Sie sind auf Seite 1von 128

SpyHolesList Version:10.6 Build:7.70.0.

170-64b
12.05.2016 12:25:25
WinDir=C:\Windows
Startup=C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Sta
rtup\
Common Startup=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Windows 7 Ultimate (6.1.7601)
Internet Explorer 9.11.9600.17041
[Internet Explorer]
[Default Home Page] :HKLM Default_Page_URL=http://www.google.com/
[Current Home Page] :HKCU Start Page=""
[Current Home Page] :HKCU HOMEOldSP=""
[Current Home Page] :HKCU Default_Page_URL=http://www.google.com/
[Current Home Page] :HKLM Start Page=http://www.google.com/
[Current Home Page] :HKLM HOMEOldSP=""
[All Users Search] :HKLM Default_Search_URL=www.google.com
[All Users Search] :HKLM Search Page=www.google.com
[Current Users Search] :HKCU Default_Search_URL=www.google.com
[Current Users Search] :HKCU Search Page=www.google.com
[Current Users Search] :HKCU Search Bar=""
[IE Local Blank Page] :HKCU Local Page=C:\Windows\system32\blank.htm
[IE Local Blank Page] :HKLM Local Page=C:\Windows\SysWOW64\blank.htm
[Browser Helper Objects] {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}=C:\PROGRAM FIL
ES (X86)\ADOBE\ACROBAT 7.0\ACTIVEX\ACROIEHELPER.DLL
### Adobe Acrobat IE Helper Version 7.0 for ActiveX Adobe Systems Incorporated
AcroIEHelper Library 7, 0, 0, 0
[Browser Helper Objects] {1F91A9A1-01BA-4c81-863D-3BA0751E1419}
### File is deleted or hidden by a rootkit or could not be located.
[Browser Helper Objects] {72853161-30C5-4D22-B7F9-0BBC1D38A37E}=C:\PROGRA~2\MI
CROS~1\OFFICE12\GR469A~1.DLL
### GrooveShellExtensions Module Microsoft Corporation GrooveShellExtensions M
odule 4.2.0.2623
[Browser Helper Objects] {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\PROGRAM FIL
ES (X86)\JAVA\JRE1.8.0_77\BIN\SSV.DLL
### Java(TM) Platform SE binary Oracle Corporation Java(TM) Platform SE 8 U77
8.0.770.3
[Browser Helper Objects] {AE7CD045-E861-484f-8273-0445EE161910}=C:\PROGRAM FIL
ES (X86)\ADOBE\ACROBAT 7.0\ACROBAT\ACROIEFAVCLIENT.DLL
### Adobe IE plugin Adobe Systems Incorporated Adobe IE plugin 7.0.0.0
[Browser Helper Objects] {CC59E0F9-7E43-44FA-9FAA-8377850BF205}=C:\PROGRAM FIL
ES (X86)\FREE DOWNLOAD MANAGER\IEFDM2.DLL
### FreeDownloadManager.ORG Free Download Manager 0.0.0.0
[Browser Helper Objects] {DBC80044-A445-435b-BC74-9C25C1C588A9}=C:\PROGRAM FIL
ES (X86)\JAVA\JRE1.8.0_77\BIN\JP2SSV.DLL
### Java(TM) Platform SE binary Oracle Corporation Java(TM) Platform SE 8 U77
8.0.770.3
[Auto Search URL] :HKCU provider=""
[Auto Search URL] :HKCU "Default Value"=""
[Search Assistant] :HKCU SearchAssistant=""
[Search Assistant] :HKLM SearchAssistant=""
[Search Assistant] :HKCU CustomizeSearch=""
[Search Assistant] :HKLM CustomizeSearch=""
[Search Provider] {0633EE93-D776-472f-A0FF-E1416B8B2E3A}=http://www.oursurfing
.com/web/?utm_source=b&utm_medium=2sq&utm_campaign=install_ie&utm_content=ds&fro
m=2sq&uid=ST2000DM001-1CH164_W1F5EHSDXXXXW1F5EHSD&ts=1439368115&type=default&q={
searchTerms}
### Bing
[Search Provider] {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0}=http://www.oursurfing
.com/web/?utm_source=b&utm_medium=2sq&utm_campaign=install_ie&utm_content=ds&fro
m=2sq&uid=ST2000DM001-1CH164_W1F5EHSDXXXXW1F5EHSD&ts=1439368115&type=default&q={

searchTerms}
### e
[Search Provider] {AF736ECA-4654-4BDD-AF19-2510C114C5D3}=http://www.oursurfing
.com/web/?utm_source=b&utm_medium=2sq&utm_campaign=install_ie&utm_content=ds&fro
m=2sq&uid=ST2000DM001-1CH164_W1F5EHSDXXXXW1F5EHSD&ts=1439368115&type=default&q={
searchTerms}
[Search Provider] {BB74DE59-BC4C-4172-9AC4-73315F71CFFE}=http://www.oursurfing
.com/web/?utm_source=b&utm_medium=2sq&utm_campaign=install_ie&utm_content=ds&fro
m=2sq&uid=ST2000DM001-1CH164_W1F5EHSDXXXXW1F5EHSD&ts=1439368115&type=default&q={
searchTerms}
[Search Provider] {BC23E1A1-0266-4668-86D8-BC4534B7BB2A}=http://www.oursurfing
.com/web/?utm_source=b&utm_medium=2sq&utm_campaign=install_ie&utm_content=ds&fro
m=2sq&uid=ST2000DM001-1CH164_W1F5EHSDXXXXW1F5EHSD&ts=1439368115&type=default&q={
searchTerms}
[Search Provider] {BDF61FAE-9D19-40F0-8F34-688DEB334CA9}=http://www.oursurfing
.com/web/?utm_source=b&utm_medium=2sq&utm_campaign=install_ie&utm_content=ds&fro
m=2sq&uid=ST2000DM001-1CH164_W1F5EHSDXXXXW1F5EHSD&ts=1439368115&type=default&q={
searchTerms}
### Ad-Aware SecureSearch
[Search Provider] {E733165D-CBCF-4FDA-883E-ADEF965B476C}=http://www.oursurfing
.com/web/?utm_source=b&utm_medium=2sq&utm_campaign=install_ie&utm_content=ds&fro
m=2sq&uid=ST2000DM001-1CH164_W1F5EHSDXXXXW1F5EHSD&ts=1439368115&type=default&q={
searchTerms}
### Google
[Search Provider] DefaultScope={0633EE93-D776-472f-A0FF-E1416B8B2E3A}
[Search Provider for All Users] {0633EE93-D776-472f-A0FF-E1416B8B2E3A}=http://
www.bing.com/search?q={searchTerms}&FORM=IE8SRC
### Bing
[Search Provider for All Users] {BB74DE59-BC4C-4172-9AC4-73315F71CFFE}=http://
websearch.toolksearchbook.info/?l=1&q={searchTerms}&pid=725&r=2014/01/15&hid=240
6902759796487476&lg=EN&cc=IN&unqvl=46
### WebSearch
[Search Provider for All Users] DefaultScope={BB82DE59-BC4C-4172-9AC4-73315F71
CFFE}
[Search Provider for All Users(x64)] {0633EE93-D776-472f-A0FF-E1416B8B2E3A}=ht
tp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
### Bing
[Search Provider for All Users(x64)] DefaultScope={33BB0A4E-99AF-4226-BDF6-491
20163DE86}
[Search Provider(x64)] {0633EE93-D776-472f-A0FF-E1416B8B2E3A}=http://www.oursu
rfing.com/web/?utm_source=b&utm_medium=2sq&utm_campaign=install_ie&utm_content=d
s&from=2sq&uid=ST2000DM001-1CH164_W1F5EHSDXXXXW1F5EHSD&ts=1439368115&type=defaul
t&q={searchTerms}
### Bing
[Search Provider(x64)] {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0}=http://www.oursu
rfing.com/web/?utm_source=b&utm_medium=2sq&utm_campaign=install_ie&utm_content=d
s&from=2sq&uid=ST2000DM001-1CH164_W1F5EHSDXXXXW1F5EHSD&ts=1439368115&type=defaul
t&q={searchTerms}
### e
[Search Provider(x64)] {AF736ECA-4654-4BDD-AF19-2510C114C5D3}=http://www.oursu
rfing.com/web/?utm_source=b&utm_medium=2sq&utm_campaign=install_ie&utm_content=d
s&from=2sq&uid=ST2000DM001-1CH164_W1F5EHSDXXXXW1F5EHSD&ts=1439368115&type=defaul
t&q={searchTerms}
[Search Provider(x64)] {BB74DE59-BC4C-4172-9AC4-73315F71CFFE}=http://www.oursu
rfing.com/web/?utm_source=b&utm_medium=2sq&utm_campaign=install_ie&utm_content=d
s&from=2sq&uid=ST2000DM001-1CH164_W1F5EHSDXXXXW1F5EHSD&ts=1439368115&type=defaul
t&q={searchTerms}
[Search Provider(x64)] {BC23E1A1-0266-4668-86D8-BC4534B7BB2A}=http://www.oursu
rfing.com/web/?utm_source=b&utm_medium=2sq&utm_campaign=install_ie&utm_content=d
s&from=2sq&uid=ST2000DM001-1CH164_W1F5EHSDXXXXW1F5EHSD&ts=1439368115&type=defaul

t&q={searchTerms}
[Search Provider(x64)] {BDF61FAE-9D19-40F0-8F34-688DEB334CA9}=http://www.oursu
rfing.com/web/?utm_source=b&utm_medium=2sq&utm_campaign=install_ie&utm_content=d
s&from=2sq&uid=ST2000DM001-1CH164_W1F5EHSDXXXXW1F5EHSD&ts=1439368115&type=defaul
t&q={searchTerms}
### Ad-Aware SecureSearch
[Search Provider(x64)] {E733165D-CBCF-4FDA-883E-ADEF965B476C}=http://www.oursu
rfing.com/web/?utm_source=b&utm_medium=2sq&utm_campaign=install_ie&utm_content=d
s&from=2sq&uid=ST2000DM001-1CH164_W1F5EHSDXXXXW1F5EHSD&ts=1439368115&type=defaul
t&q={searchTerms}
### Google
[Search Provider(x64)] DefaultScope={0633EE93-D776-472f-A0FF-E1416B8B2E3A}
[CustomizeSearch] :HKLM CustomizeSearch=""
[URLSearchHook] :HKCU {CFBFAE00-17A6-11D0-99CB-00C04FD64497}=C:\WINDOWS\SYSWOW
64\IEFRAME.DLL
### Internet Browser Microsoft Corporation Internet Explorer 11.00.9600.17041
[Search URL Template] :HKLM 1=""
[Search URL Template] :HKLM 2=""
[Search URL Template] :HKLM 3=""
[Search URL Template] :HKLM 4=""
[Default Prefix] :HKLM "Default Value"=http://
[URL Default Prefixes] :HKLM mosaic=http://
[URL Default Prefixes] :HKLM www=http://
[URL Default Prefixes] :HKLM home=http://
[URL Default Prefixes] :HKLM ftp=ftp://
[AboutURLs] :HKLM blank=res://mshtml.dll/blank.htm
[AboutURLs] :HKLM NoAdd-onsInfo=res://ieframe.dll/noaddoninfo.htm
[AboutURLs] :HKLM InPrivate=res://ieframe.dll/inprivate_win7.htm
[AboutURLs] :HKLM NavigationFailure=res://ieframe.dll/navcancl.htm
[AboutURLs] :HKLM NoAdd-ons=res://ieframe.dll/noaddon.htm
[AboutURLs] :HKLM Home=270
[AboutURLs] :HKLM PostNotCached=res://ieframe.dll/repost.htm
[AboutURLs] :HKLM DesktopItemNavigationFailure=res://ieframe.dll/navcancl.htm
[AboutURLs] :HKLM NavigationCanceled=res://ieframe.dll/navcancl.htm
[AboutURLs] :HKLM SecurityRisk=res://ieframe.dll/securityatrisk.htm
[User Style Sheet] :HKCU User Stylesheet=""
[User Style Sheet] :HKCU Use My Stylesheet=0
[Execute unsigned ActiveX in My Computer Zone] :HKCU 1201=0
[Execute unsigned ActiveX in My Computer Zone] :HKLM 1201=1
[Execute unsigned ActiveX in Local Intranet Zone] :HKCU 1201=1
[Execute unsigned ActiveX in Local Intranet Zone] :HKLM 1201=3
[Execute unsigned ActiveX in Internet Zone] :HKCU 1201=3
[Execute unsigned ActiveX in Internet Zone] :HKLM 1201=3
[Links Toolbar] :HKCU LinksFolderName=""
[Toolbars] :HKLM {47833539-D0C5-4125-9FA8-0819E2EAAC93}=C:\PROGRAM FILES (X86)
\ADOBE\ACROBAT 7.0\ACROBAT\ACROIEFAVCLIENT.DLL
### Adobe IE plugin Adobe Systems Incorporated Adobe IE plugin 7.0.0.0
[Explorer Bars] :HKLM {182EC0BE-5110-49C8-A062-BEB1D02A220B}=C:\PROGRAM FILES
(X86)\ADOBE\ACROBAT 7.0\ACROBAT\ACROIEFAVCLIENT.DLL
### Adobe IE plugin Adobe Systems Incorporated Adobe IE plugin 7.0.0.0
[IE Extensions - All Users] :HKLM {2670000A-7350-4f3c-8081-5663EE0C6C49}
### File is deleted or hidden by a rootkit or could not be located.
[IE Extensions - All Users] :HKLM {92780B25-18CC-41C8-B9BE-3C9C571A8263}=C:\PR
OGRA~2\MICROS~1\OFFICE12\REFIEBAR.DLL
### Allows you to use the Research Library and its collection of information s
ervices from Microsoft Internet Explorer Microsoft Corporation Research Library
Explorer Bar 12.0.4518.1014
[Context menu items] :HKCU Convert link target to Adobe PDF=res://C:\Program F
iles (x86)\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
### File is deleted or hidden by a rootkit or could not be located.

[Context menu items] :HKCU Convert link target to existing PDF=res://C:\Progra


m Files (x86)\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
### File is deleted or hidden by a rootkit or could not be located.
[Context menu items] :HKCU Convert selected links to Adobe PDF=res://C:\Progra
m Files (x86)\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLink
s.html
### File is deleted or hidden by a rootkit or could not be located.
[Context menu items] :HKCU Convert selected links to existing PDF=res://C:\Pro
gram Files (x86)\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLi
nks.html
### File is deleted or hidden by a rootkit or could not be located.
[Context menu items] :HKCU Convert selection to Adobe PDF=res://C:\Program Fil
es (x86)\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
### File is deleted or hidden by a rootkit or could not be located.
[Context menu items] :HKCU Convert selection to existing PDF=res://C:\Program
Files (x86)\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
### File is deleted or hidden by a rootkit or could not be located.
[Context menu items] :HKCU Convert to Adobe PDF=res://C:\Program Files (x86)\A
dobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
### File is deleted or hidden by a rootkit or could not be located.
[Context menu items] :HKCU Convert to existing PDF=res://C:\Program Files (x86
)\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
### File is deleted or hidden by a rootkit or could not be located.
[Context menu items] :HKCU Download all with Free Download Manager=C:\PROGRAM
FILES (X86)\FREE DOWNLOAD MANAGER\DLALL.HTM
### file://C:\Program Files (x86)\Free Download Manager\dlall.htm
[Context menu items] :HKCU Download selected with Free Download Manager=C:\PRO
GRAM FILES (X86)\FREE DOWNLOAD MANAGER\DLSELECTED.HTM
### file://C:\Program Files (x86)\Free Download Manager\dlselected.htm
[Context menu items] :HKCU Download video with Free Download Manager=C:\PROGRA
M FILES (X86)\FREE DOWNLOAD MANAGER\DLFVIDEO.HTM
### file://C:\Program Files (x86)\Free Download Manager\dlfvideo.htm
[Context menu items] :HKCU Download with Free Download Manager=C:\PROGRAM FILE
S (X86)\FREE DOWNLOAD MANAGER\DLLINK.HTM
### file://C:\Program Files (x86)\Free Download Manager\dllink.htm
[Context menu items] :HKCU E&xport to Microsoft Excel=res://C:\PROGRA~2\MICROS
~1\Office12\EXCEL.EXE/3000
### File is deleted or hidden by a rootkit or could not be located.
[AutoConfigURL] :HKCU AutoConfigURL=http://www.searchly.org/proxy.pac
[Protocols Filter] :HKLM application/octet-stream=C:\Windows\system32\MSCOREE.
DLL
### Microsoft .NET Runtime Execution Engine Microsoft Corporation Microsoft .NE
T Framework 4.0.40305.0 mscoree.dll
[Protocols Filter] :HKLM application/x-complus=C:\Windows\system32\MSCOREE.DLL
### Microsoft .NET Runtime Execution Engine Microsoft Corporation Microsoft .NE
T Framework 4.0.40305.0 mscoree.dll
[Protocols Filter] :HKLM application/x-msdownload=C:\Windows\system32\MSCOREE.
DLL
### Microsoft .NET Runtime Execution Engine Microsoft Corporation Microsoft .NE
T Framework 4.0.40305.0 mscoree.dll
[Protocols Filter] :HKLM text/xml=C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE12\MSOXM
LMF.DLL
### Microsoft Office XML MIME Filter Microsoft Corporation Microsoft Office In
foPath 12.0.4518.1014
[Protocols Handler] :HKLM about=C:\WINDOWS\SYSWOW64\MSHTML.DLL
### Microsoft (R) HTML Viewer Microsoft Corporation Internet Explorer 11.00.96
00.17041
[Protocols Handler] :HKLM cdl=C:\WINDOWS\SYSWOW64\URLMON.DLL
### OLE32 Extensions for Win32 Microsoft Corporation Internet Explorer 11.00.9
600.17041

[Protocols Handler] :HKLM dvd=C:\WINDOWS\SYSWOW64\MSVIDCTL.DLL


### ActiveX control for streaming video Microsoft Corporation DirectShow 6.05.
7600.16385
[Protocols Handler] :HKLM file=C:\WINDOWS\SYSWOW64\URLMON.DLL
### OLE32 Extensions for Win32 Microsoft Corporation Internet Explorer 11.00.9
600.17041
[Protocols Handler] :HKLM ftp=C:\WINDOWS\SYSWOW64\URLMON.DLL
### OLE32 Extensions for Win32 Microsoft Corporation Internet Explorer 11.00.9
600.17041
[Protocols Handler] :HKLM grooveLocalGWS=C:\PROGRA~2\MICROS~1\OFFICE12\GRA32A~
1.DLL
### GrooveSystemServices Module Microsoft Corporation GrooveSystemServices Mod
ule 4.2.0.2623
[Protocols Handler] :HKLM http=C:\WINDOWS\SYSWOW64\URLMON.DLL
### OLE32 Extensions for Win32 Microsoft Corporation Internet Explorer 11.00.9
600.17041
[Protocols Handler] :HKLM https=C:\WINDOWS\SYSWOW64\URLMON.DLL
### OLE32 Extensions for Win32 Microsoft Corporation Internet Explorer 11.00.9
600.17041
[Protocols Handler] :HKLM its=C:\WINDOWS\SYSTEM32\ITSS.DLL
### Microsoft InfoTech Storage System Library Microsoft Corporation Microsoft Wi
ndows Operating System 6.1.7600.16385 %SystemRoot%\System32\itss.dll
[Protocols Handler] :HKLM javascript=C:\WINDOWS\SYSWOW64\MSHTML.DLL
### Microsoft (R) HTML Viewer Microsoft Corporation Internet Explorer 11.00.96
00.17041
[Protocols Handler] :HKLM local=C:\WINDOWS\SYSWOW64\URLMON.DLL
### OLE32 Extensions for Win32 Microsoft Corporation Internet Explorer 11.00.9
600.17041
[Protocols Handler] :HKLM mailto=C:\WINDOWS\SYSWOW64\MSHTML.DLL
### Microsoft (R) HTML Viewer Microsoft Corporation Internet Explorer 11.00.96
00.17041
[Protocols Handler] :HKLM mhtml=C:\WINDOWS\SYSTEM32\INETCOMM.DLL
### Microsoft Internet Messaging API Resources Microsoft Corporation Microsoft
Windows Operating System 6.1.7601.17609 %SystemRoot%\system32\inetcomm.dll
[Protocols Handler] :HKLM mk=C:\WINDOWS\SYSWOW64\URLMON.DLL
### OLE32 Extensions for Win32 Microsoft Corporation Internet Explorer 11.00.9
600.17041
[Protocols Handler] :HKLM ms-help=C:\PROGRAM FILES (X86)\COMMON FILES\MICROSOF
T SHARED\HELP\HXDS.DLL
### Microsoft Help Data Services Module Microsoft Corporation Microsoft Help 2.
5 2.05.50727.198
[Protocols Handler] :HKLM ms-its=C:\WINDOWS\SYSTEM32\ITSS.DLL
### Microsoft InfoTech Storage System Library Microsoft Corporation Microsoft Wi
ndows Operating System 6.1.7600.16385 %SystemRoot%\System32\itss.dll
[Protocols Handler] :HKLM res=C:\WINDOWS\SYSWOW64\MSHTML.DLL
### Microsoft (R) HTML Viewer Microsoft Corporation Internet Explorer 11.00.96
00.17041
[Protocols Handler] :HKLM tv=C:\WINDOWS\SYSWOW64\MSVIDCTL.DLL
### ActiveX control for streaming video Microsoft Corporation DirectShow 6.05.
7600.16385
[Protocols Handler] :HKLM vbscript=C:\WINDOWS\SYSWOW64\MSHTML.DLL
### Microsoft (R) HTML Viewer Microsoft Corporation Internet Explorer 11.00.96
00.17041
[Protocols Handler] :HKLM WSISAllmytubechrome
[Proxy] :HKCU ProxyServer=http=127.0.0.1:8888;https=127.0.0.1:8888
[Proxy] :HKCU ProxyEnable=0
[Network Settings]
[Hosts File Path] :HKLM DataBasePath=%SystemRoot%\System32\drivers\etc
[Hosts File Contents] :HKLM 127.0.0.1
localhost
[Browsers]

[Installed Browsers] FIREFOX.EXE=C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\FIREFO


X.EXE
### Firefox Mozilla Corporation Firefox 39.0.3
[Installed Browsers] Google Chrome=C:\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLIC
ATION\CHROME.EXE
### Default Browser
Google Chrome Google Inc. Google Chrome 48.0.2564.82
[Installed Browsers] IEXPLORE.EXE=C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.
EXE
### Internet Explorer Microsoft Corporation Internet Explorer 11.00.9600.16428
[FireFox Components and Extensions] firefox@ghostery.com=C:\Users\admin\AppDat
a\Roaming\Mozilla\Firefox\Profiles\p2448cp5.default\extensions\firefox@ghostery.
com.xpi
### firefox@ghostery.com
[FireFox Components and Extensions] firefox@zenmate.com=C:\Users\admin\AppData
\Roaming\Mozilla\Firefox\Profiles\p2448cp5.default\extensions\firefox@zenmate.co
m.xpi
### firefox@zenmate.com
[FireFox Components and Extensions] jid1-cplLTTY501TB2Q@jetpack=C:\Users\admin
\AppData\Roaming\Mozilla\Firefox\Profiles\p2448cp5.default\extensions\jid1-cplLT
TY501TB2Q@jetpack.xpi
### jid1-cplLTTY501TB2Q@jetpack
[FireFox Components and Extensions] jid1-dgnIBwQga0SIBw@jetpack=C:\Users\admin
\AppData\Roaming\Mozilla\Firefox\Profiles\p2448cp5.default\extensions\jid1-dgnIB
wQga0SIBw@jetpack.xpi
### jid1-dgnIBwQga0SIBw@jetpack
[FireFox Components and Extensions] jid1-f3mYMbCpz2AZYl@jetpack=C:\Users\admin
\AppData\Roaming\Mozilla\Firefox\Profiles\p2448cp5.default\extensions\jid1-f3mYM
bCpz2AZYl@jetpack.xpi
### jid1-f3mYMbCpz2AZYl@jetpack
[FireFox Components and Extensions] jid1-fRvgLzKONCsPew@jetpack=C:\Users\admin
\AppData\Roaming\Mozilla\Firefox\Profiles\p2448cp5.default\extensions\jid1-fRvgL
zKONCsPew@jetpack.xpi
### jid1-fRvgLzKONCsPew@jetpack
[FireFox Components and Extensions] jid1-HAV2inXAnQPIeA@jetpack=C:\Users\admin
\AppData\Roaming\Mozilla\Firefox\Profiles\p2448cp5.default\extensions\jid1-HAV2i
nXAnQPIeA@jetpack.xpi
### jid1-HAV2inXAnQPIeA@jetpack
[FireFox Components and Extensions] lipikaar@lipikaar.databyte=C:\Users\admin\
AppData\Roaming\Mozilla\Firefox\Profiles\p2448cp5.default\extensions\lipikaar@li
pikaar.databyte.xpi
### lipikaar@lipikaar.databyte
[FireFox Components and Extensions] Lucifox@lucidor.org=C:\Users\admin\AppData
\Roaming\Mozilla\Firefox\Profiles\p2448cp5.default\extensions\Lucifox@lucidor.or
g\
### Lucifox@lucidor.org Lucifox Files autopub.js autopub.xul collections.js co
llections.xul editnote.js
[FireFox Components and Extensions] netvideohunter@netvideohunter.com=C:\Users
\admin\AppData\Roaming\Mozilla\Firefox\Profiles\p2448cp5.default\extensions\netv
ideohunter@netvideohunter.com\
### netvideohunter@netvideohunter.com NetVideoHunter Files mediaList.xul optio
ns.xul overlay.xul netvideohunter.js HashList.js
[FireFox Components and Extensions] paulsaintuzb@gmail.com=C:\Users\admin\AppD
ata\Roaming\Mozilla\Firefox\Profiles\p2448cp5.default\extensions\paulsaintuzb@gm
ail.com\
### paulsaintuzb@gmail.com Youtube Downloader - 4K Download Files browser_fenn
ec.js browser_fennec.xul offer_downloader.js offer_downloader.xul sign_petition.
xul
[FireFox Components and Extensions] save-as-pdf-ff@pdfcrowd.com=C:\Users\admin

\AppData\Roaming\Mozilla\Firefox\Profiles\p2448cp5.default\extensions\save-as-pd
f-ff@pdfcrowd.com.xpi
### save-as-pdf-ff@pdfcrowd.com
[FireFox Components and Extensions] {2d3fbcf7-be69-4433-8858-c621a8d0e58d}=C:\
Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\p2448cp5.default\extensions
\{2d3fbcf7-be69-4433-8858-c621a8d0e58d}\
### {2d3fbcf7-be69-4433-8858-c621a8d0e58d} Widevine Media Optimizer Files npwi
devinemediaoptimizer.dll
[FireFox Components and Extensions] {5384767E-00D9-40E9-B72F-9CC39D655D6F}=C:\
Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\p2448cp5.default\extensions
\{5384767E-00D9-40E9-B72F-9CC39D655D6F}\
### {5384767E-00D9-40E9-B72F-9CC39D655D6F} EPUBReader Files aboutEpubcatalog.j
s aboutEpubreader.js catalog.js catalog.xul content.js
[FireFox Components and Extensions] {bb65e674-b194-4b6e-8033-5fa0afe3a198}=C:\
Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\p2448cp5.default\extensions
\{bb65e674-b194-4b6e-8033-5fa0afe3a198}.xpi
### {bb65e674-b194-4b6e-8033-5fa0afe3a198}
[FireFox Components and Extensions] {ec8030f7-c20a-464f-9b0e-13a3a9e97384}=C:\
Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\p2448cp5.default\extensions
\{bee6eb20-01e0-ebd1-da83-080329fb9a3a}\
### {ec8030f7-c20a-464f-9b0e-13a3a9e97384} Flash and Video Download Files down
loadManager.js downloadManager.xul oldOptions.xul options.js options.xul
[FireFox Components and Extensions] wcapturex@deskperience.com=C:\Program File
s (x86)\WordWeb\WCaptureMoz\
### wcapturex@deskperience.com WCaptureX Files wcapturex.js wcapturex.xul WcxT
race.js WCaptureXpcom.dll WcxComm.xpt
[FireFox Settings] :HKLM browser.startup.homepage=about:home
[FireFox Settings] :HKLM browser.startup.homepage_override_url=""
[FireFox Settings] :HKLM browser.search.selectedEngine=yahoo!
[FireFox Settings] :HKLM browser.search.selectedEngine,S=websearch
[FireFox Settings] :HKLM browser.search.defaultEnginename=""
[FireFox Settings] :HKLM browser.search.defaultEnginename,S=""
[FireFox Settings] :HKLM browser.search.order.1=websearch
[FireFox Settings] :HKLM browser.search.order.1,S=websearch
[FireFox Settings] :HKLM browser.search.defaulturl=http://websearch.toolksearc
hbook.info/?pid=725&r=2014/01/15&hid=2406902759796487476&lg=en&cc=in&unqvl=46&l=
1&q=
[FireFox Settings] :HKLM browser.newtab.url=""
[FireFox Settings] :HKLM keyword.URL=https://in.search.yahoo.com/search?fr=gre
entree_ff1&ei=utf-8&ilc=12&type=830633&p=
[FireFox Settings] :HKLM network.proxy.autoconfig_url=""
[FireFox Settings] :HKLM network.proxy.type=0
[FireFox Settings] :HKLM network.proxy.http=""
[FireFox Settings] :HKLM network.proxy.http_port=""
[Google Chrome Settings] :HKLM backup.homepage=""
[Google Chrome Settings] :HKLM backup.session.urls_to_restore_on_startup=""
[Google Chrome Settings] :HKLM session.startup_urls=""
[Google Chrome Settings] :HKLM default_search_provider.icon_url=""
[Google Chrome Settings] :HKLM default_search_provider.keyword=""
[Google Chrome Settings] :HKLM default_search_provider.name=""
[Google Chrome Settings] :HKLM default_search_provider.search_url=""
[Google Chrome Settings] :HKLM default_search_provider.suggest_url=""
[Google Chrome Settings] :HKLM default_search_provider_data.template_url_data.
alternate_urls=""
[Google Chrome Settings] :HKLM default_search_provider_data.template_url_data.
favicon_url=""
[Google Chrome Settings] :HKLM default_search_provider_data.template_url_data.
keyword=""
[Google Chrome Settings] :HKLM default_search_provider_data.template_url_data.
short_name=""

[Google Chrome Settings] :HKLM default_search_provider_data.template_url_data.


url=""
[Google Chrome Settings] :HKLM default_search_provider_data.template_url_data.
suggest_url=""
[Google Chrome Settings] :HKLM default_search_provider_data.template_url_data.
new_tab_url=""
[Google Chrome Settings] :HKLM default_search_provider_data.template_url_data.
instant_url=""
[Google Chrome Settings] :HKLM default_search_provider_data.template_url_data.
image_url=""
[Google Chrome Settings] :HKLM homepage=""
[Google Chrome Settings] :HKLM session.urls_to_restore_on_startup=""
[Google Chrome Addons] aapocclcgogkmnckokdopfmhonfmgoek=C:\Users\admin\AppData
\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgo
ek\0.9_0
### google slides: Disabled
[Google Chrome Addons] aohghmighlieiainnegkcijnfilokake=C:\Users\admin\AppData
\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfiloka
ke\0.9_0
### google docs: Disabled
[Google Chrome Addons] apdfllckaahabafndbhieahigkjlhalf=C:\Users\admin\AppData
\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlha
lf\14.1_0
### google drive: Disabled
[Google Chrome Addons] blpcfgokakmgnkcojhhkbfbldkacnbeo=C:\Users\admin\AppData
\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnb
eo\4.2.8_0
### youtube: Disabled
[Google Chrome Addons] coobgpohoikkiipiblmjeljniedjpjpf=C:\Users\admin\AppData
\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpj
pf\0.0.0.60_0
### google search: Disabled
[Google Chrome Addons] felcaaldnbdncclmgdcncolpebgiejap=C:\Users\admin\AppData
\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiej
ap\1.1_0
### google sheets: Disabled
[Google Chrome Addons] ghbmnnjooekpmoecnnnilnnbdlolhkhi=C:\Users\admin\AppData
\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhk
hi\1.4_0
### : Disabled
[Google Chrome Addons] ndnaehgpjlnokgebbaldlmgkapkpjkkb=C:\Users\admin\AppData
\Local\Google\Chrome\User Data\Default\Extensions\ndnaehgpjlnokgebbaldlmgkapkpjk
kb\1.41.3_0
### mailtrack for gmail: Disabled
[Google Chrome Addons] nmmhkkegccagdldgiimedpiccmgmieda=C:\Users\admin\AppData
\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmie
da\1.0.0.0_0
### : Disabled
[Google Chrome Addons] pjkljhegncpnkpknbcohdijeoejaedia=C:\Users\admin\AppData
\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaed
ia\8.1_0
### gmail: Disabled
[Google Chrome Addons] fjbbjfdilbioabojmcplalojlmdngbjl=C:\USERS\ADMIN\APPDATA
\LOCAL\TEMP\SWLFILES\SMILEYSWELOVETOOLBAR.CRX
[Google Chrome Addons] mjdepfkicdcciagbigfcmdhknnoaaegf=C:\PROGRAM FILES (X86)
\WORDWEB\WCXCHROME.CRX
[Network Settings]
[Domain Name] :HKLM Domain=serverhosur.local
[Name Server] {B5D68560-FCB8-4702-88A1-C9D194A725F6}=192.168.42.129
### Network Card:SAMSUNG Mobile USB Remote NDIS Network Device DHCPNameServer:

192.168.42.129 DhcpDefaultGateway:192.168.42.129
DhcpServer:192.168.42.129
[Name Server] {E07C7B77-C4E2-4FA2-9E6B-7A05403B03CD}=192.168.1.100
### Network Card:Realtek PCIe GBE Family Controller DefaultGateway:192.168.1.4
IPAddress:192.168.1.105
[WinSock2 Components] NLAapi.dll=C:\WINDOWS\SYSWOW64\NLAAPI.DLL
### Network Location Awareness 2 Microsoft Corporation Microsoft Windows Operati
ng System 6.1.7601.17514 %SystemRoot%\SYSWOW64\NLAapi.dll
[WinSock2 Components] napinsp.dll=C:\WINDOWS\SYSWOW64\NAPINSP.DLL
### E-mail Naming Shim Provider Microsoft Corporation Microsoft Windows Operatin
g System 6.1.7600.16385 %SystemRoot%\SYSWOW64\napinsp.dll
[WinSock2 Components] pnrpnsp.dll=C:\WINDOWS\SYSWOW64\PNRPNSP.DLL
### PNRP Name Space Provider Microsoft Corporation Microsoft Windows Operating S
ystem 6.1.7600.16385 %SystemRoot%\SYSWOW64\pnrpnsp.dll
[WinSock2 Components] mswsock.dll=C:\WINDOWS\SYSWOW64\MSWSOCK.DLL
### Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation Micro
soft Windows Operating System 6.1.7600.16385 %SystemRoot%\SYSWOW64\mswsock.dll
[WinSock2 Components] winrnr.dll=C:\WINDOWS\SYSWOW64\WINRNR.DLL
### LDAP RnR Provider DLL Microsoft Corporation Microsoft Windows Operating Syst
em 6.1.7600.16385 %SystemRoot%\SYSWOW64\winrnr.dll
[WinSock2 Components (x64)] NLAapi.dll=C:\WINDOWS\SYSNATIVE\NLAAPI.DLL
### Network Location Awareness 2 Microsoft Corporation Microsoft Windows Operati
ng System 6.1.7601.17514 %SystemRoot%\SYSNATIVE\NLAapi.dll
[WinSock2 Components (x64)] napinsp.dll=C:\WINDOWS\SYSNATIVE\NAPINSP.DLL
### E-mail Naming Shim Provider Microsoft Corporation Microsoft Windows Operatin
g System 6.1.7600.16385 %SystemRoot%\SYSNATIVE\napinsp.dll
[WinSock2 Components (x64)] pnrpnsp.dll=C:\WINDOWS\SYSNATIVE\PNRPNSP.DLL
### PNRP Name Space Provider Microsoft Corporation Microsoft Windows Operating S
ystem 6.1.7600.16385 %SystemRoot%\SYSNATIVE\pnrpnsp.dll
[WinSock2 Components (x64)] mswsock.dll=C:\WINDOWS\SYSNATIVE\MSWSOCK.DLL
### Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation Micro
soft Windows Operating System 6.1.7600.16385 %SystemRoot%\SYSNATIVE\mswsock.dll
[WinSock2 Components (x64)] winrnr.dll=C:\WINDOWS\SYSNATIVE\WINRNR.DLL
### LDAP RnR Provider DLL Microsoft Corporation Microsoft Windows Operating Syst
em 6.1.7600.16385 %SystemRoot%\SYSNATIVE\winrnr.dll
[Software Components]
[Internet Components] :HKLM C:\Windows\Downloaded Program Files\alttiff.ocx=C:
\WINDOWS\DOWNLOADED PROGRAM FILES\ALTTIFF.OCX
### AlternaTIFF ActiveX control Medical Informatics Engineering, Inc. AlternaT
IFF ActiveX control 2, 0, 6, 1
[Internet Components] :HKLM C:\Windows\System32\ActiveXRes_CHI.dll=C:\Windows\
System32\ActiveXRes_CHI.dll
### File is deleted or hidden by a rootkit or could not be located.
[Internet Components] :HKLM C:\Windows\System32\ActiveXRes_ENG.dll=C:\Windows\
System32\ActiveXRes_ENG.dll
### File is deleted or hidden by a rootkit or could not be located.
[Internet Components] :HKLM C:\Windows\System32\Calendar.ocx=C:\Windows\System
32\Calendar.ocx
### File is deleted or hidden by a rootkit or could not be located.
[Internet Components] :HKLM C:\Windows\System32\HCNetSDK.dll=C:\Windows\System
32\HCNetSDK.dll
### File is deleted or hidden by a rootkit or could not be located.
[Internet Components] :HKLM C:\Windows\System32\hpr.dll=C:\Windows\System32\hp
r.dll
### File is deleted or hidden by a rootkit or could not be located.
[Internet Components] :HKLM C:\Windows\System32\NetVideoActiveX23.ocx=C:\Windo
ws\System32\NetVideoActiveX23.ocx
### File is deleted or hidden by a rootkit or could not be located.
[Internet Components] :HKLM C:\Windows\System32\PlaybackActiveX23.ocx=C:\Windo

ws\System32\PlaybackActiveX23.ocx
### File is deleted or hidden by a rootkit or could not be located.
[Internet Components] :HKLM C:\Windows\System32\PlayBackBarActiveX.ocx=C:\Wind
ows\System32\PlayBackBarActiveX.ocx
### File is deleted or hidden by a rootkit or could not be located.
[Internet Components] :HKLM C:\Windows\System32\PlayCtrl.dll=C:\Windows\System
32\PlayCtrl.dll
### File is deleted or hidden by a rootkit or could not be located.
[Internet Components] :HKLM C:\Windows\System32\RealPlayActiveX23.ocx=C:\Windo
ws\System32\RealPlayActiveX23.ocx
### File is deleted or hidden by a rootkit or could not be located.
[Internet Components] :HKLM C:\Windows\System32\RemConfigRes_CHI.dll=C:\Window
s\System32\RemConfigRes_CHI.dll
### File is deleted or hidden by a rootkit or could not be located.
[Internet Components] :HKLM C:\Windows\System32\RemConfigRes_ENG.dll=C:\Window
s\System32\RemConfigRes_ENG.dll
### File is deleted or hidden by a rootkit or could not be located.
[Internet Components] :HKLM C:\Windows\System32\SearchLogActiveX23.ocx=C:\Wind
ows\System32\SearchLogActiveX23.ocx
### File is deleted or hidden by a rootkit or could not be located.
[Internet Components] :HKLM C:\Windows\System32\ShowRemConfig.dll=C:\Windows\S
ystem32\ShowRemConfig.dll
### File is deleted or hidden by a rootkit or could not be located.
[Internet Components] :HKLM C:\Windows\System32\StreamTransClient.dll=C:\Windo
ws\System32\StreamTransClient.dll
### File is deleted or hidden by a rootkit or could not be located.
[Internet Components] :HKLM C:\Windows\System32\SystemTransform.dll=C:\Windows
\System32\SystemTransform.dll
### File is deleted or hidden by a rootkit or could not be located.
[Windows Shell]
[Display Scrap's Extensions] :HKLM NeverShowExt=""
[ScreenSaver] :HKCU SCRNSAVE.EXE=""
### File is deleted or hidden by a rootkit or could not be located.
[System.ini] shell=explorer.exe
[User Shell] :HKCU shell=""
[Main File Extensions] :HKLM .exe="%1" %*
[Main File Extensions] :HKLM .com="%1" %*
[Main File Extensions] :HKLM .pif="%1" %*
[Main File Extensions] :HKLM .bat="%1" %*
[Main File Extensions] :HKLM .cmd="%1" %*
[Main File Extensions] :HKLM .scr="%1" /S
[Main File Extensions] :HKLM .txt=%SystemRoot%\system32\NOTEPAD.EXE %1
[Main File Extensions] :HKLM .reg=regedit.exe "%1"
[Main File Extensions] :HKLM .inf=%SystemRoot%\system32\NOTEPAD.EXE %1
[Main File Extensions] :HKLM .ini=%SystemRoot%\system32\NOTEPAD.EXE %1
[Main File Extensions] :HKLM .js=%SystemRoot%\System32\WScript.exe "%1" %*
[Main File Extensions] :HKLM .vbs=%SystemRoot%\System32\WScript.exe "%1" %*
[Main File Extensions] :HKLM .vbe=%SystemRoot%\System32\WScript.exe "%1" %*
[Main File Extensions] :HKLM .msc=%SystemRoot%\system32\mmc.exe "%1" %*
[Main File Extensions] :HKLM .jpg="C:\PROGRA~2\MICROS~1\Office12\OIS.EXE" /she
llOpen "%1"
[Main File Extensions] :HKLM .jpeg="C:\PROGRA~2\MICROS~1\Office12\OIS.EXE" /sh
ellOpen "%1"
[Shell Execute Hooks] :HKLM {B5A7F190-DDA6-4420-B3BA-52453494E6CD}=C:\PROGRA~2
\MICROS~1\OFFICE12\GR469A~1.DLL
### GrooveShellExtensions Module Microsoft Corporation GrooveShellExtensions M
odule 4.2.0.2623
[UserInit Value] :HKLM UserInit=C:\Windows\system32\userinit.exe,userinit.exe,
[Shell Services DelayLoad] :HKLM WebCheck={E6FB5E20-DE35-11CF-9C87-00AA005127E
D}

[System Shell Policies] :HKCU shell=""


[System Shell Policies] :HKLM shell=""
[System Shell Policies] :HKCU run=""
[System Shell Policies] :HKLM run=""
[App Paths] :HKLM 7zFM.exe=C:\Program Files (x86)\7-Zip\7zFM.exe
### 7zFM.exe 7-Zip File Manager Igor Pavlov 7-Zip 9.20
[App Paths] :HKLM Acrobat.exe=C:\Program Files (x86)\Adobe\Acrobat 7.0\Acrobat
\Acrobat.exe
### Acrobat.exe Adobe Acrobat 7.0 Adobe Systems Incorporated Adobe Acrobat 7.0
.0.2004121400
[App Paths] :HKLM AcrobatInfo.exe=C:\Program Files (x86)\Adobe\Acrobat 7.0\Acr
obat\AcrobatInfo.exe
### AcrobatInfo.exe Adobe Acrobat PDF Info 7.0 Adobe Systems Incorporated Adob
e Acrobat PDF Info 7.0.0.2004121400
[App Paths] :HKLM AcroDist.exe=C:\Program Files (x86)\Adobe\Acrobat 7.0\Distil
lr\AcroDist.exe
### AcroDist.exe Acrobat Distiller Adobe Systems Incorporated. Acrobat Disti
ller for Windows 7.0.0.2004121400
[App Paths] :HKLM AcroRd32.exe=C:\Program Files (x86)\Adobe\Acrobat Reader DC\
Reader\AcroRd32.exe
### AcroRd32.exe Adobe Acrobat Reader DC Adobe Systems Incorporated Adobe Acr
obat Reader DC 15.10.20056.167417
[App Paths] :HKLM CAPTURE.EXE=c:\Program Files\Corel\CorelDRAW Graphics Suite
X7\Programs64\CAPTURE.EXE
### CAPTURE.EXE Corel CAPTURE X7 (64-Bit) Corel Corporation Corel Graphics App
lications 17.1.0.572
[App Paths] :HKLM ccleaner.exe=C:\Program Files\CCleaner\CCleaner64.exe
### ccleaner.exe CCleaner Piriform Ltd CCleaner 4, 18, 00, 4842
[App Paths] :HKLM chrome.exe=C:\Program Files (x86)\Google\Chrome\Application\
chrome.exe
### chrome.exe Google Chrome Google Inc. Google Chrome 48.0.2564.82
[App Paths] :HKLM cmmgr32.exe
### cmmgr32.exe
[App Paths] :HKLM CorelDrw.exe=c:\Program Files\Corel\CorelDRAW Graphics Suite
X7\Programs64\CorelDrw.exe
### CorelDrw.exe CorelDRAW X7 (64-Bit) Corel Corporation Corel Graphics Applic
ations 17.1.0.572
[App Paths] :HKLM CorelPP.exe=c:\Program Files\Corel\CorelDRAW Graphics Suite
X7\Programs64\CorelPP.exe
### CorelPP.exe Corel PHOTO-PAINT X7 (64-Bit) Corel Corporation Corel Graphics
Applications 17.1.0.572
[App Paths] :HKLM dvdmaker.exe=%ProgramFiles%\DVD Maker\dvdmaker.exe
### dvdmaker.exe
[App Paths] :HKLM excel.exe=C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE
### excel.exe Microsoft Office Excel Microsoft Corporation 2007 Microsoft Offi
ce system 12.0.4518.1014
[App Paths] :HKLM ExcelPasswordRecovery.exe=C:\Program Files (x86)\Daossoft Ex
cel Password Recovery\ExcelPasswordRecovery.exe
### ExcelPasswordRecovery.exe Excel Password Recovery Daossoft Excel Password
Recovery 7.0.0.1
[App Paths] :HKLM filezilla.exe=C:\Program Files (x86)\FileZilla FTP Client\fi
lezilla.exe
### filezilla.exe FileZilla FTP Client FileZilla Project FileZilla 3, 13, 1, 0
[App Paths] :HKLM firefox.exe=C:\Program Files (x86)\Mozilla Firefox\firefox.e
xe
### firefox.exe Firefox Mozilla Corporation Firefox 39.0.3
[App Paths] :HKLM FormDesigner.exe=C:\Program Files (x86)\Adobe\Acrobat 7.0\De
signer 7.0\FormDesigner.exe
### FormDesigner.exe Adobe Designer Adobe Systems Incorporated Adobe Designer

7, 0, 041126, 0, 161742
[App Paths] :HKLM foxitPhantom.exe=C:\Program Files (x86)\Foxit Software\Foxit
PhantomPDF\FoxitPhantomPDF.exe
### foxitPhantom.exe Foxit PhantomPDF 7.0 Foxit Software Inc. Foxit PhantomPDF
7.0.3.916
[App Paths] :HKLM free-mp3-splitter.exe=C:\Program Files (x86)\freestar\free-m
p3-splitter\free-mp3-splitter.exe.exe
### free-mp3-splitter.exe
[App Paths] :HKLM GROOVE.EXE=C:\PROGRA~2\MICROS~1\Office12\GROOVE.EXE
### GROOVE.EXE Microsoft Office Groove Microsoft Corporation Microsoft Office
Groove 4.2.0.2623
[App Paths] :HKLM IEDIAG.EXE=C:\Program Files\Internet Explorer\IEDIAGCMD.EXE
### IEDIAG.EXE Diagnostics utility for Internet Explorer Microsoft Corporation
Internet Explorer 11.00.9600.16428
[App Paths] :HKLM IEDIAGCMD.EXE=C:\Program Files\Internet Explorer\IEDIAGCMD.E
XE
### IEDIAGCMD.EXE Diagnostics utility for Internet Explorer Microsoft Corporat
ion Internet Explorer 11.00.9600.16428
[App Paths] :HKLM IEXPLORE.EXE=C:\Program Files\Internet Explorer\IEXPLORE.EXE
### IEXPLORE.EXE Internet Explorer Microsoft Corporation Internet Explorer 11.
00.9600.16428
[App Paths] :HKLM infopath.exe=C:\PROGRA~2\MICROS~1\Office12\INFOPATH.EXE
### infopath.exe Microsoft Office InfoPath 2007 Microsoft Corporation Microsof
t Office InfoPath 12.0.4518.1014
[App Paths] :HKLM install.exe
### install.exe
[App Paths] :HKLM iTunes.exe=C:\Program Files (x86)\iTunes\iTunes.exe
### iTunes.exe iTunes Apple Inc. iTunes 11.2.2.3
[App Paths] :HKLM j5store.exe=C:\Program Files (x86)\JewelArt\j5store.exe
### j5store.exe Asian Star Co. Ltd. JewelArt 3.03.0185
[App Paths] :HKLM javaws.exe=C:\Program Files (x86)\Java\jre1.8.0_77\bin\javaw
s.exe
### javaws.exe Java(TM) Web Start Launcher Oracle Corporation Java(TM) Platfor
m SE 8 U77 8.0.770.3
[App Paths] :HKLM Journal.exe=%ProgramFiles%\Windows Journal\Journal.exe
### Journal.exe
[App Paths] :HKLM kkdict.exe=C:\Program Files (x86)\KKDict\kkdict.exe
### kkdict.exe KK Dictionary www.kannadakasturi.com KK Dictionary 1.02
[App Paths] :HKLM mip.exe=%CommonProgramFiles%\Microsoft Shared\Ink\mip.exe
### mip.exe
[App Paths] :HKLM MobogenieAdd
### MobogenieAdd
[App Paths] :HKLM mplayer2.exe=%ProgramFiles(x86)%\Windows Media Player\wmplay
er.exe
### mplayer2.exe
[App Paths] :HKLM MSACCESS.EXE=C:\PROGRA~2\MICROS~1\Office12\MSACCESS.EXE
### MSACCESS.EXE Microsoft Office Access Microsoft Corporation 2007 Microsoft
Office system 12.0.4518.1014
[App Paths] :HKLM MsoHtmEd.exe
### MsoHtmEd.exe
[App Paths] :HKLM msoxmled.exe=C:\Program Files (x86)\Common Files\Microsoft S
hared\OFFICE12\MSOXMLED.EXE
### msoxmled.exe XML Editor Microsoft Corporation Microsoft Office InfoPath 12
.0.4518.1014
[App Paths] :HKLM MSPUB.EXE=C:\PROGRA~2\MICROS~1\Office12\MSPUB.EXE
### MSPUB.EXE Microsoft Office Publisher Microsoft Corporation 2007 Microsoft
Office system 12.0.4518.1014
[App Paths] :HKLM nmsetup.exe=C:\Program Files (x86)\Network Magic Pro Edition
\nmsetup.exe
### nmsetup.exe Cisco Network Magic Setup Cisco Systems, Inc. Network Magic 5.

5.09195.0
[App Paths] :HKLM ois.exe=C:\PROGRA~2\MICROS~1\Office12\OIS.EXE
### ois.exe Microsoft Office Picture Manager Microsoft Corporation Microsoft O
ffice Picture Manager 12.0.4518.1014
[App Paths] :HKLM OneNote.exe=C:\PROGRA~2\MICROS~1\Office12\ONENOTE.EXE
### OneNote.exe Microsoft Office OneNote Microsoft Corporation Microsoft Offic
e OneNote 12.0.4518.1014
[App Paths] :HKLM OUTLOOK.EXE=C:\PROGRA~2\MICROS~1\Office12\OUTLOOK.EXE
### OUTLOOK.EXE Microsoft Office Outlook Microsoft Corporation Microsoft Offic
e Outlook 12.0.4518.1014
[App Paths] :HKLM pbrush.exe=%SystemRoot%\System32\mspaint.exe
### pbrush.exe
[App Paths] :HKLM PCCompanion.exe=C:\Program Files (x86)\Sony\Sony PC Companio
n\PCCompanion.exe
### PCCompanion.exe Sony PC Companion Sony Sony PC Companion 2.1.0
[App Paths] :HKLM PMUNINST.exe
### PMUNINST.exe
[App Paths] :HKLM powerpnt.exe=C:\PROGRA~2\MICROS~1\Office12\POWERPNT.EXE
### powerpnt.exe Microsoft Office PowerPoint Microsoft Corporation 2007 Micros
oft Office system 12.0.4518.1014
[App Paths] :HKLM PowerShell.exe=%SystemRoot%\system32\WindowsPowerShell\v1.0\
PowerShell.exe
### PowerShell.exe
[App Paths] :HKLM QuickTimePlayer.exe=C:\Program Files (x86)\QuickTime\QuickTi
mePlayer.exe
### QuickTimePlayer.exe QuickTime Player Apple Inc. QuickTime QuickTime 7.7.5
(1680.95.13)
[App Paths] :HKLM RevoUninPro.exe=C:\Program Files\VS Revo Group\Revo Uninstal
ler Pro\RevoUninPro.exe
### RevoUninPro.exe Revo Uninstaller Pro VS Revo Group Revo Uninstaller Pro 2.
5.9.0
[App Paths] :HKLM setup.exe
### setup.exe
[App Paths] :HKLM sidebar.exe="%ProgramFiles%\Windows Sidebar\sidebar.exe"
### sidebar.exe
[App Paths] :HKLM Skd8821.exe=C:\Program Files\Lenovo\Lenovo Slim USB Keyboard
\Skd8821.exe
### Skd8821.exe Lenovo Slim USB Keyboard LITE-ON TECHNOLOGY CORP. Lenovo Slim
USB Keyboard 1, 0, 0, 0
[App Paths] :HKLM SnippingTool.exe=%SystemRoot%\system32\SnippingTool.exe
### SnippingTool.exe
[App Paths] :HKLM Sony Mobile Update Engine.exe=C:\Program Files (x86)\Sony Mo
bile\Update Engine\Sony Mobile Update Engine.exe
### Sony Mobile Update Engine.exe
[App Paths] :HKLM table30.exe
### table30.exe
[App Paths] :HKLM TabTip.exe=%CommonProgramFiles%\microsoft shared\ink\TabTip.
exe
### TabTip.exe
[App Paths] :HKLM Unlocker.exe=C:\Program Files (x86)\Unlocker\Unlocker.exe
### Unlocker.exe
[App Paths] :HKLM vmplayer.exe=C:\Program Files (x86)\VMware\VMware Workstatio
n\vmplayer.exe
### vmplayer.exe VMware Player VMware, Inc. VMware Workstation 10.0.0 build-12
95980
[App Paths] :HKLM vmware.exe=C:\Program Files (x86)\VMware\VMware Workstation\
vmware.exe
### vmware.exe VMware Workstation VMware, Inc. VMware Workstation 10.0.0 build
-1295980
[App Paths] :HKLM wab.exe=%ProgramFiles%\Windows Mail\wab.exe

### wab.exe
[App Paths] :HKLM wabmig.exe=%ProgramFiles%\Windows Mail\wabmig.exe
### wabmig.exe
[App Paths] :HKLM WinRAR.exe=C:\Program Files\WinRAR\WinRAR.exe
### WinRAR.exe WinRAR archiver Alexander Roshal WinRAR 5.21.0
[App Paths] :HKLM Winword.exe=C:\PROGRA~2\MICROS~1\Office12\WINWORD.EXE
### Winword.exe Microsoft Office Word Microsoft Corporation 2007 Microsoft Off
ice system 12.0.4518.1014
[App Paths] :HKLM winzip.exe=C:\PROGRA~1\WinZip\winzip64.exe
### winzip.exe WinZip WinZip Computing, S.L. WinZip 18.5 (11111)
[App Paths] :HKLM winzip32.exe=C:\PROGRA~1\WinZip\winzip64.exe
### winzip32.exe WinZip WinZip Computing, S.L. WinZip 18.5 (11111)
[App Paths] :HKLM winzip64.exe=C:\PROGRA~1\WinZip\winzip64.exe
### winzip64.exe WinZip WinZip Computing, S.L. WinZip 18.5 (11111)
[App Paths] :HKLM Wireshark.exe=C:\Program Files\Wireshark\Wireshark.exe
### Wireshark.exe Wireshark The Wireshark developer community, http://www.wire
shark.org/ Wireshark 1.10.7
[App Paths] :HKLM wmplayer.exe=%ProgramFiles(x86)%\Windows Media Player\wmplay
er.exe
### wmplayer.exe
[App Paths] :HKLM WORDPAD.EXE=C:\PROGRAM FILES (X86)\WINDOWS NT\ACCESSORIES\WO
RDPAD.EXE
### WORDPAD.EXE Windows Wordpad Application Microsoft Corporation Microsoft Win
dows Operating System 6.1.7600.16385 "%ProgramFiles%\Windows NT\Accessories\WORD
PAD.EXE"
[App Paths] :HKLM WRITE.EXE="%ProgramFiles%\Windows NT\Accessories\WORDPAD.EXE
"
### WRITE.EXE
[Prevents Display in Control Panel from running.] :HKCU NoDispCpl=0
[Disable Registry Tools] :HKCU DisableRegistryTools =0
[Internet Shortcuts] :HKLM C:\Users\admin\AppData\Roaming\Microsoft\Windows\St
art Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk=HT
TP://WWW.OURSURFING.COM/?TYPE=SC&TS=1439368024&Z=73C5E4DE807BB6E83FA8AC5G7Z6C6T4
C4Q2BEE7TAC&FROM=2SQ&UID=ST2000DM001-1CH164_W1F5EHSDXXXXW1F5EHSD
### C:\Users\admin\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\ACCESS~1
\SYSTEM~1\INTERN~1.LNK
[Internet Shortcuts] :HKLM C:\Users\admin\AppData\Roaming\Microsoft\Windows\St
art Menu\Programs\Internet Explorer.lnk=HTTP://WWW.OURSURFING.COM/?TYPE=SC&TS=14
39368024&Z=73C5E4DE807BB6E83FA8AC5G7Z6C6T4C4Q2BEE7TAC&FROM=2SQ&UID=ST2000DM001-1
CH164_W1F5EHSDXXXXW1F5EHSD
### C:\Users\admin\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\INTERN~2
.LNK
[Internet Shortcuts] :HKLM C:\ProgramData\Microsoft\Windows\Start Menu\Program
s\Mozilla Firefox.lnk=HTTP://WWW.GOOGLE.COM
### C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\MOZILL~1.LNK
[Internet Shortcuts] :HKLM C:\ProgramData\Microsoft\Windows\Start Menu\Program
s\UnHackMe\Check for UnHackMe updates.lnk=HTTP://GREATIS.COM/UNHACKME.INI
### C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\UnHackMe\CHECKF~1.LNK
[Internet Shortcuts] :HKLM C:\Users\admin\AppData\Roaming\Microsoft\Internet E
xplorer\Quick Launch\Launch Internet Explorer Browser.lnk=HTTP://WWW.OURSURFING.
COM/?TYPE=SC&TS=1439368024&Z=73C5E4DE807BB6E83FA8AC5G7Z6C6T4C4Q2BEE7TAC&FROM=2SQ
&UID=ST2000DM001-1CH164_W1F5EHSDXXXXW1F5EHSD
### C:\Users\admin\AppData\Roaming\MICROS~1\INTERN~1\QUICKL~1\LAUNCH~1.LNK
[Internet Shortcuts] :HKLM C:\Users\admin\AppData\Roaming\Microsoft\Internet E
xplorer\Quick Launch\User Pinned\StartMenu\Mozilla Firefox.lnk=HTTP://WWW.GOOGLE
.COM
### C:\Users\admin\AppData\Roaming\MICROS~1\INTERN~1\QUICKL~1\USERPI~1\STARTM~
1\MOZILL~1.LNK
[Internet Shortcuts] :HKLM C:\Users\admin\AppData\Roaming\Microsoft\Internet E
xplorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk=HTTP://WWW.GOOGLE.C

OM
### C:\Users\admin\AppData\Roaming\MICROS~1\INTERN~1\QUICKL~1\USERPI~1\TaskBar
\MOZILL~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\Desktop\All Free MP3 Cutter.lnk=C:\Progr
am Files (x86)\All Free MP3 Cutter\AllFreeMP3Cutter.exe
### C:\Users\admin\Desktop\ALLFRE~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\Desktop\baraha\Baraha.exe - Shortcut.lnk
=C:\Program Files (x86)\Baraha Software\Baraha 10\Baraha.exe
### C:\Users\admin\Desktop\baraha\BARAHA~2.LNK
[User Shortcuts] :HKLM C:\Users\admin\Desktop\baraha\BarahaIME.exe - Shortcut.
lnk=C:\Program Files (x86)\Baraha Software\Baraha 10\BarahaIME.exe
### C:\Users\admin\Desktop\baraha\BARAHA~3.LNK
[User Shortcuts] :HKLM C:\Users\admin\Desktop\baraha\BarahaPad.exe - Shortcut.
lnk=C:\Program Files (x86)\Baraha Software\Baraha 10\BarahaPad.exe
### C:\Users\admin\Desktop\baraha\BARAHA~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\Desktop\baraha\FontConvert.exe - Shortcu
t.lnk=C:\Program Files (x86)\Baraha Software\Baraha 10\FontConvert.exe
### C:\Users\admin\Desktop\baraha\FONTCO~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\Desktop\Bullzip PDF Printer.lnk=C:\Progr
am Files (x86)\Bullzip\PDF Printer\gui.exe
### C:\Users\admin\Desktop\BULLZI~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\Desktop\CMS.lnk=C:\Program Files (x86)\C
MS\CMS.exe
### C:\Users\admin\Desktop\CMS.lnk
[User Shortcuts] :HKLM C:\Users\admin\Desktop\Daossoft Excel Password Recovery
.lnk=C:\Program Files (x86)\Daossoft Excel Password Recovery\ExcelPasswordRecove
ry.exe
### C:\Users\admin\Desktop\DAOSSO~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\Desktop\Dev-C++.lnk=C:\Program Files (x8
6)\Dev-Cpp\devcpp.exe
### C:\Users\admin\Desktop\DEV-C_~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\Desktop\Dictionary.lnk=C:\Program Files
(x86)\Shipra's Dictionary\dictN1.exe
### C:\Users\admin\Desktop\DICTIO~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\Desktop\DLIMonkey.exe - Shortcut.lnk=C:\
Users\admin\Downloads\dlimonkey\bin\DLIMonkey.exe
### C:\Users\admin\Desktop\DLIMON~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\Desktop\Easy MP3 Cutter.lnk=C:\Program F
iles (x86)\Easy MP3 Cutter\mp3_cutter.exe
### C:\Users\admin\Desktop\EASYMP~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\Desktop\Excel-Xls to Pdf Converter.lnk=C
:\Program Files (x86)\Excel-Xls to Pdf Converter\Converter.exe
### C:\Users\admin\Desktop\EXCEL-~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\Desktop\Foxit Advanced PDF Editor.exe.ln
k=C:\Program Files (x86)\Foxit Software\Foxit Advanced PDF Editor\Foxit Advanced
PDF Editor.exe
### C:\Users\admin\Desktop\FOXITA~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\Desktop\Free Download Manager.lnk=C:\Pro
gram Files (x86)\Free Download Manager\fdm.exe
### C:\Users\admin\Desktop\FREEDO~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\Desktop\FreeStar Free MP3 Splitter.lnk=C
:\Program Files (x86)\freestar\free-mp3-splitter\free-mp3-splitter.exe
### C:\Users\admin\Desktop\FREEST~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\Desktop\HTTrack Website Copier.lnk=C:\Pr
ogram Files (x86)\WinHTTrack\WinHTTrack.exe
### C:\Users\admin\Desktop\HTTRAC~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\Desktop\lan - Shortcut.lnk=C:\Users\admi
n\AppData\Roaming\Microsoft\Windows\Libraries\lan.library-ms
### C:\Users\admin\Desktop\LAN-SH~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\Desktop\MediaCoder x64.lnk=C:\Program Fi

les (x86)\MediaCoder\MediaCoder.exe
### C:\Users\admin\Desktop\MEDIAC~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\Desktop\Network Magic Pro Edition.lnk=C:
\Program Files (x86)\Network Magic Pro Edition\nmsetup.exe
### C:\Users\admin\Desktop\NETWOR~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\Desktop\OfficeRecovery 2013 Ultimate.lnk
=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OfficeRecovery 2013 Ultima
te
### C:\Users\admin\Desktop\OFFICE~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\Desktop\Prezi.exe - Shortcut.lnk=C:\Prog
ram Files (x86)\Prezi\Prezi.exe
### C:\Users\admin\Desktop\PREZIE~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\Desktop\Stellar Phoenix Windows Data Rec
overy - Professional.lnk=C:\Program Files (x86)\Stellar Phoenix Windows Data Rec
overy\spwdrp.exe
### C:\Users\admin\Desktop\STELLA~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\Desktop\Total Video Converter.lnk=C:\Pro
gram Files (x86)\Total Video Converter\tvcshell.exe
### C:\Users\admin\Desktop\TOTALV~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\Desktop\Total Video Player.lnk=C:\Progra
m Files (x86)\Total Video Converter\tvp.exe
### C:\Users\admin\Desktop\TOTALV~2.LNK
[User Shortcuts] :HKLM C:\Users\admin\Desktop\udemy_ripper.exe - Shortcut (2).
lnk=E:\pendrive\Software\UDEMY RIPPER [LOADER] [WORK AROUND RANDOM COURSE DOWNLO
AD]\UDEMY RIPPER [LOADER]\UDEMY RIPPER [LOADER]\udemy_ripper.exe
### C:\Users\admin\Desktop\UDEMY_~2.LNK
[User Shortcuts] :HKLM C:\Users\admin\Desktop\udemy_ripper.exe - Shortcut.lnk=
E:\pendrive\Software\UDEMY RIPPER [LOADER] [WORK AROUND RANDOM COURSE DOWNLOAD]\
UDEMY RIPPER [LOADER]\UDEMY RIPPER [LOADER]\udemy_ripper.exe
### C:\Users\admin\Desktop\UDEMY_~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\Desktop\UnHackMe.lnk=C:\Program Files (x
86)\UnHackMe\Unhackme.exe
### C:\Users\admin\Desktop\UnHackMe.lnk
[User Shortcuts] :HKLM C:\Users\admin\Desktop\Windows 7 USB DVD Download Tool.
lnk=C:\Users\admin\AppData\Local\Apps\Windows 7 USB DVD Download Tool\Windows7-U
SB-DVD-Download-Tool.exe
### C:\Users\admin\Desktop\WINDOW~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\Desktop\Wondershare PDF Editor.lnk=C:\Pr
ogram Files (x86)\Wondershare\PDFEditor\PDFEditor.exe
### C:\Users\admin\Desktop\WONDER~1.LNK
[User Shortcuts] :HKLM C:\Users\Public\Desktop\Acrobat Reader DC.lnk=C:\Progra
m Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe
### C:\Users\Public\Desktop\ACROBA~1.LNK
[User Shortcuts] :HKLM C:\Users\Public\Desktop\Adobe Acrobat 7.0 Professional.
lnk=C:\Program Files (x86)\Adobe\Acrobat 7.0\Acrobat\Acrobat.exe
### C:\Users\Public\Desktop\ADOBEA~1.LNK
[User Shortcuts] :HKLM C:\Users\Public\Desktop\AMCap.lnk=C:\Windows\amcap.exe
### C:\Users\Public\Desktop\AMCap.lnk
[User Shortcuts] :HKLM C:\Users\Public\Desktop\B9Creator.lnk=C:\Program Files
(x86)\B9Creations\B9Creator\B9Creator.exe
### C:\Users\Public\Desktop\B9CREA~1.LNK
[User Shortcuts] :HKLM C:\Users\Public\Desktop\Bitstream Font Navigator (64-Bi
t).lnk=C:\Program Files (x86)\Corel\CorelDRAW Graphics Suite X7\FontNav64\FontNa
v.exe
### C:\Users\Public\Desktop\BITSTR~1.LNK
[User Shortcuts] :HKLM C:\Users\Public\Desktop\CCleaner.lnk=C:\Program Files (
x86)\CCleaner\CCleaner64.exe
### C:\Users\Public\Desktop\CCleaner.lnk
[User Shortcuts] :HKLM C:\Users\Public\Desktop\Corel CAPTURE X7 (64-Bit).lnk=c
:\Windows\Installer\{2C91CB9D-323D-43E5-A433-229B71CFB773}\NewShortcut8_65BCA6E0

337A452DA55C0654EAAD7A0B.exe
### C:\Users\Public\Desktop\CORELC~1.LNK
[User Shortcuts] :HKLM C:\Users\Public\Desktop\Corel PHOTO-PAINT X7 (64-Bit).l
nk=c:\Windows\Installer\{C922F325-DD52-4E22-B204-431A06E63E51}\NewShortcut2_EBB5
1BFEE10948A888CB7ADF96E8EC80.exe
### C:\Users\Public\Desktop\CORELP~1.LNK
[User Shortcuts] :HKLM C:\Users\Public\Desktop\CorelDRAW X7 (64-Bit).lnk=c:\Wi
ndows\Installer\{2C0DDC74-5234-43DD-BB5A-0645B8FE5289}\NewShortcut1_68427AB8B2C0
44C58AA777A4C3F75634.exe
### C:\Users\Public\Desktop\CORELD~1.LNK
[User Shortcuts] :HKLM C:\Users\Public\Desktop\DameWare Mini Remote Control.ln
k=C:\Program Files (x86)\SolarWinds\DameWare Mini Remote Control 9.0\DWRCC.exe
### C:\Users\Public\Desktop\DAMEWA~2.LNK
[User Shortcuts] :HKLM C:\Users\Public\Desktop\EaseUS Data Recovery Wizard 7.5
.lnk=C:\Program Files (x86)\EaseUS\EaseUS Data Recovery Wizard\DRW.exe
### C:\Users\Public\Desktop\EASEUS~1.LNK
[User Shortcuts] :HKLM C:\Users\Public\Desktop\Foxit PhantomPDF.lnk=C:\Program
Files (x86)\Foxit Software\Foxit PhantomPDF\FoxitPhantomPDF.exe
### C:\Users\Public\Desktop\FOXITP~1.LNK
[User Shortcuts] :HKLM C:\Users\Public\Desktop\FREE Word and Excel password re
covery Wizard.lnk=C:\Program Files (x86)\FREE Word and Excel password recovery W
izard\FreeWordExcel.exe
### C:\Users\Public\Desktop\FREEWO~1.LNK
[User Shortcuts] :HKLM C:\Users\Public\Desktop\Free YouTube Downloader.lnk=C:\
Program Files (x86)\Free YouTube Downloader\YouTubeDownloader.exe
### C:\Users\Public\Desktop\FREEYO~1.LNK
[User Shortcuts] :HKLM C:\Users\Public\Desktop\Google Chrome.lnk=C:\Program Fi
les (x86)\Google\Chrome\Application\chrome.exe
### C:\Users\Public\Desktop\GOOGLE~1.LNK
[User Shortcuts] :HKLM C:\Users\Public\Desktop\ImTOO DVD Audio Ripper.lnk=C:\P
rogram Files (x86)\ImTOO\DVD Audio Ripper\drloader.exe
### C:\Users\Public\Desktop\IMTOOD~1.LNK
[User Shortcuts] :HKLM C:\Users\Public\Desktop\Intel(R) Driver Update Utility
2.4.lnk=C:\Program Files (x86)\Intel Driver Update Utility\DriverUpdateUI.exe
### C:\Users\Public\Desktop\INTEL(~1.LNK
[User Shortcuts] :HKLM C:\Users\Public\Desktop\iTunes.lnk=C:\Program Files (x8
6)\iTunes\iTunes.exe
### C:\Users\Public\Desktop\iTunes.lnk
[User Shortcuts] :HKLM C:\Users\Public\Desktop\iVMS-4000(v2.0).lnk=C:\Program
Files\iVMS-4000(v2.0)\NetAppSoft.exe
### C:\Users\Public\Desktop\IVMS-4~1.LNK
[User Shortcuts] :HKLM C:\Users\Public\Desktop\iVMS-4200 Client.lnk=C:\Program
Files (x86)\iVMS-4200 Station\iVMS-4200\iVMS-4200 Client\iVMS-4200.exe
### C:\Users\Public\Desktop\IVMS-4~2.LNK
[User Shortcuts] :HKLM C:\Users\Public\Desktop\LAN Speed Test.lnk=C:\Program F
iles (x86)\LAN Speed Test\LAN_SpeedTest.exe
### C:\Users\Public\Desktop\LANSPE~1.LNK
[User Shortcuts] :HKLM C:\Users\Public\Desktop\Magics 13.0 64bit.lnk=C:\Windo
ws\Installer\{78A136F4-6FC0-403E-8BFF-953063BD122C}\Magics.exe
### C:\Users\Public\Desktop\MAGICS~1.LNK
[User Shortcuts] :HKLM C:\Users\Public\Desktop\Meda MP3 Joiner.lnk=C:\Program
Files (x86)\Meda MP3 Joiner\MP3Joiner.exe
### C:\Users\Public\Desktop\MEDAMP~1.LNK
[User Shortcuts] :HKLM C:\Users\Public\Desktop\MiniMagics.lnk=C:\Program Files
(x86)\Materialise\MiniMagics\MiniMagics.exe
### C:\Users\Public\Desktop\MINIMA~1.LNK
[User Shortcuts] :HKLM C:\Users\Public\Desktop\MiniTool Partition Wizard Home
Edition.lnk=C:\Program Files (x86)\MiniTool Partition Wizard Home Edition 5.2\Pa
rtitionWizard.exe
### C:\Users\Public\Desktop\MINITO~2.LNK

[User Shortcuts] :HKLM C:\Users\Public\Desktop\MiniTool Partition Wizard Profe


ssional Edition.lnk=C:\Program Files (x86)\MiniTool Partition Wizard Professiona
l Edition 9.1\PartitionWizard.exe
### C:\Users\Public\Desktop\MINITO~4.LNK
[User Shortcuts] :HKLM C:\Users\Public\Desktop\MiniTool Partition Wizard Serve
r Edition.lnk=C:\Program Files (x86)\MiniTool Partition Wizard Server Edition 9.
1\PartitionWizard.exe
### C:\Users\Public\Desktop\MINITO~3.LNK
[User Shortcuts] :HKLM C:\Users\Public\Desktop\MiniTool Power Data Recovery 6.
8.lnk=C:\Program Files (x86)\PowerDataRecovery\PowerDataRecovery.exe
### C:\Users\Public\Desktop\MINITO~1.LNK
[User Shortcuts] :HKLM C:\Users\Public\Desktop\PowerISO.lnk=C:\Program Files (
x86)\PowerISO\PowerISO.exe
### C:\Users\Public\Desktop\PowerISO.lnk
[User Shortcuts] :HKLM C:\Users\Public\Desktop\QuickTime Player.lnk=C:\Program
Files (x86)\QuickTime\QuickTimePlayer.exe
### C:\Users\Public\Desktop\QUICKT~1.LNK
[User Shortcuts] :HKLM C:\Users\Public\Desktop\Rosetta Stone TOTALe.lnk=C:\Pro
gram Files (x86)\Rosetta Stone\Rosetta Stone TOTALe\RosettaStoneTOTALe.exe
### C:\Users\Public\Desktop\ROSETT~1.LNK
[User Shortcuts] :HKLM C:\Users\Public\Desktop\Samsung Kies (Lite).lnk=C:\Prog
ram Files (x86)\Samsung\Kies\KiesAgent.exe
### C:\Users\Public\Desktop\SAMSUN~2.LNK
[User Shortcuts] :HKLM C:\Users\Public\Desktop\Samsung Kies.lnk=C:\Program Fil
es (x86)\Samsung\Kies\KiesAgent.exe
### C:\Users\Public\Desktop\SAMSUN~1.LNK
[User Shortcuts] :HKLM C:\Users\Public\Desktop\Sony PC Companion 2.1.lnk=C:\Pr
ogram Files (x86)\Sony\Sony PC Companion\PCCompanion.exe
### C:\Users\Public\Desktop\SONYPC~1.LNK
[User Shortcuts] :HKLM C:\Users\Public\Desktop\SysTools XLSX Recovery.lnk=C:\P
rogram Files (x86)\SysTools XLSX Recovery\XLSXRecovery.exe
### C:\Users\Public\Desktop\SYSTOO~1.LNK
[User Shortcuts] :HKLM C:\Users\Public\Desktop\TeamViewer 9.lnk=C:\Program Fil
es (x86)\TeamViewer\Version9\TeamViewer.exe
### C:\Users\Public\Desktop\TEAMVI~1.LNK
[User Shortcuts] :HKLM C:\Users\Public\Desktop\UltraDefrag.lnk=C:\Program File
s (x86)\UltraDefrag\ultradefrag.exe
### C:\Users\Public\Desktop\ULTRAD~1.LNK
[User Shortcuts] :HKLM C:\Users\Public\Desktop\Video Download Capture.lnk=C:\P
rogram Files (x86)\Apowersoft\Video Download Capture\Video Download Capture.exe
### C:\Users\Public\Desktop\VIDEOD~1.LNK
[User Shortcuts] :HKLM C:\Users\Public\Desktop\VLC media player.lnk=C:\Program
Files (x86)\VideoLAN\VLC\vlc.exe
### C:\Users\Public\Desktop\VLCMED~1.LNK
[User Shortcuts] :HKLM C:\Users\Public\Desktop\VMware Workstation.lnk=C:\Progr
am Files (x86)\VMware\VMware Workstation\vmware.exe
### C:\Users\Public\Desktop\VMWARE~1.LNK
[User Shortcuts] :HKLM C:\Users\Public\Desktop\WD SmartWare.lnk=C:\Program Fil
es (x86)\Western Digital\WD SmartWare\WDSmartWare.exe
### C:\Users\Public\Desktop\WDSMAR~1.LNK
[User Shortcuts] :HKLM C:\Users\Public\Desktop\WinZip.lnk=C:\Program Files (x8
6)\WinZip\WINZIP64.EXE
### C:\Users\Public\Desktop\WinZip.lnk
[User Shortcuts] :HKLM C:\Users\Public\Desktop\YTD Video Downloader.lnk=C:\Pro
gram Files (x86)\GreenTree Applications\YTD Video Downloader\ytd.exe
### C:\Users\Public\Desktop\YTDVID~1.LNK
[User Shortcuts] :HKLM C:\Users\Public\Desktop\ZBrush 4R6.lnk=C:\Program Files
(x86)\Pixologic\ZBrush 4R6\ZBrush.exe
### C:\Users\Public\Desktop\ZBRUSH~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\AppData\Roaming\Microsoft\Internet Explo

rer\Quick Launch\BarahaIME.lnk=C:\Program Files (x86)\Baraha Software\Baraha 10\


BarahaIME.exe
### C:\Users\admin\AppData\Roaming\MICROS~1\INTERN~1\QUICKL~1\BARAHA~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\AppData\Roaming\Microsoft\Internet Explo
rer\Quick Launch\Foxit Advanced PDF Editor.lnk=C:\Program Files (x86)\Foxit Soft
ware\Foxit Advanced PDF Editor\Foxit Advanced PDF Editor.exe
### C:\Users\admin\AppData\Roaming\MICROS~1\INTERN~1\QUICKL~1\FOXITA~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\AppData\Roaming\Microsoft\Internet Explo
rer\Quick Launch\Google Chrome.lnk=C:\Program Files (x86)\Google\Chrome\Applicat
ion\chrome.exe
### C:\Users\admin\AppData\Roaming\MICROS~1\INTERN~1\QUICKL~1\GOOGLE~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\AppData\Roaming\Microsoft\Internet Explo
rer\Quick Launch\Launch Internet Explorer Browser.lnk=C:\Program Files (x86)\Int
ernet Explorer\iexplore.exe
### C:\Users\admin\AppData\Roaming\MICROS~1\INTERN~1\QUICKL~1\LAUNCH~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\AppData\Roaming\Microsoft\Internet Explo
rer\Quick Launch\Samsung Kies (Lite).lnk=C:\Program Files (x86)\Samsung\Kies\Kie
sAgent.exe
### C:\Users\admin\AppData\Roaming\MICROS~1\INTERN~1\QUICKL~1\SAMSUN~2.LNK
[User Shortcuts] :HKLM C:\Users\admin\AppData\Roaming\Microsoft\Internet Explo
rer\Quick Launch\Samsung Kies.lnk=C:\Program Files (x86)\Samsung\Kies\KiesAgent.
exe
### C:\Users\admin\AppData\Roaming\MICROS~1\INTERN~1\QUICKL~1\SAMSUN~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\AppData\Roaming\Microsoft\Internet Explo
rer\Quick Launch\Shows Desktop.lnk
### C:\Users\admin\AppData\Roaming\MICROS~1\INTERN~1\QUICKL~1\SHOWSD~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\AppData\Roaming\Microsoft\Internet Explo
rer\Quick Launch\UltraDefrag.lnk=C:\Program Files\UltraDefrag\ultradefrag.exe
### C:\Users\admin\AppData\Roaming\MICROS~1\INTERN~1\QUICKL~1\ULTRAD~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\AppData\Roaming\Microsoft\Internet Explo
rer\Quick Launch\User Pinned\ImplicitAppShortcuts\70f62c6a7f1739bd\pinned.lnk=C:
\Windows\System32\rundll32.exe
### C:\Users\admin\AppData\Roaming\MICROS~1\INTERN~1\QUICKL~1\USERPI~1\IMPLIC~
1\70F62C~1\pinned.lnk
[User Shortcuts] :HKLM C:\Users\admin\AppData\Roaming\Microsoft\Internet Explo
rer\Quick Launch\User Pinned\ImplicitAppShortcuts\7e4dca80246863e3\pinned.lnk=C:
\Windows\System32\control.exe
### C:\Users\admin\AppData\Roaming\MICROS~1\INTERN~1\QUICKL~1\USERPI~1\IMPLIC~
1\7E4DCA~1\pinned.lnk
[User Shortcuts] :HKLM C:\Users\admin\AppData\Roaming\Microsoft\Internet Explo
rer\Quick Launch\User Pinned\ImplicitAppShortcuts\9d78513a8998829c\pinned.lnk
### C:\Users\admin\AppData\Roaming\MICROS~1\INTERN~1\QUICKL~1\USERPI~1\IMPLIC~
1\9D7851~1\pinned.lnk
[User Shortcuts] :HKLM C:\Users\admin\AppData\Roaming\Microsoft\Internet Explo
rer\Quick Launch\User Pinned\StartMenu\DameWare Mini Remote Control.lnk=C:\Progr
am Files (x86)\SolarWinds\DameWare Mini Remote Control 9.0\DWRCC.exe
### C:\Users\admin\AppData\Roaming\MICROS~1\INTERN~1\QUICKL~1\USERPI~1\STARTM~
1\DAMEWA~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\AppData\Roaming\Microsoft\Internet Explo
rer\Quick Launch\User Pinned\StartMenu\Free Download Manager.lnk=C:\Program File
s (x86)\Free Download Manager\fdm.exe
### C:\Users\admin\AppData\Roaming\MICROS~1\INTERN~1\QUICKL~1\USERPI~1\STARTM~
1\FREEDO~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\AppData\Roaming\Microsoft\Internet Explo
rer\Quick Launch\User Pinned\StartMenu\Free YouTube Downloader.lnk=C:\Program Fi
les (x86)\Free YouTube Downloader\YouTubeDownloader.exe
### C:\Users\admin\AppData\Roaming\MICROS~1\INTERN~1\QUICKL~1\USERPI~1\STARTM~
1\FREEYO~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\AppData\Roaming\Microsoft\Internet Explo
rer\Quick Launch\User Pinned\StartMenu\Microsoft Office Word 2007.lnk=C:\Windows

\Installer\{90120000-0030-0000-0000-0000000FF1CE}\wordicon.exe
### C:\Users\admin\AppData\Roaming\MICROS~1\INTERN~1\QUICKL~1\USERPI~1\STARTM~
1\MICROS~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\AppData\Roaming\Microsoft\Internet Explo
rer\Quick Launch\User Pinned\StartMenu\Mozilla Firefox.lnk=C:\Program Files (x86
)\Mozilla Firefox\firefox.exe
### C:\Users\admin\AppData\Roaming\MICROS~1\INTERN~1\QUICKL~1\USERPI~1\STARTM~
1\MOZILL~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\AppData\Roaming\Microsoft\Internet Explo
rer\Quick Launch\User Pinned\TaskBar\Adobe Acrobat 7.0 Professional.lnk=C:\Windo
ws\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe
### C:\Users\admin\AppData\Roaming\MICROS~1\INTERN~1\QUICKL~1\USERPI~1\TaskBar
\ADOBEA~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\AppData\Roaming\Microsoft\Internet Explo
rer\Quick Launch\User Pinned\TaskBar\Dictionary.lnk=C:\Program Files (x86)\Shipr
a's Dictionary\dictN1.exe
### C:\Users\admin\AppData\Roaming\MICROS~1\INTERN~1\QUICKL~1\USERPI~1\TaskBar
\DICTIO~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\AppData\Roaming\Microsoft\Internet Explo
rer\Quick Launch\User Pinned\TaskBar\DLIMonkey.exe - Shortcut.lnk=C:\Users\admin
\Downloads\dlimonkey\bin\DLIMonkey.exe
### C:\Users\admin\AppData\Roaming\MICROS~1\INTERN~1\QUICKL~1\USERPI~1\TaskBar
\DLIMON~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\AppData\Roaming\Microsoft\Internet Explo
rer\Quick Launch\User Pinned\TaskBar\dmca CT.lnk=C:\Downloads\Software\GRAB DMCA
for CT\GRAB DMCA for CT\GRAB DMCA for CT.exe
### C:\Users\admin\AppData\Roaming\MICROS~1\INTERN~1\QUICKL~1\USERPI~1\TaskBar
\DMCACT~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\AppData\Roaming\Microsoft\Internet Explo
rer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk=C:\Program Files (x86)\Go
ogle\Chrome\Application\chrome.exe
### C:\Users\admin\AppData\Roaming\MICROS~1\INTERN~1\QUICKL~1\USERPI~1\TaskBar
\GOOGLE~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\AppData\Roaming\Microsoft\Internet Explo
rer\Quick Launch\User Pinned\TaskBar\Lenovo Slim USB Keyboard.lnk=C:\Program Fil
es (x86)\Lenovo\Lenovo Slim USB Keyboard\Skd8821.exe
### C:\Users\admin\AppData\Roaming\MICROS~1\INTERN~1\QUICKL~1\USERPI~1\TaskBar
\LENOVO~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\AppData\Roaming\Microsoft\Internet Explo
rer\Quick Launch\User Pinned\TaskBar\Meda MP3 Joiner.lnk=C:\Program Files (x86)\
Meda MP3 Joiner\MP3Joiner.exe
### C:\Users\admin\AppData\Roaming\MICROS~1\INTERN~1\QUICKL~1\USERPI~1\TaskBar
\MEDAMP~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\AppData\Roaming\Microsoft\Internet Explo
rer\Quick Launch\User Pinned\TaskBar\MiniTool Partition Wizard Professional Edit
ion.lnk=C:\Program Files (x86)\MiniTool Partition Wizard Professional Edition 9.
1\PartitionWizard.exe
### C:\Users\admin\AppData\Roaming\MICROS~1\INTERN~1\QUICKL~1\USERPI~1\TaskBar
\MINITO~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\AppData\Roaming\Microsoft\Internet Explo
rer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk=C:\Program Files (x86)\
Mozilla Firefox\firefox.exe
### C:\Users\admin\AppData\Roaming\MICROS~1\INTERN~1\QUICKL~1\USERPI~1\TaskBar
\MOZILL~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\AppData\Roaming\Microsoft\Internet Explo
rer\Quick Launch\User Pinned\TaskBar\Setup Factory setup launcher.lnk=C:\Users\a
dmin\Downloads\Shipradictionary.exe
### C:\Users\admin\AppData\Roaming\MICROS~1\INTERN~1\QUICKL~1\USERPI~1\TaskBar
\SETUPF~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\AppData\Roaming\Microsoft\Internet Explo

rer\Quick Launch\User Pinned\TaskBar\Snipping Tool.lnk=C:\Windows\system32\Snipp


ingTool.exe
### C:\Users\admin\AppData\Roaming\MICROS~1\INTERN~1\QUICKL~1\USERPI~1\TaskBar
\SNIPPI~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\AppData\Roaming\Microsoft\Internet Explo
rer\Quick Launch\User Pinned\TaskBar\udemy_ripper.exe - Shortcut.lnk=E:\pendrive
\Software\UDEMY RIPPER [LOADER] [WORK AROUND RANDOM COURSE DOWNLOAD]\UDEMY RIPPE
R [LOADER]\UDEMY RIPPER [LOADER]\udemy_ripper.exe
### C:\Users\admin\AppData\Roaming\MICROS~1\INTERN~1\QUICKL~1\USERPI~1\TaskBar
\UDEMY_~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\AppData\Roaming\Microsoft\Internet Explo
rer\Quick Launch\User Pinned\TaskBar\VLC media player.lnk=C:\Program Files (x86)
\VideoLAN\VLC\vlc.exe
### C:\Users\admin\AppData\Roaming\MICROS~1\INTERN~1\QUICKL~1\USERPI~1\TaskBar
\VLCMED~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\AppData\Roaming\Microsoft\Internet Explo
rer\Quick Launch\User Pinned\TaskBar\Windows Explorer.lnk=C:\Windows\explorer.ex
e
### C:\Users\admin\AppData\Roaming\MICROS~1\INTERN~1\QUICKL~1\USERPI~1\TaskBar
\WINDOW~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\AppData\Roaming\Microsoft\Internet Explo
rer\Quick Launch\User Pinned\TaskBar\Windows Media Player.lnk=C:\Program Files (
x86)\Windows Media Player\wmplayer.exe
### C:\Users\admin\AppData\Roaming\MICROS~1\INTERN~1\QUICKL~1\USERPI~1\TaskBar
\WINDOW~2.LNK
[User Shortcuts] :HKLM C:\Users\admin\AppData\Roaming\Microsoft\Internet Explo
rer\Quick Launch\User Pinned\TaskBar\YTD Video Downloader.lnk=C:\Program Files (
x86)\GreenTree Applications\YTD Video Downloader\ytd.exe
### C:\Users\admin\AppData\Roaming\MICROS~1\INTERN~1\QUICKL~1\USERPI~1\TaskBar
\YTDVID~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\AppData\Roaming\Microsoft\Internet Explo
rer\Quick Launch\Video Download Capture.lnk=C:\Program Files (x86)\Apowersoft\Vi
deo Download Capture\Video Download Capture.exe
### C:\Users\admin\AppData\Roaming\MICROS~1\INTERN~1\QUICKL~1\VIDEOD~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\AppData\Roaming\Microsoft\Internet Explo
rer\Quick Launch\VMware Workstation.lnk=C:\Program Files (x86)\VMware\VMware Wor
kstation\vmware.exe
### C:\Users\admin\AppData\Roaming\MICROS~1\INTERN~1\QUICKL~1\VMWARE~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\AppData\Roaming\Microsoft\Internet Explo
rer\Quick Launch\Window Switcher.lnk
### C:\Users\admin\AppData\Roaming\MICROS~1\INTERN~1\QUICKL~1\WINDOW~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\AppData\Roaming\Microsoft\Internet Explo
rer\Quick Launch\Wireshark.lnk=C:\Program Files\Wireshark\Wireshark.exe
### C:\Users\admin\AppData\Roaming\MICROS~1\INTERN~1\QUICKL~1\WIRESH~1.LNK
[Print Monitors] :HKLM Adobe PDF Port Monitor=C:\Windows\system32\ADOBEPDF.DLL
### Adobe PDF Port Monitor DLL Adobe Systems Inc Adobe Acrobat 11.0.0.305 Ad
obePDF.dll
[Print Monitors] :HKLM Bullzip PDF Print Monitor=C:\Windows\system32\BZPDF.DLL
### Bullzip PDF Writer Bullzip Bullzip PDF Writer 3.0.0.43 bzpdf.dll
[Print Monitors] :HKLM CNAB4 Monitor=C:\Windows\system32\CNAB4LMD.DLL
### Canon Advanced Printing Technology Language Monitor CANON INC. Canon Advan
ced Printing Technology 3.10.0.003 CNAB4LMD.DLL
[Print Monitors] :HKLM HPM1210LM=C:\Windows\system32\HPM1210LM.DLL
### HP Printer Language Monitor HP Printer Language Monitor 2012.0614.1.53479
HPM1210LM.DLL
[Print Monitors] :HKLM Local Port=C:\Windows\system32\LOCALSPL.DLL
### Local Spooler DLL Microsoft Corporation Microsoft Windows Operating System 6
.1.7600.16385 localspl.dll
[Print Monitors] :HKLM Microsoft Shared Fax Monitor=C:\Windows\system32\FXSMON
.DLL

### Microsoft Fax Print Monitor Microsoft Corporation Microsoft Windows Operati
ng System 6.1.7601.17514 FXSMON.DLL
[Print Monitors] :HKLM Standard TCP/IP Port=C:\Windows\system32\TCPMON.DLL
### Standard TCP/IP Port Monitor DLL Microsoft Corporation Microsoft Windows Ope
rating System 6.1.7600.16385 tcpmon.dll
[Print Monitors] :HKLM USB Monitor=C:\Windows\system32\USBMON.DLL
### Standard Dynamic Printing Port Monitor DLL Microsoft Corporation Microsoft
Windows Operating System 6.1.7600.16385 usbmon.dll
[Print Monitors] :HKLM Wondershare PDF Editor Monitor=C:\Windows\system32\WSMO
NEDITOR.DLL
### Wondershare Software PDF Converter 4.0.0.0 WSMonEditor.dll
[Print Monitors] :HKLM WSD Port=C:\Windows\system32\WSDMON.DLL
### WSD Printer Port Monitor Microsoft Corporation Microsoft Windows Operating S
ystem 6.1.7600.16385 WSDMon.dll
[Shell Icon Overlay Handlers] :HKLM EnhancedStorageShell=C:\WINDOWS\SYSTEM32\E
HSTORSHELL.DLL
### Windows Enhanced Storage Shell Extension DLL Microsoft Corporation Microso
ft Windows Operating System 6.1.7600.16385 %SystemRoot%\system32\EhStorShell.dll
[Shell Icon Overlay Handlers] :HKLM Groove Explorer Icon Overlay 1 (GFS Unread
Stub)=C:\PROGRA~2\MICROS~1\OFFICE12\GR469A~1.DLL
### GrooveShellExtensions Module Microsoft Corporation GrooveShellExtensions M
odule 4.2.0.2623
[Shell Icon Overlay Handlers] :HKLM Groove Explorer Icon Overlay 2 (GFS Stub)=
C:\PROGRA~2\MICROS~1\OFFICE12\GR469A~1.DLL
### GrooveShellExtensions Module Microsoft Corporation GrooveShellExtensions M
odule 4.2.0.2623
[Shell Icon Overlay Handlers] :HKLM Groove Explorer Icon Overlay 2.5 (GFS Unre
ad Folder)=C:\PROGRA~2\MICROS~1\OFFICE12\GR469A~1.DLL
### GrooveShellExtensions Module Microsoft Corporation GrooveShellExtensions M
odule 4.2.0.2623
[Shell Icon Overlay Handlers] :HKLM Groove Explorer Icon Overlay 3 (GFS Folder
)=C:\PROGRA~2\MICROS~1\OFFICE12\GR469A~1.DLL
### GrooveShellExtensions Module Microsoft Corporation GrooveShellExtensions M
odule 4.2.0.2623
[Shell Icon Overlay Handlers] :HKLM Groove Explorer Icon Overlay 4 (GFS Unread
Mark)=C:\PROGRA~2\MICROS~1\OFFICE12\GR469A~1.DLL
### GrooveShellExtensions Module Microsoft Corporation GrooveShellExtensions M
odule 4.2.0.2623
[Shell Icon Overlay Handlers] :HKLM SharingPrivate=C:\WINDOWS\SYSTEM32\NTSHRUI
.DLL
### Shell extensions for sharing Microsoft Corporation Microsoft Windows Operati
ng System 6.1.7600.16385 %SystemRoot%\system32\ntshrui.dll
[Context Menu Handlers] :HKLM 7-Zip=C:\PROGRAM FILES (X86)\7-ZIP\7-ZIP.DLL
### 7-Zip Shell Extension Igor Pavlov 7-Zip 9.20
[Context Menu Handlers] :HKLM Adobe.Acrobat.ContextMenu=C:\PROGRAM FILES (X86)
\ADOBE\ACROBAT 7.0\ACROBAT ELEMENTS\CONTEXTMENU.DLL
### Adobe Acrobat Context Menu Adobe Systems Inc. Adobe Acrobat Elements 7.0.0
.0\0
[Context Menu Handlers] :HKLM BriefcaseMenu=C:\WINDOWS\SYSTEM32\SYNCUI.DLL
### Windows Briefcase Microsoft Corporation Microsoft Windows Operating System 6
.1.7600.16385 %SystemRoot%\system32\syncui.dll
[Context Menu Handlers] :HKLM DMRC Shell Extension V2={358B5852-38EB-4549-9D8A
-B90C9DCAD0DB}
[Context Menu Handlers] :HKLM Foxit_ConvertToPDF={C5269811-4A29-4818-A4BB-111F
9FC63A5F}
[Context Menu Handlers] :HKLM Open With=C:\WINDOWS\SYSTEM32\SHELL32.DLL
### Windows Shell Common Dll Microsoft Corporation Microsoft Windows Operating S
ystem 6.1.7601.17514 %SystemRoot%\system32\shell32.dll
[Context Menu Handlers] :HKLM Open With EncryptionMenu=C:\WINDOWS\SYSTEM32\SHE
LL32.DLL

### Windows Shell Common Dll Microsoft Corporation Microsoft Windows Operating S
ystem 6.1.7601.17514 %SystemRoot%\system32\shell32.dll
[Context Menu Handlers] :HKLM Sharing=C:\WINDOWS\SYSTEM32\NTSHRUI.DLL
### Shell extensions for sharing Microsoft Corporation Microsoft Windows Operati
ng System 6.1.7600.16385 %SystemRoot%\system32\ntshrui.dll
[Context Menu Handlers] :HKLM TVCShellExt={4E33A7F5-8083-4C08-9D45-C5CED88F5C0
4}
[Context Menu Handlers] :HKLM WDBackupMenuHandler={C752BC82-C19A-4827-9C15-099
6BA85C180}
[Context Menu Handlers] :HKLM WinRAR={B41DB860-64E4-11D2-9906-E49FADC173CA}
[Context Menu Handlers] :HKLM WinRAR32=C:\PROGRAM FILES\WINRAR\RAREXT32.DLL
### WinRAR shell extension Alexander Roshal WinRAR 5.21.0
[Context Menu Handlers] :HKLM WinZip=C:\PROGRAM FILES\WINZIP\WZSHLSTB.DLL
### WinZip Shell Extension DLL WinZip Computing, S.L. WinZip 18.5 (10060)
[Context Menu Handlers] :HKLM XXX Groove GFS Context Menu Handler XXX=C:\PROGR
A~2\MICROS~1\OFFICE12\GR469A~1.DLL
### GrooveShellExtensions Module Microsoft Corporation GrooveShellExtensions M
odule 4.2.0.2623
[Context Menu Handlers] :HKLM {90AA3A4E-1CBA-4233-B8BB-535773D48449}=C:\WINDOW
S\SYSTEM32\SHELL32.DLL
### Windows Shell Common Dll Microsoft Corporation Microsoft Windows Operating S
ystem 6.1.7601.17514 %SystemRoot%\system32\shell32.dll
[Context Menu Handlers] :HKLM {a2a9545d-a0c2-42b4-9708-a0b2badd77c8}=C:\WINDOW
S\SYSTEM32\SHELL32.DLL
### Windows Shell Common Dll Microsoft Corporation Microsoft Windows Operating S
ystem 6.1.7601.17514 %SystemRoot%\system32\shell32.dll
[Context Menu Handlers] :HKLM {F764812A-132C-4013-9960-5CBBEB408A0E}=C:\PROGRA
M FILES (X86)\COMMON FILES\NERO\NEROSHELLEXT\NEROSHELLEXT.DLL
### Nero Burning ROM Shell Extension Nero AG NeroShellExt 12,0,20,0
[Kernel Auto Boot]
[ActiveSetup] >{22d6f312-b0f6-11d0-94ab-0080c74c7e95}=C:\WINDOWS\SYSTEM32\UNRE
GMP2.EXE
### Microsoft Windows Media Player Setup Utility Microsoft Corporation Microso
ft Windows Operating System 12.0.7600.16385 %SystemRoot%\system32\unregmp2.exe /S
howWMP
[Auto Services] AdobeARMservice
### Internal Name: AdobeARMservice. Status: service is running. Actual File: "
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe" * Adobe Acrobat Up
dater keeps your Adobe software up to date. Adobe Acrobat Update Service Adobe S
ystems Incorporated Adobe Acrobat Update Service 1.824.16.6751
[Auto Services] AudioEndpointBuilder
### Internal Name: AudioEndpointBuilder. Status: service is running. Actual Fi
le: C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted * Manages au
dio devices for the Windows Audio service. If this service is stopped, audio de
vices and effects will not function properly. If this service is disabled, any
services that explicitly depend on it will fail to start Host Process for Window
s Services Microsoft Corporation Microsoft Windows Operating System 6.1.7600.16385
[Auto Services] AudioSrv
### Internal Name: AudioSrv. Status: service is running. Actual File: C:\Windo
ws\System32\svchost.exe -k LocalServiceNetworkRestricted * Manages audio for Win
dows-based programs. If this service is stopped, audio devices and effects will
not function properly. If this service is disabled, any services that explicit
ly depend on it will fail to start Host Process for Windows Services Microsoft C
orporation Microsoft Windows Operating System 6.1.7600.16385
[Auto Services] BFE
### Internal Name: BFE. Status: service is running. Actual File: C:\Windows\sy
stem32\svchost.exe -k LocalServiceNoNetwork * The Base Filtering Engine (BFE) is
a service that manages firewall and Internet Protocol security (IPsec) policies
and implements user mode filtering. Stopping or disabling the BFE service will

significantly reduce the security of the system. It will also result in unpredic
table behavior in IPsec management and firewall applications. Host Process for W
indows Services Microsoft Corporation Microsoft Windows Operating System 6.1.7600.
16385
[Auto Services] BITS
### Internal Name: BITS. Status: service is running. Actual File: C:\Windows\S
ystem32\svchost.exe -k netsvcs * Transfers files in the background using idle ne
twork bandwidth. If the service is disabled, then any applications that depend o
n BITS, such as Windows Update or MSN Explorer, will be unable to automatically
download programs and other information. Host Process for Windows Services Micro
soft Corporation Microsoft Windows Operating System 6.1.7600.16385
[Auto Services] clr_optimization_v4.0.30319_32
### Internal Name: clr_optimization_v4.0.30319_32. Status: service stopped. Ac
tual File: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe * Microsof
t .NET Framework NGEN .NET Runtime Optimization Service Microsoft Corporation Mi
crosoft .NET Framework 4.0.30319.17929
[Auto Services] clr_optimization_v4.0.30319_64
### Internal Name: clr_optimization_v4.0.30319_64. Status: service stopped. Ac
tual File: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe * Micros
oft .NET Framework NGEN .NET Runtime Optimization Service Microsoft Corporation
Microsoft .NET Framework 4.0.30319.17929
[Auto Services] CryptSvc
### Internal Name: CryptSvc. Status: service is running. Actual File: C:\Windo
ws\system32\svchost.exe -k NetworkService * Provides four management services: C
atalog Database Service, which confirms the signatures of Windows files and allo
ws new programs to be installed; Protected Root Service, which adds and removes
Trusted Root Certification Authority certificates from this computer; Automatic
Root Certificate Update Service, which retrieves root certificates from Windows
Update and enable scenarios such as SSL; and Key Service, which helps enroll thi
s computer for certificates. If this service is stopped, these management servic
es will not function properly. If this service is disabled, any services that ex
plicitly depend on it will fail to start. Host Process for Windows Services Micr
osoft Corporation Microsoft Windows Operating System 6.1.7600.16385
[Auto Services] CscService
### Internal Name: CscService. Status: service is running. Actual File: C:\Win
dows\System32\svchost.exe -k LocalSystemNetworkRestricted * The Offline Files se
rvice performs maintenance activities on the Offline Files cache, responds to us
er logon and logoff events, implements the internals of the public API, and disp
atches interesting events to those interested in Offline Files activities and ch
anges in cache state. Host Process for Windows Services Microsoft Corporation Mi
crosoft Windows Operating System 6.1.7600.16385
[Auto Services] DcomLaunch
### Internal Name: DcomLaunch. Status: service is running. Actual File: C:\Win
dows\system32\svchost.exe -k DcomLaunch * The DCOMLAUNCH service launches COM an
d DCOM servers in response to object activation requests. If this service is sto
pped or disabled, programs using COM or DCOM will not function properly. It is s
trongly recommended that you have the DCOMLAUNCH service running. Host Process f
or Windows Services Microsoft Corporation Microsoft Windows Operating System 6.1.7
600.16385
[Auto Services] Dhcp
### Internal Name: Dhcp. Status: service is running. Actual File: C:\Windows\s
ystem32\svchost.exe -k LocalServiceNetworkRestricted * Registers and updates IP
addresses and DNS records for this computer. If this service is stopped, this co
mputer will not receive dynamic IP addresses and DNS updates. If this service is
disabled, any services that explicitly depend on it will fail to start. Host Pr
ocess for Windows Services Microsoft Corporation Microsoft Windows Operating Syste
m 6.1.7600.16385
[Auto Services] Dnscache
### Internal Name: Dnscache. Status: service is running. Actual File: C:\Windo
ws\system32\svchost.exe -k NetworkService * The DNS Client service (dnscache) ca

ches Domain Name System (DNS) names and registers the full computer name for thi
s computer. If the service is stopped, DNS names will continue to be resolved. H
owever, the results of DNS name queries will not be cached and the computer's na
me will not be registered. If the service is disabled, any services that explici
tly depend on it will fail to start. Host Process for Windows Services Microsoft
Corporation Microsoft Windows Operating System 6.1.7600.16385
[Auto Services] DPS
### Internal Name: DPS. Status: service is running. Actual File: C:\Windows\Sy
stem32\svchost.exe -k LocalServiceNoNetwork * The Diagnostic Policy Service enab
les problem detection, troubleshooting and resolution for Windows components. I
f this service is stopped, diagnostics will no longer function. Host Process for
Windows Services Microsoft Corporation Microsoft Windows Operating System 6.1.760
0.16385
[Auto Services] EFS
### Internal Name: EFS. Status: service is running. Actual File: C:\Windows\Sy
stem32\lsass.exe * Provides the core file encryption technology used to store en
crypted files on NTFS file system volumes. If this service is stopped or disable
d, applications will be unable to access encrypted files. Local Security Authori
ty Process Microsoft Corporation Microsoft Windows Operating System 6.1.7601.18443
[Auto Services] ESRV_SVC_WILLAMETTE
### Internal Name: ESRV_SVC_WILLAMETTE. Status: service is running. Actual Fil
e: "C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\esrv_svc.exe" "--AUTO_START" "--s
tart" "--address" "127.0.0.1" "--port" "49330" "--depend_on_key" "SYSTEM\Current
ControlSet\Services\ESRV_SVC_WILLAMETTE" "--depend_on_value" "run" "--time_in_ms
" "--pause" "5000" "--library" "C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\intel
_modeler.dll" "--no_pl" "--watchdog" "10" "--watchdog_cpu_usage_limit" "50" "--e
nd_on_error" "--kernel_priority_boost" "--shutdown_priority_boost" "--device_opt
ions" " time=no output=w output_folder='C:\ProgramData\Intel\SUR\WILLAMETTE\Inte
lData' limit_output_by=time output_limit=3600000 output_buffer=1024 il='C:\Progr
am Files\Intel\SUR\WILLAMETTE\ESRV\intel_process_input.dll','process_input_optio
ns.txt' il='C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\intel_system_power_state_
input.dll' il='C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\intel_quality_and_reli
ability_input.dll' il='C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\acpi_battery_i
nput.dll' il='C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\sema_thermal_input.dll'
il='C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\wifi_input.dll' il='C:\Program F
iles\Intel\SUR\WILLAMETTE\ESRV\devices_use_input.dll','service=yes' il='C:\Progr
am Files\Intel\SUR\WILLAMETTE\ESRV\intel_disktrace_input.dll','pause=60000 worki
ng_dir=C:\ProgramData\Intel\SUR\WILLAMETTE\IntelData override_existing_tracing=n
o limit_output_by_filesize_mb=10' os='C:\Program Files\Intel\SUR\WILLAMETTE\ESRV
\os_counters.txt' " * Intel(r) Energy Checker SDK. ESRV Service WILLAMETTE Inte
l(R) System Usage Report Intel(R) System Usage Report
[Auto Services] eventlog
### Internal Name: eventlog. Status: service is running. Actual File: C:\Windo
ws\System32\svchost.exe -k LocalServiceNetworkRestricted * This service manages
events and event logs. It supports logging events, querying events, subscribing
to events, archiving event logs, and managing event metadata. It can display eve
nts in both XML and plain text format. Stopping this service may compromise secu
rity and reliability of the system. Host Process for Windows Services Microsoft
Corporation Microsoft Windows Operating System 6.1.7600.16385
[Auto Services] EventSystem
### Internal Name: EventSystem. Status: service is running. Actual File: C:\Wi
ndows\system32\svchost.exe -k LocalService * Supports System Event Notification
Service (SENS), which provides automatic distribution of events to subscribing C
omponent Object Model (COM) components. If the service is stopped, SENS will clo
se and will not be able to provide logon and logoff notifications. If this servi
ce is disabled, any services that explicitly depend on it will fail to start. Ho
st Process for Windows Services Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385
[Auto Services] FontCache

### Internal Name: FontCache. Status: service is running. Actual File: C:\Wind
ows\system32\svchost.exe -k LocalService * Optimizes performance of applications
by caching commonly used font data. Applications will start this service if it
is not already running. It can be disabled, though doing so will degrade applica
tion performance. Host Process for Windows Services Microsoft Corporation Micros
oft Windows Operating System 6.1.7600.16385
[Auto Services] GoogleInputService
### Internal Name: GoogleInputService. Status: service is running. Actual File
: "C:\Program Files (x86)\Google\Google Input Tools\GoogleInputService.exe" * G
oogle Input Tools. Google Inc Google Input Tools 1.1.3.18
[Auto Services] gpsvc
### Internal Name: gpsvc. Status: service is running. Actual File: C:\Windows\
system32\svchost.exe -k netsvcs * The service is responsible for applying settin
gs configured by administrators for the computer and users through the Group Pol
icy component. If the service is stopped or disabled, the settings will not be a
pplied and applications and components will not be manageable through Group Poli
cy. Any components or applications that depend on the Group Policy component mig
ht not be functional if the service is stopped or disabled. Host Process for Win
dows Services Microsoft Corporation Microsoft Windows Operating System 6.1.7600.16
385
[Auto Services] gupdate
### Internal Name: gupdate. Status: service stopped. Actual File: "C:\Program
Files (x86)\Google\Update\GoogleUpdate.exe" /svc * Keeps your Google software up
to date. If this service is disabled or stopped, your Google software will not
be kept up to date, meaning security vulnerabilities that may arise cannot be fi
xed and features may not work. This service uninstalls itself when there is no G
oogle software using it. Google Installer Google Inc. Google Update 1.3.29.1
[Auto Services] IKEEXT
### Internal Name: IKEEXT. Status: service is running. Actual File: C:\Windows
\system32\svchost.exe -k netsvcs * The IKEEXT service hosts the Internet Key Exc
hange (IKE) and Authenticated Internet Protocol (AuthIP) keying modules. These k
eying modules are used for authentication and key exchange in Internet Protocol
security (IPsec). Stopping or disabling the IKEEXT service will disable IKE and
AuthIP key exchange with peer computers. IPsec is typically configured to use IK
E or AuthIP; therefore, stopping or disabling the IKEEXT service might result in
an IPsec failure and might compromise the security of the system. It is strongl
y recommended that you have the IKEEXT service running. Host Process for Windows
Services Microsoft Corporation Microsoft Windows Operating System 6.1.7600.16385
[Auto Services] iphlpsvc
### Internal Name: iphlpsvc. Status: service is running. Actual File: C:\Windo
ws\System32\svchost.exe -k NetSvcs * Provides tunnel connectivity using IPv6 tra
nsition technologies (6to4, ISATAP, Port Proxy, and Teredo), and IP-HTTPS. If th
is service is stopped, the computer will not have the enhanced connectivity bene
fits that these technologies offer. Host Process for Windows Services Microsoft
Corporation Microsoft Windows Operating System 6.1.7600.16385
[Auto Services] LanmanServer
### Internal Name: LanmanServer. Status: service is running. Actual File: C:\W
indows\system32\svchost.exe -k netsvcs * Supports file, print, and named-pipe sh
aring over the network for this computer. If this service is stopped, these func
tions will be unavailable. If this service is disabled, any services that explic
itly depend on it will fail to start. Host Process for Windows Services Microsof
t Corporation Microsoft Windows Operating System 6.1.7600.16385
[Auto Services] LanmanWorkstation
### Internal Name: LanmanWorkstation. Status: service is running. Actual File:
C:\Windows\System32\svchost.exe -k NetworkService * Creates and maintains clien
t network connections to remote servers using the SMB protocol. If this service
is stopped, these connections will be unavailable. If this service is disabled,
any services that explicitly depend on it will fail to start. Host Process for W
indows Services Microsoft Corporation Microsoft Windows Operating System 6.1.7600.
16385

[Auto Services] lmhosts


### Internal Name: lmhosts. Status: service is running. Actual File: C:\Window
s\system32\svchost.exe -k LocalServiceNetworkRestricted * Provides support for t
he NetBIOS over TCP/IP (NetBT) service and NetBIOS name resolution for clients o
n the network, therefore enabling users to share files, print, and log on to the
network. If this service is stopped, these functions might be unavailable. If t
his service is disabled, any services that explicitly depend on it will fail to
start. Host Process for Windows Services Microsoft Corporation Microsoft Windows O
perating System 6.1.7600.16385
[Auto Services] LMS
### Internal Name: LMS. Status: service is running. Actual File: C:\Program Fi
les (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe * Allows appli
cations to access the local Intel(R) Management and Security Application using i
ts locally-available selected network interfaces. Local Manageability Service In
tel Corporation Intel(R) Active Management Technology Local Manageability Servic
e 7.1.10.1065
[Auto Services] MatLocalLicenceServer50
### Internal Name: MatLocalLicenceServer50. Status: service is running. Actual
File: "C:\Program Files (x86)\Common Files\Materialise\LicenseFiles\LicSrv50.ex
e" * Materialise Local License Server 5.0 LicSrv MFC Application LicSrv Applicat
ion 5.0.0.5
[Auto Services] MMCSS
### Internal Name: MMCSS. Status: service stopped. Actual File: C:\Windows\sys
tem32\svchost.exe -k netsvcs * Enables relative prioritization of work based on
system-wide task priorities. This is intended mainly for multimedia applications
. If this service is stopped, individual tasks resort to their default priority
. Host Process for Windows Services Microsoft Corporation Microsoft Windows Operat
ing System 6.1.7600.16385
[Auto Services] MpsSvc
### Internal Name: MpsSvc. Status: service is running. Actual File: C:\Windows
\system32\svchost.exe -k LocalServiceNoNetwork * Windows Firewall helps protect
your computer by preventing unauthorized users from gaining access to your compu
ter through the Internet or a network. Host Process for Windows Services Microso
ft Corporation Microsoft Windows Operating System 6.1.7600.16385
[Auto Services] Net Driver HPZ12
### Internal Name: Net Driver HPZ12. Status: service is running. Actual File:
C:\Windows\System32\svchost.exe -k HPZ12 * Host Process for Windows Services Mi
crosoft Corporation Microsoft Windows Operating System 6.1.7600.16385
[Auto Services] Netlogon
### Internal Name: Netlogon. Status: service is running. Actual File: C:\Windo
ws\system32\lsass.exe * Maintains a secure channel between this computer and the
domain controller for authenticating users and services. If this service is sto
pped, the computer may not authenticate users and services and the domain contro
ller cannot register DNS records. If this service is disabled, any services that
explicitly depend on it will fail to start. Local Security Authority Process Mi
crosoft Corporation Microsoft Windows Operating System 6.1.7601.18443
[Auto Services] NlaSvc
### Internal Name: NlaSvc. Status: service is running. Actual File: C:\Windows
\System32\svchost.exe -k NetworkService * Collects and stores configuration info
rmation for the network and notifies programs when this information is modified.
If this service is stopped, configuration information might be unavailable. If
this service is disabled, any services that explicitly depend on it will fail to
start. Host Process for Windows Services Microsoft Corporation Microsoft Windows
Operating System 6.1.7600.16385
[Auto Services] nsi
### Internal Name: nsi. Status: service is running. Actual File: C:\Windows\sy
stem32\svchost.exe -k LocalService * This service delivers network notifications
(e.g. interface addition/deleting etc) to user mode clients. Stopping this serv
ice will cause loss of network connectivity. If this service is disabled, any ot
her services that explicitly depend on this service will fail to start. Host Pro

cess for Windows Services Microsoft Corporation Microsoft Windows Operating System
6.1.7600.16385
[Auto Services] PcaSvc
### Internal Name: PcaSvc. Status: service is running. Actual File: C:\Windows
\system32\svchost.exe -k LocalSystemNetworkRestricted * This service provides su
pport for the Program Compatibility Assistant (PCA). PCA monitors programs inst
alled and run by the user and detects known compatibility problems. If this serv
ice is stopped, PCA will not function properly. Host Process for Windows Service
s Microsoft Corporation Microsoft Windows Operating System 6.1.7600.16385
[Auto Services] PelService
### Internal Name: PelService. Status: service is running. Actual File: C:\Pro
gram Files\Lenovo\Lenovo Mouse Suite\PelService.exe *
[Auto Services] PlugPlay
### Internal Name: PlugPlay. Status: service is running. Actual File: C:\Windo
ws\system32\svchost.exe -k DcomLaunch * Enables a computer to recognize and adap
t to hardware changes with little or no user input. Stopping or disabling this s
ervice will result in system instability. Host Process for Windows Services Micr
osoft Corporation Microsoft Windows Operating System 6.1.7600.16385
[Auto Services] Pml Driver HPZ12
### Internal Name: Pml Driver HPZ12. Status: service is running. Actual File:
C:\Windows\System32\svchost.exe -k HPZ12 * Host Process for Windows Services Mi
crosoft Corporation Microsoft Windows Operating System 6.1.7600.16385
[Auto Services] Power
### Internal Name: Power. Status: service is running. Actual File: C:\Windows\
system32\svchost.exe -k DcomLaunch * Manages power policy and power policy notif
ication delivery. Host Process for Windows Services Microsoft Corporation Micros
oft Windows Operating System 6.1.7600.16385
[Auto Services] ProfSvc
### Internal Name: ProfSvc. Status: service is running. Actual File: C:\Window
s\system32\svchost.exe -k netsvcs * This service is responsible for loading and
unloading user profiles. If this service is stopped or disabled, users will no l
onger be able to successfully logon or logoff, applications may have problems ge
tting to users' data, and components registered to receive profile event notific
ations will not receive them. Host Process for Windows Services Microsoft Corpor
ation Microsoft Windows Operating System 6.1.7600.16385
[Auto Services] PSI_SVC_2_x64
### Internal Name: PSI_SVC_2_x64. Status: service is running. Actual File: "c:
\Program Files\Common Files\Protexis\License Service\PsiService_2.exe" * This se
rvice provides license-validation functionality for Corel Corporation. It is pow
ered by Protexis from arvato digital Services. PsiService PsiService arvato digi
tal services llc PsiService System Service 3.3.0.24
[Auto Services] RemoteRegistry
### Internal Name: RemoteRegistry. Status: service is running. Actual File: C:
\Windows\system32\svchost.exe -k regsvc * Enables remote users to modify registr
y settings on this computer. If this service is stopped, the registry can be mod
ified only by users on this computer. If this service is disabled, any services
that explicitly depend on it will fail to start. Host Process for Windows Servic
es Microsoft Corporation Microsoft Windows Operating System 6.1.7600.16385
[Auto Services] RosettaStoneDaemon
### Internal Name: RosettaStoneDaemon. Status: service is running. Actual File
: "C:\Program Files (x86)\RosettaStoneLtdServices\RosettaStoneDaemon.exe" * Ros
etta Stone Ltd. application Rosetta Stone Ltd. Rosetta Stone Daemon 1.0.1.0
[Auto Services] RpcEptMapper
### Internal Name: RpcEptMapper. Status: service is running. Actual File: C:\W
indows\system32\svchost.exe -k RPCSS * Resolves RPC interfaces identifiers to tr
ansport endpoints. If this service is stopped or disabled, programs using Remote
Procedure Call (RPC) services will not function properly. Host Process for Wind
ows Services Microsoft Corporation Microsoft Windows Operating System 6.1.7600.163
85
[Auto Services] RpcSs

### Internal Name: RpcSs. Status: service is running. Actual File: C:\Windows\
system32\svchost.exe -k rpcss * The RPCSS service is the Service Control Manager
for COM and DCOM servers. It performs object activations requests, object expor
ter resolutions and distributed garbage collection for COM and DCOM servers. If
this service is stopped or disabled, programs using COM or DCOM will not functio
n properly. It is strongly recommended that you have the RPCSS service running H
ost Process for Windows Services Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385
[Auto Services] SamSs
### Internal Name: SamSs. Status: service is running. Actual File: C:\Windows\
system32\lsass.exe * The startup of this service signals other services that the
Security Accounts Manager (SAM) is ready to accept requests. Disabling this se
rvice will prevent other services in the system from being notified when the SAM
is ready, which may in turn cause those services to fail to start correctly. Th
is service should not be disabled. Local Security Authority Process Microsoft Co
rporation Microsoft Windows Operating System 6.1.7601.18443
[Auto Services] Schedule
### Internal Name: Schedule. Status: service is running. Actual File: C:\Windo
ws\system32\svchost.exe -k netsvcs * Enables a user to configure and schedule au
tomated tasks on this computer. The service also hosts multiple Windows system-c
ritical tasks. If this service is stopped or disabled, these tasks will not be r
un at their scheduled times. If this service is disabled, any services that expl
icitly depend on it will fail to start. Host Process for Windows Services Micros
oft Corporation Microsoft Windows Operating System 6.1.7600.16385
[Auto Services] SENS
### Internal Name: SENS. Status: service is running. Actual File: C:\Windows\s
ystem32\svchost.exe -k netsvcs * Monitors system events and notifies subscribers
to COM+ Event System of these events. Host Process for Windows Services Microso
ft Corporation Microsoft Windows Operating System 6.1.7600.16385
[Auto Services] ShellHWDetection
### Internal Name: ShellHWDetection. Status: service is running. Actual File:
C:\Windows\System32\svchost.exe -k netsvcs * Provides notifications for AutoPlay
hardware events. Host Process for Windows Services Microsoft Corporation Micros
oft Windows Operating System 6.1.7600.16385
[Auto Services] Sks8821
### Internal Name: Sks8821. Status: service is running. Actual File: C:\Progra
m Files\Lenovo\Lenovo Slim USB Keyboard\Sks8821.exe *
[Auto Services] Spooler
### Internal Name: Spooler. Status: service is running. Actual File: C:\Window
s\System32\spoolsv.exe * Loads files to memory for later printing Spooler SubSys
tem App Microsoft Corporation Microsoft Windows Operating System 6.1.7600.16385
[Auto Services] stisvc
### Internal Name: stisvc. Status: service is running. Actual File: C:\Windows
\system32\svchost.exe -k imgsvc * Provides image acquisition services for scanne
rs and cameras Host Process for Windows Services Microsoft Corporation Microsoft
Windows Operating System 6.1.7600.16385
[Auto Services] SysMain
### Internal Name: SysMain. Status: service is running. Actual File: C:\Window
s\system32\svchost.exe -k LocalSystemNetworkRestricted * Maintains and improves
system performance over time. Host Process for Windows Services Microsoft Corpor
ation Microsoft Windows Operating System 6.1.7600.16385
[Auto Services] SystemUsageReportSvc_WILLAMETTE
### Internal Name: SystemUsageReportSvc_WILLAMETTE. Status: service is running
. Actual File: "C:\Program Files (x86)\Intel Driver Update Utility\SUR\SurSvc.ex
e" * Inte(R) System Usage Report Service SystemUsageReportSvc_WILLAMETTE monitor
s the computer system usage and helps to improve system's performance. Intel(R)
System Usage Report Intel(R) System Usage Report
[Auto Services] TeamViewer9
### Internal Name: TeamViewer9. Status: service is running. Actual File: "C:\P
rogram Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe" * TeamViewer Remo

te Software TeamViewer 9 TeamViewer GmbH TeamViewer 9.0


[Auto Services] Themes
### Internal Name: Themes. Status: service is running. Actual File: C:\Windows
\System32\svchost.exe -k netsvcs * Provides user experience theme management. Ho
st Process for Windows Services Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385
[Auto Services] TrkWks
### Internal Name: TrkWks. Status: service is running. Actual File: C:\Windows
\System32\svchost.exe -k LocalSystemNetworkRestricted * Maintains links between
NTFS files within a computer or across computers in a network. Host Process for
Windows Services Microsoft Corporation Microsoft Windows Operating System 6.1.7600
.16385
[Auto Services] UNS
### Internal Name: UNS. Status: service is running. Actual File: "C:\Program F
iles (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe" * Intel(R) M
anagement and Security Application User Notification Service - Updates the Windo
ws Event Log with notifications of pre defined events received from the local In
tel(R) Management and Security Application Device. User Notification Service Int
el Corporation Intel(R) Management and Security Application User Notification Se
rvice 7.1.10.1065
[Auto Services] UxSms
### Internal Name: UxSms. Status: service is running. Actual File: C:\Windows\
System32\svchost.exe -k LocalSystemNetworkRestricted * Provides Desktop Window M
anager startup and maintenance services Host Process for Windows Services Micros
oft Corporation Microsoft Windows Operating System 6.1.7600.16385
[Auto Services] VMAuthdService
### Internal Name: VMAuthdService. Status: service is running. Actual File: "C
:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe" * Authorizatio
n and authentication service for starting and accessing virtual machines. VMware
Authorization Service VMware, Inc. VMware Workstation 10.0.0 build-1295980
[Auto Services] VMnetDHCP
### Internal Name: VMnetDHCP. Status: service stopped. Actual File: C:\Windows
\system32\vmnetdhcp.exe * DHCP service for virtual networks.
[Auto Services] VMUSBArbService
### Internal Name: VMUSBArbService. Status: service is running. Actual File: "
C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe" * Arb
itration and enumeration of USB devices for virtual machines VMware USB Arbitrat
ion Service VMware, Inc. VMware USB Arbitration Service 12.1.10 build-1295349
[Auto Services] VMware NAT Service
### Internal Name: VMware NAT Service. Status: service stopped. Actual File: C
:\Windows\system32\vmnat.exe * Network address translation for virtual networks.
[Auto Services] VMwareHostd
### Internal Name: VMwareHostd. Status: service stopped. Actual File: "C:\Prog
ram Files (x86)\VMware\VMware Workstation\vmware-hostd.exe" -u "C:\ProgramData\V
Mware\hostd\config.xml" * Remote access service for registration and management
of virtual machines.
[Auto Services] WDBackup
### Internal Name: WDBackup. Status: service stopped. Actual File: "C:\Program
Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe" * WD SmartWare Bac
kup Engine WD Backup Engine Western Digital Technologies, Inc. WD SmartWare 2.0.
0.15
[Auto Services] Winmgmt
### Internal Name: Winmgmt. Status: service is running. Actual File: C:\Window
s\system32\svchost.exe -k netsvcs * Provides a common interface and object model
to access management information about operating system, devices, applications
and services. If this service is stopped, most Windows-based software will not f
unction properly. If this service is disabled, any services that explicitly depe
nd on it will fail to start. Host Process for Windows Services Microsoft Corpora
tion Microsoft Windows Operating System 6.1.7600.16385

[Auto Services] WSearch


### Internal Name: WSearch. Status: service is running. Actual File: C:\Window
s\system32\SearchIndexer.exe /Embedding * Provides content indexing, property ca
ching, and search results for files, e-mail, and other content. Microsoft Window
s Search Indexer Microsoft Corporation Windows Search 7.00.7600.16385
[Auto Services] wudfsvc
### Internal Name: wudfsvc. Status: service is running. Actual File: C:\Window
s\system32\svchost.exe -k LocalSystemNetworkRestricted * Manages user-mode drive
r host processes. Host Process for Windows Services Microsoft Corporation Micros
oft Windows Operating System 6.1.7600.16385
[Keyboard Listeners] E020044B=C:\Windows\system32\GOOGLEINPUTTOOLS.IME
### Google Input Tools Google Inc. Google Input Tools 1.1.3.18 GoogleInputToo
ls.ime
[Keyboard Listeners] E0210439=C:\Windows\system32\GOOGLEINPUTTOOLS.IME
### Google Input Tools Google Inc. Google Input Tools 1.1.3.18 GoogleInputToo
ls.ime
[Svchost DLLs] :HKLM AeLookupSvc=C:\WINDOWS\SYSTEM32\AELUPSVC.DLL
### Application Experience Service Microsoft Corporation Microsoft Windows Opera
ting System 6.1.7600.16385 %SystemRoot%\System32\aelupsvc.dll
[Svchost DLLs] :HKLM CertPropSvc=C:\WINDOWS\SYSTEM32\CERTPROP.DLL
### Microsoft Smartcard Certificate Propagation Service Microsoft Corporation
Microsoft Windows Operating System 6.1.7600.16385 %SystemRoot%\System32\certprop.
dll
[Svchost DLLs] :HKLM SCPolicySvc=C:\WINDOWS\SYSTEM32\CERTPROP.DLL
### Microsoft Smartcard Certificate Propagation Service Microsoft Corporation
Microsoft Windows Operating System 6.1.7600.16385 %SystemRoot%\System32\certprop.
dll
[Svchost DLLs] :HKLM lanmanserver=C:\WINDOWS\SYSTEM32\SRVSVC.DLL
### Server Service DLL Microsoft Corporation Microsoft Windows Operating System
6.1.7600.16385 %SystemRoot%\system32\srvsvc.dll
[Svchost DLLs] :HKLM gpsvc=C:\WINDOWS\SYSTEM32\GPSVC.DLL
### Group Policy Client Microsoft Corporation Microsoft Windows Operating System
6.1.7600.16385 %SystemRoot%\System32\gpsvc.dll
[Svchost DLLs] :HKLM AudioSrv=C:\WINDOWS\SYSTEM32\AUDIOSRV.DLL
### Windows Audio Service Microsoft Corporation Microsoft Windows Operating Syst
em 6.1.7600.16385 %SystemRoot%\System32\Audiosrv.dll
[Svchost DLLs] :HKLM FastUserSwitchingCompatibility
[Svchost DLLs] :HKLM Ias
[Svchost DLLs] :HKLM Irmon
[Svchost DLLs] :HKLM Nla
[Svchost DLLs] :HKLM Ntmssvc
[Svchost DLLs] :HKLM NWCWorkstation
[Svchost DLLs] :HKLM Nwsapagent
[Svchost DLLs] :HKLM Rasauto=C:\WINDOWS\SYSTEM32\RASAUTO.DLL
### Remote Access AutoDial Manager Microsoft Corporation Microsoft Windows Opera
ting System 6.1.7600.16385 %SystemRoot%\System32\rasauto.dll
[Svchost DLLs] :HKLM Rasman=C:\WINDOWS\SYSTEM32\RASMANS.DLL
### Remote Access Connection Manager Microsoft Corporation Microsoft Windows Ope
rating System 6.1.7600.16385 %SystemRoot%\System32\rasmans.dll
[Svchost DLLs] :HKLM Remoteaccess=C:\WINDOWS\SYSTEM32\MPRDIM.DLL
### Dynamic Interface Manager Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385 %SystemRoot%\System32\mprdim.dll
[Svchost DLLs] :HKLM SENS=C:\WINDOWS\SYSTEM32\SENS.DLL
### System Event Notification Service (SENS) Microsoft Corporation Microsoft Wi
ndows Operating System 6.1.7600.16385 %SystemRoot%\System32\sens.dll
[Svchost DLLs] :HKLM Sharedaccess=C:\WINDOWS\SYSTEM32\IPNATHLP.DLL
### Microsoft NAT Helper Components Microsoft Corporation Microsoft Windows Oper
ating System 6.1.7600.16385 %SystemRoot%\System32\ipnathlp.dll
[Svchost DLLs] :HKLM SRService
[Svchost DLLs] :HKLM Tapisrv=C:\WINDOWS\SYSTEM32\TAPISRV.DLL

### Microsoft Windows(TM) Telephony Server Microsoft Corporation Microsoft Windo


ws Operating System 6.1.7600.16385 %SystemRoot%\System32\tapisrv.dll
[Svchost DLLs] :HKLM Wmi
[Svchost DLLs] :HKLM WmdmPmSp
[Svchost DLLs] :HKLM TermService=C:\WINDOWS\SYSTEM32\TERMSRV.DLL
### Remote Desktop Session Host Server Remote Connections Manager Microsoft Co
rporation Microsoft Windows Operating System 6.1.7601.17514 %SystemRoot%\System32
\termsrv.dll
[Svchost DLLs] :HKLM wuauserv=C:\WINDOWS\SYSTEM32\WUAUENG.DLL
### Windows Update Agent Microsoft Corporation Microsoft Windows Operating Syste
m 7.6.7600.256 %systemroot%\system32\wuaueng.dll
[Svchost DLLs] :HKLM BITS=C:\WINDOWS\SYSTEM32\QMGR.DLL
### Background Intelligent Transfer Service Microsoft Corporation Microsoft Win
dows Operating System 7.5.7600.16385 %SystemRoot%\System32\qmgr.dll
[Svchost DLLs] :HKLM ShellHWDetection=C:\WINDOWS\SYSTEM32\SHSVCS.DLL
### Windows Shell Services Dll Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385 %SystemRoot%\System32\shsvcs.dll
[Svchost DLLs] :HKLM LogonHours
[Svchost DLLs] :HKLM PCAudit
[Svchost DLLs] :HKLM helpsvc
[Svchost DLLs] :HKLM uploadmgr
[Svchost DLLs] :HKLM iphlpsvc=C:\WINDOWS\SYSTEM32\IPHLPSVC.DLL
### Service that offers IPv6 connectivity over an IPv4 network. Microsoft Corp
oration Microsoft Windows Operating System 6.1.7600.16385 %SystemRoot%\System32\i
phlpsvc.dll
[Svchost DLLs] :HKLM msiscsi=C:\WINDOWS\SYSTEM32\ISCSIEXE.DLL
### iSCSI Discovery service Microsoft Corporation Microsoft Windows Operating Sy
stem 6.1.7600.16385 %systemroot%\system32\iscsiexe.dll
[Svchost DLLs] :HKLM schedule=C:\WINDOWS\SYSTEM32\SCHEDSVC.DLL
### Task Scheduler Service Microsoft Corporation Microsoft Windows Operating Sys
tem 6.1.7600.16385 %systemroot%\system32\schedsvc.dll
[Svchost DLLs] :HKLM SessionEnv=C:\WINDOWS\SYSTEM32\SESSENV.DLL
### Remote Desktop Configuration service Microsoft Corporation Microsoft Window
s Operating System 6.1.7600.16385 %SystemRoot%\system32\sessenv.dll
[Svchost DLLs] :HKLM winmgmt=C:\WINDOWS\SYSTEM32\WBEM\WMISVC.DLL
### WMI Microsoft Corporation Microsoft Windows Operating System 6.1.7600.16385
%SystemRoot%\system32\wbem\WMIsvc.dll
[Svchost DLLs] :HKLM AppMgmt=C:\WINDOWS\SYSTEM32\APPMGMTS.DLL
### Software installation Service Microsoft Corporation Microsoft Windows Operat
ing System 6.1.7600.16385 %SystemRoot%\System32\appmgmts.dll
[Svchost DLLs] :HKLM RemoteRegistry=C:\WINDOWS\SYSTEM32\REGSVC.DLL
### Remote Registry Service Microsoft Corporation Microsoft Windows Operating Sy
stem 6.1.7600.16385 %SystemRoot%\system32\regsvc.dll
[Svchost DLLs] :HKLM WinHttpAutoProxySvc=C:\Windows\system32\WINHTTP.DLL
### Windows HTTP Services Microsoft Corporation Microsoft Windows Operating Syst
em 6.1.7600.16385 winhttp.dll
[Svchost DLLs] :HKLM sppuinotify=C:\WINDOWS\SYSTEM32\SPPUINOTIFY.DLL
### SPP Notification Service Microsoft Corporation Microsoft Windows Operating S
ystem 6.1.7600.16385 %SystemRoot%\system32\sppuinotify.dll
[Svchost DLLs] :HKLM netprofm=C:\WINDOWS\SYSTEM32\NETPROFM.DLL
### Network List Manager Microsoft Corporation Microsoft Windows Operating Syste
m 6.1.7600.16385 %SystemRoot%\System32\netprofm.dll
[Svchost DLLs] :HKLM WebClient=C:\WINDOWS\SYSTEM32\WEBCLNT.DLL
### Web DAV Service DLL Microsoft Corporation Microsoft Windows Operating System
6.1.7600.16385 %SystemRoot%\System32\webclnt.dll
[Svchost DLLs] :HKLM Netman=C:\WINDOWS\SYSTEM32\NETMAN.DLL
### Network Connections Manager Microsoft Corporation Microsoft Windows Operatin
g System 6.1.7600.16385 %SystemRoot%\System32\netman.dll
[Svchost DLLs] :HKLM AudioEndpointBuilder=C:\WINDOWS\SYSTEM32\AUDIOSRV.DLL
### Windows Audio Service Microsoft Corporation Microsoft Windows Operating Syst

em 6.1.7600.16385 %SystemRoot%\System32\Audiosrv.dll
[Svchost DLLs] :HKLM dot3svc=C:\WINDOWS\SYSTEM32\DOT3SVC.DLL
### Wired AutoConfig Service Microsoft Corporation Microsoft Windows Operating S
ystem 6.1.7600.16385 %SystemRoot%\System32\dot3svc.dll
[Svchost DLLs] :HKLM WPDBusEnum=C:\WINDOWS\SYSTEM32\WPDBUSENUM.DLL
### Portable Device Enumerator Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385 %SystemRoot%\system32\wpdbusenum.dll
[Svchost DLLs] :HKLM wlansvc=C:\WINDOWS\SYSTEM32\WLANSVC.DLL
### Windows WLAN AutoConfig Service DLL Microsoft Corporation Microsoft Windows
Operating System 6.1.7600.16385 %SystemRoot%\System32\wlansvc.dll
[Svchost DLLs] :HKLM PLA=C:\WINDOWS\SYSTEM32\PLA.DLL
### Performance Logs & Alerts Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385 %systemroot%\system32\pla.dll
[Svchost DLLs] :HKLM RpcSs=C:\WINDOWS\SYSTEM32\RPCSS.DLL
### Distributed COM Services Microsoft Corporation Microsoft Windows Operating S
ystem 6.1.7601.17514 %SystemRoot%\system32\rpcss.dll
[Svchost DLLs] :HKLM BthHFSrv
[Svchost DLLs] :HKLM LmHosts=C:\WINDOWS\SYSTEM32\LMHSVC.DLL
### TCPIP NetBios Transport Services DLL Microsoft Corporation Microsoft Window
s Operating System 6.1.7600.16385 %SystemRoot%\System32\lmhsvc.dll
[Svchost DLLs] :HKLM wscsvc=C:\WINDOWS\SYSTEM32\WSCSVC.DLL
### Windows Security Center Service Microsoft Corporation Microsoft Windows Oper
ating System 6.1.7600.16385 %SystemRoot%\System32\wscsvc.dll
[Svchost DLLs] :HKLM WPCSvc=C:\WINDOWS\SYSTEM32\WPCSVC.DLL
### WPC Filtering Service Microsoft Corporation Windows 1.0.0.1 %SystemRoot%\
System32\wpcsvc.dll
[Svchost DLLs] :HKLM SSDPSRV=C:\WINDOWS\SYSTEM32\SSDPSRV.DLL
### SSDP Service DLL Microsoft Corporation Microsoft Windows Operating System 6.
1.7600.16385 %SystemRoot%\System32\ssdpsrv.dll
[Svchost DLLs] :HKLM upnphost=C:\WINDOWS\SYSTEM32\UPNPHOST.DLL
### UPnP Device Host Microsoft Corporation Microsoft Windows Operating System 6.
1.7600.16385 %SystemRoot%\System32\upnphost.dll
[Svchost DLLs] :HKLM SCardSvr=C:\WINDOWS\SYSTEM32\SCARDSVR.DLL
### Smart Card Resource Management Server Microsoft Corporation Microsoft Windo
ws Operating System 6.1.7600.16385 %SystemRoot%\System32\SCardSvr.dll
[Svchost DLLs] :HKLM TBS=C:\WINDOWS\SYSTEM32\TBSSVC.DLL
### TBS Service Microsoft Corporation Microsoft Windows Operating System 6.1.760
0.16385 %SystemRoot%\System32\tbssvc.dll
[Svchost DLLs] :HKLM QWAVE=C:\WINDOWS\SYSTEM32\QWAVE.DLL
### Windows NT Microsoft Corporation Microsoft Windows Operating System 6.1.7600
.16385 %windir%\system32\qwave.dll
[Svchost DLLs] :HKLM wcncsvc=C:\WINDOWS\SYSTEM32\WCNCSVC.DLL
### Windows Connect Now - Config Registrar Service Microsoft Corporation Micro
soft Windows Operating System 6.1.7600.16385 %SystemRoot%\System32\wcncsvc.dll
[Svchost DLLs] :HKLM Power=C:\WINDOWS\SYSTEM32\UMPO.DLL
### User-mode Power Service Microsoft Corporation Microsoft Windows Operating Sy
stem 6.1.7600.16385 %SystemRoot%\system32\umpo.dll
[Svchost DLLs] :HKLM PlugPlay=C:\WINDOWS\SYSTEM32\UMPNPMGR.DLL
### User-mode Plug-and-Play Service Microsoft Corporation Microsoft Windows Oper
ating System 6.1.7600.16385 %SystemRoot%\system32\umpnpmgr.dll
[Svchost DLLs] :HKLM DcomLaunch=C:\WINDOWS\SYSTEM32\RPCSS.DLL
### Distributed COM Services Microsoft Corporation Microsoft Windows Operating S
ystem 6.1.7601.17514 %SystemRoot%\system32\rpcss.dll
[Svchost DLLs] :HKLM CryptSvc=C:\WINDOWS\SYSTEM32\CRYPTSVC.DLL
### Cryptographic Services Microsoft Corporation Microsoft Windows Operating Sys
tem 6.1.7600.16385 %SystemRoot%\system32\cryptsvc.dll
[Svchost DLLs] :HKLM DHCP=C:\WINDOWS\SYSTEM32\DHCPCORE.DLL
### DHCP Client Service Microsoft Corporation Microsoft Windows Operating System
6.1.7601.17514 %SystemRoot%\system32\dhcpcore.dll
[Svchost DLLs] :HKLM DNSCache=C:\WINDOWS\SYSTEM32\DNSRSLVR.DLL

### DNS Caching Resolver Service Microsoft Corporation Microsoft Windows Operati
ng System 6.1.7600.16385 %SystemRoot%\System32\dnsrslvr.dll
[Svchost DLLs] :HKLM NapAgent=C:\WINDOWS\SYSTEM32\QAGENTRT.DLL
### Quarantine Agent Service Run-Time Microsoft Corporation Microsoft Windows Op
erating System 6.1.7600.16385 %SystemRoot%\system32\qagentRT.dll
[Svchost DLLs] :HKLM nlasvc=C:\WINDOWS\SYSTEM32\NLASVC.DLL
### Network Location Awareness 2 Microsoft Corporation Microsoft Windows Operati
ng System 6.1.7600.16385 %SystemRoot%\System32\nlasvc.dll
[Svchost DLLs] :HKLM WinRM=C:\WINDOWS\SYSTEM32\WSMSVC.DLL
### WSMan Service Microsoft Corporation Microsoft Windows Operating System 6.1.7
600.16385 %SystemRoot%\system32\WsmSvc.dll
[Svchost DLLs] :HKLM WECSVC=C:\WINDOWS\SYSTEM32\WECSVC.DLL
### Event Collector Service Microsoft Corporation Microsoft Windows Operating Sy
stem 6.1.7600.16385 %SystemRoot%\system32\wecsvc.dll
[Svchost DLLs] :HKLM StiSvc=C:\WINDOWS\SYSTEM32\WIASERVC.DLL
### Still Image Devices Service Microsoft Corporation Microsoft Windows Operatin
g System 6.1.7600.16385 %SystemRoot%\System32\wiaservc.dll
[Svchost DLLs] :HKLM WcsPlugInService=C:\WINDOWS\SYSTEM32\WCSPLUGINSERVICE.DLL
### WcsPlugInService DLL Microsoft Corporation Microsoft Windows Operating Syste
m 6.1.7600.16385 %SystemRoot%\System32\WcsPlugInService.dll
[Svchost DLLs] :HKLM AppIDSvc=C:\WINDOWS\SYSTEM32\APPIDSVC.DLL
### Application Identity Service Microsoft Corporation Microsoft Windows Operati
ng System 6.1.7600.16385 %SystemRoot%\System32\appidsvc.dll
[Svchost DLLs] :HKLM Appinfo=C:\WINDOWS\SYSTEM32\APPINFO.DLL
### Application Information Service Microsoft Corporation Microsoft Windows Oper
ating System 6.1.7600.16385 %SystemRoot%\System32\appinfo.dll
[Svchost DLLs] :HKLM AxInstSV=C:\WINDOWS\SYSTEM32\AXINSTSV.DLL
### ActiveX Installer Service Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385 %SystemRoot%\System32\AxInstSV.dll
[Svchost DLLs] :HKLM BDESVC=C:\WINDOWS\SYSTEM32\BDESVC.DLL
### BDE Service Microsoft Corporation Microsoft Windows Operating System 6.1.760
0.16385 %SystemRoot%\System32\bdesvc.dll
[Svchost DLLs] :HKLM BFE=C:\WINDOWS\SYSTEM32\BFE.DLL
### Base Filtering Engine Microsoft Corporation Microsoft Windows Operating Syst
em 6.1.7600.16385 %SystemRoot%\System32\bfe.dll
[Svchost DLLs] :HKLM Browser=C:\WINDOWS\SYSTEM32\BROWSER.DLL
### Computer Browser Service DLL Microsoft Corporation Microsoft Windows Operati
ng System 6.1.7600.16385 %SystemRoot%\System32\browser.dll
[Svchost DLLs] :HKLM bthserv=C:\WINDOWS\SYSTEM32\BTHSERV.DLL
### Bluetooth Support Service Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385 %SystemRoot%\system32\bthserv.dll
[Svchost DLLs] :HKLM CscService=C:\WINDOWS\SYSTEM32\CSCSVC.DLL
### CSC Service DLL Microsoft Corporation Microsoft Windows Operating System 6.1
.7600.16385 %SystemRoot%\System32\cscsvc.dll
[Svchost DLLs] :HKLM defragsvc=C:\WINDOWS\SYSTEM32\DEFRAGSVC.DLL
### Microsoft\Disk Defragmenter Microsoft Corporation Microsoft Windows Operatin
g System 6.1.7600.16385 %Systemroot%\System32\defragsvc.dll
[Svchost DLLs] :HKLM DPS=C:\WINDOWS\SYSTEM32\DPS.DLL
### WDI Diagnostic Policy Service Microsoft Corporation Microsoft Windows Operat
ing System 6.1.7600.16385 %SystemRoot%\system32\dps.dll
[Svchost DLLs] :HKLM EapHost=C:\WINDOWS\SYSTEM32\EAPSVC.DLL
### Microsoft EAPHost service Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385 %SystemRoot%\System32\eapsvc.dll
[Svchost DLLs] :HKLM EventSystem=C:\WINDOWS\SYSTEM32\ES.DLL
### COM+ Microsoft Corporation Microsoft Windows Operating System 6.1.7600.16385
%systemroot%\system32\es.dll
[Svchost DLLs] :HKLM fdPHost=C:\WINDOWS\SYSTEM32\FDPHOST.DLL
### Function Discovery Provider host service Microsoft Corporation Microsoft Wi
ndows Operating System 6.1.7600.16385 %SystemRoot%\system32\fdPHost.dll
[Svchost DLLs] :HKLM FDResPub=C:\WINDOWS\SYSTEM32\FDRESPUB.DLL

### Function Discovery Resource Publication Service Microsoft Corporation Micr


osoft Windows Operating System 6.1.7600.16385 %SystemRoot%\system32\fdrespub.dll
[Svchost DLLs] :HKLM FontCache=C:\WINDOWS\SYSTEM32\FNTCACHE.DLL
### Windows Font Cache Service Microsoft Corporation Microsoft Windows Operating
System 6.2.9200.16492 %SystemRoot%\system32\FntCache.dll
[Svchost DLLs] :HKLM hidserv=C:\WINDOWS\SYSTEM32\HIDSERV.DLL
### HID Service Microsoft Corporation Microsoft Windows Operating System 6.1.760
0.16385 %SystemRoot%\system32\hidserv.dll
[Svchost DLLs] :HKLM hkmsvc=C:\WINDOWS\SYSTEM32\KMSVC.DLL
### Key Management Service Microsoft Corporation Microsoft Windows Operating Sys
tem 6.1.7600.16385 %SystemRoot%\system32\kmsvc.dll
[Svchost DLLs] :HKLM HomeGroupListener=C:\WINDOWS\SYSTEM32\LISTSVC.DLL
### Windows HomeGroup Microsoft Corporation Microsoft Windows Operating System 6
.1.7600.16385 %SystemRoot%\system32\ListSvc.dll
[Svchost DLLs] :HKLM HomeGroupProvider=C:\WINDOWS\SYSTEM32\PROVSVC.DLL
### Windows HomeGroup Microsoft Corporation Microsoft Windows Operating System 6
.1.7600.16385 %SystemRoot%\system32\provsvc.dll
[Svchost DLLs] :HKLM IKEEXT=C:\WINDOWS\SYSTEM32\IKEEXT.DLL
### IKE extension Microsoft Corporation Microsoft Windows Operating System 6.1.7
600.16385 %SystemRoot%\System32\ikeext.dll
[Svchost DLLs] :HKLM IPBusEnum=C:\WINDOWS\SYSTEM32\IPBUSENUM.DLL
### PnP-X IP Bus Enumerator DLL Microsoft Corporation Microsoft Windows Operatin
g System 6.1.7600.16385 %SystemRoot%\system32\ipbusenum.dll
[Svchost DLLs] :HKLM KtmRm=C:\WINDOWS\SYSTEM32\MSDTCKRM.DLL
### Microsoft Distributed Transaction Coordinator OLE Transactions KTM Resourc
e Manager DLL Microsoft Corporation Microsoft Windows Operating System 6.1.7600.16
385 %systemroot%\system32\msdtckrm.dll
[Svchost DLLs] :HKLM LanmanWorkstation=C:\WINDOWS\SYSTEM32\WKSSVC.DLL
### Workstation Service DLL Microsoft Corporation Microsoft Windows Operating Sy
stem 6.1.7600.16385 %SystemRoot%\System32\wkssvc.dll
[Svchost DLLs] :HKLM lltdsvc=C:\WINDOWS\SYSTEM32\LLTDSVC.DLL
### Link-Layer Topology Mapper Service Microsoft Corporation Microsoft Windows O
perating System 6.1.7600.16385 %SystemRoot%\System32\lltdsvc.dll
[Svchost DLLs] :HKLM Mcx2Svc=C:\WINDOWS\SYSTEM32\MCX2SVC.DLL
### Media Center Extender Service Microsoft Corporation Microsoft Windows Operat
ing System 6.1.7601.17514 %SystemRoot%\system32\Mcx2Svc.dll
[Svchost DLLs] :HKLM MMCSS=C:\WINDOWS\SYSTEM32\MMCSS.DLL
### Multimedia Class Scheduler Service Microsoft Corporation Microsoft Windows O
perating System 6.1.7600.16385 %SystemRoot%\system32\mmcss.dll
[Svchost DLLs] :HKLM MpsSvc=C:\WINDOWS\SYSTEM32\MPSSVC.DLL
### Microsoft Protection Service Microsoft Corporation Microsoft Windows Operati
ng System 6.1.7600.16385 %SystemRoot%\system32\mpssvc.dll
[Svchost DLLs] :HKLM Net Driver HPZ12=C:\WINDOWS\SYSTEM32\HPZINW12.DLL
### Dot4Net Module Hewlett-Packard Bidi User Mode 12,2,6,51
[Svchost DLLs] :HKLM nsi=C:\WINDOWS\SYSTEM32\NSISVC.DLL
### Network Store Interface RPC server Microsoft Corporation Microsoft Windows O
perating System 6.1.7600.16385 %systemroot%\system32\nsisvc.dll
[Svchost DLLs] :HKLM p2pimsvc=C:\WINDOWS\SYSTEM32\PNRPSVC.DLL
### PNRP Service Dll Microsoft Corporation Microsoft Windows Operating System 6.
1.7600.16385 %SystemRoot%\system32\pnrpsvc.dll
[Svchost DLLs] :HKLM p2psvc=C:\WINDOWS\SYSTEM32\P2PSVC.DLL
### Peer-to-Peer Services Microsoft Corporation Microsoft Windows Operating Syst
em 6.1.7600.16385 %SystemRoot%\system32\p2psvc.dll
[Svchost DLLs] :HKLM PcaSvc=C:\WINDOWS\SYSTEM32\PCASVC.DLL
### Program Compatibility Assistant Service Microsoft Corporation Microsoft Win
dows Operating System 6.1.7600.16385 %SystemRoot%\System32\pcasvc.dll
[Svchost DLLs] :HKLM Pml Driver HPZ12=C:\WINDOWS\SYSTEM32\HPZIPM12.DLL
### PmlDrv Module Hewlett-Packard Bidi User Mode 12,2,6,51
[Svchost DLLs] :HKLM PolicyAgent=C:\WINDOWS\SYSTEM32\IPSECSVC.DLL
### Windows IPsec SPD Server DLL Microsoft Corporation Microsoft Windows Operati

ng System 6.1.7601.17514 %SystemRoot%\System32\ipsecsvc.dll


[Svchost DLLs] :HKLM ProfSvc=C:\WINDOWS\SYSTEM32\PROFSVC.DLL
### ProfSvc Microsoft Corporation Microsoft Windows Operating System 6.1.7600.16
385 %systemroot%\system32\profsvc.dll
[Svchost DLLs] :HKLM RpcEptMapper=C:\WINDOWS\SYSTEM32\RPCEPMAP.DLL
### RPC Endpoint Mapper Microsoft Corporation Microsoft Windows Operating System
6.1.7600.16385 %SystemRoot%\System32\RpcEpMap.dll
[Svchost DLLs] :HKLM SDRSVC=C:\WINDOWS\SYSTEM32\SDRSVC.DLL
### Microsoft Windows Backup Service Microsoft Corporation Microsoft Windows Oper
ating System 6.1.7600.16385 %Systemroot%\System32\SDRSVC.dll
[Svchost DLLs] :HKLM seclogon=C:\WINDOWS\SYSTEM32\SECLOGON.DLL
### Secondary Logon Service DLL Microsoft Corporation Microsoft Windows Operatin
g System 6.1.7600.16385 %windir%\system32\seclogon.dll
[Svchost DLLs] :HKLM SensrSvc=C:\WINDOWS\SYSTEM32\SENSRSVC.DLL
### Microsoft Windows ambient light service Microsoft Corporation Microsoft Win
dows Operating System 6.1.7600.16385 %SystemRoot%\system32\sensrsvc.dll
[Svchost DLLs] :HKLM SstpSvc=C:\WINDOWS\SYSTEM32\SSTPSVC.DLL
### Provides the facility of using Secure Socket Tunneling Protocol (SSTP) to
connect to remote computers (using VPN). Microsoft Corporation Microsoft Windows O
perating System 6.1.7600.16385 %SystemRoot%\system32\sstpsvc.dll
[Svchost DLLs] :HKLM swprv=C:\WINDOWS\SYSTEM32\SWPRV.DLL
### Microsoft Volume Shadow Copy Service software provider Microsoft Corporatio
n Microsoft Windows Operating System 6.1.7600.16385 %Systemroot%\System32\swprv.d
ll
[Svchost DLLs] :HKLM SysMain=C:\WINDOWS\SYSTEM32\SYSMAIN.DLL
### Superfetch Service Host Microsoft Corporation Microsoft Windows Operating Sy
stem 6.1.7600.16385 %systemroot%\system32\sysmain.dll
[Svchost DLLs] :HKLM TabletInputService=C:\WINDOWS\SYSTEM32\TABSVC.DLL
### Microsoft Tablet PC Input Service Microsoft Corporation Microsoft Windows Op
erating System 6.1.7600.16385 %SystemRoot%\System32\TabSvc.dll
[Svchost DLLs] :HKLM Themes=C:\WINDOWS\SYSTEM32\THEMESERVICE.DLL
### Windows Shell Theme Service Dll Microsoft Corporation Microsoft Windows Oper
ating System 6.1.7600.16385 %SystemRoot%\system32\themeservice.dll
[Svchost DLLs] :HKLM THREADORDER=C:\WINDOWS\SYSTEM32\MMCSS.DLL
### Multimedia Class Scheduler Service Microsoft Corporation Microsoft Windows O
perating System 6.1.7600.16385 %SystemRoot%\system32\mmcss.dll
[Svchost DLLs] :HKLM TrkWks=C:\WINDOWS\SYSTEM32\TRKWKS.DLL
### Distributed Link Tracking Client Microsoft Corporation Microsoft Windows Ope
rating System 6.1.7600.16385 %SystemRoot%\System32\trkwks.dll
[Svchost DLLs] :HKLM UmRdpService=C:\WINDOWS\SYSTEM32\UMRDP.DLL
### Remote Desktop Services Device Redirector Service Microsoft Corporation Mi
crosoft Windows Operating System 6.1.7600.16385 %SystemRoot%\System32\umrdp.dll
[Svchost DLLs] :HKLM UxSms=C:\WINDOWS\SYSTEM32\UXSMS.DLL
### Microsoft User Experience Session Management Service Microsoft Corporation
Microsoft Windows Operating System 6.1.7600.16385 %SystemRoot%\System32\uxsms.dl
l
[Svchost DLLs] :HKLM W32Time=C:\WINDOWS\SYSTEM32\W32TIME.DLL
### Windows Time Service Microsoft Corporation Microsoft Windows Operating Syste
m 6.1.7600.16385 %systemroot%\system32\w32time.dll
[Svchost DLLs] :HKLM WbioSrvc=C:\WINDOWS\SYSTEM32\WBIOSRVC.DLL
### Windows Biometric Service Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385 %SystemRoot%\System32\wbiosrvc.dll
[Svchost DLLs] :HKLM WdiServiceHost=C:\WINDOWS\SYSTEM32\WDI.DLL
### Windows Diagnostic Infrastructure Microsoft Corporation Microsoft Windows Op
erating System 6.1.7600.16385 %SystemRoot%\system32\wdi.dll
[Svchost DLLs] :HKLM WdiSystemHost=C:\WINDOWS\SYSTEM32\WDI.DLL
### Windows Diagnostic Infrastructure Microsoft Corporation Microsoft Windows Op
erating System 6.1.7600.16385 %SystemRoot%\system32\wdi.dll
[Svchost DLLs] :HKLM wercplsupport=C:\WINDOWS\SYSTEM32\WERCPLSUPPORT.DLL
### Problem Reports and Solutions Microsoft Corporation Microsoft Windows Operat

ing System 6.1.7600.16385 %SystemRoot%\System32\wercplsupport.dll


[Svchost DLLs] :HKLM WerSvc=C:\WINDOWS\SYSTEM32\WERSVC.DLL
### Windows Error Reporting Service Microsoft Corporation Microsoft Windows Oper
ating System 6.1.7600.16385 %SystemRoot%\System32\WerSvc.dll
[Svchost DLLs] :HKLM WinDefend=C:\PROGRAM FILES\WINDOWS DEFENDER\MPSVC.DLL
### Service Module Microsoft Corporation Microsoft Windows Operating System 6.1.
7601.18170 %ProgramFiles%\Windows Defender\mpsvc.dll
[Svchost DLLs] :HKLM wudfsvc=C:\WINDOWS\SYSTEM32\WUDFSVC.DLL
### Windows Driver Foundation - User-mode Driver Framework Service Microsoft C
orporation Microsoft Windows Operating System 6.1.7600.16385 %SystemRoot%\System3
2\WUDFSvc.dll
[Svchost DLLs] :HKLM WwanSvc=C:\WINDOWS\SYSTEM32\WWANSVC.DLL
### WWAN Auto Config Service Microsoft Corporation Microsoft Windows Operating S
ystem 08.01.02.00 %SystemRoot%\System32\wwansvc.dll
[Bootexecute] :HKLM BootExecute=autocheck autochk *
[Winlogon System] :HKLM system=""
### File is deleted or hidden by a rootkit or could not be located.
[Winlogon System] :HKLM taskman=""
### File is deleted or hidden by a rootkit or could not be located.
[Winlogon System] :HKLM UIHost=""
### File is deleted or hidden by a rootkit or could not be located.
[Winlogon Autostart] :HKLM VmApplet=SystemPropertiesPerformance.exe /pagefile
[Winlogon Autostart] :HKLM AppSetup=""
[Environment - Path] :HKLM Path=C:\ProgramData\Oracle\Java\javapath;%C_EM64T_R
EDIST11%bin\Intel64;C:\oracle\product\10.2.0\db_1\bin;%SystemRoot%\system32;%Sys
temRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0
\;C:\Program Files (x86)\QuickTime\QTSystem\
[List of Injected DLLs] :HKLM AppInit_DLLs=""
[LSA Notification Packages] :HKLM scecli=C:\Windows\system32\SCECLI.DLL
### scecli Windows Security Configuration Editor Client Engine Microsoft Corpo
ration Microsoft Windows Operating System 6.1.7600.16385 scecli.dll
[LSA Security Packages] :HKLM kerberos=C:\Windows\system32\KERBEROS.DLL
### kerberos Kerberos Security Package Microsoft Corporation Microsoft Windows O
perating System 6.1.7600.16385 kerberos.dll
[LSA Security Packages] :HKLM msv1_0=C:\Windows\system32\MSV1_0.DLL
### msv1_0 Microsoft Authentication Package v1.0 Microsoft Corporation Microso
ft Windows Operating System 6.1.7600.16385 msv1_0.dll
[LSA Security Packages] :HKLM schannel=C:\Windows\system32\SCHANNEL.DLL
### schannel TLS / SSL Security Provider Microsoft Corporation Microsoft Window
s Operating System 6.1.7601.18409 schannel.dll
[LSA Security Packages] :HKLM wdigest=C:\Windows\system32\WDIGEST.DLL
### wdigest Microsoft Digest Access Microsoft Corporation Microsoft Windows Oper
ating System 6.1.7601.18409 wdigest.dll
[LSA Security Packages] :HKLM tspkg=C:\Windows\system32\TSPKG.DLL
### tspkg Web Service Security Package Microsoft Corporation Microsoft Windows O
perating System 6.1.7601.18409 tspkg.dll
[LSA Security Packages] :HKLM pku2u=C:\Windows\system32\PKU2U.DLL
### pku2u Pku2u Security Package Microsoft Corporation Microsoft Windows Operati
ng System 6.1.7600.16385 pku2u.dll
[Drivers] :HKLM 1394ohci=C:\WINDOWS\SYSTEM32\DRIVERS\1394OHCI.SYS
### 1394 OpenHCI Port Driver Microsoft Corporation Microsoft Windows Operating S
ystem 6.1.7600.16385 \SystemRoot\system32\drivers\1394ohci.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM ACPI=C:\WINDOWS\SYSTEM32\DRIVERS\ACPI.SYS
### ACPI Driver for NT Microsoft Corporation Microsoft Windows Operating System
6.1.7600.16385 Service registry key doesn't exist or hidden.
[Drivers] :HKLM AcpiPmi=C:\WINDOWS\SYSTEM32\DRIVERS\ACPIPMI.SYS
### ACPI Power Metering Driver Microsoft Corporation Microsoft Windows Operating
System 6.1.7601.17514 \SystemRoot\system32\drivers\acpipmi.sys Service registr

y key doesn't exist or hidden.


[Drivers] :HKLM adp94xx=C:\WINDOWS\SYSTEM32\DRIVERS\ADP94XX.SYS
### Adaptec Windows SAS/SATA Storport Driver Adaptec, Inc. Adaptec Windows 7 S
AS/SATA Family Storport Driver 6.1.3790.0 \SystemRoot\system32\DRIVERS\adp94xx.
sys Service registry key doesn't exist or hidden.
[Drivers] :HKLM adpahci=C:\WINDOWS\SYSTEM32\DRIVERS\ADPAHCI.SYS
### Adaptec Windows SATA Storport Driver Adaptec, Inc. Adaptec Windows Server
2003 SATA Family Storport Driver 6.0.3790.16512 \SystemRoot\system32\DRIVERS\ad
pahci.sys Service registry key doesn't exist or hidden.
[Drivers] :HKLM adpu320=C:\WINDOWS\SYSTEM32\DRIVERS\ADPU320.SYS
### Adaptec StorPort Ultra320 SCSI Driver (X64) Adaptec, Inc. Adaptec Windows
Ultra320 Family Driver 6.0.6001.16459 \SystemRoot\system32\DRIVERS\adpu320.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM AFD=C:\WINDOWS\SYSTEM32\DRIVERS\AFD.SYS
### Ancillary Function Driver for WinSock Microsoft Corporation Microsoft Windo
ws Operating System 6.1.7600.16385 \SystemRoot\system32\drivers\afd.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM agp440=C:\WINDOWS\SYSTEM32\DRIVERS\AGP440.SYS
### 440 NT AGP Filter Microsoft Corporation Microsoft Windows Operating System 6
.1.7600.16385 \SystemRoot\system32\drivers\agp440.sys Service registry key does
n't exist or hidden.
[Drivers] :HKLM aliide=C:\WINDOWS\SYSTEM32\DRIVERS\ALIIDE.SYS
### ALi mini IDE Driver Acer Laboratories Inc. ALi mini IDE Driver 1.20 \Syst
emRoot\system32\drivers\aliide.sys Service registry key doesn't exist or hidden.
[Drivers] :HKLM amdide=C:\WINDOWS\SYSTEM32\DRIVERS\AMDIDE.SYS
### AMD IDE Driver Microsoft Corporation Microsoft Windows Operating System 6.1.
7600.16385 \SystemRoot\system32\drivers\amdide.sys Service registry key doesn't
exist or hidden.
[Drivers] :HKLM AmdK8=C:\WINDOWS\SYSTEM32\DRIVERS\AMDK8.SYS
### Processor Device Driver Microsoft Corporation Microsoft Windows Operating Sy
stem 6.1.7600.16385 \SystemRoot\system32\DRIVERS\amdk8.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM AmdPPM=C:\WINDOWS\SYSTEM32\DRIVERS\AMDPPM.SYS
### Processor Device Driver Microsoft Corporation Microsoft Windows Operating Sy
stem 6.1.7600.16385 \SystemRoot\system32\DRIVERS\amdppm.sys Service registry ke
y doesn't exist or hidden.
[Drivers] :HKLM amdsata=C:\WINDOWS\SYSTEM32\DRIVERS\AMDSATA.SYS
### AHCI 1.2 Device Driver Advanced Micro Devices AHCI 1.2 Device Driver 1.1.2
.5 \SystemRoot\system32\drivers\amdsata.sys Service registry key doesn't exist
or hidden.
[Drivers] :HKLM amdsbs=C:\WINDOWS\SYSTEM32\DRIVERS\AMDSBS.SYS
### AMD Technology AHCI Compatible Controller Driver for Windows - AMD64 platf
orm AMD Technologies Inc. AMD Technology AHCI Compatible Controller 3.6.1540.127
\SystemRoot\system32\DRIVERS\amdsbs.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM amdxata=C:\WINDOWS\SYSTEM32\DRIVERS\AMDXATA.SYS
### Storage Filter Driver Advanced Micro Devices Storage Filter Driver 1.1.2.5
Service registry key doesn't exist or hidden.
[Drivers] :HKLM Apowersoft_AudioDevice=C:\WINDOWS\SYSTEM32\DRIVERS\APOWERSOFT_
AUDIODEVICE.SYS
### Wondershare Virtual Audio Device Wondershare Virtual Audio driver 1.00 Se
rvice registry key doesn't exist or hidden.
[Drivers] :HKLM AppID=C:\WINDOWS\SYSTEM32\DRIVERS\APPID.SYS
### AppID Driver Microsoft Corporation Microsoft Windows Operating System 6.1.76
01.17514 \SystemRoot\system32\drivers\appid.sys Service registry key doesn't ex
ist or hidden.
[Drivers] :HKLM arc=C:\WINDOWS\SYSTEM32\DRIVERS\ARC.SYS
### Adaptec RAID Storport Driver Adaptec, Inc. Adaptec RAID Controller 5.2.0.1
0384 \SystemRoot\system32\DRIVERS\arc.sys Service registry key doesn't exist or
hidden.

[Drivers] :HKLM arcsas=C:\WINDOWS\SYSTEM32\DRIVERS\ARCSAS.SYS


### Adaptec SAS RAID WS03 Driver Adaptec, Inc. Adaptec RAID Controller 5.2.0.1
6119 \SystemRoot\system32\DRIVERS\arcsas.sys Service registry key doesn't exist
or hidden.
[Drivers] :HKLM AsyncMac=C:\WINDOWS\SYSTEM32\DRIVERS\ASYNCMAC.SYS
### MS Remote Access serial network driver Microsoft Corporation Microsoft Wind
ows Operating System 6.1.7600.16385 Service registry key doesn't exist or hidden
.
[Drivers] :HKLM atapi=C:\WINDOWS\SYSTEM32\DRIVERS\ATAPI.SYS
### ATAPI IDE Miniport Driver Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385 Service registry key doesn't exist or hidden.
[Drivers] :HKLM AX88772B=C:\WINDOWS\SYSTEM32\DRIVERS\AX88772B.SYS
### ASIX AX88772B Network Driver ASIX Electronics Corp. ASIX AX88772B USB2.0 t
o Fast Ethernet Adapter 5.14.3.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM b06bdrv=C:\WINDOWS\SYSTEM32\DRIVERS\BXVBDA.SYS
### Broadcom NetXtreme II GigE VBD Broadcom Corporation Broadcom NetXtreme II
GigE 4.8.2.0 \SystemRoot\system32\DRIVERS\bxvbda.sys Service registry key doesn
't exist or hidden.
[Drivers] :HKLM b57nd60a=C:\WINDOWS\SYSTEM32\DRIVERS\B57ND60A.SYS
### Broadcom NetXtreme Gigabit Ethernet NDIS6.x Unified Driver. Broadcom Corpo
ration Broadcom NetXtreme Gigabit Ethernet Driver 10.100.4.0 Service registry k
ey doesn't exist or hidden.
[Drivers] :HKLM blbdrive=C:\WINDOWS\SYSTEM32\DRIVERS\BLBDRIVE.SYS
### BLB Drive Driver Microsoft Corporation Microsoft Windows Operating System 6.
1.7600.16385 Service registry key doesn't exist or hidden.
[Drivers] :HKLM bowser=C:\WINDOWS\SYSTEM32\DRIVERS\BOWSER.SYS
### NT Lan Manager Datagram Receiver Driver Microsoft Corporation Microsoft Win
dows Operating System 6.1.7601.17565 Service registry key doesn't exist or hidde
n.
[Drivers] :HKLM BrFiltLo=C:\WINDOWS\SYSTEM32\DRIVERS\BRFILTLO.SYS
### Windows ME USB Mass-Storage Bulk-Only Lower Filter Driver Brother Industri
es, Ltd. RemovableDisk 1.10.000 \SystemRoot\system32\DRIVERS\BrFiltLo.sys Servi
ce registry key doesn't exist or hidden.
[Drivers] :HKLM BrFiltUp=C:\WINDOWS\SYSTEM32\DRIVERS\BRFILTUP.SYS
### Windows ME USB Mass-Storage Bulk-Only Upper Filter Driver Brother Industri
es, Ltd. RemovableDisk 1.04.000 \SystemRoot\system32\DRIVERS\BrFiltUp.sys Servi
ce registry key doesn't exist or hidden.
[Drivers] :HKLM Brserid=C:\WINDOWS\SYSTEM32\DRIVERS\BRSERID.SYS
### Brotehr Serial I/F Driver (WDM) Brother Industries Ltd. Microsoft Windows Op
erating System 1.0.0.0,2006 \SystemRoot\System32\Drivers\Brserid.sys Service re
gistry key doesn't exist or hidden.
[Drivers] :HKLM BrSerWdm=C:\WINDOWS\SYSTEM32\DRIVERS\BRSERWDM.SYS
### Brother Serial driver (WDM version) Brother Industries Ltd. Brother MFL Pr
o 1.0.0.20,2003 \SystemRoot\System32\Drivers\BrSerWdm.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM BrUsbMdm=C:\WINDOWS\SYSTEM32\DRIVERS\BRUSBMDM.SYS
### Brother USB MDM Driver Brother Industries Ltd. Microsoft Windows Operating
System 6.0.5479.0 \SystemRoot\System32\Drivers\BrUsbMdm.sys Service registry ke
y doesn't exist or hidden.
[Drivers] :HKLM BrUsbSer=C:\WINDOWS\SYSTEM32\DRIVERS\BRUSBSER.SYS
### Brother USB Serial Driver Brother Industries Ltd. Microsoft Windows Operatin
g System 6.0.5479.0 \SystemRoot\System32\Drivers\BrUsbSer.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM BTHMODEM=C:\WINDOWS\SYSTEM32\DRIVERS\BTHMODEM.SYS
### Bluetooth Communications Driver Microsoft Corporation Microsoft Windows Oper
ating System 6.1.7600.16385 \SystemRoot\system32\DRIVERS\bthmodem.sys Service r
egistry key doesn't exist or hidden.
[Drivers] :HKLM cdfs=C:\WINDOWS\SYSTEM32\DRIVERS\CDFS.SYS
### CD-ROM File System Driver Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385 Service registry key doesn't exist or hidden.

[Drivers] :HKLM cdrom=C:\WINDOWS\SYSTEM32\DRIVERS\CDROM.SYS


### SCSI CD-ROM Driver Microsoft Corporation Microsoft Windows Operating System
6.1.7600.16385 Service registry key doesn't exist or hidden.
[Drivers] :HKLM circlass=C:\WINDOWS\SYSTEM32\DRIVERS\CIRCLASS.SYS
### Consumer IR Class Driver for eHome Microsoft Corporation Microsoft Windows O
perating System 6.1.7600.16385 \SystemRoot\system32\DRIVERS\circlass.sys Servic
e registry key doesn't exist or hidden.
[Drivers] :HKLM CLFS=C:\WINDOWS\SYSTEM32\CLFS.SYS
### Common Log File System Driver Microsoft Corporation Microsoft Windows Operat
ing System 6.1.7600.16385 Service registry key doesn't exist or hidden.
[Drivers] :HKLM CmBatt=C:\WINDOWS\SYSTEM32\DRIVERS\CMBATT.SYS
### Control Method Battery Driver Microsoft Corporation Microsoft Windows Operat
ing System 6.1.7600.16385 \SystemRoot\system32\DRIVERS\CmBatt.sys Service regis
try key doesn't exist or hidden.
[Drivers] :HKLM cmdide=C:\WINDOWS\SYSTEM32\DRIVERS\CMDIDE.SYS
### CMD PCI IDE Bus Driver CMD Technology, Inc. Microsoft Windows Operating Syst
em 6.1.7600.16385 \SystemRoot\system32\drivers\cmdide.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM CNG=C:\WINDOWS\SYSTEM32\DRIVERS\CNG.SYS
### Kernel Cryptography, Next Generation Microsoft Corporation Microsoft Window
s Operating System 6.1.7601.17919 Service registry key doesn't exist or hidden.
[Drivers] :HKLM Compbatt=C:\WINDOWS\SYSTEM32\DRIVERS\COMPBATT.SYS
### Composite Battery Driver Microsoft Corporation Microsoft Windows Operating S
ystem 6.1.7600.16385 \SystemRoot\system32\DRIVERS\compbatt.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM CompositeBus=C:\WINDOWS\SYSTEM32\DRIVERS\COMPOSITEBUS.SYS
### Multi-Transport Composite Bus Enumerator Microsoft Corporation Microsoft Wi
ndows Operating System 6.1.7601.17514 \SystemRoot\system32\drivers\CompositeBus.
sys Service registry key doesn't exist or hidden.
[Drivers] :HKLM crcdisk=C:\WINDOWS\SYSTEM32\DRIVERS\CRCDISK.SYS
### Disk Block Verification Filter Driver Microsoft Corporation Microsoft Windo
ws Operating System 6.1.7600.16385 \SystemRoot\system32\DRIVERS\crcdisk.sys Serv
ice registry key doesn't exist or hidden.
[Drivers] :HKLM CSC=C:\WINDOWS\SYSTEM32\DRIVERS\CSC.SYS
### Windows Client Side Caching Driver Microsoft Corporation Microsoft Windows O
perating System 6.1.7601.17514 Service registry key doesn't exist or hidden.
[Drivers] :HKLM DfsC=C:\WINDOWS\SYSTEM32\DRIVERS\DFSC.SYS
### DFS Namespace Client Driver Microsoft Corporation Microsoft Windows Operatin
g System 6.1.7601.17514 Service registry key doesn't exist or hidden.
[Drivers] :HKLM dg_ssudbus=C:\WINDOWS\SYSTEM32\DRIVERS\SSUDBUS.SYS
### SAMSUNG USB Composite Device Driver (MSS Ver.3) DEVGURU Co., LTD.(www.devg
uru.co.kr) SAMSUNG USB Composite Device Driver (MSS Ver.3) 2.11.10.0 Service re
gistry key doesn't exist or hidden.
[Drivers] :HKLM discache=C:\WINDOWS\SYSTEM32\DRIVERS\DISCACHE.SYS
### System Indexer/Cache Driver Microsoft Corporation Microsoft Windows Operatin
g System 6.1.7600.16385 Service registry key doesn't exist or hidden.
[Drivers] :HKLM Disk=C:\WINDOWS\SYSTEM32\DRIVERS\DISK.SYS
### PnP Disk Driver Microsoft Corporation Microsoft Windows Operating System 6.1
.7600.16385 Service registry key doesn't exist or hidden.
[Drivers] :HKLM drmkaud=C:\WINDOWS\SYSTEM32\DRIVERS\DRMKAUD.SYS
### Microsoft Trusted Audio Drivers Microsoft Corporation Microsoft Windows Oper
ating System 6.1.7600.16385 \SystemRoot\system32\drivers\drmkaud.sys Service re
gistry key doesn't exist or hidden.
[Drivers] :HKLM DXGKrnl=C:\WINDOWS\SYSTEM32\DRIVERS\DXGKRNL.SYS
### DirectX Graphics Kernel Microsoft Corporation Microsoft Windows Operating Sy
stem 6.1.7601.18228 \SystemRoot\System32\drivers\dxgkrnl.sys Service registry k
ey doesn't exist or hidden.
[Drivers] :HKLM ebdrv=C:\WINDOWS\SYSTEM32\DRIVERS\EVBDA.SYS
### Broadcom NetXtreme II 10 GigE VBD Broadcom Corporation Broadcom NetXtreme
II 10 GigE 4.8.13.0 \SystemRoot\system32\DRIVERS\evbda.sys Service registry key

doesn't exist or hidden.


[Drivers] :HKLM elxstor=C:\WINDOWS\SYSTEM32\DRIVERS\ELXSTOR.SYS
### Storport Miniport Driver for LightPulse HBAs Emulex Emulex LightPulse Stor
port Miniport Driver 7-2.10.211 01/23/2009 WS2K3 64 bit x64 \SystemRoot\system3
2\DRIVERS\elxstor.sys Service registry key doesn't exist or hidden.
[Drivers] :HKLM ErrDev=C:\WINDOWS\SYSTEM32\DRIVERS\ERRDEV.SYS
### Error Device Driver Microsoft Corporation Microsoft Windows Operating System
6.1.7600.16385 \SystemRoot\system32\drivers\errdev.sys Service registry key do
esn't exist or hidden.
[Drivers] :HKLM fdc=C:\WINDOWS\SYSTEM32\DRIVERS\FDC.SYS
### Floppy Disk Controller Driver Microsoft Corporation Microsoft Windows Operat
ing System 6.1.7600.16385 \SystemRoot\system32\DRIVERS\fdc.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM FileInfo=C:\WINDOWS\SYSTEM32\DRIVERS\FILEINFO.SYS
### FileInfo Filter Driver Microsoft Corporation Microsoft Windows Operating Sys
tem 6.1.7600.16385 Service registry key doesn't exist or hidden.
[Drivers] :HKLM Filetrace=C:\WINDOWS\SYSTEM32\DRIVERS\FILETRACE.SYS
### File Trace Filter Driver Microsoft Corporation Microsoft Windows Operating S
ystem 6.1.7600.16385 Service registry key doesn't exist or hidden.
[Drivers] :HKLM flpydisk=C:\WINDOWS\SYSTEM32\DRIVERS\FLPYDISK.SYS
### Floppy Driver Microsoft Corporation Microsoft Windows Operating System 6.1.7
600.16385 \SystemRoot\system32\DRIVERS\flpydisk.sys Service registry key doesn'
t exist or hidden.
[Drivers] :HKLM FltMgr=C:\WINDOWS\SYSTEM32\DRIVERS\FLTMGR.SYS
### Microsoft Filesystem Filter Manager Microsoft Corporation Microsoft Windows
Operating System 6.1.7600.16385 Service registry key doesn't exist or hidden.
[Drivers] :HKLM FsDepends=C:\WINDOWS\SYSTEM32\DRIVERS\FSDEPENDS.SYS
### File System Dependency Manager Mini Filter Driver Microsoft Corporation Mi
crosoft Windows Operating System 6.1.7600.16385 Service registry key doesn't exis
t or hidden.
[Drivers] :HKLM fvevol=C:\WINDOWS\SYSTEM32\DRIVERS\FVEVOL.SYS
### BitLocker Drive Encryption Driver Microsoft Corporation Microsoft Windows Op
erating System 6.1.7600.16385 Service registry key doesn't exist or hidden.
[Drivers] :HKLM gagp30kx=C:\WINDOWS\SYSTEM32\DRIVERS\GAGP30KX.SYS
### MS Generic AGPv3.0 Filter for K8/9 Processor Platforms Microsoft Corporati
on Microsoft Windows Operating System 6.1.7600.16385 \SystemRoot\system32\DRIVERS
\gagp30kx.sys Service registry key doesn't exist or hidden.
[Drivers] :HKLM GEARAspiWDM=C:\WINDOWS\SYSTEM32\DRIVERS\GEARASPIWDM.SYS
### CD DVD Filter GEAR Software Inc. CD DVD Filter 2.02.03.00 Service registr
y key doesn't exist or hidden.
[Drivers] :HKLM ggflt=C:\WINDOWS\SYSTEM32\DRIVERS\GGFLT.SYS
### SOMC USB Flash Driver Filter Sony Mobile Communications Gordon's Gate 3.1.
0.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM ggsomc=C:\WINDOWS\SYSTEM32\DRIVERS\GGSOMC.SYS
### SOMC USB Flash Driver Sony Mobile Communications Gordon's Gate 3.1.0.0 Se
rvice registry key doesn't exist or hidden.
[Drivers] :HKLM hcmon=C:\WINDOWS\SYSTEM32\DRIVERS\HCMON.SYS
### VMware USB monitor VMware, Inc. VMware USB monitor 8.5.7.1 build-1295349
\??\C:\Windows\system32\drivers\hcmon.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM hcw85cir=C:\WINDOWS\SYSTEM32\DRIVERS\HCW85CIR.SYS
### Hauppauge WinTV 885 Consumer IR Driver for eHome Hauppauge Computer Works,
Inc. hcw85cir.sys 1.31.27127 \SystemRoot\system32\drivers\hcw85cir.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM HdAudAddService=C:\WINDOWS\SYSTEM32\DRIVERS\HDAUDIO.SYS
### High Definition Audio Function Driver Microsoft Corporation Microsoft Windo
ws Operating System 6.1.7600.16385 Service registry key doesn't exist or hidden.
[Drivers] :HKLM HDAudBus=C:\WINDOWS\SYSTEM32\DRIVERS\HDAUDBUS.SYS
### High Definition Audio Bus Driver Microsoft Corporation Microsoft Windows Ope
rating System 6.1.7600.16385 Service registry key doesn't exist or hidden.

[Drivers] :HKLM hhdserhelp=C:\WINDOWS\SYSTEM32\DRIVERS\HHDSERHELP.SYS


### Serial Monitoring Helper Driver HHD Software Ltd. Device Monitoring Studio
6.54.00.5773 \??\C:\Windows\system32\drivers\hhdserhelp.sys Service registry k
ey doesn't exist or hidden.
[Drivers] :HKLM hhdserial64=C:\WINDOWS\SYSTEM32\DRIVERS\HHDSERIAL64.SYS
### Serial Monitoring Filter Driver (x64) HHD Software Ltd. Device Monitoring
Studio (x64) 6.54.00.5773 Service registry key doesn't exist or hidden.
[Drivers] :HKLM HidBatt=C:\WINDOWS\SYSTEM32\DRIVERS\HIDBATT.SYS
### Hid Battery Driver Microsoft Corporation Microsoft Windows Operating System
6.1.7600.16385 \SystemRoot\system32\DRIVERS\HidBatt.sys Service registry key do
esn't exist or hidden.
[Drivers] :HKLM HidBth=C:\WINDOWS\SYSTEM32\DRIVERS\HIDBTH.SYS
### Bluetooth Miniport Driver for HID Devices Microsoft Corporation Microsoft W
indows Operating System 6.1.7600.16385 \SystemRoot\system32\DRIVERS\hidbth.sys S
ervice registry key doesn't exist or hidden.
[Drivers] :HKLM HidIr=C:\WINDOWS\SYSTEM32\DRIVERS\HIDIR.SYS
### Infrared Miniport Driver for Input Devices Microsoft Corporation Microsoft
Windows Operating System 6.1.7600.16385 \SystemRoot\system32\DRIVERS\hidir.sys S
ervice registry key doesn't exist or hidden.
[Drivers] :HKLM HidUsb=C:\WINDOWS\SYSTEM32\DRIVERS\HIDUSB.SYS
### USB Miniport Driver for Input Devices Microsoft Corporation Microsoft Windo
ws Operating System 6.1.7601.17514 Service registry key doesn't exist or hidden.
[Drivers] :HKLM HpSAMD=C:\WINDOWS\SYSTEM32\DRIVERS\HPSAMD.SYS
### Smart Array SAS/SATA Controller Media Driver Hewlett-Packard Company Smart
Array SAS/SATA Controller Media Driver 6.12.6.64 Build 2 Media Driver (x86-64)
\SystemRoot\system32\drivers\HpSAMD.sys Service registry key doesn't exist or h
idden.
[Drivers] :HKLM HTTP=C:\WINDOWS\SYSTEM32\DRIVERS\HTTP.SYS
### HTTP Protocol Stack Microsoft Corporation Microsoft Windows Operating System
6.1.7600.16385 Service registry key doesn't exist or hidden.
[Drivers] :HKLM hwpolicy=C:\WINDOWS\SYSTEM32\DRIVERS\HWPOLICY.SYS
### Hardware Policy Driver Microsoft Corporation Microsoft Windows Operating Sys
tem 6.1.7601.17514 Service registry key doesn't exist or hidden.
[Drivers] :HKLM i8042prt=C:\WINDOWS\SYSTEM32\DRIVERS\I8042PRT.SYS
### i8042 Port Driver Microsoft Corporation Microsoft Windows Operating System 6
.1.7600.16385 \SystemRoot\system32\drivers\i8042prt.sys Service registry key do
esn't exist or hidden.
[Drivers] :HKLM iaStorV=C:\WINDOWS\SYSTEM32\DRIVERS\IASTORV.SYS
### Intel Matrix Storage Manager driver - x64 Intel Corporation Intel Matrix S
torage Manager driver 8.6.2.1014 \SystemRoot\system32\drivers\iaStorV.sys Servi
ce registry key doesn't exist or hidden.
[Drivers] :HKLM iirsp=C:\WINDOWS\SYSTEM32\DRIVERS\IIRSP.SYS
### Intel/ICP Raid Storport Driver Intel Corp./ICP vortex GmbH Intel/ICP Raid
Storport Driver 4.22.0 \SystemRoot\system32\DRIVERS\iirsp.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM intelide=C:\WINDOWS\SYSTEM32\DRIVERS\INTELIDE.SYS
### Intel PCI IDE Driver Microsoft Corporation Microsoft Windows Operating Syste
m 6.1.7600.16385 \SystemRoot\system32\drivers\intelide.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM intelppm=C:\WINDOWS\SYSTEM32\DRIVERS\INTELPPM.SYS
### Processor Device Driver Microsoft Corporation Microsoft Windows Operating Sy
stem 6.1.7600.16385 Service registry key doesn't exist or hidden.
[Drivers] :HKLM IpFilterDriver=C:\WINDOWS\SYSTEM32\DRIVERS\IPFLTDRV.SYS
### IP FILTER DRIVER Microsoft Corporation Microsoft Windows Operating System 6.
1.7601.17514 Service registry key doesn't exist or hidden.
[Drivers] :HKLM IPMIDRV=C:\WINDOWS\SYSTEM32\DRIVERS\IPMIDRV.SYS
### WMI IPMI DRIVER Microsoft Corporation Microsoft Windows Operating System 6.1
.7601.17514 \SystemRoot\system32\drivers\IPMIDrv.sys Service registry key doesn
't exist or hidden.
[Drivers] :HKLM IPNAT=C:\WINDOWS\SYSTEM32\DRIVERS\IPNAT.SYS

### IP Network Address Translator Microsoft Corporation Microsoft Windows Operat


ing System 6.1.7600.16385 Service registry key doesn't exist or hidden.
[Drivers] :HKLM IRENUM=C:\WINDOWS\SYSTEM32\DRIVERS\IRENUM.SYS
### Infra-Red Bus Enumerator Microsoft Corporation Microsoft Windows Operating S
ystem 6.1.7600.16385 Service registry key doesn't exist or hidden.
[Drivers] :HKLM isapnp=C:\WINDOWS\SYSTEM32\DRIVERS\ISAPNP.SYS
### PNP ISA Bus Driver Microsoft Corporation Microsoft Windows Operating System
6.1.7600.16385 \SystemRoot\system32\drivers\isapnp.sys Service registry key doe
sn't exist or hidden.
[Drivers] :HKLM iScsiPrt=C:\WINDOWS\SYSTEM32\DRIVERS\MSISCSI.SYS
### Microsoft iSCSI Initiator Driver Microsoft Corporation Microsoft Windows Ope
rating System 6.1.7601.17514 \SystemRoot\system32\drivers\msiscsi.sys Service r
egistry key doesn't exist or hidden.
[Drivers] :HKLM kbdclass=C:\WINDOWS\SYSTEM32\DRIVERS\KBDCLASS.SYS
### Keyboard Class Driver Microsoft Corporation Microsoft Windows Operating Syst
em 6.1.7601.17514 Service registry key doesn't exist or hidden.
[Drivers] :HKLM kbdhid=C:\WINDOWS\SYSTEM32\DRIVERS\KBDHID.SYS
### HID Keyboard Filter Driver Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385 Service registry key doesn't exist or hidden.
[Drivers] :HKLM KSecDD=C:\WINDOWS\SYSTEM32\DRIVERS\KSECDD.SYS
### Kernel Security Support Provider Interface Microsoft Corporation Microsoft
Windows Operating System 6.1.7601.18443 Service registry key doesn't exist or hi
dden.
[Drivers] :HKLM KSecPkg=C:\WINDOWS\SYSTEM32\DRIVERS\KSECPKG.SYS
### Kernel Security Support Provider Interface Packages Microsoft Corporation
Microsoft Windows Operating System 6.1.7601.18443 Service registry key doesn't ex
ist or hidden.
[Drivers] :HKLM ksthunk=C:\WINDOWS\SYSTEM32\DRIVERS\KSTHUNK.SYS
### Kernel Streaming WOW Thunk Service Microsoft Corporation Microsoft Windows O
perating System 6.1.7600.16385 \SystemRoot\system32\drivers\ksthunk.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM lltdio=C:\WINDOWS\SYSTEM32\DRIVERS\LLTDIO.SYS
### Link-Layer Topology Mapper I/O Driver Microsoft Corporation Microsoft Windo
ws Operating System 6.1.7600.16385 Service registry key doesn't exist or hidden.
[Drivers] :HKLM LSI_FC=C:\WINDOWS\SYSTEM32\DRIVERS\LSI_FC.SYS
### LSI Fusion-MPT FC Driver (StorPort) LSI Corporation Microsoft Windows Operat
ing System 6.1.7007.0 \SystemRoot\system32\DRIVERS\lsi_fc.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM LSI_SAS=C:\WINDOWS\SYSTEM32\DRIVERS\LSI_SAS.SYS
### LSI Fusion-MPT SAS Driver (StorPort) LSI Corporation Microsoft Windows Opera
ting System 6.1.7100.4100 \SystemRoot\system32\DRIVERS\lsi_sas.sys Service regi
stry key doesn't exist or hidden.
[Drivers] :HKLM LSI_SAS2=C:\WINDOWS\SYSTEM32\DRIVERS\LSI_SAS2.SYS
### LSI SAS Gen2 Driver (StorPort) LSI Corporation Microsoft Windows Operating S
ystem 6.1.7100.4100 \SystemRoot\system32\DRIVERS\lsi_sas2.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM LSI_SCSI=C:\WINDOWS\SYSTEM32\DRIVERS\LSI_SCSI.SYS
### LSI Fusion-MPT SCSI Driver (StorPort) LSI Corporation Microsoft Windows Oper
ating System 6.1.7083.0 \SystemRoot\system32\DRIVERS\lsi_scsi.sys Service regis
try key doesn't exist or hidden.
[Drivers] :HKLM luafv=C:\WINDOWS\SYSTEM32\DRIVERS\LUAFV.SYS
### LUA File Virtualization Filter Driver Microsoft Corporation Microsoft Windo
ws Operating System 6.1.7600.16385 \SystemRoot\system32\drivers\luafv.sys Servic
e registry key doesn't exist or hidden.
[Drivers] :HKLM megasas=C:\WINDOWS\SYSTEM32\DRIVERS\MEGASAS.SYS
### MEGASAS RAID Controller Driver for Windows 7\Server 2008 R2 for x64 LSI Co
rporation MEGASAS Storport Driver for Windows 7\Server 2008 R2 for x64 4.5.1.64
\SystemRoot\system32\DRIVERS\megasas.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM MegaSR=C:\WINDOWS\SYSTEM32\DRIVERS\MEGASR.SYS

### LSI MegaRAID Software RAID Driver LSI Corporation, Inc. MegaRAID Software
RAID 13.05.0409.2009 \SystemRoot\system32\DRIVERS\MegaSR.sys Service registry k
ey doesn't exist or hidden.
[Drivers] :HKLM MEIx64=C:\WINDOWS\SYSTEM32\DRIVERS\HECIX64.SYS
### Intel(R) Management Engine Interface Intel Corporation Intel(R) Management
Engine Interface 7.0.0.1144 Service registry key doesn't exist or hidden.
[Drivers] :HKLM Modem=C:\WINDOWS\SYSTEM32\DRIVERS\MODEM.SYS
### Modem Device Driver Microsoft Corporation Microsoft Windows Operating System
6.1.7600.16385 Service registry key doesn't exist or hidden.
[Drivers] :HKLM monitor=C:\WINDOWS\SYSTEM32\DRIVERS\MONITOR.SYS
### Monitor Driver Microsoft Corporation Microsoft Windows Operating System 6.1.
7600.16385 Service registry key doesn't exist or hidden.
[Drivers] :HKLM mouclass=C:\WINDOWS\SYSTEM32\DRIVERS\MOUCLASS.SYS
### Mouse Class Driver Microsoft Corporation Microsoft Windows Operating System
6.1.7600.16385 Service registry key doesn't exist or hidden.
[Drivers] :HKLM mouhid=C:\WINDOWS\SYSTEM32\DRIVERS\MOUHID.SYS
### HID Mouse Filter Driver Microsoft Corporation Microsoft Windows Operating Sy
stem 6.1.7600.16385 Service registry key doesn't exist or hidden.
[Drivers] :HKLM mountmgr=C:\WINDOWS\SYSTEM32\DRIVERS\MOUNTMGR.SYS
### Mount Point Manager Microsoft Corporation Microsoft Windows Operating System
6.1.7600.16385 Service registry key doesn't exist or hidden.
[Drivers] :HKLM mpio=C:\WINDOWS\SYSTEM32\DRIVERS\MPIO.SYS
### MultiPath Support Bus-Driver Microsoft Corporation Microsoft Windows Operati
ng System 6.1.7600.16385 \SystemRoot\system32\drivers\mpio.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM mpsdrv=C:\WINDOWS\SYSTEM32\DRIVERS\MPSDRV.SYS
### Microsoft Protection Service Driver Microsoft Corporation Microsoft Windows
Operating System 6.1.7600.16385 Service registry key doesn't exist or hidden.
[Drivers] :HKLM MRxDAV=C:\WINDOWS\SYSTEM32\DRIVERS\MRXDAV.SYS
### Windows NT WebDav Minirdr Microsoft Corporation Microsoft Windows Operating
System 6.1.7601.17514 \SystemRoot\system32\drivers\mrxdav.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM mrxsmb=C:\WINDOWS\SYSTEM32\DRIVERS\MRXSMB.SYS
### Windows NT SMB Minirdr Microsoft Corporation Microsoft Windows Operating Sys
tem 6.1.7601.17605 Service registry key doesn't exist or hidden.
[Drivers] :HKLM mrxsmb10=C:\WINDOWS\SYSTEM32\DRIVERS\MRXSMB10.SYS
### Longhorn SMB Downlevel SubRdr Microsoft Corporation Microsoft Windows Operat
ing System 6.1.7601.17647 Service registry key doesn't exist or hidden.
[Drivers] :HKLM mrxsmb20=C:\WINDOWS\SYSTEM32\DRIVERS\MRXSMB20.SYS
### Longhorn SMB 2.0 Redirector Microsoft Corporation Microsoft Windows Operatin
g System 6.1.7601.17605 Service registry key doesn't exist or hidden.
[Drivers] :HKLM msahci=C:\WINDOWS\SYSTEM32\DRIVERS\MSAHCI.SYS
### MS AHCI 1.0 Standard Driver Microsoft Corporation Microsoft Windows Operatin
g System 6.1.7601.17514 Service registry key doesn't exist or hidden.
[Drivers] :HKLM msdsm=C:\WINDOWS\SYSTEM32\DRIVERS\MSDSM.SYS
### Microsoft Device Specific Module Microsoft Corporation Microsoft Windows Ope
rating System 6.1.7600.16385 \SystemRoot\system32\drivers\msdsm.sys Service reg
istry key doesn't exist or hidden.
[Drivers] :HKLM mshidkmdf=C:\WINDOWS\SYSTEM32\DRIVERS\MSHIDKMDF.SYS
### Pass-through HID to KMDF Filter Driver Microsoft Corporation Microsoft Wind
ows Operating System 6.1.7600.16385 \SystemRoot\System32\drivers\mshidkmdf.sys S
ervice registry key doesn't exist or hidden.
[Drivers] :HKLM msisadrv=C:\WINDOWS\SYSTEM32\DRIVERS\MSISADRV.SYS
### ISA Driver Microsoft Corporation Microsoft Windows Operating System 6.1.7600
.16385 Service registry key doesn't exist or hidden.
[Drivers] :HKLM MSKSSRV=C:\WINDOWS\SYSTEM32\DRIVERS\MSKSSRV.SYS
### MS KS Server Microsoft Corporation Microsoft Windows Operating System 6.1.76
00.16385 Service registry key doesn't exist or hidden.
[Drivers] :HKLM MSPCLOCK=C:\WINDOWS\SYSTEM32\DRIVERS\MSPCLOCK.SYS
### MS Proxy Clock Microsoft Corporation Microsoft Windows Operating System 6.1.

7600.16385 Service registry key doesn't exist or hidden.


[Drivers] :HKLM MSPQM=C:\WINDOWS\SYSTEM32\DRIVERS\MSPQM.SYS
### MS Proxy Quality Manager Microsoft Corporation Microsoft Windows Operating S
ystem 6.1.7600.16385 Service registry key doesn't exist or hidden.
[Drivers] :HKLM mssmbios=C:\WINDOWS\SYSTEM32\DRIVERS\MSSMBIOS.SYS
### System Management BIOS Driver Microsoft Corporation Microsoft Windows Operat
ing System 6.1.7600.16385 \SystemRoot\system32\drivers\mssmbios.sys Service reg
istry key doesn't exist or hidden.
[Drivers] :HKLM MSTEE=C:\WINDOWS\SYSTEM32\DRIVERS\MSTEE.SYS
### WDM Tee/Communication Transform Filter Microsoft Corporation Microsoft Win
dows Operating System 6.1.7600.16385 Service registry key doesn't exist or hidde
n.
[Drivers] :HKLM MTConfig=C:\WINDOWS\SYSTEM32\DRIVERS\MTCONFIG.SYS
### Microsoft Multi-Touch HID Driver Microsoft Corporation Microsoft Windows Ope
rating System 6.1.7600.16385 \SystemRoot\system32\DRIVERS\MTConfig.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM Mup=C:\WINDOWS\SYSTEM32\DRIVERS\MUP.SYS
### Multiple UNC Provider Driver Microsoft Corporation Microsoft Windows Operati
ng System 6.1.7600.16385 Service registry key doesn't exist or hidden.
[Drivers] :HKLM NativeWifiP=C:\WINDOWS\SYSTEM32\DRIVERS\NWIFI.SYS
### NativeWiFi Miniport Driver Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385 Service registry key doesn't exist or hidden.
[Drivers] :HKLM NDIS=C:\WINDOWS\SYSTEM32\DRIVERS\NDIS.SYS
### NDIS 6.20 driver Microsoft Corporation Microsoft Windows Operating System 6.
1.7600.16385 Service registry key doesn't exist or hidden.
[Drivers] :HKLM NdisCap=C:\WINDOWS\SYSTEM32\DRIVERS\NDISCAP.SYS
### NDIS Packet Capture Filter Driver Microsoft Corporation Microsoft Windows Op
erating System 6.1.7600.16385 Service registry key doesn't exist or hidden.
[Drivers] :HKLM NdisTapi=C:\WINDOWS\SYSTEM32\DRIVERS\NDISTAPI.SYS
### NDIS 3.0 connection wrapper driver Microsoft Corporation Microsoft Windows O
perating System 6.1.7600.16385 Service registry key doesn't exist or hidden.
[Drivers] :HKLM Ndisuio=C:\WINDOWS\SYSTEM32\DRIVERS\NDISUIO.SYS
### NDIS User mode I/O driver Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385 Service registry key doesn't exist or hidden.
[Drivers] :HKLM NdisWan=C:\WINDOWS\SYSTEM32\DRIVERS\NDISWAN.SYS
### MS PPP Framing Driver (Strong Encryption) Microsoft Corporation Microsoft W
indows Operating System 6.1.7601.17514 Service registry key doesn't exist or hid
den.
[Drivers] :HKLM NetBIOS=C:\WINDOWS\SYSTEM32\DRIVERS\NETBIOS.SYS
### NetBIOS interface driver Microsoft Corporation Microsoft Windows Operating S
ystem 6.1.7600.16385 Service registry key doesn't exist or hidden.
[Drivers] :HKLM NetBT=C:\WINDOWS\SYSTEM32\DRIVERS\NETBT.SYS
### MBT Transport driver Microsoft Corporation Microsoft Windows Operating Syste
m 6.1.7601.17514 Service registry key doesn't exist or hidden.
[Drivers] :HKLM nfrd960=C:\WINDOWS\SYSTEM32\DRIVERS\NFRD960.SYS
### IBM ServeRAID Controller Driver IBM Corporation IBM ServeRAID Controller 7
.10.56 \SystemRoot\system32\DRIVERS\nfrd960.sys Service registry key doesn't ex
ist or hidden.
[Drivers] :HKLM nsiproxy=C:\WINDOWS\SYSTEM32\DRIVERS\NSIPROXY.SYS
### NSI Proxy Microsoft Corporation Microsoft Windows Operating System 6.1.7600.
16385 Service registry key doesn't exist or hidden.
[Drivers] :HKLM nvraid=C:\WINDOWS\SYSTEM32\DRIVERS\NVRAID.SYS
### NVIDIA nForce(TM) RAID Driver NVIDIA Corporation NVIDIA nForce(TM) RAID Dri
ver 10.6.0.18 \SystemRoot\system32\drivers\nvraid.sys Service registry key does
n't exist or hidden.
[Drivers] :HKLM nvstor=C:\WINDOWS\SYSTEM32\DRIVERS\NVSTOR.SYS
### NVIDIA nForce(TM) Sata Performance Driver NVIDIA Corporation NVIDIA nForce(
TM) SATA Driver 10.6.0.18 \SystemRoot\system32\drivers\nvstor.sys Service regis
try key doesn't exist or hidden.
[Drivers] :HKLM nv_agp=C:\WINDOWS\SYSTEM32\DRIVERS\NV_AGP.SYS

### NForce NT AGP Filter Microsoft Corporation Microsoft Windows Operating Syste
m 6.1.7600.16385 \SystemRoot\system32\drivers\nv_agp.sys Service registry key d
oesn't exist or hidden.
[Drivers] :HKLM ohci1394=C:\WINDOWS\SYSTEM32\DRIVERS\OHCI1394.SYS
### 1394 OpenHCI Port Driver Microsoft Corporation Microsoft Windows Operating S
ystem 6.1.7600.16385 \SystemRoot\system32\drivers\ohci1394.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM Parport=C:\WINDOWS\SYSTEM32\DRIVERS\PARPORT.SYS
### Parallel Port Driver Microsoft Corporation Microsoft Windows Operating Syste
m 6.1.7600.16385 Service registry key doesn't exist or hidden.
[Drivers] :HKLM Partizan=C:\Windows\system32\drivers\Partizan.sys
### File is deleted or hidden by a rootkit or could not be located. Service r
egistry key doesn't exist or hidden.
[Drivers] :HKLM partmgr=C:\WINDOWS\SYSTEM32\DRIVERS\PARTMGR.SYS
### Partition Management Driver Microsoft Corporation Microsoft Windows Operatin
g System 6.1.7600.16385 Service registry key doesn't exist or hidden.
[Drivers] :HKLM pci=C:\WINDOWS\SYSTEM32\DRIVERS\PCI.SYS
### NT Plug and Play PCI Enumerator Microsoft Corporation Microsoft Windows Oper
ating System 6.1.7600.16385 Service registry key doesn't exist or hidden.
[Drivers] :HKLM pciide=C:\WINDOWS\SYSTEM32\DRIVERS\PCIIDE.SYS
### Generic PCI IDE Bus Driver Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385 \SystemRoot\system32\drivers\pciide.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM pcmcia=C:\WINDOWS\SYSTEM32\DRIVERS\PCMCIA.SYS
### PCMCIA Bus Driver Microsoft Corporation Microsoft Windows Operating System 6
.1.7600.16385 \SystemRoot\system32\DRIVERS\pcmcia.sys Service registry key does
n't exist or hidden.
[Drivers] :HKLM pcw=C:\WINDOWS\SYSTEM32\DRIVERS\PCW.SYS
### Performance Counters for Windows Driver Microsoft Corporation Microsoft Win
dows Operating System 6.1.7600.16385 Service registry key doesn't exist or hidde
n.
[Drivers] :HKLM PEAUTH=C:\WINDOWS\SYSTEM32\DRIVERS\PEAUTH.SYS
### Protected Environment Authentication and Authorization Export Driver Micro
soft Corporation Microsoft Windows Operating System 6.1.7600.16385 Service regist
ry key doesn't exist or hidden.
[Drivers] :HKLM pelmouse=C:\WINDOWS\SYSTEM32\DRIVERS\PELMOUSE.SYS
### Mouse Suite Driver TPMX Electronics Ltd. Mouse Suite 98 2.1.0.0 Service
registry key doesn't exist or hidden.
[Drivers] :HKLM pelusblf=C:\WINDOWS\SYSTEM32\DRIVERS\PELUSBLF.SYS
### USB Mouse Filter Driver TPMX Electronics Ltd. Mouse Suite 98 2.1.0.0 Serv
ice registry key doesn't exist or hidden.
[Drivers] :HKLM PptpMiniport=C:\WINDOWS\SYSTEM32\DRIVERS\RASPPTP.SYS
### Peer-to-Peer Tunneling Protocol Microsoft Corporation Microsoft Windows Oper
ating System 6.1.7601.17514 Service registry key doesn't exist or hidden.
[Drivers] :HKLM Processor=C:\WINDOWS\SYSTEM32\DRIVERS\PROCESSR.SYS
### Processor Device Driver Microsoft Corporation Microsoft Windows Operating Sy
stem 6.1.7600.16385 \SystemRoot\system32\DRIVERS\processr.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM Psched=C:\WINDOWS\SYSTEM32\DRIVERS\PACER.SYS
### QoS Packet Scheduler Microsoft Corporation Microsoft Windows Operating Syste
m 6.1.7600.16385 Service registry key doesn't exist or hidden.
[Drivers] :HKLM pwdrvio=C:\WINDOWS\SYSTEM32\PWDRVIO.SYS
### \??\C:\Windows\system32\pwdrvio.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM pwdspio=C:\WINDOWS\SYSTEM32\PWDSPIO.SYS
### \??\C:\Windows\system32\pwdspio.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM ql2300=C:\WINDOWS\SYSTEM32\DRIVERS\QL2300.SYS
### QLogic Fibre Channel Stor Miniport Driver QLogic Corporation QLogic Fibre
Channel Stor Miniport Driver 9.1.8.6 \SystemRoot\system32\DRIVERS\ql2300.sys Se

rvice registry key doesn't exist or hidden.


[Drivers] :HKLM ql40xx=C:\WINDOWS\SYSTEM32\DRIVERS\QL40XX.SYS
### QLogic iSCSI Storport Miniport Driver QLogic Corporation QLA40XX iSCSI Hos
t Bus Adapter 2.1.3.20 (STOR wx64) \SystemRoot\system32\DRIVERS\ql40xx.sys Serv
ice registry key doesn't exist or hidden.
[Drivers] :HKLM QWAVEdrv=C:\WINDOWS\SYSTEM32\DRIVERS\QWAVEDRV.SYS
### Microsoft Quality Windows Audio Video Experience (qWave) Support Driver Mi
crosoft Corporation Microsoft Windows Operating System 6.1.7600.16385 \SystemRoot
\system32\drivers\qwavedrv.sys Service registry key doesn't exist or hidden.
[Drivers] :HKLM RasAcd=C:\WINDOWS\SYSTEM32\DRIVERS\RASACD.SYS
### RAS Automatic Connection Driver Microsoft Corporation Microsoft Windows Oper
ating System 6.1.7600.16385 Service registry key doesn't exist or hidden.
[Drivers] :HKLM RasAgileVpn=C:\WINDOWS\SYSTEM32\DRIVERS\AGILEVPN.SYS
### RAS Agile Vpn Miniport Call Manager Microsoft Corporation Microsoft Windows
Operating System 6.1.7600.16385 Service registry key doesn't exist or hidden.
[Drivers] :HKLM Rasl2tp=C:\WINDOWS\SYSTEM32\DRIVERS\RASL2TP.SYS
### RAS L2TP mini-port/call-manager driver Microsoft Corporation Microsoft Wind
ows Operating System 6.1.7601.17514 Service registry key doesn't exist or hidden
.
[Drivers] :HKLM RasPppoe=C:\WINDOWS\SYSTEM32\DRIVERS\RASPPPOE.SYS
### RAS PPPoE mini-port/call-manager driver Microsoft Corporation Microsoft Win
dows Operating System 6.1.7600.16385 Service registry key doesn't exist or hidde
n.
[Drivers] :HKLM RasSstp=C:\WINDOWS\SYSTEM32\DRIVERS\RASSSTP.SYS
### RAS SSTP Miniport Call Manager Microsoft Corporation Microsoft Windows Opera
ting System 6.1.7600.16385 Service registry key doesn't exist or hidden.
[Drivers] :HKLM rdbss=C:\WINDOWS\SYSTEM32\DRIVERS\RDBSS.SYS
### Redirected Drive Buffering SubSystem Driver Microsoft Corporation Microsof
t Windows Operating System 6.1.7600.16385 Service registry key doesn't exist or h
idden.
[Drivers] :HKLM rdpbus=C:\WINDOWS\SYSTEM32\DRIVERS\RDPBUS.SYS
### Microsoft RDP Bus Device driver Microsoft Corporation Microsoft Windows Oper
ating System 6.1.7600.16385 Service registry key doesn't exist or hidden.
[Drivers] :HKLM RDPCDD=C:\WINDOWS\SYSTEM32\DRIVERS\RDPCDD.SYS
### RDP Miniport Microsoft Corporation Microsoft Windows Operating System 6.1.76
00.16385 Service registry key doesn't exist or hidden.
[Drivers] :HKLM RDPDR=C:\WINDOWS\SYSTEM32\DRIVERS\RDPDR.SYS
### Microsoft RDP Device redirector Microsoft Corporation Microsoft Windows Oper
ating System 6.1.7601.17514 Service registry key doesn't exist or hidden.
[Drivers] :HKLM RDPENCDD=C:\WINDOWS\SYSTEM32\DRIVERS\RDPENCDD.SYS
### RDP Encoder Miniport Microsoft Corporation Microsoft Windows Operating Syste
m 6.1.7600.16385 Service registry key doesn't exist or hidden.
[Drivers] :HKLM RDPREFMP=C:\WINDOWS\SYSTEM32\DRIVERS\RDPREFMP.SYS
### RDP Reflector Driver Miniport Microsoft Corporation Microsoft Windows Operat
ing System 6.1.7600.16385 Service registry key doesn't exist or hidden.
[Drivers] :HKLM RdpVideoMiniport=C:\WINDOWS\SYSTEM32\DRIVERS\RDPVIDEOMINIPORT.
SYS
### Microsoft RDP Video Miniport driver Microsoft Corporation Microsoft Windows
Operating System 6.1.7601.17514 Service registry key doesn't exist or hidden.
[Drivers] :HKLM rdyboost=C:\WINDOWS\SYSTEM32\DRIVERS\RDYBOOST.SYS
### ReadyBoost Driver Microsoft Corporation Microsoft Windows Operating System 6
.1.7601.17514 Service registry key doesn't exist or hidden.
[Drivers] :HKLM Revoflt=C:\WINDOWS\SYSTEM32\DRIVERS\REVOFLT.SYS
### Revo Uninstaller Minifilter VS Revo Group Revo Uninstaller Pro 1, 0, 0, 4
Service registry key doesn't exist or hidden.
[Drivers] :HKLM rspndr=C:\WINDOWS\SYSTEM32\DRIVERS\RSPNDR.SYS
### Link-Layer Topology Responder Driver for NDIS 6 Microsoft Corporation Micr
osoft Windows Operating System 6.1.7600.16385 Service registry key doesn't exist
or hidden.
[Drivers] :HKLM RTL8167=C:\WINDOWS\SYSTEM32\DRIVERS\RT64WIN7.SYS

### Realtek 8136/8168/8169 NDIS 6.20 64-bit Driver


Realtek
Realtek 8136/8168/8169 PCI/PCIe Adapter
s
7.077.1126.2013 Service registry key doesn't exist or h
idden.
[Drivers] :HKLM s3cap=C:\WINDOWS\SYSTEM32\DRIVERS\VMS3CAP.SYS
### Microsoft S3 Emulated Device Cap Driver Microsoft Corporation Microsoft Win
dows Operating System 6.1.7601.17514 \SystemRoot\system32\drivers\vms3cap.sys Se
rvice registry key doesn't exist or hidden.
[Drivers] :HKLM SADP_NPF=C:\WINDOWS\SYSWOW64\DRIVERS\SADP_NPF64.SYS
### npf.sys (NT5/6 AMD64) Kernel Driver CACE Technologies, Inc. WinPcap 4.1.0.
2001 \??\C:\Windows\SysWOW64\drivers\sadp_npf64.sys Service registry key doesn'
t exist or hidden.
[Drivers] :HKLM sbp2port=C:\WINDOWS\SYSTEM32\DRIVERS\SBP2PORT.SYS
### SBP-2 Protocol Driver Microsoft Corporation Microsoft Windows Operating Syst
em 6.1.7601.17514 \SystemRoot\system32\drivers\sbp2port.sys Service registry ke
y doesn't exist or hidden.
[Drivers] :HKLM scfilter=C:\WINDOWS\SYSTEM32\DRIVERS\SCFILTER.SYS
### Microsoft Smart Card Reader Filter Driver Microsoft Corporation Microsoft W
indows Operating System 6.1.7600.16385 Service registry key doesn't exist or hid
den.
[Drivers] :HKLM semav6msr64=C:\WINDOWS\SYSTEM32\DRIVERS\SEMAV6MSR64.SYS
### \??\C:\Windows\system32\drivers\semav6msr64.sys Service registry key does
n't exist or hidden.
[Drivers] :HKLM Serenum=C:\WINDOWS\SYSTEM32\DRIVERS\SERENUM.SYS
### Serial Port Enumerator Microsoft Corporation Microsoft Windows Operating Sys
tem 6.1.7600.16385 Service registry key doesn't exist or hidden.
[Drivers] :HKLM Serial=C:\WINDOWS\SYSTEM32\DRIVERS\SERIAL.SYS
### Brotehr Serial I/F Driver (WDM) Brother Industries Ltd. Microsoft Windows Op
erating System 1.0.0.0,2006 Service registry key doesn't exist or hidden.
[Drivers] :HKLM sermouse=C:\WINDOWS\SYSTEM32\DRIVERS\SERMOUSE.SYS
### Serial Mouse Filter Driver Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385 \SystemRoot\system32\DRIVERS\sermouse.sys Service regist
ry key doesn't exist or hidden.
[Drivers] :HKLM sffdisk=C:\WINDOWS\SYSTEM32\DRIVERS\SFFDISK.SYS
### Small Form Factor Disk Driver Microsoft Corporation Microsoft Windows Operat
ing System 6.1.7600.16385 \SystemRoot\system32\drivers\sffdisk.sys Service regi
stry key doesn't exist or hidden.
[Drivers] :HKLM sffp_mmc=C:\WINDOWS\SYSTEM32\DRIVERS\SFFP_MMC.SYS
### Small Form Factor MMC Protocol Driver Microsoft Corporation Microsoft Windo
ws Operating System 6.1.7600.16385 \SystemRoot\system32\drivers\sffp_mmc.sys Ser
vice registry key doesn't exist or hidden.
[Drivers] :HKLM sffp_sd=C:\WINDOWS\SYSTEM32\DRIVERS\SFFP_SD.SYS
### Small Form Factor SD Protocol Driver Microsoft Corporation Microsoft Window
s Operating System 6.1.7601.17514 \SystemRoot\system32\drivers\sffp_sd.sys Servi
ce registry key doesn't exist or hidden.
[Drivers] :HKLM sfloppy=C:\WINDOWS\SYSTEM32\DRIVERS\SFLOPPY.SYS
### SCSI Floppy Driver Microsoft Corporation Microsoft Windows Operating System
6.1.7600.16385 \SystemRoot\system32\DRIVERS\sfloppy.sys Service registry key do
esn't exist or hidden.
[Drivers] :HKLM SiSRaid2=C:\WINDOWS\SYSTEM32\DRIVERS\SISRAID2.SYS
### SiS RAID Stor Miniport Driver Silicon Integrated Systems Corp. Microsoft Wi
ndows Operating System 2.60.01 \SystemRoot\system32\DRIVERS\SiSRaid2.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM SiSRaid4=C:\WINDOWS\SYSTEM32\DRIVERS\SISRAID4.SYS
### SiS AHCI Stor-Miniport Driver Silicon Integrated Systems Microsoft Windows O
perating System 6.1.6918.0 \SystemRoot\system32\DRIVERS\sisraid4.sys Service re
gistry key doesn't exist or hidden.
[Drivers] :HKLM Smb=C:\WINDOWS\SYSTEM32\DRIVERS\SMB.SYS
### SMB Transport driver Microsoft Corporation Microsoft Windows Operating Syste
m 6.1.7600.16385 Service registry key doesn't exist or hidden.

[Drivers] :HKLM SNP2UVC=C:\WINDOWS\SYSTEM32\DRIVERS\SNP2UVC.SYS


### UVC Camera Streaming Driver UVC Camera Streaming Driver 2, 1, 2, 0 Servic
e registry key doesn't exist or hidden.
[Drivers] :HKLM srv=C:\WINDOWS\SYSTEM32\DRIVERS\SRV.SYS
### Server driver Microsoft Corporation Microsoft Windows Operating System 6.1.7
600.16385 Service registry key doesn't exist or hidden.
[Drivers] :HKLM srv2=C:\WINDOWS\SYSTEM32\DRIVERS\SRV2.SYS
### Smb 2.0 Server driver Microsoft Corporation Microsoft Windows Operating Syst
em 6.1.7601.17608 Service registry key doesn't exist or hidden.
[Drivers] :HKLM srvnet=C:\WINDOWS\SYSTEM32\DRIVERS\SRVNET.SYS
### Server Network driver Microsoft Corporation Microsoft Windows Operating Syst
em 6.1.7601.17608 Service registry key doesn't exist or hidden.
[Drivers] :HKLM ssudmdm=C:\WINDOWS\SYSTEM32\DRIVERS\SSUDMDM.SYS
### SAMSUNG Android Modem Device Driver (MSS Ver.3) DEVGURU Co., LTD.(www.devg
uru.co.kr) SAMSUNG Android Modem Device Driver (MSS Ver.3) 2.11.10.0 Service re
gistry key doesn't exist or hidden.
[Drivers] :HKLM ssudobex=C:\WINDOWS\SYSTEM32\DRIVERS\SSUDOBEX.SYS
### SAMSUNG USB Mobile OBEX Device Driver (MSS Ver.3) DEVGURU Co., LTD.(www.de
vguru.co.kr) SAMSUNG USB Mobile OBEX Device Driver (MSS Ver.3) 2.11.10.0 Servic
e registry key doesn't exist or hidden.
[Drivers] :HKLM ssudserd=C:\WINDOWS\SYSTEM32\DRIVERS\SSUDSERD.SYS
### SAMSUNG USB Mobile Logging Device Driver (MSS Ver.3) DEVGURU Co., LTD.(www
.devguru.co.kr) SAMSUNG USB Mobile Logging Device Driver (MSS Ver.3) 2.11.10.0
Service registry key doesn't exist or hidden.
[Drivers] :HKLM stexstor=C:\WINDOWS\SYSTEM32\DRIVERS\STEXSTOR.SYS
### Promise SuperTrak EX Series Driver for Windows Promise Technology Promis
e SuperTrak EX Series 5.00 \SystemRoot\system32\DRIVERS\stexstor.sys Service r
egistry key doesn't exist or hidden.
[Drivers] :HKLM storflt=C:\WINDOWS\SYSTEM32\DRIVERS\VMSTORFL.SYS
### Virtual Storage Filter Driver Microsoft Corporation Microsoft Windows Operat
ing System 6.1.7601.17514 Service registry key doesn't exist or hidden.
[Drivers] :HKLM storvsc=C:\WINDOWS\SYSTEM32\DRIVERS\STORVSC.SYS
### Storage VSC Driver Microsoft Corporation Microsoft Windows Operating System
6.1.7601.17514 \SystemRoot\system32\drivers\storvsc.sys Service registry key do
esn't exist or hidden.
[Drivers] :HKLM swenum=C:\WINDOWS\SYSTEM32\DRIVERS\SWENUM.SYS
### Plug and Play Software Device Enumerator Microsoft Corporation Microsoft Wi
ndows Operating System 6.1.7600.16385 \SystemRoot\system32\drivers\swenum.sys Se
rvice registry key doesn't exist or hidden.
[Drivers] :HKLM Synth3dVsc=C:\Windows\System32\drivers\synth3dvsc.sys
### File is deleted or hidden by a rootkit or could not be located. Service r
egistry key doesn't exist or hidden.
[Drivers] :HKLM Tcpip=C:\WINDOWS\SYSTEM32\DRIVERS\TCPIP.SYS
### TCP/IP Driver Microsoft Corporation Microsoft Windows Operating System 6.1.7
600.16385 Service registry key doesn't exist or hidden.
[Drivers] :HKLM TCPIP6=C:\WINDOWS\SYSTEM32\DRIVERS\TCPIP.SYS
### TCP/IP Driver Microsoft Corporation Microsoft Windows Operating System 6.1.7
600.16385 Service registry key doesn't exist or hidden.
[Drivers] :HKLM tcpipreg=C:\WINDOWS\SYSTEM32\DRIVERS\TCPIPREG.SYS
### TCP/IP Registry Compatibility Driver Microsoft Corporation Microsoft Window
s Operating System 6.1.7601.17514 Service registry key doesn't exist or hidden.
[Drivers] :HKLM TDPIPE=C:\WINDOWS\SYSTEM32\DRIVERS\TDPIPE.SYS
### Named Pipe Transport Driver Microsoft Corporation Microsoft Windows Operatin
g System 6.1.7600.16385 Service registry key doesn't exist or hidden.
[Drivers] :HKLM TDTCP=C:\WINDOWS\SYSTEM32\DRIVERS\TDTCP.SYS
### TCP Transport Driver Microsoft Corporation Microsoft Windows Operating Syste
m 6.1.7601.17779 Service registry key doesn't exist or hidden.
[Drivers] :HKLM tdx=C:\WINDOWS\SYSTEM32\DRIVERS\TDX.SYS
### TDI Translation Driver Microsoft Corporation Microsoft Windows Operating Sys
tem 6.1.7601.17514 Service registry key doesn't exist or hidden.

[Drivers] :HKLM TermDD=C:\WINDOWS\SYSTEM32\DRIVERS\TERMDD.SYS


### Remote Desktop Server Driver Microsoft Corporation Microsoft Windows Operati
ng System 6.1.7601.17514 \SystemRoot\system32\drivers\termdd.sys Service regist
ry key doesn't exist or hidden.
[Drivers] :HKLM tssecsrv=C:\WINDOWS\SYSTEM32\DRIVERS\TSSECSRV.SYS
### TS Security Filter Driver Microsoft Corporation Microsoft Windows Operating
System 6.1.7601.18186 Service registry key doesn't exist or hidden.
[Drivers] :HKLM TsUsbFlt=C:\WINDOWS\SYSTEM32\DRIVERS\TSUSBFLT.SYS
### Remote Desktop USB Hub Filter Driver Microsoft Corporation Microsoft Window
s Operating System 6.1.7601.17514 Service registry key doesn't exist or hidden.
[Drivers] :HKLM tsusbhub=C:\Windows\system32\drivers\tsusbhub.sys
### File is deleted or hidden by a rootkit or could not be located. Service r
egistry key doesn't exist or hidden.
[Drivers] :HKLM tunnel=C:\WINDOWS\SYSTEM32\DRIVERS\TUNNEL.SYS
### Microsoft Tunnel Interface Driver Microsoft Corporation Microsoft Windows Op
erating System 6.1.7600.16385 Service registry key doesn't exist or hidden.
[Drivers] :HKLM uagp35=C:\WINDOWS\SYSTEM32\DRIVERS\UAGP35.SYS
### MS AGPv3.5 Filter Microsoft Corporation Microsoft Windows Operating System 6
.1.7600.16385 \SystemRoot\system32\DRIVERS\uagp35.sys Service registry key does
n't exist or hidden.
[Drivers] :HKLM udfs=C:\WINDOWS\SYSTEM32\DRIVERS\UDFS.SYS
### UDF File System Driver Microsoft Corporation Microsoft Windows Operating Sys
tem 6.1.7601.17514 Service registry key doesn't exist or hidden.
[Drivers] :HKLM uliagpkx=C:\WINDOWS\SYSTEM32\DRIVERS\ULIAGPKX.SYS
### ULi AGPv3.0 Filter for K8/9 Processor Platforms Microsoft Corporation Micr
osoft Windows Operating System 6.1.7600.16385 \SystemRoot\system32\drivers\uliagp
kx.sys Service registry key doesn't exist or hidden.
[Drivers] :HKLM umbus=C:\WINDOWS\SYSTEM32\DRIVERS\UMBUS.SYS
### User-Mode Bus Enumerator Microsoft Corporation Microsoft Windows Operating S
ystem 6.1.7600.16385 \SystemRoot\system32\drivers\umbus.sys Service registry ke
y doesn't exist or hidden.
[Drivers] :HKLM UmPass=C:\WINDOWS\SYSTEM32\DRIVERS\UMPASS.SYS
### Generic pass-through driver Microsoft Corporation Microsoft Windows Operatin
g System 6.1.7600.16385 \SystemRoot\system32\DRIVERS\umpass.sys Service registr
y key doesn't exist or hidden.
[Drivers] :HKLM USBAAPL64=C:\WINDOWS\SYSTEM32\DRIVERS\USBAAPL64.SYS
### Apple Mobile Device USB Driver Apple, Inc. Apple Mobile Device USB Driver
1.64.0.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM usbaudio=C:\WINDOWS\SYSTEM32\DRIVERS\USBAUDIO.SYS
### USB Audio Class Driver Microsoft Corporation Microsoft Windows Operating Sys
tem 6.1.7601.18208 \SystemRoot\system32\drivers\usbaudio.sys Service registry k
ey doesn't exist or hidden.
[Drivers] :HKLM usbccgp=C:\WINDOWS\SYSTEM32\DRIVERS\USBCCGP.SYS
### USB Common Class Generic Parent Driver Microsoft Corporation Microsoft Wind
ows Operating System 6.1.7601.18328 Service registry key doesn't exist or hidden
.
[Drivers] :HKLM usbcir=C:\WINDOWS\SYSTEM32\DRIVERS\USBCIR.SYS
### USB Consumer IR Driver for eHome Microsoft Corporation Microsoft Windows Ope
rating System 6.1.7601.18208 \SystemRoot\system32\drivers\usbcir.sys Service re
gistry key doesn't exist or hidden.
[Drivers] :HKLM usbehci=C:\WINDOWS\SYSTEM32\DRIVERS\USBEHCI.SYS
### EHCI eUSB Miniport Driver Microsoft Corporation Microsoft Windows Operating
System 6.1.7601.18328 Service registry key doesn't exist or hidden.
[Drivers] :HKLM usbhub=C:\WINDOWS\SYSTEM32\DRIVERS\USBHUB.SYS
### Default Hub Driver for USB Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385 Service registry key doesn't exist or hidden.
[Drivers] :HKLM usbohci=C:\WINDOWS\SYSTEM32\DRIVERS\USBOHCI.SYS
### OHCI USB Miniport Driver Microsoft Corporation Microsoft Windows Operating S
ystem 6.1.7601.18328 \SystemRoot\system32\drivers\usbohci.sys Service registry
key doesn't exist or hidden.

[Drivers] :HKLM usbprint=C:\WINDOWS\SYSTEM32\DRIVERS\USBPRINT.SYS


### USB Printer driver Microsoft Corporation Microsoft Windows Operating System
6.1.7600.16385 \SystemRoot\system32\DRIVERS\usbprint.sys Service registry key d
oesn't exist or hidden.
[Drivers] :HKLM usbrndis6=C:\WINDOWS\SYSTEM32\DRIVERS\USB80236.SYS
### Remote NDIS USB Driver Microsoft Corporation Microsoft Windows Operating Sys
tem 6.1.7601.18076 Service registry key doesn't exist or hidden.
[Drivers] :HKLM USBSTOR=C:\WINDOWS\SYSTEM32\DRIVERS\USBSTOR.SYS
### USB Mass Storage Class Driver Microsoft Corporation Microsoft Windows Operat
ing System 6.1.7601.17514 Service registry key doesn't exist or hidden.
[Drivers] :HKLM usbuhci=C:\WINDOWS\SYSTEM32\DRIVERS\USBUHCI.SYS
### UHCI USB Miniport Driver Microsoft Corporation Microsoft Windows Operating S
ystem 6.1.7601.18328 \SystemRoot\system32\drivers\usbuhci.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM usbvideo=C:\WINDOWS\SYSTEM32\DRIVERS\USBVIDEO.SYS
### USB Video Class Driver Microsoft Corporation Microsoft Windows Operating Sys
tem 6.1.7601.18208 \SystemRoot\System32\Drivers\usbvideo.sys Service registry k
ey doesn't exist or hidden.
[Drivers] :HKLM usb_rndisx=C:\WINDOWS\SYSTEM32\DRIVERS\USB8023X.SYS
### Remote NDIS USB Driver Microsoft Corporation Microsoft Windows Operating Sys
tem 6.1.7601.18076 Service registry key doesn't exist or hidden.
[Drivers] :HKLM vdrvroot=C:\WINDOWS\SYSTEM32\DRIVERS\VDRVROOT.SYS
### Virtual Drive Root Enumerator Microsoft Corporation Microsoft Windows Operat
ing System 6.1.7600.16385 Service registry key doesn't exist or hidden.
[Drivers] :HKLM vga=C:\WINDOWS\SYSTEM32\DRIVERS\VGAPNP.SYS
### VGA/Super VGA Video Driver Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385 Service registry key doesn't exist or hidden.
[Drivers] :HKLM VgaSave=C:\WINDOWS\SYSTEM32\DRIVERS\VGA.SYS
### VGA/Super VGA Video Driver Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385 \SystemRoot\System32\drivers\vga.sys Service registry ke
y doesn't exist or hidden.
[Drivers] :HKLM VGPU=C:\Windows\System32\drivers\rdvgkmd.sys
### File is deleted or hidden by a rootkit or could not be located. Service r
egistry key doesn't exist or hidden.
[Drivers] :HKLM vhdmp=C:\WINDOWS\SYSTEM32\DRIVERS\VHDMP.SYS
### VHD Miniport Driver Microsoft Corporation Microsoft Windows Operating System
6.1.7600.16385 \SystemRoot\system32\drivers\vhdmp.sys Service registry key doe
sn't exist or hidden.
[Drivers] :HKLM viaide=C:\WINDOWS\SYSTEM32\DRIVERS\VIAIDE.SYS
### VIA Generic PCI IDE Bus Driver VIA Technologies, Inc. VIA PCI IDE MINI Dri
ver 6,0,6000,170 \SystemRoot\system32\drivers\viaide.sys Service registry key d
oesn't exist or hidden.
[Drivers] :HKLM vmbus=C:\WINDOWS\SYSTEM32\DRIVERS\VMBUS.SYS
### Virtual Machine Bus Microsoft Corporation Microsoft Windows Operating System
6.1.7601.17514 Service registry key doesn't exist or hidden.
[Drivers] :HKLM VMBusHID=C:\WINDOWS\SYSTEM32\DRIVERS\VMBUSHID.SYS
### Microsoft VMBus HID Miniport Microsoft Corporation Microsoft Windows Operati
ng System 6.1.7601.17514 \SystemRoot\system32\drivers\VMBusHID.sys Service regi
stry key doesn't exist or hidden.
[Drivers] :HKLM vmci=C:\WINDOWS\SYSTEM32\DRIVERS\VMCI.SYS
### VMware PCI VMCI Bus Device VMware, Inc. VMware PCI VMCI Bus Device 9.5.10.
0 build-1141980 Service registry key doesn't exist or hidden.
[Drivers] :HKLM VMnetAdapter=C:\WINDOWS\SYSTEM32\DRIVERS\VMNETADAPTER.SYS
### VMware virtual network adapter driver (64-bit) VMware, Inc. VMware virtual
network adapter driver (64-bit) 4.2.1.0 build-1233679 Service registry key doe
sn't exist or hidden.
[Drivers] :HKLM VMnetBridge=C:\WINDOWS\SYSTEM32\DRIVERS\VMNETBRIDGE.SYS
### VMware bridge driver (64-bit) VMware, Inc. VMware bridge driver (64-bit) 4
.2.1.0 build-1233679 Service registry key doesn't exist or hidden.
[Drivers] :HKLM VMnetuserif=C:\WINDOWS\SYSTEM32\DRIVERS\VMNETUSERIF.SYS

### VMware network application interface driver (64-bit) VMware, Inc. VMware n
etwork application interface driver (64-bit) 4.2.1.0 build-1295980 \??\C:\Windo
ws\system32\drivers\vmnetuserif.sys Service registry key doesn't exist or hidden
.
[Drivers] :HKLM VMparport=C:\WINDOWS\SYSTEM32\DRIVERS\VMPARPORT.SYS
### VMware parallel port driver VMware, Inc. VMware parallel port driver 10.0.
0 build-1295980 \??\C:\Windows\system32\drivers\VMparport.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM vmusb=C:\WINDOWS\SYSTEM32\DRIVERS\VMUSB.SYS
### VMware USB driver VMware, Inc. VMware USB driver 4.1.0.2 build-1279205 Se
rvice registry key doesn't exist or hidden.
[Drivers] :HKLM vmx86=C:\WINDOWS\SYSTEM32\DRIVERS\VMX86.SYS
### VMware kernel driver VMware, Inc. VMware kernel driver 10.0.0 build-129598
0 \??\C:\Windows\system32\drivers\vmx86.sys Service registry key doesn't exist
or hidden.
[Drivers] :HKLM volmgr=C:\WINDOWS\SYSTEM32\DRIVERS\VOLMGR.SYS
### Volume Manager Driver Microsoft Corporation Microsoft Windows Operating Syst
em 6.1.7601.17514 Service registry key doesn't exist or hidden.
[Drivers] :HKLM volmgrx=C:\WINDOWS\SYSTEM32\DRIVERS\VOLMGRX.SYS
### Volume Manager Extension Driver Microsoft Corporation Microsoft Windows Oper
ating System 6.1.7600.16385 Service registry key doesn't exist or hidden.
[Drivers] :HKLM volsnap=C:\WINDOWS\SYSTEM32\DRIVERS\VOLSNAP.SYS
### Volume Shadow Copy Driver Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385 Service registry key doesn't exist or hidden.
[Drivers] :HKLM vsmraid=C:\WINDOWS\SYSTEM32\DRIVERS\VSMRAID.SYS
### VIA RAID DRIVER FOR AMD-X86-64 VIA Technologies Inc.,Ltd VIA RAID driver 6
.0.6000.6210 \SystemRoot\system32\DRIVERS\vsmraid.sys Service registry key does
n't exist or hidden.
[Drivers] :HKLM vsock=C:\WINDOWS\SYSTEM32\DRIVERS\VSOCK.SYS
### VMware vSockets Service VMware, Inc. VMware vSockets Service 9.5.7.0 build
-1253991 Service registry key doesn't exist or hidden.
[Drivers] :HKLM vstor2-mntapi20-shared=SysWOW64\drivers\vstor2-mntapi20-shared
.sys
### VMware Virtual Storage Volume Driver VMware, Inc. VMware vCenter Converter
Standalone 5.1.0 build-1027190 VMware Virtual Storage Volume Driver VMware, In
c. VMware vCenter Converter Standalone 5.1.0 build-1027190 File is deleted or hi
dden by a rootkit or could not be located. Service registry key doesn't exist or
hidden.
[Drivers] :HKLM vwifibus=C:\WINDOWS\SYSTEM32\DRIVERS\VWIFIBUS.SYS
### Virtual WiFi Bus Driver Microsoft Corporation Microsoft Windows Operating Sy
stem 6.1.7600.16385 \SystemRoot\System32\drivers\vwifibus.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM WacomPen=C:\WINDOWS\SYSTEM32\DRIVERS\WACOMPEN.SYS
### Wacom Serial Pen Tablet HID Driver Microsoft Corporation Microsoft Windows O
perating System 6.1.7600.16385 \SystemRoot\system32\DRIVERS\wacompen.sys Servic
e registry key doesn't exist or hidden.
[Drivers] :HKLM WANARP=C:\WINDOWS\SYSTEM32\DRIVERS\WANARP.SYS
### MS Remote Access and Routing ARP Driver Microsoft Corporation Microsoft Win
dows Operating System 6.1.7601.17514 Service registry key doesn't exist or hidde
n.
[Drivers] :HKLM Wanarpv6=C:\WINDOWS\SYSTEM32\DRIVERS\WANARP.SYS
### MS Remote Access and Routing ARP Driver Microsoft Corporation Microsoft Win
dows Operating System 6.1.7601.17514 Service registry key doesn't exist or hidde
n.
[Drivers] :HKLM Wd=C:\WINDOWS\SYSTEM32\DRIVERS\WD.SYS
### Microsoft Watchdog Timer Driver Microsoft Corporation Microsoft Windows Oper
ating System 6.1.7600.16385 \SystemRoot\system32\DRIVERS\wd.sys Service registr
y key doesn't exist or hidden.
[Drivers] :HKLM WDC_SAM=C:\WINDOWS\SYSTEM32\DRIVERS\WDCSAM64.SYS
### WD SCSI Architecture Model (SAM) driver Western Digital Technologies WD Ex

ternal Storage Service registry key doesn't exist or hidden.


[Drivers] :HKLM Wdf01000=C:\WINDOWS\SYSTEM32\DRIVERS\WDF01000.SYS
### Kernel Mode Driver Framework Runtime Microsoft Corporation Microsoft Window
s Operating System 1.11.9200.16648 Service registry key doesn't exist or hidden.
[Drivers] :HKLM WfpLwf=C:\WINDOWS\SYSTEM32\DRIVERS\WFPLWF.SYS
### WFP NDIS 6.20 Lightweight Filter Driver Microsoft Corporation Microsoft Win
dows Operating System 6.1.7600.16385 Service registry key doesn't exist or hidde
n.
[Drivers] :HKLM WIMMount=C:\WINDOWS\SYSTEM32\DRIVERS\WIMMOUNT.SYS
### Wim file system Driver Microsoft Corporation Microsoft Windows Operating Sys
tem 6.1.7600.16385 Service registry key doesn't exist or hidden.
[Drivers] :HKLM WinUsb=C:\WINDOWS\SYSTEM32\DRIVERS\WINUSB.SYS
### Windows USB Class Driver BETA Microsoft Corporation Microsoft Windows Operat
ing System 6.1.7601.17514 Service registry key doesn't exist or hidden.
[Drivers] :HKLM WmiAcpi=C:\WINDOWS\SYSTEM32\DRIVERS\WMIACPI.SYS
### Windows Management Interface for ACPI Microsoft Corporation Microsoft Windo
ws Operating System 6.1.7600.16385 \SystemRoot\system32\drivers\wmiacpi.sys Serv
ice registry key doesn't exist or hidden.
[Drivers] :HKLM ws2ifsl=C:\WINDOWS\SYSTEM32\DRIVERS\WS2IFSL.SYS
### Winsock2 IFS Layer Microsoft Corporation Microsoft Windows Operating System
6.1.7600.16385 \SystemRoot\system32\drivers\ws2ifsl.sys Service registry key do
esn't exist or hidden.
[Drivers] :HKLM WsAudioDevice_383S(1)=C:\WINDOWS\SYSTEM32\DRIVERS\WSAUDIODEVIC
E_383S(1).SYS
### Wondershare Virtual Audio Device Wondershare Virtual Audio driver 1.00 Se
rvice registry key doesn't exist or hidden.
[Drivers] :HKLM WudfPf=C:\WINDOWS\SYSTEM32\DRIVERS\WUDFPF.SYS
### Windows Driver Foundation - User-mode Driver Framework Platform Driver Mic
rosoft Corporation Microsoft Windows Operating System 6.1.7601.17514 Service regi
stry key doesn't exist or hidden.
[Drivers] :HKLM WUDFRd=C:\WINDOWS\SYSTEM32\DRIVERS\WUDFRD.SYS
### Windows Driver Foundation - User-mode Driver Framework Reflector Microsoft
Corporation Microsoft Windows Operating System 6.1.7601.17514 Service registry k
ey doesn't exist or hidden.
[Codecs] :HKLM vidc.mrle=C:\Windows\system32\MSRLE32.DLL
### Microsoft RLE Compressor Microsoft Corporation Microsoft Windows Operating S
ystem 6.1.7600.16385 msrle32.dll
[Codecs] :HKLM vidc.msvc=C:\Windows\system32\MSVIDC32.DLL
### Microsoft Video 1 Compressor Microsoft Corporation Microsoft Windows Operati
ng System 6.1.7600.16385 msvidc32.dll
[Codecs] :HKLM msacm.imaadpcm=C:\Windows\system32\IMAADP32.ACM
### IMA ADPCM CODEC for MSACM Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385 imaadp32.acm
[Codecs] :HKLM msacm.msg711=C:\Windows\system32\MSG711.ACM
### Microsoft CCITT G.711 (A-Law and u-Law) CODEC for MSACM Microsoft Corporat
ion Microsoft Windows Operating System 6.1.7600.16385 msg711.acm
[Codecs] :HKLM msacm.msgsm610=C:\Windows\system32\MSGSM32.ACM
### Microsoft GSM 6.10 Audio CODEC for MSACM Microsoft Corporation Microsoft Wi
ndows Operating System 6.1.7600.16385 msgsm32.acm
[Codecs] :HKLM msacm.msadpcm=C:\Windows\system32\MSADP32.ACM
### Microsoft ADPCM CODEC for MSACM Microsoft Corporation Microsoft Windows Oper
ating System 6.1.7600.16385 msadp32.acm
[Codecs] :HKLM midimapper=C:\Windows\system32\MIDIMAP.DLL
### Microsoft MIDI Mapper Microsoft Corporation Microsoft Windows Operating Syst
em 6.1.7600.16385 midimap.dll
[Codecs] :HKLM wavemapper=C:\Windows\system32\MSACM32.DRV
### Microsoft Sound Mapper Microsoft Corporation Microsoft Windows Operating Sys
tem 6.1.7600.16385 msacm32.drv
[Codecs] :HKLM vidc.uyvy=C:\Windows\system32\MSYUV.DLL
### Microsoft UYVY Video Decompressor Microsoft Corporation Microsoft Windows Op

erating System 6.1.7601.17514 msyuv.dll


[Codecs] :HKLM vidc.yuy2=C:\Windows\system32\MSYUV.DLL
### Microsoft UYVY Video Decompressor Microsoft Corporation Microsoft Windows Op
erating System 6.1.7601.17514 msyuv.dll
[Codecs] :HKLM vidc.yvyu=C:\Windows\system32\MSYUV.DLL
### Microsoft UYVY Video Decompressor Microsoft Corporation Microsoft Windows Op
erating System 6.1.7601.17514 msyuv.dll
[Codecs] :HKLM vidc.iyuv=C:\Windows\system32\IYUV_32.DLL
### Intel Indeo(R) Video YUV Codec Microsoft Corporation Microsoft Windows Opera
ting System 6.1.7600.16385 iyuv_32.dll
[Codecs] :HKLM vidc.i420=C:\Windows\system32\IYUV_32.DLL
### Intel Indeo(R) Video YUV Codec Microsoft Corporation Microsoft Windows Opera
ting System 6.1.7600.16385 iyuv_32.dll
[Codecs] :HKLM vidc.yvu9=C:\Windows\system32\TSBYUV.DLL
### Toshiba Video Codec Microsoft Corporation Microsoft Windows Operating System
6.1.7601.17514 tsbyuv.dll
[Codecs] :HKLM msacm.l3acm=C:\WINDOWS\SYSWOW64\L3CODECA.ACM
### MPEG Layer-3 Audio Codec for MSACM Fraunhofer Institut Integrierte Schaltu
ngen IIS MPEG Layer-3 Audio Codec for MSACM 1, 0, 0, 0
[Codecs] :HKLM vidc.cvid=iccvid.dll
### File is deleted or hidden by a rootkit or could not be located.
[Codecs] :HKLM wave=C:\Windows\system32\WDMAUD.DRV
### Winmm audio system driver Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385 wdmaud.drv
[Codecs] :HKLM midi=C:\Windows\system32\WDMAUD.DRV
### Winmm audio system driver Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385 wdmaud.drv
[Codecs] :HKLM mixer=C:\Windows\system32\WDMAUD.DRV
### Winmm audio system driver Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385 wdmaud.drv
[Codecs] :HKLM aux=C:\Windows\system32\WDMAUD.DRV
### Winmm audio system driver Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385 wdmaud.drv
[Codecs] :HKLM wave1=C:\Windows\system32\WDMAUD.DRV
### Winmm audio system driver Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385 wdmaud.drv
[Codecs] :HKLM midi1=C:\Windows\system32\WDMAUD.DRV
### Winmm audio system driver Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385 wdmaud.drv
[Codecs] :HKLM mixer1=C:\Windows\system32\WDMAUD.DRV
### Winmm audio system driver Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385 wdmaud.drv
[Codecs] :HKLM aux1=C:\Windows\system32\WDMAUD.DRV
### Winmm audio system driver Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385 wdmaud.drv
[Codecs] :HKLM wave2=C:\Windows\system32\WDMAUD.DRV
### Winmm audio system driver Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385 wdmaud.drv
[Codecs] :HKLM midi2=C:\Windows\system32\WDMAUD.DRV
### Winmm audio system driver Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385 wdmaud.drv
[Codecs] :HKLM mixer2=C:\Windows\system32\WDMAUD.DRV
### Winmm audio system driver Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385 wdmaud.drv
[Codecs] :HKLM aux2=C:\Windows\system32\WDMAUD.DRV
### Winmm audio system driver Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385 wdmaud.drv
[Codecs] :HKLM VIDC.CSCD=camcodec.dll
### File is deleted or hidden by a rootkit or could not be located.
[Codecs] :HKLM vidc.tscc=tsccvid.dll

### File is deleted or hidden by a rootkit or could not be located.


[Codecs] :HKLM wave3=C:\Windows\system32\WDMAUD.DRV
### Winmm audio system driver Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385 wdmaud.drv
[Codecs] :HKLM midi3=C:\Windows\system32\WDMAUD.DRV
### Winmm audio system driver Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385 wdmaud.drv
[Codecs] :HKLM mixer3=C:\Windows\system32\WDMAUD.DRV
### Winmm audio system driver Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385 wdmaud.drv
[Codecs] :HKLM aux3=C:\Windows\system32\WDMAUD.DRV
### Winmm audio system driver Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385 wdmaud.drv
[Codecs] :HKLM wave4=C:\Windows\system32\WDMAUD.DRV
### Winmm audio system driver Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385 wdmaud.drv
[Codecs] :HKLM midi4=C:\Windows\system32\WDMAUD.DRV
### Winmm audio system driver Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385 wdmaud.drv
[Codecs] :HKLM mixer4=C:\Windows\system32\WDMAUD.DRV
### Winmm audio system driver Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385 wdmaud.drv
[Codecs] :HKLM aux4=C:\Windows\system32\WDMAUD.DRV
### Winmm audio system driver Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385 wdmaud.drv
[Codecs] :HKLM wave5=C:\Windows\system32\WDMAUD.DRV
### Winmm audio system driver Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385 wdmaud.drv
[Codecs] :HKLM midi5=C:\Windows\system32\WDMAUD.DRV
### Winmm audio system driver Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385 wdmaud.drv
[Codecs] :HKLM mixer5=C:\Windows\system32\WDMAUD.DRV
### Winmm audio system driver Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385 wdmaud.drv
[Codecs] :HKLM aux5=C:\Windows\system32\WDMAUD.DRV
### Winmm audio system driver Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385 wdmaud.drv
[Codecs] :HKLM wave6=C:\Windows\system32\WDMAUD.DRV
### Winmm audio system driver Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385 wdmaud.drv
[Codecs] :HKLM midi6=C:\Windows\system32\WDMAUD.DRV
### Winmm audio system driver Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385 wdmaud.drv
[Codecs] :HKLM mixer6=C:\Windows\system32\WDMAUD.DRV
### Winmm audio system driver Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385 wdmaud.drv
[Codecs] :HKLM aux6=C:\Windows\system32\WDMAUD.DRV
### Winmm audio system driver Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385 wdmaud.drv
[Codecs] :HKLM wave7=C:\Windows\system32\WDMAUD.DRV
### Winmm audio system driver Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385 wdmaud.drv
[Codecs] :HKLM mixer7=C:\Windows\system32\WDMAUD.DRV
### Winmm audio system driver Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385 wdmaud.drv
[DCOM Components] :HKLM {F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}=""
[DCOM Components] :HKLM {5839FCA9-774D-42A1-ACDA-D6A79037F57F}=C:\WINDOWS\SYST
EM32\WBEM\FASTPROX.DLL
### WMI Custom Marshaller Microsoft Corporation Microsoft Windows Operating Syst
em 6.1.7600.16385

[DCOM Components] :HKLM {42AEDC87-2188-41FD-B9A3-0C966FEABEC1}=C:\WINDOWS\SYST


EM32\SHELL32.DLL
### Windows Shell Common Dll Microsoft Corporation Microsoft Windows Operating S
ystem 6.1.7601.17514
[DCOM User Components] :HKCU {F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}=""
[DCOM User Components] :HKCU {FBEB8A05-BEEE-4442-804E-409D6C4515E9}=""
[DCOM User Components] :HKCU {42AEDC87-2188-41FD-B9A3-0C966FEABEC1}=""
[Auto Start Apps]
[Registry Run] :HKCU WSHelperSetup.exe=C:\PROGRAM FILES (X86)\COMMON FILES\WON
DERSHARE\WONDERSHARE HELPER COMPACT\WSHELPER.EXE
### Wondershare Studio Wondershare Wondershare Studio 1.2.5.30
[Registry Run] :HKCU KiesPreload=C:\PROGRAM FILES (X86)\SAMSUNG\KIES\KIES.EXE
### Kies Samsung Kies 1.0.0.1821 C:\Program Files (x86)\Samsung\Kies\Kies.exe
/preload
[Registry Run] :HKCU Sony PC Companion=C:\PROGRAM FILES (X86)\SONY\SONY PC COM
PANION\PCCOMPANION.EXE
### Sony PC Companion Sony Sony PC Companion 2.1.0 "C:\Program Files (x86)\So
ny\Sony PC Companion\PCCompanion.exe" /Background
[Registry Run] :HKCU DevidAgent=C:\USERS\ADMIN\DOWNLOADS\SCI_AGENT_SETUP(2).EX
E
### DevID Agent DevID DevID Agent 1.0.0.0 C:\Users\admin\Downloads\SCI_Agent_
Setup(2).exe /autorun
[Registry Run] :HKCU QuickTime Task=C:\PROGRAM FILES (X86)\QUICKTIME\QTTASK.EX
E
### QuickTime Task Apple Inc. QuickTime QuickTime 7.7.5 (1680.95.13) "C:\Prog
ram Files (x86)\QuickTime\QTTask.exe" -atboottime
[Registry Run] :HKLM WordWeb=C:\PROGRAM FILES (X86)\WORDWEB\WWEB32.EXE
### WordWeb Thesaurus/Dictionary WordWeb Software WordWeb 6.0.2.0 "C:\Program
Files (x86)\WordWeb\wweb32.exe" -startup
[Registry Run] :HKLM Wondershare Helper Compact.exe=C:\PROGRAM FILES (X86)\COM
MON FILES\WONDERSHARE\WONDERSHARE HELPER COMPACT\WSHELPER.EXE
### Wondershare Studio Wondershare Wondershare Studio 1.2.5.30
[Registry Run] :HKLM WD Quick View=C:\PROGRAM FILES (X86)\WESTERN DIGITAL\WD Q
UICK VIEW\WDDMSTATUS.EXE
### WD Quick View Western Digital Technologies, Inc. WDDMStatus.exe 3.2.0.15
[Registry Run] :HKLM vmware-tray.exe=C:\PROGRAM FILES (X86)\VMWARE\VMWARE WORK
STATION\VMWARE-TRAY.EXE
### VMware Tray Process VMware, Inc. VMware Workstation 10.0.0 build-1295980
"C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe"
[Registry Run] :HKLM tsnp2uvc=C:\WINDOWS\TSNP2UVC.EXE
### tsnp2uvc Microsoft tsnp2uvc 1, 1, 7, 0
[Registry Run] :HKLM QuickTime Task=C:\PROGRAM FILES (X86)\QUICKTIME\QTTASK.EX
E
### QuickTime Task Apple Inc. QuickTime QuickTime 7.7.5 (1680.95.13) "C:\Prog
ram Files (x86)\QuickTime\QTTask.exe" -atboottime
[Registry Run] :HKLM iTunesHelper=C:\PROGRAM FILES (X86)\ITUNES\ITUNESHELPER.E
XE
### iTunesHelper Apple Inc. iTunes 11.2.2.3 "C:\Program Files (x86)\iTunes\iT
unesHelper.exe"
[Registry Run] :HKLM GrooveMonitor=C:\PROGRAM FILES (X86)\MICROSOFT OFFICE\OFF
ICE12\GROOVEMONITOR.EXE
### GrooveMonitor Utility Microsoft Corporation GrooveMonitor Utility 4.2.0.26
23 "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
[Registry Run] :HKLM FixCamera=C:\WINDOWS\FIXCAMERA.EXE
### CameraFixer SONIX CameraFixer Application 1, 0, 1, 2
[Registry Run] :HKLM KiesTrayAgent=C:\PROGRAM FILES (X86)\SAMSUNG\KIES\KIESTRA
YAGENT.EXE
### Kies TrayAgent Application Samsung Electronics Co., Ltd. Kies TrayAgent 0.
0.0.25
[Registry Run] :HKLM PWRISOVM.EXE=C:\PROGRAM FILES (X86)\POWERISO\PWRISOVM.EXE

### PowerISO Virtual Drive Manager Power Software Ltd PowerISO Virtual Drive M
anager 5, 1, 0, 0 C:\Program Files (x86)\PowerISO\PWRISOVM.EXE -startup
[Registry Run] :HKLM Acrobat Assistant 7.0=C:\PROGRAM FILES (X86)\ADOBE\ACROBA
T 7.0\DISTILLR\ACROTRAY.EXE
### AcroTray Adobe Systems Inc. AcroTray - Adobe Acrobat Distiller helper appl
ication. 6.0.1.2004121400 "C:\Program Files (x86)\Adobe\Acrobat 7.0\Distillr\Ac
rotray.exe"
[Registry Run] :HKLM "Default Value"=""
### File is deleted or hidden by a rootkit or could not be located.
[Registry Run] :HKLM SunJavaUpdateSched=C:\PROGRAM FILES (X86)\COMMON FILES\JA
VA\JAVA UPDATE\JUSCHED.EXE
### Java Update Scheduler Oracle Corporation Java Platform SE Auto Updater 2.8
.77.3 "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
[Registry Run] :HKLM MalwareProtectionLive=C:\USERS\ADMIN\APPDATA\LOCAL\MALWAR
EPROTECTIONLIVE\MALWAREPROTECTIONCLIENT.EXE
### MalwareProtectionClient MalwareProtectionClient 1.0.*
[Registry Run(x64)] :HKLM Daemon for Mouse Suite=C:\PROGRAM FILES\LENOVO\LENOV
O MOUSE SUITE\ICO.EXE
### Mouse Suite 98 Daemon Primax Electronics Ltd. MouseSuite 98 1.0.0.1 C:\Pr
ogram Files\Lenovo\Lenovo Mouse Suite\ICO.EXE 30
[Registry Run(x64)] :HKLM Skd8821=C:\PROGRAM FILES\LENOVO\LENOVO SLIM USB KEYB
OARD\SKD8821.EXE
### Lenovo Slim USB Keyboard LITE-ON TECHNOLOGY CORP. Lenovo Slim USB Keyboard
1, 0, 0, 0
[Registry Run(x64)] :HKLM AdobeAAMUpdater-1.0=C:\PROGRAM FILES (X86)\COMMON FI
LES\ADOBE\OOBE\PDAPP\UWA\UPDATERSTARTUPUTILITY.EXE
### Adobe Updater Startup Utility Adobe Systems Incorporated Adobe Updater Sta
rtup Utility 6.2.0.4 (BuildVersion: 1.0; BuildDate: BUILDDATETIME) "C:\Program
Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
[Win.ini] :HKCU load=""
### File is deleted or hidden by a rootkit or could not be located.
[Win.ini] :HKCU run=""
### File is deleted or hidden by a rootkit or could not be located.
[Common Startup Folder] Adobe Acrobat Speed Launcher.lnk=C:\WINDOWS\INSTALLER\
{AC76BA86-1033-0000-7760-000000000002}\SC_ACROBAT.EXE
[Common Startup Folder] Canon LBP2900 Status Window.lnk=C:\WINDOWS\SYSTEM32\SP
OOL\DRIVERS\X64\3\CNAB4LAD.EXE
### Canon Advanced Printing Technology Printer Status Window Launcher CANON IN
C. Canon Advanced Printing Technology 3.10.0.003
[Common Startup Folder] ResultsHubDesktopSearch.lnk=C:\ProgramData\Results Hub
\ResultsHubDesktopSearch.exe
### File is deleted or hidden by a rootkit or could not be located.
[Scheduled Tasks] Bidaily Synchronize Task[973b]=c:\programdata\{415f24e7-9d9e
-594e-415f-f24e79d9939e}\setup_product_18129.exe
### File is deleted or hidden by a rootkit or could not be located.
[Scheduled Tasks] Adobe Flash Player Updater=C:\WINDOWS\SYSWOW64\MACROMED\FLAS
H\FLASHPLAYERUPDATESERVICE.EXE
### Adobe Flash Player Update Service 21.0 r0 Adobe Systems Incorporated Adobe Fl
ash Player Update Service 21,0,0,213
[Scheduled Tasks] 6012184b-f747-477b-804f-54428b83a7ef-5_user=C:\Program Files
(x86)\SavePass 1.1\6012184b-f747-477b-804f-54428b83a7ef-5.exe
### File is deleted or hidden by a rootkit or could not be located.
[Scheduled Tasks] 6012184b-f747-477b-804f-54428b83a7ef-5=C:\Program Files (x86
)\SavePass 1.1\6012184b-f747-477b-804f-54428b83a7ef-5.exe
### File is deleted or hidden by a rootkit or could not be located.
[Scheduled Tasks] 0615tbUpdateInfo=C:\PROGRAMDATA\AVG_UPDATE_0615TB\0615TB_{64
222B53-94A6-4D8F-A700-11BD2ACB2FBE}.EXE
### 06.15.0.4
[Scheduled Tasks] UpdaterEX=C:\Users\admin\AppData\Roaming\UPDATE~1\UPDATE~1\U
PDATE~1.EXE

### File is deleted or hidden by a rootkit or could not be located.


[Scheduled Tasks] GoogleUpdateTaskMachineUA=C:\PROGRAM FILES (X86)\GOOGLE\UPDA
TE\GOOGLEUPDATE.EXE
### Google Installer Google Inc. Google Update 1.3.29.1
[Scheduled Tasks] GoogleUpdateTaskMachineCore=C:\PROGRAM FILES (X86)\GOOGLE\UP
DATE\GOOGLEUPDATE.EXE
### Google Installer Google Inc. Google Update 1.3.29.1
[Scheduled Tasks] Flash Update=C:\WINDOWS\UPDATE.JS
### C:\Windows\system32\wscript.exe //nologo //B C:\Windows\update.js
[Unwanted Software Files] :HKLM C:\Users\admin\AppData\Roaming\NEWNEXT.ME\=C:\
Users\admin\AppData\Roaming\NEWNEXT.ME\
[Unwanted Software Files] :HKLM C:\ProgramData\HOUSE OF SOFT\=C:\ProgramData\H
OUSE OF SOFT\
[Unwanted Software Files] :HKLM freestar=C:\PROGRAM FILES (X86)\FREESTAR\
[Unwanted Software Files] :HKLM GreenTree Applications=C:\PROGRAM FILES (X86)\
GREENTREE APPLICATIONS\
[Unwanted Software Files] :HKLM SpaceSondPro=C:\PROGRAM FILES (X86)\SPACESONDP
RO\
[Unwanted Software Files] :HKLM SpaceSondPro_v57.1407=C:\PROGRAM FILES (X86)\S
PACESONDPRO_V57.1407\
[Unwanted Software Files] :HKLM UpdaterEX=C:\USERS\ADMIN\APPDATA\ROAMING\UPDAT
EREX\
[Unwanted Software Files] :HKLM AVG Security Toolbar=C:\PROGRAMDATA\AVG SECURI
TY TOOLBAR\
[Unwanted Software Files] :HKLM Results Hub=C:\PROGRAMDATA\RESULTS HUB\
[Unwanted Software Files] :HKLM vWinManProv=C:\PROGRAMDATA\VWINMANPROV\
[Unwanted Software Files] :HKLM genienext=C:\USERS\ADMIN\APPDATA\LOCAL\GENIENE
XT\
[Unwanted Software Files] :HKLM MalwareProtectionLive=C:\USERS\ADMIN\APPDATA\L
OCAL\MALWAREPROTECTIONLIVE\
[Unwanted Software Files] :HKLM Popajar=C:\USERS\ADMIN\APPDATA\LOCAL\POPAJAR\
[Detected using Heuristic Algorithm] :HKLM UNHACKME=C:\PROGRAM FILES (X86)\UNH
ACKME\
[Detected using Heuristic Algorithm] :HKLM TEMP=C:\USERS\ADMIN\APPDATA\LOCAL\T
EMP\
[Detected using Heuristic Algorithm] :HKLM FREE DOWNLOAD MANAGER=C:\USERS\ADMI
N\APPDATA\ROAMING\FREE DOWNLOAD MANAGER\
[Detected using Heuristic Algorithm] :HKLM MIPONY=C:\USERS\ADMIN\APPDATA\ROAMI
NG\MIPONY\
[Detected using Heuristic Algorithm] :HKLM VLC=C:\USERS\ADMIN\APPDATA\ROAMING\
VLC\
[Detected using Heuristic Algorithm] :HKLM DESKTOP=C:\USERS\ADMIN\DESKTOP\
[Detected using Heuristic Algorithm] :HKLM DOWNLOADS=C:\USERS\ADMIN\DOWNLOADS\
[In memory]
[Running Processes] C:\PROGRAM FILES (X86)\GOOGLE\GOOGLE INPUT TOOLS\GOOGLEINP
UTHANDLER.EXE
### Google Input Tools Google Inc. Google Input Tools 1.1.3.18
[Running Processes] C:\PROGRAM FILES (X86)\UNHACKME\HACKMON.EXE
### Detects Rootkits in background Greatis Software UnHackMe 7.1
[Running Processes] C:\PROGRAM FILES (X86)\COMMON FILES\WONDERSHARE\WONDERSHAR
E HELPER COMPACT\WSHELPER.EXE
### Wondershare Studio Wondershare Wondershare Studio 1.2.5.30
[Running Processes] C:\PROGRAM FILES (X86)\SAMSUNG\KIES\KIES.EXE
### Kies Samsung Kies 1.0.0.1821
[Running Processes] C:\PROGRAM FILES (X86)\SONY\SONY PC COMPANION\PCCOMPANION.
EXE
### Sony PC Companion Sony Sony PC Companion 2.1.0
[Running Processes] C:\USERS\ADMIN\DOWNLOADS\SCI_AGENT_SETUP(2).EXE
### DevID Agent DevID DevID Agent 1.0.0.0
[Running Processes] C:\PROGRAM FILES (X86)\SONY\SONY PC COMPANION\PCCOMPANIONI

NFO.EXE
[Running Processes] C:\PROGRAM FILES (X86)\WORDWEB\WWEB32.EXE
### WordWeb Thesaurus/Dictionary WordWeb Software WordWeb 6.0.2.0
[Running Processes] C:\PROGRAM FILES (X86)\WESTERN DIGITAL\WD QUICK VIEW\WDDMS
TATUS.EXE
### WD Quick View Western Digital Technologies, Inc. WDDMStatus.exe 3.2.0.15
[Running Processes] C:\PROGRAM FILES (X86)\VMWARE\VMWARE WORKSTATION\VMWARE-TR
AY.EXE
### VMware Tray Process VMware, Inc. VMware Workstation 10.0.0 build-1295980
[Running Processes] C:\WINDOWS\TSNP2UVC.EXE
### tsnp2uvc Microsoft tsnp2uvc 1, 1, 7, 0
[Running Processes] C:\WINDOWS\FIXCAMERA.EXE
### CameraFixer SONIX CameraFixer Application 1, 0, 1, 2
[Running Processes] C:\PROGRAM FILES (X86)\SAMSUNG\KIES\KIESTRAYAGENT.EXE
### Kies TrayAgent Application Samsung Electronics Co., Ltd. Kies TrayAgent 0.
0.0.25
[Running Processes] C:\PROGRAM FILES (X86)\POWERISO\PWRISOVM.EXE
### PowerISO Virtual Drive Manager Power Software Ltd PowerISO Virtual Drive M
anager 5, 1, 0, 0
[Running Processes] C:\PROGRAM FILES (X86)\ADOBE\ACROBAT 7.0\DISTILLR\ACROTRAY
.EXE
### AcroTray Adobe Systems Inc. AcroTray - Adobe Acrobat Distiller helper appl
ication. 6.0.1.2004121400
[Running Processes] C:\PROGRAM FILES (X86)\COMMON FILES\JAVA\JAVA UPDATE\JUSCH
ED.EXE
### Java Update Scheduler Oracle Corporation Java Platform SE Auto Updater 2.8
.77.3
[Running Processes] C:\USERS\ADMIN\APPDATA\LOCAL\MALWAREPROTECTIONLIVE\MALWARE
PROTECTIONCLIENT.EXE
### MalwareProtectionClient MalwareProtectionClient 1.0.*
[Running Processes] C:\PROGRAM FILES (X86)\COMMON FILES\JAVA\JAVA UPDATE\JUCHE
CK.EXE
### Java Update Checker Oracle Corporation Java Platform SE Auto Updater 2.8.7
7.3
[Running Processes] C:\PROGRAM FILES (X86)\FREE DOWNLOAD MANAGER\FDM.EXE
### Free Download Manager FreeDownloadManager.ORG Free Download Manager 3.9.4
[Running Processes] C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\FIREFOX.EXE
### Firefox Mozilla Corporation Firefox 39.0.3
[Running Processes] C:\PROGRAMDATA\FREE DOWNLOAD MANAGER\FIREFOX\EXTENSIONS\2.
1.4\FDMBROWSERHELPER.EXE
### FDM Browser Helper FreeDownloadManager.ORG Free Download Manager 0.0.0.0
[Running Processes] C:\PROGRAM FILES (X86)\COMMON FILES\ADOBE\ARM\1.0\ADOBEARM
.EXE
### Adobe Reader and Acrobat Manager Adobe Systems Incorporated Adobe Reader a
nd Acrobat Manager 1.824.16.6751
[Running Processes] C:\PROGRAM FILES (X86)\UNHACKME\UNHACKME.EXE
### Detects and removes rootkits Greatis Software UnHackMe 7.70
[Running Processes] C:\PROGRAM FILES (X86)\UNHACKME\REANIMATOR.EXE
### RegRun Start Control Greatis Software RegRun Security Suite 7.70 release
[Loaded DLLs] C:\Windows\System32\mstask.dll
### Task Scheduler interface DLL Microsoft Corporation Microsoft Windows Operati
ng System 6.1.7600.16385
[Loaded DLLs] C:\Windows\SysWOW64\wer.dll
### Windows Error Reporting DLL Microsoft Corporation Microsoft Windows Operatin
g System 6.1.7600.16385
[Loaded DLLs] C:\Windows\SysWOW64\XmlLite.dll
### Microsoft XmlLite Library Microsoft Corporation Microsoft XML Core Service
s 1.3.1000.0
[Loaded DLLs] C:\Windows\SysWOW64\gameux.dll

### Games Explorer Microsoft Corporation Microsoft Windows Operating System 6.1.
7600.16385
[Loaded DLLs] C:\Program Files (x86)\UnHackMe\parser.dll
### Analytics Parser Greatis Software UnHackMe 7.65
[Loaded DLLs] C:\Windows\system32\RICHED20.dll
### Rich Text Edit Control, v3.1 Microsoft Corporation Microsoft RichEdit Cont
rol, version 3.1 3.1
[Loaded DLLs] C:\Windows\system32\RICHED32.DLL
### Wrapper Dll for Richedit 1.0 Microsoft Corporation Microsoft Windows Operati
ng System 6.1.7601.17514
[Loaded DLLs] C:\Windows\SysWOW64\qmgrprxy.dll
### Background Intelligent Transfer Service Proxy Microsoft Corporation Micros
oft Windows Operating System 7.5.7600.16385
[Loaded DLLs] C:\Windows\system32\EhStorAPI.dll
### Windows Enhanced Storage API Microsoft Corporation Microsoft Windows Operati
ng System 6.1.7600.16385
[Loaded DLLs] C:\Windows\SysWOW64\PhotoMetadataHandler.dll
### Photo Metadata Handler Microsoft Corporation Microsoft Windows Operating Sys
tem 6.1.7600.16385
[Loaded DLLs] C:\PROGRA~2\MICROS~1\Office12\GRA32A~1.DLL
### GrooveSystemServices Module Microsoft Corporation GrooveSystemServices Mod
ule 4.2.0.2623
[Loaded DLLs] C:\Windows\system32\NetworkExplorer.dll
### Network Explorer Microsoft Corporation Microsoft Windows Operating System 6.
1.7600.16385
[Loaded DLLs] C:\Windows\SysWOW64\oleacc.dll
### Active Accessibility Core Component Microsoft Corporation Microsoft Windows
Operating System 6.1.7601.17676
[Loaded DLLs] C:\Windows\SysWOW64\thumbcache.dll
### Microsoft Thumbnail Cache Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385
[Loaded DLLs] C:\Windows\system32\SearchFolder.dll
### SearchFolder Microsoft Corporation Microsoft Windows Operating System 6.1.76
00.16385
[Loaded DLLs] C:\Program Files (x86)\Internet Explorer\ieproxy.dll
### IE ActiveX Interface Marshaling Library Microsoft Corporation Internet Exp
lorer 11.00.9600.17041
[Loaded DLLs] C:\Windows\SysWOW64\actxprxy.dll
### ActiveX Interface Marshaling Library Microsoft Corporation Microsoft Window
s Operating System 6.1.7601.17514
[Loaded DLLs] C:\Windows\System32\StructuredQuery.dll
### Structured Query Microsoft Corporation Windows Search 7.00.7601.17514
[Loaded DLLs] C:\Program Files (x86)\Common Files\microsoft shared\ink\tiptsf.
dll
### Tablet PC Input Panel Text Services Framework Microsoft Corporation Micros
oft Windows Operating System 6.1.7600.16385
[Loaded DLLs] C:\Windows\System32\comdlg32.dll
### Common Dialogs DLL Microsoft Corporation Microsoft Windows Operating System
6.1.7600.16385
[Loaded DLLs] C:\Windows\system32\icm32.dll
### Microsoft Color Management Module (CMM) Microsoft Corporation Microsoft Win
dows Operating System 6.1.7600.16385
[Loaded DLLs] C:\PROGRA~2\MICROS~1\Office12\GrooveNew.DLL
### GrooveNew Module Microsoft Corporation GrooveNew Module 4.2.0.2623
[Loaded DLLs] C:\PROGRA~2\MICROS~1\Office12\GrooveUtil.DLL
### GrooveUtil Module Microsoft Corporation GrooveUtil Module 4.2.0.2623
[Loaded DLLs] C:\Windows\SysWOW64\msmpeg2adec.dll
### Microsoft DTV-DVD Audio Decoder Microsoft Corporation Microsoft Windows Oper
ating System 6.1.7140.0
[Loaded DLLs] C:\Windows\SysWOW64\bcrypt.dll

### Windows Cryptographic Primitives Library (Wow64) Microsoft Corporation Mic


rosoft Windows Operating System 6.1.7600.16385
[Loaded DLLs] C:\Windows\SysWOW64\POWRPROF.dll
### Power Profile Helper DLL Microsoft Corporation Microsoft Windows Operating S
ystem 6.1.7600.16385
[Loaded DLLs] C:\Windows\SysWOW64\EVR.dll
### Enhanced Video Renderer DLL Microsoft Corporation Microsoft Windows Operatin
g System 6.1.7600.16385
[Loaded DLLs] C:\Windows\SysWOW64\msmpeg2vdec.dll
### Microsoft DTV-DVD Video Decoder Microsoft Corporation Microsoft Windows Oper
ating System 12.0.9200.16426
[Loaded DLLs] C:\Windows\system32\dxva2.dll
### DirectX Video Acceleration 2.0 DLL Microsoft Corporation Microsoft Windows O
perating System 6.1.7600.16385
[Loaded DLLs] C:\Windows\system32\ksuser.dll
### User CSA Library Microsoft Corporation Microsoft Windows Operating System 6.
1.7600.16385
[Loaded DLLs] C:\Windows\system32\ATL.DLL
### ATL Module for Windows XP (Unicode) Microsoft Corporation Microsoft (R) Vi
sual C++ 6.05.2284
[Loaded DLLs] C:\Windows\system32\mf.dll
### Media Foundation DLL Microsoft Corporation Microsoft Windows Operating Syste
m 12.0.7600.16385
[Loaded DLLs] C:\Windows\system32\mfreadwrite.dll
### Media Foundation ReadWrite DLL Microsoft Corporation Microsoft Windows Opera
ting System 12.0.7600.16385
[Loaded DLLs] C:\Windows\system32\AVRT.dll
### Multimedia Realtime Runtime Microsoft Corporation Microsoft Windows Operatin
g System 6.1.7600.16385
[Loaded DLLs] C:\Windows\system32\mfplat.dll
### Media Foundation Platform DLL Microsoft Corporation Microsoft Windows Operat
ing System 12.0.7600.16385
[Loaded DLLs] C:\Windows\system32\LINKINFO.dll
### Windows Volume Tracking Microsoft Corporation Microsoft Windows Operating Sy
stem 6.1.7600.16385
[Loaded DLLs] C:\Windows\syswow64\PSAPI.DLL
### Process Status Helper Microsoft Corporation Microsoft Windows Operating Syst
em 6.1.7600.16385
[Loaded DLLs] C:\ProgramData\Free Download Manager\Firefox\Extensions\2.1.4\Fd
mBhSniffDllProxy.dll
### FDM component FreeDownloadManager.ORG Free Download Manager 0.0.0.0
[Loaded DLLs] C:\Windows\system32\DUI70.dll
### Windows DirectUI Engine Microsoft Corporation Microsoft Windows Operating Sy
stem 6.1.7600.16385
[Loaded DLLs] C:\Windows\system32\DUser.dll
### Windows DirectUser Engine Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385
[Loaded DLLs] C:\Windows\system32\explorerframe.dll
### ExplorerFrame Microsoft Corporation Microsoft Windows Operating System 6.1.7
600.16385
[Loaded DLLs] C:\Program Files (x86)\Mozilla Firefox\nssckbi.dll
### NSS Builtin Trusted Root CAs Mozilla Foundation Network Security Services
2.4
[Loaded DLLs] C:\Program Files (x86)\Mozilla Firefox\freebl3.dll
### NSS freebl Library Mozilla Foundation Network Security Services 3.19.2 Bas
ic ECC
[Loaded DLLs] C:\Program Files (x86)\Mozilla Firefox\nssdbm3.dll
### Legacy Database Driver Mozilla Foundation Network Security Services 3.19.2
Basic ECC
[Loaded DLLs] C:\Program Files (x86)\Mozilla Firefox\softokn3.dll

### NSS PKCS #11 Library Mozilla Foundation Network Security Services 3.19.2 B
asic ECC
[Loaded DLLs] C:\Windows\system32\mscms.dll
### Microsoft Color Matching System DLL Microsoft Corporation Microsoft Windows
Operating System 6.1.7600.16385
[Loaded DLLs] C:\Program Files (x86)\Free Download Manager\fdmumsp.dll
[Loaded DLLs] C:\Program Files (x86)\Free Download Manager\flvsniff.dll
### flvsniff Free Download Manager 0, 0, 0, 0
[Loaded DLLs] C:\Windows\system32\AUDIOSES.DLL
### Audio Session Microsoft Corporation Microsoft Windows Operating System 6.1.7
600.16385
[Loaded DLLs] C:\Windows\System32\MMDevApi.dll
### MMDevice API Microsoft Corporation Microsoft Windows Operating System 6.1.76
00.16385
[Loaded DLLs] C:\Program Files (x86)\Free Download Manager\detoured.dll
### Marks process modified by Detours technology. Microsoft Corporation Micros
oft Research Detours Package Express Version 2.1 Build_216
[Loaded DLLs] C:\Windows\System32\wevtapi.dll
### Eventing Consumption and Configuration API Microsoft Corporation Microsoft
Windows Operating System 6.1.7600.16385
[Loaded DLLs] C:\Windows\System32\Wpc.dll
### WPC Settings Library Microsoft Corporation Windows 1.0.0.1
[Loaded DLLs] C:\Windows\system32\NTDSAPI.dll
### Active Directory Domain Services API Microsoft Corporation Microsoft Window
s Operating System 6.1.7600.16385
[Loaded DLLs] C:\Windows\system32\wbem\fastprox.dll
### WMI Custom Marshaller Microsoft Corporation Microsoft Windows Operating Syst
em 6.1.7600.16385
[Loaded DLLs] C:\Windows\system32\wbem\wbemsvc.dll
### WMI Microsoft Corporation Microsoft Windows Operating System 6.1.7600.16385
[Loaded DLLs] C:\Windows\system32\wbemcomn.dll
### WMI Microsoft Corporation Microsoft Windows Operating System 6.1.7601.17514
[Loaded DLLs] C:\Windows\system32\wbem\wbemprox.dll
### WMI Microsoft Corporation Microsoft Windows Operating System 6.1.7600.16385
[Loaded DLLs] C:\Program Files (x86)\Mozilla Firefox\browser\components\browse
rcomps.dll
### Mozilla Foundation Firefox 39.0.3
[Loaded DLLs] C:\Windows\system32\pdh.dll
### Windows Performance Data Helper DLL Microsoft Corporation Microsoft Windows
Operating System 6.1.7600.16385
[Loaded DLLs] C:\Windows\system32\NETAPI32.dll
### Net Win32 API DLL Microsoft Corporation Microsoft Windows Operating System 6
.1.7601.17887
[Loaded DLLs] C:\Program Files (x86)\Mozilla Firefox\icudt52.dll
### ICU Data DLL The ICU Project International Components for Unicode 52, 1, 0
, 0
[Loaded DLLs] C:\Program Files (x86)\Mozilla Firefox\icuuc52.dll
### ICU Common DLL The ICU Project International Components for Unicode 52, 1,
0, 0
[Loaded DLLs] C:\Program Files (x86)\Mozilla Firefox\icuin52.dll
### ICU I18N DLL The ICU Project International Components for Unicode 52, 1, 0
, 0
[Loaded DLLs] C:\Program Files (x86)\Mozilla Firefox\xul.dll
### Mozilla Foundation Firefox 39.0.3
[Loaded DLLs] C:\Program Files (x86)\Mozilla Firefox\mozalloc.dll
### Mozilla Foundation Firefox 39.0.3
[Loaded DLLs] C:\Program Files (x86)\Mozilla Firefox\sandboxbroker.dll
### Mozilla Foundation Firefox 39.0.3
[Loaded DLLs] C:\Program Files (x86)\Mozilla Firefox\nss3.dll
### Mozilla Foundation Firefox 39.0.3

[Loaded DLLs] C:\Program Files (x86)\Mozilla Firefox\MSVCP120.dll


### Microsoft C Runtime Library Microsoft Corporation Microsoft Visual Studio 201
3 12.00.21005.1
[Loaded DLLs] C:\Program Files (x86)\Mozilla Firefox\MSVCR120.dll
### Microsoft C Runtime Library Microsoft Corporation Microsoft Visual Studio 201
3 12.00.21005.1
[Loaded DLLs] C:\Program Files (x86)\Mozilla Firefox\mozglue.dll
### Mozilla Foundation Firefox 39.0.3
[Loaded DLLs] C:\Windows\system32\wkscli.dll
### Workstation Service Client DLL Microsoft Corporation Microsoft Windows Opera
ting System 6.1.7601.17514
[Loaded DLLs] C:\Windows\System32\DAVHLPR.dll
### DAV Helper DLL Microsoft Corporation Microsoft Windows Operating System 6.1.
7600.16385
[Loaded DLLs] C:\Windows\System32\davclnt.dll
### Web DAV Client DLL Microsoft Corporation Microsoft Windows Operating System
6.1.7601.17514
[Loaded DLLs] C:\Windows\System32\ntlanman.dll
### Microsoft Lan Manager Microsoft Corporation Microsoft Windows Operating Syste
m 6.1.7600.16385
[Loaded DLLs] C:\Windows\System32\drprov.dll
### Microsoft Remote Desktop Session Host Server Network Provider Microsoft Co
rporation Microsoft Windows Operating System 6.1.7600.16385
[Loaded DLLs] C:\Windows\system32\SAMLIB.dll
### SAM Library DLL Microsoft Corporation Microsoft Windows Operating System 6.1
.7600.16385
[Loaded DLLs] C:\Windows\WinSxS\x86_microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50
727.42_none_dc990e4797f81af1\ATL80.DLL
### ATL Module for Windows (Unicode) Microsoft Corporation Microsoft Visual Stu
dio 2005 8.00.50727.42
[Loaded DLLs] C:\PROGRA~2\MICROS~1\Office12\GrooveNew.DLL
### GrooveNew Module Microsoft Corporation GrooveNew Module 4.2.0.2623
[Loaded DLLs] C:\PROGRA~2\MICROS~1\Office12\GrooveUtil.DLL
### GrooveUtil Module Microsoft Corporation GrooveUtil Module 4.2.0.2623
[Loaded DLLs] C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL
### GrooveShellExtensions Module Microsoft Corporation GrooveShellExtensions M
odule 4.2.0.2623
[Loaded DLLs] C:\Windows\system32\EhStorShell.dll
### Windows Enhanced Storage Shell Extension DLL Microsoft Corporation Microso
ft Windows Operating System 6.1.7600.16385
[Loaded DLLs] C:\Windows\system32\d3d11.dll
### Direct3D 11 Runtime Microsoft Corporation Microsoft Windows Operating System
6.2.9200.16570
[Loaded DLLs] C:\Program Files (x86)\Free Download Manager\fdmbtsupp.dll
[Loaded DLLs] C:\Windows\system32\dbghelp.dll
### Windows Image Helper Microsoft Corporation Microsoft Windows Operating Syste
m 6.1.7601.17514
[Loaded DLLs] C:\Windows\System32\shdocvw.dll
### Shell Doc Object and Control Library Microsoft Corporation Microsoft Window
s Operating System 6.1.7601.18222
[Loaded DLLs] C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089
\System.Data.dll
### .NET Framework Microsoft Corporation Microsoft .NET Framework 2.0.50727.542
0
[Loaded DLLs] C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\dbc23
6ca6655e4e3839ee4f802eb3f99\System.Data.ni.dll
### .NET Framework Microsoft Corporation Microsoft .NET Framework 2.0.50727.542
0
[Loaded DLLs] C:\Windows\system32\shfolder.dll
### Shell Folder Service Microsoft Corporation Microsoft Windows Operating Syste

m 6.1.7600.16385
[Loaded DLLs] C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configurat
ion\5b6ddf934128d538cd5cd77bf4209b93\System.Configuration.ni.dll
### System.Configuration.dll Microsoft Corporation Microsoft .NET Framework 2.0
.50727.5476
[Loaded DLLs] C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\217ece
46920546d718414291d463bb1c\System.Xml.ni.dll
### .NET Framework Microsoft Corporation Microsoft .NET Framework 2.0.50727.547
6
[Loaded DLLs] C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Fo
rms\8bc548587e91ecf0552a40e47bbf99cc\System.Windows.Forms.ni.dll
### .NET Framework Microsoft Corporation Microsoft .NET Framework 2.0.50727.546
8
[Loaded DLLs] C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\5c
24d3b0041ebf4f48a93615b9fa3de9\System.Drawing.ni.dll
### .NET Framework Microsoft Corporation Microsoft .NET Framework 2.0.50727.546
7
[Loaded DLLs] C:\Windows\assembly\NativeImages_v2.0.50727_32\System\b3a7826984
7005365001c33870cd121f\System.ni.dll
### .NET Framework Microsoft Corporation Microsoft .NET Framework 2.0.50727.546
7
[Loaded DLLs] C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll
### Microsoft .NET Runtime Just-In-Time Compiler Microsoft Corporation Microso
ft .NET Framework 2.0.50727.5467
[Loaded DLLs] C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsec.dll
### Microsoft .NET Security module Microsoft Corporation Microsoft .NET Framewo
rk 2.0.50727.4927
[Loaded DLLs] C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\ede2c6c8
42840e009f01bcc74fa4c457\mscorlib.ni.dll
### Microsoft Common Language Runtime Class Library Microsoft Corporation Micr
osoft .NET Framework 2.0.50727.5477
[Loaded DLLs] C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
### Microsoft .NET Runtime Common Language Runtime - WorkStation Microsoft Cor
poration Microsoft .NET Framework 2.0.50727.5477
[Loaded DLLs] C:\Windows\system32\sfc_os.DLL
### Windows File Protection Microsoft Corporation Microsoft Windows Operating Sy
stem 6.1.7600.16385
[Loaded DLLs] C:\Windows\system32\sfc.dll
### Windows File Protection Microsoft Corporation Microsoft Windows Operating Sy
stem 6.1.7600.16385
[Loaded DLLs] C:\Windows\system32\samcli.dll
### Security Accounts Manager Client DLL Microsoft Corporation Microsoft Window
s Operating System 6.1.7601.17514
[Loaded DLLs] C:\Windows\AppPatch\ACGENRAL.DLL
### Windows Compatibility DLL Microsoft Corporation Microsoft Windows Operating
System 6.1.7601.17514
[Loaded DLLs] C:\Windows\system32\netutils.dll
### Net Win32 API Helpers DLL Microsoft Corporation Microsoft Windows Operating
System 6.1.7601.17514
[Loaded DLLs] C:\Windows\system32\slc.dll
### Software Licensing Client Dll Microsoft Corporation Microsoft Windows Operat
ing System 6.1.7600.16385
[Loaded DLLs] C:\Windows\system32\cscapi.dll
### Offline Files Win32 API Microsoft Corporation Microsoft Windows Operating Sy
stem 6.1.7601.17514
[Loaded DLLs] C:\Windows\system32\srvcli.dll
### Server Service Client DLL Microsoft Corporation Microsoft Windows Operating
System 6.1.7601.17514
[Loaded DLLs] C:\Windows\system32\ntshrui.dll
### Shell extensions for sharing Microsoft Corporation Microsoft Windows Operati

ng System 6.1.7600.16385
[Loaded DLLs] C:\Program Files (x86)\FileZilla FTP Client\fzshellext.dll
### fzshellext Dynamic Link Library fzshellext Dynamic Link Library 3, 13, 1,
0
[Loaded DLLs] C:\Windows\system32\SSDPAPI.dll
### SSDP Client API DLL Microsoft Corporation Microsoft Windows Operating System
6.1.7600.16385
[Loaded DLLs] C:\Windows\system32\upnphost.dll
### UPnP Device Host Microsoft Corporation Microsoft Windows Operating System 6.
1.7600.16385
[Loaded DLLs] C:\Program Files (x86)\Samsung\Kies\External\DeviceModules\UPNPD
evice_Kies.dll
### UPnP SDK Device Host Kies Device Windows (R) Codename Longhorn DDK provide
r Windows (R) Codename Longhorn DDK driver 6.0.6000.16384
[Loaded DLLs] C:\Windows\WinSxS\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0
.30729.4148_none_4973eb1d754a9dc9\MFC90ENU.DLL
### MFC Language Specific Resources Microsoft Corporation Microsoft Visual Stud
io 2008 9.00.30729.4148
[Loaded DLLs] C:\Windows\WinSxS\x86_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30
729.4148_none_4bf5400abf9d60b7\mfc90u.dll
### MFCDLL Shared Library - Retail Version Microsoft Corporation Microsoft Visu
al Studio 2008 9.00.30729.4148
[Loaded DLLs] C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30
729.4940_none_50916076bcb9a742\MSVCP90.dll
### Microsoft C++ Runtime Library Microsoft Corporation Microsoft Visual Studio 2
008 9.00.30729.4940
[Loaded DLLs] C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30
729.4940_none_50916076bcb9a742\MSVCR90.dll
### Microsoft C Runtime Library Microsoft Corporation Microsoft Visual Studio 200
8 9.00.30729.4940
[Loaded DLLs] C:\Windows\system32\WINSTA.dll
### Winstation Library Microsoft Corporation Microsoft Windows Operating System
6.1.7601.17514
[Loaded DLLs] C:\Windows\syswow64\IMM32.dll
### Multi-User Windows IMM32 API Client DLL Microsoft Corporation Microsoft Win
dows Operating System 6.1.7601.17514
[Loaded DLLs] C:\Windows\system32\msi.dll
### Windows Installer Microsoft Corporation Windows Installer - Unicode 5.0.76
01.17514
[Loaded DLLs] C:\Windows\system32\WTSAPI32.dll
### Windows Remote Desktop Session Host Server SDK APIs Microsoft Corporation
Microsoft Windows Operating System 6.1.7600.16385
[Loaded DLLs] C:\Program Files (x86)\WordWeb\WUCNT.dll
[Loaded DLLs] C:\Windows\system32\oleacc.dll
### Active Accessibility Core Component Microsoft Corporation Microsoft Windows
Operating System 6.1.7601.17676
[Loaded DLLs] C:\Windows\system32\wweb32.dll
[Loaded DLLs] C:\Program Files (x86)\Sony\Sony PC Companion\bvrpctln.dll
### Custom controls and utilities library Avanquest Software MPT 2.00
[Loaded DLLs] C:\Windows\system32\dhcpcsvc.DLL
### DHCP Client Service Microsoft Corporation Microsoft Windows Operating System
6.1.7600.16385
[Loaded DLLs] C:\Windows\system32\dhcpcsvc6.DLL
### DHCPv6 Client Microsoft Corporation Microsoft Windows Operating System 6.1.7
600.16385
[Loaded DLLs] C:\Program Files (x86)\Sony\Sony PC Companion\DeviceIO.dll
### DeviceIO Core Library Avanquest Software PC Companion 1.0.0.1
[Loaded DLLs] C:\Program Files (x86)\Windows Portable Devices\SqmApi.dll
### SQM Client Microsoft Corporation Microsoft Windows Operating System 6.1.7601
.17514

[Loaded DLLs] C:\Windows\system32\PortableDeviceTypes.dll


### Windows Portable Device (Parameter) Types Component Microsoft Corporation
Microsoft Windows Operating System 6.1.7600.16385
[Loaded DLLs] C:\Windows\system32\PortableDeviceApi.dll
### Windows Portable Device API Components Microsoft Corporation Microsoft Wind
ows Operating System 6.1.7600.16385
[Loaded DLLs] C:\Windows\system32\SensApi.dll
### SENS Connectivity API DLL Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385
[Loaded DLLs] C:\Windows\system32\cryptnet.dll
### Crypto Network Related API Microsoft Corporation Microsoft Windows Operating
System 6.1.7601.18205
[Loaded DLLs] C:\Windows\system32\GPAPI.dll
### Group Policy Client API Microsoft Corporation Microsoft Windows Operating Sy
stem 6.1.7600.16385
[Loaded DLLs] C:\Windows\SysWOW64\bcryptprimitives.dll
### Windows Cryptographic Primitives Library Microsoft Corporation Microsoft Wi
ndows Operating System 6.1.7600.16385
[Loaded DLLs] C:\Windows\system32\bcrypt.dll
### Windows Cryptographic Primitives Library Microsoft Corporation Microsoft Wi
ndows Operating System 6.1.7600.16385
[Loaded DLLs] C:\Windows\system32\ncrypt.dll
### Windows cryptographic library Microsoft Corporation Microsoft Windows Operat
ing System 6.1.7600.16385
[Loaded DLLs] C:\Windows\SysWOW64\schannel.dll
### TLS / SSL Security Provider Microsoft Corporation Microsoft Windows Operatin
g System 6.1.7601.18409
[Loaded DLLs] C:\Windows\system32\credssp.dll
### Credential Delegation Security Package Microsoft Corporation Microsoft Wind
ows Operating System 6.1.7601.18409
[Loaded DLLs] C:\Windows\system32\USERENV.dll
### Userenv Microsoft Corporation Microsoft Windows Operating System 6.1.7600.16
385
[Loaded DLLs] C:\Windows\system32\MLANG.dll
### Multi Language Support DLL Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385
[Loaded DLLs] C:\Windows\system32\D3D10Warp.dll
### Direct3D 10 Rasterizer Microsoft Corporation Microsoft Windows Operating Sys
tem 6.2.9200.16783
[Loaded DLLs] C:\Windows\system32\d3d11.dll
### Direct3D 11 Runtime Microsoft Corporation Microsoft Windows Operating System
6.2.9200.16570
[Loaded DLLs] C:\Windows\system32\dxgi.dll
### DirectX Graphics Infrastructure Microsoft Corporation Microsoft Windows Oper
ating System 6.2.9200.16492
[Loaded DLLs] C:\Windows\system32\d2d1.dll
### Microsoft D2D Library Microsoft Corporation Microsoft Windows Operating Syst
em 6.2.9200.16492
[Loaded DLLs] C:\Windows\system32\msls31.dll
### Microsoft Line Services library file Microsoft Corporation Microsoft Line S
ervices 3.10
[Loaded DLLs] C:\Windows\SysWOW64\jscript9.dll
### Microsoft JScript Microsoft Corporation Internet Explorer 11.00.9600.17041
[Loaded DLLs] C:\Windows\system32\msimtf.dll
### Active IMM Server DLL Microsoft Corporation Microsoft Windows Operating Syst
em 6.1.7600.16385
[Loaded DLLs] C:\Windows\system32\rtutils.dll
### Routing Utilities Microsoft Corporation Microsoft Windows Operating System 6
.1.7601.17514

[Loaded DLLs] C:\Windows\System32\npmproxy.dll


### Network List Manager Proxy Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385
[Loaded DLLs] C:\Windows\System32\netprofm.dll
### Network List Manager Microsoft Corporation Microsoft Windows Operating Syste
m 6.1.7600.16385
[Loaded DLLs] C:\Program Files (x86)\Sony\Sony PC Companion\SonyEricssonMTPExt
.dll
### Sony Ericsson MTP Extension Library Avanquest Software PC Companion 2.10.0
[Loaded DLLs] C:\Program Files (x86)\Sony\Sony PC Companion\deviceupdate.dll
### Device update Sony Mobile Device update 1.0.7
[Loaded DLLs] C:\Program Files (x86)\Sony\Sony PC Companion\PCCWebServices.dll
### WebServices Core Library Avanquest Software PC Companion 1.0.0.1
[Loaded DLLs] C:\Program Files (x86)\Sony\Sony PC Companion\Statistics.dll
### Statistics Core Library Avanquest Software PC Companion 1.0.0.1
[Loaded DLLs] C:\Windows\SysWOW64\mshtml.dll
### Microsoft (R) HTML Viewer Microsoft Corporation Internet Explorer 11.00.96
00.17041
[Loaded DLLs] C:\Program Files (x86)\Sony\Sony PC Companion\PhoneUpdate.dll
[Loaded DLLs] C:\Program Files (x86)\Sony\Sony PC Companion\ContactSetup.dll
### ContactSetup.dll Avanquest Software PC Companion 1.0.0.1
[Loaded DLLs] C:\Program Files (x86)\Sony\Sony PC Companion\CrashDump.dll
### PC Companion CrashDump Library Avanquest Software PC Companion 2.10.0.0
[Loaded DLLs] C:\Windows\system32\odbcint.dll
### ODBC Resources Microsoft Corporation Microsoft Windows Operating System 6.1.
7600.16385
[Loaded DLLs] C:\Windows\system32\XmlLite.dll
### Microsoft XmlLite Library Microsoft Corporation Microsoft XML Core Service
s 1.3.1000.0
[Loaded DLLs] C:\Windows\system32\ODBC32.dll
### ODBC Driver Manager Microsoft Corporation Microsoft Windows Operating System
6.1.7601.17514
[Loaded DLLs] C:\Windows\system32\MFC42.DLL
### MFCDLL Shared Library - Retail Version Microsoft Corporation Microsoft (R)
Visual C++ 6.06.400
[Loaded DLLs] C:\Program Files (x86)\Sony\Sony PC Companion\VObject.dll
### VObject DLL Bibliothque de liaison dynamique VObject 1, 0, 0, 1
[Loaded DLLs] C:\Program Files (x86)\Sony\Sony PC Companion\PhoneMigration.dll
### PC Companion Phone Migration Avanquest Software PC Companion 2.0.0
[Loaded DLLs] C:\Program Files (x86)\Sony\Sony PC Companion\sqlite3.dll
### SQLite is a software library that implements a self-contained, serverless,
zero-configuration, transactional SQL database engine. SQLite Development Team
SQLite 3.9.2
[Loaded DLLs] C:\Program Files (x86)\Sony\Sony PC Companion\Report.dll
[Loaded DLLs] C:\Program Files (x86)\Sony\Sony PC Companion\BackupRestore.dll
### BackupRestore Plugin Library Avanquest Software PC Companion 2.0.0
[Loaded DLLs] C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50
727.6195_none_d09154e044272b9a\MSVCR80.dll
### Microsoft C Runtime Library Microsoft Corporation Microsoft Visual Studio 200
5 8.00.50727.6195
[Loaded DLLs] C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
### Microsoft Office XML MIME Filter Microsoft Corporation Microsoft Office In
foPath 12.0.4518.1014
[Loaded DLLs] C:\Program Files (x86)\Sony\Sony PC Companion\DownloadManager.dl
l
### Download Manager Core Library Avanquest Software PC Companion 2.0
[Loaded DLLs] C:\Windows\system32\webio.dll
### Web Transfer Protocols API Microsoft Corporation Microsoft Windows Operating
System 6.1.7601.17514

[Loaded DLLs] C:\Windows\system32\WINHTTP.dll


### Windows HTTP Services Microsoft Corporation Microsoft Windows Operating Syst
em 6.1.7600.16385
[Loaded DLLs] C:\Program Files (x86)\Sony\Sony PC Companion\PhoneUpdateTools.d
ll
### TODO: <File description> TODO: <Company name> TODO: <Product name> 1.0.0.1
[Loaded DLLs] C:\Program Files (x86)\Sony\Sony PC Companion\PluginManager.dll
### Plugin Manager Core Library Avanquest Software Sony PC Companion 2.0.0
[Loaded DLLs] C:\Windows\system32\rasman.dll
### Remote Access Connection Manager Microsoft Corporation Microsoft Windows Ope
rating System 6.1.7600.16385
[Loaded DLLs] C:\Windows\system32\RASAPI32.dll
### Remote Access API Microsoft Corporation Microsoft Windows Operating System 6
.1.7600.16385
[Loaded DLLs] C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.dll
### PC Companion Core Library Avanquest Software PC Companion 2.0.0
[Loaded DLLs] C:\Windows\syswow64\WINTRUST.dll
### Microsoft Trust Verification APIs Microsoft Corporation Microsoft Windows Op
erating System 6.1.7601.18205
[Loaded DLLs] C:\Windows\system32\newdev.dll
### Add Hardware Device Library Microsoft Corporation Microsoft Windows Operatin
g System 6.0.5054.0
[Loaded DLLs] C:\Windows\system32\TAPI32.dll
### Microsoft Windows(TM) Telephony API Client DLL Microsoft Corporation Micros
oft Windows Operating System 6.1.7600.16385
[Loaded DLLs] C:\Program Files (x86)\Sony\Sony PC Companion\WUNPACLN.dll
### PAC Archive Library Avanquest Software
[Loaded DLLs] C:\Program Files (x86)\Sony\Sony PC Companion\MExplorer.dll
[Loaded DLLs] C:\Program Files (x86)\Sony\Sony PC Companion\Device.dll
### Device Core Library Avanquest Software PC Companion 2.0
[Loaded DLLs] C:\Windows\system32\DEVRTL.dll
### Device Management Run Time Library Microsoft Corporation Microsoft Windows O
perating System 6.1.7600.16385
[Loaded DLLs] C:\Windows\syswow64\DEVOBJ.dll
### Device Information Set DLL Microsoft Corporation Microsoft Windows Operating
System 6.1.7601.17621
[Loaded DLLs] C:\Windows\syswow64\CFGMGR32.dll
### Configuration Manager DLL Microsoft Corporation Microsoft Windows Operating
System 6.1.7601.17621
[Loaded DLLs] C:\Windows\syswow64\SETUPAPI.dll
### Windows Setup API Microsoft Corporation Microsoft Windows Operating System 6
.1.7600.16385
[Loaded DLLs] C:\Windows\system32\PROPSYS.dll
### Microsoft Property System Microsoft Corporation Windows Search 7.00.7600.16
385
[Loaded DLLs] C:\Program Files (x86)\Sony\Sony PC Companion\TMonitorAPI.dll
[Loaded DLLs] C:\Windows\system32\MSACM32.dll
### Microsoft ACM Audio Filter Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385
[Loaded DLLs] C:\Windows\system32\AVIFIL32.dll
### Microsoft AVI File support library Microsoft Corporation Microsoft Windows O
perating System 6.1.7600.16385
[Loaded DLLs] C:\Windows\system32\oledlg.dll
### OLE User Interface Support Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385
[Loaded DLLs] C:\Program Files (x86)\Sony\Sony PC Companion\bvrpctln.dll
### Custom controls and utilities library Avanquest Software MPT 2.00
[Loaded DLLs] C:\Windows\syswow64\imagehlp.dll
### Windows NT Image Helper Microsoft Corporation Microsoft Windows Operating Sy

stem 6.1.7601.18288
[Loaded DLLs] C:\Windows\system32\MSVFW32.dll
### Microsoft Video for Windows DLL Microsoft Corporation Microsoft Windows Oper
ating System 6.1.7600.16385
[Loaded DLLs] C:\Program Files (x86)\Sony\Sony PC Companion\NewUI.dll
### New UI Avanquest Software MPT 4.0
[Loaded DLLs] C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Serv759bfb
78#\c8bd7b726e571a2948d5547fd030f303\System.ServiceProcess.ni.dll
### .NET Framework Microsoft Corporation Microsoft .NET Framework 4.0.30319.179
29
[Loaded DLLs] C:\Windows\system32\WINSPOOL.DRV
### Windows Spooler Driver Microsoft Corporation Microsoft Windows Operating Sys
tem 6.1.7600.16385
[Loaded DLLs] C:\Program Files (x86)\Samsung\Kies\External\MACSSDK.dll
### MACSSDK MarkAny. MACSSDK 3, 2, 2009, 1028
[Loaded DLLs] C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\95a58c
416cfe8803af6b325d952a374a\System.Xml.ni.dll
### .NET Framework Microsoft Corporation Microsoft .NET Framework 4.0.30319.180
60
[Loaded DLLs] C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configurat
ion\853f7abd2d9a620ba57c7b4005fe1976\System.Configuration.ni.dll
### System.Configuration.dll Microsoft Corporation Microsoft .NET Framework 4.0
.30319.18060
[Loaded DLLs] C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runt73a1fc
9d#\dbef796beff0b4632e0913ac24bbbe5e\System.Runtime.Remoting.ni.dll
### Microsoft .NET Runtime Object Remoting Microsoft Corporation Microsoft .NET
Framework 4.0.30319.34108
[Loaded DLLs] C:\Windows\Microsoft.NET\Framework\v4.0.30319\nlssorting.dll
### Microsoft Collation Support Microsoft Corporation Microsoft .NET Framework
4.0.30319.17929
[Loaded DLLs] C:\Windows\Microsoft.NET\Framework\v4.0.30319\clrjit.dll
### Microsoft .NET Runtime Just-In-Time Compiler Microsoft Corporation Microso
ft .NET Framework 4.0.30319.18021
[Loaded DLLs] C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\PresentationNa
tive_v0400.dll
### PresentationNative_v0400.dll Microsoft Corporation Microsoft .NET Framework
4.0.30319.17929
[Loaded DLLs] C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\wpfgfx_v0400.d
ll
### wpfgfx_v0400.dll Microsoft Corporation Microsoft .NET Framework 4.0.30319.1
7929
[Loaded DLLs] C:\Windows\system32\dwrite.dll
### Microsoft DirectX Typography Services Microsoft Corporation Microsoft Windo
ws Operating System 6.2.9200.16492
[Loaded DLLs] C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\6497e
394eb0346d9f374976af5033e37\System.Core.ni.dll
### .NET Framework Microsoft Corporation Microsoft .NET Framework 4.0.30319.179
29
[Loaded DLLs] C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\9d357
2e8c3c314a0f12383d41e8bee78\System.Xaml.ni.dll
### System.Xaml.dll Microsoft Corporation Microsoft .NET Framework 4.0.30319.18
015
[Loaded DLLs] C:\Windows\assembly\NativeImages_v4.0.30319_32\Presentatio5ae0f0
0f#\33e2c43bb5e6f50244ae444c1d9b33cd\PresentationFramework.ni.dll
### PresentationFramework.dll Microsoft Corporation Microsoft .NET Framework 4.
0.30319.18060
[Loaded DLLs] C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\
4752710c6fe78ee418c736dad7a05b52\PresentationCore.ni.dll
### PresentationCore.dll Microsoft Corporation Microsoft .NET Framework 4.0.303
19.18060

[Loaded DLLs] C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\ac2e2


6bafa70e93b307087d7fe6b9dd2\WindowsBase.ni.dll
### WindowsBase.dll Microsoft Corporation Microsoft .NET Framework 4.0.30319.18
060
[Loaded DLLs] C:\Windows\assembly\NativeImages_v4.0.30319_32\System\a369005c18
456d7fd36347e36d63fe05\System.ni.dll
### .NET Framework Microsoft Corporation Microsoft .NET Framework 4.0.30319.180
21
[Loaded DLLs] C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\d12f4fda
3d1bfabf888342e96983e9a7\mscorlib.ni.dll
### Microsoft Common Language Runtime Class Library Microsoft Corporation Micr
osoft .NET Framework 4.0.30319.18063
[Loaded DLLs] C:\Windows\system32\MSVCR110_CLR0400.dll
### Microsoft C Runtime Library Microsoft Corporation Microsoft Visual Studio 11
Beta 11.00.50709.17929
[Loaded DLLs] C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll
### Microsoft .NET Runtime Common Language Runtime - WorkStation Microsoft Cor
poration Microsoft .NET Framework 4.0.30319.18063
[Loaded DLLs] C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll
### Microsoft .NET Runtime Execution Engine Microsoft Corporation Microsoft .NE
T Framework 4.0.30319.17929
[Loaded DLLs] C:\Windows\SYSTEM32\MSCOREE.DLL
### Microsoft .NET Runtime Execution Engine Microsoft Corporation Microsoft .NE
T Framework 4.0.40305.0
[Loaded DLLs] C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
### ApiSet Stub DLL Microsoft Corporation Microsoft Windows Operating System 6.2
.9200.16492
[Loaded DLLs] C:\Windows\system32\profapi.dll
### User Profile Basic API Microsoft Corporation Microsoft Windows Operating Sys
tem 6.1.7600.16385
[Loaded DLLs] C:\Windows\System32\winrnr.dll
### LDAP RnR Provider DLL Microsoft Corporation Microsoft Windows Operating Syst
em 6.1.7600.16385
[Loaded DLLs] C:\Windows\system32\pnrpnsp.dll
### PNRP Name Space Provider Microsoft Corporation Microsoft Windows Operating S
ystem 6.1.7600.16385
[Loaded DLLs] C:\Windows\system32\napinsp.dll
### E-mail Naming Shim Provider Microsoft Corporation Microsoft Windows Operatin
g System 6.1.7600.16385
[Loaded DLLs] C:\Windows\system32\NLAapi.dll
### Network Location Awareness 2 Microsoft Corporation Microsoft Windows Operati
ng System 6.1.7601.17514
[Loaded DLLs] C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
### ApiSet Stub DLL Microsoft Corporation Microsoft Windows Operating System 6.2
.9200.16492
[Loaded DLLs] C:\Windows\SysWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll
### ApiSet Stub DLL Microsoft Corporation Microsoft Windows Operating System 6.2
.9200.16492
[Loaded DLLs] C:\Windows\SysWOW64\ieframe.dll
### Internet Browser Microsoft Corporation Internet Explorer 11.00.9600.17041
[Loaded DLLs] C:\Windows\system32\RpcRtRemote.dll
### Remote RPC Extension Microsoft Corporation Microsoft Windows Operating Syste
m 6.1.7601.17514
[Loaded DLLs] C:\Windows\system32\rsaenh.dll
### Microsoft Enhanced Cryptographic Provider Microsoft Corporation Microsoft W
indows Operating System 6.1.7600.16385
[Loaded DLLs] C:\Windows\system32\CRYPTSP.dll
### Cryptographic Service Provider API Microsoft Corporation Microsoft Windows O
perating System 6.1.7600.16385
[Loaded DLLs] C:\Windows\system32\SXS.DLL

### Fusion 2.5 Microsoft Corporation Microsoft Windows Operating System 6.1.7600
.16385
[Loaded DLLs] C:\Windows\system32\olepro32.dll
[Loaded DLLs] C:\Program Files (x86)\Common Files\Wondershare\Wondershare Help
er Compact\CBSProducstInfo.dll
### Wondershare Studio Wondershare Wondershare Studio 1.0.0.0
[Loaded DLLs] C:\Program Files (x86)\Common Files\Wondershare\Wondershare Help
er Compact\CBSCreateVC.dll
[Loaded DLLs] C:\Program Files (x86)\Common Files\Wondershare\Wondershare Help
er Compact\DAQExp.dll
[Loaded DLLs] C:\Windows\system32\wsock32.dll
### Windows Socket 32-Bit DLL Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385
[Loaded DLLs] C:\Windows\syswow64\api-ms-win-downlevel-ole32-l1-1-0.dll
### ApiSet Stub DLL Microsoft Corporation Microsoft Windows Operating System 6.2
.9200.16492
[Loaded DLLs] C:\Windows\syswow64\URLMON.DLL
### OLE32 Extensions for Win32 Microsoft Corporation Internet Explorer 11.00.9
600.17041
[Loaded DLLs] C:\Windows\system32\mpr.dll
### Multiple Provider Router DLL Microsoft Corporation Microsoft Windows Operati
ng System 6.1.7600.16385
[Loaded DLLs] C:\Windows\system32\msimg32.dll
### GDIEXT Client DLL Microsoft Corporation Microsoft Windows Operating System 6
.1.7600.16385
[Loaded DLLs] C:\Windows\system32\apphelp.dll
### Application Compatibility Client Library Microsoft Corporation Microsoft Wi
ndows Operating System 6.1.7600.16385
[Loaded DLLs] C:\Windows\system32\dwmapi.dll
### Microsoft Desktop Window Manager API Microsoft Corporation Microsoft Window
s Operating System 6.1.7600.16385
[Loaded DLLs] C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b641
44ccf1df_5.82.7601.18201_none_ec80f00e8593ece5\COMCTL32.DLL
### Common Controls Library Microsoft Corporation Microsoft Windows Operating Sy
stem 6.1.7600.16385
[Loaded DLLs] C:\Windows\System32\wshtcpip.dll
### Winsock2 Helper DLL (TL/IPv4) Microsoft Corporation Microsoft Windows Operat
ing System 6.1.7600.16385
[Loaded DLLs] C:\Windows\System32\wship6.dll
### Winsock2 Helper DLL (TL/IPv6) Microsoft Corporation Microsoft Windows Operat
ing System 6.1.7600.16385
[Loaded DLLs] C:\Windows\system32\rasadhlp.dll
### Remote Access AutoDial Helper Microsoft Corporation Microsoft Windows Operat
ing System 6.1.7600.16385
[Loaded DLLs] C:\Windows\System32\fwpuclnt.dll
### FWP/IPsec User-Mode API Microsoft Corporation Microsoft Windows Operating Sy
stem 6.1.7600.16385
[Loaded DLLs] C:\Windows\system32\WINNSI.DLL
### Network Store Information RPC interface Microsoft Corporation Microsoft Win
dows Operating System 6.1.7600.16385
[Loaded DLLs] C:\Windows\system32\IPHLPAPI.DLL
### IP Helper API Microsoft Corporation Microsoft Windows Operating System 6.1.7
600.16385
[Loaded DLLs] C:\Windows\system32\DNSAPI.dll
### DNS Client API DLL Microsoft Corporation Microsoft Windows Operating System
6.1.7600.16385
[Loaded DLLs] C:\Windows\System32\mswsock.dll
### Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation Micro
soft Windows Operating System 6.1.7600.16385
[Loaded DLLs] C:\ProgramData\Google\Google Input Tools\plugins\virtual_keyboar

d_plugin.dll
### Google Input Tools Plugin Google Inc. Google Input Tools 1.1.3.18
[Loaded DLLs] C:\Windows\syswow64\COMDLG32.dll
### Common Dialogs DLL Microsoft Corporation Microsoft Windows Operating System
6.1.7600.16385
[Loaded DLLs] C:\ProgramData\Google\Google Input Tools\plugins\t13n_ime_plugin
.dll
### Google Input Tools Plugin Google Inc. Google Input Tools 1.1.3.18
[Loaded DLLs] C:\ProgramData\Google\Google Input Tools\plugins\character_picke
r_plugin.dll
### Google Input Tools Plugin Google Inc. Google Input Tools 1.1.3.18
[Loaded DLLs] C:\Windows\system32\WindowsCodecs.dll
### Microsoft Windows Codecs Library Microsoft Corporation Microsoft Windows Ope
rating System 6.2.9200.16492
[Loaded DLLs] C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b641
44ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
### User Experience Controls Library Microsoft Corporation Microsoft Windows Ope
rating System 6.1.7600.16385
[Loaded DLLs] C:\Windows\System32\msxml3.dll
### MSXML 3.0 SP11 Microsoft Corporation Microsoft(R) MSXML 3.0 SP11 8.110.760
1.18334
[Loaded DLLs] C:\Windows\syswow64\CLBCatQ.DLL
### COM+ Configuration Catalog Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385
[Loaded DLLs] C:\Windows\system32\uxtheme.dll
### Microsoft UxTheme Library Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385
[Loaded DLLs] C:\Windows\syswow64\WLDAP32.dll
### Win32 LDAP API DLL Microsoft Corporation Microsoft Windows Operating System
6.1.7600.16385
[Loaded DLLs] C:\Windows\system32\ntmarta.dll
### Windows NT MARTA provider Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385
[Loaded DLLs] C:\Windows\syswow64\MSCTF.dll
### MSCTF Server DLL Microsoft Corporation Microsoft Windows Operating System 6.
1.7600.16385
[Loaded DLLs] C:\Windows\system32\IMM32.DLL
### Multi-User Windows IMM32 API Client DLL Microsoft Corporation Microsoft Win
dows Operating System 6.1.7600.16385
[Loaded DLLs] C:\Windows\syswow64\api-ms-win-downlevel-advapi32-l1-1-0.dll
### ApiSet Stub DLL Microsoft Corporation Microsoft Windows Operating System 6.2
.9200.16492
[Loaded DLLs] C:\Windows\syswow64\iertutil.dll
### Run time utility for Internet Explorer Microsoft Corporation Internet Expl
orer 11.00.9600.17041
[Loaded DLLs] C:\Windows\syswow64\normaliz.DLL
### Unicode Normalization DLL Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385
[Loaded DLLs] C:\Windows\syswow64\api-ms-win-downlevel-normaliz-l1-1-0.dll
### ApiSet Stub DLL Microsoft Corporation Microsoft Windows Operating System 6.2
.9200.16492
[Loaded DLLs] C:\Windows\system32\version.DLL
### Version Checking and File Installation Libraries Microsoft Corporation Mic
rosoft Windows Operating System 6.1.7600.16385
[Loaded DLLs] C:\Windows\syswow64\api-ms-win-downlevel-version-l1-1-0.dll
### ApiSet Stub DLL Microsoft Corporation Microsoft Windows Operating System 6.2
.9200.16492
[Loaded DLLs] C:\Windows\syswow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
### ApiSet Stub DLL Microsoft Corporation Microsoft Windows Operating System 6.2
.9200.16492

[Loaded DLLs] C:\Windows\syswow64\api-ms-win-downlevel-user32-l1-1-0.dll


### ApiSet Stub DLL Microsoft Corporation Microsoft Windows Operating System 6.2
.9200.16492
[Loaded DLLs] C:\Windows\syswow64\WININET.dll
### Internet Extensions for Win32 Microsoft Corporation Internet Explorer 11.0
0.9600.16428
[Loaded DLLs] C:\Windows\syswow64\NSI.dll
### NSI User-mode interface DLL Microsoft Corporation Microsoft Windows Operatin
g System 6.1.7600.16385
[Loaded DLLs] C:\Windows\syswow64\WS2_32.dll
### Windows Socket 2.0 32-Bit DLL Microsoft Corporation Microsoft Windows Operat
ing System 6.1.7600.16385
[Loaded DLLs] C:\Windows\system32\Secur32.dll
### Security Support Provider Interface Microsoft Corporation Microsoft Windows
Operating System 6.1.7601.18443
[Loaded DLLs] C:\Windows\syswow64\SHLWAPI.dll
### Shell Light-weight Utility Library Microsoft Corporation Microsoft Windows O
perating System 6.1.7600.16385
[Loaded DLLs] C:\Windows\syswow64\SHELL32.dll
### Windows Shell Common Dll Microsoft Corporation Microsoft Windows Operating S
ystem 6.1.7601.17514
[Loaded DLLs] C:\Windows\syswow64\MSASN1.dll
### ASN.1 Runtime APIs Microsoft Corporation Microsoft Windows Operating System
6.1.7601.17514
[Loaded DLLs] C:\Windows\syswow64\CRYPT32.dll
### Crypto API32 Microsoft Corporation Microsoft Windows Operating System 6.1.76
01.18277
[Loaded DLLs] C:\Windows\system32\WINMM.dll
### MCI API DLL Microsoft Corporation Microsoft Windows Operating System 6.1.760
0.16385
[Loaded DLLs] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df
_1.1.7601.18120_none_72d2e82386681b36\gdiplus.dll
### Microsoft GDI+ Microsoft Corporation Microsoft Windows Operating System 6.1.
7601.18120
[Loaded DLLs] C:\Windows\syswow64\OLEAUT32.dll
### Microsoft Corporation 6.1.7601.17676
[Loaded DLLs] C:\Windows\syswow64\ole32.dll
### Microsoft OLE for Windows Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385
[Loaded DLLs] C:\Windows\syswow64\USP10.dll
### Uniscribe Unicode script processor Microsoft Corporation Microsoft(R) Unis
cribe Unicode script processor 1.0626.7601.17514
[Loaded DLLs] C:\Windows\syswow64\LPK.dll
### Language Pack Microsoft Corporation Microsoft Windows Operating System 6.1.7
601.18177
[Loaded DLLs] C:\Windows\syswow64\GDI32.dll
### GDI Client DLL Microsoft Corporation Microsoft Windows Operating System 6.1.
7601.18275
[Loaded DLLs] C:\Windows\syswow64\USER32.dll
### Multi-User Windows USER API Client DLL Microsoft Corporation Microsoft Wind
ows Operating System 6.1.7601.17514
[Loaded DLLs] C:\Windows\syswow64\CRYPTBASE.dll
### Base cryptographic API DLL Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385
[Loaded DLLs] C:\Windows\syswow64\SspiCli.dll
### Security Support Provider Interface Microsoft Corporation Microsoft Windows
Operating System 6.1.7601.18443
[Loaded DLLs] C:\Windows\syswow64\RPCRT4.dll
### Remote Procedure Call Runtime Microsoft Corporation Microsoft Windows Operat
ing System 6.1.7600.16385

[Loaded DLLs] C:\Windows\SysWOW64\sechost.dll


### Host for SCM/SDDL/LSA Lookup APIs Microsoft Corporation Microsoft Windows Op
erating System 6.1.7600.16385
[Loaded DLLs] C:\Windows\syswow64\msvcrt.dll
### Windows NT CRT DLL Microsoft Corporation Microsoft Windows Operating System
7.0.7601.17744
[Loaded DLLs] C:\Windows\syswow64\ADVAPI32.dll
### Advanced Windows 32 Base API Microsoft Corporation Microsoft Windows Operati
ng System 6.1.7600.16385
[Loaded DLLs] C:\Windows\syswow64\KERNELBASE.dll
### Windows NT BASE API Client DLL Microsoft Corporation Microsoft Windows Opera
ting System 6.1.7601.17965
[Loaded DLLs] C:\Windows\syswow64\kernel32.dll
### Windows NT BASE API Client DLL Microsoft Corporation Microsoft Windows Opera
ting System 6.1.7601.17965
[Loaded DLLs] C:\Windows\SysWOW64\ntdll.dll
### NT Layer DLL Microsoft Corporation Microsoft Windows Operating System 6.1.76
00.16385
[Running Services] AdobeARMservice
### Internal Name: AdobeARMservice. Status: service is running. Actual File: "
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe" * Adobe Acrobat Up
dater keeps your Adobe software up to date. Adobe Acrobat Update Service Adobe S
ystems Incorporated Adobe Acrobat Update Service 1.824.16.6751
[Running Services] AeLookupSvc
### Internal Name: AeLookupSvc. Status: service is running. Actual File: C:\Wi
ndows\system32\svchost.exe -k netsvcs * Processes application compatibility cach
e requests for applications as they are launched Host Process for Windows Servic
es Microsoft Corporation Microsoft Windows Operating System 6.1.7600.16385
[Running Services] AudioEndpointBuilder
### Internal Name: AudioEndpointBuilder. Status: service is running. Actual Fi
le: C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted * Manages au
dio devices for the Windows Audio service. If this service is stopped, audio de
vices and effects will not function properly. If this service is disabled, any
services that explicitly depend on it will fail to start Host Process for Window
s Services Microsoft Corporation Microsoft Windows Operating System 6.1.7600.16385
[Running Services] AudioSrv
### Internal Name: AudioSrv. Status: service is running. Actual File: C:\Windo
ws\System32\svchost.exe -k LocalServiceNetworkRestricted * Manages audio for Win
dows-based programs. If this service is stopped, audio devices and effects will
not function properly. If this service is disabled, any services that explicit
ly depend on it will fail to start Host Process for Windows Services Microsoft C
orporation Microsoft Windows Operating System 6.1.7600.16385
[Running Services] BFE
### Internal Name: BFE. Status: service is running. Actual File: C:\Windows\sy
stem32\svchost.exe -k LocalServiceNoNetwork * The Base Filtering Engine (BFE) is
a service that manages firewall and Internet Protocol security (IPsec) policies
and implements user mode filtering. Stopping or disabling the BFE service will
significantly reduce the security of the system. It will also result in unpredic
table behavior in IPsec management and firewall applications. Host Process for W
indows Services Microsoft Corporation Microsoft Windows Operating System 6.1.7600.
16385
[Running Services] BITS
### Internal Name: BITS. Status: service is running. Actual File: C:\Windows\S
ystem32\svchost.exe -k netsvcs * Transfers files in the background using idle ne
twork bandwidth. If the service is disabled, then any applications that depend o
n BITS, such as Windows Update or MSN Explorer, will be unable to automatically
download programs and other information. Host Process for Windows Services Micro
soft Corporation Microsoft Windows Operating System 6.1.7600.16385
[Running Services] Browser

### Internal Name: Browser. Status: service is running. Actual File: C:\Window
s\System32\svchost.exe -k netsvcs * Maintains an updated list of computers on th
e network and supplies this list to computers designated as browsers. If this se
rvice is stopped, this list will not be updated or maintained. If this service i
s disabled, any services that explicitly depend on it will fail to start. Host P
rocess for Windows Services Microsoft Corporation Microsoft Windows Operating Syst
em 6.1.7600.16385
[Running Services] CertPropSvc
### Internal Name: CertPropSvc. Status: service is running. Actual File: C:\Wi
ndows\system32\svchost.exe -k netsvcs * Copies user certificates and root certif
icates from smart cards into the current user's certificate store, detects when
a smart card is inserted into a smart card reader, and, if needed, installs the
smart card Plug and Play minidriver. Host Process for Windows Services Microsoft
Corporation Microsoft Windows Operating System 6.1.7600.16385
[Running Services] CryptSvc
### Internal Name: CryptSvc. Status: service is running. Actual File: C:\Windo
ws\system32\svchost.exe -k NetworkService * Provides four management services: C
atalog Database Service, which confirms the signatures of Windows files and allo
ws new programs to be installed; Protected Root Service, which adds and removes
Trusted Root Certification Authority certificates from this computer; Automatic
Root Certificate Update Service, which retrieves root certificates from Windows
Update and enable scenarios such as SSL; and Key Service, which helps enroll thi
s computer for certificates. If this service is stopped, these management servic
es will not function properly. If this service is disabled, any services that ex
plicitly depend on it will fail to start. Host Process for Windows Services Micr
osoft Corporation Microsoft Windows Operating System 6.1.7600.16385
[Running Services] CscService
### Internal Name: CscService. Status: service is running. Actual File: C:\Win
dows\System32\svchost.exe -k LocalSystemNetworkRestricted * The Offline Files se
rvice performs maintenance activities on the Offline Files cache, responds to us
er logon and logoff events, implements the internals of the public API, and disp
atches interesting events to those interested in Offline Files activities and ch
anges in cache state. Host Process for Windows Services Microsoft Corporation Mi
crosoft Windows Operating System 6.1.7600.16385
[Running Services] DcomLaunch
### Internal Name: DcomLaunch. Status: service is running. Actual File: C:\Win
dows\system32\svchost.exe -k DcomLaunch * The DCOMLAUNCH service launches COM an
d DCOM servers in response to object activation requests. If this service is sto
pped or disabled, programs using COM or DCOM will not function properly. It is s
trongly recommended that you have the DCOMLAUNCH service running. Host Process f
or Windows Services Microsoft Corporation Microsoft Windows Operating System 6.1.7
600.16385
[Running Services] Dhcp
### Internal Name: Dhcp. Status: service is running. Actual File: C:\Windows\s
ystem32\svchost.exe -k LocalServiceNetworkRestricted * Registers and updates IP
addresses and DNS records for this computer. If this service is stopped, this co
mputer will not receive dynamic IP addresses and DNS updates. If this service is
disabled, any services that explicitly depend on it will fail to start. Host Pr
ocess for Windows Services Microsoft Corporation Microsoft Windows Operating Syste
m 6.1.7600.16385
[Running Services] Dnscache
### Internal Name: Dnscache. Status: service is running. Actual File: C:\Windo
ws\system32\svchost.exe -k NetworkService * The DNS Client service (dnscache) ca
ches Domain Name System (DNS) names and registers the full computer name for thi
s computer. If the service is stopped, DNS names will continue to be resolved. H
owever, the results of DNS name queries will not be cached and the computer's na
me will not be registered. If the service is disabled, any services that explici
tly depend on it will fail to start. Host Process for Windows Services Microsoft
Corporation Microsoft Windows Operating System 6.1.7600.16385
[Running Services] DPS

### Internal Name: DPS. Status: service is running. Actual File: C:\Windows\Sy
stem32\svchost.exe -k LocalServiceNoNetwork * The Diagnostic Policy Service enab
les problem detection, troubleshooting and resolution for Windows components. I
f this service is stopped, diagnostics will no longer function. Host Process for
Windows Services Microsoft Corporation Microsoft Windows Operating System 6.1.760
0.16385
[Running Services] EFS
### Internal Name: EFS. Status: service is running. Actual File: C:\Windows\Sy
stem32\lsass.exe * Provides the core file encryption technology used to store en
crypted files on NTFS file system volumes. If this service is stopped or disable
d, applications will be unable to access encrypted files. Local Security Authori
ty Process Microsoft Corporation Microsoft Windows Operating System 6.1.7601.18443
[Running Services] ESRV_SVC_WILLAMETTE
### Internal Name: ESRV_SVC_WILLAMETTE. Status: service is running. Actual Fil
e: "C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\esrv_svc.exe" "--AUTO_START" "--s
tart" "--address" "127.0.0.1" "--port" "49330" "--depend_on_key" "SYSTEM\Current
ControlSet\Services\ESRV_SVC_WILLAMETTE" "--depend_on_value" "run" "--time_in_ms
" "--pause" "5000" "--library" "C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\intel
_modeler.dll" "--no_pl" "--watchdog" "10" "--watchdog_cpu_usage_limit" "50" "--e
nd_on_error" "--kernel_priority_boost" "--shutdown_priority_boost" "--device_opt
ions" " time=no output=w output_folder='C:\ProgramData\Intel\SUR\WILLAMETTE\Inte
lData' limit_output_by=time output_limit=3600000 output_buffer=1024 il='C:\Progr
am Files\Intel\SUR\WILLAMETTE\ESRV\intel_process_input.dll','process_input_optio
ns.txt' il='C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\intel_system_power_state_
input.dll' il='C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\intel_quality_and_reli
ability_input.dll' il='C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\acpi_battery_i
nput.dll' il='C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\sema_thermal_input.dll'
il='C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\wifi_input.dll' il='C:\Program F
iles\Intel\SUR\WILLAMETTE\ESRV\devices_use_input.dll','service=yes' il='C:\Progr
am Files\Intel\SUR\WILLAMETTE\ESRV\intel_disktrace_input.dll','pause=60000 worki
ng_dir=C:\ProgramData\Intel\SUR\WILLAMETTE\IntelData override_existing_tracing=n
o limit_output_by_filesize_mb=10' os='C:\Program Files\Intel\SUR\WILLAMETTE\ESRV
\os_counters.txt' " * Intel(r) Energy Checker SDK. ESRV Service WILLAMETTE Inte
l(R) System Usage Report Intel(R) System Usage Report
[Running Services] eventlog
### Internal Name: eventlog. Status: service is running. Actual File: C:\Windo
ws\System32\svchost.exe -k LocalServiceNetworkRestricted * This service manages
events and event logs. It supports logging events, querying events, subscribing
to events, archiving event logs, and managing event metadata. It can display eve
nts in both XML and plain text format. Stopping this service may compromise secu
rity and reliability of the system. Host Process for Windows Services Microsoft
Corporation Microsoft Windows Operating System 6.1.7600.16385
[Running Services] EventSystem
### Internal Name: EventSystem. Status: service is running. Actual File: C:\Wi
ndows\system32\svchost.exe -k LocalService * Supports System Event Notification
Service (SENS), which provides automatic distribution of events to subscribing C
omponent Object Model (COM) components. If the service is stopped, SENS will clo
se and will not be able to provide logon and logoff notifications. If this servi
ce is disabled, any services that explicitly depend on it will fail to start. Ho
st Process for Windows Services Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385
[Running Services] fdPHost
### Internal Name: fdPHost. Status: service is running. Actual File: C:\Window
s\system32\svchost.exe -k LocalService * The FDPHOST service hosts the Function
Discovery (FD) network discovery providers. These FD providers supply network di
scovery services for the Simple Services Discovery Protocol (SSDP) and Web Servi
Discovery (WS-D) protocol. Stopping or disabling the FDPHOST service will di
ces
sable network discovery for these protocols when using FD. When this service is
unavailable, network services using FD and relying on these discovery protocols

will be unable to find network devices or resources. Host Process for Windows Se
rvices Microsoft Corporation Microsoft Windows Operating System 6.1.7600.16385
[Running Services] FLEXnet Licensing Service
### Internal Name: FLEXnet Licensing Service. Status: service is running. Actu
al File: "C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publish
er\FNPLicensingService.exe" * This service performs licensing functions on behal
f of FLEXnet enabled products. Activation Licensing Service Acresso Software Inc
. FLEXnet Publisher (32 bit) 11.7.0.0 build 73797
[Running Services] FontCache
### Internal Name: FontCache. Status: service is running. Actual File: C:\Wind
ows\system32\svchost.exe -k LocalService * Optimizes performance of applications
by caching commonly used font data. Applications will start this service if it
is not already running. It can be disabled, though doing so will degrade applica
tion performance. Host Process for Windows Services Microsoft Corporation Micros
oft Windows Operating System 6.1.7600.16385
[Running Services] GoogleInputService
### Internal Name: GoogleInputService. Status: service is running. Actual File
: "C:\Program Files (x86)\Google\Google Input Tools\GoogleInputService.exe" * G
oogle Input Tools. Google Inc Google Input Tools 1.1.3.18
[Running Services] gpsvc
### Internal Name: gpsvc. Status: service is running. Actual File: C:\Windows\
system32\svchost.exe -k netsvcs * The service is responsible for applying settin
gs configured by administrators for the computer and users through the Group Pol
icy component. If the service is stopped or disabled, the settings will not be a
pplied and applications and components will not be manageable through Group Poli
cy. Any components or applications that depend on the Group Policy component mig
ht not be functional if the service is stopped or disabled. Host Process for Win
dows Services Microsoft Corporation Microsoft Windows Operating System 6.1.7600.16
385
[Running Services] hidserv
### Internal Name: hidserv. Status: service is running. Actual File: C:\Window
s\system32\svchost.exe -k LocalSystemNetworkRestricted * Enables generic input a
ccess to Human Interface Devices (HID), which activates and maintains the use of
predefined hot buttons on keyboards, remote controls, and other multimedia devi
ces. If this service is stopped, hot buttons controlled by this service will no
longer function. If this service is disabled, any services that explicitly depen
d on it will fail to start. Host Process for Windows Services Microsoft Corporat
ion Microsoft Windows Operating System 6.1.7600.16385
[Running Services] IKEEXT
### Internal Name: IKEEXT. Status: service is running. Actual File: C:\Windows
\system32\svchost.exe -k netsvcs * The IKEEXT service hosts the Internet Key Exc
hange (IKE) and Authenticated Internet Protocol (AuthIP) keying modules. These k
eying modules are used for authentication and key exchange in Internet Protocol
security (IPsec). Stopping or disabling the IKEEXT service will disable IKE and
AuthIP key exchange with peer computers. IPsec is typically configured to use IK
E or AuthIP; therefore, stopping or disabling the IKEEXT service might result in
an IPsec failure and might compromise the security of the system. It is strongl
y recommended that you have the IKEEXT service running. Host Process for Windows
Services Microsoft Corporation Microsoft Windows Operating System 6.1.7600.16385
[Running Services] iphlpsvc
### Internal Name: iphlpsvc. Status: service is running. Actual File: C:\Windo
ws\System32\svchost.exe -k NetSvcs * Provides tunnel connectivity using IPv6 tra
nsition technologies (6to4, ISATAP, Port Proxy, and Teredo), and IP-HTTPS. If th
is service is stopped, the computer will not have the enhanced connectivity bene
fits that these technologies offer. Host Process for Windows Services Microsoft
Corporation Microsoft Windows Operating System 6.1.7600.16385
[Running Services] LanmanServer
### Internal Name: LanmanServer. Status: service is running. Actual File: C:\W
indows\system32\svchost.exe -k netsvcs * Supports file, print, and named-pipe sh
aring over the network for this computer. If this service is stopped, these func

tions will be unavailable. If this service is disabled, any services that explic
itly depend on it will fail to start. Host Process for Windows Services Microsof
t Corporation Microsoft Windows Operating System 6.1.7600.16385
[Running Services] LanmanWorkstation
### Internal Name: LanmanWorkstation. Status: service is running. Actual File:
C:\Windows\System32\svchost.exe -k NetworkService * Creates and maintains clien
t network connections to remote servers using the SMB protocol. If this service
is stopped, these connections will be unavailable. If this service is disabled,
any services that explicitly depend on it will fail to start. Host Process for W
indows Services Microsoft Corporation Microsoft Windows Operating System 6.1.7600.
16385
[Running Services] lmhosts
### Internal Name: lmhosts. Status: service is running. Actual File: C:\Window
s\system32\svchost.exe -k LocalServiceNetworkRestricted * Provides support for t
he NetBIOS over TCP/IP (NetBT) service and NetBIOS name resolution for clients o
n the network, therefore enabling users to share files, print, and log on to the
network. If this service is stopped, these functions might be unavailable. If t
his service is disabled, any services that explicitly depend on it will fail to
start. Host Process for Windows Services Microsoft Corporation Microsoft Windows O
perating System 6.1.7600.16385
[Running Services] LMS
### Internal Name: LMS. Status: service is running. Actual File: C:\Program Fi
les (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe * Allows appli
cations to access the local Intel(R) Management and Security Application using i
ts locally-available selected network interfaces. Local Manageability Service In
tel Corporation Intel(R) Active Management Technology Local Manageability Servic
e 7.1.10.1065
[Running Services] MatLocalLicenceServer50
### Internal Name: MatLocalLicenceServer50. Status: service is running. Actual
File: "C:\Program Files (x86)\Common Files\Materialise\LicenseFiles\LicSrv50.ex
e" * Materialise Local License Server 5.0 LicSrv MFC Application LicSrv Applicat
ion 5.0.0.5
[Running Services] MpsSvc
### Internal Name: MpsSvc. Status: service is running. Actual File: C:\Windows
\system32\svchost.exe -k LocalServiceNoNetwork * Windows Firewall helps protect
your computer by preventing unauthorized users from gaining access to your compu
ter through the Internet or a network. Host Process for Windows Services Microso
ft Corporation Microsoft Windows Operating System 6.1.7600.16385
[Running Services] Net Driver HPZ12
### Internal Name: Net Driver HPZ12. Status: service is running. Actual File:
C:\Windows\System32\svchost.exe -k HPZ12 * Host Process for Windows Services Mi
crosoft Corporation Microsoft Windows Operating System 6.1.7600.16385
[Running Services] Netlogon
### Internal Name: Netlogon. Status: service is running. Actual File: C:\Windo
ws\system32\lsass.exe * Maintains a secure channel between this computer and the
domain controller for authenticating users and services. If this service is sto
pped, the computer may not authenticate users and services and the domain contro
ller cannot register DNS records. If this service is disabled, any services that
explicitly depend on it will fail to start. Local Security Authority Process Mi
crosoft Corporation Microsoft Windows Operating System 6.1.7601.18443
[Running Services] Netman
### Internal Name: Netman. Status: service is running. Actual File: C:\Windows
\System32\svchost.exe -k LocalSystemNetworkRestricted * Manages objects in the N
etwork and Dial-Up Connections folder, in which you can view both local area net
work and remote connections. Host Process for Windows Services Microsoft Corpora
tion Microsoft Windows Operating System 6.1.7600.16385
[Running Services] netprofm
### Internal Name: netprofm. Status: service is running. Actual File: C:\Windo
ws\System32\svchost.exe -k LocalService * Identifies the networks to which the c
omputer has connected, collects and stores properties for these networks, and no

tifies applications when these properties change. Host Process for Windows Servi
ces Microsoft Corporation Microsoft Windows Operating System 6.1.7600.16385
[Running Services] NlaSvc
### Internal Name: NlaSvc. Status: service is running. Actual File: C:\Windows
\System32\svchost.exe -k NetworkService * Collects and stores configuration info
rmation for the network and notifies programs when this information is modified.
If this service is stopped, configuration information might be unavailable. If
this service is disabled, any services that explicitly depend on it will fail to
start. Host Process for Windows Services Microsoft Corporation Microsoft Windows
Operating System 6.1.7600.16385
[Running Services] nsi
### Internal Name: nsi. Status: service is running. Actual File: C:\Windows\sy
stem32\svchost.exe -k LocalService * This service delivers network notifications
(e.g. interface addition/deleting etc) to user mode clients. Stopping this serv
ice will cause loss of network connectivity. If this service is disabled, any ot
her services that explicitly depend on this service will fail to start. Host Pro
cess for Windows Services Microsoft Corporation Microsoft Windows Operating System
6.1.7600.16385
[Running Services] PcaSvc
### Internal Name: PcaSvc. Status: service is running. Actual File: C:\Windows
\system32\svchost.exe -k LocalSystemNetworkRestricted * This service provides su
pport for the Program Compatibility Assistant (PCA). PCA monitors programs inst
alled and run by the user and detects known compatibility problems. If this serv
ice is stopped, PCA will not function properly. Host Process for Windows Service
s Microsoft Corporation Microsoft Windows Operating System 6.1.7600.16385
[Running Services] PelService
### Internal Name: PelService. Status: service is running. Actual File: C:\Pro
gram Files\Lenovo\Lenovo Mouse Suite\PelService.exe *
[Running Services] PlugPlay
### Internal Name: PlugPlay. Status: service is running. Actual File: C:\Windo
ws\system32\svchost.exe -k DcomLaunch * Enables a computer to recognize and adap
t to hardware changes with little or no user input. Stopping or disabling this s
ervice will result in system instability. Host Process for Windows Services Micr
osoft Corporation Microsoft Windows Operating System 6.1.7600.16385
[Running Services] Pml Driver HPZ12
### Internal Name: Pml Driver HPZ12. Status: service is running. Actual File:
C:\Windows\System32\svchost.exe -k HPZ12 * Host Process for Windows Services Mi
crosoft Corporation Microsoft Windows Operating System 6.1.7600.16385
[Running Services] Power
### Internal Name: Power. Status: service is running. Actual File: C:\Windows\
system32\svchost.exe -k DcomLaunch * Manages power policy and power policy notif
ication delivery. Host Process for Windows Services Microsoft Corporation Micros
oft Windows Operating System 6.1.7600.16385
[Running Services] ProfSvc
### Internal Name: ProfSvc. Status: service is running. Actual File: C:\Window
s\system32\svchost.exe -k netsvcs * This service is responsible for loading and
unloading user profiles. If this service is stopped or disabled, users will no l
onger be able to successfully logon or logoff, applications may have problems ge
tting to users' data, and components registered to receive profile event notific
ations will not receive them. Host Process for Windows Services Microsoft Corpor
ation Microsoft Windows Operating System 6.1.7600.16385
[Running Services] PSI_SVC_2_x64
### Internal Name: PSI_SVC_2_x64. Status: service is running. Actual File: "c:
\Program Files\Common Files\Protexis\License Service\PsiService_2.exe" * This se
rvice provides license-validation functionality for Corel Corporation. It is pow
ered by Protexis from arvato digital Services. PsiService PsiService arvato digi
tal services llc PsiService System Service 3.3.0.24
[Running Services] RemoteRegistry
### Internal Name: RemoteRegistry. Status: service is running. Actual File: C:
\Windows\system32\svchost.exe -k regsvc * Enables remote users to modify registr

y settings on this computer. If this service is stopped, the registry can be mod
ified only by users on this computer. If this service is disabled, any services
that explicitly depend on it will fail to start. Host Process for Windows Servic
es Microsoft Corporation Microsoft Windows Operating System 6.1.7600.16385
[Running Services] RosettaStoneDaemon
### Internal Name: RosettaStoneDaemon. Status: service is running. Actual File
: "C:\Program Files (x86)\RosettaStoneLtdServices\RosettaStoneDaemon.exe" * Ros
etta Stone Ltd. application Rosetta Stone Ltd. Rosetta Stone Daemon 1.0.1.0
[Running Services] RpcEptMapper
### Internal Name: RpcEptMapper. Status: service is running. Actual File: C:\W
indows\system32\svchost.exe -k RPCSS * Resolves RPC interfaces identifiers to tr
ansport endpoints. If this service is stopped or disabled, programs using Remote
Procedure Call (RPC) services will not function properly. Host Process for Wind
ows Services Microsoft Corporation Microsoft Windows Operating System 6.1.7600.163
85
[Running Services] RpcSs
### Internal Name: RpcSs. Status: service is running. Actual File: C:\Windows\
system32\svchost.exe -k rpcss * The RPCSS service is the Service Control Manager
for COM and DCOM servers. It performs object activations requests, object expor
ter resolutions and distributed garbage collection for COM and DCOM servers. If
this service is stopped or disabled, programs using COM or DCOM will not functio
n properly. It is strongly recommended that you have the RPCSS service running H
ost Process for Windows Services Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385
[Running Services] SamSs
### Internal Name: SamSs. Status: service is running. Actual File: C:\Windows\
system32\lsass.exe * The startup of this service signals other services that the
Security Accounts Manager (SAM) is ready to accept requests. Disabling this se
rvice will prevent other services in the system from being notified when the SAM
is ready, which may in turn cause those services to fail to start correctly. Th
is service should not be disabled. Local Security Authority Process Microsoft Co
rporation Microsoft Windows Operating System 6.1.7601.18443
[Running Services] Schedule
### Internal Name: Schedule. Status: service is running. Actual File: C:\Windo
ws\system32\svchost.exe -k netsvcs * Enables a user to configure and schedule au
tomated tasks on this computer. The service also hosts multiple Windows system-c
ritical tasks. If this service is stopped or disabled, these tasks will not be r
un at their scheduled times. If this service is disabled, any services that expl
icitly depend on it will fail to start. Host Process for Windows Services Micros
oft Corporation Microsoft Windows Operating System 6.1.7600.16385
[Running Services] seclogon
### Internal Name: seclogon. Status: service is running. Actual File: C:\Windo
ws\system32\svchost.exe -k netsvcs * Enables starting processes under alternate
credentials. If this service is stopped, this type of logon access will be unava
ilable. If this service is disabled, any services that explicitly depend on it w
ill fail to start. Host Process for Windows Services Microsoft Corporation Micro
soft Windows Operating System 6.1.7600.16385
[Running Services] SENS
### Internal Name: SENS. Status: service is running. Actual File: C:\Windows\s
ystem32\svchost.exe -k netsvcs * Monitors system events and notifies subscribers
to COM+ Event System of these events. Host Process for Windows Services Microso
ft Corporation Microsoft Windows Operating System 6.1.7600.16385
[Running Services] SessionEnv
### Internal Name: SessionEnv. Status: service is running. Actual File: C:\Win
dows\System32\svchost.exe -k netsvcs * Remote Desktop Configuration service (RDC
S) is responsible for all Remote Desktop Services and Remote Desktop related con
figuration and session maintenance activities that require SYSTEM context. These
include per-session temporary folders, RD themes, and RD certificates. Host Pro
cess for Windows Services Microsoft Corporation Microsoft Windows Operating System
6.1.7600.16385

[Running Services] ShellHWDetection


### Internal Name: ShellHWDetection. Status: service is running. Actual File:
C:\Windows\System32\svchost.exe -k netsvcs * Provides notifications for AutoPlay
hardware events. Host Process for Windows Services Microsoft Corporation Micros
oft Windows Operating System 6.1.7600.16385
[Running Services] Sks8821
### Internal Name: Sks8821. Status: service is running. Actual File: C:\Progra
m Files\Lenovo\Lenovo Slim USB Keyboard\Sks8821.exe *
[Running Services] Spooler
### Internal Name: Spooler. Status: service is running. Actual File: C:\Window
s\System32\spoolsv.exe * Loads files to memory for later printing Spooler SubSys
tem App Microsoft Corporation Microsoft Windows Operating System 6.1.7600.16385
[Running Services] sppsvc
### Internal Name: sppsvc. Status: service is running. Actual File: C:\Windows
\system32\sppsvc.exe * Enables the download, installation and enforcement of dig
ital licenses for Windows and Windows applications. If the service is disabled,
the operating system and licensed applications may run in a notification mode. I
t is strongly recommended that you not disable the Software Protection service.
Microsoft Software Protection Platform Service Microsoft Corporation Microsoft Wi
ndows Operating System 6.1.7600.16385
[Running Services] sppuinotify
### Internal Name: sppuinotify. Status: service is running. Actual File: C:\Wi
ndows\system32\svchost.exe -k LocalService * Provides Software Licensing activat
ion and notification Host Process for Windows Services Microsoft Corporation Mic
rosoft Windows Operating System 6.1.7600.16385
[Running Services] SSDPSRV
### Internal Name: SSDPSRV. Status: service is running. Actual File: C:\Window
s\system32\svchost.exe -k LocalServiceAndNoImpersonation * Discovers networked d
evices and services that use the SSDP discovery protocol, such as UPnP devices.
Also announces SSDP devices and services running on the local computer. If this
service is stopped, SSDP-based devices will not be discovered. If this service i
s disabled, any services that explicitly depend on it will fail to start. Host P
rocess for Windows Services Microsoft Corporation Microsoft Windows Operating Syst
em 6.1.7600.16385
[Running Services] stisvc
### Internal Name: stisvc. Status: service is running. Actual File: C:\Windows
\system32\svchost.exe -k imgsvc * Provides image acquisition services for scanne
rs and cameras Host Process for Windows Services Microsoft Corporation Microsoft
Windows Operating System 6.1.7600.16385
[Running Services] SysMain
### Internal Name: SysMain. Status: service is running. Actual File: C:\Window
s\system32\svchost.exe -k LocalSystemNetworkRestricted * Maintains and improves
system performance over time. Host Process for Windows Services Microsoft Corpor
ation Microsoft Windows Operating System 6.1.7600.16385
[Running Services] SystemUsageReportSvc_WILLAMETTE
### Internal Name: SystemUsageReportSvc_WILLAMETTE. Status: service is running
. Actual File: "C:\Program Files (x86)\Intel Driver Update Utility\SUR\SurSvc.ex
e" * Inte(R) System Usage Report Service SystemUsageReportSvc_WILLAMETTE monitor
s the computer system usage and helps to improve system's performance. Intel(R)
System Usage Report Intel(R) System Usage Report
[Running Services] TeamViewer9
### Internal Name: TeamViewer9. Status: service is running. Actual File: "C:\P
rogram Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe" * TeamViewer Remo
te Software TeamViewer 9 TeamViewer GmbH TeamViewer 9.0
[Running Services] TermService
### Internal Name: TermService. Status: service is running. Actual File: C:\Wi
ndows\System32\svchost.exe -k NetworkService * Allows users to connect interacti
vely to a remote computer. Remote Desktop and Remote Desktop Session Host Server
depend on this service. To prevent remote use of this computer, clear the chec
kboxes on the Remote tab of the System properties control panel item. Host Proce

ss for Windows Services Microsoft Corporation Microsoft Windows Operating System 6


.1.7600.16385
[Running Services] Themes
### Internal Name: Themes. Status: service is running. Actual File: C:\Windows
\System32\svchost.exe -k netsvcs * Provides user experience theme management. Ho
st Process for Windows Services Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385
[Running Services] TrkWks
### Internal Name: TrkWks. Status: service is running. Actual File: C:\Windows
\System32\svchost.exe -k LocalSystemNetworkRestricted * Maintains links between
NTFS files within a computer or across computers in a network. Host Process for
Windows Services Microsoft Corporation Microsoft Windows Operating System 6.1.7600
.16385
[Running Services] UmRdpService
### Internal Name: UmRdpService. Status: service is running. Actual File: C:\W
indows\System32\svchost.exe -k LocalSystemNetworkRestricted * Allows the redirec
tion of Printers/Drives/Ports for RDP connections Host Process for Windows Servi
ces Microsoft Corporation Microsoft Windows Operating System 6.1.7600.16385
[Running Services] UNS
### Internal Name: UNS. Status: service is running. Actual File: "C:\Program F
iles (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe" * Intel(R) M
anagement and Security Application User Notification Service - Updates the Windo
ws Event Log with notifications of pre defined events received from the local In
tel(R) Management and Security Application Device. User Notification Service Int
el Corporation Intel(R) Management and Security Application User Notification Se
rvice 7.1.10.1065
[Running Services] upnphost
### Internal Name: upnphost. Status: service is running. Actual File: C:\Windo
ws\system32\svchost.exe -k LocalServiceAndNoImpersonation * Allows UPnP devices
to be hosted on this computer. If this service is stopped, any hosted UPnP devic
es will stop functioning and no additional hosted devices can be added. If this
service is disabled, any services that explicitly depend on it will fail to star
t. Host Process for Windows Services Microsoft Corporation Microsoft Windows Opera
ting System 6.1.7600.16385
[Running Services] UxSms
### Internal Name: UxSms. Status: service is running. Actual File: C:\Windows\
System32\svchost.exe -k LocalSystemNetworkRestricted * Provides Desktop Window M
anager startup and maintenance services Host Process for Windows Services Micros
oft Corporation Microsoft Windows Operating System 6.1.7600.16385
[Running Services] VMAuthdService
### Internal Name: VMAuthdService. Status: service is running. Actual File: "C
:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe" * Authorizatio
n and authentication service for starting and accessing virtual machines. VMware
Authorization Service VMware, Inc. VMware Workstation 10.0.0 build-1295980
[Running Services] VMUSBArbService
### Internal Name: VMUSBArbService. Status: service is running. Actual File: "
C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe" * Arb
itration and enumeration of USB devices for virtual machines VMware USB Arbitrat
ion Service VMware, Inc. VMware USB Arbitration Service 12.1.10 build-1295349
[Running Services] wcncsvc
### Internal Name: wcncsvc. Status: service is running. Actual File: C:\Window
s\System32\svchost.exe -k LocalServiceAndNoImpersonation * WCNCSVC hosts the Win
dows Connect Now Configuration which is Microsoft's Implementation of Wi-Fi Prot
ected Setup (WPS) protocol. This is used to configure Wireless LAN settings for
an Access Point (AP) or a Wi-Fi Device. The service is started programmatically
as needed. Host Process for Windows Services Microsoft Corporation Microsoft Wind
ows Operating System 6.1.7600.16385
[Running Services] WdiServiceHost
### Internal Name: WdiServiceHost. Status: service is running. Actual File: C:
\Windows\System32\svchost.exe -k LocalService * The Diagnostic Service Host is u

sed by the Diagnostic Policy Service to host diagnostics that need to run in a L
ocal Service context. If this service is stopped, any diagnostics that depend o
n it will no longer function. Host Process for Windows Services Microsoft Corpor
ation Microsoft Windows Operating System 6.1.7600.16385
[Running Services] Winmgmt
### Internal Name: Winmgmt. Status: service is running. Actual File: C:\Window
s\system32\svchost.exe -k netsvcs * Provides a common interface and object model
to access management information about operating system, devices, applications
and services. If this service is stopped, most Windows-based software will not f
unction properly. If this service is disabled, any services that explicitly depe
nd on it will fail to start. Host Process for Windows Services Microsoft Corpora
tion Microsoft Windows Operating System 6.1.7600.16385
[Running Services] WSearch
### Internal Name: WSearch. Status: service is running. Actual File: C:\Window
s\system32\SearchIndexer.exe /Embedding * Provides content indexing, property ca
ching, and search results for files, e-mail, and other content. Microsoft Window
s Search Indexer Microsoft Corporation Windows Search 7.00.7600.16385
[Running Services] wudfsvc
### Internal Name: wudfsvc. Status: service is running. Actual File: C:\Window
s\system32\svchost.exe -k LocalSystemNetworkRestricted * Manages user-mode drive
r host processes. Host Process for Windows Services Microsoft Corporation Micros
oft Windows Operating System 6.1.7600.16385
[Uninstall]
[Applications] :HKLM {4010ADCB-1347-D570-FCF1-3002CABEBD2F}=MsiExec.exe /X{401
0ADCB-1347-D570-FCF1-3002CABEBD2F}
### Rosetta Stone TOTALe - (28) 04-2016
[Applications] :HKLM com.rosettastone.rosettastonetotale=cmd /c "start /wait m
siexec /qb /x {8A1FEA5E-8DB8-AD80-5C14-AEF33D16EF5A} && msiexec /qb /x {4010ADCB
-1347-D570-FCF1-3002CABEBD2F}"
### Rosetta Stone TOTALe - (28) 04-2016
[Applications] :HKLM {7BB2EF8A-5376-4BAE-96D0-38BE49501F40}=MsiExec.exe /X{7BB
2EF8A-5376-4BAE-96D0-38BE49501F40}
### Rosetta Stone Ltd Services - (28) 04-2016
[Applications] :HKLM {8A1FEA5E-8DB8-AD80-5C14-AEF33D16EF5A}=MsiExec.exe /I{8A1
FEA5E-8DB8-AD80-5C14-AEF33D16EF5A}
### Rosetta Stone TOTALe - (28) 04-2016
[Applications] :HKLM Adobe Flash Player NPAPI=C:\Windows\SysWOW64\Macromed\Fla
sh\FlashUtil32_21_0_0_213_Plugin.exe -maintain plugin
### Adobe Flash Player 21 NPAPI - (08) 04-2016
[Applications] :HKLM Adobe Flash Player ActiveX=C:\Windows\SysWOW64\Macromed\F
lash\FlashUtil32_21_0_0_213_ActiveX.exe -maintain activex
### Adobe Flash Player 21 ActiveX - (08) 04-2016
[Applications] :HKLM {AC76BA86-1033-0000-7760-000000000002}
### Adobe Acrobat 7.0 Professional - (06) 04-2016
[Applications] :HKLM MediaCoder x64=C:\Program Files\MediaCoder\uninst.exe
### MediaCoder x64 0.8.42.5822 - (06) 04-2016
[Applications] :HKLM Meda MP3 Joiner_is1="C:\Program Files (x86)\Meda MP3 Join
er\unins000.exe"
### Meda MP3 Joiner 1.2 - (06) 04-2016
[Applications] :HKLM {A7E19604-93AF-4611-8C9F-CE509C2B286F}_is1="C:\Program Fi
les (x86)\Free YouTube Downloader\unins000.exe"
### Free YouTube Downloader 4.1.484 - (05) 04-2016
[Applications] :HKLM {619e726e-d2b4-4e28-9568-c964fd81ee6c}="C:\ProgramData\Pa
ckage Cache\{619e726e-d2b4-4e28-9568-c964fd81ee6c}\SetupChipset.exe" /uninstall
### Intel(R) Chipset Device Software - (31) 03-2016
[Applications] :HKLM {FEBB7B48-CC1C-4A50-A497-FA21413F6BE9}=MsiExec.exe /I{FEB
B7B48-CC1C-4A50-A497-FA21413F6BE9}
### Intel(R) Chipset Device Software - (31) 03-2016
[Applications] :HKLM {1b09c4de-9cae-4122-b17c-65d395062b50}="C:\ProgramData\Pa
ckage Cache\{1b09c4de-9cae-4122-b17c-65d395062b50}\Intel Driver Update Utility I

nstaller.exe" /uninstall
### Intel Driver Update Utility - (31) 03-2016
[Applications] :HKLM {B731F5C4-E304-4DFA-9C84-F67FF849B408}=MsiExec.exe /X{B73
1F5C4-E304-4DFA-9C84-F67FF849B408}
### Intel(R) Driver Update Utility 2.4 - (31) 03-2016
[Applications] :HKLM {E954D7C1-36FA-4FE8-8927-97DBDEB5A15F}=MsiExec.exe /I{E95
4D7C1-36FA-4FE8-8927-97DBDEB5A15F}
### Intel(R) Product Improvement Program - (31) 03-2016
[Applications] :HKLM {65153EA5-8B6E-43B6-857B-C6E4FC25798A}=C:\Program Files (
x86)\Intel\Intel(R) Management Engine Components\Uninstall\setup.exe -uninstall
### Intel(R) Management Engine Components - (31) 03-2016
[Applications] :HKLM {2991A446-D356-44EC-930A-42E8B02A67C0}_is1="C:\Program Fi
les (x86)\MiniTool Partition Wizard Professional Edition 9.1\unins000.exe"
### MiniTool Partition Wizard Professional Edition 9.1 - (31) 03-2016
[Applications] :HKLM {0C286478-1D87-432F-9ADB-5C36FA58BB72}_is1="C:\Program Fi
les (x86)\MiniTool Partition Wizard Server Edition 9.1\unins000.exe"
### MiniTool Partition Wizard Server Edition 9.1 - (31) 03-2016
[Applications] :HKLM MalwareProtectionLive="C:\Users\admin\AppData\Local\Malwa
reProtectionLive\uninstall.exe"
### Malware Protection Live - (30) 03-2016
[Applications] :HKLM {1a413f37-ed88-4fec-9666-5c48dc4b7bb7}="C:\Program Files
(x86)\GreenTree Applications\YTD Video Downloader\uninstall.exe"
### YTD Video Downloader 5.3 - (30) 03-2016
[Applications] :HKLM {891ED714-E54D-4BE1-8DE8-4EE54D9BB402}=MsiExec.exe /X{891
ED714-E54D-4BE1-8DE8-4EE54D9BB402}
### Pinnacle Studio 19 - Install Manager - (29) 03-2016
[Applications] :HKLM {4A03706F-666A-4037-7777-5F2748764D10}
### Java Auto Updater - (26) 03-2016
[Applications] :HKLM {26A24AE4-039D-4CA4-87B4-2F83218077F0}=MsiExec.exe /X{26A
24AE4-039D-4CA4-87B4-2F83218077F0}
### Java 8 Update 77 - (26) 03-2016
[Applications] :HKLM {3C9D008D-3716-4C3F-90CD-38ED57568FAB}_is1="C:\Program Fi
les (x86)\Apowersoft\Video Download Capture\unins000.exe"
### Video Download Capture V4.3.0 - (26) 03-2016
[Applications] :HKLM {AC76BA86-7AD7-1033-7B44-AC0F074E4100}=MsiExec.exe /I{AC7
6BA86-7AD7-1033-7B44-AC0F074E4100}
### Adobe Acrobat Reader DC - (18) 03-2016
[Applications] :HKLM UnHackMe_is1="C:\Program Files (x86)\UnHackMe\unins000.ex
e"
### UnHackMe 7.70 release - (17) 03-2016
[Applications] :HKLM {60EC980A-BDA2-4CB6-A427-B07A5498B4CA}=MsiExec.exe /I{60E
C980A-BDA2-4CB6-A427-B07A5498B4CA}
### Google Update Helper - (22) 01-2016
[Applications] :HKLM Google Chrome="C:\Program Files (x86)\Google\Chrome\Appli
cation\48.0.2564.82\Installer\setup.exe" --uninstall --multi-install --chrome -system-level --verbose-logging
### Google Chrome - (22) 01-2016
[Applications] :HKLM {AC76BA86-0804-1033-1959-001824166751}=MsiExec.exe /I{AC7
6BA86-0804-1033-1959-001824166751}
### Adobe Refresh Manager - (18) 01-2016
[Applications] :HKLM Adobe Acrobat 7.0 Professional=msiexec /I {AC76BA86-10330000-7760-000000000002}
### Adobe Acrobat 7.0 Professional - (18) 01-2016
[Applications] :HKLM NirSoft Wireless Network Watcher="C:\Program Files (x86)\
NirSoft\Wireless Network Watcher\uninst.exe"
### NirSoft Wireless Network Watcher - (07) 01-2016
[Applications] :HKLM {F09EF8F2-0976-42C1-8D9D-8DF78337C6E3}="C:\Program Files
(x86)\InstallShield Installation Information\{F09EF8F2-0976-42C1-8D9D-8DF78337C6
E3}\setup.exe" -runfromtemp -l0x0409 -removeonly
### Sony PC Companion 2.10.303 - (19) 12-2015

[Applications] :HKLM TeamViewer 9=C:\Program Files (x86)\TeamViewer\Version9\u


ninstall.exe
### TeamViewer 9 - (10) 12-2015
[Applications] :HKLM FreeStar Free MP3 Splitter=C:\Program Files (x86)\freesta
r\free-mp3-splitter\uninst.exe
### FreeStar Free MP3 Splitter 1.0.4 - (07) 11-2015
[Applications] :HKLM All Free MP3 Cutter_is1="C:\Program Files (x86)\All Free
MP3 Cutter\unins000.exe"
### All Free MP3 WMA Cutter 2.3.1 - (07) 11-2015
[Applications] :HKLM Easy MP3 Cutter_is1="C:\Program Files (x86)\Easy MP3 Cutt
er\unins000.exe"
### Easy MP3 Cutter 3.0 - (06) 11-2015
[Applications] :HKLM {26A24AE4-039D-4CA4-87B4-2F83218065F0}=MsiExec.exe /X{26A
24AE4-039D-4CA4-87B4-2F83218065F0}
### Java 8 Update 65 - (03) 11-2015
[Applications] :HKLM FileZilla Client=C:\Program Files (x86)\FileZilla FTP Cli
ent\uninstall.exe
### FileZilla Client 3.13.1 - (27) 08-2015
[Applications] :HKLM zz.1407.ssp
### - (12) 08-2015
[Applications] :HKLM WinRAR archiver=C:\Program Files\WinRAR\uninstall.exe
### WinRAR 5.21 (64-bit) - (12) 08-2015
[Applications] :HKLM {C42C5197-0EE9-4940-893B-F4EF047DFF0F}
### - (12) 08-2015
[Applications] :HKLM Mozilla Firefox 39.0.3 (x86 en-US)="C:\Program Files (x86
)\Mozilla Firefox\uninstall\helper.exe"
### Mozilla Firefox 39.0.3 (x86 en-US) - (11) 08-2015
[Applications] :HKLM {E9AA5BDC-7DFA-4CB8-96B5-F545F20EBFDB}=MsiExec.exe /I{E9A
A5BDC-7DFA-4CB8-96B5-F545F20EBFDB}
### Foxit PhantomPDF Business - (21) 07-2015
[Applications] :HKLM PDF Power Tool_is1="C:\Program Files\Bullzip\PDF Printer\
ppt\unins000.exe"
### PDF Power Tool 3.0.0.9 - (21) 07-2015
[Applications] :HKLM Bullzip PDF Printer_is1="C:\Program Files\Bullzip\PDF Pri
nter\unins000.exe"
### Bullzip PDF Printer 7.2.0.1338 - (21) 07-2015
[Applications] :HKLM Free Download Manager_is1="C:\Program Files (x86)\Free Do
wnload Manager\unins000.exe"
### Free Download Manager 3.9.4 - (02) 06-2015
[Applications] :HKLM {817750FA-EC6A-485D-9901-0683AE6FFDF1}=MsiExec.exe /I{817
750FA-EC6A-485D-9901-0683AE6FFDF1}
### Google Earth - (02) 06-2015
[Applications] :HKLM GoogleInputHindi=C:\Program Files (x86)\Google\Google Inp
ut Tools\GoogleInputUninstaller.exe --pack_name=com.google.input_tools.t13n.ime.
hindi
### Google Input Hindi - (29) 05-2015
[Applications] :HKLM MozillaMaintenanceService="C:\Program Files (x86)\Mozilla
Maintenance Service\uninstall.exe"
### Mozilla Maintenance Service - (29) 05-2015
[Applications] :HKLM {64A3A4F4-B792-11D6-A78A-00B0D0170790}=MsiExec.exe /I{64A
3A4F4-B792-11D6-A78A-00B0D0170790}
### Java SE Development Kit 7 Update 79 (64-bit) - (21) 04-2015
[Applications] :HKLM {9AEF25CF-6F43-41FB-9DDD-9BFA15EE81FD}=MsiExec.exe /I{9AE
F25CF-6F43-41FB-9DDD-9BFA15EE81FD}
### StarToken-NG - (10) 03-2015
[Applications] :HKLM VLC media player=C:\Program Files (x86)\VideoLAN\VLC\unin
stall.exe
### VLC media player - (28) 02-2015
[Applications] :HKLM Stellar Phoenix Windows Data Recovery - Professional_is1=
"C:\Program Files (x86)\Stellar Phoenix Windows Data Recovery\unins000.exe"

### Stellar Phoenix Windows Data Recovery - Professional - (17) 02-2015


[Applications] :HKLM EaseUS Data Recovery Wizard 7.5_is1="C:\Program Files (x8
6)\EaseUS\EaseUS Data Recovery Wizard\unins000.exe"
### EaseUS Data Recovery Wizard 7.5 - (16) 02-2015
[Applications] :HKLM {F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}=MsiExec.exe /X{F0C
3E5D1-1ADE-321E-8167-68EF0DE699A5}
### Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 - (14) 02-2015
[Applications] :HKLM {75BAE677-F65A-45A4-9931-363FE0CF5E58}_is1="C:\Program Fi
les (x86)\Wondershare\PDFEditor\unins000.exe"
### Wondershare PDF Editor(Build 3.5.0) - (14) 02-2015
[Applications] :HKLM Adobe AIR=C:\Program Files (x86)\Common Files\Adobe AIR\V
ersions\1.0\Resources\Adobe AIR Updater.exe -arp:uninstall
### Adobe AIR - (03) 02-2015
[Applications] :HKLM {46C045BF-2B3F-4BC4-8E4C-00E0CF8BD9DB}=MsiExec.exe /I{46C
045BF-2B3F-4BC4-8E4C-00E0CF8BD9DB}
### Adobe AIR - (03) 02-2015
[Applications] :HKLM SysTools Excel to vCard Converter - DEMO Version_is1="C:\
Program Files (x86)\SysTools Excel to vCard Converter\unins000.exe"
### SysTools Excel to vCard Converter - (02) 01-2015
[Applications] :HKLM PowerISO="C:\Program Files (x86)\PowerISO\uninstall.exe"
### PowerISO - (19) 12-2014
[Applications] :HKLM MouseSuite98=C:\Program Files\Lenovo\Lenovo Mouse Suite\P
MUninst.exe MouseSuite98
### Lenovo Mouse Suite - (06) 12-2014
[Applications] :HKLM Update Engine=C:\Program Files (x86)\Sony Mobile\Update E
ngine\uninst.exe
### Sony Mobile Update Engine - (28) 11-2014
[Applications] :HKLM {D0795B21-0CDA-4a92-AB9E-6E92D8111E44}=C:\Program Files (
x86)\Samsung\USB Drivers\Uninstall.exe
### SAMSUNG USB Driver for Mobile Phones - (22) 11-2014
[Applications] :HKLM {D6CD26FD-CD7F-4C86-96A3-EEBFABE5FE47}
### - (22) 11-2014
[Applications] :HKLM InstallShield_{758C8301-2696-4855-AF45-534B1200980A}="C:\
Program Files (x86)\InstallShield Installation Information\{758C8301-2696-4855-A
F45-534B1200980A}\setup.exe" -runfromtemp -l0x0409 -removeonly
### Samsung Kies - (22) 11-2014
[Applications] :HKLM {758C8301-2696-4855-AF45-534B1200980A}=MsiExec.exe /I{758
C8301-2696-4855-AF45-534B1200980A}
### Samsung Kies - (22) 11-2014
[Applications] :HKLM {A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}=MsiExec.exe /I{A92
DAB39-4E2C-4304-9AB6-BC44E68B55E2}
### Google Update Helper - (17) 11-2014
[Applications] :HKLM CMS="C:\Program Files (x86)\CMS\uninstall.exe" "/U:C:\Pro
gram Files (x86)\CMS\Uninstall\uninstall.xml"
### CMS - (13) 11-2014
[Applications] :HKLM {7697245D-2E00-4B83-AD27-C051DE314D1F}="C:\Program Files
(x86)\InstallShield Installation Information\{7697245D-2E00-4B83-AD27-C051DE314D
1F}\setup.exe" -runfromtemp -l0x0409 -removeonly
### iVMS-4200(v2.00) - (13) 11-2014
[Applications] :HKLM {03B13AF8-9625-478A-AF0E-205337B9415A}_is1="C:\Program Fi
les (x86)\Web Components\unins000.exe"
### Web Components - (13) 11-2014
[Applications] :HKLM {70A38006-EAE0-4FB8-8AC4-182C223D0060}=C:\Program Files (
x86)\InstallShield Installation Information\{70A38006-EAE0-4FB8-8AC4-182C223D006
0}\setup.exe -runfromtemp -l0x0009 -removeonly
### iVMS-4000(v2.0) - (13) 11-2014
[Applications] :HKLM UltraDefrag=C:\Program Files\UltraDefrag\uninstall.exe
### Ultra Defragmenter - (08) 11-2014
[Applications] :HKLM WinRAR archiver=C:\Program Files (x86)\WinRAR\uninstall.e
xe

### WinRAR 4.00 beta 3 (32-bit) - (05) 11-2014


[Applications] :HKLM CCleaner="C:\Program Files\CCleaner\uninst.exe"
### CCleaner - (29) 10-2014
[Applications] :HKLM {494D80C4-3557-4D73-A153-65FE4B3ECDC3}=MsiExec.exe /X{494
D80C4-3557-4D73-A153-65FE4B3ECDC3}
### Lenovo Slim USB Keyboard - (22) 09-2014
[Applications] :HKLM ST6UNST #3=C:\WINDOWS\st6unst.exe -n "C:\Program Files (x
86)\KKDict\ST6UNST.LOG"
### KK Dictionary Version 1.2 - (19) 09-2014
[Applications] :HKLM HHD Device Monitoring Studio 5.01="C:\Program Files\HHD S
oftware\Device Monitoring Studio\Setup\uninstSERIAL.exe" -u
### HHD Software Free Serial Port Monitor 6.54 - (15) 09-2014
[Applications] :HKLM {12FEC00C-027C-4A34-9AAB-562EDA43DC18}_is1="C:\Program Fi
les (x86)\MiniTool Partition Wizard Home Edition 5.2\unins000.exe"
### MiniTool Partition Wizard Home Edition 5.2 - (13) 09-2014
[Applications] :HKLM Kernel for Outlook_is1="C:\Program Files (x86)\Kernel for
Outlook\unins000.exe"
### Kernel for Outlook ver 7.07.01 - (10) 09-2014
[Applications] :HKLM Baraha 10_is1="C:\Program Files (x86)\Baraha Software\Bar
aha 10\unins000.exe"
### Baraha 10.10 - (09) 09-2014
[Applications] :HKLM SNS-HDR Pro_is1="C:\Program Files\SNS-HDR Pro\unins000.ex
e"
### SNS-HDR Pro v1.4.22 - (08) 09-2014
[Applications] :HKLM GoogleInputKannada=C:\Program Files (x86)\Google\Google I
nput Tools\GoogleInputUninstaller.exe --pack_name=com.google.input_tools.t13n.im
e.kannada
### Google Input Kannada - (27) 08-2014
[Applications] :HKLM GoogleInputFramework=C:\Program Files (x86)\Google\Google
Input Tools\GoogleInputUninstaller.exe --pack_name=framework
### Google Input Tools - (27) 08-2014
[Applications] :HKLM Nero=C:\Program Files (x86)\Nero\Nero 12\Nero Burning ROM
\uninstall.exe
### Nero - (21) 08-2014
[Applications] :HKLM {CCF298AF-9CE1-4B26-B251-486E98A34789}=MsiExec.exe /X{CCF
298AF-9CE1-4B26-B251-486E98A34789}
### Windows 7 USB/DVD Download Tool - (08) 08-2014
[Applications] :HKLM B521582C-6BE3-491D-BCC8-FFB8301298E9_is1="C:\Program File
s (x86)\Foxit Software\Foxit Advanced PDF Editor\unins000.exe"
### Foxit Advanced PDF Editor 3 - (26) 07-2014
[Applications] :HKLM Advanced Word to Pdf Converter_is1="C:\Program Files (x86
)\Advanced Word to Pdf Converter\unins000.exe"
### Advanced Word to Pdf Converter 6.4 - (15) 07-2014
[Applications] :HKLM ZBrush 4R6 4R6=C:\Program Files (x86)\Pixologic\ZBrush 4R
6\Uninstall\Uninstall ZBrush 4R6.exe
### ZBrush 4R6 - (09) 07-2014
[Applications] :HKLM {18CDCEAA-A9E4-4A4C-AC0E-C15E87C30EA5}_is1="C:\Program Fi
les (x86)\Wondershare\MobileTrans\unins000.exe"
### Wondershare MobileTrans ( Version 5.1.1 ) - (09) 07-2014
[Applications] :HKLM {2C91CB9D-323D-43E5-A433-229B71CFB773}
### CorelDRAW Graphics Suite X7 - Capture (x64) - (09) 07-2014
[Applications] :HKLM {966996DC-D67C-40E3-8BD4-31FA0F093571}
### CorelDRAW Graphics Suite X7 - VideoBrowser (x64) - (09) 07-2014
[Applications] :HKLM {5672E0DC-7489-4EAC-8CFD-E01B3868FCB5}
### CorelDRAW Graphics Suite X7 - VBA (x64) - (09) 07-2014
[Applications] :HKLM {D63404AC-C2F1-4B3D-96EA-9727AC9D994C}=MsiExec.exe /I{D63
404AC-C2F1-4B3D-96EA-9727AC9D994C}
### CorelDRAW Graphics Suite X7 - Writing Tools (x64) - (09) 07-2014
[Applications] :HKLM {5406029B-67AD-4F8E-9F2D-F1959CD9CD86}
### CorelDRAW Graphics Suite X7 - FontNav (x64) - (09) 07-2014

[Applications] :HKLM {D10A5CFA-FE33-4F06-AE37-554604F00A52}


### CorelDRAW Graphics Suite X7 - Filters (x64) - (09) 07-2014
[Applications] :HKLM {9178F0A8-B6F6-4DA7-AD63-317CC4875F4B}
### CorelDRAW Graphics Suite X7 - Common (x64) - (09) 07-2014
[Applications] :HKLM {5162E418-BB43-4C8F-ACD6-069645EF98C3}
### CorelDRAW Graphics Suite X7 - Custom Data (x64) - (09) 07-2014
[Applications] :HKLM {3BB8EB77-737B-4B32-BAB9-08C7110C46BD}
### CorelDRAW Graphics Suite X7 - EN (x64) - (09) 07-2014
[Applications] :HKLM {83646B67-A878-4E95-BB4B-AF4A6E61F28C}
### CGS17_Setup_x64 - (09) 07-2014
[Applications] :HKLM {BD036E95-A9CD-4DED-B744-95AB1DCAFF0C}
### CorelDRAW Graphics Suite X7 - Connect (x64) - (09) 07-2014
[Applications] :HKLM {C922F325-DD52-4E22-B204-431A06E63E51}
### CorelDRAW Graphics Suite X7 - PHOTO-PAINT (x64) - (09) 07-2014
[Applications] :HKLM {2C0DDC74-5234-43DD-BB5A-0645B8FE5289}
### CorelDRAW Graphics Suite X7 - Draw (x64) - (09) 07-2014
[Applications] :HKLM {13179AB2-69FD-459B-800F-81865A501AD4}=MsiExec.exe /I{131
79AB2-69FD-459B-800F-81865A501AD4}
### CorelDRAW Graphics Suite X7 - IPM T (x64) - (09) 07-2014
[Applications] :HKLM {D2437C5C-2D8C-40D2-8059-689AD7239FA3}=MsiExec.exe /X{D24
37C5C-2D8C-40D2-8059-689AD7239FA3}
### Intel(R) C++ Redistributables for Windows* on Intel(R) 64 - (09) 07-2014
[Applications] :HKLM _{06CD45E6-FF5E-4D8E-BC01-B276A90DADF2}=c:\Program Files
(x86)\gs\gs8.64\Uninst.exe -ProductCode {06CD45E6-FF5E-4D8E-BC01-B276A90DADF2} arp
### Ghostscript GPL 8.64 (Msi Setup) - (09) 07-2014
[Applications] :HKLM {06CD45E6-FF5E-4D8E-BC01-B276A90DADF2}=MsiExec.exe /X{06C
D45E6-FF5E-4D8E-BC01-B276A90DADF2}
### Ghostscript GPL 8.64 (Msi Setup) - (09) 07-2014
[Applications] :HKLM {89ca2a32-2b52-4595-8dfd-6fe4757958d0}="C:\ProgramData\Pa
ckage Cache\{89ca2a32-2b52-4595-8dfd-6fe4757958d0}\vsta_setup.exe" /uninstall
### Microsoft Visual Studio Tools for Applications 2012 - (09) 07-2014
[Applications] :HKLM {5950473A-825B-3019-AF86-55F2F9A95FCB}=MsiExec.exe /I{595
0473A-825B-3019-AF86-55F2F9A95FCB}
### Microsoft Visual Studio Tools for Applications 2012 Finalizer - (09) 07-20
14
[Applications] :HKLM {25FB53C5-BE4C-3B6C-A0C9-D49A39227E1E}=MsiExec.exe /X{25F
B53C5-BE4C-3B6C-A0C9-D49A39227E1E}
### ???????? ????? ??? ????????? ?????????? ?????? ??????? Microsoft Visual St
udio Tools ??? ?????? ? ???????????? 2012 (x64) - RUS - (09) 07-2014
[Applications] :HKLM {E237254B-36A1-3D27-815E-B37C13BE0796}=MsiExec.exe /X{E23
7254B-36A1-3D27-815E-B37C13BE0796}
### Pacote de Idiomas do Microsoft Visual Studio Tools for Applications 2012 x
64 Hosting Support - PTB - (09) 07-2014
[Applications] :HKLM {2F884A17-E051-3DB7-B093-6274C98740F6}=MsiExec.exe /X{2F8
84A17-E051-3DB7-B093-6274C98740F6}
### Microsoft Visual Studio Tools for Applications 2012 x64 Hosting Support ??? ?? ? - (09) 07-2014
[Applications] :HKLM {73A64813-E631-3807-8E78-BA679EDA09A8}=MsiExec.exe /X{73A
64813-E631-3807-8E78-BA679EDA09A8}
### Microsoft Visual Studio Tools for Applications 2012 x64 Hosting Support ??? Language Pack - (09) 07-2014
[Applications] :HKLM {73A36613-1F8F-3D94-B28A-4CC0E3CAECB5}=MsiExec.exe /X{73A
36613-1F8F-3D94-B28A-4CC0E3CAECB5}
### Microsoft Visual Studio Tools for Applications 2012 x64 Hosting Support Language Pack ITA - (09) 07-2014
[Applications] :HKLM {BA14C6F7-A633-3E88-831B-FCC197A5A17D}=MsiExec.exe /X{BA1
4C6F7-A633-3E88-831B-FCC197A5A17D}
### Microsoft Visual Studio Tools for Applications 2012 x64 Hosting Support Module linguistique Franais - (09) 07-2014

[Applications] :HKLM {DDDF762A-2D1D-36A3-9B70-70BD62B4EDCF}=MsiExec.exe /X{DDD


F762A-2D1D-36A3-9B70-70BD62B4EDCF}
### Microsoft Visual Studio Tools for Applications 2012 x64 Hosting Support Paquete de idioma ESN - (09) 07-2014
[Applications] :HKLM {36B98E65-CA52-348C-9ED7-77B926A16C2D}=MsiExec.exe /X{36B
98E65-CA52-348C-9ED7-77B926A16C2D}
### Microsoft Visual Studio Tools for Applications 2012 x64 Hosting Support DEU-Sprachpaket - (09) 07-2014
[Applications] :HKLM {FB501A6E-CA6D-36DA-8860-17F0E6D89155}=MsiExec.exe /X{FB5
01A6E-CA6D-36DA-8860-17F0E6D89155}
### Microsoft Visual Studio Tools for Applications 2012 x64 ???? - ???????? (09) 07-2014
[Applications] :HKLM {CD56C9B9-FB98-372B-8BC7-FDA312CD2511}=MsiExec.exe /X{CD5
6C9B9-FB98-372B-8BC7-FDA312CD2511}
### Microsoft Visual Studio Tools for Applications 2012 x64 ???? - ??????? - (
09) 07-2014
[Applications] :HKLM {5707EC26-AA9F-32C6-B7C1-347A3482CEC0}=MsiExec.exe /X{570
7EC26-AA9F-32C6-B7C1-347A3482CEC0}
### Microsoft Visual Studio Tools for Applications 2012 x64 Hosting Support (09) 07-2014
[Applications] :HKLM {03077B58-6ACF-32CA-B42A-EAA458C295A1}=MsiExec.exe /X{030
77B58-6ACF-32CA-B42A-EAA458C295A1}
### Pacote de Idiomas do Microsoft Visual Studio Tools for Applications 2012 x
86 Hosting Support - PTB - (09) 07-2014
[Applications] :HKLM {68DC347D-C1C0-3DE2-A53E-CCC71DA53E57}=MsiExec.exe /X{68D
C347D-C1C0-3DE2-A53E-CCC71DA53E57}
### ???????? ????? ??? ????????? ?????????? ?????? ??????? Microsoft Visual St
udio Tools ??? ?????? ? ???????????? 2012 (x86) - RUS - (09) 07-2014
[Applications] :HKLM {955E1388-E1F1-320A-A018-24616ED60F95}=MsiExec.exe /X{955
E1388-E1F1-320A-A018-24616ED60F95}
### Microsoft Visual Studio Tools for Applications 2012 x86 Hosting Support ??? ?? ? - (09) 07-2014
[Applications] :HKLM {859C7535-6862-3867-B97E-816795E8AB65}=MsiExec.exe /X{859
C7535-6862-3867-B97E-816795E8AB65}
### Microsoft Visual Studio Tools for Applications 2012 x86 Hosting Support ??? Language Pack - (09) 07-2014
[Applications] :HKLM {B8FD8F53-7E58-3DE5-A8FC-CB2B5CCF38CE}=MsiExec.exe /X{B8F
D8F53-7E58-3DE5-A8FC-CB2B5CCF38CE}
### Microsoft Visual Studio Tools for Applications 2012 x86 Hosting Support Language Pack ITA - (09) 07-2014
[Applications] :HKLM {3371699A-C1EF-3AC3-B094-D338191FA6E9}=MsiExec.exe /X{337
1699A-C1EF-3AC3-B094-D338191FA6E9}
### Microsoft Visual Studio Tools for Applications 2012 x86 Hosting Support Module linguistique Franais - (09) 07-2014
[Applications] :HKLM {A3EB1DE3-9D3F-34C2-BDE6-5A8A4B98CC37}=MsiExec.exe /X{A3E
B1DE3-9D3F-34C2-BDE6-5A8A4B98CC37}
### Microsoft Visual Studio Tools for Applications 2012 x86 Hosting Support Paquete de idioma ESN - (09) 07-2014
[Applications] :HKLM {CAAC553D-EE02-32D2-9F7E-FBC5C22E4C08}=MsiExec.exe /X{CAA
C553D-EE02-32D2-9F7E-FBC5C22E4C08}
### Microsoft Visual Studio Tools for Applications 2012 x86 Hosting Support DEU-Sprachpaket - (09) 07-2014
[Applications] :HKLM {0FE6DE07-8CBA-3F73-86B4-51B91E506D24}=MsiExec.exe /X{0FE
6DE07-8CBA-3F73-86B4-51B91E506D24}
### Microsoft Visual Studio Tools for Applications 2012 x86 ???? - ???????? (09) 07-2014
[Applications] :HKLM {7259BDDA-D888-309D-ADE1-84AA0CB24FE9}=MsiExec.exe /X{725
9BDDA-D888-309D-ADE1-84AA0CB24FE9}
### Microsoft Visual Studio Tools for Applications 2012 x86 ???? - ??????? - (
09) 07-2014

[Applications] :HKLM {CF06B8C4-F6FC-3A4B-ADD0-04A1CAC3DD86}=MsiExec.exe /X{CF0


6B8C4-F6FC-3A4B-ADD0-04A1CAC3DD86}
### Microsoft Visual Studio Tools for Applications 2012 x86 Hosting Support (09) 07-2014
[Applications] :HKLM _{5CB73140-806C-42C6-A05A-1AFD0E92DEB5}=c:\Program Files\
Corel\CorelDRAW Graphics Suite X7\Setup\SetupARP.exe /arp
### CorelDRAW Graphics Suite X7 (64-Bit) - (09) 07-2014
[Applications] :HKLM {5CB73140-806C-42C6-A05A-1AFD0E92DEB5}
### CorelDRAW Graphics Suite X7 - Setup Files (x64) - (09) 07-2014
[Applications] :HKLM {90F60409-7000-11D3-8CFE-0150048383C9}=MsiExec.exe /I{90F
60409-7000-11D3-8CFE-0150048383C9}
### Microsoft Visual Basic for Applications 7.1 (x64) English - (09) 07-2014
[Applications] :HKLM {90120064-0070-0000-0000-4000000FF1CE}=MsiExec.exe /I{901
20064-0070-0000-0000-4000000FF1CE}
### Microsoft Visual Basic for Applications 7.1 (x64) - (09) 07-2014
[Applications] :HKLM {3B4AE1A9-C026-4D08-8004-DA9A85A411A4}=MsiExec.exe /I{3B4
AE1A9-C026-4D08-8004-DA9A85A411A4}
### Corel Graphics - Windows Shell Extension 32 Bit - (09) 07-2014
[Applications] :HKLM _{4DC318F5-1640-4417-A218-912ED9905FAA}=c:\Program Files\
Common Files\Corel\Shared\Shell Extension\x64\ShellUninst.exe -ProductCode {4DC3
18F5-1640-4417-A218-912ED9905FAA} -arp
### Corel Graphics - Windows Shell Extension - (09) 07-2014
[Applications] :HKLM {4DC318F5-1640-4417-A218-912ED9905FAA}=MsiExec.exe /X{4DC
318F5-1640-4417-A218-912ED9905FAA}
### Corel Graphics - Windows Shell Extension - (09) 07-2014
[Applications] :HKLM {EF44BCCD-13F9-4974-862C-CCFAF43EE082}=MsiExec.exe /I{EF4
4BCCD-13F9-4974-862C-CCFAF43EE082}
### CorelDRAW Graphics Suite X7 - IPM Content (x64) - (09) 07-2014
[Applications] :HKLM {1A73168F-5983-46A6-AAAB-FD83BC231E02}
### CorelDRAW Graphics Suite X7 - Photozoom Plugin (x64) - (09) 07-2014
[Applications] :HKLM {C57EDB5A-AC8E-4E03-9F1A-DC013A2BB9B2}
### CorelDRAW Graphics Suite X7 - Redist (x64) - (09) 07-2014
[Applications] :HKLM {BD44409B-A691-4B97-B33D-F07E1DE791F3}=MsiExec.exe /I{BD4
4409B-A691-4B97-B33D-F07E1DE791F3}
### Prezi - (09) 07-2014
[Applications] :HKLM {67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1="C:\Program Fi
les\VS Revo Group\Revo Uninstaller Pro\unins000.exe"
### Revo Uninstaller Pro 2.5.9 - (08) 07-2014
[Applications] :HKLM {2cd951f7-c271-4fad-8cef-986660a71900}="C:\ProgramData\Pa
ckage Cache\{2cd951f7-c271-4fad-8cef-986660a71900}\youtube-dlm_Setup_product-web
site_en-US.exe" /uninstall
### Free YouTube Download Manager - (05) 07-2014
[Applications] :HKLM {11F475A8-A7F9-4519-814B-E2949AD5689C}=MsiExec.exe /X{11F
475A8-A7F9-4519-814B-E2949AD5689C}
### Free YouTube Download Manager - (05) 07-2014
[Applications] :HKLM {5A68A656-979F-4168-8795-E2E368AA4DC2}=MsiExec.exe /I{5A6
8A656-979F-4168-8795-E2E368AA4DC2}
### iTunes - (03) 07-2014
[Applications] :HKLM Canon LBP2900=C:\Program Files\Canon\PrnUninstall\Canon L
BP2900\CNAB4UND.EXE
### Canon LBP2900 - (03) 07-2014
[Applications] :HKLM {26A24AE4-039D-4CA4-87B4-2F03217060FB}
### - (17) 06-2014
[Applications] :HKLM Wireshark="C:\Program Files\Wireshark\uninstall.exe"
### Wireshark 1.10.7 (64-bit) - (12) 06-2014
[Applications] :HKLM WinPcapInst=C:\Program Files (x86)\WinPcap\uninstall.exe
### WinPcap 4.1.3 - (12) 06-2014
[Applications] :HKLM {1D8E6291-B0D5-35EC-8441-6616F567A0F7}=MsiExec.exe /X{1D8
E6291-B0D5-35EC-8441-6616F567A0F7}
### Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 - (12) 06-2014

[Applications] :HKLM MPlayer2


### - (11) 06-2014
[Applications] :HKLM {1AD147D0-BE0E-3D6C-AC11-64F6DC4163F1}=MsiExec.exe /X{1AD
147D0-BE0E-3D6C-AC11-64F6DC4163F1}
### Microsoft .NET Framework 4.5 - (07) 06-2014
[Applications] :HKLM {92FB6C44-E685-45AD-9B20-CADF4CABA132}.KB2861208=c:\Windo
ws\Microsoft.NET\Framework64\v4.0.30319\SetupCache\setup.exe /uninstallpatch {6A
F12FE8-C359-3748-BDF6-B437C0A42154}
### Security Update for Microsoft .NET Framework 4.5 (KB2861208) - (07) 06-201
4
[Applications] :HKLM {92FB6C44-E685-45AD-9B20-CADF4CABA132}.KB2742613=c:\Windo
ws\Microsoft.NET\Framework64\v4.0.30319\SetupCache\setup.exe /uninstallpatch {36
E5C79E-06D3-32C3-9251-D284B9F3F7E7}
### Security Update for Microsoft .NET Framework 4.5 (KB2742613) - (07) 06-201
4
[Applications] :HKLM {92FB6C44-E685-45AD-9B20-CADF4CABA132}.KB2901118=c:\Windo
ws\Microsoft.NET\Framework64\v4.0.30319\SetupCache\setup.exe /uninstallpatch {D0
52AECC-7A45-3B76-B62C-F5093799DF8D}
### Security Update for Microsoft .NET Framework 4.5 (KB2901118) - (07) 06-201
4
[Applications] :HKLM {92FB6C44-E685-45AD-9B20-CADF4CABA132}.KB2840642v2=c:\Win
dows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\setup.exe /uninstallpatch {
4F658047-A12E-38D9-8EA9-D941E4A84B7D}
### Security Update for Microsoft .NET Framework 4.5 (KB2840642v2) - (07) 06-2
014
[Applications] :HKLM {92FB6C44-E685-45AD-9B20-CADF4CABA132}.KB2737083=c:\Windo
ws\Microsoft.NET\Framework64\v4.0.30319\SetupCache\setup.exe /uninstallpatch {00
909A54-CC11-3F00-9279-3CE090432A91}
### Security Update for Microsoft .NET Framework 4.5 (KB2737083) - (07) 06-201
4
[Applications] :HKLM {92FB6C44-E685-45AD-9B20-CADF4CABA132}.KB2789648=c:\Windo
ws\Microsoft.NET\Framework64\v4.0.30319\SetupCache\setup.exe /uninstallpatch {69
8F9EB6-6753-318E-8615-53D77414313F}
### Security Update for Microsoft .NET Framework 4.5 (KB2789648) - (07) 06-201
4
[Applications] :HKLM {92FB6C44-E685-45AD-9B20-CADF4CABA132}.KB2931368=C:\Windo
ws\Microsoft.NET\Framework64\v4.0.30319\SetupCache\setup.exe /uninstallpatch {59
9EC629-2679-30CE-B28B-7432EF5FC126}
### Security Update for Microsoft .NET Framework 4.5 (KB2931368) - (07) 06-201
4
[Applications] :HKLM {92FB6C44-E685-45AD-9B20-CADF4CABA132}.KB2898864=c:\Windo
ws\Microsoft.NET\Framework64\v4.0.30319\SetupCache\setup.exe /uninstallpatch {FD
9140E9-6192-38CC-BCF6-4869B2AEBBCD}
### Security Update for Microsoft .NET Framework 4.5 (KB2898864) - (07) 06-201
4
[Applications] :HKLM Network Magic Pro Edition=C:\Program Files (x86)\Network
Magic Pro Edition\uninst.exe
### Network Magic Pro Edition 5.5 - (28) 05-2014
[Applications] :HKLM {CE48BAE6-CDEF-4EB2-9AB0-67018F25C7C4}_is1="C:\Program Fi
les (x86)\LAN Speed Test\unins000.exe"
### LAN Speed Test - (27) 05-2014
[Applications] :HKLM {CD95F661-A5C4-44F5-A6AA-ECDD91C240E3}=MsiExec.exe /X{CD9
5F661-A5C4-44F5-A6AA-ECDD91C240E3}
### WinZip 18.5 - (24) 05-2014
[Applications] :HKLM {778bfcc3-197f-4e87-8459-0642cfd8cc05}="C:\ProgramData\Pa
ckage Cache\{778bfcc3-197f-4e87-8459-0642cfd8cc05}\BoxSyncSetup.exe" /uninstall
### Box Sync - (22) 05-2014
[Applications] :HKLM {111EE7DF-FC45-40C7-98A7-753AC46B12FB}=MsiExec.exe /I{111
EE7DF-FC45-40C7-98A7-753AC46B12FB}
### QuickTime 7 - (19) 05-2014

[Applications] :HKLM {5737101A-27C4-408A-8A57-D1DC78DF84B4}=MsiExec.exe /I{573


7101A-27C4-408A-8A57-D1DC78DF84B4}
### 64 Bit HP CIO Components Installer - (10) 05-2014
[Applications] :HKLM Unlocker=C:\Program Files (x86)\Unlocker\uninst.exe
### Unlocker 1.9.1 - (22) 04-2014
[Applications] :HKLM Excel/Xls to Pdf Converter_is1="C:\Program Files (x86)\Ex
cel-Xls to Pdf Converter\unins000.exe"
### Excel/Xls to Pdf Converter 5.8 - (14) 04-2014
[Applications] :HKLM VB Decompiler Lite_is1="C:\Program Files (x86)\VB Decompi
ler Lite\unins000.exe"
### VB Decompiler Lite - (12) 04-2014
[Applications] :HKLM {232EB8E6-9B8C-4785-A994-B1E5E2376CDC}=MsiExec.exe /X{232
EB8E6-9B8C-4785-A994-B1E5E2376CDC}
### WD SmartWare - (09) 04-2014
[Applications] :HKLM ImTOO DVD Audio Ripper=C:\Program Files (x86)\ImTOO\DVD A
udio Ripper\Uninstall.exe
### ImTOO DVD Audio Ripper - (07) 04-2014
[Applications] :HKLM {FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}=MsiExec.exe /X{FF6
6E9F6-83E7-3A3E-AF14-8DE9A809A6A4}
### Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 - (07) 04-2014
[Applications] :HKLM camcodec="C:\Windows\Installer\CamStudioCodec_Uninstall.e
xe"
### CamStudio Lossless Codec v1.5 - (30) 03-2014
[Applications] :HKLM {04B83666-3A62-452B-85D3-70F8117F2329}_is1="C:\Program Fi
les\CamStudio 2.7\unins000.exe"
### CamStudio 2.7.2 - (30) 03-2014
[Applications] :HKLM {1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB982573
### - (15) 03-2014
[Applications] :HKLM {1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2467173
### - (15) 03-2014
[Applications] :HKLM {1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2151757
### - (15) 03-2014
[Applications] :HKLM {F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2151757
### - (15) 03-2014
[Applications] :HKLM {F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2467173
### - (15) 03-2014
[Applications] :HKLM {F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB982573
### - (15) 03-2014
[Applications] :HKLM Raise Data Recovery for FAT_is1="C:\Program Files (x86)\D
ata Recovery\unins001.exe"
### Raise Data Recovery for FAT, version 5.12.1 - (07) 03-2014
[Applications] :HKLM Raise Data Recovery for NTFS_is1="C:\Program Files (x86)\
Data Recovery\unins000.exe"
### Raise Data Recovery for NTFS, version 5.12.1 - (07) 03-2014
[Applications] :HKLM MiniTool Power Data Recovery_is1="C:\Program Files (x86)\
PowerDataRecovery\unins000.exe"
### MiniTool Power Data Recovery - (07) 03-2014
[Applications] :HKLM Dev-C++=C:\Program Files (x86)\Dev-Cpp\uninstall.exe
### Dev-C++ - (04) 03-2014
[Applications] :HKLM OfficeRecovery 2013 Ultimate_is1="C:\Program Files (x86)\
OfficeRecovery 2013 Ultimate\unins000.exe"
### OfficeRecovery 2013 Ultimate v13.0.40450 RU-BOARD Edition - (18) 02-2014
[Applications] :HKLM {3C73C38E-ADFB-461E-912A-73FA9A30B90F}_is1="C:\Users\admi
n\AppData\Local\S2 Recovery Tools for Microsoft Excel\unins000.exe"
### S2 Recovery Tools for Microsoft Excel version 4.0.0 - (18) 02-2014
[Applications] :HKLM {B805B869-3A82-47EF-9B58-AAEE7E913F94}=MsiExec.exe /I{B80
5B869-3A82-47EF-9B58-AAEE7E913F94}
### DameWare Mini Remote Control 9.0 - (11) 02-2014
[Applications] :HKLM {8220EEFE-38CD-377E-8595-13398D740ACE}=MsiExec.exe /X{822
0EEFE-38CD-377E-8595-13398D740ACE}

### Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 - (11) 02-201
4
[Applications] :HKLM Total Video Converter 3.71_is1="C:\Program Files (x86)\To
tal Video Converter\unins000.exe"
### Total Video Converter 3.71 100812 - (04) 02-2014
[Applications] :HKLM {A19293EE-76AB-475B-949A-5A90DCC960DE}=C:\Program Files (
x86)\InstallShield Installation Information\{A19293EE-76AB-475B-949A-5A90DCC960D
E}\setup.exe -runfromtemp -l0x0009 -removeonly
### iVMS-4000(v2.0) - (03) 02-2014
[Applications] :HKLM {AE0F62A7-A1A2-407F-9F4C-48939BD9AD8D}=MsiExec.exe /X{AE0
F62A7-A1A2-407F-9F4C-48939BD9AD8D}
### tools-winPre2k - (28) 01-2014
[Applications] :HKLM {FFD9383C-01D5-4897-A954-43AF599AED30}=MsiExec.exe /X{FFD
9383C-01D5-4897-A954-43AF599AED30}
### tools-windows - (28) 01-2014
[Applications] :HKLM {AB1C87CB-1807-4CF0-B4C2-CEE14C18CDB4}=MsiExec.exe /X{AB1
C87CB-1807-4CF0-B4C2-CEE14C18CDB4}
### tools-solaris - (28) 01-2014
[Applications] :HKLM {197597A7-AD33-4898-9D8E-73066818B464}=MsiExec.exe /X{197
597A7-AD33-4898-9D8E-73066818B464}
### tools-netware - (28) 01-2014
[Applications] :HKLM {D102611A-6466-4101-A51D-51069303AC65}=MsiExec.exe /X{D10
2611A-6466-4101-A51D-51069303AC65}
### tools-linux - (28) 01-2014
[Applications] :HKLM {003BFBBD-6C67-419E-A24D-0DCAFC3A5249}=MsiExec.exe /X{003
BFBBD-6C67-419E-A24D-0DCAFC3A5249}
### tools-freebsd - (28) 01-2014
[Applications] :HKLM VMware_Workstation="C:\ProgramData\VMware\VMware Workstat
ion\Uninstaller\\uninstall.exe" -x -S "C:\ProgramData\VMware\VMware Workstation\
Uninstaller\"
### VMware Workstation - (28) 01-2014
[Applications] :HKLM {0D94F75A-0EA6-4951-B3AF-B145FA9E05C6}
### - (28) 01-2014
[Applications] :HKLM {0D94F75A-0EA6-4951-B3AF-B145FA9E05C6}=MsiExec.exe /I{0D9
4F75A-0EA6-4951-B3AF-B145FA9E05C6}
### VMware Workstation - (28) 01-2014
[Applications] :HKLM {4B6C7001-C7D6-3710-913E-5BC23FCE91E6}=MsiExec.exe /X{4B6
C7001-C7D6-3710-913E-5BC23FCE91E6}
### Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 - (28) 01-2
014
[Applications] :HKLM {1F1C2DFC-2D24-3E06-BCB8-725134ADF989}=MsiExec.exe /X{1F1
C2DFC-2D24-3E06-BCB8-725134ADF989}
### Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 - (28) 01-2
014
[Applications] :HKLM {ECD07791-9A98-4E16-B350-0D31809E5EBF}=MsiExec.exe /X{ECD
07791-9A98-4E16-B350-0D31809E5EBF}
### Advanced Office Password Recovery - (27) 01-2014
[Applications] :HKLM {6a01f86f-4959-4e83-8ed9-78b120a9d70f}_is1="C:\Program Fi
les (x86)\SysTools XLSX Recovery\unins000.exe"
### SysTools XLSX Recovery v1.0 - (24) 01-2014
[Applications] :HKLM {BEE8AFD4-907F-4BD5-B2E9-6606291415E8}_is1="C:\Program Fi
les (x86)\FREE Word and Excel password recovery Wizard\unins000.exe"
### FREE Word and Excel password recovery Wizard version 2.1.15 - (24) 01-2014
[Applications] :HKLM Daossoft Excel Password Recovery=C:\Program Files (x86)\D
aossoft Excel Password Recovery\uninst.exe
### Daossoft Excel Password Recovery 7.0.0.1 - (24) 01-2014
[Applications] :HKLM MiniMagics
### MiniMagics - (21) 01-2014
[Applications] :HKLM {78A136F4-6FC0-403E-8BFF-953063BD122C}=MsiExec.exe /I{78A
136F4-6FC0-403E-8BFF-953063BD122C}

### Magics 13.0 64bit - (21) 01-2014


[Applications] :HKLM WinHTTrack Website Copier_is1="C:\Program Files\WinHTTrac
k\unins000.exe"
### WinHTTrack Website Copier 3.47-27 (x64) - (17) 01-2014
[Applications] :HKLM 6417b678-607f-4566-b657-61c33479f281=C:\PROGRA~3\INSTAL~1
\{EEFC0~1\Setup.exe /remove /q0
### - (15) 01-2014
[Applications] :HKLM {23170F69-40C1-2702-0920-000001000000}=MsiExec.exe /I{231
70F69-40C1-2702-0920-000001000000}
### 7-Zip 9.20 (x64 edition) - (09) 01-2014
[Applications] :HKLM {8C775E70-A791-4DA8-BCC3-6AB7136F4484}=MsiExec.exe /I{8C7
75E70-A791-4DA8-BCC3-6AB7136F4484}
### Visual Studio 2012 x64 Redistributables - (08) 01-2014
[Applications] :HKLM {98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}=MsiExec.exe /I{98E
FF19A-30AB-4E4B-B943-F06B1C63EBF8}
### Visual Studio 2012 x86 Redistributables - (08) 01-2014
[Applications] :HKLM {CEFA48AF-74CA-4298-A4B2-0646D5E37CA7}=MsiExec.exe /I{CEF
A48AF-74CA-4298-A4B2-0646D5E37CA7}
### AX88772A & AX88772 Windows 7 Drivers - (08) 01-2014
[Applications] :HKLM InstallShield_{CEFA48AF-74CA-4298-A4B2-0646D5E37CA7}="C:\
Program Files (x86)\InstallShield Installation Information\{CEFA48AF-74CA-4298-A
4B2-0646D5E37CA7}\setup.exe" -runfromtemp -l0x0409 -removeonly
### AX88772A & AX88772 Windows 7 Drivers - (08) 01-2014
[Applications] :HKLM InstallShield Uninstall Information
### - (08) 01-2014
[Applications] :HKLM 1DA6411947B95CF8FEBE86577ABAA0E92DDD1CA0=C:\PROGRA~1\DIFX
\8730326CFC0D32D8\DPInst.exe /u C:\Windows\System32\DriverStore\FileRepository\a
x88772b.inf_amd64_neutral_7703348531d0f6c7\ax88772b.inf
### Windows Driver Package - ASIX (AX88772B) Net (05/21/2010 5.14.3.0) - (08)
01-2014
[Applications] :HKLM {399C37FB-08AF-493B-BFED-20FBD85EDF7F}=C:\Program Files (
x86)\InstallShield Installation Information\{399C37FB-08AF-493B-BFED-20FBD85EDF7
F}\setup.exe -runfromtemp -l0x0009 -removeonly
### USB Video Device - (04) 01-2014
[Applications] :HKLM 7-Zip="C:\Program Files (x86)\7-Zip\Uninstall.exe"
### 7-Zip 9.20 - (03) 01-2014
[Applications] :HKLM Shipra's_Dictionary_1.0=C:\Windows\iun506.exe C:\Program
Files (x86)\Shipra's Dictionary\irunin.ini
### Shipra's Dictionary 1.0 - (03) 01-2014
[Applications] :HKLM Duplicate Files Finder="C:\Program Files (x86)\Duplicate
Files Finder\uninstall.exe"
### Duplicate Files Finder - (31) 12-2013
[Applications] :HKLM DXM_Runtime
### - (30) 12-2013
[Applications] :HKLM {92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033=C:\Windows\
Microsoft.NET\Framework64\v4.0.30319\SetupCache\\Setup.exe /repair /x86 /x64
### Microsoft .NET Framework 4.5 - (30) 12-2013
[Applications] :HKLM WordWeb=C:\Program Files (x86)\WordWeb\uninst.exe
### WordWeb Pro - (30) 12-2013
[Applications] :HKLM {8833FFB6-5B0C-4764-81AA-06DFEED9A476}=C:\Program Files (
x86)\InstallShield Installation Information\{8833FFB6-5B0C-4764-81AA-06DFEED9A47
6}\setup.exe -runfromtemp -removeonly
### Realtek Ethernet Controller Driver - (30) 12-2013
[Applications] :HKLM {7699B723-9718-41DE-8C18-549F341C02CE}=MsiExec.exe /I{769
9B723-9718-41DE-8C18-549F341C02CE}
### Crystal Reports - (01) 12-2013
[Applications] :HKLM ST6UNST #1=C:\WINDOWS\st6unst.exe -n "C:\Program Files (x
86)\JewelArt\ST6UNST.LOG"
### AStar - (01) 12-2013
[Applications] :HKLM {90120000-0030-0000-0000-0000000FF1CE}=MsiExec.exe /X{901

20000-0030-0000-0000-0000000FF1CE}
### Microsoft Office Enterprise 2007 - (01) 12-2013
[Applications] :HKLM ENTERPRISE="C:\Program Files (x86)\Common Files\Microsoft
Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall ENTERPRISE /dll O
SETUP.DLL
### Microsoft Office Enterprise 2007 - (01) 12-2013
[Applications] :HKLM {90120000-002A-0000-1000-0000000FF1CE}=MsiExec.exe /X{901
20000-002A-0000-1000-0000000FF1CE}
### Microsoft Office Office 64-bit Components 2007 - (01) 12-2013
[Applications] :HKLM {90120000-00A1-0409-0000-0000000FF1CE}=MsiExec.exe /X{901
20000-00A1-0409-0000-0000000FF1CE}
### Microsoft Office OneNote MUI (English) 2007 - (01) 12-2013
[Applications] :HKLM {90120000-0117-0409-0000-0000000FF1CE}=MsiExec.exe /X{901
20000-0117-0409-0000-0000000FF1CE}
### Microsoft Office Access Setup Metadata MUI (English) 2007 - (01) 12-2013
[Applications] :HKLM {90120000-0015-0409-0000-0000000FF1CE}=MsiExec.exe /X{901
20000-0015-0409-0000-0000000FF1CE}
### Microsoft Office Access MUI (English) 2007 - (01) 12-2013
[Applications] :HKLM {90120000-001B-0409-0000-0000000FF1CE}=MsiExec.exe /X{901
20000-001B-0409-0000-0000000FF1CE}
### Microsoft Office Word MUI (English) 2007 - (01) 12-2013
[Applications] :HKLM {90120000-0019-0409-0000-0000000FF1CE}=MsiExec.exe /X{901
20000-0019-0409-0000-0000000FF1CE}
### Microsoft Office Publisher MUI (English) 2007 - (01) 12-2013
[Applications] :HKLM {90120000-002C-0409-0000-0000000FF1CE}=MsiExec.exe /X{901
20000-002C-0409-0000-0000000FF1CE}
### Microsoft Office Proofing (English) 2007 - (01) 12-2013
[Applications] :HKLM {90120000-001F-0409-0000-0000000FF1CE}=MsiExec.exe /X{901
20000-001F-0409-0000-0000000FF1CE}
### Microsoft Office Proof (English) 2007 - (01) 12-2013
[Applications] :HKLM {90120000-001F-040C-0000-0000000FF1CE}=MsiExec.exe /X{901
20000-001F-040C-0000-0000000FF1CE}
### Microsoft Office Proof (French) 2007 - (01) 12-2013
[Applications] :HKLM {90120000-001F-0C0A-0000-0000000FF1CE}=MsiExec.exe /X{901
20000-001F-0C0A-0000-0000000FF1CE}
### Microsoft Office Proof (Spanish) 2007 - (01) 12-2013
[Applications] :HKLM {90120000-0116-0409-1000-0000000FF1CE}=MsiExec.exe /X{901
20000-0116-0409-1000-0000000FF1CE}
### Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007 - (01) 12
-2013
[Applications] :HKLM {90120000-002A-0409-1000-0000000FF1CE}=MsiExec.exe /X{901
20000-002A-0409-1000-0000000FF1CE}
### Microsoft Office Shared 64-bit MUI (English) 2007 - (01) 12-2013
[Applications] :HKLM {90120000-0044-0409-0000-0000000FF1CE}=MsiExec.exe /X{901
20000-0044-0409-0000-0000000FF1CE}
### Microsoft Office InfoPath MUI (English) 2007 - (01) 12-2013
[Applications] :HKLM {90120000-0114-0409-0000-0000000FF1CE}=MsiExec.exe /X{901
20000-0114-0409-0000-0000000FF1CE}
### Microsoft Office Groove Setup Metadata MUI (English) 2007 - (01) 12-2013
[Applications] :HKLM {90120000-00BA-0409-0000-0000000FF1CE}=MsiExec.exe /X{901
20000-00BA-0409-0000-0000000FF1CE}
### Microsoft Office Groove MUI (English) 2007 - (01) 12-2013
[Applications] :HKLM {90120000-0018-0409-0000-0000000FF1CE}=MsiExec.exe /X{901
20000-0018-0409-0000-0000000FF1CE}
### Microsoft Office PowerPoint MUI (English) 2007 - (01) 12-2013
[Applications] :HKLM {90120000-001A-0409-0000-0000000FF1CE}=MsiExec.exe /X{901
20000-001A-0409-0000-0000000FF1CE}
### Microsoft Office Outlook MUI (English) 2007 - (01) 12-2013
[Applications] :HKLM {90120000-0016-0409-0000-0000000FF1CE}=MsiExec.exe /X{901
20000-0016-0409-0000-0000000FF1CE}

### Microsoft Office Excel MUI (English) 2007 - (01) 12-2013


[Applications] :HKLM {90120000-0115-0409-0000-0000000FF1CE}=MsiExec.exe /X{901
20000-0115-0409-0000-0000000FF1CE}
### Microsoft Office Shared Setup Metadata MUI (English) 2007 - (01) 12-2013
[Applications] :HKLM {90120000-006E-0409-0000-0000000FF1CE}=MsiExec.exe /X{901
20000-006E-0409-0000-0000000FF1CE}
### Microsoft Office Shared MUI (English) 2007 - (01) 12-2013
[Applications] :HKLM {6AA003BF-73E5-4911-ADB7-71DD5674DDD4}=MsiExec.exe /I{6AA
003BF-73E5-4911-ADB7-71DD5674DDD4}
### Oracle Data Provider for .NET Help - (01) 12-2013
[Applications] :HKLM IE4Data
### - (14) 07-2009
[Applications] :HKLM IE40
### - (14) 07-2009
[Applications] :HKLM IEData
### - (14) 07-2009
[Applications] :HKLM IE5BAKEX
### - (14) 07-2009
[Applications] :HKLM Connection Manager
### - (14) 07-2009
[Applications] :HKLM AddressBook
### - (14) 07-2009
[Applications] :HKLM Fontcore
### - (14) 07-2009
[Applications] :HKLM DirectDrawEx
### - (14) 07-2009
[Applications] :HKLM MobileOptionPack
### - (14) 07-2009
[Applications] :HKLM SchedulingAgent
### - (14) 07-2009
[Applications] :HKLM WIC
### - (14) 07-2009
[Applications] :HKLM Connection Manager
### - (14) 07-2009
[Applications] :HKLM DirectDrawEx
### - (14) 07-2009
[Applications] :HKLM AddressBook
### - (14) 07-2009
[Applications] :HKLM SchedulingAgent
### - (14) 07-2009
[Applications] :HKLM WIC
### - (14) 07-2009
[Applications] :HKLM Fontcore
### - (14) 07-2009
[Applications] :HKLM IE5BAKEX
### - (14) 07-2009
[Applications] :HKLM IEData
### - (14) 07-2009
[Applications] :HKLM IE4Data
### - (14) 07-2009
[Applications] :HKLM IE40
### - (14) 07-2009
[Applications] :HKLM MobileOptionPack
### - (14) 07-2009
[MD5]
[1264F787E46DC572FA274CA09B446E01][1
44344
]C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
[786DD1892B553EFE5A004AC39775C851][1
2210608
]C:\PROGRA~2\MICROS~1\OFFICE12\GR469A~1.DLL
[BD25E3537B54C1BFF40335992B3686FD][1
222512

]C:\PROGRA~2\MICROS~1\OFFICE12\GRA32A~1.DLL
[FC3396B88F31636817D31F592A0DA848][1
274744
]C:\PROGRA~2\MICROS~1\OFFICE12\OIS.EXE
[7FC19DA1DC70C78D2FBD7A1D10942051][1
40424
]C:\PROGRA~2\MICROS~1\OFFICE12\REFIEBAR.DLL
[4289E488905354E56002E60F211ACE3A][2
86016
]C:\PROGRAM FILES (X86)\7-ZIP\7-ZIP.DLL
[EDFCA3682BCFE788BFCABF4D7E22805A][2
577536
]C:\PROGRAM FILES (X86)\ADOBE\ACROBAT 7.0\ACROBAT ELEMENTS\CONT
EXTMENU.DLL
[1BA6D822A6BA2402BC5DF7F65955D3A8][2
225280
]C:\PROGRAM FILES (X86)\ADOBE\ACROBAT 7.0\ACROBAT\ACROIEFAVCLIE
NT.DLL
[42729C3DE75A7A51FC6F9EF6546C9199][1
63136
]C:\PROGRAM FILES (X86)\ADOBE\ACROBAT 7.0\ACTIVEX\ACROIEHELPER.
DLL
[FBD06A45DB2D543EFD932768029EC5F2][2
483328
]C:\PROGRAM FILES (X86)\ADOBE\ACROBAT 7.0\DISTILLR\ACROTRAY.EXE
[6D182C31ACF16213407F2768F1107FE3][2
69632
]C:\PROGRAM FILES (X86)\COMMON FILES\ADOBE SYSTEMS SHARED\SERVI
CE\ADOBELMSVC.EXE
[4EAF6F8F0B3BE33A0E3877EB7FFD48D4][1
1085656 7224E3586E6576C071A6141F307
3A831734B08D4
]C:\PROGRAM FILES (X86)\COMMON FILES\ADOBE\ARM\1.0\ADOBEARM.EXE
[F2CEEE9ABBCEF207ACB103215AC28BC2][1
82128 54684ACD69CF8CC3649993A5DB2
953330E5601F4
]C:\PROGRAM FILES (X86)\COMMON FILES\ADOBE\ARM\1.0\ARMSVC.EXE
[320681DF28D82CDCA7E3EED0846625DB][1
444904
]C:\PROGRAM FILES (X86)\COMMON FILES\ADOBE\OOBE\PDAPP\UWA\UPDAT
ERSTARTUPUTILITY.EXE
[B17404D208C4B20518592AA43B81E04B][1
927256 C532678DA39D5C3E8BD8D042E2E
755DAAE5DBF18
]C:\PROGRAM FILES (X86)\COMMON FILES\JAVA\JAVA UPDATE\JUCHECK.E
XE
[C9B67BCB8E384064A8C2263740B0C437][1
595480 D895994F5DA9D4827389A9A9113
3D11A5F9CC9A7
]C:\PROGRAM FILES (X86)\COMMON FILES\JAVA\JAVA UPDATE\JUSCHED.E
XE
[8669BE94F63944E4F899C3950B520241][1
1045256
]C:\PROGRAM FILES (X86)\COMMON FILES\MACROVISION SHARED\FLEXNET
PUBLISHER\FNPLICENSINGSERVICE.EXE
[14C405B807A341B60683FE1D5ED65380][1
255256 AA2F0010598E131AEA6F721A0E6
B2B60BB8EB51E
]C:\PROGRAM FILES (X86)\COMMON FILES\MATERIALISE\LICENSEFILES\L
ICSRV50.EXE
[9E7370CC3D6A43942433F85D0E2BBDD8][1
873216
]C:\PROGRAM FILES (X86)\COMMON FILES\MICROSOFT SHARED\HELP\HXDS
.DLL
[84DE1DD996B48B05ACE31AD015FA108A][1
441136
]C:\PROGRAM FILES (X86)\COMMON FILES\MICROSOFT SHARED\OFFICE12\
ODSERV.EXE
[5A432A042DAE460ABE7199B758E8606C][1
145184
]C:\PROGRAM FILES (X86)\COMMON FILES\MICROSOFT SHARED\SOURCE EN
GINE\OSE.EXE
[FAEAFD0BEBFB2B5E938B29C8A155B807][1
2487192
]C:\PROGRAM FILES (X86)\COMMON FILES\NERO\NEROSHELLEXT\NEROSHEL
LEXT.DLL
[DE77A8DA45F91629EB5FC157FA00C08A][1
904248
]C:\PROGRAM FILES (X86)\COMMON FILES\VMWARE\USB\VMWARE-USBARBIT
RATOR64.EXE
[42E4E281D9646F15E5C4D0CFD61CE684][1
2020192
]C:\PROGRAM FILES (X86)\COMMON FILES\WONDERSHARE\WONDERSHARE HE
LPER COMPACT\WSHELPER.EXE
[275F70AF9857755E0440137FB3A6D2C8][2
6983168
]C:\PROGRAM FILES (X86)\FREE DOWNLOAD MANAGER\FDM.EXE

[E65C21C50283C47852D7A3B677CFA00E][2
365056 CCD5F6BC196EB1DD6CB886A5D5C
5E55F61BE6C95
]C:\PROGRAM FILES (X86)\FREE DOWNLOAD MANAGER\IEFDM2.DLL
[51667022FACBD1AA611373DA16C98533][1
748872 A1E2B2EC38DACA805AE0E963E96
D4E34916DD179
]C:\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE
[329D828599BE8859DDC81F866019B2F0][1
2511384
]C:\PROGRAM FILES (X86)\GOOGLE\GOOGLE INPUT TOOLS\GOOGLEINPUTHA
NDLER.EXE
[78AF384F14F01009EFB10A31AFEC51F4][1
164888
]C:\PROGRAM FILES (X86)\GOOGLE\GOOGLE INPUT TOOLS\GOOGLEINPUTSE
RVICE.EXE
[88FBBB1C601A6BC42054E57C2897FA45][1
144200 E025A9721B37725E6DC6E069A93
35239437B3E7C
]C:\PROGRAM FILES (X86)\GOOGLE\UPDATE\GOOGLEUPDATE.EXE
[328E65035DE1D2C1206B4F94AAFC1DB7][1
118424 76AE3743F21954D176FFC013F9D
62A4AE0CBA76C
]C:\PROGRAM FILES (X86)\INTEL DRIVER UPDATE UTILITY\SUR\SURSVC.
EXE
[E7859BA062DB5E23C6DD34AD66B09F50][1
326168
]C:\PROGRAM FILES (X86)\INTEL\INTEL(R) MANAGEMENT ENGINE COMPON
ENTS\LMS\LMS.EXE
[E91F8AFBD7FB96C94B266579D6BFA77A][1
2656280
]C:\PROGRAM FILES (X86)\INTEL\INTEL(R) MANAGEMENT ENGINE COMPON
ENTS\UNS\UNS.EXE
[D2E3E6D94A9E1CFA1561D9C748136FD0][1
152392
]C:\PROGRAM FILES (X86)\ITUNES\ITUNESHELPER.EXE
[56748C769C10A379719A2C9D93AFEA6B][1
173120 3128CD586EC9739AAF44F5F6DEF
0C6F8289F3829
]C:\PROGRAM FILES (X86)\JAVA\JRE1.8.0_77\BIN\JP2SSV.DLL
[B7483C4236E990A3C7F5A3ABEE5C1417][1
462400 D2FF9AC6537EB6FC0C9917E769B
2471F3BFF56CF
]C:\PROGRAM FILES (X86)\JAVA\JRE1.8.0_77\BIN\SSV.DLL
[32E3661326D84A06C4E9380A310B01B7][2
31016 5781B226EA791711FE7615AB75C
C304CEF7C65EA
]C:\PROGRAM FILES (X86)\MICROSOFT OFFICE\OFFICE12\GROOVEMONITOR
.EXE
[F7CEB1E5F0000FDEEE04B046BBDE1D4E][1
377000 D25AD5468157CA05C2BB30D7D5C
EE745ADDB8A88
]C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\FIREFOX.EXE
[31A94358EF55B871B1B81ADE3ACEBFF9][1
148136 C7631EAF245DB2C86ABE09C8C62
C07CE433061A6
]C:\PROGRAM FILES (X86)\MOZILLA MAINTENANCE SERVICE\MAINTENANCE
SERVICE.EXE
[AE2A8DC5C08AE6A198D5EC47561C0DEF][1
336952
]C:\PROGRAM FILES (X86)\POWERISO\PWRISOVM.EXE
[08E7173D1B74095335052459200CB1EA][2
421888
]C:\PROGRAM FILES (X86)\QUICKTIME\QTTASK.EXE
[E7062DBD907E0C5CEEB5ABDAF07E6B32][1
1646056
]C:\PROGRAM FILES (X86)\ROSETTASTONELTDSERVICES\ROSETTASTONEDAE
MON.EXE
[D3F78E38C39AB0E7358735717FB52EAE][1
1563440
]C:\PROGRAM FILES (X86)\SAMSUNG\KIES\KIES.EXE
[EB1B7B961090A4AF33FC297516B88FAE][1
310064
]C:\PROGRAM FILES (X86)\SAMSUNG\KIES\KIESTRAYAGENT.EXE
[
-2][0
-1
]C:\PROGRAM FILES (X86)\SAVEPASS 1.1\6012184B-F747-477B-804F-54
428B83A7EF-5.EXE
[89CACBC5A5D9F14AD11F09D1DE49294E][1
457088 08097C91EB38AB04C4F4064075B
D87994509B226
]C:\PROGRAM FILES (X86)\SONY\SONY PC COMPANION\PCCOMPANION.EXE
[AA1600118E222FCBE3F3BFEC1ABEC309][1
113024 67499777C8A605764BB54106035
38CAA14C95B30
]C:\PROGRAM FILES (X86)\SONY\SONY PC COMPANION\PCCOMPANIONINFO.
EXE
[21FF393512F51F5A98620C794B4488A3][1
155520 07C6DDE2F2EC2C36CBADF4EF2FF
E7EDAA036AD0B
]C:\PROGRAM FILES (X86)\SONY\SONY PC COMPANION\PCCSERVICE.EXE
[E99CD4524662A2DA7C73372C626669D8][1
5261584 D99EC6DD216976017C945F5EC96
3E27694FE75BE
]C:\PROGRAM FILES (X86)\TEAMVIEWER\VERSION9\TEAMVIEWER_SERVICE.
EXE
[515377905CC9A2EB0E585DD9AB457722][1
592656 21EF1C0A2FD3E137D246CFD6B7B

80206E19C9F65
]C:\PROGRAM FILES (X86)\UNHACKME\HACKMON.EXE
[A597D3A1073271330191EE30046C121A][1
10342712 9D2658D05059F15B2BD794F016D
18B5CD70868FB
]C:\PROGRAM FILES (X86)\UNHACKME\REANIMATOR.EXE
[5598A08634A309A64F9DD3C67B29FE28][2
1232212 A7E3215D1FD8B8F0D68C4386F54
2D97591547222
]C:\PROGRAM FILES (X86)\UNHACKME\UNHACKME.EXE
[83C92F09C507BF8C2E2BED71F7B04A29][1
86096
]C:\PROGRAM FILES (X86)\VMWARE\VMWARE WORKSTATION\VMWARE-AUTHD.
EXE
[86661538E9002DA465C8456A962180C8][1
14401104
]C:\PROGRAM FILES (X86)\VMWARE\VMWARE WORKSTATION\VMWARE-HOSTD.
EXE
[E80335157A225AD734865ADF1F929FFB][1
111696 87C522D79229DD7C5545C503DB0
ECA998CB08AB6
]C:\PROGRAM FILES (X86)\VMWARE\VMWARE WORKSTATION\VMWARE-TRAY.E
XE
[0978D90C8B61F73E926F7194CBCA331C][1
270704
]C:\PROGRAM FILES (X86)\WESTERN DIGITAL\WD DRIVE MANAGER\WDDRIV
ESERVICE.EXE
[BF1DE0D0A36B68A0D3ADC7ECEE0BF6AA][2
5537136 4E04F47CC0548D827FB41E098D7
AC867644554E7
]C:\PROGRAM FILES (X86)\WESTERN DIGITAL\WD QUICK VIEW\WDDMSTATU
S.EXE
[DEE16AB97AFB535329D0D0BE3F5929CE][1
1042808
]C:\PROGRAM FILES (X86)\WESTERN DIGITAL\WD SMARTWARE\WDBACKUPEN
GINE.EXE
[A9F3BFC9345F49614D5859EC95B9E994][6
1525248
]C:\PROGRAM FILES (X86)\WINDOWS MEDIA PLAYER\WMPNETWK.EXE
[B3DD214F23037E3D3C27D6C9447B40B5][1
4247040
]C:\PROGRAM FILES (X86)\WINDOWS NT\ACCESSORIES\WORDPAD.EXE
[33683C85592842A1505723C024056469][2
50688 9DB1CAD4F8A0AD4CFEB0A2D5A97
BB37013E3D788
]C:\PROGRAM FILES (X86)\WORDWEB\WCAPTUREMOZ\COMPONENTS\\WCAPTUR
EXPCOM.DLL
[FD73314789BBDA1FFE76FFDF350D6C09][2
148564 4E4BB606EF3C08BF5FBA4BD1CC4
DA09238672969
]C:\PROGRAM FILES (X86)\WORDWEB\WCXCHROME.CRX
[C42EDED9E707ABDD455BB27FBD72416F][1
65216
]C:\PROGRAM FILES (X86)\WORDWEB\WWEB32.EXE
[6C112DA6C86DB7FB2C50522EFDDA706A][1
337776 B1CE6D21C364A52DFE8E6D0688F
2387D52E585CA
]C:\PROGRAM FILES\COMMON FILES\PROTEXIS\LICENSE SERVICE\PSISERV
ICE_2.EXE
[52C696180AC8371163B268D648DCBDA5][1
416408 07705313E258656850851F2A09A
03F416260966E
]C:\PROGRAM FILES\INTEL\SUR\WILLAMETTE\ESRV\ESRV_SVC.EXE
[EA8386CA87165460D39A1D29FF11080B][1
809680
]C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
[835FC2EA0631B734BB06C12B0665F01D][1
641352
]C:\PROGRAM FILES\IPOD\BIN\IPODSERVICE.EXE
[C6D099464B629CE0DEAAEA791A8A8FCB][2
87040 9E8971F8DCF29645FC05B5BF9D4
797B495AD1306
]C:\PROGRAM FILES\LENOVO\LENOVO MOUSE SUITE\ICO.EXE
[9590E5FAFB67C9842F5EEDD41348F16F][2
178688 1FA5C0B52F5D8C581DE120EEE89
18788FC7DAB7A
]C:\PROGRAM FILES\LENOVO\LENOVO MOUSE SUITE\PELSERVICE.EXE
[D0E79ECFF4D7EF9F1A6C3317E14D6700][2
384512 4BF52D1CABF846B40B30B938B52
4DBB6A2EA6FD0
]C:\PROGRAM FILES\LENOVO\LENOVO SLIM USB KEYBOARD\SKD8821.EXE
[DA7CC6A3F969BBC5959AC88A8D46A5A3][2
137216
]C:\PROGRAM FILES\LENOVO\LENOVO SLIM USB KEYBOARD\SKS8821.EXE
[7CBB1D4D13DC62D7F529D87151FD3CD3][1
1011712
]C:\PROGRAM FILES\WINDOWS DEFENDER\MPSVC.DLL
[29E08F1970B681EBC3B0082D1654CF49][1
274520 F908C4061EDAD0E85B5578D9A20
65E6B8BD8C081
]C:\PROGRAM FILES\WINRAR\RAREXT32.DLL
[DC0D82C65E73BC03601E73F1367248FE][1
12144
]C:\PROGRAM FILES\WINZIP\WZSHLSTB.DLL
[
-2][0
-1
]C:\PROGRAMDATA\{415F24E7-9D9E-594E-415F-F24E79D9939E}\SETUP_PR
ODUCT_18129.EXE

[5137E8DE77B3185EC0B164A3AB9D58B9][1
2752960 2E6BC185359679D6E1A8E9BCFB5
4ADBBC5828D71
]C:\PROGRAMDATA\AVG_UPDATE_0615TB\0615TB_{64222B53-94A6-4D8F-A7
00-11BD2ACB2FBE}.EXE
[D2D91B5F04852D50142D95BB9BB69310][1
691280 F6DCA60AC27EB1CDA41DCEF368E
02EBBC7FE2545
]C:\PROGRAMDATA\FREE DOWNLOAD MANAGER\FIREFOX\EXTENSIONS\2.1.4\
FDMBROWSERHELPER.EXE
[
-2][0
-1
]C:\PROGRAMDATA\RESULTS HUB\RESULTSHUBDESKTOPSEARCH.EXE
[FF1CA44FEDCA271E314AA63692D341A6][1
1179680 F9BB919DDD07587EDB533151AAF
42DDBBE7BD71C
]C:\USERS\ADMIN\APPDATA\LOCAL\MALWAREPROTECTIONLIVE\MALWAREPROT
ECTIONCLIENT.EXE
[
-2][0
-1
]C:\USERS\ADMIN\APPDATA\LOCAL\TEMP\SWLFILES\SMILEYSWELOVETOOLBA
R.CRX
[4A270804DC8AB72DCB4F694D050A3517][1
4019696 D9DFE57B327A89916C804CD5CBF
E46B0532C59A4
]C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\P2448C
P5.DEFAULT\EXTENSIONS\{2D3FBCF7-BE69-4433-8858-C621A8D0E58D}\PLUGINS\\NPWIDEVINE
MEDIAOPTIMIZER.DLL
[611931B3E5CC24A91B8C996A8DCD59BE][2
10146890
]C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\P2448C
P5.DEFAULT\EXTENSIONS\PAULSAINTUZB@GMAIL.COM\MODULES\FFMPEG\\AVCODEC-55.DLL
[A7509D205D44F1FB41C5663EB3A9FE0F][2
1158947
]C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\P2448C
P5.DEFAULT\EXTENSIONS\PAULSAINTUZB@GMAIL.COM\MODULES\FFMPEG\\AVFILTER-3.DLL
[800163D5F4F67EC29D5685699B695B66][2
2134348
]C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\P2448C
P5.DEFAULT\EXTENSIONS\PAULSAINTUZB@GMAIL.COM\MODULES\FFMPEG\\AVFORMAT-55.DLL
[F59359C9B82E31CDF93183537EFB4E56][2
542107
]C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\P2448C
P5.DEFAULT\EXTENSIONS\PAULSAINTUZB@GMAIL.COM\MODULES\FFMPEG\\AVUTIL-52.DLL
[9823CF08B8322478E384A6FB08638B9C][2
428889
]C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\P2448C
P5.DEFAULT\EXTENSIONS\PAULSAINTUZB@GMAIL.COM\MODULES\FFMPEG\\FFMPEG.EXE
[3BAF8E1C73BC5CBED77D98BE6BFA504F][2
159175
]C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\P2448C
P5.DEFAULT\EXTENSIONS\PAULSAINTUZB@GMAIL.COM\MODULES\FFMPEG\\SWRESAMPLE-0.DLL
[
-2][0
-1
]C:\USERS\ADMIN\APPDATA\ROAMING\UPDATE~1\UPDATE~1\UPDATE~1.EXE
[3916505B50FB7002FC0CA59E81C4C4F2][2
1078784 16BF8E86CBF081D501AC52AF5AA
82A01EA507E46
]C:\USERS\ADMIN\DOWNLOADS\SCI_AGENT_SETUP(2).EXE
[24B13133A4AC2FF48BA02EB10990A08D][1
1046344 E06C71A8A7E29DD188282DE043F
3F9B9070D5021
]C:\WINDOWS\DOWNLOADED PROGRAM FILES\ALTTIFF.OCX
[C4002B6B41975F057D98C439030CEA07][1
696832
]C:\WINDOWS\EHOME\EHRECVR.EXE
[4705E8EF9934482C5BB488CE28AFC681][1
127488
]C:\WINDOWS\EHOME\EHSCHED.EXE
[AC4C51EB24AA95B77F705AB159189E24][6
2872320
]C:\WINDOWS\EXPLORER.EXE
[0A9C8038265E0B8CF921892B9469B6B2][2
188928
]C:\WINDOWS\FIXCAMERA.EXE
[D6294D59171AC375CD142003566AA89E][2
25214
]C:\WINDOWS\INSTALLER\{AC76BA86-1033-0000-7760-000000000002}\SC
_ACROBAT.EXE
[D88040F816FDA31C3B466F0FA0918F29][1
66384
]C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V2.0.50727\MSCORSVW.EXE
[6D7C8A951AF6AD6835C029B3CB88D333][1
104912
]C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V4.0.30319\MSCORSVW.EXE
[D1CEEA2B47CB998321C579651CE3E4F8][1
89920
]C:\WINDOWS\MICROSOFT.NET\FRAMEWORK64\V2.0.50727\MSCORSVW.EXE
[5988FC40F8DB5B0739CD1E3A5D0D78BD][1
856400

]C:\WINDOWS\MICROSOFT.NET\FRAMEWORK64\V3.0\WINDOWS COMMUNICATIO
N FOUNDATION\INFOCARD.EXE
[A8B7F3818AB65695E3A0BB3279F6DCE6][1
42856
]C:\WINDOWS\MICROSOFT.NET\FRAMEWORK64\V3.0\WPF\PRESENTATIONFONT
CACHE.EXE
[108FB6DDB69E537A2EA53F425363FAE5][1
51648
]C:\WINDOWS\MICROSOFT.NET\FRAMEWORK64\V4.0.30319\ASPNET_STATE.E
XE
[86329C35FF23CFEF0FB6C0023BA06BCE][1
123856
]C:\WINDOWS\MICROSOFT.NET\FRAMEWORK64\V4.0.30319\MSCORSVW.EXE
[5243CFC2E7161C91C2B355240035B9E4][1
139696
]C:\WINDOWS\MICROSOFT.NET\FRAMEWORK64\V4.0.30319\SMSVCHOST.EXE
[773212B2AAA24C1E31F10246B15B276C][1
194048
]C:\WINDOWS\SERVICING\TRUSTEDINSTALLER.EXE
[4ABA3E75A76195A3E38ED2766C962899][1
193536
]C:\WINDOWS\SYSNATIVE\APPMGMTS.DLL
[1A47D52E303B7543E4E6026595B95422][1
1297408
]C:\WINDOWS\SYSNATIVE\COMRES.DLL
[3044D07ABDF4BBEA27E2EE7B1E0C0C65][1
12288
]C:\WINDOWS\SYSNATIVE\D3D8THK.DLL
[A6C09924C6730DE8DEED9890A12AA691][1
569344
]C:\WINDOWS\SYSNATIVE\DDRAW.DLL
[9110FFAD124283F37D38771BB60556AF][1
540672
]C:\WINDOWS\SYSNATIVE\DSOUND.DLL
[3B367397320C26DBA890B260F80D1B1B][1
424448
]C:\WINDOWS\SYSNATIVE\HNETCFG.DLL
[AA2C08CE85653B1A0D2E4AB407FA176C][1
167424
]C:\WINDOWS\SYSNATIVE\IMM32.DLL
[2B81776DA02017A37FE26C662827470E][1
145920
]C:\WINDOWS\SYSNATIVE\IPHLPAPI.DLL
[8560FFFC8EB3A806DCD4F82252CFC8C6][1
5120
]C:\WINDOWS\SYSNATIVE\KSUSER.DLL
[796B47A4B82EF1C39F13435B88834C48][1
41472
]C:\WINDOWS\SYSNATIVE\LPK.DLL
[CA2A0750ED830678997695FF61B04C30][1
20480
]C:\WINDOWS\SYSNATIVE\MIDIMAP.DLL
[C210E0DF28F3B0E5D45F928F08726650][1
8704
]C:\WINDOWS\SYSNATIVE\MSCTFIME.IME
[37D0FB9E5E8EDA40B66FC3FB3D660261][1
23549440
]C:\WINDOWS\SYSNATIVE\MSHTML.DLL
[E424B3EF666B184CEE0B6871AAA8C9F6][1
8192
]C:\WINDOWS\SYSNATIVE\MSIMG32.DLL
[9A9F9F1A77D6A80EE28B57664F00013E][1
327168
]C:\WINDOWS\SYSNATIVE\MSWSOCK.DLL
[58A0CDABEA255616827B1C22C9994466][1
68096
]C:\WINDOWS\SYSNATIVE\NAPINSP.DLL
[2DF36F15B2BC1571A6A542A3C2107920][1
70656
]C:\WINDOWS\SYSNATIVE\NLAAPI.DLL
[613C8CE10A5FDE582BA5FA64C4D56AAA][1
86016
]C:\WINDOWS\SYSNATIVE\PNRPNSP.DLL
[88351B29B622B30962D2FEB6CA8D860B][1
16384
]C:\WINDOWS\SYSNATIVE\RASADHLP.DLL
[019CD868461B646E09BDF04474C19341][1
384512
]C:\WINDOWS\SYSNATIVE\RASAPI32.DLL
[5C627D1B1138676C0A7AB2C2C190D123][1
512000
]C:\WINDOWS\SYSNATIVE\RPCSS.DLL
[ED78427259134C63ED69804D2132B86C][1
232960
]C:\WINDOWS\SYSNATIVE\SCECLI.DLL
[24ACB7E5BE595468E3B9AA488B9B4FCB][6
328704
]C:\WINDOWS\SYSNATIVE\SERVICES.EXE

[09F7401D56F2393C6CA534FF0241A590][1
257024
]C:\WINDOWS\SYSNATIVE\TASKMGR.EXE
[2C353B6CE0C8D03225CAA2AF33B68D79][5
1008640
]C:\WINDOWS\SYSNATIVE\USER32.DLL
[D29E998E8277666982B4F0303BF4E7AF][1
332288
]C:\WINDOWS\SYSNATIVE\UXTHEME.DLL
[88AB9B72B4BF3963A0DE0820B4B0B06C][1
455168
]C:\WINDOWS\SYSNATIVE\WINLOGON.EXE
[2E2072EB48238FCA8FBB7A9F5FABAC45][1
28672
]C:\WINDOWS\SYSNATIVE\WINRNR.DLL
[8396C6C26AADDFE4590CCEF0F419B6B7][1
4608
]C:\WINDOWS\SYSNATIVE\WS2HELP.DLL
[E2FC47E343466505E149108371572EB9][2
28672 7AE684182881903BB8E782AA11E
7140F608D567F
]C:\WINDOWS\SYSTEM32\ACTIVEXRES_CHI.DLL
[1FD70A005C634D4FEF8E3D44567B977A][2
32768 A105D954581D9BBE3A9F132E40E
76DB95BD87E12
]C:\WINDOWS\SYSTEM32\ACTIVEXRES_ENG.DLL
[ED730D791CB026146F9FB8EFB15201B7][1
55432
]C:\WINDOWS\SYSTEM32\ADOBEPDF.DLL
[4B78B431F225FD8624C5655CB1DE7B61][1
72192
]C:\WINDOWS\SYSTEM32\AELUPSVC.DLL
[3290D6946B5E30E70414990574883DDB][1
79360
]C:\WINDOWS\SYSTEM32\ALG.EXE
[0BC381A15355A3982216F7172F545DE1][1
32256
]C:\WINDOWS\SYSTEM32\APPIDSVC.DLL
[9D2A2369AB4B08A4905FE72DB104498F][1
70144
]C:\WINDOWS\SYSTEM32\APPINFO.DLL
[4ABA3E75A76195A3E38ED2766C962899][1
193536
]C:\WINDOWS\SYSTEM32\APPMGMTS.DLL
[F23FEF6D569FCE88671949894A8BECF1][1
679424
]C:\WINDOWS\SYSTEM32\AUDIOSRV.DLL
[A6BF31A71B409DFA8CAC83159E1E2AFF][1
114688
]C:\WINDOWS\SYSTEM32\AXINSTSV.DLL
[FDE360167101B4E45A96F939F388AEB0][1
100864
]C:\WINDOWS\SYSTEM32\BDESVC.DLL
[82974D6A2FD19445CC5171FC378668A4][1
705024
]C:\WINDOWS\SYSTEM32\BFE.DLL
[05F5A0D14A2EE1D8255C2AA0E9E8E694][1
136704
]C:\WINDOWS\SYSTEM32\BROWSER.DLL
[95F9C2976059462CBBF227F7AAB10DE9][1
83968
]C:\WINDOWS\SYSTEM32\BTHSERV.DLL
[D8891208401903CE11A85BF406EBE771][2
214528
]C:\WINDOWS\SYSTEM32\BZPDF.DLL
[5F6C6FFF1ECEBA3E8E2C268674C16591][2
57344 2DD9303369935AC0A94110C959C
2063F9FBCB61F
]C:\WINDOWS\SYSTEM32\CALENDAR.OCX
[F17D1D393BBC69C5322FBFAFACA28C7F][1
80384
]C:\WINDOWS\SYSTEM32\CERTPROP.DLL
[FE1EC06F2253F691FE36217C592A0206][1
367696
]C:\WINDOWS\SYSTEM32\CLFS.SYS
[113E274E5A67A93EE8A3D143F566454E][1
58880
]C:\WINDOWS\SYSTEM32\CNAB4LMD.DLL
[6B400F211BEE880A37A1ED0368776BF4][1
184320
]C:\WINDOWS\SYSTEM32\CRYPTSVC.DLL
[3AB183AB4D2C79DCF459CD2C1266B043][1
692224
]C:\WINDOWS\SYSTEM32\CSCSVC.DLL
[3CEC7631A84943677AA8FA8EE5B6B43D][1
291328
]C:\WINDOWS\SYSTEM32\DEFRAGSVC.DLL
[43D808F5D9E1A18E5EEB5EBC83969E4E][1
317952
]C:\WINDOWS\SYSTEM32\DHCPCORE.DLL
[A8EDB86FC2A4D6D1285E4C70384AC35A][1
9728
]C:\WINDOWS\SYSTEM32\DLLHOST.EXE

[16835866AAA693C7D7FCEBA8FFF706E4][1
183296
]C:\WINDOWS\SYSTEM32\DNSRSLVR.DLL
[B1FB3DDCA0FDF408750D5843591AFBC6][1
252416
]C:\WINDOWS\SYSTEM32\DOT3SVC.DLL
[B26F4F737E8F9DF4F31AF6CF31D05820][1
162816
]C:\WINDOWS\SYSTEM32\DPS.DLL
[A87D604AEA360176311474C87A63BB88][1
229888
]C:\WINDOWS\SYSTEM32\DRIVERS\1394OHCI.SYS
[D81D9E70B8A6DD14D42D7B4EFA65D5F2][1
334208
]C:\WINDOWS\SYSTEM32\DRIVERS\ACPI.SYS
[99F8E788246D495CE3794D7E7821D2CA][1
12800
]C:\WINDOWS\SYSTEM32\DRIVERS\ACPIPMI.SYS
[2F6B34B83843F0C5118B63AC634F5BF4][1
491088
]C:\WINDOWS\SYSTEM32\DRIVERS\ADP94XX.SYS
[597F78224EE9224EA1A13D6350CED962][1
339536
]C:\WINDOWS\SYSTEM32\DRIVERS\ADPAHCI.SYS
[E109549C90F62FB570B9540C4B148E54][1
182864
]C:\WINDOWS\SYSTEM32\DRIVERS\ADPU320.SYS
[79059559E89D06E8B80CE2944BE20228][1
497152
]C:\WINDOWS\SYSTEM32\DRIVERS\AFD.SYS
[7ECFF9B22276B73F43A99A15A6094E90][1
60416
]C:\WINDOWS\SYSTEM32\DRIVERS\AGILEVPN.SYS
[608C14DBA7299D8CB6ED035A68A15799][1
61008
]C:\WINDOWS\SYSTEM32\DRIVERS\AGP440.SYS
[5812713A477A3AD7363C7438CA2EE038][1
15440
]C:\WINDOWS\SYSTEM32\DRIVERS\ALIIDE.SYS
[1FF8B4431C353CE385C875F194924C0C][1
15440
]C:\WINDOWS\SYSTEM32\DRIVERS\AMDIDE.SYS
[7024F087CFF1833A806193EF9D22CDA9][1
64512
]C:\WINDOWS\SYSTEM32\DRIVERS\AMDK8.SYS
[1E56388B3FE0D031C44144EB8C4D6217][1
60928
]C:\WINDOWS\SYSTEM32\DRIVERS\AMDPPM.SYS
[6EC6D772EAE38DC17C14AED9B178D24B][1
107904
]C:\WINDOWS\SYSTEM32\DRIVERS\AMDSATA.SYS
[F67F933E79241ED32FF46A4F29B5120B][1
194128
]C:\WINDOWS\SYSTEM32\DRIVERS\AMDSBS.SYS
[1142A21DB581A84EA5597B03A26EBAA0][1
27008
]C:\WINDOWS\SYSTEM32\DRIVERS\AMDXATA.SYS
[4FC6E2C2FC50445450651F42E90CC0BD][1
31968
]C:\WINDOWS\SYSTEM32\DRIVERS\APOWERSOFT_AUDIODEVICE.SYS
[89A69C3F2F319B43379399547526D952][1
61440
]C:\WINDOWS\SYSTEM32\DRIVERS\APPID.SYS
[C484F8CEB1717C540242531DB7845C4E][1
87632
]C:\WINDOWS\SYSTEM32\DRIVERS\ARC.SYS
[019AF6924AEFE7839F61C830227FE79C][1
97856
]C:\WINDOWS\SYSTEM32\DRIVERS\ARCSAS.SYS
[769765CE2CC62867468CEA93969B2242][1
23040
]C:\WINDOWS\SYSTEM32\DRIVERS\ASYNCMAC.SYS
[02062C0B390B7729EDC9E69C680A6F3C][1
24128
]C:\WINDOWS\SYSTEM32\DRIVERS\ATAPI.SYS
[F02E18EFA6CEA4378D3F95CB6F9A3DE4][1
98816 207316C7BC7D80871F030F86BC2
6B4A8FB25EF41
]C:\WINDOWS\SYSTEM32\DRIVERS\AX88772B.SYS
[B5ACE6968304A3900EEB1EBFD9622DF2][1
270848
]C:\WINDOWS\SYSTEM32\DRIVERS\B57ND60A.SYS
[61583EE3C3A17003C4ACD0475646B4D3][1
45056
]C:\WINDOWS\SYSTEM32\DRIVERS\BLBDRIVE.SYS
[6C02A83164F5CC0A262F4199F0871CF5][1
90624
]C:\WINDOWS\SYSTEM32\DRIVERS\BOWSER.SYS
[F09EEE9EDC320B5E1501F749FDE686C8][1
18432
]C:\WINDOWS\SYSTEM32\DRIVERS\BRFILTLO.SYS

[B114D3098E9BDB8BEA8B053685831BE6][1
8704
]C:\WINDOWS\SYSTEM32\DRIVERS\BRFILTUP.SYS
[43BEA8D483BF1870F018E2D02E06A5BD][1
286720
]C:\WINDOWS\SYSTEM32\DRIVERS\BRSERID.SYS
[A6ECA2151B08A09CACECA35C07F05B42][1
47104
]C:\WINDOWS\SYSTEM32\DRIVERS\BRSERWDM.SYS
[B79968002C277E869CF38BD22CD61524][1
14976
]C:\WINDOWS\SYSTEM32\DRIVERS\BRUSBMDM.SYS
[A87528880231C54E75EA7A44943B38BF][1
14720
]C:\WINDOWS\SYSTEM32\DRIVERS\BRUSBSER.SYS
[9DA669F11D1F894AB4EB69BF546A42E8][1
72192
]C:\WINDOWS\SYSTEM32\DRIVERS\BTHMODEM.SYS
[3E5B191307609F7514148C6832BB0842][1
468480
]C:\WINDOWS\SYSTEM32\DRIVERS\BXVBDA.SYS
[B8BD2BB284668C84865658C77574381A][1
92160
]C:\WINDOWS\SYSTEM32\DRIVERS\CDFS.SYS
[F036CE71586E93D94DAB220D7BDF4416][1
147456
]C:\WINDOWS\SYSTEM32\DRIVERS\CDROM.SYS
[D7CD5C4E1B71FA62050515314CFB52CF][1
45568
]C:\WINDOWS\SYSTEM32\DRIVERS\CIRCLASS.SYS
[0840155D0BDDF1190F84A663C284BD33][1
17664
]C:\WINDOWS\SYSTEM32\DRIVERS\CMBATT.SYS
[E19D3F095812725D88F9001985B94EDD][1
17488
]C:\WINDOWS\SYSTEM32\DRIVERS\CMDIDE.SYS
[EBF28856F69CF094A902F884CF989706][1
458712
]C:\WINDOWS\SYSTEM32\DRIVERS\CNG.SYS
[102DE219C3F61415F964C88E9085AD14][1
21584
]C:\WINDOWS\SYSTEM32\DRIVERS\COMPBATT.SYS
[03EDB043586CCEBA243D689BDDA370A8][1
38912
]C:\WINDOWS\SYSTEM32\DRIVERS\COMPOSITEBUS.SYS
[1C827878A998C18847245FE1F34EE597][1
24144
]C:\WINDOWS\SYSTEM32\DRIVERS\CRCDISK.SYS
[54DA3DFD29ED9F1619B6F53F3CE55E49][1
514560
]C:\WINDOWS\SYSTEM32\DRIVERS\CSC.SYS
[9BB2EF44EAA163B29C4A4587887A0FE4][1
102400
]C:\WINDOWS\SYSTEM32\DRIVERS\DFSC.SYS
[13096B05847EC78F0977F2C0F79E9AB3][1
40448
]C:\WINDOWS\SYSTEM32\DRIVERS\DISCACHE.SYS
[9819EEE8B5EA3784EC4AF3B137A5244C][1
73280
]C:\WINDOWS\SYSTEM32\DRIVERS\DISK.SYS
[9B19F34400D24DF84C858A421C205754][1
5632
]C:\WINDOWS\SYSTEM32\DRIVERS\DRMKAUD.SYS
[88612F1CE3BF42256913BF6E61C70D52][1
983488
]C:\WINDOWS\SYSTEM32\DRIVERS\DXGKRNL.SYS
[0E5DA5369A0FCAEA12456DD852545184][1
530496
]C:\WINDOWS\SYSTEM32\DRIVERS\ELXSTOR.SYS
[34A3C54752046E79A126E15C51DB409B][1
9728
]C:\WINDOWS\SYSTEM32\DRIVERS\ERRDEV.SYS
[DC5D737F51BE844D8C82C695EB17372F][1
3286016
]C:\WINDOWS\SYSTEM32\DRIVERS\EVBDA.SYS
[D765D19CD8EF61F650C384F62FAC00AB][1
29696
]C:\WINDOWS\SYSTEM32\DRIVERS\FDC.SYS
[655661BE46B5F5F3FD454E2C3095B930][1
70224
]C:\WINDOWS\SYSTEM32\DRIVERS\FILEINFO.SYS
[5F671AB5BC87EEA04EC38A6CD5962A47][1
34304
]C:\WINDOWS\SYSTEM32\DRIVERS\FILETRACE.SYS
[C172A0F53008EAEB8EA33FE10E177AF5][1
24576
]C:\WINDOWS\SYSTEM32\DRIVERS\FLPYDISK.SYS
[DA6B67270FD9DB3697B20FCE94950741][1
289664
]C:\WINDOWS\SYSTEM32\DRIVERS\FLTMGR.SYS

[D43703496149971890703B4B1B723EAC][1
55376
]C:\WINDOWS\SYSTEM32\DRIVERS\FSDEPENDS.SYS
[1F7B25B858FA27015169FE95E54108ED][1
223248
]C:\WINDOWS\SYSTEM32\DRIVERS\FVEVOL.SYS
[8C778D335C9D272CFD3298AB02ABE3B6][1
65088
]C:\WINDOWS\SYSTEM32\DRIVERS\GAGP30KX.SYS
[8E98D21EE06192492A5671A6144D092F][1
33240
]C:\WINDOWS\SYSTEM32\DRIVERS\GEARASPIWDM.SYS
[A1F556318931B9EA276F4E2DA2C1791C][1
16088
]C:\WINDOWS\SYSTEM32\DRIVERS\GGFLT.SYS
[7F56A3E09A6AD40B07E4EFAD34A40A18][1
30424
]C:\WINDOWS\SYSTEM32\DRIVERS\GGSOMC.SYS
[23AF3730B7B757A385721E900250CF3B][1
53816
]C:\WINDOWS\SYSTEM32\DRIVERS\HCMON.SYS
[F2523EF6460FC42405B12248338AB2F0][1
31232
]C:\WINDOWS\SYSTEM32\DRIVERS\HCW85CIR.SYS
[97BFED39B6B79EB12CDDBFEED51F56BB][1
122368
]C:\WINDOWS\SYSTEM32\DRIVERS\HDAUDBUS.SYS
[975761C778E33CD22498059B91E7373A][1
350208
]C:\WINDOWS\SYSTEM32\DRIVERS\HDAUDIO.SYS
[A6518DCC42F7A6E999BB3BEA8FD87567][1
56344
]C:\WINDOWS\SYSTEM32\DRIVERS\HECIX64.SYS
[45540DAE98ED8E6C5376F616D8D5547C][1
19560 BD0528C0C3251B3BDC6086DFAF5
2F5FE10201390
]C:\WINDOWS\SYSTEM32\DRIVERS\HHDSERHELP.SYS
[2C3D7F56BA751941D0E7DA16934FBB5D][1
39016 8B0465CFE2F991FD7EB79D607A8
BF41A7F41E7F8
]C:\WINDOWS\SYSTEM32\DRIVERS\HHDSERIAL64.SYS
[78E86380454A7B10A5EB255DC44A355F][1
26624
]C:\WINDOWS\SYSTEM32\DRIVERS\HIDBATT.SYS
[7FD2A313F7AFE5C4DAB14798C48DD104][1
100864
]C:\WINDOWS\SYSTEM32\DRIVERS\HIDBTH.SYS
[0A77D29F311B88CFAE3B13F9C1A73825][1
46592
]C:\WINDOWS\SYSTEM32\DRIVERS\HIDIR.SYS
[9592090A7E2B61CD582B612B6DF70536][1
30208
]C:\WINDOWS\SYSTEM32\DRIVERS\HIDUSB.SYS
[39D2ABCD392F3D8A6DCE7B60AE7B8EFC][1
78720
]C:\WINDOWS\SYSTEM32\DRIVERS\HPSAMD.SYS
[0EA7DE1ACB728DD5A369FD742D6EEE28][1
753664
]C:\WINDOWS\SYSTEM32\DRIVERS\HTTP.SYS
[A5462BD6884960C9DC85ED49D34FF392][1
14720
]C:\WINDOWS\SYSTEM32\DRIVERS\HWPOLICY.SYS
[FA55C73D4AFFA7EE23AC4BE53B4592D3][1
105472
]C:\WINDOWS\SYSTEM32\DRIVERS\I8042PRT.SYS
[3DF4395A7CF8B7A72A5F4606366B8C2D][1
410496
]C:\WINDOWS\SYSTEM32\DRIVERS\IASTORV.SYS
[5C18831C61933628F5BB0EA2675B9D21][1
44112
]C:\WINDOWS\SYSTEM32\DRIVERS\IIRSP.SYS
[A9771DB91E5F9B55FC8F305960875ACD][2
28672 14BA6886A454C5F37E12B1E2344
A101479ABB35F
]C:\WINDOWS\SYSTEM32\DRIVERS\InstallSadpNpfApp.exe
[F00F20E70C6EC3AA366910083A0518AA][1
16960
]C:\WINDOWS\SYSTEM32\DRIVERS\INTELIDE.SYS
[ADA036632C664CAA754079041CF1F8C1][1
62464
]C:\WINDOWS\SYSTEM32\DRIVERS\INTELPPM.SYS
[C9F0E1BD74365A8771590E9008D22AB6][1
82944
]C:\WINDOWS\SYSTEM32\DRIVERS\IPFLTDRV.SYS
[0FC1AEA580957AA8817B8F305D18CA3A][1
78848
]C:\WINDOWS\SYSTEM32\DRIVERS\IPMIDRV.SYS
[AF9B39A7E7B6CAA203B3862582E9F2D0][1
116224
]C:\WINDOWS\SYSTEM32\DRIVERS\IPNAT.SYS
[3ABF5E7213EB28966D55D58B515D5CE9][1
17920
]C:\WINDOWS\SYSTEM32\DRIVERS\IRENUM.SYS

[2F7B28DC3E1183E5EB418DF55C204F38][1
20544
]C:\WINDOWS\SYSTEM32\DRIVERS\ISAPNP.SYS
[BC02336F1CBA7DCC7D1213BB588A68A5][1
50768
]C:\WINDOWS\SYSTEM32\DRIVERS\KBDCLASS.SYS
[0705EFF5B42A9DB58548EEC3B26BB484][1
33280
]C:\WINDOWS\SYSTEM32\DRIVERS\KBDHID.SYS
[353009DEDF918B2A51414F330CF72DEC][1
95680
]C:\WINDOWS\SYSTEM32\DRIVERS\KSECDD.SYS
[1C2D8E18AA8FD50CD04C15CC27F7F5AB][1
155072
]C:\WINDOWS\SYSTEM32\DRIVERS\KSECPKG.SYS
[6869281E78CB31A43E969F06B57347C4][1
20992
]C:\WINDOWS\SYSTEM32\DRIVERS\KSTHUNK.SYS
[1538831CF8AD2979A04C423779465827][1
60928
]C:\WINDOWS\SYSTEM32\DRIVERS\LLTDIO.SYS
[1A93E54EB0ECE102495A51266DCDB6A6][1
114752
]C:\WINDOWS\SYSTEM32\DRIVERS\LSI_FC.SYS
[1047184A9FDC8BDBFF857175875EE810][1
106560
]C:\WINDOWS\SYSTEM32\DRIVERS\LSI_SAS.SYS
[30F5C0DE1EE8B5BC9306C1F0E4A75F93][1
65600
]C:\WINDOWS\SYSTEM32\DRIVERS\LSI_SAS2.SYS
[0504EACAFF0D3C8AED161C4B0D369D4A][1
115776
]C:\WINDOWS\SYSTEM32\DRIVERS\LSI_SCSI.SYS
[43D0F98E1D56CCDDB0D5254CFF7B356E][1
113152
]C:\WINDOWS\SYSTEM32\DRIVERS\LUAFV.SYS
[A55805F747C6EDB6A9080D7C633BD0F4][1
35392
]C:\WINDOWS\SYSTEM32\DRIVERS\MEGASAS.SYS
[BAF74CE0072480C3B6B7C13B2A94D6B3][1
284736
]C:\WINDOWS\SYSTEM32\DRIVERS\MEGASR.SYS
[800BA92F7010378B09F9ED9270F07137][1
40448
]C:\WINDOWS\SYSTEM32\DRIVERS\MODEM.SYS
[B03D591DC7DA45ECE20B3B467E6AADAA][1
30208
]C:\WINDOWS\SYSTEM32\DRIVERS\MONITOR.SYS
[7D27EA49F3C1F687D357E77A470AEA99][1
49216
]C:\WINDOWS\SYSTEM32\DRIVERS\MOUCLASS.SYS
[D3BF052C40B0C4166D9FD86A4288C1E6][1
31232
]C:\WINDOWS\SYSTEM32\DRIVERS\MOUHID.SYS
[32E7A3D591D671A6DF2DB515A5CBE0FA][1
94592
]C:\WINDOWS\SYSTEM32\DRIVERS\MOUNTMGR.SYS
[A44B420D30BD56E145D6A2BC8768EC58][1
155008
]C:\WINDOWS\SYSTEM32\DRIVERS\MPIO.SYS
[6C38C9E45AE0EA2FA5E551F2ED5E978F][1
77312
]C:\WINDOWS\SYSTEM32\DRIVERS\MPSDRV.SYS
[DC722758B8261E1ABAFD31A3C0A66380][1
140800
]C:\WINDOWS\SYSTEM32\DRIVERS\MRXDAV.SYS
[A5D9106A73DC88564C825D317CAC68AC][1
158208
]C:\WINDOWS\SYSTEM32\DRIVERS\MRXSMB.SYS
[D711B3C1D5F42C0C2415687BE09FC163][1
288768
]C:\WINDOWS\SYSTEM32\DRIVERS\MRXSMB10.SYS
[9423E9D355C8D303E76B8CFBD8A5C30C][1
128000
]C:\WINDOWS\SYSTEM32\DRIVERS\MRXSMB20.SYS
[C25F0BAFA182CBCA2DD3C851C2E75796][1
31104
]C:\WINDOWS\SYSTEM32\DRIVERS\MSAHCI.SYS
[DB801A638D011B9633829EB6F663C900][1
140672
]C:\WINDOWS\SYSTEM32\DRIVERS\MSDSM.SYS
[F9D215A46A8B9753F61767FA72A20326][1
8192
]C:\WINDOWS\SYSTEM32\DRIVERS\MSHIDKMDF.SYS
[D916874BBD4F8B07BFB7FA9B3CCAE29D][1
15424
]C:\WINDOWS\SYSTEM32\DRIVERS\MSISADRV.SYS
[D931D7309DEB2317035B07C9F9E6B0BD][1
273792
]C:\WINDOWS\SYSTEM32\DRIVERS\MSISCSI.SYS

[49CCF2C4FEA34FFAD8B1B59D49439366][1
11136
]C:\WINDOWS\SYSTEM32\DRIVERS\MSKSSRV.SYS
[BDD71ACE35A232104DDD349EE70E1AB3][1
7168
]C:\WINDOWS\SYSTEM32\DRIVERS\MSPCLOCK.SYS
[4ED981241DB27C3383D72092B618A1D0][1
6784
]C:\WINDOWS\SYSTEM32\DRIVERS\MSPQM.SYS
[0EED230E37515A0EAEE3C2E1BC97B288][1
32320
]C:\WINDOWS\SYSTEM32\DRIVERS\MSSMBIOS.SYS
[2E66F9ECB30B4221A318C92AC2250779][1
8064
]C:\WINDOWS\SYSTEM32\DRIVERS\MSTEE.SYS
[7EA404308934E675BFFDE8EDF0757BCD][1
15360
]C:\WINDOWS\SYSTEM32\DRIVERS\MTCONFIG.SYS
[F9A18612FD3526FE473C1BDA678D61C8][1
60496
]C:\WINDOWS\SYSTEM32\DRIVERS\MUP.SYS
[79B47FD40D9A817E932F9D26FAC0A81C][1
951680
]C:\WINDOWS\SYSTEM32\DRIVERS\NDIS.SYS
[9F9A1F53AAD7DA4D6FEF5BB73AB811AC][1
35328
]C:\WINDOWS\SYSTEM32\DRIVERS\NDISCAP.SYS
[30639C932D9FEF22B31268FE25A1B6E5][1
24064
]C:\WINDOWS\SYSTEM32\DRIVERS\NDISTAPI.SYS
[136185F9FB2CC61E573E676AA5402356][1
56832
]C:\WINDOWS\SYSTEM32\DRIVERS\NDISUIO.SYS
[53F7305169863F0A2BDDC49E116C2E11][1
164352
]C:\WINDOWS\SYSTEM32\DRIVERS\NDISWAN.SYS
[86743D9F5D2B1048062B14B1D84501C4][1
44544
]C:\WINDOWS\SYSTEM32\DRIVERS\NETBIOS.SYS
[09594D1089C523423B32A4229263F068][1
261632
]C:\WINDOWS\SYSTEM32\DRIVERS\NETBT.SYS
[98F3ABC312BC0C660BA3F3B47782455E][1
35319
]C:\WINDOWS\SYSTEM32\DRIVERS\NETMD031.sys
[417334447945C9E111FFD881F7BF4D08][1
36232
]C:\WINDOWS\SYSTEM32\DRIVERS\NETMD033.sys
[986ACDECE933131288F1957DC359865F][1
38951
]C:\WINDOWS\SYSTEM32\DRIVERS\NETMDUSB.sys
[77889813BE4D166CDAB78DDBA990DA92][1
51264
]C:\WINDOWS\SYSTEM32\DRIVERS\NFRD960.SYS
[E7F5AE18AF4168178A642A9247C63001][1
24576
]C:\WINDOWS\SYSTEM32\DRIVERS\NSIPROXY.SYS
[270D7CD42D6E3979F6DD0146650F0E05][1
122960
]C:\WINDOWS\SYSTEM32\DRIVERS\NV_AGP.SYS
[5D9FD91F3D38DC9DA01E3CB5FA89CD48][1
148352
]C:\WINDOWS\SYSTEM32\DRIVERS\NVRAID.SYS
[F7CD50FE7139F07E77DA8AC8033D1832][1
166272
]C:\WINDOWS\SYSTEM32\DRIVERS\NVSTOR.SYS
[1EA3749C4114DB3E3161156FFFFA6B33][1
318976
]C:\WINDOWS\SYSTEM32\DRIVERS\NWIFI.SYS
[3589478E4B22CE21B41FA1BFC0B8B8A0][1
72832
]C:\WINDOWS\SYSTEM32\DRIVERS\OHCI1394.SYS
[0557CF5A2556BD58E26384169D72438D][1
131584
]C:\WINDOWS\SYSTEM32\DRIVERS\PACER.SYS
[0086431C29C35BE1DBC43F52CC273887][1
97280
]C:\WINDOWS\SYSTEM32\DRIVERS\PARPORT.SYS
[6DDCF3F801EC15FE698F6A215CF30A1F][1
35816
]C:\WINDOWS\SYSTEM32\DRIVERS\PARTIZAN.SYS
[E9766131EEADE40A27DC27D2D68FBA9C][1
75120
]C:\WINDOWS\SYSTEM32\DRIVERS\PARTMGR.SYS
[94575C0571D1462A0F70BDE6BD6EE6B3][1
184704
]C:\WINDOWS\SYSTEM32\DRIVERS\PCI.SYS
[B5B8B5EF2E5CB34DF8DCF8831E3534FA][1
12352
]C:\WINDOWS\SYSTEM32\DRIVERS\PCIIDE.SYS

[B2E81D4E87CE48589F98CB8C05B01F2F][1
220752
]C:\WINDOWS\SYSTEM32\DRIVERS\PCMCIA.SYS
[D6B9C2E1A11A3A4B26A182FFEF18F603][1
50768
]C:\WINDOWS\SYSTEM32\DRIVERS\PCW.SYS
[68769C3356B3BE5D1C732C97B9A80D6E][1
651264
]C:\WINDOWS\SYSTEM32\DRIVERS\PEAUTH.SYS
[50AD172D2DDF898FC1705199B60C3264][1
23040
]C:\WINDOWS\SYSTEM32\DRIVERS\PELMOUSE.SYS
[ADC5D126ABAB5AB5B806AE32B12125E7][1
34816
]C:\WINDOWS\SYSTEM32\DRIVERS\PELUSBLF.SYS
[0D922E23C041EFB1C3FAC2A6F943C9BF][1
60416
]C:\WINDOWS\SYSTEM32\DRIVERS\PROCESSR.SYS
[A53A15A11EBFD21077463EE2C7AFEEF0][1
1524816
]C:\WINDOWS\SYSTEM32\DRIVERS\QL2300.SYS
[4F6D12B51DE1AAEFF7DC58C4D75423C8][1
128592
]C:\WINDOWS\SYSTEM32\DRIVERS\QL40XX.SYS
[76707BB36430888D9CE9D705398ADB6C][1
46592
]C:\WINDOWS\SYSTEM32\DRIVERS\QWAVEDRV.SYS
[5A0DA8AD5762FA2D91678A8A01311704][1
14848
]C:\WINDOWS\SYSTEM32\DRIVERS\RASACD.SYS
[471815800AE33E6F1C32FB1B97C490CA][1
129536
]C:\WINDOWS\SYSTEM32\DRIVERS\RASL2TP.SYS
[855C9B1CD4756C5E9A2AA58A15F58C25][1
92672
]C:\WINDOWS\SYSTEM32\DRIVERS\RASPPPOE.SYS
[F92A2C41117A11A00BE01CA01A7FCDE9][1
111104
]C:\WINDOWS\SYSTEM32\DRIVERS\RASPPTP.SYS
[E8B1E447B008D07FF47D016C2B0EEECB][1
83968
]C:\WINDOWS\SYSTEM32\DRIVERS\RASSSTP.SYS
[77F665941019A1594D887A74F301FA2F][1
309248
]C:\WINDOWS\SYSTEM32\DRIVERS\RDBSS.SYS
[302DA2A0539F2CF54D7C6CC30C1F2D8D][1
24064
]C:\WINDOWS\SYSTEM32\DRIVERS\RDPBUS.SYS
[CEA6CC257FC9B7715F1C2B4849286D24][1
7680
]C:\WINDOWS\SYSTEM32\DRIVERS\RDPCDD.SYS
[1B6163C503398B23FF8B939C67747683][1
165888
]C:\WINDOWS\SYSTEM32\DRIVERS\RDPDR.SYS
[BB5971A4F00659529A5C44831AF22365][1
7680
]C:\WINDOWS\SYSTEM32\DRIVERS\RDPENCDD.SYS
[216F3FA57533D98E1F74DED70113177A][1
8192
]C:\WINDOWS\SYSTEM32\DRIVERS\RDPREFMP.SYS
[70CBA1A0C98600A2AA1863479B35CB90][1
20992
]C:\WINDOWS\SYSTEM32\DRIVERS\RDPVIDEOMINIPORT.SYS
[
-2][0
-1
]C:\WINDOWS\SYSTEM32\DRIVERS\RDVGKMD.SYS
[34ED295FA0121C241BFEF24764FC4520][1
213888
]C:\WINDOWS\SYSTEM32\DRIVERS\RDYBOOST.SYS
[9C3AC71A9934B884FAC567A8807E9C4D][1
31800
]C:\WINDOWS\SYSTEM32\DRIVERS\REVOFLT.SYS
[DDC86E4F8E7456261E637E3552E804FF][1
76800
]C:\WINDOWS\SYSTEM32\DRIVERS\RSPNDR.SYS
[AC4CA62572CA516945AB92D6C9F501F4][1
888536
]C:\WINDOWS\SYSTEM32\DRIVERS\RT64WIN7.SYS
[B48DC6ABCD3AEFF8618350CCBDC6B09A][1
35088
]C:\WINDOWS\SYSTEM32\DRIVERS\sadp_npf.sys
[351533ACC2A069B94E80BBFC177E8FDF][1
35344
]C:\WINDOWS\SYSTEM32\DRIVERS\sadp_npf64.sys
[AC03AF3329579FFFB455AA2DAABBE22B][1
103808
]C:\WINDOWS\SYSTEM32\DRIVERS\SBP2PORT.SYS
[253F38D0D7074C02FF8DEB9836C97D2B][1
29696
]C:\WINDOWS\SYSTEM32\DRIVERS\SCFILTER.SYS

[07F83829E7429E60298440CD1E601A6A][1
21984 643383938D5E0D4FD30D302AF3E
9293A4798E392
]C:\WINDOWS\SYSTEM32\DRIVERS\SEMAV6MSR64.SYS
[CB624C0035412AF0DEBEC78C41F5CA1B][1
23552
]C:\WINDOWS\SYSTEM32\DRIVERS\SERENUM.SYS
[C1D8E28B2C2ADFAEC4BA89E9FDA69BD6][1
94208
]C:\WINDOWS\SYSTEM32\DRIVERS\SERIAL.SYS
[1C545A7D0691CC4A027396535691C3E3][1
26624
]C:\WINDOWS\SYSTEM32\DRIVERS\SERMOUSE.SYS
[A554811BCD09279536440C964AE35BBF][1
14336
]C:\WINDOWS\SYSTEM32\DRIVERS\SFFDISK.SYS
[FF414F0BAEFEBA59BC6C04B3DB0B87BF][1
13824
]C:\WINDOWS\SYSTEM32\DRIVERS\SFFP_MMC.SYS
[DD85B78243A19B59F0637DCF284DA63C][1
14336
]C:\WINDOWS\SYSTEM32\DRIVERS\SFFP_SD.SYS
[A9D601643A1647211A1EE2EC4E433FF4][1
16896
]C:\WINDOWS\SYSTEM32\DRIVERS\SFLOPPY.SYS
[843CAF1E5FDE1FFD5FF768F23A51E2E1][1
43584
]C:\WINDOWS\SYSTEM32\DRIVERS\SISRAID2.SYS
[6A6C106D42E9FFFF8B9FCB4F754F6DA4][1
80464
]C:\WINDOWS\SYSTEM32\DRIVERS\SISRAID4.SYS
[548260A7B8654E024DC30BF8A7C5BAA4][1
93184
]C:\WINDOWS\SYSTEM32\DRIVERS\SMB.SYS
[7B90D750DCBF72524DD38B105D29F8C1][1
3552512 62E5ADEE4575AF6349BE6482905
3553049863367
]C:\WINDOWS\SYSTEM32\DRIVERS\SNP2UVC.SYS
[441FBA48BFF01FDB9D5969EBC1838F0B][1
467456
]C:\WINDOWS\SYSTEM32\DRIVERS\SRV.SYS
[B4ADEBBF5E3677CCE9651E0F01F7CC28][1
410112
]C:\WINDOWS\SYSTEM32\DRIVERS\SRV2.SYS
[27E461F0BE5BFF5FC737328F749538C3][1
168448
]C:\WINDOWS\SYSTEM32\DRIVERS\SRVNET.SYS
[30710AEFCE721CEEE0F35EB6A01C263C][1
110336
]C:\WINDOWS\SYSTEM32\DRIVERS\SSUDBUS.SYS
[91310683D7B6B292B746D60734B59322][1
206080
]C:\WINDOWS\SYSTEM32\DRIVERS\SSUDMDM.SYS
[B5D5A1846972B7F93BDC6333272D750E][1
206080 7F25C61E6EFA67D6421159129C7
09EEE7A934D16
]C:\WINDOWS\SYSTEM32\DRIVERS\SSUDOBEX.SYS
[F7093A27C4AF6D9EEA0ACAC1C4FF6828][1
206080 23BCA6DAD98AE0EE70725C2AFF6
8240747331098
]C:\WINDOWS\SYSTEM32\DRIVERS\SSUDSERD.SYS
[F3817967ED533D08327DC73BC4D5542A][1
24656
]C:\WINDOWS\SYSTEM32\DRIVERS\STEXSTOR.SYS
[D34E4943D5AC096C8EDEEBFD80D76E23][1
34688
]C:\WINDOWS\SYSTEM32\DRIVERS\STORVSC.SYS
[D01EC09B6711A5F8E7E6564A4D0FBC90][1
12496
]C:\WINDOWS\SYSTEM32\DRIVERS\SWENUM.SYS
[
-2][0
-1
]C:\WINDOWS\SYSTEM32\DRIVERS\SYNTH3DVSC.SYS
[40AF23633D197905F03AB5628C558C51][1
1903552
]C:\WINDOWS\SYSTEM32\DRIVERS\TCPIP.SYS
[DF687E3D8836BFB04FCC0615BF15A519][1
45056
]C:\WINDOWS\SYSTEM32\DRIVERS\TCPIPREG.SYS
[3371D21011695B16333A3934340C4E7C][1
15872
]C:\WINDOWS\SYSTEM32\DRIVERS\TDPIPE.SYS
[51C5ECEB1CDEE2468A1748BE550CFBC8][1
23552
]C:\WINDOWS\SYSTEM32\DRIVERS\TDTCP.SYS
[DDAD5A7AB24D8B65F8D724F5C20FD806][1
119296
]C:\WINDOWS\SYSTEM32\DRIVERS\TDX.SYS
[561E7E1F06895D78DE991E01DD0FB6E5][1
63360
]C:\WINDOWS\SYSTEM32\DRIVERS\TERMDD.SYS
[4CE278FC9671BA81A138D70823FCAA09][1
39936
]C:\WINDOWS\SYSTEM32\DRIVERS\TSSECSRV.SYS

[D11C783E3EF9A3C52C0EBE83CC5000E9][1
59392
]C:\WINDOWS\SYSTEM32\DRIVERS\TSUSBFLT.SYS
[
-2][0
-1
]C:\WINDOWS\SYSTEM32\DRIVERS\TSUSBHUB.SYS
[3566A8DAAFA27AF944F5D705EAA64894][1
125440
]C:\WINDOWS\SYSTEM32\DRIVERS\TUNNEL.SYS
[B4DD609BD7E282BFC683CEC7EAAAAD67][1
64080
]C:\WINDOWS\SYSTEM32\DRIVERS\UAGP35.SYS
[FF4232A1A64012BAA1FD97C7B67DF593][1
328192
]C:\WINDOWS\SYSTEM32\DRIVERS\UDFS.SYS
[4BFE1BC28391222894CBF1E7D0E42320][1
64592
]C:\WINDOWS\SYSTEM32\DRIVERS\ULIAGPKX.SYS
[DC54A574663A895C8763AF0FA1FF7561][1
48640
]C:\WINDOWS\SYSTEM32\DRIVERS\UMBUS.SYS
[B2E8E8CB557B156DA5493BBDDCC1474D][1
9728
]C:\WINDOWS\SYSTEM32\DRIVERS\UMPASS.SYS
[24E8F8C3BDF9CEFC2135F9A3C399F37D][1
12800 9A2A42B8FE27EEF1B0922D99A4E
2EC1F01DE941F
]C:\WINDOWS\SYSTEM32\DRIVERS\UnHackMeDrv.sys
[2C42E595E7E381596B9A14F88F5AE027][1
19968
]C:\WINDOWS\SYSTEM32\DRIVERS\USB80236.SYS
[7B28E2FBE75115660FAB31079C0A9F29][1
19968
]C:\WINDOWS\SYSTEM32\DRIVERS\USB8023X.SYS
[C9E9D59C0099A9FF51697E9306A44240][1
54784
]C:\WINDOWS\SYSTEM32\DRIVERS\USBAAPL64.SYS
[B0435098C81D04CAFFF80DDB746CD3A2][1
109824
]C:\WINDOWS\SYSTEM32\DRIVERS\USBAUDIO.SYS
[DCA68B0943D6FA415F0C56C92158A83A][1
99840
]C:\WINDOWS\SYSTEM32\DRIVERS\USBCCGP.SYS
[80B0F7D5CCF86CEB5D402EAAF61FEC31][1
100864
]C:\WINDOWS\SYSTEM32\DRIVERS\USBCIR.SYS
[18A85013A3E0F7E1755365D287443965][1
53248
]C:\WINDOWS\SYSTEM32\DRIVERS\USBEHCI.SYS
[8D1196CFBB223621F2C67D45710F25BA][1
343040
]C:\WINDOWS\SYSTEM32\DRIVERS\USBHUB.SYS
[765A92D428A8DB88B960DA5A8D6089DC][1
25600
]C:\WINDOWS\SYSTEM32\DRIVERS\USBOHCI.SYS
[73188F58FB384E75C4063D29413CEE3D][1
25088
]C:\WINDOWS\SYSTEM32\DRIVERS\USBPRINT.SYS
[D76510CFA0FC09023077F22C2F979D86][1
91648
]C:\WINDOWS\SYSTEM32\DRIVERS\USBSTOR.SYS
[DD253AFC3BC6CBA412342DE60C3647F3][1
30720
]C:\WINDOWS\SYSTEM32\DRIVERS\USBUHCI.SYS
[1F775DA4CF1A3A1834207E975A72E9D7][1
185344
]C:\WINDOWS\SYSTEM32\DRIVERS\USBVIDEO.SYS
[C5C876CCFC083FF3B128F933823E87BD][1
36432
]C:\WINDOWS\SYSTEM32\DRIVERS\VDRVROOT.SYS
[53E92A310193CB3C03BEA963DE7D9CFC][1
29184
]C:\WINDOWS\SYSTEM32\DRIVERS\VGA.SYS
[DA4DA3F5E02943C2DC8C6ED875DE68DD][1
29184
]C:\WINDOWS\SYSTEM32\DRIVERS\VGAPNP.SYS
[2CE2DF28C83AEAF30084E1B1EB253CBB][1
215936
]C:\WINDOWS\SYSTEM32\DRIVERS\VHDMP.SYS
[E5689D93FFE4E5D66C0178761240DD54][1
17488
]C:\WINDOWS\SYSTEM32\DRIVERS\VIAIDE.SYS
[86EA3E79AE350FEA5331A1303054005F][1
199552
]C:\WINDOWS\SYSTEM32\DRIVERS\VMBUS.SYS
[7DE90B48F210D29649380545DB45A187][1
21760
]C:\WINDOWS\SYSTEM32\DRIVERS\VMBUSHID.SYS
[BE8E5E5D53ACF71D4E8E686B68C99B04][1
85584
]C:\WINDOWS\SYSTEM32\DRIVERS\VMCI.SYS

[18AA5F4A3B1204AD00045EE5AD39BCDB][1
20560
]C:\WINDOWS\SYSTEM32\DRIVERS\VMNETADAPTER.SYS
[04CD4347CD9E8C40F78AD51F7FF426D0][1
46160
]C:\WINDOWS\SYSTEM32\DRIVERS\VMNETBRIDGE.SYS
[748FD60D1B73F50020CFD126F940543F][1
30800
]C:\WINDOWS\SYSTEM32\DRIVERS\VMNETUSERIF.SYS
[7FBB3F1EBB009F9F711B02D599DB1CE6][1
31824 620FBC2EE83E45D320C6F1635BC
22611F2CF1369
]C:\WINDOWS\SYSTEM32\DRIVERS\VMPARPORT.SYS
[E60C0A09F997826C7627B244195AB581][1
6656
]C:\WINDOWS\SYSTEM32\DRIVERS\VMS3CAP.SYS
[7785DC213270D2FC066538DAF94087E7][1
46464
]C:\WINDOWS\SYSTEM32\DRIVERS\VMSTORFL.SYS
[F347A28F63162FF82BDDAADC14935BA4][1
38456 2C0B2D6E8A247DF058116AB4DB4
9F4F927872D16
]C:\WINDOWS\SYSTEM32\DRIVERS\VMUSB.SYS
[CB41CC41F83C9A6081A2AE71251A16D5][1
64080
]C:\WINDOWS\SYSTEM32\DRIVERS\VMX86.SYS
[D2AAFD421940F640B407AEFAAEBD91B0][1
71552
]C:\WINDOWS\SYSTEM32\DRIVERS\VOLMGR.SYS
[A255814907C89BE58B79EF2F189B843B][1
363392
]C:\WINDOWS\SYSTEM32\DRIVERS\VOLMGRX.SYS
[0D08D2F3B3FF84E433346669B5E0F639][1
295808
]C:\WINDOWS\SYSTEM32\DRIVERS\VOLSNAP.SYS
[5E2016EA6EBACA03C04FEAC5F330D997][1
161872
]C:\WINDOWS\SYSTEM32\DRIVERS\VSMRAID.SYS
[108196FE0580A18AB6237EA36FD210F2][1
73296
]C:\WINDOWS\SYSTEM32\DRIVERS\VSOCK.SYS
[E7CE8988B98202A5CF429CA358D26CC5][1
33872
]C:\WINDOWS\SYSTEM32\DRIVERS\vstor2-mntapi20-shared.sys
[36D4720B72B5C5D9CB2B9C29E9DF67A1][1
24576
]C:\WINDOWS\SYSTEM32\DRIVERS\VWIFIBUS.SYS
[4E9440F4F152A7B944CB1663D3935A3E][1
27776
]C:\WINDOWS\SYSTEM32\DRIVERS\WACOMPEN.SYS
[356AFD78A6ED4457169241AC3965230C][1
88576
]C:\WINDOWS\SYSTEM32\DRIVERS\WANARP.SYS
[72889E16FF12BA0F235467D6091B17DC][1
21056
]C:\WINDOWS\SYSTEM32\DRIVERS\WD.SYS
[A3D04EBF5227886029B4532F20D026F7][1
14464
]C:\WINDOWS\SYSTEM32\DRIVERS\WDCSAM64.SYS
[E2C933EDBC389386EBE6D2BA953F43D8][1
785624
]C:\WINDOWS\SYSTEM32\DRIVERS\WDF01000.SYS
[611B23304BF067451A9FDEE01FBDD725][1
12800
]C:\WINDOWS\SYSTEM32\DRIVERS\WFPLWF.SYS
[05ECAEC3E4529A7153B3136CEB49F0EC][1
22096
]C:\WINDOWS\SYSTEM32\DRIVERS\WIMMOUNT.SYS
[FE88B288356E7B47B74B13372ADD906D][1
41984
]C:\WINDOWS\SYSTEM32\DRIVERS\WINUSB.SYS
[F6FF8944478594D0E414D3F048F0D778][1
14336
]C:\WINDOWS\SYSTEM32\DRIVERS\WMIACPI.SYS
[6BCC1D7D2FD2453957C5479A32364E52][1
21504
]C:\WINDOWS\SYSTEM32\DRIVERS\WS2IFSL.SYS
[AD12F5C7251BB8D575D560894E73CBBA][1
29288
]C:\WINDOWS\SYSTEM32\DRIVERS\WSAUDIODEVICE_383S(1).SYS
[D3381DC54C34D79B22CEE0D65BA91B7C][1
112128
]C:\WINDOWS\SYSTEM32\DRIVERS\WUDFPF.SYS
[CF8D590BE3373029D57AF80914190682][1
172544
]C:\WINDOWS\SYSTEM32\DRIVERS\WUDFRD.SYS
[E2DDA8726DA9CB5B2C4000C9018A9633][1
111104
]C:\WINDOWS\SYSTEM32\EAPSVC.DLL
[024352FEEC9042260BB4CFB4D79A206B][1
203264
]C:\WINDOWS\SYSTEM32\EHSTORSHELL.DLL

[4166F82BE4D24938977DD1746BE9B8A0][1
402944
]C:\WINDOWS\SYSTEM32\ES.DLL
[0438CAB2E03F4FB61455A7956026FE86][1
16384
]C:\WINDOWS\SYSTEM32\FDPHOST.DLL
[802496CB59A30349F9A6DD22D6947644][1
34816
]C:\WINDOWS\SYSTEM32\FDRESPUB.DLL
[C4C183E6551084039EC862DA1C945E3D][1
1175552
]C:\WINDOWS\SYSTEM32\FNTCACHE.DLL
[19E41CCCEE697CC9465396B370929792][1
41984
]C:\WINDOWS\SYSTEM32\FXSMON.DLL
[DBEFD454F8318A0EF691FDD2EAAB44EB][1
689152
]C:\WINDOWS\SYSTEM32\FXSSVC.EXE
[0D09040EF933C3216CA5DD98E1744902][1
1128472 0F07C956836A14FC5C2F746EC9B
E6F147921D059
]C:\WINDOWS\SYSTEM32\GOOGLEINPUTTOOLS.IME
[277BBC7E1AA1EE957F573A10ECA7EF3A][1
777728
]C:\WINDOWS\SYSTEM32\GPSVC.DLL
[EDFEF3A8E4AFCCC2B6DBD163D81279FD][2
675893 3F8F976A2BF657EE8E4AD43B839
C4BD37BE08973
]C:\WINDOWS\SYSTEM32\HCNETSDK.DLL
[BD9EB3958F213F96B97B1D897DEE006D][1
38912
]C:\WINDOWS\SYSTEM32\HIDSERV.DLL
[F2AF0043DD39D1B31A58321DF9803660][2
407552 F1124D6F615427796C5E9D8DD69
5F2C8FE501582
]C:\WINDOWS\SYSTEM32\HPM1210LM.DLL
[23AB0B409A20DD110751B032F83F0B2D][2
139337 70A9389F8AF69CB12D50D788077
EF2E604927D05
]C:\WINDOWS\SYSTEM32\HPR.DLL
[2334DC48997BA203B794DF3EE70521DB][2
71680
]C:\WINDOWS\SYSTEM32\HPZINW12.DLL
[AC78DF349F0E4CFB8B667C0CFFF83CCE][2
89600
]C:\WINDOWS\SYSTEM32\HPZIPM12.DLL
[A3A132CBE48AF0324466469F2CAAE8A2][1
111616
]C:\WINDOWS\SYSTEM32\IEETWCOLLECTOR.EXE
[344789398EC3EE5A4E00C52B31847946][1
859648
]C:\WINDOWS\SYSTEM32\IKEEXT.DLL
[DA6C4B5FEEEA4DC7162B5D0C055EB967][1
22016
]C:\WINDOWS\SYSTEM32\IMAADP32.ACM
[142E90CF1A4C5B6E7505810E38B07B9F][1
976896
]C:\WINDOWS\SYSTEM32\INETCOMM.DLL
[098A91C54546A3B878DAD6A7E90A455B][1
101888
]C:\WINDOWS\SYSTEM32\IPBUSENUM.DLL
[A34A587FFFD45FA649FBA6D03784D257][1
569344
]C:\WINDOWS\SYSTEM32\IPHLPSVC.DLL
[B95F6501A2F8B2E78C697FEC401970CE][1
359424
]C:\WINDOWS\SYSTEM32\IPNATHLP.DLL
[4F15D75ADF6156BF56ECED6D4A55C389][1
501248
]C:\WINDOWS\SYSTEM32\IPSECSVC.DLL
[808E98FF49B155C522E6400953177B08][1
156672
]C:\WINDOWS\SYSTEM32\ISCSIEXE.DLL
[06DC527364A8CF48E472ECF2BA3F8403][1
170496
]C:\WINDOWS\SYSTEM32\ITSS.DLL
[5CE9241C030C004FF92037DF8F7401B0][1
54272
]C:\WINDOWS\SYSTEM32\IYUV_32.DLL
[B19C8390A1D641B9AC4490D4828A7B5E][1
728064
]C:\WINDOWS\SYSTEM32\KERBEROS.DLL
[387E72E739E15E3D37907A86D9FF98E2][1
90624
]C:\WINDOWS\SYSTEM32\KMSVC.DLL
[EFDFB3DD38A4376F93E7985173813ABD][1
232448
]C:\WINDOWS\SYSTEM32\LISTSVC.DLL
[C1185803384AB3FEED115F79F109427F][1
300032
]C:\WINDOWS\SYSTEM32\LLTDSVC.DLL
[F993A32249B66C9D622EA5592A8B76B8][1
23552
]C:\WINDOWS\SYSTEM32\LMHSVC.DLL

[45CFBFA8EDC3DF4E2B7FB0D0260FE051][1
956928
]C:\WINDOWS\SYSTEM32\LOCALSPL.DLL
[D5BA242D4CF8E384DB90E6A8ED850B8C][1
10240
]C:\WINDOWS\SYSTEM32\LOCATOR.EXE
[204F3F58212B3E422C90BD9691A2DF28][1
31232
]C:\WINDOWS\SYSTEM32\LSASS.EXE
[0BE09CD858ABF9DF6ED259D57A1A1663][1
84992
]C:\WINDOWS\SYSTEM32\MCX2SVC.DLL
[CA2A0750ED830678997695FF61B04C30][1
20480
]C:\WINDOWS\SYSTEM32\MIDIMAP.DLL
[E40E80D0304A73E8D269F7141D77250B][1
67584
]C:\WINDOWS\SYSTEM32\MMCSS.DLL
[254FB7A22D74E5511C73A3F6D802F192][1
97792
]C:\WINDOWS\SYSTEM32\MPRDIM.DLL
[54FFC9C8898113ACE189D4AA7199D2C1][1
828416
]C:\WINDOWS\SYSTEM32\MPSSVC.DLL
[1B7C3A37362C7B2890168C5FC61C8D9B][1
25600
]C:\WINDOWS\SYSTEM32\MSACM32.DRV
[329FEB3452982A377726DEDAFE9BBDF0][1
24064
]C:\WINDOWS\SYSTEM32\MSADP32.ACM
[A08C010D859F8EB42BDD7E1D55B8CA27][1
444752
]C:\WINDOWS\SYSTEM32\MSCOREE.DLL
[DE0ECE52236CFA3ED2DBFC03F28253A8][1
141824
]C:\WINDOWS\SYSTEM32\MSDTC.EXE
[6AB66E16AA859232F64DEB66887A8C9C][1
368640
]C:\WINDOWS\SYSTEM32\MSDTCKRM.DLL
[1C81E1BEA4847F406BBDB74D19721CE6][1
14848
]C:\WINDOWS\SYSTEM32\MSG711.ACM
[E5B9A2FA94D21C44DA2B898DC326B0C2][1
29184
]C:\WINDOWS\SYSTEM32\MSGSM32.ACM
[A190DA6546501CB4146BBCC0B6A3F48B][1
128000
]C:\WINDOWS\SYSTEM32\MSIEXEC.EXE
[45989C268EC2CC9EEA80030AF96CDA5A][1
16384
]C:\WINDOWS\SYSTEM32\MSRLE32.DLL
[E2A483E796D5FC7E447725FD01D98FA0][1
314880
]C:\WINDOWS\SYSTEM32\MSV1_0.DLL
[69A4347A8EAD86185EFF2F75755176E6][1
38912
]C:\WINDOWS\SYSTEM32\MSVIDC32.DLL
[B94D3DACCF5882B697A1C53D00BE643A][1
25600
]C:\WINDOWS\SYSTEM32\MSYUV.DLL
[847D3AE376C0817161A14A82C8922A9E][1
360448
]C:\WINDOWS\SYSTEM32\NETMAN.DLL
[5F28111C648F1E24F7DBC87CDEB091B8][1
459776
]C:\WINDOWS\SYSTEM32\NETPROFM.DLL
[AE5FC277F90C260CEA8E531085C46932][2
172032 76660C2E5C338A883992DEC63ED
21D47D6D54138
]C:\WINDOWS\SYSTEM32\NETVIDEOACTIVEX23.OCX
[1EE99A89CC788ADA662441D1E9830529][1
303616
]C:\WINDOWS\SYSTEM32\NLASVC.DLL
[D54BFDF3E0C953F823B3D0BFE4732528][1
25600
]C:\WINDOWS\SYSTEM32\NSISVC.DLL
[7BBF670114373CE6A203FA155A9E0D0A][1
509952
]C:\WINDOWS\SYSTEM32\NTSHRUI.DLL
[927463ECB02179F88E4B9A17568C63C3][1
438784
]C:\WINDOWS\SYSTEM32\P2PSVC.DLL
[3AEAA8B561E63452C655DC0584922257][1
186368
]C:\WINDOWS\SYSTEM32\PCASVC.DLL
[E08088A97F95345E181C3DFCE2C615EF][1
240640
]C:\WINDOWS\SYSTEM32\PKU2U.DLL
[C7CF6A6E137463219E1259E3F0F0DD6C][1
1389056
]C:\WINDOWS\SYSTEM32\PLA.DLL

[204FFF339146F88D0074B1E11C989479][2
188416 A17A91B51527817506978A254DE
6D3C6E9D39718
]C:\WINDOWS\SYSTEM32\PLAYBACKACTIVEX23.OCX
[5E6673A9FD85570B41014ECE99F59AC9][2
69632 0890ED557EB1A3FCAF0C54B24A3
F09D4E9C8D890
]C:\WINDOWS\SYSTEM32\PLAYBACKBARACTIVEX.OCX
[415221BE510B140E585B3CBEEF14F243][2
1146968 E42F6DE8DBA0E0ECAE7DBC89049
02630749EB157
]C:\WINDOWS\SYSTEM32\PLAYCTRL.DLL
[3EAC4455472CC2C97107B5291E0DCAFE][1
327168
]C:\WINDOWS\SYSTEM32\PNRPSVC.DLL
[5C78838B4D166D1A27DB3A8A820C799A][1
209920
]C:\WINDOWS\SYSTEM32\PROFSVC.DLL
[908ACB1F594274965A53926B10C81E89][1
187904
]C:\WINDOWS\SYSTEM32\PROVSVC.DLL
[C32ECB99AD25E9A04F01C8665DF29EF8][1
19152
]C:\WINDOWS\SYSTEM32\PWDRVIO.SYS
[D619356B955EEFA642F5FF72755E8B3C][1
12504
]C:\WINDOWS\SYSTEM32\PWDSPIO.SYS
[582AC6D9873E31DFA28A4547270862DD][1
476160
]C:\WINDOWS\SYSTEM32\QAGENTRT.DLL
[1EA7969E3271CBC59E1730697DC74682][1
849920
]C:\WINDOWS\SYSTEM32\QMGR.DLL
[906191634E99AEA92C4816150BDA3732][1
242688
]C:\WINDOWS\SYSTEM32\QWAVE.DLL
[8F26510C5383B8DBE976DE1CD00FC8C7][1
99328
]C:\WINDOWS\SYSTEM32\RASAUTO.DLL
[EE867A0870FC9E4972BA9EAAD35651E2][1
344064
]C:\WINDOWS\SYSTEM32\RASMANS.DLL
[9D0A80C3528CA6A1F808F6408A1BB08D][2
262144 097A2DDA4D31DDA065826D59C23
1B16311094F71
]C:\WINDOWS\SYSTEM32\REALPLAYACTIVEX23.OCX
[E4D94F24081440B5FC5AA556C7C62702][1
159232
]C:\WINDOWS\SYSTEM32\REGSVC.DLL
[0BC4CC55C598C0F1FA8F4A09A05BC577][2
49152 3FF74FB55ACA12EE20EE7E9CBF3
E73D31DC46EDA
]C:\WINDOWS\SYSTEM32\REMCONFIGRES_CHI.DLL
[0C57E1C6000ECC43D2987FA15F992ACA][2
81920 DF2762588B54913442F5D657390
587E79659E576
]C:\WINDOWS\SYSTEM32\REMCONFIGRES_ENG.DLL
[E4DC58CF7B3EA515AE917FF0D402A7BB][1
67072
]C:\WINDOWS\SYSTEM32\RPCEPMAP.DLL
[5C627D1B1138676C0A7AB2C2C190D123][1
512000
]C:\WINDOWS\SYSTEM32\RPCSS.DLL
[9B7395789E3791A3B6D000FE6F8B131E][1
190976
]C:\WINDOWS\SYSTEM32\SCARDSVR.DLL
[ED78427259134C63ED69804D2132B86C][1
232960
]C:\WINDOWS\SYSTEM32\SCECLI.DLL
[481F70241D4EA038BB02590A30F15A23][1
340992
]C:\WINDOWS\SYSTEM32\SCHANNEL.DLL
[262F6592C3299C005FD6BEC90FC4463A][1
1110016
]C:\WINDOWS\SYSTEM32\SCHEDSVC.DLL
[6EA4234DC55346E0709560FE7C2C1972][1
170496
]C:\WINDOWS\SYSTEM32\SDRSVC.DLL
[AD31942BDF3D594C404874613BC2FE4D][1
593408
]C:\WINDOWS\SYSTEM32\SEARCHINDEXER.EXE
[C96DD70C6F5F49C3EA7D37C6BB1DD9CF][2
135168 3357E885D997EEC4C5D4B3C2A02
4C3B5A9FF164F
]C:\WINDOWS\SYSTEM32\SEARCHLOGACTIVEX23.OCX
[BC617A4E1B4FA8DF523A061739A0BD87][1
30720
]C:\WINDOWS\SYSTEM32\SECLOGON.DLL
[C32AB8FA018EF34C0F113BD501436D21][1
64512
]C:\WINDOWS\SYSTEM32\SENS.DLL
[0336CFFAFAAB87A11541F1CF1594B2B2][1
29184
]C:\WINDOWS\SYSTEM32\SENSRSVC.DLL
[0B6231BF38174A1628C4AC812CC75804][1
121856
]C:\WINDOWS\SYSTEM32\SESSENV.DLL

[427015D56DF17241F634611557146C57][1
14175744
]C:\WINDOWS\SYSTEM32\SHELL32.DLL
[1E60EB6AB71EB7FCDC61688D6A2AADD4][2
880640 FEFE783954FD594C595FA3B0BD5
B3417CC4DDA62
]C:\WINDOWS\SYSTEM32\SHOWREMCONFIG.DLL
[AAF932B4011D14052955D4B212A4DA8D][1
370688
]C:\WINDOWS\SYSTEM32\SHSVCS.DLL
[6313F223E817CC09AA41811DAA7F541D][1
14336
]C:\WINDOWS\SYSTEM32\SNMPTRAP.EXE
[350A8C7BDBEE961221EB913A76B71186][1
60384
]C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\X64\3\CNAB4LAD.EXE
[B96C17B5DC1424D56EEA3A99E97428CD][1
559104
]C:\WINDOWS\SYSTEM32\SPOOLSV.EXE
[E17E0188BB90FAE42D83E98707EFA59C][1
3524608
]C:\WINDOWS\SYSTEM32\SPPSVC.EXE
[93D7D61317F3D4BC4F4E9F8A96A7DE45][1
65536
]C:\WINDOWS\SYSTEM32\SPPUINOTIFY.DLL
[D9F42719019740BAA6D1C6D536CBDAA6][1
236032
]C:\WINDOWS\SYSTEM32\SRVSVC.DLL
[51B52FBD583CDE8AA9BA62B8B4298F33][1
193024
]C:\WINDOWS\SYSTEM32\SSDPSRV.DLL
[AB7AEBF58DAD8DAAB7A6C45E6A8885CB][1
75264
]C:\WINDOWS\SYSTEM32\SSTPSVC.DLL
[33AE24A438549A216FDF82DB554224B2][2
143434 5947A0F5ADE4A3738AD75FECAB5
4258C3074EC74
]C:\WINDOWS\SYSTEM32\STREAMTRANSCLIENT.DLL
[C78655BC80301D76ED4FEF1C1EA40A7D][1
27136
]C:\WINDOWS\SYSTEM32\SVCHOST.EXE
[E08E46FDD841B7184194011CA1955A0B][1
524288
]C:\WINDOWS\SYSTEM32\SWPRV.DLL
[A10B048B681C38E26CA90CD1BC123604][1
200192
]C:\WINDOWS\SYSTEM32\SYNCUI.DLL
[BF9CCC0BF39B418C8D0AE8B05CF95B7D][1
1743360
]C:\WINDOWS\SYSTEM32\SYSMAIN.DLL
[870726CDCC241A92785572628B89CC07][1
82432
]C:\WINDOWS\SYSTEM32\SYSTEMPROPERTIESPERFORMANCE.EXE
[7FB87C7F816CDBC91149644DF926ED09][2
217205 07CF390F1E4E19BC3267A998458
544C4748EAC82
]C:\WINDOWS\SYSTEM32\SYSTEMTRANSFORM.DLL
[E3C61FD7B7C2557E1F1B0B4CEC713585][1
92672
]C:\WINDOWS\SYSTEM32\TABSVC.DLL
[40F0849F65D13EE87B9A9AE3C1DD6823][1
316928
]C:\WINDOWS\SYSTEM32\TAPISRV.DLL
[1BE03AC720F4D302EA01D40F588162F6][1
65536
]C:\WINDOWS\SYSTEM32\TBSSVC.DLL
[32A3C8600AF124CBAAD845F13CFAE3CB][6
195072
]C:\WINDOWS\SYSTEM32\TCPMON.DLL
[2E648163254233755035B46DD7B89123][1
680960
]C:\WINDOWS\SYSTEM32\TERMSRV.DLL
[F0344071948D1A1FA732231785A0664C][1
44544
]C:\WINDOWS\SYSTEM32\THEMESERVICE.DLL
[7E7AFD841694F6AC397E99D75CEAD49D][1
119808
]C:\WINDOWS\SYSTEM32\TRKWKS.DLL
[CEED624D1291081B1B7D921FBB9C61D9][1
14848
]C:\WINDOWS\SYSTEM32\TSBYUV.DLL
[B6D8C1202DACA028AD94BDA2795CBBE9][1
86528
]C:\WINDOWS\SYSTEM32\TSPKG.DLL
[3CBDEC8D06B9968ABA702EBA076364A1][1
40960
]C:\WINDOWS\SYSTEM32\UI0DETECT.EXE
[25FBDEF06C4D92815B353F6E792C8129][1
404480
]C:\WINDOWS\SYSTEM32\UMPNPMGR.DLL
[6BA9D927DDED70BD1A9CADED45F8B184][1
163840
]C:\WINDOWS\SYSTEM32\UMPO.DLL

[A293DCD756D04D8492A750D03B9A297C][1
214528
]C:\WINDOWS\SYSTEM32\UMRDP.DLL
[64B328D52DFC8CDA123093E3F6E4C37C][1
323584
]C:\WINDOWS\SYSTEM32\UNREGMP2.EXE
[D47EC6A8E81633DD18D2436B19BAF6DE][1
353792
]C:\WINDOWS\SYSTEM32\UPNPHOST.DLL
[DF72A9936D0C3F517083119648814B09][6
45056
]C:\WINDOWS\SYSTEM32\USBMON.DLL
[BAFE84E637BF7388C96EF48D4D3FDD53][1
30720
]C:\WINDOWS\SYSTEM32\USERINIT.EXE
[EDBB23CBCF2CDF727D64FF9B51A6070E][1
38912
]C:\WINDOWS\SYSTEM32\UXSMS.DLL
[8D6B481601D01A456E75C3210F1830BE][1
533504
]C:\WINDOWS\SYSTEM32\VDS.EXE
[D9B422F37FCAF61BD80E12CC03E84816][1
437328
]C:\WINDOWS\SYSTEM32\VMNAT.EXE
[5DC2DA538FF0806950B73F798A2444ED][1
358480
]C:\WINDOWS\SYSTEM32\VMNETDHCP.EXE
[B60BA0BC31B0CB414593E169F6F21CC2][1
1600512
]C:\WINDOWS\SYSTEM32\VSSVC.EXE
[1C9D80CC3849B3788048078C26486E1A][1
381952
]C:\WINDOWS\SYSTEM32\W32TIME.DLL
[3CEC96DE223E49EAAE3651FCF8FAEA6C][1
1255736
]C:\WINDOWS\SYSTEM32\WAT\WATADMINSVC.EXE
[A3F5E8EC1316C3E2562B82694A251C9E][1
909312
]C:\WINDOWS\SYSTEM32\WBEM\FASTPROX.DLL
[38B84C94C5A8AF291ADFEA478AE54F93][1
203264
]C:\WINDOWS\SYSTEM32\WBEM\WMIAPSRV.EXE
[19B07E7E8915D701225DA41CB3877306][1
242688
]C:\WINDOWS\SYSTEM32\WBEM\WMISVC.DLL
[78F4E7F5C56CB9716238EB57DA4B6A75][1
1504256
]C:\WINDOWS\SYSTEM32\WBENGINE.EXE
[3AA101E8EDAB2DB4131333F4325C76A3][1
202240
]C:\WINDOWS\SYSTEM32\WBIOSRVC.DLL
[7368A2AFD46E5A4481D1DE9D14848EDD][1
367104
]C:\WINDOWS\SYSTEM32\WCNCSVC.DLL
[20F7441334B18CEE52027661DF4A6129][1
40960
]C:\WINDOWS\SYSTEM32\WCSPLUGINSERVICE.DLL
[BF1FC3F79B863C914687A737C2F3D681][1
90624
]C:\WINDOWS\SYSTEM32\WDI.DLL
[26AF184300C0868D854D5A3092234E24][1
210944
]C:\WINDOWS\SYSTEM32\WDIGEST.DLL
[1473768973453DE50DC738C2955FC4DD][1
217088
]C:\WINDOWS\SYSTEM32\WDMAUD.DRV
[3DB6D04E1C64272F8B14EB8BC4616280][1
258560
]C:\WINDOWS\SYSTEM32\WEBCLNT.DLL
[C749025A679C5103E575E3B48E092C43][1
237568
]C:\WINDOWS\SYSTEM32\WECSVC.DLL
[7E591867422DC788B9E5BD337A669A08][1
84480
]C:\WINDOWS\SYSTEM32\WERCPLSUPPORT.DLL
[6D137963730144698CBD10F202E9F251][1
76800
]C:\WINDOWS\SYSTEM32\WERSVC.DLL
[8DD52E8E6128F4B2DA92CE27402871C1][1
580096
]C:\WINDOWS\SYSTEM32\WIASERVC.DLL
[58F4493BF748A3A89689997B7BD00E95][1
444416
]C:\WINDOWS\SYSTEM32\WINHTTP.DLL
[851A1382EED3E3A7476DB004F4EE3E1A][1
118784
]C:\WINDOWS\SYSTEM32\WKSSVC.DLL
[4FADA86E62F18A1B2F42BA18AE24E6AA][1
886784
]C:\WINDOWS\SYSTEM32\WLANSVC.DLL

[96C6E7100D724C69FCF9E7BF590D1DCA][1
12288
]C:\WINDOWS\SYSTEM32\WPCSVC.DLL
[93221146D4EBBF314C29B23CD6CC391D][1
117248
]C:\WINDOWS\SYSTEM32\WPDBUSENUM.DLL
[E8B1FE6669397D1772D8196DF0E57A9E][1
97280
]C:\WINDOWS\SYSTEM32\WSCSVC.DLL
[A1D7E3ADCDB07DDB6F423862DCB1A52B][6
224768
]C:\WINDOWS\SYSTEM32\WSDMON.DLL
[581B739BEF5B6B668E5308CFE956B84A][1
96328 1B26127179A033C653D746669F1
E596378530A38
]C:\WINDOWS\SYSTEM32\WSMONEDITOR.DLL
[BCB1310604AA415C4508708975B3931E][1
2018304
]C:\WINDOWS\SYSTEM32\WSMSVC.DLL
[D9EF901DCA379CFE914E9FA13B73B4C4][1
2428952
]C:\WINDOWS\SYSTEM32\WUAUENG.DLL
[7A95C95B6C4CF292D689106BCAE49543][1
78848
]C:\WINDOWS\SYSTEM32\WUDFSVC.DLL
[9A3452B3C2A46C073166C5CF49FAD1AE][1
229888
]C:\WINDOWS\SYSTEM32\WWANSVC.DLL
[241A1900C52DCBA38B20A4F3671444E0][1
1036800
]C:\WINDOWS\SYSWOW64\D3D8.DLL
[351533ACC2A069B94E80BBFC177E8FDF][1
35344
]C:\WINDOWS\SYSWOW64\DRIVERS\SADP_NPF64.SYS
[2AFBB91BBD2378933B26E6D68C140D1B][1
11745792
]C:\WINDOWS\SYSWOW64\IEFRAME.DLL
[1C7F1C3EA5894995E6C563E9AE9F029F][1
64000
]C:\WINDOWS\SYSWOW64\L3CODECA.ACM
[28FFB14117CCEDD7D2F124596AA9B785][1
269504 3F6B83D48CF182C60EC6416AC9D
0E0A116916560
]C:\WINDOWS\SYSWOW64\MACROMED\FLASH\FLASHPLAYERUPDATESERVICE.EX
E
[EA85144F35EDE6EE25C484D4242FF2C8][1
17387008
]C:\WINDOWS\SYSWOW64\MSHTML.DLL
[59D16C3D5CC0D573256A01783ED5CCB4][1
2291712
]C:\WINDOWS\SYSWOW64\MSVIDCTL.DLL
[E94C583CDE2348950155F2AF2876F34D][1
231424
]C:\WINDOWS\SYSWOW64\MSWSOCK.DLL
[0B7E85364CB878E2AD531DB7B601A9E5][1
52224
]C:\WINDOWS\SYSWOW64\NAPINSP.DLL
[104A1070E90F1C530328E69B49718841][1
52224
]C:\WINDOWS\SYSWOW64\NLAAPI.DLL
[703FFD301AB900B047337C5D40FD6F96][1
90112
]C:\WINDOWS\SYSWOW64\OLEPRO32.DLL
[E495E408C93141E8FC72DC0C6046DDFA][1
20992
]C:\WINDOWS\SYSWOW64\PERFHOST.EXE
[5CF640EDDB1E40A5AB1BB743BCDEC610][1
65024
]C:\WINDOWS\SYSWOW64\PNRPNSP.DLL
[76F58DB8F85C125E0D6B3AA42F3BF1D0][1
1143808
]C:\WINDOWS\SYSWOW64\URLMON.DLL
[5DF5D8CFD9B9573FA3B2C89D9061A240][1
20992
]C:\WINDOWS\SYSWOW64\WINRNR.DLL
[BD153B7E600EAC648FBE9C6C2F694B5D][2
320512 6D6D7AA2B4A3D2D11BC4FD3A550
551F6D7B2B18D
]C:\WINDOWS\TSNP2UVC.EXE
[C893A71AE21E9852027B7F0BC499B23F][2
1430 A7D959AE2AF69FF46A20E110C75
410ECD0A81823
]C:\WINDOWS\UPDATE.JS
[
-2][0
-1
]CAMCODEC.DLL
[
-2][0
-1
]ICCVID.DLL
[
-2][0
-1
]SYSWOW64\DRIVERS\VSTOR2-MNTAPI20-SHARED.SYS
[
-2][0
-1

]TSCCVID.DLL
===
[MBR]
[MD5=004BC502E8A0AB7DDDB5C2C67E1CDFEE]
M8CO0LwAfI7Ajti+AHy/AAa5AAL886RQaBwGy/u5BAC9vgeAfgAAfAsPhQ4Bg8UQ4vHNGIhW
AFXGRhEFxkYQALRBu6pVzRNdcg+B+1WqdQn3wQEAdAP+RhBmYIB+EAB0JmZoAAAAAGb/dgho
AABoAHxoAQBoEAC0QopWAIv0zROfg8QQnusUuAECuwB8ilYAinYBik4Cim4DzRNmYXMc/k4R
dQyAfgCAD4SKALKA64RVMuSKVgDNE13rnoE+/n1VqnVu/3YA6I0AdRf6sNHmZOiDALDf5mDo
fACw/+Zk6HUA+7gAu80aZiPAdTtmgftUQ1BBdTKB+QIBcixmaAe7AABmaAACAABmaAgAAABm
U2ZTZlVmaAAAAABmaAB8AABmYWgAAAfNGloy9uoAfAAAzRigtwfrCKC2B+sDoLUHMuQFAAeL
8Kw8AHQJuwcAtA7NEOvy9Ov9K8nkZOsAJALg+CQCw0ludmFsaWQgcGFydGl0aW9uIHRhYmxl
AEVycm9yIGxvYWRpbmcgb3BlcmF0aW5nIHN5c3RlbQBNaXNzaW5nIG9wZXJhdGluZyBzeXN0
ZW0AAABje5o=
===
[PT]
0x42 Unknown, 63, -387940239
===
[VBR]
61KQTlRGUyAgICAAAggAAAAAAAAA+AAAPwD/AAAIAAAAAAAAgACAAP//AwAAAAAAqioAAAAA
AAACAAAAAAAAAPYAAAABAAAAO8BDWAJEWLYAAAAA+jPAjtC8AHz7aMAHHx5oZgDLiBYOAGaB
PgMATlRGU3UVtEG7qlXNE3IMgftVqnUG98EBAHUD6d0AHoPsGGgaALRIihYOAIv0Fh/NE5+D
xBieWB9y4TsGCwB126MPAMEuDwAEHloz27kAICvIZv8GEQADFg8AjsL/BhYA6EsAK8h377gA
u80aZiPAdS1mgftUQ1BBdSSB+QIBch4WaAe7FmhwDhZoCQBmU2ZTZlUWFhZouAFmYQ4HzRoz
wL8oELnYD/zzqulfAZCQZmAeBmahEQBmAwYcAB5maAAAAABmUAZTaAEAaBAAtEKKFg4AFh+L
9M0TZllbWmZZZlkfD4IWAGb/BhEAAxYPAI7C/w4WAHW8Bx9mYcOg+AHoCQCg+wHoAwD06/20
AYvwrDwAdAm0DrsHAM0Q6/LDDQpBIGRpc2sgcmVhZCBlcnJvciBvY2N1cnJlZAANCkJPT1RN
R1IgaXMgbWlzc2luZwANCkJPT1RNR1IgaXMgY29tcHJlc3NlZAANClByZXNzIEN0cmwrQWx0
K0RlbCB0byByZXN0YXJ0DQoAjKm+1gAAVaoHAEIATwBPAFQATQBHAFIABAAkAEkAMwAwAADU
AAAAJAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAOsikJAFAE4AVABMAEQAUgAAAAAAAAAAAAAAAAAAAAAAAAAAAGYPtwYLAGYPth4NAGb3
42ajUgJmiw5AAID5AA+PDgD22Wa4AQAAAGbT4OsIkGahUgJm9+Fmo2YCZg+3HgsAZjPSZvfz
ZqNWAuiVBGaLDk4CZokOJgJmAw5mAmaJDioCZgMOZgJmiQ4uAmYDDmYCZokOPgJmAw5mAmaJ
DkYCZriQAAAAZosOJgLogwlmC8APhF7+ZqMyAma4oAAAAGaLDioC6GoJZqM2Ama4sAAAAGaL
Di4C6FgJZqM6AmahMgJmC8APhCv+Z4B4CAAPhSL+Z2aNUBBnA0IEZ2YPtkgMZokOcgJnZotI
CGaJDm4CZqFuAmYPtw4LAGYz0mb38WajdgJmoUYCZgMGbgJmo0oCZoM+NgIAD4QdAGaDPjoC
AA+Ez/1mix46Ah4HZos+SgJmoS4C6OABZg+3DgACZrgCAgAA6CIIZgvAD4UWAGYPtw5aAma4
XAIAAOgMCGYLwA+EQgxnZosAHgdmiz4+Aug/BmahPgJmuyAAAABmuQAAAABmugAAAADo5ABm
hcAPhSMAZqE+Ama7gAAAAGa5AAAAAGa6AAAAAOjEAGYLwA+FRADp8QtmM9JmuYAAAABmoT4C
6MoIZgvAD4TaCx4HZos+PgLo2wVmoT4CZruAAAAAZrkAAAAAZroAAAAA6IAAZgvAD4SwC2dm
D7dYDGaB4/8AAAAPhaULZovYaAAgB2Yr/2ahPgLoAAFoACAHZiv/ZqE+AuisCooWDgC46AOO
wI02CwArwGgAIFDLBh5mYGaL2mYPtg4NAGb34WajEQBmi8Nm9+GjFgCL34PjD4zAZsHvBAPH
UAfoPvxmYZAfB8NnA0AUZ2aDOP8PhEwAZ2Y5GA+FMwBmC8kPhQoAZ4B4CQAPhSMAw2c6SAkP
hRoAZovwZwNwCuiXBmZRHgdmi/rzp2ZZD4UBAMNnZoN4BAAPhAcAZ2YDQATrq2YrwMNmi/Po
bAZnZgMAZ/dADAIAD4U0AGdmjVAQZzpKQA+FGABnZo1yQuhJBmZRHgdmi/vzp2ZZD4UBAMNn
g3gIAA+EBgBnA0AI68JmM8DDZ4B7CAAPhRwABh5mYGdmjVMQZ2aLCmaL82cDcgTzpGZhkB8H
w2ZQZ2aNUxBmhcAPhQoAZ2aLSghmQesRkGdmi0IYZjPSZvc2UgJmi8hmK8BmXugBAMMGHmZg
Z4B7CAEPhAMA6Xb7ZoP5AA+FBgBmYZAfB8NmU2ZQZlFmVmZXBuiRBGaL0QdmX2ZeZllmhcAP
hDQAZjvKD40DAGaL0eiC/mYrymaL2maLwmYPthYNAGb34mYPtxYLAGb34mYD+GZYZgPDZlvr
n2aF9g+EDvtmUWZXBmdmD7ZDCWaFwA+EIABm0eBmK+Bmi/xmVGZWZ2YPt3MKZgPzZovI86Rm
XusDkGZQZlBnZosDZlBnZotDGGZQZ2aLViBmhdIPhAsAZov+Hgdmi8LocQNmi8ZmWmZZZkJm
UWZW6D8GZoXAD4Sd+mZeZllmi/4eB+hOA2aLxmaL2WZZZlpmUWZWZtHp6Pj9ZoXAD4R2+mZe
ZllmA+EHZl9mWWaL0GZYZltmi9rp9f4GHmZgJmdmD7dfBCZnZg+3TwZmC8kPhET6ZgPfZoPD
AmaBx/4BAABmSWYLyQ+EFwAmZ4sDJmeJB2aDwwJmgccAAgAAZknr4mZhkB8HwwYeZmBmuAEA
AABmoyICZqEeAmYDBmYCZqNqAmYDBmYCZqNOAmahMABmD7YeDQBm9+Nmix5OAmaJB2ajEQCD
wwRmoVYCZokHoxYAg8MEZokeTgJmix4eAh4H6Gf5Zov76FH/ZqEeAma7IAAAAGa5AAAAAGa6
AAAAAOgQ/WYLwA+EGQFmi9geB2aLPhoCZjPA6KL9ZoseGgJmgT+AAAAAD4TrAANfBOvwZlNm
i0cQZvcmVgJmUGYz0mYPth4NAGb382ZS6NwAZgvAD4RE+WaLDlYCZg+2Hg0AZvfjZlpmA8Jm
ix5OAmaJB4PDBGYPtgYNAGYrwmY7wQ+GAwBmi8FmiQdmK8hmWg+EdQBmA8JmUGYz0mYPth4N
AGb382ZR6IIAZllmC8APhOj4Zg+2Hg0AZvfjZoseTgJmixeDwwRmAxdmO9APhRUAZg+2Bg0A
ZjvBD4YDAGaLwWYBB+ulg8MEZokeTgJmiQeDwwRmD7YGDQBmO8EPhgMAZovBZokH64KDwwRm

/wYiAmaJHk4CZlsDXwRmgT+AAAAAD4QM/2ZhkB8Hw2aL0GaLDiICZos2agJmAzZmAmZSZlFm
UmaLHmoCZos+VgJmiwRmoxEAg8YEZosEoxYAg8YEHgfo6PdmK/gPhAgA9yYLAAPY69lmiz5q
Ah4H6L/9ZqFqAma7gAAAAGa5AAAAAGaL0eiB+2YLwA+E//dmi9hmWGZW6CwBZl5mC8APhAUA
ZltmW8NmWWZa4oRmM8DDBh5mYGZQZlFmM9JmD7YeDQBm9/NmUmZX6FP/Zl9mC8APhLn3Zg+2
Hg0AZvfjZlpmA8JmoxEAZllmD7YeDQBmO8sPjhMAiR4WAGYry2ZYZgPDZlBmUesUkGZYZgPB
ZlCJDhYAZrkAAAAAZlEGZleL34PjD4zAZsHvBAPHUAfoEPdmXwdmAz5SAmZZZlhmg/kAD49w
/2ZhkB8HwwYeZmBm9yZWAmaLDlYC6FX/6NL8ZmGQHwfDBh5mYGb3JnICZoseNgJmiw5yAmaL
NioCHgdmiz5GAuiB++in/GZhkB8Hw2ZQZlNmUWaLHkoCZovIZsHoA2aD4QdmA9hmuAEAAABm
0+BnhAMPhAQA+OsCkPlmWWZbZljDZ4B7CAEPhAQAZivAw2dmjXMQZ2aLVghmO8IPhwsAZ2aL
FmY7wg+DBABmK8DDZwNeEGYr9meAOwAPhD4A6IEAZgPx6DkAZgPKZjvBD4whAGaL0WZQZ2YP
tgtmi8Fmg+APZsHpBGYD2WYD2GZDZljrxGYryGYrwmYDxsNmK8DDZivJZ4oLgOEPZoP5AA+F
BABmK8nDZlNmUmYD2WdmD74TZklmS2aD+QAPhA0AZsHiCGeKE2ZLZknr62aLymZaZlvDZlNm
UmYr0meKE2aD4g9mK8lnigvA6QRmg/kAD4UIAGYryWZaZlvDZgPaZgPZZ2YPvhNmSWZLZoP5
AA+EDQBmweIIZ4oTZktmSevrZovKZlpmW8NmC8kPhQEAw2ZRZlZngz5hD4wMAGeDPnoPjwQA
Z4MuIGaDxgLi5mZeZlnDZlBmUWaL0GahMgJnZo1YEGcDQwRnZo1AEGaL2uhE+WYLwA+EBQBm
WWZZw2ahNgJmC8APhQgAZllmWWYzwMNmixY2AmdmjVIQZ2aLQhhmM9Jm9zZuAmYz9mZQZlZm
WGZeZjvGD4Q6AGZWZkBmUGZI6Bv+cujo6/1mWmZeZllmW2ZTZlFmVmZSZqFGAmdmjUAY6ND4
ZgvAdMRmWWZZZllmWcNmWWZZZjPAw2ZRZlBmuAUAAAAeB2aL+eiN/WaLwWa7IAAAAGa5AAAA
AGa6AAAAAOgz+GZbZllmhcAPhRUAZovBZg+3DhACZroSAgAA6Bb46zOQZjPSZovBZovLZlBm
U+gjAGZbZl9mC8APhBcAHgfoNf1mi8dmD7cOEAJmuhICAADo4ffDZlJmUWa7IAAAAGa5AAAA
AGa6AAAAAOjH92YLwA+EYwBmi9geB2aLPhoCZjPA6Fn4Hgdmix4aAmZZZlomZjkPD4UMACZm
OVcID4QxAOsTkCZmgz//D4QvACaDfwQAD4QmACZmD7dHBAPYi8MlAIB0y4zABQAIjsCB4/9/
674mZotHEMNmWWZaZjPAw2ZQZlFmi8dmwegEBlkDyFEHZoPnD2ZZZljDYAa+vQ2/ACAeB7kN
AJDzpQdhwwEjRWeJq83v/ty6mHZUMhDw4dLDAAAAACAgYIs2GCAmigWIBEdGZv8GFCCB/mAg
dQboWwC+ICDi5ok2GCBhw2ZgizYYILCAiARGMsCB/mAgdQboOgC+ICCB/lggdelmM8Bmo1gg
ZqEUIGbB4ANmD8hmo1wg6BgAuwAgZosHZg/IZokHg8MEgfs0IHXuZmHDZmC7ICBmiwdmD8hm
iQeDwwSB+2Agde67ACBmiw9mi1cEZot3CGaLfwxmi28QuyAgxwYaIDAPxgYcIBSQU4seGiD/
F2YDRwJbZgPoZgMvZovBZsHABWYDxWaL72aL/maL8mbBxh5mi9Fmi8hmiwdmM0cIZjNHIGYz
RzRm0cBmiUdAg8ME/g4cIHWygwYaIAaBPhogSA91n7sAIGYBD2YBVwRmAXcIZgF/DGYBbxBm
YcNmi8ZmM8dmI8JmM8fDZovCZjPGZjPHw2ZTZovCZiPGZovaZiPfZgvDZoveZiPfZgvDZlvD
/A6ZeYJaCQ+h69luEw/cvBuPCQ/WwWLKBh5mYGYz27gAu80aZiPAD4W7AGaB+1RDUEEPhbAA
gfkCAQ+CqABmYZAfBwYeZmBngHsIAA+FDABnZo1TEGdmiwrrJZBnZo1TEGdmi0ooZoH5AAAI
AA+DDABnZotCLGYjwA+EAwBmM8kOH+j1/WYjyQ+EMgBmugCAAABmO8oPhh8AZivKBmZRZldm
UmaLyui3/ej7/WZaZl9mWQdmA/rr2uil/ejp/egL/g4HZrtUQ1BBZr8AIAAAZrkUAAAAZrgH
uwAAZroKAAAAZjP2zRpmYZAfB8Og+QHpS/Gg+gHpRfEAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAA
===
[SIGN]
[1264F787E46DC572FA274CA09B446E01] Microsoft Corporation
[786DD1892B553EFE5A004AC39775C851] Microsoft Corporation
[BD25E3537B54C1BFF40335992B3686FD] Microsoft Corporation
[FC3396B88F31636817D31F592A0DA848] Microsoft Corporation
[7FC19DA1DC70C78D2FBD7A1D10942051] Microsoft Corporation
[42729C3DE75A7A51FC6F9EF6546C9199] Adobe Systems, Incorporated
[4EAF6F8F0B3BE33A0E3877EB7FFD48D4] Adobe Systems, Incorporated
[F2CEEE9ABBCEF207ACB103215AC28BC2] Adobe Systems, Incorporated
[320681DF28D82CDCA7E3EED0846625DB] Adobe Systems Incorporated
[B17404D208C4B20518592AA43B81E04B] Oracle America, Inc.
[C9B67BCB8E384064A8C2263740B0C437] Oracle America, Inc.
[8669BE94F63944E4F899C3950B520241] Acresso Software Inc.
[14C405B807A341B60683FE1D5ED65380] Materialise NV
[9E7370CC3D6A43942433F85D0E2BBDD8] Microsoft Corporation

[84DE1DD996B48B05ACE31AD015FA108A]
[5A432A042DAE460ABE7199B758E8606C]
[FAEAFD0BEBFB2B5E938B29C8A155B807]
[DE77A8DA45F91629EB5FC157FA00C08A]
[42E4E281D9646F15E5C4D0CFD61CE684]
[51667022FACBD1AA611373DA16C98533]
[329D828599BE8859DDC81F866019B2F0]
[78AF384F14F01009EFB10A31AFEC51F4]
[88FBBB1C601A6BC42054E57C2897FA45]
[328E65035DE1D2C1206B4F94AAFC1DB7]
[E7859BA062DB5E23C6DD34AD66B09F50]
[E91F8AFBD7FB96C94B266579D6BFA77A]
[D2E3E6D94A9E1CFA1561D9C748136FD0]
[56748C769C10A379719A2C9D93AFEA6B]
[B7483C4236E990A3C7F5A3ABEE5C1417]
[F7CEB1E5F0000FDEEE04B046BBDE1D4E]
[31A94358EF55B871B1B81ADE3ACEBFF9]
[AE2A8DC5C08AE6A198D5EC47561C0DEF]
[E7062DBD907E0C5CEEB5ABDAF07E6B32]
[D3F78E38C39AB0E7358735717FB52EAE]
[EB1B7B961090A4AF33FC297516B88FAE]
[89CACBC5A5D9F14AD11F09D1DE49294E]
[AA1600118E222FCBE3F3BFEC1ABEC309]
[21FF393512F51F5A98620C794B4488A3]
[E99CD4524662A2DA7C73372C626669D8]
[515377905CC9A2EB0E585DD9AB457722]
[A597D3A1073271330191EE30046C121A]
[83C92F09C507BF8C2E2BED71F7B04A29]
[86661538E9002DA465C8456A962180C8]
[E80335157A225AD734865ADF1F929FFB]
[0978D90C8B61F73E926F7194CBCA331C]
[DEE16AB97AFB535329D0D0BE3F5929CE]
[B3DD214F23037E3D3C27D6C9447B40B5]
[C42EDED9E707ABDD455BB27FBD72416F]
[6C112DA6C86DB7FB2C50522EFDDA706A]
[52C696180AC8371163B268D648DCBDA5]
[EA8386CA87165460D39A1D29FF11080B]
[835FC2EA0631B734BB06C12B0665F01D]
[7CBB1D4D13DC62D7F529D87151FD3CD3]
[29E08F1970B681EBC3B0082D1654CF49]
[DC0D82C65E73BC03601E73F1367248FE]
[5137E8DE77B3185EC0B164A3AB9D58B9]
[D2D91B5F04852D50142D95BB9BB69310]
[FF1CA44FEDCA271E314AA63692D341A6]
[4A270804DC8AB72DCB4F694D050A3517]
[24B13133A4AC2FF48BA02EB10990A08D]
[C4002B6B41975F057D98C439030CEA07]
[4705E8EF9934482C5BB488CE28AFC681]
[D88040F816FDA31C3B466F0FA0918F29]
[6D7C8A951AF6AD6835C029B3CB88D333]
[D1CEEA2B47CB998321C579651CE3E4F8]
[5988FC40F8DB5B0739CD1E3A5D0D78BD]
[A8B7F3818AB65695E3A0BB3279F6DCE6]
[108FB6DDB69E537A2EA53F425363FAE5]
[86329C35FF23CFEF0FB6C0023BA06BCE]
[5243CFC2E7161C91C2B355240035B9E4]
[773212B2AAA24C1E31F10246B15B276C]
[4ABA3E75A76195A3E38ED2766C962899]
[1A47D52E303B7543E4E6026595B95422]
[3044D07ABDF4BBEA27E2EE7B1E0C0C65]

Microsoft Corporation
Microsoft Corporation
Nero AG
VMware, Inc.
Wondershare software CO., LIMITED
Google Inc
Google Inc
Google Inc
Google Inc
Intel(R) Software Development Products
Intel Corporation
Intel Corporation
Apple Inc.
Oracle America, Inc.
Oracle America, Inc.
Mozilla Corporation
Mozilla Corporation
Power Software Ltd
Rosetta Stone, Ltd
Samsung Electronics CO., LTD.
Samsung Electronics CO., LTD.
Sony Mobile Communications AB
Sony Mobile Communications AB
Sony Mobile Communications AB
TeamViewer
Greatis Software LLC
Greatis Software LLC
VMware, Inc.
VMware, Inc.
VMware, Inc.
Western Digital Technologies, Inc.
Western Digital Technologies, Inc.
Microsoft Windows
WordWeb Software
Arvato Digital Services Canada Inc
Intel(R) Software Development Products
Microsoft Windows
Apple Inc.
Microsoft Windows
win.rar GmbH
WinZip Computing
AVG Technologies CZ, s.r.o.
Softdeluxe Ltd.
Malware Protection Live
Widevine Technologies
Medical Informatics Engineering
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Dynamic Code Publisher
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Corporation
Microsoft Dynamic Code Publisher
Microsoft Corporation
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows

[A6C09924C6730DE8DEED9890A12AA691]
[9110FFAD124283F37D38771BB60556AF]
[3B367397320C26DBA890B260F80D1B1B]
[AA2C08CE85653B1A0D2E4AB407FA176C]
[2B81776DA02017A37FE26C662827470E]
[8560FFFC8EB3A806DCD4F82252CFC8C6]
[796B47A4B82EF1C39F13435B88834C48]
[CA2A0750ED830678997695FF61B04C30]
[C210E0DF28F3B0E5D45F928F08726650]
[37D0FB9E5E8EDA40B66FC3FB3D660261]
[E424B3EF666B184CEE0B6871AAA8C9F6]
[9A9F9F1A77D6A80EE28B57664F00013E]
[58A0CDABEA255616827B1C22C9994466]
[2DF36F15B2BC1571A6A542A3C2107920]
[613C8CE10A5FDE582BA5FA64C4D56AAA]
[88351B29B622B30962D2FEB6CA8D860B]
[019CD868461B646E09BDF04474C19341]
[5C627D1B1138676C0A7AB2C2C190D123]
[ED78427259134C63ED69804D2132B86C]
[09F7401D56F2393C6CA534FF0241A590]
[D29E998E8277666982B4F0303BF4E7AF]
[88AB9B72B4BF3963A0DE0820B4B0B06C]
[2E2072EB48238FCA8FBB7A9F5FABAC45]
[8396C6C26AADDFE4590CCEF0F419B6B7]
[ED730D791CB026146F9FB8EFB15201B7]
[4B78B431F225FD8624C5655CB1DE7B61]
[3290D6946B5E30E70414990574883DDB]
[0BC381A15355A3982216F7172F545DE1]
[9D2A2369AB4B08A4905FE72DB104498F]
[4ABA3E75A76195A3E38ED2766C962899]
[F23FEF6D569FCE88671949894A8BECF1]
[A6BF31A71B409DFA8CAC83159E1E2AFF]
[FDE360167101B4E45A96F939F388AEB0]
[82974D6A2FD19445CC5171FC378668A4]
[05F5A0D14A2EE1D8255C2AA0E9E8E694]
[95F9C2976059462CBBF227F7AAB10DE9]
[F17D1D393BBC69C5322FBFAFACA28C7F]
[FE1EC06F2253F691FE36217C592A0206]
[6B400F211BEE880A37A1ED0368776BF4]
[3AB183AB4D2C79DCF459CD2C1266B043]
[3CEC7631A84943677AA8FA8EE5B6B43D]
[43D808F5D9E1A18E5EEB5EBC83969E4E]
[A8EDB86FC2A4D6D1285E4C70384AC35A]
[16835866AAA693C7D7FCEBA8FFF706E4]
[B1FB3DDCA0FDF408750D5843591AFBC6]
[B26F4F737E8F9DF4F31AF6CF31D05820]
[A87D604AEA360176311474C87A63BB88]
[D81D9E70B8A6DD14D42D7B4EFA65D5F2]
[99F8E788246D495CE3794D7E7821D2CA]
[2F6B34B83843F0C5118B63AC634F5BF4]
[597F78224EE9224EA1A13D6350CED962]
[E109549C90F62FB570B9540C4B148E54]
[79059559E89D06E8B80CE2944BE20228]
[7ECFF9B22276B73F43A99A15A6094E90]
[608C14DBA7299D8CB6ED035A68A15799]
[5812713A477A3AD7363C7438CA2EE038]
[1FF8B4431C353CE385C875F194924C0C]
[7024F087CFF1833A806193EF9D22CDA9]
[1E56388B3FE0D031C44144EB8C4D6217]
[6EC6D772EAE38DC17C14AED9B178D24B]

Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Adobe Systems, Incorporated
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows

[F67F933E79241ED32FF46A4F29B5120B]
[1142A21DB581A84EA5597B03A26EBAA0]
[4FC6E2C2FC50445450651F42E90CC0BD]
[89A69C3F2F319B43379399547526D952]
[C484F8CEB1717C540242531DB7845C4E]
[019AF6924AEFE7839F61C830227FE79C]
[769765CE2CC62867468CEA93969B2242]
[02062C0B390B7729EDC9E69C680A6F3C]
[F02E18EFA6CEA4378D3F95CB6F9A3DE4]
[B5ACE6968304A3900EEB1EBFD9622DF2]
[61583EE3C3A17003C4ACD0475646B4D3]
[6C02A83164F5CC0A262F4199F0871CF5]
[F09EEE9EDC320B5E1501F749FDE686C8]
[B114D3098E9BDB8BEA8B053685831BE6]
[43BEA8D483BF1870F018E2D02E06A5BD]
[A6ECA2151B08A09CACECA35C07F05B42]
[B79968002C277E869CF38BD22CD61524]
[A87528880231C54E75EA7A44943B38BF]
[9DA669F11D1F894AB4EB69BF546A42E8]
[3E5B191307609F7514148C6832BB0842]
[B8BD2BB284668C84865658C77574381A]
[F036CE71586E93D94DAB220D7BDF4416]
[D7CD5C4E1B71FA62050515314CFB52CF]
[0840155D0BDDF1190F84A663C284BD33]
[E19D3F095812725D88F9001985B94EDD]
[EBF28856F69CF094A902F884CF989706]
[102DE219C3F61415F964C88E9085AD14]
[03EDB043586CCEBA243D689BDDA370A8]
[1C827878A998C18847245FE1F34EE597]
[54DA3DFD29ED9F1619B6F53F3CE55E49]
[9BB2EF44EAA163B29C4A4587887A0FE4]
[13096B05847EC78F0977F2C0F79E9AB3]
[9819EEE8B5EA3784EC4AF3B137A5244C]
[9B19F34400D24DF84C858A421C205754]
[88612F1CE3BF42256913BF6E61C70D52]
[0E5DA5369A0FCAEA12456DD852545184]
[34A3C54752046E79A126E15C51DB409B]
[DC5D737F51BE844D8C82C695EB17372F]
[D765D19CD8EF61F650C384F62FAC00AB]
[655661BE46B5F5F3FD454E2C3095B930]
[5F671AB5BC87EEA04EC38A6CD5962A47]
[C172A0F53008EAEB8EA33FE10E177AF5]
[DA6B67270FD9DB3697B20FCE94950741]
[D43703496149971890703B4B1B723EAC]
[1F7B25B858FA27015169FE95E54108ED]
[8C778D335C9D272CFD3298AB02ABE3B6]
[8E98D21EE06192492A5671A6144D092F]
[A1F556318931B9EA276F4E2DA2C1791C]
[7F56A3E09A6AD40B07E4EFAD34A40A18]
[23AF3730B7B757A385721E900250CF3B]
[F2523EF6460FC42405B12248338AB2F0]
[97BFED39B6B79EB12CDDBFEED51F56BB]
[975761C778E33CD22498059B91E7373A]
[A6518DCC42F7A6E999BB3BEA8FD87567]
[45540DAE98ED8E6C5376F616D8D5547C]
[2C3D7F56BA751941D0E7DA16934FBB5D]
[78E86380454A7B10A5EB255DC44A355F]
[7FD2A313F7AFE5C4DAB14798C48DD104]
[0A77D29F311B88CFAE3B13F9C1A73825]
[9592090A7E2B61CD582B612B6DF70536]

Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
VMware, Inc.
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
HHD Software Ltd.
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows

[39D2ABCD392F3D8A6DCE7B60AE7B8EFC]
[0EA7DE1ACB728DD5A369FD742D6EEE28]
[A5462BD6884960C9DC85ED49D34FF392]
[FA55C73D4AFFA7EE23AC4BE53B4592D3]
[3DF4395A7CF8B7A72A5F4606366B8C2D]
[5C18831C61933628F5BB0EA2675B9D21]
[F00F20E70C6EC3AA366910083A0518AA]
[ADA036632C664CAA754079041CF1F8C1]
[C9F0E1BD74365A8771590E9008D22AB6]
[0FC1AEA580957AA8817B8F305D18CA3A]
[AF9B39A7E7B6CAA203B3862582E9F2D0]
[3ABF5E7213EB28966D55D58B515D5CE9]
[2F7B28DC3E1183E5EB418DF55C204F38]
[BC02336F1CBA7DCC7D1213BB588A68A5]
[0705EFF5B42A9DB58548EEC3B26BB484]
[353009DEDF918B2A51414F330CF72DEC]
[1C2D8E18AA8FD50CD04C15CC27F7F5AB]
[6869281E78CB31A43E969F06B57347C4]
[1538831CF8AD2979A04C423779465827]
[1A93E54EB0ECE102495A51266DCDB6A6]
[1047184A9FDC8BDBFF857175875EE810]
[30F5C0DE1EE8B5BC9306C1F0E4A75F93]
[0504EACAFF0D3C8AED161C4B0D369D4A]
[43D0F98E1D56CCDDB0D5254CFF7B356E]
[A55805F747C6EDB6A9080D7C633BD0F4]
[BAF74CE0072480C3B6B7C13B2A94D6B3]
[800BA92F7010378B09F9ED9270F07137]
[B03D591DC7DA45ECE20B3B467E6AADAA]
[7D27EA49F3C1F687D357E77A470AEA99]
[D3BF052C40B0C4166D9FD86A4288C1E6]
[32E7A3D591D671A6DF2DB515A5CBE0FA]
[A44B420D30BD56E145D6A2BC8768EC58]
[6C38C9E45AE0EA2FA5E551F2ED5E978F]
[DC722758B8261E1ABAFD31A3C0A66380]
[A5D9106A73DC88564C825D317CAC68AC]
[D711B3C1D5F42C0C2415687BE09FC163]
[9423E9D355C8D303E76B8CFBD8A5C30C]
[C25F0BAFA182CBCA2DD3C851C2E75796]
[DB801A638D011B9633829EB6F663C900]
[F9D215A46A8B9753F61767FA72A20326]
[D916874BBD4F8B07BFB7FA9B3CCAE29D]
[D931D7309DEB2317035B07C9F9E6B0BD]
[49CCF2C4FEA34FFAD8B1B59D49439366]
[BDD71ACE35A232104DDD349EE70E1AB3]
[4ED981241DB27C3383D72092B618A1D0]
[0EED230E37515A0EAEE3C2E1BC97B288]
[2E66F9ECB30B4221A318C92AC2250779]
[7EA404308934E675BFFDE8EDF0757BCD]
[F9A18612FD3526FE473C1BDA678D61C8]
[79B47FD40D9A817E932F9D26FAC0A81C]
[9F9A1F53AAD7DA4D6FEF5BB73AB811AC]
[30639C932D9FEF22B31268FE25A1B6E5]
[136185F9FB2CC61E573E676AA5402356]
[53F7305169863F0A2BDDC49E116C2E11]
[86743D9F5D2B1048062B14B1D84501C4]
[09594D1089C523423B32A4229263F068]
[98F3ABC312BC0C660BA3F3B47782455E]
[417334447945C9E111FFD881F7BF4D08]
[986ACDECE933131288F1957DC359865F]
[77889813BE4D166CDAB78DDBA990DA92]

Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft

Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows

[E7F5AE18AF4168178A642A9247C63001]
[270D7CD42D6E3979F6DD0146650F0E05]
[5D9FD91F3D38DC9DA01E3CB5FA89CD48]
[F7CD50FE7139F07E77DA8AC8033D1832]
[1EA3749C4114DB3E3161156FFFFA6B33]
[3589478E4B22CE21B41FA1BFC0B8B8A0]
[0557CF5A2556BD58E26384169D72438D]
[0086431C29C35BE1DBC43F52CC273887]
[6DDCF3F801EC15FE698F6A215CF30A1F]
[E9766131EEADE40A27DC27D2D68FBA9C]
[94575C0571D1462A0F70BDE6BD6EE6B3]
[B5B8B5EF2E5CB34DF8DCF8831E3534FA]
[B2E81D4E87CE48589F98CB8C05B01F2F]
[D6B9C2E1A11A3A4B26A182FFEF18F603]
[68769C3356B3BE5D1C732C97B9A80D6E]
[50AD172D2DDF898FC1705199B60C3264]
[ADC5D126ABAB5AB5B806AE32B12125E7]
[0D922E23C041EFB1C3FAC2A6F943C9BF]
[A53A15A11EBFD21077463EE2C7AFEEF0]
[4F6D12B51DE1AAEFF7DC58C4D75423C8]
[76707BB36430888D9CE9D705398ADB6C]
[5A0DA8AD5762FA2D91678A8A01311704]
[471815800AE33E6F1C32FB1B97C490CA]
[855C9B1CD4756C5E9A2AA58A15F58C25]
[F92A2C41117A11A00BE01CA01A7FCDE9]
[E8B1E447B008D07FF47D016C2B0EEECB]
[77F665941019A1594D887A74F301FA2F]
[302DA2A0539F2CF54D7C6CC30C1F2D8D]
[CEA6CC257FC9B7715F1C2B4849286D24]
[1B6163C503398B23FF8B939C67747683]
[BB5971A4F00659529A5C44831AF22365]
[216F3FA57533D98E1F74DED70113177A]
[70CBA1A0C98600A2AA1863479B35CB90]
[34ED295FA0121C241BFEF24764FC4520]
[9C3AC71A9934B884FAC567A8807E9C4D]
[DDC86E4F8E7456261E637E3552E804FF]
[AC4CA62572CA516945AB92D6C9F501F4]
[B48DC6ABCD3AEFF8618350CCBDC6B09A]
[351533ACC2A069B94E80BBFC177E8FDF]
[AC03AF3329579FFFB455AA2DAABBE22B]
[253F38D0D7074C02FF8DEB9836C97D2B]
[07F83829E7429E60298440CD1E601A6A]
[CB624C0035412AF0DEBEC78C41F5CA1B]
[C1D8E28B2C2ADFAEC4BA89E9FDA69BD6]
[1C545A7D0691CC4A027396535691C3E3]
[A554811BCD09279536440C964AE35BBF]
[FF414F0BAEFEBA59BC6C04B3DB0B87BF]
[DD85B78243A19B59F0637DCF284DA63C]
[A9D601643A1647211A1EE2EC4E433FF4]
[843CAF1E5FDE1FFD5FF768F23A51E2E1]
[6A6C106D42E9FFFF8B9FCB4F754F6DA4]
[548260A7B8654E024DC30BF8A7C5BAA4]
[7B90D750DCBF72524DD38B105D29F8C1]
[441FBA48BFF01FDB9D5969EBC1838F0B]
[B4ADEBBF5E3677CCE9651E0F01F7CC28]
[27E461F0BE5BFF5FC737328F749538C3]
[30710AEFCE721CEEE0F35EB6A01C263C]
[91310683D7B6B292B746D60734B59322]
[B5D5A1846972B7F93BDC6333272D750E]
[F7093A27C4AF6D9EEA0ACAC1C4FF6828]

Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Greatis Software, LLC
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
VS Revo Group
Microsoft Windows
Microsoft Windows
CACE Technologies, Inc.
CACE Technologies, Inc.
Microsoft Windows
Microsoft Windows
Intel(R) Code Signing External
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows

[F3817967ED533D08327DC73BC4D5542A]
[D34E4943D5AC096C8EDEEBFD80D76E23]
[D01EC09B6711A5F8E7E6564A4D0FBC90]
[40AF23633D197905F03AB5628C558C51]
[DF687E3D8836BFB04FCC0615BF15A519]
[3371D21011695B16333A3934340C4E7C]
[51C5ECEB1CDEE2468A1748BE550CFBC8]
[DDAD5A7AB24D8B65F8D724F5C20FD806]
[561E7E1F06895D78DE991E01DD0FB6E5]
[4CE278FC9671BA81A138D70823FCAA09]
[D11C783E3EF9A3C52C0EBE83CC5000E9]
[3566A8DAAFA27AF944F5D705EAA64894]
[B4DD609BD7E282BFC683CEC7EAAAAD67]
[FF4232A1A64012BAA1FD97C7B67DF593]
[4BFE1BC28391222894CBF1E7D0E42320]
[DC54A574663A895C8763AF0FA1FF7561]
[B2E8E8CB557B156DA5493BBDDCC1474D]
[24E8F8C3BDF9CEFC2135F9A3C399F37D]
[2C42E595E7E381596B9A14F88F5AE027]
[7B28E2FBE75115660FAB31079C0A9F29]
[B0435098C81D04CAFFF80DDB746CD3A2]
[DCA68B0943D6FA415F0C56C92158A83A]
[80B0F7D5CCF86CEB5D402EAAF61FEC31]
[18A85013A3E0F7E1755365D287443965]
[8D1196CFBB223621F2C67D45710F25BA]
[765A92D428A8DB88B960DA5A8D6089DC]
[73188F58FB384E75C4063D29413CEE3D]
[D76510CFA0FC09023077F22C2F979D86]
[DD253AFC3BC6CBA412342DE60C3647F3]
[1F775DA4CF1A3A1834207E975A72E9D7]
[C5C876CCFC083FF3B128F933823E87BD]
[53E92A310193CB3C03BEA963DE7D9CFC]
[DA4DA3F5E02943C2DC8C6ED875DE68DD]
[2CE2DF28C83AEAF30084E1B1EB253CBB]
[E5689D93FFE4E5D66C0178761240DD54]
[86EA3E79AE350FEA5331A1303054005F]
[7DE90B48F210D29649380545DB45A187]
[BE8E5E5D53ACF71D4E8E686B68C99B04]
[18AA5F4A3B1204AD00045EE5AD39BCDB]
[04CD4347CD9E8C40F78AD51F7FF426D0]
[748FD60D1B73F50020CFD126F940543F]
[7FBB3F1EBB009F9F711B02D599DB1CE6]
[E60C0A09F997826C7627B244195AB581]
[7785DC213270D2FC066538DAF94087E7]
[F347A28F63162FF82BDDAADC14935BA4]
[CB41CC41F83C9A6081A2AE71251A16D5]
[D2AAFD421940F640B407AEFAAEBD91B0]
[A255814907C89BE58B79EF2F189B843B]
[0D08D2F3B3FF84E433346669B5E0F639]
[5E2016EA6EBACA03C04FEAC5F330D997]
[108196FE0580A18AB6237EA36FD210F2]
[E7CE8988B98202A5CF429CA358D26CC5]
[36D4720B72B5C5D9CB2B9C29E9DF67A1]
[4E9440F4F152A7B944CB1663D3935A3E]
[356AFD78A6ED4457169241AC3965230C]
[72889E16FF12BA0F235467D6091B17DC]
[A3D04EBF5227886029B4532F20D026F7]
[E2C933EDBC389386EBE6D2BA953F43D8]
[611B23304BF067451A9FDEE01FBDD725]
[05ECAEC3E4529A7153B3136CEB49F0EC]

Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Greatis Software LLC
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
VMware, Inc.
VMware, Inc.
Microsoft Windows
Microsoft Windows
Microsoft Windows
VMware, Inc.
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
VMware, Inc.
VMware, Inc.
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows

[FE88B288356E7B47B74B13372ADD906D]
[F6FF8944478594D0E414D3F048F0D778]
[6BCC1D7D2FD2453957C5479A32364E52]
[AD12F5C7251BB8D575D560894E73CBBA]
[D3381DC54C34D79B22CEE0D65BA91B7C]
[CF8D590BE3373029D57AF80914190682]
[E2DDA8726DA9CB5B2C4000C9018A9633]
[024352FEEC9042260BB4CFB4D79A206B]
[4166F82BE4D24938977DD1746BE9B8A0]
[0438CAB2E03F4FB61455A7956026FE86]
[802496CB59A30349F9A6DD22D6947644]
[C4C183E6551084039EC862DA1C945E3D]
[19E41CCCEE697CC9465396B370929792]
[DBEFD454F8318A0EF691FDD2EAAB44EB]
[0D09040EF933C3216CA5DD98E1744902]
[277BBC7E1AA1EE957F573A10ECA7EF3A]
[BD9EB3958F213F96B97B1D897DEE006D]
[A3A132CBE48AF0324466469F2CAAE8A2]
[344789398EC3EE5A4E00C52B31847946]
[DA6C4B5FEEEA4DC7162B5D0C055EB967]
[142E90CF1A4C5B6E7505810E38B07B9F]
[098A91C54546A3B878DAD6A7E90A455B]
[A34A587FFFD45FA649FBA6D03784D257]
[B95F6501A2F8B2E78C697FEC401970CE]
[4F15D75ADF6156BF56ECED6D4A55C389]
[808E98FF49B155C522E6400953177B08]
[06DC527364A8CF48E472ECF2BA3F8403]
[5CE9241C030C004FF92037DF8F7401B0]
[B19C8390A1D641B9AC4490D4828A7B5E]
[387E72E739E15E3D37907A86D9FF98E2]
[EFDFB3DD38A4376F93E7985173813ABD]
[C1185803384AB3FEED115F79F109427F]
[F993A32249B66C9D622EA5592A8B76B8]
[45CFBFA8EDC3DF4E2B7FB0D0260FE051]
[D5BA242D4CF8E384DB90E6A8ED850B8C]
[204F3F58212B3E422C90BD9691A2DF28]
[0BE09CD858ABF9DF6ED259D57A1A1663]
[CA2A0750ED830678997695FF61B04C30]
[E40E80D0304A73E8D269F7141D77250B]
[254FB7A22D74E5511C73A3F6D802F192]
[54FFC9C8898113ACE189D4AA7199D2C1]
[1B7C3A37362C7B2890168C5FC61C8D9B]
[329FEB3452982A377726DEDAFE9BBDF0]
[A08C010D859F8EB42BDD7E1D55B8CA27]
[DE0ECE52236CFA3ED2DBFC03F28253A8]
[6AB66E16AA859232F64DEB66887A8C9C]
[1C81E1BEA4847F406BBDB74D19721CE6]
[E5B9A2FA94D21C44DA2B898DC326B0C2]
[A190DA6546501CB4146BBCC0B6A3F48B]
[45989C268EC2CC9EEA80030AF96CDA5A]
[E2A483E796D5FC7E447725FD01D98FA0]
[69A4347A8EAD86185EFF2F75755176E6]
[B94D3DACCF5882B697A1C53D00BE643A]
[847D3AE376C0817161A14A82C8922A9E]
[5F28111C648F1E24F7DBC87CDEB091B8]
[1EE99A89CC788ADA662441D1E9830529]
[D54BFDF3E0C953F823B3D0BFE4732528]
[7BBF670114373CE6A203FA155A9E0D0A]
[927463ECB02179F88E4B9A17568C63C3]
[3AEAA8B561E63452C655DC0584922257]

Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Google Inc
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows

[E08088A97F95345E181C3DFCE2C615EF]
[C7CF6A6E137463219E1259E3F0F0DD6C]
[3EAC4455472CC2C97107B5291E0DCAFE]
[5C78838B4D166D1A27DB3A8A820C799A]
[908ACB1F594274965A53926B10C81E89]
[C32ECB99AD25E9A04F01C8665DF29EF8]
[D619356B955EEFA642F5FF72755E8B3C]
[582AC6D9873E31DFA28A4547270862DD]
[1EA7969E3271CBC59E1730697DC74682]
[906191634E99AEA92C4816150BDA3732]
[8F26510C5383B8DBE976DE1CD00FC8C7]
[EE867A0870FC9E4972BA9EAAD35651E2]
[E4D94F24081440B5FC5AA556C7C62702]
[E4DC58CF7B3EA515AE917FF0D402A7BB]
[5C627D1B1138676C0A7AB2C2C190D123]
[9B7395789E3791A3B6D000FE6F8B131E]
[ED78427259134C63ED69804D2132B86C]
[481F70241D4EA038BB02590A30F15A23]
[262F6592C3299C005FD6BEC90FC4463A]
[6EA4234DC55346E0709560FE7C2C1972]
[AD31942BDF3D594C404874613BC2FE4D]
[BC617A4E1B4FA8DF523A061739A0BD87]
[C32AB8FA018EF34C0F113BD501436D21]
[0336CFFAFAAB87A11541F1CF1594B2B2]
[0B6231BF38174A1628C4AC812CC75804]
[427015D56DF17241F634611557146C57]
[AAF932B4011D14052955D4B212A4DA8D]
[6313F223E817CC09AA41811DAA7F541D]
[350A8C7BDBEE961221EB913A76B71186]
[B96C17B5DC1424D56EEA3A99E97428CD]
[E17E0188BB90FAE42D83E98707EFA59C]
[93D7D61317F3D4BC4F4E9F8A96A7DE45]
[D9F42719019740BAA6D1C6D536CBDAA6]
[51B52FBD583CDE8AA9BA62B8B4298F33]
[AB7AEBF58DAD8DAAB7A6C45E6A8885CB]
[C78655BC80301D76ED4FEF1C1EA40A7D]
[E08E46FDD841B7184194011CA1955A0B]
[A10B048B681C38E26CA90CD1BC123604]
[BF9CCC0BF39B418C8D0AE8B05CF95B7D]
[870726CDCC241A92785572628B89CC07]
[E3C61FD7B7C2557E1F1B0B4CEC713585]
[40F0849F65D13EE87B9A9AE3C1DD6823]
[1BE03AC720F4D302EA01D40F588162F6]
[2E648163254233755035B46DD7B89123]
[F0344071948D1A1FA732231785A0664C]
[7E7AFD841694F6AC397E99D75CEAD49D]
[CEED624D1291081B1B7D921FBB9C61D9]
[B6D8C1202DACA028AD94BDA2795CBBE9]
[3CBDEC8D06B9968ABA702EBA076364A1]
[25FBDEF06C4D92815B353F6E792C8129]
[6BA9D927DDED70BD1A9CADED45F8B184]
[A293DCD756D04D8492A750D03B9A297C]
[64B328D52DFC8CDA123093E3F6E4C37C]
[D47EC6A8E81633DD18D2436B19BAF6DE]
[BAFE84E637BF7388C96EF48D4D3FDD53]
[EDBB23CBCF2CDF727D64FF9B51A6070E]
[8D6B481601D01A456E75C3210F1830BE]
[D9B422F37FCAF61BD80E12CC03E84816]
[5DC2DA538FF0806950B73F798A2444ED]
[B60BA0BC31B0CB414593E169F6F21CC2]

Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
MiniTool Solution Ltd
MiniTool Solution Ltd
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
CANON INC.
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
VMware, Inc.
VMware, Inc.
Microsoft Windows

[1C9D80CC3849B3788048078C26486E1A]
[3CEC96DE223E49EAAE3651FCF8FAEA6C]
[A3F5E8EC1316C3E2562B82694A251C9E]
[38B84C94C5A8AF291ADFEA478AE54F93]
[19B07E7E8915D701225DA41CB3877306]
[78F4E7F5C56CB9716238EB57DA4B6A75]
[3AA101E8EDAB2DB4131333F4325C76A3]
[7368A2AFD46E5A4481D1DE9D14848EDD]
[20F7441334B18CEE52027661DF4A6129]
[BF1FC3F79B863C914687A737C2F3D681]
[26AF184300C0868D854D5A3092234E24]
[1473768973453DE50DC738C2955FC4DD]
[3DB6D04E1C64272F8B14EB8BC4616280]
[C749025A679C5103E575E3B48E092C43]
[7E591867422DC788B9E5BD337A669A08]
[6D137963730144698CBD10F202E9F251]
[8DD52E8E6128F4B2DA92CE27402871C1]
[58F4493BF748A3A89689997B7BD00E95]
[851A1382EED3E3A7476DB004F4EE3E1A]
[4FADA86E62F18A1B2F42BA18AE24E6AA]
[96C6E7100D724C69FCF9E7BF590D1DCA]
[93221146D4EBBF314C29B23CD6CC391D]
[E8B1FE6669397D1772D8196DF0E57A9E]
[581B739BEF5B6B668E5308CFE956B84A]
Co., Ltd.
[BCB1310604AA415C4508708975B3931E]
[D9EF901DCA379CFE914E9FA13B73B4C4]
[7A95C95B6C4CF292D689106BCAE49543]
[9A3452B3C2A46C073166C5CF49FAD1AE]
[241A1900C52DCBA38B20A4F3671444E0]
[351533ACC2A069B94E80BBFC177E8FDF]
[2AFBB91BBD2378933B26E6D68C140D1B]
[1C7F1C3EA5894995E6C563E9AE9F029F]
[28FFB14117CCEDD7D2F124596AA9B785]
[EA85144F35EDE6EE25C484D4242FF2C8]
[59D16C3D5CC0D573256A01783ED5CCB4]
[E94C583CDE2348950155F2AF2876F34D]
[0B7E85364CB878E2AD531DB7B601A9E5]
[104A1070E90F1C530328E69B49718841]
[703FFD301AB900B047337C5D40FD6F96]
[E495E408C93141E8FC72DC0C6046DDFA]
[5CF640EDDB1E40A5AB1BB743BCDEC610]
[76F58DB8F85C125E0D6B3AA42F3BF1D0]
[5DF5D8CFD9B9573FA3B2C89D9061A240]
===

Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Shenzhen Wondershare Information Technology
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
CACE Technologies, Inc.
Microsoft Windows
Microsoft Windows
Adobe Systems Incorporated
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows

Das könnte Ihnen auch gefallen