Vous êtes sur la page 1sur 167

SpyHolesList Version:12.9 Build:8.70.0.

570-64b
17.10.2018 20:25:35
WinDir=C:\Windows
Startup=C:\Users\sukan\AppData\Roaming\Microsoft\Windows\Start
Menu\Programs\Startup\
Common Startup=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Windows 10 Enterprise (10.0.17763)
Internet Explorer 9.11.17763.0
DBS Version: 1.856
[Internet Explorer]
[Default Home Page] :HKLM Default_Page_URL=http://go.microsoft.com/fwlink/p/?
LinkId=255141
[Current Home Page] :HKCU Start Page=http://go.microsoft.com/fwlink/p/?
LinkId=255141
[Current Home Page] :HKCU HOMEOldSP=""
[Current Home Page] :HKCU Default_Page_URL=""
[Current Home Page] :HKLM Start Page=http://go.microsoft.com/fwlink/p/?
LinkId=255141
[Current Home Page] :HKLM HOMEOldSP=""
[All Users Search] :HKLM Default_Search_URL=http://go.microsoft.com/fwlink/?
LinkId=54896
[All Users Search] :HKLM Search Page=http://go.microsoft.com/fwlink/?LinkId=54896
[Current Home Page(x64)] :HKLM Start Page=http://go.microsoft.com/fwlink/p/?
LinkId=255141
[Current Home Page(x64)] :HKLM HOMEOldSP=""
[All Users Search(x64)] :HKLM Default_Search_URL=http://go.microsoft.com/fwlink/?
LinkId=54896
[All Users Search(x64)] :HKLM Search Page=http://go.microsoft.com/fwlink/?
LinkId=54896
[Current Users Search] :HKCU Default_Search_URL=""
[Current Users Search] :HKCU Search Page=http://go.microsoft.com/fwlink/?
LinkId=54896
[Current Users Search] :HKCU Search Bar=""
[IE Local Blank Page] :HKCU Local Page=%11%\blank.htm
[IE Local Blank Page] :HKLM Local Page=C:\Windows\SysWOW64\blank.htm
[Browser Helper Objects] {0055C089-8582-441B-A0BF-17B458C2A3A8}=C:\PROGRAM FILES
(X86)\INTERNET DOWNLOAD MANAGER\IDMIECC.DLL
### IDM Browser Helper Object Internet Download Manager, Tonec Inc. Internet
Download Manager Module 6, 30, 2, 1
[Browser Helper Objects] {31D09BA0-12F5-4CCE-BE8A-2923E76605DA}=C:\PROGRAM FILES
(X86)\MICROSOFT OFFICE\OFFICE16\OCHELPER.DLL
### Skype for Business Microsoft Corporation Microsoft Office 2016 16.0.4666.1000

[Browser Helper Objects] {D0498E0A-45B7-42AE-A9AA-


ABA463DBD3BF}=C:\PROGRA~2\MICROS~1\OFFICE16\GROOVEEX.DLL
### Microsoft OneDrive for Business Extensions Microsoft Corporation Microsoft
Office 2016 16.0.4546.1000
[Browser Helper Objects(x64)] {0055C089-8582-441B-A0BF-17B458C2A3A8}=C:\PROGRAM
FILES (X86)\INTERNET DOWNLOAD MANAGER\IDMIECC64.DLL
### IDM Browser Helper Object Internet Download Manager, Tonec Inc. Internet
Download Manager Module 6, 30, 2, 1
[Browser Helper Objects(x64)] {31D09BA0-12F5-4CCE-BE8A-2923E76605DA}=C:\PROGRAM
FILES\MICROSOFT OFFICE\OFFICE16\OCHELPER.DLL
### Skype for Business Microsoft Corporation Microsoft Office 2016 16.0.4666.1000

[Browser Helper Objects(x64)] {D0498E0A-45B7-42AE-A9AA-


ABA463DBD3BF}=C:\PROGRA~1\MICROS~1\OFFICE16\GROOVEEX.DLL
### Microsoft OneDrive for Business Extensions Microsoft Corporation Microsoft
Office 2016 16.0.4546.1000
[Auto Search URL] :HKCU provider=""
[Auto Search URL] :HKCU "Default Value"=""
[Search Assistant] :HKCU SearchAssistant=""
[Search Assistant] :HKLM SearchAssistant=""
[Search Assistant] :HKCU CustomizeSearch=""
[Search Assistant] :HKLM CustomizeSearch=""
[Search Provider for All Users] {0633EE93-D776-472f-A0FF-
E1416B8B2E3A}=http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
### Bing
[Search Provider for All Users] DefaultScope={0633EE93-D776-472f-A0FF-
E1416B8B2E3A}
[Search Provider for All Users(x64)] {0633EE93-D776-472f-A0FF-
E1416B8B2E3A}=http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
### Bing
[Search Provider for All Users(x64)] DefaultScope={0633EE93-D776-472f-A0FF-
E1416B8B2E3A}
[CustomizeSearch] :HKLM CustomizeSearch=""
[URLSearchHook] :HKCU {CFBFAE00-17A6-11D0-99CB-
00C04FD64497}=C:\WINDOWS\SYSWOW64\IEFRAME.DLL
### Internet Browser Microsoft Corporation Internet Explorer 11.00.17763.1
[Search URL Template] :HKLM 1=""
[Search URL Template] :HKLM 2=""
[Search URL Template] :HKLM 3=""
[Search URL Template] :HKLM 4=""
[Default Prefix] :HKLM "Default Value"=http://
[URL Default Prefixes] :HKLM ftp=ftp://
[URL Default Prefixes] :HKLM home=http://
[URL Default Prefixes] :HKLM mosaic=http://
[URL Default Prefixes] :HKLM www=http://
[AboutURLs] :HKLM blank=res://mshtml.dll/blank.htm
[AboutURLs] :HKLM DesktopItemNavigationFailure=res://ieframe.dll/navcancl.htm
[AboutURLs] :HKLM Home=270
[AboutURLs] :HKLM InPrivate=res://ieframe.dll/inprivate.htm
[AboutURLs] :HKLM NavigationCanceled=res://ieframe.dll/navcancl.htm
[AboutURLs] :HKLM NavigationFailure=res://ieframe.dll/navcancl.htm
[AboutURLs] :HKLM NoAdd-ons=res://ieframe.dll/noaddon.htm
[AboutURLs] :HKLM NoAdd-onsInfo=res://ieframe.dll/noaddoninfo.htm
[AboutURLs] :HKLM PostNotCached=res://ieframe.dll/repost.htm
[AboutURLs] :HKLM SecurityRisk=res://ieframe.dll/securityatrisk.htm
[User Style Sheet] :HKCU User Stylesheet=""
[User Style Sheet] :HKCU Use My Stylesheet=0
[Execute unsigned ActiveX in My Computer Zone] :HKCU 1201=0
[Execute unsigned ActiveX in My Computer Zone] :HKLM 1201=1
[Execute unsigned ActiveX in Local Intranet Zone] :HKCU 1201=0
[Execute unsigned ActiveX in Local Intranet Zone] :HKLM 1201=3
[Execute unsigned ActiveX in Internet Zone] :HKCU 1201=3
[Execute unsigned ActiveX in Internet Zone] :HKLM 1201=3
[Links Toolbar] :HKCU LinksFolderName=""
[IE Extensions - All Users] :HKLM {31D09BA0-12F5-4CCE-BE8A-
2923E76605DA}=C:\PROGRAM FILES (X86)\MICROSOFT OFFICE\OFFICE16\OCHELPER.DLL
### Skype for Business Microsoft Corporation Microsoft Office 2016 16.0.4666.1000

[Context menu items] :HKCU Download all links with IDM=C:\PROGRAM FILES
(X86)\INTERNET DOWNLOAD MANAGER\IEGETALL.HTM
[Context menu items] :HKCU Download with IDM=C:\PROGRAM FILES (X86)\INTERNET
DOWNLOAD MANAGER\IEEXT.HTM
[Context menu items] :HKCU E&xport to Microsoft
Excel=res://C:\PROGRA~1\MICROS~1\Office16\EXCEL.EXE/3000
### File is missing.
[Context menu items] :HKCU Se&nd to
OneNote=res://C:\PROGRA~1\MICROS~1\Office16\ONBttnIE.dll/105
### File is missing.
[AutoConfigURL] :HKCU AutoConfigURL=""
[Protocols Filter] :HKLM application/octet-stream=C:\WINDOWS\SYSWOW64\MSCOREE.DLL
### Microsoft .NET Runtime Execution Engine Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1
[Protocols Filter] :HKLM application/x-complus=C:\WINDOWS\SYSWOW64\MSCOREE.DLL
### Microsoft .NET Runtime Execution Engine Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1
[Protocols Filter] :HKLM application/x-msdownload=C:\WINDOWS\SYSWOW64\MSCOREE.DLL
### Microsoft .NET Runtime Execution Engine Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1
[Protocols Filter] :HKLM text/xml=C:\PROGRAM FILES (X86)\COMMON FILES\MICROSOFT
SHARED\OFFICE16\MSOXMLMF.DLL
### Microsoft Office XML MIME Filter Microsoft Corporation Microsoft Office
InfoPath 16.0.4567.1000
[Protocols Handler] :HKLM about=C:\WINDOWS\SYSWOW64\MSHTML.DLL
### Microsoft (R) HTML Viewer Microsoft Corporation Internet Explorer
11.00.17763.1
[Protocols Handler] :HKLM cdl=C:\WINDOWS\SYSWOW64\URLMON.DLL
### OLE32 Extensions for Win32 Microsoft Corporation Internet Explorer
11.00.17763.1
[Protocols Handler] :HKLM dvd=C:\WINDOWS\SYSWOW64\MSVIDCTL.DLL
### ActiveX control for streaming video Microsoft Corporation DirectShow
6.5.17763.1
[Protocols Handler] :HKLM file=C:\WINDOWS\SYSWOW64\URLMON.DLL
### OLE32 Extensions for Win32 Microsoft Corporation Internet Explorer
11.00.17763.1
[Protocols Handler] :HKLM ftp=C:\WINDOWS\SYSWOW64\URLMON.DLL
### OLE32 Extensions for Win32 Microsoft Corporation Internet Explorer
11.00.17763.1
[Protocols Handler] :HKLM http=C:\WINDOWS\SYSWOW64\URLMON.DLL
### OLE32 Extensions for Win32 Microsoft Corporation Internet Explorer
11.00.17763.1
[Protocols Handler] :HKLM https=C:\WINDOWS\SYSWOW64\URLMON.DLL
### OLE32 Extensions for Win32 Microsoft Corporation Internet Explorer
11.00.17763.1
[Protocols Handler] :HKLM its=C:\WINDOWS\SYSWOW64\ITSS.DLL
### Microsoft� InfoTech Storage System Library Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1
[Protocols Handler] :HKLM javascript=C:\WINDOWS\SYSWOW64\MSHTML.DLL
### Microsoft (R) HTML Viewer Microsoft Corporation Internet Explorer
11.00.17763.1
[Protocols Handler] :HKLM local=C:\WINDOWS\SYSWOW64\URLMON.DLL
### OLE32 Extensions for Win32 Microsoft Corporation Internet Explorer
11.00.17763.1
[Protocols Handler] :HKLM mailto=C:\WINDOWS\SYSWOW64\MSHTML.DLL
### Microsoft (R) HTML Viewer Microsoft Corporation Internet Explorer
11.00.17763.1
[Protocols Handler] :HKLM mhtml=C:\WINDOWS\SYSWOW64\INETCOMM.DLL
### Microsoft Internet Messaging API Resources Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1
[Protocols Handler] :HKLM mk=C:\WINDOWS\SYSWOW64\URLMON.DLL
### OLE32 Extensions for Win32 Microsoft Corporation Internet Explorer
11.00.17763.1
[Protocols Handler] :HKLM ms-help={314111c7-a502-11d2-bbca-00c04f8ec294}
[Protocols Handler] :HKLM ms-its=C:\WINDOWS\SYSWOW64\ITSS.DLL
### Microsoft� InfoTech Storage System Library Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1
[Protocols Handler] :HKLM mso-minsb.16=C:\PROGRAM FILES (X86)\MICROSOFT
OFFICE\OFFICE16\MSOSB.DLL
### Microsoft Office 2016 component Microsoft Corporation Microsoft Office 2016
16.0.4666.1000
[Protocols Handler] :HKLM osf.16=C:\PROGRAM FILES (X86)\MICROSOFT
OFFICE\OFFICE16\MSOSB.DLL
### Microsoft Office 2016 component Microsoft Corporation Microsoft Office 2016
16.0.4666.1000
[Protocols Handler] :HKLM res=C:\WINDOWS\SYSWOW64\MSHTML.DLL
### Microsoft (R) HTML Viewer Microsoft Corporation Internet Explorer
11.00.17763.1
[Protocols Handler] :HKLM tbauth=C:\WINDOWS\SYSWOW64\TBAUTH.DLL
### TBAuth protocol handler Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1
[Protocols Handler] :HKLM tv=C:\WINDOWS\SYSWOW64\MSVIDCTL.DLL
### ActiveX control for streaming video Microsoft Corporation DirectShow
6.5.17763.1
[Protocols Handler] :HKLM vbscript=C:\WINDOWS\SYSWOW64\MSHTML.DLL
### Microsoft (R) HTML Viewer Microsoft Corporation Internet Explorer
11.00.17763.1
[Protocols Handler] :HKLM windows.tbauth=C:\WINDOWS\SYSWOW64\TBAUTH.DLL
### TBAuth protocol handler Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1
[Proxy] :HKCU ProxyServer=""
[Proxy] :HKCU ProxyEnable=0
[Network Settings]
[Hosts File Path] :HKLM DataBasePath=%SystemRoot%\System32\drivers\etc
[Browsers]
[Installed Browsers] Google Chrome=C:\PROGRAM FILES
(X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE
### Google Chrome Google Inc. Google Chrome 69.0.3497.100
[Installed Browsers] IEXPLORE.EXE=C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
### Default Browser
Internet Explorer Microsoft Corporation Internet Explorer 11.00.17763.1
[Google Chrome Settings] :HKLM backup.homepage=""
[Google Chrome Settings] :HKLM backup.session.urls_to_restore_on_startup=""
[Google Chrome Settings] :HKLM session.startup_urls=""
[Google Chrome Settings] :HKLM default_search_provider.icon_url=""
[Google Chrome Settings] :HKLM default_search_provider.keyword=""
[Google Chrome Settings] :HKLM default_search_provider.name=""
[Google Chrome Settings] :HKLM default_search_provider.search_url=""
[Google Chrome Settings] :HKLM default_search_provider.suggest_url=""
[Google Chrome Settings] :HKLM
default_search_provider_data.template_url_data.alternate_urls=""
[Google Chrome Settings] :HKLM
default_search_provider_data.template_url_data.favicon_url=""
[Google Chrome Settings] :HKLM
default_search_provider_data.template_url_data.keyword=""
[Google Chrome Settings] :HKLM
default_search_provider_data.template_url_data.short_name=""
[Google Chrome Settings] :HKLM
default_search_provider_data.template_url_data.url=""
[Google Chrome Settings] :HKLM
default_search_provider_data.template_url_data.suggest_url=""
[Google Chrome Settings] :HKLM
default_search_provider_data.template_url_data.new_tab_url=""
[Google Chrome Settings] :HKLM
default_search_provider_data.template_url_data.instant_url=""
[Google Chrome Settings] :HKLM
default_search_provider_data.template_url_data.image_url=""
[Google Chrome Settings] :HKLM homepage=""
[Google Chrome Settings] :HKLM session.urls_to_restore_on_startup=""
[Google Chrome Addons]
blpcfgokakmgnkcojhhkbfbldkacnbeo=C:\Users\sukan\AppData\Local\Google\Chrome\User
Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0
### : Disabled
update_url: http://clients2.google.com/service/update2/crx
[Google Chrome Addons]
nmmhkkegccagdldgiimedpiccmgmieda=C:\Users\sukan\AppData\Local\Google\Chrome\User
Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.4_0
### : Disabled
update_url: https://clients2.google.com/service/update2/crx
[Google Chrome Addons]
pkedcjkdefgpdelpbcmbmeomcjbeemfm=C:\Users\sukan\AppData\Local\Google\Chrome\User
Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\6918.723.0.0_0
### Chrome Media Router: Disabled
update_url: https://clients2.google.com/service/update2/crx
[Network Settings]
[Domain Name] :HKLM Domain=""
[Name Server] {24a8a45a-86dd-454e-8100-19b74dbe4ac5}=192.168.43.1
### DHCPNameServer:192.168.43.1 DhcpDefaultGateway:192.168.43.1
DhcpServer:192.168.43.1
[WinSock2 Components] napinsp.dll=C:\WINDOWS\SYSWOW64\NAPINSP.DLL
### E-mail Naming Shim Provider Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%SystemRoot%\SYSWOW64\napinsp.dll
[WinSock2 Components] pnrpnsp.dll=C:\WINDOWS\SYSWOW64\PNRPNSP.DLL
### PNRP Name Space Provider Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*%SystemRoot%\SYSWOW64\pnrpnsp.dll
[WinSock2 Components] mswsock.dll=C:\WINDOWS\SYSWOW64\MSWSOCK.DLL
### Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation
Microsoft� Windows� Operating System 10.0.17763.1 !$*%SystemRoot
%\SYSWOW64\mswsock.dll
[WinSock2 Components] winrnr.dll=C:\WINDOWS\SYSWOW64\WINRNR.DLL
### LDAP RnR Provider DLL Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*%SystemRoot%\SYSWOW64\winrnr.dll
[WinSock2 Components] NLAapi.dll=C:\WINDOWS\SYSWOW64\NLAAPI.DLL
### Network Location Awareness 2 Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%SystemRoot%\SYSWOW64\NLAapi.dll
[WinSock2 Components] wshbth.dll=C:\WINDOWS\SYSWOW64\WSHBTH.DLL
### Windows Sockets Helper DLL Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%SystemRoot%\SYSWOW64\wshbth.dll
[WinSock2 Components (x64)] napinsp.dll=C:\WINDOWS\SYSNATIVE\NAPINSP.DLL
### E-mail Naming Shim Provider Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%SystemRoot%\SYSNATIVE\napinsp.dll
[WinSock2 Components (x64)] pnrpnsp.dll=C:\WINDOWS\SYSNATIVE\PNRPNSP.DLL
### PNRP Name Space Provider Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*%SystemRoot%\SYSNATIVE\pnrpnsp.dll
[WinSock2 Components (x64)] mswsock.dll=C:\WINDOWS\SYSNATIVE\MSWSOCK.DLL
### Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation
Microsoft� Windows� Operating System 10.0.17763.1 !$*%SystemRoot
%\SYSNATIVE\mswsock.dll
[WinSock2 Components (x64)] winrnr.dll=C:\WINDOWS\SYSNATIVE\WINRNR.DLL
### LDAP RnR Provider DLL Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*%SystemRoot%\SYSNATIVE\winrnr.dll
[WinSock2 Components (x64)] NLAapi.dll=C:\WINDOWS\SYSNATIVE\NLAAPI.DLL
### Network Location Awareness 2 Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%SystemRoot%\SYSNATIVE\NLAapi.dll
[WinSock2 Components (x64)] wshbth.dll=C:\WINDOWS\SYSNATIVE\WSHBTH.DLL
### Windows Sockets Helper DLL Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%SystemRoot%\SYSNATIVE\wshbth.dll
[Windows Shell]
[Display Scrap's Extensions] :HKLM NeverShowExt=""
[ScreenSaver] :HKCU SCRNSAVE.EXE=""
### File is missing.
[System.ini] shell=explorer.exe
[User Shell] :HKCU shell=""
[User Shortcuts] :HKLM C:\Users\sukan\Desktop\Internet Download
Manager.lnk=C:\PROGRAM FILES (X86)\INTERNET DOWNLOAD MANAGER\IDMAN.EXE
### Internet Download Manager (IDM) Tonec Inc. Internet Download Manager (IDM) 6,
30, 7, 2 !$*C:\Users\sukan\Desktop\INTERN~1.LNK
[User Shortcuts] :HKLM
C:\Users\sukan\Desktop\UnHackMe.lnk=C:\UNHACKME\UNHACKME.EXE
### Detects and removes rootkits Greatis Software UnHackMe 8.70 !
$*C:\Users\sukan\Desktop\UnHackMe.lnk
[User Shortcuts] :HKLM C:\Users\Public\Desktop\CCleaner.lnk=C:\PROGRAM
FILES\CCLEANER\CCLEANER64.EXE
### CCleaner Piriform Ltd CCleaner 5, 29, 00, 6033 !
$*C:\Users\Public\Desktop\CCleaner.lnk
[User Shortcuts] :HKLM C:\Users\Public\Desktop\Foxit Reader.lnk=C:\PROGRAM FILES
(X86)\FOXIT SOFTWARE\FOXIT READER\FOXITREADER.EXE
### Foxit Reader 8.2 Foxit Software Inc. Foxit Reader 8.2.1.6871 !
$*C:\Users\Public\Desktop\FOXITR~1.LNK
[User Shortcuts] :HKLM C:\Users\Public\Desktop\SDFormatter.lnk=C:\PROGRAM FILES
(X86)\SDA\SD FORMATTER\SDFORMATTER.EXE
### Format Tool for SD Card [Normal Area Only] TRENDY Corporation SD Formatter
V4.0.0.0 4, 0, 0, 0 !$*C:\Users\Public\Desktop\SDFORM~1.LNK
[User Shortcuts] :HKLM C:\Users\Public\Desktop\SHAREit.lnk=C:\PROGRAM FILES
(X86)\SHAREIT TECHNOLOGIES\SHAREIT\SHAREIT.EXE
### SHAREit SHAREit Technologies Co.Ltd SHAREit 4.0.6.177 !
$*C:\Users\Public\Desktop\SHAREit.lnk
[User Shortcuts] :HKLM C:\Users\Public\Desktop\VLC media player.lnk=C:\PROGRAM
FILES\VIDEOLAN\VLC\VLC.EXE
### VLC media player VideoLAN VLC media player 3,0,4,0 !
$*C:\Users\Public\Desktop\VLCMED~1.LNK
[User Shortcuts] :HKLM C:\Users\sukan\AppData\Roaming\Microsoft\Internet
Explorer\Quick Launch\Foxit Reader.lnk=C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\FOXIT
READER\FOXITREADER.EXE
### Foxit Reader 8.2 Foxit Software Inc. Foxit Reader 8.2.1.6871 !
$*C:\Users\sukan\AppData\Roaming\MICROS~1\INTERN~1\QUICKL~1\FOXITR~1.LNK
[User Shortcuts] :HKLM C:\Users\sukan\AppData\Roaming\Microsoft\Internet
Explorer\Quick Launch\Google Chrome.lnk=C:\PROGRAM FILES
(X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE
### Google Chrome Google Inc. Google Chrome 69.0.3497.100 !
$*C:\Users\sukan\AppData\Roaming\MICROS~1\INTERN~1\QUICKL~1\GOOGLE~1.LNK
[User Shortcuts] :HKLM C:\Users\sukan\AppData\Roaming\Microsoft\Internet
Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk=C:\PROGRAM FILES
(X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE
### Google Chrome Google Inc. Google Chrome 69.0.3497.100 !
$*C:\Users\sukan\AppData\Roaming\MICROS~1\INTERN~1\QUICKL~1\USERPI~1\TaskBar\GOOGLE
~1.LNK
[User Shortcuts] :HKLM C:\ProgramData\Microsoft\Windows\Start
Menu\Programs\Google Chrome.lnk=C:\PROGRAM FILES
(X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE
### Google Chrome Google Inc. Google Chrome 69.0.3497.100 !
$*C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\GOOGLE~1.LNK
[User Shortcuts] :HKLM C:\ProgramData\Microsoft\Windows\Start
Menu\Programs\Internet Download Manager\Internet Download Manager.lnk=C:\PROGRAM
FILES (X86)\INTERNET DOWNLOAD MANAGER\IDMAN.EXE
### Internet Download Manager (IDM) Tonec Inc. Internet Download Manager (IDM) 6,
30, 7, 2 !$*C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\INTERN~1\INTERN~1.LNK
[Main File Extensions] :HKLM .exe=""
[Main File Extensions] :HKLM .com=""
[Main File Extensions] :HKLM .pif=""
[Main File Extensions] :HKLM .bat=""
[Main File Extensions] :HKLM .cmd=""
[Main File Extensions] :HKLM .scr=""
[Main File Extensions] :HKLM .txt=""
[Main File Extensions] :HKLM .reg=""
[Main File Extensions] :HKLM .inf=""
[Main File Extensions] :HKLM .ini=""
[Main File Extensions] :HKLM .js=""
[Main File Extensions] :HKLM .vbs=""
[Main File Extensions] :HKLM .vbe=""
[Main File Extensions] :HKLM .msc=""
[Main File Extensions] :HKLM .jpg=""
[Main File Extensions] :HKLM .jpeg=""
[Main File Extensions] :HKLM .gif=""
[Main File Extensions] :HKLM .png=""
[UserInit Value] UserInit=""
[UserInit Value(x64)] UserInit=C:\Windows\system32\userinit.exe,
### Userinit Logon Application Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1
[Shell Services DelayLoad] :HKLM WebCheck={E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[System Shell Policies ] :HKCU shell=""
[System Shell Policies ] :HKLM shell=""
[System Shell Policies ] :HKCU run=""
[System Shell Policies ] :HKLM run=""
[Prevents Display in Control Panel from running.] :HKCU NoDispCpl=0
[Disable Registry Tools] :HKCU DisableRegistryTools =0
[Print Monitors] :HKLM Appmon=C:\Windows\SYSTEM32\APPMON.DLL
### App Printer Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*AppMon.dll
[Print Monitors] :HKLM Local Port=C:\Windows\SYSTEM32\LOCALSPL.DLL
### Local Spooler DLL Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*localspl.dll
[Print Monitors] :HKLM Microsoft Shared Fax
Monitor=C:\Windows\SYSTEM32\FXSMON.DLL
### Microsoft Fax Print Monitor Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*FXSMON.DLL
[Print Monitors] :HKLM Standard TCP/IP Port=C:\Windows\SYSTEM32\TCPMON.DLL
### Standard TCP/IP Port Monitor DLL Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*tcpmon.dll
[Print Monitors] :HKLM USB Monitor=C:\Windows\SYSTEM32\USBMON.DLL
### Standard Dynamic Printing Port Monitor DLL Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 !$*usbmon.dll
[Print Monitors] :HKLM WSD Port=C:\Windows\SYSTEM32\APMON.DLL
### Adaptive Port Monitor Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*APMon.dll
[Shell Icon Overlay Handlers] :HKLM OneDrive1={BBACC218-34EA-4666-9D7A-
C78F2274A524}
[Shell Icon Overlay Handlers] :HKLM OneDrive2={5AB7172C-9C11-405C-8DD5-
AF20F3606282}
[Shell Icon Overlay Handlers] :HKLM OneDrive3={A78ED123-AB77-406B-9962-
2A5D9D2F7F30}
[Shell Icon Overlay Handlers] :HKLM OneDrive4={F241C880-6982-4CE5-8CF7-
7085BA96DA5A}
[Shell Icon Overlay Handlers] :HKLM OneDrive5={A0396A93-DC06-4AEF-BEE9-
95FFCCAEF20E}
[Shell Icon Overlay Handlers] :HKLM OneDrive6={9AA2F32D-362A-42D9-9328-
24A483E2CCC3}
[Shell Icon Overlay Handlers] :HKLM OneDrive7={C5FF006E-2AE9-408C-B85B-
2DFDD5449D9C}
[Shell Icon Overlay Handlers] :HKLM SkyDrivePro1
(ErrorConflict)=C:\PROGRA~2\MICROS~1\OFFICE16\GROOVEEX.DLL
### Microsoft OneDrive for Business Extensions Microsoft Corporation Microsoft
Office 2016 16.0.4546.1000
[Shell Icon Overlay Handlers] :HKLM SkyDrivePro2
(SyncInProgress)=C:\PROGRA~2\MICROS~1\OFFICE16\GROOVEEX.DLL
### Microsoft OneDrive for Business Extensions Microsoft Corporation Microsoft
Office 2016 16.0.4546.1000
[Shell Icon Overlay Handlers] :HKLM SkyDrivePro3
(InSync)=C:\PROGRA~2\MICROS~1\OFFICE16\GROOVEEX.DLL
### Microsoft OneDrive for Business Extensions Microsoft Corporation Microsoft
Office 2016 16.0.4546.1000
[Context Menu Handlers] :HKLM EPP={09A47860-11B0-4DA5-AFA5-26D86198A780}
[Context Menu Handlers] :HKLM Foxit_ConvertToPDF_Reader={A94757A0-0226-426F-B4F1-
4DF381C630D3}
[Context Menu Handlers] :HKLM ModernSharing=C:\WINDOWS\SYSTEM32\NTSHRUI.DLL
### Shell extensions for sharing Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%SystemRoot%\system32\ntshrui.dll
[Context Menu Handlers] :HKLM Open With=C:\WINDOWS\SYSTEM32\SHELL32.DLL
### Windows Shell Common Dll Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*%SystemRoot%\system32\shell32.dll
[Context Menu Handlers] :HKLM Open With
EncryptionMenu=C:\WINDOWS\SYSTEM32\SHELL32.DLL
### Windows Shell Common Dll Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*%SystemRoot%\system32\shell32.dll
[Context Menu Handlers] :HKLM Sharing=C:\WINDOWS\SYSTEM32\NTSHRUI.DLL
### Shell extensions for sharing Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%SystemRoot%\system32\ntshrui.dll
[Context Menu Handlers] :HKLM WinRAR={B41DB860-64E4-11D2-9906-E49FADC173CA}
[Context Menu Handlers] :HKLM WinRAR32=C:\PROGRAM FILES\WINRAR\RAREXT32.DLL
### WinRAR shell extension Alexander Roshal WinRAR 5.50.0
[Context Menu Handlers] :HKLM WorkFolders={E61BF828-5E63-4287-BEF1-60B1A4FDE0E3}
[Context Menu Handlers] :HKLM {90AA3A4E-1CBA-4233-B8BB-
535773D48449}=C:\WINDOWS\SYSTEM32\SHELL32.DLL
### Windows Shell Common Dll Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*%SystemRoot%\system32\shell32.dll
[Context Menu Handlers] :HKLM {a2a9545d-a0c2-42b4-9708-
a0b2badd77c8}=C:\WINDOWS\SYSTEM32\SHELL32.DLL
### Windows Shell Common Dll Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*%SystemRoot%\system32\shell32.dll
[App Paths] :HKLM ccleaner.exe=C:\Program Files\CCleaner\CCleaner64.exe
### ccleaner.exe CCleaner Piriform Ltd CCleaner 5, 29, 00, 6033
[App Paths] :HKLM chrome.exe=C:\Program Files
(x86)\Google\Chrome\Application\chrome.exe
### chrome.exe Google Chrome Google Inc. Google Chrome 69.0.3497.100
[App Paths] :HKLM cmmgr32.exe
### cmmgr32.exe
[App Paths] :HKLM dfshim.dll
### dfshim.dll
[App Paths] :HKLM excel.exe=C:\PROGRA~1\MICROS~1\Office16\EXCEL.EXE
### excel.exe Microsoft Excel Microsoft Corporation Microsoft Office 2016
16.0.4666.1000
[App Paths] :HKLM foxitreader.exe=C:\Program Files (x86)\Foxit Software\Foxit
Reader\FoxitReader.exe
### foxitreader.exe Foxit Reader 8.2 Foxit Software Inc. Foxit Reader 8.2.1.6871
[App Paths] :HKLM fsquirt.exe
### fsquirt.exe
[App Paths] :HKLM GROOVE.EXE=C:\PROGRA~1\MICROS~1\Office16\GROOVE.EXE
### GROOVE.EXE Microsoft OneDrive for Business Microsoft Corporation Microsoft
Office 2016 16.0.4528.1000
[App Paths] :HKLM IEDIAG.EXE=C:\Program Files\Internet Explorer\IEDIAGCMD.EXE
### IEDIAG.EXE Diagnostics utility for Internet Explorer Microsoft Corporation
Internet Explorer 11.00.17763.1
[App Paths] :HKLM IEDIAGCMD.EXE=C:\Program Files\Internet Explorer\IEDIAGCMD.EXE
### IEDIAGCMD.EXE Diagnostics utility for Internet Explorer Microsoft Corporation
Internet Explorer 11.00.17763.1
[App Paths] :HKLM IEXPLORE.EXE=C:\Program Files\Internet Explorer\IEXPLORE.EXE
### IEXPLORE.EXE Internet Explorer Microsoft Corporation Internet Explorer
11.00.17763.1
[App Paths] :HKLM install.exe
### install.exe
[App Paths] :HKLM licensemanagershellext.exe=%SystemRoot
%\System32\licensemanagershellext.exe
### licensemanagershellext.exe
[App Paths] :HKLM Lync.exe=C:\Program Files\Microsoft Office\Office16\Lync.exe
### Lync.exe Skype for Business Microsoft Corporation Microsoft Office 2016
16.0.4678.1000
[App Paths] :HKLM mip.exe=%CommonProgramFiles%\Microsoft Shared\Ink\mip.exe
### mip.exe
[App Paths] :HKLM mplayer2.exe=%ProgramFiles(x86)%\Windows Media
Player\wmplayer.exe
### mplayer2.exe
[App Paths] :HKLM MSACCESS.EXE=C:\PROGRA~1\MICROS~1\Office16\MSACCESS.EXE
### MSACCESS.EXE Microsoft Access Microsoft Corporation Microsoft Office 2016
16.0.4666.1000
[App Paths] :HKLM MsoHtmEd.exe
### MsoHtmEd.exe
[App Paths] :HKLM msoxmled.exe=C:\Program Files\Common Files\Microsoft
Shared\OFFICE16\MSOXMLED.EXE
### msoxmled.exe Office XML Handler Microsoft Corporation Microsoft Office
InfoPath 16.0.4567.1000
[App Paths] :HKLM MSPUB.EXE=C:\PROGRA~1\MICROS~1\Office16\MSPUB.EXE
### MSPUB.EXE Microsoft Publisher Microsoft Corporation Microsoft Office 2016
16.0.4573.1000
[App Paths] :HKLM OneNote.exe=C:\PROGRA~1\MICROS~1\Office16\ONENOTE.EXE
### OneNote.exe Microsoft OneNote Microsoft Corporation Microsoft OneNote
16.0.4666.1000
[App Paths] :HKLM OUTLOOK.EXE=C:\PROGRA~1\MICROS~1\Office16\OUTLOOK.EXE
### OUTLOOK.EXE Microsoft Outlook Microsoft Corporation Microsoft Outlook
16.0.4678.1000
[App Paths] :HKLM pbrush.exe=%SystemRoot%\System32\mspaint.exe
### pbrush.exe
[App Paths] :HKLM powerpnt.exe=C:\PROGRA~1\MICROS~1\Office16\POWERPNT.EXE
### powerpnt.exe Microsoft PowerPoint Microsoft Corporation Microsoft Office 2016
16.0.4266.1001
[App Paths] :HKLM PowerShell.exe=%SystemRoot
%\system32\WindowsPowerShell\v1.0\PowerShell.exe
### PowerShell.exe
[App Paths] :HKLM setup.exe
### setup.exe
[App Paths] :HKLM SnippingTool.exe=%SystemRoot%\system32\SnippingTool.exe
### SnippingTool.exe
[App Paths] :HKLM table30.exe
### table30.exe
[App Paths] :HKLM TabTip.exe=%CommonProgramFiles%\microsoft shared\ink\TabTip.exe
### TabTip.exe
[App Paths] :HKLM vlc.exe=C:\Program Files\VideoLAN\VLC\vlc.exe
### vlc.exe VLC media player VideoLAN VLC media player 3,0,4,0
[App Paths] :HKLM vstoee.dll
### vstoee.dll
[App Paths] :HKLM wab.exe=%ProgramFiles%\Windows Mail\wab.exe
### wab.exe
[App Paths] :HKLM wabmig.exe=%ProgramFiles%\Windows Mail\wabmig.exe
### wabmig.exe
[App Paths] :HKLM WinRAR.exe=C:\Program Files\WinRAR\WinRAR.exe
### WinRAR.exe WinRAR archiver Alexander Roshal WinRAR 5.50.0
[App Paths] :HKLM Winword.exe=C:\PROGRA~1\MICROS~1\Office16\WINWORD.EXE
### Winword.exe Microsoft Word Microsoft Corporation Microsoft Office 2016
16.0.4666.1000
[App Paths] :HKLM wmplayer.exe=%ProgramFiles(x86)%\Windows Media
Player\wmplayer.exe
### wmplayer.exe
[App Paths] :HKLM WORDPAD.EXE=C:\PROGRAM FILES\WINDOWS NT\ACCESSORIES\WORDPAD.EXE
### WORDPAD.EXE Windows Wordpad Application Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 !$*"%ProgramFiles%\Windows
NT\Accessories\WORDPAD.EXE"
[App Paths] :HKLM WRITE.EXE="%ProgramFiles%\Windows NT\Accessories\WORDPAD.EXE"
### WRITE.EXE
[Kernel Auto Boot]
[ActiveSetup] >{22d6f312-b0f6-11d0-94ab-
0080c74c7e95}=C:\WINDOWS\SYSTEM32\UNREGMP2.EXE
### Microsoft Windows Media Player Setup Utility Microsoft Corporation Microsoft�
Windows� Operating System 12.0.17763.1 !$*%SystemRoot%\system32\unregmp2.exe
/ShowWMP
[Auto Services] :HKLM AJRouter
### Service: AllJoyn Router Service Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Routes AllJoyn messages for the
local AllJoyn clients. If this service is stopped the AllJoyn clients that do not
have their own bundled routers will be unable to run. Host Process for Windows
Services Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1 !
$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICENETWORKRESTRICTED -P
[Auto Services] :HKLM ALG
### Service: Application Layer Gateway Service Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\ALG.EXE * Provides support for
3rd party protocol plug-ins for Internet Connection Sharing Application Layer
Gateway Service Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\ALG.EXE
[Auto Services] :HKLM AppIDSvc
### Service: Application Identity Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Determines and verifies the identity
of an application. Disabling this service will prevent AppLocker from being
enforced. Host Process for Windows Services Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
LOCALSERVICENETWORKRESTRICTED -P
[Auto Services] :HKLM Appinfo
### Service: Application Information Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Facilitates the running of
interactive applications with additional administrative privileges. If this
service is stopped, users will be unable to launch applications with the additional
administrative privileges they may require to perform desired user tasks. Host
Process for Windows Services Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS -P
[Auto Services] :HKLM AppMgmt
### Service: Application Management Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Processes installation, removal, and
enumeration requests for software deployed through Group Policy. If the service is
disabled, users will be unable to install, remove, or enumerate software deployed
through Group Policy. If this service is disabled, any services that explicitly
depend on it will fail to start. Host Process for Windows Services Microsoft
Corporation Microsoft� Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K NETSVCS -P
[Auto Services] :HKLM AppReadiness
### Service: App Readiness Status: Start Type: loaded manually on demand Actual
File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Gets apps ready for use the first time a
user signs in to this PC and when adding new apps. Host Process for Windows
Services Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1 !
$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K APPREADINESS -P
[Auto Services] :HKLM AppXSvc
### Service: AppX Deployment Service (AppXSVC) Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Provides
infrastructure support for deploying Store applications. This service is started on
demand and if disabled Store applications will not be deployed to the system, and
may not function properly. Host Process for Windows Services Microsoft Corporation
Microsoft� Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K WSAPPX -P
[Auto Services] :HKLM AssignedAccessManagerSvc
### Service: AssignedAccessManager Service Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * AssignedAccessManager Service
supports kiosk experience in Windows. Host Process for Windows Services Microsoft
Corporation Microsoft� Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K ASSIGNEDACCESSMANAGERSVC
[Auto Services] :HKLM AudioEndpointBuilder
### Service: Windows Audio Endpoint Builder Status: Start Type: loaded
automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE *
Manages audio devices for the Windows Audio service. If this service is stopped,
audio devices and effects will not function properly. If this service is disabled,
any services that explicitly depend on it will fail to start Host Process for
Windows Services Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED
-P
[Auto Services] :HKLM Audiosrv
### Service: Windows Audio Status: Start Type: loaded automatically by Server
Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Manages audio for Windows-
based programs. If this service is stopped, audio devices and effects will not
function properly. If this service is disabled, any services that explicitly
depend on it will fail to start Host Process for Windows Services Microsoft
Corporation Microsoft� Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICENETWORKRESTRICTED -P
[Auto Services] :HKLM AxInstSV
### Service: ActiveX Installer (AxInstSV) Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Provides User Account Control
validation for the installation of ActiveX controls from the Internet and enables
management of ActiveX control installation based on Group Policy settings. This
service is started on demand and if disabled the installation of ActiveX controls
will behave according to default browser settings. Host Process for Windows
Services Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1 !
$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K AXINSTSVGROUP
[Auto Services] :HKLM BcastDVRUserService
### Service: GameDVR and Broadcast User Service Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * This user service
is used for Game Recordings and Live Broadcasts Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K BCASTDVRUSERSERVICE
[Auto Services] :HKLM BcastDVRUserService_127d39
### Service: GameDVR and Broadcast User Service_127d39 Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * This user service
is used for Game Recordings and Live Broadcasts Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1 !
$*C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K BCASTDVRUSERSERVICE
[Auto Services] :HKLM BDESVC
### Service: BitLocker Drive Encryption Service Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * BDESVC hosts the
BitLocker Drive Encryption service. BitLocker Drive Encryption provides secure
startup for the operating system, as well as full volume encryption for OS, fixed
or removable volumes. This service allows BitLocker to prompt users for various
actions related to their volumes when mounted, and unlocks volumes automatically
without user interaction. Additionally, it stores recovery information to Active
Directory, if available, and, if necessary, ensures the most recent recovery
certificates are used. Stopping or disabling the service would prevent users from
leveraging this functionality. Host Process for Windows Services Microsoft
Corporation Microsoft� Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K NETSVCS -P
[Auto Services] :HKLM BFE
### Service: Base Filtering Engine Status: Start Type: loaded automatically by
Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * The Base Filtering
Engine (BFE) is a service that manages firewall and Internet Protocol security
(IPsec) policies and implements user mode filtering. Stopping or disabling the BFE
service will significantly reduce the security of the system. It will also result
in unpredictable behavior in IPsec management and firewall applications. Host
Process for Windows Services Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
LOCALSERVICENONETWORKFIREWALL -P
[Auto Services] :HKLM BITS
### Service: Background Intelligent Transfer Service Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Transfers files
in the background using idle network bandwidth. If the service is disabled, then
any applications that depend on BITS, such as Windows Update or MSN Explorer, will
be unable to automatically download programs and other information. Host Process
for Windows Services Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS -P
[Auto Services] :HKLM BluetoothUserService
### Service: Bluetooth User Support Service Status: Start Type: loaded manually
on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * The Bluetooth user service
supports proper functionality of Bluetooth features relevant to each user session.
Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K BTHAPPGROUP
-P
[Auto Services] :HKLM BluetoothUserService_127d39
### Service: Bluetooth User Support Service_127d39 Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * The Bluetooth
user service supports proper functionality of Bluetooth features relevant to each
user session. Host Process for Windows Services Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 !$*C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K
BTHAPPGROUP -P
[Auto Services] :HKLM BrokerInfrastructure
### Service: Background Tasks Infrastructure Service Status: Start Type: loaded
automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE *
Windows infrastructure service that controls which background tasks can run on the
system. Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K DCOMLAUNCH -P
[Auto Services] :HKLM BTAGService
### Service: Bluetooth Audio Gateway Service Status: Start Type: loaded manually
on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Service supporting the
audio gateway role of the Bluetooth Handsfree Profile. Host Process for Windows
Services Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1 !
$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICENETWORKRESTRICTED
[Auto Services] :HKLM BthAvctpSvc
### Service: AVCTP service Status: Start Type: loaded manually on demand Actual
File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * This is Audio Video Control Transport
Protocol service Host Process for Windows Services Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
LOCALSERVICE -P
[Auto Services] :HKLM bthserv
### Service: Bluetooth Support Service Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * The Bluetooth service
supports discovery and association of remote Bluetooth devices. Stopping or
disabling this service may cause already installed Bluetooth devices to fail to
operate properly and prevent new devices from being discovered or associated. Host
Process for Windows Services Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE -P
[Auto Services] :HKLM camsvc
### Service: Capability Access Manager Service Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Provides
facilities for managing UWP apps access to app capabilities as well as checking an
app's access to specific app capabilities Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K APPMODEL -P
[Auto Services] :HKLM CaptureService
### Service: CaptureService Status: Start Type: loaded manually on demand Actual
File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * OneCore Capture Service Host Process for
Windows Services Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE -P
[Auto Services] :HKLM CaptureService_127d39
### Service: CaptureService_127d39 Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * OneCore Capture Service Host Process
for Windows Services Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE -P
[Auto Services] :HKLM cbdhsvc
### Service: Clipboard User Service Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * This user service is used for
Clipboard scenarios Host Process for Windows Services Microsoft Corporation
Microsoft� Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K CLIPBOARDSVCGROUP -P
[Auto Services] :HKLM cbdhsvc_127d39
### Service: Clipboard User Service_127d39 Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * This user service is used for
Clipboard scenarios Host Process for Windows Services Microsoft Corporation
Microsoft� Windows� Operating System 10.0.17763.1 !
$*C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K CLIPBOARDSVCGROUP -P
[Auto Services] :HKLM CDPSvc
### Service: Connected Devices Platform Service Status: Start Type: loaded
automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * This
service is used for Connected Devices Platform scenarios Host Process for Windows
Services Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1 !
$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE -P
[Auto Services] :HKLM CDPUserSvc
### Service: Connected Devices Platform User Service Status: Start Type: loaded
automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * This
user service is used for Connected Devices Platform scenarios Host Process for
Windows Services Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K UNISTACKSVCGROUP
[Auto Services] :HKLM CDPUserSvc_127d39
### Service: Connected Devices Platform User Service_127d39 Status: Start Type:
loaded automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE
* This user service is used for Connected Devices Platform scenarios Host Process
for Windows Services Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K UNISTACKSVCGROUP
[Auto Services] :HKLM CertPropSvc
### Service: Certificate Propagation Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Copies user certificates and
root certificates from smart cards into the current user's certificate store,
detects when a smart card is inserted into a smart card reader, and, if needed,
installs the smart card Plug and Play minidriver. Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS
[Auto Services] :HKLM ClipSVC
### Service: Client License Service (ClipSVC) Status: Start Type: loaded manually
on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Provides infrastructure
support for the Microsoft Store. This service is started on demand and if disabled
applications bought using Windows Store will not behave correctly. Host Process for
Windows Services Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K WSAPPX -P
[Auto Services] :HKLM COMSysApp
### Service: COM+ System Application Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\DLLHOST.EXE * Manages the configuration and
tracking of Component Object Model (COM)+-based components. If the service is
stopped, most COM+-based components will not function properly. If this service is
disabled, any services that explicitly depend on it will fail to start. COM
Surrogate Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1 !
$*%SYSTEMROOT%\SYSTEM32\DLLHOST.EXE /PROCESSID:{02D4B3F1-FD88-11D1-960D-
00805FC79235}
[Auto Services] :HKLM ConsentUxUserSvc
### Service: ConsentUX Status: Start Type: loaded manually on demand Actual File:
C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Allows ConnectUX and PC Settings to Connect and
Pair with WiFi displays and Bluetooth devices. Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K DEVICESFLOW
[Auto Services] :HKLM ConsentUxUserSvc_127d39
### Service: ConsentUX_127d39 Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Allows ConnectUX and PC Settings to
Connect and Pair with WiFi displays and Bluetooth devices. Host Process for Windows
Services Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1 !
$*C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K DEVICESFLOW
[Auto Services] :HKLM CoreMessagingRegistrar
### Service: CoreMessaging Status: Start Type: loaded automatically by Server
Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Manages communication
between system components. Host Process for Windows Services Microsoft Corporation
Microsoft� Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICENONETWORK -P
[Auto Services] :HKLM cphs
### Service: Intel(R) Content Protection HECI Service Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSWOW64\INTELCPHECISVC.EXE * Intel(R)
Content Protection HECI Service - enables communication with the Content Protection
FW IntelCpHeciSvc Executable Intel Corporation IntelCpHeciSvc Executable
9.0.20.9000 !$*%SYSTEMROOT%\SYSWOW64\INTELCPHECISVC.EXE
[Auto Services] :HKLM CryptSvc
### Service: Cryptographic Services Status: Start Type: loaded automatically by
Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Provides three
management services: Catalog Database Service, which confirms the signatures of
Windows files and allows new programs to be installed; Protected Root Service,
which adds and removes Trusted Root Certification Authority certificates from this
computer; and Automatic Root Certificate Update Service, which retrieves root
certificates from Windows Update and enable scenarios such as SSL. If this service
is stopped, these management services will not function properly. If this service
is disabled, any services that explicitly depend on it will fail to start. Host
Process for Windows Services Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETWORKSERVICE -P
[Auto Services] :HKLM CscService
### Service: Offline Files Status: Start Type: loaded manually on demand Actual
File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * The Offline Files service performs
maintenance activities on the Offline Files cache, responds to user logon and
logoff events, implements the internals of the public API, and dispatches
interesting events to those interested in Offline Files activities and changes in
cache state. Host Process for Windows Services Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
LOCALSYSTEMNETWORKRESTRICTED -P
[Auto Services] :HKLM DcomLaunch
### Service: DCOM Server Process Launcher Status: Start Type: loaded
automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * The
DCOMLAUNCH service launches COM and DCOM servers in response to object activation
requests. If this service is stopped or disabled, programs using COM or DCOM will
not function properly. It is strongly recommended that you have the DCOMLAUNCH
service running. Host Process for Windows Services Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
DCOMLAUNCH -P
[Auto Services] :HKLM defragsvc
### Service: Optimize drives Status: Start Type: loaded manually on demand Actual
File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Helps the computer run more efficiently by
optimizing files on storage drives. Host Process for Windows Services Microsoft
Corporation Microsoft� Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K DEFRAGSVC
[Auto Services] :HKLM DeviceAssociationService
### Service: Device Association Service Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Enables pairing between the
system and wired or wireless devices. Host Process for Windows Services Microsoft
Corporation Microsoft� Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED -P
[Auto Services] :HKLM DeviceInstall
### Service: Device Install Service Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Enables a computer to recognize and
adapt to hardware changes with little or no user input. Stopping or disabling this
service will result in system instability. Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K DCOMLAUNCH -P
[Auto Services] :HKLM DevicePickerUserSvc
### Service: DevicePicker Status: Start Type: loaded manually on demand Actual
File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * This user service is used for managing the
Miracast, DLNA, and DIAL UI Host Process for Windows Services Microsoft Corporation
Microsoft� Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K DEVICESFLOW
[Auto Services] :HKLM DevicePickerUserSvc_127d39
### Service: DevicePicker_127d39 Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * This user service is used for
managing the Miracast, DLNA, and DIAL UI Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1 !
$*C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K DEVICESFLOW
[Auto Services] :HKLM DevicesFlowUserSvc
### Service: DevicesFlow Status: Start Type: loaded manually on demand Actual
File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Allows ConnectUX and PC Settings to Connect
and Pair with WiFi displays and Bluetooth devices. Host Process for Windows
Services Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1 !
$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K DEVICESFLOW
[Auto Services] :HKLM DevicesFlowUserSvc_127d39
### Service: DevicesFlow_127d39 Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Allows ConnectUX and PC Settings to
Connect and Pair with WiFi displays and Bluetooth devices. Host Process for Windows
Services Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1 !
$*C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K DEVICESFLOW
[Auto Services] :HKLM DevQueryBroker
### Service: DevQuery Background Discovery Broker Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Enables apps to
discover devices with a backgroud task Host Process for Windows Services Microsoft
Corporation Microsoft� Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED -P
[Auto Services] :HKLM Dhcp
### Service: DHCP Client Status: Start Type: loaded automatically by Server
Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Registers and updates IP
addresses and DNS records for this computer. If this service is stopped, this
computer will not receive dynamic IP addresses and DNS updates. If this service is
disabled, any services that explicitly depend on it will fail to start. Host
Process for Windows Services Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
LOCALSERVICENETWORKRESTRICTED -P
[Auto Services] :HKLM diagnosticshub.standardcollector.service
### Service: Microsoft (R) Diagnostics Hub Standard Collector Service Status:
Start Type: loaded manually on demand Actual File:
C:\WINDOWS\SYSTEM32\DIAGSVCS\DIAGNOSTICSHUB.STANDARDCOLLECTOR.SERVICE.EXE *
Diagnostics Hub Standard Collector Service. When running, this service collects
real time ETW events and processes them. Microsoft (R) Diagnostics Hub Standard
Collector Microsoft Corporation Internet Explorer 11.00.17763.1 !$*%SYSTEMROOT
%\SYSTEM32\DIAGSVCS\DIAGNOSTICSHUB.STANDARDCOLLECTOR.SERVICE.EXE
[Auto Services] :HKLM diagsvc
### Service: Diagnostic Execution Service Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Executes diagnostic actions
for troubleshooting support Host Process for Windows Services Microsoft Corporation
Microsoft� Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K DIAGNOSTICS
[Auto Services] :HKLM DiagTrack
### Service: Connected User Experiences and Telemetry Status: Start Type: loaded
automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * The
Connected User Experiences and Telemetry service enables features that support in-
application and connected user experiences. Additionally, this service manages the
event driven collection and transmission of diagnostic and usage information (used
to improve the experience and quality of the Windows Platform) when the diagnostics
and usage privacy option settings are enabled under Feedback and Diagnostics. Host
Process for Windows Services Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K UTCSVC -P
[Auto Services] :HKLM DisplayEnhancementService
### Service: Display Enhancement Service Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * A service for managing
display enhancement such as brightness control. Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED -P
[Auto Services] :HKLM DmEnrollmentSvc
### Service: Device Management Enrollment Service Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Performs Device
Enrollment Activities for Device Management Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS -P
[Auto Services] :HKLM dmwappushservice
### Service: Device Management Wireless Application Protocol (WAP) Push message
Routing Service Status: Start Type: loaded automatically by Server Manager Actual
File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Routes Wireless Application Protocol (WAP)
Push messages received by the device and synchronizes Device Management sessions
Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS -P
[Auto Services] :HKLM Dnscache
### Service: DNS Client Status: Start Type: loaded automatically by Server
Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * The DNS Client service
(dnscache) caches Domain Name System (DNS) names and registers the full computer
name for this computer. If the service is stopped, DNS names will continue to be
resolved. However, the results of DNS name queries will not be cached and the
computer's name will not be registered. If the service is disabled, any services
that explicitly depend on it will fail to start. Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETWORKSERVICE -P
[Auto Services] :HKLM DoSvc
### Service: Delivery Optimization Status: Start Type: loaded automatically by
Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Performs content
delivery optimization tasks Host Process for Windows Services Microsoft Corporation
Microsoft� Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K NETWORKSERVICE -P
[Auto Services] :HKLM dot3svc
### Service: Wired AutoConfig Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * The Wired AutoConfig (DOT3SVC)
service is responsible for performing IEEE 802.1X authentication on Ethernet
interfaces. If your current wired network deployment enforces 802.1X
authentication, the DOT3SVC service should be configured to run for establishing
Layer 2 connectivity and/or providing access to network resources. Wired networks
that do not enforce 802.1X authentication are unaffected by the DOT3SVC service.
Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
LOCALSYSTEMNETWORKRESTRICTED -P
[Auto Services] :HKLM DPS
### Service: Diagnostic Policy Service Status: Start Type: loaded automatically
by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * The Diagnostic
Policy Service enables problem detection, troubleshooting and resolution for
Windows components. If this service is stopped, diagnostics will no longer
function. Host Process for Windows Services Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
LOCALSERVICENONETWORK -P
[Auto Services] :HKLM DsmSvc
### Service: Device Setup Manager Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Enables the detection, download and
installation of device-related software. If this service is disabled, devices may
be configured with outdated software, and may not work correctly. Host Process for
Windows Services Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS -P
[Auto Services] :HKLM DsSvc
### Service: Data Sharing Service Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Provides data brokering between
applications. Host Process for Windows Services Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
LOCALSYSTEMNETWORKRESTRICTED -P
[Auto Services] :HKLM DusmSvc
### Service: Data Usage Status: Start Type: loaded automatically by Server
Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Network data usage, data
limit, restrict background data, metered networks. Host Process for Windows
Services Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1 !
$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICENETWORKRESTRICTED -P
[Auto Services] :HKLM Eaphost
### Service: Extensible Authentication Protocol Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * The Extensible
Authentication Protocol (EAP) service provides network authentication in such
scenarios as 802.1x wired and wireless, VPN, and Network Access Protection (NAP).
EAP also provides application programming interfaces (APIs) that are used by
network access clients, including wireless and VPN clients, during the
authentication process. If you disable this service, this computer is prevented
from accessing networks that require EAP authentication. Host Process for Windows
Services Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1 !
$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS -P
[Auto Services] :HKLM EFS
### Service: Encrypting File System (EFS) Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\LSASS.EXE * Provides the core file
encryption technology used to store encrypted files on NTFS file system volumes. If
this service is stopped or disabled, applications will be unable to access
encrypted files. Local Security Authority Process Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\LSASS.EXE
[Auto Services] :HKLM embeddedmode
### Service: Embedded Mode Status: Start Type: loaded manually on demand Actual
File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * The Embedded Mode service enables scenarios
related to Background Applications. Disabling this service will prevent Background
Applications from being activated. Host Process for Windows Services Microsoft
Corporation Microsoft� Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED -P
[Auto Services] :HKLM EntAppSvc
### Service: Enterprise App Management Service Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Enables
enterprise application management. Host Process for Windows Services Microsoft
Corporation Microsoft� Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K APPMODEL -P
[Auto Services] :HKLM EventLog
### Service: Windows Event Log Status: Start Type: loaded automatically by Server
Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * This service manages events
and event logs. It supports logging events, querying events, subscribing to events,
archiving event logs, and managing event metadata. It can display events in both
XML and plain text format. Stopping this service may compromise security and
reliability of the system. Host Process for Windows Services Microsoft Corporation
Microsoft� Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICENETWORKRESTRICTED -P
[Auto Services] :HKLM EventSystem
### Service: COM+ Event System Status: Start Type: loaded automatically by Server
Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Supports System Event
Notification Service (SENS), which provides automatic distribution of events to
subscribing Component Object Model (COM) components. If the service is stopped,
SENS will close and will not be able to provide logon and logoff notifications. If
this service is disabled, any services that explicitly depend on it will fail to
start. Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE
-P
[Auto Services] :HKLM Fax
### Service: Fax Status: Start Type: loaded manually on demand Actual File:
C:\WINDOWS\SYSTEM32\FXSSVC.EXE * Enables you to send and receive faxes, utilizing
fax resources available on this computer or on the network. Fax Service Microsoft
Corporation Microsoft� Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT
%\SYSTEM32\FXSSVC.EXE
[Auto Services] :HKLM fdPHost
### Service: Function Discovery Provider Host Status: Start Type: loaded manually
on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * The FDPHOST service hosts
the Function Discovery (FD) network discovery providers. These FD providers supply
network discovery services for the Simple Services Discovery Protocol (SSDP) and
Web Services � Discovery (WS-D) protocol. Stopping or disabling the FDPHOST service
will disable network discovery for these protocols when using FD. When this service
is unavailable, network services using FD and relying on these discovery protocols
will be unable to find network devices or resources. Host Process for Windows
Services Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1 !
$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE -P
[Auto Services] :HKLM FDResPub
### Service: Function Discovery Resource Publication Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Publishes this
computer and resources attached to this computer so they can be discovered over the
network. If this service is stopped, network resources will no longer be published
and they will not be discovered by other computers on the network. Host Process for
Windows Services Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICEANDNOIMPERSONATION
-P
[Auto Services] :HKLM fhsvc
### Service: File History Service Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Protects user files from accidental
loss by copying them to a backup location Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED -P
[Auto Services] :HKLM FontCache
### Service: Windows Font Cache Service Status: Start Type: loaded automatically
by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Optimizes
performance of applications by caching commonly used font data. Applications will
start this service if it is not already running. It can be disabled, though doing
so will degrade application performance. Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE -P
[Auto Services] :HKLM FontCache3.0.0.0
### Service: Windows Presentation Foundation Font Cache 3.0.0.0 Status: Start
Type: loaded manually on demand Actual File:
C:\WINDOWS\MICROSOFT.NET\FRAMEWORK64\V3.0\WPF\PRESENTATIONFONTCACHE.EXE * Optimizes
performance of Windows Presentation Foundation (WPF) applications by caching
commonly used font data. WPF applications will start this service if it is not
already running. It can be disabled, though doing so will degrade the performance
of WPF applications. PresentationFontCache.exe Microsoft Corporation Microsoft�
.NET Framework 3.0.6920.9034 !$*%SYSTEMROOT
%\MICROSOFT.NET\FRAMEWORK64\V3.0\WPF\PRESENTATIONFONTCACHE.EXE
[Auto Services] :HKLM FoxitReaderService
### Service: Foxit Reader Service Status: Start Type: loaded automatically by
Server Manager Actual File: C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\FOXIT
READER\FOXITCONNECTEDPDFSERVICE.EXE * Foxit Reader ConnectedPDF Windows Service.
Foxit Software Inc. Foxit ConnectedPDF Windows Service. 8.2.0.1206 !$*"C:\PROGRAM
FILES (X86)\FOXIT SOFTWARE\FOXIT READER\FOXITCONNECTEDPDFSERVICE.EXE"
[Auto Services] :HKLM FrameServer
### Service: Windows Camera Frame Server Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Enables multiple clients to
access video frames from camera devices. Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K CAMERA
[Auto Services] :HKLM gpsvc
### Service: Group Policy Client Status: Start Type: loaded automatically by
Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * The service is
responsible for applying settings configured by administrators for the computer and
users through the Group Policy component. If the service is disabled, the settings
will not be applied and applications and components will not be manageable through
Group Policy. Any components or applications that depend on the Group Policy
component might not be functional if the service is disabled. Host Process for
Windows Services Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS -P
[Auto Services] :HKLM GraphicsPerfSvc
### Service: GraphicsPerfSvc Status: Start Type: loaded manually on demand Actual
File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Graphics performance monitor service Host
Process for Windows Services Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K GRAPHICSPERFSVCGROUP
[Auto Services] :HKLM gupdate
### Service: Google Update Service (gupdate) Status: Start Type: loaded
automatically by Server Manager Actual File: C:\PROGRAM FILES
(X86)\GOOGLE\UPDATE\GOOGLEUPDATE.EXE * Keeps your Google software up to date. If
this service is disabled or stopped, your Google software will not be kept up to
date, meaning security vulnerabilities that may arise cannot be fixed and features
may not work. This service uninstalls itself when there is no Google software using
it. Google Installer Google Inc. Google Update 1.3.33.7 !$*"C:\PROGRAM FILES
(X86)\GOOGLE\UPDATE\GOOGLEUPDATE.EXE" /SVC
[Auto Services] :HKLM gupdatem
### Service: Google Update Service (gupdatem) Status: Start Type: loaded manually
on demand Actual File: C:\PROGRAM FILES (X86)\GOOGLE\UPDATE\GOOGLEUPDATE.EXE *
Keeps your Google software up to date. If this service is disabled or stopped, your
Google software will not be kept up to date, meaning security vulnerabilities that
may arise cannot be fixed and features may not work. This service uninstalls itself
when there is no Google software using it. Google Installer Google Inc. Google
Update 1.3.33.7 !$*"C:\PROGRAM FILES (X86)\GOOGLE\UPDATE\GOOGLEUPDATE.EXE" /MEDSVC
[Auto Services] :HKLM hidserv
### Service: Human Interface Device Service Status: Start Type: loaded manually
on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Activates and maintains
the use of hot buttons on keyboards, remote controls, and other multimedia devices.
It is recommended that you keep this service running. Host Process for Windows
Services Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1 !
$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED -P
[Auto Services] :HKLM HvHost
### Service: HV Host Service Status: Start Type: loaded manually on demand Actual
File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Provides an interface for the Hyper-V
hypervisor to provide per-partition performance counters to the host operating
system. Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
LOCALSYSTEMNETWORKRESTRICTED -P
[Auto Services] :HKLM icssvc
### Service: Windows Mobile Hotspot Service Status: Start Type: loaded manually
on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Provides the ability to
share a cellular data connection with another device. Host Process for Windows
Services Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1 !
$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICENETWORKRESTRICTED -P
[Auto Services] :HKLM igfxCUIService1.0.0.0
### Service: Intel(R) HD Graphics Control Panel Service Status: Start Type:
loaded automatically by Server Manager Actual File:
C:\WINDOWS\SYSTEM32\IGFXCUISERVICE.EXE * Service for Intel(R) HD Graphics Control
Panel igfxCUIService Module Intel Corporation Intel(R) Common User Interface
6.15.10.4252 !$*%SYSTEMROOT%\SYSTEM32\IGFXCUISERVICE.EXE
[Auto Services] :HKLM IKEEXT
### Service: IKE and AuthIP IPsec Keying Modules Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * The IKEEXT
service hosts the Internet Key Exchange (IKE) and Authenticated Internet Protocol
(AuthIP) keying modules. These keying modules are used for authentication and key
exchange in Internet Protocol security (IPsec). Stopping or disabling the IKEEXT
service will disable IKE and AuthIP key exchange with peer computers. IPsec is
typically configured to use IKE or AuthIP; therefore, stopping or disabling the
IKEEXT service might result in an IPsec failure and might compromise the security
of the system. It is strongly recommended that you have the IKEEXT service running.
Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS -P
[Auto Services] :HKLM InstallService
### Service: Microsoft Store Install Service Status: Start Type: loaded manually
on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Provides infrastructure
support for the Microsoft Store. This service is started on demand and if disabled
then installations will not function properly. Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS -P
[Auto Services] :HKLM iphlpsvc
### Service: IP Helper Status: Start Type: loaded automatically by Server Manager
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Provides tunnel connectivity using
IPv6 transition technologies (6to4, ISATAP, Port Proxy, and Teredo), and IP-HTTPS.
If this service is stopped, the computer will not have the enhanced connectivity
benefits that these technologies offer. Host Process for Windows Services Microsoft
Corporation Microsoft� Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K NETSVCS -P
[Auto Services] :HKLM IpxlatCfgSvc
### Service: IP Translation Configuration Service Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Configures and
enables translation from v4 to v6 and vice versa Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED -P
[Auto Services] :HKLM irmon
### Service: Infrared monitor service Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Detects other Infrared
devices that are in range and launches the file transfer application. Stopping the
service will prevent file transfer from working Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED -P
[Auto Services] :HKLM KeyIso
### Service: CNG Key Isolation Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\LSASS.EXE * The CNG key isolation service is
hosted in the LSA process. The service provides key process isolation to private
keys and associated cryptographic operations as required by the Common Criteria.
The service stores and uses long-lived keys in a secure process complying with
Common Criteria requirements. Local Security Authority Process Microsoft
Corporation Microsoft� Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT
%\SYSTEM32\LSASS.EXE
[Auto Services] :HKLM KtmRm
### Service: KtmRm for Distributed Transaction Coordinator Status: Start Type:
loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE *
Coordinates transactions between the Distributed Transaction Coordinator (MSDTC)
and the Kernel Transaction Manager (KTM). If it is not needed, it is recommended
that this service remain stopped. If it is needed, both MSDTC and KTM will start
this service automatically. If this service is disabled, any MSDTC transaction
interacting with a Kernel Resource Manager will fail and any services that
explicitly depend on it will fail to start. Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETWORKSERVICEANDNOIMPERSONATION -P
[Auto Services] :HKLM LanmanServer
### Service: Server Status: Start Type: loaded automatically by Server Manager
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Supports file, print, and named-pipe
sharing over the network for this computer. If this service is stopped, these
functions will be unavailable. If this service is disabled, any services that
explicitly depend on it will fail to start. Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS -P
[Auto Services] :HKLM LanmanWorkstation
### Service: Workstation Status: Start Type: loaded automatically by Server
Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Creates and maintains client
network connections to remote servers using the SMB protocol. If this service is
stopped, these connections will be unavailable. If this service is disabled, any
services that explicitly depend on it will fail to start. Host Process for Windows
Services Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1 !
$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETWORKSERVICE -P
[Auto Services] :HKLM lfsvc
### Service: Geolocation Service Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * This service monitors the current
location of the system and manages geofences (a geographical location with
associated events). If you turn off this service, applications will be unable to
use or receive notifications for geolocation or geofences. Host Process for Windows
Services Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1 !
$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS -P
[Auto Services] :HKLM LicenseManager
### Service: Windows License Manager Service Status: Start Type: loaded manually
on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Provides infrastructure
support for the Microsoft Store. This service is started on demand and if disabled
then content acquired through the Microsoft Store will not function properly. Host
Process for Windows Services Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE -P
[Auto Services] :HKLM lltdsvc
### Service: Link-Layer Topology Discovery Mapper Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Creates a Network
Map, consisting of PC and device topology (connectivity) information, and metadata
describing each PC and device. If this service is disabled, the Network Map will
not function properly. Host Process for Windows Services Microsoft Corporation
Microsoft� Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE -P
[Auto Services] :HKLM lmhosts
### Service: TCP/IP NetBIOS Helper Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Provides support for the NetBIOS
over TCP/IP (NetBT) service and NetBIOS name resolution for clients on the network,
therefore enabling users to share files, print, and log on to the network. If this
service is stopped, these functions might be unavailable. If this service is
disabled, any services that explicitly depend on it will fail to start. Host
Process for Windows Services Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
LOCALSERVICENETWORKRESTRICTED -P
[Auto Services] :HKLM LSM
### Service: Local Session Manager Status: Start Type: loaded automatically by
Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Core Windows Service
that manages local user sessions. Stopping or disabling this service will result in
system instability. Host Process for Windows Services Microsoft Corporation
Microsoft� Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K DCOMLAUNCH -P
[Auto Services] :HKLM LxpSvc
### Service: Language Experience Service Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Provides infrastructure
support for deploying and configuring localized Windows resources. This service is
started on demand and, if disabled, additional Windows languages will not be
deployed to the system, and Windows may not function properly. Host Process for
Windows Services Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS
[Auto Services] :HKLM MapsBroker
### Service: Downloaded Maps Manager Status: Start Type: loaded automatically by
Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Windows service for
application access to downloaded maps. This service is started on-demand by
application accessing downloaded maps. Disabling this service will prevent apps
from accessing maps. Host Process for Windows Services Microsoft Corporation
Microsoft� Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K NETWORKSERVICE -P
[Auto Services] :HKLM MessagingService
### Service: MessagingService Status: Start Type: loaded automatically by Server
Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Service supporting text
messaging and related functionality. Host Process for Windows Services Microsoft
Corporation Microsoft� Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K UNISTACKSVCGROUP
[Auto Services] :HKLM MessagingService_127d39
### Service: MessagingService_127d39 Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Service supporting text
messaging and related functionality. Host Process for Windows Services Microsoft
Corporation Microsoft� Windows� Operating System 10.0.17763.1 !
$*C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K UNISTACKSVCGROUP
[Auto Services] :HKLM mpssvc
### Service: Windows Defender Firewall Status: Start Type: loaded automatically
by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Windows Defender
Firewall helps protect your computer by preventing unauthorized users from gaining
access to your computer through the Internet or a network. Host Process for Windows
Services Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1 !
$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICENONETWORKFIREWALL -P
[Auto Services] :HKLM MSDTC
### Service: Distributed Transaction Coordinator Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\MSDTC.EXE * Coordinates
transactions that span multiple resource managers, such as databases, message
queues, and file systems. If this service is stopped, these transactions will fail.
If this service is disabled, any services that explicitly depend on it will fail to
start. Microsoft Distributed Transaction Coordinator Service Microsoft Corporation
Microsoft� Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT
%\SYSTEM32\MSDTC.EXE
[Auto Services] :HKLM MSiSCSI
### Service: Microsoft iSCSI Initiator Service Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Manages Internet
SCSI (iSCSI) sessions from this computer to remote iSCSI target devices. If this
service is stopped, this computer will not be able to login or access iSCSI
targets. If this service is disabled, any services that explicitly depend on it
will fail to start. Host Process for Windows Services Microsoft Corporation
Microsoft� Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K NETSVCS -P
[Auto Services] :HKLM msiserver
### Service: Windows Installer Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\MSIEXEC.EXE * Adds, modifies, and removes
applications provided as a Windows Installer (*.msi, *.msp) package. If this
service is disabled, any services that explicitly depend on it will fail to start.
Windows� installer Microsoft Corporation Windows Installer - Unicode 5.0.17763.1 !
$*%SYSTEMROOT%\SYSTEM32\MSIEXEC.EXE /V
[Auto Services] :HKLM NaturalAuthentication
### Service: Natural Authentication Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Signal aggregator service, that
evaluates signals based on time, network, geolocation, bluetooth and cdf factors.
Supported features are Device Unlock, Dynamic Lock and Dynamo MDM policies Host
Process for Windows Services Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS -P
[Auto Services] :HKLM NcaSvc
### Service: Network Connectivity Assistant Status: Start Type: loaded manually
on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Provides DirectAccess
status notification for UI components Host Process for Windows Services Microsoft
Corporation Microsoft� Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K NETSVCS -P
[Auto Services] :HKLM NcbService
### Service: Network Connection Broker Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Brokers connections that
allow Windows Store Apps to receive notifications from the internet. Host Process
for Windows Services Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED
-P
[Auto Services] :HKLM NcdAutoSetup
### Service: Network Connected Devices Auto-Setup Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Network Connected
Devices Auto-Setup service monitors and installs qualified devices that connect to
a qualified network. Stopping or disabling this service will prevent Windows from
discovering and installing qualified network connected devices automatically. Users
can still manually add network connected devices to a PC through the user
interface. Host Process for Windows Services Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
LOCALSERVICENONETWORK -P
[Auto Services] :HKLM Netlogon
### Service: Netlogon Status: Start Type: loaded manually on demand Actual File:
C:\WINDOWS\SYSTEM32\LSASS.EXE * Maintains a secure channel between this computer
and the domain controller for authenticating users and services. If this service is
stopped, the computer may not authenticate users and services and the domain
controller cannot register DNS records. If this service is disabled, any services
that explicitly depend on it will fail to start. Local Security Authority Process
Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1 !$*
%SYSTEMROOT%\SYSTEM32\LSASS.EXE
[Auto Services] :HKLM Netman
### Service: Network Connections Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Manages objects in the Network and
Dial-Up Connections folder, in which you can view both local area network and
remote connections. Host Process for Windows Services Microsoft Corporation
Microsoft� Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED -P
[Auto Services] :HKLM netprofm
### Service: Network List Service Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Identifies the networks to which the
computer has connected, collects and stores properties for these networks, and
notifies applications when these properties change. Host Process for Windows
Services Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1 !
$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE -P
[Auto Services] :HKLM NetSetupSvc
### Service: Network Setup Service Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * The Network Setup Service manages
the installation of network drivers and permits the configuration of low-level
network settings. If this service is stopped, any driver installations that are
in-progress may be cancelled. Host Process for Windows Services Microsoft
Corporation Microsoft� Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K NETSVCS -P
[Auto Services] :HKLM NgcCtnrSvc
### Service: Microsoft Passport Container Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Manages local user identity
keys used to authenticate user to identity providers as well as TPM virtual smart
cards. If this service is disabled, local user identity keys and TPM virtual smart
cards will not be accessible. It is recommended that you do not reconfigure this
service. Host Process for Windows Services Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
LOCALSERVICENETWORKRESTRICTED -P
[Auto Services] :HKLM NgcSvc
### Service: Microsoft Passport Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Provides process isolation for
cryptographic keys used to authenticate to a user�s associated identity providers.
If this service is disabled, all uses and management of these keys will not be
available, which includes machine logon and single-sign on for apps and websites.
This service starts and stops automatically. It is recommended that you do not
reconfigure this service. Host Process for Windows Services Microsoft Corporation
Microsoft� Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED -P
[Auto Services] :HKLM NlaSvc
### Service: Network Location Awareness Status: Start Type: loaded automatically
by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Collects and
stores configuration information for the network and notifies programs when this
information is modified. If this service is stopped, configuration information
might be unavailable. If this service is disabled, any services that explicitly
depend on it will fail to start. Host Process for Windows Services Microsoft
Corporation Microsoft� Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K NETWORKSERVICE -P
[Auto Services] :HKLM nsi
### Service: Network Store Interface Service Status: Start Type: loaded
automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * This
service delivers network notifications (e.g. interface addition/deleting etc) to
user mode clients. Stopping this service will cause loss of network connectivity.
If this service is disabled, any other services that explicitly depend on this
service will fail to start. Host Process for Windows Services Microsoft Corporation
Microsoft� Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE -P
[Auto Services] :HKLM OneSyncSvc
### Service: Sync Host Status: Start Type: loaded automatically by Server Manager
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * This service synchronizes mail,
contacts, calendar and various other user data. Mail and other applications
dependent on this functionality will not work properly when this service is not
running. Host Process for Windows Services Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
UNISTACKSVCGROUP
[Auto Services] :HKLM OneSyncSvc_127d39
### Service: Sync Host_127d39 Status: Start Type: loaded automatically by Server
Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * This service synchronizes
mail, contacts, calendar and various other user data. Mail and other applications
dependent on this functionality will not work properly when this service is not
running. Host Process for Windows Services Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 !$*C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K
UNISTACKSVCGROUP
[Auto Services] :HKLM ose64
### Service: Office 64 Source Engine Status: Start Type: loaded manually on
demand Actual File: C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\SOURCE
ENGINE\OSE.EXE * Saves installation files used for updates and repairs and is
required for the downloading of Setup updates and Watson error reports. Office
Source Engine Microsoft Corporation Office Source Engine 16.0.4600.1000 !
$*"C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\SOURCE ENGINE\OSE.EXE"
[Auto Services] :HKLM p2pimsvc
### Service: Peer Networking Identity Manager Status: Start Type: loaded manually
on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Provides identity services
for the Peer Name Resolution Protocol (PNRP) and Peer-to-Peer Grouping services.
If disabled, the Peer Name Resolution Protocol (PNRP) and Peer-to-Peer Grouping
services may not function, and some applications, such as HomeGroup and Remote
Assistance, may not function correctly. Host Process for Windows Services Microsoft
Corporation Microsoft� Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICEPEERNET
[Auto Services] :HKLM p2psvc
### Service: Peer Networking Grouping Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Enables multi-party
communication using Peer-to-Peer Grouping. If disabled, some applications, such as
HomeGroup, may not function. Host Process for Windows Services Microsoft
Corporation Microsoft� Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICEPEERNET
[Auto Services] :HKLM PcaSvc
### Service: Program Compatibility Assistant Service Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * This service
provides support for the Program Compatibility Assistant (PCA). PCA monitors
programs installed and run by the user and detects known compatibility problems. If
this service is stopped, PCA will not function properly. Host Process for Windows
Services Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1 !
$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED -P
[Auto Services] :HKLM PeerDistSvc
### Service: BranchCache Status: Start Type: loaded manually on demand Actual
File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * This service caches network content from
peers on the local subnet. Host Process for Windows Services Microsoft Corporation
Microsoft� Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K PEERDIST
[Auto Services] :HKLM perceptionsimulation
### Service: Windows Perception Simulation Service Status: Start Type: loaded
manually on demand Actual File:
C:\WINDOWS\SYSTEM32\PERCEPTIONSIMULATION\PERCEPTIONSIMULATIONSERVICE.EXE * Enables
spatial perception simulation, virtual camera management and spatial input
simulation. Windows Perception Simulation Service Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT
%\SYSTEM32\PERCEPTIONSIMULATION\PERCEPTIONSIMULATIONSERVICE.EXE
[Auto Services] :HKLM PerfHost
### Service: Performance Counter DLL Host Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSWOW64\PERFHOST.EXE * Enables remote users and 64-
bit processes to query performance counters provided by 32-bit DLLs. If this
service is stopped, only local users and 32-bit processes will be able to query
performance counters provided by 32-bit DLLs. x86 Performance Counter Host
Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1 !$*
%SYSTEMROOT%\SYSWOW64\PERFHOST.EXE
[Auto Services] :HKLM PhoneSvc
### Service: Phone Service Status: Start Type: loaded manually on demand Actual
File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Manages the telephony state on the device
Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE
-P
[Auto Services] :HKLM PimIndexMaintenanceSvc
### Service: Contact Data Status: Start Type: loaded manually on demand Actual
File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Indexes contact data for fast contact
searching. If you stop or disable this service, contacts might be missing from your
search results. Host Process for Windows Services Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
UNISTACKSVCGROUP
[Auto Services] :HKLM PimIndexMaintenanceSvc_127d39
### Service: Contact Data_127d39 Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Indexes contact data for fast
contact searching. If you stop or disable this service, contacts might be missing
from your search results. Host Process for Windows Services Microsoft Corporation
Microsoft� Windows� Operating System 10.0.17763.1 !
$*C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K UNISTACKSVCGROUP
[Auto Services] :HKLM pla
### Service: Performance Logs & Alerts Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Performance Logs and Alerts
Collects performance data from local or remote computers based on preconfigured
schedule parameters, then writes the data to a log or triggers an alert. If this
service is stopped, performance information will not be collected. If this service
is disabled, any services that explicitly depend on it will fail to start. Host
Process for Windows Services Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICENONETWORK
-P
[Auto Services] :HKLM PlugPlay
### Service: Plug and Play Status: Start Type: loaded manually on demand Actual
File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Enables a computer to recognize and adapt
to hardware changes with little or no user input. Stopping or disabling this
service will result in system instability. Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K DCOMLAUNCH -P
[Auto Services] :HKLM PNRPAutoReg
### Service: PNRP Machine Name Publication Service Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * This service
publishes a machine name using the Peer Name Resolution Protocol. Configuration is
managed via the netsh context 'p2p pnrp peer' Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICEPEERNET
[Auto Services] :HKLM PNRPsvc
### Service: Peer Name Resolution Protocol Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Enables serverless peer name
resolution over the Internet using the Peer Name Resolution Protocol (PNRP). If
disabled, some peer-to-peer and collaborative applications, such as Remote
Assistance, may not function. Host Process for Windows Services Microsoft
Corporation Microsoft� Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICEPEERNET
[Auto Services] :HKLM PolicyAgent
### Service: IPsec Policy Agent Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Internet Protocol security (IPsec)
supports network-level peer authentication, data origin authentication, data
integrity, data confidentiality (encryption), and replay protection. This service
enforces IPsec policies created through the IP Security Policies snap-in or the
command-line tool "netsh ipsec". If you stop this service, you may experience
network connectivity issues if your policy requires that connections use IPsec.
Also,remote management of Windows Defender Firewall is not available when this
service is stopped. Host Process for Windows Services Microsoft Corporation
Microsoft� Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K NETWORKSERVICENETWORKRESTRICTED -P
[Auto Services] :HKLM Power
### Service: Power Status: Start Type: loaded automatically by Server Manager
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Manages power policy and power
policy notification delivery. Host Process for Windows Services Microsoft
Corporation Microsoft� Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K DCOMLAUNCH -P
[Auto Services] :HKLM PrintNotify
### Service: Printer Extensions and Notifications Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * This service
opens custom printer dialog boxes and handles notifications from a remote print
server or a printer. If you turn off this service, you won�t be able to see printer
extensions or notifications. Host Process for Windows Services Microsoft
Corporation Microsoft� Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K PRINT
[Auto Services] :HKLM PrintWorkflowUserSvc
### Service: PrintWorkflow Status: Start Type: loaded manually on demand Actual
File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Print Workflow Host Process for Windows
Services Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1 !
$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K PRINTWORKFLOW
[Auto Services] :HKLM PrintWorkflowUserSvc_127d39
### Service: PrintWorkflow_127d39 Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Print Workflow Host Process for
Windows Services Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K PRINTWORKFLOW
[Auto Services] :HKLM ProfSvc
### Service: User Profile Service Status: Start Type: loaded automatically by
Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * This service is
responsible for loading and unloading user profiles. If this service is stopped or
disabled, users will no longer be able to successfully sign in or sign out, apps
might have problems getting to users' data, and components registered to receive
profile event notifications won't receive them. Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS -P
[Auto Services] :HKLM PushToInstall
### Service: Windows PushToInstall Service Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Provides infrastructure
support for the Microsoft Store. This service is started automatically and if
disabled then remote installations will not function properly. Host Process for
Windows Services Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS -P
[Auto Services] :HKLM QWAVE
### Service: Quality Windows Audio Video Experience Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Quality Windows
Audio Video Experience (qWave) is a networking platform for Audio Video (AV)
streaming applications on IP home networks. qWave enhances AV streaming performance
and reliability by ensuring network quality-of-service (QoS) for AV applications.
It provides mechanisms for admission control, run time monitoring and enforcement,
application feedback, and traffic prioritization. Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1 !$*%WINDIR
%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICEANDNOIMPERSONATION -P
[Auto Services] :HKLM RasAuto
### Service: Remote Access Auto Connection Manager Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Creates a
connection to a remote network whenever a program references a remote DNS or
NetBIOS name or address. Host Process for Windows Services Microsoft Corporation
Microsoft� Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K NETSVCS -P
[Auto Services] :HKLM RasMan
### Service: Remote Access Connection Manager Status: Start Type: loaded
automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE *
Manages dial-up and virtual private network (VPN) connections from this computer to
the Internet or other remote networks. If this service is disabled, any services
that explicitly depend on it will fail to start. Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS
[Auto Services] :HKLM RetailDemo
### Service: Retail Demo Service Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * The Retail Demo service controls
device activity while the device is in retail demo mode. Host Process for Windows
Services Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1 !
$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K RDXGROUP
[Auto Services] :HKLM RmSvc
### Service: Radio Management Service Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Radio Management and Airplane
Mode Service Host Process for Windows Services Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
LOCALSERVICENETWORKRESTRICTED
[Auto Services] :HKLM RpcEptMapper
### Service: RPC Endpoint Mapper Status: Start Type: loaded automatically by
Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Resolves RPC
interfaces identifiers to transport endpoints. If this service is stopped or
disabled, programs using Remote Procedure Call (RPC) services will not function
properly. Host Process for Windows Services Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
RPCSS -P
[Auto Services] :HKLM RpcLocator
### Service: Remote Procedure Call (RPC) Locator Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\LOCATOR.EXE * In Windows 2003
and earlier versions of Windows, the Remote Procedure Call (RPC) Locator service
manages the RPC name service database. In Windows Vista and later versions of
Windows, this service does not provide any functionality and is present for
application compatibility. Rpc Locator Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\LOCATOR.EXE
[Auto Services] :HKLM RpcSs
### Service: Remote Procedure Call (RPC) Status: Start Type: loaded automatically
by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * The RPCSS service
is the Service Control Manager for COM and DCOM servers. It performs object
activations requests, object exporter resolutions and distributed garbage
collection for COM and DCOM servers. If this service is stopped or disabled,
programs using COM or DCOM will not function properly. It is strongly recommended
that you have the RPCSS service running. Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K RPCSS -P
[Auto Services] :HKLM RtkAudioService
### Service: Realtek Audio Service Status: Start Type: loaded automatically by
Server Manager Actual File: C:\PROGRAM
FILES\REALTEK\AUDIO\HDA\RTKAUDIOSERVICE64.EXE * For cooperation with Realtek audio
driver. Realtek Audio Service Realtek Semiconductor Realtek Audio Service 1, 0, 0,
66 !$*"C:\PROGRAM FILES\REALTEK\AUDIO\HDA\RTKAUDIOSERVICE64.EXE"
[Auto Services] :HKLM SamSs
### Service: Security Accounts Manager Status: Start Type: loaded automatically
by Server Manager Actual File: C:\WINDOWS\SYSTEM32\LSASS.EXE * The startup of this
service signals other services that the Security Accounts Manager (SAM) is ready to
accept requests. Disabling this service will prevent other services in the system
from being notified when the SAM is ready, which may in turn cause those services
to fail to start correctly. This service should not be disabled. Local Security
Authority Process Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\LSASS.EXE
[Auto Services] :HKLM SCardSvr
### Service: Smart Card Status: Start Type: loaded manually on demand Actual
File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Manages access to smart cards read by this
computer. If this service is stopped, this computer will be unable to read smart
cards. If this service is disabled, any services that explicitly depend on it will
fail to start. Host Process for Windows Services Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
LOCALSERVICEANDNOIMPERSONATION
[Auto Services] :HKLM ScDeviceEnum
### Service: Smart Card Device Enumeration Service Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Creates software
device nodes for all smart card readers accessible to a given session. If this
service is disabled, WinRT APIs will not be able to enumerate smart card readers.
Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
LOCALSYSTEMNETWORKRESTRICTED
[Auto Services] :HKLM Schedule
### Service: Task Scheduler Status: Start Type: loaded automatically by Server
Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Enables a user to configure
and schedule automated tasks on this computer. The service also hosts multiple
Windows system-critical tasks. If this service is stopped or disabled, these tasks
will not be run at their scheduled times. If this service is disabled, any services
that explicitly depend on it will fail to start. Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS -P
[Auto Services] :HKLM SCPolicySvc
### Service: Smart Card Removal Policy Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Allows the system to be
configured to lock the user desktop upon smart card removal. Host Process for
Windows Services Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS
[Auto Services] :HKLM SDRSVC
### Service: Windows Backup Status: Start Type: loaded manually on demand Actual
File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Provides Windows Backup and Restore
capabilities. Host Process for Windows Services Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
SDRSVC
[Auto Services] :HKLM seclogon
### Service: Secondary Logon Status: Start Type: loaded manually on demand Actual
File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Enables starting processes under alternate
credentials. If this service is stopped, this type of logon access will be
unavailable. If this service is disabled, any services that explicitly depend on it
will fail to start. Host Process for Windows Services Microsoft Corporation
Microsoft� Windows� Operating System 10.0.17763.1 !$*%WINDIR%\SYSTEM32\SVCHOST.EXE
-K NETSVCS -P
[Auto Services] :HKLM SecurityHealthService
### Service: Windows Security Service Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\SECURITYHEALTHSERVICE.EXE * Windows
Security Service handles unified device protection and health information Windows
Security Health Service Microsoft Corporation Microsoft� Windows� Operating System
4.18.1807.16384 !$*%SYSTEMROOT%\SYSTEM32\SECURITYHEALTHSERVICE.EXE
[Auto Services] :HKLM SEMgrSvc
### Service: Payments and NFC/SE Manager Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Manages payments and Near
Field Communication (NFC) based secure elements. Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE -P
[Auto Services] :HKLM SENS
### Service: System Event Notification Service Status: Start Type: loaded
automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE *
Monitors system events and notifies subscribers to COM+ Event System of these
events. Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS -P
[Auto Services] :HKLM Sense
### Service: @%ProgramFiles%\Windows Defender Advanced Threat
Protection\MsSense.exe,-1001 Status: Start Type: loaded manually on demand Actual
File: C:\PROGRAM FILES\WINDOWS DEFENDER ADVANCED THREAT PROTECTION\MSSENSE.EXE * @
%ProgramFiles%\Windows Defender Advanced Threat Protection\MsSense.exe,-1002
Windows Defender Advanced Threat Protection Service Executable Microsoft
Corporation Microsoft� Windows� Operating System 10.5840.17763.1 !$*"%PROGRAMFILES
%\WINDOWS DEFENDER ADVANCED THREAT PROTECTION\MSSENSE.EXE"
[Auto Services] :HKLM SensorDataService
### Service: Sensor Data Service Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\SENSORDATASERVICE.EXE * Delivers data from a
variety of sensors Sensor Data Service Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\SENSORDATASERVICE.EXE
[Auto Services] :HKLM SensorService
### Service: Sensor Service Status: Start Type: loaded manually on demand Actual
File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * A service for sensors that manages
different sensors' functionality. Manages Simple Device Orientation (SDO) and
History for sensors. Loads the SDO sensor that reports device orientation changes.
If this service is stopped or disabled, the SDO sensor will not be loaded and so
auto-rotation will not occur. History collection from Sensors will also be stopped.
Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
LOCALSYSTEMNETWORKRESTRICTED -P
[Auto Services] :HKLM SensrSvc
### Service: Sensor Monitoring Service Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Monitors various sensors in
order to expose data and adapt to system and user state. If this service is
stopped or disabled, the display brightness will not adapt to lighting conditions.
Stopping this service may affect other system functionality and features as well.
Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
LOCALSERVICEANDNOIMPERSONATION -P
[Auto Services] :HKLM SessionEnv
### Service: Remote Desktop Configuration Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Remote Desktop Configuration
service (RDCS) is responsible for all Remote Desktop Services and Remote Desktop
related configuration and session maintenance activities that require SYSTEM
context. These include per-session temporary folders, RD themes, and RD
certificates. Host Process for Windows Services Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
NETSVCS -P
[Auto Services] :HKLM SgrmBroker
### Service: System Guard Runtime Monitor Broker Status: Start Type: loaded
automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SGRMBROKER.EXE *
Monitors and attests to the integrity of the Windows platform. System Guard Runtime
Monitor Broker Service Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\SGRMBROKER.EXE
[Auto Services] :HKLM SharedAccess
### Service: Internet Connection Sharing (ICS) Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Provides network
address translation, addressing, name resolution and/or intrusion prevention
services for a home or small office network. Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS -P
[Auto Services] :HKLM SharedRealitySvc
### Service: Spatial Data Service Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * This service is used for Spatial
Perception scenarios Host Process for Windows Services Microsoft Corporation
Microsoft� Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE -P
[Auto Services] :HKLM ShellHWDetection
### Service: Shell Hardware Detection Status: Start Type: loaded automatically by
Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Provides
notifications for AutoPlay hardware events. Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS -P
[Auto Services] :HKLM smphost
### Service: Microsoft Storage Spaces SMP Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Host service for the
Microsoft Storage Spaces management provider. If this service is stopped or
disabled, Storage Spaces cannot be managed. Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K SMPHOST
[Auto Services] :HKLM SmsRouter
### Service: Microsoft Windows SMS Router Service. Status: Start Type: loaded
automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE *
Routes messages based on rules to appropriate clients. Host Process for Windows
Services Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1 !
$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICENETWORKRESTRICTED -P
[Auto Services] :HKLM SNMPTRAP
### Service: SNMP Trap Status: Start Type: loaded manually on demand Actual File:
C:\WINDOWS\SYSTEM32\SNMPTRAP.EXE * Receives trap messages generated by local or
remote Simple Network Management Protocol (SNMP) agents and forwards the messages
to SNMP management programs running on this computer. If this service is stopped,
SNMP-based programs on this computer will not receive SNMP trap messages. If this
service is disabled, any services that explicitly depend on it will fail to start.
SNMP Trap Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1 !
$*%SYSTEMROOT%\SYSTEM32\SNMPTRAP.EXE
[Auto Services] :HKLM spectrum
### Service: Windows Perception Service Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\SPECTRUM.EXE * Enables spatial perception,
spatial input, and holographic rendering. Windows Perception Service Microsoft
Corporation Microsoft� Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT
%\SYSTEM32\SPECTRUM.EXE
[Auto Services] :HKLM Spooler
### Service: Print Spooler Status: Start Type: loaded automatically by Server
Manager Actual File: C:\WINDOWS\SYSTEM32\SPOOLSV.EXE * This service spools print
jobs and handles interaction with the printer. If you turn off this service, you
won�t be able to print or see your printers. Spooler SubSystem App Microsoft
Corporation Microsoft� Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT
%\SYSTEM32\SPOOLSV.EXE
[Auto Services] :HKLM sppsvc
### Service: Software Protection Status: Start Type: loaded automatically by
Server Manager Actual File: C:\WINDOWS\SYSTEM32\SPPSVC.EXE * Enables the download,
installation and enforcement of digital licenses for Windows and Windows
applications. If the service is disabled, the operating system and licensed
applications may run in a notification mode. It is strongly recommended that you
not disable the Software Protection service. Microsoft Software Protection Platform
Service Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1 !$*
%SYSTEMROOT%\SYSTEM32\SPPSVC.EXE
[Auto Services] :HKLM SSDPSRV
### Service: SSDP Discovery Status: Start Type: loaded manually on demand Actual
File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Discovers networked devices and services
that use the SSDP discovery protocol, such as UPnP devices. Also announces SSDP
devices and services running on the local computer. If this service is stopped,
SSDP-based devices will not be discovered. If this service is disabled, any
services that explicitly depend on it will fail to start. Host Process for Windows
Services Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1 !
$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICEANDNOIMPERSONATION -P
[Auto Services] :HKLM SstpSvc
### Service: Secure Socket Tunneling Protocol Service Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Provides support
for the Secure Socket Tunneling Protocol (SSTP) to connect to remote computers
using VPN. If this service is disabled, users will not be able to use SSTP to
access remote servers. Host Process for Windows Services Microsoft Corporation
Microsoft� Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE -P
[Auto Services] :HKLM StateRepository
### Service: State Repository Service Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Provides required
infrastructure support for the application model. Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K APPMODEL -P
[Auto Services] :HKLM stisvc
### Service: Windows Image Acquisition (WIA) Status: Start Type: loaded
automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE *
Provides image acquisition services for scanners and cameras Host Process for
Windows Services Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K IMGSVC
[Auto Services] :HKLM StorSvc
### Service: Storage Service Status: Start Type: loaded manually on demand Actual
File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Provides enabling services for storage
settings and external storage expansion Host Process for Windows Services Microsoft
Corporation Microsoft� Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED -P
[Auto Services] :HKLM svsvc
### Service: Spot Verifier Status: Start Type: loaded manually on demand Actual
File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Verifies potential file system corruptions.
Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
LOCALSYSTEMNETWORKRESTRICTED -P
[Auto Services] :HKLM swprv
### Service: Microsoft Software Shadow Copy Provider Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Manages software-
based volume shadow copies taken by the Volume Shadow Copy service. If this service
is stopped, software-based volume shadow copies cannot be managed. If this service
is disabled, any services that explicitly depend on it will fail to start. Host
Process for Windows Services Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K SWPRV
[Auto Services] :HKLM SysMain
### Service: SysMain Status: Start Type: loaded automatically by Server Manager
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Maintains and improves system
performance over time. Host Process for Windows Services Microsoft Corporation
Microsoft� Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED -P
[Auto Services] :HKLM SystemEventsBroker
### Service: System Events Broker Status: Start Type: loaded automatically by
Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Coordinates execution
of background work for WinRT application. If this service is stopped or disabled,
then background work might not be triggered. Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K DCOMLAUNCH -P
[Auto Services] :HKLM TabletInputService
### Service: Touch Keyboard and Handwriting Panel Service Status: Start Type:
loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Enables
Touch Keyboard and Handwriting Panel pen and ink functionality Host Process for
Windows Services Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED
-P
[Auto Services] :HKLM TapiSrv
### Service: Telephony Status: Start Type: loaded manually on demand Actual File:
C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Provides Telephony API (TAPI) support for
programs that control telephony devices on the local computer and, through the LAN,
on servers that are also running the service. Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETWORKSERVICE -P
[Auto Services] :HKLM TermService
### Service: Remote Desktop Services Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Allows users to connect
interactively to a remote computer. Remote Desktop and Remote Desktop Session Host
Server depend on this service. To prevent remote use of this computer, clear the
checkboxes on the Remote tab of the System properties control panel item. Host
Process for Windows Services Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETWORKSERVICE
[Auto Services] :HKLM Themes
### Service: Themes Status: Start Type: loaded automatically by Server Manager
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Provides user experience theme
management. Host Process for Windows Services Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
NETSVCS -P
[Auto Services] :HKLM TieringEngineService
### Service: Storage Tiers Management Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\TIERINGENGINESERVICE.EXE * Optimizes the
placement of data in storage tiers on all tiered storage spaces in the system.
Storage Tiers Management Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\TIERINGENGINESERVICE.EXE
[Auto Services] :HKLM TimeBrokerSvc
### Service: Time Broker Status: Start Type: loaded manually on demand Actual
File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Coordinates execution of background work
for WinRT application. If this service is stopped or disabled, then background work
might not be triggered. Host Process for Windows Services Microsoft Corporation
Microsoft� Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICENETWORKRESTRICTED -P
[Auto Services] :HKLM TokenBroker
### Service: Web Account Manager Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * This service is used by Web Account
Manager to provide single-sign-on to apps and services. Host Process for Windows
Services Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1 !
$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS -P
[Auto Services] :HKLM TrkWks
### Service: Distributed Link Tracking Client Status: Start Type: loaded
automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE *
Maintains links between NTFS files within a computer or across computers in a
network. Host Process for Windows Services Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
LOCALSYSTEMNETWORKRESTRICTED -P
[Auto Services] :HKLM TrustedInstaller
### Service: Windows Modules Installer Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SERVICING\TRUSTEDINSTALLER.EXE * Enables
installation, modification, and removal of Windows updates and optional components.
If this service is disabled, install or uninstall of Windows updates might fail for
this computer. Windows Modules Installer Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%SYSTEMROOT%\SERVICING\TRUSTEDINSTALLER.EXE
[Auto Services] :HKLM tzautoupdate
### Service: Auto Time Zone Updater Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Automatically sets the system time
zone. Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE
-P
[Auto Services] :HKLM UmRdpService
### Service: Remote Desktop Services UserMode Port Redirector Status: Start Type:
loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Allows the
redirection of Printers/Drives/Ports for RDP connections Host Process for Windows
Services Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1 !
$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED -P
[Auto Services] :HKLM UnistoreSvc
### Service: User Data Storage Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Handles storage of structured user
data, including contact info, calendars, messages, and other content. If you stop
or disable this service, apps that use this data might not work correctly. Host
Process for Windows Services Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K UNISTACKSVCGROUP
[Auto Services] :HKLM UnistoreSvc_127d39
### Service: User Data Storage_127d39 Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Handles storage of structured
user data, including contact info, calendars, messages, and other content. If you
stop or disable this service, apps that use this data might not work correctly.
Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K
UNISTACKSVCGROUP
[Auto Services] :HKLM upnphost
### Service: UPnP Device Host Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Allows UPnP devices to be hosted on
this computer. If this service is stopped, any hosted UPnP devices will stop
functioning and no additional hosted devices can be added. If this service is
disabled, any services that explicitly depend on it will fail to start. Host
Process for Windows Services Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
LOCALSERVICEANDNOIMPERSONATION -P
[Auto Services] :HKLM UserDataSvc
### Service: User Data Access Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Provides apps access to structured
user data, including contact info, calendars, messages, and other content. If you
stop or disable this service, apps that use this data might not work correctly.
Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
UNISTACKSVCGROUP
[Auto Services] :HKLM UserDataSvc_127d39
### Service: User Data Access_127d39 Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Provides apps access to
structured user data, including contact info, calendars, messages, and other
content. If you stop or disable this service, apps that use this data might not
work correctly. Host Process for Windows Services Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 !$*C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K
UNISTACKSVCGROUP
[Auto Services] :HKLM UserManager
### Service: User Manager Status: Start Type: loaded automatically by Server
Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * User Manager provides the
runtime components required for multi-user interaction. If this service is
stopped, some applications may not operate correctly. Host Process for Windows
Services Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1 !
$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS -P
[Auto Services] :HKLM uSHAREitSvc
### Service: SHAREit Hotspot Service Status: Start Type: loaded manually on
demand Actual File: C:\PROGRAM FILES (X86)\SHAREIT
TECHNOLOGIES\SHAREIT\SHAREIT.SERVICE.EXE * SHAREit Hotspot Service SHAREit Service
SHAREit Technologies Co.Ltd SHAREit 4.0.6.177 !$*"C:\PROGRAM FILES (X86)\SHAREIT
TECHNOLOGIES\SHAREIT\SHAREIT.SERVICE.EXE"
[Auto Services] :HKLM UsoSvc
### Service: Update Orchestrator Service Status: Start Type: loaded automatically
by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Manages Windows
Updates. If stopped, your devices will not be able download and install latest
udpates. Host Process for Windows Services Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
NETSVCS -P
[Auto Services] :HKLM VacSvc
### Service: Volumetric Audio Compositor Service Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Hosts spatial
analysis for Mixed Reality audio simulation. Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICENETWORKRESTRICTED -P
[Auto Services] :HKLM VaultSvc
### Service: Credential Manager Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\LSASS.EXE * Provides secure storage and retrieval
of credentials to users, applications and security service packages. Local Security
Authority Process Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\LSASS.EXE
[Auto Services] :HKLM vds
### Service: Virtual Disk Status: Start Type: loaded manually on demand Actual
File: C:\WINDOWS\SYSTEM32\VDS.EXE * Provides management services for disks,
volumes, file systems, and storage arrays. Virtual Disk Service Microsoft
Corporation Microsoft� Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT
%\SYSTEM32\VDS.EXE
[Auto Services] :HKLM vmicguestinterface
### Service: Hyper-V Guest Service Interface Status: Start Type: loaded manually
on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Provides an interface for
the Hyper-V host to interact with specific services running inside the virtual
machine. Host Process for Windows Services Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
LOCALSYSTEMNETWORKRESTRICTED -P
[Auto Services] :HKLM vmicheartbeat
### Service: Hyper-V Heartbeat Service Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Monitors the state of this
virtual machine by reporting a heartbeat at regular intervals. This service helps
you identify running virtual machines that have stopped responding. Host Process
for Windows Services Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K ICSERVICE -P
[Auto Services] :HKLM vmickvpexchange
### Service: Hyper-V Data Exchange Service Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Provides a mechanism to
exchange data between the virtual machine and the operating system running on the
physical computer. Host Process for Windows Services Microsoft Corporation
Microsoft� Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED -P
[Auto Services] :HKLM vmicrdv
### Service: Hyper-V Remote Desktop Virtualization Service Status: Start Type:
loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Provides a
platform for communication between the virtual machine and the operating system
running on the physical computer. Host Process for Windows Services Microsoft
Corporation Microsoft� Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K ICSERVICE -P
[Auto Services] :HKLM vmicshutdown
### Service: Hyper-V Guest Shutdown Service Status: Start Type: loaded manually
on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Provides a mechanism to
shut down the operating system of this virtual machine from the management
interfaces on the physical computer. Host Process for Windows Services Microsoft
Corporation Microsoft� Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED -P
[Auto Services] :HKLM vmictimesync
### Service: Hyper-V Time Synchronization Service Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Synchronizes the
system time of this virtual machine with the system time of the physical computer.
Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
LOCALSERVICENETWORKRESTRICTED -P
[Auto Services] :HKLM vmicvmsession
### Service: Hyper-V PowerShell Direct Service Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Provides a
mechanism to manage virtual machine with PowerShell via VM session without a
virtual network. Host Process for Windows Services Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
LOCALSYSTEMNETWORKRESTRICTED -P
[Auto Services] :HKLM vmicvss
### Service: Hyper-V Volume Shadow Copy Requestor Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Coordinates the
communications that are required to use Volume Shadow Copy Service to back up
applications and data on this virtual machine from the operating system on the
physical computer. Host Process for Windows Services Microsoft Corporation
Microsoft� Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED -P
[Auto Services] :HKLM VSS
### Service: Volume Shadow Copy Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\VSSVC.EXE * Manages and implements Volume Shadow
Copies used for backup and other purposes. If this service is stopped, shadow
copies will be unavailable for backup and the backup may fail. If this service is
disabled, any services that explicitly depend on it will fail to start. Microsoft�
Volume Shadow Copy Service Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\VSSVC.EXE
[Auto Services] :HKLM W32Time
### Service: Windows Time Status: Start Type: loaded manually on demand Actual
File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Maintains date and time synchronization on
all clients and servers in the network. If this service is stopped, date and time
synchronization will be unavailable. If this service is disabled, any services that
explicitly depend on it will fail to start. Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE
[Auto Services] :HKLM WaaSMedicSvc
### Service: Windows Update Medic Service Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Enables remediation and
protection of Windows Update components. Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K WUSVCS -P
[Auto Services] :HKLM WalletService
### Service: WalletService Status: Start Type: loaded manually on demand Actual
File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Hosts objects used by clients of the wallet
Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K APPMODEL -P
[Auto Services] :HKLM WarpJITSvc
### Service: WarpJITSvc Status: Start Type: loaded manually on demand Actual
File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Provides a JIT out of process service for
WARP when running with ACG enabled. Host Process for Windows Services Microsoft
Corporation Microsoft� Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICENETWORKRESTRICTED
[Auto Services] :HKLM wbengine
### Service: Block Level Backup Engine Service Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\WBENGINE.EXE * The WBENGINE
service is used by Windows Backup to perform backup and recovery operations. If
this service is stopped by a user, it may cause the currently running backup or
recovery operation to fail. Disabling this service may disable backup and recovery
operations using Windows Backup on this computer. Microsoft� Block Level Backup
Engine Service EXE Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*"%SYSTEMROOT%\SYSTEM32\WBENGINE.EXE"
[Auto Services] :HKLM WbioSrvc
### Service: Windows Biometric Service Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * The Windows biometric service
gives client applications the ability to capture, compare, manipulate, and store
biometric data without gaining direct access to any biometric hardware or samples.
The service is hosted in a privileged SVCHOST process. Host Process for Windows
Services Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1 !
$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K WBIOSVCGROUP
[Auto Services] :HKLM Wcmsvc
### Service: Windows Connection Manager Status: Start Type: loaded automatically
by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Makes automatic
connect/disconnect decisions based on the network connectivity options currently
available to the PC and enables management of network connectivity based on Group
Policy settings. Host Process for Windows Services Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
LOCALSERVICENETWORKRESTRICTED -P
[Auto Services] :HKLM wcncsvc
### Service: Windows Connect Now - Config Registrar Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * WCNCSVC hosts the
Windows Connect Now Configuration which is Microsoft's Implementation of Wireless
Protected Setup (WPS) protocol. This is used to configure Wireless LAN settings for
an Access Point (AP) or a Wireless Device. The service is started programmatically
as needed. Host Process for Windows Services Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
LOCALSERVICEANDNOIMPERSONATION -P
[Auto Services] :HKLM WdiServiceHost
### Service: Diagnostic Service Host Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * The Diagnostic Service Host
is used by the Diagnostic Policy Service to host diagnostics that need to run in a
Local Service context. If this service is stopped, any diagnostics that depend on
it will no longer function. Host Process for Windows Services Microsoft Corporation
Microsoft� Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE -P
[Auto Services] :HKLM WdiSystemHost
### Service: Diagnostic System Host Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * The Diagnostic System Host is used
by the Diagnostic Policy Service to host diagnostics that need to run in a Local
System context. If this service is stopped, any diagnostics that depend on it will
no longer function. Host Process for Windows Services Microsoft Corporation
Microsoft� Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED -P
[Auto Services] :HKLM WdNisSvc
### Service: Windows Defender Antivirus Network Inspection Service Status: Start
Type: loaded manually on demand Actual File: C:\PROGRAM FILES\WINDOWS
DEFENDER\NISSRV.EXE * Helps guard against intrusion attempts targeting known and
newly discovered vulnerabilities in network protocols Microsoft Network Realtime
Inspection Service Microsoft Corporation Microsoft� Windows� Operating System
4.18.1807.16384 !$*"%PROGRAMFILES%\WINDOWS DEFENDER\NISSRV.EXE"
[Auto Services] :HKLM WebClient
### Service: WebClient Status: Start Type: loaded manually on demand Actual File:
C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Enables Windows-based programs to create, access,
and modify Internet-based files. If this service is stopped, these functions will
not be available. If this service is disabled, any services that explicitly depend
on it will fail to start. Host Process for Windows Services Microsoft Corporation
Microsoft� Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE -P
[Auto Services] :HKLM Wecsvc
### Service: Windows Event Collector Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * This service manages
persistent subscriptions to events from remote sources that support WS-Management
protocol. This includes Windows Vista event logs, hardware and IPMI-enabled event
sources. The service stores forwarded events in a local Event Log. If this service
is stopped or disabled event subscriptions cannot be created and forwarded events
cannot be accepted. Host Process for Windows Services Microsoft Corporation
Microsoft� Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K NETWORKSERVICE -P
[Auto Services] :HKLM WEPHOSTSVC
### Service: Windows Encryption Provider Host Service Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Windows
Encryption Provider Host Service brokers encryption related functionalities from
3rd Party Encryption Providers to processes that need to evaluate and apply EAS
policies. Stopping this will compromise EAS compliancy checks that have been
established by the connected Mail Accounts Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K WEPHOSTSVCGROUP
[Auto Services] :HKLM wercplsupport
### Service: Problem Reports and Solutions Control Panel Support Status: Start
Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * This
service provides support for viewing, sending and deletion of system-level problem
reports for the Problem Reports and Solutions control panel. Host Process for
Windows Services Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS -P
[Auto Services] :HKLM WerSvc
### Service: Windows Error Reporting Service Status: Start Type: loaded manually
on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Allows errors to be
reported when programs stop working or responding and allows existing solutions to
be delivered. Also allows logs to be generated for diagnostic and repair services.
If this service is stopped, error reporting might not work correctly and results of
diagnostic services and repairs might not be displayed. Host Process for Windows
Services Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1 !
$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K WERSVCGROUP
[Auto Services] :HKLM WFDSConMgrSvc
### Service: Wi-Fi Direct Services Connection Manager Service Status: Start Type:
loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Manages
connections to wireless services, including wireless display and docking. Host
Process for Windows Services Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
LOCALSERVICENETWORKRESTRICTED -P
[Auto Services] :HKLM WiaRpc
### Service: Still Image Acquisition Events Status: Start Type: loaded manually
on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Launches applications
associated with still image acquisition events. Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED -P
[Auto Services] :HKLM WinDefend
### Service: Windows Defender Antivirus Service Status: Start Type: loaded
automatically by Server Manager Actual File: C:\PROGRAM FILES\WINDOWS
DEFENDER\MSMPENG.EXE * Helps protect users from malware and other potentially
unwanted software Antimalware Service Executable Microsoft Corporation Microsoft�
Windows� Operating System 4.18.1807.18075 !$*"%PROGRAMFILES%\WINDOWS
DEFENDER\MSMPENG.EXE"
[Auto Services] :HKLM WinHttpAutoProxySvc
### Service: WinHTTP Web Proxy Auto-Discovery Service Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * WinHTTP
implements the client HTTP stack and provides developers with a Win32 API and COM
Automation component for sending HTTP requests and receiving responses. In
addition, WinHTTP provides support for auto-discovering a proxy configuration via
its implementation of the Web Proxy Auto-Discovery (WPAD) protocol. Host Process
for Windows Services Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICENETWORKRESTRICTED
-P
[Auto Services] :HKLM Winmgmt
### Service: Windows Management Instrumentation Status: Start Type: loaded
automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE *
Provides a common interface and object model to access management information about
operating system, devices, applications and services. If this service is stopped,
most Windows-based software will not function properly. If this service is
disabled, any services that explicitly depend on it will fail to start. Host
Process for Windows Services Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS -P
[Auto Services] :HKLM WinRM
### Service: Windows Remote Management (WS-Management) Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Windows Remote
Management (WinRM) service implements the WS-Management protocol for remote
management. WS-Management is a standard web services protocol used for remote
software and hardware management. The WinRM service listens on the network for WS-
Management requests and processes them. The WinRM Service needs to be configured
with a listener using winrm.cmd command line tool or through Group Policy in order
for it to listen over the network. The WinRM service provides access to WMI data
and enables event collection. Event collection and subscription to events require
that the service is running. WinRM messages use HTTP and HTTPS as transports. The
WinRM service does not depend on IIS but is preconfigured to share a port with IIS
on the same machine. The WinRM service reserves the /wsman URL prefix. To prevent
conflicts with IIS, administrators should ensure that any websites hosted on IIS do
not use the /wsman URL prefix. Host Process for Windows Services Microsoft
Corporation Microsoft� Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K NETWORKSERVICE -P
[Auto Services] :HKLM wisvc
### Service: Windows Insider Service Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Provides infrastructure
support for the Windows Insider Program. This service must remain enabled for the
Windows Insider Program to work. Host Process for Windows Services Microsoft
Corporation Microsoft� Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K NETSVCS -P
[Auto Services] :HKLM WlanSvc
### Service: WLAN AutoConfig Status: Start Type: loaded automatically by Server
Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * The WLANSVC service provides
the logic required to configure, discover, connect to, and disconnect from a
wireless local area network (WLAN) as defined by IEEE 802.11 standards. It also
contains the logic to turn your computer into a software access point so that other
devices or computers can connect to your computer wirelessly using a WLAN adapter
that can support this. Stopping or disabling the WLANSVC service will make all WLAN
adapters on your computer inaccessible from the Windows networking UI. It is
strongly recommended that you have the WLANSVC service running if your computer has
a WLAN adapter. Host Process for Windows Services Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
LOCALSYSTEMNETWORKRESTRICTED -P
[Auto Services] :HKLM wlidsvc
### Service: Microsoft Account Sign-in Assistant Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Enables user
sign-in through Microsoft account identity services. If this service is stopped,
users will not be able to logon to the computer with their Microsoft account. Host
Process for Windows Services Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS -P
[Auto Services] :HKLM wlpasvc
### Service: Local Profile Assistant Service Status: Start Type: loaded manually
on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * This service provides
profile management for subscriber identity modules Host Process for Windows
Services Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1 !
$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICENETWORKRESTRICTED -P
[Auto Services] :HKLM WManSvc
### Service: Windows Management Service Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Performs management including
Provisioning and Enrollment activities Host Process for Windows Services Microsoft
Corporation Microsoft� Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K NETSVCS -P
[Auto Services] :HKLM wmiApSrv
### Service: WMI Performance Adapter Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\WBEM\WMIAPSRV.EXE * Provides performance
library information from Windows Management Instrumentation (WMI) providers to
clients on the network. This service only runs when Performance Data Helper is
activated. WMI Performance Reverse Adapter Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\WBEM\WMIAPSRV.EXE
[Auto Services] :HKLM WMPNetworkSvc
### Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 Status: Start
Type: loaded manually on demand Actual File: C:\PROGRAM FILES\WINDOWS MEDIA
PLAYER\WMPNETWK.EXE * @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-102
Windows Media Player Network Sharing Service Microsoft Corporation Microsoft�
Windows� Operating System 12.0.17763.1 !$*"%PROGRAMFILES%\WINDOWS MEDIA
PLAYER\WMPNETWK.EXE"
[Auto Services] :HKLM workfolderssvc
### Service: Work Folders Status: Start Type: loaded manually on demand Actual
File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * This service syncs files with the Work
Folders server, enabling you to use the files on any of the PCs and devices on
which you've set up Work Folders. Host Process for Windows Services Microsoft
Corporation Microsoft� Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE -P
[Auto Services] :HKLM WpcMonSvc
### Service: Parental Controls Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Enforces parental controls for child
accounts in Windows. If this service is stopped or disabled, parental controls may
not be enforced. Host Process for Windows Services Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
LOCALSERVICE
[Auto Services] :HKLM WPDBusEnum
### Service: Portable Device Enumerator Service Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Enforces group
policy for removable mass-storage devices. Enables applications such as Windows
Media Player and Image Import Wizard to transfer and synchronize content using
removable mass-storage devices. Host Process for Windows Services Microsoft
Corporation Microsoft� Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED
[Auto Services] :HKLM WpnService
### Service: Windows Push Notifications System Service Status: Start Type: loaded
automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * This
service runs in session 0 and hosts the notification platform and connection
provider which handles the connection between the device and WNS server. Host
Process for Windows Services Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS -P
[Auto Services] :HKLM WpnUserService
### Service: Windows Push Notifications User Service Status: Start Type: loaded
automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * This
service hosts Windows notification platform which provides support for local and
push notifications. Supported notifications are tile, toast and raw. Host Process
for Windows Services Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K UNISTACKSVCGROUP
[Auto Services] :HKLM WpnUserService_127d39
### Service: Windows Push Notifications User Service_127d39 Status: Start Type:
loaded automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE
* This service hosts Windows notification platform which provides support for local
and push notifications. Supported notifications are tile, toast and raw. Host
Process for Windows Services Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K UNISTACKSVCGROUP
[Auto Services] :HKLM wscsvc
### Service: Security Center Status: Start Type: loaded automatically by Server
Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * The WSCSVC (Windows Security
Center) service monitors and reports security health settings on the computer. The
health settings include firewall (on/off), antivirus (on/off/out of date),
antispyware (on/off/out of date), Windows Update (automatically/manually download
and install updates), User Account Control (on/off), and Internet settings
(recommended/not recommended). The service provides COM APIs for independent
software vendors to register and record the state of their products to the Security
Center service. The Security and Maintenance UI uses the service to provide
systray alerts and a graphical view of the security health states in the Security
and Maintenance control panel. Network Access Protection (NAP) uses the service to
report the security health states of clients to the NAP Network Policy Server to
make network quarantine decisions. The service also has a public API that allows
external consumers to programmatically retrieve the aggregated security health
state of the system. Host Process for Windows Services Microsoft Corporation
Microsoft� Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICENETWORKRESTRICTED -P
[Auto Services] :HKLM WSearch
### Service: Windows Search Status: Start Type: loaded automatically by Server
Manager Actual File: C:\WINDOWS\SYSTEM32\SEARCHINDEXER.EXE * Provides content
indexing, property caching, and search results for files, e-mail, and other
content. Microsoft Windows Search Indexer Microsoft Corporation Windows� Search
7.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\SEARCHINDEXER.EXE /EMBEDDING
[Auto Services] :HKLM wuauserv
### Service: Windows Update Status: Start Type: loaded manually on demand Actual
File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Enables the detection, download, and
installation of updates for Windows and other programs. If this service is
disabled, users of this computer will not be able to use Windows Update or its
automatic updating feature, and programs will not be able to use the Windows Update
Agent (WUA) API. Host Process for Windows Services Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K
NETSVCS -P
[Auto Services] :HKLM WwanSvc
### Service: WWAN AutoConfig Status: Start Type: loaded automatically by Server
Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * This service manages mobile
broadband (GSM & CDMA) data card/embedded module adapters and connections by auto-
configuring the networks. It is strongly recommended that this service be kept
running for best user experience of mobile broadband devices. Host Process for
Windows Services Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED
-P
[Auto Services] :HKLM XblAuthManager
### Service: Xbox Live Auth Manager Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Provides authentication and
authorization services for interacting with Xbox Live. If this service is stopped,
some applications may not operate correctly. Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1 !$*
%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS -P
[Auto Services] :HKLM XblGameSave
### Service: Xbox Live Game Save Status: Start Type: loaded manually on demand
Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * This service syncs save data for
Xbox Live save enabled games. If this service is stopped, game save data will not
upload to or download from Xbox Live. Host Process for Windows Services Microsoft
Corporation Microsoft� Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K NETSVCS -P
[Auto Services] :HKLM XboxGipSvc
### Service: Xbox Accessory Management Service Status: Start Type: loaded
manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * This service
manages connected Xbox Accessories. Host Process for Windows Services Microsoft
Corporation Microsoft� Windows� Operating System 10.0.17763.1 !$*%SYSTEMROOT
%\SYSTEM32\SVCHOST.EXE -K NETSVCS -P
[Auto Services] :HKLM XboxNetApiSvc
### Service: Xbox Live Networking Service Status: Start Type: loaded manually on
demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * This service supports the
Windows.Networking.XboxLive application programming interface. Host Process for
Windows Services Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS -P
[Svchost DLLs] :HKLM CertPropSvc=C:\WINDOWS\SYSTEM32\CERTPROP.DLL
### Microsoft Smartcard Certificate Propagation Service Microsoft Corporation
Microsoft� Windows� Operating System 10.0.17763.1 !$*%SystemRoot
%\System32\certprop.dll
[Svchost DLLs] :HKLM SCPolicySvc=C:\WINDOWS\SYSTEM32\CERTPROP.DLL
### Microsoft Smartcard Certificate Propagation Service Microsoft Corporation
Microsoft� Windows� Operating System 10.0.17763.1 !$*%SystemRoot
%\System32\certprop.dll
[Svchost DLLs] :HKLM lanmanserver=C:\WINDOWS\SYSTEM32\SRVSVC.DLL
### Server Service DLL Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*%SystemRoot%\system32\srvsvc.dll
[Svchost DLLs] :HKLM gpsvc=C:\WINDOWS\SYSTEM32\GPSVC.DLL
### Group Policy Client Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*%SystemRoot%\System32\gpsvc.dll
[Svchost DLLs] :HKLM iphlpsvc=C:\WINDOWS\SYSTEM32\IPHLPSVC.DLL
### Service that offers IPv6 connectivity over an IPv4 network. Microsoft
Corporation Microsoft� Windows� Operating System 10.0.17763.1 !$*%SystemRoot
%\System32\iphlpsvc.dll
[Svchost DLLs] :HKLM msiscsi=C:\WINDOWS\SYSTEM32\ISCSIEXE.DLL
### iSCSI Discovery service Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*%systemroot%\system32\iscsiexe.dll
[Svchost DLLs] :HKLM schedule=C:\WINDOWS\SYSTEM32\SCHEDSVC.DLL
### Task Scheduler Service Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*%systemroot%\system32\schedsvc.dll
[Svchost DLLs] :HKLM winmgmt=C:\WINDOWS\SYSTEM32\WBEM\WMISVC.DLL
### WMI Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1 !
$*%SystemRoot%\system32\wbem\WMIsvc.dll
[Svchost DLLs] :HKLM SessionEnv=C:\WINDOWS\SYSTEM32\SESSENV.DLL
### Remote Desktop Configuration service Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 !$*%SystemRoot%\system32\sessenv.dll
[Svchost DLLs] :HKLM UserManager=C:\WINDOWS\SYSTEM32\USERMGR.DLL
### UserMgr Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*%SystemRoot%\System32\usermgr.dll
[Svchost DLLs] :HKLM FastUserSwitchingCompatibility
[Svchost DLLs] :HKLM Ias
[Svchost DLLs] :HKLM Irmon=C:\WINDOWS\SYSTEM32\IRMON.DLL
### Infrared Monitor Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*%SystemRoot%\System32\irmon.dll
[Svchost DLLs] :HKLM Nla
[Svchost DLLs] :HKLM Ntmssvc
[Svchost DLLs] :HKLM NWCWorkstation
[Svchost DLLs] :HKLM Nwsapagent
[Svchost DLLs] :HKLM Rasauto=C:\WINDOWS\SYSTEM32\RASAUTO.DLL
### Remote Access AutoDial Manager Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%SystemRoot%\System32\rasauto.dll
[Svchost DLLs] :HKLM Rasman=C:\WINDOWS\SYSTEM32\RASMANS.DLL
### Remote Access Connection Manager Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%SystemRoot%\System32\rasmans.dll
[Svchost DLLs] :HKLM Remoteaccess=C:\WINDOWS\SYSTEM32\MPRDIM.DLL
### Dynamic Interface Manager Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*%SystemRoot%\System32\mprdim.dll
[Svchost DLLs] :HKLM SENS=C:\WINDOWS\SYSTEM32\SENS.DLL
### System Event Notification Service (SENS) Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 !$*%SystemRoot%\System32\sens.dll
[Svchost DLLs] :HKLM Sharedaccess=C:\WINDOWS\SYSTEM32\IPNATHLP.DLL
### Microsoft NAT Helper Components Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%SystemRoot%\System32\ipnathlp.dll
[Svchost DLLs] :HKLM SRService
[Svchost DLLs] :HKLM Tapisrv=C:\WINDOWS\SYSTEM32\TAPISRV.DLL
### Microsoft� Windows(TM) Telephony Server Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 !$*%SystemRoot%\System32\tapisrv.dll
[Svchost DLLs] :HKLM Wmi
[Svchost DLLs] :HKLM WmdmPmSp
[Svchost DLLs] :HKLM wuauserv=C:\WINDOWS\SYSTEM32\WUAUENG.DLL
### Windows Update Agent Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*%systemroot%\system32\wuaueng.dll
[Svchost DLLs] :HKLM BITS=C:\WINDOWS\SYSTEM32\QMGR.DLL
### Background Intelligent Transfer Service Microsoft Corporation Microsoft�
Windows� Operating System 7.8.17763.1 !$*%SystemRoot%\System32\qmgr.dll
[Svchost DLLs] :HKLM ShellHWDetection=C:\WINDOWS\SYSTEM32\SHSVCS.DLL
### Windows Shell Services Dll Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%SystemRoot%\System32\shsvcs.dll
[Svchost DLLs] :HKLM LogonHours
[Svchost DLLs] :HKLM PCAudit
[Svchost DLLs] :HKLM helpsvc
[Svchost DLLs] :HKLM uploadmgr
[Svchost DLLs] :HKLM TokenBroker=C:\WINDOWS\SYSTEM32\TOKENBROKER.DLL
### Token Broker Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*%SystemRoot%\System32\TokenBroker.dll
[Svchost DLLs] :HKLM AppMgmt=C:\WINDOWS\SYSTEM32\APPMGMTS.DLL
### Software installation Service Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%SystemRoot%\System32\appmgmts.dll
[Svchost DLLs] :HKLM ScDeviceEnum=C:\WINDOWS\SYSTEM32\SCDEVICEENUM.DLL
### Smart Card Device Enumeration Service Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 !$*%SystemRoot%\System32\ScDeviceEnum.dll
[Svchost DLLs] :HKLM WiaRpc=C:\WINDOWS\SYSTEM32\WIARPC.DLL
### Windows Image Acquisition RPC client DLL Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 !$*%SystemRoot%\System32\wiarpc.dll
[Svchost DLLs] :HKLM
AudioEndpointBuilder=C:\WINDOWS\SYSTEM32\AUDIOENDPOINTBUILDER.DLL
### Windows Audio Endpoint Builder Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%SystemRoot%\System32\AudioEndpointBuilder.dll
[Svchost DLLs] :HKLM dot3svc=C:\WINDOWS\SYSTEM32\DOT3SVC.DLL
### Wired AutoConfig Service Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*%SystemRoot%\System32\dot3svc.dll
[Svchost DLLs] :HKLM DeviceAssociationService=C:\WINDOWS\SYSTEM32\DAS.DLL
### Device Association Service Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%SystemRoot%\system32\das.dll
[Svchost DLLs] :HKLM Netman=C:\WINDOWS\SYSTEM32\NETMAN.DLL
### Network Connections Manager Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%SystemRoot%\System32\netman.dll
[Svchost DLLs] :HKLM wlansvc=C:\WINDOWS\SYSTEM32\WLANSVC.DLL
### Windows WLAN AutoConfig Service DLL Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%SystemRoot%\System32\wlansvc.dll
[Svchost DLLs] :HKLM NcbService=C:\WINDOWS\SYSTEM32\NCBSERVICE.DLL
### Network Connection Broker Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*%SystemRoot%\System32\ncbservice.dll
[Svchost DLLs] :HKLM WPDBusEnum=C:\WINDOWS\SYSTEM32\WPDBUSENUM.DLL
### Portable Device Enumerator Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%SystemRoot%\system32\wpdbusenum.dll
[Svchost DLLs] :HKLM netprofm=C:\WINDOWS\SYSTEM32\NETPROFMSVC.DLL
### Network List Manager Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*%SystemRoot%\System32\netprofmsvc.dll
[Svchost DLLs] :HKLM WinHttpAutoProxySvc=C:\WINDOWS\SYSTEM32\WINHTTP.DLL
### Windows HTTP Services Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*%SystemRoot%\system32\winhttp.dll
[Svchost DLLs] :HKLM WebClient=C:\WINDOWS\SYSTEM32\WEBCLNT.DLL
### Web DAV Service DLL Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*%SystemRoot%\System32\webclnt.dll
[Svchost DLLs] :HKLM StiSvc=C:\WINDOWS\SYSTEM32\WIASERVC.DLL
### Still Image Devices Service Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%SystemRoot%\System32\wiaservc.dll
[Svchost DLLs] :HKLM PLA=C:\WINDOWS\SYSTEM32\PLA.DLL
### Performance Logs & Alerts Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*%systemroot%\system32\pla.dll
[Svchost DLLs] :HKLM smphost=C:\WINDOWS\SYSTEM32\SMPHOST.DLL
### Storage Management Provider (SMP) host service Microsoft Corporation
Microsoft� Windows� Operating System 10.0.17763.1 !$*%Systemroot
%\System32\smphost.dll
[Svchost DLLs] :HKLM RpcSs=C:\WINDOWS\SYSTEM32\RPCSS.DLL
### Distributed COM Services Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*%SystemRoot%\system32\rpcss.dll
[Svchost DLLs] :HKLM AudioSrv=C:\WINDOWS\SYSTEM32\AUDIOSRV.DLL
### Windows Audio Service Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*%SystemRoot%\System32\Audiosrv.dll
[Svchost DLLs] :HKLM wscsvc=C:\WINDOWS\SYSTEM32\WSCSVC.DLL
### Windows Security Center Service Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%SystemRoot%\System32\wscsvc.dll
[Svchost DLLs] :HKLM LmHosts=C:\WINDOWS\SYSTEM32\LMHSVC.DLL
### TCPIP NetBios Transport Services DLL Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 !$*%SystemRoot%\System32\lmhsvc.dll
[Svchost DLLs] :HKLM DHCP=C:\WINDOWS\SYSTEM32\DHCPCORE.DLL
### DHCP Client Service Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*%SystemRoot%\system32\dhcpcore.dll
[Svchost DLLs] :HKLM PNRPSvc=C:\WINDOWS\SYSTEM32\PNRPSVC.DLL
### PNRP Service Dll Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*%SystemRoot%\system32\pnrpsvc.dll
[Svchost DLLs] :HKLM p2pimsvc=C:\WINDOWS\SYSTEM32\PNRPSVC.DLL
### PNRP Service Dll Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*%SystemRoot%\system32\pnrpsvc.dll
[Svchost DLLs] :HKLM p2psvc=C:\WINDOWS\SYSTEM32\P2PSVC.DLL
### Peer-to-Peer Services Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*%SystemRoot%\system32\p2psvc.dll
[Svchost DLLs] :HKLM PnrpAutoReg=C:\WINDOWS\SYSTEM32\PNRPAUTO.DLL
### PNRP Auto Service Dll Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*%SystemRoot%\system32\pnrpauto.dll
[Svchost DLLs] :HKLM camsvc=C:\WINDOWS\SYSTEM32\CAPABILITYACCESSMANAGER.DLL
### Capability Access Manager Service Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%SystemRoot%\system32\CapabilityAccessManager.dll
[Svchost DLLs] :HKLM
StateRepository=C:\WINDOWS\SYSTEM32\WINDOWS.STATEREPOSITORY.DLL
### Windows StateRepository API Server Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%SystemRoot%\system32\windows.staterepository.dll
[Svchost DLLs] :HKLM SSDPSRV=C:\WINDOWS\SYSTEM32\SSDPSRV.DLL
### SSDP Service DLL Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*%SystemRoot%\System32\ssdpsrv.dll
[Svchost DLLs] :HKLM upnphost=C:\WINDOWS\SYSTEM32\UPNPHOST.DLL
### UPnP Device Host Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*%SystemRoot%\System32\upnphost.dll
[Svchost DLLs] :HKLM SCardSvr=C:\WINDOWS\SYSTEM32\SCARDSVR.DLL
### Smart Card Resource Management Server Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 !$*%SystemRoot%\System32\SCardSvr.dll
[Svchost DLLs] :HKLM BthHFSrv
[Svchost DLLs] :HKLM QWAVE=C:\WINDOWS\SYSTEM32\QWAVE.DLL
### Windows NT Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*%windir%\system32\qwave.dll
[Svchost DLLs] :HKLM wcncsvc=C:\WINDOWS\SYSTEM32\WCNCSVC.DLL
### Windows Connect Now - Config Registrar Service Microsoft Corporation
Microsoft� Windows� Operating System 10.0.17763.1 !$*%SystemRoot
%\System32\wcncsvc.dll
[Svchost DLLs] :HKLM DcomLaunch=C:\WINDOWS\SYSTEM32\RPCSS.DLL
### Distributed COM Services Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*%SystemRoot%\system32\rpcss.dll
[Svchost DLLs] :HKLM DeviceInstall=C:\WINDOWS\SYSTEM32\UMPNPMGR.DLL
### User-mode Plug-and-Play Service Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%SystemRoot%\system32\umpnpmgr.dll
[Svchost DLLs] :HKLM
PrintWorkflowUserSvc=C:\WINDOWS\SYSTEM32\PRINTWORKFLOWSERVICE.DLL
### Microsoft Windows Print Workflow Service Internal Microsoft Corporation
Microsoft� Windows� Operating System 10.0.17763.1 !$*%SystemRoot
%\System32\PrintWorkflowService.dll
[Svchost DLLs] :HKLM CryptSvc=C:\WINDOWS\SYSTEM32\CRYPTSVC.DLL
### Cryptographic Services Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*%SystemRoot%\system32\cryptsvc.dll
[Svchost DLLs] :HKLM WinRM=C:\WINDOWS\SYSTEM32\WSMSVC.DLL
### WSMan Service Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*%SystemRoot%\system32\WsmSvc.dll
[Svchost DLLs] :HKLM WECSVC=C:\WINDOWS\SYSTEM32\WECSVC.DLL
### Event Collector Service Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*%SystemRoot%\system32\wecsvc.dll
[Svchost DLLs] :HKLM DNSCache=C:\WINDOWS\SYSTEM32\DNSRSLVR.DLL
### DNS Caching Resolver Service Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%SystemRoot%\System32\dnsrslvr.dll
[Svchost DLLs] :HKLM TermService=C:\WINDOWS\SYSTEM32\TERMSRV.DLL
### Remote Desktop Session Host Server Remote Connections Manager Microsoft
Corporation Microsoft� Windows� Operating System 10.0.17763.1 !$*%SystemRoot
%\System32\termsrv.dll
[Svchost DLLs] :HKLM AJRouter=C:\WINDOWS\SYSTEM32\AJROUTER.DLL
### AllJoyn Router Service DLL Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%SystemRoot%\System32\AJRouter.dll
[Svchost DLLs] :HKLM AppIDSvc=C:\WINDOWS\SYSTEM32\APPIDSVC.DLL
### Application Identity Service Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%SystemRoot%\System32\appidsvc.dll
[Svchost DLLs] :HKLM Appinfo=C:\WINDOWS\SYSTEM32\APPINFO.DLL
### Application Information Service Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%SystemRoot%\System32\appinfo.dll
[Svchost DLLs] :HKLM AppReadiness=C:\WINDOWS\SYSTEM32\APPREADINESS.DLL
### AppReadiness Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*%SystemRoot%\system32\AppReadiness.dll
[Svchost DLLs] :HKLM
AssignedAccessManagerSvc=C:\WINDOWS\SYSTEM32\ASSIGNEDACCESSMANAGERSVC.DLL
### AssignedAccessManagerSvc Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*%SystemRoot%\System32\assignedaccessmanagersvc.dll
[Svchost DLLs] :HKLM AxInstSV=C:\WINDOWS\SYSTEM32\AXINSTSV.DLL
### ActiveX Installer Service Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*%SystemRoot%\System32\AxInstSV.dll
[Svchost DLLs] :HKLM
BcastDVRUserService=C:\WINDOWS\SYSTEM32\BCASTDVRUSERSERVICE.DLL
### Broadcast DVR User Service Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%SystemRoot%\System32\BcastDVRUserService.dll
[Svchost DLLs] :HKLM BDESVC=C:\WINDOWS\SYSTEM32\BDESVC.DLL
### BDE Service Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*%SystemRoot%\System32\bdesvc.dll
[Svchost DLLs] :HKLM BFE=C:\WINDOWS\SYSTEM32\BFE.DLL
### Base Filtering Engine Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*%SystemRoot%\System32\bfe.dll
[Svchost DLLs] :HKLM
BluetoothUserService=C:\WINDOWS\SYSTEM32\MICROSOFT.BLUETOOTH.USERSERVICE.DLL
### Bluetooth User Support Service Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%SystemRoot
%\System32\Microsoft.Bluetooth.UserService.dll
[Svchost DLLs] :HKLM BrokerInfrastructure=C:\WINDOWS\SYSTEM32\PSMSRV.DLL
### Process State Manager (PSM) Service Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%SystemRoot%\System32\psmsrv.dll
[Svchost DLLs] :HKLM BTAGService=C:\WINDOWS\SYSTEM32\BTAGSERVICE.DLL
### Bluetooth Audio Gateway Service Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%SystemRoot%\System32\BTAGService.dll
[Svchost DLLs] :HKLM BthAvctpSvc=C:\WINDOWS\SYSTEM32\BTHAVCTPSVC.DLL
### Bluetooth AVCTP Service DLL Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%SystemRoot%\System32\BthAvctpSvc.dll
[Svchost DLLs] :HKLM bthserv=C:\WINDOWS\SYSTEM32\BTHSERV.DLL
### Bluetooth Support Service Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*%SystemRoot%\system32\bthserv.dll
[Svchost DLLs] :HKLM CaptureService=C:\WINDOWS\SYSTEM32\CAPTURESERVICE.DLL
### Microsoft Windows Capture User Service Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 !$*%SystemRoot%\System32\CaptureService.dll
[Svchost DLLs] :HKLM cbdhsvc=C:\WINDOWS\SYSTEM32\CBDHSVC.DLL
### Microsoft (R) Clipboard History Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%SystemRoot%\System32\cbdhsvc.dll
[Svchost DLLs] :HKLM CDPSvc=C:\WINDOWS\SYSTEM32\CDPSVC.DLL
### Microsoft (R) CDP Service Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*%SystemRoot%\System32\CDPSvc.dll
[Svchost DLLs] :HKLM CDPUserSvc=C:\WINDOWS\SYSTEM32\CDPUSERSVC.DLL
### Microsoft (R) CDP User Components Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%SystemRoot%\System32\CDPUserSvc.dll
[Svchost DLLs] :HKLM ClipSVC=C:\WINDOWS\SYSTEM32\CLIPSVC.DLL
### Client License Service Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*%SystemRoot%\System32\ClipSVC.dll
[Svchost DLLs] :HKLM ConsentUxUserSvc=C:\WINDOWS\SYSTEM32\CONSENTUXCLIENT.DLL
### Implementation of client-side Consent UX API Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 !$*%SystemRoot%\System32\ConsentUxClient.dll
[Svchost DLLs] :HKLM CoreMessagingRegistrar=C:\WINDOWS\SYSTEM32\COREMESSAGING.DLL
### Microsoft CoreMessaging Dll Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%SystemRoot%\system32\coremessaging.dll
[Svchost DLLs] :HKLM CscService=C:\WINDOWS\SYSTEM32\CSCSVC.DLL
### CSC Service DLL Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*%SystemRoot%\System32\cscsvc.dll
[Svchost DLLs] :HKLM defragsvc=C:\WINDOWS\SYSTEM32\DEFRAGSVC.DLL
### Microsoft\Drive Optimizer Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*%Systemroot%\System32\defragsvc.dll
[Svchost DLLs] :HKLM
DevicePickerUserSvc=C:\WINDOWS\SYSTEM32\WINDOWS.DEVICES.PICKER.DLL
### Device Picker Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*%SystemRoot%\System32\Windows.Devices.Picker.dll
[Svchost DLLs] :HKLM DevicesFlowUserSvc=C:\WINDOWS\SYSTEM32\DEVICESFLOWBROKER.DLL
### DevicesFlow Broker Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*%SystemRoot%\System32\DevicesFlowBroker.dll
[Svchost DLLs] :HKLM DevQueryBroker=C:\WINDOWS\SYSTEM32\DEVQUERYBROKER.DLL
### DevQuery Background Discovery Broker Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 !$*%SystemRoot%\system32\DevQueryBroker.dll
[Svchost DLLs] :HKLM diagsvc=C:\WINDOWS\SYSTEM32\DIAGSVC.DLL
### Microsoft Windows operating system Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%systemroot%\system32\DiagSvc.dll
[Svchost DLLs] :HKLM DiagTrack=C:\WINDOWS\SYSTEM32\DIAGTRACK.DLL
### Microsoft Windows Diagnostics Tracking Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 !$*%SystemRoot%\system32\diagtrack.dll
[Svchost DLLs] :HKLM
DisplayEnhancementService=C:\WINDOWS\SYSTEM32\MICROSOFT.GRAPHICS.DISPLAY.DISPLAYENH
ANCEMENTSERVICE.DLL
### Microsoft.Graphics.Display.DisplayEnhancementService DLL Microsoft
Corporation Microsoft� Windows� Operating System 10.0.17763.1 !$*%SystemRoot
%\system32\Microsoft.Graphics.Display.DisplayEnhancementService.dll
[Svchost DLLs] :HKLM
DmEnrollmentSvc=C:\WINDOWS\SYSTEM32\WINDOWS.INTERNAL.MANAGEMENT.DLL
### Windows Managent Service DLL Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%systemroot
%\system32\Windows.Internal.Management.dll
[Svchost DLLs] :HKLM dmwappushservice=C:\WINDOWS\SYSTEM32\DMWAPPUSHSVC.DLL
### dmwappushsvc Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*%SystemRoot%\system32\dmwappushsvc.dll
[Svchost DLLs] :HKLM DPS=C:\WINDOWS\SYSTEM32\DPS.DLL
### WDI Diagnostic Policy Service Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%SystemRoot%\system32\dps.dll
[Svchost DLLs] :HKLM DsmSvc=C:\WINDOWS\SYSTEM32\DEVICESETUPMANAGER.DLL
### Device Setup Manager Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*%SystemRoot%\System32\DeviceSetupManager.dll
[Svchost DLLs] :HKLM DsSvc=C:\WINDOWS\SYSTEM32\DSSVC.DLL
### Data Sharing Service NT Service DLL Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%SystemRoot%\System32\DsSvc.dll
[Svchost DLLs] :HKLM DusmSvc=C:\WINDOWS\SYSTEM32\DUSMSVC.DLL
### Data Usage Service Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*%SystemRoot%\System32\dusmsvc.dll
[Svchost DLLs] :HKLM Eaphost=C:\WINDOWS\SYSTEM32\EAPSVC.DLL
### Microsoft EAPHost service Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*%SystemRoot%\System32\eapsvc.dll
[Svchost DLLs] :HKLM EFS=C:\WINDOWS\SYSTEM32\EFSSVC.DLL
### EFS Service Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*%SystemRoot%\system32\efssvc.dll
[Svchost DLLs] :HKLM embeddedmode=C:\WINDOWS\SYSTEM32\EMBEDDEDMODESVC.DLL
### Debug Register Service Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*%SystemRoot%\System32\embeddedmodesvc.dll
[Svchost DLLs] :HKLM EventLog=C:\WINDOWS\SYSTEM32\WEVTSVC.DLL
### Event Logging Service Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*%SystemRoot%\System32\wevtsvc.dll
[Svchost DLLs] :HKLM EventSystem=C:\WINDOWS\SYSTEM32\ES.DLL
### COM+ Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*%systemroot%\system32\es.dll
[Svchost DLLs] :HKLM fdPHost=C:\WINDOWS\SYSTEM32\FDPHOST.DLL
### Function Discovery Provider host service Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 !$*%SystemRoot%\system32\fdPHost.dll
[Svchost DLLs] :HKLM FDResPub=C:\WINDOWS\SYSTEM32\FDRESPUB.DLL
### Function Discovery Resource Publication Service Microsoft Corporation
Microsoft� Windows� Operating System 10.0.17763.1 !$*%SystemRoot
%\system32\fdrespub.dll
[Svchost DLLs] :HKLM fhsvc=C:\WINDOWS\SYSTEM32\FHSVC.DLL
### File History Service Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*%SystemRoot%\system32\fhsvc.dll
[Svchost DLLs] :HKLM FontCache=C:\WINDOWS\SYSTEM32\FNTCACHE.DLL
### Windows Font Cache Service Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%SystemRoot%\system32\FntCache.dll
[Svchost DLLs] :HKLM GraphicsPerfSvc=C:\WINDOWS\SYSTEM32\GRAPHICSPERFSVC.DLL
### GraphicsPerfSvc Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*%SystemRoot%\System32\GraphicsPerfSvc.dll
[Svchost DLLs] :HKLM hidserv=C:\WINDOWS\SYSTEM32\HIDSERV.DLL
### Human Interface Device Service Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%SystemRoot%\system32\hidserv.dll
[Svchost DLLs] :HKLM HomeGroupListener=C:\WINDOWS\SYSTEM32\LISTSVC.DLL
### Windows HomeGroup Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*%SystemRoot%\system32\ListSvc.dll
[Svchost DLLs] :HKLM HomeGroupProvider=C:\WINDOWS\SYSTEM32\PROVSVC.DLL
### Windows HomeGroup Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*%SystemRoot%\system32\provsvc.dll
[Svchost DLLs] :HKLM HvHost=C:\WINDOWS\SYSTEM32\HVHOSTSVC.DLL
### Microsoft Hypervisor Host Service Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%SystemRoot%\System32\hvhostsvc.dll
[Svchost DLLs] :HKLM icssvc=C:\WINDOWS\SYSTEM32\TETHERINGSERVICE.DLL
### Tethering Service Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*%SystemRoot%\System32\tetheringservice.dll
[Svchost DLLs] :HKLM IKEEXT=C:\WINDOWS\SYSTEM32\IKEEXT.DLL
### IKE extension Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*%SystemRoot%\System32\ikeext.dll
[Svchost DLLs] :HKLM InstallService=C:\WINDOWS\SYSTEM32\INSTALLSERVICE.DLL
### InstallService Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*%SystemRoot%\system32\InstallService.dll
[Svchost DLLs] :HKLM IpxlatCfgSvc=C:\WINDOWS\SYSTEM32\IPXLATCFG.DLL
### IP Translation Configuration Service Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 !$*%SystemRoot%\System32\IpxlatCfg.dll
[Svchost DLLs] :HKLM KeyIso=C:\WINDOWS\SYSTEM32\KEYISO.DLL
### CNG Key Isolation Service Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*%SystemRoot%\system32\keyiso.dll
[Svchost DLLs] :HKLM KtmRm=C:\WINDOWS\SYSTEM32\MSDTCKRM.DLL
### Microsoft Distributed Transaction Coordinator OLE Transactions KTM Resource
Manager DLL Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1
!$*%systemroot%\system32\msdtckrm.dll
[Svchost DLLs] :HKLM LanmanWorkstation=C:\WINDOWS\SYSTEM32\WKSSVC.DLL
### Workstation Service DLL Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*%SystemRoot%\System32\wkssvc.dll
[Svchost DLLs] :HKLM lfsvc=C:\WINDOWS\SYSTEM32\LFSVC.DLL
### Geolocation Service Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*%SystemRoot%\System32\lfsvc.dll
[Svchost DLLs] :HKLM LicenseManager=C:\WINDOWS\SYSTEM32\LICENSEMANAGERSVC.DLL
### LicenseManagerSvc Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*%SystemRoot%\system32\LicenseManagerSvc.dll
[Svchost DLLs] :HKLM lltdsvc=C:\WINDOWS\SYSTEM32\LLTDSVC.DLL
### Link-Layer Topology Mapper Service Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%SystemRoot%\System32\lltdsvc.dll
[Svchost DLLs] :HKLM LSM=C:\WINDOWS\SYSTEM32\LSM.DLL
### Local Session Manager Service Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%SystemRoot%\System32\lsm.dll
[Svchost DLLs] :HKLM LxpSvc=C:\WINDOWS\SYSTEM32\LANGUAGEOVERLAYSERVER.DLL
### Provides infrastructure support for deploying and configuring localized
Windows resources. Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*%SystemRoot%\System32\LanguageOverlayServer.dll
[Svchost DLLs] :HKLM MapsBroker=C:\WINDOWS\SYSTEM32\MOSHOST.DLL
### Downloaded Maps Manager Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*%SystemRoot%\System32\moshost.dll
[Svchost DLLs] :HKLM MessagingService=C:\WINDOWS\SYSTEM32\MESSAGINGSERVICE.DLL
### Messaging Service Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*%SystemRoot%\System32\MessagingService.dll
[Svchost DLLs] :HKLM mpssvc=C:\WINDOWS\SYSTEM32\MPSSVC.DLL
### Microsoft Protection Service Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%SystemRoot%\system32\mpssvc.dll
[Svchost DLLs] :HKLM NaturalAuthentication=C:\WINDOWS\SYSTEM32\NATURALAUTH.DLL
### Natural Authentication Service Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%SystemRoot%\System32\NaturalAuth.dll
[Svchost DLLs] :HKLM NcaSvc=C:\WINDOWS\SYSTEM32\NCASVC.DLL
### Microsoft Network Connectivity Assistant Service Microsoft Corporation
Microsoft� Windows� Operating System 10.0.17763.1 !$*%SystemRoot
%\System32\ncasvc.dll
[Svchost DLLs] :HKLM NcdAutoSetup=C:\WINDOWS\SYSTEM32\NCDAUTOSETUP.DLL
### Network Connected Devices Auto-Setup service DLL Microsoft Corporation
Microsoft� Windows� Operating System 10.0.17763.1 !$*%SystemRoot
%\System32\NcdAutoSetup.dll
[Svchost DLLs] :HKLM Netlogon=C:\WINDOWS\SYSTEM32\NETLOGON.DLL
### Net Logon Services DLL Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*%SystemRoot%\system32\netlogon.dll
[Svchost DLLs] :HKLM NetSetupSvc=C:\WINDOWS\SYSTEM32\NETSETUPSVC.DLL
### Network Setup Service Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*%SystemRoot%\System32\NetSetupSvc.dll
[Svchost DLLs] :HKLM NgcCtnrSvc=C:\WINDOWS\SYSTEM32\NGCCTNRSVC.DLL
### Microsoft Passport Container Service Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 !$*%SystemRoot%\System32\NgcCtnrSvc.dll
[Svchost DLLs] :HKLM NgcSvc=C:\WINDOWS\SYSTEM32\NGCSVC.DLL
### Microsoft Passport Service Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%SystemRoot%\system32\ngcsvc.dll
[Svchost DLLs] :HKLM NlaSvc=C:\WINDOWS\SYSTEM32\NLASVC.DLL
### Network Location Awareness 2 Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%SystemRoot%\System32\nlasvc.dll
[Svchost DLLs] :HKLM nsi=C:\WINDOWS\SYSTEM32\NSISVC.DLL
### Network Store Interface RPC server Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%systemroot%\system32\nsisvc.dll
[Svchost DLLs] :HKLM OneSyncSvc=C:\WINDOWS\SYSTEM32\APHOSTSERVICE.DLL
### Accounts Host Service Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*%SystemRoot%\System32\APHostService.dll
[Svchost DLLs] :HKLM PcaSvc=C:\WINDOWS\SYSTEM32\PCASVC.DLL
### Program Compatibility Assistant Service Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 !$*%SystemRoot%\System32\pcasvc.dll
[Svchost DLLs] :HKLM PhoneSvc=C:\WINDOWS\SYSTEM32\PHONESERVICE.DLL
### The service used to manage phone calls and other telephony related
functionality Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*%SystemRoot%\System32\PhoneService.dll
[Svchost DLLs] :HKLM
PimIndexMaintenanceSvc=C:\WINDOWS\SYSTEM32\PIMINDEXMAINTENANCE.DLL
### Service responsible for contacts indexing and other user data related tasks
Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1 !$*
%SystemRoot%\System32\PimIndexMaintenance.dll
[Svchost DLLs] :HKLM PlugPlay=C:\WINDOWS\SYSTEM32\UMPNPMGR.DLL
### User-mode Plug-and-Play Service Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%SystemRoot%\system32\umpnpmgr.dll
[Svchost DLLs] :HKLM PolicyAgent=C:\WINDOWS\SYSTEM32\IPSECSVC.DLL
### Windows IPsec SPD Server DLL Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%SystemRoot%\System32\ipsecsvc.dll
[Svchost DLLs] :HKLM Power=C:\WINDOWS\SYSTEM32\UMPO.DLL
### User-mode Power Service Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*%SystemRoot%\system32\umpo.dll
[Svchost DLLs] :HKLM
PrintNotify=C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\X64\3\PRINTCONFIG.DLL
### PrintConfig User Interface Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1
[Svchost DLLs] :HKLM ProfSvc=C:\WINDOWS\SYSTEM32\PROFSVC.DLL
### ProfSvc Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*%systemroot%\system32\profsvc.dll
[Svchost DLLs] :HKLM PushToInstall=C:\WINDOWS\SYSTEM32\PUSHTOINSTALL.DLL
### PushToInstall Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*%SystemRoot%\system32\PushToInstall.dll
[Svchost DLLs] :HKLM RemoteRegistry=C:\WINDOWS\SYSTEM32\REGSVC.DLL
### Remote Registry Service Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*%SystemRoot%\system32\regsvc.dll
[Svchost DLLs] :HKLM RetailDemo=C:\WINDOWS\SYSTEM32\RDXSERVICE.DLL
### RDXService Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*%SystemRoot%\system32\RDXService.dll
[Svchost DLLs] :HKLM RmSvc=C:\WINDOWS\SYSTEM32\RMAPI.DLL
### Radio Manager API Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*%SystemRoot%\System32\RMapi.dll
[Svchost DLLs] :HKLM RpcEptMapper=C:\WINDOWS\SYSTEM32\RPCEPMAP.DLL
### RPC Endpoint Mapper Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*%SystemRoot%\System32\RpcEpMap.dll
[Svchost DLLs] :HKLM SDRSVC=C:\WINDOWS\SYSTEM32\SDRSVC.DLL
### Microsoft� Windows Backup Service Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%Systemroot%\System32\SDRSVC.dll
[Svchost DLLs] :HKLM seclogon=C:\WINDOWS\SYSTEM32\SECLOGON.DLL
### Secondary Logon Service DLL Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%windir%\system32\seclogon.dll
[Svchost DLLs] :HKLM SEMgrSvc=C:\WINDOWS\SYSTEM32\SEMGRSVC.DLL
### NFC SEManagement Service DLL Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%SystemRoot%\system32\SEMgrSvc.dll
[Svchost DLLs] :HKLM SensorService=C:\WINDOWS\SYSTEM32\SENSORSERVICE.DLL
### Sensor Service Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*%SystemRoot%\system32\SensorService.dll
[Svchost DLLs] :HKLM SensrSvc=C:\WINDOWS\SYSTEM32\SENSRSVC.DLL
### Microsoft Windows Sensor Monitoring Service Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 !$*%SystemRoot%\system32\sensrsvc.dll
[Svchost DLLs] :HKLM SharedRealitySvc=C:\WINDOWS\SYSTEM32\SHAREDREALITYSVC.DLL
### Microsoft (R) Spatial Data Service Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%SystemRoot%\System32\SharedRealitySvc.dll
[Svchost DLLs] :HKLM
shpamsvc=C:\WINDOWS\SYSTEM32\WINDOWS.SHAREDPC.ACCOUNTMANAGER.DLL
### SharedPC.AccountManager Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*%systemroot%\system32\Windows.SharedPC.AccountManager.dll
[Svchost DLLs] :HKLM SmsRouter=C:\WINDOWS\SYSTEM32\SMSROUTERSVC.DLL
### Windows SMS Router Service Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%SystemRoot%\system32\SmsRouterSvc.dll
[Svchost DLLs] :HKLM SstpSvc=C:\WINDOWS\SYSTEM32\SSTPSVC.DLL
### Provides the facility of using Secure Socket Tunneling Protocol (SSTP) to
connect to remote computers (using VPN). Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%SystemRoot%\system32\sstpsvc.dll
[Svchost DLLs] :HKLM StorSvc=C:\WINDOWS\SYSTEM32\STORSVC.DLL
### Storage Services Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*%SystemRoot%\system32\storsvc.dll
[Svchost DLLs] :HKLM svsvc=C:\WINDOWS\SYSTEM32\SVSVC.DLL
### Microsoft\Spot Verifier Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*%SystemRoot%\system32\svsvc.dll
[Svchost DLLs] :HKLM swprv=C:\WINDOWS\SYSTEM32\SWPRV.DLL
### Microsoft� Volume Shadow Copy Service software provider Microsoft Corporation
Microsoft� Windows� Operating System 10.0.17763.1 !$*%Systemroot
%\System32\swprv.dll
[Svchost DLLs] :HKLM SysMain=C:\WINDOWS\SYSTEM32\SYSMAIN.DLL
### SysMain Service Host Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*%systemroot%\system32\sysmain.dll
[Svchost DLLs] :HKLM
SystemEventsBroker=C:\WINDOWS\SYSTEM32\SYSTEMEVENTSBROKERSERVER.DLL
### System Events Broker Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*%SystemRoot%\System32\SystemEventsBrokerServer.dll
[Svchost DLLs] :HKLM TabletInputService=C:\WINDOWS\SYSTEM32\TABSVC.DLL
### Microsoft Touch Keyboard and Handwriting Panel Service Microsoft Corporation
Microsoft� Windows� Operating System 10.0.17763.1 !$*%SystemRoot
%\System32\TabSvc.dll
[Svchost DLLs] :HKLM Themes=C:\WINDOWS\SYSTEM32\THEMESERVICE.DLL
### Windows Shell Theme Service Dll Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%SystemRoot%\system32\themeservice.dll
[Svchost DLLs] :HKLM TimeBrokerSvc=C:\WINDOWS\SYSTEM32\TIMEBROKERSERVER.DLL
### Time Event Broker Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*%SystemRoot%\System32\TimeBrokerServer.dll
[Svchost DLLs] :HKLM TrkWks=C:\WINDOWS\SYSTEM32\TRKWKS.DLL
### Distributed Link Tracking Client Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%SystemRoot%\System32\trkwks.dll
[Svchost DLLs] :HKLM tzautoupdate=C:\WINDOWS\SYSTEM32\TZAUTOUPDATE.DLL
### Auto Time Zone Updater Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*%SystemRoot%\system32\tzautoupdate.dll
[Svchost DLLs] :HKLM UmRdpService=C:\WINDOWS\SYSTEM32\UMRDP.DLL
### Remote Desktop Services Device Redirector Service Microsoft Corporation
Microsoft� Windows� Operating System 10.0.17763.1 !$*%SystemRoot
%\System32\umrdp.dll
[Svchost DLLs] :HKLM UnistoreSvc=C:\WINDOWS\SYSTEM32\UNISTORE.DLL
### Unified Store Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*%SystemRoot%\System32\unistore.dll
[Svchost DLLs] :HKLM UserDataSvc=C:\WINDOWS\SYSTEM32\USERDATASERVICE.DLL
### The endpoint for 3rd party APIs to read/write user data Microsoft Corporation
Microsoft� Windows� Operating System 10.0.17763.1 !$*%SystemRoot
%\System32\userdataservice.dll
[Svchost DLLs] :HKLM UsoSvc=C:\WINDOWS\SYSTEM32\USOCORE.DLL
### Update Session Orchestrator Core Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%systemroot%\system32\usocore.dll
[Svchost DLLs] :HKLM VacSvc=C:\WINDOWS\SYSTEM32\VAC.DLL
### Volumetric Audio Compositor Service Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%SystemRoot%\System32\vac.dll
[Svchost DLLs] :HKLM VaultSvc=C:\WINDOWS\SYSTEM32\VAULTSVC.DLL
### Credential Manager Service Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1
[Svchost DLLs] :HKLM vmicguestinterface=C:\WINDOWS\SYSTEM32\ICSVC.DLL
### Virtual Machine Integration Component Service Microsoft Corporation
Microsoft� Windows� Operating System 10.0.17763.1 !$*%SystemRoot
%\System32\icsvc.dll
[Svchost DLLs] :HKLM vmicheartbeat=C:\WINDOWS\SYSTEM32\ICSVC.DLL
### Virtual Machine Integration Component Service Microsoft Corporation
Microsoft� Windows� Operating System 10.0.17763.1 !$*%SystemRoot
%\System32\icsvc.dll
[Svchost DLLs] :HKLM vmickvpexchange=C:\WINDOWS\SYSTEM32\ICSVC.DLL
### Virtual Machine Integration Component Service Microsoft Corporation
Microsoft� Windows� Operating System 10.0.17763.1 !$*%SystemRoot
%\System32\icsvc.dll
[Svchost DLLs] :HKLM vmicrdv=C:\WINDOWS\SYSTEM32\ICSVCEXT.DLL
### Virtual Machine Integration Component Service Microsoft Corporation
Microsoft� Windows� Operating System 10.0.17763.1 !$*%SystemRoot
%\System32\icsvcext.dll
[Svchost DLLs] :HKLM vmicshutdown=C:\WINDOWS\SYSTEM32\ICSVC.DLL
### Virtual Machine Integration Component Service Microsoft Corporation
Microsoft� Windows� Operating System 10.0.17763.1 !$*%SystemRoot
%\System32\icsvc.dll
[Svchost DLLs] :HKLM vmictimesync=C:\WINDOWS\SYSTEM32\ICSVC.DLL
### Virtual Machine Integration Component Service Microsoft Corporation
Microsoft� Windows� Operating System 10.0.17763.1 !$*%SystemRoot
%\System32\icsvc.dll
[Svchost DLLs] :HKLM vmicvmsession=C:\WINDOWS\SYSTEM32\ICSVC.DLL
### Virtual Machine Integration Component Service Microsoft Corporation
Microsoft� Windows� Operating System 10.0.17763.1 !$*%SystemRoot
%\System32\icsvc.dll
[Svchost DLLs] :HKLM vmicvss=C:\WINDOWS\SYSTEM32\ICSVCEXT.DLL
### Virtual Machine Integration Component Service Microsoft Corporation
Microsoft� Windows� Operating System 10.0.17763.1 !$*%SystemRoot
%\System32\icsvcext.dll
[Svchost DLLs] :HKLM W32Time=C:\WINDOWS\SYSTEM32\W32TIME.DLL
### Windows Time Service Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*%systemroot%\system32\w32time.dll
[Svchost DLLs] :HKLM WaaSMedicSvc=C:\WINDOWS\SYSTEM32\WAASMEDICSVC.DLL
### WaasMedic Service Dll Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*%SystemRoot%\System32\WaaSMedicSvc.dll
[Svchost DLLs] :HKLM WalletService=C:\WINDOWS\SYSTEM32\WALLETSERVICE.DLL
### Wallet Service Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*%SystemRoot%\system32\WalletService.dll
[Svchost DLLs] :HKLM WarpJITSvc=C:\WINDOWS\SYSTEM32\WINDOWS.WARP.JITSERVICE.DLL
### WARP.JITService Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*%SystemRoot%\System32\Windows.WARP.JITService.dll
[Svchost DLLs] :HKLM WbioSrvc=C:\WINDOWS\SYSTEM32\WBIOSRVC.DLL
### Windows Biometric Service Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*%SystemRoot%\System32\wbiosrvc.dll
[Svchost DLLs] :HKLM Wcmsvc=C:\WINDOWS\SYSTEM32\WCMSVC.DLL
### Windows Connection Manager Service DLL Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 !$*%SystemRoot%\System32\wcmsvc.dll
[Svchost DLLs] :HKLM WdiServiceHost=C:\WINDOWS\SYSTEM32\WDI.DLL
### Windows Diagnostic Infrastructure Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%SystemRoot%\system32\wdi.dll
[Svchost DLLs] :HKLM WdiSystemHost=C:\WINDOWS\SYSTEM32\WDI.DLL
### Windows Diagnostic Infrastructure Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%SystemRoot%\system32\wdi.dll
[Svchost DLLs] :HKLM WEPHOSTSVC=C:\WINDOWS\SYSTEM32\WEPHOSTSVC.DLL
### WEP Host Service Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*%systemroot%\system32\wephostsvc.dll
[Svchost DLLs] :HKLM wercplsupport=C:\WINDOWS\SYSTEM32\WERCPLSUPPORT.DLL
### Problem Reports and Solutions Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%SystemRoot%\System32\wercplsupport.dll
[Svchost DLLs] :HKLM WerSvc=C:\WINDOWS\SYSTEM32\WERSVC.DLL
### Windows Error Reporting Service Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%SystemRoot%\System32\WerSvc.dll
[Svchost DLLs] :HKLM WFDSConMgrSvc=C:\WINDOWS\SYSTEM32\WFDSCONMGRSVC.DLL
### Wi-Fi Direct Services Connection Manager Service Microsoft Corporation
Microsoft� Windows� Operating System 10.0.17763.1 !$*%SystemRoot
%\System32\wfdsconmgrsvc.dll
[Svchost DLLs] :HKLM wisvc=C:\WINDOWS\SYSTEM32\FLIGHTSETTINGS.DLL
### Flight Settings Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*%systemroot%\system32\flightsettings.dll
[Svchost DLLs] :HKLM wlidsvc=C:\WINDOWS\SYSTEM32\WLIDSVC.DLL
### Microsoft� Account Service Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%SystemRoot%\system32\wlidsvc.dll
[Svchost DLLs] :HKLM wlpasvc=C:\WINDOWS\SYSTEM32\LPASVC.DLL
### Local Profile Assistant Service Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%SystemRoot%\System32\lpasvc.dll
[Svchost DLLs] :HKLM WManSvc=C:\WINDOWS\SYSTEM32\WINDOWS.MANAGEMENT.SERVICE.DLL
### Windows Management Service DLL Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%systemroot
%\system32\Windows.Management.Service.dll
[Svchost DLLs] :HKLM workfolderssvc=C:\WINDOWS\SYSTEM32\WORKFOLDERSSVC.DLL
### Microsoft (C) Work Folders Service Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%systemroot%\system32\workfolderssvc.dll
[Svchost DLLs] :HKLM WpcMonSvc=C:\WINDOWS\SYSTEM32\WPCDESKTOPMONSVC.DLL
### WpcMonSvc.dll Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*%SystemRoot%\System32\WpcDesktopMonSvc.dll
[Svchost DLLs] :HKLM WpnUserService=C:\WINDOWS\SYSTEM32\WPNUSERSERVICE.DLL
### Windows Push Notification User Service Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 !$*%SystemRoot%\System32\WpnUserService.dll
[Svchost DLLs] :HKLM WwanSvc=C:\WINDOWS\SYSTEM32\WWANSVC.DLL
### WWAN Auto Config Service Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*%SystemRoot%\System32\wwansvc.dll
[Svchost DLLs] :HKLM XblAuthManager=C:\WINDOWS\SYSTEM32\XBLAUTHMANAGER.DLL
### Xbox Live Auth Manager Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*%SystemRoot%\System32\XblAuthManager.dll
[Svchost DLLs] :HKLM XblGameSave=C:\WINDOWS\SYSTEM32\XBLGAMESAVE.DLL
### Xbox Live Game Save Service Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%SystemRoot%\System32\XblGameSave.dll
[Svchost DLLs] :HKLM XboxGipSvc=C:\WINDOWS\SYSTEM32\XBOXGIPSVC.DLL
### Xbox Gip Management Service Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%SystemRoot%\System32\XboxGipSvc.dll
[Svchost DLLs] :HKLM XboxNetApiSvc=C:\WINDOWS\SYSTEM32\XBOXNETAPISVC.DLL
### Xbox Live Networking Service Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%SystemRoot%\system32\XboxNetApiSvc.dll
[Bootexecute] :HKLM BootExecute=autocheck autochk *
Partizan
[Winlogon System] :HKLM system=""
### File is missing.
[Winlogon System] :HKLM taskman=""
### File is missing.
[Winlogon System] :HKLM UIHost=""
### File is missing.
[Winlogon Autostart] :HKLM VmApplet=""
[Winlogon Autostart] :HKLM AppSetup=""
[Environment - Path] :HKLM Path=%SystemRoot%\system32;%SystemRoot%;%SystemRoot
%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;%SYSTEMROOT
%\System32\OpenSSH\
[List of Injected DLLs] :HKLM AppInit_DLLs=""
[LSA Notification Packages] :HKLM scecli=C:\Windows\SYSTEM32\SCECLI.DLL
### scecli Windows Security Configuration Editor Client Engine Microsoft
Corporation Microsoft� Windows� Operating System 10.0.17763.1 !$*scecli.dll
[Drivers] :HKLM 1394ohci=C:\WINDOWS\SYSTEM32\DRIVERS\1394OHCI.SYS
### 1394 OpenHCI Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*\SystemRoot\System32\drivers\1394ohci.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM 3ware=C:\WINDOWS\SYSTEM32\DRIVERS\3WARE.SYS
### LSI 3ware SCSI Storport Driver LSI LSI 3ware RAID Controller WindowsBlue
Service registry key doesn't exist or hidden.
[Drivers] :HKLM ACPI=C:\WINDOWS\SYSTEM32\DRIVERS\ACPI.SYS
### ACPI Driver for NT Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM AcpiDev=C:\WINDOWS\SYSTEM32\DRIVERS\ACPIDEV.SYS
### ACPI Devices Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*\SystemRoot\System32\drivers\AcpiDev.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM acpiex=C:\WINDOWS\SYSTEM32\DRIVERS\ACPIEX.SYS
### ACPIEx Driver Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM acpipagr=C:\WINDOWS\SYSTEM32\DRIVERS\ACPIPAGR.SYS
### ACPI Processor Aggregator Device Driver Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 !$*\SystemRoot\System32\drivers\acpipagr.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM AcpiPmi=C:\WINDOWS\SYSTEM32\DRIVERS\ACPIPMI.SYS
### ACPI Power Metering Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*\SystemRoot\System32\drivers\acpipmi.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM acpitime=C:\WINDOWS\SYSTEM32\DRIVERS\ACPITIME.SYS
### ACPI Wake Alarm Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*\SystemRoot\System32\drivers\acpitime.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM ADP80XX=C:\WINDOWS\SYSTEM32\DRIVERS\ADP80XX.SYS
### PMC-Sierra Storport Driver For SPC8x6G SAS/SATA controller PMC-Sierra PMC-
Sierra HBA Controller 1.3.0.10769 Service registry key doesn't exist or hidden.
[Drivers] :HKLM AFD=C:\WINDOWS\SYSTEM32\DRIVERS\AFD.SYS
### Ancillary Function Driver for WinSock Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 !$*\SystemRoot\system32\drivers\afd.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM afunix=C:\WINDOWS\SYSTEM32\DRIVERS\AFUNIX.SYS
### AF_UNIX socket provider Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*\SystemRoot\system32\drivers\afunix.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM ahcache=C:\WINDOWS\SYSTEM32\DRIVERS\AHCACHE.SYS
### Application Compatibility Cache Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM AmdK8=C:\WINDOWS\SYSTEM32\DRIVERS\AMDK8.SYS
### Processor Device Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*\SystemRoot\System32\drivers\amdk8.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM AmdPPM=C:\WINDOWS\SYSTEM32\DRIVERS\AMDPPM.SYS
### Processor Device Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*\SystemRoot\System32\drivers\amdppm.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM amdsata=C:\WINDOWS\SYSTEM32\DRIVERS\AMDSATA.SYS
### AHCI 1.3 Device Driver Advanced Micro Devices AHCI 1.3 Device Driver
1.1.3.277 Service registry key doesn't exist or hidden.
[Drivers] :HKLM amdsbs=C:\WINDOWS\SYSTEM32\DRIVERS\AMDSBS.SYS
### AMD Technology AHCI Compatible Controller Driver for Windows - AMD64 platform
AMD Technologies Inc. AMD Technology AHCI Compatible Controller 3.7.1540.43
Service registry key doesn't exist or hidden.
[Drivers] :HKLM amdxata=C:\WINDOWS\SYSTEM32\DRIVERS\AMDXATA.SYS
### Storage Filter Driver Advanced Micro Devices Storage Filter Driver 1.1.3.277
Service registry key doesn't exist or hidden.
[Drivers] :HKLM AppID=C:\WINDOWS\SYSTEM32\DRIVERS\APPID.SYS
### AppID Driver Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM applockerfltr=C:\WINDOWS\SYSTEM32\DRIVERS\APPLOCKERFLTR.SYS
### Applocker Filter Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM AppvStrm=C:\WINDOWS\SYSTEM32\DRIVERS\APPVSTRM.SYS
### Microsoft Application Virtualization Streaming Driver Microsoft Corporation
Microsoft� Windows� Operating System 10.0.17763.1 !
$*\SystemRoot\system32\drivers\AppvStrm.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM AppvVemgr=C:\WINDOWS\SYSTEM32\DRIVERS\APPVVEMGR.SYS
### Microsoft Application Virtualization VE Manager Driver Microsoft Corporation
Microsoft� Windows� Operating System 10.0.17763.1 !
$*\SystemRoot\system32\drivers\AppvVemgr.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM AppvVfs=C:\WINDOWS\SYSTEM32\DRIVERS\APPVVFS.SYS
### Microsoft Application Virtualization VFS Filter Driver Microsoft Corporation
Microsoft� Windows� Operating System 10.0.17763.1 !
$*\SystemRoot\system32\drivers\AppvVfs.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM arcsas=C:\WINDOWS\SYSTEM32\DRIVERS\ARCSAS.SYS
### Adaptec SAS RAID WS03 Driver PMC-Sierra, Inc. Adaptec RAID Controller
7.5.0.32048 Service registry key doesn't exist or hidden.
[Drivers] :HKLM AsyncMac=C:\WINDOWS\SYSTEM32\DRIVERS\ASYNCMAC.SYS
### MS Remote Access serial network driver Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 !$*\SystemRoot\System32\drivers\asyncmac.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM atapi=C:\WINDOWS\SYSTEM32\DRIVERS\ATAPI.SYS
### ATAPI IDE Miniport Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM athr=C:\WINDOWS\SYSTEM32\DRIVERS\ATHW10X.SYS
### Qualcomm Atheros Extensible Wireless LAN device driver Qualcomm Atheros
Communications, Inc. Driver for Qualcomm Atheros CB42/CB43/MB42/MB43 Network
Adapter 10.0.0.318 !$*\SystemRoot\System32\drivers\athw10x.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM b06bdrv=C:\WINDOWS\SYSTEM32\DRIVERS\BXVBDA.SYS
### QLogic Gigabit Ethernet VBD QLogic Corporation QLogic Gigabit Ethernet
7.12.31.105 Service registry key doesn't exist or hidden.
[Drivers] :HKLM bam=C:\WINDOWS\SYSTEM32\DRIVERS\BAM.SYS
### BAM Kernel Driver Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM
BasicDisplay=C:\WINDOWS\SYSTEM32\DRIVERSTORE\FILEREPOSITORY\BASICDISPLAY.INF_AMD64_
5103AC179273BE89\BASICDISPLAY.SYS
### Microsoft Basic Display Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !
$*\SystemRoot\System32\DriverStore\FileRepository\basicdisplay.inf_amd64_5103ac1792
73be89\BasicDisplay.sys Service registry key doesn't exist or hidden.
[Drivers] :HKLM
BasicRender=C:\WINDOWS\SYSTEM32\DRIVERSTORE\FILEREPOSITORY\BASICRENDER.INF_AMD64_0B
8D03C3BC0E7FD9\BASICRENDER.SYS
### Microsoft Basic Render Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !
$*\SystemRoot\System32\DriverStore\FileRepository\basicrender.inf_amd64_0b8d03c3bc0
e7fd9\BasicRender.sys Service registry key doesn't exist or hidden.
[Drivers] :HKLM bcmfn2=C:\WINDOWS\SYSTEM32\DRIVERS\BCMFN2.SYS
### BCM Function 2 Device Driver Windows (R) Win 7 DDK provider Windows (R) Win
7 DDK driver 6.3.9600.17336 !$*\SystemRoot\System32\drivers\bcmfn2.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM bindflt=C:\WINDOWS\SYSTEM32\DRIVERS\BINDFLT.SYS
### Windows Bind Filter Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*\SystemRoot\system32\drivers\bindflt.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM bowser=C:\WINDOWS\SYSTEM32\DRIVERS\BOWSER.SYS
### NT Lan Manager Datagram Receiver Driver Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 Service registry key doesn't exist or
hidden.
[Drivers] :HKLM BtFilter=C:\WINDOWS\SYSTEM32\DRIVERS\BTFILTER.SYS
### Qualcomm Atheros BtFilter Driver Qualcomm Atheros Windows (R) Win 7 DDK
driver 10.0.1.1 !$*\SystemRoot\system32\DRIVERS\btfilter.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM BthEnum=C:\WINDOWS\SYSTEM32\DRIVERS\BTHENUM.SYS
### Bluetooth Bus Extender Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*\SystemRoot\System32\drivers\BthEnum.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM BthHFEnum=C:\WINDOWS\SYSTEM32\DRIVERS\BTHHFENUM.SYS
### Bluetooth Hands-Free Audio and Call Control HID Enumerator Microsoft
Corporation Microsoft� Windows� Operating System 10.0.17763.1 !
$*\SystemRoot\System32\drivers\bthhfenum.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM
BthLEEnum=C:\WINDOWS\SYSTEM32\DRIVERS\MICROSOFT.BLUETOOTH.LEGACY.LEENUMERATOR.SYS
### Legacy Bluetooth LE Bus Enumerator Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !
$*\SystemRoot\System32\drivers\Microsoft.Bluetooth.Legacy.LEEnumerator.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM BthMini=C:\WINDOWS\SYSTEM32\DRIVERS\BTHMINI.SYS
### Bluetooth Transport Extensibility Miniport Driver Microsoft Corporation
Microsoft� Windows� Operating System 10.0.17763.1 !
$*\SystemRoot\System32\drivers\BTHMINI.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM BTHMODEM=C:\WINDOWS\SYSTEM32\DRIVERS\BTHMODEM.SYS
### Bluetooth Communications Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*\SystemRoot\System32\drivers\bthmodem.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM BthPan=C:\WINDOWS\SYSTEM32\DRIVERS\BTHPAN.SYS
### Bluetooth Personal Area Networking Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*\SystemRoot\System32\drivers\bthpan.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM BTHPORT=C:\WINDOWS\SYSTEM32\DRIVERS\BTHPORT.SYS
### Bluetooth Bus Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*\SystemRoot\System32\drivers\BTHport.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM BTHUSB=C:\WINDOWS\SYSTEM32\DRIVERS\BTHUSB.SYS
### Bluetooth Miniport Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*\SystemRoot\System32\drivers\BTHUSB.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM bttflt=C:\WINDOWS\SYSTEM32\DRIVERS\BTTFLT.SYS
### VHD BTT Filter Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM buttonconverter=C:\WINDOWS\SYSTEM32\DRIVERS\BUTTONCONVERTER.SYS
### Button Converter Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*\SystemRoot\System32\drivers\buttonconverter.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM CAD=C:\WINDOWS\SYSTEM32\DRIVERS\CAD.SYS
### Charge Arbiration Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*\SystemRoot\System32\drivers\CAD.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM CapImg=C:\WINDOWS\SYSTEM32\DRIVERS\CAPIMG.SYS
### CapImg HID Driver Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*\SystemRoot\System32\drivers\capimg.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM cdfs=C:\WINDOWS\SYSTEM32\DRIVERS\CDFS.SYS
### CD-ROM File System Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM cdrom=C:\WINDOWS\SYSTEM32\DRIVERS\CDROM.SYS
### SCSI CD-ROM Driver Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*\SystemRoot\System32\drivers\cdrom.sys Service registry key doesn't
exist or hidden.
[Drivers] :HKLM cht4iscsi=C:\WINDOWS\SYSTEM32\DRIVERS\CHT4SX64.SYS
### Chelsio iSCSI VMiniport Driver Chelsio Communications Chelsio Communications
iSCSI Controller 10.0.10011.16384 Service registry key doesn't exist or hidden.
[Drivers] :HKLM cht4vbd=C:\WINDOWS\SYSTEM32\DRIVERS\CHT4VX64.SYS
### Virtual Bus Driver for Chelsio � T5/T6 Chipset Chelsio Communications Chelsio
Communications Unified Network I/O Controller 10.0.10011.16384 !
$*\SystemRoot\System32\drivers\cht4vx64.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM circlass=C:\WINDOWS\SYSTEM32\DRIVERS\CIRCLASS.SYS
### Consumer IR Class Driver for eHome Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*\SystemRoot\System32\drivers\circlass.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM CldFlt=C:\WINDOWS\SYSTEM32\DRIVERS\CLDFLT.SYS
### Cloud Files Mini Filter Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM CLFS=C:\WINDOWS\SYSTEM32\DRIVERS\CLFS.SYS
### Common Log File System Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM CmBatt=C:\WINDOWS\SYSTEM32\DRIVERS\CMBATT.SYS
### Control Method Battery Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*\SystemRoot\System32\drivers\CmBatt.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM CNG=C:\WINDOWS\SYSTEM32\DRIVERS\CNG.SYS
### Kernel Cryptography, Next Generation Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 Service registry key doesn't exist or
hidden.
[Drivers] :HKLM cnghwassist=C:\WINDOWS\SYSTEM32\DRIVERS\CNGHWASSIST.SYS
### CNG Hardware Assist algorithm provider Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 Service registry key doesn't exist or
hidden.
[Drivers] :HKLM
CompositeBus=C:\WINDOWS\SYSTEM32\DRIVERSTORE\FILEREPOSITORY\COMPOSITEBUS.INF_AMD64_
E4D35AF746093DC3\COMPOSITEBUS.SYS
### Multi-Transport Composite Bus Enumerator Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 !
$*\SystemRoot\System32\DriverStore\FileRepository\compositebus.inf_amd64_e4d35af746
093dc3\CompositeBus.sys Service registry key doesn't exist or hidden.
[Drivers] :HKLM condrv=C:\WINDOWS\SYSTEM32\DRIVERS\CONDRV.SYS
### Console Driver Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM CSC=C:\WINDOWS\SYSTEM32\DRIVERS\CSC.SYS
### Windows Client Side Caching Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM cxwmbclass=C:\WINDOWS\SYSTEM32\DRIVERS\CXWMBCLASS.SYS
### Windows Mobile Broadband Class Driver Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 !
$*\SystemRoot\System32\drivers\cxwmbclass.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM dam=C:\WINDOWS\SYSTEM32\DRIVERS\DAM.SYS
### DAM Kernel Driver Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM Dfsc=C:\WINDOWS\SYSTEM32\DRIVERS\DFSC.SYS
### DFS Namespace Client Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM Disk=C:\WINDOWS\SYSTEM32\DRIVERS\DISK.SYS
### PnP Disk Driver Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM dmvsc=C:\WINDOWS\SYSTEM32\DRIVERS\DMVSC.SYS
### Dynamic Memory Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*\SystemRoot\System32\drivers\dmvsc.sys Service registry key doesn't
exist or hidden.
[Drivers] :HKLM drmkaud=C:\WINDOWS\SYSTEM32\DRIVERS\DRMKAUD.SYS
### Microsoft Trusted Audio Drivers Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*\SystemRoot\System32\drivers\drmkaud.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM DXGKrnl=C:\WINDOWS\SYSTEM32\DRIVERS\DXGKRNL.SYS
### DirectX Graphics Kernel Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*\SystemRoot\System32\drivers\dxgkrnl.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM ebdrv=C:\WINDOWS\SYSTEM32\DRIVERS\EVBDA.SYS
### QLogic 10 GigE VBD QLogic Corporation QLogic 10 GigE 7.13.65.105 Service
registry key doesn't exist or hidden.
[Drivers] :HKLM EhStorClass=C:\WINDOWS\SYSTEM32\DRIVERS\EHSTORCLASS.SYS
### Enhanced Storage Class driver for IEEE 1667 devices Microsoft Corporation
Microsoft� Windows� Operating System 10.0.17763.1 Service registry key doesn't
exist or hidden.
[Drivers] :HKLM EhStorTcgDrv=C:\WINDOWS\SYSTEM32\DRIVERS\EHSTORTCGDRV.SYS
### Microsoft driver for storage devices supporting IEEE 1667 and TCG protocols
Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1 Service
registry key doesn't exist or hidden.
[Drivers] :HKLM ErrDev=C:\WINDOWS\SYSTEM32\DRIVERS\ERRDEV.SYS
### Error Device Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*\SystemRoot\System32\drivers\errdev.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM fdc=C:\WINDOWS\SYSTEM32\DRIVERS\FDC.SYS
### Floppy Disk Controller Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*\SystemRoot\System32\drivers\fdc.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM FileCrypt=C:\WINDOWS\SYSTEM32\DRIVERS\FILECRYPT.SYS
### Windows sandboxing and encryption filter Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 Service registry key doesn't exist or
hidden.
[Drivers] :HKLM FileInfo=C:\WINDOWS\SYSTEM32\DRIVERS\FILEINFO.SYS
### FileInfo Filter Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM Filetrace=C:\WINDOWS\SYSTEM32\DRIVERS\FILETRACE.SYS
### File Trace Filter Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM flpydisk=C:\WINDOWS\SYSTEM32\DRIVERS\FLPYDISK.SYS
### Floppy Driver Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*\SystemRoot\System32\drivers\flpydisk.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM FltMgr=C:\WINDOWS\SYSTEM32\DRIVERS\FLTMGR.SYS
### Microsoft Filesystem Filter Manager Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM FsDepends=C:\WINDOWS\SYSTEM32\DRIVERS\FSDEPENDS.SYS
### File System Dependency Manager Mini Filter Driver Microsoft Corporation
Microsoft� Windows� Operating System 10.0.17763.1 Service registry key doesn't
exist or hidden.
[Drivers] :HKLM fvevol=C:\WINDOWS\SYSTEM32\DRIVERS\FVEVOL.SYS
### BitLocker Drive Encryption Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM gencounter=C:\WINDOWS\SYSTEM32\DRIVERS\VMGENCOUNTER.SYS
### Virtual Machine Generation Counter Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*\SystemRoot\System32\drivers\vmgencounter.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM genericusbfn=C:\WINDOWS\SYSTEM32\DRIVERS\GENERICUSBFN.SYS
### Generic USB Function Class Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*\SystemRoot\System32\drivers\genericusbfn.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM GPIOClx0101=C:\WINDOWS\SYSTEM32\DRIVERS\MSGPIOCLX.SYS
### GPIO Class Extension Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM GpuEnergyDrv=C:\WINDOWS\SYSTEM32\DRIVERS\GPUENERGYDRV.SYS
### GPU Energy Kernel Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM HdAudAddService=C:\WINDOWS\SYSTEM32\DRIVERS\HDAUDIO.SYS
### High Definition Audio Function Driver Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 !$*\SystemRoot\system32\DRIVERS\HdAudio.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM HDAudBus=C:\WINDOWS\SYSTEM32\DRIVERS\HDAUDBUS.SYS
### High Definition Audio Bus Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*\SystemRoot\System32\drivers\HDAudBus.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM HidBatt=C:\WINDOWS\SYSTEM32\DRIVERS\HIDBATT.SYS
### Hid Battery Driver Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*\SystemRoot\System32\drivers\HidBatt.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM HidBth=C:\WINDOWS\SYSTEM32\DRIVERS\HIDBTH.SYS
### Bluetooth Miniport Driver for HID Devices Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 !$*\SystemRoot\System32\drivers\hidbth.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM hidi2c=C:\WINDOWS\SYSTEM32\DRIVERS\HIDI2C.SYS
### I2C HID Miniport Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*\SystemRoot\System32\drivers\hidi2c.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM hidinterrupt=C:\WINDOWS\SYSTEM32\DRIVERS\HIDINTERRUPT.SYS
### HID Button over Interrupt Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*\SystemRoot\System32\drivers\hidinterrupt.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM HidIr=C:\WINDOWS\SYSTEM32\DRIVERS\HIDIR.SYS
### Infrared Miniport Driver for Input Devices Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 !$*\SystemRoot\System32\drivers\hidir.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM hidspi=C:\WINDOWS\SYSTEM32\DRIVERS\HIDSPI.SYS
### SPI HID Miniport Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*\SystemRoot\System32\drivers\hidspi.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM HidUsb=C:\WINDOWS\SYSTEM32\DRIVERS\HIDUSB.SYS
### USB Miniport Driver for Input Devices Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 !$*\SystemRoot\System32\drivers\hidusb.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM HpSAMD=C:\WINDOWS\SYSTEM32\DRIVERS\HPSAMD.SYS
### Smart Array SAS/SATA Controller Media Driver Hewlett-Packard Company Smart
Array SAS/SATA Controller Media Driver 8.0.4.0 Build 1 Media Driver (x86-64)
Service registry key doesn't exist or hidden.
[Drivers] :HKLM HTTP=C:\WINDOWS\SYSTEM32\DRIVERS\HTTP.SYS
### HTTP Protocol Stack Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM hvcrash=C:\WINDOWS\SYSTEM32\DRIVERS\HVCRASH.SYS
### Hyper-V Crashdump Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*\SystemRoot\System32\drivers\hvcrash.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM hvservice=C:\WINDOWS\SYSTEM32\DRIVERS\HVSERVICE.SYS
### Hypervisor Boot Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM HwNClx0101=C:\WINDOWS\SYSTEM32\DRIVERS\MSHWNCLX.SYS
### Hardware Notification Class Extension Driver Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 Service registry key doesn't exist or
hidden.
[Drivers] :HKLM hwpolicy=C:\WINDOWS\SYSTEM32\DRIVERS\HWPOLICY.SYS
### Hardware Policy Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM hyperkbd=C:\WINDOWS\SYSTEM32\DRIVERS\HYPERKBD.SYS
### Microsoft VMBus Synthetic Keyboard Driver Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 !$*\SystemRoot\System32\drivers\hyperkbd.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM HyperVideo=C:\WINDOWS\SYSTEM32\DRIVERS\HYPERVIDEO.SYS
### Microsoft VMBus Video Device Miniport Driver Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 !
$*\SystemRoot\System32\drivers\HyperVideo.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM i8042prt=C:\WINDOWS\SYSTEM32\DRIVERS\I8042PRT.SYS
### i8042 Port Driver Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*\SystemRoot\System32\drivers\i8042prt.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM iagpio=C:\WINDOWS\SYSTEM32\DRIVERS\IAGPIO.SYS
### Intel(R) Serial IO GPIO Controller Driver Intel(R) Corporation Intel(R)
Serial IO GPIO Controller Driver 1.1.1.0 !$*\SystemRoot\System32\drivers\iagpio.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM iai2c=C:\WINDOWS\SYSTEM32\DRIVERS\IAI2C.SYS
### Intel(R) Serial IO I2C Driver Intel(R) Corporation Intel(R) Serial IO I2C
Driver 1.1.1.0 !$*\SystemRoot\System32\drivers\iai2c.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM iaLPSS2i_GPIO2=C:\WINDOWS\SYSTEM32\DRIVERS\IALPSS2I_GPIO2.SYS
### Intel(R) Serial IO GPIO Driver v2 Intel Corporation Intel(R) Serial IO Driver
30.100.1816.3 !$*\SystemRoot\System32\drivers\iaLPSS2i_GPIO2.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM
iaLPSS2i_GPIO2_BXT_P=C:\WINDOWS\SYSTEM32\DRIVERS\IALPSS2I_GPIO2_BXT_P.SYS
### Intel(R) Serial IO GPIO Driver v2 Intel Corporation Intel(R) Serial IO Driver
30.100.1816.1 !$*\SystemRoot\System32\drivers\iaLPSS2i_GPIO2_BXT_P.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM
iaLPSS2i_GPIO2_CNL=C:\WINDOWS\SYSTEM32\DRIVERS\IALPSS2I_GPIO2_CNL.SYS
### Intel(R) Serial IO GPIO Driver v2 Intel Corporation Intel(R) Serial IO Driver
30.100.1816.3 !$*\SystemRoot\System32\drivers\iaLPSS2i_GPIO2_CNL.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM
iaLPSS2i_GPIO2_GLK=C:\WINDOWS\SYSTEM32\DRIVERS\IALPSS2I_GPIO2_GLK.SYS
### Intel(R) Serial IO GPIO Driver v2 Intel Corporation Intel(R) Serial IO Driver
30.100.1820.1 !$*\SystemRoot\System32\drivers\iaLPSS2i_GPIO2_GLK.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM iaLPSS2i_I2C=C:\WINDOWS\SYSTEM32\DRIVERS\IALPSS2I_I2C.SYS
### Intel(R) Serial IO I2C Driver v2 Intel Corporation Intel(R) Serial IO Driver
30.100.1816.3 !$*\SystemRoot\System32\drivers\iaLPSS2i_I2C.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM
iaLPSS2i_I2C_BXT_P=C:\WINDOWS\SYSTEM32\DRIVERS\IALPSS2I_I2C_BXT_P.SYS
### Intel(R) Serial IO I2C Driver v2 Intel Corporation Intel(R) Serial IO Driver
30.100.1816.1 !$*\SystemRoot\System32\drivers\iaLPSS2i_I2C_BXT_P.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM iaLPSS2i_I2C_CNL=C:\WINDOWS\SYSTEM32\DRIVERS\IALPSS2I_I2C_CNL.SYS
### Intel(R) Serial IO I2C Driver v2 Intel Corporation Intel(R) Serial IO Driver
30.100.1816.3 !$*\SystemRoot\System32\drivers\iaLPSS2i_I2C_CNL.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM iaLPSS2i_I2C_GLK=C:\WINDOWS\SYSTEM32\DRIVERS\IALPSS2I_I2C_GLK.SYS
### Intel(R) Serial IO I2C Driver v2 Intel Corporation Intel(R) Serial IO Driver
30.100.1820.1 !$*\SystemRoot\System32\drivers\iaLPSS2i_I2C_GLK.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM iaLPSSi_GPIO=C:\WINDOWS\SYSTEM32\DRIVERS\IALPSSI_GPIO.SYS
### Intel(R) Serial IO GPIO Controller Driver Intel Corporation Intel(R) Serial
IO Driver 1.1.250.0 !$*\SystemRoot\System32\drivers\iaLPSSi_GPIO.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM iaLPSSi_I2C=C:\WINDOWS\SYSTEM32\DRIVERS\IALPSSI_I2C.SYS
### Intel(R) Serial IO I2C Controller Driver Intel Corporation Intel(R) Serial IO
Driver 1.1.253.0 !$*\SystemRoot\System32\drivers\iaLPSSi_I2C.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM iaStorAVC=C:\WINDOWS\SYSTEM32\DRIVERS\IASTORAVC.SYS
### Intel(R) Rapid Storage Technology driver (inbox) - x64 Intel Corporation
Intel(R) Rapid Storage Technology driver (inbox) 15.44.0.1010 Service registry key
doesn't exist or hidden.
[Drivers] :HKLM iaStorV=C:\WINDOWS\SYSTEM32\DRIVERS\IASTORV.SYS
### Intel Matrix Storage Manager driver - x64 Intel Corporation Intel Matrix
Storage Manager driver 8.6.2.1019 Service registry key doesn't exist or hidden.
[Drivers] :HKLM ibbus=C:\WINDOWS\SYSTEM32\DRIVERS\IBBUS.SYS
### InfiniBand Fabric Bus Driver Mellanox OpenFabrics Windows 10.0.10011.16384 !
$*\SystemRoot\System32\drivers\ibbus.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM IDMWFP=C:\WINDOWS\SYSTEM32\DRIVERS\IDMWFP.SYS
### Internet Download Manager WFP Driver Tonec Inc. Internet Download Manager
6.30.7.1 !$*\SystemRoot\system32\DRIVERS\idmwfp.sys Service registry key doesn't
exist or hidden.
[Drivers] :HKLM igfx=C:\WINDOWS\SYSTEM32\DRIVERS\IGDKMD64.SYS
### Intel Graphics Kernel Mode Driver Intel Corporation Intel HD Graphics Drivers
for Windows 8(R) 10.18.10.4252 !$*\SystemRoot\system32\DRIVERS\igdkmd64.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM IndirectKmd=C:\WINDOWS\SYSTEM32\DRIVERS\INDIRECTKMD.SYS
### Indirect displays kernel-mode filter driver Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 !
$*\SystemRoot\System32\drivers\IndirectKmd.sys Service registry key doesn't exist
or hidden.
[Drivers] :HKLM intaud_WaveExtensible=C:\WINDOWS\SYSTEM32\DRIVERS\INTELAUD.SYS
### Intel� WiDi Solution Intel Corporation Intel� WiDi Solution 4.5.61.0 !
$*\SystemRoot\system32\drivers\intelaud.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM IntcAzAudAddService=C:\WINDOWS\SYSTEM32\DRIVERS\RTKVHD64.SYS
### Realtek(r) High Definition Audio Function Driver Realtek Semiconductor Corp.
Realtek(r) High Definition Audio Function Driver 6.0.1.7544 !
$*\SystemRoot\system32\drivers\RTKVHD64.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM intelide=C:\WINDOWS\SYSTEM32\DRIVERS\INTELIDE.SYS
### Intel PCI IDE Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM intelpep=C:\WINDOWS\SYSTEM32\DRIVERS\INTELPEP.SYS
### Intel Power Engine Plugin Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM intelppm=C:\WINDOWS\SYSTEM32\DRIVERS\INTELPPM.SYS
### Processor Device Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*\SystemRoot\System32\drivers\intelppm.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM iorate=C:\WINDOWS\SYSTEM32\DRIVERS\IORATE.SYS
### I/O rate control Filter Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM IpFilterDriver=C:\WINDOWS\SYSTEM32\DRIVERS\IPFLTDRV.SYS
### IP FILTER DRIVER Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM IPMIDRV=C:\WINDOWS\SYSTEM32\DRIVERS\IPMIDRV.SYS
### WMI IPMI DRIVER Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*\SystemRoot\System32\drivers\IPMIDrv.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM IPNAT=C:\WINDOWS\SYSTEM32\DRIVERS\IPNAT.SYS
### IP Network Address Translator Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM IPT=C:\WINDOWS\SYSTEM32\DRIVERS\IPT.SYS
### IPT Driver Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*\SystemRoot\System32\drivers\ipt.sys Service registry key doesn't
exist or hidden.
[Drivers] :HKLM irda=C:\WINDOWS\SYSTEM32\DRIVERS\IRDA.SYS
### IRDA Protocol Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*\SystemRoot\system32\drivers\irda.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM IRENUM=C:\WINDOWS\SYSTEM32\DRIVERS\IRENUM.SYS
### Infra-Red Bus Enumerator Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM isapnp=C:\WINDOWS\SYSTEM32\DRIVERS\ISAPNP.SYS
### PNP ISA Bus Driver Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM iScsiPrt=C:\WINDOWS\SYSTEM32\DRIVERS\MSISCSI.SYS
### Microsoft iSCSI Initiator Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*\SystemRoot\System32\drivers\msiscsi.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM ItSas35i=C:\WINDOWS\SYSTEM32\DRIVERS\ITSAS35I.SYS
### Avago SAS Gen3.5 Driver (StorPort) Avago Technologies Windows (R) Win 7 DDK
driver 10.0.10011.16384 Service registry key doesn't exist or hidden.
[Drivers] :HKLM iwdbus=C:\WINDOWS\SYSTEM32\DRIVERS\IWDBUS.SYS
### Intel� WiDi Solution Intel Corporation Intel� WiDi Solution 4.5.61.0 !
$*\SystemRoot\System32\drivers\iwdbus.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM kbdclass=C:\WINDOWS\SYSTEM32\DRIVERS\KBDCLASS.SYS
### Keyboard Class Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*\SystemRoot\System32\drivers\kbdclass.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM kbdhid=C:\WINDOWS\SYSTEM32\DRIVERS\KBDHID.SYS
### HID Keyboard Filter Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*\SystemRoot\System32\drivers\kbdhid.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM kdnic=C:\WINDOWS\SYSTEM32\DRIVERS\KDNIC.SYS
### Microsoft Kernel Debugger Network Miniport Microsoft Corporation Microsoft
Kernel Debugger Network Adapter (NDIS 6.20 Miniport) 6.01.00.0000 !
$*\SystemRoot\System32\drivers\kdnic.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM KSecDD=C:\WINDOWS\SYSTEM32\DRIVERS\KSECDD.SYS
### Kernel Security Support Provider Interface Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 Service registry key doesn't exist or
hidden.
[Drivers] :HKLM KSecPkg=C:\WINDOWS\SYSTEM32\DRIVERS\KSECPKG.SYS
### Kernel Security Support Provider Interface Packages Microsoft Corporation
Microsoft� Windows� Operating System 10.0.17763.1 Service registry key doesn't
exist or hidden.
[Drivers] :HKLM ksthunk=C:\WINDOWS\SYSTEM32\DRIVERS\KSTHUNK.SYS
### Kernel Streaming WOW Thunk Service Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*\SystemRoot\system32\drivers\ksthunk.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM lltdio=C:\WINDOWS\SYSTEM32\DRIVERS\LLTDIO.SYS
### Link-Layer Topology Mapper I/O Driver Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 Service registry key doesn't exist or
hidden.
[Drivers] :HKLM LSI_SAS=C:\WINDOWS\SYSTEM32\DRIVERS\LSI_SAS.SYS
### LSI Fusion-MPT SAS Driver (StorPort) LSI Corporation LSI Fusion-MPT SAS
Driver (StorPort) 1.34.03.83 Service registry key doesn't exist or hidden.
[Drivers] :HKLM LSI_SAS2i=C:\WINDOWS\SYSTEM32\DRIVERS\LSI_SAS2I.SYS
### LSI SAS Gen2 Driver (StorPort) LSI Corporation Windows (R) Win 7 DDK driver
10.0.10011.16384 Service registry key doesn't exist or hidden.
[Drivers] :HKLM LSI_SAS3i=C:\WINDOWS\SYSTEM32\DRIVERS\LSI_SAS3I.SYS
### Avago SAS Gen3 Driver (StorPort) Avago Technologies Windows (R) Win 7 DDK
driver 10.0.10011.16384 Service registry key doesn't exist or hidden.
[Drivers] :HKLM LSI_SSS=C:\WINDOWS\SYSTEM32\DRIVERS\LSI_SSS.SYS
### LSI SSS PCIe/Flash Driver (StorPort) LSI Corporation LSI SSS PCIe/Flash
Driver (StorPort) 2.10.61.81 Service registry key doesn't exist or hidden.
[Drivers] :HKLM luafv=C:\WINDOWS\SYSTEM32\DRIVERS\LUAFV.SYS
### LUA File Virtualization Filter Driver Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 !$*\SystemRoot\system32\drivers\luafv.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM mausbhost=C:\WINDOWS\SYSTEM32\DRIVERS\MAUSBHOST.SYS
### MA-USB Host Controller Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*\SystemRoot\System32\drivers\mausbhost.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM mausbip=C:\WINDOWS\SYSTEM32\DRIVERS\MAUSBIP.SYS
### MA-USB IP Driver Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*\SystemRoot\System32\drivers\mausbip.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM MbbCx=C:\WINDOWS\SYSTEM32\DRIVERS\MBBCX.SYS
### Windows Mobile Broadband Class Extension Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 Service registry key doesn't exist or
hidden.
[Drivers] :HKLM megasas=C:\WINDOWS\SYSTEM32\DRIVERS\MEGASAS.SYS
### MEGASAS RAID Controller Driver for Windows Avago Technologies MEGASAS RAID
Controller Driver for Windows 6.706.06.00 Service registry key doesn't exist or
hidden.
[Drivers] :HKLM megasas2i=C:\WINDOWS\SYSTEM32\DRIVERS\MEGASAS2I.SYS
### MEGASAS RAID Controller Driver for Windows Avago Technologies MEGASAS RAID
Controller Driver for Windows 6.714.05.00 Service registry key doesn't exist or
hidden.
[Drivers] :HKLM megasas35i=C:\WINDOWS\SYSTEM32\DRIVERS\MEGASAS35I.SYS
### MEGASAS RAID Controller Driver for Windows Avago Technologies MEGASAS RAID
Controller Driver for Windows 7.705.08.00 Service registry key doesn't exist or
hidden.
[Drivers] :HKLM megasr=C:\WINDOWS\SYSTEM32\DRIVERS\MEGASR.SYS
### LSI MegaRAID Software RAID Driver LSI Corporation, Inc. MegaRAID Software
RAID 15.02.2013.0129 Service registry key doesn't exist or hidden.
[Drivers] :HKLM
Microsoft_Bluetooth_AvrcpTransport=C:\WINDOWS\SYSTEM32\DRIVERS\MICROSOFT.BLUETOOTH.
AVRCPTRANSPORT.SYS
### Microsoft Bluetooth Avrcp Transport Driver Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 !
$*\SystemRoot\System32\drivers\Microsoft.Bluetooth.AvrcpTransport.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM mlx4_bus=C:\WINDOWS\SYSTEM32\DRIVERS\MLX4_BUS.SYS
### MLX4 Bus Driver Mellanox OpenFabrics Windows 10.0.10011.16384 !
$*\SystemRoot\System32\drivers\mlx4_bus.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM MMCSS=C:\WINDOWS\SYSTEM32\DRIVERS\MMCSS.SYS
### MMCSS Driver Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*\SystemRoot\system32\drivers\mmcss.sys Service registry key doesn't
exist or hidden.
[Drivers] :HKLM Modem=C:\WINDOWS\SYSTEM32\DRIVERS\MODEM.SYS
### Modem Device Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM monitor=C:\WINDOWS\SYSTEM32\DRIVERS\MONITOR.SYS
### Monitor Driver Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*\SystemRoot\System32\drivers\monitor.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM mouclass=C:\WINDOWS\SYSTEM32\DRIVERS\MOUCLASS.SYS
### Mouse Class Driver Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*\SystemRoot\System32\drivers\mouclass.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM mouhid=C:\WINDOWS\SYSTEM32\DRIVERS\MOUHID.SYS
### HID Mouse Filter Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*\SystemRoot\System32\drivers\mouhid.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM mountmgr=C:\WINDOWS\SYSTEM32\DRIVERS\MOUNTMGR.SYS
### Mount Point Manager Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM mpsdrv=C:\WINDOWS\SYSTEM32\DRIVERS\MPSDRV.SYS
### Microsoft Protection Service Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM MRxDAV=C:\WINDOWS\SYSTEM32\DRIVERS\MRXDAV.SYS
### Windows NT WebDav Minirdr Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*\SystemRoot\system32\drivers\mrxdav.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM mrxsmb=C:\WINDOWS\SYSTEM32\DRIVERS\MRXSMB.SYS
### Windows NT SMB Minirdr Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM mrxsmb20=C:\WINDOWS\SYSTEM32\DRIVERS\MRXSMB20.SYS
### Longhorn SMB 2.0 Redirector Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM MsBridge=C:\WINDOWS\SYSTEM32\DRIVERS\BRIDGE.SYS
### MAC Bridge Driver Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM msgpiowin32=C:\WINDOWS\SYSTEM32\DRIVERS\MSGPIOWIN32.SYS
### GPIO Button Driver Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*\SystemRoot\System32\drivers\msgpiowin32.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM mshidkmdf=C:\WINDOWS\SYSTEM32\DRIVERS\MSHIDKMDF.SYS
### Pass-through HID to KMDF Filter Driver Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 !
$*\SystemRoot\System32\drivers\mshidkmdf.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM mshidumdf=C:\WINDOWS\SYSTEM32\DRIVERS\MSHIDUMDF.SYS
### Pass-through Driver for HID-UMDF Interface Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 !
$*\SystemRoot\System32\drivers\mshidumdf.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM msisadrv=C:\WINDOWS\SYSTEM32\DRIVERS\MSISADRV.SYS
### ISA Driver Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM MSKSSRV=C:\WINDOWS\SYSTEM32\DRIVERS\MSKSSRV.SYS
### MS KS Server Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*\SystemRoot\System32\drivers\MSKSSRV.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM MsLldp=C:\WINDOWS\SYSTEM32\DRIVERS\MSLLDP.SYS
### Microsoft Link-Layer Discovery Protocol Driver Microsoft Corporation
Microsoft� Windows� Operating System 10.0.17763.1 Service registry key doesn't
exist or hidden.
[Drivers] :HKLM MSPCLOCK=C:\WINDOWS\SYSTEM32\DRIVERS\MSPCLOCK.SYS
### MS Proxy Clock Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*\SystemRoot\System32\drivers\MSPCLOCK.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM MSPQM=C:\WINDOWS\SYSTEM32\DRIVERS\MSPQM.SYS
### MS Proxy Quality Manager Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*\SystemRoot\System32\drivers\MSPQM.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM MsSecFlt=C:\WINDOWS\SYSTEM32\DRIVERS\MSSECFLT.SYS
### Microsoft Security Events Component file system filter driver Microsoft
Corporation Microsoft� Windows� Operating System 10.0.17763.1 Service registry key
doesn't exist or hidden.
[Drivers] :HKLM mssmbios=C:\WINDOWS\SYSTEM32\DRIVERS\MSSMBIOS.SYS
### System Management BIOS Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*\SystemRoot\System32\drivers\mssmbios.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM MSTEE=C:\WINDOWS\SYSTEM32\DRIVERS\MSTEE.SYS
### WDM Tee/Communication Transform Filter Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 !$*\SystemRoot\System32\drivers\MSTEE.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM MTConfig=C:\WINDOWS\SYSTEM32\DRIVERS\MTCONFIG.SYS
### Microsoft Multi-Touch HID Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*\SystemRoot\System32\drivers\MTConfig.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM Mup=C:\WINDOWS\SYSTEM32\DRIVERS\MUP.SYS
### Multiple UNC Provider Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM mvumis=C:\WINDOWS\SYSTEM32\DRIVERS\MVUMIS.SYS
### Marvell Flash Controller Driver Marvell Semiconductor, Inc. Marvell Flash
Controller 1.0.5.1016 Service registry key doesn't exist or hidden.
[Drivers] :HKLM NativeWifiP=C:\WINDOWS\SYSTEM32\DRIVERS\NWIFI.SYS
### NativeWiFi Miniport Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM ndfltr=C:\WINDOWS\SYSTEM32\DRIVERS\NDFLTR.SYS
### NetworkDirect Support Filter Driver Mellanox OpenFabrics Windows
10.0.10011.16384 !$*\SystemRoot\System32\drivers\ndfltr.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM NDIS=C:\WINDOWS\SYSTEM32\DRIVERS\NDIS.SYS
### Network Driver Interface Specification (NDIS) Microsoft Corporation
Microsoft� Windows� Operating System 10.0.17763.1 Service registry key doesn't
exist or hidden.
[Drivers] :HKLM NdisCap=C:\WINDOWS\SYSTEM32\DRIVERS\NDISCAP.SYS
### Microsoft NDIS Packet Capture Filter Driver Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 Service registry key doesn't exist or
hidden.
[Drivers] :HKLM NdisImPlatform=C:\WINDOWS\SYSTEM32\DRIVERS\NDISIMPLATFORM.SYS
### Microsoft Network Adapter Multiplexor Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 Service registry key doesn't exist or
hidden.
[Drivers] :HKLM NdisTapi=C:\WINDOWS\SYSTEM32\DRIVERS\NDISTAPI.SYS
### NDIS 3.0 connection wrapper driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM Ndisuio=C:\WINDOWS\SYSTEM32\DRIVERS\NDISUIO.SYS
### NDIS User mode I/O driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM NdisVirtualBus=C:\WINDOWS\SYSTEM32\DRIVERS\NDISVIRTUALBUS.SYS
### Microsoft Virtual Network Adapter Enumerator Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 !
$*\SystemRoot\System32\drivers\NdisVirtualBus.sys Service registry key doesn't
exist or hidden.
[Drivers] :HKLM NdisWan=C:\WINDOWS\SYSTEM32\DRIVERS\NDISWAN.SYS
### MS PPP Framing Driver (Strong Encryption) Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 !$*\SystemRoot\System32\drivers\ndiswan.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM ndiswanlegacy=C:\WINDOWS\SYSTEM32\DRIVERS\NDISWAN.SYS
### MS PPP Framing Driver (Strong Encryption) Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 Service registry key doesn't exist or
hidden.
[Drivers] :HKLM ndproxy=C:\WINDOWS\SYSTEM32\DRIVERS\NDPROXY.SYS
### NDIS Proxy Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM Ndu=C:\WINDOWS\SYSTEM32\DRIVERS\NDU.SYS
### Windows Network Data Usage Monitoring Driver Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 Service registry key doesn't exist or
hidden.
[Drivers] :HKLM NetAdapterCx=C:\WINDOWS\SYSTEM32\DRIVERS\NETADAPTERCX.SYS
### Network Adapter Class Extension for WDF Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 Service registry key doesn't exist or
hidden.
[Drivers] :HKLM NetBIOS=C:\WINDOWS\SYSTEM32\DRIVERS\NETBIOS.SYS
### NetBIOS interface driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM NetBT=C:\WINDOWS\SYSTEM32\DRIVERS\NETBT.SYS
### MBT Transport driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM netvsc=C:\WINDOWS\SYSTEM32\DRIVERS\NETVSC.SYS
### Virtual NDIS Miniport Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*\SystemRoot\System32\drivers\netvsc.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM npsvctrig=C:\WINDOWS\SYSTEM32\DRIVERS\NPSVCTRIG.SYS
### Named pipe service triggers Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*\SystemRoot\System32\drivers\npsvctrig.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM nsiproxy=C:\WINDOWS\SYSTEM32\DRIVERS\NSIPROXY.SYS
### NSI Proxy Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM nvdimm=C:\WINDOWS\SYSTEM32\DRIVERS\NVDIMM.SYS
### NVDIMM device driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*\SystemRoot\System32\drivers\nvdimm.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM nvraid=C:\WINDOWS\SYSTEM32\DRIVERS\NVRAID.SYS
### NVIDIA� nForce(TM) RAID Driver NVIDIA Corporation NVIDIA nForce(TM) RAID
Driver 10.6.0.23 Service registry key doesn't exist or hidden.
[Drivers] :HKLM nvstor=C:\WINDOWS\SYSTEM32\DRIVERS\NVSTOR.SYS
### NVIDIA� nForce(TM) Sata Performance Driver NVIDIA Corporation NVIDIA
nForce(TM) SATA Driver 10.6.0.23 Service registry key doesn't exist or hidden.
[Drivers] :HKLM Parport=C:\WINDOWS\SYSTEM32\DRIVERS\PARPORT.SYS
### Parallel Port Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*\SystemRoot\System32\drivers\parport.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM Partizan=C:\Windows\system32\drivers\Partizan.sys
### File is missing. Service registry key doesn't exist or hidden.
[Drivers] :HKLM partmgr=C:\WINDOWS\SYSTEM32\DRIVERS\PARTMGR.SYS
### Partition driver Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM pci=C:\WINDOWS\SYSTEM32\DRIVERS\PCI.SYS
### NT Plug and Play PCI Enumerator Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM pciide=C:\WINDOWS\SYSTEM32\DRIVERS\PCIIDE.SYS
### Generic PCI IDE Bus Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM pcmcia=C:\WINDOWS\SYSTEM32\DRIVERS\PCMCIA.SYS
### PCMCIA Bus Driver Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM pcw=C:\WINDOWS\SYSTEM32\DRIVERS\PCW.SYS
### Performance Counters for Windows Driver Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 Service registry key doesn't exist or
hidden.
[Drivers] :HKLM pdc=C:\WINDOWS\SYSTEM32\DRIVERS\PDC.SYS
### Power Dependency Coordinator Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM PEAUTH=C:\WINDOWS\SYSTEM32\DRIVERS\PEAUTH.SYS
### Protected Environment Authentication and Authorization Export Driver
Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1 Service
registry key doesn't exist or hidden.
[Drivers] :HKLM percsas2i=C:\WINDOWS\SYSTEM32\DRIVERS\PERCSAS2I.SYS
### MEGASAS RAID Controller Driver for Windows Avago Technologies MEGASAS RAID
Controller Driver for Windows 6.805.03.00 Service registry key doesn't exist or
hidden.
[Drivers] :HKLM percsas3i=C:\WINDOWS\SYSTEM32\DRIVERS\PERCSAS3I.SYS
### MEGASAS RAID Controller Driver for Windows Avago Technologies MEGASAS RAID
Controller Driver for Windows 6.604.06.00 Service registry key doesn't exist or
hidden.
[Drivers] :HKLM PktMon=C:\WINDOWS\SYSTEM32\DRIVERS\PKTMON.SYS
### Packet Monitor Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM pmem=C:\WINDOWS\SYSTEM32\DRIVERS\PMEM.SYS
### Persistent memory driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*\SystemRoot\System32\drivers\pmem.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM PNPMEM=C:\WINDOWS\SYSTEM32\DRIVERS\PNPMEM.SYS
### Plug and Play Memory Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*\SystemRoot\System32\drivers\pnpmem.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM PptpMiniport=C:\WINDOWS\SYSTEM32\DRIVERS\RASPPTP.SYS
### Peer-to-Peer Tunneling Protocol Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*\SystemRoot\System32\drivers\raspptp.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM Processor=C:\WINDOWS\SYSTEM32\DRIVERS\PROCESSR.SYS
### Processor Device Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*\SystemRoot\System32\drivers\processr.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM Psched=C:\WINDOWS\SYSTEM32\DRIVERS\PACER.SYS
### QoS Packet Scheduler Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM QWAVEdrv=C:\WINDOWS\SYSTEM32\DRIVERS\QWAVEDRV.SYS
### Microsoft Quality Windows Audio Video Experience (qWave) Support Driver
Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1 !
$*\SystemRoot\system32\drivers\qwavedrv.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM Ramdisk=C:\WINDOWS\SYSTEM32\DRIVERS\RAMDISK.SYS
### RAM Disk Driver Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM RasAcd=C:\WINDOWS\SYSTEM32\DRIVERS\RASACD.SYS
### RAS Automatic Connection Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM RasAgileVpn=C:\WINDOWS\SYSTEM32\DRIVERS\AGILEVPN.SYS
### RAS Agile Vpn Miniport Call Manager Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*\SystemRoot\System32\drivers\AgileVpn.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM Rasl2tp=C:\WINDOWS\SYSTEM32\DRIVERS\RASL2TP.SYS
### RAS L2TP mini-port/call-manager driver Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 !$*\SystemRoot\System32\drivers\rasl2tp.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM RasPppoe=C:\WINDOWS\SYSTEM32\DRIVERS\RASPPPOE.SYS
### RAS PPPoE mini-port/call-manager driver Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 Service registry key doesn't exist or
hidden.
[Drivers] :HKLM RasSstp=C:\WINDOWS\SYSTEM32\DRIVERS\RASSSTP.SYS
### RAS SSTP Miniport Call Manager Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*\SystemRoot\System32\drivers\rassstp.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM rdbss=C:\WINDOWS\SYSTEM32\DRIVERS\RDBSS.SYS
### Redirected Drive Buffering SubSystem Driver Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 Service registry key doesn't exist or
hidden.
[Drivers] :HKLM rdpbus=C:\WINDOWS\SYSTEM32\DRIVERS\RDPBUS.SYS
### Microsoft RDP Bus Device driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*\SystemRoot\System32\drivers\rdpbus.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM RDPDR=C:\WINDOWS\SYSTEM32\DRIVERS\RDPDR.SYS
### Microsoft RDP Device redirector Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM RdpVideoMiniport=C:\WINDOWS\SYSTEM32\DRIVERS\RDPVIDEOMINIPORT.SYS
### Microsoft RDP Video Miniport driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM rdyboost=C:\WINDOWS\SYSTEM32\DRIVERS\RDYBOOST.SYS
### ReadyBoost Driver Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM RFCOMM=C:\WINDOWS\SYSTEM32\DRIVERS\RFCOMM.SYS
### Bluetooth RFCOMM Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*\SystemRoot\System32\drivers\rfcomm.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM rhproxy=C:\WINDOWS\SYSTEM32\DRIVERS\RHPROXY.SYS
### ResourceHub Proxy Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*\SystemRoot\System32\drivers\rhproxy.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM rspndr=C:\WINDOWS\SYSTEM32\DRIVERS\RSPNDR.SYS
### Link-Layer Topology Responder Driver for NDIS 6 Microsoft Corporation
Microsoft� Windows� Operating System 10.0.17763.1 Service registry key doesn't
exist or hidden.
[Drivers] :HKLM RSUSBVSTOR=C:\WINDOWS\SYSTEM32\DRIVERS\RTSUVSTOR.SYS
### Realtek USB Mass Storage Driver for 2K/XP/Vista/Win7/Win8 Realtek
Semiconductor Corp. Realtek USB Mass Storage Driver for 2K/XP/Vista/Win7/Win8
6.2.9200.39050 !$*\SystemRoot\System32\Drivers\RtsUVStor.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM rt640x64=C:\WINDOWS\SYSTEM32\DRIVERS\RT640X64.SYS
### Realtek 8136/8168/8169 NDIS 6.40 64-bit Driver Realtek
Realtek 8136/8168/8169 PCI/PCIe Adapters 9.001.0407.2015 !
$*\SystemRoot\System32\drivers\rt640x64.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM RTSUER=C:\WINDOWS\SYSTEM32\DRIVERS\RTSUER.SYS
### RTS USB READER Driver Realsil Semiconductor Corporation Windows (R) Win 7 DDK
driver 10.0.10011.16384 !$*\SystemRoot\system32\Drivers\RtsUer.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM s3cap=C:\WINDOWS\SYSTEM32\DRIVERS\VMS3CAP.SYS
### Microsoft S3 Emulated Device Cap Driver Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 !$*\SystemRoot\System32\drivers\vms3cap.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM sbp2port=C:\WINDOWS\SYSTEM32\DRIVERS\SBP2PORT.SYS
### SBP-2 Protocol Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM scfilter=C:\WINDOWS\SYSTEM32\DRIVERS\SCFILTER.SYS
### Microsoft Smart Card Reader Filter Driver Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 Service registry key doesn't exist or
hidden.
[Drivers] :HKLM scmbus=C:\WINDOWS\SYSTEM32\DRIVERS\SCMBUS.SYS
### Storage Class Memory Bus Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM sdbus=C:\WINDOWS\SYSTEM32\DRIVERS\SDBUS.SYS
### SecureDigital Bus Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*\SystemRoot\System32\drivers\sdbus.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM SDFRd=C:\WINDOWS\SYSTEM32\DRIVERS\SDFRD.SYS
### SDF Reflector Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*\SystemRoot\System32\drivers\SDFRd.sys Service registry key doesn't
exist or hidden.
[Drivers] :HKLM sdstor=C:\WINDOWS\SYSTEM32\DRIVERS\SDSTOR.SYS
### SD Storage Class Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*\SystemRoot\System32\drivers\sdstor.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM SerCx=C:\WINDOWS\SYSTEM32\DRIVERS\SERCX.SYS
### Serial Class Extension Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM SerCx2=C:\WINDOWS\SYSTEM32\DRIVERS\SERCX2.SYS
### Serial Class Extension V2 Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM Serenum=C:\WINDOWS\SYSTEM32\DRIVERS\SERENUM.SYS
### Serial Port Enumerator Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*\SystemRoot\System32\drivers\serenum.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM Serial=C:\WINDOWS\SYSTEM32\DRIVERS\SERIAL.SYS
### Serial Device Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*\SystemRoot\System32\drivers\serial.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM sermouse=C:\WINDOWS\SYSTEM32\DRIVERS\SERMOUSE.SYS
### Serial Mouse Filter Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*\SystemRoot\System32\drivers\sermouse.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM sfloppy=C:\WINDOWS\SYSTEM32\DRIVERS\SFLOPPY.SYS
### SCSI Floppy Driver Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*\SystemRoot\System32\drivers\sfloppy.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM SgrmAgent=C:\WINDOWS\SYSTEM32\DRIVERS\SGRMAGENT.SYS
### System Guard Runtime Monitor Agent Driver Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 Service registry key doesn't exist or
hidden.
[Drivers] :HKLM SiSRaid2=C:\WINDOWS\SYSTEM32\DRIVERS\SISRAID2.SYS
### SiS RAID Stor Miniport Driver Silicon Integrated Systems Corp. Microsoft�
Windows� Operating System 2.60.01 Service registry key doesn't exist or hidden.
[Drivers] :HKLM SiSRaid4=C:\WINDOWS\SYSTEM32\DRIVERS\SISRAID4.SYS
### SiS AHCI Stor-Miniport Driver Silicon Integrated Systems Microsoft� Windows�
Operating System 6.1.6918.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM SmartSAMD=C:\WINDOWS\SYSTEM32\DRIVERS\SMARTSAMD.SYS
### Storport Miniport Driver for SmartRAID/SmartHBA Controllers Microsemi
Corportation SmartRAID, SmartHBA PQI Storport Driver 1.50.0.0 Service registry key
doesn't exist or hidden.
[Drivers] :HKLM smbdirect=C:\WINDOWS\SYSTEM32\DRIVERS\SMBDIRECT.SYS
### SMB Network Direct Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM SmbDrvI=C:\WINDOWS\SYSTEM32\DRIVERS\SMB_DRIVER_INTEL.SYS
### Synaptics SMBus Driver Synaptics Incorporated Synaptics SMBus Driver 19.0.9.4
27May15 !$*\SystemRoot\system32\DRIVERS\Smb_driver_Intel.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM spaceport=C:\WINDOWS\SYSTEM32\DRIVERS\SPACEPORT.SYS
### Storage Spaces Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM
SpatialGraphFilter=C:\WINDOWS\SYSTEM32\DRIVERS\SPATIALGRAPHFILTER.SYS
### Holographic Spatial Graph Filter Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM SpbCx=C:\WINDOWS\SYSTEM32\DRIVERS\SPBCX.SYS
### SPB Class Extension Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM srv2=C:\WINDOWS\SYSTEM32\DRIVERS\SRV2.SYS
### Smb 2.0 Server driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM srvnet=C:\WINDOWS\SYSTEM32\DRIVERS\SRVNET.SYS
### Server Network driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM stexstor=C:\WINDOWS\SYSTEM32\DRIVERS\STEXSTOR.SYS
### Promise SuperTrak EX Series Driver for Windows x64 Promise Technology, Inc.
Promise� SuperTrak EX Series 5.1.0000.10 Service registry key doesn't exist or
hidden.
[Drivers] :HKLM storahci=C:\WINDOWS\SYSTEM32\DRIVERS\STORAHCI.SYS
### MS AHCI Storport Miniport Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM storflt=C:\WINDOWS\SYSTEM32\DRIVERS\VMSTORFL.SYS
### Virtual Storage Filter Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM stornvme=C:\WINDOWS\SYSTEM32\DRIVERS\STORNVME.SYS
### Microsoft NVM Express Storport Miniport Driver Microsoft Corporation
Microsoft� Windows� Operating System 10.0.17763.1 Service registry key doesn't
exist or hidden.
[Drivers] :HKLM storqosflt=C:\WINDOWS\SYSTEM32\DRIVERS\STORQOSFLT.SYS
### Storage QoS Filter Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM storufs=C:\WINDOWS\SYSTEM32\DRIVERS\STORUFS.SYS
### MS UFS Storport Miniport Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM storvsc=C:\WINDOWS\SYSTEM32\DRIVERS\STORVSC.SYS
### Storage VSC Driver Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM
swenum=C:\WINDOWS\SYSTEM32\DRIVERSTORE\FILEREPOSITORY\SWENUM.INF_AMD64_31F554B66002
6323\SWENUM.SYS
### Plug and Play Software Device Enumerator Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 !
$*\SystemRoot\System32\DriverStore\FileRepository\swenum.inf_amd64_31f554b660026323
\swenum.sys Service registry key doesn't exist or hidden.
[Drivers] :HKLM Synth3dVsc=C:\WINDOWS\SYSTEM32\DRIVERS\SYNTH3DVSC.SYS
### Microsoft RemoteFX Synth3D Video VSC Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 !
$*\SystemRoot\System32\drivers\Synth3dVsc.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM SynTP=C:\WINDOWS\SYSTEM32\DRIVERS\SYNTP.SYS
### Synaptics Touchpad Win64 Driver Synaptics Incorporated Synaptics Pointing
Device Driver 19.0.9.4 27May15 !$*\SystemRoot\system32\DRIVERS\SynTP.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM Tcpip=C:\WINDOWS\SYSTEM32\DRIVERS\TCPIP.SYS
### TCP/IP Driver Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM Tcpip6=C:\WINDOWS\SYSTEM32\DRIVERS\TCPIP.SYS
### TCP/IP Driver Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM tcpipreg=C:\WINDOWS\SYSTEM32\DRIVERS\TCPIPREG.SYS
### TCP/IP Registry Compatibility Driver Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 Service registry key doesn't exist or
hidden.
[Drivers] :HKLM tdx=C:\WINDOWS\SYSTEM32\DRIVERS\TDX.SYS
### TDI Translation Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*\SystemRoot\system32\DRIVERS\tdx.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM terminpt=C:\WINDOWS\SYSTEM32\DRIVERS\TERMINPT.SYS
### Terminal Server Input Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*\SystemRoot\System32\drivers\terminpt.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM TPM=C:\WINDOWS\SYSTEM32\DRIVERS\TPM.SYS
### TPM Device Driver Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*\SystemRoot\System32\drivers\tpm.sys Service registry key doesn't
exist or hidden.
[Drivers] :HKLM TsUsbFlt=C:\WINDOWS\SYSTEM32\DRIVERS\TSUSBFLT.SYS
### Remote Desktop USB Hub Filter Driver Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 Service registry key doesn't exist or
hidden.
[Drivers] :HKLM TsUsbGD=C:\WINDOWS\SYSTEM32\DRIVERS\TSUSBGD.SYS
### Remote Desktop Generic USB Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*\SystemRoot\System32\drivers\TsUsbGD.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM tsusbhub=C:\WINDOWS\SYSTEM32\DRIVERS\TSUSBHUB.SYS
### Remote Desktop USB Hub Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM tunnel=C:\WINDOWS\SYSTEM32\DRIVERS\TUNNEL.SYS
### Microsoft Tunnel Interface Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM UASPStor=C:\WINDOWS\SYSTEM32\DRIVERS\UASPSTOR.SYS
### Microsoft Uasp Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*\SystemRoot\System32\drivers\uaspstor.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM UcmCx0101=C:\WINDOWS\SYSTEM32\DRIVERS\UCMCX.SYS
### USB Connector Manager KMDF Class Extension Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 Service registry key doesn't exist or
hidden.
[Drivers] :HKLM UcmTcpciCx0101=C:\WINDOWS\SYSTEM32\DRIVERS\UCMTCPCICX.SYS
### UCM-TCPCI KMDF Class Extension Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM UcmUcsi=C:\WINDOWS\SYSTEM32\DRIVERS\UCMUCSI.SYS
### USB Connector Manager UCSI Client Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*\SystemRoot\System32\drivers\UcmUcsi.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM
UcmUcsiAcpiClient=C:\WINDOWS\SYSTEM32\DRIVERS\UCMUCSIACPICLIENT.SYS
### UCM-UCSI ACPI Client Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*\SystemRoot\System32\drivers\UcmUcsiAcpiClient.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM UcmUcsiCx0101=C:\WINDOWS\SYSTEM32\DRIVERS\UCMUCSICX.SYS
### UCM-UCSI KMDF Class Extension Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM Ucx01000=C:\WINDOWS\SYSTEM32\DRIVERS\UCX01000.SYS
### USB Controller Extension Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM UdeCx=C:\WINDOWS\SYSTEM32\DRIVERS\UDECX.SYS
### "udecx.DRIVER" Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM udfs=C:\WINDOWS\SYSTEM32\DRIVERS\UDFS.SYS
### UDF File System Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM UEFI=C:\WINDOWS\SYSTEM32\DRIVERS\UEFI.SYS
### UEFI Driver for NT Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*\SystemRoot\System32\drivers\UEFI.sys Service registry key doesn't
exist or hidden.
[Drivers] :HKLM UevAgentDriver=C:\WINDOWS\SYSTEM32\DRIVERS\UEVAGENTDRIVER.SYS
### Microsoft User Experience Virtualization Agent Driver Microsoft Corporation
Microsoft� Windows� Operating System 10.0.17763.1 !
$*\SystemRoot\system32\drivers\UevAgentDriver.sys Service registry key doesn't
exist or hidden.
[Drivers] :HKLM Ufx01000=C:\WINDOWS\SYSTEM32\DRIVERS\UFX01000.SYS
### USB Function Driver Class Extension Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM UfxChipidea=C:\WINDOWS\SYSTEM32\DRIVERS\UFXCHIPIDEA.SYS
### UFX Chipidea Client Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*\SystemRoot\System32\drivers\UfxChipidea.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM ufxsynopsys=C:\WINDOWS\SYSTEM32\DRIVERS\UFXSYNOPSYS.SYS
### UFX Synopsys Client Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*\SystemRoot\System32\drivers\ufxsynopsys.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM umbus=C:\WINDOWS\SYSTEM32\DRIVERS\UMBUS.SYS
### User-Mode Bus Enumerator Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*\SystemRoot\System32\drivers\umbus.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM UmPass=C:\WINDOWS\SYSTEM32\DRIVERS\UMPASS.SYS
### Generic pass-through driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*\SystemRoot\System32\drivers\umpass.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM UrsChipidea=C:\WINDOWS\SYSTEM32\DRIVERS\URSCHIPIDEA.SYS
### USB Role-Switch Driver for Chipidea Core Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 !
$*\SystemRoot\System32\drivers\urschipidea.sys Service registry key doesn't exist
or hidden.
[Drivers] :HKLM UrsCx01000=C:\WINDOWS\SYSTEM32\DRIVERS\URSCX01000.SYS
### USB Role-Switch Class Extension Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM UrsSynopsys=C:\WINDOWS\SYSTEM32\DRIVERS\URSSYNOPSYS.SYS
### USB Role-Switch Driver for Synopsys Core Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 !
$*\SystemRoot\System32\drivers\urssynopsys.sys Service registry key doesn't exist
or hidden.
[Drivers] :HKLM usbccgp=C:\WINDOWS\SYSTEM32\DRIVERS\USBCCGP.SYS
### USB Common Class Generic Parent Driver Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 !$*\SystemRoot\System32\drivers\usbccgp.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM usbcir=C:\WINDOWS\SYSTEM32\DRIVERS\USBCIR.SYS
### USB Consumer IR Driver for eHome Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*\SystemRoot\System32\drivers\usbcir.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM usbehci=C:\WINDOWS\SYSTEM32\DRIVERS\USBEHCI.SYS
### EHCI eUSB Miniport Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*\SystemRoot\System32\drivers\usbehci.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM usbhub=C:\WINDOWS\SYSTEM32\DRIVERS\USBHUB.SYS
### Default Hub Driver for USB Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*\SystemRoot\System32\drivers\usbhub.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM USBHUB3=C:\WINDOWS\SYSTEM32\DRIVERS\USBHUB3.SYS
### USB3 HUB Driver Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*\SystemRoot\System32\drivers\UsbHub3.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM usbohci=C:\WINDOWS\SYSTEM32\DRIVERS\USBOHCI.SYS
### OHCI USB Miniport Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*\SystemRoot\System32\drivers\usbohci.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM usbprint=C:\WINDOWS\SYSTEM32\DRIVERS\USBPRINT.SYS
### USB Printer driver Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*\SystemRoot\System32\drivers\usbprint.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM usbser=C:\WINDOWS\SYSTEM32\DRIVERS\USBSER.SYS
### USB Serial Driver Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*\SystemRoot\System32\drivers\usbser.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM USBSTOR=C:\WINDOWS\SYSTEM32\DRIVERS\USBSTOR.SYS
### USB Mass Storage Class Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*\SystemRoot\System32\drivers\USBSTOR.SYS Service
registry key doesn't exist or hidden.
[Drivers] :HKLM usbuhci=C:\WINDOWS\SYSTEM32\DRIVERS\USBUHCI.SYS
### UHCI USB Miniport Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*\SystemRoot\System32\drivers\usbuhci.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM usbvideo=C:\WINDOWS\SYSTEM32\DRIVERS\USBVIDEO.SYS
### USB Video Class Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*\SystemRoot\System32\Drivers\usbvideo.sys Service registry
key doesn't exist or hidden.
[Drivers] :HKLM USBXHCI=C:\WINDOWS\SYSTEM32\DRIVERS\USBXHCI.SYS
### USB XHCI Driver Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*\SystemRoot\System32\drivers\USBXHCI.SYS Service registry key
doesn't exist or hidden.
[Drivers] :HKLM vdrvroot=C:\WINDOWS\SYSTEM32\DRIVERS\VDRVROOT.SYS
### Virtual Drive Root Enumerator Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM VerifierExt=C:\WINDOWS\SYSTEM32\DRIVERS\VERIFIEREXT.SYS
### Driver Verifier Extension Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM vhdmp=C:\WINDOWS\SYSTEM32\DRIVERS\VHDMP.SYS
### VHD Miniport Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*\SystemRoot\System32\drivers\vhdmp.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM vhf=C:\WINDOWS\SYSTEM32\DRIVERS\VHF.SYS
### Virtual HID Framework (VHF) Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*\SystemRoot\System32\drivers\vhf.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM Vid=C:\WINDOWS\SYSTEM32\DRIVERS\VID.SYS
### Microsoft Hyper-V Virtualization Infrastructure Driver Microsoft Corporation
Microsoft� Windows� Operating System 10.0.17763.1 !
$*\SystemRoot\System32\drivers\Vid.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM vmbus=C:\WINDOWS\SYSTEM32\DRIVERS\VMBUS.SYS
### Microsoft Hyper-V Virtual Machine Bus Child Driver Microsoft Corporation
Microsoft� Windows� Operating System 10.0.17763.1 Service registry key doesn't
exist or hidden.
[Drivers] :HKLM VMBusHID=C:\WINDOWS\SYSTEM32\DRIVERS\VMBUSHID.SYS
### Microsoft VMBus HID Miniport Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*\SystemRoot\System32\drivers\VMBusHID.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM vmgid=C:\WINDOWS\SYSTEM32\DRIVERS\VMGID.SYS
### Virtual Machine Guest Infrastructure Driver Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 !$*\SystemRoot\System32\drivers\vmgid.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM volmgr=C:\WINDOWS\SYSTEM32\DRIVERS\VOLMGR.SYS
### Volume Manager Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM volmgrx=C:\WINDOWS\SYSTEM32\DRIVERS\VOLMGRX.SYS
### Volume Manager Extension Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM volsnap=C:\WINDOWS\SYSTEM32\DRIVERS\VOLSNAP.SYS
### Volume Shadow Copy driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM volume=C:\WINDOWS\SYSTEM32\DRIVERS\VOLUME.SYS
### Volume driver Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM vpci=C:\WINDOWS\SYSTEM32\DRIVERS\VPCI.SYS
### Virtual PCI Bus Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*\SystemRoot\System32\drivers\vpci.sys Service registry key doesn't
exist or hidden.
[Drivers] :HKLM vsmraid=C:\WINDOWS\SYSTEM32\DRIVERS\VSMRAID.SYS
### VIA RAID DRIVER FOR AMD-X86-64 VIA Technologies Inc.,Ltd VIA RAID driver
7.0.9600,6352 Service registry key doesn't exist or hidden.
[Drivers] :HKLM VSTXRAID=C:\WINDOWS\SYSTEM32\DRIVERS\VSTXRAID.SYS
### VIA StorX RAID Controller Driver VIA Corporation VIA StorX RAID Controller
Driver 8.0.9200.8110 Service registry key doesn't exist or hidden.
[Drivers] :HKLM vwifibus=C:\WINDOWS\SYSTEM32\DRIVERS\VWIFIBUS.SYS
### Virtual Wireless Bus Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*\SystemRoot\System32\drivers\vwifibus.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM vwififlt=C:\WINDOWS\SYSTEM32\DRIVERS\VWIFIFLT.SYS
### Virtual WiFi Filter Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM vwifimp=C:\WINDOWS\SYSTEM32\DRIVERS\VWIFIMP.SYS
### Virtual WiFi Miniport Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*\SystemRoot\System32\drivers\vwifimp.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM WacomPen=C:\WINDOWS\SYSTEM32\DRIVERS\WACOMPEN.SYS
### Wacom Serial Pen Tablet HID Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*\SystemRoot\System32\drivers\wacompen.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM wanarp=C:\WINDOWS\SYSTEM32\DRIVERS\WANARP.SYS
### MS Remote Access and Routing ARP Driver Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 Service registry key doesn't exist or
hidden.
[Drivers] :HKLM wanarpv6=C:\WINDOWS\SYSTEM32\DRIVERS\WANARP.SYS
### MS Remote Access and Routing ARP Driver Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 Service registry key doesn't exist or
hidden.
[Drivers] :HKLM wcifs=C:\WINDOWS\SYSTEM32\DRIVERS\WCIFS.SYS
### Windows Container Isolation FS Filter Driver Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 !$*\SystemRoot\system32\drivers\wcifs.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM wcnfs=C:\WINDOWS\SYSTEM32\DRIVERS\WCNFS.SYS
### Windows Container Name Virtualization FS Filter Driver Microsoft Corporation
Microsoft� Windows� Operating System 10.0.17763.1 !
$*\SystemRoot\system32\drivers\wcnfs.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM WdBoot=C:\WINDOWS\SYSTEM32\DRIVERS\WDBOOT.SYS
### Microsoft antimalware boot driver Microsoft Corporation Microsoft� Windows�
Operating System 4.18.1807.18075 Service registry key doesn't exist or hidden.
[Drivers] :HKLM Wdf01000=C:\WINDOWS\SYSTEM32\DRIVERS\WDF01000.SYS
### Kernel Mode Driver Framework Runtime Microsoft Corporation Microsoft�
Windows� Operating System 1.27.17763.1 Service registry key doesn't exist or
hidden.
[Drivers] :HKLM WdFilter=C:\WINDOWS\SYSTEM32\DRIVERS\WDFILTER.SYS
### Microsoft antimalware file system filter driver Microsoft Corporation
Microsoft� Windows� Operating System 4.18.1807.18075 Service registry key doesn't
exist or hidden.
[Drivers] :HKLM wdiwifi=C:\WINDOWS\SYSTEM32\DRIVERS\WDIWIFI.SYS
### WDI Driver Framework Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM
WdmCompanionFilter=C:\WINDOWS\SYSTEM32\DRIVERS\WDMCOMPANIONFILTER.SYS
### WDM Companion Filter Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM WdNisDrv=C:\WINDOWS\SYSTEM32\DRIVERS\WDNISDRV.SYS
### Windows Defender Network Stream Filter Microsoft Corporation Microsoft�
Windows� Operating System 4.18.1807.18075 Service registry key doesn't exist or
hidden.
[Drivers] :HKLM WFPLWFS=C:\WINDOWS\SYSTEM32\DRIVERS\WFPLWFS.SYS
### WFP NDIS 6.30 Lightweight Filter Driver Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 Service registry key doesn't exist or
hidden.
[Drivers] :HKLM WIMMount=C:\WINDOWS\SYSTEM32\DRIVERS\WIMMOUNT.SYS
### Wim file system Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM WindowsTrustedRT=C:\WINDOWS\SYSTEM32\DRIVERS\WINDOWSTRUSTEDRT.SYS
### Windows Trusted Runtime Interface Driver Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 Service registry key doesn't exist or
hidden.
[Drivers] :HKLM
WindowsTrustedRTProxy=C:\WINDOWS\SYSTEM32\DRIVERS\WINDOWSTRUSTEDRTPROXY.SYS
### Windows Trusted Runtime Service Proxy Driver Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 Service registry key doesn't exist or
hidden.
[Drivers] :HKLM WinMad=C:\WINDOWS\SYSTEM32\DRIVERS\WINMAD.SYS
### Kernel WinMad Mellanox OpenFabrics Windows 10.0.10011.16384 !
$*\SystemRoot\System32\drivers\winmad.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM WinNat=C:\WINDOWS\SYSTEM32\DRIVERS\WINNAT.SYS
### Windows NAT Driver Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM WinQuic=C:\WINDOWS\SYSTEM32\DRIVERS\WINQUIC.SYS
### Windows QUIC Driver Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 Service registry key doesn't exist or hidden.
[Drivers] :HKLM WINUSB=C:\WINDOWS\SYSTEM32\DRIVERS\WINUSB.SYS
### Windows WinUSB Class Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*\SystemRoot\System32\drivers\WinUSB.SYS Service
registry key doesn't exist or hidden.
[Drivers] :HKLM WinVerbs=C:\WINDOWS\SYSTEM32\DRIVERS\WINVERBS.SYS
### Kernel WinVerbs Mellanox OpenFabrics Windows 10.0.10011.16384 !
$*\SystemRoot\System32\drivers\winverbs.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM WmiAcpi=C:\WINDOWS\SYSTEM32\DRIVERS\WMIACPI.SYS
### Windows Management Interface for ACPI Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 !$*\SystemRoot\System32\drivers\wmiacpi.sys
Service registry key doesn't exist or hidden.
[Drivers] :HKLM WpdUpFltr=C:\WINDOWS\SYSTEM32\DRIVERS\WPDUPFLTR.SYS
### Windows Portable Device Upper Class Filter Driver Microsoft Corporation
Microsoft� Windows� Operating System 10.0.17763.1 Service registry key doesn't
exist or hidden.
[Drivers] :HKLM ws2ifsl=C:\WINDOWS\SYSTEM32\DRIVERS\WS2IFSL.SYS
### Winsock2 IFS Layer Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*\SystemRoot\system32\drivers\ws2ifsl.sys Service registry key
doesn't exist or hidden.
[Drivers] :HKLM WudfPf=C:\WINDOWS\SYSTEM32\DRIVERS\WUDFPF.SYS
### Windows Driver Foundation - User-mode Driver Framework Platform Driver
Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1 Service
registry key doesn't exist or hidden.
[Drivers] :HKLM WUDFRd=C:\WINDOWS\SYSTEM32\DRIVERS\WUDFRD.SYS
### Windows Driver Foundation - User-mode Driver Framework Reflector Microsoft
Corporation Microsoft� Windows� Operating System 10.0.17763.1 Service registry key
doesn't exist or hidden.
[Drivers] :HKLM WUDFWpdFs=C:\WINDOWS\SYSTEM32\DRIVERS\WUDFRD.SYS
### Windows Driver Foundation - User-mode Driver Framework Reflector Microsoft
Corporation Microsoft� Windows� Operating System 10.0.17763.1 !
$*\SystemRoot\system32\DRIVERS\WUDFRd.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM WUDFWpdMtp=C:\WINDOWS\SYSTEM32\DRIVERS\WUDFRD.SYS
### Windows Driver Foundation - User-mode Driver Framework Reflector Microsoft
Corporation Microsoft� Windows� Operating System 10.0.17763.1 !
$*\SystemRoot\system32\DRIVERS\WUDFRd.sys Service registry key doesn't exist or
hidden.
[Drivers] :HKLM xboxgip=C:\WINDOWS\SYSTEM32\DRIVERS\XBOXGIP.SYS
### Game Input Protocol Driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*\SystemRoot\System32\drivers\xboxgip.sys Service
registry key doesn't exist or hidden.
[Drivers] :HKLM xinputhid=C:\WINDOWS\SYSTEM32\DRIVERS\XINPUTHID.SYS
### XINPUT filter driver for HID Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*\SystemRoot\System32\drivers\xinputhid.sys Service
registry key doesn't exist or hidden.
[Codecs] :HKLM midimapper=C:\Windows\SYSTEM32\MIDIMAP.DLL
### Microsoft MIDI Mapper Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*midimap.dll
[Codecs] :HKLM msacm.imaadpcm=C:\Windows\SYSTEM32\IMAADP32.ACM
### IMA ADPCM CODEC for MSACM Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*imaadp32.acm
[Codecs] :HKLM msacm.msadpcm=C:\Windows\SYSTEM32\MSADP32.ACM
### Microsoft ADPCM CODEC for MSACM Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*msadp32.acm
[Codecs] :HKLM msacm.msg711=C:\Windows\SYSTEM32\MSG711.ACM
### Microsoft CCITT G.711 (A-Law and u-Law) CODEC for MSACM Microsoft Corporation
Microsoft� Windows� Operating System 10.0.17763.1 !$*msg711.acm
[Codecs] :HKLM msacm.msgsm610=C:\Windows\SYSTEM32\MSGSM32.ACM
### Microsoft GSM 6.10 Audio CODEC for MSACM Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 !$*msgsm32.acm
[Codecs] :HKLM vidc.cvid=C:\WINDOWS\Syswow64\ICCVID.DLL
### Cinepak� Codec Radius Inc. Cinepak for Windows 32 1.10.0.0 !$*iccvid.dll
[Codecs] :HKLM vidc.i420=C:\Windows\SYSTEM32\IYUV_32.DLL
### Intel Indeo(R) Video YUV Codec Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*iyuv_32.dll
[Codecs] :HKLM vidc.iyuv=C:\Windows\SYSTEM32\IYUV_32.DLL
### Intel Indeo(R) Video YUV Codec Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*iyuv_32.dll
[Codecs] :HKLM vidc.mrle=C:\Windows\SYSTEM32\MSRLE32.DLL
### Microsoft RLE Compressor Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*msrle32.dll
[Codecs] :HKLM vidc.msvc=C:\Windows\SYSTEM32\MSVIDC32.DLL
### Microsoft Video 1 Compressor Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*msvidc32.dll
[Codecs] :HKLM vidc.uyvy=C:\Windows\SYSTEM32\MSYUV.DLL
### Microsoft UYVY Video Decompressor Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*msyuv.dll
[Codecs] :HKLM vidc.yuy2=C:\Windows\SYSTEM32\MSYUV.DLL
### Microsoft UYVY Video Decompressor Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*msyuv.dll
[Codecs] :HKLM vidc.yvu9=C:\Windows\SYSTEM32\TSBYUV.DLL
### Toshiba Video Codec Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*tsbyuv.dll
[Codecs] :HKLM vidc.yvyu=C:\Windows\SYSTEM32\MSYUV.DLL
### Microsoft UYVY Video Decompressor Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*msyuv.dll
[Codecs] :HKLM wavemapper=C:\Windows\SYSTEM32\MSACM32.DRV
### Microsoft Sound Mapper Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*msacm32.drv
[Codecs] :HKLM msacm.l3acm=C:\WINDOWS\SYSWOW64\L3CODECA.ACM
### MPEG Layer-3 Audio Codec for MSACM Fraunhofer Institut Integrierte
Schaltungen IIS MPEG Layer-3 Audio Codec for MSACM 1, 0, 0, 0
[Codecs] :HKLM wave=C:\Windows\SYSTEM32\WDMAUD.DRV
### Winmm audio system driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*wdmaud.drv
[Codecs] :HKLM midi=C:\Windows\SYSTEM32\WDMAUD.DRV
### Winmm audio system driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*wdmaud.drv
[Codecs] :HKLM mixer=C:\Windows\SYSTEM32\WDMAUD.DRV
### Winmm audio system driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*wdmaud.drv
[Codecs] :HKLM aux=C:\Windows\SYSTEM32\WDMAUD.DRV
### Winmm audio system driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*wdmaud.drv
[Codecs] :HKLM wave1=C:\Windows\SYSTEM32\WDMAUD.DRV
### Winmm audio system driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*wdmaud.drv
[Codecs] :HKLM midi1=C:\Windows\SYSTEM32\WDMAUD.DRV
### Winmm audio system driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*wdmaud.drv
[Codecs] :HKLM mixer1=C:\Windows\SYSTEM32\WDMAUD.DRV
### Winmm audio system driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*wdmaud.drv
[Codecs] :HKLM aux1=C:\Windows\SYSTEM32\WDMAUD.DRV
### Winmm audio system driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*wdmaud.drv
[Codecs] :HKLM wave2=C:\Windows\SYSTEM32\WDMAUD.DRV
### Winmm audio system driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*wdmaud.drv
[Codecs] :HKLM midi2=C:\Windows\SYSTEM32\WDMAUD.DRV
### Winmm audio system driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*wdmaud.drv
[Codecs] :HKLM mixer2=C:\Windows\SYSTEM32\WDMAUD.DRV
### Winmm audio system driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*wdmaud.drv
[Codecs] :HKLM wave3=C:\Windows\SYSTEM32\WDMAUD.DRV
### Winmm audio system driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*wdmaud.drv
[Codecs] :HKLM midi3=C:\Windows\SYSTEM32\WDMAUD.DRV
### Winmm audio system driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*wdmaud.drv
[Codecs] :HKLM mixer3=C:\Windows\SYSTEM32\WDMAUD.DRV
### Winmm audio system driver Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*wdmaud.drv
[DCOM Components] :HKLM {F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}=""
[DCOM Components] :HKLM {5839FCA9-774D-42A1-ACDA-
D6A79037F57F}=C:\WINDOWS\SYSTEM32\WBEM\FASTPROX.DLL
### WMI Custom Marshaller Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1
[DCOM Components] :HKLM {42AEDC87-2188-41FD-B9A3-
0C966FEABEC1}=C:\WINDOWS\SYSTEM32\WINDOWS.STORAGE.DLL
### Microsoft WinRT Storage API Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1
[DCOM User Components] :HKCU {F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}=""
[DCOM User Components] :HKCU {FBEB8A05-BEEE-4442-804E-409D6C4515E9}=""
[DCOM User Components] :HKCU {42AEDC87-2188-41FD-B9A3-0C966FEABEC1}=""
[Auto Start Apps]
[Registry Run] :HKCU
OneDrive=C:\USERS\SUKAN\APPDATA\LOCAL\MICROSOFT\ONEDRIVE\ONEDRIVE.EXE
### Microsoft OneDrive Microsoft Corporation Microsoft OneDrive
18.143.0717.0002 !
$*"C:\Users\sukan\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
[Registry Run] :HKCU CCleaner Monitoring=C:\PROGRAM FILES\CCLEANER\CCLEANER64.EXE
### CCleaner Piriform Ltd CCleaner 5, 29, 00, 6033 !$*"C:\Program
Files\CCleaner\CCleaner64.exe" /MONITOR
[Registry Run] :HKCU IDMan=C:\PROGRAM FILES (X86)\INTERNET DOWNLOAD
MANAGER\IDMAN.EXE
### Internet Download Manager (IDM) Tonec Inc. Internet Download Manager (IDM) 6,
30, 7, 2 !$*C:\Program Files (x86)\Internet Download Manager\IDMan.exe /onboot
[Registry Run(x64)] :HKLM
SecurityHealth=C:\WINDOWS\SYSTEM32\SECURITYHEALTHSYSTRAY.EXE
### Windows Security notification icon Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*%windir%\system32\SecurityHealthSystray.exe
[Registry Run(x64)] :HKLM RTHDVCPL=C:\PROGRAM
FILES\REALTEK\AUDIO\HDA\RTKNGUI64.EXE
### Realtek HD Audio Manager Realtek Semiconductor Realtek HD Audio Manager
1.0.484.0 !$*"C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
[Registry Run(x64)] :HKLM RtHDVBg=C:\PROGRAM FILES\REALTEK\AUDIO\HDA\RAVBG64.EXE
### HD Audio Background Process Realtek Semiconductor HD Audio Background Process
1, 0, 0, 220 !$*"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /MAXX4
[Registry RunOnceEx] :HKLM @Regrun2=C:\UNHACKME\REANIMATOR.EXE
### RegRun Start Control Greatis Software RegRun Security Suite 8.70 !
$*C:\UnHackMe\reanimator.exe /wiz /full
[Win.ini] :HKCU load=""
### File is missing.
[Win.ini] :HKCU run=""
### File is missing.
[Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\CCleanerSkipUAC=C:\PROGRAM
FILES\CCLEANER\CCLEANER.EXE
### CCleaner Piriform Ltd CCleaner 5, 29, 00, 6033 !$*"C:\Program
Files\CCleaner\CCleaner.exe" Parameters: $(Arg0)
[Scheduled Tasks 2]
C:\WINDOWS\SYSNATIVE\TASKS\GoogleUpdateTaskMachineCore=C:\PROGRAM FILES
(X86)\GOOGLE\UPDATE\GOOGLEUPDATE.EXE
### Google Installer Google Inc. Google Update 1.3.33.7 Description: Keeps your
Google software up to date. If this tas Parameters: /c
[Scheduled Tasks 2]
C:\WINDOWS\SYSNATIVE\TASKS\GoogleUpdateTaskMachineUA=C:\PROGRAM FILES
(X86)\GOOGLE\UPDATE\GOOGLEUPDATE.EXE
### Google Installer Google Inc. Google Update 1.3.33.7 Description: Keeps your
Google software up to date. If this tas Parameters: /ua /installsource scheduler
[Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\OneDrive Standalone Update Task-S-
1-5-21-67703685-4255488207-1546581969-
1001=C:\USERS\SUKAN\APPDATA\LOCAL\MICROSOFT\ONEDRIVE\ONEDRIVESTANDALONEUPDATER.EXE
### Standalone Updater Microsoft Corporation Microsoft OneDrive
18.143.0717.0002 !$*%localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe
Parameters: {}
[Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\RtHDVBg_PushButton=C:\PROGRAM
FILES\REALTEK\AUDIO\HDA\RAVBG64.EXE
### HD Audio Background Process Realtek Semiconductor HD Audio Background Process
1, 0, 0, 220 !$*"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" Parameters: /IM
[Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Synaptics TouchPad
Enhancements=C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPENH.EXE
### Synaptics TouchPad 64-bit Enhancements Synaptics Incorporated Synaptics
Pointing Device Driver 19.0.9.4 27May15 !$*"C:\Program
Files\Synaptics\SynTP\SynTPEnh.exe"
[Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\UnHackMe Task
Scheduler=C:\UNHACKME\HACKMON.EXE
### Detects Rootkits in background Greatis Software UnHackMe 8.50 Description:
Part of RegRun Suite/UnHackMe software. http://www Parameters: $(Arg0)
[Scheduled Tasks 2.0 Cached] :HKLM CCleanerSkipUAC=C:\PROGRAM
FILES\CCLEANER\CCLEANER.EXE
### CCleaner Piriform Ltd CCleaner 5, 29, 00, 6033 !$*"C:\Program
Files\CCleaner\CCleaner.exe" Parameters: $(Arg0)
[Scheduled Tasks 2.0 Cached] :HKLM GoogleUpdateTaskMachineCore=C:\PROGRAM FILES
(X86)\GOOGLE\UPDATE\GOOGLEUPDATE.EXE
### Google Installer Google Inc. Google Update 1.3.33.7 Keeps your Google
software up to date. If this task is disabled or stopped, your Google software will
not be kept up to date, meaning security vulnerabilities that may arise cannot be
fixed and features may not work. This task uninstalls itself when there is no
Google software using it. Parameters: /c
[Scheduled Tasks 2.0 Cached] :HKLM GoogleUpdateTaskMachineUA=C:\PROGRAM FILES
(X86)\GOOGLE\UPDATE\GOOGLEUPDATE.EXE
### Google Installer Google Inc. Google Update 1.3.33.7 Keeps your Google
software up to date. If this task is disabled or stopped, your Google software will
not be kept up to date, meaning security vulnerabilities that may arise cannot be
fixed and features may not work. This task uninstalls itself when there is no
Google software using it. Parameters: /ua /installsource scheduler
[Scheduled Tasks 2.0 Cached] :HKLM OneDrive Standalone Update Task-S-1-5-21-
67703685-4255488207-1546581969-
1001=C:\USERS\SUKAN\APPDATA\LOCAL\MICROSOFT\ONEDRIVE\ONEDRIVESTANDALONEUPDATER.EXE
### Standalone Updater Microsoft Corporation Microsoft OneDrive
18.143.0717.0002 !$*%localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe

[Scheduled Tasks 2.0 Cached] :HKLM RtHDVBg_PushButton=C:\PROGRAM


FILES\REALTEK\AUDIO\HDA\RAVBG64.EXE
### HD Audio Background Process Realtek Semiconductor HD Audio Background Process
1, 0, 0, 220 !$*"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" Parameters: /IM
[Scheduled Tasks 2.0 Cached] :HKLM Synaptics TouchPad Enhancements=C:\PROGRAM
FILES\SYNAPTICS\SYNTP\SYNTPENH.EXE
### Synaptics TouchPad 64-bit Enhancements Synaptics Incorporated Synaptics
Pointing Device Driver 19.0.9.4 27May15 !$*"C:\Program
Files\Synaptics\SynTP\SynTPEnh.exe"
[Scheduled Tasks 2.0 Cached] :HKLM UnHackMe Task
Scheduler=C:\UNHACKME\HACKMON.EXE
### Detects Rootkits in background Greatis Software UnHackMe 8.50 Part of
RegRun Suite/UnHackMe software. http://www.greatis.com Parameters: $(Arg0)
[Detected using Heuristic Algorithm] :HKLM CISCO=C:\PROGRAM FILES (X86)\CISCO\
### "CISCO EAP-FAST MODULE\" "CISCO LEAP MODULE\" "CISCO PEAP MODULE\" "Cisco
EAP-FAST Module: CISCO-FAST-MANIFEST.XML" "CISCOEAPFAST.DLL" "CISCOEAPFAST.XSD"
"LICENSE.RTF" "Cisco LEAP Module: CISCO-LEAP-MANIFEST.XML" "CISCOEAPLEAP.DLL"
"CISCOEAPLEAP.XSD" "LI
[Detected using Heuristic Algorithm] :HKLM COMMON FILES=C:\PROGRAM FILES
(X86)\COMMON FILES\
### "ATHEROS\" "INTEL\" "MICROSOFT SHARED\" "SERVICES\" "SYSTEM\" "Atheros:
INSTALLLOG.TXT" "Intel\OpenCL: LLVM_RELEASE_LICENSE.TXT" "README.TXT" "VERSION.INI"
"microsoft shared\DAO: DAO360.DLL" "microsoft shared\Filters: TIFFFILT.DLL"
"microsoft shared\Help
[Detected using Heuristic Algorithm] :HKLM ATHEROS=C:\PROGRAM FILES (X86)\COMMON
FILES\ATHEROS\
### "INSTALLLOG.TXT"
[Detected using Heuristic Algorithm] :HKLM INTEL=C:\PROGRAM FILES (X86)\COMMON
FILES\INTEL\
### "OPENCL\" "OpenCL: LLVM_RELEASE_LICENSE.TXT" "README.TXT" "VERSION.INI"
"OpenCL\bin\x64: CLANG_COMPILER64.DLL" "CLBLTFNE9.RTL" "CLBLTFNE9_IMG_CBK.O"
"CLBLTFNE9_IMG_CBK.RTL" "CLBLTFNH8.RTL" "CLBLTFNH8_IMG_CBK.O"
"CLBLTFNH8_IMG_CBK.RTL" "OpenCL\bin\x86: CLA
[Detected using Heuristic Algorithm] :HKLM MICROSOFT SHARED=C:\PROGRAM FILES
(X86)\COMMON FILES\MICROSOFT SHARED\
### "DAO\" "FILTERS\" "HELP\" "INK\" "MSENV\" "MSINFO\" "OFFICE16\" "PORTAL\"
"STATIONERY\" "TEXTCONV\" "TRIEDIT\"
[Detected using Heuristic Algorithm] :HKLM DELL WIRELESS=C:\PROGRAM FILES
(X86)\DELL WIRELESS\
### "BLUETOOTH SUITE\" "ICON FILES\" "LICENSE.TXT" "NOTICE.TXT" "WDK_LICENSE.RTF"
"Bluetooth Suite: ADMINSERVICE.EXE" "ATHEROS_BTH.CAT" "ATHEROS_BTH.INF"
"BTATHEROSINSTALL.EXE" "BTCONTEXTMENU.DLL" "BTFILTER.SYS" "Icon Files: ACU.ICO"
"ADU.ICO" "DCU.ICO" "ICO
[Detected using Heuristic Algorithm] :HKLM FOXIT SOFTWARE=C:\PROGRAM FILES
(X86)\FOXIT SOFTWARE\
### "FOXIT READER\" "Foxit Reader: 64BITMAILAGENT.EXE"
"FOXITCONNECTEDPDFSERVICE.EXE" "FOXITREADER.EXE" "FOXITREADER.EXE.MAN"
"FOXITREADER.VISUALELEMENTSMANIFEST.XML" "FOXITUPDATER.EXE" "FPCSDK.DLL"
"FPCSDK64.DLL" "FXCUSTOM.DLL" "LOCALSERVICE.DLL"
[Detected using Heuristic Algorithm] :HKLM GOOGLE=C:\PROGRAM FILES (X86)\GOOGLE\
### "CHROME\" "CRASHREPORTS\" "UPDATE\" "Chrome\Application: CHROME.EXE"
"CHROME.VISUALELEMENTSMANIFEST.XML" "MASTER_PREFERENCES" "Update: GOOGLEUPDATE.EXE"
"Update\1.3.33.17: GOOGLECRASHHANDLER.EXE" "GOOGLECRASHHANDLER64.EXE"
"GOOGLEUPDATE.EXE" "Update\Downl
[Detected using Heuristic Algorithm] :HKLM INSTALLSHIELD INSTALLATION
INFORMATION=C:\PROGRAM FILES (X86)\INSTALLSHIELD INSTALLATION INFORMATION\
### "{28006915-2739-4EBE-B5E8-49B25D32EB33}\" "{5BC2B5AB-80DE-4E83-B8CF-
426902051D0A}\" "{28006915-2739-4EBE-B5E8-49B25D32EB33}: 0X0401.INI" "0X0402.INI"
"0X0404.INI" "0X0405.INI" "0X0406.INI" "0X0407.INI" "{5BC2B5AB-80DE-4E83-B8CF-
426902051D0A}: DATA1.CAB"
[Detected using Heuristic Algorithm] :HKLM INTEL=C:\PROGRAM FILES (X86)\INTEL\
### "INTEL(R) PROCESSOR GRAPHICS\" "Intel(R) Processor Graphics\uninstall:
SETUP.EXE"
[Detected using Heuristic Algorithm] :HKLM INTERNET DOWNLOAD MANAGER=C:\PROGRAM
FILES (X86)\INTERNET DOWNLOAD MANAGER\
### "DEFEXCLIST.TXT" "DOWNLWITHIDM.DLL" "DOWNLWITHIDM64.DLL" "GRABBER.CHM" "IDM
PATCH UNINSTALLER 6.30 BUILD 7.EXE" "IDM PATCH UNINSTALLER 6.30 BUILD 7.INI"
"IDMAN.CHM" "IDMAN.EXE" "IDMANTYPEINFO.TLB" "IDMBRBTN.DLL" "IDMBRBTN64.DLL"
[Detected using Heuristic Algorithm] :HKLM MICROSOFT ANALYSIS SERVICES=C:\PROGRAM
FILES (X86)\MICROSOFT ANALYSIS SERVICES\
### "AS OLEDB\" "AS OLEDB\110: DBGHELP.DLL" "MSMDLOCAL.DLL" "MSMGDSRV.DLL"
"MSOLAP110.DLL" "MSOLUI110.DLL" "SQLDUMPER.EXE" "XMSRV.DLL" "AS
OLEDB\110\Cartridges: AS80.XSL" "AS90.XSL" "DB2V0801.XSL" "AS
OLEDB\110\Resources\1033: MSMDSRV.RLL" "MSMDSRVI.RLL" "MSO
[Detected using Heuristic Algorithm] :HKLM MICROSOFT OFFICE=C:\PROGRAM FILES
(X86)\MICROSOFT OFFICE\
### "OFFICE16\" "Office16: APPSHARINGCHROMEHOOK.DLL"
"APPSHARINGHOOKCONTROLLER.EXE" "AUTOHELPER.DLL" "BCSLAUNCH.DLL" "GROOVEEX.DLL"
"IEAWSDC.DLL" "MEETINGJOINAXOC.DLL" "MINSBPROXY.DLL" "MINSBROAMINGPROXY.DLL"
"MSOHEV.DLL"
[Detected using Heuristic Algorithm] :HKLM MICROSOFT SQL SERVER=C:\PROGRAM FILES
(X86)\MICROSOFT SQL SERVER\
### "110\" "110\Shared: MSASXPRESS.DLL"
[Detected using Heuristic Algorithm] :HKLM MICROSOFT.NET=C:\PROGRAM FILES
(X86)\MICROSOFT.NET\
### "ADOMD.NET\" "PRIMARY INTEROP ASSEMBLIES\" "REDISTLIST\" "ADOMD.NET\110:
MICROSOFT.ANALYSISSERVICES.ADOMDCLIENT.DLL" "Primary Interop Assemblies:
ADODB.DLL" "MICROSOFT.MSHTML.DLL" "MICROSOFT.STDFORMAT.DLL" "MSDATASRC.DLL"
"RedistList: ASSEMBLYLIST_4_CLIE
[Detected using Heuristic Algorithm] :HKLM MOZILLA FIREFOX=C:\PROGRAM FILES
(X86)\MOZILLA FIREFOX\
### "PLUGINS\" "plugins: NPMEETINGJOINPLUGINOC.DLL"
[Detected using Heuristic Algorithm] :HKLM REALTEK=C:\PROGRAM FILES
(X86)\REALTEK\
### "REALTEK CARD READER\" "Realtek Card Reader: CONFIG.INI" "DISPLAY.ICO"
"REVCON32.EXE" "REVCON64.EXE" "RICONMAN.EXE" "RMB.EXE" "RMB.LOG" "RSCRLIB.DLL"
"RTSUVSTOR.INF" "RTSUVSTOR.SYS"
[Detected using Heuristic Algorithm] :HKLM SDA=C:\PROGRAM FILES (X86)\SDA\
### "SD FORMATTER\" "SD Formatter: DLL32NT.DLL" "SDFORMATTER.EXE"
"SDFORMATTERCHS.DLL" "SDFORMATTERCHT.DLL" "SDFORMATTERJPN.DLL"
[Detected using Heuristic Algorithm] :HKLM SHAREIT TECHNOLOGIES=C:\PROGRAM FILES
(X86)\SHAREIT TECHNOLOGIES\
### "SHAREIT\" "SHAREit: GALASOFT.MVVMLIGHT.DLL" "GALASOFT.MVVMLIGHT.EXTRAS.DLL"
"GMA.QRCODENET.ENCODING.DLL" "INSTALLUTIL.INSTALLLOG"
"INTEROP.IWSHRUNTIMELIBRARY.DLL" "MICROSOFT.MSHTML.DLL"
"MICROSOFT.PRACTICES.SERVICELOCATION.DLL" "MICROSOFT.WINDOWSAPICODEP
[Detected using Heuristic Algorithm] :HKLM TEMP=C:\PROGRAM FILES (X86)\TEMP\
[Detected using Heuristic Algorithm] :HKLM CCLEANER=C:\PROGRAM FILES\CCLEANER\
### "BRANDING.DLL" "CCLEANER.DAT" "CCLEANER.EXE" "CCLEANER64.EXE" "LANG\"
"UNINST.EXE" "Lang: LANG-1025.DLL" "LANG-1026.DLL" "LANG-1027.DLL" "LANG-1028.DLL"
"LANG-1029.DLL" "LANG-1030.DLL" "LANG-1031.DLL" "LANG-1032.DLL" "LANG-1034.DLL"
"LANG-1035.DLL"
[Detected using Heuristic Algorithm] :HKLM COMMON FILES=C:\PROGRAM FILES\COMMON
FILES\
### "ATHEROS\" "DESIGNER\" "MICROSOFT SHARED\" "QCA_BLUETOOTH\" "SERVICES\"
"SYSTEM\" "Atheros: INSTALLLOG.TXT" "DESIGNER: MSADDNDR.OLB" "microsoft
shared\DW: DBGHELP.DLL" "DW20.EXE" "DWTRIG20.EXE" "microsoft shared\EQUATION\1033:
EEINTL.DLL" "microsoft sha
[Detected using Heuristic Algorithm] :HKLM ATHEROS=C:\PROGRAM FILES\COMMON
FILES\ATHEROS\
### "INSTALLLOG.TXT"
[Detected using Heuristic Algorithm] :HKLM DESIGNER=C:\PROGRAM FILES\COMMON
FILES\DESIGNER\
### "MSADDNDR.OLB"
[Detected using Heuristic Algorithm] :HKLM MICROSOFT SHARED=C:\PROGRAM
FILES\COMMON FILES\MICROSOFT SHARED\
### "DW\" "EQUATION\" "EURO\" "FILTERS\" "GRPHFLT\" "HELP\" "INK\"
"MSCLIENTDATAMGR\" "MSINFO\" "OFFICE16\" "OFFICESOFTWAREPROTECTIONPLATFORM\"
[Detected using Heuristic Algorithm] :HKLM QCA_BLUETOOTH=C:\PROGRAM FILES\COMMON
FILES\QCA_BLUETOOTH\
### "ATHEROSBT.BIN" "ATHRBT_0X01020200.DFU" "ATHRBT_0X01020200_BTUSB.DFU"
"ATHRBT_0X01020200_GA01.DFU" "ATHRBT_0X01020200_SY01.DFU" "ATHRBT_0X01020201.DFU"
"ATHRBT_0X11020000.DFU" "ATHRBT_0X11020000_AC01.DFU" "ATHRBT_0X11020000_SWOI.DFU"
"ATHRBT_0X11020100.DF
[Detected using Heuristic Algorithm] :HKLM SYSTEM=C:\PROGRAM FILES\COMMON
FILES\SYSTEM\
### "ADO\" "EN-US\" "MSADC\" "MSMAPI\" "OLE DB\" "WAB32.DLL" "WAB32RES.DLL"
"ado: ADOJAVAS.INC" "ADOVBS.INC" "MSADER15.DLL" "MSADO15.DLL" "en-US:
WAB32RES.DLL.MUI" "msadc: ADCJAVAS.INC" "ADCVBS.INC" "MSADCE.DLL" "MSADCER.DLL"
"MSMAPI\1033: MSMAPI32.DLL"
[Detected using Heuristic Algorithm] :HKLM INTEL=C:\PROGRAM FILES\INTEL\
### "MEDIA SDK\" "Media SDK: CPA_32.VP" "CPA_64.VP" "C_32.CPA" "C_64.CPA"
"DEV_32.VP" "DEV_64.VP" "HE_32.VP" "HE_64.VP" "LIBMFXHW32.DLL" "LIBMFXHW64.DLL"
[Detected using Heuristic Algorithm] :HKLM MICROSOFT ANALYSIS SERVICES=C:\PROGRAM
FILES\MICROSOFT ANALYSIS SERVICES\
### "AS OLEDB\" "AS OLEDB\110: DBGHELP.DLL" "MSMDLOCAL.DLL" "MSMGDSRV.DLL"
"MSOLAP110.DLL" "MSOLUI110.DLL" "SQLDUMPER.EXE" "XMSRV.DLL" "AS
OLEDB\110\Cartridges: AS80.XSL" "AS90.XSL" "DB2V0801.XSL" "AS
OLEDB\110\Resources\1033: MSMDSRV.RLL" "MSMDSRVI.RLL" "MSO
[Detected using Heuristic Algorithm] :HKLM MICROSOFT OFFICE=C:\PROGRAM
FILES\MICROSOFT OFFICE\
### "CLIPART\" "DOCUMENT THEMES 16\" "OFFICE16\" "STATIONERY\" "TEMPLATES\"
"CLIPART\PUB60COR: AG00004_.GIF" "AG00011_.GIF" "AG00021_.GIF" "AG00037_.GIF"
"CLIPART\Publisher\Backgrounds: J0143743.GIF" "J0143744.GIF" "J0143745.GIF"
"J0143746.GIF" "Document Them
[Detected using Heuristic Algorithm] :HKLM MICROSOFT SQL SERVER=C:\PROGRAM
FILES\MICROSOFT SQL SERVER\
### "110\" "110\Shared: MSASXPRESS.DLL"
[Detected using Heuristic Algorithm] :HKLM MICROSOFT.NET=C:\PROGRAM
FILES\MICROSOFT.NET\
### "ADOMD.NET\" "ADOMD.NET\110: MICROSOFT.ANALYSISSERVICES.ADOMDCLIENT.DLL"
[Detected using Heuristic Algorithm] :HKLM REALTEK=C:\PROGRAM FILES\REALTEK\
### "AUDIO\" "Audio\HDA: AERTSR64.EXE" "BLACKSKINIMAGES64.DLL"
"DARKSKINIMAGES64.DLL" "DTSAUDIOSERVICE64.EXE" "FMAPP.EXE"
"GRAYJADESKINIMAGES64.DLL" "RAVBG64.EXE" "RAVCPL64.EXE" "RTKAUDIOSERVICE64.EXE"
"RTKNGUI64.EXE"
[Detected using Heuristic Algorithm] :HKLM SYNAPTICS=C:\PROGRAM FILES\SYNAPTICS\
### "SYNTP\" "SynTP: DELLTOUCHPAD.EXE" "DELLTOUCHPAD35.EXE" "DELLTPAD.EXE"
"DPINST.EXE" "INSTNT.EXE" "SYNCNTXT.RTF" "SYNISDLL.DLL" "SYNMOOD.EXE"
"SYNREFLASH.EXE" "SYNREMOVEUSERSETTINGS.DAT"
[Detected using Heuristic Algorithm] :HKLM UNINSTALL INFORMATION=C:\PROGRAM
FILES\UNINSTALL INFORMATION\
[Detected using Heuristic Algorithm] :HKLM VIDEOLAN=C:\PROGRAM FILES\VIDEOLAN\
### "VLC\" "VLC: AUTHORS.TXT" "AXVLC.DLL" "COPYING.TXT" "DOCUMENTATION.URL"
"LIBVLC.DLL" "LIBVLCCORE.DLL" "NEWS.TXT" "NEW_SKINS.URL" "NPVLC.DLL" "README.TXT"
[Detected using Heuristic Algorithm] :HKLM WINDOWSAPPS=C:\PROGRAM
FILES\WINDOWSAPPS\
### "DELETED\" "DELETEDALLUSERPACKAGES\"
"MICROSOFT.ADVERTISING.XAML_10.1804.2.0_X64__8WEKYB3D8BBWE\"
"MICROSOFT.ADVERTISING.XAML_10.1807.9.0_X64__8WEKYB3D8BBWE\"
"MICROSOFT.ADVERTISING.XAML_10.1807.9.0_X86__8WEKYB3D8BBWE\"
"MICROSOFT.BINGWEATHER_4.25.12127.0
[Detected using Heuristic Algorithm] :HKLM WINRAR=C:\PROGRAM FILES\WINRAR\
### "7ZXA.DLL" "ACE32LOADER.EXE" "DEFAULT.SFX" "DEFAULT64.SFX" "DESCRIPT.ION"
"LICENSE.TXT" "ORDER.HTM" "RAR.EXE" "RAR.TXT" "RAREXT.DLL" "RAREXT32.DLL"
[Detected using Heuristic Algorithm] :HKLM APPLICATION
DATA=C:\PROGRAMDATA\APPLICATION DATA\
### "APPLICATION DATA\" "AVAST SOFTWARE\" "DELL\" "DESKTOP\" "DOCUMENTS\"
"DP45977C.LFL" "FOXIT CONTENTPLATFORM\" "FOXIT SOFTWARE\" "IDM\" "MICROSOFT\"
"MICROSOFT HELP\"
[Detected using Heuristic Algorithm] :HKLM AVAST SOFTWARE=C:\PROGRAMDATA\AVAST
SOFTWARE\
### "AVAST\" "PERSISTENT DATA\" "Avast: AVAST5.INI" "Persistent Data\Avast\Logs:
EVENT_MANAGER.LOG" "SETUP.LOG"
[Detected using Heuristic Algorithm] :HKLM DELL=C:\PROGRAMDATA\DELL\
### "BLUETOOTH\" "DELLJANUS_INSTALLER.LOG" "DRIVERS\" "INSTALLHELPER.LOG"
"UPDATEPACKAGE\" "drivers\Audio_Driver_21H15_WN32_6.0.1.7520_A00: DELLMUP.EXE"
"MINIUNZ.EXE" "MUP.XML" "PACKAGE.XML" "UpdatePackage\Log:
AUDIO_DRIVER_21H15_WN32_6.0.1.7520_A00.TXT" "AUDI
[Detected using Heuristic Algorithm] :HKLM DESKTOP=C:\PROGRAMDATA\DESKTOP\
### "CCLEANER.LNK" "DESKTOP.INI" "FOXIT READER.LNK" "SDFORMATTER.LNK"
"SHAREIT.LNK" "VLC MEDIA PLAYER.LNK"
[Detected using Heuristic Algorithm] :HKLM DOCUMENTS=C:\PROGRAMDATA\DOCUMENTS\
### "DESKTOP.INI" "MY MUSIC\" "MY PICTURES\" "MY VIDEOS\" "PRE_FILEASSOC.TMP"
"REGRUNINFO\" "My Music: DESKTOP.INI" "My Pictures: DESKTOP.INI" "My Videos:
DESKTOP.INI" "regruninfo: USERINFO.DB"
[Detected using Heuristic Algorithm] :HKLM FOXIT
CONTENTPLATFORM=C:\PROGRAMDATA\FOXIT CONTENTPLATFORM\
### "PROGRESS.INI"
[Detected using Heuristic Algorithm] :HKLM FOXIT SOFTWARE=C:\PROGRAMDATA\FOXIT
SOFTWARE\
### "FOXIT READER\" "Foxit Reader\FoxitConnectPDF: CONNECTPDFLOCALDATABASE.DB"
[Detected using Heuristic Algorithm] :HKLM IDM=C:\PROGRAMDATA\IDM\
[Detected using Heuristic Algorithm] :HKLM MICROSOFT=C:\PROGRAMDATA\MICROSOFT\
### "APPV\" "CRYPTO\" "DEVICE STAGE\" "DEVICESYNC\" "DIAGNOSIS\"
"DIAGNOSTICLOGCSP\" "DRM\" "IDENTITYCRL\" "MAPDATA\" "MF\" "NETFRAMEWORK\"
[Detected using Heuristic Algorithm] :HKLM MICROSOFT
HELP=C:\PROGRAMDATA\MICROSOFT HELP\
### "MS.DATABASECOMPARE.16.1033.HXN" "MS.EXCEL.16.1033.HXN"
"MS.GRAPH.16.1033.HXN" "MS.GROOVE.16.1033.HXN" "MS.LYNC.16.1033.HXN"
"MS.LYNC_BASIC.16.1033.HXN" "MS.LYNC_ONLINE.16.1033.HXN" "MS.MSACCESS.16.1033.HXN"
"MS.MSOUC.16.1033.HXN" "MS.MSPUB.16.1033.HXN" "
[Detected using Heuristic Algorithm] :HKLM MICROSOFT
ONEDRIVE=C:\PROGRAMDATA\MICROSOFT ONEDRIVE\
### "SETUP\" "setup: REFCOUNT.INI"
[Detected using Heuristic Algorithm] :HKLM PACKAGES=C:\PROGRAMDATA\PACKAGES\
### "MICROSOFT.MICROSOFT3DVIEWER_8WEKYB3D8BBWE\"
"MICROSOFT.MICROSOFTOFFICEHUB_8WEKYB3D8BBWE\"
"MICROSOFT.MIXEDREALITY.PORTAL_8WEKYB3D8BBWE\"
[Detected using Heuristic Algorithm] :HKLM REGID.1991-
06.COM.MICROSOFT=C:\PROGRAMDATA\REGID.1991-06.COM.MICROSOFT\
### "REGID.1991-06.COM.MICROSOFT MICROSOFT OFFICE PROFESSIONAL PLUS
2016.SWIDTAG" "REGID.1991-06.COM.MICROSOFT_WINDOWS-10-PRO.SWIDTAG"
[Detected using Heuristic Algorithm] :HKLM REGRUN=C:\PROGRAMDATA\REGRUN\
[Detected using Heuristic Algorithm] :HKLM START MENU=C:\PROGRAMDATA\START MENU\
### "DESKTOP.INI" "PROGRAMS\" "Programs: ACCESS 2016.LNK" "DESKTOP.INI" "EXCEL
2016.LNK" "GOOGLE CHROME.LNK" "IMMERSIVE CONTROL PANEL.LNK" "ONEDRIVE FOR
BUSINESS.LNK" "ONENOTE 2016.LNK" "OUTLOOK 2016.LNK" "POWERPOINT 2016.LNK"
"PUBLISHER 2016.LNK"
[Detected using Heuristic Algorithm] :HKLM TEMPLATES=C:\PROGRAMDATA\TEMPLATES\
[Detected using Heuristic Algorithm] :HKLM USOPRIVATE=C:\PROGRAMDATA\USOPRIVATE\
### "UPDATESTORE\" "UpdateStore: UPDATECSPSTORE.XML" "UPDATESTORE51B519D5-B6F5-
4333-8DF6-E74D7C9AEAD4.XML"
[Detected using Heuristic Algorithm] :HKLM USOSHARED=C:\PROGRAMDATA\USOSHARED\
### "LOGS\" "Logs: NOTIFICATIONUXBROKER_TEMP.1.ETL" "NOTIFICATIONUX_TEMP.1.ETL"
"UPDATESESSIONORCHESTRATION.001.ETL" "UPDATESESSIONORCHESTRATION.002.ETL"
"UPDATESESSIONORCHESTRATION.003.ETL" "UPDATESESSIONORCHESTRATION.004.ETL"
"UPDATESESSIONORCHESTRATION.005
[Detected using Heuristic Algorithm] :HKLM 3D OBJECTS=C:\USERS\SUKAN\3D OBJECTS\
### "DESKTOP.INI"
[Detected using Heuristic Algorithm] :HKLM APPDATA=C:\USERS\SUKAN\APPDATA\
### "LOCAL\" "LOCALLOW\" "ROAMING\" "Local: ICONCACHE.DB" "Local\Application
Data: ICONCACHE.DB" "Local\Application Data\Application Data: ICONCACHE.DB"
"Local\Application Data\Comms\Unistore\data: AGGREGATECACHE.UCA"
"Local\Application Data\Comms\UnistoreDB
[Detected using Heuristic Algorithm] :HKLM APPLICATION
DATA=C:\USERS\SUKAN\APPDATA\LOCAL\APPLICATION DATA\
### "APPLICATION DATA\" "COMMS\" "CONNECTEDDEVICESPLATFORM\" "DBG\"
"DIAGNOSTICS\" "DOWNLOADED INSTALLATIONS\" "ELEVATEDDIAGNOSTICS\" "GOOGLE\"
"HISTORY\" "ICONCACHE.DB" "MICROSOFT\"
[Detected using Heuristic Algorithm] :HKLM
COMMS=C:\USERS\SUKAN\APPDATA\LOCAL\COMMS\
### "UNISTORE\" "UNISTOREDB\" "Unistore\data: AGGREGATECACHE.UCA" "UnistoreDB:
STORE.JFM" "STORE.VOL" "TMP.EDB" "USS.JCP" "USS.JTX" "USSRES00001.JRS"
[Detected using Heuristic Algorithm] :HKLM
CONNECTEDDEVICESPLATFORM=C:\USERS\SUKAN\APPDATA\LOCAL\CONNECTEDDEVICESPLATFORM\
### "789CA16778779BDA\" "789CA16778779BDA.CDP" "789CA16778779BDA.CDPRESOURCE"
"CDPGLOBALSETTINGS.CDP" "CONNECTED DEVICES PLATFORM CERTIFICATES.SST"
"L.SUKAN.CDPRESOURCE" "789ca16778779bda: ACTIVITIESCACHE.DB" "ACTIVITIESCACHE.DB-
SHM" "ACTIVITIESCACHE.DB-WAL"
[Detected using Heuristic Algorithm] :HKLM DBG=C:\USERS\SUKAN\APPDATA\LOCAL\DBG\
[Detected using Heuristic Algorithm] :HKLM
DIAGNOSTICS=C:\USERS\SUKAN\APPDATA\LOCAL\DIAGNOSTICS\
### "460911090\" "460911090: LATEST.CAB" "460911090\2018101311.000:
NETWORKDIAGNOSTICS.DEBUGREPORT.XML" "RESULTREPORT.XML" "RESULTS.XML" "RESULTS.XSL"
[Detected using Heuristic Algorithm] :HKLM DOWNLOADED
INSTALLATIONS=C:\USERS\SUKAN\APPDATA\LOCAL\DOWNLOADED INSTALLATIONS\
### "{5D501D62-F028-4C06-A9FF-CB3356EFA62D}\" "{5D501D62-F028-4C06-A9FF-
CB3356EFA62D}: 1033.MST" "SDFORMATTER.MSI"
[Detected using Heuristic Algorithm] :HKLM
ELEVATEDDIAGNOSTICS=C:\USERS\SUKAN\APPDATA\LOCAL\ELEVATEDDIAGNOSTICS\
### "2974208707\" "2974208707: LATEST.CAB" "2974208707\2018101311.000:
KEYBOARDDIAGNOSTIC.DEBUGREPORT.XML" "RESULTREPORT.XML" "RESULTS.XML" "RESULTS.XSL"
[Detected using Heuristic Algorithm] :HKLM
GOOGLE=C:\USERS\SUKAN\APPDATA\LOCAL\GOOGLE\
### "CHROME\" "CRASHREPORTS\" "Chrome\User Data: BROWSERMETRICS-SPARE.PMA"
"CHROME_SHUTDOWN_MS.TXT" "CRASHPADMETRICS-ACTIVE.PMA" "CRASHPADMETRICS.PMA" "EN-GB-
8-0.BDIC" "FIRST RUN"
[Detected using Heuristic Algorithm] :HKLM
HISTORY=C:\USERS\SUKAN\APPDATA\LOCAL\HISTORY\
### "DESKTOP.INI" "HISTORY.IE5\" "History.IE5: CONTAINER.DAT"
"History.IE5\MSHist012018100820181015: CONTAINER.DAT"
"History.IE5\MSHist012018101720181018: CONTAINER.DAT"
[Detected using Heuristic Algorithm] :HKLM
MICROSOFT=C:\USERS\SUKAN\APPDATA\LOCAL\MICROSOFT\
### "CLR_V2.0\" "CLR_V4.0\" "CLR_V4.0_32\" "CREDENTIALS\" "FEEDS\" "FEEDS
CACHE\" "GAMEDVR\" "INPUT\" "INPUTPERSONALIZATION\" "INTERNET EXPLORER\" "MEDIA
PLAYER\"
[Detected using Heuristic Algorithm] :HKLM MICROSOFT
HELP=C:\USERS\SUKAN\APPDATA\LOCAL\MICROSOFT HELP\
[Detected using Heuristic Algorithm] :HKLM
MICROSOFTEDGE=C:\USERS\SUKAN\APPDATA\LOCAL\MICROSOFTEDGE\
### "SHAREDCACHECONTAINERS\" "USER\"
"SharedCacheContainers\MicrosoftEdge_DNTException: CONTAINER.DAT"
"SharedCacheContainers\MicrosoftEdge_EmieSiteList: CONTAINER.DAT"
"SharedCacheContainers\MicrosoftEdge_EmieUserList: CONTAINER.DAT"
"SharedCacheContainers
[Detected using Heuristic Algorithm] :HKLM MSFREE
INC=C:\USERS\SUKAN\APPDATA\LOCAL\MSFREE INC\
### "KMSAUTO.INI"
[Detected using Heuristic Algorithm] :HKLM
PACKAGES=C:\USERS\SUKAN\APPDATA\LOCAL\PACKAGES\
### "1527C705-839A-4832-9118-54D4BD6A0C89_CW5N1H2TXYEWY\" "ACTIVESYNC\"
"C5E2524A-EA46-4F67-841F-6A9465D9D515_CW5N1H2TXYEWY\" "E2A4F912-2574-4A75-9BB0-
0D023378592B_CW5N1H2TXYEWY\" "F46D4000-FD22-4DB4-AC8E-4E1DDDE828FE_CW5N1H2TXYEWY\"
"INPUTAPP_CW5N1H2TXYEWY\"
[Detected using Heuristic Algorithm] :HKLM
PACKAGESTAGING=C:\USERS\SUKAN\APPDATA\LOCAL\PACKAGESTAGING\
[Detected using Heuristic Algorithm] :HKLM
PEERDISTREPUB=C:\USERS\SUKAN\APPDATA\LOCAL\PEERDISTREPUB\
[Detected using Heuristic Algorithm] :HKLM
PLACEHOLDERTILELOGOFOLDER=C:\USERS\SUKAN\APPDATA\LOCAL\PLACEHOLDERTILELOGOFOLDER\
### "9N0866FS04W8\" "9NBLGGH18846\" "9NBLGGH1ZRPV\" "9N0866FS04W8: 044X044.PNG"
"300X300.PNG" "310X150.PNG" "9NBLGGH18846: 044X044.PNG" "300X300.PNG"
"310X150.PNG" "9NBLGGH1ZRPV: 044X044.PNG" "300X300.PNG" "310X150.PNG"
[Detected using Heuristic Algorithm] :HKLM
PROGRAMS=C:\USERS\SUKAN\APPDATA\LOCAL\PROGRAMS\
### "COMMON\"
[Detected using Heuristic Algorithm] :HKLM
PUBLISHERS=C:\USERS\SUKAN\APPDATA\LOCAL\PUBLISHERS\
### "8WEKYB3D8BBWE\"
[Detected using Heuristic Algorithm] :HKLM SHAREIT
TECHNOLOGIES=C:\USERS\SUKAN\APPDATA\LOCAL\SHAREIT TECHNOLOGIES\
### "SHAREIT\" "SHAREit: BUDDY.DB" "SETTING.XML" "SHAREit\Avatar:
LENOVO_REAPER.DB7" "REAPER.LOG" "SERVER_CONFIG.JSON" "SHAREit\beyla:
181017195209035.BLA" "SHAREit\Log: 2018-10-13.LOG" "2018-10-17.LOG"
"SHAREit\Updater: 2018-10-17.LOG" "SHAREITSUBSCRIPTIO
[Detected using Heuristic Algorithm] :HKLM
SPEECH=C:\USERS\SUKAN\APPDATA\LOCAL\SPEECH\
### "MICROSOFT\" "Microsoft\Speech\Files\UserLexicons:
SP_94992F3B486847B3B67A680DC9145856.DAT"
[Detected using Heuristic Algorithm] :HKLM
TEMP=C:\USERS\SUKAN\APPDATA\LOCAL\TEMP\
### "%%%A666.TMP" "324609\" "8283DB39-CFF8-4D76-A21E-4433EFB17080.TMP"
"A40CF573-1E00-4815-BDBF-5E4663C7D4C6.TMP" "ACTIVITYVISUALCACHE\" "ARIA-DEBUG-
7256.LOG" "ARIA-DEBUG-8956.LOG" "BITA32.TMP" "CE4CF87733651BF1F44DD1E02FC1A8E8"
"CHROME_INSTALLER.LOG" "CR_DB2
[Detected using Heuristic Algorithm] :HKLM TEMPORARY INTERNET
FILES=C:\USERS\SUKAN\APPDATA\LOCAL\TEMPORARY INTERNET FILES\
### "CONTENT.IE5\" "CONTENT.MSO\" "CONTENT.WORD\" "IE\" "LOW\" "VIRTUALIZED\"
"Content.IE5: CONTAINER.DAT" "Content.IE5\1TA6I5EX: COLLAPSE[1]"
"Content.IE5\D1D3T60M: SETTINGS-TIPSET[1].XML" "SETTINGS-TIPSET[2].XML"
"Content.IE5\E6BUC2O6: EXPAND[1]" "PRINT[1
[Detected using Heuristic Algorithm] :HKLM
VIRTUALSTORE=C:\USERS\SUKAN\APPDATA\LOCAL\VIRTUALSTORE\
[Detected using Heuristic Algorithm] :HKLM
MICROSOFT=C:\USERS\SUKAN\APPDATA\LOCALLOW\MICROSOFT\
### "CRYPTNETURLCACHE\" "CryptnetUrlCache\Content:
0DA515F703BB9B49479E8697ADB0B955_7DC3E633EDFAEFC3AA3C99552548EC2F"
"1E11E75149C17A93653DA7DC0B8CF53F_1A1094451483DE2533F9DC37363240D2"
"50D6B15D9F2DCE1EDBB0C098625FBE47_281AC807DE0FEF15F2CA9911FE760A9B" "57C8E
[Detected using Heuristic Algorithm] :HKLM
ADOBE=C:\USERS\SUKAN\APPDATA\ROAMING\ADOBE\
### "FLASH PLAYER\"
[Detected using Heuristic Algorithm] :HKLM
DMCACHE=C:\USERS\SUKAN\APPDATA\ROAMING\DMCACHE\
### "SETTINGS.BAK"
[Detected using Heuristic Algorithm] :HKLM FOXIT
AGENTINFORMATION=C:\USERS\SUKAN\APPDATA\ROAMING\FOXIT AGENTINFORMATION\
### "AGENT.TXT"
[Detected using Heuristic Algorithm] :HKLM FOXIT
SOFTWARE=C:\USERS\SUKAN\APPDATA\ROAMING\FOXIT SOFTWARE\
### "ADDON\" "CERTFILE\" "FOXIT PDF CREATOR\" "FOXIT READER\" "Addon\Foxit
Reader: FOXITREADERUPDATER.EXE" "CertFile: TSFILE.FOXITDATA" "Foxit PDF
Creator\Foxit Reader PDF Printer: 1539411965_2704__FOXITTEMP.XML"
"FOXITPRINTERPROFILE.XML" "Foxit Reader: COLLE
[Detected using Heuristic Algorithm] :HKLM
GOOGLE=C:\USERS\SUKAN\APPDATA\ROAMING\GOOGLE\
### "CHROME\"
[Detected using Heuristic Algorithm] :HKLM
IDM=C:\USERS\SUKAN\APPDATA\ROAMING\IDM\
### "DEFEXTMAP.DAT" "DWNLDATA\" "FOLDRESHISTORY.TXT" "GRABBER\" "IDMMZCC5\"
"SCHEDULER\" "URLEXCLIST.DAT" "idmmzcc5: CHROME.MANIFEST" "ICON.PNG" "INSTALL.JS"
"INSTALL.RDF" "Scheduler: Q_1.DT" "S_1.DT"
[Detected using Heuristic Algorithm] :HKLM
MICROSOFT=C:\USERS\SUKAN\APPDATA\ROAMING\MICROSOFT\
### "ADDINS\" "BIBLIOGRAPHY\" "CREDENTIALS\" "CRYPTO\" "DOCUMENT BUILDING
BLOCKS\" "INPUTMETHOD\" "INTERNET EXPLORER\" "MMC\" "NETWORK\" "OFFICE\" "PROOF\"
[Detected using Heuristic Algorithm] :HKLM
UMENG=C:\USERS\SUKAN\APPDATA\ROAMING\UMENG\
### "746FD727857C9DC88927B4185E1C331E\" "746FD727857C9DC88927B4185E1C331E:
4_0_6" "UMENGSETTINGS.XML"
[Detected using Heuristic Algorithm] :HKLM
VLC=C:\USERS\SUKAN\APPDATA\ROAMING\VLC\
### "ML.XSPF" "VLC-QT-INTERFACE.INI" "VLCRC"
[Detected using Heuristic Algorithm] :HKLM
WINRAR=C:\USERS\SUKAN\APPDATA\ROAMING\WINRAR\
### "VERSION.DAT"
[Detected using Heuristic Algorithm] :HKLM APPLICATION
DATA=C:\USERS\SUKAN\APPLICATION DATA\
### "ADOBE\" "DMCACHE\" "FOXIT AGENTINFORMATION\" "FOXIT SOFTWARE\" "GOOGLE\"
"IDM\" "MICROSOFT\" "UMENG\" "VLC\" "WINRAR\"
[Detected using Heuristic Algorithm] :HKLM CONTACTS=C:\USERS\SUKAN\CONTACTS\
### "DESKTOP.INI"
[Detected using Heuristic Algorithm] :HKLM COOKIES=C:\USERS\SUKAN\COOKIES\
### "CONTAINER.DAT" "DNTEXCEPTION\" "ESE\" "LOW\" "PRIVACIE\" "ESE:
CONTAINER.DAT"
[Detected using Heuristic Algorithm] :HKLM DESKTOP=C:\USERS\SUKAN\DESKTOP\
### "DESKTOP.INI" "INTERNET DOWNLOAD MANAGER.LNK" "MICROSOFT EDGE.LNK"
"UNHACKME.LNK"
[Detected using Heuristic Algorithm] :HKLM DOCUMENTS=C:\USERS\SUKAN\DOCUMENTS\
### "DESKTOP.INI" "MY MUSIC\" "MY PICTURES\" "MY VIDEOS\" "REGRUN2\" "My Music:
DESKTOP.INI" "My Pictures: DESKTOP.INI" "My Pictures\Camera Roll: DESKTOP.INI"
"My Pictures\Saved Pictures: DESKTOP.INI" "My Videos: DESKTOP.INI" "My
Videos\Captures: DESKTOP.I
[Detected using Heuristic Algorithm] :HKLM DOWNLOADS=C:\USERS\SUKAN\DOWNLOADS\
### "COMPRESSED\" "DESKTOP.INI" "DOCUMENTS\" "MUSIC\" "PROGRAMS\" "SHAREIT\"
"VIDEO\" "Compressed: SD-CARD-FORMATTER-4-0-EN-WIN.ZIP"
"Compressed\1111111111111111111111111111111111: SETUP.EXE"
"Compressed\1111111111111111111111111111111111\__MACOSX: ._SETUP.EX
[Detected using Heuristic Algorithm] :HKLM FAVORITES=C:\USERS\SUKAN\FAVORITES\
### "BING.URL" "DESKTOP.INI" "LINKS\" "Links: DESKTOP.INI"
[Detected using Heuristic Algorithm] :HKLM
INTELGRAPHICSPROFILES=C:\USERS\SUKAN\INTELGRAPHICSPROFILES\
### "BRIGHTEN VIDEO.MAN.IGPI" "DARKEN VIDEO.MAN.IGPI" "ENHANCE VIDEO
COLORS.MAN.IGPI"
[Detected using Heuristic Algorithm] :HKLM LINKS=C:\USERS\SUKAN\LINKS\
### "DESKTOP.INI" "DESKTOP.LNK" "DOWNLOADS.LNK"
[Detected using Heuristic Algorithm] :HKLM LOCAL SETTINGS=C:\USERS\SUKAN\LOCAL
SETTINGS\
### "APPLICATION DATA\" "COMMS\" "CONNECTEDDEVICESPLATFORM\" "DBG\"
"DIAGNOSTICS\" "DOWNLOADED INSTALLATIONS\" "ELEVATEDDIAGNOSTICS\" "GOOGLE\"
"HISTORY\" "ICONCACHE.DB" "MICROSOFT\"
[Detected using Heuristic Algorithm] :HKLM
MICROSOFTEDGEBACKUPS=C:\USERS\SUKAN\MICROSOFTEDGEBACKUPS\
### "BACKUPS\" "backups\MicrosoftEdgeBackup20181013:
MICROSOFTEDGECOOKIESBACKUP.DAT" "MICROSOFTEDGESETTINGSBACKUP.TXT"
"backups\MicrosoftEdgeBackup20181013\DatastoreBackup: EDB00001.LOG" "SCHEMA.TXT"
"SPARTAN.EDB" "SPARTAN.PAT" "backups\MicrosoftEdgeBackup20
[Detected using Heuristic Algorithm] :HKLM MUSIC=C:\USERS\SUKAN\MUSIC\
### "DESKTOP.INI"
[Detected using Heuristic Algorithm] :HKLM MY DOCUMENTS=C:\USERS\SUKAN\MY
DOCUMENTS\
### "DESKTOP.INI" "MY MUSIC\" "MY PICTURES\" "MY VIDEOS\" "REGRUN2\" "My Music:
DESKTOP.INI" "My Pictures: DESKTOP.INI" "My Pictures\Camera Roll: DESKTOP.INI"
"My Pictures\Saved Pictures: DESKTOP.INI" "My Videos: DESKTOP.INI" "My
Videos\Captures: DESKTOP.I
[Detected using Heuristic Algorithm] :HKLM NETHOOD=C:\USERS\SUKAN\NETHOOD\
[Detected using Heuristic Algorithm] :HKLM ONEDRIVE=C:\USERS\SUKAN\ONEDRIVE\
### ".849C9593-D756-4E56-8D6E-42412F2A707B" "DESKTOP.INI" "DOCUMENTS\"
"DSC_72945.JPG" "EMAIL ATTACHMENTS\" "GETTING STARTED WITH ONEDRIVE.PDF" "MUSIC\"
"PICTURES\" "SONG\" "Documents: BOOK (1).XLSX" "BOOK.XLSX" "DOCUMENT.DOCX"
"INTRODUCTION.DOCX" "Pictures\C
[Detected using Heuristic Algorithm] :HKLM PICTURES=C:\USERS\SUKAN\PICTURES\
### "CAMERA ROLL\" "DESKTOP.INI" "SAVED PICTURES\" "Camera Roll: DESKTOP.INI"
"Saved Pictures: DESKTOP.INI"
[Detected using Heuristic Algorithm] :HKLM PRINTHOOD=C:\USERS\SUKAN\PRINTHOOD\
[Detected using Heuristic Algorithm] :HKLM RECENT=C:\USERS\SUKAN\RECENT\
### "2016_ROSSO_MARS_NOVARA_EDIZIONE_LAMBORGHINI_HURACAN-WALLPAPER-1366X768.LNK"
"29.10.17.LNK" "ALL TASKS.LNK" "AUTOMATICDESTINATIONS\" "CHANGE HOW YOUR KEYBOARD
WORKS.LNK" "CUSTOMDESTINATIONS\" "DESKTOP.INI" "DOCUMENTS.LNK" "DOWNLODS.LNK"
"DSC_0302.LNK" "DS
[Detected using Heuristic Algorithm] :HKLM SAVED GAMES=C:\USERS\SUKAN\SAVED
GAMES\
### "DESKTOP.INI"
[Detected using Heuristic Algorithm] :HKLM SEARCHES=C:\USERS\SUKAN\SEARCHES\
### "DESKTOP.INI" "EVERYWHERE.SEARCH-MS" "INDEXED LOCATIONS.SEARCH-MS" "WINRT--
{S-1-5-21-67703685-4255488207-1546581969-1001}-.SEARCHCONNECTOR-MS"
[Detected using Heuristic Algorithm] :HKLM SENDTO=C:\USERS\SUKAN\SENDTO\
### "BLUETOOTH FILE TRANSFER.LNK" "COMPRESSED (ZIPPED) FOLDER.ZFSENDTOTARGET"
"DESKTOP (CREATE SHORTCUT).DESKLINK" "DESKTOP.INI" "DOCUMENTS.MYDOCS" "FAX
RECIPIENT.LNK" "MAIL RECIPIENT.MAPIMAIL"
[Detected using Heuristic Algorithm] :HKLM START MENU=C:\USERS\SUKAN\START MENU\
### "DESKTOP.INI" "PROGRAMS\" "Programs: DESKTOP.INI" "ONEDRIVE.LNK"
"Programs\Accessibility: DESKTOP.INI" "MAGNIFY.LNK" "NARRATOR.LNK" "ON-SCREEN
KEYBOARD.LNK" "Programs\Accessories: DESKTOP.INI" "INTERNET EXPLORER.LNK"
"NOTEPAD.LNK" "Programs\Administrati
[Detected using Heuristic Algorithm] :HKLM TEMPLATES=C:\USERS\SUKAN\TEMPLATES\
[Detected using Heuristic Algorithm] :HKLM VIDEOS=C:\USERS\SUKAN\VIDEOS\
### "CAPTURES\" "DESKTOP.INI" "Captures: DESKTOP.INI"
[In memory]
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\LSASS.EXE
### Local Security Authority Process Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*C:\Windows\system32\lsass.exe
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*C:\Windows\system32\svchost.exe -k DcomLaunch -p
-s PlugPlay
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\FONTDRVHOST.EXE
### Usermode Font Driver Host Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*"fontdrvhost.exe"
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*C:\Windows\system32\svchost.exe -k DcomLaunch -p
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*C:\Windows\system32\svchost.exe -k RPCSS -p
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*C:\Windows\system32\svchost.exe -k DcomLaunch -p
-s LSM
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*C:\Windows\system32\svchost.exe -k netsvcs -p -s
DsmSvc
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*C:\Windows\System32\svchost.exe -k
LocalSystemNetworkRestricted -p -s NcbService
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*C:\Windows\system32\svchost.exe -k netsvcs -p -s
Schedule
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*C:\Windows\system32\svchost.exe -k netsvcs -p -s
ProfSvc
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*C:\Windows\system32\svchost.exe -k
LocalSystemNetworkRestricted -p -s DisplayEnhancementService
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*C:\Windows\system32\svchost.exe -k netsvcs -p -s
UserManager
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*C:\Windows\system32\svchost.exe -k
LocalServiceNetworkRestricted -p -s TimeBrokerSvc
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*C:\Windows\System32\svchost.exe -k
LocalServiceNetworkRestricted -p -s EventLog
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*C:\Windows\system32\svchost.exe -k LocalService
-p -s nsi
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*C:\Windows\system32\svchost.exe -k LocalService
-p -s EventSystem
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*C:\Windows\system32\svchost.exe -k
LocalSystemNetworkRestricted -p -s SysMain
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*C:\Windows\System32\svchost.exe -k netsvcs -p -s
Themes
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*C:\Windows\system32\svchost.exe -k
LocalServiceNetworkRestricted -p -s Dhcp
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*C:\Windows\system32\svchost.exe -k netsvcs -p -s
SENS
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*C:\Windows\system32\svchost.exe -k netsvcs -p -s
lfsvc
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\WUDFHOST.EXE
### Windows Driver Foundation - User-mode Driver Framework Host Process Microsoft
Corporation Microsoft� Windows� Operating System 10.0.17763.1 !
$*"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-
be817523f6aa} -IoEventPortName:\UMDFCommunicationPorts\WUDF\HostProcess-bdf760e3-
8998-4703-97a3-8a02a98f8e3b
-SystemEventPortName:\UMDFCommunicationPorts\WUDF\HostProcess-e010dba4-49c2-406a-
87c2-6692fd6e311c -IoCancelEventPortName:\UMDFCommunicationPorts\WUDF\HostProcess-
a87c0a82-4d45-4e21-8ab2-77db74c7853e
-NonStateChangingEventPortName:\UMDFCommunicationPorts\WUDF\HostProcess-bebd5536-
11ff-4d59-924d-297847670ba8 -LifetimeId:a1b8d2a3-3e4c-446c-bde6-6f4b0a809e14
-DeviceGroupId:WpdFsGroup -HostArg:0
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*C:\Windows\System32\svchost.exe -k NetworkService
-p -s NlaSvc
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*C:\Windows\system32\svchost.exe -k appmodel -p -s
StateRepository
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*C:\Windows\system32\svchost.exe -k appmodel -p -s
camsvc
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\IGFXCUISERVICE.EXE
### igfxCUIService Module Intel Corporation Intel(R) Common User Interface
6.15.10.4252 !$*C:\Windows\system32\igfxCUIService.exe
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*C:\Windows\System32\svchost.exe -k
LocalSystemNetworkRestricted -p -s AudioEndpointBuilder
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*C:\Windows\system32\svchost.exe -k LocalService
-p -s FontCache
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*C:\Windows\System32\svchost.exe -k LocalService
-p -s netprofm
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*C:\Windows\system32\svchost.exe -k netsvcs -p -s
wlidsvc
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*C:\Windows\system32\svchost.exe -k
LocalServiceNoNetwork -p
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*C:\Windows\system32\svchost.exe -k LocalService
-p
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*C:\Windows\System32\svchost.exe -k
LocalServiceNetworkRestricted -p
[Running Processes] :HKLM C:\PROGRAM
FILES\REALTEK\AUDIO\HDA\RTKAUDIOSERVICE64.EXE
### Realtek Audio Service Realtek Semiconductor Realtek Audio Service 1, 0, 0, 66
!$*"C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe"
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*C:\Windows\system32\svchost.exe -k NetworkService
-p -s Dnscache
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*C:\Windows\System32\svchost.exe -k
LocalServiceNetworkRestricted -p
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*C:\Windows\system32\svchost.exe -k
LocalServiceNetworkRestricted -p
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*C:\Windows\system32\svchost.exe -k
LocalServiceNetworkRestricted -p -s WinHttpAutoProxySvc
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*C:\Windows\system32\svchost.exe -k
LocalSystemNetworkRestricted -p
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*C:\Windows\System32\svchost.exe -k netsvcs -p -s
ShellHWDetection
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\WLANEXT.EXE
### Windows Wireless LAN 802.11 Extensibility Framework Microsoft Corporation
Microsoft� Windows� Operating System 10.0.17763.1 !
$*C:\Windows\system32\WLANExt.exe 1892325742416
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\CONHOST.EXE
### Console Window Host Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*\??\C:\Windows\system32\conhost.exe 0x4
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SPOOLSV.EXE
### Spooler SubSystem App Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*C:\Windows\System32\spoolsv.exe
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*C:\Windows\system32\svchost.exe -k
LocalServiceNoNetworkFirewall -p
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*C:\Windows\System32\svchost.exe -k NetworkService
-p -s LanmanWorkstation
[Running Processes] :HKLM C:\PROGRAM FILES (X86)\DELL WIRELESS\BLUETOOTH
SUITE\ADMINSERVICE.EXE
### Windows Setup API Windows (R) Win 7 DDK provider Windows (R) Win 7 DDK driver
6.2.9200.16384 !$*"C:\Program Files (x86)\Dell Wireless\Bluetooth
Suite\adminservice.exe"
[Running Processes] :HKLM C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\FOXIT
READER\FOXITCONNECTEDPDFSERVICE.EXE
### Foxit Reader ConnectedPDF Windows Service. Foxit Software Inc. Foxit
ConnectedPDF Windows Service. 8.2.0.1206 !$*"C:\Program Files (x86)\Foxit
Software\Foxit Reader\FoxitConnectedPDFService.exe"
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*C:\Windows\system32\svchost.exe -k NetworkService
-p -s CryptSvc
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*C:\Windows\System32\svchost.exe -k
LocalServiceNoNetwork -p -s DPS
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*C:\Windows\System32\svchost.exe -k utcsvc -p
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*C:\Windows\system32\svchost.exe -k netsvcs -p -s
Winmgmt
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*C:\Windows\system32\svchost.exe -k LocalService
-p -s SstpSvc
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*C:\Windows\System32\svchost.exe -k
LocalSystemNetworkRestricted -p -s TrkWks
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*C:\Windows\system32\svchost.exe -k netsvcs -p -s
WpnService
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*C:\Windows\system32\svchost.exe -k netsvcs -p -s
LanmanServer
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*C:\Windows\System32\svchost.exe -k NetSvcs -p -s
iphlpsvc
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*C:\Windows\System32\svchost.exe -k LocalService
-p -s WdiServiceHost
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*C:\Windows\System32\svchost.exe -k netsvcs
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*C:\Windows\system32\svchost.exe -k
LocalSystemNetworkRestricted -p -s DeviceAssociationService
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\AUDIODG.EXE
### Windows Audio Device Graph Isolation Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 !$*C:\Windows\system32\AUDIODG.EXE 0x4ec
[Running Processes] :HKLM
C:\WINDOWS\MICROSOFT.NET\FRAMEWORK64\V3.0\WPF\PRESENTATIONFONTCACHE.EXE
### PresentationFontCache.exe Microsoft Corporation Microsoft� .NET Framework
3.0.6920.9034 !
$*C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*C:\Windows\system32\svchost.exe -k netsvcs -p -s
TokenBroker
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*C:\Windows\System32\svchost.exe -k
LocalSystemNetworkRestricted -p -s TabletInputService
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*C:\Windows\System32\svchost.exe -k
LocalSystemNetworkRestricted -p -s WdiSystemHost
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*C:\Windows\system32\svchost.exe -k
LocalServiceNetworkRestricted -p -s NgcCtnrSvc
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*C:\Windows\system32\svchost.exe -k LocalService
-p -s CDPSvc
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SEARCHINDEXER.EXE
### Microsoft Windows Search Indexer Microsoft Corporation Windows� Search
7.0.17763.1 !$*C:\Windows\system32\SearchIndexer.exe /Embedding
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*C:\Windows\system32\svchost.exe -k
LocalSystemNetworkRestricted -p -s PcaSvc
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*C:\Windows\system32\svchost.exe -k netsvcs -p -s
Appinfo
[Running Processes] :HKLM C:\PROGRAM FILES
(X86)\GOOGLE\UPDATE\1.3.33.17\GOOGLECRASHHANDLER.EXE
### Google Crash Handler Google Inc. Google Update 1.3.33.17 !$*"C:\Program
Files (x86)\Google\Update\1.3.33.17\GoogleCrashHandler.exe"
[Running Processes] :HKLM C:\PROGRAM FILES
(X86)\GOOGLE\UPDATE\1.3.33.17\GOOGLECRASHHANDLER64.EXE
### Google Crash Handler Google Inc. Google Update 1.3.33.17 !$*"C:\Program
Files (x86)\Google\Update\1.3.33.17\GoogleCrashHandler64.exe"
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*C:\Windows\system32\svchost.exe -k
LocalServiceAndNoImpersonation -p -s SSDPSRV
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\WBEM\WMIPRVSE.EXE
### WMI Provider Host Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*C:\Windows\system32\wbem\wmiprvse.exe
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*C:\Windows\System32\svchost.exe -k
LocalSystemNetworkRestricted -p -s StorSvc
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*C:\Windows\System32\svchost.exe -k LocalService
-p -s LicenseManager
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*C:\Windows\system32\svchost.exe -k netsvcs -p -s
UsoSvc
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\WINLOGON.EXE
### Windows Logon Application Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*C:\Windows\System32\WinLogon.exe -SpecialSession
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\FONTDRVHOST.EXE
### Usermode Font Driver Host Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*"fontdrvhost.exe"
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\DWM.EXE
### Desktop Window Manager Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*"dwm.exe"
[Running Processes] :HKLM C:\PROGRAM FILES\REALTEK\AUDIO\HDA\RAVBG64.EXE
### HD Audio Background Process Realtek Semiconductor HD Audio Background Process
1, 0, 0, 220 !$*"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /SRSPS
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SIHOST.EXE
### Shell Infrastructure Host Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*sihost.exe
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*C:\Windows\system32\svchost.exe -k
UnistackSvcGroup -s CDPUserSvc
[Running Processes] :HKLM C:\PROGRAM FILES\REALTEK\AUDIO\HDA\RAVBG64.EXE
### HD Audio Background Process Realtek Semiconductor HD Audio Background Process
1, 0, 0, 220 !$*"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /SENDINPUT
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*C:\Windows\system32\svchost.exe -k
UnistackSvcGroup -s WpnUserService
[Running Processes] :HKLM C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPENH.EXE
### Synaptics TouchPad 64-bit Enhancements Synaptics Incorporated Synaptics
Pointing Device Driver 19.0.9.4 27May15 !$*"C:\Program
Files\Synaptics\SynTP\SynTPEnh.exe"
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\TASKHOSTW.EXE
### Host Process for Windows Tasks Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*taskhostw.exe {222A245B-E637-4AE9-A93F-
A59CA119A75E}
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*C:\Windows\system32\svchost.exe -k
LocalSystemNetworkRestricted -p -s NgcSvc
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\IGFXEM.EXE
### igfxEM Module Intel Corporation Intel(R) Common User Interface
6.15.10.4252 !$*"C:\Windows\system32\igfxEM.exe"
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*C:\Windows\system32\svchost.exe -k
ClipboardSvcGroup -p -s cbdhsvc
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\IGFXHK.EXE
### igfxHK Module Intel Corporation Intel(R) Common User Interface
6.15.10.4252 !$*"C:\Windows\system32\igfxHK.exe"
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\IGFXTRAY.EXE
### igfxTray Module Intel Corporation Intel(R) Common User Interface 6.15.10.4252
!$*"C:\Windows\system32\igfxTray.exe"
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\CTFMON.EXE
### CTF Loader Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*"ctfmon.exe"
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\RUNTIMEBROKER.EXE
### Runtime Broker Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*C:\Windows\System32\RuntimeBroker.exe -Embedding
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\RUNTIMEBROKER.EXE
### Runtime Broker Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*C:\Windows\System32\RuntimeBroker.exe -Embedding
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SETTINGSYNCHOST.EXE
### Host Process for Setting Synchronization Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1 !$*C:\Windows\system32\SettingSyncHost.exe
-Embedding
[Running Processes] :HKLM
C:\WINDOWS\SYSTEMAPPS\MICROSOFT.WINDOWS.CORTANA_CW5N1H2TXYEWY\REMINDERSSERVER.EXE
### Reminders WinRT OOP Server Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !
$*"C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersServer.ex
e" -ServerName:RemindersServer
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\RUNTIMEBROKER.EXE
### Runtime Broker Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*C:\Windows\System32\RuntimeBroker.exe -Embedding
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SECURITYHEALTHSYSTRAY.EXE
### Windows Security notification icon Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*"C:\Windows\System32\SecurityHealthSystray.exe"
[Running Processes] :HKLM C:\PROGRAM FILES\REALTEK\AUDIO\HDA\RTKNGUI64.EXE
### Realtek HD Audio Manager Realtek Semiconductor Realtek HD Audio Manager
1.0.484.0 !$*"C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
[Running Processes] :HKLM C:\PROGRAM FILES\REALTEK\AUDIO\HDA\RAVBG64.EXE
### HD Audio Background Process Realtek Semiconductor HD Audio Background Process
1, 0, 0, 220 !$*"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /MAXX4
[Running Processes] :HKLM
C:\USERS\SUKAN\APPDATA\LOCAL\MICROSOFT\ONEDRIVE\ONEDRIVE.EXE
### Microsoft OneDrive Microsoft Corporation Microsoft OneDrive 18.143.0717.0002
!$*"C:\Users\sukan\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
[Running Processes] :HKLM C:\PROGRAM FILES (X86)\INTERNET DOWNLOAD
MANAGER\IDMAN.EXE
### Internet Download Manager (IDM) Tonec Inc. Internet Download Manager (IDM) 6,
30, 7, 2 !$*"C:\Program Files (x86)\Internet Download Manager\IDMan.exe" /onboot
[Running Processes] :HKLM C:\PROGRAM FILES (X86)\INTERNET DOWNLOAD
MANAGER\IEMONITOR.EXE
### Internet Download Manager agent for click monitoring in IE-based browsers
Tonec Inc. IEMonitor Application 6, 22, 1, 1 !$*"C:\Program Files (x86)\Internet
Download Manager\IEMonitor.exe"
[Running Processes] :HKLM C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE
### Synaptics Pointing Device Helper Synaptics Incorporated Synaptics Pointing
Device Driver 19.0.9.4 27May15 !$*"C:\PROGRAM
FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE"
[Running Processes] :HKLM C:\PROGRAM FILES\REALTEK\AUDIO\HDA\RAVBG64.EXE
### HD Audio Background Process Realtek Semiconductor HD Audio Background Process
1, 0, 0, 220 !$*"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /IM
[Running Processes] :HKLM C:\PROGRAM FILES\CCLEANER\CCLEANER64.EXE
### CCleaner Piriform Ltd CCleaner 5, 29, 00, 6033 !$*"C:\Program
Files\CCleaner\CCleaner.exe" /MONITOR /uac
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\WBEM\UNSECAPP.EXE
### Sink to receive asynchronous callbacks for WMI client application Microsoft
Corporation Microsoft� Windows� Operating System 10.0.17763.1 !
$*C:\Windows\system32\wbem\unsecapp.exe -Embedding
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\APPLICATIONFRAMEHOST.EXE
### Application Frame Host Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*C:\Windows\system32\ApplicationFrameHost.exe -Embedding
[Running Processes] :HKLM
C:\WINDOWS\SYSTEMAPPS\MICROSOFT.MICROSOFTEDGE_8WEKYB3D8BBWE\MICROSOFTEDGE.EXE
### Microsoft Edge Microsoft Corporation Microsoft Edge 11.00.17763.1 !
$*"C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe"
-ServerName:MicrosoftEdge.AppXdnhjhccw3zf0j06tkg3jtqr00qdm0khc.mca
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\BROWSER_BROKER.EXE
### Browser_Broker Microsoft Corporation Microsoft� Windows� Operating System
11.00.17763.1 !$*C:\Windows\system32\browser_broker.exe -Embedding
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\RUNTIMEBROKER.EXE
### Runtime Broker Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*C:\Windows\System32\RuntimeBroker.exe -Embedding
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\MICROSOFTEDGECP.EXE
### Microsoft Edge Content Process Microsoft Corporation Microsoft Edge Web
Platform 11.00.17763.1 !$*"C:\Windows\System32\MicrosoftEdgeCP.exe"
-ServerName:Windows.Internal.WebRuntime.ContentProcessServer
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\MICROSOFTEDGESH.EXE
### Microsoft Edge Web Platform Microsoft Corporation Microsoft Edge Web Platform
11.00.17763.1 !$*C:\Windows\system32\MicrosoftEdgeSH.exe SCODEF:6572 CREDAT:9730
APH:8400000000007 JITHOST /prefetch:2
[Running Processes] :HKLM C:\PROGRAM
FILES\WINDOWSAPPS\MICROSOFT.WINDOWSSTORE_11805.1001.49.0_X64__8WEKYB3D8BBWE\WINSTOR
E.APP.EXE
### Store Microsoft Corporation Windows Store 11805.1001.49.0 !$*"C:\Program
Files\WindowsApps\Microsoft.WindowsStore_11805.1001.49.0_x64__8wekyb3d8bbwe\WinStor
e.App.exe" -ServerName:App.AppXc75wvwned5vhz4xyxxecvgdjhdkgsdza.mca
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\RUNTIMEBROKER.EXE
### Runtime Broker Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*C:\Windows\System32\RuntimeBroker.exe -Embedding
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*C:\Windows\system32\svchost.exe -k imgsvc
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*C:\Windows\system32\svchost.exe -k
UnistackSvcGroup
[Running Processes] :HKLM C:\WINDOWS\EXPLORER.EXE
### Windows Explorer Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*"C:\Windows\explorer.exe" /LOADSAVEDWINDOWS
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\DLLHOST.EXE
### COM Surrogate Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-
B78D-A8F59079A8D5}
[Running Processes] :HKLM
C:\WINDOWS\SYSTEMAPPS\SHELLEXPERIENCEHOST_CW5N1H2TXYEWY\SHELLEXPERIENCEHOST.EXE
### Windows Shell Experience Host Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !
$*"C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe"
-ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca
[Running Processes] :HKLM
C:\WINDOWS\SYSTEMAPPS\MICROSOFT.WINDOWS.CORTANA_CW5N1H2TXYEWY\SEARCHUI.EXE
### Search and Cortana application Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !
$*"C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe"
-ServerName:CortanaUI.AppXa50dqqa5gqv4a428c9y1jjw7m3btvepj.mca
[Running Processes] :HKLM
C:\WINDOWS\SYSTEMAPPS\INPUTAPP_CW5N1H2TXYEWY\WINDOWSINTERNAL.COMPOSABLESHELL.EXPERI
ENCES.TEXTINPUT.INPUTAPP.EXE
### WindowsInternal.ComposableShell.Experiences.TextInput.InputApp.exe Microsoft
Corporation Microsoft� Windows� Operating System 10.0.17763.1 !
$*"C:\Windows\SystemApps\InputApp_cw5n1h2txyewy\WindowsInternal.ComposableShell.Exp
eriences.TextInput.InputApp.exe"
-ServerName:App.AppXagta193n5rpf7mheremt3yyfa1g555vc.mca
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\DLLHOST.EXE
### COM Surrogate Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1 !$*C:\Windows\system32\DllHost.exe /Processid:{973D20D7-562D-44B9-
B70B-5A0F49CCDF3F}
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SYSTEMSETTINGSBROKER.EXE
### System Settings Broker Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1 !$*C:\Windows\System32\SystemSettingsBroker.exe -Embedding
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*C:\Windows\System32\svchost.exe -k
LocalServiceNetworkRestricted -s RmSvc
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*C:\Windows\system32\svchost.exe -k LocalService
-p -s BthAvctpSvc
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*C:\Windows\system32\svchost.exe -k LocalService
-p -s bthserv
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*C:\Windows\system32\svchost.exe -k
LocalServiceNetworkRestricted -s BTAGService
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*C:\Windows\system32\svchost.exe -k netsvcs -p -s
wuauserv
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*C:\Windows\system32\svchost.exe -k
LocalSystemNetworkRestricted -p -s WwanSvc
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*C:\Windows\system32\svchost.exe -k
LocalServiceNetworkRestricted -p -s SmsRouter
[Running Processes] :HKLM C:\UNHACKME\HACKMON.EXE
### Detects Rootkits in background Greatis Software UnHackMe 8.50 !
$*"C:\UnHackMe\hackmon.exe"
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SMARTSCREEN.EXE
### Windows Defender SmartScreen Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1 !$*C:\Windows\System32\smartscreen.exe -Embedding
[Running Processes] :HKLM C:\PROGRAM FILES (X86)\SDA\SD FORMATTER\SDFORMATTER.EXE
### Format Tool for SD Card [Normal Area Only] TRENDY Corporation SD Formatter
V4.0.0.0 4, 0, 0, 0 !$*"C:\Program Files (x86)\SDA\SD Formatter\SDFormatter.exe"
[Running Processes] :HKLM C:\UNHACKME\UNHACKME.EXE
### Detects and removes rootkits Greatis Software UnHackMe 8.70 !
$*"C:\UnHackMe\Unhackme.exe"
[Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SEARCHPROTOCOLHOST.EXE
### Microsoft Windows Search Protocol Host Microsoft Corporation Windows� Search
7.0.17763.1 !$*"C:\Windows\system32\SearchProtocolHost.exe"
Global\UsGthrFltPipeMssGthrPipe10_ Global\UsGthrCtrlFltPipeMssGthrPipe10 1
-2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0;
Windows NT; MS Search 4.0 Robot)"
"C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
[Running Processes] :HKLM C:\UNHACKME\REANIMATOR.EXE
### RegRun Start Control Greatis Software RegRun Security Suite 8.70 !
$*"C:\UnHackMe\reanimator.exe" /wiz /full /malw
[Running Services] Appinfo
### Internal Name: Appinfo. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k netsvcs -p * Facilitates the running of
interactive applications with additional administrative privileges. If this
service is stopped, users will be unable to launch applications with the additional
administrative privileges they may require to perform desired user tasks. Host
Process for Windows Services Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1
[Running Services] AppXSvc
### Internal Name: AppXSvc. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k wsappx -p * Provides infrastructure support for
deploying Store applications. This service is started on demand and if disabled
Store applications will not be deployed to the system, and may not function
properly. Host Process for Windows Services Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1
[Running Services] AtherosSvc
### Internal Name: AtherosSvc. Status: service is running. Actual File: *
[Running Services] AudioEndpointBuilder
### Internal Name: AudioEndpointBuilder. Status: service is running. Actual File:
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p * Manages audio
devices for the Windows Audio service. If this service is stopped, audio devices
and effects will not function properly. If this service is disabled, any services
that explicitly depend on it will fail to start Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1
[Running Services] Audiosrv
### Internal Name: Audiosrv. Status: service is running. Actual File:
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted -p * Manages audio
for Windows-based programs. If this service is stopped, audio devices and effects
will not function properly. If this service is disabled, any services that
explicitly depend on it will fail to start Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1
[Running Services] BFE
### Internal Name: BFE. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k LocalServiceNoNetworkFirewall -p * The Base
Filtering Engine (BFE) is a service that manages firewall and Internet Protocol
security (IPsec) policies and implements user mode filtering. Stopping or disabling
the BFE service will significantly reduce the security of the system. It will also
result in unpredictable behavior in IPsec management and firewall applications.
Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1
[Running Services] BrokerInfrastructure
### Internal Name: BrokerInfrastructure. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k DcomLaunch -p * Windows infrastructure service
that controls which background tasks can run on the system. Host Process for
Windows Services Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1
[Running Services] BTAGService
### Internal Name: BTAGService. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted * Service
supporting the audio gateway role of the Bluetooth Handsfree Profile. Host Process
for Windows Services Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1
[Running Services] BthAvctpSvc
### Internal Name: BthAvctpSvc. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k LocalService -p * This is Audio Video Control
Transport Protocol service Host Process for Windows Services Microsoft Corporation
Microsoft� Windows� Operating System 10.0.17763.1
[Running Services] bthserv
### Internal Name: bthserv. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k LocalService -p * The Bluetooth service supports
discovery and association of remote Bluetooth devices. Stopping or disabling this
service may cause already installed Bluetooth devices to fail to operate properly
and prevent new devices from being discovered or associated. Host Process for
Windows Services Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1
[Running Services] camsvc
### Internal Name: camsvc. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k appmodel -p * Provides facilities for managing
UWP apps access to app capabilities as well as checking an app's access to specific
app capabilities Host Process for Windows Services Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1
[Running Services] CDPSvc
### Internal Name: CDPSvc. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k LocalService -p * This service is used for
Connected Devices Platform scenarios Host Process for Windows Services Microsoft
Corporation Microsoft� Windows� Operating System 10.0.17763.1
[Running Services] CoreMessagingRegistrar
### Internal Name: CoreMessagingRegistrar. Status: service is running. Actual
File: C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork -p * Manages
communication between system components. Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1
[Running Services] CryptSvc
### Internal Name: CryptSvc. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k NetworkService -p * Provides three management
services: Catalog Database Service, which confirms the signatures of Windows files
and allows new programs to be installed; Protected Root Service, which adds and
removes Trusted Root Certification Authority certificates from this computer; and
Automatic Root Certificate Update Service, which retrieves root certificates from
Windows Update and enable scenarios such as SSL. If this service is stopped, these
management services will not function properly. If this service is disabled, any
services that explicitly depend on it will fail to start. Host Process for Windows
Services Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1
[Running Services] DcomLaunch
### Internal Name: DcomLaunch. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k DcomLaunch -p * The DCOMLAUNCH service launches
COM and DCOM servers in response to object activation requests. If this service is
stopped or disabled, programs using COM or DCOM will not function properly. It is
strongly recommended that you have the DCOMLAUNCH service running. Host Process for
Windows Services Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1
[Running Services] DeviceAssociationService
### Internal Name: DeviceAssociationService. Status: service is running. Actual
File: C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p * Enables
pairing between the system and wired or wireless devices. Host Process for Windows
Services Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1
[Running Services] Dhcp
### Internal Name: Dhcp. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -p * Registers and
updates IP addresses and DNS records for this computer. If this service is stopped,
this computer will not receive dynamic IP addresses and DNS updates. If this
service is disabled, any services that explicitly depend on it will fail to start.
Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1
[Running Services] DiagTrack
### Internal Name: DiagTrack. Status: service is running. Actual File:
C:\Windows\System32\svchost.exe -k utcsvc -p * The Connected User Experiences and
Telemetry service enables features that support in-application and connected user
experiences. Additionally, this service manages the event driven collection and
transmission of diagnostic and usage information (used to improve the experience
and quality of the Windows Platform) when the diagnostics and usage privacy option
settings are enabled under Feedback and Diagnostics. Host Process for Windows
Services Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1
[Running Services] DisplayEnhancementService
### Internal Name: DisplayEnhancementService. Status: service is running. Actual
File: C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p * A
service for managing display enhancement such as brightness control. Host Process
for Windows Services Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1
[Running Services] Dnscache
### Internal Name: Dnscache. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k NetworkService -p * The DNS Client service
(dnscache) caches Domain Name System (DNS) names and registers the full computer
name for this computer. If the service is stopped, DNS names will continue to be
resolved. However, the results of DNS name queries will not be cached and the
computer's name will not be registered. If the service is disabled, any services
that explicitly depend on it will fail to start. Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1
[Running Services] DoSvc
### Internal Name: DoSvc. Status: service is running. Actual File:
C:\Windows\System32\svchost.exe -k NetworkService -p * Performs content delivery
optimization tasks Host Process for Windows Services Microsoft Corporation
Microsoft� Windows� Operating System 10.0.17763.1
[Running Services] DPS
### Internal Name: DPS. Status: service is running. Actual File:
C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork -p * The Diagnostic Policy
Service enables problem detection, troubleshooting and resolution for Windows
components. If this service is stopped, diagnostics will no longer function. Host
Process for Windows Services Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1
[Running Services] DsmSvc
### Internal Name: DsmSvc. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k netsvcs -p * Enables the detection, download and
installation of device-related software. If this service is disabled, devices may
be configured with outdated software, and may not work correctly. Host Process for
Windows Services Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1
[Running Services] DusmSvc
### Internal Name: DusmSvc. Status: service is running. Actual File:
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted -p * Network data
usage, data limit, restrict background data, metered networks. Host Process for
Windows Services Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1
[Running Services] EventLog
### Internal Name: EventLog. Status: service is running. Actual File:
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted -p * This service
manages events and event logs. It supports logging events, querying events,
subscribing to events, archiving event logs, and managing event metadata. It can
display events in both XML and plain text format. Stopping this service may
compromise security and reliability of the system. Host Process for Windows
Services Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1
[Running Services] EventSystem
### Internal Name: EventSystem. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k LocalService -p * Supports System Event
Notification Service (SENS), which provides automatic distribution of events to
subscribing Component Object Model (COM) components. If the service is stopped,
SENS will close and will not be able to provide logon and logoff notifications. If
this service is disabled, any services that explicitly depend on it will fail to
start. Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1
[Running Services] FontCache
### Internal Name: FontCache. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k LocalService -p * Optimizes performance of
applications by caching commonly used font data. Applications will start this
service if it is not already running. It can be disabled, though doing so will
degrade application performance. Host Process for Windows Services Microsoft
Corporation Microsoft� Windows� Operating System 10.0.17763.1
[Running Services] FontCache3.0.0.0
### Internal Name: FontCache3.0.0.0. Status: service is running. Actual File:
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe * Optimizes
performance of Windows Presentation Foundation (WPF) applications by caching
commonly used font data. WPF applications will start this service if it is not
already running. It can be disabled, though doing so will degrade the performance
of WPF applications. PresentationFontCache.exe Microsoft Corporation Microsoft�
.NET Framework 3.0.6920.9034
[Running Services] FoxitReaderService
### Internal Name: FoxitReaderService. Status: service is running. Actual File:
"C:\Program Files (x86)\Foxit Software\Foxit Reader\FoxitConnectedPDFService.exe" *
Foxit Reader ConnectedPDF Windows Service. Foxit Software Inc. Foxit ConnectedPDF
Windows Service. 8.2.0.1206
[Running Services] igfxCUIService1.0.0.0
### Internal Name: igfxCUIService1.0.0.0. Status: service is running. Actual
File: C:\Windows\system32\igfxCUIService.exe * Service for Intel(R) HD Graphics
Control Panel igfxCUIService Module Intel Corporation Intel(R) Common User
Interface 6.15.10.4252
[Running Services] iphlpsvc
### Internal Name: iphlpsvc. Status: service is running. Actual File:
C:\Windows\System32\svchost.exe -k NetSvcs -p * Provides tunnel connectivity using
IPv6 transition technologies (6to4, ISATAP, Port Proxy, and Teredo), and IP-HTTPS.
If this service is stopped, the computer will not have the enhanced connectivity
benefits that these technologies offer. Host Process for Windows Services Microsoft
Corporation Microsoft� Windows� Operating System 10.0.17763.1
[Running Services] KeyIso
### Internal Name: KeyIso. Status: service is running. Actual File:
C:\Windows\system32\lsass.exe * The CNG key isolation service is hosted in the LSA
process. The service provides key process isolation to private keys and associated
cryptographic operations as required by the Common Criteria. The service stores and
uses long-lived keys in a secure process complying with Common Criteria
requirements. Local Security Authority Process Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1
[Running Services] LanmanServer
### Internal Name: LanmanServer. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k netsvcs -p * Supports file, print, and named-
pipe sharing over the network for this computer. If this service is stopped, these
functions will be unavailable. If this service is disabled, any services that
explicitly depend on it will fail to start. Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1
[Running Services] LanmanWorkstation
### Internal Name: LanmanWorkstation. Status: service is running. Actual File:
C:\Windows\System32\svchost.exe -k NetworkService -p * Creates and maintains client
network connections to remote servers using the SMB protocol. If this service is
stopped, these connections will be unavailable. If this service is disabled, any
services that explicitly depend on it will fail to start. Host Process for Windows
Services Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1
[Running Services] lfsvc
### Internal Name: lfsvc. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k netsvcs -p * This service monitors the current
location of the system and manages geofences (a geographical location with
associated events). If you turn off this service, applications will be unable to
use or receive notifications for geolocation or geofences. Host Process for Windows
Services Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1
[Running Services] LicenseManager
### Internal Name: LicenseManager. Status: service is running. Actual File:
C:\Windows\System32\svchost.exe -k LocalService -p * Provides infrastructure
support for the Microsoft Store. This service is started on demand and if disabled
then content acquired through the Microsoft Store will not function properly. Host
Process for Windows Services Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1
[Running Services] LSM
### Internal Name: LSM. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k DcomLaunch -p * Core Windows Service that
manages local user sessions. Stopping or disabling this service will result in
system instability. Host Process for Windows Services Microsoft Corporation
Microsoft� Windows� Operating System 10.0.17763.1
[Running Services] mpssvc
### Internal Name: mpssvc. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k LocalServiceNoNetworkFirewall -p * Windows
Defender Firewall helps protect your computer by preventing unauthorized users from
gaining access to your computer through the Internet or a network. Host Process for
Windows Services Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1
[Running Services] NcbService
### Internal Name: NcbService. Status: service is running. Actual File:
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p * Brokers
connections that allow Windows Store Apps to receive notifications from the
internet. Host Process for Windows Services Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1
[Running Services] netprofm
### Internal Name: netprofm. Status: service is running. Actual File:
C:\Windows\System32\svchost.exe -k LocalService -p * Identifies the networks to
which the computer has connected, collects and stores properties for these
networks, and notifies applications when these properties change. Host Process for
Windows Services Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1
[Running Services] NgcCtnrSvc
### Internal Name: NgcCtnrSvc. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -p * Manages local
user identity keys used to authenticate user to identity providers as well as TPM
virtual smart cards. If this service is disabled, local user identity keys and TPM
virtual smart cards will not be accessible. It is recommended that you do not
reconfigure this service. Host Process for Windows Services Microsoft Corporation
Microsoft� Windows� Operating System 10.0.17763.1
[Running Services] NgcSvc
### Internal Name: NgcSvc. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p * Provides
process isolation for cryptographic keys used to authenticate to a user�s
associated identity providers. If this service is disabled, all uses and management
of these keys will not be available, which includes machine logon and single-sign
on for apps and websites. This service starts and stops automatically. It is
recommended that you do not reconfigure this service. Host Process for Windows
Services Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1
[Running Services] NlaSvc
### Internal Name: NlaSvc. Status: service is running. Actual File:
C:\Windows\System32\svchost.exe -k NetworkService -p * Collects and stores
configuration information for the network and notifies programs when this
information is modified. If this service is stopped, configuration information
might be unavailable. If this service is disabled, any services that explicitly
depend on it will fail to start. Host Process for Windows Services Microsoft
Corporation Microsoft� Windows� Operating System 10.0.17763.1
[Running Services] nsi
### Internal Name: nsi. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k LocalService -p * This service delivers network
notifications (e.g. interface addition/deleting etc) to user mode clients. Stopping
this service will cause loss of network connectivity. If this service is disabled,
any other services that explicitly depend on this service will fail to start. Host
Process for Windows Services Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1
[Running Services] PcaSvc
### Internal Name: PcaSvc. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p * This service
provides support for the Program Compatibility Assistant (PCA). PCA monitors
programs installed and run by the user and detects known compatibility problems. If
this service is stopped, PCA will not function properly. Host Process for Windows
Services Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1
[Running Services] PlugPlay
### Internal Name: PlugPlay. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k DcomLaunch -p * Enables a computer to recognize
and adapt to hardware changes with little or no user input. Stopping or disabling
this service will result in system instability. Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1
[Running Services] Power
### Internal Name: Power. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k DcomLaunch -p * Manages power policy and power
policy notification delivery. Host Process for Windows Services Microsoft
Corporation Microsoft� Windows� Operating System 10.0.17763.1
[Running Services] ProfSvc
### Internal Name: ProfSvc. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k netsvcs -p * This service is responsible for
loading and unloading user profiles. If this service is stopped or disabled, users
will no longer be able to successfully sign in or sign out, apps might have
problems getting to users' data, and components registered to receive profile event
notifications won't receive them. Host Process for Windows Services Microsoft
Corporation Microsoft� Windows� Operating System 10.0.17763.1
[Running Services] RasMan
### Internal Name: RasMan. Status: service is running. Actual File:
C:\Windows\System32\svchost.exe -k netsvcs * Manages dial-up and virtual private
network (VPN) connections from this computer to the Internet or other remote
networks. If this service is disabled, any services that explicitly depend on it
will fail to start. Host Process for Windows Services Microsoft Corporation
Microsoft� Windows� Operating System 10.0.17763.1
[Running Services] RmSvc
### Internal Name: RmSvc. Status: service is running. Actual File:
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted * Radio Management
and Airplane Mode Service Host Process for Windows Services Microsoft Corporation
Microsoft� Windows� Operating System 10.0.17763.1
[Running Services] RpcEptMapper
### Internal Name: RpcEptMapper. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k RPCSS -p * Resolves RPC interfaces identifiers
to transport endpoints. If this service is stopped or disabled, programs using
Remote Procedure Call (RPC) services will not function properly. Host Process for
Windows Services Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1
[Running Services] RpcSs
### Internal Name: RpcSs. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k rpcss -p * The RPCSS service is the Service
Control Manager for COM and DCOM servers. It performs object activations requests,
object exporter resolutions and distributed garbage collection for COM and DCOM
servers. If this service is stopped or disabled, programs using COM or DCOM will
not function properly. It is strongly recommended that you have the RPCSS service
running. Host Process for Windows Services Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1
[Running Services] RtkAudioService
### Internal Name: RtkAudioService. Status: service is running. Actual File:
"C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe" * For cooperation with
Realtek audio driver. Realtek Audio Service Realtek Semiconductor Realtek Audio
Service 1, 0, 0, 66
[Running Services] SamSs
### Internal Name: SamSs. Status: service is running. Actual File:
C:\Windows\system32\lsass.exe * The startup of this service signals other services
that the Security Accounts Manager (SAM) is ready to accept requests. Disabling
this service will prevent other services in the system from being notified when the
SAM is ready, which may in turn cause those services to fail to start correctly.
This service should not be disabled. Local Security Authority Process Microsoft
Corporation Microsoft� Windows� Operating System 10.0.17763.1
[Running Services] Schedule
### Internal Name: Schedule. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k netsvcs -p * Enables a user to configure and
schedule automated tasks on this computer. The service also hosts multiple Windows
system-critical tasks. If this service is stopped or disabled, these tasks will not
be run at their scheduled times. If this service is disabled, any services that
explicitly depend on it will fail to start. Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1
[Running Services] SecurityHealthService
### Internal Name: SecurityHealthService. Status: service is running. Actual
File: C:\Windows\system32\SecurityHealthService.exe * Windows Security Service
handles unified device protection and health information Windows Security Health
Service Microsoft Corporation Microsoft� Windows� Operating System 4.18.1807.16384
[Running Services] SEMgrSvc
### Internal Name: SEMgrSvc. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k LocalService -p * Manages payments and Near
Field Communication (NFC) based secure elements. Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1
[Running Services] SENS
### Internal Name: SENS. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k netsvcs -p * Monitors system events and notifies
subscribers to COM+ Event System of these events. Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1
[Running Services] SgrmBroker
### Internal Name: SgrmBroker. Status: service is running. Actual File:
C:\Windows\system32\SgrmBroker.exe * Monitors and attests to the integrity of the
Windows platform. System Guard Runtime Monitor Broker Service Microsoft Corporation
Microsoft� Windows� Operating System 10.0.17763.1
[Running Services] ShellHWDetection
### Internal Name: ShellHWDetection. Status: service is running. Actual File:
C:\Windows\System32\svchost.exe -k netsvcs -p * Provides notifications for AutoPlay
hardware events. Host Process for Windows Services Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1
[Running Services] SmsRouter
### Internal Name: SmsRouter. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -p * Routes
messages based on rules to appropriate clients. Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1
[Running Services] Spooler
### Internal Name: Spooler. Status: service is running. Actual File:
C:\Windows\System32\spoolsv.exe * This service spools print jobs and handles
interaction with the printer. If you turn off this service, you won�t be able to
print or see your printers. Spooler SubSystem App Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1
[Running Services] SSDPSRV
### Internal Name: SSDPSRV. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation -p * Discovers
networked devices and services that use the SSDP discovery protocol, such as UPnP
devices. Also announces SSDP devices and services running on the local computer. If
this service is stopped, SSDP-based devices will not be discovered. If this service
is disabled, any services that explicitly depend on it will fail to start. Host
Process for Windows Services Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1
[Running Services] SstpSvc
### Internal Name: SstpSvc. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k LocalService -p * Provides support for the
Secure Socket Tunneling Protocol (SSTP) to connect to remote computers using VPN.
If this service is disabled, users will not be able to use SSTP to access remote
servers. Host Process for Windows Services Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1
[Running Services] StateRepository
### Internal Name: StateRepository. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k appmodel -p * Provides required infrastructure
support for the application model. Host Process for Windows Services Microsoft
Corporation Microsoft� Windows� Operating System 10.0.17763.1
[Running Services] stisvc
### Internal Name: stisvc. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k imgsvc * Provides image acquisition services for
scanners and cameras Host Process for Windows Services Microsoft Corporation
Microsoft� Windows� Operating System 10.0.17763.1
[Running Services] StorSvc
### Internal Name: StorSvc. Status: service is running. Actual File:
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p * Provides
enabling services for storage settings and external storage expansion Host Process
for Windows Services Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1
[Running Services] SysMain
### Internal Name: SysMain. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p * Maintains and
improves system performance over time. Host Process for Windows Services Microsoft
Corporation Microsoft� Windows� Operating System 10.0.17763.1
[Running Services] SystemEventsBroker
### Internal Name: SystemEventsBroker. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k DcomLaunch -p * Coordinates execution of
background work for WinRT application. If this service is stopped or disabled, then
background work might not be triggered. Host Process for Windows Services Microsoft
Corporation Microsoft� Windows� Operating System 10.0.17763.1
[Running Services] TabletInputService
### Internal Name: TabletInputService. Status: service is running. Actual File:
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p * Enables Touch
Keyboard and Handwriting Panel pen and ink functionality Host Process for Windows
Services Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1
[Running Services] Themes
### Internal Name: Themes. Status: service is running. Actual File:
C:\Windows\System32\svchost.exe -k netsvcs -p * Provides user experience theme
management. Host Process for Windows Services Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1
[Running Services] TimeBrokerSvc
### Internal Name: TimeBrokerSvc. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -p * Coordinates
execution of background work for WinRT application. If this service is stopped or
disabled, then background work might not be triggered. Host Process for Windows
Services Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1
[Running Services] TokenBroker
### Internal Name: TokenBroker. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k netsvcs -p * This service is used by Web Account
Manager to provide single-sign-on to apps and services. Host Process for Windows
Services Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1
[Running Services] TrkWks
### Internal Name: TrkWks. Status: service is running. Actual File:
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p * Maintains
links between NTFS files within a computer or across computers in a network. Host
Process for Windows Services Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1
[Running Services] UserManager
### Internal Name: UserManager. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k netsvcs -p * User Manager provides the runtime
components required for multi-user interaction. If this service is stopped, some
applications may not operate correctly. Host Process for Windows Services Microsoft
Corporation Microsoft� Windows� Operating System 10.0.17763.1
[Running Services] UsoSvc
### Internal Name: UsoSvc. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k netsvcs -p * Manages Windows Updates. If
stopped, your devices will not be able download and install latest udpates. Host
Process for Windows Services Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1
[Running Services] VaultSvc
### Internal Name: VaultSvc. Status: service is running. Actual File:
C:\Windows\system32\lsass.exe * Provides secure storage and retrieval of
credentials to users, applications and security service packages. Local Security
Authority Process Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1
[Running Services] Wcmsvc
### Internal Name: Wcmsvc. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -p * Makes
automatic connect/disconnect decisions based on the network connectivity options
currently available to the PC and enables management of network connectivity based
on Group Policy settings. Host Process for Windows Services Microsoft Corporation
Microsoft� Windows� Operating System 10.0.17763.1
[Running Services] WdiServiceHost
### Internal Name: WdiServiceHost. Status: service is running. Actual File:
C:\Windows\System32\svchost.exe -k LocalService -p * The Diagnostic Service Host is
used by the Diagnostic Policy Service to host diagnostics that need to run in a
Local Service context. If this service is stopped, any diagnostics that depend on
it will no longer function. Host Process for Windows Services Microsoft Corporation
Microsoft� Windows� Operating System 10.0.17763.1
[Running Services] WdiSystemHost
### Internal Name: WdiSystemHost. Status: service is running. Actual File:
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p * The Diagnostic
System Host is used by the Diagnostic Policy Service to host diagnostics that need
to run in a Local System context. If this service is stopped, any diagnostics that
depend on it will no longer function. Host Process for Windows Services Microsoft
Corporation Microsoft� Windows� Operating System 10.0.17763.1
[Running Services] WdNisSvc
### Internal Name: WdNisSvc. Status: service is running. Actual File: "C:\Program
Files\Windows Defender\NisSrv.exe" * Helps guard against intrusion attempts
targeting known and newly discovered vulnerabilities in network protocols Microsoft
Network Realtime Inspection Service Microsoft Corporation Microsoft� Windows�
Operating System 4.18.1807.16384
[Running Services] WinDefend
### Internal Name: WinDefend. Status: service is running. Actual File:
"C:\Program Files\Windows Defender\MsMpEng.exe" * Helps protect users from malware
and other potentially unwanted software Antimalware Service Executable Microsoft
Corporation Microsoft� Windows� Operating System 4.18.1807.18075
[Running Services] WinHttpAutoProxySvc
### Internal Name: WinHttpAutoProxySvc. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -p * WinHTTP
implements the client HTTP stack and provides developers with a Win32 API and COM
Automation component for sending HTTP requests and receiving responses. In
addition, WinHTTP provides support for auto-discovering a proxy configuration via
its implementation of the Web Proxy Auto-Discovery (WPAD) protocol. Host Process
for Windows Services Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1
[Running Services] Winmgmt
### Internal Name: Winmgmt. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k netsvcs -p * Provides a common interface and
object model to access management information about operating system, devices,
applications and services. If this service is stopped, most Windows-based software
will not function properly. If this service is disabled, any services that
explicitly depend on it will fail to start. Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1
[Running Services] WlanSvc
### Internal Name: WlanSvc. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p * The WLANSVC
service provides the logic required to configure, discover, connect to, and
disconnect from a wireless local area network (WLAN) as defined by IEEE 802.11
standards. It also contains the logic to turn your computer into a software access
point so that other devices or computers can connect to your computer wirelessly
using a WLAN adapter that can support this. Stopping or disabling the WLANSVC
service will make all WLAN adapters on your computer inaccessible from the Windows
networking UI. It is strongly recommended that you have the WLANSVC service running
if your computer has a WLAN adapter. Host Process for Windows Services Microsoft
Corporation Microsoft� Windows� Operating System 10.0.17763.1
[Running Services] wlidsvc
### Internal Name: wlidsvc. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k netsvcs -p * Enables user sign-in through
Microsoft account identity services. If this service is stopped, users will not be
able to logon to the computer with their Microsoft account. Host Process for
Windows Services Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1
[Running Services] WpnService
### Internal Name: WpnService. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k netsvcs -p * This service runs in session 0 and
hosts the notification platform and connection provider which handles the
connection between the device and WNS server. Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1
[Running Services] wscsvc
### Internal Name: wscsvc. Status: service is running. Actual File:
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted -p * The WSCSVC
(Windows Security Center) service monitors and reports security health settings on
the computer. The health settings include firewall (on/off), antivirus (on/off/out
of date), antispyware (on/off/out of date), Windows Update (automatically/manually
download and install updates), User Account Control (on/off), and Internet settings
(recommended/not recommended). The service provides COM APIs for independent
software vendors to register and record the state of their products to the Security
Center service. The Security and Maintenance UI uses the service to provide
systray alerts and a graphical view of the security health states in the Security
and Maintenance control panel. Network Access Protection (NAP) uses the service to
report the security health states of clients to the NAP Network Policy Server to
make network quarantine decisions. The service also has a public API that allows
external consumers to programmatically retrieve the aggregated security health
state of the system. Host Process for Windows Services Microsoft Corporation
Microsoft� Windows� Operating System 10.0.17763.1
[Running Services] WSearch
### Internal Name: WSearch. Status: service is running. Actual File:
C:\Windows\system32\SearchIndexer.exe /Embedding * Provides content indexing,
property caching, and search results for files, e-mail, and other content.
Microsoft Windows Search Indexer Microsoft Corporation Windows� Search 7.0.17763.1
[Running Services] wuauserv
### Internal Name: wuauserv. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k netsvcs -p * Enables the detection, download,
and installation of updates for Windows and other programs. If this service is
disabled, users of this computer will not be able to use Windows Update or its
automatic updating feature, and programs will not be able to use the Windows Update
Agent (WUA) API. Host Process for Windows Services Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1
[Running Services] WwanSvc
### Internal Name: WwanSvc. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p * This service
manages mobile broadband (GSM & CDMA) data card/embedded module adapters and
connections by auto-configuring the networks. It is strongly recommended that this
service be kept running for best user experience of mobile broadband devices. Host
Process for Windows Services Microsoft Corporation Microsoft� Windows� Operating
System 10.0.17763.1
[Running Services] cbdhsvc_127d39
### Internal Name: cbdhsvc_127d39. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k ClipboardSvcGroup -p * This user service is used
for Clipboard scenarios Host Process for Windows Services Microsoft Corporation
Microsoft� Windows� Operating System 10.0.17763.1
[Running Services] CDPUserSvc_127d39
### Internal Name: CDPUserSvc_127d39. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k UnistackSvcGroup * This user service is used for
Connected Devices Platform scenarios Host Process for Windows Services Microsoft
Corporation Microsoft� Windows� Operating System 10.0.17763.1
[Running Services] OneSyncSvc_127d39
### Internal Name: OneSyncSvc_127d39. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k UnistackSvcGroup * This service synchronizes
mail, contacts, calendar and various other user data. Mail and other applications
dependent on this functionality will not work properly when this service is not
running. Host Process for Windows Services Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1
[Running Services] PimIndexMaintenanceSvc_127d39
### Internal Name: PimIndexMaintenanceSvc_127d39. Status: service is running.
Actual File: C:\Windows\system32\svchost.exe -k UnistackSvcGroup * Indexes contact
data for fast contact searching. If you stop or disable this service, contacts
might be missing from your search results. Host Process for Windows Services
Microsoft Corporation Microsoft� Windows� Operating System 10.0.17763.1
[Running Services] UnistoreSvc_127d39
### Internal Name: UnistoreSvc_127d39. Status: service is running. Actual File:
C:\Windows\System32\svchost.exe -k UnistackSvcGroup * Handles storage of structured
user data, including contact info, calendars, messages, and other content. If you
stop or disable this service, apps that use this data might not work correctly.
Host Process for Windows Services Microsoft Corporation Microsoft� Windows�
Operating System 10.0.17763.1
[Running Services] UserDataSvc_127d39
### Internal Name: UserDataSvc_127d39. Status: service is running. Actual File:
C:\Windows\system32\svchost.exe -k UnistackSvcGroup * Provides apps access to
structured user data, including contact info, calendars, messages, and other
content. If you stop or disable this service, apps that use this data might not
work correctly. Host Process for Windows Services Microsoft Corporation Microsoft�
Windows� Operating System 10.0.17763.1
[Running Services] WpnUserService_127d39
### Internal Name: WpnUserService_127d39. Status: service is running. Actual
File: C:\Windows\system32\svchost.exe -k UnistackSvcGroup * This service hosts
Windows notification platform which provides support for local and push
notifications. Supported notifications are tile, toast and raw. Host Process for
Windows Services Microsoft Corporation Microsoft� Windows� Operating System
10.0.17763.1
[Uninstall]
[Applications] :HKLM {179324FF-7B16-4BA8-9836-055CAAEE4F08}=MsiExec.exe
/X{179324FF-7B16-4BA8-9836-055CAAEE4F08}
### SDFormatter - (17) 10-2018
[Applications] :HKLM UnHackMe_is1="C:\UnHackMe\unins000.exe" /SILENT
### UnHackMe 8.70 - (17) 10-2018
[Applications] :HKLM www.ushareit.com_is1="C:\Program Files (x86)\SHAREit
Technologies\SHAREit\unins001.exe" /SILENT
### SHAREit - (17) 10-2018
[Applications] :HKLM IDM Crack 6.30 build 7=C:\Program Files (x86)\Internet
Download Manager\IDM Patch Uninstaller 6.30 build 7.exe
### IDM Crack 6.30 build 7 - (13) 10-2018
[Applications] :HKLM Internet Download Manager=C:\Program Files (x86)\Internet
Download Manager\Uninstall.exe
### Internet Download Manager - (13) 10-2018
[Applications] :HKLM {90160000-0011-0000-1000-
0000000FF1CE}_Office16.PROPLUS_{7AFED019-B612-489B-B369-2920C6B5A96D}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-0011-0000-1000-0000000FF1CE}" "{7AFED019-B612-489B-B369-2920C6B5A96D}"
"1033" "0"
### Security Update for Microsoft Office 2016 (KB3213551) 64-Bit Edition - (13)
10-2018
[Applications] :HKLM {90160000-0011-0000-1000-
0000000FF1CE}_Office16.PROPLUS_{86B5E1DD-CAD1-455F-A21E-BA4CA4F74706}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-0011-0000-1000-0000000FF1CE}" "{86B5E1DD-CAD1-455F-A21E-BA4CA4F74706}"
"1033" "0"
### Update for Microsoft Office 2016 (KB3203471) 64-Bit Edition - (13) 10-2018
[Applications] :HKLM {90160000-0011-0000-1000-
0000000FF1CE}_Office16.PROPLUS_{89B85BAE-5618-49A4-9C18-153202BDFC73}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-0011-0000-1000-0000000FF1CE}" "{89B85BAE-5618-49A4-9C18-153202BDFC73}"
"1033" "0"
### Update for Microsoft Office 2016 (KB2910954) 64-Bit Edition - (13) 10-2018
[Applications] :HKLM {90160000-0011-0000-1000-
0000000FF1CE}_Office16.PROPLUS_{78D7B4DE-619F-4312-9707-DF354A48D110}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-0011-0000-1000-0000000FF1CE}" "{78D7B4DE-619F-4312-9707-DF354A48D110}"
"1033" "0"
### Update for Microsoft Office 2016 (KB3115081) 64-Bit Edition - (13) 10-2018
[Applications] :HKLM {90160000-0011-0000-1000-
0000000FF1CE}_Office16.PROPLUS_{8683D594-A08C-451F-82C3-51D6FB730A6C}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-0011-0000-1000-0000000FF1CE}" "{8683D594-A08C-451F-82C3-51D6FB730A6C}"
"1033" "0"
### Update for Microsoft Office 2016 (KB2920720) 64-Bit Edition - (13) 10-2018
[Applications] :HKLM {90160000-0011-0000-1000-
0000000FF1CE}_Office16.PROPLUS_{7D634991-F4C0-4761-9F90-54F69A8199EB}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-0011-0000-1000-0000000FF1CE}" "{7D634991-F4C0-4761-9F90-54F69A8199EB}"
"1033" "0"
### Update for Microsoft Office 2016 (KB3118262) 64-Bit Edition - (13) 10-2018
[Applications] :HKLM {90160000-0011-0000-1000-
0000000FF1CE}_Office16.PROPLUS_{830268FA-EAD3-4BE1-BF80-0E5CCE01192F}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-0011-0000-1000-0000000FF1CE}" "{830268FA-EAD3-4BE1-BF80-0E5CCE01192F}"
"1033" "0"
### Update for Microsoft Office 2016 (KB4011671) 64-Bit Edition - (13) 10-2018
[Applications] :HKLM {90160000-0011-0000-1000-
0000000FF1CE}_Office16.PROPLUS_{7CB794F9-8C52-4DD4-B9A8-17FB5E66BEA9}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-0011-0000-1000-0000000FF1CE}" "{7CB794F9-8C52-4DD4-B9A8-17FB5E66BEA9}"
"1033" "0"
### Update for Microsoft Office 2016 (KB4011031) 64-Bit Edition - (13) 10-2018
[Applications] :HKLM {90160000-0011-0000-1000-
0000000FF1CE}_Office16.PROPLUS_{7C02FBD8-2EA8-4FBA-B47B-20696253BC27}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-0011-0000-1000-0000000FF1CE}" "{7C02FBD8-2EA8-4FBA-B47B-20696253BC27}"
"1033" "0"
### Update for Microsoft Office 2016 (KB4011225) 64-Bit Edition - (13) 10-2018
[Applications] :HKLM {90160000-0011-0000-1000-
0000000FF1CE}_Office16.PROPLUS_{847C18F4-D7FD-4833-BCB3-7036953BC967}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-0011-0000-1000-0000000FF1CE}" "{847C18F4-D7FD-4833-BCB3-7036953BC967}"
"1033" "0"
### Update for Microsoft Office 2016 (KB3141506) 64-Bit Edition - (13) 10-2018
[Applications] :HKLM {90160000-0011-0000-1000-
0000000FF1CE}_Office16.PROPLUS_{3DBF9257-2612-4385-BCE3-E9D4C41CC8CB}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-0011-0000-1000-0000000FF1CE}" "{3DBF9257-2612-4385-BCE3-E9D4C41CC8CB}"
"1033" "0"
### Definition Update for Microsoft Office 2016 (KB3115407) 64-Bit Edition - (13)
10-2018
[Applications] :HKLM {90160000-0011-0000-1000-
0000000FF1CE}_Office16.PROPLUS_{45610767-EC8C-44CD-9001-6845F626FCD5}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-0011-0000-1000-0000000FF1CE}" "{45610767-EC8C-44CD-9001-6845F626FCD5}"
"1033" "0"
### Update for Microsoft Office 2016 (KB3115276) 64-Bit Edition - (13) 10-2018
[Applications] :HKLM {90160000-0011-0000-1000-
0000000FF1CE}_Office16.PROPLUS_{49ECA25A-7982-48D8-AA93-58C09E9D481A}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-0011-0000-1000-0000000FF1CE}" "{49ECA25A-7982-48D8-AA93-58C09E9D481A}"
"1033" "0"
### Update for Microsoft PowerPoint 2016 (KB4011726) 64-Bit Edition - (13) 10-
2018
[Applications] :HKLM {90160000-0011-0000-1000-
0000000FF1CE}_Office16.PROPLUS_{370B11B2-F876-4EDE-BD13-E323E9AB215F}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-0011-0000-1000-0000000FF1CE}" "{370B11B2-F876-4EDE-BD13-E323E9AB215F}"
"1033" "0"
### Security Update for Microsoft Office 2016 (KB2920723) 64-Bit Edition - (13)
10-2018
[Applications] :HKLM {90160000-0011-0000-1000-
0000000FF1CE}_Office16.PROPLUS_{3AF87AAA-17AE-4BD0-AAC6-86BA5DF1115E}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-0011-0000-1000-0000000FF1CE}" "{3AF87AAA-17AE-4BD0-AAC6-86BA5DF1115E}"
"1033" "0"
### Update for Microsoft Office 2016 (KB4011218) 64-Bit Edition - (13) 10-2018
[Applications] :HKLM {90160000-0011-0000-1000-
0000000FF1CE}_Office16.PROPLUS_{3C3547B7-61D4-41C8-B8EA-36DB5CA6C51A}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-0011-0000-1000-0000000FF1CE}" "{3C3547B7-61D4-41C8-B8EA-36DB5CA6C51A}"
"1033" "0"
### Update for Microsoft Office 2016 (KB4011732) 64-Bit Edition - (13) 10-2018
[Applications] :HKLM {90160000-0011-0000-1000-
0000000FF1CE}_Office16.PROPLUS_{4D4432EE-ECE1-42CA-8B93-0916170C8252}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-0011-0000-1000-0000000FF1CE}" "{4D4432EE-ECE1-42CA-8B93-0916170C8252}"
"1033" "0"
### Update for Microsoft Office 2016 (KB2920684) 64-Bit Edition - (13) 10-2018
[Applications] :HKLM {90160000-0011-0000-1000-
0000000FF1CE}_Office16.PROPLUS_{5A84393A-E440-48A1-BB99-AD1244AC0C35}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-0011-0000-1000-0000000FF1CE}" "{5A84393A-E440-48A1-BB99-AD1244AC0C35}"
"1033" "0"
### Security Update for Microsoft Office 2016 (KB3085538) 64-Bit Edition - (13)
10-2018
[Applications] :HKLM {90160000-0011-0000-1000-
0000000FF1CE}_Office16.PROPLUS_{6BB390A3-FA2A-4F84-8004-D086564DE9E4}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-0011-0000-1000-0000000FF1CE}" "{6BB390A3-FA2A-4F84-8004-D086564DE9E4}"
"1033" "0"
### Security Update for Microsoft Excel 2016 (KB4011727) 64-Bit Edition - (13)
10-2018
[Applications] :HKLM {90160000-0011-0000-1000-
0000000FF1CE}_Office16.PROPLUS_{6DB5528D-2F8F-4C67-84C2-1578B9052F03}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-0011-0000-1000-0000000FF1CE}" "{6DB5528D-2F8F-4C67-84C2-1578B9052F03}"
"1033" "0"
### Update for Microsoft Outlook 2016 (KB4018326) 64-Bit Edition - (13) 10-2018
[Applications] :HKLM {90160000-0011-0000-1000-
0000000FF1CE}_Office16.PROPLUS_{4EAC16BA-08BE-44DE-AD3D-4FF4C309CCFE}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-0011-0000-1000-0000000FF1CE}" "{4EAC16BA-08BE-44DE-AD3D-4FF4C309CCFE}"
"1033" "0"
### Security Update for Microsoft Office 2016 (KB4011185) 64-Bit Edition - (13)
10-2018
[Applications] :HKLM {90160000-0011-0000-1000-
0000000FF1CE}_Office16.PROPLUS_{53515168-F906-4C7C-8038-9EF0CEBC6EB5}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-0011-0000-1000-0000000FF1CE}" "{53515168-F906-4C7C-8038-9EF0CEBC6EB5}"
"1033" "0"
### Update for Microsoft Office 2016 (KB3141457) 64-Bit Edition - (13) 10-2018
[Applications] :HKLM {90160000-0011-0000-1000-
0000000FF1CE}_Office16.PROPLUS_{542634C3-CF0E-4EC6-91A7-FCF797695791}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-0011-0000-1000-0000000FF1CE}" "{542634C3-CF0E-4EC6-91A7-FCF797695791}"
"1033" "0"
### Security Update for Microsoft Word 2016 (KB4011730) 64-Bit Edition - (13) 10-
2018
[Applications] :HKLM {90160000-0011-0000-1000-
0000000FF1CE}_Office16.PROPLUS_{D6AE0D54-13A7-4B0D-A862-8AEF7D4796A6}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-0011-0000-1000-0000000FF1CE}" "{D6AE0D54-13A7-4B0D-A862-8AEF7D4796A6}"
"1033" "0"
### Update for Microsoft Office 2016 (KB2920678) 64-Bit Edition - (13) 10-2018
[Applications] :HKLM {90160000-0011-0000-1000-
0000000FF1CE}_Office16.PROPLUS_{D9DCE570-856D-4813-80FC-17515D72E608}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-0011-0000-1000-0000000FF1CE}" "{D9DCE570-856D-4813-80FC-17515D72E608}"
"1033" "0"
### Update for Microsoft OneNote 2016 (KB4011733) 64-Bit Edition - (13) 10-2018
[Applications] :HKLM {90160000-0011-0000-1000-
0000000FF1CE}_Office16.PROPLUS_{C611D846-95F7-482D-A1DD-35E805BC82A6}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-0011-0000-1000-0000000FF1CE}" "{C611D846-95F7-482D-A1DD-35E805BC82A6}"
"1033" "0"
### Update for Skype for Business 2016 (KB4018323) 64-Bit Edition - (13) 10-2018
[Applications] :HKLM {90160000-0011-0000-1000-
0000000FF1CE}_Office16.PROPLUS_{B28924F7-8261-4281-9D1B-7255C301947E}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-0011-0000-1000-0000000FF1CE}" "{B28924F7-8261-4281-9D1B-7255C301947E}"
"1033" "0"
### Update for Microsoft Office 2016 (KB4011630) 64-Bit Edition - (13) 10-2018
[Applications] :HKLM {90160000-0011-0000-1000-
0000000FF1CE}_Office16.PROPLUS_{B65ED2DA-5B85-4CD8-8A15-821E8D7E78AB}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-0011-0000-1000-0000000FF1CE}" "{B65ED2DA-5B85-4CD8-8A15-821E8D7E78AB}"
"1033" "0"
### Update for Microsoft Publisher 2016 (KB3178696) 64-Bit Edition - (13) 10-2018
[Applications] :HKLM {90160000-0011-0000-1000-
0000000FF1CE}_Office16.PROPLUS_{DB9D4D82-852B-494B-A93C-CB228B2FB890}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-0011-0000-1000-0000000FF1CE}" "{DB9D4D82-852B-494B-A93C-CB228B2FB890}"
"1033" "0"
### Update for Microsoft Project 2016 (KB4018320) 64-Bit Edition - (13) 10-2018
[Applications] :HKLM {90160000-0011-0000-1000-
0000000FF1CE}_Office16.PROPLUS_{FF3C4299-6B38-4207-845A-DD8AEBAE2475}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-0011-0000-1000-0000000FF1CE}" "{FF3C4299-6B38-4207-845A-DD8AEBAE2475}"
"1033" "0"
### Security Update for Microsoft Office 2016 (KB4011574) 64-Bit Edition - (13)
10-2018
[Applications] :HKLM {90160000-0011-0000-1000-
0000000FF1CE}_Office16.PROPLUS_{FFCB61E2-D38E-4BE0-8511-95FEE12D0683}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-0011-0000-1000-0000000FF1CE}" "{FFCB61E2-D38E-4BE0-8511-95FEE12D0683}"
"1033" "0"
### Update for Microsoft Office 2016 (KB4011569) 64-Bit Edition - (13) 10-2018
[Applications] :HKLM {90160000-0011-0000-1000-
0000000FF1CE}_Office16.PROPLUS_{FE1D0112-B10B-44FC-A1B4-C4FE863CB5E0}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-0011-0000-1000-0000000FF1CE}" "{FE1D0112-B10B-44FC-A1B4-C4FE863CB5E0}"
"1033" "0"
### Security Update for Microsoft Office 2016 (KB4011143) 64-Bit Edition - (13)
10-2018
[Applications] :HKLM {90160000-0011-0000-1000-
0000000FF1CE}_Office16.PROPLUS_{E5C1DB83-9468-4CE0-947F-1CA99C32EAD2}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-0011-0000-1000-0000000FF1CE}" "{E5C1DB83-9468-4CE0-947F-1CA99C32EAD2}"
"1033" "0"
### Update for Microsoft OneDrive for Business (KB3178707) 64-Bit Edition - (13)
10-2018
[Applications] :HKLM {90160000-0011-0000-1000-
0000000FF1CE}_Office16.PROPLUS_{F3859B93-03A6-4D24-9C59-FAF8A930DBBB}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-0011-0000-1000-0000000FF1CE}" "{F3859B93-03A6-4D24-9C59-FAF8A930DBBB}"
"1033" "0"
### Update for Microsoft Office 2016 (KB3178666) 64-Bit Edition - (13) 10-2018
[Applications] :HKLM {90160000-0011-0000-1000-
0000000FF1CE}_Office16.PROPLUS_{B2437330-4140-4B97-8041-3D337D716DC9}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-0011-0000-1000-0000000FF1CE}" "{B2437330-4140-4B97-8041-3D337D716DC9}"
"1033" "0"
### Update for Microsoft Office 2016 (KB3118264) 64-Bit Edition - (13) 10-2018
[Applications] :HKLM {90160000-0011-0000-1000-
0000000FF1CE}_Office16.PROPLUS_{9E3A63D0-B0C8-455B-9E99-37F0B0CDC7FB}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-0011-0000-1000-0000000FF1CE}" "{9E3A63D0-B0C8-455B-9E99-37F0B0CDC7FB}"
"1033" "0"
### Update for Microsoft Office 2016 (KB3178662) 64-Bit Edition - (13) 10-2018
[Applications] :HKLM {90160000-0011-0000-1000-
0000000FF1CE}_Office16.PROPLUS_{A53508FE-AB9B-4EE4-90AD-2A1EBE903011}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-0011-0000-1000-0000000FF1CE}" "{A53508FE-AB9B-4EE4-90AD-2A1EBE903011}"
"1033" "0"
### Update for Microsoft Office 2016 (KB4011624) 64-Bit Edition - (13) 10-2018
[Applications] :HKLM {90160000-0011-0000-1000-
0000000FF1CE}_Office16.PROPLUS_{963E279F-A75D-4788-A0E7-9F693D46518B}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-0011-0000-1000-0000000FF1CE}" "{963E279F-A75D-4788-A0E7-9F693D46518B}"
"1033" "0"
### Update for Microsoft Office 2016 (KB4018322) 64-Bit Edition - (13) 10-2018
[Applications] :HKLM {90160000-0011-0000-1000-
0000000FF1CE}_Office16.PROPLUS_{92281B72-2A8C-40A4-BD15-58CCDF7DEDB1}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-0011-0000-1000-0000000FF1CE}" "{92281B72-2A8C-40A4-BD15-58CCDF7DEDB1}"
"1033" "0"
### Update for Microsoft Office 2016 (KB3114903) 64-Bit Edition - (13) 10-2018
[Applications] :HKLM {90160000-0011-0000-1000-
0000000FF1CE}_Office16.PROPLUS_{94848838-9497-4F39-8294-CFB65614776A}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-0011-0000-1000-0000000FF1CE}" "{94848838-9497-4F39-8294-CFB65614776A}"
"1033" "0"
### Update for Microsoft Office 2016 (KB3118263) 64-Bit Edition - (13) 10-2018
[Applications] :HKLM {90160000-0011-0000-1000-
0000000FF1CE}_Office16.PROPLUS_{A5E6E836-C0F0-4D98-B36B-C70516737EFD}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-0011-0000-1000-0000000FF1CE}" "{A5E6E836-C0F0-4D98-B36B-C70516737EFD}"
"1033" "0"
### Update for Microsoft Office 2016 (KB4011667) 64-Bit Edition - (13) 10-2018
[Applications] :HKLM {90160000-0011-0000-1000-
0000000FF1CE}_Office16.PROPLUS_{A73D1FF5-0819-44C7-9294-FBDD4BA2F43B}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-0011-0000-1000-0000000FF1CE}" "{A73D1FF5-0819-44C7-9294-FBDD4BA2F43B}"
"1033" "0"
### Update for Microsoft Office 2016 (KB2920712) 64-Bit Edition - (13) 10-2018
[Applications] :HKLM {90160000-0011-0000-1000-
0000000FF1CE}_Office16.PROPLUS_{AA7A282E-E962-4C45-9A74-16C49FD88FF1}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-0011-0000-1000-0000000FF1CE}" "{AA7A282E-E962-4C45-9A74-16C49FD88FF1}"
"1033" "0"
### Update for Microsoft Office 2016 (KB2920724) 64-Bit Edition - (13) 10-2018
[Applications] :HKLM {90160000-0011-0000-1000-
0000000FF1CE}_Office16.PROPLUS_{A7364D7B-4090-4536-AB7D-F80AA3A8995A}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-0011-0000-1000-0000000FF1CE}" "{A7364D7B-4090-4536-AB7D-F80AA3A8995A}"
"1033" "0"
### Update for Microsoft Office 2016 (KB3115281) 64-Bit Edition - (13) 10-2018
[Applications] :HKLM {90160000-0011-0000-1000-
0000000FF1CE}_Office16.PROPLUS_{A65F3D82-7DC0-42EE-9374-AA7BA1AA586A}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-0011-0000-1000-0000000FF1CE}" "{A65F3D82-7DC0-42EE-9374-AA7BA1AA586A}"
"1033" "0"
### Update for Microsoft Office 2016 (KB3191929) 64-Bit Edition - (13) 10-2018
[Applications] :HKLM {90160000-0011-0000-1000-
0000000FF1CE}_Office16.PROPLUS_{A6E4BACB-4E5F-40DE-904E-C089CDC2CB27}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-0011-0000-1000-0000000FF1CE}" "{A6E4BACB-4E5F-40DE-904E-C089CDC2CB27}"
"1033" "0"
### Update for Microsoft Office 2016 (KB4011562) 64-Bit Edition - (13) 10-2018
[Applications] :HKLM {90160000-0011-0000-1000-
0000000FF1CE}_Office16.PROPLUS_{18224882-1EA1-460B-8899-DD7F013C1EC7}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-0011-0000-1000-0000000FF1CE}" "{18224882-1EA1-460B-8899-DD7F013C1EC7}"
"1033" "0"
### Update for Microsoft Office 2016 (KB3213650) 64-Bit Edition - (13) 10-2018
[Applications] :HKLM {90160000-0011-0000-1000-
0000000FF1CE}_Office16.PROPLUS_{080ED49A-CDBE-45CE-9BFB-0CE21E50E732}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-0011-0000-1000-0000000FF1CE}" "{080ED49A-CDBE-45CE-9BFB-0CE21E50E732}"
"1033" "0"
### Security Update for Microsoft Access 2016 (KB4011665) 64-Bit Edition - (13)
10-2018
[Applications] :HKLM {90160000-0011-0000-1000-
0000000FF1CE}_Office16.PROPLUS_{02E071E3-BA0C-48C5-8D1E-6701065D1A3E}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-0011-0000-1000-0000000FF1CE}" "{02E071E3-BA0C-48C5-8D1E-6701065D1A3E}"
"1033" "0"
### Security Update for Microsoft Office 2016 (KB3115135) 64-Bit Edition - (13)
10-2018
[Applications] :HKLM {90160000-0011-0000-1000-
0000000FF1CE}_Office16.PROPLUS_{25377288-D71A-411E-A51D-EFB04F53E19F}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-0011-0000-1000-0000000FF1CE}" "{25377288-D71A-411E-A51D-EFB04F53E19F}"
"1033" "0"
### Update for Microsoft Visio 2016 (KB4011661) 64-Bit Edition - (13) 10-2018
[Applications] :HKLM {90160000-0011-0000-1000-
0000000FF1CE}_Office16.PROPLUS_{3697C03A-8A49-4622-9854-6FBE7AF537BF}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-0011-0000-1000-0000000FF1CE}" "{3697C03A-8A49-4622-9854-6FBE7AF537BF}"
"1033" "0"
### Update for Microsoft Office 2016 (KB4011729) 64-Bit Edition - (13) 10-2018
[Applications] :HKLM {90160000-0011-0000-1000-
0000000FF1CE}_Office16.PROPLUS_{34CE7F6F-F55C-487F-A89C-AD4D6D412BD3}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-0011-0000-1000-0000000FF1CE}" "{34CE7F6F-F55C-487F-A89C-AD4D6D412BD3}"
"1033" "0"
### Update for Microsoft Office 2016 (KB4018295) 64-Bit Edition - (13) 10-2018
[Applications] :HKLM {90160000-0011-0000-1000-
0000000FF1CE}_Office16.PROPLUS_{328D548A-FC7C-40E0-A87B-9676C059315B}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-0011-0000-1000-0000000FF1CE}" "{328D548A-FC7C-40E0-A87B-9676C059315B}"
"1033" "0"
### Update for Microsoft Office 2016 (KB4011259) 64-Bit Edition - (13) 10-2018
[Applications] :HKLM {90160000-0011-0000-1000-0000000FF1CE}=MsiExec.exe
/X{90160000-0011-0000-1000-0000000FF1CE}
### Microsoft Office Professional Plus 2016 - (13) 10-2018
[Applications] :HKLM {90160000-00C1-0000-1000-
0000000FF1CE}_Office16.PROPLUS_{53515168-F906-4C7C-8038-9EF0CEBC6EB5}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-00C1-0000-1000-0000000FF1CE}" "{53515168-F906-4C7C-8038-9EF0CEBC6EB5}"
"1033" "0"
### Update for Microsoft Office 2016 (KB3141457) 64-Bit Edition - (13) 10-2018
[Applications] :HKLM {90160000-00C1-0000-1000-
0000000FF1CE}_Office16.PROPLUS_{49ECA25A-7982-48D8-AA93-58C09E9D481A}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-00C1-0000-1000-0000000FF1CE}" "{49ECA25A-7982-48D8-AA93-58C09E9D481A}"
"1033" "0"
### Update for Microsoft PowerPoint 2016 (KB4011726) 64-Bit Edition - (13) 10-
2018
[Applications] :HKLM {90160000-00C1-0000-1000-
0000000FF1CE}_Office16.PROPLUS_{542634C3-CF0E-4EC6-91A7-FCF797695791}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-00C1-0000-1000-0000000FF1CE}" "{542634C3-CF0E-4EC6-91A7-FCF797695791}"
"1033" "0"
### Security Update for Microsoft Word 2016 (KB4011730) 64-Bit Edition - (13) 10-
2018
[Applications] :HKLM {90160000-00C1-0000-1000-
0000000FF1CE}_Office16.PROPLUS_{6BB390A3-FA2A-4F84-8004-D086564DE9E4}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-00C1-0000-1000-0000000FF1CE}" "{6BB390A3-FA2A-4F84-8004-D086564DE9E4}"
"1033" "0"
### Security Update for Microsoft Excel 2016 (KB4011727) 64-Bit Edition - (13)
10-2018
[Applications] :HKLM {90160000-00C1-0000-1000-
0000000FF1CE}_Office16.PROPLUS_{5A84393A-E440-48A1-BB99-AD1244AC0C35}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-00C1-0000-1000-0000000FF1CE}" "{5A84393A-E440-48A1-BB99-AD1244AC0C35}"
"1033" "0"
### Security Update for Microsoft Office 2016 (KB3085538) 64-Bit Edition - (13)
10-2018
[Applications] :HKLM {90160000-00C1-0000-1000-
0000000FF1CE}_Office16.PROPLUS_{3697C03A-8A49-4622-9854-6FBE7AF537BF}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-00C1-0000-1000-0000000FF1CE}" "{3697C03A-8A49-4622-9854-6FBE7AF537BF}"
"1033" "0"
### Update for Microsoft Office 2016 (KB4011729) 64-Bit Edition - (13) 10-2018
[Applications] :HKLM {90160000-00C1-0000-1000-
0000000FF1CE}_Office16.PROPLUS_{080ED49A-CDBE-45CE-9BFB-0CE21E50E732}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-00C1-0000-1000-0000000FF1CE}" "{080ED49A-CDBE-45CE-9BFB-0CE21E50E732}"
"1033" "0"
### Security Update for Microsoft Access 2016 (KB4011665) 64-Bit Edition - (13)
10-2018
[Applications] :HKLM {90160000-00C1-0000-1000-0000000FF1CE}=MsiExec.exe
/X{90160000-00C1-0000-1000-0000000FF1CE}
### Microsoft Office 32-bit Components 2016 - (13) 10-2018
[Applications] :HKLM {90160000-00C1-0000-1000-
0000000FF1CE}_Office16.PROPLUS_{18224882-1EA1-460B-8899-DD7F013C1EC7}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-00C1-0000-1000-0000000FF1CE}" "{18224882-1EA1-460B-8899-DD7F013C1EC7}"
"1033" "0"
### Update for Microsoft Office 2016 (KB3213650) 64-Bit Edition - (13) 10-2018
[Applications] :HKLM {90160000-00C1-0000-1000-
0000000FF1CE}_Office16.PROPLUS_{34CE7F6F-F55C-487F-A89C-AD4D6D412BD3}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-00C1-0000-1000-0000000FF1CE}" "{34CE7F6F-F55C-487F-A89C-AD4D6D412BD3}"
"1033" "0"
### Update for Microsoft Office 2016 (KB4018295) 64-Bit Edition - (13) 10-2018
[Applications] :HKLM {90160000-00C1-0000-1000-
0000000FF1CE}_Office16.PROPLUS_{25377288-D71A-411E-A51D-EFB04F53E19F}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-00C1-0000-1000-0000000FF1CE}" "{25377288-D71A-411E-A51D-EFB04F53E19F}"
"1033" "0"
### Update for Microsoft Visio 2016 (KB4011661) 64-Bit Edition - (13) 10-2018
[Applications] :HKLM {90160000-00C1-0000-1000-
0000000FF1CE}_Office16.PROPLUS_{D6AE0D54-13A7-4B0D-A862-8AEF7D4796A6}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-00C1-0000-1000-0000000FF1CE}" "{D6AE0D54-13A7-4B0D-A862-8AEF7D4796A6}"
"1033" "0"
### Update for Microsoft Office 2016 (KB2920678) 64-Bit Edition - (13) 10-2018
[Applications] :HKLM {90160000-00C1-0000-1000-
0000000FF1CE}_Office16.PROPLUS_{C611D846-95F7-482D-A1DD-35E805BC82A6}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-00C1-0000-1000-0000000FF1CE}" "{C611D846-95F7-482D-A1DD-35E805BC82A6}"
"1033" "0"
### Update for Skype for Business 2016 (KB4018323) 64-Bit Edition - (13) 10-2018
[Applications] :HKLM {90160000-00C1-0000-1000-
0000000FF1CE}_Office16.PROPLUS_{D9DCE570-856D-4813-80FC-17515D72E608}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-00C1-0000-1000-0000000FF1CE}" "{D9DCE570-856D-4813-80FC-17515D72E608}"
"1033" "0"
### Update for Microsoft OneNote 2016 (KB4011733) 64-Bit Edition - (13) 10-2018
[Applications] :HKLM {90160000-00C1-0000-1000-
0000000FF1CE}_Office16.PROPLUS_{E5C1DB83-9468-4CE0-947F-1CA99C32EAD2}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-00C1-0000-1000-0000000FF1CE}" "{E5C1DB83-9468-4CE0-947F-1CA99C32EAD2}"
"1033" "0"
### Update for Microsoft OneDrive for Business (KB3178707) 64-Bit Edition - (13)
10-2018
[Applications] :HKLM {90160000-00C1-0000-1000-
0000000FF1CE}_Office16.PROPLUS_{DB9D4D82-852B-494B-A93C-CB228B2FB890}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-00C1-0000-1000-0000000FF1CE}" "{DB9D4D82-852B-494B-A93C-CB228B2FB890}"
"1033" "0"
### Update for Microsoft Project 2016 (KB4018320) 64-Bit Edition - (13) 10-2018
[Applications] :HKLM {90160000-00C1-0000-1000-
0000000FF1CE}_Office16.PROPLUS_{B65ED2DA-5B85-4CD8-8A15-821E8D7E78AB}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-00C1-0000-1000-0000000FF1CE}" "{B65ED2DA-5B85-4CD8-8A15-821E8D7E78AB}"
"1033" "0"
### Update for Microsoft Publisher 2016 (KB3178696) 64-Bit Edition - (13) 10-2018
[Applications] :HKLM {90160000-00C1-0000-1000-
0000000FF1CE}_Office16.PROPLUS_{830268FA-EAD3-4BE1-BF80-0E5CCE01192F}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-00C1-0000-1000-0000000FF1CE}" "{830268FA-EAD3-4BE1-BF80-0E5CCE01192F}"
"1033" "0"
### Update for Microsoft Office 2016 (KB4011671) 64-Bit Edition - (13) 10-2018
[Applications] :HKLM {90160000-00C1-0000-1000-
0000000FF1CE}_Office16.PROPLUS_{7CB794F9-8C52-4DD4-B9A8-17FB5E66BEA9}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-00C1-0000-1000-0000000FF1CE}" "{7CB794F9-8C52-4DD4-B9A8-17FB5E66BEA9}"
"1033" "0"
### Update for Microsoft Office 2016 (KB4011031) 64-Bit Edition - (13) 10-2018
[Applications] :HKLM {90160000-00C1-0000-1000-
0000000FF1CE}_Office16.PROPLUS_{963E279F-A75D-4788-A0E7-9F693D46518B}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-00C1-0000-1000-0000000FF1CE}" "{963E279F-A75D-4788-A0E7-9F693D46518B}"
"1033" "0"
### Update for Microsoft Office 2016 (KB4018322) 64-Bit Edition - (13) 10-2018
[Applications] :HKLM {90160000-00C1-0000-1000-
0000000FF1CE}_Office16.PROPLUS_{B28924F7-8261-4281-9D1B-7255C301947E}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-00C1-0000-1000-0000000FF1CE}" "{B28924F7-8261-4281-9D1B-7255C301947E}"
"1033" "0"
### Update for Microsoft Office 2016 (KB4011630) 64-Bit Edition - (13) 10-2018
[Applications] :HKLM {90160000-00C1-0000-1000-
0000000FF1CE}_Office16.PROPLUS_{A5E6E836-C0F0-4D98-B36B-C70516737EFD}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-00C1-0000-1000-0000000FF1CE}" "{A5E6E836-C0F0-4D98-B36B-C70516737EFD}"
"1033" "0"
### Update for Microsoft Office 2016 (KB4011667) 64-Bit Edition - (13) 10-2018
[Applications] :HKLM {90160000-001B-0409-1000-
0000000FF1CE}_Office16.PROPLUS_{542634C3-CF0E-4EC6-91A7-FCF797695791}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-001B-0409-1000-0000000FF1CE}" "{542634C3-CF0E-4EC6-91A7-FCF797695791}"
"1033" "0"
### Security Update for Microsoft Word 2016 (KB4011730) 64-Bit Edition - (13) 10-
2018
[Applications] :HKLM {90160000-001B-0409-1000-
0000000FF1CE}_Office16.PROPLUS_{6BB390A3-FA2A-4F84-8004-D086564DE9E4}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-001B-0409-1000-0000000FF1CE}" "{6BB390A3-FA2A-4F84-8004-D086564DE9E4}"
"1033" "0"
### Security Update for Microsoft Excel 2016 (KB4011727) 64-Bit Edition - (13)
10-2018
[Applications] :HKLM {90160000-001B-0409-1000-0000000FF1CE}=MsiExec.exe
/X{90160000-001B-0409-1000-0000000FF1CE}
### Microsoft Word MUI (English) 2016 - (13) 10-2018
[Applications] :HKLM {90160000-001A-0409-1000-0000000FF1CE}=MsiExec.exe
/X{90160000-001A-0409-1000-0000000FF1CE}
### Microsoft Outlook MUI (English) 2016 - (13) 10-2018
[Applications] :HKLM {90160000-001A-0409-1000-
0000000FF1CE}_Office16.PROPLUS_{542634C3-CF0E-4EC6-91A7-FCF797695791}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-001A-0409-1000-0000000FF1CE}" "{542634C3-CF0E-4EC6-91A7-FCF797695791}"
"1033" "0"
### Security Update for Microsoft Word 2016 (KB4011730) 64-Bit Edition - (13) 10-
2018
[Applications] :HKLM {90160000-001A-0409-1000-
0000000FF1CE}_Office16.PROPLUS_{6DB5528D-2F8F-4C67-84C2-1578B9052F03}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-001A-0409-1000-0000000FF1CE}" "{6DB5528D-2F8F-4C67-84C2-1578B9052F03}"
"1033" "0"
### Update for Microsoft Outlook 2016 (KB4018326) 64-Bit Edition - (13) 10-2018
[Applications] :HKLM {90160000-012B-0409-1000-0000000FF1CE}=MsiExec.exe
/X{90160000-012B-0409-1000-0000000FF1CE}
### Microsoft Skype for Business MUI (English) 2016 - (13) 10-2018
[Applications] :HKLM {90160000-012B-0409-1000-
0000000FF1CE}_Office16.PROPLUS_{542634C3-CF0E-4EC6-91A7-FCF797695791}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-012B-0409-1000-0000000FF1CE}" "{542634C3-CF0E-4EC6-91A7-FCF797695791}"
"1033" "0"
### Security Update for Microsoft Word 2016 (KB4011730) 64-Bit Edition - (13) 10-
2018
[Applications] :HKLM {90160000-012B-0409-1000-
0000000FF1CE}_Office16.PROPLUS_{C611D846-95F7-482D-A1DD-35E805BC82A6}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-012B-0409-1000-0000000FF1CE}" "{C611D846-95F7-482D-A1DD-35E805BC82A6}"
"1033" "0"
### Update for Skype for Business 2016 (KB4018323) 64-Bit Edition - (13) 10-2018
[Applications] :HKLM {90160000-0019-0409-1000-0000000FF1CE}=MsiExec.exe
/X{90160000-0019-0409-1000-0000000FF1CE}
### Microsoft Publisher MUI (English) 2016 - (13) 10-2018
[Applications] :HKLM {90160000-0019-0409-1000-
0000000FF1CE}_Office16.PROPLUS_{B65ED2DA-5B85-4CD8-8A15-821E8D7E78AB}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-0019-0409-1000-0000000FF1CE}" "{B65ED2DA-5B85-4CD8-8A15-821E8D7E78AB}"
"1033" "0"
### Update for Microsoft Publisher 2016 (KB3178696) 64-Bit Edition - (13) 10-2018
[Applications] :HKLM {90160000-001F-040C-1000-
0000000FF1CE}_Office16.PROPLUS_{9E3A63D0-B0C8-455B-9E99-37F0B0CDC7FB}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-001F-040C-1000-0000000FF1CE}" "{9E3A63D0-B0C8-455B-9E99-37F0B0CDC7FB}"
"1033" "0"
### Update for Microsoft Office 2016 (KB3178662) 64-Bit Edition - (13) 10-2018
[Applications] :HKLM {90160000-001F-040C-1000-0000000FF1CE}=MsiExec.exe
/X{90160000-001F-040C-1000-0000000FF1CE}
### Outils de v�rification linguistique 2016 de Microsoft Office�- Fran�ais -
(13) 10-2018
[Applications] :HKLM {90160000-001F-0C0A-1000-
0000000FF1CE}_Office16.PROPLUS_{9E3A63D0-B0C8-455B-9E99-37F0B0CDC7FB}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-001F-0C0A-1000-0000000FF1CE}" "{9E3A63D0-B0C8-455B-9E99-37F0B0CDC7FB}"
"1033" "0"
### Update for Microsoft Office 2016 (KB3178662) 64-Bit Edition - (13) 10-2018
[Applications] :HKLM {90160000-001F-0C0A-1000-0000000FF1CE}=MsiExec.exe
/X{90160000-001F-0C0A-1000-0000000FF1CE}
### Herramientas de correcci�n de Microsoft Office 2016: espa�ol - (13) 10-2018
[Applications] :HKLM {90160000-001F-0409-1000-
0000000FF1CE}_Office16.PROPLUS_{9E3A63D0-B0C8-455B-9E99-37F0B0CDC7FB}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-001F-0409-1000-0000000FF1CE}" "{9E3A63D0-B0C8-455B-9E99-37F0B0CDC7FB}"
"1033" "0"
### Update for Microsoft Office 2016 (KB3178662) 64-Bit Edition - (13) 10-2018
[Applications] :HKLM {90160000-001F-0409-1000-0000000FF1CE}=MsiExec.exe
/X{90160000-001F-0409-1000-0000000FF1CE}
### Microsoft Office Proofing Tools 2016 - English - (13) 10-2018
[Applications] :HKLM {90160000-0018-0409-1000-0000000FF1CE}=MsiExec.exe
/X{90160000-0018-0409-1000-0000000FF1CE}
### Microsoft PowerPoint MUI (English) 2016 - (13) 10-2018
[Applications] :HKLM {90160000-0018-0409-1000-
0000000FF1CE}_Office16.PROPLUS_{49ECA25A-7982-48D8-AA93-58C09E9D481A}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-0018-0409-1000-0000000FF1CE}" "{49ECA25A-7982-48D8-AA93-58C09E9D481A}"
"1033" "0"
### Update for Microsoft PowerPoint 2016 (KB4011726) 64-Bit Edition - (13) 10-
2018
[Applications] :HKLM {90160000-0018-0409-1000-
0000000FF1CE}_Office16.PROPLUS_{6BB390A3-FA2A-4F84-8004-D086564DE9E4}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-0018-0409-1000-0000000FF1CE}" "{6BB390A3-FA2A-4F84-8004-D086564DE9E4}"
"1033" "0"
### Security Update for Microsoft Excel 2016 (KB4011727) 64-Bit Edition - (13)
10-2018
[Applications] :HKLM {90160000-006E-0409-1000-
0000000FF1CE}_Office16.PROPLUS_{FF3C4299-6B38-4207-845A-DD8AEBAE2475}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-006E-0409-1000-0000000FF1CE}" "{FF3C4299-6B38-4207-845A-DD8AEBAE2475}"
"1033" "0"
### Security Update for Microsoft Office 2016 (KB4011574) 64-Bit Edition - (13)
10-2018
[Applications] :HKLM {90160000-006E-0409-1000-
0000000FF1CE}_Office16.PROPLUS_{34CE7F6F-F55C-487F-A89C-AD4D6D412BD3}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-006E-0409-1000-0000000FF1CE}" "{34CE7F6F-F55C-487F-A89C-AD4D6D412BD3}"
"1033" "0"
### Update for Microsoft Office 2016 (KB4018295) 64-Bit Edition - (13) 10-2018
[Applications] :HKLM {90160000-006E-0409-1000-0000000FF1CE}=MsiExec.exe
/X{90160000-006E-0409-1000-0000000FF1CE}
### Microsoft Office Shared MUI (English) 2016 - (13) 10-2018
[Applications] :HKLM {90160000-006E-0409-1000-
0000000FF1CE}_Office16.PROPLUS_{A5E6E836-C0F0-4D98-B36B-C70516737EFD}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-006E-0409-1000-0000000FF1CE}" "{A5E6E836-C0F0-4D98-B36B-C70516737EFD}"
"1033" "0"
### Update for Microsoft Office 2016 (KB4011667) 64-Bit Edition - (13) 10-2018
[Applications] :HKLM {90160000-006E-0409-1000-
0000000FF1CE}_Office16.PROPLUS_{963E279F-A75D-4788-A0E7-9F693D46518B}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-006E-0409-1000-0000000FF1CE}" "{963E279F-A75D-4788-A0E7-9F693D46518B}"
"1033" "0"
### Update for Microsoft Office 2016 (KB4018322) 64-Bit Edition - (13) 10-2018
[Applications] :HKLM {90160000-006E-0409-1000-
0000000FF1CE}_Office16.PROPLUS_{7AFED019-B612-489B-B369-2920C6B5A96D}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-006E-0409-1000-0000000FF1CE}" "{7AFED019-B612-489B-B369-2920C6B5A96D}"
"1033" "0"
### Security Update for Microsoft Office 2016 (KB3213551) 64-Bit Edition - (13)
10-2018
[Applications] :HKLM {90160000-006E-0409-1000-
0000000FF1CE}_Office16.PROPLUS_{4EAC16BA-08BE-44DE-AD3D-4FF4C309CCFE}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-006E-0409-1000-0000000FF1CE}" "{4EAC16BA-08BE-44DE-AD3D-4FF4C309CCFE}"
"1033" "0"
### Security Update for Microsoft Office 2016 (KB4011185) 64-Bit Edition - (13)
10-2018
[Applications] :HKLM {90160000-00A1-0409-1000-
0000000FF1CE}_Office16.PROPLUS_{D9DCE570-856D-4813-80FC-17515D72E608}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-00A1-0409-1000-0000000FF1CE}" "{D9DCE570-856D-4813-80FC-17515D72E608}"
"1033" "0"
### Update for Microsoft OneNote 2016 (KB4011733) 64-Bit Edition - (13) 10-2018
[Applications] :HKLM {90160000-00A1-0409-1000-0000000FF1CE}=MsiExec.exe
/X{90160000-00A1-0409-1000-0000000FF1CE}
### Microsoft OneNote MUI (English) 2016 - (13) 10-2018
[Applications] :HKLM {90160000-00C1-0409-1000-
0000000FF1CE}_Office16.PROPLUS_{A5E6E836-C0F0-4D98-B36B-C70516737EFD}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-00C1-0409-1000-0000000FF1CE}" "{A5E6E836-C0F0-4D98-B36B-C70516737EFD}"
"1033" "0"
### Update for Microsoft Office 2016 (KB4011667) 64-Bit Edition - (13) 10-2018
[Applications] :HKLM {90160000-00C1-0409-1000-
0000000FF1CE}_Office16.PROPLUS_{34CE7F6F-F55C-487F-A89C-AD4D6D412BD3}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-00C1-0409-1000-0000000FF1CE}" "{34CE7F6F-F55C-487F-A89C-AD4D6D412BD3}"
"1033" "0"
### Update for Microsoft Office 2016 (KB4018295) 64-Bit Edition - (13) 10-2018
[Applications] :HKLM {90160000-00C1-0409-1000-0000000FF1CE}=MsiExec.exe
/X{90160000-00C1-0409-1000-0000000FF1CE}
### Microsoft Office Shared 32-bit MUI (English) 2016 - (13) 10-2018
[Applications] :HKLM {90160000-00C1-0409-1000-
0000000FF1CE}_Office16.PROPLUS_{E5C1DB83-9468-4CE0-947F-1CA99C32EAD2}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-00C1-0409-1000-0000000FF1CE}" "{E5C1DB83-9468-4CE0-947F-1CA99C32EAD2}"
"1033" "0"
### Update for Microsoft OneDrive for Business (KB3178707) 64-Bit Edition - (13)
10-2018
[Applications] :HKLM {90160000-00BA-0409-1000-
0000000FF1CE}_Office16.PROPLUS_{E5C1DB83-9468-4CE0-947F-1CA99C32EAD2}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-00BA-0409-1000-0000000FF1CE}" "{E5C1DB83-9468-4CE0-947F-1CA99C32EAD2}"
"1033" "0"
### Update for Microsoft OneDrive for Business (KB3178707) 64-Bit Edition - (13)
10-2018
[Applications] :HKLM {90160000-00BA-0409-1000-0000000FF1CE}=MsiExec.exe
/X{90160000-00BA-0409-1000-0000000FF1CE}
### Microsoft Groove MUI (English) 2016 - (13) 10-2018
[Applications] :HKLM {90160000-0016-0409-1000-
0000000FF1CE}_Office16.PROPLUS_{6BB390A3-FA2A-4F84-8004-D086564DE9E4}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-0016-0409-1000-0000000FF1CE}" "{6BB390A3-FA2A-4F84-8004-D086564DE9E4}"
"1033" "0"
### Security Update for Microsoft Excel 2016 (KB4011727) 64-Bit Edition - (13)
10-2018
[Applications] :HKLM {90160000-0016-0409-1000-
0000000FF1CE}_Office16.PROPLUS_{3AF87AAA-17AE-4BD0-AAC6-86BA5DF1115E}="C:\Program
Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch
"{90160000-0016-0409-1000-0000000FF1CE}" "{3AF87AAA-17AE-4BD0-AAC6-86BA5DF1115E}"
"1033" "0"
### Update for Microsoft Office 2016 (KB4011218) 64-Bit Edition - (13) 10-2018
[Applications] :HKLM {90160000-0016-0409-1000-0000000FF1CE}=MsiExec.exe
/X{90160000-0016-0409-1000-0000000FF1CE}
### Microsoft Excel MUI (English) 2016 - (13) 10-2018
[Applications] :HKLM Office16.PROPLUS="C:\Program Files\Common Files\Microsoft
Shared\OFFICE16\Office Setup Controller\setup.exe" /uninstall PROPLUS /dll
OSETUP.DLL
### Microsoft Office Professional Plus 2016 - (13) 10-2018
[Applications] :HKLM {90160000-00E2-0409-1000-0000000FF1CE}=MsiExec.exe
/X{90160000-00E2-0409-1000-0000000FF1CE}
### Microsoft Office OSM UX MUI (English) 2016 - (13) 10-2018
[Applications] :HKLM {90160000-0044-0409-1000-0000000FF1CE}=MsiExec.exe
/X{90160000-0044-0409-1000-0000000FF1CE}
### Microsoft InfoPath MUI (English) 2016 - (13) 10-2018
[Applications] :HKLM {90160000-0090-0409-1000-0000000FF1CE}=MsiExec.exe
/X{90160000-0090-0409-1000-0000000FF1CE}
### Microsoft DCF MUI (English) 2016 - (13) 10-2018
[Applications] :HKLM {90160000-00E1-0409-1000-0000000FF1CE}=MsiExec.exe
/X{90160000-00E1-0409-1000-0000000FF1CE}
### Microsoft Office OSM MUI (English) 2016 - (13) 10-2018
[Applications] :HKLM {90160000-0117-0409-1000-0000000FF1CE}=MsiExec.exe
/X{90160000-0117-0409-1000-0000000FF1CE}
### Microsoft Access Setup Metadata MUI (English) 2016 - (13) 10-2018
[Applications] :HKLM {90160000-0015-0409-1000-0000000FF1CE}=MsiExec.exe
/X{90160000-0015-0409-1000-0000000FF1CE}
### Microsoft Access MUI (English) 2016 - (13) 10-2018
[Applications] :HKLM {90160000-002C-0409-1000-0000000FF1CE}=MsiExec.exe
/X{90160000-002C-0409-1000-0000000FF1CE}
### Microsoft Office Proofing (English) 2016 - (13) 10-2018
[Applications] :HKLM {90160000-0115-0409-1000-0000000FF1CE}=MsiExec.exe
/X{90160000-0115-0409-1000-0000000FF1CE}
### Microsoft Office Shared Setup Metadata MUI (English) 2016 - (13) 10-2018
[Applications] :HKLM CCleaner="C:\Program Files\CCleaner\uninst.exe"
### CCleaner - (13) 10-2018
[Applications] :HKLM SynTPDeinstKey=rundll32.exe "%ProgramFiles
%\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
### Dell Touchpad - (13) 10-2018
[Applications] :HKLM {28006915-2739-4EBE-B5E8-49B25D32EB33}="C:\Program Files
(x86)\InstallShield Installation Information\{28006915-2739-4EBE-B5E8-
49B25D32EB33}\Setup.exe" -runfromtemp -l0x0409 -removeonly
### Dell WLAN and Bluetooth Client Installation - (13) 10-2018
[Applications] :HKLM {A84A4FB1-D703-48DB-89E0-68B6499D2801}
### Qualcomm Atheros Bluetooth Suite (64) - (13) 10-2018
[Applications] :HKLM {60EC980A-BDA2-4CB6-A427-B07A5498B4CA}=MsiExec.exe
/I{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}
### Google Update Helper - (13) 10-2018
[Applications] :HKLM {F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}=C:\Program
Files\Realtek\Audio\HDA\RtlUpd64.exe -r -m -nrg2709
### Realtek High Definition Audio Driver - (13) 10-2018
[Applications] :HKLM {ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}=MsiExec.exe
/X{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}
### Microsoft Visual C++ 2005 Redistributable (x64) - (13) 10-2018
[Applications] :HKLM {5BC2B5AB-80DE-4E83-B8CF-426902051D0A}="C:\Program Files
(x86)\InstallShield Installation Information\{5BC2B5AB-80DE-4E83-B8CF-
426902051D0A}\Setup.exe" -runfromtemp -removeonly
### Realtek Card Reader - (13) 10-2018
[Applications] :HKLM Google Chrome="C:\Program Files
(x86)\Google\Chrome\Application\69.0.3497.100\Installer\setup.exe" --uninstall
--system-level --verbose-logging
### Google Chrome - (13) 10-2018
[Applications] :HKLM WinRAR archiver=C:\Program Files\WinRAR\uninstall.exe
### WinRAR 5.50 (64-bit) - (13) 10-2018
[Applications] :HKLM Foxit Reader_is1="C:\Program Files (x86)\Foxit
Software\Foxit Reader\unins000.exe" /SILENT
### Foxit Reader - (13) 10-2018
[Applications] :HKLM VLC media player="C:\Program
Files\VideoLAN\VLC\uninstall.exe"
### VLC media player - (13) 10-2018
[Applications] :HKCU
OneDriveSetup.exe=C:\Users\sukan\AppData\Local\Microsoft\OneDrive\18.143.0717.0002\
OneDriveSetup.exe /uninstall
### Microsoft OneDrive - (13) 10-2018
[Applications] :HKLM MPlayer2
### - (15) 09-2018
[Applications] :HKLM DXM_Runtime
### - (15) 09-2018
[Applications] :HKLM DXM_Runtime
### - (15) 09-2018
[Applications] :HKLM MPlayer2
### - (15) 09-2018
[Applications] :HKLM DirectDrawEx
### - (15) 09-2018
[Applications] :HKLM IE40
### - (15) 09-2018
[Applications] :HKLM WIC
### - (15) 09-2018
[Applications] :HKLM AddressBook
### - (15) 09-2018
[Applications] :HKLM Connection Manager
### - (15) 09-2018
[Applications] :HKLM IEData
### - (15) 09-2018
[Applications] :HKLM IE5BAKEX
### - (15) 09-2018
[Applications] :HKLM IE4Data
### - (15) 09-2018
[Applications] :HKLM MobileOptionPack
### - (15) 09-2018
[Applications] :HKLM SchedulingAgent
### - (15) 09-2018
[Applications] :HKLM Fontcore
### - (15) 09-2018
[Applications] :HKLM Fontcore
### - (15) 09-2018
[Applications] :HKLM IE40
### - (15) 09-2018
[Applications] :HKLM IE5BAKEX
### - (15) 09-2018
[Applications] :HKLM IE4Data
### - (15) 09-2018
[Applications] :HKLM SchedulingAgent
### - (15) 09-2018
[Applications] :HKLM AddressBook
### - (15) 09-2018
[Applications] :HKLM Connection Manager
### - (15) 09-2018
[Applications] :HKLM DirectDrawEx
### - (15) 09-2018
[Applications] :HKLM WIC
### - (15) 09-2018
[Applications] :HKLM MobileOptionPack
### - (15) 09-2018
[Applications] :HKLM IEData
### - (15) 09-2018
[MD5]
[F9F69A0B2568EA1CD55B735A0A386606][1 2179376
4E8FC37C8A5A38BE68CB146481E87E47E44599F5 ]
C:\PROGRA~1\MICROS~1\OFFICE16\GROOVEEX.DLL
[8B9F2CF0C3EED9E98EA4795A9585B6B9][1 1524016
F5820F88B7AB92A343FDB5D10D6B3DDF4967A58F ]
C:\PROGRA~2\MICROS~1\OFFICE16\GROOVEEX.DLL
[9012FF88724B4C9C82DC176E9B3BD788][1 63232
3E2EFC62EE64FD25E39FBF591030528B0BF9BA39 ]C:\PROGRAM FILES (X86)\COMMON
FILES\MICROSOFT SHARED\OFFICE16\MSOXMLMF.DLL
[924CFBC423AEC4175BF016155B8909B1][2 323152
29FB6C4A805EBFBA8F631EFE2DEE7A9F67380AB4 ]C:\PROGRAM FILES (X86)\DELL
WIRELESS\BLUETOOTH SUITE\ADMINSERVICE.EXE
[02C0D16BBEF9C7CCE913D22BF01B2987][1 1659592
]C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\FOXIT READER\FOXITCONNECTEDPDFSERVICE.EXE
[CE8A7CA22D2EAB00D09E25E5FEC0DB9F][1 54778568
]C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\FOXIT READER\FOXITREADER.EXE
[F8BA54AD76C8F8EC9F3D639871B30F27][1 1469784
D42EA42B362442299195A82CFB998F10B11AF868 ]C:\PROGRAM FILES
(X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE
[6C718849D436A7CCEBED72538F8BD04B][1 288848
E8217EFAFC6A679EAA9FCD5E9C46E2975F60997E ]C:\PROGRAM FILES
(X86)\GOOGLE\UPDATE\1.3.33.17\GOOGLECRASHHANDLER.EXE
[D2F56E366F1CB26866A6F43BD53B46C3][1 366160
A84063A7544D8031912D76A00A90DD058BC8D49C ]C:\PROGRAM FILES
(X86)\GOOGLE\UPDATE\1.3.33.17\GOOGLECRASHHANDLER64.EXE
[605CCC9CE1839BC5583017DF7CAE27A6][1 153168
AE73B2E2EA5DCA80C5A98907A6786124EDAA7623 ]C:\PROGRAM FILES
(X86)\GOOGLE\UPDATE\GOOGLEUPDATE.EXE
[3733ACF8E93D0F73EA35FA2CB738B723][2 4096056
43E6CC1BEA39C11697C2ED57E54C68FDB724D56D ]C:\PROGRAM FILES (X86)\INTERNET
DOWNLOAD MANAGER\IDMAN.EXE
[2CC2D84CFD0694CA53FCFF43670F1EBA][1 453688
]C:\PROGRAM FILES (X86)\INTERNET DOWNLOAD MANAGER\IDMIECC.DLL
[9AF02944DA6A9C2C82790E4B21A7A470][1 528440
]C:\PROGRAM FILES (X86)\INTERNET DOWNLOAD MANAGER\IDMIECC64.DLL
[B289C20C10B241F6016FECD92B267098][1 275512
]C:\PROGRAM FILES (X86)\INTERNET DOWNLOAD MANAGER\IEMONITOR.EXE
[B58E7316785596F9918AED57B33DDA25][1 151784
EA59C2E15CD7BA468447727222E1B1676CE2A4F2 ]C:\PROGRAM FILES (X86)\MICROSOFT
OFFICE\OFFICE16\MSOSB.DLL
[7CA2C84A3CB5A4C55150A9FCD60CC1FF][1 171192
7E1D7D7FA45240F61E362658B043CDF1DF1B1A67 ]C:\PROGRAM FILES (X86)\MICROSOFT
OFFICE\OFFICE16\OCHELPER.DLL
[DFCBA29A5A6637FA0A8196C086A13371][1 1148832
]C:\PROGRAM FILES (X86)\SDA\SD FORMATTER\SDFORMATTER.EXE
[C19ED5A3B0C5DFEF7F1EBEF02CCBAEEA][1 807368
]C:\PROGRAM FILES (X86)\SHAREIT TECHNOLOGIES\SHAREIT\SHAREIT.EXE
[FCB8DD20046D231611EC4D3E466BAD45][1 33224
]C:\PROGRAM FILES (X86)\SHAREIT TECHNOLOGIES\SHAREIT\SHAREIT.SERVICE.EXE
[FFE2D028D996BC6279A2E4894F9FCBFD][1 7456984
9A781523D1D01AB0BB74C8B700910891B422F9FE ]C:\PROGRAM FILES\CCLEANER\CCLEANER.EXE
[638AE77DC319958727FBEA403D37B2D6][1 9532120
7C5590DD3C06D844ABEE1E992E538257FCE27EEC ]C:\PROGRAM
FILES\CCLEANER\CCLEANER64.EXE
[97BED53AF0A644ECEA40DE5AB75A7067][1 253128
1AEF26E9CE22468F05681DEE1E84A727CF0ED24D ]C:\PROGRAM FILES\COMMON
FILES\MICROSOFT SHARED\SOURCE ENGINE\OSE.EXE
[EAC888C884C5AE875B16E8C714B4D2E6][1 826704
021415D73D02C6247001BAD6E5C9BC6E220F34FC ]C:\PROGRAM FILES\INTERNET
EXPLORER\IEXPLORE.EXE
[FB7FBBFAD6F56D8D9C5199EC2B7D15F8][1 236720
5F16DE849C36C6AB474ABF0B44274D9D4AE74B9E ]C:\PROGRAM FILES\MICROSOFT
OFFICE\OFFICE16\OCHELPER.DLL
[BC5A40AEAC1CF7708D07CBC2F577F90B][1 1411320
B47F573487CDEA9D4D0307A617F73C1F428C52FB ]C:\PROGRAM
FILES\REALTEK\AUDIO\HDA\RAVBG64.EXE
[DBE1ADA144291F8E0F29ECC40AE14562][1 312056
0F83ED4DFBBBCB822D30AEC4F6DBFF0C12451FF3 ]C:\PROGRAM
FILES\REALTEK\AUDIO\HDA\RTKAUDIOSERVICE64.EXE
[641B19018CB32619ADBD0AED4964E1D9][1 8512760
0D7FC7714B9D71DBE4329360A91DC6844C9666B3 ]C:\PROGRAM
FILES\REALTEK\AUDIO\HDA\RTKNGUI64.EXE
[60229D15D4B8022678C604550DB05BD1][1 3935400
89D9201F0CB0E3A40B223EF6946EFD8A7E59D2FE ]C:\PROGRAM
FILES\SYNAPTICS\SYNTP\SYNTPENH.EXE
[50C644D09E79A9BF47CDD5A39EC6F876][1 201384
301DB5E232AE7BEB3DD40057BC84F49C78DB34C9 ]C:\PROGRAM
FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE
[D0CA1D05B5615808E6601113030C3666][1 985800
]C:\PROGRAM FILES\VIDEOLAN\VLC\VLC.EXE
[393B2DADF99EEF3B081BC0E455BCAFFD][1 5381624
1214F633F442421CCE34CCB120C830EB9130352C ]C:\PROGRAM FILES\WINDOWS DEFENDER
ADVANCED THREAT PROTECTION\MSSENSE.EXE
[CEDC4E5155D9D48F2922C21EC02419B7][1 110944
82E7FFB4E780BF16F3C42D52E2C6B0A4EF48732C ]C:\PROGRAM FILES\WINDOWS
DEFENDER\MSMPENG.EXE
[A067A0D2C1C5F9BBA10E5ABF9B6B5A42][1 3830488
37FC308C3F4E03C664321CC76F154929F2D12A5D ]C:\PROGRAM FILES\WINDOWS
DEFENDER\NISSRV.EXE
[DA094771C21F8FD92C4A68312A087A4D][1 1114112
90E41A9A15318D64135CEED624D8345FB04929E7 ]C:\PROGRAM FILES\WINDOWS MEDIA
PLAYER\WMPNETWK.EXE
[39D901F323BB584EABFE21FE1CEA809C][1 4549120
405A7B01EAEBC2F0A30622ECF26DEB8ED4659E7C ]C:\PROGRAM FILES\WINDOWS
NT\ACCESSORIES\WORDPAD.EXE
[893899F428647F2569F7FEABD59E83E2][2 16384
0F707655B73838667BE6F9AF80426B2C3CFAA0DD ]C:\PROGRAM
FILES\WINDOWSAPPS\MICROSOFT.WINDOWSSTORE_11805.1001.49.0_X64__8WEKYB3D8BBWE\WINSTOR
E.APP.EXE
[E3438A61D11253AFF1698942777C19E2][1 369368
]C:\PROGRAM FILES\WINRAR\RAREXT32.DLL
[F6AAC412E5E73C5D4064F1D51EEE442F][1 1193880
300E50735048016F4D38CAF816154CFDBE5A4FBA ]C:\UNHACKME\HACKMON.EXE
[76B135A15F550B044A52C98B59B606FC][1 11202968
E48CA8B575F8FCB5901AF028C2F3EE28F35218B8 ]C:\UNHACKME\REANIMATOR.EXE
[E0EC94CC481580CDAED257B210C880C6][1 2560920
1316FAF0487EFA7649E2AC6A1D3616AAF18664D6 ]C:\UNHACKME\UNHACKME.EXE
[2192B5059195D40C7A737BCFCC04ABB2][1 1645368
1D103964AF1AB922252CE1091E906ABDEBB024B7 ]
C:\USERS\SUKAN\APPDATA\LOCAL\MICROSOFT\ONEDRIVE\ONEDRIVE.EXE
[5BDB5A69952DEC775BA91677781FF506][1 2458944
36FF52122E9EE3573104E337CDA7DAAA0DA4B37C ]
C:\USERS\SUKAN\APPDATA\LOCAL\MICROSOFT\ONEDRIVE\ONEDRIVESTANDALONEUPDATER.EXE
[6A65873EA949C5CCC72DDEF9E9780AA5][1 4245072
59AB8548708342C77C51F70EEC5CED0A88DC4701 ]C:\WINDOWS\EXPLORER.EXE
[5EF8B333C40A3D177DB17B4590BC885C][1 43632
83C442EC7C55DFFC05860A157B6D0A80678F5313 ]
C:\WINDOWS\MICROSOFT.NET\FRAMEWORK64\V3.0\WPF\PRESENTATIONFONTCACHE.EXE
[65EA3086C7F28BA5982043D2491B8856][1 136272
1D655E5D9425D212B9643B97DC64F103293D1BDA ]
C:\WINDOWS\MICROSOFT.NET\FRAMEWORK64\V4.0.30319\SMSVCHOST.EXE
[59D38A41008A7A229273D8AF693ADBAC][1 169472
9E85C1DA4FB0C51D39BD648DA34C416807677184 ]
C:\WINDOWS\SERVICING\TRUSTEDINSTALLER.EXE
[785A1493731880AE44C7E6C46CCA004E][1 198656
53691F701144231EFCC1A8D65B321A0458A62875 ]C:\WINDOWS\SYSNATIVE\APPMGMTS.DLL
[F7A3878E9059A8E1E3CB7CE74A539201][1 1295360
E6F31B5EB48B1EDEC377D93D861F4B7FA209FC17 ]C:\WINDOWS\SYSNATIVE\COMRES.DLL
[B6408E917726CF5AE115CD939940EA38][1 13824
0C53542A338A30C309F25811F579A47331987FB6 ]C:\WINDOWS\SYSNATIVE\D3D8THK.DLL
[0222ED97F392077F05A7CC6C0E259850][1 583680
B8108C3FCF08164A4A6FC9742D98E7F3860AE16E ]C:\WINDOWS\SYSNATIVE\DDRAW.DLL
[018D6E7BA23E28ECA0CB7F071A9FF291][1 799568
D6EF59BC2F0469392EB1FCFA4C8D625A7CD868D6 ]C:\Windows\SYSNATIVE\DNSAPI.DLL
[9FAD8034D504201B557BD82E824F9EFC][1 593920
E3D997FF4F7B940EDDE5CA898F58F4C611E20622 ]C:\WINDOWS\SYSNATIVE\DSOUND.DLL
[2354C6B55E174B46EBF3147EA3114777][1 400384
14114BFCD246CCA783D3B7F762FC0B33F7374CA9 ]C:\WINDOWS\SYSNATIVE\HNETCFG.DLL
[A5CF51E5938BC3B36F035678EADFFAD3][1 177384
23D5E7B79893CAB4A777D9CE48A4DDF6B9168408 ]C:\WINDOWS\SYSNATIVE\IMM32.DLL
[190053992A600E1E07D82B3AFD59A855][1 241712
2BFEB5E05056BF5991C76204D8C4E4CFBB6E9164 ]C:\WINDOWS\SYSNATIVE\IPHLPAPI.DLL
[ABF80D6CA310317D10DA580BC59D0202][1 23264
AA6F5993EEDF45CCA689DF2E5C5E25218920363A ]C:\WINDOWS\SYSNATIVE\KSUSER.DLL
[9A62F0FCAEE1DA5C047F763495A5FF54][1 3072
A465336592201048F104C02F1B2E070D135A9D1A ]C:\WINDOWS\SYSNATIVE\LPK.DLL
[B56AAB10E981BB84A6CB076CF1CE8A6A][1 25600
85D0E1CFB8F4131F14A5192CBBFEE13FAA69988F ]C:\WINDOWS\SYSNATIVE\MIDIMAP.DLL
[D4BE993965CE6DBABB595B3EFEECC7D0][1 10752
31D7948F8C1902C498C40D14ED208A1C3997A98D ]C:\WINDOWS\SYSNATIVE\MSCTFIME.IME
[46801BECD7CBD6E12A4722895AB216B2][1 23440384
860C332067608B79F60BCBE60857603AC6F51E85 ]C:\WINDOWS\SYSNATIVE\MSHTML.DLL
[D17F6C945AF73BEAC7A6FFAD6E30859F][1 8192
97D048435F1464F2D979E8A6FBB83B5EB0BD4980 ]C:\WINDOWS\SYSNATIVE\MSIMG32.DLL
[DA5868EABB74AEC4354647D45F97C0AF][1 408560
012CFD4471871F0F57EF071F17E6625B3615489B ]C:\WINDOWS\SYSNATIVE\MSWSOCK.DLL
[9A2DF1905A6AC59527FED7D0DFEBA42D][1 68096
B3381CBB3C3F59E1F2846DF1EF3219DC698E5AD5 ]C:\WINDOWS\SYSNATIVE\NAPINSP.DLL
[CBA59BEFF4E854C481D27DEAC17429F4][1 92160
6A12FD396745F8C2CA0BCDA86459188C92742D36 ]C:\WINDOWS\SYSNATIVE\NLAAPI.DLL
[A792B49B96CE0C33D5BBDF3D3EDC1751][1 86016
DDFA096C3230626C781E6B19C5121B41191C818C ]C:\WINDOWS\SYSNATIVE\PNRPNSP.DLL
[79E2068FB1E925B013EE28ACA7D1BEEE][1 16896
3A0C498A80C536731CD8519BC056D534F8530DCE ]C:\WINDOWS\SYSNATIVE\RASADHLP.DLL
[A44D27D03056EEC97CF2AFDC658EAB45][1 954368
0E6F6E77415112E3B9F02FC7A8B9ED01B00A85CD ]C:\WINDOWS\SYSNATIVE\RASAPI32.DLL
[0AED07F28B0B0820C9895656FE67FD1C][1 1211904
34F3DFF5CAE349ED8B8177974EFAEB9AF8BEE79C ]C:\WINDOWS\SYSNATIVE\RPCSS.DLL
[D6CE62F271345D40472A002E0AAE1C07][1 279040
45D54E8794966D5FD015D026D0E71FEAB2BE5F0C ]C:\WINDOWS\SYSNATIVE\SCECLI.DLL
[7A20DA1F1406492A70E9C8243634467B][1 679424
3C60D92EF86FC4F658CDE02F67A03F107ED6C062 ]C:\WINDOWS\SYSNATIVE\SERVICES.EXE
[BDC6F41710F85FC5752DF132484FD98C][1 1390888
4BE9D9BD14D7BADF6086818DD7C5ABA37E200DBD ]C:\WINDOWS\SYSNATIVE\TASKMGR.EXE
[7E2D956634CD227D2ABCBB9F62EC93F0][1 1664688
23CF7387E56465E9ACAFCD3A5B743C6B97BB8C6D ]C:\WINDOWS\SYSNATIVE\USER32.DLL
[9473F2B5794F0A81C7C7FB602D7B34ED][1 613376
552983A0F4E7D5F842BC7E55D428A47D9535EB33 ]C:\WINDOWS\SYSNATIVE\UXTHEME.DLL
[92419F3B74C6C3D7304B7665DA984552][1 779776
7290A3DEADF86D38F03933CBD09DA6841B6B2DCC ]C:\WINDOWS\SYSNATIVE\WINLOGON.EXE
[0C0EDC90F6D3F80EE82DAC1586F432AF][1 31232
C7E2F025690FD199DE7B7C56ADBF235CCBCAE493 ]C:\WINDOWS\SYSNATIVE\WINRNR.DLL
[81D023450CD83A8021B6F8DDDFBED8CC][1 4608
6A79515A8B5B732A258A72A0163B9F00E52A3542 ]C:\WINDOWS\SYSNATIVE\WS2HELP.DLL
[78AA5FEDC6ECA8269093F4D1EE2A27B3][1 64000
C3192EEA4B38A8CF87F473AF27D671257C4390EA ]C:\WINDOWS\SYSNATIVE\WSHBTH.DLL
[05793B87BFD0101369AD01DEC810048B][1 1180672
11B44C9C9F5BD7B9AA1DF4DE18A27BF1353F2CC7 ]C:\WINDOWS\SYSTEM32\AGENTSERVICE.EXE
[50137D32AACD4D73AC3BC2BBBED9B135][1 25088
1CBC9F661DC797DE9DA0435CC87FB8D8A346E929 ]C:\WINDOWS\SYSTEM32\AJROUTER.DLL
[E67AEB5F9FA81EE896EC3F0EB837BB12][1 94720
EE7149A52241AD1285ACED57C56DCB7EA5DA56B3 ]C:\WINDOWS\SYSTEM32\ALG.EXE
[43C9CCAA6BE7AED7E2957A7FCFB4AC54][1 329728
117B328C8A927390D61CF0FF137BE09082FB9108 ]C:\WINDOWS\SYSTEM32\APHOSTSERVICE.DLL
[776DDA478631BF8D2143D53FF0F9E5E7][1 1267712
EB6BE38245D87F37E8888B96BDDDC8BA35AC078F ]C:\WINDOWS\SYSTEM32\APMON.DLL
[C891C2BE30DF2EF1E3769D4EEDB27A9C][1 78336
C1AE41FBAF41D6B7AD46AD7225EB4CA5DCB2B97D ]C:\WINDOWS\SYSTEM32\APPIDSVC.DLL
[A939CDAB068CF5775E29D8B915042BA2][1 176640
F5A147687572B60A87514FC739289392F07D8DA1 ]C:\WINDOWS\SYSTEM32\APPINFO.DLL
[F04ADA7AF26797029FA84FE969E7D215][1 72776
CB91407F81D32E05D97AB017789406D0D14B7C13 ]
C:\WINDOWS\SYSTEM32\APPLICATIONFRAMEHOST.EXE
[785A1493731880AE44C7E6C46CCA004E][1 198656
53691F701144231EFCC1A8D65B321A0458A62875 ]C:\WINDOWS\SYSTEM32\APPMGMTS.DLL
[B27279D58FF5801DF02F83E7E51C53C9][1 112128
61419C9D7839ED32DBBE1B8E0F7B475DBEE26C2A ]C:\WINDOWS\SYSTEM32\APPMON.DLL
[425280AF4EB1F4A105097A4DEBD84B18][1 676352
449F94C224B3367C17A9A0F00B05E15EC82464F7 ]C:\WINDOWS\SYSTEM32\APPREADINESS.DLL
[77F7A3C5F9C843173EC787CF85CCC1CF][1 831504
6922B2ABC37740B1E6E3A7598D2AB3ECF062E308 ]C:\WINDOWS\SYSTEM32\APPVCLIENT.EXE
[8333C5EB5C9E8F06861717DF2E319966][1 924672
F0AF6D81CFCBBBACC653A499E535E5FE39314101 ]
C:\WINDOWS\SYSTEM32\ASSIGNEDACCESSMANAGERSVC.DLL
[7340CCD55E6BEC8F98019F2018A3B6A3][1 604536
F25428D71B2A5B0B73F53752BCFB2B5F43ED95C0 ]C:\WINDOWS\SYSTEM32\AUDIODG.EXE
[72C05E1DCEF19658EFDE2E22CB747884][1 744960
00A2328059C128DD8E910E8CB07D0EB235BCE5F7 ]
C:\WINDOWS\SYSTEM32\AUDIOENDPOINTBUILDER.DLL
[1B0620BED0E3FA44617301558D7E9815][1 1975296
417BD72E9D24CAC23ADFE7FDF591E2141D69067B ]C:\WINDOWS\SYSTEM32\AUDIOSRV.DLL
[E129358A0BE95CBF9EB0742173E72665][1 111104
C6C5B2F1C2C0C123847B2507308F147337F530F8 ]C:\WINDOWS\SYSTEM32\AXINSTSV.DLL
[7C2C340E8EA637F930E9F82D16CBFF2F][1 1388032
6C7CB66132927F9173219B3838EBC2D6153F9D8E ]
C:\WINDOWS\SYSTEM32\BCASTDVRUSERSERVICE.DLL
[96E090FE8C0559EB39DCE2F2165C3BAB][1 454144
2EC0E5E79B04E0845E1AF327D0BFD175B7B65C3A ]C:\WINDOWS\SYSTEM32\BDESVC.DLL
[3C5E2B48021E9D45CCB35B8987F3A399][1 882176
8586A20FF98D40F0ACB382EA9D4877F6DCB60D7E ]C:\WINDOWS\SYSTEM32\BFE.DLL
[37746E238D02257E1DE4C3832326CD18][1 46592
21CFB6F0458F6E22787B9818AE18813923B0D0CF ]C:\WINDOWS\SYSTEM32\BROWSER_BROKER.EXE
[07176C2B95E1E9E6114956084EBAE9AD][1 556544
D19F1F12CEDAC192821E123F6BA8F3C031AB921E ]C:\WINDOWS\SYSTEM32\BTAGSERVICE.DLL
[43F1CDBE6650A2989E1C2F6F02F0E4F1][1 381952
8D528DE2BF90214C47C277EE6A59FDD4DC94068A ]C:\WINDOWS\SYSTEM32\BTHAVCTPSVC.DLL
[7A2163DA90A08C73776B07FA0B8E3852][1 196608
2BC1F30D6A147C91510A2A11F5823F33A34B989C ]C:\WINDOWS\SYSTEM32\BTHSERV.DLL
[20AF2F885AE06DDBB31BF586D0333047][1 291840
803B23AA0DDA01DC4A2C76685198308DF9510459 ]
C:\WINDOWS\SYSTEM32\CAPABILITYACCESSMANAGER.DLL
[61E4F7601980AA8396D608EFABF1FAFF][1 122880
096AEAAA43AC566CBC39AFE95C92D3AE1AC5537C ]C:\WINDOWS\SYSTEM32\CAPTURESERVICE.DLL
[FED9AB89CEA58D22566DBF65DB3A5BDC][1 961024
279319BA8FBB6F9C2EDA6E584CA2D9CAB5AF1799 ]C:\WINDOWS\SYSTEM32\CBDHSVC.DLL
[72DCA3EF93EAB7A87D3EBE9DD94C959F][1 645120
3D056ABA922016317EFFFEEB6C23B45D7CB88A4B ]C:\WINDOWS\SYSTEM32\CDPSVC.DLL
[3F5392AE17DB28A5E4A7022140B0421E][1 514048
16978C9823224E3D7417DF2A4A5F401B46F2327C ]C:\WINDOWS\SYSTEM32\CDPUSERSVC.DLL
[0AA32D46BBEC1509B13FFBFB00C26116][1 192512
D2D716680C6C986B98339FF4DA7195885D3BBA49 ]C:\WINDOWS\SYSTEM32\CERTPROP.DLL
[759E47EE37B5C8368A5CA39F95F3B0B8][1 871280
75C43610311A6A47077045C56620D6BB735DCF30 ]C:\WINDOWS\SYSTEM32\CLIPSVC.DLL
[4C41666923A14DC687DEEE3B143AFB55][1 822784
A32A03532A2AC2CA9C9F67FF4E7FB45680985DF9 ]C:\WINDOWS\SYSTEM32\CONHOST.EXE
[EBD5C968ADCCE803DED93A1B7F6A62BC][1 157696
75F12DFAEEECF6241B4AF22A4C2D62419EFA8E39 ]
C:\WINDOWS\SYSTEM32\CONSENTUXCLIENT.DLL
[8D11B28DA95463364439E394C2CF62E6][1 918496
1D88204E4A7808C65FEB18DCE5FCEC51ABBDA499 ]C:\WINDOWS\SYSTEM32\COREMESSAGING.DLL
[E8A9C2E4DCCFA92B197A5FC6D3B5249A][1 95232
C28EE651D04828BE8596CB4C86F35574B45F7D73 ]C:\WINDOWS\SYSTEM32\CRYPTSVC.DLL
[0837EDC0FA9710F51E197A124E8310F9][1 740352
830398471E52D4EB05AFF278FCCEC013EEB068D3 ]C:\WINDOWS\SYSTEM32\CSCSVC.DLL
[AFE653CCC2592633C22DD5DA4124AB59][1 10752
65597164F3BFC193EAC140A8BCA7EAA3FCE8A92C ]C:\WINDOWS\SYSTEM32\CTFMON.EXE
[35A20D48D8A84AF8154B47CBCEACBCCC][1 475136
E922EA862FD345B6E9E1420C22ECE3E03B499E2F ]C:\WINDOWS\SYSTEM32\DAS.DLL
[7384E7ADCE23BD023B85D97ED83AB149][1 491520
BBE2388FBA80435014722E542782319D6CAB4BCC ]C:\WINDOWS\SYSTEM32\DEFRAGSVC.DLL
[B440713B9913F70952CD75B776B95E29][1 240128
2A2C489502EB105C50A710DA5D5C0BF85EA20E21 ]
C:\WINDOWS\SYSTEM32\DEVICESETUPMANAGER.DLL
[B11044B116BC28695B426DFFFB2BA728][1 745472
36A9EDAB5D6995EF624891A820AF52A58107AE6A ]
C:\WINDOWS\SYSTEM32\DEVICESFLOWBROKER.DLL
[D3FB829B5D8A01790661A17D19626290][1 34304
1D9B16BA1519D86F1464596E2F55D1578CC08586 ]C:\WINDOWS\SYSTEM32\DEVQUERYBROKER.DLL
[7A5388F4E7CB37108543070D41235E5C][1 367104
1BB194E4D74BF920368FCCC044EC79B88DE10C9F ]C:\WINDOWS\SYSTEM32\DHCPCORE.DLL
[F7AD25F7667C1B5C1D681A48AED0FF0F][1 210944
12E249C9E0F886D3808DE9E94B5DDA35DD33A256 ]C:\WINDOWS\SYSTEM32\DIAGSVC.DLL
[B6A55F43F2C7D6F90D69FC63FFE08310][1 92672
C710B33FCB9C2131C1E25846588E2F2065C1AD3F ]
C:\WINDOWS\SYSTEM32\DIAGSVCS\DIAGNOSTICSHUB.STANDARDCOLLECTOR.SERVICE.EXE
[CC9071D7AC1A3B81FB80016A16FD9F9A][1 3554816
6EA272F6BC796967FCB9CE2F7C6A27DD887B2FB8 ]C:\WINDOWS\SYSTEM32\DIAGTRACK.DLL
[D2AB39EA2C0FCD172751F84BDA723A97][1 21304
DCE2AF90E45FB9FC05ECBC9BEDDEE53FB66F3C6D ]C:\WINDOWS\SYSTEM32\DLLHOST.EXE
[18286E4DF795E502905EC5218E5726F8][1 58368
61F48BFB61E34551110FFA706C5E13710C951684 ]C:\WINDOWS\SYSTEM32\DMWAPPUSHSVC.DLL
[2D06B7F6F72790BF0E58CAB865428AE7][1 349696
097282BA27BD69AFB1DECC4D34BB8BF19C81DEA1 ]C:\WINDOWS\SYSTEM32\DNSRSLVR.DLL
[7231A7C8515B00D2708EC68B2A792EBE][1 265728
35BC10CF9CBD4600F1E9D32A45589D84D5F67345 ]C:\WINDOWS\SYSTEM32\DOT3SVC.DLL
[449075E8889DE1D57714B8177457D533][1 169984
504EC5417961595D0D18D64D51B45CB018D21DA5 ]C:\WINDOWS\SYSTEM32\DPS.DLL
[9B0EA8FC801305EB23E8611785BBE847][1 245248
35DB8FD43DAC86F8DEC9E808579E412228278346 ]
C:\WINDOWS\SYSTEM32\DRIVERS\1394OHCI.SYS
[81639B18EB7C4FB1C49B35CCA7F80EE8][1 107520
F29A668C4257DAC4A79F320B71E7E96711E3CCDF ]C:\WINDOWS\SYSTEM32\DRIVERS\3WARE.SYS
[52166C84DA4BBD0FB70EF15F84D8A5B7][1 790840
72106F8B47EBFBC9E95F5CCC253E41152C26E0F3 ]C:\WINDOWS\SYSTEM32\DRIVERS\ACPI.SYS
[C3807173110FCDD0B877D23F5FD28138][1 19968
16B2050752F96546944207A9396BF0970F86E61D ]
C:\WINDOWS\SYSTEM32\DRIVERS\ACPIDEV.SYS
[FEB0C1D3F1CE24CA8546FB02B8B1241A][1 132096
BAAA916382862D899CE85A86A89AFCF187A13B8B ]C:\WINDOWS\SYSTEM32\DRIVERS\ACPIEX.SYS
[8F56B78F502BA54DF0E7F252D007A33B][1 12800
CB0983939A31921F557E375DF6120278A373B2A2 ]
C:\WINDOWS\SYSTEM32\DRIVERS\ACPIPAGR.SYS
[6253BFF71CE081511CE362714B21F24F][1 16384
235147673EB8D54D8F2C2E981A92488C5BFFBB5B ]
C:\WINDOWS\SYSTEM32\DRIVERS\ACPIPMI.SYS
[9E85604FC93AFC1237C29CF9EFA83D60][1 13312
5AB9D40058C5021F9F767E14E30D93143C98F355 ]
C:\WINDOWS\SYSTEM32\DRIVERS\ACPITIME.SYS
[1E56666C11164E0BE83A2330D85D65A9][1 1135616
19C164C123EE6E533A593598CD72BBD8E2DC6687 ]
C:\WINDOWS\SYSTEM32\DRIVERS\ADP80XX.SYS
[5AFE650194C07BE81CB5A01B72549A1B][1 655160
01D6455EB4EA4491C1A3221041F9F157CDB387B7 ]C:\WINDOWS\SYSTEM32\DRIVERS\AFD.SYS
[5194BF2FEDA9F6BE6F7691EDA1F910DE][1 40960
B77DF1C0A28667BAE2E12044B10ECA3B68ED048F ]C:\WINDOWS\SYSTEM32\DRIVERS\AFUNIX.SYS
[AF17F63DFDE9F19BBE730A1ED86DFEF0][1 113664
9AD8DEBFFDA6C5F9A61957EB8916F10D8CD4E9AA ]
C:\WINDOWS\SYSTEM32\DRIVERS\AGILEVPN.SYS
[AE0B2FAC90C4DF325F24A7BE70CE5609][1 288256
963D5BB54352742B411CA1F03538032DD3CFFFA3 ]
C:\WINDOWS\SYSTEM32\DRIVERS\AHCACHE.SYS
[F88D3AF78AE83F9206D60ACC8D735DC0][1 198656
DC9B7E0D571B771CE1DAFBC97FAA7C9605A057BE ]C:\WINDOWS\SYSTEM32\DRIVERS\AMDK8.SYS
[BB5A205BFB6AC39CE965322B27D07915][1 196608
C6BB57B7F305F3720E3BD50047BFCBC0C4259A23 ]C:\WINDOWS\SYSTEM32\DRIVERS\AMDPPM.SYS
[89D675A01B6A4E1AEEB563DD8450E8CD][1 83456
B647ADEF7629252B4217F444BD378E5C6262312F ]
C:\WINDOWS\SYSTEM32\DRIVERS\AMDSATA.SYS
[EFB766859B1A4A14EA65528AAFFD1549][1 259384
C6114840E891B210452AEB31775E9F10C3E833EF ]C:\WINDOWS\SYSTEM32\DRIVERS\AMDSBS.SYS
[1085914F24F74234C16BF12E7BBFC403][1 27136
F6E30FE7AA25B1516F680623251EF6E40984A083 ]
C:\WINDOWS\SYSTEM32\DRIVERS\AMDXATA.SYS
[056C68D7ED2270EF12990B80A47592B5][1 201528
93104C98C7D2D71736DCB505D0857CC0E0131460 ]C:\WINDOWS\SYSTEM32\DRIVERS\APPID.SYS
[DF8F48328EFA4EFB04CC5528629DE585][1 18432
8BCD13041843BEA9A1AC40AE0F0DB815CBE5A198 ]
C:\WINDOWS\SYSTEM32\DRIVERS\APPLOCKERFLTR.SYS
[C3D9BE0D466EA8240B129FA54257562D][1 137016
B96D0B9C1A2A0E712BC97818F37636AD1C73769E ]
C:\WINDOWS\SYSTEM32\DRIVERS\APPVSTRM.SYS
[B433AE814237F91624E3AAACF6BC3563][1 172560
D221D2A5F3BC90A7B6E4D59DBCBC8A5F37BCD7CE ]
C:\WINDOWS\SYSTEM32\DRIVERS\APPVVEMGR.SYS
[2F01953999020AC8C5EE3BBFB0094E79][1 153400
828B9DB13D88688A4FCC1A8867699D9495ACB10F ]
C:\WINDOWS\SYSTEM32\DRIVERS\APPVVFS.SYS
[F543CC0BDF5EBAF462C77FED31593C3C][1 131896
37B5E6CF2425F7DE9B2C9777380534A4843669F6 ]C:\WINDOWS\SYSTEM32\DRIVERS\ARCSAS.SYS
[863DCECAE095A3749546C89A7897E8A7][1 31232
80FFF45105870DA17EA8E21B1D6DC2A36D14415D ]
C:\WINDOWS\SYSTEM32\DRIVERS\ASYNCMAC.SYS
[A39C05B19C079401A9AF8A2EF3067B64][1 30208
F0EF55FC029B1702CEB7476D5F4FE5D74EE5BDB3 ]C:\WINDOWS\SYSTEM32\DRIVERS\ATAPI.SYS
[477906D31E1A5FDA0E5CD8D189DAD61F][1 4301304
1D267339A1C6BD5877FB5639EE26B20A353F57E4 ]
C:\WINDOWS\SYSTEM32\DRIVERS\ATHW10X.SYS
[E42AF3C735EFBAB61D00B5101190ACE8][1 63288
E924B8E161B07D962132B61AE5BD3543302687B2 ]C:\WINDOWS\SYSTEM32\DRIVERS\BAM.SYS
[739D089777D2B66DBE7201E5EA4BA2D7][1 9728
8E830AF8CDDACEE01D44747352AB62418665248D ]C:\WINDOWS\SYSTEM32\DRIVERS\BCMFN2.SYS
[79647BFB7A9B6019E1C8D000A96D8D7C][1 101392
70FF99297935C7233E76FA0A2892E9DF795E92C8 ]
C:\WINDOWS\SYSTEM32\DRIVERS\BINDFLT.SYS
[DAFF6F23D321DF8106CEC03BC0E9E964][1 116224
A3675DDCEF6AB1EEA601F66244EC2C541AFFCE14 ]C:\WINDOWS\SYSTEM32\DRIVERS\BOWSER.SYS
[7D44193A9ABD39FD7D7427414B845855][1 126464
7EB00767889CF42F403B8886DD8D75B05AD402CF ]C:\WINDOWS\SYSTEM32\DRIVERS\BRIDGE.SYS
[B33351A77FFE93A9CA4C625E4CF2E6D3][1 618720
CBD857540A236D22B6F4D1D4CFEFB59A371C7A52 ]
C:\WINDOWS\SYSTEM32\DRIVERS\BTFILTER.SYS
[DA261B477C713EA9481EF8527328D027][1 111104
33F9F041A875716B76A22C7D836D478CA7D08687 ]
C:\WINDOWS\SYSTEM32\DRIVERS\BTHENUM.SYS
[F8D27297A01AB57929BC3F39E61281DE][1 119808
380DD1F0E0FE337C2EAF6477959B6ECE6B50E891 ]
C:\WINDOWS\SYSTEM32\DRIVERS\BTHHFENUM.SYS
[1A0AF89F61538B833075FEB438EBC33D][1 34816
E805E09F2519F83D7F1A1D76316B44B4B556E434 ]
C:\WINDOWS\SYSTEM32\DRIVERS\BTHMINI.SYS
[AE60FA63282CFB1825C68D2F44737A1B][1 72192
A51287C644A6794066C7326DFA367D1A5EFB1EE4 ]
C:\WINDOWS\SYSTEM32\DRIVERS\BTHMODEM.SYS
[451193C2EC533818B7474D2B24623836][1 133120
E5C722D21302316D503D619659E2C72DC527832F ]C:\WINDOWS\SYSTEM32\DRIVERS\BTHPAN.SYS
[122A2FBC5231E8AA6768F0998BC68279][1 1219072
84A59A7825133439786104BF5732934B5B935161 ]
C:\WINDOWS\SYSTEM32\DRIVERS\BTHPORT.SYS
[8FA206A2891883E610B8501CF9880F07][1 92672
D0A46E71BD9960681197BFA1E90E8B8193D311E9 ]C:\WINDOWS\SYSTEM32\DRIVERS\BTHUSB.SYS
[E0F9E50058E4EA6B1CD7002310B00F0D][1 42504
9F81BB71412A6E251D963C3A1FBEF145FBB30B0E ]C:\WINDOWS\SYSTEM32\DRIVERS\BTTFLT.SYS
[DB01E910747D4AB7B59842AF88D7F86A][1 40960
11D975884639E123A60C3C36E3F0B31056BAD55E ]
C:\WINDOWS\SYSTEM32\DRIVERS\BUTTONCONVERTER.SYS
[2BBDBBA403F23A4197BFB1147AF566C1][1 533816
1518707F44A38AC6BC56995CC65EBB05804EC595 ]C:\WINDOWS\SYSTEM32\DRIVERS\BXVBDA.SYS
[F50AFEFFB3DB2BDC549AF4A230A3ADB5][1 63288
9E44E3BCD2D94B3F348D82D7E5D4ECEDEA507C16 ]C:\WINDOWS\SYSTEM32\DRIVERS\CAD.SYS
[7014CEFB8F3652B2AA0533D33D94F936][1 125952
00C34720B230748A897455DA734708464F607E3E ]C:\WINDOWS\SYSTEM32\DRIVERS\CAPIMG.SYS
[5787AFA76808253F32DBBB31C4E26C8A][1 100352
2107BA4DA64A7BDA9093402814582D3019AD1868 ]C:\WINDOWS\SYSTEM32\DRIVERS\CDFS.SYS
[D7FAEE38C867DFDAA626B886A7AEA89A][1 165888
0A2143BAF87C8700843A4EEECE2D51383E9AE78A ]C:\WINDOWS\SYSTEM32\DRIVERS\CDROM.SYS
[F9BA5E23AAE945513581594BB7A947C1][1 319488
72F4141D427AE2659935BC1A3DA056F780FC527E ]
C:\WINDOWS\SYSTEM32\DRIVERS\CHT4SX64.SYS
[E37576C5716151B03D9B374D40ECBFA4][1 1866768
7F538A362CC1183CAB6707D9D61B829CD23981A8 ]
C:\WINDOWS\SYSTEM32\DRIVERS\CHT4VX64.SYS
[C93B6F7C1D03400315AEA8530698FF57][1 50688
8FD7479192970B02E45DDA9ED693778666E62BD1 ]
C:\WINDOWS\SYSTEM32\DRIVERS\CIRCLASS.SYS
[769ACDF8CE8BBA378B9D32C123CCE647][1 452096
9356B70860C67F63A54172F19B3CC3D231DEEEEA ]C:\WINDOWS\SYSTEM32\DRIVERS\CLDFLT.SYS
[CF389361290FD38EA31932CD52D18D63][1 405504
F7E7B46A946F0CCEBBE6D84AB3EEF916CF8F72C7 ]C:\WINDOWS\SYSTEM32\DRIVERS\CLFS.SYS
[EBD069FB399EE8EAC498D5F9B129AAA5][1 34816
BFF95C433C58C237242BDF1EE7185B962C950C40 ]C:\WINDOWS\SYSTEM32\DRIVERS\CMBATT.SYS
[75DAB6D505A8774A17DC29BB71A8FE7C][1 730384
9ADCB3A76DE6CB964AB7D362C968B0E01158443F ]C:\WINDOWS\SYSTEM32\DRIVERS\CNG.SYS
[DF2E93BD5CD438688ADAA3AEBFBBDC9F][1 40248
CDA2343AF4A6D25343681172D217B0D85F5F6559 ]
C:\WINDOWS\SYSTEM32\DRIVERS\CNGHWASSIST.SYS
[912B28456292AF00A8EBF2B0F90E42B5][1 60928
B988A1890DFD07EA8ED0E8411948F89A680981B6 ]C:\WINDOWS\SYSTEM32\DRIVERS\CONDRV.SYS
[92AF73FAE4F0D3E95ADE69C45CAF5022][1 579072
4BE65B3AC05561972C612296F4DB97427B69D35B ]C:\WINDOWS\SYSTEM32\DRIVERS\CSC.SYS
[175A50CD43C776E07CC00B6E6C5DA1B3][1 123392
A7E822967C3B31059278FB5A81DE6F938970DC0F ]
C:\WINDOWS\SYSTEM32\DRIVERS\CXWMBCLASS.SYS
[567EBEC0D1127D2E48A68273DF9049B2][1 97592
592CDD2EC6DB4F69307165F14DFED257B074B70A ]C:\WINDOWS\SYSTEM32\DRIVERS\DAM.SYS
[C7E85EEDBC05491FF1CDD3ACA98FA1DE][1 151040
CC6957482C045B899A8D3EBEA827410815757CAE ]C:\WINDOWS\SYSTEM32\DRIVERS\DFSC.SYS
[CD76072EE8E1E91099ADF566DC4DBC5C][1 97592
39201F7D4ABE8C729666A17293731355BDE90293 ]C:\WINDOWS\SYSTEM32\DRIVERS\DISK.SYS
[048980E575F5228248511B3E0ACC1749][1 57144
1776CE7629AF0D53582DD6AC381409E52557B7C9 ]C:\WINDOWS\SYSTEM32\DRIVERS\DMVSC.SYS
[B41EDC7CDD2C1F35BB36CD384C3985AB][1 16328
E9118DD595EE88E994496C24B5F47EE657EA9881 ]
C:\WINDOWS\SYSTEM32\DRIVERS\DRMKAUD.SYS
[2A17E43AEEA415005B3BA59E6242343A][1 3377152
FA5271FB1B2FE187E45CCD309688CF3538680A6B ]
C:\WINDOWS\SYSTEM32\DRIVERS\DXGKRNL.SYS
[106290B54A85834C0E6EB005BC54AD31][1 90936
549C25DA91EF09A7BC6C5CBE5D12679D9BD31868 ]
C:\WINDOWS\SYSTEM32\DRIVERS\EHSTORCLASS.SYS
[2B24FC41E7ED5BB730DDF8D78AA73A52][1 119608
FA33338F504499EA8E3B005F8B08DD0CE354B0FE ]
C:\WINDOWS\SYSTEM32\DRIVERS\EHSTORTCGDRV.SYS
[F7193E7F929653AD4CE636FCFBDBEEDC][1 14336
24069CD6D3B0B6FF96B246A727853E0A6625C76C ]C:\WINDOWS\SYSTEM32\DRIVERS\ERRDEV.SYS
[F314609DBF8A3AA9EA69EF40C7FE7762][1 3419152
0AE2C7EC5F4F00C129332342D78444FC6E77431A ]C:\WINDOWS\SYSTEM32\DRIVERS\EVBDA.SYS
[6CBC38EC80F2976F7EF23602308FA644][1 35328
20BDC93F8CD648335166476F72387D41FE33319B ]C:\WINDOWS\SYSTEM32\DRIVERS\FDC.SYS
[D64F99DD8480935CDA61ADC66C81FE87][1 60416
A97FB4A8DE528BCA6728A6EAF1F15BB090472977 ]
C:\WINDOWS\SYSTEM32\DRIVERS\FILECRYPT.SYS
[A3FBC41B97CAAF95795F3AB86AE82549][1 94008
727580E9981148A1E0B42FD1984F7903AF02DB87 ]
C:\WINDOWS\SYSTEM32\DRIVERS\FILEINFO.SYS
[15677C04E81E80BAB562D39879F06235][1 40448
926F17F3A2DC2CC91AB1D963A3FC635905D2AD04 ]
C:\WINDOWS\SYSTEM32\DRIVERS\FILETRACE.SYS
[A751D0D8462665969C43337435A26711][1 28160
32EB435295C7B31D7743170A7AFD62CC7B7CE935 ]
C:\WINDOWS\SYSTEM32\DRIVERS\FLPYDISK.SYS
[F7555EBB13AA476E9B15B5082249E0AF][1 436736
6F16C99D01807191F5C34BBCB523F53760D31BAA ]C:\WINDOWS\SYSTEM32\DRIVERS\FLTMGR.SYS
[CC9425EB85BFFF1FC67FB8F1CB3174A8][1 67384
64A5226DF337D8DD6646A6CE1F1793375AFDB202 ]
C:\WINDOWS\SYSTEM32\DRIVERS\FSDEPENDS.SYS
[3D719AD748F65869EA0E7002F0D2D2A7][1 798520
F5C85EF36BB9D73CA7223B2443FE4C52A2473115 ]C:\WINDOWS\SYSTEM32\DRIVERS\FVEVOL.SYS
[4EF5EA4643076475D1B34345FA245930][1 20992
A94737892840E4DFEDA0DA865DA80DEB9F57DA44 ]
C:\WINDOWS\SYSTEM32\DRIVERS\GENERICUSBFN.SYS
[FB0B8778A55ED71728D28E9B3889A11E][1 8704
CF54094D9F463D7D8D681869C10BF37637FF65CF ]
C:\WINDOWS\SYSTEM32\DRIVERS\GPUENERGYDRV.SYS
[855678C1760AE7DCE0CF2BAFD989176E][1 104960
8C14C395CD41EB75698C5668738D33A14B68821C ]
C:\WINDOWS\SYSTEM32\DRIVERS\HDAUDBUS.SYS
[6973720AB8B0F7063B05E9211661AF5E][1 398336
B8ECE1FAE94958D3B1C7AD9383BC8EA9818CC487 ]
C:\WINDOWS\SYSTEM32\DRIVERS\HDAUDIO.SYS
[8BE5EBA8A54B789690B9493BF7DE1DCF][1 39736
172DFE8F81CC65A13A570CFB3E34ACB8D222916C ]
C:\WINDOWS\SYSTEM32\DRIVERS\HIDBATT.SYS
[34A4E4C0D8DBB733F14CB5B7186B9975][1 118272
443DEFC1EF67A554464A195A6E3A291A2A375E5A ]C:\WINDOWS\SYSTEM32\DRIVERS\HIDBTH.SYS
[24075C6DA27D05D869C56102E8220E92][1 52224
33DC5B02B820F33E91ECF9F273A1FB86EDE9C895 ]C:\WINDOWS\SYSTEM32\DRIVERS\HIDI2C.SYS
[96FC1329E286E2309AA94D970C962EC7][1 51512
026C6553785B758EFBC697BA5AC9216DD36861FB ]
C:\WINDOWS\SYSTEM32\DRIVERS\HIDINTERRUPT.SYS
[7DFC088DEDC2232C36562CCAAFC26824][1 48640
B23492D592F241D64E5FB158A675AAFFCE9CA19D ]C:\WINDOWS\SYSTEM32\DRIVERS\HIDIR.SYS
[12DB9F4C1ABB1B8F7AC7203C049528CB][1 60928
F1B1CB2C953E83DFEF2B01C72D9524341C342580 ]C:\WINDOWS\SYSTEM32\DRIVERS\HIDSPI.SYS
[69EDC8900C69E2BBB13D2FD24B3A085C][1 43520
24649A55DC06567D1D72A3A8FE324F804C7DCAE4 ]C:\WINDOWS\SYSTEM32\DRIVERS\HIDUSB.SYS
[8EFE5647D0CDD02A0F456C15D5ECF979][1 64312
2DE72FC9A1DD8A20DD3A4DAFA06E8864C2447ADA ]C:\WINDOWS\SYSTEM32\DRIVERS\HPSAMD.SYS
[E3E53B226DCC3D0F8A714929C45F068B][1 1258296
31A76A4478F7BEA9F5640C7BEA2DBBAC8735636A ]C:\WINDOWS\SYSTEM32\DRIVERS\HTTP.SYS
[F023C1F4A112B912D3625324CAA8B616][1 33280
367D61E4BD3F0817F546450840FEA3C8C794EC9C ]
C:\WINDOWS\SYSTEM32\DRIVERS\HVCRASH.SYS
[FDAA6E61D35A03AB7EA08A8D99845EF3][1 80184
D64DF39ACD5BD53010CE386DE789378F8E1CDF3B ]
C:\WINDOWS\SYSTEM32\DRIVERS\HVSERVICE.SYS
[F677A4B785E0BBD01C531B1668F7D3F3][1 29696
EA143BBD52FCD57E2B45AAEAD873C76EE094FFD1 ]
C:\WINDOWS\SYSTEM32\DRIVERS\HWPOLICY.SYS
[2B8FD5359FB5A1FA2EE9504D53C0D286][1 25400
33C26D743C67B4713B5CA51DE2D6504CF0342805 ]
C:\WINDOWS\SYSTEM32\DRIVERS\HYPERKBD.SYS
[D2BCEA4C0513E098277F10CCBAC8FAF2][1 32256
2EE01E9207D1E8E82F60927E0FD21479B2F8D903 ]
C:\WINDOWS\SYSTEM32\DRIVERS\HYPERVIDEO.SYS
[7EF070F21CAB7E8DC906F9CA8516CE5B][1 110592
25E7E4ADF546E3A6523E0CA861BC7A255FF2E516 ]
C:\WINDOWS\SYSTEM32\DRIVERS\I8042PRT.SYS
[9E5AECAB5F05218D9AC923E7CEA1CE15][1 36352
2A697703D2D8913D2874614014DAE4B0F7571601 ]C:\WINDOWS\SYSTEM32\DRIVERS\IAGPIO.SYS
[48EDB9B5DAB7D294951A520330F13715][1 91136
458A43F7F0674B68504AF1D02EA33F2F6FD5A03F ]C:\WINDOWS\SYSTEM32\DRIVERS\IAI2C.SYS
[6C3EDE394C71D5A67A504F55E35B6F47][1 79360
BFB14D74BF8088F99E96C6BBD036C320F913E7F7 ]
C:\WINDOWS\SYSTEM32\DRIVERS\IALPSS2I_GPIO2.SYS
[806D14CEAF25E5F2DFCBA8E7E33B86BB][1 93184
33AA47FC5A149896110E343209C14A530D4487BE ]
C:\WINDOWS\SYSTEM32\DRIVERS\IALPSS2I_GPIO2_BXT_P.SYS
[87DDDAE1693484BD0A210C877BDA00C2][1 112128
B069D53CE6CE3A5EF35F985285D2BF7F6114C8CA ]
C:\WINDOWS\SYSTEM32\DRIVERS\IALPSS2I_GPIO2_CNL.SYS
[8D3E3C431367E3BA632B4396CA662E1A][1 96256
27406A360E030CB321D0F4F77A1C53D7BCC9B53E ]
C:\WINDOWS\SYSTEM32\DRIVERS\IALPSS2I_GPIO2_GLK.SYS
[149F1260537C4F68C3F67C363B62F3C5][1 171520
7C971D0A702EA48481C9FCA3AE127528DBEDAE20 ]
C:\WINDOWS\SYSTEM32\DRIVERS\IALPSS2I_I2C.SYS
[3E641E905A6DBF29CBA1E72BBE349808][1 175104
58AF5951DFE87FA74D04EB6C171976089BA15BB8 ]
C:\WINDOWS\SYSTEM32\DRIVERS\IALPSS2I_I2C_BXT_P.SYS
[B78D6AF79045B0DAB58596AF75037516][1 180736
93B1FAE341087B8ABF8692BCC2F7E66BC5B2C314 ]
C:\WINDOWS\SYSTEM32\DRIVERS\IALPSS2I_I2C_CNL.SYS
[2ED3B41C7CB4101ACB15D84D8AB5AA9D][1 177664
7DAF5030A0444B5DD6101875CDCAAEB90509C3CB ]
C:\WINDOWS\SYSTEM32\DRIVERS\IALPSS2I_I2C_GLK.SYS
[16A10CCEDCF5AC4CAAE43DC9FC40392F][1 38128
F9C70BDC52A485F1577372D828DCC75824A52711 ]
C:\WINDOWS\SYSTEM32\DRIVERS\IALPSSI_GPIO.SYS
[EB82A11613326691508D9ED9A4FE29E7][1 113152
B226F7E4189BF32E6159BBF54C304753E6610633 ]
C:\WINDOWS\SYSTEM32\DRIVERS\IALPSSI_I2C.SYS
[42B660654149FB181E49EA160808D3BC][1 885048
1BC06CA7FDAAF513663206BE0E6888A10E4C86E3 ]
C:\WINDOWS\SYSTEM32\DRIVERS\IASTORAVC.SYS
[E47022690D960CA022F0ADAD3CEE7028][1 411960
B20958AABB51127E498D5CB4645962C25222ED5B ]
C:\WINDOWS\SYSTEM32\DRIVERS\IASTORV.SYS
[1382FAA11F64E6AEE553D6889DC2ED2C][1 566800
8850D97079AA49810D9AC14B9BDAF2F4C7B2AF27 ]C:\WINDOWS\SYSTEM32\DRIVERS\IBBUS.SYS
[6248F7270A37B8890C7A058AAD4D6620][1 226032
]C:\WINDOWS\SYSTEM32\DRIVERS\IDMWFP.SYS
[3F8B046C0839FDB879FE179C07A1A6A4][1 3797960
4E7EE2EE8C747F614AF10F4E29377AB9D87D5C34 ]
C:\WINDOWS\SYSTEM32\DRIVERS\IGDKMD64.SYS
[3B0C7978321F691DCA332A3A30D3D34D][1 45568
91E3C0DDF389EFB33CF78CEEB875D23D9650A623 ]
C:\WINDOWS\SYSTEM32\DRIVERS\INDIRECTKMD.SYS
[87E738E189EB31E2EB07F609C930D068][1 50232
5825F87AFDE2AAC278D12CA544B6F053CF2209FC ]
C:\WINDOWS\SYSTEM32\DRIVERS\INTELAUD.SYS
[9E3EFA9EC7C87D20706E7A545773415A][1 19456
3A114C8630B05BFB7E7FAD22C4B944CF1C693EFB ]
C:\WINDOWS\SYSTEM32\DRIVERS\INTELIDE.SYS
[1FD5F56938424E3D437F2DD7FFE68A58][1 254952
A620203E60E9CEC324852A84701E24FB4DA320EA ]
C:\WINDOWS\SYSTEM32\DRIVERS\INTELPEP.SYS
[84BD903F361891CB3C3CEB1DA5198130][1 219648
EEAB30A1583DE4FC01C71C86B0DE3D52F135794C ]
C:\WINDOWS\SYSTEM32\DRIVERS\INTELPPM.SYS
[16406F139B0B986F38D4C25B6C2C97D3][1 55824
8593386271CFFE7DD773147AF91368107D73F6FF ]C:\WINDOWS\SYSTEM32\DRIVERS\IORATE.SYS
[A25F081BFDB86B48AAF36C4BAA398466][1 90112
B2A83C78673BBC2E132C6CBC53AA64461574FB12 ]
C:\WINDOWS\SYSTEM32\DRIVERS\IPFLTDRV.SYS
[EC972A6A764579EF04D28D70675D11A9][1 95744
90C2BDDDBD73C619B59D865C70658A4D2B00F788 ]
C:\WINDOWS\SYSTEM32\DRIVERS\IPMIDRV.SYS
[CEC63D8B8E7A525233D2AEE19EF9A5A8][1 224768
9ADF08543F96E7D5C24AAFBAFFFCE9FB9EBCFBB7 ]C:\WINDOWS\SYSTEM32\DRIVERS\IPNAT.SYS
[5AAD8A0ABC294C7A547F1C903AC04716][1 42496
80D1665785E2E0472FB73C20612D54DCCDB310C4 ]C:\WINDOWS\SYSTEM32\DRIVERS\IPT.SYS
[35FD8315E03C4B5FB4C81B3F5AA6793E][1 124928
544EA25A95CAA3A0E795961719BE5A882F2B1797 ]C:\WINDOWS\SYSTEM32\DRIVERS\IRDA.SYS
[C48B4FD5F9D4A0AEF69A691558BF30A4][1 20992
8F1B8A48E6C20DD3509F4728C14804865F2970C8 ]C:\WINDOWS\SYSTEM32\DRIVERS\IRENUM.SYS
[6FC797BC9152E34D3C1C1AB6F7C3FD33][1 23352
A4915D5AFD8F0A63620BF52B143DC68DFA0628E2 ]C:\WINDOWS\SYSTEM32\DRIVERS\ISAPNP.SYS
[08E5CBEAC1E11CBB4A27823F031B7E61][1 148480
F5BFD04E3A32C78F6A2858F54FD523715259E2EB ]
C:\WINDOWS\SYSTEM32\DRIVERS\ITSAS35I.SYS
[56D480702478880805F4E74F2BA02382][1 39480
A538BDA85C62C935CC24723ECCD3E2F6DB8AAE1E ]C:\WINDOWS\SYSTEM32\DRIVERS\IWDBUS.SYS
[38EDAC4667F2616442770D8DB0B2DC25][1 67896
03D994F56E758C25C4121BA4B3F04764FB5D455C ]
C:\WINDOWS\SYSTEM32\DRIVERS\KBDCLASS.SYS
[8F16F4D9D8E57AF55D42E182E8F83BCA][1 44544
51D99B3F18109FBFA9CACC6C541D0B9C1AC83C19 ]C:\WINDOWS\SYSTEM32\DRIVERS\KBDHID.SYS
[92DBC56CF0C981AAAAADDEAA6A563E39][1 24064
BF8ACD064C6C9161181108A6A1B4B4451EF05EA5 ]C:\WINDOWS\SYSTEM32\DRIVERS\KDNIC.SYS
[711E26B6F381ADC675D8C52CDEE505D5][1 147968
C29270ACC9A3C7644DDFA92F805B5C7F2CBFD56E ]C:\WINDOWS\SYSTEM32\DRIVERS\KSECDD.SYS
[479D8B6848EE3F6DA748C6636DF89389][1 178488
1DDEF86633C025F04971B8BEEC76B18D6718A82B ]
C:\WINDOWS\SYSTEM32\DRIVERS\KSECPKG.SYS
[7E3BEDEF17FFC3DA9E2E306138C5250F][1 28672
4F937EBD5283D80C61A421F331633F996F612F0E ]
C:\WINDOWS\SYSTEM32\DRIVERS\KSTHUNK.SYS
[91563B08A4FF7013420A14A1446264AE][1 71680
04FA5E16AC6819A856063B7B51A7B1236361CDBA ]C:\WINDOWS\SYSTEM32\DRIVERS\LLTDIO.SYS
[1BBADB9591080518596B9E57E6867DA9][1 109056
1C7B905D24F843C9CA80DE301E1ACCBB6622040F ]
C:\WINDOWS\SYSTEM32\DRIVERS\LSI_SAS.SYS
[7C1D1CB733DE28F7D15D69C5112B983D][1 124416
231533DD94634EBC92B286CC827B0A2B7149EF53 ]
C:\WINDOWS\SYSTEM32\DRIVERS\LSI_SAS2I.SYS
[C18F1929FB5594233CCA71FC624428FF][1 128512
4DABC1416E55412BE7D0C87CE09AB161945C5DB5 ]
C:\WINDOWS\SYSTEM32\DRIVERS\LSI_SAS3I.SYS
[4D322612CB0E3E8DFFDE8B78A5CAA841][1 82944
BD274B40B5471F21047EBBEE3934AC9A9C39EBE9 ]
C:\WINDOWS\SYSTEM32\DRIVERS\LSI_SSS.SYS
[03D9EDE1E96D1D158BD984D88B1095CC][1 135680
2904CE887D211BEA25B78CDC4666BA8CF6429068 ]C:\WINDOWS\SYSTEM32\DRIVERS\LUAFV.SYS
[CBC57FDBD22DD92B3B7B71DC44304301][1 515384
90065260D276B1BA27F74ADDAD760ACB347B0724 ]
C:\WINDOWS\SYSTEM32\DRIVERS\MAUSBHOST.SYS
[4C71C550AC2CD9E0201BCBFCF19DB0D7][1 58680
54EC2A1AC8EE3F69C2613F6C6F1CDD8B03AD130E ]
C:\WINDOWS\SYSTEM32\DRIVERS\MAUSBIP.SYS
[5EA3D977905D88627B5667E761C51F50][1 290816
043950E9729AACFADDE9F68E734374057D5F76E5 ]C:\WINDOWS\SYSTEM32\DRIVERS\MBBCX.SYS
[7DC0311FA450D54C5D345CE19778EA8A][1 59904
A4102D0E9D3BF61AC9A08D1F561D6F539ADC980D ]
C:\WINDOWS\SYSTEM32\DRIVERS\MEGASAS.SYS
[660C8651E6D9A15062A497364CA4A329][1 75264
A5FAA50C0A95C093B089338203C129FBA0DC5707 ]
C:\WINDOWS\SYSTEM32\DRIVERS\MEGASAS2I.SYS
[329C1C69386412444D05C82A6062F9AD][1 79872
D2C5FC5D22D598D1E79B64200D0A4EBF4441B96D ]
C:\WINDOWS\SYSTEM32\DRIVERS\MEGASAS35I.SYS
[E8DDD6B4FB2F20780B41B117F689A44E][1 575800
141BF341F029ADCD0762E29704F9DE3601319128 ]C:\WINDOWS\SYSTEM32\DRIVERS\MEGASR.SYS
[9089316A8C1D2F4A604470DFD1B6865D][1 53760
49BD4FA946A2C149DBADD3DB4564ABD56C2ABFE4 ]
C:\WINDOWS\SYSTEM32\DRIVERS\MICROSOFT.BLUETOOTH.AVRCPTRANSPORT.SYS
[ED1393D406757F6533257476F27209E9][1 90624
18E166F5FF5E95501210DD24056F81D7BA52D320 ]
C:\WINDOWS\SYSTEM32\DRIVERS\MICROSOFT.BLUETOOTH.LEGACY.LEENUMERATOR.SYS
[9117B78500C6A09F16EDC604ABD71F38][1 1150496
010E13418BBB76DFA16C170E0D943C5210F208CF ]
C:\WINDOWS\SYSTEM32\DRIVERS\MLX4_BUS.SYS
[1CA135D48C2C552E5A2DB2E5A14DFCCD][1 53248
474D323662EAC4C5BBCBAF5EB27F9D434F0BC0BD ]C:\WINDOWS\SYSTEM32\DRIVERS\MMCSS.SYS
[5F37CEDED43E3816BA38809E062134E1][1 46080
D80C44544C01C8CA082B418A935740F138F8F369 ]C:\WINDOWS\SYSTEM32\DRIVERS\MODEM.SYS
[753917AE790F884EE62D5E1F8EBFCC44][1 61952
3F400CE63CA49266318165102C8C1C23C458EBF3 ]
C:\WINDOWS\SYSTEM32\DRIVERS\MONITOR.SYS
[46708375D885CDD367CB6027A515D0E0][1 61240
ABBDF5A5E6C437F9753F43644029EEF63A11D786 ]
C:\WINDOWS\SYSTEM32\DRIVERS\MOUCLASS.SYS
[165AE5452B9155025814BAE5535E3019][1 34816
3273A9917756871909CA49CF22FBBFAC3E150536 ]C:\WINDOWS\SYSTEM32\DRIVERS\MOUHID.SYS
[6B0B650460A7501E3F01C191F865E298][1 112440
D5B3A6DE530DFCED1D9B97B32BE6D8B6474C3CDF ]
C:\WINDOWS\SYSTEM32\DRIVERS\MOUNTMGR.SYS
[AB7C450FA26544AB6D9344A81597B30B][1 79360
84A8E9A9482B2C0A460BA5D00AAC1FC287055BA1 ]C:\WINDOWS\SYSTEM32\DRIVERS\MPSDRV.SYS
[E7219627FF618544FEAF5CE61D99581B][1 157696
667DD8706368BCAD994761178A6BA0601E44C1FD ]C:\WINDOWS\SYSTEM32\DRIVERS\MRXDAV.SYS
[6DC929A7046019A4F7C27EAF25351C55][1 534840
C8C69DE9CC4A96A14E14D3BDD6875D4372E85C48 ]C:\WINDOWS\SYSTEM32\DRIVERS\MRXSMB.SYS
[CCBCB215B0DB2153F5F7F77D10F05B07][1 262456
85C5E37733B98216D3E539CE8E1DD39264A3BF4E ]
C:\WINDOWS\SYSTEM32\DRIVERS\MRXSMB20.SYS
[00D2E49ED6A5A11A5354637D3A632D03][1 174904
47FB0EDDCF103204673C98B7159971A4A14F9071 ]
C:\WINDOWS\SYSTEM32\DRIVERS\MSGPIOCLX.SYS
[07B8BAF680467BAB0607245E68D59805][1 51000
CE4CDDF32C0DC5DA4C682C11214F8E9C6532FFC2 ]
C:\WINDOWS\SYSTEM32\DRIVERS\MSGPIOWIN32.SYS
[0A68189FC5A0A09FF3BF7CA60278864C][1 8192
C3D401869301EA674686F2E83144C5B6E23F8F4E ]
C:\WINDOWS\SYSTEM32\DRIVERS\MSHIDKMDF.SYS
[05F3DCB8F90EF90C59E616F1D4C7585D][1 12288
55A9AF6AD724E89BC490ECFC506BD8283943CF68 ]
C:\WINDOWS\SYSTEM32\DRIVERS\MSHIDUMDF.SYS
[07C51C8E403121E63E3F7CC2B19840A6][1 27648
53194C63F31879D7DEF3AC73729815C174E311EB ]
C:\WINDOWS\SYSTEM32\DRIVERS\MSHWNCLX.SYS
[E64484CBBEF329B919D9E78B8CB58CF5][1 18744
60464C70E8C9266175A6F4A3CD249D96732DB8D5 ]
C:\WINDOWS\SYSTEM32\DRIVERS\MSISADRV.SYS
[E9013D05C43A68E4820540D413569415][1 292864
77003C6942DB343E8723A93D47FAA5FE0CFE4BC7 ]
C:\WINDOWS\SYSTEM32\DRIVERS\MSISCSI.SYS
[D8A1393038D9E6C803E1DFEDEF386E23][1 34816
6F6C8C8BFCBC30E437056FAE7C428F143BEAB764 ]
C:\WINDOWS\SYSTEM32\DRIVERS\MSKSSRV.SYS
[6479443BB89DBAC3BBCE9C2517EFAD0D][1 81920
B6EA55F95DD3FA779EC2D787779FD0CED233EABD ]C:\WINDOWS\SYSTEM32\DRIVERS\MSLLDP.SYS
[226F3D5F50000A36CE3B62C8121CD74A][1 11264
A85C3DA30CDC768477CB218603C645646BBF2F44 ]
C:\WINDOWS\SYSTEM32\DRIVERS\MSPCLOCK.SYS
[DE7DA242F4A7C0882006ADF6C541FA33][1 11264
0B99F45256FEDE50CA8C21A7E4A3F73BDB5618BA ]C:\WINDOWS\SYSTEM32\DRIVERS\MSPQM.SYS
[A4D1316CB4EF1B753DE772C342F091AA][1 317456
6CBD9F1E4908B6AD0D17896635B947C7EF44A570 ]
C:\WINDOWS\SYSTEM32\DRIVERS\MSSECFLT.SYS
[6EE73A7918BC1EC7EFAC4A32DCFC8B13][1 45880
AC55093D05A5AA56DDC28B6ADCC4F08E46E3409C ]
C:\WINDOWS\SYSTEM32\DRIVERS\MSSMBIOS.SYS
[18CE49B3D3C73B3DF4B5D566F0BADCC3][1 12800
2BFF74F70A6A488A647C434031A232298A692AD6 ]C:\WINDOWS\SYSTEM32\DRIVERS\MSTEE.SYS
[DA4A165EFD14AB23DC9210A806252B41][1 16384
AFA0B5E412F9AA09188D5F97FBB6FAA35D172FD9 ]
C:\WINDOWS\SYSTEM32\DRIVERS\MTCONFIG.SYS
[5C7905E2EB6BE00E9C998A4BB8EC233D][1 130360
444BD618A3B8B3BC8D497F6CFD610D7EFDA61267 ]C:\WINDOWS\SYSTEM32\DRIVERS\MUP.SYS
[724459B4B727662A5F69A12AD31FC197][1 63800
B4808D92AAA56210BAAA77DC015FA0341146A442 ]C:\WINDOWS\SYSTEM32\DRIVERS\MVUMIS.SYS
[1599EAB4DC6DE373BC57F768A6AE770F][1 153616
76FB9108469A2A5DD3919B5A96076F070608051B ]C:\WINDOWS\SYSTEM32\DRIVERS\NDFLTR.SYS
[66883438C1B3273F31DB8A7924D8314E][1 1360896
F06ED6EF4B01CEE7D45969A4724DC5417FCD46A8 ]C:\WINDOWS\SYSTEM32\DRIVERS\NDIS.SYS
[10D7989C206DFB0CB7AF85C38EE323D3][1 55808
6C71ECC92401C5DE96101BD4E1FA35DF87926CFB ]
C:\WINDOWS\SYSTEM32\DRIVERS\NDISCAP.SYS
[D51A226E5E7803894596683F6E0DC5B6][1 134656
F6BE517AC440382187080E1F5D7EF906CB6CDC60 ]
C:\WINDOWS\SYSTEM32\DRIVERS\NDISIMPLATFORM.SYS
[E997374B5EBB4FC5528B4F653B2E6CAB][1 28672
5C30C93674063BBE1776E2E4A04485DC13D01B03 ]
C:\WINDOWS\SYSTEM32\DRIVERS\NDISTAPI.SYS
[3BBF4C8BB52DCB265EF71E4F75369C65][1 69632
140EBD56C5B3A052E1CB55211DC961C042D0FFCE ]
C:\WINDOWS\SYSTEM32\DRIVERS\NDISUIO.SYS
[69E1E41C47B2B11C53A6193E49ADEF11][1 20992
8C6472FF1A0EB59BB3D5EF1654F3E5C9E19FDCDA ]
C:\WINDOWS\SYSTEM32\DRIVERS\NDISVIRTUALBUS.SYS
[F9FACC5EA4D793F8265F30C2DA0EDBA7][1 206848
3734B4D32294395FC91D1A759FC888770DDD1A35 ]
C:\WINDOWS\SYSTEM32\DRIVERS\NDISWAN.SYS
[438BB0743B2AA510D616AD81ECE2FA08][1 70144
6EFEB79A8C3FB660B8B86F21D50040A30B5AC587 ]
C:\WINDOWS\SYSTEM32\DRIVERS\NDPROXY.SYS
[5DFB139945F70FA15CAF7F3929B932AD][1 132096
1AAF75CEC2CB84D0AB545FA823CC2261F721F020 ]C:\WINDOWS\SYSTEM32\DRIVERS\NDU.SYS
[BC36AFFA77E02ED12317C33B07B78238][1 184320
A28E4F7D31D7AD9A793FA4CCAAC30DE029EC0541 ]
C:\WINDOWS\SYSTEM32\DRIVERS\NETADAPTERCX.SYS
[1680BBF697C0F93857131292C134A99F][1 64528
8290BCB14E0D9D11F54F1191BF9DCA421ED99694 ]
C:\WINDOWS\SYSTEM32\DRIVERS\NETBIOS.SYS
[717FC248242BDCBB3B8159B8098BD34F][1 301568
9E59ECE8FE165A632B288ECB81E6D2C45A53A399 ]C:\WINDOWS\SYSTEM32\DRIVERS\NETBT.SYS
[C0AD5C89FA61DD92E40BDD9A802C9DC6][1 234808
C452516F23990374C468D15C07395F2BB4203FC9 ]C:\WINDOWS\SYSTEM32\DRIVERS\NETVSC.SYS
[720633286CA7E9E1FD1456338317AD8A][1 27136
E014967A42C02A906CB56D158454607CD79DBB15 ]
C:\WINDOWS\SYSTEM32\DRIVERS\NPSVCTRIG.SYS
[7782D0BEEF87BFF841B5684E3FBCAC1B][1 47104
9333FD0C46677DAC6C7D5487AB744BCF1FC1EDCF ]
C:\WINDOWS\SYSTEM32\DRIVERS\NSIPROXY.SYS
[E52627112D11E7F96879FA0245902209][1 148480
6FB69F1DADD24226679A1D41ED50218E1C2F4C81 ]C:\WINDOWS\SYSTEM32\DRIVERS\NVDIMM.SYS
[BE048641E0F24F422B8A269AC3CBDA83][1 150528
CCBA2003BD6053FFAEFAC13DB902C3B4A5B2E936 ]C:\WINDOWS\SYSTEM32\DRIVERS\NVRAID.SYS
[1D08E2FFF4F950CF303B981C97D921D6][1 166400
BA331A717CC4D0A8310CB7E63E4E1A3F7B9F6637 ]C:\WINDOWS\SYSTEM32\DRIVERS\NVSTOR.SYS
[5B8D57A3FA8AFD8EA21240E10E570E4E][1 550912
2830DB690E9EC1124846BC53C5542D5E10A7B8BD ]C:\WINDOWS\SYSTEM32\DRIVERS\NWIFI.SYS
[14D167238A8C42EA8E951A5A956DEF42][1 159744
E8E112D765CD47F845B8BAB691348FCEE0BC57E6 ]C:\WINDOWS\SYSTEM32\DRIVERS\PACER.SYS
[838C9F2D2EB6D29776AF1AC78B4AA1D7][1 106496
72DE615047C83C6452C76640AEAC652D38886A60 ]
C:\WINDOWS\SYSTEM32\DRIVERS\PARPORT.SYS
[032F1C32A6A97C317AEFF9D64D2A1D8A][1 40304
50D027EB8240A4C0D4610E47A912DC8E4D6D88E5 ]
C:\WINDOWS\SYSTEM32\DRIVERS\PARTIZAN.SYS
[5DE91FBA48F6179083F2860CFF4905EB][1 176640
BEFCF51523CC4A16645D8DD61D0625FE1D790982 ]
C:\WINDOWS\SYSTEM32\DRIVERS\PARTMGR.SYS
[79BE670056FF45B9B6280B1FA55FFD90][1 421176
DD268DDB9BD6A34BD577AB0B638ABAB4E8D88C4A ]C:\WINDOWS\SYSTEM32\DRIVERS\PCI.SYS
[D72B9224E91AD87B88ABAFE5B8E1885A][1 16696
E7691F8DE8D15D701BC24C7DD9191DE1745F8ECF ]C:\WINDOWS\SYSTEM32\DRIVERS\PCIIDE.SYS
[F0638A0AB447F0A46D36F28E8F817AAC][1 126264
8C6A69B866B60AC9E99EE2C6DEE9734D2AC7164E ]C:\WINDOWS\SYSTEM32\DRIVERS\PCMCIA.SYS
[4AC3A1D2F9AC74DA7BA3A30344AAB664][1 57856
5587E73F7B12291265C592F6E9831D3E8314DDEA ]C:\WINDOWS\SYSTEM32\DRIVERS\PCW.SYS
[A90AE269096D22897BC7219922ACF12B][1 157184
4C0789ED875C3C9B6F57EECFFD7D4D2D4C4BCA0F ]C:\WINDOWS\SYSTEM32\DRIVERS\PDC.SYS
[E4518C35D159A468A789AB216A03AE8C][1 816640
898650B6588CBC3AB2E3F248746885106E4463DD ]C:\WINDOWS\SYSTEM32\DRIVERS\PEAUTH.SYS
[B289D34C47978B8AB473BF19DB66BB91][1 58880
1CBE509B4D314B9516902909B7B7279593F8A3F8 ]
C:\WINDOWS\SYSTEM32\DRIVERS\PERCSAS2I.SYS
[446B72ACD460A1B8C46DA7FF2F018A82][1 68608
A351E77F5A489C48D3DC39D02171E5D36C4D28ED ]
C:\WINDOWS\SYSTEM32\DRIVERS\PERCSAS3I.SYS
[5CD0064D4642934BC5979EF8135180DC][1 85504
52B0F02ADC2D22D73D955924BA2D1EF549569DF2 ]C:\WINDOWS\SYSTEM32\DRIVERS\PKTMON.SYS
[DA8CB2643EDD2DA82BB804A8712796D0][1 117248
747E2B01CB39B971CD18AB8804E2A2004EB1E71B ]C:\WINDOWS\SYSTEM32\DRIVERS\PMEM.SYS
[BE7468019B1731CA2FAA030C13DB1913][1 17408
5CFB70BDD599CD5E84621A85B21D5555E11253AD ]C:\WINDOWS\SYSTEM32\DRIVERS\PNPMEM.SYS
[738FD8811518AC7A630A277BF1CCF389][1 194048
A232A354767EA31734A54A70EBF438D477159218 ]
C:\WINDOWS\SYSTEM32\DRIVERS\PROCESSR.SYS
[4DAB92FD311B9F841EE40EF7B967DF8E][1 53248
D8B60E074120E0D8F9AAD6066B54F1066786AC47 ]
C:\WINDOWS\SYSTEM32\DRIVERS\QWAVEDRV.SYS
[342F9BA59313C2B796241DCECE18B727][1 41784
E243808116E2531494F4194E2627C7F8AB916993 ]
C:\WINDOWS\SYSTEM32\DRIVERS\RAMDISK.SYS
[7BE861DDB225B0C373FE1FCA3BE8A3B0][1 19968
8BB44BAF39D5038032C66FAEFF2D32AD80E2AB56 ]C:\WINDOWS\SYSTEM32\DRIVERS\RASACD.SYS
[6E28E1CE915FE617D4F38BFB8543696F][1 111616
F78303B351E59FA42AA4D4D300F17D5D3246A69E ]
C:\WINDOWS\SYSTEM32\DRIVERS\RASL2TP.SYS
[252FDEF9B98564F47A36CF11911D926C][1 87552
2B13E5593D88C2CBFB005B7A3AF35D7C12A2C6E6 ]
C:\WINDOWS\SYSTEM32\DRIVERS\RASPPPOE.SYS
[3515CD197282D7C867DCBD973CD44E3E][1 103424
6A9E38DDAC0BE7F6BF5DEF1A62EBE0C99B90C962 ]
C:\WINDOWS\SYSTEM32\DRIVERS\RASPPTP.SYS
[71A6C25E3B9C7BDF0ACE20958F2CF8C4][1 84992
EFBBCD6D9BB5105776A3107E5FAD1D2E6D911A95 ]
C:\WINDOWS\SYSTEM32\DRIVERS\RASSSTP.SYS
[54BFF443F91F970F61B377A589CF38D8][1 453944
13AE5E1749DA1E90C83F8FDE42CA6C0AC68DB1C1 ]C:\WINDOWS\SYSTEM32\DRIVERS\RDBSS.SYS
[76C18F3B4EB5BC611FA7F249CF676911][1 28160
C345B5E4FE052D6025BB6B8DBEA25B5B97E3C231 ]C:\WINDOWS\SYSTEM32\DRIVERS\RDPBUS.SYS
[1AEE22C5FBF18F53C47AC4373F0DB542][1 166912
C65B608FA25C3862CF173113B62D9446C4BFF5B8 ]C:\WINDOWS\SYSTEM32\DRIVERS\RDPDR.SYS
[0631645A1C5196BA5D5AC6C186CF55FA][1 31760
666F00663E95FF202E7E8C162AC13EA2801A988A ]
C:\WINDOWS\SYSTEM32\DRIVERS\RDPVIDEOMINIPORT.SYS
[88FC2D00DE5A999E29B8FD432DE3A071][1 295440
F280712948370123B48806446E22D2E3143456D5 ]
C:\WINDOWS\SYSTEM32\DRIVERS\RDYBOOST.SYS
[D8D7FEED713C25F089CE0768C266EAA1][1 202240
0437793F78F1676B267921F7A56FC2B23B91E32E ]C:\WINDOWS\SYSTEM32\DRIVERS\RFCOMM.SYS
[DF8FE557182A7B2C2D7ED893A04A63E9][1 108032
CA145758D920421DEBB32520EBBE3FB724849F2B ]
C:\WINDOWS\SYSTEM32\DRIVERS\RHPROXY.SYS
[7936E95FFEA1758638715C6465B2A739][1 89088
E42DCD3A5D984B0D574DE65B26140717039FE5B4 ]C:\WINDOWS\SYSTEM32\DRIVERS\RSPNDR.SYS
[7E29520C0B9E3E4039C8D2946557CF3D][1 605696
91C0E8CFB6D409B809CFA9C12004D42BAEEC8BDB ]
C:\WINDOWS\SYSTEM32\DRIVERS\RT640X64.SYS
[48AC5F706780BCC34811EA89A0727189][1 4518136
180DFF2F70367FFFFB46E560CFC242E67FC750E3 ]
C:\WINDOWS\SYSTEM32\DRIVERS\RTKVHD64.SYS
[CEE65C35DBCFD71CDDAC291E54DF1722][1 430720
BEE53A205CFE90FC5F7EECA8F1A8656D7E82968E ]C:\WINDOWS\SYSTEM32\DRIVERS\RTSUER.SYS
[4873CF79FBE56B9B35C1DE3EEB907A50][2 329944
]C:\WINDOWS\SYSTEM32\DRIVERS\RTSUVSTOR.SYS
[9C7CECCEED1FF5818CD5A118258EE0C5][1 118584
F7D9BB393491E5643A754782589BA3B47D120039 ]
C:\WINDOWS\SYSTEM32\DRIVERS\SBP2PORT.SYS
[EFBD152E3DBA02D06C7D2FF1E034919B][1 44032
9E360EDE57FB8D2BEB0AECF52AD04C2E132E5292 ]
C:\WINDOWS\SYSTEM32\DRIVERS\SCFILTER.SYS
[6274ED5017EEFE775FDDF9082271472E][1 135168
6BD4B5896272BAC632AC5574ECE9CABAED5319B3 ]C:\WINDOWS\SYSTEM32\DRIVERS\SCMBUS.SYS
[460E007E94F053F56D3FA9DE486B7146][1 298296
39AFCEEF49EAC41CFB212D5390BFE5444ED5B669 ]C:\WINDOWS\SYSTEM32\DRIVERS\SDBUS.SYS
[1E7ECD63D209EE5CE02E582CA8918023][1 33080
147AB2FBD0440481E26FDAACFA8B0DD89DFE6705 ]C:\WINDOWS\SYSTEM32\DRIVERS\SDFRD.SYS
[7B58DD1E1CF8E1AE2A22C8CFFBDA3DB3][1 102712
25897F84E672D4F54987E5E4EC31FC7B00C44AC9 ]C:\WINDOWS\SYSTEM32\DRIVERS\SDSTOR.SYS
[4358940866F520CCF4D64185F771F19C][1 76088
E6AD131360C257C38A99F80CF1C9644736EA03D6 ]C:\WINDOWS\SYSTEM32\DRIVERS\SERCX.SYS
[AAE554DB5302A636B078F9C19E02E7FC][1 156472
E362B91741139127C0EFB9144F655A4A69259BD2 ]C:\WINDOWS\SYSTEM32\DRIVERS\SERCX2.SYS
[51B9B16E99B1EF7D2107629DB8C4B578][1 27648
A21397A14DD127693CFFDF5211952CE6F806F555 ]
C:\WINDOWS\SYSTEM32\DRIVERS\SERENUM.SYS
[6D581AD1593B35711075886F153A8BAE][1 89600
CB5ED32DCCD3DE26DD80167F4FEDDB57489F0519 ]C:\WINDOWS\SYSTEM32\DRIVERS\SERIAL.SYS
[43E10E093B3249C78D649A4096271AA0][1 29184
55235EE77B362F8EB42436B89BEDE9C2AC398F35 ]
C:\WINDOWS\SYSTEM32\DRIVERS\SERMOUSE.SYS
[BDDF94AB15E77B54ED2CC60CCCE8F922][1 18944
8A8D2F81217FA58133E102D94F924A435F1AA8D2 ]
C:\WINDOWS\SYSTEM32\DRIVERS\SFLOPPY.SYS
[01D980C33003B078324E3FE032C8A42A][1 87552
6C1AC950BB294351F09CCF9A0FC8FB3482E0FFBB ]
C:\WINDOWS\SYSTEM32\DRIVERS\SGRMAGENT.SYS
[12E42E20BC0ABF8FC2AA5D13609ED0E7][1 45056
6B310F1E7AA80EF7742E8F7513032F786E57489F ]
C:\WINDOWS\SYSTEM32\DRIVERS\SISRAID2.SYS
[E156CB3AAF1E2C397A8F93EA9ACD8290][1 81920
94622E002EE4A5E413F4C08F7A07B0873DC291EE ]
C:\WINDOWS\SYSTEM32\DRIVERS\SISRAID4.SYS
[CFFE219F9CA183C40AA5D44DC26E6F2D][1 219960
C467461C20A280A4A20331C422A96F389501F36F ]
C:\WINDOWS\SYSTEM32\DRIVERS\SMARTSAMD.SYS
[D88FC13079D14E5403AED5F7D33A2015][1 33960
D1252933BA7C0AE321B44CE05153B8C93FF1DE16 ]
C:\WINDOWS\SYSTEM32\DRIVERS\SMB_DRIVER_INTEL.SYS
[039E1D037ED8D8F55962EE49F4B74B8F][1 171520
BF613B1E592C0653A92FC42EF850D8849A6E9703 ]
C:\WINDOWS\SYSTEM32\DRIVERS\SMBDIRECT.SYS
[AABB5699D96708CE7372C6D71D298801][1 653112
6F116C2E8C1C825D0A52377375F6E67C0D7D8896 ]
C:\WINDOWS\SYSTEM32\DRIVERS\SPACEPORT.SYS
[7EFD2145C9AD88BD2528E4DC91D55A04][1 73016
9F05E8BD90561463FCD163F37D759042D4D093EB ]
C:\WINDOWS\SYSTEM32\DRIVERS\SPATIALGRAPHFILTER.SYS
[AD40AC6DC145B2C48A58EF61AF8ECE82][1 82744
30DCEBBBCF2082788C51DB54990C92DF86FB6990 ]C:\WINDOWS\SYSTEM32\DRIVERS\SPBCX.SYS
[9A03A0D6D52859667599B7DE9A238502][1 772096
D67810CB7CF04851E7E7B109547227D841A1A9E1 ]C:\WINDOWS\SYSTEM32\DRIVERS\SRV2.SYS
[A79265A2CF42790393832EB1771E0967][1 293376
686AAF05E8586771D32343D33DF8AA77A76B252F ]C:\WINDOWS\SYSTEM32\DRIVERS\SRVNET.SYS
[CE0F176C7C3DC2AEA1C75EF6A7583B67][1 31032
14EF45A5120ED32FC2BE0CBF619EB7E8017D9DC0 ]
C:\WINDOWS\SYSTEM32\DRIVERS\STEXSTOR.SYS
[3E0B5A23A5A68051CDA332A4DFC09484][1 164152
EFDEB1D302474A05AF96A898AEC058589A48EDC1 ]
C:\WINDOWS\SYSTEM32\DRIVERS\STORAHCI.SYS
[9056D0A8791B00E841B4A5E5A04FCEF3][1 129848
C04ED5B5D2DB44DC084F5DACC886FBD92988DEB8 ]
C:\WINDOWS\SYSTEM32\DRIVERS\STORNVME.SYS
[3A82BBE802C82FE519A735F70F102D6F][1 95544
E93104A6D12F55AC8BE9599E70291E1EDE522C94 ]
C:\WINDOWS\SYSTEM32\DRIVERS\STORQOSFLT.SYS
[BC74E93B52526753408BC578C01CC786][1 51512
6AF6C7A80A726316790E0BBEB1EABE3546BD7CD5 ]
C:\WINDOWS\SYSTEM32\DRIVERS\STORUFS.SYS
[C58DC01DBBFB0DC058AC1AB792D88AC2][1 41784
DCDEE155E4EDB1A005E7BEF70774FCC713BBFE0A ]
C:\WINDOWS\SYSTEM32\DRIVERS\STORVSC.SYS
[7B4BF4CC6C96749124984A9E0AE1896A][1 66560
56012523F70FC127EB663DDF534999411E73009B ]
C:\WINDOWS\SYSTEM32\DRIVERS\SYNTH3DVSC.SYS
[94EFB93479FD9EF655BAB3B80EE5C998][1 604840
E9474B646B713A0C62C3B2065A6ED35C0A48CE4F ]C:\WINDOWS\SYSTEM32\DRIVERS\SYNTP.SYS
[66A6639AD401BAA8F92FF59FD2AAE774][1 2926904
629AE7289B25136893E45B8ABAAF0A3F4D8E307F ]C:\WINDOWS\SYSTEM32\DRIVERS\TCPIP.SYS
[A8766E18A1E2D41301E7A8EEFBABCDDD][1 54272
748815C3D4FAF79D2CF3C846C6D43B7090D6EA14 ]
C:\WINDOWS\SYSTEM32\DRIVERS\TCPIPREG.SYS
[E5CE3388A455ED80480EAE3A8ADD53A9][1 132408
8341BF01B879BFFAC9F26033E67D516F0EE74B3A ]C:\WINDOWS\SYSTEM32\DRIVERS\TDX.SYS
[DC451F4DC01E116C35121EBD6813618E][1 38944
A41F3168DFE4FF5DE009FE90FAE1728D710350A5 ]
C:\WINDOWS\SYSTEM32\DRIVERS\TERMINPT.SYS
[BF97F92E1043BC92073FAED0752B70A2][1 248120
80E4732257B87F5609144598B0DB5AB28AD602ED ]C:\WINDOWS\SYSTEM32\DRIVERS\TPM.SYS
[19DC44DF9C859396B3608F5CF5C83D82][1 64512
061BFDCE5505116A452CC1C1CED14FA262BB2690 ]
C:\WINDOWS\SYSTEM32\DRIVERS\TSUSBFLT.SYS
[C7E9FAB0880D66EFB62C2B6314284D47][1 35840
C10DFF8E82609EDCA4433351F67F3365D7D10133 ]
C:\WINDOWS\SYSTEM32\DRIVERS\TSUSBGD.SYS
[06DE25D00DA359742445B525229E9929][1 131072
3C283DFE2F8AC5B8A43C2EF8F0D3C6E574109171 ]
C:\WINDOWS\SYSTEM32\DRIVERS\TSUSBHUB.SYS
[4227DDD821E0A81448CD187B80265927][1 124416
08F5BD761E407647769099E4D64198B6E6252EB1 ]C:\WINDOWS\SYSTEM32\DRIVERS\TUNNEL.SYS
[4631D2B2B5567A768389796A267ABED9][1 84792
AF453975F9A8B46B178B0AE8E915E735901FB969 ]
C:\WINDOWS\SYSTEM32\DRIVERS\UASPSTOR.SYS
[B5A296C6DE5A56B62FB98859A8AB6C10][1 146944
8347B915D62D511BE8A6CEFEF21FBB1FE4EDE484 ]C:\WINDOWS\SYSTEM32\DRIVERS\UCMCX.SYS
[9E8CC2A2F39A6C5377B4A2D3A061A429][1 162304
D8E40EE4671B52A5200795DA076D18F6270EBC9B ]
C:\WINDOWS\SYSTEM32\DRIVERS\UCMTCPCICX.SYS
[EB21892E714A16FAA18642F3A53A26B8][1 61440
916D9304889072E089A1F87BF0D3F495428342D1 ]
C:\WINDOWS\SYSTEM32\DRIVERS\UCMUCSI.SYS
[41ED24E49525CB10312C707112E34C98][1 31232
EB1007ABA68264CD6DFADFE988ACEF43BD08F774 ]
C:\WINDOWS\SYSTEM32\DRIVERS\UCMUCSIACPICLIENT.SYS
[B107AD3336E791B7B0F8E87301D23E44][1 99840
D5811FA598C36FD7925FD69CD377FBFB8295A04F ]
C:\WINDOWS\SYSTEM32\DRIVERS\UCMUCSICX.SYS
[8BC17A0C2D93B66CDA5C5A9DC6854406][1 236344
7FF8E185CFF5D09F5140BFA2159D63D50BB35CA5 ]
C:\WINDOWS\SYSTEM32\DRIVERS\UCX01000.SYS
[EDFDDA5AF0557E6BF265893A223EDDD0][1 48128
A3B0C2736C902B3454D20463FDD57B22D0F2821E ]C:\WINDOWS\SYSTEM32\DRIVERS\UDECX.SYS
[9C5951944F78F3233CCB76273FCFCAE4][1 340480
A3AFE5F416F26F3F706C9D81C353D1F135D38E28 ]C:\WINDOWS\SYSTEM32\DRIVERS\UDFS.SYS
[E1D26FA75626B66D0020E07E30CDEC8C][1 30008
93AC6496E7FC139F6D7D430F665879863E47FFF0 ]C:\WINDOWS\SYSTEM32\DRIVERS\UEFI.SYS
[3556FCC172C935D65C3A682B30A54985][1 41272
4C55DED486A03EDB9CC64D586C336603532D2D29 ]
C:\WINDOWS\SYSTEM32\DRIVERS\UEVAGENTDRIVER.SYS
[D88BCBABE51CCB450B3DD1C696D9DD80][1 292152
C9A9F9D5B8F4FABC6AE4976307CB2389A6BD7A26 ]
C:\WINDOWS\SYSTEM32\DRIVERS\UFX01000.SYS
[D5E1A8CB08CEF619E0949535C917621C][1 99640
5AAD0431668DF73BC5127F4D32A74080FA7823A8 ]
C:\WINDOWS\SYSTEM32\DRIVERS\UFXCHIPIDEA.SYS
[EC86C5BF1EBE408BA39730EDAAC93353][1 147256
F7457323A6751906AE5EA2BEABF4000C502F8752 ]
C:\WINDOWS\SYSTEM32\DRIVERS\UFXSYNOPSYS.SYS
[07B0CD801BBF164F36DA3EE9F25C721D][1 56832
4596FF7FCB5C8AFB68CFD0F17BBBDC8DEB07193D ]C:\WINDOWS\SYSTEM32\DRIVERS\UMBUS.SYS
[826827B952041E884774E0A87AA3D216][1 13312
98A7062062FA91DCA93317E1556874D72DDBC095 ]C:\WINDOWS\SYSTEM32\DRIVERS\UMPASS.SYS
[CEE726DA975EC26A10857CB1E2FCA041][1 14984
254E200A741E51DEF652E8A81613FDF083969673 ]
C:\WINDOWS\SYSTEM32\DRIVERS\UnHackMeDrv.sys
[AF79E1A4747418B190F36877977485F6][1 28472
4A62BAF6EC521826AEEEB76B5E76B1DE221A58C7 ]
C:\WINDOWS\SYSTEM32\DRIVERS\URSCHIPIDEA.SYS
[0BA7174544F4064EF5C9383BA8EDAC78][1 68920
ABD79C4444624D59059F33DECF578C35FE1C9BD6 ]
C:\WINDOWS\SYSTEM32\DRIVERS\URSCX01000.SYS
[7DDE04DB56833A97492DC3013D4B3239][1 27448
52786204E7474EE9E743324597B1C5DA6C8BBBFB ]
C:\WINDOWS\SYSTEM32\DRIVERS\URSSYNOPSYS.SYS
[B116EC25D7AD2EDD602A6EDEA8D7681C][1 179000
4AB159894D483E17F137117DDC4021997CD840B5 ]
C:\WINDOWS\SYSTEM32\DRIVERS\USBCCGP.SYS
[E7BFC2CCC6D416673A1698781991C656][1 106496
C85F32384AB3F6E09654F961F17918A1A526C0CB ]C:\WINDOWS\SYSTEM32\DRIVERS\USBCIR.SYS
[4CABA64DF4B1F3E772E70FD4FAE6CA0C][1 99128
9444C604A2A954068E010E2605889211FB10EBB2 ]
C:\WINDOWS\SYSTEM32\DRIVERS\USBEHCI.SYS
[04A34578BC8A70B5698D1D950C4F22FB][1 535352
961B5452736C6515702A815ED218BD1AFB786FD7 ]C:\WINDOWS\SYSTEM32\DRIVERS\USBHUB.SYS
[6C5563F34424790A8F23985D837D18C0][1 586552
3B1077634903550E8532E4450F80EA92143EEDB3 ]
C:\WINDOWS\SYSTEM32\DRIVERS\USBHUB3.SYS
[DCEB4F28AE40D0D9B80177C2072545D4][1 30720
53399D7128A04F29C1547C7A9C8446C1ADE47C04 ]
C:\WINDOWS\SYSTEM32\DRIVERS\USBOHCI.SYS
[AB3AD5D5F58FF144094052349E85459D][1 29184
663EADDC827F541E9E9E75DA8291221704ECF693 ]
C:\WINDOWS\SYSTEM32\DRIVERS\USBPRINT.SYS
[EE67BDAA526DB1538D514C1BB8EE227F][1 73216
B303F1BC977FE74ED3A1C55DD6D1FADAFD0CDC0B ]C:\WINDOWS\SYSTEM32\DRIVERS\USBSER.SYS
[FF22D57250991143E6E969EE7BFAC0F1][1 138552
C6DD85ABA5BEE8D5C54A38D300908C28FDE54C70 ]
C:\WINDOWS\SYSTEM32\DRIVERS\USBSTOR.SYS
[2DAEB3D979208B3DDA0C480BFD1D6A3B][1 35840
01715A2B44A47B3C7E5C47A3632810A39597BA13 ]
C:\WINDOWS\SYSTEM32\DRIVERS\USBUHCI.SYS
[5BDF58D2E5556465189C2FDC7DDC1803][1 300544
69021506D06DC27342B46511AC801CD92717DC73 ]
C:\WINDOWS\SYSTEM32\DRIVERS\USBVIDEO.SYS
[10165ECCC7A1DF3C1B6AA53C8EB2A87F][1 467768
BB8156D6E9FD2F161D489482EFCF20246DC3EBA9 ]
C:\WINDOWS\SYSTEM32\DRIVERS\USBXHCI.SYS
[C06E30A8EE21D4E8AB184F985DD50C12][1 55608
1416CD77D41287138295D3D1CBFA8B93A470EEED ]
C:\WINDOWS\SYSTEM32\DRIVERS\VDRVROOT.SYS
[A9957C709EE8AB75837916648827B900][1 237056
39327A82319D22D9BE7CC749A0431660AEC82DD6 ]
C:\WINDOWS\SYSTEM32\DRIVERS\VERIFIEREXT.SYS
[2CD9E1B442B8BD5FC7F879916D49E692][1 751928
774622371E9B7D7C328A4557C99E96A3DDE085A0 ]C:\WINDOWS\SYSTEM32\DRIVERS\VHDMP.SYS
[562C0C9FFF08A6DF60D858E6482E35CE][1 37376
9938A977DE562FB0269FFB6705E79A8F2B744DAE ]C:\WINDOWS\SYSTEM32\DRIVERS\VHF.SYS
[EF47B2B95A428110D79C6357C6079AE7][1 519696
E863CD4FF614A686CD03E55B6809DE25C774D20E ]C:\WINDOWS\SYSTEM32\DRIVERS\VID.SYS
[A898490F7840AB1012D70887DEB20106][1 127288
C6D7897AEFFA1F931C53BABCFBFEDC38BAD84D29 ]C:\WINDOWS\SYSTEM32\DRIVERS\VMBUS.SYS
[C3B4E43D5283D32E1D3890D101C70C1C][1 27648
664E51E0F6E0A08E9C6C81F3A87CC6B11631463C ]
C:\WINDOWS\SYSTEM32\DRIVERS\VMBUSHID.SYS
[0B7CFD2F8B043740CE20A23B666DE408][1 21816
CD81D362E1E3D71395AD9A57FCB01130A3B26E2D ]
C:\WINDOWS\SYSTEM32\DRIVERS\VMGENCOUNTER.SYS
[634A15C2B5CC3BBB151F2AFE9C3AE031][1 18232
1D575FC4BDA7E0ECD5A2DFB601650E78D9E292EE ]C:\WINDOWS\SYSTEM32\DRIVERS\VMGID.SYS
[FC7A59A1AA07632AF8E9DC254918F879][1 9216
3799D327608DF73AB8E342E47D497CDEB92F55A8 ]
C:\WINDOWS\SYSTEM32\DRIVERS\VMS3CAP.SYS
[6CC21AB292E58758F151456D0ED3A628][1 51512
9AD7C8442B80FB09F93617252A9D0815F8662C92 ]
C:\WINDOWS\SYSTEM32\DRIVERS\VMSTORFL.SYS
[F5B761B65CC090F32C97D9311AC246E2][1 89912
A17AE24408F067412903D462207D1CA10D7137AE ]C:\WINDOWS\SYSTEM32\DRIVERS\VOLMGR.SYS
[23C594CF5049DF2096D2D9ECBADEF29F][1 389944
6B6718C7FDB3D8E34A785EF7CE19EF6411272D24 ]
C:\WINDOWS\SYSTEM32\DRIVERS\VOLMGRX.SYS
[0F13F63BA93C89DA4F54B8830EB5410B][1 427832
E818316469F8EFB2CF4B48CCC5127076DB3E4F91 ]
C:\WINDOWS\SYSTEM32\DRIVERS\VOLSNAP.SYS
[C0F4049CBD0632DA2B3E1F515A460531][1 16696
906E2CD9F6757972372BC34AAE5202E9746EA3C1 ]C:\WINDOWS\SYSTEM32\DRIVERS\VOLUME.SYS
[915D53A7C56FE47F617F0714511AF869][1 79672
EFBF0F6FCF69248AC72B2D6DF0BFE2BB238B244F ]C:\WINDOWS\SYSTEM32\DRIVERS\VPCI.SYS
[EE4D650D73A565F7921C6F097ED6E709][1 166712
4337406E9E8C276A8EE72D766F76CD9E28C70628 ]
C:\WINDOWS\SYSTEM32\DRIVERS\VSMRAID.SYS
[B4E3EB14D422A128EE2C391A05C8958A][1 305464
CE87B1AA7A53981474E573B6BE39766A9D4411EF ]
C:\WINDOWS\SYSTEM32\DRIVERS\VSTXRAID.SYS
[F978AE0389352BEA2EA921600AF64C16][1 27648
4AAFA6E8F4FF80934D1C8CE02C756E7EB6362BFA ]
C:\WINDOWS\SYSTEM32\DRIVERS\VWIFIBUS.SYS
[510865271FDA73ACE622A4E74CEDC32E][1 78336
303415C604555B377FECBED141F6B5437449E5A1 ]
C:\WINDOWS\SYSTEM32\DRIVERS\VWIFIFLT.SYS
[CE7E2BD9759702F635CB7F268DDD449A][1 47616
02CEFC4F02D4A9D2AB8C7579314FC371642188F0 ]
C:\WINDOWS\SYSTEM32\DRIVERS\VWIFIMP.SYS
[4943F603998D4AF78D403A3461D89508][1 30720
F5CAB79119DAFC87C1EA8D2E15CEBB8EFA50D4B8 ]
C:\WINDOWS\SYSTEM32\DRIVERS\WACOMPEN.SYS
[FF91879639B18FEBC6F509401686FCDD][1 92160
19E91BA0BEA2F0EF8C5BD85D58F601006B91EA35 ]C:\WINDOWS\SYSTEM32\DRIVERS\WANARP.SYS
[95C4DB08A740015BB3FB5659F16EF321][1 169784
32CC4B45E50E75849F3205326B0F5C573F9F8B57 ]C:\WINDOWS\SYSTEM32\DRIVERS\WCIFS.SYS
[9CDFAC4943F24A36EA741645F3E6769A][1 87040
DEABC21F7F06524195B3767A75CC16EF809B12DE ]C:\WINDOWS\SYSTEM32\DRIVERS\WCNFS.SYS
[E6B9D4C5BB2C8B7BA7946EC54392B14E][1 46584
C62D45E71D656B762F63412FBC6FC7E390B26EEB ]C:\WINDOWS\SYSTEM32\DRIVERS\WDBOOT.SYS
[2F76D984214FCE6DC7037A7E1094E062][1 843496
CD94A5C11411BDAF8DA56A582764B58B1DD24F28 ]
C:\WINDOWS\SYSTEM32\DRIVERS\WDF01000.SYS
[C0100756EBE0B8CCC9517949A0809893][1 340008
CDE6F76B5B887F1908E107FDED6FC03F23E73BE4 ]
C:\WINDOWS\SYSTEM32\DRIVERS\WDFILTER.SYS
[FD044582B0529793AD198F773F58F211][1 806912
970F272B52BD9D0BB65F35BDEBDACAFECBF39645 ]
C:\WINDOWS\SYSTEM32\DRIVERS\WDIWIFI.SYS
[76C194DFF2EDEFE3BD0C731C267BC6F8][1 22016
4E308F2522836B3A358FFC036BF61D466FC6D79D ]
C:\WINDOWS\SYSTEM32\DRIVERS\WDMCOMPANIONFILTER.SYS
[CF07A18380EBA6609F66002B82BE2E84][1 61992
5D70158A24D7BEEA765F9111EB72014F7038AF86 ]
C:\WINDOWS\SYSTEM32\DRIVERS\WDNISDRV.SYS
[F2E1963A78B8CCDF8B70A4FD235A7576][1 179712
B5552491B3276FA0559FE3111B54632FBF38B80D ]
C:\WINDOWS\SYSTEM32\DRIVERS\WFPLWFS.SYS
[2F304DE29F3D5F2360DF902084BB5B45][1 36664
D24C398842CC381EAD9E00AD6E88A53C72492D61 ]
C:\WINDOWS\SYSTEM32\DRIVERS\WIMMOUNT.SYS
[7D35D1A936E3D291851A8D01D5F7AA79][1 74216
833E26952D55E2F7D11DBDDD3BBF632E366BE707 ]
C:\WINDOWS\SYSTEM32\DRIVERS\WINDOWSTRUSTEDRT.SYS
[F179027B9FE048633A60D782E1132AAA][1 17896
63190721BA7D69932E59EE43C944BF62202CF6FB ]
C:\WINDOWS\SYSTEM32\DRIVERS\WINDOWSTRUSTEDRTPROXY.SYS
[C2610A6427166E0999CEA79A3128B915][1 37688
B358ABBAC2D3B97CD0D0D601E957F9202245C18A ]C:\WINDOWS\SYSTEM32\DRIVERS\WINMAD.SYS
[B7FEA2CC1333D4C30E58E89F682D8BCB][1 240128
6BC3FAF370C64C2E51C7F1AE0D699263121446E8 ]C:\WINDOWS\SYSTEM32\DRIVERS\WINNAT.SYS
[33FB24F528B7B48AC594B95557922D6A][1 156984
6A92399D5721082B14BE6F2A938E6AE4B44623FA ]
C:\WINDOWS\SYSTEM32\DRIVERS\WINQUIC.SYS
[9A0D43B4E4530C8BE34DAC3119FD5780][1 95744
6BAD62782F6384154F3055E8573298B9B32E9E33 ]C:\WINDOWS\SYSTEM32\DRIVERS\WINUSB.SYS
[D805E030EC7503ABD98158E0C28E1092][1 77856
92135D974CEF12A83544FE53BF973D02896FFBDD ]
C:\WINDOWS\SYSTEM32\DRIVERS\WINVERBS.SYS
[8943C52909164A64195645C618C276BE][1 19456
D57D711B5CA47594F745C1C69BA39DC0F5547462 ]
C:\WINDOWS\SYSTEM32\DRIVERS\WMIACPI.SYS
[4D5E154DE168E4A3B90F86A1966CE5D1][1 30008
DAE3934D6CC309CF2F3917C510DB92834BA6CE06 ]
C:\WINDOWS\SYSTEM32\DRIVERS\WPDUPFLTR.SYS
[C4229EDA839055DAB514F74D3860C23E][1 24576
03910453D77FD9B3F65C69DFFB6E70EE01603DBA ]
C:\WINDOWS\SYSTEM32\DRIVERS\WS2IFSL.SYS
[5A632AFC20B5BCF9D33A60AA3F2B85A6][1 134656
68BA89E8D9B31F7CA12489DD64ECCA0920D02A91 ]C:\WINDOWS\SYSTEM32\DRIVERS\WUDFPF.SYS
[6C3D8C8C991B62588C52336C5F60423C][1 282112
CE3F5E4DCFA631F1DF12A54B2A227A5069695587 ]C:\WINDOWS\SYSTEM32\DRIVERS\WUDFRD.SYS
[A56ABFB5B8FC315A63B599B2273B7444][1 317440
E0FB2DCB45DF7DA841CAC65A5FD5D0DDAEF3C488 ]
C:\WINDOWS\SYSTEM32\DRIVERS\XBOXGIP.SYS
[30FE2A17957C4D5466FBE684F83730E6][1 48128
58F601B9A07C21621FF72B7E268EFB244E20C0FD ]
C:\WINDOWS\SYSTEM32\DRIVERS\XINPUTHID.SYS
[5D97E67BAA0EE0AA78EDDE8BE78344B6][1 68096
AD12015D4F1002013C18936EFFBC0FDEB7190666 ]
C:\WINDOWS\SYSTEM32\DRIVERSTORE\FILEREPOSITORY\BASICDISPLAY.INF_AMD64_5103AC179273B
E89\BASICDISPLAY.SYS
[5DA606023922A06B1C4160761EDF5AF3][1 37376
D18FB6E07248E83842420C34A87E588E1B72567C ]
C:\WINDOWS\SYSTEM32\DRIVERSTORE\FILEREPOSITORY\BASICRENDER.INF_AMD64_0B8D03C3BC0E7F
D9\BASICRENDER.SYS
[7841121E05EE3D540266092A6E86AE77][1 40960
B768B0599360ABB86996461B330962DEBCCC040B ]
C:\WINDOWS\SYSTEM32\DRIVERSTORE\FILEREPOSITORY\COMPOSITEBUS.INF_AMD64_E4D35AF746093
DC3\COMPOSITEBUS.SYS
[B8ACABC8939CB50047C2BF0272B5156C][1 18944
258244C45ED2615224AEA1828BF32D5A3ED5C4B5 ]
C:\WINDOWS\SYSTEM32\DRIVERSTORE\FILEREPOSITORY\SWENUM.INF_AMD64_31F554B660026323\SW
ENUM.SYS
[C5620DB0168CA8FF93B2F378A877CCF2][1 152064
CDF50447D4DEC8CABE6DEF7DCDDF2BD9E3E21667 ]C:\WINDOWS\SYSTEM32\DSSVC.DLL
[84B2EC0DFF47099E0F05D4C1173ADBE9][1 359424
FBC7A28216F5D8460CFE61CA365F746772CCA4B1 ]C:\WINDOWS\SYSTEM32\DUSMSVC.DLL
[38833EC9E139654135BD183DFBABC36B][1 50176
A2198B6D266720E3139554C2781E0F4586D29F80 ]C:\WINDOWS\SYSTEM32\DWM.EXE
[03BB081F55653A11C9D7DEFED559AC6E][1 110080
2A9CCC74FDEB8159F835BD80843B4AEF9DCE6DAA ]C:\WINDOWS\SYSTEM32\EAPSVC.DLL
[391BA0E22634DA7996EAE59FA86023C7][1 79872
B83DA99A63E1BC307AD3DBA9B31A337029F77A1E ]C:\WINDOWS\SYSTEM32\EFSSVC.DLL
[27C0AB2D8630F45877837537367673C5][1 168960
FE34D7418EF507C098163F2CC543F27722646D4D ]
C:\WINDOWS\SYSTEM32\EMBEDDEDMODESVC.DLL
[25222B73D463284A85D32A56F002BD62][1 490496
07312D1E8ADF86E563FD7704A3617D2461177A9F ]C:\WINDOWS\SYSTEM32\ES.DLL
[B76160030D8254639E5FA949CE00850B][1 21504
798880FE4B5C9E932FC725FDEFE8AADBA97CB87D ]C:\WINDOWS\SYSTEM32\FDPHOST.DLL
[8CED235DE8C2F476022E04DEA1AA786B][1 35328
7C60165AC5F2BC085F77F52E674763E22AF2C622 ]C:\WINDOWS\SYSTEM32\FDRESPUB.DLL
[738BF8CD600B313FBC40FCDEF5C81550][1 120832
EEB4B9F9C20E5B11863F76D6E1695C6B072B30E7 ]C:\WINDOWS\SYSTEM32\FHSVC.DLL
[8412671AADE74110F385242CD2BAEA1D][1 889344
9379C76B8A63205A1066A0E8442E8AFC0AEBEC15 ]C:\WINDOWS\SYSTEM32\FLIGHTSETTINGS.DLL
[0C03F3CE69034D1D76D2FF2D3E0F8A03][1 1903616
D76DA6208A733D7E93101D6E09B59EE63B3BB3BD ]C:\WINDOWS\SYSTEM32\FNTCACHE.DLL
[5708BFDDB5E37B98E65D71E404138937][1 807456
78E20A9CD43AF80627C5C239358E8534E849BE87 ]C:\WINDOWS\SYSTEM32\FONTDRVHOST.EXE
[E390C844FFD78351AD78F17B3DA9A712][1 46592
0639C0C684B2F475D95BDACC0714F08F1BBEC384 ]C:\WINDOWS\SYSTEM32\FXSMON.DLL
[15BE7070232B1187345AEA3EA27811D2][1 636928
9D3D9CEE17D7571C2CCCE921D8D682307CC1C91A ]C:\WINDOWS\SYSTEM32\FXSSVC.EXE
[DB0D6123F4561125AF4CC1D24A36B9C1][1 1280000
FA26DF77BE9822E586D75FDC42EC62AD37B57D44 ]C:\WINDOWS\SYSTEM32\GPSVC.DLL
[D2133D061486A8AD29234A21F50CEB1E][1 93696
7E1A374939130B6A266612BC702EE7C1F8A26358 ]
C:\WINDOWS\SYSTEM32\GRAPHICSPERFSVC.DLL
[21A372ADF9F00D33E98FFFAFE9BEBC6B][1 34816
979F4077496C1E0DEBD8F81C104070AD7B7CDD46 ]C:\WINDOWS\SYSTEM32\HIDSERV.DLL
[94C01CBB754697F97452205222B0170E][1 61240
CEE581932D10FDAFE3CE84E8D58C432F894930B0 ]C:\WINDOWS\SYSTEM32\HVHOSTSVC.DLL
[DC88E5876A0DE83383B9715D1F8D07BA][1 299832
8640885F05D91CB53395EBA113D68BCAB93FC74A ]C:\WINDOWS\SYSTEM32\ICSVC.DLL
[92087EE68B06E0EC988EFC9DC44E25C9][1 310784
7282C6740F02B74708E3A5011AE6AE50628A5BBC ]C:\WINDOWS\SYSTEM32\ICSVCEXT.DLL
[1DBE918F1EDE43C8D49B6D9A7DEA25F3][1 328608
15FF2775B639AD5035C5300A2D0300FC9F509AA9 ]C:\WINDOWS\SYSTEM32\IGFXCUISERVICE.EXE
[BFE27E59D71DA8D4C5433AECE14C4CBF][1 540064
AAF3CD2492E820C1F59BCB043CDD0F6A198D6580 ]C:\WINDOWS\SYSTEM32\IGFXEM.EXE
[D6298429D647B5ECFB3D1A407E2C364C][1 256928
871C89EB1D63ED73898FF9CA0DD9D5AF44570047 ]C:\WINDOWS\SYSTEM32\IGFXHK.EXE
[97BB6425C86F46C2B21E0861421B6AE5][1 393632
63F993C5838FD915D8A51DBF9FDDDCC1ECF3EB75 ]C:\WINDOWS\SYSTEM32\IGFXTRAY.EXE
[A5483EDF19986EECE8383C4BBD554996][1 1058304
128E6C48016C490770E4AD7AFCF472C633C8B13D ]C:\WINDOWS\SYSTEM32\IKEEXT.DLL
[F06278B7B13D24DCC6928951D01574AA][1 36680
5403E40D1D43A8FBF10A7CE71F075470362716BB ]C:\WINDOWS\SYSTEM32\IMAADP32.ACM
[2E8DB0FC5D0A8D70ED1953A1BB8C6810][1 1671680
2858D91F32D90645F1977F00F619E72BEE2E6569 ]C:\WINDOWS\SYSTEM32\INSTALLSERVICE.DLL
[70124ABD0EA0C710F1F10706E2FDE73D][1 833024
810350C495AA74F198977B8C782785967A533416 ]C:\WINDOWS\SYSTEM32\IPHLPSVC.DLL
[DBDD7F9912067B099485E1B428CCF17F][1 629760
2B18831397712C83453769D1A877100A59807F6E ]C:\WINDOWS\SYSTEM32\IPNATHLP.DLL
[62199BF94E3F7B05CF9A1DB1458423FE][1 447488
CA69E9228F75D9753CABFD7A9919ED3632AF5423 ]C:\WINDOWS\SYSTEM32\IPSECSVC.DLL
[77C6BD7E7524D80F5BC6E1BF7E21FD14][1 64512
8C3F69D5EB8D8D5EE05CD94698719FB81A114A06 ]C:\WINDOWS\SYSTEM32\IPXLATCFG.DLL
[CA956BB7374CB74F5CADD56DF7039AC3][1 24576
08CA81FAE55306368B66D944285DE4385735E411 ]C:\WINDOWS\SYSTEM32\IRMON.DLL
[CF9405B4CE6698988D4AAD36BD770B8A][1 151552
799948F77E2E10625B4F1CE6874E699402DBF341 ]C:\WINDOWS\SYSTEM32\ISCSIEXE.DLL
[23A336AF5C49DED9599262297632E7B7][1 54272
EC2145F767A005B4DA98D0F6EBEF23905BF76730 ]C:\WINDOWS\SYSTEM32\IYUV_32.DLL
[814A312ED278D67A5AE033500065F49F][1 90112
1A8AFB345D900DDB60B7911E2BC3841B6E74A443 ]C:\WINDOWS\SYSTEM32\KEYISO.DLL
[5508D816271F24857897497F109E11C9][1 312320
416FB3595FECF2732C82858AD241D825C6895DEE ]
C:\WINDOWS\SYSTEM32\LANGUAGEOVERLAYSERVER.DLL
[CDEFD75D8A313646B7073C0BCDA5855C][1 47104
B213B0E90197787D349A8C9BBC57EFB88F080912 ]C:\WINDOWS\SYSTEM32\LFSVC.DLL
[112EFD0CCFA2994491F4D877D2DBA582][1 49664
541E0F8CC4C6256C67E17129BFA68386A943B603 ]
C:\WINDOWS\SYSTEM32\LICENSEMANAGERSVC.DLL
[2A5D30A714704742EE8ED1F9BA7EB28F][1 276992
3EAFEE3FF01391E3530B62A0AF682F6F9EDDE2BE ]C:\WINDOWS\SYSTEM32\LISTSVC.DLL
[DBFDAB4925BA2D54DC7C840EADDC64EC][1 266240
5B5A5760D0D9165B8F7F267A53A3832F8931D863 ]C:\WINDOWS\SYSTEM32\LLTDSVC.DLL
[2A798A380EE1187CBD27321C6FDA5AF0][1 27136
A1AFC7D9AE4807BF1CA565C0A052B827FB75FAAD ]C:\WINDOWS\SYSTEM32\LMHSVC.DLL
[1F7FFAAE18926EE31F8B9741EA7ED6A4][1 1197568
80EF86EBC050F44859F4D59619965B2984D74F19 ]C:\WINDOWS\SYSTEM32\LOCALSPL.DLL
[A0DD6042F7734F61D55D6A62D60FE498][1 11264
47D3CD96D2D9776F4CCE212859EAD98E2B4FC4DF ]C:\WINDOWS\SYSTEM32\LOCATOR.EXE
[C087C499C922144DA2198EC4B1BCB90C][1 1332736
B746EAF9F31A5F3A81D5836BB1D8CD27CE2C37E4 ]C:\WINDOWS\SYSTEM32\LPASVC.DLL
[568C5CBF9877F6B9E39D1E7CA0FF0A36][1 57880
0FB26350106C9BDD196D4E7D01EB30007663687C ]C:\WINDOWS\SYSTEM32\LSASS.EXE
[C9E9A7EC257A3C7F9C76502F78D38360][1 658432
47219E0A4BEC9B2D08B986DDBC243C97D28F515A ]C:\WINDOWS\SYSTEM32\LSM.DLL
[EAB4B99D5C81402572A410AEDB1590BE][1 55296
2C89AAFFFA42AD1A53FC95B44D813173E4CA7FA0 ]
C:\WINDOWS\SYSTEM32\MESSAGINGSERVICE.DLL
[B5704DC9DC9E87DB736DB103456C0E61][1 491520
C54CE329272EC2A462237A75108339124AB81EDB ]
C:\WINDOWS\SYSTEM32\MICROSOFT.BLUETOOTH.USERSERVICE.DLL
[E184B0FF681C5AB9438DEF1DF7661F79][1 914944
E122C66572C0379EDCDFC8739C2079F83164B33A ]
C:\WINDOWS\SYSTEM32\MICROSOFT.GRAPHICS.DISPLAY.DISPLAYENHANCEMENTSERVICE.DLL
[3FAE70080E7D900A469355C85ADACBDB][1 104960
DEA5960571532F73D886F5DD79B0F7EED6F10582 ]
C:\WINDOWS\SYSTEM32\MICROSOFTEDGECP.EXE
[2785CEE75163F3C8755BE16BDBA68155][1 57344
CE41DC5BBDDE4F779C2CCFFB119FEFAFDFCAF01D ]
C:\WINDOWS\SYSTEM32\MICROSOFTEDGESH.EXE
[B56AAB10E981BB84A6CB076CF1CE8A6A][1 25600
85D0E1CFB8F4131F14A5192CBBFEE13FAA69988F ]C:\WINDOWS\SYSTEM32\MIDIMAP.DLL
[10967D62F419CA0EB6EB9DA57D91286B][1 91648
5B2861A3DA50D05295E0183051F41464E153A44E ]C:\WINDOWS\SYSTEM32\MOSHOST.DLL
[C76CBDE7EBE13EA8D51FDA3EF3EB22C1][1 500736
819ABF47062F944F148C30E31955FA52C6DD74A2 ]C:\WINDOWS\SYSTEM32\MPRDIM.DLL
[46DD89D6C4878D2A3BEF0DAF2ABFC639][1 1050624
55CBC34618E8638ADD570495B81AD40AA2F8A7A3 ]C:\WINDOWS\SYSTEM32\MPSSVC.DLL
[F877A1DA90103B6DF26766D7EC02D5BC][1 29184
10EF19C6BAA628944CEA7FEB1B15231FDD4E14DD ]C:\WINDOWS\SYSTEM32\MSACM32.DRV
[18B340EC89A96A44D5C9444760F2BC63][1 34800
1B3D3CE38850DB60AD34100CD22FD7447F3A541E ]C:\WINDOWS\SYSTEM32\MSADP32.ACM
[7215CE218BDEAD41B708F098258CF972][1 148480
A002BC39095E7F9A3C3281505A42876F480FB95F ]C:\WINDOWS\SYSTEM32\MSDTC.EXE
[50AC18BB0C9B6097076001A96D1838B5][1 372224
EED396AF6712A815884BF41B1AD4221E35A4413B ]C:\WINDOWS\SYSTEM32\MSDTCKRM.DLL
[45E975E36664148A4B00E690E9B1A95C][1 25824
FB2D0B698959DBE4F3EF111FA0324D4329C302B7 ]C:\WINDOWS\SYSTEM32\MSG711.ACM
[1DE50F4E710EE3447C6EB6A37ABBC407][1 42904
328DAAA7E29473CBEFBDAA4F74C6814E33E7C312 ]C:\WINDOWS\SYSTEM32\MSGSM32.ACM
[785D2832863C28491A34BBF5314949EC][1 93696
5AFD3876668617B261E44C6A80E457093E631267 ]C:\WINDOWS\SYSTEM32\MSIEXEC.EXE
[D80832600E08F088ACA7788A43B1BE48][1 17920
AA7681F97F1EEF60A382E316F6C9685D749C8EF5 ]C:\WINDOWS\SYSTEM32\MSRLE32.DLL
[23261D36726D82F303B4AB867F3AF324][1 39424
F92AFF80CF8D59B6CDDD1EA24B2476C2D7E0DAA1 ]C:\WINDOWS\SYSTEM32\MSVIDC32.DLL
[F745EC391FDD60836D98BE15B8B8657E][1 27648
E4B0E2BBFAA92E83830ED0EBC631DB658DCD27E2 ]C:\WINDOWS\SYSTEM32\MSYUV.DLL
[7A0872F5645541A1CD1879199B0489E2][1 833024
3F7BFD5228D73460D29BDC2AFB2FC6CE16862BC3 ]C:\WINDOWS\SYSTEM32\NATURALAUTH.DLL
[20FAE1EACA6E5E9D1B940D7578CA4499][1 169984
2C168A255A4D6E12962F332B520A45E6A9D9EC85 ]C:\WINDOWS\SYSTEM32\NCASVC.DLL
[0E7C317DD9F8E46E0C90B88A3C536BA6][1 374784
B75167B869DBA962F41289D9AB9ED57EB1BA3C35 ]C:\WINDOWS\SYSTEM32\NCBSERVICE.DLL
[136B0632385280CA2ED8F9E5D17167AB][1 89600
A539360A51423E0F2596CF1BCEE952916B120509 ]C:\WINDOWS\SYSTEM32\NCDAUTOSETUP.DLL
[3BA9E57811BBB9C92880D7D5EF2E0685][1 864768
89FF9DFA0AAE7EF4DF796B0D9A1BF13A2691D214 ]C:\WINDOWS\SYSTEM32\NETLOGON.DLL
[70292FA0A21FE00503386478117CA067][1 262144
985C484C77196AC2613238E0036F3FF53C357767 ]C:\WINDOWS\SYSTEM32\NETMAN.DLL
[5B1562292E8C4A96703D6EB373A24E30][1 578048
B6D0A865C7CC469CAA16377E9AEEAF5137B48761 ]C:\WINDOWS\SYSTEM32\NETPROFMSVC.DLL
[C6D64FDB19A235BF9D0F0CA526BA9129][1 332800
062315997B9F9F853348C585889AA199D230B754 ]C:\WINDOWS\SYSTEM32\NETSETUPSVC.DLL
[56C91F8EA5C83A5AFE83AACF2586B875][1 623104
F564EA88C8457DD17172EDCB1754324F87427C76 ]C:\WINDOWS\SYSTEM32\NGCCTNRSVC.DLL
[7963A81757459412B08C6DD6A72D5FC1][1 782848
BCC602C25C0E6113B0462C63BD40256A01D22C84 ]C:\WINDOWS\SYSTEM32\NGCSVC.DLL
[ECF241DFFBAA6860EBBBFC1560D1F9D3][1 385536
B831A4EB985FA775F990E62E416CF13161EF1B9B ]C:\WINDOWS\SYSTEM32\NLASVC.DLL
[5FC3A698DE6BA51AB9709E1403F1A8DB][1 30720
CE4D9FAFCA5BB90B5C64B71E336A95C6F206371D ]C:\WINDOWS\SYSTEM32\NSISVC.DLL
[005B5F4FF4AAB4FC3CDE47762F1616EB][1 776192
9564D41170176E52F8DEB3758A3F6291C0420739 ]C:\WINDOWS\SYSTEM32\NTSHRUI.DLL
[9FFECD197D09FF33B00D5E5B78A48146][1 384512
74F3580EC1374F5A7367E157ACD76AA03EE7F7CB ]C:\WINDOWS\SYSTEM32\OPENSSH\SSH-
AGENT.EXE
[3B28A64AC649EA67E9946BDFE8EF513A][1 431616
4EBF8D7CE6C2EECC4F1B7160B9382FA4A0639BDA ]C:\WINDOWS\SYSTEM32\P2PSVC.DLL
[FB953BD1C9B60607B9CBEE70EAFC7ABA][1 553992
6990477D9BF4468569582CC46FCD17F3BD5A284B ]C:\WINDOWS\SYSTEM32\PCASVC.DLL
[51EC6CBC4A2B1C82A60A742D52F7B5EB][1 78848
7020FB55CC901FB4227D774AF19A389654AF5BAD ]
C:\WINDOWS\SYSTEM32\PERCEPTIONSIMULATION\PERCEPTIONSIMULATIONSERVICE.EXE
[4E55E08DE94A2690DED7F3035210D8B2][1 889344
DABD3EC00F54F07AAE2C710ECAAC0ACFCECB38D2 ]C:\WINDOWS\SYSTEM32\PHONESERVICE.DLL
[68594C1DBB617C2F9669016DE4B5BA78][1 188416
C8031CBF5AB446E790BE873003A33D4E0344B8F0 ]
C:\WINDOWS\SYSTEM32\PIMINDEXMAINTENANCE.DLL
[8ADDEE39782CBEB49B4C3A8E9AA2DF56][1 1473024
39D0E4393D855FA6C08EF5FCFFEB198AAB325CEF ]C:\WINDOWS\SYSTEM32\PLA.DLL
[142CF57538077D313B4B6226D2F7AFE3][1 27136
A77E048DA68FBF93728A4FBE0E8B00F4077C82D6 ]C:\WINDOWS\SYSTEM32\PNRPAUTO.DLL
[2B7F843E9FD1CFD5F1DAA523B2573698][1 356352
5D066972974AA7113F8C772E75A8EF005F70F920 ]C:\WINDOWS\SYSTEM32\PNRPSVC.DLL
[3BEDBD3B2544074AB63F646618853A94][1 177152
A38C3D85DD4F497F8706DF0168C3185116E58FD4 ]
C:\WINDOWS\SYSTEM32\PRINTWORKFLOWSERVICE.DLL
[4506179DB96B7FA4BF05748EAC9210D7][1 469504
918EF3A487F0ED8DD4926755D2B3BE35EBC015E4 ]C:\WINDOWS\SYSTEM32\PROFSVC.DLL
[23B5CF987C66B31053EDCF7B8ACBEEF8][1 468480
FAC733B6A91F8209464F314F4C97109BE125DC50 ]C:\WINDOWS\SYSTEM32\PROVSVC.DLL
[ED0FD37CDA820E66F4C212B7F5EE5105][1 241664
4AA02D2EF9203BDB9AABEEBE203B47CA8931D66F ]C:\WINDOWS\SYSTEM32\PSMSRV.DLL
[9507F059F53CA14F496C025AF536EE95][1 270336
16C8B9CD09823CB628615F16766178C5DE409590 ]C:\WINDOWS\SYSTEM32\PUSHTOINSTALL.DLL
[762E1319019E9E3D61127533FA3F3A07][1 1388032
62F0D9DB33AD656CE80E28C1218E2B59B857BD38 ]C:\WINDOWS\SYSTEM32\QMGR.DLL
[1CCA2B375CD44A6A0389B9288F60E96D][1 296960
B40D26C57CC2E95843D65D6D7936EF309923B0C8 ]C:\WINDOWS\SYSTEM32\QWAVE.DLL
[4E5BE8E17E8987912A9EBC84925A57F2][1 104448
0F326F209CD44AA27A3FAAC4A7C046E7EF19BD38 ]C:\WINDOWS\SYSTEM32\RASAUTO.DLL
[5EB093335CECA0FF6B8A6A10C43F8F54][1 924672
166CC02BD21D60E67B3631EC53102B20BE03942D ]C:\WINDOWS\SYSTEM32\RASMANS.DLL
[1DA817E5217CD0C05DE9EE377E059705][1 658944
11DFA94457F1D45E02A5A95467D2873F4AEFA1C8 ]C:\WINDOWS\SYSTEM32\RDXSERVICE.DLL
[7D58DC151856B3474B160B7ABD2B1C96][1 159232
222973F57DFB11738057483B1D1B32B2585A8106 ]C:\WINDOWS\SYSTEM32\REGSVC.DLL
[65C2ADC8A39C3F0D77FA611B4053EC4D][1 156160
095603764B750ED097ED0C2DF1E972DF6184C958 ]C:\WINDOWS\SYSTEM32\RMAPI.DLL
[F5645D54232AFA55E57927C9E0D24267][1 80384
0AA948EAF7B90380C889F70598F0051C4C0EA9BE ]C:\WINDOWS\SYSTEM32\RPCEPMAP.DLL
[0AED07F28B0B0820C9895656FE67FD1C][1 1211904
34F3DFF5CAE349ED8B8177974EFAEB9AF8BEE79C ]C:\WINDOWS\SYSTEM32\RPCSS.DLL
[2879BF3F6F6CE63477135F7C061B14F3][1 99688
EE8FDECE70D4D64D2C422E3F6861E066E85BD139 ]C:\WINDOWS\SYSTEM32\RUNTIMEBROKER.EXE
[92FB066DF4943FDDC571CD9EE434B390][1 262656
A9969A4C17080718DB8C35B4499984009554CAD1 ]C:\WINDOWS\SYSTEM32\SCARDSVR.DLL
[0713B90453D4D465F67DEF4A2FC8EFB5][1 200192
01C4E033FAFC5C6DA0CE484E6DF153A54EF28DF6 ]C:\WINDOWS\SYSTEM32\SCDEVICEENUM.DLL
[D6CE62F271345D40472A002E0AAE1C07][1 279040
45D54E8794966D5FD015D026D0E71FEAB2BE5F0C ]C:\WINDOWS\SYSTEM32\SCECLI.DLL
[020B510CCAE838763B7E3456C59B7BCA][1 901632
A2433719DE8DF86FA83A834761567D5E9C688780 ]C:\WINDOWS\SYSTEM32\SCHEDSVC.DLL
[5443C69569DB315B5015DD8E9004071B][1 148992
D3034B332678C42FCA107D16A2A6506E63E6EFBF ]C:\WINDOWS\SYSTEM32\SDRSVC.DLL
[CFE7F5E5D3FFBFE2689120630286C20C][1 1057792
FEB28D05C60F28684D93D1DF8023A92826BEA5FF ]C:\WINDOWS\SYSTEM32\SEARCHINDEXER.EXE
[4A7C5CDA6016AA0C705B185632DA1812][1 415744
13EABBD0E7679BFBF929015CC667B4BDF873D220 ]
C:\WINDOWS\SYSTEM32\SEARCHPROTOCOLHOST.EXE
[F3F8232DF651CFC4DBCF4C5BAB61CFCC][1 31232
CAB9DE2583E8DF24F38BDAAE20FF2432500BA492 ]C:\WINDOWS\SYSTEM32\SECLOGON.DLL
[6C294BA4F53127DF5060D3DD057A2DCA][1 863744
49818CE7A23E2C5A23F761614050F42FDD95B22E ]
C:\WINDOWS\SYSTEM32\SECURITYHEALTHSERVICE.EXE
[09F3F2298DDA6EBB57B12C530D35C52C][1 83968
D7FC50DC0A08C9EC089E428A03606EE4A2E8C759 ]
C:\WINDOWS\SYSTEM32\SECURITYHEALTHSYSTRAY.EXE
[DB10A49052B94A7D55B5A60E7F18CC36][1 1247232
9723067053A42830671BC9EED9EDB536F0C5FE75 ]C:\WINDOWS\SYSTEM32\SEMGRSVC.DLL
[EE711439FD0F1293B43F0FE195E5C073][1 73728
CB06F18BEAC752F8E2CBA2EC57C8925364754AE4 ]C:\WINDOWS\SYSTEM32\SENS.DLL
[E77A116240C022634504C54ACA876E62][1 1269248
F987BDB80EC55E443ED3EC01465D66A74C4FB69F ]
C:\WINDOWS\SYSTEM32\SENSORDATASERVICE.EXE
[0BB8E709234B5309556A4B6A7C26ABA6][1 433152
6BB97003DD6F22613EB49FEA8498930104BE7204 ]C:\WINDOWS\SYSTEM32\SENSORSERVICE.DLL
[03CC1E13F3FB31E17FE97392DA2AD74B][1 148992
CD5CE2A4C313BAE30610058B1B254181E9ED9ECA ]C:\WINDOWS\SYSTEM32\SENSRSVC.DLL
[9EE7998CF17E4059B9857B9C37361C2F][1 478208
CD1DFE036FC55E36479C057911023005FD93AA6C ]C:\WINDOWS\SYSTEM32\SESSENV.DLL
[2D443C08AAF6B917528EF0309742723E][1 995128
D8517916162AC588A9279C4B16BAA4BA656F34AB ]
C:\WINDOWS\SYSTEM32\SETTINGSYNCHOST.EXE
[1760AE8C5D731819A4BB1CF0448AC57C][1 254832
9CD08CCBF0785FEA97CEF96EA0F29D9353CBEA69 ]C:\WINDOWS\SYSTEM32\SGRMBROKER.EXE
[DF00D18142A1A3315A264521D8E3801A][1 642048
EA3D99C32F813FE2C6438AC1B977C6C60E530D68 ]
C:\WINDOWS\SYSTEM32\SHAREDREALITYSVC.DLL
[6CD79B201B564037C3B3D372F3733CB2][1 22111560
1BD7A53DBB792487D998F9B3469B24F18C5EFB1E ]C:\WINDOWS\SYSTEM32\SHELL32.DLL
[7BB985D3D68A423CE05E007B14E225AB][1 616448
3467181C3AA1CB9778523BF6B2B2A5565AD5DA90 ]C:\WINDOWS\SYSTEM32\SHSVCS.DLL
[8B6722980E0C5A06312E00BD0565B692][1 109056
F0467AAD55C4551009C19C3F64CB9CFF6EC1198F ]C:\WINDOWS\SYSTEM32\SIHOST.EXE
[33C24A31DF112266EE3580FAA5C6D088][1 2637312
97B640C2B124D3E11E5B060510202B35A778FAA6 ]C:\WINDOWS\SYSTEM32\SMARTSCREEN.EXE
[03FB4A01CD3AB73164FD9EF2D80171B5][1 23552
3FF1C0769CD4B4AD9C31F2D83F7FD4B9028D0AF2 ]C:\WINDOWS\SYSTEM32\SMPHOST.DLL
[827088445274D2F1660750C4E71A5DEF][1 584192
7B0D46F88105F9744D45A8E23D63044322638154 ]C:\WINDOWS\SYSTEM32\SMSROUTERSVC.DLL
[58983BFDDDB09E21AF8F3BA3EC45FC7D][1 15872
EC79F827947C95B9BA0C4E9584E45A06553CAB5C ]C:\WINDOWS\SYSTEM32\SNMPTRAP.EXE
[1609C84BD8592CFF07225C088859480B][1 982528
BA185D717003CB221BF47708A1F9C1FDCA016100 ]C:\WINDOWS\SYSTEM32\SPECTRUM.EXE
[66A0B1A55F21A275B7D5DECD295BD92A][1 3534848
D4EF7B55F7371C2B16EF110AAE42C37F93937EF8 ]
C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\X64\3\PRINTCONFIG.DLL
[B54A80B1A307CE44C843EDD080FEA03E][1 774144
48A666588FE797DD28366D4E0032F5919D3950B6 ]C:\WINDOWS\SYSTEM32\SPOOLSV.EXE
[06518ECE4BC47D1C015AB803068877E0][1 4588240
2B4F8D3B3D78BD149B82518C6F1D8DC8826FD6DB ]C:\WINDOWS\SYSTEM32\SPPSVC.EXE
[1C546EB2083C14C6EE79F10A16685F67][1 273920
54954E7AA9CEFA440E2B682D6E60430B7B10D4F2 ]C:\WINDOWS\SYSTEM32\SRVSVC.DLL
[06B6E9408BCE355CE4DA24FD7609F93C][1 231936
26DB643E3C18C5D86B7183306A6DEE2BA8511D43 ]C:\WINDOWS\SYSTEM32\SSDPSRV.DLL
[2CA5A7BECA0433EB10ECB4F2F03BB29F][1 206848
CA2818D1809960DAA31A46DA55B4E483130B4317 ]C:\WINDOWS\SYSTEM32\SSTPSVC.DLL
[F36E3D11E41D785E13225C63E9D46261][1 972288
F27D1E30175F2AAC7A6F568EAB4C8C972CF8DEE4 ]C:\WINDOWS\SYSTEM32\STORSVC.DLL
[8A0A29438052FAED8A2532DA50455756][1 51696
A1385CE20AD79F55DF235EFFD9780C31442AA234 ]C:\WINDOWS\SYSTEM32\SVCHOST.EXE
[304945C08A6B7C680321A01D3B21F39F][1 13824
E02A4F0C5B35866917CE7AC994876A415C3A7899 ]C:\WINDOWS\SYSTEM32\SVSVC.DLL
[0204819882A0D22DB34A1E493F622905][1 456704
4BDF739CBE04AB45A28E36A5617435A8737A83E6 ]C:\WINDOWS\SYSTEM32\SWPRV.DLL
[85CA90F0AF4B92B64EF3D10812F1C810][1 1064960
86D6561047100BCFB499AC18425DD9F24EAE7272 ]C:\WINDOWS\SYSTEM32\SYSMAIN.DLL
[853A94B84BEDFDEA8983F1D1D2DB491F][1 273920
5080EA0017F584CA4607CD0B6310AAD34249ACA6 ]
C:\WINDOWS\SYSTEM32\SYSTEMEVENTSBROKERSERVER.DLL
[0B028C71256D0D72215FE40330B03B6B][1 205072
7CD618F0174BBE7463EB93A3B446F88B5E4BA5B5 ]
C:\WINDOWS\SYSTEM32\SYSTEMSETTINGSBROKER.EXE
[626A1593186D839054720C0D116C682E][1 229888
F4A4D917A03A27EFA8AC38DDE0BE47BBFCBD3576 ]C:\WINDOWS\SYSTEM32\TABSVC.DLL
[9CEB8FC77A7FBEC5ED344EEC9227A10C][1 310784
622D75DDCA9814B00D8EBF22D20C34581DEF2AAF ]C:\WINDOWS\SYSTEM32\TAPISRV.DLL
[F225F37717C8D714B56CF21C7C1E9C34][1 86744
121E6C3CF7AF4CA30DB43440F71C1510EC3EA261 ]C:\WINDOWS\SYSTEM32\TASKHOSTW.EXE
[C0A22C631462B3122957FB34DC71AA85][1 223232
B86A567009EAF2DE6CB353C67DE0765259C24BF4 ]C:\WINDOWS\SYSTEM32\TCPMON.DLL
[F187376E07386C4D904D33144B6C4983][1 1018368
72746E8532AB92021B8C25203F7273834800F7D2 ]C:\WINDOWS\SYSTEM32\TERMSRV.DLL
[9ADC9B273EA9A6E0E43027D7AFB67589][1 246784
90A5CD157FECA11517286CCF5C71BB23239F7170 ]
C:\WINDOWS\SYSTEM32\TETHERINGSERVICE.DLL
[A90774D7D465E1085A95326FAD89B25C][1 67584
78BD48E135128570FC36179EC5E49F287AD4F8C1 ]C:\WINDOWS\SYSTEM32\THEMESERVICE.DLL
[33E60A1BD76A877683FCD7DC93A10635][1 310272
57A3F1BB5D26537F9735BDDDA9B6DE300F218C9F ]
C:\WINDOWS\SYSTEM32\TIERINGENGINESERVICE.EXE
[6B50241793122402D063A17FFEC04C01][1 174592
07B98158815E1878DF6D969D89A493F2923C8DBD ]
C:\WINDOWS\SYSTEM32\TIMEBROKERSERVER.DLL
[99B827BF34A6FF47394320341898519D][1 1462272
EBFB925ED8F73126709BA81CEE3070ECECF91A82 ]C:\WINDOWS\SYSTEM32\TOKENBROKER.DLL
[BCA97819779D7876B6F98C29844CF505][1 113152
241E5551CED660DCF2D35E2364067AA79A867C8C ]C:\WINDOWS\SYSTEM32\TRKWKS.DLL
[869902A984EA4C5C6979DE16C1E6243F][1 16896
E8F1CD428E638054C191CAA8B7E80095BD0AF607 ]C:\WINDOWS\SYSTEM32\TSBYUV.DLL
[0D7B0A007BCC65CF6CC20E25A43D151A][1 98304
8204D94B109A6AED0ACDC58BA4992F9DDF873A5C ]C:\WINDOWS\SYSTEM32\TZAUTOUPDATE.DLL
[03BA8BB294CE2B52D9E8F64E94B4B402][1 120832
1E81129C4035A573482ABFA570DE33A1D76E7A87 ]C:\WINDOWS\SYSTEM32\UMPNPMGR.DLL
[C1ADDE298CF5146E367CDE9C3FB0E940][1 157184
B0F10B75C589E318702CBA8BEE638CE3AE68486F ]C:\WINDOWS\SYSTEM32\UMPO.DLL
[86F5651C8448134FE32C9B34A9273EBD][1 395264
A6B192536E004CBF84C1428F282AD1BD924CD1B1 ]C:\WINDOWS\SYSTEM32\UMRDP.DLL
[8B4DC02D01400255E6CFB53C51689557][1 1160704
D4296F966CCC02C7CB0441A965A8210682D82C09 ]C:\WINDOWS\SYSTEM32\UNISTORE.DLL
[9CF8E80F71544316E5F90F2B87F2350C][1 256000
5D5BF791D38DF29D52F4585A6853FC8242CDB73C ]C:\WINDOWS\SYSTEM32\UNREGMP2.EXE
[BD627E48043957D70AA7100EC8DF0974][1 454144
665DE592137DFBEE6692DFCE3F1493A9518684FA ]C:\WINDOWS\SYSTEM32\UPNPHOST.DLL
[2517371801167619C066D910B98B7EB8][1 336896
8D8F324200E8F5C5708FB55D33D75C7BAFDEF49F ]C:\WINDOWS\SYSTEM32\USBMON.DLL
[C05A20A037C6675E854FFE8282BE9B20][1 1540608
6729C43B0D608AE59663EFB8CC18523B8FEF4564 ]
C:\WINDOWS\SYSTEM32\USERDATASERVICE.DLL
[BF8825D08BC235F0609CA8BBEF4E179C][1 33792
470C3E60F9B2B6D83F95C7916A5361E34DEC3471 ]C:\WINDOWS\SYSTEM32\USERINIT.EXE
[9E78FF24C05874B3EA4C8029879C28AC][1 1255936
859FD9E21D607A9C0CED0C5E58EA96D9F6387815 ]C:\WINDOWS\SYSTEM32\USERMGR.DLL
[AF2979208ABA46C5DAAF254DD0919EC7][1 883712
A2BEC87F3BEDD5911113366E0190C3566E742D0E ]C:\WINDOWS\SYSTEM32\USOCORE.DLL
[F7B1BC5C7799E1247DC7CB5FD2C0F921][1 418368
78048424203F941638675BAB74F71CB80E0586A6 ]C:\WINDOWS\SYSTEM32\VAC.DLL
[7D824D8A2C82B4D3EA69D41D74C1394D][1 359424
1ABEC74A470F486C9E3658FB05FC8B037C06126E ]C:\WINDOWS\SYSTEM32\VAULTSVC.DLL
[E845A556FC6574216078A02FE53189C1][1 640000
EEFD84BCBB943CDD21B292FA5F5A811E3C4CC711 ]C:\WINDOWS\SYSTEM32\VDS.EXE
[70757EE40A3DFC19BFEE29E67100C708][1 1516544
296E78F6E115CC747FEA793ECAC2EAF4F3D42651 ]C:\WINDOWS\SYSTEM32\VSSVC.EXE
[F4BA7F7899745E6D0F6C7CD0792F03E9][1 647168
6E2A34302CE18CADC2C09490635D646B3C3D8E9A ]C:\WINDOWS\SYSTEM32\W32TIME.DLL
[3C662445E3B925A7519805E74317DDB9][1 437760
BD24AC78BF2A46FABEFC74226DB24515104A9F6E ]C:\WINDOWS\SYSTEM32\WAASMEDICSVC.DLL
[B7BB14302C5BE67EA6E79E5B48284A12][1 431104
0FFCFE78E3F00BDD0DC4339D6973EC241F68FE18 ]C:\WINDOWS\SYSTEM32\WALLETSERVICE.DLL
[12ABB40F3E15A6826DFBBDC0D9967A8C][1 969216
B29C90D1BA5F4FE33B6A2C633469D668DC6356A4 ]C:\WINDOWS\SYSTEM32\WBEM\FASTPROX.DLL
[8B0E699F01BDD3B9AD741D1BD7343248][1 49664
BA0B729D2E78D533DFC771238F1BF8188D2DB2BC ]C:\WINDOWS\SYSTEM32\WBEM\UNSECAPP.EXE
[D0A901EE141FE5AD78A12AE6A6378990][1 200704
CDB1CAF9EB1EDF441375F320450C0CA7D637D63F ]C:\WINDOWS\SYSTEM32\WBEM\WMIAPSRV.EXE
[06C66FF5CCDC2D22344A3EB761A4D38A][1 489472
67C25C8F28B5FA7F5BAA85BF1D2726AED48E9CF0 ]C:\WINDOWS\SYSTEM32\WBEM\WMIPRVSE.EXE
[ABA4B3C8252BE9D3A6F1E9A1D9756213][1 228352
7447C5B4D697E193094DB134589DD707EF032ABB ]C:\WINDOWS\SYSTEM32\WBEM\WMISVC.DLL
[CD9EA97E282A5229E66202312DC021BB][1 1537536
9E859932DE99CF2D589EFF77DA6BD892D5444380 ]C:\WINDOWS\SYSTEM32\WBENGINE.EXE
[3BEA0B1841B52E438F9CE0F6628E88DC][1 955392
952AF9FA0F9B6D7CE805DBB6DD054E22A716C99D ]C:\WINDOWS\SYSTEM32\WBIOSRVC.DLL
[BF3A1962EDDB3C139133D0B0928B3761][1 1008128
5A29D29B8A472A6D2E4783D3B5A8368A0CB3ECD1 ]C:\WINDOWS\SYSTEM32\WCMSVC.DLL
[E9D4CB72F791B11FB4599006B7A01A58][1 475136
4D8EC65F09219FF48CD2BD1EB5602C9E5AA5C8EC ]C:\WINDOWS\SYSTEM32\WCNCSVC.DLL
[2DF1213455A71E2C453575C425EEE079][1 102400
3C539419B8D4701F86A062F08F574F61418B2CF5 ]C:\WINDOWS\SYSTEM32\WDI.DLL
[BA8C8398B3DA1BCC1737FBD9CA7526F0][1 254976
5E232E15D3AE8AFF172F3D492E67C2C8A3A3772D ]C:\WINDOWS\SYSTEM32\WDMAUD.DRV
[0714DD5FEC336CBFC3E8C0B2C1A25A95][1 219136
C22B9A9119BBD60E355DB10627401D604D25B957 ]C:\WINDOWS\SYSTEM32\WEBCLNT.DLL
[92A0CB8C13014D9589855A1B1FAE789E][1 197632
82ED4CD5F28ABD58CB1C59841709A2254113E780 ]C:\WINDOWS\SYSTEM32\WECSVC.DLL
[C40BC5164317312AEFC3A37376B696E6][1 27648
A1B3D16DDFB74699B2F0B875121BB9684F80F18C ]C:\WINDOWS\SYSTEM32\WEPHOSTSVC.DLL
[5CE5CBC5A85BB319F278737BB20054AE][1 121856
7347331C3E083221477F5E571ACFB3775A65E0DE ]C:\WINDOWS\SYSTEM32\WERCPLSUPPORT.DLL
[77B25A61B3AEC06EA58035C9B9CAD9FE][1 216064
7795E4E2A7F419F7A2A735610BF16BD65105BB3D ]C:\WINDOWS\SYSTEM32\WERSVC.DLL
[A9C18F7D907645183D6194E1A85AB7DE][1 1893376
BF5F08A1977BC7425E60BE692CFF80458A02C165 ]C:\WINDOWS\SYSTEM32\WEVTSVC.DLL
[76E43A1AABB4CEB6DB83224F19CC4681][1 715776
4A5C2BD4076E84E9BB3CC680323440E5C1BDD706 ]C:\WINDOWS\SYSTEM32\WFDSCONMGRSVC.DLL
[E2C1DB0AB6F9C3C592BC3540687389C4][1 83456
05936386CF2C4DF74DD2F5B1260609AD4E428AD8 ]C:\WINDOWS\SYSTEM32\WIARPC.DLL
[697B0D4078F0F70AC4829B4EBA0538B1][1 651776
56A1BAB84D6D9470A8AEC1097486A2D17EB6CEE3 ]C:\WINDOWS\SYSTEM32\WIASERVC.DLL
[4035C0ECBC2FA54845DBA9D2D732978D][1 456704
97B8BD778ED335FA62811C6E60661813C949D1D0 ]
C:\WINDOWS\SYSTEM32\WINDOWS.DEVICES.PICKER.DLL
[29C5305644CA39922991028058841D78][1 949248
8B43E1CD54FD02C11EBEBEF41A3B7741A9E4EE2A ]
C:\WINDOWS\SYSTEM32\WINDOWS.INTERNAL.MANAGEMENT.DLL
[09C7796D31DCFF582064829CB59E35BF][1 370176
4FB301708962BB31D8E0B8F819418328CB81465F ]
C:\WINDOWS\SYSTEM32\WINDOWS.MANAGEMENT.SERVICE.DLL
[82BE61D6660F4259606371E73027AAEA][1 223744
F0727548B4695934681DFA2C75D1D13CD7F306C1 ]
C:\WINDOWS\SYSTEM32\WINDOWS.SHAREDPC.ACCOUNTMANAGER.DLL
[D41B7D3152E4ED1A32FA8939A828BAF7][1 4991592
6B7E2802C3136C3EE48AA13E676FC11CEF3A8E26 ]
C:\WINDOWS\SYSTEM32\WINDOWS.STATEREPOSITORY.DLL
[DE4E84C2E16362423B993A5E4FBB6B7B][1 7679504
83A31B936DA74434BB8E148E5A09E5ABBFBE5B58 ]
C:\WINDOWS\SYSTEM32\WINDOWS.STORAGE.DLL
[6A775E36973111923169368CC7299E30][1 32768
B2139BEF87B845738C2194849CFEF783D7A9F89C ]
C:\WINDOWS\SYSTEM32\WINDOWS.WARP.JITSERVICE.DLL
[61A61ED80D52421DAE4F6E32137508B4][1 982880
93A6458F45E694417827796BBFFFBBA1ED8349C4 ]C:\WINDOWS\SYSTEM32\WINHTTP.DLL
[92419F3B74C6C3D7304B7665DA984552][1 779776
7290A3DEADF86D38F03933CBD09DA6841B6B2DCC ]C:\WINDOWS\SYSTEM32\WINLOGON.EXE
[84626BB521ACD1B5DAA81EDAC1D67F06][1 290816
7BCBFDB935DB626A6F6F14F64233C7B9E3612682 ]C:\WINDOWS\SYSTEM32\WKSSVC.DLL
[00CBFE7A6862AF10624F4C9F6B854718][1 103424
8E710F8805425A4E7946D6BE5599B84D4D15C143 ]C:\WINDOWS\SYSTEM32\WLANEXT.EXE
[315A9AA7E6FA02B3AED5814E0D2BF263][1 2630144
62D50B443E95AA3075A54328525EFEC29A98E6D9 ]C:\WINDOWS\SYSTEM32\WLANSVC.DLL
[D490407C13EDD902F95D29CF82478E73][1 2185728
78FF1C86D057AC8A7A56DB00BD23E28B910BA52A ]C:\WINDOWS\SYSTEM32\WLIDSVC.DLL
[3EFA1DCA6A3731ECC84F024B0DF17CEB][1 2176824
77BAA3A98AA1E77CE51054961051FCF480531DDB ]C:\WINDOWS\SYSTEM32\WORKFOLDERSSVC.DLL
[56A1AC9C2DB9B440743C7F13DCEDD4F1][1 1422336
11243EFEECB791B7747D0E5EBD44E474EC914DE8 ]
C:\WINDOWS\SYSTEM32\WPCDESKTOPMONSVC.DLL
[B4F8ED117D5120009972A470AF4FA323][1 83968
BD088597C709457F3B6060F6CE818E9461DF5429 ]C:\WINDOWS\SYSTEM32\WPDBUSENUM.DLL
[48FB3FFACCD2194CDD6B04CE84361C29][1 97280
29ED72343EED504FEF96C33993C1B8BF7C8F4BFC ]C:\WINDOWS\SYSTEM32\WPNUSERSERVICE.DLL
[ADAD15298AD0D593FAF61BB89D538D73][1 314064
6EA825819A8210580040AE71FE2509692294CE8D ]C:\WINDOWS\SYSTEM32\WSCSVC.DLL
[1CFF7C3900CDF1C9762558548BFA1C2A][1 2618368
6BDC21A9E16D28E073D72083617E9B28718EE647 ]C:\WINDOWS\SYSTEM32\WSMSVC.DLL
[60290713ED848D607A7F3CE5DD2F02A0][1 2988032
4B70FFB33A419CA538E9BA437C1371E9B275CF01 ]C:\WINDOWS\SYSTEM32\WUAUENG.DLL
[902D7BA5FADD42DB2DC6C7DD5F9C0CF7][1 256512
5D1194767DE49B6882C6083D52B2CA966E05CB75 ]C:\WINDOWS\SYSTEM32\WUDFHOST.EXE
[32308032F6D475E9AE0564F8713A4DFE][1 1749504
736BCE1962A1B5FDA1ECD92C55252D6EA3EC9410 ]C:\WINDOWS\SYSTEM32\WWANSVC.DLL
[5F69A7DE728668CD6A80FCB0EB3B7EB2][1 1049600
61DE38DDBFF921DD33827A7E06F80FA5E83486D2 ]C:\WINDOWS\SYSTEM32\XBLAUTHMANAGER.DLL
[9AD74ADD767D1FF755F52E4F5778C641][1 1265152
68BCC4005BC441E4D0053A5B8B548AA80919A4CA ]C:\WINDOWS\SYSTEM32\XBLGAMESAVE.DLL
[9266191829E944E4E7F474C9A8FC3947][1 72704
22FD4C7839D9E612531AEC9A3F15737568F5769F ]C:\WINDOWS\SYSTEM32\XBOXGIPSVC.DLL
[42DCAA6173FC1447A298637C16C973FC][1 1228800
6C3EFDCBD6DC1179553AAC1FB3B72738083F4573 ]C:\WINDOWS\SYSTEM32\XBOXNETAPISVC.DLL
[493C50B1A37B45B2A6600D95B4884505][1 956416
09BA46157AA134F0A9366E72301DC2A11B723800 ]
C:\WINDOWS\SYSTEMAPPS\INPUTAPP_CW5N1H2TXYEWY\WINDOWSINTERNAL.COMPOSABLESHELL.EXPERI
ENCES.TEXTINPUT.INPUTAPP.EXE
[D0B59C5A711EB8E9F818023D81B226CC][1 15999304
4A515DC0ECA59E07FF95B156403D61256D49F778 ]
C:\WINDOWS\SYSTEMAPPS\MICROSOFT.MICROSOFTEDGE_8WEKYB3D8BBWE\MICROSOFTEDGE.EXE
[0E54CEC76C044C834C0572DCD5941E2E][1 286208
18350E0BA7A9BF84963B51A2776DCF51CD4CECE0 ]
C:\WINDOWS\SYSTEMAPPS\MICROSOFT.WINDOWS.CORTANA_CW5N1H2TXYEWY\REMINDERSSERVER.EXE
[6D66AFEF886392CE79C1A61F3AF835A1][1 12079928
111E0D13C0F95AA71B84DAC0ADB38755FB520E16 ]
C:\WINDOWS\SYSTEMAPPS\MICROSOFT.WINDOWS.CORTANA_CW5N1H2TXYEWY\SEARCHUI.EXE
[78AC970D7765FD11580FF67DF518197B][1 2271544
AFC9C799E05B8C6309B58EA96A84F3140E47F5CC ]
C:\WINDOWS\SYSTEMAPPS\SHELLEXPERIENCEHOST_CW5N1H2TXYEWY\SHELLEXPERIENCEHOST.EXE
[8A124E89D984F07E66FF8EBDDA3807CD][1 698880
3A845165385D0FFBD17875607A8998A1BAE12BA2 ]C:\WINDOWS\SYSWOW64\D3D8.DLL
[052495BF199C5369F9C86BF9B26F2A3A][1 580024
E2B1D3559C3B22B3FDFAB8E8B0FE9ED09823EB2B ]C:\Windows\SYSWOW64\DNSAPI.DLL
[7D4652B6413FE0EB85D2D7575F8E3C71][1 84992
9813D1653288A3DAE7E020E5E7BC3F1ED3A9C228 ]C:\WINDOWS\SYSWOW64\ICCVID.DLL
[7F687723C96A7CA799C53FF09C157B7B][1 12150784
A6B91E5AFC63C4E1FE489FA07DBDE8616C5EAA2E ]C:\WINDOWS\SYSWOW64\IEFRAME.DLL
[B8BCBCFCFBFF8E57CBEC77F3A9E4296E][1 889344
91212B31D6D479FB506D3CEB7EEAFA79E9C042B5 ]C:\WINDOWS\SYSWOW64\INETCOMM.DLL
[0781DE74790BDBB9A7B9EF6CAA62B4E0][1 290208
9D62A97974094D44F2BE63DBC4E7011ECF659305 ]C:\WINDOWS\SYSWOW64\INTELCPHECISVC.EXE
[F2C1700742455B474C0CA745A357CE94][1 145920
BDA7F0564FD39D3AE135ECACFA7DA31BC2CAF56B ]C:\WINDOWS\SYSWOW64\ITSS.DLL
[7104CF2E111A65AC4F5C16690C63C481][1 69120
B253501E632E919FAC83D658142654010A5D78EC ]C:\WINDOWS\SYSWOW64\L3CODECA.ACM
[208B18B92C068377F5EB21CD72FBC993][1 315904
192852493E0DE39C1FED9A453BFACD30555AC712 ]C:\WINDOWS\SYSWOW64\MSCOREE.DLL
[AA627C814E39C95897C31511B1B709E7][1 19023872
660F266A7D47017A16C4F20B3186100297B54555 ]C:\WINDOWS\SYSWOW64\MSHTML.DLL
[A100B0BD33B76D71F663EA93931DF062][1 2225152
F4ADE33EFB1C126017A452EE773E1AFD80DAD1D5 ]C:\WINDOWS\SYSWOW64\MSVIDCTL.DLL
[80F2A1191FF909612F6B2149BC34D25D][1 324616
AD6311725EE90621EAB343394DAB35C322C92784 ]C:\WINDOWS\SYSWOW64\MSWSOCK.DLL
[C222443BA793F4C2DD92AF5B20EF0820][1 54784
9E466EE22A642334A4C96805F4E68B08D1503339 ]C:\WINDOWS\SYSWOW64\NAPINSP.DLL
[A5E88A4F900044CAA4E5F3A5F283E703][1 70144
1BD366B6A2D9CBDAAA773914AAC68DA8C68FA45C ]C:\WINDOWS\SYSWOW64\NLAAPI.DLL
[E0C9BFCDEC97D66F2ADAF356967508F9][1 88064
35D38380A9E7D462B39DA636D36B71FF43EAD3C2 ]C:\WINDOWS\SYSWOW64\OLEPRO32.DLL
[CC037C3D8F265E65F7200D9665D653FD][1 21504
08D3D23C735DF2EA0546FCBCC2FEFEBB7D340216 ]C:\WINDOWS\SYSWOW64\PERFHOST.EXE
[D43032BCCDA09360AA5BAAFF3039AEA6][1 70656
2A91160CCD2A1E4CD080E14F3DC72590973AC73E ]C:\WINDOWS\SYSWOW64\PNRPNSP.DLL
[CAC54AA1F714C40D0FB99E790A2DD5B9][1 49152
B22689E374C79856E8B2627E62C933884E9CEED6 ]C:\WINDOWS\SYSWOW64\TBAUTH.DLL
[9E012753342DD7F95B7A07104E49C084][1 1762816
EEDEF8E39F8B3FE34725B8E1937320FA7DBD2090 ]C:\WINDOWS\SYSWOW64\URLMON.DLL
[5D8056CE269CDC09733F228883A8279D][1 23552
12A3B028335F3B960EB2058859932AFBEBA02116 ]C:\WINDOWS\SYSWOW64\WINRNR.DLL
[3F361BE7140B83974AB4FA9B7E09D0DC][1 50688
265AD8FABFD8A578533F1E3FDC3519658AB91403 ]C:\WINDOWS\SYSWOW64\WSHBTH.DLL
===
[MBR]
[MD5=004BC502E8A0AB7DDDB5C2C67E1CDFEE]
M8CO0LwAfI7Ajti+AHy/AAa5AAL886RQaBwGy/u5BAC9vgeAfgAAfAsPhQ4Bg8UQ4vHNGIhW
AFXGRhEFxkYQALRBu6pVzRNdcg+B+1WqdQn3wQEAdAP+RhBmYIB+EAB0JmZoAAAAAGb/dgho
AABoAHxoAQBoEAC0QopWAIv0zROfg8QQnusUuAECuwB8ilYAinYBik4Cim4DzRNmYXMc/k4R
dQyAfgCAD4SKALKA64RVMuSKVgDNE13rnoE+/n1VqnVu/3YA6I0AdRf6sNHmZOiDALDf5mDo
fACw/+Zk6HUA+7gAu80aZiPAdTtmgftUQ1BBdTKB+QIBcixmaAe7AABmaAACAABmaAgAAABm
U2ZTZlVmaAAAAABmaAB8AABmYWgAAAfNGloy9uoAfAAAzRigtwfrCKC2B+sDoLUHMuQFAAeL
8Kw8AHQJuwcAtA7NEOvy9Ov9K8nkZOsAJALg+CQCw0ludmFsaWQgcGFydGl0aW9uIHRhYmxl
AEVycm9yIGxvYWRpbmcgb3BlcmF0aW5nIHN5c3RlbQBNaXNzaW5nIG9wZXJhdGluZyBzeXN0
ZW0AAABje5o=
===
[PT]
A 0x7 NTFS, 2048, 204800
0x7 NTFS, 206848, 163840000
0x7 NTFS, 164046848, 269201408
0xf Extended, 433248256, 543522816
===
[VBR]
61KQTlRGUyAgICAAAggAAAAAAAAA+AAAPwD/AAAIAAAAAAAAgACAAP8fAwAAAAAAVSEAAAAA
AAACAAAAAAAAAPYAAAABAAAAlnCQVKKQVGwAAAAA+jPAjtC8AHz7aMAHHx5oZgDLiBYOAGaB
PgMATlRGU3UVtEG7qlXNE3IMgftVqnUG98EBAHUD6d0AHoPsGGgaALRIihYOAIv0Fh/NE5+D
xBieWB9y4TsGCwB126MPAMEuDwAEHloz27kAICvIZv8GEQADFg8AjsL/BhYA6EsAK8h377gA
u80aZiPAdS1mgftUQ1BBdSSB+QIBch4WaAe7FmhSERZoCQBmU2ZTZlUWFhZouAFmYQ4HzRoz
wL8KE7n2DPzzqun+AZCQZmAeBmahEQBmAwYcAB5maAAAAABmUAZTaAEAaBAAtEKKFg4AFh+L
9M0TZllbWmZZZlkfD4IWAGb/BhEAAxYPAI7C/w4WAHW8Bx9mYcOh9gHoCQCh+gHoAwD06/2L
8Kw8AHQJtA67BwDNEOvyww0KQSBkaXNrIHJlYWQgZXJyb3Igb2NjdXJyZWQADQpCT09UTUdS
IGlzIGNvbXByZXNzZWQADQpQcmVzcyBDdHJsK0FsdCtEZWwgdG8gcmVzdGFydA0KAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAIoBpwG/AQAAVaoHAEIATwBPAFQATQBHAFIABAAkAEkAMwAwAADU
AAAAJAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAOnAAJAFAE4AVABMAEQAUgAHAEIATwBPAFQAVABHAFQABwBCAE8ATwBUAE4AWABUAAAA
AAAAAAAAAAAAAAAAAAAAAAAADQpBbiBvcGVyYXRpbmcgc3lzdGVtIHdhc24ndCBmb3VuZC4g
VHJ5IGRpc2Nvbm5lY3RpbmcgYW55IGRyaXZlcyB0aGF0IGRvbid0DQpjb250YWluIGFuIG9w
ZXJhdGluZyBzeXN0ZW0uAAAAAAAAAAAAAAAAAAAAAAAAAACaAmYPtwYLAGYPth4NAGb342aj
UgJmiw5AAID5AA+PDgD22Wa4AQAAAGbT4OsIkGahUgJm9+Fmo4YCZg+3HgsAZjPSZvfzZqNW
AuiiBGaLDk4CZokOJgJmAw6GAmaJDioCZgMOhgJmiQ4uAmYDDoYCZokOPgJmAw6GAmaJDkYC
ZriQAAAAZosOJgLokAlmC8APhL/9ZqMyAma4oAAAAGaLDioC6HcJZqM2Ama4sAAAAGaLDi4C
6GUJZqM6AmahMgJmC8APhIz9Z4B4CAAPhYP9Z2aNUBBnA0IEZ2YPtkgMZokOkgJnZotICGaJ
Do4CZqGOAmYPtw4LAGYz0mb38WajlgJmoUYCZgMGjgJmo0oCZoM+NgIAD4QdAGaDPjoCAA+E
MP1mix46Ah4HZos+SgJmoS4C6O0B6CwNZgvAD4QDAOhCDmYPtw4AAma4AgIAAOgiCGYLwA+F
FgBmD7cOWgJmuFwCAADoDAhmC8APhHgOZ2aLAB4HZos+PgLoPwZmoT4CZrsgAAAAZrkAAAAA
ZroAAAAA6OQAZoXAD4UjAGahPgJmu4AAAABmuQAAAABmugAAAADoxABmC8APhUQA6ScOZjPS
ZrmAAAAAZqE+AujKCGYLwA+EEA4eB2aLPj4C6NsFZqE+Ama7gAAAAGa5AAAAAGa6AAAAAOiA
AGYLwA+E5g1nZg+3WAxmgeP/AAAAD4XbDWaL2GgAIAdmK/9moT4C6AABaAAgB2Yr/2ahPgLo
rAqKFg4AuOgDjsCNNgsAK8BoACBQywYeZmBmi9pmD7YODQBm9+FmoxEAZovDZvfhoxYAi9+D
4w+MwGbB7wQDx1AH6JL7ZmGQHwfDZwNAFGdmgzj/D4RMAGdmORgPhTMAZgvJD4UKAGeAeAkA
D4UjAMNnOkgJD4UaAGaL8GcDcArolwZmUR4HZov686dmWQ+FAQDDZ2aDeAQAD4QHAGdmA0AE
66tmK8DDZovz6GwGZ2YDAGf3QAwCAA+FNABnZo1QEGc6SkAPhRgAZ2aNckLoSQZmUR4HZov7
86dmWQ+FAQDDZ4N4CAAPhAYAZwNACOvCZjPAw2eAewgAD4UcAAYeZmBnZo1TEGdmiwpmi/Nn
A3IE86RmYZAfB8NmUGdmjVMQZoXAD4UKAGdmi0oIZkHrEZBnZotCGGYz0mb3NlICZovIZivA
Zl7oAQDDBh5mYGeAewgBD4QDAOnK+maD+QAPhQYAZmGQHwfDZlNmUGZRZlZmVwbokQRmi9EH
Zl9mXmZZZoXAD4Q0AGY7yg+NAwBmi9Hogv5mK8pmi9pmi8JmD7YWDQBm9+JmD7cWCwBm9+Jm
A/hmWGYDw2Zb659mhfYPhGL6ZlFmVwZnZg+2QwlmhcAPhCAAZtHgZivgZov8ZlRmVmdmD7dz
CmYD82aLyPOkZl7rA5BmUGZQZ2aLA2ZQZ2aLQxhmUGdmi1YgZoXSD4QLAGaL/h4HZovC6HED
ZovGZlpmWWZCZlFmVug/BmaFwA+E8flmXmZZZov+HgfoTgNmi8Zmi9lmWWZaZlFmVmbR6ej4
/WaFwA+EyvlmXmZZZgPhB2ZfZllmi9BmWGZbZova6fX+Bh5mYCZnZg+3XwQmZ2YPt08GZgvJ
D4SY+WYD32aDwwJmgcf+AQAAZklmC8kPhBcAJmeLAyZniQdmg8MCZoHHAAIAAGZJ6+JmYZAf
B8MGHmZgZrgBAAAAZqMiAmahHgJmAwaGAmajigJmAwaGAmajTgJmoTAAZg+2Hg0AZvfjZose
TgJmiQdmoxEAg8MEZqFWAmaJB6MWAIPDBGaJHk4CZoseHgIeB+i7+GaL++hR/2ahHgJmuyAA
AABmuQAAAABmugAAAADoEP1mC8APhBkBZovYHgdmiz4aAmYzwOii/WaLHhoCZoE/gAAAAA+E
6wADXwTr8GZTZotHEGb3JlYCZlBmM9JmD7YeDQBm9/NmUujcAGYLwA+EmPhmiw5WAmYPth4N
AGb342ZaZgPCZoseTgJmiQeDwwRmD7YGDQBmK8JmO8EPhgMAZovBZokHZivIZloPhHUAZgPC
ZlBmM9JmD7YeDQBm9/NmUeiCAGZZZgvAD4Q8+GYPth4NAGb342aLHk4CZosXg8MEZgMXZjvQ
D4UVAGYPtgYNAGY7wQ+GAwBmi8FmAQfrpYPDBGaJHk4CZokHg8MEZg+2Bg0AZjvBD4YDAGaL
wWaJB+uCg8MEZv8GIgJmiR5OAmZbA18EZoE/gAAAAA+EDP9mYZAfB8Nmi9Bmiw4iAmaLNooC
ZgM2hgJmUmZRZlJmix6KAmaLPlYCZosEZqMRAIPGBGaLBKMWAIPGBB4H6Dz3Ziv4D4QIAPcm
CwAD2OvZZos+igIeB+i//WahigJmu4AAAABmuQAAAABmi9HogftmC8APhFP3ZovYZlhmVugs
AWZeZgvAD4QFAGZbZlvDZllmWuKEZjPAwwYeZmBmUGZRZjPSZg+2Hg0AZvfzZlJmV+hT/2Zf
ZgvAD4QN92YPth4NAGb342ZaZgPCZqMRAGZZZg+2Hg0AZjvLD44TAIkeFgBmK8tmWGYDw2ZQ
ZlHrFJBmWGYDwWZQiQ4WAGa5AAAAAGZRBmZXi9+D4w+MwGbB7wQDx1AH6GT2Zl8HZgM+UgJm
WWZYZoP5AA+PcP9mYZAfB8MGHmZgZvcmVgJmiw5WAuhV/+jS/GZhkB8HwwYeZmBm9yaSAmaL
HjYCZosOkgJmizYqAh4HZos+RgLogfvop/xmYZAfB8NmUGZTZlFmix5KAmaLyGbB6ANmg+EH
ZgPYZrgBAAAAZtPgZ4QDD4QEAPjrApD5ZllmW2ZYw2eAewgBD4QEAGYrwMNnZo1zEGdmi1YI
ZjvCD4cLAGdmixZmO8IPgwQAZivAw2cDXhBmK/ZngDsAD4Q+AOiBAGYD8eg5AGYDymY7wQ+M
IQBmi9FmUGdmD7YLZovBZoPgD2bB6QRmA9lmA9hmQ2ZY68RmK8hmK8JmA8bDZivAw2YryWeK
C4DhD2aD+QAPhQQAZivJw2ZTZlJmA9lnZg++E2ZJZktmg/kAD4QNAGbB4ghnihNmS2ZJ6+tm
i8pmWmZbw2ZTZlJmK9JnihNmg+IPZivJZ4oLwOkEZoP5AA+FCABmK8lmWmZbw2YD2mYD2Wdm
D74TZklmS2aD+QAPhA0AZsHiCGeKE2ZLZknr62aLymZaZlvDZgvJD4UBAMNmUWZWZ4M+YQ+M
DABngz56D48EAGeDLiBmg8YC4uZmXmZZw2ZQZlFmi9BmoTICZ2aNWBBnA0MEZ2aNQBBmi9ro
RPlmC8APhAUAZllmWcNmoTYCZgvAD4UIAGZZZllmM8DDZosWNgJnZo1SEGdmi0IYZjPSZvc2
jgJmM/ZmUGZWZlhmXmY7xg+EOgBmVmZAZlBmSOgb/nLo6Ov9ZlpmXmZZZltmU2ZRZlZmUmah
RgJnZo1AGOjQ+GYLwHTEZllmWWZZZlnDZllmWWYzwMNmUWZQZrgFAAAAHgdmi/nojf1mi8Fm
uyAAAABmuQAAAABmugAAAADoM/hmW2ZZZoXAD4UVAGaLwWYPtw4QAma6EgIAAOgW+OszkGYz
0maLwWaLy2ZQZlPoIwBmW2ZfZgvAD4QXAB4H6DX9ZovHZg+3DhACZroSAgAA6OH3w2ZSZlFm
uyAAAABmuQAAAABmugAAAADox/dmC8APhGMAZovYHgdmiz4aAmYzwOhZ+B4HZoseGgJmWWZa
JmY5Dw+FDAAmZjlXCA+EMQDrE5AmZoM//w+ELwAmg38EAA+EJgAmZg+3RwQD2IvDJQCAdMuM
wAUACI7AgeP/f+u+JmaLRxDDZllmWmYzwMNmUGZRZovHZsHoBAZZA8hRB2aD5w9mWWZYw2AG
vmkOvwAgHge5DQCQ86UHYcMBI0VniavN7/7cuph2VDIQ8OHSwwAAAAAgIGCLNhggJooFiARH
Rmb/BhQggf5gIHUG6FsAviAg4uaJNhggYcNmYIs2GCCwgIgERjLAgf5gIHUG6DoAviAggf5Y
IHXpZjPAZqNYIGahFCBmweADZg/IZqNcIOgYALsAIGaLB2YPyGaJB4PDBIH7NCB17mZhw2Zg
uyAgZosHZg/IZokHg8MEgftgIHXuuwAgZosPZotXBGaLdwhmi38MZotvELsgIMcGGiDcD8YG
HCAUkFOLHhog/xdmA0cCW2YD6GYDL2aLwWbBwAVmA8Vmi+9mi/5mi/JmwcYeZovRZovIZosH
ZjNHCGYzRyBmM0c0ZtHAZolHQIPDBP4OHCB1soMGGiAGgT4aIPQPdZ+7ACBmAQ9mAVcEZgF3
CGYBfwxmAW8QZmHDZovGZjPHZiPCZjPHw2aLwmYzxmYzx8NmU2aLwmYjxmaL2mYj32YLw2aL
3mYj32YLw2Zbw6gPmXmCWrUPoevZbr8P3Lwbj7UP1sFiygYeZmBmM9u4ALvNGmYjwA+FuwBm
gftUQ1BBD4WwAIH5AgEPgqgAZmGQHwcGHmZgZ4B7CAAPhQwAZ2aNUxBnZosK6yWQZ2aNUxBn
ZotKKGaB+QAACAAPgwwAZ2aLQixmI8APhAMAZjPJDh/o9f1mI8kPhDIAZroAgAAAZjvKD4Yf
AGYrygZmUWZXZlJmi8rot/3o+/1mWmZfZlkHZgP669ropf3o6f3oC/4OB2a7VENQQWa/ACAA
AGa5FAAAAGa4B7sAAGa6CgAAAGYz9s0aZmGQHwfDBh5mYGYz27gAu80aZiPAD4V0AGaB+1RD
UEEPhWkAgfkCAQ+CYQBmuAe7AABmu1RDUEFmubgBAABmugQAAABmM/Zmvk1CUkNoAAAHZr8A
fAAAzRpmuAe7AABmu1RDUEFmuUIAAABmugUAAABmM/Zmvk1CUkRoAAAHZr8AfAAAZoHHvgEA
AM0aZmGQHwfDZlJmM8BngHsIAA+FDABnZo1TEGdmiwLrC5BnZo1TEGdmi0IoZlrDBh5mYGYP
tw5mAma4aAIAAOj8+mYLwA+E+gBmD7cOdgJmuHgCAADo5vpmC8APhOQAZ2aLAB4HZos+PgLo
GflmoT4CZrsgAAAAZrkAAAAAZroAAAAA6L7zZoXAD4UjAGahPgJmu4AAAABmuQAAAABmugAA
AADonvNmC8APhUQA6ZMAZjPS
===
[SIGN]
[F9F69A0B2568EA1CD55B735A0A386606] MICROSOFT CORPORATION
[8B9F2CF0C3EED9E98EA4795A9585B6B9] MICROSOFT CORPORATION
[9012FF88724B4C9C82DC176E9B3BD788] MICROSOFT CORPORATION
[02C0D16BBEF9C7CCE913D22BF01B2987] Foxit Software Incorporated
[CE8A7CA22D2EAB00D09E25E5FEC0DB9F] Foxit Software Incorporated
[F8BA54AD76C8F8EC9F3D639871B30F27] GOOGLE INC
[6C718849D436A7CCEBED72538F8BD04B] GOOGLE INC
[D2F56E366F1CB26866A6F43BD53B46C3] GOOGLE INC
[605CCC9CE1839BC5583017DF7CAE27A6] GOOGLE INC
[2CC2D84CFD0694CA53FCFF43670F1EBA] Tonec Inc.
[9AF02944DA6A9C2C82790E4B21A7A470] Tonec Inc.
[B289C20C10B241F6016FECD92B267098] Tonec Inc.
[B58E7316785596F9918AED57B33DDA25] MICROSOFT CORPORATION
[7CA2C84A3CB5A4C55150A9FCD60CC1FF] MICROSOFT CORPORATION
[DFCBA29A5A6637FA0A8196C086A13371] TRENDY Co.
[C19ED5A3B0C5DFEF7F1EBEF02CCBAEEA] SHAREit Technologies Co.Ltd
[FCB8DD20046D231611EC4D3E466BAD45] SHAREit Technologies Co.Ltd
[FFE2D028D996BC6279A2E4894F9FCBFD] PIRIFORM LTD
[638AE77DC319958727FBEA403D37B2D6] PIRIFORM LTD
[97BED53AF0A644ECEA40DE5AB75A7067] MICROSOFT CORPORATION
[EAC888C884C5AE875B16E8C714B4D2E6] MICROSOFT WINDOWS
[FB7FBBFAD6F56D8D9C5199EC2B7D15F8] MICROSOFT CORPORATION
[BC5A40AEAC1CF7708D07CBC2F577F90B] MICROSOFT WINDOWS
[DBE1ADA144291F8E0F29ECC40AE14562] MICROSOFT WINDOWS
[641B19018CB32619ADBD0AED4964E1D9] MICROSOFT WINDOWS
[60229D15D4B8022678C604550DB05BD1] MICROSOFT WINDOWS
[50C644D09E79A9BF47CDD5A39EC6F876] MICROSOFT WINDOWS
[D0CA1D05B5615808E6601113030C3666] VideoLAN
[393B2DADF99EEF3B081BC0E455BCAFFD] MICROSOFT WINDOWS
[CEDC4E5155D9D48F2922C21EC02419B7] MICROSOFT WINDOWS
[A067A0D2C1C5F9BBA10E5ABF9B6B5A42] MICROSOFT WINDOWS
[DA094771C21F8FD92C4A68312A087A4D] MICROSOFT WINDOWS
[39D901F323BB584EABFE21FE1CEA809C] MICROSOFT WINDOWS
[E3438A61D11253AFF1698942777C19E2] win.rar GmbH
[F6AAC412E5E73C5D4064F1D51EEE442F] GREATIS SOFTWARE LLC
[76B135A15F550B044A52C98B59B606FC] GREATIS SOFTWARE LLC
[E0EC94CC481580CDAED257B210C880C6] GREATIS SOFTWARE LLC
[2192B5059195D40C7A737BCFCC04ABB2] MICROSOFT CORPORATION
[5BDB5A69952DEC775BA91677781FF506] MICROSOFT CORPORATION
[6A65873EA949C5CCC72DDEF9E9780AA5] MICROSOFT WINDOWS
[5EF8B333C40A3D177DB17B4590BC885C] MICROSOFT WINDOWS
[65EA3086C7F28BA5982043D2491B8856] MICROSOFT WINDOWS
[59D38A41008A7A229273D8AF693ADBAC] MICROSOFT WINDOWS
[785A1493731880AE44C7E6C46CCA004E] MICROSOFT WINDOWS
[F7A3878E9059A8E1E3CB7CE74A539201] MICROSOFT WINDOWS
[B6408E917726CF5AE115CD939940EA38] MICROSOFT WINDOWS
[0222ED97F392077F05A7CC6C0E259850] MICROSOFT WINDOWS
[018D6E7BA23E28ECA0CB7F071A9FF291] MICROSOFT WINDOWS
[9FAD8034D504201B557BD82E824F9EFC] MICROSOFT WINDOWS
[2354C6B55E174B46EBF3147EA3114777] MICROSOFT WINDOWS
[A5CF51E5938BC3B36F035678EADFFAD3] MICROSOFT WINDOWS
[190053992A600E1E07D82B3AFD59A855] MICROSOFT WINDOWS
[ABF80D6CA310317D10DA580BC59D0202] MICROSOFT WINDOWS
[9A62F0FCAEE1DA5C047F763495A5FF54] MICROSOFT WINDOWS
[B56AAB10E981BB84A6CB076CF1CE8A6A] MICROSOFT WINDOWS
[D4BE993965CE6DBABB595B3EFEECC7D0] MICROSOFT WINDOWS
[46801BECD7CBD6E12A4722895AB216B2] MICROSOFT WINDOWS
[D17F6C945AF73BEAC7A6FFAD6E30859F] MICROSOFT WINDOWS
[DA5868EABB74AEC4354647D45F97C0AF] MICROSOFT WINDOWS
[9A2DF1905A6AC59527FED7D0DFEBA42D] MICROSOFT WINDOWS
[CBA59BEFF4E854C481D27DEAC17429F4] MICROSOFT WINDOWS
[A792B49B96CE0C33D5BBDF3D3EDC1751] MICROSOFT WINDOWS
[79E2068FB1E925B013EE28ACA7D1BEEE] MICROSOFT WINDOWS
[A44D27D03056EEC97CF2AFDC658EAB45] MICROSOFT WINDOWS
[0AED07F28B0B0820C9895656FE67FD1C] MICROSOFT WINDOWS
[D6CE62F271345D40472A002E0AAE1C07] MICROSOFT WINDOWS
[7A20DA1F1406492A70E9C8243634467B] MICROSOFT WINDOWS
[BDC6F41710F85FC5752DF132484FD98C] MICROSOFT WINDOWS
[7E2D956634CD227D2ABCBB9F62EC93F0] MICROSOFT WINDOWS
[9473F2B5794F0A81C7C7FB602D7B34ED] MICROSOFT WINDOWS
[92419F3B74C6C3D7304B7665DA984552] MICROSOFT WINDOWS
[0C0EDC90F6D3F80EE82DAC1586F432AF] MICROSOFT WINDOWS
[81D023450CD83A8021B6F8DDDFBED8CC] MICROSOFT WINDOWS
[78AA5FEDC6ECA8269093F4D1EE2A27B3] MICROSOFT WINDOWS
[05793B87BFD0101369AD01DEC810048B] MICROSOFT WINDOWS
[50137D32AACD4D73AC3BC2BBBED9B135] MICROSOFT WINDOWS
[E67AEB5F9FA81EE896EC3F0EB837BB12] MICROSOFT WINDOWS
[43C9CCAA6BE7AED7E2957A7FCFB4AC54] MICROSOFT WINDOWS
[776DDA478631BF8D2143D53FF0F9E5E7] MICROSOFT WINDOWS
[C891C2BE30DF2EF1E3769D4EEDB27A9C] MICROSOFT WINDOWS
[A939CDAB068CF5775E29D8B915042BA2] MICROSOFT WINDOWS
[F04ADA7AF26797029FA84FE969E7D215] MICROSOFT WINDOWS
[785A1493731880AE44C7E6C46CCA004E] MICROSOFT WINDOWS
[B27279D58FF5801DF02F83E7E51C53C9] MICROSOFT WINDOWS
[425280AF4EB1F4A105097A4DEBD84B18] MICROSOFT WINDOWS
[77F7A3C5F9C843173EC787CF85CCC1CF] MICROSOFT WINDOWS
[8333C5EB5C9E8F06861717DF2E319966] MICROSOFT WINDOWS
[7340CCD55E6BEC8F98019F2018A3B6A3] MICROSOFT WINDOWS
[72C05E1DCEF19658EFDE2E22CB747884] MICROSOFT WINDOWS
[1B0620BED0E3FA44617301558D7E9815] MICROSOFT WINDOWS
[E129358A0BE95CBF9EB0742173E72665] MICROSOFT WINDOWS
[7C2C340E8EA637F930E9F82D16CBFF2F] MICROSOFT WINDOWS
[96E090FE8C0559EB39DCE2F2165C3BAB] MICROSOFT WINDOWS
[3C5E2B48021E9D45CCB35B8987F3A399] MICROSOFT WINDOWS
[37746E238D02257E1DE4C3832326CD18] MICROSOFT WINDOWS
[07176C2B95E1E9E6114956084EBAE9AD] MICROSOFT WINDOWS
[43F1CDBE6650A2989E1C2F6F02F0E4F1] MICROSOFT WINDOWS
[7A2163DA90A08C73776B07FA0B8E3852] MICROSOFT WINDOWS
[20AF2F885AE06DDBB31BF586D0333047] MICROSOFT WINDOWS
[61E4F7601980AA8396D608EFABF1FAFF] MICROSOFT WINDOWS
[FED9AB89CEA58D22566DBF65DB3A5BDC] MICROSOFT WINDOWS
[72DCA3EF93EAB7A87D3EBE9DD94C959F] MICROSOFT WINDOWS
[3F5392AE17DB28A5E4A7022140B0421E] MICROSOFT WINDOWS
[0AA32D46BBEC1509B13FFBFB00C26116] MICROSOFT WINDOWS
[759E47EE37B5C8368A5CA39F95F3B0B8] MICROSOFT WINDOWS
[4C41666923A14DC687DEEE3B143AFB55] MICROSOFT WINDOWS
[EBD5C968ADCCE803DED93A1B7F6A62BC] MICROSOFT WINDOWS
[8D11B28DA95463364439E394C2CF62E6] MICROSOFT WINDOWS
[E8A9C2E4DCCFA92B197A5FC6D3B5249A] MICROSOFT WINDOWS
[0837EDC0FA9710F51E197A124E8310F9] MICROSOFT WINDOWS
[AFE653CCC2592633C22DD5DA4124AB59] MICROSOFT WINDOWS
[35A20D48D8A84AF8154B47CBCEACBCCC] MICROSOFT WINDOWS
[7384E7ADCE23BD023B85D97ED83AB149] MICROSOFT WINDOWS
[B440713B9913F70952CD75B776B95E29] MICROSOFT WINDOWS
[B11044B116BC28695B426DFFFB2BA728] MICROSOFT WINDOWS
[D3FB829B5D8A01790661A17D19626290] MICROSOFT WINDOWS
[7A5388F4E7CB37108543070D41235E5C] MICROSOFT WINDOWS
[F7AD25F7667C1B5C1D681A48AED0FF0F] MICROSOFT WINDOWS
[B6A55F43F2C7D6F90D69FC63FFE08310] MICROSOFT WINDOWS
[CC9071D7AC1A3B81FB80016A16FD9F9A] MICROSOFT WINDOWS
[D2AB39EA2C0FCD172751F84BDA723A97] MICROSOFT WINDOWS
[18286E4DF795E502905EC5218E5726F8] MICROSOFT WINDOWS
[2D06B7F6F72790BF0E58CAB865428AE7] MICROSOFT WINDOWS
[7231A7C8515B00D2708EC68B2A792EBE] MICROSOFT WINDOWS
[449075E8889DE1D57714B8177457D533] MICROSOFT WINDOWS
[9B0EA8FC801305EB23E8611785BBE847] MICROSOFT WINDOWS
[81639B18EB7C4FB1C49B35CCA7F80EE8] MICROSOFT WINDOWS
[52166C84DA4BBD0FB70EF15F84D8A5B7] MICROSOFT WINDOWS
[C3807173110FCDD0B877D23F5FD28138] MICROSOFT WINDOWS
[FEB0C1D3F1CE24CA8546FB02B8B1241A] MICROSOFT WINDOWS
[8F56B78F502BA54DF0E7F252D007A33B] MICROSOFT WINDOWS
[6253BFF71CE081511CE362714B21F24F] MICROSOFT WINDOWS
[9E85604FC93AFC1237C29CF9EFA83D60] MICROSOFT WINDOWS
[1E56666C11164E0BE83A2330D85D65A9] MICROSOFT WINDOWS
[5AFE650194C07BE81CB5A01B72549A1B] MICROSOFT WINDOWS
[5194BF2FEDA9F6BE6F7691EDA1F910DE] MICROSOFT WINDOWS
[AF17F63DFDE9F19BBE730A1ED86DFEF0] MICROSOFT WINDOWS
[AE0B2FAC90C4DF325F24A7BE70CE5609] MICROSOFT WINDOWS
[F88D3AF78AE83F9206D60ACC8D735DC0] MICROSOFT WINDOWS
[BB5A205BFB6AC39CE965322B27D07915] MICROSOFT WINDOWS
[89D675A01B6A4E1AEEB563DD8450E8CD] MICROSOFT WINDOWS
[EFB766859B1A4A14EA65528AAFFD1549] MICROSOFT WINDOWS
[1085914F24F74234C16BF12E7BBFC403] MICROSOFT WINDOWS
[056C68D7ED2270EF12990B80A47592B5] MICROSOFT WINDOWS
[DF8F48328EFA4EFB04CC5528629DE585] MICROSOFT WINDOWS
[C3D9BE0D466EA8240B129FA54257562D] MICROSOFT WINDOWS
[B433AE814237F91624E3AAACF6BC3563] MICROSOFT WINDOWS
[2F01953999020AC8C5EE3BBFB0094E79] MICROSOFT WINDOWS
[F543CC0BDF5EBAF462C77FED31593C3C] MICROSOFT WINDOWS
[863DCECAE095A3749546C89A7897E8A7] MICROSOFT WINDOWS
[A39C05B19C079401A9AF8A2EF3067B64] MICROSOFT WINDOWS
[477906D31E1A5FDA0E5CD8D189DAD61F] MICROSOFT WINDOWS
[E42AF3C735EFBAB61D00B5101190ACE8] MICROSOFT WINDOWS
[739D089777D2B66DBE7201E5EA4BA2D7] MICROSOFT WINDOWS
[79647BFB7A9B6019E1C8D000A96D8D7C] MICROSOFT WINDOWS
[DAFF6F23D321DF8106CEC03BC0E9E964] MICROSOFT WINDOWS
[7D44193A9ABD39FD7D7427414B845855] MICROSOFT WINDOWS
[B33351A77FFE93A9CA4C625E4CF2E6D3] MICROSOFT WINDOWS
[DA261B477C713EA9481EF8527328D027] MICROSOFT WINDOWS
[F8D27297A01AB57929BC3F39E61281DE] MICROSOFT WINDOWS
[1A0AF89F61538B833075FEB438EBC33D] MICROSOFT WINDOWS
[AE60FA63282CFB1825C68D2F44737A1B] MICROSOFT WINDOWS
[451193C2EC533818B7474D2B24623836] MICROSOFT WINDOWS
[122A2FBC5231E8AA6768F0998BC68279] MICROSOFT WINDOWS
[8FA206A2891883E610B8501CF9880F07] MICROSOFT WINDOWS
[E0F9E50058E4EA6B1CD7002310B00F0D] MICROSOFT WINDOWS
[DB01E910747D4AB7B59842AF88D7F86A] MICROSOFT WINDOWS
[2BBDBBA403F23A4197BFB1147AF566C1] MICROSOFT WINDOWS
[F50AFEFFB3DB2BDC549AF4A230A3ADB5] MICROSOFT WINDOWS
[7014CEFB8F3652B2AA0533D33D94F936] MICROSOFT WINDOWS
[5787AFA76808253F32DBBB31C4E26C8A] MICROSOFT WINDOWS
[D7FAEE38C867DFDAA626B886A7AEA89A] MICROSOFT WINDOWS
[F9BA5E23AAE945513581594BB7A947C1] MICROSOFT WINDOWS
[E37576C5716151B03D9B374D40ECBFA4] MICROSOFT WINDOWS
[C93B6F7C1D03400315AEA8530698FF57] MICROSOFT WINDOWS
[769ACDF8CE8BBA378B9D32C123CCE647] MICROSOFT WINDOWS
[CF389361290FD38EA31932CD52D18D63] MICROSOFT WINDOWS
[EBD069FB399EE8EAC498D5F9B129AAA5] MICROSOFT WINDOWS
[75DAB6D505A8774A17DC29BB71A8FE7C] MICROSOFT WINDOWS
[DF2E93BD5CD438688ADAA3AEBFBBDC9F] MICROSOFT WINDOWS
[912B28456292AF00A8EBF2B0F90E42B5] MICROSOFT WINDOWS
[92AF73FAE4F0D3E95ADE69C45CAF5022] MICROSOFT WINDOWS
[175A50CD43C776E07CC00B6E6C5DA1B3] MICROSOFT WINDOWS
[567EBEC0D1127D2E48A68273DF9049B2] MICROSOFT WINDOWS
[C7E85EEDBC05491FF1CDD3ACA98FA1DE] MICROSOFT WINDOWS
[CD76072EE8E1E91099ADF566DC4DBC5C] MICROSOFT WINDOWS
[048980E575F5228248511B3E0ACC1749] MICROSOFT WINDOWS
[B41EDC7CDD2C1F35BB36CD384C3985AB] MICROSOFT WINDOWS
[2A17E43AEEA415005B3BA59E6242343A] MICROSOFT WINDOWS
[106290B54A85834C0E6EB005BC54AD31] MICROSOFT WINDOWS
[2B24FC41E7ED5BB730DDF8D78AA73A52] MICROSOFT WINDOWS
[F7193E7F929653AD4CE636FCFBDBEEDC] MICROSOFT WINDOWS
[F314609DBF8A3AA9EA69EF40C7FE7762] MICROSOFT WINDOWS
[6CBC38EC80F2976F7EF23602308FA644] MICROSOFT WINDOWS
[D64F99DD8480935CDA61ADC66C81FE87] MICROSOFT WINDOWS
[A3FBC41B97CAAF95795F3AB86AE82549] MICROSOFT WINDOWS
[15677C04E81E80BAB562D39879F06235] MICROSOFT WINDOWS
[A751D0D8462665969C43337435A26711] MICROSOFT WINDOWS
[F7555EBB13AA476E9B15B5082249E0AF] MICROSOFT WINDOWS
[CC9425EB85BFFF1FC67FB8F1CB3174A8] MICROSOFT WINDOWS
[3D719AD748F65869EA0E7002F0D2D2A7] MICROSOFT WINDOWS
[4EF5EA4643076475D1B34345FA245930] MICROSOFT WINDOWS
[FB0B8778A55ED71728D28E9B3889A11E] MICROSOFT WINDOWS
[855678C1760AE7DCE0CF2BAFD989176E] MICROSOFT WINDOWS
[6973720AB8B0F7063B05E9211661AF5E] MICROSOFT WINDOWS
[8BE5EBA8A54B789690B9493BF7DE1DCF] MICROSOFT WINDOWS
[34A4E4C0D8DBB733F14CB5B7186B9975] MICROSOFT WINDOWS
[24075C6DA27D05D869C56102E8220E92] MICROSOFT WINDOWS
[96FC1329E286E2309AA94D970C962EC7] MICROSOFT WINDOWS
[7DFC088DEDC2232C36562CCAAFC26824] MICROSOFT WINDOWS
[12DB9F4C1ABB1B8F7AC7203C049528CB] MICROSOFT WINDOWS
[69EDC8900C69E2BBB13D2FD24B3A085C] MICROSOFT WINDOWS
[8EFE5647D0CDD02A0F456C15D5ECF979] MICROSOFT WINDOWS
[E3E53B226DCC3D0F8A714929C45F068B] MICROSOFT WINDOWS
[F023C1F4A112B912D3625324CAA8B616] MICROSOFT WINDOWS
[FDAA6E61D35A03AB7EA08A8D99845EF3] MICROSOFT WINDOWS
[F677A4B785E0BBD01C531B1668F7D3F3] MICROSOFT WINDOWS
[2B8FD5359FB5A1FA2EE9504D53C0D286] MICROSOFT WINDOWS
[D2BCEA4C0513E098277F10CCBAC8FAF2] MICROSOFT WINDOWS
[7EF070F21CAB7E8DC906F9CA8516CE5B] MICROSOFT WINDOWS
[9E5AECAB5F05218D9AC923E7CEA1CE15] MICROSOFT WINDOWS
[48EDB9B5DAB7D294951A520330F13715] MICROSOFT WINDOWS
[6C3EDE394C71D5A67A504F55E35B6F47] MICROSOFT WINDOWS
[806D14CEAF25E5F2DFCBA8E7E33B86BB] MICROSOFT WINDOWS
[87DDDAE1693484BD0A210C877BDA00C2] MICROSOFT WINDOWS
[8D3E3C431367E3BA632B4396CA662E1A] MICROSOFT WINDOWS
[149F1260537C4F68C3F67C363B62F3C5] MICROSOFT WINDOWS
[3E641E905A6DBF29CBA1E72BBE349808] MICROSOFT WINDOWS
[B78D6AF79045B0DAB58596AF75037516] MICROSOFT WINDOWS
[2ED3B41C7CB4101ACB15D84D8AB5AA9D] MICROSOFT WINDOWS
[16A10CCEDCF5AC4CAAE43DC9FC40392F] MICROSOFT WINDOWS
[EB82A11613326691508D9ED9A4FE29E7] MICROSOFT WINDOWS
[42B660654149FB181E49EA160808D3BC] MICROSOFT WINDOWS
[E47022690D960CA022F0ADAD3CEE7028] MICROSOFT WINDOWS
[1382FAA11F64E6AEE553D6889DC2ED2C] MICROSOFT WINDOWS
[6248F7270A37B8890C7A058AAD4D6620] Tonec Inc.
[3F8B046C0839FDB879FE179C07A1A6A4] MICROSOFT WINDOWS
[3B0C7978321F691DCA332A3A30D3D34D] MICROSOFT WINDOWS
[87E738E189EB31E2EB07F609C930D068] MICROSOFT WINDOWS
[9E3EFA9EC7C87D20706E7A545773415A] MICROSOFT WINDOWS
[1FD5F56938424E3D437F2DD7FFE68A58] MICROSOFT WINDOWS
[84BD903F361891CB3C3CEB1DA5198130] MICROSOFT WINDOWS
[16406F139B0B986F38D4C25B6C2C97D3] MICROSOFT WINDOWS
[A25F081BFDB86B48AAF36C4BAA398466] MICROSOFT WINDOWS
[EC972A6A764579EF04D28D70675D11A9] MICROSOFT WINDOWS
[CEC63D8B8E7A525233D2AEE19EF9A5A8] MICROSOFT WINDOWS
[5AAD8A0ABC294C7A547F1C903AC04716] MICROSOFT WINDOWS
[35FD8315E03C4B5FB4C81B3F5AA6793E] MICROSOFT WINDOWS
[C48B4FD5F9D4A0AEF69A691558BF30A4] MICROSOFT WINDOWS
[6FC797BC9152E34D3C1C1AB6F7C3FD33] MICROSOFT WINDOWS
[08E5CBEAC1E11CBB4A27823F031B7E61] MICROSOFT WINDOWS
[56D480702478880805F4E74F2BA02382] MICROSOFT WINDOWS
[38EDAC4667F2616442770D8DB0B2DC25] MICROSOFT WINDOWS
[8F16F4D9D8E57AF55D42E182E8F83BCA] MICROSOFT WINDOWS
[92DBC56CF0C981AAAAADDEAA6A563E39] MICROSOFT WINDOWS
[711E26B6F381ADC675D8C52CDEE505D5] MICROSOFT WINDOWS
[479D8B6848EE3F6DA748C6636DF89389] MICROSOFT WINDOWS
[7E3BEDEF17FFC3DA9E2E306138C5250F] MICROSOFT WINDOWS
[91563B08A4FF7013420A14A1446264AE] MICROSOFT WINDOWS
[1BBADB9591080518596B9E57E6867DA9] MICROSOFT WINDOWS
[7C1D1CB733DE28F7D15D69C5112B983D] MICROSOFT WINDOWS
[C18F1929FB5594233CCA71FC624428FF] MICROSOFT WINDOWS
[4D322612CB0E3E8DFFDE8B78A5CAA841] MICROSOFT WINDOWS
[03D9EDE1E96D1D158BD984D88B1095CC] MICROSOFT WINDOWS
[CBC57FDBD22DD92B3B7B71DC44304301] MICROSOFT WINDOWS
[4C71C550AC2CD9E0201BCBFCF19DB0D7] MICROSOFT WINDOWS
[5EA3D977905D88627B5667E761C51F50] MICROSOFT WINDOWS
[7DC0311FA450D54C5D345CE19778EA8A] MICROSOFT WINDOWS
[660C8651E6D9A15062A497364CA4A329] MICROSOFT WINDOWS
[329C1C69386412444D05C82A6062F9AD] MICROSOFT WINDOWS
[E8DDD6B4FB2F20780B41B117F689A44E] MICROSOFT WINDOWS
[9089316A8C1D2F4A604470DFD1B6865D] MICROSOFT WINDOWS
[ED1393D406757F6533257476F27209E9] MICROSOFT WINDOWS
[9117B78500C6A09F16EDC604ABD71F38] MICROSOFT WINDOWS
[1CA135D48C2C552E5A2DB2E5A14DFCCD] MICROSOFT WINDOWS
[5F37CEDED43E3816BA38809E062134E1] MICROSOFT WINDOWS
[753917AE790F884EE62D5E1F8EBFCC44] MICROSOFT WINDOWS
[46708375D885CDD367CB6027A515D0E0] MICROSOFT WINDOWS
[165AE5452B9155025814BAE5535E3019] MICROSOFT WINDOWS
[6B0B650460A7501E3F01C191F865E298] MICROSOFT WINDOWS
[AB7C450FA26544AB6D9344A81597B30B] MICROSOFT WINDOWS
[E7219627FF618544FEAF5CE61D99581B] MICROSOFT WINDOWS
[6DC929A7046019A4F7C27EAF25351C55] MICROSOFT WINDOWS
[CCBCB215B0DB2153F5F7F77D10F05B07] MICROSOFT WINDOWS
[00D2E49ED6A5A11A5354637D3A632D03] MICROSOFT WINDOWS
[07B8BAF680467BAB0607245E68D59805] MICROSOFT WINDOWS
[0A68189FC5A0A09FF3BF7CA60278864C] MICROSOFT WINDOWS
[05F3DCB8F90EF90C59E616F1D4C7585D] MICROSOFT WINDOWS
[07C51C8E403121E63E3F7CC2B19840A6] MICROSOFT WINDOWS
[E64484CBBEF329B919D9E78B8CB58CF5] MICROSOFT WINDOWS
[E9013D05C43A68E4820540D413569415] MICROSOFT WINDOWS
[D8A1393038D9E6C803E1DFEDEF386E23] MICROSOFT WINDOWS
[6479443BB89DBAC3BBCE9C2517EFAD0D] MICROSOFT WINDOWS
[226F3D5F50000A36CE3B62C8121CD74A] MICROSOFT WINDOWS
[DE7DA242F4A7C0882006ADF6C541FA33] MICROSOFT WINDOWS
[A4D1316CB4EF1B753DE772C342F091AA] MICROSOFT WINDOWS
[6EE73A7918BC1EC7EFAC4A32DCFC8B13] MICROSOFT WINDOWS
[18CE49B3D3C73B3DF4B5D566F0BADCC3] MICROSOFT WINDOWS
[DA4A165EFD14AB23DC9210A806252B41] MICROSOFT WINDOWS
[5C7905E2EB6BE00E9C998A4BB8EC233D] MICROSOFT WINDOWS
[724459B4B727662A5F69A12AD31FC197] MICROSOFT WINDOWS
[1599EAB4DC6DE373BC57F768A6AE770F] MICROSOFT WINDOWS
[66883438C1B3273F31DB8A7924D8314E] MICROSOFT WINDOWS
[10D7989C206DFB0CB7AF85C38EE323D3] MICROSOFT WINDOWS
[D51A226E5E7803894596683F6E0DC5B6] MICROSOFT WINDOWS
[E997374B5EBB4FC5528B4F653B2E6CAB] MICROSOFT WINDOWS
[3BBF4C8BB52DCB265EF71E4F75369C65] MICROSOFT WINDOWS
[69E1E41C47B2B11C53A6193E49ADEF11] MICROSOFT WINDOWS
[F9FACC5EA4D793F8265F30C2DA0EDBA7] MICROSOFT WINDOWS
[438BB0743B2AA510D616AD81ECE2FA08] MICROSOFT WINDOWS
[5DFB139945F70FA15CAF7F3929B932AD] MICROSOFT WINDOWS
[BC36AFFA77E02ED12317C33B07B78238] MICROSOFT WINDOWS
[1680BBF697C0F93857131292C134A99F] MICROSOFT WINDOWS
[717FC248242BDCBB3B8159B8098BD34F] MICROSOFT WINDOWS
[C0AD5C89FA61DD92E40BDD9A802C9DC6] MICROSOFT WINDOWS
[720633286CA7E9E1FD1456338317AD8A] MICROSOFT WINDOWS
[7782D0BEEF87BFF841B5684E3FBCAC1B] MICROSOFT WINDOWS
[E52627112D11E7F96879FA0245902209] MICROSOFT WINDOWS
[BE048641E0F24F422B8A269AC3CBDA83] MICROSOFT WINDOWS
[1D08E2FFF4F950CF303B981C97D921D6] MICROSOFT WINDOWS
[5B8D57A3FA8AFD8EA21240E10E570E4E] MICROSOFT WINDOWS
[14D167238A8C42EA8E951A5A956DEF42] MICROSOFT WINDOWS
[838C9F2D2EB6D29776AF1AC78B4AA1D7] MICROSOFT WINDOWS
[032F1C32A6A97C317AEFF9D64D2A1D8A] GREATIS SOFTWARE LLC
[5DE91FBA48F6179083F2860CFF4905EB] MICROSOFT WINDOWS
[79BE670056FF45B9B6280B1FA55FFD90] MICROSOFT WINDOWS
[D72B9224E91AD87B88ABAFE5B8E1885A] MICROSOFT WINDOWS
[F0638A0AB447F0A46D36F28E8F817AAC] MICROSOFT WINDOWS
[4AC3A1D2F9AC74DA7BA3A30344AAB664] MICROSOFT WINDOWS
[A90AE269096D22897BC7219922ACF12B] MICROSOFT WINDOWS
[E4518C35D159A468A789AB216A03AE8C] MICROSOFT WINDOWS
[B289D34C47978B8AB473BF19DB66BB91] MICROSOFT WINDOWS
[446B72ACD460A1B8C46DA7FF2F018A82] MICROSOFT WINDOWS
[5CD0064D4642934BC5979EF8135180DC] MICROSOFT WINDOWS
[DA8CB2643EDD2DA82BB804A8712796D0] MICROSOFT WINDOWS
[BE7468019B1731CA2FAA030C13DB1913] MICROSOFT WINDOWS
[738FD8811518AC7A630A277BF1CCF389] MICROSOFT WINDOWS
[4DAB92FD311B9F841EE40EF7B967DF8E] MICROSOFT WINDOWS
[342F9BA59313C2B796241DCECE18B727] MICROSOFT WINDOWS
[7BE861DDB225B0C373FE1FCA3BE8A3B0] MICROSOFT WINDOWS
[6E28E1CE915FE617D4F38BFB8543696F] MICROSOFT WINDOWS
[252FDEF9B98564F47A36CF11911D926C] MICROSOFT WINDOWS
[3515CD197282D7C867DCBD973CD44E3E] MICROSOFT WINDOWS
[71A6C25E3B9C7BDF0ACE20958F2CF8C4] MICROSOFT WINDOWS
[54BFF443F91F970F61B377A589CF38D8] MICROSOFT WINDOWS
[76C18F3B4EB5BC611FA7F249CF676911] MICROSOFT WINDOWS
[1AEE22C5FBF18F53C47AC4373F0DB542] MICROSOFT WINDOWS
[0631645A1C5196BA5D5AC6C186CF55FA] MICROSOFT WINDOWS
[88FC2D00DE5A999E29B8FD432DE3A071] MICROSOFT WINDOWS
[D8D7FEED713C25F089CE0768C266EAA1] MICROSOFT WINDOWS
[DF8FE557182A7B2C2D7ED893A04A63E9] MICROSOFT WINDOWS
[7936E95FFEA1758638715C6465B2A739] MICROSOFT WINDOWS
[7E29520C0B9E3E4039C8D2946557CF3D] MICROSOFT WINDOWS
[48AC5F706780BCC34811EA89A0727189] MICROSOFT WINDOWS
[CEE65C35DBCFD71CDDAC291E54DF1722] MICROSOFT WINDOWS
[9C7CECCEED1FF5818CD5A118258EE0C5] MICROSOFT WINDOWS
[EFBD152E3DBA02D06C7D2FF1E034919B] MICROSOFT WINDOWS
[6274ED5017EEFE775FDDF9082271472E] MICROSOFT WINDOWS
[460E007E94F053F56D3FA9DE486B7146] MICROSOFT WINDOWS
[1E7ECD63D209EE5CE02E582CA8918023] MICROSOFT WINDOWS
[7B58DD1E1CF8E1AE2A22C8CFFBDA3DB3] MICROSOFT WINDOWS
[4358940866F520CCF4D64185F771F19C] MICROSOFT WINDOWS
[AAE554DB5302A636B078F9C19E02E7FC] MICROSOFT WINDOWS
[51B9B16E99B1EF7D2107629DB8C4B578] MICROSOFT WINDOWS
[6D581AD1593B35711075886F153A8BAE] MICROSOFT WINDOWS
[43E10E093B3249C78D649A4096271AA0] MICROSOFT WINDOWS
[BDDF94AB15E77B54ED2CC60CCCE8F922] MICROSOFT WINDOWS
[01D980C33003B078324E3FE032C8A42A] MICROSOFT WINDOWS
[12E42E20BC0ABF8FC2AA5D13609ED0E7] MICROSOFT WINDOWS
[E156CB3AAF1E2C397A8F93EA9ACD8290] MICROSOFT WINDOWS
[CFFE219F9CA183C40AA5D44DC26E6F2D] MICROSOFT WINDOWS
[D88FC13079D14E5403AED5F7D33A2015] MICROSOFT WINDOWS
[039E1D037ED8D8F55962EE49F4B74B8F] MICROSOFT WINDOWS
[AABB5699D96708CE7372C6D71D298801] MICROSOFT WINDOWS
[7EFD2145C9AD88BD2528E4DC91D55A04] MICROSOFT WINDOWS
[AD40AC6DC145B2C48A58EF61AF8ECE82] MICROSOFT WINDOWS
[9A03A0D6D52859667599B7DE9A238502] MICROSOFT WINDOWS
[A79265A2CF42790393832EB1771E0967] MICROSOFT WINDOWS
[CE0F176C7C3DC2AEA1C75EF6A7583B67] MICROSOFT WINDOWS
[3E0B5A23A5A68051CDA332A4DFC09484] MICROSOFT WINDOWS
[9056D0A8791B00E841B4A5E5A04FCEF3] MICROSOFT WINDOWS
[3A82BBE802C82FE519A735F70F102D6F] MICROSOFT WINDOWS
[BC74E93B52526753408BC578C01CC786] MICROSOFT WINDOWS
[C58DC01DBBFB0DC058AC1AB792D88AC2] MICROSOFT WINDOWS
[7B4BF4CC6C96749124984A9E0AE1896A] MICROSOFT WINDOWS
[94EFB93479FD9EF655BAB3B80EE5C998] MICROSOFT WINDOWS
[66A6639AD401BAA8F92FF59FD2AAE774] MICROSOFT WINDOWS
[A8766E18A1E2D41301E7A8EEFBABCDDD] MICROSOFT WINDOWS
[E5CE3388A455ED80480EAE3A8ADD53A9] MICROSOFT WINDOWS
[DC451F4DC01E116C35121EBD6813618E] MICROSOFT WINDOWS
[BF97F92E1043BC92073FAED0752B70A2] MICROSOFT WINDOWS
[19DC44DF9C859396B3608F5CF5C83D82] MICROSOFT WINDOWS
[C7E9FAB0880D66EFB62C2B6314284D47] MICROSOFT WINDOWS
[06DE25D00DA359742445B525229E9929] MICROSOFT WINDOWS
[4227DDD821E0A81448CD187B80265927] MICROSOFT WINDOWS
[4631D2B2B5567A768389796A267ABED9] MICROSOFT WINDOWS
[B5A296C6DE5A56B62FB98859A8AB6C10] MICROSOFT WINDOWS
[9E8CC2A2F39A6C5377B4A2D3A061A429] MICROSOFT WINDOWS
[EB21892E714A16FAA18642F3A53A26B8] MICROSOFT WINDOWS
[41ED24E49525CB10312C707112E34C98] MICROSOFT WINDOWS
[B107AD3336E791B7B0F8E87301D23E44] MICROSOFT WINDOWS
[8BC17A0C2D93B66CDA5C5A9DC6854406] MICROSOFT WINDOWS
[EDFDDA5AF0557E6BF265893A223EDDD0] MICROSOFT WINDOWS
[9C5951944F78F3233CCB76273FCFCAE4] MICROSOFT WINDOWS
[E1D26FA75626B66D0020E07E30CDEC8C] MICROSOFT WINDOWS
[3556FCC172C935D65C3A682B30A54985] MICROSOFT WINDOWS
[D88BCBABE51CCB450B3DD1C696D9DD80] MICROSOFT WINDOWS
[D5E1A8CB08CEF619E0949535C917621C] MICROSOFT WINDOWS
[EC86C5BF1EBE408BA39730EDAAC93353] MICROSOFT WINDOWS
[07B0CD801BBF164F36DA3EE9F25C721D] MICROSOFT WINDOWS
[826827B952041E884774E0A87AA3D216] MICROSOFT WINDOWS
[CEE726DA975EC26A10857CB1E2FCA041] GREATIS SOFTWARE LLC
[AF79E1A4747418B190F36877977485F6] MICROSOFT WINDOWS
[0BA7174544F4064EF5C9383BA8EDAC78] MICROSOFT WINDOWS
[7DDE04DB56833A97492DC3013D4B3239] MICROSOFT WINDOWS
[B116EC25D7AD2EDD602A6EDEA8D7681C] MICROSOFT WINDOWS
[E7BFC2CCC6D416673A1698781991C656] MICROSOFT WINDOWS
[4CABA64DF4B1F3E772E70FD4FAE6CA0C] MICROSOFT WINDOWS
[04A34578BC8A70B5698D1D950C4F22FB] MICROSOFT WINDOWS
[6C5563F34424790A8F23985D837D18C0] MICROSOFT WINDOWS
[DCEB4F28AE40D0D9B80177C2072545D4] MICROSOFT WINDOWS
[AB3AD5D5F58FF144094052349E85459D] MICROSOFT WINDOWS
[EE67BDAA526DB1538D514C1BB8EE227F] MICROSOFT WINDOWS
[FF22D57250991143E6E969EE7BFAC0F1] MICROSOFT WINDOWS
[2DAEB3D979208B3DDA0C480BFD1D6A3B] MICROSOFT WINDOWS
[5BDF58D2E5556465189C2FDC7DDC1803] MICROSOFT WINDOWS
[10165ECCC7A1DF3C1B6AA53C8EB2A87F] MICROSOFT WINDOWS
[C06E30A8EE21D4E8AB184F985DD50C12] MICROSOFT WINDOWS
[A9957C709EE8AB75837916648827B900] MICROSOFT WINDOWS
[2CD9E1B442B8BD5FC7F879916D49E692] MICROSOFT WINDOWS
[562C0C9FFF08A6DF60D858E6482E35CE] MICROSOFT WINDOWS
[EF47B2B95A428110D79C6357C6079AE7] MICROSOFT WINDOWS
[A898490F7840AB1012D70887DEB20106] MICROSOFT WINDOWS
[C3B4E43D5283D32E1D3890D101C70C1C] MICROSOFT WINDOWS
[0B7CFD2F8B043740CE20A23B666DE408] MICROSOFT WINDOWS
[634A15C2B5CC3BBB151F2AFE9C3AE031] MICROSOFT WINDOWS
[FC7A59A1AA07632AF8E9DC254918F879] MICROSOFT WINDOWS
[6CC21AB292E58758F151456D0ED3A628] MICROSOFT WINDOWS
[F5B761B65CC090F32C97D9311AC246E2] MICROSOFT WINDOWS
[23C594CF5049DF2096D2D9ECBADEF29F] MICROSOFT WINDOWS
[0F13F63BA93C89DA4F54B8830EB5410B] MICROSOFT WINDOWS
[C0F4049CBD0632DA2B3E1F515A460531] MICROSOFT WINDOWS
[915D53A7C56FE47F617F0714511AF869] MICROSOFT WINDOWS
[EE4D650D73A565F7921C6F097ED6E709] MICROSOFT WINDOWS
[B4E3EB14D422A128EE2C391A05C8958A] MICROSOFT WINDOWS
[F978AE0389352BEA2EA921600AF64C16] MICROSOFT WINDOWS
[510865271FDA73ACE622A4E74CEDC32E] MICROSOFT WINDOWS
[CE7E2BD9759702F635CB7F268DDD449A] MICROSOFT WINDOWS
[4943F603998D4AF78D403A3461D89508] MICROSOFT WINDOWS
[FF91879639B18FEBC6F509401686FCDD] MICROSOFT WINDOWS
[95C4DB08A740015BB3FB5659F16EF321] MICROSOFT WINDOWS
[9CDFAC4943F24A36EA741645F3E6769A] MICROSOFT WINDOWS
[E6B9D4C5BB2C8B7BA7946EC54392B14E] MICROSOFT WINDOWS
[2F76D984214FCE6DC7037A7E1094E062] MICROSOFT WINDOWS
[C0100756EBE0B8CCC9517949A0809893] MICROSOFT WINDOWS
[FD044582B0529793AD198F773F58F211] MICROSOFT WINDOWS
[76C194DFF2EDEFE3BD0C731C267BC6F8] MICROSOFT WINDOWS
[CF07A18380EBA6609F66002B82BE2E84] MICROSOFT WINDOWS
[F2E1963A78B8CCDF8B70A4FD235A7576] MICROSOFT WINDOWS
[2F304DE29F3D5F2360DF902084BB5B45] MICROSOFT WINDOWS
[7D35D1A936E3D291851A8D01D5F7AA79] MICROSOFT WINDOWS
[F179027B9FE048633A60D782E1132AAA] MICROSOFT WINDOWS
[C2610A6427166E0999CEA79A3128B915] MICROSOFT WINDOWS
[B7FEA2CC1333D4C30E58E89F682D8BCB] MICROSOFT WINDOWS
[33FB24F528B7B48AC594B95557922D6A] MICROSOFT WINDOWS
[9A0D43B4E4530C8BE34DAC3119FD5780] MICROSOFT WINDOWS
[D805E030EC7503ABD98158E0C28E1092] MICROSOFT WINDOWS
[8943C52909164A64195645C618C276BE] MICROSOFT WINDOWS
[4D5E154DE168E4A3B90F86A1966CE5D1] MICROSOFT WINDOWS
[C4229EDA839055DAB514F74D3860C23E] MICROSOFT WINDOWS
[5A632AFC20B5BCF9D33A60AA3F2B85A6] MICROSOFT WINDOWS
[6C3D8C8C991B62588C52336C5F60423C] MICROSOFT WINDOWS
[A56ABFB5B8FC315A63B599B2273B7444] MICROSOFT WINDOWS
[30FE2A17957C4D5466FBE684F83730E6] MICROSOFT WINDOWS
[5D97E67BAA0EE0AA78EDDE8BE78344B6] MICROSOFT WINDOWS
[5DA606023922A06B1C4160761EDF5AF3] MICROSOFT WINDOWS
[7841121E05EE3D540266092A6E86AE77] MICROSOFT WINDOWS
[B8ACABC8939CB50047C2BF0272B5156C] MICROSOFT WINDOWS
[C5620DB0168CA8FF93B2F378A877CCF2] MICROSOFT WINDOWS
[84B2EC0DFF47099E0F05D4C1173ADBE9] MICROSOFT WINDOWS
[38833EC9E139654135BD183DFBABC36B] MICROSOFT WINDOWS
[03BB081F55653A11C9D7DEFED559AC6E] MICROSOFT WINDOWS
[391BA0E22634DA7996EAE59FA86023C7] MICROSOFT WINDOWS
[27C0AB2D8630F45877837537367673C5] MICROSOFT WINDOWS
[25222B73D463284A85D32A56F002BD62] MICROSOFT WINDOWS
[B76160030D8254639E5FA949CE00850B] MICROSOFT WINDOWS
[8CED235DE8C2F476022E04DEA1AA786B] MICROSOFT WINDOWS
[738BF8CD600B313FBC40FCDEF5C81550] MICROSOFT WINDOWS
[8412671AADE74110F385242CD2BAEA1D] MICROSOFT WINDOWS
[0C03F3CE69034D1D76D2FF2D3E0F8A03] MICROSOFT WINDOWS
[5708BFDDB5E37B98E65D71E404138937] MICROSOFT WINDOWS
[E390C844FFD78351AD78F17B3DA9A712] MICROSOFT WINDOWS
[15BE7070232B1187345AEA3EA27811D2] MICROSOFT WINDOWS
[DB0D6123F4561125AF4CC1D24A36B9C1] MICROSOFT WINDOWS
[D2133D061486A8AD29234A21F50CEB1E] MICROSOFT WINDOWS
[21A372ADF9F00D33E98FFFAFE9BEBC6B] MICROSOFT WINDOWS
[94C01CBB754697F97452205222B0170E] MICROSOFT WINDOWS
[DC88E5876A0DE83383B9715D1F8D07BA] MICROSOFT WINDOWS
[92087EE68B06E0EC988EFC9DC44E25C9] MICROSOFT WINDOWS
[1DBE918F1EDE43C8D49B6D9A7DEA25F3] MICROSOFT WINDOWS
[BFE27E59D71DA8D4C5433AECE14C4CBF] MICROSOFT WINDOWS
[D6298429D647B5ECFB3D1A407E2C364C] MICROSOFT WINDOWS
[97BB6425C86F46C2B21E0861421B6AE5] MICROSOFT WINDOWS
[A5483EDF19986EECE8383C4BBD554996] MICROSOFT WINDOWS
[F06278B7B13D24DCC6928951D01574AA] MICROSOFT WINDOWS
[2E8DB0FC5D0A8D70ED1953A1BB8C6810] MICROSOFT WINDOWS
[70124ABD0EA0C710F1F10706E2FDE73D] MICROSOFT WINDOWS
[DBDD7F9912067B099485E1B428CCF17F] MICROSOFT WINDOWS
[62199BF94E3F7B05CF9A1DB1458423FE] MICROSOFT WINDOWS
[77C6BD7E7524D80F5BC6E1BF7E21FD14] MICROSOFT WINDOWS
[CA956BB7374CB74F5CADD56DF7039AC3] MICROSOFT WINDOWS
[CF9405B4CE6698988D4AAD36BD770B8A] MICROSOFT WINDOWS
[23A336AF5C49DED9599262297632E7B7] MICROSOFT WINDOWS
[814A312ED278D67A5AE033500065F49F] MICROSOFT WINDOWS
[5508D816271F24857897497F109E11C9] MICROSOFT WINDOWS
[CDEFD75D8A313646B7073C0BCDA5855C] MICROSOFT WINDOWS
[112EFD0CCFA2994491F4D877D2DBA582] MICROSOFT WINDOWS
[2A5D30A714704742EE8ED1F9BA7EB28F] MICROSOFT WINDOWS
[DBFDAB4925BA2D54DC7C840EADDC64EC] MICROSOFT WINDOWS
[2A798A380EE1187CBD27321C6FDA5AF0] MICROSOFT WINDOWS
[1F7FFAAE18926EE31F8B9741EA7ED6A4] MICROSOFT WINDOWS
[A0DD6042F7734F61D55D6A62D60FE498] MICROSOFT WINDOWS
[C087C499C922144DA2198EC4B1BCB90C] MICROSOFT WINDOWS
[568C5CBF9877F6B9E39D1E7CA0FF0A36] MICROSOFT WINDOWS
[C9E9A7EC257A3C7F9C76502F78D38360] MICROSOFT WINDOWS
[EAB4B99D5C81402572A410AEDB1590BE] MICROSOFT WINDOWS
[B5704DC9DC9E87DB736DB103456C0E61] MICROSOFT WINDOWS
[E184B0FF681C5AB9438DEF1DF7661F79] MICROSOFT WINDOWS
[3FAE70080E7D900A469355C85ADACBDB] MICROSOFT WINDOWS
[2785CEE75163F3C8755BE16BDBA68155] MICROSOFT WINDOWS
[B56AAB10E981BB84A6CB076CF1CE8A6A] MICROSOFT WINDOWS
[10967D62F419CA0EB6EB9DA57D91286B] MICROSOFT WINDOWS
[C76CBDE7EBE13EA8D51FDA3EF3EB22C1] MICROSOFT WINDOWS
[46DD89D6C4878D2A3BEF0DAF2ABFC639] MICROSOFT WINDOWS
[F877A1DA90103B6DF26766D7EC02D5BC] MICROSOFT WINDOWS
[18B340EC89A96A44D5C9444760F2BC63] MICROSOFT WINDOWS
[7215CE218BDEAD41B708F098258CF972] MICROSOFT WINDOWS
[50AC18BB0C9B6097076001A96D1838B5] MICROSOFT WINDOWS
[45E975E36664148A4B00E690E9B1A95C] MICROSOFT WINDOWS
[1DE50F4E710EE3447C6EB6A37ABBC407] MICROSOFT WINDOWS
[785D2832863C28491A34BBF5314949EC] MICROSOFT WINDOWS
[D80832600E08F088ACA7788A43B1BE48] MICROSOFT WINDOWS
[23261D36726D82F303B4AB867F3AF324] MICROSOFT WINDOWS
[F745EC391FDD60836D98BE15B8B8657E] MICROSOFT WINDOWS
[7A0872F5645541A1CD1879199B0489E2] MICROSOFT WINDOWS
[20FAE1EACA6E5E9D1B940D7578CA4499] MICROSOFT WINDOWS
[0E7C317DD9F8E46E0C90B88A3C536BA6] MICROSOFT WINDOWS
[136B0632385280CA2ED8F9E5D17167AB] MICROSOFT WINDOWS
[3BA9E57811BBB9C92880D7D5EF2E0685] MICROSOFT WINDOWS
[70292FA0A21FE00503386478117CA067] MICROSOFT WINDOWS
[5B1562292E8C4A96703D6EB373A24E30] MICROSOFT WINDOWS
[C6D64FDB19A235BF9D0F0CA526BA9129] MICROSOFT WINDOWS
[56C91F8EA5C83A5AFE83AACF2586B875] MICROSOFT WINDOWS
[7963A81757459412B08C6DD6A72D5FC1] MICROSOFT WINDOWS
[ECF241DFFBAA6860EBBBFC1560D1F9D3] MICROSOFT WINDOWS
[5FC3A698DE6BA51AB9709E1403F1A8DB] MICROSOFT WINDOWS
[005B5F4FF4AAB4FC3CDE47762F1616EB] MICROSOFT WINDOWS
[9FFECD197D09FF33B00D5E5B78A48146] MICROSOFT WINDOWS
[3B28A64AC649EA67E9946BDFE8EF513A] MICROSOFT WINDOWS
[FB953BD1C9B60607B9CBEE70EAFC7ABA] MICROSOFT WINDOWS
[51EC6CBC4A2B1C82A60A742D52F7B5EB] MICROSOFT WINDOWS
[4E55E08DE94A2690DED7F3035210D8B2] MICROSOFT WINDOWS
[68594C1DBB617C2F9669016DE4B5BA78] MICROSOFT WINDOWS
[8ADDEE39782CBEB49B4C3A8E9AA2DF56] MICROSOFT WINDOWS
[142CF57538077D313B4B6226D2F7AFE3] MICROSOFT WINDOWS
[2B7F843E9FD1CFD5F1DAA523B2573698] MICROSOFT WINDOWS
[3BEDBD3B2544074AB63F646618853A94] MICROSOFT WINDOWS
[4506179DB96B7FA4BF05748EAC9210D7] MICROSOFT WINDOWS
[23B5CF987C66B31053EDCF7B8ACBEEF8] MICROSOFT WINDOWS
[ED0FD37CDA820E66F4C212B7F5EE5105] MICROSOFT WINDOWS
[9507F059F53CA14F496C025AF536EE95] MICROSOFT WINDOWS
[762E1319019E9E3D61127533FA3F3A07] MICROSOFT WINDOWS
[1CCA2B375CD44A6A0389B9288F60E96D] MICROSOFT WINDOWS
[4E5BE8E17E8987912A9EBC84925A57F2] MICROSOFT WINDOWS
[5EB093335CECA0FF6B8A6A10C43F8F54] MICROSOFT WINDOWS
[1DA817E5217CD0C05DE9EE377E059705] MICROSOFT WINDOWS
[7D58DC151856B3474B160B7ABD2B1C96] MICROSOFT WINDOWS
[65C2ADC8A39C3F0D77FA611B4053EC4D] MICROSOFT WINDOWS
[F5645D54232AFA55E57927C9E0D24267] MICROSOFT WINDOWS
[0AED07F28B0B0820C9895656FE67FD1C] MICROSOFT WINDOWS
[2879BF3F6F6CE63477135F7C061B14F3] MICROSOFT WINDOWS
[92FB066DF4943FDDC571CD9EE434B390] MICROSOFT WINDOWS
[0713B90453D4D465F67DEF4A2FC8EFB5] MICROSOFT WINDOWS
[D6CE62F271345D40472A002E0AAE1C07] MICROSOFT WINDOWS
[020B510CCAE838763B7E3456C59B7BCA] MICROSOFT WINDOWS
[5443C69569DB315B5015DD8E9004071B] MICROSOFT WINDOWS
[CFE7F5E5D3FFBFE2689120630286C20C] MICROSOFT WINDOWS
[4A7C5CDA6016AA0C705B185632DA1812] MICROSOFT WINDOWS
[F3F8232DF651CFC4DBCF4C5BAB61CFCC] MICROSOFT WINDOWS
[6C294BA4F53127DF5060D3DD057A2DCA] MICROSOFT WINDOWS
[09F3F2298DDA6EBB57B12C530D35C52C] MICROSOFT WINDOWS
[DB10A49052B94A7D55B5A60E7F18CC36] MICROSOFT WINDOWS
[EE711439FD0F1293B43F0FE195E5C073] MICROSOFT WINDOWS
[E77A116240C022634504C54ACA876E62] MICROSOFT WINDOWS
[0BB8E709234B5309556A4B6A7C26ABA6] MICROSOFT WINDOWS
[03CC1E13F3FB31E17FE97392DA2AD74B] MICROSOFT WINDOWS
[9EE7998CF17E4059B9857B9C37361C2F] MICROSOFT WINDOWS
[2D443C08AAF6B917528EF0309742723E] MICROSOFT WINDOWS
[1760AE8C5D731819A4BB1CF0448AC57C] MICROSOFT WINDOWS
[DF00D18142A1A3315A264521D8E3801A] MICROSOFT WINDOWS
[6CD79B201B564037C3B3D372F3733CB2] MICROSOFT WINDOWS
[7BB985D3D68A423CE05E007B14E225AB] MICROSOFT WINDOWS
[8B6722980E0C5A06312E00BD0565B692] MICROSOFT WINDOWS
[33C24A31DF112266EE3580FAA5C6D088] MICROSOFT WINDOWS
[03FB4A01CD3AB73164FD9EF2D80171B5] MICROSOFT WINDOWS
[827088445274D2F1660750C4E71A5DEF] MICROSOFT WINDOWS
[58983BFDDDB09E21AF8F3BA3EC45FC7D] MICROSOFT WINDOWS
[1609C84BD8592CFF07225C088859480B] MICROSOFT WINDOWS
[66A0B1A55F21A275B7D5DECD295BD92A] MICROSOFT WINDOWS
[B54A80B1A307CE44C843EDD080FEA03E] MICROSOFT WINDOWS
[06518ECE4BC47D1C015AB803068877E0] MICROSOFT WINDOWS
[1C546EB2083C14C6EE79F10A16685F67] MICROSOFT WINDOWS
[06B6E9408BCE355CE4DA24FD7609F93C] MICROSOFT WINDOWS
[2CA5A7BECA0433EB10ECB4F2F03BB29F] MICROSOFT WINDOWS
[F36E3D11E41D785E13225C63E9D46261] MICROSOFT WINDOWS
[8A0A29438052FAED8A2532DA50455756] MICROSOFT WINDOWS
[304945C08A6B7C680321A01D3B21F39F] MICROSOFT WINDOWS
[0204819882A0D22DB34A1E493F622905] MICROSOFT WINDOWS
[85CA90F0AF4B92B64EF3D10812F1C810] MICROSOFT WINDOWS
[853A94B84BEDFDEA8983F1D1D2DB491F] MICROSOFT WINDOWS
[0B028C71256D0D72215FE40330B03B6B] MICROSOFT WINDOWS
[626A1593186D839054720C0D116C682E] MICROSOFT WINDOWS
[9CEB8FC77A7FBEC5ED344EEC9227A10C] MICROSOFT WINDOWS
[F225F37717C8D714B56CF21C7C1E9C34] MICROSOFT WINDOWS
[C0A22C631462B3122957FB34DC71AA85] MICROSOFT WINDOWS
[F187376E07386C4D904D33144B6C4983] MICROSOFT WINDOWS
[9ADC9B273EA9A6E0E43027D7AFB67589] MICROSOFT WINDOWS
[A90774D7D465E1085A95326FAD89B25C] MICROSOFT WINDOWS
[33E60A1BD76A877683FCD7DC93A10635] MICROSOFT WINDOWS
[6B50241793122402D063A17FFEC04C01] MICROSOFT WINDOWS
[99B827BF34A6FF47394320341898519D] MICROSOFT WINDOWS
[BCA97819779D7876B6F98C29844CF505] MICROSOFT WINDOWS
[869902A984EA4C5C6979DE16C1E6243F] MICROSOFT WINDOWS
[0D7B0A007BCC65CF6CC20E25A43D151A] MICROSOFT WINDOWS
[03BA8BB294CE2B52D9E8F64E94B4B402] MICROSOFT WINDOWS
[C1ADDE298CF5146E367CDE9C3FB0E940] MICROSOFT WINDOWS
[86F5651C8448134FE32C9B34A9273EBD] MICROSOFT WINDOWS
[8B4DC02D01400255E6CFB53C51689557] MICROSOFT WINDOWS
[9CF8E80F71544316E5F90F2B87F2350C] MICROSOFT WINDOWS
[BD627E48043957D70AA7100EC8DF0974] MICROSOFT WINDOWS
[2517371801167619C066D910B98B7EB8] MICROSOFT WINDOWS
[C05A20A037C6675E854FFE8282BE9B20] MICROSOFT WINDOWS
[BF8825D08BC235F0609CA8BBEF4E179C] MICROSOFT WINDOWS
[9E78FF24C05874B3EA4C8029879C28AC] MICROSOFT WINDOWS
[AF2979208ABA46C5DAAF254DD0919EC7] MICROSOFT WINDOWS
[F7B1BC5C7799E1247DC7CB5FD2C0F921] MICROSOFT WINDOWS
[7D824D8A2C82B4D3EA69D41D74C1394D] MICROSOFT WINDOWS
[E845A556FC6574216078A02FE53189C1] MICROSOFT WINDOWS
[70757EE40A3DFC19BFEE29E67100C708] MICROSOFT WINDOWS
[F4BA7F7899745E6D0F6C7CD0792F03E9] MICROSOFT WINDOWS
[3C662445E3B925A7519805E74317DDB9] MICROSOFT WINDOWS
[B7BB14302C5BE67EA6E79E5B48284A12] MICROSOFT WINDOWS
[12ABB40F3E15A6826DFBBDC0D9967A8C] MICROSOFT WINDOWS
[8B0E699F01BDD3B9AD741D1BD7343248] MICROSOFT WINDOWS
[D0A901EE141FE5AD78A12AE6A6378990] MICROSOFT WINDOWS
[06C66FF5CCDC2D22344A3EB761A4D38A] MICROSOFT WINDOWS
[ABA4B3C8252BE9D3A6F1E9A1D9756213] MICROSOFT WINDOWS
[CD9EA97E282A5229E66202312DC021BB] MICROSOFT WINDOWS
[3BEA0B1841B52E438F9CE0F6628E88DC] MICROSOFT WINDOWS
[BF3A1962EDDB3C139133D0B0928B3761] MICROSOFT WINDOWS
[E9D4CB72F791B11FB4599006B7A01A58] MICROSOFT WINDOWS
[2DF1213455A71E2C453575C425EEE079] MICROSOFT WINDOWS
[BA8C8398B3DA1BCC1737FBD9CA7526F0] MICROSOFT WINDOWS
[0714DD5FEC336CBFC3E8C0B2C1A25A95] MICROSOFT WINDOWS
[92A0CB8C13014D9589855A1B1FAE789E] MICROSOFT WINDOWS
[C40BC5164317312AEFC3A37376B696E6] MICROSOFT WINDOWS
[5CE5CBC5A85BB319F278737BB20054AE] MICROSOFT WINDOWS
[77B25A61B3AEC06EA58035C9B9CAD9FE] MICROSOFT WINDOWS
[A9C18F7D907645183D6194E1A85AB7DE] MICROSOFT WINDOWS
[76E43A1AABB4CEB6DB83224F19CC4681] MICROSOFT WINDOWS
[E2C1DB0AB6F9C3C592BC3540687389C4] MICROSOFT WINDOWS
[697B0D4078F0F70AC4829B4EBA0538B1] MICROSOFT WINDOWS
[4035C0ECBC2FA54845DBA9D2D732978D] MICROSOFT WINDOWS
[29C5305644CA39922991028058841D78] MICROSOFT WINDOWS
[09C7796D31DCFF582064829CB59E35BF] MICROSOFT WINDOWS
[82BE61D6660F4259606371E73027AAEA] MICROSOFT WINDOWS
[D41B7D3152E4ED1A32FA8939A828BAF7] MICROSOFT WINDOWS
[DE4E84C2E16362423B993A5E4FBB6B7B] MICROSOFT WINDOWS
[6A775E36973111923169368CC7299E30] MICROSOFT WINDOWS
[61A61ED80D52421DAE4F6E32137508B4] MICROSOFT WINDOWS
[92419F3B74C6C3D7304B7665DA984552] MICROSOFT WINDOWS
[84626BB521ACD1B5DAA81EDAC1D67F06] MICROSOFT WINDOWS
[00CBFE7A6862AF10624F4C9F6B854718] MICROSOFT WINDOWS
[315A9AA7E6FA02B3AED5814E0D2BF263] MICROSOFT WINDOWS
[D490407C13EDD902F95D29CF82478E73] MICROSOFT WINDOWS
[3EFA1DCA6A3731ECC84F024B0DF17CEB] MICROSOFT WINDOWS
[56A1AC9C2DB9B440743C7F13DCEDD4F1] MICROSOFT WINDOWS
[B4F8ED117D5120009972A470AF4FA323] MICROSOFT WINDOWS
[48FB3FFACCD2194CDD6B04CE84361C29] MICROSOFT WINDOWS
[ADAD15298AD0D593FAF61BB89D538D73] MICROSOFT WINDOWS
[1CFF7C3900CDF1C9762558548BFA1C2A] MICROSOFT WINDOWS
[60290713ED848D607A7F3CE5DD2F02A0] MICROSOFT WINDOWS
[902D7BA5FADD42DB2DC6C7DD5F9C0CF7] MICROSOFT WINDOWS
[32308032F6D475E9AE0564F8713A4DFE] MICROSOFT WINDOWS
[5F69A7DE728668CD6A80FCB0EB3B7EB2] MICROSOFT WINDOWS
[9AD74ADD767D1FF755F52E4F5778C641] MICROSOFT WINDOWS
[9266191829E944E4E7F474C9A8FC3947] MICROSOFT WINDOWS
[42DCAA6173FC1447A298637C16C973FC] MICROSOFT WINDOWS
[493C50B1A37B45B2A6600D95B4884505] MICROSOFT WINDOWS
[D0B59C5A711EB8E9F818023D81B226CC] MICROSOFT WINDOWS
[0E54CEC76C044C834C0572DCD5941E2E] MICROSOFT WINDOWS
[6D66AFEF886392CE79C1A61F3AF835A1] MICROSOFT WINDOWS
[78AC970D7765FD11580FF67DF518197B] MICROSOFT WINDOWS
[8A124E89D984F07E66FF8EBDDA3807CD] MICROSOFT WINDOWS
[052495BF199C5369F9C86BF9B26F2A3A] MICROSOFT WINDOWS
[7D4652B6413FE0EB85D2D7575F8E3C71] MICROSOFT WINDOWS
[7F687723C96A7CA799C53FF09C157B7B] MICROSOFT WINDOWS
[B8BCBCFCFBFF8E57CBEC77F3A9E4296E] MICROSOFT WINDOWS
[0781DE74790BDBB9A7B9EF6CAA62B4E0] MICROSOFT WINDOWS
[F2C1700742455B474C0CA745A357CE94] MICROSOFT WINDOWS
[7104CF2E111A65AC4F5C16690C63C481] MICROSOFT WINDOWS
[208B18B92C068377F5EB21CD72FBC993] MICROSOFT WINDOWS
[AA627C814E39C95897C31511B1B709E7] MICROSOFT WINDOWS
[A100B0BD33B76D71F663EA93931DF062] MICROSOFT WINDOWS
[80F2A1191FF909612F6B2149BC34D25D] MICROSOFT WINDOWS
[C222443BA793F4C2DD92AF5B20EF0820] MICROSOFT WINDOWS
[A5E88A4F900044CAA4E5F3A5F283E703] MICROSOFT WINDOWS
[E0C9BFCDEC97D66F2ADAF356967508F9] MICROSOFT WINDOWS
[CC037C3D8F265E65F7200D9665D653FD] MICROSOFT WINDOWS
[D43032BCCDA09360AA5BAAFF3039AEA6] MICROSOFT WINDOWS
[CAC54AA1F714C40D0FB99E790A2DD5B9] MICROSOFT WINDOWS
[9E012753342DD7F95B7A07104E49C084] MICROSOFT WINDOWS
[5D8056CE269CDC09733F228883A8279D] MICROSOFT WINDOWS
[3F361BE7140B83974AB4FA9B7E09D0DC] MICROSOFT WINDOWS
===