Вы находитесь на странице: 1из 137

SpyHolesList Version:13.0 Build:8.80.0.

580-64b
02.05.2017 14:50:55
WinDir=C:\Windows
Startup=C:\Users\User\AppData\Roaming\Microsoft\Windows\Start
Menu\Programs\Startup\
Common Startup=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Windows 8.1 Pro (6.3.9600)
Internet Explorer 9.11.9600.16384
DBS Version: 1.918
[Internet Explorer]
[Default Home Page] :HKLM
Default_Page_URL=http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
[Current Home Page] :HKCU Start Page=http://www.microsoft.com/isapi/redir.dll?
prd=ie&pver=6&ar=msnhome
[Current Home Page] :HKCU HOMEOldSP=""
[Current Home Page] :HKCU Default_Page_URL=""
[Current Home Page] :HKLM Start Page=http://www.microsoft.com/isapi/redir.dll?
prd=ie&pver=6&ar=msnhome
[Current Home Page] :HKLM HOMEOldSP=""
[All Users Search] :HKLM
Default_Search_URL=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
[All Users Search] :HKLM Search Page=http://www.microsoft.com/isapi/redir.dll?
prd=ie&ar=iesearch
[Current Home Page(x64)] :HKLM Start
Page=http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
[Current Home Page(x64)] :HKLM HOMEOldSP=""
[All Users Search(x64)] :HKLM
Default_Search_URL=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
[All Users Search(x64)] :HKLM Search
Page=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
[Current Users Search] :HKCU
Default_Search_URL=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
[Current Users Search] :HKCU Search
Page=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
[Current Users Search] :HKCU Search Bar=http://www.microsoft.com/isapi/redir.dll?
prd=ie&ar=iesearch
[IE Local Blank Page] :HKCU Local Page=C:\Windows\system32\blank.htm
[IE Local Blank Page] :HKLM Local Page=C:\Windows\system32\blank.htm
[Auto Search URL] :HKCU provider=""
[Auto Search URL] :HKCU "Default
Value"=http://home.microsoft.com/access/autosearch.asp?p=%s
[Search Assistant] :HKCU SearchAssistant=http://ie.search.msn.com/
{SUB_RFC1766}/srchasst/srchasst.htm
[Search Assistant] :HKLM SearchAssistant=http://ie.search.msn.com/
{SUB_RFC1766}/srchasst/srchasst.htm
[Search Assistant] :HKCU CustomizeSearch=""
[Search Assistant] :HKLM CustomizeSearch=""
[Search Provider] DefaultScope={0633EE93-D776-472f-A0FF-E1416B8B2E3A}
[Search Provider for All Users] DefaultScope={0633EE93-D776-472f-A0FF-
E1416B8B2E3A}
[Search Provider for All Users(x64)] DefaultScope={0633EE93-D776-472f-A0FF-
E1416B8B2E3A}
[Search Provider(x64)] DefaultScope={0633EE93-D776-472f-A0FF-E1416B8B2E3A}
[CustomizeSearch] :HKLM CustomizeSearch=""
[Search URL Template] :HKLM 1=""
[Search URL Template] :HKLM 2=""
[Search URL Template] :HKLM 3=""
[Search URL Template] :HKLM 4=""
[Default Prefix] :HKLM "Default Value"=http://
[URL Default Prefixes] :HKLM mosaic=http://
[URL Default Prefixes] :HKLM www=http://
[URL Default Prefixes] :HKLM home=http://
[URL Default Prefixes] :HKLM ftp=ftp://
[User Style Sheet] :HKCU User Stylesheet=""
[User Style Sheet] :HKCU Use My Stylesheet=0
[Execute unsigned ActiveX in My Computer Zone] :HKCU 1201=0
[Execute unsigned ActiveX in My Computer Zone] :HKLM 1201=1
[Execute unsigned ActiveX in Local Intranet Zone] :HKCU 1201=0
[Execute unsigned ActiveX in Local Intranet Zone] :HKLM 1201=3
[Execute unsigned ActiveX in Internet Zone] :HKCU 1201=0
[Execute unsigned ActiveX in Internet Zone] :HKLM 1201=3
[Links Toolbar] :HKCU LinksFolderName=""
[AutoConfigURL] :HKCU AutoConfigURL=""
[Protocols Filter] :HKLM application/octet-stream=C:\WINDOWS\SYSWOW64\MSCOREE.DLL
### Microsoft .NET Runtime Execution Engine Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384
[Protocols Filter] :HKLM application/x-complus=C:\WINDOWS\SYSWOW64\MSCOREE.DLL
### Microsoft .NET Runtime Execution Engine Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384
[Protocols Filter] :HKLM application/x-msdownload=C:\WINDOWS\SYSWOW64\MSCOREE.DLL
### Microsoft .NET Runtime Execution Engine Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384
[Protocols Handler] :HKLM about=C:\WINDOWS\SYSWOW64\MSHTML.DLL
### Microsoft (R) HTML Viewer Microsoft Corporation Internet Explorer
11.00.9600.16384
[Protocols Handler] :HKLM cdl=C:\WINDOWS\SYSWOW64\URLMON.DLL
### OLE32 Extensions for Win32 Microsoft Corporation Internet Explorer
11.00.9600.16384
[Protocols Handler] :HKLM dvd=C:\WINDOWS\SYSWOW64\MSVIDCTL.DLL
### ActiveX control for streaming video Microsoft Corporation DirectShow
6.05.9600.16384
[Protocols Handler] :HKLM file=C:\WINDOWS\SYSWOW64\URLMON.DLL
### OLE32 Extensions for Win32 Microsoft Corporation Internet Explorer
11.00.9600.16384
[Protocols Handler] :HKLM ftp=C:\WINDOWS\SYSWOW64\URLMON.DLL
### OLE32 Extensions for Win32 Microsoft Corporation Internet Explorer
11.00.9600.16384
[Protocols Handler] :HKLM http=C:\WINDOWS\SYSWOW64\URLMON.DLL
### OLE32 Extensions for Win32 Microsoft Corporation Internet Explorer
11.00.9600.16384
[Protocols Handler] :HKLM https=C:\WINDOWS\SYSWOW64\URLMON.DLL
### OLE32 Extensions for Win32 Microsoft Corporation Internet Explorer
11.00.9600.16384
[Protocols Handler] :HKLM its=C:\WINDOWS\SYSWOW64\ITSS.DLL
### Microsoft InfoTech Storage System Library Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384
[Protocols Handler] :HKLM javascript=C:\WINDOWS\SYSWOW64\MSHTML.DLL
### Microsoft (R) HTML Viewer Microsoft Corporation Internet Explorer
11.00.9600.16384
[Protocols Handler] :HKLM local=C:\WINDOWS\SYSWOW64\URLMON.DLL
### OLE32 Extensions for Win32 Microsoft Corporation Internet Explorer
11.00.9600.16384
[Protocols Handler] :HKLM mailto=C:\WINDOWS\SYSWOW64\MSHTML.DLL
### Microsoft (R) HTML Viewer Microsoft Corporation Internet Explorer
11.00.9600.16384
[Protocols Handler] :HKLM mhtml=C:\WINDOWS\SYSWOW64\INETCOMM.DLL
### Microsoft Internet Messaging API Resources Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384
[Protocols Handler] :HKLM mk=C:\WINDOWS\SYSWOW64\URLMON.DLL
### OLE32 Extensions for Win32 Microsoft Corporation Internet Explorer
11.00.9600.16384
[Protocols Handler] :HKLM ms-its=C:\WINDOWS\SYSWOW64\ITSS.DLL
### Microsoft InfoTech Storage System Library Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384
[Protocols Handler] :HKLM res=C:\WINDOWS\SYSWOW64\MSHTML.DLL
### Microsoft (R) HTML Viewer Microsoft Corporation Internet Explorer
11.00.9600.16384
[Protocols Handler] :HKLM tv=C:\WINDOWS\SYSWOW64\MSVIDCTL.DLL
### ActiveX control for streaming video Microsoft Corporation DirectShow
6.05.9600.16384
[Protocols Handler] :HKLM vbscript=C:\WINDOWS\SYSWOW64\MSHTML.DLL
### Microsoft (R) HTML Viewer Microsoft Corporation Internet Explorer
11.00.9600.16384
[Proxy] :HKCU ProxyServer=""
[Proxy] :HKCU ProxyEnable=0
[Network Settings]
[Hosts File Path] :HKLM DataBasePath=%SystemRoot%\System32\drivers\etc
[Hosts File Contents] :HKLM 127.0.0.1 clients2.google.com
[Hosts File Contents] :HKLM 127.0.0.1 v1.ff.avast.com
[Hosts File Contents] :HKLM 127.0.0.1 vlcproxy.ff.avast.com
[Hosts File Contents] :HKLM 127.0.0.1 cpm.paneladmin.pro
[Hosts File Contents] :HKLM 127.0.0.1 publisher.hmdiadmingate.xyz
[Hosts File Contents] :HKLM 127.0.0.1 distribution.hmdiadmingate.xyz
[Hosts File Contents] :HKLM 127.0.0.1 hmdicrewtracksystem.xyz
[Hosts File Contents] :HKLM 127.0.0.1 linkmate.space
[Hosts File Contents] :HKLM 127.0.0.1 space1.adminpressure.space
[Hosts File Contents] :HKLM 127.0.0.1 trackpressure.website
[Hosts File Contents] :HKLM 127.0.0.1 doctorlink.space
[Hosts File Contents] :HKLM 127.0.0.1 beautifllink.xyz
[Browsers]
[Installed Browsers] FIREFOX.EXE=C:\PROGRAM FILES (X86)\MOZILLA
FIREFOX\FIREFOX.EXE
### Firefox Mozilla Corporation Firefox 44.0.1
[Installed Browsers] IEXPLORE.EXE=C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
### Default Browser
Internet Explorer Microsoft Corporation Internet Explorer 11.00.9600.16384
[Installed Browsers] OperaStable=C:\PROGRAM FILES (X86)\OPERA\LAUNCHER.EXE
### Opera Internet Browser Opera Software Opera Internet Browser 43.0.2442.1144
[FireFox Settings] :HKLM browser.startup.homepage=about:blank
[FireFox Settings] :HKLM browser.startup.homepage_override_url=""
[FireFox Settings] :HKLM browser.search.selectedEngine=""
[FireFox Settings] :HKLM browser.search.selectedEngine,S=""
[FireFox Settings] :HKLM browser.search.defaultEnginename=google
[FireFox Settings] :HKLM browser.search.defaultEnginename,S=""
[FireFox Settings] :HKLM browser.search.order.1=""
[FireFox Settings] :HKLM browser.search.order.1,S=""
[FireFox Settings] :HKLM browser.search.defaulturl=""
[FireFox Settings] :HKLM browser.newtab.url=""
[FireFox Settings] :HKLM keyword.URL=""
[FireFox Settings] :HKLM network.proxy.autoconfig_url=""
[FireFox Settings] :HKLM network.proxy.type=""
[FireFox Settings] :HKLM network.proxy.http=""
[FireFox Settings] :HKLM network.proxy.http_port=""
[FireFox Settings] :HKLM browser.search.searchengine.hp=""
[FireFox Settings] :HKLM browser.search.searchengine.sp=""
[FireFox Settings] :HKLM browser.search.searchengine.url=""
[FireFox Settings] :HKLM browser.search.selectedEngine=""
[Firefox Search Engine (search-metadata)] :HKLM [global].searchdefault=""
[Firefox Search Engine (search-metadata)] :HKLM [global].current=""
[Firefox SearchDefault (mozlz4)] :HKLM metaData.searchDefault=""
[Firefox SearchDefault (mozlz4)] :HKLM metaData.current=""
[Network Settings]
[Domain Name] :HKLM Domain=""
[Name Server] {112F6A80-BB38-4D2C-B920-41B3FAF94BB4}=8.8.8.8
### DHCPNameServer:8.8.8.8
[Name Server] {8B57D787-0E06-4FB1-A754-B66743FF97FF}=8.8.8.8
### Network Card:Qualcomm Atheros AR956x Wireless Network Adapter
DHCPNameServer:192.168.1.254 DhcpDefaultGateway:192.168.1.254
DhcpServer:192.168.1.254
[Name Server] {9056088C-05C7-4DF0-AE60-644176BB3A83}=8.8.8.8
### Network Card:Realtek PCIe GBE Family Controller DHCPNameServer:8.8.8.8
DhcpDefaultGateway:192.168.1.254
DhcpServer:192.168.1.254
[Name Server] {CEFB05FA-43C3-4F13-AAC5-BECA690EC10B}=8.8.8.8
### DHCPNameServer:8.8.8.8
[WinSock2 Components] napinsp.dll=C:\WINDOWS\SYSWOW64\NAPINSP.DLL
### E-mail Naming Shim Provider Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%SystemRoot%\SYSWOW64\napinsp.dll
[WinSock2 Components] pnrpnsp.dll=C:\WINDOWS\SYSWOW64\PNRPNSP.DLL
### PNRP Name Space Provider Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*%SystemRoot%\SYSWOW64\pnrpnsp.dll
[WinSock2 Components] NLAapi.dll=C:\WINDOWS\SYSWOW64\NLAAPI.DLL
### Network Location Awareness 2 Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%SystemRoot%\SYSWOW64\NLAapi.dll
[WinSock2 Components] mswsock.dll=C:\WINDOWS\SYSWOW64\MSWSOCK.DLL
### Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation
Microsoft Windows Operating System 6.3.9600.16384 !$*%SystemRoot
%\SYSWOW64\mswsock.dll
[WinSock2 Components] winrnr.dll=C:\WINDOWS\SYSWOW64\WINRNR.DLL
### LDAP RnR Provider DLL Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*%SystemRoot%\SYSWOW64\winrnr.dll
[WinSock2 Components] wshbth.dll=C:\WINDOWS\SYSWOW64\WSHBTH.DLL
### Windows Sockets Helper DLL Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%SystemRoot%\SYSWOW64\wshbth.dll
[WinSock2 Components (x64)] napinsp.dll=C:\WINDOWS\SYSNATIVE\NAPINSP.DLL
### E-mail Naming Shim Provider Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%SystemRoot%\SYSNATIVE\napinsp.dll
[WinSock2 Components (x64)] pnrpnsp.dll=C:\WINDOWS\SYSNATIVE\PNRPNSP.DLL
### PNRP Name Space Provider Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*%SystemRoot%\SYSNATIVE\pnrpnsp.dll
[WinSock2 Components (x64)] NLAapi.dll=C:\WINDOWS\SYSNATIVE\NLAAPI.DLL
### Network Location Awareness 2 Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%SystemRoot%\SYSNATIVE\NLAapi.dll
[WinSock2 Components (x64)] mswsock.dll=C:\WINDOWS\SYSNATIVE\MSWSOCK.DLL
### Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation
Microsoft Windows Operating System 6.3.9600.16384 !$*%SystemRoot
%\SYSNATIVE\mswsock.dll
[WinSock2 Components (x64)] winrnr.dll=C:\WINDOWS\SYSNATIVE\WINRNR.DLL
### LDAP RnR Provider DLL Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*%SystemRoot%\SYSNATIVE\winrnr.dll
[WinSock2 Components (x64)] wshbth.dll=C:\WINDOWS\SYSNATIVE\WSHBTH.DLL
### Windows Sockets Helper DLL Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%SystemRoot%\SYSNATIVE\wshbth.dll
[Windows Shell]
[Display Scrap's Extensions] :HKLM NeverShowExt=""
[ScreenSaver] :HKCU SCRNSAVE.EXE=""
### File is missing.
[System.ini] shell=explorer.exe
[User Shell] :HKCU shell=""
[User Shortcuts] :HKLM C:\Users\User\Desktop\Counter Strike Xtreme -
Shortcut.lnk=D:\APP-GAMES\COUNTER STRIKE V6\COUNTER STRIKE XTREME.EXE
### Counter Strike Xtreme Counter Strike Xtreme Launcher 1.0.0.0 !
$*C:\Users\User\Desktop\COUNTE~1.LNK
[User Shortcuts] :HKLM C:\Users\User\Desktop\HP Photo
Creations.lnk=C:\USERS\USER\APPDATA\ROAMING\HP PHOTO CREATIONS\PHOTOPRODUCT.EXE
### PhotoProduct.exe Visan / RocketLife PhotoProduct.exe 1, 0, 0, 19802 !
$*C:\Users\User\Desktop\HPPHOT~1.LNK
[User Shortcuts] :HKLM
C:\Users\User\Desktop\LINE.lnk=C:\USERS\USER\APPDATA\LOCAL\LINE\BIN\LINELAUNCHER.EX
E
### LINE LINE Corporation LINE 1.0.0.0 !$*C:\Users\User\Desktop\LINE.lnk
[User Shortcuts] :HKLM C:\Users\User\Desktop\PhotoScape.lnk=C:\PROGRAM FILES
(X86)\PHOTOSCAPE\PHOTOSCAPE.EXE
### PhotoScape PhotoScape 1, 0, 0, 1302 !$*C:\Users\User\Desktop\PHOTOS~1.LNK
[User Shortcuts] :HKLM C:\Users\User\Desktop\UnHackMe.lnk=C:\PROGRAM FILES
(X86)\UNHACKME\UNHACKME.EXE
### Detects and removes rootkits Greatis Software UnHackMe 8.80 !
$*C:\Users\User\Desktop\UnHackMe.lnk
[User Shortcuts] :HKLM C:\Users\Public\Desktop\Adobe Reader XI.lnk=C:\PROGRAM
FILES (X86)\ADOBE\READER 11.0\READER\ACRORD32.EXE
### Adobe Reader Adobe Systems Incorporated Adobe Reader 11.0.10.32 !
$*C:\Users\Public\Desktop\ADOBER~1.LNK
[User Shortcuts] :HKLM C:\Users\Public\Desktop\AudioWizard.lnk=C:\PROGRAM
FILES\CONEXANT\MAXXAUDIO\MAXXAUDIOCONTROL64.EXE
### Waves Audio Ltd. MaxxAudioControl 3.14.3.0 !
$*C:\Users\Public\Desktop\AUDIOW~1.LNK
[User Shortcuts] :HKLM
C:\Users\Public\Desktop\eManual.Lnk=C:\ESUPPORT\MANUAL\EMANUAL.EXE
### EManual Application ASUSTek Computer Inc. EManual Application 1.0.0.4 !
$*C:\Users\Public\Desktop\eManual.Lnk
[User Shortcuts] :HKLM C:\Users\Public\Desktop\GOM Player.lnk=C:\PROGRAM FILES
(X86)\GRETECH\GOMPLAYER\GOM.EXE
### GOM Player Gretech Corp. GOM Player 2, 1, 18, 4762 !
$*C:\Users\Public\Desktop\GOMPLA~1.LNK
[User Shortcuts] :HKLM C:\Users\Public\Desktop\HP Deskjet 1510
series.lnk=C:\PROGRAM FILES\HP\HP DESKJET 1510 SERIES\BIN\HP DESKJET 1510
SERIES.EXE
### HP Printer Assistant Hewlett-Packard Co. HP Digital Imaging
032.000.1180.44630 !$*C:\Users\Public\Desktop\HPDESK~1.LNK ?-Start UDCDevicePage
[User Shortcuts] :HKLM C:\Users\Public\Desktop\Mozilla Firefox.lnk=C:\PROGRAM
FILES (X86)\MOZILLA FIREFOX\FIREFOX.EXE
### Firefox Mozilla Corporation Firefox 44.0.1 !
$*C:\Users\Public\Desktop\MOZILL~1.LNK ?http://www.yeadesktop.com/
[User Shortcuts] :HKLM C:\Users\Public\Desktop\Opera.lnk=C:\PROGRAM FILES
(X86)\OPERA\LAUNCHER.EXE
### Opera Internet Browser Opera Software Opera Internet Browser 43.0.2442.1144 !
$*C:\Users\Public\Desktop\Opera.lnk
[User Shortcuts] :HKLM C:\Users\Public\Desktop\PESEdit 2014
Selector.lnk=C:\PROGRAM FILES (X86)\KONAMI\PRO EVOLUTION SOCCER 2014\PESEDIT
SELECTOR.EXE
### PESEDIT Selector PESEDIT Selector 2.1.0.0 !
$*C:\Users\Public\Desktop\PESEDI~1.LNK
[User Shortcuts] :HKLM C:\Users\Public\Desktop\scilab-5.5.2 (64-
bit).lnk=C:\PROGRAM FILES\SCILAB-5.5.2\BIN\WSCILEX.EXE
### Scilab 5.5.2 (GUI) Scilab Enterprises Scilab 5.x Application 5, 5, 2, 0 !
$*C:\Users\Public\Desktop\SCILAB~1.LNK
[User Shortcuts] :HKLM C:\Users\Public\Desktop\Shop for Supplies - HP Deskjet
1510 series.lnk=C:\PROGRAM FILES\HP\HP DESKJET 1510 SERIES\BIN\HPQDTSS.EXE
### DesktopSureSupply Hewlett-Packard Co. HP Digital Imaging 032.000.1180.44630 !
$*C:\Users\Public\Desktop\SHOPFO~1.LNK
[User Shortcuts] :HKLM C:\Users\Public\Desktop\VLC media player.lnk=C:\PROGRAM
FILES\VIDEOLAN\VLC\VLC.EXE
### VLC media player 2.1.3 VideoLAN VLC media player 2,1,3,0 !
$*C:\Users\Public\Desktop\VLCMED~1.LNK
[User Shortcuts] :HKLM C:\Users\Public\Desktop\WPS Presentation.lnk=C:\PROGRAM
FILES (X86)\KINGSOFT\KINGSOFT OFFICE\KSOLAUNCH.EXE
### WPS Office Zhuhai Kingsoft Office Software Co.,Ltd WPS Office 10,2,0,5811 !
$*C:\Users\Public\Desktop\WPSPRE~1.LNK ?/wpp /w /fromksolaunch
[User Shortcuts] :HKLM C:\Users\Public\Desktop\WPS Spreadsheets.lnk=C:\PROGRAM
FILES (X86)\KINGSOFT\KINGSOFT OFFICE\KSOLAUNCH.EXE
### WPS Office Zhuhai Kingsoft Office Software Co.,Ltd WPS Office 10,2,0,5811 !
$*C:\Users\Public\Desktop\WPSSPR~1.LNK ?/et /fromksolaunch
[User Shortcuts] :HKLM C:\Users\Public\Desktop\WPS Writer.lnk=C:\PROGRAM FILES
(X86)\KINGSOFT\KINGSOFT OFFICE\KSOLAUNCH.EXE
### WPS Office Zhuhai Kingsoft Office Software Co.,Ltd WPS Office 10,2,0,5811 !
$*C:\Users\Public\Desktop\WPSWRI~1.LNK ?/wps /w /fromksolaunch
[User Shortcuts] :HKLM C:\Users\User\AppData\Roaming\Microsoft\Internet
Explorer\Quick Launch\GOM Player.lnk=C:\PROGRAM FILES
(X86)\GRETECH\GOMPLAYER\GOM.EXE
### GOM Player Gretech Corp. GOM Player 2, 1, 18, 4762 !
$*C:\Users\User\AppData\Roaming\MICROS~1\INTERN~1\QUICKL~1\GOMPLA~1.LNK
[User Shortcuts] :HKLM C:\Users\User\AppData\Roaming\Microsoft\Internet
Explorer\Quick Launch\PhotoScape.lnk=C:\PROGRAM FILES
(X86)\PHOTOSCAPE\PHOTOSCAPE.EXE
### PhotoScape PhotoScape 1, 0, 0, 1302 !
$*C:\Users\User\AppData\Roaming\MICROS~1\INTERN~1\QUICKL~1\PHOTOS~1.LNK
[User Shortcuts] :HKLM C:\Users\User\AppData\Roaming\Microsoft\Internet
Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk=C:\PROGRAM FILES
(X86)\MOZILLA FIREFOX\FIREFOX.EXE
### Firefox Mozilla Corporation Firefox 44.0.1 !
$*C:\Users\User\AppData\Roaming\MICROS~1\INTERN~1\QUICKL~1\USERPI~1\TaskBar\MOZILL~
1.LNK ?http://www.yeadesktop.com/
[User Shortcuts] :HKLM C:\ProgramData\Microsoft\Windows\Start
Menu\Programs\Mozilla Firefox.lnk=C:\PROGRAM FILES (X86)\MOZILLA
FIREFOX\FIREFOX.EXE
### Firefox Mozilla Corporation Firefox 44.0.1 !
$*C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\MOZILL~1.LNK ?
http://www.yeadesktop.com/
[Main File Extensions] :HKLM .exe=""
[Main File Extensions] :HKLM .com=""
[Main File Extensions] :HKLM .pif=""
[Main File Extensions] :HKLM .bat=""
[Main File Extensions] :HKLM .cmd=""
[Main File Extensions] :HKLM .scr=""
[Main File Extensions] :HKLM .txt=""
[Main File Extensions] :HKLM .reg=""
[Main File Extensions] :HKLM .inf=""
[Main File Extensions] :HKLM .ini=""
[Main File Extensions] :HKLM .js=""
[Main File Extensions] :HKLM .vbs=""
[Main File Extensions] :HKLM .vbe=""
[Main File Extensions] :HKLM .msc=""
[Main File Extensions] :HKLM .jpg=""
[Main File Extensions] :HKLM .jpeg=""
[Main File Extensions] :HKLM .gif=""
[Main File Extensions] :HKLM .png=""
[UserInit Value] UserInit=C:\Windows\system32\userinit.exe,
### Userinit Logon Application Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384
[UserInit Value(x64)] UserInit=C:\Windows\system32\userinit.exe,
### Userinit Logon Application Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384
[Shell Services DelayLoad] :HKLM WebCheck={E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[Explorer Run] :HKLM BtvStack=C:\PROGRAM FILES (X86)\BLUETOOTH SUITE\BTVSTACK.EXE
### Extension Core QualcommAtheros BT Software Suite 8.0.1.318 !$*"C:\Program
Files (x86)\Bluetooth Suite\BtvStack.exe"
[System Shell Policies ] :HKCU shell=""
[System Shell Policies ] :HKLM shell=""
[System Shell Policies ] :HKCU run=""
[System Shell Policies ] :HKLM run=""
[Prevents Display in Control Panel from running.] :HKCU NoDispCpl=0
[Disable Registry Tools] :HKCU DisableRegistryTools =0
[Print Monitors] :HKLM HP c111 Status
Monitor=C:\Windows\SYSTEM32\HPINKSTSC111LM.DLL
### Print Status Language Monitor Hewlett-Packard Co. HP Digital Imaging
030.000.1044.40289 !$*hpinkstsc111LM.dll
[Print Monitors] :HKLM Local Port=C:\Windows\SYSTEM32\LOCALSPL.DLL
### Local Spooler DLL Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*localspl.dll
[Print Monitors] :HKLM Microsoft Shared Fax
Monitor=C:\Windows\SYSTEM32\FXSMON.DLL
### Microsoft Fax Print Monitor Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*FXSMON.DLL
[Print Monitors] :HKLM Standard TCP/IP Port=C:\Windows\SYSTEM32\TCPMON.DLL
### Standard TCP/IP Port Monitor DLL Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*tcpmon.dll
[Print Monitors] :HKLM USB Monitor=C:\Windows\SYSTEM32\USBMON.DLL
### Standard Dynamic Printing Port Monitor DLL Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 !$*usbmon.dll
[Print Monitors] :HKLM WSD Port=C:\Windows\SYSTEM32\WSDMON.DLL
### WSD Printer Port Monitor Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*WSDMon.dll
[Shell Icon Overlay Handlers] :HKLM
StorageProviderError=C:\WINDOWS\SYSWOW64\SHELL32.DLL
### Windows Shell Common Dll Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384
[Shell Icon Overlay Handlers] :HKLM
StorageProviderSyncing=C:\WINDOWS\SYSWOW64\SHELL32.DLL
### Windows Shell Common Dll Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384
[Context Menu Handlers] :HKLM Atheros={B8952421-0E55-400B-94A6-FA858FC0A39F}
[Context Menu Handlers] :HKLM BriefcaseMenu=C:\WINDOWS\SYSTEM32\SYNCUI.DLL
### Windows Briefcase Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*%SystemRoot%\system32\syncui.dll
[Context Menu Handlers] :HKLM Open With=C:\WINDOWS\SYSTEM32\SHELL32.DLL
### Windows Shell Common Dll Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*%SystemRoot%\system32\shell32.dll
[Context Menu Handlers] :HKLM Open With
EncryptionMenu=C:\WINDOWS\SYSTEM32\SHELL32.DLL
### Windows Shell Common Dll Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*%SystemRoot%\system32\shell32.dll
[Context Menu Handlers] :HKLM Sharing=C:\WINDOWS\SYSTEM32\NTSHRUI.DLL
### Shell extensions for sharing Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%SystemRoot%\system32\ntshrui.dll
[Context Menu Handlers] :HKLM WinRAR={B41DB860-64E4-11D2-9906-E49FADC173CA}
[Context Menu Handlers] :HKLM WinRAR32=C:\PROGRAM FILES\WINRAR\RAREXT32.DLL
### WinRAR shell extension Alexander Roshal WinRAR 5.10.0
[Context Menu Handlers] :HKLM WorkFolders={E61BF828-5E63-4287-BEF1-60B1A4FDE0E3}
[Context Menu Handlers] :HKLM {90AA3A4E-1CBA-4233-B8BB-
535773D48449}=C:\WINDOWS\SYSTEM32\SHELL32.DLL
### Windows Shell Common Dll Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*%SystemRoot%\system32\shell32.dll
[App Paths] :HKLM AcroRd32.exe=C:\Program Files (x86)\Adobe\Reader
11.0\Reader\AcroRd32.exe
### AcroRd32.exe Adobe Reader Adobe Systems Incorporated Adobe Reader 11.0.10.32

[App Paths] :HKLM cmmgr32.exe


### cmmgr32.exe
[App Paths] :HKLM dfshim.dll
### dfshim.dll
[App Paths] :HKLM et.exe=C:\Program Files (x86)\Kingsoft\Kingsoft
Office\10.2.0.5811\office6\et.exe
### et.exe WPS Spreadsheets Zhuhai Kingsoft Office Software Co.,Ltd WPS Office
11,2,0,5811
[App Paths] :HKLM excel.exe=C:\Program Files (x86)\Kingsoft\Kingsoft
Office\10.2.0.5811\office6\et.exe
### excel.exe WPS Spreadsheets Zhuhai Kingsoft Office Software Co.,Ltd WPS Office
11,2,0,5811
[App Paths] :HKLM firefox.exe=C:\Program Files (x86)\Mozilla Firefox\firefox.exe
### firefox.exe Firefox Mozilla Corporation Firefox 44.0.1
[App Paths] :HKLM fsquirt.exe
### fsquirt.exe
[App Paths] :HKLM GOM.exe=C:\Program Files (x86)\GRETECH\GomPlayer\GOM.exe
### GOM.exe GOM Player Gretech Corp. GOM Player 2, 1, 18, 4762
[App Paths] :HKLM IEDIAG.EXE=C:\Program Files\Internet Explorer\IEDIAGCMD.EXE
### IEDIAG.EXE Diagnostics utility for Internet Explorer Microsoft Corporation
Internet Explorer 11.00.9600.16384
[App Paths] :HKLM IEDIAGCMD.EXE=C:\Program Files\Internet Explorer\IEDIAGCMD.EXE
### IEDIAGCMD.EXE Diagnostics utility for Internet Explorer Microsoft Corporation
Internet Explorer 11.00.9600.16384
[App Paths] :HKLM IEXPLORE.EXE=C:\Program Files\Internet Explorer\IEXPLORE.EXE
### IEXPLORE.EXE Internet Explorer Microsoft Corporation Internet Explorer
11.00.9600.16384
[App Paths] :HKLM install.exe
### install.exe
[App Paths] :HKLM Journal.exe=%ProgramFiles%\Windows Journal\Journal.exe
### Journal.exe
[App Paths] :HKLM migwiz.exe
### migwiz.exe
[App Paths] :HKLM mip.exe=%CommonProgramFiles%\Microsoft Shared\Ink\mip.exe
### mip.exe
[App Paths] :HKLM mplayer2.exe=%ProgramFiles(x86)%\Windows Media
Player\wmplayer.exe
### mplayer2.exe
[App Paths] :HKLM Opera.exe="C:\Program Files (x86)\Opera\Launcher.exe"
### Opera.exe Opera Internet Browser Opera Software Opera Internet Browser
43.0.2442.1144
[App Paths] :HKLM pbrush.exe=%SystemRoot%\System32\mspaint.exe
### pbrush.exe
[App Paths] :HKLM PhotoScape.exe="C:\Program Files
(x86)\PhotoScape\PhotoScape.exe"
### PhotoScape.exe PhotoScape PhotoScape 1, 0, 0, 1302
[App Paths] :HKLM powerpnt.exe=C:\Program Files (x86)\Kingsoft\Kingsoft
Office\10.2.0.5811\office6\wpp.exe
### powerpnt.exe WPS Presentation Zhuhai Kingsoft Office Software Co.,Ltd WPS
Office 11,2,0,5811
[App Paths] :HKLM PowerShell.exe=%SystemRoot
%\system32\WindowsPowerShell\v1.0\PowerShell.exe
### PowerShell.exe
[App Paths] :HKLM setup.exe
### setup.exe
[App Paths] :HKLM SmartAudio.exe=C:\Program Files\Conexant\SAII\
### SmartAudio.exe
[App Paths] :HKLM SnippingTool.exe=%SystemRoot%\system32\SnippingTool.exe
### SnippingTool.exe
[App Paths] :HKLM table30.exe
### table30.exe
[App Paths] :HKLM TabTip.exe=%CommonProgramFiles%\microsoft shared\ink\TabTip.exe
### TabTip.exe
[App Paths] :HKLM wab.exe=%ProgramFiles%\Windows Mail\wab.exe
### wab.exe
[App Paths] :HKLM wabmig.exe=%ProgramFiles%\Windows Mail\wabmig.exe
### wabmig.exe
[App Paths] :HKLM WinRAR.exe=C:\Program Files\WinRAR\WinRAR.exe
### WinRAR.exe WinRAR archiver Alexander Roshal WinRAR 5.10.0
[App Paths] :HKLM winword.exe=C:\Program Files (x86)\Kingsoft\Kingsoft
Office\10.2.0.5811\office6\wps.exe
### winword.exe WPS Writer Zhuhai Kingsoft Office Software Co.,Ltd WPS Office
11,2,0,5811
[App Paths] :HKLM wmplayer.exe=%ProgramFiles(x86)%\Windows Media
Player\wmplayer.exe
### wmplayer.exe
[App Paths] :HKLM WORDPAD.EXE=C:\PROGRAM FILES\WINDOWS NT\ACCESSORIES\WORDPAD.EXE
### WORDPAD.EXE Windows Wordpad Application Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 !$*"%ProgramFiles%\Windows
NT\Accessories\WORDPAD.EXE"
[App Paths] :HKLM wpp.exe=C:\Program Files (x86)\Kingsoft\Kingsoft
Office\10.2.0.5811\office6\wpp.exe
### wpp.exe WPS Presentation Zhuhai Kingsoft Office Software Co.,Ltd WPS Office
11,2,0,5811
[App Paths] :HKLM wps.exe=C:\Program Files (x86)\Kingsoft\Kingsoft
Office\10.2.0.5811\office6\wps.exe
### wps.exe WPS Writer Zhuhai Kingsoft Office Software Co.,Ltd WPS Office
11,2,0,5811
[App Paths] :HKLM WRITE.EXE="%ProgramFiles%\Windows NT\Accessories\WORDPAD.EXE"
### WRITE.EXE
[Kernel Auto Boot]
[ActiveSetup] >{22d6f312-b0f6-11d0-94ab-
0080c74c7e95}=C:\WINDOWS\SYSTEM32\UNREGMP2.EXE
### Microsoft Windows Media Player Setup Utility Microsoft Corporation Microsoft
Windows Operating System 12.0.9600.16384 !$*%SystemRoot%\system32\unregmp2.exe
/ShowWMP
[Auto Services] :HKLM AdobeARMservice
### Service: Adobe Acrobat Update Service Status: Start Type: loaded
automatically by Server Manager Actual File: C:\PROGRAM FILES (X86)\COMMON
FILES\ADOBE\ARM\1.0\ARMSVC.EXE * Adobe Acrobat Updater keeps your Adobe software up
to date. Adobe Acrobat Update Service Adobe Systems Incorporated Adobe Acrobat
Update Service 1.801.10.4720 !$*"C:\PROGRAM FILES (X86)\COMMON
FILES\ADOBE\ARM\1.0\ARMSVC.EXE"
[Auto Services] :HKLM AdobeFlashPlayerUpdateSvc
### Service: Adobe Flash Player Update Service Status: Start Type: loaded
manually on demand Actual File:
C:\WINDOWS\SYSWOW64\MACROMED\FLASH\FLASHPLAYERUPDATESERVICE.EXE * This service
keeps your Adobe Flash Player installation up to date with the latest enhancements
and security fixes. Adobe Flash Player Update Service 26.0 d0 Adobe Systems
Incorporated Adobe Flash Player Update Service 26,0,0,89
[Auto Services] :HKLM AeLookupSvc
### Service: Application Experience Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Processes application compatibility
cache requests for applications as they are launched Host Process for Windows
Services Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS
[Auto Services] :HKLM AIPS
### Service: Arp Intelligent Protection Service Status: Start Type: loaded
automatically by Server Manager Actual File: C:\PROGRAM FILES
(X86)\NETCUTDEFENDER\SERVICES\AIPS.EXE * Arp Intelligent Protection Service
Arcai.com AIPS Application 214
[Auto Services] :HKLM ALG
### Service: Application Layer Gateway Service Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\ALG.EXE * Provides support for
3rd party protocol plug-ins for Internet Connection Sharing Application Layer
Gateway Service Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*%SYSTEMROOT%\SYSTEM32\ALG.EXE
[Auto Services] :HKLM AppIDSvc
### Service: Application Identity Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Determines and verifies the identity
of an application. Disabling this service will prevent AppLocker from being
enforced. Host Process for Windows Services Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
LOCALSERVICENETWORKRESTRICTED
[Auto Services] :HKLM Appinfo
### Service: Application Information Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Facilitates the running of
interactive applications with additional administrative privileges. If this
service is stopped, users will be unable to launch applications with the additional
administrative privileges they may require to perform desired user tasks. Host
Process for Windows Services Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS
[Auto Services] :HKLM AppMgmt
### Service: Application Management Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Processes installation, removal, and
enumeration requests for software deployed through Group Policy. If the service is
disabled, users will be unable to install, remove, or enumerate software deployed
through Group Policy. If this service is disabled, any services that explicitly
depend on it will fail to start. Host Process for Windows Services Microsoft
Corporation Microsoft Windows Operating System 6.3.9600.16384 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K NETSVCS
[Auto Services] :HKLM AppReadiness
### Service: App Readiness Status: Start Type: loaded manually on demand Actual
File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Gets apps ready for use the first time a
user signs in to this PC and when adding new apps. Host Process for Windows
Services Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K APPREADINESS
[Auto Services] :HKLM AppXSvc
### Service: AppX Deployment Service (AppXSVC) Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Provides
infrastructure support for deploying Store applications. This service is started on
demand and if disabled Store applications will not be deployed to the system, and
may not function properly. Host Process for Windows Services Microsoft Corporation
Microsoft Windows Operating System 6.3.9600.16384 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K WSAPPX
[Auto Services] :HKLM ASLDRService
### Service: ASLDR Service Status: Start Type: loaded automatically by Server
Manager Actual File: C:\PROGRAM FILES (X86)\ASUS\ATK PACKAGE\ATK
HOTKEY\ASLDRSRV.EXE * ASLDR Service ASUSTek Computer Inc. ATK Hotkey 1, 0, 81, 0
[Auto Services] :HKLM AtherosSvc
### Service: AtherosSvc Status: Start Type: loaded automatically by Server
Manager Actual File: C:\PROGRAM FILES (X86)\BLUETOOTH SUITE\ADMINSERVICE.EXE *
Atheros BT Stack Service Agent Windows Setup API Windows (R) Win 7 DDK provider
Windows (R) Win 7 DDK driver 6.2.9200.16384 !$*"C:\PROGRAM FILES (X86)\BLUETOOTH
SUITE\ADMINSERVICE.EXE"
[Auto Services] :HKLM ATKGFNEXSrv
### Service: ATKGFNEX Service Status: Start Type: loaded automatically by Server
Manager Actual File: C:\PROGRAM FILES (X86)\ASUS\ATK PACKAGE\ATKGFNEX\GFNEXSRV.EXE
* GFNEXSrv ASUS ATK Generic Function Service 1, 0, 11, 0
[Auto Services] :HKLM AudioEndpointBuilder
### Service: Windows Audio Endpoint Builder Status: Start Type: loaded
automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE *
Manages audio devices for the Windows Audio service. If this service is stopped,
audio devices and effects will not function properly. If this service is disabled,
any services that explicitly depend on it will fail to start Host Process for
Windows Services Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED
[Auto Services] :HKLM Audiosrv
### Service: Windows Audio Status: Start Type: loaded automatically by Server
Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Manages audio for Windows-
based programs. If this service is stopped, audio devices and effects will not
function properly. If this service is disabled, any services that explicitly
depend on it will fail to start Host Process for Windows Services Microsoft
Corporation Microsoft Windows Operating System 6.3.9600.16384 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICENETWORKRESTRICTED
[Auto Services] :HKLM AxInstSV
### Service: ActiveX Installer (AxInstSV) Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Provides User Account Control
validation for the installation of ActiveX controls from the Internet and enables
management of ActiveX control installation based on Group Policy settings. This
service is started on demand and if disabled the installation of ActiveX controls
will behave according to default browser settings. Host Process for Windows
Services Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K AXINSTSVGROUP
[Auto Services] :HKLM BDESVC
### Service: BitLocker Drive Encryption Service Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * BDESVC hosts the
BitLocker Drive Encryption service. BitLocker Drive Encryption provides secure
startup for the operating system, as well as full volume encryption for OS, fixed
or removable volumes. This service allows BitLocker to prompt users for various
actions related to their volumes when mounted, and unlocks volumes automatically
without user interaction. Additionally, it stores recovery information to Active
Directory, if available, and, if necessary, ensures the most recent recovery
certificates are used. Stopping or disabling the service would prevent users from
leveraging this functionality. Host Process for Windows Services Microsoft
Corporation Microsoft Windows Operating System 6.3.9600.16384 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K NETSVCS
[Auto Services] :HKLM BFE
### Service: Base Filtering Engine Status: Start Type: loaded automatically by
Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * The Base Filtering
Engine (BFE) is a service that manages firewall and Internet Protocol security
(IPsec) policies and implements user mode filtering. Stopping or disabling the BFE
service will significantly reduce the security of the system. It will also result
in unpredictable behavior in IPsec management and firewall applications. Host
Process for Windows Services Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICENONETWORK
[Auto Services] :HKLM BITS
### Service: Background Intelligent Transfer Service Status: Start Type: loaded
automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE *
Transfers files in the background using idle network bandwidth. If the service is
disabled, then any applications that depend on BITS, such as Windows Update or MSN
Explorer, will be unable to automatically download programs and other information.
Host Process for Windows Services Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS
[Auto Services] :HKLM BrokerInfrastructure
### Service: Background Tasks Infrastructure Service Status: Start Type: loaded
automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE *
Windows infrastructure service that controls which background tasks can run on the
system. Host Process for Windows Services Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K DCOMLAUNCH
[Auto Services] :HKLM Browser
### Service: Computer Browser Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Maintains an updated list of
computers on the network and supplies this list to computers designated as
browsers. If this service is stopped, this list will not be updated or maintained.
If this service is disabled, any services that explicitly depend on it will fail to
start. Host Process for Windows Services Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS
[Auto Services] :HKLM bthserv
### Service: Bluetooth Support Service Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * The Bluetooth service
supports discovery and association of remote Bluetooth devices. Stopping or
disabling this service may cause already installed Bluetooth devices to fail to
operate properly and prevent new devices from being discovered or associated. Host
Process for Windows Services Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE
[Auto Services] :HKLM CertPropSvc
### Service: Certificate Propagation Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Copies user certificates and
root certificates from smart cards into the current user's certificate store,
detects when a smart card is inserted into a smart card reader, and, if needed,
installs the smart card Plug and Play minidriver. Host Process for Windows Services
Microsoft Corporation Microsoft Windows Operating System 6.3.9600.16384 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS
[Auto Services] :HKLM COMSysApp
### Service: COM+ System Application Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\DLLHOST.EXE * Manages the configuration and
tracking of Component Object Model (COM)+-based components. If the service is
stopped, most COM+-based components will not function properly. If this service is
disabled, any services that explicitly depend on it will fail to start. COM
Surrogate Microsoft Corporation Microsoft Windows Operating System 6.3.9600.16384
!$*%SYSTEMROOT%\SYSTEM32\DLLHOST.EXE /PROCESSID:{02D4B3F1-FD88-11D1-960D-
00805FC79235}
[Auto Services] :HKLM cphs
### Service: Intel(R) Content Protection HECI Service Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSWOW64\INTELCPHECISVC.EXE * Intel(R)
Content Protection HECI Service - enables communication with the Content Protection
FW IntelCpHeciSvc Executable Intel Corporation IntelCpHeciSvc Executable
9.0.20.9000 !$*%SYSTEMROOT%\SYSWOW64\INTELCPHECISVC.EXE
[Auto Services] :HKLM CryptSvc
### Service: Cryptographic Services Status: Start Type: loaded automatically by
Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Provides three
management services: Catalog Database Service, which confirms the signatures of
Windows files and allows new programs to be installed; Protected Root Service,
which adds and removes Trusted Root Certification Authority certificates from this
computer; and Automatic Root Certificate Update Service, which retrieves root
certificates from Windows Update and enable scenarios such as SSL. If this service
is stopped, these management services will not function properly. If this service
is disabled, any services that explicitly depend on it will fail to start. Host
Process for Windows Services Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETWORKSERVICE
[Auto Services] :HKLM CscService
### Service: Offline Files Status: Start Type: loaded manually on demand Actual
File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * The Offline Files service performs
maintenance activities on the Offline Files cache, responds to user logon and
logoff events, implements the internals of the public API, and dispatches
interesting events to those interested in Offline Files activities and changes in
cache state. Host Process for Windows Services Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
LOCALSYSTEMNETWORKRESTRICTED
[Auto Services] :HKLM CxAudMsg
### Service: Conexant Audio Message Service Status: Start Type: loaded
automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\CXAUDMSG64.EXE *
Monitors audio device events and forward them to subscribing application. If this
service is stop. the aduio effects will not function properly. Conexant Audio
Message Service Conexant Systems Inc. Conexant Audio Message Service 1.13.0.0
[Auto Services] :HKLM DcomLaunch
### Service: DCOM Server Process Launcher Status: Start Type: loaded
automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * The
DCOMLAUNCH service launches COM and DCOM servers in response to object activation
requests. If this service is stopped or disabled, programs using COM or DCOM will
not function properly. It is strongly recommended that you have the DCOMLAUNCH
service running. Host Process for Windows Services Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
DCOMLAUNCH
[Auto Services] :HKLM defragsvc
### Service: Optimize drives Status: Start Type: loaded manually on demand Actual
File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Helps the computer run more efficiently by
optimizing files on storage drives. Host Process for Windows Services Microsoft
Corporation Microsoft Windows Operating System 6.3.9600.16384 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K DEFRAGSVC
[Auto Services] :HKLM DeviceAssociationService
### Service: Device Association Service Status: Start Type: loaded automatically
by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Enables pairing
between the system and wired or wireless devices. Host Process for Windows Services
Microsoft Corporation Microsoft Windows Operating System 6.3.9600.16384 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED
[Auto Services] :HKLM DeviceInstall
### Service: Device Install Service Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Enables a computer to recognize and
adapt to hardware changes with little or no user input. Stopping or disabling this
service will result in system instability. Host Process for Windows Services
Microsoft Corporation Microsoft Windows Operating System 6.3.9600.16384 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K DCOMLAUNCH
[Auto Services] :HKLM Dhcp
### Service: DHCP Client Status: Start Type: loaded automatically by Server
Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Registers and updates IP
addresses and DNS records for this computer. If this service is stopped, this
computer will not receive dynamic IP addresses and DNS updates. If this service is
disabled, any services that explicitly depend on it will fail to start. Host
Process for Windows Services Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
LOCALSERVICENETWORKRESTRICTED
[Auto Services] :HKLM Dnscache
### Service: DNS Client Status: Start Type: loaded automatically by Server
Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * The DNS Client service
(dnscache) caches Domain Name System (DNS) names and registers the full computer
name for this computer. If the service is stopped, DNS names will continue to be
resolved. However, the results of DNS name queries will not be cached and the
computer's name will not be registered. If the service is disabled, any services
that explicitly depend on it will fail to start. Host Process for Windows Services
Microsoft Corporation Microsoft Windows Operating System 6.3.9600.16384 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETWORKSERVICE
[Auto Services] :HKLM dot3svc
### Service: Wired AutoConfig Status: Start Type: loaded automatically by Server
Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * The Wired AutoConfig
(DOT3SVC) service is responsible for performing IEEE 802.1X authentication on
Ethernet interfaces. If your current wired network deployment enforces 802.1X
authentication, the DOT3SVC service should be configured to run for establishing
Layer 2 connectivity and/or providing access to network resources. Wired networks
that do not enforce 802.1X authentication are unaffected by the DOT3SVC service.
Host Process for Windows Services Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
LOCALSYSTEMNETWORKRESTRICTED
[Auto Services] :HKLM DPS
### Service: Diagnostic Policy Service Status: Start Type: loaded automatically
by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * The Diagnostic
Policy Service enables problem detection, troubleshooting and resolution for
Windows components. If this service is stopped, diagnostics will no longer
function. Host Process for Windows Services Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
LOCALSERVICENONETWORK
[Auto Services] :HKLM DptfParticipantProcessorService
### Service: @oem13.inf,%WIN32_DPTF_PARTICIPANT_PROC_SERVICE_DISPLAY_NAME
%;Intel(R) Dynamic Platform and Thermal Framework Processor Participant Service
Application Status: Start Type: loaded automatically by Server Manager Actual File:
C:\WINDOWS\SYSTEM32\DPTFPARTICIPANTPROCESSORSERVICE.EXE * @oem13.inf,
%WIN32_DPTF_PARTICIPANT_PROC_SERVICE_DESCRIPTION%;Intel(R) Dynamic Platform and
Thermal Framework Processor Participant Service Application Intel(R) Dynamic
Platform and Thermal Framework Processor Participant Service Intel Corporation
Intel(R) Dynamic Platform and Thermal Framework 7.1.0.2105 !$*%SYSTEMROOT
%\SYSTEM32\DPTFPARTICIPANTPROCESSORSERVICE.EXE
[Auto Services] :HKLM DptfPolicyConfigTDPService
### Service: @oem13.inf,%WIN32_DPTF_POLICY_CONFIGTDP_SERVICE_DISPLAY_NAME
%;Intel(R) Dynamic Platform and Thermal Framework Config TDP Service Application
Status: Start Type: loaded automatically by Server Manager Actual File:
C:\WINDOWS\SYSTEM32\DPTFPOLICYCONFIGTDPSERVICE.EXE * @oem13.inf,
%WIN32_DPTF_POLICY_CONFIGTDP_SERVICE_DESCRIPTION%;Intel(R) Dynamic Platform and
Thermal Framework Config TDP Service Application Intel(R) Dynamic Platform and
Thermal Framework Config TDP Policy Service Intel Corporation Intel(R) Dynamic
Platform and Thermal Framework 7.1.0.2105 !$*%SYSTEMROOT
%\SYSTEM32\DPTFPOLICYCONFIGTDPSERVICE.EXE
[Auto Services] :HKLM DptfPolicyLpmService
### Service: @oem13.inf,%WIN32_DPTF_POLICY_LPM_SERVICE_DISPLAY_NAME%;Intel(R)
Dynamic Platform and Thermal Framework Low Power Mode Service Application Status:
Start Type: loaded automatically by Server Manager Actual File:
C:\WINDOWS\SYSTEM32\DPTFPOLICYLPMSERVICE.EXE * @oem13.inf,
%WIN32_DPTF_POLICY_LPM_SERVICE_DESCRIPTION%;Intel(R) Dynamic Platform and Thermal
Framework Low Power Mode Service Application Intel(R) Dynamic Platform and Thermal
Framework LPM Policy Service Intel Corporation Intel(R) Dynamic Platform and
Thermal Framework 7.1.0.2105 !$*%SYSTEMROOT%\SYSTEM32\DPTFPOLICYLPMSERVICE.EXE
[Auto Services] :HKLM DsmSvc
### Service: Device Setup Manager Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Enables the detection, download and
installation of device-related software. If this service is disabled, devices may
be configured with outdated software, and may not work correctly. Host Process for
Windows Services Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS
[Auto Services] :HKLM Eaphost
### Service: Extensible Authentication Protocol Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * The Extensible
Authentication Protocol (EAP) service provides network authentication in such
scenarios as 802.1x wired and wireless, VPN, and Network Access Protection (NAP).
EAP also provides application programming interfaces (APIs) that are used by
network access clients, including wireless and VPN clients, during the
authentication process. If you disable this service, this computer is prevented
from accessing networks that require EAP authentication. Host Process for Windows
Services Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS
[Auto Services] :HKLM EFS
### Service: Encrypting File System (EFS) Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\LSASS.EXE * Provides the core file
encryption technology used to store encrypted files on NTFS file system volumes. If
this service is stopped or disabled, applications will be unable to access
encrypted files. Local Security Authority Process Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 !$*%SYSTEMROOT%\SYSTEM32\LSASS.EXE
[Auto Services] :HKLM EventLog
### Service: Windows Event Log Status: Start Type: loaded automatically by Server
Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * This service manages events
and event logs. It supports logging events, querying events, subscribing to events,
archiving event logs, and managing event metadata. It can display events in both
XML and plain text format. Stopping this service may compromise security and
reliability of the system. Host Process for Windows Services Microsoft Corporation
Microsoft Windows Operating System 6.3.9600.16384 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICENETWORKRESTRICTED
[Auto Services] :HKLM EventSystem
### Service: COM+ Event System Status: Start Type: loaded automatically by Server
Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Supports System Event
Notification Service (SENS), which provides automatic distribution of events to
subscribing Component Object Model (COM) components. If the service is stopped,
SENS will close and will not be able to provide logon and logoff notifications. If
this service is disabled, any services that explicitly depend on it will fail to
start. Host Process for Windows Services Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
LOCALSERVICE
[Auto Services] :HKLM Fax
### Service: Fax Status: Start Type: loaded manually on demand Actual File:
C:\WINDOWS\SYSTEM32\FXSSVC.EXE * Enables you to send and receive faxes, utilizing
fax resources available on this computer or on the network. Fax Service Microsoft
Corporation Microsoft Windows Operating System 6.3.9600.16384 !$*%SYSTEMROOT
%\SYSTEM32\FXSSVC.EXE
[Auto Services] :HKLM fdPHost
### Service: Function Discovery Provider Host Status: Start Type: loaded manually
on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * The FDPHOST service hosts
the Function Discovery (FD) network discovery providers. These FD providers supply
network discovery services for the Simple Services Discovery Protocol (SSDP) and
Web Services Discovery (WS-D) protocol. Stopping or disabling the FDPHOST service
will disable network discovery for these protocols when using FD. When this service
is unavailable, network services using FD and relying on these discovery protocols
will be unable to find network devices or resources. Host Process for Windows
Services Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE
[Auto Services] :HKLM FDResPub
### Service: Function Discovery Resource Publication Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Publishes this
computer and resources attached to this computer so they can be discovered over the
network. If this service is stopped, network resources will no longer be published
and they will not be discovered by other computers on the network. Host Process for
Windows Services Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
LOCALSERVICEANDNOIMPERSONATION
[Auto Services] :HKLM fhsvc
### Service: File History Service Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Protects user files from accidental
loss by copying them to a backup location Host Process for Windows Services
Microsoft Corporation Microsoft Windows Operating System 6.3.9600.16384 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED
[Auto Services] :HKLM FontCache
### Service: Windows Font Cache Service Status: Start Type: loaded automatically
by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Optimizes
performance of applications by caching commonly used font data. Applications will
start this service if it is not already running. It can be disabled, though doing
so will degrade application performance. Host Process for Windows Services
Microsoft Corporation Microsoft Windows Operating System 6.3.9600.16384 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE
[Auto Services] :HKLM FontCache3.0.0.0
### Service: Windows Presentation Foundation Font Cache 3.0.0.0 Status: Start
Type: loaded manually on demand Actual File:
C:\WINDOWS\MICROSOFT.NET\FRAMEWORK64\V3.0\WPF\PRESENTATIONFONTCACHE.EXE * Optimizes
performance of Windows Presentation Foundation (WPF) applications by caching
commonly used font data. WPF applications will start this service if it is not
already running. It can be disabled, though doing so will degrade the performance
of WPF applications. PresentationFontCache.exe Microsoft Corporation Microsoft
.NET Framework 3.0.6920.7903 !$*%SYSTEMROOT
%\MICROSOFT.NET\FRAMEWORK64\V3.0\WPF\PRESENTATIONFONTCACHE.EXE
[Auto Services] :HKLM gpsvc
### Service: Group Policy Client Status: Start Type: loaded automatically by
Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * The service is
responsible for applying settings configured by administrators for the computer and
users through the Group Policy component. If the service is disabled, the settings
will not be applied and applications and components will not be manageable through
Group Policy. Any components or applications that depend on the Group Policy
component might not be functional if the service is disabled. Host Process for
Windows Services Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS
[Auto Services] :HKLM hidserv
### Service: Human Interface Device Service Status: Start Type: loaded manually
on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Activates and maintains
the use of hot buttons on keyboards, remote controls, and other multimedia devices.
It is recommended that you keep this service running. Host Process for Windows
Services Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED
[Auto Services] :HKLM hkmsvc
### Service: Health Key and Certificate Management Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Provides X.509
certificate and key management services for the Network Access Protection Agent
(NAPAgent). Enforcement technologies that use X.509 certificates may not function
properly without this service Host Process for Windows Services Microsoft
Corporation Microsoft Windows Operating System 6.3.9600.16384 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K NETSVCS
[Auto Services] :HKLM HomeGroupListener
### Service: HomeGroup Listener Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Makes local computer changes
associated with configuration and maintenance of the homegroup-joined computer. If
this service is stopped or disabled, your computer will not work properly in a
homegroup and your homegroup might not work properly. It is recommended that you
keep this service running. Host Process for Windows Services Microsoft Corporation
Microsoft Windows Operating System 6.3.9600.16384 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED
[Auto Services] :HKLM HomeGroupProvider
### Service: HomeGroup Provider Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Performs networking tasks associated
with configuration and maintenance of homegroups. If this service is stopped or
disabled, your computer will be unable to detect other homegroups and your
homegroup might not work properly. It is recommended that you keep this service
running. Host Process for Windows Services Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
LOCALSERVICENETWORKRESTRICTED
[Auto Services] :HKLM IEEtwCollectorService
### Service: Internet Explorer ETW Collector Service Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\IEETWCOLLECTOR.EXE * ETW
Collector Service for Internet Explorer. When running, this service collects real
time ETW events and processes them. IE ETW Collector Service Microsoft Corporation
Internet Explorer 11.00.9600.16384 !$*%SYSTEMROOT%\SYSTEM32\IEETWCOLLECTOR.EXE /V
[Auto Services] :HKLM igfxCUIService1.0.0.0
### Service: Intel(R) HD Graphics Control Panel Service Status: Start Type:
loaded automatically by Server Manager Actual File:
C:\WINDOWS\SYSTEM32\IGFXCUISERVICE.EXE * Service for Intel(R) HD Graphics Control
Panel igfxCUIService Module Intel Corporation Intel(R) Common User Interface
6.15.10.3496 !$*%SYSTEMROOT%\SYSTEM32\IGFXCUISERVICE.EXE
[Auto Services] :HKLM IKEEXT
### Service: IKE and AuthIP IPsec Keying Modules Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * The IKEEXT
service hosts the Internet Key Exchange (IKE) and Authenticated Internet Protocol
(AuthIP) keying modules. These keying modules are used for authentication and key
exchange in Internet Protocol security (IPsec). Stopping or disabling the IKEEXT
service will disable IKE and AuthIP key exchange with peer computers. IPsec is
typically configured to use IKE or AuthIP; therefore, stopping or disabling the
IKEEXT service might result in an IPsec failure and might compromise the security
of the system. It is strongly recommended that you have the IKEEXT service running.
Host Process for Windows Services Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS
[Auto Services] :HKLM Intel(R) Capability Licensing Service Interface
### Service: Intel(R) Capability Licensing Service Interface Status: Start Type:
loaded automatically by Server Manager Actual File: C:\PROGRAM FILES\INTEL\ICLS
CLIENT\HECISERVER.EXE * Version: 1.31.8.1 Intel(R) Capability Licensing Service
Interface Intel(R) Corporation Intel(R) Capability Licensing Service Interface
1,31,8,1 !$*"C:\PROGRAM FILES\INTEL\ICLS CLIENT\HECISERVER.EXE"
[Auto Services] :HKLM Intel(R) Capability Licensing Service TCP IP Interface
### Service: Intel(R) Capability Licensing Service TCP IP Interface Status: Start
Type: loaded manually on demand Actual File: C:\PROGRAM FILES\INTEL\ICLS
CLIENT\SOCKETHECISERVER.EXE * Version: 1.31.8.1 Intel(R) Capability Licensing
Service TCP IP Interface Intel(R) Corporation Intel(R) Capability Licensing Service
TCP IP Interface 1,31,8,1 !$*"C:\PROGRAM FILES\INTEL\ICLS
CLIENT\SOCKETHECISERVER.EXE"
[Auto Services] :HKLM iphlpsvc
### Service: IP Helper Status: Start Type: loaded automatically by Server Manager
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Provides tunnel connectivity using
IPv6 transition technologies (6to4, ISATAP, Port Proxy, and Teredo), and IP-HTTPS.
If this service is stopped, the computer will not have the enhanced connectivity
benefits that these technologies offer. Host Process for Windows Services Microsoft
Corporation Microsoft Windows Operating System 6.3.9600.16384 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K NETSVCS
[Auto Services] :HKLM jhi_service
### Service: Intel(R) Dynamic Application Loader Host Interface Service Status:
Start Type: loaded automatically by Server Manager Actual File: C:\PROGRAM FILES
(X86)\INTEL\INTEL(R) MANAGEMENT ENGINE COMPONENTS\DAL\JHI_SERVICE.EXE * Intel(R)
Dynamic Application Loader Host Interface Service - Allows applications to access
the local Intel (R) DAL Intel(R) Dynamic Application Loader Host Interface Intel
Corporation Intel(R) Dynamic Application Loader Host Interface 9.5.12.1682 !
$*"C:\PROGRAM FILES (X86)\INTEL\INTEL(R) MANAGEMENT ENGINE
COMPONENTS\DAL\JHI_SERVICE.EXE"
[Auto Services] :HKLM KeyIso
### Service: CNG Key Isolation Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\LSASS.EXE * The CNG key isolation service is
hosted in the LSA process. The service provides key process isolation to private
keys and associated cryptographic operations as required by the Common Criteria.
The service stores and uses long-lived keys in a secure process complying with
Common Criteria requirements. Local Security Authority Process Microsoft
Corporation Microsoft Windows Operating System 6.3.9600.16384 !$*%SYSTEMROOT
%\SYSTEM32\LSASS.EXE
[Auto Services] :HKLM KtmRm
### Service: KtmRm for Distributed Transaction Coordinator Status: Start Type:
loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE *
Coordinates transactions between the Distributed Transaction Coordinator (MSDTC)
and the Kernel Transaction Manager (KTM). If it is not needed, it is recommended
that this service remain stopped. If it is needed, both MSDTC and KTM will start
this service automatically. If this service is disabled, any MSDTC transaction
interacting with a Kernel Resource Manager will fail and any services that
explicitly depend on it will fail to start. Host Process for Windows Services
Microsoft Corporation Microsoft Windows Operating System 6.3.9600.16384 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETWORKSERVICEANDNOIMPERSONATION
[Auto Services] :HKLM LanmanServer
### Service: Server Status: Start Type: loaded automatically by Server Manager
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Supports file, print, and named-pipe
sharing over the network for this computer. If this service is stopped, these
functions will be unavailable. If this service is disabled, any services that
explicitly depend on it will fail to start. Host Process for Windows Services
Microsoft Corporation Microsoft Windows Operating System 6.3.9600.16384 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS
[Auto Services] :HKLM LanmanWorkstation
### Service: Workstation Status: Start Type: loaded automatically by Server
Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Creates and maintains client
network connections to remote servers using the SMB protocol. If this service is
stopped, these connections will be unavailable. If this service is disabled, any
services that explicitly depend on it will fail to start. Host Process for Windows
Services Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETWORKSERVICE
[Auto Services] :HKLM lfsvc
### Service: Windows Location Framework Service Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * This services
monitors the current location of the system and manages geo-fences (a geographical
location with associated events). If you turn off this service, applications will
be unable to use or receive notifications for geo-fences. Host Process for Windows
Services Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS
[Auto Services] :HKLM lltdsvc
### Service: Link-Layer Topology Discovery Mapper Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Creates a Network
Map, consisting of PC and device topology (connectivity) information, and metadata
describing each PC and device. If this service is disabled, the Network Map will
not function properly. Host Process for Windows Services Microsoft Corporation
Microsoft Windows Operating System 6.3.9600.16384 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE
[Auto Services] :HKLM lmhosts
### Service: TCP/IP NetBIOS Helper Status: Start Type: loaded automatically by
Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Provides support for
the NetBIOS over TCP/IP (NetBT) service and NetBIOS name resolution for clients on
the network, therefore enabling users to share files, print, and log on to the
network. If this service is stopped, these functions might be unavailable. If this
service is disabled, any services that explicitly depend on it will fail to start.
Host Process for Windows Services Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
LOCALSERVICENETWORKRESTRICTED
[Auto Services] :HKLM LMS
### Service: Intel(R) Management and Security Application Local Management
Service Status: Start Type: loaded automatically by Server Manager Actual File:
C:\PROGRAM FILES (X86)\INTEL\INTEL(R) MANAGEMENT ENGINE COMPONENTS\LMS\LMS.EXE *
Intel(R) Management and Security Application Local Management Service - Provides
OS-related Intel(R) ME functionality. Intel(R) Local Management Service Intel
Corporation Intel(R) Management and Security Application Local Management Service
9.5.10.1628 !$*"C:\PROGRAM FILES (X86)\INTEL\INTEL(R) MANAGEMENT ENGINE
COMPONENTS\LMS\LMS.EXE"
[Auto Services] :HKLM LSM
### Service: Local Session Manager Status: Start Type: loaded automatically by
Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Core Windows Service
that manages local user sessions. Stopping or disabling this service will result in
system instability. Host Process for Windows Services Microsoft Corporation
Microsoft Windows Operating System 6.3.9600.16384 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K DCOMLAUNCH
[Auto Services] :HKLM MMCSS
### Service: Multimedia Class Scheduler Status: Start Type: loaded automatically
by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Enables relative
prioritization of work based on system-wide task priorities. This is intended
mainly for multimedia applications. If this service is stopped, individual tasks
resort to their default priority. Host Process for Windows Services Microsoft
Corporation Microsoft Windows Operating System 6.3.9600.16384 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K NETSVCS
[Auto Services] :HKLM MozillaMaintenance
### Service: Mozilla Maintenance Service Status: Start Type: loaded manually on
demand Actual File: C:\PROGRAM FILES (X86)\MOZILLA MAINTENANCE
SERVICE\MAINTENANCESERVICE.EXE * Layanan Pemeliharaan Mozilla memastikan agar
Mozilla Firefox terbaru dan teraman dipasang pada komputer Anda. Sangat penting
untuk memastikan agar versi Firefox tetap yang terbaru demi keamanan daring Anda,
sehingga Mozilla sangat menyarankan agar layanan ini tetap diaktifkan. Mozilla
Foundation Firefox 44.0.1 !$*"C:\PROGRAM FILES (X86)\MOZILLA MAINTENANCE
SERVICE\MAINTENANCESERVICE.EXE"
[Auto Services] :HKLM MpsSvc
### Service: Windows Firewall Status: Start Type: loaded automatically by Server
Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Windows Firewall helps
protect your computer by preventing unauthorized users from gaining access to your
computer through the Internet or a network. Host Process for Windows Services
Microsoft Corporation Microsoft Windows Operating System 6.3.9600.16384 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICENONETWORK
[Auto Services] :HKLM MSDTC
### Service: Distributed Transaction Coordinator Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\MSDTC.EXE * Coordinates
transactions that span multiple resource managers, such as databases, message
queues, and file systems. If this service is stopped, these transactions will fail.
If this service is disabled, any services that explicitly depend on it will fail to
start. Microsoft Distributed Transaction Coordinator Service Microsoft Corporation
Microsoft Windows Operating System 6.3.9600.16384 !$*%SYSTEMROOT
%\SYSTEM32\MSDTC.EXE
[Auto Services] :HKLM MSiSCSI
### Service: Microsoft iSCSI Initiator Service Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Manages Internet
SCSI (iSCSI) sessions from this computer to remote iSCSI target devices. If this
service is stopped, this computer will not be able to login or access iSCSI
targets. If this service is disabled, any services that explicitly depend on it
will fail to start. Host Process for Windows Services Microsoft Corporation
Microsoft Windows Operating System 6.3.9600.16384 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K NETSVCS
[Auto Services] :HKLM msiserver
### Service: Windows Installer Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\MSIEXEC.EXE * Adds, modifies, and removes
applications provided as a Windows Installer (*.msi, *.msp) package. If this
service is disabled, any services that explicitly depend on it will fail to start.
Windows installer Microsoft Corporation Windows Installer - Unicode 5.0.9600.16384
!$*%SYSTEMROOT%\SYSTEM32\MSIEXEC.EXE /V
[Auto Services] :HKLM napagent
### Service: Network Access Protection Agent Status: Start Type: loaded manually
on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * The Network Access
Protection (NAP) agent service collects and manages health information for client
computers on a network. Information collected by NAP agent is used to make sure
that the client computer has the required software and settings. If a client
computer is not compliant with health policy, it can be provided with restricted
network access until its configuration is updated. Depending on the configuration
of health policy, client computers might be automatically updated so that users
quickly regain full network access without having to manually update their
computer. Host Process for Windows Services Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
NETWORKSERVICE
[Auto Services] :HKLM NcaSvc
### Service: Network Connectivity Assistant Status: Start Type: loaded manually
on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Provides DirectAccess
status notification for UI components Host Process for Windows Services Microsoft
Corporation Microsoft Windows Operating System 6.3.9600.16384 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K NETSVCS
[Auto Services] :HKLM NcbService
### Service: Network Connection Broker Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Brokers connections that
allow Windows Store Apps to receive notifications from the internet. Host Process
for Windows Services Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED
[Auto Services] :HKLM NcdAutoSetup
### Service: Network Connected Devices Auto-Setup Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Network Connected
Devices Auto-Setup service monitors and installs qualified devices that connect to
a qualified network. Stopping or disabling this service will prevent Windows from
discovering and installing qualified network connected devices automatically. Users
can still manually add network connected devices to a PC through the user
interface. Host Process for Windows Services Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
LOCALSERVICENONETWORK
[Auto Services] :HKLM Netlogon
### Service: Netlogon Status: Start Type: loaded manually on demand Actual File:
C:\WINDOWS\SYSTEM32\LSASS.EXE * Maintains a secure channel between this computer
and the domain controller for authenticating users and services. If this service is
stopped, the computer may not authenticate users and services and the domain
controller cannot register DNS records. If this service is disabled, any services
that explicitly depend on it will fail to start. Local Security Authority Process
Microsoft Corporation Microsoft Windows Operating System 6.3.9600.16384 !$*
%SYSTEMROOT%\SYSTEM32\LSASS.EXE
[Auto Services] :HKLM Netman
### Service: Network Connections Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Manages objects in the Network and
Dial-Up Connections folder, in which you can view both local area network and
remote connections. Host Process for Windows Services Microsoft Corporation
Microsoft Windows Operating System 6.3.9600.16384 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED
[Auto Services] :HKLM netprofm
### Service: Network List Service Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Identifies the networks to which the
computer has connected, collects and stores properties for these networks, and
notifies applications when these properties change. Host Process for Windows
Services Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE
[Auto Services] :HKLM NlaSvc
### Service: Network Location Awareness Status: Start Type: loaded automatically
by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Collects and
stores configuration information for the network and notifies programs when this
information is modified. If this service is stopped, configuration information
might be unavailable. If this service is disabled, any services that explicitly
depend on it will fail to start. Host Process for Windows Services Microsoft
Corporation Microsoft Windows Operating System 6.3.9600.16384 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K NETWORKSERVICE
[Auto Services] :HKLM nsi
### Service: Network Store Interface Service Status: Start Type: loaded
automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * This
service delivers network notifications (e.g. interface addition/deleting etc) to
user mode clients. Stopping this service will cause loss of network connectivity.
If this service is disabled, any other services that explicitly depend on this
service will fail to start. Host Process for Windows Services Microsoft Corporation
Microsoft Windows Operating System 6.3.9600.16384 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE
[Auto Services] :HKLM NvNetworkService
### Service: NVIDIA Network Service Status: Start Type: loaded automatically by
Server Manager Actual File: C:\PROGRAM FILES (X86)\NVIDIA
CORPORATION\NETSERVICE\NVNETWORKSERVICE.EXE * NVIDIA Network Service NVIDIA Network
Service NVIDIA Corporation NVIDIA Network Service 1.0.5.16 !$*"C:\PROGRAM FILES
(X86)\NVIDIA CORPORATION\NETSERVICE\NVNETWORKSERVICE.EXE"
[Auto Services] :HKLM nvsvc
### Service: NVIDIA Display Driver Service Status: Start Type: loaded
automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\NVVSVC.EXE *
Provides system and desktop level support to the NVIDIA display driver NVIDIA
Driver Helper Service, Version 333.17 NVIDIA Corporation NVIDIA Driver Helper
Service, Version 333.17 8.17.13.3317 !$*"C:\WINDOWS\SYSTEM32\NVVSVC.EXE"
[Auto Services] :HKLM p2pimsvc
### Service: Peer Networking Identity Manager Status: Start Type: loaded manually
on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Provides identity services
for the Peer Name Resolution Protocol (PNRP) and Peer-to-Peer Grouping services.
If disabled, the Peer Name Resolution Protocol (PNRP) and Peer-to-Peer Grouping
services may not function, and some applications, such as HomeGroup and Remote
Assistance, may not function correctly. Host Process for Windows Services Microsoft
Corporation Microsoft Windows Operating System 6.3.9600.16384 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICEPEERNET
[Auto Services] :HKLM p2psvc
### Service: Peer Networking Grouping Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Enables multi-party
communication using Peer-to-Peer Grouping. If disabled, some applications, such as
HomeGroup, may not function. Host Process for Windows Services Microsoft
Corporation Microsoft Windows Operating System 6.3.9600.16384 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICEPEERNET
[Auto Services] :HKLM PcaSvc
### Service: Program Compatibility Assistant Service Status: Start Type: loaded
automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * This
service provides support for the Program Compatibility Assistant (PCA). PCA
monitors programs installed and run by the user and detects known compatibility
problems. If this service is stopped, PCA will not function properly. Host Process
for Windows Services Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED
[Auto Services] :HKLM PeerDistSvc
### Service: BranchCache Status: Start Type: loaded manually on demand Actual
File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * This service caches network content from
peers on the local subnet. Host Process for Windows Services Microsoft Corporation
Microsoft Windows Operating System 6.3.9600.16384 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K PEERDIST
[Auto Services] :HKLM PerfHost
### Service: Performance Counter DLL Host Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSWOW64\PERFHOST.EXE * Enables remote users and 64-
bit processes to query performance counters provided by 32-bit DLLs. If this
service is stopped, only local users and 32-bit processes will be able to query
performance counters provided by 32-bit DLLs. x86 Performance Counter Host
Microsoft Corporation Microsoft Windows Operating System 6.3.9600.16384 !$*
%SYSTEMROOT%\SYSWOW64\PERFHOST.EXE
[Auto Services] :HKLM pla
### Service: Performance Logs & Alerts Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Performance Logs and Alerts
Collects performance data from local or remote computers based on preconfigured
schedule parameters, then writes the data to a log or triggers an alert. If this
service is stopped, performance information will not be collected. If this service
is disabled, any services that explicitly depend on it will fail to start. Host
Process for Windows Services Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICENONETWORK
[Auto Services] :HKLM PlugPlay
### Service: Plug and Play Status: Start Type: loaded manually on demand Actual
File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Enables a computer to recognize and adapt
to hardware changes with little or no user input. Stopping or disabling this
service will result in system instability. Host Process for Windows Services
Microsoft Corporation Microsoft Windows Operating System 6.3.9600.16384 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K DCOMLAUNCH
[Auto Services] :HKLM PNRPAutoReg
### Service: PNRP Machine Name Publication Service Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * This service
publishes a machine name using the Peer Name Resolution Protocol. Configuration is
managed via the netsh context 'p2p pnrp peer' Host Process for Windows Services
Microsoft Corporation Microsoft Windows Operating System 6.3.9600.16384 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICEPEERNET
[Auto Services] :HKLM PNRPsvc
### Service: Peer Name Resolution Protocol Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Enables serverless peer name
resolution over the Internet using the Peer Name Resolution Protocol (PNRP). If
disabled, some peer-to-peer and collaborative applications, such as Remote
Assistance, may not function. Host Process for Windows Services Microsoft
Corporation Microsoft Windows Operating System 6.3.9600.16384 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICEPEERNET
[Auto Services] :HKLM PolicyAgent
### Service: IPsec Policy Agent Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Internet Protocol security (IPsec)
supports network-level peer authentication, data origin authentication, data
integrity, data confidentiality (encryption), and replay protection. This service
enforces IPsec policies created through the IP Security Policies snap-in or the
command-line tool "netsh ipsec". If you stop this service, you may experience
network connectivity issues if your policy requires that connections use IPsec.
Also,remote management of Windows Firewall is not available when this service is
stopped. Host Process for Windows Services Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
NETWORKSERVICENETWORKRESTRICTED
[Auto Services] :HKLM Power
### Service: Power Status: Start Type: loaded automatically by Server Manager
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Manages power policy and power
policy notification delivery. Host Process for Windows Services Microsoft
Corporation Microsoft Windows Operating System 6.3.9600.16384 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K DCOMLAUNCH
[Auto Services] :HKLM PrintNotify
### Service: Printer Extensions and Notifications Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * This service
opens custom printer dialog boxes and handles notifications from a remote print
server or a printer. If you turn off this service, you wont be able to see printer
extensions or notifications. Host Process for Windows Services Microsoft
Corporation Microsoft Windows Operating System 6.3.9600.16384 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K PRINT
[Auto Services] :HKLM ProfSvc
### Service: User Profile Service Status: Start Type: loaded automatically by
Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * This service is
responsible for loading and unloading user profiles. If this service is stopped or
disabled, users will no longer be able to successfully sign in or sign out, apps
might have problems getting to users' data, and components registered to receive
profile event notifications won't receive them. Host Process for Windows Services
Microsoft Corporation Microsoft Windows Operating System 6.3.9600.16384 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS
[Auto Services] :HKLM QWAVE
### Service: Quality Windows Audio Video Experience Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Quality Windows
Audio Video Experience (qWave) is a networking platform for Audio Video (AV)
streaming applications on IP home networks. qWave enhances AV streaming performance
and reliability by ensuring network quality-of-service (QoS) for AV applications.
It provides mechanisms for admission control, run time monitoring and enforcement,
application feedback, and traffic prioritization. Host Process for Windows Services
Microsoft Corporation Microsoft Windows Operating System 6.3.9600.16384 !$*
%WINDIR%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICEANDNOIMPERSONATION
[Auto Services] :HKLM RasAuto
### Service: Remote Access Auto Connection Manager Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Creates a
connection to a remote network whenever a program references a remote DNS or
NetBIOS name or address. Host Process for Windows Services Microsoft Corporation
Microsoft Windows Operating System 6.3.9600.16384 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K NETSVCS
[Auto Services] :HKLM RasMan
### Service: Remote Access Connection Manager Status: Start Type: loaded manually
on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Manages dial-up and
virtual private network (VPN) connections from this computer to the Internet or
other remote networks. If this service is disabled, any services that explicitly
depend on it will fail to start. Host Process for Windows Services Microsoft
Corporation Microsoft Windows Operating System 6.3.9600.16384 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K NETSVCS
[Auto Services] :HKLM rpcapd
### Service: Remote Packet Capture Protocol v.0 (experimental) Status: Start
Type: loaded manually on demand Actual File: C:\PROGRAM FILES
(X86)\WINPCAP\RPCAPD.EXE * Allows to capture traffic on this machine from a remote
machine. Remote Packet Capture Daemon CACE Technologies, Inc. WinPcap 4.1.0.2001 !
$*"%PROGRAMFILES(X86)%\WINPCAP\RPCAPD.EXE" -D -F
"%PROGRAMFILES(X86)%\WINPCAP\RPCAPD.INI"
[Auto Services] :HKLM RpcEptMapper
### Service: RPC Endpoint Mapper Status: Start Type: loaded automatically by
Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Resolves RPC
interfaces identifiers to transport endpoints. If this service is stopped or
disabled, programs using Remote Procedure Call (RPC) services will not function
properly. Host Process for Windows Services Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
RPCSS
[Auto Services] :HKLM RpcLocator
### Service: Remote Procedure Call (RPC) Locator Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\LOCATOR.EXE * In Windows 2003
and earlier versions of Windows, the Remote Procedure Call (RPC) Locator service
manages the RPC name service database. In Windows Vista and later versions of
Windows, this service does not provide any functionality and is present for
application compatibility. Rpc Locator Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%SYSTEMROOT%\SYSTEM32\LOCATOR.EXE
[Auto Services] :HKLM RpcSs
### Service: Remote Procedure Call (RPC) Status: Start Type: loaded automatically
by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * The RPCSS service
is the Service Control Manager for COM and DCOM servers. It performs object
activations requests, object exporter resolutions and distributed garbage
collection for COM and DCOM servers. If this service is stopped or disabled,
programs using COM or DCOM will not function properly. It is strongly recommended
that you have the RPCSS service running. Host Process for Windows Services
Microsoft Corporation Microsoft Windows Operating System 6.3.9600.16384 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K RPCSS
[Auto Services] :HKLM SamSs
### Service: Security Accounts Manager Status: Start Type: loaded automatically
by Server Manager Actual File: C:\WINDOWS\SYSTEM32\LSASS.EXE * The startup of this
service signals other services that the Security Accounts Manager (SAM) is ready to
accept requests. Disabling this service will prevent other services in the system
from being notified when the SAM is ready, which may in turn cause those services
to fail to start correctly. This service should not be disabled. Local Security
Authority Process Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*%SYSTEMROOT%\SYSTEM32\LSASS.EXE
[Auto Services] :HKLM SAService
### Service: Conexant SmartAudio service Status: Start Type: loaded automatically
by Server Manager Actual File: C:\WINDOWS\SYSWOW64\SASRV.EXE * SmartAudio Helper
service SmartAudio Service Application Conexant Systems, Inc. SmartAudio Service
Application 1, 0, 4, 0 !$*%SYSTEMROOT%\SYSTEM32\SASRV.EXE
[Auto Services] :HKLM ScDeviceEnum
### Service: Smart Card Device Enumeration Service Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Creates software
device nodes for all smart card readers accessible to a given session. If this
service is disabled, WinRT APIs will not be able to enumerate smart card readers.
Host Process for Windows Services Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
LOCALSYSTEMNETWORKRESTRICTED
[Auto Services] :HKLM Schedule
### Service: Task Scheduler Status: Start Type: loaded automatically by Server
Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Enables a user to configure
and schedule automated tasks on this computer. The service also hosts multiple
Windows system-critical tasks. If this service is stopped or disabled, these tasks
will not be run at their scheduled times. If this service is disabled, any services
that explicitly depend on it will fail to start. Host Process for Windows Services
Microsoft Corporation Microsoft Windows Operating System 6.3.9600.16384 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS
[Auto Services] :HKLM SCPolicySvc
### Service: Smart Card Removal Policy Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Allows the system to be
configured to lock the user desktop upon smart card removal. Host Process for
Windows Services Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS
[Auto Services] :HKLM seclogon
### Service: Secondary Logon Status: Start Type: loaded manually on demand Actual
File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Enables starting processes under alternate
credentials. If this service is stopped, this type of logon access will be
unavailable. If this service is disabled, any services that explicitly depend on it
will fail to start. Host Process for Windows Services Microsoft Corporation
Microsoft Windows Operating System 6.3.9600.16384 !$*%WINDIR
%\SYSTEM32\SVCHOST.EXE -K NETSVCS
[Auto Services] :HKLM SENS
### Service: System Event Notification Service Status: Start Type: loaded
automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE *
Monitors system events and notifies subscribers to COM+ Event System of these
events. Host Process for Windows Services Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS
[Auto Services] :HKLM SensrSvc
### Service: Sensor Monitoring Service Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Monitors various sensors in
order to expose data and adapt to system and user state. If this service is
stopped or disabled, the display brightness will not adapt to lighting conditions.
Stopping this service may affect other system functionality and features as well.
Host Process for Windows Services Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
LOCALSERVICEANDNOIMPERSONATION
[Auto Services] :HKLM SessionEnv
### Service: Remote Desktop Configuration Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Remote Desktop Configuration
service (RDCS) is responsible for all Remote Desktop Services and Remote Desktop
related configuration and session maintenance activities that require SYSTEM
context. These include per-session temporary folders, RD themes, and RD
certificates. Host Process for Windows Services Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
NETSVCS
[Auto Services] :HKLM ShellHWDetection
### Service: Shell Hardware Detection Status: Start Type: loaded automatically by
Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Provides
notifications for AutoPlay hardware events. Host Process for Windows Services
Microsoft Corporation Microsoft Windows Operating System 6.3.9600.16384 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS
[Auto Services] :HKLM smphost
### Service: Microsoft Storage Spaces SMP Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Host service for the
Microsoft Storage Spaces management provider. If this service is stopped or
disabled, Storage Spaces cannot be managed. Host Process for Windows Services
Microsoft Corporation Microsoft Windows Operating System 6.3.9600.16384 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K SMPHOST
[Auto Services] :HKLM SNMPTRAP
### Service: SNMP Trap Status: Start Type: loaded manually on demand Actual File:
C:\WINDOWS\SYSTEM32\SNMPTRAP.EXE * Receives trap messages generated by local or
remote Simple Network Management Protocol (SNMP) agents and forwards the messages
to SNMP management programs running on this computer. If this service is stopped,
SNMP-based programs on this computer will not receive SNMP trap messages. If this
service is disabled, any services that explicitly depend on it will fail to start.
SNMP Trap Microsoft Corporation Microsoft Windows Operating System 6.3.9600.16384
!$*%SYSTEMROOT%\SYSTEM32\SNMPTRAP.EXE
[Auto Services] :HKLM Spooler
### Service: Print Spooler Status: Start Type: loaded automatically by Server
Manager Actual File: C:\WINDOWS\SYSTEM32\SPOOLSV.EXE * This service spools print
jobs and handles interaction with the printer. If you turn off this service, you
wont be able to print or see your printers. Spooler SubSystem App Microsoft
Corporation Microsoft Windows Operating System 6.3.9600.16384 !$*%SYSTEMROOT
%\SYSTEM32\SPOOLSV.EXE
[Auto Services] :HKLM sppsvc
### Service: Software Protection Status: Start Type: loaded automatically by
Server Manager Actual File: C:\WINDOWS\SYSTEM32\SPPSVC.EXE * Enables the download,
installation and enforcement of digital licenses for Windows and Windows
applications. If the service is disabled, the operating system and licensed
applications may run in a notification mode. It is strongly recommended that you
not disable the Software Protection service. Microsoft Software Protection Platform
Service Microsoft Corporation Microsoft Windows Operating System 6.3.9600.16384 !
$*%SYSTEMROOT%\SYSTEM32\SPPSVC.EXE
[Auto Services] :HKLM SSDPSRV
### Service: SSDP Discovery Status: Start Type: loaded manually on demand Actual
File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Discovers networked devices and services
that use the SSDP discovery protocol, such as UPnP devices. Also announces SSDP
devices and services running on the local computer. If this service is stopped,
SSDP-based devices will not be discovered. If this service is disabled, any
services that explicitly depend on it will fail to start. Host Process for Windows
Services Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
LOCALSERVICEANDNOIMPERSONATION
[Auto Services] :HKLM SstpSvc
### Service: Secure Socket Tunneling Protocol Service Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Provides support
for the Secure Socket Tunneling Protocol (SSTP) to connect to remote computers
using VPN. If this service is disabled, users will not be able to use SSTP to
access remote servers. Host Process for Windows Services Microsoft Corporation
Microsoft Windows Operating System 6.3.9600.16384 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE
[Auto Services] :HKLM stisvc
### Service: Windows Image Acquisition (WIA) Status: Start Type: loaded
automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE *
Provides image acquisition services for scanners and cameras Host Process for
Windows Services Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K IMGSVC
[Auto Services] :HKLM StorSvc
### Service: Storage Service Status: Start Type: loaded manually on demand Actual
File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Enforces group policy for storage devices
Host Process for Windows Services Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
LOCALSYSTEMNETWORKRESTRICTED
[Auto Services] :HKLM svsvc
### Service: Spot Verifier Status: Start Type: loaded manually on demand Actual
File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Verifies potential file system corruptions.
Host Process for Windows Services Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
LOCALSYSTEMNETWORKRESTRICTED
[Auto Services] :HKLM swprv
### Service: Microsoft Software Shadow Copy Provider Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Manages software-
based volume shadow copies taken by the Volume Shadow Copy service. If this service
is stopped, software-based volume shadow copies cannot be managed. If this service
is disabled, any services that explicitly depend on it will fail to start. Host
Process for Windows Services Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K SWPRV
[Auto Services] :HKLM SysMain
### Service: Superfetch Status: Start Type: loaded automatically by Server
Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Maintains and improves
system performance over time. Host Process for Windows Services Microsoft
Corporation Microsoft Windows Operating System 6.3.9600.16384 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED
[Auto Services] :HKLM SystemEventsBroker
### Service: System Events Broker Status: Start Type: loaded automatically by
Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Coordinates execution
of background work for WinRT application. If this service is stopped or disabled,
then background work might not be triggered. Host Process for Windows Services
Microsoft Corporation Microsoft Windows Operating System 6.3.9600.16384 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K DCOMLAUNCH
[Auto Services] :HKLM TabletInputService
### Service: Touch Keyboard and Handwriting Panel Service Status: Start Type:
loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Enables
Touch Keyboard and Handwriting Panel pen and ink functionality Host Process for
Windows Services Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED
[Auto Services] :HKLM TapiSrv
### Service: Telephony Status: Start Type: loaded manually on demand Actual File:
C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Provides Telephony API (TAPI) support for
programs that control telephony devices on the local computer and, through the LAN,
on servers that are also running the service. Host Process for Windows Services
Microsoft Corporation Microsoft Windows Operating System 6.3.9600.16384 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETWORKSERVICE
[Auto Services] :HKLM TermService
### Service: Remote Desktop Services Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Allows users to connect
interactively to a remote computer. Remote Desktop and Remote Desktop Session Host
Server depend on this service. To prevent remote use of this computer, clear the
checkboxes on the Remote tab of the System properties control panel item. Host
Process for Windows Services Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETWORKSERVICE
[Auto Services] :HKLM Themes
### Service: Themes Status: Start Type: loaded automatically by Server Manager
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Provides user experience theme
management. Host Process for Windows Services Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
NETSVCS
[Auto Services] :HKLM THREADORDER
### Service: Thread Ordering Server Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Provides ordered execution for a
group of threads within a specific period of time. Host Process for Windows
Services Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE
[Auto Services] :HKLM TimeBroker
### Service: Time Broker Status: Start Type: loaded manually on demand Actual
File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Coordinates execution of background work
for WinRT application. If this service is stopped or disabled, then background work
might not be triggered. Host Process for Windows Services Microsoft Corporation
Microsoft Windows Operating System 6.3.9600.16384 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICEANDNOIMPERSONATION
[Auto Services] :HKLM TrkWks
### Service: Distributed Link Tracking Client Status: Start Type: loaded
automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE *
Maintains links between NTFS files within a computer or across computers in a
network. Host Process for Windows Services Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
LOCALSYSTEMNETWORKRESTRICTED
[Auto Services] :HKLM TrustedInstaller
### Service: Windows Modules Installer Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SERVICING\TRUSTEDINSTALLER.EXE * Enables
installation, modification, and removal of Windows updates and optional components.
If this service is disabled, install or uninstall of Windows updates might fail for
this computer. Windows Modules Installer Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%SYSTEMROOT%\SERVICING\TRUSTEDINSTALLER.EXE
[Auto Services] :HKLM UI0Detect
### Service: Interactive Services Detection Status: Start Type: loaded manually
on demand Actual File: C:\WINDOWS\SYSTEM32\UI0DETECT.EXE * Enables user
notification of user input for interactive services, which enables access to
dialogs created by interactive services when they appear. If this service is
stopped, notifications of new interactive service dialogs will no longer function
and there might not be access to interactive service dialogs. If this service is
disabled, both notifications of and access to new interactive service dialogs will
no longer function. Interactive services detection Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 !$*%SYSTEMROOT%\SYSTEM32\UI0DETECT.EXE
[Auto Services] :HKLM UmRdpService
### Service: Remote Desktop Services UserMode Port Redirector Status: Start Type:
loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Allows the
redirection of Printers/Drives/Ports for RDP connections Host Process for Windows
Services Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED
[Auto Services] :HKLM upnphost
### Service: UPnP Device Host Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Allows UPnP devices to be hosted on
this computer. If this service is stopped, any hosted UPnP devices will stop
functioning and no additional hosted devices can be added. If this service is
disabled, any services that explicitly depend on it will fail to start. Host
Process for Windows Services Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
LOCALSERVICEANDNOIMPERSONATION
[Auto Services] :HKLM VaultSvc
### Service: Credential Manager Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\LSASS.EXE * Provides secure storage and retrieval
of credentials to users, applications and security service packages. Local Security
Authority Process Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*%SYSTEMROOT%\SYSTEM32\LSASS.EXE
[Auto Services] :HKLM vds
### Service: Virtual Disk Status: Start Type: loaded manually on demand Actual
File: C:\WINDOWS\SYSTEM32\VDS.EXE * Provides management services for disks,
volumes, file systems, and storage arrays. Virtual Disk Service Microsoft
Corporation Microsoft Windows Operating System 6.3.9600.16384 !$*%SYSTEMROOT
%\SYSTEM32\VDS.EXE
[Auto Services] :HKLM vmicguestinterface
### Service: Hyper-V Guest Service Interface Status: Start Type: loaded manually
on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Provides an interface for
the Hyper-V host to interact with specific services running inside the virtual
machine. Host Process for Windows Services Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
LOCALSYSTEMNETWORKRESTRICTED
[Auto Services] :HKLM vmicheartbeat
### Service: Hyper-V Heartbeat Service Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Monitors the state of this
virtual machine by reporting a heartbeat at regular intervals. This service helps
you identify running virtual machines that have stopped responding. Host Process
for Windows Services Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K ICSERVICE
[Auto Services] :HKLM vmickvpexchange
### Service: Hyper-V Data Exchange Service Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Provides a mechanism to
exchange data between the virtual machine and the operating system running on the
physical computer. Host Process for Windows Services Microsoft Corporation
Microsoft Windows Operating System 6.3.9600.16384 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED
[Auto Services] :HKLM vmicrdv
### Service: Hyper-V Remote Desktop Virtualization Service Status: Start Type:
loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Provides a
platform for communication between the virtual machine and the operating system
running on the physical computer. Host Process for Windows Services Microsoft
Corporation Microsoft Windows Operating System 6.3.9600.16384 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K ICSERVICE
[Auto Services] :HKLM vmicshutdown
### Service: Hyper-V Guest Shutdown Service Status: Start Type: loaded manually
on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Provides a mechanism to
shut down the operating system of this virtual machine from the management
interfaces on the physical computer. Host Process for Windows Services Microsoft
Corporation Microsoft Windows Operating System 6.3.9600.16384 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED
[Auto Services] :HKLM vmictimesync
### Service: Hyper-V Time Synchronization Service Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Synchronizes the
system time of this virtual machine with the system time of the physical computer.
Host Process for Windows Services Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
LOCALSERVICENETWORKRESTRICTED
[Auto Services] :HKLM vmicvss
### Service: Hyper-V Volume Shadow Copy Requestor Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Coordinates the
communications that are required to use Volume Shadow Copy Service to back up
applications and data on this virtual machine from the operating system on the
physical computer. Host Process for Windows Services Microsoft Corporation
Microsoft Windows Operating System 6.3.9600.16384 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED
[Auto Services] :HKLM VSS
### Service: Volume Shadow Copy Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\VSSVC.EXE * Manages and implements Volume Shadow
Copies used for backup and other purposes. If this service is stopped, shadow
copies will be unavailable for backup and the backup may fail. If this service is
disabled, any services that explicitly depend on it will fail to start. Microsoft
Volume Shadow Copy Service Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*%SYSTEMROOT%\SYSTEM32\VSSVC.EXE
[Auto Services] :HKLM W32Time
### Service: Windows Time Status: Start Type: loaded manually on demand Actual
File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Maintains date and time synchronization on
all clients and servers in the network. If this service is stopped, date and time
synchronization will be unavailable. If this service is disabled, any services that
explicitly depend on it will fail to start. Host Process for Windows Services
Microsoft Corporation Microsoft Windows Operating System 6.3.9600.16384 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE
[Auto Services] :HKLM wbengine
### Service: Block Level Backup Engine Service Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\WBENGINE.EXE * The WBENGINE
service is used by Windows Backup to perform backup and recovery operations. If
this service is stopped by a user, it may cause the currently running backup or
recovery operation to fail. Disabling this service may disable backup and recovery
operations using Windows Backup on this computer. Microsoft Block Level Backup
Engine Service EXE Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*"%SYSTEMROOT%\SYSTEM32\WBENGINE.EXE"
[Auto Services] :HKLM WbioSrvc
### Service: Windows Biometric Service Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * The Windows biometric service
gives client applications the ability to capture, compare, manipulate, and store
biometric data without gaining direct access to any biometric hardware or samples.
The service is hosted in a privileged SVCHOST process. Host Process for Windows
Services Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K WBIOSVCGROUP
[Auto Services] :HKLM Wcmsvc
### Service: Windows Connection Manager Status: Start Type: loaded automatically
by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Makes automatic
connect/disconnect decisions based on the network connectivity options currently
available to the PC and enables management of network connectivity based on Group
Policy settings. Host Process for Windows Services Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
LOCALSERVICENETWORKRESTRICTED
[Auto Services] :HKLM wcncsvc
### Service: Windows Connect Now - Config Registrar Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * WCNCSVC hosts the
Windows Connect Now Configuration which is Microsoft's Implementation of Wi-Fi
Protected Setup (WPS) protocol. This is used to configure Wireless LAN settings for
an Access Point (AP) or a Wi-Fi Device. The service is started programmatically as
needed. Host Process for Windows Services Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
LOCALSERVICEANDNOIMPERSONATION
[Auto Services] :HKLM WcsPlugInService
### Service: Windows Color System Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * The WcsPlugInService service hosts
third-party Windows Color System color device model and gamut map model plug-in
modules. These plug-in modules are vendor-specific extensions to the Windows Color
System baseline color device and gamut map models. Stopping or disabling the
WcsPlugInService service will disable this extensibility feature, and the Windows
Color System will use its baseline model processing rather than the vendor's
desired processing. This might result in inaccurate color rendering. Host Process
for Windows Services Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K WCSSVC
[Auto Services] :HKLM WdiServiceHost
### Service: Diagnostic Service Host Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * The Diagnostic Service Host
is used by the Diagnostic Policy Service to host diagnostics that need to run in a
Local Service context. If this service is stopped, any diagnostics that depend on
it will no longer function. Host Process for Windows Services Microsoft Corporation
Microsoft Windows Operating System 6.3.9600.16384 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE
[Auto Services] :HKLM WdiSystemHost
### Service: Diagnostic System Host Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * The Diagnostic System Host is used
by the Diagnostic Policy Service to host diagnostics that need to run in a Local
System context. If this service is stopped, any diagnostics that depend on it will
no longer function. Host Process for Windows Services Microsoft Corporation
Microsoft Windows Operating System 6.3.9600.16384 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED
[Auto Services] :HKLM WdNisSvc
### Service: Windows Defender Network Inspection Service Status: Start Type:
loaded manually on demand Actual File: C:\PROGRAM FILES\WINDOWS DEFENDER\NISSRV.EXE
* Helps guard against intrusion attempts targeting known and newly discovered
vulnerabilities in network protocols Microsoft Network Realtime Inspection Service
Microsoft Corporation Microsoft Windows Operating System 4.3.9600.16384 !
$*"%PROGRAMFILES%\WINDOWS DEFENDER\NISSRV.EXE"
[Auto Services] :HKLM WebClient
### Service: WebClient Status: Start Type: loaded manually on demand Actual File:
C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Enables Windows-based programs to create, access,
and modify Internet-based files. If this service is stopped, these functions will
not be available. If this service is disabled, any services that explicitly depend
on it will fail to start. Host Process for Windows Services Microsoft Corporation
Microsoft Windows Operating System 6.3.9600.16384 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE
[Auto Services] :HKLM Wecsvc
### Service: Windows Event Collector Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * This service manages
persistent subscriptions to events from remote sources that support WS-Management
protocol. This includes Windows Vista event logs, hardware and IPMI-enabled event
sources. The service stores forwarded events in a local Event Log. If this service
is stopped or disabled event subscriptions cannot be created and forwarded events
cannot be accepted. Host Process for Windows Services Microsoft Corporation
Microsoft Windows Operating System 6.3.9600.16384 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K NETWORKSERVICE
[Auto Services] :HKLM WEPHOSTSVC
### Service: Windows Encryption Provider Host Service Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Windows
Encryption Provider Host Service brokers encryption related functionalities from
3rd Party Encryption Providers to processes that need to evaluate and apply EAS
policies. Stopping this will compromise EAS compliancy checks that have been
established by the connected Mail Accounts Host Process for Windows Services
Microsoft Corporation Microsoft Windows Operating System 6.3.9600.16384 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K WEPHOSTSVCGROUP
[Auto Services] :HKLM wercplsupport
### Service: Problem Reports and Solutions Control Panel Support Status: Start
Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * This
service provides support for viewing, sending and deletion of system-level problem
reports for the Problem Reports and Solutions control panel. Host Process for
Windows Services Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS
[Auto Services] :HKLM WerSvc
### Service: Windows Error Reporting Service Status: Start Type: loaded manually
on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Allows errors to be
reported when programs stop working or responding and allows existing solutions to
be delivered. Also allows logs to be generated for diagnostic and repair services.
If this service is stopped, error reporting might not work correctly and results of
diagnostic services and repairs might not be displayed. Host Process for Windows
Services Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K WERSVCGROUP
[Auto Services] :HKLM WiaRpc
### Service: Still Image Acquisition Events Status: Start Type: loaded manually
on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Launches applications
associated with still image acquisition events. Host Process for Windows Services
Microsoft Corporation Microsoft Windows Operating System 6.3.9600.16384 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED
[Auto Services] :HKLM WinDefend
### Service: Windows Defender Service Status: Start Type: loaded automatically by
Server Manager Actual File: C:\PROGRAM FILES\WINDOWS DEFENDER\MSMPENG.EXE * Helps
protect users from malware and other potentially unwanted software Antimalware
Service Executable Microsoft Corporation Microsoft Windows Operating System
4.3.9600.16384 !$*"%PROGRAMFILES%\WINDOWS DEFENDER\MSMPENG.EXE"
[Auto Services] :HKLM WinHttpAutoProxySvc
### Service: WinHTTP Web Proxy Auto-Discovery Service Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * WinHTTP
implements the client HTTP stack and provides developers with a Win32 API and COM
Automation component for sending HTTP requests and receiving responses. In
addition, WinHTTP provides support for auto-discovering a proxy configuration via
its implementation of the Web Proxy Auto-Discovery (WPAD) protocol. Host Process
for Windows Services Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE
[Auto Services] :HKLM Winmgmt
### Service: Windows Management Instrumentation Status: Start Type: loaded
automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE *
Provides a common interface and object model to access management information about
operating system, devices, applications and services. If this service is stopped,
most Windows-based software will not function properly. If this service is
disabled, any services that explicitly depend on it will fail to start. Host
Process for Windows Services Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS
[Auto Services] :HKLM WinRM
### Service: Windows Remote Management (WS-Management) Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Windows Remote
Management (WinRM) service implements the WS-Management protocol for remote
management. WS-Management is a standard web services protocol used for remote
software and hardware management. The WinRM service listens on the network for WS-
Management requests and processes them. The WinRM Service needs to be configured
with a listener using winrm.cmd command line tool or through Group Policy in order
for it to listen over the network. The WinRM service provides access to WMI data
and enables event collection. Event collection and subscription to events require
that the service is running. WinRM messages use HTTP and HTTPS as transports. The
WinRM service does not depend on IIS but is preconfigured to share a port with IIS
on the same machine. The WinRM service reserves the /wsman URL prefix. To prevent
conflicts with IIS, administrators should ensure that any websites hosted on IIS do
not use the /wsman URL prefix. Host Process for Windows Services Microsoft
Corporation Microsoft Windows Operating System 6.3.9600.16384 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K NETWORKSERVICE
[Auto Services] :HKLM WlanSvc
### Service: WLAN AutoConfig Status: Start Type: loaded automatically by Server
Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * The WLANSVC service provides
the logic required to configure, discover, connect to, and disconnect from a
wireless local area network (WLAN) as defined by IEEE 802.11 standards. It also
contains the logic to turn your computer into a software access point so that other
devices or computers can connect to your computer wirelessly using a WLAN adapter
that can support this. Stopping or disabling the WLANSVC service will make all WLAN
adapters on your computer inaccessible from the Windows networking UI. It is
strongly recommended that you have the WLANSVC service running if your computer has
a WLAN adapter. Host Process for Windows Services Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
LOCALSYSTEMNETWORKRESTRICTED
[Auto Services] :HKLM wlidsvc
### Service: Microsoft Account Sign-in Assistant Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Enables user
sign-in through Microsoft account identity services. If this service is stopped,
users will not be able to logon to the computer with their Microsoft account. Host
Process for Windows Services Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS
[Auto Services] :HKLM wmiApSrv
### Service: WMI Performance Adapter Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\WBEM\WMIAPSRV.EXE * Provides performance
library information from Windows Management Instrumentation (WMI) providers to
clients on the network. This service only runs when Performance Data Helper is
activated. WMI Performance Reverse Adapter Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 !$*%SYSTEMROOT%\SYSTEM32\WBEM\WMIAPSRV.EXE
[Auto Services] :HKLM WMPNetworkSvc
### Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 Status: Start
Type: loaded manually on demand Actual File: C:\PROGRAM FILES\WINDOWS MEDIA
PLAYER\WMPNETWK.EXE * @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-102
Windows Media Player Network Sharing Service Microsoft Corporation Microsoft
Windows Operating System 12.0.9600.16384 !$*"%PROGRAMFILES%\WINDOWS MEDIA
PLAYER\WMPNETWK.EXE"
[Auto Services] :HKLM workfolderssvc
### Service: Work Folders Status: Start Type: loaded manually on demand Actual
File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * This service syncs files with the Work
Folders server, enabling you to use the files on any of the PCs and devices on
which you've set up Work Folders. Host Process for Windows Services Microsoft
Corporation Microsoft Windows Operating System 6.3.9600.16384 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE
[Auto Services] :HKLM WPCSvc
### Service: Family Safety Status: Start Type: loaded manually on demand Actual
File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * This service is a stub for Windows Parental
Control functionality that existed in Vista. It is provided for backward
compatibility only. Host Process for Windows Services Microsoft Corporation
Microsoft Windows Operating System 6.3.9600.16384 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICENETWORKRESTRICTED
[Auto Services] :HKLM WPDBusEnum
### Service: Portable Device Enumerator Service Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Enforces group
policy for removable mass-storage devices. Enables applications such as Windows
Media Player and Image Import Wizard to transfer and synchronize content using
removable mass-storage devices. Host Process for Windows Services Microsoft
Corporation Microsoft Windows Operating System 6.3.9600.16384 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED
[Auto Services] :HKLM wpscloudsvr
### Service: WPS Office Cloud Service Status: Start Type: loaded manually on
demand Actual File: C:\PROGRAM FILES (X86)\KINGSOFT\KINGSOFT OFFICE\WPSCLOUDSVR.EXE
* WPS Cloud Service WPS service program for service such as login and Cloud storage
Zhuhai Kingsoft Office Software Co.,Ltd WPS Office 10,2,0,5811 !$*"C:\PROGRAM FILES
(X86)\KINGSOFT\KINGSOFT OFFICE\WPSCLOUDSVR.EXE" LOCALSERVICE
[Auto Services] :HKLM wscsvc
### Service: Security Center Status: Start Type: loaded automatically by Server
Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * The WSCSVC (Windows Security
Center) service monitors and reports security health settings on the computer. The
health settings include firewall (on/off), antivirus (on/off/out of date),
antispyware (on/off/out of date), Windows Update (automatically/manually download
and install updates), User Account Control (on/off), and Internet settings
(recommended/not recommended). The service provides COM APIs for independent
software vendors to register and record the state of their products to the Security
Center service. The Action Center (AC) UI uses the service to provide systray
alerts and a graphical view of the security health states in the AC control panel.
Network Access Protection (NAP) uses the service to report the security health
states of clients to the NAP Network Policy Server to make network quarantine
decisions. The service also has a public API that allows external consumers to
programmatically retrieve the aggregated security health state of the system. Host
Process for Windows Services Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
LOCALSERVICENETWORKRESTRICTED
[Auto Services] :HKLM WSearch
### Service: Windows Search Status: Start Type: loaded automatically by Server
Manager Actual File: C:\WINDOWS\SYSTEM32\SEARCHINDEXER.EXE * Provides content
indexing, property caching, and search results for files, e-mail, and other
content. Microsoft Windows Search Indexer Microsoft Corporation Windows Search
7.00.9600.16384 !$*%SYSTEMROOT%\SYSTEM32\SEARCHINDEXER.EXE /EMBEDDING
[Auto Services] :HKLM WSService
### Service: Windows Store Service (WSService) Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Provides
infrastructure support for Windows Store.This service is started on demand and if
disabled applications bought using Windows Store will not behave correctly. Host
Process for Windows Services Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K WSAPPX
[Auto Services] :HKLM wuauserv
### Service: Windows Update Status: Start Type: loaded manually on demand Actual
File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Enables the detection, download, and
installation of updates for Windows and other programs. If this service is
disabled, users of this computer will not be able to use Windows Update or its
automatic updating feature, and programs will not be able to use the Windows Update
Agent (WUA) API. Host Process for Windows Services Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
NETSVCS
[Auto Services] :HKLM wudfsvc
### Service: Windows Driver Foundation - User-mode Driver Framework Status: Start
Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE *
Creates and manages user-mode driver processes. This service cannot be stopped.
Host Process for Windows Services Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
LOCALSYSTEMNETWORKRESTRICTED
[Auto Services] :HKLM WwanSvc
### Service: WWAN AutoConfig Status: Start Type: loaded manually on demand Actual
File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * This service manages mobile broadband (GSM
& CDMA) data card/embedded module adapters and connections by auto-configuring the
networks. It is strongly recommended that this service be kept running for best
user experience of mobile broadband devices. Host Process for Windows Services
Microsoft Corporation Microsoft Windows Operating System 6.3.9600.16384 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICENONETWORK
[Auto Services] :HKLM ZAtheros Bt and Wlan Coex Agent
### Service: ZAtheros Bt and Wlan Coex Agent Status: Start Type: loaded
automatically by Server Manager Actual File: C:\PROGRAM FILES (X86)\BLUETOOTH
SUITE\ATH_COEXAGENT.EXE * Co-existence Coordinator Service between 11a/b/g/n
Wireless LAN and Bluetooth. Atheros Coex Service Application Atheros Ath_Coex
Application 8.0.0.270
[Svchost DLLs] :HKLM CertPropSvc=C:\WINDOWS\SYSTEM32\CERTPROP.DLL
### Microsoft Smartcard Certificate Propagation Service Microsoft Corporation
Microsoft Windows Operating System 6.3.9600.16384 !$*%SystemRoot
%\System32\certprop.dll
[Svchost DLLs] :HKLM SCPolicySvc=C:\WINDOWS\SYSTEM32\CERTPROP.DLL
### Microsoft Smartcard Certificate Propagation Service Microsoft Corporation
Microsoft Windows Operating System 6.3.9600.16384 !$*%SystemRoot
%\System32\certprop.dll
[Svchost DLLs] :HKLM lanmanserver=C:\WINDOWS\SYSTEM32\SRVSVC.DLL
### Server Service DLL Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*%SystemRoot%\system32\srvsvc.dll
[Svchost DLLs] :HKLM gpsvc=C:\WINDOWS\SYSTEM32\GPSVC.DLL
### Group Policy Client Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*%SystemRoot%\System32\gpsvc.dll
[Svchost DLLs] :HKLM iphlpsvc=C:\WINDOWS\SYSTEM32\IPHLPSVC.DLL
### Service that offers IPv6 connectivity over an IPv4 network. Microsoft
Corporation Microsoft Windows Operating System 6.3.9600.16384 !$*%SystemRoot
%\System32\iphlpsvc.dll
[Svchost DLLs] :HKLM msiscsi=C:\WINDOWS\SYSTEM32\ISCSIEXE.DLL
### iSCSI Discovery service Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*%systemroot%\system32\iscsiexe.dll
[Svchost DLLs] :HKLM schedule=C:\WINDOWS\SYSTEM32\SCHEDSVC.DLL
### Task Scheduler Service Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*%systemroot%\system32\schedsvc.dll
[Svchost DLLs] :HKLM winmgmt=C:\WINDOWS\SYSTEM32\WBEM\WMISVC.DLL
### WMI Microsoft Corporation Microsoft Windows Operating System 6.3.9600.16384
!$*%SystemRoot%\system32\wbem\WMIsvc.dll
[Svchost DLLs] :HKLM SessionEnv=C:\WINDOWS\SYSTEM32\SESSENV.DLL
### Remote Desktop Configuration service Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 !$*%SystemRoot%\system32\sessenv.dll
[Svchost DLLs] :HKLM FastUserSwitchingCompatibility
[Svchost DLLs] :HKLM Ias
[Svchost DLLs] :HKLM Irmon
[Svchost DLLs] :HKLM Nla
[Svchost DLLs] :HKLM Ntmssvc
[Svchost DLLs] :HKLM NWCWorkstation
[Svchost DLLs] :HKLM Nwsapagent
[Svchost DLLs] :HKLM Rasauto=C:\WINDOWS\SYSTEM32\RASAUTO.DLL
### Remote Access AutoDial Manager Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%SystemRoot%\System32\rasauto.dll
[Svchost DLLs] :HKLM Rasman=C:\WINDOWS\SYSTEM32\RASMANS.DLL
### Remote Access Connection Manager Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%SystemRoot%\System32\rasmans.dll
[Svchost DLLs] :HKLM Remoteaccess=C:\WINDOWS\SYSTEM32\MPRDIM.DLL
### Dynamic Interface Manager Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*%SystemRoot%\System32\mprdim.dll
[Svchost DLLs] :HKLM SENS=C:\WINDOWS\SYSTEM32\SENS.DLL
### System Event Notification Service (SENS) Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 !$*%SystemRoot%\System32\sens.dll
[Svchost DLLs] :HKLM Sharedaccess=C:\WINDOWS\SYSTEM32\IPNATHLP.DLL
### Microsoft NAT Helper Components Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%SystemRoot%\System32\ipnathlp.dll
[Svchost DLLs] :HKLM SRService
[Svchost DLLs] :HKLM Tapisrv=C:\WINDOWS\SYSTEM32\TAPISRV.DLL
### Microsoft Windows(TM) Telephony Server Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 !$*%SystemRoot%\System32\tapisrv.dll
[Svchost DLLs] :HKLM Wmi
[Svchost DLLs] :HKLM WmdmPmSp
[Svchost DLLs] :HKLM wuauserv=C:\WINDOWS\SYSTEM32\WUAUENG.DLL
### Windows Update Agent Microsoft Corporation Microsoft Windows Operating
System 7.9.9600.16384 !$*%systemroot%\system32\wuaueng.dll
[Svchost DLLs] :HKLM BITS=C:\WINDOWS\SYSTEM32\QMGR.DLL
### Background Intelligent Transfer Service Microsoft Corporation Microsoft
Windows Operating System 7.7.9600.16384 !$*%SystemRoot%\System32\qmgr.dll
[Svchost DLLs] :HKLM ShellHWDetection=C:\WINDOWS\SYSTEM32\SHSVCS.DLL
### Windows Shell Services Dll Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%SystemRoot%\System32\shsvcs.dll
[Svchost DLLs] :HKLM LogonHours
[Svchost DLLs] :HKLM PCAudit
[Svchost DLLs] :HKLM helpsvc
[Svchost DLLs] :HKLM uploadmgr
[Svchost DLLs] :HKLM AppMgmt=C:\WINDOWS\SYSTEM32\APPMGMTS.DLL
### Software installation Service Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%SystemRoot%\System32\appmgmts.dll
[Svchost DLLs] :HKLM ScDeviceEnum=C:\WINDOWS\SYSTEM32\SCDEVICEENUM.DLL
### Smart Card Device Enumeration Service Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 !$*%SystemRoot%\System32\ScDeviceEnum.dll
[Svchost DLLs] :HKLM WiaRpc=C:\WINDOWS\SYSTEM32\WIARPC.DLL
### Windows Image Acquisition RPC client DLL Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 !$*%SystemRoot%\System32\wiarpc.dll
[Svchost DLLs] :HKLM
AudioEndpointBuilder=C:\WINDOWS\SYSTEM32\AUDIOENDPOINTBUILDER.DLL
### Windows Audio Endpoint Builder Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%SystemRoot%\System32\AudioEndpointBuilder.dll
[Svchost DLLs] :HKLM dot3svc=C:\WINDOWS\SYSTEM32\DOT3SVC.DLL
### Wired AutoConfig Service Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*%SystemRoot%\System32\dot3svc.dll
[Svchost DLLs] :HKLM StorSvc=C:\WINDOWS\SYSTEM32\STORSVC.DLL
### Storage Services Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*%SystemRoot%\system32\storsvc.dll
[Svchost DLLs] :HKLM Netman=C:\WINDOWS\SYSTEM32\NETMAN.DLL
### Network Connections Manager Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%SystemRoot%\System32\netman.dll
[Svchost DLLs] :HKLM DeviceAssociationService=C:\WINDOWS\SYSTEM32\DAS.DLL
### Device Association Service Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%SystemRoot%\system32\das.dll
[Svchost DLLs] :HKLM WPDBusEnum=C:\WINDOWS\SYSTEM32\WPDBUSENUM.DLL
### Portable Device Enumerator Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%SystemRoot%\system32\wpdbusenum.dll
[Svchost DLLs] :HKLM wlansvc=C:\WINDOWS\SYSTEM32\WLANSVC.DLL
### Windows WLAN AutoConfig Service DLL Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%SystemRoot%\System32\wlansvc.dll
[Svchost DLLs] :HKLM WinHttpAutoProxySvc=C:\WINDOWS\SYSTEM32\WINHTTP.DLL
### Windows HTTP Services Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*%SystemRoot%\system32\winhttp.dll
[Svchost DLLs] :HKLM netprofm=C:\WINDOWS\SYSTEM32\NETPROFMSVC.DLL
### Network List Manager Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*%SystemRoot%\System32\netprofmsvc.dll
[Svchost DLLs] :HKLM RemoteRegistry=C:\WINDOWS\SYSTEM32\REGSVC.DLL
### Remote Registry Service Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*%SystemRoot%\system32\regsvc.dll
[Svchost DLLs] :HKLM WebClient=C:\WINDOWS\SYSTEM32\WEBCLNT.DLL
### Web DAV Service DLL Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*%SystemRoot%\System32\webclnt.dll
[Svchost DLLs] :HKLM StiSvc=C:\WINDOWS\SYSTEM32\WIASERVC.DLL
### Still Image Devices Service Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%SystemRoot%\System32\wiaservc.dll
[Svchost DLLs] :HKLM PLA=C:\WINDOWS\SYSTEM32\PLA.DLL
### Performance Logs & Alerts Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*%systemroot%\system32\pla.dll
[Svchost DLLs] :HKLM smphost=C:\WINDOWS\SYSTEM32\SMPHOST.DLL
### Storage Management Provider (SMP) host service Microsoft Corporation
Microsoft Windows Operating System 6.3.9600.16384 !$*%Systemroot
%\System32\smphost.dll
[Svchost DLLs] :HKLM RpcSs=C:\WINDOWS\SYSTEM32\RPCSS.DLL
### Distributed COM Services Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*%SystemRoot%\system32\rpcss.dll
[Svchost DLLs] :HKLM AudioSrv=C:\WINDOWS\SYSTEM32\AUDIOSRV.DLL
### Windows Audio Service Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*%SystemRoot%\System32\Audiosrv.dll
[Svchost DLLs] :HKLM wscsvc=C:\WINDOWS\SYSTEM32\WSCSVC.DLL
### Windows Security Center Service Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%SystemRoot%\System32\wscsvc.dll
[Svchost DLLs] :HKLM LmHosts=C:\WINDOWS\SYSTEM32\LMHSVC.DLL
### TCPIP NetBios Transport Services DLL Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 !$*%SystemRoot%\System32\lmhsvc.dll
[Svchost DLLs] :HKLM WPCSvc=C:\WINDOWS\SYSTEM32\WPCSVC.DLL
### WPC Filtering Service Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*%SystemRoot%\System32\wpcsvc.dll
[Svchost DLLs] :HKLM WcsPlugInService=C:\WINDOWS\SYSTEM32\WCSPLUGINSERVICE.DLL
### WcsPlugInService DLL Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*%SystemRoot%\System32\WcsPlugInService.dll
[Svchost DLLs] :HKLM SSDPSRV=C:\WINDOWS\SYSTEM32\SSDPSRV.DLL
### SSDP Service DLL Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*%SystemRoot%\System32\ssdpsrv.dll
[Svchost DLLs] :HKLM upnphost=C:\WINDOWS\SYSTEM32\UPNPHOST.DLL
### UPnP Device Host Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*%SystemRoot%\System32\upnphost.dll
[Svchost DLLs] :HKLM SCardSvr=C:\WINDOWS\SYSTEM32\SCARDSVR.DLL
### Smart Card Resource Management Server Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 !$*%SystemRoot%\System32\SCardSvr.dll
[Svchost DLLs] :HKLM BthHFSrv
[Svchost DLLs] :HKLM QWAVE=C:\WINDOWS\SYSTEM32\QWAVE.DLL
### Windows NT Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*%windir%\system32\qwave.dll
[Svchost DLLs] :HKLM wcncsvc=C:\WINDOWS\SYSTEM32\WCNCSVC.DLL
### Windows Connect Now - Config Registrar Service Microsoft Corporation
Microsoft Windows Operating System 6.3.9600.16384 !$*%SystemRoot
%\System32\wcncsvc.dll
[Svchost DLLs] :HKLM PlugPlay=C:\WINDOWS\SYSTEM32\UMPNPMGR.DLL
### User-mode Plug-and-Play Service Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%SystemRoot%\system32\umpnpmgr.dll
[Svchost DLLs] :HKLM DcomLaunch=C:\WINDOWS\SYSTEM32\RPCSS.DLL
### Distributed COM Services Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*%SystemRoot%\system32\rpcss.dll
[Svchost DLLs] :HKLM DeviceInstall=C:\WINDOWS\SYSTEM32\UMPNPMGR.DLL
### User-mode Plug-and-Play Service Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%SystemRoot%\system32\umpnpmgr.dll
[Svchost DLLs] :HKLM CryptSvc=C:\WINDOWS\SYSTEM32\CRYPTSVC.DLL
### Cryptographic Services Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*%SystemRoot%\system32\cryptsvc.dll
[Svchost DLLs] :HKLM NapAgent=C:\WINDOWS\SYSTEM32\QAGENTRT.DLL
### Quarantine Agent Service Run-Time Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%SystemRoot%\system32\qagentRT.dll
[Svchost DLLs] :HKLM WinRM=C:\WINDOWS\SYSTEM32\WSMSVC.DLL
### WSMan Service Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*%SystemRoot%\system32\WsmSvc.dll
[Svchost DLLs] :HKLM WECSVC=C:\WINDOWS\SYSTEM32\WECSVC.DLL
### Event Collector Service Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*%SystemRoot%\system32\wecsvc.dll
[Svchost DLLs] :HKLM DHCP=C:\WINDOWS\SYSTEM32\DHCPCORE.DLL
### DHCP Client Service Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*%SystemRoot%\system32\dhcpcore.dll
[Svchost DLLs] :HKLM TermService=C:\WINDOWS\SYSTEM32\TERMSRV.DLL
### Remote Desktop Session Host Server Remote Connections Manager Microsoft
Corporation Microsoft Windows Operating System 6.3.9600.16384 !$*%SystemRoot
%\System32\termsrv.dll
[Svchost DLLs] :HKLM DNSCache=C:\WINDOWS\SYSTEM32\DNSRSLVR.DLL
### DNS Caching Resolver Service Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%SystemRoot%\System32\dnsrslvr.dll
[Svchost DLLs] :HKLM AeLookupSvc=C:\WINDOWS\SYSTEM32\AELUPSVC.DLL
### Application Experience Service Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%SystemRoot%\System32\aelupsvc.dll
[Svchost DLLs] :HKLM AppIDSvc=C:\WINDOWS\SYSTEM32\APPIDSVC.DLL
### Application Identity Service Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%SystemRoot%\System32\appidsvc.dll
[Svchost DLLs] :HKLM Appinfo=C:\WINDOWS\SYSTEM32\APPINFO.DLL
### Application Information Service Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%SystemRoot%\System32\appinfo.dll
[Svchost DLLs] :HKLM AppReadiness=C:\WINDOWS\SYSTEM32\APPREADINESS.DLL
### AppReadiness Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*%SystemRoot%\system32\AppReadiness.dll
[Svchost DLLs] :HKLM AxInstSV=C:\WINDOWS\SYSTEM32\AXINSTSV.DLL
### ActiveX Installer Service Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*%SystemRoot%\System32\AxInstSV.dll
[Svchost DLLs] :HKLM BDESVC=C:\WINDOWS\SYSTEM32\BDESVC.DLL
### BDE Service Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*%SystemRoot%\System32\bdesvc.dll
[Svchost DLLs] :HKLM BFE=C:\WINDOWS\SYSTEM32\BFE.DLL
### Base Filtering Engine Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*%SystemRoot%\System32\bfe.dll
[Svchost DLLs] :HKLM BrokerInfrastructure=C:\WINDOWS\SYSTEM32\BISRV.DLL
### Background Tasks Infrastructure Service Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 !$*%SystemRoot%\System32\bisrv.dll
[Svchost DLLs] :HKLM Browser=C:\WINDOWS\SYSTEM32\BROWSER.DLL
### Computer Browser Service DLL Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%SystemRoot%\System32\browser.dll
[Svchost DLLs] :HKLM bthserv=C:\WINDOWS\SYSTEM32\BTHSERV.DLL
### Bluetooth Support Service Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*%SystemRoot%\system32\bthserv.dll
[Svchost DLLs] :HKLM CscService=C:\WINDOWS\SYSTEM32\CSCSVC.DLL
### CSC Service DLL Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*%SystemRoot%\System32\cscsvc.dll
[Svchost DLLs] :HKLM defragsvc=C:\WINDOWS\SYSTEM32\DEFRAGSVC.DLL
### Microsoft\Drive Optimizer Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*%Systemroot%\System32\defragsvc.dll
[Svchost DLLs] :HKLM DPS=C:\WINDOWS\SYSTEM32\DPS.DLL
### WDI Diagnostic Policy Service Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%SystemRoot%\system32\dps.dll
[Svchost DLLs] :HKLM DsmSvc=C:\WINDOWS\SYSTEM32\DEVICESETUPMANAGER.DLL
### Device Setup Manager Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*%SystemRoot%\System32\DeviceSetupManager.dll
[Svchost DLLs] :HKLM Eaphost=C:\WINDOWS\SYSTEM32\EAPSVC.DLL
### Microsoft EAPHost service Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*%SystemRoot%\System32\eapsvc.dll
[Svchost DLLs] :HKLM EFS=C:\WINDOWS\SYSTEM32\EFSSVC.DLL
### EFS Service Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*%SystemRoot%\system32\efssvc.dll
[Svchost DLLs] :HKLM EventSystem=C:\WINDOWS\SYSTEM32\ES.DLL
### COM+ Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*%systemroot%\system32\es.dll
[Svchost DLLs] :HKLM fdPHost=C:\WINDOWS\SYSTEM32\FDPHOST.DLL
### Function Discovery Provider host service Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 !$*%SystemRoot%\system32\fdPHost.dll
[Svchost DLLs] :HKLM FDResPub=C:\WINDOWS\SYSTEM32\FDRESPUB.DLL
### Function Discovery Resource Publication Service Microsoft Corporation
Microsoft Windows Operating System 6.3.9600.16384 !$*%SystemRoot
%\system32\fdrespub.dll
[Svchost DLLs] :HKLM fhsvc=C:\WINDOWS\SYSTEM32\FHSVC.DLL
### File History Service Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*%SystemRoot%\system32\fhsvc.dll
[Svchost DLLs] :HKLM FontCache=C:\WINDOWS\SYSTEM32\FNTCACHE.DLL
### Windows Font Cache Service Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%SystemRoot%\system32\FntCache.dll
[Svchost DLLs] :HKLM hidserv=C:\WINDOWS\SYSTEM32\HIDSERV.DLL
### Human Interface Device Service Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%SystemRoot%\system32\hidserv.dll
[Svchost DLLs] :HKLM hkmsvc=C:\WINDOWS\SYSTEM32\KMSVC.DLL
### Key Management Service Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*%SystemRoot%\system32\kmsvc.dll
[Svchost DLLs] :HKLM HomeGroupListener=C:\WINDOWS\SYSTEM32\LISTSVC.DLL
### Windows HomeGroup Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*%SystemRoot%\system32\ListSvc.dll
[Svchost DLLs] :HKLM HomeGroupProvider=C:\WINDOWS\SYSTEM32\PROVSVC.DLL
### Windows HomeGroup Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*%SystemRoot%\system32\provsvc.dll
[Svchost DLLs] :HKLM IKEEXT=C:\WINDOWS\SYSTEM32\IKEEXT.DLL
### IKE extension Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*%SystemRoot%\System32\ikeext.dll
[Svchost DLLs] :HKLM KeyIso=C:\WINDOWS\SYSTEM32\KEYISO.DLL
### CNG Key Isolation Service Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*%SystemRoot%\system32\keyiso.dll
[Svchost DLLs] :HKLM KtmRm=C:\WINDOWS\SYSTEM32\MSDTCKRM.DLL
### Microsoft Distributed Transaction Coordinator OLE Transactions KTM Resource
Manager DLL Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*%systemroot%\system32\msdtckrm.dll
[Svchost DLLs] :HKLM LanmanWorkstation=C:\WINDOWS\SYSTEM32\WKSSVC.DLL
### Workstation Service DLL Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*%SystemRoot%\System32\wkssvc.dll
[Svchost DLLs] :HKLM lfsvc=C:\WINDOWS\SYSTEM32\GEOFENCEMONITORSERVICE.DLL
### Windows Location Framework Service Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%SystemRoot%\System32\GeofenceMonitorService.dll
[Svchost DLLs] :HKLM lltdsvc=C:\WINDOWS\SYSTEM32\LLTDSVC.DLL
### Link-Layer Topology Mapper Service Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%SystemRoot%\System32\lltdsvc.dll
[Svchost DLLs] :HKLM LSM=C:\WINDOWS\SYSTEM32\LSM.DLL
### Local Session Manager Service Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%SystemRoot%\System32\lsm.dll
[Svchost DLLs] :HKLM MMCSS=C:\WINDOWS\SYSTEM32\MMCSS.DLL
### Multimedia Class Scheduler Service Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%SystemRoot%\system32\mmcss.dll
[Svchost DLLs] :HKLM MpsSvc=C:\WINDOWS\SYSTEM32\MPSSVC.DLL
### Microsoft Protection Service Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%SystemRoot%\system32\mpssvc.dll
[Svchost DLLs] :HKLM MsKeyboardFilter=C:\WINDOWS\SYSTEM32\KEYBOARDFILTERSVC.DLL
### SvcHost Service for Microsoft Keyboard Filter Microsoft Corporation
Microsoft Windows Operating System 6.3.9600.16384 !$*%SystemRoot
%\System32\KeyboardFilterSvc.dll
[Svchost DLLs] :HKLM NcaSvc=C:\WINDOWS\SYSTEM32\NCASVC.DLL
### Microsoft Network Connectivity Assistant Service Microsoft Corporation
Microsoft Windows Operating System 6.3.9600.16384 !$*%SystemRoot
%\System32\ncasvc.dll
[Svchost DLLs] :HKLM NcbService=C:\WINDOWS\SYSTEM32\NCBSERVICE.DLL
### Network Connection Broker Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*%SystemRoot%\System32\ncbservice.dll
[Svchost DLLs] :HKLM NcdAutoSetup=C:\WINDOWS\SYSTEM32\NCDAUTOSETUP.DLL
### Network Connected Devices Auto-Setup service DLL Microsoft Corporation
Microsoft Windows Operating System 6.3.9600.16384 !$*%SystemRoot
%\System32\NcdAutoSetup.dll
[Svchost DLLs] :HKLM Netlogon=C:\WINDOWS\SYSTEM32\NETLOGON.DLL
### Net Logon Services DLL Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*%SystemRoot%\system32\netlogon.dll
[Svchost DLLs] :HKLM NlaSvc=C:\WINDOWS\SYSTEM32\NLASVC.DLL
### Network Location Awareness 2 Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%SystemRoot%\System32\nlasvc.dll
[Svchost DLLs] :HKLM nsi=C:\WINDOWS\SYSTEM32\NSISVC.DLL
### Network Store Interface RPC server Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%systemroot%\system32\nsisvc.dll
[Svchost DLLs] :HKLM p2pimsvc=C:\WINDOWS\SYSTEM32\PNRPSVC.DLL
### PNRP Service Dll Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*%SystemRoot%\system32\pnrpsvc.dll
[Svchost DLLs] :HKLM p2psvc=C:\WINDOWS\SYSTEM32\P2PSVC.DLL
### Peer-to-Peer Services Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*%SystemRoot%\system32\p2psvc.dll
[Svchost DLLs] :HKLM PcaSvc=C:\WINDOWS\SYSTEM32\PCASVC.DLL
### Program Compatibility Assistant Service Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 !$*%SystemRoot%\System32\pcasvc.dll
[Svchost DLLs] :HKLM PolicyAgent=C:\WINDOWS\SYSTEM32\IPSECSVC.DLL
### Windows IPsec SPD Server DLL Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%SystemRoot%\System32\ipsecsvc.dll
[Svchost DLLs] :HKLM Power=C:\WINDOWS\SYSTEM32\UMPO.DLL
### User-mode Power Service Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*%SystemRoot%\system32\umpo.dll
[Svchost DLLs] :HKLM
PrintNotify=C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\X64\3\PRINTCONFIG.DLL
### PrintConfig User Interface Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384
[Svchost DLLs] :HKLM ProfSvc=C:\WINDOWS\SYSTEM32\PROFSVC.DLL
### ProfSvc Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*%systemroot%\system32\profsvc.dll
[Svchost DLLs] :HKLM RpcEptMapper=C:\WINDOWS\SYSTEM32\RPCEPMAP.DLL
### RPC Endpoint Mapper Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*%SystemRoot%\System32\RpcEpMap.dll
[Svchost DLLs] :HKLM seclogon=C:\WINDOWS\SYSTEM32\SECLOGON.DLL
### Secondary Logon Service DLL Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%windir%\system32\seclogon.dll
[Svchost DLLs] :HKLM SensrSvc=C:\WINDOWS\SYSTEM32\SENSRSVC.DLL
### Microsoft Windows Sensor Monitoring Service Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 !$*%SystemRoot%\system32\sensrsvc.dll
[Svchost DLLs] :HKLM SstpSvc=C:\WINDOWS\SYSTEM32\SSTPSVC.DLL
### Provides the facility of using Secure Socket Tunneling Protocol (SSTP) to
connect to remote computers (using VPN). Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%SystemRoot%\system32\sstpsvc.dll
[Svchost DLLs] :HKLM svsvc=C:\WINDOWS\SYSTEM32\SVSVC.DLL
### Microsoft\Spot Verifier Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*%SystemRoot%\system32\svsvc.dll
[Svchost DLLs] :HKLM swprv=C:\WINDOWS\SYSTEM32\SWPRV.DLL
### Microsoft Volume Shadow Copy Service software provider Microsoft Corporation
Microsoft Windows Operating System 6.3.9600.16384 !$*%Systemroot
%\System32\swprv.dll
[Svchost DLLs] :HKLM SysMain=C:\WINDOWS\SYSTEM32\SYSMAIN.DLL
### Superfetch Service Host Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*%systemroot%\system32\sysmain.dll
[Svchost DLLs] :HKLM
SystemEventsBroker=C:\WINDOWS\SYSTEM32\SYSTEMEVENTSBROKERSERVER.DLL
### System Events Broker Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*%SystemRoot%\System32\SystemEventsBrokerServer.dll
[Svchost DLLs] :HKLM TabletInputService=C:\WINDOWS\SYSTEM32\TABSVC.DLL
### Microsoft Touch Keyboard and Handwriting Panel Service Microsoft Corporation
Microsoft Windows Operating System 6.3.9600.16384 !$*%SystemRoot
%\System32\TabSvc.dll
[Svchost DLLs] :HKLM Themes=C:\WINDOWS\SYSTEM32\THEMESERVICE.DLL
### Windows Shell Theme Service Dll Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%SystemRoot%\system32\themeservice.dll
[Svchost DLLs] :HKLM THREADORDER=C:\WINDOWS\SYSTEM32\MMCSS.DLL
### Multimedia Class Scheduler Service Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%SystemRoot%\system32\mmcss.dll
[Svchost DLLs] :HKLM TimeBroker=C:\WINDOWS\SYSTEM32\TIMEBROKERSERVER.DLL
### Time Event Broker Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*%SystemRoot%\System32\TimeBrokerServer.dll
[Svchost DLLs] :HKLM TrkWks=C:\WINDOWS\SYSTEM32\TRKWKS.DLL
### Distributed Link Tracking Client Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%SystemRoot%\System32\trkwks.dll
[Svchost DLLs] :HKLM UmRdpService=C:\WINDOWS\SYSTEM32\UMRDP.DLL
### Remote Desktop Services Device Redirector Service Microsoft Corporation
Microsoft Windows Operating System 6.3.9600.16384 !$*%SystemRoot
%\System32\umrdp.dll
[Svchost DLLs] :HKLM VaultSvc=C:\WINDOWS\SYSTEM32\VAULTSVC.DLL
### Credential Manager Service Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384
[Svchost DLLs] :HKLM vmicguestinterface=C:\WINDOWS\SYSTEM32\ICSVC.DLL
### Virtual Machine Integration Component Service Microsoft Corporation
Microsoft Windows Operating System 6.3.9600.16384 !$*%SystemRoot
%\System32\ICSvc.dll
[Svchost DLLs] :HKLM vmicheartbeat=C:\WINDOWS\SYSTEM32\ICSVC.DLL
### Virtual Machine Integration Component Service Microsoft Corporation
Microsoft Windows Operating System 6.3.9600.16384 !$*%SystemRoot
%\System32\ICSvc.dll
[Svchost DLLs] :HKLM vmickvpexchange=C:\WINDOWS\SYSTEM32\ICSVC.DLL
### Virtual Machine Integration Component Service Microsoft Corporation
Microsoft Windows Operating System 6.3.9600.16384 !$*%SystemRoot
%\System32\ICSvc.dll
[Svchost DLLs] :HKLM vmicrdv=C:\WINDOWS\SYSTEM32\ICSVC.DLL
### Virtual Machine Integration Component Service Microsoft Corporation
Microsoft Windows Operating System 6.3.9600.16384 !$*%SystemRoot
%\System32\ICSvc.dll
[Svchost DLLs] :HKLM vmicshutdown=C:\WINDOWS\SYSTEM32\ICSVC.DLL
### Virtual Machine Integration Component Service Microsoft Corporation
Microsoft Windows Operating System 6.3.9600.16384 !$*%SystemRoot
%\System32\ICSvc.dll
[Svchost DLLs] :HKLM vmictimesync=C:\WINDOWS\SYSTEM32\ICSVC.DLL
### Virtual Machine Integration Component Service Microsoft Corporation
Microsoft Windows Operating System 6.3.9600.16384 !$*%SystemRoot
%\System32\ICSvc.dll
[Svchost DLLs] :HKLM vmicvss=C:\WINDOWS\SYSTEM32\ICSVC.DLL
### Virtual Machine Integration Component Service Microsoft Corporation
Microsoft Windows Operating System 6.3.9600.16384 !$*%SystemRoot
%\System32\ICSvc.dll
[Svchost DLLs] :HKLM W32Time=C:\WINDOWS\SYSTEM32\W32TIME.DLL
### Windows Time Service Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*%systemroot%\system32\w32time.dll
[Svchost DLLs] :HKLM WbioSrvc=C:\WINDOWS\SYSTEM32\WBIOSRVC.DLL
### Windows Biometric Service Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*%SystemRoot%\System32\wbiosrvc.dll
[Svchost DLLs] :HKLM Wcmsvc=C:\WINDOWS\SYSTEM32\WCMSVC.DLL
### Windows Connection Manager Service DLL Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 !$*%SystemRoot%\System32\wcmsvc.dll
[Svchost DLLs] :HKLM WdiServiceHost=C:\WINDOWS\SYSTEM32\WDI.DLL
### Windows Diagnostic Infrastructure Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%SystemRoot%\system32\wdi.dll
[Svchost DLLs] :HKLM WdiSystemHost=C:\WINDOWS\SYSTEM32\WDI.DLL
### Windows Diagnostic Infrastructure Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%SystemRoot%\system32\wdi.dll
[Svchost DLLs] :HKLM WEPHOSTSVC=C:\WINDOWS\SYSTEM32\WEPHOSTSVC.DLL
### WEP Host Service Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*%systemroot%\system32\wephostsvc.dll
[Svchost DLLs] :HKLM wercplsupport=C:\WINDOWS\SYSTEM32\WERCPLSUPPORT.DLL
### Problem Reports and Solutions Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%SystemRoot%\System32\wercplsupport.dll
[Svchost DLLs] :HKLM WerSvc=C:\WINDOWS\SYSTEM32\WERSVC.DLL
### Windows Error Reporting Service Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%SystemRoot%\System32\WerSvc.dll
[Svchost DLLs] :HKLM wlidsvc=C:\WINDOWS\SYSTEM32\WLIDSVC.DLL
### Microsoft Account Service Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%SystemRoot%\system32\wlidsvc.dll
[Svchost DLLs] :HKLM workfolderssvc=C:\WINDOWS\SYSTEM32\WORKFOLDERSSVC.DLL
### Microsoft (C) Work Folders Service Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%systemroot%\system32\workfolderssvc.dll
[Svchost DLLs] :HKLM WSService=C:\WINDOWS\SYSTEM32\WSSERVICE.DLL
### Windows Store Service Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*%SystemRoot%\System32\WSService.dll
[Svchost DLLs] :HKLM wudfsvc=C:\WINDOWS\SYSTEM32\WUDFSVC.DLL
### Windows Driver Foundation - User-mode Driver Framework Service Microsoft
Corporation Microsoft Windows Operating System 6.3.9600.16384 !$*%SystemRoot
%\System32\WUDFSvc.dll
[Svchost DLLs] :HKLM WwanSvc=C:\WINDOWS\SYSTEM32\WWANSVC.DLL
### WWAN Auto Config Service Microsoft Corporation Microsoft Windows Operating
System 08.01.9600.16384 !$*%SystemRoot%\System32\wwansvc.dll
[Bootexecute] :HKLM BootExecute=autocheck autochk *
Partizan
[Winlogon System] :HKLM system=""
### File is missing.
[Winlogon System] :HKLM taskman=""
### File is missing.
[Winlogon System] :HKLM UIHost=""
### File is missing.
[Winlogon Autostart] :HKLM VmApplet=SystemPropertiesPerformance.exe /pagefile
[Winlogon Autostart] :HKLM AppSetup=""
[Environment - Path] :HKLM Path=C:\Program Files (x86)\NVIDIA
Corporation\PhysX\Common;C:\Program Files (x86)\Intel\iCLS Client\;C:\Program
Files\Intel\iCLS Client\;%SystemRoot%\system32;%SystemRoot%;%SystemRoot
%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;C:\Program
Files\Intel\Intel(R) Management Engine Components\DAL;C:\Program
Files\Intel\Intel(R) Management Engine Components\IPT;C:\Program Files
(x86)\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files
(x86)\Intel\Intel(R) Management Engine Components\IPT
[List of Injected DLLs] :HKLM AppInit_DLLs=""
[LSA Notification Packages] :HKLM scecli=C:\Windows\SYSTEM32\SCECLI.DLL
### scecli Windows Security Configuration Editor Client Engine Microsoft
Corporation Microsoft Windows Operating System 6.3.9600.16384 !$*scecli.dll
[Print Providers] :HKLM Internet Print Provider=C:\Windows\SYSTEM32\INETPP.DLL
### Display Name: HTTP Print Services * Internet Print Provider DLL Microsoft
Corporation Microsoft Windows Operating System 6.3.9600.16384 !$*inetpp.dll
[Print Providers] :HKLM LanMan Print Services=C:\Windows\SYSTEM32\WIN32SPL.DLL
### Display Name: LanMan Print Services * Client Side Rendering Print Provider
Microsoft Corporation Microsoft Windows Operating System 6.3.9600.16384 !
$*win32spl.dll
[Eventlog Application DLL] :HKLM .NET Runtime=C:\WINDOWS\SYSTEM32\MSCOREE.DLL
### Microsoft .NET Runtime Execution Engine Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384
[Eventlog Application DLL] :HKLM .NET Runtime Optimization
Service=C:\WINDOWS\SYSTEM32\MSCOREE.DLL
### Microsoft .NET Runtime Execution Engine Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384
[Eventlog Application DLL] :HKLM Application Error=C:\WINDOWS\SYSTEM32\WER.DLL
### Windows Error Reporting DLL Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%SystemRoot%\System32\wer.dll
[Eventlog Application DLL] :HKLM Application Hang=C:\WINDOWS\SYSTEM32\WERSVC.DLL
### Windows Error Reporting Service Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%SystemRoot%\System32\wersvc.dll
[Eventlog Application DLL] :HKLM Application
Management=C:\WINDOWS\SYSTEM32\APPMGMTS.DLL
### Software installation Service Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%SystemRoot%\System32\appmgmts.dll
[Eventlog Application DLL] :HKLM Application-Addon-Event-
Provider=C:\WINDOWS\SYSTEM32\IEFRAME.DLL
### Internet Browser Microsoft Corporation Internet Explorer 11.00.9600.16384 !$*
%SystemRoot%\system32\ieframe.dll
[Eventlog Application DLL] :HKLM ASP.NET
2.0.50727.0=C:\WINDOWS\MICROSOFT.NET\FRAMEWORK64\V2.0.50727\ASPNET_RC.DLL
### aspnet_rc.dll Microsoft Corporation Microsoft .NET Framework 2.0.50727.7905
[Eventlog Application DLL] :HKLM
BstHdAndroidSvc=C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V4.0.30319\EVENTLOGMESSAGES.DLL
### EventLogMessages.dll Microsoft Corporation Microsoft .NET Framework
4.0.30319.33440
[Eventlog Application DLL] :HKLM
BstHdLogRotatorSvc=C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V4.0.30319\EVENTLOGMESSAGES.D
LL
### EventLogMessages.dll Microsoft Corporation Microsoft .NET Framework
4.0.30319.33440
[Eventlog Application DLL] :HKLM
bstupdater=C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V4.0.30319\EVENTLOGMESSAGES.DLL
### EventLogMessages.dll Microsoft Corporation Microsoft .NET Framework
4.0.30319.33440
[Eventlog Application DLL] :HKLM CardSpace
4.0.0.0=C:\WINDOWS\MICROSOFT.NET\FRAMEWORK64\V4.0.30319\SERVICEMODELEVENTS.DLL
### ServiceModel related event descriptions Microsoft Corporation Microsoft .NET
Framework 4.0.30319.33440
[Eventlog Application DLL] :HKLM CardSpace
4.0.0.0=C:\Windows\System32\icardres.dll
### File is missing.
[Eventlog Application DLL] :HKLM Chkdsk=C:\WINDOWS\SYSTEM32\ULIB.DLL
### File Utilities Support DLL Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%SystemRoot%\System32\ulib.dll
[Eventlog Application DLL] :HKLM CxAudMsg=C:\WINDOWS\SYSTEM32\CXAUDMSG64.EXE
### Conexant Audio Message Service Conexant Systems Inc. Conexant Audio Message
Service 1.13.0.0
[Eventlog Application DLL] :HKLM Desktop Window
Manager=C:\WINDOWS\SYSTEM32\DWM.EXE
### Desktop Window Manager Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*%SystemRoot%\system32\dwm.exe
[Eventlog Application DLL] :HKLM DiskQuota=C:\WINDOWS\SYSTEM32\DSKQUOTA.DLL
### Windows Shell Disk Quota Support DLL Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 !$*%SystemRoot%\System32\dskquota.dll
[Eventlog Application DLL] :HKLM
DptfEvent=C:\WINDOWS\SYSTEM32\DPTFEVENTLOGMESSAGE.DLL
### Intel(R) Dynamic Platform and Thermal Framework Event Log Message DLL Intel
Corporation Intel(R) Dynamic Platform and Thermal Framework 7.1.0.2105
[Eventlog Application DLL] :HKLM Error Instrument=C:\WINDOWS\SYSTEM32\USER32.DLL
### Multi-User Windows USER API Client DLL Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 !$*%SystemRoot%\system32\user32.dll
[Eventlog Application DLL] :HKLM ESENT=C:\WINDOWS\SYSTEM32\ESENT.DLL
### Extensible Storage Engine for Microsoft(R) Windows(R) Microsoft Corporation
Microsoft Windows Operating System 6.3.9600.16384 !$*%systemroot
%\system32\esent.dll
[Eventlog Application DLL] :HKLM Folder
Redirection=C:\WINDOWS\SYSTEM32\FDEPLOY.DLL
### Folder Redirection Group Policy Extension Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 !$*%SystemRoot%\System32\fdeploy.dll
[Eventlog Application DLL] :HKLM Group Policy
Applications=C:\WINDOWS\SYSTEM32\GPPREFCL.DLL
### Group Policy Preference Client Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384
[Eventlog Application DLL] :HKLM Group Policy
Client=C:\WINDOWS\SYSTEM32\GPPREFCL.DLL
### Group Policy Preference Client Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384
[Eventlog Application DLL] :HKLM Group Policy Data
Sources=C:\WINDOWS\SYSTEM32\GPPREFCL.DLL
### Group Policy Preference Client Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384
[Eventlog Application DLL] :HKLM Group Policy Device
Settings=C:\WINDOWS\SYSTEM32\GPPREFCL.DLL
### Group Policy Preference Client Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384
[Eventlog Application DLL] :HKLM Group Policy Drive
Maps=C:\WINDOWS\SYSTEM32\GPPREFCL.DLL
### Group Policy Preference Client Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384
[Eventlog Application DLL] :HKLM Group Policy
Environment=C:\WINDOWS\SYSTEM32\GPPREFCL.DLL
### Group Policy Preference Client Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384
[Eventlog Application DLL] :HKLM Group Policy
Files=C:\WINDOWS\SYSTEM32\GPPREFCL.DLL
### Group Policy Preference Client Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384
[Eventlog Application DLL] :HKLM Group Policy Folder
Options=C:\WINDOWS\SYSTEM32\GPPREFCL.DLL
### Group Policy Preference Client Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384
[Eventlog Application DLL] :HKLM Group Policy
Folders=C:\WINDOWS\SYSTEM32\GPPREFCL.DLL
### Group Policy Preference Client Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384
[Eventlog Application DLL] :HKLM Group Policy Ini
Files=C:\WINDOWS\SYSTEM32\GPPREFCL.DLL
### Group Policy Preference Client Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384
[Eventlog Application DLL] :HKLM Group Policy Internet
Settings=C:\WINDOWS\SYSTEM32\GPPREFCL.DLL
### Group Policy Preference Client Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384
[Eventlog Application DLL] :HKLM Group Policy Local Users and
Groups=C:\WINDOWS\SYSTEM32\GPPREFCL.DLL
### Group Policy Preference Client Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384
[Eventlog Application DLL] :HKLM Group Policy Mail
Profiles=C:\WINDOWS\SYSTEM32\GPPREFCL.DLL
### Group Policy Preference Client Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384
[Eventlog Application DLL] :HKLM Group Policy Network
Options=C:\WINDOWS\SYSTEM32\GPPREFCL.DLL
### Group Policy Preference Client Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384
[Eventlog Application DLL] :HKLM Group Policy Network
Shares=C:\WINDOWS\SYSTEM32\GPPREFCL.DLL
### Group Policy Preference Client Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384
[Eventlog Application DLL] :HKLM Group Policy Power
Options=C:\WINDOWS\SYSTEM32\GPPREFCL.DLL
### Group Policy Preference Client Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384
[Eventlog Application DLL] :HKLM Group Policy
Printers=C:\WINDOWS\SYSTEM32\GPPREFCL.DLL
### Group Policy Preference Client Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384
[Eventlog Application DLL] :HKLM Group Policy Regional
Options=C:\WINDOWS\SYSTEM32\GPPREFCL.DLL
### Group Policy Preference Client Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384
[Eventlog Application DLL] :HKLM Group Policy
Registry=C:\WINDOWS\SYSTEM32\GPPREFCL.DLL
### Group Policy Preference Client Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384
[Eventlog Application DLL] :HKLM Group Policy Scheduled
Tasks=C:\WINDOWS\SYSTEM32\GPPREFCL.DLL
### Group Policy Preference Client Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384
[Eventlog Application DLL] :HKLM Group Policy
Services=C:\WINDOWS\SYSTEM32\GPPREFCL.DLL
### Group Policy Preference Client Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384
[Eventlog Application DLL] :HKLM Group Policy
Shortcuts=C:\WINDOWS\SYSTEM32\GPPREFCL.DLL
### Group Policy Preference Client Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384
[Eventlog Application DLL] :HKLM Group Policy Standard
Edition=C:\WINDOWS\SYSTEM32\GPPREFCL.DLL
### Group Policy Preference Client Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384
[Eventlog Application DLL] :HKLM Group Policy Start Menu
Settings=C:\WINDOWS\SYSTEM32\GPPREFCL.DLL
### Group Policy Preference Client Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384
[Eventlog Application DLL] :HKLM GroupPolicy=C:\WINDOWS\SYSTEM32\GPAPI.DLL
### Group Policy Client API Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*%SystemRoot%\System32\gpapi.dll
[Eventlog Application DLL] :HKLM Handwriting Recognition=%CommonProgramFiles
%\Microsoft Shared\Ink\IPSEventLogMsg.dll
### !$*%CommonProgramFiles%\Microsoft Shared\Ink\IPSEventLogMsg.dll File is
missing.
[Eventlog Application DLL] :HKLM Intel(R) Capability Licensing Service
Interface=C:\WINDOWS\SYSWOW64\IUSEVENTLOG.DLL
### !$*%SystemRoot%\System32\IusEventLog.dll
[Eventlog Application DLL] :HKLM IntelDalJhi=C:\PROGRAM FILES
(X86)\INTEL\INTEL(R) MANAGEMENT ENGINE COMPONENTS\DAL\JHI_SERVICE.EXE
### Intel(R) Dynamic Application Loader Host Interface Intel Corporation Intel(R)
Dynamic Application Loader Host Interface 9.5.12.1682
[Eventlog Application DLL] :HKLM Interactive Services
detection=C:\WINDOWS\SYSTEM32\UI0DETECT.EXE
### Interactive services detection Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%SystemRoot%\System32\UI0Detect.exe
[Eventlog Application DLL] :HKLM ipmiprv=C:\WINDOWS\SYSTEM32\WBEM\IPMIPRR.DLL
### IPMI Provider Resource Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*%windir%\system32\wbem\ipmiprr.dll
[Eventlog Application DLL] :HKLM LMS=C:\PROGRAM FILES (X86)\INTEL\INTEL(R)
MANAGEMENT ENGINE COMPONENTS\LMS\LMS.EXE
### Intel(R) Local Management Service Intel Corporation Intel(R) Management and
Security Application Local Management Service 9.5.10.1628
[Eventlog Application DLL] :HKLM
LocationNotifications=C:\WINDOWS\SYSTEM32\LOCATIONNOTIFICATIONS.EXE
### Location Activity Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*%SystemRoot%\System32\LocationNotifications.exe
[Eventlog Application DLL] :HKLM Microsoft Fax=C:\WINDOWS\SYSTEM32\FXSEVENT.DLL
### Microsoft Fax EventLog Support DLL Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384
[Eventlog Application DLL] :HKLM Microsoft WSE
3.0=C:\WINDOWS\MICROSOFT.NET\FRAMEWORK64\V2.0.50727\EVENTLOGMESSAGES.DLL
### EventLogMessages.dll Microsoft Corporation Microsoft .NET Framework
2.0.50727.7905
[Eventlog Application DLL] :HKLM Microsoft-Windows-
ApplicationExperienceInfrastructure=C:\WINDOWS\SYSTEM32\APPHELP.DLL
### Application Compatibility Client Library Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 !$*%SystemRoot%\system32\apphelp.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-AppModel-
Runtime=C:\WINDOWS\SYSTEM32\MICROSOFT-WINDOWS-SYSTEM-EVENTS.DLL
### Microsoft-Windows-System-Events Resources Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 !$*%SystemRoot%\system32\Microsoft-
Windows-System-Events.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-AppModel-
State=C:\WINDOWS\SYSTEM32\MICROSOFT-WINDOWS-SYSTEM-EVENTS.DLL
### Microsoft-Windows-System-Events Resources Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 !$*%SystemRoot%\system32\Microsoft-
Windows-System-Events.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-
Audio=C:\WINDOWS\SYSTEM32\AUDIOSES.DLL
### Audio Session Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*%SystemRoot%\System32\audioses.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-
AxInstallService=C:\WINDOWS\SYSTEM32\AXINSTSV.DLL
### ActiveX Installer Service Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*%SystemRoot%\System32\AxInstSv.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-
Backup=C:\WINDOWS\SYSTEM32\BLBEVENTS.DLL
### Blb Publisher Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*%windir%\system32\BlbEvents.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-
CAPI2=C:\WINDOWS\SYSTEM32\CRYPT32.DLL
### Crypto API32 Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*%SystemRoot%\System32\crypt32.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-
CertificateServicesClient=C:\WINDOWS\SYSTEM32\DIMSJOB.DLL
### DIMS Job DLL Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*%SystemRoot%\system32\dimsjob.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-CertificateServicesClient-
AutoEnrollment=C:\WINDOWS\SYSTEM32\PAUTOENR.DLL
### Auto Enrollment DLL Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*%SystemRoot%\system32\pautoenr.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-CertificateServicesClient-
CertEnroll=C:\WINDOWS\SYSTEM32\CERTENROLL.DLL
### Microsoft Active Directory Certificate Services Enrollment Client Microsoft
Corporation Microsoft Windows Operating System 6.3.9600.16384 !$*%SystemRoot
%\system32\certenroll.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-CertificateServicesClient-
CredentialRoaming=C:\WINDOWS\SYSTEM32\DIMSROAM.DLL
### Key Roaming DIMS Provider DLL Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%SystemRoot%\system32\dimsroam.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-CertificationAuthorityClient-
CertCli=C:\WINDOWS\SYSTEM32\CERTCLI.DLL
### Microsoft Active Directory Certificate Services Client Microsoft Corporation
Microsoft Windows Operating System 6.3.9600.16384 !$*%SystemRoot
%\system32\certcli.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-
COMRuntime=C:\WINDOWS\SYSTEM32\COMBASE.DLL
### Microsoft COM for Windows Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*%SystemRoot%\system32\combase.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-
Deduplication=C:\WINDOWS\SYSTEM32\DDPUTILS.DLL
### Microsoft Data Deduplication Common Library Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 !$*%SystemRoot%\System32\ddputils.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-
Defrag=C:\WINDOWS\SYSTEM32\DEFRAGSVC.DLL
### Microsoft\Drive Optimizer Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*%systemroot%\system32\defragsvc.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-DirectShow-
Core=C:\WINDOWS\SYSTEM32\QUARTZ.DLL
### DirectShow Runtime. Microsoft Corporation Microsoft Windows Operating
System 6.6.9600.16384 !$*%SystemRoot%\system32\quartz.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-DirectShow-
KernelSupport=C:\WINDOWS\SYSTEM32\KSPROXY.AX
### WDM Streaming ActiveMovie Proxy Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%SystemRoot%\System32\ksproxy.ax
[Eventlog Application DLL] :HKLM Microsoft-Windows-
EapHost=C:\WINDOWS\SYSTEM32\EAPSVC.DLL
### Microsoft EAPHost service Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*%systemroot%\system32\eapsvc.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-
EFS=C:\WINDOWS\SYSTEM32\EFSCORE.DLL
### EFS Core Library Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*%SystemRoot%\system32\efscore.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-
EventCollector=C:\WINDOWS\SYSTEM32\WECSVC.DLL
### Event Collector Service Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*%SystemRoot%\system32\wecsvc.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-Folder
Redirection=C:\WINDOWS\SYSTEM32\FDEPLOY.DLL
### Folder Redirection Group Policy Extension Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 !$*%SystemRoot%\System32\fdeploy.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-Immersive-
Shell=C:\WINDOWS\SYSTEM32\TWINUI.DLL
### TWINUI Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*%SystemRoot%\system32\twinui.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-
LoadPerf=C:\WINDOWS\SYSTEM32\LOADPERF.DLL
### Load & Unload Performance Counters Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%SystemRoot%\system32\loadperf.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-
LocationProvider=C:\WINDOWS\SYSTEM32\DRIVERS\UMDF\LOCATIONPROVIDER.DLL
### Location Provider Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*%SystemRoot%\System32\drivers\UMDF\LocationProvider.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-
PerfCtrs=C:\WINDOWS\SYSTEM32\PERFCTRS.DLL
### Performance Counters Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*%SystemRoot%\system32\perfctrs.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-
PerfNet=C:\WINDOWS\SYSTEM32\PERFNET.DLL
### Windows Network Service Performance Objects DLL Microsoft Corporation
Microsoft Windows Operating System 6.3.9600.16384 !$*%SystemRoot
%\system32\perfnet.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-
PerfOS=C:\WINDOWS\SYSTEM32\PERFOS.DLL
### Windows System Performance Objects DLL Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 !$*%SystemRoot%\system32\perfos.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-
PerfProc=C:\WINDOWS\SYSTEM32\PERFPROC.DLL
### Windows System Process Performance Objects DLL Microsoft Corporation
Microsoft Windows Operating System 6.3.9600.16384 !$*%SystemRoot
%\system32\perfproc.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-
propsys=C:\WINDOWS\SYSTEM32\PROPSYS.DLL
### Microsoft Property System Microsoft Corporation Windows Search
7.00.9600.16384 !$*%SystemRoot%\system32\propsys.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-RemoteApp and Desktop
Connections=C:\WINDOWS\SYSTEM32\TSWORKSPACE.DLL
### RemoteApp and Desktop Connection Component Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 !$*%SystemRoot%\system32\TSWorkspace.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-
RemoteAssistance=C:\WINDOWS\SYSTEM32\MSRA.EXE
### Windows Remote Assistance Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*%systemroot%\system32\msra.exe
[Eventlog Application DLL] :HKLM Microsoft-Windows-
RestartManager=C:\WINDOWS\SYSTEM32\RSTRTMGR.DLL
### Restart Manager Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*%SystemRoot%\System32\RstrtMgr.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-RPC-
Events=C:\WINDOWS\SYSTEM32\RPCRT4.DLL
### Remote Procedure Call Runtime Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%SystemRoot%\system32\rpcrt4.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-Security-EnterpriseData-
FileRevocationManager=C:\WINDOWS\SYSTEM32\EFSWRT.DLL
### Storage Protection Windows Runtime DLL Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 !$*%SystemRoot%\system32\efswrt.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-
SoftwareRestrictionPolicies=C:\WINDOWS\SYSTEM32\MICROSOFT-WINDOWS-SYSTEM-EVENTS.DLL
### Microsoft-Windows-System-Events Resources Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 !$*%SystemRoot%\system32\Microsoft-
Windows-System-Events.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-Spell-
Checking=C:\WINDOWS\SYSTEM32\MSSPELLCHECKINGFACILITY.DLL
### Microsoft Spell Checking Facility Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%systemroot
%\System32\MsSpellCheckingFacility.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-
SpellChecker=C:\WINDOWS\SYSTEM32\MSSPELLCHECKINGFACILITY.DLL
### Microsoft Spell Checking Facility Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%systemroot
%\System32\MsSpellCheckingFacility.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-Spellchecking-
Host=C:\WINDOWS\SYSTEM32\MSSPELLCHECKINGHOST.EXE
### Microsoft Spell Checking Host Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%systemroot%\System32\MsSpellCheckingHost.exe
[Eventlog Application DLL] :HKLM Microsoft-Windows-System-
Restore=C:\WINDOWS\SYSTEM32\SREVENTS.DLL
### SrEvents Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*%windir%\system32\SrEvents.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-TerminalServices-
ClientActiveXCore=C:\WINDOWS\SYSTEM32\MSTSCAX.DLL
### Remote Desktop Services ActiveX Client Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 !$*%SystemRoot%\system32\mstscax.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-User Profiles
General=C:\WINDOWS\SYSTEM32\USERENV.DLL
### Userenv Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*%SystemRoot%\System32\userenv.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-User Profiles
Service=C:\WINDOWS\SYSTEM32\PROFSVC.DLL
### ProfSvc Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*%SystemRoot%\System32\profsvc.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-User-
Loader=C:\WINDOWS\SYSTEM32\MICROSOFT-WINDOWS-SYSTEM-EVENTS.DLL
### Microsoft-Windows-System-Events Resources Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 !$*%SystemRoot%\system32\Microsoft-
Windows-System-Events.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-Video-For-
Windows=C:\WINDOWS\SYSTEM32\MCIAVI32.DLL
### Video For Windows MCI driver Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%SystemRoot%\system32\mciavi32.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-
WindowsSystemAssessmentTool=C:\WINDOWS\SYSTEM32\WINSAT.EXE
### Windows System Assessment Tool Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%SystemRoot%\system32\WINSAT.EXE
[Eventlog Application DLL] :HKLM Microsoft-Windows-
Winsrv=C:\WINDOWS\SYSTEM32\WINSRV.DLL
### Multi-User Windows Server DLL Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%SystemRoot%\system32\winsrv.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-
WMI=C:\WINDOWS\SYSTEM32\WBEM\WINMGMTR.DLL
### WMI Microsoft Corporation Microsoft Windows Operating System 6.3.9600.16384
!$*%SystemRoot%\system32\wbem\WinMgmtR.dll
[Eventlog Application DLL] :HKLM Microsoft-Windows-
XWizards=C:\WINDOWS\SYSTEM32\XWIZARDS.DLL
### Extensible Wizards Manager Module Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%windir%\system32\xwizards.dll
[Eventlog Application DLL] :HKLM Microsoft.Transactions.Bridge
3.0.0.0=C:\WINDOWS\MICROSOFT.NET\FRAMEWORK64\V3.0\WINDOWS COMMUNICATION
FOUNDATION\SERVICEMODELEVENTS.DLL
### ServiceModel related event descriptions Microsoft Corporation Microsoft .NET
Framework 3.0.4506.7903
[Eventlog Application DLL] :HKLM Microsoft.Transactions.Bridge
4.0.0.0=C:\WINDOWS\MICROSOFT.NET\FRAMEWORK64\V4.0.30319\SERVICEMODELEVENTS.DLL
### ServiceModel related event descriptions Microsoft Corporation Microsoft .NET
Framework 4.0.30319.33440
[Eventlog Application DLL] :HKLM MsiInstaller=C:\WINDOWS\SYSTEM32\MSIMSG.DLL
### Windows Installer International Messages Microsoft Corporation Windows
Installer - Unicode 5.0.9600.16384
[Eventlog Application DLL] :HKLM NVIDIA OpenGL
Driver=C:\WINDOWS\SYSTEM32\NVOGLV64.DLL
### NVIDIA Compatible OpenGL ICD NVIDIA Corporation NVIDIA Compatible OpenGL ICD
9.18.13.3317 !$*%SystemRoot%\System32\nvoglv64.dll
[Eventlog Application DLL] :HKLM NVIDIA Update Core Service=C:\PROGRAM FILES
(X86)\NVIDIA CORPORATION\UPDATE CORE\NVBACKEND.EXE
### NVIDIA GeForce Experience Backend NVIDIA Corporation NVIDIA GeForce
Experience 14.6.22.1
[Eventlog Application DLL] :HKLM Picasa3=C:\Program Files
(x86)\Google\Picasa3\Picasa3.exe
### File is missing.
[Eventlog Application DLL] :HKLM Profsvc=C:\WINDOWS\SYSTEM32\PROFSVC.DLL
### ProfSvc Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*%SystemRoot%\System32\profsvc.dll
[Eventlog Application DLL] :HKLM RasClient=C:\WINDOWS\SYSTEM32\MPRMSG.DLL
### Multi-Protocol Router Service Messages DLL Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 !$*%SystemRoot%\System32\mprmsg.dll
[Eventlog Application DLL] :HKLM SceCli=C:\WINDOWS\SYSTEM32\SCECLI.DLL
### Windows Security Configuration Editor Client Engine Microsoft Corporation
Microsoft Windows Operating System 6.3.9600.16384 !$*%SystemRoot
%\System32\scecli.dll
[Eventlog Application DLL] :HKLM SceSrv=C:\WINDOWS\SYSTEM32\SCESRV.DLL
### Windows Security Configuration Editor Engine Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 !$*%SystemRoot%\System32\scesrv.dll
[Eventlog Application DLL] :HKLM SecurityCenter=C:\WINDOWS\SYSTEM32\WSCSVC.DLL
### Windows Security Center Service Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%SystemRoot%\System32\wscsvc.dll
[Eventlog Application DLL] :HKLM ServiceModel Audit
3.0.0.0=C:\WINDOWS\MICROSOFT.NET\FRAMEWORK64\V3.0\WINDOWS COMMUNICATION
FOUNDATION\SERVICEMODELEVENTS.DLL
### ServiceModel related event descriptions Microsoft Corporation Microsoft .NET
Framework 3.0.4506.7903
[Eventlog Application DLL] :HKLM ServiceModel Audit
4.0.0.0=C:\WINDOWS\MICROSOFT.NET\FRAMEWORK64\V4.0.30319\SERVICEMODELEVENTS.DLL
### ServiceModel related event descriptions Microsoft Corporation Microsoft .NET
Framework 4.0.30319.33440
[Eventlog Application DLL] :HKLM SideBySide=C:\WINDOWS\SYSTEM32\SXS.DLL
### Fusion 2.5 Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*%SystemRoot%\System32\sxs.dll
[Eventlog Application DLL] :HKLM Software
Installation=C:\WINDOWS\SYSTEM32\APPMGR.DLL
### Software Installation Snapin Extenstion Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 !$*%SystemRoot%\System32\appmgr.dll
[Eventlog Application DLL] :HKLM Software Protection Platform
Service=C:\WINDOWS\SYSTEM32\SPPSVC.EXE
### Microsoft Software Protection Platform Service Microsoft Corporation
Microsoft Windows Operating System 6.3.9600.16384 !$*%SystemRoot
%\system32\sppsvc.exe
[Eventlog Application DLL] :HKLM SPP=C:\WINDOWS\SYSTEM32\SXPROXY.DLL
### Microsoft Windows System Protection Proxy Library Microsoft Corporation
Microsoft Windows Operating System 6.3.9600.16384 !$*%systemroot
%\system32\sxproxy.dll
[Eventlog Application DLL] :HKLM SrmSvc=C:\WINDOWS\SYSTEM32\SRM.DLL
### Microsoft File Server Resource Manager Common Library Microsoft Corporation
Microsoft Windows Operating System 6.3.9600.16384 !$*%SystemRoot
%\System32\srm.dll
[Eventlog Application DLL] :HKLM System Restore=C:\WINDOWS\SYSTEM32\SRCORE.DLL
### Microsoft Windows System Restore Core Library Microsoft Corporation
Microsoft Windows Operating System 6.3.9600.16384 !$*%systemroot
%\system32\srcore.dll
[Eventlog Application DLL] :HKLM System.IdentityModel
3.0.0.0=C:\WINDOWS\MICROSOFT.NET\FRAMEWORK64\V3.0\WINDOWS COMMUNICATION
FOUNDATION\SERVICEMODELEVENTS.DLL
### ServiceModel related event descriptions Microsoft Corporation Microsoft .NET
Framework 3.0.4506.7903
[Eventlog Application DLL] :HKLM System.IdentityModel
4.0.0.0=C:\WINDOWS\MICROSOFT.NET\FRAMEWORK64\V4.0.30319\SERVICEMODELEVENTS.DLL
### ServiceModel related event descriptions Microsoft Corporation Microsoft .NET
Framework 4.0.30319.33440
[Eventlog Application DLL] :HKLM System.IO.Log
3.0.0.0=C:\WINDOWS\MICROSOFT.NET\FRAMEWORK64\V3.0\WINDOWS COMMUNICATION
FOUNDATION\SERVICEMODELEVENTS.DLL
### ServiceModel related event descriptions Microsoft Corporation Microsoft .NET
Framework 3.0.4506.7903
[Eventlog Application DLL] :HKLM System.IO.Log
4.0.0.0=C:\WINDOWS\MICROSOFT.NET\FRAMEWORK64\V4.0.30319\SERVICEMODELEVENTS.DLL
### ServiceModel related event descriptions Microsoft Corporation Microsoft .NET
Framework 4.0.30319.33440
[Eventlog Application DLL] :HKLM System.Runtime.Serialization
3.0.0.0=C:\WINDOWS\MICROSOFT.NET\FRAMEWORK64\V3.0\WINDOWS COMMUNICATION
FOUNDATION\SERVICEMODELEVENTS.DLL
### ServiceModel related event descriptions Microsoft Corporation Microsoft .NET
Framework 3.0.4506.7903
[Eventlog Application DLL] :HKLM System.Runtime.Serialization
4.0.0.0=C:\WINDOWS\MICROSOFT.NET\FRAMEWORK64\V4.0.30319\SERVICEMODELEVENTS.DLL
### ServiceModel related event descriptions Microsoft Corporation Microsoft .NET
Framework 4.0.30319.33440
[Eventlog Application DLL] :HKLM System.ServiceModel
3.0.0.0=C:\WINDOWS\MICROSOFT.NET\FRAMEWORK64\V3.0\WINDOWS COMMUNICATION
FOUNDATION\SERVICEMODELEVENTS.DLL
### ServiceModel related event descriptions Microsoft Corporation Microsoft .NET
Framework 3.0.4506.7903
[Eventlog Application DLL] :HKLM System.ServiceModel
4.0.0.0=C:\WINDOWS\MICROSOFT.NET\FRAMEWORK64\V4.0.30319\SERVICEMODELEVENTS.DLL
### ServiceModel related event descriptions Microsoft Corporation Microsoft .NET
Framework 4.0.30319.33440
[Eventlog Application DLL] :HKLM usbperf=C:\WINDOWS\SYSTEM32\USBPERF.DLL
### USB Performance Objects DLL Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%SystemRoot%\system32\usbperf.dll
[Eventlog Application DLL] :HKLM Userenv=C:\WINDOWS\SYSTEM32\USERENV.DLL
### Userenv Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*%SystemRoot%\System32\userenv.dll
[Eventlog Application DLL] :HKLM VBRuntime=C:\WINDOWS\SYSWOW64\MSVBVM60.DLL
### Visual Basic Virtual Machine Microsoft Corporation Visual Basic 6.00.9815
[Eventlog Application DLL] :HKLM
vmicguestinterface=C:\WINDOWS\SYSTEM32\VMICRES.DLL
### Virtual Machine Integration Component Service Resource DLL Microsoft
Corporation Microsoft Windows Operating System 6.3.9600.16384 !$*%systemroot
%\system32\vmicres.dll
[Eventlog Application DLL] :HKLM vmicheartbeat=C:\WINDOWS\SYSTEM32\VMICRES.DLL
### Virtual Machine Integration Component Service Resource DLL Microsoft
Corporation Microsoft Windows Operating System 6.3.9600.16384 !$*%systemroot
%\system32\vmicres.dll
[Eventlog Application DLL] :HKLM vmickvpexchange=C:\WINDOWS\SYSTEM32\VMICRES.DLL
### Virtual Machine Integration Component Service Resource DLL Microsoft
Corporation Microsoft Windows Operating System 6.3.9600.16384 !$*%systemroot
%\system32\vmicres.dll
[Eventlog Application DLL] :HKLM vmicrdv=C:\WINDOWS\SYSTEM32\VMICRES.DLL
### Virtual Machine Integration Component Service Resource DLL Microsoft
Corporation Microsoft Windows Operating System 6.3.9600.16384 !$*%systemroot
%\system32\vmicres.dll
[Eventlog Application DLL] :HKLM vmicshutdown=C:\WINDOWS\SYSTEM32\VMICRES.DLL
### Virtual Machine Integration Component Service Resource DLL Microsoft
Corporation Microsoft Windows Operating System 6.3.9600.16384 !$*%systemroot
%\system32\vmicres.dll
[Eventlog Application DLL] :HKLM vmictimesync=C:\WINDOWS\SYSTEM32\VMICRES.DLL
### Virtual Machine Integration Component Service Resource DLL Microsoft
Corporation Microsoft Windows Operating System 6.3.9600.16384 !$*%systemroot
%\system32\vmicres.dll
[Eventlog Application DLL] :HKLM vmicvss=C:\WINDOWS\SYSTEM32\VMICRES.DLL
### Virtual Machine Integration Component Service Resource DLL Microsoft
Corporation Microsoft Windows Operating System 6.3.9600.16384 !$*%systemroot
%\system32\vmicres.dll
[Eventlog Application DLL] :HKLM VSS=C:\WINDOWS\SYSTEM32\VSSVC.EXE
### Microsoft Volume Shadow Copy Service Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 !$*%SystemRoot%\System32\VSSVC.EXE
[Eventlog Application DLL] :HKLM VSSetup=d:\cad14d21dd5e2e0c5bd282\DW\DW20.exe
### File is missing.
[Eventlog Application DLL] :HKLM WerSvc=C:\WINDOWS\SYSTEM32\WERSVC.DLL
### Windows Error Reporting Service Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%SystemRoot%\System32\wersvc.dll
[Eventlog Application DLL] :HKLM Windows Error
Reporting=C:\WINDOWS\SYSTEM32\WER.DLL
### Windows Error Reporting DLL Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%SystemRoot%\System32\wer.dll
[Eventlog Application DLL] :HKLM Windows Search
Service=C:\WINDOWS\SYSTEM32\TQUERY.DLL
### Microsoft Tripoli Query Microsoft Corporation Windows Search 7.00.9600.16384
!$*%systemroot%\system32\tquery.dll
[Eventlog Application DLL] :HKLM Windows Search Service Profile
Notification=C:\WINDOWS\SYSTEM32\WSEPNO.DLL
### Profile notification support for Windows Search Service Microsoft Corporation
Windows Search 7.00.9600.16384 !$*%SystemRoot%\system32\wsepno.dll
[Eventlog Application DLL] :HKLM Wininit=C:\WINDOWS\SYSTEM32\WININIT.EXE
### Windows Start-Up Application Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*%SystemRoot%\System32\wininit.exe
[Eventlog Application DLL] :HKLM Winlogon=C:\WINDOWS\SYSTEM32\WINLOGON.EXE
### Windows Logon Application Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*%SystemRoot%\System32\winlogon.exe
[Eventlog Application DLL] :HKLM Wlclntfy=C:\WINDOWS\SYSTEM32\WINLOGON.EXE
### Windows Logon Application Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*%SystemRoot%\System32\winlogon.exe
[Eventlog Application DLL] :HKLM WMI.NET Provider
Extension=C:\WINDOWS\MICROSOFT.NET\FRAMEWORK64\V4.0.30319\EVENTLOGMESSAGES.DLL
### EventLogMessages.dll Microsoft Corporation Microsoft .NET Framework
4.0.30319.33440
[Eventlog Application DLL] :HKLM Wow64 Emulation
Layer=C:\WINDOWS\SYSTEM32\NTVDM64.DLL
### 16-bit Emulation on NT64 Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*%SystemRoot%\System32\ntvdm64.dll
[Eventlog Application DLL] :HKLM WSH=C:\WINDOWS\SYSTEM32\WSHEXT.DLL
### Microsoft Shell Extension for Windows Script Host Microsoft Corporation
Microsoft Windows Script Host 5.8.9600.16384 !$*%SystemRoot%\System32\wshext.dll
[Drivers] :HKLM 1394ohci=C:\WINDOWS\SYSTEM32\DRIVERS\1394OHCI.SYS
### 1394 OpenHCI Driver Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*\SystemRoot\System32\drivers\1394ohci.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM 3ware=C:\WINDOWS\SYSTEM32\DRIVERS\3WARE.SYS
### LSI 3ware SCSI Storport Driver LSI LSI 3ware RAID Controller WindowsBlue
Service registry key doesn't exist or hidden.
[Drivers] :HKLM ACPI=C:\WINDOWS\SYSTEM32\DRIVERS\ACPI.SYS
### ACPI Driver for NT Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 Service registry key doesn't exist or hidden.
[Drivers] :HKLM acpiex=C:\WINDOWS\SYSTEM32\DRIVERS\ACPIEX.SYS
### ACPIEx Driver Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 Service registry key doesn't exist or hidden.
[Drivers] :HKLM acpipagr=C:\WINDOWS\SYSTEM32\DRIVERS\ACPIPAGR.SYS
### ACPI Processor Aggregator Device Driver Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 !
$*\SystemRoot\System32\drivers\acpipagr.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM AcpiPmi=C:\WINDOWS\SYSTEM32\DRIVERS\ACPIPMI.SYS
### ACPI Power Metering Driver Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*\SystemRoot\System32\drivers\acpipmi.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM acpitime=C:\WINDOWS\SYSTEM32\DRIVERS\ACPITIME.SYS
### ACPI Wake Alarm Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*\SystemRoot\System32\drivers\acpitime.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM ADP80XX=C:\WINDOWS\SYSTEM32\DRIVERS\ADP80XX.SYS
### PMC-Sierra Storport Driver For SPC8x6G SAS/SATA controller PMC-Sierra PMC-
Sierra HBA Controller 1.0.0.0254 Service registry key doesn't exist or hidden.
[Drivers] :HKLM AFD=C:\WINDOWS\SYSTEM32\DRIVERS\AFD.SYS
### Ancillary Function Driver for WinSock Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 !$*\SystemRoot\system32\drivers\afd.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM agp440=C:\WINDOWS\SYSTEM32\DRIVERS\AGP440.SYS
### 440 NT AGP Filter Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 Service registry key doesn't exist or hidden.
[Drivers] :HKLM ahcache=C:\WINDOWS\SYSTEM32\DRIVERS\AHCACHE.SYS
### Application Compatibility Cache Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 Service registry key doesn't exist or hidden.
[Drivers] :HKLM AmdK8=C:\WINDOWS\SYSTEM32\DRIVERS\AMDK8.SYS
### Processor Device Driver Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*\SystemRoot\System32\drivers\amdk8.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM AmdPPM=C:\WINDOWS\SYSTEM32\DRIVERS\AMDPPM.SYS
### Processor Device Driver Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*\SystemRoot\System32\drivers\amdppm.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM amdsata=C:\WINDOWS\SYSTEM32\DRIVERS\AMDSATA.SYS
### AHCI 1.3 Device Driver Advanced Micro Devices AHCI 1.3 Device Driver 1.1.4.14
Service registry key doesn't exist or hidden.
[Drivers] :HKLM amdsbs=C:\WINDOWS\SYSTEM32\DRIVERS\AMDSBS.SYS
### AMD Technology AHCI Compatible Controller Driver for Windows - AMD64 platform
AMD Technologies Inc. AMD Technology AHCI Compatible Controller 3.7.1540.43
Service registry key doesn't exist or hidden.
[Drivers] :HKLM amdxata=C:\WINDOWS\SYSTEM32\DRIVERS\AMDXATA.SYS
### Storage Filter Driver Advanced Micro Devices Storage Filter Driver 1.1.4.14
Service registry key doesn't exist or hidden.
[Drivers] :HKLM AmUStor=C:\WINDOWS\SYSTEM32\DRIVERS\AMUSTOR.SYS
### Alocr Micro USB Mass Storage Driver Alcor Micro, Corp. Alocr Micro USB Mass
Storage Driver amd64 !$*\SystemRoot\system32\drivers\AmUStor.SYS Service registry
key doesn't exist or hidden.
[Drivers] :HKLM AppID=C:\WINDOWS\SYSTEM32\DRIVERS\APPID.SYS
### AppID Driver Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*\SystemRoot\system32\drivers\appid.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM arcsas=C:\WINDOWS\SYSTEM32\DRIVERS\ARCSAS.SYS
### Adaptec SAS RAID WS03 Driver PMC-Sierra, Inc. Adaptec RAID Controller
7.2.0.30261 Service registry key doesn't exist or hidden.
[Drivers] :HKLM ASMMAP64=C:\PROGRAM FILES (X86)\ASUS\ATK
PACKAGE\ATKGFNEX\ASMMAP64.SYS
### Memory mapping Driver ASUS ATK Generic Function Service 1, 0, 9, 0 !
$*\??\C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM AsyncMac=C:\WINDOWS\SYSTEM32\DRIVERS\ASYNCMAC.SYS
### MS Remote Access serial network driver Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 !
$*\SystemRoot\system32\DRIVERS\asyncmac.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM atapi=C:\WINDOWS\SYSTEM32\DRIVERS\ATAPI.SYS
### ATAPI IDE Miniport Driver Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 Service registry key doesn't exist or hidden.
[Drivers] :HKLM AthBTPort=C:\WINDOWS\SYSTEM32\DRIVERS\BTATH_FLT.SYS
### Qualcomm Atheros FILTER driver Qualcomm Atheros Blue Manager 8.0.1.302 !
$*\SystemRoot\system32\DRIVERS\btath_flt.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM athr=C:\WINDOWS\SYSTEM32\DRIVERS\ATHWBX.SYS
### Qualcomm Atheros Extensible Wireless LAN device driver Qualcomm Atheros
Communications, Inc. Driver for Qualcomm Atheros CB42/CB43/MB42/MB43 Network
Adapter 10.0.0.287 !$*\SystemRoot\system32\DRIVERS\athwbx.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM ATKWMIACPIIO=C:\PROGRAM FILES (X86)\ASUS\ATK PACKAGE\ATK
WMIACPI\ATKWMIACPI64.SYS
### ATK WMIACPI Utility ASUSTek Computer Inc. ATK WMIACPI Utility 1, 0, 6, 0 !
$*\??\C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM ATP=C:\WINDOWS\SYSTEM32\DRIVERS\ASUSTP.SYS
### Asus TP Filter Driver(X64) ASUS Corporation Asus TP Filter Driver 6.0.0.35 !
$*\SystemRoot\System32\drivers\AsusTP.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM b06bdrv=C:\WINDOWS\SYSTEM32\DRIVERS\BXVBDA.SYS
### Broadcom NetXtreme II GigE VBD Broadcom Corporation Broadcom NetXtreme II
GigE 7.4.14.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM BasicDisplay=C:\WINDOWS\SYSTEM32\DRIVERS\BASICDISPLAY.SYS
### Microsoft Basic Display Driver Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*\SystemRoot\System32\drivers\BasicDisplay.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM BasicRender=C:\WINDOWS\SYSTEM32\DRIVERS\BASICRENDER.SYS
### Microsoft Basic Render Driver Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*\SystemRoot\System32\drivers\BasicRender.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM bcmfn2=C:\WINDOWS\SYSTEM32\DRIVERS\BCMFN2.SYS
### BCM Function 2 Device Driver Windows (R) Win 7 DDK provider Windows (R) Win
7 DDK driver 6.3.9391.6 !$*\SystemRoot\System32\drivers\bcmfn2.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM bowser=C:\WINDOWS\SYSTEM32\DRIVERS\BOWSER.SYS
### NT Lan Manager Datagram Receiver Driver Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 Service registry key doesn't exist or
hidden.
[Drivers] :HKLM BTATH_A2DP=C:\WINDOWS\SYSTEM32\DRIVERS\BTATH_A2DP.SYS
### Qualcomm Atheros A2DP driver Qualcomm Atheros Blue Manager 8.0.1.316 !
$*\SystemRoot\system32\drivers\btath_a2dp.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM btath_avdt=C:\WINDOWS\SYSTEM32\DRIVERS\BTATH_AVDT.SYS
### Qualcomm Atheros Bluetooth AVDT driver Qualcomm Atheros Blue Manager
8.0.1.316 !$*\SystemRoot\system32\drivers\btath_avdt.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM BTATH_BUS=C:\WINDOWS\SYSTEM32\DRIVERS\BTATH_BUS.SYS
### Qualcomm Atheros BUS driver Qualcomm Atheros Blue Manager 8.0.1.316 Service
registry key doesn't exist or hidden.
[Drivers] :HKLM BTATH_HCRP=C:\WINDOWS\SYSTEM32\DRIVERS\BTATH_HCRP.SYS
### Qualcomm Atheros HCRP driver Qualcomm Atheros Blue Manager 8.0.0.218 !
$*\SystemRoot\System32\drivers\btath_hcrp.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM BTATH_LWFLT=C:\WINDOWS\SYSTEM32\DRIVERS\BTATH_LWFLT.SYS
### Qualcomm Atheros FILTER driver Qualcomm Atheros Blue Manager 8.0.0.216 !
$*\SystemRoot\system32\DRIVERS\btath_lwflt.sys Service registry key doesn't exist
or hidden.
[Drivers] :HKLM BTATH_RCP=C:\WINDOWS\SYSTEM32\DRIVERS\BTATH_RCP.SYS
### Qualcomm Atheros AVRCP driver Qualcomm Atheros Blue Manager 8.0.0.230 !
$*\SystemRoot\System32\drivers\btath_rcp.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM BtFilter=C:\WINDOWS\SYSTEM32\DRIVERS\BTFILTER.SYS
### Qualcomm Atheros BtFilter Driver Qualcomm Atheros Windows (R) Win 7 DDK
driver 8.0.1.318 !$*\SystemRoot\system32\DRIVERS\btfilter.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM BthAvrcpTg=C:\WINDOWS\SYSTEM32\DRIVERS\BTHAVRCPTG.SYS
### Bluetooth Audio/Video Remote Control HID Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 !
$*\SystemRoot\System32\drivers\BthAvrcpTg.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM BthEnum=C:\WINDOWS\SYSTEM32\DRIVERS\BTHENUM.SYS
### Bluetooth Bus Extender Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*\SystemRoot\system32\DRIVERS\BthEnum.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM BthHFEnum=C:\WINDOWS\SYSTEM32\DRIVERS\BTHHFENUM.SYS
### Bluetooth Hands-Free Audio and Call Control HID Enumerator Microsoft
Corporation Microsoft Windows Operating System 6.3.9600.16384 !
$*\SystemRoot\System32\drivers\bthhfenum.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM bthhfhid=C:\WINDOWS\SYSTEM32\DRIVERS\BTHHFHID.SYS
### Bluetooth Hands-free HID Minidriver Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*\SystemRoot\System32\drivers\BthHFHid.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM BthLEEnum=C:\WINDOWS\SYSTEM32\DRIVERS\BTHLEENUM.SYS
### Bluetooth LE Bus Enumerator Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*\SystemRoot\system32\DRIVERS\BthLEEnum.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM BTHMODEM=C:\WINDOWS\SYSTEM32\DRIVERS\BTHMODEM.SYS
### Bluetooth Communications Driver Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*\SystemRoot\System32\drivers\bthmodem.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM BthPan=C:\WINDOWS\SYSTEM32\DRIVERS\BTHPAN.SYS
### Bluetooth Personal Area Networking Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*\SystemRoot\system32\DRIVERS\bthpan.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM BTHPORT=C:\WINDOWS\SYSTEM32\DRIVERS\BTHPORT.SYS
### Bluetooth Bus Driver Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*\SystemRoot\System32\Drivers\BTHport.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM BTHUSB=C:\WINDOWS\SYSTEM32\DRIVERS\BTHUSB.SYS
### Bluetooth Miniport Driver Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*\SystemRoot\System32\Drivers\BTHUSB.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM cdfs=C:\WINDOWS\SYSTEM32\DRIVERS\CDFS.SYS
### CD-ROM File System Driver Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 Service registry key doesn't exist or hidden.
[Drivers] :HKLM cdrom=C:\WINDOWS\SYSTEM32\DRIVERS\CDROM.SYS
### SCSI CD-ROM Driver Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*\SystemRoot\System32\drivers\cdrom.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM circlass=C:\WINDOWS\SYSTEM32\DRIVERS\CIRCLASS.SYS
### Consumer IR Class Driver for eHome Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*\SystemRoot\System32\drivers\circlass.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM CLFS=C:\WINDOWS\SYSTEM32\DRIVERS\CLFS.SYS
### Common Log File System Driver Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 Service registry key doesn't exist or hidden.
[Drivers] :HKLM CmBatt=C:\WINDOWS\SYSTEM32\DRIVERS\CMBATT.SYS
### Control Method Battery Driver Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*\SystemRoot\System32\drivers\CmBatt.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM CNG=C:\WINDOWS\SYSTEM32\DRIVERS\CNG.SYS
### Kernel Cryptography, Next Generation Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 Service registry key doesn't exist or
hidden.
[Drivers] :HKLM CnxtHdAudService=C:\WINDOWS\SYSTEM32\DRIVERS\CHDRT64.SYS
### 64-bit High Definition Audio Function Driver Conexant Systems Inc. Conexant
HDAudio Driver 8.65.41.0 !$*\SystemRoot\system32\drivers\CHDRT64.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM CompositeBus=C:\WINDOWS\SYSTEM32\DRIVERS\COMPOSITEBUS.SYS
### Multi-Transport Composite Bus Enumerator Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 !
$*\SystemRoot\System32\drivers\CompositeBus.sys Service registry key doesn't exist
or hidden.
[Drivers] :HKLM condrv=C:\WINDOWS\SYSTEM32\DRIVERS\CONDRV.SYS
### Console Driver Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 Service registry key doesn't exist or hidden.
[Drivers] :HKLM CSC=C:\WINDOWS\SYSTEM32\DRIVERS\CSC.SYS
### Windows Client Side Caching Driver Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 Service registry key doesn't exist or hidden.
[Drivers] :HKLM dam=C:\WINDOWS\SYSTEM32\DRIVERS\DAM.SYS
### DAM Kernel Driver Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 Service registry key doesn't exist or hidden.
[Drivers] :HKLM Dfsc=C:\WINDOWS\SYSTEM32\DRIVERS\DFSC.SYS
### DFS Namespace Client Driver Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 Service registry key doesn't exist or hidden.
[Drivers] :HKLM dg_ssudbus=C:\WINDOWS\SYSTEM32\DRIVERS\SSUDBUS.SYS
### SAMSUNG USB Composite Device Driver Samsung Electronics Co., Ltd. SAMSUNG USB
Composite Device Driver 2.12.4.0 !$*\SystemRoot\system32\DRIVERS\ssudbus.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM disk=C:\WINDOWS\SYSTEM32\DRIVERS\DISK.SYS
### PnP Disk Driver Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 Service registry key doesn't exist or hidden.
[Drivers] :HKLM dmvsc=C:\WINDOWS\SYSTEM32\DRIVERS\DMVSC.SYS
### Dynamic Memory Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*\SystemRoot\System32\drivers\dmvsc.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM DptfDevProc=C:\WINDOWS\SYSTEM32\DRIVERS\DPTFDEVPROC.SYS
### Intel(R) Dynamic Platform and Thermal Framework Processor Participant Driver
Intel Corporation Intel(R) Dynamic Platform and Thermal Framework 7.1.0.2105 !
$*\SystemRoot\system32\DRIVERS\DptfDevProc.sys Service registry key doesn't exist
or hidden.
[Drivers] :HKLM DptfManager=C:\WINDOWS\SYSTEM32\DRIVERS\DPTFMANAGER.SYS
### Intel(R) Dynamic Platform and Thermal Framework Manager Driver Intel
Corporation Intel(R) Dynamic Platform and Thermal Framework 7.1.0.2105 !
$*\SystemRoot\system32\DRIVERS\DptfManager.sys Service registry key doesn't exist
or hidden.
[Drivers] :HKLM drmkaud=C:\WINDOWS\SYSTEM32\DRIVERS\DRMKAUD.SYS
### Microsoft Trusted Audio Drivers Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*\SystemRoot\system32\drivers\drmkaud.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM DXGKrnl=C:\WINDOWS\SYSTEM32\DRIVERS\DXGKRNL.SYS
### DirectX Graphics Kernel Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*\SystemRoot\System32\drivers\dxgkrnl.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM ebdrv=C:\WINDOWS\SYSTEM32\DRIVERS\EVBDA.SYS
### Broadcom NetXtreme II 10 GigE VBD Broadcom Corporation Broadcom NetXtreme II
10 GigE 7.4.33.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM EhStorClass=C:\WINDOWS\SYSTEM32\DRIVERS\EHSTORCLASS.SYS
### Enhanced Storage Class driver for IEEE 1667 devices Microsoft Corporation
Microsoft Windows Operating System 6.3.9600.16384 Service registry key doesn't
exist or hidden.
[Drivers] :HKLM EhStorTcgDrv=C:\WINDOWS\SYSTEM32\DRIVERS\EHSTORTCGDRV.SYS
### Microsoft driver for storage devices supporting IEEE 1667 and TCG protocols
Microsoft Corporation Microsoft Windows Operating System 6.3.9600.16384 Service
registry key doesn't exist or hidden.
[Drivers] :HKLM ErrDev=C:\WINDOWS\SYSTEM32\DRIVERS\ERRDEV.SYS
### Error Device Driver Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*\SystemRoot\System32\drivers\errdev.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM fdc=C:\WINDOWS\SYSTEM32\DRIVERS\FDC.SYS
### Floppy Disk Controller Driver Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*\SystemRoot\System32\drivers\fdc.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM FileInfo=C:\WINDOWS\SYSTEM32\DRIVERS\FILEINFO.SYS
### FileInfo Filter Driver Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 Service registry key doesn't exist or hidden.
[Drivers] :HKLM Filetrace=C:\WINDOWS\SYSTEM32\DRIVERS\FILETRACE.SYS
### File Trace Filter Driver Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 Service registry key doesn't exist or hidden.
[Drivers] :HKLM flpydisk=C:\WINDOWS\SYSTEM32\DRIVERS\FLPYDISK.SYS
### Floppy Driver Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*\SystemRoot\System32\drivers\flpydisk.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM FltMgr=C:\WINDOWS\SYSTEM32\DRIVERS\FLTMGR.SYS
### Microsoft Filesystem Filter Manager Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 Service registry key doesn't exist or hidden.
[Drivers] :HKLM FsDepends=C:\WINDOWS\SYSTEM32\DRIVERS\FSDEPENDS.SYS
### File System Dependency Manager Mini Filter Driver Microsoft Corporation
Microsoft Windows Operating System 6.3.9600.16384 Service registry key doesn't
exist or hidden.
[Drivers] :HKLM fvevol=C:\WINDOWS\SYSTEM32\DRIVERS\FVEVOL.SYS
### BitLocker Drive Encryption Driver Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 Service registry key doesn't exist or hidden.
[Drivers] :HKLM FxPPM=C:\WINDOWS\SYSTEM32\DRIVERS\FXPPM.SYS
### Processor Driver Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*\SystemRoot\System32\drivers\fxppm.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM gagp30kx=C:\WINDOWS\SYSTEM32\DRIVERS\GAGP30KX.SYS
### MS Generic AGPv3.0 Filter for K8/9 Processor Platforms Microsoft Corporation
Microsoft Windows Operating System 6.3.9600.16384 Service registry key doesn't
exist or hidden.
[Drivers] :HKLM gencounter=C:\WINDOWS\SYSTEM32\DRIVERS\VMGENCOUNTER.SYS
### Virtual Machine Generation Counter Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*\SystemRoot\System32\drivers\vmgencounter.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM GPIOClx0101=C:\WINDOWS\SYSTEM32\DRIVERS\MSGPIOCLX.SYS
### GPIO Class Extension Driver Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 Service registry key doesn't exist or hidden.
[Drivers] :HKLM HdAudAddService=C:\WINDOWS\SYSTEM32\DRIVERS\HDAUDIO.SYS
### High Definition Audio Function Driver Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 !
$*\SystemRoot\system32\drivers\HdAudio.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM HDAudBus=C:\WINDOWS\SYSTEM32\DRIVERS\HDAUDBUS.SYS
### High Definition Audio Bus Driver Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*\SystemRoot\System32\drivers\HDAudBus.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM HidBatt=C:\WINDOWS\SYSTEM32\DRIVERS\HIDBATT.SYS
### Hid Battery Driver Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*\SystemRoot\System32\drivers\HidBatt.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM HidBth=C:\WINDOWS\SYSTEM32\DRIVERS\HIDBTH.SYS
### Bluetooth Miniport Driver for HID Devices Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 !$*\SystemRoot\System32\drivers\hidbth.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM hidi2c=C:\WINDOWS\SYSTEM32\DRIVERS\HIDI2C.SYS
### I2C HID Miniport Driver Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*\SystemRoot\System32\drivers\hidi2c.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM HidIr=C:\WINDOWS\SYSTEM32\DRIVERS\HIDIR.SYS
### Infrared Miniport Driver for Input Devices Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 !$*\SystemRoot\System32\drivers\hidir.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM HIDSwitch=C:\WINDOWS\SYSTEM32\DRIVERS\ASHIDSWITCH64.SYS
### HID driver for ASUS Wireless Radio Control ASUS ASUS Wireless Radio Control
1.0.0.3 !$*\SystemRoot\System32\drivers\AsHIDSwitch64.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM HidUsb=C:\WINDOWS\SYSTEM32\DRIVERS\HIDUSB.SYS
### USB Miniport Driver for Input Devices Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 !$*\SystemRoot\System32\drivers\hidusb.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM HpSAMD=C:\WINDOWS\SYSTEM32\DRIVERS\HPSAMD.SYS
### Smart Array SAS/SATA Controller Media Driver Hewlett-Packard Company Smart
Array SAS/SATA Controller Media Driver 8.0.4.0 Build 1 Media Driver (x86-64)
Service registry key doesn't exist or hidden.
[Drivers] :HKLM HTTP=C:\WINDOWS\SYSTEM32\DRIVERS\HTTP.SYS
### HTTP Protocol Stack Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 Service registry key doesn't exist or hidden.
[Drivers] :HKLM hwpolicy=C:\WINDOWS\SYSTEM32\DRIVERS\HWPOLICY.SYS
### Hardware Policy Driver Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 Service registry key doesn't exist or hidden.
[Drivers] :HKLM hyperkbd=C:\WINDOWS\SYSTEM32\DRIVERS\HYPERKBD.SYS
### Microsoft VMBus Synthetic Keyboard Driver Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 !
$*\SystemRoot\System32\drivers\hyperkbd.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM HyperVideo=C:\WINDOWS\SYSTEM32\DRIVERS\HYPERVIDEO.SYS
### Microsoft VMBus Video Device Miniport Driver Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 !
$*\SystemRoot\system32\DRIVERS\HyperVideo.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM i8042prt=C:\WINDOWS\SYSTEM32\DRIVERS\I8042PRT.SYS
### i8042 Port Driver Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*\SystemRoot\System32\drivers\i8042prt.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM iaLPSSi_GPIO=C:\WINDOWS\SYSTEM32\DRIVERS\IALPSSI_GPIO.SYS
### Intel(R) Serial IO GPIO Controller Driver Intel Corporation Intel(R) Serial
IO Driver 1.1.163.0 !$*\SystemRoot\System32\drivers\iaLPSSi_GPIO.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM iaLPSSi_I2C=C:\WINDOWS\SYSTEM32\DRIVERS\IALPSSI_I2C.SYS
### Intel(R) Serial IO I2C Controller Driver Intel Corporation Intel(R) Serial IO
Driver 1.1.163.0 !$*\SystemRoot\System32\drivers\iaLPSSi_I2C.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM iaStorA=C:\WINDOWS\SYSTEM32\DRIVERS\IASTORA.SYS
### Intel Rapid Storage Technology driver - x64 Intel Corporation Intel Rapid
Storage Technology driver 12.8.5.1000 Service registry key doesn't exist or
hidden.
[Drivers] :HKLM iaStorAV=C:\WINDOWS\SYSTEM32\DRIVERS\IASTORAV.SYS
### Intel Rapid Storage Technology driver (inbox) - x64 Intel Corporation Intel
Rapid Storage Technology driver (inbox) 12.0.1.1018 Service registry key doesn't
exist or hidden.
[Drivers] :HKLM iaStorV=C:\WINDOWS\SYSTEM32\DRIVERS\IASTORV.SYS
### Intel Matrix Storage Manager driver - x64 Intel Corporation Intel Matrix
Storage Manager driver 8.6.2.1019 Service registry key doesn't exist or hidden.
[Drivers] :HKLM igfx=C:\WINDOWS\SYSTEM32\DRIVERS\IGDKMD64.SYS
### Intel Graphics Kernel Mode Driver Intel Corporation Intel HD Graphics Drivers
for Windows 8(R) 10.18.10.3496 !$*\SystemRoot\system32\DRIVERS\igdkmd64.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM intaud_WaveExtensible=C:\WINDOWS\SYSTEM32\DRIVERS\INTELAUD.SYS
### Intel WiDi Solution Intel Corporation Intel WiDi Solution 4.5.44.0 !
$*\SystemRoot\system32\drivers\intelaud.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM IntcDAud=C:\WINDOWS\SYSTEM32\DRIVERS\INTCDAUD.SYS
### Intel(R) Display Audio Driver Intel(R) Corporation Intel(R) Display Audio
6.16.00.3135 !$*\SystemRoot\system32\DRIVERS\IntcDAud.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM intelide=C:\WINDOWS\SYSTEM32\DRIVERS\INTELIDE.SYS
### Intel PCI IDE Driver Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 Service registry key doesn't exist or hidden.
[Drivers] :HKLM intelpep=C:\WINDOWS\SYSTEM32\DRIVERS\INTELPEP.SYS
### Intel Power Engine Plugin Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 Service registry key doesn't exist or hidden.
[Drivers] :HKLM intelppm=C:\WINDOWS\SYSTEM32\DRIVERS\INTELPPM.SYS
### Processor Device Driver Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*\SystemRoot\System32\drivers\intelppm.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM IpFilterDriver=C:\WINDOWS\SYSTEM32\DRIVERS\IPFLTDRV.SYS
### IP FILTER DRIVER Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 Service registry key doesn't exist or hidden.
[Drivers] :HKLM IPMIDRV=C:\WINDOWS\SYSTEM32\DRIVERS\IPMIDRV.SYS
### WMI IPMI DRIVER Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*\SystemRoot\System32\drivers\IPMIDrv.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM IPNAT=C:\WINDOWS\SYSTEM32\DRIVERS\IPNAT.SYS
### IP Network Address Translator Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 Service registry key doesn't exist or hidden.
[Drivers] :HKLM IRENUM=C:\WINDOWS\SYSTEM32\DRIVERS\IRENUM.SYS
### Infra-Red Bus Enumerator Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 Service registry key doesn't exist or hidden.
[Drivers] :HKLM isapnp=C:\WINDOWS\SYSTEM32\DRIVERS\ISAPNP.SYS
### PNP ISA Bus Driver Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 Service registry key doesn't exist or hidden.
[Drivers] :HKLM iScsiPrt=C:\WINDOWS\SYSTEM32\DRIVERS\MSISCSI.SYS
### Microsoft iSCSI Initiator Driver Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*\SystemRoot\System32\drivers\msiscsi.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM iwdbus=C:\WINDOWS\SYSTEM32\DRIVERS\IWDBUS.SYS
### Intel WiDi Solution Intel Corporation Intel WiDi Solution 4.5.44.0 !
$*\SystemRoot\System32\drivers\iwdbus.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM kbdclass=C:\WINDOWS\SYSTEM32\DRIVERS\KBDCLASS.SYS
### Keyboard Class Driver Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*\SystemRoot\System32\drivers\kbdclass.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM kbdhid=C:\WINDOWS\SYSTEM32\DRIVERS\KBDHID.SYS
### HID Keyboard Filter Driver Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*\SystemRoot\System32\drivers\kbdhid.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM kbfiltr=C:\WINDOWS\SYSTEM32\DRIVERS\KBFILTR.SYS
### Keyboard Filter Driver Keyboard Filter Driver 1.0.0.1 !
$*\SystemRoot\System32\drivers\kbfiltr.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM kbldfltr=C:\WINDOWS\SYSTEM32\DRIVERS\KBLDFLTR.SYS
### Keyboard Lockdown Subsystem Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 Service registry key doesn't exist or hidden.
[Drivers] :HKLM kdnic=C:\WINDOWS\SYSTEM32\DRIVERS\KDNIC.SYS
### Microsoft Kernel Debugger Network Miniport Microsoft Corporation Microsoft
Kernel Debugger Network Adapter (NDIS 6.20 Miniport) 6.01.00.0000 !
$*\SystemRoot\system32\DRIVERS\kdnic.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM KSecDD=C:\WINDOWS\SYSTEM32\DRIVERS\KSECDD.SYS
### Kernel Security Support Provider Interface Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 Service registry key doesn't exist or
hidden.
[Drivers] :HKLM KSecPkg=C:\WINDOWS\SYSTEM32\DRIVERS\KSECPKG.SYS
### Kernel Security Support Provider Interface Packages Microsoft Corporation
Microsoft Windows Operating System 6.3.9600.16384 Service registry key doesn't
exist or hidden.
[Drivers] :HKLM ksthunk=C:\WINDOWS\SYSTEM32\DRIVERS\KSTHUNK.SYS
### Kernel Streaming WOW Thunk Service Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*\SystemRoot\system32\drivers\ksthunk.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM lltdio=C:\WINDOWS\SYSTEM32\DRIVERS\LLTDIO.SYS
### Link-Layer Topology Mapper I/O Driver Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 !$*\SystemRoot\system32\DRIVERS\lltdio.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM LSI_SAS=C:\WINDOWS\SYSTEM32\DRIVERS\LSI_SAS.SYS
### LSI Fusion-MPT SAS Driver (StorPort) LSI Corporation LSI Fusion-MPT SAS
Driver (StorPort) 1.34.03.82 Service registry key doesn't exist or hidden.
[Drivers] :HKLM LSI_SAS2=C:\WINDOWS\SYSTEM32\DRIVERS\LSI_SAS2.SYS
### LSI SAS Gen2 Driver (StorPort) LSI Corporation LSI SAS Gen2 Driver (StorPort)
2.00.60.82 Service registry key doesn't exist or hidden.
[Drivers] :HKLM LSI_SAS3=C:\WINDOWS\SYSTEM32\DRIVERS\LSI_SAS3.SYS
### LSI SAS Gen3 Driver (StorPort) LSI Corporation LSI SAS Gen3 Driver (StorPort)
2.50.65.01 Service registry key doesn't exist or hidden.
[Drivers] :HKLM LSI_SSS=C:\WINDOWS\SYSTEM32\DRIVERS\LSI_SSS.SYS
### LSI SSS PCIe/Flash Driver (StorPort) LSI Corporation LSI SSS PCIe/Flash
Driver (StorPort) 2.10.61.81 Service registry key doesn't exist or hidden.
[Drivers] :HKLM luafv=C:\WINDOWS\SYSTEM32\DRIVERS\LUAFV.SYS
### LUA File Virtualization Filter Driver Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 !$*\SystemRoot\system32\drivers\luafv.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM massfilter=C:\Windows\system32\drivers\massfilter.sys
### File is missing. Service registry key doesn't exist or hidden.
[Drivers] :HKLM megasas=C:\WINDOWS\SYSTEM32\DRIVERS\MEGASAS.SYS
### MEGASAS RAID Controller Driver for Windows LSI Corporation MEGASAS RAID
Controller Driver for Windows 6.600.21.08 Service registry key doesn't exist or
hidden.
[Drivers] :HKLM megasr=C:\WINDOWS\SYSTEM32\DRIVERS\MEGASR.SYS
### LSI MegaRAID Software RAID Driver LSI Corporation, Inc. MegaRAID Software
RAID 15.02.2013.0129 Service registry key doesn't exist or hidden.
[Drivers] :HKLM MEIx64=C:\WINDOWS\SYSTEM32\DRIVERS\TEEDRIVERX64.SYS
### Intel(R) Management Engine Interface Intel Corporation Intel(R) Management
Engine Interface 9.5.24.1790 !$*\SystemRoot\system32\DRIVERS\TeeDriverx64.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM Modem=C:\WINDOWS\SYSTEM32\DRIVERS\MODEM.SYS
### Modem Device Driver Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 Service registry key doesn't exist or hidden.
[Drivers] :HKLM monitor=C:\WINDOWS\SYSTEM32\DRIVERS\MONITOR.SYS
### Monitor Driver Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*\SystemRoot\System32\drivers\monitor.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM mouclass=C:\WINDOWS\SYSTEM32\DRIVERS\MOUCLASS.SYS
### Mouse Class Driver Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*\SystemRoot\System32\drivers\mouclass.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM mouhid=C:\WINDOWS\SYSTEM32\DRIVERS\MOUHID.SYS
### HID Mouse Filter Driver Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*\SystemRoot\System32\drivers\mouhid.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM mountmgr=C:\WINDOWS\SYSTEM32\DRIVERS\MOUNTMGR.SYS
### Mount Point Manager Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 Service registry key doesn't exist or hidden.
[Drivers] :HKLM mpsdrv=C:\WINDOWS\SYSTEM32\DRIVERS\MPSDRV.SYS
### Microsoft Protection Service Driver Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 Service registry key doesn't exist or hidden.
[Drivers] :HKLM MRxDAV=C:\WINDOWS\SYSTEM32\DRIVERS\MRXDAV.SYS
### Windows NT WebDav Minirdr Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*\SystemRoot\system32\drivers\mrxdav.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM mrxsmb=C:\WINDOWS\SYSTEM32\DRIVERS\MRXSMB.SYS
### Windows NT SMB Minirdr Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 Service registry key doesn't exist or hidden.
[Drivers] :HKLM mrxsmb10=C:\WINDOWS\SYSTEM32\DRIVERS\MRXSMB10.SYS
### Longhorn SMB Downlevel SubRdr Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 Service registry key doesn't exist or hidden.
[Drivers] :HKLM mrxsmb20=C:\WINDOWS\SYSTEM32\DRIVERS\MRXSMB20.SYS
### Longhorn SMB 2.0 Redirector Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 Service registry key doesn't exist or hidden.
[Drivers] :HKLM MsBridge=C:\WINDOWS\SYSTEM32\DRIVERS\BRIDGE.SYS
### MAC Bridge Driver Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*\SystemRoot\system32\DRIVERS\bridge.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM msgpiowin32=C:\WINDOWS\SYSTEM32\DRIVERS\MSGPIOWIN32.SYS
### GPIO Button Driver Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*\SystemRoot\System32\drivers\msgpiowin32.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM mshidkmdf=C:\WINDOWS\SYSTEM32\DRIVERS\MSHIDKMDF.SYS
### Pass-through HID to KMDF Filter Driver Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 !
$*\SystemRoot\System32\drivers\mshidkmdf.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM mshidumdf=C:\WINDOWS\SYSTEM32\DRIVERS\MSHIDUMDF.SYS
### Pass-through Driver for HID-UMDF Interface Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 !
$*\SystemRoot\System32\drivers\mshidumdf.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM msisadrv=C:\WINDOWS\SYSTEM32\DRIVERS\MSISADRV.SYS
### ISA Driver Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 Service registry key doesn't exist or hidden.
[Drivers] :HKLM MSKSSRV=C:\WINDOWS\SYSTEM32\DRIVERS\MSKSSRV.SYS
### MS KS Server Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*\SystemRoot\system32\drivers\MSKSSRV.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM MsLldp=C:\WINDOWS\SYSTEM32\DRIVERS\MSLLDP.SYS
### Microsoft Link-Layer Discovery Protocol Driver Microsoft Corporation
Microsoft Windows Operating System 6.3.9600.16384 !
$*\SystemRoot\system32\DRIVERS\mslldp.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM MSPCLOCK=C:\WINDOWS\SYSTEM32\DRIVERS\MSPCLOCK.SYS
### MS Proxy Clock Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*\SystemRoot\system32\drivers\MSPCLOCK.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM MSPQM=C:\WINDOWS\SYSTEM32\DRIVERS\MSPQM.SYS
### MS Proxy Quality Manager Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*\SystemRoot\system32\drivers\MSPQM.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM mssmbios=C:\WINDOWS\SYSTEM32\DRIVERS\MSSMBIOS.SYS
### System Management BIOS Driver Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*\SystemRoot\System32\drivers\mssmbios.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM MSTEE=C:\WINDOWS\SYSTEM32\DRIVERS\MSTEE.SYS
### WDM Tee/Communication Transform Filter Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 !$*\SystemRoot\system32\drivers\MSTEE.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM MTConfig=C:\WINDOWS\SYSTEM32\DRIVERS\MTCONFIG.SYS
### Microsoft Multi-Touch HID Driver Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*\SystemRoot\System32\drivers\MTConfig.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM Mup=C:\WINDOWS\SYSTEM32\DRIVERS\MUP.SYS
### Multiple UNC Provider Driver Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 Service registry key doesn't exist or hidden.
[Drivers] :HKLM mvumis=C:\WINDOWS\SYSTEM32\DRIVERS\MVUMIS.SYS
### Marvell Flash Controller Driver Marvell Semiconductor, Inc. Marvell Flash
Controller 1.0.5.1015 Service registry key doesn't exist or hidden.
[Drivers] :HKLM NativeWifiP=C:\WINDOWS\SYSTEM32\DRIVERS\NWIFI.SYS
### NativeWiFi Miniport Driver Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*\SystemRoot\system32\DRIVERS\nwifi.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM NDIS=C:\WINDOWS\SYSTEM32\DRIVERS\NDIS.SYS
### Network Driver Interface Specification (NDIS) Microsoft Corporation
Microsoft Windows Operating System 6.3.9600.16384 Service registry key doesn't
exist or hidden.
[Drivers] :HKLM NdisCap=C:\WINDOWS\SYSTEM32\DRIVERS\NDISCAP.SYS
### Microsoft NDIS Packet Capture Filter Driver Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 !
$*\SystemRoot\system32\DRIVERS\ndiscap.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM NdisImPlatform=C:\WINDOWS\SYSTEM32\DRIVERS\NDISIMPLATFORM.SYS
### Microsoft Network Adapter Multiplexor Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 !
$*\SystemRoot\system32\DRIVERS\NdisImPlatform.sys Service registry key doesn't
exist or hidden.
[Drivers] :HKLM NdisTapi=C:\WINDOWS\SYSTEM32\DRIVERS\NDISTAPI.SYS
### NDIS 3.0 connection wrapper driver Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*\SystemRoot\system32\DRIVERS\ndistapi.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM Ndisuio=C:\WINDOWS\SYSTEM32\DRIVERS\NDISUIO.SYS
### NDIS User mode I/O driver Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*\SystemRoot\system32\DRIVERS\ndisuio.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM NdisVirtualBus=C:\WINDOWS\SYSTEM32\DRIVERS\NDISVIRTUALBUS.SYS
### Microsoft Virtual Network Adapter Enumerator Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 !
$*\SystemRoot\System32\drivers\NdisVirtualBus.sys Service registry key doesn't
exist or hidden.
[Drivers] :HKLM NdisWan=C:\WINDOWS\SYSTEM32\DRIVERS\NDISWAN.SYS
### MS PPP Framing Driver (Strong Encryption) Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 !
$*\SystemRoot\system32\DRIVERS\ndiswan.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM NdisWanLegacy=C:\WINDOWS\SYSTEM32\DRIVERS\NDISWAN.SYS
### MS PPP Framing Driver (Strong Encryption) Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 !
$*\SystemRoot\system32\DRIVERS\ndiswan.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM Ndu=C:\WINDOWS\SYSTEM32\DRIVERS\NDU.SYS
### Windows Network Data Usage Monitoring Driver Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 Service registry key doesn't exist or
hidden.
[Drivers] :HKLM NetBIOS=C:\WINDOWS\SYSTEM32\DRIVERS\NETBIOS.SYS
### NetBIOS interface driver Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 Service registry key doesn't exist or hidden.
[Drivers] :HKLM NetBT=C:\WINDOWS\SYSTEM32\DRIVERS\NETBT.SYS
### MBT Transport driver Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 Service registry key doesn't exist or hidden.
[Drivers] :HKLM netvsc=C:\WINDOWS\SYSTEM32\DRIVERS\NETVSC63.SYS
### Virtual NDIS6.3 Miniport Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*\SystemRoot\system32\DRIVERS\netvsc63.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM NPF=C:\WINDOWS\SYSTEM32\DRIVERS\NPF.SYS
### npf.sys (NT5/6 AMD64) Kernel Driver CACE Technologies, Inc. WinPcap
4.1.0.2001 Service registry key doesn't exist or hidden.
[Drivers] :HKLM npsvctrig=C:\WINDOWS\SYSTEM32\DRIVERS\NPSVCTRIG.SYS
### Named pipe service triggers Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*\SystemRoot\System32\drivers\npsvctrig.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM nsiproxy=C:\WINDOWS\SYSTEM32\DRIVERS\NSIPROXY.SYS
### NSI Proxy Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 Service registry key doesn't exist or hidden.
[Drivers] :HKLM nvlddmkm=C:\WINDOWS\SYSTEM32\DRIVERS\NVLDDMKM.SYS
### NVIDIA Windows Kernel Mode Driver, Version 333.17 NVIDIA Corporation NVIDIA
Windows Kernel Mode Driver, Version 333.17 9.18.13.3317 !
$*\SystemRoot\system32\DRIVERS\nvlddmkm.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM nvraid=C:\WINDOWS\SYSTEM32\DRIVERS\NVRAID.SYS
### NVIDIA nForce(TM) RAID Driver NVIDIA Corporation NVIDIA nForce(TM) RAID
Driver 10.6.0.22 Service registry key doesn't exist or hidden.
[Drivers] :HKLM nvstor=C:\WINDOWS\SYSTEM32\DRIVERS\NVSTOR.SYS
### NVIDIA nForce(TM) Sata Performance Driver NVIDIA Corporation NVIDIA
nForce(TM) SATA Driver 10.6.0.22 Service registry key doesn't exist or hidden.
[Drivers] :HKLM nv_agp=C:\WINDOWS\SYSTEM32\DRIVERS\NV_AGP.SYS
### NForce NT AGP Filter Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 Service registry key doesn't exist or hidden.
[Drivers] :HKLM Parport=C:\WINDOWS\SYSTEM32\DRIVERS\PARPORT.SYS
### Parallel Port Driver Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*\SystemRoot\System32\drivers\parport.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM Partizan=C:\Windows\system32\drivers\Partizan.sys
### File is missing. Service registry key doesn't exist or hidden.
[Drivers] :HKLM partmgr=C:\WINDOWS\SYSTEM32\DRIVERS\PARTMGR.SYS
### Partition Management Driver Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 Service registry key doesn't exist or hidden.
[Drivers] :HKLM pci=C:\WINDOWS\SYSTEM32\DRIVERS\PCI.SYS
### NT Plug and Play PCI Enumerator Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 Service registry key doesn't exist or hidden.
[Drivers] :HKLM pciide=C:\WINDOWS\SYSTEM32\DRIVERS\PCIIDE.SYS
### Generic PCI IDE Bus Driver Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 Service registry key doesn't exist or hidden.
[Drivers] :HKLM pcmcia=C:\WINDOWS\SYSTEM32\DRIVERS\PCMCIA.SYS
### PCMCIA Bus Driver Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 Service registry key doesn't exist or hidden.
[Drivers] :HKLM pcw=C:\WINDOWS\SYSTEM32\DRIVERS\PCW.SYS
### Performance Counters for Windows Driver Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 Service registry key doesn't exist or
hidden.
[Drivers] :HKLM pdc=C:\WINDOWS\SYSTEM32\DRIVERS\PDC.SYS
### Power Dependency Coordinator Driver Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 Service registry key doesn't exist or hidden.
[Drivers] :HKLM PEAUTH=C:\WINDOWS\SYSTEM32\DRIVERS\PEAUTH.SYS
### Protected Environment Authentication and Authorization Export Driver
Microsoft Corporation Microsoft Windows Operating System 6.3.9600.16384 Service
registry key doesn't exist or hidden.
[Drivers] :HKLM PptpMiniport=C:\WINDOWS\SYSTEM32\DRIVERS\RASPPTP.SYS
### Peer-to-Peer Tunneling Protocol Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*\SystemRoot\system32\DRIVERS\raspptp.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM Processor=C:\WINDOWS\SYSTEM32\DRIVERS\PROCESSR.SYS
### Processor Device Driver Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*\SystemRoot\System32\drivers\processr.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM Psched=C:\WINDOWS\SYSTEM32\DRIVERS\PACER.SYS
### QoS Packet Scheduler Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*\SystemRoot\system32\DRIVERS\pacer.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM QWAVEdrv=C:\WINDOWS\SYSTEM32\DRIVERS\QWAVEDRV.SYS
### Microsoft Quality Windows Audio Video Experience (qWave) Support Driver
Microsoft Corporation Microsoft Windows Operating System 6.3.9600.16384 !
$*\SystemRoot\system32\drivers\qwavedrv.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM RasAcd=C:\WINDOWS\SYSTEM32\DRIVERS\RASACD.SYS
### RAS Automatic Connection Driver Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 Service registry key doesn't exist or hidden.
[Drivers] :HKLM RasAgileVpn=C:\WINDOWS\SYSTEM32\DRIVERS\AGILEVPN.SYS
### RAS Agile Vpn Miniport Call Manager Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*\SystemRoot\system32\DRIVERS\AgileVpn.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM Rasl2tp=C:\WINDOWS\SYSTEM32\DRIVERS\RASL2TP.SYS
### RAS L2TP mini-port/call-manager driver Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 !
$*\SystemRoot\system32\DRIVERS\rasl2tp.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM RasPppoe=C:\WINDOWS\SYSTEM32\DRIVERS\RASPPPOE.SYS
### RAS PPPoE mini-port/call-manager driver Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 !
$*\SystemRoot\system32\DRIVERS\raspppoe.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM RasSstp=C:\WINDOWS\SYSTEM32\DRIVERS\RASSSTP.SYS
### RAS SSTP Miniport Call Manager Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*\SystemRoot\system32\DRIVERS\rassstp.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM rdbss=C:\WINDOWS\SYSTEM32\DRIVERS\RDBSS.SYS
### Redirected Drive Buffering SubSystem Driver Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 Service registry key doesn't exist or
hidden.
[Drivers] :HKLM rdpbus=C:\WINDOWS\SYSTEM32\DRIVERS\RDPBUS.SYS
### Microsoft RDP Bus Device driver Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*\SystemRoot\System32\drivers\rdpbus.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM RDPDR=C:\WINDOWS\SYSTEM32\DRIVERS\RDPDR.SYS
### Microsoft RDP Device redirector Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 Service registry key doesn't exist or hidden.
[Drivers] :HKLM RdpVideoMiniport=C:\WINDOWS\SYSTEM32\DRIVERS\RDPVIDEOMINIPORT.SYS
### Microsoft RDP Video Miniport driver Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 Service registry key doesn't exist or hidden.
[Drivers] :HKLM rdyboost=C:\WINDOWS\SYSTEM32\DRIVERS\RDYBOOST.SYS
### ReadyBoost Driver Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 Service registry key doesn't exist or hidden.
[Drivers] :HKLM RFCOMM=C:\WINDOWS\SYSTEM32\DRIVERS\RFCOMM.SYS
### Bluetooth RFCOMM Driver Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*\SystemRoot\system32\DRIVERS\rfcomm.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM rspndr=C:\WINDOWS\SYSTEM32\DRIVERS\RSPNDR.SYS
### Link-Layer Topology Responder Driver for NDIS 6 Microsoft Corporation
Microsoft Windows Operating System 6.3.9600.16384 !
$*\SystemRoot\system32\DRIVERS\rspndr.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM RTL8168=C:\WINDOWS\SYSTEM32\DRIVERS\RT630X64.SYS
### Realtek 8101E/8168/8169 NDIS 6.30 64-bit Driver Realtek
Realtek 8136/8168/8169 PCI/PCIe Adapters 8.033.0529.2014 !
$*\SystemRoot\system32\DRIVERS\Rt630x64.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM s3cap=C:\WINDOWS\SYSTEM32\DRIVERS\VMS3CAP.SYS
### Microsoft S3 Emulated Device Cap Driver Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 !
$*\SystemRoot\System32\drivers\vms3cap.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM sbp2port=C:\WINDOWS\SYSTEM32\DRIVERS\SBP2PORT.SYS
### SBP-2 Protocol Driver Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 Service registry key doesn't exist or hidden.
[Drivers] :HKLM scfilter=C:\WINDOWS\SYSTEM32\DRIVERS\SCFILTER.SYS
### Microsoft Smart Card Reader Filter Driver Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 Service registry key doesn't exist or
hidden.
[Drivers] :HKLM sdbus=C:\WINDOWS\SYSTEM32\DRIVERS\SDBUS.SYS
### SecureDigital Bus Driver Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*\SystemRoot\System32\drivers\sdbus.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM sdstor=C:\WINDOWS\SYSTEM32\DRIVERS\SDSTOR.SYS
### SD Storage Class Driver Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*\SystemRoot\System32\drivers\sdstor.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM SerCx=C:\WINDOWS\SYSTEM32\DRIVERS\SERCX.SYS
### Serial Class Extension Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 Service registry key doesn't exist or hidden.
[Drivers] :HKLM SerCx2=C:\WINDOWS\SYSTEM32\DRIVERS\SERCX2.SYS
### Serial Class Extension V2 Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 Service registry key doesn't exist or hidden.
[Drivers] :HKLM Serenum=C:\WINDOWS\SYSTEM32\DRIVERS\SERENUM.SYS
### Serial Port Enumerator Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*\SystemRoot\System32\drivers\serenum.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM Serial=C:\WINDOWS\SYSTEM32\DRIVERS\SERIAL.SYS
### Serial Device Driver Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*\SystemRoot\System32\drivers\serial.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM sermouse=C:\WINDOWS\SYSTEM32\DRIVERS\SERMOUSE.SYS
### Serial Mouse Filter Driver Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*\SystemRoot\System32\drivers\sermouse.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM sfloppy=C:\WINDOWS\SYSTEM32\DRIVERS\SFLOPPY.SYS
### SCSI Floppy Driver Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*\SystemRoot\System32\drivers\sfloppy.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM SiSRaid2=C:\WINDOWS\SYSTEM32\DRIVERS\SISRAID2.SYS
### SiS RAID Stor Miniport Driver Silicon Integrated Systems Corp. Microsoft
Windows Operating System 2.60.01 Service registry key doesn't exist or hidden.
[Drivers] :HKLM SiSRaid4=C:\WINDOWS\SYSTEM32\DRIVERS\SISRAID4.SYS
### SiS AHCI Stor-Miniport Driver Silicon Integrated Systems Microsoft Windows
Operating System 6.1.6918.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM spaceport=C:\WINDOWS\SYSTEM32\DRIVERS\SPACEPORT.SYS
### Storage Spaces Driver Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 Service registry key doesn't exist or hidden.
[Drivers] :HKLM SpbCx=C:\WINDOWS\SYSTEM32\DRIVERS\SPBCX.SYS
### SPB Class Extension Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 Service registry key doesn't exist or hidden.
[Drivers] :HKLM sptd=C:\WINDOWS\SYSTEM32\DRIVERS\SPTD.SYS
### SCSI Pass Through Direct Host Duplex Secure Ltd. SCSI Pass Through Direct
1.81.0.0 !$*\SystemRoot\System32\Drivers\sptd.sys Service registry key doesn't
exist or hidden.
[Drivers] :HKLM srv=C:\WINDOWS\SYSTEM32\DRIVERS\SRV.SYS
### Server driver Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 Service registry key doesn't exist or hidden.
[Drivers] :HKLM srv2=C:\WINDOWS\SYSTEM32\DRIVERS\SRV2.SYS
### Smb 2.0 Server driver Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 Service registry key doesn't exist or hidden.
[Drivers] :HKLM srvnet=C:\WINDOWS\SYSTEM32\DRIVERS\SRVNET.SYS
### Server Network driver Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 Service registry key doesn't exist or hidden.
[Drivers] :HKLM ssudmdm=C:\WINDOWS\SYSTEM32\DRIVERS\SSUDMDM.SYS
### SAMSUNG Android Modem Device Driver Samsung Electronics Co., Ltd. SAMSUNG
Android Modem Device Driver 2.12.4.0 !$*\SystemRoot\system32\DRIVERS\ssudmdm.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM ssudserd=C:\WINDOWS\SYSTEM32\DRIVERS\SSUDSERD.SYS
### SAMSUNG USB Mobile Logging Device Driver (MSS Ver.3) DEVGURU Co., LTD.
(www.devguru.co.kr) SAMSUNG USB Mobile Logging Device Driver (MSS Ver.3) 2.11.7.0 !
$*\SystemRoot\system32\DRIVERS\ssudserd.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM stexstor=C:\WINDOWS\SYSTEM32\DRIVERS\STEXSTOR.SYS
### Promise SuperTrak EX Series Driver for Windows x64 Promise Technology, Inc.
Promise SuperTrak EX Series 5.1.0000.10 Service registry key doesn't exist or
hidden.
[Drivers] :HKLM storahci=C:\WINDOWS\SYSTEM32\DRIVERS\STORAHCI.SYS
### MS AHCI Storport Miniport Driver Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 Service registry key doesn't exist or hidden.
[Drivers] :HKLM storflt=C:\WINDOWS\SYSTEM32\DRIVERS\VMSTORFL.SYS
### Virtual Storage Filter Driver Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 Service registry key doesn't exist or hidden.
[Drivers] :HKLM stornvme=C:\WINDOWS\SYSTEM32\DRIVERS\STORNVME.SYS
### Microsoft NVM Express Storport Miniport Driver Microsoft Corporation
Microsoft Windows Operating System 6.3.9600.16384 Service registry key doesn't
exist or hidden.
[Drivers] :HKLM storvsc=C:\WINDOWS\SYSTEM32\DRIVERS\STORVSC.SYS
### Storage VSC Driver Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 Service registry key doesn't exist or hidden.
[Drivers] :HKLM storvsp=C:\WINDOWS\SYSTEM32\DRIVERS\STORVSP.SYS
### Storage vsp Driver Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*\SystemRoot\System32\drivers\storvsp.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM swenum=C:\WINDOWS\SYSTEM32\DRIVERS\SWENUM.SYS
### Plug and Play Software Device Enumerator Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 !$*\SystemRoot\System32\drivers\swenum.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM Tcpip=C:\WINDOWS\SYSTEM32\DRIVERS\TCPIP.SYS
### TCP/IP Driver Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 Service registry key doesn't exist or hidden.
[Drivers] :HKLM TCPIP6=C:\WINDOWS\SYSTEM32\DRIVERS\TCPIP.SYS
### TCP/IP Driver Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*\SystemRoot\system32\DRIVERS\tcpip.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM tcpipreg=C:\WINDOWS\SYSTEM32\DRIVERS\TCPIPREG.SYS
### TCP/IP Registry Compatibility Driver Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 Service registry key doesn't exist or
hidden.
[Drivers] :HKLM tdx=C:\WINDOWS\SYSTEM32\DRIVERS\TDX.SYS
### TDI Translation Driver Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*\SystemRoot\system32\DRIVERS\tdx.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM terminpt=C:\WINDOWS\SYSTEM32\DRIVERS\TERMINPT.SYS
### Terminal Server Input Driver Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*\SystemRoot\System32\drivers\terminpt.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM TPM=C:\WINDOWS\SYSTEM32\DRIVERS\TPM.SYS
### TPM Device Driver Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*\SystemRoot\system32\drivers\tpm.sys Service registry key doesn't
exist or hidden.
[Drivers] :HKLM TsUsbFlt=C:\WINDOWS\SYSTEM32\DRIVERS\TSUSBFLT.SYS
### Remote Desktop USB Hub Filter Driver Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 Service registry key doesn't exist or
hidden.
[Drivers] :HKLM TsUsbGD=C:\WINDOWS\SYSTEM32\DRIVERS\TSUSBGD.SYS
### Remote Desktop Generic USB Driver Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*\SystemRoot\System32\drivers\TsUsbGD.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM tunnel=C:\WINDOWS\SYSTEM32\DRIVERS\TUNNEL.SYS
### Microsoft Tunnel Interface Driver Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*\SystemRoot\system32\DRIVERS\tunnel.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM uagp35=C:\WINDOWS\SYSTEM32\DRIVERS\UAGP35.SYS
### MS AGPv3.5 Filter Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 Service registry key doesn't exist or hidden.
[Drivers] :HKLM UASPStor=C:\WINDOWS\SYSTEM32\DRIVERS\UASPSTOR.SYS
### Microsoft Uasp Driver Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*\SystemRoot\System32\drivers\uaspstor.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM UCX01000=C:\WINDOWS\SYSTEM32\DRIVERS\UCX01000.SYS
### USB Controller Extension Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*\SystemRoot\System32\drivers\ucx01000.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM udfs=C:\WINDOWS\SYSTEM32\DRIVERS\UDFS.SYS
### UDF File System Driver Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 Service registry key doesn't exist or hidden.
[Drivers] :HKLM UEFI=C:\WINDOWS\SYSTEM32\DRIVERS\UEFI.SYS
### UEFI Driver for NT Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*\SystemRoot\System32\drivers\UEFI.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM uliagpkx=C:\WINDOWS\SYSTEM32\DRIVERS\ULIAGPKX.SYS
### ULi AGPv3.0 Filter for K8/9 Processor Platforms Microsoft Corporation
Microsoft Windows Operating System 6.3.9600.16384 Service registry key doesn't
exist or hidden.
[Drivers] :HKLM umbus=C:\WINDOWS\SYSTEM32\DRIVERS\UMBUS.SYS
### User-Mode Bus Enumerator Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*\SystemRoot\System32\drivers\umbus.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM UmPass=C:\WINDOWS\SYSTEM32\DRIVERS\UMPASS.SYS
### Generic pass-through driver Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*\SystemRoot\System32\drivers\umpass.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM usbccgp=C:\WINDOWS\SYSTEM32\DRIVERS\USBCCGP.SYS
### USB Common Class Generic Parent Driver Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 !
$*\SystemRoot\System32\drivers\usbccgp.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM usbcir=C:\WINDOWS\SYSTEM32\DRIVERS\USBCIR.SYS
### USB Consumer IR Driver for eHome Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*\SystemRoot\System32\drivers\usbcir.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM usbehci=C:\WINDOWS\SYSTEM32\DRIVERS\USBEHCI.SYS
### EHCI eUSB Miniport Driver Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*\SystemRoot\System32\drivers\usbehci.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM usbhub=C:\WINDOWS\SYSTEM32\DRIVERS\USBHUB.SYS
### Default Hub Driver for USB Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*\SystemRoot\System32\drivers\usbhub.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM USBHUB3=C:\WINDOWS\SYSTEM32\DRIVERS\USBHUB3.SYS
### USB3 HUB Driver Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*\SystemRoot\System32\drivers\UsbHub3.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM usbohci=C:\WINDOWS\SYSTEM32\DRIVERS\USBOHCI.SYS
### OHCI USB Miniport Driver Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*\SystemRoot\System32\drivers\usbohci.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM usbprint=C:\WINDOWS\SYSTEM32\DRIVERS\USBPRINT.SYS
### USB Printer driver Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*\SystemRoot\System32\drivers\usbprint.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM usbrndis6=C:\WINDOWS\SYSTEM32\DRIVERS\USB80236.SYS
### Remote NDIS USB Driver Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*\SystemRoot\system32\DRIVERS\usb80236.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM usbscan=C:\WINDOWS\SYSTEM32\DRIVERS\USBSCAN.SYS
### USB Scanner Driver Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*\SystemRoot\system32\DRIVERS\usbscan.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM USBSTOR=C:\WINDOWS\SYSTEM32\DRIVERS\USBSTOR.SYS
### USB Mass Storage Class Driver Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*\SystemRoot\System32\drivers\USBSTOR.SYS Service
registry key doesn't exist or hidden.
[Drivers] :HKLM usbuhci=C:\WINDOWS\SYSTEM32\DRIVERS\USBUHCI.SYS
### UHCI USB Miniport Driver Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*\SystemRoot\System32\drivers\usbuhci.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM usbvideo=C:\WINDOWS\SYSTEM32\DRIVERS\USBVIDEO.SYS
### USB Video Class Driver Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*\SystemRoot\System32\Drivers\usbvideo.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM USBXHCI=C:\WINDOWS\SYSTEM32\DRIVERS\USBXHCI.SYS
### USB XHCI Driver Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*\SystemRoot\System32\drivers\USBXHCI.SYS Service registry key
doesn't exist or hidden.
[Drivers] :HKLM usb_rndisx=C:\WINDOWS\SYSTEM32\DRIVERS\USB8023X.SYS
### Remote NDIS USB Driver Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*\SystemRoot\system32\DRIVERS\usb8023x.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM vdrvroot=C:\WINDOWS\SYSTEM32\DRIVERS\VDRVROOT.SYS
### Virtual Drive Root Enumerator Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 Service registry key doesn't exist or hidden.
[Drivers] :HKLM VerifierExt=C:\WINDOWS\SYSTEM32\DRIVERS\VERIFIEREXT.SYS
### Driver Verifier Extension Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 Service registry key doesn't exist or hidden.
[Drivers] :HKLM vhdmp=C:\WINDOWS\SYSTEM32\DRIVERS\VHDMP.SYS
### VHD Miniport Driver Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*\SystemRoot\System32\drivers\vhdmp.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM viaide=C:\WINDOWS\SYSTEM32\DRIVERS\VIAIDE.SYS
### VIA Generic PCI IDE Bus Driver VIA Technologies, Inc. VIA PCI IDE MINI Driver
6,0,6000,170 Service registry key doesn't exist or hidden.
[Drivers] :HKLM Vid=C:\WINDOWS\SYSTEM32\DRIVERS\VID.SYS
### Microsoft Hyper-V Virtualization Infrastructure Driver Microsoft Corporation
Microsoft Windows Operating System 6.3.9600.16384 !
$*\SystemRoot\System32\drivers\Vid.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM vmbus=C:\WINDOWS\SYSTEM32\DRIVERS\VMBUS.SYS
### Microsoft Hyper-V Virtual Machine Bus Child Driver Microsoft Corporation
Microsoft Windows Operating System 6.3.9600.16384 Service registry key doesn't
exist or hidden.
[Drivers] :HKLM VMBusHID=C:\WINDOWS\SYSTEM32\DRIVERS\VMBUSHID.SYS
### Microsoft VMBus HID Miniport Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*\SystemRoot\System32\drivers\VMBusHID.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM vmbusr=C:\WINDOWS\SYSTEM32\DRIVERS\VMBUSR.SYS
### Microsoft Hyper-V Virtual Machine Bus Root Driver Microsoft Corporation
Microsoft Windows Operating System 6.3.9600.16384 !
$*\SystemRoot\System32\drivers\vmbusr.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM volmgr=C:\WINDOWS\SYSTEM32\DRIVERS\VOLMGR.SYS
### Volume Manager Driver Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 Service registry key doesn't exist or hidden.
[Drivers] :HKLM volmgrx=C:\WINDOWS\SYSTEM32\DRIVERS\VOLMGRX.SYS
### Volume Manager Extension Driver Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 Service registry key doesn't exist or hidden.
[Drivers] :HKLM volsnap=C:\WINDOWS\SYSTEM32\DRIVERS\VOLSNAP.SYS
### Volume Shadow Copy Driver Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 Service registry key doesn't exist or hidden.
[Drivers] :HKLM vpci=C:\WINDOWS\SYSTEM32\DRIVERS\VPCI.SYS
### Virtual PCI Bus Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*\SystemRoot\System32\drivers\vpci.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM vpcivsp=C:\WINDOWS\SYSTEM32\DRIVERS\VPCIVSP.SYS
### Virtual PCI VSP Driver Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*\SystemRoot\System32\drivers\vpcivsp.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM vsmraid=C:\WINDOWS\SYSTEM32\DRIVERS\VSMRAID.SYS
### VIA RAID DRIVER FOR AMD-X86-64 VIA Technologies Inc.,Ltd VIA RAID driver
7.0.9200,6320 Service registry key doesn't exist or hidden.
[Drivers] :HKLM VSTXRAID=C:\WINDOWS\SYSTEM32\DRIVERS\VSTXRAID.SYS
### VIA StorX RAID Controller Driver VIA Corporation VIA StorX RAID Controller
Driver 8.0.9200.8110 Service registry key doesn't exist or hidden.
[Drivers] :HKLM vwifibus=C:\WINDOWS\SYSTEM32\DRIVERS\VWIFIBUS.SYS
### Virtual WiFi Bus Driver Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*\SystemRoot\System32\drivers\vwifibus.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM vwififlt=C:\WINDOWS\SYSTEM32\DRIVERS\VWIFIFLT.SYS
### Virtual WiFi Filter Driver Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*\SystemRoot\system32\DRIVERS\vwififlt.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM vwifimp=C:\WINDOWS\SYSTEM32\DRIVERS\VWIFIMP.SYS
### Virtual WiFi Miniport Driver Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*\SystemRoot\system32\DRIVERS\vwifimp.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM WacomPen=C:\WINDOWS\SYSTEM32\DRIVERS\WACOMPEN.SYS
### Wacom Serial Pen Tablet HID Driver Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*\SystemRoot\System32\drivers\wacompen.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM Wanarp=C:\WINDOWS\SYSTEM32\DRIVERS\WANARP.SYS
### MS Remote Access and Routing ARP Driver Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 !$*\SystemRoot\system32\DRIVERS\wanarp.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM Wanarpv6=C:\WINDOWS\SYSTEM32\DRIVERS\WANARP.SYS
### MS Remote Access and Routing ARP Driver Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 !$*\SystemRoot\system32\DRIVERS\wanarp.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM WdBoot=C:\WINDOWS\SYSTEM32\DRIVERS\WDBOOT.SYS
### Microsoft antimalware boot driver Microsoft Corporation Microsoft Windows
Operating System 4.3.9600.16384 Service registry key doesn't exist or hidden.
[Drivers] :HKLM Wdf01000=C:\WINDOWS\SYSTEM32\DRIVERS\WDF01000.SYS
### Kernel Mode Driver Framework Runtime Microsoft Corporation Microsoft
Windows Operating System 1.13.9600.16384 Service registry key doesn't exist or
hidden.
[Drivers] :HKLM WdFilter=C:\WINDOWS\SYSTEM32\DRIVERS\WDFILTER.SYS
### Microsoft antimalware file system filter driver Microsoft Corporation
Microsoft Windows Operating System 4.3.9600.16384 Service registry key doesn't
exist or hidden.
[Drivers] :HKLM WdNisDrv=C:\WINDOWS\SYSTEM32\DRIVERS\WDNISDRV.SYS
### Microsoft Network Realtime Inspection Driver Microsoft Corporation Microsoft
Windows Operating System 4.3.9600.16384 Service registry key doesn't exist or
hidden.
[Drivers] :HKLM WFPLWFS=C:\WINDOWS\SYSTEM32\DRIVERS\WFPLWFS.SYS
### WFP NDIS 6.30 Lightweight Filter Driver Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 Service registry key doesn't exist or
hidden.
[Drivers] :HKLM WIMMount=C:\WINDOWS\SYSTEM32\DRIVERS\WIMMOUNT.SYS
### Wim file system Driver Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 Service registry key doesn't exist or hidden.
[Drivers] :HKLM WinUsb=C:\WINDOWS\SYSTEM32\DRIVERS\WINUSB.SYS
### Windows WinUSB Class Driver Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*\SystemRoot\system32\DRIVERS\WinUsb.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM WmiAcpi=C:\WINDOWS\SYSTEM32\DRIVERS\WMIACPI.SYS
### Windows Management Interface for ACPI Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 !
$*\SystemRoot\System32\drivers\wmiacpi.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM wpcfltr=C:\WINDOWS\SYSTEM32\DRIVERS\WPCFLTR.SYS
### Family Safety Filter Driver Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 Service registry key doesn't exist or hidden.
[Drivers] :HKLM WpdUpFltr=C:\WINDOWS\SYSTEM32\DRIVERS\WPDUPFLTR.SYS
### Windows Portable Device Upper Class Filter Driver Microsoft Corporation
Microsoft Windows Operating System 6.3.9600.16384 Service registry key doesn't
exist or hidden.
[Drivers] :HKLM ws2ifsl=C:\WINDOWS\SYSTEM32\DRIVERS\WS2IFSL.SYS
### Winsock2 IFS Layer Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*\SystemRoot\system32\drivers\ws2ifsl.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM WudfPf=C:\WINDOWS\SYSTEM32\DRIVERS\WUDFPF.SYS
### Windows Driver Foundation - User-mode Driver Framework Platform Driver
Microsoft Corporation Microsoft Windows Operating System 6.3.9600.16384 Service
registry key doesn't exist or hidden.
[Drivers] :HKLM WUDFRd=C:\WINDOWS\SYSTEM32\DRIVERS\WUDFRD.SYS
### Windows Driver Foundation - User-mode Driver Framework Reflector Microsoft
Corporation Microsoft Windows Operating System 6.3.9600.16384 !
$*\SystemRoot\System32\drivers\WUDFRd.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM WUDFSensorLP=C:\WINDOWS\SYSTEM32\DRIVERS\WUDFRD.SYS
### Windows Driver Foundation - User-mode Driver Framework Reflector Microsoft
Corporation Microsoft Windows Operating System 6.3.9600.16384 !
$*\SystemRoot\system32\DRIVERS\WUDFRd.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM WUDFWpdFs=C:\WINDOWS\SYSTEM32\DRIVERS\WUDFRD.SYS
### Windows Driver Foundation - User-mode Driver Framework Reflector Microsoft
Corporation Microsoft Windows Operating System 6.3.9600.16384 !
$*\SystemRoot\system32\DRIVERS\WUDFRd.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM WUDFWpdMtp=C:\WINDOWS\SYSTEM32\DRIVERS\WUDFRD.SYS
### Windows Driver Foundation - User-mode Driver Framework Reflector Microsoft
Corporation Microsoft Windows Operating System 6.3.9600.16384 !
$*\SystemRoot\system32\DRIVERS\WUDFRd.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM ZTEusbmdm6k=\SystemRoot\system32\DRIVERS\ZTEusbmdm6k.sys
### !$*\SystemRoot\system32\DRIVERS\ZTEusbmdm6k.sys File is missing. Service
registry key doesn't exist or hidden.
[Drivers] :HKLM ZTEusbnmea=\SystemRoot\system32\DRIVERS\ZTEusbnmea.sys
### !$*\SystemRoot\system32\DRIVERS\ZTEusbnmea.sys File is missing. Service
registry key doesn't exist or hidden.
[Drivers] :HKLM ZTEusbser6k=\SystemRoot\system32\DRIVERS\ZTEusbser6k.sys
### !$*\SystemRoot\system32\DRIVERS\ZTEusbser6k.sys File is missing. Service
registry key doesn't exist or hidden.
[Codecs] :HKLM msacm.msgsm610=C:\Windows\SYSTEM32\MSGSM32.ACM
### Microsoft GSM 6.10 Audio CODEC for MSACM Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 !$*msgsm32.acm
[Codecs] :HKLM msacm.msg711=C:\Windows\SYSTEM32\MSG711.ACM
### Microsoft CCITT G.711 (A-Law and u-Law) CODEC for MSACM Microsoft Corporation
Microsoft Windows Operating System 6.3.9600.16384 !$*msg711.acm
[Codecs] :HKLM msacm.l3acm=C:\WINDOWS\SYSWOW64\L3CODECA.ACM
### MPEG Layer-3 Audio Codec for MSACM Fraunhofer Institut Integrierte
Schaltungen IIS MPEG Layer-3 Audio Codec for MSACM 1, 0, 0, 0
[Codecs] :HKLM vidc.yuy2=C:\Windows\SYSTEM32\MSYUV.DLL
### Microsoft UYVY Video Decompressor Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*msyuv.dll
[Codecs] :HKLM vidc.i420=C:\Windows\SYSTEM32\IYUV_32.DLL
### Intel Indeo(R) Video YUV Codec Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*iyuv_32.dll
[Codecs] :HKLM vidc.cvid=C:\WINDOWS\Syswow64\ICCVID.DLL
### Cinepak Codec Radius Inc. Cinepak for Windows 32 1.10.0.0 !$*iccvid.dll
[Codecs] :HKLM vidc.yvyu=C:\Windows\SYSTEM32\MSYUV.DLL
### Microsoft UYVY Video Decompressor Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*msyuv.dll
[Codecs] :HKLM vidc.yvu9=C:\Windows\SYSTEM32\TSBYUV.DLL
### Toshiba Video Codec Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*tsbyuv.dll
[Codecs] :HKLM wavemapper=C:\Windows\SYSTEM32\MSACM32.DRV
### Microsoft Sound Mapper Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*msacm32.drv
[Codecs] :HKLM midimapper=C:\Windows\SYSTEM32\MIDIMAP.DLL
### Microsoft MIDI Mapper Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*midimap.dll
[Codecs] :HKLM vidc.uyvy=C:\Windows\SYSTEM32\MSYUV.DLL
### Microsoft UYVY Video Decompressor Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*msyuv.dll
[Codecs] :HKLM msacm.imaadpcm=C:\Windows\SYSTEM32\IMAADP32.ACM
### IMA ADPCM CODEC for MSACM Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*imaadp32.acm
[Codecs] :HKLM msacm.msadpcm=C:\Windows\SYSTEM32\MSADP32.ACM
### Microsoft ADPCM CODEC for MSACM Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*msadp32.acm
[Codecs] :HKLM vidc.iyuv=C:\Windows\SYSTEM32\IYUV_32.DLL
### Intel Indeo(R) Video YUV Codec Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*iyuv_32.dll
[Codecs] :HKLM vidc.mrle=C:\Windows\SYSTEM32\MSRLE32.DLL
### Microsoft RLE Compressor Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*msrle32.dll
[Codecs] :HKLM vidc.msvc=C:\Windows\SYSTEM32\MSVIDC32.DLL
### Microsoft Video 1 Compressor Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*msvidc32.dll
[Codecs] :HKLM wave1=C:\Windows\SYSTEM32\WDMAUD.DRV
### Winmm audio system driver Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*wdmaud.drv
[Codecs] :HKLM midi1=C:\Windows\SYSTEM32\WDMAUD.DRV
### Winmm audio system driver Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*wdmaud.drv
[Codecs] :HKLM mixer1=C:\Windows\SYSTEM32\WDMAUD.DRV
### Winmm audio system driver Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*wdmaud.drv
[Codecs] :HKLM aux1=C:\Windows\SYSTEM32\WDMAUD.DRV
### Winmm audio system driver Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*wdmaud.drv
[Codecs] :HKLM wave=C:\Windows\SYSTEM32\WDMAUD.DRV
### Winmm audio system driver Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*wdmaud.drv
[Codecs] :HKLM midi=C:\Windows\SYSTEM32\WDMAUD.DRV
### Winmm audio system driver Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*wdmaud.drv
[Codecs] :HKLM mixer=C:\Windows\SYSTEM32\WDMAUD.DRV
### Winmm audio system driver Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*wdmaud.drv
[Codecs] :HKLM aux=C:\Windows\SYSTEM32\WDMAUD.DRV
### Winmm audio system driver Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*wdmaud.drv
[Codecs] :HKLM msacm.divxa32=C:\WINDOWS\Syswow64\MSAUD32_DIVX.ACM
### Windows Media Audio Microsoft Corporation Windows Media Audio 8.00.00.4487 !
$*msaud32_divx.acm
[Codecs] :HKLM wave4=C:\Windows\SYSTEM32\WDMAUD.DRV
### Winmm audio system driver Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*wdmaud.drv
[Codecs] :HKLM mixer4=C:\Windows\SYSTEM32\WDMAUD.DRV
### Winmm audio system driver Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*wdmaud.drv
[Codecs] :HKLM midi4=C:\Windows\SYSTEM32\WDMAUD.DRV
### Winmm audio system driver Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*wdmaud.drv
[DCOM Components] :HKLM {F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}=""
[DCOM Components] :HKLM {5839FCA9-774D-42A1-ACDA-
D6A79037F57F}=C:\WINDOWS\SYSTEM32\WBEM\FASTPROX.DLL
### WMI Custom Marshaller Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384
[DCOM Components] :HKLM {42AEDC87-2188-41FD-B9A3-
0C966FEABEC1}=C:\WINDOWS\SYSTEM32\SHELL32.DLL
### Windows Shell Common Dll Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384
[DCOM User Components] :HKCU {F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}=""
[DCOM User Components] :HKCU {FBEB8A05-BEEE-4442-804E-409D6C4515E9}=""
[DCOM User Components] :HKCU {42AEDC87-2188-41FD-B9A3-0C966FEABEC1}=""
[Auto Start Apps]
[Registry Run] :HKCU Akamai NetSession
Interface=C:\USERS\USER\APPDATA\LOCAL\AKAMAI\NETSESSION_WIN.EXE
### Akamai NetSession Client Akamai Technologies, Inc. Akamai NetSession Client
1.9.1.5 !$*"C:\Users\User\AppData\Local\Akamai\netsession_win.exe"
[Registry Run] :HKCU zzz=C:\Windows\SYSTEM32\WSCRIPT.EXE
### Microsoft Windows Based Script Host Microsoft Corporation Microsoft
Windows Script Host 5.8.9600.16384 !$*wscript.exe //B
"C:\Users\User\AppData\Local\Temp\zzz.vbs"
[Registry Run] :HKLM Adobe ARM=C:\PROGRAM FILES (X86)\COMMON
FILES\ADOBE\ARM\1.0\ADOBEARM.EXE
### Adobe Reader and Acrobat Manager Adobe Systems Incorporated Adobe Reader and
Acrobat Manager 1.801.10.4720 !$*"C:\Program Files (x86)\Common
Files\Adobe\ARM\1.0\AdobeARM.exe"
[Registry Run] :HKLM HP Software Update=C:\PROGRAM FILES (X86)\HP\HP SOFTWARE
UPDATE\HPWUSCHD2.EXE
### hpwuSchd Application Hewlett-Packard hpwuSchd Application 80, 1, 1, 0
[Registry Run(x64)] :HKLM NvBackend=C:\PROGRAM FILES (X86)\NVIDIA
CORPORATION\UPDATE CORE\NVBACKEND.EXE
### NVIDIA GeForce Experience Backend NVIDIA Corporation NVIDIA GeForce
Experience 14.6.22.1 !$*"C:\Program Files (x86)\NVIDIA Corporation\Update
Core\NvBackend.exe"
[Registry Run(x64)] :HKLM cAudioFilterAgent=C:\PROGRAM
FILES\CONEXANT\CAUDIOFILTERAGENT\CAUDIOFILTERAGENT64.EXE
### Conexant High Definition Audio Filter Agent Conexant Systems, Inc. Conexant
High Definition Audio Filter Agent 1.7.76.0
[Registry Run(x64)] :HKLM SmartAudio=C:\PROGRAM FILES\CONEXANT\SAII\SACPL.EXE
### SmartAudio CPL (32bit) Conexant Systems, Inc. SmartAudio CPL (32bit) 6.0.45.0
!$*C:\Program Files\CONEXANT\SAII\SACpl.exe /c /delay:30
[Registry Run(x64)] :HKLM
DptfPolicyLpmServiceHelper=C:\WINDOWS\SYSTEM32\DPTFPOLICYLPMSERVICEHELPER.EXE
### Intel(R) Dynamic Platform and Thermal Framework LPM Policy Service Helper
Intel Corporation Intel(R) Dynamic Platform and Thermal Framework 7.1.0.2105
[Win.ini] :HKCU load=""
[Win.ini] :HKCU run=""
[Startup Folder] Monitor Ink Alerts - .lnk=C:\PROGRAM FILES\HP\HP DESKJET 1510
SERIES\BIN\HPSTATUSBL.DLL
### Print Driver Status Business Logic Hewlett-Packard Co. HP Digital Imaging
032.000.1180.44630 !$*C:\Windows\system32\RunDll32.exe "C:\Program Files\HP\HP
Deskjet 1510 series\bin\HPStatusBL.dll",RunDLLEntry
SERIALNUMBER=CN43J1F4QM05YR;CONNECTION=USB;MONITOR=1;
[Startup Folder] Monitor Ink Alerts - HP Deskjet 1510 series.lnk=C:\PROGRAM
FILES\HP\HP DESKJET 1510 SERIES\BIN\HPSTATUSBL.DLL
### Print Driver Status Business Logic Hewlett-Packard Co. HP Digital Imaging
032.000.1180.44630 !$*C:\Windows\system32\RunDll32.exe "C:\Program Files\HP\HP
Deskjet 1510 series\bin\HPStatusBL.dll",RunDLLEntry
SERIALNUMBER=CN43J1F4QM05YR;CONNECTION=USB;MONITOR=1;
[Startup Folder] Sidebar.lnk=C:\Program Files\Windows Sidebar\sidebar.exe
### File is missing.
[Scheduled Tasks] WpsUpdateTask_User=C:\PROGRAM FILES (X86)\KINGSOFT\KINGSOFT
OFFICE\10.2.0.5811\WTOOLEX\WPSUPDATE.EXE
### WPS Office Expansion tool Zhuhai Kingsoft Office Software Co.,Ltd WPS Office
10,2,0,5811
[Scheduled Tasks] WpsKtpcntrQingTask_User=C:\PROGRAM FILES
(X86)\KINGSOFT\KINGSOFT OFFICE\10.2.0.5811\OFFICE6\KTPCNTR.EXE
### ktpcntr Zhuhai Kingsoft Office Software Co.,Ltd WPS Office 10,2,0,5811
[Scheduled Tasks] WpsExternal_User_20170208010954=C:\PROGRAM FILES
(X86)\KINGSOFT\KINGSOFT OFFICE\KSOLAUNCH.EXE
### WPS Office Zhuhai Kingsoft Office Software Co.,Ltd WPS Office 10,2,0,5811
[Scheduled Tasks] HP Photo Creations
Communicator=C:\USERS\USER\APPDATA\ROAMING\HP PHOTO CREATIONS\COMMUNICATOR.EXE
[Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Adobe Flash Player PPAPI
Notifier=C:\WINDOWS\SYSWOW64\MACROMED\FLASH\FLASHUTIL32_25_0_0_148_PEPPER.EXE
### Adobe Flash Player Installer/Uninstaller 25.0 r0 Adobe Systems Incorporated
Adobe Flash Player Installer/Uninstaller 25,0,0,148 Description: This task
keeps your Adobe Flash PPAPI Player inst Parameters: -check pepperplugin
[Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Adobe Flash Player
Updater=C:\WINDOWS\SYSWOW64\MACROMED\FLASH\FLASHPLAYERUPDATESERVICE.EXE
### Adobe Flash Player Update Service 26.0 d0 Adobe Systems Incorporated Adobe
Flash Player Update Service 26,0,0,89 Description: This task keeps your Adobe
Flash Player installati
[Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\ASUS Smart Gesture
Launcher=C:\PROGRAM FILES (X86)\ASUS\ASUS SMART
GESTURE\ASTPCENTER\X64\ASUSTPLAUNCHER.EXE
### ASUS Smart Gesture Launcher AsusTek ASUS Smart Gesture Launcher 1.0.3.0
Description: ASUS Smart Gesture Launcher
[Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\ATK Package
36D18D69AFC3=C:\PROGRAM FILES (X86)\ASUS\ATK PACKAGE\ATK HOTKEY\SIMAPPEXEC.EXE
### Simulate Store App Execution Application ASUSTek Computer Inc. ATK Hotkey
1.0.80.0 !$*"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\SimAppExec.exe"
Parameters: -CancelShutdown
[Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\HP Photo Creations
Communicator=C:\USERS\USER\APPDATA\ROAMING\HP PHOTO CREATIONS\COMMUNICATOR.EXE
### Parameters: --auto
[Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\HPCustParticipation HP Deskjet
1510 series=C:\PROGRAM FILES\HP\HP DESKJET 1510 SERIES\BIN\HPCUSTPARTIC.EXE
### HP Customer Participation. Hewlett-Packard Co. HP Digital Imaging
032.000.1180.44630 !$*"C:\Program Files\HP\HP Deskjet 1510
series\Bin\HPCustPartic.exe" Parameters: /UA 12.5 /DDV 0x0b00
[Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Opera scheduled Autoupdate
1419920981=C:\PROGRAM FILES (X86)\OPERA\LAUNCHER.EXE
### Opera Internet Browser Opera Software Opera Internet Browser 43.0.2442.1144
Description: Keeps Opera up to date. Parameters: --scheduledautoupdate $(Arg0)
[Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Optimize Start Menu Cache Files-S-
1-5-21-1494715353-3767046383-1133986942-1001
### File is missing. Description: $(@%SystemRoot%\system32\twinapi.dll,-8002)
[Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Optimize Start Menu Cache Files-S-
1-5-21-1494715353-3767046383-1133986942-1002
### File is missing. Status: Disabled Description: $(@%SystemRoot
%\system32\twinapi.dll,-8002)
[Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\UnHackMe Task Scheduler=C:\PROGRAM
FILES (X86)\UNHACKME\HACKMON.EXE
### Detects Rootkits in background Greatis Software UnHackMe 8.50 Description:
Part of RegRun Suite/UnHackMe software. http://www Parameters: $(Arg0)
[Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\User_Feed_Synchronization-
{F99DD404-36BE-4B0E-9A87-D7DC4E3DD715}=C:\WINDOWS\SYSTEM32\MSFEEDSSYNC.EXE
### Microsoft Feeds Synchronization Microsoft Corporation Internet Explorer
11.00.9600.16384 Description: Updates out-of-date system feeds. Parameters: sync
[Scheduled Tasks 2]
C:\WINDOWS\SYSNATIVE\TASKS\WpsExternal_User_20170208010954=C:\PROGRAM FILES
(X86)\KINGSOFT\KINGSOFT OFFICE\KSOLAUNCH.EXE
### WPS Office Zhuhai Kingsoft Office Software Co.,Ltd WPS Office 10,2,0,5811
Description: WPS Office External Task. Parameters: /wpscloudlaunch /run_plugin
/plugin_name=ktaskschdtool /plugin_entry=ktaskschdtool.dll /task=wpsexternal
/launchtask /ver=1.0
[Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\WpsKtpcntrQingTask_User=C:\PROGRAM
FILES (X86)\KINGSOFT\KINGSOFT OFFICE\10.2.0.5811\OFFICE6\KTPCNTR.EXE
### ktpcntr Zhuhai Kingsoft Office Software Co.,Ltd WPS Office 10,2,0,5811
Parameters: qing 10.2.0.5811 xxx
server_url="http://kdl1.cache.wps.com/ksodl/wpscfg/client/____client____html____ser
vice____bubble.html"
ic_server_url="http://info.kingsoftstore.com/wpsv6internet/infos.ads"
[Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\WpsUpdateTask_User=C:\PROGRAM
FILES (X86)\KINGSOFT\KINGSOFT OFFICE\10.2.0.5811\WTOOLEX\WPSUPDATE.EXE
### WPS Office Expansion tool Zhuhai Kingsoft Office Software Co.,Ltd WPS Office
10,2,0,5811 Description: WPS Office Update Task. Parameters: -from=task
[Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\{2BC1BB86-FC2C-4E63-BAFF-
9C5143753325}=C:\WINDOWS\SYSTEM32\PCALUA.EXE
### Program Compatibility Assistant Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 Parameters: -a "C:\Program Files
(x86)\YeaDesktop\unins000.exe"
[Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\{523DC39D-FDDA-4E02-899B-
5CC9172F568D}=C:\Program Files (x86)\Skype\\Phone\Skype.exe
### File is missing.
[Scheduled Tasks 2.0 Cached] :HKLM Adobe Flash Player PPAPI Notifier
### This task keeps your Adobe Flash PPAPI Player installation up to date with
the latest enhancements and security fixes. If this task is disabled or removed,
Adobe Flash Player will be unable to automatically secure your machine with the
latest security fixes.
[Scheduled Tasks 2.0 Cached] :HKLM Adobe Flash Player Updater
### This task keeps your Adobe Flash Player installation up to date with the
latest enhancements and security fixes. If this task is disabled or removed, Adobe
Flash Player will be unable to automatically secure your machine with the latest
security fixes.
[Scheduled Tasks 2.0 Cached] :HKLM ASUS Smart Gesture Launcher
### ASUS Smart Gesture Launcher
[Scheduled Tasks 2.0 Cached] :HKLM ATK Package 36D18D69AFC3
[Scheduled Tasks 2.0 Cached] :HKLM Coerbght Center
### Receives requests from parts of Coerbght, and do the tasks.
[Scheduled Tasks 2.0 Cached] :HKLM HP Photo Creations Communicator
[Scheduled Tasks 2.0 Cached] :HKLM HPCustParticipation HP Deskjet 1510 series
[Scheduled Tasks 2.0 Cached] :HKLM Nidghtdrijch
### Nidghtdrijch
[Scheduled Tasks 2.0 Cached] :HKLM Opera scheduled Autoupdate 1419920981
### Keeps Opera up to date.
[Scheduled Tasks 2.0 Cached] :HKLM Optimize Start Menu Cache Files-S-1-5-21-
1494715353-3767046383-1133986942-1001
[Scheduled Tasks 2.0 Cached] :HKLM Optimize Start Menu Cache Files-S-1-5-21-
1494715353-3767046383-1133986942-1002
[Scheduled Tasks 2.0 Cached] :HKLM smadav
### Smadav
[Scheduled Tasks 2.0 Cached] :HKLM UnHackMe Task Scheduler
### Part of RegRun Suite/UnHackMe software. http://www.greatis.com
[Scheduled Tasks 2.0 Cached] :HKLM User_Feed_Synchronization-{F99DD404-36BE-4B0E-
9A87-D7DC4E3DD715}
### Updates out-of-date system feeds.
[Scheduled Tasks 2.0 Cached] :HKLM WpsExternal_User_20170208010954
### WPS Office External Task.
[Scheduled Tasks 2.0 Cached] :HKLM WpsKtpcntrQingTask_User
[Scheduled Tasks 2.0 Cached] :HKLM WpsUpdateTask_User
### WPS Office Update Task.
[Scheduled Tasks 2.0 Cached] :HKLM {2BC1BB86-FC2C-4E63-BAFF-9C5143753325}
[Scheduled Tasks 2.0 Cached] :HKLM {523DC39D-FDDA-4E02-899B-5CC9172F568D}
[Scheduled Tasks 2.0 Cached] :HKLM {5A4AA204-C066-7FC1-9B1C-703BC4D54B10}
[Scheduled Tasks 2.0 Cached] :HKLM {A2A90AA9-CA25-1843-115E-0A877FDBE302}
[Detected using Heuristic Algorithm] :HKLM COMMON FILES=C:\PROGRAM FILES
(X86)\COMMON FILES\
### "ADOBE\" "ATHEROS\" "INTEL\" "MICROSOFT SHARED\" "POSTUREAGENT\"
"REALLUSION\" "SERVICES\" "SYSTEM\" "Adobe\Acrobat\ActiveX: ACROIEHELPER.DLL"
"ACROIEHELPERSHIM.DLL" "ACROPDF.DLL" "ACROPDF64.DLL" "Adobe\ARM\1.0: ADOBEARM.EXE"
"ADOBEARMHELPER.EXE" "ARMSVC.E
[Detected using Heuristic Algorithm] :HKLM MOZILLA FIREFOX=C:\PROGRAM FILES
(X86)\MOZILLA FIREFOX\
### "ACCESSIBLEMARSHAL.DLL" "APPLICATION.INI" "BREAKPADINJECTOR.DLL" "BROWSER\"
"CRASHREPORTER.EXE" "CRASHREPORTER.INI" "D3DCOMPILER_43.DLL" "D3DCOMPILER_47.DLL"
"DEFAULTS\" "DEPENDENTLIBS.LIST" "DICTIONARIES\"
[Detected using Heuristic Algorithm] :HKLM MOZILLA MAINTENANCE SERVICE=C:\PROGRAM
FILES (X86)\MOZILLA MAINTENANCE SERVICE\
### "LOGS\" "MAINTENANCESERVICE.EXE" "UNINSTALL.EXE" "UPDATER.INI" "logs:
MAINTENANCESERVICE-INSTALL.LOG"
[Detected using Heuristic Algorithm] :HKLM OPERA=C:\PROGRAM FILES (X86)\OPERA\
### "43.0.2442.1144\" "43.0.2442.806\" "ASSETS\" "INSTALLATION_STATUS.XML"
"INSTALLER_PREFS.JSON" "LAUNCHER.EXE" "LAUNCHER.VISUALELEMENTSMANIFEST.XML"
"OLD_STATUS\" "PREF_DEFAULT_OVERRIDES" "RESOURCES.PRI"
[Detected using Heuristic Algorithm] :HKLM SMADAV=C:\PROGRAM FILES (X86)\SMADAV\
### "README.TXT" "SMADAV-UPDATER.EXE" "SMADAV.LOG" "SMADAV.LOOV"
"SMADENGINE.DLL" "SMADEXTC64.DLL" "SM|CE|94RTP.EXE" "UNINS000.DAT" "UNINS000.EXE"
[Detected using Heuristic Algorithm] :HKLM UNHACKME=C:\PROGRAM FILES
(X86)\UNHACKME\
### "7ZA.EXE" "DATABASE.RDB" "DBS.DB" "DBS.INI" "DBS.ZIP" "DBSWWW.INI"
"GWEBUPDATE.EXE" "HACKMON.EXE" "JSONFAST.DLL" "LICENSE.TXT" "LOGO.BMP"
[Detected using Heuristic Algorithm] :HKLM AUTODESK=C:\PROGRAM FILES\AUTODESK\
### "AUTODESK SYNC\" "INVENTOR 2014\" "VAULT BASIC 2014\" "Autodesk Sync\RealDwg:
TBB.DLL" "TBBMALLOC.DLL" "Inventor 2014\ContentPacks: MASTER.XML" "MASTER.XSD"
"Inventor 2014\ContentPacks\en: ASM-EN-US-X-IES.XML" "DOCUMENT.XSD" "Vault Basic
2014\Explorer: IN
[Detected using Heuristic Algorithm] :HKLM COMMON FILES=C:\PROGRAM FILES\COMMON
FILES\
### "MICROSOFT SHARED\" "QCA_BLUETOOTH\" "SERVICES\" "SYSTEM\" "microsoft
shared\ink: ALPHABET.XML" "CONTENT.XML" "FLICKANIMATION.AVI"
"FLICKLEARNINGWIZARD.EXE" "microsoft shared\MSInfo: MSINFO32.EXE" "microsoft
shared\MSInfo\en-US: MSINFO32.EXE.MUI" "micros
[Detected using Heuristic Algorithm] :HKLM 811F60AF=C:\PROGRAMDATA\811F60AF\
[Detected using Heuristic Algorithm] :HKLM AUTODESK=C:\PROGRAMDATA\AUTODESK\
### "ADLM\" "ADUT\" "APPINDEX.XML" "APPINDEX.XSD" "CONTENTPACKS\" "INSTALLER\"
"INVENTOR 2014\" "INVPROSA\" "MC3\" "MOLDFLOW\"
[Detected using Heuristic Algorithm] :HKLM CACHE=C:\PROGRAMDATA\CACHE\
[Detected using Heuristic Algorithm] :HKLM MICROSOFT=C:\PROGRAMDATA\MICROSOFT\
### "CRYPTO\" "DEVICE STAGE\" "DEVICESYNC\" "DOT3SVC\" "DRM\" "EVENT VIEWER\"
"HTML HELP\" "IDENTITYCRL\" "MF\" "NETFRAMEWORK\" "NETWORK\"
[Detected using Heuristic Algorithm] :HKLM REGRUN=C:\PROGRAMDATA\REGRUN\
[Detected using Heuristic Algorithm] :HKLM
VIDEOMEMORYDIAGNOSTIC=C:\PROGRAMDATA\VIDEOMEMORYDIAGNOSTIC\
### "VMDIAG.EXE"
[Detected using Heuristic Algorithm] :HKLM
CRASHDUMPS=C:\USERS\USER\APPDATA\LOCAL\CRASHDUMPS\
### "PES2014.EXE.2808.DMP" "PES2014.EXE.3776.DMP" "PES2014.EXE.5628.DMP"
"PES2014.EXE.5808.DMP" "PESEDIT SELECTOR.EXE.1100.DMP" "PESEDIT
SELECTOR.EXE.5416.DMP" "PESEDIT SELECTOR.EXE.5644.DMP" "PESEDIT
SELECTOR.EXE.6100.DMP" "VLC.EXE.3032.DMP" "VLC.EXE.3312.DM
[Detected using Heuristic Algorithm] :HKLM
ELEVATEDDIAGNOSTICS=C:\USERS\USER\APPDATA\LOCAL\ELEVATEDDIAGNOSTICS\
### "733862231\" "733862231: LATEST.CAB" "733862231\2017050203.000:
PCW.DEBUGREPORT.XML" "RESULTREPORT.XML" "RESULTS.XML" "RESULTS.XSL"
[Detected using Heuristic Algorithm] :HKLM TEMP=C:\USERS\USER\APPDATA\LOCAL\TEMP\
### ".ANSYS\" "00005491\" "00005508\" "00005511\" "00005527\" "00005531\"
"00005553\" "00005557\" "00005560\" "00005586\" "00013864\"
[Detected using Heuristic Algorithm] :HKLM TOTAL
DOWNLOAD=C:\USERS\USER\APPDATA\LOCAL\TOTAL DOWNLOAD\
### "XBIN\" "xBin: TOTALDOWNLOAD.DLL" "VER.DAT" "YYNYM.DLL"
[Detected using Heuristic Algorithm] :HKLM
MOZILLA=C:\USERS\USER\APPDATA\LOCALLOW\MOZILLA\
[Detected using Heuristic Algorithm] :HKLM
241344=C:\USERS\USER\APPDATA\ROAMING\241344\
### "170617.EXE" "170617.EXE.CONFIG"
[Detected using Heuristic Algorithm] :HKLM
580916=C:\USERS\USER\APPDATA\ROAMING\580916\
### "18798.EXE" "18798.EXE.CONFIG"
[Detected using Heuristic Algorithm] :HKLM
681015=C:\USERS\USER\APPDATA\ROAMING\681015\
### "196657.EXE" "196657.EXE.CONFIG"
[Detected using Heuristic Algorithm] :HKLM
721393=C:\USERS\USER\APPDATA\ROAMING\721393\
### "604405.EXE" "604405.EXE.CONFIG"
[Detected using Heuristic Algorithm] :HKLM
GOVEGEGRETITAIN=C:\USERS\USER\APPDATA\ROAMING\GOVEGEGRETITAIN\
[Detected using Heuristic Algorithm] :HKLM
PROFILES=C:\USERS\USER\APPDATA\ROAMING\PROFILES\
### "BUFUSECLLY.DEFAULT\" "Bufuseclly.default: ADDONS.JSON"
"ALTERNATESERVICES.TXT" "BLOCKLIST-ADDONS.JSON" "BLOCKLIST-GFX.JSON" "BLOCKLIST-
PLUGINS.JSON" "BLOCKLIST.XML" "CERT8.DB" "CERT_OVERRIDE.TXT" "COMPATIBILITY.INI"
"CONTAINERS.JSON"
[Detected using Heuristic Algorithm] :HKLM VLC=C:\USERS\USER\APPDATA\ROAMING\VLC\
### "ART\" "D031BBBA323FD9E5B47E0EE5A0353F11-X86_64.CACHE-3" "ML.XSPF" "VLC-QT-
INTERFACE.INI" "VLCRC" "art\artistalbum\Adele\19 - www.stafaband.co: ART.JPG"
"art\artistalbum\Adele\21 - www.stafaband.co: ART.JPG"
"art\artistalbum\Alexa\Alexa: ART.PNG" "art\art
[Detected using Heuristic Algorithm] :HKLM DESKTOP=C:\USERS\USER\DESKTOP\
### "COUNTER STRIKE XTREME - SHORTCUT.LNK" "DESKTOP.INI" "DUCTING\" "FILE KP\"
"HP PHOTO CREATIONS.LNK" "IMPACT OF JET\" "IMPACT OF Z KEL 31 SEBAGIAN.PDF" "IMPACT
REVISI DIKIT.PDF" "JADWAL KULIAH SEMESTER GENAP 2016.DOCX" "KONDUKTIVITAS\"
"KONVEKSI\"
[Detected using Heuristic Algorithm] :HKLM DOCUMENTS=C:\USERS\USER\DOCUMENTS\
### "+BONUS\" "13SURAT_KETERANGAN_BEASISWA.DOCX" "ACTIVISION\" "AKRED 1.JPG"
"AKRED.JPG" "AUTODESK\" "BAB I IMPACT OF JET NEW.DOC" "BEASISWA.RAR" "BLUETOOTH
FOLDER\" "CFD SIMULATION OF CYCLONE SEPARATORS TO REDUCE AIR.DOCX" "DAFTAR
PSTAKA.PDF"
[Detected using Heuristic Algorithm] :HKLM DOWNLOADS=C:\USERS\USER\DOWNLOADS\
### "135797424-WEIBULL-2-PARAMETER.PDF" "13SURAT_KETERANGAN_BEASISWA.DOCX"
"145106509-LAPORAN-PRAKTEK-KERJA-LAPANGAN-PLTGU-PT-PLN-PERSERO-SEKTOR-PEMBANGKITAN-
BELAWAN-MEDAN-SUMATERA-UTARA.DOCX" "161272644-BAB-1-IMPACT-OF-JET-DOCX(1).DOCX"
"161272644-BAB-1-IMPA
[Detected using Heuristic Algorithm] :HKLM LINKS=C:\USERS\USER\LINKS\
### "DESKTOP.INI" "DESKTOP.LNK" "DOWNLOADS.LNK" "RECENTPLACES.LNK"
[Detected using Heuristic Algorithm] :HKLM SKYDRIVE=C:\USERS\USER\SKYDRIVE\
### "DESKTOP.INI" "DOCUMENTS\" "PICTURES\" "Documents\VIDEO_TS: VIDEO_TS.BUP"
"VIDEO_TS.IFO" "VIDEO_TS.VOB" "Pictures\Camera Roll: ASUSA455LN -
WIN_20160822_220819.JPG" "ASUSA455LN - WIN_20160822_221204.JPG" "ASUSA455LN -
WIN_20160822_221206.JPG" "ASUSA455LN -
[Detected using Heuristic Algorithm] :HKLM VIDEOS=C:\USERS\USER\VIDEOS\
### "DESKTOP.INI"
[Detected using Heuristic Algorithm] :HKLM zkrzfe.exe=C:\USERS\USER\ZKRZFE.EXE
### Sightnine Formthing 6.5.6661.2542
[In memory]
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\WININIT.EXE
### Windows Start-Up Application Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*wininit.exe
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\WINLOGON.EXE
### Windows Logon Application Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*winlogon.exe
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\LSASS.EXE
### Local Security Authority Process Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*C:\Windows\system32\lsass.exe
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*C:\Windows\system32\svchost.exe -k DcomLaunch
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*C:\Windows\system32\svchost.exe -k RPCSS
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\NVVSVC.EXE
### NVIDIA Driver Helper Service, Version 333.17 NVIDIA Corporation NVIDIA Driver
Helper Service, Version 333.17 8.17.13.3317 !$*"C:\Windows\system32\nvvsvc.exe"
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\DWM.EXE
### Desktop Window Manager Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*"dwm.exe"
[Running Processes] :HKLM C:\PROGRAM FILES\NVIDIA
CORPORATION\DISPLAY\NVXDSYNC.EXE
### NVIDIA User Experience Driver Component NVIDIA Corporation NVIDIA User
Experience Driver Component 8.17.13.3317 !$*"C:\Program Files\NVIDIA
Corporation\Display\nvxdsync.exe"
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\NVVSVC.EXE
### NVIDIA Driver Helper Service, Version 333.17 NVIDIA Corporation NVIDIA Driver
Helper Service, Version 333.17 8.17.13.3317 !$*C:\Windows\system32\nvvsvc.exe
-session -first
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*C:\Windows\System32\svchost.exe -k
LocalServiceNetworkRestricted
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*C:\Windows\system32\svchost.exe -k netsvcs
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*C:\Windows\system32\svchost.exe -k LocalService
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\IGFXCUISERVICE.EXE
### igfxCUIService Module Intel Corporation Intel(R) Common User Interface
6.15.10.3496 !$*C:\Windows\system32\igfxCUIService.exe
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*C:\Windows\System32\svchost.exe -k
LocalSystemNetworkRestricted
[Running Processes] :HKLM C:\PROGRAM FILES (X86)\NETCUTDEFENDER\SERVICES\AIPS.EXE
### Arp Intelligent Protection Service Arcai.com AIPS Application 214 !
$*"C:\Program Files (x86)\NetCutDefender\services\AIPS.exe"
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*C:\Windows\system32\svchost.exe -k
NetworkService
[Running Processes] :HKLM C:\PROGRAM FILES (X86)\ASUS\ATK PACKAGE\ATK
HOTKEY\ASLDRSRV.EXE
### ASLDR Service ASUSTek Computer Inc. ATK Hotkey 1, 0, 81, 0 !$*"C:\Program
Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe"
[Running Processes] :HKLM C:\PROGRAM FILES (X86)\ASUS\ATK
PACKAGE\ATKGFNEX\GFNEXSRV.EXE
### GFNEXSrv ASUS ATK Generic Function Service 1, 0, 11, 0 !$*"C:\Program Files
(x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe"
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SPOOLSV.EXE
### Spooler SubSystem App Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384 !$*C:\Windows\System32\spoolsv.exe
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*C:\Windows\system32\svchost.exe -k
LocalServiceNoNetwork
[Running Processes] :HKLM C:\PROGRAM FILES (X86)\COMMON
FILES\ADOBE\ARM\1.0\ARMSVC.EXE
### Adobe Acrobat Update Service Adobe Systems Incorporated Adobe Acrobat Update
Service 1.801.10.4720 !$*"C:\Program Files (x86)\Common
Files\Adobe\ARM\1.0\armsvc.exe"
[Running Processes] :HKLM C:\PROGRAM FILES (X86)\BLUETOOTH SUITE\ADMINSERVICE.EXE
### Windows Setup API Windows (R) Win 7 DDK provider Windows (R) Win 7 DDK driver
6.2.9200.16384 !$*"C:\Program Files (x86)\Bluetooth Suite\adminservice.exe"
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\CXAUDMSG64.EXE
### Conexant Audio Message Service Conexant Systems Inc. Conexant Audio Message
Service 1.13.0.0 !$*C:\Windows\system32\CxAudMsg64.exe
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\DPTFPARTICIPANTPROCESSORSERVICE.EXE
### Intel(R) Dynamic Platform and Thermal Framework Processor Participant Service
Intel Corporation Intel(R) Dynamic Platform and Thermal Framework 7.1.0.2105 !
$*C:\Windows\system32\DptfParticipantProcessorService.exe
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\DPTFPOLICYCONFIGTDPSERVICE.EXE
### Intel(R) Dynamic Platform and Thermal Framework Config TDP Policy Service
Intel Corporation Intel(R) Dynamic Platform and Thermal Framework 7.1.0.2105 !
$*C:\Windows\system32\DptfPolicyConfigTDPService.exe
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\DASHOST.EXE
### Device Association Framework Provider Host Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 !$*dashost.exe {53411133-b4c5-4288-
924e5864b29591a3}
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\DPTFPOLICYLPMSERVICE.EXE
### Intel(R) Dynamic Platform and Thermal Framework LPM Policy Service Intel
Corporation Intel(R) Dynamic Platform and Thermal Framework 7.1.0.2105 !
$*C:\Windows\system32\DptfPolicyLpmService.exe
[Running Processes] :HKLM C:\PROGRAM FILES\INTEL\ICLS CLIENT\HECISERVER.EXE
### Intel(R) Capability Licensing Service Interface Intel(R) Corporation Intel(R)
Capability Licensing Service Interface 1,31,8,1 !$*"C:\Program Files\Intel\iCLS
Client\HeciServer.exe"
[Running Processes] :HKLM C:\PROGRAM FILES (X86)\NVIDIA
CORPORATION\NETSERVICE\NVNETWORKSERVICE.EXE
### NVIDIA Network Service NVIDIA Corporation NVIDIA Network Service 1.0.5.16 !
$*"C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe"
[Running Processes] :HKLM C:\WINDOWS\SYSWOW64\SASRV.EXE
### SmartAudio Service Application Conexant Systems, Inc. SmartAudio Service
Application 1, 0, 4, 0 !$*C:\Windows\SysWOW64\SAsrv.exe
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*C:\Windows\system32\svchost.exe -k imgsvc
[Running Processes] :HKLM C:\PROGRAM FILES (X86)\BLUETOOTH
SUITE\ATH_COEXAGENT.EXE
### Atheros Coex Service Application Atheros Ath_Coex Application 8.0.0.270 !
$*"C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe"
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*C:\Windows\system32\svchost.exe -k
LocalServiceAndNoImpersonation
[Running Processes] :HKLM C:\PROGRAM FILES (X86)\ASUS\ATK PACKAGE\ATK
HOTKEY\HCONTROL.EXE
### HControl ASUSTek Computer Inc. ATK Hotkey 1, 0, 81, 0 !$*"C:\Program Files
(x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe"
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\TASKHOSTEX.EXE
### Host Process for Windows Tasks Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*taskhostex.exe
[Running Processes] :HKLM
C:\WINDOWS\MICROSOFT.NET\FRAMEWORK64\V3.0\WPF\PRESENTATIONFONTCACHE.EXE
### PresentationFontCache.exe Microsoft Corporation Microsoft .NET Framework
3.0.6920.7903 !
$*C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
[Running Processes] :HKLM C:\WINDOWS\EXPLORER.EXE
### Windows Explorer Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*C:\Windows\Explorer.EXE
[Running Processes] :HKLM C:\PROGRAM FILES (X86)\ASUS\ATK PACKAGE\ATK
HOTKEY\KBFILTR.EXE
### KBFiltr ASUSTek Computer Inc. ATK Hotkey 1, 0, 67, 0 !$*KBFiltr.exe
[Running Processes] :HKLM C:\PROGRAM FILES (X86)\UNHACKME\HACKMON.EXE
### Detects Rootkits in background Greatis Software UnHackMe 8.50 !$*"C:\Program
Files (x86)\UnHackMe\hackmon.exe" $(Arg0)
[Running Processes] :HKLM C:\PROGRAM FILES\NVIDIA CORPORATION\DISPLAY\NVTRAY.EXE
### NVIDIA Settings NVIDIA Corporation NVIDIA Settings 7.17.13.3317 !
$*"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\IGFXEM.EXE
### igfxEM Module Intel Corporation Intel(R) Common User Interface
6.15.10.3496 !$*igfxEM.exe
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\IGFXHK.EXE
### igfxHK Module Intel Corporation Intel(R) Common User Interface
6.15.10.3496 !$*igfxHK.exe
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\IGFXTRAY.EXE
### igfxTray Module Intel Corporation Intel(R) Common User Interface 6.15.10.3496
!$*igfxTray.exe
[Running Processes] :HKLM C:\PROGRAM FILES (X86)\ASUS\ATK
PACKAGE\ATKOSD2\ATKOSD2.EXE
### ATKOSD2 ASUSTek Computer Inc. ATKOSD2 7, 0, 30, 0 !$*"C:\Program Files
(x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe"
[Running Processes] :HKLM C:\PROGRAM FILES (X86)\ASUS\ATK PACKAGE\ATK
MEDIA\DMEDIA.EXE
### ATK Media ASUSTek Computer Inc. ATK Media 2, 0, 18, 0 !$*"C:\Program Files
(x86)\ASUS\ATK Package\ATK Media\DMedia.exe"
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SEARCHINDEXER.EXE
### Microsoft Windows Search Indexer Microsoft Corporation Windows Search
7.00.9600.16384 !$*C:\Windows\system32\SearchIndexer.exe /Embedding
[Running Processes] :HKLM C:\PROGRAM FILES
(X86)\NETCUTDEFENDER\NETCUTDEFENDER.EXE
### netcut Defender arcai.com Netcut Defender 215 !$*"C:\Program Files
(x86)\NetCutDefender\NetCutDefender.exe"
[Running Processes] :HKLM C:\PROGRAM FILES (X86)\BLUETOOTH SUITE\BTVSTACK.EXE
### Extension Core QualcommAtheros BT Software Suite 8.0.1.318 !$*"C:\Program
Files (x86)\Bluetooth Suite\BtvStack.exe"
[Running Processes] :HKLM C:\PROGRAM FILES (X86)\NVIDIA CORPORATION\UPDATE
CORE\NVBACKEND.EXE
### NVIDIA GeForce Experience Backend NVIDIA Corporation NVIDIA GeForce
Experience 14.6.22.1 !$*"C:\Program Files (x86)\NVIDIA Corporation\Update
Core\NvBackend.exe"
[Running Processes] :HKLM C:\PROGRAM FILES (X86)\BLUETOOTH
SUITE\ACTIVATEDESKTOP.EXE
### !$*"C:\Program Files (x86)\Bluetooth Suite\ActivateDesktop.exe"
[Running Processes] :HKLM C:\PROGRAM
FILES\CONEXANT\CAUDIOFILTERAGENT\CAUDIOFILTERAGENT64.EXE
### Conexant High Definition Audio Filter Agent Conexant Systems, Inc. Conexant
High Definition Audio Filter Agent 1.7.76.0 !$*"C:\Program
Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe"
[Running Processes] :HKLM C:\PROGRAM FILES (X86)\HP\HP SOFTWARE
UPDATE\HPWUSCHD2.EXE
### hpwuSchd Application Hewlett-Packard hpwuSchd Application 80, 1, 1, 0 !
$*"C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe"
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\DLLHOST.EXE
### COM Surrogate Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*C:\Windows\system32\DllHost.exe /Processid:{3EB3C877-1F16-487C-
9050-104DBCD66683}
[Running Processes] :HKLM C:\PROGRAM FILES (X86)\ASUS\ASUS SMART
GESTURE\ASTPCENTER\X64\ASUSTPLOADER.EXE
### ASUS Smart Gesture Loader AsusTek ASUS Smart Gesture 1.0.28.0 !$*"C:\Program
Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe"
[Running Processes] :HKLM C:\PROGRAM FILES (X86)\ASUS\ASUS SMART
GESTURE\ASTPCENTER\X64\ASUSTPCENTER.EXE
### ASUS Smart Gesture Center AsusTek ASUS Smart Gesture 1.0.0.69 !$*"C:\Program
Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe"
[Running Processes] :HKLM C:\PROGRAM FILES (X86)\ASUS\ASUS SMART
GESTURE\ASTPCENTER\X64\ASUSTPHELPER.EXE
### ASUS Smart Gesture Helper AsusTek ASUS Smart Gesture Helper 1.0.17.0 !
$*"C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe"
[Running Processes] :HKLM C:\PROGRAM FILES (X86)\INTEL\INTEL(R) MANAGEMENT ENGINE
COMPONENTS\DAL\JHI_SERVICE.EXE
### Intel(R) Dynamic Application Loader Host Interface Intel Corporation Intel(R)
Dynamic Application Loader Host Interface 9.5.12.1682 !$*"C:\Program Files
(x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
[Running Processes] :HKLM C:\PROGRAM FILES (X86)\INTEL\INTEL(R) MANAGEMENT ENGINE
COMPONENTS\LMS\LMS.EXE
### Intel(R) Local Management Service Intel Corporation Intel(R) Management and
Security Application Local Management Service 9.5.10.1628 !$*"C:\Program Files
(x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\TASKHOST.EXE
### Host Process for Windows Tasks Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384 !$*taskhost.exe $(Arg0)
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\WBEM\WMIPRVSE.EXE
### WMI Provider Host Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*C:\Windows\system32\wbem\wmiprvse.exe
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SETTINGSYNCHOST.EXE
### Host Process for Setting Synchronization Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384 !
$*"C:\Windows\System32\SettingSyncHost.exe" -Embedding
[Running Processes] :HKLM C:\PROGRAM FILES (X86)\UNHACKME\UNHACKME.EXE
### Detects and removes rootkits Greatis Software UnHackMe 8.80 !$*"C:\Program
Files (x86)\UnHackMe\UnHackMe.exe"
[Running Processes] :HKLM C:\PROGRAM FILES (X86)\INTERNET EXPLORER\IELOWUTIL.EXE
### Internet Low-Mic Utility Tool Microsoft Corporation Internet Explorer
11.00.9600.16384 !$*"C:\Program Files (x86)\Internet Explorer\IELowutil.exe"
-embedding
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\MSIEXEC.EXE
### Windows installer Microsoft Corporation Windows Installer - Unicode
5.0.9600.16384 !$*C:\Windows\system32\msiexec.exe /V
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\NOTEPAD.EXE
### Notepad Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*"C:\Windows\system32\NOTEPAD.EXE" D:\APP-
Games\PES\PES_2014_FILES\Cara Pemasangan Crack Rld.dll Pes 2014.txt
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SEARCHPROTOCOLHOST.EXE
### Microsoft Windows Search Protocol Host Microsoft Corporation Windows Search
7.00.9600.16384 !$*"C:\Windows\system32\SearchProtocolHost.exe"
Global\UsGthrFltPipeMssGthrPipe4_ Global\UsGthrCtrlFltPipeMssGthrPipe4 1
-2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0;
Windows NT; MS Search 4.0 Robot)"
"C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SEARCHFILTERHOST.EXE
### Microsoft Windows Search Filter Host Microsoft Corporation Windows Search
7.00.9600.16384 !$*"C:\Windows\system32\SearchFilterHost.exe" 0 572 576 584 65536
580
[Running Processes] :HKLM C:\PROGRAM
FILES\WINDOWSAPPS\MICROSOFT.WINDOWSCOMMUNICATIONSAPPS_17.5.9600.20911_X64__8WEKYB3D
8BBWE\LIVECOMM.EXE
### Communications Service Microsoft Corporation Microsoft Windows Operating
System 17.5.9600.17923 !$*"C:\Program
Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20911_x64__8wekyb3d
8bbwe\LiveComm.exe" -ServerName:Microsoft.WindowsLive.Platform.Server
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\RUNTIMEBROKER.EXE
### Runtime Broker Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*C:\Windows\System32\RuntimeBroker.exe -Embedding
[Running Processes] :HKLM C:\PROGRAM FILES (X86)\UNHACKME\REANIMATOR.EXE
### RegRun Start Control Greatis Software RegRun Security Suite 8.80 !
$*"C:\Program Files (x86)\UnHackMe\reanimator.exe" /wiz /full /malw
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\WBEM\WMIPRVSE.EXE
### WMI Provider Host Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384 !$*C:\Windows\system32\wbem\wmiprvse.exe
[Running Services] AdobeARMservice
### Internal Name: AdobeARMservice. Status: service is running. Actual File:
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe" * Adobe Acrobat
Updater keeps your Adobe software up to date. Adobe Acrobat Update Service Adobe
Systems Incorporated Adobe Acrobat Update Service 1.801.10.4720
[Running Services] AeLookupSvc
### Internal Name: AeLookupSvc. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k netsvcs * Processes application compatibility
cache requests for applications as they are launched Host Process for Windows
Services Microsoft Corporation Microsoft Windows Operating System 6.3.9600.16384
[Running Services] AIPS
### Internal Name: AIPS. Status: service is running. Actual File: C:\Program
Files (x86)\NetCutDefender\services\AIPS.exe * Arp Intelligent Protection Service
Arcai.com AIPS Application 214
[Running Services] Appinfo
### Internal Name: Appinfo. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k netsvcs * Facilitates the running of interactive
applications with additional administrative privileges. If this service is
stopped, users will be unable to launch applications with the additional
administrative privileges they may require to perform desired user tasks. Host
Process for Windows Services Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384
[Running Services] ASLDRService
### Internal Name: ASLDRService. Status: service is running. Actual File:
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe * ASLDR Service
ASUSTek Computer Inc. ATK Hotkey 1, 0, 81, 0
[Running Services] AtherosSvc
### Internal Name: AtherosSvc. Status: service is running. Actual File:
"C:\Program Files (x86)\Bluetooth Suite\adminservice.exe" * Atheros BT Stack
Service Agent Windows Setup API Windows (R) Win 7 DDK provider Windows (R) Win 7
DDK driver 6.2.9200.16384
[Running Services] ATKGFNEXSrv
### Internal Name: ATKGFNEXSrv. Status: service is running. Actual File:
C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe * GFNEXSrv ASUS ATK
Generic Function Service 1, 0, 11, 0
[Running Services] AudioEndpointBuilder
### Internal Name: AudioEndpointBuilder. Status: service is running. Actual File:
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted * Manages audio
devices for the Windows Audio service. If this service is stopped, audio devices
and effects will not function properly. If this service is disabled, any services
that explicitly depend on it will fail to start Host Process for Windows Services
Microsoft Corporation Microsoft Windows Operating System 6.3.9600.16384
[Running Services] Audiosrv
### Internal Name: Audiosrv. Status: service is running. Actual File:
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted * Manages audio
for Windows-based programs. If this service is stopped, audio devices and effects
will not function properly. If this service is disabled, any services that
explicitly depend on it will fail to start Host Process for Windows Services
Microsoft Corporation Microsoft Windows Operating System 6.3.9600.16384
[Running Services] BFE
### Internal Name: BFE. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork * The Base Filtering
Engine (BFE) is a service that manages firewall and Internet Protocol security
(IPsec) policies and implements user mode filtering. Stopping or disabling the BFE
service will significantly reduce the security of the system. It will also result
in unpredictable behavior in IPsec management and firewall applications. Host
Process for Windows Services Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384
[Running Services] BITS
### Internal Name: BITS. Status: service is running. Actual File:
C:\Windows\System32\svchost.exe -k netsvcs * Transfers files in the background
using idle network bandwidth. If the service is disabled, then any applications
that depend on BITS, such as Windows Update or MSN Explorer, will be unable to
automatically download programs and other information. Host Process for Windows
Services Microsoft Corporation Microsoft Windows Operating System 6.3.9600.16384
[Running Services] BrokerInfrastructure
### Internal Name: BrokerInfrastructure. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k DcomLaunch * Windows infrastructure service that
controls which background tasks can run on the system. Host Process for Windows
Services Microsoft Corporation Microsoft Windows Operating System 6.3.9600.16384
[Running Services] bthserv
### Internal Name: bthserv. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k LocalService * The Bluetooth service supports
discovery and association of remote Bluetooth devices. Stopping or disabling this
service may cause already installed Bluetooth devices to fail to operate properly
and prevent new devices from being discovered or associated. Host Process for
Windows Services Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384
[Running Services] CryptSvc
### Internal Name: CryptSvc. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k NetworkService * Provides three management
services: Catalog Database Service, which confirms the signatures of Windows files
and allows new programs to be installed; Protected Root Service, which adds and
removes Trusted Root Certification Authority certificates from this computer; and
Automatic Root Certificate Update Service, which retrieves root certificates from
Windows Update and enable scenarios such as SSL. If this service is stopped, these
management services will not function properly. If this service is disabled, any
services that explicitly depend on it will fail to start. Host Process for Windows
Services Microsoft Corporation Microsoft Windows Operating System 6.3.9600.16384
[Running Services] CxAudMsg
### Internal Name: CxAudMsg. Status: service is running. Actual File:
C:\Windows\system32\CxAudMsg64.exe * Monitors audio device events and forward them
to subscribing application. If this service is stop. the aduio effects will not
function properly. Conexant Audio Message Service Conexant Systems Inc. Conexant
Audio Message Service 1.13.0.0
[Running Services] DcomLaunch
### Internal Name: DcomLaunch. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k DcomLaunch * The DCOMLAUNCH service launches COM
and DCOM servers in response to object activation requests. If this service is
stopped or disabled, programs using COM or DCOM will not function properly. It is
strongly recommended that you have the DCOMLAUNCH service running. Host Process for
Windows Services Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384
[Running Services] DeviceAssociationService
### Internal Name: DeviceAssociationService. Status: service is running. Actual
File: C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted * Enables
pairing between the system and wired or wireless devices. Host Process for Windows
Services Microsoft Corporation Microsoft Windows Operating System 6.3.9600.16384
[Running Services] Dhcp
### Internal Name: Dhcp. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted * Registers and
updates IP addresses and DNS records for this computer. If this service is stopped,
this computer will not receive dynamic IP addresses and DNS updates. If this
service is disabled, any services that explicitly depend on it will fail to start.
Host Process for Windows Services Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384
[Running Services] Dnscache
### Internal Name: Dnscache. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k NetworkService * The DNS Client service
(dnscache) caches Domain Name System (DNS) names and registers the full computer
name for this computer. If the service is stopped, DNS names will continue to be
resolved. However, the results of DNS name queries will not be cached and the
computer's name will not be registered. If the service is disabled, any services
that explicitly depend on it will fail to start. Host Process for Windows Services
Microsoft Corporation Microsoft Windows Operating System 6.3.9600.16384
[Running Services] dot3svc
### Internal Name: dot3svc. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted * The Wired
AutoConfig (DOT3SVC) service is responsible for performing IEEE 802.1X
authentication on Ethernet interfaces. If your current wired network deployment
enforces 802.1X authentication, the DOT3SVC service should be configured to run for
establishing Layer 2 connectivity and/or providing access to network resources.
Wired networks that do not enforce 802.1X authentication are unaffected by the
DOT3SVC service. Host Process for Windows Services Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384
[Running Services] DPS
### Internal Name: DPS. Status: service is running. Actual File:
C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork * The Diagnostic Policy
Service enables problem detection, troubleshooting and resolution for Windows
components. If this service is stopped, diagnostics will no longer function. Host
Process for Windows Services Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384
[Running Services] DptfParticipantProcessorService
### Internal Name: DptfParticipantProcessorService. Status: service is running.
Actual File: C:\Windows\system32\DptfParticipantProcessorService.exe * Intel(R)
Dynamic Platform and Thermal Framework Processor Participant Service Application
Intel(R) Dynamic Platform and Thermal Framework Processor Participant Service Intel
Corporation Intel(R) Dynamic Platform and Thermal Framework 7.1.0.2105
[Running Services] DptfPolicyConfigTDPService
### Internal Name: DptfPolicyConfigTDPService. Status: service is running. Actual
File: C:\Windows\system32\DptfPolicyConfigTDPService.exe * Intel(R) Dynamic
Platform and Thermal Framework Config TDP Service Application Intel(R) Dynamic
Platform and Thermal Framework Config TDP Policy Service Intel Corporation Intel(R)
Dynamic Platform and Thermal Framework 7.1.0.2105
[Running Services] DptfPolicyLpmService
### Internal Name: DptfPolicyLpmService. Status: service is running. Actual File:
C:\Windows\system32\DptfPolicyLpmService.exe * Intel(R) Dynamic Platform and
Thermal Framework Low Power Mode Service Application Intel(R) Dynamic Platform and
Thermal Framework LPM Policy Service Intel Corporation Intel(R) Dynamic Platform
and Thermal Framework 7.1.0.2105
[Running Services] Eaphost
### Internal Name: Eaphost. Status: service is running. Actual File:
C:\Windows\System32\svchost.exe -k netsvcs * The Extensible Authentication Protocol
(EAP) service provides network authentication in such scenarios as 802.1x wired and
wireless, VPN, and Network Access Protection (NAP). EAP also provides application
programming interfaces (APIs) that are used by network access clients, including
wireless and VPN clients, during the authentication process. If you disable this
service, this computer is prevented from accessing networks that require EAP
authentication. Host Process for Windows Services Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384
[Running Services] EventLog
### Internal Name: EventLog. Status: service is running. Actual File:
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted * This service
manages events and event logs. It supports logging events, querying events,
subscribing to events, archiving event logs, and managing event metadata. It can
display events in both XML and plain text format. Stopping this service may
compromise security and reliability of the system. Host Process for Windows
Services Microsoft Corporation Microsoft Windows Operating System 6.3.9600.16384
[Running Services] EventSystem
### Internal Name: EventSystem. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k LocalService * Supports System Event
Notification Service (SENS), which provides automatic distribution of events to
subscribing Component Object Model (COM) components. If the service is stopped,
SENS will close and will not be able to provide logon and logoff notifications. If
this service is disabled, any services that explicitly depend on it will fail to
start. Host Process for Windows Services Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384
[Running Services] FontCache
### Internal Name: FontCache. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k LocalService * Optimizes performance of
applications by caching commonly used font data. Applications will start this
service if it is not already running. It can be disabled, though doing so will
degrade application performance. Host Process for Windows Services Microsoft
Corporation Microsoft Windows Operating System 6.3.9600.16384
[Running Services] FontCache3.0.0.0
### Internal Name: FontCache3.0.0.0. Status: service is running. Actual File:
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe * Optimizes
performance of Windows Presentation Foundation (WPF) applications by caching
commonly used font data. WPF applications will start this service if it is not
already running. It can be disabled, though doing so will degrade the performance
of WPF applications. PresentationFontCache.exe Microsoft Corporation Microsoft
.NET Framework 3.0.6920.7903
[Running Services] hidserv
### Internal Name: hidserv. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted * Activates and
maintains the use of hot buttons on keyboards, remote controls, and other
multimedia devices. It is recommended that you keep this service running. Host
Process for Windows Services Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384
[Running Services] igfxCUIService1.0.0.0
### Internal Name: igfxCUIService1.0.0.0. Status: service is running. Actual
File: C:\Windows\system32\igfxCUIService.exe * Service for Intel(R) HD Graphics
Control Panel igfxCUIService Module Intel Corporation Intel(R) Common User
Interface 6.15.10.3496
[Running Services] Intel(R) Capability Licensing Service Interface
### Internal Name: Intel(R) Capability Licensing Service Interface. Status:
service is running. Actual File: "C:\Program Files\Intel\iCLS
Client\HeciServer.exe" * Version: 1.31.8.1 Intel(R) Capability Licensing Service
Interface Intel(R) Corporation Intel(R) Capability Licensing Service Interface
1,31,8,1
[Running Services] iphlpsvc
### Internal Name: iphlpsvc. Status: service is running. Actual File:
C:\Windows\System32\svchost.exe -k NetSvcs * Provides tunnel connectivity using
IPv6 transition technologies (6to4, ISATAP, Port Proxy, and Teredo), and IP-HTTPS.
If this service is stopped, the computer will not have the enhanced connectivity
benefits that these technologies offer. Host Process for Windows Services Microsoft
Corporation Microsoft Windows Operating System 6.3.9600.16384
[Running Services] jhi_service
### Internal Name: jhi_service. Status: service is running. Actual File:
"C:\Program Files (x86)\Intel\Intel(R) Management Engine
Components\DAL\jhi_service.exe" * Intel(R) Dynamic Application Loader Host
Interface Service - Allows applications to access the local Intel (R) DAL Intel(R)
Dynamic Application Loader Host Interface Intel Corporation Intel(R) Dynamic
Application Loader Host Interface 9.5.12.1682
[Running Services] KeyIso
### Internal Name: KeyIso. Status: service is running. Actual File:
C:\Windows\system32\lsass.exe * The CNG key isolation service is hosted in the LSA
process. The service provides key process isolation to private keys and associated
cryptographic operations as required by the Common Criteria. The service stores and
uses long-lived keys in a secure process complying with Common Criteria
requirements. Local Security Authority Process Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384
[Running Services] LanmanServer
### Internal Name: LanmanServer. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k netsvcs * Supports file, print, and named-pipe
sharing over the network for this computer. If this service is stopped, these
functions will be unavailable. If this service is disabled, any services that
explicitly depend on it will fail to start. Host Process for Windows Services
Microsoft Corporation Microsoft Windows Operating System 6.3.9600.16384
[Running Services] LanmanWorkstation
### Internal Name: LanmanWorkstation. Status: service is running. Actual File:
C:\Windows\System32\svchost.exe -k NetworkService * Creates and maintains client
network connections to remote servers using the SMB protocol. If this service is
stopped, these connections will be unavailable. If this service is disabled, any
services that explicitly depend on it will fail to start. Host Process for Windows
Services Microsoft Corporation Microsoft Windows Operating System 6.3.9600.16384
[Running Services] lmhosts
### Internal Name: lmhosts. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted * Provides support
for the NetBIOS over TCP/IP (NetBT) service and NetBIOS name resolution for clients
on the network, therefore enabling users to share files, print, and log on to the
network. If this service is stopped, these functions might be unavailable. If this
service is disabled, any services that explicitly depend on it will fail to start.
Host Process for Windows Services Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384
[Running Services] LMS
### Internal Name: LMS. Status: service is running. Actual File: "C:\Program
Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe" * Intel(R)
Management and Security Application Local Management Service - Provides OS-related
Intel(R) ME functionality. Intel(R) Local Management Service Intel Corporation
Intel(R) Management and Security Application Local Management Service 9.5.10.1628
[Running Services] LSM
### Internal Name: LSM. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k DcomLaunch * Core Windows Service that manages
local user sessions. Stopping or disabling this service will result in system
instability. Host Process for Windows Services Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384
[Running Services] MMCSS
### Internal Name: MMCSS. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k netsvcs * Enables relative prioritization of
work based on system-wide task priorities. This is intended mainly for multimedia
applications. If this service is stopped, individual tasks resort to their default
priority. Host Process for Windows Services Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384
[Running Services] MpsSvc
### Internal Name: MpsSvc. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork * Windows Firewall helps
protect your computer by preventing unauthorized users from gaining access to your
computer through the Internet or a network. Host Process for Windows Services
Microsoft Corporation Microsoft Windows Operating System 6.3.9600.16384
[Running Services] msiserver
### Internal Name: msiserver. Status: service is running. Actual File:
C:\Windows\system32\msiexec.exe /V * Adds, modifies, and removes applications
provided as a Windows Installer (*.msi, *.msp) package. If this service is
disabled, any services that explicitly depend on it will fail to start. Windows
installer Microsoft Corporation Windows Installer - Unicode 5.0.9600.16384
[Running Services] NcbService
### Internal Name: NcbService. Status: service is running. Actual File:
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted * Brokers
connections that allow Windows Store Apps to receive notifications from the
internet. Host Process for Windows Services Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384
[Running Services] Netman
### Internal Name: Netman. Status: service is running. Actual File:
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted * Manages objects
in the Network and Dial-Up Connections folder, in which you can view both local
area network and remote connections. Host Process for Windows Services Microsoft
Corporation Microsoft Windows Operating System 6.3.9600.16384
[Running Services] netprofm
### Internal Name: netprofm. Status: service is running. Actual File:
C:\Windows\System32\svchost.exe -k LocalService * Identifies the networks to which
the computer has connected, collects and stores properties for these networks, and
notifies applications when these properties change. Host Process for Windows
Services Microsoft Corporation Microsoft Windows Operating System 6.3.9600.16384
[Running Services] NlaSvc
### Internal Name: NlaSvc. Status: service is running. Actual File:
C:\Windows\System32\svchost.exe -k NetworkService * Collects and stores
configuration information for the network and notifies programs when this
information is modified. If this service is stopped, configuration information
might be unavailable. If this service is disabled, any services that explicitly
depend on it will fail to start. Host Process for Windows Services Microsoft
Corporation Microsoft Windows Operating System 6.3.9600.16384
[Running Services] nsi
### Internal Name: nsi. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k LocalService * This service delivers network
notifications (e.g. interface addition/deleting etc) to user mode clients. Stopping
this service will cause loss of network connectivity. If this service is disabled,
any other services that explicitly depend on this service will fail to start. Host
Process for Windows Services Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384
[Running Services] NvNetworkService
### Internal Name: NvNetworkService. Status: service is running. Actual File:
"C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe" *
NVIDIA Network Service NVIDIA Network Service NVIDIA Corporation NVIDIA Network
Service 1.0.5.16
[Running Services] nvsvc
### Internal Name: nvsvc. Status: service is running. Actual File:
"C:\Windows\system32\nvvsvc.exe" * Provides system and desktop level support to the
NVIDIA display driver NVIDIA Driver Helper Service, Version 333.17 NVIDIA
Corporation NVIDIA Driver Helper Service, Version 333.17 8.17.13.3317
[Running Services] PcaSvc
### Internal Name: PcaSvc. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted * This service
provides support for the Program Compatibility Assistant (PCA). PCA monitors
programs installed and run by the user and detects known compatibility problems. If
this service is stopped, PCA will not function properly. Host Process for Windows
Services Microsoft Corporation Microsoft Windows Operating System 6.3.9600.16384
[Running Services] PlugPlay
### Internal Name: PlugPlay. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k DcomLaunch * Enables a computer to recognize and
adapt to hardware changes with little or no user input. Stopping or disabling this
service will result in system instability. Host Process for Windows Services
Microsoft Corporation Microsoft Windows Operating System 6.3.9600.16384
[Running Services] Power
### Internal Name: Power. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k DcomLaunch * Manages power policy and power
policy notification delivery. Host Process for Windows Services Microsoft
Corporation Microsoft Windows Operating System 6.3.9600.16384
[Running Services] ProfSvc
### Internal Name: ProfSvc. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k netsvcs * This service is responsible for
loading and unloading user profiles. If this service is stopped or disabled, users
will no longer be able to successfully sign in or sign out, apps might have
problems getting to users' data, and components registered to receive profile event
notifications won't receive them. Host Process for Windows Services Microsoft
Corporation Microsoft Windows Operating System 6.3.9600.16384
[Running Services] RasMan
### Internal Name: RasMan. Status: service is running. Actual File:
C:\Windows\System32\svchost.exe -k netsvcs * Manages dial-up and virtual private
network (VPN) connections from this computer to the Internet or other remote
networks. If this service is disabled, any services that explicitly depend on it
will fail to start. Host Process for Windows Services Microsoft Corporation
Microsoft Windows Operating System 6.3.9600.16384
[Running Services] RpcEptMapper
### Internal Name: RpcEptMapper. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k RPCSS * Resolves RPC interfaces identifiers to
transport endpoints. If this service is stopped or disabled, programs using Remote
Procedure Call (RPC) services will not function properly. Host Process for Windows
Services Microsoft Corporation Microsoft Windows Operating System 6.3.9600.16384
[Running Services] RpcSs
### Internal Name: RpcSs. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k rpcss * The RPCSS service is the Service Control
Manager for COM and DCOM servers. It performs object activations requests, object
exporter resolutions and distributed garbage collection for COM and DCOM servers.
If this service is stopped or disabled, programs using COM or DCOM will not
function properly. It is strongly recommended that you have the RPCSS service
running. Host Process for Windows Services Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384
[Running Services] SamSs
### Internal Name: SamSs. Status: service is running. Actual File:
C:\Windows\system32\lsass.exe * The startup of this service signals other services
that the Security Accounts Manager (SAM) is ready to accept requests. Disabling
this service will prevent other services in the system from being notified when the
SAM is ready, which may in turn cause those services to fail to start correctly.
This service should not be disabled. Local Security Authority Process Microsoft
Corporation Microsoft Windows Operating System 6.3.9600.16384
[Running Services] SAService
### Internal Name: SAService. Status: service is running. Actual File:
C:\Windows\system32\SAsrv.exe * SmartAudio Helper service
[Running Services] Schedule
### Internal Name: Schedule. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k netsvcs * Enables a user to configure and
schedule automated tasks on this computer. The service also hosts multiple Windows
system-critical tasks. If this service is stopped or disabled, these tasks will not
be run at their scheduled times. If this service is disabled, any services that
explicitly depend on it will fail to start. Host Process for Windows Services
Microsoft Corporation Microsoft Windows Operating System 6.3.9600.16384
[Running Services] SENS
### Internal Name: SENS. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k netsvcs * Monitors system events and notifies
subscribers to COM+ Event System of these events. Host Process for Windows Services
Microsoft Corporation Microsoft Windows Operating System 6.3.9600.16384
[Running Services] ShellHWDetection
### Internal Name: ShellHWDetection. Status: service is running. Actual File:
C:\Windows\System32\svchost.exe -k netsvcs * Provides notifications for AutoPlay
hardware events. Host Process for Windows Services Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384
[Running Services] Spooler
### Internal Name: Spooler. Status: service is running. Actual File:
C:\Windows\System32\spoolsv.exe * This service spools print jobs and handles
interaction with the printer. If you turn off this service, you wont be able to
print or see your printers. Spooler SubSystem App Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384
[Running Services] SSDPSRV
### Internal Name: SSDPSRV. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation * Discovers
networked devices and services that use the SSDP discovery protocol, such as UPnP
devices. Also announces SSDP devices and services running on the local computer. If
this service is stopped, SSDP-based devices will not be discovered. If this service
is disabled, any services that explicitly depend on it will fail to start. Host
Process for Windows Services Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384
[Running Services] SstpSvc
### Internal Name: SstpSvc. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k LocalService * Provides support for the Secure
Socket Tunneling Protocol (SSTP) to connect to remote computers using VPN. If this
service is disabled, users will not be able to use SSTP to access remote servers.
Host Process for Windows Services Microsoft Corporation Microsoft Windows
Operating System 6.3.9600.16384
[Running Services] stisvc
### Internal Name: stisvc. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k imgsvc * Provides image acquisition services for
scanners and cameras Host Process for Windows Services Microsoft Corporation
Microsoft Windows Operating System 6.3.9600.16384
[Running Services] SysMain
### Internal Name: SysMain. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted * Maintains and
improves system performance over time. Host Process for Windows Services Microsoft
Corporation Microsoft Windows Operating System 6.3.9600.16384
[Running Services] SystemEventsBroker
### Internal Name: SystemEventsBroker. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k DcomLaunch * Coordinates execution of background
work for WinRT application. If this service is stopped or disabled, then background
work might not be triggered. Host Process for Windows Services Microsoft
Corporation Microsoft Windows Operating System 6.3.9600.16384
[Running Services] TapiSrv
### Internal Name: TapiSrv. Status: service is running. Actual File:
C:\Windows\System32\svchost.exe -k NetworkService * Provides Telephony API (TAPI)
support for programs that control telephony devices on the local computer and,
through the LAN, on servers that are also running the service. Host Process for
Windows Services Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384
[Running Services] Themes
### Internal Name: Themes. Status: service is running. Actual File:
C:\Windows\System32\svchost.exe -k netsvcs * Provides user experience theme
management. Host Process for Windows Services Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384
[Running Services] TimeBroker
### Internal Name: TimeBroker. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation * Coordinates
execution of background work for WinRT application. If this service is stopped or
disabled, then background work might not be triggered. Host Process for Windows
Services Microsoft Corporation Microsoft Windows Operating System 6.3.9600.16384
[Running Services] TrkWks
### Internal Name: TrkWks. Status: service is running. Actual File:
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted * Maintains links
between NTFS files within a computer or across computers in a network. Host Process
for Windows Services Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384
[Running Services] Wcmsvc
### Internal Name: Wcmsvc. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted * Makes automatic
connect/disconnect decisions based on the network connectivity options currently
available to the PC and enables management of network connectivity based on Group
Policy settings. Host Process for Windows Services Microsoft Corporation Microsoft
Windows Operating System 6.3.9600.16384
[Running Services] WdiServiceHost
### Internal Name: WdiServiceHost. Status: service is running. Actual File:
C:\Windows\System32\svchost.exe -k LocalService * The Diagnostic Service Host is
used by the Diagnostic Policy Service to host diagnostics that need to run in a
Local Service context. If this service is stopped, any diagnostics that depend on
it will no longer function. Host Process for Windows Services Microsoft Corporation
Microsoft Windows Operating System 6.3.9600.16384
[Running Services] WdiSystemHost
### Internal Name: WdiSystemHost. Status: service is running. Actual File:
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted * The Diagnostic
System Host is used by the Diagnostic Policy Service to host diagnostics that need
to run in a Local System context. If this service is stopped, any diagnostics that
depend on it will no longer function. Host Process for Windows Services Microsoft
Corporation Microsoft Windows Operating System 6.3.9600.16384
[Running Services] WdNisSvc
### Internal Name: WdNisSvc. Status: service is running. Actual File: "C:\Program
Files\Windows Defender\NisSrv.exe" * Helps guard against intrusion attempts
targeting known and newly discovered vulnerabilities in network protocols Microsoft
Network Realtime Inspection Service Microsoft Corporation Microsoft Windows
Operating System 4.3.9600.16384
[Running Services] WinDefend
### Internal Name: WinDefend. Status: service is running. Actual File:
"C:\Program Files\Windows Defender\MsMpEng.exe" * Helps protect users from malware
and other potentially unwanted software Antimalware Service Executable Microsoft
Corporation Microsoft Windows Operating System 4.3.9600.16384
[Running Services] WinHttpAutoProxySvc
### Internal Name: WinHttpAutoProxySvc. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k LocalService * WinHTTP implements the client
HTTP stack and provides developers with a Win32 API and COM Automation component
for sending HTTP requests and receiving responses. In addition, WinHTTP provides
support for auto-discovering a proxy configuration via its implementation of the
Web Proxy Auto-Discovery (WPAD) protocol. Host Process for Windows Services
Microsoft Corporation Microsoft Windows Operating System 6.3.9600.16384
[Running Services] Winmgmt
### Internal Name: Winmgmt. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k netsvcs * Provides a common interface and object
model to access management information about operating system, devices,
applications and services. If this service is stopped, most Windows-based software
will not function properly. If this service is disabled, any services that
explicitly depend on it will fail to start. Host Process for Windows Services
Microsoft Corporation Microsoft Windows Operating System 6.3.9600.16384
[Running Services] WlanSvc
### Internal Name: WlanSvc. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted * The WLANSVC
service provides the logic required to configure, discover, connect to, and
disconnect from a wireless local area network (WLAN) as defined by IEEE 802.11
standards. It also contains the logic to turn your computer into a software access
point so that other devices or computers can connect to your computer wirelessly
using a WLAN adapter that can support this. Stopping or disabling the WLANSVC
service will make all WLAN adapters on your computer inaccessible from the Windows
networking UI. It is strongly recommended that you have the WLANSVC service running
if your computer has a WLAN adapter. Host Process for Windows Services Microsoft
Corporation Microsoft Windows Operating System 6.3.9600.16384
[Running Services] wscsvc
### Internal Name: wscsvc. Status: service is running. Actual File:
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted * The WSCSVC
(Windows Security Center) service monitors and reports security health settings on
the computer. The health settings include firewall (on/off), antivirus (on/off/out
of date), antispyware (on/off/out of date), Windows Update (automatically/manually
download and install updates), User Account Control (on/off), and Internet settings
(recommended/not recommended). The service provides COM APIs for independent
software vendors to register and record the state of their products to the Security
Center service. The Action Center (AC) UI uses the service to provide systray
alerts and a graphical view of the security health states in the AC control panel.
Network Access Protection (NAP) uses the service to report the security health
states of clients to the NAP Network Policy Server to make network quarantine
decisions. The service also has a public API that allows external consumers to
programmatically retrieve the aggregated security health state of the system. Host
Process for Windows Services Microsoft Corporation Microsoft Windows Operating
System 6.3.9600.16384
[Running Services] WSearch
### Internal Name: WSearch. Status: service is running. Actual File:
C:\Windows\system32\SearchIndexer.exe /Embedding * Provides content indexing,
property caching, and search results for files, e-mail, and other content.
Microsoft Windows Search Indexer Microsoft Corporation Windows Search
7.00.9600.16384
[Running Services] wudfsvc
### Internal Name: wudfsvc. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted * Creates and
manages user-mode driver processes. This service cannot be stopped. Host Process
for Windows Services Microsoft Corporation Microsoft Windows Operating System
6.3.9600.16384
[Running Services] ZAtheros Bt and Wlan Coex Agent
### Internal Name: ZAtheros Bt and Wlan Coex Agent. Status: service is running.
Actual File: C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe * Co-
existence Coordinator Service between 11a/b/g/n Wireless LAN and Bluetooth. Atheros
Coex Service Application Atheros Ath_Coex Application 8.0.0.270
[Uninstall]
[Applications] :HKLM {5EFD3544-2371-4900-8ACA-F157BA80FB0C}=MsiExec.exe
/X{5EFD3544-2371-4900-8ACA-F157BA80FB0C}
### Pro Evolution Soccer 2014 - (02) 05-2017
[Applications] :HKLM MozillaMaintenanceService="C:\Program Files (x86)\Mozilla
Maintenance Service\uninstall.exe"
### Mozilla Maintenance Service - (02) 05-2017
[Applications] :HKLM Mozilla Firefox 44.0.1 (x86 id)="C:\Program Files
(x86)\Mozilla Firefox\uninstall\helper.exe"
### Mozilla Firefox 44.0.1 (x86 id) - (02) 05-2017
[Applications] :HKLM UnHackMe_is1="C:\Program Files
(x86)\UnHackMe\unins000.exe" /SILENT
### UnHackMe 8.80 - (02) 05-2017
[Applications] :HKLM {5266F634-7B7D-4537-BDDC-98DD6CFCBAA1}=MsiExec.exe
/X{5266F634-7B7D-4537-BDDC-98DD6CFCBAA1}
### Online Application - (02) 05-2017
[Applications] :HKCU 15975b31049382c0
### - (02) 05-2017
[Applications] :HKLM Adobe Flash Player
NPAPI=C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_26_0_0_89_Plugin.exe -maintain
plugin
### Adobe Flash Player 26 NPAPI - (28) 04-2017
[Applications] :HKLM Adobe Flash Player
PPAPI=C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_25_0_0_148_pepper.exe
-maintain pepperplugin
### Adobe Flash Player 25 PPAPI - (12) 04-2017
[Applications] :HKLM {AC76BA86-7AD7-2530-0000-A00000000049}=MsiExec.exe
/I{AC76BA86-7AD7-2530-0000-A00000000049}
### Extended Asian Language font pack for Adobe Reader XI - (04) 03-2017
[Applications] :HKLM Opera 43.0.2442.1144="C:\Program Files
(x86)\Opera\Launcher.exe" /uninstall
### Opera Stable 43.0.2442.1144 - (02) 03-2017
[Applications] :HKLM Kingsoft Office=C:\Program Files (x86)\Kingsoft\Kingsoft
Office\10.2.0.5811\utility\uninst.exe
### WPS Office (10.2.0.5811) - (08) 02-2017
[Applications] :HKCU LINE=C:\Users\User\AppData\Local\LINE\bin\LineUnInst.exe
### LINE - (22) 01-2017
[Applications] :HKLM {8220EEFE-38CD-377E-8595-13398D740ACE}=MsiExec.exe
/X{8220EEFE-38CD-377E-8595-13398D740ACE}
### Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 - (10) 01-2017
[Applications] :HKLM {071c9b48-7c32-4621-a0ac-3f809523288f}=MsiExec.exe
/X{071c9b48-7c32-4621-a0ac-3f809523288f}
### Microsoft Visual C++ 2005 Redistributable (x64) - (11) 12-2016
[Applications] :HKLM WinMount_is1
### - (21) 09-2016
[Applications] :HKLM {811f60af}
### - (22) 07-2016
[Applications] :HKLM scilab-5.5.2 (64-bit)_is1="C:\Program Files\scilab-
5.5.2\unins000.exe" /SILENT
### scilab-5.5.2 (64-bit) - (23) 05-2016
[Applications] :HKLM {7299052b-02a4-4627-81f2-1818da5d550d}=MsiExec.exe
/X{7299052b-02a4-4627-81f2-1818da5d550d}
### Microsoft Visual C++ 2005 Redistributable - (27) 03-2016
[Applications] :HKLM {F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}=MsiExec.exe
/X{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}
### Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 - (27) 03-2016
[Applications] :HKLM {f65db027-aff3-4070-886a-
0d87064aabb1}="C:\ProgramData\Package Cache\{f65db027-aff3-4070-886a-
0d87064aabb1}\vcredist_x86.exe" /uninstall /quiet
### Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 - (27) 03-2016
[Applications] :HKLM {13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}=MsiExec.exe
/X{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}
### Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 - (27) 03-2016
[Applications] :HKLM {F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}=MsiExec.exe
/X{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}
### Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 - (27) 03-2016
[Applications] :HKLM {050d4fc8-5d48-4b8f-8972-
47c82c46020f}="C:\ProgramData\Package Cache\{050d4fc8-5d48-4b8f-8972-
47c82c46020f}\vcredist_x64.exe" /uninstall /quiet
### Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 - (27) 03-2016
[Applications] :HKLM {929FBD26-9020-399B-9A7A-751D61F0B942}=MsiExec.exe
/X{929FBD26-9020-399B-9A7A-751D61F0B942}
### Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.21005 - (27) 03-2016
[Applications] :HKLM {A749D8E6-B613-3BE3-8F5F-045C84EBA29B}=MsiExec.exe
/X{A749D8E6-B613-3BE3-8F5F-045C84EBA29B}
### Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.21005 - (27) 03-2016
[Applications] :HKLM {1D8E6291-B0D5-35EC-8441-6616F567A0F7}=MsiExec.exe
/X{1D8E6291-B0D5-35EC-8441-6616F567A0F7}
### Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 - (27) 03-2016
[Applications] :HKCU HP Photo Creations="C:\Users\User\AppData\Roaming\HP Photo
Creations\remove.exe"
### HP Photo Creations - (10) 03-2016
[Applications] :HKLM {2E25FCEB-EFCB-4696-AA01-D3CBAC721831}=MsiExec.exe
/I{2E25FCEB-EFCB-4696-AA01-D3CBAC721831}
### HP Deskjet 1510 series Help - (03) 03-2016
[Applications] :HKLM {912D30CF-F39E-4B31-AD9A-123C6B794EE2}=MsiExec.exe
/X{912D30CF-F39E-4B31-AD9A-123C6B794EE2}
### HP Update - (03) 03-2016
[Applications] :HKLM {EC27E742-EB04-4A2C-BA64-20271929528A}=MsiExec.exe
/I{EC27E742-EB04-4A2C-BA64-20271929528A}
### Product Improvement Study for HP Deskjet 1510 series - (03) 03-2016
[Applications] :HKLM {C9064E5C-D5AB-4EEB-86A6-50756901038A}=MsiExec.exe
/I{C9064E5C-D5AB-4EEB-86A6-50756901038A}
### HP Deskjet 1510 series Basic Device Software - (03) 03-2016
[Applications] :HKLM 749f32a07f28fec7
### - (29) 01-2016
[Applications] :HKLM 13c2c556bd907d41
### - (09) 01-2016
[Applications] :HKLM {98449C67-C7AF-BB53-112D-26C916814611}
### - (01) 07-2015
[Applications] :HKLM {B696F285-F54E-2524-58B1-E06A70ABE6BE}
### - (29) 06-2015
[Applications] :HKLM WinPcapInst=C:\Program Files (x86)\WinPcap\uninstall.exe
### WinPcap 4.1.2 - (29) 06-2015
[Applications] :HKLM {9A25302D-30C0-39D9-BD6F-21E6EC160475}=MsiExec.exe
/X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
### Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 - (20) 06-2015
[Applications] :HKLM a69b9bef-7300-455b-a3a5-f8d464755c8b=C:\PROGRA~3\INSTAL~1\
{482C4~1\Setup.exe /remove /q
### - (16) 06-2015
[Applications] :HKCU Akamai="C:\Users\User\AppData\Local\Akamai\uninstall.exe"
### Akamai NetSession Interface - (03) 06-2015
[Applications] :HKCU 792e88f7b37d9294
### - (13) 05-2015
[Applications] :HKLM {8A470330-70B2-49AD-86AF-79885EF9898A}=MsiExec.exe
/I{8A470330-70B2-49AD-86AF-79885EF9898A}
### FARO LS 1.1.501.0 (64bit) - (12) 01-2015
[Applications] :HKLM {E3E71D07-CD27-46CB-8448-16D4FB29AA13}=MsiExec.exe
/X{E3E71D07-CD27-46CB-8448-16D4FB29AA13}
### Microsoft WSE 3.0 Runtime - (12) 01-2015
[Applications] :HKLM {8CCEA24C-51AE-3B71-9092-
7D0C44DDA2DF}.KB958357=C:\Windows\SysWOW64\msiexec.exe /x {8CCEA24C-51AE-3B71-9092-
7D0C44DDA2DF} /qb+ REBOOTPROMPT=""
### Visual C++ 2008 - x64 (KB958357) - v9.0.30729.177 - (12) 01-2015
[Applications] :HKLM {8CCEA24C-51AE-3B71-9092-7D0C44DDA2DF}=MsiExec.exe
/X{8CCEA24C-51AE-3B71-9092-7D0C44DDA2DF}
### Microsoft Visual C++ 2008 x64 OpenMP Runtime 9.0.30729 - (12) 01-2015
[Applications] :HKLM {F6F09DD8-F39B-3A16-ADB9-C9E6B56903F9}=MsiExec.exe
/X{F6F09DD8-F39B-3A16-ADB9-C9E6B56903F9}
### Microsoft Visual C++ 2008 x64 CRT Runtime 9.0.30729 - (12) 01-2015
[Applications] :HKLM {F6F09DD8-F39B-3A16-ADB9-
C9E6B56903F9}.KB958357=C:\Windows\SysWOW64\msiexec.exe /x {F6F09DD8-F39B-3A16-ADB9-
C9E6B56903F9} /qb+ REBOOTPROMPT=""
### Visual C++ 2008 - x64 (KB958357) - v9.0.30729.177 - (12) 01-2015
[Applications] :HKLM {6DA2B636-698A-3294-BF4A-B5E11B238CDD}=MsiExec.exe
/X{6DA2B636-698A-3294-BF4A-B5E11B238CDD}
### Microsoft Visual C++ 2008 x64 MFC Runtime 9.0.30729 - (12) 01-2015
[Applications] :HKLM {6DA2B636-698A-3294-BF4A-
B5E11B238CDD}.KB958357=C:\Windows\SysWOW64\msiexec.exe /x {6DA2B636-698A-3294-BF4A-
B5E11B238CDD} /qb+ REBOOTPROMPT=""
### Visual C++ 2008 - x64 (KB958357) - v9.0.30729.177 - (12) 01-2015
[Applications] :HKLM {C3A57BB3-9AA6-3F6F-9395-6C062BDD5FC4}=MsiExec.exe
/X{C3A57BB3-9AA6-3F6F-9395-6C062BDD5FC4}
### Microsoft Visual C++ 2008 x64 ATL Runtime 9.0.30729 - (12) 01-2015
[Applications] :HKLM {C3A57BB3-9AA6-3F6F-9395-
6C062BDD5FC4}.KB958357=C:\Windows\SysWOW64\msiexec.exe /x {C3A57BB3-9AA6-3F6F-9395-
6C062BDD5FC4} /qb+ REBOOTPROMPT=""
### Visual C++ 2008 - x64 (KB958357) - v9.0.30729.177 - (12) 01-2015
[Applications] :HKLM {4B90093A-5D9C-3956-8ABB-95848BE6EFAD}=MsiExec.exe
/X{4B90093A-5D9C-3956-8ABB-95848BE6EFAD}
### Microsoft Visual C++ 2008 x86 OpenMP Runtime 9.0.30729 - (12) 01-2015
[Applications] :HKLM {4B90093A-5D9C-3956-8ABB-
95848BE6EFAD}.KB958357=C:\Windows\SysWOW64\msiexec.exe /x {4B90093A-5D9C-3956-8ABB-
95848BE6EFAD} /qb+ REBOOTPROMPT=""
### Visual C++ 2008 - x86 (KB958357) - v9.0.30729.177 - (12) 01-2015
[Applications] :HKLM {14866AAD-1F23-39AC-A62B-7091ED1ADE64}=MsiExec.exe
/X{14866AAD-1F23-39AC-A62B-7091ED1ADE64}
### Microsoft Visual C++ 2008 x86 CRT Runtime 9.0.30729 - (12) 01-2015
[Applications] :HKLM {14866AAD-1F23-39AC-A62B-
7091ED1ADE64}.KB958357=C:\Windows\SysWOW64\msiexec.exe /x {14866AAD-1F23-39AC-A62B-
7091ED1ADE64} /qb+ REBOOTPROMPT=""
### Visual C++ 2008 - x86 (KB958357) - v9.0.30729.177 - (12) 01-2015
[Applications] :HKLM {B42E259C-E4D4-37F1-A1B2-
EB9C4FC5A04D}.KB958357=C:\Windows\SysWOW64\msiexec.exe /x {B42E259C-E4D4-37F1-A1B2-
EB9C4FC5A04D} /qb+ REBOOTPROMPT=""
### Visual C++ 2008 - x86 (KB958357) - v9.0.30729.177 - (12) 01-2015
[Applications] :HKLM {B42E259C-E4D4-37F1-A1B2-EB9C4FC5A04D}=MsiExec.exe
/X{B42E259C-E4D4-37F1-A1B2-EB9C4FC5A04D}
### Microsoft Visual C++ 2008 x86 MFC Runtime 9.0.30729 - (12) 01-2015
[Applications] :HKLM {04B34E21-5BEE-3D2B-8D3D-E3E80D253F64}=MsiExec.exe
/X{04B34E21-5BEE-3D2B-8D3D-E3E80D253F64}
### Microsoft Visual C++ 2008 x86 ATL Runtime 9.0.30729 - (12) 01-2015
[Applications] :HKLM {04B34E21-5BEE-3D2B-8D3D-
E3E80D253F64}.KB958357=C:\Windows\SysWOW64\msiexec.exe /x {04B34E21-5BEE-3D2B-8D3D-
E3E80D253F64} /qb+ REBOOTPROMPT=""
### Visual C++ 2008 - x86 (KB958357) - v9.0.30729.177 - (12) 01-2015
[Applications] :HKLM {1F1C2DFC-2D24-3E06-BCB8-725134ADF989}=MsiExec.exe
/X{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}
### Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 - (12) 01-2015
[Applications] :HKLM {4B6C7001-C7D6-3710-913E-5BC23FCE91E6}=MsiExec.exe
/X{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}
### Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 - (12) 01-2015
[Applications] :HKLM {90F60409-7000-11D3-8CFE-0150048383C9}=MsiExec.exe
/I{90F60409-7000-11D3-8CFE-0150048383C9}
### Microsoft Visual Basic for Applications 7.1 (x64) English - (12) 01-2015
[Applications] :HKLM {90120064-0070-0000-0000-4000000FF1CE}=MsiExec.exe
/I{90120064-0070-0000-0000-4000000FF1CE}
### Microsoft Visual Basic for Applications 7.1 (x64) - (12) 01-2015
[Applications] :HKLM {9BE518E6-ECC6-35A9-88E4-87755C07200F}=MsiExec.exe
/X{9BE518E6-ECC6-35A9-88E4-87755C07200F}
### Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 - (12) 01-2015
[Applications] :HKLM {5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}=MsiExec.exe
/X{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}
### Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 - (12) 01-2015
[Applications] :HKLM {837b34e3-7c30-493c-8f6a-2b0f04e2912c}=MsiExec.exe
/X{837b34e3-7c30-493c-8f6a-2b0f04e2912c}
### Microsoft Visual C++ 2005 Redistributable - (12) 01-2015
[Applications] :HKLM {6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}=MsiExec.exe
/X{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}
### Microsoft Visual C++ 2005 Redistributable (x64) - (12) 01-2015
[Applications] :HKLM {B5E06417-A4AC-4225-B36E-7E34C91616E7}=MsiExec.exe
/I{B5E06417-A4AC-4225-B36E-7E34C91616E7}
### Intel Trusted Connect Service Client - (30) 12-2014
[Applications] :HKLM {1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2549743
### - (30) 12-2014
[Applications] :HKLM {1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2565063
### - (30) 12-2014
[Applications] :HKLM {1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2524860
### - (30) 12-2014
[Applications] :HKLM {1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2544655
### - (30) 12-2014
[Applications] :HKLM {F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2549743
### - (30) 12-2014
[Applications] :HKLM {F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2524860
### - (30) 12-2014
[Applications] :HKLM {F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2565063
### - (30) 12-2014
[Applications] :HKLM {F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2544655
### - (30) 12-2014
[Applications] :HKLM VLC media player=C:\Program Files\VideoLAN\VLC\uninstall.exe
### VLC media player 2.1.3 - (30) 12-2014
[Applications] :HKLM GOM Player="C:\Program Files
(x86)\GRETECH\GomPlayer\Uninstall.exe"
### GOM Player - (30) 12-2014
[Applications] :HKLM {AC76BA86-7AD7-1033-7B44-AB0000000001}=MsiExec.exe
/I{AC76BA86-7AD7-1033-7B44-AB0000000001}
### Adobe Reader XI (11.0.10) - (30) 12-2014
[Applications] :HKLM PhotoScape="C:\Program Files (x86)\PhotoScape\uninstall.exe"
### PhotoScape - (30) 12-2014
[Applications] :HKLM {8B9FA5FF-3E61-4658-B0DA-E6DDB46D6BAD}_is1="C:\Program Files
(x86)\SMADAV\unins000.exe" /SILENT
### SMADAV version 9.9.1 - (30) 12-2014
[Applications] :HKLM WinRAR archiver=C:\Program Files\WinRAR\uninstall.exe
### WinRAR 5.10 (64-bit) - (30) 12-2014
[Applications] :HKLM {AB5C933E-5C7D-4D30-B314-9C83A49B94BE}=MsiExec.exe
/I{AB5C933E-5C7D-4D30-B314-9C83A49B94BE}
### ATK Package - (30) 12-2014
[Applications] :HKLM {A84A4FB1-D703-48DB-89E0-68B6499D2801}=MsiExec.exe
/X{A84A4FB1-D703-48DB-89E0-68B6499D2801}
### Qualcomm Atheros Bluetooth Suite (64) - (30) 12-2014
[Applications] :HKLM {28006915-2739-4EBE-B5E8-49B25D32EB33}="C:\Program Files
(x86)\InstallShield Installation Information\{28006915-2739-4EBE-B5E8-
49B25D32EB33}\setup.exe" -runfromtemp -l0x0409 -removeonly
### Qualcomm Atheros Client Installation Program - (30) 12-2014
[Applications] :HKLM InstallShield_{5CA55DFC-2008-460F-B7A7-
FB92100C4494}=C:\Program Files (x86)\InstallShield Installation Information\
{5CA55DFC-2008-460F-B7A7-FB92100C4494}\setup.exe
### Alcor Micro USB Card Reader Driver - (30) 12-2014
[Applications] :HKLM InstallShield Uninstall Information
### - (30) 12-2014
[Applications] :HKLM {5CA55DFC-2008-460F-B7A7-FB92100C4494}
### Alcor Micro USB Card Reader Driver - (30) 12-2014
[Applications] :HKLM AmUStor
### - (30) 12-2014
[Applications] :HKLM {8833FFB6-5B0C-4764-81AA-06DFEED9A476}=C:\Program Files
(x86)\InstallShield Installation Information\{8833FFB6-5B0C-4764-81AA-
06DFEED9A476}\setup.exe -runfromtemp -removeonly
### Realtek Ethernet Controller Driver - (30) 12-2014
[Applications] :HKLM FFD10ECE-F715-4a86-9BD8-F6F47DA5DA1C=C:\Program Files
(x86)\Intel\Intel(R) Dynamic Platform and Thermal Framework\Uninstall\setup.exe
-uninstall
### Intel(R) Dynamic Platform and Thermal Framework - (30) 12-2014
[Applications] :HKLM {4D3286A6-F6AB-498A-82A4-E4F040529F3D}=MsiExec.exe
/I{4D3286A6-F6AB-498A-82A4-E4F040529F3D}
### ASUS Smart Gesture - (30) 12-2014
[Applications] :HKLM
DAA6E0EEB715139C1CEA332C78AB4609FB3C211B=C:\PROGRA~1\DIFX\DDFC0430A8092634\dpinst.e
xe /u
C:\Windows\System32\DriverStore\FileRepository\asustp.inf_amd64_db619cf391ea9938\as
ustp.inf
### Windows Driver Package - ASUS (ATP) Mouse (03/18/2014 6.0.0.35) - (30) 12-
2014
[Applications] :HKLM SAII=C:\Program Files\Conexant\SAII\SETUP64.EXE -U -ISAII
-SWTM="HDAudioAPI-D9A3021B-9BCE-458C-B667-9029C4EF4050,1801"
### - (30) 12-2014
[Applications] :HKLM cAudioFilterAgent=C:\Program
Files\CONEXANT\cAudioFilterAgent\SETUP64.EXE -U -IcAudioFilterAgent
-SM=cAudioFilterAgent64.exe,16
### - (30) 12-2014
[Applications] :HKLM MA4String=C:\Program Files\Conexant\MA4String\SETUP64.EXE -U
-IMA4String
### - (30) 12-2014
[Applications] :HKLM MA4Preset=C:\Program Files\Conexant\MA4Preset\SETUP64.EXE -U
-IMA4Preset
### - (30) 12-2014
[Applications] :HKLM MaxxAudio=C:\Program Files\Conexant\MaxxAudio\SETUP64.EXE -U
-IMaxxAudio
### - (30) 12-2014
[Applications] :HKLM CxAudMsg=C:\Program Files\Conexant\CxAudMsg\SETUP64.EXE -U
-ICxAudMsg
### - (30) 12-2014
[Applications] :HKLM CNXT_AUDIO_HDA=C:\Program
Files\CONEXANT\CNXT_AUDIO_HDA\UIU64a.exe -U -G -IX40Plmwa.inf
### Conexant HD Audio - (30) 12-2014
[Applications] :HKLM {B2FE1952-0186-46C3-BAEC-
A80AA35AC5B8}_Display.PhysX="C:\Windows\SysWOW64\RunDll32.EXE" "C:\Program
Files\NVIDIA Corporation\Installer2\installer.{9324E3F2-F0A3-4A1A-BB12-
8A80EEE8D8B8}\NVI2.DLL",UninstallPackage Display.PhysX
### NVIDIA PhysX System Software 9.13.1220 - (30) 12-2014
[Applications] :HKLM {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Update.Core
### NVIDIA Update Core - (30) 12-2014
[Applications] :HKLM {80407BA7-7763-4395-AB98-5233F1B34E65}=MsiExec.exe
/I{80407BA7-7763-4395-AB98-5233F1B34E65}
### NVIDIA PhysX - (30) 12-2014
[Applications] :HKLM {582876EC-A178-44D4-9823-C10D6C62EAFF}=MsiExec /X{80407BA7-
7763-4395-AB98-5233F1B34E65}
### - (30) 12-2014
[Applications] :HKLM {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Optimus
### NVIDIA Optimus Update 14.6.22 - (30) 12-2014
[Applications] :HKLM {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Network.Service
### NVIDIA Network Service - (30) 12-2014
[Applications] :HKLM {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer
### NVIDIA Install Application - (30) 12-2014
[Applications] :HKLM {B2FE1952-0186-46C3-BAEC-
A80AA35AC5B8}_Display.Driver="C:\Windows\SysWOW64\RunDll32.EXE" "C:\Program
Files\NVIDIA Corporation\Installer2\installer.{9324E3F2-F0A3-4A1A-BB12-
8A80EEE8D8B8}\NVI2.DLL",UninstallPackage Display.Driver
### NVIDIA Graphics Driver 333.17 - (30) 12-2014
[Applications] :HKLM {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel
### NVIDIA Control Panel 333.17 - (30) 12-2014
[Applications] :HKLM {F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}=C:\Program Files
(x86)\Intel\Intel(R) Processor Graphics\Uninstall\setup.exe -uninstall
### Intel(R) Processor Graphics - (30) 12-2014
[Applications] :HKLM {1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2467173
### - (30) 12-2014
[Applications] :HKLM {1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB982573
### - (30) 12-2014
[Applications] :HKLM {1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2151757
### - (30) 12-2014
[Applications] :HKLM {F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2151757
### - (30) 12-2014
[Applications] :HKLM {F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB982573
### - (30) 12-2014
[Applications] :HKLM {F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2467173
### - (30) 12-2014
[Applications] :HKLM {65153EA5-8B6E-43B6-857B-C6E4FC25798A}=C:\Program Files
(x86)\Intel\Intel(R) Management Engine Components\Uninstall\setup.exe -uninstall
### Intel(R) Management Engine Components - (30) 12-2014
[Applications] :HKLM AddressBook
### - (22) 08-2013
[Applications] :HKLM IE4Data
### - (22) 08-2013
[Applications] :HKLM IE5BAKEX
### - (22) 08-2013
[Applications] :HKLM Connection Manager
### - (22) 08-2013
[Applications] :HKLM DirectDrawEx
### - (22) 08-2013
[Applications] :HKLM DXM_Runtime
### - (22) 08-2013
[Applications] :HKLM IE40
### - (22) 08-2013
[Applications] :HKLM Fontcore
### - (22) 08-2013
[Applications] :HKLM MPlayer2
### - (22) 08-2013
[Applications] :HKLM SchedulingAgent
### - (22) 08-2013
[Applications] :HKLM WIC
### - (22) 08-2013
[Applications] :HKLM IEData
### - (22) 08-2013
[Applications] :HKLM MobileOptionPack
### - (22) 08-2013
[Applications] :HKLM DXM_Runtime
### - (22) 08-2013
[Applications] :HKLM Fontcore
### - (22) 08-2013
[Applications] :HKLM IE40
### - (22) 08-2013
[Applications] :HKLM AddressBook
### - (22) 08-2013
[Applications] :HKLM Connection Manager
### - (22) 08-2013
[Applications] :HKLM DirectDrawEx
### - (22) 08-2013
[Applications] :HKLM MPlayer2
### - (22) 08-2013
[Applications] :HKLM SchedulingAgent
### - (22) 08-2013
[Applications] :HKLM WIC
### - (22) 08-2013
[Applications] :HKLM MobileOptionPack
### - (22) 08-2013
[Applications] :HKLM IE4Data
### - (22) 08-2013
[Applications] :HKLM IE5BAKEX
### - (22) 08-2013
[Applications] :HKLM IEData
### - (22) 08-2013
[MD5]
[C53B99F4EB6C0BBE7313777B3ED03E89][1 1732408
0177D96DC79E844E0E0D40C855C5423DF91C80E7 ]C:\ESUPPORT\MANUAL\EMANUAL.EXE
[7A97AA40D8A3DA4A9095873C72D524C5][1 1534184
D219DB66995E0548EA1226CB1806388B1AC718F7 ]C:\PROGRAM FILES (X86)\ADOBE\READER
11.0\READER\ACRORD32.EXE
[489FA9A917C02A0AD2824A1339C13485][1 283960
C7814881379546F07EC17D605B534D21BB5619E7 ]C:\PROGRAM FILES (X86)\ASUS\ASUS SMART
GESTURE\ASTPCENTER\X64\ASUSTPCENTER.EXE
[FA1BFFE455074BD7445AB75B449BF9AD][1 176952
1D912AAA5BC7084627BF4B8184963D68C3C7C1F7 ]C:\PROGRAM FILES (X86)\ASUS\ASUS SMART
GESTURE\ASTPCENTER\X64\ASUSTPHELPER.EXE
[67BCFC63F639C1C7F68E4F8ED9305587][1 18232
138ECFA27C05279D5FFF1A18890CBA6AF2BD630A ]C:\PROGRAM FILES (X86)\ASUS\ASUS SMART
GESTURE\ASTPCENTER\X64\ASUSTPLAUNCHER.EXE
[6C0D429419FC1E1A16AA0CF769C3863D][1 355128
3C43C691CF1B844E0AAA9B768CC92812F5994928 ]C:\PROGRAM FILES (X86)\ASUS\ASUS SMART
GESTURE\ASTPCENTER\X64\ASUSTPLOADER.EXE
[564CB886D1A968B9798C1AB03F4EB54F][1 115512
5BF83A533E70C33DBB315E7CC67AB820352E00A6 ]C:\PROGRAM FILES (X86)\ASUS\ATK
PACKAGE\ATK HOTKEY\ASLDRSRV.EXE
[47F12AD8FD0151607CE66D8A165C28F7][1 303928
CDFE72AEEB4E69A860E6F92A28DDE6DB17E632E7 ]C:\PROGRAM FILES (X86)\ASUS\ATK
PACKAGE\ATK HOTKEY\HCONTROL.EXE
[4F870EF9292559AB9DE6F31527A1DCBF][1 113312
569A88D83A940F65117C86CCB484AB8632498C83 ]C:\PROGRAM FILES (X86)\ASUS\ATK
PACKAGE\ATK HOTKEY\KBFILTR.EXE
[08B018EF53C79AF2DAC005B494B9AF53][1 109880
E3B71C9B49D2603298DC3D13C18A4349B9B0A7B3 ]C:\PROGRAM FILES (X86)\ASUS\ATK
PACKAGE\ATK HOTKEY\SIMAPPEXEC.EXE
[230553C24EEE56CA07CF66117A10BFCC][1 209720
7395C9D710EC8576E519503F6ED9408218C5E260 ]C:\PROGRAM FILES (X86)\ASUS\ATK
PACKAGE\ATK MEDIA\DMEDIA.EXE
[C435191FAD19B43E5C3082E4275DCE75][1 19768
]C:\PROGRAM FILES (X86)\ASUS\ATK PACKAGE\ATK WMIACPI\ATKWMIACPI64.SYS
[4C016FD76ED5C05E84CA8CAB77993961][1 15416
]C:\PROGRAM FILES (X86)\ASUS\ATK PACKAGE\ATKGFNEX\ASMMAP64.SYS
[DBC598E47E7A382E60E2A4745D41FEF9][1 96896
]C:\PROGRAM FILES (X86)\ASUS\ATK PACKAGE\ATKGFNEX\GFNEXSRV.EXE
[99B0DD6A5DF7E130C81C7CC05137A861][1 406328
BC4DD7065577EF7E41023248C8253BC07AD642A4 ]C:\PROGRAM FILES (X86)\ASUS\ATK
PACKAGE\ATKOSD2\ATKOSD2.EXE
[998667FAC120069B57A599ABF2880E11][2 12928
7969BE4F17FD8BDF71241355B5C69935DA46D72D ]C:\PROGRAM FILES (X86)\BLUETOOTH
SUITE\ACTIVATEDESKTOP.EXE
[BBF78A7D6F9BFF37927303ED2539FAB7][1 319104
]C:\PROGRAM FILES (X86)\BLUETOOTH SUITE\ADMINSERVICE.EXE
[86B8B1F5C1189D68B07666784BE882FE][2 323584
]C:\PROGRAM FILES (X86)\BLUETOOTH SUITE\ATH_COEXAGENT.EXE
[49B7481C3D50FAABAF07F775E077FD8B][1 134784
]C:\PROGRAM FILES (X86)\BLUETOOTH SUITE\BTVSTACK.EXE
[07A37CB5C5A01E73FB69F138FAE2DB0E][1 1021128
163ECF59988DAAFB98463C9CA847CF98B59785B7 ]C:\PROGRAM FILES (X86)\COMMON
FILES\ADOBE\ARM\1.0\ADOBEARM.EXE
[4C72FDD915D62EAEF149BD9C73AB9CF4][1 81088
102AAA1D93A7F84D9071E9EABFEFD5F01ED9F267 ]C:\PROGRAM FILES (X86)\COMMON
FILES\ADOBE\ARM\1.0\ARMSVC.EXE
[DD59DB2A6E582A80ED06636E50B36F59][1 2048
D01141B16F1B341E6464864AC5A7D62AC8C00894 ]C:\PROGRAM FILES (X86)\COMMON
FILES\MICROSOFT SHARED\INK\IPSEVENTLOGMSG.DLL
[ -2][0 -1
]C:\PROGRAM FILES (X86)\GOOGLE\PICASA3\PICASA3.EXE
[ADA4C8A5F210B0F5EEED547FA1B537CF][1 2758200
]C:\PROGRAM FILES (X86)\GRETECH\GOMPLAYER\GOM.EXE
[34D296AFC913E302953C70463EF09A48][1 96056
]C:\PROGRAM FILES (X86)\HP\HP SOFTWARE UPDATE\HPWUSCHD2.EXE
[52069AEB42D3D0F97CBCA1085EBF55E6][1 169432
]C:\PROGRAM FILES (X86)\INTEL\INTEL(R) MANAGEMENT ENGINE
COMPONENTS\DAL\JHI_SERVICE.EXE
[E2952760B05A256FB1412D20A41C89C1][1 390616
]C:\PROGRAM FILES (X86)\INTEL\INTEL(R) MANAGEMENT ENGINE COMPONENTS\LMS\LMS.EXE
[849D66021A0EF43A20137BA9D85ECADF][1 222720
]C:\PROGRAM FILES (X86)\INTERNET EXPLORER\IELOWUTIL.EXE
[A9CF130554ECB9FEDDEA199BB25D328A][1 1841920
]C:\PROGRAM FILES (X86)\KINGSOFT\KINGSOFT OFFICE\10.2.0.5811\OFFICE6\KTPCNTR.EXE
[40855BAC4FBD8686971CC67C2B99F390][1 578304
]C:\PROGRAM FILES (X86)\KINGSOFT\KINGSOFT OFFICE\10.2.0.5811\WTOOLEX\WPSUPDATE.EXE
[065F7A34C446184F6356703EEE146A6E][1 625408
]C:\PROGRAM FILES (X86)\KINGSOFT\KINGSOFT OFFICE\KSOLAUNCH.EXE
[B83C9114A1C7318184080128464063AA][1 173824
]C:\PROGRAM FILES (X86)\KINGSOFT\KINGSOFT OFFICE\WPSCLOUDSVR.EXE
[4C064FD2776BD409A6A05689F4654EB2][2 136192
0F5463A65EECB52E972E106180B8391392A4D7C8 ]C:\PROGRAM FILES (X86)\KONAMI\PRO
EVOLUTION SOCCER 2014\PESEDIT SELECTOR.EXE
[742412B75CC7840FD36AE634719F640B][1 393672
]C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\FIREFOX.EXE
[A162D258A73516324DA7D7D44D04F1A9][1 146888
]C:\PROGRAM FILES (X86)\MOZILLA MAINTENANCE SERVICE\MAINTENANCESERVICE.EXE
[40F22D18E6A2B68A0E2634CE14301C51][2 929792
B88A8A0B1C8494EC9683077CB0942B67A59A5806 ]C:\PROGRAM FILES
(X86)\NETCUTDEFENDER\NETCUTDEFENDER.EXE
[2870CE9BFD6BA66FB0FFC6D11C9E41A7][2 262144
]C:\PROGRAM FILES (X86)\NETCUTDEFENDER\SERVICES\AIPS.EXE
[E09C5339746C10596C1BA740956F3416][1 1631008
CE5986DEBE9307CAFE5F7DA84DE624845A08C886 ]C:\PROGRAM FILES (X86)\NVIDIA
CORPORATION\NETSERVICE\NVNETWORKSERVICE.EXE
[42663C9A625EA030F10746EBA60F8CCD][1 2350880
28101C636DE96620338B16556A78591F33E3C061 ]C:\PROGRAM FILES (X86)\NVIDIA
CORPORATION\UPDATE CORE\NVBACKEND.EXE
[A897CB2ED77492B013553EC25C5B4584][1 834648
]C:\PROGRAM FILES (X86)\OPERA\LAUNCHER.EXE
[A990930EA25BB8359A4EBC5043B8FA59][1 7406656
]C:\PROGRAM FILES (X86)\PHOTOSCAPE\PHOTOSCAPE.EXE
[ -2][0 -1
]C:\PROGRAM FILES (X86)\SKYPE\\PHONE\SKYPE.EXE
[37E95CA1EAB1DB1FB4D3D815D83DE0A6][1 1193880
C0B3FF4D1B7B954C9FFC9F618B0AABF2DBD46DBA ]C:\PROGRAM FILES
(X86)\UNHACKME\HACKMON.EXE
[BE6C6AAC65CFF551E2E83404AA9F94BF][1 11239320
DD658B25B54AACEA20177BC894E46A9805BD1B02 ]C:\PROGRAM FILES
(X86)\UNHACKME\REANIMATOR.EXE
[89A43B58089C434C598E26E4FD8FD6BE][1 2575256
9B705C55A844C8507693B82839DDDA5C5ADAFEDD ]C:\PROGRAM FILES
(X86)\UNHACKME\UNHACKME.EXE
[B60F58F175DE20A6739194E85B035178][1 117264
]C:\PROGRAM FILES (X86)\WINPCAP\RPCAPD.EXE
[0AF7D4CC9262C143B692B3A83C13D850][1 915160
]C:\PROGRAM FILES\CONEXANT\CAUDIOFILTERAGENT\CAUDIOFILTERAGENT64.EXE
[2899F16BF6B6242F2C469EAE84346770][2 3735640
E5DFF5D50AEE1B87AC6CA0EA6F3D473A6C085A43 ]C:\PROGRAM
FILES\CONEXANT\MAXXAUDIO\MAXXAUDIOCONTROL64.EXE
[4F8B94EC4D4FFA0712CCADF8145F28D1][1 1830616
]C:\PROGRAM FILES\CONEXANT\SAII\SACPL.EXE
[2121EB9E70C5931F3EC8741D47A1CB74][1 6340640
]C:\PROGRAM FILES\HP\HP DESKJET 1510 SERIES\BIN\HP DESKJET 1510 SERIES.EXE
[CEC2EE3F2D7D9E14E1E1BAF0D740D860][1 5642272
]C:\PROGRAM FILES\HP\HP DESKJET 1510 SERIES\BIN\HPCUSTPARTIC.EXE
[E0FA3B6D94F635426724029BEEE45FCA][1 6259744
]C:\PROGRAM FILES\HP\HP DESKJET 1510 SERIES\BIN\HPQDTSS.EXE
[925471076EB70C97DFC7B4FCC2AE39D6][1 6631456
]C:\PROGRAM FILES\HP\HP DESKJET 1510 SERIES\BIN\HPSTATUSBL.DLL
[DAE6C3099D291EED8922A65C29ABCF52][2 747520
]C:\PROGRAM FILES\INTEL\ICLS CLIENT\HECISERVER.EXE
[D45226E3E7A25F1E7CE8DF8FD0A2A098][1 828376
]C:\PROGRAM FILES\INTEL\ICLS CLIENT\SOCKETHECISERVER.EXE
[1C39C41D50FF7113748D825F4327D406][1 804464
]C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
[C3FD97F6EB5C60B96E09E6930ECDFFFE][1 2446680
2E2C0878B20F0EB624F560BFC469C8A9274F65DA ]C:\PROGRAM FILES\NVIDIA
CORPORATION\DISPLAY\NVTRAY.EXE
[38C3C1225638BF1E8665060A51C4F598][1 1196488
AFC8F95919B5AAC50D6018E4485607B707A6F1C0 ]C:\PROGRAM FILES\NVIDIA
CORPORATION\DISPLAY\NVXDSYNC.EXE
[8D96A39732DC55393E21020BD9DA141A][2 911872
594E7036BDF571538D907A0CAB7FA79544C2421E ]C:\PROGRAM FILES\SCILAB-
5.5.2\BIN\WSCILEX.EXE
[9ACB56CF4AD684E812D94D0DDC912857][2 131091
7B1CAF8024458D5F6C120C3EDF1369BF24FBFB36 ]C:\PROGRAM FILES\VIDEOLAN\VLC\VLC.EXE
[90B85FFBDEEAD1BE861D59134EA985B0][1 23840
]C:\PROGRAM FILES\WINDOWS DEFENDER\MSMPENG.EXE
[78ABEA36C5228E99D849D478A7F3C814][1 346872
]C:\PROGRAM FILES\WINDOWS DEFENDER\NISSRV.EXE
[9CE95E2A32023CE9D9B38EE2295688A9][1 1402368
]C:\PROGRAM FILES\WINDOWS MEDIA PLAYER\WMPNETWK.EXE
[324F9D3EEEE321EA60641362FE94D188][6 4561920
]C:\PROGRAM FILES\WINDOWS NT\ACCESSORIES\WORDPAD.EXE
[ -2][0 -1
]C:\PROGRAM FILES\WINDOWS SIDEBAR\SIDEBAR.EXE
[95EBCD689FC41B1B658AC5FB9CE08714][2 139776
A6452946FC863E1C8126025A29763F591E107861 ]C:\PROGRAM
FILES\WINDOWSAPPS\MICROSOFT.WINDOWSCOMMUNICATIONSAPPS_17.5.9600.20911_X64__8WEKYB3D
8BBWE\LIVECOMM.EXE
[6F0CC657B8FDA5B5F82F51F330EA3CA7][1 267352
]C:\PROGRAM FILES\WINRAR\RAREXT32.DLL
[D6E2ED7F1F7BE7CCB8676491BF950B57][1 4673432
]C:\USERS\USER\APPDATA\LOCAL\AKAMAI\NETSESSION_WIN.EXE
[18145C69C9F7740A0F1400AC622792C9][1 610768
]C:\USERS\USER\APPDATA\LOCAL\LINE\BIN\LINELAUNCHER.EXE
[859C3C109F85150D76DA60482FEAC3F2][1 186368
]C:\USERS\USER\APPDATA\ROAMING\HP PHOTO CREATIONS\COMMUNICATOR.EXE
[8A9D646284BED4247484963FA9F3EA02][1 149504
]C:\USERS\USER\APPDATA\ROAMING\HP PHOTO CREATIONS\PHOTOPRODUCT.EXE
[2B5F7C1B260D391E047151AA788E3E24][2 145408
E0AA12EE7341F215864C0EEC7B5945E4F7EA29FC ]C:\USERS\USER\ZKRZFE.EXE
[8479DC46E9A09015C0777A16BC22A15D][1 2328880
]C:\WINDOWS\EXPLORER.EXE
[FA19CFB97AA20A5E402EB6A5AC7E4295][1 804464
85AE8B7073D21EE1D3F9A9C3D969B3D972806280 ]
C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V4.0.30319\EVENTLOGMESSAGES.DLL
[04A4541C92B70513EB8C883C9BC28C21][1 81560
457591F6606AE031046DBB6023DB4F94522D5274 ]
C:\WINDOWS\MICROSOFT.NET\FRAMEWORK64\V2.0.50727\ASPNET_RC.DLL
[6671A48C12AC9B113BC40246F86335EE][1 795304
03FCA7DE8D96DEB6B4560C55015E2C485A4416AD ]
C:\WINDOWS\MICROSOFT.NET\FRAMEWORK64\V2.0.50727\EVENTLOGMESSAGES.DLL
[FFA6791937150C8E49B2D4CCE6BA52DF][1 8872
949B8BCB153B2E638C6331B4C7406D3AEFC15A4F ]
C:\WINDOWS\MICROSOFT.NET\FRAMEWORK64\V3.0\WINDOWS COMMUNICATION
FOUNDATION\SERVICEMODELEVENTS.DLL
[1C52387BF5A127F5F3BFB31288F30D93][1 43696
]C:\WINDOWS\MICROSOFT.NET\FRAMEWORK64\V3.0\WPF\PRESENTATIONFONTCACHE.EXE
[FA6650A3F96CECD493FC11934D534FE6][1 804464
50F32EC1C46DC538A356818717FF84660ED51276 ]
C:\WINDOWS\MICROSOFT.NET\FRAMEWORK64\V4.0.30319\EVENTLOGMESSAGES.DLL
[161CEB1A0A864F04C6BF789D83B83CDC][1 18040
C5ACA73C104E59A2FC800B6D8B2F3A7AB66D80D5 ]
C:\WINDOWS\MICROSOFT.NET\FRAMEWORK64\V4.0.30319\SERVICEMODELEVENTS.DLL
[1092B3190E69E0C5ECBCE90F171DE047][1 139856
]C:\WINDOWS\MICROSOFT.NET\FRAMEWORK64\V4.0.30319\SMSVCHOST.EXE
[DA56FFA46030E6FEB215E3D5DAA65B11][1 98816
]C:\WINDOWS\SERVICING\TRUSTEDINSTALLER.EXE
[8176FBA685178FB0F52D46693474FA50][1 183296
]C:\WINDOWS\SYSNATIVE\APPMGMTS.DLL
[BE5A38071760E223CEEE9C8D9A0BFF9F][1 1297408
]C:\WINDOWS\SYSNATIVE\COMRES.DLL
[552BF16E6398EDD8E320D70FE1DF8DF4][1 13312
]C:\WINDOWS\SYSNATIVE\D3D8THK.DLL
[854DA94B8CB68D74CB7480B2F426CA2A][1 580096
]C:\WINDOWS\SYSNATIVE\DDRAW.DLL
[59E2D5DD885C5A06C16CD5E309A5060A][1 655872
8446E6ED40672B96171DFB86C340336D889D31D2 ]C:\Windows\SYSNATIVE\DNSAPI.DLL
[5F540AD6674AEFD64C1051648FF87DE3][1 532480
]C:\WINDOWS\SYSNATIVE\DSOUND.DLL
[448D8F8B51F785EAB56947D94EBDFC66][1 506880
]C:\WINDOWS\SYSNATIVE\HNETCFG.DLL
[F3A96882598EA84470646C6501917A98][1 209168
]C:\WINDOWS\SYSNATIVE\IMM32.DLL
[0D12F606DE18A5739AF27F12A32C6A6E][1 160128
]C:\WINDOWS\SYSNATIVE\IPHLPAPI.DLL
[8420491FFA891600A88FD12F5059A54C][1 22240
]C:\WINDOWS\SYSNATIVE\KSUSER.DLL
[74B258D5896FC8F8256E8D03459AC2A2][1 3072
]C:\WINDOWS\SYSNATIVE\LPK.DLL
[D72877D08AC821E3983C185D12034B19][1 23552
]C:\WINDOWS\SYSNATIVE\MIDIMAP.DLL
[BBB22E224FC242E80DF2179A07066C82][1 9728
]C:\WINDOWS\SYSNATIVE\MSCTFIME.IME
[41C101B9BC1EAD38F886719C5652838F][1 23157248
]C:\WINDOWS\SYSNATIVE\MSHTML.DLL
[6A5C1EA6E0B31B168FDE21A1FDC078C2][1 7168
]C:\WINDOWS\SYSNATIVE\MSIMG32.DLL
[896B307E803430F67EC772807F9CC023][1 338432
]C:\WINDOWS\SYSNATIVE\MSWSOCK.DLL
[4CD5B246B2DB81DC403B7C9041456B0E][1 67584
]C:\WINDOWS\SYSNATIVE\NAPINSP.DLL
[E5DFD54D2DAA70738F581D1AC74C09CD][1 84480
]C:\WINDOWS\SYSNATIVE\NLAAPI.DLL
[F916298AF3C6AC9887427E545C7E3A69][1 87040
]C:\WINDOWS\SYSNATIVE\PNRPNSP.DLL
[E372BBF897005442ECEB7843CEB394D2][1 17408
]C:\WINDOWS\SYSNATIVE\RASADHLP.DLL
[4D8F3CEF04AFF366972ED6411DB2E0E0][1 690176
]C:\WINDOWS\SYSNATIVE\RASAPI32.DLL
[3FD5AE42EC87C6F532A931F96BE731DD][1 761344
]C:\WINDOWS\SYSNATIVE\RPCSS.DLL
[1F1B8D07708E40E54C55B392C78ECCE2][1 271360
]C:\WINDOWS\SYSNATIVE\SCECLI.DLL
[B4B610BBCB002EC478C6FD80CF915697][1 405488
]C:\WINDOWS\SYSNATIVE\SERVICES.EXE
[2750EEB7440726085036BC746A095540][1 1207024
]C:\WINDOWS\SYSNATIVE\TASKMGR.EXE
[1A811BAFA2114C2FC878507F9F86566C][1 1517984
]C:\WINDOWS\SYSNATIVE\USER32.DLL
[3BE05B2695179F8F3CF1136544E46A14][1 1165824
]C:\WINDOWS\SYSNATIVE\UXTHEME.DLL
[7C94FDA3809015B8F2208D2E1C221F17][1 564736
]C:\WINDOWS\SYSNATIVE\WINLOGON.EXE
[218F874A78CB670172280A39A58B8F8A][1 30208
]C:\WINDOWS\SYSNATIVE\WINRNR.DLL
[420070BF9D3967F4AF15FDEDDFF64C45][1 4608
]C:\WINDOWS\SYSNATIVE\WS2HELP.DLL
[B78C9FB3D92F4502079BB1F07470BE60][1 63488
]C:\WINDOWS\SYSNATIVE\WSHBTH.DLL
[B19CA8E441D35AA2B1EE51C10B27DA1B][1 207360
]C:\WINDOWS\SYSTEM32\AELUPSVC.DLL
[A91D8E1E433EFB32551BCE69037E1CE7][1 92672
]C:\WINDOWS\SYSTEM32\ALG.EXE
[706423B1B2C8F2237FD0F3822C8DC1C7][1 558080
FE03D1516203D6407B13D6EF1CD36A69F6F5D5C3 ]C:\WINDOWS\SYSTEM32\APPHELP.DLL
[C0DC3F58214A227980AEB091CFD2F973][1 37888
]C:\WINDOWS\SYSTEM32\APPIDSVC.DLL
[7E790DE2487CEDB349D1750B9E47F090][1 109568
]C:\WINDOWS\SYSTEM32\APPINFO.DLL
[8176FBA685178FB0F52D46693474FA50][1 183296
]C:\WINDOWS\SYSTEM32\APPMGMTS.DLL
[FBE385C73EF9C8117B7CE5C55370FBC8][1 449024
85E3535D3121930B9C07FA2AF7B5BF9B8F3E5DF5 ]C:\WINDOWS\SYSTEM32\APPMGR.DLL
[550076AD22A72FF2C28FE2B19FB64C12][1 528896
]C:\WINDOWS\SYSTEM32\APPREADINESS.DLL
[4903CBC14742B5AB4DCF7A92F7DEC483][1 198656
]C:\WINDOWS\SYSTEM32\AUDIOENDPOINTBUILDER.DLL
[01E0A2E6263F48F4ED4FD2B96C8A3F8B][1 465976
AB244F3D0A7CDEF949C95EC44503A925A867987F ]C:\WINDOWS\SYSTEM32\AUDIOSES.DLL
[86DD7884124D363A63CCE7A11FDEBBED][1 835072
]C:\WINDOWS\SYSTEM32\AUDIOSRV.DLL
[74FD4F3D4CCF7E0AD040BE0F70D916A5][1 109056
]C:\WINDOWS\SYSTEM32\AXINSTSV.DLL
[BBE61A40665B83488901E41082A6097D][1 336896
]C:\WINDOWS\SYSTEM32\BDESVC.DLL
[ACC04CBB75086D86031E0C63D0930B98][1 827904
]C:\WINDOWS\SYSTEM32\BFE.DLL
[85948475C7FFCA1B7A825BB7BE9A5E72][1 265216
]C:\WINDOWS\SYSTEM32\BISRV.DLL
[9276A1B1086F36169469F69DF36B10A3][1 77312
D901BBD97A3339065A66AB4909B5D34EB23A3681 ]C:\WINDOWS\SYSTEM32\BLBEVENTS.DLL
[D528D6A92D187777691993DD757AF19A][1 134144
]C:\WINDOWS\SYSTEM32\BROWSER.DLL
[E5E48FEED73D463175EAB1542495191C][1 92160
]C:\WINDOWS\SYSTEM32\BTHSERV.DLL
[A7E778F47D324BA986BF74DA1CD24F65][1 434176
54D588F147F620CB0FD286CD35F94855BBD0E400 ]C:\WINDOWS\SYSTEM32\CERTCLI.DLL
[F99300CAF66307E295438355E9B11ACD][1 2465280
B6F086B3F69DF465ED5D29702A3D2F2C57A2E87B ]C:\WINDOWS\SYSTEM32\CERTENROLL.DLL
[AB285CE3431FF3D2ACE669245874C1C7][1 155136
]C:\WINDOWS\SYSTEM32\CERTPROP.DLL
[7F63629A60E6E1F12FA8D75B52CC17B2][1 1929176
AE14F403A00A9A9609562C39D9F4F2375585876C ]C:\WINDOWS\SYSTEM32\COMBASE.DLL
[77CBFFA2358967D252D6A3794A262BBC][1 1942520
2A954C574D9516D7CBD8FB5A843C832CF2927F15 ]C:\WINDOWS\SYSTEM32\CRYPT32.DLL
[0EFE4B5884A8032617826A4D76F80969][1 129536
]C:\WINDOWS\SYSTEM32\CRYPTSVC.DLL
[936D9E2871CEEFF6A33695D98374367B][1 778240
]C:\WINDOWS\SYSTEM32\CSCSVC.DLL
[77D62C92D05633D2F1EAA13C3FD7F325][1 207064
]C:\WINDOWS\SYSTEM32\CXAUDMSG64.EXE
[0BC71D4D3B5883903C37BF4E13B0F0C5][1 398848
]C:\WINDOWS\SYSTEM32\DAS.DLL
[CD95892713570725F4CBBA99F07CDDF2][1 92672
576050FDF7204763CDBC211D1F1C8F70910F7BE5 ]C:\WINDOWS\SYSTEM32\DASHOST.EXE
[B3D210DF0F057C53BB8817B96B2B3FC3][1 259072
74E7451C9864DC3767DFC8382790F1C4D56844DD ]C:\WINDOWS\SYSTEM32\DDPUTILS.DLL
[F4CCAADC2C78F57E4F16B24C9201CE22][1 449536
]C:\WINDOWS\SYSTEM32\DEFRAGSVC.DLL
[5B074F14F5DD6418F46EE4CA2DEB7EA8][1 201728
]C:\WINDOWS\SYSTEM32\DEVICESETUPMANAGER.DLL
[A40B5232D325AC0200E73329F7F19F54][1 353792
]C:\WINDOWS\SYSTEM32\DHCPCORE.DLL
[521ED020A6708FECA2473AF00B73FC4D][1 36864
CC4D04C93D895EB192AE9B9AD11C76E4B5B42CB0 ]C:\WINDOWS\SYSTEM32\DIMSJOB.DLL
[0EC96EC2D2D02649DCAD3D3C4E08A8DE][1 44032
71DA529DEAA91B86912B4B1076C17D05AE13BF01 ]C:\WINDOWS\SYSTEM32\DIMSROAM.DLL
[0934499394EB3D8027B8AB78C07D56CB][1 19296
]C:\WINDOWS\SYSTEM32\DLLHOST.EXE
[FBD2D7F491F3EBC5C54C5C4DB2564953][1 255488
]C:\WINDOWS\SYSTEM32\DNSRSLVR.DLL
[50288EA079BB520C2B8C8A154202D518][1 258560
]C:\WINDOWS\SYSTEM32\DOT3SVC.DLL
[281BEE07BA97E3E98D12A822D923D0D8][1 170496
]C:\WINDOWS\SYSTEM32\DPS.DLL
[F734A794A0A047FCC6882A52CC22A553][1 12232
E0D230026C3A8EB998402617CFC4D36AC6F8E7A5 ]
C:\WINDOWS\SYSTEM32\DPTFEVENTLOGMESSAGE.DLL
[6E467BC0B40D7479516BA330DDA97B1D][1 117704
30B70130DE27EE3952416A1DE7B7E65D0A6DF9E7 ]
C:\WINDOWS\SYSTEM32\DPTFPARTICIPANTPROCESSORSERVICE.EXE
[6C469C846EF4F256622C21A428E2E14E][1 116680
40897F439EBE4F35F46AED89F437640753309222 ]
C:\WINDOWS\SYSTEM32\DPTFPOLICYCONFIGTDPSERVICE.EXE
[F7EDD1A5F067AF6BEF40AB7F738F610D][1 126952
BDC82A6CED8D8E1D94DC5EBF2572FD0EC006C5BB ]
C:\WINDOWS\SYSTEM32\DPTFPOLICYLPMSERVICE.EXE
[1837EDFE746F910B0FFF4B86C2DB2B5E][1 114048
371572D4CEFF6CE2D58C0A668C3EB64A522D328C ]
C:\WINDOWS\SYSTEM32\DPTFPOLICYLPMSERVICEHELPER.EXE
[E1832BD9FD7E0FC2DC9FA5935DE3E8C1][1 231424
]C:\WINDOWS\SYSTEM32\DRIVERS\1394OHCI.SYS
[AD508A1A46EC21B740AB31C28EFDFDB1][1 108896
]C:\WINDOWS\SYSTEM32\DRIVERS\3WARE.SYS
[E19D921EBBD1A2CA4C48D7B5F1685B30][1 522592
]C:\WINDOWS\SYSTEM32\DRIVERS\ACPI.SYS
[AC8279D229398BCF05C3154ADCA86813][1 79712
]C:\WINDOWS\SYSTEM32\DRIVERS\ACPIEX.SYS
[A8970D9BF23CD309E0403978A1B58F3F][1 10240
]C:\WINDOWS\SYSTEM32\DRIVERS\ACPIPAGR.SYS
[111A89C99C5B4F1A7BCE5F643DD86F65][1 12288
]C:\WINDOWS\SYSTEM32\DRIVERS\ACPIPMI.SYS
[5758387D68A20AE7D3245011B07E36E7][1 10752
]C:\WINDOWS\SYSTEM32\DRIVERS\ACPITIME.SYS
[7C1FDF1B48298CBA7CE4BDD4978951AD][1 782176
]C:\WINDOWS\SYSTEM32\DRIVERS\ADP80XX.SYS
[239268BAB58EAE9A3FF4E08334C00451][1 567296
]C:\WINDOWS\SYSTEM32\DRIVERS\AFD.SYS
[B91EB769A3EB9F44BA7439451B7E1A7F][1 95744
5E45AABC47F8386134EC11C960C55A48B6289ACD ]
C:\WINDOWS\SYSTEM32\DRIVERS\AGILEVPN.SYS
[7DFAEBA9AD62D20102B576D5CAC45EC8][1 62304
]C:\WINDOWS\SYSTEM32\DRIVERS\AGP440.SYS
[8E8E34B7BA059050EED827410D0697A2][1 76800
]C:\WINDOWS\SYSTEM32\DRIVERS\AHCACHE.SYS
[7589DE749DB6F71A68489DCE04158729][1 95744
]C:\WINDOWS\SYSTEM32\DRIVERS\AMDK8.SYS
[B46D2D89AFF8A9490FA8C98C7A5616E3][1 98816
]C:\WINDOWS\SYSTEM32\DRIVERS\AMDPPM.SYS
[D2BF2F94A47D332814910FD47C6BBCD2][1 79200
]C:\WINDOWS\SYSTEM32\DRIVERS\AMDSATA.SYS
[A8E04943C7BBA7219AA50400272C3C6E][1 259424
]C:\WINDOWS\SYSTEM32\DRIVERS\AMDSBS.SYS
[CEA5F4F27CFC08E3A44D576811B35F50][1 25952
]C:\WINDOWS\SYSTEM32\DRIVERS\AMDXATA.SYS
[618F25E577FD7F1367CD24FD423D68A2][1 74240
91D477E830822BFE63182B315B1EA356C45D2469 ]
C:\WINDOWS\SYSTEM32\DRIVERS\AMUSTOR.SYS
[BE3BFEFD0EDA6AA4C3A81B0490B1F7F5][1 83456
]C:\WINDOWS\SYSTEM32\DRIVERS\APPID.SYS
[65045784366F7EC5FB4E71BCF923187B][1 114016
]C:\WINDOWS\SYSTEM32\DRIVERS\ARCSAS.SYS
[894D982CEAB8CD45A56AE2C9988E86C0][1 20280
]C:\WINDOWS\SYSTEM32\DRIVERS\ASHIDSWITCH64.SYS
[01D911D09BD63E6CA76137F9655B18C5][1 69904
C5218FB30F38F6556FB2D5067301649A8904E834 ]C:\WINDOWS\SYSTEM32\DRIVERS\ASUSTP.SYS
[3DB7721F06BC2FEDB25029EA23AB27DA][1 26624
]C:\WINDOWS\SYSTEM32\DRIVERS\ASYNCMAC.SYS
[74B14192CF79A72F7536B27CB8814FBD][1 26464
]C:\WINDOWS\SYSTEM32\DRIVERS\ATAPI.SYS
[BBE82125AC1E180DA7E3AF98AB4C0DA2][1 3892224
A96D55CBD281120F0B45597FF08AE7A25C0C14EB ]C:\WINDOWS\SYSTEM32\DRIVERS\ATHWBX.SYS
[8CC7F7E4AFCBA605921B137ED7992C68][1 50688
]C:\WINDOWS\SYSTEM32\DRIVERS\BASICDISPLAY.SYS
[2748E116F8621A4DB0D39FCDD7318C01][1 33792
]C:\WINDOWS\SYSTEM32\DRIVERS\BASICRENDER.SYS
[C1ABB0F7E3BEA48A0417BDF6FF14AB21][1 17624
]C:\WINDOWS\SYSTEM32\DRIVERS\BCMFN2.SYS
[6B4FFFDDC618FCF64473CAA86E305697][1 102912
]C:\WINDOWS\SYSTEM32\DRIVERS\BOWSER.SYS
[4E888019078AC363076A5433E89AA4F8][1 115712
]C:\WINDOWS\SYSTEM32\DRIVERS\BRIDGE.SYS
[DE8D825D9D45108CC7640C7944E68D60][2 355528
]C:\WINDOWS\SYSTEM32\DRIVERS\BTATH_A2DP.SYS
[30609197DBF90028615E9CE312C60A14][2 118984
]C:\WINDOWS\SYSTEM32\DRIVERS\BTATH_AVDT.SYS
[AF7DEA6A0E93AF8517A310D189B656BE][2 35016
]C:\WINDOWS\SYSTEM32\DRIVERS\BTATH_BUS.SYS
[8302D313DCC5536FE6BFB85165D9BB1E][2 89800
]C:\WINDOWS\SYSTEM32\DRIVERS\BTATH_FLT.SYS
[4AF7C20F94DAC343C01ED671C82DCB99][1 179432
]C:\WINDOWS\SYSTEM32\DRIVERS\BTATH_HCRP.SYS
[785C38070043BEEE9E9D591DE4067244][1 77464
]C:\WINDOWS\SYSTEM32\DRIVERS\BTATH_LWFLT.SYS
[859A116D748FBA603AF94C251DC5CF97][1 137928
]C:\WINDOWS\SYSTEM32\DRIVERS\BTATH_RCP.SYS
[8434237E1EC39E85D8ACE6FA694A5733][1 598216
]C:\WINDOWS\SYSTEM32\DRIVERS\BTFILTER.SYS
[A8F23D453A424FF4DE04989C4727ECC7][1 36992
]C:\WINDOWS\SYSTEM32\DRIVERS\BTHAVRCPTG.SYS
[131F1C8573E7BFB41C54FBF5309CCD94][1 53248
]C:\WINDOWS\SYSTEM32\DRIVERS\BTHENUM.SYS
[746B9F94214915AECDE4B7FEA5FF9664][1 57856
]C:\WINDOWS\SYSTEM32\DRIVERS\BTHHFENUM.SYS
[71FE2A48E4C93DDB9798C024880B6C07][1 30720
]C:\WINDOWS\SYSTEM32\DRIVERS\BTHHFHID.SYS
[FCD8BD17B7193CFFF18C332D1A381D7F][1 224768
]C:\WINDOWS\SYSTEM32\DRIVERS\BTHLEENUM.SYS
[07E33226AD218A2A162662A05CAFB52F][1 63488
]C:\WINDOWS\SYSTEM32\DRIVERS\BTHMODEM.SYS
[3AFE71D80EDF5D4DE0C5731352905669][1 118272
]C:\WINDOWS\SYSTEM32\DRIVERS\BTHPAN.SYS
[8458ECAB701EE385851C2559B71D1209][1 1200128
]C:\WINDOWS\SYSTEM32\DRIVERS\BTHPORT.SYS
[2C0B77176CD68F1F60510CDF36ADC401][1 77312
]C:\WINDOWS\SYSTEM32\DRIVERS\BTHUSB.SYS
[A4A73F631FE2AA2826FBE4A399B04DEF][1 531296
]C:\WINDOWS\SYSTEM32\DRIVERS\BXVBDA.SYS
[2FA6510E33F7DEFEC03658B74101A9B9][1 88576
]C:\WINDOWS\SYSTEM32\DRIVERS\CDFS.SYS
[C6796EA22B513E3457514D92DCDB1A3D][1 164352
]C:\WINDOWS\SYSTEM32\DRIVERS\CDROM.SYS
[BB1B91F57E1F9186BB42FD27F8A00D40][1 1457344
B75D123BE767EAE49F0AD83B137BF64135F74C8F ]
C:\WINDOWS\SYSTEM32\DRIVERS\CHDRT64.SYS
[BE9936EDD3267FAAFF94A7835867F00B][1 44032
]C:\WINDOWS\SYSTEM32\DRIVERS\CIRCLASS.SYS
[7F006813C2AFE622C13D7AF94F56CD07][1 377696
]C:\WINDOWS\SYSTEM32\DRIVERS\CLFS.SYS
[EF6EF85DADC3184A10D8F2F7159973CB][1 25472
]C:\WINDOWS\SYSTEM32\DRIVERS\CMBATT.SYS
[825BE21E6395E00698D8A23955A87972][1 564520
]C:\WINDOWS\SYSTEM32\DRIVERS\CNG.SYS
[03AAED827C36F35D70900558B8274905][1 36352
]C:\WINDOWS\SYSTEM32\DRIVERS\COMPOSITEBUS.SYS
[A1FF7DFBFBE164CF92603C651D304DD2][1 43008
]C:\WINDOWS\SYSTEM32\DRIVERS\CONDRV.SYS
[EE2F3C0D6ADBC975D6B621EC15ACF4E2][1 559616
]C:\WINDOWS\SYSTEM32\DRIVERS\CSC.SYS
[315BA4BC19316D72B2E037534E048B93][1 57696
]C:\WINDOWS\SYSTEM32\DRIVERS\DAM.SYS
[5DB26D7E0216D0BF364A81D3829AD7B9][1 134656
]C:\WINDOWS\SYSTEM32\DRIVERS\DFSC.SYS
[4D40C9B33F738797CF50E77CB7C53E85][1 100192
]C:\WINDOWS\SYSTEM32\DRIVERS\DISK.SYS
[EB70A894708D1BC176AFD690FF06085F][1 29696
]C:\WINDOWS\SYSTEM32\DRIVERS\DMVSC.SYS
[3E8D052C6DB66F9CCCB74BD2745122C4][1 289744
55EE343528F1879876D562D6B76AE631E5D8DBB3 ]
C:\WINDOWS\SYSTEM32\DRIVERS\DPTFDEVPROC.SYS
[EA2498A29131E284CF1F9609BB4A44F4][1 494296
A56536AD849D4107D09216A706C0C90F43130496 ]
C:\WINDOWS\SYSTEM32\DRIVERS\DPTFMANAGER.SYS
[DDC11A202207C0400CBE07315B8FDE5E][1 14560
]C:\WINDOWS\SYSTEM32\DRIVERS\DRMKAUD.SYS
[5A5C2A5D961CADF49DDE26582B8ED1FA][1 1537376
]C:\WINDOWS\SYSTEM32\DRIVERS\DXGKRNL.SYS
[43531A5993380CC5113242C29D265FD9][1 82784
]C:\WINDOWS\SYSTEM32\DRIVERS\EHSTORCLASS.SYS
[6F8E738A9505A388B1157FDDE7B3101B][1 114016
]C:\WINDOWS\SYSTEM32\DRIVERS\EHSTORTCGDRV.SYS
[DFFFAE1442BA4076E18EED5E406FA0D3][1 10240
]C:\WINDOWS\SYSTEM32\DRIVERS\ERRDEV.SYS
[114BCFDF367FF37C3F1B0A96AF542E4D][1 3357024
]C:\WINDOWS\SYSTEM32\DRIVERS\EVBDA.SYS
[5D8402613E778B3BD45E687A8372710B][1 30720
]C:\WINDOWS\SYSTEM32\DRIVERS\FDC.SYS
[957A7A8F5ACCAF23DD9DFF6DAA393CE5][1 79200
]C:\WINDOWS\SYSTEM32\DRIVERS\FILEINFO.SYS
[A1A66C4FDAFD6B0289523232AFB7D8AF][1 34816
]C:\WINDOWS\SYSTEM32\DRIVERS\FILETRACE.SYS
[BE743083CF7063C486A4398E3AEFE59A][1 25088
]C:\WINDOWS\SYSTEM32\DRIVERS\FLPYDISK.SYS
[60D5067FCE6D9433D35E04C01D8538B3][1 358752
]C:\WINDOWS\SYSTEM32\DRIVERS\FLTMGR.SYS
[35005534E600E993A90B036E4E599F2B][1 56672
]C:\WINDOWS\SYSTEM32\DRIVERS\FSDEPENDS.SYS
[818CF11786B2FA424E33A49E2CB79CC9][1 579424
]C:\WINDOWS\SYSTEM32\DRIVERS\FVEVOL.SYS
[9591D0B9351ED489EAFD9D1CE52A8015][1 27136
]C:\WINDOWS\SYSTEM32\DRIVERS\FXPPM.SYS
[FC3EF65EE20D39F8749C2218DBA681CA][1 65888
]C:\WINDOWS\SYSTEM32\DRIVERS\GAGP30KX.SYS
[03909BDBFF0DCACCABF2B2D4ADEE44DC][1 78336
]C:\WINDOWS\SYSTEM32\DRIVERS\HDAUDBUS.SYS
[56F69F7C25FB67C970997D7066DBC593][1 395776
]C:\WINDOWS\SYSTEM32\DRIVERS\HDAUDIO.SYS
[10A70BC1871CD955D85CD88372724906][1 26624
]C:\WINDOWS\SYSTEM32\DRIVERS\HIDBATT.SYS
[1EA1B4FABB8CC348E73CA90DBA22E104][1 96768
]C:\WINDOWS\SYSTEM32\DRIVERS\HIDBTH.SYS
[C241A8BAFBBFC90176EA0F5240EACC17][1 41472
]C:\WINDOWS\SYSTEM32\DRIVERS\HIDI2C.SYS
[9BDDEE26255421017E161CCB9D5EDA95][1 45568
]C:\WINDOWS\SYSTEM32\DRIVERS\HIDIR.SYS
[F31397220D9687E11EB448649AA6E038][1 33792
]C:\WINDOWS\SYSTEM32\DRIVERS\HIDUSB.SYS
[A6AACEA4C785789BDA5912AD1FEDA80D][1 64352
]C:\WINDOWS\SYSTEM32\DRIVERS\HPSAMD.SYS
[3502776E366C913D49C0DA928AE3E6CB][1 994144
]C:\WINDOWS\SYSTEM32\DRIVERS\HTTP.SYS
[90656C0B3864804B090434EFC582404F][1 24416
]C:\WINDOWS\SYSTEM32\DRIVERS\HWPOLICY.SYS
[6D6F9E3BF0484967E52F7E846BFF1CA1][1 13824
]C:\WINDOWS\SYSTEM32\DRIVERS\HYPERKBD.SYS
[907C870F8C31F8DDD6F090857B46AB25][1 22016
]C:\WINDOWS\SYSTEM32\DRIVERS\HYPERVIDEO.SYS
[84CFC5EFA97D0C965EDE1D56F116A541][1 107520
]C:\WINDOWS\SYSTEM32\DRIVERS\I8042PRT.SYS
[5D90E32E36CE5D4C535D17CE08AEAF05][1 24568
]C:\WINDOWS\SYSTEM32\DRIVERS\IALPSSI_GPIO.SYS
[DD05E7E80F52ADE9AEB292819920F32C][1 99320
]C:\WINDOWS\SYSTEM32\DRIVERS\IALPSSI_I2C.SYS
[E5A15FEDEBDFB8E12CB94DBF01833775][1 631656
CABA1595A5779E7093332D1EA71A8162965474F3 ]
C:\WINDOWS\SYSTEM32\DRIVERS\IASTORA.SYS
[08BFE413B0B4AA8DFA4B5684CE06D3DC][1 651248
]C:\WINDOWS\SYSTEM32\DRIVERS\IASTORAV.SYS
[A2200C3033FA4EF249FC096A7A7D02A2][1 412000
]C:\WINDOWS\SYSTEM32\DRIVERS\IASTORV.SYS
[142CFBE6ED0E498CCA7ABE8DD932C1AF][1 3729920
]C:\WINDOWS\SYSTEM32\DRIVERS\IGDKMD64.SYS
[8E4044C6B71B2F837166F6EDB6BF9100][1 450520
]C:\WINDOWS\SYSTEM32\DRIVERS\INTCDAUD.SYS
[F0F581A2299CB2BAB1DF2597BCDDB80F][1 38296
]C:\WINDOWS\SYSTEM32\DRIVERS\INTELAUD.SYS
[4E448FCFFD00E8D657CD9E48D3E47157][1 18272
]C:\WINDOWS\SYSTEM32\DRIVERS\INTELIDE.SYS
[647CF2AB16D2A23F1C441A313BC39820][1 39776
]C:\WINDOWS\SYSTEM32\DRIVERS\INTELPEP.SYS
[47E74A8E53C7C24DCE38311E1451C1D9][1 98816
]C:\WINDOWS\SYSTEM32\DRIVERS\INTELPPM.SYS
[9DB76D7F9E4E53EFE5DD8C53DE837514][1 84992
]C:\WINDOWS\SYSTEM32\DRIVERS\IPFLTDRV.SYS
[9949A3C7590B8C536C05312205079A82][1 79360
]C:\WINDOWS\SYSTEM32\DRIVERS\IPMIDRV.SYS
[0063040EFD7C5B81D67CF985BA35388A][1 141824
]C:\WINDOWS\SYSTEM32\DRIVERS\IPNAT.SYS
[AE44C526AB5F8A487D941CEB57B10C97][1 17920
]C:\WINDOWS\SYSTEM32\DRIVERS\IRENUM.SYS
[8AFEEA3955AA43616A60F133B1D25F21][1 21856
]C:\WINDOWS\SYSTEM32\DRIVERS\ISAPNP.SYS
[C2BC9AC9C6514230A481BDCA6A24BEFD][1 27032
]C:\WINDOWS\SYSTEM32\DRIVERS\IWDBUS.SYS
[8BE92376799B6B44D543E8D07CDCF885][1 58208
]C:\WINDOWS\SYSTEM32\DRIVERS\KBDCLASS.SYS
[FB6E47E569D4872ABEB506BE03A45FBA][1 32256
]C:\WINDOWS\SYSTEM32\DRIVERS\KBDHID.SYS
[6C6F4A5FC5A2343995D1B0F111D5CF06][1 17280
]C:\WINDOWS\SYSTEM32\DRIVERS\KBFILTR.SYS
[DB7A09BC90DF20F44F16F8B0F9ED3491][1 22272
]C:\WINDOWS\SYSTEM32\DRIVERS\KBLDFLTR.SYS
[813871C7D402A05F2E3A7075F9584A05][1 19456
]C:\WINDOWS\SYSTEM32\DRIVERS\KDNIC.SYS
[0AD1DF5AF3E1AEE66583F9718E892B50][1 100704
]C:\WINDOWS\SYSTEM32\DRIVERS\KSECDD.SYS
[7296EA420134EAC390798B3232D066A4][1 192864
]C:\WINDOWS\SYSTEM32\DRIVERS\KSECPKG.SYS
[11AFB527AA370B1DAFD5C36F35F6D45F][1 21248
]C:\WINDOWS\SYSTEM32\DRIVERS\KSTHUNK.SYS
[C09010B3680860131631F53E8FE7BAD8][1 59392
]C:\WINDOWS\SYSTEM32\DRIVERS\LLTDIO.SYS
[C755AE4635457AA2A11F79C0DF857ABC][1 109408
]C:\WINDOWS\SYSTEM32\DRIVERS\LSI_SAS.SYS
[ADAC09CBE7A2040B7F68B5E5C9A75141][1 93536
]C:\WINDOWS\SYSTEM32\DRIVERS\LSI_SAS2.SYS
[04D1274BB9BBCCF12BD12374002AA191][1 81760
]C:\WINDOWS\SYSTEM32\DRIVERS\LSI_SAS3.SYS
[327469EEF3833D0C584B7E88A76AEC0C][1 82784
]C:\WINDOWS\SYSTEM32\DRIVERS\LSI_SSS.SYS
[5EF604B0698F4FA962778285E8C5F1F2][1 123904
]C:\WINDOWS\SYSTEM32\DRIVERS\LUAFV.SYS
[ -2][0 -1
]C:\WINDOWS\SYSTEM32\DRIVERS\MASSFILTER.SYS
[EB5C03A070F30D64A6DF80E53B22F53F][1 56672
]C:\WINDOWS\SYSTEM32\DRIVERS\MEGASAS.SYS
[F6F13533196DE7A582D422B0241E4363][1 575840
]C:\WINDOWS\SYSTEM32\DRIVERS\MEGASR.SYS
[8B38C44F69259987C95135C9627E2378][1 40960
]C:\WINDOWS\SYSTEM32\DRIVERS\MODEM.SYS
[601589000CC90F0DF8DA2CC254A3CCC9][1 30208
]C:\WINDOWS\SYSTEM32\DRIVERS\MONITOR.SYS
[CEAC6D40FE887CE8406C2393CF97DE06][1 51040
]C:\WINDOWS\SYSTEM32\DRIVERS\MOUCLASS.SYS
[02D98BF804084E9A0D69D1C69B02CCA9][1 30208
]C:\WINDOWS\SYSTEM32\DRIVERS\MOUHID.SYS
[515549560D481138E6E21AF7C6998E56][1 101728
]C:\WINDOWS\SYSTEM32\DRIVERS\MOUNTMGR.SYS
[F170510BE94CF45E3C6274578F6204B2][1 74240
]C:\WINDOWS\SYSTEM32\DRIVERS\MPSDRV.SYS
[59DCEC7499095DE5AED741358037AE2D][1 140288
]C:\WINDOWS\SYSTEM32\DRIVERS\MRXDAV.SYS
[405A2E5754DF76663CF0522B87D7929F][1 402432
]C:\WINDOWS\SYSTEM32\DRIVERS\MRXSMB.SYS
[295771B092D4F7FCF2B62F80CCD14320][1 283648
]C:\WINDOWS\SYSTEM32\DRIVERS\MRXSMB10.SYS
[FFC548EABBB8271E979B0EEE0EA4D55B][1 206848
]C:\WINDOWS\SYSTEM32\DRIVERS\MRXSMB20.SYS
[FDA72810CA2F8409D9B31E833C448E34][1 146272
]C:\WINDOWS\SYSTEM32\DRIVERS\MSGPIOCLX.SYS
[C6B474E46F9E543B875981ED3FFE6ADD][1 41824
]C:\WINDOWS\SYSTEM32\DRIVERS\MSGPIOWIN32.SYS
[65C92EB9D08DB5C69F28C7FFD4E84E31][1 8192
]C:\WINDOWS\SYSTEM32\DRIVERS\MSHIDKMDF.SYS
[52299F086AC2DAFD100DD5DC4A8614BA][1 9728
]C:\WINDOWS\SYSTEM32\DRIVERS\MSHIDUMDF.SYS
[36D92AF3343C3A3E57FEF11C449AEA4C][1 17248
]C:\WINDOWS\SYSTEM32\DRIVERS\MSISADRV.SYS
[034D4BD9DC67C64F3A4C8A049B5173BF][1 274784
]C:\WINDOWS\SYSTEM32\DRIVERS\MSISCSI.SYS
[A9BBBD2BAE6142253B9195E949AC2E8D][1 10624
]C:\WINDOWS\SYSTEM32\DRIVERS\MSKSSRV.SYS
[375E44168F2DFB91A68B8A3F619C5A7C][1 66560
]C:\WINDOWS\SYSTEM32\DRIVERS\MSLLDP.SYS
[7B2128EB875DCBC006E6A913211006D6][1 7040
]C:\WINDOWS\SYSTEM32\DRIVERS\MSPCLOCK.SYS
[1E88171579B218115C7A772F8DE04BD8][1 6784
]C:\WINDOWS\SYSTEM32\DRIVERS\MSPQM.SYS
[8D6B7D515C5CBCDB75B928A0B73C3C5E][1 37728
]C:\WINDOWS\SYSTEM32\DRIVERS\MSSMBIOS.SYS
[115019AE01E0EB9C048530D2928AB4A2][1 7936
]C:\WINDOWS\SYSTEM32\DRIVERS\MSTEE.SYS
[96D604A35070360F0DD4A7A8AF410B5E][1 13312
]C:\WINDOWS\SYSTEM32\DRIVERS\MTCONFIG.SYS
[619CA29326B82372621DB2C0964D8365][1 78688
]C:\WINDOWS\SYSTEM32\DRIVERS\MUP.SYS
[B8C35C94DCB2DFEAF03BB42131F2F77F][1 63840
]C:\WINDOWS\SYSTEM32\DRIVERS\MVUMIS.SYS
[424B0796F85BB0DADD4438EAFFADA133][1 1118552
]C:\WINDOWS\SYSTEM32\DRIVERS\NDIS.SYS
[C6BB12BC35D1637CA17AE16D3A4725EB][1 43008
]C:\WINDOWS\SYSTEM32\DRIVERS\NDISCAP.SYS
[9F1DA20E943BE7AA4ED5F3E1EBA78B37][1 124928
]C:\WINDOWS\SYSTEM32\DRIVERS\NDISIMPLATFORM.SYS
[9423421E735BD5394351E0C47C76BB92][1 24576
]C:\WINDOWS\SYSTEM32\DRIVERS\NDISTAPI.SYS
[B832B35055BA2B7B4181861FF94D8E59][1 60416
]C:\WINDOWS\SYSTEM32\DRIVERS\NDISUIO.SYS
[1F58E48EF75F34C35D8E93A0DC535CFE][1 16384
]C:\WINDOWS\SYSTEM32\DRIVERS\NDISVIRTUALBUS.SYS
[DEC29080202D4F9F17F55E18BCFCC41A][1 220672
]C:\WINDOWS\SYSTEM32\DRIVERS\NDISWAN.SYS
[5A072F0B90C29C5233D78BE33EF5ED78][1 103424
]C:\WINDOWS\SYSTEM32\DRIVERS\NDU.SYS
[A83D67D347A684F10B7D3019C8A6380C][1 48128
]C:\WINDOWS\SYSTEM32\DRIVERS\NETBIOS.SYS
[0217532E19A748F0E5D569307363D5FD][1 282624
]C:\WINDOWS\SYSTEM32\DRIVERS\NETBT.SYS
[70414DB660BFBB7BD58FCE8EA4364E1B][1 87040
]C:\WINDOWS\SYSTEM32\DRIVERS\NETVSC63.SYS
[351533ACC2A069B94E80BBFC177E8FDF][1 35344
]C:\WINDOWS\SYSTEM32\DRIVERS\NPF.SYS
[CBDB4F0871C88DF930FC0E8588CA67FC][1 23040
]C:\WINDOWS\SYSTEM32\DRIVERS\NPSVCTRIG.SYS
[E490B459978CB87779E84C761D22B827][1 39936
]C:\WINDOWS\SYSTEM32\DRIVERS\NSIPROXY.SYS
[6934A936A7369DFE37B7DBA93F5E5E49][1 124768
]C:\WINDOWS\SYSTEM32\DRIVERS\NV_AGP.SYS
[EEA11D0AED5C40A6C926B21CEC53EE65][1 12701472
F158F9D7AB8A9E881B6FEACBDE3C81DE3854D09F ]
C:\WINDOWS\SYSTEM32\DRIVERS\NVLDDMKM.SYS
[BC6B5942AFF25EBAF62DE43C3807EDF8][1 150368
]C:\WINDOWS\SYSTEM32\DRIVERS\NVRAID.SYS
[1F43ABFFAC3D6CA356851D517392966E][1 168288
]C:\WINDOWS\SYSTEM32\DRIVERS\NVSTOR.SYS
[869055F61568AA08E7DEE95EC82ED653][1 442368
]C:\WINDOWS\SYSTEM32\DRIVERS\NWIFI.SYS
[8528BB05E4D4E25945F78B00B2555FB7][1 151552
]C:\WINDOWS\SYSTEM32\DRIVERS\PACER.SYS
[764B1121867B2D9B31C491668AC72B2B][1 94208
]C:\WINDOWS\SYSTEM32\DRIVERS\PARPORT.SYS
[032F1C32A6A97C317AEFF9D64D2A1D8A][1 40304
50D027EB8240A4C0D4610E47A912DC8E4D6D88E5 ]
C:\WINDOWS\SYSTEM32\DRIVERS\PARTIZAN.SYS
[EF0C1749C9A8CEE9A457473D433CC00F][1 88928
]C:\WINDOWS\SYSTEM32\DRIVERS\PARTMGR.SYS
[C0D3F3BC1C84B4BA746D9847314C1164][1 285536
]C:\WINDOWS\SYSTEM32\DRIVERS\PCI.SYS
[346E38FCC6859A727DD28AFAD1F0AFF4][1 14688
]C:\WINDOWS\SYSTEM32\DRIVERS\PCIIDE.SYS
[4D3BDCC1C7B40C9D7B6AD990E6DEC397][1 114528
]C:\WINDOWS\SYSTEM32\DRIVERS\PCMCIA.SYS
[BF28771D1436C88BE1D297D3098B0F7D][1 50016
]C:\WINDOWS\SYSTEM32\DRIVERS\PCW.SYS
[28AAACD3B871305F07188A0DB366B439][1 86880
]C:\WINDOWS\SYSTEM32\DRIVERS\PDC.SYS
[BA50CC0BD19004AAB88BE37338B6FA0D][1 663040
]C:\WINDOWS\SYSTEM32\DRIVERS\PEAUTH.SYS
[ECD373F9571C745894367CC2635EA44F][1 92160
]C:\WINDOWS\SYSTEM32\DRIVERS\PROCESSR.SYS
[3FB466684609A4329858CF2EBD62E0FD][1 47104
]C:\WINDOWS\SYSTEM32\DRIVERS\QWAVEDRV.SYS
[2C56F0EE27E4EF70CA4B4983D3638905][1 17408
]C:\WINDOWS\SYSTEM32\DRIVERS\RASACD.SYS
[BBB6272B7F46C4640A8CDB8A70C3450F][1 120832
]C:\WINDOWS\SYSTEM32\DRIVERS\RASL2TP.SYS
[5247F308C4103CDC4FE12AE1D235800A][1 84992
]C:\WINDOWS\SYSTEM32\DRIVERS\RASPPPOE.SYS
[E075CC071022BD4E9BE7C024717C0E0A][1 107520
]C:\WINDOWS\SYSTEM32\DRIVERS\RASPPTP.SYS
[2B0F1677CDD08967005F34488559BC6F][1 96256
]C:\WINDOWS\SYSTEM32\DRIVERS\RASSSTP.SYS
[B939A2A0F9D6C6C186721E268EB6FA93][1 408576
]C:\WINDOWS\SYSTEM32\DRIVERS\RDBSS.SYS
[6B21EBF892CD8CACB71669B35AB5DE32][1 22528
]C:\WINDOWS\SYSTEM32\DRIVERS\RDPBUS.SYS
[680C1DAE268B6FB67FA21B389A8B79EF][1 195584
]C:\WINDOWS\SYSTEM32\DRIVERS\RDPDR.SYS
[858776908AF838E3790F3261B799CDA6][1 27488
]C:\WINDOWS\SYSTEM32\DRIVERS\RDPVIDEOMINIPORT.SYS
[2C915EFFF23EA65D1E760FA397BCA6AB][1 258400
]C:\WINDOWS\SYSTEM32\DRIVERS\RDYBOOST.SYS
[6D22E97C0390D736D220B03015A5569F][1 167424
]C:\WINDOWS\SYSTEM32\DRIVERS\RFCOMM.SYS
[2D05A5508F4685412F2B89E8C2189ABC][1 80384
]C:\WINDOWS\SYSTEM32\DRIVERS\RSPNDR.SYS
[D5C3918E3EF787A41172B8E5348247F0][1 873176
77CDF7C252BF407E19361CB6E69C6DCE56E2E3FF ]
C:\WINDOWS\SYSTEM32\DRIVERS\RT630X64.SYS
[C624A1B32211C3166EDB3F4AB02A30B7][1 107872
]C:\WINDOWS\SYSTEM32\DRIVERS\SBP2PORT.SYS
[ABD0237B15DBD2B4695F4B7D734A58F7][1 40960
]C:\WINDOWS\SYSTEM32\DRIVERS\SCFILTER.SYS
[C6A6F8921B94BC1673AC9AB485DF9A18][1 234848
]C:\WINDOWS\SYSTEM32\DRIVERS\SDBUS.SYS
[4EAF4DCF9DBD9A56952A58F56D61C005][1 78688
]C:\WINDOWS\SYSTEM32\DRIVERS\SDSTOR.SYS
[DB2FF24CE0BDD15FE75870AFE312BA89][1 69472
]C:\WINDOWS\SYSTEM32\DRIVERS\SERCX.SYS
[53BDBF04ECAF943CBF6359E3BCB2445E][1 146272
]C:\WINDOWS\SYSTEM32\DRIVERS\SERCX2.SYS
[3CD600C089C1251BEEB4CD4CD5164F9E][1 23040
]C:\WINDOWS\SYSTEM32\DRIVERS\SERENUM.SYS
[D864381BC9C725FAB01D94C060660166][1 83456
]C:\WINDOWS\SYSTEM32\DRIVERS\SERIAL.SYS
[0BD2B65DCE756FDE95A2E5CCCBF7705D][1 26112
]C:\WINDOWS\SYSTEM32\DRIVERS\SERMOUSE.SYS
[472B7A5AC181C050888DB454663DD764][1 17408
]C:\WINDOWS\SYSTEM32\DRIVERS\SFLOPPY.SYS
[2F518D13DD6F3053837FE606F1A2EA1F][1 44896
]C:\WINDOWS\SYSTEM32\DRIVERS\SISRAID2.SYS
[1AC9A200A9C49C4508F04AAFFCA34A3F][1 81760
]C:\WINDOWS\SYSTEM32\DRIVERS\SISRAID4.SYS
[349059B0C9EAED5A951D1693132A2EA8][1 370528
]C:\WINDOWS\SYSTEM32\DRIVERS\SPACEPORT.SYS
[F337BE11071818FC3F5DC2940B6BDE34][1 72032
]C:\WINDOWS\SYSTEM32\DRIVERS\SPBCX.SYS
[A15860E920B02C9A7CE8F3A6C2FF1E3A][1 560184
]C:\WINDOWS\SYSTEM32\DRIVERS\SPTD.SYS
[CD7534BA5BA92086B1BC10ADF880FC49][1 454656
]C:\WINDOWS\SYSTEM32\DRIVERS\SRV.SYS
[59F15EFD74FDE8A1D9278F2C04F5D0B9][1 674816
]C:\WINDOWS\SYSTEM32\DRIVERS\SRV2.SYS
[96A7F9E8B3E0DD0355067D894C71A8F7][1 244224
]C:\WINDOWS\SYSTEM32\DRIVERS\SRVNET.SYS
[9593475FBC857A05D93BFF4FA7323C2B][1 131712
541ACB4AD5195B02AA06ACBBD05CA9BCBC308EAD ]
C:\WINDOWS\SYSTEM32\DRIVERS\SSUDBUS.SYS
[592FF34A2FD6C6351B8A3AA76B2C0A9E][1 165504
1FB2E01F7EC79EB85B0606E371B81E8C933A7628 ]
C:\WINDOWS\SYSTEM32\DRIVERS\SSUDMDM.SYS
[76F7D7217FBDAB77798A2A244ACD641F][1 206080
]C:\WINDOWS\SYSTEM32\DRIVERS\SSUDSERD.SYS
[366DEA74BBA65B362BCCFC6FC2ADFD8B][1 31072
]C:\WINDOWS\SYSTEM32\DRIVERS\STEXSTOR.SYS
[0ED2E318ABB68C1A35A8B8038BDB4C90][1 107872
]C:\WINDOWS\SYSTEM32\DRIVERS\STORAHCI.SYS
[D57AEE34C7C0DD1DC8B6B54B7A89649C][1 56672
]C:\WINDOWS\SYSTEM32\DRIVERS\STORNVME.SYS
[548759755BC73DAD663250239D7E0B9F][1 45888
]C:\WINDOWS\SYSTEM32\DRIVERS\STORVSC.SYS
[03618F935379614837F915D04C45FC0E][1 68608
]C:\WINDOWS\SYSTEM32\DRIVERS\STORVSP.SYS
[84E0F5D41C138C5CC975137A2A98F6D3][1 14176
]C:\WINDOWS\SYSTEM32\DRIVERS\SWENUM.SYS
[C9436791C9DD3B5206DDBB1F75EE3E54][1 2549600
]C:\WINDOWS\SYSTEM32\DRIVERS\TCPIP.SYS
[33A7D83EEB15431773A6E186CFAABA21][1 48640
]C:\WINDOWS\SYSTEM32\DRIVERS\TCPIPREG.SYS
[FFF28F9F6823EB1756C60F1649560BBF][1 107520
]C:\WINDOWS\SYSTEM32\DRIVERS\TDX.SYS
[EB1D78140D6634C32A46AB1006105EDC][1 100312
]C:\WINDOWS\SYSTEM32\DRIVERS\TEEDRIVERX64.SYS
[232D185D2337F141311D0CF1983E1431][1 37216
]C:\WINDOWS\SYSTEM32\DRIVERS\TERMINPT.SYS
[82F909359600D3603FE852DB7F135626][1 159584
]C:\WINDOWS\SYSTEM32\DRIVERS\TPM.SYS
[BF8F54CA37E9C9D6582C31C5761F8C93][1 56320
]C:\WINDOWS\SYSTEM32\DRIVERS\TSUSBFLT.SYS
[E0088068DCE2EE82897027DDB8E05254][1 29696
]C:\WINDOWS\SYSTEM32\DRIVERS\TSUSBGD.SYS
[C8E0E78B5D284C2FF59BDFFDAF997242][1 154112
]C:\WINDOWS\SYSTEM32\DRIVERS\TUNNEL.SYS
[F6EEAD052943B5A3104C1405BB856C54][1 64864
]C:\WINDOWS\SYSTEM32\DRIVERS\UAGP35.SYS
[FE6067B1FD4E63650C667B33D080565B][1 74080
]C:\WINDOWS\SYSTEM32\DRIVERS\UASPSTOR.SYS
[5D1B430EA11064C56E7C8F84B90DEB6A][1 189792
]C:\WINDOWS\SYSTEM32\DRIVERS\UCX01000.SYS
[1EC649F112896FAE33250F0B97AC5D0B][1 316928
]C:\WINDOWS\SYSTEM32\DRIVERS\UDFS.SYS
[9578691F297E1B1F519970FE6D47CB21][1 26976
]C:\WINDOWS\SYSTEM32\DRIVERS\UEFI.SYS
[5EAB5117DDB24FC4D39E6FFFCF1837B9][1 65888
]C:\WINDOWS\SYSTEM32\DRIVERS\ULIAGPKX.SYS
[DA34C39A18E60E7C3FA0630566408034][1 46080
]C:\WINDOWS\SYSTEM32\DRIVERS\UMBUS.SYS
[643EF9E542EF1E438FBDF6A88235C50C][1 212480
8DEA5EACA7A3C4F139A010F6336C893C3C2A5691 ]
C:\WINDOWS\SYSTEM32\DRIVERS\UMDF\LOCATIONPROVIDER.DLL
[AE8294875E5446E359B1E8035D40C05E][1 11776
]C:\WINDOWS\SYSTEM32\DRIVERS\UMPASS.SYS
[734695C602E69F9DDBD29280D3E9E8BB][1 14984
A5FA0859766273800D524549034EF10E65EE6E9E ]
C:\WINDOWS\SYSTEM32\DRIVERS\UnHackMeDrv.sys
[F3F90825C416B264D016AA9D02C244C4][1 20992
]C:\WINDOWS\SYSTEM32\DRIVERS\USB80236.SYS
[3CAAB947B1F247A570DE15983BEDEBCF][1 20992
]C:\WINDOWS\SYSTEM32\DRIVERS\USB8023X.SYS
[3432E857B8EC1C1316AB098F2BCCDFB6][1 155488
]C:\WINDOWS\SYSTEM32\DRIVERS\USBCCGP.SYS
[B3D6457D841A0CAEF4C52D88621715F2][1 98304
]C:\WINDOWS\SYSTEM32\DRIVERS\USBCIR.SYS
[5477D6E27C7D266EF8C152B9A25ADE5E][1 89952
]C:\WINDOWS\SYSTEM32\DRIVERS\USBEHCI.SYS
[DF56C2C04EFA328D7A66B69007130266][1 422240
]C:\WINDOWS\SYSTEM32\DRIVERS\USBHUB.SYS
[4475096DAB15E613A95D6A53F800B377][1 466784
]C:\WINDOWS\SYSTEM32\DRIVERS\USBHUB3.SYS
[3019097FB6C985EF24C058090FF3BDBD][1 30208
]C:\WINDOWS\SYSTEM32\DRIVERS\USBOHCI.SYS
[4D655E3B684BE9B0F7FFD8A2935C348C][1 26112
]C:\WINDOWS\SYSTEM32\DRIVERS\USBPRINT.SYS
[F04D164C4168701A4E7835607722E5F1][1 44544
]C:\WINDOWS\SYSTEM32\DRIVERS\USBSCAN.SYS
[B1230E9813B5C7E762DF27756AA23917][1 142688
]C:\WINDOWS\SYSTEM32\DRIVERS\USBSTOR.SYS
[BA4FA655E0FC577DB7436FC963932CE4][1 34816
]C:\WINDOWS\SYSTEM32\DRIVERS\USBUHCI.SYS
[18F744E8CCEB2670040EBAF7AD77B8C6][1 212224
]C:\WINDOWS\SYSTEM32\DRIVERS\USBVIDEO.SYS
[BCD8FC0A47AA31889C94168A4E56BB26][1 325472
]C:\WINDOWS\SYSTEM32\DRIVERS\USBXHCI.SYS
[FEB26E3B8345A7E8D62F945C4AE86562][1 37728
]C:\WINDOWS\SYSTEM32\DRIVERS\VDRVROOT.SYS
[2582B87082A935ACB76F949F760AF236][1 175968
]C:\WINDOWS\SYSTEM32\DRIVERS\VERIFIEREXT.SYS
[041D3EF364E624DBB2703A64A5AADF89][1 551776
]C:\WINDOWS\SYSTEM32\DRIVERS\VHDMP.SYS
[06D38968028E9AB19DE9B618C7B6D199][1 19808
]C:\WINDOWS\SYSTEM32\DRIVERS\VIAIDE.SYS
[3CE922E34DB12D9F3C0EA856BC09687C][1 220672
]C:\WINDOWS\SYSTEM32\DRIVERS\VID.SYS
[C6305BDFC4F7CE51F72BB072C03D4ACE][1 97088
]C:\WINDOWS\SYSTEM32\DRIVERS\VMBUS.SYS
[DA40BEA0A863CE768C940CA9723BF81F][1 21760
]C:\WINDOWS\SYSTEM32\DRIVERS\VMBUSHID.SYS
[68F8C26DEA2D42E8DEC0778943433C80][1 129536
]C:\WINDOWS\SYSTEM32\DRIVERS\VMBUSR.SYS
[0BF5CAD281E25F1418E5B8875DC5ADD1][1 11264
]C:\WINDOWS\SYSTEM32\DRIVERS\VMGENCOUNTER.SYS
[1A063730F221B2746FF00457AE17E4F0][1 7168
]C:\WINDOWS\SYSTEM32\DRIVERS\VMS3CAP.SYS
[7A08CEE1535F5A448215634C5EA74E50][1 49984
]C:\WINDOWS\SYSTEM32\DRIVERS\VMSTORFL.SYS
[55D7D963DE85162F1C49721E502F9744][1 73568
]C:\WINDOWS\SYSTEM32\DRIVERS\VOLMGR.SYS
[CCB9E901F7254BF96D28EB1B0E5329B7][1 377696
]C:\WINDOWS\SYSTEM32\DRIVERS\VOLMGRX.SYS
[9F9CE33B50611A1C61A46B8911E0B30B][1 312160
]C:\WINDOWS\SYSTEM32\DRIVERS\VOLSNAP.SYS
[01355C98B5C3ED1EC446743CDA848FCE][1 69472
]C:\WINDOWS\SYSTEM32\DRIVERS\VPCI.SYS
[ADBE96C33D1A5BB1BBAF90B4BC84F523][1 65536
]C:\WINDOWS\SYSTEM32\DRIVERS\VPCIVSP.SYS
[4539F45F9F4C9757A86A56C949421E07][1 168800
]C:\WINDOWS\SYSTEM32\DRIVERS\VSMRAID.SYS
[0849B7260F26FE05EA56DED0672E2F4B][1 305504
]C:\WINDOWS\SYSTEM32\DRIVERS\VSTXRAID.SYS
[BE970C369E43B509C1EDA2B8FA7CECB0][1 24576
]C:\WINDOWS\SYSTEM32\DRIVERS\VWIFIBUS.SYS
[6B26AD573CCDD5209DF4397438B76354][1 71680
]C:\WINDOWS\SYSTEM32\DRIVERS\VWIFIFLT.SYS
[0B48E0DFB44EE475F4FD8A8EE599AF30][1 36864
]C:\WINDOWS\SYSTEM32\DRIVERS\VWIFIMP.SYS
[0910AB9ED404C1434E2D0376C2AD5D8B][1 26752
]C:\WINDOWS\SYSTEM32\DRIVERS\WACOMPEN.SYS
[AFCD4054D61BD708B82991348ED1C763][1 79872
]C:\WINDOWS\SYSTEM32\DRIVERS\WANARP.SYS
[694B28DE12AD47031FFB4B052662131A][1 34760
]C:\WINDOWS\SYSTEM32\DRIVERS\WDBOOT.SYS
[CB6C63FF8342B467E2EF76E98D5B934D][1 839488
]C:\WINDOWS\SYSTEM32\DRIVERS\WDF01000.SYS
[0B99529A3BECC3528D865DDECB62503B][1 265056
]C:\WINDOWS\SYSTEM32\DRIVERS\WDFILTER.SYS
[282E7D46310338FF4A6B7680440EB0DA][1 124256
]C:\WINDOWS\SYSTEM32\DRIVERS\WDNISDRV.SYS
[011F431624366917180C904CE17FEA1A][1 135520
]C:\WINDOWS\SYSTEM32\DRIVERS\WFPLWFS.SYS
[867BCC69ED9C31C501465EB0E8BA9DFA][1 33632
]C:\WINDOWS\SYSTEM32\DRIVERS\WIMMOUNT.SYS
[AC263C2F66405589528995AA41040599][1 78848
]C:\WINDOWS\SYSTEM32\DRIVERS\WINUSB.SYS
[2834D9D3B4F554A39C72F00EA3F0E128][1 16384
]C:\WINDOWS\SYSTEM32\DRIVERS\WMIACPI.SYS
[E746BCDBA2E02CF6B8D6B26FB167FBE0][1 54304
]C:\WINDOWS\SYSTEM32\DRIVERS\WPCFLTR.SYS
[9F2904B55F6CECCD1A8D986B5CE2609A][1 26976
]C:\WINDOWS\SYSTEM32\DRIVERS\WPDUPFLTR.SYS
[AE072B0339D0A18E455DC21666CAD572][1 21504
]C:\WINDOWS\SYSTEM32\DRIVERS\WS2IFSL.SYS
[2FEAE33E9B2B56104596E1BA444405A9][1 117760
]C:\WINDOWS\SYSTEM32\DRIVERS\WUDFPF.SYS
[19240C13F526125554B5370566F21A0A][1 230912
]C:\WINDOWS\SYSTEM32\DRIVERS\WUDFRD.SYS
[ -2][0 -1
]C:\WINDOWS\SYSTEM32\DRIVERS\ZTEUSBMDM6K.SYS
[ -2][0 -1
]C:\WINDOWS\SYSTEM32\DRIVERS\ZTEUSBNMEA.SYS
[ -2][0 -1
]C:\WINDOWS\SYSTEM32\DRIVERS\ZTEUSBSER6K.SYS
[A1BECE49EF88F58F6DC881AF251B822E][1 113152
4F1AE0EDB96270074C478E89C0A7EB8EC075C3B8 ]C:\WINDOWS\SYSTEM32\DSKQUOTA.DLL
[B4BBC6E4998042EF21437EED52EC0273][1 110080
2A9F711A601DB66788695BF6C8EFCF9C47632F84 ]C:\WINDOWS\SYSTEM32\DWM.EXE
[6073537F250B45E1CB2A02E97F0FE1B2][1 107008
]C:\WINDOWS\SYSTEM32\EAPSVC.DLL
[DDBF755EF92C0AB1F27C14A0D251F884][1 412160
2DD2D5656AB18C26EFAAB11B17EA94A3E9F04E63 ]C:\WINDOWS\SYSTEM32\EFSCORE.DLL
[6A5914B21D33A1CC4D294A696ADDB3E2][1 40448
]C:\WINDOWS\SYSTEM32\EFSSVC.DLL
[CE85A6750D9C54DFAB2434854C9CF2B6][1 131584
7D8C7ED8F4E2124ABE2626313788EC2526E71874 ]C:\WINDOWS\SYSTEM32\EFSWRT.DLL
[030CE75B7D8F75FAA7BA1EC6FD0EB5A3][1 468992
]C:\WINDOWS\SYSTEM32\ES.DLL
[CBCA90CF2ACE96038571ED0A7BD3D756][1 2791936
DB5C1C553F92AC3D753911562665FE7389D09149 ]C:\WINDOWS\SYSTEM32\ESENT.DLL
[04044091129B73C7BCF99B1CB842835F][1 162816
C797B653223AEA7DA20CC5C89EA9D6E8E7F81001 ]C:\WINDOWS\SYSTEM32\FDEPLOY.DLL
[DC1A78BCCCB7EE53D6FD3BD615A8E222][1 21504
]C:\WINDOWS\SYSTEM32\FDPHOST.DLL
[E5AD448F2DC84B1CF387FA7F2A3D1936][1 33280
]C:\WINDOWS\SYSTEM32\FDRESPUB.DLL
[0046E0BD031213D37123876B0D0FA61C][1 118272
]C:\WINDOWS\SYSTEM32\FHSVC.DLL
[183CA7699474FDE235853967D1DA4D9B][1 1348608
]C:\WINDOWS\SYSTEM32\FNTCACHE.DLL
[EBD5D338F95EE156ECA6198E8FA378F3][1 7680
CB7AD1001C66400BE3A89E1A6343D58F69E62B8E ]C:\WINDOWS\SYSTEM32\FXSEVENT.DLL
[64362206C83D3C300E37267118D5936B][1 41472
]C:\WINDOWS\SYSTEM32\FXSMON.DLL
[2BC8532ABF2B3756B78FA1DA54147DDE][1 655360
]C:\WINDOWS\SYSTEM32\FXSSVC.EXE
[48C163706383C7319DC1F8E9D135D68E][1 491520
]C:\WINDOWS\SYSTEM32\GEOFENCEMONITORSERVICE.DLL
[2788CA31DD51CF747D9C94772CE93E02][1 130696
144064715351DC283B22127115216F3D82A5EAF6 ]C:\WINDOWS\SYSTEM32\GPAPI.DLL
[ECCEC3F904FFE5F8DB4C44F907C3A62F][1 666112
A91476C705E29AB24561713BCADE3CF2EC0BF123 ]C:\WINDOWS\SYSTEM32\GPPREFCL.DLL
[0BDE0FCF597E9B65600121EF54FF8340][1 1311744
]C:\WINDOWS\SYSTEM32\GPSVC.DLL
[449A20A674AA3FAA7F0DD4E33EE2DC20][1 32256
]C:\WINDOWS\SYSTEM32\HIDSERV.DLL
[EC464E8901BA5504CE72985B3A7D5E2F][1 333496
1F18AE8D3D15091D6F20DE9B01CECFA2E32E9213 ]C:\WINDOWS\SYSTEM32\HPINKSTSC111LM.DLL
[ -2][0 -1
]C:\WINDOWS\SYSTEM32\ICARDRES.DLL
[9067880BBB1C18703DBFF27D731D7ECA][1 517120
]C:\WINDOWS\SYSTEM32\ICSVC.DLL
[EC4455EEB36577D79D4D7653ECF306B5][1 111616
]C:\WINDOWS\SYSTEM32\IEETWCOLLECTOR.EXE
[AC3158E78F44C8BB7463E4DBC454168F][1 12946944
28F109F6F671ECA7B6F1C2BC37B29CAC35AC4DBB ]C:\WINDOWS\SYSTEM32\IEFRAME.DLL
[A368C3545420535B2CCE54D3D6649D49][1 282072
9C3F3E9C5F3D17E253AA89395F0EF0BEB67159FD ]C:\WINDOWS\SYSTEM32\IGFXCUISERVICE.EXE
[B119F4CB5C455FBD25B0BCF06095D341][1 501720
CC281423CC1D6007CCB97028F639EA6C2C0533D6 ]C:\WINDOWS\SYSTEM32\IGFXEM.EXE
[68D99E1CEB32DA0681481BC62FC1237F][1 243672
46B79139769ABD60C1932EE1CE0A76DE5FECC907 ]C:\WINDOWS\SYSTEM32\IGFXHK.EXE
[6D83B1A7CED08CFC3836FF51C14C3FA8][1 440792
35BAC1B17E0143BFECFC2154ED36859B9DE980B4 ]C:\WINDOWS\SYSTEM32\IGFXTRAY.EXE
[F568467CD984714E1B849CA170358EC0][1 1102336
]C:\WINDOWS\SYSTEM32\IKEEXT.DLL
[DDD5B1A303EA579EFE2D5A4DE801E9AE][1 34120
]C:\WINDOWS\SYSTEM32\IMAADP32.ACM
[BE0FC6BFE7181F8621B2BD572658A83E][1 162304
EC7C96A9B407FAD230533453FC2BC87FE1374A9C ]C:\WINDOWS\SYSTEM32\INETPP.DLL
[201EDF3C5E674BF1FE44D28CC6A76EA2][1 903168
]C:\WINDOWS\SYSTEM32\IPHLPSVC.DLL
[08A08EC17F1874802A8BC6D083BF1C55][1 433152
]C:\WINDOWS\SYSTEM32\IPNATHLP.DLL
[C16097D77A232A288D65F299E2E01105][1 403456
]C:\WINDOWS\SYSTEM32\IPSECSVC.DLL
[810F8A0A0680662BB0CE44D0E2CEF90C][1 150528
]C:\WINDOWS\SYSTEM32\ISCSIEXE.DLL
[6932138B1E9C1D9601F262EC696E419D][1 52736
]C:\WINDOWS\SYSTEM32\IYUV_32.DLL
[D22AE5313F6B7EFDDD8C117B5501F4A3][1 90464
]C:\WINDOWS\SYSTEM32\KEYBOARDFILTERSVC.DLL
[ECCE051BB49773BEE210B515669AFC6E][1 59392
]C:\WINDOWS\SYSTEM32\KEYISO.DLL
[7BF3ADCBD021D4F4A84CF40EB49C71B5][1 97792
]C:\WINDOWS\SYSTEM32\KMSVC.DLL
[AC63B7ABC65EA78BF50B981FD8C2E346][1 254464
8FB363D501DF7AC9F7F1EDE61D810BD6313DA95E ]C:\WINDOWS\SYSTEM32\KSPROXY.AX
[6CD9C3819BE8C0A3DACC82AE5D3C4F18][1 261632
]C:\WINDOWS\SYSTEM32\LISTSVC.DLL
[00E070FC0C673311AFD4B068D1242780][1 269824
]C:\WINDOWS\SYSTEM32\LLTDSVC.DLL
[D113FAD71A5E67AA94B32A0F8828D265][1 24576
]C:\WINDOWS\SYSTEM32\LMHSVC.DLL
[E4B40D5609F2E5513E616F5BF9D32689][1 121344
395EC12CDCABA2EDE041625E40D7C83F1D41C34C ]C:\WINDOWS\SYSTEM32\LOADPERF.DLL
[E58B2EA7B004184E229854A3D1C00CBB][1 1044480
]C:\WINDOWS\SYSTEM32\LOCALSPL.DLL
[21A02F14CD6D248C7B58B6D7AABA64F4][1 86528
2569CA0611A9D882E54DD616DB80D3F5D792F5F1 ]
C:\WINDOWS\SYSTEM32\LOCATIONNOTIFICATIONS.EXE
[5CAE8F47B31D5CFC322B5B898C19E0FE][1 10240
]C:\WINDOWS\SYSTEM32\LOCATOR.EXE
[F6F209DDB94959BA104FC8FC87C53759][1 45008
]C:\WINDOWS\SYSTEM32\LSASS.EXE
[B6B69FF200F68888A7FAFDF204D00C91][1 716288
]C:\WINDOWS\SYSTEM32\LSM.DLL
[B1AB8E24CD0902E867FD7867193CC44D][1 96768
10CB8FC47738931BFB940D17FAC044486DA13151 ]C:\WINDOWS\SYSTEM32\MCIAVI32.DLL
[277E2DF97D31B07F472DDFF3547D527D][1 241664
92768D205D73DB8FC6B0F63AE3C8D378F7EB080C ]C:\WINDOWS\SYSTEM32\MICROSOFT-WINDOWS-
SYSTEM-EVENTS.DLL
[D72877D08AC821E3983C185D12034B19][1 23552
]C:\WINDOWS\SYSTEM32\MIDIMAP.DLL
[FD788C2D96EA91469A3C1D13E80D7473][1 70656
]C:\WINDOWS\SYSTEM32\MMCSS.DLL
[BFFB40FBE6D2C3469F8D06EE5E4934AB][1 223744
]C:\WINDOWS\SYSTEM32\MPRDIM.DLL
[A46C1D6EE4BC27E8A767079CECCADE9E][1 114176
CB0379B64F9518D56538A5498F3C2E558E1B8F90 ]C:\WINDOWS\SYSTEM32\MPRMSG.DLL
[D186C5844393252147BE934F3871DB7A][1 878080
]C:\WINDOWS\SYSTEM32\MPSSVC.DLL
[ADB4E145B99352A3058A6AB502BB99A1][1 25088
]C:\WINDOWS\SYSTEM32\MSACM32.DRV
[865F786E086BD42E73A218B62E6C5D88][1 34120
]C:\WINDOWS\SYSTEM32\MSADP32.ACM
[2A857CCAFE18B1D396484AC9CC0B9B80][1 382976
]C:\WINDOWS\SYSTEM32\MSCOREE.DLL
[A082C17D14D0790E27D064EA4B138AE1][1 142848
]C:\WINDOWS\SYSTEM32\MSDTC.EXE
[32B1A8351160F307A8C66BCB0F94A9C2][1 357888
]C:\WINDOWS\SYSTEM32\MSDTCKRM.DLL
[418BED8C46E60ECD929CAEA147ADC928][1 13312
EE87098975F1A1E29C760EC798CB0CFCC1F15010 ]C:\WINDOWS\SYSTEM32\MSFEEDSSYNC.EXE
[4F3A00DC17C0B02DD69A7F2C079EE967][1 24832
]C:\WINDOWS\SYSTEM32\MSG711.ACM
[E81D2F5C9CEC6DFBEFDA510CF4C70DA4][1 40816
]C:\WINDOWS\SYSTEM32\MSGSM32.ACM
[50DAB9E7E976BD7FF5F25B83440606AA][1 62464
]C:\WINDOWS\SYSTEM32\MSIEXEC.EXE
[C26803E3870D2587FBB1CA0F26C29B31][1 25088
A33325B7AF6E0164A07AAD8E1AFD81349ECB3B5C ]C:\WINDOWS\SYSTEM32\MSIMSG.DLL
[DC961E92BF50783FB89EFE3CCAB785B4][1 597504
67562D6E8D0C59F574E6CF75CC48173647E614CE ]C:\WINDOWS\SYSTEM32\MSRA.EXE
[86B5C163A3A0E1A9841ED04012E2C109][1 16896
]C:\WINDOWS\SYSTEM32\MSRLE32.DLL
[6ECE4FEEC0FEAF9AB55A8B37EA6207CC][1 842752
00548CE6EB024D4C9E5C1FB1DBA1BD9A29A99461 ]
C:\WINDOWS\SYSTEM32\MSSPELLCHECKINGFACILITY.DLL
[F61A7B0E8F1C7C0B800E51E9CA6FC5F0][1 73216
D03D2DA69BB5176BB8AAC62C6B8D746AF6710526 ]
C:\WINDOWS\SYSTEM32\MSSPELLCHECKINGHOST.EXE
[F23063BEA95D08C0077F69EFBB45F4C0][1 6635520
B663C0535D32881CC07B834B57DDFD7D04E1902E ]C:\WINDOWS\SYSTEM32\MSTSCAX.DLL
[A230BE9C954935719EFF45DFBF86E3EA][1 37376
]C:\WINDOWS\SYSTEM32\MSVIDC32.DLL
[923FB63EAA4CAE2EEE8AFA409CBA1D06][1 26112
]C:\WINDOWS\SYSTEM32\MSYUV.DLL
[71E3C0100AA19D11373CCEB2F51A6008][1 164352
]C:\WINDOWS\SYSTEM32\NCASVC.DLL
[51DF09CAB2CAC64FEE3E371D9028ED01][1 151040
]C:\WINDOWS\SYSTEM32\NCBSERVICE.DLL
[2586C4C167499210DCBF3ECFD8CCE210][1 73728
]C:\WINDOWS\SYSTEM32\NCDAUTOSETUP.DLL
[E01B8CE6646E055D2B806AE4DD5A1202][1 832512
]C:\WINDOWS\SYSTEM32\NETLOGON.DLL
[B7AD851A21FEBA3BA214972627614207][1 254976
]C:\WINDOWS\SYSTEM32\NETMAN.DLL
[F0F0A372C2EF6358399C4936F91B6131][1 525312
]C:\WINDOWS\SYSTEM32\NETPROFMSVC.DLL
[3A280F3B3C7A46E29C404ACD46ECBF5E][1 387584
]C:\WINDOWS\SYSTEM32\NLASVC.DLL
[24DA05ADE2A978E199875DA0D859E7EB][1 217600
]C:\WINDOWS\SYSTEM32\NOTEPAD.EXE
[6E2271ED0C3E95B8E29F3752B91B9E84][1 29184
]C:\WINDOWS\SYSTEM32\NSISVC.DLL
[F611E6125B86F2CFB6D2C6A4F98E487A][1 715776
]C:\WINDOWS\SYSTEM32\NTSHRUI.DLL
[0F7C0962499DA2F817F91B7269ECE56D][1 16384
CD3CDF2B86802B51ECE2C763B85FAF43F3CE3F51 ]C:\WINDOWS\SYSTEM32\NTVDM64.DLL
[2BB3DB931BA3FDEA48044E33C1CD4569][1 30411552
758F79A2B954A65E5C107D937C396FD12D5155BE ]C:\WINDOWS\SYSTEM32\NVOGLV64.DLL
[79D473EA26DBD029DBF21DDB83F7552B][1 923936
3B6F8AD9AB0C2BE189EDD3A41FAB26FC2E83C5FF ]C:\WINDOWS\SYSTEM32\NVVSVC.EXE
[2A57A937BC5B1B2D6AFE6A8C5925F50B][1 433664
]C:\WINDOWS\SYSTEM32\P2PSVC.DLL
[0BDB5190B3AFAEFF93800F149781F942][1 62464
2F85CC431440F70BB62285EF3263E199E6D42622 ]C:\WINDOWS\SYSTEM32\PAUTOENR.DLL
[E8283AF4E98903470B391F24C01ABA03][1 13312
2DDEB77BA774FF23F15FC307C0DD236D5397F256 ]C:\WINDOWS\SYSTEM32\PCALUA.EXE
[38A31075D9630062AD7E26C97033CCC7][1 471040
]C:\WINDOWS\SYSTEM32\PCASVC.DLL
[339DC84D10960038320625CA52E4C843][1 45568
038F9D1327FF0097A151052B31EE104CF8CFA340 ]C:\WINDOWS\SYSTEM32\PERFCTRS.DLL
[FE05B89D609EC317F106E615F14BAFAF][1 25088
73B74978B135416D8D13D9FFA2A924433605D25B ]C:\WINDOWS\SYSTEM32\PERFNET.DLL
[065C787060A095DD0DF8358BC7EF4070][1 39936
5EA382152E7DD80AFE5EF951F942A8330BDCBF96 ]C:\WINDOWS\SYSTEM32\PERFOS.DLL
[028A102C4473D3F53D5D727F05AE3B5D][1 40960
D456703D0E907E22E4409D02DE93A7BDD5E68C27 ]C:\WINDOWS\SYSTEM32\PERFPROC.DLL
[928061178CD9856CA6B67FFFCE6BA766][1 1443840
]C:\WINDOWS\SYSTEM32\PLA.DLL
[3B510F20806B94E389784ED09DBD2111][1 419328
]C:\WINDOWS\SYSTEM32\PNRPSVC.DLL
[9E5A3A3B702ECB9E88AA07731F0E65EB][1 220672
]C:\WINDOWS\SYSTEM32\PROFSVC.DLL
[1480A23374019528CF11B911E60E52AA][1 1461200
BFFA33A04A47C4DFE8FCF969F28A75EDB7B1F682 ]C:\WINDOWS\SYSTEM32\PROPSYS.DLL
[BE5F89BAFBD4272D5A0C0A37B97865ED][1 405504
]C:\WINDOWS\SYSTEM32\PROVSVC.DLL
[41A45D2A75494EABF2806EA051E00376][1 435200
]C:\WINDOWS\SYSTEM32\QAGENTRT.DLL
[15225081966C785A9192782401643FD4][1 1017856
]C:\WINDOWS\SYSTEM32\QMGR.DLL
[30C62CC33E024C3A9EC52201E304D288][1 1564160
]C:\WINDOWS\SYSTEM32\QUARTZ.DLL
[AF90BB44C99D6820BE52C9BBAA523283][1 297472
]C:\WINDOWS\SYSTEM32\QWAVE.DLL
[5F061AC45266841A2860C1858ED863B8][1 101376
]C:\WINDOWS\SYSTEM32\RASAUTO.DLL
[BF3B17016764F20F9D28CF1A8DC210C0][1 534016
]C:\WINDOWS\SYSTEM32\RASMANS.DLL
[4DCCABE03D06955ED61BABBD8EF9F30F][1 164864
]C:\WINDOWS\SYSTEM32\REGSVC.DLL
[D894CBD7DA753C881EE8D5E33B583225][1 79872
]C:\WINDOWS\SYSTEM32\RPCEPMAP.DLL
[CFCDAAA210D62B277A2183F62FEE068F][1 1268056
D10BF7B5B4B4F36A4016422BF29B7C400AA1154B ]C:\WINDOWS\SYSTEM32\RPCRT4.DLL
[3FD5AE42EC87C6F532A931F96BE731DD][1 761344
]C:\WINDOWS\SYSTEM32\RPCSS.DLL
[5B9273124588AB0F2E40AAEC9D3C62EC][1 178688
496FE8605691D9FFFFCBAA956D30FA91DA868574 ]C:\WINDOWS\SYSTEM32\RSTRTMGR.DLL
[2F65C548322123B479616DFA8238770A][1 32584
]C:\WINDOWS\SYSTEM32\RUNTIMEBROKER.EXE
[47C497FA4DDEA908633CAA60CEBE6805][1 188416
]C:\WINDOWS\SYSTEM32\SCARDSVR.DLL
[E76C4E98302AE39CC6FA5D20FC8B5438][1 130560
]C:\WINDOWS\SYSTEM32\SCDEVICEENUM.DLL
[1F1B8D07708E40E54C55B392C78ECCE2][1 271360
]C:\WINDOWS\SYSTEM32\SCECLI.DLL
[7172D44ED18787964B43146863466672][1 539648
9E2E4520EF0ED29160CC550E89ECE9728C10F6F9 ]C:\WINDOWS\SYSTEM32\SCESRV.DLL
[888A30EAB651502352C18745367FD179][1 1212416
]C:\WINDOWS\SYSTEM32\SCHEDSVC.DLL
[572D14ECE0B882AAC770E59B72977481][1 194048
023BF80756F06674B02A371063BE6280E9A6B922 ]
C:\WINDOWS\SYSTEM32\SEARCHFILTERHOST.EXE
[79227C1E2225DE455F365B607A6D46FB][1 844800
]C:\WINDOWS\SYSTEM32\SEARCHINDEXER.EXE
[D6021013D7C4E248AEB8BED12D3DCC88][1 318976
7C7FB7A4304D197AF010B9E63362284FF8411C29 ]
C:\WINDOWS\SYSTEM32\SEARCHPROTOCOLHOST.EXE
[C49009F897BA4F2F4F31043663AA1485][1 30720
]C:\WINDOWS\SYSTEM32\SECLOGON.DLL
[A88882E64BDC1D8E8D6E727B71CCCC53][1 71680
]C:\WINDOWS\SYSTEM32\SENS.DLL
[E66A7C8CE7ED22DED6DF1CA479FB4790][1 220672
]C:\WINDOWS\SYSTEM32\SENSRSVC.DLL
[438CFF94FC90A571389FE49CDC913E49][1 326656
]C:\WINDOWS\SYSTEM32\SESSENV.DLL
[50543966B5C2214A5157372BF77AF982][1 640000
9E140CE2F7EECA562E5E4A22ECFF993246C8F70D ]
C:\WINDOWS\SYSTEM32\SETTINGSYNCHOST.EXE
[52BDBD0FAD538597D85F689A298DE360][1 21192024
]C:\WINDOWS\SYSTEM32\SHELL32.DLL
[0D190D8B4B20446BE6299AC734DFADF1][1 629760
]C:\WINDOWS\SYSTEM32\SHSVCS.DLL
[587ACA15210D1B01FBF272E07A08F91A][1 13312
]C:\WINDOWS\SYSTEM32\SMPHOST.DLL
[49EEB92DE930B8566EF615D600781DB4][1 14848
]C:\WINDOWS\SYSTEM32\SNMPTRAP.EXE
[B7DB57A000D46D4DE75BC0C563E58072][1 2899968
]C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\X64\3\PRINTCONFIG.DLL
[FE0CB40F36D3FCDD3A1B312EF72C38D5][1 798208
]C:\WINDOWS\SYSTEM32\SPOOLSV.EXE
[4F68F08D3AF5AAE315800338932AF042][1 6353960
]C:\WINDOWS\SYSTEM32\SPPSVC.EXE
[C376497571BE84191AE8103A04E6A8F8][1 466944
1CA401CE2E0E152C40A7B228AD5081372A66FDDE ]C:\WINDOWS\SYSTEM32\SRCORE.DLL
[A173F70AED6B661FEB7A0272F07F0E1D][1 4096
BBCD381992B873057AFB8CC911A18BB94D483E19 ]C:\WINDOWS\SYSTEM32\SREVENTS.DLL
[310E6374F4B3E0E8B50CFB8AE3B76F76][1 279552
FBC71604D1ABCAB4B735850CFE644EA14E85E97F ]C:\WINDOWS\SYSTEM32\SRM.DLL
[27B58E16CF895AC1F1A97C04814C2239][1 324608
]C:\WINDOWS\SYSTEM32\SRVSVC.DLL
[BB9ED3EDD8E85008215A7250D325A72E][1 239616
]C:\WINDOWS\SYSTEM32\SSDPSRV.DLL
[3911418AFDE10EA6823B7799E4815524][1 144384
]C:\WINDOWS\SYSTEM32\SSTPSVC.DLL
[3118058E3D07021A55324A943C6D722B][1 19968
]C:\WINDOWS\SYSTEM32\STORSVC.DLL
[E4CA434F251681590D0538BC21C32D2F][1 37768
]C:\WINDOWS\SYSTEM32\SVCHOST.EXE
[D8E1AE075AB3E8AD56F69C44AA978596][1 13312
]C:\WINDOWS\SYSTEM32\SVSVC.DLL
[A5DC2E63F5E5D3C0B843307374998479][1 716288
]C:\WINDOWS\SYSTEM32\SWPRV.DLL
[075A05D710F701B9D41AF5CB411A2A2F][1 83968
E8273E80D1AB9B641839E93EFB9BD0EC774A4FC2 ]C:\WINDOWS\SYSTEM32\SXPROXY.DLL
[BCECD25BCFFE2FC4498374BF2E572DBE][1 603136
C145E17B283CD7FDB8E1C4CF9B9FAA0471989AE5 ]C:\WINDOWS\SYSTEM32\SXS.DLL
[A6DB9DCC34A9EFF0EAECF1978B84C5A2][1 173568
]C:\WINDOWS\SYSTEM32\SYNCUI.DLL
[3C2B9C8EA210F014563BF6391596D8F7][1 1240576
]C:\WINDOWS\SYSTEM32\SYSMAIN.DLL
[373382005ACB27CB16ED16722FBE946A][1 280576
]C:\WINDOWS\SYSTEM32\SYSTEMEVENTSBROKERSERVER.DLL
[0F00B4C00F8F0674892EB31D5D24F8F1][1 82944
]C:\WINDOWS\SYSTEM32\SYSTEMPROPERTIESPERFORMANCE.EXE
[BA6DD39266A5E15515C8C14DA2DA3E5C][1 147456
]C:\WINDOWS\SYSTEM32\TABSVC.DLL
[B517410F157693043DACA21B19B258A6][1 306688
]C:\WINDOWS\SYSTEM32\TAPISRV.DLL
[EDE582496D0CADEE35EA2B1076FF19A8][1 84696
0439C7E56BFBDBE29A78876F3B06D4DF03FF61CF ]C:\WINDOWS\SYSTEM32\TASKHOST.EXE
[40BD4960734B0FA0872AF71B1E4314CE][1 79536
CD5833098A7B72FA5977EF805BFED77E38AF8C4A ]C:\WINDOWS\SYSTEM32\TASKHOSTEX.EXE
[70179FFB5487A8A2BB4A1AB1B22219E6][1 205824
]C:\WINDOWS\SYSTEM32\TCPMON.DLL
[2C77831737491F4D684D315B95C62883][1 1032704
]C:\WINDOWS\SYSTEM32\TERMSRV.DLL
[05FBE1F7C13E87AF7A414CDF288B1F62][1 50688
]C:\WINDOWS\SYSTEM32\THEMESERVICE.DLL
[347A3E49CE18402305B8119A6EC7CFEB][1 245760
]C:\WINDOWS\SYSTEM32\TIMEBROKERSERVER.DLL
[616DF4ADC4E04753BB4951D3464B8157][1 3486208
9CBB89D2F3B2B6BB8A2AB9EEA4DC0F9D5E22E7DA ]C:\WINDOWS\SYSTEM32\TQUERY.DLL
[C97E14BB6A196B0554D6EB67D8818175][1 122368
]C:\WINDOWS\SYSTEM32\TRKWKS.DLL
[0BAF086D41F4AE011EB14EDE92A3D00E][1 15872
]C:\WINDOWS\SYSTEM32\TSBYUV.DLL
[28AB6EFCBA8D298A284CF3279171E443][1 1011200
42F6774975BABF705B683AC30C4E41BBC028BEA6 ]C:\WINDOWS\SYSTEM32\TSWORKSPACE.DLL
[13F844C253486BCB2ADE05ED3E2E4993][1 13165568
8A65AF4B818C6B73CB40523489575719BFFB4C0F ]C:\WINDOWS\SYSTEM32\TWINUI.DLL
[320878AFECDBBD61BBE98624A6CAAC08][1 40960
]C:\WINDOWS\SYSTEM32\UI0DETECT.EXE
[084FFAFC9796DD43BD8FD854673E3132][1 161280
4E9E48FF8A0BCC674CE525468C05F5DC0879291E ]C:\WINDOWS\SYSTEM32\ULIB.DLL
[752A457320A946E03C3AA86C3ACD735E][1 124928
]C:\WINDOWS\SYSTEM32\UMPNPMGR.DLL
[00E08B30E7F7C13ECE2CDF4F46A77311][1 79360
]C:\WINDOWS\SYSTEM32\UMPO.DLL
[E3DDF7D43E05784FAA5E042605EEE528][1 289280
]C:\WINDOWS\SYSTEM32\UMRDP.DLL
[E234DBE3B155D5F7CFD77B814D592E79][1 235008
]C:\WINDOWS\SYSTEM32\UNREGMP2.EXE
[4A2FFDAC45F317E17DF642C7160EB633][1 436224
]C:\WINDOWS\SYSTEM32\UPNPHOST.DLL
[9BE4639FD1A3F8A9FECFE958D7B04F9A][1 289280
]C:\WINDOWS\SYSTEM32\USBMON.DLL
[D2F749A01019A5A50716BA14EE714342][1 13312
451EED762E2A7A0D5A20501E875C684A0E2F42AB ]C:\WINDOWS\SYSTEM32\USBPERF.DLL
[1A811BAFA2114C2FC878507F9F86566C][1 1517984
]C:\WINDOWS\SYSTEM32\USER32.DLL
[64E2C7176D189E4A838D04F7C724CAE7][1 117784
FD44E663717C4A09A8B092EF2BEE57A4661B9A84 ]C:\WINDOWS\SYSTEM32\USERENV.DLL
[08C191B2917862BE90C33E31CB6B6D79][1 25088
]C:\WINDOWS\SYSTEM32\USERINIT.EXE
[81DAC9F3309A51C041545AF760CFDF06][1 248832
]C:\WINDOWS\SYSTEM32\VAULTSVC.DLL
[CFBAD6B48EDFAA0828A52646B7C4C08D][1 1283584
]C:\WINDOWS\SYSTEM32\VDS.EXE
[5A6EAE44508C4C604A31E4AC37F2D758][1 208384
C44501749FB885C2D99726E0BC505A09B8710A14 ]C:\WINDOWS\SYSTEM32\VMICRES.DLL
[D51D7EF1EA5ED2BB01E9D07E6E0533BC][1 1436160
]C:\WINDOWS\SYSTEM32\VSSVC.EXE
[7599E582CA3A6AAA95A18FFE1172D339][1 404480
]C:\WINDOWS\SYSTEM32\W32TIME.DLL
[C510810D292782189F8BE12A1B0E366E][1 921088
]C:\WINDOWS\SYSTEM32\WBEM\FASTPROX.DLL
[EB83C257C95F2E00D92F9432C849E712][1 3072
6F35188AE4348BB0615D82E61142181DEAB3C664 ]C:\WINDOWS\SYSTEM32\WBEM\IPMIPRR.DLL
[69D81B5403B913369B4A694CD2F42744][1 26624
06231506DFE9B108F56917649383F1D60167FC70 ]C:\WINDOWS\SYSTEM32\WBEM\WINMGMTR.DLL
[7AFAC828F52D62F304A911EC32F42EEE][1 195072
]C:\WINDOWS\SYSTEM32\WBEM\WMIAPSRV.EXE
[CE6D08350D0A1278E9A97D94023D1800][1 478208
5A4C0E82FF95C9FB762D46A696EF9F1B68001C21 ]C:\WINDOWS\SYSTEM32\WBEM\WMIPRVSE.EXE
[9DB490F3E823C5C3C070644B96CB9D59][1 220672
]C:\WINDOWS\SYSTEM32\WBEM\WMISVC.DLL
[92BF4B3EBD6F163B94B7A20C65E7B698][1 1542144
]C:\WINDOWS\SYSTEM32\WBENGINE.EXE
[CE9E5A541CB4203B4930CE89766D4E5C][1 453120
]C:\WINDOWS\SYSTEM32\WBIOSRVC.DLL
[5A619483E21DAAF186DF23270D226A7D][1 365056
]C:\WINDOWS\SYSTEM32\WCMSVC.DLL
[8AF411E94155BF44DD4E878B42AA455B][1 459264
]C:\WINDOWS\SYSTEM32\WCNCSVC.DLL
[846C02A8B48CBD921A3D6AB521AA0DC4][1 41984
]C:\WINDOWS\SYSTEM32\WCSPLUGINSERVICE.DLL
[40C67D1A4891120874767F6E6604D6C5][1 91136
]C:\WINDOWS\SYSTEM32\WDI.DLL
[D199A538404FB72FC0AB036595D20E1F][1 217600
]C:\WINDOWS\SYSTEM32\WDMAUD.DRV
[6588A957873326361AB1CAC4E76F8394][1 226816
]C:\WINDOWS\SYSTEM32\WEBCLNT.DLL
[3274312F263882B51B964329FAF49734][1 215040
]C:\WINDOWS\SYSTEM32\WECSVC.DLL
[7CDD84E0023A0C5C230B06A7965EC65E][1 24576
]C:\WINDOWS\SYSTEM32\WEPHOSTSVC.DLL
[A188CA36B475624E547C750EE8616376][1 533032
49ED17672C74ACA319DA8DE1AEAA032ED5EC7407 ]C:\WINDOWS\SYSTEM32\WER.DLL
[AA1315B87D9B2E39584165318A59F15D][1 81408
]C:\WINDOWS\SYSTEM32\WERCPLSUPPORT.DLL
[22B4C24AB921BFF7827FFBCA1F4E1BB3][1 100864
]C:\WINDOWS\SYSTEM32\WERSVC.DLL
[E06AFE2F94BA7CFA2FE4FD2A449E60E2][1 66048
]C:\WINDOWS\SYSTEM32\WIARPC.DLL
[D638904FE86A5FE542A1BA13A9D68E5C][1 634368
]C:\WINDOWS\SYSTEM32\WIASERVC.DLL
[EB1910FCBC61A478E07FCB59487B56AD][1 805888
5DE2AD98A429711B5FB46B432CD67F17516B4498 ]C:\WINDOWS\SYSTEM32\WIN32SPL.DLL
[DD079EC8F44DCA3A176B345C6ADEFB66][1 786432
]C:\WINDOWS\SYSTEM32\WINHTTP.DLL
[48CFA7BE561A7BE144C29BB912055016][1 144384
2263BDF440400904669706E48AE5AC0FAE25762A ]C:\WINDOWS\SYSTEM32\WININIT.EXE
[7C94FDA3809015B8F2208D2E1C221F17][1 564736
]C:\WINDOWS\SYSTEM32\WINLOGON.EXE
[DA3AC70D35B1283A37821624215A49FE][1 3687424
E3422973107E62A91C33C57D16C93903AC502BD1 ]C:\WINDOWS\SYSTEM32\WINSAT.EXE
[599F1244C60E3D6C28A8DA7FBA7A2C13][1 193536
4C6AEA18D333C129B5018D1FF026E5668C7C9455 ]C:\WINDOWS\SYSTEM32\WINSRV.DLL
[D0D9C2ECA4D03A8F06DCD91236B90C98][1 284160
]C:\WINDOWS\SYSTEM32\WKSSVC.DLL
[191294664E1397B5B0C95218A545250F][1 1500672
]C:\WINDOWS\SYSTEM32\WLANSVC.DLL
[02A13DB2D44B17A1C37769246694C7CD][1 1563136
]C:\WINDOWS\SYSTEM32\WLIDSVC.DLL
[A1314F0CD51E8F7CF613A17D8B0724F7][1 1534464
]C:\WINDOWS\SYSTEM32\WORKFOLDERSSVC.DLL
[4E6A0F60DA7EF050D3D26417CD4D24E9][1 12288
]C:\WINDOWS\SYSTEM32\WPCSVC.DLL
[D27491CFCE452C154CECFA155AD0EBC8][1 84480
]C:\WINDOWS\SYSTEM32\WPDBUSENUM.DLL
[C15B3FE9B7AB65A984B7BFD1382DE43E][1 161280
]C:\WINDOWS\SYSTEM32\WSCRIPT.EXE
[5CFA46C4ACB2FD70572017052378DAE5][1 133632
]C:\WINDOWS\SYSTEM32\WSCSVC.DLL
[48B5A62750FC3E3E8733106FB7E2DF0F][1 297984
]C:\WINDOWS\SYSTEM32\WSDMON.DLL
[F011F1F2CF1701374A361EB1E74B4289][1 29184
EF138766D719131B7169C9648C8C680143AE8837 ]C:\WINDOWS\SYSTEM32\WSEPNO.DLL
[2B659DAB8F020252FF862AA2692B33CA][1 102400
99575990AEAED973F0A7AA87EE1A1DC378DE41BF ]C:\WINDOWS\SYSTEM32\WSHEXT.DLL
[690C3FC5C9DBD6B9AEDF8341EC720E41][1 2479616
]C:\WINDOWS\SYSTEM32\WSMSVC.DLL
[DD988D37D33574D02642E528C8CD8808][1 3395928
]C:\WINDOWS\SYSTEM32\WSSERVICE.DLL
[B957B92C79A4CD138D5CFF1D20A9CF7B][1 3524096
]C:\WINDOWS\SYSTEM32\WUAUENG.DLL
[BB73CBC65AABC4EA0A5C6A1474A0A743][1 100352
]C:\WINDOWS\SYSTEM32\WUDFSVC.DLL
[2FA9794CA36147756F3FDFD6CA29B46F][1 510464
]C:\WINDOWS\SYSTEM32\WWANSVC.DLL
[5430FA34D2FDA83ED1DBC43A8D516E31][1 446464
B4A72126240F07476E6EB463F067996A37D53918 ]C:\WINDOWS\SYSTEM32\XWIZARDS.DLL
[6E21307B8E6C88C12E4DD11A62C8EBFE][1 1007104
]C:\WINDOWS\SYSWOW64\D3D8.DLL
[9AE11282C83784273732ED155BC9FF4A][1 492032
0B9D755487825FEDA05B0BE9A4298C2F5FAEB62C ]C:\Windows\SYSWOW64\DNSAPI.DLL
[3FEEBF51CFDBFB4CD30093609888DCEB][1 84992
]C:\WINDOWS\SYSWOW64\ICCVID.DLL
[04EE1AD7E9277EC632C390DFEECF4C11][1 740864
]C:\WINDOWS\SYSWOW64\INETCOMM.DLL
[335ECC1529062E7E7428F30C891B1B76][1 279000
8E37873767AC2E7EB550D9AF631B9F808A880478 ]C:\WINDOWS\SYSWOW64\INTELCPHECISVC.EXE
[28853B76503048E818E3B143B8C2860B][1 139776
]C:\WINDOWS\SYSWOW64\ITSS.DLL
[FA2E1F09ED6C4C221E4513A7E815E13D][2 1536
5AA4C802E64E82D001B5DC77F40CDAB07757A33E ]C:\WINDOWS\SYSWOW64\IUSEVENTLOG.DLL
[6109EEADA1F9D2B971C7EA668A58D768][1 68096
]C:\WINDOWS\SYSWOW64\L3CODECA.ACM
[414899B223DC3888BCA6D81CBBB05080][1 272888
C58A7C073DA285F598CF6DA4AD706F47D16B8A67 ]
C:\WINDOWS\SYSWOW64\MACROMED\FLASH\FLASHPLAYERUPDATESERVICE.EXE
[73395776872F0EE6DA11F92BF6A7A874][1 1277016
775A72C8C722F7B849CCFEEDC1EA11525933BDB4 ]
C:\WINDOWS\SYSWOW64\MACROMED\FLASH\FLASHUTIL32_25_0_0_148_PEPPER.EXE
[71EA3DCE8B998B6730A942469D15ED44][2 186368
]C:\WINDOWS\SYSWOW64\MSAUD32_DIVX.ACM
[84F20198CAE435DE32ABDB4511550BD7][1 330240
]C:\WINDOWS\SYSWOW64\MSCOREE.DLL
[F21C143173614345E97AC7932ADD220C][1 17074176
]C:\WINDOWS\SYSWOW64\MSHTML.DLL
[9618E4752B19CE24EFD729C662C8DB1E][1 1386496
E2FC41553E1F85472E3E4C6B20DEA5430E500EF7 ]C:\WINDOWS\SYSWOW64\MSVBVM60.DLL
[7EEC1F2A4F4D651BCB7263F69E15E5DA][1 2284544
]C:\WINDOWS\SYSWOW64\MSVIDCTL.DLL
[5B4FF009D24F73F6FC6EB4870A789843][1 270848
]C:\WINDOWS\SYSWOW64\MSWSOCK.DLL
[8DB30DA1FA8620A5C4AF53DEB85194D8][1 53760
]C:\WINDOWS\SYSWOW64\NAPINSP.DLL
[F604350906CE4E3F67D81384566DE3E4][1 64000
]C:\WINDOWS\SYSWOW64\NLAAPI.DLL
[0FC9B04C7F729498B41A19FA55C33573][1 80384
]C:\WINDOWS\SYSWOW64\OLEPRO32.DLL
[8E3C640FFF5A963F570233AE99C0FFF3][1 21504
]C:\WINDOWS\SYSWOW64\PERFHOST.EXE
[4947B4C100BE88C83F027D1C8DBC4B84][1 68096
]C:\WINDOWS\SYSWOW64\PNRPNSP.DLL
[07D58D5F7839ABA76118BC037C2C63BD][1 447104
]C:\WINDOWS\SYSWOW64\SASRV.EXE
[4C99F942021C5F3741BCDD576F2FE435][1 18634248
]C:\WINDOWS\SYSWOW64\SHELL32.DLL
[3E274E8A9403CCAF8FDDBF20E5AB944D][1 1152512
]C:\WINDOWS\SYSWOW64\URLMON.DLL
[8700883867FBD565BF6C2DAE8B2D7810][1 21504
]C:\WINDOWS\SYSWOW64\WINRNR.DLL
[D349F1E9D0388A78B6AE769F1450BA3E][1 51200
]C:\WINDOWS\SYSWOW64\WSHBTH.DLL
[3B9F88B5F521111D16222F66071730C2][2 6892544
4ED057D1B212E8E0DE97B4B72487ED7B64F09FBC ]D:\APP-GAMES\COUNTER STRIKE V6\COUNTER
STRIKE XTREME.EXE
[ -2][0 -1
]D:\CAD14D21DD5E2E0C5BD282\DW\DW20.EXE
===
[MBR]
[MD5=6F5C728704818D7DC62499B0E441E6D3]
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAA=
===
[PT]
0xee Unknown, 1, -1
===
[VBR]
61KQTlRGUyAgICAAAggAAAAAAAAA+AAAPwD/AAAIAAAAAAAAgACAAP9fCQAAAAAA/2MAAAAA
AAAQAAAAAAAAAPYAAAABAAAALdClNOClNMoAAAAA+jPAjtC8AHz7aMAHHx5oZgDLiBYOAGaB
PgMATlRGU3UVtEG7qlXNE3IMgftVqnUG98EBAHUD6d0AHoPsGGgaALRIihYOAIv0Fh/NE5+D
xBieWB9y4TsGCwB126MPAMEuDwAEHloz27kAICvIZv8GEQADFg8AjsL/BhYA6EsAK8h377gA
u80aZiPAdS1mgftUQ1BBdSSB+QIBch4WaAe7FmhSERZoCQBmU2ZTZlUWFhZouAFmYQ4HzRoz
wL8KE7n2DPzzqun+AZCQZmAeBmahEQBmAwYcAB5maAAAAABmUAZTaAEAaBAAtEKKFg4AFh+L
9M0TZllbWmZZZlkfD4IWAGb/BhEAAxYPAI7C/w4WAHW8Bx9mYcOh9gHoCQCh+gHoAwD06/2L
8Kw8AHQJtA67BwDNEOvyww0KQSBkaXNrIHJlYWQgZXJyb3Igb2NjdXJyZWQADQpCT09UTUdS
IGlzIGNvbXByZXNzZWQADQpQcmVzcyBDdHJsK0FsdCtEZWwgdG8gcmVzdGFydA0KAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAIoBpwG/AQAAVaoHAEIATwBPAFQATQBHAFIABAAkAEkAMwAwAADU
AAAAJAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAOnAAJAFAE4AVABMAEQAUgAHAEIATwBPAFQAVABHAFQABwBCAE8ATwBUAE4AWABUAAAA
AAAAAAAAAAAAAAAAAAAAAAAADQpBbiBvcGVyYXRpbmcgc3lzdGVtIHdhc24ndCBmb3VuZC4g
VHJ5IGRpc2Nvbm5lY3RpbmcgYW55IGRyaXZlcyB0aGF0IGRvbid0DQpjb250YWluIGFuIG9w
ZXJhdGluZyBzeXN0ZW0uAAAAAAAAAAAAAAAAAAAAAAAAAACaAmYPtwYLAGYPth4NAGb342aj
UgJmiw5AAID5AA+PDgD22Wa4AQAAAGbT4OsIkGahUgJm9+Fmo4YCZg+3HgsAZjPSZvfzZqNW
AuiiBGaLDk4CZokOJgJmAw6GAmaJDioCZgMOhgJmiQ4uAmYDDoYCZokOPgJmAw6GAmaJDkYC
ZriQAAAAZosOJgLokAlmC8APhL/9ZqMyAma4oAAAAGaLDioC6HcJZqM2Ama4sAAAAGaLDi4C
6GUJZqM6AmahMgJmC8APhIz9Z4B4CAAPhYP9Z2aNUBBnA0IEZ2YPtkgMZokOkgJnZotICGaJ
Do4CZqGOAmYPtw4LAGYz0mb38WajlgJmoUYCZgMGjgJmo0oCZoM+NgIAD4QdAGaDPjoCAA+E
MP1mix46Ah4HZos+SgJmoS4C6O0B6CwNZgvAD4QDAOhCDmYPtw4AAma4AgIAAOgiCGYLwA+F
FgBmD7cOWgJmuFwCAADoDAhmC8APhHgOZ2aLAB4HZos+PgLoPwZmoT4CZrsgAAAAZrkAAAAA
ZroAAAAA6OQAZoXAD4UjAGahPgJmu4AAAABmuQAAAABmugAAAADoxABmC8APhUQA6ScOZjPS
ZrmAAAAAZqE+AujKCGYLwA+EEA4eB2aLPj4C6NsFZqE+Ama7gAAAAGa5AAAAAGa6AAAAAOiA
AGYLwA+E5g1nZg+3WAxmgeP/AAAAD4XbDWaL2GgAIAdmK/9moT4C6AABaAAgB2Yr/2ahPgLo
rAqKFg4AuOgDjsCNNgsAK8BoACBQywYeZmBmi9pmD7YODQBm9+FmoxEAZovDZvfhoxYAi9+D
4w+MwGbB7wQDx1AH6JL7ZmGQHwfDZwNAFGdmgzj/D4RMAGdmORgPhTMAZgvJD4UKAGeAeAkA
D4UjAMNnOkgJD4UaAGaL8GcDcArolwZmUR4HZov686dmWQ+FAQDDZ2aDeAQAD4QHAGdmA0AE
66tmK8DDZovz6GwGZ2YDAGf3QAwCAA+FNABnZo1QEGc6SkAPhRgAZ2aNckLoSQZmUR4HZov7
86dmWQ+FAQDDZ4N4CAAPhAYAZwNACOvCZjPAw2eAewgAD4UcAAYeZmBnZo1TEGdmiwpmi/Nn
A3IE86RmYZAfB8NmUGdmjVMQZoXAD4UKAGdmi0oIZkHrEZBnZotCGGYz0mb3NlICZovIZivA
Zl7oAQDDBh5mYGeAewgBD4QDAOnK+maD+QAPhQYAZmGQHwfDZlNmUGZRZlZmVwbokQRmi9EH
Zl9mXmZZZoXAD4Q0AGY7yg+NAwBmi9Hogv5mK8pmi9pmi8JmD7YWDQBm9+JmD7cWCwBm9+Jm
A/hmWGYDw2Zb659mhfYPhGL6ZlFmVwZnZg+2QwlmhcAPhCAAZtHgZivgZov8ZlRmVmdmD7dz
CmYD82aLyPOkZl7rA5BmUGZQZ2aLA2ZQZ2aLQxhmUGdmi1YgZoXSD4QLAGaL/h4HZovC6HED
ZovGZlpmWWZCZlFmVug/BmaFwA+E8flmXmZZZov+HgfoTgNmi8Zmi9lmWWZaZlFmVmbR6ej4
/WaFwA+EyvlmXmZZZgPhB2ZfZllmi9BmWGZbZova6fX+Bh5mYCZnZg+3XwQmZ2YPt08GZgvJ
D4SY+WYD32aDwwJmgcf+AQAAZklmC8kPhBcAJmeLAyZniQdmg8MCZoHHAAIAAGZJ6+JmYZAf
B8MGHmZgZrgBAAAAZqMiAmahHgJmAwaGAmajigJmAwaGAmajTgJmoTAAZg+2Hg0AZvfjZose
TgJmiQdmoxEAg8MEZqFWAmaJB6MWAIPDBGaJHk4CZoseHgIeB+i7+GaL++hR/2ahHgJmuyAA
AABmuQAAAABmugAAAADoEP1mC8APhBkBZovYHgdmiz4aAmYzwOii/WaLHhoCZoE/gAAAAA+E
6wADXwTr8GZTZotHEGb3JlYCZlBmM9JmD7YeDQBm9/NmUujcAGYLwA+EmPhmiw5WAmYPth4N
AGb342ZaZgPCZoseTgJmiQeDwwRmD7YGDQBmK8JmO8EPhgMAZovBZokHZivIZloPhHUAZgPC
ZlBmM9JmD7YeDQBm9/NmUeiCAGZZZgvAD4Q8+GYPth4NAGb342aLHk4CZosXg8MEZgMXZjvQ
D4UVAGYPtgYNAGY7wQ+GAwBmi8FmAQfrpYPDBGaJHk4CZokHg8MEZg+2Bg0AZjvBD4YDAGaL
wWaJB+uCg8MEZv8GIgJmiR5OAmZbA18EZoE/gAAAAA+EDP9mYZAfB8Nmi9Bmiw4iAmaLNooC
ZgM2hgJmUmZRZlJmix6KAmaLPlYCZosEZqMRAIPGBGaLBKMWAIPGBB4H6Dz3Ziv4D4QIAPcm
CwAD2OvZZos+igIeB+i//WahigJmu4AAAABmuQAAAABmi9HogftmC8APhFP3ZovYZlhmVugs
AWZeZgvAD4QFAGZbZlvDZllmWuKEZjPAwwYeZmBmUGZRZjPSZg+2Hg0AZvfzZlJmV+hT/2Zf
ZgvAD4QN92YPth4NAGb342ZaZgPCZqMRAGZZZg+2Hg0AZjvLD44TAIkeFgBmK8tmWGYDw2ZQ
ZlHrFJBmWGYDwWZQiQ4WAGa5AAAAAGZRBmZXi9+D4w+MwGbB7wQDx1AH6GT2Zl8HZgM+UgJm
WWZYZoP5AA+PcP9mYZAfB8MGHmZgZvcmVgJmiw5WAuhV/+jS/GZhkB8HwwYeZmBm9yaSAmaL
HjYCZosOkgJmizYqAh4HZos+RgLogfvop/xmYZAfB8NmUGZTZlFmix5KAmaLyGbB6ANmg+EH
ZgPYZrgBAAAAZtPgZ4QDD4QEAPjrApD5ZllmW2ZYw2eAewgBD4QEAGYrwMNnZo1zEGdmi1YI
ZjvCD4cLAGdmixZmO8IPgwQAZivAw2cDXhBmK/ZngDsAD4Q+AOiBAGYD8eg5AGYDymY7wQ+M
IQBmi9FmUGdmD7YLZovBZoPgD2bB6QRmA9lmA9hmQ2ZY68RmK8hmK8JmA8bDZivAw2YryWeK
C4DhD2aD+QAPhQQAZivJw2ZTZlJmA9lnZg++E2ZJZktmg/kAD4QNAGbB4ghnihNmS2ZJ6+tm
i8pmWmZbw2ZTZlJmK9JnihNmg+IPZivJZ4oLwOkEZoP5AA+FCABmK8lmWmZbw2YD2mYD2Wdm
D74TZklmS2aD+QAPhA0AZsHiCGeKE2ZLZknr62aLymZaZlvDZgvJD4UBAMNmUWZWZ4M+YQ+M
DABngz56D48EAGeDLiBmg8YC4uZmXmZZw2ZQZlFmi9BmoTICZ2aNWBBnA0MEZ2aNQBBmi9ro
RPlmC8APhAUAZllmWcNmoTYCZgvAD4UIAGZZZllmM8DDZosWNgJnZo1SEGdmi0IYZjPSZvc2
jgJmM/ZmUGZWZlhmXmY7xg+EOgBmVmZAZlBmSOgb/nLo6Ov9ZlpmXmZZZltmU2ZRZlZmUmah
RgJnZo1AGOjQ+GYLwHTEZllmWWZZZlnDZllmWWYzwMNmUWZQZrgFAAAAHgdmi/nojf1mi8Fm
uyAAAABmuQAAAABmugAAAADoM/hmW2ZZZoXAD4UVAGaLwWYPtw4QAma6EgIAAOgW+OszkGYz
0maLwWaLy2ZQZlPoIwBmW2ZfZgvAD4QXAB4H6DX9ZovHZg+3DhACZroSAgAA6OH3w2ZSZlFm
uyAAAABmuQAAAABmugAAAADox/dmC8APhGMAZovYHgdmiz4aAmYzwOhZ+B4HZoseGgJmWWZa
JmY5Dw+FDAAmZjlXCA+EMQDrE5AmZoM//w+ELwAmg38EAA+EJgAmZg+3RwQD2IvDJQCAdMuM
wAUACI7AgeP/f+u+JmaLRxDDZllmWmYzwMNmUGZRZovHZsHoBAZZA8hRB2aD5w9mWWZYw2AG
vmkOvwAgHge5DQCQ86UHYcMBI0VniavN7/7cuph2VDIQ8OHSwwAAAAAgIGCLNhggJooFiARH
Rmb/BhQggf5gIHUG6FsAviAg4uaJNhggYcNmYIs2GCCwgIgERjLAgf5gIHUG6DoAviAggf5Y
IHXpZjPAZqNYIGahFCBmweADZg/IZqNcIOgYALsAIGaLB2YPyGaJB4PDBIH7NCB17mZhw2Zg
uyAgZosHZg/IZokHg8MEgftgIHXuuwAgZosPZotXBGaLdwhmi38MZotvELsgIMcGGiDcD8YG
HCAUkFOLHhog/xdmA0cCW2YD6GYDL2aLwWbBwAVmA8Vmi+9mi/5mi/JmwcYeZovRZovIZosH
ZjNHCGYzRyBmM0c0ZtHAZolHQIPDBP4OHCB1soMGGiAGgT4aIPQPdZ+7ACBmAQ9mAVcEZgF3
CGYBfwxmAW8QZmHDZovGZjPHZiPCZjPHw2aLwmYzxmYzx8NmU2aLwmYjxmaL2mYj32YLw2aL
3mYj32YLw2Zbw6gPmXmCWrUPoevZbr8P3Lwbj7UP1sFiygYeZmBmM9u4ALvNGmYjwA+FuwBm
gftUQ1BBD4WwAIH5AgEPgqgAZmGQHwcGHmZgZ4B7CAAPhQwAZ2aNUxBnZosK6yWQZ2aNUxBn
ZotKKGaB+QAACAAPgwwAZ2aLQixmI8APhAMAZjPJDh/o9f1mI8kPhDIAZroAgAAAZjvKD4Yf
AGYrygZmUWZXZlJmi8rot/3o+/1mWmZfZlkHZgP669ropf3o6f3oC/4OB2a7VENQQWa/ACAA
AGa5FAAAAGa4B7sAAGa6CgAAAGYz9s0aZmGQHwfDBh5mYGYz27gAu80aZiPAD4V0AGaB+1RD
UEEPhWkAgfkCAQ+CYQBmuAe7AABmu1RDUEFmubgBAABmugQAAABmM/Zmvk1CUkNoAAAHZr8A
fAAAzRpmuAe7AABmu1RDUEFmuUIAAABmugUAAABmM/Zmvk1CUkRoAAAHZr8AfAAAZoHHvgEA
AM0aZmGQHwfDZlJmM8BngHsIAA+FDABnZo1TEGdmiwLrC5BnZo1TEGdmi0IoZlrDBh5mYGYP
tw5mAma4aAIAAOj8+mYLwA+E+gBmD7cOdgJmuHgCAADo5vpmC8APhOQAZ2aLAB4HZos+PgLo
GflmoT4CZrsgAAAAZrkAAAAAZroAAAAA6L7zZoXAD4UjAGahPgJmu4AAAABmuQAAAABmugAA
AADonvNmC8APhUQA6ZMAZjPS
===
[SIGN]
[C53B99F4EB6C0BBE7313777B3ED03E89] ASUSTEK COMPUTER INC.
[7A97AA40D8A3DA4A9095873C72D524C5] ADOBE SYSTEMS, INCORPORATED
[489FA9A917C02A0AD2824A1339C13485] ASUSTEK COMPUTER INC.
[FA1BFFE455074BD7445AB75B449BF9AD] ASUSTEK COMPUTER INC.
[67BCFC63F639C1C7F68E4F8ED9305587] ASUSTEK COMPUTER INC.
[6C0D429419FC1E1A16AA0CF769C3863D] ASUSTEK COMPUTER INC.
[564CB886D1A968B9798C1AB03F4EB54F] ASUSTEK COMPUTER INC.
[47F12AD8FD0151607CE66D8A165C28F7] ASUSTEK COMPUTER INC.
[4F870EF9292559AB9DE6F31527A1DCBF] ASUSTEK COMPUTER INC.
[08B018EF53C79AF2DAC005B494B9AF53] ASUSTEK COMPUTER INC.
[230553C24EEE56CA07CF66117A10BFCC] ASUSTEK COMPUTER INC.
[C435191FAD19B43E5C3082E4275DCE75] ASUSTEK COMPUTER INC.
[4C016FD76ED5C05E84CA8CAB77993961] ASUSTEK COMPUTER INC.
[DBC598E47E7A382E60E2A4745D41FEF9] ASUSTEK COMPUTER INC.
[99B0DD6A5DF7E130C81C7CC05137A861] ASUSTEK COMPUTER INC.
[07A37CB5C5A01E73FB69F138FAE2DB0E] ADOBE SYSTEMS, INCORPORATED
[4C72FDD915D62EAEF149BD9C73AB9CF4] ADOBE SYSTEMS, INCORPORATED
[DD59DB2A6E582A80ED06636E50B36F59] MICROSOFT WINDOWS
[ADA4C8A5F210B0F5EEED547FA1B537CF] Gretech Corp.
[34D296AFC913E302953C70463EF09A48] HEWLETT-PACKARD COMPANY
[52069AEB42D3D0F97CBCA1085EBF55E6] Intel Corporation - Intel Management Engine
Firmware
[E2952760B05A256FB1412D20A41C89C1] INTEL CORPORATION - SOFTWARE AND FIRMWARE
PRODUCTS
[849D66021A0EF43A20137BA9D85ECADF] MICROSOFT WINDOWS
[A9CF130554ECB9FEDDEA199BB25D328A] Zhuhai Kingsoft Office Software Co.,Ltd
[40855BAC4FBD8686971CC67C2B99F390] Zhuhai Kingsoft Office Software Co.,Ltd
[065F7A34C446184F6356703EEE146A6E] Zhuhai Kingsoft Office Software Co.,Ltd
[B83C9114A1C7318184080128464063AA] Zhuhai Kingsoft Office Software Co.,Ltd
[742412B75CC7840FD36AE634719F640B] Mozilla Corporation
[A162D258A73516324DA7D7D44D04F1A9] Mozilla Corporation
[E09C5339746C10596C1BA740956F3416] NVIDIA CORPORATION
[42663C9A625EA030F10746EBA60F8CCD] NVIDIA CORPORATION
[A897CB2ED77492B013553EC25C5B4584] Opera Software AS
[A990930EA25BB8359A4EBC5043B8FA59] Mooii Tech
[37E95CA1EAB1DB1FB4D3D815D83DE0A6] GREATIS SOFTWARE LLC
[BE6C6AAC65CFF551E2E83404AA9F94BF] GREATIS SOFTWARE LLC
[89A43B58089C434C598E26E4FD8FD6BE] GREATIS SOFTWARE LLC
[B60F58F175DE20A6739194E85B035178] CACE Technologies, Inc.
[0AF7D4CC9262C143B692B3A83C13D850] Conexant Systems, Inc.
[4F8B94EC4D4FFA0712CCADF8145F28D1] Conexant Systems, Inc.
[2121EB9E70C5931F3EC8741D47A1CB74] Hewlett Packard
[CEC2EE3F2D7D9E14E1E1BAF0D740D860] Hewlett Packard
[E0FA3B6D94F635426724029BEEE45FCA] Hewlett Packard
[925471076EB70C97DFC7B4FCC2AE39D6] Hewlett Packard
[D45226E3E7A25F1E7CE8DF8FD0A2A098] Intel Trusted Connect Service
[1C39C41D50FF7113748D825F4327D406] MICROSOFT WINDOWS
[C3FD97F6EB5C60B96E09E6930ECDFFFE] NVIDIA CORPORATION
[38C3C1225638BF1E8665060A51C4F598] NVIDIA CORPORATION
[90B85FFBDEEAD1BE861D59134EA985B0] MICROSOFT WINDOWS
[78ABEA36C5228E99D849D478A7F3C814] MICROSOFT WINDOWS
[9CE95E2A32023CE9D9B38EE2295688A9] MICROSOFT WINDOWS
[6F0CC657B8FDA5B5F82F51F330EA3CA7] win.rar GmbH
[D6E2ED7F1F7BE7CCB8676491BF950B57] Akamai Technologies, Inc.
[18145C69C9F7740A0F1400AC622792C9] LINE Corporation
[859C3C109F85150D76DA60482FEAC3F2] Visan Industries
[8A9D646284BED4247484963FA9F3EA02] Visan Industries
[8479DC46E9A09015C0777A16BC22A15D] MICROSOFT WINDOWS
[FA19CFB97AA20A5E402EB6A5AC7E4295] MICROSOFT WINDOWS
[04A4541C92B70513EB8C883C9BC28C21] MICROSOFT WINDOWS
[6671A48C12AC9B113BC40246F86335EE] MICROSOFT WINDOWS
[FFA6791937150C8E49B2D4CCE6BA52DF] MICROSOFT WINDOWS
[1C52387BF5A127F5F3BFB31288F30D93] MICROSOFT WINDOWS
[FA6650A3F96CECD493FC11934D534FE6] MICROSOFT WINDOWS
[161CEB1A0A864F04C6BF789D83B83CDC] MICROSOFT WINDOWS
[1092B3190E69E0C5ECBCE90F171DE047] MICROSOFT WINDOWS
[DA56FFA46030E6FEB215E3D5DAA65B11] MICROSOFT WINDOWS
[8176FBA685178FB0F52D46693474FA50] MICROSOFT WINDOWS
[BE5A38071760E223CEEE9C8D9A0BFF9F] MICROSOFT WINDOWS
[552BF16E6398EDD8E320D70FE1DF8DF4] MICROSOFT WINDOWS
[854DA94B8CB68D74CB7480B2F426CA2A] MICROSOFT WINDOWS
[59E2D5DD885C5A06C16CD5E309A5060A] MICROSOFT WINDOWS
[5F540AD6674AEFD64C1051648FF87DE3] MICROSOFT WINDOWS
[448D8F8B51F785EAB56947D94EBDFC66] MICROSOFT WINDOWS
[F3A96882598EA84470646C6501917A98] MICROSOFT WINDOWS
[0D12F606DE18A5739AF27F12A32C6A6E] MICROSOFT WINDOWS
[8420491FFA891600A88FD12F5059A54C] MICROSOFT WINDOWS
[74B258D5896FC8F8256E8D03459AC2A2] MICROSOFT WINDOWS
[D72877D08AC821E3983C185D12034B19] MICROSOFT WINDOWS
[BBB22E224FC242E80DF2179A07066C82] MICROSOFT WINDOWS
[41C101B9BC1EAD38F886719C5652838F] MICROSOFT WINDOWS
[6A5C1EA6E0B31B168FDE21A1FDC078C2] MICROSOFT WINDOWS
[896B307E803430F67EC772807F9CC023] MICROSOFT WINDOWS
[4CD5B246B2DB81DC403B7C9041456B0E] MICROSOFT WINDOWS
[E5DFD54D2DAA70738F581D1AC74C09CD] MICROSOFT WINDOWS
[F916298AF3C6AC9887427E545C7E3A69] MICROSOFT WINDOWS
[E372BBF897005442ECEB7843CEB394D2] MICROSOFT WINDOWS
[4D8F3CEF04AFF366972ED6411DB2E0E0] MICROSOFT WINDOWS
[3FD5AE42EC87C6F532A931F96BE731DD] MICROSOFT WINDOWS
[1F1B8D07708E40E54C55B392C78ECCE2] MICROSOFT WINDOWS
[B4B610BBCB002EC478C6FD80CF915697] MICROSOFT WINDOWS
[2750EEB7440726085036BC746A095540] MICROSOFT WINDOWS
[1A811BAFA2114C2FC878507F9F86566C] MICROSOFT WINDOWS
[3BE05B2695179F8F3CF1136544E46A14] MICROSOFT WINDOWS
[7C94FDA3809015B8F2208D2E1C221F17] MICROSOFT WINDOWS
[218F874A78CB670172280A39A58B8F8A] MICROSOFT WINDOWS
[420070BF9D3967F4AF15FDEDDFF64C45] MICROSOFT WINDOWS
[B78C9FB3D92F4502079BB1F07470BE60] MICROSOFT WINDOWS
[B19CA8E441D35AA2B1EE51C10B27DA1B] MICROSOFT WINDOWS
[A91D8E1E433EFB32551BCE69037E1CE7] MICROSOFT WINDOWS
[706423B1B2C8F2237FD0F3822C8DC1C7] MICROSOFT WINDOWS
[C0DC3F58214A227980AEB091CFD2F973] MICROSOFT WINDOWS
[7E790DE2487CEDB349D1750B9E47F090] MICROSOFT WINDOWS
[8176FBA685178FB0F52D46693474FA50] MICROSOFT WINDOWS
[FBE385C73EF9C8117B7CE5C55370FBC8] MICROSOFT WINDOWS
[550076AD22A72FF2C28FE2B19FB64C12] MICROSOFT WINDOWS
[4903CBC14742B5AB4DCF7A92F7DEC483] MICROSOFT WINDOWS
[01E0A2E6263F48F4ED4FD2B96C8A3F8B] MICROSOFT WINDOWS
[86DD7884124D363A63CCE7A11FDEBBED] MICROSOFT WINDOWS
[74FD4F3D4CCF7E0AD040BE0F70D916A5] MICROSOFT WINDOWS
[BBE61A40665B83488901E41082A6097D] MICROSOFT WINDOWS
[ACC04CBB75086D86031E0C63D0930B98] MICROSOFT WINDOWS
[85948475C7FFCA1B7A825BB7BE9A5E72] MICROSOFT WINDOWS
[9276A1B1086F36169469F69DF36B10A3] MICROSOFT WINDOWS
[D528D6A92D187777691993DD757AF19A] MICROSOFT WINDOWS
[E5E48FEED73D463175EAB1542495191C] MICROSOFT WINDOWS
[A7E778F47D324BA986BF74DA1CD24F65] MICROSOFT WINDOWS
[F99300CAF66307E295438355E9B11ACD] MICROSOFT WINDOWS
[AB285CE3431FF3D2ACE669245874C1C7] MICROSOFT WINDOWS
[7F63629A60E6E1F12FA8D75B52CC17B2] MICROSOFT WINDOWS
[77CBFFA2358967D252D6A3794A262BBC] MICROSOFT WINDOWS
[0EFE4B5884A8032617826A4D76F80969] MICROSOFT WINDOWS
[936D9E2871CEEFF6A33695D98374367B] MICROSOFT WINDOWS
[77D62C92D05633D2F1EAA13C3FD7F325] Conexant Systems, Inc.
[0BC71D4D3B5883903C37BF4E13B0F0C5] MICROSOFT WINDOWS
[CD95892713570725F4CBBA99F07CDDF2] MICROSOFT WINDOWS
[B3D210DF0F057C53BB8817B96B2B3FC3] MICROSOFT WINDOWS
[F4CCAADC2C78F57E4F16B24C9201CE22] MICROSOFT WINDOWS
[5B074F14F5DD6418F46EE4CA2DEB7EA8] MICROSOFT WINDOWS
[A40B5232D325AC0200E73329F7F19F54] MICROSOFT WINDOWS
[521ED020A6708FECA2473AF00B73FC4D] MICROSOFT WINDOWS
[0EC96EC2D2D02649DCAD3D3C4E08A8DE] MICROSOFT WINDOWS
[0934499394EB3D8027B8AB78C07D56CB] MICROSOFT WINDOWS
[FBD2D7F491F3EBC5C54C5C4DB2564953] MICROSOFT WINDOWS
[50288EA079BB520C2B8C8A154202D518] MICROSOFT WINDOWS
[281BEE07BA97E3E98D12A822D923D0D8] MICROSOFT WINDOWS
[F734A794A0A047FCC6882A52CC22A553] MICROSOFT WINDOWS
[6E467BC0B40D7479516BA330DDA97B1D] MICROSOFT WINDOWS
[6C469C846EF4F256622C21A428E2E14E] MICROSOFT WINDOWS
[F7EDD1A5F067AF6BEF40AB7F738F610D] MICROSOFT WINDOWS
[1837EDFE746F910B0FFF4B86C2DB2B5E] MICROSOFT WINDOWS
[E1832BD9FD7E0FC2DC9FA5935DE3E8C1] MICROSOFT WINDOWS
[AD508A1A46EC21B740AB31C28EFDFDB1] MICROSOFT WINDOWS
[E19D921EBBD1A2CA4C48D7B5F1685B30] MICROSOFT WINDOWS
[AC8279D229398BCF05C3154ADCA86813] MICROSOFT WINDOWS
[A8970D9BF23CD309E0403978A1B58F3F] MICROSOFT WINDOWS
[111A89C99C5B4F1A7BCE5F643DD86F65] MICROSOFT WINDOWS
[5758387D68A20AE7D3245011B07E36E7] MICROSOFT WINDOWS
[7C1FDF1B48298CBA7CE4BDD4978951AD] MICROSOFT WINDOWS
[239268BAB58EAE9A3FF4E08334C00451] MICROSOFT WINDOWS
[B91EB769A3EB9F44BA7439451B7E1A7F] MICROSOFT WINDOWS
[7DFAEBA9AD62D20102B576D5CAC45EC8] MICROSOFT WINDOWS
[8E8E34B7BA059050EED827410D0697A2] MICROSOFT WINDOWS
[7589DE749DB6F71A68489DCE04158729] MICROSOFT WINDOWS
[B46D2D89AFF8A9490FA8C98C7A5616E3] MICROSOFT WINDOWS
[D2BF2F94A47D332814910FD47C6BBCD2] MICROSOFT WINDOWS
[A8E04943C7BBA7219AA50400272C3C6E] MICROSOFT WINDOWS
[CEA5F4F27CFC08E3A44D576811B35F50] MICROSOFT WINDOWS
[618F25E577FD7F1367CD24FD423D68A2] MICROSOFT WINDOWS
[BE3BFEFD0EDA6AA4C3A81B0490B1F7F5] MICROSOFT WINDOWS
[65045784366F7EC5FB4E71BCF923187B] MICROSOFT WINDOWS
[894D982CEAB8CD45A56AE2C9988E86C0] MICROSOFT WINDOWS
[01D911D09BD63E6CA76137F9655B18C5] MICROSOFT WINDOWS
[3DB7721F06BC2FEDB25029EA23AB27DA] MICROSOFT WINDOWS
[74B14192CF79A72F7536B27CB8814FBD] MICROSOFT WINDOWS
[BBE82125AC1E180DA7E3AF98AB4C0DA2] MICROSOFT WINDOWS
[8CC7F7E4AFCBA605921B137ED7992C68] MICROSOFT WINDOWS
[2748E116F8621A4DB0D39FCDD7318C01] MICROSOFT WINDOWS
[C1ABB0F7E3BEA48A0417BDF6FF14AB21] MICROSOFT WINDOWS
[6B4FFFDDC618FCF64473CAA86E305697] MICROSOFT WINDOWS
[4E888019078AC363076A5433E89AA4F8] MICROSOFT WINDOWS
[4AF7C20F94DAC343C01ED671C82DCB99] MICROSOFT WINDOWS
[785C38070043BEEE9E9D591DE4067244] MICROSOFT WINDOWS
[859A116D748FBA603AF94C251DC5CF97] MICROSOFT WINDOWS
[8434237E1EC39E85D8ACE6FA694A5733] MICROSOFT WINDOWS
[A8F23D453A424FF4DE04989C4727ECC7] MICROSOFT WINDOWS
[131F1C8573E7BFB41C54FBF5309CCD94] MICROSOFT WINDOWS
[746B9F94214915AECDE4B7FEA5FF9664] MICROSOFT WINDOWS
[71FE2A48E4C93DDB9798C024880B6C07] MICROSOFT WINDOWS
[FCD8BD17B7193CFFF18C332D1A381D7F] MICROSOFT WINDOWS
[07E33226AD218A2A162662A05CAFB52F] MICROSOFT WINDOWS
[3AFE71D80EDF5D4DE0C5731352905669] MICROSOFT WINDOWS
[8458ECAB701EE385851C2559B71D1209] MICROSOFT WINDOWS
[2C0B77176CD68F1F60510CDF36ADC401] MICROSOFT WINDOWS
[A4A73F631FE2AA2826FBE4A399B04DEF] MICROSOFT WINDOWS
[2FA6510E33F7DEFEC03658B74101A9B9] MICROSOFT WINDOWS
[C6796EA22B513E3457514D92DCDB1A3D] MICROSOFT WINDOWS
[BB1B91F57E1F9186BB42FD27F8A00D40] MICROSOFT WINDOWS
[BE9936EDD3267FAAFF94A7835867F00B] MICROSOFT WINDOWS
[7F006813C2AFE622C13D7AF94F56CD07] MICROSOFT WINDOWS
[EF6EF85DADC3184A10D8F2F7159973CB] MICROSOFT WINDOWS
[825BE21E6395E00698D8A23955A87972] MICROSOFT WINDOWS
[03AAED827C36F35D70900558B8274905] MICROSOFT WINDOWS
[A1FF7DFBFBE164CF92603C651D304DD2] MICROSOFT WINDOWS
[EE2F3C0D6ADBC975D6B621EC15ACF4E2] MICROSOFT WINDOWS
[315BA4BC19316D72B2E037534E048B93] MICROSOFT WINDOWS
[5DB26D7E0216D0BF364A81D3829AD7B9] MICROSOFT WINDOWS
[4D40C9B33F738797CF50E77CB7C53E85] MICROSOFT WINDOWS
[EB70A894708D1BC176AFD690FF06085F] MICROSOFT WINDOWS
[3E8D052C6DB66F9CCCB74BD2745122C4] MICROSOFT WINDOWS
[EA2498A29131E284CF1F9609BB4A44F4] MICROSOFT WINDOWS
[DDC11A202207C0400CBE07315B8FDE5E] MICROSOFT WINDOWS
[5A5C2A5D961CADF49DDE26582B8ED1FA] MICROSOFT WINDOWS
[43531A5993380CC5113242C29D265FD9] MICROSOFT WINDOWS
[6F8E738A9505A388B1157FDDE7B3101B] MICROSOFT WINDOWS
[DFFFAE1442BA4076E18EED5E406FA0D3] MICROSOFT WINDOWS
[114BCFDF367FF37C3F1B0A96AF542E4D] MICROSOFT WINDOWS
[5D8402613E778B3BD45E687A8372710B] MICROSOFT WINDOWS
[957A7A8F5ACCAF23DD9DFF6DAA393CE5] MICROSOFT WINDOWS
[A1A66C4FDAFD6B0289523232AFB7D8AF] MICROSOFT WINDOWS
[BE743083CF7063C486A4398E3AEFE59A] MICROSOFT WINDOWS
[60D5067FCE6D9433D35E04C01D8538B3] MICROSOFT WINDOWS
[35005534E600E993A90B036E4E599F2B] MICROSOFT WINDOWS
[818CF11786B2FA424E33A49E2CB79CC9] MICROSOFT WINDOWS
[9591D0B9351ED489EAFD9D1CE52A8015] MICROSOFT WINDOWS
[FC3EF65EE20D39F8749C2218DBA681CA] MICROSOFT WINDOWS
[03909BDBFF0DCACCABF2B2D4ADEE44DC] MICROSOFT WINDOWS
[56F69F7C25FB67C970997D7066DBC593] MICROSOFT WINDOWS
[10A70BC1871CD955D85CD88372724906] MICROSOFT WINDOWS
[1EA1B4FABB8CC348E73CA90DBA22E104] MICROSOFT WINDOWS
[C241A8BAFBBFC90176EA0F5240EACC17] MICROSOFT WINDOWS
[9BDDEE26255421017E161CCB9D5EDA95] MICROSOFT WINDOWS
[F31397220D9687E11EB448649AA6E038] MICROSOFT WINDOWS
[A6AACEA4C785789BDA5912AD1FEDA80D] MICROSOFT WINDOWS
[3502776E366C913D49C0DA928AE3E6CB] MICROSOFT WINDOWS
[90656C0B3864804B090434EFC582404F] MICROSOFT WINDOWS
[6D6F9E3BF0484967E52F7E846BFF1CA1] MICROSOFT WINDOWS
[907C870F8C31F8DDD6F090857B46AB25] MICROSOFT WINDOWS
[84CFC5EFA97D0C965EDE1D56F116A541] MICROSOFT WINDOWS
[5D90E32E36CE5D4C535D17CE08AEAF05] MICROSOFT WINDOWS
[DD05E7E80F52ADE9AEB292819920F32C] MICROSOFT WINDOWS
[E5A15FEDEBDFB8E12CB94DBF01833775] MICROSOFT WINDOWS
[08BFE413B0B4AA8DFA4B5684CE06D3DC] MICROSOFT WINDOWS
[A2200C3033FA4EF249FC096A7A7D02A2] MICROSOFT WINDOWS
[142CFBE6ED0E498CCA7ABE8DD932C1AF] MICROSOFT WINDOWS
[8E4044C6B71B2F837166F6EDB6BF9100] MICROSOFT WINDOWS
[F0F581A2299CB2BAB1DF2597BCDDB80F] MICROSOFT WINDOWS
[4E448FCFFD00E8D657CD9E48D3E47157] MICROSOFT WINDOWS
[647CF2AB16D2A23F1C441A313BC39820] MICROSOFT WINDOWS
[47E74A8E53C7C24DCE38311E1451C1D9] MICROSOFT WINDOWS
[9DB76D7F9E4E53EFE5DD8C53DE837514] MICROSOFT WINDOWS
[9949A3C7590B8C536C05312205079A82] MICROSOFT WINDOWS
[0063040EFD7C5B81D67CF985BA35388A] MICROSOFT WINDOWS
[AE44C526AB5F8A487D941CEB57B10C97] MICROSOFT WINDOWS
[8AFEEA3955AA43616A60F133B1D25F21] MICROSOFT WINDOWS
[C2BC9AC9C6514230A481BDCA6A24BEFD] MICROSOFT WINDOWS
[8BE92376799B6B44D543E8D07CDCF885] MICROSOFT WINDOWS
[FB6E47E569D4872ABEB506BE03A45FBA] MICROSOFT WINDOWS
[6C6F4A5FC5A2343995D1B0F111D5CF06] MICROSOFT WINDOWS
[DB7A09BC90DF20F44F16F8B0F9ED3491] MICROSOFT WINDOWS
[813871C7D402A05F2E3A7075F9584A05] MICROSOFT WINDOWS
[0AD1DF5AF3E1AEE66583F9718E892B50] MICROSOFT WINDOWS
[7296EA420134EAC390798B3232D066A4] MICROSOFT WINDOWS
[11AFB527AA370B1DAFD5C36F35F6D45F] MICROSOFT WINDOWS
[C09010B3680860131631F53E8FE7BAD8] MICROSOFT WINDOWS
[C755AE4635457AA2A11F79C0DF857ABC] MICROSOFT WINDOWS
[ADAC09CBE7A2040B7F68B5E5C9A75141] MICROSOFT WINDOWS
[04D1274BB9BBCCF12BD12374002AA191] MICROSOFT WINDOWS
[327469EEF3833D0C584B7E88A76AEC0C] MICROSOFT WINDOWS
[5EF604B0698F4FA962778285E8C5F1F2] MICROSOFT WINDOWS
[EB5C03A070F30D64A6DF80E53B22F53F] MICROSOFT WINDOWS
[F6F13533196DE7A582D422B0241E4363] MICROSOFT WINDOWS
[8B38C44F69259987C95135C9627E2378] MICROSOFT WINDOWS
[601589000CC90F0DF8DA2CC254A3CCC9] MICROSOFT WINDOWS
[CEAC6D40FE887CE8406C2393CF97DE06] MICROSOFT WINDOWS
[02D98BF804084E9A0D69D1C69B02CCA9] MICROSOFT WINDOWS
[515549560D481138E6E21AF7C6998E56] MICROSOFT WINDOWS
[F170510BE94CF45E3C6274578F6204B2] MICROSOFT WINDOWS
[59DCEC7499095DE5AED741358037AE2D] MICROSOFT WINDOWS
[405A2E5754DF76663CF0522B87D7929F] MICROSOFT WINDOWS
[295771B092D4F7FCF2B62F80CCD14320] MICROSOFT WINDOWS
[FFC548EABBB8271E979B0EEE0EA4D55B] MICROSOFT WINDOWS
[FDA72810CA2F8409D9B31E833C448E34] MICROSOFT WINDOWS
[C6B474E46F9E543B875981ED3FFE6ADD] MICROSOFT WINDOWS
[65C92EB9D08DB5C69F28C7FFD4E84E31] MICROSOFT WINDOWS
[52299F086AC2DAFD100DD5DC4A8614BA] MICROSOFT WINDOWS
[36D92AF3343C3A3E57FEF11C449AEA4C] MICROSOFT WINDOWS
[034D4BD9DC67C64F3A4C8A049B5173BF] MICROSOFT WINDOWS
[A9BBBD2BAE6142253B9195E949AC2E8D] MICROSOFT WINDOWS
[375E44168F2DFB91A68B8A3F619C5A7C] MICROSOFT WINDOWS
[7B2128EB875DCBC006E6A913211006D6] MICROSOFT WINDOWS
[1E88171579B218115C7A772F8DE04BD8] MICROSOFT WINDOWS
[8D6B7D515C5CBCDB75B928A0B73C3C5E] MICROSOFT WINDOWS
[115019AE01E0EB9C048530D2928AB4A2] MICROSOFT WINDOWS
[96D604A35070360F0DD4A7A8AF410B5E] MICROSOFT WINDOWS
[619CA29326B82372621DB2C0964D8365] MICROSOFT WINDOWS
[B8C35C94DCB2DFEAF03BB42131F2F77F] MICROSOFT WINDOWS
[424B0796F85BB0DADD4438EAFFADA133] MICROSOFT WINDOWS
[C6BB12BC35D1637CA17AE16D3A4725EB] MICROSOFT WINDOWS
[9F1DA20E943BE7AA4ED5F3E1EBA78B37] MICROSOFT WINDOWS
[9423421E735BD5394351E0C47C76BB92] MICROSOFT WINDOWS
[B832B35055BA2B7B4181861FF94D8E59] MICROSOFT WINDOWS
[1F58E48EF75F34C35D8E93A0DC535CFE] MICROSOFT WINDOWS
[DEC29080202D4F9F17F55E18BCFCC41A] MICROSOFT WINDOWS
[5A072F0B90C29C5233D78BE33EF5ED78] MICROSOFT WINDOWS
[A83D67D347A684F10B7D3019C8A6380C] MICROSOFT WINDOWS
[0217532E19A748F0E5D569307363D5FD] MICROSOFT WINDOWS
[70414DB660BFBB7BD58FCE8EA4364E1B] MICROSOFT WINDOWS
[351533ACC2A069B94E80BBFC177E8FDF] CACE Technologies, Inc.
[CBDB4F0871C88DF930FC0E8588CA67FC] MICROSOFT WINDOWS
[E490B459978CB87779E84C761D22B827] MICROSOFT WINDOWS
[6934A936A7369DFE37B7DBA93F5E5E49] MICROSOFT WINDOWS
[EEA11D0AED5C40A6C926B21CEC53EE65] MICROSOFT WINDOWS
[BC6B5942AFF25EBAF62DE43C3807EDF8] MICROSOFT WINDOWS
[1F43ABFFAC3D6CA356851D517392966E] MICROSOFT WINDOWS
[869055F61568AA08E7DEE95EC82ED653] MICROSOFT WINDOWS
[8528BB05E4D4E25945F78B00B2555FB7] MICROSOFT WINDOWS
[764B1121867B2D9B31C491668AC72B2B] MICROSOFT WINDOWS
[032F1C32A6A97C317AEFF9D64D2A1D8A] GREATIS SOFTWARE LLC
[EF0C1749C9A8CEE9A457473D433CC00F] MICROSOFT WINDOWS
[C0D3F3BC1C84B4BA746D9847314C1164] MICROSOFT WINDOWS
[346E38FCC6859A727DD28AFAD1F0AFF4] MICROSOFT WINDOWS
[4D3BDCC1C7B40C9D7B6AD990E6DEC397] MICROSOFT WINDOWS
[BF28771D1436C88BE1D297D3098B0F7D] MICROSOFT WINDOWS
[28AAACD3B871305F07188A0DB366B439] MICROSOFT WINDOWS
[BA50CC0BD19004AAB88BE37338B6FA0D] MICROSOFT WINDOWS
[ECD373F9571C745894367CC2635EA44F] MICROSOFT WINDOWS
[3FB466684609A4329858CF2EBD62E0FD] MICROSOFT WINDOWS
[2C56F0EE27E4EF70CA4B4983D3638905] MICROSOFT WINDOWS
[BBB6272B7F46C4640A8CDB8A70C3450F] MICROSOFT WINDOWS
[5247F308C4103CDC4FE12AE1D235800A] MICROSOFT WINDOWS
[E075CC071022BD4E9BE7C024717C0E0A] MICROSOFT WINDOWS
[2B0F1677CDD08967005F34488559BC6F] MICROSOFT WINDOWS
[B939A2A0F9D6C6C186721E268EB6FA93] MICROSOFT WINDOWS
[6B21EBF892CD8CACB71669B35AB5DE32] MICROSOFT WINDOWS
[680C1DAE268B6FB67FA21B389A8B79EF] MICROSOFT WINDOWS
[858776908AF838E3790F3261B799CDA6] MICROSOFT WINDOWS
[2C915EFFF23EA65D1E760FA397BCA6AB] MICROSOFT WINDOWS
[6D22E97C0390D736D220B03015A5569F] MICROSOFT WINDOWS
[2D05A5508F4685412F2B89E8C2189ABC] MICROSOFT WINDOWS
[D5C3918E3EF787A41172B8E5348247F0] MICROSOFT WINDOWS
[C624A1B32211C3166EDB3F4AB02A30B7] MICROSOFT WINDOWS
[ABD0237B15DBD2B4695F4B7D734A58F7] MICROSOFT WINDOWS
[C6A6F8921B94BC1673AC9AB485DF9A18] MICROSOFT WINDOWS
[4EAF4DCF9DBD9A56952A58F56D61C005] MICROSOFT WINDOWS
[DB2FF24CE0BDD15FE75870AFE312BA89] MICROSOFT WINDOWS
[53BDBF04ECAF943CBF6359E3BCB2445E] MICROSOFT WINDOWS
[3CD600C089C1251BEEB4CD4CD5164F9E] MICROSOFT WINDOWS
[D864381BC9C725FAB01D94C060660166] MICROSOFT WINDOWS
[0BD2B65DCE756FDE95A2E5CCCBF7705D] MICROSOFT WINDOWS
[472B7A5AC181C050888DB454663DD764] MICROSOFT WINDOWS
[2F518D13DD6F3053837FE606F1A2EA1F] MICROSOFT WINDOWS
[1AC9A200A9C49C4508F04AAFFCA34A3F] MICROSOFT WINDOWS
[349059B0C9EAED5A951D1693132A2EA8] MICROSOFT WINDOWS
[F337BE11071818FC3F5DC2940B6BDE34] MICROSOFT WINDOWS
[A15860E920B02C9A7CE8F3A6C2FF1E3A] Duplex Secure Ltd
[CD7534BA5BA92086B1BC10ADF880FC49] MICROSOFT WINDOWS
[59F15EFD74FDE8A1D9278F2C04F5D0B9] MICROSOFT WINDOWS
[96A7F9E8B3E0DD0355067D894C71A8F7] MICROSOFT WINDOWS
[9593475FBC857A05D93BFF4FA7323C2B] MICROSOFT WINDOWS
[592FF34A2FD6C6351B8A3AA76B2C0A9E] MICROSOFT WINDOWS
[76F7D7217FBDAB77798A2A244ACD641F] MICROSOFT WINDOWS
[366DEA74BBA65B362BCCFC6FC2ADFD8B] MICROSOFT WINDOWS
[0ED2E318ABB68C1A35A8B8038BDB4C90] MICROSOFT WINDOWS
[D57AEE34C7C0DD1DC8B6B54B7A89649C] MICROSOFT WINDOWS
[548759755BC73DAD663250239D7E0B9F] MICROSOFT WINDOWS
[03618F935379614837F915D04C45FC0E] MICROSOFT WINDOWS
[84E0F5D41C138C5CC975137A2A98F6D3] MICROSOFT WINDOWS
[C9436791C9DD3B5206DDBB1F75EE3E54] MICROSOFT WINDOWS
[33A7D83EEB15431773A6E186CFAABA21] MICROSOFT WINDOWS
[FFF28F9F6823EB1756C60F1649560BBF] MICROSOFT WINDOWS
[EB1D78140D6634C32A46AB1006105EDC] MICROSOFT WINDOWS
[232D185D2337F141311D0CF1983E1431] MICROSOFT WINDOWS
[82F909359600D3603FE852DB7F135626] MICROSOFT WINDOWS
[BF8F54CA37E9C9D6582C31C5761F8C93] MICROSOFT WINDOWS
[E0088068DCE2EE82897027DDB8E05254] MICROSOFT WINDOWS
[C8E0E78B5D284C2FF59BDFFDAF997242] MICROSOFT WINDOWS
[F6EEAD052943B5A3104C1405BB856C54] MICROSOFT WINDOWS
[FE6067B1FD4E63650C667B33D080565B] MICROSOFT WINDOWS
[5D1B430EA11064C56E7C8F84B90DEB6A] MICROSOFT WINDOWS
[1EC649F112896FAE33250F0B97AC5D0B] MICROSOFT WINDOWS
[9578691F297E1B1F519970FE6D47CB21] MICROSOFT WINDOWS
[5EAB5117DDB24FC4D39E6FFFCF1837B9] MICROSOFT WINDOWS
[DA34C39A18E60E7C3FA0630566408034] MICROSOFT WINDOWS
[643EF9E542EF1E438FBDF6A88235C50C] MICROSOFT WINDOWS
[AE8294875E5446E359B1E8035D40C05E] MICROSOFT WINDOWS
[734695C602E69F9DDBD29280D3E9E8BB] GREATIS SOFTWARE LLC
[F3F90825C416B264D016AA9D02C244C4] MICROSOFT WINDOWS
[3CAAB947B1F247A570DE15983BEDEBCF] MICROSOFT WINDOWS
[3432E857B8EC1C1316AB098F2BCCDFB6] MICROSOFT WINDOWS
[B3D6457D841A0CAEF4C52D88621715F2] MICROSOFT WINDOWS
[5477D6E27C7D266EF8C152B9A25ADE5E] MICROSOFT WINDOWS
[DF56C2C04EFA328D7A66B69007130266] MICROSOFT WINDOWS
[4475096DAB15E613A95D6A53F800B377] MICROSOFT WINDOWS
[3019097FB6C985EF24C058090FF3BDBD] MICROSOFT WINDOWS
[4D655E3B684BE9B0F7FFD8A2935C348C] MICROSOFT WINDOWS
[F04D164C4168701A4E7835607722E5F1] MICROSOFT WINDOWS
[B1230E9813B5C7E762DF27756AA23917] MICROSOFT WINDOWS
[BA4FA655E0FC577DB7436FC963932CE4] MICROSOFT WINDOWS
[18F744E8CCEB2670040EBAF7AD77B8C6] MICROSOFT WINDOWS
[BCD8FC0A47AA31889C94168A4E56BB26] MICROSOFT WINDOWS
[FEB26E3B8345A7E8D62F945C4AE86562] MICROSOFT WINDOWS
[2582B87082A935ACB76F949F760AF236] MICROSOFT WINDOWS
[041D3EF364E624DBB2703A64A5AADF89] MICROSOFT WINDOWS
[06D38968028E9AB19DE9B618C7B6D199] MICROSOFT WINDOWS
[3CE922E34DB12D9F3C0EA856BC09687C] MICROSOFT WINDOWS
[C6305BDFC4F7CE51F72BB072C03D4ACE] MICROSOFT WINDOWS
[DA40BEA0A863CE768C940CA9723BF81F] MICROSOFT WINDOWS
[68F8C26DEA2D42E8DEC0778943433C80] MICROSOFT WINDOWS
[0BF5CAD281E25F1418E5B8875DC5ADD1] MICROSOFT WINDOWS
[1A063730F221B2746FF00457AE17E4F0] MICROSOFT WINDOWS
[7A08CEE1535F5A448215634C5EA74E50] MICROSOFT WINDOWS
[55D7D963DE85162F1C49721E502F9744] MICROSOFT WINDOWS
[CCB9E901F7254BF96D28EB1B0E5329B7] MICROSOFT WINDOWS
[9F9CE33B50611A1C61A46B8911E0B30B] MICROSOFT WINDOWS
[01355C98B5C3ED1EC446743CDA848FCE] MICROSOFT WINDOWS
[ADBE96C33D1A5BB1BBAF90B4BC84F523] MICROSOFT WINDOWS
[4539F45F9F4C9757A86A56C949421E07] MICROSOFT WINDOWS
[0849B7260F26FE05EA56DED0672E2F4B] MICROSOFT WINDOWS
[BE970C369E43B509C1EDA2B8FA7CECB0] MICROSOFT WINDOWS
[6B26AD573CCDD5209DF4397438B76354] MICROSOFT WINDOWS
[0B48E0DFB44EE475F4FD8A8EE599AF30] MICROSOFT WINDOWS
[0910AB9ED404C1434E2D0376C2AD5D8B] MICROSOFT WINDOWS
[AFCD4054D61BD708B82991348ED1C763] MICROSOFT WINDOWS
[694B28DE12AD47031FFB4B052662131A] MICROSOFT WINDOWS
[CB6C63FF8342B467E2EF76E98D5B934D] MICROSOFT WINDOWS
[0B99529A3BECC3528D865DDECB62503B] MICROSOFT WINDOWS
[282E7D46310338FF4A6B7680440EB0DA] MICROSOFT WINDOWS
[011F431624366917180C904CE17FEA1A] MICROSOFT WINDOWS
[867BCC69ED9C31C501465EB0E8BA9DFA] MICROSOFT WINDOWS
[AC263C2F66405589528995AA41040599] MICROSOFT WINDOWS
[2834D9D3B4F554A39C72F00EA3F0E128] MICROSOFT WINDOWS
[E746BCDBA2E02CF6B8D6B26FB167FBE0] MICROSOFT WINDOWS
[9F2904B55F6CECCD1A8D986B5CE2609A] MICROSOFT WINDOWS
[AE072B0339D0A18E455DC21666CAD572] MICROSOFT WINDOWS
[2FEAE33E9B2B56104596E1BA444405A9] MICROSOFT WINDOWS
[19240C13F526125554B5370566F21A0A] MICROSOFT WINDOWS
[A1BECE49EF88F58F6DC881AF251B822E] MICROSOFT WINDOWS
[B4BBC6E4998042EF21437EED52EC0273] MICROSOFT WINDOWS
[6073537F250B45E1CB2A02E97F0FE1B2] MICROSOFT WINDOWS
[DDBF755EF92C0AB1F27C14A0D251F884] MICROSOFT WINDOWS
[6A5914B21D33A1CC4D294A696ADDB3E2] MICROSOFT WINDOWS
[CE85A6750D9C54DFAB2434854C9CF2B6] MICROSOFT WINDOWS
[030CE75B7D8F75FAA7BA1EC6FD0EB5A3] MICROSOFT WINDOWS
[CBCA90CF2ACE96038571ED0A7BD3D756] MICROSOFT WINDOWS
[04044091129B73C7BCF99B1CB842835F] MICROSOFT WINDOWS
[DC1A78BCCCB7EE53D6FD3BD615A8E222] MICROSOFT WINDOWS
[E5AD448F2DC84B1CF387FA7F2A3D1936] MICROSOFT WINDOWS
[0046E0BD031213D37123876B0D0FA61C] MICROSOFT WINDOWS
[183CA7699474FDE235853967D1DA4D9B] MICROSOFT WINDOWS
[EBD5D338F95EE156ECA6198E8FA378F3] MICROSOFT WINDOWS
[64362206C83D3C300E37267118D5936B] MICROSOFT WINDOWS
[2BC8532ABF2B3756B78FA1DA54147DDE] MICROSOFT WINDOWS
[48C163706383C7319DC1F8E9D135D68E] MICROSOFT WINDOWS
[2788CA31DD51CF747D9C94772CE93E02] MICROSOFT WINDOWS
[ECCEC3F904FFE5F8DB4C44F907C3A62F] MICROSOFT WINDOWS
[0BDE0FCF597E9B65600121EF54FF8340] MICROSOFT WINDOWS
[449A20A674AA3FAA7F0DD4E33EE2DC20] MICROSOFT WINDOWS
[EC464E8901BA5504CE72985B3A7D5E2F] MICROSOFT WINDOWS
[9067880BBB1C18703DBFF27D731D7ECA] MICROSOFT WINDOWS
[EC4455EEB36577D79D4D7653ECF306B5] MICROSOFT WINDOWS
[AC3158E78F44C8BB7463E4DBC454168F] MICROSOFT WINDOWS
[A368C3545420535B2CCE54D3D6649D49] MICROSOFT WINDOWS
[B119F4CB5C455FBD25B0BCF06095D341] MICROSOFT WINDOWS
[68D99E1CEB32DA0681481BC62FC1237F] MICROSOFT WINDOWS
[6D83B1A7CED08CFC3836FF51C14C3FA8] MICROSOFT WINDOWS
[F568467CD984714E1B849CA170358EC0] MICROSOFT WINDOWS
[DDD5B1A303EA579EFE2D5A4DE801E9AE] MICROSOFT WINDOWS
[BE0FC6BFE7181F8621B2BD572658A83E] MICROSOFT WINDOWS
[201EDF3C5E674BF1FE44D28CC6A76EA2] MICROSOFT WINDOWS
[08A08EC17F1874802A8BC6D083BF1C55] MICROSOFT WINDOWS
[C16097D77A232A288D65F299E2E01105] MICROSOFT WINDOWS
[810F8A0A0680662BB0CE44D0E2CEF90C] MICROSOFT WINDOWS
[6932138B1E9C1D9601F262EC696E419D] MICROSOFT WINDOWS
[D22AE5313F6B7EFDDD8C117B5501F4A3] MICROSOFT WINDOWS
[ECCE051BB49773BEE210B515669AFC6E] MICROSOFT WINDOWS
[7BF3ADCBD021D4F4A84CF40EB49C71B5] MICROSOFT WINDOWS
[AC63B7ABC65EA78BF50B981FD8C2E346] MICROSOFT WINDOWS
[6CD9C3819BE8C0A3DACC82AE5D3C4F18] MICROSOFT WINDOWS
[00E070FC0C673311AFD4B068D1242780] MICROSOFT WINDOWS
[D113FAD71A5E67AA94B32A0F8828D265] MICROSOFT WINDOWS
[E4B40D5609F2E5513E616F5BF9D32689] MICROSOFT WINDOWS
[E58B2EA7B004184E229854A3D1C00CBB] MICROSOFT WINDOWS
[21A02F14CD6D248C7B58B6D7AABA64F4] MICROSOFT WINDOWS
[5CAE8F47B31D5CFC322B5B898C19E0FE] MICROSOFT WINDOWS
[F6F209DDB94959BA104FC8FC87C53759] MICROSOFT WINDOWS
[B6B69FF200F68888A7FAFDF204D00C91] MICROSOFT WINDOWS
[B1AB8E24CD0902E867FD7867193CC44D] MICROSOFT WINDOWS
[277E2DF97D31B07F472DDFF3547D527D] MICROSOFT WINDOWS
[D72877D08AC821E3983C185D12034B19] MICROSOFT WINDOWS
[FD788C2D96EA91469A3C1D13E80D7473] MICROSOFT WINDOWS
[BFFB40FBE6D2C3469F8D06EE5E4934AB] MICROSOFT WINDOWS
[A46C1D6EE4BC27E8A767079CECCADE9E] MICROSOFT WINDOWS
[D186C5844393252147BE934F3871DB7A] MICROSOFT WINDOWS
[ADB4E145B99352A3058A6AB502BB99A1] MICROSOFT WINDOWS
[865F786E086BD42E73A218B62E6C5D88] MICROSOFT WINDOWS
[2A857CCAFE18B1D396484AC9CC0B9B80] MICROSOFT WINDOWS
[A082C17D14D0790E27D064EA4B138AE1] MICROSOFT WINDOWS
[32B1A8351160F307A8C66BCB0F94A9C2] MICROSOFT WINDOWS
[418BED8C46E60ECD929CAEA147ADC928] MICROSOFT WINDOWS
[4F3A00DC17C0B02DD69A7F2C079EE967] MICROSOFT WINDOWS
[E81D2F5C9CEC6DFBEFDA510CF4C70DA4] MICROSOFT WINDOWS
[50DAB9E7E976BD7FF5F25B83440606AA] MICROSOFT WINDOWS
[C26803E3870D2587FBB1CA0F26C29B31] MICROSOFT WINDOWS
[DC961E92BF50783FB89EFE3CCAB785B4] MICROSOFT WINDOWS
[86B5C163A3A0E1A9841ED04012E2C109] MICROSOFT WINDOWS
[6ECE4FEEC0FEAF9AB55A8B37EA6207CC] MICROSOFT WINDOWS
[F61A7B0E8F1C7C0B800E51E9CA6FC5F0] MICROSOFT WINDOWS
[F23063BEA95D08C0077F69EFBB45F4C0] MICROSOFT WINDOWS
[A230BE9C954935719EFF45DFBF86E3EA] MICROSOFT WINDOWS
[923FB63EAA4CAE2EEE8AFA409CBA1D06] MICROSOFT WINDOWS
[71E3C0100AA19D11373CCEB2F51A6008] MICROSOFT WINDOWS
[51DF09CAB2CAC64FEE3E371D9028ED01] MICROSOFT WINDOWS
[2586C4C167499210DCBF3ECFD8CCE210] MICROSOFT WINDOWS
[E01B8CE6646E055D2B806AE4DD5A1202] MICROSOFT WINDOWS
[B7AD851A21FEBA3BA214972627614207] MICROSOFT WINDOWS
[F0F0A372C2EF6358399C4936F91B6131] MICROSOFT WINDOWS
[3A280F3B3C7A46E29C404ACD46ECBF5E] MICROSOFT WINDOWS
[24DA05ADE2A978E199875DA0D859E7EB] Microsoft Windows
[6E2271ED0C3E95B8E29F3752B91B9E84] MICROSOFT WINDOWS
[F611E6125B86F2CFB6D2C6A4F98E487A] MICROSOFT WINDOWS
[0F7C0962499DA2F817F91B7269ECE56D] MICROSOFT WINDOWS
[2BB3DB931BA3FDEA48044E33C1CD4569] MICROSOFT WINDOWS
[79D473EA26DBD029DBF21DDB83F7552B] NVIDIA CORPORATION
[2A57A937BC5B1B2D6AFE6A8C5925F50B] MICROSOFT WINDOWS
[0BDB5190B3AFAEFF93800F149781F942] MICROSOFT WINDOWS
[E8283AF4E98903470B391F24C01ABA03] MICROSOFT WINDOWS
[38A31075D9630062AD7E26C97033CCC7] MICROSOFT WINDOWS
[339DC84D10960038320625CA52E4C843] MICROSOFT WINDOWS
[FE05B89D609EC317F106E615F14BAFAF] MICROSOFT WINDOWS
[065C787060A095DD0DF8358BC7EF4070] MICROSOFT WINDOWS
[028A102C4473D3F53D5D727F05AE3B5D] MICROSOFT WINDOWS
[928061178CD9856CA6B67FFFCE6BA766] MICROSOFT WINDOWS
[3B510F20806B94E389784ED09DBD2111] MICROSOFT WINDOWS
[9E5A3A3B702ECB9E88AA07731F0E65EB] MICROSOFT WINDOWS
[1480A23374019528CF11B911E60E52AA] MICROSOFT WINDOWS
[BE5F89BAFBD4272D5A0C0A37B97865ED] MICROSOFT WINDOWS
[41A45D2A75494EABF2806EA051E00376] MICROSOFT WINDOWS
[15225081966C785A9192782401643FD4] MICROSOFT WINDOWS
[30C62CC33E024C3A9EC52201E304D288] MICROSOFT WINDOWS
[AF90BB44C99D6820BE52C9BBAA523283] MICROSOFT WINDOWS
[5F061AC45266841A2860C1858ED863B8] MICROSOFT WINDOWS
[BF3B17016764F20F9D28CF1A8DC210C0] MICROSOFT WINDOWS
[4DCCABE03D06955ED61BABBD8EF9F30F] MICROSOFT WINDOWS
[D894CBD7DA753C881EE8D5E33B583225] MICROSOFT WINDOWS
[CFCDAAA210D62B277A2183F62FEE068F] MICROSOFT WINDOWS
[3FD5AE42EC87C6F532A931F96BE731DD] MICROSOFT WINDOWS
[5B9273124588AB0F2E40AAEC9D3C62EC] MICROSOFT WINDOWS
[2F65C548322123B479616DFA8238770A] Microsoft Windows
[47C497FA4DDEA908633CAA60CEBE6805] MICROSOFT WINDOWS
[E76C4E98302AE39CC6FA5D20FC8B5438] MICROSOFT WINDOWS
[1F1B8D07708E40E54C55B392C78ECCE2] MICROSOFT WINDOWS
[7172D44ED18787964B43146863466672] MICROSOFT WINDOWS
[888A30EAB651502352C18745367FD179] MICROSOFT WINDOWS
[572D14ECE0B882AAC770E59B72977481] MICROSOFT WINDOWS
[79227C1E2225DE455F365B607A6D46FB] MICROSOFT WINDOWS
[D6021013D7C4E248AEB8BED12D3DCC88] MICROSOFT WINDOWS
[C49009F897BA4F2F4F31043663AA1485] MICROSOFT WINDOWS
[A88882E64BDC1D8E8D6E727B71CCCC53] MICROSOFT WINDOWS
[E66A7C8CE7ED22DED6DF1CA479FB4790] MICROSOFT WINDOWS
[438CFF94FC90A571389FE49CDC913E49] MICROSOFT WINDOWS
[50543966B5C2214A5157372BF77AF982] MICROSOFT WINDOWS
[52BDBD0FAD538597D85F689A298DE360] MICROSOFT WINDOWS
[0D190D8B4B20446BE6299AC734DFADF1] MICROSOFT WINDOWS
[587ACA15210D1B01FBF272E07A08F91A] MICROSOFT WINDOWS
[49EEB92DE930B8566EF615D600781DB4] MICROSOFT WINDOWS
[B7DB57A000D46D4DE75BC0C563E58072] MICROSOFT WINDOWS
[FE0CB40F36D3FCDD3A1B312EF72C38D5] MICROSOFT WINDOWS
[4F68F08D3AF5AAE315800338932AF042] MICROSOFT WINDOWS
[C376497571BE84191AE8103A04E6A8F8] MICROSOFT WINDOWS
[A173F70AED6B661FEB7A0272F07F0E1D] MICROSOFT WINDOWS
[310E6374F4B3E0E8B50CFB8AE3B76F76] MICROSOFT WINDOWS
[27B58E16CF895AC1F1A97C04814C2239] MICROSOFT WINDOWS
[BB9ED3EDD8E85008215A7250D325A72E] MICROSOFT WINDOWS
[3911418AFDE10EA6823B7799E4815524] MICROSOFT WINDOWS
[3118058E3D07021A55324A943C6D722B] MICROSOFT WINDOWS
[E4CA434F251681590D0538BC21C32D2F] MICROSOFT WINDOWS
[D8E1AE075AB3E8AD56F69C44AA978596] MICROSOFT WINDOWS
[A5DC2E63F5E5D3C0B843307374998479] MICROSOFT WINDOWS
[075A05D710F701B9D41AF5CB411A2A2F] MICROSOFT WINDOWS
[BCECD25BCFFE2FC4498374BF2E572DBE] MICROSOFT WINDOWS
[A6DB9DCC34A9EFF0EAECF1978B84C5A2] MICROSOFT WINDOWS
[3C2B9C8EA210F014563BF6391596D8F7] MICROSOFT WINDOWS
[373382005ACB27CB16ED16722FBE946A] MICROSOFT WINDOWS
[0F00B4C00F8F0674892EB31D5D24F8F1] MICROSOFT WINDOWS
[BA6DD39266A5E15515C8C14DA2DA3E5C] MICROSOFT WINDOWS
[B517410F157693043DACA21B19B258A6] MICROSOFT WINDOWS
[EDE582496D0CADEE35EA2B1076FF19A8] MICROSOFT WINDOWS
[40BD4960734B0FA0872AF71B1E4314CE] MICROSOFT WINDOWS
[70179FFB5487A8A2BB4A1AB1B22219E6] MICROSOFT WINDOWS
[2C77831737491F4D684D315B95C62883] MICROSOFT WINDOWS
[05FBE1F7C13E87AF7A414CDF288B1F62] MICROSOFT WINDOWS
[347A3E49CE18402305B8119A6EC7CFEB] MICROSOFT WINDOWS
[616DF4ADC4E04753BB4951D3464B8157] MICROSOFT WINDOWS
[C97E14BB6A196B0554D6EB67D8818175] MICROSOFT WINDOWS
[0BAF086D41F4AE011EB14EDE92A3D00E] MICROSOFT WINDOWS
[28AB6EFCBA8D298A284CF3279171E443] MICROSOFT WINDOWS
[13F844C253486BCB2ADE05ED3E2E4993] MICROSOFT WINDOWS
[320878AFECDBBD61BBE98624A6CAAC08] MICROSOFT WINDOWS
[084FFAFC9796DD43BD8FD854673E3132] MICROSOFT WINDOWS
[752A457320A946E03C3AA86C3ACD735E] MICROSOFT WINDOWS
[00E08B30E7F7C13ECE2CDF4F46A77311] MICROSOFT WINDOWS
[E3DDF7D43E05784FAA5E042605EEE528] MICROSOFT WINDOWS
[E234DBE3B155D5F7CFD77B814D592E79] MICROSOFT WINDOWS
[4A2FFDAC45F317E17DF642C7160EB633] MICROSOFT WINDOWS
[9BE4639FD1A3F8A9FECFE958D7B04F9A] MICROSOFT WINDOWS
[D2F749A01019A5A50716BA14EE714342] MICROSOFT WINDOWS
[1A811BAFA2114C2FC878507F9F86566C] MICROSOFT WINDOWS
[64E2C7176D189E4A838D04F7C724CAE7] MICROSOFT WINDOWS
[08C191B2917862BE90C33E31CB6B6D79] MICROSOFT WINDOWS
[81DAC9F3309A51C041545AF760CFDF06] MICROSOFT WINDOWS
[CFBAD6B48EDFAA0828A52646B7C4C08D] MICROSOFT WINDOWS
[5A6EAE44508C4C604A31E4AC37F2D758] MICROSOFT WINDOWS
[D51D7EF1EA5ED2BB01E9D07E6E0533BC] MICROSOFT WINDOWS
[7599E582CA3A6AAA95A18FFE1172D339] MICROSOFT WINDOWS
[C510810D292782189F8BE12A1B0E366E] MICROSOFT WINDOWS
[EB83C257C95F2E00D92F9432C849E712] MICROSOFT WINDOWS
[69D81B5403B913369B4A694CD2F42744] MICROSOFT WINDOWS
[7AFAC828F52D62F304A911EC32F42EEE] MICROSOFT WINDOWS
[CE6D08350D0A1278E9A97D94023D1800] MICROSOFT WINDOWS
[9DB490F3E823C5C3C070644B96CB9D59] MICROSOFT WINDOWS
[92BF4B3EBD6F163B94B7A20C65E7B698] MICROSOFT WINDOWS
[CE9E5A541CB4203B4930CE89766D4E5C] MICROSOFT WINDOWS
[5A619483E21DAAF186DF23270D226A7D] MICROSOFT WINDOWS
[8AF411E94155BF44DD4E878B42AA455B] MICROSOFT WINDOWS
[846C02A8B48CBD921A3D6AB521AA0DC4] MICROSOFT WINDOWS
[40C67D1A4891120874767F6E6604D6C5] MICROSOFT WINDOWS
[D199A538404FB72FC0AB036595D20E1F] MICROSOFT WINDOWS
[6588A957873326361AB1CAC4E76F8394] MICROSOFT WINDOWS
[3274312F263882B51B964329FAF49734] MICROSOFT WINDOWS
[7CDD84E0023A0C5C230B06A7965EC65E] MICROSOFT WINDOWS
[A188CA36B475624E547C750EE8616376] MICROSOFT WINDOWS
[AA1315B87D9B2E39584165318A59F15D] MICROSOFT WINDOWS
[22B4C24AB921BFF7827FFBCA1F4E1BB3] MICROSOFT WINDOWS
[E06AFE2F94BA7CFA2FE4FD2A449E60E2] MICROSOFT WINDOWS
[D638904FE86A5FE542A1BA13A9D68E5C] MICROSOFT WINDOWS
[EB1910FCBC61A478E07FCB59487B56AD] MICROSOFT WINDOWS
[DD079EC8F44DCA3A176B345C6ADEFB66] MICROSOFT WINDOWS
[48CFA7BE561A7BE144C29BB912055016] MICROSOFT WINDOWS
[7C94FDA3809015B8F2208D2E1C221F17] MICROSOFT WINDOWS
[DA3AC70D35B1283A37821624215A49FE] MICROSOFT WINDOWS
[599F1244C60E3D6C28A8DA7FBA7A2C13] MICROSOFT WINDOWS
[D0D9C2ECA4D03A8F06DCD91236B90C98] MICROSOFT WINDOWS
[191294664E1397B5B0C95218A545250F] MICROSOFT WINDOWS
[02A13DB2D44B17A1C37769246694C7CD] MICROSOFT WINDOWS
[A1314F0CD51E8F7CF613A17D8B0724F7] MICROSOFT WINDOWS
[4E6A0F60DA7EF050D3D26417CD4D24E9] MICROSOFT WINDOWS
[D27491CFCE452C154CECFA155AD0EBC8] MICROSOFT WINDOWS
[C15B3FE9B7AB65A984B7BFD1382DE43E] MICROSOFT WINDOWS
[5CFA46C4ACB2FD70572017052378DAE5] MICROSOFT WINDOWS
[48B5A62750FC3E3E8733106FB7E2DF0F] MICROSOFT WINDOWS
[F011F1F2CF1701374A361EB1E74B4289] MICROSOFT WINDOWS
[2B659DAB8F020252FF862AA2692B33CA] MICROSOFT WINDOWS
[690C3FC5C9DBD6B9AEDF8341EC720E41] MICROSOFT WINDOWS
[DD988D37D33574D02642E528C8CD8808] MICROSOFT WINDOWS
[B957B92C79A4CD138D5CFF1D20A9CF7B] MICROSOFT WINDOWS
[BB73CBC65AABC4EA0A5C6A1474A0A743] MICROSOFT WINDOWS
[2FA9794CA36147756F3FDFD6CA29B46F] MICROSOFT WINDOWS
[5430FA34D2FDA83ED1DBC43A8D516E31] MICROSOFT WINDOWS
[6E21307B8E6C88C12E4DD11A62C8EBFE] MICROSOFT WINDOWS
[9AE11282C83784273732ED155BC9FF4A] MICROSOFT WINDOWS
[3FEEBF51CFDBFB4CD30093609888DCEB] MICROSOFT WINDOWS
[04EE1AD7E9277EC632C390DFEECF4C11] MICROSOFT WINDOWS
[335ECC1529062E7E7428F30C891B1B76] MICROSOFT WINDOWS
[28853B76503048E818E3B143B8C2860B] MICROSOFT WINDOWS
[6109EEADA1F9D2B971C7EA668A58D768] MICROSOFT WINDOWS
[414899B223DC3888BCA6D81CBBB05080] ADOBE SYSTEMS INCORPORATED
[73395776872F0EE6DA11F92BF6A7A874] ADOBE SYSTEMS INCORPORATED
[84F20198CAE435DE32ABDB4511550BD7] MICROSOFT WINDOWS
[F21C143173614345E97AC7932ADD220C] MICROSOFT WINDOWS
[9618E4752B19CE24EFD729C662C8DB1E] MICROSOFT WINDOWS
[7EEC1F2A4F4D651BCB7263F69E15E5DA] MICROSOFT WINDOWS
[5B4FF009D24F73F6FC6EB4870A789843] MICROSOFT WINDOWS
[8DB30DA1FA8620A5C4AF53DEB85194D8] MICROSOFT WINDOWS
[F604350906CE4E3F67D81384566DE3E4] MICROSOFT WINDOWS
[0FC9B04C7F729498B41A19FA55C33573] MICROSOFT WINDOWS
[8E3C640FFF5A963F570233AE99C0FFF3] MICROSOFT WINDOWS
[4947B4C100BE88C83F027D1C8DBC4B84] MICROSOFT WINDOWS
[07D58D5F7839ABA76118BC037C2C63BD] Conexant Systems, Inc.
[4C99F942021C5F3741BCDD576F2FE435] MICROSOFT WINDOWS
[3E274E8A9403CCAF8FDDBF20E5AB944D] MICROSOFT WINDOWS
[8700883867FBD565BF6C2DAE8B2D7810] MICROSOFT WINDOWS
[D349F1E9D0388A78B6AE769F1450BA3E] MICROSOFT WINDOWS
===