Вы находитесь на странице: 1из 124

SpyHolesList Version:12.2 Build:8.12.0.

512-64b
12.07.2016 10:20:49 AM
WinDir=C:\Windows
Startup=C:\Users\bammi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Sta
rtup\
Common Startup=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Windows 10 Pro (10.0.10586)
Internet Explorer 9.11.10586.0
DBS Version: 1.654
[Internet Explorer]
[Default Home Page] :HKLM Default_Page_URL=http://go.microsoft.com/fwlink/p/?L
inkId=255141
[Current Home Page] :HKCU Start Page=about:blank
[Current Home Page] :HKCU HOMEOldSP=""
[Current Home Page] :HKCU Default_Page_URL=""
[Current Home Page] :HKLM Start Page=about:blank
[Current Home Page] :HKLM HOMEOldSP=""
[All Users Search] :HKLM Default_Search_URL=http://go.microsoft.com/fwlink/?Li
nkId=54896
[All Users Search] :HKLM Search Page=http://go.microsoft.com/fwlink/?LinkId=54
896
[Current Home Page(x64)] :HKLM Start Page=about:blank
[Current Home Page(x64)] :HKLM HOMEOldSP=""
[All Users Search(x64)] :HKLM Default_Search_URL=http://go.microsoft.com/fwlin
k/?LinkId=54896
[All Users Search(x64)] :HKLM Search Page=http://go.microsoft.com/fwlink/?Link
Id=54896
[Current Users Search] :HKCU Default_Search_URL=""
[Current Users Search] :HKCU Search Page=http://go.microsoft.com/fwlink/?LinkI
d=54896
[Current Users Search] :HKCU Search Bar=""
[IE Local Blank Page] :HKCU Local Page=%11%\blank.htm
[IE Local Blank Page] :HKLM Local Page=C:\Windows\SysWOW64\blank.htm
[Browser Helper Objects] {03993315-5CE9-4F00-8790-D14A94F1D91A}=C:\PROGRAM FIL
ES (X86)\KASPERSKY LAB\KASPERSKY INTERNET SECURITY 16.0.1\IEEXT\IE_PLUGIN.DLL
### Kaspersky Protection plugins AO Kaspersky Lab Plugins PDK 4.6.1.201
[Browser Helper Objects] {31D09BA0-12F5-4CCE-BE8A-2923E76605DA}=C:\PROGRAM FIL
ES (X86)\MICROSOFT OFFICE\OFFICE16\OCHELPER.DLL
### Skype for Business Microsoft Corporation Microsoft Office 2016 16.0.4266.1
001
[Browser Helper Objects] {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}=C:\PROGRA~2\MI
CROS~1\OFFICE16\GROOVEEX.DLL
### Microsoft OneDrive for Business Extensions Microsoft Corporation Microsoft
Office 2016 16.0.4266.1001
[Browser Helper Objects(x64)] {03993315-5CE9-4F00-8790-D14A94F1D91A}=C:\PROGRA
M FILES (X86)\KASPERSKY LAB\KASPERSKY INTERNET SECURITY 16.0.1\X64\IEEXT\IE_PLUG
IN.DLL
### Kaspersky Protection plugins AO Kaspersky Lab Plugins PDK 4.6.1.201
[Browser Helper Objects(x64)] {10921475-03CE-4E04-90CE-E2E7EF20C814}=C:\PROGRA
M FILES (X86)\IOBIT\IOBIT UNINSTALLER\UNINSTALLEXPLORER.DLL
### Uninstall for explorer IObit Uninstall Programs 1.0.0.0
[Browser Helper Objects(x64)] {31D09BA0-12F5-4CCE-BE8A-2923E76605DA}=C:\PROGRA
M FILES\MICROSOFT OFFICE\OFFICE16\OCHELPER.DLL
### Skype for Business Microsoft Corporation Microsoft Office 2016 16.0.4266.1
001
[Browser Helper Objects(x64)] {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}=C:\PROGRA
~1\MICROS~1\OFFICE16\GROOVEEX.DLL
### Microsoft OneDrive for Business Extensions Microsoft Corporation Microsoft
Office 2016 16.0.4266.1001
[Auto Search URL] :HKCU provider=""

[Auto Search URL] :HKCU "Default Value"=""


[Search Assistant] :HKCU SearchAssistant=""
[Search Assistant] :HKLM SearchAssistant=""
[Search Assistant] :HKCU CustomizeSearch=""
[Search Assistant] :HKLM CustomizeSearch=""
[Search Provider for All Users] {0633EE93-D776-472f-A0FF-E1416B8B2E3A}=http://
www.bing.com/search?q={searchTerms}&FORM=IE8SRC
### Bing
[Search Provider for All Users] DefaultScope={0633EE93-D776-472f-A0FF-E1416B8B
2E3A}
[Search Provider for All Users(x64)] {0633EE93-D776-472f-A0FF-E1416B8B2E3A}=ht
tp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
### Bing
[Search Provider for All Users(x64)] DefaultScope={0633EE93-D776-472f-A0FF-E14
16B8B2E3A}
[CustomizeSearch] :HKLM CustomizeSearch=""
[URLSearchHook] :HKCU {CFBFAE00-17A6-11D0-99CB-00C04FD64497}=C:\WINDOWS\SYSWOW
64\IEFRAME.DLL
### Internet Browser Microsoft Corporation Internet Explorer 11.00.10586.17
[Search URL Template] :HKLM 1=""
[Search URL Template] :HKLM 2=""
[Search URL Template] :HKLM 3=""
[Search URL Template] :HKLM 4=""
[Default Prefix] :HKLM "Default Value"=http://
[URL Default Prefixes] :HKLM ftp=ftp://
[URL Default Prefixes] :HKLM home=http://
[URL Default Prefixes] :HKLM mosaic=http://
[URL Default Prefixes] :HKLM www=http://
[AboutURLs] :HKLM blank=res://mshtml.dll/blank.htm
[AboutURLs] :HKLM DesktopItemNavigationFailure=res://ieframe.dll/navcancl.htm
[AboutURLs] :HKLM Home=270
[AboutURLs] :HKLM InPrivate=res://ieframe.dll/inprivate.htm
[AboutURLs] :HKLM NavigationCanceled=res://ieframe.dll/navcancl.htm
[AboutURLs] :HKLM NavigationFailure=res://ieframe.dll/navcancl.htm
[AboutURLs] :HKLM NoAdd-ons=res://ieframe.dll/noaddon.htm
[AboutURLs] :HKLM NoAdd-onsInfo=res://ieframe.dll/noaddoninfo.htm
[AboutURLs] :HKLM PostNotCached=res://ieframe.dll/repost.htm
[AboutURLs] :HKLM SecurityRisk=res://ieframe.dll/securityatrisk.htm
[Registry IE Policy] :HKLM \Software\Policies\Microsoft\Internet Explorer\INFO
DELIVERY\Restrictions\NoUpdateCheck=0
[User Style Sheet] :HKCU User Stylesheet=""
[User Style Sheet] :HKCU Use My Stylesheet=0
[Execute unsigned ActiveX in My Computer Zone] :HKCU 1201=0
[Execute unsigned ActiveX in My Computer Zone] :HKLM 1201=1
[Execute unsigned ActiveX in Local Intranet Zone] :HKCU 1201=0
[Execute unsigned ActiveX in Local Intranet Zone] :HKLM 1201=3
[Execute unsigned ActiveX in Internet Zone] :HKCU 1201=3
[Execute unsigned ActiveX in Internet Zone] :HKLM 1201=3
[Links Toolbar] :HKCU LinksFolderName=""
[Toolbars] :HKLM {001032CB-B0AC-4F2C-A650-AD4B2B26E5DA}=C:\PROGRAM FILES (X86)
\KASPERSKY LAB\KASPERSKY INTERNET SECURITY 16.0.1\IEEXT\IE_PLUGIN.DLL
### Kaspersky Protection plugins AO Kaspersky Lab Plugins PDK 4.6.1.201
[Toolbars(x64)] :HKLM {001032CB-B0AC-4F2C-A650-AD4B2B26E5DA}=C:\PROGRAM FILES
(X86)\KASPERSKY LAB\KASPERSKY INTERNET SECURITY 16.0.1\X64\IEEXT\IE_PLUGIN.DLL
### Kaspersky Protection plugins AO Kaspersky Lab Plugins PDK 4.6.1.201
[IE Extensions - All Users] :HKLM {2670000A-7350-4f3c-8081-5663EE0C6C49}
### File is deleted or hidden by a rootkit or could not be located.
[IE Extensions - All Users] :HKLM {31D09BA0-12F5-4CCE-BE8A-2923E76605DA}=C:\PR
OGRAM FILES (X86)\MICROSOFT OFFICE\OFFICE16\OCHELPER.DLL
### Skype for Business Microsoft Corporation Microsoft Office 2016 16.0.4266.1

001
[IE Extensions - All Users] :HKLM {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}
### File is deleted or hidden by a rootkit or could not be located.
[Context menu items] :HKCU E&xport to Microsoft Excel=res://C:\PROGRA~1\MICROS
~1\Office16\EXCEL.EXE/3000
### File is deleted or hidden by a rootkit or could not be located.
[Context menu items] :HKCU Se&nd to OneNote=res://C:\PROGRA~1\MICROS~1\Office1
6\ONBttnIE.dll/105
### File is deleted or hidden by a rootkit or could not be located.
[AutoConfigURL] :HKCU AutoConfigURL=""
[Protocols Filter] :HKLM text/xml=C:\PROGRAM FILES (X86)\COMMON FILES\MICROSOF
T SHARED\OFFICE16\MSOXMLMF.DLL
### Microsoft Office XML MIME Filter Microsoft Corporation Microsoft Office In
foPath 16.0.4266.1001
[Protocols Handler] :HKLM about=C:\WINDOWS\SYSWOW64\MSHTML.DLL
### Microsoft (R) HTML Viewer Microsoft Corporation Internet Explorer 11.00.10
586.0
[Protocols Handler] :HKLM cdl=C:\WINDOWS\SYSWOW64\URLMON.DLL
### OLE32 Extensions for Win32 Microsoft Corporation Internet Explorer 11.00.1
0586.0
[Protocols Handler] :HKLM dvd=C:\WINDOWS\SYSWOW64\MSVIDCTL.DLL
### ActiveX control for streaming video Microsoft Corporation DirectShow 6.5.1
0586.0
[Protocols Handler] :HKLM file=C:\WINDOWS\SYSWOW64\URLMON.DLL
### OLE32 Extensions for Win32 Microsoft Corporation Internet Explorer 11.00.1
0586.0
[Protocols Handler] :HKLM ftp=C:\WINDOWS\SYSWOW64\URLMON.DLL
### OLE32 Extensions for Win32 Microsoft Corporation Internet Explorer 11.00.1
0586.0
[Protocols Handler] :HKLM http=C:\WINDOWS\SYSWOW64\URLMON.DLL
### OLE32 Extensions for Win32 Microsoft Corporation Internet Explorer 11.00.1
0586.0
[Protocols Handler] :HKLM https=C:\WINDOWS\SYSWOW64\URLMON.DLL
### OLE32 Extensions for Win32 Microsoft Corporation Internet Explorer 11.00.1
0586.0
[Protocols Handler] :HKLM its=C:\WINDOWS\SYSWOW64\ITSS.DLL
### Microsoft InfoTech Storage System Library Microsoft Corporation Microsoft Wi
ndows Operating System 10.0.10586.0
[Protocols Handler] :HKLM javascript=C:\WINDOWS\SYSWOW64\MSHTML.DLL
### Microsoft (R) HTML Viewer Microsoft Corporation Internet Explorer 11.00.10
586.0
[Protocols Handler] :HKLM local=C:\WINDOWS\SYSWOW64\URLMON.DLL
### OLE32 Extensions for Win32 Microsoft Corporation Internet Explorer 11.00.1
0586.0
[Protocols Handler] :HKLM mailto=C:\WINDOWS\SYSWOW64\MSHTML.DLL
### Microsoft (R) HTML Viewer Microsoft Corporation Internet Explorer 11.00.10
586.0
[Protocols Handler] :HKLM mhtml=C:\WINDOWS\SYSWOW64\INETCOMM.DLL
### Microsoft Internet Messaging API Resources Microsoft Corporation Microsoft
Windows Operating System 10.0.10586.0
[Protocols Handler] :HKLM mk=C:\WINDOWS\SYSWOW64\URLMON.DLL
### OLE32 Extensions for Win32 Microsoft Corporation Internet Explorer 11.00.1
0586.0
[Protocols Handler] :HKLM ms-help={314111c7-a502-11d2-bbca-00c04f8ec294}
[Protocols Handler] :HKLM ms-its=C:\WINDOWS\SYSWOW64\ITSS.DLL
### Microsoft InfoTech Storage System Library Microsoft Corporation Microsoft Wi
ndows Operating System 10.0.10586.0
[Protocols Handler] :HKLM mso-minsb.16=C:\PROGRAM FILES (X86)\MICROSOFT OFFICE
\OFFICE16\MSOSB.DLL
### Microsoft Office 2016 component Microsoft Corporation Microsoft Office 201

6 16.0.4266.1001
[Protocols Handler] :HKLM osf.16=C:\PROGRAM FILES (X86)\MICROSOFT OFFICE\OFFIC
E16\MSOSB.DLL
### Microsoft Office 2016 component Microsoft Corporation Microsoft Office 201
6 16.0.4266.1001
[Protocols Handler] :HKLM res=C:\WINDOWS\SYSWOW64\MSHTML.DLL
### Microsoft (R) HTML Viewer Microsoft Corporation Internet Explorer 11.00.10
586.0
[Protocols Handler] :HKLM tbauth=C:\WINDOWS\SYSWOW64\TBAUTH.DLL
### TBAuth protocol handler Microsoft Corporation Microsoft Windows Operating Sy
stem 10.0.10586.212
[Protocols Handler] :HKLM tv=C:\WINDOWS\SYSWOW64\MSVIDCTL.DLL
### ActiveX control for streaming video Microsoft Corporation DirectShow 6.5.1
0586.0
[Protocols Handler] :HKLM vbscript=C:\WINDOWS\SYSWOW64\MSHTML.DLL
### Microsoft (R) HTML Viewer Microsoft Corporation Internet Explorer 11.00.10
586.0
[Protocols Handler] :HKLM windows.tbauth=C:\WINDOWS\SYSWOW64\TBAUTH.DLL
### TBAuth protocol handler Microsoft Corporation Microsoft Windows Operating Sy
stem 10.0.10586.212
[Proxy] :HKCU ProxyServer=""
[Proxy] :HKCU ProxyEnable=0
[Network Settings]
[Hosts File Path] :HKLM DataBasePath=%SystemRoot%\System32\drivers\etc
[Browsers]
[Installed Browsers] Google Chrome=C:\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLIC
ATION\CHROME.EXE
### Google Chrome Google Inc. Google Chrome 51.0.2704.106
[Installed Browsers] IEXPLORE.EXE=C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.
EXE
### Default Browser
Internet Explorer Microsoft Corporation Internet Explorer 11.00.10586.0
[Google Chrome Settings] :HKLM backup.homepage=""
[Google Chrome Settings] :HKLM backup.session.urls_to_restore_on_startup=""
[Google Chrome Settings] :HKLM session.startup_urls=""
[Google Chrome Settings] :HKLM default_search_provider.icon_url=""
[Google Chrome Settings] :HKLM default_search_provider.keyword=""
[Google Chrome Settings] :HKLM default_search_provider.name=""
[Google Chrome Settings] :HKLM default_search_provider.search_url=""
[Google Chrome Settings] :HKLM default_search_provider.suggest_url=""
[Google Chrome Settings] :HKLM default_search_provider_data.template_url_data.
alternate_urls=""
[Google Chrome Settings] :HKLM default_search_provider_data.template_url_data.
favicon_url=""
[Google Chrome Settings] :HKLM default_search_provider_data.template_url_data.
keyword=""
[Google Chrome Settings] :HKLM default_search_provider_data.template_url_data.
short_name=""
[Google Chrome Settings] :HKLM default_search_provider_data.template_url_data.
url=""
[Google Chrome Settings] :HKLM default_search_provider_data.template_url_data.
suggest_url=""
[Google Chrome Settings] :HKLM default_search_provider_data.template_url_data.
new_tab_url=""
[Google Chrome Settings] :HKLM default_search_provider_data.template_url_data.
instant_url=""
[Google Chrome Settings] :HKLM default_search_provider_data.template_url_data.
image_url=""
[Google Chrome Settings] :HKLM homepage=""
[Google Chrome Settings] :HKLM session.urls_to_restore_on_startup=""

[Google Chrome Addons] felcaaldnbdncclmgdcncolpebgiejap=C:\Users\bammi\AppData


\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiej
ap\1.1_0
### Google Sheets: Create and edit spreadsheets update_url: https://clients2.g
oogle.com/service/update2/crx
[Google Chrome Addons] eemcgdkfndhakfknompkggombfjjjeno=C:\Program Files (x86)
\Google\Chrome\Application\51.0.2704.106\resources\bookmark_manager
### Bookmark Manager: Bookmark Manager
[Google Chrome Addons] ennkphjdgehloodpbhlhldgbnhmacadg=C:\Program Files (x86)
\Google\Chrome\Application\51.0.2704.106\resources\settings_app
### Settings: Settings
[Google Chrome Addons] lpeeaghdjmhlakojjcgfdhgcejdaefmi=C:\Users\bammi\AppData
\Local\Google\Chrome\User Data\Default\Extensions\lpeeaghdjmhlakojjcgfdhgcejdaef
mi\4.6.1.170_0
### Kaspersky Protection: Your protection on the Internet with extension from
Kaspersky Lab update_url: https://clients2.google.com/service/update2/crx
[Google Chrome Addons] pjkljhegncpnkpknbcohdijeoejaedia=C:\Users\bammi\AppData
\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaed
ia\8.1_0
### Gmail: Fast, searchable email with less spam. update_url: http://clients2.
google.com/service/update2/crx
[Google Chrome Addons] ahfgeienlihckogmohjhadlkjgocpleb=C:\Program Files (x86)
\Google\Chrome\Application\51.0.2704.106\resources\web_store
### Web Store: Discover great apps, games, extensions and themes for Google Ch
rome.
[Google Chrome Addons] aapocclcgogkmnckokdopfmhonfmgoek=C:\Users\bammi\AppData
\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgo
ek\0.9_0
### Google Slides: Create and edit presentations update_url: https://clients2
.google.com/service/update2/crx
[Google Chrome Addons] aohghmighlieiainnegkcijnfilokake=C:\Users\bammi\AppData
\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfiloka
ke\0.9_0
### Google Docs: Create and edit documents update_url: https://clients2.googl
e.com/service/update2/crx
[Google Chrome Addons] kmendfapggjehodndflmmgagdbamhnfd=C:\Program Files (x86)
\Google\Chrome\Application\51.0.2704.106\resources\cryptotoken
### CryptoTokenExtension: CryptoToken Component Extension
[Google Chrome Addons] mhjfbmdgcfjbbpaeojofohoefgiehjai=C:\Program Files (x86)
\Google\Chrome\Application\51.0.2704.106\resources\pdf
### Chrome PDF Viewer:
[Google Chrome Addons] apdfllckaahabafndbhieahigkjlhalf=C:\Users\bammi\AppData
\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlha
lf\14.1_0
### Google Drive: Google Drive: create, share and keep all your stuff in one p
lace. update_url: https://clients2.google.com/service/update2/crx
[Google Chrome Addons] neajdppkdcdipfabeoofebfddakdcjhd=C:\Program Files (x86)
\Google\Chrome\Application\51.0.2704.106\resources\network_speech_synthesis
### Google Network Speech: Component extension providing speech via the Google
network text-to-speech service.
[Google Chrome Addons] nkeimhogjdpnpccoofpliimaahmaaome=C:\Program Files (x86)
\Google\Chrome\Application\51.0.2704.106\resources\hangout_services
### Google Hangouts:
[Google Chrome Addons] ghbmnnjooekpmoecnnnilnnbdlolhkhi=C:\Users\bammi\AppData
\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhk
hi\1.4_1
### Google Docs Offline: Get things done offline with the Google Docs family o
f products. update_url: https://clients2.google.com/service/update2/crx
[Google Chrome Addons] gfdkimpbcpahaombhbimeihdjnejgicl=C:\Program Files (x86)
\Google\Chrome\Application\51.0.2704.106\resources\feedback

### Feedback: User feedback extension


[Google Chrome Addons] mfehgcgbbipciphmccgaenjidiccnmng=C:\Program Files (x86)
\Google\Chrome\Application\51.0.2704.106\resources\cloud_print
### Cloud Print: Cloud Print
[Google Chrome Addons] nmmhkkegccagdldgiimedpiccmgmieda=C:\Users\bammi\AppData
\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmie
da\1.0.0.0_0
### Chrome Web Store Payments: Chrome Web Store Payments update_url: https://c
lients2.google.com/service/update2/crx
[Google Chrome Addons] blpcfgokakmgnkcojhhkbfbldkacnbeo=C:\Users\bammi\AppData
\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnb
eo\4.2.8_0
### YouTube: update_url: http://clients2.google.com/service/update2/crx
[Google Chrome Addons] mgndgikekgjfcpckkfioiadnlibdjbkf=C:\Program Files (x86)
\Google\Chrome\Application\51.0.2704.106\resources\chrome_app
### Chrome: A fast, simple, and secure web browser, built for the modern web.
[Google Chrome Addons] lpeeaghdjmhlakojjcgfdhgcejdaefmi=C:\Users\bammi\AppData
\Local\Google\Chrome\User Data\Default\Extensions\HTTPS://CHROME.GOOGLE.COM/WEBS
TORE/DETAIL/LPEEAGHDJMHLAKOJJCGFDHGCEJDAEFMI
### Kaspersky Protection: Your protection on the Internet with extension from
Kaspersky Lab
[Network Settings]
[Domain Name] :HKLM Domain=""
[Name Server] {dd8618d4-567f-4022-b898-6def979b4559}=192.168.8.1 192.168.8.1
### DHCPNameServer:192.168.8.1 192.168.8.1 DhcpDefaultGateway:192.168.8.1
DhcpServer:192.168.8.1
[WinSock2 Components] napinsp.dll=C:\WINDOWS\SYSWOW64\NAPINSP.DLL
### E-mail Naming Shim Provider Microsoft Corporation Microsoft Windows Operatin
g System 10.0.10586.0 C:\WINDOWS\SYSWOW64\NAPINSP.DLL
[WinSock2 Components] pnrpnsp.dll=C:\WINDOWS\SYSWOW64\PNRPNSP.DLL
### PNRP Name Space Provider Microsoft Corporation Microsoft Windows Operating S
ystem 10.0.10586.0 C:\WINDOWS\SYSWOW64\PNRPNSP.DLL
[WinSock2 Components] NLAapi.dll=C:\WINDOWS\SYSWOW64\NLAAPI.DLL
### Network Location Awareness 2 Microsoft Corporation Microsoft Windows Operati
ng System 10.0.10586.0 C:\WINDOWS\SYSWOW64\NLAAPI.DLL
[WinSock2 Components] mswsock.dll=C:\WINDOWS\SYSWOW64\MSWSOCK.DLL
### Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation Micro
soft Windows Operating System 10.0.10586.0 C:\WINDOWS\SYSWOW64\MSWSOCK.DLL
[WinSock2 Components] winrnr.dll=C:\WINDOWS\SYSWOW64\WINRNR.DLL
### LDAP RnR Provider DLL Microsoft Corporation Microsoft Windows Operating Syst
em 10.0.10586.0 C:\WINDOWS\SYSWOW64\WINRNR.DLL
[WinSock2 Components] wshbth.dll=C:\WINDOWS\SYSWOW64\WSHBTH.DLL
### Windows Sockets Helper DLL Microsoft Corporation Microsoft Windows Operating
System 10.0.10586.306 C:\WINDOWS\SYSWOW64\WSHBTH.DLL
[WinSock2 Components (x64)] napinsp.dll=C:\WINDOWS\SYSNATIVE\NAPINSP.DLL
### E-mail Naming Shim Provider Microsoft Corporation Microsoft Windows Operatin
g System 10.0.10586.0 C:\WINDOWS\SYSNATIVE\NAPINSP.DLL
[WinSock2 Components (x64)] pnrpnsp.dll=C:\WINDOWS\SYSNATIVE\PNRPNSP.DLL
### PNRP Name Space Provider Microsoft Corporation Microsoft Windows Operating S
ystem 10.0.10586.0 C:\WINDOWS\SYSNATIVE\PNRPNSP.DLL
[WinSock2 Components (x64)] NLAapi.dll=C:\WINDOWS\SYSNATIVE\NLAAPI.DLL
### Network Location Awareness 2 Microsoft Corporation Microsoft Windows Operati
ng System 10.0.10586.0 C:\WINDOWS\SYSNATIVE\NLAAPI.DLL
[WinSock2 Components (x64)] mswsock.dll=C:\WINDOWS\SYSNATIVE\MSWSOCK.DLL
### Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation Micro
soft Windows Operating System 10.0.10586.0 C:\WINDOWS\SYSNATIVE\MSWSOCK.DLL
[WinSock2 Components (x64)] winrnr.dll=C:\WINDOWS\SYSNATIVE\WINRNR.DLL
### LDAP RnR Provider DLL Microsoft Corporation Microsoft Windows Operating Syst
em 10.0.10586.0 C:\WINDOWS\SYSNATIVE\WINRNR.DLL
[WinSock2 Components (x64)] wshbth.dll=C:\WINDOWS\SYSNATIVE\WSHBTH.DLL

### Windows Sockets Helper DLL Microsoft Corporation Microsoft Windows Operating
System 10.0.10586.306 C:\WINDOWS\SYSNATIVE\WSHBTH.DLL
[Windows Shell]
[Display Scrap's Extensions] :HKLM NeverShowExt=""
[ScreenSaver] :HKCU SCRNSAVE.EXE=""
### File is deleted or hidden by a rootkit or could not be located.
[System.ini] shell=explorer.exe
[User Shell] :HKCU shell=""
[Internet Shortcuts] :HKLM C:\ProgramData\Microsoft\Windows\Start Menu\Program
s\UnHackMe\Check for UnHackMe updates.lnk=HTTP://GREATIS.COM/UNHACKME.INI
### C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\UnHackMe\CHECKF~1.LNK
[User Shortcuts] :HKLM C:\Users\bammi\Desktop\UnHackMe.lnk=C:\Program Files (x
86)\UnHackMe\Unhackme.exe
### C:\Users\bammi\Desktop\UnHackMe.lnk
[User Shortcuts] :HKLM C:\Users\Public\Desktop\Safe Money.lnk=C:\Program Files
(x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.1\avpui.exe
### C:\Users\Public\Desktop\SAFEMO~1.LNK ?-safebanking
[User Shortcuts] :HKLM C:\Users\Public\Desktop\SHAREit.lnk=C:\Program Files (x
86)\SHAREit\SHAREit\SHAREit.exe
### C:\Users\Public\Desktop\SHAREit.lnk
[User Shortcuts] :HKLM C:\Users\bammi\AppData\Roaming\Microsoft\Internet Explo
rer\Quick Launch\Google Chrome.lnk=C:\Program Files (x86)\Google\Chrome\Applicat
ion\chrome.exe
### C:\Users\bammi\AppData\Roaming\MICROS~1\INTERN~1\QUICKL~1\GOOGLE~1.LNK
[User Shortcuts] :HKLM C:\Users\bammi\AppData\Roaming\Microsoft\Internet Explo
rer\Quick Launch\Shows Desktop.lnk
### C:\Users\bammi\AppData\Roaming\MICROS~1\INTERN~1\QUICKL~1\SHOWSD~1.LNK
[User Shortcuts] :HKLM C:\Users\bammi\AppData\Roaming\Microsoft\Internet Explo
rer\Quick Launch\User Pinned\TaskBar\File Explorer.lnk
### C:\Users\bammi\AppData\Roaming\MICROS~1\INTERN~1\QUICKL~1\USERPI~1\TaskBar
\FILEEX~1.LNK
[User Shortcuts] :HKLM C:\Users\bammi\AppData\Roaming\Microsoft\Internet Explo
rer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk=C:\Program Files (x86)\Go
ogle\Chrome\Application\chrome.exe
### C:\Users\bammi\AppData\Roaming\MICROS~1\INTERN~1\QUICKL~1\USERPI~1\TaskBar
\GOOGLE~1.LNK
[User Shortcuts] :HKLM C:\Users\bammi\AppData\Roaming\Microsoft\Internet Explo
rer\Quick Launch\Window Switcher.lnk
### C:\Users\bammi\AppData\Roaming\MICROS~1\INTERN~1\QUICKL~1\WINDOW~1.LNK
[User Shortcuts] :HKLM C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Go
ogle Chrome.lnk=C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
### C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\GOOGLE~1.LNK
[User Shortcuts] :HKLM C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ka
spersky Internet Security\Kaspersky Internet Security Help.lnk=C:\Program Files
(x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.1\Doc\en-IN\kis\context.chm
### C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\KASPER~1\KASPER~1.LNK
[User Shortcuts] :HKLM C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ka
spersky Internet Security\Kaspersky Internet Security.lnk=C:\Program Files (x86)
\Kaspersky Lab\Kaspersky Internet Security 16.0.1\avpui.exe
### C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\KASPER~1\KASPER~2.LNK
[User Shortcuts] :HKLM C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ka
spersky Internet Security\Remove Kaspersky Internet Security.lnk=C:\Windows\SysW
OW64\msiexec.exe
### C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\KASPER~1\REMOVE~1.LNK ?/i{F
575F386-57EF-4943-B003-A13F13B05EEB} REMOVE=ALL
[Main File Extensions] :HKLM .exe=""
[Main File Extensions] :HKLM .com=""
[Main File Extensions] :HKLM .pif=""
[Main File Extensions] :HKLM .bat=""
[Main File Extensions] :HKLM .cmd=""

[Main File Extensions] :HKLM .scr=""


[Main File Extensions] :HKLM .txt=""
[Main File Extensions] :HKLM .reg=""
[Main File Extensions] :HKLM .inf=""
[Main File Extensions] :HKLM .ini=""
[Main File Extensions] :HKLM .js=""
[Main File Extensions] :HKLM .vbs=""
[Main File Extensions] :HKLM .vbe=""
[Main File Extensions] :HKLM .msc=""
[Main File Extensions] :HKLM .jpg=""
[Main File Extensions] :HKLM .jpeg=""
[Main File Extensions] :HKLM .gif=""
[Main File Extensions] :HKLM .png=""
[UserInit Value] :HKLM UserInit=""
[UserInit Value(x64)] :HKLM UserInit=C:\Windows\system32\userinit.exe,
[Shell Services DelayLoad] :HKLM WebCheck={E6FB5E20-DE35-11CF-9C87-00AA005127E
D}
[System Shell Policies] :HKCU shell=""
[System Shell Policies] :HKLM shell=""
[System Shell Policies] :HKCU run=""
[System Shell Policies] :HKLM run=""
[Prevents Display in Control Panel from running.] :HKCU NoDispCpl=0
[Disable Registry Tools] :HKCU DisableRegistryTools =0
[Print Monitors] :HKLM Local Port=C:\Windows\SYSTEM32\LOCALSPL.DLL
### Local Spooler DLL Microsoft Corporation Microsoft Windows Operating System 1
0.0.10586.0 C:\Windows\SYSTEM32\LOCALSPL.DLL
[Print Monitors] :HKLM Microsoft Shared Fax Monitor=C:\Windows\SYSTEM32\FXSMON
.DLL
### Microsoft Fax Print Monitor Microsoft Corporation Microsoft Windows Operati
ng System 10.0.10586.0 C:\Windows\SYSTEM32\FXSMON.DLL
[Print Monitors] :HKLM Standard TCP/IP Port=C:\Windows\SYSTEM32\TCPMON.DLL
### Standard TCP/IP Port Monitor DLL Microsoft Corporation Microsoft Windows Ope
rating System 10.0.10586.0 C:\Windows\SYSTEM32\TCPMON.DLL
[Print Monitors] :HKLM USB Monitor=C:\Windows\SYSTEM32\USBMON.DLL
### Standard Dynamic Printing Port Monitor DLL Microsoft Corporation Microsoft
Windows Operating System 10.0.10586.0 C:\Windows\SYSTEM32\USBMON.DLL
[Print Monitors] :HKLM WSD Port=C:\Windows\SYSTEM32\WSDMON.DLL
### WSD Printer Port Monitor Microsoft Corporation Microsoft Windows Operating S
ystem 10.0.10586.0 C:\Windows\SYSTEM32\WSDMON.DLL
[Shell Icon Overlay Handlers] :HKLM OneDrive1={BBACC218-34EA-4666-9D7A-C78F22
74A524}
[Shell Icon Overlay Handlers] :HKLM OneDrive2={5AB7172C-9C11-405C-8DD5-AF20F3
606282}
[Shell Icon Overlay Handlers] :HKLM OneDrive3={A78ED123-AB77-406B-9962-2A5D9D
2F7F30}
[Shell Icon Overlay Handlers] :HKLM OneDrive4={F241C880-6982-4CE5-8CF7-7085BA
96DA5A}
[Shell Icon Overlay Handlers] :HKLM OneDrive5={A0396A93-DC06-4AEF-BEE9-95FFCC
AEF20E}
[Shell Icon Overlay Handlers] :HKLM SkyDrivePro1 (ErrorConflict)=C:\PROGRA~2\
MICROS~1\OFFICE16\GROOVEEX.DLL
### Microsoft OneDrive for Business Extensions Microsoft Corporation Microsoft
Office 2016 16.0.4266.1001
[Shell Icon Overlay Handlers] :HKLM SkyDrivePro2 (SyncInProgress)=C:\PROGRA~2
\MICROS~1\OFFICE16\GROOVEEX.DLL
### Microsoft OneDrive for Business Extensions Microsoft Corporation Microsoft
Office 2016 16.0.4266.1001
[Shell Icon Overlay Handlers] :HKLM SkyDrivePro3 (InSync)=C:\PROGRA~2\MICROS~
1\OFFICE16\GROOVEEX.DLL
### Microsoft OneDrive for Business Extensions Microsoft Corporation Microsoft

Office 2016 16.0.4266.1001


[Context Menu Handlers] :HKLM BriefcaseMenu=C:\WINDOWS\SYSTEM32\SYNCUI.DLL
### Windows Briefcase Microsoft Corporation Microsoft Windows Operating System 1
0.0.10586.0 C:\WINDOWS\SYSTEM32\SYNCUI.DLL
[Context Menu Handlers] :HKLM EPP={09A47860-11B0-4DA5-AFA5-26D86198A780}
[Context Menu Handlers] :HKLM IObitUnstaler={B19ED566-D419-470b-B111-3C89040BC
027}
[Context Menu Handlers] :HKLM Kaspersky Anti-Virus 16.0.1=C:\PROGRAM FILES (X8
6)\KASPERSKY LAB\KASPERSKY INTERNET SECURITY 16.0.1\SHELLEX.DLL
### Shell Extension AO Kaspersky Lab Kaspersky Anti-Virus 16.0.1.445
[Context Menu Handlers] :HKLM Open With=C:\WINDOWS\SYSTEM32\SHELL32.DLL
### Windows Shell Common Dll Microsoft Corporation Microsoft Windows Operating S
ystem 10.0.10586.103 C:\WINDOWS\SYSTEM32\SHELL32.DLL
[Context Menu Handlers] :HKLM Open With EncryptionMenu=C:\WINDOWS\SYSTEM32\SHE
LL32.DLL
### Windows Shell Common Dll Microsoft Corporation Microsoft Windows Operating S
ystem 10.0.10586.103 C:\WINDOWS\SYSTEM32\SHELL32.DLL
[Context Menu Handlers] :HKLM Sharing=C:\WINDOWS\SYSTEM32\NTSHRUI.DLL
### Shell extensions for sharing Microsoft Corporation Microsoft Windows Operati
ng System 10.0.10586.0 C:\WINDOWS\SYSTEM32\NTSHRUI.DLL
[Context Menu Handlers] :HKLM WorkFolders={E61BF828-5E63-4287-BEF1-60B1A4FDE0E
3}
[Context Menu Handlers] :HKLM {90AA3A4E-1CBA-4233-B8BB-535773D48449}=C:\WINDOW
S\SYSTEM32\SHELL32.DLL
### Windows Shell Common Dll Microsoft Corporation Microsoft Windows Operating S
ystem 10.0.10586.103 C:\WINDOWS\SYSTEM32\SHELL32.DLL
[Context Menu Handlers] :HKLM {a2a9545d-a0c2-42b4-9708-a0b2badd77c8}=C:\WINDOW
S\SYSTEM32\SHELL32.DLL
### Windows Shell Common Dll Microsoft Corporation Microsoft Windows Operating S
ystem 10.0.10586.103 C:\WINDOWS\SYSTEM32\SHELL32.DLL
[App Paths] :HKLM chrome.exe=C:\Program Files (x86)\Google\Chrome\Application\
chrome.exe
### chrome.exe Google Chrome Google Inc. Google Chrome 51.0.2704.106
[App Paths] :HKLM cmmgr32.exe
### cmmgr32.exe
[App Paths] :HKLM dfshim.dll
### dfshim.dll
[App Paths] :HKLM excel.exe=C:\PROGRA~1\MICROS~1\Office16\EXCEL.EXE
### excel.exe Microsoft Excel Microsoft Corporation Microsoft Office 2016 16.0
.4266.1001
[App Paths] :HKLM fsquirt.exe
### fsquirt.exe
[App Paths] :HKLM GROOVE.EXE=C:\PROGRA~1\MICROS~1\Office16\GROOVE.EXE
### GROOVE.EXE Microsoft OneDrive for Business Microsoft Corporation Microsoft
Office 2016 16.0.4266.1001
[App Paths] :HKLM IEDIAG.EXE=C:\Program Files\Internet Explorer\IEDIAGCMD.EXE
### IEDIAG.EXE Diagnostics utility for Internet Explorer Microsoft Corporation
Internet Explorer 11.00.10586.0
[App Paths] :HKLM IEDIAGCMD.EXE=C:\Program Files\Internet Explorer\IEDIAGCMD.E
XE
### IEDIAGCMD.EXE Diagnostics utility for Internet Explorer Microsoft Corporat
ion Internet Explorer 11.00.10586.0
[App Paths] :HKLM IEXPLORE.EXE=C:\Program Files\Internet Explorer\IEXPLORE.EXE
### IEXPLORE.EXE Internet Explorer Microsoft Corporation Internet Explorer 11.
00.10586.0
[App Paths] :HKLM install.exe
### install.exe
[App Paths] :HKLM Journal.exe=%ProgramFiles%\Windows Journal\Journal.exe
### Journal.exe
[App Paths] :HKLM licensemanagershellext.exe=%SystemRoot%\System32\licensemana

gershellext.exe
### licensemanagershellext.exe
[App Paths] :HKLM Lync.exe=C:\Program Files\Microsoft Office\Office16\Lync.exe
### Lync.exe Skype for Business Microsoft Corporation Microsoft Office 2016 16
.0.4266.1001
[App Paths] :HKLM mip.exe=%CommonProgramFiles%\Microsoft Shared\Ink\mip.exe
### mip.exe
[App Paths] :HKLM mplayer2.exe=%ProgramFiles(x86)%\Windows Media Player\wmplay
er.exe
### mplayer2.exe
[App Paths] :HKLM MSACCESS.EXE=C:\PROGRA~1\MICROS~1\Office16\MSACCESS.EXE
### MSACCESS.EXE Microsoft Access Microsoft Corporation Microsoft Office 2016
16.0.4266.1001
[App Paths] :HKLM MsoHtmEd.exe
### MsoHtmEd.exe
[App Paths] :HKLM msoxmled.exe=C:\Program Files\Common Files\Microsoft Shared\
OFFICE16\MSOXMLED.EXE
### msoxmled.exe Office XML Handler Microsoft Corporation Microsoft Office Inf
oPath 16.0.4266.1001
[App Paths] :HKLM MSPUB.EXE=C:\PROGRA~1\MICROS~1\Office16\MSPUB.EXE
### MSPUB.EXE Microsoft Publisher Microsoft Corporation Microsoft Office 2016
16.0.4266.1001
[App Paths] :HKLM OneNote.exe=C:\PROGRA~1\MICROS~1\Office16\ONENOTE.EXE
### OneNote.exe Microsoft OneNote Microsoft Corporation Microsoft OneNote 16.0
.4266.1001
[App Paths] :HKLM OUTLOOK.EXE=C:\PROGRA~1\MICROS~1\Office16\OUTLOOK.EXE
### OUTLOOK.EXE Microsoft Outlook Microsoft Corporation Microsoft Outlook 16.0
.4266.1001
[App Paths] :HKLM pbrush.exe=%SystemRoot%\System32\mspaint.exe
### pbrush.exe
[App Paths] :HKLM PerfectDisk.exe=C:\Program Files\Raxco\PerfectDisk\PerfectDi
sk.exe
### PerfectDisk.exe PerfectDisk Raxco Software, Inc. PerfectDisk 14.0.890.0
[App Paths] :HKLM powerpnt.exe=C:\PROGRA~1\MICROS~1\Office16\POWERPNT.EXE
### powerpnt.exe Microsoft PowerPoint Microsoft Corporation Microsoft Office 2
016 16.0.4266.1001
[App Paths] :HKLM PowerShell.exe=%SystemRoot%\system32\WindowsPowerShell\v1.0\
PowerShell.exe
### PowerShell.exe
[App Paths] :HKLM setup.exe
### setup.exe
[App Paths] :HKLM SnippingTool.exe=%SystemRoot%\system32\SnippingTool.exe
### SnippingTool.exe
[App Paths] :HKLM table30.exe
### table30.exe
[App Paths] :HKLM TabTip.exe=%CommonProgramFiles%\microsoft shared\ink\TabTip.
exe
### TabTip.exe
[App Paths] :HKLM vstoee.dll
### vstoee.dll
[App Paths] :HKLM wab.exe=%ProgramFiles%\Windows Mail\wab.exe
### wab.exe
[App Paths] :HKLM wabmig.exe=%ProgramFiles%\Windows Mail\wabmig.exe
### wabmig.exe
[App Paths] :HKLM Winword.exe=C:\PROGRA~1\MICROS~1\Office16\WINWORD.EXE
### Winword.exe Microsoft Word Microsoft Corporation Microsoft Office 2016 16.
0.4266.1001
[App Paths] :HKLM wmplayer.exe=%ProgramFiles(x86)%\Windows Media Player\wmplay
er.exe
### wmplayer.exe

[App Paths] :HKLM WORDPAD.EXE=C:\PROGRAM FILES (X86)\WINDOWS NT\ACCESSORIES\WO


RDPAD.EXE
### WORDPAD.EXE Windows Wordpad Application Microsoft Corporation Microsoft Win
dows Operating System 10.0.10586.0 C:\PROGRAM FILES (X86)\WINDOWS NT\ACCESSORIES
\WORDPAD.EXE
[App Paths] :HKLM WRITE.EXE="%ProgramFiles%\Windows NT\Accessories\WORDPAD.EXE
"
### WRITE.EXE
[Kernel Auto Boot]
[ActiveSetup] >{22d6f312-b0f6-11d0-94ab-0080c74c7e95}=C:\WINDOWS\SYSTEM32\UNRE
GMP2.EXE
### Microsoft Windows Media Player Setup Utility Microsoft Corporation Microso
ft Windows Operating System 12.0.10586.0 C:\WINDOWS\SYSTEM32\UNREGMP2.EXE
[Auto Services] AudioEndpointBuilder
### Internal Name: AudioEndpointBuilder. Status: service is running. Actual Fi
le: C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted * Manages au
dio devices for the Windows Audio service. If this service is stopped, audio de
vices and effects will not function properly. If this service is disabled, any
services that explicitly depend on it will fail to start Host Process for Window
s Services Microsoft Corporation Microsoft Windows Operating System 10.0.10586.0
[Auto Services] Audiosrv
### Internal Name: Audiosrv. Status: service is running. Actual File: C:\Windo
ws\System32\svchost.exe -k LocalServiceNetworkRestricted * Manages audio for Win
dows-based programs. If this service is stopped, audio devices and effects will
not function properly. If this service is disabled, any services that explicit
ly depend on it will fail to start Host Process for Windows Services Microsoft C
orporation Microsoft Windows Operating System 10.0.10586.0
[Auto Services] AVP16.0.1
### Internal Name: AVP16.0.1. Status: service is running. Actual File: "C:\Pro
gram Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.1\avp.exe" -r *
Provides computer protection against viruses, dangerous software, network attack
s, internet fraud and spam. Kaspersky Anti-Virus AO Kaspersky Lab Kaspersky Anti
-Virus 16.0.1.445
[Auto Services] BFE
### Internal Name: BFE. Status: service is running. Actual File: C:\Windows\sy
stem32\svchost.exe -k LocalServiceNoNetwork * The Base Filtering Engine (BFE) is
a service that manages firewall and Internet Protocol security (IPsec) policies
and implements user mode filtering. Stopping or disabling the BFE service will
significantly reduce the security of the system. It will also result in unpredic
table behavior in IPsec management and firewall applications. Host Process for W
indows Services Microsoft Corporation Microsoft Windows Operating System 10.0.1058
6.0
[Auto Services] BITS
### Internal Name: BITS. Status: service stopped. Actual File: C:\Windows\Syst
em32\svchost.exe -k netsvcs * Transfers files in the background using idle netwo
rk bandwidth. If the service is disabled, then any applications that depend on B
ITS, such as Windows Update or MSN Explorer, will be unable to automatically dow
nload programs and other information. Host Process for Windows Services Microsof
t Corporation Microsoft Windows Operating System 10.0.10586.0
[Auto Services] BrokerInfrastructure
### Internal Name: BrokerInfrastructure. Status: service is running. Actual Fi
le: C:\Windows\system32\svchost.exe -k DcomLaunch * Windows infrastructure servi
ce that controls which background tasks can run on the system. Host Process for
Windows Services Microsoft Corporation Microsoft Windows Operating System 10.0.105
86.0
[Auto Services] CCSDK
### Internal Name: CCSDK. Status: service is running. Actual File: C:\Program
Files (x86)\Lenovo\CCSDK\CCSDK.exe * Lenovo Customer Engagement Service is for t
he continuous improvement of Lenovo products and services. Lenovo will collect o
nly basic information about your usage of your device and the preloaded applicat

ions, without any appreciable inconvenience to your usage of your device. These
processes do not involve the collection of any personally identifiable informat
ion. CCSDK Lenovo CCSDK 1.3.0.3
[Auto Services] CoreMessagingRegistrar
### Internal Name: CoreMessagingRegistrar. Status: service is running. Actual
File: C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork * Manages communi
cation between system components. Host Process for Windows Services Microsoft Co
rporation Microsoft Windows Operating System 10.0.10586.0
[Auto Services] CryptSvc
### Internal Name: CryptSvc. Status: service is running. Actual File: C:\Windo
ws\system32\svchost.exe -k NetworkService * Provides three management services:
Catalog Database Service, which confirms the signatures of Windows files and all
ows new programs to be installed; Protected Root Service, which adds and removes
Trusted Root Certification Authority certificates from this computer; and Autom
atic Root Certificate Update Service, which retrieves root certificates from Win
dows Update and enable scenarios such as SSL. If this service is stopped, these
management services will not function properly. If this service is disabled, any
services that explicitly depend on it will fail to start. Host Process for Wind
ows Services Microsoft Corporation Microsoft Windows Operating System 10.0.10586.0
[Auto Services] DcomLaunch
### Internal Name: DcomLaunch. Status: service is running. Actual File: C:\Win
dows\system32\svchost.exe -k DcomLaunch * The DCOMLAUNCH service launches COM an
d DCOM servers in response to object activation requests. If this service is sto
pped or disabled, programs using COM or DCOM will not function properly. It is s
trongly recommended that you have the DCOMLAUNCH service running. Host Process f
or Windows Services Microsoft Corporation Microsoft Windows Operating System 10.0.
10586.0
[Auto Services] Dhcp
### Internal Name: Dhcp. Status: service is running. Actual File: C:\Windows\s
ystem32\svchost.exe -k LocalServiceNetworkRestricted * Registers and updates IP
addresses and DNS records for this computer. If this service is stopped, this co
mputer will not receive dynamic IP addresses and DNS updates. If this service is
disabled, any services that explicitly depend on it will fail to start. Host Pr
ocess for Windows Services Microsoft Corporation Microsoft Windows Operating Syste
m 10.0.10586.0
[Auto Services] DiagTrack
### Internal Name: DiagTrack. Status: service is running. Actual File: C:\Wind
ows\System32\svchost.exe -k utcsvc * The Connected User Experiences and Telemetr
y service enables features that support in-application and connected user experi
ences. Additionally, this service manages the event driven collection and transm
ission of diagnostic and usage information (used to improve the experience and q
uality of the Windows Platform) when the diagnostics and usage privacy option se
ttings are enabled under Feedback and Diagnostics. Host Process for Windows Serv
ices Microsoft Corporation Microsoft Windows Operating System 10.0.10586.0
[Auto Services] Dnscache
### Internal Name: Dnscache. Status: service is running. Actual File: C:\Windo
ws\system32\svchost.exe -k NetworkService * The DNS Client service (dnscache) ca
ches Domain Name System (DNS) names and registers the full computer name for thi
s computer. If the service is stopped, DNS names will continue to be resolved. H
owever, the results of DNS name queries will not be cached and the computer's na
me will not be registered. If the service is disabled, any services that explici
tly depend on it will fail to start. Host Process for Windows Services Microsoft
Corporation Microsoft Windows Operating System 10.0.10586.0
[Auto Services] DoSvc
### Internal Name: DoSvc. Status: service is running. Actual File: C:\Windows\
system32\svchost.exe -k netsvcs * Performs content delivery optimization tasks H
ost Process for Windows Services Microsoft Corporation Microsoft Windows Operating
System 10.0.10586.0
[Auto Services] DPS

### Internal Name: DPS. Status: service is running. Actual File: C:\Windows\Sy
stem32\svchost.exe -k LocalServiceNoNetwork * The Diagnostic Policy Service enab
les problem detection, troubleshooting and resolution for Windows components. I
f this service is stopped, diagnostics will no longer function. Host Process for
Windows Services Microsoft Corporation Microsoft Windows Operating System 10.0.10
586.0
[Auto Services] EventLog
### Internal Name: EventLog. Status: service is running. Actual File: C:\Windo
ws\System32\svchost.exe -k LocalServiceNetworkRestricted * This service manages
events and event logs. It supports logging events, querying events, subscribing
to events, archiving event logs, and managing event metadata. It can display eve
nts in both XML and plain text format. Stopping this service may compromise secu
rity and reliability of the system. Host Process for Windows Services Microsoft
Corporation Microsoft Windows Operating System 10.0.10586.0
[Auto Services] EventSystem
### Internal Name: EventSystem. Status: service is running. Actual File: C:\Wi
ndows\system32\svchost.exe -k LocalService * Supports System Event Notification
Service (SENS), which provides automatic distribution of events to subscribing C
omponent Object Model (COM) components. If the service is stopped, SENS will clo
se and will not be able to provide logon and logoff notifications. If this servi
ce is disabled, any services that explicitly depend on it will fail to start. Ho
st Process for Windows Services Microsoft Corporation Microsoft Windows Operating
System 10.0.10586.0
[Auto Services] EvtEng
### Internal Name: EvtEng. Status: service is running. Actual File: "C:\Progra
m Files\Intel\WiFi\bin\EvtEng.exe" * Manages the event trace messages for all th
e Intel PROSet/Wireless Software components. Intel(R) PROSet/Wireless Event Log S
ervice Intel(R) Corporation Intel(R) PROSet/Wireless 18, 20, 0, 0
[Auto Services] FastbootService
### Internal Name: FastbootService. Status: service is running. Actual File: "
C:\Program Files\Lenovo\OneKey Optimizer\bin\FbService.exe" * Lenovo RapidBoot H
DD Accelerator Service Lenovo RapidBoot HDD Accelerator Service Lenovo RapidBoot
HDD Accelerator 3,0,0,21
[Auto Services] GfExperienceService
### Internal Name: GfExperienceService. Status: service is running. Actual Fil
e: "C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceS
ervice.exe" * NVIDIA GeForce Experience Service NVIDIA GeForce ExperienceService
NVIDIA Corporation NVIDIA GeForce ExperienceService 2.11.4.0
[Auto Services] gpsvc
### Internal Name: gpsvc. Status: service stopped. Actual File: C:\Windows\sys
tem32\svchost.exe -k netsvcs * The service is responsible for applying settings
configured by administrators for the computer and users through the Group Policy
component. If the service is disabled, the settings will not be applied and app
lications and components will not be manageable through Group Policy. Any compon
ents or applications that depend on the Group Policy component might not be func
tional if the service is disabled. Host Process for Windows Services Microsoft C
orporation Microsoft Windows Operating System 10.0.10586.0
[Auto Services] gupdate
### Internal Name: gupdate. Status: service stopped. Actual File: "C:\Program
Files (x86)\Google\Update\GoogleUpdate.exe" /svc * Keeps your Google software up
to date. If this service is disabled or stopped, your Google software will not
be kept up to date, meaning security vulnerabilities that may arise cannot be fi
xed and features may not work. This service uninstalls itself when there is no G
oogle software using it. Google Installer Google Inc. Google Update 1.3.29.5
[Auto Services] HarmonySettingService
### Internal Name: HarmonySettingService. Status: service is running. Actual F
ile: "C:\Program Files (x86)\Lenovo\Harmony\Setting\HarmonySettingService.exe" *
HarmonySettingService HarmonySettingService Lenovo HarmonySettingService 1.1.0.
209
[Auto Services] IAStorDataMgrSvc

### Internal Name: IAStorDataMgrSvc. Status: service is running. Actual File:


"C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
* Provides storage event notification and manages communication between the stor
age driver and user space applications. IAStorDataSvc Intel Corporation IAStorDa
taSvc 14.6.0.1029
[Auto Services] ibtsiva
### Internal Name: ibtsiva. Status: service is running. Actual File: "C:\Progr
am Files (x86)\Intel\Bluetooth\utilities\ibtsiva.exe" * Intel(R) Wireless Blueto
oth(R) iBtSiva Service Intel(R) Wireless Bluetooth(R) iBtSiva Service Intel Corp
oration Intel(R) Wireless Bluetooth(R) 17.1.1524.1353
[Auto Services] igfxCUIService2.0.0.0
### Internal Name: igfxCUIService2.0.0.0. Status: service is running. Actual F
ile: C:\Windows\system32\igfxCUIService.exe * Service for Intel(R) HD Graphics C
ontrol Panel igfxCUIService Module Intel Corporation Intel(R) Common User Interf
ace 6.15.10.4248
[Auto Services] IKEEXT
### Internal Name: IKEEXT. Status: service is running. Actual File: C:\Windows
\system32\svchost.exe -k netsvcs * The IKEEXT service hosts the Internet Key Exc
hange (IKE) and Authenticated Internet Protocol (AuthIP) keying modules. These k
eying modules are used for authentication and key exchange in Internet Protocol
security (IPsec). Stopping or disabling the IKEEXT service will disable IKE and
AuthIP key exchange with peer computers. IPsec is typically configured to use IK
E or AuthIP; therefore, stopping or disabling the IKEEXT service might result in
an IPsec failure and might compromise the security of the system. It is strongl
y recommended that you have the IKEEXT service running. Host Process for Windows
Services Microsoft Corporation Microsoft Windows Operating System 10.0.10586.0
[Auto Services] ImControllerService
### Internal Name: ImControllerService. Status: service is running. Actual Fil
e: "C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe"
* The Lenovo System Interface Foundation Service provides interfaces for key fe
atures such as: system power management, system optimization, driver and applica
tion updates, and system settings to Lenovo applications including Lenovo Compan
ion, Lenovo Settings and Lenovo ID. If you disable this service, Lenovo applicat
ions will not work properly. Lenovo.Modern.ImController Lenovo Group Limited Len
ovo.Modern.ImController 1.0.0077.01
[Auto Services] iphlpsvc
### Internal Name: iphlpsvc. Status: service is running. Actual File: C:\Windo
ws\System32\svchost.exe -k NetSvcs * Provides tunnel connectivity using IPv6 tra
nsition technologies (6to4, ISATAP, Port Proxy, and Teredo), and IP-HTTPS. If th
is service is stopped, the computer will not have the enhanced connectivity bene
fits that these technologies offer. Host Process for Windows Services Microsoft
Corporation Microsoft Windows Operating System 10.0.10586.0
[Auto Services] isaHelperSvc
### Internal Name: isaHelperSvc. Status: service stopped. Actual File: "C:\Pro
gram Files (x86)\Intel\Intel(R) Security Assist\isaHelperService.exe" * Security
Helper
[Auto Services] jhi_service
### Internal Name: jhi_service. Status: service is running. Actual File: "C:\P
rogram Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.e
xe" * Intel(R) Dynamic Application Loader Host Interface Service - Allows applic
ations to access the local Intel (R) DAL Intel(R) Dynamic Application Loader Hos
t Interface Intel Corporation Intel(R) Dynamic Application Loader Host Interface
11.0.0.1158
[Auto Services] LanmanServer
### Internal Name: LanmanServer. Status: service is running. Actual File: C:\W
indows\system32\svchost.exe -k netsvcs * Supports file, print, and named-pipe sh
aring over the network for this computer. If this service is stopped, these func
tions will be unavailable. If this service is disabled, any services that explic
itly depend on it will fail to start. Host Process for Windows Services Microsof
t Corporation Microsoft Windows Operating System 10.0.10586.0

[Auto Services] LanmanWorkstation


### Internal Name: LanmanWorkstation. Status: service is running. Actual File:
C:\Windows\System32\svchost.exe -k NetworkService * Creates and maintains clien
t network connections to remote servers using the SMB protocol. If this service
is stopped, these connections will be unavailable. If this service is disabled,
any services that explicitly depend on it will fail to start. Host Process for W
indows Services Microsoft Corporation Microsoft Windows Operating System 10.0.1058
6.0
[Auto Services] Lenovo OKO Service
### Internal Name: Lenovo OKO Service. Status: service is running. Actual File
: "C:\Program Files\Lenovo\OneKey Optimizer\bin\OKOUpdataService.exe" * OneKey
Optimizer Self Update Install Service Lenovo(beijing) Limited OneKeyOptimizer 1.
2.24.6
[Auto Services] LiveUpdateSvc
### Internal Name: LiveUpdateSvc. Status: service is running. Actual File: C:\
Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe * LiveUpdate Product Updater
IObit Product Updater 2.0.0.0
[Auto Services] LMS
### Internal Name: LMS. Status: service is running. Actual File: "C:\Program F
iles (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe" * Intel(R) M
anagement and Security Application Local Management Service - Provides OS-relate
d Intel(R) ME functionality. Intel(R) Local Management Service Intel Corporation
Intel(R) Management and Security Application Local Management Service 11.0.0.11
58
[Auto Services] LSM
### Internal Name: LSM. Status: service is running. Actual File: C:\Windows\sy
stem32\svchost.exe -k DcomLaunch * Core Windows Service that manages local user
sessions. Stopping or disabling this service will result in system instability.
Host Process for Windows Services Microsoft Corporation Microsoft Windows Operatin
g System 10.0.10586.0
[Auto Services] MapsBroker
### Internal Name: MapsBroker. Status: service stopped. Actual File: C:\Window
s\System32\svchost.exe -k NetworkService * Windows service for application acces
s to downloaded maps. This service is started on-demand by application accessing
downloaded maps. Disabling this service will prevent apps from accessing maps.
Host Process for Windows Services Microsoft Corporation Microsoft Windows Operatin
g System 10.0.10586.0
[Auto Services] MpsSvc
### Internal Name: MpsSvc. Status: service is running. Actual File: C:\Windows
\system32\svchost.exe -k LocalServiceNoNetwork * Windows Firewall helps protect
your computer by preventing unauthorized users from gaining access to your compu
ter through the Internet or a network. Host Process for Windows Services Microso
ft Corporation Microsoft Windows Operating System 10.0.10586.0
[Auto Services] NlaSvc
### Internal Name: NlaSvc. Status: service is running. Actual File: C:\Windows
\System32\svchost.exe -k NetworkService * Collects and stores configuration info
rmation for the network and notifies programs when this information is modified.
If this service is stopped, configuration information might be unavailable. If
this service is disabled, any services that explicitly depend on it will fail to
start. Host Process for Windows Services Microsoft Corporation Microsoft Windows
Operating System 10.0.10586.0
[Auto Services] nsi
### Internal Name: nsi. Status: service is running. Actual File: C:\Windows\sy
stem32\svchost.exe -k LocalService * This service delivers network notifications
(e.g. interface addition/deleting etc) to user mode clients. Stopping this serv
ice will cause loss of network connectivity. If this service is disabled, any ot
her services that explicitly depend on this service will fail to start. Host Pro
cess for Windows Services Microsoft Corporation Microsoft Windows Operating System
10.0.10586.0
[Auto Services] NvNetworkService

### Internal Name: NvNetworkService. Status: service is running. Actual File:


"C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe" * NV
IDIA Network Service NVIDIA Network Service NVIDIA Corporation NVIDIA Network Se
rvice 2.4.13.69
[Auto Services] nvsvc
### Internal Name: nvsvc. Status: service is running. Actual File: "C:\Windows
\system32\nvvsvc.exe" * Provides system and desktop level support to the NVIDIA
display driver NVIDIA Driver Helper Service, Version 368.69 NVIDIA Corporation N
VIDIA Driver Helper Service, Version 368.69 8.17.13.6869
[Auto Services] OKOControlSvc
### Internal Name: OKOControlSvc. Status: service is running. Actual File: "C:
\Program Files\Lenovo\OneKey Optimizer\bin\OKOControlSvc.exe" * OneKey Optimizer
contains an important core service. If disabled, you will not able to use the L
enovo-provided update service. OneKey Optimizer contains an important core servi
ce. If disabled, you will not able to use the Lenovo-provided update service. Le
novo(beijing) Limited OneKey Optimizer 1.3.0.7
[Auto Services] PcaSvc
### Internal Name: PcaSvc. Status: service is running. Actual File: C:\Windows
\system32\svchost.exe -k LocalSystemNetworkRestricted * This service provides su
pport for the Program Compatibility Assistant (PCA). PCA monitors programs inst
alled and run by the user and detects known compatibility problems. If this serv
ice is stopped, PCA will not function properly. Host Process for Windows Service
s Microsoft Corporation Microsoft Windows Operating System 10.0.10586.0
[Auto Services] PDAgent
### Internal Name: PDAgent. Status: service is running. Actual File: "C:\Progr
am Files\Raxco\PerfectDisk\PDAgent.exe" * This service controls PerfectDisk's sc
heduling and remote communication. PDAgent Module Raxco Software, Inc. PerfectDi
sk 14.0.890.0
[Auto Services] PDEngine
### Internal Name: PDEngine. Status: service is running. Actual File: "C:\Prog
ram Files\Common Files\Raxco\Shared\PDEngine.exe" * PerfectDisk's defrag engine
PDEngine Module Raxco Software, Inc. PerfectDisk 14.0.890.0
[Auto Services] ProfSvc
### Internal Name: ProfSvc. Status: service is running. Actual File: C:\Window
s\system32\svchost.exe -k netsvcs * This service is responsible for loading and
unloading user profiles. If this service is stopped or disabled, users will no l
onger be able to successfully sign in or sign out, apps might have problems gett
ing to users' data, and components registered to receive profile event notificat
ions won't receive them. Host Process for Windows Services Microsoft Corporation
Microsoft Windows Operating System 10.0.10586.0
[Auto Services] RegSrvc
### Internal Name: RegSrvc. Status: service is running. Actual File: "C:\Progr
am Files\Common Files\Intel\WirelessCommon\RegSrvc.exe" * Provides registry acce
ss to all Intel PROSet/Wireless Software components Intel(R) PROSet/Wireless Regi
stry Service Intel(R) Corporation Intel(R) PROSet/Wireless 18, 20, 0, 0
[Auto Services] RpcEptMapper
### Internal Name: RpcEptMapper. Status: service is running. Actual File: C:\W
indows\system32\svchost.exe -k RPCSS * Resolves RPC interfaces identifiers to tr
ansport endpoints. If this service is stopped or disabled, programs using Remote
Procedure Call (RPC) services will not function properly. Host Process for Wind
ows Services Microsoft Corporation Microsoft Windows Operating System 10.0.10586.0
[Auto Services] RpcSs
### Internal Name: RpcSs. Status: service is running. Actual File: C:\Windows\
system32\svchost.exe -k rpcss * The RPCSS service is the Service Control Manager
for COM and DCOM servers. It performs object activations requests, object expor
ter resolutions and distributed garbage collection for COM and DCOM servers. If
this service is stopped or disabled, programs using COM or DCOM will not functio
n properly. It is strongly recommended that you have the RPCSS service running.
Host Process for Windows Services Microsoft Corporation Microsoft Windows Operatin

g System 10.0.10586.0
[Auto Services] Schedule
### Internal Name: Schedule. Status: service is running. Actual File: C:\Windo
ws\system32\svchost.exe -k netsvcs * Enables a user to configure and schedule au
tomated tasks on this computer. The service also hosts multiple Windows system-c
ritical tasks. If this service is stopped or disabled, these tasks will not be r
un at their scheduled times. If this service is disabled, any services that expl
icitly depend on it will fail to start. Host Process for Windows Services Micros
oft Corporation Microsoft Windows Operating System 10.0.10586.0
[Auto Services] SENS
### Internal Name: SENS. Status: service is running. Actual File: C:\Windows\s
ystem32\svchost.exe -k netsvcs * Monitors system events and notifies subscribers
to COM+ Event System of these events. Host Process for Windows Services Microso
ft Corporation Microsoft Windows Operating System 10.0.10586.0
[Auto Services] ShellHWDetection
### Internal Name: ShellHWDetection. Status: service is running. Actual File:
C:\Windows\System32\svchost.exe -k netsvcs * Provides notifications for AutoPlay
hardware events. Host Process for Windows Services Microsoft Corporation Micros
oft Windows Operating System 10.0.10586.0
[Auto Services] Spooler
### Internal Name: Spooler. Status: service is running. Actual File: C:\Window
s\System32\spoolsv.exe * This service spools print jobs and handles interaction
with the printer. If you turn off this service, you won t be able to print or see
your printers. Spooler SubSystem App Microsoft Corporation Microsoft Windows Oper
ating System 10.0.10586.0
[Auto Services] sppsvc
### Internal Name: sppsvc. Status: service stopped. Actual File: C:\Windows\sy
stem32\sppsvc.exe * Enables the download, installation and enforcement of digita
l licenses for Windows and Windows applications. If the service is disabled, the
operating system and licensed applications may run in a notification mode. It i
s strongly recommended that you not disable the Software Protection service. Mic
rosoft Software Protection Platform Service Microsoft Corporation Microsoft Windo
ws Operating System 10.0.10586.0
[Auto Services] SynTPEnhService
### Internal Name: SynTPEnhService. Status: service is running. Actual File: "
C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe" * 64-bit Synaptics Pointi
ng Enhance Service Synaptics Incorporated Synaptics Pointing Device Driver 19.0.
18 23Jul15
[Auto Services] SysMain
### Internal Name: SysMain. Status: service is running. Actual File: C:\Window
s\system32\svchost.exe -k LocalSystemNetworkRestricted * Maintains and improves
system performance over time. Host Process for Windows Services Microsoft Corpor
ation Microsoft Windows Operating System 10.0.10586.0
[Auto Services] SystemEventsBroker
### Internal Name: SystemEventsBroker. Status: service is running. Actual File
: C:\Windows\system32\svchost.exe -k DcomLaunch * Coordinates execution of backg
round work for WinRT application. If this service is stopped or disabled, then b
ackground work might not be triggered. Host Process for Windows Services Microso
ft Corporation Microsoft Windows Operating System 10.0.10586.0
[Auto Services] TabletInputService
### Internal Name: TabletInputService. Status: service is running. Actual File
: C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted * Enables Touc
h Keyboard and Handwriting Panel pen and ink functionality Host Process for Wind
ows Services Microsoft Corporation Microsoft Windows Operating System 10.0.10586.0
[Auto Services] Themes
### Internal Name: Themes. Status: service is running. Actual File: C:\Windows
\System32\svchost.exe -k netsvcs * Provides user experience theme management. Ho
st Process for Windows Services Microsoft Corporation Microsoft Windows Operating
System 10.0.10586.0

[Auto Services] tiledatamodelsvc


### Internal Name: tiledatamodelsvc. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k appmodel * Tile Server for tile updates. Host
Process for Windows Services Microsoft Corporation Microsoft Windows Operating Sy
stem 10.0.10586.0
[Auto Services] TrkWks
### Internal Name: TrkWks. Status: service is running. Actual File: C:\Windows
\System32\svchost.exe -k LocalSystemNetworkRestricted * Maintains links between
NTFS files within a computer or across computers in a network. Host Process for
Windows Services Microsoft Corporation Microsoft Windows Operating System 10.0.105
86.0
[Auto Services] UserManager
### Internal Name: UserManager. Status: service is running. Actual File: C:\Wi
ndows\system32\svchost.exe -k netsvcs * User Manager provides the runtime compon
ents required for multi-user interaction. If this service is stopped, some appl
ications may not operate correctly. Host Process for Windows Services Microsoft
Corporation Microsoft Windows Operating System 10.0.10586.0
[Auto Services] WbioSrvc
### Internal Name: WbioSrvc. Status: service stopped. Actual File: C:\Windows\
system32\svchost.exe -k WbioSvcGroup * The Windows biometric service gives clien
t applications the ability to capture, compare, manipulate, and store biometric
data without gaining direct access to any biometric hardware or samples. The ser
vice is hosted in a privileged SVCHOST process. Host Process for Windows Service
s Microsoft Corporation Microsoft Windows Operating System 10.0.10586.0
[Auto Services] Wcmsvc
### Internal Name: Wcmsvc. Status: service is running. Actual File: C:\Windows
\system32\svchost.exe -k LocalServiceNetworkRestricted * Makes automatic connect
/disconnect decisions based on the network connectivity options currently availa
ble to the PC and enables management of network connectivity based on Group Poli
cy settings. Host Process for Windows Services Microsoft Corporation Microsoft Wi
ndows Operating System 10.0.10586.0
[Auto Services] Winmgmt
### Internal Name: Winmgmt. Status: service is running. Actual File: C:\Window
s\system32\svchost.exe -k netsvcs * Provides a common interface and object model
to access management information about operating system, devices, applications
and services. If this service is stopped, most Windows-based software will not f
unction properly. If this service is disabled, any services that explicitly depe
nd on it will fail to start. Host Process for Windows Services Microsoft Corpora
tion Microsoft Windows Operating System 10.0.10586.0
[Auto Services] WlanSvc
### Internal Name: WlanSvc. Status: service is running. Actual File: C:\Window
s\system32\svchost.exe -k LocalSystemNetworkRestricted * The WLANSVC service pro
vides the logic required to configure, discover, connect to, and disconnect from
a wireless local area network (WLAN) as defined by IEEE 802.11 standards. It al
so contains the logic to turn your computer into a software access point so that
other devices or computers can connect to your computer wirelessly using a WLAN
adapter that can support this. Stopping or disabling the WLANSVC service will m
ake all WLAN adapters on your computer inaccessible from the Windows networking
UI. It is strongly recommended that you have the WLANSVC service running if your
computer has a WLAN adapter. Host Process for Windows Services Microsoft Corpor
ation Microsoft Windows Operating System 10.0.10586.0
[Auto Services] WMPNetworkSvc
### Internal Name: WMPNetworkSvc. Status: service is running. Actual File: "C:
\Program Files\Windows Media Player\wmpnetwk.exe" * Shares Windows Media Player
libraries to other networked players and media devices using Universal Plug and
Play Windows Media Player Network Sharing Service Microsoft Corporation Microsof
t Windows Operating System 12.0.10586.0
[Auto Services] wscsvc
### Internal Name: wscsvc. Status: service is running. Actual File: C:\Windows
\System32\svchost.exe -k LocalServiceNetworkRestricted * The WSCSVC (Windows Sec

urity Center) service monitors and reports security health settings on the compu
ter. The health settings include firewall (on/off), antivirus (on/off/out of da
te), antispyware (on/off/out of date), Windows Update (automatically/manually do
wnload and install updates), User Account Control (on/off), and Internet setting
s (recommended/not recommended). The service provides COM APIs for independent s
oftware vendors to register and record the state of their products to the Securi
ty Center service. The Security and Maintenance UI uses the service to provide
systray alerts and a graphical view of the security health states in the Securit
y and Maintenance control panel. Network Access Protection (NAP) uses the servi
ce to report the security health states of clients to the NAP Network Policy Ser
ver to make network quarantine decisions. The service also has a public API tha
t allows external consumers to programmatically retrieve the aggregated security
health state of the system. Host Process for Windows Services Microsoft Corpora
tion Microsoft Windows Operating System 10.0.10586.0
[Auto Services] WSearch
### Internal Name: WSearch. Status: service is running. Actual File: C:\Window
s\system32\SearchIndexer.exe /Embedding * Provides content indexing, property ca
ching, and search results for files, e-mail, and other content. Microsoft Window
s Search Indexer Microsoft Corporation Windows Search 7.00.10586.0
[Auto Services] ymc
### Internal Name: ymc. Status: service is running. Actual File: C:\ProgramDat
a\LenovoTransition\Server\x64\ymc.exe * Lenovo Yoga Mode Control Lenovo Lenovo
Yoga Mode Control 1.0.0.0
[Auto Services] ZeroConfigService
### Internal Name: ZeroConfigService. Status: service is running. Actual File:
"C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe" * Manages the zero conf
iguration service for all the Intel PROSet/Wireless Software components. Intel PRO
Set/Wireless Zero Configure Service Intel Corporation Intel(R) PROSet/Wireless 18
, 20, 0, 0
[Svchost DLLs] :HKLM CertPropSvc=C:\WINDOWS\SYSTEM32\CERTPROP.DLL
### Microsoft Smartcard Certificate Propagation Service Microsoft Corporation
Microsoft Windows Operating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\CERTPROP.DLL
[Svchost DLLs] :HKLM SCPolicySvc=C:\WINDOWS\SYSTEM32\CERTPROP.DLL
### Microsoft Smartcard Certificate Propagation Service Microsoft Corporation
Microsoft Windows Operating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\CERTPROP.DLL
[Svchost DLLs] :HKLM lanmanserver=C:\WINDOWS\SYSTEM32\SRVSVC.DLL
### Server Service DLL Microsoft Corporation Microsoft Windows Operating System
10.0.10586.0 C:\WINDOWS\SYSTEM32\SRVSVC.DLL
[Svchost DLLs] :HKLM gpsvc=C:\WINDOWS\SYSTEM32\GPSVC.DLL
### Group Policy Client Microsoft Corporation Microsoft Windows Operating System
10.0.10586.0 C:\WINDOWS\SYSTEM32\GPSVC.DLL
[Svchost DLLs] :HKLM iphlpsvc=C:\WINDOWS\SYSTEM32\IPHLPSVC.DLL
### Service that offers IPv6 connectivity over an IPv4 network. Microsoft Corp
oration Microsoft Windows Operating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\IPHLP
SVC.DLL
[Svchost DLLs] :HKLM msiscsi=C:\WINDOWS\SYSTEM32\ISCSIEXE.DLL
### iSCSI Discovery service Microsoft Corporation Microsoft Windows Operating Sy
stem 10.0.10586.0 C:\WINDOWS\SYSTEM32\ISCSIEXE.DLL
[Svchost DLLs] :HKLM schedule=C:\WINDOWS\SYSTEM32\SCHEDSVC.DLL
### Task Scheduler Service Microsoft Corporation Microsoft Windows Operating Sys
tem 10.0.10586.0 C:\WINDOWS\SYSTEM32\SCHEDSVC.DLL
[Svchost DLLs] :HKLM winmgmt=C:\WINDOWS\SYSTEM32\WBEM\WMISVC.DLL
### WMI Microsoft Corporation Microsoft Windows Operating System 10.0.10586.0 C
:\WINDOWS\SYSTEM32\WBEM\WMISVC.DLL
[Svchost DLLs] :HKLM SessionEnv=C:\WINDOWS\SYSTEM32\SESSENV.DLL
### Remote Desktop Configuration service Microsoft Corporation Microsoft Window
s Operating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\SESSENV.DLL
[Svchost DLLs] :HKLM FastUserSwitchingCompatibility
[Svchost DLLs] :HKLM Ias
[Svchost DLLs] :HKLM Irmon

[Svchost DLLs] :HKLM Nla


[Svchost DLLs] :HKLM Ntmssvc
[Svchost DLLs] :HKLM NWCWorkstation
[Svchost DLLs] :HKLM Nwsapagent
[Svchost DLLs] :HKLM Rasauto=C:\WINDOWS\SYSTEM32\RASAUTO.DLL
### Remote Access AutoDial Manager Microsoft Corporation Microsoft Windows Opera
ting System 10.0.10586.0 C:\WINDOWS\SYSTEM32\RASAUTO.DLL
[Svchost DLLs] :HKLM Rasman=C:\WINDOWS\SYSTEM32\RASMANS.DLL
### Remote Access Connection Manager Microsoft Corporation Microsoft Windows Ope
rating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\RASMANS.DLL
[Svchost DLLs] :HKLM Remoteaccess=C:\WINDOWS\SYSTEM32\MPRDIM.DLL
### Dynamic Interface Manager Microsoft Corporation Microsoft Windows Operating
System 10.0.10586.0 C:\WINDOWS\SYSTEM32\MPRDIM.DLL
[Svchost DLLs] :HKLM SENS=C:\WINDOWS\SYSTEM32\SENS.DLL
### System Event Notification Service (SENS) Microsoft Corporation Microsoft Wi
ndows Operating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\SENS.DLL
[Svchost DLLs] :HKLM Sharedaccess=C:\WINDOWS\SYSTEM32\IPNATHLP.DLL
### Microsoft NAT Helper Components Microsoft Corporation Microsoft Windows Oper
ating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\IPNATHLP.DLL
[Svchost DLLs] :HKLM SRService
[Svchost DLLs] :HKLM Tapisrv=C:\WINDOWS\SYSTEM32\TAPISRV.DLL
### Microsoft Windows(TM) Telephony Server Microsoft Corporation Microsoft Windo
ws Operating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\TAPISRV.DLL
[Svchost DLLs] :HKLM Wmi
[Svchost DLLs] :HKLM WmdmPmSp
[Svchost DLLs] :HKLM wuauserv=C:\WINDOWS\SYSTEM32\WUAUENG.DLL
### Windows Update Agent Microsoft Corporation Microsoft Windows Operating Syste
m 10.0.10586.0 C:\WINDOWS\SYSTEM32\WUAUENG.DLL
[Svchost DLLs] :HKLM BITS=C:\WINDOWS\SYSTEM32\QMGR.DLL
### Background Intelligent Transfer Service Microsoft Corporation Microsoft Win
dows Operating System 7.8.10586.0 C:\WINDOWS\SYSTEM32\QMGR.DLL
[Svchost DLLs] :HKLM ShellHWDetection=C:\WINDOWS\SYSTEM32\SHSVCS.DLL
### Windows Shell Services Dll Microsoft Corporation Microsoft Windows Operating
System 10.0.10586.0 C:\WINDOWS\SYSTEM32\SHSVCS.DLL
[Svchost DLLs] :HKLM LogonHours
[Svchost DLLs] :HKLM PCAudit
[Svchost DLLs] :HKLM helpsvc
[Svchost DLLs] :HKLM uploadmgr
[Svchost DLLs] :HKLM NetSetupSvc=C:\WINDOWS\SYSTEM32\NETSETUPSVC.DLL
### Network Setup Service Microsoft Corporation Microsoft Windows Operating Syst
em 10.0.10586.0 C:\WINDOWS\SYSTEM32\NETSETUPSVC.DLL
[Svchost DLLs] :HKLM UserManager=C:\WINDOWS\SYSTEM32\USERMGR.DLL
### UserMgr Microsoft Corporation Microsoft Windows Operating System 10.0.10586.
0 C:\WINDOWS\SYSTEM32\USERMGR.DLL
[Svchost DLLs] :HKLM AppMgmt=C:\WINDOWS\SYSTEM32\APPMGMTS.DLL
### Software installation Service Microsoft Corporation Microsoft Windows Operat
ing System 10.0.10586.0 C:\WINDOWS\SYSTEM32\APPMGMTS.DLL
[Svchost DLLs] :HKLM ScDeviceEnum=C:\WINDOWS\SYSTEM32\SCDEVICEENUM.DLL
### Smart Card Device Enumeration Service Microsoft Corporation Microsoft Windo
ws Operating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\SCDEVICEENUM.DLL
[Svchost DLLs] :HKLM WiaRpc=C:\WINDOWS\SYSTEM32\WIARPC.DLL
### Windows Image Acquisition RPC client DLL Microsoft Corporation Microsoft Wi
ndows Operating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\WIARPC.DLL
[Svchost DLLs] :HKLM AudioEndpointBuilder=C:\WINDOWS\SYSTEM32\AUDIOENDPOINTBUI
LDER.DLL
### Windows Audio Endpoint Builder Microsoft Corporation Microsoft Windows Opera
ting System 10.0.10586.0 C:\WINDOWS\SYSTEM32\AUDIOENDPOINTBUILDER.DLL
[Svchost DLLs] :HKLM dot3svc=C:\WINDOWS\SYSTEM32\DOT3SVC.DLL
### Wired AutoConfig Service Microsoft Corporation Microsoft Windows Operating S
ystem 10.0.10586.0 C:\WINDOWS\SYSTEM32\DOT3SVC.DLL

[Svchost DLLs] :HKLM Netman=C:\WINDOWS\SYSTEM32\NETMAN.DLL


### Network Connections Manager Microsoft Corporation Microsoft Windows Operatin
g System 10.0.10586.0 C:\WINDOWS\SYSTEM32\NETMAN.DLL
[Svchost DLLs] :HKLM WPDBusEnum=C:\WINDOWS\SYSTEM32\WPDBUSENUM.DLL
### Portable Device Enumerator Microsoft Corporation Microsoft Windows Operating
System 10.0.10586.0 C:\WINDOWS\SYSTEM32\WPDBUSENUM.DLL
[Svchost DLLs] :HKLM DeviceAssociationService=C:\WINDOWS\SYSTEM32\DAS.DLL
### Device Association Service Microsoft Corporation Microsoft Windows Operating
System 10.0.10586.0 C:\WINDOWS\SYSTEM32\DAS.DLL
[Svchost DLLs] :HKLM NcbService=C:\WINDOWS\SYSTEM32\NCBSERVICE.DLL
### Network Connection Broker Microsoft Corporation Microsoft Windows Operating
System 10.0.10586.0 C:\WINDOWS\SYSTEM32\NCBSERVICE.DLL
[Svchost DLLs] :HKLM wlansvc=C:\WINDOWS\SYSTEM32\WLANSVC.DLL
### Windows WLAN AutoConfig Service DLL Microsoft Corporation Microsoft Windows
Operating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\WLANSVC.DLL
[Svchost DLLs] :HKLM WinHttpAutoProxySvc=C:\WINDOWS\SYSTEM32\WINHTTP.DLL
### Windows HTTP Services Microsoft Corporation Microsoft Windows Operating Syst
em 10.0.10586.0 C:\WINDOWS\SYSTEM32\WINHTTP.DLL
[Svchost DLLs] :HKLM netprofm=C:\WINDOWS\SYSTEM32\NETPROFMSVC.DLL
### Network List Manager Microsoft Corporation Microsoft Windows Operating Syste
m 10.0.10586.0 C:\WINDOWS\SYSTEM32\NETPROFMSVC.DLL
[Svchost DLLs] :HKLM WebClient=C:\WINDOWS\SYSTEM32\WEBCLNT.DLL
### Web DAV Service DLL Microsoft Corporation Microsoft Windows Operating System
10.0.10586.0 C:\WINDOWS\SYSTEM32\WEBCLNT.DLL
[Svchost DLLs] :HKLM StiSvc=C:\WINDOWS\SYSTEM32\WIASERVC.DLL
### Still Image Devices Service Microsoft Corporation Microsoft Windows Operatin
g System 10.0.10586.0 C:\WINDOWS\SYSTEM32\WIASERVC.DLL
[Svchost DLLs] :HKLM PLA=C:\WINDOWS\SYSTEM32\PLA.DLL
### Performance Logs & Alerts Microsoft Corporation Microsoft Windows Operating
System 10.0.10586.0 C:\WINDOWS\SYSTEM32\PLA.DLL
[Svchost DLLs] :HKLM smphost=C:\WINDOWS\SYSTEM32\SMPHOST.DLL
### Storage Management Provider (SMP) host service Microsoft Corporation Micro
soft Windows Operating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\SMPHOST.DLL
[Svchost DLLs] :HKLM RpcSs=C:\WINDOWS\SYSTEM32\RPCSS.DLL
### Distributed COM Services Microsoft Corporation Microsoft Windows Operating S
ystem 10.0.10586.0 C:\WINDOWS\SYSTEM32\RPCSS.DLL
[Svchost DLLs] :HKLM AudioSrv=C:\WINDOWS\SYSTEM32\AUDIOSRV.DLL
### Windows Audio Service Microsoft Corporation Microsoft Windows Operating Syst
em 10.0.10586.0 C:\WINDOWS\SYSTEM32\AUDIOSRV.DLL
[Svchost DLLs] :HKLM wscsvc=C:\WINDOWS\SYSTEM32\WSCSVC.DLL
### Windows Security Center Service Microsoft Corporation Microsoft Windows Oper
ating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\WSCSVC.DLL
[Svchost DLLs] :HKLM LmHosts=C:\WINDOWS\SYSTEM32\LMHSVC.DLL
### TCPIP NetBios Transport Services DLL Microsoft Corporation Microsoft Window
s Operating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\LMHSVC.DLL
[Svchost DLLs] :HKLM DHCP=C:\WINDOWS\SYSTEM32\DHCPCORE.DLL
### DHCP Client Service Microsoft Corporation Microsoft Windows Operating System
10.0.10586.0 C:\WINDOWS\SYSTEM32\DHCPCORE.DLL
[Svchost DLLs] :HKLM WcsPlugInService=C:\WINDOWS\SYSTEM32\WCSPLUGINSERVICE.DLL
### WcsPlugInService DLL Microsoft Corporation Microsoft Windows Operating Syste
m 10.0.10586.0 C:\WINDOWS\SYSTEM32\WCSPLUGINSERVICE.DLL
[Svchost DLLs] :HKLM StateRepository=C:\WINDOWS\SYSTEM32\WINDOWS.STATEREPOSITO
RY.DLL
### Windows StateRepository API Server Microsoft Corporation Microsoft Windows O
perating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\WINDOWS.STATEREPOSITORY.DLL
[Svchost DLLs] :HKLM SSDPSRV=C:\WINDOWS\SYSTEM32\SSDPSRV.DLL
### SSDP Service DLL Microsoft Corporation Microsoft Windows Operating System 10
.0.10586.0 C:\WINDOWS\SYSTEM32\SSDPSRV.DLL
[Svchost DLLs] :HKLM upnphost=C:\WINDOWS\SYSTEM32\UPNPHOST.DLL
### UPnP Device Host Microsoft Corporation Microsoft Windows Operating System 10

.0.10586.0 C:\WINDOWS\SYSTEM32\UPNPHOST.DLL
[Svchost DLLs] :HKLM SCardSvr=C:\WINDOWS\SYSTEM32\SCARDSVR.DLL
### Smart Card Resource Management Server Microsoft Corporation Microsoft Windo
ws Operating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\SCARDSVR.DLL
[Svchost DLLs] :HKLM BthHFSrv=C:\WINDOWS\SYSTEM32\BTHHFSRV.DLL
### Bluetooth Handsfree Service Microsoft Corporation Microsoft Windows Operatin
g System 10.0.10586.0 C:\WINDOWS\SYSTEM32\BTHHFSRV.DLL
[Svchost DLLs] :HKLM QWAVE=C:\WINDOWS\SYSTEM32\QWAVE.DLL
### Windows NT Microsoft Corporation Microsoft Windows Operating System 10.0.105
86.0 C:\WINDOWS\SYSTEM32\QWAVE.DLL
[Svchost DLLs] :HKLM wcncsvc=C:\WINDOWS\SYSTEM32\WCNCSVC.DLL
### Windows Connect Now - Config Registrar Service Microsoft Corporation Micro
soft Windows Operating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\WCNCSVC.DLL
[Svchost DLLs] :HKLM PlugPlay=C:\WINDOWS\SYSTEM32\UMPNPMGR.DLL
### User-mode Plug-and-Play Service Microsoft Corporation Microsoft Windows Oper
ating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\UMPNPMGR.DLL
[Svchost DLLs] :HKLM DcomLaunch=C:\WINDOWS\SYSTEM32\RPCSS.DLL
### Distributed COM Services Microsoft Corporation Microsoft Windows Operating S
ystem 10.0.10586.0 C:\WINDOWS\SYSTEM32\RPCSS.DLL
[Svchost DLLs] :HKLM DeviceInstall=C:\WINDOWS\SYSTEM32\UMPNPMGR.DLL
### User-mode Plug-and-Play Service Microsoft Corporation Microsoft Windows Oper
ating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\UMPNPMGR.DLL
[Svchost DLLs] :HKLM CryptSvc=C:\WINDOWS\SYSTEM32\CRYPTSVC.DLL
### Cryptographic Services Microsoft Corporation Microsoft Windows Operating Sys
tem 10.0.10586.0 C:\WINDOWS\SYSTEM32\CRYPTSVC.DLL
[Svchost DLLs] :HKLM WinRM=C:\WINDOWS\SYSTEM32\WSMSVC.DLL
### WSMan Service Microsoft Corporation Microsoft Windows Operating System 10.0.
10586.0 C:\WINDOWS\SYSTEM32\WSMSVC.DLL
[Svchost DLLs] :HKLM WECSVC=C:\WINDOWS\SYSTEM32\WECSVC.DLL
### Event Collector Service Microsoft Corporation Microsoft Windows Operating Sy
stem 10.0.10586.0 C:\WINDOWS\SYSTEM32\WECSVC.DLL
[Svchost DLLs] :HKLM TermService=C:\WINDOWS\SYSTEM32\TERMSRV.DLL
### Remote Desktop Session Host Server Remote Connections Manager Microsoft Co
rporation Microsoft Windows Operating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\TER
MSRV.DLL
[Svchost DLLs] :HKLM DNSCache=C:\WINDOWS\SYSTEM32\DNSRSLVR.DLL
### DNS Caching Resolver Service Microsoft Corporation Microsoft Windows Operati
ng System 10.0.10586.0 C:\WINDOWS\SYSTEM32\DNSRSLVR.DLL
[Svchost DLLs] :HKLM AJRouter=C:\WINDOWS\SYSTEM32\AJROUTER.DLL
### AllJoyn Router Service DLL Microsoft Corporation Microsoft Windows Operating
System 10.0.10586.0 C:\WINDOWS\SYSTEM32\AJROUTER.DLL
[Svchost DLLs] :HKLM AppIDSvc=C:\WINDOWS\SYSTEM32\APPIDSVC.DLL
### Application Identity Service Microsoft Corporation Microsoft Windows Operati
ng System 10.0.10586.0 C:\WINDOWS\SYSTEM32\APPIDSVC.DLL
[Svchost DLLs] :HKLM Appinfo=C:\WINDOWS\SYSTEM32\APPINFO.DLL
### Application Information Service Microsoft Corporation Microsoft Windows Oper
ating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\APPINFO.DLL
[Svchost DLLs] :HKLM AppReadiness=C:\WINDOWS\SYSTEM32\APPREADINESS.DLL
### AppReadiness Microsoft Corporation Microsoft Windows Operating System 10.0.1
0586.0 C:\WINDOWS\SYSTEM32\APPREADINESS.DLL
[Svchost DLLs] :HKLM AxInstSV=C:\WINDOWS\SYSTEM32\AXINSTSV.DLL
### ActiveX Installer Service Microsoft Corporation Microsoft Windows Operating
System 10.0.10586.0 C:\WINDOWS\SYSTEM32\AXINSTSV.DLL
[Svchost DLLs] :HKLM BDESVC=C:\WINDOWS\SYSTEM32\BDESVC.DLL
### BDE Service Microsoft Corporation Microsoft Windows Operating System 10.0.10
586.0 C:\WINDOWS\SYSTEM32\BDESVC.DLL
[Svchost DLLs] :HKLM BFE=C:\WINDOWS\SYSTEM32\BFE.DLL
### Base Filtering Engine Microsoft Corporation Microsoft Windows Operating Syst
em 10.0.10586.0 C:\WINDOWS\SYSTEM32\BFE.DLL
[Svchost DLLs] :HKLM BrokerInfrastructure=C:\WINDOWS\SYSTEM32\BISRV.DLL

### Background Tasks Infrastructure Service Microsoft Corporation Microsoft Win


dows Operating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\BISRV.DLL
[Svchost DLLs] :HKLM Browser=C:\WINDOWS\SYSTEM32\BROWSER.DLL
### Computer Browser Service DLL Microsoft Corporation Microsoft Windows Operati
ng System 10.0.10586.0 C:\WINDOWS\SYSTEM32\BROWSER.DLL
[Svchost DLLs] :HKLM bthserv=C:\WINDOWS\SYSTEM32\BTHSERV.DLL
### Bluetooth Support Service Microsoft Corporation Microsoft Windows Operating
System 10.0.10586.0 C:\WINDOWS\SYSTEM32\BTHSERV.DLL
[Svchost DLLs] :HKLM CDPSvc=C:\WINDOWS\SYSTEM32\CDPSVC.DLL
### Microsoft (R) CDP Service Microsoft Corporation Microsoft Windows Operating
System 10.0.10586.0 C:\WINDOWS\SYSTEM32\CDPSVC.DLL
[Svchost DLLs] :HKLM ClipSVC=C:\WINDOWS\SYSTEM32\CLIPSVC.DLL
### Client License Service Microsoft Corporation Microsoft Windows Operating Sys
tem 10.0.10586.0 C:\WINDOWS\SYSTEM32\CLIPSVC.DLL
[Svchost DLLs] :HKLM CoreMessagingRegistrar=C:\WINDOWS\SYSTEM32\COREMESSAGING.
DLL
### Microsoft CoreMessaging Dll Microsoft Corporation Microsoft Windows Operatin
g System 10.0.10586.0 C:\WINDOWS\SYSTEM32\COREMESSAGING.DLL
[Svchost DLLs] :HKLM CscService=C:\WINDOWS\SYSTEM32\CSCSVC.DLL
### CSC Service DLL Microsoft Corporation Microsoft Windows Operating System 10.
0.10586.0 C:\WINDOWS\SYSTEM32\CSCSVC.DLL
[Svchost DLLs] :HKLM DcpSvc=C:\WINDOWS\SYSTEM32\DCPSVC.DLL
### dcpsvc Task Microsoft Corporation Microsoft Windows Operating System 10.0.10
586.0 C:\WINDOWS\SYSTEM32\DCPSVC.DLL
[Svchost DLLs] :HKLM defragsvc=C:\WINDOWS\SYSTEM32\DEFRAGSVC.DLL
### Microsoft\Drive Optimizer Microsoft Corporation Microsoft Windows Operating
System 10.0.10586.0 C:\WINDOWS\SYSTEM32\DEFRAGSVC.DLL
[Svchost DLLs] :HKLM DevQueryBroker=C:\WINDOWS\SYSTEM32\DEVQUERYBROKER.DLL
### DevQuery Background Discovery Broker Microsoft Corporation Microsoft Window
s Operating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\DEVQUERYBROKER.DLL
[Svchost DLLs] :HKLM DiagTrack=C:\WINDOWS\SYSTEM32\DIAGTRACK.DLL
### Microsoft Windows Diagnostics Tracking Microsoft Corporation Microsoft Wind
ows Operating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\DIAGTRACK.DLL
[Svchost DLLs] :HKLM DmEnrollmentSvc=C:\WINDOWS\SYSTEM32\WINDOWS.INTERNAL.MANA
GEMENT.DLL
### Windows Managent Service DLL Microsoft Corporation Microsoft Windows Operati
ng System 10.0.10586.0 C:\WINDOWS\SYSTEM32\WINDOWS.INTERNAL.MANAGEMENT.DLL
[Svchost DLLs] :HKLM dmwappushservice=C:\WINDOWS\SYSTEM32\DMWAPPUSHSVC.DLL
### dmwappushsvc Microsoft Corporation Microsoft Windows Operating System 10.0.1
0586.0 C:\WINDOWS\SYSTEM32\DMWAPPUSHSVC.DLL
[Svchost DLLs] :HKLM DPS=C:\WINDOWS\SYSTEM32\DPS.DLL
### WDI Diagnostic Policy Service Microsoft Corporation Microsoft Windows Operat
ing System 10.0.10586.0 C:\WINDOWS\SYSTEM32\DPS.DLL
[Svchost DLLs] :HKLM DsmSvc=C:\WINDOWS\SYSTEM32\DEVICESETUPMANAGER.DLL
### Device Setup Manager Microsoft Corporation Microsoft Windows Operating Syste
m 10.0.10586.0 C:\WINDOWS\SYSTEM32\DEVICESETUPMANAGER.DLL
[Svchost DLLs] :HKLM DsSvc=C:\WINDOWS\SYSTEM32\DSSVC.DLL
### Data Sharing Service NT Service DLL Microsoft Corporation Microsoft Windows
Operating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\DSSVC.DLL
[Svchost DLLs] :HKLM Eaphost=C:\WINDOWS\SYSTEM32\EAPSVC.DLL
### Microsoft EAPHost service Microsoft Corporation Microsoft Windows Operating
System 10.0.10586.0 C:\WINDOWS\SYSTEM32\EAPSVC.DLL
[Svchost DLLs] :HKLM EFS=C:\WINDOWS\SYSTEM32\EFSSVC.DLL
### EFS Service Microsoft Corporation Microsoft Windows Operating System 10.0.10
586.0 C:\WINDOWS\SYSTEM32\EFSSVC.DLL
[Svchost DLLs] :HKLM embeddedmode=C:\WINDOWS\SYSTEM32\EMBEDDEDMODESVC.DLL
### Debug Register Service Microsoft Corporation Microsoft Windows Operating Sys
tem 10.0.10586.0 C:\WINDOWS\SYSTEM32\EMBEDDEDMODESVC.DLL
[Svchost DLLs] :HKLM EventSystem=C:\WINDOWS\SYSTEM32\ES.DLL
### COM+ Microsoft Corporation Microsoft Windows Operating System 10.0.10586.0

C:\WINDOWS\SYSTEM32\ES.DLL
[Svchost DLLs] :HKLM fdPHost=C:\WINDOWS\SYSTEM32\FDPHOST.DLL
### Function Discovery Provider host service Microsoft Corporation Microsoft Wi
ndows Operating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\FDPHOST.DLL
[Svchost DLLs] :HKLM FDResPub=C:\WINDOWS\SYSTEM32\FDRESPUB.DLL
### Function Discovery Resource Publication Service Microsoft Corporation Micr
osoft Windows Operating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\FDRESPUB.DLL
[Svchost DLLs] :HKLM fhsvc=C:\WINDOWS\SYSTEM32\FHSVC.DLL
### File History Service Microsoft Corporation Microsoft Windows Operating Syste
m 10.0.10586.0 C:\WINDOWS\SYSTEM32\FHSVC.DLL
[Svchost DLLs] :HKLM FontCache=C:\WINDOWS\SYSTEM32\FNTCACHE.DLL
### Windows Font Cache Service Microsoft Corporation Microsoft Windows Operating
System 10.0.10586.0 C:\WINDOWS\SYSTEM32\FNTCACHE.DLL
[Svchost DLLs] :HKLM hidserv=C:\WINDOWS\SYSTEM32\HIDSERV.DLL
### Human Interface Device Service Microsoft Corporation Microsoft Windows Opera
ting System 10.0.10586.0 C:\WINDOWS\SYSTEM32\HIDSERV.DLL
[Svchost DLLs] :HKLM HomeGroupListener=C:\WINDOWS\SYSTEM32\LISTSVC.DLL
### Windows HomeGroup Microsoft Corporation Microsoft Windows Operating System 1
0.0.10586.0 C:\WINDOWS\SYSTEM32\LISTSVC.DLL
[Svchost DLLs] :HKLM HomeGroupProvider=C:\WINDOWS\SYSTEM32\PROVSVC.DLL
### Windows HomeGroup Microsoft Corporation Microsoft Windows Operating System 1
0.0.10586.0 C:\WINDOWS\SYSTEM32\PROVSVC.DLL
[Svchost DLLs] :HKLM icssvc=C:\WINDOWS\SYSTEM32\TETHERINGSERVICE.DLL
### Tethering Service Microsoft Corporation Microsoft Windows Operating System 1
0.0.10586.0 C:\WINDOWS\SYSTEM32\TETHERINGSERVICE.DLL
[Svchost DLLs] :HKLM IKEEXT=C:\WINDOWS\SYSTEM32\IKEEXT.DLL
### IKE extension Microsoft Corporation Microsoft Windows Operating System 10.0.
10586.0 C:\WINDOWS\SYSTEM32\IKEEXT.DLL
[Svchost DLLs] :HKLM KeyIso=C:\WINDOWS\SYSTEM32\KEYISO.DLL
### CNG Key Isolation Service Microsoft Corporation Microsoft Windows Operating
System 10.0.10586.0 C:\WINDOWS\SYSTEM32\KEYISO.DLL
[Svchost DLLs] :HKLM KtmRm=C:\WINDOWS\SYSTEM32\MSDTCKRM.DLL
### Microsoft Distributed Transaction Coordinator OLE Transactions KTM Resourc
e Manager DLL Microsoft Corporation Microsoft Windows Operating System 10.0.10586.
0 C:\WINDOWS\SYSTEM32\MSDTCKRM.DLL
[Svchost DLLs] :HKLM LanmanWorkstation=C:\WINDOWS\SYSTEM32\WKSSVC.DLL
### Workstation Service DLL Microsoft Corporation Microsoft Windows Operating Sy
stem 10.0.10586.0 C:\WINDOWS\SYSTEM32\WKSSVC.DLL
[Svchost DLLs] :HKLM lfsvc=C:\WINDOWS\SYSTEM32\LFSVC.DLL
### Geolocation Service Microsoft Corporation Microsoft Windows Operating System
10.0.10586.0 C:\WINDOWS\SYSTEM32\LFSVC.DLL
[Svchost DLLs] :HKLM LicenseManager=C:\WINDOWS\SYSTEM32\LICENSEMANAGERSVC.DLL
### LicenseManagerSvc Microsoft Corporation Microsoft Windows Operating System 1
0.0.10586.0 C:\WINDOWS\SYSTEM32\LICENSEMANAGERSVC.DLL
[Svchost DLLs] :HKLM lltdsvc=C:\WINDOWS\SYSTEM32\LLTDSVC.DLL
### Link-Layer Topology Mapper Service Microsoft Corporation Microsoft Windows O
perating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\LLTDSVC.DLL
[Svchost DLLs] :HKLM LSM=C:\WINDOWS\SYSTEM32\LSM.DLL
### Local Session Manager Service Microsoft Corporation Microsoft Windows Operat
ing System 10.0.10586.0 C:\WINDOWS\SYSTEM32\LSM.DLL
[Svchost DLLs] :HKLM MapsBroker=C:\WINDOWS\SYSTEM32\MOSHOST.DLL
### Downloaded Maps Manager Microsoft Corporation Microsoft Windows Operating Sy
stem 10.0.10586.0 C:\WINDOWS\SYSTEM32\MOSHOST.DLL
[Svchost DLLs] :HKLM MessagingService=C:\WINDOWS\SYSTEM32\MESSAGINGSERVICE.DLL
### Messaging Service Microsoft Corporation Microsoft Windows Operating System 1
0.0.10586.0 C:\WINDOWS\SYSTEM32\MESSAGINGSERVICE.DLL
[Svchost DLLs] :HKLM MpsSvc=C:\WINDOWS\SYSTEM32\MPSSVC.DLL
### Microsoft Protection Service Microsoft Corporation Microsoft Windows Operati
ng System 10.0.10586.0 C:\WINDOWS\SYSTEM32\MPSSVC.DLL
[Svchost DLLs] :HKLM NcaSvc=C:\WINDOWS\SYSTEM32\NCASVC.DLL

### Microsoft Network Connectivity Assistant Service Microsoft Corporation Mic


rosoft Windows Operating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\NCASVC.DLL
[Svchost DLLs] :HKLM NcdAutoSetup=C:\WINDOWS\SYSTEM32\NCDAUTOSETUP.DLL
### Network Connected Devices Auto-Setup service DLL Microsoft Corporation Mic
rosoft Windows Operating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\NCDAUTOSETUP.DLL
[Svchost DLLs] :HKLM Netlogon=C:\WINDOWS\SYSTEM32\NETLOGON.DLL
### Net Logon Services DLL Microsoft Corporation Microsoft Windows Operating Sys
tem 10.0.10586.0 C:\WINDOWS\SYSTEM32\NETLOGON.DLL
[Svchost DLLs] :HKLM NgcCtnrSvc=C:\WINDOWS\SYSTEM32\NGCCTNRSVC.DLL
### Microsoft Passport Container Service Microsoft Corporation Microsoft Window
s Operating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\NGCCTNRSVC.DLL
[Svchost DLLs] :HKLM NgcSvc=C:\WINDOWS\SYSTEM32\NGCSVC.DLL
### Microsoft Passport Service Microsoft Corporation Microsoft Windows Operating
System 10.0.10586.0 C:\WINDOWS\SYSTEM32\NGCSVC.DLL
[Svchost DLLs] :HKLM NlaSvc=C:\WINDOWS\SYSTEM32\NLASVC.DLL
### Network Location Awareness 2 Microsoft Corporation Microsoft Windows Operati
ng System 10.0.10586.0 C:\WINDOWS\SYSTEM32\NLASVC.DLL
[Svchost DLLs] :HKLM nsi=C:\WINDOWS\SYSTEM32\NSISVC.DLL
### Network Store Interface RPC server Microsoft Corporation Microsoft Windows O
perating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\NSISVC.DLL
[Svchost DLLs] :HKLM OneSyncSvc=C:\WINDOWS\SYSTEM32\APHOSTSERVICE.DLL
### Accounts Host Service Microsoft Corporation Microsoft Windows Operating Syst
em 10.0.10586.0 C:\WINDOWS\SYSTEM32\APHOSTSERVICE.DLL
[Svchost DLLs] :HKLM p2pimsvc=C:\WINDOWS\SYSTEM32\PNRPSVC.DLL
### PNRP Service Dll Microsoft Corporation Microsoft Windows Operating System 10
.0.10586.0 C:\WINDOWS\SYSTEM32\PNRPSVC.DLL
[Svchost DLLs] :HKLM p2psvc=C:\WINDOWS\SYSTEM32\P2PSVC.DLL
### Peer-to-Peer Services Microsoft Corporation Microsoft Windows Operating Syst
em 10.0.10586.0 C:\WINDOWS\SYSTEM32\P2PSVC.DLL
[Svchost DLLs] :HKLM PcaSvc=C:\WINDOWS\SYSTEM32\PCASVC.DLL
### Program Compatibility Assistant Service Microsoft Corporation Microsoft Win
dows Operating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\PCASVC.DLL
[Svchost DLLs] :HKLM PhoneSvc=C:\WINDOWS\SYSTEM32\PHONESERVICE.DLL
### The service used to manage phone calls and other telephony related functio
nality Microsoft Corporation Microsoft Windows Operating System 10.0.10586.0 C:\W
INDOWS\SYSTEM32\PHONESERVICE.DLL
[Svchost DLLs] :HKLM PimIndexMaintenanceSvc=C:\WINDOWS\SYSTEM32\PIMINDEXMAINTE
NANCE.DLL
### Service responsible for contacts indexing and other user data related task
s Microsoft Corporation Microsoft Windows Operating System 10.0.10586.0 C:\WINDOW
S\SYSTEM32\PIMINDEXMAINTENANCE.DLL
[Svchost DLLs] :HKLM PolicyAgent=C:\WINDOWS\SYSTEM32\IPSECSVC.DLL
### Windows IPsec SPD Server DLL Microsoft Corporation Microsoft Windows Operati
ng System 10.0.10586.0 C:\WINDOWS\SYSTEM32\IPSECSVC.DLL
[Svchost DLLs] :HKLM Power=C:\WINDOWS\SYSTEM32\UMPO.DLL
### User-mode Power Service Microsoft Corporation Microsoft Windows Operating Sy
stem 10.0.10586.0 C:\WINDOWS\SYSTEM32\UMPO.DLL
[Svchost DLLs] :HKLM PrintNotify=C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\X64\3\PRINT
CONFIG.DLL
### PrintConfig User Interface Microsoft Corporation Microsoft Windows Operating
System 10.0.10586.0
[Svchost DLLs] :HKLM ProfSvc=C:\WINDOWS\SYSTEM32\PROFSVC.DLL
### ProfSvc Microsoft Corporation Microsoft Windows Operating System 10.0.10586.
0 C:\WINDOWS\SYSTEM32\PROFSVC.DLL
[Svchost DLLs] :HKLM RemoteRegistry=C:\WINDOWS\SYSTEM32\REGSVC.DLL
### Remote Registry Service Microsoft Corporation Microsoft Windows Operating Sy
stem 10.0.10586.0 C:\WINDOWS\SYSTEM32\REGSVC.DLL
[Svchost DLLs] :HKLM RetailDemo=C:\WINDOWS\SYSTEM32\RDXSERVICE.DLL
### RDXService Microsoft Corporation Microsoft Windows Operating System 10.0.105
86.0 C:\WINDOWS\SYSTEM32\RDXSERVICE.DLL

[Svchost DLLs] :HKLM RpcEptMapper=C:\WINDOWS\SYSTEM32\RPCEPMAP.DLL


### RPC Endpoint Mapper Microsoft Corporation Microsoft Windows Operating System
10.0.10586.0 C:\WINDOWS\SYSTEM32\RPCEPMAP.DLL
[Svchost DLLs] :HKLM SDRSVC=C:\WINDOWS\SYSTEM32\SDRSVC.DLL
### Microsoft Windows Backup Service Microsoft Corporation Microsoft Windows Oper
ating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\SDRSVC.DLL
[Svchost DLLs] :HKLM seclogon=C:\WINDOWS\SYSTEM32\SECLOGON.DLL
### Secondary Logon Service DLL Microsoft Corporation Microsoft Windows Operatin
g System 10.0.10586.0 C:\WINDOWS\SYSTEM32\SECLOGON.DLL
[Svchost DLLs] :HKLM SensorService=C:\WINDOWS\SYSTEM32\SENSORSERVICE.DLL
### Sensor Service Microsoft Corporation Microsoft Windows Operating System 10.0
.10586.0 C:\WINDOWS\SYSTEM32\SENSORSERVICE.DLL
[Svchost DLLs] :HKLM SensrSvc=C:\WINDOWS\SYSTEM32\SENSRSVC.DLL
### Microsoft Windows Sensor Monitoring Service Microsoft Corporation Microsof
t Windows Operating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\SENSRSVC.DLL
[Svchost DLLs] :HKLM SmsRouter=C:\WINDOWS\SYSTEM32\SMSROUTERSVC.DLL
### Windows SMS Router Service Microsoft Corporation Microsoft Windows Operating
System 10.0.10586.0 C:\WINDOWS\SYSTEM32\SMSROUTERSVC.DLL
[Svchost DLLs] :HKLM SstpSvc=C:\WINDOWS\SYSTEM32\SSTPSVC.DLL
### Provides the facility of using Secure Socket Tunneling Protocol (SSTP) to
connect to remote computers (using VPN). Microsoft Corporation Microsoft Windows O
perating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\SSTPSVC.DLL
[Svchost DLLs] :HKLM StorSvc=C:\WINDOWS\SYSTEM32\STORSVC.DLL
### Storage Services Microsoft Corporation Microsoft Windows Operating System 10
.0.10586.0 C:\WINDOWS\SYSTEM32\STORSVC.DLL
[Svchost DLLs] :HKLM svsvc=C:\WINDOWS\SYSTEM32\SVSVC.DLL
### Microsoft\Spot Verifier Microsoft Corporation Microsoft Windows Operating Sy
stem 10.0.10586.0 C:\WINDOWS\SYSTEM32\SVSVC.DLL
[Svchost DLLs] :HKLM swprv=C:\WINDOWS\SYSTEM32\SWPRV.DLL
### Microsoft Volume Shadow Copy Service software provider Microsoft Corporatio
n Microsoft Windows Operating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\SWPRV.DLL
[Svchost DLLs] :HKLM SysMain=C:\WINDOWS\SYSTEM32\SYSMAIN.DLL
### Superfetch Service Host Microsoft Corporation Microsoft Windows Operating Sy
stem 10.0.10586.0 C:\WINDOWS\SYSTEM32\SYSMAIN.DLL
[Svchost DLLs] :HKLM SystemEventsBroker=C:\WINDOWS\SYSTEM32\SYSTEMEVENTSBROKER
SERVER.DLL
### System Events Broker Microsoft Corporation Microsoft Windows Operating Syste
m 10.0.10586.0 C:\WINDOWS\SYSTEM32\SYSTEMEVENTSBROKERSERVER.DLL
[Svchost DLLs] :HKLM TabletInputService=C:\WINDOWS\SYSTEM32\TABSVC.DLL
### Microsoft Touch Keyboard and Handwriting Panel Service Microsoft Corporati
on Microsoft Windows Operating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\TABSVC.DLL
[Svchost DLLs] :HKLM Themes=C:\WINDOWS\SYSTEM32\THEMESERVICE.DLL
### Windows Shell Theme Service Dll Microsoft Corporation Microsoft Windows Oper
ating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\THEMESERVICE.DLL
[Svchost DLLs] :HKLM TimeBroker=C:\WINDOWS\SYSTEM32\TIMEBROKERSERVER.DLL
### Time Event Broker Microsoft Corporation Microsoft Windows Operating System 1
0.0.10586.0 C:\WINDOWS\SYSTEM32\TIMEBROKERSERVER.DLL
[Svchost DLLs] :HKLM TrkWks=C:\WINDOWS\SYSTEM32\TRKWKS.DLL
### Distributed Link Tracking Client Microsoft Corporation Microsoft Windows Ope
rating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\TRKWKS.DLL
[Svchost DLLs] :HKLM tzautoupdate=C:\WINDOWS\SYSTEM32\TZAUTOUPDATE.DLL
### Auto Time Zone Updater Microsoft Corporation Microsoft Windows Operating Sys
tem 10.0.10586.0 C:\WINDOWS\SYSTEM32\TZAUTOUPDATE.DLL
[Svchost DLLs] :HKLM UmRdpService=C:\WINDOWS\SYSTEM32\UMRDP.DLL
### Remote Desktop Services Device Redirector Service Microsoft Corporation Mi
crosoft Windows Operating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\UMRDP.DLL
[Svchost DLLs] :HKLM UnistoreSvc=C:\WINDOWS\SYSTEM32\UNISTORE.DLL
### Unified Store Microsoft Corporation Microsoft Windows Operating System 10.0.
10586.0 C:\WINDOWS\SYSTEM32\UNISTORE.DLL
[Svchost DLLs] :HKLM UserDataSvc=C:\WINDOWS\SYSTEM32\USERDATASERVICE.DLL

### The endpoint for 3rd party APIs to read/write user data Microsoft Corporat
ion Microsoft Windows Operating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\USERDATAS
ERVICE.DLL
[Svchost DLLs] :HKLM UsoSvc=C:\WINDOWS\SYSTEM32\USOCORE.DLL
### Update Session Orchestrator Core Microsoft Corporation Microsoft Windows Ope
rating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\USOCORE.DLL
[Svchost DLLs] :HKLM VaultSvc=C:\WINDOWS\SYSTEM32\VAULTSVC.DLL
### Credential Manager Service Microsoft Corporation Microsoft Windows Operating
System 10.0.10586.0
[Svchost DLLs] :HKLM vmicguestinterface=C:\WINDOWS\SYSTEM32\ICSVC.DLL
### Virtual Machine Integration Component Service Microsoft Corporation Micros
oft Windows Operating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\ICSVC.DLL
[Svchost DLLs] :HKLM vmicheartbeat=C:\WINDOWS\SYSTEM32\ICSVC.DLL
### Virtual Machine Integration Component Service Microsoft Corporation Micros
oft Windows Operating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\ICSVC.DLL
[Svchost DLLs] :HKLM vmickvpexchange=C:\WINDOWS\SYSTEM32\ICSVC.DLL
### Virtual Machine Integration Component Service Microsoft Corporation Micros
oft Windows Operating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\ICSVC.DLL
[Svchost DLLs] :HKLM vmicrdv=C:\WINDOWS\SYSTEM32\ICSVC.DLL
### Virtual Machine Integration Component Service Microsoft Corporation Micros
oft Windows Operating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\ICSVC.DLL
[Svchost DLLs] :HKLM vmicshutdown=C:\WINDOWS\SYSTEM32\ICSVC.DLL
### Virtual Machine Integration Component Service Microsoft Corporation Micros
oft Windows Operating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\ICSVC.DLL
[Svchost DLLs] :HKLM vmictimesync=C:\WINDOWS\SYSTEM32\ICSVC.DLL
### Virtual Machine Integration Component Service Microsoft Corporation Micros
oft Windows Operating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\ICSVC.DLL
[Svchost DLLs] :HKLM vmicvmsession=C:\WINDOWS\SYSTEM32\ICSVC.DLL
### Virtual Machine Integration Component Service Microsoft Corporation Micros
oft Windows Operating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\ICSVC.DLL
[Svchost DLLs] :HKLM vmicvss=C:\WINDOWS\SYSTEM32\ICSVC.DLL
### Virtual Machine Integration Component Service Microsoft Corporation Micros
oft Windows Operating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\ICSVC.DLL
[Svchost DLLs] :HKLM W32Time=C:\WINDOWS\SYSTEM32\W32TIME.DLL
### Windows Time Service Microsoft Corporation Microsoft Windows Operating Syste
m 10.0.10586.0 C:\WINDOWS\SYSTEM32\W32TIME.DLL
[Svchost DLLs] :HKLM WalletService=C:\WINDOWS\SYSTEM32\WALLETSERVICE.DLL
### Wallet Service Microsoft Corporation Microsoft Windows Operating System 10.0
.10586.0 C:\WINDOWS\SYSTEM32\WALLETSERVICE.DLL
[Svchost DLLs] :HKLM WbioSrvc=C:\WINDOWS\SYSTEM32\WBIOSRVC.DLL
### Windows Biometric Service Microsoft Corporation Microsoft Windows Operating
System 10.0.10586.0 C:\WINDOWS\SYSTEM32\WBIOSRVC.DLL
[Svchost DLLs] :HKLM Wcmsvc=C:\WINDOWS\SYSTEM32\WCMSVC.DLL
### Windows Connection Manager Service DLL Microsoft Corporation Microsoft Wind
ows Operating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\WCMSVC.DLL
[Svchost DLLs] :HKLM WdiServiceHost=C:\WINDOWS\SYSTEM32\WDI.DLL
### Windows Diagnostic Infrastructure Microsoft Corporation Microsoft Windows Op
erating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\WDI.DLL
[Svchost DLLs] :HKLM WdiSystemHost=C:\WINDOWS\SYSTEM32\WDI.DLL
### Windows Diagnostic Infrastructure Microsoft Corporation Microsoft Windows Op
erating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\WDI.DLL
[Svchost DLLs] :HKLM WEPHOSTSVC=C:\WINDOWS\SYSTEM32\WEPHOSTSVC.DLL
### WEP Host Service Microsoft Corporation Microsoft Windows Operating System 10
.0.10586.0 C:\WINDOWS\SYSTEM32\WEPHOSTSVC.DLL
[Svchost DLLs] :HKLM wercplsupport=C:\WINDOWS\SYSTEM32\WERCPLSUPPORT.DLL
### Problem Reports and Solutions Microsoft Corporation Microsoft Windows Operat
ing System 10.0.10586.0 C:\WINDOWS\SYSTEM32\WERCPLSUPPORT.DLL
[Svchost DLLs] :HKLM WerSvc=C:\WINDOWS\SYSTEM32\WERSVC.DLL
### Windows Error Reporting Service Microsoft Corporation Microsoft Windows Oper
ating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\WERSVC.DLL

[Svchost DLLs] :HKLM wlidsvc=C:\WINDOWS\SYSTEM32\WLIDSVC.DLL


### Microsoft Account Service Microsoft Corporation Microsoft Windows Operating S
ystem 10.0.10586.0 C:\WINDOWS\SYSTEM32\WLIDSVC.DLL
[Svchost DLLs] :HKLM workfolderssvc=C:\WINDOWS\SYSTEM32\WORKFOLDERSSVC.DLL
### Microsoft (C) Work Folders Service Microsoft Corporation Microsoft Windows O
perating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\WORKFOLDERSSVC.DLL
[Svchost DLLs] :HKLM WSService=C:\WINDOWS\SYSTEM32\WSSERVICE.DLL
### Windows Store Service Microsoft Corporation Microsoft Windows Operating Syst
em 10.0.10586.0 C:\WINDOWS\SYSTEM32\WSSERVICE.DLL
[Svchost DLLs] :HKLM wudfsvc=C:\WINDOWS\SYSTEM32\WUDFSVC.DLL
### Windows Driver Foundation - User-mode Driver Framework Service Microsoft C
orporation Microsoft Windows Operating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\WU
DFSVC.DLL
[Svchost DLLs] :HKLM WwanSvc=C:\WINDOWS\SYSTEM32\WWANSVC.DLL
### WWAN Auto Config Service Microsoft Corporation Microsoft Windows Operating S
ystem 8.1.10586.0 C:\WINDOWS\SYSTEM32\WWANSVC.DLL
[Svchost DLLs] :HKLM XblAuthManager=C:\WINDOWS\SYSTEM32\XBLAUTHMANAGER.DLL
### Xbox Live Auth Manager Microsoft Corporation Microsoft Windows Operating Sys
tem 10.0.10586.0 C:\WINDOWS\SYSTEM32\XBLAUTHMANAGER.DLL
[Svchost DLLs] :HKLM XblGameSave=C:\WINDOWS\SYSTEM32\XBLGAMESAVE.DLL
### Xbox Live Game Save Service Microsoft Corporation Microsoft Windows Operatin
g System 10.0.10586.0 C:\WINDOWS\SYSTEM32\XBLGAMESAVE.DLL
[Svchost DLLs] :HKLM XboxNetApiSvc=C:\WINDOWS\SYSTEM32\XBOXNETAPISVC.DLL
### Xbox Live Networking Service Microsoft Corporation Microsoft Windows Operati
ng System 10.0.10586.0 C:\WINDOWS\SYSTEM32\XBOXNETAPISVC.DLL
[Bootexecute] :HKLM BootExecute=PDBoot.exe
autocheck autochk *
[Winlogon System] :HKLM system=""
### File is deleted or hidden by a rootkit or could not be located.
[Winlogon System] :HKLM taskman=""
### File is deleted or hidden by a rootkit or could not be located.
[Winlogon System] :HKLM UIHost=""
### File is deleted or hidden by a rootkit or could not be located.
[Winlogon Autostart] :HKLM VmApplet=""
[Winlogon Autostart] :HKLM AppSetup=""
[Environment - Path] :HKLM Path=C:\Program Files (x86)\Intel\iCLS Client\;C:\P
rogram Files\Intel\iCLS Client\;C:\Windows\system32;C:\Windows;C:\Windows\System
32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Intel
\Intel(R) Management Engine Components\DAL;C:\Program Files\Intel\Intel(R) Manag
ement Engine Components\DAL;C:\Program Files (x86)\Intel\Intel(R) Management Eng
ine Components\IPT;C:\Program Files\Intel\Intel(R) Management Engine Components\
IPT;C:\Program Files\Intel\WiFi\bin\;C:\Program Files\Common Files\Intel\Wireles
sCommon\;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common
[List of Injected DLLs] :HKLM AppInit_DLLs=""
[LSA Notification Packages] :HKLM scecli=C:\Windows\SYSTEM32\SCECLI.DLL
### scecli Windows Security Configuration Editor Client Engine Microsoft Corpo
ration Microsoft Windows Operating System 10.0.10586.0 C:\Windows\SYSTEM32\SCECLI
.DLL
[Drivers] :HKLM 1394ohci=C:\WINDOWS\SYSTEM32\DRIVERS\1394OHCI.SYS
### 1394 OpenHCI Driver Microsoft Corporation Microsoft Windows Operating System
10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\1394OHCI.SYS Service registry key doe
sn't exist or hidden.
[Drivers] :HKLM 3ware=C:\WINDOWS\SYSTEM32\DRIVERS\3WARE.SYS
### LSI 3ware SCSI Storport Driver LSI LSI 3ware RAID Controller WindowsBlue
Service registry key doesn't exist or hidden.
[Drivers] :HKLM ACPI=C:\WINDOWS\SYSTEM32\DRIVERS\ACPI.SYS
### ACPI Driver for NT Microsoft Corporation Microsoft Windows Operating System
10.0.10586.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM acpiex=C:\WINDOWS\SYSTEM32\DRIVERS\ACPIEX.SYS

### ACPIEx Driver Microsoft Corporation Microsoft Windows Operating System 10.0.
10586.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM acpipagr=C:\WINDOWS\SYSTEM32\DRIVERS\ACPIPAGR.SYS
### ACPI Processor Aggregator Device Driver Microsoft Corporation Microsoft Win
dows Operating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\ACPIPAGR.SYS Serv
ice registry key doesn't exist or hidden.
[Drivers] :HKLM AcpiPmi=C:\WINDOWS\SYSTEM32\DRIVERS\ACPIPMI.SYS
### ACPI Power Metering Driver Microsoft Corporation Microsoft Windows Operating
System 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\ACPIPMI.SYS Service registry k
ey doesn't exist or hidden.
[Drivers] :HKLM acpitime=C:\WINDOWS\SYSTEM32\DRIVERS\ACPITIME.SYS
### ACPI Wake Alarm Microsoft Corporation Microsoft Windows Operating System 10.
0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\ACPITIME.SYS Service registry key doesn't
exist or hidden.
[Drivers] :HKLM ACPIVPC=C:\WINDOWS\SYSTEM32\DRIVERS\ACPIVPC.SYS
### ACPI Virtual Power Controller Driver Lenovo Corporation Lenovo 1.5.0.14 C
:\WINDOWS\SYSTEM32\DRIVERS\ACPIVPC.SYS Service registry key doesn't exist or hid
den.
[Drivers] :HKLM ADP80XX=C:\WINDOWS\SYSTEM32\DRIVERS\ADP80XX.SYS
### PMC-Sierra Storport Driver For SPC8x6G SAS/SATA controller PMC-Sierra PMC
-Sierra HBA Controller 1.3.0.10769 Service registry key doesn't exist or hidden
.
[Drivers] :HKLM AFD=C:\WINDOWS\SYSTEM32\DRIVERS\AFD.SYS
### Ancillary Function Driver for WinSock Microsoft Corporation Microsoft Windo
ws Operating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\AFD.SYS Service reg
istry key doesn't exist or hidden.
[Drivers] :HKLM agp440=C:\WINDOWS\SYSTEM32\DRIVERS\AGP440.SYS
### 440 NT AGP Filter Microsoft Corporation Microsoft Windows Operating System 1
0.0.10586.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM ahcache=C:\WINDOWS\SYSTEM32\DRIVERS\AHCACHE.SYS
### Application Compatibility Cache Microsoft Corporation Microsoft Windows Oper
ating System 10.0.10586.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM AmdK8=C:\WINDOWS\SYSTEM32\DRIVERS\AMDK8.SYS
### Processor Device Driver Microsoft Corporation Microsoft Windows Operating Sy
stem 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\AMDK8.SYS Service registry key do
esn't exist or hidden.
[Drivers] :HKLM AmdPPM=C:\WINDOWS\SYSTEM32\DRIVERS\AMDPPM.SYS
### Processor Device Driver Microsoft Corporation Microsoft Windows Operating Sy
stem 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\AMDPPM.SYS Service registry key d
oesn't exist or hidden.
[Drivers] :HKLM amdsata=C:\WINDOWS\SYSTEM32\DRIVERS\AMDSATA.SYS
### AHCI 1.3 Device Driver Advanced Micro Devices AHCI 1.3 Device Driver 1.1.3
.277 Service registry key doesn't exist or hidden.
[Drivers] :HKLM amdsbs=C:\WINDOWS\SYSTEM32\DRIVERS\AMDSBS.SYS
### AMD Technology AHCI Compatible Controller Driver for Windows - AMD64 platf
orm AMD Technologies Inc. AMD Technology AHCI Compatible Controller 3.7.1540.43
Service registry key doesn't exist or hidden.
[Drivers] :HKLM amdxata=C:\WINDOWS\SYSTEM32\DRIVERS\AMDXATA.SYS
### Storage Filter Driver Advanced Micro Devices Storage Filter Driver 1.1.3.2
77 Service registry key doesn't exist or hidden.
[Drivers] :HKLM AppID=C:\WINDOWS\SYSTEM32\DRIVERS\APPID.SYS
### AppID Driver Microsoft Corporation Microsoft Windows Operating System 10.0.1
0586.122 Service registry key doesn't exist or hidden.
[Drivers] :HKLM arcsas=C:\WINDOWS\SYSTEM32\DRIVERS\ARCSAS.SYS
### Adaptec SAS RAID WS03 Driver PMC-Sierra, Inc. Adaptec RAID Controller 7.5.
0.32048 Service registry key doesn't exist or hidden.
[Drivers] :HKLM AsyncMac=C:\WINDOWS\SYSTEM32\DRIVERS\ASYNCMAC.SYS
### MS Remote Access serial network driver Microsoft Corporation Microsoft Wind
ows Operating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\ASYNCMAC.SYS Servi
ce registry key doesn't exist or hidden.

[Drivers] :HKLM atapi=C:\WINDOWS\SYSTEM32\DRIVERS\ATAPI.SYS


### ATAPI IDE Miniport Driver Microsoft Corporation Microsoft Windows Operating
System 10.0.10586.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM b06bdrv=C:\WINDOWS\SYSTEM32\DRIVERS\BXVBDA.SYS
### Broadcom NetXtreme II GigE VBD Broadcom Corporation Broadcom NetXtreme II
GigE 7.4.14.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM BasicDisplay=C:\WINDOWS\SYSTEM32\DRIVERS\BASICDISPLAY.SYS
### Microsoft Basic Display Driver Microsoft Corporation Microsoft Windows Opera
ting System 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\BASICDISPLAY.SYS Service r
egistry key doesn't exist or hidden.
[Drivers] :HKLM BasicRender=C:\WINDOWS\SYSTEM32\DRIVERS\BASICRENDER.SYS
### Microsoft Basic Render Driver Microsoft Corporation Microsoft Windows Operat
ing System 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\BASICRENDER.SYS Service reg
istry key doesn't exist or hidden.
[Drivers] :HKLM bcmfn=C:\WINDOWS\SYSTEM32\DRIVERS\BCMFN.SYS
### BCM Function 2 Device Driver Windows (R) Win 7 DDK provider Windows (R) W
in 7 DDK driver 6.3.9477.0 C:\WINDOWS\SYSTEM32\DRIVERS\BCMFN.SYS Service regist
ry key doesn't exist or hidden.
[Drivers] :HKLM bcmfn2=C:\WINDOWS\SYSTEM32\DRIVERS\BCMFN2.SYS
### BCM Function 2 Device Driver Windows (R) Win 7 DDK provider Windows (R) W
in 7 DDK driver 6.3.9391.6 C:\WINDOWS\SYSTEM32\DRIVERS\BCMFN2.SYS Service regis
try key doesn't exist or hidden.
[Drivers] :HKLM bowser=C:\WINDOWS\SYSTEM32\DRIVERS\BOWSER.SYS
### NT Lan Manager Datagram Receiver Driver Microsoft Corporation Microsoft Win
dows Operating System 10.0.10586.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM BthAvrcpTg=C:\WINDOWS\SYSTEM32\DRIVERS\BTHAVRCPTG.SYS
### Bluetooth Audio/Video Remote Control HID Microsoft Corporation Microsoft Wi
ndows Operating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\BTHAVRCPTG.SYS S
ervice registry key doesn't exist or hidden.
[Drivers] :HKLM BthEnum=C:\WINDOWS\SYSTEM32\DRIVERS\BTHENUM.SYS
### Bluetooth Bus Extender Microsoft Corporation Microsoft Windows Operating Sys
tem 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\BTHENUM.SYS Service registry key d
oesn't exist or hidden.
[Drivers] :HKLM BthHFEnum=C:\WINDOWS\SYSTEM32\DRIVERS\BTHHFENUM.SYS
### Bluetooth Hands-Free Audio and Call Control HID Enumerator Microsoft Corpo
ration Microsoft Windows Operating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVER
S\BTHHFENUM.SYS Service registry key doesn't exist or hidden.
[Drivers] :HKLM bthhfhid=C:\WINDOWS\SYSTEM32\DRIVERS\BTHHFHID.SYS
### Bluetooth Hands-free HID Minidriver Microsoft Corporation Microsoft Windows
Operating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\BTHHFHID.SYS Service
registry key doesn't exist or hidden.
[Drivers] :HKLM BthLEEnum=C:\WINDOWS\SYSTEM32\DRIVERS\BTHLEENUM.SYS
### Bluetooth LE Bus Enumerator Microsoft Corporation Microsoft Windows Operatin
g System 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\BTHLEENUM.SYS Service registr
y key doesn't exist or hidden.
[Drivers] :HKLM BTHMODEM=C:\WINDOWS\SYSTEM32\DRIVERS\BTHMODEM.SYS
### Bluetooth Communications Driver Microsoft Corporation Microsoft Windows Oper
ating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\BTHMODEM.SYS Service regi
stry key doesn't exist or hidden.
[Drivers] :HKLM BthPan=C:\WINDOWS\SYSTEM32\DRIVERS\BTHPAN.SYS
### Bluetooth Personal Area Networking Microsoft Corporation Microsoft Windows O
perating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\BTHPAN.SYS Service reg
istry key doesn't exist or hidden.
[Drivers] :HKLM BTHPORT=C:\WINDOWS\SYSTEM32\DRIVERS\BTHPORT.SYS
### Bluetooth Bus Driver Microsoft Corporation Microsoft Windows Operating Syste
m 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\BTHPORT.SYS Service registry key doe
sn't exist or hidden.
[Drivers] :HKLM BTHUSB=C:\WINDOWS\SYSTEM32\DRIVERS\BTHUSB.SYS
### Bluetooth Miniport Driver Microsoft Corporation Microsoft Windows Operating
System 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\BTHUSB.SYS Service registry key

doesn't exist or hidden.


[Drivers] :HKLM buttonconverter=C:\WINDOWS\SYSTEM32\DRIVERS\BUTTONCONVERTER.SY
S
### Button Converter Driver Microsoft Corporation Microsoft Windows Operating Sy
stem 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\BUTTONCONVERTER.SYS Service regis
try key doesn't exist or hidden.
[Drivers] :HKLM CapImg=C:\WINDOWS\SYSTEM32\DRIVERS\CAPIMG.SYS
### CapImg HID Driver Microsoft Corporation Microsoft Windows Operating System 1
0.0.10586.17 C:\WINDOWS\SYSTEM32\DRIVERS\CAPIMG.SYS Service registry key doesn'
t exist or hidden.
[Drivers] :HKLM cdfs=C:\WINDOWS\SYSTEM32\DRIVERS\CDFS.SYS
### CD-ROM File System Driver Microsoft Corporation Microsoft Windows Operating
System 10.0.10586.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM cdrom=C:\WINDOWS\SYSTEM32\DRIVERS\CDROM.SYS
### SCSI CD-ROM Driver Microsoft Corporation Microsoft Windows Operating System
10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\CDROM.SYS Service registry key doesn't
exist or hidden.
[Drivers] :HKLM circlass=C:\WINDOWS\SYSTEM32\DRIVERS\CIRCLASS.SYS
### Consumer IR Class Driver for eHome Microsoft Corporation Microsoft Windows O
perating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\CIRCLASS.SYS Service r
egistry key doesn't exist or hidden.
[Drivers] :HKLM CLFS=C:\WINDOWS\SYSTEM32\DRIVERS\CLFS.SYS
### Common Log File System Driver Microsoft Corporation Microsoft Windows Operat
ing System 10.0.10586.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM CmBatt=C:\WINDOWS\SYSTEM32\DRIVERS\CMBATT.SYS
### Control Method Battery Driver Microsoft Corporation Microsoft Windows Operat
ing System 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\CMBATT.SYS Service registry
key doesn't exist or hidden.
[Drivers] :HKLM cm_km=C:\WINDOWS\SYSTEM32\DRIVERS\CM_KM.SYS
### Cryptographic Module Driver x64 (Weak) Kaspersky Lab ZAO Kaspersky Crypto
Module 2.1.0.8 Service registry key doesn't exist or hidden.
[Drivers] :HKLM CNG=C:\WINDOWS\SYSTEM32\DRIVERS\CNG.SYS
### Kernel Cryptography, Next Generation Microsoft Corporation Microsoft Window
s Operating System 10.0.10586.420 Service registry key doesn't exist or hidden.
[Drivers] :HKLM cnghwassist=C:\WINDOWS\SYSTEM32\DRIVERS\CNGHWASSIST.SYS
### CNG Hardware Assist algorithm provider Microsoft Corporation Microsoft Wind
ows Operating System 10.0.10586.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM CompositeBus=C:\WINDOWS\SYSTEM32\DRIVERSTORE\FILEREPOSITORY\CO
MPOSITEBUS.INF_AMD64_912DFDEDC3D2F520\COMPOSITEBUS.SYS
### Multi-Transport Composite Bus Enumerator Microsoft Corporation Microsoft Wi
ndows Operating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERSTORE\FILEREPOSITO
RY\COMPOSITEBUS.INF_AMD64_912DFDEDC3D2F520\COMPOSITEBUS.SYS Service registry key
doesn't exist or hidden.
[Drivers] :HKLM condrv=C:\WINDOWS\SYSTEM32\DRIVERS\CONDRV.SYS
### Console Driver Microsoft Corporation Microsoft Windows Operating System 10.0
.10586.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM CSC=C:\WINDOWS\SYSTEM32\DRIVERS\CSC.SYS
### Windows Client Side Caching Driver Microsoft Corporation Microsoft Windows O
perating System 10.0.10586.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM dam=C:\WINDOWS\SYSTEM32\DRIVERS\DAM.SYS
### DAM Kernel Driver Microsoft Corporation Microsoft Windows Operating System 1
0.0.10586.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM Dfsc=C:\WINDOWS\SYSTEM32\DRIVERS\DFSC.SYS
### DFS Namespace Client Driver Microsoft Corporation Microsoft Windows Operatin
g System 10.0.10586.212 Service registry key doesn't exist or hidden.
[Drivers] :HKLM disk=C:\WINDOWS\SYSTEM32\DRIVERS\DISK.SYS
### PnP Disk Driver Microsoft Corporation Microsoft Windows Operating System 10.
0.10586.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM dmvsc=C:\WINDOWS\SYSTEM32\DRIVERS\DMVSC.SYS
### Dynamic Memory Microsoft Corporation Microsoft Windows Operating System 10.0

.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\DMVSC.SYS Service registry key doesn't exi


st or hidden.
[Drivers] :HKLM dptf_pch=C:\WINDOWS\SYSTEM32\DRIVERS\DPTF_PCH.SYS
### DPTF PCH Device (64-Bit) Intel Corporation Dynamic Platform Thermal Framew
ork 8.1.10600.150 C:\WINDOWS\SYSTEM32\DRIVERS\DPTF_PCH.SYS Service registry key
doesn't exist or hidden.
[Drivers] :HKLM drmkaud=C:\WINDOWS\SYSTEM32\DRIVERS\DRMKAUD.SYS
### Microsoft Trusted Audio Drivers Microsoft Corporation Microsoft Windows Oper
ating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\DRMKAUD.SYS Service regis
try key doesn't exist or hidden.
[Drivers] :HKLM DXGKrnl=C:\WINDOWS\SYSTEM32\DRIVERS\DXGKRNL.SYS
### DirectX Graphics Kernel Microsoft Corporation Microsoft Windows Operating Sy
stem 10.0.10586.420 C:\WINDOWS\SYSTEM32\DRIVERS\DXGKRNL.SYS Service registry ke
y doesn't exist or hidden.
[Drivers] :HKLM ebdrv=C:\WINDOWS\SYSTEM32\DRIVERS\EVBDA.SYS
### QLogic 10 GigE VBD QLogic Corporation QLogic 10 GigE 7.12.2.3 Service reg
istry key doesn't exist or hidden.
[Drivers] :HKLM EhStorClass=C:\WINDOWS\SYSTEM32\DRIVERS\EHSTORCLASS.SYS
### Enhanced Storage Class driver for IEEE 1667 devices Microsoft Corporation
Microsoft Windows Operating System 10.0.10586.0 Service registry key doesn't exis
t or hidden.
[Drivers] :HKLM EhStorTcgDrv=C:\WINDOWS\SYSTEM32\DRIVERS\EHSTORTCGDRV.SYS
### Microsoft driver for storage devices supporting IEEE 1667 and TCG protocol
s Microsoft Corporation Microsoft Windows Operating System 10.0.10586.0 Service r
egistry key doesn't exist or hidden.
[Drivers] :HKLM ErrDev=C:\WINDOWS\SYSTEM32\DRIVERS\ERRDEV.SYS
### Error Device Driver Microsoft Corporation Microsoft Windows Operating System
10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\ERRDEV.SYS Service registry key doesn
't exist or hidden.
[Drivers] :HKLM Fastboot=C:\WINDOWS\SYSTEM32\DRIVERS\FASTBOOT.SYS
### WINNT/2K/XP/2003 Driver Windows (R) Win 7 DDK provider Windows (R) Win 7 D
DK driver 6.1.7600.16385 Service registry key doesn't exist or hidden.
[Drivers] :HKLM fdc=C:\WINDOWS\SYSTEM32\DRIVERS\FDC.SYS
### Floppy Disk Controller Driver Microsoft Corporation Microsoft Windows Operat
ing System 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\FDC.SYS Service registry ke
y doesn't exist or hidden.
[Drivers] :HKLM FileCrypt=C:\WINDOWS\SYSTEM32\DRIVERS\FILECRYPT.SYS
### Windows sandboxing and encryption filter Microsoft Corporation Microsoft Wi
ndows Operating System 10.0.10586.306 Service registry key doesn't exist or hidd
en.
[Drivers] :HKLM FileInfo=C:\WINDOWS\SYSTEM32\DRIVERS\FILEINFO.SYS
### FileInfo Filter Driver Microsoft Corporation Microsoft Windows Operating Sys
tem 10.0.10586.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM Filetrace=C:\WINDOWS\SYSTEM32\DRIVERS\FILETRACE.SYS
### File Trace Filter Driver Microsoft Corporation Microsoft Windows Operating S
ystem 10.0.10586.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM flpydisk=C:\WINDOWS\SYSTEM32\DRIVERS\FLPYDISK.SYS
### Floppy Driver Microsoft Corporation Microsoft Windows Operating System 10.0.
10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\FLPYDISK.SYS Service registry key doesn't e
xist or hidden.
[Drivers] :HKLM FltMgr=C:\WINDOWS\SYSTEM32\DRIVERS\FLTMGR.SYS
### Microsoft Filesystem Filter Manager Microsoft Corporation Microsoft Windows
Operating System 10.0.10586.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM FsDepends=C:\WINDOWS\SYSTEM32\DRIVERS\FSDEPENDS.SYS
### File System Dependency Manager Mini Filter Driver Microsoft Corporation Mi
crosoft Windows Operating System 10.0.10586.0 Service registry key doesn't exist
or hidden.
[Drivers] :HKLM fvevol=C:\WINDOWS\SYSTEM32\DRIVERS\FVEVOL.SYS
### BitLocker Drive Encryption Driver Microsoft Corporation Microsoft Windows Op
erating System 10.0.10586.0 Service registry key doesn't exist or hidden.

[Drivers] :HKLM gagp30kx=C:\WINDOWS\SYSTEM32\DRIVERS\GAGP30KX.SYS


### MS Generic AGPv3.0 Filter for K8/9 Processor Platforms Microsoft Corporati
on Microsoft Windows Operating System 10.0.10586.0 Service registry key doesn't e
xist or hidden.
[Drivers] :HKLM gencounter=C:\WINDOWS\SYSTEM32\DRIVERS\VMGENCOUNTER.SYS
### Virtual Machine Generation Counter Microsoft Corporation Microsoft Windows O
perating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\VMGENCOUNTER.SYS Servi
ce registry key doesn't exist or hidden.
[Drivers] :HKLM genericusbfn=C:\WINDOWS\SYSTEM32\DRIVERS\GENERICUSBFN.SYS
### Generic USB Function Class Driver Microsoft Corporation Microsoft Windows Op
erating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\GENERICUSBFN.SYS Servic
e registry key doesn't exist or hidden.
[Drivers] :HKLM GPIOClx0101=C:\WINDOWS\SYSTEM32\DRIVERS\MSGPIOCLX.SYS
### GPIO Class Extension Driver Microsoft Corporation Microsoft Windows Operatin
g System 10.0.10586.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM GpuEnergyDrv=C:\WINDOWS\SYSTEM32\DRIVERS\GPUENERGYDRV.SYS
### GPU Energy Kernel Driver Microsoft Corporation Microsoft Windows Operating S
ystem 10.0.10586.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM HdAudAddService=C:\WINDOWS\SYSTEM32\DRIVERS\HDAUDIO.SYS
### High Definition Audio Function Driver Microsoft Corporation Microsoft Windo
ws Operating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\HDAUDIO.SYS Service
registry key doesn't exist or hidden.
[Drivers] :HKLM HDAudBus=C:\WINDOWS\SYSTEM32\DRIVERS\HDAUDBUS.SYS
### High Definition Audio Bus Driver Microsoft Corporation Microsoft Windows Ope
rating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\HDAUDBUS.SYS Service reg
istry key doesn't exist or hidden.
[Drivers] :HKLM HidBatt=C:\WINDOWS\SYSTEM32\DRIVERS\HIDBATT.SYS
### Hid Battery Driver Microsoft Corporation Microsoft Windows Operating System
10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\HIDBATT.SYS Service registry key doesn
't exist or hidden.
[Drivers] :HKLM HidBth=C:\WINDOWS\SYSTEM32\DRIVERS\HIDBTH.SYS
### Bluetooth Miniport Driver for HID Devices Microsoft Corporation Microsoft W
indows Operating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\HIDBTH.SYS Serv
ice registry key doesn't exist or hidden.
[Drivers] :HKLM hidi2c=C:\WINDOWS\SYSTEM32\DRIVERS\HIDI2C.SYS
### I2C HID Miniport Driver Microsoft Corporation Microsoft Windows Operating Sy
stem 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\HIDI2C.SYS Service registry key d
oesn't exist or hidden.
[Drivers] :HKLM hidinterrupt=C:\WINDOWS\SYSTEM32\DRIVERS\HIDINTERRUPT.SYS
### HID Button over Interrupt Driver Microsoft Corporation Microsoft Windows Ope
rating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\HIDINTERRUPT.SYS Service
registry key doesn't exist or hidden.
[Drivers] :HKLM HidIr=C:\WINDOWS\SYSTEM32\DRIVERS\HIDIR.SYS
### Infrared Miniport Driver for Input Devices Microsoft Corporation Microsoft
Windows Operating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\HIDIR.SYS Serv
ice registry key doesn't exist or hidden.
[Drivers] :HKLM HidUsb=C:\WINDOWS\SYSTEM32\DRIVERS\HIDUSB.SYS
### USB Miniport Driver for Input Devices Microsoft Corporation Microsoft Windo
ws Operating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\HIDUSB.SYS Service
registry key doesn't exist or hidden.
[Drivers] :HKLM HpSAMD=C:\WINDOWS\SYSTEM32\DRIVERS\HPSAMD.SYS
### Smart Array SAS/SATA Controller Media Driver Hewlett-Packard Company Smart
Array SAS/SATA Controller Media Driver 8.0.4.0 Build 1 Media Driver (x86-64) S
ervice registry key doesn't exist or hidden.
[Drivers] :HKLM HTTP=C:\WINDOWS\SYSTEM32\DRIVERS\HTTP.SYS
### HTTP Protocol Stack Microsoft Corporation Microsoft Windows Operating System
10.0.10586.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM hwpolicy=C:\WINDOWS\SYSTEM32\DRIVERS\HWPOLICY.SYS
### Hardware Policy Driver Microsoft Corporation Microsoft Windows Operating Sys
tem 10.0.10586.0 Service registry key doesn't exist or hidden.

[Drivers] :HKLM hyperkbd=C:\WINDOWS\SYSTEM32\DRIVERS\HYPERKBD.SYS


### Microsoft VMBus Synthetic Keyboard Driver Microsoft Corporation Microsoft W
indows Operating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\HYPERKBD.SYS Se
rvice registry key doesn't exist or hidden.
[Drivers] :HKLM i8042prt=C:\WINDOWS\SYSTEM32\DRIVERS\I8042PRT.SYS
### i8042 Port Driver Microsoft Corporation Microsoft Windows Operating System 1
0.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\I8042PRT.SYS Service registry key doesn
't exist or hidden.
[Drivers] :HKLM iai2c=C:\WINDOWS\SYSTEM32\DRIVERS\IAI2C.SYS
### Intel(R) Serial IO I2C Driver Intel(R) Corporation Intel(R) Serial IO I2C
Driver 604.10146.2643.68354 C:\WINDOWS\SYSTEM32\DRIVERS\IAI2C.SYS Service regis
try key doesn't exist or hidden.
[Drivers] :HKLM iaLPSS2i_I2C=C:\WINDOWS\SYSTEM32\DRIVERS\IALPSS2I_I2C.SYS
### Intel(R) Serial IO I2C Driver v2 Intel Corporation Intel(R) Serial IO Driv
er 30.63.1519.07 C:\WINDOWS\SYSTEM32\DRIVERS\IALPSS2I_I2C.SYS Service registry
key doesn't exist or hidden.
[Drivers] :HKLM iaLPSSi_GPIO=C:\WINDOWS\SYSTEM32\DRIVERS\IALPSSI_GPIO.SYS
### Intel(R) Serial IO GPIO Controller Driver Intel Corporation Intel(R) Seria
l IO Driver 1.1.250.0 C:\WINDOWS\SYSTEM32\DRIVERS\IALPSSI_GPIO.SYS Service regi
stry key doesn't exist or hidden.
[Drivers] :HKLM iaLPSSi_I2C=C:\WINDOWS\SYSTEM32\DRIVERS\IALPSSI_I2C.SYS
### Intel(R) Serial IO I2C Controller Driver Intel Corporation Intel(R) Serial
IO Driver 1.1.253.0 C:\WINDOWS\SYSTEM32\DRIVERS\IALPSSI_I2C.SYS Service regist
ry key doesn't exist or hidden.
[Drivers] :HKLM iaLPSS_GPIO=C:\WINDOWS\SYSTEM32\DRIVERS\IALPSS_GPIO.SYS
### Intel(R) Serial IO GPIO Driver Intel Corporation Intel(R) Serial IO Driver
1.1.253.0 C:\WINDOWS\SYSTEM32\DRIVERS\IALPSS_GPIO.SYS Service registry key doe
sn't exist or hidden.
[Drivers] :HKLM iaLPSS_I2C=C:\WINDOWS\SYSTEM32\DRIVERS\IALPSS_I2C.SYS
### Intel(R) Serial IO I2C Driver Intel Corporation Intel(R) Serial IO Driver
1.1.253.0 C:\WINDOWS\SYSTEM32\DRIVERS\IALPSS_I2C.SYS Service registry key doesn
't exist or hidden.
[Drivers] :HKLM iaStorA=C:\WINDOWS\SYSTEM32\DRIVERS\IASTORA.SYS
### Intel(R) Rapid Storage Technology driver - x64 Intel Corporation Intel(R)
Rapid Storage Technology driver 14.6.0.1029 Service registry key doesn't exist
or hidden.
[Drivers] :HKLM iaStorAV=C:\WINDOWS\SYSTEM32\DRIVERS\IASTORAV.SYS
### Intel(R) Rapid Storage Technology driver (inbox) - x64 Intel Corporation I
ntel(R) Rapid Storage Technology driver (inbox) 13.2.0.1022 Service registry ke
y doesn't exist or hidden.
[Drivers] :HKLM iaStorV=C:\WINDOWS\SYSTEM32\DRIVERS\IASTORV.SYS
### Intel Matrix Storage Manager driver - x64 Intel Corporation Intel Matrix S
torage Manager driver 8.6.2.1019 Service registry key doesn't exist or hidden.
[Drivers] :HKLM ibbus=C:\WINDOWS\SYSTEM32\DRIVERS\IBBUS.SYS
### InfiniBand Fabric Bus Driver Mellanox OpenFabrics Windows 6.3.9600.16384
C:\WINDOWS\SYSTEM32\DRIVERS\IBBUS.SYS Service registry key doesn't exist or hidd
en.
[Drivers] :HKLM ibtusb=C:\WINDOWS\SYSTEM32\DRIVERS\IBTUSB.SYS
### Intel(R) Wireless Bluetooth(R) USB Driver Intel Corporation Intel(R) Wirel
ess Bluetooth(R) 17.1.1524.1353 C:\WINDOWS\SYSTEM32\DRIVERS\IBTUSB.SYS Service
registry key doesn't exist or hidden.
[Drivers] :HKLM igfx=C:\WINDOWS\SYSTEM32\DRIVERS\IGDKMD64.SYS
### Intel Graphics Kernel Mode Driver Intel Corporation Intel HD Graphics Driv
ers for Windows 8(R) 10.18.15.4248 C:\WINDOWS\SYSTEM32\DRIVERS\IGDKMD64.SYS Ser
vice registry key doesn't exist or hidden.
[Drivers] :HKLM IntcAzAudAddService=C:\WINDOWS\SYSTEM32\DRIVERS\RTKVHD64.SYS
### Realtek(r) High Definition Audio Function Driver Realtek Semiconductor Cor
p. Realtek(r) High Definition Audio Function Driver 6.0.1.7606 C:\WINDOWS\SYSTE
M32\DRIVERS\RTKVHD64.SYS Service registry key doesn't exist or hidden.
[Drivers] :HKLM IntcDAud=C:\WINDOWS\SYSTEM32\DRIVERS\INTCDAUD.SYS

### Intel(R) Display Audio Driver Intel(R) Corporation Intel(R) Display Audio
6.16.00.3178 C:\WINDOWS\SYSTEM32\DRIVERS\INTCDAUD.SYS Service registry key does
n't exist or hidden.
[Drivers] :HKLM intelide=C:\WINDOWS\SYSTEM32\DRIVERS\INTELIDE.SYS
### Intel PCI IDE Driver Microsoft Corporation Microsoft Windows Operating Syste
m 10.0.10586.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM intelpep=C:\WINDOWS\SYSTEM32\DRIVERS\INTELPEP.SYS
### Intel Power Engine Plugin Microsoft Corporation Microsoft Windows Operating
System 10.0.10586.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM intelppm=C:\WINDOWS\SYSTEM32\DRIVERS\INTELPPM.SYS
### Processor Device Driver Microsoft Corporation Microsoft Windows Operating Sy
stem 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\INTELPPM.SYS Service registry key
doesn't exist or hidden.
[Drivers] :HKLM IoQos=C:\WINDOWS\SYSTEM32\DRIVERS\IOQOS.SYS
### I/O QoS Filter Microsoft Corporation Microsoft Windows Operating System 10.0
.10586.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM IpFilterDriver=C:\WINDOWS\SYSTEM32\DRIVERS\IPFLTDRV.SYS
### IP FILTER DRIVER Microsoft Corporation Microsoft Windows Operating System 10
.0.10586.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM IPMIDRV=C:\WINDOWS\SYSTEM32\DRIVERS\IPMIDRV.SYS
### WMI IPMI DRIVER Microsoft Corporation Microsoft Windows Operating System 10.
0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\IPMIDRV.SYS Service registry key doesn't
exist or hidden.
[Drivers] :HKLM IPNAT=C:\WINDOWS\SYSTEM32\DRIVERS\IPNAT.SYS
### IP Network Address Translator Microsoft Corporation Microsoft Windows Operat
ing System 10.0.10586.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM IRENUM=C:\WINDOWS\SYSTEM32\DRIVERS\IRENUM.SYS
### Infra-Red Bus Enumerator Microsoft Corporation Microsoft Windows Operating S
ystem 10.0.10586.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM isapnp=C:\WINDOWS\SYSTEM32\DRIVERS\ISAPNP.SYS
### PNP ISA Bus Driver Microsoft Corporation Microsoft Windows Operating System
10.0.10586.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM iScsiPrt=C:\WINDOWS\SYSTEM32\DRIVERS\MSISCSI.SYS
### Microsoft iSCSI Initiator Driver Microsoft Corporation Microsoft Windows Ope
rating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\MSISCSI.SYS Service regi
stry key doesn't exist or hidden.
[Drivers] :HKLM kbdclass=C:\WINDOWS\SYSTEM32\DRIVERS\KBDCLASS.SYS
### Keyboard Class Driver Microsoft Corporation Microsoft Windows Operating Syst
em 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\KBDCLASS.SYS Service registry key d
oesn't exist or hidden.
[Drivers] :HKLM kbdhid=C:\WINDOWS\SYSTEM32\DRIVERS\KBDHID.SYS
### HID Keyboard Filter Driver Microsoft Corporation Microsoft Windows Operating
System 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\KBDHID.SYS Service registry ke
y doesn't exist or hidden.
[Drivers] :HKLM kdnic=C:\WINDOWS\SYSTEM32\DRIVERS\KDNIC.SYS
### Microsoft Kernel Debugger Network Miniport Microsoft Corporation Microsoft
Kernel Debugger Network Adapter (NDIS 6.20 Miniport) 6.01.00.0000 C:\WINDOWS\S
YSTEM32\DRIVERS\KDNIC.SYS Service registry key doesn't exist or hidden.
[Drivers] :HKLM kl1=C:\WINDOWS\SYSTEM32\DRIVERS\KL1.SYS
### Kaspersky Unified Driver Kaspersky Lab ZAO Kaspersky Anti-Virus 6.0.1.990
Service registry key doesn't exist or hidden.
[Drivers] :HKLM klbackupdisk=C:\WINDOWS\SYSTEM32\DRIVERS\KLBACKUPDISK.SYS
### Backup Disk Filter [fre_wnet_x64] Kaspersky Lab ZAO System Interceptors PD
K 10.0.0.20 Service registry key doesn't exist or hidden.
[Drivers] :HKLM klbackupflt=C:\WINDOWS\SYSTEM32\DRIVERS\KLBACKUPFLT.SYS
### Backup File Filter [fre_win8_x64] AO Kaspersky Lab System Interceptors PDK
10.0.0.26 Service registry key doesn't exist or hidden.
[Drivers] :HKLM kldisk=C:\WINDOWS\SYSTEM32\DRIVERS\KLDISK.SYS
### Virtual Disk [fre_wnet_x64] AO Kaspersky Lab System Interceptors PDK 10.0.
0.22 C:\WINDOWS\SYSTEM32\DRIVERS\KLDISK.SYS Service registry key doesn't exist

or hidden.
[Drivers] :HKLM klelam=C:\WINDOWS\SYSTEM32\DRIVERS\KLELAM.SYS
### Klelam Mini-Filter [fre_win8_x64] Kaspersky Lab Kaspersky Anti-Virus 1.0.0.
121 Service registry key doesn't exist or hidden.
[Drivers] :HKLM klflt=C:\WINDOWS\SYSTEM32\DRIVERS\KLFLT.SYS
### Filter Core [fre_win8_x64] AO Kaspersky Lab System Interceptors PDK 11.0.4
5.0 C:\WINDOWS\SYSTEM32\DRIVERS\KLFLT.SYS Service registry key doesn't exist or
hidden.
[Drivers] :HKLM klhk=C:\WINDOWS\SYSTEM32\DRIVERS\KLHK.SYS
### klhk [fre_win8_x64] AO Kaspersky Lab System Interceptors PDK 11.0.60.62 C
:\WINDOWS\SYSTEM32\DRIVERS\KLHK.SYS Service registry key doesn't exist or hidden
.
[Drivers] :HKLM klids=C:\PROGRAMDATA\KASPERSKY LAB\AVP16.0.1\BASES\KLIDS.SYS
### IDS Engine [fre_wnet_x64] AO Kaspersky Lab KL IDS Engine 10.1.1.4 C:\PROG
RAMDATA\KASPERSKY LAB\AVP16.0.1\BASES\KLIDS.SYS Service registry key doesn't exi
st or hidden.
[Drivers] :HKLM KLIF=C:\WINDOWS\SYSTEM32\DRIVERS\KLIF.SYS
### Core System Interceptors [fre_win8_x64] AO Kaspersky Lab System Intercepto
rs PDK 11.0.246.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM KLIM6=C:\WINDOWS\SYSTEM32\DRIVERS\KLIM6.SYS
### Packet Network Filter [fre_win8_x64] AO Kaspersky Lab System Interceptors
PDK 11.0.0.12 C:\WINDOWS\SYSTEM32\DRIVERS\KLIM6.SYS Service registry key doesn'
t exist or hidden.
[Drivers] :HKLM klkbdflt=C:\WINDOWS\SYSTEM32\DRIVERS\KLKBDFLT.SYS
### Keyboard Device Filter [fre_win8_x64] AO Kaspersky Lab System Interceptors
PDK 10.0.0.23 C:\WINDOWS\SYSTEM32\DRIVERS\KLKBDFLT.SYS Service registry key do
esn't exist or hidden.
[Drivers] :HKLM klkbdflt2=\SystemRoot\system32\DRIVERS\klkbdflt2.sys
### C:\WINDOWS\SYSTEM32\DRIVERS\KLKBDFLT2.SYS File is deleted or hidden by a
rootkit or could not be located. Service registry key doesn't exist or hidden.
[Drivers] :HKLM klmouflt=C:\WINDOWS\SYSTEM32\DRIVERS\KLMOUFLT.SYS
### Mouse Device Filter [fre_win8_x64] Kaspersky Lab ZAO System Interceptors P
DK 10.0.0.11 C:\WINDOWS\SYSTEM32\DRIVERS\KLMOUFLT.SYS Service registry key does
n't exist or hidden.
[Drivers] :HKLM klpd=C:\WINDOWS\SYSTEM32\DRIVERS\KLPD.SYS
### Format Recognizer [fre_wnet_x64] AO Kaspersky Lab System Interceptors PDK
11.0.0.13 Service registry key doesn't exist or hidden.
[Drivers] :HKLM klwfp=C:\WINDOWS\SYSTEM32\DRIVERS\KLWFP.SYS
### Network filtering component [fre_win8_x64] Kaspersky Lab ZAO Kaspersky Anti
-Virus 1.7.0.34 C:\WINDOWS\SYSTEM32\DRIVERS\KLWFP.SYS Service registry key does
n't exist or hidden.
[Drivers] :HKLM Klwtp=C:\WINDOWS\SYSTEM32\DRIVERS\KLWTP.SYS
### WFP Network Connection Filter Driver [fre_win8_x64] AO Kaspersky Lab Syste
m Interceptors PDK 11.0.0.12 C:\WINDOWS\SYSTEM32\DRIVERS\KLWTP.SYS Service regi
stry key doesn't exist or hidden.
[Drivers] :HKLM kneps=C:\WINDOWS\SYSTEM32\DRIVERS\KNEPS.SYS
### Network Processor [fre_wnet_x64] AO Kaspersky Lab System Interceptors PDK
11.0.0.18 C:\WINDOWS\SYSTEM32\DRIVERS\KNEPS.SYS Service registry key doesn't ex
ist or hidden.
[Drivers] :HKLM KSecDD=C:\WINDOWS\SYSTEM32\DRIVERS\KSECDD.SYS
### Kernel Security Support Provider Interface Microsoft Corporation Microsoft
Windows Operating System 10.0.10586.0 Service registry key doesn't exist or hidd
en.
[Drivers] :HKLM KSecPkg=C:\WINDOWS\SYSTEM32\DRIVERS\KSECPKG.SYS
### Kernel Security Support Provider Interface Packages Microsoft Corporation
Microsoft Windows Operating System 10.0.10586.420 Service registry key doesn't ex
ist or hidden.
[Drivers] :HKLM ksthunk=C:\WINDOWS\SYSTEM32\DRIVERS\KSTHUNK.SYS
### Kernel Streaming WOW Thunk Service Microsoft Corporation Microsoft Windows O
perating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\KSTHUNK.SYS Service re

gistry key doesn't exist or hidden.


[Drivers] :HKLM lltdio=C:\WINDOWS\SYSTEM32\DRIVERS\LLTDIO.SYS
### Link-Layer Topology Mapper I/O Driver Microsoft Corporation Microsoft Windo
ws Operating System 10.0.10586.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM LSI_SAS=C:\WINDOWS\SYSTEM32\DRIVERS\LSI_SAS.SYS
### LSI Fusion-MPT SAS Driver (StorPort) LSI Corporation LSI Fusion-MPT SAS Dr
iver (StorPort) 1.34.03.83 Service registry key doesn't exist or hidden.
[Drivers] :HKLM LSI_SAS2i=C:\WINDOWS\SYSTEM32\DRIVERS\LSI_SAS2I.SYS
### LSI SAS Gen2 Driver (StorPort) LSI Corporation Microsoft Windows Operating S
ystem 10.0.10048.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM LSI_SAS3i=C:\WINDOWS\SYSTEM32\DRIVERS\LSI_SAS3I.SYS
### Avago SAS Gen3 Driver (StorPort) Avago Technologies Microsoft Windows Operat
ing System 10.0.10048.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM LSI_SSS=C:\WINDOWS\SYSTEM32\DRIVERS\LSI_SSS.SYS
### LSI SSS PCIe/Flash Driver (StorPort) LSI Corporation LSI SSS PCIe/Flash Dr
iver (StorPort) 2.10.61.81 Service registry key doesn't exist or hidden.
[Drivers] :HKLM luafv=C:\WINDOWS\SYSTEM32\DRIVERS\LUAFV.SYS
### LUA File Virtualization Filter Driver Microsoft Corporation Microsoft Windo
ws Operating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\LUAFV.SYS Service r
egistry key doesn't exist or hidden.
[Drivers] :HKLM megasas=C:\WINDOWS\SYSTEM32\DRIVERS\MEGASAS.SYS
### MEGASAS RAID Controller Driver for Windows Avago Technologies MEGASAS RAID
Controller Driver for Windows 6.706.06.00 Service registry key doesn't exist o
r hidden.
[Drivers] :HKLM megasr=C:\WINDOWS\SYSTEM32\DRIVERS\MEGASR.SYS
### LSI MegaRAID Software RAID Driver LSI Corporation, Inc. MegaRAID Software
RAID 15.02.2013.0129 Service registry key doesn't exist or hidden.
[Drivers] :HKLM MEIx64=C:\WINDOWS\SYSTEM32\DRIVERS\TEEDRIVERW8X64.SYS
### Intel(R) Management Engine Interface Intel Corporation Intel(R) Management
Engine Interface 11.0.0.1157 C:\WINDOWS\SYSTEM32\DRIVERS\TEEDRIVERW8X64.SYS Se
rvice registry key doesn't exist or hidden.
[Drivers] :HKLM mlx4_bus=C:\WINDOWS\SYSTEM32\DRIVERS\MLX4_BUS.SYS
### MLX4 Bus Driver Mellanox OpenFabrics Windows 6.3.9600.16384 C:\WINDOWS\SY
STEM32\DRIVERS\MLX4_BUS.SYS Service registry key doesn't exist or hidden.
[Drivers] :HKLM MMCSS=C:\WINDOWS\SYSTEM32\DRIVERS\MMCSS.SYS
### MMCSS Driver Microsoft Corporation Microsoft Windows Operating System 10.0.1
0586.0 C:\WINDOWS\SYSTEM32\DRIVERS\MMCSS.SYS Service registry key doesn't exist
or hidden.
[Drivers] :HKLM Modem=C:\WINDOWS\SYSTEM32\DRIVERS\MODEM.SYS
### Modem Device Driver Microsoft Corporation Microsoft Windows Operating System
10.0.10586.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM monitor=C:\WINDOWS\SYSTEM32\DRIVERS\MONITOR.SYS
### Monitor Driver Microsoft Corporation Microsoft Windows Operating System 10.0
.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\MONITOR.SYS Service registry key doesn't e
xist or hidden.
[Drivers] :HKLM mouclass=C:\WINDOWS\SYSTEM32\DRIVERS\MOUCLASS.SYS
### Mouse Class Driver Microsoft Corporation Microsoft Windows Operating System
10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\MOUCLASS.SYS Service registry key does
n't exist or hidden.
[Drivers] :HKLM mouhid=C:\WINDOWS\SYSTEM32\DRIVERS\MOUHID.SYS
### HID Mouse Filter Driver Microsoft Corporation Microsoft Windows Operating Sy
stem 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\MOUHID.SYS Service registry key d
oesn't exist or hidden.
[Drivers] :HKLM mountmgr=C:\WINDOWS\SYSTEM32\DRIVERS\MOUNTMGR.SYS
### Mount Point Manager Microsoft Corporation Microsoft Windows Operating System
10.0.10586.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM mpsdrv=C:\WINDOWS\SYSTEM32\DRIVERS\MPSDRV.SYS
### Microsoft Protection Service Driver Microsoft Corporation Microsoft Windows
Operating System 10.0.10586.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM MRxDAV=C:\WINDOWS\SYSTEM32\DRIVERS\MRXDAV.SYS

### Windows NT WebDav Minirdr Microsoft Corporation Microsoft Windows Operating


System 10.0.10586.103 C:\WINDOWS\SYSTEM32\DRIVERS\MRXDAV.SYS Service registry k
ey doesn't exist or hidden.
[Drivers] :HKLM mrxsmb=C:\WINDOWS\SYSTEM32\DRIVERS\MRXSMB.SYS
### Windows NT SMB Minirdr Microsoft Corporation Microsoft Windows Operating Sys
tem 10.0.10586.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM mrxsmb10=C:\WINDOWS\SYSTEM32\DRIVERS\MRXSMB10.SYS
### Longhorn SMB Downlevel SubRdr Microsoft Corporation Microsoft Windows Operat
ing System 10.0.10586.122 Service registry key doesn't exist or hidden.
[Drivers] :HKLM mrxsmb20=C:\WINDOWS\SYSTEM32\DRIVERS\MRXSMB20.SYS
### Longhorn SMB 2.0 Redirector Microsoft Corporation Microsoft Windows Operatin
g System 10.0.10586.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM MsBridge=C:\WINDOWS\SYSTEM32\DRIVERS\BRIDGE.SYS
### MAC Bridge Driver Microsoft Corporation Microsoft Windows Operating System 1
0.0.10586.122 Service registry key doesn't exist or hidden.
[Drivers] :HKLM msgpiowin32=C:\WINDOWS\SYSTEM32\DRIVERS\MSGPIOWIN32.SYS
### GPIO Button Driver Microsoft Corporation Microsoft Windows Operating System
10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\MSGPIOWIN32.SYS Service registry key d
oesn't exist or hidden.
[Drivers] :HKLM mshidkmdf=C:\WINDOWS\SYSTEM32\DRIVERS\MSHIDKMDF.SYS
### Pass-through HID to KMDF Filter Driver Microsoft Corporation Microsoft Wind
ows Operating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\MSHIDKMDF.SYS Serv
ice registry key doesn't exist or hidden.
[Drivers] :HKLM mshidumdf=C:\WINDOWS\SYSTEM32\DRIVERS\MSHIDUMDF.SYS
### Pass-through Driver for HID-UMDF Interface Microsoft Corporation Microsoft
Windows Operating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\MSHIDUMDF.SYS
Service registry key doesn't exist or hidden.
[Drivers] :HKLM msisadrv=C:\WINDOWS\SYSTEM32\DRIVERS\MSISADRV.SYS
### ISA Driver Microsoft Corporation Microsoft Windows Operating System 10.0.105
86.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM MSKSSRV=C:\WINDOWS\SYSTEM32\DRIVERS\MSKSSRV.SYS
### MS KS Server Microsoft Corporation Microsoft Windows Operating System 10.0.1
0586.0 C:\WINDOWS\SYSTEM32\DRIVERS\MSKSSRV.SYS Service registry key doesn't exi
st or hidden.
[Drivers] :HKLM MsLldp=C:\WINDOWS\SYSTEM32\DRIVERS\MSLLDP.SYS
### Microsoft Link-Layer Discovery Protocol Driver Microsoft Corporation Micro
soft Windows Operating System 10.0.10586.0 Service registry key doesn't exist or
hidden.
[Drivers] :HKLM MSPCLOCK=C:\WINDOWS\SYSTEM32\DRIVERS\MSPCLOCK.SYS
### MS Proxy Clock Microsoft Corporation Microsoft Windows Operating System 10.0
.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\MSPCLOCK.SYS Service registry key doesn't
exist or hidden.
[Drivers] :HKLM MSPQM=C:\WINDOWS\SYSTEM32\DRIVERS\MSPQM.SYS
### MS Proxy Quality Manager Microsoft Corporation Microsoft Windows Operating S
ystem 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\MSPQM.SYS Service registry key d
oesn't exist or hidden.
[Drivers] :HKLM mssmbios=C:\WINDOWS\SYSTEM32\DRIVERS\MSSMBIOS.SYS
### System Management BIOS Driver Microsoft Corporation Microsoft Windows Operat
ing System 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\MSSMBIOS.SYS Service regist
ry key doesn't exist or hidden.
[Drivers] :HKLM MSTEE=C:\WINDOWS\SYSTEM32\DRIVERS\MSTEE.SYS
### WDM Tee/Communication Transform Filter Microsoft Corporation Microsoft Win
dows Operating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\MSTEE.SYS Service
registry key doesn't exist or hidden.
[Drivers] :HKLM MTConfig=C:\WINDOWS\SYSTEM32\DRIVERS\MTCONFIG.SYS
### Microsoft Multi-Touch HID Driver Microsoft Corporation Microsoft Windows Ope
rating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\MTCONFIG.SYS Service reg
istry key doesn't exist or hidden.
[Drivers] :HKLM Mup=C:\WINDOWS\SYSTEM32\DRIVERS\MUP.SYS
### Multiple UNC Provider Driver Microsoft Corporation Microsoft Windows Operati

ng System 10.0.10586.0 Service registry key doesn't exist or hidden.


[Drivers] :HKLM mvumis=C:\WINDOWS\SYSTEM32\DRIVERS\MVUMIS.SYS
### Marvell Flash Controller Driver Marvell Semiconductor, Inc. Marvell Flash
Controller 1.0.5.1016 Service registry key doesn't exist or hidden.
[Drivers] :HKLM NativeWifiP=C:\WINDOWS\SYSTEM32\DRIVERS\NWIFI.SYS
### NativeWiFi Miniport Driver Microsoft Corporation Microsoft Windows Operating
System 10.0.10586.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM ndfltr=C:\WINDOWS\SYSTEM32\DRIVERS\NDFLTR.SYS
### NetworkDirect Support Filter Driver Mellanox OpenFabrics Windows 6.3.9600.
16384 C:\WINDOWS\SYSTEM32\DRIVERS\NDFLTR.SYS Service registry key doesn't exist
or hidden.
[Drivers] :HKLM NDIS=C:\WINDOWS\SYSTEM32\DRIVERS\NDIS.SYS
### Network Driver Interface Specification (NDIS) Microsoft Corporation Micros
oft Windows Operating System 10.0.10586.0 Service registry key doesn't exist or h
idden.
[Drivers] :HKLM NdisCap=C:\WINDOWS\SYSTEM32\DRIVERS\NDISCAP.SYS
### Microsoft NDIS Packet Capture Filter Driver Microsoft Corporation Microsof
t Windows Operating System 10.0.10586.0 Service registry key doesn't exist or hid
den.
[Drivers] :HKLM NdisImPlatform=C:\WINDOWS\SYSTEM32\DRIVERS\NDISIMPLATFORM.SYS
### Microsoft Network Adapter Multiplexor Microsoft Corporation Microsoft Windo
ws Operating System 10.0.10586.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM NdisTapi=C:\WINDOWS\SYSTEM32\DRIVERS\NDISTAPI.SYS
### NDIS 3.0 connection wrapper driver Microsoft Corporation Microsoft Windows O
perating System 10.0.10586.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM Ndisuio=C:\WINDOWS\SYSTEM32\DRIVERS\NDISUIO.SYS
### NDIS User mode I/O driver Microsoft Corporation Microsoft Windows Operating
System 10.0.10586.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM NdisVirtualBus=C:\WINDOWS\SYSTEM32\DRIVERS\NDISVIRTUALBUS.SYS
### Microsoft Virtual Network Adapter Enumerator Microsoft Corporation Microso
ft Windows Operating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\NDISVIRTUALB
US.SYS Service registry key doesn't exist or hidden.
[Drivers] :HKLM NdisWan=C:\WINDOWS\SYSTEM32\DRIVERS\NDISWAN.SYS
### MS PPP Framing Driver (Strong Encryption) Microsoft Corporation Microsoft W
indows Operating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\NDISWAN.SYS Ser
vice registry key doesn't exist or hidden.
[Drivers] :HKLM ndiswanlegacy=C:\WINDOWS\SYSTEM32\DRIVERS\NDISWAN.SYS
### MS PPP Framing Driver (Strong Encryption) Microsoft Corporation Microsoft W
indows Operating System 10.0.10586.0 Service registry key doesn't exist or hidde
n.
[Drivers] :HKLM ndproxy=C:\WINDOWS\SYSTEM32\DRIVERS\NDPROXY.SYS
### NDIS Proxy Microsoft Corporation Microsoft Windows Operating System 10.0.105
86.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM Ndu=C:\WINDOWS\SYSTEM32\DRIVERS\NDU.SYS
### Windows Network Data Usage Monitoring Driver Microsoft Corporation Microso
ft Windows Operating System 10.0.10586.420 Service registry key doesn't exist or
hidden.
[Drivers] :HKLM NetBIOS=C:\WINDOWS\SYSTEM32\DRIVERS\NETBIOS.SYS
### NetBIOS interface driver Microsoft Corporation Microsoft Windows Operating S
ystem 10.0.10586.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM NetBT=C:\WINDOWS\SYSTEM32\DRIVERS\NETBT.SYS
### MBT Transport driver Microsoft Corporation Microsoft Windows Operating Syste
m 10.0.10586.420 Service registry key doesn't exist or hidden.
[Drivers] :HKLM NETwNb64=C:\WINDOWS\SYSTEM32\DRIVERS\NETWBW02.SYS
### Intel Wireless WiFi Link Driver Intel Corporation Intel Wireless WiFi Link A
dapter C:\WINDOWS\SYSTEM32\DRIVERS\NETWBW02.SYS Service registry key doesn't ex
ist or hidden.
[Drivers] :HKLM npsvctrig=C:\WINDOWS\SYSTEM32\DRIVERS\NPSVCTRIG.SYS
### Named pipe service triggers Microsoft Corporation Microsoft Windows Operatin
g System 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\NPSVCTRIG.SYS Service registr

y key doesn't exist or hidden.


[Drivers] :HKLM nsiproxy=C:\WINDOWS\SYSTEM32\DRIVERS\NSIPROXY.SYS
### NSI Proxy Microsoft Corporation Microsoft Windows Operating System 10.0.1058
6.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM nvlddmkm=C:\WINDOWS\SYSTEM32\DRIVERS\NVLDDMKM.SYS
### NVIDIA Windows Kernel Mode Driver, Version 368.69 NVIDIA Corporation NVID
IA Windows Kernel Mode Driver, Version 368.69 10.18.13.6869 C:\WINDOWS\SYSTEM3
2\DRIVERS\NVLDDMKM.SYS Service registry key doesn't exist or hidden.
[Drivers] :HKLM nvraid=C:\WINDOWS\SYSTEM32\DRIVERS\NVRAID.SYS
### NVIDIA nForce(TM) RAID Driver NVIDIA Corporation NVIDIA nForce(TM) RAID Dri
ver 10.6.0.23 Service registry key doesn't exist or hidden.
[Drivers] :HKLM nvstor=C:\WINDOWS\SYSTEM32\DRIVERS\NVSTOR.SYS
### NVIDIA nForce(TM) Sata Performance Driver NVIDIA Corporation NVIDIA nForce(
TM) SATA Driver 10.6.0.23 Service registry key doesn't exist or hidden.
[Drivers] :HKLM nv_agp=C:\WINDOWS\SYSTEM32\DRIVERS\NV_AGP.SYS
### NForce NT AGP Filter Microsoft Corporation Microsoft Windows Operating Syste
m 10.0.10586.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM Parport=C:\WINDOWS\SYSTEM32\DRIVERS\PARPORT.SYS
### Parallel Port Driver Microsoft Corporation Microsoft Windows Operating Syste
m 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\PARPORT.SYS Service registry key doe
sn't exist or hidden.
[Drivers] :HKLM Partizan=C:\Windows\system32\drivers\Partizan.sys
### File is deleted or hidden by a rootkit or could not be located. Service r
egistry key doesn't exist or hidden.
[Drivers] :HKLM partmgr=C:\WINDOWS\SYSTEM32\DRIVERS\PARTMGR.SYS
### Partition Management Driver Microsoft Corporation Microsoft Windows Operatin
g System 10.0.10586.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM pci=C:\WINDOWS\SYSTEM32\DRIVERS\PCI.SYS
### NT Plug and Play PCI Enumerator Microsoft Corporation Microsoft Windows Oper
ating System 10.0.10586.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM pciide=C:\WINDOWS\SYSTEM32\DRIVERS\PCIIDE.SYS
### Generic PCI IDE Bus Driver Microsoft Corporation Microsoft Windows Operating
System 10.0.10586.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM pcmcia=C:\WINDOWS\SYSTEM32\DRIVERS\PCMCIA.SYS
### PCMCIA Bus Driver Microsoft Corporation Microsoft Windows Operating System 1
0.0.10586.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM pcw=C:\WINDOWS\SYSTEM32\DRIVERS\PCW.SYS
### Performance Counters for Windows Driver Microsoft Corporation Microsoft Win
dows Operating System 10.0.10586.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM pdc=C:\WINDOWS\SYSTEM32\DRIVERS\PDC.SYS
### Power Dependency Coordinator Driver Microsoft Corporation Microsoft Windows
Operating System 10.0.10586.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM PDFSFilter=C:\WINDOWS\SYSTEM32\DRIVERS\PDFSFILTER.SYS
### PerfectDisk OptiWrite Filter Driver Raxco Software, Inc. PerfectDisk 12.0.
0.298 Service registry key doesn't exist or hidden.
[Drivers] :HKLM PEAUTH=C:\WINDOWS\SYSTEM32\DRIVERS\PEAUTH.SYS
### Protected Environment Authentication and Authorization Export Driver Micro
soft Corporation Microsoft Windows Operating System 10.0.10586.0 Service registry
key doesn't exist or hidden.
[Drivers] :HKLM percsas2i=C:\WINDOWS\SYSTEM32\DRIVERS\PERCSAS2I.SYS
### MEGASAS RAID Controller Driver for Windows LSI Corporation MEGASAS RAID Co
ntroller Driver for Windows 6.803.21.00 Service registry key doesn't exist or h
idden.
[Drivers] :HKLM percsas3i=C:\WINDOWS\SYSTEM32\DRIVERS\PERCSAS3I.SYS
### MEGASAS RAID Controller Driver for Windows Avago Technologies MEGASAS RAID
Controller Driver for Windows 6.602.12.0 Service registry key doesn't exist or
hidden.
[Drivers] :HKLM PptpMiniport=C:\WINDOWS\SYSTEM32\DRIVERS\RASPPTP.SYS
### Peer-to-Peer Tunneling Protocol Microsoft Corporation Microsoft Windows Oper
ating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\RASPPTP.SYS Service regis

try key doesn't exist or hidden.


[Drivers] :HKLM Processor=C:\WINDOWS\SYSTEM32\DRIVERS\PROCESSR.SYS
### Processor Device Driver Microsoft Corporation Microsoft Windows Operating Sy
stem 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\PROCESSR.SYS Service registry key
doesn't exist or hidden.
[Drivers] :HKLM Psched=C:\WINDOWS\SYSTEM32\DRIVERS\PACER.SYS
### QoS Packet Scheduler Microsoft Corporation Microsoft Windows Operating Syste
m 10.0.10586.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM QWAVEdrv=C:\WINDOWS\SYSTEM32\DRIVERS\QWAVEDRV.SYS
### Microsoft Quality Windows Audio Video Experience (qWave) Support Driver Mi
crosoft Corporation Microsoft Windows Operating System 10.0.10586.0 C:\WINDOWS\SY
STEM32\DRIVERS\QWAVEDRV.SYS Service registry key doesn't exist or hidden.
[Drivers] :HKLM RasAcd=C:\WINDOWS\SYSTEM32\DRIVERS\RASACD.SYS
### RAS Automatic Connection Driver Microsoft Corporation Microsoft Windows Oper
ating System 10.0.10586.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM RasAgileVpn=C:\WINDOWS\SYSTEM32\DRIVERS\AGILEVPN.SYS
### RAS Agile Vpn Miniport Call Manager Microsoft Corporation Microsoft Windows
Operating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\AGILEVPN.SYS Service
registry key doesn't exist or hidden.
[Drivers] :HKLM Rasl2tp=C:\WINDOWS\SYSTEM32\DRIVERS\RASL2TP.SYS
### RAS L2TP mini-port/call-manager driver Microsoft Corporation Microsoft Wind
ows Operating System 10.0.10586.122 C:\WINDOWS\SYSTEM32\DRIVERS\RASL2TP.SYS Serv
ice registry key doesn't exist or hidden.
[Drivers] :HKLM RasPppoe=C:\WINDOWS\SYSTEM32\DRIVERS\RASPPPOE.SYS
### RAS PPPoE mini-port/call-manager driver Microsoft Corporation Microsoft Win
dows Operating System 10.0.10586.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM RasSstp=C:\WINDOWS\SYSTEM32\DRIVERS\RASSSTP.SYS
### RAS SSTP Miniport Call Manager Microsoft Corporation Microsoft Windows Opera
ting System 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\RASSSTP.SYS Service regist
ry key doesn't exist or hidden.
[Drivers] :HKLM rdbss=C:\WINDOWS\SYSTEM32\DRIVERS\RDBSS.SYS
### Redirected Drive Buffering SubSystem Driver Microsoft Corporation Microsof
t Windows Operating System 10.0.10586.0 Service registry key doesn't exist or hid
den.
[Drivers] :HKLM rdpbus=C:\WINDOWS\SYSTEM32\DRIVERS\RDPBUS.SYS
### Microsoft RDP Bus Device driver Microsoft Corporation Microsoft Windows Oper
ating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\RDPBUS.SYS Service regist
ry key doesn't exist or hidden.
[Drivers] :HKLM RDPDR=C:\WINDOWS\SYSTEM32\DRIVERS\RDPDR.SYS
### Microsoft RDP Device redirector Microsoft Corporation Microsoft Windows Oper
ating System 10.0.10586.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM RdpVideoMiniport=C:\WINDOWS\SYSTEM32\DRIVERS\RDPVIDEOMINIPORT.
SYS
### Microsoft RDP Video Miniport driver Microsoft Corporation Microsoft Windows
Operating System 10.0.10586.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM rdyboost=C:\WINDOWS\SYSTEM32\DRIVERS\RDYBOOST.SYS
### ReadyBoost Driver Microsoft Corporation Microsoft Windows Operating System 1
0.0.10586.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM RFCOMM=C:\WINDOWS\SYSTEM32\DRIVERS\RFCOMM.SYS
### Bluetooth RFCOMM Driver Microsoft Corporation Microsoft Windows Operating Sy
stem 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\RFCOMM.SYS Service registry key d
oesn't exist or hidden.
[Drivers] :HKLM rspndr=C:\WINDOWS\SYSTEM32\DRIVERS\RSPNDR.SYS
### Link-Layer Topology Responder Driver for NDIS 6 Microsoft Corporation Micr
osoft Windows Operating System 10.0.10586.0 Service registry key doesn't exist or
hidden.
[Drivers] :HKLM rt640x64=C:\WINDOWS\SYSTEM32\DRIVERS\RT640X64.SYS
### Realtek 8101E/8168/8169 NDIS 6.40 64-bit Driver
Realtek
Realtek 8136/8168/8169 PCI/PCIe Adapte
rs
10.001.0505.2015 C:\WINDOWS\SYSTEM32\DRIVERS\RT640X64.

SYS Service registry key doesn't exist or hidden.


[Drivers] :HKLM rtsuvc=C:\WINDOWS\SYSTEM32\DRIVERS\RTSUVC.SYS
### Realtek UVC Driver for Vista/Win7/Win8/Win8.1 Realtek Semiconductor Corp.
Realtek UVC Driver for Vista/Win7/Win8/Win8.1 6.3.9600.11103 C:\WINDOWS\SYSTEM3
2\DRIVERS\RTSUVC.SYS Service registry key doesn't exist or hidden.
[Drivers] :HKLM s3cap=C:\WINDOWS\SYSTEM32\DRIVERS\VMS3CAP.SYS
### Microsoft S3 Emulated Device Cap Driver Microsoft Corporation Microsoft Win
dows Operating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\VMS3CAP.SYS Servi
ce registry key doesn't exist or hidden.
[Drivers] :HKLM sbp2port=C:\WINDOWS\SYSTEM32\DRIVERS\SBP2PORT.SYS
### SBP-2 Protocol Driver Microsoft Corporation Microsoft Windows Operating Syst
em 10.0.10586.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM scfilter=C:\WINDOWS\SYSTEM32\DRIVERS\SCFILTER.SYS
### Microsoft Smart Card Reader Filter Driver Microsoft Corporation Microsoft W
indows Operating System 10.0.10586.0 Service registry key doesn't exist or hidde
n.
[Drivers] :HKLM sdbus=C:\WINDOWS\SYSTEM32\DRIVERS\SDBUS.SYS
### SecureDigital Bus Driver Microsoft Corporation Microsoft Windows Operating S
ystem 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\SDBUS.SYS Service registry key d
oesn't exist or hidden.
[Drivers] :HKLM sdstor=C:\WINDOWS\SYSTEM32\DRIVERS\SDSTOR.SYS
### SD Storage Class Driver Microsoft Corporation Microsoft Windows Operating Sy
stem 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\SDSTOR.SYS Service registry key d
oesn't exist or hidden.
[Drivers] :HKLM SensorsHIDClassDriver=C:\WINDOWS\SYSTEM32\DRIVERS\WUDFRD.SYS
### Windows Driver Foundation - User-mode Driver Framework Reflector Microsoft
Corporation Microsoft Windows Operating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\
DRIVERS\WUDFRD.SYS Service registry key doesn't exist or hidden.
[Drivers] :HKLM SerCx=C:\WINDOWS\SYSTEM32\DRIVERS\SERCX.SYS
### Serial Class Extension Microsoft Corporation Microsoft Windows Operating Sys
tem 10.0.10586.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM SerCx2=C:\WINDOWS\SYSTEM32\DRIVERS\SERCX2.SYS
### Serial Class Extension V2 Microsoft Corporation Microsoft Windows Operating
System 10.0.10586.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM Serenum=C:\WINDOWS\SYSTEM32\DRIVERS\SERENUM.SYS
### Serial Port Enumerator Microsoft Corporation Microsoft Windows Operating Sys
tem 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\SERENUM.SYS Service registry key d
oesn't exist or hidden.
[Drivers] :HKLM Serial=C:\WINDOWS\SYSTEM32\DRIVERS\SERIAL.SYS
### Serial Device Driver Microsoft Corporation Microsoft Windows Operating Syste
m 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\SERIAL.SYS Service registry key does
n't exist or hidden.
[Drivers] :HKLM sermouse=C:\WINDOWS\SYSTEM32\DRIVERS\SERMOUSE.SYS
### Serial Mouse Filter Driver Microsoft Corporation Microsoft Windows Operating
System 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\SERMOUSE.SYS Service registry
key doesn't exist or hidden.
[Drivers] :HKLM sfloppy=C:\WINDOWS\SYSTEM32\DRIVERS\SFLOPPY.SYS
### SCSI Floppy Driver Microsoft Corporation Microsoft Windows Operating System
10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\SFLOPPY.SYS Service registry key doesn
't exist or hidden.
[Drivers] :HKLM SiSRaid2=C:\WINDOWS\SYSTEM32\DRIVERS\SISRAID2.SYS
### SiS RAID Stor Miniport Driver Silicon Integrated Systems Corp. Microsoft Wi
ndows Operating System 2.60.01 Service registry key doesn't exist or hidden.
[Drivers] :HKLM SiSRaid4=C:\WINDOWS\SYSTEM32\DRIVERS\SISRAID4.SYS
### SiS AHCI Stor-Miniport Driver Silicon Integrated Systems Microsoft Windows O
perating System 6.1.6918.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM SmbDrvI=C:\WINDOWS\SYSTEM32\DRIVERS\SMB_DRIVER_INTEL.SYS
### Synaptics SMBus Driver Synaptics Incorporated Synaptics SMBus Driver 19.0.
18 23Jul15 C:\WINDOWS\SYSTEM32\DRIVERS\SMB_DRIVER_INTEL.SYS Service registry ke
y doesn't exist or hidden.

[Drivers] :HKLM spaceport=C:\WINDOWS\SYSTEM32\DRIVERS\SPACEPORT.SYS


### Storage Spaces Driver Microsoft Corporation Microsoft Windows Operating Syst
em 10.0.10586.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM SpbCx=C:\WINDOWS\SYSTEM32\DRIVERS\SPBCX.SYS
### SPB Class Extension Microsoft Corporation Microsoft Windows Operating System
10.0.10586.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM srv=C:\WINDOWS\SYSTEM32\DRIVERS\SRV.SYS
### Server driver Microsoft Corporation Microsoft Windows Operating System 10.0.
10586.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM srv2=C:\WINDOWS\SYSTEM32\DRIVERS\SRV2.SYS
### Smb 2.0 Server driver Microsoft Corporation Microsoft Windows Operating Syst
em 10.0.10586.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM srvnet=C:\WINDOWS\SYSTEM32\DRIVERS\SRVNET.SYS
### Server Network driver Microsoft Corporation Microsoft Windows Operating Syst
em 10.0.10586.420 Service registry key doesn't exist or hidden.
[Drivers] :HKLM stexstor=C:\WINDOWS\SYSTEM32\DRIVERS\STEXSTOR.SYS
### Promise SuperTrak EX Series Driver for Windows x64 Promise Technology, Inc
. Promise SuperTrak EX Series 5.1.0000.10 Service registry key doesn't exist o
r hidden.
[Drivers] :HKLM storahci=C:\WINDOWS\SYSTEM32\DRIVERS\STORAHCI.SYS
### MS AHCI Storport Miniport Driver Microsoft Corporation Microsoft Windows Ope
rating System 10.0.10586.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM storflt=C:\WINDOWS\SYSTEM32\DRIVERS\VMSTORFL.SYS
### Virtual Storage Filter Driver Microsoft Corporation Microsoft Windows Operat
ing System 10.0.10586.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM stornvme=C:\WINDOWS\SYSTEM32\DRIVERS\STORNVME.SYS
### Microsoft NVM Express Storport Miniport Driver Microsoft Corporation Micro
soft Windows Operating System 10.0.10586.0 Service registry key doesn't exist or
hidden.
[Drivers] :HKLM storqosflt=C:\WINDOWS\SYSTEM32\DRIVERS\STORQOSFLT.SYS
### Storage QoS Filter Microsoft Corporation Microsoft Windows Operating System
10.0.10586.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM storufs=C:\WINDOWS\SYSTEM32\DRIVERS\STORUFS.SYS
### MS UFS Storport Miniport Driver Microsoft Corporation Microsoft Windows Oper
ating System 10.0.10586.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM storvsc=C:\WINDOWS\SYSTEM32\DRIVERS\STORVSC.SYS
### Storage VSC Driver Microsoft Corporation Microsoft Windows Operating System
10.0.10586.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM swenum=C:\WINDOWS\SYSTEM32\DRIVERS\SWENUM.SYS
### Plug and Play Software Device Enumerator Microsoft Corporation Microsoft Wi
ndows Operating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\SWENUM.SYS Servi
ce registry key doesn't exist or hidden.
[Drivers] :HKLM Synth3dVsc=C:\WINDOWS\SYSTEM32\DRIVERS\SYNTH3DVSC.SYS
### Microsoft RemoteFX Synth3D Video VSC Microsoft Corporation Microsoft Window
s Operating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\SYNTH3DVSC.SYS Servi
ce registry key doesn't exist or hidden.
[Drivers] :HKLM SynTP=C:\WINDOWS\SYSTEM32\DRIVERS\SYNTP.SYS
### Synaptics Touchpad Win64 Driver Synaptics Incorporated Synaptics Pointing
Device Driver 19.0.18 23Jul15 C:\WINDOWS\SYSTEM32\DRIVERS\SYNTP.SYS Service reg
istry key doesn't exist or hidden.
[Drivers] :HKLM Tcpip=C:\WINDOWS\SYSTEM32\DRIVERS\TCPIP.SYS
### TCP/IP Driver Microsoft Corporation Microsoft Windows Operating System 10.0.
10586.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM Tcpip6=C:\WINDOWS\SYSTEM32\DRIVERS\TCPIP.SYS
### TCP/IP Driver Microsoft Corporation Microsoft Windows Operating System 10.0.
10586.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM tcpipreg=C:\WINDOWS\SYSTEM32\DRIVERS\TCPIPREG.SYS
### TCP/IP Registry Compatibility Driver Microsoft Corporation Microsoft Window
s Operating System 10.0.10586.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM tdx=C:\WINDOWS\SYSTEM32\DRIVERS\TDX.SYS

### TDI Translation Driver Microsoft Corporation Microsoft Windows Operating Sys
tem 10.0.10586.3 C:\WINDOWS\SYSTEM32\DRIVERS\TDX.SYS Service registry key doesn
't exist or hidden.
[Drivers] :HKLM terminpt=C:\WINDOWS\SYSTEM32\DRIVERS\TERMINPT.SYS
### Terminal Server Input Driver Microsoft Corporation Microsoft Windows Operati
ng System 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\TERMINPT.SYS Service registr
y key doesn't exist or hidden.
[Drivers] :HKLM TPM=C:\WINDOWS\SYSTEM32\DRIVERS\TPM.SYS
### TPM Device Driver Microsoft Corporation Microsoft Windows Operating System 1
0.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\TPM.SYS Service registry key doesn't ex
ist or hidden.
[Drivers] :HKLM tsusbflt=C:\WINDOWS\SYSTEM32\DRIVERS\TSUSBFLT.SYS
### Remote Desktop USB Hub Filter Driver Microsoft Corporation Microsoft Window
s Operating System 10.0.10586.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM TsUsbGD=C:\WINDOWS\SYSTEM32\DRIVERS\TSUSBGD.SYS
### Remote Desktop Generic USB Driver Microsoft Corporation Microsoft Windows Op
erating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\TSUSBGD.SYS Service reg
istry key doesn't exist or hidden.
[Drivers] :HKLM tunnel=C:\WINDOWS\SYSTEM32\DRIVERS\TUNNEL.SYS
### Microsoft Tunnel Interface Driver Microsoft Corporation Microsoft Windows Op
erating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\TUNNEL.SYS Service regi
stry key doesn't exist or hidden.
[Drivers] :HKLM uagp35=C:\WINDOWS\SYSTEM32\DRIVERS\UAGP35.SYS
### MS AGPv3.5 Filter Microsoft Corporation Microsoft Windows Operating System 1
0.0.10586.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM UASPStor=C:\WINDOWS\SYSTEM32\DRIVERS\UASPSTOR.SYS
### Microsoft Uasp Driver Microsoft Corporation Microsoft Windows Operating Syst
em 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\UASPSTOR.SYS Service registry key d
oesn't exist or hidden.
[Drivers] :HKLM UcmCx0101=C:\WINDOWS\SYSTEM32\DRIVERS\UCMCX.SYS
### USB Connector Manager KMDF Class Extension Microsoft Corporation Microsoft
Windows Operating System 10.0.10586.306 Service registry key doesn't exist or hi
dden.
[Drivers] :HKLM UcmUcsi=C:\WINDOWS\SYSTEM32\DRIVERS\UCMUCSI.SYS
### USB Connector Manager UCSI Client Microsoft Corporation Microsoft Windows Op
erating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\UCMUCSI.SYS Service reg
istry key doesn't exist or hidden.
[Drivers] :HKLM Ucx01000=C:\WINDOWS\SYSTEM32\DRIVERS\UCX01000.SYS
### USB Controller Extension Microsoft Corporation Microsoft Windows Operating S
ystem 10.0.10586.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM UdeCx=C:\WINDOWS\SYSTEM32\DRIVERS\UDECX.SYS
### udecx.DRIVER Microsoft Corporation Microsoft Windows Operating System 10.0.1
0586.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM udfs=C:\WINDOWS\SYSTEM32\DRIVERS\UDFS.SYS
### UDF File System Driver Microsoft Corporation Microsoft Windows Operating Sys
tem 10.0.10586.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM UEFI=C:\WINDOWS\SYSTEM32\DRIVERS\UEFI.SYS
### UEFI Driver for NT Microsoft Corporation Microsoft Windows Operating System
10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\UEFI.SYS Service registry key doesn't
exist or hidden.
[Drivers] :HKLM Ufx01000=C:\WINDOWS\SYSTEM32\DRIVERS\UFX01000.SYS
### USB Function Driver Class Extension Microsoft Corporation Microsoft Windows
Operating System 10.0.10586.420 Service registry key doesn't exist or hidden.
[Drivers] :HKLM UfxChipidea=C:\WINDOWS\SYSTEM32\DRIVERS\UFXCHIPIDEA.SYS
### UFX Chipidea Client Driver Microsoft Corporation Microsoft Windows Operating
System 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\UFXCHIPIDEA.SYS Service regist
ry key doesn't exist or hidden.
[Drivers] :HKLM ufxsynopsys=C:\WINDOWS\SYSTEM32\DRIVERS\UFXSYNOPSYS.SYS
### UFX Synopsys Client Driver Microsoft Corporation Microsoft Windows Operating
System 10.0.10586.306 C:\WINDOWS\SYSTEM32\DRIVERS\UFXSYNOPSYS.SYS Service regi

stry key doesn't exist or hidden.


[Drivers] :HKLM uliagpkx=C:\WINDOWS\SYSTEM32\DRIVERS\ULIAGPKX.SYS
### ULi AGPv3.0 Filter for K8/9 Processor Platforms Microsoft Corporation Micr
osoft Windows Operating System 10.0.10586.0 Service registry key doesn't exist or
hidden.
[Drivers] :HKLM umbus=C:\WINDOWS\SYSTEM32\DRIVERS\UMBUS.SYS
### User-Mode Bus Enumerator Microsoft Corporation Microsoft Windows Operating S
ystem 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\UMBUS.SYS Service registry key d
oesn't exist or hidden.
[Drivers] :HKLM UmPass=C:\WINDOWS\SYSTEM32\DRIVERS\UMPASS.SYS
### Generic pass-through driver Microsoft Corporation Microsoft Windows Operatin
g System 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\UMPASS.SYS Service registry k
ey doesn't exist or hidden.
[Drivers] :HKLM UrsChipidea=C:\WINDOWS\SYSTEM32\DRIVERS\URSCHIPIDEA.SYS
### USB Role-Switch Driver for Chipidea Core Microsoft Corporation Microsoft Wi
ndows Operating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\URSCHIPIDEA.SYS
Service registry key doesn't exist or hidden.
[Drivers] :HKLM UrsCx01000=C:\WINDOWS\SYSTEM32\DRIVERS\URSCX01000.SYS
### USB Role-Switch Class Extension Microsoft Corporation Microsoft Windows Oper
ating System 10.0.10586.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM UrsSynopsys=C:\WINDOWS\SYSTEM32\DRIVERS\URSSYNOPSYS.SYS
### USB Role-Switch Driver for Synopsys Core Microsoft Corporation Microsoft Wi
ndows Operating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\URSSYNOPSYS.SYS
Service registry key doesn't exist or hidden.
[Drivers] :HKLM usbccgp=C:\WINDOWS\SYSTEM32\DRIVERS\USBCCGP.SYS
### USB Common Class Generic Parent Driver Microsoft Corporation Microsoft Wind
ows Operating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\USBCCGP.SYS Servic
e registry key doesn't exist or hidden.
[Drivers] :HKLM usbcir=C:\WINDOWS\SYSTEM32\DRIVERS\USBCIR.SYS
### USB Consumer IR Driver for eHome Microsoft Corporation Microsoft Windows Ope
rating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\USBCIR.SYS Service regis
try key doesn't exist or hidden.
[Drivers] :HKLM usbehci=C:\WINDOWS\SYSTEM32\DRIVERS\USBEHCI.SYS
### EHCI eUSB Miniport Driver Microsoft Corporation Microsoft Windows Operating
System 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\USBEHCI.SYS Service registry ke
y doesn't exist or hidden.
[Drivers] :HKLM usbhub=C:\WINDOWS\SYSTEM32\DRIVERS\USBHUB.SYS
### Default Hub Driver for USB Microsoft Corporation Microsoft Windows Operating
System 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\USBHUB.SYS Service registry ke
y doesn't exist or hidden.
[Drivers] :HKLM USBHUB3=C:\WINDOWS\SYSTEM32\DRIVERS\USBHUB3.SYS
### USB3 HUB Driver Microsoft Corporation Microsoft Windows Operating System 10.
0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\USBHUB3.SYS Service registry key doesn't
exist or hidden.
[Drivers] :HKLM usbohci=C:\WINDOWS\SYSTEM32\DRIVERS\USBOHCI.SYS
### OHCI USB Miniport Driver Microsoft Corporation Microsoft Windows Operating S
ystem 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\USBOHCI.SYS Service registry key
doesn't exist or hidden.
[Drivers] :HKLM usbprint=C:\WINDOWS\SYSTEM32\DRIVERS\USBPRINT.SYS
### USB Printer driver Microsoft Corporation Microsoft Windows Operating System
10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\USBPRINT.SYS Service registry key does
n't exist or hidden.
[Drivers] :HKLM usbser=C:\WINDOWS\SYSTEM32\DRIVERS\USBSER.SYS
### USB Serial Driver Microsoft Corporation Microsoft Windows Operating System 1
0.0.10586.306 C:\WINDOWS\SYSTEM32\DRIVERS\USBSER.SYS Service registry key doesn
't exist or hidden.
[Drivers] :HKLM USBSTOR=C:\WINDOWS\SYSTEM32\DRIVERS\USBSTOR.SYS
### USB Mass Storage Class Driver Microsoft Corporation Microsoft Windows Operat
ing System 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\USBSTOR.SYS Service registr
y key doesn't exist or hidden.

[Drivers] :HKLM usbuhci=C:\WINDOWS\SYSTEM32\DRIVERS\USBUHCI.SYS


### UHCI USB Miniport Driver Microsoft Corporation Microsoft Windows Operating S
ystem 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\USBUHCI.SYS Service registry key
doesn't exist or hidden.
[Drivers] :HKLM usbvideo=C:\WINDOWS\SYSTEM32\DRIVERS\USBVIDEO.SYS
### USB Video Class Driver Microsoft Corporation Microsoft Windows Operating Sys
tem 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\USBVIDEO.SYS Service registry key
doesn't exist or hidden.
[Drivers] :HKLM USBXHCI=C:\WINDOWS\SYSTEM32\DRIVERS\USBXHCI.SYS
### USB XHCI Driver Microsoft Corporation Microsoft Windows Operating System 10.
0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\USBXHCI.SYS Service registry key doesn't
exist or hidden.
[Drivers] :HKLM vdrvroot=C:\WINDOWS\SYSTEM32\DRIVERS\VDRVROOT.SYS
### Virtual Drive Root Enumerator Microsoft Corporation Microsoft Windows Operat
ing System 10.0.10586.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM VerifierExt=C:\WINDOWS\SYSTEM32\DRIVERS\VERIFIEREXT.SYS
### Driver Verifier Extension Microsoft Corporation Microsoft Windows Operating
System 10.0.10586.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM vhdmp=C:\WINDOWS\SYSTEM32\DRIVERS\VHDMP.SYS
### VHD Miniport Driver Microsoft Corporation Microsoft Windows Operating System
10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\VHDMP.SYS Service registry key doesn'
t exist or hidden.
[Drivers] :HKLM vhf=C:\WINDOWS\SYSTEM32\DRIVERS\VHF.SYS
### Virtual HID Framework (VHF) Driver Microsoft Corporation Microsoft Windows O
perating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\VHF.SYS Service regist
ry key doesn't exist or hidden.
[Drivers] :HKLM vmbus=C:\WINDOWS\SYSTEM32\DRIVERS\VMBUS.SYS
### Microsoft Hyper-V Virtual Machine Bus Child Driver Microsoft Corporation M
icrosoft Windows Operating System 10.0.10586.0 Service registry key doesn't exist
or hidden.
[Drivers] :HKLM VMBusHID=C:\WINDOWS\SYSTEM32\DRIVERS\VMBUSHID.SYS
### Microsoft VMBus HID Miniport Microsoft Corporation Microsoft Windows Operati
ng System 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\VMBUSHID.SYS Service registr
y key doesn't exist or hidden.
[Drivers] :HKLM volmgr=C:\WINDOWS\SYSTEM32\DRIVERS\VOLMGR.SYS
### Volume Manager Driver Microsoft Corporation Microsoft Windows Operating Syst
em 10.0.10586.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM volmgrx=C:\WINDOWS\SYSTEM32\DRIVERS\VOLMGRX.SYS
### Volume Manager Extension Driver Microsoft Corporation Microsoft Windows Oper
ating System 10.0.10586.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM volsnap=C:\WINDOWS\SYSTEM32\DRIVERS\VOLSNAP.SYS
### Volume Shadow Copy Driver Microsoft Corporation Microsoft Windows Operating
System 10.0.10586.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM vpci=C:\WINDOWS\SYSTEM32\DRIVERS\VPCI.SYS
### Virtual PCI Bus Microsoft Corporation Microsoft Windows Operating System 10.
0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\VPCI.SYS Service registry key doesn't exi
st or hidden.
[Drivers] :HKLM vsmraid=C:\WINDOWS\SYSTEM32\DRIVERS\VSMRAID.SYS
### VIA RAID DRIVER FOR AMD-X86-64 VIA Technologies Inc.,Ltd VIA RAID driver 7
.0.9600,6352 Service registry key doesn't exist or hidden.
[Drivers] :HKLM VSTXRAID=C:\WINDOWS\SYSTEM32\DRIVERS\VSTXRAID.SYS
### VIA StorX RAID Controller Driver VIA Corporation VIA StorX RAID Controller
Driver 8.0.9200.8110 Service registry key doesn't exist or hidden.
[Drivers] :HKLM vwifibus=C:\WINDOWS\SYSTEM32\DRIVERS\VWIFIBUS.SYS
### Virtual Wi-Fi Bus Driver Microsoft Corporation Microsoft Windows Operating S
ystem 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\VWIFIBUS.SYS Service registry ke
y doesn't exist or hidden.
[Drivers] :HKLM vwififlt=C:\WINDOWS\SYSTEM32\DRIVERS\VWIFIFLT.SYS
### Virtual WiFi Filter Driver Microsoft Corporation Microsoft Windows Operating
System 10.0.10586.0 Service registry key doesn't exist or hidden.

[Drivers] :HKLM vwifimp=C:\WINDOWS\SYSTEM32\DRIVERS\VWIFIMP.SYS


### Virtual WiFi Miniport Driver Microsoft Corporation Microsoft Windows Operati
ng System 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\VWIFIMP.SYS Service registry
key doesn't exist or hidden.
[Drivers] :HKLM WacomPen=C:\WINDOWS\SYSTEM32\DRIVERS\WACOMPEN.SYS
### Wacom Serial Pen Tablet HID Driver Microsoft Corporation Microsoft Windows O
perating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\WACOMPEN.SYS Service r
egistry key doesn't exist or hidden.
[Drivers] :HKLM wanarp=C:\WINDOWS\SYSTEM32\DRIVERS\WANARP.SYS
### MS Remote Access and Routing ARP Driver Microsoft Corporation Microsoft Win
dows Operating System 10.0.10586.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM wanarpv6=C:\WINDOWS\SYSTEM32\DRIVERS\WANARP.SYS
### MS Remote Access and Routing ARP Driver Microsoft Corporation Microsoft Win
dows Operating System 10.0.10586.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM WdBoot=C:\WINDOWS\SYSTEM32\DRIVERS\WDBOOT.SYS
### Microsoft antimalware boot driver Microsoft Corporation Microsoft Windows Op
erating System 4.9.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\WDBOOT.SYS Service regis
try key doesn't exist or hidden.
[Drivers] :HKLM Wdf01000=C:\WINDOWS\SYSTEM32\DRIVERS\WDF01000.SYS
### Kernel Mode Driver Framework Runtime Microsoft Corporation Microsoft Window
s Operating System 1.17.10586.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM WdFilter=C:\WINDOWS\SYSTEM32\DRIVERS\WDFILTER.SYS
### Microsoft antimalware file system filter driver Microsoft Corporation Micr
osoft Windows Operating System 4.9.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\WDFILTER.S
YS Service registry key doesn't exist or hidden.
[Drivers] :HKLM wdiwifi=C:\WINDOWS\SYSTEM32\DRIVERS\WDIWIFI.SYS
### WDI Driver Framework Driver Microsoft Corporation Microsoft Windows Operatin
g System 10.0.10586.212 Service registry key doesn't exist or hidden.
[Drivers] :HKLM WdNisDrv=C:\WINDOWS\SYSTEM32\DRIVERS\WDNISDRV.SYS
### Microsoft Network Realtime Inspection Driver Microsoft Corporation Microso
ft Windows Operating System 4.9.10586.0 Service registry key doesn't exist or hid
den.
[Drivers] :HKLM WFPLWFS=C:\WINDOWS\SYSTEM32\DRIVERS\WFPLWFS.SYS
### WFP NDIS 6.30 Lightweight Filter Driver Microsoft Corporation Microsoft Win
dows Operating System 10.0.10586.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM WIMMount=C:\WINDOWS\SYSTEM32\DRIVERS\WIMMOUNT.SYS
### Wim file system Driver Microsoft Corporation Microsoft Windows Operating Sys
tem 10.0.10586.11 Service registry key doesn't exist or hidden.
[Drivers] :HKLM WindowsTrustedRT=C:\WINDOWS\SYSTEM32\DRIVERS\WINDOWSTRUSTEDRT.
SYS
### Windows Trusted Runtime Interface Driver Microsoft Corporation Microsoft Wi
ndows Operating System 10.0.10586.0 Service registry key doesn't exist or hidden
.
[Drivers] :HKLM WindowsTrustedRTProxy=C:\WINDOWS\SYSTEM32\DRIVERS\WINDOWSTRUST
EDRTPROXY.SYS
### Windows Trusted Runtime Service Proxy Driver Microsoft Corporation Microso
ft Windows Operating System 10.0.10586.0 Service registry key doesn't exist or hi
dden.
[Drivers] :HKLM WinMad=C:\WINDOWS\SYSTEM32\DRIVERS\WINMAD.SYS
### Kernel WinMad Mellanox OpenFabrics Windows 6.3.9600.16384 C:\WINDOWS\SYST
EM32\DRIVERS\WINMAD.SYS Service registry key doesn't exist or hidden.
[Drivers] :HKLM WINUSB=C:\WINDOWS\SYSTEM32\DRIVERS\WINUSB.SYS
### Windows WinUSB Class Driver Microsoft Corporation Microsoft Windows Operatin
g System 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\WINUSB.SYS Service registry k
ey doesn't exist or hidden.
[Drivers] :HKLM WinVerbs=C:\WINDOWS\SYSTEM32\DRIVERS\WINVERBS.SYS
### Kernel WinVerbs Mellanox OpenFabrics Windows 6.3.9600.16384 C:\WINDOWS\SY
STEM32\DRIVERS\WINVERBS.SYS Service registry key doesn't exist or hidden.
[Drivers] :HKLM WmiAcpi=C:\WINDOWS\SYSTEM32\DRIVERS\WMIACPI.SYS
### Windows Management Interface for ACPI Microsoft Corporation Microsoft Windo

ws Operating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\WMIACPI.SYS Service


registry key doesn't exist or hidden.
[Drivers] :HKLM wpcfltr=C:\WINDOWS\SYSTEM32\DRIVERS\WPCFLTR.SYS
### Family Safety Filter Driver Microsoft Corporation Microsoft Windows Operatin
g System 10.0.10586.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM WpdUpFltr=C:\WINDOWS\SYSTEM32\DRIVERS\WPDUPFLTR.SYS
### Windows Portable Device Upper Class Filter Driver Microsoft Corporation Mi
crosoft Windows Operating System 10.0.10586.0 Service registry key doesn't exist
or hidden.
[Drivers] :HKLM ws2ifsl=C:\WINDOWS\SYSTEM32\DRIVERS\WS2IFSL.SYS
### Winsock2 IFS Layer Microsoft Corporation Microsoft Windows Operating System
10.0.10586.0 C:\WINDOWS\SYSTEM32\DRIVERS\WS2IFSL.SYS Service registry key doesn
't exist or hidden.
[Drivers] :HKLM WudfPf=C:\WINDOWS\SYSTEM32\DRIVERS\WUDFPF.SYS
### Windows Driver Foundation - User-mode Driver Framework Platform Driver Mic
rosoft Corporation Microsoft Windows Operating System 10.0.10586.0 Service regist
ry key doesn't exist or hidden.
[Drivers] :HKLM WUDFRd=C:\WINDOWS\SYSTEM32\DRIVERS\WUDFRD.SYS
### Windows Driver Foundation - User-mode Driver Framework Reflector Microsoft
Corporation Microsoft Windows Operating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\
DRIVERS\WUDFRD.SYS Service registry key doesn't exist or hidden.
[Drivers] :HKLM WUDFWpdFs=C:\WINDOWS\SYSTEM32\DRIVERS\WUDFRD.SYS
### Windows Driver Foundation - User-mode Driver Framework Reflector Microsoft
Corporation Microsoft Windows Operating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\
DRIVERS\WUDFRD.SYS Service registry key doesn't exist or hidden.
[Drivers] :HKLM xboxgip=C:\WINDOWS\SYSTEM32\DRIVERS\XBOXGIP.SYS
### Game Input Protocol Driver Microsoft Corporation Microsoft Windows Operating
System 10.0.10586.122 C:\WINDOWS\SYSTEM32\DRIVERS\XBOXGIP.SYS Service registry
key doesn't exist or hidden.
[Drivers] :HKLM xinputhid=C:\WINDOWS\SYSTEM32\DRIVERS\XINPUTHID.SYS
### XINPUT filter driver for HID Microsoft Corporation Microsoft Windows Operati
ng System 10.0.10586.212 C:\WINDOWS\SYSTEM32\DRIVERS\XINPUTHID.SYS Service regi
stry key doesn't exist or hidden.
[Codecs] :HKLM midimapper=C:\Windows\SYSTEM32\MIDIMAP.DLL
### Microsoft MIDI Mapper Microsoft Corporation Microsoft Windows Operating Syst
em 10.0.10586.0 C:\Windows\SYSTEM32\MIDIMAP.DLL
[Codecs] :HKLM msacm.imaadpcm=C:\Windows\SYSTEM32\IMAADP32.ACM
### IMA ADPCM CODEC for MSACM Microsoft Corporation Microsoft Windows Operating
System 10.0.10586.0 C:\Windows\SYSTEM32\IMAADP32.ACM
[Codecs] :HKLM msacm.l3acm=C:\WINDOWS\SYSWOW64\L3CODECA.ACM
### MPEG Layer-3 Audio Codec for MSACM Fraunhofer Institut Integrierte Schaltu
ngen IIS MPEG Layer-3 Audio Codec for MSACM 1, 0, 0, 0
[Codecs] :HKLM msacm.msadpcm=C:\Windows\SYSTEM32\MSADP32.ACM
### Microsoft ADPCM CODEC for MSACM Microsoft Corporation Microsoft Windows Oper
ating System 10.0.10586.0 C:\Windows\SYSTEM32\MSADP32.ACM
[Codecs] :HKLM msacm.msg711=C:\Windows\SYSTEM32\MSG711.ACM
### Microsoft CCITT G.711 (A-Law and u-Law) CODEC for MSACM Microsoft Corporat
ion Microsoft Windows Operating System 10.0.10586.0 C:\Windows\SYSTEM32\MSG711.AC
M
[Codecs] :HKLM msacm.msgsm610=C:\Windows\SYSTEM32\MSGSM32.ACM
### Microsoft GSM 6.10 Audio CODEC for MSACM Microsoft Corporation Microsoft Wi
ndows Operating System 10.0.10586.0 C:\Windows\SYSTEM32\MSGSM32.ACM
[Codecs] :HKLM vidc.cvid=C:\WINDOWS\Syswow64\ICCVID.DLL
### Cinepak Codec Radius Inc. Cinepak for Windows 32 1.10.0.0 C:\WINDOWS\Syswo
w64\ICCVID.DLL
[Codecs] :HKLM vidc.i420=C:\Windows\SYSTEM32\IYUV_32.DLL
### Intel Indeo(R) Video YUV Codec Microsoft Corporation Microsoft Windows Opera
ting System 10.0.10586.0 C:\Windows\SYSTEM32\IYUV_32.DLL
[Codecs] :HKLM vidc.iyuv=C:\Windows\SYSTEM32\IYUV_32.DLL
### Intel Indeo(R) Video YUV Codec Microsoft Corporation Microsoft Windows Opera

ting System 10.0.10586.0 C:\Windows\SYSTEM32\IYUV_32.DLL


[Codecs] :HKLM vidc.mrle=C:\Windows\SYSTEM32\MSRLE32.DLL
### Microsoft RLE Compressor Microsoft Corporation Microsoft Windows Operating S
ystem 10.0.10586.0 C:\Windows\SYSTEM32\MSRLE32.DLL
[Codecs] :HKLM vidc.msvc=C:\Windows\SYSTEM32\MSVIDC32.DLL
### Microsoft Video 1 Compressor Microsoft Corporation Microsoft Windows Operati
ng System 10.0.10586.0 C:\Windows\SYSTEM32\MSVIDC32.DLL
[Codecs] :HKLM vidc.uyvy=C:\Windows\SYSTEM32\MSYUV.DLL
### Microsoft UYVY Video Decompressor Microsoft Corporation Microsoft Windows Op
erating System 10.0.10586.0 C:\Windows\SYSTEM32\MSYUV.DLL
[Codecs] :HKLM vidc.yuy2=C:\Windows\SYSTEM32\MSYUV.DLL
### Microsoft UYVY Video Decompressor Microsoft Corporation Microsoft Windows Op
erating System 10.0.10586.0 C:\Windows\SYSTEM32\MSYUV.DLL
[Codecs] :HKLM vidc.yvu9=C:\Windows\SYSTEM32\TSBYUV.DLL
### Toshiba Video Codec Microsoft Corporation Microsoft Windows Operating System
10.0.10586.0 C:\Windows\SYSTEM32\TSBYUV.DLL
[Codecs] :HKLM vidc.yvyu=C:\Windows\SYSTEM32\MSYUV.DLL
### Microsoft UYVY Video Decompressor Microsoft Corporation Microsoft Windows Op
erating System 10.0.10586.0 C:\Windows\SYSTEM32\MSYUV.DLL
[Codecs] :HKLM wavemapper=C:\Windows\SYSTEM32\MSACM32.DRV
### Microsoft Sound Mapper Microsoft Corporation Microsoft Windows Operating Sys
tem 10.0.10586.0 C:\Windows\SYSTEM32\MSACM32.DRV
[Codecs] :HKLM wave=C:\Windows\SYSTEM32\WDMAUD.DRV
### Winmm audio system driver Microsoft Corporation Microsoft Windows Operating
System 10.0.10586.0 C:\Windows\SYSTEM32\WDMAUD.DRV
[Codecs] :HKLM midi=C:\Windows\SYSTEM32\WDMAUD.DRV
### Winmm audio system driver Microsoft Corporation Microsoft Windows Operating
System 10.0.10586.0 C:\Windows\SYSTEM32\WDMAUD.DRV
[Codecs] :HKLM mixer=C:\Windows\SYSTEM32\WDMAUD.DRV
### Winmm audio system driver Microsoft Corporation Microsoft Windows Operating
System 10.0.10586.0 C:\Windows\SYSTEM32\WDMAUD.DRV
[Codecs] :HKLM aux=C:\Windows\SYSTEM32\WDMAUD.DRV
### Winmm audio system driver Microsoft Corporation Microsoft Windows Operating
System 10.0.10586.0 C:\Windows\SYSTEM32\WDMAUD.DRV
[Codecs] :HKLM wave1=C:\Windows\SYSTEM32\WDMAUD.DRV
### Winmm audio system driver Microsoft Corporation Microsoft Windows Operating
System 10.0.10586.0 C:\Windows\SYSTEM32\WDMAUD.DRV
[Codecs] :HKLM midi1=C:\Windows\SYSTEM32\WDMAUD.DRV
### Winmm audio system driver Microsoft Corporation Microsoft Windows Operating
System 10.0.10586.0 C:\Windows\SYSTEM32\WDMAUD.DRV
[Codecs] :HKLM mixer1=C:\Windows\SYSTEM32\WDMAUD.DRV
### Winmm audio system driver Microsoft Corporation Microsoft Windows Operating
System 10.0.10586.0 C:\Windows\SYSTEM32\WDMAUD.DRV
[Codecs] :HKLM aux1=C:\Windows\SYSTEM32\WDMAUD.DRV
### Winmm audio system driver Microsoft Corporation Microsoft Windows Operating
System 10.0.10586.0 C:\Windows\SYSTEM32\WDMAUD.DRV
[DCOM Components] :HKLM {F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}=""
[DCOM Components] :HKLM {5839FCA9-774D-42A1-ACDA-D6A79037F57F}=C:\WINDOWS\SYST
EM32\WBEM\FASTPROX.DLL
### WMI Custom Marshaller Microsoft Corporation Microsoft Windows Operating Syst
em 10.0.10586.0
[DCOM Components] :HKLM {42AEDC87-2188-41FD-B9A3-0C966FEABEC1}=C:\WINDOWS\SYST
EM32\WINDOWS.STORAGE.DLL
### Microsoft WinRT Storage API Microsoft Corporation Microsoft Windows Operatin
g System 10.0.10586.0
[DCOM User Components] :HKCU {F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}=""
[DCOM User Components] :HKCU {FBEB8A05-BEEE-4442-804E-409D6C4515E9}=""
[DCOM User Components] :HKCU {42AEDC87-2188-41FD-B9A3-0C966FEABEC1}=""
[Auto Start Apps]
[Registry Run] :HKCU OneDrive=C:\USERS\BAMMI\APPDATA\LOCAL\MICROSOFT\ONEDRIVE\

ONEDRIVE.EXE
### Microsoft OneDrive Microsoft Corporation Microsoft OneDrive 17.3.6390.0509
C:\USERS\BAMMI\APPDATA\LOCAL\MICROSOFT\ONEDRIVE\ONEDRIVE.EXE
[Registry Run] :HKLM HarmonyPicks=C:\PROGRAM FILES (X86)\LENOVO\HARMONY\PICKS\
LENOVO.HARMONYPICKS.EXE
### Lenovo.HarmonyPicks Lenovo Lenovo.HarmonyPicks 1.0.1.228 C:\PROGRAM FILES
(X86)\LENOVO\HARMONY\PICKS\LENOVO.HARMONYPICKS.EXE
[Registry Run] :HKLM HarmonySetting=C:\PROGRAM FILES (X86)\LENOVO\HARMONY\SETT
ING\LENOVO.HARMONYSETTING.EXE
### Lenovo.HarmonySetting Lenovo Lenovo.HarmonySetting 1.0.1.303 C:\PROGRAM F
ILES (X86)\LENOVO\HARMONY\SETTING\LENOVO.HARMONYSETTING.EXE
[Registry Run(x64)] :HKLM IAStorIcon=C:\PROGRAM FILES\INTEL\INTEL(R) RAPID STO
RAGE TECHNOLOGY\IASTORICONLAUNCH.EXE
### Delayed launcher Intel Corporation Delayed launcher 1, 0, 0, 1 C:\PROGRAM
FILES\INTEL\INTEL(R) RAPID STORAGE TECHNOLOGY\IASTORICONLAUNCH.EXE
[Registry Run(x64)] :HKLM RtHDVBg_Dolby=C:\PROGRAM FILES\REALTEK\AUDIO\HDA\RAV
BG64.EXE
### HD Audio Background Process Realtek Semiconductor HD Audio Background Proc
ess 1, 0, 0, 225 C:\PROGRAM FILES\REALTEK\AUDIO\HDA\RAVBG64.EXE
[Registry Run(x64)] :HKLM RtHDVBg_LENOVO_DOLBYDRAGON=C:\PROGRAM FILES\REALTEK\
AUDIO\HDA\RAVBG64.EXE
### HD Audio Background Process Realtek Semiconductor HD Audio Background Proc
ess 1, 0, 0, 225 C:\PROGRAM FILES\REALTEK\AUDIO\HDA\RAVBG64.EXE
[Registry Run(x64)] :HKLM RtHDVBg_LENOVO_MICPKEY=C:\PROGRAM FILES\REALTEK\AUDI
O\HDA\RAVBG64.EXE
### HD Audio Background Process Realtek Semiconductor HD Audio Background Proc
ess 1, 0, 0, 225 C:\PROGRAM FILES\REALTEK\AUDIO\HDA\RAVBG64.EXE
[Registry Run(x64)] :HKLM DDPF3=C:\PROGRAM FILES\DOLBY\DDP_F3\DDPF3.EXE
### DolbyDigitalPlus Dolby Laboratories Inc. DolbyDigitalPlus 7.6.7.1 C:\PROG
RAM FILES\DOLBY\DDP_F3\DDPF3.EXE
[Registry Run(x64)] :HKLM NvBackend=C:\PROGRAM FILES (X86)\NVIDIA CORPORATION\
UPDATE CORE\NVBACKEND.EXE
### NVIDIA Backend NVIDIA Corporation NVIDIA Backend 20.16.6.0 C:\PROGRAM FIL
ES (X86)\NVIDIA CORPORATION\UPDATE CORE\NVBACKEND.EXE
[Registry Run(x64)] :HKLM SynTPEnh=C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPENH.E
XE
### Synaptics TouchPad 64-bit Enhancements Synaptics Incorporated Synaptics Po
inting Device Driver 19.0.18 23Jul15 C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPENH.
EXE
[Registry Run(x64)] :HKLM OneKeyOptimizer=C:\PROGRAM FILES\LENOVO\ONEKEY OPTIM
IZER\BIN\ONEKEYOPTIMIZERTRAY.EXE
### OneKey Optimizer is Lenovo's unique power management and optimization app
Lenovo(beijing) Limited OneKeyOptimizer 1.3.0.5 C:\PROGRAM FILES\LENOVO\ONEKEY
OPTIMIZER\BIN\ONEKEYOPTIMIZERTRAY.EXE
[Registry Run(x64)] :HKLM AutoStartTransition=C:\PROGRAM FILES (X86)\LENOVO\LE
NOVOTRANSITION\TRANSITIONSERVER.EXE
[Win.ini] :HKCU load=""
### File is deleted or hidden by a rootkit or could not be located.
[Win.ini] :HKCU run=""
### File is deleted or hidden by a rootkit or could not be located.
[Scheduled Tasks] Uninstaller_SkipUac_bammi=C:\PROGRAM FILES (X86)\IOBIT\IOBIT
UNINSTALLER\IOBITUNINSTALER.EXE
### Uninstall Programs IObit Uninstall Programs 5.4.0.0
[Scheduled Tasks] GoogleUpdateTaskMachineUA=C:\PROGRAM FILES (X86)\GOOGLE\UPDA
TE\GOOGLEUPDATE.EXE
### Google Installer Google Inc. Google Update 1.3.29.5
[Scheduled Tasks] GoogleUpdateTaskMachineCore=C:\PROGRAM FILES (X86)\GOOGLE\UP
DATE\GOOGLEUPDATE.EXE
### Google Installer Google Inc. Google Update 1.3.29.5
[Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\BDAntiCryptoWallTask=C:\PROGRAM

FILES\BITDEFENDER\TOOLS\BDANTIRANSOMWARE\BDANTIRANSOMWARE.EXE
[Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\GoogleUpdateTaskMachineCore=C:\
PROGRAM FILES (X86)\GOOGLE\UPDATE\GOOGLEUPDATE.EXE
### Google Installer Google Inc. Google Update 1.3.29.5 Description: Keeps y
our Google software up to date. If this tas Parameters: /c
[Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\GoogleUpdateTaskMachineUA=C:\PR
OGRAM FILES (X86)\GOOGLE\UPDATE\GOOGLEUPDATE.EXE
### Google Installer Google Inc. Google Update 1.3.29.5 Description: Keeps y
our Google software up to date. If this tas Parameters: /ua /installsource sche
duler
[Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Lenovo\ImController\Lenovo iM C
ontroller Scheduled Maintenance=C:\WINDOWS\SYSTEM32\SC.EXE
### Service Control Manager Configuration Tool Microsoft Corporation Microsoft
Windows Operating System 10.0.10586.0 C:\WINDOWS\SYSTEM32\SC.EXE Parameters: co
ntrol iMControllerService 128
[Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Lenovo\ImController\Plugins\Len
ovoSystemUpdatePlugin_TVSUUpdateTask=C:\WINDOWS\SYSTEM32\REG.EXE
### Registry Console Tool Microsoft Corporation Microsoft Windows Operating Syst
em 10.0.10586.0 C:\WINDOWS\SYSTEM32\REG.EXE Parameters: add hklm\SOFTWARE\Leno
vo\SystemUpdatePlugin\scheduler /v start /t reg_dword /d 1 /f /reg:32
[Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Lenovo\ImController\Plugins\Len
ovoSystemUpdatePlugin_TVSUUpdateTask_Weekly=C:\WINDOWS\SYSTEM32\REG.EXE
### Registry Console Tool Microsoft Corporation Microsoft Windows Operating Syst
em 10.0.10586.0 C:\WINDOWS\SYSTEM32\REG.EXE Parameters: add hklm\SOFTWARE\Leno
vo\SystemUpdatePlugin\scheduler /v start /t reg_dword /d 1 /f /reg:32
[Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Lenovo\Lenovo Customer Feedback
Program 64=C:\PROGRAM FILES (X86)\LENOVO\CUSTOMER FEEDBACK PROGRAM\LENOVO.TVT.C
USTOMERFEEDBACK.AGENT.EXE
### Lenovo.TVT.CustomerFeedback.Agent Lenovo Lenovo Customer Feedback Program
1.1.0009.000 C:\PROGRAM FILES (X86)\LENOVO\CUSTOMER FEEDBACK PROGRAM\LENOVO.TVT
.CUSTOMERFEEDBACK.AGENT.EXE Description: This task uploads Customer Feedback Pr
ogram data t
[Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\UnHackMe Task Scheduler=C:\PROG
RAM FILES (X86)\UNHACKME\HACKMON.EXE
### Detects Rootkits in background Greatis Software UnHackMe 8.12 Descriptio
n: Part of RegRun Suite/UnHackMe software. http://www Parameters: $(Arg0)
[Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Uninstaller_SkipUac_bammi=C:\PR
OGRAM FILES (X86)\IOBIT\IOBIT UNINSTALLER\IOBITUNINSTALER.EXE
### Uninstall Programs IObit Uninstall Programs 5.4.0.0 Parameters: /Uninsta
llExplorer
[Scheduled Tasks 2.0 Cached] :HKLM BDAntiCryptoWallTask=C:\PROGRAM FILES\BITDE
FENDER\TOOLS\BDANTIRANSOMWARE\BDANTIRANSOMWARE.EXE
[Scheduled Tasks 2.0 Cached] :HKLM GoogleUpdateTaskMachineCore=C:\PROGRAM FILE
S (X86)\GOOGLE\UPDATE\GOOGLEUPDATE.EXE
### Google Installer Google Inc. Google Update 1.3.29.5 Keeps your Google so
ftware up to date. If this task is disabled or stopped, your Google software wil
l not be kept up to date, meaning security vulnerabilities that may arise cannot
be fixed and features may not work. This task uninstalls itself when there is n
o Google software using it. Parameters: /c
[Scheduled Tasks 2.0 Cached] :HKLM GoogleUpdateTaskMachineUA=C:\PROGRAM FILES
(X86)\GOOGLE\UPDATE\GOOGLEUPDATE.EXE
### Google Installer Google Inc. Google Update 1.3.29.5 Keeps your Google so
ftware up to date. If this task is disabled or stopped, your Google software wil
l not be kept up to date, meaning security vulnerabilities that may arise cannot
be fixed and features may not work. This task uninstalls itself when there is n
o Google software using it. Parameters: /ua /installsource scheduler
[Scheduled Tasks 2.0 Cached] :HKLM UnHackMe Task Scheduler=C:\PROGRAM FILES (X
86)\UNHACKME\HACKMON.EXE
### Detects Rootkits in background Greatis Software UnHackMe 8.12 Part of Re
gRun Suite/UnHackMe software. http://www.greatis.com Parameters: $(Arg0)

[Scheduled Tasks 2.0 Cached] :HKLM Uninstaller_SkipUac_bammi=C:\PROGRAM FILES


(X86)\IOBIT\IOBIT UNINSTALLER\IOBITUNINSTALER.EXE
### Uninstall Programs IObit Uninstall Programs 5.4.0.0 Parameters: /Uninsta
llExplorer
[Unwanted Software Files] :HKLM vghd=C:\USERS\BAMMI\APPDATA\LOCAL\VGHD\
[Detected using Heuristic Algorithm] :HKLM CISCO=C:\PROGRAM FILES (X86)\CISCO\
### "CISCO EAP-FAST MODULE\" "CISCO LEAP MODULE\" "CISCO PEAP MODULE\"
[Detected using Heuristic Algorithm] :HKLM COMMON FILES=C:\PROGRAM FILES (X86)
\COMMON FILES\
### "INTEL\" "INTEL CORPORATION\" "MICROSOFT SHARED\" "POSTUREAGENT\" "SERVIC
ES\" "SYSTEM\"
[Detected using Heuristic Algorithm] :HKLM INTEL=C:\PROGRAM FILES (X86)\COMMON
FILES\INTEL\
### "OPENCL\"
[Detected using Heuristic Algorithm] :HKLM INTEL CORPORATION=C:\PROGRAM FILES
(X86)\COMMON FILES\INTEL CORPORATION\
### "IASTORUTIL\" "PSI\"
[Detected using Heuristic Algorithm] :HKLM MICROSOFT SHARED=C:\PROGRAM FILES (
X86)\COMMON FILES\MICROSOFT SHARED\
### "DAO\" "HELP\" "INK\" "MSENV\" "MSINFO\" "OFFICE16\" "PORTAL\" "STATIONER
Y\" "TEXTCONV\" "TRIEDIT\" "VBA\"
[Detected using Heuristic Algorithm] :HKLM POSTUREAGENT=C:\PROGRAM FILES (X86)
\COMMON FILES\POSTUREAGENT\
### "PLUGINS\"
[Detected using Heuristic Algorithm] :HKLM GOOGLE=C:\PROGRAM FILES (X86)\GOOGL
E\
### "CHROME\" "CRASHREPORTS\" "UPDATE\"
[Detected using Heuristic Algorithm] :HKLM INSTALLSHIELD INSTALLATION INFORMAT
ION=C:\PROGRAM FILES (X86)\INSTALLSHIELD INSTALLATION INFORMATION\
### "{83272F62-4914-4EF8-B07E-271B92C56477}\" "{8833FFB6-5B0C-4764-81AA-06DFE
ED9A476}\" "{D02D9427-507D-4912-9285-97FCD5417E72}\" "{D5D573DC-D989-4769-9B56-D
6A7EA503D7F}\" "{E399A5B3-ED53-4DEA-AF04-8011E1EB1EAC}\" "{F132AF7F-7BCA-4EDE-8A
7C-958108FE7DBC}\"
[Detected using Heuristic Algorithm] :HKLM INTEL=C:\PROGRAM FILES (X86)\INTEL\
### "BLUETOOTH\" "ICLS CLIENT\" "INTEL(R) DYNAMIC PLATFORM AND THERMAL FRAMEW
ORK\" "INTEL(R) MANAGEMENT ENGINE COMPONENTS\" "INTEL(R) PROCESSOR GRAPHICS\" "I
NTEL(R) SECURITY ASSIST\" "WIFI\"
[Detected using Heuristic Algorithm] :HKLM INTERNET EXPLORER=C:\PROGRAM FILES
(X86)\INTERNET EXPLORER\
### "EN-US\" "EXTEXPORT.EXE" "HMMAPI.DLL" "IE9PROPS.PROPDESC" "IEINSTAL.EXE"
"IELOWUTIL.EXE" "IESHIMS.DLL" "IEXPLORE.EXE" "IMAGES\" "SIGNUP\" "SQMAPI.DLL"
[Detected using Heuristic Algorithm] :HKLM IOBIT=C:\PROGRAM FILES (X86)\IOBIT\
### "IOBIT UNINSTALLER\" "LIVEUPDATE\"
[Detected using Heuristic Algorithm] :HKLM KASPERSKY LAB=C:\PROGRAM FILES (X86
)\KASPERSKY LAB\
### "KASPERSKY INTERNET SECURITY 16.0.1\"
[Detected using Heuristic Algorithm] :HKLM LENOVO=C:\PROGRAM FILES (X86)\LENOV
O\
### "CCSDK\" "CUSTOMER FEEDBACK PROGRAM\" "HARMONY\" "IMCONTROLLER\" "LENOVOT
RANSITION\" "METRICCOLLECTIONSDK\" "QUICKSETTING\"
[Detected using Heuristic Algorithm] :HKLM MICROSOFT ANALYSIS SERVICES=C:\PROG
RAM FILES (X86)\MICROSOFT ANALYSIS SERVICES\
### "AS OLEDB\"
[Detected using Heuristic Algorithm] :HKLM MICROSOFT OFFICE=C:\PROGRAM FILES (
X86)\MICROSOFT OFFICE\
### "OFFICE16\"
[Detected using Heuristic Algorithm] :HKLM MICROSOFT SQL SERVER=C:\PROGRAM FIL
ES (X86)\MICROSOFT SQL SERVER\
### "110\"
[Detected using Heuristic Algorithm] :HKLM MICROSOFT.NET=C:\PROGRAM FILES (X86

)\MICROSOFT.NET\
### "ADOMD.NET\" "PRIMARY INTEROP ASSEMBLIES\" "REDISTLIST\"
[Detected using Heuristic Algorithm] :HKLM MOZILLA FIREFOX=C:\PROGRAM FILES (X
86)\MOZILLA FIREFOX\
### "PLUGINS\"
[Detected using Heuristic Algorithm] :HKLM NVIDIA CORPORATION=C:\PROGRAM FILES
(X86)\NVIDIA CORPORATION\
### "LED VISUALIZER\" "NETSERVICE\" "NVIDIA GEFORCE EXPERIENCE\" "PHYSX\" "UP
DATE CORE\"
[Detected using Heuristic Algorithm] :HKLM RAXCO=C:\PROGRAM FILES (X86)\RAXCO\
### "PD14.0_PRO_INSTALL\"
[Detected using Heuristic Algorithm] :HKLM REALTEK=C:\PROGRAM FILES (X86)\REAL
TEK\
### "AUDIO\" "NICDRV_8169\" "REALTEK PC CAMERA\"
[Detected using Heuristic Algorithm] :HKLM SHAREIT=C:\PROGRAM FILES (X86)\SHAR
EIT\
### "SHAREIT\"
[Detected using Heuristic Algorithm] :HKLM TEMP=C:\PROGRAM FILES (X86)\TEMP\
[Detected using Heuristic Algorithm] :HKLM UNHACKME=C:\PROGRAM FILES (X86)\UNH
ACKME\
### "7ZA.EXE" "DATABASE.RDB" "DBS.DB" "DBS.INI" "DBS.ZIP" "DBSWWW.INI" "GWEBU
PDATE.EXE" "GWEBUPDATE.EXE+" "GWEBUPDATE.EXE-" "HACKMON.EXE" "JSONFAST.DLL"
[Detected using Heuristic Algorithm] :HKLM VULKANRT=C:\PROGRAM FILES (X86)\VUL
KANRT\
### "1.0.11.1\"
[Detected using Heuristic Algorithm] :HKLM WINDOWS MULTIMEDIA PLATFORM=C:\PROG
RAM FILES (X86)\WINDOWS MULTIMEDIA PLATFORM\
### "SQMAPI.DLL"
[Detected using Heuristic Algorithm] :HKLM WINDOWS PORTABLE DEVICES=C:\PROGRAM
FILES (X86)\WINDOWS PORTABLE DEVICES\
### "SQMAPI.DLL"
[Detected using Heuristic Algorithm] :HKLM BITDEFENDER=C:\PROGRAM FILES\BITDEF
ENDER\
### "TOOLS\"
[Detected using Heuristic Algorithm] :HKLM COMMON FILES=C:\PROGRAM FILES\COMMO
N FILES\
### "DESIGNER\" "INTEL\" "MICROSOFT SHARED\" "RAXCO\" "SERVICES\" "SYSTEM\"
[Detected using Heuristic Algorithm] :HKLM DESIGNER=C:\PROGRAM FILES\COMMON FI
LES\DESIGNER\
### "MSADDNDR.OLB"
[Detected using Heuristic Algorithm] :HKLM INTEL=C:\PROGRAM FILES\COMMON FILES
\INTEL\
### "WIRELESSCOMMON\"
[Detected using Heuristic Algorithm] :HKLM MICROSOFT SHARED=C:\PROGRAM FILES\C
OMMON FILES\MICROSOFT SHARED\
### "DW\" "EQUATION\" "EURO\" "FILTERS\" "GRPHFLT\" "HELP\" "INK\" "MSCLIENTD
ATAMGR\" "MSINFO\" "OFFICE16\" "OFFICESOFTWAREPROTECTIONPLATFORM\"
[Detected using Heuristic Algorithm] :HKLM RAXCO=C:\PROGRAM FILES\COMMON FILES
\RAXCO\
### "SHARED\"
[Detected using Heuristic Algorithm] :HKLM SYSTEM=C:\PROGRAM FILES\COMMON FILE
S\SYSTEM\
### "ADO\" "DIRECTDB.DLL" "EN-US\" "MSADC\" "MSMAPI\" "OLE DB\" "WAB32.DLL" "
WAB32RES.DLL"
[Detected using Heuristic Algorithm] :HKLM DOLBY=C:\PROGRAM FILES\DOLBY\
### "DDP_F3\"
[Detected using Heuristic Algorithm] :HKLM INTEL=C:\PROGRAM FILES\INTEL\
### "ICLS CLIENT\" "INTEL(R) CHIPSET DEVICE SOFTWARE\" "INTEL(R) MANAGEMENT E
NGINE COMPONENTS\" "INTEL(R) RAPID STORAGE TECHNOLOGY\" "INTEL(R) SERIAL IO\" "M
EDIA SDK\" "WIFI\" "WIFIDRIVERS\"

[Detected using Heuristic Algorithm] :HKLM INTERNET EXPLORER=C:\PROGRAM FILES\


INTERNET EXPLORER\
### "EN-US\" "HMMAPI.DLL" "IEDIAGCMD.EXE" "IEINSTAL.EXE" "IELOWUTIL.EXE" "IES
HIMS.DLL" "IEXPLORE.EXE" "IMAGES\" "SIGNUP\" "SQMAPI.DLL"
[Detected using Heuristic Algorithm] :HKLM LENOVO=C:\PROGRAM FILES\LENOVO\
### "BATTERYGAUGE\" "IMCONTROLLER\" "ONEKEY OPTIMIZER\" "QUICKOPTIMIZER\"
[Detected using Heuristic Algorithm] :HKLM MICROSOFT ANALYSIS SERVICES=C:\PROG
RAM FILES\MICROSOFT ANALYSIS SERVICES\
### "AS OLEDB\"
[Detected using Heuristic Algorithm] :HKLM MICROSOFT OFFICE=C:\PROGRAM FILES\M
ICROSOFT OFFICE\
### "CLIPART\" "DOCUMENT THEMES 16\" "OFFICE16\" "STATIONERY\" "TEMPLATES\"
[Detected using Heuristic Algorithm] :HKLM MICROSOFT SQL SERVER=C:\PROGRAM FIL
ES\MICROSOFT SQL SERVER\
### "110\"
[Detected using Heuristic Algorithm] :HKLM MICROSOFT.NET=C:\PROGRAM FILES\MICR
OSOFT.NET\
### "ADOMD.NET\"
[Detected using Heuristic Algorithm] :HKLM NVIDIA CORPORATION=C:\PROGRAM FILES
\NVIDIA CORPORATION\
### "CONTROL PANEL CLIENT\" "DISPLAY\" "DRS\" "GEFORCE EXPERIENCE SERVICE\" "
INSTALLER2\" "LICENSE.TXT" "NETSERVICE\" "NVSMI\" "OPENCL\" "UPDATE CORE\"
[Detected using Heuristic Algorithm] :HKLM RAXCO=C:\PROGRAM FILES\RAXCO\
### "PERFECTDISK\"
[Detected using Heuristic Algorithm] :HKLM REALTEK=C:\PROGRAM FILES\REALTEK\
### "AUDIO\"
[Detected using Heuristic Algorithm] :HKLM SYNAPTICS=C:\PROGRAM FILES\SYNAPTIC
S\
### "SYNTP\"
[Detected using Heuristic Algorithm] :HKLM UNINSTALL INFORMATION=C:\PROGRAM FI
LES\UNINSTALL INFORMATION\
[Detected using Heuristic Algorithm] :HKLM WINDOWS JOURNAL=C:\PROGRAM FILES\WI
NDOWS JOURNAL\
### "EN-US\" "INKSEG.DLL" "JNTFILTR.DLL" "JNWDRV.DLL" "JNWDUI.DLL" "JNWMON.DL
L" "JNWPPR.DLL" "JOURNAL.EXE" "MSPVWCTL.DLL" "NBDOC.DLL" "NBMAPTIP.DLL"
[Detected using Heuristic Algorithm] :HKLM WINDOWS MEDIA PLAYER=C:\PROGRAM FIL
ES\WINDOWS MEDIA PLAYER\
### "EN-US\" "ICONS\" "MEDIA RENDERER\" "MPVIS.DLL" "NETWORK SHARING\" "SETUP
_WM.EXE" "SKINS\" "VISUALIZATIONS\" "WMLAUNCH.EXE" "WMPCONFIG.EXE" "WMPLAYER.EXE
"
[Detected using Heuristic Algorithm] :HKLM WINDOWS MULTIMEDIA PLATFORM=C:\PROG
RAM FILES\WINDOWS MULTIMEDIA PLATFORM\
### "SQMAPI.DLL"
[Detected using Heuristic Algorithm] :HKLM WINDOWS PORTABLE DEVICES=C:\PROGRAM
FILES\WINDOWS PORTABLE DEVICES\
### "SQMAPI.DLL"
[Detected using Heuristic Algorithm] :HKLM WINDOWSAPPS=C:\PROGRAM FILES\WINDOW
SAPPS\
### "9E2F88E3.TWITTER_5.1.3.0_X86__WGEQDKKX372WM\" "DELETED\" "E046963F.LENOV
OCOMPANION_3.49.1.0_NEUTRAL_SPLIT.SCALE-150_K1H2YWK1493X8\" "E046963F.LENOVOCOMP
ANION_3.49.1.0_NEUTRAL_~_K1H2YWK1493X8\" "E046963F.LENOVOCOMPANION_3.49.1.0_X86_
_K1H2YWK1493X8\" "KING.COM.CANDYCRUSHSODASAGA_1.68.500.0_X86__KGQVNYMYFVS32\" "L
ENOVOCORPORATION.LENOVOSETTINGS_3.105.0.0_NEUTRAL_SPLIT.SCALE-180_4642SHXVSV8S2\
" "LENOVOCORPORATION.LENOVOSETTINGS_3.105.0.0_NEUTRAL_~_4642SHXVSV8S2\" "LENOVOC
ORPORATION.LENOVOSETTINGS_3.105.0.0_X86__4642SHXVSV8S2\" "MICROSOFT.3DBUILDER_10
.9.50.0_NEUTRAL_SPLIT.SCALE-180_8WEKYB3D8BBWE\" "MICROSOFT.3DBUILDER_11.1.8.0_NE
UTRAL_SPLIT.LANGUAGE-HI_8WEKYB3D8BBWE\"
[Detected using Heuristic Algorithm] :HKLM APPLICATION DATA=C:\PROGRAMDATA\APP
LICATION DATA\
### "APPLICATION DATA\" "COMMS\" "DESKTOP\" "DOCUMENTS\" "DOWNLOADED INSTALLA

TIONS\" "DP45977C.LFL" "INTEL\" "INTEL.SAV\" "IOBIT\" "KASPERSKY LAB\" "LENOVO\"


[Detected using Heuristic Algorithm] :HKLM DESKTOP=C:\PROGRAMDATA\DESKTOP\
### "DESKTOP.INI" "SAFE MONEY.LNK" "SHAREIT.LNK"
[Detected using Heuristic Algorithm] :HKLM DOCUMENTS=C:\PROGRAMDATA\DOCUMENTS\
### "DESKTOP.INI" "LENOVO\" "MY MUSIC\" "MY PICTURES\" "MY VIDEOS\" "REGRUNIN
FO\"
[Detected using Heuristic Algorithm] :HKLM DOWNLOADED INSTALLATIONS=C:\PROGRAM
DATA\DOWNLOADED INSTALLATIONS\
### "{91317471-D47D-4E3A-B737-78A7E89D2802}\"
[Detected using Heuristic Algorithm] :HKLM INTEL=C:\PROGRAMDATA\INTEL\
### "DAL\" "PACKAGE CACHE\" "WIRELESS\"
[Detected using Heuristic Algorithm] :HKLM INTEL.SAV=C:\PROGRAMDATA\INTEL.SAV\
### "DAL\" "PACKAGE CACHE\"
[Detected using Heuristic Algorithm] :HKLM IOBIT=C:\PROGRAMDATA\IOBIT\
### "INSTALL.INI"
[Detected using Heuristic Algorithm] :HKLM KASPERSKY LAB=C:\PROGRAMDATA\KASPER
SKY LAB\
### "AVP16.0.1\" "SAFEBROWSER\" "UCPSTORAGE\"
[Detected using Heuristic Algorithm] :HKLM LENOVO=C:\PROGRAMDATA\LENOVO\
### "IMCONTROLLER\" "LENOVOAUDIOPLUGIN\" "OKO\" "ONEKEYOPTIMIZER\" "SHAREIT\"
"SYSTEMUPDATEPLUGIN\"
[Detected using Heuristic Algorithm] :HKLM LENOVOTRANSITION=C:\PROGRAMDATA\LEN
OVOTRANSITION\
### "SERVER\" "SETTING.XML" "SOFTLIST.XML"
[Detected using Heuristic Algorithm] :HKLM MALWAREBYTES=C:\PROGRAMDATA\MALWARE
BYTES\
### "MALWAREBYTES ANTI-MALWARE\"
[Detected using Heuristic Algorithm] :HKLM MICROSOFT=C:\PROGRAMDATA\MICROSOFT\
### "CRYPTO\" "DATAMART\" "DEVICE STAGE\" "DEVICESYNC\" "DIAGNOSIS\" "DRM\" "
IDENTITYCRL\" "ILSCACHE\" "MAPDATA\" "MF\" "NETFRAMEWORK\"
[Detected using Heuristic Algorithm] :HKLM MICROSOFT HELP=C:\PROGRAMDATA\MICRO
SOFT HELP\
### "MS.DATABASECOMPARE.16.1033.HXN" "MS.EXCEL.16.1033.HXN" "MS.GRAPH.16.1033
.HXN" "MS.GROOVE.16.1033.HXN" "MS.LYNC.16.1033.HXN" "MS.LYNC_BASIC.16.1033.HXN"
"MS.LYNC_ONLINE.16.1033.HXN" "MS.MSACCESS.16.1033.HXN" "MS.MSOUC.16.1033.HXN" "M
S.MSPUB.16.1033.HXN" "MS.ONENOTE.16.1033.HXN"
[Detected using Heuristic Algorithm] :HKLM MICROSOFT ONEDRIVE=C:\PROGRAMDATA\M
ICROSOFT ONEDRIVE\
### "SETUP\"
[Detected using Heuristic Algorithm] :HKLM NVIDIA=C:\PROGRAMDATA\NVIDIA\
### "NVSTARTED"
[Detected using Heuristic Algorithm] :HKLM NVIDIA CORPORATION=C:\PROGRAMDATA\N
VIDIA CORPORATION\
### "DRS\" "GEFORCE EXPERIENCE\" "NETSERVICE\"
[Detected using Heuristic Algorithm] :HKLM ONEKEY OPTIMIZER=C:\PROGRAMDATA\ONE
KEY OPTIMIZER\
### "DB.INI"
[Detected using Heuristic Algorithm] :HKLM PACKAGE CACHE=C:\PROGRAMDATA\PACKAG
E CACHE\
### "D73CE732C3CF0660C5715A46221C77B09DCA8AB8\" "{050D4FC8-5D48-4B8F-8972-47C
82C46020F}\" "{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}V12.0.21005\" "{4C8B7360-62A
2-4339-B745-41323055D0BB}\" "{5368D82D-CAA5-48CC-9017-5BAAAB87591B}V18.20.0\" "{
929FBD26-9020-399B-9A7A-751D61F0B942}V12.0.21005\" "{A749D8E6-B613-3BE3-8F5F-045
C84EBA29B}V12.0.21005\" "{B685D0AD-42A8-4A39-9BFE-8C063FA9AF29}V10.1.1.8\" "{C6C
FF78A-CCCB-49D5-BE68-AE0EC5F0D48A}\" "{F65DB027-AFF3-4070-886A-0D87064AABB1}\" "
{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}V12.0.21005\"
[Detected using Heuristic Algorithm] :HKLM PRODUCTDATA=C:\PROGRAMDATA\PRODUCTD
ATA\
### "STATCACHE.DB" "UN5STAT.INI"
[Detected using Heuristic Algorithm] :HKLM RAXCO=C:\PROGRAMDATA\RAXCO\

### "PERFECTDISK\"
[Detected using Heuristic Algorithm] :HKLM REGID.1991-06.COM.MICROSOFT=C:\PROG
RAMDATA\REGID.1991-06.COM.MICROSOFT\
### "REGID.1991-06.COM.MICROSOFT MICROSOFT OFFICE PROFESSIONAL PLUS 2016.SWID
TAG" "REGID.1991-06.COM.MICROSOFT_WINDOWS-10-PRO.SWIDTAG"
[Detected using Heuristic Algorithm] :HKLM REGRUN=C:\PROGRAMDATA\REGRUN\
[Detected using Heuristic Algorithm] :HKLM ROAMING=C:\PROGRAMDATA\ROAMING\
### "INTEL\"
[Detected using Heuristic Algorithm] :HKLM START MENU=C:\PROGRAMDATA\START MEN
U\
### "DESKTOP.INI" "PROGRAMS\"
[Detected using Heuristic Algorithm] :HKLM TEMPLATES=C:\PROGRAMDATA\TEMPLATES\
[Detected using Heuristic Algorithm] :HKLM USOPRIVATE=C:\PROGRAMDATA\USOPRIVAT
E\
### "UPDATESTORE\"
[Detected using Heuristic Algorithm] :HKLM USOSHARED=C:\PROGRAMDATA\USOSHARED\
### "LOGS\"
[Detected using Heuristic Algorithm] :HKLM APPDATA=C:\USERS\BAMMI\APPDATA\
### "LOCAL\" "LOCALLOW\" "ROAMING\"
[Detected using Heuristic Algorithm] :HKLM ACTIVESYNC=C:\USERS\BAMMI\APPDATA\L
OCAL\ACTIVESYNC\
[Detected using Heuristic Algorithm] :HKLM APPLICATION DATA=C:\USERS\BAMMI\APP
DATA\LOCAL\APPLICATION DATA\
### "ACTIVESYNC\" "APPLICATION DATA\" "COMMS\" "CRASHDUMPS\" "GOOGLE\" "HISTO
RY\" "ICONCACHE.DB" "LENOVO\" "MICROSOFT\" "MICROSOFT HELP\" "MICROSOFTEDGE\"
[Detected using Heuristic Algorithm] :HKLM COMMS=C:\USERS\BAMMI\APPDATA\LOCAL\
COMMS\
### "TEMP\" "UNISTORE\" "UNISTOREDB\"
[Detected using Heuristic Algorithm] :HKLM CRASHDUMPS=C:\USERS\BAMMI\APPDATA\L
OCAL\CRASHDUMPS\
### "DDPF3.EXE.2704.DMP" "DDPF3.EXE.3412.DMP" "DDPF3.EXE.4132.DMP" "DDPF3.EXE
.5288.DMP" "DDPF3.EXE.6032.DMP" "SHELLEXPERIENCEHOST.EXE.4452.DMP"
[Detected using Heuristic Algorithm] :HKLM GOOGLE=C:\USERS\BAMMI\APPDATA\LOCAL
\GOOGLE\
### "CHROME\" "CHROME CLEANUP TOOL\" "CRASHREPORTS\"
[Detected using Heuristic Algorithm] :HKLM HISTORY=C:\USERS\BAMMI\APPDATA\LOCA
L\HISTORY\
### "DESKTOP.INI" "HISTORY.IE5\" "LOW\"
[Detected using Heuristic Algorithm] :HKLM LENOVO=C:\USERS\BAMMI\APPDATA\LOCAL
\LENOVO\
### "LENOVOAUDIOPLUGIN\" "METRICCOLLECTIONSDK\" "SHAREIT\"
[Detected using Heuristic Algorithm] :HKLM MICROSOFT=C:\USERS\BAMMI\APPDATA\LO
CAL\MICROSOFT\
### "CLR_V4.0\" "CLR_V4.0_32\" "CREDENTIALS\" "FEEDS\" "FEEDS CACHE\" "GAMEDV
R\" "INPUTPERSONALIZATION\" "INSTALLAGENT\" "INTERNET EXPLORER\" "MEDIA PLAYER\"
"OFFICE\"
[Detected using Heuristic Algorithm] :HKLM MICROSOFT HELP=C:\USERS\BAMMI\APPDA
TA\LOCAL\MICROSOFT HELP\
[Detected using Heuristic Algorithm] :HKLM MICROSOFTEDGE=C:\USERS\BAMMI\APPDAT
A\LOCAL\MICROSOFTEDGE\
### "SHAREDCACHECONTAINERS\" "USER\"
[Detected using Heuristic Algorithm] :HKLM NETWORKTILES=C:\USERS\BAMMI\APPDATA
\LOCAL\NETWORKTILES\
[Detected using Heuristic Algorithm] :HKLM NVIDIA=C:\USERS\BAMMI\APPDATA\LOCAL
\NVIDIA\
### "ACCOUNTS" "GFEXPERIENCE.EXE_URL_TGM3MTTMT5ITFLHJ0KYKOI5XKJY53X4G\" "NVBA
CKEND\" "NVGS\" "SHARECONNECT\"
[Detected using Heuristic Algorithm] :HKLM PACKAGES=C:\USERS\BAMMI\APPDATA\LOC
AL\PACKAGES\
### "9E2F88E3.TWITTER_WGEQDKKX372WM\" "E046963F.LENOVOCOMPANION_K1H2YWK1493X8

\" "KING.COM.CANDYCRUSHSODASAGA_KGQVNYMYFVS32\" "LENOVOCORPORATION.LENOVOSETTING


S_4642SHXVSV8S2\" "MICROSOFT.3DBUILDER_8WEKYB3D8BBWE\" "MICROSOFT.AAD.BROKERPLUG
IN_CW5N1H2TXYEWY\" "MICROSOFT.ACCOUNTSCONTROL_CW5N1H2TXYEWY\" "MICROSOFT.ADVERTI
SING.XAML_8WEKYB3D8BBWE\" "MICROSOFT.APPCONNECTOR_8WEKYB3D8BBWE\" "MICROSOFT.AVA
TARS_8WEKYB3D8BBWE\" "MICROSOFT.BINGWEATHER_8WEKYB3D8BBWE\"
[Detected using Heuristic Algorithm] :HKLM PACKAGESTAGING=C:\USERS\BAMMI\APPDA
TA\LOCAL\PACKAGESTAGING\
[Detected using Heuristic Algorithm] :HKLM PEERDISTREPUB=C:\USERS\BAMMI\APPDAT
A\LOCAL\PEERDISTREPUB\
[Detected using Heuristic Algorithm] :HKLM PROGRAMS=C:\USERS\BAMMI\APPDATA\LOC
AL\PROGRAMS\
### "COMMON\"
[Detected using Heuristic Algorithm] :HKLM PUBLISHERS=C:\USERS\BAMMI\APPDATA\L
OCAL\PUBLISHERS\
### "8WEKYB3D8BBWE\"
[Detected using Heuristic Algorithm] :HKLM SHAREIT=C:\USERS\BAMMI\APPDATA\LOCA
L\SHAREIT\
### "SHAREIT\"
[Detected using Heuristic Algorithm] :HKLM TEMP=C:\USERS\BAMMI\APPDATA\LOCAL\T
EMP\
### "904D57F61A9D7FE5185C01B47D54C2FB" "BAMMI.BMP" "BC2B56CE-4762-11E6-BCDC-5
4EE75502D16\" "BDANTIRANSOMWARE_UPDATE\" "CE4CF87733651BF1F44DD1E02FC1A8E8" "CHR
OME_BITS_5060_17396\" "ETILQS_Y2OM8WR16VL0WQG" "GREATISTMP\" "IIF7118.TMP\" "IIF
7203.TMP\" "IIF9C64.TMP\"
[Detected using Heuristic Algorithm] :HKLM TEMPORARY INTERNET FILES=C:\USERS\B
AMMI\APPDATA\LOCAL\TEMPORARY INTERNET FILES\
### "CONTENT.IE5\" "CONTENT.MSO\" "CONTENT.WORD\" "COUNTERS.DAT" "IE\" "LOW\"
"VIRTUALIZED\"
[Detected using Heuristic Algorithm] :HKLM TILEDATALAYER=C:\USERS\BAMMI\APPDAT
A\LOCAL\TILEDATALAYER\
### "DATABASE\"
[Detected using Heuristic Algorithm] :HKLM VIRTUALSTORE=C:\USERS\BAMMI\APPDATA
\LOCAL\VIRTUALSTORE\
[Detected using Heuristic Algorithm] :HKLM IOBIT=C:\USERS\BAMMI\APPDATA\LOCALL
OW\IOBIT\
### "AC.INI" "AUPDATE.INI" "INSTALLINFO.INI"
[Detected using Heuristic Algorithm] :HKLM MICROSOFT=C:\USERS\BAMMI\APPDATA\LO
CALLOW\MICROSOFT\
### "CRYPTNETURLCACHE\"
[Detected using Heuristic Algorithm] :HKLM ADOBE=C:\USERS\BAMMI\APPDATA\ROAMIN
G\ADOBE\
### "FLASH PLAYER\"
[Detected using Heuristic Algorithm] :HKLM INTEL=C:\USERS\BAMMI\APPDATA\ROAMIN
G\INTEL\
### "WIRELESS\"
[Detected using Heuristic Algorithm] :HKLM INTEL CORPORATION=C:\USERS\BAMMI\AP
PDATA\ROAMING\INTEL CORPORATION\
### "IASTORUTIL\"
[Detected using Heuristic Algorithm] :HKLM IOBIT=C:\USERS\BAMMI\APPDATA\ROAMIN
G\IOBIT\
### "ADVANCED SYSTEMCARE\" "IOBIT UNINSTALLER\" "PPMAIN.INI"
[Detected using Heuristic Algorithm] :HKLM LENOVO=C:\USERS\BAMMI\APPDATA\ROAMI
NG\LENOVO\
### "OKO\"
[Detected using Heuristic Algorithm] :HKLM MACROMEDIA=C:\USERS\BAMMI\APPDATA\R
OAMING\MACROMEDIA\
### "FLASH PLAYER\"
[Detected using Heuristic Algorithm] :HKLM MICROSOFT=C:\USERS\BAMMI\APPDATA\RO
AMING\MICROSOFT\
### "ADDINS\" "BIBLIOGRAPHY\" "CREDENTIALS\" "CRYPTO\" "DOCUMENT BUILDING BLO

CKS\" "INPUTMETHOD\" "INTERNET EXPLORER\" "MMC\" "NETWORK\" "OFFICE\" "PROOF\"


[Detected using Heuristic Algorithm] :HKLM PRODUCTDATA=C:\USERS\BAMMI\APPDATA\
ROAMING\PRODUCTDATA\
### "UPDATE.SPT"
[Detected using Heuristic Algorithm] :HKLM APPLICATION DATA=C:\USERS\BAMMI\APP
LICATION DATA\
### "ADOBE\" "INTEL\" "INTEL CORPORATION\" "IOBIT\" "LENOVO\" "MACROMEDIA\" "
MICROSOFT\" "PRODUCTDATA\"
[Detected using Heuristic Algorithm] :HKLM CONTACTS=C:\USERS\BAMMI\CONTACTS\
### "DESKTOP.INI"
[Detected using Heuristic Algorithm] :HKLM COOKIES=C:\USERS\BAMMI\COOKIES\
### "CONTAINER.DAT" "UKJRG8U8.TXT"
[Detected using Heuristic Algorithm] :HKLM DESKTOP=C:\USERS\BAMMI\DESKTOP\
### "DESKTOP.INI" "UNHACKME.LNK"
[Detected using Heuristic Algorithm] :HKLM DOCUMENTS=C:\USERS\BAMMI\DOCUMENTS\
### "DESKTOP.INI" "MY MUSIC\" "MY PICTURES\" "MY VIDEOS\" "REGRUN2\"
[Detected using Heuristic Algorithm] :HKLM DOWNLOADS=C:\USERS\BAMMI\DOWNLOADS\
### "3D-ABSTRACT-WALLPAPER-HD-1920X1081.JPG" "3DABSTRACT-WALLPAPER-HD-1920X12
00.JPG" "413835.JPG" "ABSTRACT-FULL-HD-WALLPAPER.PNG" "ADWARE REMOVAL TOOL BY TS
A.EXE" "BACKGROUND-NOIR-ET-ROUGE-1.JPG" "BDANTIRANSOMWARESETUP.EXE" "BDPUARLAUNC
HER.EXE" "CINEMA_4D__CUBE_ROOM_BY_NECROBYTE1-D6M4DZ2.JPG" "DESKTOP.INI" "IMAGES
(1).JPG"
[Detected using Heuristic Algorithm] :HKLM FAVORITES=C:\USERS\BAMMI\FAVORITES\
### "BING.URL" "DESKTOP.INI" "DOWNLOAD SONY XPERIA ADB & USB DRIVERS AND INST
ALL ON PC - DROIDJAR.URL" "LAPTOPS AND NETBOOKS YOGA SERIES YOGA 500 14IBD - L
ENOVO SUPPORT (US).URL" "LENOVO\" "LINKS\" "LINKS FOR UNITED STATES\" "MICROSOFT
WEBSITES\" "MSN WEBSITES\" "WINDOWS LIVE\"
[Detected using Heuristic Algorithm] :HKLM INTEL=C:\USERS\BAMMI\INTEL\
### "LOGS\"
[Detected using Heuristic Algorithm] :HKLM INTEL.SAV=C:\USERS\BAMMI\INTEL.SAV\
### "LOGS\"
[Detected using Heuristic Algorithm] :HKLM INTELGRAPHICSPROFILES=C:\USERS\BAMM
I\INTELGRAPHICSPROFILES\
### "BRIGHTEN VIDEO.MAN.IGPI" "DARKEN VIDEO.MAN.IGPI" "ENHANCE VIDEO COLORS.M
AN.IGPI"
[Detected using Heuristic Algorithm] :HKLM LINKS=C:\USERS\BAMMI\LINKS\
### "DESKTOP.INI" "DESKTOP.LNK" "DOWNLOADS.LNK"
[Detected using Heuristic Algorithm] :HKLM LOCAL SETTINGS=C:\USERS\BAMMI\LOCAL
SETTINGS\
### "ACTIVESYNC\" "APPLICATION DATA\" "COMMS\" "CRASHDUMPS\" "GOOGLE\" "HISTO
RY\" "ICONCACHE.DB" "LENOVO\" "MICROSOFT\" "MICROSOFT HELP\" "MICROSOFTEDGE\"
[Detected using Heuristic Algorithm] :HKLM MUSIC=C:\USERS\BAMMI\MUSIC\
### "DESKTOP.INI"
[Detected using Heuristic Algorithm] :HKLM MY DOCUMENTS=C:\USERS\BAMMI\MY DOCU
MENTS\
### "DESKTOP.INI" "MY MUSIC\" "MY PICTURES\" "MY VIDEOS\" "REGRUN2\"
[Detected using Heuristic Algorithm] :HKLM NETHOOD=C:\USERS\BAMMI\NETHOOD\
[Detected using Heuristic Algorithm] :HKLM ONEDRIVE=C:\USERS\BAMMI\ONEDRIVE\
### "DESKTOP.INI" "DOCUMENTS\" "GETTING STARTED WITH ONEDRIVE.PDF" "LINKS\" "
MUSIC\" "PICTURES\"
[Detected using Heuristic Algorithm] :HKLM PICTURES=C:\USERS\BAMMI\PICTURES\
### "CAMERA ROLL\" "DESKTOP.INI" "SAVED PICTURES\"
[Detected using Heuristic Algorithm] :HKLM PRINTHOOD=C:\USERS\BAMMI\PRINTHOOD\
[Detected using Heuristic Algorithm] :HKLM RECENT=C:\USERS\BAMMI\RECENT\
### "AUTOMATICDESTINATIONS\" "CUSTOMDESTINATIONS\" "DESKTOP.INI"
[Detected using Heuristic Algorithm] :HKLM ROAMING=C:\USERS\BAMMI\ROAMING\
### "INTEL\"
[Detected using Heuristic Algorithm] :HKLM SAVED GAMES=C:\USERS\BAMMI\SAVED GA
MES\
### "DESKTOP.INI"

[Detected using Heuristic Algorithm] :HKLM SEARCHES=C:\USERS\BAMMI\SEARCHES\


### "DESKTOP.INI" "EVERYWHERE.SEARCH-MS" "INDEXED LOCATIONS.SEARCH-MS" "WINRT
--{S-1-5-21-2529283801-2643127874-3567046402-1001}-.SEARCHCONNECTOR-MS"
[Detected using Heuristic Algorithm] :HKLM SENDTO=C:\USERS\BAMMI\SENDTO\
### "BLUETOOTH FILE TRANSFER.LNK" "COMPRESSED (ZIPPED) FOLDER.ZFSENDTOTARGET"
"DESKTOP (CREATE SHORTCUT).DESKLINK" "DESKTOP.INI" "DOCUMENTS.MYDOCS" "FAX RECI
PIENT.LNK" "MAIL RECIPIENT.MAPIMAIL"
[Detected using Heuristic Algorithm] :HKLM START MENU=C:\USERS\BAMMI\START MEN
U\
### "DESKTOP.INI" "PROGRAMS\"
[Detected using Heuristic Algorithm] :HKLM TEMPLATES=C:\USERS\BAMMI\TEMPLATES\
[Detected using Heuristic Algorithm] :HKLM VIDEOS=C:\USERS\BAMMI\VIDEOS\
### "DESKTOP.INI"
[In memory]
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\WINLOGON.EXE
### Windows Logon Application Microsoft Corporation Microsoft Windows Operating
System 10.0.10586.0 winlogon.exe
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\LSASS.EXE
### Local Security Authority Process Microsoft Corporation Microsoft Windows Ope
rating System 10.0.10586.0 C:\Windows\system32\lsass.exe
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft Windows Op
erating System 10.0.10586.0 C:\Windows\system32\svchost.exe -k DcomLaunch
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft Windows Op
erating System 10.0.10586.0 C:\Windows\system32\svchost.exe -k RPCSS
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\DWM.EXE
### Desktop Window Manager Microsoft Corporation Microsoft Windows Operating Sys
tem 10.0.10586.0 "dwm.exe"
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft Windows Op
erating System 10.0.10586.0 C:\Windows\system32\svchost.exe -k netsvcs
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft Windows Op
erating System 10.0.10586.0 C:\Windows\system32\svchost.exe -k LocalSystemNetwor
kRestricted
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft Windows Op
erating System 10.0.10586.0 C:\Windows\system32\svchost.exe -k LocalServiceAndNo
Impersonation
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft Windows Op
erating System 10.0.10586.0 C:\Windows\system32\svchost.exe -k LocalService
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\NVVSVC.EXE
### NVIDIA Driver Helper Service, Version 368.69 NVIDIA Corporation NVIDIA Dri
ver Helper Service, Version 368.69 8.17.13.6869 "C:\Windows\system32\nvvsvc.exe"
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft Windows Op
erating System 10.0.10586.0 C:\Windows\System32\svchost.exe -k LocalServiceNetwo
rkRestricted
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\IGFXCUISERVICE.EXE
### igfxCUIService Module Intel Corporation Intel(R) Common User Interface 6.1
5.10.4248 C:\Windows\system32\igfxCUIService.exe
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft Windows Op
erating System 10.0.10586.0 C:\Windows\system32\svchost.exe -k LocalServiceNoNet
work
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft Windows Op
erating System 10.0.10586.0 C:\Windows\system32\svchost.exe -k NetworkService

[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\WUDFHOST.EXE


### Windows Driver Foundation - User-mode Driver Framework Host Process Micros
oft Corporation Microsoft Windows Operating System 10.0.10586.0 "C:\Windows\System
32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortNa
me:HostProcess-cd205dbd-ca76-4f94-b770-1cd005c624bc -SystemEventPortName:HostPro
cess-72dc2000-9ee4-4c30-ac77-4f1112060814 -IoCancelEventPortName:HostProcess-66f
fa3c1-68d0-4106-85ab-209457c6984c -NonStateChangingEventPortName:HostProcess-e0d
45d9e-747d-4429-9271-afdcbbdb1e02 -ServiceSID:S-1-5-80-2652678385-582572993-1835
434367-1344795993-749280709 -LifetimeId:6a1914d7-b2b0-4805-9e61-c68341ce8c95 -De
viceGroupId:WudfDefaultDevicePool
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SPOOLSV.EXE
### Spooler SubSystem App Microsoft Corporation Microsoft Windows Operating Syst
em 10.0.10586.0 C:\Windows\System32\spoolsv.exe
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\WUDFHOST.EXE
### Windows Driver Foundation - User-mode Driver Framework Host Process Micros
oft Corporation Microsoft Windows Operating System 10.0.10586.0 "C:\Windows\System
32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortNa
me:HostProcess-fdd94cc0-cbaf-4387-8539-46be8f5ec3dc -SystemEventPortName:HostPro
cess-0f50c93b-f464-4ac0-98a8-9136afb84741 -IoCancelEventPortName:HostProcess-4b7
ecb14-b918-4731-9f62-1c837be260bb -NonStateChangingEventPortName:HostProcess-ed7
25210-c551-4e11-b0fd-3ca2c062472c -ServiceSID:S-1-5-80-2652678385-582572993-1835
434367-1344795993-749280709 -LifetimeId:b6c78ca2-0913-4915-bd1e-6fae47f13587 -De
viceGroupId:
[Running Processes] :HKLM C:\WINDOWS\SYSWOW64\INTELCPHECISVC.EXE
### IntelCpHeciSvc Executable Intel Corporation IntelCpHeciSvc Executable 9.0.
31.9000 C:\Windows\SysWow64\IntelCpHeciSvc.exe
[Running Processes] :HKLM C:\PROGRAM FILES\INTEL\WIFI\BIN\EVTENG.EXE
### Intel(R) PROSet/Wireless Event Log Service Intel(R) Corporation Intel(R) P
ROSet/Wireless 18, 20, 0, 0 "C:\Program Files\Intel\WiFi\bin\EvtEng.exe"
[Running Processes] :HKLM C:\PROGRAM FILES (X86)\LENOVO\HARMONY\SETTING\HARMON
YSETTINGSERVICE.EXE
### HarmonySettingService Lenovo HarmonySettingService 1.1.0.209 "C:\Program F
iles (x86)\Lenovo\Harmony\Setting\HarmonySettingService.exe"
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft Windows Op
erating System 10.0.10586.0 C:\Windows\System32\svchost.exe -k utcsvc
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft Windows Op
erating System 10.0.10586.0 C:\Windows\system32\svchost.exe -k appmodel
[Running Processes] :HKLM C:\PROGRAM FILES\LENOVO\IMCONTROLLER\SERVICE\LENOVO.
MODERN.IMCONTROLLER.EXE
### Lenovo.Modern.ImController Lenovo Group Limited Lenovo.Modern.ImController
1.0.0077.01 "C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImContr
oller.exe"
[Running Processes] :HKLM C:\PROGRAM FILES (X86)\INTEL\BLUETOOTH\UTILITIES\IBT
SIVA.EXE
### Intel(R) Wireless Bluetooth(R) iBtSiva Service Intel Corporation Intel(R)
Wireless Bluetooth(R) 17.1.1524.1353 "C:\Program Files (x86)\Intel\Bluetooth\uti
lities\ibtsiva.exe"
[Running Processes] :HKLM C:\PROGRAM FILES\LENOVO\ONEKEY OPTIMIZER\BIN\OKOCONT
ROLSVC.EXE
### OneKey Optimizer contains an important core service. If disabled, you will
not able to use the Lenovo-provided update service. Lenovo(beijing) Limited One
Key Optimizer 1.3.0.7 "C:\Program Files\Lenovo\OneKey Optimizer\bin\OKOControlSv
c.exe"
[Running Processes] :HKLM C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPENHSERVICE.EXE
### 64-bit Synaptics Pointing Enhance Service Synaptics Incorporated Synaptics
Pointing Device Driver 19.0.18 23Jul15 "C:\Program Files\Synaptics\SynTP\SynTPE
nhService.exe"
[Running Processes] :HKLM C:\PROGRAM FILES (X86)\NVIDIA CORPORATION\NETSERVICE

\NVNETWORKSERVICE.EXE
### NVIDIA Network Service NVIDIA Corporation NVIDIA Network Service 2.4.13.69
"C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe"
[Running Processes] :HKLM C:\PROGRAM FILES (X86)\IOBIT\LIVEUPDATE\LIVEUPDATE.E
XE
### Product Updater IObit Product Updater 2.0.0.0 "C:\Program Files (x86)\IObi
t\LiveUpdate\LiveUpdate.exe"
[Running Processes] :HKLM C:\PROGRAMDATA\LENOVOTRANSITION\SERVER\X64\YMC.EXE
### Lenovo Yoga Mode Control Lenovo Lenovo Yoga Mode Control 1.0.0.0 C:\Progra
mData\LenovoTransition\Server\x64\ymc.exe
[Running Processes] :HKLM C:\PROGRAM FILES\LENOVO\ONEKEY OPTIMIZER\BIN\FBSERVI
CE.EXE
### Lenovo RapidBoot HDD Accelerator Service Lenovo RapidBoot HDD Accelerator
3,0,0,21 "C:\Program Files\Lenovo\OneKey Optimizer\bin\FbService.exe"
[Running Processes] :HKLM C:\PROGRAM FILES\COMMON FILES\INTEL\WIRELESSCOMMON\R
EGSRVC.EXE
### Intel(R) PROSet/Wireless Registry Service Intel(R) Corporation Intel(R) PR
OSet/Wireless 18, 20, 0, 0 "C:\Program Files\Common Files\Intel\WirelessCommon\R
egSrvc.exe"
[Running Processes] :HKLM C:\PROGRAM FILES\COMMON FILES\RAXCO\SHARED\PDENGINE.
EXE
### PDEngine Module Raxco Software, Inc. PerfectDisk 14.0.890.0 "C:\Program Fi
les\Common Files\Raxco\Shared\PDEngine.exe"
[Running Processes] :HKLM C:\PROGRAM FILES\NVIDIA CORPORATION\GEFORCE EXPERIEN
CE SERVICE\GFEXPERIENCESERVICE.EXE
### NVIDIA GeForce ExperienceService NVIDIA Corporation NVIDIA GeForce Experie
nceService 2.11.4.0 "C:\Program Files\NVIDIA Corporation\GeForce Experience Serv
ice\GfExperienceService.exe"
[Running Processes] :HKLM C:\PROGRAM FILES\INTEL\WIFI\BIN\ZEROCONFIGSERVICE.EX
E
### Intel PROSet/Wireless Zero Configure Service Intel Corporation Intel(R) PROS
et/Wireless 18, 20, 0, 0 "C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe"
[Running Processes] :HKLM C:\PROGRAM FILES (X86)\KASPERSKY LAB\KASPERSKY INTER
NET SECURITY 16.0.1\AVP.EXE
### Kaspersky Anti-Virus AO Kaspersky Lab Kaspersky Anti-Virus 16.0.1.445 "C:\
Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.1\avp.exe" -r
[Running Processes] :HKLM C:\PROGRAM FILES\LENOVO\ONEKEY OPTIMIZER\BIN\OKOUPDA
TASERVICE.EXE
### OneKey Optimizer Self Update Install Service Lenovo(beijing) Limited OneKe
yOptimizer 1.2.24.6 "C:\Program Files\Lenovo\OneKey Optimizer\bin\OKOUpdataServi
ce.exe"
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\WLANEXT.EXE
### Windows Wireless LAN 802.11 Extensibility Framework Microsoft Corporation
Microsoft Windows Operating System 10.0.10586.0 C:\Windows\system32\WLANExt.exe 13
91337572128
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\CONHOST.EXE
### Console Window Host Microsoft Corporation Microsoft Windows Operating System
10.0.10586.0 \??\C:\Windows\system32\conhost.exe 0x4
[Running Processes] :HKLM C:\PROGRAM FILES\NVIDIA CORPORATION\DISPLAY\NVXDSYNC
.EXE
### NVIDIA User Experience Driver Component NVIDIA Corporation NVIDIA User Exp
erience Driver Component 8.17.13.6869 C:\Program Files\NVIDIA Corporation\Displa
y\nvxdsync.exe
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\WBEM\UNSECAPP.EXE
### Sink to receive asynchronous callbacks for WMI client application Microsof
t Corporation Microsoft Windows Operating System 10.0.10586.0 C:\Windows\system32\
wbem\unsecapp.exe -Embedding
[Running Processes] :HKLM C:\PROGRAM FILES\RAXCO\PERFECTDISK\PDAGENT.EXE
### PDAgent Module Raxco Software, Inc. PerfectDisk 14.0.890.0 "C:\Program Fil
es\Raxco\PerfectDisk\PDAgent.exe"

[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\WBEM\WMIPRVSE.EXE


### WMI Provider Host Microsoft Corporation Microsoft Windows Operating System 1
0.0.10586.0 C:\Windows\system32\wbem\wmiprvse.exe
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\WBEM\WMIPRVSE.EXE
### WMI Provider Host Microsoft Corporation Microsoft Windows Operating System 1
0.0.10586.0 C:\Windows\system32\wbem\wmiprvse.exe
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\DASHOST.EXE
### Device Association Framework Provider Host Microsoft Corporation Microsoft
Windows Operating System 10.0.10586.0 dashost.exe {168de2f6-3b4b-4df9-92454e11068
19c2f}
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft Windows Op
erating System 10.0.10586.0 C:\Windows\System32\svchost.exe -k LocalServicePeerN
et
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SIHOST.EXE
### Shell Infrastructure Host Microsoft Corporation Microsoft Windows Operating
System 10.0.10586.0 sihost.exe
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\TASKHOSTW.EXE
### Host Process for Windows Tasks Microsoft Corporation Microsoft Windows Opera
ting System 10.0.10586.0 taskhostw.exe {222A245B-E637-4AE9-A93F-A59CA119A75E}
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\IGFXEM.EXE
### igfxEM Module Intel Corporation Intel(R) Common User Interface 6.15.10.424
8 igfxEM.exe
[Running Processes] :HKLM C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPENH.EXE
### Synaptics TouchPad 64-bit Enhancements Synaptics Incorporated Synaptics Po
inting Device Driver 19.0.18 23Jul15 "C:\Program Files\Synaptics\SynTP\SynTPEnh.
exe"
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\IGFXHK.EXE
### igfxHK Module Intel Corporation Intel(R) Common User Interface 6.15.10.424
8 igfxHK.exe
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\IGFXTRAY.EXE
### igfxTray.exe
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\RUNTIMEBROKER.EXE
### Runtime Broker Microsoft Corporation Microsoft Windows Operating System 10.0
.10586.0 C:\Windows\System32\RuntimeBroker.exe -Embedding
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\DLLHOST.EXE
### COM Surrogate Microsoft Corporation Microsoft Windows Operating System 10.0.
10586.0 C:\Windows\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9D
DD652EB7}
[Running Processes] :HKLM C:\WINDOWS\EXPLORER.EXE
### Windows Explorer Microsoft Corporation Microsoft Windows Operating System 10
.0.10586.0 C:\Windows\Explorer.EXE
[Running Processes] :HKLM C:\PROGRAM FILES\RAXCO\PERFECTDISK\PDAGENTS1.EXE
### PDAgentS1 Module Raxco Software, Inc. PerfectDisk 14.0.890.0 "C:\Program F
iles\Raxco\PerfectDisk\PDAgentS1.exe"
[Running Processes] :HKLM C:\PROGRAM FILES\WINDOWSAPPS\MICROSOFT.MESSAGING_2.1
5.20002.0_X86__8WEKYB3D8BBWE\SKYPEHOST.EXE
### "C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb
3d8bbwe\SkypeHost.exe" -ServerName:SkypeHost.ServerServer
[Running Processes] :HKLM C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE
### Synaptics Pointing Device Helper Synaptics Incorporated Synaptics Pointing
Device Driver 19.0.18 23Jul15 "C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE
"
[Running Processes] :HKLM C:\PROGRAM FILES (X86)\KASPERSKY LAB\KASPERSKY INTER
NET SECURITY 16.0.1\AVPUI.EXE
### Kaspersky Anti-Virus AO Kaspersky Lab Kaspersky Anti-Virus 16.0.1.445 "C:\
Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.1\avpui.exe"
-hidden
[Running Processes] :HKLM C:\WINDOWS\SYSTEMAPPS\SHELLEXPERIENCEHOST_CW5N1H2TXY
EWY\SHELLEXPERIENCEHOST.EXE

### Windows Shell Experience Host Microsoft Corporation Microsoft Windows Operat
ing System 10.0.10586.306 "C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txye
wy\ShellExperienceHost.exe" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t
.mca
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SEARCHINDEXER.EXE
### Microsoft Windows Search Indexer Microsoft Corporation Windows Search 7.00.
10586.0 C:\Windows\system32\SearchIndexer.exe /Embedding
[Running Processes] :HKLM C:\PROGRAM FILES (X86)\LENOVO\IMCONTROLLER\PLUGINHOS
T\LENOVO.MODERN.IMCONTROLLER.PLUGINHOST.EXE
### Lenovo.Modern.ImController.PluginHost Lenovo Group Limited Lenovo.Modern.I
mController.PluginHost 1.0.0077.01 -name faf0ff32-3fb6-4733-82cc-945e3396db92 -r
unas -pluginName LenovoAudioPlugin -pluginVersion 1.2.103.0
[Running Processes] :HKLM C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\INK\T
ABTIP.EXE
### Touch Keyboard and Handwriting Panel Microsoft Corporation Microsoft Window
s Operating System 10.0.10586.0 /QuitInfo:0000000000000F60;0000000000000F08;
[Running Processes] :HKLM C:\PROGRAM FILES (X86)\COMMON FILES\MICROSOFT SHARED
\INK\TABTIP32.EXE
### Touch Keyboard and Handwriting Panel Helper Microsoft Corporation Microsof
t Windows Operating System 10.0.10586.0 /loadhooks /Parent:00000000000013e8
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SETTINGSYNCHOST.EXE
### Host Process for Setting Synchronization Microsoft Corporation Microsoft Wi
ndows Operating System 10.0.10586.306 C:\Windows\system32\SettingSyncHost.exe -Em
bedding
[Running Processes] :HKLM C:\PROGRAM FILES\REALTEK\AUDIO\HDA\RAVBG64.EXE
### HD Audio Background Process Realtek Semiconductor HD Audio Background Proc
ess 1, 0, 0, 225 "C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /FORPCEE4
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft Windows Op
erating System 10.0.10586.0 C:\Windows\system32\svchost.exe -k NetworkServiceNet
workRestricted
[Running Processes] :HKLM C:\PROGRAM FILES (X86)\LENOVO\IMCONTROLLER\PLUGINHOS
T\LENOVO.MODERN.IMCONTROLLER.PLUGINHOST.EXE
### Lenovo.Modern.ImController.PluginHost Lenovo Group Limited Lenovo.Modern.I
mController.PluginHost 1.0.0077.01 -name 077aec0d-a4c1-4e58-bba7-11541744b0e7 -r
unas -pluginName LenovoCameraPlugin -pluginVersion 1.2.104.0
[Running Processes] :HKLM C:\PROGRAM FILES\REALTEK\AUDIO\HDA\RAVBG64.EXE
### HD Audio Background Process Realtek Semiconductor HD Audio Background Proc
ess 1, 0, 0, 225 "C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /LENOVO_DOLBYD
RAGON
[Running Processes] :HKLM C:\PROGRAM FILES\REALTEK\AUDIO\HDA\RAVBG64.EXE
### HD Audio Background Process Realtek Semiconductor HD Audio Background Proc
ess 1, 0, 0, 225 "C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /LENOVO_MICPKE
Y
[Running Processes] :HKLM C:\PROGRAM FILES\DOLBY\DDP_F3\DDPF3.EXE
### DolbyDigitalPlus Dolby Laboratories Inc. DolbyDigitalPlus 7.6.7.1 "C:\Prog
ram Files\Dolby\DDP_F3\ddpf3.exe" -S
[Running Processes] :HKLM C:\PROGRAM FILES\LENOVO\ONEKEY OPTIMIZER\BIN\ONEKEYO
PTIMIZERTRAY.EXE
### OneKey Optimizer is Lenovo's unique power management and optimization app
Lenovo(beijing) Limited OneKeyOptimizer 1.3.0.5 "C:\Program Files\Lenovo\OneKey
Optimizer\bin\OneKeyOptimizerTray.exe" /run
[Running Processes] :HKLM C:\PROGRAM FILES (X86)\LENOVO\LENOVOTRANSITION\TRANS
ITIONSERVER.EXE
### "C:\Program Files (x86)\Lenovo\LenovoTransition\TransitionServer.exe"
[Running Processes] :HKLM C:\PROGRAM FILES (X86)\IOBIT\IOBIT UNINSTALLER\UNINS
TALLMONITOR.EXE
### IObit Uninstaller 5 UninstallMontior IObit UninstallMonitor 5.2.0.0 "C:\Pr
ogram Files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe"
[Running Processes] :HKLM C:\PROGRAM FILES\LENOVO\ONEKEY OPTIMIZER\BIN\ONEKEYO

PTIMIZERUPDATA.EXE
### OneKey Optimizer download engine. Lenovo(beijing) Limited OneKeyOptimizerU
pdate 1.3.0.3 "C:\Program Files\Lenovo\OneKey Optimizer\bin\OnekeyOptimizerUpdat
a.exe"
[Running Processes] :HKLM C:\PROGRAM FILES (X86)\LENOVO\HARMONY\PICKS\LENOVO.H
ARMONYPICKS.EXE
### Lenovo.HarmonyPicks Lenovo Lenovo.HarmonyPicks 1.0.1.228 "C:\Program Files
(x86)\Lenovo\Harmony\Picks\Lenovo.HarmonyPicks.exe" s
[Running Processes] :HKLM C:\PROGRAM FILES (X86)\LENOVO\HARMONY\SETTING\LENOVO
.HARMONYSETTING.EXE
### Lenovo.HarmonySetting Lenovo Lenovo.HarmonySetting 1.0.1.303 "C:\Program F
iles (x86)\Lenovo\Harmony\Setting\Lenovo.HarmonySetting.exe" s
[Running Processes] :HKLM C:\PROGRAM FILES (X86)\LENOVO\CCSDK\CCSDK.EXE
### CCSDK Lenovo CCSDK 1.3.0.3 "C:\Program Files (x86)\Lenovo\CCSDK\CCSDK.exe"
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft Windows Op
erating System 10.0.10586.0 C:\Windows\system32\svchost.exe -k UnistackSvcGroup
[Running Processes] :HKLM C:\PROGRAM FILES\INTEL\INTEL(R) RAPID STORAGE TECHNO
LOGY\IASTORICON.EXE
### IAStorIcon Intel Corporation IAStorIcon 14.6.0.1029 "C:\Program Files\Inte
l\Intel(R) Rapid Storage Technology\IAStorIcon.exe"
[Running Processes] :HKLM C:\PROGRAM FILES\INTEL\INTEL(R) RAPID STORAGE TECHNO
LOGY\IASTORDATAMGRSVC.EXE
### IAStorDataSvc Intel Corporation IAStorDataSvc 14.6.0.1029 "C:\Program File
s\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
[Running Processes] :HKLM C:\PROGRAM FILES (X86)\INTEL\INTEL(R) MANAGEMENT ENG
INE COMPONENTS\DAL\JHI_SERVICE.EXE
### Intel(R) Dynamic Application Loader Host Interface Intel Corporation Intel
(R) Dynamic Application Loader Host Interface 11.0.0.1158 "C:\Program Files (x86
)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
[Running Processes] :HKLM C:\PROGRAM FILES (X86)\INTEL\INTEL(R) MANAGEMENT ENG
INE COMPONENTS\LMS\LMS.EXE
### Intel(R) Local Management Service Intel Corporation Intel(R) Management an
d Security Application Local Management Service 11.0.0.1158 "C:\Program Files (x
86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
[Running Processes] :HKLM C:\PROGRAM FILES\LENOVO\ONEKEY OPTIMIZER\BIN\ONEKEYO
PTIMIZER.EXE
### OneKey Optimizer is Lenovo's unique power management and optimization app
Lenovo(beijing) Limited OneKeyOptimizer 1.3.0.6 "C:\Program Files\Lenovo\OneKey
Optimizer\bin\OneKeyOptimizer.exe" /hide
[Running Processes] :HKLM C:\PROGRAM FILES\WINDOWS MEDIA PLAYER\WMPNETWK.EXE
### Windows Media Player Network Sharing Service Microsoft Corporation Microso
ft Windows Operating System 12.0.10586.0 "C:\Program Files\Windows Media Player\wm
pnetwk.exe"
[Running Processes] :HKLM C:\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLICATION\CHR
OME.EXE
### Google Chrome Google Inc. Google Chrome 51.0.2704.106 "C:\Program Files (x
86)\Google\Chrome\Application\chrome.exe"
[Running Processes] :HKLM C:\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLICATION\CHR
OME.EXE
### Google Chrome Google Inc. Google Chrome 51.0.2704.106 "C:\Program Files (x
86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler /prefetch:7 -no-rate-limit "--database=C:\Users\bammi\AppData\Local\Google\Chrome\User Data\C
rashpad" --url=https://clients2.google.com/cr/report --annotation=channel=m --an
notation=plat=Win64 --annotation=prod=Chrome --annotation=ver=51.0.2704.106 --ha
ndshake-handle=0x174
[Running Processes] :HKLM C:\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLICATION\CHR
OME.EXE
### Google Chrome Google Inc. Google Chrome 51.0.2704.106 "C:\Program Files (x
86)\Google\Chrome\Application\chrome.exe" --enable-features=AutomaticTabDiscardi

ng<AutomaticTabDiscarding,IncidentReportingModuleLoadAnalysis<SafeBrowsingIncide
ntReportingServiceFeatures,IncidentReportingSuspiciousModuleReporting<SafeBrowsi
ngIncidentReportingServiceFeatures,UsePasswordSeparatedSigninFlow<PasswordSepara
tedSigninFlow,WebFontsIntervention<WebFontsIntervention,*WebRTC-EnableWebRtcEcds
a<WebRTC-EnableWebRtcEcdsa,brotli-encoding<BrotliEncoding --disable-features=Doc
umentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,RenderingPipeli
neThrottling<RenderingPipelineThrottling,UpdateRendererPriorityOnStartup<UpdateR
endererPriorityOnStartup --force-fieldtrials=AppBannerTriggering/Aggressive/Auto
fillProfileOrderByFrecency/Enabled/AutomaticTabDiscarding/Enabled_Once_10-gen2/*
BrotliEncoding/Enabled/CaptivePortalInterstitial/Enabled/ChildAccountDetection/D
isabled/ClientSideDetectionModel/Model0/*DefaultBrowserInfobar/Default/DirectWri
teFontProxy/UseDirectWriteFontProxy/DisallowFetchForDocWrittenScriptsInMainFrame
/Default/EnableMediaRouter/Disabled/ExtensionActionRedesign/Enabled/ExtensionDev
eloperModeWarning/Enabled/*GFE/Default/GoogleBrandedContextMenu/default/Instance
ID/Enabled/MaterialDesignDownloads/Enabled/*NetworkQualityEstimator/Enabled/Omni
boxBundledExperimentV1/PP_Ethersuggest_A7_Stable_R8/OutOfProcessPac/Default/Pass
wordBranding/Disabled/*PasswordGeneration/Disabled/PasswordManagerSettingsMigrat
ion/Disable/PasswordSeparatedSigninFlow/Enabled/*QUIC/EnabledNoId/RenderingPipel
ineThrottling/Disabled/ReportCertificateErrors/ShowAndPossiblySend/ResourcePrior
ities/Control25PermanentB/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016
/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/SSLCommonNameMis
matchHandling/Control/SafeBrowsingIncidentReportingService/Default/SafeBrowsingI
ncidentReportingServiceFeatures/WithSuspiciousModuleReporting/SafeBrowsingUnveri
fiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingUpdateFrequency/Default
/SyncHttpContentCompression/Enabled/TriggeredResetFieldTrial/On/*UMA-Dynamic-Uni
formity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Per
cent/group_46/*UMA-Uniformity-Trial-10-Percent/group_05/*UMA-Uniformity-Trial-10
0-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_04/*UMA-Uniformity-Tri
al-5-Percent/group_04/*UMA-Uniformity-Trial-50-Percent/group_01/WebFontsInterven
tion/Enabled/WebRTC-EnableWebRtcEcdsa/Default/ --type=gpu-process --channel="953
6.0.1285031082\2104940948" --supports-dual-gpus=false --gpu-driver-bug-workaroun
ds=4,13,25,46,54 --gpu-vendor-id=0x8086 --gpu-device-id=0x1616 --gpu-driver-vend
or="Intel Corporation" --gpu-driver-version=10.18.15.4248 --mojo-platform-channe
l-handle=1236 --ignored=" --type=renderer " /prefetch:2
[Running Processes] :HKLM C:\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLICATION\CHR
OME.EXE
### Google Chrome Google Inc. Google Chrome 51.0.2704.106 "C:\Program Files (x
86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=Auto
maticTabDiscarding<AutomaticTabDiscarding,IncidentReportingModuleLoadAnalysis<Sa
feBrowsingIncidentReportingServiceFeatures,IncidentReportingSuspiciousModuleRepo
rting<SafeBrowsingIncidentReportingServiceFeatures,UsePasswordSeparatedSigninFlo
w<PasswordSeparatedSigninFlow,WebFontsIntervention<WebFontsIntervention,*WebRTCEnableWebRtcEcdsa<WebRTC-EnableWebRtcEcdsa,brotli-encoding<BrotliEncoding --disa
ble-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame
,RenderingPipelineThrottling<RenderingPipelineThrottling,UpdateRendererPriorityO
nStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=AppBannerTriggering
/Aggressive/AutofillProfileOrderByFrecency/Enabled/*AutomaticTabDiscarding/Enabl
ed_Once_10-gen2/*BrotliEncoding/Enabled/CaptivePortalInterstitial/Enabled/ChildA
ccountDetection/Disabled/*ClientSideDetectionModel/Model0/*DefaultBrowserInfobar
/Default/DirectWriteFontProxy/UseDirectWriteFontProxy/*DisallowFetchForDocWritte
nScriptsInMainFrame/Default/*EnableMediaRouter/Disabled/*ExtensionActionRedesign
/Enabled/ExtensionDeveloperModeWarning/Enabled/*GFE/Default/GoogleBrandedContext
Menu/default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/*NetworkQualityE
stimator/Enabled/*OmniboxBundledExperimentV1/PP_Ethersuggest_A7_Stable_R8/*OutOf
ProcessPac/Default/PasswordBranding/Disabled/*PasswordGeneration/Disabled/*Passw
ordManagerSettingsMigration/Disable/PasswordSeparatedSigninFlow/Enabled/*QUIC/En
abledNoId/RenderingPipelineThrottling/Disabled/ReportCertificateErrors/ShowAndPo
ssiblySend/*ResourcePriorities/Control25PermanentB/SHA1IdentityUIWarning/Enabled
/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptField
Trial/On/SSLCommonNameMismatchHandling/Control/*SafeBrowsingIncidentReportingSer

vice/Default/*SafeBrowsingIncidentReportingServiceFeatures/WithSuspiciousModuleR
eporting/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrow
singUpdateFrequency/Default/SyncHttpContentCompression/Enabled/*TriggeredResetFi
eldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal
/*UMA-Uniformity-Trial-1-Percent/group_46/*UMA-Uniformity-Trial-10-Percent/group
_05/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/
group_04/*UMA-Uniformity-Trial-5-Percent/group_04/*UMA-Uniformity-Trial-50-Perce
nt/group_01/WebFontsIntervention/Enabled/WebRTC-EnableWebRtcEcdsa/Default/ --pri
mordial-pipe-token=C906EFD60EC5038C0B94B50F0D44A67B --lang=en-US --extension-pro
cess --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offl
ine-auto-reload-visible-only --enable-pinch --device-scale-factor=1.5 --num-rast
er-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3
553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,35
53,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --channel="9536.2.995323958
\1679841227" --mojo-platform-channel-handle=2456 /prefetch:1
[Running Processes] :HKLM C:\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLICATION\CHR
OME.EXE
### Google Chrome Google Inc. Google Chrome 51.0.2704.106 "C:\Program Files (x
86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=Auto
maticTabDiscarding<AutomaticTabDiscarding,IncidentReportingModuleLoadAnalysis<Sa
feBrowsingIncidentReportingServiceFeatures,IncidentReportingSuspiciousModuleRepo
rting<SafeBrowsingIncidentReportingServiceFeatures,UsePasswordSeparatedSigninFlo
w<PasswordSeparatedSigninFlow,WebFontsIntervention<WebFontsIntervention,*WebRTCEnableWebRtcEcdsa<WebRTC-EnableWebRtcEcdsa,brotli-encoding<BrotliEncoding --disa
ble-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame
,RenderingPipelineThrottling<RenderingPipelineThrottling,UpdateRendererPriorityO
nStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=AppBannerTriggering
/Aggressive/AutofillProfileOrderByFrecency/Enabled/*AutomaticTabDiscarding/Enabl
ed_Once_10-gen2/*BrotliEncoding/Enabled/CaptivePortalInterstitial/Enabled/ChildA
ccountDetection/Disabled/*ClientSideDetectionModel/Model0/*DefaultBrowserInfobar
/Default/DirectWriteFontProxy/UseDirectWriteFontProxy/*DisallowFetchForDocWritte
nScriptsInMainFrame/Default/*EnableMediaRouter/Disabled/*ExtensionActionRedesign
/Enabled/ExtensionDeveloperModeWarning/Enabled/*GFE/Default/GoogleBrandedContext
Menu/default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/*NetworkQualityE
stimator/Enabled/*OmniboxBundledExperimentV1/PP_Ethersuggest_A7_Stable_R8/*OutOf
ProcessPac/Default/PasswordBranding/Disabled/*PasswordGeneration/Disabled/*Passw
ordManagerSettingsMigration/Disable/PasswordSeparatedSigninFlow/Enabled/*QUIC/En
abledNoId/*RenderingPipelineThrottling/Disabled/ReportCertificateErrors/ShowAndP
ossiblySend/*ResourcePriorities/Control25PermanentB/SHA1IdentityUIWarning/Enable
d/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFiel
dTrial/On/SSLCommonNameMismatchHandling/Control/*SafeBrowsingIncidentReportingSe
rvice/Default/*SafeBrowsingIncidentReportingServiceFeatures/WithSuspiciousModule
Reporting/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBro
wsingUpdateFrequency/Default/SyncHttpContentCompression/Enabled/*TriggeredResetF
ieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/norma
l/*UMA-Uniformity-Trial-1-Percent/group_46/*UMA-Uniformity-Trial-10-Percent/grou
p_05/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent
/group_04/*UMA-Uniformity-Trial-5-Percent/group_04/*UMA-Uniformity-Trial-50-Perc
ent/group_01/*WebFontsIntervention/Enabled/WebRTC-EnableWebRtcEcdsa/Default/ --p
rimordial-pipe-token=ACF6197399EF84500BDD3A93E63A2427 --lang=en-US --instant-pro
cess --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --en
able-pinch --device-scale-factor=1.5 --num-raster-threads=2 --content-image-text
ure-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553
--video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,
3553,3553,3553,3553 --channel="9536.13.1622909559\2140907510" --mojo-platform-ch
annel-handle=4256 /prefetch:1
[Running Processes] :HKLM C:\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLICATION\CHR
OME.EXE
### Google Chrome Google Inc. Google Chrome 51.0.2704.106 "C:\Program Files (x
86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=Auto

maticTabDiscarding<AutomaticTabDiscarding,IncidentReportingModuleLoadAnalysis<Sa
feBrowsingIncidentReportingServiceFeatures,IncidentReportingSuspiciousModuleRepo
rting<SafeBrowsingIncidentReportingServiceFeatures,UsePasswordSeparatedSigninFlo
w<PasswordSeparatedSigninFlow,WebFontsIntervention<WebFontsIntervention,*WebRTCEnableWebRtcEcdsa<WebRTC-EnableWebRtcEcdsa,brotli-encoding<BrotliEncoding --disa
ble-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame
,RenderingPipelineThrottling<RenderingPipelineThrottling,UpdateRendererPriorityO
nStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=AppBannerTriggering
/Aggressive/AutofillProfileOrderByFrecency/Enabled/*AutomaticTabDiscarding/Enabl
ed_Once_10-gen2/*BrotliEncoding/Enabled/CaptivePortalInterstitial/Enabled/ChildA
ccountDetection/Disabled/*ClientSideDetectionModel/Model0/*DefaultBrowserInfobar
/Default/DirectWriteFontProxy/UseDirectWriteFontProxy/*DisallowFetchForDocWritte
nScriptsInMainFrame/Default/*EnableMediaRouter/Disabled/*ExtensionActionRedesign
/Enabled/ExtensionDeveloperModeWarning/Enabled/*GFE/Default/GoogleBrandedContext
Menu/default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/*NetworkQualityE
stimator/Enabled/*OmniboxBundledExperimentV1/PP_Ethersuggest_A7_Stable_R8/*OutOf
ProcessPac/Default/PasswordBranding/Disabled/*PasswordGeneration/Disabled/*Passw
ordManagerSettingsMigration/Disable/PasswordSeparatedSigninFlow/Enabled/*QUIC/En
abledNoId/*RenderingPipelineThrottling/Disabled/ReportCertificateErrors/ShowAndP
ossiblySend/*ResourcePriorities/Control25PermanentB/SHA1IdentityUIWarning/Enable
d/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFiel
dTrial/On/SSLCommonNameMismatchHandling/Control/*SafeBrowsingIncidentReportingSe
rvice/Default/*SafeBrowsingIncidentReportingServiceFeatures/WithSuspiciousModule
Reporting/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBro
wsingUpdateFrequency/Default/SyncHttpContentCompression/Enabled/*TriggeredResetF
ieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/norma
l/*UMA-Uniformity-Trial-1-Percent/group_46/*UMA-Uniformity-Trial-10-Percent/grou
p_05/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent
/group_04/*UMA-Uniformity-Trial-5-Percent/group_04/*UMA-Uniformity-Trial-50-Perc
ent/group_01/*WebFontsIntervention/Enabled/WebRTC-EnableWebRtcEcdsa/Default/ --p
rimordial-pipe-token=313E84973DAEC7E4F142DB8CF172D878 --lang=en-US --enable-offl
ine-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --devic
e-scale-factor=1.5 --num-raster-threads=2 --content-image-texture-target=3553,35
53,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-tex
ture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,355
3 --channel="9536.14.854672892\469127732" --mojo-platform-channel-handle=4472 /p
refetch:1
[Running Processes] :HKLM C:\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLICATION\CHR
OME.EXE
### Google Chrome Google Inc. Google Chrome 51.0.2704.106 "C:\Program Files (x
86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=Auto
maticTabDiscarding<AutomaticTabDiscarding,IncidentReportingModuleLoadAnalysis<Sa
feBrowsingIncidentReportingServiceFeatures,IncidentReportingSuspiciousModuleRepo
rting<SafeBrowsingIncidentReportingServiceFeatures,UsePasswordSeparatedSigninFlo
w<PasswordSeparatedSigninFlow,WebFontsIntervention<WebFontsIntervention,*WebRTCEnableWebRtcEcdsa<WebRTC-EnableWebRtcEcdsa,brotli-encoding<BrotliEncoding --disa
ble-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame
,RenderingPipelineThrottling<RenderingPipelineThrottling,UpdateRendererPriorityO
nStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=AppBannerTriggering
/Aggressive/AutofillProfileOrderByFrecency/Enabled/*AutomaticTabDiscarding/Enabl
ed_Once_10-gen2/*BrotliEncoding/Enabled/CaptivePortalInterstitial/Enabled/ChildA
ccountDetection/Disabled/*ClientSideDetectionModel/Model0/*DefaultBrowserInfobar
/Default/DirectWriteFontProxy/UseDirectWriteFontProxy/*DisallowFetchForDocWritte
nScriptsInMainFrame/Default/*EnableMediaRouter/Disabled/*ExtensionActionRedesign
/Enabled/ExtensionDeveloperModeWarning/Enabled/*GFE/Default/GoogleBrandedContext
Menu/default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/*NetworkQualityE
stimator/Enabled/*OmniboxBundledExperimentV1/PP_Ethersuggest_A7_Stable_R8/*OutOf
ProcessPac/Default/PasswordBranding/Disabled/*PasswordGeneration/Disabled/*Passw
ordManagerSettingsMigration/Disable/PasswordSeparatedSigninFlow/Enabled/*QUIC/En
abledNoId/*RenderingPipelineThrottling/Disabled/ReportCertificateErrors/ShowAndP

ossiblySend/*ResourcePriorities/Control25PermanentB/SHA1IdentityUIWarning/Enable
d/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFiel
dTrial/On/SSLCommonNameMismatchHandling/Control/*SafeBrowsingIncidentReportingSe
rvice/Default/*SafeBrowsingIncidentReportingServiceFeatures/WithSuspiciousModule
Reporting/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBro
wsingUpdateFrequency/Default/SyncHttpContentCompression/Enabled/*TriggeredResetF
ieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/norma
l/*UMA-Uniformity-Trial-1-Percent/group_46/*UMA-Uniformity-Trial-10-Percent/grou
p_05/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent
/group_04/*UMA-Uniformity-Trial-5-Percent/group_04/*UMA-Uniformity-Trial-50-Perc
ent/group_01/*WebFontsIntervention/Enabled/WebRTC-EnableWebRtcEcdsa/Default/ --p
rimordial-pipe-token=210FFE98B07ACA5D0562D181EF31DCD1 --lang=en-US --enable-offl
ine-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --devic
e-scale-factor=1.5 --num-raster-threads=2 --content-image-texture-target=3553,35
53,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-tex
ture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,355
3 --channel="9536.15.136237071\358814089" --mojo-platform-channel-handle=6480 /p
refetch:1
[Running Processes] :HKLM C:\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLICATION\CHR
OME.EXE
### Google Chrome Google Inc. Google Chrome 51.0.2704.106 "C:\Program Files (x
86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=Auto
maticTabDiscarding<AutomaticTabDiscarding,IncidentReportingModuleLoadAnalysis<Sa
feBrowsingIncidentReportingServiceFeatures,IncidentReportingSuspiciousModuleRepo
rting<SafeBrowsingIncidentReportingServiceFeatures,UsePasswordSeparatedSigninFlo
w<PasswordSeparatedSigninFlow,WebFontsIntervention<WebFontsIntervention,*WebRTCEnableWebRtcEcdsa<WebRTC-EnableWebRtcEcdsa,brotli-encoding<BrotliEncoding --disa
ble-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame
,RenderingPipelineThrottling<RenderingPipelineThrottling,UpdateRendererPriorityO
nStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=AppBannerTriggering
/Aggressive/AutofillProfileOrderByFrecency/Enabled/*AutomaticTabDiscarding/Enabl
ed_Once_10-gen2/*BrotliEncoding/Enabled/CaptivePortalInterstitial/Enabled/ChildA
ccountDetection/Disabled/*ClientSideDetectionModel/Model0/*DefaultBrowserInfobar
/Default/DirectWriteFontProxy/UseDirectWriteFontProxy/*DisallowFetchForDocWritte
nScriptsInMainFrame/Default/*EnableMediaRouter/Disabled/*ExtensionActionRedesign
/Enabled/ExtensionDeveloperModeWarning/Enabled/*GFE/Default/GoogleBrandedContext
Menu/default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/*NetworkQualityE
stimator/Enabled/*OmniboxBundledExperimentV1/PP_Ethersuggest_A7_Stable_R8/*OutOf
ProcessPac/Default/PasswordBranding/Disabled/*PasswordGeneration/Disabled/*Passw
ordManagerSettingsMigration/Disable/PasswordSeparatedSigninFlow/Enabled/*QUIC/En
abledNoId/*RenderingPipelineThrottling/Disabled/ReportCertificateErrors/ShowAndP
ossiblySend/*ResourcePriorities/Control25PermanentB/SHA1IdentityUIWarning/Enable
d/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFiel
dTrial/On/SSLCommonNameMismatchHandling/Control/*SafeBrowsingIncidentReportingSe
rvice/Default/*SafeBrowsingIncidentReportingServiceFeatures/WithSuspiciousModule
Reporting/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBro
wsingUpdateFrequency/Default/SyncHttpContentCompression/Enabled/*TriggeredResetF
ieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/norma
l/*UMA-Uniformity-Trial-1-Percent/group_46/*UMA-Uniformity-Trial-10-Percent/grou
p_05/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent
/group_04/*UMA-Uniformity-Trial-5-Percent/group_04/*UMA-Uniformity-Trial-50-Perc
ent/group_01/*WebFontsIntervention/Enabled/WebRTC-EnableWebRtcEcdsa/Default/ --p
rimordial-pipe-token=18CF111E3627878FD00CBBC112669075 --lang=en-US --enable-offl
ine-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --devic
e-scale-factor=1.5 --num-raster-threads=2 --content-image-texture-target=3553,35
53,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-tex
ture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,355
3 --channel="9536.16.1856388979\140612361" --mojo-platform-channel-handle=7508 /
prefetch:1
[Running Processes] :HKLM C:\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLICATION\CHR

OME.EXE
### Google Chrome Google Inc. Google Chrome 51.0.2704.106 "C:\Program Files (x
86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=Auto
maticTabDiscarding<AutomaticTabDiscarding,IncidentReportingModuleLoadAnalysis<Sa
feBrowsingIncidentReportingServiceFeatures,IncidentReportingSuspiciousModuleRepo
rting<SafeBrowsingIncidentReportingServiceFeatures,UsePasswordSeparatedSigninFlo
w<PasswordSeparatedSigninFlow,WebFontsIntervention<WebFontsIntervention,*WebRTCEnableWebRtcEcdsa<WebRTC-EnableWebRtcEcdsa,brotli-encoding<BrotliEncoding --disa
ble-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame
,RenderingPipelineThrottling<RenderingPipelineThrottling,UpdateRendererPriorityO
nStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=AppBannerTriggering
/Aggressive/AutofillProfileOrderByFrecency/Enabled/*AutomaticTabDiscarding/Enabl
ed_Once_10-gen2/*BrotliEncoding/Enabled/CaptivePortalInterstitial/Enabled/ChildA
ccountDetection/Disabled/*ClientSideDetectionModel/Model0/*DefaultBrowserInfobar
/Default/DirectWriteFontProxy/UseDirectWriteFontProxy/*DisallowFetchForDocWritte
nScriptsInMainFrame/Default/*EnableMediaRouter/Disabled/*ExtensionActionRedesign
/Enabled/ExtensionDeveloperModeWarning/Enabled/*GFE/Default/GoogleBrandedContext
Menu/default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/*NetworkQualityE
stimator/Enabled/*OmniboxBundledExperimentV1/PP_Ethersuggest_A7_Stable_R8/*OutOf
ProcessPac/Default/PasswordBranding/Disabled/*PasswordGeneration/Disabled/*Passw
ordManagerSettingsMigration/Disable/PasswordSeparatedSigninFlow/Enabled/*QUIC/En
abledNoId/*RenderingPipelineThrottling/Disabled/ReportCertificateErrors/ShowAndP
ossiblySend/*ResourcePriorities/Control25PermanentB/SHA1IdentityUIWarning/Enable
d/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFiel
dTrial/On/SSLCommonNameMismatchHandling/Control/*SafeBrowsingIncidentReportingSe
rvice/Default/*SafeBrowsingIncidentReportingServiceFeatures/WithSuspiciousModule
Reporting/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBro
wsingUpdateFrequency/Default/SyncHttpContentCompression/Enabled/*TriggeredResetF
ieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/norma
l/*UMA-Uniformity-Trial-1-Percent/group_46/*UMA-Uniformity-Trial-10-Percent/grou
p_05/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent
/group_04/*UMA-Uniformity-Trial-5-Percent/group_04/*UMA-Uniformity-Trial-50-Perc
ent/group_01/*WebFontsIntervention/Enabled/WebRTC-EnableWebRtcEcdsa/Default/ --p
rimordial-pipe-token=0E3AF237D5C199423FD6AA2FE008C8FB --lang=en-US --enable-offl
ine-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --devic
e-scale-factor=1.5 --num-raster-threads=2 --content-image-texture-target=3553,35
53,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-tex
ture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,355
3 --channel="9536.17.1016586028\923796189" --mojo-platform-channel-handle=6248 /
prefetch:1
[Running Processes] :HKLM C:\WINDOWS\SYSTEMAPPS\MICROSOFT.WINDOWS.CORTANA_CW5N
1H2TXYEWY\SEARCHUI.EXE
### Search and Cortana application Microsoft Corporation Microsoft Windows Opera
ting System 10.0.10586.420 "C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n
1h2txyewy\SearchUI.exe" -ServerName:CortanaUI.AppXa50dqqa5gqv4a428c9y1jjw7m3btve
pj.mca
[Running Processes] :HKLM C:\PROGRAM FILES (X86)\INTEL\INTEL(R) SECURITY ASSIS
T\ISA.EXE
### Intel(R) Security Assist Intel Corporation Intel(R) Security Assist 1.0.0.
532 "C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe"
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\APPLICATIONFRAMEHOST.EXE
### Application Frame Host Microsoft Corporation Microsoft Windows Operating Sys
tem 10.0.10586.0 C:\Windows\system32\ApplicationFrameHost.exe -Embedding
[Running Processes] :HKLM C:\WINDOWS\IMMERSIVECONTROLPANEL\SYSTEMSETTINGS.EXE
### Settings Microsoft Corporation Microsoft Windows Operating System 10.0.10586
.0 "C:\Windows\ImmersiveControlPanel\SystemSettings.exe" -ServerName:microsoft.w
indows.immersivecontrolpanel
[Running Processes] :HKLM C:\PROGRAM FILES\WINDOWSAPPS\MICROSOFT.WINDOWS.PHOTO
S_15.1001.16470.0_X64__8WEKYB3D8BBWE\MICROSOFT.PHOTOS.EXE
### Microsoft Photos Microsoft Photos 15.1001.16470.0 "C:\Program Files\Window

sApps\Microsoft.Windows.Photos_15.1001.16470.0_x64__8wekyb3d8bbwe\Microsoft.Phot
os.exe" -ServerName:App.AppXzst44mncqdg84v7sv6p7yznqwssy6f7f.mca
[Running Processes] :HKLM C:\PROGRAM FILES\WINDOWSAPPS\MICROSOFT.WINDOWSSTORE_
11602.1.26.0_X64__8WEKYB3D8BBWE\WINSTORE.MOBILE.EXE
### Store Microsoft Corporation Windows Store 11602.1.26.0 "C:\Program Files\W
indowsApps\Microsoft.WindowsStore_11602.1.26.0_x64__8wekyb3d8bbwe\WinStore.Mobil
e.exe" -ServerName:App.AppXqagq4n4gvy0tjw576pgh6xr601s1h1mv.mca
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\WBEM\WMIAPSRV.EXE
### WMI Performance Reverse Adapter Microsoft Corporation Microsoft Windows Oper
ating System 10.0.10586.0 C:\Windows\system32\wbem\WmiApSrv.exe
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SEARCHPROTOCOLHOST.EXE
### Microsoft Windows Search Protocol Host Microsoft Corporation Windows Search
7.00.10586.0 "C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeM
ssGthrPipe30_ Global\UsGthrCtrlFltPipeMssGthrPipe30 1 -2147483646 "Software\Micr
osoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search
4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaem
on"
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SEARCHFILTERHOST.EXE
### Microsoft Windows Search Filter Host Microsoft Corporation Windows Search 7
.00.10586.0 "C:\Windows\system32\SearchFilterHost.exe" 0 628 632 640 8192 636
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SEARCHPROTOCOLHOST.EXE
### Microsoft Windows Search Protocol Host Microsoft Corporation Windows Search
7.00.10586.0 "C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeM
ssGthrPipe_S-1-5-21-2529283801-2643127874-3567046402-100131_ Global\UsGthrCtrlFl
tPipeMssGthrPipe_S-1-5-21-2529283801-2643127874-3567046402-100131 1 -2147483646
"Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows
NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc"
"DownLevelDaemon" "1"
[Running Processes] :HKLM C:\PROGRAM FILES (X86)\UNHACKME\UNHACKME.EXE
### Detects and removes rootkits Greatis Software UnHackMe 8.12 "C:\Program Fi
les (x86)\UnHackMe\Unhackme.exe"
[Running Processes] :HKLM C:\PROGRAM FILES (X86)\UNHACKME\HACKMON.EXE
### Detects Rootkits in background Greatis Software UnHackMe 8.12 "C:\Program
Files (x86)\UnHackMe\hackmon.exe"
[Running Processes] :HKLM C:\PROGRAM FILES (X86)\UNHACKME\REANIMATOR.EXE
### RegRun Start Control Greatis Software RegRun Security Suite 8.12 "C:\Progr
am Files (x86)\UnHackMe\reanimator.exe" /wiz /full /malw
[Running Services] Appinfo
### Internal Name: Appinfo. Status: service is running. Actual File: C:\Window
s\system32\svchost.exe -k netsvcs * Facilitates the running of interactive appli
cations with additional administrative privileges. If this service is stopped,
users will be unable to launch applications with the additional administrative p
rivileges they may require to perform desired user tasks. Host Process for Windo
ws Services Microsoft Corporation Microsoft Windows Operating System 10.0.10586.0
[Running Services] AudioEndpointBuilder
### Internal Name: AudioEndpointBuilder. Status: service is running. Actual Fi
le: C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted * Manages au
dio devices for the Windows Audio service. If this service is stopped, audio de
vices and effects will not function properly. If this service is disabled, any
services that explicitly depend on it will fail to start Host Process for Window
s Services Microsoft Corporation Microsoft Windows Operating System 10.0.10586.0
[Running Services] Audiosrv
### Internal Name: Audiosrv. Status: service is running. Actual File: C:\Windo
ws\System32\svchost.exe -k LocalServiceNetworkRestricted * Manages audio for Win
dows-based programs. If this service is stopped, audio devices and effects will
not function properly. If this service is disabled, any services that explicit
ly depend on it will fail to start Host Process for Windows Services Microsoft C
orporation Microsoft Windows Operating System 10.0.10586.0
[Running Services] AVP16.0.1
### Internal Name: AVP16.0.1. Status: service is running. Actual File: "C:\Pro

gram Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.1\avp.exe" -r *


Provides computer protection against viruses, dangerous software, network attack
s, internet fraud and spam. Kaspersky Anti-Virus AO Kaspersky Lab Kaspersky Anti
-Virus 16.0.1.445
[Running Services] BFE
### Internal Name: BFE. Status: service is running. Actual File: C:\Windows\sy
stem32\svchost.exe -k LocalServiceNoNetwork * The Base Filtering Engine (BFE) is
a service that manages firewall and Internet Protocol security (IPsec) policies
and implements user mode filtering. Stopping or disabling the BFE service will
significantly reduce the security of the system. It will also result in unpredic
table behavior in IPsec management and firewall applications. Host Process for W
indows Services Microsoft Corporation Microsoft Windows Operating System 10.0.1058
6.0
[Running Services] BrokerInfrastructure
### Internal Name: BrokerInfrastructure. Status: service is running. Actual Fi
le: C:\Windows\system32\svchost.exe -k DcomLaunch * Windows infrastructure servi
ce that controls which background tasks can run on the system. Host Process for
Windows Services Microsoft Corporation Microsoft Windows Operating System 10.0.105
86.0
[Running Services] Browser
### Internal Name: Browser. Status: service is running. Actual File: C:\Window
s\System32\svchost.exe -k netsvcs * Maintains an updated list of computers on th
e network and supplies this list to computers designated as browsers. If this se
rvice is stopped, this list will not be updated or maintained. If this service i
s disabled, any services that explicitly depend on it will fail to start. Host P
rocess for Windows Services Microsoft Corporation Microsoft Windows Operating Syst
em 10.0.10586.0
[Running Services] CCSDK
### Internal Name: CCSDK. Status: service is running. Actual File: C:\Program
Files (x86)\Lenovo\CCSDK\CCSDK.exe * Lenovo Customer Engagement Service is for t
he continuous improvement of Lenovo products and services. Lenovo will collect o
nly basic information about your usage of your device and the preloaded applicat
ions, without any appreciable inconvenience to your usage of your device. These
processes do not involve the collection of any personally identifiable informat
ion. CCSDK Lenovo CCSDK 1.3.0.3
[Running Services] CoreMessagingRegistrar
### Internal Name: CoreMessagingRegistrar. Status: service is running. Actual
File: C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork * Manages communi
cation between system components. Host Process for Windows Services Microsoft Co
rporation Microsoft Windows Operating System 10.0.10586.0
[Running Services] cphs
### Internal Name: cphs. Status: service is running. Actual File: C:\Windows\S
ysWow64\IntelCpHeciSvc.exe * Intel(R) Content Protection HECI Service - enables
communication with the Content Protection FW IntelCpHeciSvc Executable Intel Cor
poration IntelCpHeciSvc Executable 9.0.31.9000
[Running Services] CryptSvc
### Internal Name: CryptSvc. Status: service is running. Actual File: C:\Windo
ws\system32\svchost.exe -k NetworkService * Provides three management services:
Catalog Database Service, which confirms the signatures of Windows files and all
ows new programs to be installed; Protected Root Service, which adds and removes
Trusted Root Certification Authority certificates from this computer; and Autom
atic Root Certificate Update Service, which retrieves root certificates from Win
dows Update and enable scenarios such as SSL. If this service is stopped, these
management services will not function properly. If this service is disabled, any
services that explicitly depend on it will fail to start. Host Process for Wind
ows Services Microsoft Corporation Microsoft Windows Operating System 10.0.10586.0
[Running Services] DcomLaunch
### Internal Name: DcomLaunch. Status: service is running. Actual File: C:\Win
dows\system32\svchost.exe -k DcomLaunch * The DCOMLAUNCH service launches COM an

d DCOM servers in response to object activation requests. If this service is sto


pped or disabled, programs using COM or DCOM will not function properly. It is s
trongly recommended that you have the DCOMLAUNCH service running. Host Process f
or Windows Services Microsoft Corporation Microsoft Windows Operating System 10.0.
10586.0
[Running Services] DeviceAssociationService
### Internal Name: DeviceAssociationService. Status: service is running. Actua
l File: C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted * Enable
s pairing between the system and wired or wireless devices. Host Process for Win
dows Services Microsoft Corporation Microsoft Windows Operating System 10.0.10586.
0
[Running Services] Dhcp
### Internal Name: Dhcp. Status: service is running. Actual File: C:\Windows\s
ystem32\svchost.exe -k LocalServiceNetworkRestricted * Registers and updates IP
addresses and DNS records for this computer. If this service is stopped, this co
mputer will not receive dynamic IP addresses and DNS updates. If this service is
disabled, any services that explicitly depend on it will fail to start. Host Pr
ocess for Windows Services Microsoft Corporation Microsoft Windows Operating Syste
m 10.0.10586.0
[Running Services] DiagTrack
### Internal Name: DiagTrack. Status: service is running. Actual File: C:\Wind
ows\System32\svchost.exe -k utcsvc * The Connected User Experiences and Telemetr
y service enables features that support in-application and connected user experi
ences. Additionally, this service manages the event driven collection and transm
ission of diagnostic and usage information (used to improve the experience and q
uality of the Windows Platform) when the diagnostics and usage privacy option se
ttings are enabled under Feedback and Diagnostics. Host Process for Windows Serv
ices Microsoft Corporation Microsoft Windows Operating System 10.0.10586.0
[Running Services] Dnscache
### Internal Name: Dnscache. Status: service is running. Actual File: C:\Windo
ws\system32\svchost.exe -k NetworkService * The DNS Client service (dnscache) ca
ches Domain Name System (DNS) names and registers the full computer name for thi
s computer. If the service is stopped, DNS names will continue to be resolved. H
owever, the results of DNS name queries will not be cached and the computer's na
me will not be registered. If the service is disabled, any services that explici
tly depend on it will fail to start. Host Process for Windows Services Microsoft
Corporation Microsoft Windows Operating System 10.0.10586.0
[Running Services] DoSvc
### Internal Name: DoSvc. Status: service is running. Actual File: C:\Windows\
system32\svchost.exe -k netsvcs * Performs content delivery optimization tasks H
ost Process for Windows Services Microsoft Corporation Microsoft Windows Operating
System 10.0.10586.0
[Running Services] DPS
### Internal Name: DPS. Status: service is running. Actual File: C:\Windows\Sy
stem32\svchost.exe -k LocalServiceNoNetwork * The Diagnostic Policy Service enab
les problem detection, troubleshooting and resolution for Windows components. I
f this service is stopped, diagnostics will no longer function. Host Process for
Windows Services Microsoft Corporation Microsoft Windows Operating System 10.0.10
586.0
[Running Services] DsSvc
### Internal Name: DsSvc. Status: service is running. Actual File: C:\Windows\
System32\svchost.exe -k LocalSystemNetworkRestricted * Provides data brokering b
etween applications. Host Process for Windows Services Microsoft Corporation Mic
rosoft Windows Operating System 10.0.10586.0
[Running Services] EventLog
### Internal Name: EventLog. Status: service is running. Actual File: C:\Windo
ws\System32\svchost.exe -k LocalServiceNetworkRestricted * This service manages
events and event logs. It supports logging events, querying events, subscribing
to events, archiving event logs, and managing event metadata. It can display eve
nts in both XML and plain text format. Stopping this service may compromise secu

rity and reliability of the system. Host Process for Windows Services Microsoft
Corporation Microsoft Windows Operating System 10.0.10586.0
[Running Services] EventSystem
### Internal Name: EventSystem. Status: service is running. Actual File: C:\Wi
ndows\system32\svchost.exe -k LocalService * Supports System Event Notification
Service (SENS), which provides automatic distribution of events to subscribing C
omponent Object Model (COM) components. If the service is stopped, SENS will clo
se and will not be able to provide logon and logoff notifications. If this servi
ce is disabled, any services that explicitly depend on it will fail to start. Ho
st Process for Windows Services Microsoft Corporation Microsoft Windows Operating
System 10.0.10586.0
[Running Services] EvtEng
### Internal Name: EvtEng. Status: service is running. Actual File: "C:\Progra
m Files\Intel\WiFi\bin\EvtEng.exe" * Manages the event trace messages for all th
e Intel PROSet/Wireless Software components. Intel(R) PROSet/Wireless Event Log S
ervice Intel(R) Corporation Intel(R) PROSet/Wireless 18, 20, 0, 0
[Running Services] FastbootService
### Internal Name: FastbootService. Status: service is running. Actual File: "
C:\Program Files\Lenovo\OneKey Optimizer\bin\FbService.exe" * Lenovo RapidBoot H
DD Accelerator Service Lenovo RapidBoot HDD Accelerator Service Lenovo RapidBoot
HDD Accelerator 3,0,0,21
[Running Services] fdPHost
### Internal Name: fdPHost. Status: service is running. Actual File: C:\Window
s\system32\svchost.exe -k LocalService * The FDPHOST service hosts the Function
Discovery (FD) network discovery providers. These FD providers supply network di
scovery services for the Simple Services Discovery Protocol (SSDP) and Web Servi
Discovery (WS-D) protocol. Stopping or disabling the FDPHOST service will di
ces
sable network discovery for these protocols when using FD. When this service is
unavailable, network services using FD and relying on these discovery protocols
will be unable to find network devices or resources. Host Process for Windows Se
rvices Microsoft Corporation Microsoft Windows Operating System 10.0.10586.0
[Running Services] FDResPub
### Internal Name: FDResPub. Status: service is running. Actual File: C:\Windo
ws\system32\svchost.exe -k LocalServiceAndNoImpersonation * Publishes this compu
ter and resources attached to this computer so they can be discovered over the n
etwork. If this service is stopped, network resources will no longer be publish
ed and they will not be discovered by other computers on the network. Host Proce
ss for Windows Services Microsoft Corporation Microsoft Windows Operating System 1
0.0.10586.0
[Running Services] FontCache
### Internal Name: FontCache. Status: service is running. Actual File: C:\Wind
ows\system32\svchost.exe -k LocalService * Optimizes performance of applications
by caching commonly used font data. Applications will start this service if it
is not already running. It can be disabled, though doing so will degrade applica
tion performance. Host Process for Windows Services Microsoft Corporation Micros
oft Windows Operating System 10.0.10586.0
[Running Services] GfExperienceService
### Internal Name: GfExperienceService. Status: service is running. Actual Fil
e: "C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceS
ervice.exe" * NVIDIA GeForce Experience Service NVIDIA GeForce ExperienceService
NVIDIA Corporation NVIDIA GeForce ExperienceService 2.11.4.0
[Running Services] HarmonySettingService
### Internal Name: HarmonySettingService. Status: service is running. Actual F
ile: "C:\Program Files (x86)\Lenovo\Harmony\Setting\HarmonySettingService.exe" *
HarmonySettingService HarmonySettingService Lenovo HarmonySettingService 1.1.0.
209
[Running Services] HomeGroupListener
### Internal Name: HomeGroupListener. Status: service is running. Actual File:
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted * Makes local c
omputer changes associated with configuration and maintenance of the homegroup-j

oined computer. If this service is stopped or disabled, your computer will not w
ork properly in a homegroup and your homegroup might not work properly. It is re
commended that you keep this service running. Host Process for Windows Services
Microsoft Corporation Microsoft Windows Operating System 10.0.10586.0
[Running Services] HomeGroupProvider
### Internal Name: HomeGroupProvider. Status: service is running. Actual File:
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted * Performs net
working tasks associated with configuration and maintenance of homegroups. If th
is service is stopped or disabled, your computer will be unable to detect other
homegroups and your homegroup might not work properly. It is recommended that yo
u keep this service running. Host Process for Windows Services Microsoft Corpora
tion Microsoft Windows Operating System 10.0.10586.0
[Running Services] IAStorDataMgrSvc
### Internal Name: IAStorDataMgrSvc. Status: service is running. Actual File:
"C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
* Provides storage event notification and manages communication between the stor
age driver and user space applications. IAStorDataSvc Intel Corporation IAStorDa
taSvc 14.6.0.1029
[Running Services] ibtsiva
### Internal Name: ibtsiva. Status: service is running. Actual File: "C:\Progr
am Files (x86)\Intel\Bluetooth\utilities\ibtsiva.exe" * Intel(R) Wireless Blueto
oth(R) iBtSiva Service Intel(R) Wireless Bluetooth(R) iBtSiva Service Intel Corp
oration Intel(R) Wireless Bluetooth(R) 17.1.1524.1353
[Running Services] igfxCUIService2.0.0.0
### Internal Name: igfxCUIService2.0.0.0. Status: service is running. Actual F
ile: C:\Windows\system32\igfxCUIService.exe * Service for Intel(R) HD Graphics C
ontrol Panel igfxCUIService Module Intel Corporation Intel(R) Common User Interf
ace 6.15.10.4248
[Running Services] IKEEXT
### Internal Name: IKEEXT. Status: service is running. Actual File: C:\Windows
\system32\svchost.exe -k netsvcs * The IKEEXT service hosts the Internet Key Exc
hange (IKE) and Authenticated Internet Protocol (AuthIP) keying modules. These k
eying modules are used for authentication and key exchange in Internet Protocol
security (IPsec). Stopping or disabling the IKEEXT service will disable IKE and
AuthIP key exchange with peer computers. IPsec is typically configured to use IK
E or AuthIP; therefore, stopping or disabling the IKEEXT service might result in
an IPsec failure and might compromise the security of the system. It is strongl
y recommended that you have the IKEEXT service running. Host Process for Windows
Services Microsoft Corporation Microsoft Windows Operating System 10.0.10586.0
[Running Services] ImControllerService
### Internal Name: ImControllerService. Status: service is running. Actual Fil
e: "C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe"
* The Lenovo System Interface Foundation Service provides interfaces for key fe
atures such as: system power management, system optimization, driver and applica
tion updates, and system settings to Lenovo applications including Lenovo Compan
ion, Lenovo Settings and Lenovo ID. If you disable this service, Lenovo applicat
ions will not work properly. Lenovo.Modern.ImController Lenovo Group Limited Len
ovo.Modern.ImController 1.0.0077.01
[Running Services] Intel(R) Security Assist
### Internal Name: Intel(R) Security Assist. Status: service is running. Actua
l File: "C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe" * Securi
ty Helper Intel(R) Security Assist Intel Corporation Intel(R) Security Assist 1.
0.0.532
[Running Services] iphlpsvc
### Internal Name: iphlpsvc. Status: service is running. Actual File: C:\Windo
ws\System32\svchost.exe -k NetSvcs * Provides tunnel connectivity using IPv6 tra
nsition technologies (6to4, ISATAP, Port Proxy, and Teredo), and IP-HTTPS. If th
is service is stopped, the computer will not have the enhanced connectivity bene
fits that these technologies offer. Host Process for Windows Services Microsoft
Corporation Microsoft Windows Operating System 10.0.10586.0

[Running Services] jhi_service


### Internal Name: jhi_service. Status: service is running. Actual File: "C:\P
rogram Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.e
xe" * Intel(R) Dynamic Application Loader Host Interface Service - Allows applic
ations to access the local Intel (R) DAL Intel(R) Dynamic Application Loader Hos
t Interface Intel Corporation Intel(R) Dynamic Application Loader Host Interface
11.0.0.1158
[Running Services] KeyIso
### Internal Name: KeyIso. Status: service is running. Actual File: C:\Windows
\system32\lsass.exe * The CNG key isolation service is hosted in the LSA process
. The service provides key process isolation to private keys and associated cryp
tographic operations as required by the Common Criteria. The service stores and
uses long-lived keys in a secure process complying with Common Criteria requirem
ents. Local Security Authority Process Microsoft Corporation Microsoft Windows Ope
rating System 10.0.10586.0
[Running Services] LanmanServer
### Internal Name: LanmanServer. Status: service is running. Actual File: C:\W
indows\system32\svchost.exe -k netsvcs * Supports file, print, and named-pipe sh
aring over the network for this computer. If this service is stopped, these func
tions will be unavailable. If this service is disabled, any services that explic
itly depend on it will fail to start. Host Process for Windows Services Microsof
t Corporation Microsoft Windows Operating System 10.0.10586.0
[Running Services] LanmanWorkstation
### Internal Name: LanmanWorkstation. Status: service is running. Actual File:
C:\Windows\System32\svchost.exe -k NetworkService * Creates and maintains clien
t network connections to remote servers using the SMB protocol. If this service
is stopped, these connections will be unavailable. If this service is disabled,
any services that explicitly depend on it will fail to start. Host Process for W
indows Services Microsoft Corporation Microsoft Windows Operating System 10.0.1058
6.0
[Running Services] Lenovo OKO Service
### Internal Name: Lenovo OKO Service. Status: service is running. Actual File
: "C:\Program Files\Lenovo\OneKey Optimizer\bin\OKOUpdataService.exe" * OneKey
Optimizer Self Update Install Service Lenovo(beijing) Limited OneKeyOptimizer 1.
2.24.6
[Running Services] lfsvc
### Internal Name: lfsvc. Status: service is running. Actual File: C:\Windows\
system32\svchost.exe -k netsvcs * This service monitors the current location of
the system and manages geofences (a geographical location with associated events
). If you turn off this service, applications will be unable to use or receive
notifications for geolocation or geofences. Host Process for Windows Services Mi
crosoft Corporation Microsoft Windows Operating System 10.0.10586.0
[Running Services] LicenseManager
### Internal Name: LicenseManager. Status: service is running. Actual File: C:
\Windows\System32\svchost.exe -k LocalService * Provides infrastructure support
for the Windows Store. This service is started on demand and if disabled then c
ontent acquired through the Windows Store will not function properly. Host Proce
ss for Windows Services Microsoft Corporation Microsoft Windows Operating System 1
0.0.10586.0
[Running Services] LiveUpdateSvc
### Internal Name: LiveUpdateSvc. Status: service is running. Actual File: C:\
Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe * LiveUpdate Product Updater
IObit Product Updater 2.0.0.0
[Running Services] lmhosts
### Internal Name: lmhosts. Status: service is running. Actual File: C:\Window
s\System32\svchost.exe -k LocalServiceNetworkRestricted * Provides support for t
he NetBIOS over TCP/IP (NetBT) service and NetBIOS name resolution for clients o
n the network, therefore enabling users to share files, print, and log on to the
network. If this service is stopped, these functions might be unavailable. If t
his service is disabled, any services that explicitly depend on it will fail to

start. Host Process for Windows Services Microsoft Corporation Microsoft Windows O
perating System 10.0.10586.0
[Running Services] LMS
### Internal Name: LMS. Status: service is running. Actual File: "C:\Program F
iles (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe" * Intel(R) M
anagement and Security Application Local Management Service - Provides OS-relate
d Intel(R) ME functionality. Intel(R) Local Management Service Intel Corporation
Intel(R) Management and Security Application Local Management Service 11.0.0.11
58
[Running Services] LSM
### Internal Name: LSM. Status: service is running. Actual File: C:\Windows\sy
stem32\svchost.exe -k DcomLaunch * Core Windows Service that manages local user
sessions. Stopping or disabling this service will result in system instability.
Host Process for Windows Services Microsoft Corporation Microsoft Windows Operatin
g System 10.0.10586.0
[Running Services] MpsSvc
### Internal Name: MpsSvc. Status: service is running. Actual File: C:\Windows
\system32\svchost.exe -k LocalServiceNoNetwork * Windows Firewall helps protect
your computer by preventing unauthorized users from gaining access to your compu
ter through the Internet or a network. Host Process for Windows Services Microso
ft Corporation Microsoft Windows Operating System 10.0.10586.0
[Running Services] NcbService
### Internal Name: NcbService. Status: service is running. Actual File: C:\Win
dows\System32\svchost.exe -k LocalSystemNetworkRestricted * Brokers connections
that allow Windows Store Apps to receive notifications from the internet. Host P
rocess for Windows Services Microsoft Corporation Microsoft Windows Operating Syst
em 10.0.10586.0
[Running Services] NcdAutoSetup
### Internal Name: NcdAutoSetup. Status: service is running. Actual File: C:\W
indows\System32\svchost.exe -k LocalServiceNoNetwork * Network Connected Devices
Auto-Setup service monitors and installs qualified devices that connect to a qu
alified network. Stopping or disabling this service will prevent Windows from di
scovering and installing qualified network connected devices automatically. User
s can still manually add network connected devices to a PC through the user inte
rface. Host Process for Windows Services Microsoft Corporation Microsoft Windows O
perating System 10.0.10586.0
[Running Services] netprofm
### Internal Name: netprofm. Status: service is running. Actual File: C:\Windo
ws\System32\svchost.exe -k LocalService * Identifies the networks to which the c
omputer has connected, collects and stores properties for these networks, and no
tifies applications when these properties change. Host Process for Windows Servi
ces Microsoft Corporation Microsoft Windows Operating System 10.0.10586.0
[Running Services] NlaSvc
### Internal Name: NlaSvc. Status: service is running. Actual File: C:\Windows
\System32\svchost.exe -k NetworkService * Collects and stores configuration info
rmation for the network and notifies programs when this information is modified.
If this service is stopped, configuration information might be unavailable. If
this service is disabled, any services that explicitly depend on it will fail to
start. Host Process for Windows Services Microsoft Corporation Microsoft Windows
Operating System 10.0.10586.0
[Running Services] nsi
### Internal Name: nsi. Status: service is running. Actual File: C:\Windows\sy
stem32\svchost.exe -k LocalService * This service delivers network notifications
(e.g. interface addition/deleting etc) to user mode clients. Stopping this serv
ice will cause loss of network connectivity. If this service is disabled, any ot
her services that explicitly depend on this service will fail to start. Host Pro
cess for Windows Services Microsoft Corporation Microsoft Windows Operating System
10.0.10586.0
[Running Services] NvNetworkService
### Internal Name: NvNetworkService. Status: service is running. Actual File:

"C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe" * NV


IDIA Network Service NVIDIA Network Service NVIDIA Corporation NVIDIA Network Se
rvice 2.4.13.69
[Running Services] nvsvc
### Internal Name: nvsvc. Status: service is running. Actual File: "C:\Windows
\system32\nvvsvc.exe" * Provides system and desktop level support to the NVIDIA
display driver NVIDIA Driver Helper Service, Version 368.69 NVIDIA Corporation N
VIDIA Driver Helper Service, Version 368.69 8.17.13.6869
[Running Services] OKOControlSvc
### Internal Name: OKOControlSvc. Status: service is running. Actual File: "C:
\Program Files\Lenovo\OneKey Optimizer\bin\OKOControlSvc.exe" * OneKey Optimizer
contains an important core service. If disabled, you will not able to use the L
enovo-provided update service. OneKey Optimizer contains an important core servi
ce. If disabled, you will not able to use the Lenovo-provided update service. Le
novo(beijing) Limited OneKey Optimizer 1.3.0.7
[Running Services] p2pimsvc
### Internal Name: p2pimsvc. Status: service is running. Actual File: C:\Windo
ws\System32\svchost.exe -k LocalServicePeerNet * Provides identity services for
the Peer Name Resolution Protocol (PNRP) and Peer-to-Peer Grouping services. If
disabled, the Peer Name Resolution Protocol (PNRP) and Peer-to-Peer Grouping se
rvices may not function, and some applications, such as HomeGroup and Remote Ass
istance, may not function correctly. Host Process for Windows Services Microsoft
Corporation Microsoft Windows Operating System 10.0.10586.0
[Running Services] p2psvc
### Internal Name: p2psvc. Status: service is running. Actual File: C:\Windows
\System32\svchost.exe -k LocalServicePeerNet * Enables multi-party communication
using Peer-to-Peer Grouping. If disabled, some applications, such as HomeGroup
, may not function. Host Process for Windows Services Microsoft Corporation Micr
osoft Windows Operating System 10.0.10586.0
[Running Services] PcaSvc
### Internal Name: PcaSvc. Status: service is running. Actual File: C:\Windows
\system32\svchost.exe -k LocalSystemNetworkRestricted * This service provides su
pport for the Program Compatibility Assistant (PCA). PCA monitors programs inst
alled and run by the user and detects known compatibility problems. If this serv
ice is stopped, PCA will not function properly. Host Process for Windows Service
s Microsoft Corporation Microsoft Windows Operating System 10.0.10586.0
[Running Services] PDAgent
### Internal Name: PDAgent. Status: service is running. Actual File: "C:\Progr
am Files\Raxco\PerfectDisk\PDAgent.exe" * This service controls PerfectDisk's sc
heduling and remote communication. PDAgent Module Raxco Software, Inc. PerfectDi
sk 14.0.890.0
[Running Services] PDEngine
### Internal Name: PDEngine. Status: service is running. Actual File: "C:\Prog
ram Files\Common Files\Raxco\Shared\PDEngine.exe" * PerfectDisk's defrag engine
PDEngine Module Raxco Software, Inc. PerfectDisk 14.0.890.0
[Running Services] PlugPlay
### Internal Name: PlugPlay. Status: service is running. Actual File: C:\Windo
ws\system32\svchost.exe -k DcomLaunch * Enables a computer to recognize and adap
t to hardware changes with little or no user input. Stopping or disabling this s
ervice will result in system instability. Host Process for Windows Services Micr
osoft Corporation Microsoft Windows Operating System 10.0.10586.0
[Running Services] PNRPsvc
### Internal Name: PNRPsvc. Status: service is running. Actual File: C:\Window
s\System32\svchost.exe -k LocalServicePeerNet * Enables serverless peer name res
olution over the Internet using the Peer Name Resolution Protocol (PNRP). If dis
abled, some peer-to-peer and collaborative applications, such as Remote Assistan
ce, may not function. Host Process for Windows Services Microsoft Corporation Mi
crosoft Windows Operating System 10.0.10586.0
[Running Services] PolicyAgent
### Internal Name: PolicyAgent. Status: service is running. Actual File: C:\Wi

ndows\system32\svchost.exe -k NetworkServiceNetworkRestricted * Internet Protoco


l security (IPsec) supports network-level peer authentication, data origin authe
ntication, data integrity, data confidentiality (encryption), and replay protect
ion. This service enforces IPsec policies created through the IP Security Polic
ies snap-in or the command-line tool "netsh ipsec". If you stop this service, y
ou may experience network connectivity issues if your policy requires that conne
ctions use IPsec. Also,remote management of Windows Firewall is not available w
hen this service is stopped. Host Process for Windows Services Microsoft Corpora
tion Microsoft Windows Operating System 10.0.10586.0
[Running Services] Power
### Internal Name: Power. Status: service is running. Actual File: C:\Windows\
system32\svchost.exe -k DcomLaunch * Manages power policy and power policy notif
ication delivery. Host Process for Windows Services Microsoft Corporation Micros
oft Windows Operating System 10.0.10586.0
[Running Services] ProfSvc
### Internal Name: ProfSvc. Status: service is running. Actual File: C:\Window
s\system32\svchost.exe -k netsvcs * This service is responsible for loading and
unloading user profiles. If this service is stopped or disabled, users will no l
onger be able to successfully sign in or sign out, apps might have problems gett
ing to users' data, and components registered to receive profile event notificat
ions won't receive them. Host Process for Windows Services Microsoft Corporation
Microsoft Windows Operating System 10.0.10586.0
[Running Services] RegSrvc
### Internal Name: RegSrvc. Status: service is running. Actual File: "C:\Progr
am Files\Common Files\Intel\WirelessCommon\RegSrvc.exe" * Provides registry acce
ss to all Intel PROSet/Wireless Software components Intel(R) PROSet/Wireless Regi
stry Service Intel(R) Corporation Intel(R) PROSet/Wireless 18, 20, 0, 0
[Running Services] RpcEptMapper
### Internal Name: RpcEptMapper. Status: service is running. Actual File: C:\W
indows\system32\svchost.exe -k RPCSS * Resolves RPC interfaces identifiers to tr
ansport endpoints. If this service is stopped or disabled, programs using Remote
Procedure Call (RPC) services will not function properly. Host Process for Wind
ows Services Microsoft Corporation Microsoft Windows Operating System 10.0.10586.0
[Running Services] RpcSs
### Internal Name: RpcSs. Status: service is running. Actual File: C:\Windows\
system32\svchost.exe -k rpcss * The RPCSS service is the Service Control Manager
for COM and DCOM servers. It performs object activations requests, object expor
ter resolutions and distributed garbage collection for COM and DCOM servers. If
this service is stopped or disabled, programs using COM or DCOM will not functio
n properly. It is strongly recommended that you have the RPCSS service running.
Host Process for Windows Services Microsoft Corporation Microsoft Windows Operatin
g System 10.0.10586.0
[Running Services] SamSs
### Internal Name: SamSs. Status: service is running. Actual File: C:\Windows\
system32\lsass.exe * The startup of this service signals other services that the
Security Accounts Manager (SAM) is ready to accept requests. Disabling this se
rvice will prevent other services in the system from being notified when the SAM
is ready, which may in turn cause those services to fail to start correctly. Th
is service should not be disabled. Local Security Authority Process Microsoft Co
rporation Microsoft Windows Operating System 10.0.10586.0
[Running Services] Schedule
### Internal Name: Schedule. Status: service is running. Actual File: C:\Windo
ws\system32\svchost.exe -k netsvcs * Enables a user to configure and schedule au
tomated tasks on this computer. The service also hosts multiple Windows system-c
ritical tasks. If this service is stopped or disabled, these tasks will not be r
un at their scheduled times. If this service is disabled, any services that expl
icitly depend on it will fail to start. Host Process for Windows Services Micros
oft Corporation Microsoft Windows Operating System 10.0.10586.0
[Running Services] SENS

### Internal Name: SENS. Status: service is running. Actual File: C:\Windows\s
ystem32\svchost.exe -k netsvcs * Monitors system events and notifies subscribers
to COM+ Event System of these events. Host Process for Windows Services Microso
ft Corporation Microsoft Windows Operating System 10.0.10586.0
[Running Services] SensorService
### Internal Name: SensorService. Status: service is running. Actual File: C:\
Windows\system32\svchost.exe -k LocalSystemNetworkRestricted * A service for sen
sors that manages different sensors' functionality. Manages Simple Device Orient
ation (SDO) and History for sensors. Loads the SDO sensor that reports device or
ientation changes. If this service is stopped or disabled, the SDO sensor will
not be loaded and so auto-rotation will not occur. History collection from Senso
rs will also be stopped. Host Process for Windows Services Microsoft Corporation
Microsoft Windows Operating System 10.0.10586.0
[Running Services] SensrSvc
### Internal Name: SensrSvc. Status: service is running. Actual File: C:\Windo
ws\system32\svchost.exe -k LocalServiceAndNoImpersonation * Monitors various sen
sors in order to expose data and adapt to system and user state. If this servic
e is stopped or disabled, the display brightness will not adapt to lighting cond
itions. Stopping this service may affect other system functionality and features
as well. Host Process for Windows Services Microsoft Corporation Microsoft Windo
ws Operating System 10.0.10586.0
[Running Services] ShellHWDetection
### Internal Name: ShellHWDetection. Status: service is running. Actual File:
C:\Windows\System32\svchost.exe -k netsvcs * Provides notifications for AutoPlay
hardware events. Host Process for Windows Services Microsoft Corporation Micros
oft Windows Operating System 10.0.10586.0
[Running Services] Spooler
### Internal Name: Spooler. Status: service is running. Actual File: C:\Window
s\System32\spoolsv.exe * This service spools print jobs and handles interaction
with the printer. If you turn off this service, you won t be able to print or see
your printers. Spooler SubSystem App Microsoft Corporation Microsoft Windows Oper
ating System 10.0.10586.0
[Running Services] SSDPSRV
### Internal Name: SSDPSRV. Status: service is running. Actual File: C:\Window
s\system32\svchost.exe -k LocalServiceAndNoImpersonation * Discovers networked d
evices and services that use the SSDP discovery protocol, such as UPnP devices.
Also announces SSDP devices and services running on the local computer. If this
service is stopped, SSDP-based devices will not be discovered. If this service i
s disabled, any services that explicitly depend on it will fail to start. Host P
rocess for Windows Services Microsoft Corporation Microsoft Windows Operating Syst
em 10.0.10586.0
[Running Services] StateRepository
### Internal Name: StateRepository. Status: service is running. Actual File: C
:\Windows\system32\svchost.exe -k appmodel * Provides required infrastructure su
pport for the application model. Host Process for Windows Services Microsoft Cor
poration Microsoft Windows Operating System 10.0.10586.0
[Running Services] SynTPEnhService
### Internal Name: SynTPEnhService. Status: service is running. Actual File: "
C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe" * 64-bit Synaptics Pointi
ng Enhance Service Synaptics Incorporated Synaptics Pointing Device Driver 19.0.
18 23Jul15
[Running Services] SysMain
### Internal Name: SysMain. Status: service is running. Actual File: C:\Window
s\system32\svchost.exe -k LocalSystemNetworkRestricted * Maintains and improves
system performance over time. Host Process for Windows Services Microsoft Corpor
ation Microsoft Windows Operating System 10.0.10586.0
[Running Services] SystemEventsBroker
### Internal Name: SystemEventsBroker. Status: service is running. Actual File
: C:\Windows\system32\svchost.exe -k DcomLaunch * Coordinates execution of backg
round work for WinRT application. If this service is stopped or disabled, then b

ackground work might not be triggered. Host Process for Windows Services Microso
ft Corporation Microsoft Windows Operating System 10.0.10586.0
[Running Services] TabletInputService
### Internal Name: TabletInputService. Status: service is running. Actual File
: C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted * Enables Touc
h Keyboard and Handwriting Panel pen and ink functionality Host Process for Wind
ows Services Microsoft Corporation Microsoft Windows Operating System 10.0.10586.0
[Running Services] Themes
### Internal Name: Themes. Status: service is running. Actual File: C:\Windows
\System32\svchost.exe -k netsvcs * Provides user experience theme management. Ho
st Process for Windows Services Microsoft Corporation Microsoft Windows Operating
System 10.0.10586.0
[Running Services] tiledatamodelsvc
### Internal Name: tiledatamodelsvc. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k appmodel * Tile Server for tile updates. Host
Process for Windows Services Microsoft Corporation Microsoft Windows Operating Sy
stem 10.0.10586.0
[Running Services] TimeBroker
### Internal Name: TimeBroker. Status: service is running. Actual File: C:\Win
dows\system32\svchost.exe -k LocalServiceAndNoImpersonation * Coordinates execut
ion of background work for WinRT application. If this service is stopped or disa
bled, then background work might not be triggered. Host Process for Windows Serv
ices Microsoft Corporation Microsoft Windows Operating System 10.0.10586.0
[Running Services] TrkWks
### Internal Name: TrkWks. Status: service is running. Actual File: C:\Windows
\System32\svchost.exe -k LocalSystemNetworkRestricted * Maintains links between
NTFS files within a computer or across computers in a network. Host Process for
Windows Services Microsoft Corporation Microsoft Windows Operating System 10.0.105
86.0
[Running Services] upnphost
### Internal Name: upnphost. Status: service is running. Actual File: C:\Windo
ws\system32\svchost.exe -k LocalServiceAndNoImpersonation * Allows UPnP devices
to be hosted on this computer. If this service is stopped, any hosted UPnP devic
es will stop functioning and no additional hosted devices can be added. If this
service is disabled, any services that explicitly depend on it will fail to star
t. Host Process for Windows Services Microsoft Corporation Microsoft Windows Opera
ting System 10.0.10586.0
[Running Services] UserManager
### Internal Name: UserManager. Status: service is running. Actual File: C:\Wi
ndows\system32\svchost.exe -k netsvcs * User Manager provides the runtime compon
ents required for multi-user interaction. If this service is stopped, some appl
ications may not operate correctly. Host Process for Windows Services Microsoft
Corporation Microsoft Windows Operating System 10.0.10586.0
[Running Services] VaultSvc
### Internal Name: VaultSvc. Status: service is running. Actual File: C:\Windo
ws\system32\lsass.exe * Provides secure storage and retrieval of credentials to
users, applications and security service packages. Local Security Authority Proc
ess Microsoft Corporation Microsoft Windows Operating System 10.0.10586.0
[Running Services] Wcmsvc
### Internal Name: Wcmsvc. Status: service is running. Actual File: C:\Windows
\system32\svchost.exe -k LocalServiceNetworkRestricted * Makes automatic connect
/disconnect decisions based on the network connectivity options currently availa
ble to the PC and enables management of network connectivity based on Group Poli
cy settings. Host Process for Windows Services Microsoft Corporation Microsoft Wi
ndows Operating System 10.0.10586.0
[Running Services] WdiServiceHost
### Internal Name: WdiServiceHost. Status: service is running. Actual File: C:
\Windows\System32\svchost.exe -k LocalService * The Diagnostic Service Host is u
sed by the Diagnostic Policy Service to host diagnostics that need to run in a L

ocal Service context. If this service is stopped, any diagnostics that depend o
n it will no longer function. Host Process for Windows Services Microsoft Corpor
ation Microsoft Windows Operating System 10.0.10586.0
[Running Services] WdiSystemHost
### Internal Name: WdiSystemHost. Status: service is running. Actual File: C:\
Windows\System32\svchost.exe -k LocalSystemNetworkRestricted * The Diagnostic Sy
stem Host is used by the Diagnostic Policy Service to host diagnostics that need
to run in a Local System context. If this service is stopped, any diagnostics
that depend on it will no longer function. Host Process for Windows Services Mic
rosoft Corporation Microsoft Windows Operating System 10.0.10586.0
[Running Services] WinHttpAutoProxySvc
### Internal Name: WinHttpAutoProxySvc. Status: service is running. Actual Fil
e: C:\Windows\system32\svchost.exe -k LocalService * WinHTTP implements the clie
nt HTTP stack and provides developers with a Win32 API and COM Automation compon
ent for sending HTTP requests and receiving responses. In addition, WinHTTP prov
ides support for auto-discovering a proxy configuration via its implementation o
f the Web Proxy Auto-Discovery (WPAD) protocol. Host Process for Windows Service
s Microsoft Corporation Microsoft Windows Operating System 10.0.10586.0
[Running Services] Winmgmt
### Internal Name: Winmgmt. Status: service is running. Actual File: C:\Window
s\system32\svchost.exe -k netsvcs * Provides a common interface and object model
to access management information about operating system, devices, applications
and services. If this service is stopped, most Windows-based software will not f
unction properly. If this service is disabled, any services that explicitly depe
nd on it will fail to start. Host Process for Windows Services Microsoft Corpora
tion Microsoft Windows Operating System 10.0.10586.0
[Running Services] WlanSvc
### Internal Name: WlanSvc. Status: service is running. Actual File: C:\Window
s\system32\svchost.exe -k LocalSystemNetworkRestricted * The WLANSVC service pro
vides the logic required to configure, discover, connect to, and disconnect from
a wireless local area network (WLAN) as defined by IEEE 802.11 standards. It al
so contains the logic to turn your computer into a software access point so that
other devices or computers can connect to your computer wirelessly using a WLAN
adapter that can support this. Stopping or disabling the WLANSVC service will m
ake all WLAN adapters on your computer inaccessible from the Windows networking
UI. It is strongly recommended that you have the WLANSVC service running if your
computer has a WLAN adapter. Host Process for Windows Services Microsoft Corpor
ation Microsoft Windows Operating System 10.0.10586.0
[Running Services] wmiApSrv
### Internal Name: wmiApSrv. Status: service is running. Actual File: C:\Windo
ws\system32\wbem\WmiApSrv.exe * Provides performance library information from Wi
ndows Management Instrumentation (WMI) providers to clients on the network. This
service only runs when Performance Data Helper is activated. WMI Performance Re
verse Adapter Microsoft Corporation Microsoft Windows Operating System 10.0.10586.
0
[Running Services] WMPNetworkSvc
### Internal Name: WMPNetworkSvc. Status: service is running. Actual File: "C:
\Program Files\Windows Media Player\wmpnetwk.exe" * Shares Windows Media Player
libraries to other networked players and media devices using Universal Plug and
Play Windows Media Player Network Sharing Service Microsoft Corporation Microsof
t Windows Operating System 12.0.10586.0
[Running Services] wscsvc
### Internal Name: wscsvc. Status: service is running. Actual File: C:\Windows
\System32\svchost.exe -k LocalServiceNetworkRestricted * The WSCSVC (Windows Sec
urity Center) service monitors and reports security health settings on the compu
ter. The health settings include firewall (on/off), antivirus (on/off/out of da
te), antispyware (on/off/out of date), Windows Update (automatically/manually do
wnload and install updates), User Account Control (on/off), and Internet setting
s (recommended/not recommended). The service provides COM APIs for independent s
oftware vendors to register and record the state of their products to the Securi

ty Center service. The Security and Maintenance UI uses the service to provide
systray alerts and a graphical view of the security health states in the Securit
y and Maintenance control panel. Network Access Protection (NAP) uses the servi
ce to report the security health states of clients to the NAP Network Policy Ser
ver to make network quarantine decisions. The service also has a public API tha
t allows external consumers to programmatically retrieve the aggregated security
health state of the system. Host Process for Windows Services Microsoft Corpora
tion Microsoft Windows Operating System 10.0.10586.0
[Running Services] WSearch
### Internal Name: WSearch. Status: service is running. Actual File: C:\Window
s\system32\SearchIndexer.exe /Embedding * Provides content indexing, property ca
ching, and search results for files, e-mail, and other content. Microsoft Window
s Search Indexer Microsoft Corporation Windows Search 7.00.10586.0
[Running Services] wudfsvc
### Internal Name: wudfsvc. Status: service is running. Actual File: C:\Window
s\system32\svchost.exe -k LocalSystemNetworkRestricted * Creates and manages use
r-mode driver processes. This service cannot be stopped. Host Process for Window
s Services Microsoft Corporation Microsoft Windows Operating System 10.0.10586.0
[Running Services] ymc
### Internal Name: ymc. Status: service is running. Actual File: C:\ProgramDat
a\LenovoTransition\Server\x64\ymc.exe * Lenovo Yoga Mode Control Lenovo Lenovo
Yoga Mode Control 1.0.0.0
[Running Services] ZeroConfigService
### Internal Name: ZeroConfigService. Status: service is running. Actual File:
"C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe" * Manages the zero conf
iguration service for all the Intel PROSet/Wireless Software components. Intel PRO
Set/Wireless Zero Configure Service Intel Corporation Intel(R) PROSet/Wireless 18
, 20, 0, 0
[Uninstall]
[Applications] :HKLM UnHackMe_is1="C:\Program Files (x86)\UnHackMe\unins000.ex
e" /SILENT
### UnHackMe 8.12 - (12) 07-2016
[Applications] :HKLM {BE40AB1F-558F-4434-B72F-461EF97E7796}_is1="C:\Program Fi
les\Bitdefender\Tools\BDAntiRansomware\unins000.exe" /SILENT
### BDAntiRansomware - (11) 07-2016
[Applications] :HKLM {F575F386-57EF-4943-B003-A13F13B05EEB}=MsiExec.exe /I{F57
5F386-57EF-4943-B003-A13F13B05EEB}
### Kaspersky Internet Security - (11) 07-2016
[Applications] :HKLM InstallWIX_{F575F386-57EF-4943-B003-A13F13B05EEB}=MsiExec
.exe /I{F575F386-57EF-4943-B003-A13F13B05EEB} REMOVE=ALL
### Kaspersky Internet Security - (11) 07-2016
[Applications] :HKLM {C4E01CDC-0063-493C-B383-9C4FCF7A89F7}=MsiExec.exe /I{C4E
01CDC-0063-493C-B383-9C4FCF7A89F7}
### PerfectDisk Professional Business - (11) 07-2016
[Applications] :HKLM {90160000-00C1-0409-1000-0000000FF1CE}=MsiExec.exe /X{901
60000-00C1-0409-1000-0000000FF1CE}
### Microsoft Office Shared 32-bit MUI (English) 2016 - (11) 07-2016
[Applications] :HKLM {90160000-00C1-0409-1000-0000000FF1CE}_Office16.PROPLUS_{
A25ADEB9-6D54-4AD2-81E4-C4C03FD35C0B}="C:\Program Files\Common Files\Microsoft S
hared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-00C1-0409-1000-000
0000FF1CE}" "{A25ADEB9-6D54-4AD2-81E4-C4C03FD35C0B}" "1033" "0"
### Update for Microsoft Office 2016 (KB3114970) 64-Bit Edition - (11) 07-2016
[Applications] :HKLM {90160000-00C1-0000-1000-0000000FF1CE}=MsiExec.exe /X{901
60000-00C1-0000-1000-0000000FF1CE}
### Microsoft Office 32-bit Components 2016 - (11) 07-2016
[Applications] :HKLM {90160000-00C1-0000-1000-0000000FF1CE}_Office16.PROPLUS_{
A25ADEB9-6D54-4AD2-81E4-C4C03FD35C0B}="C:\Program Files\Common Files\Microsoft S
hared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-00C1-0000-1000-000
0000FF1CE}" "{A25ADEB9-6D54-4AD2-81E4-C4C03FD35C0B}" "1033" "0"
### Update for Microsoft Office 2016 (KB3114970) 64-Bit Edition - (11) 07-2016

[Applications] :HKLM {90160000-006E-0409-1000-0000000FF1CE}=MsiExec.exe /X{901


60000-006E-0409-1000-0000000FF1CE}
### Microsoft Office Shared MUI (English) 2016 - (11) 07-2016
[Applications] :HKLM {90160000-006E-0409-1000-0000000FF1CE}_Office16.PROPLUS_{
A25ADEB9-6D54-4AD2-81E4-C4C03FD35C0B}="C:\Program Files\Common Files\Microsoft S
hared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-006E-0409-1000-000
0000FF1CE}" "{A25ADEB9-6D54-4AD2-81E4-C4C03FD35C0B}" "1033" "0"
### Update for Microsoft Office 2016 (KB3114970) 64-Bit Edition - (11) 07-2016
[Applications] :HKLM {90160000-006E-0409-1000-0000000FF1CE}_Office16.PROPLUS_{
0605597C-4A46-4405-B352-8FB4ABEC231B}="C:\Program Files\Common Files\Microsoft S
hared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-006E-0409-1000-000
0000FF1CE}" "{0605597C-4A46-4405-B352-8FB4ABEC231B}" "1033" "0"
### Security Update for Microsoft Office 2016 (KB2910993) 64-Bit Edition - (11
) 07-2016
[Applications] :HKLM {90160000-0011-0000-1000-0000000FF1CE}_Office16.PROPLUS_{
A25ADEB9-6D54-4AD2-81E4-C4C03FD35C0B}="C:\Program Files\Common Files\Microsoft S
hared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0011-0000-1000-000
0000FF1CE}" "{A25ADEB9-6D54-4AD2-81E4-C4C03FD35C0B}" "1033" "0"
### Update for Microsoft Office 2016 (KB3114970) 64-Bit Edition - (11) 07-2016
[Applications] :HKLM {90160000-0011-0000-1000-0000000FF1CE}=MsiExec.exe /X{901
60000-0011-0000-1000-0000000FF1CE}
### Microsoft Office Professional Plus 2016 - (11) 07-2016
[Applications] :HKLM Office16.PROPLUS="C:\Program Files\Common Files\Microsoft
Shared\OFFICE16\Office Setup Controller\setup.exe" /uninstall PROPLUS /dll OSET
UP.DLL
### Microsoft Office Professional Plus 2016 - (11) 07-2016
[Applications] :HKLM {90160000-001B-0409-1000-0000000FF1CE}=MsiExec.exe /X{901
60000-001B-0409-1000-0000000FF1CE}
### Microsoft Word MUI (English) 2016 - (11) 07-2016
[Applications] :HKLM {90160000-0019-0409-1000-0000000FF1CE}=MsiExec.exe /X{901
60000-0019-0409-1000-0000000FF1CE}
### Microsoft Publisher MUI (English) 2016 - (11) 07-2016
[Applications] :HKLM {90160000-0018-0409-1000-0000000FF1CE}=MsiExec.exe /X{901
60000-0018-0409-1000-0000000FF1CE}
### Microsoft PowerPoint MUI (English) 2016 - (11) 07-2016
[Applications] :HKLM {90160000-001A-0409-1000-0000000FF1CE}=MsiExec.exe /X{901
60000-001A-0409-1000-0000000FF1CE}
### Microsoft Outlook MUI (English) 2016 - (11) 07-2016
[Applications] :HKLM {90160000-00E2-0409-1000-0000000FF1CE}=MsiExec.exe /X{901
60000-00E2-0409-1000-0000000FF1CE}
### Microsoft Office OSM UX MUI (English) 2016 - (11) 07-2016
[Applications] :HKLM {90160000-012B-0409-1000-0000000FF1CE}=MsiExec.exe /X{901
60000-012B-0409-1000-0000000FF1CE}
### Microsoft Skype for Business MUI (English) 2016 - (11) 07-2016
[Applications] :HKLM {90160000-0044-0409-1000-0000000FF1CE}=MsiExec.exe /X{901
60000-0044-0409-1000-0000000FF1CE}
### Microsoft InfoPath MUI (English) 2016 - (11) 07-2016
[Applications] :HKLM {90160000-00BA-0409-1000-0000000FF1CE}=MsiExec.exe /X{901
60000-00BA-0409-1000-0000000FF1CE}
### Microsoft Groove MUI (English) 2016 - (11) 07-2016
[Applications] :HKLM {90160000-0016-0409-1000-0000000FF1CE}=MsiExec.exe /X{901
60000-0016-0409-1000-0000000FF1CE}
### Microsoft Excel MUI (English) 2016 - (11) 07-2016
[Applications] :HKLM {90160000-0090-0409-1000-0000000FF1CE}=MsiExec.exe /X{901
60000-0090-0409-1000-0000000FF1CE}
### Microsoft DCF MUI (English) 2016 - (11) 07-2016
[Applications] :HKLM {90160000-00E1-0409-1000-0000000FF1CE}=MsiExec.exe /X{901
60000-00E1-0409-1000-0000000FF1CE}
### Microsoft Office OSM MUI (English) 2016 - (11) 07-2016
[Applications] :HKLM {90160000-00A1-0409-1000-0000000FF1CE}=MsiExec.exe /X{901

60000-00A1-0409-1000-0000000FF1CE}
### Microsoft OneNote MUI (English) 2016 - (11) 07-2016
[Applications] :HKLM {90160000-0117-0409-1000-0000000FF1CE}=MsiExec.exe /X{901
60000-0117-0409-1000-0000000FF1CE}
### Microsoft Access Setup Metadata MUI (English) 2016 - (11) 07-2016
[Applications] :HKLM {90160000-0015-0409-1000-0000000FF1CE}=MsiExec.exe /X{901
60000-0015-0409-1000-0000000FF1CE}
### Microsoft Access MUI (English) 2016 - (11) 07-2016
[Applications] :HKLM {90160000-002C-0409-1000-0000000FF1CE}=MsiExec.exe /X{901
60000-002C-0409-1000-0000000FF1CE}
### Microsoft Office Proofing (English) 2016 - (11) 07-2016
[Applications] :HKLM {90160000-001F-0409-1000-0000000FF1CE}=MsiExec.exe /X{901
60000-001F-0409-1000-0000000FF1CE}
### Microsoft Office Proofing Tools 2016 - English - (11) 07-2016
[Applications] :HKLM {90160000-001F-040C-1000-0000000FF1CE}=MsiExec.exe /X{901
60000-001F-040C-1000-0000000FF1CE}
### Outils de vrification linguistique 2016 de Microsoft Office- Franais - (11) 0
7-2016
[Applications] :HKLM {90160000-001F-0C0A-1000-0000000FF1CE}=MsiExec.exe /X{901
60000-001F-0C0A-1000-0000000FF1CE}
### Herramientas de correccin de Microsoft Office 2016: espaol - (11) 07-2016
[Applications] :HKLM {90160000-0115-0409-1000-0000000FF1CE}=MsiExec.exe /X{901
60000-0115-0409-1000-0000000FF1CE}
### Microsoft Office Shared Setup Metadata MUI (English) 2016 - (11) 07-2016
[Applications] :HKLM {60EC980A-BDA2-4CB6-A427-B07A5498B4CA}=MsiExec.exe /I{60E
C980A-BDA2-4CB6-A427-B07A5498B4CA}
### Google Update Helper - (11) 07-2016
[Applications] :HKLM Google Chrome="C:\Program Files (x86)\Google\Chrome\Appli
cation\51.0.2704.106\Installer\setup.exe" --uninstall --multi-install --chrome -system-level --verbose-logging
### Google Chrome - (11) 07-2016
[Applications] :HKLM IObitUninstall="C:\Program Files (x86)\IObit\IObit Uninst
aller\unins000.exe" /SILENT
### IObit Uninstaller - (11) 07-2016
[Applications] :HKLM {A06FD661-4B18-4054-B09C-E852D28E5AEB}
### Harmony - (11) 07-2016
[Applications] :HKLM {D02D9427-507D-4912-9285-97FCD5417E72}="C:\Program Files
(x86)\InstallShield Installation Information\{D02D9427-507D-4912-9285-97FCD5417E
72}\setup.exe" -runfromtemp -l0x0009 -removeonly
### Harmony - (11) 07-2016
[Applications] :HKLM {CBEDEC16-C4F5-4255-99E4-5884EFEDD1BC}=MsiExec.exe /X{CBE
DEC16-C4F5-4255-99E4-5884EFEDD1BC}
### Lenovo BatteryGauge - (11) 07-2016
[Applications] :HKLM {AE75190B-11B4-4F90-8254-DAB275CF2557}_is1="C:\Program Fi
les (x86)\Lenovo\CCSDK\unins000.exe" /SILENT
### CCSDK Customer Engagement Service - (11) 07-2016
[Applications] :HKLM {C2E5CA37-C862-4A69-AC6D-24F450A20C16}=MsiExec.exe /X{C2E
5CA37-C862-4A69-AC6D-24F450A20C16}
### Lenovo System Interface Foundation - (11) 07-2016
[Applications] :HKLM {f65db027-aff3-4070-886a-0d87064aabb1}="C:\ProgramData\Pa
ckage Cache\{f65db027-aff3-4070-886a-0d87064aabb1}\vcredist_x86.exe" /uninstall
/quiet
### Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 - (11) 07-201
6
[Applications] :HKLM InstallShield_{D5D573DC-D989-4769-9B56-D6A7EA503D7F}="C:\
Program Files (x86)\InstallShield Installation Information\{D5D573DC-D989-4769-9
B56-D6A7EA503D7F}\setup.exe" -runfromtemp -l0x0409 -removeonly
### OneKey Optimizer - (11) 07-2016
[Applications] :HKLM {D5D573DC-D989-4769-9B56-D6A7EA503D7F}=MsiExec.exe /I{D5D
573DC-D989-4769-9B56-D6A7EA503D7F}

### OneKey Optimizer - (11) 07-2016


[Applications] :HKLM SHAREit_is1="C:\Program Files (x86)\SHAREit\SHAREit\unins
000.exe" /SILENT
### SHAREit - (11) 07-2016
[Applications] :HKLM SynTPDeinstKey=rundll32.exe "%ProgramFiles%\Synaptics\Syn
TP\SynISDLL.dll",standAloneUninstall
### Synaptics Pointing Device Driver - (11) 07-2016
[Applications] :HKLM {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GFExperience.LEDVi
sualizer
### NVIDIA LED Visualizer 1.0 - (10) 07-2016
[Applications] :HKLM {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperien
ce="C:\Windows\SysWOW64\RunDll32.EXE" "C:\Program Files\NVIDIA Corporation\Insta
ller2\InstallerCore\NVI2.DLL",UninstallPackage Display.GFExperience
### NVIDIA GeForce Experience 2.11.4.0 - (10) 07-2016
[Applications] :HKLM {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update
### NVIDIA Update 2.11.4.0 - (10) 07-2016
[Applications] :HKLM {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Optimus
### NVIDIA Optimus Update 2.11.4.0 - (10) 07-2016
[Applications] :HKLM {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GfExperienceServic
e
### NVIDIA GeForce Experience Service - (10) 07-2016
[Applications] :HKLM {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Update.Core
### NVIDIA Update Core - (10) 07-2016
[Applications] :HKLM {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX="C:\
Windows\SysWOW64\RunDll32.EXE" "C:\Program Files\NVIDIA Corporation\Installer2\I
nstallerCore\NVI2.DLL",UninstallPackage Display.PhysX
### NVIDIA PhysX System Software 9.16.0318 - (10) 07-2016
[Applications] :HKLM {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Network.Service
### NVIDIA Network Service - (10) 07-2016
[Applications] :HKLM {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver="C:
\Windows\SysWOW64\RunDll32.EXE" "C:\Program Files\NVIDIA Corporation\Installer2\
InstallerCore\NVI2.DLL",UninstallPackage Display.Driver
### NVIDIA Graphics Driver 368.69 - (10) 07-2016
[Applications] :HKLM {F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}=MsiExec.exe /X{F8C
FEB22-A2E7-3971-9EDA-4B11EDEFC185}
### Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 - (10) 07-20
16
[Applications] :HKLM {13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}=MsiExec.exe /X{13A
4EE12-23EA-3371-91EE-EFB36DDFFF3E}
### Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 - (10) 07-2016
[Applications] :HKLM {050d4fc8-5d48-4b8f-8972-47c82c46020f}="C:\ProgramData\Pa
ckage Cache\{050d4fc8-5d48-4b8f-8972-47c82c46020f}\vcredist_x64.exe" /uninstall
/quiet
### Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 - (10) 07-201
6
[Applications] :HKLM VulkanRT1.0.11.1=C:\Program Files (x86)\VulkanRT\1.0.11.1
\UninstallVulkanRT.exe
### Vulkan Run Time Libraries 1.0.11.1 - (10) 07-2016
[Applications] :HKLM {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer
### NVIDIA Install Application - (10) 07-2016
[Applications] :HKLM {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPan
el
### NVIDIA Control Panel 368.69 - (10) 07-2016
[Applications] :HKLM {929FBD26-9020-399B-9A7A-751D61F0B942}=MsiExec.exe /X{929
FBD26-9020-399B-9A7A-751D61F0B942}
### Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.21005 - (10) 07-20
16
[Applications] :HKLM {A749D8E6-B613-3BE3-8F5F-045C84EBA29B}=MsiExec.exe /X{A74
9D8E6-B613-3BE3-8F5F-045C84EBA29B}
### Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.21005 - (10) 07-2016

[Applications] :HKLM {8833FFB6-5B0C-4764-81AA-06DFEED9A476}=C:\Program Files (


x86)\InstallShield Installation Information\{8833FFB6-5B0C-4764-81AA-06DFEED9A47
6}\setup.exe -runfromtemp -removeonly
### Realtek Ethernet Controller Driver - (10) 07-2016
[Applications] :HKLM {F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}="C:\Program Files
(x86)\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7D
BC}\Setup.exe" -runfromtemp -removeonly
### Realtek High Definition Audio Driver - (10) 07-2016
[Applications] :HKLM {D2CD7DCF-D129-4A54-8543-38BECC6CFDAE}=MsiExec.exe /X{D2C
D7DCF-D129-4A54-8543-38BECC6CFDAE}
### Dolby Digital Plus - (10) 07-2016
[Applications] :HKLM {8D2C871B-1B9F-45AC-9C43-2BB18089CDFA}=MsiExec.exe /X{8D2
C871B-1B9F-45AC-9C43-2BB18089CDFA}
### Lenovo QuickOptimizer - (10) 07-2016
[Applications] :HKLM {4c8b7360-62a2-4339-b745-41323055d0bb}="C:\ProgramData\Pa
ckage Cache\{4c8b7360-62a2-4339-b745-41323055d0bb}\Setup.exe" /uninstall /quiet
### Intel PROSet/Wireless Software - (10) 07-2016
[Applications] :HKLM {2FB369C6-9264-472B-836A-DB2F6B2C9BE4}=MsiExec.exe /I{2FB
369C6-9264-472B-836A-DB2F6B2C9BE4}
### Intel PROSet/Wireless WiFi Software - (10) 07-2016
[Applications] :HKLM {07a12c6f-97c2-4a0e-9dd6-50ffc08ff551}
### Intel(R) PRO/Wireless Driver - (10) 07-2016
[Applications] :HKLM {F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}="C:\Program Files
(x86)\Intel\Intel(R) Processor Graphics\Uninstall\setup.exe" -uninstall
### Intel(R) Processor Graphics - (10) 07-2016
[Applications] :HKLM {9FD91C5C-44AE-4D9D-85BE-AE52816B0294}="C:\ProgramData\In
tel\Package Cache\{9FD91C5C-44AE-4D9D-85BE-AE52816B0294}\Setup.exe" -uninstall
### Intel(R) Serial IO - (10) 07-2016
[Applications] :HKLM {CBD9BDB2-3126-4756-A03A-621CCF87C188}=MsiExec.exe /I{CBD
9BDB2-3126-4756-A03A-621CCF87C188}
### Intel(R) Serial IO - (10) 07-2016
[Applications] :HKLM {409CB30E-E457-4008-9B1A-ED1B9EA21140}="C:\ProgramData\In
tel\Package Cache\{409CB30E-E457-4008-9B1A-ED1B9EA21140}\Setup.exe" -uninstall
### Intel(R) Rapid Storage Technology - (10) 07-2016
[Applications] :HKLM {6DADC2C0-C9A9-4814-B59D-1FFA36F147EB}=MsiExec.exe /I{6DA
DC2C0-C9A9-4814-B59D-1FFA36F147EB}
### Intel(R) Rapid Storage Technology - (10) 07-2016
[Applications] :HKLM {4B230374-6475-4A73-BA6E-41015E9C5013}=MsiExec.exe /I{4B2
30374-6475-4A73-BA6E-41015E9C5013}
### Intel Security Assist - (10) 07-2016
[Applications] :HKLM {1CEAC85D-2590-4760-800F-8DE5E91F3700}="C:\ProgramData\In
tel\Package Cache\{1CEAC85D-2590-4760-800F-8DE5E91F3700}\Setup.exe" -uninstall
### Intel(R) Management Engine Components - (10) 07-2016
[Applications] :HKLM {7D84E343-A23D-451C-B123-0195B2D903A6}=MsiExec.exe /I{7D8
4E343-A23D-451C-B123-0195B2D903A6}
### Intel Trusted Connect Service Client - (10) 07-2016
[Applications] :HKLM {BFACB3F5-7091-429E-A6A9-59C0696B710E}=MsiExec.exe /I{BFA
CB3F5-7091-429E-A6A9-59C0696B710E}
### Intel(R) Management Engine Components - (10) 07-2016
[Applications] :HKLM {CCCB484E-79D5-4398-9377-CA6EEB6B53AE}=MsiExec.exe /I{CCC
B484E-79D5-4398-9377-CA6EEB6B53AE}
### Intel(R) Management Engine Components - (10) 07-2016
[Applications] :HKLM {DF17C0DB-76D8-4A45-B26E-674F8455B803}=MsiExec.exe /I{DF1
7C0DB-76D8-4A45-B26E-674F8455B803}
### Intel(R) ME UninstallLegacy - (10) 07-2016
[Applications] :HKLM {c6cff78a-cccb-49d5-be68-ae0ec5f0d48a}="C:\ProgramData\Pa
ckage Cache\{c6cff78a-cccb-49d5-be68-ae0ec5f0d48a}\SetupChipset.exe" /uninstall
/quiet
### Intel(R) Chipset Device Software - (10) 07-2016
[Applications] :HKLM {B685D0AD-42A8-4A39-9BFE-8C063FA9AF29}=MsiExec.exe /I{B68

5D0AD-42A8-4A39-9BFE-8C063FA9AF29}
### Intel(R) Chipset Device Software - (10) 07-2016
[Applications] :HKLM {DC5673D2-228D-45BC-B9BB-9610CE67DFC0}=MsiExec.exe /I{DC5
673D2-228D-45BC-B9BB-9610CE67DFC0}
### Intel(R) Wireless Bluetooth(R) - (10) 07-2016
[Applications] :HKLM {654EE65D-FAA4-4EA6-8C07-DC94E6A304D4}=C:\Program Files (
x86)\Intel\Intel(R) Dynamic Platform and Thermal Framework\Uninstall\setup.exe uninstall
### Intel(R) Dynamic Platform and Thermal Framework - (10) 07-2016
[Applications] :HKLM {E399A5B3-ED53-4DEA-AF04-8011E1EB1EAC}="C:\Program Files
(x86)\InstallShield Installation Information\{E399A5B3-ED53-4DEA-AF04-8011E1EB1E
AC}\Temp.exe" /runfromtemp /removeonly /s /f1"C:\Program Files (x86)\InstallShie
ld Installation Information\{E399A5B3-ED53-4DEA-AF04-8011E1EB1EAC}\usetup.iss"
### Lenovo EasyCamera - (10) 07-2016
[Applications] :HKLM Connection Manager
### - (30) 10-2015
[Applications] :HKLM WIC
### - (30) 10-2015
[Applications] :HKLM WIC
### - (30) 10-2015
[Applications] :HKLM Connection Manager
### - (30) 10-2015
[MD5]
[B76B8924F91072D25FC29ABD82A28D5B][1
2165976 D2C359935016D957FDC58A6E155
194BABBECFD57
]C:\PROGRA~1\MICROS~1\OFFICE16\GROOVEEX.DLL
[752C1127E137083C0D120EBF74E336C5][1
1512152 05B60D4BF90C852E116B249F1A3
045C0A069608A
]C:\PROGRA~2\MICROS~1\OFFICE16\GROOVEEX.DLL
[1B137C417E86D42D3F48ACF7CF9E553E][1
21216 727387647D76D233863DBFF72B9
A134BE7767F05
]C:\PROGRAM FILES (X86)\COMMON FILES\MICROSOFT SHARED\INK\TABTI
P32.EXE
[09D23CB52A1508A7F96AB656DFB8B548][1
53960 8C59BFAE70C41C985FC44022267
B98F4DC1513A4
]C:\PROGRAM FILES (X86)\COMMON FILES\MICROSOFT SHARED\OFFICE16\
MSOXMLMF.DLL
[64B21B3E863BE0B42FAEAA17DD9292A9][1
1125192 9BF806BBC3A63657D392B2DD8ED
EC31252658953
]C:\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE
[750446ED76A5D13E902174DDDDA1A62B][1
154440 9D04597F8CFC8841DFA876487DE
965C0F05708CA
]C:\PROGRAM FILES (X86)\GOOGLE\UPDATE\GOOGLEUPDATE.EXE
[127E0F8100D329A3814C80F47713FA79][1
150256 F38748829C72543A5AE4D32CB4D
7B83173CD3B1D
]C:\PROGRAM FILES (X86)\INTEL\BLUETOOTH\UTILITIES\IBTSIVA.EXE
[DE70C5C10803C700DC1CFDE2D5CF207A][1
223520 ADA6C30D52E26717C70A1FEBFDB
98AC08FAD3EFE
]C:\PROGRAM FILES (X86)\INTEL\INTEL(R) MANAGEMENT ENGINE COMPON
ENTS\DAL\JHI_SERVICE.EXE
[1CE3A27B6B0658F4242AB2DECE69704E][1
415520 227DACF466EECAD1E9C056275E5
6E8691BADEDB5
]C:\PROGRAM FILES (X86)\INTEL\INTEL(R) MANAGEMENT ENGINE COMPON
ENTS\LMS\LMS.EXE
[8213094EA736A9C575AB0E22AD09B0BA][2
335872 2CB81A3DD394504C855056DF869
CC00470753AF3
]C:\PROGRAM FILES (X86)\INTEL\INTEL(R) SECURITY ASSIST\ISA.EXE
[1DFC3CCA51785254C5604238BB1A5467][2
7680 E2CAAD27F718CB9FEF12AC616CB
A3F3917FCF922
]C:\PROGRAM FILES (X86)\INTEL\INTEL(R) SECURITY ASSIST\ISAHELPE
RSERVICE.EXE
[F44CA6BFAAAB8C27B4A688E2D3CDD728][1
5301536 A4619385A9F74BC312555FB9BD2
5176D9279D495
]C:\PROGRAM FILES (X86)\IOBIT\IOBIT UNINSTALLER\IOBITUNINSTALER
.EXE
[C72EE92A4C995B0DDC0255FEB59BE151][1
2478880 63081C63796400DC691A8395B54
DF05CF1AB5F47
]C:\PROGRAM FILES (X86)\IOBIT\IOBIT UNINSTALLER\UNINSTALLEXPLOR
ER.DLL
[EC43E30BEB3E06E5DAEF4D49A81220BC][1
282400 0CC7B6275C79BBF2047A80AADE4
EC9E110C2A5D4
]C:\PROGRAM FILES (X86)\IOBIT\IOBIT UNINSTALLER\UNINSTALLMONITO
R.EXE
[DCE4D6B8A07E18E719A10311E4FA3125][1
2960672 1FC7CABD5705E16AA8D5002E710

00FAEF7463C1F
]C:\PROGRAM FILES (X86)\IOBIT\LIVEUPDATE\LIVEUPDATE.EXE
[09F0E4D1F66C40AB770AD1540758C59E][1
236928 29956C9CA20E08EBC443A1B7967
954686C0C1E31
]C:\PROGRAM FILES (X86)\KASPERSKY LAB\KASPERSKY INTERNET SECURI
TY 16.0.1\AVP.EXE
[784F6F48C541F383F90AE4C5B3FCE0B5][1
220072 7269E0AB85D57E4DAEE12B1B8B7
462610D8780BA
]C:\PROGRAM FILES (X86)\KASPERSKY LAB\KASPERSKY INTERNET SECURI
TY 16.0.1\AVPUI.EXE
[CF93C0D4B408F5BF9801E49FC3A63F3D][1
749024 3BCA1F3AF554B722F6270EDF366
F7CA63B3B7949
]C:\PROGRAM FILES (X86)\KASPERSKY LAB\KASPERSKY INTERNET SECURI
TY 16.0.1\IEEXT\IE_PLUGIN.DLL
[8F94291E9665EE667214C01780777B92][1
524200 161D8B623928C0FA22BB3ECD458
D188B360907E8
]C:\PROGRAM FILES (X86)\KASPERSKY LAB\KASPERSKY INTERNET SECURI
TY 16.0.1\SHELLEX.DLL
[62E40B04DD9A4915FBD798FD273526AC][1
969696 E911E6FDF58D4CE29F17BC1C588
1B90D9919AD61
]C:\PROGRAM FILES (X86)\KASPERSKY LAB\KASPERSKY INTERNET SECURI
TY 16.0.1\X64\IEEXT\IE_PLUGIN.DLL
[B48F79A7B58EB9A5E4894A96453C6957][1
152488 C3FB5D694833D83556640A58620
636B0B99411BE
]C:\PROGRAM FILES (X86)\KASPERSKY LAB\KASPERSKY INTERNET SECURI
TY 16.0.1\X64\VSSBRIDGE64.EXE
[CE8477DE4E12022AAFB3075CC1688DED][1
666608 F99AA13DCDB3E33BC9208EAC520
B4B3F2BB8889B
]C:\PROGRAM FILES (X86)\LENOVO\CCSDK\CCSDK.EXE
[E9A46FCB53833669A4AECABD60BAEE87][1
17184 0224673DD65B70449086A520417
F78F483150BD3
]C:\PROGRAM FILES (X86)\LENOVO\CUSTOMER FEEDBACK PROGRAM\LENOVO
.TVT.CUSTOMERFEEDBACK.AGENT.EXE
[EEEF244E90F709BF393EC649CD8F3028][1
5275064 80E4157993A953BA2FE87288EF9
0E0E0F3F76E3E
]C:\PROGRAM FILES (X86)\LENOVO\HARMONY\PICKS\LENOVO.HARMONYPICK
S.EXE
[CB609E1E85B2117031431AEEB4ACAC63][1
19896 5C1983BFE946649453E19B34536
7A6B2EFEAE617
]C:\PROGRAM FILES (X86)\LENOVO\HARMONY\SETTING\HARMONYSETTINGSE
RVICE.EXE
[1351B590E4B2FE5DF40D3157950B3912][1
2721208 B810E3FAF8EA1BFDC8FDCFA72E4
67A94AF7D9677
]C:\PROGRAM FILES (X86)\LENOVO\HARMONY\SETTING\LENOVO.HARMONYSE
TTING.EXE
[E6DB86C3E24B0F76CA139C6C89853DDA][1
37200 E4050DB4A4DE2634D4375A19BB1
E6926CFB9A043
]C:\PROGRAM FILES (X86)\LENOVO\IMCONTROLLER\PLUGINHOST\LENOVO.M
ODERN.IMCONTROLLER.PLUGINHOST.EXE
[B0271E30A7E4E0385E4F2291EEA97B32][1
107776 6F875964D1D80C211B35149B408
3AE620B913E42
]C:\PROGRAM FILES (X86)\LENOVO\LENOVOTRANSITION\TRANSITIONSERVE
R.EXE
[D697F01FDEADC1EA4E5F54158CE7B6A3][1
140992 F8F003E8F69E714B0E233B04CCB
A85A00104517F
]C:\PROGRAM FILES (X86)\MICROSOFT OFFICE\OFFICE16\MSOSB.DLL
[69BD29240C9C4AAD5C2046F24D40CC96][1
161448 07BE3432F4D8C42318344F4AE67
C800724668C48
]C:\PROGRAM FILES (X86)\MICROSOFT OFFICE\OFFICE16\OCHELPER.DLL
[020F45E362D3B57CCC5735582BB1A6EC][1
1879488 36747DBD252552ED3608F58713F
E86DA76B83BC0
]C:\PROGRAM FILES (X86)\NVIDIA CORPORATION\NETSERVICE\NVNETWORK
SERVICE.EXE
[94A8196066774252DF015EEDF02CCA44][1
2397120 28B6667F95888EBD0F19D98C432
9A17FB1F8F27A
]C:\PROGRAM FILES (X86)\NVIDIA CORPORATION\UPDATE CORE\NVBACKEN
D.EXE
[E829D42DD6C64DFE2587FD9B9F598693][1
35272 0F11118C3C1ED3D42FE8CCAD368
1C4644A981D73
]C:\PROGRAM FILES (X86)\SHAREIT\SHAREIT\SHAREIT.SERVICE.EXE
[D1F515B1C897AB7D26E1EB4970892E76][1
1091000 DA21C61052F71397CD56149B7E8
789A9DF121660
]C:\PROGRAM FILES (X86)\UNHACKME\HACKMON.EXE
[97389A435853020EC82835934C64CFFA][1
10769848 1FB9450225B386E654D3B135391
329F8DD5028CE
]C:\PROGRAM FILES (X86)\UNHACKME\REANIMATOR.EXE
[B044435A68D8EAC596E48473A05E5BDC][1
2446264 7802A5C49B1EB37B5DD017802C8
26F839AB9AB86
]C:\PROGRAM FILES (X86)\UNHACKME\UNHACKME.EXE
[8532792113BDC019923A2B04DE62BE67][1
24864 1D289A46473DDC8F94704CA9EA7
70A646F9CD5F7
]C:\PROGRAM FILES (X86)\WINDOWS DEFENDER\MSMPENG.EXE
[F3A57F42D94B3B7CD1F6D82600D14C98][1
364464 B59D851C4B61E1E4B601CFB027E

70053E9D4973E
]C:\PROGRAM FILES (X86)\WINDOWS DEFENDER\NISSRV.EXE
[09D8EBC01776C2D117918993EDDC19B2][1
1474560 FB1E24E68C9BB7635E8EBD8E0A3
CF168A31C6E7D
]C:\PROGRAM FILES (X86)\WINDOWS MEDIA PLAYER\WMPNETWK.EXE
[AB19DB70D94FFC43B5C5EA00D57DFF1E][1
4304896 61FACA19B8C9CA303A0C2FDFE8B
8BFD349B8AE25
]C:\PROGRAM FILES (X86)\WINDOWS NT\ACCESSORIES\WORDPAD.EXE
[6B8366AA47F166C89848A7FB1103BB24][1
1318488 ADF4EB3E7F251BEBCF01B3326CF
142EFF2AD0064
]C:\PROGRAM FILES\BITDEFENDER\TOOLS\BDANTIRANSOMWARE\BDANTIRANS
OMWARE.EXE
[B91EE7363FDC2B0CB1C5E6190B46F7DC][1
157088 BC3E8AB8D7AE9CCE56BB76E107B
08E7E5DA5213E
]C:\PROGRAM FILES\COMMON FILES\INTEL\WIRELESSCOMMON\REGSRVC.EXE
[22004B9C1C7C73BF97D11F9C158FB3F7][1
386368 E4DD7D98483BD52566B84AEBAF4
053957E381BB3
]C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\INK\TABTIP.EXE
[58327B7E7C4E325C66B7C4A5220CE5F4][1
242864 A1A43C7B34A5021210F6E40248E
61C6D6783F49D
]C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\SOURCE ENGINE\O
SE.EXE
[41CCA0C13E03F9C1443BEF374B4BBCFB][1
3562944 C4FE0E4C454DCF0685D764944FA
F53B5E36F2FE3
]C:\PROGRAM FILES\COMMON FILES\RAXCO\SHARED\PDENGINE.EXE
[079511E999ACAB4B8CC08432F0363368][2
746496 4A95CF89B0C70731642C0073515
72761AA123002
]C:\PROGRAM FILES\DOLBY\DDP_F3\DDPF3.EXE
[B63CF22D1AD2ABDC39D85851B2BEAA6D][1
881152 295B50EDE2683D736E672B0CA0C
1DFBC15357B04
]C:\PROGRAM FILES\INTEL\ICLS CLIENT\SOCKETHECISERVER.EXE
[D90885430767C6152AF908D57A5159AC][1
18856 4DAE8FAB10819DDA4C1BFF990C4
B9233F9A79E6E
]C:\PROGRAM FILES\INTEL\INTEL(R) RAPID STORAGE TECHNOLOGY\IASTO
RDATAMGRSVC.EXE
[FF9F8695FA627E3BE6CF14239B44234D][1
322472 6661DE014F06A501C7B1C609914
A04F5F675CFDE
]C:\PROGRAM FILES\INTEL\INTEL(R) RAPID STORAGE TECHNOLOGY\IASTO
RICON.EXE
[03AE229AD0EC7BFDA3D2B37BA9E5799E][2
36352 2CBC02CBD4C8648F4985A4D9574
3D7C88D83DBA6
]C:\PROGRAM FILES\INTEL\INTEL(R) RAPID STORAGE TECHNOLOGY\IASTO
RICONLAUNCH.EXE
[6DCB7233AAD29E43331B3ECFCC8FB8D1][1
640928 3610B3DA9EB8DAF1E4CA8C42E9B
2D9A6A66E29FC
]C:\PROGRAM FILES\INTEL\WIFI\BIN\EVTENG.EXE
[F1F6EE6C068CBDB80BAC43A79591F1F2][1
268192 7D4FFBA672AFFDDE42A40575F4C
8765F9CCD5A96
]C:\PROGRAM FILES\INTEL\WIFI\BIN\PANDHCPDNS.EXE
[65308E8DDBCA0A3D7A72E3404E194319][1
3831712 DB6312E6B56F224A605FFA7318C
77ACCB0478491
]C:\PROGRAM FILES\INTEL\WIFI\BIN\ZEROCONFIGSERVICE.EXE
[4180512B8E8E1F0CE1F8C546C090DB97][1
816320 F163F39F8C825C060F4989A1D6E
07AE7C1EC1EB2
]C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
[5CF3AF4EC4A374438EBC7CD820080FCB][1
56144 B7739391FD5BA2234585AC89169
3F9CC6B87CDF0
]C:\PROGRAM FILES\LENOVO\IMCONTROLLER\SERVICE\LENOVO.MODERN.IMC
ONTROLLER.EXE
[56CA8297F6F97DF3FF2898D5A738E426][1
193640 F2061665FE739C0B3C4667664B0
700E15C40F232
]C:\PROGRAM FILES\LENOVO\ONEKEY OPTIMIZER\BIN\FBSERVICE.EXE
[30FF10C903D88749E0D1B12B53F78A41][1
369960 4ABC7913F4565BC18741489EAAC
57DD8341D12E6
]C:\PROGRAM FILES\LENOVO\ONEKEY OPTIMIZER\BIN\OKOCONTROLSVC.EXE
[B3E1F6B325BC2DC5DDB701406255E9A4][1
2730280 6979F99887492C801E824F2FF19
34B5B1624DD66
]C:\PROGRAM FILES\LENOVO\ONEKEY OPTIMIZER\BIN\OKOUPDATASERVICE.
EXE
[F7C0982B7D302064CB227BDF35B9C1DF][1
1398056 390EA4BF791DD7F9D6002F6B56A
78B61109F7CD2
]C:\PROGRAM FILES\LENOVO\ONEKEY OPTIMIZER\BIN\ONEKEYOPTIMIZER.E
XE
[1867F14EE28F2CF846BF05D1031A0FE5][1
604968 D70D0ECCF404185FDB65497B62D
B9B908EEBBFC9
]C:\PROGRAM FILES\LENOVO\ONEKEY OPTIMIZER\BIN\ONEKEYOPTIMIZERTR
AY.EXE
[74D94B97E44878044D6AA02C7DDB5D29][1
318248 FE5EFFA3ADC1BFB845F2CD82879
6B1629C6DA06A
]C:\PROGRAM FILES\LENOVO\ONEKEY OPTIMIZER\BIN\ONEKEYOPTIMIZERUP
DATA.EXE
[CC954D5B0AE39E621CD39659DB10E85B][1
226984 DEFF961CF8F8DD988FDCDBEDAED
B1E83D2C41C9E
]C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE16\OCHELPER.DLL
[111350FC207AAF2E39DA9F1AD672B8C4][1
1272256 82D04B28FD9B96439D062A7B453

A67D4E3A7769E
]C:\PROGRAM FILES\NVIDIA CORPORATION\DISPLAY\NVXDSYNC.EXE
[F78BC07DCED5EDDD6D477E923620F8EA][1
1163712 18B1EE9645880718BE835E8BC92
073610D10110A
]C:\PROGRAM FILES\NVIDIA CORPORATION\GEFORCE EXPERIENCE SERVICE
\GFEXPERIENCESERVICE.EXE
[09C1C6CA8A8708ADA417BD1F5FBB0559][1
3162048 23AC2AA46C4C1B6C5B16514F95E
8F7A266269141
]C:\PROGRAM FILES\RAXCO\PERFECTDISK\PDAGENT.EXE
[EF0609095F508A24C3AD49352BCB38A0][1
90048 896BD1CA581D4091B32D0CA3B40
4083D72D110BA
]C:\PROGRAM FILES\RAXCO\PERFECTDISK\PDAGENTS1.EXE
[78C48AD707AADA8E7692A5D58E7D6753][1
1408752 5595A90EDC63A7983C37D96425D
55DA9D9ADE491
]C:\PROGRAM FILES\REALTEK\AUDIO\HDA\RAVBG64.EXE
[8705EE93E1BFC4308F0DEDA2FA02DE3E][1
3948216 AB11AB03984EC49FC4FF4DC0933
25C74CA548113
]C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPENH.EXE
[D635E700E43F4ECA021FD159CFF3F8B9][1
246472 191AED97AC1792CD82F4445BBC3
65D08D2D058EF
]C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPENHSERVICE.EXE
[02B07DA28089AAF8034749BCB5DD3657][1
211640 3A6CF6654BCEAE1007BF1080E96
1F09FF10EF2AF
]C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE
[09D8EBC01776C2D117918993EDDC19B2][1
1474560 FB1E24E68C9BB7635E8EBD8E0A3
CF168A31C6E7D
]C:\PROGRAM FILES\WINDOWS MEDIA PLAYER\WMPNETWK.EXE
[C3EF139378171D8BB852BEB6E759B7F1][2
144384 CA1AD84972A213BB78859E19089
1D058CB642EC8
]C:\PROGRAM FILES\WINDOWSAPPS\MICROSOFT.MESSAGING_2.15.20002.0_
X86__8WEKYB3D8BBWE\SKYPEHOST.EXE
[C0FB6E2E3601EB3B92A1B1ABA790C8E5][2
12288 2999E6FAE7FDE41FC99847F8A9B
F6A06E3C19304
]C:\PROGRAM FILES\WINDOWSAPPS\MICROSOFT.WINDOWS.PHOTOS_15.1001.
16470.0_X64__8WEKYB3D8BBWE\MICROSOFT.PHOTOS.EXE
[E0290F32DA32F45DC7A959D14D575D4C][2
14336 D3199A238C76FBF90E7B09A8175
7ADBB6F9E914F
]C:\PROGRAM FILES\WINDOWSAPPS\MICROSOFT.WINDOWSSTORE_11602.1.26
.0_X64__8WEKYB3D8BBWE\WINSTORE.MOBILE.EXE
[7990F2BD88507BA0343317353D2DF6F1][1
178872 016764F48D013F29EE1F6A89EDC
ADAB4DE5B4336
]C:\PROGRAMDATA\KASPERSKY LAB\AVP16.0.1\BASES\KLIDS.SYS
[EECC6FB48D5137A331D02AAC1D99DF8C][1
30464 14A9728155A1F35C9B3EA41E44A
018F3A98A13FB
]C:\PROGRAMDATA\LENOVOTRANSITION\SERVER\X64\YMC.EXE
[
-2][0
-1
]C:\USERS\BAMMI\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\E
XTENSIONS\HTTPS://CHROME.GOOGLE.COM/WEBSTORE/DETAIL/LPEEAGHDJMHLAKOJJCGFDHGCEJDA
EFMI
[8F2EA5EE0695CCE2285D92C44108375C][1
554184 CF2DF13D8115151D9D54BC6215B
3BB790EC99DF8
]C:\USERS\BAMMI\APPDATA\LOCAL\MICROSOFT\ONEDRIVE\ONEDRIVE.EXE
[E15BEB03592BA12C5C99E2BA46146BDD][1
4515264 B612CFE9506AFD65F3B67CE0991
8AEE51AEEE73E
]C:\WINDOWS\EXPLORER.EXE
[8F26CB57B225F046E49A4D8003DAE920][1
83704 6166E53DD6E022FACD51946F75B
169ED5E0AFFAC
]C:\WINDOWS\IMMERSIVECONTROLPANEL\SYSTEMSETTINGS.EXE
[9E9BEB22644CE1DA521A1D7821BF891F][1
135848 6E646F69AA92AACFBEFB3B1071C
5863E0CA75B71
]C:\WINDOWS\MICROSOFT.NET\FRAMEWORK64\V4.0.30319\SMSVCHOST.EXE
[E50DD57F496CED8873FA3E7D38BCCD42][1
121856 E5363CAC7F54FF62CCDCFF84498
16C108A7BE9F4
]C:\WINDOWS\SERVICING\TRUSTEDINSTALLER.EXE
[B4AE5296C9597F45E1CFE0B1DBE7739E][1
200192 3FB9DA7773BEF4D2A744CF2E9A1
390C8BD0ADCA5
]C:\WINDOWS\SYSNATIVE\APPMGMTS.DLL
[61EE0E80EF7FD384C37A591CF9379DC1][1
1298432 84E8A64D5B5DC83C3857DAE3918
1E2EE1C9C1AA1
]C:\WINDOWS\SYSNATIVE\COMRES.DLL
[3EFB194760F2C347E53713AA8D7A46C7][1
14336 9016E771940BC79BEF845725BE6
51AAAC9FDA968
]C:\WINDOWS\SYSNATIVE\D3D8THK.DLL
[E65AF7A23F6B8A8E270A4D237D906407][1
588288 BB4A6892E478CAE524931880F5F
1FF925D53220C
]C:\WINDOWS\SYSNATIVE\DDRAW.DLL
[9A3E17CDB177913C2A111C80F3D0DBB4][1
686976 FF77062486ABB8CC2135A31C5A2
0D1DCEDDC04F0
]C:\Windows\SYSNATIVE\DNSAPI.DLL
[5F96092CC55C643837C891F082007C9C][1
617984 A2EFA4DFFFD668F9C56D97852ED
F057A092782B6
]C:\WINDOWS\SYSNATIVE\DSOUND.DLL
[1A2E3B6697F5468B0D4FD47E340D3E90][1
513024 49718F6BBCE178CBF16ADB76D83
D9AF771632968
]C:\WINDOWS\SYSNATIVE\HNETCFG.DLL
[706EAE0012D8489D1DA0FD73140A4D93][1
230416 B6C72D2BFD13E2A6BE2C4477E01

45A5C0C8D62D3
]C:\WINDOWS\SYSNATIVE\IMM32.DLL
[348DDE16E5F6E24CD8A5CB31A0B2297C][1
219040 C3049049536E989AEAA7AFE38D1
896BE6A82F374
]C:\WINDOWS\SYSNATIVE\IPHLPAPI.DLL
[0F2B1FB6DDFA739AF5E50915DC134334][1
22752 A62B2903C82A7C69E8360341B32
2E7B7D2C133A5
]C:\WINDOWS\SYSNATIVE\KSUSER.DLL
[6ABAC83AD594B0390C470F9C1C017382][1
3072 F4C2B4BC336B982C2CEBAD09049
00B65BA09188A
]C:\WINDOWS\SYSNATIVE\LPK.DLL
[73C44205E57B561FAA308312B108165B][1
25088 B340D818C550794140F58B24594
B29E82B452102
]C:\WINDOWS\SYSNATIVE\MIDIMAP.DLL
[12203B26197D49D2BDF7B27FCB7C184B][1
10240 75F37D980A63B894BF40FFA1706
E3B79792A8A7A
]C:\WINDOWS\SYSNATIVE\MSCTFIME.IME
[C1B13204994572C941C14A7FF410C4D6][1
24605696 79BD4B80874D43A173C7AFDB5DF
B9F11F6617EDB
]C:\WINDOWS\SYSNATIVE\MSHTML.DLL
[A3A66211CF74409C7B7D200E1B945DBE][1
8704 8B5F51633AC2F906DF5F356A24D
BD566453C855A
]C:\WINDOWS\SYSNATIVE\MSIMG32.DLL
[199298181CB86E5056D82BD1F86C8A97][1
357216 452BFB21E430822B5A011B3A6FE
F660E27F3089F
]C:\WINDOWS\SYSNATIVE\MSWSOCK.DLL
[84E12C5A6041EC7C629A1FDD2581D0AF][1
68096 CA19607AEB68A4E9E2990D6DCA6
67430C96B4629
]C:\WINDOWS\SYSNATIVE\NAPINSP.DLL
[D2B807A29858D89EDB1D8D5415B9E6F6][1
80896 0BC550EF0C17D73F3D91255F608
66D7BDAA74AE4
]C:\WINDOWS\SYSNATIVE\NLAAPI.DLL
[309CC67EC901D1D42A5E1D3975DA3E77][1
87040 EE10E26BCA7AEF87E1FF0CD72B2
9B0046CF42316
]C:\WINDOWS\SYSNATIVE\PNRPNSP.DLL
[52B49D01CE8F8EEC3D557D2CCD46548B][1
17408 3D978D8025CC6CDC657276C0BB0
7B3D83FA26A26
]C:\WINDOWS\SYSNATIVE\RASADHLP.DLL
[50FED971D0FAD2B990C0A05735761D62][1
733184 B176420F51C03BF60C423E3822B
4031107A9086D
]C:\WINDOWS\SYSNATIVE\RASAPI32.DLL
[B339861C6A2A86FBCA67C2006B461473][1
904704 8147D405EE3DC32BA9D2F3C05B6
9D80D6B8F2599
]C:\WINDOWS\SYSNATIVE\RPCSS.DLL
[930A1C518D65A9E781CD16C9BCFC5BEF][1
251392 689B95A43AA56D7499603BE0494
0E97E483DB050
]C:\WINDOWS\SYSNATIVE\SCECLI.DLL
[6FF8248F3A9D69A095C7F3F42BC29CB2][1
440152 0D57FE069ED17B42811F444BEAD
54E7E3399BA6E
]C:\WINDOWS\SYSNATIVE\SERVICES.EXE
[864BBE3CC3478AE5C53FFD5E7C95AA63][1
1238584 91E7AD993CEE462A3956B30735B
64766E0648624
]C:\WINDOWS\SYSNATIVE\TASKMGR.EXE
[F5F7CE3E32536F1A37FB3972F27A814F][1
1399224 63B56EDD96DB9FB345B6DBB418C
CBA2EAC8F22BC
]C:\WINDOWS\SYSNATIVE\USER32.DLL
[76CB0E0CA741CE280F9B9D2D2BCD2CCB][1
589312 8481DF2F6C9B44B798AB35C2D38
3A06596C64366
]C:\WINDOWS\SYSNATIVE\UXTHEME.DLL
[5C156EC4E44E30331BCC865A3B61D839][1
585728 55DAAB0704DE997B363F4D2506F
41D85C927038E
]C:\WINDOWS\SYSNATIVE\WINLOGON.EXE
[4DB377DB30B00E59828E8BA4C90C680F][1
31744 D9CFD13E14FAEAEC1D8F3C6B8D7
DCA14BFEBD278
]C:\WINDOWS\SYSNATIVE\WINRNR.DLL
[054916A6A9C86607869D247F2CA425B5][1
4608 8A9DA3B382193D900D9F1A81DFF
3645903E3291D
]C:\WINDOWS\SYSNATIVE\WS2HELP.DLL
[C3534256AF526A16AADBA335AA99D58F][1
63488 F1547097B3296EDABB73C7422B6
8846BFBDEF930
]C:\WINDOWS\SYSNATIVE\WSHBTH.DLL
[19707ECBCEA71080A85DB2336580DB39][1
23040 814078D9DCCB53A2BCEBB25057F
84C00B33E4B89
]C:\WINDOWS\SYSTEM32\AJROUTER.DLL
[AA91A5E156D0364ABA7B01658C2EB014][1
97792 4DCC2B9275AAF9C25FEAD297C49
59C1BBE06ACAA
]C:\WINDOWS\SYSTEM32\ALG.EXE
[7F3A0D052B8E00E730316210B1DD092F][1
342016 4B94D5BC3D327A367738CEACB89
A4453DC67A9EB
]C:\WINDOWS\SYSTEM32\APHOSTSERVICE.DLL
[7A55F9237F726D1667073A47B0D1B90F][1
45056 CA3ADBAFBD2BF8D1BC575FFC31B
8813A64E9E101
]C:\WINDOWS\SYSTEM32\APPIDSVC.DLL
[56E219DF92BE16F62308F884739BE022][1
94720 A6A9847B1C87F573C473B5717BC
B2F4068CA3474
]C:\WINDOWS\SYSTEM32\APPINFO.DLL
[EB8B7935A446A137163AB1F94CD11B2A][1
43408 A3DF2748375FCC2E3462BF9FBA8
4411188866D2D
]C:\WINDOWS\SYSTEM32\APPLICATIONFRAMEHOST.EXE
[B4AE5296C9597F45E1CFE0B1DBE7739E][1
200192 3FB9DA7773BEF4D2A744CF2E9A1

390C8BD0ADCA5
]C:\WINDOWS\SYSTEM32\APPMGMTS.DLL
[610499A73DF3599608EBB6B3F9929052][1
504320 68561B4D6AB7A7F497F7EB62BED
E7B3587A48AAA
]C:\WINDOWS\SYSTEM32\APPREADINESS.DLL
[42BF7FA295F453618104B5A50BEE105B][1
275456 061A5224F65F919541189B5B641
38E838E32CEDB
]C:\WINDOWS\SYSTEM32\AUDIOENDPOINTBUILDER.DLL
[2A2C0983B6FE62F02E7183335B1F5C20][1
1054208 6F4BD75BF36BFF1ED0D7EE8FD8A
C9C6D67CD5065
]C:\WINDOWS\SYSTEM32\AUDIOSRV.DLL
[7062CE507814D5306DCA5D6A15B7B6B6][1
114176 9104EAFF873A6B4570B4375FBBE
6B7EEC5CDFDB6
]C:\WINDOWS\SYSTEM32\AXINSTSV.DLL
[F374C27099807E99A156953F8416D34A][1
361472 7A733080FD42EFA1B6DE86A4139
107A3FE1DAC0A
]C:\WINDOWS\SYSTEM32\BDESVC.DLL
[37F5E2385CB4D10AB42186974B9C241A][1
794112 B47B97271FE79E45915D7B004CF
38C1EAE967F2B
]C:\WINDOWS\SYSTEM32\BFE.DLL
[4F2621E187382D22045D0BC65B23858E][1
587776 A067C1B3952CC6D0D66D740F342
1FB05F39DEF84
]C:\WINDOWS\SYSTEM32\BISRV.DLL
[A617BE5E429A035A1CA8217C1B16F0BB][1
134656 AE6F672142FB68993DDFE7EAF64
12765C09FAEAC
]C:\WINDOWS\SYSTEM32\BROWSER.DLL
[BAB101E7826BE287F79C4BA721621989][1
326144 33E35310F5EC0BEADB7BB4FE832
8C7C54A15F4E4
]C:\WINDOWS\SYSTEM32\BTHHFSRV.DLL
[7A177E18AA6A6A6365E6351C2BF8EDAE][1
91136 CD09575BC175F58306298D26A9D
689465E173513
]C:\WINDOWS\SYSTEM32\BTHSERV.DLL
[0A92DC116CFC7F6BE8167DD25CB925CC][1
287744 236C6EAFBBE4B5C9140A9F728E4
ED7742CFCF18C
]C:\WINDOWS\SYSTEM32\CDPSVC.DLL
[4E9158CECF77A029AB98E8FBB43FCED5][1
192000 C5211FA5DB774FCBB306DA8428D
05A41700A4F46
]C:\WINDOWS\SYSTEM32\CERTPROP.DLL
[F7526C133AC265F283012E9CD751F873][1
625000 B7C3F6782AB8D35A6917F736B8B
2297554D0B2AB
]C:\WINDOWS\SYSTEM32\CLIPSVC.DLL
[841F937D7B6A7EB605D1B4535DE889DA][1
47104 F8204EE42D6AFD9A1B0A09F858C
588387C07B22F
]C:\WINDOWS\SYSTEM32\CONHOST.EXE
[86BE19C6A177AEB93302EA5C4FBE2D11][1
754664 24996FFAD929F7551FD3465E079
7D79EDECE2161
]C:\WINDOWS\SYSTEM32\COREMESSAGING.DLL
[9E79A2208A9ED205A7383CBC92C28053][1
79872 5092714EFD311FFB4E26B7E5893
69DAE1B05153F
]C:\WINDOWS\SYSTEM32\CRYPTSVC.DLL
[5F07CCEE514894C9474AEDCA50B6C2C7][1
735232 F5B299B0FF004AC4E7632BC43F6
C05AB1C0A0A8A
]C:\WINDOWS\SYSTEM32\CSCSVC.DLL
[D12B9B6A6C4885824876422AACC89954][1
444928 10247CA1A5E925DD430B4682BFF
49915CFE82A22
]C:\WINDOWS\SYSTEM32\DAS.DLL
[0967A14066601A948A32B12C5858CB4C][1
95232 53210661D0559D49A617522EAC7
1AAF009D33DAA
]C:\WINDOWS\SYSTEM32\DASHOST.EXE
[620921E77351FB651632322AD2C195C4][1
186880 503855AEE2CB6306EDE32B03EFB
C88EEEB430291
]C:\WINDOWS\SYSTEM32\DCPSVC.DLL
[6129EA4294C5C69E4665801E95B16AB2][1
527872 531FB5BFF777D7BF90F4FCA549C
02C4CE4AA3E55
]C:\WINDOWS\SYSTEM32\DEFRAGSVC.DLL
[16EE6701115BECF8C657D9D6E123F6A1][1
205824 8DE8A5D91BC3204C201FF0DB39F
0FE17FBA59313
]C:\WINDOWS\SYSTEM32\DEVICESETUPMANAGER.DLL
[5BF8BD9B19D665452494C8D56DF4B28D][1
34304 E78F656645F3F1530A91A76189E
42844D8C03FC4
]C:\WINDOWS\SYSTEM32\DEVQUERYBROKER.DLL
[D461D2BECEFA661291EB1B748A8D2CCB][1
355840 937C7908307EAB6675DC0D9586F
0F107A15EA534
]C:\WINDOWS\SYSTEM32\DHCPCORE.DLL
[9F5AC03F5A0000DD96FA29CD68A6605B][1
31744 8F0808A5B7427C8BC3AB435D34F
D4DC41EEA14F4
]C:\WINDOWS\SYSTEM32\DIAGSVCS\DIAGNOSTICSHUB.STANDARDCOLLECTOR.
SERVICE.EXE
[15D174719872A30F2FDD6B5B1B8BA5D9][1
1613664 B822D20322D61E1F52B31F6E41A
D370B538E7240
]C:\WINDOWS\SYSTEM32\DIAGTRACK.DLL
[9513834DAC717444F04169EA5D120885][1
18784 8DC2C41D4476CC401A8A464A91E
1DAAA2AA865A9
]C:\WINDOWS\SYSTEM32\DLLHOST.EXE
[5EF8EC71A7A91F3DF7798BEFE6786B0E][1
57856 46AABBA0B4883308B17D664DD5F
2F5BC63284A19
]C:\WINDOWS\SYSTEM32\DMWAPPUSHSVC.DLL
[5839A317C25F70979433E0905DFABB1B][1
284672 427BD25C8FA5DF3B96B8EBC942E
7F8ED02466E1D
]C:\WINDOWS\SYSTEM32\DNSRSLVR.DLL

[1B15297A3A2CAB6BD586676154F389D8][1
264704 162244B71BA822D5969F4A7022C
45A60C350FB35
]C:\WINDOWS\SYSTEM32\DOT3SVC.DLL
[316C2D8B8E3C0727969F1C3790EF7193][1
170496 AEA1605259DD05B6DD13FFFAB81
9B705CB8FB222
]C:\WINDOWS\SYSTEM32\DPS.DLL
[DF1C3D7E6C7929AD83BE22852B5B08CB][1
235520 14E923C298984B21EEB552DF3B6
F958CB3D57FCD
]C:\WINDOWS\SYSTEM32\DRIVERS\1394OHCI.SYS
[2C5B3035B86770ADD2FE9BFBAF5B35A4][1
107360 24C1A838A6D77D84295069A6A04
53FACE7C4D4F3
]C:\WINDOWS\SYSTEM32\DRIVERS\3WARE.SYS
[469441BAE3FF8A16826FC62C51EF5E18][1
563552 5E9482E4344E0D0C30F572BEA1E
625B8A9E35D3F
]C:\WINDOWS\SYSTEM32\DRIVERS\ACPI.SYS
[7EADED8087C392876521F7EBCE846EF4][1
127840 ED00E99FCBADF6825A92366888B
A7DC57151E626
]C:\WINDOWS\SYSTEM32\DRIVERS\ACPIEX.SYS
[C498887123327CDFD73A05E7A2780920][1
12288 B04180EE6E8ED5F3360D3189E19
03422327B6936
]C:\WINDOWS\SYSTEM32\DRIVERS\ACPIPAGR.SYS
[C8DBE6EFFCF014CAA010B9BDDAC833EC][1
14336 5D395DF0C0FDBB3D1D8E653AD42
EDB857C425C69
]C:\WINDOWS\SYSTEM32\DRIVERS\ACPIPMI.SYS
[17039DBEB3B7B9ADCDB4B4533AA9771F][1
12800 21540E382CE68D01C8298EA7D79
6835D65C44859
]C:\WINDOWS\SYSTEM32\DRIVERS\ACPITIME.SYS
[E13DE7CD2B62254DD4FF658B7798A37D][1
42328 0B560521B13C247D7429A6E01FA
320B6B8EE0221
]C:\WINDOWS\SYSTEM32\DRIVERS\ACPIVPC.SYS
[F7D0CD345D2DA42E7042ABCD73662403][1
1135456 EC6C91F13085DC4223437196CB5
A9794CFBBC12E
]C:\WINDOWS\SYSTEM32\DRIVERS\ADP80XX.SYS
[70148EFA9A562E7185B75BBE7D376BF7][1
578912 DA83D4AC1DE857D1BD1312C6588
03140AEBBECB4
]C:\WINDOWS\SYSTEM32\DRIVERS\AFD.SYS
[E15A9CE1E2E7D1C8DF97A4FC1FFE6289][1
105472 595B79F264FABECBE51657A1836
8E0DF4102C036
]C:\WINDOWS\SYSTEM32\DRIVERS\AGILEVPN.SYS
[870F1A2C936F92B5D053DF7EC75B352F][1
63328 FEEFAE5B081B0CA43FBF6E2CF98
865DF5ECFE2B5
]C:\WINDOWS\SYSTEM32\DRIVERS\AGP440.SYS
[3DF7751D5DC6525E7DC6617FBB45054F][1
218624 F0CE4B9CF2BB8F54CD0AD8F6F60
23515B066FCD0
]C:\WINDOWS\SYSTEM32\DRIVERS\AHCACHE.SYS
[B70F0F2F54B4A4DB6E9C830454752F5A][1
121856 57E332E01135873EC90DFD1D4BF
66C306C11A8BE
]C:\WINDOWS\SYSTEM32\DRIVERS\AMDK8.SYS
[35E890482C9728DD5C552B85DA8A5AB2][1
119296 B1AAAEBC223CB026AC510F872C2
D2A5BA65CC671
]C:\WINDOWS\SYSTEM32\DRIVERS\AMDPPM.SYS
[5B30BCFE6E02E45D3EE268FF001BC5E0][1
83296 8703EFADB556DB450659AAA948D
08855EFD1B218
]C:\WINDOWS\SYSTEM32\DRIVERS\AMDSATA.SYS
[F20B30F35A5C7888441B4DCA001ECF8E][1
259424 79D271D9DAE58530B0BFE02F99D
73CE8911AE114
]C:\WINDOWS\SYSTEM32\DRIVERS\AMDSBS.SYS
[AFE838D7576C581D6483529621AB10CC][1
26976 1DA85AC7BE8C8A6E8F7786A8883
5C0940DA1F0BB
]C:\WINDOWS\SYSTEM32\DRIVERS\AMDXATA.SYS
[EDDB0D726DBECDFC1DBCC6DB464E5A13][1
146272 6F03774975FE7F161F3E3EF914A
A27DD7387F01F
]C:\WINDOWS\SYSTEM32\DRIVERS\APPID.SYS
[E3FE8F610B1CC12BC3B2E6BC43DC97E2][1
131936 2BA069AA76528C01CAA8918996B
3FCA946BC262F
]C:\WINDOWS\SYSTEM32\DRIVERS\ARCSAS.SYS
[5E00748A1AD246CAECBBB7553BED36CC][1
28160 4BD2F52681B7EE435BBC505F671
BEE7F4CA79149
]C:\WINDOWS\SYSTEM32\DRIVERS\ASYNCMAC.SYS
[492B99D2E3D5D7BFD5F0AE1BE7BD37DD][1
28512 130059987C4F966448F4EFEDDDB
C547DE3865246
]C:\WINDOWS\SYSTEM32\DRIVERS\ATAPI.SYS
[B4AC08B1D04D0CE085435E5CD0E663C5][1
55808 CFC03B6E9D013C21C1652C82053
1DB382F8B83AA
]C:\WINDOWS\SYSTEM32\DRIVERS\BASICDISPLAY.SYS
[25B5BB369DEE2BAE4BF459C978FF9035][1
41472 396F2F7E0048EF841E090ED7306
65EE5DD41783A
]C:\WINDOWS\SYSTEM32\DRIVERS\BASICRENDER.SYS
[3F5523DCEFE42B385659C5CB46A6B810][1
9728 B682D88DAFB083EFE74A6853F6B
90C7B8753CE73
]C:\WINDOWS\SYSTEM32\DRIVERS\BCMFN.SYS
[0B750A6A6D847E73CA48ADD7A0F5A393][1
9728 4A5A71A74E9A0E1138B805DFBCF
4A12D46D2C0E5
]C:\WINDOWS\SYSTEM32\DRIVERS\BCMFN2.SYS
[DA2C6F7ACE392193C424FEA975C5BFFB][1
105984 37B7C1B6A9E6C8792BD0FDE780D
FCC1D612218D5
]C:\WINDOWS\SYSTEM32\DRIVERS\BOWSER.SYS
[A4411C522D41707D5BCA817A5BB9E30B][1
114688 23451499AC3CC80E3E8378C7D3E
A56F3E4A85831
]C:\WINDOWS\SYSTEM32\DRIVERS\BRIDGE.SYS

[CAEC7BC11AF69A181AF7932E636E09E4][1
43008 1FD0E97E605E2F6238B5339F7B4
95154939F25FA
]C:\WINDOWS\SYSTEM32\DRIVERS\BTHAVRCPTG.SYS
[3C7DE7B7CAD633CD2DA07710BC17361C][1
112640 F11D77842EFF7D24FB3BCE63200
D9195670FE241
]C:\WINDOWS\SYSTEM32\DRIVERS\BTHENUM.SYS
[5F2B4B32E986C058525D3BA2A475A16C][1
65536 ED3992C12A88C64B1CBACF0622A
53DCD8AE01D4B
]C:\WINDOWS\SYSTEM32\DRIVERS\BTHHFENUM.SYS
[5406289E8AE2CB52FC408154E0A64BA7][1
30720 FB287BCF9647173DB7366CA8F3D
C479A36738BAC
]C:\WINDOWS\SYSTEM32\DRIVERS\BTHHFHID.SYS
[3B3BF88BB54CB9A18DE1EF07292B5A3D][1
245760 81D4B47CCC9A3D44C2364407ED7
DB8E9950CFA31
]C:\WINDOWS\SYSTEM32\DRIVERS\BTHLEENUM.SYS
[A76F20CCCA31895A1DA78A875E50F946][1
65536 5EB22B343650BA36BE868709D54
D46C06291FF82
]C:\WINDOWS\SYSTEM32\DRIVERS\BTHMODEM.SYS
[09C3DB1B137B269A822F941D867A6BB6][1
128512 BFFDE7ED455EAC44E2CF59C072E
BAC48875E98EE
]C:\WINDOWS\SYSTEM32\DRIVERS\BTHPAN.SYS
[FFB773E4AA55E4F5FBBB084B41D7A86F][1
954368 6EB2A141E31DB37019F1FDD3FE2
72F3C66FE079D
]C:\WINDOWS\SYSTEM32\DRIVERS\BTHPORT.SYS
[BE265ABFB467BBAC8C73A55AD94F4216][1
84992 DD776DAC1706187F45F687B6C63
4E2D25AB20AAB
]C:\WINDOWS\SYSTEM32\DRIVERS\BTHUSB.SYS
[BF89BDBA5D3A0B4256D3F6FC8D31880D][1
37376 B004E8FCB1A6B6F01256B433D5C
816F25F9DC850
]C:\WINDOWS\SYSTEM32\DRIVERS\BUTTONCONVERTER.SYS
[6447BA6FA709514B6C803D159B4C7D1E][1
531296 2578107F3F53B6DEE35EC9F26EE
8BDA2BA66879A
]C:\WINDOWS\SYSTEM32\DRIVERS\BXVBDA.SYS
[C24C27FDF93B85A4EFCF25F830253AA2][1
117248 ECE7846B241DA9F57F56B3821DB
865FE58499745
]C:\WINDOWS\SYSTEM32\DRIVERS\CAPIMG.SYS
[7F9C7226D743B232907ED2537B8A574F][1
92672 542CF1CBD624B0CF64C340BFB42
68218CFE14C09
]C:\WINDOWS\SYSTEM32\DRIVERS\CDFS.SYS
[82D97776BF982AA143BDC7DFB5054EA8][1
173568 9EA90ABB07454220A9E2AC02C10
EF3C4C8EF0189
]C:\WINDOWS\SYSTEM32\DRIVERS\CDROM.SYS
[0505C1D991D0F9D47F3353BB98597C7E][1
48640 DBBF638B2D4CE5CD3F63BEF88CE
83AF850D27704
]C:\WINDOWS\SYSTEM32\DRIVERS\CIRCLASS.SYS
[8B4B39C507ABA09AAFE8E3932D1B392C][1
385376 F6081F6563A8A9C8B8647AAF7E6
A45D5898E368F
]C:\WINDOWS\SYSTEM32\DRIVERS\CLFS.SYS
[B2A6D2A30E93B6F215F74AC7E1733C9C][1
389816 F92E1CD19F80D9911ADD22A7D78
75E0FC5BCDAAA
]C:\WINDOWS\SYSTEM32\DRIVERS\CM_KM.SYS
[95832B049E2833B9F5189823CDF946C7][1
29696 572A17F882F45448FD270EECFD1
C429CA0726B91
]C:\WINDOWS\SYSTEM32\DRIVERS\CMBATT.SYS
[3F7C80D9F16B94367646CBF8B8C052F4][1
604928 223D20E679E42E4B3513E2F4068
DA9BCDAE74B9A
]C:\WINDOWS\SYSTEM32\DRIVERS\CNG.SYS
[58D640BC2294C71BDE0953F12D4B432F][1
39264 913C1093A9BAAEDAA3E0D13CBEC
EEAD0EFAA1B1A
]C:\WINDOWS\SYSTEM32\DRIVERS\CNGHWASSIST.SYS
[02B8E49148DE5E0A2F6FDF28CE94A6AC][1
50016 230E1A162E50B7E1549A93E2686
D6C90BD443C16
]C:\WINDOWS\SYSTEM32\DRIVERS\CONDRV.SYS
[5D578EAAFB6FD4F59523E5878B541296][1
553472 3052A118C709D673BFF1EC1BBFE
4FB1ABBE3D9CC
]C:\WINDOWS\SYSTEM32\DRIVERS\CSC.SYS
[2619DC483579DB9FE804044C1ADFFD1A][1
61280 3753D8958CD5F10227465CC1262
D88F674C00A53
]C:\WINDOWS\SYSTEM32\DRIVERS\DAM.SYS
[935823F79CBEDB91637B63D37E3A5A36][1
148480 B713EC99F5D1271C02944474415
4E6EC3C520E8A
]C:\WINDOWS\SYSTEM32\DRIVERS\DFSC.SYS
[4904B152E4942BF700F2D73228B4D477][1
103264 2755E0C15518B456677F6834A5D
AE2D12B89DEE0
]C:\WINDOWS\SYSTEM32\DRIVERS\DISK.SYS
[0197AE4B9790A4E73751CACFAA480126][1
33792 EF27F6D3444647707F70D41B022
12B05156098C8
]C:\WINDOWS\SYSTEM32\DRIVERS\DMVSC.SYS
[4310841C9B6773A4F01D6057710BA145][1
41976 097D252FF7D6A00971FD687E92D
2C77B8A04EEBD
]C:\WINDOWS\SYSTEM32\DRIVERS\DPTF_PCH.SYS
[25FA06D3B49D6ADF8E874FFCDCD76B50][1
16168 83404B90BCF3492B27E8A219B52
A4025AAC8652C
]C:\WINDOWS\SYSTEM32\DRIVERS\DRMKAUD.SYS
[8B83335B6A86F39785FC7C9DE5F5B29F][1
1996640 E6331CF5F6585FA742C73226BD5
120E0FD278E49
]C:\WINDOWS\SYSTEM32\DRIVERS\DXGKRNL.SYS
[CEF108FCE06892CFA5F1B49527D4BF49][1
88416 7E60B71EED925C01CE92D0D271C
4E2BA2279C1E8
]C:\WINDOWS\SYSTEM32\DRIVERS\EHSTORCLASS.SYS

[5B1EAAE3001A7A320C106FC3859F4111][1
117088 D96507E4FD222D16EEEBA524A09
26B012A4B66CA
]C:\WINDOWS\SYSTEM32\DRIVERS\EHSTORTCGDRV.SYS
[7A2705148A4BB3CA255F81624338B461][1
12288 A505486F9967C3E788B7AEDE93F
07D765385758D
]C:\WINDOWS\SYSTEM32\DRIVERS\ERRDEV.SYS
[491275B864B704B54EC08168344E0F38][1
3436896 2734DBC3606AFD26511283E8AED
9E7A12BF4ED3C
]C:\WINDOWS\SYSTEM32\DRIVERS\EVBDA.SYS
[F003B437645009FDA04AB266EAD240EB][1
72808 7A6A7B47F4D82B1B5F88B0AF5D9
6633433187FCE
]C:\WINDOWS\SYSTEM32\DRIVERS\FASTBOOT.SYS
[9D299AE86D671488926126A84DF77BFD][1
32256 E7108D95FCAEDE829000F4033A1
C774C90647104
]C:\WINDOWS\SYSTEM32\DRIVERS\FDC.SYS
[8F2523C9D8F1448FF2156452AF60FA00][1
87552 6A9C39C160B9664B2E3B77B8B55
AA99975D4BCAF
]C:\WINDOWS\SYSTEM32\DRIVERS\FILECRYPT.SYS
[92ECCFA58C8195B8EA33ED942469D4E6][1
85344 F01001F021B8728325EE21AB698
08B4D96921EF4
]C:\WINDOWS\SYSTEM32\DRIVERS\FILEINFO.SYS
[87C51FDD50C17882BA93E28BBABB9847][1
35840 C2B27ACDB6F09D550F503DDC8E8
048EE66B8DA64
]C:\WINDOWS\SYSTEM32\DRIVERS\FILETRACE.SYS
[E99261DD76D1C9E05AF575939CAE5AC5][1
26112 46204580E4B4444AE67D975196E
2C99FF7FAE7DF
]C:\WINDOWS\SYSTEM32\DRIVERS\FLPYDISK.SYS
[25D7A58625E1453E40D36825DE74E4F1][1
377696 6EA30CAA244BB745DAB8D1D80B3
48591DF666F95
]C:\WINDOWS\SYSTEM32\DRIVERS\FLTMGR.SYS
[B4175E8BE60B099686FF55CA7D692316][1
62816 58D2C4A429CB81DAA17360E1CD3
1518ED38FFA94
]C:\WINDOWS\SYSTEM32\DRIVERS\FSDEPENDS.SYS
[50DFE05C698E9B0A63D95E3D669A105C][1
638816 C4DB3F6359B55E3F5CB7D444713
74AD8D0777563
]C:\WINDOWS\SYSTEM32\DRIVERS\FVEVOL.SYS
[B9981A4CB9F728B3312A3885BFAA7204][1
66912 EAE2C41DBA743608C5A92A9FCDF
DBAA28F1E9BC1
]C:\WINDOWS\SYSTEM32\DRIVERS\GAGP30KX.SYS
[F3AC9652D88BF87BA6596CBEA28CE10F][1
20992 F2CD034B837ACF1C07A3A260C7A
A2A9E59ACA2D0
]C:\WINDOWS\SYSTEM32\DRIVERS\GENERICUSBFN.SYS
[D011B0ADB15F4815310CE1BF4780B33E][1
8192 2A38FCBA8ACE617D57D4D5DEAD0
9D7D156438D0B
]C:\WINDOWS\SYSTEM32\DRIVERS\GPUENERGYDRV.SYS
[84BC034B6BB763733C1949B7B9BAF976][1
79872 F13F065CCAEF9D8C208212DAB2D
61CC93DD7F386
]C:\WINDOWS\SYSTEM32\DRIVERS\HDAUDBUS.SYS
[0F93EBE9071A6BB1548BF0F816EEA24B][1
404480 BDAF6F9698E0D1246354C8748C3
5FD9B3758D3AD
]C:\WINDOWS\SYSTEM32\DRIVERS\HDAUDIO.SYS
[6B8CB114B8E64C0636EB49F7B914D1FC][1
28160 1B6402D505B66E73ED207463769
E2E35B68DAFF4
]C:\WINDOWS\SYSTEM32\DRIVERS\HIDBATT.SYS
[D1AD197CCDAAC0CB4819DA1D6EB17BAE][1
107520 5EF0622A0D6ECCBD0855982395B
14690305AE63C
]C:\WINDOWS\SYSTEM32\DRIVERS\HIDBTH.SYS
[64909DECCFCC6FB5D9A5BAFDCCB31FEE][1
51200 8E82457A1443AD2F07C4D0805E2
8A08085E6BEAC
]C:\WINDOWS\SYSTEM32\DRIVERS\HIDI2C.SYS
[F510F7B7BF61DEAAC04E65C3B65E8D59][1
50016 2831EEB6A089F0FDC667CEC2C06
CC54EF0138FC1
]C:\WINDOWS\SYSTEM32\DRIVERS\HIDINTERRUPT.SYS
[90F3ED42D423C942BA5EA54E2FFE7AC7][1
46592 457E5A7DA3AE9AC9B28CEF13520
B711B91F819FD
]C:\WINDOWS\SYSTEM32\DRIVERS\HIDIR.SYS
[128DEDDD61915DBA4D451D91D21F0513][1
38400 48F4F194750B132D0A095A01891
9211CA6FDBBCF
]C:\WINDOWS\SYSTEM32\DRIVERS\HIDUSB.SYS
[FF442DCDCE1F6E9FAA9C8AD0CD1D199B][1
64352 17DC4AB7D77ADBE8203F1FD8D2B
236A978DEB86C
]C:\WINDOWS\SYSTEM32\DRIVERS\HPSAMD.SYS
[63C3F74DC398A1C1A77E39DFB9C312CA][1
1089888 EDC5B79C7C84F71F74694061510
230A33E26BD75
]C:\WINDOWS\SYSTEM32\DRIVERS\HTTP.SYS
[CBA5E88A0F0475B7F49653BB72150BEF][1
29024 DDFE0E9361E79DDF943AB5A5000
52C6124B0A706
]C:\WINDOWS\SYSTEM32\DRIVERS\HWPOLICY.SYS
[D668FAB4B0397B426EE3D41683B9A1C0][1
16896 0AC0A88303BC1B296527A78917F
EDD167036126D
]C:\WINDOWS\SYSTEM32\DRIVERS\HYPERKBD.SYS
[53FDD9E69189E546DE4740F8C4D8AB2F][1
114688 779D23CC7D5FA1B358715CD6676
0B10A5AF39DF8
]C:\WINDOWS\SYSTEM32\DRIVERS\I8042PRT.SYS
[9A2A2F3C69B9A30B6E78536F6D258BAD][1
81408 C5C81A8D87A58E144408BB89D2A
A557391385770
]C:\WINDOWS\SYSTEM32\DRIVERS\IAI2C.SYS
[8FD3487A6AE70321404C34AC278840D8][1
46856 65B6D47C40CDA9770A75BB7C696
10809CF39875F
]C:\WINDOWS\SYSTEM32\DRIVERS\IALPSS_GPIO.SYS

[4D962133CAB3A8555E7B1FD8D6BF38EA][1
132360 370958A277FFD0EAF30B4E45E6A
F4FCE44B0AB60
]C:\WINDOWS\SYSTEM32\DRIVERS\IALPSS_I2C.SYS
[59A20F5AD9F4AE54098154359519408E][1
165888 C69AB6548A12418F4FB9A4AC94E
BB54D98F6FBA3
]C:\WINDOWS\SYSTEM32\DRIVERS\IALPSS2I_I2C.SYS
[16A10CCEDCF5AC4CAAE43DC9FC40392F][1
38128 F9C70BDC52A485F1577372D828D
CC75824A52711
]C:\WINDOWS\SYSTEM32\DRIVERS\IALPSSI_GPIO.SYS
[EB82A11613326691508D9ED9A4FE29E7][1
113152 B226F7E4189BF32E6159BBF54C3
04753E6610633
]C:\WINDOWS\SYSTEM32\DRIVERS\IALPSSI_I2C.SYS
[5F6CA62BE8ECC4D0E1F5D4D4A02B456B][1
1462720 273109F90CC7A03140FF4C3AF64
2DA6364BBFBA3
]C:\WINDOWS\SYSTEM32\DRIVERS\IASTORA.SYS
[6B0029A0253098CCE28EACCFDB9E7208][1
673120 B815BFB3AA7B3364E6D93AFA3BD
AC809758E4780
]C:\WINDOWS\SYSTEM32\DRIVERS\IASTORAV.SYS
[9652E1E35A92D8C75710C17A63B15796][1
412000 CE74C17644A3468E44418F9C44B
ABFBCFF6819F5
]C:\WINDOWS\SYSTEM32\DRIVERS\IASTORV.SYS
[FFADF691F7BF727AF5C863454A372723][1
424800 BF2CB7FDC237C82F9198880015A
3CC3C1A88BEC2
]C:\WINDOWS\SYSTEM32\DRIVERS\IBBUS.SYS
[94F952B4B0E440C9562FC8074D52BC4B][1
255728 932A5694D161E42B8C8747470D9
8E2B104D231DD
]C:\WINDOWS\SYSTEM32\DRIVERS\IBTUSB.SYS
[657224010BED3776D669391E313C0F5E][1
6261688 34B01F04C04A71A2992A154EFA9
69280DFADB1F5
]C:\WINDOWS\SYSTEM32\DRIVERS\IGDKMD64.SYS
[907C8FE6894710604AD1F1F92324A7D6][1
464144 8724EE084578E6E3E85A45EC4A3
3AC668FDD69E4
]C:\WINDOWS\SYSTEM32\DRIVERS\INTCDAUD.SYS
[ECDB27420D3A98424666904525A8562A][1
19808 4E7873D8D116D4DF58683376788
8187C1302B503
]C:\WINDOWS\SYSTEM32\DRIVERS\INTELIDE.SYS
[63C827AAE9117D8EB9C4AF4621797996][1
18720 1F8606EEA454F67AA26AC7D4DAF
68BB1E189C03A
]C:\WINDOWS\SYSTEM32\DRIVERS\IntelMEFWVer.dll
[8FF1978643EFD219C5BA49690191D701][1
46432 BEB676448D34FA8C05AD13F4C7E
E5E45C561F9F4
]C:\WINDOWS\SYSTEM32\DRIVERS\INTELPEP.SYS
[B61B60F36E1C8022FA8166ABF0F66B07][1
133632 B101434550DE5B26E8A95CCF9C7
C92B9E25B6165
]C:\WINDOWS\SYSTEM32\DRIVERS\INTELPPM.SYS
[CA0D42029AFFC4514D295E1EF823D02D][1
26624 FDA005BD6A8683AA0054F1E25AA
92059EF402FB9
]C:\WINDOWS\SYSTEM32\DRIVERS\IOQOS.SYS
[6E3F9D95235DFC9417384080A216F310][1
85504 2655716C5FB0FF2FF36F32F1708
57FFCAC7AA388
]C:\WINDOWS\SYSTEM32\DRIVERS\IPFLTDRV.SYS
[4F527ECB5EAB47D8EAF34A469666C469][1
81408 88B4D82216351E2EB921821DFB4
5C2F24D4DD492
]C:\WINDOWS\SYSTEM32\DRIVERS\IPMIDRV.SYS
[9E5E8F2A1996F23B7E9687846AA81B01][1
143360 D0E803AD48B37B709A600DFB61C
C5DC852131C17
]C:\WINDOWS\SYSTEM32\DRIVERS\IPNAT.SYS
[C317EB660138BC9CBFE37CCDE56351AE][1
19456 0E81954BCC7F1DCB541F8C5A55A
C32CD3C029521
]C:\WINDOWS\SYSTEM32\DRIVERS\IRENUM.SYS
[531994A6D9399D9B74BE12B5BB58A81E][1
22880 EF9723AED1CF4D743DA6D523F75
4AD82456E18BB
]C:\WINDOWS\SYSTEM32\DRIVERS\ISAPNP.SYS
[701D7DB13B0815E7076EF4CB4CE981F8][1
62304 7127B3D88ECE9F5A9EFC10CFE83
512A42B9350E2
]C:\WINDOWS\SYSTEM32\DRIVERS\KBDCLASS.SYS
[884EBBDDBF5968003B40185BD96FF0E6][1
36864 69DD25C0588F1318CE5EE4323A6
8E0D04C103A9B
]C:\WINDOWS\SYSTEM32\DRIVERS\KBDHID.SYS
[6B3A0C7902811E6372643447E41F7048][1
23040 184209CAF24740ED8B0C8EFA91F
6D7FDBA2049D4
]C:\WINDOWS\SYSTEM32\DRIVERS\KDNIC.SYS
[62EBD4202B505ACADE2FBC56CC73E0A2][1
478392 C5E148CCBC126B21913E88DCAA1
94DD28BB71EE0
]C:\WINDOWS\SYSTEM32\DRIVERS\KL1.SYS
[86F40D79CE80ACBE6BEBAC8CE89D75A0][1
53432 A8740707E5C85DC57928B6A8DE4
563E04B86FB40
]C:\WINDOWS\SYSTEM32\DRIVERS\KLBACKUPDISK.SYS
[1B321722C507A04E1EAFCFFD0F7B7EF9][1
79752 A87B39AB38A148CA9F925D8A2B7
4DCA543C57A06
]C:\WINDOWS\SYSTEM32\DRIVERS\KLBACKUPFLT.SYS
[B12242478186B62B2E214288B7DB3612][1
78200 6821C3319115B770E54E7B0A4BC
7FF0DD7DFA022
]C:\WINDOWS\SYSTEM32\DRIVERS\KLDISK.SYS
[E2097C8F18F1E8E3B7D09F12B51843A3][1
30328 222A6252E64D6590606534C742D
3EEDADBEAA489
]C:\WINDOWS\SYSTEM32\DRIVERS\KLELAM.SYS
[C64655B935BCBB5AB39F87F79F5087A6][1
182664 A261E917B473ADF89A8B9DC1BA1
9D67776320707
]C:\WINDOWS\SYSTEM32\DRIVERS\KLFLT.SYS

[E06446CAB518D66247E8042B3FDC6CDB][1
237488 DE68646FD08C8CD84A88886D481
BB61CF6A813DF
]C:\WINDOWS\SYSTEM32\DRIVERS\KLHK.SYS
[D49C6C43CC00296BB942BD12764E707B][1
987568 C989DBB2902C26EB26E495C0C53
F06B583A0B566
]C:\WINDOWS\SYSTEM32\DRIVERS\KLIF.SYS
[5D9960343E6866C420727727AFBE17BC][1
51288 52367B62838BB2FBB85619ECDF1
396FF354210ED
]C:\WINDOWS\SYSTEM32\DRIVERS\KLIM6.SYS
[36E044A2C64FCBCBC0F42ED5050F9CBD][1
52608 58C9733EE1DD07BBC8EBCDE1BC6
B27080662E32A
]C:\WINDOWS\SYSTEM32\DRIVERS\KLKBDFLT.SYS
[
-2][0
-1
]C:\WINDOWS\SYSTEM32\DRIVERS\KLKBDFLT2.SYS
[FD47C92A63B6EADEA830BFA96C06EAEE][1
41656 B1A99C1536CE4A53473422D5FAB
A2C0100655673
]C:\WINDOWS\SYSTEM32\DRIVERS\KLMOUFLT.SYS
[26E1917517E613D07F2A122CEEBB8161][1
45960 7446AF5545F9123EEED1234D28B
3D31496CC2ABD
]C:\WINDOWS\SYSTEM32\DRIVERS\KLPD.SYS
[26D3895A519220E94D241A8858D40CD9][1
87944 81F48DAF6558A1CDB9EC4E243C5
F8BBE9C3BB7C1
]C:\WINDOWS\SYSTEM32\DRIVERS\KLWFP.SYS
[6B98C134815C9AB284F9DEA03B8BD5E8][1
112520 1D3C4EBF318280D9D594EC8D54C
B514BCB536C38
]C:\WINDOWS\SYSTEM32\DRIVERS\KLWTP.SYS
[58CD685752080EDAEB4EEC7E6428546D][1
194440 8EADAB530CD0F09A1E70E99213A
F5AFAD53CBFF8
]C:\WINDOWS\SYSTEM32\DRIVERS\KNEPS.SYS
[982C795DE20CED7AEDD2E7899B5D9BC1][1
129888 CF3BD7B81AD765016DDFF184C15
7150FB9090C4C
]C:\WINDOWS\SYSTEM32\DRIVERS\KSECDD.SYS
[425CFD45BDF5B9F8B790BEB20E0A8721][1
161632 30CA4A1AF657BFC81C0FFC7D3E8
99B8F83600119
]C:\WINDOWS\SYSTEM32\DRIVERS\KSECPKG.SYS
[E9BB0023D730701BB5D9839B44F5E6B5][1
26112 EB7C1E19A53711F48EB13632151
B2D82F93C38E2
]C:\WINDOWS\SYSTEM32\DRIVERS\KSTHUNK.SYS
[EC34EED89C34B27C292166B725AC7A7B][1
64000 A81EDE95FEC1C9795990B2BA2AC
09D4467E48311
]C:\WINDOWS\SYSTEM32\DRIVERS\LLTDIO.SYS
[961F28D879D345BFA50AF51285C90F2E][1
108888 890B631C79A8F37522C0469DE1E
D25E3835280A0
]C:\WINDOWS\SYSTEM32\DRIVERS\LSI_SAS.SYS
[6BFB8D1B3407518BE06B6F81F92FA0F5][1
104800 618750094FE7CE4EFFCB197F636
7CEF6B19F1FEC
]C:\WINDOWS\SYSTEM32\DRIVERS\LSI_SAS2I.SYS
[BE0E47988D78F731DEC2C0CB03E765CB][1
99168 3A860CBF83582248D402B55C789
FB53AA4C0B993
]C:\WINDOWS\SYSTEM32\DRIVERS\LSI_SAS3I.SYS
[F99BF02BE9219986817BF094981EEB18][1
82784 453E20B48AE5E07D19AF04014E9
8C6C294606477
]C:\WINDOWS\SYSTEM32\DRIVERS\LSI_SSS.SYS
[2FCF837196082864F66CFD9CAB256275][1
126464 83FC473089A78FC5D9E95507A58
EBAC7513765AE
]C:\WINDOWS\SYSTEM32\DRIVERS\LUAFV.SYS
[2ED29B635F35E31A1C0D3DDB7DD2AD03][1
59744 4BBF2AD45C8A828C97CCC8FF3C8
7B611413A2A51
]C:\WINDOWS\SYSTEM32\DRIVERS\MEGASAS.SYS
[22E3CB85870879CBAE13C5095A8B12E3][1
575840 732F8550CE539F06FB5FF43F802
5225DA7E3D7A6
]C:\WINDOWS\SYSTEM32\DRIVERS\MEGASR.SYS
[D41920FBFFF2BBCBBC69A5B383AD022E][1
705376 A218157190B75C0E82AA603E2F8
B16496D3CA67B
]C:\WINDOWS\SYSTEM32\DRIVERS\MLX4_BUS.SYS
[64BD0C87064EA20C2D3DC4199F9C239C][1
47616 A62BCB071D639E408FC1488EC7A
0426341C9C360
]C:\WINDOWS\SYSTEM32\DRIVERS\MMCSS.SYS
[8D4B46FA84A3A3702EDADD37FAC6EDBA][1
41984 019CD3F0442C645BA782D415949
417BA5AE9FCFA
]C:\WINDOWS\SYSTEM32\DRIVERS\MODEM.SYS
[78FEC1BDB168370F131BFBFEA0A04E9D][1
38400 EBBFBFF1ACF6F957CF4FE5D2E61
D2C61E202D276
]C:\WINDOWS\SYSTEM32\DRIVERS\MONITOR.SYS
[D1CC0833CFBC4222A95CAA5D0C8C78FF][1
59232 DAD7DA999D6869EC3CBBD88F9D1
279E22A458DD2
]C:\WINDOWS\SYSTEM32\DRIVERS\MOUCLASS.SYS
[C2E05EC6B80BCF5AE362DA873E1BCE64][1
32256 12D17F84B8A9B8FF5E79B1A802A
8C3C53E40ED6F
]C:\WINDOWS\SYSTEM32\DRIVERS\MOUHID.SYS
[D5B7668A8F6C67C51FA5C6C513396D6C][1
102752 C8EDF587DCF070269FB2E10DBF5
177E8AF12F1EE
]C:\WINDOWS\SYSTEM32\DRIVERS\MOUNTMGR.SYS
[5FBCB85D127BE21E3A9DAF11A13C00EA][1
76288 A1279BC66854D2595C02088A62D
784C845B4457D
]C:\WINDOWS\SYSTEM32\DRIVERS\MPSDRV.SYS
[BF6CA7EA5ECD6CF72D3D76652A9B8280][1
144384 56BC1ECE4AA87C3FF15FBA38C7E
B2059670932F7
]C:\WINDOWS\SYSTEM32\DRIVERS\MRXDAV.SYS

[0B3B0C1D86050355676640488FA897D3][1
430944 5B330ACDB14F3EEB496B3CB47B4
F077F09B6AFBB
]C:\WINDOWS\SYSTEM32\DRIVERS\MRXSMB.SYS
[1A490555FD330CA2764D89191177C867][1
285696 20550914D1E3A4D99791B7D0418
D136E835C1FB2
]C:\WINDOWS\SYSTEM32\DRIVERS\MRXSMB10.SYS
[0F47A6C09F0A7FB5513D322A2B9BE4EC][1
216408 3B33EBE8CBB906F4D51C9EFB480
31716D329941C
]C:\WINDOWS\SYSTEM32\DRIVERS\MRXSMB20.SYS
[F802FBABF0C4DF1BAA733187B2E476F5][1
163680 EE040393977CD20F2A239302AD3
64F90B82FAA30
]C:\WINDOWS\SYSTEM32\DRIVERS\MSGPIOCLX.SYS
[B3358F380BA3F29F56BE0F7734C24D5F][1
46944 2DF472C2725F715A744512E6C5E
8E7DB94916F00
]C:\WINDOWS\SYSTEM32\DRIVERS\MSGPIOWIN32.SYS
[B2044D5D125F249680508EC0B2AAEFAC][1
8704 96A2A638A2D405E0F7A0D37C737
525B71FA48933
]C:\WINDOWS\SYSTEM32\DRIVERS\MSHIDKMDF.SYS
[36ABE7FC80BED4FE44754AE5CFB51432][1
11776 BBC29BBE04C6C7FE4DA6CE2CCE8
1A87CAF74ED04
]C:\WINDOWS\SYSTEM32\DRIVERS\MSHIDUMDF.SYS
[59307FEAFC9E72EEEC56B7FD7D294F4C][1
18784 F5E6D6DC8027C9F70FFEC04AE3C
56284B1B09485
]C:\WINDOWS\SYSTEM32\DRIVERS\MSISADRV.SYS
[68D5354A4A9692EEC24664C60F47D4A2][1
277344 AFBDB88CEDA17CF72041351AA6D
DBD9D8191B0E9
]C:\WINDOWS\SYSTEM32\DRIVERS\MSISCSI.SYS
[E9457EDFEBC774199F907395C6D09CA2][1
13824 F51D31C523A590533458760D816
3ABD61D4FBAD9
]C:\WINDOWS\SYSTEM32\DRIVERS\MSKSSRV.SYS
[C85D79735641D27C5821C35ECDDC2334][1
81920 E46C06473C3E6A903079DF8E4FF
A96BBA148E1DE
]C:\WINDOWS\SYSTEM32\DRIVERS\MSLLDP.SYS
[EF75184B64356850D0F04D049C253526][1
10752 185DABC0354CD0360AC5EFD7EF2
51D7CA407A5ED
]C:\WINDOWS\SYSTEM32\DRIVERS\MSPCLOCK.SYS
[543933D166C618E7588EA77707EC1683][1
10752 EFAF45801D84A00D19AC4D87640
DB0CA8EB17DB7
]C:\WINDOWS\SYSTEM32\DRIVERS\MSPQM.SYS
[E887FFDD6734C496407E9219225CB6FF][1
43872 2A0CACAF92814ECF4DFC98876BB
CFB109D6FBBC8
]C:\WINDOWS\SYSTEM32\DRIVERS\MSSMBIOS.SYS
[83A2AB75951000D681FABDB80C07AEFC][1
12800 C552E61852346E4328AE56863FB
4E1C786FD548B
]C:\WINDOWS\SYSTEM32\DRIVERS\MSTEE.SYS
[4FA0483896FC16583851EFB733FCB083][1
15872 377D9A2D4EEA57942EC1D025A6F
77E5205B8B51A
]C:\WINDOWS\SYSTEM32\DRIVERS\MTCONFIG.SYS
[60F88248608315E13391C2F1C3B4473F][1
124248 6D13709BE4E5714CA1FC6CBF66E
82CCFC6EFB564
]C:\WINDOWS\SYSTEM32\DRIVERS\MUP.SYS
[218705233D02776AE4D19CC37D985C1B][1
63840 68361604DF509A34CDAAE8241C6
3B02F3B73900C
]C:\WINDOWS\SYSTEM32\DRIVERS\MVUMIS.SYS
[B57CE307DA101C739885B7CC0678077F][1
76128 C837E21E7F57E1F2D7D4658245C
7AAF58DCF075C
]C:\WINDOWS\SYSTEM32\DRIVERS\NDFLTR.SYS
[E582DA849A58524E645545FB68B6625D][1
1152864 94A5E18DDB2FB64A62411774A40
C855BCAC1EC63
]C:\WINDOWS\SYSTEM32\DRIVERS\NDIS.SYS
[202260E7CDD731A32AF62ABD1ABEE008][1
50176 FC4570521FC5A6E2E765792456E
38F59F4FBC32A
]C:\WINDOWS\SYSTEM32\DRIVERS\NDISCAP.SYS
[A1D473D0CF10561F29B58EA7C5412A92][1
126976 7E7AEC5712A36D3A0971E420560
8A00D93334AD8
]C:\WINDOWS\SYSTEM32\DRIVERS\NDISIMPLATFORM.SYS
[1A0AE283B8DE6BB76412A0F8213D45AC][1
25600 710EC839D1091E295876F38866D
736419804C09E
]C:\WINDOWS\SYSTEM32\DRIVERS\NDISTAPI.SYS
[A74EE2D2C0BFF5EC3A6185791868C4CA][1
63488 8E3F068F875628359E575A2F80C
5C080BFFC6D78
]C:\WINDOWS\SYSTEM32\DRIVERS\NDISUIO.SYS
[32A9BD1342640D48AD85C8B3E812B984][1
20480 CAE5CE893966D6924B799758846
DA1A2A51ED62B
]C:\WINDOWS\SYSTEM32\DRIVERS\NDISVIRTUALBUS.SYS
[6A6A8CF5EE61801375A38EBB871D4057][1
188928 3D38269D3DBCE53167248BB9BA1
2FBB2713F6FE5
]C:\WINDOWS\SYSTEM32\DRIVERS\NDISWAN.SYS
[50AEF8EF0064A91ABB08D858D039C9DE][1
60928 3B391D6EF37904E8B70F6BC6ED9
7C90A012392EE
]C:\WINDOWS\SYSTEM32\DRIVERS\NDPROXY.SYS
[883A36E2FF7FA3E1281CB575579FE3AF][1
124928 54A52D70212AA46A3BFAA5C1B97
0462928F37895
]C:\WINDOWS\SYSTEM32\DRIVERS\NDU.SYS
[026618ECF6C4BEBDCB7885D42EC0DBE4][1
57184 EF3BBE0A80EF7EDC373A93E072A
B1A71FC5D0E4B
]C:\WINDOWS\SYSTEM32\DRIVERS\NETBIOS.SYS
[C03E926B0E7D66D68994067231DC3246][1
278528 4DECB51DAC07D125DA03832965A
302A1AF539E49
]C:\WINDOWS\SYSTEM32\DRIVERS\NETBT.SYS

[93F9E44D6AA0FFDE901D53CEF389AADD][1
4103920 ED98AAF256914DD0420C46BB502
0AB707B8B3246
]C:\WINDOWS\SYSTEM32\DRIVERS\NETWBW02.SYS
[29395C214D2CD4C81F73166AB988A797][1
26624 2FDDDE6BAA37EFA228930B4D8FF
3030EC7B19EDB
]C:\WINDOWS\SYSTEM32\DRIVERS\NPSVCTRIG.SYS
[2871225495F832A8C8A7DD1A17EDB3DC][1
40960 FA7A5E3D9E60C60A3F4A3A3A52F
47AF186B7C68A
]C:\WINDOWS\SYSTEM32\DRIVERS\NSIPROXY.SYS
[31F990B2B6B91E9D7A667405CE12FCB1][1
126304 574C875B939F1B63B900F0A2D03
B777935A4CC4C
]C:\WINDOWS\SYSTEM32\DRIVERS\NV_AGP.SYS
[85C3FBD47FA65313A5DA31FC1A9BC249][1
13617096 4AA0CE4399DA0AB4F52DF131980
B02F89D6F6905
]C:\WINDOWS\SYSTEM32\DRIVERS\NVLDDMKM.SYS
[604D27CC38CC23493F218D0BB834B3FF][1
150368 84CFB6673CF5AFC590EF04D6161
69A97FFC84A83
]C:\WINDOWS\SYSTEM32\DRIVERS\NVRAID.SYS
[8B50D897657AB4A15FD9E251BBF7D107][1
166240 F0B6EE3497E51DF6429003B7ADF
40B6DECE6F1C7
]C:\WINDOWS\SYSTEM32\DRIVERS\NVSTOR.SYS
[AA4CD20708B7E0412A5316D7E2875103][1
530432 086DB484EF34EF5F902428BAF76
03BFECB9ED7FF
]C:\WINDOWS\SYSTEM32\DRIVERS\NWIFI.SYS
[596FB6C5A72F34B7566930985E543806][1
160608 B271DA5FED691DC61DA7A602C22
83A6BEF7A2A53
]C:\WINDOWS\SYSTEM32\DRIVERS\PACER.SYS
[7D0FC96264C0F8F2C1321E33E8EB646C][1
96768 6DCD07D1F6590874D25317F6AC7
E3D2B6002C9C5
]C:\WINDOWS\SYSTEM32\DRIVERS\PARPORT.SYS
[032F1C32A6A97C317AEFF9D64D2A1D8A][1
40304 50D027EB8240A4C0D4610E47A91
2DC8E4D6D88E5
]C:\WINDOWS\SYSTEM32\DRIVERS\PARTIZAN.SYS
[D330D74B5F99309B5CCA30AE41C57CDE][1
118624 57FACC5A85B4213DB722ED49305
79A917EFB0DDE
]C:\WINDOWS\SYSTEM32\DRIVERS\PARTMGR.SYS
[CF78AF126B00C1B0A6FF45BD838E8EFE][1
331616 CDB3A7CBED41C235021F81565B5
14655FB745C9C
]C:\WINDOWS\SYSTEM32\DRIVERS\PCI.SYS
[2B4D98DF0CA57FB9536DBC80D2449D1F][1
16224 F3C800505794FBA0AA5143335FA
9F760F5E7B6C7
]C:\WINDOWS\SYSTEM32\DRIVERS\PCIIDE.SYS
[F4D5793BF2E58AF15C6CF2FEEF9E73EB][1
118112 021E07690E0C2C4E2AD270EA9E8
E46DFABD57155
]C:\WINDOWS\SYSTEM32\DRIVERS\PCMCIA.SYS
[22A53744CEEADFFFD33BA010FAD95229][1
51544 687ECA1BAA568F3ED6C19392CD7
0A21CEC8430E3
]C:\WINDOWS\SYSTEM32\DRIVERS\PCW.SYS
[67B9684B8272D5EBD1CCBB1DBD425EC8][1
99680 A86883723FE79A6828BE3B1CEF6
74432F37002FB
]C:\WINDOWS\SYSTEM32\DRIVERS\PDC.SYS
[9F5E27C8B88A8DA1DC93E93A5C27BB9B][1
83224
]C:\WINDOWS\SYSTEM32\DRIVERS\PDFSFILTER.SYS
[E2F8376F9731D12A009C522036C6073A][1
721408 ED710D45110ABAC755906DFEE72
3448FADF24892
]C:\WINDOWS\SYSTEM32\DRIVERS\PEAUTH.SYS
[1398A85E59698067CBBE1D66A9C13ADF][1
58208 189E4CF5C1ED2A644E99AA1D8D4
D487F82D23B57
]C:\WINDOWS\SYSTEM32\DRIVERS\PERCSAS2I.SYS
[35F7C7AD709D909D618D9EDF987FC3ED][1
58720 F3085CEEDEF3B72AE694D20851D
F1353E2DDDA8F
]C:\WINDOWS\SYSTEM32\DRIVERS\PERCSAS3I.SYS
[21AECFF3EB5748CBE12538A2500EFDE5][1
118272 9ECEF3393510947E6BAA0B38F73
200A1AE042D0D
]C:\WINDOWS\SYSTEM32\DRIVERS\PROCESSR.SYS
[CFBA9C976CBF6796E5DC39EF59984021][1
48640 BDACA6736A994A38F8A18C5DD9C
BD66D69DCCCC9
]C:\WINDOWS\SYSTEM32\DRIVERS\QWAVEDRV.SYS
[7B2AD8C55217B514C14281AB97B4E21D][1
17408 904C1DC0B4DA9EFAF477032D46E
C4125304AA5C2
]C:\WINDOWS\SYSTEM32\DRIVERS\RASACD.SYS
[E3C82823B22463BC38AA4F8ADA852624][1
104960 056DAF1BFDC9D560810B237D5D0
4C942425D4010
]C:\WINDOWS\SYSTEM32\DRIVERS\RASL2TP.SYS
[3369023EB5790A75BA7DABA14B75D922][1
81408 E16AC88812868B66ACCDC51729E
82F5C61E77CFD
]C:\WINDOWS\SYSTEM32\DRIVERS\RASPPPOE.SYS
[5BA6B9AD03B81546BA64E488C4EF9D17][1
95744 4B6964A2EF3B01188A343886431
DC64C4BAE04CF
]C:\WINDOWS\SYSTEM32\DRIVERS\RASPPTP.SYS
[1E32A8CD65C4AD0A827CFEB13034DA29][1
78336 484D0D8888AB39276C892625B4F
B818C70811022
]C:\WINDOWS\SYSTEM32\DRIVERS\RASSSTP.SYS
[2B648363E4C5E34B469C58596F377DD9][1
422752 D9EFF4F0FFBAAC9C4FC99BBD970
7174102E15BD9
]C:\WINDOWS\SYSTEM32\DRIVERS\RDBSS.SYS
[D0221C13960E274CC539D72D5A842ED0][1
26112 B2D197BC0CF0ABD958D48CB0662
020E1684C73ED
]C:\WINDOWS\SYSTEM32\DRIVERS\RDPBUS.SYS

[1DC2CC74B51E4DC4CD5A20C1021E4010][1
173056 E718CD6953177A58D16853B5E05
023CE2730A9CF
]C:\WINDOWS\SYSTEM32\DRIVERS\RDPDR.SYS
[177DF954D0DEC0465A380C75F6E7F65F][1
29536 3931893BEACF8D05B1E938C9C60
883F2B4D29E8F
]C:\WINDOWS\SYSTEM32\DRIVERS\RDPVIDEOMINIPORT.SYS
[5D1680871054D2B0B8A971BC8AB3B837][1
236384 F7E02F56582DFD467ABC021D6F2
EE87DD76FA71F
]C:\WINDOWS\SYSTEM32\DRIVERS\RDYBOOST.SYS
[AEEF76F938188EBF27DF70C1806877F2][1
181248 8B6FFDE4CE15C4430807DF8E5DA
5B9E58E3FC1AB
]C:\WINDOWS\SYSTEM32\DRIVERS\RFCOMM.SYS
[0AC5FCDC29ED97ECDEF1276425EE2059][1
80896 EB52EE0BEDD350A29C749398507
FA168ED0A3BBC
]C:\WINDOWS\SYSTEM32\DRIVERS\RSPNDR.SYS
[12A3D1530E3F67B8664EBA923A3981E4][1
886528 8403F87196117C45A99FB1AF26D
A5F5C6A12E297
]C:\WINDOWS\SYSTEM32\DRIVERS\RT640X64.SYS
[73D45AF87AD38A24CD9EA7834324D41C][1
4592384 E8636BB3EAEC08A2F2F193EBD14
78B8E1A8808B1
]C:\WINDOWS\SYSTEM32\DRIVERS\RTKVHD64.SYS
[924449B5A5A6AC96BBBED49915E40719][1
3049176 5DDBB13BE605FBD4944500E0F86
CFB6719FB0C65
]C:\WINDOWS\SYSTEM32\DRIVERS\RTSUVC.SYS
[530F797129776AA7E81994783A97E2AD][1
110432 1C54346469C82A4D76E34D0AE23
FB352B5DEF263
]C:\WINDOWS\SYSTEM32\DRIVERS\SBP2PORT.SYS
[9B6B1D4DB35A3D9BEAF023BC95E1F49D][1
43008 B386E94B3A72E69348A3BD59388
28706A0EBC749
]C:\WINDOWS\SYSTEM32\DRIVERS\SCFILTER.SYS
[B24408471C1BCB17FC44F5B47EA8DEA3][1
277856 C64DD2FA3E75096193C1DFCB676
9F4556269CCCE
]C:\WINDOWS\SYSTEM32\DRIVERS\SDBUS.SYS
[DE6D7DC78D956928F59F7415A0F41E13][1
95072 4295903D7F5712A8A5CD202AA3B
8E2DFD58EAA22
]C:\WINDOWS\SYSTEM32\DRIVERS\SDSTOR.SYS
[67585C295FF2D221679E376B68893B35][1
74584 7315E6013ED1E55C31428D45BED
5AAEE9BD8F809
]C:\WINDOWS\SYSTEM32\DRIVERS\SERCX.SYS
[B8C4852CBCAAC1374C08EC7445443824][1
155488 5843B5A4E0E70FD77AAA77E91B3
2F4FEB039201B
]C:\WINDOWS\SYSTEM32\DRIVERS\SERCX2.SYS
[D3A103944A8FCD78FD48B2B19092790C][1
25088 CA7415CCB59BF4C8AA174D69D26
0170642318E78
]C:\WINDOWS\SYSTEM32\DRIVERS\SERENUM.SYS
[249A563C48DFD9E42A37587653E003BB][1
83968 068E07508CE8FBFA8B5C467CEEF
AA0AEF00F5554
]C:\WINDOWS\SYSTEM32\DRIVERS\SERIAL.SYS
[0F5B43074AE731D2C6F061241C9D84A6][1
27648 2D46D2A2D44F778FFA1657EEDE3
3E7126AAF07B0
]C:\WINDOWS\SYSTEM32\DRIVERS\SERMOUSE.SYS
[D9FE59276BD56A9643C32D5FACE2F251][1
18432 E1DFD3D14D65928DCB9F011A615
4AECDF61A25B1
]C:\WINDOWS\SYSTEM32\DRIVERS\SFLOPPY.SYS
[ABBE803FE0BDAE0E5BE74DDEFBE62F23][1
44896 E436DDD1775D854CC034B52DACC
9BC8A2ECFE617
]C:\WINDOWS\SYSTEM32\DRIVERS\SISRAID2.SYS
[6043DF55CFE3C7ACF477645FA64DEA98][1
81760 13729F473502E1BF8A3D6A36A19
A401C73BA4DC9
]C:\WINDOWS\SYSTEM32\DRIVERS\SISRAID4.SYS
[7EE0F7F86557FCB8A70E85A51D28224D][1
42696 0865FFA078751FC86C8B06D618E
DB999CF2C7F9F
]C:\WINDOWS\SYSTEM32\DRIVERS\SMB_DRIVER_INTEL.SYS
[1A6CB30F0EFC1632E6F1B852CA892583][1
532832 38C5C5D9FAF4251001B3EA41DCA
8CFFA74E7108E
]C:\WINDOWS\SYSTEM32\DRIVERS\SPACEPORT.SYS
[E1C158F6C00359278727A2CEE5D2ED71][1
77664 73DFAEE7A7D95AD57B996C099F4
1689D0F314F43
]C:\WINDOWS\SYSTEM32\DRIVERS\SPBCX.SYS
[BE88248427A6AA548A904FD867667F70][1
406528 DFD14BE9E17E0A71E5E204FC619
3797A17AB89B4
]C:\WINDOWS\SYSTEM32\DRIVERS\SRV.SYS
[2568B86F6A50D254324CB89022CA9EFC][1
690176 F654FAAE06EE416E597A6FA8798
107E2EB92007E
]C:\WINDOWS\SYSTEM32\DRIVERS\SRV2.SYS
[6E520D6B16EA8AE23D1F81C1194F00C8][1
237056 95129C169C4EEE9C53D951C24C0
CCEB72C40B50E
]C:\WINDOWS\SYSTEM32\DRIVERS\SRVNET.SYS
[CCDA497C880AD16D87EDFAEFCFB2EDF5][1
31072 E2A3DC4D0C9F4D3F42C7C4BFEBE
E1D2BB07CCF22
]C:\WINDOWS\SYSTEM32\DRIVERS\STEXSTOR.SYS
[BF8EA6FC3358C2F69678E3E94F764F84][1
133984 0614A881AB189A139968ECA7738
CEC50681EDF57
]C:\WINDOWS\SYSTEM32\DRIVERS\STORAHCI.SYS
[CC21DB3EF619B9480FE31A4EFE92CBEB][1
79200 42E9BD12C3E1ED690F85FFEBCF0
6879C19950929
]C:\WINDOWS\SYSTEM32\DRIVERS\STORNVME.SYS
[390B8A75768E2689586539C224520895][1
78848 A1ACC71748137ACEFAE172F5290
61B618558EC6A
]C:\WINDOWS\SYSTEM32\DRIVERS\STORQOSFLT.SYS

[770A92D9D3A0BF61C97C3AFCB36847D9][1
34144 1958E421279B80D6EED403C2899
C8A0EFD6CF983
]C:\WINDOWS\SYSTEM32\DRIVERS\STORUFS.SYS
[736A2418E3E7F3DB3CF6EB0A55D1D581][1
36192 EA6691B130C40F0ED3A3385EE35
6D2E2D675E523
]C:\WINDOWS\SYSTEM32\DRIVERS\STORVSC.SYS
[BD98B0225BCD49E8A62F4F8EE1D1F613][1
17760 B3B7A43D0C61E4F63EAB8857D6A
785DBA2E83419
]C:\WINDOWS\SYSTEM32\DRIVERS\SWENUM.SYS
[CAE4B27B469C583131EA5AAE622F5D76][1
64000 0183566550F9DD96ABD3FA86CC9
11B50E4A90FE7
]C:\WINDOWS\SYSTEM32\DRIVERS\SYNTH3DVSC.SYS
[3FA9FDECDF704C2622FB81E34BDF0D8E][1
621256 EE7B547635056FA0F4F0A612415
0228CC57AB653
]C:\WINDOWS\SYSTEM32\DRIVERS\SYNTP.SYS
[083A727D784009F9CCFB120C7841B7AF][1
2403680 7FFE742F8436DEE082E8FC7A37E
C42C9094C6C3B
]C:\WINDOWS\SYSTEM32\DRIVERS\TCPIP.SYS
[17F37EC9042D84561C550620643D9A85][1
52224 B8AF5372D2E701DB46F60A2299A
86858CD97893C
]C:\WINDOWS\SYSTEM32\DRIVERS\TCPIPREG.SYS
[91D3F2A6253EF83EFBD7903028F58C4D][1
118624 E47B5AC5B829540DFD67B196632
D3C2E3095EE31
]C:\WINDOWS\SYSTEM32\DRIVERS\TDX.SYS
[48F64A35BA9F2E4AC0587DDA555FF951][1
184608 9D772B4A0097829F0F0D0ADD25A
6584379D572F4
]C:\WINDOWS\SYSTEM32\DRIVERS\TEEDRIVERW8X64.SYS
[E730D0EB1B84EBC98423FC8D285EDBC0][1
38752 5A077865B2A0E9D857E58D55CB4
0612DBE8F1204
]C:\WINDOWS\SYSTEM32\DRIVERS\TERMINPT.SYS
[87B9ABB965F7AF987D52791F0DD1663D][1
211296 3A3883DF4754676E4BE9EDD4841
6C372576B0BF9
]C:\WINDOWS\SYSTEM32\DRIVERS\TPM.SYS
[48E828C66AB016E48F2CB4DD585315FD][1
61952 7CE9209E3E855AF7DD7A4286C1B
B2F83E5C46569
]C:\WINDOWS\SYSTEM32\DRIVERS\TSUSBFLT.SYS
[267C76EE60736EA5A1811A53FA02AABE][1
33280 2430D7C75A489B5E6DA043057FE
F2C314F1F74C8
]C:\WINDOWS\SYSTEM32\DRIVERS\TSUSBGD.SYS
[8CE72F094B822AD5EE9C3A3AFC0C16B6][1
153600 E7DB43BEF05ADC8D17815CAA551
1A6DAC9EAED24
]C:\WINDOWS\SYSTEM32\DRIVERS\TUNNEL.SYS
[42C546414F80BD6C0137FC3A106F8A69][1
66400 7F2324AB1B4B561BBB1435E6617
2F6F31B4D3497
]C:\WINDOWS\SYSTEM32\DRIVERS\UAGP35.SYS
[1686DBC81748B096232B15F16C302985][1
77664 AA229C5D0F2EF740527EBE23F87
53BA5F4EE2B65
]C:\WINDOWS\SYSTEM32\DRIVERS\UASPSTOR.SYS
[82D3B1F4D80057826AA649D78147DE36][1
63488 776D2C8C96289F428CEF5653BC4
EDE4A839B7C4D
]C:\WINDOWS\SYSTEM32\DRIVERS\UCMCX.SYS
[1C95F7CE37D9EFB90EBE987A9712356C][1
46592 160E5A5909E4F88CBBB94A3FF0E
131F65264CB84
]C:\WINDOWS\SYSTEM32\DRIVERS\UCMUCSI.SYS
[AED081772091C98173905E2DF28C223B][1
209248 B2BA8E56D1FC10D6C70DE7B1119
5D25F7AB1FB86
]C:\WINDOWS\SYSTEM32\DRIVERS\UCX01000.SYS
[DCA34A111C29E4578DF2B8CEA3C7CDBD][1
45056 AEC535244D2809FDC88E8A1C831
0D2677487BFAF
]C:\WINDOWS\SYSTEM32\DRIVERS\UDECX.SYS
[718A956AE00CE086F381044AB66CC29C][1
321024 FBD4EF7BE7F84D64863EE13BA10
F842D90DEE425
]C:\WINDOWS\SYSTEM32\DRIVERS\UDFS.SYS
[BA760F8E66428BA9FF1E8BFBC6248136][1
28512 FE5A2316F07503C789345B2096C
89F3A77748DF5
]C:\WINDOWS\SYSTEM32\DRIVERS\UEFI.SYS
[05DD22294A4F3F89E52351C7721E6D2C][1
258912 7E922EFBBE2AB00470269F3ACF5
D8C7CF32C022E
]C:\WINDOWS\SYSTEM32\DRIVERS\UFX01000.SYS
[2B1DABA97DDF5365FC66EE7DEDD86A13][1
94048 5DC0F3FDF5E22B155B802D2F261
83966AE06CA2E
]C:\WINDOWS\SYSTEM32\DRIVERS\UFXCHIPIDEA.SYS
[2A87EA182EA333D79AA0B03833EA67F2][1
131424 BFCA53D08E5594C0DFB63FF2BCA
C6B2E4D2B5217
]C:\WINDOWS\SYSTEM32\DRIVERS\UFXSYNOPSYS.SYS
[6DE78C04BF32ECA7AF3064F53687C9A5][1
66912 9AA18CB1F0B54456826A8B79BDD
30CC2673CECEB
]C:\WINDOWS\SYSTEM32\DRIVERS\ULIAGPKX.SYS
[67D1E0E6E4D5D33AF0AEF0E33B4DA0F4][1
56832 B42BF80A9AB320EBE8EA596020C
F1043262DC830
]C:\WINDOWS\SYSTEM32\DRIVERS\UMBUS.SYS
[11680607944A719EF20E0E740785712A][1
13824 B07EC35602FC29D9050650EE06B
D512024B89AC4
]C:\WINDOWS\SYSTEM32\DRIVERS\UMPASS.SYS
[1973905F86420E6E216C1825E1A5D0E8][1
12808 F4B8FE3F554C08F67E6A975CE7C
3C6750EE952E6
]C:\WINDOWS\SYSTEM32\DRIVERS\UnHackMeDrv.sys
[2410A0C20D21A25E6C01979FA886BE90][1
28512 D4B2C5F92C6D0DF9A645326BE97
BCB3113A7E369
]C:\WINDOWS\SYSTEM32\DRIVERS\URSCHIPIDEA.SYS

[6E59CE43B6BA5AA1ADCF36A4DBBB92BB][1
57696 8B75AED4E3E43350E6FA1FE3422
A021ED81E0009
]C:\WINDOWS\SYSTEM32\DRIVERS\URSCX01000.SYS
[E8A59FA109A22FC07E44BDFCC9727DBD][1
27488 42A49880842B0C6B5BA89D67EF6
C9BC016D91EC2
]C:\WINDOWS\SYSTEM32\DRIVERS\URSSYNOPSYS.SYS
[D8A44550ECE102B6443F5D54DCE7DAB3][1
159072 F05A5BB5C977AC75FB9FDE5307F
8BBAF4F8B55C6
]C:\WINDOWS\SYSTEM32\DRIVERS\USBCCGP.SYS
[66B3D22DAB5312FF238ABF5C6D9F8FAB][1
102400 CABCED81E470ED532EE6D880D2B
65E777BD270F3
]C:\WINDOWS\SYSTEM32\DRIVERS\USBCIR.SYS
[3E4F20DB902D2E2914F3FF3DB9772200][1
95584 8DD5D7B06CE2E9B9BED631295BA
4478F1FCD164C
]C:\WINDOWS\SYSTEM32\DRIVERS\USBEHCI.SYS
[41F7F00D76904416EF1F9EFA1A4C37A2][1
500064 D5DED1809560A30CAA164C2465A
2B9065A317074
]C:\WINDOWS\SYSTEM32\DRIVERS\USBHUB.SYS
[E7463CE8579A0418A98BE9BE42C647D7][1
534872 4F0BA988B60B87D0C2FD31F9797
A266614F2C4FE
]C:\WINDOWS\SYSTEM32\DRIVERS\USBHUB3.SYS
[DAB35CCA86F5FBE77D870A40089BC4A1][1
29696 24F0C4F894A14F84515FCA28AC0
F2D1CB6A3FF95
]C:\WINDOWS\SYSTEM32\DRIVERS\USBOHCI.SYS
[21162F65C7756AAECAEBED9E67D0A5FE][1
27648 94770344DDC56D2883D81D2A40B
2C5C97D2096F1
]C:\WINDOWS\SYSTEM32\DRIVERS\USBPRINT.SYS
[4AAD6547953D373A1EB5B2DF583D868B][1
67072 FE1B471B77F6E43CABA11CCB703
CD633F69FA9D4
]C:\WINDOWS\SYSTEM32\DRIVERS\USBSER.SYS
[8949F77132A4F8F3BA17C6727099F002][1
127840 A595F5BBB0177183D34B93C6AA3
C1BB2CE1D4296
]C:\WINDOWS\SYSTEM32\DRIVERS\USBSTOR.SYS
[8B3E458A8851F9A3B2109B1680EE1159][1
35328 B746C390C5F881A4925956813A5
32356954DF872
]C:\WINDOWS\SYSTEM32\DRIVERS\USBUHCI.SYS
[4B13B61CBB9CC3CB373C60B930D648F5][1
221184 5D32AF8C947AFE165A62F82AC34
384B45B186100
]C:\WINDOWS\SYSTEM32\DRIVERS\USBVIDEO.SYS
[9E9D58F5E1702955B2F4D62996F80E8E][1
378208 CBCCBB2A923DBA7B48EBD4C6642
C52A0B4C384BC
]C:\WINDOWS\SYSTEM32\DRIVERS\USBXHCI.SYS
[E1BE37312785A71862516F66B3FD24CE][1
52576 8AC029E80B27BC0046D35FB9DA3
71C023940F8AB
]C:\WINDOWS\SYSTEM32\DRIVERS\VDRVROOT.SYS
[E42C0F2850735FF9D908B9DB581E6314][1
200536 6EFFEF4CF8840BBE946EF50A330
5A76510FBA063
]C:\WINDOWS\SYSTEM32\DRIVERS\VERIFIEREXT.SYS
[EC15FD6A28757793E2DA394CD94ABD52][1
707424 589896EB08ACADEEBC4DE49B5DA
5F744E210B377
]C:\WINDOWS\SYSTEM32\DRIVERS\VHDMP.SYS
[D0C9632C350F46786643A069251BC249][1
31744 8B71B9F60B5BFDE35E9EB47E65C
E74BA2E36362E
]C:\WINDOWS\SYSTEM32\DRIVERS\VHF.SYS
[E886CB75DA2B6EB35469EF10135624C7][1
99672 C09E02837C1F47FAB686EC21C63
46E8E7A2E9945
]C:\WINDOWS\SYSTEM32\DRIVERS\VMBUS.SYS
[46D2EC27820EC0F798F85821E53C2942][1
25088 71818872BF864C51B77BF2648CC
405D0C3ACCAD1
]C:\WINDOWS\SYSTEM32\DRIVERS\VMBUSHID.SYS
[77555B11B264991DDC26872FFCF1AB97][1
13312 E06F7A5B274DCEE30BAD0D315D9
0DF1A70859446
]C:\WINDOWS\SYSTEM32\DRIVERS\VMGENCOUNTER.SYS
[044890BB0D6CF1E23C1087234D320509][1
8704 F8D5BC1B2BFF3CB659457AAE928
D3CFD2ADCAEF8
]C:\WINDOWS\SYSTEM32\DRIVERS\VMS3CAP.SYS
[32FF460DA8C1F370F5C08B7654899B73][1
46944 0E2220B7BB8D1ED4B6C729DE979
542E92D147759
]C:\WINDOWS\SYSTEM32\DRIVERS\VMSTORFL.SYS
[B9265F47E7A354BAAA0AF5CBA3F8F7CE][1
81248 91AA78AC34712580121062BDC4A
FAA81A39CB9D6
]C:\WINDOWS\SYSTEM32\DRIVERS\VOLMGR.SYS
[BEE9C8B72AB752B794F69C2B9B3678AA][1
367968 2AAE3EBE93810FEDF96C25BB8B5
15CF6788B1915
]C:\WINDOWS\SYSTEM32\DRIVERS\VOLMGRX.SYS
[E1F91A727A04C9F8199D04FF3BBBF63C][1
414560 DAFC3DFF907DDBAB9DCAD20AA14
E54E14333AB86
]C:\WINDOWS\SYSTEM32\DRIVERS\VOLSNAP.SYS
[F7B1B1101271E31F43CC76E890704F51][1
74080 E21EA212A2B8EF6F7D43C4909F3
85CA0193D87F2
]C:\WINDOWS\SYSTEM32\DRIVERS\VPCI.SYS
[D48ED0A08BD2FD25A833E6AC99623091][1
166752 B18A527CCAEEDB6E213410A545B
061EDED2B47BF
]C:\WINDOWS\SYSTEM32\DRIVERS\VSMRAID.SYS
[6990D4AFDF545669D4E6C232F26DE1FB][1
305504 226066F3EB2289412D9B7415CA1
EB6CAFD3107CB
]C:\WINDOWS\SYSTEM32\DRIVERS\VSTXRAID.SYS
[1EE11F0508C58EF081F4176E66D6970B][1
26624 30E127F1B836025C5553A066896
984F836953A23
]C:\WINDOWS\SYSTEM32\DRIVERS\VWIFIBUS.SYS

[938E4EF58E42D252B742B0E243011B90][1
74240 89D728EA6EEDBA11E9383A33EE9
AEB060D1F3695
]C:\WINDOWS\SYSTEM32\DRIVERS\VWIFIFLT.SYS
[3BE5AAC930447FD18D4A8255A2FEC95C][1
39936 45D3D6580F74E89AA9982A91CDF
B21AF8F2E0BFA
]C:\WINDOWS\SYSTEM32\DRIVERS\VWIFIMP.SYS
[00C27B64C758C111E5D78A70DE6CA2B6][1
30208 A09C41E2DE622126D68843E36CE
F3F7EBC98595D
]C:\WINDOWS\SYSTEM32\DRIVERS\WACOMPEN.SYS
[8CB53620B2C2F0641DD7563EA0FDF491][1
79872 431A754BC44C40451C80FDA8742
73E5030DD0863
]C:\WINDOWS\SYSTEM32\DRIVERS\WANARP.SYS
[069D3D6E20AD753B34FCE856F0436869][1
44568 DB36B6F5F6E36F60B6D3E73D83E
7705167A51085
]C:\WINDOWS\SYSTEM32\DRIVERS\WDBOOT.SYS
[6CC727E94CD84E9720FDCDA8089CABCC][1
794432 93828633DDCF436022585A65659
E66F30D6AB4A8
]C:\WINDOWS\SYSTEM32\DRIVERS\WDF01000.SYS
[E3E97151A1D1E87BB2D5371F66C5F169][1
293216 9A66CAA7EBAB7B08A371317D551
65ECB84E9CD50
]C:\WINDOWS\SYSTEM32\DRIVERS\WDFILTER.SYS
[2BC2E99623119521EEF7910A11D0FDE0][1
694784 3CE327F9CD272E2E19B293D1C2E
4F7CCC04C39F6
]C:\WINDOWS\SYSTEM32\DRIVERS\WDIWIFI.SYS
[07B043160399AF4009054E2EA3464BF4][1
118112 617B89EA52D7154C15E722F8632
BF9CF3A3A4B96
]C:\WINDOWS\SYSTEM32\DRIVERS\WDNISDRV.SYS
[C11272713719922DE5711094333BD166][1
154464 7AAB442D318FCFFBF9F6E28958C
5E5BEFC9BA15C
]C:\WINDOWS\SYSTEM32\DRIVERS\WFPLWFS.SYS
[EF536C54AB9281FDC4E83B07279FCFC4][1
35680 0334575968A230EEA6609BADEF1
A6F34B8C9734A
]C:\WINDOWS\SYSTEM32\DRIVERS\WIMMOUNT.SYS
[D8966A76408107224C6013993135DD78][1
106520 C2D5EFF14D03125B2C38CEE20C2
B0DEF07D2E2F5
]C:\WINDOWS\SYSTEM32\DRIVERS\WINDOWSTRUSTEDRT.SYS
[8B102A7B6CE326FD4208CC7C2D183343][1
17944 080FD2CA46CD17619838411093C
654BF25BA1795
]C:\WINDOWS\SYSTEM32\DRIVERS\WINDOWSTRUSTEDRTPROXY.SYS
[4A53441C1C4D2878BEF27E381138BB2D][1
26976 DA79007387CD84E4FA1F3E535E1
81095F60275A4
]C:\WINDOWS\SYSTEM32\DRIVERS\WINMAD.SYS
[260907CE034FE327AC99BDA4153AB22F][1
89088 ED447B4D49F44A03A07C4BC950B
B3B4B54187917
]C:\WINDOWS\SYSTEM32\DRIVERS\WINUSB.SYS
[40A3E8D729F458B2C9A8BD9380FF83D5][1
59232 36A043114A7E7685E308BF361C8
9BD685ACF3455
]C:\WINDOWS\SYSTEM32\DRIVERS\WINVERBS.SYS
[8F010BF65238F3F822D22BA12831796E][1
18432 E2DFB0042F02905C748FD1350E2
34BC8B3A9B2A5
]C:\WINDOWS\SYSTEM32\DRIVERS\WMIACPI.SYS
[22C52D7EE7C7D0E02C8EFD8CAE8E3A71][1
52768 322D8E0BFCAF692CBEB5DEA1B46
4E7841BFFC6B8
]C:\WINDOWS\SYSTEM32\DRIVERS\WPCFLTR.SYS
[1C08E424CBDD5065BB7266F8C048C1B1][1
30560 85D14313891F01A167319867762
F7934570777F5
]C:\WINDOWS\SYSTEM32\DRIVERS\WPDUPFLTR.SYS
[638B43D39A3D0B47024555CF1095E6F1][1
22528 B7478212597164879BA154DD48D
EB406F2F34BD0
]C:\WINDOWS\SYSTEM32\DRIVERS\WS2IFSL.SYS
[A928F25CB62232F413EE655352856E10][1
98816 846398C49AB5C6727F9DB3C741C
C5A5BA9B93CD0
]C:\WINDOWS\SYSTEM32\DRIVERS\WUDFPF.SYS
[A932391623D5CEC4EF4A2A17D3CEBFCD][1
216064 C792B4B24F19C1A919D8D5600EF
062B46BEDACF4
]C:\WINDOWS\SYSTEM32\DRIVERS\WUDFRD.SYS
[F279536122B83FD0D8E158AA753E1B7C][1
238592 3B0B337FA2078058CA232052BFE
8E39C0D3F6FCC
]C:\WINDOWS\SYSTEM32\DRIVERS\XBOXGIP.SYS
[DA0807D87A62D076C29C4E30F1E84F46][1
26112 0995460B9D6B3917016F080F1D4
E9006DCCA255D
]C:\WINDOWS\SYSTEM32\DRIVERS\XINPUTHID.SYS
[14F9883588398A1BDE49C75098C75DE6][1
40448 E3AF3FED9612CC2FB0BD54F9D86
CE5402D6923FD
]C:\WINDOWS\SYSTEM32\DRIVERSTORE\FILEREPOSITORY\COMPOSITEBUS.IN
F_AMD64_912DFDEDC3D2F520\COMPOSITEBUS.SYS
[FBC8C56814642A7CA88ACBCA8DD1121F][1
145408 D8D3EDD4DD9E2B3BE2B617CD862
6555E6457A0FD
]C:\WINDOWS\SYSTEM32\DSSVC.DLL
[BB481FE489428821B192CCD0C8CDD937][1
46592 8A2E945D0C09FF86F9AF22F723B
CD6626B0A2FA7
]C:\WINDOWS\SYSTEM32\DWM.EXE
[0CDF6B61D7F7FFCD195AF0113B9B2C16][1
112640 812D43F377C1755B75247A63A36
5EE3D43705605
]C:\WINDOWS\SYSTEM32\EAPSVC.DLL
[45D52DCBE934AB9AC0D91C7027FCD18C][1
60416 B5E0FDFF13FDB370D09CA8FB68A
A37BB4BDFAE80
]C:\WINDOWS\SYSTEM32\EFSSVC.DLL
[E34DEFC09F2843C2C24C2248F1ABE6D8][1
111616 647C64D3947F9C69C79B424B6B6

A49BB1DE782BF
]C:\WINDOWS\SYSTEM32\EMBEDDEDMODESVC.DLL
[17BE4A35829B37C742084DC02D48E5F0][1
473088 E5CC3AE248F20AF3DAC0A3E4014
B0482C5ED9CF4
]C:\WINDOWS\SYSTEM32\ES.DLL
[47D09B8C312658ACE433E46DDF51C3A5][1
21504 6175112D8D313EA20491135C6F3
C30BDD1B2F3B2
]C:\WINDOWS\SYSTEM32\FDPHOST.DLL
[177AC945B20C81400A1525ED7B49A425][1
35840 CEC5681073BD4D40790502E4BE5
7FBEBC8AABF4B
]C:\WINDOWS\SYSTEM32\FDRESPUB.DLL
[3E78BEC276DA5A062E4D55F3291B3463][1
118784 F18C35380B312FC5E172A2AE00A
57903E51556EC
]C:\WINDOWS\SYSTEM32\FHSVC.DLL
[4387DE200BF8DD0E2EE828E655434B9A][1
1671168 7A558D4E4E6DC70159F5B3F3841
601B8EBB66647
]C:\WINDOWS\SYSTEM32\FNTCACHE.DLL
[1F5469E93CA0893B7E7663D965CA849B][1
48640 37DB84585AEF0319AE843208A32
00201EBCEC7AE
]C:\WINDOWS\SYSTEM32\FXSMON.DLL
[952F10D2116B91BA433842D07879AE7A][1
651776 A7775DF9D0E5EB5291D74D5D8E9
963C36D3E4F23
]C:\WINDOWS\SYSTEM32\FXSSVC.EXE
[B89C353AFC8F56D961D07FF1FE7B4BCD][1
1339904 839FF5D2134FC8B13394552FCAA
85249BA6A14AE
]C:\WINDOWS\SYSTEM32\GPSVC.DLL
[46DE2EF6382DD9613CB506760648F262][1
36864 5C6F142D910A747B1E8DCA63F17
1A4D38D2AA6BA
]C:\WINDOWS\SYSTEM32\HIDSERV.DLL
[9AFCCEBFC4D311B62EF0C5457FBB405C][1
511488 F7FEB0BFF55AFA9C7BA5DE6D21A
8DCD7DC865833
]C:\WINDOWS\SYSTEM32\ICSVC.DLL
[9BC12A9AC849D7887D0B566CF6CEFBF5][1
117760 62F1FD329B4D261ABEB81AE6FE4
AC15F32269BE8
]C:\WINDOWS\SYSTEM32\IEETWCOLLECTOR.EXE
[67D62A5063519601C7CD531DE206E5E0][1
350312 3F9B7D45BDB8F8F7CA54312D5F0
01D5541A79048
]C:\WINDOWS\SYSTEM32\IGFXCUISERVICE.EXE
[7811F4770BF3A4900E687767BB15B705][1
326760 C5960FC12C1080356ECB69CED33
6BF0E2229BD80
]C:\WINDOWS\SYSTEM32\IGFXEM.EXE
[EB8C18C86785A2B5B915E48B76A00E46][1
248424 AA8C9A54BF7E0A06AA2609E44AD
B113D1041C3FE
]C:\WINDOWS\SYSTEM32\IGFXHK.EXE
[21A454AC519857F3A874ABBCCD3BD429][1
395368 C2F050D5E91B4D5F3FB4973021C
21DD4D7273FF9
]C:\WINDOWS\SYSTEM32\IGFXTRAY.EXE
[95A03F67830FDCB950E70261128D540D][1
957952 16B62DAEABB15A78C0640B95AAC
26453BF76835F
]C:\WINDOWS\SYSTEM32\IKEEXT.DLL
[D5800D5ED7D0232359A9EFC5F0997286][1
35696 967EED0E6D093DE74FABF358239
603704E840212
]C:\WINDOWS\SYSTEM32\IMAADP32.ACM
[5AAB28A6AC2AAC9F66D4EAB6695D0474][1
963072 25B9A9205DF171EBAA78C8C8853
8D42B28C449B8
]C:\WINDOWS\SYSTEM32\IPHLPSVC.DLL
[F8083C536BEDE61AFB4069D8A8C16DA7][1
456704 BA1A0B8BD302B3877AC9A606D5A
A37EEAD5D92BD
]C:\WINDOWS\SYSTEM32\IPNATHLP.DLL
[D67052BD0DA9C17BCBBF8AB5B6D354EE][1
392192 FF8F43F39FB5A010B4A4B444572
9AD992F4FDB3B
]C:\WINDOWS\SYSTEM32\IPSECSVC.DLL
[236A38F5CB0A23BF0ACCD70ED0BD7F70][1
151040 3635611C8BDFCA2C445619E8BE4
4F01055F02DCC
]C:\WINDOWS\SYSTEM32\ISCSIEXE.DLL
[77AE39F73551A6F8702C76F25CEBAA8F][1
53760 E2740F19AE87EB2CCC6FD96E6E9
CC8FAB60DBAAC
]C:\WINDOWS\SYSTEM32\IYUV_32.DLL
[193C1C4ABD2B9CAE3B086C0180708BF4][1
97792 9C6EF3A34CDC48162FE726832EC
1B5621990F414
]C:\WINDOWS\SYSTEM32\KEYISO.DLL
[02C54C5C7EBE371EC0C59795ED22213F][1
27136 A21C517CF56ADD4266AB9721CDB
34D890A7C89BF
]C:\WINDOWS\SYSTEM32\LFSVC.DLL
[01BF128CC327A2E53898F732AF52B3DB][1
22528 C81155A7B361ADD915D5D338286
012829E7438A9
]C:\WINDOWS\SYSTEM32\LICENSEMANAGERSVC.DLL
[7CEC266216126BC9A0E1072E1A7E5702][1
279040 AC70A8141976E89737F188F0DDA
A71489DFC6B3E
]C:\WINDOWS\SYSTEM32\LISTSVC.DLL
[2C23283A0815B048C06D8C0ED76AAD95][1
280576 11E79752CCCEAFC893A83D1B193
AD6D71093EC03
]C:\WINDOWS\SYSTEM32\LLTDSVC.DLL
[CB6365E995F4DB856866500EDD8F61C1][1
24576 FEC79FFE0ED1CD143D89060298A
628652C2B24DC
]C:\WINDOWS\SYSTEM32\LMHSVC.DLL
[8AF0CBE3FC6129C42D7A2A73B681F226][1
1118208 9FC4021204B1E46476FC3992F36
F1B16DABFD3EF
]C:\WINDOWS\SYSTEM32\LOCALSPL.DLL
[1A563653DAEDFE4CA81936E0D2FD8B56][1
10752 539086A0D38DBBD2F6876D1E791

DB975856815C7
]C:\WINDOWS\SYSTEM32\LOCATOR.EXE
[889459F1FDDC5EC58B437AA6C436F33F][1
57912 C6C9E1E362EE3E93D41B4EAC492
797D52E43C739
]C:\WINDOWS\SYSTEM32\LSASS.EXE
[FFAA37FBBDD161E8C200C83B40F7872E][1
729600 E2F97F171C4F5F66E44685D1497
132DDFEED6F68
]C:\WINDOWS\SYSTEM32\LSM.DLL
[F2C23E25636BCA3543E6AD7858E861B7][1
52736 8AB605BC333CBC3F10707B5F71B
A8963C0B05D40
]C:\WINDOWS\SYSTEM32\MESSAGINGSERVICE.DLL
[73C44205E57B561FAA308312B108165B][1
25088 B340D818C550794140F58B24594
B29E82B452102
]C:\WINDOWS\SYSTEM32\MIDIMAP.DLL
[FA2CDF42B3E9F53B12E506BA48BE16AA][1
72704 A48413121FDD5095209212CC9CF
D1829CAACE225
]C:\WINDOWS\SYSTEM32\MOSHOST.DLL
[8355BCA85B0928382DFCDD02FCD1681A][1
507904 7CD10D7F61BB225E2BC8FB45BC7
8BB129E86EBFF
]C:\WINDOWS\SYSTEM32\MPRDIM.DLL
[0B28F2ACE5103586D322AD98FAA01309][1
870912 FAA951ADC51DEA9FA07627CB1D6
B002BBDEFF52D
]C:\WINDOWS\SYSTEM32\MPSSVC.DLL
[BD6705BEF0F792652E5424416DFAD2A2][1
27648 1B33400061B20BAA3D602E7E7AF
9B80B0808887E
]C:\WINDOWS\SYSTEM32\MSACM32.DRV
[D90D1DF34E5C6912496548BEF0791742][1
34632 39467EF1BDEBCFCEB8C81812C0E
9DFCB5C098D11
]C:\WINDOWS\SYSTEM32\MSADP32.ACM
[807A6636828E5F43C10A01474B8907EE][1
147968 AD5D35549B684F9262D45E42172
1641B938899F0
]C:\WINDOWS\SYSTEM32\MSDTC.EXE
[71DE1AD9B23661EEC4F2A6EAA5A7D33D][1
378880 3176277D65B54C39B3BDF98E8CA
7C51FCDAC5432
]C:\WINDOWS\SYSTEM32\MSDTCKRM.DLL
[9205E2AB8092C448A09A1EDF7A35F400][1
25344 FAC814F85874001FE5211379E42
5C7D96A7892DD
]C:\WINDOWS\SYSTEM32\MSG711.ACM
[E94759309E2876EA58FD76244A6E26E6][1
42936 65C704C11C33F9C00AE932E81BE
EAFACA54A4BBB
]C:\WINDOWS\SYSTEM32\MSGSM32.ACM
[4708F4FB63D8F73C090CC4893B261692][1
66048 53D463D105C7DA4369909675D0F
9CAED3C54F9A3
]C:\WINDOWS\SYSTEM32\MSIEXEC.EXE
[9AB1E36A443CB08B667B6A1FE0FA9E9E][1
17920 89398DC255F159AF75EEAC42D4C
54D2D9753C00A
]C:\WINDOWS\SYSTEM32\MSRLE32.DLL
[944FAE17E66C809AF40B34BF8DFD1DF2][1
38912 C385DCEDF4370FD7D3784F2CC65
107364F48788F
]C:\WINDOWS\SYSTEM32\MSVIDC32.DLL
[C798AFF023B8C4982E872A4026DEC0E5][1
27136 C4605A56B3884E55BFB5E583768
4A17EB9AD47A2
]C:\WINDOWS\SYSTEM32\MSYUV.DLL
[A340A4B27CC7DEDDF953B7E2C9699747][1
168960 D5B2A67F878A091E2052F7C811C
7ACAC9C369F11
]C:\WINDOWS\SYSTEM32\NCASVC.DLL
[24146738C422814EEB2A98FF1FC5C6E1][1
338432 002F107FFD1749DA585050982F8
E65CE4625017D
]C:\WINDOWS\SYSTEM32\NCBSERVICE.DLL
[476466DC3AB2327E2DBFAEC11798E2EE][1
81408 44FD8808E5E6D27C0248CA14BC1
CAEFD608FAEEF
]C:\WINDOWS\SYSTEM32\NCDAUTOSETUP.DLL
[BEF109D45139E2646C116DD9B6E53E3C][1
847360 85707A0CBA30BDE26F1E2685077
CF7CFD52B27A3
]C:\WINDOWS\SYSTEM32\NETLOGON.DLL
[7FD4C3D32DAE890608F44074A3437CD8][1
265728 3788A8C893E7569CF184133C15C
A5533FC30C0E0
]C:\WINDOWS\SYSTEM32\NETMAN.DLL
[A059F75402710535A90A8D043674A514][1
547840 802AF604D04DD9AC915BE6D743E
3F9EE5365BC61
]C:\WINDOWS\SYSTEM32\NETPROFMSVC.DLL
[A3AA03C0C5002F3D89397637B770A1BA][1
207360 4FA49BE7E2E2822D313E23B8BC5
E2A0EFC33167F
]C:\WINDOWS\SYSTEM32\NETSETUPSVC.DLL
[0FB83658FBB2C5A18AB98C5C94DB9FAF][1
289792 E805E217EE64BF0972172E86342
3C901EA2C302D
]C:\WINDOWS\SYSTEM32\NGCCTNRSVC.DLL
[7AAA9916AA10F4B0E9743798A5BA6549][1
649216 B99FCD4C85F0C8843C8BE6DBEFC
007CD09D0D5DA
]C:\WINDOWS\SYSTEM32\NGCSVC.DLL
[1B8F07B59F7DAE02264FB8A16088C467][1
371712 8683C2E806A4352810185CF584C
F4BFFAAEF3B35
]C:\WINDOWS\SYSTEM32\NLASVC.DLL
[AF8B7848E102A83AAECCD24B181CEBE5][1
30720 E37157899E9C21D62AC612F91DB
DD18E2B1C4AC8
]C:\WINDOWS\SYSTEM32\NSISVC.DLL
[0B49AC860EC6BD165D58218A7AEA18A5][1
882688 D00DE313F5B9E893E11D6FA9C03
7513D0DF42B4C
]C:\WINDOWS\SYSTEM32\NTSHRUI.DLL
[4A9CA28E04B4987E0C33EB742BC99DBB][1
1352760 BEAAED0B8A56409E14662533EAA

B23ED18DFC189
]C:\WINDOWS\SYSTEM32\NVVSVC.EXE
[4A5634915AF62C983E08425905D0C04C][1
434176 BC76DBF3FF451812ED59B49A987
FAE08866EB6D5
]C:\WINDOWS\SYSTEM32\P2PSVC.DLL
[0ECA2ADD5FBCE73183A68935C71B40B7][1
528736 2B9961F7BB41FE77F225D4B5270
36C8E4537240D
]C:\WINDOWS\SYSTEM32\PCASVC.DLL
[57606281E23B0F53347527691E947B2B][1
749056 13869108F1CEDA6E08770365999
3FEF4768C2AAA
]C:\WINDOWS\SYSTEM32\PHONESERVICE.DLL
[04F7878E7017105AB782353231561749][1
252928 16DCAF8F2FD95720D81B01DC362
9FF313B9D23EE
]C:\WINDOWS\SYSTEM32\PIMINDEXMAINTENANCE.DLL
[A546F72EFFE5CBBC98003A0CA19DA0F8][1
1487360 5199605B741CA9798662C2BFE45
A7D90A990C9E1
]C:\WINDOWS\SYSTEM32\PLA.DLL
[334131C162B118EF49930D41B0E17825][1
351232 C1351469A3AC8F5D11CD27A5DE4
AA4B5774C203E
]C:\WINDOWS\SYSTEM32\PNRPSVC.DLL
[7E0078F1EFEB6F8F47CF85C1D73C7EBC][1
328192 DEAEC2B6A39553CDFF0DC0CE146
CD53E842BC010
]C:\WINDOWS\SYSTEM32\PROFSVC.DLL
[E2145534FB853921788F52701BED0CAB][1
464384 B9E0BBBB2E97779F43E0A0F63E7
39F237B322705
]C:\WINDOWS\SYSTEM32\PROVSVC.DLL
[64582C924C48175D52AED0D0E64AB413][1
1144320 E4BBBE072FF2557BA243A0BEF43
F33944FE93427
]C:\WINDOWS\SYSTEM32\QMGR.DLL
[E84F66BA185934C166F8DF0FA8F88455][1
286720 A275FEBDD16095BD13BA1EDCAB6
C0E5013176E77
]C:\WINDOWS\SYSTEM32\QWAVE.DLL
[D60BA4C76D194472D6602FF3D2D51ADE][1
106496 B7C16C740FE34F8B28A326E13E1
325C2EED048C9
]C:\WINDOWS\SYSTEM32\RASAUTO.DLL
[3655D86C5E2982B131FC0935DE24F98F][1
696320 F6FE55A9E8304C175623BD08425
7740028764635
]C:\WINDOWS\SYSTEM32\RASMANS.DLL
[DF7A59E70F398EEB9FDCDD310987D8AE][1
1073152 6B1F8E3E35DE5B08CBD6F4F06D3
A4B9BA31D0D30
]C:\WINDOWS\SYSTEM32\RDXSERVICE.DLL
[AC46883E2BD132344D0EE13FB901257C][1
74240 3313E9724FC1852A10962A1BFB1
C1F125BF9A974
]C:\WINDOWS\SYSTEM32\REG.EXE
[2C82F4DCABAB389CEBB1C9E86C715C9C][1
156160 C7C5B324291DBE8492E919FCC35
119E197232A3E
]C:\WINDOWS\SYSTEM32\REGSVC.DLL
[176D8470B15CD9080861594F9A33FA01][1
79360 3158425236BEAB19DBC0FA8E84C
D6E46C6526D37
]C:\WINDOWS\SYSTEM32\RPCEPMAP.DLL
[B339861C6A2A86FBCA67C2006B461473][1
904704 8147D405EE3DC32BA9D2F3C05B6
9D80D6B8F2599
]C:\WINDOWS\SYSTEM32\RPCSS.DLL
[46FDF02BDA740CFAB469022EF1F95474][1
85720 629F35DE9234A05707B87EBED3A
CE89F87F14CA5
]C:\WINDOWS\SYSTEM32\RUNTIMEBROKER.EXE
[4244808B9CDCAD3670B717E6B936736E][1
68096 22C638F430AAECF5BEB95A74FBD
9400510188295
]C:\WINDOWS\SYSTEM32\SC.EXE
[0C12493B333B96797AFC5F3C7831C051][1
235520 C0A6FB38322A591B2C99B925B52
A3D4EC087A6C5
]C:\WINDOWS\SYSTEM32\SCARDSVR.DLL
[40110802D217FE1CB581D9A70B1FD16F][1
181760 49D65546E0A98B12BC02CBFA7A7
8668D97A46F9B
]C:\WINDOWS\SYSTEM32\SCDEVICEENUM.DLL
[930A1C518D65A9E781CD16C9BCFC5BEF][1
251392 689B95A43AA56D7499603BE0494
0E97E483DB050
]C:\WINDOWS\SYSTEM32\SCECLI.DLL
[EA195B8BC11C1CDB313CFD456EFFA0E9][1
997376 A721BC68B68A0F19E79980E3A88
C9635CE6305BE
]C:\WINDOWS\SYSTEM32\SCHEDSVC.DLL
[811EC0B1221402FCED0BA37E112BF627][1
150528 7914AAD91F580F7492E7C3E3A18
055DBC87ADA08
]C:\WINDOWS\SYSTEM32\SDRSVC.DLL
[9084E1BE90DB98E2B48A2EDD1A5EA753][1
203264 8FE92652705C61678EB4A55C25D
5F7162B8A722D
]C:\WINDOWS\SYSTEM32\SEARCHFILTERHOST.EXE
[9E8B4F59C878AD30720D4194CBD3BE81][1
938496 03492882333174627F58BCE3EF6
479F22275BD7C
]C:\WINDOWS\SYSTEM32\SEARCHINDEXER.EXE
[E98CD3C1A5FE067975DE1DEC5D954D79][1
334848 3350381B2CB44F5B1CF671C2AC2
8ACAF094C33BF
]C:\WINDOWS\SYSTEM32\SEARCHPROTOCOLHOST.EXE
[EBD07BD20B5E0E92A398566EF8720F79][1
31232 ECA27ADBF2C0C581FD07C6A770D
7303FD5A6614D
]C:\WINDOWS\SYSTEM32\SECLOGON.DLL
[B7B9EEBCB7466338403A75D15AC120D7][1
73216 D2C7C47D2E28EC6A320854CDEB3
A28764A5592B2
]C:\WINDOWS\SYSTEM32\SENS.DLL
[D14DD7D766664F880FECF44CE6017966][1
1297408 E7964F8B0DC9EA4D283C1AC4812

FE87B7B027622
]C:\WINDOWS\SYSTEM32\SENSORDATASERVICE.EXE
[45D26646E3AD737E5DE3DB91CCCE7DBA][1
339968 B76AFE7A019D6FD60C785BB9523
D6E11B8EF888E
]C:\WINDOWS\SYSTEM32\SENSORSERVICE.DLL
[7363A65C738F5A5292D7BDBE55D8C3C2][1
180224 56E247E4724442522C6052CBDDB
59D208CC11FEC
]C:\WINDOWS\SYSTEM32\SENSRSVC.DLL
[CD90E445F6458512A5BA884D561EFCF1][1
372736 AF9D86DFFEB60C1717002E501BE
F81F8F7BDD8BA
]C:\WINDOWS\SYSTEM32\SESSENV.DLL
[B9B902C12D6872DE9135B0A7C1ACA5A8][1
565600 C3C11CADFCE687FB540C877BAD5
629A37ED7D7D5
]C:\WINDOWS\SYSTEM32\SETTINGSYNCHOST.EXE
[6DC05FFA78B5E1D34AFDBA08D00B1A8B][1
22561256 4F15A780984B70FB6707B3AA007
BBA2BBF093B03
]C:\WINDOWS\SYSTEM32\SHELL32.DLL
[AE6E4D3172FBF45B944668CB3998B8A8][1
608768 F08C6AB96BDF89BB90632D6C7F3
A8D7C48187CAA
]C:\WINDOWS\SYSTEM32\SHSVCS.DLL
[1CD2F4A74AD6AC2DE5ECF8BB9F12C723][1
72704 DA225EDD4A72F2283343CCB593E
5867D75DB8F04
]C:\WINDOWS\SYSTEM32\SIHOST.EXE
[B922D32039A3B5991E64429EC4EE52A9][1
23552 C6C3069547563B2BF24B5EA20A0
E1EFE606EAB39
]C:\WINDOWS\SYSTEM32\SMPHOST.DLL
[F07301C282AA222C33F8C28B4F545275][1
591872 70D598854D86BCDC8D45B5DE129
E0E7A14A42CC9
]C:\WINDOWS\SYSTEM32\SMSROUTERSVC.DLL
[0B6BECB2651EF947249CDC3715E8B9CC][1
15872 0120CA8E237633B797D9F4F5B38
C67FF7272F4B9
]C:\WINDOWS\SYSTEM32\SNMPTRAP.EXE
[15709A9AB1411565754CEE33AAB36387][1
3337728 9EBDD87CD1FD0E969CB46F15D16
37E647AF787F9
]C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\X64\3\PRINTCONFIG.DLL
[D1241DFC397FA8CCFB4BB4B63AAD31AC][1
755712 138733AADC844F78D479A7C1B62
39C42F1644EA1
]C:\WINDOWS\SYSTEM32\SPOOLSV.EXE
[7C58AFEC26E9F7730A8AA7FD40225937][1
6536248 4EFE7380E6A99CBD5FE76234C99
BDA2F46DCCFA4
]C:\WINDOWS\SYSTEM32\SPPSVC.EXE
[8BBB2B4429AF340481520C20C17FC5B6][1
283136 EA901D56E937231384F8DD12849
B04C1308DCC8B
]C:\WINDOWS\SYSTEM32\SRVSVC.DLL
[8C1786C073A496B8C0C8A5450A4FFD5B][1
239616 1B50B999A45BCCEEC3076B00034
CD64F786DFFF4
]C:\WINDOWS\SYSTEM32\SSDPSRV.DLL
[217A982201052EFC8C3C0C88D229791C][1
212480 3214C7A0978106131230718893B
5BE7A8AE57C2F
]C:\WINDOWS\SYSTEM32\SSTPSVC.DLL
[FE42F8A07885E518ED1E846C93E4B78C][1
617984 2673E36BA8F149A2B56FAC76B69
3C1E2D5C4320C
]C:\WINDOWS\SYSTEM32\STORSVC.DLL
[8497852ED44AFF902D502015792D315D][1
43944 800A4C2E524FC392C45748EAE16
91FA01D24EA4C
]C:\WINDOWS\SYSTEM32\SVCHOST.EXE
[FA8F6E3AD3F92B35D2673CC9FD20429C][1
13824 74162D6649A682D7118FC83ACC4
3AFF9D067C01B
]C:\WINDOWS\SYSTEM32\SVSVC.DLL
[22E539A9B96C66A713583EC017562616][1
467456 225F989FC375B6AB3B40828BD85
A1B68EB66B1AC
]C:\WINDOWS\SYSTEM32\SWPRV.DLL
[401077069C4B017F6179A1BC36BD6E80][1
177152 FE72B5B15DFECBC9E51C120F798
3F6C5A14538DF
]C:\WINDOWS\SYSTEM32\SYNCUI.DLL
[34A3EB84B2A830E6F450B8F885AE4E6E][1
1088512 3F05170D29E2B8E40274A50BED7
209A1638F9482
]C:\WINDOWS\SYSTEM32\SYSMAIN.DLL
[FA8E0A9C648035CA1B47C9DA77EDB7EA][1
380416 B9DEFFAD0D5920AF417C6E2C63D
3669D280994C7
]C:\WINDOWS\SYSTEM32\SYSTEMEVENTSBROKERSERVER.DLL
[6979A147C0D5C5CAB621ADC394D32B80][1
151040 5511BD9D22A3521EB49D955CCEE
EA2D8AB8ADF6D
]C:\WINDOWS\SYSTEM32\TABSVC.DLL
[86B62FC8CB89946446F9B24FE49A66FD][1
311808 C149EAA6CDC266E73CA1E09EBC3
0CABDA2224122
]C:\WINDOWS\SYSTEM32\TAPISRV.DLL
[F56DAF008FFD7E423292DE21A990B2D4][1
90440 8CAD6B39845D56565DBFE7C7C6A
0EB6DADBCA61D
]C:\WINDOWS\SYSTEM32\TASKHOSTW.EXE
[4C120EE77388093EEC45E912EE38C37D][1
216576 62F222B80F5D0E48C28C59B8680
826A77E275225
]C:\WINDOWS\SYSTEM32\TCPMON.DLL
[14307D4801C8CEF0A615907C09E886B3][1
1033216 7655BCF3CDB373A591FF5577B6F
04FAF97790F9F
]C:\WINDOWS\SYSTEM32\TERMSRV.DLL
[57C88C15CEC97318F580D7F4327AAA46][1
163328 11E1A08B2C20E6B5F11E4B8C641
90F6C08990D65
]C:\WINDOWS\SYSTEM32\TETHERINGSERVICE.DLL
[D009D1BC14FD5F2AC93D1878735F6C39][1
59392 CF03B4BA532E71C04BE1108A5D2

CC047770C3F8F
]C:\WINDOWS\SYSTEM32\THEMESERVICE.DLL
[5F27DE2082E16D4C1D6C627C8ECBD341][1
290304 B7837CE25389F1B69CEEBBDDE4B
CDF19AA3BC605
]C:\WINDOWS\SYSTEM32\TIERINGENGINESERVICE.EXE
[7E81E3E0D7F83BFE3C3975020B6C7F12][1
163840 C6623710527AB357DCC87F5D15E
53D96822417FD
]C:\WINDOWS\SYSTEM32\TIMEBROKERSERVER.DLL
[AA84AF93CE5AF1F05838B51D20295419][1
115200 38608CEE5F3B9A8BECE9745FF39
12682CE025DEF
]C:\WINDOWS\SYSTEM32\TRKWKS.DLL
[A9EA339B636506B4452FA2D84CC64D5D][1
16896 2ECFB1969FE764ACFDE89D38486
64F9F65EDE94E
]C:\WINDOWS\SYSTEM32\TSBYUV.DLL
[56C238ACFE4CB020D3E38508249039EA][1
87040 AFD22F7DF92B287EA4FF0BA6665
8A467EEF1F15E
]C:\WINDOWS\SYSTEM32\TZAUTOUPDATE.DLL
[63451BD694651307254B8DD37A3D79C7][1
43008 8DADDF67AE35C8F659DD4BAFF03
7CE5679B6549E
]C:\WINDOWS\SYSTEM32\UI0DETECT.EXE
[15BA68662CED4B0618010A54478E18E5][1
111616 7E28BB7718C5CC18980258A09D9
BD6FBA63C7C5F
]C:\WINDOWS\SYSTEM32\UMPNPMGR.DLL
[AE3B1056FC1795F18D990C4908A6ECBF][1
113664 404957482E6587122A3A07F1CC7
1ACEB5C0FA7B4
]C:\WINDOWS\SYSTEM32\UMPO.DLL
[FD949725D9EB52C0B87435CDE1134668][1
278016 3EE9D1F24D9D5D9405477EE0379
EACC859693A0E
]C:\WINDOWS\SYSTEM32\UMRDP.DLL
[CB902A15DD21B363FECA5DCCF34F5C57][1
1224704 9B4103B6D856DF0D9D698743EE7
C5D59F478F5D8
]C:\WINDOWS\SYSTEM32\UNISTORE.DLL
[8ACE7A8D694C4F0DFA3FCBEFA2D441FB][1
237056 850B3A3A04493D8CFB9046D6391
428B68C792C57
]C:\WINDOWS\SYSTEM32\UNREGMP2.EXE
[B85A8CF2BE74DFF1E80097AC94584112][1
452608 58EDEF43DFB024C8F06BBB48B99
E620708421AF2
]C:\WINDOWS\SYSTEM32\UPNPHOST.DLL
[FF07BE14ED82E218C3EEE7C986118A2E][1
307712 FD09F30559AF4EE034FE53203B6
DC962018FB444
]C:\WINDOWS\SYSTEM32\USBMON.DLL
[2771EBB565F5C121E66060B173991D4D][1
1490432 E927BDB1D592BF5EDB0B7ABDF50
CE3F53D1AE77A
]C:\WINDOWS\SYSTEM32\USERDATASERVICE.DLL
[8F3ECCB5DC878FA14887B43CD148CBA9][1
30720 636B973BCF88ED76B0605A69A26
2F64D0400C399
]C:\WINDOWS\SYSTEM32\USERINIT.EXE
[36EC82F0E399F36BD25F593D63DC144A][1
912384 CD4ADC7923F3C6AD2957DD79C80
B2C0250E54794
]C:\WINDOWS\SYSTEM32\USERMGR.DLL
[0D33D06EF42E3BC6A7BBC4F7F7517C25][1
368640 D9407AC4DD63E147030D4BB6C62
50D7FD5AF070E
]C:\WINDOWS\SYSTEM32\USOCORE.DLL
[B37F21B4C25BF10605A196791F93E324][1
360448 01C1B05BF015A299CD5BFE46727
125477DA79492
]C:\WINDOWS\SYSTEM32\VAULTSVC.DLL
[67A6E949395A09914AD8B38FE14B8D15][1
667136 7BFEB659C63E1B5FD204BCF709A
6444D9BE431E0
]C:\WINDOWS\SYSTEM32\VDS.EXE
[4CF5A1E0C4FCA956ACD6C654E2A8610E][1
1465344 98AD15232D53C492785442C536B
55AE65137744F
]C:\WINDOWS\SYSTEM32\VSSVC.EXE
[48C1A256591297C43ECFC4E30D144EAA][1
526848 E27F2CCC5466263D18F7C3818E3
CFA7A861EC37E
]C:\WINDOWS\SYSTEM32\W32TIME.DLL
[D76D1AC4F2C642D09A68227D129A4726][1
497664 CDF0A45268C584F0925FCFDEBEF
A1FCE738A847A
]C:\WINDOWS\SYSTEM32\WALLETSERVICE.DLL
[854933CEAE3CCB18330BD416F627C545][1
987648 DCF13FF5AD9120F619A9D44A20D
1A0AD147C886A
]C:\WINDOWS\SYSTEM32\WBEM\FASTPROX.DLL
[F0F9F5D57EC0712E69C51563CCE0793C][1
50688 A982B66738CD3BDFB77194819B5
EE2DDC49715C5
]C:\WINDOWS\SYSTEM32\WBEM\UNSECAPP.EXE
[74ACA5A7880C1F0BB9D60E32E1705A70][1
202752 9FE1EEDC17055C4BD0BB2E4C524
EBE9782F6DC3A
]C:\WINDOWS\SYSTEM32\WBEM\WMIAPSRV.EXE
[94BD625209F7BB993F228CD68ADD2455][1
504832 FAB171C4CCAFDD6CB5A9265F2F0
3A90F069AAF76
]C:\WINDOWS\SYSTEM32\WBEM\WMIPRVSE.EXE
[1033C37122C7404C3B926ADF84874832][1
225280 824ADAADA8420F195C89EAD28B2
C0158D32716C6
]C:\WINDOWS\SYSTEM32\WBEM\WMISVC.DLL
[2598BBF11C9E7D0885DCA52E7FD5BCBD][1
1570816 E2195D489B2EF697220CB949448
E9382DD951888
]C:\WINDOWS\SYSTEM32\WBENGINE.EXE
[642EFABF900374FA85639D83B5533AFD][1
621568 7922A162298FE079CE738AD782A
98975FEBC04C6
]C:\WINDOWS\SYSTEM32\WBIOSRVC.DLL
[0BF8D8C7EC9FB15D6480A12101E88B71][1
606720 02C0D30BBB45781E2FD7EAE5941

34F9210947322
]C:\WINDOWS\SYSTEM32\WCMSVC.DLL
[53A036CED1270F2459E708A05922FD49][1
471040 D4CA066187C2A8FDF90507825B3
50E3A9A5400B8
]C:\WINDOWS\SYSTEM32\WCNCSVC.DLL
[965B6197A659782B6A0F68411A180AAD][1
43008 425CC686952E5FB6DA01F05D64B
3A6EED008A9EA
]C:\WINDOWS\SYSTEM32\WCSPLUGINSERVICE.DLL
[75DC67553051103547B693898CB32D08][1
100352 76CE0F6B9D1F49644E01E2FB678
ADF0A08E73B07
]C:\WINDOWS\SYSTEM32\WDI.DLL
[1FA86056BE5F821C25EF7AEFDFB83FF1][1
245248 C23AD3B64AD54441D8B198637EB
ED27413074107
]C:\WINDOWS\SYSTEM32\WDMAUD.DRV
[9972D395DBD05D91DA5EDADEB9325680][1
228864 858C90BAD5357028179787921D1
0345799273DC8
]C:\WINDOWS\SYSTEM32\WEBCLNT.DLL
[B6BF579761489720BCE787F723F596E5][1
211456 C82B5C6CD925F44412B3E9427C5
0433BC1EFC380
]C:\WINDOWS\SYSTEM32\WECSVC.DLL
[10C9CF8771A2A87F575F9FB56821474E][1
27648 95DC82592E8EF23F92B6B260E30
7B141E66A233F
]C:\WINDOWS\SYSTEM32\WEPHOSTSVC.DLL
[357C083FE35D030D991D163AAF622A06][1
96256 BE09BD3CBD655B35BC2F588E54D
FBA5B26889CFC
]C:\WINDOWS\SYSTEM32\WERCPLSUPPORT.DLL
[2235AF716D15D9DFE4C59DC2AC0C440C][1
143360 7FC38B415FD7F41B2CFB039FDCC
C9F2C88B4294A
]C:\WINDOWS\SYSTEM32\WERSVC.DLL
[205A1FAE910F5C493D236245850BB62A][1
75264 6EBD411F3E2326C578CAAEA556D
060413B2DCF3A
]C:\WINDOWS\SYSTEM32\WIARPC.DLL
[75476CAA8FA0A4E573948CDE8C7F0304][1
643584 7AE2269A3B68B2AF650A6D8FE71
8F0EE42D96FAE
]C:\WINDOWS\SYSTEM32\WIASERVC.DLL
[E32F15E26724F3BB6423FB29FF3E2A8F][1
278016 7FA1ADC1F4C1820A16B7FF623B8
F75B9684B9BC9
]C:\WINDOWS\SYSTEM32\WINDOWS.INTERNAL.MANAGEMENT.DLL
[58863C57E4598C4F9DA967C5C36CFA5D][1
2745856 B43D8C5C4460BDDFD0CFC958EFA
1E4125E1D1BD0
]C:\WINDOWS\SYSTEM32\WINDOWS.STATEREPOSITORY.DLL
[24F2141493C1A2F6FDEC8C3FA5A95CDE][1
6605504 EC8A59A5850A183C6166724DDF0
3E92E97FADF7F
]C:\WINDOWS\SYSTEM32\WINDOWS.STORAGE.DLL
[D4B30E23A3B373648F61290DAF432CB2][1
794624 CC76B9B8725F0DC041CB2CEED75
278C6810F2446
]C:\WINDOWS\SYSTEM32\WINHTTP.DLL
[5C156EC4E44E30331BCC865A3B61D839][1
585728 55DAAB0704DE997B363F4D2506F
41D85C927038E
]C:\WINDOWS\SYSTEM32\WINLOGON.EXE
[1F5D48B1DA1B812BD2411CA44D75DD32][1
274432 4A24607E00DD05A11DA85C445AA
DC860B81F4B22
]C:\WINDOWS\SYSTEM32\WKSSVC.DLL
[6974DE4152EDBC1351B9806006726259][1
100864 429DE0337823562768868CFEAB7
AE03B13E50674
]C:\WINDOWS\SYSTEM32\WLANEXT.EXE
[453740989239803FE363FF8B40EA2E08][1
2295808 232C9E7426247A27A3A2D603FFD
FB9EBED8B2352
]C:\WINDOWS\SYSTEM32\WLANSVC.DLL
[E48BBF1363F843E030757EC190DD33E6][1
2057216 2BA8DAE51656940935FF307B394
0CA84ACFCE907
]C:\WINDOWS\SYSTEM32\WLIDSVC.DLL
[4090C6738AA92B428220857B4D44F638][1
1872896 E88E4D651DD5A82D2EA83E659D2
242D0E9EA2932
]C:\WINDOWS\SYSTEM32\WORKFOLDERSSVC.DLL
[45FA01F8B7971ACB65202038E34D04A3][1
86528 A0AF067DCEED1D8FE14B890309B
AAB211BCF071F
]C:\WINDOWS\SYSTEM32\WPDBUSENUM.DLL
[5B813FADEA5BE9195F01C83287F823F7][1
190464 F1B8A561D850956E87122BA8010
87B5E5B4B293E
]C:\WINDOWS\SYSTEM32\WSCSVC.DLL
[E70E169F779EAC621A197A084F0649A1][1
587776 1164AF3331F6286EB3DD6AC4E80
B434A40DB2205
]C:\WINDOWS\SYSTEM32\WSDMON.DLL
[703D0F62C5AA4D08EE8756516C0D125D][1
2573824 9C3DE8DC4ED9F509F7DB924F2D7
1410139C1ECFB
]C:\WINDOWS\SYSTEM32\WSMSVC.DLL
[6E04BBE242E2889B37300C4DF5CE1126][1
3449168 2666F70A1E7ADA7AE2AA970FAC3
56E79A973F544
]C:\WINDOWS\SYSTEM32\WSSERVICE.DLL
[8D3AC00C88BC2A63D1D3CC320E0EAA19][1
2281472 BB990E380F5B0B2484E3388AE25
26F6D45B990BD
]C:\WINDOWS\SYSTEM32\WUAUENG.DLL
[3760FD529432DFC93B307440534A70AC][1
265728 69CB9803D216A5DA3928890047B
3C0E669C3FCFA
]C:\WINDOWS\SYSTEM32\WUDFHOST.EXE
[1336DA39FE006EAB2733CA4DE5B3560C][1
104448 CE42FCDA3BECBCFEF0002B09FAE
73A4582F0519A
]C:\WINDOWS\SYSTEM32\WUDFSVC.DLL
[5DA95027DF2317174E8C39B4A8D1FCD8][1
1213440 47AE788F2D52652138DE82D65DA

4766991C0359B
]C:\WINDOWS\SYSTEM32\WWANSVC.DLL
[5DFAF8BE5A3CABAABF6795BC09EB7876][1
948736 25A29B97C488794B87D8D2AE391
F207DC2AC1467
]C:\WINDOWS\SYSTEM32\XBLAUTHMANAGER.DLL
[7118498F6E48758A2EF5A7D1982E2B62][1
1139712 ED81DA5834A4C1BF87CD5085F36
6DEE5B5F2283B
]C:\WINDOWS\SYSTEM32\XBLGAMESAVE.DLL
[69E727F94BEA64E66C284F3C482F33E6][1
1035776 90AC2B5446DBF4A01614DD3C241
80E2AFE5F82D4
]C:\WINDOWS\SYSTEM32\XBOXNETAPISVC.DLL
[8B42614E97AA27347B3AD72C18FDDEDA][1
9371488 162019B463D181FADD14D83409E
67058248FE5EE
]C:\WINDOWS\SYSTEMAPPS\MICROSOFT.WINDOWS.CORTANA_CW5N1H2TXYEWY\
SEARCHUI.EXE
[EEC01707BA931B7113DE3E1CF7528F69][1
2095968 32D7A8928730D32828EA32FDAD7
E7DE9F9C48A07
]C:\WINDOWS\SYSTEMAPPS\SHELLEXPERIENCEHOST_CW5N1H2TXYEWY\SHELLE
XPERIENCEHOST.EXE
[86F7D07FB783988F3641C5CE41A74052][1
1072128 A4866412FD312C822996925CDBE
D1603DFC2034C
]C:\WINDOWS\SYSWOW64\D3D8.DLL
[6A7ACABAE92C837F5C1330188EAE36AE][1
535080 2AA4BF4F352B1B4BEEAD87E5CBE
E91A006F98D07
]C:\Windows\SYSWOW64\DNSAPI.DLL
[A3C3160BCD364BE6FCEF7FAEA15AC34F][1
86528 CAB3EC85281003B4CDF4E733BB4
7C8A608DF41DF
]C:\WINDOWS\SYSWOW64\ICCVID.DLL
[92347FC58A8BD2A45F440239EA9A4F04][1
12128256 FA4322C0BE583CD932D7CFD957C
8BAEF93A6DB9E
]C:\WINDOWS\SYSWOW64\IEFRAME.DLL
[1D80F6B8E8125AA2CB1857872D47EE00][1
885248 09667FDBE931D673E528CF3180F
56B010B805E3D
]C:\WINDOWS\SYSWOW64\INETCOMM.DLL
[237917AFE9016D1C6E1CBDCE97717B5D][1
282216 02E0B69655662B56FA74577A90F
882EE18DDE5A1
]C:\WINDOWS\SYSWOW64\INTELCPHECISVC.EXE
[7ED6FD05286C5CC5652C9196365E2EE1][1
151552 6C2CBD3418038B1699237801674
E26DA4CB9EC53
]C:\WINDOWS\SYSWOW64\ITSS.DLL
[7EA22EE5CFDC5D0D0A10769DA53E42E2][1
73216 729D642D809223C1F40CFCA4BD8
41150C84AF0E0
]C:\WINDOWS\SYSWOW64\L3CODECA.ACM
[6D879552B32CCD2536F66F4F88F54800][1
19344384 CC9FD23E860B20439BE2AD78348
1F0DEF331968B
]C:\WINDOWS\SYSWOW64\MSHTML.DLL
[D0D98F403155463C95508639BF283CD2][1
2362880 21B597B882F02372C89E4260182
AAE40081F3D75
]C:\WINDOWS\SYSWOW64\MSVIDCTL.DLL
[1F5B5642253FC9760EEACD81900C38DC][1
312160 757413A3EBFFA1869321D31800A
E7F4CB4DC87E8
]C:\WINDOWS\SYSWOW64\MSWSOCK.DLL
[BCB1BF49F2966FB37D0ADAE538C6FD73][1
55808 34D46607F62139CE44D94144CA7
0566163B1A3DE
]C:\WINDOWS\SYSWOW64\NAPINSP.DLL
[B5081D56F1CD87F6BF0BF1AA4E9C6BAB][1
65024 F6FB704B58FB8888E240E564922
CC694AE1A882C
]C:\WINDOWS\SYSWOW64\NLAAPI.DLL
[56DEB6F17F290B8C4AF8B2AA10097B55][1
88576 C1EFBFEF1D3C9703DD1EF14BC7E
91EA46724C5EF
]C:\WINDOWS\SYSWOW64\OLEPRO32.DLL
[0DAF7B7D85F7AF38E29161460899C63F][1
21504 F61F8E7DB2322BDE06954CD0752
0E5502B5058FC
]C:\WINDOWS\SYSWOW64\PERFHOST.EXE
[F56DE562FAA1901587F63DD289E71129][1
70656 C169FDD9E9D93407DF63C9EB8CA
D0654D7FE661A
]C:\WINDOWS\SYSWOW64\PNRPNSP.DLL
[2E947792E9B1C738E33FD5794B1650F9][1
30208 DF64F74E36BAF6FE91AE758D407
7DAEB0F0635BD
]C:\WINDOWS\SYSWOW64\TBAUTH.DLL
[B011360F95F911F025BC91CB17449798][1
1500160 87A53D895A232AC1D7E94A4A1A3
33E8F60610553
]C:\WINDOWS\SYSWOW64\URLMON.DLL
[310B40B6E8224393EAAE116335918A6A][1
23552 B861D6FA25EB7FD10370A5B4ED3
53CFAEA0C81F6
]C:\WINDOWS\SYSWOW64\WINRNR.DLL
[8450005F7BA8662A64E3FB7B0C3EE836][1
51712 64C8E8A06AA373C0788EFF8D056
F0618B8CE0F48
]C:\WINDOWS\SYSWOW64\WSHBTH.DLL
===
[MBR]
[MD5=6F5C728704818D7DC62499B0E441E6D3]
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA

AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAA=
===
[PT]
0xee Unknown, 1, -1
===
[VBR]
61KQTlRGUyAgICAAAggAAAAAAAAA+AAAPwD/AAAIAAAAAAAAgACAAP8PDgAAAAAAAJYAAAAA
AAACAAAAAAAAAPYAAAABAAAAflh/Cmp/CsQAAAAA+jPAjtC8AHz7aMAHHx5oZgDLiBYOAGaB
PgMATlRGU3UVtEG7qlXNE3IMgftVqnUG98EBAHUD6d0AHoPsGGgaALRIihYOAIv0Fh/NE5+D
xBieWB9y4TsGCwB126MPAMEuDwAEHloz27kAICvIZv8GEQADFg8AjsL/BhYA6EsAK8h377gA
u80aZiPAdS1mgftUQ1BBdSSB+QIBch4WaAe7FmhSERZoCQBmU2ZTZlUWFhZouAFmYQ4HzRoz
wL8KE7n2DPzzqun+AZCQZmAeBmahEQBmAwYcAB5maAAAAABmUAZTaAEAaBAAtEKKFg4AFh+L
9M0TZllbWmZZZlkfD4IWAGb/BhEAAxYPAI7C/w4WAHW8Bx9mYcOh9gHoCQCh+gHoAwD06/2L
8Kw8AHQJtA67BwDNEOvyww0KQSBkaXNrIHJlYWQgZXJyb3Igb2NjdXJyZWQADQpCT09UTUdS
IGlzIGNvbXByZXNzZWQADQpQcmVzcyBDdHJsK0FsdCtEZWwgdG8gcmVzdGFydA0KAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAIoBpwG/AQAAVaoHAEIATwBPAFQATQBHAFIABAAkAEkAMwAwAADU
AAAAJAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAOnAAJAFAE4AVABMAEQAUgAHAEIATwBPAFQAVABHAFQABwBCAE8ATwBUAE4AWABUAAAA
AAAAAAAAAAAAAAAAAAAAAAAADQpBbiBvcGVyYXRpbmcgc3lzdGVtIHdhc24ndCBmb3VuZC4g
VHJ5IGRpc2Nvbm5lY3RpbmcgYW55IGRyaXZlcyB0aGF0IGRvbid0DQpjb250YWluIGFuIG9w
ZXJhdGluZyBzeXN0ZW0uAAAAAAAAAAAAAAAAAAAAAAAAAACaAmYPtwYLAGYPth4NAGb342aj
UgJmiw5AAID5AA+PDgD22Wa4AQAAAGbT4OsIkGahUgJm9+Fmo4YCZg+3HgsAZjPSZvfzZqNW
AuiiBGaLDk4CZokOJgJmAw6GAmaJDioCZgMOhgJmiQ4uAmYDDoYCZokOPgJmAw6GAmaJDkYC
ZriQAAAAZosOJgLokAlmC8APhL/9ZqMyAma4oAAAAGaLDioC6HcJZqM2Ama4sAAAAGaLDi4C
6GUJZqM6AmahMgJmC8APhIz9Z4B4CAAPhYP9Z2aNUBBnA0IEZ2YPtkgMZokOkgJnZotICGaJ
Do4CZqGOAmYPtw4LAGYz0mb38WajlgJmoUYCZgMGjgJmo0oCZoM+NgIAD4QdAGaDPjoCAA+E
MP1mix46Ah4HZos+SgJmoS4C6O0B6CwNZgvAD4QDAOhCDmYPtw4AAma4AgIAAOgiCGYLwA+F
FgBmD7cOWgJmuFwCAADoDAhmC8APhHgOZ2aLAB4HZos+PgLoPwZmoT4CZrsgAAAAZrkAAAAA
ZroAAAAA6OQAZoXAD4UjAGahPgJmu4AAAABmuQAAAABmugAAAADoxABmC8APhUQA6ScOZjPS
ZrmAAAAAZqE+AujKCGYLwA+EEA4eB2aLPj4C6NsFZqE+Ama7gAAAAGa5AAAAAGa6AAAAAOiA
AGYLwA+E5g1nZg+3WAxmgeP/AAAAD4XbDWaL2GgAIAdmK/9moT4C6AABaAAgB2Yr/2ahPgLo
rAqKFg4AuOgDjsCNNgsAK8BoACBQywYeZmBmi9pmD7YODQBm9+FmoxEAZovDZvfhoxYAi9+D
4w+MwGbB7wQDx1AH6JL7ZmGQHwfDZwNAFGdmgzj/D4RMAGdmORgPhTMAZgvJD4UKAGeAeAkA
D4UjAMNnOkgJD4UaAGaL8GcDcArolwZmUR4HZov686dmWQ+FAQDDZ2aDeAQAD4QHAGdmA0AE
66tmK8DDZovz6GwGZ2YDAGf3QAwCAA+FNABnZo1QEGc6SkAPhRgAZ2aNckLoSQZmUR4HZov7
86dmWQ+FAQDDZ4N4CAAPhAYAZwNACOvCZjPAw2eAewgAD4UcAAYeZmBnZo1TEGdmiwpmi/Nn
A3IE86RmYZAfB8NmUGdmjVMQZoXAD4UKAGdmi0oIZkHrEZBnZotCGGYz0mb3NlICZovIZivA
Zl7oAQDDBh5mYGeAewgBD4QDAOnK+maD+QAPhQYAZmGQHwfDZlNmUGZRZlZmVwbokQRmi9EH
Zl9mXmZZZoXAD4Q0AGY7yg+NAwBmi9Hogv5mK8pmi9pmi8JmD7YWDQBm9+JmD7cWCwBm9+Jm
A/hmWGYDw2Zb659mhfYPhGL6ZlFmVwZnZg+2QwlmhcAPhCAAZtHgZivgZov8ZlRmVmdmD7dz
CmYD82aLyPOkZl7rA5BmUGZQZ2aLA2ZQZ2aLQxhmUGdmi1YgZoXSD4QLAGaL/h4HZovC6HED
ZovGZlpmWWZCZlFmVug/BmaFwA+E8flmXmZZZov+HgfoTgNmi8Zmi9lmWWZaZlFmVmbR6ej4
/WaFwA+EyvlmXmZZZgPhB2ZfZllmi9BmWGZbZova6fX+Bh5mYCZnZg+3XwQmZ2YPt08GZgvJ
D4SY+WYD32aDwwJmgcf+AQAAZklmC8kPhBcAJmeLAyZniQdmg8MCZoHHAAIAAGZJ6+JmYZAf
B8MGHmZgZrgBAAAAZqMiAmahHgJmAwaGAmajigJmAwaGAmajTgJmoTAAZg+2Hg0AZvfjZose
TgJmiQdmoxEAg8MEZqFWAmaJB6MWAIPDBGaJHk4CZoseHgIeB+i7+GaL++hR/2ahHgJmuyAA
AABmuQAAAABmugAAAADoEP1mC8APhBkBZovYHgdmiz4aAmYzwOii/WaLHhoCZoE/gAAAAA+E
6wADXwTr8GZTZotHEGb3JlYCZlBmM9JmD7YeDQBm9/NmUujcAGYLwA+EmPhmiw5WAmYPth4N
AGb342ZaZgPCZoseTgJmiQeDwwRmD7YGDQBmK8JmO8EPhgMAZovBZokHZivIZloPhHUAZgPC
ZlBmM9JmD7YeDQBm9/NmUeiCAGZZZgvAD4Q8+GYPth4NAGb342aLHk4CZosXg8MEZgMXZjvQ
D4UVAGYPtgYNAGY7wQ+GAwBmi8FmAQfrpYPDBGaJHk4CZokHg8MEZg+2Bg0AZjvBD4YDAGaL
wWaJB+uCg8MEZv8GIgJmiR5OAmZbA18EZoE/gAAAAA+EDP9mYZAfB8Nmi9Bmiw4iAmaLNooC
ZgM2hgJmUmZRZlJmix6KAmaLPlYCZosEZqMRAIPGBGaLBKMWAIPGBB4H6Dz3Ziv4D4QIAPcm
CwAD2OvZZos+igIeB+i//WahigJmu4AAAABmuQAAAABmi9HogftmC8APhFP3ZovYZlhmVugs
AWZeZgvAD4QFAGZbZlvDZllmWuKEZjPAwwYeZmBmUGZRZjPSZg+2Hg0AZvfzZlJmV+hT/2Zf
ZgvAD4QN92YPth4NAGb342ZaZgPCZqMRAGZZZg+2Hg0AZjvLD44TAIkeFgBmK8tmWGYDw2ZQ

ZlHrFJBmWGYDwWZQiQ4WAGa5AAAAAGZRBmZXi9+D4w+MwGbB7wQDx1AH6GT2Zl8HZgM+UgJm
WWZYZoP5AA+PcP9mYZAfB8MGHmZgZvcmVgJmiw5WAuhV/+jS/GZhkB8HwwYeZmBm9yaSAmaL
HjYCZosOkgJmizYqAh4HZos+RgLogfvop/xmYZAfB8NmUGZTZlFmix5KAmaLyGbB6ANmg+EH
ZgPYZrgBAAAAZtPgZ4QDD4QEAPjrApD5ZllmW2ZYw2eAewgBD4QEAGYrwMNnZo1zEGdmi1YI
ZjvCD4cLAGdmixZmO8IPgwQAZivAw2cDXhBmK/ZngDsAD4Q+AOiBAGYD8eg5AGYDymY7wQ+M
IQBmi9FmUGdmD7YLZovBZoPgD2bB6QRmA9lmA9hmQ2ZY68RmK8hmK8JmA8bDZivAw2YryWeK
C4DhD2aD+QAPhQQAZivJw2ZTZlJmA9lnZg++E2ZJZktmg/kAD4QNAGbB4ghnihNmS2ZJ6+tm
i8pmWmZbw2ZTZlJmK9JnihNmg+IPZivJZ4oLwOkEZoP5AA+FCABmK8lmWmZbw2YD2mYD2Wdm
D74TZklmS2aD+QAPhA0AZsHiCGeKE2ZLZknr62aLymZaZlvDZgvJD4UBAMNmUWZWZ4M+YQ+M
DABngz56D48EAGeDLiBmg8YC4uZmXmZZw2ZQZlFmi9BmoTICZ2aNWBBnA0MEZ2aNQBBmi9ro
RPlmC8APhAUAZllmWcNmoTYCZgvAD4UIAGZZZllmM8DDZosWNgJnZo1SEGdmi0IYZjPSZvc2
jgJmM/ZmUGZWZlhmXmY7xg+EOgBmVmZAZlBmSOgb/nLo6Ov9ZlpmXmZZZltmU2ZRZlZmUmah
RgJnZo1AGOjQ+GYLwHTEZllmWWZZZlnDZllmWWYzwMNmUWZQZrgFAAAAHgdmi/nojf1mi8Fm
uyAAAABmuQAAAABmugAAAADoM/hmW2ZZZoXAD4UVAGaLwWYPtw4QAma6EgIAAOgW+OszkGYz
0maLwWaLy2ZQZlPoIwBmW2ZfZgvAD4QXAB4H6DX9ZovHZg+3DhACZroSAgAA6OH3w2ZSZlFm
uyAAAABmuQAAAABmugAAAADox/dmC8APhGMAZovYHgdmiz4aAmYzwOhZ+B4HZoseGgJmWWZa
JmY5Dw+FDAAmZjlXCA+EMQDrE5AmZoM//w+ELwAmg38EAA+EJgAmZg+3RwQD2IvDJQCAdMuM
wAUACI7AgeP/f+u+JmaLRxDDZllmWmYzwMNmUGZRZovHZsHoBAZZA8hRB2aD5w9mWWZYw2AG
vmkOvwAgHge5DQCQ86UHYcMBI0VniavN7/7cuph2VDIQ8OHSwwAAAAAgIGCLNhggJooFiARH
Rmb/BhQggf5gIHUG6FsAviAg4uaJNhggYcNmYIs2GCCwgIgERjLAgf5gIHUG6DoAviAggf5Y
IHXpZjPAZqNYIGahFCBmweADZg/IZqNcIOgYALsAIGaLB2YPyGaJB4PDBIH7NCB17mZhw2Zg
uyAgZosHZg/IZokHg8MEgftgIHXuuwAgZosPZotXBGaLdwhmi38MZotvELsgIMcGGiDcD8YG
HCAUkFOLHhog/xdmA0cCW2YD6GYDL2aLwWbBwAVmA8Vmi+9mi/5mi/JmwcYeZovRZovIZosH
ZjNHCGYzRyBmM0c0ZtHAZolHQIPDBP4OHCB1soMGGiAGgT4aIPQPdZ+7ACBmAQ9mAVcEZgF3
CGYBfwxmAW8QZmHDZovGZjPHZiPCZjPHw2aLwmYzxmYzx8NmU2aLwmYjxmaL2mYj32YLw2aL
3mYj32YLw2Zbw6gPmXmCWrUPoevZbr8P3Lwbj7UP1sFiygYeZmBmM9u4ALvNGmYjwA+FuwBm
gftUQ1BBD4WwAIH5AgEPgqgAZmGQHwcGHmZgZ4B7CAAPhQwAZ2aNUxBnZosK6yWQZ2aNUxBn
ZotKKGaB+QAACAAPgwwAZ2aLQixmI8APhAMAZjPJDh/o9f1mI8kPhDIAZroAgAAAZjvKD4Yf
AGYrygZmUWZXZlJmi8rot/3o+/1mWmZfZlkHZgP669ropf3o6f3oC/4OB2a7VENQQWa/ACAA
AGa5FAAAAGa4B7sAAGa6CgAAAGYz9s0aZmGQHwfDBh5mYGYz27gAu80aZiPAD4V0AGaB+1RD
UEEPhWkAgfkCAQ+CYQBmuAe7AABmu1RDUEFmubgBAABmugQAAABmM/Zmvk1CUkNoAAAHZr8A
fAAAzRpmuAe7AABmu1RDUEFmuUIAAABmugUAAABmM/Zmvk1CUkRoAAAHZr8AfAAAZoHHvgEA
AM0aZmGQHwfDZlJmM8BngHsIAA+FDABnZo1TEGdmiwLrC5BnZo1TEGdmi0IoZlrDBh5mYGYP
tw5mAma4aAIAAOj8+mYLwA+E+gBmD7cOdgJmuHgCAADo5vpmC8APhOQAZ2aLAB4HZos+PgLo
GflmoT4CZrsgAAAAZrkAAAAAZroAAAAA6L7zZoXAD4UjAGahPgJmu4AAAABmuQAAAABmugAA
AADonvNmC8APhUQA6ZMAZjPS
===
[SIGN]
[B76B8924F91072D25FC29ABD82A28D5B] Microsoft Corporation
[752C1127E137083C0D120EBF74E336C5] Microsoft Corporation
[1B137C417E86D42D3F48ACF7CF9E553E] Microsoft Windows
[09D23CB52A1508A7F96AB656DFB8B548] Microsoft Corporation
[64B21B3E863BE0B42FAEAA17DD9292A9] Google Inc
[750446ED76A5D13E902174DDDDA1A62B] Google Inc
[127E0F8100D329A3814C80F47713FA79] Intel Corporation-Wireless Connectivity Sol
utions
[DE70C5C10803C700DC1CFDE2D5CF207A] Intel Corporation - Embedded Subsystems and
IP Blocks Group
[1CE3A27B6B0658F4242AB2DECE69704E] Intel Corporation - Embedded Subsystems and
IP Blocks Group
[F44CA6BFAAAB8C27B4A688E2D3CDD728] IObit Information Technology
[C72EE92A4C995B0DDC0255FEB59BE151] IObit Information Technology
[EC43E30BEB3E06E5DAEF4D49A81220BC] IObit Information Technology
[DCE4D6B8A07E18E719A10311E4FA3125] IObit Information Technology
[09F0E4D1F66C40AB770AD1540758C59E] Kaspersky Lab
[784F6F48C541F383F90AE4C5B3FCE0B5] Kaspersky Lab
[CF93C0D4B408F5BF9801E49FC3A63F3D] Kaspersky Lab
[8F94291E9665EE667214C01780777B92] Kaspersky Lab
[62E40B04DD9A4915FBD798FD273526AC] Kaspersky Lab
[B48F79A7B58EB9A5E4894A96453C6957] Kaspersky Lab

[CE8477DE4E12022AAFB3075CC1688DED]
[E9A46FCB53833669A4AECABD60BAEE87]
[EEEF244E90F709BF393EC649CD8F3028]
[CB609E1E85B2117031431AEEB4ACAC63]
[1351B590E4B2FE5DF40D3157950B3912]
[E6DB86C3E24B0F76CA139C6C89853DDA]
[B0271E30A7E4E0385E4F2291EEA97B32]
[D697F01FDEADC1EA4E5F54158CE7B6A3]
[69BD29240C9C4AAD5C2046F24D40CC96]
[020F45E362D3B57CCC5735582BB1A6EC]
[94A8196066774252DF015EEDF02CCA44]
[E829D42DD6C64DFE2587FD9B9F598693]
[D1F515B1C897AB7D26E1EB4970892E76]
[97389A435853020EC82835934C64CFFA]
[B044435A68D8EAC596E48473A05E5BDC]
[8532792113BDC019923A2B04DE62BE67]
[F3A57F42D94B3B7CD1F6D82600D14C98]
[09D8EBC01776C2D117918993EDDC19B2]
[AB19DB70D94FFC43B5C5EA00D57DFF1E]
[6B8366AA47F166C89848A7FB1103BB24]
[B91EE7363FDC2B0CB1C5E6190B46F7DC]
utions
[22004B9C1C7C73BF97D11F9C158FB3F7]
[58327B7E7C4E325C66B7C4A5220CE5F4]
[41CCA0C13E03F9C1443BEF374B4BBCFB]
[B63CF22D1AD2ABDC39D85851B2BEAA6D]
[D90885430767C6152AF908D57A5159AC]
y
[FF9F8695FA627E3BE6CF14239B44234D]
y
[6DCB7233AAD29E43331B3ECFCC8FB8D1]
utions
[F1F6EE6C068CBDB80BAC43A79591F1F2]
utions
[65308E8DDBCA0A3D7A72E3404E194319]
utions
[4180512B8E8E1F0CE1F8C546C090DB97]
[5CF3AF4EC4A374438EBC7CD820080FCB]
[56CA8297F6F97DF3FF2898D5A738E426]
[30FF10C903D88749E0D1B12B53F78A41]
[B3E1F6B325BC2DC5DDB701406255E9A4]
[F7C0982B7D302064CB227BDF35B9C1DF]
[1867F14EE28F2CF846BF05D1031A0FE5]
[74D94B97E44878044D6AA02C7DDB5D29]
[CC954D5B0AE39E621CD39659DB10E85B]
[111350FC207AAF2E39DA9F1AD672B8C4]
[F78BC07DCED5EDDD6D477E923620F8EA]
[09C1C6CA8A8708ADA417BD1F5FBB0559]
[EF0609095F508A24C3AD49352BCB38A0]
[78C48AD707AADA8E7692A5D58E7D6753]
[8705EE93E1BFC4308F0DEDA2FA02DE3E]
[D635E700E43F4ECA021FD159CFF3F8B9]
[02B07DA28089AAF8034749BCB5DD3657]
[09D8EBC01776C2D117918993EDDC19B2]
[7990F2BD88507BA0343317353D2DF6F1]
[EECC6FB48D5137A331D02AAC1D99DF8C]
[8F2EA5EE0695CCE2285D92C44108375C]
[E15BEB03592BA12C5C99E2BA46146BDD]
[8F26CB57B225F046E49A4D8003DAE920]
[9E9BEB22644CE1DA521A1D7821BF891F]

LENOVO
LENOVO
LENOVO
LENOVO
LENOVO
LENOVO
LENOVO
Microsoft Corporation
Microsoft Corporation
NVIDIA Corporation
NVIDIA Corporation
LENOVO
Greatis Software LLC
Greatis Software LLC
Greatis Software LLC
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Bitdefender SRL
Intel Corporation-Wireless Connectivity Sol
Microsoft Windows
Microsoft Corporation
Raxco Software, Inc.
Intel Trusted Connect Service
Intel Corporation - Rapid Storage Technolog
Intel Corporation - Rapid Storage Technolog
Intel Corporation-Wireless Connectivity Sol
Intel Corporation-Wireless Connectivity Sol
Intel Corporation-Wireless Connectivity Sol
Microsoft Windows
LENOVO
New Horizon DataSys Inc.
LENOVO
LENOVO
LENOVO
LENOVO
LENOVO
Microsoft Corporation
NVIDIA Corporation
NVIDIA Corporation
Raxco Software, Inc.
Raxco Software, Inc.
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Kaspersky Lab
LENOVO
Microsoft Corporation
Microsoft Windows
Microsoft Windows
Microsoft Windows

[E50DD57F496CED8873FA3E7D38BCCD42]
[B4AE5296C9597F45E1CFE0B1DBE7739E]
[61EE0E80EF7FD384C37A591CF9379DC1]
[3EFB194760F2C347E53713AA8D7A46C7]
[E65AF7A23F6B8A8E270A4D237D906407]
[9A3E17CDB177913C2A111C80F3D0DBB4]
[5F96092CC55C643837C891F082007C9C]
[1A2E3B6697F5468B0D4FD47E340D3E90]
[706EAE0012D8489D1DA0FD73140A4D93]
[348DDE16E5F6E24CD8A5CB31A0B2297C]
[0F2B1FB6DDFA739AF5E50915DC134334]
[6ABAC83AD594B0390C470F9C1C017382]
[73C44205E57B561FAA308312B108165B]
[12203B26197D49D2BDF7B27FCB7C184B]
[C1B13204994572C941C14A7FF410C4D6]
[A3A66211CF74409C7B7D200E1B945DBE]
[199298181CB86E5056D82BD1F86C8A97]
[84E12C5A6041EC7C629A1FDD2581D0AF]
[D2B807A29858D89EDB1D8D5415B9E6F6]
[309CC67EC901D1D42A5E1D3975DA3E77]
[52B49D01CE8F8EEC3D557D2CCD46548B]
[50FED971D0FAD2B990C0A05735761D62]
[B339861C6A2A86FBCA67C2006B461473]
[930A1C518D65A9E781CD16C9BCFC5BEF]
[6FF8248F3A9D69A095C7F3F42BC29CB2]
[864BBE3CC3478AE5C53FFD5E7C95AA63]
[F5F7CE3E32536F1A37FB3972F27A814F]
[76CB0E0CA741CE280F9B9D2D2BCD2CCB]
[5C156EC4E44E30331BCC865A3B61D839]
[4DB377DB30B00E59828E8BA4C90C680F]
[054916A6A9C86607869D247F2CA425B5]
[C3534256AF526A16AADBA335AA99D58F]
[19707ECBCEA71080A85DB2336580DB39]
[AA91A5E156D0364ABA7B01658C2EB014]
[7F3A0D052B8E00E730316210B1DD092F]
[7A55F9237F726D1667073A47B0D1B90F]
[56E219DF92BE16F62308F884739BE022]
[EB8B7935A446A137163AB1F94CD11B2A]
[B4AE5296C9597F45E1CFE0B1DBE7739E]
[610499A73DF3599608EBB6B3F9929052]
[42BF7FA295F453618104B5A50BEE105B]
[2A2C0983B6FE62F02E7183335B1F5C20]
[7062CE507814D5306DCA5D6A15B7B6B6]
[F374C27099807E99A156953F8416D34A]
[37F5E2385CB4D10AB42186974B9C241A]
[4F2621E187382D22045D0BC65B23858E]
[A617BE5E429A035A1CA8217C1B16F0BB]
[BAB101E7826BE287F79C4BA721621989]
[7A177E18AA6A6A6365E6351C2BF8EDAE]
[0A92DC116CFC7F6BE8167DD25CB925CC]
[4E9158CECF77A029AB98E8FBB43FCED5]
[F7526C133AC265F283012E9CD751F873]
[841F937D7B6A7EB605D1B4535DE889DA]
[86BE19C6A177AEB93302EA5C4FBE2D11]
[9E79A2208A9ED205A7383CBC92C28053]
[5F07CCEE514894C9474AEDCA50B6C2C7]
[D12B9B6A6C4885824876422AACC89954]
[0967A14066601A948A32B12C5858CB4C]
[620921E77351FB651632322AD2C195C4]
[6129EA4294C5C69E4665801E95B16AB2]

Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft

Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows

[16EE6701115BECF8C657D9D6E123F6A1]
[5BF8BD9B19D665452494C8D56DF4B28D]
[D461D2BECEFA661291EB1B748A8D2CCB]
[9F5AC03F5A0000DD96FA29CD68A6605B]
[15D174719872A30F2FDD6B5B1B8BA5D9]
[9513834DAC717444F04169EA5D120885]
[5EF8EC71A7A91F3DF7798BEFE6786B0E]
[5839A317C25F70979433E0905DFABB1B]
[1B15297A3A2CAB6BD586676154F389D8]
[316C2D8B8E3C0727969F1C3790EF7193]
[DF1C3D7E6C7929AD83BE22852B5B08CB]
[2C5B3035B86770ADD2FE9BFBAF5B35A4]
[469441BAE3FF8A16826FC62C51EF5E18]
[7EADED8087C392876521F7EBCE846EF4]
[C498887123327CDFD73A05E7A2780920]
[C8DBE6EFFCF014CAA010B9BDDAC833EC]
[17039DBEB3B7B9ADCDB4B4533AA9771F]
[E13DE7CD2B62254DD4FF658B7798A37D]
[F7D0CD345D2DA42E7042ABCD73662403]
[70148EFA9A562E7185B75BBE7D376BF7]
[E15A9CE1E2E7D1C8DF97A4FC1FFE6289]
[870F1A2C936F92B5D053DF7EC75B352F]
[3DF7751D5DC6525E7DC6617FBB45054F]
[B70F0F2F54B4A4DB6E9C830454752F5A]
[35E890482C9728DD5C552B85DA8A5AB2]
[5B30BCFE6E02E45D3EE268FF001BC5E0]
[F20B30F35A5C7888441B4DCA001ECF8E]
[AFE838D7576C581D6483529621AB10CC]
[EDDB0D726DBECDFC1DBCC6DB464E5A13]
[E3FE8F610B1CC12BC3B2E6BC43DC97E2]
[5E00748A1AD246CAECBBB7553BED36CC]
[492B99D2E3D5D7BFD5F0AE1BE7BD37DD]
[B4AC08B1D04D0CE085435E5CD0E663C5]
[25B5BB369DEE2BAE4BF459C978FF9035]
[3F5523DCEFE42B385659C5CB46A6B810]
[0B750A6A6D847E73CA48ADD7A0F5A393]
[DA2C6F7ACE392193C424FEA975C5BFFB]
[A4411C522D41707D5BCA817A5BB9E30B]
[CAEC7BC11AF69A181AF7932E636E09E4]
[3C7DE7B7CAD633CD2DA07710BC17361C]
[5F2B4B32E986C058525D3BA2A475A16C]
[5406289E8AE2CB52FC408154E0A64BA7]
[3B3BF88BB54CB9A18DE1EF07292B5A3D]
[A76F20CCCA31895A1DA78A875E50F946]
[09C3DB1B137B269A822F941D867A6BB6]
[FFB773E4AA55E4F5FBBB084B41D7A86F]
[BE265ABFB467BBAC8C73A55AD94F4216]
[BF89BDBA5D3A0B4256D3F6FC8D31880D]
[6447BA6FA709514B6C803D159B4C7D1E]
[C24C27FDF93B85A4EFCF25F830253AA2]
[7F9C7226D743B232907ED2537B8A574F]
[82D97776BF982AA143BDC7DFB5054EA8]
[0505C1D991D0F9D47F3353BB98597C7E]
[8B4B39C507ABA09AAFE8E3932D1B392C]
[B2A6D2A30E93B6F215F74AC7E1733C9C]
[95832B049E2833B9F5189823CDF946C7]
[3F7C80D9F16B94367646CBF8B8C052F4]
[58D640BC2294C71BDE0953F12D4B432F]
[02B8E49148DE5E0A2F6FDF28CE94A6AC]
[5D578EAAFB6FD4F59523E5878B541296]

Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft

Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows

[2619DC483579DB9FE804044C1ADFFD1A]
[935823F79CBEDB91637B63D37E3A5A36]
[4904B152E4942BF700F2D73228B4D477]
[0197AE4B9790A4E73751CACFAA480126]
[4310841C9B6773A4F01D6057710BA145]
[25FA06D3B49D6ADF8E874FFCDCD76B50]
[8B83335B6A86F39785FC7C9DE5F5B29F]
[CEF108FCE06892CFA5F1B49527D4BF49]
[5B1EAAE3001A7A320C106FC3859F4111]
[7A2705148A4BB3CA255F81624338B461]
[491275B864B704B54EC08168344E0F38]
[F003B437645009FDA04AB266EAD240EB]
[9D299AE86D671488926126A84DF77BFD]
[8F2523C9D8F1448FF2156452AF60FA00]
[92ECCFA58C8195B8EA33ED942469D4E6]
[87C51FDD50C17882BA93E28BBABB9847]
[E99261DD76D1C9E05AF575939CAE5AC5]
[25D7A58625E1453E40D36825DE74E4F1]
[B4175E8BE60B099686FF55CA7D692316]
[50DFE05C698E9B0A63D95E3D669A105C]
[B9981A4CB9F728B3312A3885BFAA7204]
[F3AC9652D88BF87BA6596CBEA28CE10F]
[D011B0ADB15F4815310CE1BF4780B33E]
[84BC034B6BB763733C1949B7B9BAF976]
[0F93EBE9071A6BB1548BF0F816EEA24B]
[6B8CB114B8E64C0636EB49F7B914D1FC]
[D1AD197CCDAAC0CB4819DA1D6EB17BAE]
[64909DECCFCC6FB5D9A5BAFDCCB31FEE]
[F510F7B7BF61DEAAC04E65C3B65E8D59]
[90F3ED42D423C942BA5EA54E2FFE7AC7]
[128DEDDD61915DBA4D451D91D21F0513]
[FF442DCDCE1F6E9FAA9C8AD0CD1D199B]
[63C3F74DC398A1C1A77E39DFB9C312CA]
[CBA5E88A0F0475B7F49653BB72150BEF]
[D668FAB4B0397B426EE3D41683B9A1C0]
[53FDD9E69189E546DE4740F8C4D8AB2F]
[9A2A2F3C69B9A30B6E78536F6D258BAD]
[8FD3487A6AE70321404C34AC278840D8]
[4D962133CAB3A8555E7B1FD8D6BF38EA]
[59A20F5AD9F4AE54098154359519408E]
[16A10CCEDCF5AC4CAAE43DC9FC40392F]
[EB82A11613326691508D9ED9A4FE29E7]
[5F6CA62BE8ECC4D0E1F5D4D4A02B456B]
[6B0029A0253098CCE28EACCFDB9E7208]
[9652E1E35A92D8C75710C17A63B15796]
[FFADF691F7BF727AF5C863454A372723]
[94F952B4B0E440C9562FC8074D52BC4B]
[657224010BED3776D669391E313C0F5E]
[907C8FE6894710604AD1F1F92324A7D6]
[ECDB27420D3A98424666904525A8562A]
[63C827AAE9117D8EB9C4AF4621797996]
IP Blocks Group
[8FF1978643EFD219C5BA49690191D701]
[B61B60F36E1C8022FA8166ABF0F66B07]
[CA0D42029AFFC4514D295E1EF823D02D]
[6E3F9D95235DFC9417384080A216F310]
[4F527ECB5EAB47D8EAF34A469666C469]
[9E5E8F2A1996F23B7E9687846AA81B01]
[C317EB660138BC9CBFE37CCDE56351AE]
[531994A6D9399D9B74BE12B5BB58A81E]

Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
New Horizon DataSys Inc.
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Intel Corporation - Embedded Subsystems and
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft

Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows

[701D7DB13B0815E7076EF4CB4CE981F8]
[884EBBDDBF5968003B40185BD96FF0E6]
[6B3A0C7902811E6372643447E41F7048]
[62EBD4202B505ACADE2FBC56CC73E0A2]
[86F40D79CE80ACBE6BEBAC8CE89D75A0]
[1B321722C507A04E1EAFCFFD0F7B7EF9]
[B12242478186B62B2E214288B7DB3612]
[E2097C8F18F1E8E3B7D09F12B51843A3]
[C64655B935BCBB5AB39F87F79F5087A6]
[E06446CAB518D66247E8042B3FDC6CDB]
[D49C6C43CC00296BB942BD12764E707B]
[5D9960343E6866C420727727AFBE17BC]
[36E044A2C64FCBCBC0F42ED5050F9CBD]
[FD47C92A63B6EADEA830BFA96C06EAEE]
[26E1917517E613D07F2A122CEEBB8161]
[26D3895A519220E94D241A8858D40CD9]
[6B98C134815C9AB284F9DEA03B8BD5E8]
[58CD685752080EDAEB4EEC7E6428546D]
[982C795DE20CED7AEDD2E7899B5D9BC1]
[425CFD45BDF5B9F8B790BEB20E0A8721]
[E9BB0023D730701BB5D9839B44F5E6B5]
[EC34EED89C34B27C292166B725AC7A7B]
[961F28D879D345BFA50AF51285C90F2E]
[6BFB8D1B3407518BE06B6F81F92FA0F5]
[BE0E47988D78F731DEC2C0CB03E765CB]
[F99BF02BE9219986817BF094981EEB18]
[2FCF837196082864F66CFD9CAB256275]
[2ED29B635F35E31A1C0D3DDB7DD2AD03]
[22E3CB85870879CBAE13C5095A8B12E3]
[D41920FBFFF2BBCBBC69A5B383AD022E]
[64BD0C87064EA20C2D3DC4199F9C239C]
[8D4B46FA84A3A3702EDADD37FAC6EDBA]
[78FEC1BDB168370F131BFBFEA0A04E9D]
[D1CC0833CFBC4222A95CAA5D0C8C78FF]
[C2E05EC6B80BCF5AE362DA873E1BCE64]
[D5B7668A8F6C67C51FA5C6C513396D6C]
[5FBCB85D127BE21E3A9DAF11A13C00EA]
[BF6CA7EA5ECD6CF72D3D76652A9B8280]
[0B3B0C1D86050355676640488FA897D3]
[1A490555FD330CA2764D89191177C867]
[0F47A6C09F0A7FB5513D322A2B9BE4EC]
[F802FBABF0C4DF1BAA733187B2E476F5]
[B3358F380BA3F29F56BE0F7734C24D5F]
[B2044D5D125F249680508EC0B2AAEFAC]
[36ABE7FC80BED4FE44754AE5CFB51432]
[59307FEAFC9E72EEEC56B7FD7D294F4C]
[68D5354A4A9692EEC24664C60F47D4A2]
[E9457EDFEBC774199F907395C6D09CA2]
[C85D79735641D27C5821C35ECDDC2334]
[EF75184B64356850D0F04D049C253526]
[543933D166C618E7588EA77707EC1683]
[E887FFDD6734C496407E9219225CB6FF]
[83A2AB75951000D681FABDB80C07AEFC]
[4FA0483896FC16583851EFB733FCB083]
[60F88248608315E13391C2F1C3B4473F]
[218705233D02776AE4D19CC37D985C1B]
[B57CE307DA101C739885B7CC0678077F]
[E582DA849A58524E645545FB68B6625D]
[202260E7CDD731A32AF62ABD1ABEE008]
[A1D473D0CF10561F29B58EA7C5412A92]

Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft

Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows

[1A0AE283B8DE6BB76412A0F8213D45AC]
[A74EE2D2C0BFF5EC3A6185791868C4CA]
[32A9BD1342640D48AD85C8B3E812B984]
[6A6A8CF5EE61801375A38EBB871D4057]
[50AEF8EF0064A91ABB08D858D039C9DE]
[883A36E2FF7FA3E1281CB575579FE3AF]
[026618ECF6C4BEBDCB7885D42EC0DBE4]
[C03E926B0E7D66D68994067231DC3246]
[93F9E44D6AA0FFDE901D53CEF389AADD]
[29395C214D2CD4C81F73166AB988A797]
[2871225495F832A8C8A7DD1A17EDB3DC]
[31F990B2B6B91E9D7A667405CE12FCB1]
[85C3FBD47FA65313A5DA31FC1A9BC249]
[604D27CC38CC23493F218D0BB834B3FF]
[8B50D897657AB4A15FD9E251BBF7D107]
[AA4CD20708B7E0412A5316D7E2875103]
[596FB6C5A72F34B7566930985E543806]
[7D0FC96264C0F8F2C1321E33E8EB646C]
[032F1C32A6A97C317AEFF9D64D2A1D8A]
[D330D74B5F99309B5CCA30AE41C57CDE]
[CF78AF126B00C1B0A6FF45BD838E8EFE]
[2B4D98DF0CA57FB9536DBC80D2449D1F]
[F4D5793BF2E58AF15C6CF2FEEF9E73EB]
[22A53744CEEADFFFD33BA010FAD95229]
[67B9684B8272D5EBD1CCBB1DBD425EC8]
[9F5E27C8B88A8DA1DC93E93A5C27BB9B]
[E2F8376F9731D12A009C522036C6073A]
[1398A85E59698067CBBE1D66A9C13ADF]
[35F7C7AD709D909D618D9EDF987FC3ED]
[21AECFF3EB5748CBE12538A2500EFDE5]
[CFBA9C976CBF6796E5DC39EF59984021]
[7B2AD8C55217B514C14281AB97B4E21D]
[E3C82823B22463BC38AA4F8ADA852624]
[3369023EB5790A75BA7DABA14B75D922]
[5BA6B9AD03B81546BA64E488C4EF9D17]
[1E32A8CD65C4AD0A827CFEB13034DA29]
[2B648363E4C5E34B469C58596F377DD9]
[D0221C13960E274CC539D72D5A842ED0]
[1DC2CC74B51E4DC4CD5A20C1021E4010]
[177DF954D0DEC0465A380C75F6E7F65F]
[5D1680871054D2B0B8A971BC8AB3B837]
[AEEF76F938188EBF27DF70C1806877F2]
[0AC5FCDC29ED97ECDEF1276425EE2059]
[12A3D1530E3F67B8664EBA923A3981E4]
[73D45AF87AD38A24CD9EA7834324D41C]
[924449B5A5A6AC96BBBED49915E40719]
[530F797129776AA7E81994783A97E2AD]
[9B6B1D4DB35A3D9BEAF023BC95E1F49D]
[B24408471C1BCB17FC44F5B47EA8DEA3]
[DE6D7DC78D956928F59F7415A0F41E13]
[67585C295FF2D221679E376B68893B35]
[B8C4852CBCAAC1374C08EC7445443824]
[D3A103944A8FCD78FD48B2B19092790C]
[249A563C48DFD9E42A37587653E003BB]
[0F5B43074AE731D2C6F061241C9D84A6]
[D9FE59276BD56A9643C32D5FACE2F251]
[ABBE803FE0BDAE0E5BE74DDEFBE62F23]
[6043DF55CFE3C7ACF477645FA64DEA98]
[7EE0F7F86557FCB8A70E85A51D28224D]
[1A6CB30F0EFC1632E6F1B852CA892583]

Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Greatis Software LLC
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Raxco Software, Inc.
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows

[E1C158F6C00359278727A2CEE5D2ED71]
[BE88248427A6AA548A904FD867667F70]
[2568B86F6A50D254324CB89022CA9EFC]
[6E520D6B16EA8AE23D1F81C1194F00C8]
[CCDA497C880AD16D87EDFAEFCFB2EDF5]
[BF8EA6FC3358C2F69678E3E94F764F84]
[CC21DB3EF619B9480FE31A4EFE92CBEB]
[390B8A75768E2689586539C224520895]
[770A92D9D3A0BF61C97C3AFCB36847D9]
[736A2418E3E7F3DB3CF6EB0A55D1D581]
[BD98B0225BCD49E8A62F4F8EE1D1F613]
[CAE4B27B469C583131EA5AAE622F5D76]
[3FA9FDECDF704C2622FB81E34BDF0D8E]
[083A727D784009F9CCFB120C7841B7AF]
[17F37EC9042D84561C550620643D9A85]
[91D3F2A6253EF83EFBD7903028F58C4D]
[48F64A35BA9F2E4AC0587DDA555FF951]
[E730D0EB1B84EBC98423FC8D285EDBC0]
[87B9ABB965F7AF987D52791F0DD1663D]
[48E828C66AB016E48F2CB4DD585315FD]
[267C76EE60736EA5A1811A53FA02AABE]
[8CE72F094B822AD5EE9C3A3AFC0C16B6]
[42C546414F80BD6C0137FC3A106F8A69]
[1686DBC81748B096232B15F16C302985]
[82D3B1F4D80057826AA649D78147DE36]
[1C95F7CE37D9EFB90EBE987A9712356C]
[AED081772091C98173905E2DF28C223B]
[DCA34A111C29E4578DF2B8CEA3C7CDBD]
[718A956AE00CE086F381044AB66CC29C]
[BA760F8E66428BA9FF1E8BFBC6248136]
[05DD22294A4F3F89E52351C7721E6D2C]
[2B1DABA97DDF5365FC66EE7DEDD86A13]
[2A87EA182EA333D79AA0B03833EA67F2]
[6DE78C04BF32ECA7AF3064F53687C9A5]
[67D1E0E6E4D5D33AF0AEF0E33B4DA0F4]
[11680607944A719EF20E0E740785712A]
[1973905F86420E6E216C1825E1A5D0E8]
[2410A0C20D21A25E6C01979FA886BE90]
[6E59CE43B6BA5AA1ADCF36A4DBBB92BB]
[E8A59FA109A22FC07E44BDFCC9727DBD]
[D8A44550ECE102B6443F5D54DCE7DAB3]
[66B3D22DAB5312FF238ABF5C6D9F8FAB]
[3E4F20DB902D2E2914F3FF3DB9772200]
[41F7F00D76904416EF1F9EFA1A4C37A2]
[E7463CE8579A0418A98BE9BE42C647D7]
[DAB35CCA86F5FBE77D870A40089BC4A1]
[21162F65C7756AAECAEBED9E67D0A5FE]
[4AAD6547953D373A1EB5B2DF583D868B]
[8949F77132A4F8F3BA17C6727099F002]
[8B3E458A8851F9A3B2109B1680EE1159]
[4B13B61CBB9CC3CB373C60B930D648F5]
[9E9D58F5E1702955B2F4D62996F80E8E]
[E1BE37312785A71862516F66B3FD24CE]
[E42C0F2850735FF9D908B9DB581E6314]
[EC15FD6A28757793E2DA394CD94ABD52]
[D0C9632C350F46786643A069251BC249]
[E886CB75DA2B6EB35469EF10135624C7]
[46D2EC27820EC0F798F85821E53C2942]
[77555B11B264991DDC26872FFCF1AB97]
[044890BB0D6CF1E23C1087234D320509]

Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Greatis Software LLC
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows

[32FF460DA8C1F370F5C08B7654899B73]
[B9265F47E7A354BAAA0AF5CBA3F8F7CE]
[BEE9C8B72AB752B794F69C2B9B3678AA]
[E1F91A727A04C9F8199D04FF3BBBF63C]
[F7B1B1101271E31F43CC76E890704F51]
[D48ED0A08BD2FD25A833E6AC99623091]
[6990D4AFDF545669D4E6C232F26DE1FB]
[1EE11F0508C58EF081F4176E66D6970B]
[938E4EF58E42D252B742B0E243011B90]
[3BE5AAC930447FD18D4A8255A2FEC95C]
[00C27B64C758C111E5D78A70DE6CA2B6]
[8CB53620B2C2F0641DD7563EA0FDF491]
[069D3D6E20AD753B34FCE856F0436869]
[6CC727E94CD84E9720FDCDA8089CABCC]
[E3E97151A1D1E87BB2D5371F66C5F169]
[2BC2E99623119521EEF7910A11D0FDE0]
[07B043160399AF4009054E2EA3464BF4]
[C11272713719922DE5711094333BD166]
[EF536C54AB9281FDC4E83B07279FCFC4]
[D8966A76408107224C6013993135DD78]
[8B102A7B6CE326FD4208CC7C2D183343]
[4A53441C1C4D2878BEF27E381138BB2D]
[260907CE034FE327AC99BDA4153AB22F]
[40A3E8D729F458B2C9A8BD9380FF83D5]
[8F010BF65238F3F822D22BA12831796E]
[22C52D7EE7C7D0E02C8EFD8CAE8E3A71]
[1C08E424CBDD5065BB7266F8C048C1B1]
[638B43D39A3D0B47024555CF1095E6F1]
[A928F25CB62232F413EE655352856E10]
[A932391623D5CEC4EF4A2A17D3CEBFCD]
[F279536122B83FD0D8E158AA753E1B7C]
[DA0807D87A62D076C29C4E30F1E84F46]
[14F9883588398A1BDE49C75098C75DE6]
[FBC8C56814642A7CA88ACBCA8DD1121F]
[BB481FE489428821B192CCD0C8CDD937]
[0CDF6B61D7F7FFCD195AF0113B9B2C16]
[45D52DCBE934AB9AC0D91C7027FCD18C]
[E34DEFC09F2843C2C24C2248F1ABE6D8]
[17BE4A35829B37C742084DC02D48E5F0]
[47D09B8C312658ACE433E46DDF51C3A5]
[177AC945B20C81400A1525ED7B49A425]
[3E78BEC276DA5A062E4D55F3291B3463]
[4387DE200BF8DD0E2EE828E655434B9A]
[1F5469E93CA0893B7E7663D965CA849B]
[952F10D2116B91BA433842D07879AE7A]
[B89C353AFC8F56D961D07FF1FE7B4BCD]
[46DE2EF6382DD9613CB506760648F262]
[9AFCCEBFC4D311B62EF0C5457FBB405C]
[9BC12A9AC849D7887D0B566CF6CEFBF5]
[67D62A5063519601C7CD531DE206E5E0]
[7811F4770BF3A4900E687767BB15B705]
[EB8C18C86785A2B5B915E48B76A00E46]
[21A454AC519857F3A874ABBCCD3BD429]
[95A03F67830FDCB950E70261128D540D]
[D5800D5ED7D0232359A9EFC5F0997286]
[5AAB28A6AC2AAC9F66D4EAB6695D0474]
[F8083C536BEDE61AFB4069D8A8C16DA7]
[D67052BD0DA9C17BCBBF8AB5B6D354EE]
[236A38F5CB0A23BF0ACCD70ED0BD7F70]
[77AE39F73551A6F8702C76F25CEBAA8F]

Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft

Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows

[193C1C4ABD2B9CAE3B086C0180708BF4]
[02C54C5C7EBE371EC0C59795ED22213F]
[01BF128CC327A2E53898F732AF52B3DB]
[7CEC266216126BC9A0E1072E1A7E5702]
[2C23283A0815B048C06D8C0ED76AAD95]
[CB6365E995F4DB856866500EDD8F61C1]
[8AF0CBE3FC6129C42D7A2A73B681F226]
[1A563653DAEDFE4CA81936E0D2FD8B56]
[889459F1FDDC5EC58B437AA6C436F33F]
[FFAA37FBBDD161E8C200C83B40F7872E]
[F2C23E25636BCA3543E6AD7858E861B7]
[73C44205E57B561FAA308312B108165B]
[FA2CDF42B3E9F53B12E506BA48BE16AA]
[8355BCA85B0928382DFCDD02FCD1681A]
[0B28F2ACE5103586D322AD98FAA01309]
[BD6705BEF0F792652E5424416DFAD2A2]
[D90D1DF34E5C6912496548BEF0791742]
[807A6636828E5F43C10A01474B8907EE]
[71DE1AD9B23661EEC4F2A6EAA5A7D33D]
[9205E2AB8092C448A09A1EDF7A35F400]
[E94759309E2876EA58FD76244A6E26E6]
[4708F4FB63D8F73C090CC4893B261692]
[9AB1E36A443CB08B667B6A1FE0FA9E9E]
[944FAE17E66C809AF40B34BF8DFD1DF2]
[C798AFF023B8C4982E872A4026DEC0E5]
[A340A4B27CC7DEDDF953B7E2C9699747]
[24146738C422814EEB2A98FF1FC5C6E1]
[476466DC3AB2327E2DBFAEC11798E2EE]
[BEF109D45139E2646C116DD9B6E53E3C]
[7FD4C3D32DAE890608F44074A3437CD8]
[A059F75402710535A90A8D043674A514]
[A3AA03C0C5002F3D89397637B770A1BA]
[0FB83658FBB2C5A18AB98C5C94DB9FAF]
[7AAA9916AA10F4B0E9743798A5BA6549]
[1B8F07B59F7DAE02264FB8A16088C467]
[AF8B7848E102A83AAECCD24B181CEBE5]
[0B49AC860EC6BD165D58218A7AEA18A5]
[4A9CA28E04B4987E0C33EB742BC99DBB]
[4A5634915AF62C983E08425905D0C04C]
[0ECA2ADD5FBCE73183A68935C71B40B7]
[57606281E23B0F53347527691E947B2B]
[04F7878E7017105AB782353231561749]
[A546F72EFFE5CBBC98003A0CA19DA0F8]
[334131C162B118EF49930D41B0E17825]
[7E0078F1EFEB6F8F47CF85C1D73C7EBC]
[E2145534FB853921788F52701BED0CAB]
[64582C924C48175D52AED0D0E64AB413]
[E84F66BA185934C166F8DF0FA8F88455]
[D60BA4C76D194472D6602FF3D2D51ADE]
[3655D86C5E2982B131FC0935DE24F98F]
[DF7A59E70F398EEB9FDCDD310987D8AE]
[AC46883E2BD132344D0EE13FB901257C]
[2C82F4DCABAB389CEBB1C9E86C715C9C]
[176D8470B15CD9080861594F9A33FA01]
[B339861C6A2A86FBCA67C2006B461473]
[46FDF02BDA740CFAB469022EF1F95474]
[4244808B9CDCAD3670B717E6B936736E]
[0C12493B333B96797AFC5F3C7831C051]
[40110802D217FE1CB581D9A70B1FD16F]
[930A1C518D65A9E781CD16C9BCFC5BEF]

Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
NVIDIA Corporation
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows

[EA195B8BC11C1CDB313CFD456EFFA0E9]
[811EC0B1221402FCED0BA37E112BF627]
[9084E1BE90DB98E2B48A2EDD1A5EA753]
[9E8B4F59C878AD30720D4194CBD3BE81]
[E98CD3C1A5FE067975DE1DEC5D954D79]
[EBD07BD20B5E0E92A398566EF8720F79]
[B7B9EEBCB7466338403A75D15AC120D7]
[D14DD7D766664F880FECF44CE6017966]
[45D26646E3AD737E5DE3DB91CCCE7DBA]
[7363A65C738F5A5292D7BDBE55D8C3C2]
[CD90E445F6458512A5BA884D561EFCF1]
[B9B902C12D6872DE9135B0A7C1ACA5A8]
[6DC05FFA78B5E1D34AFDBA08D00B1A8B]
[AE6E4D3172FBF45B944668CB3998B8A8]
[1CD2F4A74AD6AC2DE5ECF8BB9F12C723]
[B922D32039A3B5991E64429EC4EE52A9]
[F07301C282AA222C33F8C28B4F545275]
[0B6BECB2651EF947249CDC3715E8B9CC]
[15709A9AB1411565754CEE33AAB36387]
[D1241DFC397FA8CCFB4BB4B63AAD31AC]
[7C58AFEC26E9F7730A8AA7FD40225937]
[8BBB2B4429AF340481520C20C17FC5B6]
[8C1786C073A496B8C0C8A5450A4FFD5B]
[217A982201052EFC8C3C0C88D229791C]
[FE42F8A07885E518ED1E846C93E4B78C]
[8497852ED44AFF902D502015792D315D]
[FA8F6E3AD3F92B35D2673CC9FD20429C]
[22E539A9B96C66A713583EC017562616]
[401077069C4B017F6179A1BC36BD6E80]
[34A3EB84B2A830E6F450B8F885AE4E6E]
[FA8E0A9C648035CA1B47C9DA77EDB7EA]
[6979A147C0D5C5CAB621ADC394D32B80]
[86B62FC8CB89946446F9B24FE49A66FD]
[F56DAF008FFD7E423292DE21A990B2D4]
[4C120EE77388093EEC45E912EE38C37D]
[14307D4801C8CEF0A615907C09E886B3]
[57C88C15CEC97318F580D7F4327AAA46]
[D009D1BC14FD5F2AC93D1878735F6C39]
[5F27DE2082E16D4C1D6C627C8ECBD341]
[7E81E3E0D7F83BFE3C3975020B6C7F12]
[AA84AF93CE5AF1F05838B51D20295419]
[A9EA339B636506B4452FA2D84CC64D5D]
[56C238ACFE4CB020D3E38508249039EA]
[63451BD694651307254B8DD37A3D79C7]
[15BA68662CED4B0618010A54478E18E5]
[AE3B1056FC1795F18D990C4908A6ECBF]
[FD949725D9EB52C0B87435CDE1134668]
[CB902A15DD21B363FECA5DCCF34F5C57]
[8ACE7A8D694C4F0DFA3FCBEFA2D441FB]
[B85A8CF2BE74DFF1E80097AC94584112]
[FF07BE14ED82E218C3EEE7C986118A2E]
[2771EBB565F5C121E66060B173991D4D]
[8F3ECCB5DC878FA14887B43CD148CBA9]
[36EC82F0E399F36BD25F593D63DC144A]
[0D33D06EF42E3BC6A7BBC4F7F7517C25]
[B37F21B4C25BF10605A196791F93E324]
[67A6E949395A09914AD8B38FE14B8D15]
[4CF5A1E0C4FCA956ACD6C654E2A8610E]
[48C1A256591297C43ECFC4E30D144EAA]
[D76D1AC4F2C642D09A68227D129A4726]

Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft

Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows

[854933CEAE3CCB18330BD416F627C545]
[F0F9F5D57EC0712E69C51563CCE0793C]
[74ACA5A7880C1F0BB9D60E32E1705A70]
[94BD625209F7BB993F228CD68ADD2455]
[1033C37122C7404C3B926ADF84874832]
[2598BBF11C9E7D0885DCA52E7FD5BCBD]
[642EFABF900374FA85639D83B5533AFD]
[0BF8D8C7EC9FB15D6480A12101E88B71]
[53A036CED1270F2459E708A05922FD49]
[965B6197A659782B6A0F68411A180AAD]
[75DC67553051103547B693898CB32D08]
[1FA86056BE5F821C25EF7AEFDFB83FF1]
[9972D395DBD05D91DA5EDADEB9325680]
[B6BF579761489720BCE787F723F596E5]
[10C9CF8771A2A87F575F9FB56821474E]
[357C083FE35D030D991D163AAF622A06]
[2235AF716D15D9DFE4C59DC2AC0C440C]
[205A1FAE910F5C493D236245850BB62A]
[75476CAA8FA0A4E573948CDE8C7F0304]
[E32F15E26724F3BB6423FB29FF3E2A8F]
[58863C57E4598C4F9DA967C5C36CFA5D]
[24F2141493C1A2F6FDEC8C3FA5A95CDE]
[D4B30E23A3B373648F61290DAF432CB2]
[5C156EC4E44E30331BCC865A3B61D839]
[1F5D48B1DA1B812BD2411CA44D75DD32]
[6974DE4152EDBC1351B9806006726259]
[453740989239803FE363FF8B40EA2E08]
[E48BBF1363F843E030757EC190DD33E6]
[4090C6738AA92B428220857B4D44F638]
[45FA01F8B7971ACB65202038E34D04A3]
[5B813FADEA5BE9195F01C83287F823F7]
[E70E169F779EAC621A197A084F0649A1]
[703D0F62C5AA4D08EE8756516C0D125D]
[6E04BBE242E2889B37300C4DF5CE1126]
[8D3AC00C88BC2A63D1D3CC320E0EAA19]
[3760FD529432DFC93B307440534A70AC]
[1336DA39FE006EAB2733CA4DE5B3560C]
[5DA95027DF2317174E8C39B4A8D1FCD8]
[5DFAF8BE5A3CABAABF6795BC09EB7876]
[7118498F6E48758A2EF5A7D1982E2B62]
[69E727F94BEA64E66C284F3C482F33E6]
[8B42614E97AA27347B3AD72C18FDDEDA]
[EEC01707BA931B7113DE3E1CF7528F69]
[86F7D07FB783988F3641C5CE41A74052]
[6A7ACABAE92C837F5C1330188EAE36AE]
[A3C3160BCD364BE6FCEF7FAEA15AC34F]
[92347FC58A8BD2A45F440239EA9A4F04]
[1D80F6B8E8125AA2CB1857872D47EE00]
[237917AFE9016D1C6E1CBDCE97717B5D]
[7ED6FD05286C5CC5652C9196365E2EE1]
[7EA22EE5CFDC5D0D0A10769DA53E42E2]
[6D879552B32CCD2536F66F4F88F54800]
[D0D98F403155463C95508639BF283CD2]
[1F5B5642253FC9760EEACD81900C38DC]
[BCB1BF49F2966FB37D0ADAE538C6FD73]
[B5081D56F1CD87F6BF0BF1AA4E9C6BAB]
[56DEB6F17F290B8C4AF8B2AA10097B55]
[0DAF7B7D85F7AF38E29161460899C63F]
[F56DE562FAA1901587F63DD289E71129]
[2E947792E9B1C738E33FD5794B1650F9]

Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft

Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows

[B011360F95F911F025BC91CB17449798] Microsoft Windows


[310B40B6E8224393EAAE116335918A6A] Microsoft Windows
[8450005F7BA8662A64E3FB7B0C3EE836] Microsoft Windows
===