Regrunlog
Regrunlog
Regrunlog
170-64b
12.05.2016 12:25:25
WinDir=C:\Windows
Startup=C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Sta
rtup\
Common Startup=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Windows 7 Ultimate (6.1.7601)
Internet Explorer 9.11.9600.17041
[Internet Explorer]
[Default Home Page] :HKLM Default_Page_URL=http://www.google.com/
[Current Home Page] :HKCU Start Page=""
[Current Home Page] :HKCU HOMEOldSP=""
[Current Home Page] :HKCU Default_Page_URL=http://www.google.com/
[Current Home Page] :HKLM Start Page=http://www.google.com/
[Current Home Page] :HKLM HOMEOldSP=""
[All Users Search] :HKLM Default_Search_URL=www.google.com
[All Users Search] :HKLM Search Page=www.google.com
[Current Users Search] :HKCU Default_Search_URL=www.google.com
[Current Users Search] :HKCU Search Page=www.google.com
[Current Users Search] :HKCU Search Bar=""
[IE Local Blank Page] :HKCU Local Page=C:\Windows\system32\blank.htm
[IE Local Blank Page] :HKLM Local Page=C:\Windows\SysWOW64\blank.htm
[Browser Helper Objects] {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}=C:\PROGRAM FIL
ES (X86)\ADOBE\ACROBAT 7.0\ACTIVEX\ACROIEHELPER.DLL
### Adobe Acrobat IE Helper Version 7.0 for ActiveX Adobe Systems Incorporated
AcroIEHelper Library 7, 0, 0, 0
[Browser Helper Objects] {1F91A9A1-01BA-4c81-863D-3BA0751E1419}
### File is deleted or hidden by a rootkit or could not be located.
[Browser Helper Objects] {72853161-30C5-4D22-B7F9-0BBC1D38A37E}=C:\PROGRA~2\MI
CROS~1\OFFICE12\GR469A~1.DLL
### GrooveShellExtensions Module Microsoft Corporation GrooveShellExtensions M
odule 4.2.0.2623
[Browser Helper Objects] {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\PROGRAM FIL
ES (X86)\JAVA\JRE1.8.0_77\BIN\SSV.DLL
### Java(TM) Platform SE binary Oracle Corporation Java(TM) Platform SE 8 U77
8.0.770.3
[Browser Helper Objects] {AE7CD045-E861-484f-8273-0445EE161910}=C:\PROGRAM FIL
ES (X86)\ADOBE\ACROBAT 7.0\ACROBAT\ACROIEFAVCLIENT.DLL
### Adobe IE plugin Adobe Systems Incorporated Adobe IE plugin 7.0.0.0
[Browser Helper Objects] {CC59E0F9-7E43-44FA-9FAA-8377850BF205}=C:\PROGRAM FIL
ES (X86)\FREE DOWNLOAD MANAGER\IEFDM2.DLL
### FreeDownloadManager.ORG Free Download Manager 0.0.0.0
[Browser Helper Objects] {DBC80044-A445-435b-BC74-9C25C1C588A9}=C:\PROGRAM FIL
ES (X86)\JAVA\JRE1.8.0_77\BIN\JP2SSV.DLL
### Java(TM) Platform SE binary Oracle Corporation Java(TM) Platform SE 8 U77
8.0.770.3
[Auto Search URL] :HKCU provider=""
[Auto Search URL] :HKCU "Default Value"=""
[Search Assistant] :HKCU SearchAssistant=""
[Search Assistant] :HKLM SearchAssistant=""
[Search Assistant] :HKCU CustomizeSearch=""
[Search Assistant] :HKLM CustomizeSearch=""
[Search Provider] {0633EE93-D776-472f-A0FF-E1416B8B2E3A}=http://www.oursurfing
.com/web/?utm_source=b&utm_medium=2sq&utm_campaign=install_ie&utm_content=ds&fro
m=2sq&uid=ST2000DM001-1CH164_W1F5EHSDXXXXW1F5EHSD&ts=1439368115&type=default&q={
searchTerms}
### Bing
[Search Provider] {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0}=http://www.oursurfing
.com/web/?utm_source=b&utm_medium=2sq&utm_campaign=install_ie&utm_content=ds&fro
m=2sq&uid=ST2000DM001-1CH164_W1F5EHSDXXXXW1F5EHSD&ts=1439368115&type=default&q={
searchTerms}
### e
[Search Provider] {AF736ECA-4654-4BDD-AF19-2510C114C5D3}=http://www.oursurfing
.com/web/?utm_source=b&utm_medium=2sq&utm_campaign=install_ie&utm_content=ds&fro
m=2sq&uid=ST2000DM001-1CH164_W1F5EHSDXXXXW1F5EHSD&ts=1439368115&type=default&q={
searchTerms}
[Search Provider] {BB74DE59-BC4C-4172-9AC4-73315F71CFFE}=http://www.oursurfing
.com/web/?utm_source=b&utm_medium=2sq&utm_campaign=install_ie&utm_content=ds&fro
m=2sq&uid=ST2000DM001-1CH164_W1F5EHSDXXXXW1F5EHSD&ts=1439368115&type=default&q={
searchTerms}
[Search Provider] {BC23E1A1-0266-4668-86D8-BC4534B7BB2A}=http://www.oursurfing
.com/web/?utm_source=b&utm_medium=2sq&utm_campaign=install_ie&utm_content=ds&fro
m=2sq&uid=ST2000DM001-1CH164_W1F5EHSDXXXXW1F5EHSD&ts=1439368115&type=default&q={
searchTerms}
[Search Provider] {BDF61FAE-9D19-40F0-8F34-688DEB334CA9}=http://www.oursurfing
.com/web/?utm_source=b&utm_medium=2sq&utm_campaign=install_ie&utm_content=ds&fro
m=2sq&uid=ST2000DM001-1CH164_W1F5EHSDXXXXW1F5EHSD&ts=1439368115&type=default&q={
searchTerms}
### Ad-Aware SecureSearch
[Search Provider] {E733165D-CBCF-4FDA-883E-ADEF965B476C}=http://www.oursurfing
.com/web/?utm_source=b&utm_medium=2sq&utm_campaign=install_ie&utm_content=ds&fro
m=2sq&uid=ST2000DM001-1CH164_W1F5EHSDXXXXW1F5EHSD&ts=1439368115&type=default&q={
searchTerms}
### Google
[Search Provider] DefaultScope={0633EE93-D776-472f-A0FF-E1416B8B2E3A}
[Search Provider for All Users] {0633EE93-D776-472f-A0FF-E1416B8B2E3A}=http://
www.bing.com/search?q={searchTerms}&FORM=IE8SRC
### Bing
[Search Provider for All Users] {BB74DE59-BC4C-4172-9AC4-73315F71CFFE}=http://
websearch.toolksearchbook.info/?l=1&q={searchTerms}&pid=725&r=2014/01/15&hid=240
6902759796487476&lg=EN&cc=IN&unqvl=46
### WebSearch
[Search Provider for All Users] DefaultScope={BB82DE59-BC4C-4172-9AC4-73315F71
CFFE}
[Search Provider for All Users(x64)] {0633EE93-D776-472f-A0FF-E1416B8B2E3A}=ht
tp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
### Bing
[Search Provider for All Users(x64)] DefaultScope={33BB0A4E-99AF-4226-BDF6-491
20163DE86}
[Search Provider(x64)] {0633EE93-D776-472f-A0FF-E1416B8B2E3A}=http://www.oursu
rfing.com/web/?utm_source=b&utm_medium=2sq&utm_campaign=install_ie&utm_content=d
s&from=2sq&uid=ST2000DM001-1CH164_W1F5EHSDXXXXW1F5EHSD&ts=1439368115&type=defaul
t&q={searchTerms}
### Bing
[Search Provider(x64)] {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0}=http://www.oursu
rfing.com/web/?utm_source=b&utm_medium=2sq&utm_campaign=install_ie&utm_content=d
s&from=2sq&uid=ST2000DM001-1CH164_W1F5EHSDXXXXW1F5EHSD&ts=1439368115&type=defaul
t&q={searchTerms}
### e
[Search Provider(x64)] {AF736ECA-4654-4BDD-AF19-2510C114C5D3}=http://www.oursu
rfing.com/web/?utm_source=b&utm_medium=2sq&utm_campaign=install_ie&utm_content=d
s&from=2sq&uid=ST2000DM001-1CH164_W1F5EHSDXXXXW1F5EHSD&ts=1439368115&type=defaul
t&q={searchTerms}
[Search Provider(x64)] {BB74DE59-BC4C-4172-9AC4-73315F71CFFE}=http://www.oursu
rfing.com/web/?utm_source=b&utm_medium=2sq&utm_campaign=install_ie&utm_content=d
s&from=2sq&uid=ST2000DM001-1CH164_W1F5EHSDXXXXW1F5EHSD&ts=1439368115&type=defaul
t&q={searchTerms}
[Search Provider(x64)] {BC23E1A1-0266-4668-86D8-BC4534B7BB2A}=http://www.oursu
rfing.com/web/?utm_source=b&utm_medium=2sq&utm_campaign=install_ie&utm_content=d
s&from=2sq&uid=ST2000DM001-1CH164_W1F5EHSDXXXXW1F5EHSD&ts=1439368115&type=defaul
t&q={searchTerms}
[Search Provider(x64)] {BDF61FAE-9D19-40F0-8F34-688DEB334CA9}=http://www.oursu
rfing.com/web/?utm_source=b&utm_medium=2sq&utm_campaign=install_ie&utm_content=d
s&from=2sq&uid=ST2000DM001-1CH164_W1F5EHSDXXXXW1F5EHSD&ts=1439368115&type=defaul
t&q={searchTerms}
### Ad-Aware SecureSearch
[Search Provider(x64)] {E733165D-CBCF-4FDA-883E-ADEF965B476C}=http://www.oursu
rfing.com/web/?utm_source=b&utm_medium=2sq&utm_campaign=install_ie&utm_content=d
s&from=2sq&uid=ST2000DM001-1CH164_W1F5EHSDXXXXW1F5EHSD&ts=1439368115&type=defaul
t&q={searchTerms}
### Google
[Search Provider(x64)] DefaultScope={0633EE93-D776-472f-A0FF-E1416B8B2E3A}
[CustomizeSearch] :HKLM CustomizeSearch=""
[URLSearchHook] :HKCU {CFBFAE00-17A6-11D0-99CB-00C04FD64497}=C:\WINDOWS\SYSWOW
64\IEFRAME.DLL
### Internet Browser Microsoft Corporation Internet Explorer 11.00.9600.17041
[Search URL Template] :HKLM 1=""
[Search URL Template] :HKLM 2=""
[Search URL Template] :HKLM 3=""
[Search URL Template] :HKLM 4=""
[Default Prefix] :HKLM "Default Value"=http://
[URL Default Prefixes] :HKLM mosaic=http://
[URL Default Prefixes] :HKLM www=http://
[URL Default Prefixes] :HKLM home=http://
[URL Default Prefixes] :HKLM ftp=ftp://
[AboutURLs] :HKLM blank=res://mshtml.dll/blank.htm
[AboutURLs] :HKLM NoAdd-onsInfo=res://ieframe.dll/noaddoninfo.htm
[AboutURLs] :HKLM InPrivate=res://ieframe.dll/inprivate_win7.htm
[AboutURLs] :HKLM NavigationFailure=res://ieframe.dll/navcancl.htm
[AboutURLs] :HKLM NoAdd-ons=res://ieframe.dll/noaddon.htm
[AboutURLs] :HKLM Home=270
[AboutURLs] :HKLM PostNotCached=res://ieframe.dll/repost.htm
[AboutURLs] :HKLM DesktopItemNavigationFailure=res://ieframe.dll/navcancl.htm
[AboutURLs] :HKLM NavigationCanceled=res://ieframe.dll/navcancl.htm
[AboutURLs] :HKLM SecurityRisk=res://ieframe.dll/securityatrisk.htm
[User Style Sheet] :HKCU User Stylesheet=""
[User Style Sheet] :HKCU Use My Stylesheet=0
[Execute unsigned ActiveX in My Computer Zone] :HKCU 1201=0
[Execute unsigned ActiveX in My Computer Zone] :HKLM 1201=1
[Execute unsigned ActiveX in Local Intranet Zone] :HKCU 1201=1
[Execute unsigned ActiveX in Local Intranet Zone] :HKLM 1201=3
[Execute unsigned ActiveX in Internet Zone] :HKCU 1201=3
[Execute unsigned ActiveX in Internet Zone] :HKLM 1201=3
[Links Toolbar] :HKCU LinksFolderName=""
[Toolbars] :HKLM {47833539-D0C5-4125-9FA8-0819E2EAAC93}=C:\PROGRAM FILES (X86)
\ADOBE\ACROBAT 7.0\ACROBAT\ACROIEFAVCLIENT.DLL
### Adobe IE plugin Adobe Systems Incorporated Adobe IE plugin 7.0.0.0
[Explorer Bars] :HKLM {182EC0BE-5110-49C8-A062-BEB1D02A220B}=C:\PROGRAM FILES
(X86)\ADOBE\ACROBAT 7.0\ACROBAT\ACROIEFAVCLIENT.DLL
### Adobe IE plugin Adobe Systems Incorporated Adobe IE plugin 7.0.0.0
[IE Extensions - All Users] :HKLM {2670000A-7350-4f3c-8081-5663EE0C6C49}
### File is deleted or hidden by a rootkit or could not be located.
[IE Extensions - All Users] :HKLM {92780B25-18CC-41C8-B9BE-3C9C571A8263}=C:\PR
OGRA~2\MICROS~1\OFFICE12\REFIEBAR.DLL
### Allows you to use the Research Library and its collection of information s
ervices from Microsoft Internet Explorer Microsoft Corporation Research Library
Explorer Bar 12.0.4518.1014
[Context menu items] :HKCU Convert link target to Adobe PDF=res://C:\Program F
iles (x86)\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
### File is deleted or hidden by a rootkit or could not be located.
\AppData\Roaming\Mozilla\Firefox\Profiles\p2448cp5.default\extensions\save-as-pd
[email protected]
### [email protected]
[FireFox Components and Extensions] {2d3fbcf7-be69-4433-8858-c621a8d0e58d}=C:\
Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\p2448cp5.default\extensions
\{2d3fbcf7-be69-4433-8858-c621a8d0e58d}\
### {2d3fbcf7-be69-4433-8858-c621a8d0e58d} Widevine Media Optimizer Files npwi
devinemediaoptimizer.dll
[FireFox Components and Extensions] {5384767E-00D9-40E9-B72F-9CC39D655D6F}=C:\
Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\p2448cp5.default\extensions
\{5384767E-00D9-40E9-B72F-9CC39D655D6F}\
### {5384767E-00D9-40E9-B72F-9CC39D655D6F} EPUBReader Files aboutEpubcatalog.j
s aboutEpubreader.js catalog.js catalog.xul content.js
[FireFox Components and Extensions] {bb65e674-b194-4b6e-8033-5fa0afe3a198}=C:\
Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\p2448cp5.default\extensions
\{bb65e674-b194-4b6e-8033-5fa0afe3a198}.xpi
### {bb65e674-b194-4b6e-8033-5fa0afe3a198}
[FireFox Components and Extensions] {ec8030f7-c20a-464f-9b0e-13a3a9e97384}=C:\
Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\p2448cp5.default\extensions
\{bee6eb20-01e0-ebd1-da83-080329fb9a3a}\
### {ec8030f7-c20a-464f-9b0e-13a3a9e97384} Flash and Video Download Files down
loadManager.js downloadManager.xul oldOptions.xul options.js options.xul
[FireFox Components and Extensions] [email protected]=C:\Program File
s (x86)\WordWeb\WCaptureMoz\
### [email protected] WCaptureX Files wcapturex.js wcapturex.xul WcxT
race.js WCaptureXpcom.dll WcxComm.xpt
[FireFox Settings] :HKLM browser.startup.homepage=about:home
[FireFox Settings] :HKLM browser.startup.homepage_override_url=""
[FireFox Settings] :HKLM browser.search.selectedEngine=yahoo!
[FireFox Settings] :HKLM browser.search.selectedEngine,S=websearch
[FireFox Settings] :HKLM browser.search.defaultEnginename=""
[FireFox Settings] :HKLM browser.search.defaultEnginename,S=""
[FireFox Settings] :HKLM browser.search.order.1=websearch
[FireFox Settings] :HKLM browser.search.order.1,S=websearch
[FireFox Settings] :HKLM browser.search.defaulturl=http://websearch.toolksearc
hbook.info/?pid=725&r=2014/01/15&hid=2406902759796487476&lg=en&cc=in&unqvl=46&l=
1&q=
[FireFox Settings] :HKLM browser.newtab.url=""
[FireFox Settings] :HKLM keyword.URL=https://in.search.yahoo.com/search?fr=gre
entree_ff1&ei=utf-8&ilc=12&type=830633&p=
[FireFox Settings] :HKLM network.proxy.autoconfig_url=""
[FireFox Settings] :HKLM network.proxy.type=0
[FireFox Settings] :HKLM network.proxy.http=""
[FireFox Settings] :HKLM network.proxy.http_port=""
[Google Chrome Settings] :HKLM backup.homepage=""
[Google Chrome Settings] :HKLM backup.session.urls_to_restore_on_startup=""
[Google Chrome Settings] :HKLM session.startup_urls=""
[Google Chrome Settings] :HKLM default_search_provider.icon_url=""
[Google Chrome Settings] :HKLM default_search_provider.keyword=""
[Google Chrome Settings] :HKLM default_search_provider.name=""
[Google Chrome Settings] :HKLM default_search_provider.search_url=""
[Google Chrome Settings] :HKLM default_search_provider.suggest_url=""
[Google Chrome Settings] :HKLM default_search_provider_data.template_url_data.
alternate_urls=""
[Google Chrome Settings] :HKLM default_search_provider_data.template_url_data.
favicon_url=""
[Google Chrome Settings] :HKLM default_search_provider_data.template_url_data.
keyword=""
[Google Chrome Settings] :HKLM default_search_provider_data.template_url_data.
short_name=""
192.168.42.129 DhcpDefaultGateway:192.168.42.129
DhcpServer:192.168.42.129
[Name Server] {E07C7B77-C4E2-4FA2-9E6B-7A05403B03CD}=192.168.1.100
### Network Card:Realtek PCIe GBE Family Controller DefaultGateway:192.168.1.4
IPAddress:192.168.1.105
[WinSock2 Components] NLAapi.dll=C:\WINDOWS\SYSWOW64\NLAAPI.DLL
### Network Location Awareness 2 Microsoft Corporation Microsoft Windows Operati
ng System 6.1.7601.17514 %SystemRoot%\SYSWOW64\NLAapi.dll
[WinSock2 Components] napinsp.dll=C:\WINDOWS\SYSWOW64\NAPINSP.DLL
### E-mail Naming Shim Provider Microsoft Corporation Microsoft Windows Operatin
g System 6.1.7600.16385 %SystemRoot%\SYSWOW64\napinsp.dll
[WinSock2 Components] pnrpnsp.dll=C:\WINDOWS\SYSWOW64\PNRPNSP.DLL
### PNRP Name Space Provider Microsoft Corporation Microsoft Windows Operating S
ystem 6.1.7600.16385 %SystemRoot%\SYSWOW64\pnrpnsp.dll
[WinSock2 Components] mswsock.dll=C:\WINDOWS\SYSWOW64\MSWSOCK.DLL
### Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation Micro
soft Windows Operating System 6.1.7600.16385 %SystemRoot%\SYSWOW64\mswsock.dll
[WinSock2 Components] winrnr.dll=C:\WINDOWS\SYSWOW64\WINRNR.DLL
### LDAP RnR Provider DLL Microsoft Corporation Microsoft Windows Operating Syst
em 6.1.7600.16385 %SystemRoot%\SYSWOW64\winrnr.dll
[WinSock2 Components (x64)] NLAapi.dll=C:\WINDOWS\SYSNATIVE\NLAAPI.DLL
### Network Location Awareness 2 Microsoft Corporation Microsoft Windows Operati
ng System 6.1.7601.17514 %SystemRoot%\SYSNATIVE\NLAapi.dll
[WinSock2 Components (x64)] napinsp.dll=C:\WINDOWS\SYSNATIVE\NAPINSP.DLL
### E-mail Naming Shim Provider Microsoft Corporation Microsoft Windows Operatin
g System 6.1.7600.16385 %SystemRoot%\SYSNATIVE\napinsp.dll
[WinSock2 Components (x64)] pnrpnsp.dll=C:\WINDOWS\SYSNATIVE\PNRPNSP.DLL
### PNRP Name Space Provider Microsoft Corporation Microsoft Windows Operating S
ystem 6.1.7600.16385 %SystemRoot%\SYSNATIVE\pnrpnsp.dll
[WinSock2 Components (x64)] mswsock.dll=C:\WINDOWS\SYSNATIVE\MSWSOCK.DLL
### Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation Micro
soft Windows Operating System 6.1.7600.16385 %SystemRoot%\SYSNATIVE\mswsock.dll
[WinSock2 Components (x64)] winrnr.dll=C:\WINDOWS\SYSNATIVE\WINRNR.DLL
### LDAP RnR Provider DLL Microsoft Corporation Microsoft Windows Operating Syst
em 6.1.7600.16385 %SystemRoot%\SYSNATIVE\winrnr.dll
[Software Components]
[Internet Components] :HKLM C:\Windows\Downloaded Program Files\alttiff.ocx=C:
\WINDOWS\DOWNLOADED PROGRAM FILES\ALTTIFF.OCX
### AlternaTIFF ActiveX control Medical Informatics Engineering, Inc. AlternaT
IFF ActiveX control 2, 0, 6, 1
[Internet Components] :HKLM C:\Windows\System32\ActiveXRes_CHI.dll=C:\Windows\
System32\ActiveXRes_CHI.dll
### File is deleted or hidden by a rootkit or could not be located.
[Internet Components] :HKLM C:\Windows\System32\ActiveXRes_ENG.dll=C:\Windows\
System32\ActiveXRes_ENG.dll
### File is deleted or hidden by a rootkit or could not be located.
[Internet Components] :HKLM C:\Windows\System32\Calendar.ocx=C:\Windows\System
32\Calendar.ocx
### File is deleted or hidden by a rootkit or could not be located.
[Internet Components] :HKLM C:\Windows\System32\HCNetSDK.dll=C:\Windows\System
32\HCNetSDK.dll
### File is deleted or hidden by a rootkit or could not be located.
[Internet Components] :HKLM C:\Windows\System32\hpr.dll=C:\Windows\System32\hp
r.dll
### File is deleted or hidden by a rootkit or could not be located.
[Internet Components] :HKLM C:\Windows\System32\NetVideoActiveX23.ocx=C:\Windo
ws\System32\NetVideoActiveX23.ocx
### File is deleted or hidden by a rootkit or could not be located.
[Internet Components] :HKLM C:\Windows\System32\PlaybackActiveX23.ocx=C:\Windo
ws\System32\PlaybackActiveX23.ocx
### File is deleted or hidden by a rootkit or could not be located.
[Internet Components] :HKLM C:\Windows\System32\PlayBackBarActiveX.ocx=C:\Wind
ows\System32\PlayBackBarActiveX.ocx
### File is deleted or hidden by a rootkit or could not be located.
[Internet Components] :HKLM C:\Windows\System32\PlayCtrl.dll=C:\Windows\System
32\PlayCtrl.dll
### File is deleted or hidden by a rootkit or could not be located.
[Internet Components] :HKLM C:\Windows\System32\RealPlayActiveX23.ocx=C:\Windo
ws\System32\RealPlayActiveX23.ocx
### File is deleted or hidden by a rootkit or could not be located.
[Internet Components] :HKLM C:\Windows\System32\RemConfigRes_CHI.dll=C:\Window
s\System32\RemConfigRes_CHI.dll
### File is deleted or hidden by a rootkit or could not be located.
[Internet Components] :HKLM C:\Windows\System32\RemConfigRes_ENG.dll=C:\Window
s\System32\RemConfigRes_ENG.dll
### File is deleted or hidden by a rootkit or could not be located.
[Internet Components] :HKLM C:\Windows\System32\SearchLogActiveX23.ocx=C:\Wind
ows\System32\SearchLogActiveX23.ocx
### File is deleted or hidden by a rootkit or could not be located.
[Internet Components] :HKLM C:\Windows\System32\ShowRemConfig.dll=C:\Windows\S
ystem32\ShowRemConfig.dll
### File is deleted or hidden by a rootkit or could not be located.
[Internet Components] :HKLM C:\Windows\System32\StreamTransClient.dll=C:\Windo
ws\System32\StreamTransClient.dll
### File is deleted or hidden by a rootkit or could not be located.
[Internet Components] :HKLM C:\Windows\System32\SystemTransform.dll=C:\Windows
\System32\SystemTransform.dll
### File is deleted or hidden by a rootkit or could not be located.
[Windows Shell]
[Display Scrap's Extensions] :HKLM NeverShowExt=""
[ScreenSaver] :HKCU SCRNSAVE.EXE=""
### File is deleted or hidden by a rootkit or could not be located.
[System.ini] shell=explorer.exe
[User Shell] :HKCU shell=""
[Main File Extensions] :HKLM .exe="%1" %*
[Main File Extensions] :HKLM .com="%1" %*
[Main File Extensions] :HKLM .pif="%1" %*
[Main File Extensions] :HKLM .bat="%1" %*
[Main File Extensions] :HKLM .cmd="%1" %*
[Main File Extensions] :HKLM .scr="%1" /S
[Main File Extensions] :HKLM .txt=%SystemRoot%\system32\NOTEPAD.EXE %1
[Main File Extensions] :HKLM .reg=regedit.exe "%1"
[Main File Extensions] :HKLM .inf=%SystemRoot%\system32\NOTEPAD.EXE %1
[Main File Extensions] :HKLM .ini=%SystemRoot%\system32\NOTEPAD.EXE %1
[Main File Extensions] :HKLM .js=%SystemRoot%\System32\WScript.exe "%1" %*
[Main File Extensions] :HKLM .vbs=%SystemRoot%\System32\WScript.exe "%1" %*
[Main File Extensions] :HKLM .vbe=%SystemRoot%\System32\WScript.exe "%1" %*
[Main File Extensions] :HKLM .msc=%SystemRoot%\system32\mmc.exe "%1" %*
[Main File Extensions] :HKLM .jpg="C:\PROGRA~2\MICROS~1\Office12\OIS.EXE" /she
llOpen "%1"
[Main File Extensions] :HKLM .jpeg="C:\PROGRA~2\MICROS~1\Office12\OIS.EXE" /sh
ellOpen "%1"
[Shell Execute Hooks] :HKLM {B5A7F190-DDA6-4420-B3BA-52453494E6CD}=C:\PROGRA~2
\MICROS~1\OFFICE12\GR469A~1.DLL
### GrooveShellExtensions Module Microsoft Corporation GrooveShellExtensions M
odule 4.2.0.2623
[UserInit Value] :HKLM UserInit=C:\Windows\system32\userinit.exe,userinit.exe,
[Shell Services DelayLoad] :HKLM WebCheck={E6FB5E20-DE35-11CF-9C87-00AA005127E
D}
7, 0, 041126, 0, 161742
[App Paths] :HKLM foxitPhantom.exe=C:\Program Files (x86)\Foxit Software\Foxit
PhantomPDF\FoxitPhantomPDF.exe
### foxitPhantom.exe Foxit PhantomPDF 7.0 Foxit Software Inc. Foxit PhantomPDF
7.0.3.916
[App Paths] :HKLM free-mp3-splitter.exe=C:\Program Files (x86)\freestar\free-m
p3-splitter\free-mp3-splitter.exe.exe
### free-mp3-splitter.exe
[App Paths] :HKLM GROOVE.EXE=C:\PROGRA~2\MICROS~1\Office12\GROOVE.EXE
### GROOVE.EXE Microsoft Office Groove Microsoft Corporation Microsoft Office
Groove 4.2.0.2623
[App Paths] :HKLM IEDIAG.EXE=C:\Program Files\Internet Explorer\IEDIAGCMD.EXE
### IEDIAG.EXE Diagnostics utility for Internet Explorer Microsoft Corporation
Internet Explorer 11.00.9600.16428
[App Paths] :HKLM IEDIAGCMD.EXE=C:\Program Files\Internet Explorer\IEDIAGCMD.E
XE
### IEDIAGCMD.EXE Diagnostics utility for Internet Explorer Microsoft Corporat
ion Internet Explorer 11.00.9600.16428
[App Paths] :HKLM IEXPLORE.EXE=C:\Program Files\Internet Explorer\IEXPLORE.EXE
### IEXPLORE.EXE Internet Explorer Microsoft Corporation Internet Explorer 11.
00.9600.16428
[App Paths] :HKLM infopath.exe=C:\PROGRA~2\MICROS~1\Office12\INFOPATH.EXE
### infopath.exe Microsoft Office InfoPath 2007 Microsoft Corporation Microsof
t Office InfoPath 12.0.4518.1014
[App Paths] :HKLM install.exe
### install.exe
[App Paths] :HKLM iTunes.exe=C:\Program Files (x86)\iTunes\iTunes.exe
### iTunes.exe iTunes Apple Inc. iTunes 11.2.2.3
[App Paths] :HKLM j5store.exe=C:\Program Files (x86)\JewelArt\j5store.exe
### j5store.exe Asian Star Co. Ltd. JewelArt 3.03.0185
[App Paths] :HKLM javaws.exe=C:\Program Files (x86)\Java\jre1.8.0_77\bin\javaw
s.exe
### javaws.exe Java(TM) Web Start Launcher Oracle Corporation Java(TM) Platfor
m SE 8 U77 8.0.770.3
[App Paths] :HKLM Journal.exe=%ProgramFiles%\Windows Journal\Journal.exe
### Journal.exe
[App Paths] :HKLM kkdict.exe=C:\Program Files (x86)\KKDict\kkdict.exe
### kkdict.exe KK Dictionary www.kannadakasturi.com KK Dictionary 1.02
[App Paths] :HKLM mip.exe=%CommonProgramFiles%\Microsoft Shared\Ink\mip.exe
### mip.exe
[App Paths] :HKLM MobogenieAdd
### MobogenieAdd
[App Paths] :HKLM mplayer2.exe=%ProgramFiles(x86)%\Windows Media Player\wmplay
er.exe
### mplayer2.exe
[App Paths] :HKLM MSACCESS.EXE=C:\PROGRA~2\MICROS~1\Office12\MSACCESS.EXE
### MSACCESS.EXE Microsoft Office Access Microsoft Corporation 2007 Microsoft
Office system 12.0.4518.1014
[App Paths] :HKLM MsoHtmEd.exe
### MsoHtmEd.exe
[App Paths] :HKLM msoxmled.exe=C:\Program Files (x86)\Common Files\Microsoft S
hared\OFFICE12\MSOXMLED.EXE
### msoxmled.exe XML Editor Microsoft Corporation Microsoft Office InfoPath 12
.0.4518.1014
[App Paths] :HKLM MSPUB.EXE=C:\PROGRA~2\MICROS~1\Office12\MSPUB.EXE
### MSPUB.EXE Microsoft Office Publisher Microsoft Corporation 2007 Microsoft
Office system 12.0.4518.1014
[App Paths] :HKLM nmsetup.exe=C:\Program Files (x86)\Network Magic Pro Edition
\nmsetup.exe
### nmsetup.exe Cisco Network Magic Setup Cisco Systems, Inc. Network Magic 5.
5.09195.0
[App Paths] :HKLM ois.exe=C:\PROGRA~2\MICROS~1\Office12\OIS.EXE
### ois.exe Microsoft Office Picture Manager Microsoft Corporation Microsoft O
ffice Picture Manager 12.0.4518.1014
[App Paths] :HKLM OneNote.exe=C:\PROGRA~2\MICROS~1\Office12\ONENOTE.EXE
### OneNote.exe Microsoft Office OneNote Microsoft Corporation Microsoft Offic
e OneNote 12.0.4518.1014
[App Paths] :HKLM OUTLOOK.EXE=C:\PROGRA~2\MICROS~1\Office12\OUTLOOK.EXE
### OUTLOOK.EXE Microsoft Office Outlook Microsoft Corporation Microsoft Offic
e Outlook 12.0.4518.1014
[App Paths] :HKLM pbrush.exe=%SystemRoot%\System32\mspaint.exe
### pbrush.exe
[App Paths] :HKLM PCCompanion.exe=C:\Program Files (x86)\Sony\Sony PC Companio
n\PCCompanion.exe
### PCCompanion.exe Sony PC Companion Sony Sony PC Companion 2.1.0
[App Paths] :HKLM PMUNINST.exe
### PMUNINST.exe
[App Paths] :HKLM powerpnt.exe=C:\PROGRA~2\MICROS~1\Office12\POWERPNT.EXE
### powerpnt.exe Microsoft Office PowerPoint Microsoft Corporation 2007 Micros
oft Office system 12.0.4518.1014
[App Paths] :HKLM PowerShell.exe=%SystemRoot%\system32\WindowsPowerShell\v1.0\
PowerShell.exe
### PowerShell.exe
[App Paths] :HKLM QuickTimePlayer.exe=C:\Program Files (x86)\QuickTime\QuickTi
mePlayer.exe
### QuickTimePlayer.exe QuickTime Player Apple Inc. QuickTime QuickTime 7.7.5
(1680.95.13)
[App Paths] :HKLM RevoUninPro.exe=C:\Program Files\VS Revo Group\Revo Uninstal
ler Pro\RevoUninPro.exe
### RevoUninPro.exe Revo Uninstaller Pro VS Revo Group Revo Uninstaller Pro 2.
5.9.0
[App Paths] :HKLM setup.exe
### setup.exe
[App Paths] :HKLM sidebar.exe="%ProgramFiles%\Windows Sidebar\sidebar.exe"
### sidebar.exe
[App Paths] :HKLM Skd8821.exe=C:\Program Files\Lenovo\Lenovo Slim USB Keyboard
\Skd8821.exe
### Skd8821.exe Lenovo Slim USB Keyboard LITE-ON TECHNOLOGY CORP. Lenovo Slim
USB Keyboard 1, 0, 0, 0
[App Paths] :HKLM SnippingTool.exe=%SystemRoot%\system32\SnippingTool.exe
### SnippingTool.exe
[App Paths] :HKLM Sony Mobile Update Engine.exe=C:\Program Files (x86)\Sony Mo
bile\Update Engine\Sony Mobile Update Engine.exe
### Sony Mobile Update Engine.exe
[App Paths] :HKLM table30.exe
### table30.exe
[App Paths] :HKLM TabTip.exe=%CommonProgramFiles%\microsoft shared\ink\TabTip.
exe
### TabTip.exe
[App Paths] :HKLM Unlocker.exe=C:\Program Files (x86)\Unlocker\Unlocker.exe
### Unlocker.exe
[App Paths] :HKLM vmplayer.exe=C:\Program Files (x86)\VMware\VMware Workstatio
n\vmplayer.exe
### vmplayer.exe VMware Player VMware, Inc. VMware Workstation 10.0.0 build-12
95980
[App Paths] :HKLM vmware.exe=C:\Program Files (x86)\VMware\VMware Workstation\
vmware.exe
### vmware.exe VMware Workstation VMware, Inc. VMware Workstation 10.0.0 build
-1295980
[App Paths] :HKLM wab.exe=%ProgramFiles%\Windows Mail\wab.exe
### wab.exe
[App Paths] :HKLM wabmig.exe=%ProgramFiles%\Windows Mail\wabmig.exe
### wabmig.exe
[App Paths] :HKLM WinRAR.exe=C:\Program Files\WinRAR\WinRAR.exe
### WinRAR.exe WinRAR archiver Alexander Roshal WinRAR 5.21.0
[App Paths] :HKLM Winword.exe=C:\PROGRA~2\MICROS~1\Office12\WINWORD.EXE
### Winword.exe Microsoft Office Word Microsoft Corporation 2007 Microsoft Off
ice system 12.0.4518.1014
[App Paths] :HKLM winzip.exe=C:\PROGRA~1\WinZip\winzip64.exe
### winzip.exe WinZip WinZip Computing, S.L. WinZip 18.5 (11111)
[App Paths] :HKLM winzip32.exe=C:\PROGRA~1\WinZip\winzip64.exe
### winzip32.exe WinZip WinZip Computing, S.L. WinZip 18.5 (11111)
[App Paths] :HKLM winzip64.exe=C:\PROGRA~1\WinZip\winzip64.exe
### winzip64.exe WinZip WinZip Computing, S.L. WinZip 18.5 (11111)
[App Paths] :HKLM Wireshark.exe=C:\Program Files\Wireshark\Wireshark.exe
### Wireshark.exe Wireshark The Wireshark developer community, http://www.wire
shark.org/ Wireshark 1.10.7
[App Paths] :HKLM wmplayer.exe=%ProgramFiles(x86)%\Windows Media Player\wmplay
er.exe
### wmplayer.exe
[App Paths] :HKLM WORDPAD.EXE=C:\PROGRAM FILES (X86)\WINDOWS NT\ACCESSORIES\WO
RDPAD.EXE
### WORDPAD.EXE Windows Wordpad Application Microsoft Corporation Microsoft Win
dows Operating System 6.1.7600.16385 "%ProgramFiles%\Windows NT\Accessories\WORD
PAD.EXE"
[App Paths] :HKLM WRITE.EXE="%ProgramFiles%\Windows NT\Accessories\WORDPAD.EXE
"
### WRITE.EXE
[Prevents Display in Control Panel from running.] :HKCU NoDispCpl=0
[Disable Registry Tools] :HKCU DisableRegistryTools =0
[Internet Shortcuts] :HKLM C:\Users\admin\AppData\Roaming\Microsoft\Windows\St
art Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk=HT
TP://WWW.OURSURFING.COM/?TYPE=SC&TS=1439368024&Z=73C5E4DE807BB6E83FA8AC5G7Z6C6T4
C4Q2BEE7TAC&FROM=2SQ&UID=ST2000DM001-1CH164_W1F5EHSDXXXXW1F5EHSD
### C:\Users\admin\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\ACCESS~1
\SYSTEM~1\INTERN~1.LNK
[Internet Shortcuts] :HKLM C:\Users\admin\AppData\Roaming\Microsoft\Windows\St
art Menu\Programs\Internet Explorer.lnk=HTTP://WWW.OURSURFING.COM/?TYPE=SC&TS=14
39368024&Z=73C5E4DE807BB6E83FA8AC5G7Z6C6T4C4Q2BEE7TAC&FROM=2SQ&UID=ST2000DM001-1
CH164_W1F5EHSDXXXXW1F5EHSD
### C:\Users\admin\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\INTERN~2
.LNK
[Internet Shortcuts] :HKLM C:\ProgramData\Microsoft\Windows\Start Menu\Program
s\Mozilla Firefox.lnk=HTTP://WWW.GOOGLE.COM
### C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\MOZILL~1.LNK
[Internet Shortcuts] :HKLM C:\ProgramData\Microsoft\Windows\Start Menu\Program
s\UnHackMe\Check for UnHackMe updates.lnk=HTTP://GREATIS.COM/UNHACKME.INI
### C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\UnHackMe\CHECKF~1.LNK
[Internet Shortcuts] :HKLM C:\Users\admin\AppData\Roaming\Microsoft\Internet E
xplorer\Quick Launch\Launch Internet Explorer Browser.lnk=HTTP://WWW.OURSURFING.
COM/?TYPE=SC&TS=1439368024&Z=73C5E4DE807BB6E83FA8AC5G7Z6C6T4C4Q2BEE7TAC&FROM=2SQ
&UID=ST2000DM001-1CH164_W1F5EHSDXXXXW1F5EHSD
### C:\Users\admin\AppData\Roaming\MICROS~1\INTERN~1\QUICKL~1\LAUNCH~1.LNK
[Internet Shortcuts] :HKLM C:\Users\admin\AppData\Roaming\Microsoft\Internet E
xplorer\Quick Launch\User Pinned\StartMenu\Mozilla Firefox.lnk=HTTP://WWW.GOOGLE
.COM
### C:\Users\admin\AppData\Roaming\MICROS~1\INTERN~1\QUICKL~1\USERPI~1\STARTM~
1\MOZILL~1.LNK
[Internet Shortcuts] :HKLM C:\Users\admin\AppData\Roaming\Microsoft\Internet E
xplorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk=HTTP://WWW.GOOGLE.C
OM
### C:\Users\admin\AppData\Roaming\MICROS~1\INTERN~1\QUICKL~1\USERPI~1\TaskBar
\MOZILL~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\Desktop\All Free MP3 Cutter.lnk=C:\Progr
am Files (x86)\All Free MP3 Cutter\AllFreeMP3Cutter.exe
### C:\Users\admin\Desktop\ALLFRE~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\Desktop\baraha\Baraha.exe - Shortcut.lnk
=C:\Program Files (x86)\Baraha Software\Baraha 10\Baraha.exe
### C:\Users\admin\Desktop\baraha\BARAHA~2.LNK
[User Shortcuts] :HKLM C:\Users\admin\Desktop\baraha\BarahaIME.exe - Shortcut.
lnk=C:\Program Files (x86)\Baraha Software\Baraha 10\BarahaIME.exe
### C:\Users\admin\Desktop\baraha\BARAHA~3.LNK
[User Shortcuts] :HKLM C:\Users\admin\Desktop\baraha\BarahaPad.exe - Shortcut.
lnk=C:\Program Files (x86)\Baraha Software\Baraha 10\BarahaPad.exe
### C:\Users\admin\Desktop\baraha\BARAHA~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\Desktop\baraha\FontConvert.exe - Shortcu
t.lnk=C:\Program Files (x86)\Baraha Software\Baraha 10\FontConvert.exe
### C:\Users\admin\Desktop\baraha\FONTCO~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\Desktop\Bullzip PDF Printer.lnk=C:\Progr
am Files (x86)\Bullzip\PDF Printer\gui.exe
### C:\Users\admin\Desktop\BULLZI~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\Desktop\CMS.lnk=C:\Program Files (x86)\C
MS\CMS.exe
### C:\Users\admin\Desktop\CMS.lnk
[User Shortcuts] :HKLM C:\Users\admin\Desktop\Daossoft Excel Password Recovery
.lnk=C:\Program Files (x86)\Daossoft Excel Password Recovery\ExcelPasswordRecove
ry.exe
### C:\Users\admin\Desktop\DAOSSO~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\Desktop\Dev-C++.lnk=C:\Program Files (x8
6)\Dev-Cpp\devcpp.exe
### C:\Users\admin\Desktop\DEV-C_~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\Desktop\Dictionary.lnk=C:\Program Files
(x86)\Shipra's Dictionary\dictN1.exe
### C:\Users\admin\Desktop\DICTIO~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\Desktop\DLIMonkey.exe - Shortcut.lnk=C:\
Users\admin\Downloads\dlimonkey\bin\DLIMonkey.exe
### C:\Users\admin\Desktop\DLIMON~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\Desktop\Easy MP3 Cutter.lnk=C:\Program F
iles (x86)\Easy MP3 Cutter\mp3_cutter.exe
### C:\Users\admin\Desktop\EASYMP~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\Desktop\Excel-Xls to Pdf Converter.lnk=C
:\Program Files (x86)\Excel-Xls to Pdf Converter\Converter.exe
### C:\Users\admin\Desktop\EXCEL-~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\Desktop\Foxit Advanced PDF Editor.exe.ln
k=C:\Program Files (x86)\Foxit Software\Foxit Advanced PDF Editor\Foxit Advanced
PDF Editor.exe
### C:\Users\admin\Desktop\FOXITA~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\Desktop\Free Download Manager.lnk=C:\Pro
gram Files (x86)\Free Download Manager\fdm.exe
### C:\Users\admin\Desktop\FREEDO~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\Desktop\FreeStar Free MP3 Splitter.lnk=C
:\Program Files (x86)\freestar\free-mp3-splitter\free-mp3-splitter.exe
### C:\Users\admin\Desktop\FREEST~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\Desktop\HTTrack Website Copier.lnk=C:\Pr
ogram Files (x86)\WinHTTrack\WinHTTrack.exe
### C:\Users\admin\Desktop\HTTRAC~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\Desktop\lan - Shortcut.lnk=C:\Users\admi
n\AppData\Roaming\Microsoft\Windows\Libraries\lan.library-ms
### C:\Users\admin\Desktop\LAN-SH~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\Desktop\MediaCoder x64.lnk=C:\Program Fi
les (x86)\MediaCoder\MediaCoder.exe
### C:\Users\admin\Desktop\MEDIAC~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\Desktop\Network Magic Pro Edition.lnk=C:
\Program Files (x86)\Network Magic Pro Edition\nmsetup.exe
### C:\Users\admin\Desktop\NETWOR~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\Desktop\OfficeRecovery 2013 Ultimate.lnk
=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OfficeRecovery 2013 Ultima
te
### C:\Users\admin\Desktop\OFFICE~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\Desktop\Prezi.exe - Shortcut.lnk=C:\Prog
ram Files (x86)\Prezi\Prezi.exe
### C:\Users\admin\Desktop\PREZIE~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\Desktop\Stellar Phoenix Windows Data Rec
overy - Professional.lnk=C:\Program Files (x86)\Stellar Phoenix Windows Data Rec
overy\spwdrp.exe
### C:\Users\admin\Desktop\STELLA~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\Desktop\Total Video Converter.lnk=C:\Pro
gram Files (x86)\Total Video Converter\tvcshell.exe
### C:\Users\admin\Desktop\TOTALV~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\Desktop\Total Video Player.lnk=C:\Progra
m Files (x86)\Total Video Converter\tvp.exe
### C:\Users\admin\Desktop\TOTALV~2.LNK
[User Shortcuts] :HKLM C:\Users\admin\Desktop\udemy_ripper.exe - Shortcut (2).
lnk=E:\pendrive\Software\UDEMY RIPPER [LOADER] [WORK AROUND RANDOM COURSE DOWNLO
AD]\UDEMY RIPPER [LOADER]\UDEMY RIPPER [LOADER]\udemy_ripper.exe
### C:\Users\admin\Desktop\UDEMY_~2.LNK
[User Shortcuts] :HKLM C:\Users\admin\Desktop\udemy_ripper.exe - Shortcut.lnk=
E:\pendrive\Software\UDEMY RIPPER [LOADER] [WORK AROUND RANDOM COURSE DOWNLOAD]\
UDEMY RIPPER [LOADER]\UDEMY RIPPER [LOADER]\udemy_ripper.exe
### C:\Users\admin\Desktop\UDEMY_~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\Desktop\UnHackMe.lnk=C:\Program Files (x
86)\UnHackMe\Unhackme.exe
### C:\Users\admin\Desktop\UnHackMe.lnk
[User Shortcuts] :HKLM C:\Users\admin\Desktop\Windows 7 USB DVD Download Tool.
lnk=C:\Users\admin\AppData\Local\Apps\Windows 7 USB DVD Download Tool\Windows7-U
SB-DVD-Download-Tool.exe
### C:\Users\admin\Desktop\WINDOW~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\Desktop\Wondershare PDF Editor.lnk=C:\Pr
ogram Files (x86)\Wondershare\PDFEditor\PDFEditor.exe
### C:\Users\admin\Desktop\WONDER~1.LNK
[User Shortcuts] :HKLM C:\Users\Public\Desktop\Acrobat Reader DC.lnk=C:\Progra
m Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe
### C:\Users\Public\Desktop\ACROBA~1.LNK
[User Shortcuts] :HKLM C:\Users\Public\Desktop\Adobe Acrobat 7.0 Professional.
lnk=C:\Program Files (x86)\Adobe\Acrobat 7.0\Acrobat\Acrobat.exe
### C:\Users\Public\Desktop\ADOBEA~1.LNK
[User Shortcuts] :HKLM C:\Users\Public\Desktop\AMCap.lnk=C:\Windows\amcap.exe
### C:\Users\Public\Desktop\AMCap.lnk
[User Shortcuts] :HKLM C:\Users\Public\Desktop\B9Creator.lnk=C:\Program Files
(x86)\B9Creations\B9Creator\B9Creator.exe
### C:\Users\Public\Desktop\B9CREA~1.LNK
[User Shortcuts] :HKLM C:\Users\Public\Desktop\Bitstream Font Navigator (64-Bi
t).lnk=C:\Program Files (x86)\Corel\CorelDRAW Graphics Suite X7\FontNav64\FontNa
v.exe
### C:\Users\Public\Desktop\BITSTR~1.LNK
[User Shortcuts] :HKLM C:\Users\Public\Desktop\CCleaner.lnk=C:\Program Files (
x86)\CCleaner\CCleaner64.exe
### C:\Users\Public\Desktop\CCleaner.lnk
[User Shortcuts] :HKLM C:\Users\Public\Desktop\Corel CAPTURE X7 (64-Bit).lnk=c
:\Windows\Installer\{2C91CB9D-323D-43E5-A433-229B71CFB773}\NewShortcut8_65BCA6E0
337A452DA55C0654EAAD7A0B.exe
### C:\Users\Public\Desktop\CORELC~1.LNK
[User Shortcuts] :HKLM C:\Users\Public\Desktop\Corel PHOTO-PAINT X7 (64-Bit).l
nk=c:\Windows\Installer\{C922F325-DD52-4E22-B204-431A06E63E51}\NewShortcut2_EBB5
1BFEE10948A888CB7ADF96E8EC80.exe
### C:\Users\Public\Desktop\CORELP~1.LNK
[User Shortcuts] :HKLM C:\Users\Public\Desktop\CorelDRAW X7 (64-Bit).lnk=c:\Wi
ndows\Installer\{2C0DDC74-5234-43DD-BB5A-0645B8FE5289}\NewShortcut1_68427AB8B2C0
44C58AA777A4C3F75634.exe
### C:\Users\Public\Desktop\CORELD~1.LNK
[User Shortcuts] :HKLM C:\Users\Public\Desktop\DameWare Mini Remote Control.ln
k=C:\Program Files (x86)\SolarWinds\DameWare Mini Remote Control 9.0\DWRCC.exe
### C:\Users\Public\Desktop\DAMEWA~2.LNK
[User Shortcuts] :HKLM C:\Users\Public\Desktop\EaseUS Data Recovery Wizard 7.5
.lnk=C:\Program Files (x86)\EaseUS\EaseUS Data Recovery Wizard\DRW.exe
### C:\Users\Public\Desktop\EASEUS~1.LNK
[User Shortcuts] :HKLM C:\Users\Public\Desktop\Foxit PhantomPDF.lnk=C:\Program
Files (x86)\Foxit Software\Foxit PhantomPDF\FoxitPhantomPDF.exe
### C:\Users\Public\Desktop\FOXITP~1.LNK
[User Shortcuts] :HKLM C:\Users\Public\Desktop\FREE Word and Excel password re
covery Wizard.lnk=C:\Program Files (x86)\FREE Word and Excel password recovery W
izard\FreeWordExcel.exe
### C:\Users\Public\Desktop\FREEWO~1.LNK
[User Shortcuts] :HKLM C:\Users\Public\Desktop\Free YouTube Downloader.lnk=C:\
Program Files (x86)\Free YouTube Downloader\YouTubeDownloader.exe
### C:\Users\Public\Desktop\FREEYO~1.LNK
[User Shortcuts] :HKLM C:\Users\Public\Desktop\Google Chrome.lnk=C:\Program Fi
les (x86)\Google\Chrome\Application\chrome.exe
### C:\Users\Public\Desktop\GOOGLE~1.LNK
[User Shortcuts] :HKLM C:\Users\Public\Desktop\ImTOO DVD Audio Ripper.lnk=C:\P
rogram Files (x86)\ImTOO\DVD Audio Ripper\drloader.exe
### C:\Users\Public\Desktop\IMTOOD~1.LNK
[User Shortcuts] :HKLM C:\Users\Public\Desktop\Intel(R) Driver Update Utility
2.4.lnk=C:\Program Files (x86)\Intel Driver Update Utility\DriverUpdateUI.exe
### C:\Users\Public\Desktop\INTEL(~1.LNK
[User Shortcuts] :HKLM C:\Users\Public\Desktop\iTunes.lnk=C:\Program Files (x8
6)\iTunes\iTunes.exe
### C:\Users\Public\Desktop\iTunes.lnk
[User Shortcuts] :HKLM C:\Users\Public\Desktop\iVMS-4000(v2.0).lnk=C:\Program
Files\iVMS-4000(v2.0)\NetAppSoft.exe
### C:\Users\Public\Desktop\IVMS-4~1.LNK
[User Shortcuts] :HKLM C:\Users\Public\Desktop\iVMS-4200 Client.lnk=C:\Program
Files (x86)\iVMS-4200 Station\iVMS-4200\iVMS-4200 Client\iVMS-4200.exe
### C:\Users\Public\Desktop\IVMS-4~2.LNK
[User Shortcuts] :HKLM C:\Users\Public\Desktop\LAN Speed Test.lnk=C:\Program F
iles (x86)\LAN Speed Test\LAN_SpeedTest.exe
### C:\Users\Public\Desktop\LANSPE~1.LNK
[User Shortcuts] :HKLM C:\Users\Public\Desktop\Magics 13.0 64bit.lnk=C:\Windo
ws\Installer\{78A136F4-6FC0-403E-8BFF-953063BD122C}\Magics.exe
### C:\Users\Public\Desktop\MAGICS~1.LNK
[User Shortcuts] :HKLM C:\Users\Public\Desktop\Meda MP3 Joiner.lnk=C:\Program
Files (x86)\Meda MP3 Joiner\MP3Joiner.exe
### C:\Users\Public\Desktop\MEDAMP~1.LNK
[User Shortcuts] :HKLM C:\Users\Public\Desktop\MiniMagics.lnk=C:\Program Files
(x86)\Materialise\MiniMagics\MiniMagics.exe
### C:\Users\Public\Desktop\MINIMA~1.LNK
[User Shortcuts] :HKLM C:\Users\Public\Desktop\MiniTool Partition Wizard Home
Edition.lnk=C:\Program Files (x86)\MiniTool Partition Wizard Home Edition 5.2\Pa
rtitionWizard.exe
### C:\Users\Public\Desktop\MINITO~2.LNK
\Installer\{90120000-0030-0000-0000-0000000FF1CE}\wordicon.exe
### C:\Users\admin\AppData\Roaming\MICROS~1\INTERN~1\QUICKL~1\USERPI~1\STARTM~
1\MICROS~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\AppData\Roaming\Microsoft\Internet Explo
rer\Quick Launch\User Pinned\StartMenu\Mozilla Firefox.lnk=C:\Program Files (x86
)\Mozilla Firefox\firefox.exe
### C:\Users\admin\AppData\Roaming\MICROS~1\INTERN~1\QUICKL~1\USERPI~1\STARTM~
1\MOZILL~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\AppData\Roaming\Microsoft\Internet Explo
rer\Quick Launch\User Pinned\TaskBar\Adobe Acrobat 7.0 Professional.lnk=C:\Windo
ws\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe
### C:\Users\admin\AppData\Roaming\MICROS~1\INTERN~1\QUICKL~1\USERPI~1\TaskBar
\ADOBEA~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\AppData\Roaming\Microsoft\Internet Explo
rer\Quick Launch\User Pinned\TaskBar\Dictionary.lnk=C:\Program Files (x86)\Shipr
a's Dictionary\dictN1.exe
### C:\Users\admin\AppData\Roaming\MICROS~1\INTERN~1\QUICKL~1\USERPI~1\TaskBar
\DICTIO~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\AppData\Roaming\Microsoft\Internet Explo
rer\Quick Launch\User Pinned\TaskBar\DLIMonkey.exe - Shortcut.lnk=C:\Users\admin
\Downloads\dlimonkey\bin\DLIMonkey.exe
### C:\Users\admin\AppData\Roaming\MICROS~1\INTERN~1\QUICKL~1\USERPI~1\TaskBar
\DLIMON~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\AppData\Roaming\Microsoft\Internet Explo
rer\Quick Launch\User Pinned\TaskBar\dmca CT.lnk=C:\Downloads\Software\GRAB DMCA
for CT\GRAB DMCA for CT\GRAB DMCA for CT.exe
### C:\Users\admin\AppData\Roaming\MICROS~1\INTERN~1\QUICKL~1\USERPI~1\TaskBar
\DMCACT~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\AppData\Roaming\Microsoft\Internet Explo
rer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk=C:\Program Files (x86)\Go
ogle\Chrome\Application\chrome.exe
### C:\Users\admin\AppData\Roaming\MICROS~1\INTERN~1\QUICKL~1\USERPI~1\TaskBar
\GOOGLE~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\AppData\Roaming\Microsoft\Internet Explo
rer\Quick Launch\User Pinned\TaskBar\Lenovo Slim USB Keyboard.lnk=C:\Program Fil
es (x86)\Lenovo\Lenovo Slim USB Keyboard\Skd8821.exe
### C:\Users\admin\AppData\Roaming\MICROS~1\INTERN~1\QUICKL~1\USERPI~1\TaskBar
\LENOVO~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\AppData\Roaming\Microsoft\Internet Explo
rer\Quick Launch\User Pinned\TaskBar\Meda MP3 Joiner.lnk=C:\Program Files (x86)\
Meda MP3 Joiner\MP3Joiner.exe
### C:\Users\admin\AppData\Roaming\MICROS~1\INTERN~1\QUICKL~1\USERPI~1\TaskBar
\MEDAMP~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\AppData\Roaming\Microsoft\Internet Explo
rer\Quick Launch\User Pinned\TaskBar\MiniTool Partition Wizard Professional Edit
ion.lnk=C:\Program Files (x86)\MiniTool Partition Wizard Professional Edition 9.
1\PartitionWizard.exe
### C:\Users\admin\AppData\Roaming\MICROS~1\INTERN~1\QUICKL~1\USERPI~1\TaskBar
\MINITO~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\AppData\Roaming\Microsoft\Internet Explo
rer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk=C:\Program Files (x86)\
Mozilla Firefox\firefox.exe
### C:\Users\admin\AppData\Roaming\MICROS~1\INTERN~1\QUICKL~1\USERPI~1\TaskBar
\MOZILL~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\AppData\Roaming\Microsoft\Internet Explo
rer\Quick Launch\User Pinned\TaskBar\Setup Factory setup launcher.lnk=C:\Users\a
dmin\Downloads\Shipradictionary.exe
### C:\Users\admin\AppData\Roaming\MICROS~1\INTERN~1\QUICKL~1\USERPI~1\TaskBar
\SETUPF~1.LNK
[User Shortcuts] :HKLM C:\Users\admin\AppData\Roaming\Microsoft\Internet Explo
### Microsoft Fax Print Monitor Microsoft Corporation Microsoft Windows Operati
ng System 6.1.7601.17514 FXSMON.DLL
[Print Monitors] :HKLM Standard TCP/IP Port=C:\Windows\system32\TCPMON.DLL
### Standard TCP/IP Port Monitor DLL Microsoft Corporation Microsoft Windows Ope
rating System 6.1.7600.16385 tcpmon.dll
[Print Monitors] :HKLM USB Monitor=C:\Windows\system32\USBMON.DLL
### Standard Dynamic Printing Port Monitor DLL Microsoft Corporation Microsoft
Windows Operating System 6.1.7600.16385 usbmon.dll
[Print Monitors] :HKLM Wondershare PDF Editor Monitor=C:\Windows\system32\WSMO
NEDITOR.DLL
### Wondershare Software PDF Converter 4.0.0.0 WSMonEditor.dll
[Print Monitors] :HKLM WSD Port=C:\Windows\system32\WSDMON.DLL
### WSD Printer Port Monitor Microsoft Corporation Microsoft Windows Operating S
ystem 6.1.7600.16385 WSDMon.dll
[Shell Icon Overlay Handlers] :HKLM EnhancedStorageShell=C:\WINDOWS\SYSTEM32\E
HSTORSHELL.DLL
### Windows Enhanced Storage Shell Extension DLL Microsoft Corporation Microso
ft Windows Operating System 6.1.7600.16385 %SystemRoot%\system32\EhStorShell.dll
[Shell Icon Overlay Handlers] :HKLM Groove Explorer Icon Overlay 1 (GFS Unread
Stub)=C:\PROGRA~2\MICROS~1\OFFICE12\GR469A~1.DLL
### GrooveShellExtensions Module Microsoft Corporation GrooveShellExtensions M
odule 4.2.0.2623
[Shell Icon Overlay Handlers] :HKLM Groove Explorer Icon Overlay 2 (GFS Stub)=
C:\PROGRA~2\MICROS~1\OFFICE12\GR469A~1.DLL
### GrooveShellExtensions Module Microsoft Corporation GrooveShellExtensions M
odule 4.2.0.2623
[Shell Icon Overlay Handlers] :HKLM Groove Explorer Icon Overlay 2.5 (GFS Unre
ad Folder)=C:\PROGRA~2\MICROS~1\OFFICE12\GR469A~1.DLL
### GrooveShellExtensions Module Microsoft Corporation GrooveShellExtensions M
odule 4.2.0.2623
[Shell Icon Overlay Handlers] :HKLM Groove Explorer Icon Overlay 3 (GFS Folder
)=C:\PROGRA~2\MICROS~1\OFFICE12\GR469A~1.DLL
### GrooveShellExtensions Module Microsoft Corporation GrooveShellExtensions M
odule 4.2.0.2623
[Shell Icon Overlay Handlers] :HKLM Groove Explorer Icon Overlay 4 (GFS Unread
Mark)=C:\PROGRA~2\MICROS~1\OFFICE12\GR469A~1.DLL
### GrooveShellExtensions Module Microsoft Corporation GrooveShellExtensions M
odule 4.2.0.2623
[Shell Icon Overlay Handlers] :HKLM SharingPrivate=C:\WINDOWS\SYSTEM32\NTSHRUI
.DLL
### Shell extensions for sharing Microsoft Corporation Microsoft Windows Operati
ng System 6.1.7600.16385 %SystemRoot%\system32\ntshrui.dll
[Context Menu Handlers] :HKLM 7-Zip=C:\PROGRAM FILES (X86)\7-ZIP\7-ZIP.DLL
### 7-Zip Shell Extension Igor Pavlov 7-Zip 9.20
[Context Menu Handlers] :HKLM Adobe.Acrobat.ContextMenu=C:\PROGRAM FILES (X86)
\ADOBE\ACROBAT 7.0\ACROBAT ELEMENTS\CONTEXTMENU.DLL
### Adobe Acrobat Context Menu Adobe Systems Inc. Adobe Acrobat Elements 7.0.0
.0\0
[Context Menu Handlers] :HKLM BriefcaseMenu=C:\WINDOWS\SYSTEM32\SYNCUI.DLL
### Windows Briefcase Microsoft Corporation Microsoft Windows Operating System 6
.1.7600.16385 %SystemRoot%\system32\syncui.dll
[Context Menu Handlers] :HKLM DMRC Shell Extension V2={358B5852-38EB-4549-9D8A
-B90C9DCAD0DB}
[Context Menu Handlers] :HKLM Foxit_ConvertToPDF={C5269811-4A29-4818-A4BB-111F
9FC63A5F}
[Context Menu Handlers] :HKLM Open With=C:\WINDOWS\SYSTEM32\SHELL32.DLL
### Windows Shell Common Dll Microsoft Corporation Microsoft Windows Operating S
ystem 6.1.7601.17514 %SystemRoot%\system32\shell32.dll
[Context Menu Handlers] :HKLM Open With EncryptionMenu=C:\WINDOWS\SYSTEM32\SHE
LL32.DLL
### Windows Shell Common Dll Microsoft Corporation Microsoft Windows Operating S
ystem 6.1.7601.17514 %SystemRoot%\system32\shell32.dll
[Context Menu Handlers] :HKLM Sharing=C:\WINDOWS\SYSTEM32\NTSHRUI.DLL
### Shell extensions for sharing Microsoft Corporation Microsoft Windows Operati
ng System 6.1.7600.16385 %SystemRoot%\system32\ntshrui.dll
[Context Menu Handlers] :HKLM TVCShellExt={4E33A7F5-8083-4C08-9D45-C5CED88F5C0
4}
[Context Menu Handlers] :HKLM WDBackupMenuHandler={C752BC82-C19A-4827-9C15-099
6BA85C180}
[Context Menu Handlers] :HKLM WinRAR={B41DB860-64E4-11D2-9906-E49FADC173CA}
[Context Menu Handlers] :HKLM WinRAR32=C:\PROGRAM FILES\WINRAR\RAREXT32.DLL
### WinRAR shell extension Alexander Roshal WinRAR 5.21.0
[Context Menu Handlers] :HKLM WinZip=C:\PROGRAM FILES\WINZIP\WZSHLSTB.DLL
### WinZip Shell Extension DLL WinZip Computing, S.L. WinZip 18.5 (10060)
[Context Menu Handlers] :HKLM XXX Groove GFS Context Menu Handler XXX=C:\PROGR
A~2\MICROS~1\OFFICE12\GR469A~1.DLL
### GrooveShellExtensions Module Microsoft Corporation GrooveShellExtensions M
odule 4.2.0.2623
[Context Menu Handlers] :HKLM {90AA3A4E-1CBA-4233-B8BB-535773D48449}=C:\WINDOW
S\SYSTEM32\SHELL32.DLL
### Windows Shell Common Dll Microsoft Corporation Microsoft Windows Operating S
ystem 6.1.7601.17514 %SystemRoot%\system32\shell32.dll
[Context Menu Handlers] :HKLM {a2a9545d-a0c2-42b4-9708-a0b2badd77c8}=C:\WINDOW
S\SYSTEM32\SHELL32.DLL
### Windows Shell Common Dll Microsoft Corporation Microsoft Windows Operating S
ystem 6.1.7601.17514 %SystemRoot%\system32\shell32.dll
[Context Menu Handlers] :HKLM {F764812A-132C-4013-9960-5CBBEB408A0E}=C:\PROGRA
M FILES (X86)\COMMON FILES\NERO\NEROSHELLEXT\NEROSHELLEXT.DLL
### Nero Burning ROM Shell Extension Nero AG NeroShellExt 12,0,20,0
[Kernel Auto Boot]
[ActiveSetup] >{22d6f312-b0f6-11d0-94ab-0080c74c7e95}=C:\WINDOWS\SYSTEM32\UNRE
GMP2.EXE
### Microsoft Windows Media Player Setup Utility Microsoft Corporation Microso
ft Windows Operating System 12.0.7600.16385 %SystemRoot%\system32\unregmp2.exe /S
howWMP
[Auto Services] AdobeARMservice
### Internal Name: AdobeARMservice. Status: service is running. Actual File: "
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe" * Adobe Acrobat Up
dater keeps your Adobe software up to date. Adobe Acrobat Update Service Adobe S
ystems Incorporated Adobe Acrobat Update Service 1.824.16.6751
[Auto Services] AudioEndpointBuilder
### Internal Name: AudioEndpointBuilder. Status: service is running. Actual Fi
le: C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted * Manages au
dio devices for the Windows Audio service. If this service is stopped, audio de
vices and effects will not function properly. If this service is disabled, any
services that explicitly depend on it will fail to start Host Process for Window
s Services Microsoft Corporation Microsoft Windows Operating System 6.1.7600.16385
[Auto Services] AudioSrv
### Internal Name: AudioSrv. Status: service is running. Actual File: C:\Windo
ws\System32\svchost.exe -k LocalServiceNetworkRestricted * Manages audio for Win
dows-based programs. If this service is stopped, audio devices and effects will
not function properly. If this service is disabled, any services that explicit
ly depend on it will fail to start Host Process for Windows Services Microsoft C
orporation Microsoft Windows Operating System 6.1.7600.16385
[Auto Services] BFE
### Internal Name: BFE. Status: service is running. Actual File: C:\Windows\sy
stem32\svchost.exe -k LocalServiceNoNetwork * The Base Filtering Engine (BFE) is
a service that manages firewall and Internet Protocol security (IPsec) policies
and implements user mode filtering. Stopping or disabling the BFE service will
significantly reduce the security of the system. It will also result in unpredic
table behavior in IPsec management and firewall applications. Host Process for W
indows Services Microsoft Corporation Microsoft Windows Operating System 6.1.7600.
16385
[Auto Services] BITS
### Internal Name: BITS. Status: service is running. Actual File: C:\Windows\S
ystem32\svchost.exe -k netsvcs * Transfers files in the background using idle ne
twork bandwidth. If the service is disabled, then any applications that depend o
n BITS, such as Windows Update or MSN Explorer, will be unable to automatically
download programs and other information. Host Process for Windows Services Micro
soft Corporation Microsoft Windows Operating System 6.1.7600.16385
[Auto Services] clr_optimization_v4.0.30319_32
### Internal Name: clr_optimization_v4.0.30319_32. Status: service stopped. Ac
tual File: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe * Microsof
t .NET Framework NGEN .NET Runtime Optimization Service Microsoft Corporation Mi
crosoft .NET Framework 4.0.30319.17929
[Auto Services] clr_optimization_v4.0.30319_64
### Internal Name: clr_optimization_v4.0.30319_64. Status: service stopped. Ac
tual File: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe * Micros
oft .NET Framework NGEN .NET Runtime Optimization Service Microsoft Corporation
Microsoft .NET Framework 4.0.30319.17929
[Auto Services] CryptSvc
### Internal Name: CryptSvc. Status: service is running. Actual File: C:\Windo
ws\system32\svchost.exe -k NetworkService * Provides four management services: C
atalog Database Service, which confirms the signatures of Windows files and allo
ws new programs to be installed; Protected Root Service, which adds and removes
Trusted Root Certification Authority certificates from this computer; Automatic
Root Certificate Update Service, which retrieves root certificates from Windows
Update and enable scenarios such as SSL; and Key Service, which helps enroll thi
s computer for certificates. If this service is stopped, these management servic
es will not function properly. If this service is disabled, any services that ex
plicitly depend on it will fail to start. Host Process for Windows Services Micr
osoft Corporation Microsoft Windows Operating System 6.1.7600.16385
[Auto Services] CscService
### Internal Name: CscService. Status: service is running. Actual File: C:\Win
dows\System32\svchost.exe -k LocalSystemNetworkRestricted * The Offline Files se
rvice performs maintenance activities on the Offline Files cache, responds to us
er logon and logoff events, implements the internals of the public API, and disp
atches interesting events to those interested in Offline Files activities and ch
anges in cache state. Host Process for Windows Services Microsoft Corporation Mi
crosoft Windows Operating System 6.1.7600.16385
[Auto Services] DcomLaunch
### Internal Name: DcomLaunch. Status: service is running. Actual File: C:\Win
dows\system32\svchost.exe -k DcomLaunch * The DCOMLAUNCH service launches COM an
d DCOM servers in response to object activation requests. If this service is sto
pped or disabled, programs using COM or DCOM will not function properly. It is s
trongly recommended that you have the DCOMLAUNCH service running. Host Process f
or Windows Services Microsoft Corporation Microsoft Windows Operating System 6.1.7
600.16385
[Auto Services] Dhcp
### Internal Name: Dhcp. Status: service is running. Actual File: C:\Windows\s
ystem32\svchost.exe -k LocalServiceNetworkRestricted * Registers and updates IP
addresses and DNS records for this computer. If this service is stopped, this co
mputer will not receive dynamic IP addresses and DNS updates. If this service is
disabled, any services that explicitly depend on it will fail to start. Host Pr
ocess for Windows Services Microsoft Corporation Microsoft Windows Operating Syste
m 6.1.7600.16385
[Auto Services] Dnscache
### Internal Name: Dnscache. Status: service is running. Actual File: C:\Windo
ws\system32\svchost.exe -k NetworkService * The DNS Client service (dnscache) ca
ches Domain Name System (DNS) names and registers the full computer name for thi
s computer. If the service is stopped, DNS names will continue to be resolved. H
owever, the results of DNS name queries will not be cached and the computer's na
me will not be registered. If the service is disabled, any services that explici
tly depend on it will fail to start. Host Process for Windows Services Microsoft
Corporation Microsoft Windows Operating System 6.1.7600.16385
[Auto Services] DPS
### Internal Name: DPS. Status: service is running. Actual File: C:\Windows\Sy
stem32\svchost.exe -k LocalServiceNoNetwork * The Diagnostic Policy Service enab
les problem detection, troubleshooting and resolution for Windows components. I
f this service is stopped, diagnostics will no longer function. Host Process for
Windows Services Microsoft Corporation Microsoft Windows Operating System 6.1.760
0.16385
[Auto Services] EFS
### Internal Name: EFS. Status: service is running. Actual File: C:\Windows\Sy
stem32\lsass.exe * Provides the core file encryption technology used to store en
crypted files on NTFS file system volumes. If this service is stopped or disable
d, applications will be unable to access encrypted files. Local Security Authori
ty Process Microsoft Corporation Microsoft Windows Operating System 6.1.7601.18443
[Auto Services] ESRV_SVC_WILLAMETTE
### Internal Name: ESRV_SVC_WILLAMETTE. Status: service is running. Actual Fil
e: "C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\esrv_svc.exe" "--AUTO_START" "--s
tart" "--address" "127.0.0.1" "--port" "49330" "--depend_on_key" "SYSTEM\Current
ControlSet\Services\ESRV_SVC_WILLAMETTE" "--depend_on_value" "run" "--time_in_ms
" "--pause" "5000" "--library" "C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\intel
_modeler.dll" "--no_pl" "--watchdog" "10" "--watchdog_cpu_usage_limit" "50" "--e
nd_on_error" "--kernel_priority_boost" "--shutdown_priority_boost" "--device_opt
ions" " time=no output=w output_folder='C:\ProgramData\Intel\SUR\WILLAMETTE\Inte
lData' limit_output_by=time output_limit=3600000 output_buffer=1024 il='C:\Progr
am Files\Intel\SUR\WILLAMETTE\ESRV\intel_process_input.dll','process_input_optio
ns.txt' il='C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\intel_system_power_state_
input.dll' il='C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\intel_quality_and_reli
ability_input.dll' il='C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\acpi_battery_i
nput.dll' il='C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\sema_thermal_input.dll'
il='C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\wifi_input.dll' il='C:\Program F
iles\Intel\SUR\WILLAMETTE\ESRV\devices_use_input.dll','service=yes' il='C:\Progr
am Files\Intel\SUR\WILLAMETTE\ESRV\intel_disktrace_input.dll','pause=60000 worki
ng_dir=C:\ProgramData\Intel\SUR\WILLAMETTE\IntelData override_existing_tracing=n
o limit_output_by_filesize_mb=10' os='C:\Program Files\Intel\SUR\WILLAMETTE\ESRV
\os_counters.txt' " * Intel(r) Energy Checker SDK. ESRV Service WILLAMETTE Inte
l(R) System Usage Report Intel(R) System Usage Report
[Auto Services] eventlog
### Internal Name: eventlog. Status: service is running. Actual File: C:\Windo
ws\System32\svchost.exe -k LocalServiceNetworkRestricted * This service manages
events and event logs. It supports logging events, querying events, subscribing
to events, archiving event logs, and managing event metadata. It can display eve
nts in both XML and plain text format. Stopping this service may compromise secu
rity and reliability of the system. Host Process for Windows Services Microsoft
Corporation Microsoft Windows Operating System 6.1.7600.16385
[Auto Services] EventSystem
### Internal Name: EventSystem. Status: service is running. Actual File: C:\Wi
ndows\system32\svchost.exe -k LocalService * Supports System Event Notification
Service (SENS), which provides automatic distribution of events to subscribing C
omponent Object Model (COM) components. If the service is stopped, SENS will clo
se and will not be able to provide logon and logoff notifications. If this servi
ce is disabled, any services that explicitly depend on it will fail to start. Ho
st Process for Windows Services Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385
[Auto Services] FontCache
### Internal Name: FontCache. Status: service is running. Actual File: C:\Wind
ows\system32\svchost.exe -k LocalService * Optimizes performance of applications
by caching commonly used font data. Applications will start this service if it
is not already running. It can be disabled, though doing so will degrade applica
tion performance. Host Process for Windows Services Microsoft Corporation Micros
oft Windows Operating System 6.1.7600.16385
[Auto Services] GoogleInputService
### Internal Name: GoogleInputService. Status: service is running. Actual File
: "C:\Program Files (x86)\Google\Google Input Tools\GoogleInputService.exe" * G
oogle Input Tools. Google Inc Google Input Tools 1.1.3.18
[Auto Services] gpsvc
### Internal Name: gpsvc. Status: service is running. Actual File: C:\Windows\
system32\svchost.exe -k netsvcs * The service is responsible for applying settin
gs configured by administrators for the computer and users through the Group Pol
icy component. If the service is stopped or disabled, the settings will not be a
pplied and applications and components will not be manageable through Group Poli
cy. Any components or applications that depend on the Group Policy component mig
ht not be functional if the service is stopped or disabled. Host Process for Win
dows Services Microsoft Corporation Microsoft Windows Operating System 6.1.7600.16
385
[Auto Services] gupdate
### Internal Name: gupdate. Status: service stopped. Actual File: "C:\Program
Files (x86)\Google\Update\GoogleUpdate.exe" /svc * Keeps your Google software up
to date. If this service is disabled or stopped, your Google software will not
be kept up to date, meaning security vulnerabilities that may arise cannot be fi
xed and features may not work. This service uninstalls itself when there is no G
oogle software using it. Google Installer Google Inc. Google Update 1.3.29.1
[Auto Services] IKEEXT
### Internal Name: IKEEXT. Status: service is running. Actual File: C:\Windows
\system32\svchost.exe -k netsvcs * The IKEEXT service hosts the Internet Key Exc
hange (IKE) and Authenticated Internet Protocol (AuthIP) keying modules. These k
eying modules are used for authentication and key exchange in Internet Protocol
security (IPsec). Stopping or disabling the IKEEXT service will disable IKE and
AuthIP key exchange with peer computers. IPsec is typically configured to use IK
E or AuthIP; therefore, stopping or disabling the IKEEXT service might result in
an IPsec failure and might compromise the security of the system. It is strongl
y recommended that you have the IKEEXT service running. Host Process for Windows
Services Microsoft Corporation Microsoft Windows Operating System 6.1.7600.16385
[Auto Services] iphlpsvc
### Internal Name: iphlpsvc. Status: service is running. Actual File: C:\Windo
ws\System32\svchost.exe -k NetSvcs * Provides tunnel connectivity using IPv6 tra
nsition technologies (6to4, ISATAP, Port Proxy, and Teredo), and IP-HTTPS. If th
is service is stopped, the computer will not have the enhanced connectivity bene
fits that these technologies offer. Host Process for Windows Services Microsoft
Corporation Microsoft Windows Operating System 6.1.7600.16385
[Auto Services] LanmanServer
### Internal Name: LanmanServer. Status: service is running. Actual File: C:\W
indows\system32\svchost.exe -k netsvcs * Supports file, print, and named-pipe sh
aring over the network for this computer. If this service is stopped, these func
tions will be unavailable. If this service is disabled, any services that explic
itly depend on it will fail to start. Host Process for Windows Services Microsof
t Corporation Microsoft Windows Operating System 6.1.7600.16385
[Auto Services] LanmanWorkstation
### Internal Name: LanmanWorkstation. Status: service is running. Actual File:
C:\Windows\System32\svchost.exe -k NetworkService * Creates and maintains clien
t network connections to remote servers using the SMB protocol. If this service
is stopped, these connections will be unavailable. If this service is disabled,
any services that explicitly depend on it will fail to start. Host Process for W
indows Services Microsoft Corporation Microsoft Windows Operating System 6.1.7600.
16385
cess for Windows Services Microsoft Corporation Microsoft Windows Operating System
6.1.7600.16385
[Auto Services] PcaSvc
### Internal Name: PcaSvc. Status: service is running. Actual File: C:\Windows
\system32\svchost.exe -k LocalSystemNetworkRestricted * This service provides su
pport for the Program Compatibility Assistant (PCA). PCA monitors programs inst
alled and run by the user and detects known compatibility problems. If this serv
ice is stopped, PCA will not function properly. Host Process for Windows Service
s Microsoft Corporation Microsoft Windows Operating System 6.1.7600.16385
[Auto Services] PelService
### Internal Name: PelService. Status: service is running. Actual File: C:\Pro
gram Files\Lenovo\Lenovo Mouse Suite\PelService.exe *
[Auto Services] PlugPlay
### Internal Name: PlugPlay. Status: service is running. Actual File: C:\Windo
ws\system32\svchost.exe -k DcomLaunch * Enables a computer to recognize and adap
t to hardware changes with little or no user input. Stopping or disabling this s
ervice will result in system instability. Host Process for Windows Services Micr
osoft Corporation Microsoft Windows Operating System 6.1.7600.16385
[Auto Services] Pml Driver HPZ12
### Internal Name: Pml Driver HPZ12. Status: service is running. Actual File:
C:\Windows\System32\svchost.exe -k HPZ12 * Host Process for Windows Services Mi
crosoft Corporation Microsoft Windows Operating System 6.1.7600.16385
[Auto Services] Power
### Internal Name: Power. Status: service is running. Actual File: C:\Windows\
system32\svchost.exe -k DcomLaunch * Manages power policy and power policy notif
ication delivery. Host Process for Windows Services Microsoft Corporation Micros
oft Windows Operating System 6.1.7600.16385
[Auto Services] ProfSvc
### Internal Name: ProfSvc. Status: service is running. Actual File: C:\Window
s\system32\svchost.exe -k netsvcs * This service is responsible for loading and
unloading user profiles. If this service is stopped or disabled, users will no l
onger be able to successfully logon or logoff, applications may have problems ge
tting to users' data, and components registered to receive profile event notific
ations will not receive them. Host Process for Windows Services Microsoft Corpor
ation Microsoft Windows Operating System 6.1.7600.16385
[Auto Services] PSI_SVC_2_x64
### Internal Name: PSI_SVC_2_x64. Status: service is running. Actual File: "c:
\Program Files\Common Files\Protexis\License Service\PsiService_2.exe" * This se
rvice provides license-validation functionality for Corel Corporation. It is pow
ered by Protexis from arvato digital Services. PsiService PsiService arvato digi
tal services llc PsiService System Service 3.3.0.24
[Auto Services] RemoteRegistry
### Internal Name: RemoteRegistry. Status: service is running. Actual File: C:
\Windows\system32\svchost.exe -k regsvc * Enables remote users to modify registr
y settings on this computer. If this service is stopped, the registry can be mod
ified only by users on this computer. If this service is disabled, any services
that explicitly depend on it will fail to start. Host Process for Windows Servic
es Microsoft Corporation Microsoft Windows Operating System 6.1.7600.16385
[Auto Services] RosettaStoneDaemon
### Internal Name: RosettaStoneDaemon. Status: service is running. Actual File
: "C:\Program Files (x86)\RosettaStoneLtdServices\RosettaStoneDaemon.exe" * Ros
etta Stone Ltd. application Rosetta Stone Ltd. Rosetta Stone Daemon 1.0.1.0
[Auto Services] RpcEptMapper
### Internal Name: RpcEptMapper. Status: service is running. Actual File: C:\W
indows\system32\svchost.exe -k RPCSS * Resolves RPC interfaces identifiers to tr
ansport endpoints. If this service is stopped or disabled, programs using Remote
Procedure Call (RPC) services will not function properly. Host Process for Wind
ows Services Microsoft Corporation Microsoft Windows Operating System 6.1.7600.163
85
[Auto Services] RpcSs
### Internal Name: RpcSs. Status: service is running. Actual File: C:\Windows\
system32\svchost.exe -k rpcss * The RPCSS service is the Service Control Manager
for COM and DCOM servers. It performs object activations requests, object expor
ter resolutions and distributed garbage collection for COM and DCOM servers. If
this service is stopped or disabled, programs using COM or DCOM will not functio
n properly. It is strongly recommended that you have the RPCSS service running H
ost Process for Windows Services Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385
[Auto Services] SamSs
### Internal Name: SamSs. Status: service is running. Actual File: C:\Windows\
system32\lsass.exe * The startup of this service signals other services that the
Security Accounts Manager (SAM) is ready to accept requests. Disabling this se
rvice will prevent other services in the system from being notified when the SAM
is ready, which may in turn cause those services to fail to start correctly. Th
is service should not be disabled. Local Security Authority Process Microsoft Co
rporation Microsoft Windows Operating System 6.1.7601.18443
[Auto Services] Schedule
### Internal Name: Schedule. Status: service is running. Actual File: C:\Windo
ws\system32\svchost.exe -k netsvcs * Enables a user to configure and schedule au
tomated tasks on this computer. The service also hosts multiple Windows system-c
ritical tasks. If this service is stopped or disabled, these tasks will not be r
un at their scheduled times. If this service is disabled, any services that expl
icitly depend on it will fail to start. Host Process for Windows Services Micros
oft Corporation Microsoft Windows Operating System 6.1.7600.16385
[Auto Services] SENS
### Internal Name: SENS. Status: service is running. Actual File: C:\Windows\s
ystem32\svchost.exe -k netsvcs * Monitors system events and notifies subscribers
to COM+ Event System of these events. Host Process for Windows Services Microso
ft Corporation Microsoft Windows Operating System 6.1.7600.16385
[Auto Services] ShellHWDetection
### Internal Name: ShellHWDetection. Status: service is running. Actual File:
C:\Windows\System32\svchost.exe -k netsvcs * Provides notifications for AutoPlay
hardware events. Host Process for Windows Services Microsoft Corporation Micros
oft Windows Operating System 6.1.7600.16385
[Auto Services] Sks8821
### Internal Name: Sks8821. Status: service is running. Actual File: C:\Progra
m Files\Lenovo\Lenovo Slim USB Keyboard\Sks8821.exe *
[Auto Services] Spooler
### Internal Name: Spooler. Status: service is running. Actual File: C:\Window
s\System32\spoolsv.exe * Loads files to memory for later printing Spooler SubSys
tem App Microsoft Corporation Microsoft Windows Operating System 6.1.7600.16385
[Auto Services] stisvc
### Internal Name: stisvc. Status: service is running. Actual File: C:\Windows
\system32\svchost.exe -k imgsvc * Provides image acquisition services for scanne
rs and cameras Host Process for Windows Services Microsoft Corporation Microsoft
Windows Operating System 6.1.7600.16385
[Auto Services] SysMain
### Internal Name: SysMain. Status: service is running. Actual File: C:\Window
s\system32\svchost.exe -k LocalSystemNetworkRestricted * Maintains and improves
system performance over time. Host Process for Windows Services Microsoft Corpor
ation Microsoft Windows Operating System 6.1.7600.16385
[Auto Services] SystemUsageReportSvc_WILLAMETTE
### Internal Name: SystemUsageReportSvc_WILLAMETTE. Status: service is running
. Actual File: "C:\Program Files (x86)\Intel Driver Update Utility\SUR\SurSvc.ex
e" * Inte(R) System Usage Report Service SystemUsageReportSvc_WILLAMETTE monitor
s the computer system usage and helps to improve system's performance. Intel(R)
System Usage Report Intel(R) System Usage Report
[Auto Services] TeamViewer9
### Internal Name: TeamViewer9. Status: service is running. Actual File: "C:\P
rogram Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe" * TeamViewer Remo
em 6.1.7600.16385 %SystemRoot%\System32\Audiosrv.dll
[Svchost DLLs] :HKLM dot3svc=C:\WINDOWS\SYSTEM32\DOT3SVC.DLL
### Wired AutoConfig Service Microsoft Corporation Microsoft Windows Operating S
ystem 6.1.7600.16385 %SystemRoot%\System32\dot3svc.dll
[Svchost DLLs] :HKLM WPDBusEnum=C:\WINDOWS\SYSTEM32\WPDBUSENUM.DLL
### Portable Device Enumerator Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385 %SystemRoot%\system32\wpdbusenum.dll
[Svchost DLLs] :HKLM wlansvc=C:\WINDOWS\SYSTEM32\WLANSVC.DLL
### Windows WLAN AutoConfig Service DLL Microsoft Corporation Microsoft Windows
Operating System 6.1.7600.16385 %SystemRoot%\System32\wlansvc.dll
[Svchost DLLs] :HKLM PLA=C:\WINDOWS\SYSTEM32\PLA.DLL
### Performance Logs & Alerts Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385 %systemroot%\system32\pla.dll
[Svchost DLLs] :HKLM RpcSs=C:\WINDOWS\SYSTEM32\RPCSS.DLL
### Distributed COM Services Microsoft Corporation Microsoft Windows Operating S
ystem 6.1.7601.17514 %SystemRoot%\system32\rpcss.dll
[Svchost DLLs] :HKLM BthHFSrv
[Svchost DLLs] :HKLM LmHosts=C:\WINDOWS\SYSTEM32\LMHSVC.DLL
### TCPIP NetBios Transport Services DLL Microsoft Corporation Microsoft Window
s Operating System 6.1.7600.16385 %SystemRoot%\System32\lmhsvc.dll
[Svchost DLLs] :HKLM wscsvc=C:\WINDOWS\SYSTEM32\WSCSVC.DLL
### Windows Security Center Service Microsoft Corporation Microsoft Windows Oper
ating System 6.1.7600.16385 %SystemRoot%\System32\wscsvc.dll
[Svchost DLLs] :HKLM WPCSvc=C:\WINDOWS\SYSTEM32\WPCSVC.DLL
### WPC Filtering Service Microsoft Corporation Windows 1.0.0.1 %SystemRoot%\
System32\wpcsvc.dll
[Svchost DLLs] :HKLM SSDPSRV=C:\WINDOWS\SYSTEM32\SSDPSRV.DLL
### SSDP Service DLL Microsoft Corporation Microsoft Windows Operating System 6.
1.7600.16385 %SystemRoot%\System32\ssdpsrv.dll
[Svchost DLLs] :HKLM upnphost=C:\WINDOWS\SYSTEM32\UPNPHOST.DLL
### UPnP Device Host Microsoft Corporation Microsoft Windows Operating System 6.
1.7600.16385 %SystemRoot%\System32\upnphost.dll
[Svchost DLLs] :HKLM SCardSvr=C:\WINDOWS\SYSTEM32\SCARDSVR.DLL
### Smart Card Resource Management Server Microsoft Corporation Microsoft Windo
ws Operating System 6.1.7600.16385 %SystemRoot%\System32\SCardSvr.dll
[Svchost DLLs] :HKLM TBS=C:\WINDOWS\SYSTEM32\TBSSVC.DLL
### TBS Service Microsoft Corporation Microsoft Windows Operating System 6.1.760
0.16385 %SystemRoot%\System32\tbssvc.dll
[Svchost DLLs] :HKLM QWAVE=C:\WINDOWS\SYSTEM32\QWAVE.DLL
### Windows NT Microsoft Corporation Microsoft Windows Operating System 6.1.7600
.16385 %windir%\system32\qwave.dll
[Svchost DLLs] :HKLM wcncsvc=C:\WINDOWS\SYSTEM32\WCNCSVC.DLL
### Windows Connect Now - Config Registrar Service Microsoft Corporation Micro
soft Windows Operating System 6.1.7600.16385 %SystemRoot%\System32\wcncsvc.dll
[Svchost DLLs] :HKLM Power=C:\WINDOWS\SYSTEM32\UMPO.DLL
### User-mode Power Service Microsoft Corporation Microsoft Windows Operating Sy
stem 6.1.7600.16385 %SystemRoot%\system32\umpo.dll
[Svchost DLLs] :HKLM PlugPlay=C:\WINDOWS\SYSTEM32\UMPNPMGR.DLL
### User-mode Plug-and-Play Service Microsoft Corporation Microsoft Windows Oper
ating System 6.1.7600.16385 %SystemRoot%\system32\umpnpmgr.dll
[Svchost DLLs] :HKLM DcomLaunch=C:\WINDOWS\SYSTEM32\RPCSS.DLL
### Distributed COM Services Microsoft Corporation Microsoft Windows Operating S
ystem 6.1.7601.17514 %SystemRoot%\system32\rpcss.dll
[Svchost DLLs] :HKLM CryptSvc=C:\WINDOWS\SYSTEM32\CRYPTSVC.DLL
### Cryptographic Services Microsoft Corporation Microsoft Windows Operating Sys
tem 6.1.7600.16385 %SystemRoot%\system32\cryptsvc.dll
[Svchost DLLs] :HKLM DHCP=C:\WINDOWS\SYSTEM32\DHCPCORE.DLL
### DHCP Client Service Microsoft Corporation Microsoft Windows Operating System
6.1.7601.17514 %SystemRoot%\system32\dhcpcore.dll
[Svchost DLLs] :HKLM DNSCache=C:\WINDOWS\SYSTEM32\DNSRSLVR.DLL
### DNS Caching Resolver Service Microsoft Corporation Microsoft Windows Operati
ng System 6.1.7600.16385 %SystemRoot%\System32\dnsrslvr.dll
[Svchost DLLs] :HKLM NapAgent=C:\WINDOWS\SYSTEM32\QAGENTRT.DLL
### Quarantine Agent Service Run-Time Microsoft Corporation Microsoft Windows Op
erating System 6.1.7600.16385 %SystemRoot%\system32\qagentRT.dll
[Svchost DLLs] :HKLM nlasvc=C:\WINDOWS\SYSTEM32\NLASVC.DLL
### Network Location Awareness 2 Microsoft Corporation Microsoft Windows Operati
ng System 6.1.7600.16385 %SystemRoot%\System32\nlasvc.dll
[Svchost DLLs] :HKLM WinRM=C:\WINDOWS\SYSTEM32\WSMSVC.DLL
### WSMan Service Microsoft Corporation Microsoft Windows Operating System 6.1.7
600.16385 %SystemRoot%\system32\WsmSvc.dll
[Svchost DLLs] :HKLM WECSVC=C:\WINDOWS\SYSTEM32\WECSVC.DLL
### Event Collector Service Microsoft Corporation Microsoft Windows Operating Sy
stem 6.1.7600.16385 %SystemRoot%\system32\wecsvc.dll
[Svchost DLLs] :HKLM StiSvc=C:\WINDOWS\SYSTEM32\WIASERVC.DLL
### Still Image Devices Service Microsoft Corporation Microsoft Windows Operatin
g System 6.1.7600.16385 %SystemRoot%\System32\wiaservc.dll
[Svchost DLLs] :HKLM WcsPlugInService=C:\WINDOWS\SYSTEM32\WCSPLUGINSERVICE.DLL
### WcsPlugInService DLL Microsoft Corporation Microsoft Windows Operating Syste
m 6.1.7600.16385 %SystemRoot%\System32\WcsPlugInService.dll
[Svchost DLLs] :HKLM AppIDSvc=C:\WINDOWS\SYSTEM32\APPIDSVC.DLL
### Application Identity Service Microsoft Corporation Microsoft Windows Operati
ng System 6.1.7600.16385 %SystemRoot%\System32\appidsvc.dll
[Svchost DLLs] :HKLM Appinfo=C:\WINDOWS\SYSTEM32\APPINFO.DLL
### Application Information Service Microsoft Corporation Microsoft Windows Oper
ating System 6.1.7600.16385 %SystemRoot%\System32\appinfo.dll
[Svchost DLLs] :HKLM AxInstSV=C:\WINDOWS\SYSTEM32\AXINSTSV.DLL
### ActiveX Installer Service Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385 %SystemRoot%\System32\AxInstSV.dll
[Svchost DLLs] :HKLM BDESVC=C:\WINDOWS\SYSTEM32\BDESVC.DLL
### BDE Service Microsoft Corporation Microsoft Windows Operating System 6.1.760
0.16385 %SystemRoot%\System32\bdesvc.dll
[Svchost DLLs] :HKLM BFE=C:\WINDOWS\SYSTEM32\BFE.DLL
### Base Filtering Engine Microsoft Corporation Microsoft Windows Operating Syst
em 6.1.7600.16385 %SystemRoot%\System32\bfe.dll
[Svchost DLLs] :HKLM Browser=C:\WINDOWS\SYSTEM32\BROWSER.DLL
### Computer Browser Service DLL Microsoft Corporation Microsoft Windows Operati
ng System 6.1.7600.16385 %SystemRoot%\System32\browser.dll
[Svchost DLLs] :HKLM bthserv=C:\WINDOWS\SYSTEM32\BTHSERV.DLL
### Bluetooth Support Service Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385 %SystemRoot%\system32\bthserv.dll
[Svchost DLLs] :HKLM CscService=C:\WINDOWS\SYSTEM32\CSCSVC.DLL
### CSC Service DLL Microsoft Corporation Microsoft Windows Operating System 6.1
.7600.16385 %SystemRoot%\System32\cscsvc.dll
[Svchost DLLs] :HKLM defragsvc=C:\WINDOWS\SYSTEM32\DEFRAGSVC.DLL
### Microsoft\Disk Defragmenter Microsoft Corporation Microsoft Windows Operatin
g System 6.1.7600.16385 %Systemroot%\System32\defragsvc.dll
[Svchost DLLs] :HKLM DPS=C:\WINDOWS\SYSTEM32\DPS.DLL
### WDI Diagnostic Policy Service Microsoft Corporation Microsoft Windows Operat
ing System 6.1.7600.16385 %SystemRoot%\system32\dps.dll
[Svchost DLLs] :HKLM EapHost=C:\WINDOWS\SYSTEM32\EAPSVC.DLL
### Microsoft EAPHost service Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385 %SystemRoot%\System32\eapsvc.dll
[Svchost DLLs] :HKLM EventSystem=C:\WINDOWS\SYSTEM32\ES.DLL
### COM+ Microsoft Corporation Microsoft Windows Operating System 6.1.7600.16385
%systemroot%\system32\es.dll
[Svchost DLLs] :HKLM fdPHost=C:\WINDOWS\SYSTEM32\FDPHOST.DLL
### Function Discovery Provider host service Microsoft Corporation Microsoft Wi
ndows Operating System 6.1.7600.16385 %SystemRoot%\system32\fdPHost.dll
[Svchost DLLs] :HKLM FDResPub=C:\WINDOWS\SYSTEM32\FDRESPUB.DLL
### LSI MegaRAID Software RAID Driver LSI Corporation, Inc. MegaRAID Software
RAID 13.05.0409.2009 \SystemRoot\system32\DRIVERS\MegaSR.sys Service registry k
ey doesn't exist or hidden.
[Drivers] :HKLM MEIx64=C:\WINDOWS\SYSTEM32\DRIVERS\HECIX64.SYS
### Intel(R) Management Engine Interface Intel Corporation Intel(R) Management
Engine Interface 7.0.0.1144 Service registry key doesn't exist or hidden.
[Drivers] :HKLM Modem=C:\WINDOWS\SYSTEM32\DRIVERS\MODEM.SYS
### Modem Device Driver Microsoft Corporation Microsoft Windows Operating System
6.1.7600.16385 Service registry key doesn't exist or hidden.
[Drivers] :HKLM monitor=C:\WINDOWS\SYSTEM32\DRIVERS\MONITOR.SYS
### Monitor Driver Microsoft Corporation Microsoft Windows Operating System 6.1.
7600.16385 Service registry key doesn't exist or hidden.
[Drivers] :HKLM mouclass=C:\WINDOWS\SYSTEM32\DRIVERS\MOUCLASS.SYS
### Mouse Class Driver Microsoft Corporation Microsoft Windows Operating System
6.1.7600.16385 Service registry key doesn't exist or hidden.
[Drivers] :HKLM mouhid=C:\WINDOWS\SYSTEM32\DRIVERS\MOUHID.SYS
### HID Mouse Filter Driver Microsoft Corporation Microsoft Windows Operating Sy
stem 6.1.7600.16385 Service registry key doesn't exist or hidden.
[Drivers] :HKLM mountmgr=C:\WINDOWS\SYSTEM32\DRIVERS\MOUNTMGR.SYS
### Mount Point Manager Microsoft Corporation Microsoft Windows Operating System
6.1.7600.16385 Service registry key doesn't exist or hidden.
[Drivers] :HKLM mpio=C:\WINDOWS\SYSTEM32\DRIVERS\MPIO.SYS
### MultiPath Support Bus-Driver Microsoft Corporation Microsoft Windows Operati
ng System 6.1.7600.16385 \SystemRoot\system32\drivers\mpio.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM mpsdrv=C:\WINDOWS\SYSTEM32\DRIVERS\MPSDRV.SYS
### Microsoft Protection Service Driver Microsoft Corporation Microsoft Windows
Operating System 6.1.7600.16385 Service registry key doesn't exist or hidden.
[Drivers] :HKLM MRxDAV=C:\WINDOWS\SYSTEM32\DRIVERS\MRXDAV.SYS
### Windows NT WebDav Minirdr Microsoft Corporation Microsoft Windows Operating
System 6.1.7601.17514 \SystemRoot\system32\drivers\mrxdav.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM mrxsmb=C:\WINDOWS\SYSTEM32\DRIVERS\MRXSMB.SYS
### Windows NT SMB Minirdr Microsoft Corporation Microsoft Windows Operating Sys
tem 6.1.7601.17605 Service registry key doesn't exist or hidden.
[Drivers] :HKLM mrxsmb10=C:\WINDOWS\SYSTEM32\DRIVERS\MRXSMB10.SYS
### Longhorn SMB Downlevel SubRdr Microsoft Corporation Microsoft Windows Operat
ing System 6.1.7601.17647 Service registry key doesn't exist or hidden.
[Drivers] :HKLM mrxsmb20=C:\WINDOWS\SYSTEM32\DRIVERS\MRXSMB20.SYS
### Longhorn SMB 2.0 Redirector Microsoft Corporation Microsoft Windows Operatin
g System 6.1.7601.17605 Service registry key doesn't exist or hidden.
[Drivers] :HKLM msahci=C:\WINDOWS\SYSTEM32\DRIVERS\MSAHCI.SYS
### MS AHCI 1.0 Standard Driver Microsoft Corporation Microsoft Windows Operatin
g System 6.1.7601.17514 Service registry key doesn't exist or hidden.
[Drivers] :HKLM msdsm=C:\WINDOWS\SYSTEM32\DRIVERS\MSDSM.SYS
### Microsoft Device Specific Module Microsoft Corporation Microsoft Windows Ope
rating System 6.1.7600.16385 \SystemRoot\system32\drivers\msdsm.sys Service reg
istry key doesn't exist or hidden.
[Drivers] :HKLM mshidkmdf=C:\WINDOWS\SYSTEM32\DRIVERS\MSHIDKMDF.SYS
### Pass-through HID to KMDF Filter Driver Microsoft Corporation Microsoft Wind
ows Operating System 6.1.7600.16385 \SystemRoot\System32\drivers\mshidkmdf.sys S
ervice registry key doesn't exist or hidden.
[Drivers] :HKLM msisadrv=C:\WINDOWS\SYSTEM32\DRIVERS\MSISADRV.SYS
### ISA Driver Microsoft Corporation Microsoft Windows Operating System 6.1.7600
.16385 Service registry key doesn't exist or hidden.
[Drivers] :HKLM MSKSSRV=C:\WINDOWS\SYSTEM32\DRIVERS\MSKSSRV.SYS
### MS KS Server Microsoft Corporation Microsoft Windows Operating System 6.1.76
00.16385 Service registry key doesn't exist or hidden.
[Drivers] :HKLM MSPCLOCK=C:\WINDOWS\SYSTEM32\DRIVERS\MSPCLOCK.SYS
### MS Proxy Clock Microsoft Corporation Microsoft Windows Operating System 6.1.
### NForce NT AGP Filter Microsoft Corporation Microsoft Windows Operating Syste
m 6.1.7600.16385 \SystemRoot\system32\drivers\nv_agp.sys Service registry key d
oesn't exist or hidden.
[Drivers] :HKLM ohci1394=C:\WINDOWS\SYSTEM32\DRIVERS\OHCI1394.SYS
### 1394 OpenHCI Port Driver Microsoft Corporation Microsoft Windows Operating S
ystem 6.1.7600.16385 \SystemRoot\system32\drivers\ohci1394.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM Parport=C:\WINDOWS\SYSTEM32\DRIVERS\PARPORT.SYS
### Parallel Port Driver Microsoft Corporation Microsoft Windows Operating Syste
m 6.1.7600.16385 Service registry key doesn't exist or hidden.
[Drivers] :HKLM Partizan=C:\Windows\system32\drivers\Partizan.sys
### File is deleted or hidden by a rootkit or could not be located. Service r
egistry key doesn't exist or hidden.
[Drivers] :HKLM partmgr=C:\WINDOWS\SYSTEM32\DRIVERS\PARTMGR.SYS
### Partition Management Driver Microsoft Corporation Microsoft Windows Operatin
g System 6.1.7600.16385 Service registry key doesn't exist or hidden.
[Drivers] :HKLM pci=C:\WINDOWS\SYSTEM32\DRIVERS\PCI.SYS
### NT Plug and Play PCI Enumerator Microsoft Corporation Microsoft Windows Oper
ating System 6.1.7600.16385 Service registry key doesn't exist or hidden.
[Drivers] :HKLM pciide=C:\WINDOWS\SYSTEM32\DRIVERS\PCIIDE.SYS
### Generic PCI IDE Bus Driver Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385 \SystemRoot\system32\drivers\pciide.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM pcmcia=C:\WINDOWS\SYSTEM32\DRIVERS\PCMCIA.SYS
### PCMCIA Bus Driver Microsoft Corporation Microsoft Windows Operating System 6
.1.7600.16385 \SystemRoot\system32\DRIVERS\pcmcia.sys Service registry key does
n't exist or hidden.
[Drivers] :HKLM pcw=C:\WINDOWS\SYSTEM32\DRIVERS\PCW.SYS
### Performance Counters for Windows Driver Microsoft Corporation Microsoft Win
dows Operating System 6.1.7600.16385 Service registry key doesn't exist or hidde
n.
[Drivers] :HKLM PEAUTH=C:\WINDOWS\SYSTEM32\DRIVERS\PEAUTH.SYS
### Protected Environment Authentication and Authorization Export Driver Micro
soft Corporation Microsoft Windows Operating System 6.1.7600.16385 Service regist
ry key doesn't exist or hidden.
[Drivers] :HKLM pelmouse=C:\WINDOWS\SYSTEM32\DRIVERS\PELMOUSE.SYS
### Mouse Suite Driver TPMX Electronics Ltd. Mouse Suite 98 2.1.0.0 Service
registry key doesn't exist or hidden.
[Drivers] :HKLM pelusblf=C:\WINDOWS\SYSTEM32\DRIVERS\PELUSBLF.SYS
### USB Mouse Filter Driver TPMX Electronics Ltd. Mouse Suite 98 2.1.0.0 Serv
ice registry key doesn't exist or hidden.
[Drivers] :HKLM PptpMiniport=C:\WINDOWS\SYSTEM32\DRIVERS\RASPPTP.SYS
### Peer-to-Peer Tunneling Protocol Microsoft Corporation Microsoft Windows Oper
ating System 6.1.7601.17514 Service registry key doesn't exist or hidden.
[Drivers] :HKLM Processor=C:\WINDOWS\SYSTEM32\DRIVERS\PROCESSR.SYS
### Processor Device Driver Microsoft Corporation Microsoft Windows Operating Sy
stem 6.1.7600.16385 \SystemRoot\system32\DRIVERS\processr.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM Psched=C:\WINDOWS\SYSTEM32\DRIVERS\PACER.SYS
### QoS Packet Scheduler Microsoft Corporation Microsoft Windows Operating Syste
m 6.1.7600.16385 Service registry key doesn't exist or hidden.
[Drivers] :HKLM pwdrvio=C:\WINDOWS\SYSTEM32\PWDRVIO.SYS
### \??\C:\Windows\system32\pwdrvio.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM pwdspio=C:\WINDOWS\SYSTEM32\PWDSPIO.SYS
### \??\C:\Windows\system32\pwdspio.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM ql2300=C:\WINDOWS\SYSTEM32\DRIVERS\QL2300.SYS
### QLogic Fibre Channel Stor Miniport Driver QLogic Corporation QLogic Fibre
Channel Stor Miniport Driver 9.1.8.6 \SystemRoot\system32\DRIVERS\ql2300.sys Se
### VMware network application interface driver (64-bit) VMware, Inc. VMware n
etwork application interface driver (64-bit) 4.2.1.0 build-1295980 \??\C:\Windo
ws\system32\drivers\vmnetuserif.sys Service registry key doesn't exist or hidden
.
[Drivers] :HKLM VMparport=C:\WINDOWS\SYSTEM32\DRIVERS\VMPARPORT.SYS
### VMware parallel port driver VMware, Inc. VMware parallel port driver 10.0.
0 build-1295980 \??\C:\Windows\system32\drivers\VMparport.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM vmusb=C:\WINDOWS\SYSTEM32\DRIVERS\VMUSB.SYS
### VMware USB driver VMware, Inc. VMware USB driver 4.1.0.2 build-1279205 Se
rvice registry key doesn't exist or hidden.
[Drivers] :HKLM vmx86=C:\WINDOWS\SYSTEM32\DRIVERS\VMX86.SYS
### VMware kernel driver VMware, Inc. VMware kernel driver 10.0.0 build-129598
0 \??\C:\Windows\system32\drivers\vmx86.sys Service registry key doesn't exist
or hidden.
[Drivers] :HKLM volmgr=C:\WINDOWS\SYSTEM32\DRIVERS\VOLMGR.SYS
### Volume Manager Driver Microsoft Corporation Microsoft Windows Operating Syst
em 6.1.7601.17514 Service registry key doesn't exist or hidden.
[Drivers] :HKLM volmgrx=C:\WINDOWS\SYSTEM32\DRIVERS\VOLMGRX.SYS
### Volume Manager Extension Driver Microsoft Corporation Microsoft Windows Oper
ating System 6.1.7600.16385 Service registry key doesn't exist or hidden.
[Drivers] :HKLM volsnap=C:\WINDOWS\SYSTEM32\DRIVERS\VOLSNAP.SYS
### Volume Shadow Copy Driver Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385 Service registry key doesn't exist or hidden.
[Drivers] :HKLM vsmraid=C:\WINDOWS\SYSTEM32\DRIVERS\VSMRAID.SYS
### VIA RAID DRIVER FOR AMD-X86-64 VIA Technologies Inc.,Ltd VIA RAID driver 6
.0.6000.6210 \SystemRoot\system32\DRIVERS\vsmraid.sys Service registry key does
n't exist or hidden.
[Drivers] :HKLM vsock=C:\WINDOWS\SYSTEM32\DRIVERS\VSOCK.SYS
### VMware vSockets Service VMware, Inc. VMware vSockets Service 9.5.7.0 build
-1253991 Service registry key doesn't exist or hidden.
[Drivers] :HKLM vstor2-mntapi20-shared=SysWOW64\drivers\vstor2-mntapi20-shared
.sys
### VMware Virtual Storage Volume Driver VMware, Inc. VMware vCenter Converter
Standalone 5.1.0 build-1027190 VMware Virtual Storage Volume Driver VMware, In
c. VMware vCenter Converter Standalone 5.1.0 build-1027190 File is deleted or hi
dden by a rootkit or could not be located. Service registry key doesn't exist or
hidden.
[Drivers] :HKLM vwifibus=C:\WINDOWS\SYSTEM32\DRIVERS\VWIFIBUS.SYS
### Virtual WiFi Bus Driver Microsoft Corporation Microsoft Windows Operating Sy
stem 6.1.7600.16385 \SystemRoot\System32\drivers\vwifibus.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM WacomPen=C:\WINDOWS\SYSTEM32\DRIVERS\WACOMPEN.SYS
### Wacom Serial Pen Tablet HID Driver Microsoft Corporation Microsoft Windows O
perating System 6.1.7600.16385 \SystemRoot\system32\DRIVERS\wacompen.sys Servic
e registry key doesn't exist or hidden.
[Drivers] :HKLM WANARP=C:\WINDOWS\SYSTEM32\DRIVERS\WANARP.SYS
### MS Remote Access and Routing ARP Driver Microsoft Corporation Microsoft Win
dows Operating System 6.1.7601.17514 Service registry key doesn't exist or hidde
n.
[Drivers] :HKLM Wanarpv6=C:\WINDOWS\SYSTEM32\DRIVERS\WANARP.SYS
### MS Remote Access and Routing ARP Driver Microsoft Corporation Microsoft Win
dows Operating System 6.1.7601.17514 Service registry key doesn't exist or hidde
n.
[Drivers] :HKLM Wd=C:\WINDOWS\SYSTEM32\DRIVERS\WD.SYS
### Microsoft Watchdog Timer Driver Microsoft Corporation Microsoft Windows Oper
ating System 6.1.7600.16385 \SystemRoot\system32\DRIVERS\wd.sys Service registr
y key doesn't exist or hidden.
[Drivers] :HKLM WDC_SAM=C:\WINDOWS\SYSTEM32\DRIVERS\WDCSAM64.SYS
### WD SCSI Architecture Model (SAM) driver Western Digital Technologies WD Ex
### PowerISO Virtual Drive Manager Power Software Ltd PowerISO Virtual Drive M
anager 5, 1, 0, 0 C:\Program Files (x86)\PowerISO\PWRISOVM.EXE -startup
[Registry Run] :HKLM Acrobat Assistant 7.0=C:\PROGRAM FILES (X86)\ADOBE\ACROBA
T 7.0\DISTILLR\ACROTRAY.EXE
### AcroTray Adobe Systems Inc. AcroTray - Adobe Acrobat Distiller helper appl
ication. 6.0.1.2004121400 "C:\Program Files (x86)\Adobe\Acrobat 7.0\Distillr\Ac
rotray.exe"
[Registry Run] :HKLM "Default Value"=""
### File is deleted or hidden by a rootkit or could not be located.
[Registry Run] :HKLM SunJavaUpdateSched=C:\PROGRAM FILES (X86)\COMMON FILES\JA
VA\JAVA UPDATE\JUSCHED.EXE
### Java Update Scheduler Oracle Corporation Java Platform SE Auto Updater 2.8
.77.3 "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
[Registry Run] :HKLM MalwareProtectionLive=C:\USERS\ADMIN\APPDATA\LOCAL\MALWAR
EPROTECTIONLIVE\MALWAREPROTECTIONCLIENT.EXE
### MalwareProtectionClient MalwareProtectionClient 1.0.*
[Registry Run(x64)] :HKLM Daemon for Mouse Suite=C:\PROGRAM FILES\LENOVO\LENOV
O MOUSE SUITE\ICO.EXE
### Mouse Suite 98 Daemon Primax Electronics Ltd. MouseSuite 98 1.0.0.1 C:\Pr
ogram Files\Lenovo\Lenovo Mouse Suite\ICO.EXE 30
[Registry Run(x64)] :HKLM Skd8821=C:\PROGRAM FILES\LENOVO\LENOVO SLIM USB KEYB
OARD\SKD8821.EXE
### Lenovo Slim USB Keyboard LITE-ON TECHNOLOGY CORP. Lenovo Slim USB Keyboard
1, 0, 0, 0
[Registry Run(x64)] :HKLM AdobeAAMUpdater-1.0=C:\PROGRAM FILES (X86)\COMMON FI
LES\ADOBE\OOBE\PDAPP\UWA\UPDATERSTARTUPUTILITY.EXE
### Adobe Updater Startup Utility Adobe Systems Incorporated Adobe Updater Sta
rtup Utility 6.2.0.4 (BuildVersion: 1.0; BuildDate: BUILDDATETIME) "C:\Program
Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
[Win.ini] :HKCU load=""
### File is deleted or hidden by a rootkit or could not be located.
[Win.ini] :HKCU run=""
### File is deleted or hidden by a rootkit or could not be located.
[Common Startup Folder] Adobe Acrobat Speed Launcher.lnk=C:\WINDOWS\INSTALLER\
{AC76BA86-1033-0000-7760-000000000002}\SC_ACROBAT.EXE
[Common Startup Folder] Canon LBP2900 Status Window.lnk=C:\WINDOWS\SYSTEM32\SP
OOL\DRIVERS\X64\3\CNAB4LAD.EXE
### Canon Advanced Printing Technology Printer Status Window Launcher CANON IN
C. Canon Advanced Printing Technology 3.10.0.003
[Common Startup Folder] ResultsHubDesktopSearch.lnk=C:\ProgramData\Results Hub
\ResultsHubDesktopSearch.exe
### File is deleted or hidden by a rootkit or could not be located.
[Scheduled Tasks] Bidaily Synchronize Task[973b]=c:\programdata\{415f24e7-9d9e
-594e-415f-f24e79d9939e}\setup_product_18129.exe
### File is deleted or hidden by a rootkit or could not be located.
[Scheduled Tasks] Adobe Flash Player Updater=C:\WINDOWS\SYSWOW64\MACROMED\FLAS
H\FLASHPLAYERUPDATESERVICE.EXE
### Adobe Flash Player Update Service 21.0 r0 Adobe Systems Incorporated Adobe Fl
ash Player Update Service 21,0,0,213
[Scheduled Tasks] 6012184b-f747-477b-804f-54428b83a7ef-5_user=C:\Program Files
(x86)\SavePass 1.1\6012184b-f747-477b-804f-54428b83a7ef-5.exe
### File is deleted or hidden by a rootkit or could not be located.
[Scheduled Tasks] 6012184b-f747-477b-804f-54428b83a7ef-5=C:\Program Files (x86
)\SavePass 1.1\6012184b-f747-477b-804f-54428b83a7ef-5.exe
### File is deleted or hidden by a rootkit or could not be located.
[Scheduled Tasks] 0615tbUpdateInfo=C:\PROGRAMDATA\AVG_UPDATE_0615TB\0615TB_{64
222B53-94A6-4D8F-A700-11BD2ACB2FBE}.EXE
### 06.15.0.4
[Scheduled Tasks] UpdaterEX=C:\Users\admin\AppData\Roaming\UPDATE~1\UPDATE~1\U
PDATE~1.EXE
NFO.EXE
[Running Processes] C:\PROGRAM FILES (X86)\WORDWEB\WWEB32.EXE
### WordWeb Thesaurus/Dictionary WordWeb Software WordWeb 6.0.2.0
[Running Processes] C:\PROGRAM FILES (X86)\WESTERN DIGITAL\WD QUICK VIEW\WDDMS
TATUS.EXE
### WD Quick View Western Digital Technologies, Inc. WDDMStatus.exe 3.2.0.15
[Running Processes] C:\PROGRAM FILES (X86)\VMWARE\VMWARE WORKSTATION\VMWARE-TR
AY.EXE
### VMware Tray Process VMware, Inc. VMware Workstation 10.0.0 build-1295980
[Running Processes] C:\WINDOWS\TSNP2UVC.EXE
### tsnp2uvc Microsoft tsnp2uvc 1, 1, 7, 0
[Running Processes] C:\WINDOWS\FIXCAMERA.EXE
### CameraFixer SONIX CameraFixer Application 1, 0, 1, 2
[Running Processes] C:\PROGRAM FILES (X86)\SAMSUNG\KIES\KIESTRAYAGENT.EXE
### Kies TrayAgent Application Samsung Electronics Co., Ltd. Kies TrayAgent 0.
0.0.25
[Running Processes] C:\PROGRAM FILES (X86)\POWERISO\PWRISOVM.EXE
### PowerISO Virtual Drive Manager Power Software Ltd PowerISO Virtual Drive M
anager 5, 1, 0, 0
[Running Processes] C:\PROGRAM FILES (X86)\ADOBE\ACROBAT 7.0\DISTILLR\ACROTRAY
.EXE
### AcroTray Adobe Systems Inc. AcroTray - Adobe Acrobat Distiller helper appl
ication. 6.0.1.2004121400
[Running Processes] C:\PROGRAM FILES (X86)\COMMON FILES\JAVA\JAVA UPDATE\JUSCH
ED.EXE
### Java Update Scheduler Oracle Corporation Java Platform SE Auto Updater 2.8
.77.3
[Running Processes] C:\USERS\ADMIN\APPDATA\LOCAL\MALWAREPROTECTIONLIVE\MALWARE
PROTECTIONCLIENT.EXE
### MalwareProtectionClient MalwareProtectionClient 1.0.*
[Running Processes] C:\PROGRAM FILES (X86)\COMMON FILES\JAVA\JAVA UPDATE\JUCHE
CK.EXE
### Java Update Checker Oracle Corporation Java Platform SE Auto Updater 2.8.7
7.3
[Running Processes] C:\PROGRAM FILES (X86)\FREE DOWNLOAD MANAGER\FDM.EXE
### Free Download Manager FreeDownloadManager.ORG Free Download Manager 3.9.4
[Running Processes] C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\FIREFOX.EXE
### Firefox Mozilla Corporation Firefox 39.0.3
[Running Processes] C:\PROGRAMDATA\FREE DOWNLOAD MANAGER\FIREFOX\EXTENSIONS\2.
1.4\FDMBROWSERHELPER.EXE
### FDM Browser Helper FreeDownloadManager.ORG Free Download Manager 0.0.0.0
[Running Processes] C:\PROGRAM FILES (X86)\COMMON FILES\ADOBE\ARM\1.0\ADOBEARM
.EXE
### Adobe Reader and Acrobat Manager Adobe Systems Incorporated Adobe Reader a
nd Acrobat Manager 1.824.16.6751
[Running Processes] C:\PROGRAM FILES (X86)\UNHACKME\UNHACKME.EXE
### Detects and removes rootkits Greatis Software UnHackMe 7.70
[Running Processes] C:\PROGRAM FILES (X86)\UNHACKME\REANIMATOR.EXE
### RegRun Start Control Greatis Software RegRun Security Suite 7.70 release
[Loaded DLLs] C:\Windows\System32\mstask.dll
### Task Scheduler interface DLL Microsoft Corporation Microsoft Windows Operati
ng System 6.1.7600.16385
[Loaded DLLs] C:\Windows\SysWOW64\wer.dll
### Windows Error Reporting DLL Microsoft Corporation Microsoft Windows Operatin
g System 6.1.7600.16385
[Loaded DLLs] C:\Windows\SysWOW64\XmlLite.dll
### Microsoft XmlLite Library Microsoft Corporation Microsoft XML Core Service
s 1.3.1000.0
[Loaded DLLs] C:\Windows\SysWOW64\gameux.dll
### Games Explorer Microsoft Corporation Microsoft Windows Operating System 6.1.
7600.16385
[Loaded DLLs] C:\Program Files (x86)\UnHackMe\parser.dll
### Analytics Parser Greatis Software UnHackMe 7.65
[Loaded DLLs] C:\Windows\system32\RICHED20.dll
### Rich Text Edit Control, v3.1 Microsoft Corporation Microsoft RichEdit Cont
rol, version 3.1 3.1
[Loaded DLLs] C:\Windows\system32\RICHED32.DLL
### Wrapper Dll for Richedit 1.0 Microsoft Corporation Microsoft Windows Operati
ng System 6.1.7601.17514
[Loaded DLLs] C:\Windows\SysWOW64\qmgrprxy.dll
### Background Intelligent Transfer Service Proxy Microsoft Corporation Micros
oft Windows Operating System 7.5.7600.16385
[Loaded DLLs] C:\Windows\system32\EhStorAPI.dll
### Windows Enhanced Storage API Microsoft Corporation Microsoft Windows Operati
ng System 6.1.7600.16385
[Loaded DLLs] C:\Windows\SysWOW64\PhotoMetadataHandler.dll
### Photo Metadata Handler Microsoft Corporation Microsoft Windows Operating Sys
tem 6.1.7600.16385
[Loaded DLLs] C:\PROGRA~2\MICROS~1\Office12\GRA32A~1.DLL
### GrooveSystemServices Module Microsoft Corporation GrooveSystemServices Mod
ule 4.2.0.2623
[Loaded DLLs] C:\Windows\system32\NetworkExplorer.dll
### Network Explorer Microsoft Corporation Microsoft Windows Operating System 6.
1.7600.16385
[Loaded DLLs] C:\Windows\SysWOW64\oleacc.dll
### Active Accessibility Core Component Microsoft Corporation Microsoft Windows
Operating System 6.1.7601.17676
[Loaded DLLs] C:\Windows\SysWOW64\thumbcache.dll
### Microsoft Thumbnail Cache Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385
[Loaded DLLs] C:\Windows\system32\SearchFolder.dll
### SearchFolder Microsoft Corporation Microsoft Windows Operating System 6.1.76
00.16385
[Loaded DLLs] C:\Program Files (x86)\Internet Explorer\ieproxy.dll
### IE ActiveX Interface Marshaling Library Microsoft Corporation Internet Exp
lorer 11.00.9600.17041
[Loaded DLLs] C:\Windows\SysWOW64\actxprxy.dll
### ActiveX Interface Marshaling Library Microsoft Corporation Microsoft Window
s Operating System 6.1.7601.17514
[Loaded DLLs] C:\Windows\System32\StructuredQuery.dll
### Structured Query Microsoft Corporation Windows Search 7.00.7601.17514
[Loaded DLLs] C:\Program Files (x86)\Common Files\microsoft shared\ink\tiptsf.
dll
### Tablet PC Input Panel Text Services Framework Microsoft Corporation Micros
oft Windows Operating System 6.1.7600.16385
[Loaded DLLs] C:\Windows\System32\comdlg32.dll
### Common Dialogs DLL Microsoft Corporation Microsoft Windows Operating System
6.1.7600.16385
[Loaded DLLs] C:\Windows\system32\icm32.dll
### Microsoft Color Management Module (CMM) Microsoft Corporation Microsoft Win
dows Operating System 6.1.7600.16385
[Loaded DLLs] C:\PROGRA~2\MICROS~1\Office12\GrooveNew.DLL
### GrooveNew Module Microsoft Corporation GrooveNew Module 4.2.0.2623
[Loaded DLLs] C:\PROGRA~2\MICROS~1\Office12\GrooveUtil.DLL
### GrooveUtil Module Microsoft Corporation GrooveUtil Module 4.2.0.2623
[Loaded DLLs] C:\Windows\SysWOW64\msmpeg2adec.dll
### Microsoft DTV-DVD Audio Decoder Microsoft Corporation Microsoft Windows Oper
ating System 6.1.7140.0
[Loaded DLLs] C:\Windows\SysWOW64\bcrypt.dll
### NSS PKCS #11 Library Mozilla Foundation Network Security Services 3.19.2 B
asic ECC
[Loaded DLLs] C:\Windows\system32\mscms.dll
### Microsoft Color Matching System DLL Microsoft Corporation Microsoft Windows
Operating System 6.1.7600.16385
[Loaded DLLs] C:\Program Files (x86)\Free Download Manager\fdmumsp.dll
[Loaded DLLs] C:\Program Files (x86)\Free Download Manager\flvsniff.dll
### flvsniff Free Download Manager 0, 0, 0, 0
[Loaded DLLs] C:\Windows\system32\AUDIOSES.DLL
### Audio Session Microsoft Corporation Microsoft Windows Operating System 6.1.7
600.16385
[Loaded DLLs] C:\Windows\System32\MMDevApi.dll
### MMDevice API Microsoft Corporation Microsoft Windows Operating System 6.1.76
00.16385
[Loaded DLLs] C:\Program Files (x86)\Free Download Manager\detoured.dll
### Marks process modified by Detours technology. Microsoft Corporation Micros
oft Research Detours Package Express Version 2.1 Build_216
[Loaded DLLs] C:\Windows\System32\wevtapi.dll
### Eventing Consumption and Configuration API Microsoft Corporation Microsoft
Windows Operating System 6.1.7600.16385
[Loaded DLLs] C:\Windows\System32\Wpc.dll
### WPC Settings Library Microsoft Corporation Windows 1.0.0.1
[Loaded DLLs] C:\Windows\system32\NTDSAPI.dll
### Active Directory Domain Services API Microsoft Corporation Microsoft Window
s Operating System 6.1.7600.16385
[Loaded DLLs] C:\Windows\system32\wbem\fastprox.dll
### WMI Custom Marshaller Microsoft Corporation Microsoft Windows Operating Syst
em 6.1.7600.16385
[Loaded DLLs] C:\Windows\system32\wbem\wbemsvc.dll
### WMI Microsoft Corporation Microsoft Windows Operating System 6.1.7600.16385
[Loaded DLLs] C:\Windows\system32\wbemcomn.dll
### WMI Microsoft Corporation Microsoft Windows Operating System 6.1.7601.17514
[Loaded DLLs] C:\Windows\system32\wbem\wbemprox.dll
### WMI Microsoft Corporation Microsoft Windows Operating System 6.1.7600.16385
[Loaded DLLs] C:\Program Files (x86)\Mozilla Firefox\browser\components\browse
rcomps.dll
### Mozilla Foundation Firefox 39.0.3
[Loaded DLLs] C:\Windows\system32\pdh.dll
### Windows Performance Data Helper DLL Microsoft Corporation Microsoft Windows
Operating System 6.1.7600.16385
[Loaded DLLs] C:\Windows\system32\NETAPI32.dll
### Net Win32 API DLL Microsoft Corporation Microsoft Windows Operating System 6
.1.7601.17887
[Loaded DLLs] C:\Program Files (x86)\Mozilla Firefox\icudt52.dll
### ICU Data DLL The ICU Project International Components for Unicode 52, 1, 0
, 0
[Loaded DLLs] C:\Program Files (x86)\Mozilla Firefox\icuuc52.dll
### ICU Common DLL The ICU Project International Components for Unicode 52, 1,
0, 0
[Loaded DLLs] C:\Program Files (x86)\Mozilla Firefox\icuin52.dll
### ICU I18N DLL The ICU Project International Components for Unicode 52, 1, 0
, 0
[Loaded DLLs] C:\Program Files (x86)\Mozilla Firefox\xul.dll
### Mozilla Foundation Firefox 39.0.3
[Loaded DLLs] C:\Program Files (x86)\Mozilla Firefox\mozalloc.dll
### Mozilla Foundation Firefox 39.0.3
[Loaded DLLs] C:\Program Files (x86)\Mozilla Firefox\sandboxbroker.dll
### Mozilla Foundation Firefox 39.0.3
[Loaded DLLs] C:\Program Files (x86)\Mozilla Firefox\nss3.dll
### Mozilla Foundation Firefox 39.0.3
m 6.1.7600.16385
[Loaded DLLs] C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configurat
ion\5b6ddf934128d538cd5cd77bf4209b93\System.Configuration.ni.dll
### System.Configuration.dll Microsoft Corporation Microsoft .NET Framework 2.0
.50727.5476
[Loaded DLLs] C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\217ece
46920546d718414291d463bb1c\System.Xml.ni.dll
### .NET Framework Microsoft Corporation Microsoft .NET Framework 2.0.50727.547
6
[Loaded DLLs] C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Fo
rms\8bc548587e91ecf0552a40e47bbf99cc\System.Windows.Forms.ni.dll
### .NET Framework Microsoft Corporation Microsoft .NET Framework 2.0.50727.546
8
[Loaded DLLs] C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\5c
24d3b0041ebf4f48a93615b9fa3de9\System.Drawing.ni.dll
### .NET Framework Microsoft Corporation Microsoft .NET Framework 2.0.50727.546
7
[Loaded DLLs] C:\Windows\assembly\NativeImages_v2.0.50727_32\System\b3a7826984
7005365001c33870cd121f\System.ni.dll
### .NET Framework Microsoft Corporation Microsoft .NET Framework 2.0.50727.546
7
[Loaded DLLs] C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll
### Microsoft .NET Runtime Just-In-Time Compiler Microsoft Corporation Microso
ft .NET Framework 2.0.50727.5467
[Loaded DLLs] C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsec.dll
### Microsoft .NET Security module Microsoft Corporation Microsoft .NET Framewo
rk 2.0.50727.4927
[Loaded DLLs] C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\ede2c6c8
42840e009f01bcc74fa4c457\mscorlib.ni.dll
### Microsoft Common Language Runtime Class Library Microsoft Corporation Micr
osoft .NET Framework 2.0.50727.5477
[Loaded DLLs] C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
### Microsoft .NET Runtime Common Language Runtime - WorkStation Microsoft Cor
poration Microsoft .NET Framework 2.0.50727.5477
[Loaded DLLs] C:\Windows\system32\sfc_os.DLL
### Windows File Protection Microsoft Corporation Microsoft Windows Operating Sy
stem 6.1.7600.16385
[Loaded DLLs] C:\Windows\system32\sfc.dll
### Windows File Protection Microsoft Corporation Microsoft Windows Operating Sy
stem 6.1.7600.16385
[Loaded DLLs] C:\Windows\system32\samcli.dll
### Security Accounts Manager Client DLL Microsoft Corporation Microsoft Window
s Operating System 6.1.7601.17514
[Loaded DLLs] C:\Windows\AppPatch\ACGENRAL.DLL
### Windows Compatibility DLL Microsoft Corporation Microsoft Windows Operating
System 6.1.7601.17514
[Loaded DLLs] C:\Windows\system32\netutils.dll
### Net Win32 API Helpers DLL Microsoft Corporation Microsoft Windows Operating
System 6.1.7601.17514
[Loaded DLLs] C:\Windows\system32\slc.dll
### Software Licensing Client Dll Microsoft Corporation Microsoft Windows Operat
ing System 6.1.7600.16385
[Loaded DLLs] C:\Windows\system32\cscapi.dll
### Offline Files Win32 API Microsoft Corporation Microsoft Windows Operating Sy
stem 6.1.7601.17514
[Loaded DLLs] C:\Windows\system32\srvcli.dll
### Server Service Client DLL Microsoft Corporation Microsoft Windows Operating
System 6.1.7601.17514
[Loaded DLLs] C:\Windows\system32\ntshrui.dll
### Shell extensions for sharing Microsoft Corporation Microsoft Windows Operati
ng System 6.1.7600.16385
[Loaded DLLs] C:\Program Files (x86)\FileZilla FTP Client\fzshellext.dll
### fzshellext Dynamic Link Library fzshellext Dynamic Link Library 3, 13, 1,
0
[Loaded DLLs] C:\Windows\system32\SSDPAPI.dll
### SSDP Client API DLL Microsoft Corporation Microsoft Windows Operating System
6.1.7600.16385
[Loaded DLLs] C:\Windows\system32\upnphost.dll
### UPnP Device Host Microsoft Corporation Microsoft Windows Operating System 6.
1.7600.16385
[Loaded DLLs] C:\Program Files (x86)\Samsung\Kies\External\DeviceModules\UPNPD
evice_Kies.dll
### UPnP SDK Device Host Kies Device Windows (R) Codename Longhorn DDK provide
r Windows (R) Codename Longhorn DDK driver 6.0.6000.16384
[Loaded DLLs] C:\Windows\WinSxS\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0
.30729.4148_none_4973eb1d754a9dc9\MFC90ENU.DLL
### MFC Language Specific Resources Microsoft Corporation Microsoft Visual Stud
io 2008 9.00.30729.4148
[Loaded DLLs] C:\Windows\WinSxS\x86_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30
729.4148_none_4bf5400abf9d60b7\mfc90u.dll
### MFCDLL Shared Library - Retail Version Microsoft Corporation Microsoft Visu
al Studio 2008 9.00.30729.4148
[Loaded DLLs] C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30
729.4940_none_50916076bcb9a742\MSVCP90.dll
### Microsoft C++ Runtime Library Microsoft Corporation Microsoft Visual Studio 2
008 9.00.30729.4940
[Loaded DLLs] C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30
729.4940_none_50916076bcb9a742\MSVCR90.dll
### Microsoft C Runtime Library Microsoft Corporation Microsoft Visual Studio 200
8 9.00.30729.4940
[Loaded DLLs] C:\Windows\system32\WINSTA.dll
### Winstation Library Microsoft Corporation Microsoft Windows Operating System
6.1.7601.17514
[Loaded DLLs] C:\Windows\syswow64\IMM32.dll
### Multi-User Windows IMM32 API Client DLL Microsoft Corporation Microsoft Win
dows Operating System 6.1.7601.17514
[Loaded DLLs] C:\Windows\system32\msi.dll
### Windows Installer Microsoft Corporation Windows Installer - Unicode 5.0.76
01.17514
[Loaded DLLs] C:\Windows\system32\WTSAPI32.dll
### Windows Remote Desktop Session Host Server SDK APIs Microsoft Corporation
Microsoft Windows Operating System 6.1.7600.16385
[Loaded DLLs] C:\Program Files (x86)\WordWeb\WUCNT.dll
[Loaded DLLs] C:\Windows\system32\oleacc.dll
### Active Accessibility Core Component Microsoft Corporation Microsoft Windows
Operating System 6.1.7601.17676
[Loaded DLLs] C:\Windows\system32\wweb32.dll
[Loaded DLLs] C:\Program Files (x86)\Sony\Sony PC Companion\bvrpctln.dll
### Custom controls and utilities library Avanquest Software MPT 2.00
[Loaded DLLs] C:\Windows\system32\dhcpcsvc.DLL
### DHCP Client Service Microsoft Corporation Microsoft Windows Operating System
6.1.7600.16385
[Loaded DLLs] C:\Windows\system32\dhcpcsvc6.DLL
### DHCPv6 Client Microsoft Corporation Microsoft Windows Operating System 6.1.7
600.16385
[Loaded DLLs] C:\Program Files (x86)\Sony\Sony PC Companion\DeviceIO.dll
### DeviceIO Core Library Avanquest Software PC Companion 1.0.0.1
[Loaded DLLs] C:\Program Files (x86)\Windows Portable Devices\SqmApi.dll
### SQM Client Microsoft Corporation Microsoft Windows Operating System 6.1.7601
.17514
stem 6.1.7601.18288
[Loaded DLLs] C:\Windows\system32\MSVFW32.dll
### Microsoft Video for Windows DLL Microsoft Corporation Microsoft Windows Oper
ating System 6.1.7600.16385
[Loaded DLLs] C:\Program Files (x86)\Sony\Sony PC Companion\NewUI.dll
### New UI Avanquest Software MPT 4.0
[Loaded DLLs] C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Serv759bfb
78#\c8bd7b726e571a2948d5547fd030f303\System.ServiceProcess.ni.dll
### .NET Framework Microsoft Corporation Microsoft .NET Framework 4.0.30319.179
29
[Loaded DLLs] C:\Windows\system32\WINSPOOL.DRV
### Windows Spooler Driver Microsoft Corporation Microsoft Windows Operating Sys
tem 6.1.7600.16385
[Loaded DLLs] C:\Program Files (x86)\Samsung\Kies\External\MACSSDK.dll
### MACSSDK MarkAny. MACSSDK 3, 2, 2009, 1028
[Loaded DLLs] C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\95a58c
416cfe8803af6b325d952a374a\System.Xml.ni.dll
### .NET Framework Microsoft Corporation Microsoft .NET Framework 4.0.30319.180
60
[Loaded DLLs] C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configurat
ion\853f7abd2d9a620ba57c7b4005fe1976\System.Configuration.ni.dll
### System.Configuration.dll Microsoft Corporation Microsoft .NET Framework 4.0
.30319.18060
[Loaded DLLs] C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runt73a1fc
9d#\dbef796beff0b4632e0913ac24bbbe5e\System.Runtime.Remoting.ni.dll
### Microsoft .NET Runtime Object Remoting Microsoft Corporation Microsoft .NET
Framework 4.0.30319.34108
[Loaded DLLs] C:\Windows\Microsoft.NET\Framework\v4.0.30319\nlssorting.dll
### Microsoft Collation Support Microsoft Corporation Microsoft .NET Framework
4.0.30319.17929
[Loaded DLLs] C:\Windows\Microsoft.NET\Framework\v4.0.30319\clrjit.dll
### Microsoft .NET Runtime Just-In-Time Compiler Microsoft Corporation Microso
ft .NET Framework 4.0.30319.18021
[Loaded DLLs] C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\PresentationNa
tive_v0400.dll
### PresentationNative_v0400.dll Microsoft Corporation Microsoft .NET Framework
4.0.30319.17929
[Loaded DLLs] C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\wpfgfx_v0400.d
ll
### wpfgfx_v0400.dll Microsoft Corporation Microsoft .NET Framework 4.0.30319.1
7929
[Loaded DLLs] C:\Windows\system32\dwrite.dll
### Microsoft DirectX Typography Services Microsoft Corporation Microsoft Windo
ws Operating System 6.2.9200.16492
[Loaded DLLs] C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\6497e
394eb0346d9f374976af5033e37\System.Core.ni.dll
### .NET Framework Microsoft Corporation Microsoft .NET Framework 4.0.30319.179
29
[Loaded DLLs] C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\9d357
2e8c3c314a0f12383d41e8bee78\System.Xaml.ni.dll
### System.Xaml.dll Microsoft Corporation Microsoft .NET Framework 4.0.30319.18
015
[Loaded DLLs] C:\Windows\assembly\NativeImages_v4.0.30319_32\Presentatio5ae0f0
0f#\33e2c43bb5e6f50244ae444c1d9b33cd\PresentationFramework.ni.dll
### PresentationFramework.dll Microsoft Corporation Microsoft .NET Framework 4.
0.30319.18060
[Loaded DLLs] C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\
4752710c6fe78ee418c736dad7a05b52\PresentationCore.ni.dll
### PresentationCore.dll Microsoft Corporation Microsoft .NET Framework 4.0.303
19.18060
### Fusion 2.5 Microsoft Corporation Microsoft Windows Operating System 6.1.7600
.16385
[Loaded DLLs] C:\Windows\system32\olepro32.dll
[Loaded DLLs] C:\Program Files (x86)\Common Files\Wondershare\Wondershare Help
er Compact\CBSProducstInfo.dll
### Wondershare Studio Wondershare Wondershare Studio 1.0.0.0
[Loaded DLLs] C:\Program Files (x86)\Common Files\Wondershare\Wondershare Help
er Compact\CBSCreateVC.dll
[Loaded DLLs] C:\Program Files (x86)\Common Files\Wondershare\Wondershare Help
er Compact\DAQExp.dll
[Loaded DLLs] C:\Windows\system32\wsock32.dll
### Windows Socket 32-Bit DLL Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385
[Loaded DLLs] C:\Windows\syswow64\api-ms-win-downlevel-ole32-l1-1-0.dll
### ApiSet Stub DLL Microsoft Corporation Microsoft Windows Operating System 6.2
.9200.16492
[Loaded DLLs] C:\Windows\syswow64\URLMON.DLL
### OLE32 Extensions for Win32 Microsoft Corporation Internet Explorer 11.00.9
600.17041
[Loaded DLLs] C:\Windows\system32\mpr.dll
### Multiple Provider Router DLL Microsoft Corporation Microsoft Windows Operati
ng System 6.1.7600.16385
[Loaded DLLs] C:\Windows\system32\msimg32.dll
### GDIEXT Client DLL Microsoft Corporation Microsoft Windows Operating System 6
.1.7600.16385
[Loaded DLLs] C:\Windows\system32\apphelp.dll
### Application Compatibility Client Library Microsoft Corporation Microsoft Wi
ndows Operating System 6.1.7600.16385
[Loaded DLLs] C:\Windows\system32\dwmapi.dll
### Microsoft Desktop Window Manager API Microsoft Corporation Microsoft Window
s Operating System 6.1.7600.16385
[Loaded DLLs] C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b641
44ccf1df_5.82.7601.18201_none_ec80f00e8593ece5\COMCTL32.DLL
### Common Controls Library Microsoft Corporation Microsoft Windows Operating Sy
stem 6.1.7600.16385
[Loaded DLLs] C:\Windows\System32\wshtcpip.dll
### Winsock2 Helper DLL (TL/IPv4) Microsoft Corporation Microsoft Windows Operat
ing System 6.1.7600.16385
[Loaded DLLs] C:\Windows\System32\wship6.dll
### Winsock2 Helper DLL (TL/IPv6) Microsoft Corporation Microsoft Windows Operat
ing System 6.1.7600.16385
[Loaded DLLs] C:\Windows\system32\rasadhlp.dll
### Remote Access AutoDial Helper Microsoft Corporation Microsoft Windows Operat
ing System 6.1.7600.16385
[Loaded DLLs] C:\Windows\System32\fwpuclnt.dll
### FWP/IPsec User-Mode API Microsoft Corporation Microsoft Windows Operating Sy
stem 6.1.7600.16385
[Loaded DLLs] C:\Windows\system32\WINNSI.DLL
### Network Store Information RPC interface Microsoft Corporation Microsoft Win
dows Operating System 6.1.7600.16385
[Loaded DLLs] C:\Windows\system32\IPHLPAPI.DLL
### IP Helper API Microsoft Corporation Microsoft Windows Operating System 6.1.7
600.16385
[Loaded DLLs] C:\Windows\system32\DNSAPI.dll
### DNS Client API DLL Microsoft Corporation Microsoft Windows Operating System
6.1.7600.16385
[Loaded DLLs] C:\Windows\System32\mswsock.dll
### Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation Micro
soft Windows Operating System 6.1.7600.16385
[Loaded DLLs] C:\ProgramData\Google\Google Input Tools\plugins\virtual_keyboar
d_plugin.dll
### Google Input Tools Plugin Google Inc. Google Input Tools 1.1.3.18
[Loaded DLLs] C:\Windows\syswow64\COMDLG32.dll
### Common Dialogs DLL Microsoft Corporation Microsoft Windows Operating System
6.1.7600.16385
[Loaded DLLs] C:\ProgramData\Google\Google Input Tools\plugins\t13n_ime_plugin
.dll
### Google Input Tools Plugin Google Inc. Google Input Tools 1.1.3.18
[Loaded DLLs] C:\ProgramData\Google\Google Input Tools\plugins\character_picke
r_plugin.dll
### Google Input Tools Plugin Google Inc. Google Input Tools 1.1.3.18
[Loaded DLLs] C:\Windows\system32\WindowsCodecs.dll
### Microsoft Windows Codecs Library Microsoft Corporation Microsoft Windows Ope
rating System 6.2.9200.16492
[Loaded DLLs] C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b641
44ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
### User Experience Controls Library Microsoft Corporation Microsoft Windows Ope
rating System 6.1.7600.16385
[Loaded DLLs] C:\Windows\System32\msxml3.dll
### MSXML 3.0 SP11 Microsoft Corporation Microsoft(R) MSXML 3.0 SP11 8.110.760
1.18334
[Loaded DLLs] C:\Windows\syswow64\CLBCatQ.DLL
### COM+ Configuration Catalog Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385
[Loaded DLLs] C:\Windows\system32\uxtheme.dll
### Microsoft UxTheme Library Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385
[Loaded DLLs] C:\Windows\syswow64\WLDAP32.dll
### Win32 LDAP API DLL Microsoft Corporation Microsoft Windows Operating System
6.1.7600.16385
[Loaded DLLs] C:\Windows\system32\ntmarta.dll
### Windows NT MARTA provider Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385
[Loaded DLLs] C:\Windows\syswow64\MSCTF.dll
### MSCTF Server DLL Microsoft Corporation Microsoft Windows Operating System 6.
1.7600.16385
[Loaded DLLs] C:\Windows\system32\IMM32.DLL
### Multi-User Windows IMM32 API Client DLL Microsoft Corporation Microsoft Win
dows Operating System 6.1.7600.16385
[Loaded DLLs] C:\Windows\syswow64\api-ms-win-downlevel-advapi32-l1-1-0.dll
### ApiSet Stub DLL Microsoft Corporation Microsoft Windows Operating System 6.2
.9200.16492
[Loaded DLLs] C:\Windows\syswow64\iertutil.dll
### Run time utility for Internet Explorer Microsoft Corporation Internet Expl
orer 11.00.9600.17041
[Loaded DLLs] C:\Windows\syswow64\normaliz.DLL
### Unicode Normalization DLL Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385
[Loaded DLLs] C:\Windows\syswow64\api-ms-win-downlevel-normaliz-l1-1-0.dll
### ApiSet Stub DLL Microsoft Corporation Microsoft Windows Operating System 6.2
.9200.16492
[Loaded DLLs] C:\Windows\system32\version.DLL
### Version Checking and File Installation Libraries Microsoft Corporation Mic
rosoft Windows Operating System 6.1.7600.16385
[Loaded DLLs] C:\Windows\syswow64\api-ms-win-downlevel-version-l1-1-0.dll
### ApiSet Stub DLL Microsoft Corporation Microsoft Windows Operating System 6.2
.9200.16492
[Loaded DLLs] C:\Windows\syswow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
### ApiSet Stub DLL Microsoft Corporation Microsoft Windows Operating System 6.2
.9200.16492
### Internal Name: Browser. Status: service is running. Actual File: C:\Window
s\System32\svchost.exe -k netsvcs * Maintains an updated list of computers on th
e network and supplies this list to computers designated as browsers. If this se
rvice is stopped, this list will not be updated or maintained. If this service i
s disabled, any services that explicitly depend on it will fail to start. Host P
rocess for Windows Services Microsoft Corporation Microsoft Windows Operating Syst
em 6.1.7600.16385
[Running Services] CertPropSvc
### Internal Name: CertPropSvc. Status: service is running. Actual File: C:\Wi
ndows\system32\svchost.exe -k netsvcs * Copies user certificates and root certif
icates from smart cards into the current user's certificate store, detects when
a smart card is inserted into a smart card reader, and, if needed, installs the
smart card Plug and Play minidriver. Host Process for Windows Services Microsoft
Corporation Microsoft Windows Operating System 6.1.7600.16385
[Running Services] CryptSvc
### Internal Name: CryptSvc. Status: service is running. Actual File: C:\Windo
ws\system32\svchost.exe -k NetworkService * Provides four management services: C
atalog Database Service, which confirms the signatures of Windows files and allo
ws new programs to be installed; Protected Root Service, which adds and removes
Trusted Root Certification Authority certificates from this computer; Automatic
Root Certificate Update Service, which retrieves root certificates from Windows
Update and enable scenarios such as SSL; and Key Service, which helps enroll thi
s computer for certificates. If this service is stopped, these management servic
es will not function properly. If this service is disabled, any services that ex
plicitly depend on it will fail to start. Host Process for Windows Services Micr
osoft Corporation Microsoft Windows Operating System 6.1.7600.16385
[Running Services] CscService
### Internal Name: CscService. Status: service is running. Actual File: C:\Win
dows\System32\svchost.exe -k LocalSystemNetworkRestricted * The Offline Files se
rvice performs maintenance activities on the Offline Files cache, responds to us
er logon and logoff events, implements the internals of the public API, and disp
atches interesting events to those interested in Offline Files activities and ch
anges in cache state. Host Process for Windows Services Microsoft Corporation Mi
crosoft Windows Operating System 6.1.7600.16385
[Running Services] DcomLaunch
### Internal Name: DcomLaunch. Status: service is running. Actual File: C:\Win
dows\system32\svchost.exe -k DcomLaunch * The DCOMLAUNCH service launches COM an
d DCOM servers in response to object activation requests. If this service is sto
pped or disabled, programs using COM or DCOM will not function properly. It is s
trongly recommended that you have the DCOMLAUNCH service running. Host Process f
or Windows Services Microsoft Corporation Microsoft Windows Operating System 6.1.7
600.16385
[Running Services] Dhcp
### Internal Name: Dhcp. Status: service is running. Actual File: C:\Windows\s
ystem32\svchost.exe -k LocalServiceNetworkRestricted * Registers and updates IP
addresses and DNS records for this computer. If this service is stopped, this co
mputer will not receive dynamic IP addresses and DNS updates. If this service is
disabled, any services that explicitly depend on it will fail to start. Host Pr
ocess for Windows Services Microsoft Corporation Microsoft Windows Operating Syste
m 6.1.7600.16385
[Running Services] Dnscache
### Internal Name: Dnscache. Status: service is running. Actual File: C:\Windo
ws\system32\svchost.exe -k NetworkService * The DNS Client service (dnscache) ca
ches Domain Name System (DNS) names and registers the full computer name for thi
s computer. If the service is stopped, DNS names will continue to be resolved. H
owever, the results of DNS name queries will not be cached and the computer's na
me will not be registered. If the service is disabled, any services that explici
tly depend on it will fail to start. Host Process for Windows Services Microsoft
Corporation Microsoft Windows Operating System 6.1.7600.16385
[Running Services] DPS
### Internal Name: DPS. Status: service is running. Actual File: C:\Windows\Sy
stem32\svchost.exe -k LocalServiceNoNetwork * The Diagnostic Policy Service enab
les problem detection, troubleshooting and resolution for Windows components. I
f this service is stopped, diagnostics will no longer function. Host Process for
Windows Services Microsoft Corporation Microsoft Windows Operating System 6.1.760
0.16385
[Running Services] EFS
### Internal Name: EFS. Status: service is running. Actual File: C:\Windows\Sy
stem32\lsass.exe * Provides the core file encryption technology used to store en
crypted files on NTFS file system volumes. If this service is stopped or disable
d, applications will be unable to access encrypted files. Local Security Authori
ty Process Microsoft Corporation Microsoft Windows Operating System 6.1.7601.18443
[Running Services] ESRV_SVC_WILLAMETTE
### Internal Name: ESRV_SVC_WILLAMETTE. Status: service is running. Actual Fil
e: "C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\esrv_svc.exe" "--AUTO_START" "--s
tart" "--address" "127.0.0.1" "--port" "49330" "--depend_on_key" "SYSTEM\Current
ControlSet\Services\ESRV_SVC_WILLAMETTE" "--depend_on_value" "run" "--time_in_ms
" "--pause" "5000" "--library" "C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\intel
_modeler.dll" "--no_pl" "--watchdog" "10" "--watchdog_cpu_usage_limit" "50" "--e
nd_on_error" "--kernel_priority_boost" "--shutdown_priority_boost" "--device_opt
ions" " time=no output=w output_folder='C:\ProgramData\Intel\SUR\WILLAMETTE\Inte
lData' limit_output_by=time output_limit=3600000 output_buffer=1024 il='C:\Progr
am Files\Intel\SUR\WILLAMETTE\ESRV\intel_process_input.dll','process_input_optio
ns.txt' il='C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\intel_system_power_state_
input.dll' il='C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\intel_quality_and_reli
ability_input.dll' il='C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\acpi_battery_i
nput.dll' il='C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\sema_thermal_input.dll'
il='C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\wifi_input.dll' il='C:\Program F
iles\Intel\SUR\WILLAMETTE\ESRV\devices_use_input.dll','service=yes' il='C:\Progr
am Files\Intel\SUR\WILLAMETTE\ESRV\intel_disktrace_input.dll','pause=60000 worki
ng_dir=C:\ProgramData\Intel\SUR\WILLAMETTE\IntelData override_existing_tracing=n
o limit_output_by_filesize_mb=10' os='C:\Program Files\Intel\SUR\WILLAMETTE\ESRV
\os_counters.txt' " * Intel(r) Energy Checker SDK. ESRV Service WILLAMETTE Inte
l(R) System Usage Report Intel(R) System Usage Report
[Running Services] eventlog
### Internal Name: eventlog. Status: service is running. Actual File: C:\Windo
ws\System32\svchost.exe -k LocalServiceNetworkRestricted * This service manages
events and event logs. It supports logging events, querying events, subscribing
to events, archiving event logs, and managing event metadata. It can display eve
nts in both XML and plain text format. Stopping this service may compromise secu
rity and reliability of the system. Host Process for Windows Services Microsoft
Corporation Microsoft Windows Operating System 6.1.7600.16385
[Running Services] EventSystem
### Internal Name: EventSystem. Status: service is running. Actual File: C:\Wi
ndows\system32\svchost.exe -k LocalService * Supports System Event Notification
Service (SENS), which provides automatic distribution of events to subscribing C
omponent Object Model (COM) components. If the service is stopped, SENS will clo
se and will not be able to provide logon and logoff notifications. If this servi
ce is disabled, any services that explicitly depend on it will fail to start. Ho
st Process for Windows Services Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385
[Running Services] fdPHost
### Internal Name: fdPHost. Status: service is running. Actual File: C:\Window
s\system32\svchost.exe -k LocalService * The FDPHOST service hosts the Function
Discovery (FD) network discovery providers. These FD providers supply network di
scovery services for the Simple Services Discovery Protocol (SSDP) and Web Servi
Discovery (WS-D) protocol. Stopping or disabling the FDPHOST service will di
ces
sable network discovery for these protocols when using FD. When this service is
unavailable, network services using FD and relying on these discovery protocols
will be unable to find network devices or resources. Host Process for Windows Se
rvices Microsoft Corporation Microsoft Windows Operating System 6.1.7600.16385
[Running Services] FLEXnet Licensing Service
### Internal Name: FLEXnet Licensing Service. Status: service is running. Actu
al File: "C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publish
er\FNPLicensingService.exe" * This service performs licensing functions on behal
f of FLEXnet enabled products. Activation Licensing Service Acresso Software Inc
. FLEXnet Publisher (32 bit) 11.7.0.0 build 73797
[Running Services] FontCache
### Internal Name: FontCache. Status: service is running. Actual File: C:\Wind
ows\system32\svchost.exe -k LocalService * Optimizes performance of applications
by caching commonly used font data. Applications will start this service if it
is not already running. It can be disabled, though doing so will degrade applica
tion performance. Host Process for Windows Services Microsoft Corporation Micros
oft Windows Operating System 6.1.7600.16385
[Running Services] GoogleInputService
### Internal Name: GoogleInputService. Status: service is running. Actual File
: "C:\Program Files (x86)\Google\Google Input Tools\GoogleInputService.exe" * G
oogle Input Tools. Google Inc Google Input Tools 1.1.3.18
[Running Services] gpsvc
### Internal Name: gpsvc. Status: service is running. Actual File: C:\Windows\
system32\svchost.exe -k netsvcs * The service is responsible for applying settin
gs configured by administrators for the computer and users through the Group Pol
icy component. If the service is stopped or disabled, the settings will not be a
pplied and applications and components will not be manageable through Group Poli
cy. Any components or applications that depend on the Group Policy component mig
ht not be functional if the service is stopped or disabled. Host Process for Win
dows Services Microsoft Corporation Microsoft Windows Operating System 6.1.7600.16
385
[Running Services] hidserv
### Internal Name: hidserv. Status: service is running. Actual File: C:\Window
s\system32\svchost.exe -k LocalSystemNetworkRestricted * Enables generic input a
ccess to Human Interface Devices (HID), which activates and maintains the use of
predefined hot buttons on keyboards, remote controls, and other multimedia devi
ces. If this service is stopped, hot buttons controlled by this service will no
longer function. If this service is disabled, any services that explicitly depen
d on it will fail to start. Host Process for Windows Services Microsoft Corporat
ion Microsoft Windows Operating System 6.1.7600.16385
[Running Services] IKEEXT
### Internal Name: IKEEXT. Status: service is running. Actual File: C:\Windows
\system32\svchost.exe -k netsvcs * The IKEEXT service hosts the Internet Key Exc
hange (IKE) and Authenticated Internet Protocol (AuthIP) keying modules. These k
eying modules are used for authentication and key exchange in Internet Protocol
security (IPsec). Stopping or disabling the IKEEXT service will disable IKE and
AuthIP key exchange with peer computers. IPsec is typically configured to use IK
E or AuthIP; therefore, stopping or disabling the IKEEXT service might result in
an IPsec failure and might compromise the security of the system. It is strongl
y recommended that you have the IKEEXT service running. Host Process for Windows
Services Microsoft Corporation Microsoft Windows Operating System 6.1.7600.16385
[Running Services] iphlpsvc
### Internal Name: iphlpsvc. Status: service is running. Actual File: C:\Windo
ws\System32\svchost.exe -k NetSvcs * Provides tunnel connectivity using IPv6 tra
nsition technologies (6to4, ISATAP, Port Proxy, and Teredo), and IP-HTTPS. If th
is service is stopped, the computer will not have the enhanced connectivity bene
fits that these technologies offer. Host Process for Windows Services Microsoft
Corporation Microsoft Windows Operating System 6.1.7600.16385
[Running Services] LanmanServer
### Internal Name: LanmanServer. Status: service is running. Actual File: C:\W
indows\system32\svchost.exe -k netsvcs * Supports file, print, and named-pipe sh
aring over the network for this computer. If this service is stopped, these func
tions will be unavailable. If this service is disabled, any services that explic
itly depend on it will fail to start. Host Process for Windows Services Microsof
t Corporation Microsoft Windows Operating System 6.1.7600.16385
[Running Services] LanmanWorkstation
### Internal Name: LanmanWorkstation. Status: service is running. Actual File:
C:\Windows\System32\svchost.exe -k NetworkService * Creates and maintains clien
t network connections to remote servers using the SMB protocol. If this service
is stopped, these connections will be unavailable. If this service is disabled,
any services that explicitly depend on it will fail to start. Host Process for W
indows Services Microsoft Corporation Microsoft Windows Operating System 6.1.7600.
16385
[Running Services] lmhosts
### Internal Name: lmhosts. Status: service is running. Actual File: C:\Window
s\system32\svchost.exe -k LocalServiceNetworkRestricted * Provides support for t
he NetBIOS over TCP/IP (NetBT) service and NetBIOS name resolution for clients o
n the network, therefore enabling users to share files, print, and log on to the
network. If this service is stopped, these functions might be unavailable. If t
his service is disabled, any services that explicitly depend on it will fail to
start. Host Process for Windows Services Microsoft Corporation Microsoft Windows O
perating System 6.1.7600.16385
[Running Services] LMS
### Internal Name: LMS. Status: service is running. Actual File: C:\Program Fi
les (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe * Allows appli
cations to access the local Intel(R) Management and Security Application using i
ts locally-available selected network interfaces. Local Manageability Service In
tel Corporation Intel(R) Active Management Technology Local Manageability Servic
e 7.1.10.1065
[Running Services] MatLocalLicenceServer50
### Internal Name: MatLocalLicenceServer50. Status: service is running. Actual
File: "C:\Program Files (x86)\Common Files\Materialise\LicenseFiles\LicSrv50.ex
e" * Materialise Local License Server 5.0 LicSrv MFC Application LicSrv Applicat
ion 5.0.0.5
[Running Services] MpsSvc
### Internal Name: MpsSvc. Status: service is running. Actual File: C:\Windows
\system32\svchost.exe -k LocalServiceNoNetwork * Windows Firewall helps protect
your computer by preventing unauthorized users from gaining access to your compu
ter through the Internet or a network. Host Process for Windows Services Microso
ft Corporation Microsoft Windows Operating System 6.1.7600.16385
[Running Services] Net Driver HPZ12
### Internal Name: Net Driver HPZ12. Status: service is running. Actual File:
C:\Windows\System32\svchost.exe -k HPZ12 * Host Process for Windows Services Mi
crosoft Corporation Microsoft Windows Operating System 6.1.7600.16385
[Running Services] Netlogon
### Internal Name: Netlogon. Status: service is running. Actual File: C:\Windo
ws\system32\lsass.exe * Maintains a secure channel between this computer and the
domain controller for authenticating users and services. If this service is sto
pped, the computer may not authenticate users and services and the domain contro
ller cannot register DNS records. If this service is disabled, any services that
explicitly depend on it will fail to start. Local Security Authority Process Mi
crosoft Corporation Microsoft Windows Operating System 6.1.7601.18443
[Running Services] Netman
### Internal Name: Netman. Status: service is running. Actual File: C:\Windows
\System32\svchost.exe -k LocalSystemNetworkRestricted * Manages objects in the N
etwork and Dial-Up Connections folder, in which you can view both local area net
work and remote connections. Host Process for Windows Services Microsoft Corpora
tion Microsoft Windows Operating System 6.1.7600.16385
[Running Services] netprofm
### Internal Name: netprofm. Status: service is running. Actual File: C:\Windo
ws\System32\svchost.exe -k LocalService * Identifies the networks to which the c
omputer has connected, collects and stores properties for these networks, and no
tifies applications when these properties change. Host Process for Windows Servi
ces Microsoft Corporation Microsoft Windows Operating System 6.1.7600.16385
[Running Services] NlaSvc
### Internal Name: NlaSvc. Status: service is running. Actual File: C:\Windows
\System32\svchost.exe -k NetworkService * Collects and stores configuration info
rmation for the network and notifies programs when this information is modified.
If this service is stopped, configuration information might be unavailable. If
this service is disabled, any services that explicitly depend on it will fail to
start. Host Process for Windows Services Microsoft Corporation Microsoft Windows
Operating System 6.1.7600.16385
[Running Services] nsi
### Internal Name: nsi. Status: service is running. Actual File: C:\Windows\sy
stem32\svchost.exe -k LocalService * This service delivers network notifications
(e.g. interface addition/deleting etc) to user mode clients. Stopping this serv
ice will cause loss of network connectivity. If this service is disabled, any ot
her services that explicitly depend on this service will fail to start. Host Pro
cess for Windows Services Microsoft Corporation Microsoft Windows Operating System
6.1.7600.16385
[Running Services] PcaSvc
### Internal Name: PcaSvc. Status: service is running. Actual File: C:\Windows
\system32\svchost.exe -k LocalSystemNetworkRestricted * This service provides su
pport for the Program Compatibility Assistant (PCA). PCA monitors programs inst
alled and run by the user and detects known compatibility problems. If this serv
ice is stopped, PCA will not function properly. Host Process for Windows Service
s Microsoft Corporation Microsoft Windows Operating System 6.1.7600.16385
[Running Services] PelService
### Internal Name: PelService. Status: service is running. Actual File: C:\Pro
gram Files\Lenovo\Lenovo Mouse Suite\PelService.exe *
[Running Services] PlugPlay
### Internal Name: PlugPlay. Status: service is running. Actual File: C:\Windo
ws\system32\svchost.exe -k DcomLaunch * Enables a computer to recognize and adap
t to hardware changes with little or no user input. Stopping or disabling this s
ervice will result in system instability. Host Process for Windows Services Micr
osoft Corporation Microsoft Windows Operating System 6.1.7600.16385
[Running Services] Pml Driver HPZ12
### Internal Name: Pml Driver HPZ12. Status: service is running. Actual File:
C:\Windows\System32\svchost.exe -k HPZ12 * Host Process for Windows Services Mi
crosoft Corporation Microsoft Windows Operating System 6.1.7600.16385
[Running Services] Power
### Internal Name: Power. Status: service is running. Actual File: C:\Windows\
system32\svchost.exe -k DcomLaunch * Manages power policy and power policy notif
ication delivery. Host Process for Windows Services Microsoft Corporation Micros
oft Windows Operating System 6.1.7600.16385
[Running Services] ProfSvc
### Internal Name: ProfSvc. Status: service is running. Actual File: C:\Window
s\system32\svchost.exe -k netsvcs * This service is responsible for loading and
unloading user profiles. If this service is stopped or disabled, users will no l
onger be able to successfully logon or logoff, applications may have problems ge
tting to users' data, and components registered to receive profile event notific
ations will not receive them. Host Process for Windows Services Microsoft Corpor
ation Microsoft Windows Operating System 6.1.7600.16385
[Running Services] PSI_SVC_2_x64
### Internal Name: PSI_SVC_2_x64. Status: service is running. Actual File: "c:
\Program Files\Common Files\Protexis\License Service\PsiService_2.exe" * This se
rvice provides license-validation functionality for Corel Corporation. It is pow
ered by Protexis from arvato digital Services. PsiService PsiService arvato digi
tal services llc PsiService System Service 3.3.0.24
[Running Services] RemoteRegistry
### Internal Name: RemoteRegistry. Status: service is running. Actual File: C:
\Windows\system32\svchost.exe -k regsvc * Enables remote users to modify registr
y settings on this computer. If this service is stopped, the registry can be mod
ified only by users on this computer. If this service is disabled, any services
that explicitly depend on it will fail to start. Host Process for Windows Servic
es Microsoft Corporation Microsoft Windows Operating System 6.1.7600.16385
[Running Services] RosettaStoneDaemon
### Internal Name: RosettaStoneDaemon. Status: service is running. Actual File
: "C:\Program Files (x86)\RosettaStoneLtdServices\RosettaStoneDaemon.exe" * Ros
etta Stone Ltd. application Rosetta Stone Ltd. Rosetta Stone Daemon 1.0.1.0
[Running Services] RpcEptMapper
### Internal Name: RpcEptMapper. Status: service is running. Actual File: C:\W
indows\system32\svchost.exe -k RPCSS * Resolves RPC interfaces identifiers to tr
ansport endpoints. If this service is stopped or disabled, programs using Remote
Procedure Call (RPC) services will not function properly. Host Process for Wind
ows Services Microsoft Corporation Microsoft Windows Operating System 6.1.7600.163
85
[Running Services] RpcSs
### Internal Name: RpcSs. Status: service is running. Actual File: C:\Windows\
system32\svchost.exe -k rpcss * The RPCSS service is the Service Control Manager
for COM and DCOM servers. It performs object activations requests, object expor
ter resolutions and distributed garbage collection for COM and DCOM servers. If
this service is stopped or disabled, programs using COM or DCOM will not functio
n properly. It is strongly recommended that you have the RPCSS service running H
ost Process for Windows Services Microsoft Corporation Microsoft Windows Operating
System 6.1.7600.16385
[Running Services] SamSs
### Internal Name: SamSs. Status: service is running. Actual File: C:\Windows\
system32\lsass.exe * The startup of this service signals other services that the
Security Accounts Manager (SAM) is ready to accept requests. Disabling this se
rvice will prevent other services in the system from being notified when the SAM
is ready, which may in turn cause those services to fail to start correctly. Th
is service should not be disabled. Local Security Authority Process Microsoft Co
rporation Microsoft Windows Operating System 6.1.7601.18443
[Running Services] Schedule
### Internal Name: Schedule. Status: service is running. Actual File: C:\Windo
ws\system32\svchost.exe -k netsvcs * Enables a user to configure and schedule au
tomated tasks on this computer. The service also hosts multiple Windows system-c
ritical tasks. If this service is stopped or disabled, these tasks will not be r
un at their scheduled times. If this service is disabled, any services that expl
icitly depend on it will fail to start. Host Process for Windows Services Micros
oft Corporation Microsoft Windows Operating System 6.1.7600.16385
[Running Services] seclogon
### Internal Name: seclogon. Status: service is running. Actual File: C:\Windo
ws\system32\svchost.exe -k netsvcs * Enables starting processes under alternate
credentials. If this service is stopped, this type of logon access will be unava
ilable. If this service is disabled, any services that explicitly depend on it w
ill fail to start. Host Process for Windows Services Microsoft Corporation Micro
soft Windows Operating System 6.1.7600.16385
[Running Services] SENS
### Internal Name: SENS. Status: service is running. Actual File: C:\Windows\s
ystem32\svchost.exe -k netsvcs * Monitors system events and notifies subscribers
to COM+ Event System of these events. Host Process for Windows Services Microso
ft Corporation Microsoft Windows Operating System 6.1.7600.16385
[Running Services] SessionEnv
### Internal Name: SessionEnv. Status: service is running. Actual File: C:\Win
dows\System32\svchost.exe -k netsvcs * Remote Desktop Configuration service (RDC
S) is responsible for all Remote Desktop Services and Remote Desktop related con
figuration and session maintenance activities that require SYSTEM context. These
include per-session temporary folders, RD themes, and RD certificates. Host Pro
cess for Windows Services Microsoft Corporation Microsoft Windows Operating System
6.1.7600.16385
sed by the Diagnostic Policy Service to host diagnostics that need to run in a L
ocal Service context. If this service is stopped, any diagnostics that depend o
n it will no longer function. Host Process for Windows Services Microsoft Corpor
ation Microsoft Windows Operating System 6.1.7600.16385
[Running Services] Winmgmt
### Internal Name: Winmgmt. Status: service is running. Actual File: C:\Window
s\system32\svchost.exe -k netsvcs * Provides a common interface and object model
to access management information about operating system, devices, applications
and services. If this service is stopped, most Windows-based software will not f
unction properly. If this service is disabled, any services that explicitly depe
nd on it will fail to start. Host Process for Windows Services Microsoft Corpora
tion Microsoft Windows Operating System 6.1.7600.16385
[Running Services] WSearch
### Internal Name: WSearch. Status: service is running. Actual File: C:\Window
s\system32\SearchIndexer.exe /Embedding * Provides content indexing, property ca
ching, and search results for files, e-mail, and other content. Microsoft Window
s Search Indexer Microsoft Corporation Windows Search 7.00.7600.16385
[Running Services] wudfsvc
### Internal Name: wudfsvc. Status: service is running. Actual File: C:\Window
s\system32\svchost.exe -k LocalSystemNetworkRestricted * Manages user-mode drive
r host processes. Host Process for Windows Services Microsoft Corporation Micros
oft Windows Operating System 6.1.7600.16385
[Uninstall]
[Applications] :HKLM {4010ADCB-1347-D570-FCF1-3002CABEBD2F}=MsiExec.exe /X{401
0ADCB-1347-D570-FCF1-3002CABEBD2F}
### Rosetta Stone TOTALe - (28) 04-2016
[Applications] :HKLM com.rosettastone.rosettastonetotale=cmd /c "start /wait m
siexec /qb /x {8A1FEA5E-8DB8-AD80-5C14-AEF33D16EF5A} && msiexec /qb /x {4010ADCB
-1347-D570-FCF1-3002CABEBD2F}"
### Rosetta Stone TOTALe - (28) 04-2016
[Applications] :HKLM {7BB2EF8A-5376-4BAE-96D0-38BE49501F40}=MsiExec.exe /X{7BB
2EF8A-5376-4BAE-96D0-38BE49501F40}
### Rosetta Stone Ltd Services - (28) 04-2016
[Applications] :HKLM {8A1FEA5E-8DB8-AD80-5C14-AEF33D16EF5A}=MsiExec.exe /I{8A1
FEA5E-8DB8-AD80-5C14-AEF33D16EF5A}
### Rosetta Stone TOTALe - (28) 04-2016
[Applications] :HKLM Adobe Flash Player NPAPI=C:\Windows\SysWOW64\Macromed\Fla
sh\FlashUtil32_21_0_0_213_Plugin.exe -maintain plugin
### Adobe Flash Player 21 NPAPI - (08) 04-2016
[Applications] :HKLM Adobe Flash Player ActiveX=C:\Windows\SysWOW64\Macromed\F
lash\FlashUtil32_21_0_0_213_ActiveX.exe -maintain activex
### Adobe Flash Player 21 ActiveX - (08) 04-2016
[Applications] :HKLM {AC76BA86-1033-0000-7760-000000000002}
### Adobe Acrobat 7.0 Professional - (06) 04-2016
[Applications] :HKLM MediaCoder x64=C:\Program Files\MediaCoder\uninst.exe
### MediaCoder x64 0.8.42.5822 - (06) 04-2016
[Applications] :HKLM Meda MP3 Joiner_is1="C:\Program Files (x86)\Meda MP3 Join
er\unins000.exe"
### Meda MP3 Joiner 1.2 - (06) 04-2016
[Applications] :HKLM {A7E19604-93AF-4611-8C9F-CE509C2B286F}_is1="C:\Program Fi
les (x86)\Free YouTube Downloader\unins000.exe"
### Free YouTube Downloader 4.1.484 - (05) 04-2016
[Applications] :HKLM {619e726e-d2b4-4e28-9568-c964fd81ee6c}="C:\ProgramData\Pa
ckage Cache\{619e726e-d2b4-4e28-9568-c964fd81ee6c}\SetupChipset.exe" /uninstall
### Intel(R) Chipset Device Software - (31) 03-2016
[Applications] :HKLM {FEBB7B48-CC1C-4A50-A497-FA21413F6BE9}=MsiExec.exe /I{FEB
B7B48-CC1C-4A50-A497-FA21413F6BE9}
### Intel(R) Chipset Device Software - (31) 03-2016
[Applications] :HKLM {1b09c4de-9cae-4122-b17c-65d395062b50}="C:\ProgramData\Pa
ckage Cache\{1b09c4de-9cae-4122-b17c-65d395062b50}\Intel Driver Update Utility I
nstaller.exe" /uninstall
### Intel Driver Update Utility - (31) 03-2016
[Applications] :HKLM {B731F5C4-E304-4DFA-9C84-F67FF849B408}=MsiExec.exe /X{B73
1F5C4-E304-4DFA-9C84-F67FF849B408}
### Intel(R) Driver Update Utility 2.4 - (31) 03-2016
[Applications] :HKLM {E954D7C1-36FA-4FE8-8927-97DBDEB5A15F}=MsiExec.exe /I{E95
4D7C1-36FA-4FE8-8927-97DBDEB5A15F}
### Intel(R) Product Improvement Program - (31) 03-2016
[Applications] :HKLM {65153EA5-8B6E-43B6-857B-C6E4FC25798A}=C:\Program Files (
x86)\Intel\Intel(R) Management Engine Components\Uninstall\setup.exe -uninstall
### Intel(R) Management Engine Components - (31) 03-2016
[Applications] :HKLM {2991A446-D356-44EC-930A-42E8B02A67C0}_is1="C:\Program Fi
les (x86)\MiniTool Partition Wizard Professional Edition 9.1\unins000.exe"
### MiniTool Partition Wizard Professional Edition 9.1 - (31) 03-2016
[Applications] :HKLM {0C286478-1D87-432F-9ADB-5C36FA58BB72}_is1="C:\Program Fi
les (x86)\MiniTool Partition Wizard Server Edition 9.1\unins000.exe"
### MiniTool Partition Wizard Server Edition 9.1 - (31) 03-2016
[Applications] :HKLM MalwareProtectionLive="C:\Users\admin\AppData\Local\Malwa
reProtectionLive\uninstall.exe"
### Malware Protection Live - (30) 03-2016
[Applications] :HKLM {1a413f37-ed88-4fec-9666-5c48dc4b7bb7}="C:\Program Files
(x86)\GreenTree Applications\YTD Video Downloader\uninstall.exe"
### YTD Video Downloader 5.3 - (30) 03-2016
[Applications] :HKLM {891ED714-E54D-4BE1-8DE8-4EE54D9BB402}=MsiExec.exe /X{891
ED714-E54D-4BE1-8DE8-4EE54D9BB402}
### Pinnacle Studio 19 - Install Manager - (29) 03-2016
[Applications] :HKLM {4A03706F-666A-4037-7777-5F2748764D10}
### Java Auto Updater - (26) 03-2016
[Applications] :HKLM {26A24AE4-039D-4CA4-87B4-2F83218077F0}=MsiExec.exe /X{26A
24AE4-039D-4CA4-87B4-2F83218077F0}
### Java 8 Update 77 - (26) 03-2016
[Applications] :HKLM {3C9D008D-3716-4C3F-90CD-38ED57568FAB}_is1="C:\Program Fi
les (x86)\Apowersoft\Video Download Capture\unins000.exe"
### Video Download Capture V4.3.0 - (26) 03-2016
[Applications] :HKLM {AC76BA86-7AD7-1033-7B44-AC0F074E4100}=MsiExec.exe /I{AC7
6BA86-7AD7-1033-7B44-AC0F074E4100}
### Adobe Acrobat Reader DC - (18) 03-2016
[Applications] :HKLM UnHackMe_is1="C:\Program Files (x86)\UnHackMe\unins000.ex
e"
### UnHackMe 7.70 release - (17) 03-2016
[Applications] :HKLM {60EC980A-BDA2-4CB6-A427-B07A5498B4CA}=MsiExec.exe /I{60E
C980A-BDA2-4CB6-A427-B07A5498B4CA}
### Google Update Helper - (22) 01-2016
[Applications] :HKLM Google Chrome="C:\Program Files (x86)\Google\Chrome\Appli
cation\48.0.2564.82\Installer\setup.exe" --uninstall --multi-install --chrome -system-level --verbose-logging
### Google Chrome - (22) 01-2016
[Applications] :HKLM {AC76BA86-0804-1033-1959-001824166751}=MsiExec.exe /I{AC7
6BA86-0804-1033-1959-001824166751}
### Adobe Refresh Manager - (18) 01-2016
[Applications] :HKLM Adobe Acrobat 7.0 Professional=msiexec /I {AC76BA86-10330000-7760-000000000002}
### Adobe Acrobat 7.0 Professional - (18) 01-2016
[Applications] :HKLM NirSoft Wireless Network Watcher="C:\Program Files (x86)\
NirSoft\Wireless Network Watcher\uninst.exe"
### NirSoft Wireless Network Watcher - (07) 01-2016
[Applications] :HKLM {F09EF8F2-0976-42C1-8D9D-8DF78337C6E3}="C:\Program Files
(x86)\InstallShield Installation Information\{F09EF8F2-0976-42C1-8D9D-8DF78337C6
E3}\setup.exe" -runfromtemp -l0x0409 -removeonly
### Sony PC Companion 2.10.303 - (19) 12-2015
### Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 - (11) 02-201
4
[Applications] :HKLM Total Video Converter 3.71_is1="C:\Program Files (x86)\To
tal Video Converter\unins000.exe"
### Total Video Converter 3.71 100812 - (04) 02-2014
[Applications] :HKLM {A19293EE-76AB-475B-949A-5A90DCC960DE}=C:\Program Files (
x86)\InstallShield Installation Information\{A19293EE-76AB-475B-949A-5A90DCC960D
E}\setup.exe -runfromtemp -l0x0009 -removeonly
### iVMS-4000(v2.0) - (03) 02-2014
[Applications] :HKLM {AE0F62A7-A1A2-407F-9F4C-48939BD9AD8D}=MsiExec.exe /X{AE0
F62A7-A1A2-407F-9F4C-48939BD9AD8D}
### tools-winPre2k - (28) 01-2014
[Applications] :HKLM {FFD9383C-01D5-4897-A954-43AF599AED30}=MsiExec.exe /X{FFD
9383C-01D5-4897-A954-43AF599AED30}
### tools-windows - (28) 01-2014
[Applications] :HKLM {AB1C87CB-1807-4CF0-B4C2-CEE14C18CDB4}=MsiExec.exe /X{AB1
C87CB-1807-4CF0-B4C2-CEE14C18CDB4}
### tools-solaris - (28) 01-2014
[Applications] :HKLM {197597A7-AD33-4898-9D8E-73066818B464}=MsiExec.exe /X{197
597A7-AD33-4898-9D8E-73066818B464}
### tools-netware - (28) 01-2014
[Applications] :HKLM {D102611A-6466-4101-A51D-51069303AC65}=MsiExec.exe /X{D10
2611A-6466-4101-A51D-51069303AC65}
### tools-linux - (28) 01-2014
[Applications] :HKLM {003BFBBD-6C67-419E-A24D-0DCAFC3A5249}=MsiExec.exe /X{003
BFBBD-6C67-419E-A24D-0DCAFC3A5249}
### tools-freebsd - (28) 01-2014
[Applications] :HKLM VMware_Workstation="C:\ProgramData\VMware\VMware Workstat
ion\Uninstaller\\uninstall.exe" -x -S "C:\ProgramData\VMware\VMware Workstation\
Uninstaller\"
### VMware Workstation - (28) 01-2014
[Applications] :HKLM {0D94F75A-0EA6-4951-B3AF-B145FA9E05C6}
### - (28) 01-2014
[Applications] :HKLM {0D94F75A-0EA6-4951-B3AF-B145FA9E05C6}=MsiExec.exe /I{0D9
4F75A-0EA6-4951-B3AF-B145FA9E05C6}
### VMware Workstation - (28) 01-2014
[Applications] :HKLM {4B6C7001-C7D6-3710-913E-5BC23FCE91E6}=MsiExec.exe /X{4B6
C7001-C7D6-3710-913E-5BC23FCE91E6}
### Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 - (28) 01-2
014
[Applications] :HKLM {1F1C2DFC-2D24-3E06-BCB8-725134ADF989}=MsiExec.exe /X{1F1
C2DFC-2D24-3E06-BCB8-725134ADF989}
### Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 - (28) 01-2
014
[Applications] :HKLM {ECD07791-9A98-4E16-B350-0D31809E5EBF}=MsiExec.exe /X{ECD
07791-9A98-4E16-B350-0D31809E5EBF}
### Advanced Office Password Recovery - (27) 01-2014
[Applications] :HKLM {6a01f86f-4959-4e83-8ed9-78b120a9d70f}_is1="C:\Program Fi
les (x86)\SysTools XLSX Recovery\unins000.exe"
### SysTools XLSX Recovery v1.0 - (24) 01-2014
[Applications] :HKLM {BEE8AFD4-907F-4BD5-B2E9-6606291415E8}_is1="C:\Program Fi
les (x86)\FREE Word and Excel password recovery Wizard\unins000.exe"
### FREE Word and Excel password recovery Wizard version 2.1.15 - (24) 01-2014
[Applications] :HKLM Daossoft Excel Password Recovery=C:\Program Files (x86)\D
aossoft Excel Password Recovery\uninst.exe
### Daossoft Excel Password Recovery 7.0.0.1 - (24) 01-2014
[Applications] :HKLM MiniMagics
### MiniMagics - (21) 01-2014
[Applications] :HKLM {78A136F4-6FC0-403E-8BFF-953063BD122C}=MsiExec.exe /I{78A
136F4-6FC0-403E-8BFF-953063BD122C}
20000-0030-0000-0000-0000000FF1CE}
### Microsoft Office Enterprise 2007 - (01) 12-2013
[Applications] :HKLM ENTERPRISE="C:\Program Files (x86)\Common Files\Microsoft
Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall ENTERPRISE /dll O
SETUP.DLL
### Microsoft Office Enterprise 2007 - (01) 12-2013
[Applications] :HKLM {90120000-002A-0000-1000-0000000FF1CE}=MsiExec.exe /X{901
20000-002A-0000-1000-0000000FF1CE}
### Microsoft Office Office 64-bit Components 2007 - (01) 12-2013
[Applications] :HKLM {90120000-00A1-0409-0000-0000000FF1CE}=MsiExec.exe /X{901
20000-00A1-0409-0000-0000000FF1CE}
### Microsoft Office OneNote MUI (English) 2007 - (01) 12-2013
[Applications] :HKLM {90120000-0117-0409-0000-0000000FF1CE}=MsiExec.exe /X{901
20000-0117-0409-0000-0000000FF1CE}
### Microsoft Office Access Setup Metadata MUI (English) 2007 - (01) 12-2013
[Applications] :HKLM {90120000-0015-0409-0000-0000000FF1CE}=MsiExec.exe /X{901
20000-0015-0409-0000-0000000FF1CE}
### Microsoft Office Access MUI (English) 2007 - (01) 12-2013
[Applications] :HKLM {90120000-001B-0409-0000-0000000FF1CE}=MsiExec.exe /X{901
20000-001B-0409-0000-0000000FF1CE}
### Microsoft Office Word MUI (English) 2007 - (01) 12-2013
[Applications] :HKLM {90120000-0019-0409-0000-0000000FF1CE}=MsiExec.exe /X{901
20000-0019-0409-0000-0000000FF1CE}
### Microsoft Office Publisher MUI (English) 2007 - (01) 12-2013
[Applications] :HKLM {90120000-002C-0409-0000-0000000FF1CE}=MsiExec.exe /X{901
20000-002C-0409-0000-0000000FF1CE}
### Microsoft Office Proofing (English) 2007 - (01) 12-2013
[Applications] :HKLM {90120000-001F-0409-0000-0000000FF1CE}=MsiExec.exe /X{901
20000-001F-0409-0000-0000000FF1CE}
### Microsoft Office Proof (English) 2007 - (01) 12-2013
[Applications] :HKLM {90120000-001F-040C-0000-0000000FF1CE}=MsiExec.exe /X{901
20000-001F-040C-0000-0000000FF1CE}
### Microsoft Office Proof (French) 2007 - (01) 12-2013
[Applications] :HKLM {90120000-001F-0C0A-0000-0000000FF1CE}=MsiExec.exe /X{901
20000-001F-0C0A-0000-0000000FF1CE}
### Microsoft Office Proof (Spanish) 2007 - (01) 12-2013
[Applications] :HKLM {90120000-0116-0409-1000-0000000FF1CE}=MsiExec.exe /X{901
20000-0116-0409-1000-0000000FF1CE}
### Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007 - (01) 12
-2013
[Applications] :HKLM {90120000-002A-0409-1000-0000000FF1CE}=MsiExec.exe /X{901
20000-002A-0409-1000-0000000FF1CE}
### Microsoft Office Shared 64-bit MUI (English) 2007 - (01) 12-2013
[Applications] :HKLM {90120000-0044-0409-0000-0000000FF1CE}=MsiExec.exe /X{901
20000-0044-0409-0000-0000000FF1CE}
### Microsoft Office InfoPath MUI (English) 2007 - (01) 12-2013
[Applications] :HKLM {90120000-0114-0409-0000-0000000FF1CE}=MsiExec.exe /X{901
20000-0114-0409-0000-0000000FF1CE}
### Microsoft Office Groove Setup Metadata MUI (English) 2007 - (01) 12-2013
[Applications] :HKLM {90120000-00BA-0409-0000-0000000FF1CE}=MsiExec.exe /X{901
20000-00BA-0409-0000-0000000FF1CE}
### Microsoft Office Groove MUI (English) 2007 - (01) 12-2013
[Applications] :HKLM {90120000-0018-0409-0000-0000000FF1CE}=MsiExec.exe /X{901
20000-0018-0409-0000-0000000FF1CE}
### Microsoft Office PowerPoint MUI (English) 2007 - (01) 12-2013
[Applications] :HKLM {90120000-001A-0409-0000-0000000FF1CE}=MsiExec.exe /X{901
20000-001A-0409-0000-0000000FF1CE}
### Microsoft Office Outlook MUI (English) 2007 - (01) 12-2013
[Applications] :HKLM {90120000-0016-0409-0000-0000000FF1CE}=MsiExec.exe /X{901
20000-0016-0409-0000-0000000FF1CE}
]C:\PROGRA~2\MICROS~1\OFFICE12\GRA32A~1.DLL
[FC3396B88F31636817D31F592A0DA848][1
274744
]C:\PROGRA~2\MICROS~1\OFFICE12\OIS.EXE
[7FC19DA1DC70C78D2FBD7A1D10942051][1
40424
]C:\PROGRA~2\MICROS~1\OFFICE12\REFIEBAR.DLL
[4289E488905354E56002E60F211ACE3A][2
86016
]C:\PROGRAM FILES (X86)\7-ZIP\7-ZIP.DLL
[EDFCA3682BCFE788BFCABF4D7E22805A][2
577536
]C:\PROGRAM FILES (X86)\ADOBE\ACROBAT 7.0\ACROBAT ELEMENTS\CONT
EXTMENU.DLL
[1BA6D822A6BA2402BC5DF7F65955D3A8][2
225280
]C:\PROGRAM FILES (X86)\ADOBE\ACROBAT 7.0\ACROBAT\ACROIEFAVCLIE
NT.DLL
[42729C3DE75A7A51FC6F9EF6546C9199][1
63136
]C:\PROGRAM FILES (X86)\ADOBE\ACROBAT 7.0\ACTIVEX\ACROIEHELPER.
DLL
[FBD06A45DB2D543EFD932768029EC5F2][2
483328
]C:\PROGRAM FILES (X86)\ADOBE\ACROBAT 7.0\DISTILLR\ACROTRAY.EXE
[6D182C31ACF16213407F2768F1107FE3][2
69632
]C:\PROGRAM FILES (X86)\COMMON FILES\ADOBE SYSTEMS SHARED\SERVI
CE\ADOBELMSVC.EXE
[4EAF6F8F0B3BE33A0E3877EB7FFD48D4][1
1085656 7224E3586E6576C071A6141F307
3A831734B08D4
]C:\PROGRAM FILES (X86)\COMMON FILES\ADOBE\ARM\1.0\ADOBEARM.EXE
[F2CEEE9ABBCEF207ACB103215AC28BC2][1
82128 54684ACD69CF8CC3649993A5DB2
953330E5601F4
]C:\PROGRAM FILES (X86)\COMMON FILES\ADOBE\ARM\1.0\ARMSVC.EXE
[320681DF28D82CDCA7E3EED0846625DB][1
444904
]C:\PROGRAM FILES (X86)\COMMON FILES\ADOBE\OOBE\PDAPP\UWA\UPDAT
ERSTARTUPUTILITY.EXE
[B17404D208C4B20518592AA43B81E04B][1
927256 C532678DA39D5C3E8BD8D042E2E
755DAAE5DBF18
]C:\PROGRAM FILES (X86)\COMMON FILES\JAVA\JAVA UPDATE\JUCHECK.E
XE
[C9B67BCB8E384064A8C2263740B0C437][1
595480 D895994F5DA9D4827389A9A9113
3D11A5F9CC9A7
]C:\PROGRAM FILES (X86)\COMMON FILES\JAVA\JAVA UPDATE\JUSCHED.E
XE
[8669BE94F63944E4F899C3950B520241][1
1045256
]C:\PROGRAM FILES (X86)\COMMON FILES\MACROVISION SHARED\FLEXNET
PUBLISHER\FNPLICENSINGSERVICE.EXE
[14C405B807A341B60683FE1D5ED65380][1
255256 AA2F0010598E131AEA6F721A0E6
B2B60BB8EB51E
]C:\PROGRAM FILES (X86)\COMMON FILES\MATERIALISE\LICENSEFILES\L
ICSRV50.EXE
[9E7370CC3D6A43942433F85D0E2BBDD8][1
873216
]C:\PROGRAM FILES (X86)\COMMON FILES\MICROSOFT SHARED\HELP\HXDS
.DLL
[84DE1DD996B48B05ACE31AD015FA108A][1
441136
]C:\PROGRAM FILES (X86)\COMMON FILES\MICROSOFT SHARED\OFFICE12\
ODSERV.EXE
[5A432A042DAE460ABE7199B758E8606C][1
145184
]C:\PROGRAM FILES (X86)\COMMON FILES\MICROSOFT SHARED\SOURCE EN
GINE\OSE.EXE
[FAEAFD0BEBFB2B5E938B29C8A155B807][1
2487192
]C:\PROGRAM FILES (X86)\COMMON FILES\NERO\NEROSHELLEXT\NEROSHEL
LEXT.DLL
[DE77A8DA45F91629EB5FC157FA00C08A][1
904248
]C:\PROGRAM FILES (X86)\COMMON FILES\VMWARE\USB\VMWARE-USBARBIT
RATOR64.EXE
[42E4E281D9646F15E5C4D0CFD61CE684][1
2020192
]C:\PROGRAM FILES (X86)\COMMON FILES\WONDERSHARE\WONDERSHARE HE
LPER COMPACT\WSHELPER.EXE
[275F70AF9857755E0440137FB3A6D2C8][2
6983168
]C:\PROGRAM FILES (X86)\FREE DOWNLOAD MANAGER\FDM.EXE
[E65C21C50283C47852D7A3B677CFA00E][2
365056 CCD5F6BC196EB1DD6CB886A5D5C
5E55F61BE6C95
]C:\PROGRAM FILES (X86)\FREE DOWNLOAD MANAGER\IEFDM2.DLL
[51667022FACBD1AA611373DA16C98533][1
748872 A1E2B2EC38DACA805AE0E963E96
D4E34916DD179
]C:\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE
[329D828599BE8859DDC81F866019B2F0][1
2511384
]C:\PROGRAM FILES (X86)\GOOGLE\GOOGLE INPUT TOOLS\GOOGLEINPUTHA
NDLER.EXE
[78AF384F14F01009EFB10A31AFEC51F4][1
164888
]C:\PROGRAM FILES (X86)\GOOGLE\GOOGLE INPUT TOOLS\GOOGLEINPUTSE
RVICE.EXE
[88FBBB1C601A6BC42054E57C2897FA45][1
144200 E025A9721B37725E6DC6E069A93
35239437B3E7C
]C:\PROGRAM FILES (X86)\GOOGLE\UPDATE\GOOGLEUPDATE.EXE
[328E65035DE1D2C1206B4F94AAFC1DB7][1
118424 76AE3743F21954D176FFC013F9D
62A4AE0CBA76C
]C:\PROGRAM FILES (X86)\INTEL DRIVER UPDATE UTILITY\SUR\SURSVC.
EXE
[E7859BA062DB5E23C6DD34AD66B09F50][1
326168
]C:\PROGRAM FILES (X86)\INTEL\INTEL(R) MANAGEMENT ENGINE COMPON
ENTS\LMS\LMS.EXE
[E91F8AFBD7FB96C94B266579D6BFA77A][1
2656280
]C:\PROGRAM FILES (X86)\INTEL\INTEL(R) MANAGEMENT ENGINE COMPON
ENTS\UNS\UNS.EXE
[D2E3E6D94A9E1CFA1561D9C748136FD0][1
152392
]C:\PROGRAM FILES (X86)\ITUNES\ITUNESHELPER.EXE
[56748C769C10A379719A2C9D93AFEA6B][1
173120 3128CD586EC9739AAF44F5F6DEF
0C6F8289F3829
]C:\PROGRAM FILES (X86)\JAVA\JRE1.8.0_77\BIN\JP2SSV.DLL
[B7483C4236E990A3C7F5A3ABEE5C1417][1
462400 D2FF9AC6537EB6FC0C9917E769B
2471F3BFF56CF
]C:\PROGRAM FILES (X86)\JAVA\JRE1.8.0_77\BIN\SSV.DLL
[32E3661326D84A06C4E9380A310B01B7][2
31016 5781B226EA791711FE7615AB75C
C304CEF7C65EA
]C:\PROGRAM FILES (X86)\MICROSOFT OFFICE\OFFICE12\GROOVEMONITOR
.EXE
[F7CEB1E5F0000FDEEE04B046BBDE1D4E][1
377000 D25AD5468157CA05C2BB30D7D5C
EE745ADDB8A88
]C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\FIREFOX.EXE
[31A94358EF55B871B1B81ADE3ACEBFF9][1
148136 C7631EAF245DB2C86ABE09C8C62
C07CE433061A6
]C:\PROGRAM FILES (X86)\MOZILLA MAINTENANCE SERVICE\MAINTENANCE
SERVICE.EXE
[AE2A8DC5C08AE6A198D5EC47561C0DEF][1
336952
]C:\PROGRAM FILES (X86)\POWERISO\PWRISOVM.EXE
[08E7173D1B74095335052459200CB1EA][2
421888
]C:\PROGRAM FILES (X86)\QUICKTIME\QTTASK.EXE
[E7062DBD907E0C5CEEB5ABDAF07E6B32][1
1646056
]C:\PROGRAM FILES (X86)\ROSETTASTONELTDSERVICES\ROSETTASTONEDAE
MON.EXE
[D3F78E38C39AB0E7358735717FB52EAE][1
1563440
]C:\PROGRAM FILES (X86)\SAMSUNG\KIES\KIES.EXE
[EB1B7B961090A4AF33FC297516B88FAE][1
310064
]C:\PROGRAM FILES (X86)\SAMSUNG\KIES\KIESTRAYAGENT.EXE
[
-2][0
-1
]C:\PROGRAM FILES (X86)\SAVEPASS 1.1\6012184B-F747-477B-804F-54
428B83A7EF-5.EXE
[89CACBC5A5D9F14AD11F09D1DE49294E][1
457088 08097C91EB38AB04C4F4064075B
D87994509B226
]C:\PROGRAM FILES (X86)\SONY\SONY PC COMPANION\PCCOMPANION.EXE
[AA1600118E222FCBE3F3BFEC1ABEC309][1
113024 67499777C8A605764BB54106035
38CAA14C95B30
]C:\PROGRAM FILES (X86)\SONY\SONY PC COMPANION\PCCOMPANIONINFO.
EXE
[21FF393512F51F5A98620C794B4488A3][1
155520 07C6DDE2F2EC2C36CBADF4EF2FF
E7EDAA036AD0B
]C:\PROGRAM FILES (X86)\SONY\SONY PC COMPANION\PCCSERVICE.EXE
[E99CD4524662A2DA7C73372C626669D8][1
5261584 D99EC6DD216976017C945F5EC96
3E27694FE75BE
]C:\PROGRAM FILES (X86)\TEAMVIEWER\VERSION9\TEAMVIEWER_SERVICE.
EXE
[515377905CC9A2EB0E585DD9AB457722][1
592656 21EF1C0A2FD3E137D246CFD6B7B
80206E19C9F65
]C:\PROGRAM FILES (X86)\UNHACKME\HACKMON.EXE
[A597D3A1073271330191EE30046C121A][1
10342712 9D2658D05059F15B2BD794F016D
18B5CD70868FB
]C:\PROGRAM FILES (X86)\UNHACKME\REANIMATOR.EXE
[5598A08634A309A64F9DD3C67B29FE28][2
1232212 A7E3215D1FD8B8F0D68C4386F54
2D97591547222
]C:\PROGRAM FILES (X86)\UNHACKME\UNHACKME.EXE
[83C92F09C507BF8C2E2BED71F7B04A29][1
86096
]C:\PROGRAM FILES (X86)\VMWARE\VMWARE WORKSTATION\VMWARE-AUTHD.
EXE
[86661538E9002DA465C8456A962180C8][1
14401104
]C:\PROGRAM FILES (X86)\VMWARE\VMWARE WORKSTATION\VMWARE-HOSTD.
EXE
[E80335157A225AD734865ADF1F929FFB][1
111696 87C522D79229DD7C5545C503DB0
ECA998CB08AB6
]C:\PROGRAM FILES (X86)\VMWARE\VMWARE WORKSTATION\VMWARE-TRAY.E
XE
[0978D90C8B61F73E926F7194CBCA331C][1
270704
]C:\PROGRAM FILES (X86)\WESTERN DIGITAL\WD DRIVE MANAGER\WDDRIV
ESERVICE.EXE
[BF1DE0D0A36B68A0D3ADC7ECEE0BF6AA][2
5537136 4E04F47CC0548D827FB41E098D7
AC867644554E7
]C:\PROGRAM FILES (X86)\WESTERN DIGITAL\WD QUICK VIEW\WDDMSTATU
S.EXE
[DEE16AB97AFB535329D0D0BE3F5929CE][1
1042808
]C:\PROGRAM FILES (X86)\WESTERN DIGITAL\WD SMARTWARE\WDBACKUPEN
GINE.EXE
[A9F3BFC9345F49614D5859EC95B9E994][6
1525248
]C:\PROGRAM FILES (X86)\WINDOWS MEDIA PLAYER\WMPNETWK.EXE
[B3DD214F23037E3D3C27D6C9447B40B5][1
4247040
]C:\PROGRAM FILES (X86)\WINDOWS NT\ACCESSORIES\WORDPAD.EXE
[33683C85592842A1505723C024056469][2
50688 9DB1CAD4F8A0AD4CFEB0A2D5A97
BB37013E3D788
]C:\PROGRAM FILES (X86)\WORDWEB\WCAPTUREMOZ\COMPONENTS\\WCAPTUR
EXPCOM.DLL
[FD73314789BBDA1FFE76FFDF350D6C09][2
148564 4E4BB606EF3C08BF5FBA4BD1CC4
DA09238672969
]C:\PROGRAM FILES (X86)\WORDWEB\WCXCHROME.CRX
[C42EDED9E707ABDD455BB27FBD72416F][1
65216
]C:\PROGRAM FILES (X86)\WORDWEB\WWEB32.EXE
[6C112DA6C86DB7FB2C50522EFDDA706A][1
337776 B1CE6D21C364A52DFE8E6D0688F
2387D52E585CA
]C:\PROGRAM FILES\COMMON FILES\PROTEXIS\LICENSE SERVICE\PSISERV
ICE_2.EXE
[52C696180AC8371163B268D648DCBDA5][1
416408 07705313E258656850851F2A09A
03F416260966E
]C:\PROGRAM FILES\INTEL\SUR\WILLAMETTE\ESRV\ESRV_SVC.EXE
[EA8386CA87165460D39A1D29FF11080B][1
809680
]C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
[835FC2EA0631B734BB06C12B0665F01D][1
641352
]C:\PROGRAM FILES\IPOD\BIN\IPODSERVICE.EXE
[C6D099464B629CE0DEAAEA791A8A8FCB][2
87040 9E8971F8DCF29645FC05B5BF9D4
797B495AD1306
]C:\PROGRAM FILES\LENOVO\LENOVO MOUSE SUITE\ICO.EXE
[9590E5FAFB67C9842F5EEDD41348F16F][2
178688 1FA5C0B52F5D8C581DE120EEE89
18788FC7DAB7A
]C:\PROGRAM FILES\LENOVO\LENOVO MOUSE SUITE\PELSERVICE.EXE
[D0E79ECFF4D7EF9F1A6C3317E14D6700][2
384512 4BF52D1CABF846B40B30B938B52
4DBB6A2EA6FD0
]C:\PROGRAM FILES\LENOVO\LENOVO SLIM USB KEYBOARD\SKD8821.EXE
[DA7CC6A3F969BBC5959AC88A8D46A5A3][2
137216
]C:\PROGRAM FILES\LENOVO\LENOVO SLIM USB KEYBOARD\SKS8821.EXE
[7CBB1D4D13DC62D7F529D87151FD3CD3][1
1011712
]C:\PROGRAM FILES\WINDOWS DEFENDER\MPSVC.DLL
[29E08F1970B681EBC3B0082D1654CF49][1
274520 F908C4061EDAD0E85B5578D9A20
65E6B8BD8C081
]C:\PROGRAM FILES\WINRAR\RAREXT32.DLL
[DC0D82C65E73BC03601E73F1367248FE][1
12144
]C:\PROGRAM FILES\WINZIP\WZSHLSTB.DLL
[
-2][0
-1
]C:\PROGRAMDATA\{415F24E7-9D9E-594E-415F-F24E79D9939E}\SETUP_PR
ODUCT_18129.EXE
[5137E8DE77B3185EC0B164A3AB9D58B9][1
2752960 2E6BC185359679D6E1A8E9BCFB5
4ADBBC5828D71
]C:\PROGRAMDATA\AVG_UPDATE_0615TB\0615TB_{64222B53-94A6-4D8F-A7
00-11BD2ACB2FBE}.EXE
[D2D91B5F04852D50142D95BB9BB69310][1
691280 F6DCA60AC27EB1CDA41DCEF368E
02EBBC7FE2545
]C:\PROGRAMDATA\FREE DOWNLOAD MANAGER\FIREFOX\EXTENSIONS\2.1.4\
FDMBROWSERHELPER.EXE
[
-2][0
-1
]C:\PROGRAMDATA\RESULTS HUB\RESULTSHUBDESKTOPSEARCH.EXE
[FF1CA44FEDCA271E314AA63692D341A6][1
1179680 F9BB919DDD07587EDB533151AAF
42DDBBE7BD71C
]C:\USERS\ADMIN\APPDATA\LOCAL\MALWAREPROTECTIONLIVE\MALWAREPROT
ECTIONCLIENT.EXE
[
-2][0
-1
]C:\USERS\ADMIN\APPDATA\LOCAL\TEMP\SWLFILES\SMILEYSWELOVETOOLBA
R.CRX
[4A270804DC8AB72DCB4F694D050A3517][1
4019696 D9DFE57B327A89916C804CD5CBF
E46B0532C59A4
]C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\P2448C
P5.DEFAULT\EXTENSIONS\{2D3FBCF7-BE69-4433-8858-C621A8D0E58D}\PLUGINS\\NPWIDEVINE
MEDIAOPTIMIZER.DLL
[611931B3E5CC24A91B8C996A8DCD59BE][2
10146890
]C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\P2448C
P5.DEFAULT\EXTENSIONS\[email protected]\MODULES\FFMPEG\\AVCODEC-55.DLL
[A7509D205D44F1FB41C5663EB3A9FE0F][2
1158947
]C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\P2448C
P5.DEFAULT\EXTENSIONS\[email protected]\MODULES\FFMPEG\\AVFILTER-3.DLL
[800163D5F4F67EC29D5685699B695B66][2
2134348
]C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\P2448C
P5.DEFAULT\EXTENSIONS\[email protected]\MODULES\FFMPEG\\AVFORMAT-55.DLL
[F59359C9B82E31CDF93183537EFB4E56][2
542107
]C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\P2448C
P5.DEFAULT\EXTENSIONS\[email protected]\MODULES\FFMPEG\\AVUTIL-52.DLL
[9823CF08B8322478E384A6FB08638B9C][2
428889
]C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\P2448C
P5.DEFAULT\EXTENSIONS\[email protected]\MODULES\FFMPEG\\FFMPEG.EXE
[3BAF8E1C73BC5CBED77D98BE6BFA504F][2
159175
]C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\P2448C
P5.DEFAULT\EXTENSIONS\[email protected]\MODULES\FFMPEG\\SWRESAMPLE-0.DLL
[
-2][0
-1
]C:\USERS\ADMIN\APPDATA\ROAMING\UPDATE~1\UPDATE~1\UPDATE~1.EXE
[3916505B50FB7002FC0CA59E81C4C4F2][2
1078784 16BF8E86CBF081D501AC52AF5AA
82A01EA507E46
]C:\USERS\ADMIN\DOWNLOADS\SCI_AGENT_SETUP(2).EXE
[24B13133A4AC2FF48BA02EB10990A08D][1
1046344 E06C71A8A7E29DD188282DE043F
3F9B9070D5021
]C:\WINDOWS\DOWNLOADED PROGRAM FILES\ALTTIFF.OCX
[C4002B6B41975F057D98C439030CEA07][1
696832
]C:\WINDOWS\EHOME\EHRECVR.EXE
[4705E8EF9934482C5BB488CE28AFC681][1
127488
]C:\WINDOWS\EHOME\EHSCHED.EXE
[AC4C51EB24AA95B77F705AB159189E24][6
2872320
]C:\WINDOWS\EXPLORER.EXE
[0A9C8038265E0B8CF921892B9469B6B2][2
188928
]C:\WINDOWS\FIXCAMERA.EXE
[D6294D59171AC375CD142003566AA89E][2
25214
]C:\WINDOWS\INSTALLER\{AC76BA86-1033-0000-7760-000000000002}\SC
_ACROBAT.EXE
[D88040F816FDA31C3B466F0FA0918F29][1
66384
]C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V2.0.50727\MSCORSVW.EXE
[6D7C8A951AF6AD6835C029B3CB88D333][1
104912
]C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V4.0.30319\MSCORSVW.EXE
[D1CEEA2B47CB998321C579651CE3E4F8][1
89920
]C:\WINDOWS\MICROSOFT.NET\FRAMEWORK64\V2.0.50727\MSCORSVW.EXE
[5988FC40F8DB5B0739CD1E3A5D0D78BD][1
856400
]C:\WINDOWS\MICROSOFT.NET\FRAMEWORK64\V3.0\WINDOWS COMMUNICATIO
N FOUNDATION\INFOCARD.EXE
[A8B7F3818AB65695E3A0BB3279F6DCE6][1
42856
]C:\WINDOWS\MICROSOFT.NET\FRAMEWORK64\V3.0\WPF\PRESENTATIONFONT
CACHE.EXE
[108FB6DDB69E537A2EA53F425363FAE5][1
51648
]C:\WINDOWS\MICROSOFT.NET\FRAMEWORK64\V4.0.30319\ASPNET_STATE.E
XE
[86329C35FF23CFEF0FB6C0023BA06BCE][1
123856
]C:\WINDOWS\MICROSOFT.NET\FRAMEWORK64\V4.0.30319\MSCORSVW.EXE
[5243CFC2E7161C91C2B355240035B9E4][1
139696
]C:\WINDOWS\MICROSOFT.NET\FRAMEWORK64\V4.0.30319\SMSVCHOST.EXE
[773212B2AAA24C1E31F10246B15B276C][1
194048
]C:\WINDOWS\SERVICING\TRUSTEDINSTALLER.EXE
[4ABA3E75A76195A3E38ED2766C962899][1
193536
]C:\WINDOWS\SYSNATIVE\APPMGMTS.DLL
[1A47D52E303B7543E4E6026595B95422][1
1297408
]C:\WINDOWS\SYSNATIVE\COMRES.DLL
[3044D07ABDF4BBEA27E2EE7B1E0C0C65][1
12288
]C:\WINDOWS\SYSNATIVE\D3D8THK.DLL
[A6C09924C6730DE8DEED9890A12AA691][1
569344
]C:\WINDOWS\SYSNATIVE\DDRAW.DLL
[9110FFAD124283F37D38771BB60556AF][1
540672
]C:\WINDOWS\SYSNATIVE\DSOUND.DLL
[3B367397320C26DBA890B260F80D1B1B][1
424448
]C:\WINDOWS\SYSNATIVE\HNETCFG.DLL
[AA2C08CE85653B1A0D2E4AB407FA176C][1
167424
]C:\WINDOWS\SYSNATIVE\IMM32.DLL
[2B81776DA02017A37FE26C662827470E][1
145920
]C:\WINDOWS\SYSNATIVE\IPHLPAPI.DLL
[8560FFFC8EB3A806DCD4F82252CFC8C6][1
5120
]C:\WINDOWS\SYSNATIVE\KSUSER.DLL
[796B47A4B82EF1C39F13435B88834C48][1
41472
]C:\WINDOWS\SYSNATIVE\LPK.DLL
[CA2A0750ED830678997695FF61B04C30][1
20480
]C:\WINDOWS\SYSNATIVE\MIDIMAP.DLL
[C210E0DF28F3B0E5D45F928F08726650][1
8704
]C:\WINDOWS\SYSNATIVE\MSCTFIME.IME
[37D0FB9E5E8EDA40B66FC3FB3D660261][1
23549440
]C:\WINDOWS\SYSNATIVE\MSHTML.DLL
[E424B3EF666B184CEE0B6871AAA8C9F6][1
8192
]C:\WINDOWS\SYSNATIVE\MSIMG32.DLL
[9A9F9F1A77D6A80EE28B57664F00013E][1
327168
]C:\WINDOWS\SYSNATIVE\MSWSOCK.DLL
[58A0CDABEA255616827B1C22C9994466][1
68096
]C:\WINDOWS\SYSNATIVE\NAPINSP.DLL
[2DF36F15B2BC1571A6A542A3C2107920][1
70656
]C:\WINDOWS\SYSNATIVE\NLAAPI.DLL
[613C8CE10A5FDE582BA5FA64C4D56AAA][1
86016
]C:\WINDOWS\SYSNATIVE\PNRPNSP.DLL
[88351B29B622B30962D2FEB6CA8D860B][1
16384
]C:\WINDOWS\SYSNATIVE\RASADHLP.DLL
[019CD868461B646E09BDF04474C19341][1
384512
]C:\WINDOWS\SYSNATIVE\RASAPI32.DLL
[5C627D1B1138676C0A7AB2C2C190D123][1
512000
]C:\WINDOWS\SYSNATIVE\RPCSS.DLL
[ED78427259134C63ED69804D2132B86C][1
232960
]C:\WINDOWS\SYSNATIVE\SCECLI.DLL
[24ACB7E5BE595468E3B9AA488B9B4FCB][6
328704
]C:\WINDOWS\SYSNATIVE\SERVICES.EXE
[09F7401D56F2393C6CA534FF0241A590][1
257024
]C:\WINDOWS\SYSNATIVE\TASKMGR.EXE
[2C353B6CE0C8D03225CAA2AF33B68D79][5
1008640
]C:\WINDOWS\SYSNATIVE\USER32.DLL
[D29E998E8277666982B4F0303BF4E7AF][1
332288
]C:\WINDOWS\SYSNATIVE\UXTHEME.DLL
[88AB9B72B4BF3963A0DE0820B4B0B06C][1
455168
]C:\WINDOWS\SYSNATIVE\WINLOGON.EXE
[2E2072EB48238FCA8FBB7A9F5FABAC45][1
28672
]C:\WINDOWS\SYSNATIVE\WINRNR.DLL
[8396C6C26AADDFE4590CCEF0F419B6B7][1
4608
]C:\WINDOWS\SYSNATIVE\WS2HELP.DLL
[E2FC47E343466505E149108371572EB9][2
28672 7AE684182881903BB8E782AA11E
7140F608D567F
]C:\WINDOWS\SYSTEM32\ACTIVEXRES_CHI.DLL
[1FD70A005C634D4FEF8E3D44567B977A][2
32768 A105D954581D9BBE3A9F132E40E
76DB95BD87E12
]C:\WINDOWS\SYSTEM32\ACTIVEXRES_ENG.DLL
[ED730D791CB026146F9FB8EFB15201B7][1
55432
]C:\WINDOWS\SYSTEM32\ADOBEPDF.DLL
[4B78B431F225FD8624C5655CB1DE7B61][1
72192
]C:\WINDOWS\SYSTEM32\AELUPSVC.DLL
[3290D6946B5E30E70414990574883DDB][1
79360
]C:\WINDOWS\SYSTEM32\ALG.EXE
[0BC381A15355A3982216F7172F545DE1][1
32256
]C:\WINDOWS\SYSTEM32\APPIDSVC.DLL
[9D2A2369AB4B08A4905FE72DB104498F][1
70144
]C:\WINDOWS\SYSTEM32\APPINFO.DLL
[4ABA3E75A76195A3E38ED2766C962899][1
193536
]C:\WINDOWS\SYSTEM32\APPMGMTS.DLL
[F23FEF6D569FCE88671949894A8BECF1][1
679424
]C:\WINDOWS\SYSTEM32\AUDIOSRV.DLL
[A6BF31A71B409DFA8CAC83159E1E2AFF][1
114688
]C:\WINDOWS\SYSTEM32\AXINSTSV.DLL
[FDE360167101B4E45A96F939F388AEB0][1
100864
]C:\WINDOWS\SYSTEM32\BDESVC.DLL
[82974D6A2FD19445CC5171FC378668A4][1
705024
]C:\WINDOWS\SYSTEM32\BFE.DLL
[05F5A0D14A2EE1D8255C2AA0E9E8E694][1
136704
]C:\WINDOWS\SYSTEM32\BROWSER.DLL
[95F9C2976059462CBBF227F7AAB10DE9][1
83968
]C:\WINDOWS\SYSTEM32\BTHSERV.DLL
[D8891208401903CE11A85BF406EBE771][2
214528
]C:\WINDOWS\SYSTEM32\BZPDF.DLL
[5F6C6FFF1ECEBA3E8E2C268674C16591][2
57344 2DD9303369935AC0A94110C959C
2063F9FBCB61F
]C:\WINDOWS\SYSTEM32\CALENDAR.OCX
[F17D1D393BBC69C5322FBFAFACA28C7F][1
80384
]C:\WINDOWS\SYSTEM32\CERTPROP.DLL
[FE1EC06F2253F691FE36217C592A0206][1
367696
]C:\WINDOWS\SYSTEM32\CLFS.SYS
[113E274E5A67A93EE8A3D143F566454E][1
58880
]C:\WINDOWS\SYSTEM32\CNAB4LMD.DLL
[6B400F211BEE880A37A1ED0368776BF4][1
184320
]C:\WINDOWS\SYSTEM32\CRYPTSVC.DLL
[3AB183AB4D2C79DCF459CD2C1266B043][1
692224
]C:\WINDOWS\SYSTEM32\CSCSVC.DLL
[3CEC7631A84943677AA8FA8EE5B6B43D][1
291328
]C:\WINDOWS\SYSTEM32\DEFRAGSVC.DLL
[43D808F5D9E1A18E5EEB5EBC83969E4E][1
317952
]C:\WINDOWS\SYSTEM32\DHCPCORE.DLL
[A8EDB86FC2A4D6D1285E4C70384AC35A][1
9728
]C:\WINDOWS\SYSTEM32\DLLHOST.EXE
[16835866AAA693C7D7FCEBA8FFF706E4][1
183296
]C:\WINDOWS\SYSTEM32\DNSRSLVR.DLL
[B1FB3DDCA0FDF408750D5843591AFBC6][1
252416
]C:\WINDOWS\SYSTEM32\DOT3SVC.DLL
[B26F4F737E8F9DF4F31AF6CF31D05820][1
162816
]C:\WINDOWS\SYSTEM32\DPS.DLL
[A87D604AEA360176311474C87A63BB88][1
229888
]C:\WINDOWS\SYSTEM32\DRIVERS\1394OHCI.SYS
[D81D9E70B8A6DD14D42D7B4EFA65D5F2][1
334208
]C:\WINDOWS\SYSTEM32\DRIVERS\ACPI.SYS
[99F8E788246D495CE3794D7E7821D2CA][1
12800
]C:\WINDOWS\SYSTEM32\DRIVERS\ACPIPMI.SYS
[2F6B34B83843F0C5118B63AC634F5BF4][1
491088
]C:\WINDOWS\SYSTEM32\DRIVERS\ADP94XX.SYS
[597F78224EE9224EA1A13D6350CED962][1
339536
]C:\WINDOWS\SYSTEM32\DRIVERS\ADPAHCI.SYS
[E109549C90F62FB570B9540C4B148E54][1
182864
]C:\WINDOWS\SYSTEM32\DRIVERS\ADPU320.SYS
[79059559E89D06E8B80CE2944BE20228][1
497152
]C:\WINDOWS\SYSTEM32\DRIVERS\AFD.SYS
[7ECFF9B22276B73F43A99A15A6094E90][1
60416
]C:\WINDOWS\SYSTEM32\DRIVERS\AGILEVPN.SYS
[608C14DBA7299D8CB6ED035A68A15799][1
61008
]C:\WINDOWS\SYSTEM32\DRIVERS\AGP440.SYS
[5812713A477A3AD7363C7438CA2EE038][1
15440
]C:\WINDOWS\SYSTEM32\DRIVERS\ALIIDE.SYS
[1FF8B4431C353CE385C875F194924C0C][1
15440
]C:\WINDOWS\SYSTEM32\DRIVERS\AMDIDE.SYS
[7024F087CFF1833A806193EF9D22CDA9][1
64512
]C:\WINDOWS\SYSTEM32\DRIVERS\AMDK8.SYS
[1E56388B3FE0D031C44144EB8C4D6217][1
60928
]C:\WINDOWS\SYSTEM32\DRIVERS\AMDPPM.SYS
[6EC6D772EAE38DC17C14AED9B178D24B][1
107904
]C:\WINDOWS\SYSTEM32\DRIVERS\AMDSATA.SYS
[F67F933E79241ED32FF46A4F29B5120B][1
194128
]C:\WINDOWS\SYSTEM32\DRIVERS\AMDSBS.SYS
[1142A21DB581A84EA5597B03A26EBAA0][1
27008
]C:\WINDOWS\SYSTEM32\DRIVERS\AMDXATA.SYS
[4FC6E2C2FC50445450651F42E90CC0BD][1
31968
]C:\WINDOWS\SYSTEM32\DRIVERS\APOWERSOFT_AUDIODEVICE.SYS
[89A69C3F2F319B43379399547526D952][1
61440
]C:\WINDOWS\SYSTEM32\DRIVERS\APPID.SYS
[C484F8CEB1717C540242531DB7845C4E][1
87632
]C:\WINDOWS\SYSTEM32\DRIVERS\ARC.SYS
[019AF6924AEFE7839F61C830227FE79C][1
97856
]C:\WINDOWS\SYSTEM32\DRIVERS\ARCSAS.SYS
[769765CE2CC62867468CEA93969B2242][1
23040
]C:\WINDOWS\SYSTEM32\DRIVERS\ASYNCMAC.SYS
[02062C0B390B7729EDC9E69C680A6F3C][1
24128
]C:\WINDOWS\SYSTEM32\DRIVERS\ATAPI.SYS
[F02E18EFA6CEA4378D3F95CB6F9A3DE4][1
98816 207316C7BC7D80871F030F86BC2
6B4A8FB25EF41
]C:\WINDOWS\SYSTEM32\DRIVERS\AX88772B.SYS
[B5ACE6968304A3900EEB1EBFD9622DF2][1
270848
]C:\WINDOWS\SYSTEM32\DRIVERS\B57ND60A.SYS
[61583EE3C3A17003C4ACD0475646B4D3][1
45056
]C:\WINDOWS\SYSTEM32\DRIVERS\BLBDRIVE.SYS
[6C02A83164F5CC0A262F4199F0871CF5][1
90624
]C:\WINDOWS\SYSTEM32\DRIVERS\BOWSER.SYS
[F09EEE9EDC320B5E1501F749FDE686C8][1
18432
]C:\WINDOWS\SYSTEM32\DRIVERS\BRFILTLO.SYS
[B114D3098E9BDB8BEA8B053685831BE6][1
8704
]C:\WINDOWS\SYSTEM32\DRIVERS\BRFILTUP.SYS
[43BEA8D483BF1870F018E2D02E06A5BD][1
286720
]C:\WINDOWS\SYSTEM32\DRIVERS\BRSERID.SYS
[A6ECA2151B08A09CACECA35C07F05B42][1
47104
]C:\WINDOWS\SYSTEM32\DRIVERS\BRSERWDM.SYS
[B79968002C277E869CF38BD22CD61524][1
14976
]C:\WINDOWS\SYSTEM32\DRIVERS\BRUSBMDM.SYS
[A87528880231C54E75EA7A44943B38BF][1
14720
]C:\WINDOWS\SYSTEM32\DRIVERS\BRUSBSER.SYS
[9DA669F11D1F894AB4EB69BF546A42E8][1
72192
]C:\WINDOWS\SYSTEM32\DRIVERS\BTHMODEM.SYS
[3E5B191307609F7514148C6832BB0842][1
468480
]C:\WINDOWS\SYSTEM32\DRIVERS\BXVBDA.SYS
[B8BD2BB284668C84865658C77574381A][1
92160
]C:\WINDOWS\SYSTEM32\DRIVERS\CDFS.SYS
[F036CE71586E93D94DAB220D7BDF4416][1
147456
]C:\WINDOWS\SYSTEM32\DRIVERS\CDROM.SYS
[D7CD5C4E1B71FA62050515314CFB52CF][1
45568
]C:\WINDOWS\SYSTEM32\DRIVERS\CIRCLASS.SYS
[0840155D0BDDF1190F84A663C284BD33][1
17664
]C:\WINDOWS\SYSTEM32\DRIVERS\CMBATT.SYS
[E19D3F095812725D88F9001985B94EDD][1
17488
]C:\WINDOWS\SYSTEM32\DRIVERS\CMDIDE.SYS
[EBF28856F69CF094A902F884CF989706][1
458712
]C:\WINDOWS\SYSTEM32\DRIVERS\CNG.SYS
[102DE219C3F61415F964C88E9085AD14][1
21584
]C:\WINDOWS\SYSTEM32\DRIVERS\COMPBATT.SYS
[03EDB043586CCEBA243D689BDDA370A8][1
38912
]C:\WINDOWS\SYSTEM32\DRIVERS\COMPOSITEBUS.SYS
[1C827878A998C18847245FE1F34EE597][1
24144
]C:\WINDOWS\SYSTEM32\DRIVERS\CRCDISK.SYS
[54DA3DFD29ED9F1619B6F53F3CE55E49][1
514560
]C:\WINDOWS\SYSTEM32\DRIVERS\CSC.SYS
[9BB2EF44EAA163B29C4A4587887A0FE4][1
102400
]C:\WINDOWS\SYSTEM32\DRIVERS\DFSC.SYS
[13096B05847EC78F0977F2C0F79E9AB3][1
40448
]C:\WINDOWS\SYSTEM32\DRIVERS\DISCACHE.SYS
[9819EEE8B5EA3784EC4AF3B137A5244C][1
73280
]C:\WINDOWS\SYSTEM32\DRIVERS\DISK.SYS
[9B19F34400D24DF84C858A421C205754][1
5632
]C:\WINDOWS\SYSTEM32\DRIVERS\DRMKAUD.SYS
[88612F1CE3BF42256913BF6E61C70D52][1
983488
]C:\WINDOWS\SYSTEM32\DRIVERS\DXGKRNL.SYS
[0E5DA5369A0FCAEA12456DD852545184][1
530496
]C:\WINDOWS\SYSTEM32\DRIVERS\ELXSTOR.SYS
[34A3C54752046E79A126E15C51DB409B][1
9728
]C:\WINDOWS\SYSTEM32\DRIVERS\ERRDEV.SYS
[DC5D737F51BE844D8C82C695EB17372F][1
3286016
]C:\WINDOWS\SYSTEM32\DRIVERS\EVBDA.SYS
[D765D19CD8EF61F650C384F62FAC00AB][1
29696
]C:\WINDOWS\SYSTEM32\DRIVERS\FDC.SYS
[655661BE46B5F5F3FD454E2C3095B930][1
70224
]C:\WINDOWS\SYSTEM32\DRIVERS\FILEINFO.SYS
[5F671AB5BC87EEA04EC38A6CD5962A47][1
34304
]C:\WINDOWS\SYSTEM32\DRIVERS\FILETRACE.SYS
[C172A0F53008EAEB8EA33FE10E177AF5][1
24576
]C:\WINDOWS\SYSTEM32\DRIVERS\FLPYDISK.SYS
[DA6B67270FD9DB3697B20FCE94950741][1
289664
]C:\WINDOWS\SYSTEM32\DRIVERS\FLTMGR.SYS
[D43703496149971890703B4B1B723EAC][1
55376
]C:\WINDOWS\SYSTEM32\DRIVERS\FSDEPENDS.SYS
[1F7B25B858FA27015169FE95E54108ED][1
223248
]C:\WINDOWS\SYSTEM32\DRIVERS\FVEVOL.SYS
[8C778D335C9D272CFD3298AB02ABE3B6][1
65088
]C:\WINDOWS\SYSTEM32\DRIVERS\GAGP30KX.SYS
[8E98D21EE06192492A5671A6144D092F][1
33240
]C:\WINDOWS\SYSTEM32\DRIVERS\GEARASPIWDM.SYS
[A1F556318931B9EA276F4E2DA2C1791C][1
16088
]C:\WINDOWS\SYSTEM32\DRIVERS\GGFLT.SYS
[7F56A3E09A6AD40B07E4EFAD34A40A18][1
30424
]C:\WINDOWS\SYSTEM32\DRIVERS\GGSOMC.SYS
[23AF3730B7B757A385721E900250CF3B][1
53816
]C:\WINDOWS\SYSTEM32\DRIVERS\HCMON.SYS
[F2523EF6460FC42405B12248338AB2F0][1
31232
]C:\WINDOWS\SYSTEM32\DRIVERS\HCW85CIR.SYS
[97BFED39B6B79EB12CDDBFEED51F56BB][1
122368
]C:\WINDOWS\SYSTEM32\DRIVERS\HDAUDBUS.SYS
[975761C778E33CD22498059B91E7373A][1
350208
]C:\WINDOWS\SYSTEM32\DRIVERS\HDAUDIO.SYS
[A6518DCC42F7A6E999BB3BEA8FD87567][1
56344
]C:\WINDOWS\SYSTEM32\DRIVERS\HECIX64.SYS
[45540DAE98ED8E6C5376F616D8D5547C][1
19560 BD0528C0C3251B3BDC6086DFAF5
2F5FE10201390
]C:\WINDOWS\SYSTEM32\DRIVERS\HHDSERHELP.SYS
[2C3D7F56BA751941D0E7DA16934FBB5D][1
39016 8B0465CFE2F991FD7EB79D607A8
BF41A7F41E7F8
]C:\WINDOWS\SYSTEM32\DRIVERS\HHDSERIAL64.SYS
[78E86380454A7B10A5EB255DC44A355F][1
26624
]C:\WINDOWS\SYSTEM32\DRIVERS\HIDBATT.SYS
[7FD2A313F7AFE5C4DAB14798C48DD104][1
100864
]C:\WINDOWS\SYSTEM32\DRIVERS\HIDBTH.SYS
[0A77D29F311B88CFAE3B13F9C1A73825][1
46592
]C:\WINDOWS\SYSTEM32\DRIVERS\HIDIR.SYS
[9592090A7E2B61CD582B612B6DF70536][1
30208
]C:\WINDOWS\SYSTEM32\DRIVERS\HIDUSB.SYS
[39D2ABCD392F3D8A6DCE7B60AE7B8EFC][1
78720
]C:\WINDOWS\SYSTEM32\DRIVERS\HPSAMD.SYS
[0EA7DE1ACB728DD5A369FD742D6EEE28][1
753664
]C:\WINDOWS\SYSTEM32\DRIVERS\HTTP.SYS
[A5462BD6884960C9DC85ED49D34FF392][1
14720
]C:\WINDOWS\SYSTEM32\DRIVERS\HWPOLICY.SYS
[FA55C73D4AFFA7EE23AC4BE53B4592D3][1
105472
]C:\WINDOWS\SYSTEM32\DRIVERS\I8042PRT.SYS
[3DF4395A7CF8B7A72A5F4606366B8C2D][1
410496
]C:\WINDOWS\SYSTEM32\DRIVERS\IASTORV.SYS
[5C18831C61933628F5BB0EA2675B9D21][1
44112
]C:\WINDOWS\SYSTEM32\DRIVERS\IIRSP.SYS
[A9771DB91E5F9B55FC8F305960875ACD][2
28672 14BA6886A454C5F37E12B1E2344
A101479ABB35F
]C:\WINDOWS\SYSTEM32\DRIVERS\InstallSadpNpfApp.exe
[F00F20E70C6EC3AA366910083A0518AA][1
16960
]C:\WINDOWS\SYSTEM32\DRIVERS\INTELIDE.SYS
[ADA036632C664CAA754079041CF1F8C1][1
62464
]C:\WINDOWS\SYSTEM32\DRIVERS\INTELPPM.SYS
[C9F0E1BD74365A8771590E9008D22AB6][1
82944
]C:\WINDOWS\SYSTEM32\DRIVERS\IPFLTDRV.SYS
[0FC1AEA580957AA8817B8F305D18CA3A][1
78848
]C:\WINDOWS\SYSTEM32\DRIVERS\IPMIDRV.SYS
[AF9B39A7E7B6CAA203B3862582E9F2D0][1
116224
]C:\WINDOWS\SYSTEM32\DRIVERS\IPNAT.SYS
[3ABF5E7213EB28966D55D58B515D5CE9][1
17920
]C:\WINDOWS\SYSTEM32\DRIVERS\IRENUM.SYS
[2F7B28DC3E1183E5EB418DF55C204F38][1
20544
]C:\WINDOWS\SYSTEM32\DRIVERS\ISAPNP.SYS
[BC02336F1CBA7DCC7D1213BB588A68A5][1
50768
]C:\WINDOWS\SYSTEM32\DRIVERS\KBDCLASS.SYS
[0705EFF5B42A9DB58548EEC3B26BB484][1
33280
]C:\WINDOWS\SYSTEM32\DRIVERS\KBDHID.SYS
[353009DEDF918B2A51414F330CF72DEC][1
95680
]C:\WINDOWS\SYSTEM32\DRIVERS\KSECDD.SYS
[1C2D8E18AA8FD50CD04C15CC27F7F5AB][1
155072
]C:\WINDOWS\SYSTEM32\DRIVERS\KSECPKG.SYS
[6869281E78CB31A43E969F06B57347C4][1
20992
]C:\WINDOWS\SYSTEM32\DRIVERS\KSTHUNK.SYS
[1538831CF8AD2979A04C423779465827][1
60928
]C:\WINDOWS\SYSTEM32\DRIVERS\LLTDIO.SYS
[1A93E54EB0ECE102495A51266DCDB6A6][1
114752
]C:\WINDOWS\SYSTEM32\DRIVERS\LSI_FC.SYS
[1047184A9FDC8BDBFF857175875EE810][1
106560
]C:\WINDOWS\SYSTEM32\DRIVERS\LSI_SAS.SYS
[30F5C0DE1EE8B5BC9306C1F0E4A75F93][1
65600
]C:\WINDOWS\SYSTEM32\DRIVERS\LSI_SAS2.SYS
[0504EACAFF0D3C8AED161C4B0D369D4A][1
115776
]C:\WINDOWS\SYSTEM32\DRIVERS\LSI_SCSI.SYS
[43D0F98E1D56CCDDB0D5254CFF7B356E][1
113152
]C:\WINDOWS\SYSTEM32\DRIVERS\LUAFV.SYS
[A55805F747C6EDB6A9080D7C633BD0F4][1
35392
]C:\WINDOWS\SYSTEM32\DRIVERS\MEGASAS.SYS
[BAF74CE0072480C3B6B7C13B2A94D6B3][1
284736
]C:\WINDOWS\SYSTEM32\DRIVERS\MEGASR.SYS
[800BA92F7010378B09F9ED9270F07137][1
40448
]C:\WINDOWS\SYSTEM32\DRIVERS\MODEM.SYS
[B03D591DC7DA45ECE20B3B467E6AADAA][1
30208
]C:\WINDOWS\SYSTEM32\DRIVERS\MONITOR.SYS
[7D27EA49F3C1F687D357E77A470AEA99][1
49216
]C:\WINDOWS\SYSTEM32\DRIVERS\MOUCLASS.SYS
[D3BF052C40B0C4166D9FD86A4288C1E6][1
31232
]C:\WINDOWS\SYSTEM32\DRIVERS\MOUHID.SYS
[32E7A3D591D671A6DF2DB515A5CBE0FA][1
94592
]C:\WINDOWS\SYSTEM32\DRIVERS\MOUNTMGR.SYS
[A44B420D30BD56E145D6A2BC8768EC58][1
155008
]C:\WINDOWS\SYSTEM32\DRIVERS\MPIO.SYS
[6C38C9E45AE0EA2FA5E551F2ED5E978F][1
77312
]C:\WINDOWS\SYSTEM32\DRIVERS\MPSDRV.SYS
[DC722758B8261E1ABAFD31A3C0A66380][1
140800
]C:\WINDOWS\SYSTEM32\DRIVERS\MRXDAV.SYS
[A5D9106A73DC88564C825D317CAC68AC][1
158208
]C:\WINDOWS\SYSTEM32\DRIVERS\MRXSMB.SYS
[D711B3C1D5F42C0C2415687BE09FC163][1
288768
]C:\WINDOWS\SYSTEM32\DRIVERS\MRXSMB10.SYS
[9423E9D355C8D303E76B8CFBD8A5C30C][1
128000
]C:\WINDOWS\SYSTEM32\DRIVERS\MRXSMB20.SYS
[C25F0BAFA182CBCA2DD3C851C2E75796][1
31104
]C:\WINDOWS\SYSTEM32\DRIVERS\MSAHCI.SYS
[DB801A638D011B9633829EB6F663C900][1
140672
]C:\WINDOWS\SYSTEM32\DRIVERS\MSDSM.SYS
[F9D215A46A8B9753F61767FA72A20326][1
8192
]C:\WINDOWS\SYSTEM32\DRIVERS\MSHIDKMDF.SYS
[D916874BBD4F8B07BFB7FA9B3CCAE29D][1
15424
]C:\WINDOWS\SYSTEM32\DRIVERS\MSISADRV.SYS
[D931D7309DEB2317035B07C9F9E6B0BD][1
273792
]C:\WINDOWS\SYSTEM32\DRIVERS\MSISCSI.SYS
[49CCF2C4FEA34FFAD8B1B59D49439366][1
11136
]C:\WINDOWS\SYSTEM32\DRIVERS\MSKSSRV.SYS
[BDD71ACE35A232104DDD349EE70E1AB3][1
7168
]C:\WINDOWS\SYSTEM32\DRIVERS\MSPCLOCK.SYS
[4ED981241DB27C3383D72092B618A1D0][1
6784
]C:\WINDOWS\SYSTEM32\DRIVERS\MSPQM.SYS
[0EED230E37515A0EAEE3C2E1BC97B288][1
32320
]C:\WINDOWS\SYSTEM32\DRIVERS\MSSMBIOS.SYS
[2E66F9ECB30B4221A318C92AC2250779][1
8064
]C:\WINDOWS\SYSTEM32\DRIVERS\MSTEE.SYS
[7EA404308934E675BFFDE8EDF0757BCD][1
15360
]C:\WINDOWS\SYSTEM32\DRIVERS\MTCONFIG.SYS
[F9A18612FD3526FE473C1BDA678D61C8][1
60496
]C:\WINDOWS\SYSTEM32\DRIVERS\MUP.SYS
[79B47FD40D9A817E932F9D26FAC0A81C][1
951680
]C:\WINDOWS\SYSTEM32\DRIVERS\NDIS.SYS
[9F9A1F53AAD7DA4D6FEF5BB73AB811AC][1
35328
]C:\WINDOWS\SYSTEM32\DRIVERS\NDISCAP.SYS
[30639C932D9FEF22B31268FE25A1B6E5][1
24064
]C:\WINDOWS\SYSTEM32\DRIVERS\NDISTAPI.SYS
[136185F9FB2CC61E573E676AA5402356][1
56832
]C:\WINDOWS\SYSTEM32\DRIVERS\NDISUIO.SYS
[53F7305169863F0A2BDDC49E116C2E11][1
164352
]C:\WINDOWS\SYSTEM32\DRIVERS\NDISWAN.SYS
[86743D9F5D2B1048062B14B1D84501C4][1
44544
]C:\WINDOWS\SYSTEM32\DRIVERS\NETBIOS.SYS
[09594D1089C523423B32A4229263F068][1
261632
]C:\WINDOWS\SYSTEM32\DRIVERS\NETBT.SYS
[98F3ABC312BC0C660BA3F3B47782455E][1
35319
]C:\WINDOWS\SYSTEM32\DRIVERS\NETMD031.sys
[417334447945C9E111FFD881F7BF4D08][1
36232
]C:\WINDOWS\SYSTEM32\DRIVERS\NETMD033.sys
[986ACDECE933131288F1957DC359865F][1
38951
]C:\WINDOWS\SYSTEM32\DRIVERS\NETMDUSB.sys
[77889813BE4D166CDAB78DDBA990DA92][1
51264
]C:\WINDOWS\SYSTEM32\DRIVERS\NFRD960.SYS
[E7F5AE18AF4168178A642A9247C63001][1
24576
]C:\WINDOWS\SYSTEM32\DRIVERS\NSIPROXY.SYS
[270D7CD42D6E3979F6DD0146650F0E05][1
122960
]C:\WINDOWS\SYSTEM32\DRIVERS\NV_AGP.SYS
[5D9FD91F3D38DC9DA01E3CB5FA89CD48][1
148352
]C:\WINDOWS\SYSTEM32\DRIVERS\NVRAID.SYS
[F7CD50FE7139F07E77DA8AC8033D1832][1
166272
]C:\WINDOWS\SYSTEM32\DRIVERS\NVSTOR.SYS
[1EA3749C4114DB3E3161156FFFFA6B33][1
318976
]C:\WINDOWS\SYSTEM32\DRIVERS\NWIFI.SYS
[3589478E4B22CE21B41FA1BFC0B8B8A0][1
72832
]C:\WINDOWS\SYSTEM32\DRIVERS\OHCI1394.SYS
[0557CF5A2556BD58E26384169D72438D][1
131584
]C:\WINDOWS\SYSTEM32\DRIVERS\PACER.SYS
[0086431C29C35BE1DBC43F52CC273887][1
97280
]C:\WINDOWS\SYSTEM32\DRIVERS\PARPORT.SYS
[6DDCF3F801EC15FE698F6A215CF30A1F][1
35816
]C:\WINDOWS\SYSTEM32\DRIVERS\PARTIZAN.SYS
[E9766131EEADE40A27DC27D2D68FBA9C][1
75120
]C:\WINDOWS\SYSTEM32\DRIVERS\PARTMGR.SYS
[94575C0571D1462A0F70BDE6BD6EE6B3][1
184704
]C:\WINDOWS\SYSTEM32\DRIVERS\PCI.SYS
[B5B8B5EF2E5CB34DF8DCF8831E3534FA][1
12352
]C:\WINDOWS\SYSTEM32\DRIVERS\PCIIDE.SYS
[B2E81D4E87CE48589F98CB8C05B01F2F][1
220752
]C:\WINDOWS\SYSTEM32\DRIVERS\PCMCIA.SYS
[D6B9C2E1A11A3A4B26A182FFEF18F603][1
50768
]C:\WINDOWS\SYSTEM32\DRIVERS\PCW.SYS
[68769C3356B3BE5D1C732C97B9A80D6E][1
651264
]C:\WINDOWS\SYSTEM32\DRIVERS\PEAUTH.SYS
[50AD172D2DDF898FC1705199B60C3264][1
23040
]C:\WINDOWS\SYSTEM32\DRIVERS\PELMOUSE.SYS
[ADC5D126ABAB5AB5B806AE32B12125E7][1
34816
]C:\WINDOWS\SYSTEM32\DRIVERS\PELUSBLF.SYS
[0D922E23C041EFB1C3FAC2A6F943C9BF][1
60416
]C:\WINDOWS\SYSTEM32\DRIVERS\PROCESSR.SYS
[A53A15A11EBFD21077463EE2C7AFEEF0][1
1524816
]C:\WINDOWS\SYSTEM32\DRIVERS\QL2300.SYS
[4F6D12B51DE1AAEFF7DC58C4D75423C8][1
128592
]C:\WINDOWS\SYSTEM32\DRIVERS\QL40XX.SYS
[76707BB36430888D9CE9D705398ADB6C][1
46592
]C:\WINDOWS\SYSTEM32\DRIVERS\QWAVEDRV.SYS
[5A0DA8AD5762FA2D91678A8A01311704][1
14848
]C:\WINDOWS\SYSTEM32\DRIVERS\RASACD.SYS
[471815800AE33E6F1C32FB1B97C490CA][1
129536
]C:\WINDOWS\SYSTEM32\DRIVERS\RASL2TP.SYS
[855C9B1CD4756C5E9A2AA58A15F58C25][1
92672
]C:\WINDOWS\SYSTEM32\DRIVERS\RASPPPOE.SYS
[F92A2C41117A11A00BE01CA01A7FCDE9][1
111104
]C:\WINDOWS\SYSTEM32\DRIVERS\RASPPTP.SYS
[E8B1E447B008D07FF47D016C2B0EEECB][1
83968
]C:\WINDOWS\SYSTEM32\DRIVERS\RASSSTP.SYS
[77F665941019A1594D887A74F301FA2F][1
309248
]C:\WINDOWS\SYSTEM32\DRIVERS\RDBSS.SYS
[302DA2A0539F2CF54D7C6CC30C1F2D8D][1
24064
]C:\WINDOWS\SYSTEM32\DRIVERS\RDPBUS.SYS
[CEA6CC257FC9B7715F1C2B4849286D24][1
7680
]C:\WINDOWS\SYSTEM32\DRIVERS\RDPCDD.SYS
[1B6163C503398B23FF8B939C67747683][1
165888
]C:\WINDOWS\SYSTEM32\DRIVERS\RDPDR.SYS
[BB5971A4F00659529A5C44831AF22365][1
7680
]C:\WINDOWS\SYSTEM32\DRIVERS\RDPENCDD.SYS
[216F3FA57533D98E1F74DED70113177A][1
8192
]C:\WINDOWS\SYSTEM32\DRIVERS\RDPREFMP.SYS
[70CBA1A0C98600A2AA1863479B35CB90][1
20992
]C:\WINDOWS\SYSTEM32\DRIVERS\RDPVIDEOMINIPORT.SYS
[
-2][0
-1
]C:\WINDOWS\SYSTEM32\DRIVERS\RDVGKMD.SYS
[34ED295FA0121C241BFEF24764FC4520][1
213888
]C:\WINDOWS\SYSTEM32\DRIVERS\RDYBOOST.SYS
[9C3AC71A9934B884FAC567A8807E9C4D][1
31800
]C:\WINDOWS\SYSTEM32\DRIVERS\REVOFLT.SYS
[DDC86E4F8E7456261E637E3552E804FF][1
76800
]C:\WINDOWS\SYSTEM32\DRIVERS\RSPNDR.SYS
[AC4CA62572CA516945AB92D6C9F501F4][1
888536
]C:\WINDOWS\SYSTEM32\DRIVERS\RT64WIN7.SYS
[B48DC6ABCD3AEFF8618350CCBDC6B09A][1
35088
]C:\WINDOWS\SYSTEM32\DRIVERS\sadp_npf.sys
[351533ACC2A069B94E80BBFC177E8FDF][1
35344
]C:\WINDOWS\SYSTEM32\DRIVERS\sadp_npf64.sys
[AC03AF3329579FFFB455AA2DAABBE22B][1
103808
]C:\WINDOWS\SYSTEM32\DRIVERS\SBP2PORT.SYS
[253F38D0D7074C02FF8DEB9836C97D2B][1
29696
]C:\WINDOWS\SYSTEM32\DRIVERS\SCFILTER.SYS
[07F83829E7429E60298440CD1E601A6A][1
21984 643383938D5E0D4FD30D302AF3E
9293A4798E392
]C:\WINDOWS\SYSTEM32\DRIVERS\SEMAV6MSR64.SYS
[CB624C0035412AF0DEBEC78C41F5CA1B][1
23552
]C:\WINDOWS\SYSTEM32\DRIVERS\SERENUM.SYS
[C1D8E28B2C2ADFAEC4BA89E9FDA69BD6][1
94208
]C:\WINDOWS\SYSTEM32\DRIVERS\SERIAL.SYS
[1C545A7D0691CC4A027396535691C3E3][1
26624
]C:\WINDOWS\SYSTEM32\DRIVERS\SERMOUSE.SYS
[A554811BCD09279536440C964AE35BBF][1
14336
]C:\WINDOWS\SYSTEM32\DRIVERS\SFFDISK.SYS
[FF414F0BAEFEBA59BC6C04B3DB0B87BF][1
13824
]C:\WINDOWS\SYSTEM32\DRIVERS\SFFP_MMC.SYS
[DD85B78243A19B59F0637DCF284DA63C][1
14336
]C:\WINDOWS\SYSTEM32\DRIVERS\SFFP_SD.SYS
[A9D601643A1647211A1EE2EC4E433FF4][1
16896
]C:\WINDOWS\SYSTEM32\DRIVERS\SFLOPPY.SYS
[843CAF1E5FDE1FFD5FF768F23A51E2E1][1
43584
]C:\WINDOWS\SYSTEM32\DRIVERS\SISRAID2.SYS
[6A6C106D42E9FFFF8B9FCB4F754F6DA4][1
80464
]C:\WINDOWS\SYSTEM32\DRIVERS\SISRAID4.SYS
[548260A7B8654E024DC30BF8A7C5BAA4][1
93184
]C:\WINDOWS\SYSTEM32\DRIVERS\SMB.SYS
[7B90D750DCBF72524DD38B105D29F8C1][1
3552512 62E5ADEE4575AF6349BE6482905
3553049863367
]C:\WINDOWS\SYSTEM32\DRIVERS\SNP2UVC.SYS
[441FBA48BFF01FDB9D5969EBC1838F0B][1
467456
]C:\WINDOWS\SYSTEM32\DRIVERS\SRV.SYS
[B4ADEBBF5E3677CCE9651E0F01F7CC28][1
410112
]C:\WINDOWS\SYSTEM32\DRIVERS\SRV2.SYS
[27E461F0BE5BFF5FC737328F749538C3][1
168448
]C:\WINDOWS\SYSTEM32\DRIVERS\SRVNET.SYS
[30710AEFCE721CEEE0F35EB6A01C263C][1
110336
]C:\WINDOWS\SYSTEM32\DRIVERS\SSUDBUS.SYS
[91310683D7B6B292B746D60734B59322][1
206080
]C:\WINDOWS\SYSTEM32\DRIVERS\SSUDMDM.SYS
[B5D5A1846972B7F93BDC6333272D750E][1
206080 7F25C61E6EFA67D6421159129C7
09EEE7A934D16
]C:\WINDOWS\SYSTEM32\DRIVERS\SSUDOBEX.SYS
[F7093A27C4AF6D9EEA0ACAC1C4FF6828][1
206080 23BCA6DAD98AE0EE70725C2AFF6
8240747331098
]C:\WINDOWS\SYSTEM32\DRIVERS\SSUDSERD.SYS
[F3817967ED533D08327DC73BC4D5542A][1
24656
]C:\WINDOWS\SYSTEM32\DRIVERS\STEXSTOR.SYS
[D34E4943D5AC096C8EDEEBFD80D76E23][1
34688
]C:\WINDOWS\SYSTEM32\DRIVERS\STORVSC.SYS
[D01EC09B6711A5F8E7E6564A4D0FBC90][1
12496
]C:\WINDOWS\SYSTEM32\DRIVERS\SWENUM.SYS
[
-2][0
-1
]C:\WINDOWS\SYSTEM32\DRIVERS\SYNTH3DVSC.SYS
[40AF23633D197905F03AB5628C558C51][1
1903552
]C:\WINDOWS\SYSTEM32\DRIVERS\TCPIP.SYS
[DF687E3D8836BFB04FCC0615BF15A519][1
45056
]C:\WINDOWS\SYSTEM32\DRIVERS\TCPIPREG.SYS
[3371D21011695B16333A3934340C4E7C][1
15872
]C:\WINDOWS\SYSTEM32\DRIVERS\TDPIPE.SYS
[51C5ECEB1CDEE2468A1748BE550CFBC8][1
23552
]C:\WINDOWS\SYSTEM32\DRIVERS\TDTCP.SYS
[DDAD5A7AB24D8B65F8D724F5C20FD806][1
119296
]C:\WINDOWS\SYSTEM32\DRIVERS\TDX.SYS
[561E7E1F06895D78DE991E01DD0FB6E5][1
63360
]C:\WINDOWS\SYSTEM32\DRIVERS\TERMDD.SYS
[4CE278FC9671BA81A138D70823FCAA09][1
39936
]C:\WINDOWS\SYSTEM32\DRIVERS\TSSECSRV.SYS
[D11C783E3EF9A3C52C0EBE83CC5000E9][1
59392
]C:\WINDOWS\SYSTEM32\DRIVERS\TSUSBFLT.SYS
[
-2][0
-1
]C:\WINDOWS\SYSTEM32\DRIVERS\TSUSBHUB.SYS
[3566A8DAAFA27AF944F5D705EAA64894][1
125440
]C:\WINDOWS\SYSTEM32\DRIVERS\TUNNEL.SYS
[B4DD609BD7E282BFC683CEC7EAAAAD67][1
64080
]C:\WINDOWS\SYSTEM32\DRIVERS\UAGP35.SYS
[FF4232A1A64012BAA1FD97C7B67DF593][1
328192
]C:\WINDOWS\SYSTEM32\DRIVERS\UDFS.SYS
[4BFE1BC28391222894CBF1E7D0E42320][1
64592
]C:\WINDOWS\SYSTEM32\DRIVERS\ULIAGPKX.SYS
[DC54A574663A895C8763AF0FA1FF7561][1
48640
]C:\WINDOWS\SYSTEM32\DRIVERS\UMBUS.SYS
[B2E8E8CB557B156DA5493BBDDCC1474D][1
9728
]C:\WINDOWS\SYSTEM32\DRIVERS\UMPASS.SYS
[24E8F8C3BDF9CEFC2135F9A3C399F37D][1
12800 9A2A42B8FE27EEF1B0922D99A4E
2EC1F01DE941F
]C:\WINDOWS\SYSTEM32\DRIVERS\UnHackMeDrv.sys
[2C42E595E7E381596B9A14F88F5AE027][1
19968
]C:\WINDOWS\SYSTEM32\DRIVERS\USB80236.SYS
[7B28E2FBE75115660FAB31079C0A9F29][1
19968
]C:\WINDOWS\SYSTEM32\DRIVERS\USB8023X.SYS
[C9E9D59C0099A9FF51697E9306A44240][1
54784
]C:\WINDOWS\SYSTEM32\DRIVERS\USBAAPL64.SYS
[B0435098C81D04CAFFF80DDB746CD3A2][1
109824
]C:\WINDOWS\SYSTEM32\DRIVERS\USBAUDIO.SYS
[DCA68B0943D6FA415F0C56C92158A83A][1
99840
]C:\WINDOWS\SYSTEM32\DRIVERS\USBCCGP.SYS
[80B0F7D5CCF86CEB5D402EAAF61FEC31][1
100864
]C:\WINDOWS\SYSTEM32\DRIVERS\USBCIR.SYS
[18A85013A3E0F7E1755365D287443965][1
53248
]C:\WINDOWS\SYSTEM32\DRIVERS\USBEHCI.SYS
[8D1196CFBB223621F2C67D45710F25BA][1
343040
]C:\WINDOWS\SYSTEM32\DRIVERS\USBHUB.SYS
[765A92D428A8DB88B960DA5A8D6089DC][1
25600
]C:\WINDOWS\SYSTEM32\DRIVERS\USBOHCI.SYS
[73188F58FB384E75C4063D29413CEE3D][1
25088
]C:\WINDOWS\SYSTEM32\DRIVERS\USBPRINT.SYS
[D76510CFA0FC09023077F22C2F979D86][1
91648
]C:\WINDOWS\SYSTEM32\DRIVERS\USBSTOR.SYS
[DD253AFC3BC6CBA412342DE60C3647F3][1
30720
]C:\WINDOWS\SYSTEM32\DRIVERS\USBUHCI.SYS
[1F775DA4CF1A3A1834207E975A72E9D7][1
185344
]C:\WINDOWS\SYSTEM32\DRIVERS\USBVIDEO.SYS
[C5C876CCFC083FF3B128F933823E87BD][1
36432
]C:\WINDOWS\SYSTEM32\DRIVERS\VDRVROOT.SYS
[53E92A310193CB3C03BEA963DE7D9CFC][1
29184
]C:\WINDOWS\SYSTEM32\DRIVERS\VGA.SYS
[DA4DA3F5E02943C2DC8C6ED875DE68DD][1
29184
]C:\WINDOWS\SYSTEM32\DRIVERS\VGAPNP.SYS
[2CE2DF28C83AEAF30084E1B1EB253CBB][1
215936
]C:\WINDOWS\SYSTEM32\DRIVERS\VHDMP.SYS
[E5689D93FFE4E5D66C0178761240DD54][1
17488
]C:\WINDOWS\SYSTEM32\DRIVERS\VIAIDE.SYS
[86EA3E79AE350FEA5331A1303054005F][1
199552
]C:\WINDOWS\SYSTEM32\DRIVERS\VMBUS.SYS
[7DE90B48F210D29649380545DB45A187][1
21760
]C:\WINDOWS\SYSTEM32\DRIVERS\VMBUSHID.SYS
[BE8E5E5D53ACF71D4E8E686B68C99B04][1
85584
]C:\WINDOWS\SYSTEM32\DRIVERS\VMCI.SYS
[18AA5F4A3B1204AD00045EE5AD39BCDB][1
20560
]C:\WINDOWS\SYSTEM32\DRIVERS\VMNETADAPTER.SYS
[04CD4347CD9E8C40F78AD51F7FF426D0][1
46160
]C:\WINDOWS\SYSTEM32\DRIVERS\VMNETBRIDGE.SYS
[748FD60D1B73F50020CFD126F940543F][1
30800
]C:\WINDOWS\SYSTEM32\DRIVERS\VMNETUSERIF.SYS
[7FBB3F1EBB009F9F711B02D599DB1CE6][1
31824 620FBC2EE83E45D320C6F1635BC
22611F2CF1369
]C:\WINDOWS\SYSTEM32\DRIVERS\VMPARPORT.SYS
[E60C0A09F997826C7627B244195AB581][1
6656
]C:\WINDOWS\SYSTEM32\DRIVERS\VMS3CAP.SYS
[7785DC213270D2FC066538DAF94087E7][1
46464
]C:\WINDOWS\SYSTEM32\DRIVERS\VMSTORFL.SYS
[F347A28F63162FF82BDDAADC14935BA4][1
38456 2C0B2D6E8A247DF058116AB4DB4
9F4F927872D16
]C:\WINDOWS\SYSTEM32\DRIVERS\VMUSB.SYS
[CB41CC41F83C9A6081A2AE71251A16D5][1
64080
]C:\WINDOWS\SYSTEM32\DRIVERS\VMX86.SYS
[D2AAFD421940F640B407AEFAAEBD91B0][1
71552
]C:\WINDOWS\SYSTEM32\DRIVERS\VOLMGR.SYS
[A255814907C89BE58B79EF2F189B843B][1
363392
]C:\WINDOWS\SYSTEM32\DRIVERS\VOLMGRX.SYS
[0D08D2F3B3FF84E433346669B5E0F639][1
295808
]C:\WINDOWS\SYSTEM32\DRIVERS\VOLSNAP.SYS
[5E2016EA6EBACA03C04FEAC5F330D997][1
161872
]C:\WINDOWS\SYSTEM32\DRIVERS\VSMRAID.SYS
[108196FE0580A18AB6237EA36FD210F2][1
73296
]C:\WINDOWS\SYSTEM32\DRIVERS\VSOCK.SYS
[E7CE8988B98202A5CF429CA358D26CC5][1
33872
]C:\WINDOWS\SYSTEM32\DRIVERS\vstor2-mntapi20-shared.sys
[36D4720B72B5C5D9CB2B9C29E9DF67A1][1
24576
]C:\WINDOWS\SYSTEM32\DRIVERS\VWIFIBUS.SYS
[4E9440F4F152A7B944CB1663D3935A3E][1
27776
]C:\WINDOWS\SYSTEM32\DRIVERS\WACOMPEN.SYS
[356AFD78A6ED4457169241AC3965230C][1
88576
]C:\WINDOWS\SYSTEM32\DRIVERS\WANARP.SYS
[72889E16FF12BA0F235467D6091B17DC][1
21056
]C:\WINDOWS\SYSTEM32\DRIVERS\WD.SYS
[A3D04EBF5227886029B4532F20D026F7][1
14464
]C:\WINDOWS\SYSTEM32\DRIVERS\WDCSAM64.SYS
[E2C933EDBC389386EBE6D2BA953F43D8][1
785624
]C:\WINDOWS\SYSTEM32\DRIVERS\WDF01000.SYS
[611B23304BF067451A9FDEE01FBDD725][1
12800
]C:\WINDOWS\SYSTEM32\DRIVERS\WFPLWF.SYS
[05ECAEC3E4529A7153B3136CEB49F0EC][1
22096
]C:\WINDOWS\SYSTEM32\DRIVERS\WIMMOUNT.SYS
[FE88B288356E7B47B74B13372ADD906D][1
41984
]C:\WINDOWS\SYSTEM32\DRIVERS\WINUSB.SYS
[F6FF8944478594D0E414D3F048F0D778][1
14336
]C:\WINDOWS\SYSTEM32\DRIVERS\WMIACPI.SYS
[6BCC1D7D2FD2453957C5479A32364E52][1
21504
]C:\WINDOWS\SYSTEM32\DRIVERS\WS2IFSL.SYS
[AD12F5C7251BB8D575D560894E73CBBA][1
29288
]C:\WINDOWS\SYSTEM32\DRIVERS\WSAUDIODEVICE_383S(1).SYS
[D3381DC54C34D79B22CEE0D65BA91B7C][1
112128
]C:\WINDOWS\SYSTEM32\DRIVERS\WUDFPF.SYS
[CF8D590BE3373029D57AF80914190682][1
172544
]C:\WINDOWS\SYSTEM32\DRIVERS\WUDFRD.SYS
[E2DDA8726DA9CB5B2C4000C9018A9633][1
111104
]C:\WINDOWS\SYSTEM32\EAPSVC.DLL
[024352FEEC9042260BB4CFB4D79A206B][1
203264
]C:\WINDOWS\SYSTEM32\EHSTORSHELL.DLL
[4166F82BE4D24938977DD1746BE9B8A0][1
402944
]C:\WINDOWS\SYSTEM32\ES.DLL
[0438CAB2E03F4FB61455A7956026FE86][1
16384
]C:\WINDOWS\SYSTEM32\FDPHOST.DLL
[802496CB59A30349F9A6DD22D6947644][1
34816
]C:\WINDOWS\SYSTEM32\FDRESPUB.DLL
[C4C183E6551084039EC862DA1C945E3D][1
1175552
]C:\WINDOWS\SYSTEM32\FNTCACHE.DLL
[19E41CCCEE697CC9465396B370929792][1
41984
]C:\WINDOWS\SYSTEM32\FXSMON.DLL
[DBEFD454F8318A0EF691FDD2EAAB44EB][1
689152
]C:\WINDOWS\SYSTEM32\FXSSVC.EXE
[0D09040EF933C3216CA5DD98E1744902][1
1128472 0F07C956836A14FC5C2F746EC9B
E6F147921D059
]C:\WINDOWS\SYSTEM32\GOOGLEINPUTTOOLS.IME
[277BBC7E1AA1EE957F573A10ECA7EF3A][1
777728
]C:\WINDOWS\SYSTEM32\GPSVC.DLL
[EDFEF3A8E4AFCCC2B6DBD163D81279FD][2
675893 3F8F976A2BF657EE8E4AD43B839
C4BD37BE08973
]C:\WINDOWS\SYSTEM32\HCNETSDK.DLL
[BD9EB3958F213F96B97B1D897DEE006D][1
38912
]C:\WINDOWS\SYSTEM32\HIDSERV.DLL
[F2AF0043DD39D1B31A58321DF9803660][2
407552 F1124D6F615427796C5E9D8DD69
5F2C8FE501582
]C:\WINDOWS\SYSTEM32\HPM1210LM.DLL
[23AB0B409A20DD110751B032F83F0B2D][2
139337 70A9389F8AF69CB12D50D788077
EF2E604927D05
]C:\WINDOWS\SYSTEM32\HPR.DLL
[2334DC48997BA203B794DF3EE70521DB][2
71680
]C:\WINDOWS\SYSTEM32\HPZINW12.DLL
[AC78DF349F0E4CFB8B667C0CFFF83CCE][2
89600
]C:\WINDOWS\SYSTEM32\HPZIPM12.DLL
[A3A132CBE48AF0324466469F2CAAE8A2][1
111616
]C:\WINDOWS\SYSTEM32\IEETWCOLLECTOR.EXE
[344789398EC3EE5A4E00C52B31847946][1
859648
]C:\WINDOWS\SYSTEM32\IKEEXT.DLL
[DA6C4B5FEEEA4DC7162B5D0C055EB967][1
22016
]C:\WINDOWS\SYSTEM32\IMAADP32.ACM
[142E90CF1A4C5B6E7505810E38B07B9F][1
976896
]C:\WINDOWS\SYSTEM32\INETCOMM.DLL
[098A91C54546A3B878DAD6A7E90A455B][1
101888
]C:\WINDOWS\SYSTEM32\IPBUSENUM.DLL
[A34A587FFFD45FA649FBA6D03784D257][1
569344
]C:\WINDOWS\SYSTEM32\IPHLPSVC.DLL
[B95F6501A2F8B2E78C697FEC401970CE][1
359424
]C:\WINDOWS\SYSTEM32\IPNATHLP.DLL
[4F15D75ADF6156BF56ECED6D4A55C389][1
501248
]C:\WINDOWS\SYSTEM32\IPSECSVC.DLL
[808E98FF49B155C522E6400953177B08][1
156672
]C:\WINDOWS\SYSTEM32\ISCSIEXE.DLL
[06DC527364A8CF48E472ECF2BA3F8403][1
170496
]C:\WINDOWS\SYSTEM32\ITSS.DLL
[5CE9241C030C004FF92037DF8F7401B0][1
54272
]C:\WINDOWS\SYSTEM32\IYUV_32.DLL
[B19C8390A1D641B9AC4490D4828A7B5E][1
728064
]C:\WINDOWS\SYSTEM32\KERBEROS.DLL
[387E72E739E15E3D37907A86D9FF98E2][1
90624
]C:\WINDOWS\SYSTEM32\KMSVC.DLL
[EFDFB3DD38A4376F93E7985173813ABD][1
232448
]C:\WINDOWS\SYSTEM32\LISTSVC.DLL
[C1185803384AB3FEED115F79F109427F][1
300032
]C:\WINDOWS\SYSTEM32\LLTDSVC.DLL
[F993A32249B66C9D622EA5592A8B76B8][1
23552
]C:\WINDOWS\SYSTEM32\LMHSVC.DLL
[45CFBFA8EDC3DF4E2B7FB0D0260FE051][1
956928
]C:\WINDOWS\SYSTEM32\LOCALSPL.DLL
[D5BA242D4CF8E384DB90E6A8ED850B8C][1
10240
]C:\WINDOWS\SYSTEM32\LOCATOR.EXE
[204F3F58212B3E422C90BD9691A2DF28][1
31232
]C:\WINDOWS\SYSTEM32\LSASS.EXE
[0BE09CD858ABF9DF6ED259D57A1A1663][1
84992
]C:\WINDOWS\SYSTEM32\MCX2SVC.DLL
[CA2A0750ED830678997695FF61B04C30][1
20480
]C:\WINDOWS\SYSTEM32\MIDIMAP.DLL
[E40E80D0304A73E8D269F7141D77250B][1
67584
]C:\WINDOWS\SYSTEM32\MMCSS.DLL
[254FB7A22D74E5511C73A3F6D802F192][1
97792
]C:\WINDOWS\SYSTEM32\MPRDIM.DLL
[54FFC9C8898113ACE189D4AA7199D2C1][1
828416
]C:\WINDOWS\SYSTEM32\MPSSVC.DLL
[1B7C3A37362C7B2890168C5FC61C8D9B][1
25600
]C:\WINDOWS\SYSTEM32\MSACM32.DRV
[329FEB3452982A377726DEDAFE9BBDF0][1
24064
]C:\WINDOWS\SYSTEM32\MSADP32.ACM
[A08C010D859F8EB42BDD7E1D55B8CA27][1
444752
]C:\WINDOWS\SYSTEM32\MSCOREE.DLL
[DE0ECE52236CFA3ED2DBFC03F28253A8][1
141824
]C:\WINDOWS\SYSTEM32\MSDTC.EXE
[6AB66E16AA859232F64DEB66887A8C9C][1
368640
]C:\WINDOWS\SYSTEM32\MSDTCKRM.DLL
[1C81E1BEA4847F406BBDB74D19721CE6][1
14848
]C:\WINDOWS\SYSTEM32\MSG711.ACM
[E5B9A2FA94D21C44DA2B898DC326B0C2][1
29184
]C:\WINDOWS\SYSTEM32\MSGSM32.ACM
[A190DA6546501CB4146BBCC0B6A3F48B][1
128000
]C:\WINDOWS\SYSTEM32\MSIEXEC.EXE
[45989C268EC2CC9EEA80030AF96CDA5A][1
16384
]C:\WINDOWS\SYSTEM32\MSRLE32.DLL
[E2A483E796D5FC7E447725FD01D98FA0][1
314880
]C:\WINDOWS\SYSTEM32\MSV1_0.DLL
[69A4347A8EAD86185EFF2F75755176E6][1
38912
]C:\WINDOWS\SYSTEM32\MSVIDC32.DLL
[B94D3DACCF5882B697A1C53D00BE643A][1
25600
]C:\WINDOWS\SYSTEM32\MSYUV.DLL
[847D3AE376C0817161A14A82C8922A9E][1
360448
]C:\WINDOWS\SYSTEM32\NETMAN.DLL
[5F28111C648F1E24F7DBC87CDEB091B8][1
459776
]C:\WINDOWS\SYSTEM32\NETPROFM.DLL
[AE5FC277F90C260CEA8E531085C46932][2
172032 76660C2E5C338A883992DEC63ED
21D47D6D54138
]C:\WINDOWS\SYSTEM32\NETVIDEOACTIVEX23.OCX
[1EE99A89CC788ADA662441D1E9830529][1
303616
]C:\WINDOWS\SYSTEM32\NLASVC.DLL
[D54BFDF3E0C953F823B3D0BFE4732528][1
25600
]C:\WINDOWS\SYSTEM32\NSISVC.DLL
[7BBF670114373CE6A203FA155A9E0D0A][1
509952
]C:\WINDOWS\SYSTEM32\NTSHRUI.DLL
[927463ECB02179F88E4B9A17568C63C3][1
438784
]C:\WINDOWS\SYSTEM32\P2PSVC.DLL
[3AEAA8B561E63452C655DC0584922257][1
186368
]C:\WINDOWS\SYSTEM32\PCASVC.DLL
[E08088A97F95345E181C3DFCE2C615EF][1
240640
]C:\WINDOWS\SYSTEM32\PKU2U.DLL
[C7CF6A6E137463219E1259E3F0F0DD6C][1
1389056
]C:\WINDOWS\SYSTEM32\PLA.DLL
[204FFF339146F88D0074B1E11C989479][2
188416 A17A91B51527817506978A254DE
6D3C6E9D39718
]C:\WINDOWS\SYSTEM32\PLAYBACKACTIVEX23.OCX
[5E6673A9FD85570B41014ECE99F59AC9][2
69632 0890ED557EB1A3FCAF0C54B24A3
F09D4E9C8D890
]C:\WINDOWS\SYSTEM32\PLAYBACKBARACTIVEX.OCX
[415221BE510B140E585B3CBEEF14F243][2
1146968 E42F6DE8DBA0E0ECAE7DBC89049
02630749EB157
]C:\WINDOWS\SYSTEM32\PLAYCTRL.DLL
[3EAC4455472CC2C97107B5291E0DCAFE][1
327168
]C:\WINDOWS\SYSTEM32\PNRPSVC.DLL
[5C78838B4D166D1A27DB3A8A820C799A][1
209920
]C:\WINDOWS\SYSTEM32\PROFSVC.DLL
[908ACB1F594274965A53926B10C81E89][1
187904
]C:\WINDOWS\SYSTEM32\PROVSVC.DLL
[C32ECB99AD25E9A04F01C8665DF29EF8][1
19152
]C:\WINDOWS\SYSTEM32\PWDRVIO.SYS
[D619356B955EEFA642F5FF72755E8B3C][1
12504
]C:\WINDOWS\SYSTEM32\PWDSPIO.SYS
[582AC6D9873E31DFA28A4547270862DD][1
476160
]C:\WINDOWS\SYSTEM32\QAGENTRT.DLL
[1EA7969E3271CBC59E1730697DC74682][1
849920
]C:\WINDOWS\SYSTEM32\QMGR.DLL
[906191634E99AEA92C4816150BDA3732][1
242688
]C:\WINDOWS\SYSTEM32\QWAVE.DLL
[8F26510C5383B8DBE976DE1CD00FC8C7][1
99328
]C:\WINDOWS\SYSTEM32\RASAUTO.DLL
[EE867A0870FC9E4972BA9EAAD35651E2][1
344064
]C:\WINDOWS\SYSTEM32\RASMANS.DLL
[9D0A80C3528CA6A1F808F6408A1BB08D][2
262144 097A2DDA4D31DDA065826D59C23
1B16311094F71
]C:\WINDOWS\SYSTEM32\REALPLAYACTIVEX23.OCX
[E4D94F24081440B5FC5AA556C7C62702][1
159232
]C:\WINDOWS\SYSTEM32\REGSVC.DLL
[0BC4CC55C598C0F1FA8F4A09A05BC577][2
49152 3FF74FB55ACA12EE20EE7E9CBF3
E73D31DC46EDA
]C:\WINDOWS\SYSTEM32\REMCONFIGRES_CHI.DLL
[0C57E1C6000ECC43D2987FA15F992ACA][2
81920 DF2762588B54913442F5D657390
587E79659E576
]C:\WINDOWS\SYSTEM32\REMCONFIGRES_ENG.DLL
[E4DC58CF7B3EA515AE917FF0D402A7BB][1
67072
]C:\WINDOWS\SYSTEM32\RPCEPMAP.DLL
[5C627D1B1138676C0A7AB2C2C190D123][1
512000
]C:\WINDOWS\SYSTEM32\RPCSS.DLL
[9B7395789E3791A3B6D000FE6F8B131E][1
190976
]C:\WINDOWS\SYSTEM32\SCARDSVR.DLL
[ED78427259134C63ED69804D2132B86C][1
232960
]C:\WINDOWS\SYSTEM32\SCECLI.DLL
[481F70241D4EA038BB02590A30F15A23][1
340992
]C:\WINDOWS\SYSTEM32\SCHANNEL.DLL
[262F6592C3299C005FD6BEC90FC4463A][1
1110016
]C:\WINDOWS\SYSTEM32\SCHEDSVC.DLL
[6EA4234DC55346E0709560FE7C2C1972][1
170496
]C:\WINDOWS\SYSTEM32\SDRSVC.DLL
[AD31942BDF3D594C404874613BC2FE4D][1
593408
]C:\WINDOWS\SYSTEM32\SEARCHINDEXER.EXE
[C96DD70C6F5F49C3EA7D37C6BB1DD9CF][2
135168 3357E885D997EEC4C5D4B3C2A02
4C3B5A9FF164F
]C:\WINDOWS\SYSTEM32\SEARCHLOGACTIVEX23.OCX
[BC617A4E1B4FA8DF523A061739A0BD87][1
30720
]C:\WINDOWS\SYSTEM32\SECLOGON.DLL
[C32AB8FA018EF34C0F113BD501436D21][1
64512
]C:\WINDOWS\SYSTEM32\SENS.DLL
[0336CFFAFAAB87A11541F1CF1594B2B2][1
29184
]C:\WINDOWS\SYSTEM32\SENSRSVC.DLL
[0B6231BF38174A1628C4AC812CC75804][1
121856
]C:\WINDOWS\SYSTEM32\SESSENV.DLL
[427015D56DF17241F634611557146C57][1
14175744
]C:\WINDOWS\SYSTEM32\SHELL32.DLL
[1E60EB6AB71EB7FCDC61688D6A2AADD4][2
880640 FEFE783954FD594C595FA3B0BD5
B3417CC4DDA62
]C:\WINDOWS\SYSTEM32\SHOWREMCONFIG.DLL
[AAF932B4011D14052955D4B212A4DA8D][1
370688
]C:\WINDOWS\SYSTEM32\SHSVCS.DLL
[6313F223E817CC09AA41811DAA7F541D][1
14336
]C:\WINDOWS\SYSTEM32\SNMPTRAP.EXE
[350A8C7BDBEE961221EB913A76B71186][1
60384
]C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\X64\3\CNAB4LAD.EXE
[B96C17B5DC1424D56EEA3A99E97428CD][1
559104
]C:\WINDOWS\SYSTEM32\SPOOLSV.EXE
[E17E0188BB90FAE42D83E98707EFA59C][1
3524608
]C:\WINDOWS\SYSTEM32\SPPSVC.EXE
[93D7D61317F3D4BC4F4E9F8A96A7DE45][1
65536
]C:\WINDOWS\SYSTEM32\SPPUINOTIFY.DLL
[D9F42719019740BAA6D1C6D536CBDAA6][1
236032
]C:\WINDOWS\SYSTEM32\SRVSVC.DLL
[51B52FBD583CDE8AA9BA62B8B4298F33][1
193024
]C:\WINDOWS\SYSTEM32\SSDPSRV.DLL
[AB7AEBF58DAD8DAAB7A6C45E6A8885CB][1
75264
]C:\WINDOWS\SYSTEM32\SSTPSVC.DLL
[33AE24A438549A216FDF82DB554224B2][2
143434 5947A0F5ADE4A3738AD75FECAB5
4258C3074EC74
]C:\WINDOWS\SYSTEM32\STREAMTRANSCLIENT.DLL
[C78655BC80301D76ED4FEF1C1EA40A7D][1
27136
]C:\WINDOWS\SYSTEM32\SVCHOST.EXE
[E08E46FDD841B7184194011CA1955A0B][1
524288
]C:\WINDOWS\SYSTEM32\SWPRV.DLL
[A10B048B681C38E26CA90CD1BC123604][1
200192
]C:\WINDOWS\SYSTEM32\SYNCUI.DLL
[BF9CCC0BF39B418C8D0AE8B05CF95B7D][1
1743360
]C:\WINDOWS\SYSTEM32\SYSMAIN.DLL
[870726CDCC241A92785572628B89CC07][1
82432
]C:\WINDOWS\SYSTEM32\SYSTEMPROPERTIESPERFORMANCE.EXE
[7FB87C7F816CDBC91149644DF926ED09][2
217205 07CF390F1E4E19BC3267A998458
544C4748EAC82
]C:\WINDOWS\SYSTEM32\SYSTEMTRANSFORM.DLL
[E3C61FD7B7C2557E1F1B0B4CEC713585][1
92672
]C:\WINDOWS\SYSTEM32\TABSVC.DLL
[40F0849F65D13EE87B9A9AE3C1DD6823][1
316928
]C:\WINDOWS\SYSTEM32\TAPISRV.DLL
[1BE03AC720F4D302EA01D40F588162F6][1
65536
]C:\WINDOWS\SYSTEM32\TBSSVC.DLL
[32A3C8600AF124CBAAD845F13CFAE3CB][6
195072
]C:\WINDOWS\SYSTEM32\TCPMON.DLL
[2E648163254233755035B46DD7B89123][1
680960
]C:\WINDOWS\SYSTEM32\TERMSRV.DLL
[F0344071948D1A1FA732231785A0664C][1
44544
]C:\WINDOWS\SYSTEM32\THEMESERVICE.DLL
[7E7AFD841694F6AC397E99D75CEAD49D][1
119808
]C:\WINDOWS\SYSTEM32\TRKWKS.DLL
[CEED624D1291081B1B7D921FBB9C61D9][1
14848
]C:\WINDOWS\SYSTEM32\TSBYUV.DLL
[B6D8C1202DACA028AD94BDA2795CBBE9][1
86528
]C:\WINDOWS\SYSTEM32\TSPKG.DLL
[3CBDEC8D06B9968ABA702EBA076364A1][1
40960
]C:\WINDOWS\SYSTEM32\UI0DETECT.EXE
[25FBDEF06C4D92815B353F6E792C8129][1
404480
]C:\WINDOWS\SYSTEM32\UMPNPMGR.DLL
[6BA9D927DDED70BD1A9CADED45F8B184][1
163840
]C:\WINDOWS\SYSTEM32\UMPO.DLL
[A293DCD756D04D8492A750D03B9A297C][1
214528
]C:\WINDOWS\SYSTEM32\UMRDP.DLL
[64B328D52DFC8CDA123093E3F6E4C37C][1
323584
]C:\WINDOWS\SYSTEM32\UNREGMP2.EXE
[D47EC6A8E81633DD18D2436B19BAF6DE][1
353792
]C:\WINDOWS\SYSTEM32\UPNPHOST.DLL
[DF72A9936D0C3F517083119648814B09][6
45056
]C:\WINDOWS\SYSTEM32\USBMON.DLL
[BAFE84E637BF7388C96EF48D4D3FDD53][1
30720
]C:\WINDOWS\SYSTEM32\USERINIT.EXE
[EDBB23CBCF2CDF727D64FF9B51A6070E][1
38912
]C:\WINDOWS\SYSTEM32\UXSMS.DLL
[8D6B481601D01A456E75C3210F1830BE][1
533504
]C:\WINDOWS\SYSTEM32\VDS.EXE
[D9B422F37FCAF61BD80E12CC03E84816][1
437328
]C:\WINDOWS\SYSTEM32\VMNAT.EXE
[5DC2DA538FF0806950B73F798A2444ED][1
358480
]C:\WINDOWS\SYSTEM32\VMNETDHCP.EXE
[B60BA0BC31B0CB414593E169F6F21CC2][1
1600512
]C:\WINDOWS\SYSTEM32\VSSVC.EXE
[1C9D80CC3849B3788048078C26486E1A][1
381952
]C:\WINDOWS\SYSTEM32\W32TIME.DLL
[3CEC96DE223E49EAAE3651FCF8FAEA6C][1
1255736
]C:\WINDOWS\SYSTEM32\WAT\WATADMINSVC.EXE
[A3F5E8EC1316C3E2562B82694A251C9E][1
909312
]C:\WINDOWS\SYSTEM32\WBEM\FASTPROX.DLL
[38B84C94C5A8AF291ADFEA478AE54F93][1
203264
]C:\WINDOWS\SYSTEM32\WBEM\WMIAPSRV.EXE
[19B07E7E8915D701225DA41CB3877306][1
242688
]C:\WINDOWS\SYSTEM32\WBEM\WMISVC.DLL
[78F4E7F5C56CB9716238EB57DA4B6A75][1
1504256
]C:\WINDOWS\SYSTEM32\WBENGINE.EXE
[3AA101E8EDAB2DB4131333F4325C76A3][1
202240
]C:\WINDOWS\SYSTEM32\WBIOSRVC.DLL
[7368A2AFD46E5A4481D1DE9D14848EDD][1
367104
]C:\WINDOWS\SYSTEM32\WCNCSVC.DLL
[20F7441334B18CEE52027661DF4A6129][1
40960
]C:\WINDOWS\SYSTEM32\WCSPLUGINSERVICE.DLL
[BF1FC3F79B863C914687A737C2F3D681][1
90624
]C:\WINDOWS\SYSTEM32\WDI.DLL
[26AF184300C0868D854D5A3092234E24][1
210944
]C:\WINDOWS\SYSTEM32\WDIGEST.DLL
[1473768973453DE50DC738C2955FC4DD][1
217088
]C:\WINDOWS\SYSTEM32\WDMAUD.DRV
[3DB6D04E1C64272F8B14EB8BC4616280][1
258560
]C:\WINDOWS\SYSTEM32\WEBCLNT.DLL
[C749025A679C5103E575E3B48E092C43][1
237568
]C:\WINDOWS\SYSTEM32\WECSVC.DLL
[7E591867422DC788B9E5BD337A669A08][1
84480
]C:\WINDOWS\SYSTEM32\WERCPLSUPPORT.DLL
[6D137963730144698CBD10F202E9F251][1
76800
]C:\WINDOWS\SYSTEM32\WERSVC.DLL
[8DD52E8E6128F4B2DA92CE27402871C1][1
580096
]C:\WINDOWS\SYSTEM32\WIASERVC.DLL
[58F4493BF748A3A89689997B7BD00E95][1
444416
]C:\WINDOWS\SYSTEM32\WINHTTP.DLL
[851A1382EED3E3A7476DB004F4EE3E1A][1
118784
]C:\WINDOWS\SYSTEM32\WKSSVC.DLL
[4FADA86E62F18A1B2F42BA18AE24E6AA][1
886784
]C:\WINDOWS\SYSTEM32\WLANSVC.DLL
[96C6E7100D724C69FCF9E7BF590D1DCA][1
12288
]C:\WINDOWS\SYSTEM32\WPCSVC.DLL
[93221146D4EBBF314C29B23CD6CC391D][1
117248
]C:\WINDOWS\SYSTEM32\WPDBUSENUM.DLL
[E8B1FE6669397D1772D8196DF0E57A9E][1
97280
]C:\WINDOWS\SYSTEM32\WSCSVC.DLL
[A1D7E3ADCDB07DDB6F423862DCB1A52B][6
224768
]C:\WINDOWS\SYSTEM32\WSDMON.DLL
[581B739BEF5B6B668E5308CFE956B84A][1
96328 1B26127179A033C653D746669F1
E596378530A38
]C:\WINDOWS\SYSTEM32\WSMONEDITOR.DLL
[BCB1310604AA415C4508708975B3931E][1
2018304
]C:\WINDOWS\SYSTEM32\WSMSVC.DLL
[D9EF901DCA379CFE914E9FA13B73B4C4][1
2428952
]C:\WINDOWS\SYSTEM32\WUAUENG.DLL
[7A95C95B6C4CF292D689106BCAE49543][1
78848
]C:\WINDOWS\SYSTEM32\WUDFSVC.DLL
[9A3452B3C2A46C073166C5CF49FAD1AE][1
229888
]C:\WINDOWS\SYSTEM32\WWANSVC.DLL
[241A1900C52DCBA38B20A4F3671444E0][1
1036800
]C:\WINDOWS\SYSWOW64\D3D8.DLL
[351533ACC2A069B94E80BBFC177E8FDF][1
35344
]C:\WINDOWS\SYSWOW64\DRIVERS\SADP_NPF64.SYS
[2AFBB91BBD2378933B26E6D68C140D1B][1
11745792
]C:\WINDOWS\SYSWOW64\IEFRAME.DLL
[1C7F1C3EA5894995E6C563E9AE9F029F][1
64000
]C:\WINDOWS\SYSWOW64\L3CODECA.ACM
[28FFB14117CCEDD7D2F124596AA9B785][1
269504 3F6B83D48CF182C60EC6416AC9D
0E0A116916560
]C:\WINDOWS\SYSWOW64\MACROMED\FLASH\FLASHPLAYERUPDATESERVICE.EX
E
[EA85144F35EDE6EE25C484D4242FF2C8][1
17387008
]C:\WINDOWS\SYSWOW64\MSHTML.DLL
[59D16C3D5CC0D573256A01783ED5CCB4][1
2291712
]C:\WINDOWS\SYSWOW64\MSVIDCTL.DLL
[E94C583CDE2348950155F2AF2876F34D][1
231424
]C:\WINDOWS\SYSWOW64\MSWSOCK.DLL
[0B7E85364CB878E2AD531DB7B601A9E5][1
52224
]C:\WINDOWS\SYSWOW64\NAPINSP.DLL
[104A1070E90F1C530328E69B49718841][1
52224
]C:\WINDOWS\SYSWOW64\NLAAPI.DLL
[703FFD301AB900B047337C5D40FD6F96][1
90112
]C:\WINDOWS\SYSWOW64\OLEPRO32.DLL
[E495E408C93141E8FC72DC0C6046DDFA][1
20992
]C:\WINDOWS\SYSWOW64\PERFHOST.EXE
[5CF640EDDB1E40A5AB1BB743BCDEC610][1
65024
]C:\WINDOWS\SYSWOW64\PNRPNSP.DLL
[76F58DB8F85C125E0D6B3AA42F3BF1D0][1
1143808
]C:\WINDOWS\SYSWOW64\URLMON.DLL
[5DF5D8CFD9B9573FA3B2C89D9061A240][1
20992
]C:\WINDOWS\SYSWOW64\WINRNR.DLL
[BD153B7E600EAC648FBE9C6C2F694B5D][2
320512 6D6D7AA2B4A3D2D11BC4FD3A550
551F6D7B2B18D
]C:\WINDOWS\TSNP2UVC.EXE
[C893A71AE21E9852027B7F0BC499B23F][2
1430 A7D959AE2AF69FF46A20E110C75
410ECD0A81823
]C:\WINDOWS\UPDATE.JS
[
-2][0
-1
]CAMCODEC.DLL
[
-2][0
-1
]ICCVID.DLL
[
-2][0
-1
]SYSWOW64\DRIVERS\VSTOR2-MNTAPI20-SHARED.SYS
[
-2][0
-1
]TSCCVID.DLL
===
[MBR]
[MD5=004BC502E8A0AB7DDDB5C2C67E1CDFEE]
M8CO0LwAfI7Ajti+AHy/AAa5AAL886RQaBwGy/u5BAC9vgeAfgAAfAsPhQ4Bg8UQ4vHNGIhW
AFXGRhEFxkYQALRBu6pVzRNdcg+B+1WqdQn3wQEAdAP+RhBmYIB+EAB0JmZoAAAAAGb/dgho
AABoAHxoAQBoEAC0QopWAIv0zROfg8QQnusUuAECuwB8ilYAinYBik4Cim4DzRNmYXMc/k4R
dQyAfgCAD4SKALKA64RVMuSKVgDNE13rnoE+/n1VqnVu/3YA6I0AdRf6sNHmZOiDALDf5mDo
fACw/+Zk6HUA+7gAu80aZiPAdTtmgftUQ1BBdTKB+QIBcixmaAe7AABmaAACAABmaAgAAABm
U2ZTZlVmaAAAAABmaAB8AABmYWgAAAfNGloy9uoAfAAAzRigtwfrCKC2B+sDoLUHMuQFAAeL
8Kw8AHQJuwcAtA7NEOvy9Ov9K8nkZOsAJALg+CQCw0ludmFsaWQgcGFydGl0aW9uIHRhYmxl
AEVycm9yIGxvYWRpbmcgb3BlcmF0aW5nIHN5c3RlbQBNaXNzaW5nIG9wZXJhdGluZyBzeXN0
ZW0AAABje5o=
===
[PT]
0x42 Unknown, 63, -387940239
===
[VBR]
61KQTlRGUyAgICAAAggAAAAAAAAA+AAAPwD/AAAIAAAAAAAAgACAAP//AwAAAAAAqioAAAAA
AAACAAAAAAAAAPYAAAABAAAAO8BDWAJEWLYAAAAA+jPAjtC8AHz7aMAHHx5oZgDLiBYOAGaB
PgMATlRGU3UVtEG7qlXNE3IMgftVqnUG98EBAHUD6d0AHoPsGGgaALRIihYOAIv0Fh/NE5+D
xBieWB9y4TsGCwB126MPAMEuDwAEHloz27kAICvIZv8GEQADFg8AjsL/BhYA6EsAK8h377gA
u80aZiPAdS1mgftUQ1BBdSSB+QIBch4WaAe7FmhwDhZoCQBmU2ZTZlUWFhZouAFmYQ4HzRoz
wL8oELnYD/zzqulfAZCQZmAeBmahEQBmAwYcAB5maAAAAABmUAZTaAEAaBAAtEKKFg4AFh+L
9M0TZllbWmZZZlkfD4IWAGb/BhEAAxYPAI7C/w4WAHW8Bx9mYcOg+AHoCQCg+wHoAwD06/20
AYvwrDwAdAm0DrsHAM0Q6/LDDQpBIGRpc2sgcmVhZCBlcnJvciBvY2N1cnJlZAANCkJPT1RN
R1IgaXMgbWlzc2luZwANCkJPT1RNR1IgaXMgY29tcHJlc3NlZAANClByZXNzIEN0cmwrQWx0
K0RlbCB0byByZXN0YXJ0DQoAjKm+1gAAVaoHAEIATwBPAFQATQBHAFIABAAkAEkAMwAwAADU
AAAAJAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAOsikJAFAE4AVABMAEQAUgAAAAAAAAAAAAAAAAAAAAAAAAAAAGYPtwYLAGYPth4NAGb3
42ajUgJmiw5AAID5AA+PDgD22Wa4AQAAAGbT4OsIkGahUgJm9+Fmo2YCZg+3HgsAZjPSZvfz
ZqNWAuiVBGaLDk4CZokOJgJmAw5mAmaJDioCZgMOZgJmiQ4uAmYDDmYCZokOPgJmAw5mAmaJ
DkYCZriQAAAAZosOJgLogwlmC8APhF7+ZqMyAma4oAAAAGaLDioC6GoJZqM2Ama4sAAAAGaL
Di4C6FgJZqM6AmahMgJmC8APhCv+Z4B4CAAPhSL+Z2aNUBBnA0IEZ2YPtkgMZokOcgJnZotI
CGaJDm4CZqFuAmYPtw4LAGYz0mb38WajdgJmoUYCZgMGbgJmo0oCZoM+NgIAD4QdAGaDPjoC
AA+Ez/1mix46Ah4HZos+SgJmoS4C6OABZg+3DgACZrgCAgAA6CIIZgvAD4UWAGYPtw5aAma4
XAIAAOgMCGYLwA+EQgxnZosAHgdmiz4+Aug/BmahPgJmuyAAAABmuQAAAABmugAAAADo5ABm
hcAPhSMAZqE+Ama7gAAAAGa5AAAAAGa6AAAAAOjEAGYLwA+FRADp8QtmM9JmuYAAAABmoT4C
6MoIZgvAD4TaCx4HZos+PgLo2wVmoT4CZruAAAAAZrkAAAAAZroAAAAA6IAAZgvAD4SwC2dm
D7dYDGaB4/8AAAAPhaULZovYaAAgB2Yr/2ahPgLoAAFoACAHZiv/ZqE+AuisCooWDgC46AOO
wI02CwArwGgAIFDLBh5mYGaL2mYPtg4NAGb34WajEQBmi8Nm9+GjFgCL34PjD4zAZsHvBAPH
UAfoPvxmYZAfB8NnA0AUZ2aDOP8PhEwAZ2Y5GA+FMwBmC8kPhQoAZ4B4CQAPhSMAw2c6SAkP
hRoAZovwZwNwCuiXBmZRHgdmi/rzp2ZZD4UBAMNnZoN4BAAPhAcAZ2YDQATrq2YrwMNmi/Po
bAZnZgMAZ/dADAIAD4U0AGdmjVAQZzpKQA+FGABnZo1yQuhJBmZRHgdmi/vzp2ZZD4UBAMNn
g3gIAA+EBgBnA0AI68JmM8DDZ4B7CAAPhRwABh5mYGdmjVMQZ2aLCmaL82cDcgTzpGZhkB8H
w2ZQZ2aNUxBmhcAPhQoAZ2aLSghmQesRkGdmi0IYZjPSZvc2UgJmi8hmK8BmXugBAMMGHmZg
Z4B7CAEPhAMA6Xb7ZoP5AA+FBgBmYZAfB8NmU2ZQZlFmVmZXBuiRBGaL0QdmX2ZeZllmhcAP
hDQAZjvKD40DAGaL0eiC/mYrymaL2maLwmYPthYNAGb34mYPtxYLAGb34mYD+GZYZgPDZlvr
n2aF9g+EDvtmUWZXBmdmD7ZDCWaFwA+EIABm0eBmK+Bmi/xmVGZWZ2YPt3MKZgPzZovI86Rm
XusDkGZQZlBnZosDZlBnZotDGGZQZ2aLViBmhdIPhAsAZov+Hgdmi8LocQNmi8ZmWmZZZkJm
UWZW6D8GZoXAD4Sd+mZeZllmi/4eB+hOA2aLxmaL2WZZZlpmUWZWZtHp6Pj9ZoXAD4R2+mZe
ZllmA+EHZl9mWWaL0GZYZltmi9rp9f4GHmZgJmdmD7dfBCZnZg+3TwZmC8kPhET6ZgPfZoPD
AmaBx/4BAABmSWYLyQ+EFwAmZ4sDJmeJB2aDwwJmgccAAgAAZknr4mZhkB8HwwYeZmBmuAEA
AABmoyICZqEeAmYDBmYCZqNqAmYDBmYCZqNOAmahMABmD7YeDQBm9+Nmix5OAmaJB2ajEQCD
wwRmoVYCZokHoxYAg8MEZokeTgJmix4eAh4H6Gf5Zov76FH/ZqEeAma7IAAAAGa5AAAAAGa6
AAAAAOgQ/WYLwA+EGQFmi9geB2aLPhoCZjPA6KL9ZoseGgJmgT+AAAAAD4TrAANfBOvwZlNm
i0cQZvcmVgJmUGYz0mYPth4NAGb382ZS6NwAZgvAD4RE+WaLDlYCZg+2Hg0AZvfjZlpmA8Jm
ix5OAmaJB4PDBGYPtgYNAGYrwmY7wQ+GAwBmi8FmiQdmK8hmWg+EdQBmA8JmUGYz0mYPth4N
AGb382ZR6IIAZllmC8APhOj4Zg+2Hg0AZvfjZoseTgJmixeDwwRmAxdmO9APhRUAZg+2Bg0A
ZjvBD4YDAGaLwWYBB+ulg8MEZokeTgJmiQeDwwRmD7YGDQBmO8EPhgMAZovBZokH64KDwwRm
/wYiAmaJHk4CZlsDXwRmgT+AAAAAD4QM/2ZhkB8Hw2aL0GaLDiICZos2agJmAzZmAmZSZlFm
UmaLHmoCZos+VgJmiwRmoxEAg8YEZosEoxYAg8YEHgfo6PdmK/gPhAgA9yYLAAPY69lmiz5q
Ah4H6L/9ZqFqAma7gAAAAGa5AAAAAGaL0eiB+2YLwA+E//dmi9hmWGZW6CwBZl5mC8APhAUA
ZltmW8NmWWZa4oRmM8DDBh5mYGZQZlFmM9JmD7YeDQBm9/NmUmZX6FP/Zl9mC8APhLn3Zg+2
Hg0AZvfjZlpmA8JmoxEAZllmD7YeDQBmO8sPjhMAiR4WAGYry2ZYZgPDZlBmUesUkGZYZgPB
ZlCJDhYAZrkAAAAAZlEGZleL34PjD4zAZsHvBAPHUAfoEPdmXwdmAz5SAmZZZlhmg/kAD49w
/2ZhkB8HwwYeZmBm9yZWAmaLDlYC6FX/6NL8ZmGQHwfDBh5mYGb3JnICZoseNgJmiw5yAmaL
NioCHgdmiz5GAuiB++in/GZhkB8Hw2ZQZlNmUWaLHkoCZovIZsHoA2aD4QdmA9hmuAEAAABm
0+BnhAMPhAQA+OsCkPlmWWZbZljDZ4B7CAEPhAQAZivAw2dmjXMQZ2aLVghmO8IPhwsAZ2aL
FmY7wg+DBABmK8DDZwNeEGYr9meAOwAPhD4A6IEAZgPx6DkAZgPKZjvBD4whAGaL0WZQZ2YP
tgtmi8Fmg+APZsHpBGYD2WYD2GZDZljrxGYryGYrwmYDxsNmK8DDZivJZ4oLgOEPZoP5AA+F
BABmK8nDZlNmUmYD2WdmD74TZklmS2aD+QAPhA0AZsHiCGeKE2ZLZknr62aLymZaZlvDZlNm
UmYr0meKE2aD4g9mK8lnigvA6QRmg/kAD4UIAGYryWZaZlvDZgPaZgPZZ2YPvhNmSWZLZoP5
AA+EDQBmweIIZ4oTZktmSevrZovKZlpmW8NmC8kPhQEAw2ZRZlZngz5hD4wMAGeDPnoPjwQA
Z4MuIGaDxgLi5mZeZlnDZlBmUWaL0GahMgJnZo1YEGcDQwRnZo1AEGaL2uhE+WYLwA+EBQBm
WWZZw2ahNgJmC8APhQgAZllmWWYzwMNmixY2AmdmjVIQZ2aLQhhmM9Jm9zZuAmYz9mZQZlZm
WGZeZjvGD4Q6AGZWZkBmUGZI6Bv+cujo6/1mWmZeZllmW2ZTZlFmVmZSZqFGAmdmjUAY6ND4
ZgvAdMRmWWZZZllmWcNmWWZZZjPAw2ZRZlBmuAUAAAAeB2aL+eiN/WaLwWa7IAAAAGa5AAAA
AGa6AAAAAOgz+GZbZllmhcAPhRUAZovBZg+3DhACZroSAgAA6Bb46zOQZjPSZovBZovLZlBm
U+gjAGZbZl9mC8APhBcAHgfoNf1mi8dmD7cOEAJmuhICAADo4ffDZlJmUWa7IAAAAGa5AAAA
AGa6AAAAAOjH92YLwA+EYwBmi9geB2aLPhoCZjPA6Fn4Hgdmix4aAmZZZlomZjkPD4UMACZm
OVcID4QxAOsTkCZmgz//D4QvACaDfwQAD4QmACZmD7dHBAPYi8MlAIB0y4zABQAIjsCB4/9/
674mZotHEMNmWWZaZjPAw2ZQZlFmi8dmwegEBlkDyFEHZoPnD2ZZZljDYAa+vQ2/ACAeB7kN
AJDzpQdhwwEjRWeJq83v/ty6mHZUMhDw4dLDAAAAACAgYIs2GCAmigWIBEdGZv8GFCCB/mAg
dQboWwC+ICDi5ok2GCBhw2ZgizYYILCAiARGMsCB/mAgdQboOgC+ICCB/lggdelmM8Bmo1gg
ZqEUIGbB4ANmD8hmo1wg6BgAuwAgZosHZg/IZokHg8MEgfs0IHXuZmHDZmC7ICBmiwdmD8hm
iQeDwwSB+2Agde67ACBmiw9mi1cEZot3CGaLfwxmi28QuyAgxwYaIDAPxgYcIBSQU4seGiD/
F2YDRwJbZgPoZgMvZovBZsHABWYDxWaL72aL/maL8mbBxh5mi9Fmi8hmiwdmM0cIZjNHIGYz
RzRm0cBmiUdAg8ME/g4cIHWygwYaIAaBPhogSA91n7sAIGYBD2YBVwRmAXcIZgF/DGYBbxBm
YcNmi8ZmM8dmI8JmM8fDZovCZjPGZjPHw2ZTZovCZiPGZovaZiPfZgvDZoveZiPfZgvDZlvD
/A6ZeYJaCQ+h69luEw/cvBuPCQ/WwWLKBh5mYGYz27gAu80aZiPAD4W7AGaB+1RDUEEPhbAA
gfkCAQ+CqABmYZAfBwYeZmBngHsIAA+FDABnZo1TEGdmiwrrJZBnZo1TEGdmi0ooZoH5AAAI
AA+DDABnZotCLGYjwA+EAwBmM8kOH+j1/WYjyQ+EMgBmugCAAABmO8oPhh8AZivKBmZRZldm
UmaLyui3/ej7/WZaZl9mWQdmA/rr2uil/ejp/egL/g4HZrtUQ1BBZr8AIAAAZrkUAAAAZrgH
uwAAZroKAAAAZjP2zRpmYZAfB8Og+QHpS/Gg+gHpRfEAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAA
===
[SIGN]
[1264F787E46DC572FA274CA09B446E01] Microsoft Corporation
[786DD1892B553EFE5A004AC39775C851] Microsoft Corporation
[BD25E3537B54C1BFF40335992B3686FD] Microsoft Corporation
[FC3396B88F31636817D31F592A0DA848] Microsoft Corporation
[7FC19DA1DC70C78D2FBD7A1D10942051] Microsoft Corporation
[42729C3DE75A7A51FC6F9EF6546C9199] Adobe Systems, Incorporated
[4EAF6F8F0B3BE33A0E3877EB7FFD48D4] Adobe Systems, Incorporated
[F2CEEE9ABBCEF207ACB103215AC28BC2] Adobe Systems, Incorporated
[320681DF28D82CDCA7E3EED0846625DB] Adobe Systems Incorporated
[B17404D208C4B20518592AA43B81E04B] Oracle America, Inc.
[C9B67BCB8E384064A8C2263740B0C437] Oracle America, Inc.
[8669BE94F63944E4F899C3950B520241] Acresso Software Inc.
[14C405B807A341B60683FE1D5ED65380] Materialise NV
[9E7370CC3D6A43942433F85D0E2BBDD8] Microsoft Corporation
[84DE1DD996B48B05ACE31AD015FA108A]
[5A432A042DAE460ABE7199B758E8606C]
[FAEAFD0BEBFB2B5E938B29C8A155B807]
[DE77A8DA45F91629EB5FC157FA00C08A]
[42E4E281D9646F15E5C4D0CFD61CE684]
[51667022FACBD1AA611373DA16C98533]
[329D828599BE8859DDC81F866019B2F0]
[78AF384F14F01009EFB10A31AFEC51F4]
[88FBBB1C601A6BC42054E57C2897FA45]
[328E65035DE1D2C1206B4F94AAFC1DB7]
[E7859BA062DB5E23C6DD34AD66B09F50]
[E91F8AFBD7FB96C94B266579D6BFA77A]
[D2E3E6D94A9E1CFA1561D9C748136FD0]
[56748C769C10A379719A2C9D93AFEA6B]
[B7483C4236E990A3C7F5A3ABEE5C1417]
[F7CEB1E5F0000FDEEE04B046BBDE1D4E]
[31A94358EF55B871B1B81ADE3ACEBFF9]
[AE2A8DC5C08AE6A198D5EC47561C0DEF]
[E7062DBD907E0C5CEEB5ABDAF07E6B32]
[D3F78E38C39AB0E7358735717FB52EAE]
[EB1B7B961090A4AF33FC297516B88FAE]
[89CACBC5A5D9F14AD11F09D1DE49294E]
[AA1600118E222FCBE3F3BFEC1ABEC309]
[21FF393512F51F5A98620C794B4488A3]
[E99CD4524662A2DA7C73372C626669D8]
[515377905CC9A2EB0E585DD9AB457722]
[A597D3A1073271330191EE30046C121A]
[83C92F09C507BF8C2E2BED71F7B04A29]
[86661538E9002DA465C8456A962180C8]
[E80335157A225AD734865ADF1F929FFB]
[0978D90C8B61F73E926F7194CBCA331C]
[DEE16AB97AFB535329D0D0BE3F5929CE]
[B3DD214F23037E3D3C27D6C9447B40B5]
[C42EDED9E707ABDD455BB27FBD72416F]
[6C112DA6C86DB7FB2C50522EFDDA706A]
[52C696180AC8371163B268D648DCBDA5]
[EA8386CA87165460D39A1D29FF11080B]
[835FC2EA0631B734BB06C12B0665F01D]
[7CBB1D4D13DC62D7F529D87151FD3CD3]
[29E08F1970B681EBC3B0082D1654CF49]
[DC0D82C65E73BC03601E73F1367248FE]
[5137E8DE77B3185EC0B164A3AB9D58B9]
[D2D91B5F04852D50142D95BB9BB69310]
[FF1CA44FEDCA271E314AA63692D341A6]
[4A270804DC8AB72DCB4F694D050A3517]
[24B13133A4AC2FF48BA02EB10990A08D]
[C4002B6B41975F057D98C439030CEA07]
[4705E8EF9934482C5BB488CE28AFC681]
[D88040F816FDA31C3B466F0FA0918F29]
[6D7C8A951AF6AD6835C029B3CB88D333]
[D1CEEA2B47CB998321C579651CE3E4F8]
[5988FC40F8DB5B0739CD1E3A5D0D78BD]
[A8B7F3818AB65695E3A0BB3279F6DCE6]
[108FB6DDB69E537A2EA53F425363FAE5]
[86329C35FF23CFEF0FB6C0023BA06BCE]
[5243CFC2E7161C91C2B355240035B9E4]
[773212B2AAA24C1E31F10246B15B276C]
[4ABA3E75A76195A3E38ED2766C962899]
[1A47D52E303B7543E4E6026595B95422]
[3044D07ABDF4BBEA27E2EE7B1E0C0C65]
Microsoft Corporation
Microsoft Corporation
Nero AG
VMware, Inc.
Wondershare software CO., LIMITED
Google Inc
Google Inc
Google Inc
Google Inc
Intel(R) Software Development Products
Intel Corporation
Intel Corporation
Apple Inc.
Oracle America, Inc.
Oracle America, Inc.
Mozilla Corporation
Mozilla Corporation
Power Software Ltd
Rosetta Stone, Ltd
Samsung Electronics CO., LTD.
Samsung Electronics CO., LTD.
Sony Mobile Communications AB
Sony Mobile Communications AB
Sony Mobile Communications AB
TeamViewer
Greatis Software LLC
Greatis Software LLC
VMware, Inc.
VMware, Inc.
VMware, Inc.
Western Digital Technologies, Inc.
Western Digital Technologies, Inc.
Microsoft Windows
WordWeb Software
Arvato Digital Services Canada Inc
Intel(R) Software Development Products
Microsoft Windows
Apple Inc.
Microsoft Windows
win.rar GmbH
WinZip Computing
AVG Technologies CZ, s.r.o.
Softdeluxe Ltd.
Malware Protection Live
Widevine Technologies
Medical Informatics Engineering
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Dynamic Code Publisher
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Corporation
Microsoft Dynamic Code Publisher
Microsoft Corporation
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
[A6C09924C6730DE8DEED9890A12AA691]
[9110FFAD124283F37D38771BB60556AF]
[3B367397320C26DBA890B260F80D1B1B]
[AA2C08CE85653B1A0D2E4AB407FA176C]
[2B81776DA02017A37FE26C662827470E]
[8560FFFC8EB3A806DCD4F82252CFC8C6]
[796B47A4B82EF1C39F13435B88834C48]
[CA2A0750ED830678997695FF61B04C30]
[C210E0DF28F3B0E5D45F928F08726650]
[37D0FB9E5E8EDA40B66FC3FB3D660261]
[E424B3EF666B184CEE0B6871AAA8C9F6]
[9A9F9F1A77D6A80EE28B57664F00013E]
[58A0CDABEA255616827B1C22C9994466]
[2DF36F15B2BC1571A6A542A3C2107920]
[613C8CE10A5FDE582BA5FA64C4D56AAA]
[88351B29B622B30962D2FEB6CA8D860B]
[019CD868461B646E09BDF04474C19341]
[5C627D1B1138676C0A7AB2C2C190D123]
[ED78427259134C63ED69804D2132B86C]
[09F7401D56F2393C6CA534FF0241A590]
[D29E998E8277666982B4F0303BF4E7AF]
[88AB9B72B4BF3963A0DE0820B4B0B06C]
[2E2072EB48238FCA8FBB7A9F5FABAC45]
[8396C6C26AADDFE4590CCEF0F419B6B7]
[ED730D791CB026146F9FB8EFB15201B7]
[4B78B431F225FD8624C5655CB1DE7B61]
[3290D6946B5E30E70414990574883DDB]
[0BC381A15355A3982216F7172F545DE1]
[9D2A2369AB4B08A4905FE72DB104498F]
[4ABA3E75A76195A3E38ED2766C962899]
[F23FEF6D569FCE88671949894A8BECF1]
[A6BF31A71B409DFA8CAC83159E1E2AFF]
[FDE360167101B4E45A96F939F388AEB0]
[82974D6A2FD19445CC5171FC378668A4]
[05F5A0D14A2EE1D8255C2AA0E9E8E694]
[95F9C2976059462CBBF227F7AAB10DE9]
[F17D1D393BBC69C5322FBFAFACA28C7F]
[FE1EC06F2253F691FE36217C592A0206]
[6B400F211BEE880A37A1ED0368776BF4]
[3AB183AB4D2C79DCF459CD2C1266B043]
[3CEC7631A84943677AA8FA8EE5B6B43D]
[43D808F5D9E1A18E5EEB5EBC83969E4E]
[A8EDB86FC2A4D6D1285E4C70384AC35A]
[16835866AAA693C7D7FCEBA8FFF706E4]
[B1FB3DDCA0FDF408750D5843591AFBC6]
[B26F4F737E8F9DF4F31AF6CF31D05820]
[A87D604AEA360176311474C87A63BB88]
[D81D9E70B8A6DD14D42D7B4EFA65D5F2]
[99F8E788246D495CE3794D7E7821D2CA]
[2F6B34B83843F0C5118B63AC634F5BF4]
[597F78224EE9224EA1A13D6350CED962]
[E109549C90F62FB570B9540C4B148E54]
[79059559E89D06E8B80CE2944BE20228]
[7ECFF9B22276B73F43A99A15A6094E90]
[608C14DBA7299D8CB6ED035A68A15799]
[5812713A477A3AD7363C7438CA2EE038]
[1FF8B4431C353CE385C875F194924C0C]
[7024F087CFF1833A806193EF9D22CDA9]
[1E56388B3FE0D031C44144EB8C4D6217]
[6EC6D772EAE38DC17C14AED9B178D24B]
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Adobe Systems, Incorporated
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
[F67F933E79241ED32FF46A4F29B5120B]
[1142A21DB581A84EA5597B03A26EBAA0]
[4FC6E2C2FC50445450651F42E90CC0BD]
[89A69C3F2F319B43379399547526D952]
[C484F8CEB1717C540242531DB7845C4E]
[019AF6924AEFE7839F61C830227FE79C]
[769765CE2CC62867468CEA93969B2242]
[02062C0B390B7729EDC9E69C680A6F3C]
[F02E18EFA6CEA4378D3F95CB6F9A3DE4]
[B5ACE6968304A3900EEB1EBFD9622DF2]
[61583EE3C3A17003C4ACD0475646B4D3]
[6C02A83164F5CC0A262F4199F0871CF5]
[F09EEE9EDC320B5E1501F749FDE686C8]
[B114D3098E9BDB8BEA8B053685831BE6]
[43BEA8D483BF1870F018E2D02E06A5BD]
[A6ECA2151B08A09CACECA35C07F05B42]
[B79968002C277E869CF38BD22CD61524]
[A87528880231C54E75EA7A44943B38BF]
[9DA669F11D1F894AB4EB69BF546A42E8]
[3E5B191307609F7514148C6832BB0842]
[B8BD2BB284668C84865658C77574381A]
[F036CE71586E93D94DAB220D7BDF4416]
[D7CD5C4E1B71FA62050515314CFB52CF]
[0840155D0BDDF1190F84A663C284BD33]
[E19D3F095812725D88F9001985B94EDD]
[EBF28856F69CF094A902F884CF989706]
[102DE219C3F61415F964C88E9085AD14]
[03EDB043586CCEBA243D689BDDA370A8]
[1C827878A998C18847245FE1F34EE597]
[54DA3DFD29ED9F1619B6F53F3CE55E49]
[9BB2EF44EAA163B29C4A4587887A0FE4]
[13096B05847EC78F0977F2C0F79E9AB3]
[9819EEE8B5EA3784EC4AF3B137A5244C]
[9B19F34400D24DF84C858A421C205754]
[88612F1CE3BF42256913BF6E61C70D52]
[0E5DA5369A0FCAEA12456DD852545184]
[34A3C54752046E79A126E15C51DB409B]
[DC5D737F51BE844D8C82C695EB17372F]
[D765D19CD8EF61F650C384F62FAC00AB]
[655661BE46B5F5F3FD454E2C3095B930]
[5F671AB5BC87EEA04EC38A6CD5962A47]
[C172A0F53008EAEB8EA33FE10E177AF5]
[DA6B67270FD9DB3697B20FCE94950741]
[D43703496149971890703B4B1B723EAC]
[1F7B25B858FA27015169FE95E54108ED]
[8C778D335C9D272CFD3298AB02ABE3B6]
[8E98D21EE06192492A5671A6144D092F]
[A1F556318931B9EA276F4E2DA2C1791C]
[7F56A3E09A6AD40B07E4EFAD34A40A18]
[23AF3730B7B757A385721E900250CF3B]
[F2523EF6460FC42405B12248338AB2F0]
[97BFED39B6B79EB12CDDBFEED51F56BB]
[975761C778E33CD22498059B91E7373A]
[A6518DCC42F7A6E999BB3BEA8FD87567]
[45540DAE98ED8E6C5376F616D8D5547C]
[2C3D7F56BA751941D0E7DA16934FBB5D]
[78E86380454A7B10A5EB255DC44A355F]
[7FD2A313F7AFE5C4DAB14798C48DD104]
[0A77D29F311B88CFAE3B13F9C1A73825]
[9592090A7E2B61CD582B612B6DF70536]
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
VMware, Inc.
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
HHD Software Ltd.
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
[39D2ABCD392F3D8A6DCE7B60AE7B8EFC]
[0EA7DE1ACB728DD5A369FD742D6EEE28]
[A5462BD6884960C9DC85ED49D34FF392]
[FA55C73D4AFFA7EE23AC4BE53B4592D3]
[3DF4395A7CF8B7A72A5F4606366B8C2D]
[5C18831C61933628F5BB0EA2675B9D21]
[F00F20E70C6EC3AA366910083A0518AA]
[ADA036632C664CAA754079041CF1F8C1]
[C9F0E1BD74365A8771590E9008D22AB6]
[0FC1AEA580957AA8817B8F305D18CA3A]
[AF9B39A7E7B6CAA203B3862582E9F2D0]
[3ABF5E7213EB28966D55D58B515D5CE9]
[2F7B28DC3E1183E5EB418DF55C204F38]
[BC02336F1CBA7DCC7D1213BB588A68A5]
[0705EFF5B42A9DB58548EEC3B26BB484]
[353009DEDF918B2A51414F330CF72DEC]
[1C2D8E18AA8FD50CD04C15CC27F7F5AB]
[6869281E78CB31A43E969F06B57347C4]
[1538831CF8AD2979A04C423779465827]
[1A93E54EB0ECE102495A51266DCDB6A6]
[1047184A9FDC8BDBFF857175875EE810]
[30F5C0DE1EE8B5BC9306C1F0E4A75F93]
[0504EACAFF0D3C8AED161C4B0D369D4A]
[43D0F98E1D56CCDDB0D5254CFF7B356E]
[A55805F747C6EDB6A9080D7C633BD0F4]
[BAF74CE0072480C3B6B7C13B2A94D6B3]
[800BA92F7010378B09F9ED9270F07137]
[B03D591DC7DA45ECE20B3B467E6AADAA]
[7D27EA49F3C1F687D357E77A470AEA99]
[D3BF052C40B0C4166D9FD86A4288C1E6]
[32E7A3D591D671A6DF2DB515A5CBE0FA]
[A44B420D30BD56E145D6A2BC8768EC58]
[6C38C9E45AE0EA2FA5E551F2ED5E978F]
[DC722758B8261E1ABAFD31A3C0A66380]
[A5D9106A73DC88564C825D317CAC68AC]
[D711B3C1D5F42C0C2415687BE09FC163]
[9423E9D355C8D303E76B8CFBD8A5C30C]
[C25F0BAFA182CBCA2DD3C851C2E75796]
[DB801A638D011B9633829EB6F663C900]
[F9D215A46A8B9753F61767FA72A20326]
[D916874BBD4F8B07BFB7FA9B3CCAE29D]
[D931D7309DEB2317035B07C9F9E6B0BD]
[49CCF2C4FEA34FFAD8B1B59D49439366]
[BDD71ACE35A232104DDD349EE70E1AB3]
[4ED981241DB27C3383D72092B618A1D0]
[0EED230E37515A0EAEE3C2E1BC97B288]
[2E66F9ECB30B4221A318C92AC2250779]
[7EA404308934E675BFFDE8EDF0757BCD]
[F9A18612FD3526FE473C1BDA678D61C8]
[79B47FD40D9A817E932F9D26FAC0A81C]
[9F9A1F53AAD7DA4D6FEF5BB73AB811AC]
[30639C932D9FEF22B31268FE25A1B6E5]
[136185F9FB2CC61E573E676AA5402356]
[53F7305169863F0A2BDDC49E116C2E11]
[86743D9F5D2B1048062B14B1D84501C4]
[09594D1089C523423B32A4229263F068]
[98F3ABC312BC0C660BA3F3B47782455E]
[417334447945C9E111FFD881F7BF4D08]
[986ACDECE933131288F1957DC359865F]
[77889813BE4D166CDAB78DDBA990DA92]
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
[E7F5AE18AF4168178A642A9247C63001]
[270D7CD42D6E3979F6DD0146650F0E05]
[5D9FD91F3D38DC9DA01E3CB5FA89CD48]
[F7CD50FE7139F07E77DA8AC8033D1832]
[1EA3749C4114DB3E3161156FFFFA6B33]
[3589478E4B22CE21B41FA1BFC0B8B8A0]
[0557CF5A2556BD58E26384169D72438D]
[0086431C29C35BE1DBC43F52CC273887]
[6DDCF3F801EC15FE698F6A215CF30A1F]
[E9766131EEADE40A27DC27D2D68FBA9C]
[94575C0571D1462A0F70BDE6BD6EE6B3]
[B5B8B5EF2E5CB34DF8DCF8831E3534FA]
[B2E81D4E87CE48589F98CB8C05B01F2F]
[D6B9C2E1A11A3A4B26A182FFEF18F603]
[68769C3356B3BE5D1C732C97B9A80D6E]
[50AD172D2DDF898FC1705199B60C3264]
[ADC5D126ABAB5AB5B806AE32B12125E7]
[0D922E23C041EFB1C3FAC2A6F943C9BF]
[A53A15A11EBFD21077463EE2C7AFEEF0]
[4F6D12B51DE1AAEFF7DC58C4D75423C8]
[76707BB36430888D9CE9D705398ADB6C]
[5A0DA8AD5762FA2D91678A8A01311704]
[471815800AE33E6F1C32FB1B97C490CA]
[855C9B1CD4756C5E9A2AA58A15F58C25]
[F92A2C41117A11A00BE01CA01A7FCDE9]
[E8B1E447B008D07FF47D016C2B0EEECB]
[77F665941019A1594D887A74F301FA2F]
[302DA2A0539F2CF54D7C6CC30C1F2D8D]
[CEA6CC257FC9B7715F1C2B4849286D24]
[1B6163C503398B23FF8B939C67747683]
[BB5971A4F00659529A5C44831AF22365]
[216F3FA57533D98E1F74DED70113177A]
[70CBA1A0C98600A2AA1863479B35CB90]
[34ED295FA0121C241BFEF24764FC4520]
[9C3AC71A9934B884FAC567A8807E9C4D]
[DDC86E4F8E7456261E637E3552E804FF]
[AC4CA62572CA516945AB92D6C9F501F4]
[B48DC6ABCD3AEFF8618350CCBDC6B09A]
[351533ACC2A069B94E80BBFC177E8FDF]
[AC03AF3329579FFFB455AA2DAABBE22B]
[253F38D0D7074C02FF8DEB9836C97D2B]
[07F83829E7429E60298440CD1E601A6A]
[CB624C0035412AF0DEBEC78C41F5CA1B]
[C1D8E28B2C2ADFAEC4BA89E9FDA69BD6]
[1C545A7D0691CC4A027396535691C3E3]
[A554811BCD09279536440C964AE35BBF]
[FF414F0BAEFEBA59BC6C04B3DB0B87BF]
[DD85B78243A19B59F0637DCF284DA63C]
[A9D601643A1647211A1EE2EC4E433FF4]
[843CAF1E5FDE1FFD5FF768F23A51E2E1]
[6A6C106D42E9FFFF8B9FCB4F754F6DA4]
[548260A7B8654E024DC30BF8A7C5BAA4]
[7B90D750DCBF72524DD38B105D29F8C1]
[441FBA48BFF01FDB9D5969EBC1838F0B]
[B4ADEBBF5E3677CCE9651E0F01F7CC28]
[27E461F0BE5BFF5FC737328F749538C3]
[30710AEFCE721CEEE0F35EB6A01C263C]
[91310683D7B6B292B746D60734B59322]
[B5D5A1846972B7F93BDC6333272D750E]
[F7093A27C4AF6D9EEA0ACAC1C4FF6828]
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Greatis Software, LLC
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
VS Revo Group
Microsoft Windows
Microsoft Windows
CACE Technologies, Inc.
CACE Technologies, Inc.
Microsoft Windows
Microsoft Windows
Intel(R) Code Signing External
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
[F3817967ED533D08327DC73BC4D5542A]
[D34E4943D5AC096C8EDEEBFD80D76E23]
[D01EC09B6711A5F8E7E6564A4D0FBC90]
[40AF23633D197905F03AB5628C558C51]
[DF687E3D8836BFB04FCC0615BF15A519]
[3371D21011695B16333A3934340C4E7C]
[51C5ECEB1CDEE2468A1748BE550CFBC8]
[DDAD5A7AB24D8B65F8D724F5C20FD806]
[561E7E1F06895D78DE991E01DD0FB6E5]
[4CE278FC9671BA81A138D70823FCAA09]
[D11C783E3EF9A3C52C0EBE83CC5000E9]
[3566A8DAAFA27AF944F5D705EAA64894]
[B4DD609BD7E282BFC683CEC7EAAAAD67]
[FF4232A1A64012BAA1FD97C7B67DF593]
[4BFE1BC28391222894CBF1E7D0E42320]
[DC54A574663A895C8763AF0FA1FF7561]
[B2E8E8CB557B156DA5493BBDDCC1474D]
[24E8F8C3BDF9CEFC2135F9A3C399F37D]
[2C42E595E7E381596B9A14F88F5AE027]
[7B28E2FBE75115660FAB31079C0A9F29]
[B0435098C81D04CAFFF80DDB746CD3A2]
[DCA68B0943D6FA415F0C56C92158A83A]
[80B0F7D5CCF86CEB5D402EAAF61FEC31]
[18A85013A3E0F7E1755365D287443965]
[8D1196CFBB223621F2C67D45710F25BA]
[765A92D428A8DB88B960DA5A8D6089DC]
[73188F58FB384E75C4063D29413CEE3D]
[D76510CFA0FC09023077F22C2F979D86]
[DD253AFC3BC6CBA412342DE60C3647F3]
[1F775DA4CF1A3A1834207E975A72E9D7]
[C5C876CCFC083FF3B128F933823E87BD]
[53E92A310193CB3C03BEA963DE7D9CFC]
[DA4DA3F5E02943C2DC8C6ED875DE68DD]
[2CE2DF28C83AEAF30084E1B1EB253CBB]
[E5689D93FFE4E5D66C0178761240DD54]
[86EA3E79AE350FEA5331A1303054005F]
[7DE90B48F210D29649380545DB45A187]
[BE8E5E5D53ACF71D4E8E686B68C99B04]
[18AA5F4A3B1204AD00045EE5AD39BCDB]
[04CD4347CD9E8C40F78AD51F7FF426D0]
[748FD60D1B73F50020CFD126F940543F]
[7FBB3F1EBB009F9F711B02D599DB1CE6]
[E60C0A09F997826C7627B244195AB581]
[7785DC213270D2FC066538DAF94087E7]
[F347A28F63162FF82BDDAADC14935BA4]
[CB41CC41F83C9A6081A2AE71251A16D5]
[D2AAFD421940F640B407AEFAAEBD91B0]
[A255814907C89BE58B79EF2F189B843B]
[0D08D2F3B3FF84E433346669B5E0F639]
[5E2016EA6EBACA03C04FEAC5F330D997]
[108196FE0580A18AB6237EA36FD210F2]
[E7CE8988B98202A5CF429CA358D26CC5]
[36D4720B72B5C5D9CB2B9C29E9DF67A1]
[4E9440F4F152A7B944CB1663D3935A3E]
[356AFD78A6ED4457169241AC3965230C]
[72889E16FF12BA0F235467D6091B17DC]
[A3D04EBF5227886029B4532F20D026F7]
[E2C933EDBC389386EBE6D2BA953F43D8]
[611B23304BF067451A9FDEE01FBDD725]
[05ECAEC3E4529A7153B3136CEB49F0EC]
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Greatis Software LLC
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
VMware, Inc.
VMware, Inc.
Microsoft Windows
Microsoft Windows
Microsoft Windows
VMware, Inc.
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
VMware, Inc.
VMware, Inc.
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
[FE88B288356E7B47B74B13372ADD906D]
[F6FF8944478594D0E414D3F048F0D778]
[6BCC1D7D2FD2453957C5479A32364E52]
[AD12F5C7251BB8D575D560894E73CBBA]
[D3381DC54C34D79B22CEE0D65BA91B7C]
[CF8D590BE3373029D57AF80914190682]
[E2DDA8726DA9CB5B2C4000C9018A9633]
[024352FEEC9042260BB4CFB4D79A206B]
[4166F82BE4D24938977DD1746BE9B8A0]
[0438CAB2E03F4FB61455A7956026FE86]
[802496CB59A30349F9A6DD22D6947644]
[C4C183E6551084039EC862DA1C945E3D]
[19E41CCCEE697CC9465396B370929792]
[DBEFD454F8318A0EF691FDD2EAAB44EB]
[0D09040EF933C3216CA5DD98E1744902]
[277BBC7E1AA1EE957F573A10ECA7EF3A]
[BD9EB3958F213F96B97B1D897DEE006D]
[A3A132CBE48AF0324466469F2CAAE8A2]
[344789398EC3EE5A4E00C52B31847946]
[DA6C4B5FEEEA4DC7162B5D0C055EB967]
[142E90CF1A4C5B6E7505810E38B07B9F]
[098A91C54546A3B878DAD6A7E90A455B]
[A34A587FFFD45FA649FBA6D03784D257]
[B95F6501A2F8B2E78C697FEC401970CE]
[4F15D75ADF6156BF56ECED6D4A55C389]
[808E98FF49B155C522E6400953177B08]
[06DC527364A8CF48E472ECF2BA3F8403]
[5CE9241C030C004FF92037DF8F7401B0]
[B19C8390A1D641B9AC4490D4828A7B5E]
[387E72E739E15E3D37907A86D9FF98E2]
[EFDFB3DD38A4376F93E7985173813ABD]
[C1185803384AB3FEED115F79F109427F]
[F993A32249B66C9D622EA5592A8B76B8]
[45CFBFA8EDC3DF4E2B7FB0D0260FE051]
[D5BA242D4CF8E384DB90E6A8ED850B8C]
[204F3F58212B3E422C90BD9691A2DF28]
[0BE09CD858ABF9DF6ED259D57A1A1663]
[CA2A0750ED830678997695FF61B04C30]
[E40E80D0304A73E8D269F7141D77250B]
[254FB7A22D74E5511C73A3F6D802F192]
[54FFC9C8898113ACE189D4AA7199D2C1]
[1B7C3A37362C7B2890168C5FC61C8D9B]
[329FEB3452982A377726DEDAFE9BBDF0]
[A08C010D859F8EB42BDD7E1D55B8CA27]
[DE0ECE52236CFA3ED2DBFC03F28253A8]
[6AB66E16AA859232F64DEB66887A8C9C]
[1C81E1BEA4847F406BBDB74D19721CE6]
[E5B9A2FA94D21C44DA2B898DC326B0C2]
[A190DA6546501CB4146BBCC0B6A3F48B]
[45989C268EC2CC9EEA80030AF96CDA5A]
[E2A483E796D5FC7E447725FD01D98FA0]
[69A4347A8EAD86185EFF2F75755176E6]
[B94D3DACCF5882B697A1C53D00BE643A]
[847D3AE376C0817161A14A82C8922A9E]
[5F28111C648F1E24F7DBC87CDEB091B8]
[1EE99A89CC788ADA662441D1E9830529]
[D54BFDF3E0C953F823B3D0BFE4732528]
[7BBF670114373CE6A203FA155A9E0D0A]
[927463ECB02179F88E4B9A17568C63C3]
[3AEAA8B561E63452C655DC0584922257]
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Google Inc
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
[E08088A97F95345E181C3DFCE2C615EF]
[C7CF6A6E137463219E1259E3F0F0DD6C]
[3EAC4455472CC2C97107B5291E0DCAFE]
[5C78838B4D166D1A27DB3A8A820C799A]
[908ACB1F594274965A53926B10C81E89]
[C32ECB99AD25E9A04F01C8665DF29EF8]
[D619356B955EEFA642F5FF72755E8B3C]
[582AC6D9873E31DFA28A4547270862DD]
[1EA7969E3271CBC59E1730697DC74682]
[906191634E99AEA92C4816150BDA3732]
[8F26510C5383B8DBE976DE1CD00FC8C7]
[EE867A0870FC9E4972BA9EAAD35651E2]
[E4D94F24081440B5FC5AA556C7C62702]
[E4DC58CF7B3EA515AE917FF0D402A7BB]
[5C627D1B1138676C0A7AB2C2C190D123]
[9B7395789E3791A3B6D000FE6F8B131E]
[ED78427259134C63ED69804D2132B86C]
[481F70241D4EA038BB02590A30F15A23]
[262F6592C3299C005FD6BEC90FC4463A]
[6EA4234DC55346E0709560FE7C2C1972]
[AD31942BDF3D594C404874613BC2FE4D]
[BC617A4E1B4FA8DF523A061739A0BD87]
[C32AB8FA018EF34C0F113BD501436D21]
[0336CFFAFAAB87A11541F1CF1594B2B2]
[0B6231BF38174A1628C4AC812CC75804]
[427015D56DF17241F634611557146C57]
[AAF932B4011D14052955D4B212A4DA8D]
[6313F223E817CC09AA41811DAA7F541D]
[350A8C7BDBEE961221EB913A76B71186]
[B96C17B5DC1424D56EEA3A99E97428CD]
[E17E0188BB90FAE42D83E98707EFA59C]
[93D7D61317F3D4BC4F4E9F8A96A7DE45]
[D9F42719019740BAA6D1C6D536CBDAA6]
[51B52FBD583CDE8AA9BA62B8B4298F33]
[AB7AEBF58DAD8DAAB7A6C45E6A8885CB]
[C78655BC80301D76ED4FEF1C1EA40A7D]
[E08E46FDD841B7184194011CA1955A0B]
[A10B048B681C38E26CA90CD1BC123604]
[BF9CCC0BF39B418C8D0AE8B05CF95B7D]
[870726CDCC241A92785572628B89CC07]
[E3C61FD7B7C2557E1F1B0B4CEC713585]
[40F0849F65D13EE87B9A9AE3C1DD6823]
[1BE03AC720F4D302EA01D40F588162F6]
[2E648163254233755035B46DD7B89123]
[F0344071948D1A1FA732231785A0664C]
[7E7AFD841694F6AC397E99D75CEAD49D]
[CEED624D1291081B1B7D921FBB9C61D9]
[B6D8C1202DACA028AD94BDA2795CBBE9]
[3CBDEC8D06B9968ABA702EBA076364A1]
[25FBDEF06C4D92815B353F6E792C8129]
[6BA9D927DDED70BD1A9CADED45F8B184]
[A293DCD756D04D8492A750D03B9A297C]
[64B328D52DFC8CDA123093E3F6E4C37C]
[D47EC6A8E81633DD18D2436B19BAF6DE]
[BAFE84E637BF7388C96EF48D4D3FDD53]
[EDBB23CBCF2CDF727D64FF9B51A6070E]
[8D6B481601D01A456E75C3210F1830BE]
[D9B422F37FCAF61BD80E12CC03E84816]
[5DC2DA538FF0806950B73F798A2444ED]
[B60BA0BC31B0CB414593E169F6F21CC2]
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
MiniTool Solution Ltd
MiniTool Solution Ltd
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
CANON INC.
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
VMware, Inc.
VMware, Inc.
Microsoft Windows
[1C9D80CC3849B3788048078C26486E1A]
[3CEC96DE223E49EAAE3651FCF8FAEA6C]
[A3F5E8EC1316C3E2562B82694A251C9E]
[38B84C94C5A8AF291ADFEA478AE54F93]
[19B07E7E8915D701225DA41CB3877306]
[78F4E7F5C56CB9716238EB57DA4B6A75]
[3AA101E8EDAB2DB4131333F4325C76A3]
[7368A2AFD46E5A4481D1DE9D14848EDD]
[20F7441334B18CEE52027661DF4A6129]
[BF1FC3F79B863C914687A737C2F3D681]
[26AF184300C0868D854D5A3092234E24]
[1473768973453DE50DC738C2955FC4DD]
[3DB6D04E1C64272F8B14EB8BC4616280]
[C749025A679C5103E575E3B48E092C43]
[7E591867422DC788B9E5BD337A669A08]
[6D137963730144698CBD10F202E9F251]
[8DD52E8E6128F4B2DA92CE27402871C1]
[58F4493BF748A3A89689997B7BD00E95]
[851A1382EED3E3A7476DB004F4EE3E1A]
[4FADA86E62F18A1B2F42BA18AE24E6AA]
[96C6E7100D724C69FCF9E7BF590D1DCA]
[93221146D4EBBF314C29B23CD6CC391D]
[E8B1FE6669397D1772D8196DF0E57A9E]
[581B739BEF5B6B668E5308CFE956B84A]
Co., Ltd.
[BCB1310604AA415C4508708975B3931E]
[D9EF901DCA379CFE914E9FA13B73B4C4]
[7A95C95B6C4CF292D689106BCAE49543]
[9A3452B3C2A46C073166C5CF49FAD1AE]
[241A1900C52DCBA38B20A4F3671444E0]
[351533ACC2A069B94E80BBFC177E8FDF]
[2AFBB91BBD2378933B26E6D68C140D1B]
[1C7F1C3EA5894995E6C563E9AE9F029F]
[28FFB14117CCEDD7D2F124596AA9B785]
[EA85144F35EDE6EE25C484D4242FF2C8]
[59D16C3D5CC0D573256A01783ED5CCB4]
[E94C583CDE2348950155F2AF2876F34D]
[0B7E85364CB878E2AD531DB7B601A9E5]
[104A1070E90F1C530328E69B49718841]
[703FFD301AB900B047337C5D40FD6F96]
[E495E408C93141E8FC72DC0C6046DDFA]
[5CF640EDDB1E40A5AB1BB743BCDEC610]
[76F58DB8F85C125E0D6B3AA42F3BF1D0]
[5DF5D8CFD9B9573FA3B2C89D9061A240]
===
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Shenzhen Wondershare Information Technology
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
CACE Technologies, Inc.
Microsoft Windows
Microsoft Windows
Adobe Systems Incorporated
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows