
7501BAE05F161138A510432A56CFA47639212CC4 ]C:\WINDOWS\SYSTEM32\SRCORE.DLL
[770458466089046624CE3CAC1F10581D][1 4608
96C8F62FB8607EF8FB1688F2DC84B45A3750C6C5 ]C:\WINDOWS\SYSTEM32\SREVENTS.DLL
[D9874F8E0BF0BCA148A8829839259B5B][1 280064
A64498126AE90963330D57376551FE5CA8882633 ]C:\WINDOWS\SYSTEM32\SRM.DLL
[6B515518F39854F4FDD9B8571A7304E9][1 304128
B4772DE48A691FD03FA8B35470A724D9693D56BE ]C:\WINDOWS\SYSTEM32\SRVSVC.DLL
[44758105AB3EA34E815D4B6CA1153311][1 236544
3BD38B57CD997957F3D5ED02C849A5ED3B777177 ]C:\WINDOWS\SYSTEM32\SSDPSRV.DLL
[B97C7EC07218A8002323718202BF5E77][1 209920
426F5391D564B4A310F34BA28597134DBB69193C ]C:\WINDOWS\SYSTEM32\SSTPSVC.DLL
[B91FBE7CB4633FEB32AFBD0B48576396][1 396800
B71CEF5E0F731308BC1A33588D1A3315992D7A0C ]C:\WINDOWS\SYSTEM32\STORSVC.DLL
[36F670D89040709013F6A460176767EC][1 44496
0DAC68816AE7C09EFC24D11C27C3274DFD147DEE ]C:\WINDOWS\SYSTEM32\SVCHOST.EXE
[224C92E442B1B8C20C274332F1ACF00D][1 13824
80323BB8D366D0B821D4C84DDF899EB608CF28ED ]C:\WINDOWS\SYSTEM32\SVSVC.DLL
[2EE27411B5904C63D723BEA391819F58][1 467456
4F450EF09C2C947B25DC53AF0388EA1F3EDD86FA ]C:\WINDOWS\SYSTEM32\SWPRV.DLL
[D00F7DA3612C894AF0A76A699A8BEF5C][1 78336
5FA0F5D9B17DD34B26A7C3CF7A528B8AA4F50B39 ]C:\WINDOWS\SYSTEM32\SXPROXY.DLL
[D39F3674320CE083AB894A00ED134276][1 616736
305D8B5F14195336EC4D4E7FEF0A55DA1D252356 ]C:\WINDOWS\SYSTEM32\SXS.DLL
[7F64574E8FA462425B27F98D36C4F8EB][1 183808
D0E585D9B6C7211ADC4482B6AE3963A66C8E3B0F ]C:\WINDOWS\SYSTEM32\SYNCUI.DLL
[FED48B19D6F55D7A3AB498D85729D1BA][1 944128
33D7D271C5A2E8E619FBC0E85F28F5C8EE695B72 ]C:\WINDOWS\SYSTEM32\SYSMAIN.DLL
[D9FEA79BF6AF136F8E656AE045C2FEC8][1 387072
74C998E1ABC00E6ED4642013AF88A768C88C2438 ]
C:\WINDOWS\SYSTEM32\SYSTEMEVENTSBROKERSERVER.DLL
[0ED2AACA902980E3A8DC04CF03739B5B][1 148992
B3A33C4388B216538B5D81782BBDEF3A24A435EA ]C:\WINDOWS\SYSTEM32\TABSVC.DLL
[3929C8FC134AC672C4F3F85160956257][1 309248
D5133922C676750DF89A8980866247335EF3E89D ]C:\WINDOWS\SYSTEM32\TAPISRV.DLL
[0E1853D3339D2963D2BC6AC1FDC1C811][1 88392
9CC394E9F9AEF58F7BDB90B8B19559AB6605CB64 ]C:\WINDOWS\SYSTEM32\TASKHOSTW.EXE
[4D80E84AB61A0A56B682272F64047A9C][1 219648
091481535B5B9A77056E0B10552F717B8E279740 ]C:\WINDOWS\SYSTEM32\TCPMON.DLL
[5339C07E04EF056ED7F1E25F1D2F1C8A][1 987648
AFD588E720274675A81BA16199E0800FD4C06760 ]C:\WINDOWS\SYSTEM32\TERMSRV.DLL
[937AC47F7356554DA05D9722C356EB55][1 202240
29AED87B8DBADCE9BB82DDCDE0FF65144D19D0A8 ]
C:\WINDOWS\SYSTEM32\TETHERINGSERVICE.DLL
[2AF438EC0D361A7BBB70E604A686602C][1 70656
FD2C610F7E65DF4E8FB8A07A35822B1EDB65DC38 ]C:\WINDOWS\SYSTEM32\THEMESERVICE.DLL
[1482B8ED5CACA87992A882B853B83CEE][1 287744
44E6C947EEFF806E44D180F18624053497878624 ]
C:\WINDOWS\SYSTEM32\TIERINGENGINESERVICE.EXE
[C1F8CBE2D4843E0CCC3EFEA2EC60D4AB][1 177664
026CFED526813A41AF8A303BD18971092D4E13D0 ]
C:\WINDOWS\SYSTEM32\TIMEBROKERSERVER.DLL
[EC00F7D5094A5BDFAAE082DBE0E649AC][1 3401216
52AA84030A324B50F081D50FCB1BC37DB2B86F82 ]C:\WINDOWS\SYSTEM32\TQUERY.DLL
[3B91F35089240F6187AD681A5EC28BDE][1 116736
4BF49C8451C038B1E3C9549E17C94919459D74D2 ]C:\WINDOWS\SYSTEM32\TRKWKS.DLL
[B6E4D6D468223F93632D870D842BD52B][1 16896
2636A4B90B97B439F2773B3A3D47C84BE00B8EEF ]C:\WINDOWS\SYSTEM32\TSBYUV.DLL
[C95805E5E690B0A8FF7E8200954FC5FE][1 998912
54B7CF60C4EECBEC2EF033731E7E8D7611179087 ]C:\WINDOWS\SYSTEM32\TSWORKSPACE.DLL
[E0A5C8E2CC38FDD77CB2D410FE1124DA][1 971264
7D11476E844BB516908882B54C1E7B2670F45969 ]C:\WINDOWS\SYSTEM32\TWINUI.APPCORE.DLL
[13781908186770ABE9F8EBCC2B45B138][1 95232
A79E7910A16B304ACD51E1DB69F9D58BA420516C ]C:\WINDOWS\SYSTEM32\TZAUTOUPDATE.DLL
[8578F83EC5175920F2D8586FFF9DCE47][1 42496
F8002418C55D585B3C477B94B9493C13BB3EE111 ]C:\WINDOWS\SYSTEM32\UI0DETECT.EXE
[7382BEEA88CC0631C1A9D7FAF102A745][1 181600
616811F42F3D004593E35D2C37450D7549369D68 ]C:\WINDOWS\SYSTEM32\ULIB.DLL
[FEA494AC3A1BAE63C1F2AF267D49F1DB][1 111104
044764DE4C1B0435107987952A469ECF42F3246B ]C:\WINDOWS\SYSTEM32\UMPNPMGR.DLL
[60C8376B48BA96F07AEA536527433D44][1 123904
4EBE274A3E70AC46BD9F58FFABAA4489B464AFA7 ]C:\WINDOWS\SYSTEM32\UMPO.DLL
[A960392B1B9D20CC6308896112CE3C82][1 273920
AB59FDD16C192F74E9721C97DEE5532F0BE9A517 ]C:\WINDOWS\SYSTEM32\UMRDP.DLL
[4B956444AF2A352366CF59C3A4A87C64][1 1184256
24BD3FA340C8930D62EF006297004FF039F81156 ]C:\WINDOWS\SYSTEM32\UNISTORE.DLL
[0CB6D7CC1881D055C54242D032B7C874][1 235008
4342548A7C8671188801F0FAF31F11E066F80924 ]C:\WINDOWS\SYSTEM32\UNREGMP2.EXE
[6CDA3536F6BAB7896A57EAB7DC07F379][1 440832
269F4A07682ECBBEBD12C46BBC23A2CECF9BBC51 ]C:\WINDOWS\SYSTEM32\UPNPHOST.DLL
[85B548343071325CAE75847E3E5DEE5D][1 324608
BA01680EBF3A3075FBF161B396769B16A2A10EC7 ]C:\WINDOWS\SYSTEM32\USBMON.DLL
[C72DFA81684D685A3C8532102BD10B74][1 14336
795EA929A24DD6AD1C546DAD2B1E32BE1CD5BD89 ]C:\WINDOWS\SYSTEM32\USBPERF.DLL
[BAB449E496892494C1E8152A25A1E867][1 1460696
A35CF87C22E33FA33D80D2AA7B052C831721CB87 ]C:\WINDOWS\SYSTEM32\USER32.DLL
[A39AFDD26E6F2E5595FF2D3997D7E1FE][1 1512448
86C8C91AE0DFDDDFB8D4969FA92C50233491254B ]
C:\WINDOWS\SYSTEM32\USERDATASERVICE.DLL
[5CFA1B3D6417449F98D040DEDBD14A4C][1 115744
CADEDDF6A4CFA44F3159859D63AD66F94C75CCB5 ]C:\WINDOWS\SYSTEM32\USERENV.DLL
[C1B1FFC800BE2F31EB2CF8CB40629C69][1 33280
F1B962CF2939030C15C91226D97B9EEB9649A04A ]C:\WINDOWS\SYSTEM32\USERINIT.EXE
[F8888D8CCECAA7B77CCAEABA901AB874][1 1021440
185D8C445928199175BFBFDE0A5A9B9FF241F992 ]C:\WINDOWS\SYSTEM32\USERMGR.DLL
[8B4B4A866956637DBED47D393C8B2350][1 549376
752865161078B372A0D6EF7D3B6A5005052A3D7B ]C:\WINDOWS\SYSTEM32\USOCORE.DLL
[41C2E66EDF2118CAF328ACA1D67055CE][1 358912
D6F73D4B90EE45BCF317DD8D5DC9EE357054F601 ]C:\WINDOWS\SYSTEM32\VAULTSVC.DLL
[70D165B3EA8BC576828DC2B964C8D116][1 649216
B680965BA75ABAB69DE567D5B93B605A0423F5B1 ]C:\WINDOWS\SYSTEM32\VDS.EXE
[DDA66AEF89DAC320A85AECCB4369D2E7][1 1443328
8681199E4730DB4D0A9FDC88DDCEC2AF6F3573E0 ]C:\WINDOWS\SYSTEM32\VSSVC.EXE
[76C1CC611352499326001F25A3ED15F8][1 520192
B4574DEAA95A36C71E0FCB5352EEA14D64B3AFCA ]C:\WINDOWS\SYSTEM32\W32TIME.DLL
[1483BE4D0135C378CB61D3CD73AB3E03][1 436224
6CB75F8544AEC7DBF5738E56AE18C1E74E865C23 ]C:\WINDOWS\SYSTEM32\WALLETSERVICE.DLL
[C2F7834269D565263C65757EDE37A66C][1 977920
E129B667EA76B1265C5D3DA891AF80A7AB8AC76F ]C:\WINDOWS\SYSTEM32\WBEM\FASTPROX.DLL
[31BAA1524D10843EA325743059B8334D][1 3584
3C803B9D54895F5C0779F66F21BAADE63D5CD44C ]C:\WINDOWS\SYSTEM32\WBEM\IPMIPRR.DLL
[A541A823601197A440C75A71FA5AA373][1 29696
BCDD9BA6FA7FADD12200B93F6DD0DCF47451FB13 ]C:\WINDOWS\SYSTEM32\WBEM\WINMGMTR.DLL
[3CDDFF6CAD962C5EF1C52FD667C358B6][1 203264
B430761A8E67CF55F72D20C403D98C4AC0141627 ]C:\WINDOWS\SYSTEM32\WBEM\WMIAPSRV.EXE
[D8E539426644A0F23CBF53DD0A5EE079][1 494080
5935A1978B114199079C01D48407894AF30C07DA ]C:\WINDOWS\SYSTEM32\WBEM\WMIPRVSE.EXE
[CD49CA8E3280ACEEC5ECF431A59F5EFD][1 222720
4E59C7CF6982FAFDE436F719780FFC5E3E828659 ]C:\WINDOWS\SYSTEM32\WBEM\WMISVC.DLL
[8413D292CD1B27D6B6127B90697F2B1C][1 1547264
1FFD7E392C973F1D056243F09F7740A8F6FCBDEC ]C:\WINDOWS\SYSTEM32\WBENGINE.EXE
[8C521D161445C3E1F38A494E7649E70D][1 837632
D853C5A516A2E3D73BE6EF5A14108052433A38F8 ]C:\WINDOWS\SYSTEM32\WBIOSRVC.DLL
[CA10C91D802ABE6E5136E2168C2CD2B4][1 715776
DE519F830E3F4090A1C612C0052F5466536E89CD ]C:\WINDOWS\SYSTEM32\WCMSVC.DLL
[D50645235A507B0546B1B5CF7D0B8849][1 468992
F93B8DD8FB0EB0CFCF5D86D0255B31B8D8E4508F ]C:\WINDOWS\SYSTEM32\WCNCSVC.DLL
[E7A7E8803E66B7CCED95D327A4DBC135][1 97792
07FE1E381F868E602A470905E54B0920D8578E7E ]C:\WINDOWS\SYSTEM32\WDI.DLL
[CA7112DF5736B6627F8E353E96071398][1 233472
0D5E481285A49D487F861804A0CE33CF29AF7677 ]C:\WINDOWS\SYSTEM32\WDMAUD.DRV
[3570C4E14F85CE0B537D126727ACA91C][1 227328
40F6868CC0C515CCDB1F37E425BF30A0D2860FEB ]C:\WINDOWS\SYSTEM32\WEBCLNT.DLL
[1785F9C96A0BDEC1F6E0C79EF412F342][1 206848
9598864DCFC1BF5B36C74145D2C1D1E2EE51EAD2 ]C:\WINDOWS\SYSTEM32\WECSVC.DLL
[B9175D63527B05131F2FA504CF0265F2][1 27648
103CD2364F4ACDC638B7AB00E0F9D9D99DB13960 ]C:\WINDOWS\SYSTEM32\WEPHOSTSVC.DLL
[9BD1998FF417055D13829165618373C9][1 684896
8508D86BD3E68827767F392E925380CAA5A99D32 ]C:\WINDOWS\SYSTEM32\WER.DLL
[162FDC2DCD4C3FD06FCA6BD1D11F4798][1 95232
9D444E9FFDC78FEC9AA50E80B98482E2010EDA19 ]C:\WINDOWS\SYSTEM32\WERCPLSUPPORT.DLL
[441C509DCDD8B095EC2342546BAF638F][1 156672
935CD1C80B967E1DC71F8A514967E2BD148FA154 ]C:\WINDOWS\SYSTEM32\WERSVC.DLL
[B154618505A6A9026EFA6AB8C4123BF1][1 82944
8CE186527BEE04653CEFC166537A1DD179ECC821 ]C:\WINDOWS\SYSTEM32\WIARPC.DLL
[505F32DE573ECEDF398DB9E2FC0D5E45][1 646656
627CC06DBAAC78B9E348E8F1BB4A72A41324FD11 ]C:\WINDOWS\SYSTEM32\WIASERVC.DLL
[B78E0A446015AC08986E38CFF9E43A42][1 834560
04000291EA58E3D6A8F0D4BCEBFFFAC5376A206F ]C:\WINDOWS\SYSTEM32\WIN32SPL.DLL
[0EB603B0B43F70608D8AC643C6DA6D47][1 407552
C051DC504E30130DF58F7C03D8C3A51E98B7A653 ]
C:\WINDOWS\SYSTEM32\WINDOWS.INTERNAL.MANAGEMENT.DLL
[CF3BDF9EAD8D3EF671E9339B44B185BA][1 161792
F8888E51359B96DEBF079FBFD3124EEEF83979A5 ]
C:\WINDOWS\SYSTEM32\WINDOWS.SHAREDPC.ACCOUNTMANAGER.DLL
[4E330AD1EED4A5D582EE415FD55953A2][1 4136448
D4407A0D77A418A97AD63D7622C9477D765EB625 ]
C:\WINDOWS\SYSTEM32\WINDOWS.STATEREPOSITORY.DLL
[0B26E253E4FB736309006BDF88400BBA][1 7213464
D9EFC68C1583971765E45534455F4D8B0C45AC3A ]
C:\WINDOWS\SYSTEM32\WINDOWS.STORAGE.DLL
[2B44C579773DEC3AD0D3F9F73E0D676D][1 817664
307B4789D52001B69491FEA29C2558BDA77B1F47 ]C:\WINDOWS\SYSTEM32\WINHTTP.DLL
[99A19C9A74E2F9820E501DCE77F84F70][1 304240
C710B6C67C34889571E797B7C8D73AEFB52C6002 ]C:\WINDOWS\SYSTEM32\WININIT.EXE
[CB440E1C4EC9C369EC9DD07B48A83F36][1 673792
5216DEC07642D8C2CC6EB105674DA2A8C2917F8F ]C:\WINDOWS\SYSTEM32\WINLOGON.EXE
[CBA1A726FF14C960845B61F787D0A2CB][1 3392000
0F39929531521B5E6BB961AAF8EA4078CFD3F18D ]C:\WINDOWS\SYSTEM32\WINSAT.EXE
[FE82F7FEAD7B319CF6501E01B6F56CF6][1 147456
40A6213CD3D067944DC3BBBB5F23E34778D9891C ]C:\WINDOWS\SYSTEM32\WINSRV.DLL
[33DBBCF71F68EA97D9FD34E4C9AB5AC6][1 283648
500F69F66D4940B26A522FEEB9B45002BA6026A5 ]C:\WINDOWS\SYSTEM32\WKSSVC.DLL
[C741858C36DBB08D868EAB3C7EAD87D3][1 2370048
B66BF705ACD938478663CCF807A87F95AEA17644 ]C:\WINDOWS\SYSTEM32\WLANSVC.DLL
[BBAB21FDBCA80743710062D8E3806286][1 2103808
C580D025B04DA149E9C82056B8191AF0A089802E ]C:\WINDOWS\SYSTEM32\WLIDSVC.DLL
[BAFDD52CE6D1DFF28FD8EF19064F4789][1 1837056
F12E297AD6BB32D794052BDFF004A283CDC7B070 ]C:\WINDOWS\SYSTEM32\WORKFOLDERSSVC.DLL
[9BBCB2C1CAC372FF6BA55CE56842A937][1 87552
9905E22D944CD58D5D2471B3DFA87BC63BB46B7C ]C:\WINDOWS\SYSTEM32\WPDBUSENUM.DLL
[C7C91FB86A3C6CD7619725A88ED1884C][1 74240
59672EB6618C82B2F8D6A80FF17809B440F38099 ]C:\WINDOWS\SYSTEM32\WPNUSERSERVICE.DLL
[9A0E0B836413EB0BC885532D2A5389D6][1 184832
8E2DE7A0B51955E19DCCE1B215164F95DBAC5D3C ]C:\WINDOWS\SYSTEM32\WSCSVC.DLL
[DC7A6A5F9CE7F1C825E11BC296447CC4][1 590848
791F5B3C0B88C6942601CAA72B82B8D6955F84C8 ]C:\WINDOWS\SYSTEM32\WSDMON.DLL
[252C60BDB56F0C99D511C6B284DF5F4E][1 40448
4CB023033DB60A76B5513E254275E945767C1F9C ]C:\WINDOWS\SYSTEM32\WSEPNO.DLL
[05B454451B82A20D925A727E5CAE4DD6][1 99840
9893C6A8E366EDB4181AAE8768CD4C6317ADC124 ]C:\WINDOWS\SYSTEM32\WSHEXT.DLL
[1EA1FD0332B21F11D424FD5114EA9F2F][1 2716672
95D52A094E6E018385EC6C004A006CFBA555ECA4 ]C:\WINDOWS\SYSTEM32\WSMSVC.DLL
[533CF910870330354DBFDECF0869E2E2][1 2321408
75A8DD4C2AC1118E1A3391AC7E68E41735D7FF47 ]C:\WINDOWS\SYSTEM32\WUAUENG.DLL
[47F6450F28BAA32B2AB0D6BE00996249][1 99840
FA8DDB047F1DAE481A82A67140488439AA5572BB ]C:\WINDOWS\SYSTEM32\WUDFSVC.DLL
[60448819208208629F2C5ED3882F8079][1 1282048
A7CE6122CDE0784E7D600C5C2AD06163B00CD159 ]C:\WINDOWS\SYSTEM32\WWANSVC.DLL
[7EF75102A793AAA6AAA45A4F7C15FF4D][1 1016320
69B3786E079CC14B5AC5283F20D64B207E7A41BC ]C:\WINDOWS\SYSTEM32\XBLAUTHMANAGER.DLL
[9A3F176A793C68961774A79457F59ADC][1 1159680
5E4843BDAA0BE4394A2EA81BA678C852752F3BA2 ]C:\WINDOWS\SYSTEM32\XBLGAMESAVE.DLL
[1A8D9EA4DD1A3E276B85EDB05B42BEC7][1 1025536
30EDC64A3FDDAFFB63BA4C458D39519519E4B4B1 ]C:\WINDOWS\SYSTEM32\XBOXNETAPISVC.DLL
[F4C2BEF4F33E5CD160EDBDBA4800B5B0][1 449536
5B803655D8729157CEB57825DF881F9FB2F8A3B0 ]C:\WINDOWS\SYSTEM32\XWIZARDS.DLL
[EBC4935445CA5A3D4D898076642EC618][1 10652512
95DF6ACB41F279BE84F4FD68D79EF508F5AFD0A9 ]
C:\WINDOWS\SYSTEMAPPS\MICROSOFT.WINDOWS.CORTANA_CW5N1H2TXYEWY\SEARCHUI.EXE
[7850D58EE55539B703EA883D375D2D70][1 1653600
8146F07FFF4A249772C93E3EAA5CCE180F9A1A88 ]
C:\WINDOWS\SYSTEMAPPS\SHELLEXPERIENCEHOST_CW5N1H2TXYEWY\SHELLEXPERIENCEHOST.EXE
[5B3B4FBBACE6A551A7A23F2A97A708EE][1 731136
969846CD7DC87B05BF10C3288D3DEDB4341AA4AF ]C:\WINDOWS\SYSWOW64\D3D8.DLL
[C1A05F68C92A8B9D4D5A3D4953427154][1 497424
F17B99CCD0D9497BED62C98A8BCD025C8F59DD2E ]C:\WINDOWS\SYSWOW64\DNSAPI.DLL
[5CC081B65046E5DE37DCDD1C0AB99FE4][1 86528
72EABB5B7B965186C18FBAAB6B0B0C6BD589AEE4 ]C:\WINDOWS\SYSWOW64\ICCVID.DLL
[9E24D897754566125D3303B820122366][1 12204032
99535807728E3EE856B6960CC08146514BB0F9A1 ]C:\WINDOWS\SYSWOW64\IEFRAME.DLL
[C165A15FF793D822EB28D6FFC088092C][1 884224
4C21094F982C1713E2A611E180D45171E265F3A8 ]C:\WINDOWS\SYSWOW64\INETCOMM.DLL
[E49BF2E02840BF204F4A7F9EA60FF2EC][1 301536
6D29FED89D681274D345635FC853BC94F5AEC97C ]C:\WINDOWS\SYSWOW64\INTELCPHECISVC.EXE
[D872C2EB274CACF5E3CEC4932355DB2B][1 151552
A4FD818AE072E4A588B97CEE9570D7A56EB27591 ]C:\WINDOWS\SYSWOW64\ITSS.DLL
[5A762B4157DE7E1A035897CE30B46708][1 73728
E181513A38FAE8CE9E05C434F24617BD973122BA ]C:\WINDOWS\SYSWOW64\L3CODECA.ACM
[21952ADDD6E80648E97BDCAE4A231A2B][1 19414016
4A468FEC6B6F6C19081111326930CA8C1DD7CA11 ]C:\WINDOWS\SYSWOW64\MSHTML.DLL
[9618E4752B19CE24EFD729C662C8DB1E][1 1386496
E2FC41553E1F85472E3E4C6B20DEA5430E500EF7 ]C:\WINDOWS\SYSWOW64\MSVBVM60.DLL
[AC1E3E0991DFA564BE304F569B01D3F2][1 2356736
7897EE69275CB13B4AE64FB7B53E482CFFBB4ED6 ]C:\WINDOWS\SYSWOW64\MSVIDCTL.DLL
[8E6958813B6FAAFF8A6EE9F2A7040299][1 306016
B3779607005B048717C7C55B380099338F598F63 ]C:\WINDOWS\SYSWOW64\MSWSOCK.DLL
[390E89B590BF63EEBF88ABC15078A198][1 55808
72D593D0A5A49C3267ADEDE7DFDE25CECCDEA49D ]C:\WINDOWS\SYSWOW64\NAPINSP.DLL
[A8C6FCB5A946AB8A9553F43529DFDA9A][1 65024
12FAE57FDA826B82F698CE85CEE2C8CDAB4612D6 ]C:\WINDOWS\SYSWOW64\NLAAPI.DLL
[5AC0EC99D9BC23FE97E8F8851DDB660C][1 90624
194DC754731E4E0CB21841883F3292E082B0A5F8 ]C:\WINDOWS\SYSWOW64\OLEPRO32.DLL
[CB5343FF52A702A9ACFAAE6BE972FE09][1 21504
CCF8044181971DDA200CD90F040F6937F555DD75 ]C:\WINDOWS\SYSWOW64\PERFHOST.EXE
[3F0F179C20F3633D2EC06774430BA831][1 70656
5F1A5DFF9EAB035C922D8CACEE8F6F9AABD1C7B8 ]C:\WINDOWS\SYSWOW64\PNRPNSP.DLL
[6EDB3C97D8D015F04A2C61CD31DCB057][1 30208
80E50121CC760DD494B4F761771C5D183CBE371E ]C:\WINDOWS\SYSWOW64\TBAUTH.DLL
[EDA94BE1F9E05B9C125484FB5EDD0E3A][1 1599488
70E61C398FE2F064BF1B0A2763A2364F6E00026E ]C:\WINDOWS\SYSWOW64\URLMON.DLL
[6B408458867BF3B61F363C0EB423F87F][1 24064
2130EDE65881706480E618914CFDDE90474D20BD ]C:\WINDOWS\SYSWOW64\WINRNR.DLL
[453C23668FD9F3B8720379AD2B0EA5CF][1 51712
938F45E104909F5531A5416E037D8ABC42EA9AEE ]C:\WINDOWS\SYSWOW64\WSHBTH.DLL
[A06EC8D96CAFDA2FFEB9B8552099BBA7][1 1236680
0E3B04FF6131CB099E1CAF9A55BB4278D2A22E3B ]
C:\WINDOWS10UPGRADE\WINDOWS10UPGRADERAPP.EXE
[ -2][0 -1
]VP8VFW.DLL
[ -2][0 -1
]XVIDVFW.DLL
===
[MBR]
[MD5=004BC502E8A0AB7DDDB5C2C67E1CDFEE]
M8CO0LwAfI7Ajti+AHy/AAa5AAL886RQaBwGy/u5BAC9vgeAfgAAfAsPhQ4Bg8UQ4vHNGIhW
AFXGRhEFxkYQALRBu6pVzRNdcg+B+1WqdQn3wQEAdAP+RhBmYIB+EAB0JmZoAAAAAGb/dgho
AABoAHxoAQBoEAC0QopWAIv0zROfg8QQnusUuAECuwB8ilYAinYBik4Cim4DzRNmYXMc/k4R
dQyAfgCAD4SKALKA64RVMuSKVgDNE13rnoE+/n1VqnVu/3YA6I0AdRf6sNHmZOiDALDf5mDo
fACw/+Zk6HUA+7gAu80aZiPAdTtmgftUQ1BBdTKB+QIBcixmaAe7AABmaAACAABmaAgAAABm
U2ZTZlVmaAAAAABmaAB8AABmYWgAAAfNGloy9uoAfAAAzRigtwfrCKC2B+sDoLUHMuQFAAeL
8Kw8AHQJuwcAtA7NEOvy9Ov9K8nkZOsAJALg+CQCw0ludmFsaWQgcGFydGl0aW9uIHRhYmxl
AEVycm9yIGxvYWRpbmcgb3BlcmF0aW5nIHN5c3RlbQBNaXNzaW5nIG9wZXJhdGluZyBzeXN0
ZW0AAABje5o=
===
[PT]
A 0x7 NTFS, 2048, 1024000
0x7 NTFS, 1026048, 203776000
0x7 NTFS, 204802048, 386930688
0x7 NTFS, 591732736, 385024000
===
[VBR]
61KQTlRGUyAgICAAAggAAAAAAAAA+AAAPwD/AAAIAAAAAAAAgACAAP+fDwAAAAAABTMAAAAA
AAACAAAAAAAAAPYAAAABAAAA6qozkNwzkCwAAAAA+jPAjtC8AHz7aMAHHx5oZgDLiBYOAGaB
PgMATlRGU3UVtEG7qlXNE3IMgftVqnUG98EBAHUD6d0AHoPsGGgaALRIihYOAIv0Fh/NE5+D
xBieWB9y4TsGCwB126MPAMEuDwAEHloz27kAICvIZv8GEQADFg8AjsL/BhYA6EsAK8h377gA
u80aZiPAdS1mgftUQ1BBdSSB+QIBch4WaAe7FmhSERZoCQBmU2ZTZlUWFhZouAFmYQ4HzRoz
wL8KE7n2DPzzqun+AZCQZmAeBmahEQBmAwYcAB5maAAAAABmUAZTaAEAaBAAtEKKFg4AFh+L
9M0TZllbWmZZZlkfD4IWAGb/BhEAAxYPAI7C/w4WAHW8Bx9mYcOh9gHoCQCh+gHoAwD06/2L
8Kw8AHQJtA67BwDNEOvyww0KQSBkaXNrIHJlYWQgZXJyb3Igb2NjdXJyZWQADQpCT09UTUdS
IGlzIGNvbXByZXNzZWQADQpQcmVzcyBDdHJsK0FsdCtEZWwgdG8gcmVzdGFydA0KAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAIoBpwG/AQAAVaoHAEIATwBPAFQATQBHAFIABAAkAEkAMwAwAADU
AAAAJAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAOnAAJAFAE4AVABMAEQAUgAHAEIATwBPAFQAVABHAFQABwBCAE8ATwBUAE4AWABUAAAA
AAAAAAAAAAAAAAAAAAAAAAAADQpBbiBvcGVyYXRpbmcgc3lzdGVtIHdhc24ndCBmb3VuZC4g
VHJ5IGRpc2Nvbm5lY3RpbmcgYW55IGRyaXZlcyB0aGF0IGRvbid0DQpjb250YWluIGFuIG9w
ZXJhdGluZyBzeXN0ZW0uAAAAAAAAAAAAAAAAAAAAAAAAAACaAmYPtwYLAGYPth4NAGb342aj
UgJmiw5AAID5AA+PDgD22Wa4AQAAAGbT4OsIkGahUgJm9+Fmo4YCZg+3HgsAZjPSZvfzZqNW
AuiiBGaLDk4CZokOJgJmAw6GAmaJDioCZgMOhgJmiQ4uAmYDDoYCZokOPgJmAw6GAmaJDkYC
ZriQAAAAZosOJgLokAlmC8APhL/9ZqMyAma4oAAAAGaLDioC6HcJZqM2Ama4sAAAAGaLDi4C
6GUJZqM6AmahMgJmC8APhIz9Z4B4CAAPhYP9Z2aNUBBnA0IEZ2YPtkgMZokOkgJnZotICGaJ
Do4CZqGOAmYPtw4LAGYz0mb38WajlgJmoUYCZgMGjgJmo0oCZoM+NgIAD4QdAGaDPjoCAA+E
MP1mix46Ah4HZos+SgJmoS4C6O0B6CwNZgvAD4QDAOhCDmYPtw4AAma4AgIAAOgiCGYLwA+F
FgBmD7cOWgJmuFwCAADoDAhmC8APhHgOZ2aLAB4HZos+PgLoPwZmoT4CZrsgAAAAZrkAAAAA
ZroAAAAA6OQAZoXAD4UjAGahPgJmu4AAAABmuQAAAABmugAAAADoxABmC8APhUQA6ScOZjPS
ZrmAAAAAZqE+AujKCGYLwA+EEA4eB2aLPj4C6NsFZqE+Ama7gAAAAGa5AAAAAGa6AAAAAOiA
AGYLwA+E5g1nZg+3WAxmgeP/AAAAD4XbDWaL2GgAIAdmK/9moT4C6AABaAAgB2Yr/2ahPgLo
rAqKFg4AuOgDjsCNNgsAK8BoACBQywYeZmBmi9pmD7YODQBm9+FmoxEAZovDZvfhoxYAi9+D
4w+MwGbB7wQDx1AH6JL7ZmGQHwfDZwNAFGdmgzj/D4RMAGdmORgPhTMAZgvJD4UKAGeAeAkA
D4UjAMNnOkgJD4UaAGaL8GcDcArolwZmUR4HZov686dmWQ+FAQDDZ2aDeAQAD4QHAGdmA0AE
66tmK8DDZovz6GwGZ2YDAGf3QAwCAA+FNABnZo1QEGc6SkAPhRgAZ2aNckLoSQZmUR4HZov7
86dmWQ+FAQDDZ4N4CAAPhAYAZwNACOvCZjPAw2eAewgAD4UcAAYeZmBnZo1TEGdmiwpmi/Nn
A3IE86RmYZAfB8NmUGdmjVMQZoXAD4UKAGdmi0oIZkHrEZBnZotCGGYz0mb3NlICZovIZivA
Zl7oAQDDBh5mYGeAewgBD4QDAOnK+maD+QAPhQYAZmGQHwfDZlNmUGZRZlZmVwbokQRmi9EH
Zl9mXmZZZoXAD4Q0AGY7yg+NAwBmi9Hogv5mK8pmi9pmi8JmD7YWDQBm9+JmD7cWCwBm9+Jm
A/hmWGYDw2Zb659mhfYPhGL6ZlFmVwZnZg+2QwlmhcAPhCAAZtHgZivgZov8ZlRmVmdmD7dz
CmYD82aLyPOkZl7rA5BmUGZQZ2aLA2ZQZ2aLQxhmUGdmi1YgZoXSD4QLAGaL/h4HZovC6HED
ZovGZlpmWWZCZlFmVug/BmaFwA+E8flmXmZZZov+HgfoTgNmi8Zmi9lmWWZaZlFmVmbR6ej4
/WaFwA+EyvlmXmZZZgPhB2ZfZllmi9BmWGZbZova6fX+Bh5mYCZnZg+3XwQmZ2YPt08GZgvJ
D4SY+WYD32aDwwJmgcf+AQAAZklmC8kPhBcAJmeLAyZniQdmg8MCZoHHAAIAAGZJ6+JmYZAf
B8MGHmZgZrgBAAAAZqMiAmahHgJmAwaGAmajigJmAwaGAmajTgJmoTAAZg+2Hg0AZvfjZose
TgJmiQdmoxEAg8MEZqFWAmaJB6MWAIPDBGaJHk4CZoseHgIeB+i7+GaL++hR/2ahHgJmuyAA
AABmuQAAAABmugAAAADoEP1mC8APhBkBZovYHgdmiz4aAmYzwOii/WaLHhoCZoE/gAAAAA+E
6wADXwTr8GZTZotHEGb3JlYCZlBmM9JmD7YeDQBm9/NmUujcAGYLwA+EmPhmiw5WAmYPth4N
AGb342ZaZgPCZoseTgJmiQeDwwRmD7YGDQBmK8JmO8EPhgMAZovBZokHZivIZloPhHUAZgPC
ZlBmM9JmD7YeDQBm9/NmUeiCAGZZZgvAD4Q8+GYPth4NAGb342aLHk4CZosXg8MEZgMXZjvQ
D4UVAGYPtgYNAGY7wQ+GAwBmi8FmAQfrpYPDBGaJHk4CZokHg8MEZg+2Bg0AZjvBD4YDAGaL
wWaJB+uCg8MEZv8GIgJmiR5OAmZbA18EZoE/gAAAAA+EDP9mYZAfB8Nmi9Bmiw4iAmaLNooC
ZgM2hgJmUmZRZlJmix6KAmaLPlYCZosEZqMRAIPGBGaLBKMWAIPGBB4H6Dz3Ziv4D4QIAPcm
CwAD2OvZZos+igIeB+i//WahigJmu4AAAABmuQAAAABmi9HogftmC8APhFP3ZovYZlhmVugs
AWZeZgvAD4QFAGZbZlvDZllmWuKEZjPAwwYeZmBmUGZRZjPSZg+2Hg0AZvfzZlJmV+hT/2Zf
ZgvAD4QN92YPth4NAGb342ZaZgPCZqMRAGZZZg+2Hg0AZjvLD44TAIkeFgBmK8tmWGYDw2ZQ
ZlHrFJBmWGYDwWZQiQ4WAGa5AAAAAGZRBmZXi9+D4w+MwGbB7wQDx1AH6GT2Zl8HZgM+UgJm
WWZYZoP5AA+PcP9mYZAfB8MGHmZgZvcmVgJmiw5WAuhV/+jS/GZhkB8HwwYeZmBm9yaSAmaL
HjYCZosOkgJmizYqAh4HZos+RgLogfvop/xmYZAfB8NmUGZTZlFmix5KAmaLyGbB6ANmg+EH
ZgPYZrgBAAAAZtPgZ4QDD4QEAPjrApD5ZllmW2ZYw2eAewgBD4QEAGYrwMNnZo1zEGdmi1YI
ZjvCD4cLAGdmixZmO8IPgwQAZivAw2cDXhBmK/ZngDsAD4Q+AOiBAGYD8eg5AGYDymY7wQ+M
IQBmi9FmUGdmD7YLZovBZoPgD2bB6QRmA9lmA9hmQ2ZY68RmK8hmK8JmA8bDZivAw2YryWeK
C4DhD2aD+QAPhQQAZivJw2ZTZlJmA9lnZg++E2ZJZktmg/kAD4QNAGbB4ghnihNmS2ZJ6+tm
i8pmWmZbw2ZTZlJmK9JnihNmg+IPZivJZ4oLwOkEZoP5AA+FCABmK8lmWmZbw2YD2mYD2Wdm
D74TZklmS2aD+QAPhA0AZsHiCGeKE2ZLZknr62aLymZaZlvDZgvJD4UBAMNmUWZWZ4M+YQ+M
DABngz56D48EAGeDLiBmg8YC4uZmXmZZw2ZQZlFmi9BmoTICZ2aNWBBnA0MEZ2aNQBBmi9ro
RPlmC8APhAUAZllmWcNmoTYCZgvAD4UIAGZZZllmM8DDZosWNgJnZo1SEGdmi0IYZjPSZvc2
jgJmM/ZmUGZWZlhmXmY7xg+EOgBmVmZAZlBmSOgb/nLo6Ov9ZlpmXmZZZltmU2ZRZlZmUmah
RgJnZo1AGOjQ+GYLwHTEZllmWWZZZlnDZllmWWYzwMNmUWZQZrgFAAAAHgdmi/nojf1mi8Fm
uyAAAABmuQAAAABmugAAAADoM/hmW2ZZZoXAD4UVAGaLwWYPtw4QAma6EgIAAOgW+OszkGYz
0maLwWaLy2ZQZlPoIwBmW2ZfZgvAD4QXAB4H6DX9ZovHZg+3DhACZroSAgAA6OH3w2ZSZlFm
uyAAAABmuQAAAABmugAAAADox/dmC8APhGMAZovYHgdmiz4aAmYzwOhZ+B4HZoseGgJmWWZa
JmY5Dw+FDAAmZjlXCA+EMQDrE5AmZoM//w+ELwAmg38EAA+EJgAmZg+3RwQD2IvDJQCAdMuM
wAUACI7AgeP/f+u+JmaLRxDDZllmWmYzwMNmUGZRZovHZsHoBAZZA8hRB2aD5w9mWWZYw2AG
vmkOvwAgHge5DQCQ86UHYcMBI0VniavN7/7cuph2VDIQ8OHSwwAAAAAgIGCLNhggJooFiARH
Rmb/BhQggf5gIHUG6FsAviAg4uaJNhggYcNmYIs2GCCwgIgERjLAgf5gIHUG6DoAviAggf5Y
IHXpZjPAZqNYIGahFCBmweADZg/IZqNcIOgYALsAIGaLB2YPyGaJB4PDBIH7NCB17mZhw2Zg
uyAgZosHZg/IZokHg8MEgftgIHXuuwAgZosPZotXBGaLdwhmi38MZotvELsgIMcGGiDcD8YG
HCAUkFOLHhog/xdmA0cCW2YD6GYDL2aLwWbBwAVmA8Vmi+9mi/5mi/JmwcYeZovRZovIZosH
ZjNHCGYzRyBmM0c0ZtHAZolHQIPDBP4OHCB1soMGGiAGgT4aIPQPdZ+7ACBmAQ9mAVcEZgF3
CGYBfwxmAW8QZmHDZovGZjPHZiPCZjPHw2aLwmYzxmYzx8NmU2aLwmYjxmaL2mYj32YLw2aL
3mYj32YLw2Zbw6gPmXmCWrUPoevZbr8P3Lwbj7UP1sFiygYeZmBmM9u4ALvNGmYjwA+FuwBm
gftUQ1BBD4WwAIH5AgEPgqgAZmGQHwcGHmZgZ4B7CAAPhQwAZ2aNUxBnZosK6yWQZ2aNUxBn
ZotKKGaB+QAACAAPgwwAZ2aLQixmI8APhAMAZjPJDh/o9f1mI8kPhDIAZroAgAAAZjvKD4Yf
AGYrygZmUWZXZlJmi8rot/3o+/1mWmZfZlkHZgP669ropf3o6f3oC/4OB2a7VENQQWa/ACAA
AGa5FAAAAGa4B7sAAGa6CgAAAGYz9s0aZmGQHwfDBh5mYGYz27gAu80aZiPAD4V0AGaB+1RD
UEEPhWkAgfkCAQ+CYQBmuAe7AABmu1RDUEFmubgBAABmugQAAABmM/Zmvk1CUkNoAAAHZr8A
fAAAzRpmuAe7AABmu1RDUEFmuUIAAABmugUAAABmM/Zmvk1CUkRoAAAHZr8AfAAAZoHHvgEA
AM0aZmGQHwfDZlJmM8BngHsIAA+FDABnZo1TEGdmiwLrC5BnZo1TEGdmi0IoZlrDBh5mYGYP
tw5mAma4aAIAAOj8+mYLwA+E+gBmD7cOdgJmuHgCAADo5vpmC8APhOQAZ2aLAB4HZos+PgLo
GflmoT4CZrsgAAAAZrkAAAAAZroAAAAA6L7zZoXAD4UjAGahPgJmu4AAAABmuQAAAABmugAA
AADonvNmC8APhUQA6ZMAZjPS
===
[STAT]u\\VVRSSUFMLTMw
[SIGN]
[726798E8D852FC48746850E3B1FB1066] MICROSOFT CORPORATION
[4861404A4249372CD2D528A9F2056D0B] MICROSOFT CORPORATION
[4BB1A5813F35E391044A9694060AC0E8] MICROSOFT CORPORATION
[FC8EC7040A6BC0150F194440C75B3E39] MICROSOFT CORPORATION
[34ACE6E837F846CF72AA2D445C0C6E2D] MICROSOFT CORPORATION
[B3810DE6BBED550B7F503A75681C7FBA] MICROSOFT CORPORATION
[5AA237EAF522154183AB8E95F2099827] ADOBE SYSTEMS, INCORPORATED
[47C77C53C41E3797046A04AFB6468ABE] ASUSTEK COMPUTER INC.
[0F5EF3F836D2E449FE01FCAF17DBD9CF] ASUSTEK COMPUTER INC.
[3363222F80843B2F180C38DAB2D925C4] ASUSTEK COMPUTER INC.
[EEAC360113AFCC4EA16A7372212235C6] ASUSTEK COMPUTER INC.
[564CB886D1A968B9798C1AB03F4EB54F] ASUSTEK COMPUTER INC.
[D248FB4E0D6C4EBABB1593A35353D16B] ASUSTEK COMPUTER INC.
[F19CAC58C0DF486984D446FB52A3A8DA] ASUSTEK COMPUTER INC.
[FDC95B0F0D94CB62954C56EA6E1CC179] ASUSTEK COMPUTER INC.
[C435191FAD19B43E5C3082E4275DCE75] ASUSTEK COMPUTER INC.
[DBC598E47E7A382E60E2A4745D41FEF9] ASUSTEK COMPUTER INC.
[360D693A81527213D30D45676C3477E1] ASUSTEK COMPUTER INC.
[8C4AC22616E77925135C221C46DC6307] ADOBE SYSTEMS, INCORPORATED
[47C1DE0A890613FFCFF1D67648EEDF90] ADOBE SYSTEMS, INCORPORATED
[11A52CF7B265631DEEB24C6149309EFF] ADOBE SYSTEMS, INCORPORATED
[86F0D0B3A07C142C81DAB47E8495A822] Nero AG
[A328A46D87BB92CE4D8A4528E9D84787] Nero AG
[FFBD5650348D4F9E0AA8E72938DC6478] Nero AG
[7DE2E1AB0B5DA45A136FD7499B4C64C7] MICROSOFT CORPORATION
[0B3EEAD619B72692ECEEC2D05E1FE2C4] MICROSOFT CORPORATION
[792400B8F2DD55C943BCB18EE6002AE9] MICROSOFT WINDOWS
[DCBE32AE2E460CDFC667BD8E2DFE76BE] MICROSOFT CORPORATION
[1BA584DEEC9A600A4697522E1D2F1E9A] MICROSOFT CORPORATION
[2B8E4C792BED0E5882702720BC528AE5] MICROSOFT CORPORATION
[DA2E580E51232D5C81989B1A2FD9CF47] MICROSOFT CORPORATION
[174D2EB772E843B6175EED45D8FA11E7] Sonic Solutions
[9555982C980B760398C09EEFAE6FCF01] Sonic Solutions
[09132A1DA77EF78D06421C871B3B92C5] Sonic Solutions
[B248A451721CF86A6CDBA18B379EC80C] Sonic Solutions
[51598A4CD5BFC25C8D4FB1A740A43583] Sonic Solutions
[B36F01A58631341310C6D4116F2EDF5F] Sonic Solutions
[D4BFF8B48CD9A212B45C425F2A1C9B77] Sonic Solutions
[5420BAFE4BEFBC64452DEE6AF8782A20] Sonic Solutions
[DFC64F80CBC171FB0631E7F15D79C998] Sonic Solutions
[23C98662461CA549487676E3E4E16C4F] Sonic Solutions
[0181815874F0D68BCE2FF4DB1655DC04] MICROSOFT WINDOWS
[C71925849D278D7E9415C1C4B373F3AB] MICROSOFT WINDOWS
[E9B4B2FE508E5F1995665BF170977C7C] MICROSOFT WINDOWS
[A1741C3B79F9DF8895E05EF43579E74B] CyberLink
[08053E610C778572920DD52E4CAB4BAA] GRETECH
[50C2E62660C7C1D26C60D320CC61F8A6] Tonec Inc.
[B06190AF451B2037FF075AEB5D21E26F] Tonec Inc.
[C75F3BF8FAABBA3EED8FEE27256C6E46] Tonec Inc.
[A4B9EB733D753DD8D700B47551AA6B00] Tonec Inc.
[01188C6E88C451ADA0FF2715F882F730] Tonec Inc.
[85D34E4F4EB601666C411645731E2BBF] Tonec Inc.
[36B618F848D6DDA620BF0B151EACF02D] Tonec Inc.
[FE82C6F8416FB9645B6DBAD037AC5479] Tonec Inc.
[2ECBD0616A07D7B0DA79CA0BD8B9AFB6] Tonec Inc.
[B0DB7C748AF3EF055447DB522239BC68] MICROSOFT WINDOWS
[91C3863162B85B564D0F76B7D2C49AE6] MICROSOFT WINDOWS
[4459AAD5DA99EF5BF12D18D1FA0D1EC0] MICROSOFT WINDOWS
[6A1337363C6EA5851302C928E05AE60D] MICROSOFT WINDOWS
[A4F0806BDBA10FE2F16302928C428F99] MICROSOFT WINDOWS
[27D8231B9DA1B46F9D3FA238A096A24D] MICROSOFT WINDOWS
[E567AEE9682F4DBE9251C68EFB5E00E1] MICROSOFT WINDOWS
[F2E0B22B58F90CE86621C9B53D5C6B8D] Shenzhen Wondershare Information Technology
Co., Ltd.
[7D3453A5641CB146EB5F19B176AC9929] MICROSOFT CORPORATION
[C6472164E8467E73857E6FA4EB31D4EF] MICROSOFT CORPORATION
[436FF18AB0E57A8D6A7EB2C9BD477291] MICROSOFT CORPORATION
[80FF9262DF9370D120EEB52508249E5A] MICROSOFT CORPORATION
[ED43CEF838A79C09A88DC43E26D1B60C] MOZILLA CORPORATION
[3381F3FA4AEEF9F737FE934227F837E9] MOZILLA CORPORATION
[F4604E259459F5A0D5BE6914A6D4C5FB] MICROSOFT CORPORATION
[E205DE17A85B0C3352A6857EF9B3C6DD] MICROSOFT CORPORATION
[405BB6A7CD56CBF5276C3A8DC631963D] MICROSOFT CORPORATION
[9A4FC3727AAF02C3285B47DF5EE56244] MICROSOFT CORPORATION
[6B937FE1EFF0E440B124BBB9334DF34D] MICROSOFT CORPORATION
[EA4AE42721460002DC31515F295AD1C4] MICROSOFT CORPORATION
[AD895B2A99A3EC18F1690BBAC1E2037A] MICROSOFT CORPORATION
[0A0084D4B3635E4D8EBAB587DCFCC16C] MICROSOFT CORPORATION
[52FFABA4273678BAE75442F2BC85B470] MOZILLA CORPORATION
[363D3B5EE2B394089A7CEEEE6A74A263] MOZILLA CORPORATION
[B498A14133BD09AD0817590ACE4470AD] Nero AG
[57B941BC9AF99E03ECC1E2BEF753782A] Nero AG
[B08BE238F67339373207C29E12EDDF4C] Nero AG
[7F471D168B27E4FD7005F42D5449BDD6] Nero AG
[55835DA201C86563BA49F045A90ABB3D] Nero AG
[99BF09D43D2963F8EC0F830C4B6A6286] NVIDIA CORPORATION
[D0141DBF9B2E3AB0A326CE05194CC28D] HUAWEI TECHNOLOGIES CO., LTD.
[66AAE701A787E4BDF73116B79274DC86] HUAWEI TECHNOLOGIES CO., LTD.
[3A4072C8D36CEF6A82D4221C56DDDD74] GREATIS SOFTWARE LLC
[8B4BA6F39B9E07D553704CD0F1DBA46B] GREATIS SOFTWARE LLC
[FD7732EB1925A06AE2B38A1C3D05CBD5] GREATIS SOFTWARE LLC
[333961BB8AB2055AF0D69A3D812D1D21] GREATIS SOFTWARE LLC
[764374A75D93A06CD36A818A2F2A7E45] GREATIS SOFTWARE LLC
[717CAD2011E934039AB977D863914190] Greatis Software LLC
[015E878DFF62E4E77A81A39D64FDA529] GREATIS SOFTWARE LLC
[A9DE7FF6141FABC0C6677E571F3BD9A1] Winamp
[E77899573470873FD7B9B0E717794886] Winamp
[95A97A8A9DD7E4FA1EBC2FBE7B039C47] MICROSOFT WINDOWS
[3BAA8E3BAC846451DFADB48C18FB8E4D] MICROSOFT WINDOWS
[64C468F111B9DEB401A4336B6366DEA6] MICROSOFT WINDOWS
[2CAB4EA393A5B893CDDACB595A930A5B] MICROSOFT WINDOWS
[44300EB58F3E2271F3B271E9843E5589] MICROSOFT WINDOWS
[FC88FE6E28CA6973819E25A13630A59A] MICROSOFT WINDOWS
[A7ECC7A0FADDADF34ED063B8C7BDB0D2] MICROSOFT WINDOWS
[15EEBFECC6A3B6A8352CD90B3E24736F] MICROSOFT WINDOWS
[16C8EC7D893F88A06EAEF45DB75CBE64] MICROSOFT WINDOWS
[2781E6EF593909A8B73FE1AD397F778A] MICROSOFT WINDOWS
[D926F5805CCE007EDCAA57E165C2D14B] MICROSOFT WINDOWS
[20F8EC18219B9A6043C4EA46F6D015FB] MICROSOFT WINDOWS
[EE82204845B5CA903A82F3D88EF1D8A7] MICROSOFT WINDOWS
[C03B3489E0B6DDE2EA794BE1ADF3045D] MICROSOFT WINDOWS
[C4B56C14C70B324FCF50AA857733A0B0] MICROSOFT WINDOWS
[08D16561E6724637D887F451A896F7F0] MICROSOFT WINDOWS
[ADB4E49FA88CFE2D6CD1AB0C798114E8] MICROSOFT WINDOWS
[B1419B38FBD14C65CB73D26D5577BD99] MICROSOFT WINDOWS
[AC4E70ECF1F6A0B4372954EB655ADB03] MICROSOFT WINDOWS
[523CCD263FE87516AF05886E4CE80D1E] MICROSOFT WINDOWS
[8BFE40DA68F6F2CF6542C9A97859F0EB] MICROSOFT WINDOWS
[522CE924B8FAE4DF3E888350BA45747D] MICROSOFT WINDOWS
[DAD2758A806A22B9EC1956218C040741] MICROSOFT WINDOWS
[0742F93AE13FC5AEAB07AC268FDB82F1] MICROSOFT WINDOWS
[F831AA40EECB5821EFA15916996BC72C] MICROSOFT WINDOWS
[D5EAA06A5CEE340672E5665B7793EC64] MICROSOFT WINDOWS
[A674491AF23EF2D9D8044D02144DE909] MICROSOFT WINDOWS
[470F753937B2BC3EF76EE5F6FB66BB94] MICROSOFT WINDOWS
[0576C439AE1BFD6B2048D5CD2DD4B509] MICROSOFT WINDOWS
[01A7F0EB0FA2E15BE8F6B84316F95DA3] MICROSOFT WINDOWS
[9BE821EB9BD18ED241A926B5DDAC6D18] MICROSOFT WINDOWS
[547020D1093BAFD405855F065560C901] MICROSOFT WINDOWS
[AEC841B454F9B7EDEB2E719F6B19D5ED] MICROSOFT WINDOWS
[2B328FEB08F104F1973C230D6C25356E] MICROSOFT WINDOWS
[F4A0FA76204E19468465F1164631AA77] MICROSOFT WINDOWS
[6A874F47AC63B6B909CBFD1D79527A29] PassMark Software Pty Ltd
[635B37E964C3454BA38D669C7521B627] MICROSOFT CORPORATION
[3C7CF966C13F5081A05CAAED5304950C] NVIDIA CORPORATION
[EF5ADA88F01635A0F8CE5222CEEBC2D2] NVIDIA CORPORATION
[CC4A5098095A918FD0E6BE01EE07646A] Plumbytes Software Lp
[6F820B6B9A6649AFE84D9F2C72B7BA37] Plumbytes Software Lp
[BEA7C958B57607ACEDA85C515D8F1936] MICROSOFT CORPORATION
[501EE9F49000480AE903FE4B9C620551] MICROSOFT CORPORATION
[E0DC497C2B77E24418A9DD06E4E127F8] MICROSOFT WINDOWS
[39D76F7C72B5C41089C8FD7BB8F44417] MICROSOFT WINDOWS
[F74D9F48969D1EAEC92773972C7277AD] MICROSOFT WINDOWS
[3CE78583DF803541F907DEA625F24DBC] MICROSOFT WINDOWS
[D9DA25006DF709013818EF18D8CC6257] MICROSOFT WINDOWS
[B3A583725D3DF22C65241FCF7820312C] MICROSOFT WINDOWS
[83EDE17A1087F8D5779A6C023B5B490A] MICROSOFT WINDOWS
[E351D93D81B404C4264A3B892CDE5F63] MICROSOFT WINDOWS
[39E4335CEE44BC72B051D507A96C6D3C] MICROSOFT WINDOWS
[8778AB3D6B4F621F9169BC6A329543A3] MICROSOFT WINDOWS
[0691E383B177676EED882A9B6993A821] MICROSOFT WINDOWS
[19FABBE4C1DDC6417C3029A508D4827F] MICROSOFT WINDOWS
[6172D16FF17620FD9F0121A7C8E148CE] MICROSOFT WINDOWS
[80F04680CB078F6DB5ED42A5F9C412DC] MICROSOFT WINDOWS
[4596B539E05DA555E5DCC1619D94383C] MICROSOFT WINDOWS
[DA8F93E3FE82595E59D3C7F37423C0C8] MICROSOFT WINDOWS
[05D159B05709E110075587FADB51EDA7] MICROSOFT WINDOWS
[DFD024A0B4BDD920DA9EBEC7B0ECE9EF] MICROSOFT WINDOWS
[26E0B4CE4FEBD882391625C5CA4F7EF5] MICROSOFT WINDOWS
[C5A69100E505265FA73C6B8F288F75F9] MICROSOFT WINDOWS
[C5F5E02254B53EEC94402EFFDB89AE05] MICROSOFT WINDOWS
[D359FFFE85645585694A96AA8D0C628F] MICROSOFT WINDOWS
[13C398101A5ED0CE80ADBEBA857314A8] MICROSOFT WINDOWS
[21E5561A3B3B7A9A32E84C15D1E4F7A4] MICROSOFT WINDOWS
[0E95DAD7FC69B2BDE60B7DFFFAAF6BB1] MICROSOFT WINDOWS
[7F44C62301131DC4235B978DD9012F29] MICROSOFT WINDOWS
[B3F74E43A73504F3C1D2B10948E67EC4] MICROSOFT WINDOWS
[B398A9122434C379F3737197EB2DD5C9] MICROSOFT WINDOWS
[24BA34EFBD7CE7DC20D0A2C7596E0044] MICROSOFT WINDOWS
[EA85193143D6B3E418931C3346ED5181] MICROSOFT WINDOWS
[E120A034B508051B00D05C98306334F4] MICROSOFT WINDOWS
[8FF5003A798BC97556E56652BAE742CF] MICROSOFT WINDOWS
[91C265D9C7BFF499B8745DC4B3F9CB67] MICROSOFT WINDOWS
[F46A42D9AD47A273F9B3DB2F1AA91F7A] MICROSOFT WINDOWS
[DD83C6FD509052A50C2432ACC4656C4E] MICROSOFT WINDOWS
[903930192DCD755910CA5F8E188CF10F] HUAWEI TECHNOLOGIES CO., LTD.
[349AB4F70E2AC44970894E7F03E1576E] HUAWEI TECHNOLOGIES CO., LTD.
[5EF3427AE503B5C03A48F7C9FF458B69] HUAWEI TECHNOLOGIES CO., LTD.
[E90DA42B87D684DEBFB73B38A718A006] HUAWEI TECHNOLOGIES CO., LTD.
[C856C9308A3F6E4328CDFF0C360ADB74] MICROSOFT WINDOWS
[67849862DC4CA6A8A34C1FA703F67AF4] MICROSOFT WINDOWS
[66AAE701A787E4BDF73116B79274DC86] HUAWEI TECHNOLOGIES CO., LTD.
[CB037F03178E31BA2985ADD15879CA56] GOOGLE INC
[EE2826CAAF139688445D93C7C6613EE3] MICROSOFT CORPORATION
[4C1E83ABF727837F6E99100D49A24719] MICROSOFT CORPORATION
[A7DF60B14578045DD07E0965D8DB6D0C] Caphyon SRL
[A7DF60B14578045DD07E0965D8DB6D0C] Caphyon SRL
[AFDBB9D68320CFD5B9789FF0F248B685] Plumbytes Software Lp
[422AA91F542B07C6D5668B711A844F18] MICROSOFT CORPORATION
[9D85CD8E245989DE49CB1A7FF89EF320] MICROSOFT CORPORATION
[EE0F39935189F6F2B749651A5843EB5A] MICROSOFT CORPORATION
[4CC103AC942998CF807361F73D2129E1] MICROSOFT CORPORATION
[AE0A7D1C63482A6C3754BBA061F4437A] MICROSOFT CORPORATION
[7D9FBEE2B835D139FA9519873BAAF4C2] MICROSOFT CORPORATION
[6A2BD1A3D350DA0A0CBE276A34103A13] Tonec Inc.
[E675C7006BDC625BC4EE9CF5BB1F7677] Shenzhen Wondershare Information Technology
Co., Ltd.
[577119EC77525D3F80FFB03BFACC17D4] MICROSOFT WINDOWS
[AE96BFE60A23845475156F6C189C9CF3] MICROSOFT CORPORATION
[E3DDF6A11B872AF1F959038DAB9DAE8A] MICROSOFT WINDOWS
[2223D97FCF5E77A75D81EC732B8CFE1F] MICROSOFT WINDOWS
[1080AFA8B42F9542CBB13BD5A53F0443] MICROSOFT WINDOWS
[10D5997E2F5F16FE3BC3BD1A4BF31EA8] MICROSOFT WINDOWS
[09440FA30C020B4443391FAFCF4876E3] MICROSOFT WINDOWS
[76A12AC673B0F8A607ACDD0583C247D4] MICROSOFT WINDOWS
[1B6BA244B378EFEAB72AB9982BE56960] MICROSOFT WINDOWS
[31D327F410B68F23E2616C5383F2E022] MICROSOFT WINDOWS
[833C77070F107248F17F90E6E7416A5F] MICROSOFT WINDOWS
[2DA9DA17F0FE6C0A8598EBBB1E59E320] MICROSOFT WINDOWS
[AD732A06645E88A1BE604BD9802901B0] MICROSOFT WINDOWS
[FB30AD7EAD9E77C61778DE7E27E30C59] MICROSOFT WINDOWS
[E1024CF2E35DD3467F52BC83F7FEDA3F] MICROSOFT WINDOWS
[D0ACFE08DAE3996DA1A6C8EAF5E0953F] MICROSOFT WINDOWS
[725F5C26331AE8F24BAD8BC2AB99DB9E] MICROSOFT WINDOWS
[44BEC97BD0CED39125993D75BE728D80] MICROSOFT WINDOWS
[DAB20111EE99BCA4019A6D285FF2EA0E] MICROSOFT WINDOWS
[E7C0E7F21AF69FE20FB697DCE66AD255] MICROSOFT WINDOWS
[A7F056E77075FE6D380E92C07273D7B6] MICROSOFT WINDOWS
[78DA58DF85F86CA61E5EAFB9EF0A83BE] MICROSOFT WINDOWS
[10A6561536EC8ECC53BE5EABC40177A1] MICROSOFT WINDOWS
[71514D9A6350A37B4F0BAA6ACB751771] MICROSOFT WINDOWS
[3BB593E36F3D8ADBCF63649C4DA5FB79] MICROSOFT WINDOWS
[B7CB8C4C89239FF52907E470A8AEAF84] MICROSOFT WINDOWS
[FAE8D0480BDD905EEA453D3A57C8D5C6] MICROSOFT WINDOWS
[ACB36AD75A7DF5E5E8222EC02818D534] MICROSOFT WINDOWS
[4A7015195E49A3BA7DB967B277B21E9D] MICROSOFT WINDOWS
[7ED53A9C37AE7ADE2A72A1C2EE86879B] MICROSOFT WINDOWS
[29C7C9F0FE9F048FB47DEE5F66134940] MICROSOFT WINDOWS
[36638CF94B685EB9298E53327B64B4EC] MICROSOFT WINDOWS
[BAB449E496892494C1E8152A25A1E867] MICROSOFT WINDOWS
[DB390129C210F39926A28AE5DF146DCA] MICROSOFT WINDOWS
[CB440E1C4EC9C369EC9DD07B48A83F36] MICROSOFT WINDOWS
[B0DE13ABF238AB28E963629B977A012F] MICROSOFT WINDOWS
[ED864F0617F9D4925CB99A3755E91FB5] MICROSOFT WINDOWS
[D305B1E69D5647854F22EE2ED1FD81E4] MICROSOFT WINDOWS
[D9546C1D46352D55704A3696C8DFF19A] MICROSOFT WINDOWS
[D0905D4A945D01D4B28DB9E1BD5985F7] MICROSOFT WINDOWS
[8FD51B3B35707A66080D7C8CB05E792D] MICROSOFT WINDOWS
[17997DC2441F7E29CDFC6458E0392764] MICROSOFT WINDOWS
[64479503F983B5A15FA8948E64484EAD] MICROSOFT WINDOWS
[0A7C202CDBFD295363A09DE1A2C05F45] MICROSOFT WINDOWS
[79A87DD43331290A276C02DC396BF530] MICROSOFT WINDOWS
[76A12AC673B0F8A607ACDD0583C247D4] MICROSOFT WINDOWS
[03ACBF443DD7DCDCF7D9F783F8C676F0] MICROSOFT WINDOWS
[96EA35C8FB0862772B9D3BA5BFAE4345] MICROSOFT WINDOWS
[64F968FD1AA5C3D8979D90CB562C05F9] MICROSOFT WINDOWS
[CBFCE3D7C013B8C06C758278F646A110] MICROSOFT WINDOWS
[08877BD788DA2F263169CE878BB3DBBA] MICROSOFT WINDOWS
[179FF6D2853E9925157D47E283C3CAB9] MICROSOFT WINDOWS
[6D90FDA2DC364B8EA1420F2F81585CC3] MICROSOFT WINDOWS
[2B4D3AEAAD02954F8C191BC2D67949AD] MICROSOFT WINDOWS
[5125CBB61AC81168366BEB290399CB8E] MICROSOFT WINDOWS
[82A93A0772A29EB6E41438D9AE5ECDBD] MICROSOFT WINDOWS
[7E53588ABEE2DFE330203772FBE6ACC0] MICROSOFT WINDOWS
[B3F32C630DD3F2F6A6091B89CFF13641] MICROSOFT WINDOWS
[B157D72BDA6A6DD6E9DC6BF338CD0CF8] MICROSOFT WINDOWS
[577FFA2B0B8572587FEB825F42453E81] MICROSOFT WINDOWS
[2E6612376D257F74781F2EF1F869D8C3] MICROSOFT WINDOWS
[A93C9B9EBE2FDE5A536000D72CC17F7F] MICROSOFT WINDOWS
[E723468DB8B986D2C7F2441FE9CB4A6E] MICROSOFT WINDOWS
[5F630B2EB47C3DC8DE3C405677069D66] MICROSOFT WINDOWS
[F99E6C664A3D503878DAD628088AF855] MICROSOFT WINDOWS
[E133CFCBFABB3CB517BE9F42FEA5887C] MICROSOFT WINDOWS
[F4F684066175B77E0C3A000549D2922C] MICROSOFT WINDOWS
[642C70214A0310F3C92EBF5FEFBC5570] MICROSOFT WINDOWS
[D752C96401E2540A443C599154FC6FA9] MICROSOFT WINDOWS
[6BA7D72D00D3E7A4BFFAFC8002E0E28A] MICROSOFT WINDOWS
[A00EF88CB0CE0DB24251B5266BCD1973] MICROSOFT WINDOWS
[5F06CAC4B09250CDDDD0180A08162924] MICROSOFT WINDOWS
[BE35D1BAC3F18C9EB1C1CFBA31ED95E3] MICROSOFT WINDOWS
[DD74F18227ACC837D9856E24282D446D] MICROSOFT WINDOWS
[6F12B244B6BAC8EEEB506C0BEE04F8CB] MICROSOFT WINDOWS
[AE9F09F87755C18904656CB4F59F351D] MICROSOFT WINDOWS
[3C212EF64653D92DACD4F181F3EC0CE8] MICROSOFT WINDOWS
[ABBD3EE724117242E28D31F19FBCFF03] MICROSOFT WINDOWS
[7433474BE77F065D2FA628671FE31A3E] MICROSOFT WINDOWS
[CDF1B1B5C5951111791C236B2696C7F8] MICROSOFT WINDOWS
[F0D4400BA0F08610D9A551B15BF10B76] MICROSOFT WINDOWS
[CA7FEDDFCF61EF15A09C54DA2C07C49F] MICROSOFT WINDOWS
[5BEE714B23F24C2FE8DDDDF3D936CAEB] MICROSOFT WINDOWS
[F2F2FED1EAE5A089D959D1D6DBFD7DD4] MICROSOFT WINDOWS
[706E1428017BF2667368457199343745] MICROSOFT WINDOWS
[DA63852A2B0340E94D74EAF0CD444979] MICROSOFT WINDOWS
[6E5EE6E420FECD64DE463C5F01CBFE71] MICROSOFT WINDOWS
[DBF8AEF8F3573B9D5A5BCE68A2442487] MICROSOFT WINDOWS
[8F46B4C3F9BA19C26A26D0A11137B20B] MICROSOFT WINDOWS
[CA09EAEE92C6FDDC6B05057F11A0372D] MICROSOFT WINDOWS
[80208B7892BEC1ACA6409383F193E860] MICROSOFT WINDOWS
[D46558489473E42271DECF7D914A0375] MICROSOFT WINDOWS
[BC5F74FE1451C10C4AF32EF441DB72F1] MICROSOFT WINDOWS
[F27686F62321BBB8246D468A2F8F42E1] MICROSOFT WINDOWS
[09B7C685A35DFB954BD2C7FE30268C0A] MICROSOFT WINDOWS
[A7901875F89D011C38CF52C98ACF5B29] MICROSOFT WINDOWS
[EE1CCC54F75C24727A218F98FC5349DA] MICROSOFT WINDOWS
[73C73E1AA0D4D727A04AAAB120B7F56A] MICROSOFT WINDOWS
[0935496EF9624B46B935CB35ECE1F205] MICROSOFT WINDOWS
[D6794C31F4077B71433988787BAA926E] MICROSOFT WINDOWS
[FE5F656D6B35089DA39112E74EC6A85A] MICROSOFT WINDOWS
[2F242941E4DFF69B883D77A16F039557] MICROSOFT WINDOWS
[C247E35A21682DA8D0DC3AF9F025FCC5] MICROSOFT WINDOWS
[49B9DB97AFC85DCCBDACDAB2E90085B7] MICROSOFT WINDOWS
[323AA1953ED9C01E23F740FA891FE064] MICROSOFT WINDOWS
[28C2EA278070EE12701D0EDF8CB0EC36] MICROSOFT WINDOWS
[23522E5D581F7722B1B5B86737CAE39C] MICROSOFT WINDOWS
[DF21E05E41E5AC3F13F304D91457649A] MICROSOFT WINDOWS
[45D0AA4BB90B821DF92E8F19ABED0C5E] MICROSOFT WINDOWS
[74FFBC43B4B899C9A8CA06A892F2CE73] MICROSOFT WINDOWS
[AAB0F1D8D7E54761ABAB13AF161F1680] MICROSOFT WINDOWS
[F91BAAC4237C40352A807000F3B716F9] MICROSOFT WINDOWS
[BC121C099C6C659126AD2102AFDFF8CF] MICROSOFT WINDOWS
[68190E2BADF23BD782344970E5B5DE9E] MICROSOFT WINDOWS
[B66ED2CB37F7E4696A51612AFBA08834] MICROSOFT WINDOWS
[8DC924848E20F890BEFC6B31136D46BE] MICROSOFT WINDOWS
[9ADC5A8BEE10E174F95349E9232D8E76] MICROSOFT WINDOWS
[E6AB1F0B4C3D4E0D2A88332D76FECD03] MICROSOFT WINDOWS
[38DA94B6DD8022DA43810E4328608E54] MICROSOFT WINDOWS
[CB9C9479F43A3C1C9DC8F16E71C0AA6B] MICROSOFT WINDOWS
[61C5A480C43E7E8E49C42869F49D0D3E] MICROSOFT WINDOWS
[A10F989A812B57B9695F6C305907C9C6] MICROSOFT WINDOWS
[835E2C1A3D32492E2B90BD4FE5527CB6] MICROSOFT WINDOWS
[94D6B95485BFA35D81524B0EBA0F7569] MICROSOFT WINDOWS
[8CE702B1F8BB3C2A9702A4F3742D6216] MICROSOFT WINDOWS
[3F5523DCEFE42B385659C5CB46A6B810] MICROSOFT WINDOWS
[0B750A6A6D847E73CA48ADD7A0F5A393] MICROSOFT WINDOWS
[7A3593DC24D0030CD4B0D92355768D63] MICROSOFT WINDOWS
[9CD2A4821DE379305CACB2E99AD8953A] MICROSOFT WINDOWS
[85669C51BA3BBD4CF6457C280BFAEA0C] MICROSOFT WINDOWS
[06E525D9DFEEA87BB69FCAADF21013E1] MICROSOFT WINDOWS
[722036C26D2C4E50EC2A2EC5FD678846] MICROSOFT WINDOWS
[77630A51FAF6A07922FEE835F4DED8F6] MICROSOFT WINDOWS
[C2E31BE025D46D189E38DD1EDF07837A] MICROSOFT WINDOWS
[F7CD605FC0B0B22F3F6F247595E3A655] MICROSOFT WINDOWS
[B887F6536B6F6566E1B6794878E8FBA6] MICROSOFT WINDOWS
[535DC41A33630AE4C262406F9E981C03] MICROSOFT WINDOWS
[09A2E0DF0ED1D5D3F8C6779A0CC19529] MICROSOFT WINDOWS
[34C35293F5A3DEFEC59DBCD7BD4C17D0] MICROSOFT WINDOWS
[DC5955E589C55E2313D69B64E1A183F3] MICROSOFT WINDOWS
[23F9EF739F685E07482116425E7879AA] MICROSOFT WINDOWS
[61BAC67048CA5C1D08C48FCC8012B613] MICROSOFT WINDOWS
[60EB6A4CE3E21887D302350631C16F26] MICROSOFT WINDOWS
[F8FB51B9EF6372610E9B31A1D86B62FC] MICROSOFT WINDOWS
[613D0137C269187FA298A157E3D14A18] MICROSOFT WINDOWS
[1219A31A19E13524F9F73D59B01A478F] MICROSOFT WINDOWS
[0AED948DA8D5F08B3D6F12E4E2089736] MICROSOFT WINDOWS
[0002A0FDE087C1657AB31CE73077539C] MICROSOFT WINDOWS
[6B4F90A287D75CCD78694F6790C911B2] MICROSOFT WINDOWS
[D9B1D367ED0852AD2BEBB58848995CBC] MICROSOFT WINDOWS
[50F92C943F18B070F166D019DFAB3D9A] MICROSOFT WINDOWS
[429623E266EF067A44E8CF148E9DFB9B] MICROSOFT WINDOWS
[572F57487C4CFC0EDE2682F41D0AD424] MICROSOFT WINDOWS
[3DB10C59405931E2C72EFB82C1AF97D1] MICROSOFT WINDOWS
[44EEEB2382F566999287E13F2067693C] MICROSOFT WINDOWS
[EC2EA2F6C6D23315C20B4829F00D0440] MICROSOFT WINDOWS
[3BBD0073265DA6D3EFBA54B26E5D8236] MICROSOFT WINDOWS
[385E6F76E684E7EEEECBBB156C45D191] MICROSOFT WINDOWS
[630A3DA76BAC02E678AD0C3EF77CCDE3] MICROSOFT WINDOWS
[815F45161A4571C2C44491564F3D5968] MICROSOFT WINDOWS
[620D90C4AB9091FECB3103BDD9165284] MICROSOFT WINDOWS
[C092B887E61D5A85FA891BF1D48C678E] MICROSOFT WINDOWS
[AE6BD4C879A8C849E53947C92DF3B3A0] MICROSOFT WINDOWS
[0B729AE130D2EC2953865A09497F9F43] MICROSOFT WINDOWS
[8D74B8B5D6F7C5BC4C525BAF2B083FF1] MICROSOFT WINDOWS
[2A9817B5A9260D8F60D52E36BEF10443] MICROSOFT WINDOWS
[77B60DEC7DCB4233E4A69D3F52E5DB24] MICROSOFT WINDOWS
[7EC6FC0266D74BD47ABB130A328B70EC] MICROSOFT WINDOWS
[86F7951BBCEE4A86E79A97306BD14318] MICROSOFT WINDOWS
[F6C1661C55EAAD2DD9FBB37D5DF1A011] MICROSOFT WINDOWS
[24FA6177FE55C4BC045EC87E39F90688] MICROSOFT WINDOWS
[2FF4826C4BC5AAFC3F579E2063F76BCA] MICROSOFT WINDOWS
[99598ECA5E41996E005D5B9D9FF1EFA2] MICROSOFT WINDOWS
[F44F666B0EACC3181544FFCF8CA0FFC7] MICROSOFT WINDOWS
[78A210DDFDF2C9EC884631D2DAA573F0] MICROSOFT WINDOWS
[1A97DB5E701A186989F3795223C3BE39] MICROSOFT WINDOWS
[46626665F0E5906E45619B4EFD6186B8] MICROSOFT WINDOWS
[FDA72ACA14D516D18C33AFCD0FD9260F] MICROSOFT WINDOWS
[B07A40B5A7A58B8C75663A572A46084C] MICROSOFT WINDOWS
[3807CB07B3A446B87004240B1D7BD4F8] MICROSOFT WINDOWS
[B55FEBC6A00DAA1FE074F020B6907516] MICROSOFT WINDOWS
[7ACD8F69B5D6EC97E6D2C006E19BED88] MICROSOFT WINDOWS
[10E3515FE5DBA6656FA62C29342EC4A1] MICROSOFT WINDOWS
[B90D284B97CD4CA9DE7430AAAD887A56] MICROSOFT WINDOWS
[6B6E527B24F0D76F17E7DBD6D4059B22] MICROSOFT WINDOWS
[D24355488A2D4D2323518EC1AC7A6D9E] MICROSOFT WINDOWS
[0AF9ABBA4F3F55C6C803890D64BC3C29] MICROSOFT WINDOWS
[CDBCF8E9AB06D88A1E1191D32F320C5D] MICROSOFT WINDOWS
[D8536CB438CC4CCDAE047B768EED22B2] MICROSOFT WINDOWS
[F5CA18197B4646E04DB9EB2D6642CC4D] MICROSOFT WINDOWS
[AB91AF050B5FFFE25BEEEDE8AB6ED035] MICROSOFT WINDOWS
[74FC79C52395B10FFD0B55CF22CF88FC] MICROSOFT WINDOWS
[771EDDA9830A3079F996F34D681FB6E5] MICROSOFT WINDOWS
[3B9F315E7FA72CC25228EB097DD9C694] MICROSOFT WINDOWS
[6A0B9F5662598D229F62CD317292E8F3] MICROSOFT WINDOWS
[B54B30992620C97230013A74461C8517] MICROSOFT WINDOWS
[C6B8743B213F06AA60943D8366FE968F] MICROSOFT WINDOWS
[9A2A2F3C69B9A30B6E78536F6D258BAD] MICROSOFT WINDOWS
[5A0E850F8CD17791A3E6A3CF81D0CA28] MICROSOFT WINDOWS
[7508F1096803385D6376BFD0BD473AC4] MICROSOFT WINDOWS
[16A10CCEDCF5AC4CAAE43DC9FC40392F] MICROSOFT WINDOWS
[EB82A11613326691508D9ED9A4FE29E7] MICROSOFT WINDOWS
[97E553D03219D3D51705C7235D9EAEBD] MICROSOFT WINDOWS
[8350FE3BCDE3428BC040877BB7E9EAEB] MICROSOFT WINDOWS
[3BA03F7C7700DDF4C383DDE9252F5817] MICROSOFT WINDOWS
[025868A34E359A5F49D2324C0B14D537] Tonec Inc.
[7BA5F6FEAA79BB7C7A635E6B3982A0D3] MICROSOFT WINDOWS
[2A01C96DF5802D3434634E55C91232D8] MICROSOFT WINDOWS
[E300D1E37B737ED14F7A08CD5604E5D9] MICROSOFT WINDOWS
[9F7E87F6595D065A8A200A291043045E] MICROSOFT WINDOWS
[A6BD2E20AE1BC5CB2776C87C28E4F4CA] MICROSOFT WINDOWS
[2A48DA39542636DB0FA3BA915385D1B3] MICROSOFT WINDOWS
[DB32758F3A7F6CCE81A5430080A2EA65] MICROSOFT WINDOWS
[FE85D0A86CA7A5A99CF8CD04DE7F80AE] MICROSOFT WINDOWS
[10D01A3657AC8E8004C83D613163DE1E] MICROSOFT WINDOWS
[F1DAECC3B3D6399875D4F10529D6A77C] MICROSOFT WINDOWS
[7475A2903BB704B446AA6309E34D3362] MICROSOFT WINDOWS
[9725E7F0C64CE9916A5CDABE8D6E13C3] MICROSOFT WINDOWS
[58040898883A96160D41739C80328BBF] MICROSOFT WINDOWS
[210808437570BDDEE71A43535E3A2D30] MICROSOFT WINDOWS
[0B779E9FC426CA2268D28181FA6C222F] MICROSOFT WINDOWS
[813BA3EB2CE038F2A5382DDD75CAD60B] MICROSOFT WINDOWS
[251F05F5F617C88DF7491441671720DA] MICROSOFT WINDOWS
[B88617822DA473114DE754A2A312A8C5] MICROSOFT WINDOWS
[4ED115CD1A1099705F56B5E0FFF97CC6] MICROSOFT WINDOWS
[5933A6673F00D8255C52957E40C2D601] MICROSOFT WINDOWS
[8E1B0946948CCC0BC1FA3CB70374A795] MICROSOFT WINDOWS
[4F68163FC04C973500DC4DA0946917B0] MICROSOFT WINDOWS
[E5AC5F2815938651CDCC27F425474673] MICROSOFT WINDOWS
[CCF6EC9FB9B8F18E05B4253E81013E48] MICROSOFT WINDOWS
[C9579D32219E5B936AC3A48D470117EC] MICROSOFT WINDOWS
[C3CDCCF07486BD2616A7B82946E07AC0] MICROSOFT WINDOWS
[2CF0CB2A0ED68C5455371E84C16F9627] MICROSOFT WINDOWS
[FADB2FE017E69EECE0E1BA78661C2E8C] MICROSOFT WINDOWS
[FD60818B66B2E8A5415EA840E99A9D8F] MICROSOFT WINDOWS
[68F6977F1CFBAAC770D940A8C0326FA1] MICROSOFT WINDOWS
[0D50B3F3AB32D416786B58D4553859CE] MICROSOFT WINDOWS
[9CCCB7FC3EDADEBA461D78615A6011A6] MICROSOFT WINDOWS
[27A07B2FB2E3057DA8DAEA4F25D843C7] MICROSOFT WINDOWS
[7BD6E7F7C9001AB21B8362CFFEE80B25] MICROSOFT WINDOWS
[F5BDAEE4B7D369D4C74668DCFBA3FF10] MICROSOFT WINDOWS
[30844BD376F9D01E62C820BEF446F1F8] MICROSOFT WINDOWS
[25D32BE04FE0A23FDF57FD5382757672] MICROSOFT WINDOWS
[F4A3EFC57F7A5406565E6519B25A4C31] MICROSOFT WINDOWS
[E0AC54C9EEF2C8B14363B256CB0B281C] MICROSOFT WINDOWS
[87B9D4998D9CA0DBB6CA01BB2C28857D] MICROSOFT WINDOWS
[DDD8A8CDDC7F13EF57D1DAAE71865936] MICROSOFT WINDOWS
[22ECD8F5D1DFADF2011BBB1700CB871D] MICROSOFT WINDOWS
[FD870F6968A145E4D2BA8A8842686B03] MICROSOFT WINDOWS
[30364757963A028CE5DF0FBAAC270173] MICROSOFT WINDOWS
[6BB0FEDDAE7135FA37FFAFF4D9E0E876] MICROSOFT WINDOWS
[3C97BBD57E92F76A079338DE6F8317C6] MICROSOFT WINDOWS
[4586CDA25B7866DD9505CEECF9DB3C74] MICROSOFT WINDOWS
[642CDE46351D5D2D90311E77072AB46D] MICROSOFT WINDOWS
[F2302A5CE63CA7673200FAFCEEEDB6AF] MICROSOFT WINDOWS
[6114512EA26E835BA522C63635429DB5] MICROSOFT WINDOWS
[7ACFE7435317E791FF9EED2F49B402F2] MICROSOFT WINDOWS
[0543BEFD41EC4D25C7F7CF36409CEC7D] MICROSOFT WINDOWS
[C1569E4DB8EFE3617847BF041A3C842F] MICROSOFT WINDOWS
[130B16970154BA9876B09E5C4BAC63BE] MICROSOFT WINDOWS
[A2A906C0D38BFE1D780251D044BDBD4D] MICROSOFT WINDOWS
[3D2C5B4995CA0751D32DEA0DE9FDFE44] MICROSOFT WINDOWS
[629CB21AC49C8867E0F29DF1C16DB7B4] MICROSOFT WINDOWS
[42A3B76320D483D443A60661FE1FEF14] MICROSOFT WINDOWS
[6DD605338FAAF6BA17662AA874E0D162] MICROSOFT WINDOWS
[E34196F285F8B8879E1FF36C31F7179E] MICROSOFT WINDOWS
[1FAD2398673F30CEC616B89C46B7DCBA] MICROSOFT WINDOWS
[AEB8ECBE66CC46854066CB1F5623E179] MICROSOFT WINDOWS
[7340104C2BF2F126714F7CDE85E63610] MICROSOFT WINDOWS
[07ADC1F8DCBEB8104D75129B11584B8C] MICROSOFT WINDOWS
[78A12E3DF035B5D054986949B19BE43C] MICROSOFT WINDOWS
[04C8859355C1DC9C0FA198D1894D71C2] MICROSOFT WINDOWS
[6C76780A01FC2B885BD6E957B5C36B02] MICROSOFT WINDOWS
[5D1513BD6430307C9DB86C6E351372ED] MICROSOFT WINDOWS
[C2B9D1E69B332210E87C22CD94665BA3] MICROSOFT WINDOWS
[1DDA483F4BD657C36B26B3791118E9B7] MICROSOFT WINDOWS
[90F5DC9802AAA00CD0B6E2AD9E7FFADC] MICROSOFT WINDOWS
[7C6C3B9E771A7BE2924FEF1A42942841] MICROSOFT WINDOWS
[C9A2046A3B749CFD7E485B6FB1FB3A6C] MICROSOFT WINDOWS
[D261DF41F0840F734856A2B4F5E072C7] MICROSOFT WINDOWS
[23B702B555EB0436B9DAA0BC63DA65CE] MICROSOFT WINDOWS
[10200887FD2B3BDCEAA9453B939BB643] MICROSOFT WINDOWS
[B621114B8D1E9256DC1BFD6BA2F4DE69] MICROSOFT WINDOWS
[6B81BF7853D161DB8AC62CD8B9C2DE6B] MICROSOFT WINDOWS
[032F1C32A6A97C317AEFF9D64D2A1D8A] GREATIS SOFTWARE LLC
[0553ECB742278C8F4CFA28B43FF20EAD] MICROSOFT WINDOWS
[29AF16726F4DD84376ECA85AB6AFF2C6] MICROSOFT WINDOWS
[214DCC87E3898F738075D1341252A552] MICROSOFT WINDOWS
[AED76A3333B3A31536E430020E0226FC] MICROSOFT WINDOWS
[E63FB38B6E75B39467492FBAD2CD512A] MICROSOFT WINDOWS
[382D493B91B816D12C6F775E7896ED29] MICROSOFT WINDOWS
[1509A77F840AA9E72CF8247D0CF2FBDE] MICROSOFT WINDOWS
[540116170E2135FCD5DDE77702166B67] MICROSOFT WINDOWS
[8356F87553BF49C703CF382033815898] MICROSOFT WINDOWS
[372913E12677A8CBBBABDD8311894F9D] MICROSOFT WINDOWS
[819602BBBFDB0BD46DEA3715BF0DD452] MICROSOFT WINDOWS
[CDF47037A0939F56D11F699629C276AD] MICROSOFT WINDOWS
[17E565710172ED71B8531D8822E1C5D1] MICROSOFT WINDOWS
[726857E441D1D67F57694A1B613ABD34] MICROSOFT WINDOWS
[5645B9D9788CCA2C88B9534996ED2D6D] MICROSOFT WINDOWS
[F0F4EEDEEBEE7A4244FAFB96A16B5712] MICROSOFT WINDOWS
[3B80AAAEC3A3DD308DBE7B0775013E10] MICROSOFT WINDOWS
[79A415E6FA915EFC00297DAB16EC2635] MICROSOFT WINDOWS
[7135785C21CA79D270D11037C43D3F19] MICROSOFT WINDOWS
[97A61A3CB2B5CB4FC32B3224EF333448] MICROSOFT WINDOWS
[69BB204AE07EE84ECFAB1BF13C4BD04B] MICROSOFT WINDOWS
[EEC3A4A98AE1A337E3CD1483AD6F2E15] MICROSOFT WINDOWS
[E82F3B1918C6A5FE6EB761CDF1E772AF] MICROSOFT WINDOWS
[5FF28F097C9699097B473F8FC7C1AA7D] MICROSOFT WINDOWS
[DFE1602D6A08A0C27C48DD8C4EFB11CA] MICROSOFT WINDOWS
[C6431D29271C5952CBC4FCEE97BDE256] MICROSOFT WINDOWS
[FEAB5D20ECE485D6C0BD9FC9846F32B8] MICROSOFT WINDOWS
[5E73FB63E2DBC75FE0C17DEB0010CE0E] MICROSOFT WINDOWS
[3D9A82B03C92D1FEC42CB171D6F57778] MICROSOFT WINDOWS
[227A7AAD04CB11116F8B935CA31F0D04] MICROSOFT WINDOWS
[50FCAD2051E6DD313393437DE6D7C049] MICROSOFT WINDOWS
[08ED027CD8A43E3412BDD134A43B13E8] MICROSOFT WINDOWS
[4DFEC463DD018EC4EC47F9E94128EFDC] MICROSOFT WINDOWS
[401D706DDC0A7AF18C3DD228ADF74551] MICROSOFT WINDOWS
[7084D11083F0CDCA8B5C76F9846ABF5D] MICROSOFT WINDOWS
[3FF478A8ED32A83C36581425F6282B6C] MICROSOFT WINDOWS
[92509187AA171A80521528B36F753E1D] MICROSOFT WINDOWS
[433D38FF6D08B993847EA2A10EB8CB52] MICROSOFT WINDOWS
[697D3EE0740AEAB62B66ABCA1C83D13B] MICROSOFT WINDOWS
[A34CE1830E45DA98932295FDE4B7908A] MICROSOFT WINDOWS
[A7B5C670770E908DA5FEF5BF1136E933] MICROSOFT WINDOWS
[D88FC13079D14E5403AED5F7D33A2015] MICROSOFT WINDOWS
[1A5F733CD6705C805BA09244B3E0E442] MICROSOFT WINDOWS
[E03264C4C25B568F92ED1656AD541E64] MICROSOFT WINDOWS
[7765EF139A8744ABE297EFA6A7390677] MICROSOFT WINDOWS
[8B4A7F1BC1CF7FC83A305F4B0F979155] MICROSOFT WINDOWS
[EF2D84A9E1ED7CA32FC15E33FD235B65] MICROSOFT WINDOWS
[5F78930AAB3900102EA8ACDD38F97324] MICROSOFT WINDOWS
[F0B59ADCD06BCEB9D47311B7041CA2C9] MICROSOFT WINDOWS
[76F7D7217FBDAB77798A2A244ACD641F] MICROSOFT WINDOWS
[29D26E1347AE1BBD4201014E19880B2C] MICROSOFT WINDOWS
[6BC6023E866489D22CE30E18846B80D9] MICROSOFT WINDOWS
[9886ECF5D6142DD2EE30D2C23F411E60] MICROSOFT WINDOWS
[BEBF85EB4D90E6996047DA027D0ED26E] MICROSOFT WINDOWS
[8E73037A6F8938475692FFCC26EBF385] MICROSOFT WINDOWS
[9D9DED47DA10E845EFF2DD57C94C809B] MICROSOFT WINDOWS
[505E0C40B5D0ADDCBB414640F59BD2E0] MICROSOFT WINDOWS
[32F46FB0F290D16DAA452B289C985795] MICROSOFT WINDOWS
[3C32FF010F869BC184DF71290477384E] MICROSOFT WINDOWS
[03B9DF5A59B5A201D9B7409EF1C50F6B] MICROSOFT WINDOWS
[14A6ED9AD702CE1F1CE34756EB41834F] MICROSOFT WINDOWS
[3CE84BB06DB5FD6ABF2DE88294E56EDE] MICROSOFT WINDOWS
[296C443FCC228EA643ED310465772820] MICROSOFT WINDOWS
[06130AFFECEB94525FC2352936576B70] MICROSOFT WINDOWS
[46171262D0E806779DEEDFCAB2F830CC] MICROSOFT WINDOWS
[A6F4025664C9D4BC2A9EDAB4092706D7] MICROSOFT WINDOWS
[37A96AD493E110C0BF1EE0AC0F9E7DBD] MICROSOFT WINDOWS
[E9503E60345EEDFB9C11E74063E03E2E] MICROSOFT WINDOWS
[79E264287F17D56D768440B0270466DE] MICROSOFT WINDOWS
[AA65954F512BA097DD190790876DD991] MICROSOFT WINDOWS
[AB6268022C3A5B529075A39C33904DA6] MICROSOFT WINDOWS
[7ED2EDA43D21C7A5F589A7960E265C52] MICROSOFT WINDOWS
[169351463039B45F5CDED9768879F712] MICROSOFT WINDOWS
[08A9E3AD29B215484FBB68CDC175DF3A] MICROSOFT WINDOWS
[DA70AEE267491AA56BC63AA0C0C96CA2] MICROSOFT WINDOWS
[FBC5ECF6D5A868D0B116C2DBB02B8168] MICROSOFT WINDOWS
[B918E40FAA9CD118CCA4AD388B748C98] MICROSOFT WINDOWS
[166B17AE1DD24D8BA8CA474C7C31148F] MICROSOFT WINDOWS
[0FD75222C1AD2687AB365BEBEA400DD4] MICROSOFT WINDOWS
[C1A78C53E01C641AE41BFA65797819F5] MICROSOFT WINDOWS
[767307212110EBEFB93EC9A5BE9E85B9] MICROSOFT WINDOWS
[DC460AAA18CA2342FBBFB2DF9B044472] MICROSOFT WINDOWS
[C3CF0377917ECE6D65D7623E1E61568F] MICROSOFT WINDOWS
[049CF5376EF87B39DC5CF3D776605422] GREATIS SOFTWARE LLC
[6B46FC140C9AF68E6E7697D66D59CB4D] MICROSOFT WINDOWS
[B4402E7F0923F660270442CE76877ABE] MICROSOFT WINDOWS
[9DD431F1B94789CFB527E5D19261F124] MICROSOFT WINDOWS
[C87E32B90F085970D9637FBAD45EF6FE] MICROSOFT WINDOWS
[0B663856474AC41924D9E9112203858F] MICROSOFT WINDOWS
[F83D2250256203AC5DA5E8601C1AFDD7] MICROSOFT WINDOWS
[7FFD26742321919590ED77FCA556D65F] MICROSOFT WINDOWS
[7A749B2863B5561BE34B39E8E249AD8F] MICROSOFT WINDOWS
[D2109F1F4FEBF1DAC415CDC5DE876479] MICROSOFT WINDOWS
[29C9572F2D061CFC3C0BD48A3163E343] MICROSOFT WINDOWS
[2EC7B2C8123236B1233A77281D378DF7] MICROSOFT WINDOWS
[429477D6DEF3321FF7D3EF23CAAADA00] MICROSOFT WINDOWS
[529634743FB9D72BDC27F2AF02F3260C] MICROSOFT WINDOWS
[C917D09064CDBD18F75ADC9B2C48F847] MICROSOFT WINDOWS
[B4F448F2424492F99F83D3676A453553] MICROSOFT WINDOWS
[58827BEFC54D4396D3FD191F5DD31C1D] MICROSOFT WINDOWS
[0CBDE344FB48E42D78E29469F202ADBC] MICROSOFT WINDOWS
[723195568C8755CAD57F7933C5F2C5C2] MICROSOFT WINDOWS
[BB742D3DAA0A186618BF2B7C13446004] MICROSOFT WINDOWS
[7929228F0E8B0C2FA0495A17A4FC27F6] MICROSOFT WINDOWS
[AEE432ED868831B1F068E373598F6D93] MICROSOFT WINDOWS
[9444B23FC694B5F90F21B0FC7F10D8DD] MICROSOFT WINDOWS
[EF78034773CE506323655A868C949144] MICROSOFT WINDOWS
[4D0287F566B36536DD812A54C015FC4A] MICROSOFT WINDOWS
[B5DAEE69BACA64D2BB004568E22D8756] MICROSOFT WINDOWS
[C5E0ACE4771F5575D9D5B457ABF3AD03] MICROSOFT WINDOWS
[29075915F9BDC3437F8BED71C067D399] MICROSOFT WINDOWS
[6BDB6CE6D2D9E3D3F28F1C97E12B62E2] MICROSOFT WINDOWS
[BF2546583BB75F01DDA60A7921DFB230] MICROSOFT WINDOWS
[AC2E20A74D09D24485BE8396CE04F07B] MICROSOFT WINDOWS
[92F6E3E6D3F1795263EB34B37F74AEF7] MICROSOFT WINDOWS
[FD9BCB8920973CEAD4D49DC7A6D8A618] MICROSOFT WINDOWS
[0C111F220798CCE80484026E06822379] MICROSOFT WINDOWS
[607639716E9DB1CEF4E18B5B229293B4] MICROSOFT WINDOWS
[B1ED64E628763148BF84FBE23F2AD711] MICROSOFT WINDOWS
[B1133B813E4CBF258A392CA08255BA24] MICROSOFT WINDOWS
[55D00B785A7587F4263D125817871283] MICROSOFT WINDOWS
[CEF3D306C09BEC1A800E9B4A06F859F6] MICROSOFT WINDOWS
[E330144B97D493AA886000DCAAA8DAF5] MICROSOFT WINDOWS
[8FE13674424DE8438F1A81A02BA2D423] MICROSOFT WINDOWS
[D520B1B849B6D4D707AB31722B952C2D] MICROSOFT WINDOWS
[5030C76047D756263093A47B82970868] MICROSOFT WINDOWS
[29FF9199EDEB4F5470BB134D1A2563D2] MICROSOFT WINDOWS
[E02A8693904E87398663D01C0CCE3AD9] MICROSOFT WINDOWS
[17CF416CFF408190F5A4CBD79AB12E55] MICROSOFT WINDOWS
[0A9985727EC057BBAE4C1615CD93938C] MICROSOFT WINDOWS
[0CF79A0EACFFBB75A50A469A27696D02] MICROSOFT WINDOWS
[0DE131733317EB4BE67028366B0CAAC6] MICROSOFT WINDOWS
[92EB5D38BDF10C790450F3E46BF93A0E] MICROSOFT WINDOWS
[F95DE20312ACCA7761446DE152BD1F7C] MICROSOFT WINDOWS
[4EFB346BFDAEEB29316AA52BBB9852B1] MICROSOFT WINDOWS
[8B9AFF5F08E66A6F1F1063DEC9457FB6] MICROSOFT WINDOWS
[6F4F4F5A007D1710BD76FB311DA97C07] MICROSOFT WINDOWS
[75A9284F01FE7CB1A7D5EAE5C1EB4F33] MICROSOFT WINDOWS
[36D7B73ADC3E10607ED6EC874AFB5D1E] MICROSOFT WINDOWS
[AED7FE551E8672B824A56324076183EB] MICROSOFT WINDOWS
[CEFAB17FD7DFCFA515626C306262E89D] MICROSOFT WINDOWS
[DB77764B46D02DCB9777D9E00A3F7D63] MICROSOFT WINDOWS
[63088A3361D9A308F328F11E9099DD87] MICROSOFT WINDOWS
[F98415E5B83742C901D0A336972509A0] MICROSOFT WINDOWS
[F98415E5B83742C901D0A336972509A0] MICROSOFT WINDOWS
[34C935AF2A414572B412B3556586D783] MICROSOFT WINDOWS
[D53844D90420BC73DC151EE1C9E45C08] MICROSOFT WINDOWS
[5FCA45C24501DA7390065D3706A9FC3F] MICROSOFT WINDOWS
[C89F159A577F19F7F03C73C98D29D841] MICROSOFT WINDOWS
[A8895E416EABF23C07D559DD2B03FC1C] MICROSOFT WINDOWS
[EC03B2D63A9A3AB25A7062CC9036F453] MICROSOFT WINDOWS
[9FCE4EF7D5E274F862D9A2526B5F4779] MICROSOFT WINDOWS
[31BFADFB13EBC9CB06D6E250FEA0FD36] MICROSOFT WINDOWS
[7A2FB2DB4F7772DD4C0ED41011B5FB8B] MICROSOFT WINDOWS
[0043AD6FF21DA011F05C33790875635F] MICROSOFT WINDOWS
[80A7999DE02CE678B865832E1CE78CD6] MICROSOFT WINDOWS
[F89083AB8B9F51C0031C1CBD0A9A7E35] MICROSOFT WINDOWS
[BCB9F3F5C67DAF7FCA462CB7F63C4376] MICROSOFT WINDOWS
[2B9F2151617798C967B90451F26BD364] MICROSOFT WINDOWS
[EF0DD43A4CBAB367BCA1AFBDC9971E4F] MICROSOFT WINDOWS
[34DAC585994CD3B4E910DE11C584EF3D] MICROSOFT WINDOWS
[B68DA1FE3CA2311AFD38DD6905CA7F71] MICROSOFT WINDOWS
[15F0990B7C101163FE27D9B19FEB3D43] MICROSOFT WINDOWS
[5070B37B20DDC257AF93EB0BE8AB5690] MICROSOFT WINDOWS
[6B4604F08F18FF986A5BB411049B7230] MICROSOFT WINDOWS
[3ED36FD05013F4E77E5861FECD4DFB3D] MICROSOFT WINDOWS
[77CE56471AF984800F318F3734D768C7] MICROSOFT WINDOWS
[39A3A7E108ECFDEE421CACCA06C99BA9] MICROSOFT WINDOWS
[D299735117D7DF61A083878C96A3099A] MICROSOFT WINDOWS
[8997353398C8466ECD183942D5FCC65B] MICROSOFT WINDOWS
[C900FE0DD6A1E2220084B8F1C427790C] MICROSOFT WINDOWS
[0C84C250F80EAEC2C9768464CC1A9626] MICROSOFT WINDOWS
[F5D67749BCB061C4E108DB5E7C4B12CE] MICROSOFT WINDOWS
[F70DCCE72343449F0D12A0A92282B019] MICROSOFT WINDOWS
[A674BF4F3A8A995DD816CD83B9358AD4] MICROSOFT WINDOWS
[AFDAB46F7D47A5D298A4F956A3C18116] MICROSOFT WINDOWS
[40F9C1B354C0B70B9D5FB3E540977B66] MICROSOFT WINDOWS
[A92D14C1240FC998075456D5475351FF] MICROSOFT WINDOWS
[63C36E3D97A3EA6B3A89B6075BD77925] MICROSOFT WINDOWS
[F2934208C0E50C0B971A7981AB90BED2] MICROSOFT WINDOWS
[A5538EE91A10A7520A69AB855DC61183] MICROSOFT WINDOWS
[F798F225C38510BE4085EB19524861FD] MICROSOFT WINDOWS
[DB5F6C68E345268B56D635EA13699413] MICROSOFT WINDOWS
[E38BE81F0F6D9C74E420A82BC6A02AFE] MICROSOFT WINDOWS
[F70CAC34B455D05EAA04B2F8FB58E1CB] MICROSOFT WINDOWS
[8C604213A2E73088BFFE6CD2E6F1AE53] MICROSOFT WINDOWS
[07E3E54734B14F43A4A95A849C0A0DE2] MICROSOFT WINDOWS
[557AF00E0FF6FB1D9EFF95ABCFD67B1C] MICROSOFT WINDOWS
[1C0CF1ADBA19E1CD3CB4FAEAE78E86C2] MICROSOFT WINDOWS
[B9C54CDB8779423E2E3C4865D544939C] MICROSOFT WINDOWS
[F8EBAA1FE6D3BF84752931DE1BFA0E2A] MICROSOFT WINDOWS
[5A23E4BE0CCF49663C4CF7EB74C20278] MICROSOFT WINDOWS
[0AC1BD5A28FAA371EF34859FE703E515] MICROSOFT WINDOWS
[88A3C935725FA6EA1A228DCC26CF9C6F] MICROSOFT WINDOWS
[3F858E28AEE6545FA1B64134DFD5C2CE] MICROSOFT WINDOWS
[4A1EC99F1D9F2AC8B96937FC65DE7E16] MICROSOFT WINDOWS
[E8728C29BA67AD5B9F917001FC347271] MICROSOFT WINDOWS
[109C1D609951E886D3643B15C1EDD1C2] MICROSOFT WINDOWS
[5C6553D5E541E15C18BBD59E0FABF2F4] MICROSOFT WINDOWS
[D5EFC0BAEC21EDE6FE03D377D403B421] MICROSOFT WINDOWS
[916AF28E2A7B5EB4328623A5BE960D79] MICROSOFT WINDOWS
[55A417C3E41F2A98666CF929EC19108E] MICROSOFT WINDOWS
[46357DDCA2C795B63DE0FFA00F2C33D4] MICROSOFT WINDOWS
[DAB20111EE99BCA4019A6D285FF2EA0E] MICROSOFT WINDOWS
[9F699136FA1A8A170C2C05D7790A5FC0] MICROSOFT WINDOWS
[13F6B64235C60167052364BF7D99E4CA] MICROSOFT WINDOWS
[70F9352EF3D91058486BE638948E0CD0] MICROSOFT WINDOWS
[8FC71447AC1D835A0DD2D12EF03D95A7] MICROSOFT WINDOWS
[D71EF631D3EEA14FBAE8C8EDF7BEE307] MICROSOFT WINDOWS
[198B34F7ACCDEA764A508D9B86A8AAC1] MICROSOFT WINDOWS
[5ECE402D7E12EC3750D044BF3D878DF6] MICROSOFT WINDOWS
[308F08347923DEEDE7BC03EC7D485841] MICROSOFT WINDOWS
[8125BDF7ADC261F75EF0CAD92456E350] MICROSOFT WINDOWS
[CD8F44AD342C9633C58B3917ADC06F3F] MICROSOFT WINDOWS
[BCC8C24184252E88F455FA4E893BFF20] MICROSOFT WINDOWS
[196F849F8C3FAD6A70A77790D55242E1] MICROSOFT WINDOWS
[FB9843FDF519FF36C520DC6BB3D520C8] MICROSOFT WINDOWS
[068361A7A9EFA2111F58A7B6A7F09FB6] MICROSOFT WINDOWS
[4D12DA6749429B2178C7A9EEF867DA9A] MICROSOFT WINDOWS
[E7CDD4C7C8DC34A6CA536825042F7946] MICROSOFT WINDOWS
[6130E5C1F51B75CA0B39241DAC5BA6F9] MICROSOFT WINDOWS
[EAA0B5A766E8FABB40F5D2DB226CD58E] MICROSOFT WINDOWS
[C1FF79BDD477989AE6A82DDB9520F7EE] MICROSOFT WINDOWS
[E4FF0CC27BE9672E4902DE05EFD17D30] MICROSOFT WINDOWS
[5918AA7EA238D7C79DF3EA19A327539F] MICROSOFT WINDOWS
[C3D9870E680D9D843B18F4626C3858FE] MICROSOFT WINDOWS
[04CE2C0F0759EACD886BA4B658B60D5D] MICROSOFT WINDOWS
[E6094065008FE423377294050E7CEA2D] MICROSOFT WINDOWS
[DDCDCAE28069AEDD21F25558FE3F549E] MICROSOFT WINDOWS
[D3BF2DA9216A4CF22A97820A50A67EFF] MICROSOFT WINDOWS
[ABAA5AB84E420F3C478B0591D3CF5E26] MICROSOFT WINDOWS
[C24EB837E1CF8500BBE6BD282AAA840C] MICROSOFT WINDOWS
[DD248F485177E78F4737A0A3242B2D9D] MICROSOFT WINDOWS
[427A0DE4C03B890604AACFF941B57C34] MICROSOFT WINDOWS
[9B9F520C72EE33EAEC857124BB800243] MICROSOFT WINDOWS
[1993C85962692EF7024501E7FE92D466] MICROSOFT WINDOWS
[9E3202DD11964FE4B05D89D7095BBD4B] MICROSOFT WINDOWS
[F8A52513028AC950346CEED6DD771719] MICROSOFT WINDOWS
[19382F6C0FFD6ABB340527BB4B8EDA55] NVIDIA CORPORATION
[2BBCED66D7AFC968BDBB0E4D8524DF0A] MICROSOFT WINDOWS
[9886F4C8026D37BEFAFF2B99EAC136B0] MICROSOFT WINDOWS
[CDD8EDF4C35BE6D6137112F5CC7A70DA] MICROSOFT WINDOWS
[31E6E5EB5DADCC96EF14B224E787EBEA] MICROSOFT WINDOWS
[4E951BCE60A6E22D34180489AF322E53] MICROSOFT WINDOWS
[6192765AF80C0519F8CD3DDD5166AD95] MICROSOFT WINDOWS
[D11B7FC326EEA4D412FD4D7E5117190F] MICROSOFT WINDOWS
[928B1EF93EB20E8DF05D01BF0DE41AC8] MICROSOFT WINDOWS
[C7A94D99CDF054248EFBD9B93D096DA6] MICROSOFT WINDOWS
[F931F21E4287FE3ECCF09B54A232BBA2] MICROSOFT WINDOWS
[4578ECA1FCEF4E7C787D84F78625143B] MICROSOFT WINDOWS
[D419FCF2AC6BD928B2383A4FFF15A692] MICROSOFT WINDOWS
[8E91463B087FBAB49E42049F3BE0E1B3] MICROSOFT WINDOWS
[86161A89F16851728802590EC7C92608] MICROSOFT WINDOWS
[A344054D9965A116EC99C9AE63729782] MICROSOFT WINDOWS
[8C97BD85FAFA22D2483DE56FBF7298ED] MICROSOFT WINDOWS
[7A68710BAC9B6809314B86C0CB1CBC4A] MICROSOFT WINDOWS
[7B82197BF35CC3BE59AEF8B706AB8A16] MICROSOFT WINDOWS
[5286CC0599ED8837322E6546C578047A] MICROSOFT WINDOWS
[D298D9224AE66A5E50BA55877F2B3EA9] MICROSOFT WINDOWS
[3183B161B1F05333F6C325577FEF3596] MICROSOFT WINDOWS
[5DAA644F17780FC4E3F4820A46D38FEC] MICROSOFT WINDOWS
[672724C8B21B7DC56646045DE4D5B860] MICROSOFT WINDOWS
[F66BFFD863C4397A88242C3206FB63DC] MICROSOFT WINDOWS
[4A7015195E49A3BA7DB967B277B21E9D] MICROSOFT WINDOWS
[C79CF9814E18D13BB77F74D40F06DEBE] MICROSOFT WINDOWS
[1E03C94933E088D9FAB00B49D46CC370] MICROSOFT WINDOWS
[3CD0130FFDEAEACF0905B482F3934EA3] MICROSOFT WINDOWS
[3FE129F92033059B84885E1F5D458EF3] MICROSOFT WINDOWS
[7ED53A9C37AE7ADE2A72A1C2EE86879B] MICROSOFT WINDOWS
[93718CA7CD59170FA994FEBBD87C8182] MICROSOFT WINDOWS
[D4DB6B318A0A0C74A90260725A228C0B] MICROSOFT WINDOWS
[0A0C06D77839AC86EFF2CC0250A7C53F] MICROSOFT WINDOWS
[F3714DBAA42C15F78FFCDFE4273214EB] MICROSOFT WINDOWS
[6D994905C62A6F295D1C2460FCF86D9A] MICROSOFT WINDOWS
[5F5FC52A4CE1B1C3890268EA46EB06D4] MICROSOFT WINDOWS
[C9B18904B4F50506E8A621B15666221A] MICROSOFT WINDOWS
[EFD644DD091E1D94555FC3BBC95EA66D] MICROSOFT WINDOWS
[F48535714BED7DD784853889B4594B26] MICROSOFT WINDOWS
[CF2AEB951CFC56D4F6CF2D66218B673C] MICROSOFT WINDOWS
[C09A42163878A082C3F0D0A3DFE95714] MICROSOFT WINDOWS
[E6F00415DADCEEC860E7AB42BFD19A65] MICROSOFT WINDOWS
[82CF273F0E8F243789683DEB40757569] MICROSOFT WINDOWS
[E4AC8A0D5FDCF8EA075C514FDE912098] MICROSOFT WINDOWS
[482E6BE8A07832E824080D352075ACA1] MICROSOFT WINDOWS
[57C78F5EB4D7D6427F5A43137683A245] MICROSOFT WINDOWS
[D233EAE2A9D48485321816486ED635EF] MICROSOFT WINDOWS
[0B217141AC1283655402CDB356577735] MICROSOFT WINDOWS
[01275E832DB5A5159379A9C67AF51BBF] MICROSOFT WINDOWS
[E320E11DE8152CC0EC1425FF986FE5E1] MICROSOFT WINDOWS
[30AA256A85C1A7B17A590B1C5244D28E] MICROSOFT WINDOWS
[1DFE222F8D6A422B7ADC909E0C8840DA] MICROSOFT WINDOWS
[23529A00195CE71252FEBF647E56E27D] MICROSOFT WINDOWS
[F106D2960A93059701F35243DEF6421B] MICROSOFT WINDOWS
[770458466089046624CE3CAC1F10581D] MICROSOFT WINDOWS
[D9874F8E0BF0BCA148A8829839259B5B] MICROSOFT WINDOWS
[6B515518F39854F4FDD9B8571A7304E9] MICROSOFT WINDOWS
[44758105AB3EA34E815D4B6CA1153311] MICROSOFT WINDOWS
[B97C7EC07218A8002323718202BF5E77] MICROSOFT WINDOWS
[B91FBE7CB4633FEB32AFBD0B48576396] MICROSOFT WINDOWS
[36F670D89040709013F6A460176767EC] MICROSOFT WINDOWS
[224C92E442B1B8C20C274332F1ACF00D] MICROSOFT WINDOWS
[2EE27411B5904C63D723BEA391819F58] MICROSOFT WINDOWS
[D00F7DA3612C894AF0A76A699A8BEF5C] MICROSOFT WINDOWS
[D39F3674320CE083AB894A00ED134276] MICROSOFT WINDOWS
[7F64574E8FA462425B27F98D36C4F8EB] MICROSOFT WINDOWS
[FED48B19D6F55D7A3AB498D85729D1BA] MICROSOFT WINDOWS
[D9FEA79BF6AF136F8E656AE045C2FEC8] MICROSOFT WINDOWS
[0ED2AACA902980E3A8DC04CF03739B5B] MICROSOFT WINDOWS
[3929C8FC134AC672C4F3F85160956257] MICROSOFT WINDOWS
[0E1853D3339D2963D2BC6AC1FDC1C811] MICROSOFT WINDOWS
[4D80E84AB61A0A56B682272F64047A9C] MICROSOFT WINDOWS
[5339C07E04EF056ED7F1E25F1D2F1C8A] MICROSOFT WINDOWS
[937AC47F7356554DA05D9722C356EB55] MICROSOFT WINDOWS
[2AF438EC0D361A7BBB70E604A686602C] MICROSOFT WINDOWS
[1482B8ED5CACA87992A882B853B83CEE] MICROSOFT WINDOWS
[C1F8CBE2D4843E0CCC3EFEA2EC60D4AB] MICROSOFT WINDOWS
[EC00F7D5094A5BDFAAE082DBE0E649AC] MICROSOFT WINDOWS
[3B91F35089240F6187AD681A5EC28BDE] MICROSOFT WINDOWS
[B6E4D6D468223F93632D870D842BD52B] MICROSOFT WINDOWS
[C95805E5E690B0A8FF7E8200954FC5FE] MICROSOFT WINDOWS
[E0A5C8E2CC38FDD77CB2D410FE1124DA] MICROSOFT WINDOWS
[13781908186770ABE9F8EBCC2B45B138] MICROSOFT WINDOWS
[8578F83EC5175920F2D8586FFF9DCE47] MICROSOFT WINDOWS
[7382BEEA88CC0631C1A9D7FAF102A745] MICROSOFT WINDOWS
[FEA494AC3A1BAE63C1F2AF267D49F1DB] MICROSOFT WINDOWS
[60C8376B48BA96F07AEA536527433D44] MICROSOFT WINDOWS
[A960392B1B9D20CC6308896112CE3C82] MICROSOFT WINDOWS
[4B956444AF2A352366CF59C3A4A87C64] MICROSOFT WINDOWS
[0CB6D7CC1881D055C54242D032B7C874] MICROSOFT WINDOWS
[6CDA3536F6BAB7896A57EAB7DC07F379] MICROSOFT WINDOWS
[85B548343071325CAE75847E3E5DEE5D] MICROSOFT WINDOWS
[C72DFA81684D685A3C8532102BD10B74] MICROSOFT WINDOWS
[BAB449E496892494C1E8152A25A1E867] MICROSOFT WINDOWS
[A39AFDD26E6F2E5595FF2D3997D7E1FE] MICROSOFT WINDOWS
[5CFA1B3D6417449F98D040DEDBD14A4C] MICROSOFT WINDOWS
[C1B1FFC800BE2F31EB2CF8CB40629C69] MICROSOFT WINDOWS
[F8888D8CCECAA7B77CCAEABA901AB874] MICROSOFT WINDOWS
[8B4B4A866956637DBED47D393C8B2350] MICROSOFT WINDOWS
[41C2E66EDF2118CAF328ACA1D67055CE] MICROSOFT WINDOWS
[70D165B3EA8BC576828DC2B964C8D116] MICROSOFT WINDOWS
[DDA66AEF89DAC320A85AECCB4369D2E7] MICROSOFT WINDOWS
[76C1CC611352499326001F25A3ED15F8] MICROSOFT WINDOWS
[1483BE4D0135C378CB61D3CD73AB3E03] MICROSOFT WINDOWS
[C2F7834269D565263C65757EDE37A66C] MICROSOFT WINDOWS
[31BAA1524D10843EA325743059B8334D] MICROSOFT WINDOWS
[A541A823601197A440C75A71FA5AA373] MICROSOFT WINDOWS
[3CDDFF6CAD962C5EF1C52FD667C358B6] MICROSOFT WINDOWS
[D8E539426644A0F23CBF53DD0A5EE079] MICROSOFT WINDOWS
[CD49CA8E3280ACEEC5ECF431A59F5EFD] MICROSOFT WINDOWS
[8413D292CD1B27D6B6127B90697F2B1C] MICROSOFT WINDOWS
[8C521D161445C3E1F38A494E7649E70D] MICROSOFT WINDOWS
[CA10C91D802ABE6E5136E2168C2CD2B4] MICROSOFT WINDOWS
[D50645235A507B0546B1B5CF7D0B8849] MICROSOFT WINDOWS
[E7A7E8803E66B7CCED95D327A4DBC135] MICROSOFT WINDOWS
[CA7112DF5736B6627F8E353E96071398] MICROSOFT WINDOWS
[3570C4E14F85CE0B537D126727ACA91C] MICROSOFT WINDOWS
[1785F9C96A0BDEC1F6E0C79EF412F342] MICROSOFT WINDOWS
[B9175D63527B05131F2FA504CF0265F2] MICROSOFT WINDOWS
[9BD1998FF417055D13829165618373C9] MICROSOFT WINDOWS
[162FDC2DCD4C3FD06FCA6BD1D11F4798] MICROSOFT WINDOWS
[441C509DCDD8B095EC2342546BAF638F] MICROSOFT WINDOWS
[B154618505A6A9026EFA6AB8C4123BF1] MICROSOFT WINDOWS
[505F32DE573ECEDF398DB9E2FC0D5E45] MICROSOFT WINDOWS
[B78E0A446015AC08986E38CFF9E43A42] MICROSOFT WINDOWS
[0EB603B0B43F70608D8AC643C6DA6D47] MICROSOFT WINDOWS
[CF3BDF9EAD8D3EF671E9339B44B185BA] MICROSOFT WINDOWS
[4E330AD1EED4A5D582EE415FD55953A2] MICROSOFT WINDOWS
[0B26E253E4FB736309006BDF88400BBA] MICROSOFT WINDOWS
[2B44C579773DEC3AD0D3F9F73E0D676D] MICROSOFT WINDOWS
[99A19C9A74E2F9820E501DCE77F84F70] MICROSOFT WINDOWS
[CB440E1C4EC9C369EC9DD07B48A83F36] MICROSOFT WINDOWS
[CBA1A726FF14C960845B61F787D0A2CB] MICROSOFT WINDOWS
[FE82F7FEAD7B319CF6501E01B6F56CF6] MICROSOFT WINDOWS
[33DBBCF71F68EA97D9FD34E4C9AB5AC6] MICROSOFT WINDOWS
[C741858C36DBB08D868EAB3C7EAD87D3] MICROSOFT WINDOWS
[BBAB21FDBCA80743710062D8E3806286] MICROSOFT WINDOWS
[BAFDD52CE6D1DFF28FD8EF19064F4789] MICROSOFT WINDOWS
[9BBCB2C1CAC372FF6BA55CE56842A937] MICROSOFT WINDOWS
[C7C91FB86A3C6CD7619725A88ED1884C] MICROSOFT WINDOWS
[9A0E0B836413EB0BC885532D2A5389D6] MICROSOFT WINDOWS
[DC7A6A5F9CE7F1C825E11BC296447CC4] MICROSOFT WINDOWS
[252C60BDB56F0C99D511C6B284DF5F4E] MICROSOFT WINDOWS
[05B454451B82A20D925A727E5CAE4DD6] MICROSOFT WINDOWS
[1EA1FD0332B21F11D424FD5114EA9F2F] MICROSOFT WINDOWS
[533CF910870330354DBFDECF0869E2E2] MICROSOFT WINDOWS
[47F6450F28BAA32B2AB0D6BE00996249] MICROSOFT WINDOWS
[60448819208208629F2C5ED3882F8079] MICROSOFT WINDOWS
[7EF75102A793AAA6AAA45A4F7C15FF4D] MICROSOFT WINDOWS
[9A3F176A793C68961774A79457F59ADC] MICROSOFT WINDOWS
[1A8D9EA4DD1A3E276B85EDB05B42BEC7] MICROSOFT WINDOWS
[F4C2BEF4F33E5CD160EDBDBA4800B5B0] MICROSOFT WINDOWS
[EBC4935445CA5A3D4D898076642EC618] MICROSOFT WINDOWS
[7850D58EE55539B703EA883D375D2D70] MICROSOFT WINDOWS
[5B3B4FBBACE6A551A7A23F2A97A708EE] MICROSOFT WINDOWS
[C1A05F68C92A8B9D4D5A3D4953427154] MICROSOFT WINDOWS
[5CC081B65046E5DE37DCDD1C0AB99FE4] MICROSOFT WINDOWS
[9E24D897754566125D3303B820122366] MICROSOFT WINDOWS
[C165A15FF793D822EB28D6FFC088092C] MICROSOFT WINDOWS
[E49BF2E02840BF204F4A7F9EA60FF2EC] MICROSOFT WINDOWS
[D872C2EB274CACF5E3CEC4932355DB2B] MICROSOFT WINDOWS
[5A762B4157DE7E1A035897CE30B46708] MICROSOFT WINDOWS
[21952ADDD6E80648E97BDCAE4A231A2B] MICROSOFT WINDOWS
[9618E4752B19CE24EFD729C662C8DB1E] MICROSOFT WINDOWS
[AC1E3E0991DFA564BE304F569B01D3F2] MICROSOFT WINDOWS
[8E6958813B6FAAFF8A6EE9F2A7040299] MICROSOFT WINDOWS
[390E89B590BF63EEBF88ABC15078A198] MICROSOFT WINDOWS
[A8C6FCB5A946AB8A9553F43529DFDA9A] MICROSOFT WINDOWS
[5AC0EC99D9BC23FE97E8F8851DDB660C] MICROSOFT WINDOWS
[CB5343FF52A702A9ACFAAE6BE972FE09] MICROSOFT WINDOWS
[3F0F179C20F3633D2EC06774430BA831] MICROSOFT WINDOWS
[6EDB3C97D8D015F04A2C61CD31DCB057] MICROSOFT WINDOWS
[EDA94BE1F9E05B9C125484FB5EDD0E3A] MICROSOFT WINDOWS
[6B408458867BF3B61F363C0EB423F87F] MICROSOFT WINDOWS
[453C23668FD9F3B8720379AD2B0EA5CF] MICROSOFT WINDOWS
[A06EC8D96CAFDA2FFEB9B8552099BBA7] MICROSOFT CORPORATION
===