------------------------------------------------------------------------------------------- TaskList /V /FO:CSV /NH (processes running): "aerohost.exe","1336","Services","0","372 K","Unknown","NT AUTHORITY\SYSTEM","0:06:17","N/A" "ClassicStartMenu.exe","6488","Console","9","2,412 K","Running","NoelC4\NoelC","0:00:00","StartHookWindow" "CLOCK32.EXE","3304","Console","9","1,796 K","Running","NoelC4\NoelC","0:00:00","Clock" "cmd.exe","2616","Console","9","2,652 K","Running","NoelC4\NoelC","0:00:00","Log Sys Info" "conhost.exe","8004","Console","9","5,548 K","Running","NoelC4\NoelC","0:00:00","OleMainThreadWndName" "csrss.exe","11028","Console","9","5,172 K","Running","NT AUTHORITY\SYSTEM","0:01:43","N/A" "csrss.exe","648","Services","0","1,888 K","Unknown","NT AUTHORITY\SYSTEM","0:00:03","N/A" "dasHost.exe","1784","Services","0","3,288 K","Unknown","NT AUTHORITY\LOCAL SERVICE","0:00:00","N/A" "dwm.exe","13860","Console","9","32,788 K","Running","Window Manager\DWM-9","0:17:37","DWM Notification Window" "explorer.exe","14480","Console","9","96,372 K","Running","NoelC4\NoelC","0:03:16","N/A" "explorer.exe","3052","Console","9","33,864 K","Not Responding","NoelC4\NoelC","0:00:01","OLEChannelWnd" "FamItrfc.Exe","3892","Console","9","2,344 K","Running","NT AUTHORITY\SYSTEM","0:00:00","N/A" "FamItrfc.Exe","9096","Console","9","4,356 K","Running","NoelC4\NoelC","0:09:42","N/A" "gsort.exe","2956","Console","9","5,268 K","Unknown","NoelC4\NoelC","0:00:00","N/A" "lsass.exe","764","Services","0","21,544 K","Unknown","NT AUTHORITY\SYSTEM","0:05:36","N/A" "mainserv.exe","1680","Services","0","3,812 K","Unknown","NT AUTHORITY\SYSTEM","0:00:29","N/A" "NVDisplay.Container.exe","10268","Services","0","4,076 K","Unknown","NT AUTHORITY\SYSTEM","0:00:00","N/A" "nvxdsync.exe","15288","Console","9","10,448 K","Running","NT AUTHORITY\SYSTEM","0:00:01","NvSvc" "OutlookPasswordWorkaround.exe","5532","Console","9","3,144 K","Running","NoelC4\NoelC","0:00:00","WBT - OutlookPasswordWorkaround.exe" "rserver3.exe","1664","Services","0","6,956 K","Unknown","NT AUTHORITY\SYSTEM","0:06:04","N/A" "services.exe","756","Services","0","5,788 K","Unknown","NT AUTHORITY\SYSTEM","0:20:12","N/A" "ShellFolderFixUI.exe","6992","Console","9","1,848 K","Running","NoelC4\NoelC","0:00:00","ShellFolderFix" "Skype.exe","14532","Console","9","104,884 K","Running","NoelC4\NoelC","0:07:19","N/A" "smss.exe","532","Services","0","232 K","Unknown","NT AUTHORITY\SYSTEM","0:00:42","N/A" "spoolsv.exe","1328","Services","0","11,536 K","Unknown","NT AUTHORITY\SYSTEM","0:00:09","N/A" "svchost.exe","1052","Services","0","21,636 K","Unknown","NT AUTHORITY\LOCAL SERVICE","0:00:12","N/A" "svchost.exe","1100","Services","0","15,384 K","Unknown","NT AUTHORITY\SYSTEM","0:00:36","N/A" "svchost.exe","1200","Services","0","27,064 K","Unknown","NT AUTHORITY\NETWORK SERVICE","0:11:26","N/A" "svchost.exe","1360","Services","0","34,592 K","Unknown","NT AUTHORITY\LOCAL SERVICE","0:01:38","N/A" "svchost.exe","176","Services","0","35,836 K","Unknown","NT AUTHORITY\SYSTEM","0:00:52","N/A" "svchost.exe","1776","Services","0","9,036 K","Unknown","NT AUTHORITY\LOCAL SERVICE","0:00:06","N/A" "svchost.exe","2124","Services","0","820 K","Unknown","NT AUTHORITY\NETWORK SERVICE","0:00:00","N/A" "svchost.exe","2564","Services","0","8,432 K","Unknown","NT AUTHORITY\LOCAL SERVICE","0:00:01","N/A" "svchost.exe","840","Services","0","10,088 K","Unknown","NT AUTHORITY\SYSTEM","0:05:49","N/A" "svchost.exe","872","Services","0","25,160 K","Unknown","NT AUTHORITY\LOCAL SERVICE","0:04:17","N/A" "svchost.exe","880","Services","0","12,752 K","Unknown","NT AUTHORITY\NETWORK SERVICE","0:06:04","N/A" "System Idle Process","0","Services","0","4 K","Unknown","NT AUTHORITY\SYSTEM","8299:10:09","N/A" "System","4","Services","0","157,528 K","Unknown","N/A","10:46:32","N/A" "taskhostex.exe","6148","Console","9","18,476 K","Running","NoelC4\NoelC","0:00:08","Task Host Window" "tasklist.exe","5728","Console","9","7,180 K","Unknown","NoelC4\NoelC","0:00:00","N/A" "TortoiseProc.exe","11516","Console","9","28,020 K","Running","NoelC4\NoelC","0:00:02","TortoiseSVN Project Monitor" "TSVNCache.exe","6836","Console","9","63,556 K","Running","NoelC4\NoelC","0:01:56","TSVNCacheWindow" "vmware-authd.exe","1904","Services","0","3,472 K","Unknown","NT AUTHORITY\SYSTEM","0:03:39","N/A" "vmware-usbarbitrator64.exe","1112","Services","0","1,848 K","Unknown","NT AUTHORITY\SYSTEM","0:00:00","N/A" "Windows10FirewallControl.exe","13580","Console","9","8,384 K","Running","NoelC4\NoelC","0:00:01"," Events (click to manage, drag to move): "Windows10FirewallService.exe","1476","Services","0","12,312 K","Unknown","NT AUTHORITY\SYSTEM","0:00:51","N/A" "wininit.exe","708","Services","0","980 K","Unknown","NT AUTHORITY\SYSTEM","0:00:00","N/A" "winlogon.exe","10920","Console","9","1,736 K","Unknown","NT AUTHORITY\SYSTEM","0:00:00","N/A" "WizMouse.exe","6520","Console","9","776 K","Running","NoelC4\NoelC","0:00:23","N/A" "WmiPrvSE.exe","3572","Services","0","6,536 K","Unknown","NT AUTHORITY\NETWORK SERVICE","0:00:00","N/A" NOELC4: Allowed IPv4 ------ TCP download.microsoft.com/96.7.192.9:443(50204) App - Visual Studio 2017 vs_installerservice.exe -W81- Visual Studio/UPD download.microsoft.com/download.microsoft.com/download.microsof" ------------------------------------------------------------------------------------------- TaskList /SVC /FO:CSV /NH (services running): "lsass.exe","764","EFS,KeyIso,SamSs,VaultSvc" "mainserv.exe","1680","APC UPS Service" "NVDisplay.Container.exe","10268","NVDisplay.ContainerLocalSystem" "rserver3.exe","1664","RServer3" "spoolsv.exe","1328","Spooler" "svchost.exe","1052","EventSystem,FontCache,netprofm,nsi,WdiServiceHost,WinHttpAutoProxySvc" "svchost.exe","1100","AudioEndpointBuilder,DeviceAssociationService,PcaSvc,TrkWks,UmRdpService,WdiSystemHost,wudfsvc" "svchost.exe","1200","CryptSvc,Dnscache,LanmanWorkstation,NlaSvc,TermService" "svchost.exe","1360","BFE,DPS" "svchost.exe","176","AeLookupSvc,AppMgmt,BITS,CertPropSvc,IKEEXT,iphlpsvc,LanmanServer,MMCSS,ProfSvc,Schedule,seclogon,SENS,SessionEnv,ShellHWDetection,Themes,Winmgmt" "svchost.exe","1776","stisvc" "svchost.exe","2124","PolicyAgent" "svchost.exe","2564","SSDPSRV,upnphost,wcncsvc" "svchost.exe","840","BrokerInfrastructure,DcomLaunch,LSM,PlugPlay,Power,SystemEventsBroker" "svchost.exe","872","Audiosrv,Dhcp,EventLog,lmhosts,Wcmsvc,wscsvc" "svchost.exe","880","RpcEptMapper,RpcSs" "vmware-authd.exe","1904","VMAuthdService" "vmware-usbarbitrator64.exe","1112","VMUSBArbService" "Windows10FirewallService.exe","1476","Windows10FirewallService" ------------------------------------------------------------------------------------------- TaskList /M /FO:CSV /NH (modules loaded): "aerohost.exe","1336","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,ADVAPI32.dll,msvcrt.dll,sechost.dll,RPCRT4.dll,CRYPTBASE.DLL,SspiCli.dll,bcryptPrimitives.dll,imagehlp.dll,DWMGlass.dll,SHLWAPI.dll,COMCTL32.dll,combase.dll,USER32.dll,GDI32.dll,UxThemeSignatureBypass64.dll,UxTheme.dll,MSIMG32.dll,ole32.dll,dbghelp.dll,ntmarta.dll,kernel.appcore.dll,WTSAPI32.dll,WINSTA.dll" "ClassicStartMenu.exe","6488","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,USER32.dll,ADVAPI32.dll,SHELL32.dll,ole32.dll,ClassicStartMenuDLL.dll,SHLWAPI.dll,GDI32.dll,msvcrt.dll,sechost.dll,RPCRT4.dll,combase.dll,COMCTL32.dll,UxTheme.dll,WTSAPI32.dll,Secur32.dll,MSIMG32.dll,NETAPI32.dll,dwmapi.dll,POWRPROF.dll,OLEACC.dll,WINMM.dll,PROPSYS.dll,COMDLG32.dll,OLEAUT32.dll,WININET.dll,WINTRUST.dll,CRYPT32.dll,SspiCli.dll,netutils.dll,srvcli.dll,wkscli.dll,WINMMBASE.dll,SHCORE.DLL,iertutil.dll,USERENV.dll,MSASN1.dll,cfgmgr32.dll,DEVOBJ.dll,profapi.dll,LOGONCLI.DLL,IMM32.DLL,MSCTF.dll,UxThemeSignatureBypass64.dll,dbghelp.dll,kernel.appcore.dll,CRYPTBASE.dll,bcryptPrimitives.dll,SETUPAPI.dll,clbcatq.dll" "CLOCK32.EXE","3304","ntdll.dll,wow64.dll,wow64win.dll,wow64cpu.dll" "cmd.exe","2616","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,msvcrt.dll,cmdext.dll,ADVAPI32.dll,sechost.dll,RPCRT4.dll,SspiCli.dll" "conhost.exe","8004","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,GDI32.dll,USER32.dll,msvcrt.dll,IMM32.dll,OLEAUT32.dll,combase.dll,MSCTF.dll,RPCRT4.dll,SspiCli.dll,sechost.dll,UxThemeSignatureBypass64.dll,UxTheme.dll,MSIMG32.dll,ole32.dll,ADVAPI32.dll,dbghelp.dll,dwmapi.dll,comctl32.DLL,kernel.appcore.dll,CRYPTBASE.dll,bcryptPrimitives.dll,SHCORE.dll" "dasHost.exe","1784","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,msvcrt.dll,RPCRT4.dll,sechost.dll,cfgmgr32.dll,SspiCli.dll,CRYPTBASE.dll,bcryptPrimitives.dll,dafupnp.dll,OLEAUT32.dll,IPHLPAPI.DLL,WS2_32.dll,bcrypt.dll,combase.dll,WINHTTP.dll,SSDPAPI.dll,deviceassociation.dll,NSI.dll,WINNSI.DLL,kernel.appcore.dll,DAFWSD.dll,CRYPTSP.dll,wsdapi.dll,FirewallAPI.dll,webservices.dll,CRYPT32.dll,MSASN1.dll,dhcpcsvc6.DLL,dhcpcsvc.DLL,mswsock.dll,powrprof.dll,rsaenh.dll,clbcatq.dll,msxml6.dll,webio.dll,DNSAPI.dll,netprofm.dll,user32.dll,GDI32.dll,UxThemeSignatureBypass64.dll,UxTheme.dll,MSIMG32.dll,ole32.dll,ADVAPI32.dll,dbghelp.dll,npmproxy.dll,XmlLite.dll,MLANG.dll" "dwm.exe","13860","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,apphelp.dll,msvcrt.dll,USER32.dll,GDI32.dll,IMM32.dll,dwmredir.dll,dwmcore.dll,MSCTF.dll,dcomp.dll,UxThemeSignatureBypass64.dll,UxTheme.dll,MSIMG32.dll,ole32.dll,ADVAPI32.dll,combase.dll,RPCRT4.dll,sechost.dll,SspiCli.dll,dbghelp.dll,WindowsCodecs.dll,avrt.dll,d3d11.dll,dxgi.dll,Shell32.dll,SHLWAPI.dll,SHCORE.dll,nvwgf2umx.dll,WINMM.dll,VERSION.dll,bcrypt.dll,WINMMBASE.dll,cfgmgr32.dll,DEVOBJ.dll,uDWM.dll,kernel.appcore.dll,CRYPTBASE.dll,bcryptPrimitives.dll,clbcatq.dll,UIAnimation.dll,d2d1.dll,XmlLite.dll,powrprof.dll,DWMGlass.dll,COMCTL32.dll,dwmapi.dll,dbghelp.dll,WTSAPI32.dll,WINSTA.dll,d3d10warp.dll" "explorer.exe","14480","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,apphelp.dll,msvcrt.dll,OLEAUT32.dll,combase.dll,powrprof.dll,USERENV.dll,advapi32.dll,USER32.dll,GDI32.dll,SHCORE.dll,SHLWAPI.dll,SHELL32.dll,UxTheme.dll,dwmapi.dll,DUser.dll,DUI70.dll,TWINAPI.dll,d3d11.dll,dcomp.dll,SspiCli.dll,sechost.dll,PROPSYS.dll,RPCRT4.dll,SLC.dll,profapi.dll,dxgi.dll,sppc.dll,IMM32.DLL,MSCTF.dll,UxThemeSignatureBypass64.dll,MSIMG32.dll,ole32.dll,dbghelp.dll,kernel.appcore.dll,CRYPTBASE.dll,bcryptPrimitives.dll,clbcatq.dll,WINSTA.dll,Bcp47Langs.dll,IDStore.dll,SAMLIB.dll,SETTINGSYNCPOLICY.dll,Comctl32.dll,SndVolSSO.DLL,HID.DLL,MMDevApi.dll,DEVOBJ.dll,cfgmgr32.dll,OLEACC.dll,D3D10Warp.dll,twinui.dll,twinapi.appcore.dll,XmlLite.dll,Windows.UI.Immersive.dll,ntmarta.dll,CRYPTSP.dll,rsaenh.dll,bcrypt.dll,actxprxy.dll,windowscodecs.dll,VERSION.dll,WINMM.dll,COMDLG32.dll,WINMMBASE.dll,explorerframe.dll,windows.immersiveshell.serviceprovider.dll,samcli.dll,netutils.dll,WLDP.DLL,WTSAPI32.dll,PhotoMetadataHandler.dll,twinui.appcore.dll,wpncore.dll,dwrite.dll,UIAnimation.dll,nvwgf2umx.dll,wlidprov.dll,thumbcache.dll,Windows.Networking.Connectivity.dll,InputSwitch.dll,stobject.dll,BatMeter.dll,es.dll,prnfldr.dll,WINSPOOL.DRV,DeviceSetupManagerAPI.dll,wevtapi.dll,atlthunk.dll,dxp.dll,gdiplus.dll,SETUPAPI.dll,SHDOCVW.dll,WININET.dll,iertutil.dll,Syncreg.dll,Actioncenter.dll,CRYPT32.dll,MSASN1.dll,Secur32.dll,ehSSO.dll,wpdshserviceobj.dll,PortableDeviceTypes.dll,PortableDeviceApi.dll,WINTRUST.dll,SettingMonitor.dll,SqmApi.dll,srchadmin.dll,CSCAPI.dll,SyncCenter.dll,imapi2.dll,sxs.dll,AUDIOSES.DLL,hgcpl.dll,provsvc.dll,WS2_32.dll,NSI.dll,npmproxy.dll,netprofm.dll,wkscli.dll,AltTab.dll,authui.dll,pnidui.dll,IPHLPAPI.DLL,WINNSI.DLL,NetworkStatus.dll,imagehlp.dll,ncrypt.dll,NTASN1.dll,gpapi.dll,ClassicStartMenuDLL.dll,NETAPI32.dll,srvcli.dll,LOGONCLI.DLL,bthprops.cpl,BluetoothApis.dll,dhcpcsvc6.DLL,dhcpcsvc.DLL,fontext.dll,MPR.dll,DeviceCenter.dll,ntshrui.dll,ieframe.dll,LINKINFO.dll,Windows.UI.Search.dll,urlmon.dll,wincorlib.DLL,WSClient.dll,UIAutomationCore.DLL,WSShared.dll,WSSync.dll,wer.dll,elscore.dll,MrmCoreR.dll,Windows.UI.dll,NInput.dll,Windows.UI.Xaml.dll,wintypes.dll,searchfolder.dll,StructuredQuery.dll,d2d1.dll,MsftEdit.dll,tiptsf.dll,TortoiseOverlays.dll,TortoiseStub.dll,TortoiseSVN.dll,libsvn_tsvn.dll,libapr_tsvn.dll,intl3_tsvn.dll,MSVCP140.dll,VCRUNTIME140.dll,api-ms-win-crt-runtime-l1-1-0.dll,api-ms-win-crt-environment-l1-1-0.dll,api-ms-win-crt-string-l1-1-0.dll,api-ms-win-crt-multibyte-l1-1-0.dll,api-ms-win-crt-heap-l1-1-0.dll,api-ms-win-crt-stdio-l1-1-0.dll,api-ms-win-crt-convert-l1-1-0.dll,api-ms-win-crt-utility-l1-1-0.dll,api-ms-win-crt-time-l1-1-0.dll,libaprutil_tsvn.dll,libsasl.dll,api-ms-win-crt-locale-l1-1-0.dll,api-ms-win-crt-conio-l1-1-0.dll,api-ms-win-crt-filesystem-l1-1-0.dll,MSWSOCK.dll,api-ms-win-crt-math-l1-1-0.dll,WLDAP32.dll,ucrtbase.DLL,crshhndl.dll,MLANG.dll,IconCodecService.dll,fxsst.dll,FXSAPI.dll,FXSRESM.DLL,msiltcfg.dll,msi.dll,ShellFolderFix.dll,pcacli.dll,sfc_os.dll,wscinterop.dll,WSCAPI.dll,wscui.cpl,DPAPI.dll,werconcpl.dll,framedynos.dll,wercplsupport.dll,hcproviders.dll,ieproxy.dll,drprov.dll,ntlanman.dll,davclnt.dll,DAVHLPR.dll,gameux.dll,appwiz.cpl,osbaseln.dll,netjoin.dll,oledb32.dll,MSDART.DLL,comsvcs.dll,AUTHZ.dll,tquery.dll,DEVRTL.dll,sfc.dll,SendToClipboardAsNameShellExt.dll,nvapi64.dll,SendToFolderShellExt.dll,dlnashext.dll,DevDispItemProvider.dll,CHARTV.dll,NetworkExplorer.dll,timedate.cpl,ATL.DLL,nvshext.dll,twext.dll,mbshlext.dll,BCShellEx64.dll,syncui.dll,SYNCENG.dll,StartMenuHelper64.dll,nv3dappshext.dll,acppage.dll,zipfldr.dll,PlayToDevice.dll,EhStorAPI.dll" "explorer.exe","3052","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,apphelp.dll,msvcrt.dll,OLEAUT32.dll,combase.dll,powrprof.dll,USERENV.dll,advapi32.dll,USER32.dll,GDI32.dll,SHCORE.dll,SHLWAPI.dll,SHELL32.dll,UxTheme.dll,dwmapi.dll,DUser.dll,DUI70.dll,TWINAPI.dll,d3d11.dll,dcomp.dll,SspiCli.dll,sechost.dll,PROPSYS.dll,RPCRT4.dll,SLC.dll,profapi.dll,dxgi.dll,sppc.dll,IMM32.DLL,MSCTF.dll,UxThemeSignatureBypass64.dll,MSIMG32.dll,ole32.dll,dbghelp.dll,kernel.appcore.dll,CRYPTBASE.dll,bcryptPrimitives.dll,clbcatq.dll,explorerframe.dll,CRYPTSP.dll,rsaenh.dll,bcrypt.dll,actxprxy.dll,comctl32.dll,sxs.dll,WindowsCodecs.dll,Windows.Globalization.dll,Bcp47Langs.dll,globinputhost.dll,ShellFolderFix.dll,urlmon.dll,iertutil.dll,WININET.dll,WINTRUST.dll,CRYPT32.dll,netutils.dll,srvcli.dll,wkscli.dll,MSASN1.dll,cfgmgr32.dll,DEVOBJ.dll,Secur32.dll,UIRibbonRes.dll,thumbcache.dll,SETUPAPI.dll,atlthunk.dll,MPR.dll,drprov.dll,WINSTA.dll,ntlanman.dll,davclnt.dll,DAVHLPR.dll,cscapi.dll,dlnashext.dll,PlayToDevice.dll,WS2_32.dll,NSI.dll,TortoiseOverlays.dll,NetworkExplorer.dll,TortoiseStub.dll,TortoiseSVN.dll,VERSION.dll,libsvn_tsvn.dll,libapr_tsvn.dll,intl3_tsvn.dll,MSVCP140.dll,VCRUNTIME140.dll,api-ms-win-crt-runtime-l1-1-0.dll,api-ms-win-crt-environment-l1-1-0.dll,api-ms-win-crt-string-l1-1-0.dll,api-ms-win-crt-multibyte-l1-1-0.dll,api-ms-win-crt-heap-l1-1-0.dll,api-ms-win-crt-stdio-l1-1-0.dll,api-ms-win-crt-convert-l1-1-0.dll,api-ms-win-crt-utility-l1-1-0.dll,api-ms-win-crt-time-l1-1-0.dll,libaprutil_tsvn.dll,libsasl.dll,api-ms-win-crt-locale-l1-1-0.dll,api-ms-win-crt-conio-l1-1-0.dll,api-ms-win-crt-filesystem-l1-1-0.dll,MSWSOCK.dll,api-ms-win-crt-math-l1-1-0.dll,WLDAP32.dll,ucrtbase.DLL,DevDispItemProvider.dll,crshhndl.dll,ntshrui.dll,PortableDeviceApi.dll,EhStorAPI.dll,WTSAPI32.dll,ntmarta.dll,provsvc.dll" "FamItrfc.Exe","3892","ntdll.dll,wow64.dll,wow64win.dll,wow64cpu.dll" "FamItrfc.Exe","9096","ntdll.dll,wow64.dll,wow64win.dll,wow64cpu.dll" "gsort.exe","5044","ntdll.dll,wow64.dll,wow64win.dll,wow64cpu.dll" "lsass.exe","764","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,RPCRT4.dll,SspiSrv.dll,SspiCli.dll,sechost.dll,lsasrv.dll,msvcrt.dll,WS2_32.dll,cfgmgr32.dll,MSASN1.dll,NSI.dll,samsrv.dll,bcrypt.dll,ncrypt.dll,NTASN1.dll,msprivs.DLL,netjoin.dll,negoexts.DLL,CRYPTBASE.dll,cryptdll.dll,bcryptPrimitives.dll,kerberos.DLL,CRYPTSP.dll,mswsock.dll,msv1_0.DLL,netlogon.DLL,DNSAPI.dll,logoncli.dll,powrprof.dll,USERENV.dll,advapi32.dll,profapi.dll,tspkg.DLL,pku2u.DLL,livessp.DLL,rsaenh.dll,wdigest.DLL,schannel.DLL,CRYPT32.dll,efslsaext.dll,dpapisrv.dll,scecli.DLL,netutils.dll,winsta.dll,efssvc.dll,EFSCORE.dll,AUTHZ.dll,EFSUTIL.dll,gpapi.dll,WTSAPI32.dll,wevtapi.dll,IPHLPAPI.DLL,WINNSI.DLL,wkscli.dll,fveapi.dll,bcd.dll,FVECERTS.dll,combase.dll,DPAPI.DLL,ncryptsslp.dll,ncryptprov.dll,dssenh.dll,DSPARSE.dll,certpoleng.dll,samcli.dll,SAMLIB.dll,vaultsvc.dll,keyiso.dll,secur32.dll,WLDAP32.dll" "mainserv.exe","1680","ntdll.dll,wow64.dll,wow64win.dll,wow64cpu.dll" "NVDisplay.Container.exe","10268","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,USER32.dll,SHELL32.dll,ADVAPI32.dll,GDI32.dll,msvcrt.dll,combase.dll,SHLWAPI.dll,sechost.dll,RPCRT4.dll,SspiCli.dll,UxThemeSignatureBypass64.dll,UxTheme.dll,MSIMG32.dll,ole32.dll,dbghelp.dll,shcore.dll,NvXDCore.dll,WTSAPI32.dll,USERENV.dll,SETUPAPI.dll,OLEAUT32.dll,profapi.dll,CFGMGR32.dll,WINSTA.dll,kernel.appcore.dll,CRYPTBASE.dll,bcryptPrimitives.dll,clbcatq.dll,CRYPTSP.dll,rsaenh.dll,bcrypt.dll,nvxdbat.dll,apphelp.dll,DEVOBJ.dll,WINTRUST.dll,CRYPT32.dll,MSASN1.dll" "nvxdsync.exe","15288","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,RPCRT4.dll,SHLWAPI.dll,ADVAPI32.dll,ole32.dll,OLEAUT32.dll,SspiCli.dll,msvcrt.dll,combase.dll,USER32.dll,GDI32.dll,sechost.dll,IMM32.DLL,MSCTF.dll,UxThemeSignatureBypass64.dll,UxTheme.dll,MSIMG32.dll,dbghelp.dll,kernel.appcore.dll,CRYPTBASE.dll,bcryptPrimitives.dll,clbcatq.dll,NVSVC64.DLL,mscms.dll,VERSION.dll,WTSAPI32.dll,COMCTL32.dll,USERENV.dll,POWRPROF.dll,SETUPAPI.dll,PSAPI.DLL,dwmapi.dll,profapi.dll,CFGMGR32.dll,CRYPTSP.dll,nvapi64.dll,SHELL32.dll,rsaenh.dll,bcrypt.dll,SHCORE.dll,NVSVCR.DLL,nvxdapix.dll,NvUI.dll,gdiplus.dll,WINMM.dll,COMCTL32.dll,COMDLG32.dll,WINSPOOL.DRV,OLEACC.dll,WINMMBASE.dll,DEVOBJ.dll,nvumdshimx.dll,nvxdbat.dll,nvxdplcy.dll,WINSTA.dll,WINTRUST.dll,CRYPT32.dll,MSASN1.dll,NvSmartMax64.dll,ntmarta.dll" "OutlookPasswordWorkaround.exe","5532","ntdll.dll,wow64.dll,wow64win.dll,wow64cpu.dll" "rserver3.exe","1664","ntdll.dll,wow64.dll,wow64win.dll,wow64cpu.dll" "sed.exe","15064","ntdll.dll,wow64.dll,wow64win.dll,wow64cpu.dll" "ShellFolderFixUI.exe","6992","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,UxTheme.dll,USER32.dll,GDI32.dll,MSIMG32.dll,COMDLG32.dll,WINSPOOL.DRV,ADVAPI32.dll,SHELL32.dll,COMCTL32.dll,SHLWAPI.dll,ole32.dll,OLEAUT32.dll,gdiplus.dll,WININET.dll,IMM32.dll,WINMM.dll,msvcrt.dll,combase.dll,sechost.dll,RPCRT4.dll,iertutil.dll,USERENV.dll,MSCTF.dll,WINMMBASE.dll,SspiCli.dll,profapi.dll,cfgmgr32.dll,DEVOBJ.dll,SHCORE.DLL,UxThemeSignatureBypass64.dll,dbghelp.dll,dwmapi.dll,ShellFolderFix.dll,kernel.appcore.dll,CRYPTBASE.dll,bcryptPrimitives.dll" "Skype.exe","14532","ntdll.dll,wow64.dll,wow64win.dll,wow64cpu.dll" "spoolsv.exe","1328","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,USER32.dll,msvcrt.dll,sechost.dll,RPCRT4.dll,DNSAPI.dll,powrprof.dll,GDI32.dll,SspiCli.dll,WS2_32.dll,NSI.dll,UxThemeSignatureBypass64.dll,UxTheme.dll,MSIMG32.dll,ole32.dll,ADVAPI32.dll,combase.dll,dbghelp.dll,kernel.appcore.dll,CRYPTBASE.dll,bcryptPrimitives.dll,mswsock.dll,IPHLPAPI.DLL,WINNSI.DLL,rasadhlp.dll,fwpuclnt.dll,localspl.dll,CRYPT32.dll,srvcli.dll,cfgmgr32.dll,CRYPTSP.dll,SPOOLSS.DLL,WINTRUST.dll,SETUPAPI.dll,bcrypt.dll,MSASN1.dll,winspool.drv,PrintIsolationProxy.dll,AdobePDF.dll,SHELL32.dll,SHLWAPI.dll,hpinkstsBB11LM.dll,OLEAUT32.dll,USERENV.dll,PSAPI.DLL,VERSION.dll,Secur32.dll,profapi.dll,HPDiscoPMBB11.dll,wsnmp32.dll,WININET.dll,iertutil.dll,FXSMON.DLL,tcpmon.dll,snmpapi.dll,usbmon.dll,DEVOBJ.dll,WSDMon.dll,wsdapi.dll,webservices.dll,FirewallAPI.dll,clbcatq.dll,FunDisc.dll,XmlLite.dll,fdPnp.dll,ATL.DLL,WSDCHNGR.DLL,deviceassociation.dll,msxml6.dll,drvstore.dll,dhcpcsvc6.DLL,dhcpcsvc.DLL,winprint.dll,gpapi.dll,DSROLE.dll,DEVRTL.dll,SPINF.dll,win32spl.dll,inetpp.dll,WINSTA.dll,rsaenh.dll,cscapi.dll,netutils.dll,WTSAPI32.dll,WSDPrintProxy.dll,WINHTTP.dll,webio.dll,HTTPAPI.dll,UNIDRVUI.DLL,twinapi.appcore.dll,shcore.dll,UNIDRV.DLL,mscms.dll,FXSRESM.DLL,hpvplui09.dll" "svchost.exe","1052","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,sechost.dll,RPCRT4.dll,SspiCli.dll,combase.dll,msvcrt.dll,kernel.appcore.dll,CRYPTBASE.dll,bcryptPrimitives.dll,user32.dll,GDI32.dll,UxThemeSignatureBypass64.dll,UxTheme.dll,MSIMG32.dll,ole32.dll,ADVAPI32.dll,dbghelp.dll,es.dll,CRYPTSP.dll,rsaenh.dll,bcrypt.dll,clbcatq.dll,OLEAUT32.dll,fntcache.dll,nsisvc.dll,NSI.dll,winhttp.dll,WS2_32.dll,mswsock.dll,IPHLPAPI.DLL,WINNSI.DLL,sxs.dll,netprofmsvc.dll,nlaapi.dll,wdi.dll,perftrack.dll,wer.dll,AEPIC.dll,pcwum.dll,sfc_os.dll,VERSION.dll,npmproxy.dll,gpapi.dll,DNSAPI.dll,dhcpcsvc6.DLL,dhcpcsvc.DLL,rasadhlp.dll,CFGMGR32.dll,fthsvc.dll,apphelp.dll,wevtapi.dll,fdwsd.dll,wsdapi.dll,webservices.dll,FirewallAPI.dll,fdssdp.dll,SSDPAPI.dll,fdproxy.dll,FunDisc.dll,XmlLite.dll,CRYPT32.dll,MSASN1.dll,powrprof.dll,msxml6.dll,webio.dll,propsys.dll,actxprxy.dll" "svchost.exe","1100","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,sechost.dll,RPCRT4.dll,SspiCli.dll,combase.dll,msvcrt.dll,kernel.appcore.dll,CRYPTBASE.dll,bcryptPrimitives.dll,user32.dll,GDI32.dll,UxThemeSignatureBypass64.dll,UxTheme.dll,MSIMG32.dll,ole32.dll,ADVAPI32.dll,dbghelp.dll,audioendpointbuilder.dll,bcrypt.dll,cfgmgr32.dll,MMDevAPI.DLL,SETUPAPI.dll,DEVOBJ.dll,clbcatq.dll,powrprof.dll,wtsapi32.dll,WINSTA.dll,das.dll,pcasvc.dll,AEPIC.dll,apphelp.dll,USERENV.dll,sfc_os.dll,VERSION.dll,profapi.dll,trkwks.dll,OLEAUT32.dll,umrdp.dll,WINSPOOL.DRV,fhcfg.dll,SHELL32.dll,SHLWAPI.dll,PROPSYS.dll,wevtapi.dll,EFSUTIL.dll,MPR.dll,netutils.dll,XmlLite.dll,Secur32.dll,NETAPI32.dll,srvcli.dll,wkscli.dll,SHCORE.dll,ntmarta.dll,DEVRTL.dll,CRYPTSP.dll,rsaenh.dll,wintrust.dll,CRYPT32.dll,MSASN1.dll,imagehlp.dll,ncrypt.dll,NTASN1.dll,gpapi.dll,cryptnet.dll,WLDAP32.dll,wudfsvc.dll,WUDFPlatform.dll,wdi.dll,pcadm.dll,wer.dll,pcacli.dll" "svchost.exe","1200","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,sechost.dll,RPCRT4.dll,SspiCli.dll,combase.dll,msvcrt.dll,kernel.appcore.dll,CRYPTBASE.dll,bcryptPrimitives.dll,user32.dll,GDI32.dll,UxThemeSignatureBypass64.dll,UxTheme.dll,MSIMG32.dll,ole32.dll,ADVAPI32.dll,dbghelp.dll,dnsrslvr.dll,WS2_32.dll,DNSAPI.dll,WINNSI.DLL,NSI.dll,Fwpuclnt.dll,dnsext.dll,USERENV.dll,profapi.dll,gpapi.dll,mswsock.dll,iphlpapi.dll,dhcpcsvc6.DLL,dhcpcsvc.DLL,wkssvc.dll,netutils.dll,netjoin.dll,bcrypt.dll,OLEAUT32.dll,clbcatq.dll,taskschd.dll,cryptsvc.dll,CRYPT32.dll,MSASN1.dll,nlasvc.dll,CFGMGR32.dll,wevtapi.dll,ncsi.dll,powrprof.dll,WINHTTP.dll,crypttpmeksvc.dll,ncrypt.dll,NTASN1.dll,cryptcatsvc.dll,ssdpapi.dll,VSSAPI.DLL,VssTrace.DLL,DSROLE.dll,bcd.dll,WMICLNT.dll,samcli.dll,SAMLIB.dll,wkscli.dll,CRYPTSP.dll,rsaenh.dll,WlanApi.dll,es.dll,WTSAPI32.dll,WINSTA.dll,PROPSYS.dll,termsrv.dll,lsmproxy.dll,REGAPI.dll,rdpcorets.dll,pdh.dll,rfxvmt.dll,SHELL32.dll,SETUPAPI.dll,SHLWAPI.dll,AUTHZ.dll,tlscsp.dll,d3d9.dll,VERSION.dll,dwmapi.dll,DPAPI.DLL,umb.dll,ATL.DLL,DEVOBJ.dll,WINTRUST.dll,ntmarta.dll,ESENT.dll,CRYPTNET.dll,WLDAP32.dll,webio.dll,rasadhlp.dll,msv1_0.DLL,cryptdll.dll,Cabinet.dll,sxs.dll,vss_ps.dll,msxml3.dll,drvstore.dll" "svchost.exe","1360","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,sechost.dll,RPCRT4.dll,SspiCli.dll,combase.dll,msvcrt.dll,kernel.appcore.dll,CRYPTBASE.dll,bcryptPrimitives.dll,user32.dll,GDI32.dll,UxThemeSignatureBypass64.dll,UxTheme.dll,MSIMG32.dll,ole32.dll,ADVAPI32.dll,dbghelp.dll,bfe.dll,AUTHZ.dll,WS2_32.dll,DNSAPI.dll,NSI.dll,wevtapi.dll,pcwum.dll,dps.dll,clbcatq.dll,taskschd.dll,OLEAUT32.dll,gpapi.dll,ktmw32.dll,wdi.dll,srumsvc.dll,powrprof.dll,ESENT.dll,CRYPTSP.dll,rsaenh.dll,bcrypt.dll,wdiasqmmodule.dll,nduprov.dll,wpnsruprov.dll,appsruprov.dll,shcore.dll,ncuprov.dll,IPHLPAPI.DLL,WINNSI.DLL,wlanapi.dll,wwapi.dll,energyprov.dll,XmlLite.dll,DEVOBJ.dll,SrumAPI.dll,cfgmgr32.dll,netprofm.dll,npmproxy.dll,dhcpcsvc.DLL,radardt.dll,WTSAPI32.dll,VERSION.dll,ntmarta.dll,WINSTA.dll,pnpts.dll,diagperf.dll" "svchost.exe","176","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,sechost.dll,RPCRT4.dll,SspiCli.dll,combase.dll,msvcrt.dll,kernel.appcore.dll,CRYPTBASE.dll,bcryptPrimitives.dll,user32.dll,GDI32.dll,UxThemeSignatureBypass64.dll,UxTheme.dll,MSIMG32.dll,ole32.dll,ADVAPI32.dll,dbghelp.dll,profsvc.dll,USERENV.dll,OLEAUT32.dll,SYSNTFY.dll,profapi.dll,themeservice.dll,gpsvc.dll,srvcli.dll,WLDAP32.dll,GPAPI.dll,NSI.dll,wevtapi.dll,nlaapi.dll,profsvcext.dll,NTDSAPI.dll,NETAPI32.dll,SHELL32.dll,ATL.DLL,SHLWAPI.dll,WS2_32.dll,netutils.dll,wkscli.dll,LOGONCLI.DLL,DSROLE.dll,clbcatq.dll,WINSTA.dll,CRYPTSP.dll,rsaenh.dll,bcrypt.dll,sens.dll,shsvcs.dll,cfgmgr32.dll,HID.DLL,schedsvc.dll,UBPM.dll,AUTHZ.dll,pcwum.dll,ktmw32.dll,XmlLite.dll,DABAPI.dll,CSystemEventsBrokerClient.dll,EventAggregation.dll,DEVOBJ.dll,FVEAPI.dll,bcd.dll,FVECERTS.dll,CRYPT32.dll,MSASN1.dll,POWRPROF.dll,WMICLNT.dll,taskcomp.dll,ntmarta.dll,mswsock.dll,netjoin.dll,WTSAPI32.dll,SHCORE.DLL,PROPSYS.dll,ProximityService.dll,ProximityServicePAL.dll,IPHLPAPI.DLL,ProximityCommon.dll,WINNSI.DLL,ProximityCommonPal.dll,firewallapi.dll,SAMLIB.dll,ikeext.dll,fwpuclnt.dll,dhcpcsvc6.DLL,dhcpcsvc.DLL,wmisvc.dll,wbemcomn.dll,srvsvc.dll,iphlpsvc.dll,rtutils.dll,httpprxm.dll,adhsvc.dll,SSCORE.DLL,sscoreext.dll,mi.dll,miutils.dll,SETUPAPI.dll,sqmapi.dll,WINHTTP.dll,wmidcom.dll,DPAPI.DLL,netprofm.dll,RESUTILS.DLL,CLUSAPI.dll,cryptdll.dll,WDSCORE.dll,WINTRUST.dll,DNSAPI.dll,rasadhlp.dll,VSSAPI.DLL,VssTrace.DLL,samcli.dll,wbemcore.dll,esscli.dll,FastProx.dll,wbemsvc.dll,wmiutils.dll,repdrvfs.dll,wmiprvsd.dll,NCObjAPI.DLL,wbemess.dll,npmproxy.dll,ACTIVEDS.dll,adsldpc.dll,sxs.dll,SECUR32.DLL,cscapi.dll,certprop.dll,WinSCard.dll,WMsgAPI.dll,sessenv.dll,ncrypt.dll,NTASN1.dll,ncprov.dll,qmgr.dll,bitsperf.dll,bitsigd.dll,webio.dll,urlmon.dll,iertutil.dll,WININET.dll,seclogon.dll,RasApi32.dll,rasman.dll,devrtl.DLL,SPINF.dll,drvstore.dll,apphelp.dll,appmgmts.dll,mmcss.dll,AVRT.dll,aelupsvc.dll" "svchost.exe","1776","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,sechost.dll,RPCRT4.dll,SspiCli.dll,wiaservc.dll,msvcrt.dll,ADVAPI32.dll,USER32.dll,OLEAUT32.dll,ole32.dll,VERSION.dll,GDI32.dll,combase.dll,UxThemeSignatureBypass64.dll,UxTheme.dll,MSIMG32.dll,dbghelp.dll,wiatrace.dll,kernel.appcore.dll,CRYPTBASE.dll,bcryptPrimitives.dll,msv1_0.DLL,cryptdll.dll,powrprof.dll,cfgmgr32.dll,SETUPAPI.dll,clbcatq.dll,DEVOBJ.dll,CRYPTSP.dll,WSDCHNGR.DLL,deviceassociation.dll,rsaenh.dll,bcrypt.dll,FunDisc.dll,WINTRUST.dll,CRYPT32.dll,MSASN1.dll,HPWia2_LS120.dll,XmlLite.dll,fdPnp.dll,ATL.DLL,HPScanTRDrv_LS120.dll,SHLWAPI.dll,PSAPI.DLL,SHELL32.dll,Secur32.dll,WS2_32.dll,WININET.dll,WINSPOOL.DRV,IPHLPAPI.DLL,NSI.dll,iertutil.dll,USERENV.dll,WINNSI.DLL,profapi.dll,SHCORE.dll,wsdapi.dll,webservices.dll,FirewallAPI.dll,mswsock.dll,dhcpcsvc6.DLL,dhcpcsvc.DLL,WSDScanProxy.dll,WINHTTP.dll,webio.dll,DNSAPI.dll,HTTPAPI.dll,sti.dll,comctl32.dll,PortableDeviceApi.dll,PortableDeviceTypes.dll,PROPSYS.dll,SqmApi.dll,WSDScDrv.dll,gdiplus.dll" "svchost.exe","2124","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,sechost.dll,RPCRT4.dll,SspiCli.dll,ipsecsvc.dll,msvcrt.dll,AUTHZ.dll,fwpuclnt.dll,FirewallAPI.dll,FwRemoteSvr.DLL,combase.dll,kernel.appcore.dll,CRYPTBASE.dll,bcryptPrimitives.dll,clbcatq.dll,OLEAUT32.dll,WS2_32.dll,NSI.dll,mswsock.dll,IPHLPAPI.DLL,WINNSI.DLL,dhcpcsvc6.DLL,dhcpcsvc.DLL" "svchost.exe","2564","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,sechost.dll,RPCRT4.dll,SspiCli.dll,combase.dll,msvcrt.dll,kernel.appcore.dll,CRYPTBASE.dll,bcryptPrimitives.dll,user32.dll,GDI32.dll,UxThemeSignatureBypass64.dll,UxTheme.dll,MSIMG32.dll,ole32.dll,ADVAPI32.dll,dbghelp.dll,ssdpsrv.dll,WS2_32.dll,NSI.dll,FirewallAPI.dll,IPHLPAPI.DLL,WINNSI.DLL,dhcpcsvc6.DLL,dhcpcsvc.DLL,CRYPTSP.dll,rsaenh.dll,bcrypt.dll,mswsock.dll,POWRPROF.dll,httpapi.dll,WINHTTP.dll,webio.dll,DNSAPI.dll,wcncsvc.dll,authz.dll,clbcatq.dll,upnp.dll,OLEAUT32.dll,SSDPAPI.dll,sxs.dll,wlanapi.dll,upnphost.dll,profapi.dll,ntmarta.dll,msxml6.dll,urlmon.dll,SHLWAPI.dll,iertutil.dll,WININET.dll,USERENV.dll,shcore.dll" "svchost.exe","840","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,sechost.dll,RPCRT4.dll,SspiCli.dll,umpnpmgr.dll,msvcrt.dll,umpo.dll,umpoext.dll,cfgmgr32.dll,powrprof.dll,pcwum.dll,HID.DLL,gpapi.dll,rpcss.dll,combase.dll,bisrv.dll,OLEAUT32.dll,psmsrv.dll,lsm.dll,SYSNTFY.dll,WMsgAPI.dll,CRYPTBASE.dll,bcryptPrimitives.dll,DEVOBJ.dll,Userenv.dll,profapi.dll,ADVAPI32.dll,kernel.appcore.dll,user32.dll,GDI32.dll,UxThemeSignatureBypass64.dll,UxTheme.dll,MSIMG32.dll,ole32.dll,dbghelp.dll,clbcatq.dll,CRYPTSP.dll,rsaenh.dll,bcrypt.dll,systemeventsbrokerserver.dll,bi.dll,DAB.dll,wtsapi32.dll,WINSTA.dll,lsmproxy.dll,actxprxy.dll,twinapi.dll,shcore.dll,apphelp.dll,msv1_0.DLL,cryptdll.dll,DEVRTL.dll" "svchost.exe","872","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,sechost.dll,RPCRT4.dll,SspiCli.dll,combase.dll,msvcrt.dll,kernel.appcore.dll,CRYPTBASE.dll,bcryptPrimitives.dll,user32.dll,GDI32.dll,UxThemeSignatureBypass64.dll,UxTheme.dll,MSIMG32.dll,ole32.dll,ADVAPI32.dll,dbghelp.dll,wevtsvc.dll,powrprof.dll,WS2_32.dll,NSI.dll,mswsock.dll,gpapi.dll,audiosrv.dll,ksuser.dll,OLEAUT32.dll,HID.DLL,MMDevAPI.DLL,AVRT.dll,DEVOBJ.dll,cfgmgr32.dll,clbcatq.dll,winsta.dll,wtsapi32.dll,lmhsvc.dll,IPHLPAPI.DLL,nrpsrv.DLL,WINNSI.DLL,wcmsvc.dll,dhcpcore.dll,DNSAPI.dll,firewallapi.dll,wcmcsp.dll,WMICLNT.dll,dhcpcore6.dll,kerberos.DLL,MSASN1.dll,cryptdll.dll,nlaapi.dll,dhcpcsvc6.DLL,dhcpcsvc.DLL,PROPSYS.dll,CRYPTSP.dll,rsaenh.dll,bcrypt.dll,audioses.dll,deviceaccess.dll,winrnr.dll,rasadhlp.dll,napinsp.dll,pnrpnsp.dll,fwpuclnt.dll,wscsvc.dll,netutils.dll,wbemprox.dll,wbemcomn.dll,wbemsvc.dll,fastprox.dll,WINHTTP.dll,wuapi.dll,CRYPT32.dll,SHLWAPI.dll,Cabinet.dll,WINTRUST.dll,VERSION.dll,USERENV.dll,profapi.dll,wkscli.dll,WMALFXGFXDSP.dll,mfplat.DLL,RTWorkQ.DLL,twinapi.appcore.dll,shcore.dll" "svchost.exe","880","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,sechost.dll,RPCRT4.dll,SspiCli.dll,rpcepmap.dll,RpcRtRemote.dll,rpcss.dll,msvcrt.dll,powrprof.dll,combase.dll,CRYPTSP.dll,rsaenh.dll,bcrypt.dll,CRYPTBASE.dll,bcryptPrimitives.dll,WS2_32.dll,NSI.dll,mswsock.dll,FirewallAPI.dll,kernel.appcore.dll,clbcatq.dll,fwpuclnt.dll,advapi32.dll,msiltcfg.dll,VERSION.dll,msi.dll,USER32.dll,SHELL32.dll,GDI32.dll,SHLWAPI.dll,ole32.dll,UxThemeSignatureBypass64.dll,UxTheme.dll,MSIMG32.dll,dbghelp.dll,Comctl32.dll,SFC.DLL,sfc_os.DLL,SXS.DLL,wtsapi32.dll,WINSTA.dll" "taskhostex.exe","6148","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,msvcrt.dll,RPCRT4.dll,combase.dll,OLEAUT32.dll,SspiCli.dll,sechost.dll,kernel.appcore.dll,CRYPTBASE.dll,bcryptPrimitives.dll,user32.dll,GDI32.dll,IMM32.DLL,MSCTF.dll,UxThemeSignatureBypass64.dll,UxTheme.dll,MSIMG32.dll,ole32.dll,ADVAPI32.dll,dbghelp.dll,dwmapi.dll,clbcatq.dll,PlaySndSrv.dll,MsCtfMonitor.dll,MSUTB.dll,WINSTA.dll,WTSAPI32.dll,wininet.dll,iertutil.dll,USERENV.dll,profapi.dll,ESENT.dll,SHELL32.dll,SHLWAPI.dll,SHCORE.dll,WINMM.dll,WINMMBASE.dll,cfgmgr32.dll,DEVOBJ.dll,sqmapi.dll,POWRPROF.dll,profext.dll,ntmarta.dll,MMDevAPI.DLL,wdmaud.drv,ksuser.dll,AVRT.dll,AUDIOSES.DLL,msacm32.drv,MSACM32.dll,midimap.dll" "tasklist.exe","4132","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,ADVAPI32.dll,msvcrt.dll,USER32.dll,ole32.dll,VERSION.dll,MPR.dll,OLEAUT32.dll,Secur32.dll,WS2_32.dll,framedynos.dll,NETAPI32.dll,dbghelp.dll,SHLWAPI.dll,sechost.dll,RPCRT4.dll,GDI32.dll,combase.dll,NSI.dll,SspiCli.dll,netutils.dll,srvcli.dll,wkscli.dll,IMM32.DLL,MSCTF.dll,UxThemeSignatureBypass64.dll,UxTheme.dll,MSIMG32.dll,kernel.appcore.dll,CRYPTBASE.dll,bcryptPrimitives.dll,clbcatq.dll,wbemprox.dll,wbemcomn.dll,Winsta.dll,CRYPTSP.dll,rsaenh.dll,bcrypt.dll,wbemsvc.dll,fastprox.dll,wmiutils.dll" "TortoiseProc.exe","11516","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,CRYPT32.dll,WINMM.dll,WININET.dll,UxTheme.dll,COMCTL32.dll,RPCRT4.dll,SHLWAPI.dll,VERSION.dll,gdiplus.dll,libsvn_tsvn.dll,libapr_tsvn.dll,libsasl.dll,libaprutil_tsvn.dll,intl3_tsvn.dll,MSVCP140.dll,mfc140u.dll,USER32.dll,GDI32.dll,COMDLG32.dll,ADVAPI32.dll,SHELL32.dll,ole32.dll,OLEAUT32.dll,urlmon.dll,dwmapi.dll,VCRUNTIME140.dll,api-ms-win-crt-string-l1-1-0.dll,api-ms-win-crt-runtime-l1-1-0.dll,api-ms-win-crt-stdio-l1-1-0.dll,api-ms-win-crt-environment-l1-1-0.dll,api-ms-win-crt-heap-l1-1-0.dll,api-ms-win-crt-convert-l1-1-0.dll,api-ms-win-crt-utility-l1-1-0.dll,api-ms-win-crt-filesystem-l1-1-0.dll,api-ms-win-crt-time-l1-1-0.dll,api-ms-win-crt-locale-l1-1-0.dll,api-ms-win-crt-math-l1-1-0.dll,msvcrt.dll,MSASN1.dll,WINMMBASE.dll,iertutil.dll,USERENV.dll,combase.dll,SspiCli.dll,WS2_32.dll,Secur32.dll,api-ms-win-crt-conio-l1-1-0.dll,MSWSOCK.dll,WLDAP32.dll,api-ms-win-crt-multibyte-l1-1-0.dll,IMM32.dll,sechost.dll,cfgmgr32.dll,DEVOBJ.dll,profapi.dll,NSI.dll,MSCTF.dll,ucrtbase.DLL,SHCORE.DLL,CRYPTBASE.DLL,bcryptPrimitives.dll,UxThemeSignatureBypass64.dll,MSIMG32.dll,dbghelp.dll,crshhndl.dll,kernel.appcore.dll,MSFTEDIT.DLL,SETUPAPI.dll,clbcatq.dll,propsys.dll,WindowsCodecs.dll,LINKINFO.dll,ntshrui.dll,srvcli.dll,cscapi.dll,CRYPTSP.dll,rsaenh.dll,bcrypt.dll,XmlLite.dll,ntmarta.dll,IconCodecService.dll,Windows.Globalization.dll,Bcp47Langs.dll,globinputhost.dll,explorerframe.dll,DUser.dll,DUI70.dll,thumbcache.dll,oleacc.dll,DPAPI.dll,napinsp.dll,pnrpnsp.dll,NLAapi.dll,DNSAPI.dll,winrnr.dll,IPHLPAPI.DLL,WINNSI.DLL,fwpuclnt.dll,rasadhlp.dll,CRYPTUI.DLL,gpapi.dll,ncrypt.dll,NTASN1.dll,ondemandconnroutehelper.dll,winhttp.dll,schannel.DLL,WINTRUST.dll,ncryptsslp.dll,MMDevAPI.DLL,wdmaud.drv,ksuser.dll,AVRT.dll,AUDIOSES.DLL,powrprof.dll,msacm32.drv,MSACM32.dll,midimap.dll" "TSVNCache.exe","6836","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,libsvn_tsvn.dll,libapr_tsvn.dll,USER32.dll,GDI32.dll,ADVAPI32.dll,SHELL32.dll,ole32.dll,SHLWAPI.dll,MSVCP140.dll,VCRUNTIME140.dll,api-ms-win-crt-runtime-l1-1-0.dll,api-ms-win-crt-environment-l1-1-0.dll,api-ms-win-crt-string-l1-1-0.dll,api-ms-win-crt-multibyte-l1-1-0.dll,api-ms-win-crt-stdio-l1-1-0.dll,api-ms-win-crt-heap-l1-1-0.dll,api-ms-win-crt-convert-l1-1-0.dll,api-ms-win-crt-math-l1-1-0.dll,api-ms-win-crt-locale-l1-1-0.dll,libaprutil_tsvn.dll,intl3_tsvn.dll,libsasl.dll,WS2_32.dll,Secur32.dll,CRYPT32.dll,VERSION.dll,api-ms-win-crt-utility-l1-1-0.dll,api-ms-win-crt-conio-l1-1-0.dll,api-ms-win-crt-time-l1-1-0.dll,api-ms-win-crt-filesystem-l1-1-0.dll,MSWSOCK.dll,RPCRT4.dll,msvcrt.dll,sechost.dll,combase.dll,WLDAP32.dll,NSI.dll,MSASN1.dll,SspiCli.dll,ucrtbase.DLL,CRYPTBASE.DLL,bcryptPrimitives.dll,IMM32.DLL,MSCTF.dll,UxThemeSignatureBypass64.dll,UxTheme.dll,MSIMG32.dll,dbghelp.dll,crshhndl.dll,SHCORE.dll,profapi.dll,kernel.appcore.dll,PROPSYS.dll,OLEAUT32.dll,ntmarta.dll,cfgmgr32.dll,dwmapi.dll" "vmware-authd.exe","1904","ntdll.dll,wow64.dll,wow64win.dll,wow64cpu.dll" "vmware-usbarbitrator64.exe","1112","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,MSVCR90.dll,ADVAPI32.dll,ole32.dll,OLEAUT32.dll,PSAPI.DLL,SETUPAPI.dll,SHELL32.dll,USER32.dll,WS2_32.dll,CRYPT32.dll,msvcrt.dll,sechost.dll,RPCRT4.dll,combase.dll,GDI32.dll,CFGMGR32.dll,SHLWAPI.dll,NSI.dll,MSASN1.dll,SspiCli.dll,UxThemeSignatureBypass64.dll,UxTheme.dll,MSIMG32.dll,dbghelp.dll,SHCORE.dll,profapi.dll,ntmarta.dll,DEVOBJ.dll,WINTRUST.dll,kernel.appcore.dll,CRYPTBASE.dll,bcryptPrimitives.dll,clbcatq.dll,wbemprox.dll,wbemcomn.dll,CRYPTSP.dll,rsaenh.dll,bcrypt.dll,wbemsvc.dll,fastprox.dll,bthprops.cpl,BluetoothApis.dll,comctl32.dll" "Windows10FirewallControl.exe","13580","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,USER32.dll,GDI32.dll,MSIMG32.dll,comdlg32.dll,WINSPOOL.DRV,ADVAPI32.dll,SHELL32.dll,COMCTL32.dll,SHLWAPI.dll,ole32.dll,OLEAUT32.dll,WS2_32.dll,iphlpapi.dll,NETAPI32.dll,VERSION.dll,WINMM.dll,USERENV.dll,MPR.dll,msvcrt.dll,sechost.dll,RPCRT4.dll,combase.dll,NSI.dll,WINNSI.DLL,netutils.dll,srvcli.dll,wkscli.dll,WINMMBASE.dll,profapi.dll,SspiCli.dll,cfgmgr32.dll,DEVOBJ.dll,SAMCLI.DLL,SHCORE.DLL,IMM32.DLL,MSCTF.dll,UxThemeSignatureBypass64.dll,UxTheme.dll,dbghelp.dll,RICHED20.DLL,USP10.dll,msls31.dll,kernel.appcore.dll,CRYPTBASE.dll,bcryptPrimitives.dll,clbcatq.dll,CRYPTSP.dll,rsaenh.dll,bcrypt.dll,sxs.dll,dwmapi.dll,WindowsCodecs.dll,upnp.dll,WINHTTP.dll,SSDPAPI.dll,mswsock.dll,dhcpcsvc.DLL,msxml6.dll,webio.dll,DNSAPI.dll,urlmon.dll,iertutil.dll,WININET.dll,dhcpcsvc6.DLL,actxprxy.dll" "Windows10FirewallService.exe","1476","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,fwpuclnt.dll,USER32.dll,ADVAPI32.dll,SHELL32.dll,ole32.dll,OLEAUT32.dll,SHLWAPI.dll,USERENV.dll,WS2_32.dll,VERSION.dll,MSWSOCK.dll,CRYPT32.dll,NETAPI32.dll,PSAPI.DLL,wevtapi.dll,iphlpapi.dll,DNSAPI.dll,msvcrt.dll,RPCRT4.dll,GDI32.dll,sechost.dll,combase.dll,profapi.dll,NSI.dll,MSASN1.dll,netutils.dll,srvcli.dll,wkscli.dll,WINNSI.DLL,SspiCli.dll,SAMCLI.DLL,BROWCLI.DLL,UxThemeSignatureBypass64.dll,UxTheme.dll,MSIMG32.dll,dbghelp.dll,kernel.appcore.dll,CRYPTBASE.dll,bcryptPrimitives.dll,shcore.dll,ntmarta.dll,clbcatq.dll,CRYPTSP.dll,rsaenh.dll,bcrypt.dll,secur32.dll,security.dll,dhcpcsvc6.DLL,dhcpcsvc.DLL,sxs.dll,cscapi.dll" "wininit.exe","708","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,msvcrt.dll,RPCRT4.dll,sechost.dll,profapi.dll,SspiCli.dll,wininitext.dll,USER32.dll,GDI32.dll,UxThemeSignatureBypass64.dll,UxTheme.dll,MSIMG32.dll,ole32.dll,ADVAPI32.dll,combase.dll,dbghelp.dll,WS2_32.dll,NSI.dll,mswsock.dll" "winlogon.exe","10920","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,msvcrt.dll,advapi32.dll,sechost.dll,powrprof.dll,RPCRT4.dll,SspiCli.dll,winlogonext.dll,USER32.dll,GDI32.dll,IMM32.DLL,MSCTF.dll,UxThemeSignatureBypass64.dll,UxTheme.dll,MSIMG32.dll,ole32.dll,combase.dll,UXInit.dll,dbghelp.dll,profapi.dll,winsta.dll,CRYPTBASE.DLL,bcryptPrimitives.dll,apphelp.dll,ntmarta.dll,MPR.dll,wkscli.dll,netutils.dll" "WizMouse.exe","6520","ntdll.dll,wow64.dll,wow64win.dll,wow64cpu.dll" "WmiPrvSE.exe","3572","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,msvcrt.dll,FastProx.dll,NCObjAPI.DLL,wbemcomn.dll,combase.dll,WS2_32.dll,sechost.dll,RPCRT4.dll,NSI.dll,SspiCli.dll,advapi32.dll,user32.dll,GDI32.dll,UxThemeSignatureBypass64.dll,UxTheme.dll,MSIMG32.dll,ole32.dll,dbghelp.dll,kernel.appcore.dll,CRYPTBASE.dll,bcryptPrimitives.dll,clbcatq.dll,wbemprox.dll,OLEAUT32.dll,CRYPTSP.dll,rsaenh.dll,bcrypt.dll,wbemsvc.dll,wmiutils.dll,cimwin32.dll,powrprof.dll,framedynos.dll,winbrand.dll" ------------------------------------------------------------------------------------------- SCHTASKS /Query /FO CSV (states of all scheduled tasks): "\Adobe Acrobat Update Task","N/A","Disabled" "\Aero Glass","N/A","Running" "\AMD Updater","N/A","Disabled" "\Hosts Compiler","N/A","Disabled" "\LogSystemInfo","5/21/2017 1:50:00 AM","Ready" "\Nightly File Backup","5/20/2017 3:30:00 AM","Ready" "\Nightly System Image Backup","5/21/2017 2:00:00 AM","Ready" "\Optimize Start Menu Cache Files-S-1-5-21-3441778262-1243350346-4227163889-1001","N/A","Disabled" "\RAID Health Check","5/20/2017 5:44:00 AM","Ready" "\Scan with MalwareBytes AntiMalware","5/20/2017 8:14:19 AM","Ready" "\SVN Backup","N/A","Disabled" "\Task Scheduler Test Job","N/A","Ready" "\Time Sync","5/20/2017 5:07:43 AM","Ready" "\WizMouse","N/A","Ready" "\WizMouse","N/A","Ready" "\{1E52E3A4-C4CA-40F3-974A-912A9CE57D85}","N/A","Disabled" "\Microsoft\VisualStudio\VSIX Auto Update 14","N/A","Disabled" "\Microsoft\VisualStudio\VSIX Auto Update 15.0.26403.7","N/A","Disabled" "\Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319","N/A","Disabled" "\Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 64","N/A","Disabled" "\Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 64 Critical","N/A","Disabled" "\Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 Critical","N/A","Disabled" "\Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Automated)","N/A","Disabled" "\Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Automated)","N/A","Disabled" "\Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Manual)","N/A","Disabled" "\Microsoft\Windows\AppID\PolicyConverter","N/A","Disabled" "\Microsoft\Windows\AppID\SmartScreenSpecific","N/A","Disabled" "\Microsoft\Windows\AppID\VerifiedPublisherCertStoreCheck","N/A","Disabled" "\Microsoft\Windows\Application Experience\AitAgent","N/A","Disabled" "\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser","N/A","Disabled" "\Microsoft\Windows\Application Experience\ProgramDataUpdater","N/A","Disabled" "\Microsoft\Windows\Application Experience\StartupAppTask","N/A","Disabled" "\Microsoft\Windows\ApplicationData\CleanupTemporaryState","N/A","Disabled" "\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup","N/A","Disabled" "\Microsoft\Windows\Autochk\Proxy","N/A","Disabled" "\Microsoft\Windows\Bluetooth\UninstallDeviceTask","N/A","Ready" "\Microsoft\Windows\CertificateServicesClient\SystemTask","N/A","Ready" "\Microsoft\Windows\CertificateServicesClient\SystemTask","N/A","Ready" "\Microsoft\Windows\CertificateServicesClient\SystemTask","N/A","Ready" "\Microsoft\Windows\CertificateServicesClient\UserTask","N/A","Ready" "\Microsoft\Windows\CertificateServicesClient\UserTask","N/A","Ready" "\Microsoft\Windows\CertificateServicesClient\UserTask","N/A","Ready" "\Microsoft\Windows\CertificateServicesClient\UserTask-Roam","N/A","Disabled" "\Microsoft\Windows\CertificateServicesClient\UserTask-Roam","N/A","Disabled" "\Microsoft\Windows\Chkdsk\ProactiveScan","N/A","Ready" "\Microsoft\Windows\Customer Experience Improvement Program\BthSQM","N/A","Disabled" "\Microsoft\Windows\Customer Experience Improvement Program\Consolidator","N/A","Disabled" "\Microsoft\Windows\Customer Experience Improvement Program\KernelCeipTask","N/A","Disabled" "\Microsoft\Windows\Customer Experience Improvement Program\UsbCeip","N/A","Disabled" "\Microsoft\Windows\Data Integrity Scan\Data Integrity Scan","N/A","Disabled" "\Microsoft\Windows\Data Integrity Scan\Data Integrity Scan","N/A","Disabled" "\Microsoft\Windows\Data Integrity Scan\Data Integrity Scan for Crash Recovery","N/A","Ready" "\Microsoft\Windows\Defrag\ScheduledDefrag","N/A","Ready" "\Microsoft\Windows\Device Setup\Metadata Refresh","N/A","Ready" "\Microsoft\Windows\Diagnosis\Scheduled","N/A","Ready" "\Microsoft\Windows\DiskCleanup\SilentCleanup","N/A","Disabled" "\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector","N/A","Disabled" "\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticResolver","N/A","Disabled" "\Microsoft\Windows\DiskFootprint\Diagnostics","N/A","Ready" "\Microsoft\Windows\File Classification Infrastructure\Property Definition Sync","N/A","Disabled" "\Microsoft\Windows\FileHistory\File History (maintenance mode)","N/A","Disabled" "\Microsoft\Windows\IME\SQM data sender","N/A","Disabled" "\Microsoft\Windows\Location\Notifications","N/A","Disabled" "\Microsoft\Windows\Maintenance\WinSAT","N/A","Ready" "\Microsoft\Windows\Media Center\ActivateWindowsSearch","N/A","Disabled" "\Microsoft\Windows\Media Center\ConfigureInternetTimeService","N/A","Disabled" "\Microsoft\Windows\Media Center\DispatchRecoveryTasks","N/A","Disabled" "\Microsoft\Windows\Media Center\ehDRMInit","N/A","Disabled" "\Microsoft\Windows\Media Center\InstallPlayReady","N/A","Disabled" "\Microsoft\Windows\Media Center\mcupdate","N/A","Disabled" "\Microsoft\Windows\Media Center\mcupdate_scheduled","N/A","Disabled" "\Microsoft\Windows\Media Center\MediaCenterRecoveryTask","N/A","Disabled" "\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask","N/A","Disabled" "\Microsoft\Windows\Media Center\OCURActivate","N/A","Disabled" "\Microsoft\Windows\Media Center\OCURDiscovery","N/A","Disabled" "\Microsoft\Windows\Media Center\PBDADiscovery","N/A","Disabled" "\Microsoft\Windows\Media Center\PBDADiscoveryW1","N/A","Disabled" "\Microsoft\Windows\Media Center\PBDADiscoveryW2","N/A","Disabled" "\Microsoft\Windows\Media Center\PeriodicScanRetry","N/A","Disabled" "\Microsoft\Windows\Media Center\PvrRecoveryTask","N/A","Disabled" "\Microsoft\Windows\Media Center\PvrScheduleTask","N/A","Disabled" "\Microsoft\Windows\Media Center\RecordingRestart","N/A","Disabled" "\Microsoft\Windows\Media Center\RegisterSearch","N/A","Disabled" "\Microsoft\Windows\Media Center\ReindexSearchRoot","N/A","Disabled" "\Microsoft\Windows\Media Center\SqlLiteRecoveryTask","N/A","Disabled" "\Microsoft\Windows\Media Center\StartRecording","N/A","Disabled" "\Microsoft\Windows\Media Center\UpdateRecordPath","N/A","Disabled" "\Microsoft\Windows\MemoryDiagnostic\ProcessMemoryDiagnosticEvents","N/A","Ready" "\Microsoft\Windows\MemoryDiagnostic\ProcessMemoryDiagnosticEvents","N/A","Ready" "\Microsoft\Windows\MemoryDiagnostic\ProcessMemoryDiagnosticEvents","N/A","Ready" "\Microsoft\Windows\MemoryDiagnostic\ProcessMemoryDiagnosticEvents","N/A","Ready" "\Microsoft\Windows\MemoryDiagnostic\RunFullMemoryDiagnostic","N/A","Ready" "\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser","N/A","Disabled" "\Microsoft\Windows\MUI\LPRemove","N/A","Disabled" "\Microsoft\Windows\Multimedia\SystemSoundsService","N/A","Running" "\Microsoft\Windows\NetCfg\BindingWorkItemQueueHandler","N/A","Disabled" "\Microsoft\Windows\NetTrace\GatherNetworkInfo","N/A","Disabled" "\Microsoft\Windows\Offline Files\Background Synchronization","N/A","Disabled" "\Microsoft\Windows\Offline Files\Logon Synchronization","N/A","Disabled" "\Microsoft\Windows\PerfTrack\BackgroundConfigSurveyor","N/A","Disabled" "\Microsoft\Windows\PerfTrack\BackgroundConfigSurveyor","N/A","Disabled" "\Microsoft\Windows\PI\Secure-Boot-Update","N/A","Disabled" "\Microsoft\Windows\PI\Sqm-Tasks","N/A","Disabled" "\Microsoft\Windows\Plug and Play\Device Install Group Policy","N/A","Ready" "\Microsoft\Windows\Plug and Play\Device Install Reboot Required","N/A","Ready" "\Microsoft\Windows\Plug and Play\Plug and Play Cleanup","N/A","Ready" "\Microsoft\Windows\Plug and Play\Sysprep Generalize Drivers","N/A","Ready" "\Microsoft\Windows\Power Efficiency Diagnostics\AnalyzeSystem","N/A","Ready" "\Microsoft\Windows\RAC\RacTask","5/20/2017 8:00:33 AM","Ready" "\Microsoft\Windows\RAC\RacTask","5/20/2017 8:03:39 AM","Ready" "\Microsoft\Windows\RAC\RacTask","5/20/2017 8:03:45 AM","Ready" "\Microsoft\Windows\RAC\RacTask","5/20/2017 8:04:41 AM","Ready" "\Microsoft\Windows\Ras\MobilityManager","N/A","Ready" "\Microsoft\Windows\RecoveryEnvironment\VerifyWinRE","N/A","Disabled" "\Microsoft\Windows\Registry\RegIdleBackup","N/A","Ready" "\Microsoft\Windows\RemoteAssistance\RemoteAssistanceTask","N/A","Disabled" "\Microsoft\Windows\RemoteAssistance\RemoteAssistanceTask","N/A","Disabled" "\Microsoft\Windows\Servicing\StartComponentCleanup","N/A","Disabled" "\Microsoft\Windows\SettingSync\BackgroundUploadTask","N/A","Disabled" "\Microsoft\Windows\SettingSync\BackupTask","N/A","Disabled" "\Microsoft\Windows\SettingSync\NetworkStateChangeTask","N/A","Disabled" "\Microsoft\Windows\SettingSync\NetworkStateChangeTask","N/A","Disabled" "\Microsoft\Windows\Shell\FamilySafetyMonitor","N/A","Disabled" "\Microsoft\Windows\Shell\FamilySafetyRefresh","N/A","Disabled" "\Microsoft\Windows\Shell\FamilySafetyUpload","N/A","Disabled" "\Microsoft\Windows\Shell\IndexerAutomaticMaintenance","N/A","Disabled" "\Microsoft\Windows\SkyDrive\Idle Sync Maintenance Task","N/A","Disabled" "\Microsoft\Windows\SkyDrive\Routine Maintenance Task","N/A","Disabled" "\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask","4/11/2117 11:14:15 AM","Ready" "\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTaskLogon","N/A","Disabled" "\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTaskNetwork","N/A","Disabled" "\Microsoft\Windows\SpacePort\SpaceAgentTask","N/A","Ready" "\Microsoft\Windows\SpacePort\SpaceAgentTask","N/A","Ready" "\Microsoft\Windows\Sysmain\HybridDriveCachePrepopulate","N/A","Disabled" "\Microsoft\Windows\Sysmain\HybridDriveCacheRebalance","N/A","Disabled" "\Microsoft\Windows\Sysmain\WsSwapAssessmentTask","N/A","Ready" "\Microsoft\Windows\SystemRestore\SR","N/A","Ready" "\Microsoft\Windows\Task Manager\Interactive","N/A","Ready" "\Microsoft\Windows\TaskScheduler\Idle Maintenance","N/A","Disabled" "\Microsoft\Windows\TaskScheduler\Maintenance Configurator","5/21/2017 1:00:00 AM","Ready" "\Microsoft\Windows\TaskScheduler\Maintenance Configurator","5/21/2017 1:00:00 AM","Ready" "\Microsoft\Windows\TaskScheduler\Maintenance Configurator","5/21/2017 1:00:00 AM","Ready" "\Microsoft\Windows\TaskScheduler\Manual Maintenance","N/A","Ready" "\Microsoft\Windows\TaskScheduler\Regular Maintenance","5/21/2017 2:52:55 AM","Ready" "\Microsoft\Windows\TextServicesFramework\MsCtfMonitor","N/A","Running" "\Microsoft\Windows\Time Synchronization\ForceSynchronizeTime","N/A","Disabled" "\Microsoft\Windows\Time Synchronization\SynchronizeTime","N/A","Disabled" "\Microsoft\Windows\Time Zone\SynchronizeTimeZone","N/A","Ready" "\Microsoft\Windows\TPM\Tpm-Maintenance","N/A","Ready" "\Microsoft\Windows\TPM\Tpm-Maintenance","N/A","Ready" "\Microsoft\Windows\TPM\Tpm-Maintenance","N/A","Ready" "\Microsoft\Windows\TPM\Tpm-Maintenance","N/A","Ready" "\Microsoft\Windows\UPnP\UPnPHostConfig","N/A","Ready" "\Microsoft\Windows\User Profile Service\HiveUploadTask","N/A","Disabled" "\Microsoft\Windows\WDI\ResolutionHost","N/A","Disabled" "\Microsoft\Windows\Windows Error Reporting\QueueReporting","N/A","Disabled" "\Microsoft\Windows\Windows Error Reporting\QueueReporting","N/A","Disabled" "\Microsoft\Windows\Windows Filtering Platform\BfeOnServiceStartTypeChange","N/A","Ready" "\Microsoft\Windows\Windows Media Sharing\UpdateLibrary","N/A","Disabled" "\Microsoft\Windows\WindowsColorSystem\Calibration Loader","N/A","Disabled" "\Microsoft\Windows\WindowsColorSystem\Calibration Loader","N/A","Disabled" "\Microsoft\Windows\WindowsUpdate\AUFirmwareInstall","N/A","Disabled" "\Microsoft\Windows\WindowsUpdate\AUScheduledInstall","N/A","Disabled" "\Microsoft\Windows\WindowsUpdate\AUSessionConnect","N/A","Disabled" "\Microsoft\Windows\WindowsUpdate\AUSessionConnect","N/A","Disabled" "\Microsoft\Windows\WindowsUpdate\AUSessionConnect","N/A","Disabled" "\Microsoft\Windows\WindowsUpdate\AUSessionConnect","N/A","Disabled" "\Microsoft\Windows\WindowsUpdate\AUSessionConnect","N/A","Disabled" "\Microsoft\Windows\WindowsUpdate\Scheduled Start","N/A","Disabled" "\Microsoft\Windows\WindowsUpdate\Scheduled Start","N/A","Disabled" "\Microsoft\Windows\WindowsUpdate\Scheduled Start","N/A","Disabled" "\Microsoft\Windows\WindowsUpdate\Scheduled Start","N/A","Disabled" "\Microsoft\Windows\WindowsUpdate\Scheduled Start With Network","N/A","Disabled" "\Microsoft\Windows\WindowsUpdate\Scheduled Start With Network","N/A","Disabled" "\Microsoft\Windows\WindowsUpdate\Scheduled Start With Network","N/A","Disabled" "\Microsoft\Windows\WindowsUpdate\Scheduled Start With Network","N/A","Disabled" "\Microsoft\Windows\Wininet\CacheTask","N/A","Running" "\Microsoft\Windows\WOF\WIM-Hash-Management","N/A","Disabled" "\Microsoft\Windows\WOF\WIM-Hash-Management","N/A","Disabled" "\Microsoft\Windows\WOF\WIM-Hash-Validation","N/A","Disabled" "\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join","N/A","Disabled" "\Microsoft\Windows\WS\Badge Update","N/A","Disabled" "\Microsoft\Windows\WS\License Validation","5/23/2017 1:35:57 AM","Ready" "\Microsoft\Windows\WS\Sync Licenses","N/A","Disabled" "\Microsoft\Windows\WS\WSRefreshBannedAppsListTask","N/A","Disabled" "\Microsoft\Windows\WS\WSTask","N/A","Disabled" "\OfficeSoftwareProtectionPlatform\SvcRestartTask","N/A","Disabled" ------------------------------------------------------------------------------------------- SC qc (configurations of all services): C:\TEMP>SC qc "AdobeARMservice" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: AdobeARMservice TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe" LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Adobe Acrobat Update Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "AdobeUpdateService" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: AdobeUpdateService TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : "C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe" LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : AdobeUpdateService DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "AeLookupSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: AeLookupSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Application Experience DEPENDENCIES : SERVICE_START_NAME : localSystem C:\TEMP>SC qc "AGSService" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: AGSService TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : "C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe" LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Adobe Genuine Software Integrity Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "ALG" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: ALG TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\System32\alg.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Application Layer Gateway Service DEPENDENCIES : SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "APC Data Service" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: APC Data Service TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : "C:\Program Files (x86)\APC\PowerChute Personal Edition\dataserv.exe" LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : APC Data Service DEPENDENCIES : APC UPS Service SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "APC UPS Service" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: APC UPS Service TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : "C:\Program Files (x86)\APC\PowerChute Personal Edition\mainserv.exe" LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : APC UPS Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "AppIDSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: AppIDSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted LOAD_ORDER_GROUP : ProfSvc_Group TAG : 0 DISPLAY_NAME : Application Identity DEPENDENCIES : RpcSs : AppID : CryptSvc SERVICE_START_NAME : NT Authority\LocalService C:\TEMP>SC qc "Appinfo" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: Appinfo TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Application Information DEPENDENCIES : RpcSs : ProfSvc SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "AppMgmt" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: AppMgmt TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Application Management DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "AppReadiness" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: AppReadiness TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\System32\svchost.exe -k AppReadiness LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : App Readiness DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "AppXSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: AppXSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k wsappx LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : AppX Deployment Service (AppXSVC) DEPENDENCIES : rpcss SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "aspnet_state" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: aspnet_state TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : ASP.NET State Service DEPENDENCIES : SERVICE_START_NAME : NT AUTHORITY\NetworkService C:\TEMP>SC qc "AudioEndpointBuilder" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: AudioEndpointBuilder TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : AudioGroup TAG : 0 DISPLAY_NAME : Windows Audio Endpoint Builder DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "Audiosrv" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: Audiosrv TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted LOAD_ORDER_GROUP : AudioGroup TAG : 0 DISPLAY_NAME : Windows Audio DEPENDENCIES : AudioEndpointBuilder : RpcSs : MMCSS SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "AxInstSV" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: AxInstSV TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k AxInstSVGroup LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : ActiveX Installer (AxInstSV) DEPENDENCIES : rpcss SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "BDESVC" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: BDESVC TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\System32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : BitLocker Drive Encryption Service DEPENDENCIES : SERVICE_START_NAME : localSystem C:\TEMP>SC qc "BFE" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: BFE TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork LOAD_ORDER_GROUP : NetworkProvider TAG : 0 DISPLAY_NAME : Base Filtering Engine DEPENDENCIES : RpcSs : WfpLwfs SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "BITS" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: BITS TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\System32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Background Intelligent Transfer Service DEPENDENCIES : RpcSs : EventSystem SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "Bonjour Service" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: Bonjour Service TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : "C:\Program Files (x86)\Bonjour\mDNSResponder.exe" LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## DEPENDENCIES : Tcpip SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "BrokerInfrastructure" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: BrokerInfrastructure TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k DcomLaunch LOAD_ORDER_GROUP : COM Infrastructure TAG : 0 DISPLAY_NAME : Background Tasks Infrastructure Service DEPENDENCIES : RpcEptMapper : DcomLaunch : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "BthHFSrv" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: BthHFSrv TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\System32\svchost.exe -k LocalServiceAndNoImpersonation LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Bluetooth Handsfree Service DEPENDENCIES : bthserv SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "bthserv" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: bthserv TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k LocalService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Bluetooth Support Service DEPENDENCIES : SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "CertPropSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: CertPropSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Certificate Propagation DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "CollabNetSubversionServer" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: CollabNetSubversionServer TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : "C:\svn\bin\httpd.exe" -k runservice LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : CollabNet Subversion Server DEPENDENCIES : Tcpip : Afd SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "COMSysApp" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: COMSysApp TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235} LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : COM+ System Application DEPENDENCIES : RpcSs : EventSystem : SENS SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "CryptSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: CryptSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k NetworkService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Cryptographic Services DEPENDENCIES : RpcSs SERVICE_START_NAME : NT Authority\NetworkService C:\TEMP>SC qc "CscService" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: CscService TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : ProfSvc_Group TAG : 0 DISPLAY_NAME : Offline Files DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "CSVNConsole" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: CSVNConsole TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : "C:\Program Files\Java\jre7\bin\java.exe" "-classpath" "C:\SVN\svcwrapper\wrapper.jar" "-Xrs" "-Dwrapper.service=true" "-Dwrapper.working.dir=C:\SVN\svcwrapper\..\appserver" "-Dwrapper.config=C:\SVN\svcwrapper\conf\wrapper.conf" "-Dwrapper.additional.1x=-Xrs" "org.rzo.yajsw.boot.WrapperServiceBooter" LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : CollabNet Subversion Edge DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "DcomLaunch" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: DcomLaunch TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k DcomLaunch LOAD_ORDER_GROUP : COM Infrastructure TAG : 0 DISPLAY_NAME : DCOM Server Process Launcher DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "defragsvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: defragsvc TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k defragsvc LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Optimize drives DEPENDENCIES : RPCSS SERVICE_START_NAME : localSystem C:\TEMP>SC qc "DeviceAssociationService" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: DeviceAssociationService TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Device Association Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "DeviceInstall" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: DeviceInstall TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k DcomLaunch LOAD_ORDER_GROUP : PlugPlay TAG : 0 DISPLAY_NAME : Device Install Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "Dhcp" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: Dhcp TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted LOAD_ORDER_GROUP : TDI TAG : 0 DISPLAY_NAME : DHCP Client DEPENDENCIES : NSI : Tdx : Afd SERVICE_START_NAME : NT Authority\LocalService C:\TEMP>SC qc "DiagTrack" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: DiagTrack TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\System32\svchost.exe -k utcsvc LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Diagnostics Tracking Service DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "Dnscache" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: Dnscache TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k NetworkService LOAD_ORDER_GROUP : TDI TAG : 0 DISPLAY_NAME : DNS Client DEPENDENCIES : Tdx : nsi SERVICE_START_NAME : NT AUTHORITY\NetworkService C:\TEMP>SC qc "dot3svc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: dot3svc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TDI TAG : 0 DISPLAY_NAME : Wired AutoConfig DEPENDENCIES : RpcSs : Ndisuio : Eaphost SERVICE_START_NAME : localSystem C:\TEMP>SC qc "DPS" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: DPS TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Diagnostic Policy Service DEPENDENCIES : SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "DsmSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: DsmSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Device Setup Manager DEPENDENCIES : RpcSs : HTTP SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "Eaphost" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: Eaphost TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\System32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Extensible Authentication Protocol DEPENDENCIES : RPCSS : KeyIso SERVICE_START_NAME : localSystem C:\TEMP>SC qc "EFS" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: EFS TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\System32\lsass.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Encrypting File System (EFS) DEPENDENCIES : RPCSS SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "ehRecvr" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: ehRecvr TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : C:\Windows\ehome\ehRecvr.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Media Center Receiver Service DEPENDENCIES : RPCSS SERVICE_START_NAME : NT AUTHORITY\networkService C:\TEMP>SC qc "ehSched" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: ehSched TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : C:\Windows\ehome\ehsched.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Media Center Scheduler Service DEPENDENCIES : RPCSS SERVICE_START_NAME : NT AUTHORITY\networkService C:\TEMP>SC qc "EventLog" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: EventLog TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted LOAD_ORDER_GROUP : Event Log TAG : 0 DISPLAY_NAME : Windows Event Log DEPENDENCIES : SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "EventSystem" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: EventSystem TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k LocalService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : COM+ Event System DEPENDENCIES : rpcss SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "Fax" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: Fax TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\fxssvc.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Fax DEPENDENCIES : TapiSrv : RpcSs : Spooler SERVICE_START_NAME : NT AUTHORITY\NetworkService C:\TEMP>SC qc "fdPHost" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: fdPHost TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k LocalService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Function Discovery Provider Host DEPENDENCIES : RpcSs : http SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "FDResPub" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: FDResPub TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Function Discovery Resource Publication DEPENDENCIES : RpcSs : http SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "fhsvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: fhsvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : File History Service DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "FLEXnet Licensing Service" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: FLEXnet Licensing Service TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : "C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe" LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : FLEXnet Licensing Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "FLEXnet Licensing Service 64" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: FLEXnet Licensing Service 64 TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : "C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe" LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : FLEXnet Licensing Service 64 DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "FontCache" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: FontCache TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k LocalService LOAD_ORDER_GROUP : AudioGroup TAG : 0 DISPLAY_NAME : Windows Font Cache Service DEPENDENCIES : SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "FontCache3.0.0.0" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: FontCache3.0.0.0 TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Presentation Foundation Font Cache 3.0.0.0 DEPENDENCIES : SERVICE_START_NAME : NT Authority\LocalService C:\TEMP>SC qc "gpsvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: gpsvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : ProfSvc_Group TAG : 0 DISPLAY_NAME : Group Policy Client DEPENDENCIES : RPCSS : Mup SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "hidserv" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: hidserv TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Human Interface Device Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "hkmsvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: hkmsvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\System32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Health Key and Certificate Management DEPENDENCIES : RpcSs SERVICE_START_NAME : localSystem C:\TEMP>SC qc "HomeGroupListener" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: HomeGroupListener TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : HomeGroup Listener DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "HomeGroupProvider" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: HomeGroupProvider TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : HomeGroup Provider DEPENDENCIES : netprofm : fdrespub : fdphost SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "hptsvr" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: hptsvr TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Program Files (x86)\HighPoint Technologies, Inc.\HighPoint RAID Management\Service\hptsvr.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : HighPoint RAID Management Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "IEEtwCollectorService" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: IEEtwCollectorService TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\IEEtwCollector.exe /V LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Internet Explorer ETW Collector Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "IKEEXT" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: IKEEXT TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : IKE and AuthIP IPsec Keying Modules DEPENDENCIES : BFE SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "IntuitUpdateServiceV4" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: IntuitUpdateServiceV4 TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : "C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe" LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Intuit Update Service v4 DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "iphlpsvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: iphlpsvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\System32\svchost.exe -k NetSvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : IP Helper DEPENDENCIES : RpcSS : Tdx : winmgmt : tcpip : nsi : WinHttpAutoProxySvc SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "IpOverUsbSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: IpOverUsbSvc TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : "C:\Program Files (x86)\Common Files\Microsoft Shared\Phone Tools\CoreCon\11.0\bin\IpOverUsbSvc.exe" LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Phone IP over USB Transport (IpOverUsbSvc) DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "KeyIso" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: KeyIso TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\lsass.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : CNG Key Isolation DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "KtmRm" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: KtmRm TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\System32\svchost.exe -k NetworkServiceAndNoImpersonation LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : KtmRm for Distributed Transaction Coordinator DEPENDENCIES : RPCSS : SamSS SERVICE_START_NAME : NT AUTHORITY\NetworkService C:\TEMP>SC qc "LanmanServer" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: LanmanServer TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Server DEPENDENCIES : SamSS : Srv2 SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "LanmanWorkstation" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: LanmanWorkstation TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\System32\svchost.exe -k NetworkService LOAD_ORDER_GROUP : NetworkProvider TAG : 0 DISPLAY_NAME : Workstation DEPENDENCIES : Bowser : MRxSmb20 : NSI SERVICE_START_NAME : NT AUTHORITY\NetworkService C:\TEMP>SC qc "lfsvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: lfsvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Location Framework Service DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "lltdsvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: lltdsvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\System32\svchost.exe -k LocalService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Link-Layer Topology Discovery Mapper DEPENDENCIES : rpcss : lltdio SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "lmhosts" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: lmhosts TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted LOAD_ORDER_GROUP : TDI TAG : 0 DISPLAY_NAME : TCP/IP NetBIOS Helper DEPENDENCIES : NetBT : Afd SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "LSM" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: LSM TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k DcomLaunch LOAD_ORDER_GROUP : COM Infrastructure TAG : 0 DISPLAY_NAME : Local Session Manager DEPENDENCIES : RpcEptMapper : DcomLaunch : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "MBAMService" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: MBAMService TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : "C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe" LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Malwarebytes Service DEPENDENCIES : RPCSS : WINMGMT SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "Mcx2Svc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: Mcx2Svc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Media Center Extender Service DEPENDENCIES : SSDPSRV : DeviceAssociationService : TermService : fdphost SERVICE_START_NAME : NT Authority\LocalService C:\TEMP>SC qc "MDM" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: MDM TYPE : 110 WIN32_OWN_PROCESS (interactive) START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : "C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE" LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Machine Debug Manager DEPENDENCIES : RPCSS SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "MMCSS" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: MMCSS TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Multimedia Class Scheduler DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "MpsSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: MpsSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork LOAD_ORDER_GROUP : NetworkProvider TAG : 0 DISPLAY_NAME : Windows Firewall DEPENDENCIES : mpsdrv : bfe SERVICE_START_NAME : NT Authority\LocalService C:\TEMP>SC qc "MSDTC" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: MSDTC TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\System32\msdtc.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Distributed Transaction Coordinator DEPENDENCIES : RPCSS : SamSS SERVICE_START_NAME : NT AUTHORITY\NetworkService C:\TEMP>SC qc "MSiSCSI" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: MSiSCSI TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : iSCSI TAG : 0 DISPLAY_NAME : Microsoft iSCSI Initiator Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "msiserver" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: msiserver TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\msiexec.exe /V LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Installer DEPENDENCIES : rpcss SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "MsKeyboardFilter" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: MsKeyboardFilter TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Microsoft Keyboard Filter DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "napagent" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: napagent TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\System32\svchost.exe -k NetworkService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Network Access Protection Agent DEPENDENCIES : RpcSs SERVICE_START_NAME : NT AUTHORITY\NetworkService C:\TEMP>SC qc "NcaSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: NcaSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\System32\svchost.exe -k NetSvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Network Connectivity Assistant DEPENDENCIES : BFE : dnscache : NSI : iphlpsvc SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "NcbService" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: NcbService TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Network Connection Broker DEPENDENCIES : RpcSS : tcpip SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "NcdAutoSetup" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: NcdAutoSetup TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Network Connected Devices Auto-Setup DEPENDENCIES : netprofm SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "Netlogon" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: Netlogon TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\lsass.exe LOAD_ORDER_GROUP : MS_WindowsRemoteValidation TAG : 0 DISPLAY_NAME : Netlogon DEPENDENCIES : LanmanWorkstation SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "Netman" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: Netman TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Network Connections DEPENDENCIES : RpcSs : nsi SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "netprofm" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: netprofm TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\System32\svchost.exe -k LocalService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Network List Service DEPENDENCIES : RpcSs : nlasvc SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "NetTcpPortSharing" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: NetTcpPortSharing TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Net.Tcp Port Sharing Service DEPENDENCIES : SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "NlaSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: NlaSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\System32\svchost.exe -k NetworkService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Network Location Awareness DEPENDENCIES : NSI : RpcSs : TcpIp : Dhcp : Eventlog SERVICE_START_NAME : NT AUTHORITY\NetworkService C:\TEMP>SC qc "nlsX86cc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: nlsX86cc TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : C:\Windows\SysWOW64\nlssrv32.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Nalpeiron Licensing Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "nsi" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: nsi TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k LocalService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Network Store Interface Service DEPENDENCIES : rpcss : nsiproxy SERVICE_START_NAME : NT Authority\LocalService C:\TEMP>SC qc "NVDisplay.ContainerLocalSystem" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: NVDisplay.ContainerLocalSystem TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" LOAD_ORDER_GROUP : Video TAG : 0 DISPLAY_NAME : NVIDIA Display Container LS DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "ose" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: ose TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : "C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE" LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Office Source Engine DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "ose64" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: ose64 TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : "C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE" LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Office 64 Source Engine DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "osppsvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: osppsvc TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : "C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE" LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Office Software Protection Platform DEPENDENCIES : RpcSs SERVICE_START_NAME : NT AUTHORITY\NetworkService C:\TEMP>SC qc "p2pimsvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: p2pimsvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\System32\svchost.exe -k LocalServicePeerNet LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Peer Networking Identity Manager DEPENDENCIES : SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "p2psvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: p2psvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\System32\svchost.exe -k LocalServicePeerNet LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Peer Networking Grouping DEPENDENCIES : p2pimsvc : PNRPSvc SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "PcaSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: PcaSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Program Compatibility Assistant Service DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "PeerDistSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: PeerDistSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\System32\svchost.exe -k PeerDist LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : BranchCache DEPENDENCIES : http SERVICE_START_NAME : NT AUTHORITY\NetworkService C:\TEMP>SC qc "PerfHost" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: PerfHost TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\SysWow64\perfhost.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Performance Counter DLL Host DEPENDENCIES : RPCSS SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "pla" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: pla TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Performance Logs & Alerts DEPENDENCIES : RPCSS SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "PlugPlay" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: PlugPlay TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k DcomLaunch LOAD_ORDER_GROUP : PlugPlay TAG : 0 DISPLAY_NAME : Plug and Play DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "PNRPAutoReg" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: PNRPAutoReg TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\System32\svchost.exe -k LocalServicePeerNet LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : PNRP Machine Name Publication Service DEPENDENCIES : pnrpsvc SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "PNRPsvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: PNRPsvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\System32\svchost.exe -k LocalServicePeerNet LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Peer Name Resolution Protocol DEPENDENCIES : p2pimsvc SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "PolicyAgent" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: PolicyAgent TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : IPsec Policy Agent DEPENDENCIES : Tcpip : bfe SERVICE_START_NAME : NT Authority\NetworkService C:\TEMP>SC qc "Power" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: Power TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k DcomLaunch LOAD_ORDER_GROUP : Plugplay TAG : 0 DISPLAY_NAME : Power DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "PrintNotify" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: PrintNotify TYPE : 120 WIN32_SHARE_PROCESS (interactive) START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k print LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Printer Extensions and Notifications DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "ProfSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: ProfSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : profsvc_group TAG : 0 DISPLAY_NAME : User Profile Service DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "QWAVE" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: QWAVE TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Quality Windows Audio Video Experience DEPENDENCIES : rpcss : psched : QWAVEdrv : LLTDIO SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "RasAuto" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: RasAuto TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\System32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Remote Access Auto Connection Manager DEPENDENCIES : RasAcd SERVICE_START_NAME : localSystem C:\TEMP>SC qc "RasMan" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: RasMan TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\System32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Remote Access Connection Manager DEPENDENCIES : TapiSrv : SstpSvc SERVICE_START_NAME : localSystem C:\TEMP>SC qc "RemoteAccess" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: RemoteAccess TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\System32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Routing and Remote Access DEPENDENCIES : RpcSS : Bfe : RasMan : Http : +NetBIOSGroup SERVICE_START_NAME : localSystem C:\TEMP>SC qc "RemoteRegistry" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: RemoteRegistry TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k localService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Remote Registry DEPENDENCIES : RPCSS SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "RpcEptMapper" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: RpcEptMapper TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k RPCSS LOAD_ORDER_GROUP : COM Infrastructure TAG : 0 DISPLAY_NAME : RPC Endpoint Mapper DEPENDENCIES : SERVICE_START_NAME : NT AUTHORITY\NetworkService C:\TEMP>SC qc "RpcLocator" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: RpcLocator TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\locator.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Remote Procedure Call (RPC) Locator DEPENDENCIES : SERVICE_START_NAME : NT AUTHORITY\NetworkService C:\TEMP>SC qc "RpcSs" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: RpcSs TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k rpcss LOAD_ORDER_GROUP : COM Infrastructure TAG : 0 DISPLAY_NAME : Remote Procedure Call (RPC) DEPENDENCIES : RpcEptMapper : DcomLaunch SERVICE_START_NAME : NT AUTHORITY\NetworkService C:\TEMP>SC qc "RServer3" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: RServer3 TYPE : 110 WIN32_OWN_PROCESS (interactive) START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : "C:\Windows\SysWOW64\rserver30\RServer3.exe" /service LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Radmin Server V3 DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "SamSs" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: SamSs TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\lsass.exe LOAD_ORDER_GROUP : MS_WindowsLocalValidation TAG : 0 DISPLAY_NAME : Security Accounts Manager DEPENDENCIES : RPCSS SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "SCardSvr" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: SCardSvr TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation LOAD_ORDER_GROUP : SmartCardGroup TAG : 0 DISPLAY_NAME : Smart Card DEPENDENCIES : wudfsvc SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "ScDeviceEnum" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: ScDeviceEnum TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Smart Card Device Enumeration Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "Schedule" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: Schedule TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : SchedulerGroup TAG : 0 DISPLAY_NAME : Task Scheduler DEPENDENCIES : RPCSS : SystemEventsBroker SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "SCPolicySvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: SCPolicySvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Smart Card Removal Policy DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "seclogon" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: seclogon TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Secondary Logon DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "SENS" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: SENS TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : ProfSvc_Group TAG : 0 DISPLAY_NAME : System Event Notification Service DEPENDENCIES : EventSystem SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "SensrSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: SensrSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Sensor Monitoring Service DEPENDENCIES : SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "SessionEnv" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: SessionEnv TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\System32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Remote Desktop Configuration DEPENDENCIES : RPCSS : LanmanWorkstation SERVICE_START_NAME : localSystem C:\TEMP>SC qc "SharedAccess" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: SharedAccess TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\System32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Internet Connection Sharing (ICS) DEPENDENCIES : Netman : WinMgmt : BFE SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "ShellHWDetection" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: ShellHWDetection TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : C:\Windows\System32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : ShellSvcGroup TAG : 0 DISPLAY_NAME : Shell Hardware Detection DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "SkypeUpdate" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: SkypeUpdate TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : "C:\Program Files (x86)\Skype\Updater\Updater.exe" LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Skype Updater DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "smphost" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: smphost TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\System32\svchost.exe -k smphost LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Microsoft Storage Spaces SMP DEPENDENCIES : RPCSS SERVICE_START_NAME : NT AUTHORITY\NetworkService C:\TEMP>SC qc "SNMPTRAP" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: SNMPTRAP TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\System32\snmptrap.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : SNMP Trap DEPENDENCIES : SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "Spooler" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: Spooler TYPE : 110 WIN32_OWN_PROCESS (interactive) START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\System32\spoolsv.exe LOAD_ORDER_GROUP : SpoolerGroup TAG : 0 DISPLAY_NAME : Print Spooler DEPENDENCIES : RPCSS : http SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "sppsvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: sppsvc TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 2 AUTO_START (DELAYED) ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\sppsvc.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Software Protection DEPENDENCIES : RpcSs SERVICE_START_NAME : NT AUTHORITY\NetworkService C:\TEMP>SC qc "SQLWriter" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: SQLWriter TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : "C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe" LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : SQL Server VSS Writer DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "SSDPSRV" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: SSDPSRV TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : SSDP Discovery DEPENDENCIES : HTTP SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "SstpSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: SstpSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k LocalService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Secure Socket Tunneling Protocol Service DEPENDENCIES : SERVICE_START_NAME : NT Authority\LocalService C:\TEMP>SC qc "stisvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: stisvc TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k imgsvc LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Image Acquisition (WIA) DEPENDENCIES : RpcSs SERVICE_START_NAME : NT Authority\LocalService C:\TEMP>SC qc "StorSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: StorSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Storage Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "svsvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: svsvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Spot Verifier DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "SwitchBoard" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: SwitchBoard TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : "C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Adobe SwitchBoard DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "swprv" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: swprv TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\System32\svchost.exe -k swprv LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Microsoft Software Shadow Copy Provider DEPENDENCIES : RPCSS SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "SysMain" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: SysMain TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Superfetch DEPENDENCIES : rpcss : fileinfo SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "SystemEventsBroker" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: SystemEventsBroker TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k DcomLaunch LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : System Events Broker DEPENDENCIES : RpcEptMapper : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "TabletInputService" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: TabletInputService TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : PlugPlay TAG : 0 DISPLAY_NAME : Touch Keyboard and Handwriting Panel Service DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "TapiSrv" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: TapiSrv TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\System32\svchost.exe -k NetworkService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Telephony DEPENDENCIES : RpcSs SERVICE_START_NAME : NT AUTHORITY\NetworkService C:\TEMP>SC qc "Te.Service" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: Te.Service TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : "C:\Program Files (x86)\Windows Kits\10\Testing\Runtimes\TAEF\Wex.Services.exe" LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Te.Service DEPENDENCIES : RpcSs : SecLogon SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "TermService" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: TermService TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\System32\svchost.exe -k NetworkService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Remote Desktop Services DEPENDENCIES : RPCSS SERVICE_START_NAME : NT Authority\NetworkService C:\TEMP>SC qc "Themes" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: Themes TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\System32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : ProfSvc_Group TAG : 0 DISPLAY_NAME : Themes DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "THREADORDER" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: THREADORDER TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k LocalService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Thread Ordering Server DEPENDENCIES : SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "TimeBroker" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: TimeBroker TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Time Broker DEPENDENCIES : SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "TrkWks" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: TrkWks TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Distributed Link Tracking Client DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "TrustedInstaller" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: TrustedInstaller TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\servicing\TrustedInstaller.exe LOAD_ORDER_GROUP : ProfSvc_Group TAG : 0 DISPLAY_NAME : Windows Modules Installer DEPENDENCIES : SERVICE_START_NAME : localSystem C:\TEMP>SC qc "UI0Detect" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: UI0Detect TYPE : 110 WIN32_OWN_PROCESS (interactive) START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\UI0Detect.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Interactive Services Detection DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "UmRdpService" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: UmRdpService TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Remote Desktop Services UserMode Port Redirector DEPENDENCIES : TermService : RDPDR SERVICE_START_NAME : localSystem C:\TEMP>SC qc "upnphost" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: upnphost TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : UPnP Device Host DEPENDENCIES : SSDPSRV : HTTP SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "VaultSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: VaultSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\lsass.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Credential Manager DEPENDENCIES : rpcss SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "vds" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: vds TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\System32\vds.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Virtual Disk DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "VMAuthdService" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: VMAuthdService TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : "C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe" LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : VMware Authorization Service DEPENDENCIES : vmx86 : winmgmt SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "vmicguestinterface" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: vmicguestinterface TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Hyper-V Guest Service Interface DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "vmicheartbeat" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: vmicheartbeat TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k ICService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Hyper-V Heartbeat Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "vmickvpexchange" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: vmickvpexchange TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Hyper-V Data Exchange Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "vmicrdv" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: vmicrdv TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k ICService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Hyper-V Remote Desktop Virtualization Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "vmicshutdown" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: vmicshutdown TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Hyper-V Guest Shutdown Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "vmictimesync" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: vmictimesync TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Hyper-V Time Synchronization Service DEPENDENCIES : SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "vmicvss" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: vmicvss TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Hyper-V Volume Shadow Copy Requestor DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "VMnetDHCP" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: VMnetDHCP TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\SysWOW64\vmnetdhcp.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : VMware DHCP Service DEPENDENCIES : VMnetuserif SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "VMUSBArbService" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: VMUSBArbService TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : "C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe" LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : VMware USB Arbitration Service DEPENDENCIES : winmgmt SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "VMware NAT Service" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: VMware NAT Service TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\SysWOW64\vmnat.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : VMware NAT Service DEPENDENCIES : VMnetuserif SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "VMwareHostd" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: VMwareHostd TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : "C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe" -u "C:\ProgramData\VMware\hostd\config.xml" LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : VMware Workstation Server DEPENDENCIES : VMAuthdService : VMUSBArbService : lanmanworkstation SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "VsEtwService120" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: VsEtwService120 TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : "C:\Program Files\Microsoft Visual Studio 12.0\Common7\Packages\Debugger\Services\VsEtwService.exe" LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Visual Studio ETW Event Collection Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "VSS" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: VSS TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\vssvc.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Volume Shadow Copy DEPENDENCIES : RPCSS SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "VSStandardCollectorService140" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: VSStandardCollectorService140 TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : "C:\Program Files (x86)\Microsoft Visual Studio 14.0\Team Tools\DiagnosticsHub\Collector\StandardCollector.Service.exe" LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Visual Studio Standard Collector Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "VSStandardCollectorService150" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: VSStandardCollectorService150 TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : "C:\Program Files (x86)\Microsoft Visual Studio\Shared\Common\DiagnosticsHub.Collection.Service\StandardCollector.Service.exe" LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Visual Studio Standard Collector Service 150 DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "W32Time" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: W32Time TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k LocalService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Time DEPENDENCIES : SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "wbengine" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: wbengine TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : "C:\Windows\system32\wbengine.exe" LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Block Level Backup Engine Service DEPENDENCIES : SERVICE_START_NAME : localSystem C:\TEMP>SC qc "WbioSrvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: WbioSrvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k WbioSvcGroup LOAD_ORDER_GROUP : SmartCardGroup TAG : 0 DISPLAY_NAME : Windows Biometric Service DEPENDENCIES : RpcSs : VaultSvc : WUDFSvc SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "Wcmsvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: Wcmsvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted LOAD_ORDER_GROUP : TDI TAG : 0 DISPLAY_NAME : Windows Connection Manager DEPENDENCIES : RpcSs SERVICE_START_NAME : NT Authority\LocalService C:\TEMP>SC qc "wcncsvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: wcncsvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\System32\svchost.exe -k LocalServiceAndNoImpersonation LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Connect Now - Config Registrar DEPENDENCIES : rpcss SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "WcsPlugInService" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: WcsPlugInService TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k wcssvc LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Color System DEPENDENCIES : RpcSs SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "WdiServiceHost" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: WdiServiceHost TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\System32\svchost.exe -k LocalService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Diagnostic Service Host DEPENDENCIES : SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "WdiSystemHost" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: WdiSystemHost TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Diagnostic System Host DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "WdNisSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: WdNisSvc TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : "C:\Program Files\Windows Defender\NisSrv.exe" LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Defender Network Inspection Service DEPENDENCIES : WdNisDrv SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "WebClient" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: WebClient TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k LocalService LOAD_ORDER_GROUP : NetworkProvider TAG : 0 DISPLAY_NAME : WebClient DEPENDENCIES : MRxDAV SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "Wecsvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: Wecsvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k NetworkService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Event Collector DEPENDENCIES : HTTP : Eventlog SERVICE_START_NAME : NT AUTHORITY\NetworkService C:\TEMP>SC qc "WEPHOSTSVC" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: WEPHOSTSVC TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k WepHostSvcGroup LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Encryption Provider Host Service DEPENDENCIES : rpcss SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "wercplsupport" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: wercplsupport TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\System32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Problem Reports and Solutions Control Panel Support DEPENDENCIES : SERVICE_START_NAME : localSystem C:\TEMP>SC qc "WerSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: WerSvc TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : C:\Windows\System32\svchost.exe -k WerSvcGroup LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Error Reporting Service DEPENDENCIES : SERVICE_START_NAME : localSystem C:\TEMP>SC qc "WiaRpc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: WiaRpc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Still Image Acquisition Events DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "WinDefend" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: WinDefend TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : "C:\Program Files\Windows Defender\MsMpEng.exe" LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Defender Service DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "Windows10FirewallService" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: Windows10FirewallService TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : "C:\Program Files\Windows10FirewallControl\Windows10FirewallService.exe" LOAD_ORDER_GROUP : NetworkProvider TAG : 0 DISPLAY_NAME : Windows10FirewallService DEPENDENCIES : BFE SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "WinHttpAutoProxySvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: WinHttpAutoProxySvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k LocalService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : WinHTTP Web Proxy Auto-Discovery Service DEPENDENCIES : Dhcp SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "Winmgmt" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: Winmgmt TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Management Instrumentation DEPENDENCIES : RPCSS SERVICE_START_NAME : localSystem C:\TEMP>SC qc "WinRM" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: WinRM TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\System32\svchost.exe -k NetworkService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Remote Management (WS-Management) DEPENDENCIES : RPCSS : HTTP SERVICE_START_NAME : NT AUTHORITY\NetworkService C:\TEMP>SC qc "WlanSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: WlanSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TDI TAG : 0 DISPLAY_NAME : WLAN AutoConfig DEPENDENCIES : nativewifip : RpcSs : Ndisuio : wcmsvc SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "wlidsvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: wlidsvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Microsoft Account Sign-in Assistant DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "wmiApSrv" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: wmiApSrv TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\wbem\WmiApSrv.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : WMI Performance Adapter DEPENDENCIES : SERVICE_START_NAME : localSystem C:\TEMP>SC qc "WMPNetworkSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: WMPNetworkSvc TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : "C:\Program Files\Windows Media Player\wmpnetwk.exe" LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Media Player Network Sharing Service DEPENDENCIES : http : WSearch SERVICE_START_NAME : NT AUTHORITY\NetworkService C:\TEMP>SC qc "WPCSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: WPCSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Family Safety DEPENDENCIES : RpcSs SERVICE_START_NAME : NT Authority\LocalService C:\TEMP>SC qc "WPDBusEnum" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: WPDBusEnum TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Portable Device Enumerator Service DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "wscsvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: wscsvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START (DELAYED) ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Security Center DEPENDENCIES : RpcSs : WinMgmt SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "WSearch" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: WSearch TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\SearchIndexer.exe /Embedding LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Search DEPENDENCIES : RPCSS SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "WSService" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: WSService TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\System32\svchost.exe -k wsappx LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Store Service (WSService) DEPENDENCIES : rpcss SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "wuauserv" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: wuauserv TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Update DEPENDENCIES : rpcss SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "wudfsvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: wudfsvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : PlugPlay TAG : 0 DISPLAY_NAME : Windows Driver Foundation - User-mode Driver Framework DEPENDENCIES : WudfPf SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "WwanSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: WwanSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork LOAD_ORDER_GROUP : TDI TAG : 0 DISPLAY_NAME : WWAN AutoConfig DEPENDENCIES : RpcSs : NdisUio : wcmsvc SERVICE_START_NAME : NT Authority\LocalService C:\TEMP>SC qc "Z-VSScopy" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: Z-VSScopy TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Program Files (x86)\Z-VSScopy\Z-VSScopy.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Z-VSScopy DEPENDENCIES : SERVICE_START_NAME : LocalSystem ------------------------------------------------------------------------------------------- WMIC qfe list (list of all installed updates): Caption CSName Description FixComments HotFixID InstallDate InstalledBy InstalledOn Name ServicePackInEffect Status http://support.microsoft.com/kb/2899189 NOELC4 Update KB2899189_Microsoft-Windows-CameraCodec-Package NoelC4\NoelC 12/11/2013 http://support.microsoft.com/?kbid=2868626 NOELC4 Security Update KB2868626 NT AUTHORITY\SYSTEM 11/13/2013 http://support.microsoft.com/?kbid=2883200 NOELC4 Update KB2883200 NT AUTHORITY\SYSTEM 11/13/2013 http://support.microsoft.com/?kbid=2887595 NOELC4 Update KB2887595 NT AUTHORITY\SYSTEM 11/13/2013 http://support.microsoft.com/?kbid=2894852 NOELC4 Security Update KB2894852 NoelC4\NoelC 9/10/2014 http://support.microsoft.com/?kbid=2894856 NOELC4 Security Update KB2894856 NoelC4\NoelC 9/10/2014 http://support.microsoft.com/?kbid=2903939 NOELC4 Update KB2903939 NT AUTHORITY\SYSTEM 12/11/2013 http://support.microsoft.com/?kbid=2904440 NOELC4 Update KB2904440 NT AUTHORITY\SYSTEM 1/14/2014 http://support.microsoft.com/?kbid=2911106 NOELC4 Update KB2911106 NoelC4\NoelC 1/14/2014 http://support.microsoft.com/?kbid=2919355 NOELC4 Update KB2919355 NoelC4\NoelC 4/9/2014 http://support.microsoft.com/?kbid=2919394 NOELC4 Update KB2919394 NT AUTHORITY\SYSTEM 2/11/2014 http://support.microsoft.com/?kbid=2919442 NOELC4 Update KB2919442 NoelC4\NoelC 3/12/2014 http://support.microsoft.com/?kbid=2920189 NOELC4 Security Update KB2920189 NoelC4\NoelC 5/13/2014 http://support.microsoft.com/?kbid=2928680 NOELC4 Update KB2928680 NT AUTHORITY\SYSTEM 3/12/2014 http://support.microsoft.com/?kbid=2934520 NOELC4 Update KB2934520 NoelC4\NoelC 1/16/2015 http://support.microsoft.com/?kbid=2954879 NOELC4 Update KB2954879 NoelC4\NoelC 5/13/2014 http://support.microsoft.com/?kbid=2955164 NOELC4 Update KB2955164 NT AUTHORITY\SYSTEM 5/13/2014 http://support.microsoft.com/?kbid=2959626 NOELC4 Hotfix KB2959626 NT AUTHORITY\SYSTEM 7/8/2014 http://support.microsoft.com/?kbid=2962409 NOELC4 Update KB2962409 NT AUTHORITY\SYSTEM 6/10/2014 http://support.microsoft.com/?kbid=2962806 NOELC4 Update KB2962806 NoelC4\NoelC 1/16/2015 http://support.microsoft.com/?kbid=2965142 NOELC4 Update KB2965142 NT AUTHORITY\SYSTEM 6/10/2014 http://support.microsoft.com/?kbid=2965500 NOELC4 Update KB2965500 NoelC4\NoelC 5/13/2014 http://support.microsoft.com/?kbid=2966826 NOELC4 Security Update KB2966826 NT AUTHORITY\SYSTEM 8/12/2014 http://support.microsoft.com/?kbid=2966828 NOELC4 Security Update KB2966828 NoelC4\NoelC 8/12/2014 http://support.microsoft.com/?kbid=2967917 NOELC4 Update KB2967917 NT AUTHORITY\SYSTEM 7/8/2014 http://support.microsoft.com/?kbid=2968296 NOELC4 Security Update KB2968296 NoelC4\NoelC 10/16/2014 http://support.microsoft.com/?kbid=2969339 NOELC4 Update KB2969339 NoelC4\NoelC 6/10/2014 http://support.microsoft.com/?kbid=2971203 NOELC4 Update KB2971203 NT AUTHORITY\SYSTEM 7/8/2014 http://support.microsoft.com/?kbid=2972103 NOELC4 Security Update KB2972103 NoelC4\NoelC 10/16/2014 http://support.microsoft.com/?kbid=2972213 NOELC4 Security Update KB2972213 NoelC4\NoelC 9/10/2014 http://support.microsoft.com/?kbid=2973114 NOELC4 Security Update KB2973114 NoelC4\NoelC 9/10/2014 http://support.microsoft.com/?kbid=2973201 NOELC4 Security Update KB2973201 NT AUTHORITY\SYSTEM 7/8/2014 http://support.microsoft.com/?kbid=2973351 NOELC4 Security Update KB2973351 NT AUTHORITY\SYSTEM 7/8/2014 http://support.microsoft.com/?kbid=2975061 NOELC4 Update KB2975061 NoelC4\NoelC 7/8/2014 http://support.microsoft.com/?kbid=2975719 NOELC4 Update KB2975719 NT AUTHORITY\SYSTEM 9/3/2014 http://support.microsoft.com/?kbid=2976627 NOELC4 Security Update KB2976627 NT AUTHORITY\SYSTEM 8/12/2014 http://support.microsoft.com/?kbid=2977629 NOELC4 Security Update KB2977629 NT AUTHORITY\SYSTEM 9/10/2014 http://support.microsoft.com/?kbid=2977765 NOELC4 Security Update KB2977765 NT AUTHORITY\SYSTEM 9/10/2014 http://support.microsoft.com/?kbid=2978041 NOELC4 Security Update KB2978041 NoelC4\NoelC 10/16/2014 http://support.microsoft.com/?kbid=2978122 NOELC4 Security Update KB2978122 NoelC4\NoelC 11/12/2014 http://support.microsoft.com/?kbid=2978126 NOELC4 Security Update KB2978126 NoelC4\NoelC 11/12/2014 http://support.microsoft.com/?kbid=2978742 NOELC4 Security Update KB2978742 NoelC4\NoelC 8/12/2014 http://support.microsoft.com/?kbid=2979576 NOELC4 Security Update KB2979576 NoelC4\NoelC 10/16/2014 http://support.microsoft.com/?kbid=2984006 NOELC4 Update KB2984006 NT AUTHORITY\SYSTEM 9/10/2014 http://support.microsoft.com/?kbid=2987107 NOELC4 Security Update KB2987107 NT AUTHORITY\SYSTEM 10/16/2014 http://support.microsoft.com/?kbid=2989647 NOELC4 Update KB2989647 NoelC4\NoelC 9/10/2014 http://support.microsoft.com/?kbid=2989930 NOELC4 Update KB2989930 NoelC4\NoelC 12/10/2014 http://support.microsoft.com/?kbid=2990967 NOELC4 Update KB2990967 NoelC4\NoelC 9/24/2014 http://support.microsoft.com/?kbid=2993100 NOELC4 Update KB2993100 NoelC4\NoelC 9/3/2014 http://support.microsoft.com/?kbid=2994290 NOELC4 Update KB2994290 NoelC4\NoelC 12/10/2014 http://support.microsoft.com/?kbid=2995004 NOELC4 Update KB2995004 NT AUTHORITY\SYSTEM 9/10/2014 http://support.microsoft.com/?kbid=2995388 NOELC4 Update KB2995388 NT AUTHORITY\SYSTEM 10/16/2014 http://support.microsoft.com/?kbid=2996799 NOELC4 Hotfix KB2996799 NT AUTHORITY\SYSTEM 10/16/2014 http://support.microsoft.com/?kbid=2998174 NOELC4 Update KB2998174 NT AUTHORITY\SYSTEM 10/16/2014 http://support.microsoft.com/?kbid=2999226 NOELC4 Update KB2999226 NoelC4\NoelC 12/15/2015 http://support.microsoft.com/?kbid=3000850 NOELC4 Update KB3000850 NoelC4\NoelC 11/20/2014 http://support.microsoft.com/?kbid=3003057 NOELC4 Security Update KB3003057 NT AUTHORITY\SYSTEM 11/12/2014 http://support.microsoft.com/?kbid=3003667 NOELC4 Update KB3003667 NoelC4\NoelC 11/12/2014 http://support.microsoft.com/?kbid=3004361 NOELC4 Security Update KB3004361 NT AUTHORITY\SYSTEM 2/13/2015 http://support.microsoft.com/?kbid=3004365 NOELC4 Security Update KB3004365 NoelC4\NoelC 7/16/2015 http://support.microsoft.com/?kbid=3004394 NOELC4 Update KB3004394 NT AUTHORITY\SYSTEM 12/10/2014 http://support.microsoft.com/?kbid=3004545 NOELC4 Hotfix KB3004545 NT AUTHORITY\SYSTEM 4/14/2015 http://support.microsoft.com/?kbid=3008923 NOELC4 Security Update KB3008923 NT AUTHORITY\SYSTEM 12/10/2014 http://support.microsoft.com/?kbid=3012199 NOELC4 Update KB3012199 NoelC4\NoelC 12/10/2014 http://support.microsoft.com/?kbid=3012235 NOELC4 Update KB3012235 NoelC4\NoelC 3/12/2015 http://support.microsoft.com/?kbid=3012702 NOELC4 Update KB3012702 NoelC4\NoelC 3/12/2015 http://support.microsoft.com/?kbid=3013172 NOELC4 Update KB3013172 NoelC4\NoelC 3/12/2015 http://support.microsoft.com/?kbid=3013531 NOELC4 Update KB3013531 NoelC4\NoelC 4/22/2015 http://support.microsoft.com/?kbid=3013538 NOELC4 Update KB3013538 NoelC4\NoelC 4/22/2015 http://support.microsoft.com/?kbid=3013769 NOELC4 Update KB3013769 NT AUTHORITY\SYSTEM 12/10/2014 http://support.microsoft.com/?kbid=3013791 NOELC4 Update KB3013791 NT AUTHORITY\SYSTEM 6/17/2015 http://support.microsoft.com/?kbid=3013816 NOELC4 Update KB3013816 NT AUTHORITY\SYSTEM 12/10/2014 http://support.microsoft.com/?kbid=3014442 NOELC4 Update KB3014442 NoelC4\NoelC 11/20/2014 http://support.microsoft.com/?kbid=3015696 NOELC4 Update KB3015696 NoelC4\NoelC 4/22/2015 http://support.microsoft.com/?kbid=3018133 NOELC4 Update KB3018133 NoelC4\NoelC 3/12/2015 http://support.microsoft.com/?kbid=3019978 NOELC4 Security Update KB3019978 NoelC4\NoelC 1/16/2015 http://support.microsoft.com/?kbid=3020338 NOELC4 Update KB3020338 NT AUTHORITY\SYSTEM 2/13/2015 http://support.microsoft.com/?kbid=3020370 NOELC4 Update KB3020370 NoelC4\NoelC 4/22/2015 http://support.microsoft.com/?kbid=3021910 NOELC4 Update KB3021910 NoelC4\NoelC 5/1/2015 http://support.microsoft.com/?kbid=3021952 NOELC4 Security Update KB3021952 NT AUTHORITY\SYSTEM 2/13/2015 http://support.microsoft.com/?kbid=3022777 NOELC4 Security Update KB3022777 NT AUTHORITY\SYSTEM 1/16/2015 http://support.microsoft.com/?kbid=3023219 NOELC4 Security Update KB3023219 NoelC4\NoelC 5/14/2015 http://support.microsoft.com/?kbid=3023222 NOELC4 Security Update KB3023222 NoelC4\NoelC 5/14/2015 http://support.microsoft.com/?kbid=3023266 NOELC4 Security Update KB3023266 NoelC4\NoelC 1/16/2015 http://support.microsoft.com/?kbid=3024751 NOELC4 Update KB3024751 NoelC4\NoelC 3/12/2015 http://support.microsoft.com/?kbid=3024755 NOELC4 Update KB3024755 NoelC4\NoelC 3/12/2015 http://support.microsoft.com/?kbid=3029432 NOELC4 Update KB3029432 NT AUTHORITY\SYSTEM 5/20/2015 http://support.microsoft.com/?kbid=3029603 NOELC4 Update KB3029603 NT AUTHORITY\SYSTEM 5/20/2015 http://support.microsoft.com/?kbid=3029606 NOELC4 Update KB3029606 NT AUTHORITY\SYSTEM 6/17/2015 http://support.microsoft.com/?kbid=3030377 NOELC4 Security Update KB3030377 NT AUTHORITY\SYSTEM 3/12/2015 http://support.microsoft.com/?kbid=3030947 NOELC4 Update KB3030947 NoelC4\NoelC 3/12/2015 http://support.microsoft.com/?kbid=3032359 NOELC4 Security Update KB3032359 NT AUTHORITY\SYSTEM 3/12/2015 http://support.microsoft.com/?kbid=3032663 NOELC4 Security Update KB3032663 NoelC4\NoelC 5/14/2015 http://support.microsoft.com/?kbid=3033446 NOELC4 Update KB3033446 NT AUTHORITY\SYSTEM 4/22/2015 http://support.microsoft.com/?kbid=3034348 NOELC4 Update KB3034348 NT AUTHORITY\SYSTEM 10/24/2015 http://support.microsoft.com/?kbid=3035126 NOELC4 Security Update KB3035126 NoelC4\NoelC 3/12/2015 http://support.microsoft.com/?kbid=3036612 NOELC4 Update KB3036612 NT AUTHORITY\SYSTEM 3/12/2015 http://support.microsoft.com/?kbid=3037576 NOELC4 Security Update KB3037576 NoelC4\NoelC 4/14/2015 http://support.microsoft.com/?kbid=3037579 NOELC4 Security Update KB3037579 NoelC4\NoelC 4/14/2015 http://support.microsoft.com/?kbid=3037924 NOELC4 Update KB3037924 NT AUTHORITY\SYSTEM 4/22/2015 http://support.microsoft.com/?kbid=3038002 NOELC4 Update KB3038002 NT AUTHORITY\SYSTEM 4/22/2015 http://support.microsoft.com/?kbid=3038314 NOELC4 Security Update KB3038314 NT AUTHORITY\SYSTEM 4/14/2015 http://support.microsoft.com/?kbid=3038701 NOELC4 Hotfix KB3038701 NT AUTHORITY\SYSTEM 4/22/2015 http://support.microsoft.com/?kbid=3038936 NOELC4 Security Update KB3038936 NoelC4\NoelC 8/12/2015 http://support.microsoft.com/?kbid=3041857 NOELC4 Update KB3041857 NT AUTHORITY\SYSTEM 5/20/2015 http://support.microsoft.com/?kbid=3042085 NOELC4 Update KB3042085 NT AUTHORITY\SYSTEM 4/11/2015 http://support.microsoft.com/?kbid=3042553 NOELC4 Security Update KB3042553 NT AUTHORITY\SYSTEM 4/14/2015 http://support.microsoft.com/?kbid=3044374 NOELC4 Update KB3044374 NT AUTHORITY\SYSTEM 4/19/2015 http://support.microsoft.com/?kbid=3044673 NOELC4 Update KB3044673 NT AUTHORITY\SYSTEM 4/22/2015 http://support.microsoft.com/?kbid=3045563 NOELC4 Update KB3045563 NoelC4\NoelC 9/21/2015 http://support.microsoft.com/?kbid=3045634 NOELC4 Update KB3045634 NoelC4\NoelC 5/20/2015 http://support.microsoft.com/?kbid=3045685 NOELC4 Security Update KB3045685 NT AUTHORITY\SYSTEM 4/14/2015 http://support.microsoft.com/?kbid=3045717 NOELC4 Update KB3045717 NoelC4\NoelC 4/22/2015 http://support.microsoft.com/?kbid=3045719 NOELC4 Update KB3045719 NoelC4\NoelC 4/22/2015 http://support.microsoft.com/?kbid=3045755 NOELC4 Security Update KB3045755 NT AUTHORITY\SYSTEM 4/14/2015 http://support.microsoft.com/?kbid=3045992 NOELC4 Update KB3045992 NT AUTHORITY\SYSTEM 4/22/2015 http://support.microsoft.com/?kbid=3045999 NOELC4 Security Update KB3045999 NT AUTHORITY\SYSTEM 4/14/2015 http://support.microsoft.com/?kbid=3046017 NOELC4 Security Update KB3046017 NoelC4\NoelC 8/12/2015 http://support.microsoft.com/?kbid=3046359 NOELC4 Security Update KB3046359 NT AUTHORITY\SYSTEM 7/16/2015 http://support.microsoft.com/?kbid=3046737 NOELC4 Hotfix KB3046737 NoelC4\NoelC 4/22/2015 http://support.microsoft.com/?kbid=3047254 NOELC4 Update KB3047254 NT AUTHORITY\SYSTEM 4/22/2015 http://support.microsoft.com/?kbid=3048043 NOELC4 Update KB3048043 NT AUTHORITY\SYSTEM 5/14/2015 http://support.microsoft.com/?kbid=3049563 NOELC4 Security Update KB3049563 NT AUTHORITY\SYSTEM 5/14/2015 http://support.microsoft.com/?kbid=3050267 NOELC4 Update KB3050267 NT AUTHORITY\SYSTEM 6/3/2015 http://support.microsoft.com/?kbid=3053863 NOELC4 Update KB3053863 NoelC4\NoelC 6/17/2015 http://support.microsoft.com/?kbid=3053946 NOELC4 Update KB3053946 NoelC4\NoelC 4/22/2015 http://support.microsoft.com/?kbid=3054169 NOELC4 Update KB3054169 NT AUTHORITY\SYSTEM 5/1/2015 http://support.microsoft.com/?kbid=3054256 NOELC4 Update KB3054256 NT AUTHORITY\SYSTEM 6/17/2015 http://support.microsoft.com/?kbid=3054464 NOELC4 Update KB3054464 NT AUTHORITY\SYSTEM 5/20/2015 http://support.microsoft.com/?kbid=3055323 NOELC4 Update KB3055323 NoelC4\NoelC 5/20/2015 http://support.microsoft.com/?kbid=3055343 NOELC4 Update KB3055343 NT AUTHORITY\SYSTEM 7/29/2015 http://support.microsoft.com/?kbid=3055642 NOELC4 Security Update KB3055642 NT AUTHORITY\SYSTEM 5/14/2015 http://support.microsoft.com/?kbid=3056347 NOELC4 Update KB3056347 NoelC4\NoelC 6/17/2015 http://support.microsoft.com/?kbid=3058168 NOELC4 Update KB3058168 NoelC4\NoelC 6/17/2015 http://support.microsoft.com/?kbid=3058515 NOELC4 Security Update KB3058515 NT AUTHORITY\SYSTEM 6/10/2015 http://support.microsoft.com/?kbid=3059316 NOELC4 Update KB3059316 NT AUTHORITY\SYSTEM 6/17/2015 http://support.microsoft.com/?kbid=3059317 NOELC4 Security Update KB3059317 NT AUTHORITY\SYSTEM 6/10/2015 http://support.microsoft.com/?kbid=3060793 NOELC4 Update KB3060793 NT AUTHORITY\SYSTEM 6/17/2015 http://support.microsoft.com/?kbid=3061493 NOELC4 Update KB3061493 NT AUTHORITY\SYSTEM 7/22/2015 http://support.microsoft.com/?kbid=3061512 NOELC4 Security Update KB3061512 NoelC4\NoelC 7/16/2015 http://support.microsoft.com/?kbid=3062760 NOELC4 Security Update KB3062760 NoelC4\NoelC 6/10/2015 http://support.microsoft.com/?kbid=3063843 NOELC4 Update KB3063843 NT AUTHORITY\SYSTEM 6/17/2015 http://support.microsoft.com/?kbid=3064059 NOELC4 Update KB3064059 NoelC4\NoelC 6/17/2015 http://support.microsoft.com/?kbid=3064209 NOELC4 Update KB3064209 NT AUTHORITY\SYSTEM 6/17/2015 http://support.microsoft.com/?kbid=3065822 NOELC4 Security Update KB3065822 NT AUTHORITY\SYSTEM 7/16/2015 http://support.microsoft.com/?kbid=3065988 NOELC4 Update KB3065988 NoelC4\NoelC 7/16/2015 http://support.microsoft.com/?kbid=3071756 NOELC4 Security Update KB3071756 NoelC4\NoelC 8/12/2015 http://support.microsoft.com/?kbid=3072019 NOELC4 Update KB3072019 NT AUTHORITY\SYSTEM 7/22/2015 http://support.microsoft.com/?kbid=3072307 NOELC4 Security Update KB3072307 NoelC4\NoelC 8/12/2015 http://support.microsoft.com/?kbid=3074228 NOELC4 Security Update KB3074228 NoelC4\NoelC 9/9/2015 http://support.microsoft.com/?kbid=3074545 NOELC4 Security Update KB3074545 NoelC4\NoelC 9/9/2015 http://support.microsoft.com/?kbid=3074548 NOELC4 Security Update KB3074548 NoelC4\NoelC 9/9/2015 http://support.microsoft.com/?kbid=3075220 NOELC4 Security Update KB3075220 NoelC4\NoelC 8/12/2015 http://support.microsoft.com/?kbid=3075853 NOELC4 Update KB3075853 NT AUTHORITY\SYSTEM 8/8/2015 http://support.microsoft.com/?kbid=3076949 NOELC4 Security Update KB3076949 NoelC4\NoelC 8/12/2015 http://support.microsoft.com/?kbid=3077715 NOELC4 Update KB3077715 NoelC4\NoelC 8/20/2015 http://support.microsoft.com/?kbid=3078071 NOELC4 Security Update KB3078071 NoelC4\NoelC 8/12/2015 http://support.microsoft.com/?kbid=3078405 NOELC4 Update KB3078405 NoelC4\NoelC 10/24/2015 http://support.microsoft.com/?kbid=3078676 NOELC4 Update KB3078676 NT AUTHORITY\SYSTEM 8/20/2015 http://support.microsoft.com/?kbid=3079318 NOELC4 Update KB3079318 NT AUTHORITY\SYSTEM 8/20/2015 http://support.microsoft.com/?kbid=3080042 NOELC4 Update KB3080042 NoelC4\NoelC 9/21/2015 http://support.microsoft.com/?kbid=3080800 NOELC4 Update KB3080800 NoelC4\NoelC 9/21/2015 http://support.microsoft.com/?kbid=3082089 NOELC4 Security Update KB3082089 NT AUTHORITY\SYSTEM 9/9/2015 http://support.microsoft.com/?kbid=3083185 NOELC4 Security Update KB3083185 NoelC4\NoelC 9/21/2015 http://support.microsoft.com/?kbid=3083325 NOELC4 Update KB3083325 NT AUTHORITY\SYSTEM 9/9/2015 http://support.microsoft.com/?kbid=3083992 NOELC4 Security Update KB3083992 NoelC4\NoelC 9/9/2015 http://support.microsoft.com/?kbid=3084135 NOELC4 Security Update KB3084135 NT AUTHORITY\SYSTEM 9/9/2015 http://support.microsoft.com/?kbid=3084905 NOELC4 Update KB3084905 NT AUTHORITY\SYSTEM 10/16/2015 http://support.microsoft.com/?kbid=3086255 NOELC4 Security Update KB3086255 NoelC4\NoelC 9/9/2015 http://support.microsoft.com/?kbid=3087038 NOELC4 Security Update KB3087038 NT AUTHORITY\SYSTEM 9/9/2015 http://support.microsoft.com/?kbid=3087040 NOELC4 Update KB3087040 NoelC4\NoelC 9/21/2015 http://support.microsoft.com/?kbid=3087041 NOELC4 Update KB3087041 NoelC4\NoelC 9/21/2015 http://support.microsoft.com/?kbid=3087137 NOELC4 Update KB3087137 NoelC4\NoelC 9/21/2015 http://support.microsoft.com/?kbid=3087916 NOELC4 Security Update KB3087916 NoelC4\NoelC 8/12/2015 http://support.microsoft.com/?kbid=3089023 NOELC4 Update KB3089023 NoelC4\NoelC 8/20/2015 http://support.microsoft.com/?kbid=3091297 NOELC4 Update KB3091297 NoelC4\NoelC 10/24/2015 http://support.microsoft.com/?kbid=3092601 NOELC4 Security Update KB3092601 NoelC4\NoelC 12/11/2015 http://support.microsoft.com/?kbid=3092627 NOELC4 Update KB3092627 NT AUTHORITY\SYSTEM 9/9/2015 http://support.microsoft.com/?kbid=3093983 NOELC4 Security Update KB3093983 NT AUTHORITY\SYSTEM 10/16/2015 http://support.microsoft.com/?kbid=3095108 NOELC4 Update KB3095108 NoelC4\NoelC 10/24/2015 http://support.microsoft.com/?kbid=3095701 NOELC4 Update KB3095701 NoelC4\NoelC 10/24/2015 http://support.microsoft.com/?kbid=3096433 NOELC4 Update KB3096433 NoelC4\NoelC 10/24/2015 http://support.microsoft.com/?kbid=3097966 NOELC4 Security Update KB3097966 NT AUTHORITY\SYSTEM 10/16/2015 http://support.microsoft.com/?kbid=3097992 NOELC4 Security Update KB3097992 NoelC4\NoelC 12/11/2015 http://support.microsoft.com/?kbid=3098785 NOELC4 Security Update KB3098785 NoelC4\NoelC 3/18/2016 http://support.microsoft.com/?kbid=3099406 NOELC4 Security Update KB3099406 NoelC4\NoelC 10/16/2015 http://support.microsoft.com/?kbid=3099834 NOELC4 Update KB3099834 NoelC4\NoelC 12/11/2015 http://support.microsoft.com/?kbid=3100473 NOELC4 Update KB3100473 NoelC4\NoelC 3/18/2016 http://support.microsoft.com/?kbid=3100919 NOELC4 Update KB3100919 NoelC4\NoelC 12/11/2015 http://support.microsoft.com/?kbid=3100956 NOELC4 Update KB3100956 NoelC4\NoelC 12/11/2015 http://support.microsoft.com/?kbid=3102429 NOELC4 Update KB3102429 NoelC4\NoelC 3/18/2016 http://support.microsoft.com/?kbid=3102467 NOELC4 Update KB3102467 NoelC4\NoelC 12/15/2015 http://support.microsoft.com/?kbid=3103616 NOELC4 Update KB3103616 NoelC4\NoelC 4/21/2016 http://support.microsoft.com/?kbid=3103688 NOELC4 Security Update KB3103688 NoelC4\NoelC 12/11/2015 http://support.microsoft.com/?kbid=3103696 NOELC4 Update KB3103696 NoelC4\NoelC 12/11/2015 http://support.microsoft.com/?kbid=3103699 NOELC4 Update KB3103699 NoelC4\NoelC 3/18/2016 http://support.microsoft.com/?kbid=3103709 NOELC4 Update KB3103709 NT AUTHORITY\SYSTEM 4/21/2016 http://support.microsoft.com/?kbid=3104002 NOELC4 Security Update KB3104002 NoelC4\NoelC 12/11/2015 http://support.microsoft.com/?kbid=3105216 NOELC4 Security Update KB3105216 NoelC4\NoelC 10/24/2015 http://support.microsoft.com/?kbid=3109094 NOELC4 Security Update KB3109094 NoelC4\NoelC 12/11/2015 http://support.microsoft.com/?kbid=3109103 NOELC4 Security Update KB3109103 NoelC4\NoelC 12/11/2015 http://support.microsoft.com/?kbid=3109560 NOELC4 Security Update KB3109560 NoelC4\NoelC 1/17/2016 http://support.microsoft.com/?kbid=3109976 NOELC4 Update KB3109976 NoelC4\NoelC 3/18/2016 http://support.microsoft.com/?kbid=3110329 NOELC4 Security Update KB3110329 NoelC4\NoelC 1/17/2016 http://support.microsoft.com/?kbid=3112148 NOELC4 Update KB3112148 NoelC4\NoelC 12/11/2015 http://support.microsoft.com/?kbid=3115224 NOELC4 Update KB3115224 NoelC4\NoelC 3/18/2016 http://support.microsoft.com/?kbid=3118401 NOELC4 Update KB3118401 NoelC4\NoelC 3/18/2016 http://support.microsoft.com/?kbid=3119147 NOELC4 Security Update KB3119147 NoelC4\NoelC 12/11/2015 http://support.microsoft.com/?kbid=3121255 NOELC4 Update KB3121255 NoelC4\NoelC 3/18/2016 http://support.microsoft.com/?kbid=3121261 NOELC4 Update KB3121261 NoelC4\NoelC 3/18/2016 http://support.microsoft.com/?kbid=3121918 NOELC4 Security Update KB3121918 NT AUTHORITY\SYSTEM 1/17/2016 http://support.microsoft.com/?kbid=3122651 NOELC4 Security Update KB3122651 NoelC4\NoelC 3/18/2016 http://support.microsoft.com/?kbid=3122660 NOELC4 Security Update KB3122660 NoelC4\NoelC 3/18/2016 http://support.microsoft.com/?kbid=3123242 NOELC4 Update KB3123242 NoelC4\NoelC 3/18/2016 http://support.microsoft.com/?kbid=3123479 NOELC4 Security Update KB3123479 NoelC4\NoelC 1/17/2016 http://support.microsoft.com/?kbid=3124275 NOELC4 Security Update KB3124275 NoelC4\NoelC 1/17/2016 http://support.microsoft.com/?kbid=3124280 NOELC4 Security Update KB3124280 NoelC4\NoelC 3/18/2016 http://support.microsoft.com/?kbid=3125424 NOELC4 Update KB3125424 NT AUTHORITY\SYSTEM 4/21/2016 http://support.microsoft.com/?kbid=3126030 NOELC4 Update KB3126030 NoelC4\NoelC 3/18/2016 http://support.microsoft.com/?kbid=3126033 NOELC4 Update KB3126033 NoelC4\NoelC 3/18/2016 http://support.microsoft.com/?kbid=3126434 NOELC4 Security Update KB3126434 NoelC4\NoelC 3/18/2016 http://support.microsoft.com/?kbid=3126587 NOELC4 Security Update KB3126587 NoelC4\NoelC 3/18/2016 http://support.microsoft.com/?kbid=3126593 NOELC4 Security Update KB3126593 NoelC4\NoelC 3/18/2016 http://support.microsoft.com/?kbid=3127222 NOELC4 Security Update KB3127222 NoelC4\NoelC 3/18/2016 http://support.microsoft.com/?kbid=3127231 NOELC4 Security Update KB3127231 NoelC4\NoelC 3/18/2016 http://support.microsoft.com/?kbid=3128650 NOELC4 Update KB3128650 NoelC4\NoelC 3/18/2016 http://support.microsoft.com/?kbid=3132372 NOELC4 Security Update KB3132372 NoelC4\NoelC 12/31/2015 http://support.microsoft.com/?kbid=3133431 NOELC4 Update KB3133431 NoelC4\NoelC 1/17/2016 http://support.microsoft.com/?kbid=3133681 NOELC4 Update KB3133681 NoelC4\NoelC 3/18/2016 http://support.microsoft.com/?kbid=3133690 NOELC4 Update KB3133690 NoelC4\NoelC 3/18/2016 http://support.microsoft.com/?kbid=3133924 NOELC4 Update KB3133924 NoelC4\NoelC 3/18/2016 http://support.microsoft.com/?kbid=3134815 NOELC4 Update KB3134815 NoelC4\NoelC 3/18/2016 http://support.microsoft.com/?kbid=3135456 NOELC4 Security Update KB3135456 NT AUTHORITY\SYSTEM 4/18/2016 http://support.microsoft.com/?kbid=3135782 NOELC4 Security Update KB3135782 NoelC4\NoelC 3/18/2016 http://support.microsoft.com/?kbid=3135985 NOELC4 Security Update KB3135985 NoelC4\NoelC 3/18/2016 http://support.microsoft.com/?kbid=3135998 NOELC4 Security Update KB3135998 NoelC4\NoelC 5/16/2016 http://support.microsoft.com/?kbid=3136019 NOELC4 Update KB3136019 NoelC4\NoelC 3/18/2016 http://support.microsoft.com/?kbid=3137061 NOELC4 Update KB3137061 NoelC4\NoelC 3/18/2016 http://support.microsoft.com/?kbid=3137725 NOELC4 Update KB3137725 NoelC4\NoelC 3/18/2016 http://support.microsoft.com/?kbid=3137728 NOELC4 Update KB3137728 NoelC4\NoelC 3/18/2016 http://support.microsoft.com/?kbid=3138378 NOELC4 Update KB3138378 NoelC4\NoelC 4/21/2016 http://support.microsoft.com/?kbid=3138602 NOELC4 Update KB3138602 NoelC4\NoelC 3/18/2016 http://support.microsoft.com/?kbid=3138615 NOELC4 Update KB3138615 NoelC4\NoelC 3/18/2016 http://support.microsoft.com/?kbid=3138910 NOELC4 Security Update KB3138910 NoelC4\NoelC 3/18/2016 http://support.microsoft.com/?kbid=3138962 NOELC4 Security Update KB3138962 NoelC4\NoelC 3/18/2016 http://support.microsoft.com/?kbid=3139219 NOELC4 Update KB3139219 NoelC4\NoelC 3/18/2016 http://support.microsoft.com/?kbid=3139398 NOELC4 Security Update KB3139398 NoelC4\NoelC 3/18/2016 http://support.microsoft.com/?kbid=3139914 NOELC4 Security Update KB3139914 NoelC4\NoelC 3/18/2016 http://support.microsoft.com/?kbid=3139929 NOELC4 Security Update KB3139929 NoelC4\NoelC 3/18/2016 http://support.microsoft.com/?kbid=3140219 NOELC4 Update KB3140219 NoelC4\NoelC 3/18/2016 http://support.microsoft.com/?kbid=3140234 NOELC4 Update KB3140234 NoelC4\NoelC 3/18/2016 http://support.microsoft.com/?kbid=3140786 NOELC4 Update KB3140786 NoelC4\NoelC 3/18/2016 http://support.microsoft.com/?kbid=3142026 NOELC4 Security Update KB3142026 NoelC4\NoelC 5/16/2016 http://support.microsoft.com/?kbid=3142036 NOELC4 Security Update KB3142036 NoelC4\NoelC 5/16/2016 http://support.microsoft.com/?kbid=3142045 NOELC4 Security Update KB3142045 NoelC4\NoelC 4/18/2016 http://support.microsoft.com/?kbid=3144756 NOELC4 Security Update KB3144756 NoelC4\NoelC 3/18/2016 http://support.microsoft.com/?kbid=3145384 NOELC4 Update KB3145384 NT AUTHORITY\SYSTEM 4/21/2016 http://support.microsoft.com/?kbid=3146604 NOELC4 Update KB3146604 NT AUTHORITY\SYSTEM 4/21/2016 http://support.microsoft.com/?kbid=3146723 NOELC4 Security Update KB3146723 NT AUTHORITY\SYSTEM 4/18/2016 http://support.microsoft.com/?kbid=3146751 NOELC4 Update KB3146751 NoelC4\NoelC 4/21/2016 http://support.microsoft.com/?kbid=3146963 NOELC4 Security Update KB3146963 NT AUTHORITY\SYSTEM 4/18/2016 http://support.microsoft.com/?kbid=3146978 NOELC4 Update KB3146978 NT AUTHORITY\SYSTEM 4/21/2016 http://support.microsoft.com/?kbid=3147071 NOELC4 Update KB3147071 NT AUTHORITY\SYSTEM 4/18/2016 http://support.microsoft.com/?kbid=3148198 NOELC4 Security Update KB3148198 NT AUTHORITY\SYSTEM 4/18/2016 http://support.microsoft.com/?kbid=3148851 NOELC4 Update KB3148851 NoelC4\NoelC 4/18/2016 http://support.microsoft.com/?kbid=3149090 NOELC4 Security Update KB3149090 NT AUTHORITY\SYSTEM 4/18/2016 http://support.microsoft.com/?kbid=3149157 NOELC4 Update KB3149157 NT AUTHORITY\SYSTEM 4/21/2016 http://support.microsoft.com/?kbid=3150220 NOELC4 Security Update KB3150220 NoelC4\NoelC 5/16/2016 http://support.microsoft.com/?kbid=3151058 NOELC4 Security Update KB3151058 NT AUTHORITY\SYSTEM 5/16/2016 http://support.microsoft.com/?kbid=3153704 NOELC4 Security Update KB3153704 NT AUTHORITY\SYSTEM 5/16/2016 http://support.microsoft.com/?kbid=3154070 NOELC4 Security Update KB3154070 NT AUTHORITY\SYSTEM 5/16/2016 http://support.microsoft.com/?kbid=3154132 NOELC4 Security Update KB3154132 NoelC4\NoelC 4/18/2016 http://support.microsoft.com/?kbid=3155178 NOELC4 Security Update KB3155178 NoelC4\NoelC 5/16/2016 http://support.microsoft.com/?kbid=3155784 NOELC4 Security Update KB3155784 NT AUTHORITY\SYSTEM 5/16/2016 http://support.microsoft.com/?kbid=3156016 NOELC4 Security Update KB3156016 NoelC4\NoelC 5/16/2016 http://support.microsoft.com/?kbid=3156017 NOELC4 Security Update KB3156017 NT AUTHORITY\SYSTEM 5/16/2016 http://support.microsoft.com/?kbid=3156019 NOELC4 Security Update KB3156019 NT AUTHORITY\SYSTEM 5/16/2016 http://support.microsoft.com/?kbid=3156059 NOELC4 Security Update KB3156059 NT AUTHORITY\SYSTEM 5/16/2016 http://support.microsoft.com/?kbid=3156418 NOELC4 Update KB3156418 NT AUTHORITY\SYSTEM 7/4/2016 http://support.microsoft.com/?kbid=3157569 NOELC4 Security Update KB3157569 NoelC4\NoelC 7/4/2016 http://support.microsoft.com/?kbid=3159398 NOELC4 Security Update KB3159398 NoelC4\NoelC 7/4/2016 http://support.microsoft.com/?kbid=3160005 NOELC4 Security Update KB3160005 NT AUTHORITY\SYSTEM 7/4/2016 http://support.microsoft.com/?kbid=3161102 NOELC4 Update KB3161102 NoelC4\NoelC 11/11/2016 http://support.microsoft.com/?kbid=3161561 NOELC4 Security Update KB3161561 NT AUTHORITY\SYSTEM 7/4/2016 http://support.microsoft.com/?kbid=3161606 NOELC4 Update KB3161606 NT AUTHORITY\SYSTEM 7/4/2016 http://support.microsoft.com/?kbid=3161664 NOELC4 Security Update KB3161664 NT AUTHORITY\SYSTEM 7/4/2016 http://support.microsoft.com/?kbid=3161949 NOELC4 Security Update KB3161949 NT AUTHORITY\SYSTEM 7/4/2016 http://support.microsoft.com/?kbid=3161958 NOELC4 Security Update KB3161958 NT AUTHORITY\SYSTEM 7/4/2016 http://support.microsoft.com/?kbid=3162835 NOELC4 Update KB3162835 NoelC4\NoelC 7/4/2016 http://support.microsoft.com/?kbid=3163207 NOELC4 Security Update KB3163207 NoelC4\NoelC 5/16/2016 http://support.microsoft.com/?kbid=3163247 NOELC4 Security Update KB3163247 NoelC4\NoelC 11/11/2016 http://support.microsoft.com/?kbid=3164024 NOELC4 Security Update KB3164024 NoelC4\NoelC 11/11/2016 http://support.microsoft.com/?kbid=3164033 NOELC4 Security Update KB3164033 NT AUTHORITY\SYSTEM 7/4/2016 http://support.microsoft.com/?kbid=3164035 NOELC4 Security Update KB3164035 NT AUTHORITY\SYSTEM 7/4/2016 http://support.microsoft.com/?kbid=3167685 NOELC4 Security Update KB3167685 NoelC4\NoelC 7/4/2016 http://support.microsoft.com/?kbid=3169704 NOELC4 Security Update KB3169704 NoelC4\NoelC 11/11/2016 http://support.microsoft.com/?kbid=3170455 NOELC4 Security Update KB3170455 NoelC4\NoelC 11/11/2016 http://support.microsoft.com/?kbid=3172614 NOELC4 Update KB3172614 NT AUTHORITY\SYSTEM 11/11/2016 http://support.microsoft.com/?kbid=3172729 NOELC4 Security Update KB3172729 NoelC4\NoelC 1/13/2017 http://support.microsoft.com/?kbid=3173424 NOELC4 Update KB3173424 NoelC4\NoelC 11/11/2016 http://support.microsoft.com/?kbid=3174644 NOELC4 Security Update KB3174644 NT AUTHORITY\SYSTEM 11/11/2016 http://support.microsoft.com/?kbid=3175024 NOELC4 Security Update KB3175024 NT AUTHORITY\SYSTEM 11/11/2016 http://support.microsoft.com/?kbid=3177186 NOELC4 Security Update KB3177186 NoelC4\NoelC 11/11/2016 http://support.microsoft.com/?kbid=3178539 NOELC4 Security Update KB3178539 NT AUTHORITY\SYSTEM 11/11/2016 http://support.microsoft.com/?kbid=3179574 NOELC4 Update KB3179574 NT AUTHORITY\SYSTEM 11/11/2016 http://support.microsoft.com/?kbid=3179948 NOELC4 Update KB3179948 NoelC4\NoelC 11/11/2016 http://support.microsoft.com/?kbid=3182203 NOELC4 Update KB3182203 NoelC4\NoelC 11/11/2016 http://support.microsoft.com/?kbid=3184122 NOELC4 Security Update KB3184122 NT AUTHORITY\SYSTEM 11/11/2016 http://support.microsoft.com/?kbid=3184143 NOELC4 Update KB3184143 NT AUTHORITY\SYSTEM 11/11/2016 http://support.microsoft.com/?kbid=3184943 NOELC4 Security Update KB3184943 NoelC4\NoelC 11/11/2016 http://support.microsoft.com/?kbid=3185911 NOELC4 Security Update KB3185911 NT AUTHORITY\SYSTEM 11/11/2016 http://support.microsoft.com/?kbid=3187754 NOELC4 Security Update KB3187754 NT AUTHORITY\SYSTEM 11/11/2016 http://support.microsoft.com/?kbid=3188743 NOELC4 Update KB3188743 NoelC4\NoelC 11/11/2016 http://support.microsoft.com/?kbid=3194343 NOELC4 Security Update KB3194343 NoelC4\NoelC 10/13/2016 http://support.microsoft.com/?kbid=3202790 NOELC4 Security Update KB3202790 NoelC4\NoelC 11/11/2016 http://support.microsoft.com/?kbid=3210132 NOELC4 Update KB3210132 NoelC4\NoelC 1/13/2017 http://support.microsoft.com/?kbid=3210135 NOELC4 Update KB3210135 NoelC4\NoelC 1/13/2017 http://support.microsoft.com/?kbid=3214628 NOELC4 Security Update KB3214628 NoelC4\NoelC 1/13/2017 http://support.microsoft.com/?kbid=4010250 NOELC4 Security Update KB4010250 NoelC4\NoelC 3/2/2017 http://support.microsoft.com/?kbid=4012204 NOELC4 Security Update KB4012204 NoelC4\NoelC 4/3/2017 http://support.microsoft.com/?kbid=4014551 NOELC4 Update KB4014551 NoelC4\NoelC 4/14/2017 http://support.microsoft.com/?kbid=4014567 NOELC4 Update KB4014567 NoelC4\NoelC 4/14/2017 http://support.microsoft.com/?kbid=4014661 NOELC4 Security Update KB4014661 NoelC4\NoelC 4/11/2017 http://support.microsoft.com/?kbid=4018483 NOELC4 Security Update KB4018483 NoelC4\NoelC 4/14/2017 http://support.microsoft.com/?kbid=4015550 NOELC4 Security Update KB4015550 NT AUTHORITY\SYSTEM 4/14/2017 ------------------------------------------------------------------------------------------- BCDEDIT /ENUM ALL (list of all boot configuration options): Windows Boot Manager -------------------- identifier {bootmgr} device partition=\Device\HarddiskVolume1 description Windows Boot Manager locale en-US inherit {globalsettings} integrityservices Enable default {current} resumeobject {e1f7ba30-0a1d-11df-9677-88288868dd8a} displayorder {current} toolsdisplayorder {memdiag} timeout 10 displaybootmenu Yes Windows Boot Loader ------------------- identifier {e1f7ba2e-0a1d-11df-9677-88288868dd8a} device ramdisk=[C:]\Recovery\e1f7ba2e-0a1d-11df-9677-88288868dd8a\Winre.wim,{e1f7ba2f-0a1d-11df-9677-88288868dd8a} path \windows\system32\winload.exe description Windows Recovery Environment inherit {bootloadersettings} osdevice ramdisk=[C:]\Recovery\e1f7ba2e-0a1d-11df-9677-88288868dd8a\Winre.wim,{e1f7ba2f-0a1d-11df-9677-88288868dd8a} systemroot \windows nx OptIn winpe Yes Windows Boot Loader ------------------- identifier {current} device partition=C: path \Windows\system32\winload.exe description Windows 8.1 locale en-US loadoptions ENABLE_INTEGRITY_CHECKS inherit {bootloadersettings} recoverysequence {e1f7ba32-0a1d-11df-9677-88288868dd8a} integrityservices Enable recoveryenabled Yes testsigning No allowedinmemorysettings 0x15000075 osdevice partition=C: systemroot \Windows resumeobject {e1f7ba30-0a1d-11df-9677-88288868dd8a} nx OptIn bootmenupolicy Standard Windows Boot Loader ------------------- identifier {e1f7ba32-0a1d-11df-9677-88288868dd8a} device ramdisk=[C:]\Recovery\WindowsRE\Winre.wim,{e1f7ba33-0a1d-11df-9677-88288868dd8a} path \windows\system32\winload.exe description Windows Recovery Environment locale en-US inherit {bootloadersettings} displaymessage Recovery osdevice ramdisk=[C:]\Recovery\WindowsRE\Winre.wim,{e1f7ba33-0a1d-11df-9677-88288868dd8a} systemroot \windows nx OptIn bootmenupolicy Standard winpe Yes Resume from Hibernate --------------------- identifier {e1f7ba30-0a1d-11df-9677-88288868dd8a} device partition=C: path \Windows\system32\winresume.exe description Windows Resume Application locale en-US inherit {resumeloadersettings} recoverysequence {e1f7ba32-0a1d-11df-9677-88288868dd8a} recoveryenabled Yes allowedinmemorysettings 0x15000075 filedevice partition=C: filepath \hiberfil.sys bootmenupolicy Standard debugoptionenabled No Windows Memory Tester --------------------- identifier {memdiag} device partition=\Device\HarddiskVolume1 path \boot\memtest.exe description Windows Memory Diagnostic locale en-US inherit {globalsettings} badmemoryaccess Yes EMS Settings ------------ identifier {emssettings} bootems No Debugger Settings ----------------- identifier {dbgsettings} debugtype Serial debugport 1 baudrate 115200 RAM Defects ----------- identifier {badmemory} Global Settings --------------- identifier {globalsettings} inherit {dbgsettings} {emssettings} {badmemory} Boot Loader Settings -------------------- identifier {bootloadersettings} inherit {globalsettings} {hypervisorsettings} Hypervisor Settings ------------------- identifier {hypervisorsettings} hypervisordebugtype Serial hypervisordebugport 1 hypervisorbaudrate 115200 Resume Loader Settings ---------------------- identifier {resumeloadersettings} inherit {globalsettings} Device options -------------- identifier {e1f7ba2f-0a1d-11df-9677-88288868dd8a} description Ramdisk Options ramdisksdidevice partition=C: ramdisksdipath \Recovery\e1f7ba2e-0a1d-11df-9677-88288868dd8a\boot.sdi Device options -------------- identifier {e1f7ba33-0a1d-11df-9677-88288868dd8a} description Windows Recovery ramdisksdidevice partition=C: ramdisksdipath \Recovery\WindowsRE\boot.sdi ------------------------------------------------------------------------------------------- autorunsc -a * (list of all auto-starting programs): Sysinternals Autoruns v13.71 - Autostart program viewer Copyright (C) 2002-2017 Mark Russinovich Sysinternals - www.sysinternals.com HKLM\System\CurrentControlSet\Control\Session Manager\BootExecute autocheck autochk * autocheck autochk * Auto Check Utility Microsoft Corporation 6.3.9600.17031 c:\windows\system32\autochk.exe 2/22/2014 8:17 AM HKLM\System\CurrentControlSet\Control\ServiceControlManagerExtension %systemroot%\system32\scext.dll %systemroot%\system32\scext.dll Service Control Manager Extension DLL for non-minwin Microsoft Corporation 6.3.9600.17415 c:\windows\system32\scext.dll 10/28/2014 9:28 PM HKLM\Software\Microsoft\Office\Outlook\Addins Microsoft VBA for Outlook Addin HKCR\CLSID\{799ED9EA-FB5E-11D1-B7D6-00C04FC2AAE2} Outlook VBA Integration Add-In Microsoft Corporation 14.0.7010.1000 c:\program files\microsoft office\office14\addins\outlvba.dll 2/14/2013 11:33 PM Acrobat PDFMaker Office COM Addin HKCR\CLSID\{9177B23F-7D46-11D6-B816-00C04FC06913} PDFMOutlook Addin Module Adobe Systems Incorporated 15.7.20033.2203 c:\program files (x86)\adobe\acrobat dc\pdfmaker\mail\outlook\x64\pdfmoutlookaddin.dll 3/17/2015 2:12 AM Windows_Search_OutlookToolbar HKCR\CLSID\{F37AFD4F-E736-4980-8650-A486B1F2DF25} Outlook MSSearch Connector Microsoft Corporation 7.0.9600.17787 c:\windows\system32\mssphtb.dll 4/1/2015 12:17 AM FormRegionAddin Class HKCR\CLSID\{F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3} 14.0.7164.5000 c:\program files\microsoft office\office14\addins\umoutlookaddin.dll 11/10/2015 10:48 PM HKLM\Software\Wow6432Node\Microsoft\Office\Outlook\Addins [DISABLED] Adobe Send for Microsoft Outlook HKCR\CLSID\{C25EDAAF-1FA0-40D2-9A08-E5159D018255} Adobe Send & Track for Microsoft Outlook Addin Module Adobe Systems Incorporated 15.7.20033.2203 c:\program files (x86)\adobe\acrobat dc\pdfmaker\mail\outlook\sendaslinkaddin.dll 3/17/2015 2:21 AM Acrobat PDFMaker Office COM Addin HKCR\CLSID\{9177B23F-7D46-11D6-B816-00C04FC06913} PDFMOutlook Addin Module Adobe Systems Incorporated 15.7.20033.2203 c:\program files (x86)\adobe\acrobat dc\pdfmaker\mail\outlook\pdfmoutlookaddin.dll 3/17/2015 2:10 AM Windows_Search_OutlookToolbar HKCR\CLSID\{F37AFD4F-E736-4980-8650-A486B1F2DF25} Outlook MSSearch Connector Microsoft Corporation 7.0.9600.17415 c:\windows\syswow64\mssphtb.dll 10/28/2014 9:20 PM HKLM\Software\Microsoft\Office\Excel\Addins Acrobat PDFMaker Office COM Addin HKCR\CLSID\{5789D319-A0E6-4788-8120-B0D3D1AB9797} PDFMOfficeAddin Module Adobe Systems Incorporated 15.7.20033.2203 c:\program files (x86)\adobe\acrobat dc\pdfmaker\office\x64\pdfmofficeaddin.dll 3/17/2015 2:09 AM Connect Class HKCR\CLSID\{5DC1CC51-2694-47CD-B7B7-21363388FFFC} Team Foundation Office Add-in Microsoft Corporation 15.112.26421.0 c:\program files\common files\microsoft shared\team foundation server\15.0\x64\tfsofficeadd-in.dll 4/21/2017 4:56 PM [DISABLED] Connect Class HKCR\CLSID\{23A20EA8-2DF0-40a6-A1FA-8143EDB7B172} VSTODesigner Package Microsoft Corporation 10.0.40219.1 c:\program files\microsoft visual studio 10.0\common7\ide\privateassemblies\tfsofficeadd-in.dll 2/18/2011 9:01 PM [DISABLED] Connect Class HKCR\CLSID\{4D427FAE-03FD-4ACA-9AA7-5C779D7F8A3D} Team Foundation Office Add-in Microsoft Corporation 12.0.40629.0 c:\program files\common files\microsoft shared\team foundation server\12.0\amd64\tfsofficeadd-in.dll 6/28/2015 11:59 PM [DISABLED] Visual Studio Tools for Office Design-Time Adaptor for Excel HKCR\CLSID\{1A55DFEC-DAA0-4aad-A2DF-62420CCC537E} Visual Studio Design-Time Adaptor for Excel Microsoft Corporation 12.0.30626.0 c:\program files (x86)\microsoft visual studio 12.0\visual studio tools for office\x64\vstoexceladaptor.dll 6/25/2014 11:33 PM HKLM\Software\Wow6432Node\Microsoft\Office\Excel\Addins Acrobat PDFMaker Office COM Addin HKCR\CLSID\{5789D319-A0E6-4788-8120-B0D3D1AB9797} PDFMOfficeAddin Module Adobe Systems Incorporated 15.7.20033.2203 c:\program files (x86)\adobe\acrobat dc\pdfmaker\office\pdfmofficeaddin.dll 3/17/2015 2:09 AM Connect Class HKCR\CLSID\{5DC1CC51-2694-47CD-B7B7-21363388FFFC} Team Foundation Office Add-in Microsoft Corporation 15.112.26421.0 c:\program files\common files\microsoft shared\team foundation server\15.0\x86\tfsofficeadd-in.dll 4/21/2017 4:56 PM [DISABLED] Connect Class HKCR\CLSID\{23A20EA8-2DF0-40a6-A1FA-8143EDB7B172} VSTODesigner Package Microsoft Corporation 10.0.40219.1 c:\program files (x86)\microsoft visual studio 10.0\common7\ide\privateassemblies\tfsofficeadd-in.dll 2/18/2011 11:49 PM [DISABLED] Connect Class HKCR\CLSID\{4D427FAE-03FD-4ACA-9AA7-5C779D7F8A3D} Team Foundation Office Add-in Microsoft Corporation 12.0.40629.0 c:\program files\common files\microsoft shared\team foundation server\12.0\x86\tfsofficeadd-in.dll 6/29/2015 12:25 AM [DISABLED] Visual Studio Tools for Office Design-Time Adaptor for Excel HKCR\CLSID\{1A55DFEC-DAA0-4aad-A2DF-62420CCC537E} Visual Studio Design-Time Adaptor for Excel Microsoft Corporation 12.0.30626.0 c:\program files (x86)\microsoft visual studio 12.0\visual studio tools for office\x86\vstoexceladaptor.dll 6/25/2014 11:55 PM HKLM\Software\Microsoft\Office\PowerPoint\Addins Acrobat PDFMaker Office COM Addin HKCR\CLSID\{5789D319-A0E6-4788-8120-B0D3D1AB9797} PDFMOfficeAddin Module Adobe Systems Incorporated 15.7.20033.2203 c:\program files (x86)\adobe\acrobat dc\pdfmaker\office\x64\pdfmofficeaddin.dll 3/17/2015 2:09 AM [DISABLED] Connect Class HKCR\CLSID\{04986E13-556D-463F-ADBD-9D8CAD03707B} Team Foundation Office Add-in Microsoft Corporation 14.98.25331.0 c:\program files\common files\microsoft shared\team foundation server\14.0\x64\tfsofficeadd-in.dll 5/31/2016 6:35 PM Connect Class HKCR\CLSID\{5DC1CC51-2694-47CD-B7B7-21363388FFFC} Team Foundation Office Add-in Microsoft Corporation 15.112.26421.0 c:\program files\common files\microsoft shared\team foundation server\15.0\x64\tfsofficeadd-in.dll 4/21/2017 4:56 PM HKLM\Software\Wow6432Node\Microsoft\Office\PowerPoint\Addins Acrobat PDFMaker Office COM Addin HKCR\CLSID\{5789D319-A0E6-4788-8120-B0D3D1AB9797} PDFMOfficeAddin Module Adobe Systems Incorporated 15.7.20033.2203 c:\program files (x86)\adobe\acrobat dc\pdfmaker\office\pdfmofficeaddin.dll 3/17/2015 2:09 AM [DISABLED] Connect Class HKCR\CLSID\{04986E13-556D-463F-ADBD-9D8CAD03707B} Team Foundation Office Add-in Microsoft Corporation 14.98.25331.0 c:\program files\common files\microsoft shared\team foundation server\14.0\x86\tfsofficeadd-in.dll 5/31/2016 6:35 PM Connect Class HKCR\CLSID\{5DC1CC51-2694-47CD-B7B7-21363388FFFC} Team Foundation Office Add-in Microsoft Corporation 15.112.26421.0 c:\program files\common files\microsoft shared\team foundation server\15.0\x86\tfsofficeadd-in.dll 4/21/2017 4:56 PM HKLM\Software\Microsoft\Office\Word\Addins Acrobat PDFMaker Office COM Addin HKCR\CLSID\{5789D319-A0E6-4788-8120-B0D3D1AB9797} PDFMOfficeAddin Module Adobe Systems Incorporated 15.7.20033.2203 c:\program files (x86)\adobe\acrobat dc\pdfmaker\office\x64\pdfmofficeaddin.dll 3/17/2015 2:09 AM [DISABLED] Visual Studio Tools for Office Design-Time Adaptor for Word HKCR\CLSID\{5AD8B195-BDDA-4b42-90A4-A5389D9E30DC} Visual Studio Design-Time Adaptor for Word Microsoft Corporation 12.0.30626.0 c:\program files (x86)\microsoft visual studio 12.0\visual studio tools for office\x64\vstowordadaptor.dll 6/25/2014 11:33 PM HKLM\Software\Wow6432Node\Microsoft\Office\Word\Addins Acrobat PDFMaker Office COM Addin HKCR\CLSID\{5789D319-A0E6-4788-8120-B0D3D1AB9797} PDFMOfficeAddin Module Adobe Systems Incorporated 15.7.20033.2203 c:\program files (x86)\adobe\acrobat dc\pdfmaker\office\pdfmofficeaddin.dll 3/17/2015 2:09 AM [DISABLED] Visual Studio Tools for Office Design-Time Adaptor for Word HKCR\CLSID\{5AD8B195-BDDA-4b42-90A4-A5389D9E30DC} Visual Studio Design-Time Adaptor for Word Microsoft Corporation 12.0.30626.0 c:\program files (x86)\microsoft visual studio 12.0\visual studio tools for office\x86\vstowordadaptor.dll 6/25/2014 11:55 PM HKLM\SOFTWARE\Classes\Htmlfile\Shell\Open\Command\(Default) C:\Program Files\Internet Explorer\iexplore.exe Internet Explorer Microsoft Corporation 11.0.9600.18123 c:\program files\internet explorer\iexplore.exe 11/8/2015 4:24 PM HKLM\System\CurrentControlSet\Services [DISABLED] AdobeARMservice "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe" Adobe Acrobat Updater keeps your Adobe software up to date. Adobe Systems Incorporated 1.824.16.1310 c:\program files (x86)\common files\adobe\arm\1.0\armsvc.exe 10/28/2015 9:42 PM [DISABLED] AdobeUpdateService "C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe" Adobe Update Service Adobe Systems Incorporated 4.0.0.184 c:\program files (x86)\common files\adobe\adobe desktop common\elevationmanager\adobeupdateservice.exe 3/10/2017 10:13 AM AeLookupSvc %SystemRoot%\System32\aelupsvc.dll Processes application compatibility cache requests for applications as they are launched Microsoft Corporation 6.3.9600.17415 c:\windows\system32\aelupsvc.dll 10/28/2014 10:42 PM [DISABLED] AGSService "C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe" Adobe Genuine Software Integrity Service Adobe Systems, Incorporated 3.6.0.462 c:\program files (x86)\common files\adobe\adobegcclient\agsservice.exe 1/19/2017 1:38 AM ALG %SystemRoot%\System32\alg.exe Provides support for 3rd party protocol plug-ins for Internet Connection Sharing Microsoft Corporation 6.3.9600.17415 c:\windows\system32\alg.exe 10/28/2014 9:21 PM [DISABLED] APC Data Service "C:\Program Files (x86)\APC\PowerChute Personal Edition\dataserv.exe" PowerChute Personal Edition service for managing data operations. Schneider Electric 3.0.2.0 c:\program files (x86)\apc\powerchute personal edition\dataserv.exe 1/24/2012 6:32 AM APC UPS Service "C:\Program Files (x86)\APC\PowerChute Personal Edition\mainserv.exe" PowerChute Personal Edition service for managing battery backup power events. Schneider Electric 3.0.2.0 c:\program files (x86)\apc\powerchute personal edition\mainserv.exe 1/24/2012 6:25 AM AppIDSvc %SystemRoot%\System32\appidsvc.dll Determines and verifies the identity of an application. Disabling this service will prevent AppLocker from being enforced. Microsoft Corporation 6.3.9600.18002 c:\windows\system32\appidsvc.dll 8/1/2015 10:22 AM Appinfo %SystemRoot%\System32\appinfo.dll Facilitates the running of interactive applications with additional administrative privileges. If this service is stopped, users will be unable to launch applications with the additional administrative privileges they may require to perform desired user tasks. Microsoft Corporation 6.3.9600.18224 c:\windows\system32\appinfo.dll 1/31/2016 2:07 PM AppMgmt %SystemRoot%\System32\appmgmts.dll Processes installation, removal, and enumeration requests for software deployed through Group Policy. If the service is disabled, users will be unable to install, remove, or enumerate software deployed through Group Policy. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\appmgmts.dll 10/28/2014 10:30 PM AppReadiness %SystemRoot%\system32\AppReadiness.dll Gets apps ready for use the first time a user signs in to this PC and when adding new apps. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\appreadiness.dll 10/28/2014 8:48 PM AppXSvc %SystemRoot%\system32\appxdeploymentserver.dll Provides infrastructure support for deploying Store applications. This service is started on demand and if disabled Store applications will not be deployed to the system, and may not function properly. Microsoft Corporation 6.3.9600.18231 c:\windows\system32\appxdeploymentserver.dll 2/8/2016 12:53 PM aspnet_state %systemroot%\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe Provides support for out-of-process session states for ASP.NET. If this service is stopped, out-of-process requests will not be processed. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation 4.6.1087.0 c:\windows\microsoft.net\framework64\v4.0.30319\aspnet_state.exe 11/30/2016 1:12 AM AudioEndpointBuilder %SystemRoot%\System32\AudioEndpointBuilder.dll Manages audio devices for the Windows Audio service. If this service is stopped, audio devices and effects will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start Microsoft Corporation 6.3.9600.17893 c:\windows\system32\audioendpointbuilder.dll 5/30/2015 3:36 PM Audiosrv %SystemRoot%\System32\Audiosrv.dll Manages audio for Windows-based programs. If this service is stopped, audio devices and effects will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start Microsoft Corporation 6.3.9600.17893 c:\windows\system32\audiosrv.dll 5/30/2015 3:35 PM AxInstSV %SystemRoot%\System32\AxInstSV.dll Provides User Account Control validation for the installation of ActiveX controls from the Internet and enables management of ActiveX control installation based on Group Policy settings. This service is started on demand and if disabled the installation of ActiveX controls will behave according to default browser settings. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\axinstsv.dll 10/28/2014 9:43 PM BDESVC %SystemRoot%\System32\bdesvc.dll BDESVC hosts the BitLocker Drive Encryption service. BitLocker Drive Encryption provides secure startup for the operating system, as well as full volume encryption for OS, fixed or removable volumes. This service allows BitLocker to prompt users for various actions related to their volumes when mounted, and unlocks volumes automatically without user interaction. Additionally, it stores recovery information to Active Directory, if available, and, if necessary, ensures the most recent recovery certificates are used. Stopping or disabling the service would prevent users from leveraging this functionality. Microsoft Corporation 6.3.9600.18294 c:\windows\system32\bdesvc.dll 4/1/2016 12:53 PM BFE %SystemRoot%\System32\bfe.dll The Base Filtering Engine (BFE) is a service that manages firewall and Internet Protocol security (IPsec) policies and implements user mode filtering. Stopping or disabling the BFE service will significantly reduce the security of the system. It will also result in unpredictable behavior in IPsec management and firewall applications. Microsoft Corporation 6.3.9600.18229 c:\windows\system32\bfe.dll 2/5/2016 11:11 AM BITS %SystemRoot%\System32\qmgr.dll Transfers files in the background using idle network bandwidth. If the service is disabled, then any applications that depend on BITS, such as Windows Update or MSN Explorer, will be unable to automatically download programs and other information. Microsoft Corporation 7.7.9600.17415 c:\windows\system32\qmgr.dll 10/28/2014 9:43 PM BrokerInfrastructure %SystemRoot%\System32\bisrv.dll Windows infrastructure service that controls which background tasks can run on the system. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\bisrv.dll 10/28/2014 9:12 PM BthHFSrv %SystemRoot%\System32\BthHFSrv.dll Enables wireless Bluetooth headsets to run on this computer. If this service is stopped or disabled, then Bluetooth headsets will not function properly with this machine. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\bthhfsrv.dll 10/28/2014 9:57 PM bthserv %SystemRoot%\system32\bthserv.dll The Bluetooth service supports discovery and association of remote Bluetooth devices. Stopping or disabling this service may cause already installed Bluetooth devices to fail to operate properly and prevent new devices from being discovered or associated. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\bthserv.dll 10/28/2014 9:18 PM CertPropSvc %SystemRoot%\System32\certprop.dll Copies user certificates and root certificates from smart cards into the current user's certificate store, detects when a smart card is inserted into a smart card reader, and, if needed, installs the smart card Plug and Play minidriver. Microsoft Corporation 6.3.9600.18562 c:\windows\system32\certprop.dll 12/24/2016 8:48 PM [DISABLED] CollabNetSubversionServer "C:\svn\bin\httpd.exe" -k runservice Apache/2.4.12 (Win64) SVN/1.8.13 OpenSSL/1.0.1m Apache Software Foundation 2.4.25.0 c:\svn\bin\httpd.exe 1/27/2017 4:04 AM COMSysApp %SystemRoot%\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235} Manages the configuration and tracking of Component Object Model (COM)+-based components. If the service is stopped, most COM+-based components will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\dllhost.exe 10/28/2014 9:21 PM CryptSvc %SystemRoot%\system32\cryptsvc.dll Provides three management services: Catalog Database Service, which confirms the signatures of Windows files and allows new programs to be installed; Protected Root Service, which adds and removes Trusted Root Certification Authority certificates from this computer; and Automatic Root Certificate Update Service, which retrieves root certificates from Windows Update and enable scenarios such as SSL. If this service is stopped, these management services will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\cryptsvc.dll 10/28/2014 9:27 PM CscService %SystemRoot%\System32\cscsvc.dll The Offline Files service performs maintenance activities on the Offline Files cache, responds to user logon and logoff events, implements the internals of the public API, and dispatches interesting events to those interested in Offline Files activities and changes in cache state. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\cscsvc.dll 10/28/2014 10:20 PM [DISABLED] CSVNConsole "%JAVA_HOME%\bin\java.exe" "-classpath" "C:\SVN\svcwrapper\wrapper.jar" "-Xrs" "-Dwrapper.service=true" "-Dwrapper.working.dir=C:\SVN\svcwrapper\..\appserver" "-Dwrapper.config=C:\SVN\svcwrapper\conf\wrapper.conf" "-Dwrapper.additional.1x=-Xrs" "org.rzo.yajsw.boot.WrapperServiceBooter" CollabNet Subversion Edge browser-based management console Oracle Corporation 7.0.670.1 c:\program files\java\jre7\bin\java.exe 7/25/2014 12:00 PM DcomLaunch %SystemRoot%\system32\rpcss.dll The DCOMLAUNCH service launches COM and DCOM servers in response to object activation requests. If this service is stopped or disabled, programs using COM or DCOM will not function properly. It is strongly recommended that you have the DCOMLAUNCH service running. Microsoft Corporation 6.3.9600.18302 c:\windows\system32\rpcss.dll 4/9/2016 6:10 PM defragsvc %Systemroot%\System32\defragsvc.dll Helps the computer run more efficiently by optimizing files on storage drives. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\defragsvc.dll 10/28/2014 9:12 PM DeviceAssociationService %SystemRoot%\system32\das.dll Enables pairing between the system and wired or wireless devices. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\das.dll 10/28/2014 9:12 PM DeviceInstall %SystemRoot%\system32\umpnpmgr.dll Enables a computer to recognize and adapt to hardware changes with little or no user input. Stopping or disabling this service will result in system instability. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\umpnpmgr.dll 10/28/2014 10:45 PM Dhcp %SystemRoot%\system32\dhcpcore.dll Registers and updates IP addresses and DNS records for this computer. If this service is stopped, this computer will not receive dynamic IP addresses and DNS updates. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\dhcpcore.dll 10/28/2014 9:29 PM Dnscache %SystemRoot%\System32\dnsrslvr.dll The DNS Client service (dnscache) caches Domain Name System (DNS) names and registers the full computer name for this computer. If the service is stopped, DNS names will continue to be resolved. However, the results of DNS name queries will not be cached and the computer's name will not be registered. If the service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation 6.3.9600.18592 c:\windows\system32\dnsrslvr.dll 2/9/2017 10:58 AM dot3svc %SystemRoot%\System32\dot3svc.dll The Wired AutoConfig (DOT3SVC) service is responsible for performing IEEE 802.1X authentication on Ethernet interfaces. If your current wired network deployment enforces 802.1X authentication, the DOT3SVC service should be configured to run for establishing Layer 2 connectivity and/or providing access to network resources. Wired networks that do not enforce 802.1X authentication are unaffected by the DOT3SVC service. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\dot3svc.dll 10/28/2014 9:53 PM DPS %SystemRoot%\system32\dps.dll The Diagnostic Policy Service enables problem detection, troubleshooting and resolution for Windows components. If this service is stopped, diagnostics will no longer function. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\dps.dll 10/28/2014 9:21 PM DsmSvc %SystemRoot%\System32\DeviceSetupManager.dll Enables the detection, download and installation of device-related software. If this service is disabled, devices may be configured with outdated software, and may not work correctly. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\devicesetupmanager.dll 10/28/2014 9:05 PM Eaphost %SystemRoot%\System32\eapsvc.dll The Extensible Authentication Protocol (EAP) service provides network authentication in such scenarios as 802.1x wired and wireless, VPN, and Network Access Protection (NAP). EAP also provides application programming interfaces (APIs) that are used by network access clients, including wireless and VPN clients, during the authentication process. If you disable this service, this computer is prevented from accessing networks that require EAP authentication. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\eapsvc.dll 10/28/2014 9:14 PM EFS %SystemRoot%\system32\efssvc.dll Provides the core file encryption technology used to store encrypted files on NTFS file system volumes. If this service is stopped or disabled, applications will be unable to access encrypted files. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\efssvc.dll 10/28/2014 10:42 PM ehRecvr %systemroot%\ehome\ehRecvr.exe Windows Media Center Service for TV and FM broadcast reception Microsoft Corporation 6.3.9600.16395 c:\windows\ehome\ehrecvr.exe 9/5/2013 2:35 AM ehSched %systemroot%\ehome\ehsched.exe Starts and stops recording of TV programs within Windows Media Center Microsoft Corporation 6.3.9600.16384 c:\windows\ehome\ehsched.exe 8/22/2013 7:02 AM EventLog %SystemRoot%\System32\wevtsvc.dll This service manages events and event logs. It supports logging events, querying events, subscribing to events, archiving event logs, and managing event metadata. It can display events in both XML and plain text format. Stopping this service may compromise security and reliability of the system. Microsoft Corporation 6.3.9600.17722 c:\windows\system32\wevtsvc.dll 3/5/2015 10:47 PM EventSystem %systemroot%\system32\es.dll Supports System Event Notification Service (SENS), which provides automatic distribution of events to subscribing Component Object Model (COM) components. If the service is stopped, SENS will close and will not be able to provide logon and logoff notifications. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation 2001.12.10530.17415 c:\windows\system32\es.dll 10/28/2014 9:12 PM Fax %systemroot%\system32\fxssvc.exe Enables you to send and receive faxes, utilizing fax resources available on this computer or on the network. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\fxssvc.exe 10/28/2014 9:45 PM fdPHost %SystemRoot%\system32\fdPHost.dll The FDPHOST service hosts the Function Discovery (FD) network discovery providers. These FD providers supply network discovery services for the Simple Services Discovery Protocol (SSDP) and Web Services - Discovery (WS-D) protocol. Stopping or disabling the FDPHOST service will disable network discovery for these protocols when using FD. When this service is unavailable, network services using FD and relying on these discovery protocols will be unable to find network devices or resources. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\fdphost.dll 10/28/2014 8:58 PM FDResPub %SystemRoot%\system32\fdrespub.dll Publishes this computer and resources attached to this computer so they can be discovered over the network. If this service is stopped, network resources will no longer be published and they will not be discovered by other computers on the network. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\fdrespub.dll 10/28/2014 9:15 PM fhsvc %SystemRoot%\system32\fhsvc.dll Protects user files from accidental loss by copying them to a backup location Microsoft Corporation 6.3.9600.17415 c:\windows\system32\fhsvc.dll 10/28/2014 10:29 PM FLEXnet Licensing Service "C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe" This service performs licensing functions on behalf of FLEXnet enabled products. Acresso Software Inc. 11.6.0.1 c:\program files (x86)\common files\macrovision shared\flexnet publisher\fnplicensingservice.exe 5/6/2008 11:26 AM FLEXnet Licensing Service 64 "C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe" This service performs licensing functions on behalf of FLEXnet enabled products. Acresso Software Inc. 11.6.0.1 c:\program files\common files\macrovision shared\flexnet publisher\fnplicensingservice64.exe 5/6/2008 11:17 AM FontCache %SystemRoot%\system32\FntCache.dll Optimizes performance of applications by caching commonly used font data. Applications will start this service if it is not already running. It can be disabled, though doing so will degrade application performance. Microsoft Corporation 6.3.9600.18592 c:\windows\system32\fntcache.dll 2/9/2017 11:19 AM FontCache3.0.0.0 %systemroot%\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe Optimizes performance of Windows Presentation Foundation (WPF) applications by caching commonly used font data. WPF applications will start this service if it is not already running. It can be disabled, though doing so will degrade the performance of WPF applications. Microsoft Corporation 3.0.6920.7903 c:\windows\microsoft.net\framework64\v3.0\wpf\presentationfontcache.exe 7/20/2013 1:58 AM gpsvc %SystemRoot%\System32\gpsvc.dll The service is responsible for applying settings configured by administrators for the computer and users through the Group Policy component. If the service is disabled, the settings will not be applied and applications and components will not be manageable through Group Policy. Any components or applications that depend on the Group Policy component might not be functional if the service is disabled. Microsoft Corporation 6.3.9600.18339 c:\windows\system32\gpsvc.dll 5/12/2016 12:07 PM hidserv %SystemRoot%\system32\hidserv.dll Activates and maintains the use of hot buttons on keyboards, remote controls, and other multimedia devices. It is recommended that you keep this service running. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\hidserv.dll 10/28/2014 10:44 PM hkmsvc %SystemRoot%\system32\kmsvc.dll Provides X.509 certificate and key management services for the Network Access Protection Agent (NAPAgent). Enforcement technologies that use X.509 certificates may not function properly without this service Microsoft Corporation 6.3.9600.17415 c:\windows\system32\kmsvc.dll 10/28/2014 10:33 PM hptsvr C:\Program Files (x86)\HighPoint Technologies, Inc.\HighPoint RAID Management\Service\hptsvr.exe c:\program files (x86)\highpoint technologies, inc.\highpoint raid management\service\hptsvr.exe 2/1/2013 3:33 AM IEEtwCollectorService %SystemRoot%\system32\IEEtwCollector.exe /V ETW Collector Service for Internet Explorer. When running, this service collects real time ETW events and processes them. Microsoft Corporation 11.0.9600.18618 c:\windows\system32\ieetwcollector.exe 3/4/2017 3:45 AM IKEEXT %SystemRoot%\System32\ikeext.dll The IKEEXT service hosts the Internet Key Exchange (IKE) and Authenticated Internet Protocol (AuthIP) keying modules. These keying modules are used for authentication and key exchange in Internet Protocol security (IPsec). Stopping or disabling the IKEEXT service will disable IKE and AuthIP key exchange with peer computers. IPsec is typically configured to use IKE or AuthIP; therefore, stopping or disabling the IKEEXT service might result in an IPsec failure and might compromise the security of the system. It is strongly recommended that you have the IKEEXT service running. Microsoft Corporation 6.3.9600.18404 c:\windows\system32\ikeext.dll 7/7/2016 4:59 PM IntuitUpdateServiceV4 "C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe" Helps Intuit applications automatically update themselves. Intuit Inc. 4.5.1.0 c:\program files (x86)\common files\intuit\update service v4\intuitupdateservice.exe 9/2/2016 2:26 AM iphlpsvc %SystemRoot%\System32\iphlpsvc.dll Provides tunnel connectivity using IPv6 transition technologies (6to4, ISATAP, Port Proxy, and Teredo), and IP-HTTPS. If this service is stopped, the computer will not have the enhanced connectivity benefits that these technologies offer. Microsoft Corporation 6.3.9600.18299 c:\windows\system32\iphlpsvc.dll 4/7/2016 12:06 PM KeyIso %SystemRoot%\system32\keyiso.dll The CNG key isolation service is hosted in the LSA process. The service provides key process isolation to private keys and associated cryptographic operations as required by the Common Criteria. The service stores and uses long-lived keys in a secure process complying with Common Criteria requirements. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\keyiso.dll 10/28/2014 9:22 PM KtmRm %systemroot%\system32\msdtckrm.dll Coordinates transactions between the Distributed Transaction Coordinator (MSDTC) and the Kernel Transaction Manager (KTM). If it is not needed, it is recommended that this service remain stopped. If it is needed, both MSDTC and KTM will start this service automatically. If this service is disabled, any MSDTC transaction interacting with a Kernel Resource Manager will fail and any services that explicitly depend on it will fail to start. Microsoft Corporation 2001.12.10530.17415 c:\windows\system32\msdtckrm.dll 10/28/2014 9:11 PM LanmanServer %SystemRoot%\system32\srvsvc.dll Supports file, print, and named-pipe sharing over the network for this computer. If this service is stopped, these functions will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\srvsvc.dll 10/28/2014 9:18 PM LanmanWorkstation %SystemRoot%\System32\wkssvc.dll Creates and maintains client network connections to remote servers using the SMB protocol. If this service is stopped, these connections will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\wkssvc.dll 10/28/2014 9:24 PM lfsvc %SystemRoot%\System32\GeofenceMonitorService.dll This services monitors the current location of the system and manages geo-fences (a geographical location with associated events). If you turn off this service, applications will be unable to use or receive notifications for geo-fences. Microsoft Corporation 6.3.9600.17824 c:\windows\system32\geofencemonitorservice.dll 5/7/2015 11:21 AM lltdsvc %SystemRoot%\System32\lltdsvc.dll Creates a Network Map, consisting of PC and device topology (connectivity) information, and metadata describing each PC and device. If this service is disabled, the Network Map will not function properly. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\lltdsvc.dll 10/28/2014 10:09 PM lmhosts %SystemRoot%\System32\lmhsvc.dll Provides support for the NetBIOS over TCP/IP (NetBT) service and NetBIOS name resolution for clients on the network, therefore enabling users to share files, print, and log on to the network. If this service is stopped, these functions might be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\lmhsvc.dll 10/28/2014 10:48 PM LSM %SystemRoot%\System32\lsm.dll Core Windows Service that manages local user sessions. Stopping or disabling this service will result in system instability. Microsoft Corporation 6.3.9600.17690 c:\windows\system32\lsm.dll 2/20/2015 7:49 PM MBAMService "C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe" Malwarebytes Service Malwarebytes 3.1.0.479 c:\program files\malwarebytes\anti-malware\mbamservice.exe 4/18/2017 8:27 PM [DISABLED] MDM "C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE" Supports local and remote debugging for Visual Studio and script debuggers. If this service is stopped, the debuggers will not function properly. Microsoft Corporation 7.0.9466.0 c:\program files (x86)\common files\microsoft shared\vs7debug\mdm.exe 1/5/2002 12:00 PM MMCSS %SystemRoot%\system32\mmcss.dll Enables relative prioritization of work based on system-wide task priorities. This is intended mainly for multimedia applications. If this service is stopped, individual tasks resort to their default priority. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\mmcss.dll 10/28/2014 9:22 PM MSDTC %SystemRoot%\System32\msdtc.exe Coordinates transactions that span multiple resource managers, such as databases, message queues, and file systems. If this service is stopped, these transactions will fail. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation 2001.12.10530.17415 c:\windows\system32\msdtc.exe 10/28/2014 9:12 PM MSiSCSI %systemroot%\system32\iscsiexe.dll Manages Internet SCSI (iSCSI) sessions from this computer to remote iSCSI target devices. If this service is stopped, this computer will not be able to login or access iSCSI targets. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation 6.3.9600.18467 c:\windows\system32\iscsiexe.dll 9/3/2016 2:06 PM msiserver %systemroot%\system32\msiexec.exe /V Adds, modifies, and removes applications provided as a Windows Installer (*.msi, *.msp) package. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation 5.0.9600.18333 c:\windows\system32\msiexec.exe 5/5/2016 1:18 PM napagent %SystemRoot%\system32\qagentRT.dll The Network Access Protection (NAP) agent service collects and manages health information for client computers on a network. Information collected by NAP agent is used to make sure that the client computer has the required software and settings. If a client computer is not compliant with health policy, it can be provided with restricted network access until its configuration is updated. Depending on the configuration of health policy, client computers might be automatically updated so that users quickly regain full network access without having to manually update their computer. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\qagentrt.dll 10/28/2014 10:20 PM NcaSvc %SystemRoot%\System32\ncasvc.dll Provides DirectAccess status notification for UI components Microsoft Corporation 6.3.9600.17415 c:\windows\system32\ncasvc.dll 10/28/2014 9:48 PM NcdAutoSetup %SystemRoot%\System32\NcdAutoSetup.dll Network Connected Devices Auto-Setup service monitors and installs qualified devices that connect to a qualified network. Stopping or disabling this service will prevent Windows from discovering and installing qualified network connected devices automatically. Users can still manually add network connected devices to a PC through the user interface. Microsoft Corporation 6.3.9600.17937 c:\windows\system32\ncdautosetup.dll 7/16/2015 2:58 PM Netlogon %SystemRoot%\system32\netlogon.dll Maintains a secure channel between this computer and the domain controller for authenticating users and services. If this service is stopped, the computer may not authenticate users and services and the domain controller cannot register DNS records. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation 6.3.9600.18573 c:\windows\system32\netlogon.dll 1/10/2017 5:06 PM Netman %SystemRoot%\System32\netman.dll Manages objects in the Network and Dial-Up Connections folder, in which you can view both local area network and remote connections. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\netman.dll 10/28/2014 8:51 PM netprofm %SystemRoot%\System32\netprofmsvc.dll Identifies the networks to which the computer has connected, collects and stores properties for these networks, and notifies applications when these properties change. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\netprofmsvc.dll 10/28/2014 9:19 PM NlaSvc %SystemRoot%\System32\nlasvc.dll Collects and stores configuration information for the network and notifies programs when this information is modified. If this service is stopped, configuration information might be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation 6.3.9600.17550 c:\windows\system32\nlasvc.dll 12/5/2014 9:41 PM nlsX86cc C:\Windows\SysWOW64\nlssrv32.exe Nalpeiron Licensing Service Nalpeiron Ltd. 7.3.1.0 c:\windows\syswow64\nlssrv32.exe 4/23/2013 4:08 PM nsi %systemroot%\system32\nsisvc.dll This service delivers network notifications (e.g. interface addition/deleting etc) to user mode clients. Stopping this service will cause loss of network connectivity. If this service is disabled, any other services that explicitly depend on this service will fail to start. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\nsisvc.dll 10/28/2014 9:29 PM NVDisplay.ContainerLocalSystem "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" Container service for NVIDIA root features NVIDIA Corporation 1.0.0.0 c:\program files\nvidia corporation\display.nvcontainer\nvdisplay.container.exe 5/1/2017 2:09 PM ose "C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE" Saves installation files used for updates and repairs and is required for the downloading of Setup updates and Watson error reports. Microsoft Corporation 15.0.4454.1000 c:\program files (x86)\common files\microsoft shared\source engine\ose.exe 11/7/2012 6:37 AM ose64 "C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE" Saves installation files used for updates and repairs and is required for the downloading of Setup updates and Watson error reports. Microsoft Corporation 14.0.4730.1010 c:\program files\common files\microsoft shared\source engine\ose.exe 1/10/2010 12:19 AM osppsvc "C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE" Office Software Protection Platform Service (unlocalized description) Microsoft Corporation 14.0.370.400 c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\osppsvc.exe 8/11/2009 10:00 PM p2pimsvc %SystemRoot%\system32\pnrpsvc.dll Provides identity services for the Peer Name Resolution Protocol (PNRP) and Peer-to-Peer Grouping services. If disabled, the Peer Name Resolution Protocol (PNRP) and Peer-to-Peer Grouping services may not function, and some applications, such as HomeGroup and Remote Assistance, may not function correctly. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\pnrpsvc.dll 10/28/2014 9:05 PM p2psvc %SystemRoot%\system32\p2psvc.dll Enables multi-party communication using Peer-to-Peer Grouping. If disabled, some applications, such as HomeGroup, may not function. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\p2psvc.dll 10/28/2014 8:52 PM PcaSvc %SystemRoot%\System32\pcasvc.dll This service provides support for the Program Compatibility Assistant (PCA). PCA monitors programs installed and run by the user and detects known compatibility problems. If this service is stopped, PCA will not function properly. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\pcasvc.dll 10/28/2014 9:03 PM PeerDistSvc %SystemRoot%\system32\peerdistsvc.dll This service caches network content from peers on the local subnet. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\peerdistsvc.dll 10/28/2014 8:59 PM PerfHost %SystemRoot%\SysWow64\perfhost.exe Enables remote users and 64-bit processes to query performance counters provided by 32-bit DLLs. If this service is stopped, only local users and 32-bit processes will be able to query performance counters provided by 32-bit DLLs. Microsoft Corporation 6.3.9600.16384 c:\windows\syswow64\perfhost.exe 8/22/2013 12:12 AM pla %systemroot%\system32\pla.dll Performance Logs and Alerts Collects performance data from local or remote computers based on preconfigured schedule parameters, then writes the data to a log or triggers an alert. If this service is stopped, performance information will not be collected. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\pla.dll 10/28/2014 9:56 PM PlugPlay %SystemRoot%\system32\umpnpmgr.dll Enables a computer to recognize and adapt to hardware changes with little or no user input. Stopping or disabling this service will result in system instability. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\umpnpmgr.dll 10/28/2014 10:45 PM PNRPAutoReg %SystemRoot%\system32\pnrpauto.dll This service publishes a machine name using the Peer Name Resolution Protocol. Configuration is managed via the netsh context 'p2p pnrp peer' Microsoft Corporation 6.3.9600.17415 c:\windows\system32\pnrpauto.dll 10/28/2014 9:19 PM PNRPsvc %SystemRoot%\system32\pnrpsvc.dll Enables serverless peer name resolution over the Internet using the Peer Name Resolution Protocol (PNRP). If disabled, some peer-to-peer and collaborative applications, such as Remote Assistance, may not function. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\pnrpsvc.dll 10/28/2014 9:05 PM PolicyAgent %SystemRoot%\System32\ipsecsvc.dll Internet Protocol security (IPsec) supports network-level peer authentication, data origin authentication, data integrity, data confidentiality (encryption), and replay protection. This service enforces IPsec policies created through the IP Security Policies snap-in or the command-line tool "netsh ipsec". If you stop this service, you may experience network connectivity issues if your policy requires that connections use IPsec. Also,remote management of Windows Firewall is not available when this service is stopped. Microsoft Corporation 6.3.9600.18339 c:\windows\system32\ipsecsvc.dll 5/12/2016 11:59 AM Power %SystemRoot%\system32\umpo.dll Manages power policy and power policy notification delivery. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\umpo.dll 10/28/2014 9:27 PM PrintNotify C:\Windows\system32\spool\drivers\x64\3\PrintConfig.dll This service opens custom printer dialog boxes and handles notifications from a remote print server or a printer. If you turn off this service, you won't be able to see printer extensions or notifications. Microsoft Corporation 0.3.9600.17415 c:\windows\system32\spool\drivers\x64\3\printconfig.dll 10/28/2014 10:07 PM ProfSvc %systemroot%\system32\profsvc.dll This service is responsible for loading and unloading user profiles. If this service is stopped or disabled, users will no longer be able to successfully sign in or sign out, apps might have problems getting to users' data, and components registered to receive profile event notifications won't receive them. Microsoft Corporation 6.3.9600.17930 c:\windows\system32\profsvc.dll 7/9/2015 12:14 PM QWAVE %windir%\system32\qwave.dll Quality Windows Audio Video Experience (qWave) is a networking platform for Audio Video (AV) streaming applications on IP home networks. qWave enhances AV streaming performance and reliability by ensuring network quality-of-service (QoS) for AV applications. It provides mechanisms for admission control, run time monitoring and enforcement, application feedback, and traffic prioritization. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\qwave.dll 10/28/2014 9:17 PM RasAuto %SystemRoot%\System32\rasauto.dll Creates a connection to a remote network whenever a program references a remote DNS or NetBIOS name or address. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\rasauto.dll 10/28/2014 10:34 PM RasMan %SystemRoot%\System32\rasmans.dll Manages dial-up and virtual private network (VPN) connections from this computer to the Internet or other remote networks. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation 6.3.9600.18404 c:\windows\system32\rasmans.dll 7/7/2016 4:34 PM RpcEptMapper %SystemRoot%\System32\RpcEpMap.dll Resolves RPC interfaces identifiers to transport endpoints. If this service is stopped or disabled, programs using Remote Procedure Call (RPC) services will not function properly. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\rpcepmap.dll 10/28/2014 9:28 PM RpcLocator %SystemRoot%\system32\locator.exe In Windows 2003 and earlier versions of Windows, the Remote Procedure Call (RPC) Locator service manages the RPC name service database. In Windows Vista and later versions of Windows, this service does not provide any functionality and is present for application compatibility. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\locator.exe 10/28/2014 10:48 PM RpcSs %SystemRoot%\system32\rpcss.dll The RPCSS service is the Service Control Manager for COM and DCOM servers. It performs object activations requests, object exporter resolutions and distributed garbage collection for COM and DCOM servers. If this service is stopped or disabled, programs using COM or DCOM will not function properly. It is strongly recommended that you have the RPCSS service running. Microsoft Corporation 6.3.9600.18302 c:\windows\system32\rpcss.dll 4/9/2016 6:10 PM RServer3 "C:\Windows\SysWOW64\rserver30\RServer3.exe" /service Provides secure remote control, file transfer, text chat, voice chat and other services for authorized remote users. Famatech Corp. 3.5.0.0 c:\windows\syswow64\rserver30\rserver3.exe 12/16/2012 11:58 AM SamSs %SystemRoot%\system32\lsass.exe The startup of this service signals other services that the Security Accounts Manager (SAM) is ready to accept requests. Disabling this service will prevent other services in the system from being notified when the SAM is ready, which may in turn cause those services to fail to start correctly. This service should not be disabled. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\lsass.exe 10/28/2014 9:29 PM ScDeviceEnum %SystemRoot%\System32\ScDeviceEnum.dll Creates software device nodes for all smart card readers accessible to a given session. If this service is disabled, WinRT APIs will not be able to enumerate smart card readers. Microsoft Corporation 6.3.9600.18562 c:\windows\system32\scdeviceenum.dll 12/24/2016 7:39 PM Schedule %systemroot%\system32\schedsvc.dll Enables a user to configure and schedule automated tasks on this computer. The service also hosts multiple Windows system-critical tasks. If this service is stopped or disabled, these tasks will not be run at their scheduled times. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation 6.3.9600.18001 c:\windows\system32\schedsvc.dll 7/31/2015 11:38 PM SCPolicySvc %SystemRoot%\System32\certprop.dll Allows the system to be configured to lock the user desktop upon smart card removal. Microsoft Corporation 6.3.9600.18562 c:\windows\system32\certprop.dll 12/24/2016 8:48 PM seclogon %windir%\system32\seclogon.dll Enables starting processes under alternate credentials. If this service is stopped, this type of logon access will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation 6.3.9600.18230 c:\windows\system32\seclogon.dll 2/6/2016 2:08 PM SENS %SystemRoot%\System32\sens.dll Monitors system events and notifies subscribers to COM+ Event System of these events. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\sens.dll 10/28/2014 9:21 PM SensrSvc %SystemRoot%\system32\sensrsvc.dll Monitors various sensors in order to expose data and adapt to system and user state. If this service is stopped or disabled, the display brightness will not adapt to lighting conditions. Stopping this service may affect other system functionality and features as well. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\sensrsvc.dll 10/28/2014 10:11 PM SessionEnv %SystemRoot%\system32\sessenv.dll Remote Desktop Configuration service (RDCS) is responsible for all Remote Desktop Services and Remote Desktop related configuration and session maintenance activities that require SYSTEM context. These include per-session temporary folders, RD themes, and RD certificates. Microsoft Corporation 6.3.9600.18574 c:\windows\system32\sessenv.dll 1/11/2017 3:12 PM SharedAccess %SystemRoot%\System32\ipnathlp.dll Provides network address translation, addressing, name resolution and/or intrusion prevention services for a home or small office network. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\ipnathlp.dll 10/28/2014 9:07 PM ShellHWDetection %SystemRoot%\System32\shsvcs.dll Provides notifications for AutoPlay hardware events. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\shsvcs.dll 10/28/2014 9:04 PM [DISABLED] SkypeUpdate "C:\Program Files (x86)\Skype\Updater\Updater.exe" Enables the detection, download and installation of updates for Skype. Skype Technologies 7.0.0.450 c:\program files (x86)\skype\updater\updater.exe 3/14/2017 5:59 AM smphost %Systemroot%\System32\smphost.dll Host service for the Microsoft Storage Spaces management provider. If this service is stopped or disabled, Storage Spaces cannot be managed. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\smphost.dll 10/28/2014 9:27 PM SNMPTRAP %SystemRoot%\System32\snmptrap.exe Receives trap messages generated by local or remote Simple Network Management Protocol (SNMP) agents and forwards the messages to SNMP management programs running on this computer. If this service is stopped, SNMP-based programs on this computer will not receive SNMP trap messages. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\snmptrap.exe 10/28/2014 10:42 PM Spooler %SystemRoot%\System32\spoolsv.exe This service spools print jobs and handles interaction with the printer. If you turn off this service, you won't be able to print or see your printers. Microsoft Corporation 6.3.9600.17480 c:\windows\system32\spoolsv.exe 11/4/2014 1:01 AM sppsvc %SystemRoot%\system32\sppsvc.exe Enables the download, installation and enforcement of digital licenses for Windows and Windows applications. If the service is disabled, the operating system and licensed applications may run in a notification mode. It is strongly recommended that you not disable the Software Protection service. Microsoft Corporation 6.3.9600.18376 c:\windows\system32\sppsvc.exe 6/9/2016 3:40 PM SQLWriter "C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe" Provides the interface to backup/restore Microsoft SQL server through the Windows VSS infrastructure. Microsoft Corporation 2015.130.1601.5 c:\program files\microsoft sql server\90\shared\sqlwriter.exe 4/30/2016 2:30 AM SSDPSRV %SystemRoot%\System32\ssdpsrv.dll Discovers networked devices and services that use the SSDP discovery protocol, such as UPnP devices. Also announces SSDP devices and services running on the local computer. If this service is stopped, SSDP-based devices will not be discovered. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\ssdpsrv.dll 10/28/2014 9:09 PM SstpSvc %SystemRoot%\system32\sstpsvc.dll Provides support for the Secure Socket Tunneling Protocol (SSTP) to connect to remote computers using VPN. If this service is disabled, users will not be able to use SSTP to access remote servers. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\sstpsvc.dll 10/28/2014 9:22 PM stisvc %SystemRoot%\System32\wiaservc.dll Provides image acquisition services for scanners and cameras Microsoft Corporation 6.3.9600.17415 c:\windows\system32\wiaservc.dll 10/28/2014 9:59 PM StorSvc %SystemRoot%\system32\storsvc.dll Enforces group policy for storage devices Microsoft Corporation 6.3.9600.17415 c:\windows\system32\storsvc.dll 10/28/2014 10:34 PM svsvc %SystemRoot%\system32\svsvc.dll Verifies potential file system corruptions. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\svsvc.dll 10/28/2014 10:33 PM [DISABLED] SwitchBoard "C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" Adobe SwitchBoard Adobe Systems Incorporated 2.0.13.7486 c:\program files (x86)\common files\adobe\switchboard\switchboard.exe 2/19/2010 4:50 PM swprv %Systemroot%\System32\swprv.dll Manages software-based volume shadow copies taken by the Volume Shadow Copy service. If this service is stopped, software-based volume shadow copies cannot be managed. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\swprv.dll 10/28/2014 9:01 PM SystemEventsBroker %SystemRoot%\System32\SystemEventsBrokerServer.dll Coordinates execution of background work for WinRT application. If this service is stopped or disabled, then background work might not be triggered. Microsoft Corporation 6.3.9600.17827 c:\windows\system32\systemeventsbrokerserver.dll 5/12/2015 9:19 AM TapiSrv %SystemRoot%\System32\tapisrv.dll Provides Telephony API (TAPI) support for programs that control telephony devices on the local computer and, through the LAN, on servers that are also running the service. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\tapisrv.dll 10/28/2014 10:12 PM Te.Service "C:\Program Files (x86)\Windows Kits\10\Testing\Runtimes\TAEF\Wex.Services.exe" Wex.Services [v5.8k] Microsoft Corporation 10.0.14393.795 c:\program files (x86)\windows kits\10\testing\runtimes\taef\wex.services.exe 1/6/2017 1:27 AM TermService %SystemRoot%\System32\termsrv.dll Allows users to connect interactively to a remote computer. Remote Desktop and Remote Desktop Session Host Server depend on this service. To prevent remote use of this computer, clear the checkboxes on the Remote tab of the System properties control panel item. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\termsrv.dll 10/28/2014 9:34 PM Themes %SystemRoot%\system32\themeservice.dll Provides user experience theme management. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\themeservice.dll 10/28/2014 9:26 PM THREADORDER %SystemRoot%\system32\mmcss.dll Provides ordered execution for a group of threads within a specific period of time. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\mmcss.dll 10/28/2014 9:22 PM TrkWks %SystemRoot%\System32\trkwks.dll Maintains links between NTFS files within a computer or across computers in a network. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\trkwks.dll 10/28/2014 9:21 PM TrustedInstaller %SystemRoot%\servicing\TrustedInstaller.exe Enables installation, modification, and removal of Windows updates and optional components. If this service is disabled, install or uninstall of Windows updates might fail for this computer. Microsoft Corporation 6.3.9600.17415 c:\windows\servicing\trustedinstaller.exe 10/28/2014 9:19 PM UI0Detect %SystemRoot%\system32\UI0Detect.exe Enables user notification of user input for interactive services, which enables access to dialogs created by interactive services when they appear. If this service is stopped, notifications of new interactive service dialogs will no longer function and there might not be access to interactive service dialogs. If this service is disabled, both notifications of and access to new interactive service dialogs will no longer function. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\ui0detect.exe 10/28/2014 10:34 PM UmRdpService %SystemRoot%\System32\umrdp.dll Allows the redirection of Printers/Drives/Ports for RDP connections Microsoft Corporation 6.3.9600.17415 c:\windows\system32\umrdp.dll 10/28/2014 8:49 PM upnphost %SystemRoot%\System32\upnphost.dll Allows UPnP devices to be hosted on this computer. If this service is stopped, any hosted UPnP devices will stop functioning and no additional hosted devices can be added. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\upnphost.dll 10/28/2014 8:51 PM VaultSvc C:\Windows\System32\vaultsvc.dll Provides secure storage and retrieval of credentials to users, applications and security service packages. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\vaultsvc.dll 10/28/2014 9:13 PM vds %SystemRoot%\System32\vds.exe Provides management services for disks, volumes, file systems, and storage arrays. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\vds.exe 10/28/2014 10:06 PM VMAuthdService "C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe" Authorization and authentication service for starting and accessing virtual machines. VMware, Inc. 11.1.4.7549 c:\program files (x86)\vmware\vmware workstation\vmware-authd.exe 5/5/2016 3:43 AM vmicguestinterface %SystemRoot%\System32\ICSvc.dll Provides an interface for the Hyper-V host to interact with specific services running inside the virtual machine. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\icsvc.dll 10/28/2014 9:43 PM vmicheartbeat %SystemRoot%\System32\ICSvc.dll Monitors the state of this virtual machine by reporting a heartbeat at regular intervals. This service helps you identify running virtual machines that have stopped responding. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\icsvc.dll 10/28/2014 9:43 PM vmickvpexchange %SystemRoot%\System32\ICSvc.dll Provides a mechanism to exchange data between the virtual machine and the operating system running on the physical computer. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\icsvc.dll 10/28/2014 9:43 PM vmicrdv %SystemRoot%\System32\ICSvc.dll Provides a platform for communication between the virtual machine and the operating system running on the physical computer. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\icsvc.dll 10/28/2014 9:43 PM vmicshutdown %SystemRoot%\System32\ICSvc.dll Provides a mechanism to shut down the operating system of this virtual machine from the management interfaces on the physical computer. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\icsvc.dll 10/28/2014 9:43 PM vmictimesync %SystemRoot%\System32\ICSvc.dll Synchronizes the system time of this virtual machine with the system time of the physical computer. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\icsvc.dll 10/28/2014 9:43 PM vmicvss %SystemRoot%\System32\ICSvc.dll Coordinates the communications that are required to use Volume Shadow Copy Service to back up applications and data on this virtual machine from the operating system on the physical computer. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\icsvc.dll 10/28/2014 9:43 PM [DISABLED] VMnetDHCP C:\Windows\SysWOW64\vmnetdhcp.exe DHCP service for virtual networks. VMware, Inc. 11.1.4.7549 c:\windows\syswow64\vmnetdhcp.exe 5/5/2016 3:43 AM VMUSBArbService "C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe" Arbitration and enumeration of USB devices for virtual machines VMware, Inc. 14.1.5.0 c:\program files (x86)\common files\vmware\usb\vmware-usbarbitrator64.exe 10/21/2015 3:41 PM [DISABLED] VMware NAT Service C:\Windows\SysWOW64\vmnat.exe Network address translation for virtual networks. VMware, Inc. 11.1.4.7549 c:\windows\syswow64\vmnat.exe 5/5/2016 4:07 AM [DISABLED] VMwareHostd "C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe" -u "C:\ProgramData\VMware\hostd\config.xml" Remote access service for registration and management of virtual machines. c:\program files (x86)\vmware\vmware workstation\vmware-hostd.exe 5/5/2016 5:16 AM [DISABLED] VsEtwService120 "C:\Program Files\Microsoft Visual Studio 12.0\Common7\Packages\Debugger\Services\VsEtwService.exe" Provides the Visual Studio Debugger events about the debugged processes. The service will start automaticially when debugging begins. Microsoft Corporation 12.0.30723.0 c:\program files\microsoft visual studio 12.0\common7\packages\debugger\services\vsetwservice.exe 7/22/2014 11:15 PM VSS %systemroot%\system32\vssvc.exe Manages and implements Volume Shadow Copies used for backup and other purposes. If this service is stopped, shadow copies will be unavailable for backup and the backup may fail. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation 6.3.9600.18229 c:\windows\system32\vssvc.exe 2/5/2016 10:46 AM [DISABLED] VSStandardCollectorService140 "C:\Program Files (x86)\Microsoft Visual Studio 14.0\Team Tools\DiagnosticsHub\Collector\StandardCollector.Service.exe" Visual Studio Data Collection Service. When running, this service collects real-time ETW events and processes them. Microsoft Corporation 14.0.25431.1 c:\program files (x86)\microsoft visual studio 14.0\team tools\diagnosticshub\collector\standardcollector.service.exe 9/7/2016 12:06 AM VSStandardCollectorService150 "C:\Program Files (x86)\Microsoft Visual Studio\Shared\Common\DiagnosticsHub.Collection.Service\StandardCollector.Service.exe" Visual Studio Data Collection Service. When running, this service collects real-time ETW events and processes them. Microsoft Corporation 15.0.26208.0 c:\program files (x86)\microsoft visual studio\shared\common\diagnosticshub.collection.service\standardcollector.service.exe 2/8/2017 11:13 PM wbengine "%systemroot%\system32\wbengine.exe" The WBENGINE service is used by Windows Backup to perform backup and recovery operations. If this service is stopped by a user, it may cause the currently running backup or recovery operation to fail. Disabling this service may disable backup and recovery operations using Windows Backup on this computer. Microsoft Corporation 6.3.9600.18437 c:\windows\system32\wbengine.exe 8/11/2016 1:17 PM WbioSrvc %SystemRoot%\System32\wbiosrvc.dll The Windows biometric service gives client applications the ability to capture, compare, manipulate, and store biometric data without gaining direct access to any biometric hardware or samples. The service is hosted in a privileged SVCHOST process. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\wbiosrvc.dll 10/28/2014 9:22 PM Wcmsvc %SystemRoot%\System32\wcmsvc.dll Makes automatic connect/disconnect decisions based on the network connectivity options currently available to the PC and enables management of network connectivity based on Group Policy settings. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\wcmsvc.dll 10/28/2014 9:13 PM wcncsvc %SystemRoot%\System32\wcncsvc.dll WCNCSVC hosts the Windows Connect Now Configuration which is Microsoft's Implementation of Wi-Fi Protected Setup (WPS) protocol. This is used to configure Wireless LAN settings for an Access Point (AP) or a Wi-Fi Device. The service is started programmatically as needed. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\wcncsvc.dll 10/28/2014 9:04 PM WcsPlugInService %SystemRoot%\System32\WcsPlugInService.dll The WcsPlugInService service hosts third-party Windows Color System color device model and gamut map model plug-in modules. These plug-in modules are vendor-specific extensions to the Windows Color System baseline color device and gamut map models. Stopping or disabling the WcsPlugInService service will disable this extensibility feature, and the Windows Color System will use its baseline model processing rather than the vendor's desired processing. This might result in inaccurate color rendering. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\wcspluginservice.dll 10/28/2014 10:17 PM WdiServiceHost %SystemRoot%\system32\wdi.dll The Diagnostic Service Host is used by the Diagnostic Policy Service to host diagnostics that need to run in a Local Service context. If this service is stopped, any diagnostics that depend on it will no longer function. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\wdi.dll 10/28/2014 9:21 PM WdiSystemHost %SystemRoot%\system32\wdi.dll The Diagnostic System Host is used by the Diagnostic Policy Service to host diagnostics that need to run in a Local System context. If this service is stopped, any diagnostics that depend on it will no longer function. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\wdi.dll 10/28/2014 9:21 PM WdNisSvc "%ProgramFiles%\Windows Defender\NisSrv.exe" Helps guard against intrusion attempts targeting known and newly discovered vulnerabilities in network protocols Microsoft Corporation 4.10.209.0 c:\program files\windows defender\nissrv.exe 11/15/2016 12:52 AM WebClient %SystemRoot%\System32\webclnt.dll Enables Windows-based programs to create, access, and modify Internet-based files. If this service is stopped, these functions will not be available. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation 6.3.9600.18376 c:\windows\system32\webclnt.dll 6/9/2016 3:32 PM Wecsvc %SystemRoot%\system32\wecsvc.dll This service manages persistent subscriptions to events from remote sources that support WS-Management protocol. This includes Windows Vista event logs, hardware and IPMI-enabled event sources. The service stores forwarded events in a local Event Log. If this service is stopped or disabled event subscriptions cannot be created and forwarded events cannot be accepted. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\wecsvc.dll 10/28/2014 9:08 PM WEPHOSTSVC %systemroot%\system32\wephostsvc.dll Windows Encryption Provider Host Service brokers encryption related functionalities from 3rd Party Encryption Providers to processes that need to evaluate and apply EAS policies. Stopping this will compromise EAS compliancy checks that have been established by the connected Mail Accounts Microsoft Corporation 6.3.9600.17415 c:\windows\system32\wephostsvc.dll 10/28/2014 10:42 PM wercplsupport %SystemRoot%\System32\wercplsupport.dll This service provides support for viewing, sending and deletion of system-level problem reports for the Problem Reports and Solutions control panel. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\wercplsupport.dll 10/28/2014 10:11 PM WerSvc %SystemRoot%\System32\WerSvc.dll Allows errors to be reported when programs stop working or responding and allows existing solutions to be delivered. Also allows logs to be generated for diagnostic and repair services. If this service is stopped, error reporting might not work correctly and results of diagnostic services and repairs might not be displayed. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\wersvc.dll 10/28/2014 9:20 PM WiaRpc %SystemRoot%\System32\wiarpc.dll Launches applications associated with still image acquisition events. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\wiarpc.dll 10/28/2014 10:34 PM WinDefend "%ProgramFiles%\Windows Defender\MsMpEng.exe" Helps protect users from malware and other potentially unwanted software Microsoft Corporation 4.10.209.0 c:\program files\windows defender\msmpeng.exe 11/15/2016 12:52 AM Windows10FirewallService "C:\Program Files\Windows10FirewallControl\Windows10FirewallService.exe" Windows10FirewallControl (alternative WindowsFirewall/WindowsFilteringPlatform) control panel provider (http://sphinx-soft.com/Vista) Sphinx Software 8.2.0.29 c:\program files\windows10firewallcontrol\windows10firewallservice.exe 3/28/2017 1:58 PM WinHttpAutoProxySvc %SystemRoot%\system32\winhttp.dll WinHTTP implements the client HTTP stack and provides developers with a Win32 API and COM Automation component for sending HTTP requests and receiving responses. In addition, WinHTTP provides support for auto-discovering a proxy configuration via its implementation of the Web Proxy Auto-Discovery (WPAD) protocol. Microsoft Corporation 6.3.9600.18378 c:\windows\system32\winhttp.dll 6/11/2016 12:37 PM Winmgmt %SystemRoot%\system32\wbem\WMIsvc.dll Provides a common interface and object model to access management information about operating system, devices, applications and services. If this service is stopped, most Windows-based software will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\wbem\wmisvc.dll 10/28/2014 9:18 PM WinRM %SystemRoot%\system32\WsmSvc.dll Windows Remote Management (WinRM) service implements the WS-Management protocol for remote management. WS-Management is a standard web services protocol used for remote software and hardware management. The WinRM service listens on the network for WS-Management requests and processes them. The WinRM Service needs to be configured with a listener using winrm.cmd command line tool or through Group Policy in order for it to listen over the network. The WinRM service provides access to WMI data and enables event collection. Event collection and subscription to events require that the service is running. WinRM messages use HTTP and HTTPS as transports. The WinRM service does not depend on IIS but is preconfigured to share a port with IIS on the same machine. The WinRM service reserves the /wsman URL prefix. To prevent conflicts with IIS, administrators should ensure that any websites hosted on IIS do not use the /wsman URL prefix. Microsoft Corporation 6.3.9600.18226 c:\windows\system32\wsmsvc.dll 2/2/2016 12:51 PM WlanSvc %SystemRoot%\System32\wlansvc.dll The WLANSVC service provides the logic required to configure, discover, connect to, and disconnect from a wireless local area network (WLAN) as defined by IEEE 802.11 standards. It also contains the logic to turn your computer into a software access point so that other devices or computers can connect to your computer wirelessly using a WLAN adapter that can support this. Stopping or disabling the WLANSVC service will make all WLAN adapters on your computer inaccessible from the Windows networking UI. It is strongly recommended that you have the WLANSVC service running if your computer has a WLAN adapter. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\wlansvc.dll 10/28/2014 9:03 PM wmiApSrv %systemroot%\system32\wbem\WmiApSrv.exe Provides performance library information from Windows Management Instrumentation (WMI) providers to clients on the network. This service only runs when Performance Data Helper is activated. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\wbem\wmiapsrv.exe 10/28/2014 9:18 PM [DISABLED] WMPNetworkSvc "%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe" Shares Windows Media Player libraries to other networked players and media devices using Universal Plug and Play Microsoft Corporation 12.0.9600.17415 c:\program files\windows media player\wmpnetwk.exe 10/28/2014 9:36 PM WPCSvc %SystemRoot%\System32\wpcsvc.dll This service is a stub for Windows Parental Control functionality that existed in Vista. It is provided for backward compatibility only. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\wpcsvc.dll 10/28/2014 9:26 PM wscsvc %SystemRoot%\System32\wscsvc.dll The WSCSVC (Windows Security Center) service monitors and reports security health settings on the computer. The health settings include firewall (on/off), antivirus (on/off/out of date), antispyware (on/off/out of date), Windows Update (automatically/manually download and install updates), User Account Control (on/off), and Internet settings (recommended/not recommended). The service provides COM APIs for independent software vendors to register and record the state of their products to the Security Center service. The Action Center (AC) UI uses the service to provide systray alerts and a graphical view of the security health states in the AC control panel. Network Access Protection (NAP) uses the service to report the security health states of clients to the NAP Network Policy Server to make network quarantine decisions. The service also has a public API that allows external consumers to programmatically retrieve the aggregated security health state of the system. Microsoft Corporation 6.3.9600.18189 c:\windows\system32\wscsvc.dll 1/6/2016 12:47 PM WSService %SystemRoot%\System32\WSService.dll Provides infrastructure support for Windows Store.This service is started on demand and if disabled applications bought using Windows Store will not behave correctly. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\wsservice.dll 10/28/2014 9:11 PM wudfsvc %SystemRoot%\System32\WUDFSvc.dll Creates and manages user-mode driver processes. This service cannot be stopped. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\wudfsvc.dll 10/28/2014 9:21 PM WwanSvc %SystemRoot%\System32\wwansvc.dll This service manages mobile broadband (GSM & CDMA) data card/embedded module adapters and connections by auto-configuring the networks. It is strongly recommended that this service be kept running for best user experience of mobile broadband devices. Microsoft Corporation 8.1.9600.17415 c:\windows\system32\wwansvc.dll 10/28/2014 9:02 PM Z-VSScopy C:\Program Files (x86)\Z-VSScopy\Z-VSScopy.exe Allows Z-DBackup and Z-VssCopy to access the volume shadow copies of Windows. IMU-BerliNet 1.7.0.9 c:\program files (x86)\z-vsscopy\z-vsscopy.exe 9/5/2013 12:11 PM HKLM\System\CurrentControlSet\Services 1394ohci \SystemRoot\System32\drivers\1394ohci.sys 1394 OpenHCI Driver Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\1394ohci.sys 8/22/2013 7:38 AM 272x_1x System32\drivers\272x_1x.sys rr272x/271x Miniport Driver HighPoint Technologies, Inc. 1.6.6.0 c:\windows\system32\drivers\272x_1x.sys 1/28/2015 1:29 AM 3ware System32\drivers\3ware.sys LSI 3ware SCSI Storport Driver LSI 5.1.0.51 c:\windows\system32\drivers\3ware.sys 4/11/2013 6:49 PM ACPI System32\drivers\ACPI.sys ACPI Driver for NT Microsoft Corporation 6.3.9600.17393 c:\windows\system32\drivers\acpi.sys 10/6/2014 11:29 PM acpiex System32\Drivers\acpiex.sys ACPIEx Driver Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\acpiex.sys 8/22/2013 7:37 AM acpipagr \SystemRoot\System32\drivers\acpipagr.sys ACPI Processor Aggregator Device Driver Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\acpipagr.sys 8/22/2013 7:38 AM AcpiPmi \SystemRoot\System32\drivers\acpipmi.sys ACPI Power Metering Driver Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\acpipmi.sys 8/22/2013 7:38 AM acpitime \SystemRoot\System32\drivers\acpitime.sys ACPI Wake Alarm Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\acpitime.sys 8/22/2013 7:38 AM [DISABLED] adfs adfs Adobe Drive File System Driver Adobe Systems, Inc. 1.0.0.0 c:\windows\system32\drivers\adfs.sys 6/26/2008 4:52 PM ADP80XX System32\drivers\ADP80XX.SYS PMC-Sierra Storport Driver For SPC8x6G SAS/SATA controller PMC-Sierra 1.0.0.254 c:\windows\system32\drivers\adp80xx.sys 7/12/2013 5:47 PM AFD \SystemRoot\system32\drivers\afd.sys Ancillary Function Driver for Winsock Microsoft Corporation 6.3.9600.18089 c:\windows\system32\drivers\afd.sys 10/13/2015 1:10 PM agp440 System32\drivers\agp440.sys 440 NT AGP Filter Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\agp440.sys 8/22/2013 7:39 AM ahcache system32\DRIVERS\ahcache.sys Cache Compatibility Data and Attributes for Individual PE File Microsoft Corporation 6.3.9600.17555 c:\windows\system32\drivers\ahcache.sys 12/11/2014 8:51 PM AmdK8 \SystemRoot\System32\drivers\amdk8.sys Processor Device Driver Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\amdk8.sys 8/22/2013 4:46 AM amdkmafd System32\drivers\amdkmafd.sys AMD Audio Bus Lower Filter Advanced Micro Devices, Inc. 8.14.1.6000 c:\windows\system32\drivers\amdkmafd.sys 9/22/2012 9:04 PM AmdPPM \SystemRoot\System32\drivers\amdppm.sys Processor Device Driver Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\amdppm.sys 8/22/2013 4:46 AM amdsata System32\drivers\amdsata.sys AHCI 1.3 Device Driver Advanced Micro Devices 1.1.4.14 c:\windows\system32\drivers\amdsata.sys 7/8/2013 6:54 PM amdsbs System32\drivers\amdsbs.sys AMD Technology AHCI Compatible Controller Driver for Windows - AMD64 platform AMD Technologies Inc. 3.7.1540.43 c:\windows\system32\drivers\amdsbs.sys 12/11/2012 5:21 PM amdxata System32\drivers\amdxata.sys Storage Filter Driver Advanced Micro Devices 1.1.4.14 c:\windows\system32\drivers\amdxata.sys 7/8/2013 6:45 PM AppID \SystemRoot\system32\drivers\appid.sys Identifies an application and enforces software restriction policies. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\drivers\appid.sys 10/28/2014 10:46 PM arcsas System32\drivers\arcsas.sys Adaptec SAS RAID WS03 Driver PMC-Sierra, Inc. 7.2.0.30261 c:\windows\system32\drivers\arcsas.sys 7/8/2013 8:50 PM AsyncMac \SystemRoot\system32\DRIVERS\asyncmac.sys RAS Asynchronous Media Driver Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\asyncmac.sys 8/22/2013 7:38 AM atapi System32\drivers\atapi.sys ATAPI IDE Miniport Driver Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\atapi.sys 8/22/2013 7:40 AM b06bdrv System32\drivers\bxvbda.sys Broadcom NetXtreme II GigE VBD Broadcom Corporation 7.4.14.0 c:\windows\system32\drivers\bxvbda.sys 2/4/2013 3:47 PM b57nd60a \SystemRoot\system32\DRIVERS\b57nd60a.sys Broadcom NetXtreme Gigabit Ethernet NDIS6.x Unified Driver. Broadcom Corporation 16.2.0.4 c:\windows\system32\drivers\b57nd60a.sys 8/5/2013 10:28 PM BasicDisplay \SystemRoot\System32\drivers\BasicDisplay.sys Microsoft Basic Display Driver Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\basicdisplay.sys 8/22/2013 7:39 AM BasicRender \SystemRoot\System32\drivers\BasicRender.sys Microsoft Basic Render Driver Microsoft Corporation 6.3.9600.18626 c:\windows\system32\drivers\basicrender.sys 3/12/2017 11:04 AM bcmfn2 \SystemRoot\System32\drivers\bcmfn2.sys BCM Function 2 Device Driver Windows (R) Win 7 DDK provider 6.3.9391.6 c:\windows\system32\drivers\bcmfn2.sys 8/2/2013 7:59 PM Beep Beep BEEP Driver Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\beep.sys 8/22/2013 7:40 AM bowser system32\DRIVERS\bowser.sys @%systemroot%\system32\browser.dll,-103 Microsoft Corporation 6.3.9600.18508 c:\windows\system32\drivers\bowser.sys 10/4/2016 4:39 PM BthAvrcpTg \SystemRoot\System32\drivers\BthAvrcpTg.sys Bluetooth Audio/Video Remote Control HID Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\bthavrcptg.sys 8/22/2013 7:38 AM BthHFEnum \SystemRoot\System32\drivers\bthhfenum.sys Bluetooth Hands-Free Audio and Call Control HID Enumerator Microsoft Corporation 6.3.9600.17723 c:\windows\system32\drivers\bthhfenum.sys 3/8/2015 10:02 PM bthhfhid \SystemRoot\System32\drivers\BthHFHid.sys Bluetooth Hands-free HID Minidriver Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\bthhfhid.sys 8/22/2013 7:38 AM BTHMODEM \SystemRoot\System32\drivers\bthmodem.sys Bluetooth Communications Driver Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\bthmodem.sys 8/22/2013 7:36 AM cdrom \SystemRoot\System32\drivers\cdrom.sys SCSI CD-ROM Driver Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\cdrom.sys 8/22/2013 4:46 AM circlass \SystemRoot\System32\drivers\circlass.sys Consumer IR Class Driver for eHome Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\circlass.sys 8/22/2013 7:38 AM CLFS System32\drivers\CLFS.sys General-purpose logging service Microsoft Corporation 6.3.9600.18539 c:\windows\system32\drivers\clfs.sys 11/16/2016 10:52 AM [DISABLED] CLVirtualDrive1.1 \SystemRoot\system32\DRIVERS\CLVirtualDrive1_1.sys CyberLink CLVirtualDrive Driver 1.1 CyberLink 1.1.0.603 c:\windows\system32\drivers\clvirtualdrive1_1.sys 4/26/2013 4:51 AM CmBatt \SystemRoot\System32\drivers\CmBatt.sys Control Method Battery Driver Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\cmbatt.sys 8/22/2013 7:39 AM CNG System32\Drivers\cng.sys Kernel Cryptography, Next Generation Microsoft Corporation 6.3.9600.18581 c:\windows\system32\drivers\cng.sys 1/21/2017 3:22 PM CompFilter64 \SystemRoot\System32\drivers\lvbflt64.sys Logitech USB Video Class Filter Driver Logitech Inc. 13.80.853.0 c:\windows\system32\drivers\lvbflt64.sys 10/22/2012 10:10 PM CompositeBus \SystemRoot\System32\drivers\CompositeBus.sys Multi-Transport Composite Bus Enumerator Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\compositebus.sys 8/22/2013 7:38 AM condrv System32\drivers\condrv.sys Console Driver Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\condrv.sys 8/22/2013 7:40 AM CSC system32\drivers\csc.sys Allows network files to be used while the local computer is offline. Microsoft Corporation 6.3.9600.18581 c:\windows\system32\drivers\csc.sys 1/21/2017 3:22 PM dam system32\drivers\dam.sys Controls activity of desktop applications Microsoft Corporation 6.3.9600.17480 c:\windows\system32\drivers\dam.sys 11/4/2014 2:55 AM Dfsc System32\Drivers\dfsc.sys Client driver for access to DFS Namespaces Microsoft Corporation 6.3.9600.18573 c:\windows\system32\drivers\dfsc.sys 1/10/2017 6:37 PM DIRECTIO \??\C:\Program Files\PerformanceTest\DirectIo64.sys c:\program files\performancetest\directio64.sys 2/16/2015 1:32 AM disk System32\drivers\disk.sys PnP Disk Driver Microsoft Corporation 6.3.9600.18203 c:\windows\system32\drivers\disk.sys 1/20/2016 10:52 AM dmvsc \SystemRoot\System32\drivers\dmvsc.sys Dynamic Memory Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\dmvsc.sys 8/22/2013 7:37 AM drmkaud \SystemRoot\system32\drivers\drmkaud.sys Microsoft Trusted Audio Drivers Microsoft Corporation 6.3.9600.17415 c:\windows\system32\drivers\drmkaud.sys 10/28/2014 10:47 PM DXGKrnl \SystemRoot\System32\drivers\dxgkrnl.sys Controls the underlying video driver stacks to provide fully-featured display capabilities. Microsoft Corporation 6.3.9600.18623 c:\windows\system32\drivers\dxgkrnl.sys 3/9/2017 5:11 PM ebdrv System32\drivers\evbda.sys Broadcom NetXtreme II 10 GigE VBD Broadcom Corporation 7.4.33.1 c:\windows\system32\drivers\evbda.sys 4/8/2013 10:30 AM EhStorClass System32\drivers\EhStorClass.sys Enhanced Storage Filter Driver Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\ehstorclass.sys 8/22/2013 7:38 AM EhStorTcgDrv System32\drivers\EhStorTcgDrv.sys Microsoft driver for storage devices supporting IEEE 1667 and TCG protocols Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\ehstortcgdrv.sys 8/22/2013 7:37 AM ErrDev \SystemRoot\System32\drivers\errdev.sys Error Device Driver Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\errdev.sys 8/22/2013 7:38 AM exfat exfat exFAT File System Driver Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\exfat.sys 8/22/2013 7:40 AM fastfat fastfat Note - dependance on CDROM.SYS only if required to read/write DVD-RAM media (which appears as CD class device). (Core) (All pieces) Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\fastfat.sys 8/22/2013 7:40 AM fdc \SystemRoot\System32\drivers\fdc.sys Floppy Disk Controller Driver Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\fdc.sys 8/22/2013 7:40 AM FileInfo System32\drivers\fileinfo.sys Collects information about files in memory to be consumed by other system services. Microsoft Corporation 6.3.9600.17031 c:\windows\system32\drivers\fileinfo.sys 2/22/2014 8:13 AM Filetrace system32\drivers\filetrace.sys ETW File Trace Filter Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\filetrace.sys 8/22/2013 7:39 AM flpydisk \SystemRoot\System32\drivers\flpydisk.sys Floppy Driver Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\flpydisk.sys 8/22/2013 7:40 AM FltMgr system32\drivers\fltmgr.sys File System Filter Manager Driver Microsoft Corporation 6.3.9600.17326 c:\windows\system32\drivers\fltmgr.sys 8/25/2014 10:25 PM FsDepends System32\drivers\FsDepends.sys This minifilter tracks the dependencies associated with the various nested volumes/filesystems Microsoft Corporation 6.3.9600.17396 c:\windows\system32\drivers\fsdepends.sys 10/8/2014 3:34 AM fvevol System32\DRIVERS\fvevol.sys BitLocker Drive Encryption Filter Driver Microsoft Corporation 6.3.9600.18383 c:\windows\system32\drivers\fvevol.sys 6/18/2016 2:31 PM FxPPM \SystemRoot\System32\drivers\fxppm.sys Processor Driver Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\fxppm.sys 8/22/2013 4:46 AM gagp30kx System32\drivers\gagp30kx.sys MS Generic AGPv3.0 Filter for K8/9 Processor Platforms Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\gagp30kx.sys 8/22/2013 7:39 AM gencounter \SystemRoot\System32\drivers\vmgencounter.sys Virtual Machine Generation Counter Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\vmgencounter.sys 8/22/2013 7:38 AM GPIOClx0101 System32\Drivers\msgpioclx.sys GPIO Class Extension Driver Microsoft Corporation 6.3.9600.17253 c:\windows\system32\drivers\msgpioclx.sys 8/14/2014 6:24 PM hcmon \??\C:\Windows\system32\drivers\hcmon.sys VMware USB Driver. VMware, Inc. 8.8.0.1 c:\windows\system32\drivers\hcmon.sys 10/21/2015 3:41 PM HdAudAddService \SystemRoot\system32\drivers\HdAudio.sys High Definition Audio Function Driver Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\hdaudio.sys 8/22/2013 7:38 AM HDAudBus \SystemRoot\System32\drivers\HDAudBus.sys High Definition Audio Bus Driver Microsoft Corporation 6.3.9600.17238 c:\windows\system32\drivers\hdaudbus.sys 7/24/2014 7:45 AM HidBatt \SystemRoot\System32\drivers\HidBatt.sys Hid Battery Driver Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\hidbatt.sys 8/22/2013 7:39 AM HidBth \SystemRoot\System32\drivers\hidbth.sys Bluetooth Miniport Driver for HID Devices Microsoft Corporation 6.3.9600.17670 c:\windows\system32\drivers\hidbth.sys 1/29/2015 11:01 PM hidi2c \SystemRoot\System32\drivers\hidi2c.sys I2C HID Miniport Driver Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\hidi2c.sys 8/22/2013 7:37 AM HidIr \SystemRoot\System32\drivers\hidir.sys Infrared Miniport Driver for Input Devices Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\hidir.sys 8/22/2013 7:39 AM HidUsb \SystemRoot\System32\drivers\hidusb.sys USB Miniport Driver for Input Devices Microsoft Corporation 6.3.9600.18340 c:\windows\system32\drivers\hidusb.sys 5/13/2016 7:08 PM HpSAMD System32\drivers\HpSAMD.sys Smart Array SAS/SATA Controller Media Driver Hewlett-Packard Company 8.0.4.0 c:\windows\system32\drivers\hpsamd.sys 3/26/2013 5:36 PM HTTP system32\drivers\HTTP.sys HTTP Service Microsoft Corporation 6.3.9600.18574 c:\windows\system32\drivers\http.sys 1/11/2017 5:29 PM hwpolicy System32\drivers\hwpolicy.sys Contains Processor and other policies Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\hwpolicy.sys 8/22/2013 7:40 AM hyperkbd \SystemRoot\System32\drivers\hyperkbd.sys Microsoft VMBus Synthetic Keyboard Driver Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\hyperkbd.sys 8/22/2013 7:37 AM HyperVideo \SystemRoot\system32\DRIVERS\HyperVideo.sys Microsoft VMBus Video Device Miniport Driver Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\hypervideo.sys 8/22/2013 7:39 AM i8042prt \SystemRoot\System32\drivers\i8042prt.sys i8042 Port Driver Microsoft Corporation 6.3.9600.17480 c:\windows\system32\drivers\i8042prt.sys 11/4/2014 2:54 AM iaLPSSi_GPIO \SystemRoot\System32\drivers\iaLPSSi_GPIO.sys Intel(R) Serial IO GPIO Controller Driver Intel Corporation 1.1.163.0 c:\windows\system32\drivers\ialpssi_gpio.sys 6/26/2013 10:22 AM iaLPSSi_I2C \SystemRoot\System32\drivers\iaLPSSi_I2C.sys Intel(R) Serial IO I2C Controller Driver Intel Corporation 1.1.163.0 c:\windows\system32\drivers\ialpssi_i2c.sys 6/26/2013 10:22 AM iaStorAV System32\drivers\iaStorAV.sys Intel Rapid Storage Technology driver (inbox) - x64 Intel Corporation 12.0.1.1018 c:\windows\system32\drivers\iastorav.sys 7/31/2013 8:00 PM iaStorV System32\drivers\iaStorV.sys Intel Matrix Storage Manager driver - x64 Intel Corporation 8.6.2.1019 c:\windows\system32\drivers\iastorv.sys 4/11/2011 2:48 PM intelide System32\drivers\intelide.sys Intel PCI IDE Driver Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\intelide.sys 8/22/2013 7:40 AM intelpep System32\drivers\intelpep.sys Intel Power Engine Plugin Microsoft Corporation 6.3.9600.17254 c:\windows\system32\drivers\intelpep.sys 10/15/2014 2:29 AM intelppm \SystemRoot\System32\drivers\intelppm.sys Processor Device Driver Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\intelppm.sys 8/22/2013 4:46 AM IpFilterDriver system32\DRIVERS\ipfltdrv.sys IP Traffic Filter Driver Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\ipfltdrv.sys 8/22/2013 7:35 AM IPMIDRV \SystemRoot\System32\drivers\IPMIDrv.sys WMI IPMI DRIVER Microsoft Corporation 6.3.9600.18227 c:\windows\system32\drivers\ipmidrv.sys 2/3/2016 11:14 AM IPNAT System32\drivers\ipnat.sys IP Network Address Translator Microsoft Corporation 6.3.9600.16477 c:\windows\system32\drivers\ipnat.sys 11/27/2013 8:02 AM IRENUM system32\drivers\irenum.sys IR Bus Enumerator Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\irenum.sys 8/22/2013 7:38 AM isapnp System32\drivers\isapnp.sys PNP ISA Bus Driver Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\isapnp.sys 8/22/2013 7:40 AM iScsiPrt \SystemRoot\System32\drivers\msiscsi.sys Microsoft iSCSI Initiator Driver Microsoft Corporation 6.3.9600.18470 c:\windows\system32\drivers\msiscsi.sys 9/9/2016 10:03 AM kbdclass \SystemRoot\System32\drivers\kbdclass.sys Keyboard Class Driver Microsoft Corporation 6.3.9600.17480 c:\windows\system32\drivers\kbdclass.sys 11/4/2014 2:54 AM kbdhid \SystemRoot\System32\drivers\kbdhid.sys HID Keyboard Filter Driver Microsoft Corporation 6.3.9600.17480 c:\windows\system32\drivers\kbdhid.sys 11/4/2014 2:54 AM kbldfltr system32\drivers\kbldfltr.sys Keyboard Lockdown Subsystem Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\kbldfltr.sys 8/22/2013 7:38 AM kdnic \SystemRoot\system32\DRIVERS\kdnic.sys Microsoft Kernel Debugger Network Miniport Microsoft Corporation 6.1.0.0 c:\windows\system32\drivers\kdnic.sys 8/22/2013 7:38 AM KSecDD System32\Drivers\ksecdd.sys Kernel Security Support Provider Interface Microsoft Corporation 6.3.9600.18454 c:\windows\system32\drivers\ksecdd.sys 8/20/2016 9:04 PM KSecPkg System32\Drivers\ksecpkg.sys Kernel Security Support Provider Interface Packages Microsoft Corporation 6.3.9600.18344 c:\windows\system32\drivers\ksecpkg.sys 5/18/2016 6:11 PM ksthunk \SystemRoot\system32\drivers\ksthunk.sys Kernel Streaming WOW Thunk Service Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\ksthunk.sys 8/22/2013 7:39 AM lltdio \SystemRoot\system32\DRIVERS\lltdio.sys Link-Layer Topology Mapper I/O Driver Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\lltdio.sys 8/22/2013 7:36 AM LSI_SAS System32\drivers\lsi_sas.sys LSI Fusion-MPT SAS Driver (StorPort) LSI Corporation 1.34.3.82 c:\windows\system32\drivers\lsi_sas.sys 3/28/2013 1:42 PM LSI_SAS2 System32\drivers\lsi_sas2.sys LSI SAS Gen2 Driver (StorPort) LSI Corporation 2.0.60.82 c:\windows\system32\drivers\lsi_sas2.sys 3/28/2013 1:45 PM LSI_SAS3 System32\drivers\lsi_sas3.sys LSI SAS Gen3 Driver (StorPort) LSI Corporation 2.50.65.1 c:\windows\system32\drivers\lsi_sas3.sys 3/15/2013 7:38 PM LSI_SSS System32\drivers\lsi_sss.sys LSI SSS PCIe/Flash Driver (StorPort) LSI Corporation 2.10.61.81 c:\windows\system32\drivers\lsi_sss.sys 3/15/2013 7:39 PM luafv \SystemRoot\system32\drivers\luafv.sys Virtualizes file write failures to per-user locations. Microsoft Corporation 6.3.9600.17031 c:\windows\system32\drivers\luafv.sys 2/22/2014 8:14 AM LVRS64 \SystemRoot\system32\DRIVERS\lvrs64.sys Logitech Kernel Audio Improvement Filter Driver Logitech Inc. 13.80.853.0 c:\windows\system32\drivers\lvrs64.sys 10/22/2012 10:11 PM LVUVC64 \SystemRoot\system32\DRIVERS\lvuvc64.sys Logitech USB Video Class Driver Logitech Inc. 13.80.853.0 c:\windows\system32\drivers\lvuvc64.sys 10/22/2012 10:12 PM megasas System32\drivers\megasas.sys MEGASAS RAID Controller Driver for Windows LSI Corporation 6.3.9466.0 c:\windows\system32\drivers\megasas.sys 7/23/2013 5:08 PM megasr System32\drivers\megasr.sys LSI MegaRAID Software RAID Driver LSI Corporation, Inc. 15.2.2013.129 c:\windows\system32\drivers\megasr.sys 6/3/2013 6:02 PM mirrorv3 \SystemRoot\system32\DRIVERS\rminiv3.sys Radmin Mirror Miniport Driver V3 Famatech International Corp. 3.1.0.0 c:\windows\system32\drivers\rminiv3.sys 8/17/2007 4:53 PM Modem system32\drivers\modem.sys Modem Device Driver Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\modem.sys 8/22/2013 7:40 AM monitor \SystemRoot\System32\drivers\monitor.sys Monitor Driver Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\monitor.sys 8/22/2013 7:36 AM mouclass \SystemRoot\System32\drivers\mouclass.sys Mouse Class Driver Microsoft Corporation 6.3.9600.17480 c:\windows\system32\drivers\mouclass.sys 11/4/2014 2:54 AM mouhid \SystemRoot\System32\drivers\mouhid.sys HID Mouse Filter Driver Microsoft Corporation 6.3.9600.17480 c:\windows\system32\drivers\mouhid.sys 11/4/2014 2:54 AM mountmgr System32\drivers\mountmgr.sys Driver responsible with maintaining persistent drive letters and names for volumes Microsoft Corporation 6.3.9600.18405 c:\windows\system32\drivers\mountmgr.sys 7/8/2016 10:17 AM mpsdrv System32\drivers\mpsdrv.sys @%SystemRoot%\system32\FirewallAPI.dll,-23093 Microsoft Corporation 6.3.9600.17415 c:\windows\system32\drivers\mpsdrv.sys 10/28/2014 10:45 PM MRxDAV \SystemRoot\system32\drivers\mrxdav.sys Network Redirector that provides WebDAV file access for the WebClient service Microsoft Corporation 6.3.9600.18469 c:\windows\system32\drivers\mrxdav.sys 9/8/2016 10:00 AM mrxsmb system32\DRIVERS\mrxsmb.sys Implements the framework for the SMB filesystem redirector Microsoft Corporation 6.3.9600.18586 c:\windows\system32\drivers\mrxsmb.sys 2/1/2017 3:42 PM mrxsmb20 system32\DRIVERS\mrxsmb20.sys Implements the SMB 2.0 protocol, which provides connectivity to network resources on Windows Vista and later servers Microsoft Corporation 6.3.9600.18586 c:\windows\system32\drivers\mrxsmb20.sys 2/1/2017 3:44 PM MsBridge \SystemRoot\system32\DRIVERS\bridge.sys Microsoft MAC Bridge Microsoft Corporation 6.3.9600.17415 c:\windows\system32\drivers\bridge.sys 10/28/2014 10:45 PM Msfs Msfs Mailslot driver Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\msfs.sys 8/22/2013 7:40 AM msgpiowin32 \SystemRoot\System32\drivers\msgpiowin32.sys GPIO Button Driver Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\msgpiowin32.sys 8/22/2013 7:38 AM mshidkmdf \SystemRoot\System32\drivers\mshidkmdf.sys Device Filter to provide pass-through interface between HIDCLASS and KMDF Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\mshidkmdf.sys 8/22/2013 7:39 AM mshidumdf \SystemRoot\System32\drivers\mshidumdf.sys Pass-through Driver for HID-UMDF Interface Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\mshidumdf.sys 8/22/2013 7:39 AM msi2500 \SystemRoot\system32\DRIVERS\msi2500.sys Msi2500 Device Driver Mirics 5.2.1.0 c:\windows\system32\drivers\msi2500.sys 10/15/2016 2:06 PM msisadrv System32\drivers\msisadrv.sys ISA Driver Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\msisadrv.sys 8/22/2013 7:39 AM MSKSSRV \SystemRoot\system32\drivers\MSKSSRV.sys MS KS Server Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\mskssrv.sys 8/22/2013 7:39 AM MsLldp \SystemRoot\system32\DRIVERS\mslldp.sys Microsoft Link-Layer Discovery Protocol Driver Microsoft Corporation 6.3.9600.17415 c:\windows\system32\drivers\mslldp.sys 10/28/2014 10:45 PM MSPCLOCK \SystemRoot\system32\drivers\MSPCLOCK.sys MS Proxy Clock Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\mspclock.sys 8/22/2013 7:39 AM MSPQM \SystemRoot\system32\drivers\MSPQM.sys MS Proxy Quality Manager Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\mspqm.sys 8/22/2013 7:39 AM MsRPC MsRPC Kernel Remote Procedure Call Provider Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\msrpc.sys 8/22/2013 7:39 AM mssmbios \SystemRoot\System32\drivers\mssmbios.sys System Management BIOS Driver Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\mssmbios.sys 8/22/2013 7:39 AM MSTEE \SystemRoot\system32\drivers\MSTEE.sys WDM Tee/Communication Transform Filter Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\mstee.sys 8/22/2013 7:38 AM MTConfig \SystemRoot\System32\drivers\MTConfig.sys Microsoft Multi-Touch HID Driver Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\mtconfig.sys 8/22/2013 7:37 AM Mup System32\Drivers\mup.sys Multiple UNC Provider Driver Microsoft Corporation 6.3.9600.18298 c:\windows\system32\drivers\mup.sys 4/6/2016 2:22 PM mvumis System32\drivers\mvumis.sys Marvell Flash Controller Driver Marvell Semiconductor, Inc. 1.0.5.1015 c:\windows\system32\drivers\mvumis.sys 3/20/2013 1:14 PM NativeWifiP \SystemRoot\system32\DRIVERS\nwifi.sys NativeWiFi Miniport Driver Microsoft Corporation 6.3.9600.17415 c:\windows\system32\drivers\nwifi.sys 10/28/2014 10:45 PM NDIS system32\drivers\ndis.sys NDIS System Driver Microsoft Corporation 6.3.9600.18577 c:\windows\system32\drivers\ndis.sys 1/14/2017 3:29 PM NdisCap \SystemRoot\system32\DRIVERS\ndiscap.sys Microsoft NDIS Capture Microsoft Corporation 6.3.9600.17415 c:\windows\system32\drivers\ndiscap.sys 10/28/2014 10:46 PM NdisImPlatform \SystemRoot\system32\DRIVERS\NdisImPlatform.sys Microsoft Network Adapter Multiplexor Protocol Microsoft Corporation 6.3.9600.17415 c:\windows\system32\drivers\ndisimplatform.sys 10/28/2014 10:45 PM NdisTapi \SystemRoot\system32\DRIVERS\ndistapi.sys Remote Access NDIS TAPI Driver Microsoft Corporation 6.3.9600.17484 c:\windows\system32\drivers\ndistapi.sys 11/8/2014 12:00 AM Ndisuio \SystemRoot\system32\DRIVERS\ndisuio.sys NDIS User mode I/O driver Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\ndisuio.sys 8/22/2013 7:37 AM NdisVirtualBus \SystemRoot\System32\drivers\NdisVirtualBus.sys Microsoft Virtual Network Adapter Enumerator Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\ndisvirtualbus.sys 8/22/2013 7:36 AM NdisWan \SystemRoot\system32\DRIVERS\ndiswan.sys Remote Access NDIS WAN Driver Microsoft Corporation 6.3.9600.18297 c:\windows\system32\drivers\ndiswan.sys 4/5/2016 6:37 PM NdisWanLegacy \SystemRoot\system32\DRIVERS\ndiswan.sys Remote Access LEGACY NDIS WAN Driver Microsoft Corporation 6.3.9600.18297 c:\windows\system32\drivers\ndiswan.sys 4/5/2016 6:37 PM NDProxy NDProxy NDIS Proxy Microsoft Corporation 6.3.9600.17626 c:\windows\system32\drivers\ndproxy.sys 1/5/2015 11:00 PM Ndu system32\drivers\Ndu.sys This service provides network data usage monitoring functionality Microsoft Corporation 6.3.9600.17415 c:\windows\system32\drivers\ndu.sys 10/28/2014 10:45 PM NetBIOS system32\DRIVERS\netbios.sys @netnb.inf,%NetBIOS_Desc%;NetBIOS Interface Microsoft Corporation 6.3.9600.17415 c:\windows\system32\drivers\netbios.sys 10/28/2014 10:47 PM NetBT System32\DRIVERS\netbt.sys This service implements NetBios over TCP/IP. Microsoft Corporation 6.3.9600.18340 c:\windows\system32\drivers\netbt.sys 5/13/2016 7:07 PM netvsc \SystemRoot\System32\drivers\netvsc63.sys Virtual NDIS6.3 Miniport Microsoft Corporation 6.3.9600.18339 c:\windows\system32\drivers\netvsc63.sys 5/12/2016 1:37 PM Npfs Npfs NPFS Driver Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\npfs.sys 8/22/2013 7:40 AM npsvctrig \SystemRoot\System32\drivers\npsvctrig.sys Named pipe service triggers Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\npsvctrig.sys 8/22/2013 7:38 AM nsiproxy system32\drivers\nsiproxy.sys NSI Proxy Service Microsoft Corporation 6.3.9600.17415 c:\windows\system32\drivers\nsiproxy.sys 10/28/2014 10:46 PM Ntfs Ntfs NT File System Driver Microsoft Corporation 6.3.9600.18183 c:\windows\system32\drivers\ntfs.sys 12/28/2015 5:04 PM Null Null NULL Driver Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\null.sys 8/22/2013 7:40 AM nvlddmkm \SystemRoot\system32\DRIVERS\nvlddmkm.sys NVIDIA Windows Kernel Mode Driver, Version 377.35 NVIDIA Corporation 21.21.13.7735 c:\windows\system32\drivers\nvlddmkm.sys 5/1/2017 2:21 PM nvraid System32\drivers\nvraid.sys NVIDIAr nForce(TM) RAID Driver NVIDIA Corporation 10.6.0.22 c:\windows\system32\drivers\nvraid.sys 9/12/2011 8:01 PM nvstor System32\drivers\nvstor.sys NVIDIAr nForce(TM) Sata Performance Driver NVIDIA Corporation 10.6.0.22 c:\windows\system32\drivers\nvstor.sys 9/12/2011 7:53 PM nv_agp System32\drivers\nv_agp.sys NForce NT AGP Filter Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\nv_agp.sys 8/22/2013 7:39 AM Parport \SystemRoot\System32\drivers\parport.sys Parallel Port Driver Microsoft Corporation 6.3.9600.18437 c:\windows\system32\drivers\parport.sys 8/11/2016 2:33 PM partmgr System32\drivers\partmgr.sys Disk class filter driver that auctions out partitions to volume managers Microsoft Corporation 6.3.9600.17396 c:\windows\system32\drivers\partmgr.sys 10/8/2014 3:34 AM pci System32\drivers\pci.sys NT Plug and Play PCI Enumerator Microsoft Corporation 6.3.9600.17238 c:\windows\system32\drivers\pci.sys 7/24/2014 7:45 AM pciide System32\drivers\pciide.sys Generic PCI IDE Bus Driver Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\pciide.sys 8/22/2013 7:40 AM pcmcia System32\drivers\pcmcia.sys PCMCIA Bus Driver Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\pcmcia.sys 8/22/2013 7:40 AM pcw System32\drivers\pcw.sys Performance Counters for Windows Driver Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\pcw.sys 8/22/2013 4:46 AM pdc system32\drivers\pdc.sys Power Dependency Coordinator Driver Microsoft Corporation 6.3.9600.17254 c:\windows\system32\drivers\pdc.sys 10/15/2014 12:34 AM PEAUTH system32\drivers\peauth.sys Protected Environment Authentication and Authorization Export Driver Microsoft Corporation 6.3.9600.17031 c:\windows\system32\drivers\peauth.sys 2/22/2014 8:09 AM PptpMiniport \SystemRoot\system32\DRIVERS\raspptp.sys WAN Miniport (PPTP) Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\raspptp.sys 8/22/2013 7:35 AM Processor \SystemRoot\System32\drivers\processr.sys Processor Device Driver Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\processr.sys 8/22/2013 4:46 AM Psched \SystemRoot\system32\DRIVERS\pacer.sys QoS Packet Scheduler Microsoft Corporation 6.3.9600.17415 c:\windows\system32\drivers\pacer.sys 10/28/2014 10:45 PM QWAVEdrv \SystemRoot\system32\drivers\qwavedrv.sys Quality Windows Audio/Video Experience component driver Microsoft Corporation 6.3.9600.17415 c:\windows\system32\drivers\qwavedrv.sys 10/28/2014 10:47 PM raddrvv3 \??\C:\Windows\SysWOW64\rserver30\raddrvv3.sys Radmin Server support driver Famatech Corp. 3.5.0.0 c:\windows\syswow64\rserver30\raddrvv3.sys 12/18/2012 9:16 PM RasAcd System32\DRIVERS\rasacd.sys Remote Access Auto Connection Driver Microsoft Corporation 6.3.9600.17415 c:\windows\system32\drivers\rasacd.sys 10/28/2014 10:48 PM RasAgileVpn \SystemRoot\system32\DRIVERS\AgileVpn.sys @netavpna.inf,%Svc-Mp-AgileVpn-DispName%;WAN Miniport (IKEv2) Microsoft Corporation 6.3.9600.18404 c:\windows\system32\drivers\agilevpn.sys 7/7/2016 6:32 PM Rasl2tp \SystemRoot\system32\DRIVERS\rasl2tp.sys WAN Miniport (L2TP) Microsoft Corporation 6.3.9600.18226 c:\windows\system32\drivers\rasl2tp.sys 2/2/2016 2:16 PM RasPppoe \SystemRoot\system32\DRIVERS\raspppoe.sys Remote Access PPPOE Driver Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\raspppoe.sys 8/22/2013 7:36 AM RasSstp \SystemRoot\system32\DRIVERS\rassstp.sys WAN Miniport (SSTP) Microsoft Corporation 6.3.9600.17415 c:\windows\system32\drivers\rassstp.sys 10/28/2014 10:45 PM rdbss system32\DRIVERS\rdbss.sys Provides the framework for network mini-redirectors Microsoft Corporation 6.3.9600.18298 c:\windows\system32\drivers\rdbss.sys 4/6/2016 2:20 PM rdpbus \SystemRoot\System32\drivers\rdpbus.sys Microsoft RDP Bus Device driver Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\rdpbus.sys 8/22/2013 7:38 AM RDPDR System32\drivers\rdpdr.sys Remote Desktop Device Redirector Driver Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\rdpdr.sys 8/22/2013 7:36 AM RdpVideoMiniport System32\drivers\rdpvideominiport.sys Microsoft RDP Video Miniport driver Microsoft Corporation 6.3.9600.17415 c:\windows\system32\drivers\rdpvideominiport.sys 10/28/2014 10:47 PM rdyboost System32\drivers\rdyboost.sys ReadyBoost Microsoft Corporation 6.3.9600.17031 c:\windows\system32\drivers\rdyboost.sys 2/22/2014 8:13 AM ReFS ReFS NT ReFS FS Driver Microsoft Corporation 6.3.9600.18514 c:\windows\system32\drivers\refs.sys 10/11/2016 11:56 AM rspndr \SystemRoot\system32\DRIVERS\rspndr.sys Link-Layer Topology Responder Driver for NDIS 6 Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\rspndr.sys 8/22/2013 7:36 AM s3cap \SystemRoot\System32\drivers\vms3cap.sys Microsoft S3 Emulated Device Cap Driver Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\vms3cap.sys 8/22/2013 7:38 AM sbp2port System32\drivers\sbp2port.sys SBP-2 Protocol Driver Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\sbp2port.sys 8/22/2013 4:46 AM scfilter System32\DRIVERS\scfilter.sys Smart card reader filter driver enabling smart card PnP. Microsoft Corporation 6.3.9600.18562 c:\windows\system32\drivers\scfilter.sys 12/24/2016 9:21 PM sdbus \SystemRoot\System32\drivers\sdbus.sys SecureDigital Bus Driver Microsoft Corporation 6.3.9600.17705 c:\windows\system32\drivers\sdbus.sys 3/12/2015 10:01 PM sdstor \SystemRoot\System32\drivers\sdstor.sys SD Storage Class Driver Microsoft Corporation 6.3.9600.17031 c:\windows\system32\drivers\sdstor.sys 2/22/2014 8:14 AM [DISABLED] SensorsSimulatorDriver \SystemRoot\system32\DRIVERS\WUDFRd.sys Windows Driver Foundation - User-mode Driver Framework Reflector Microsoft Corporation 6.3.9600.17415 c:\windows\system32\drivers\wudfrd.sys 10/28/2014 10:46 PM SerCx system32\drivers\SerCx.sys Serial Class Extension Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\sercx.sys 8/22/2013 7:38 AM SerCx2 system32\drivers\SerCx2.sys Serial Class Extension V2 Microsoft Corporation 6.3.9600.16444 c:\windows\system32\drivers\sercx2.sys 10/25/2013 4:28 PM Serenum \SystemRoot\System32\drivers\serenum.sys Serial Port Enumerator Microsoft Corporation 6.3.9600.18437 c:\windows\system32\drivers\serenum.sys 8/11/2016 2:33 PM Serial \SystemRoot\System32\drivers\serial.sys Serial Device Driver Microsoft Corporation 6.3.9600.18437 c:\windows\system32\drivers\serial.sys 8/11/2016 2:33 PM sermouse \SystemRoot\System32\drivers\sermouse.sys Serial Mouse Filter Driver Microsoft Corporation 6.3.9600.17480 c:\windows\system32\drivers\sermouse.sys 11/4/2014 2:55 AM sfloppy \SystemRoot\System32\drivers\sfloppy.sys SCSI Floppy Driver Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\sfloppy.sys 8/22/2013 7:40 AM SiSRaid2 System32\drivers\SiSRaid2.sys SiS RAID Stor Miniport Driver Silicon Integrated Systems Corp. 5.1.1039.2600 c:\windows\system32\drivers\sisraid2.sys 9/24/2008 2:28 PM SiSRaid4 System32\drivers\sisraid4.sys SiS AHCI Stor-Miniport Driver Silicon Integrated Systems 5.1.1039.3600 c:\windows\system32\drivers\sisraid4.sys 10/1/2008 5:56 PM spaceport System32\drivers\spaceport.sys Storage Spaces Driver Microsoft Corporation 6.3.9600.18573 c:\windows\system32\drivers\spaceport.sys 1/10/2017 6:37 PM SpbCx system32\drivers\SpbCx.sys SPB Class Extension Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\spbcx.sys 8/22/2013 7:38 AM srv2 System32\DRIVERS\srv2.sys Enables connectivity from Windows Vista and later clients Microsoft Corporation 6.3.9600.18535 c:\windows\system32\drivers\srv2.sys 11/9/2016 3:22 PM srvnet System32\DRIVERS\srvnet.sys Server Network driver Microsoft Corporation 6.3.9600.18431 c:\windows\system32\drivers\srvnet.sys 8/3/2016 2:05 PM stexstor System32\drivers\stexstor.sys Promise SuperTrak EX Series Driver for Windows x64 Promise Technology, Inc. 5.1.0.10 c:\windows\system32\drivers\stexstor.sys 11/26/2012 8:02 PM StillCam \SystemRoot\system32\DRIVERS\serscan.sys Serial Imaging Device Driver Microsoft Corporation 6.3.9600.17415 c:\windows\system32\drivers\serscan.sys 10/28/2014 9:50 PM storahci System32\drivers\storahci.sys MS AHCI Storport Miniport Driver Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\storahci.sys 8/22/2013 7:40 AM storflt System32\drivers\vmstorfl.sys Virtual Storage Filter Driver Microsoft Corporation 6.3.9600.17415 c:\windows\system32\drivers\vmstorfl.sys 10/28/2014 10:46 PM stornvme System32\drivers\stornvme.sys Microsoft NVM Express Storport Miniport Driver Microsoft Corporation 6.3.9600.18378 c:\windows\system32\drivers\stornvme.sys 6/11/2016 2:33 PM storvsc System32\drivers\storvsc.sys Storage VSC Driver Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\storvsc.sys 8/22/2013 7:37 AM storvsp \SystemRoot\System32\drivers\storvsp.sys Storage vsp Driver Microsoft Corporation 6.3.9600.18575 c:\windows\system32\drivers\storvsp.sys 1/12/2017 11:03 AM swenum \SystemRoot\System32\drivers\swenum.sys Plug and Play Software Device Enumerator Microsoft Corporation 6.3.9600.17415 c:\windows\system32\drivers\swenum.sys 10/28/2014 10:47 PM Tcpip System32\drivers\tcpip.sys TCP/IP Protocol Driver Microsoft Corporation 6.3.9600.18478 c:\windows\system32\drivers\tcpip.sys 9/20/2016 10:18 AM TCPIP6 \SystemRoot\system32\DRIVERS\tcpip.sys @netip6.inf,%MS_TCPIP6.TCPIP6.ServiceDescription%;Microsoft IPv6 Protocol Driver Microsoft Corporation 6.3.9600.18478 c:\windows\system32\drivers\tcpip.sys 9/20/2016 10:18 AM tcpipreg System32\drivers\tcpipreg.sys Provides compatibility for legacy applications which interact with TCP/IP through the registry. If this service is stopped, certain applications may have impaired functionality. Microsoft Corporation 6.3.9600.17041 c:\windows\system32\drivers\tcpipreg.sys 3/6/2014 5:19 AM tdx \SystemRoot\system32\DRIVERS\tdx.sys NetIO Legacy TDI Support Driver Microsoft Corporation 6.3.9600.18089 c:\windows\system32\drivers\tdx.sys 10/13/2015 1:10 PM terminpt \SystemRoot\System32\drivers\terminpt.sys Terminal Server Input Driver Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\terminpt.sys 8/22/2013 7:39 AM TPM \SystemRoot\system32\drivers\tpm.sys @tpm.inf,%TPMDesc%;TPM Driver Microsoft Corporation 6.3.9600.18065 c:\windows\system32\drivers\tpm.sys 9/25/2015 10:23 AM TsUsbFlt system32\drivers\tsusbflt.sys Remote Desktop USB Hub Class Filter Driver Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\tsusbflt.sys 8/22/2013 7:37 AM TsUsbGD \SystemRoot\System32\drivers\TsUsbGD.sys Remote Desktop Generic USB Driver Microsoft Corporation 6.3.9600.17415 c:\windows\system32\drivers\tsusbgd.sys 10/28/2014 10:46 PM tunnel \SystemRoot\system32\DRIVERS\tunnel.sys Microsoft Tunnel Interface Driver Microsoft Corporation 6.3.9600.18048 c:\windows\system32\drivers\tunnel.sys 9/4/2015 3:24 PM uagp35 System32\drivers\uagp35.sys MS AGPv3.5 Filter Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\uagp35.sys 8/22/2013 7:39 AM UASPStor \SystemRoot\System32\drivers\uaspstor.sys Microsoft Uasp Driver Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\uaspstor.sys 8/22/2013 7:37 AM UCX01000 \SystemRoot\System32\drivers\ucx01000.sys USB Controller Extension Microsoft Corporation 6.3.9600.17393 c:\windows\system32\drivers\ucx01000.sys 10/7/2014 1:00 AM UEFI \SystemRoot\System32\drivers\UEFI.sys UEFI Driver for NT Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\uefi.sys 8/22/2013 7:40 AM uliagpkx System32\drivers\uliagpkx.sys ULi AGPv3.0 Filter for K8/9 Processor Platforms Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\uliagpkx.sys 8/22/2013 7:39 AM umbus \SystemRoot\System32\drivers\umbus.sys User-Mode Bus Enumerator Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\umbus.sys 8/22/2013 7:38 AM UmPass \SystemRoot\System32\drivers\umpass.sys Generic pass-through driver Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\umpass.sys 8/22/2013 7:38 AM usbaudio \SystemRoot\system32\drivers\usbaudio.sys USB Audio Class Driver Microsoft Corporation 6.3.9600.16490 c:\windows\system32\drivers\usbaudio.sys 12/13/2013 3:24 AM usbccgp \SystemRoot\System32\drivers\usbccgp.sys USB Common Class Generic Parent Driver Microsoft Corporation 6.3.9600.17238 c:\windows\system32\drivers\usbccgp.sys 7/24/2014 7:44 AM usbcir \SystemRoot\System32\drivers\usbcir.sys USB Consumer IR Driver for eHome Microsoft Corporation 6.3.9600.17415 c:\windows\system32\drivers\usbcir.sys 10/28/2014 10:47 PM usbehci \SystemRoot\System32\drivers\usbehci.sys EHCI eUSB Miniport Driver Microsoft Corporation 6.3.9600.18191 c:\windows\system32\drivers\usbehci.sys 1/8/2016 2:22 PM usbhub \SystemRoot\System32\drivers\usbhub.sys Default Hub Driver for USB Microsoft Corporation 6.3.9600.18088 c:\windows\system32\drivers\usbhub.sys 10/10/2015 2:40 PM USBHUB3 \SystemRoot\System32\drivers\UsbHub3.sys USB3 HUB Driver Microsoft Corporation 6.3.9600.18088 c:\windows\system32\drivers\usbhub3.sys 10/10/2015 2:40 PM usbohci \SystemRoot\System32\drivers\usbohci.sys OHCI USB Miniport Driver Microsoft Corporation 6.3.9600.18088 c:\windows\system32\drivers\usbohci.sys 10/10/2015 2:41 PM usbprint \SystemRoot\System32\drivers\usbprint.sys USB Printer driver Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\usbprint.sys 8/22/2013 7:36 AM USBSTOR \SystemRoot\System32\drivers\USBSTOR.SYS USB Mass Storage Class Driver Microsoft Corporation 6.3.9600.18224 c:\windows\system32\drivers\usbstor.sys 1/31/2016 2:09 PM usbuhci \SystemRoot\System32\drivers\usbuhci.sys UHCI USB Miniport Driver Microsoft Corporation 6.3.9600.18088 c:\windows\system32\drivers\usbuhci.sys 10/10/2015 2:41 PM usbvideo \SystemRoot\System32\Drivers\usbvideo.sys USB Video Class Driver Microsoft Corporation 6.3.9600.17217 c:\windows\system32\drivers\usbvideo.sys 6/21/2014 3:33 AM USBXHCI \SystemRoot\System32\drivers\USBXHCI.SYS USB XHCI Driver Microsoft Corporation 6.3.9600.17795 c:\windows\system32\drivers\usbxhci.sys 4/9/2015 10:08 PM vdrvroot System32\drivers\vdrvroot.sys Virtual Drive Root Enumerator Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\vdrvroot.sys 8/22/2013 7:38 AM VerifierExt system32\drivers\VerifierExt.sys Driver Verifier Extension Microsoft Corporation 6.3.9600.16404 c:\windows\system32\drivers\verifierext.sys 9/14/2013 7:40 AM vhdmp \SystemRoot\System32\drivers\vhdmp.sys VHD Miniport Driver Microsoft Corporation 6.3.9600.18512 c:\windows\system32\drivers\vhdmp.sys 10/8/2016 7:58 PM viaide System32\drivers\viaide.sys VIA Generic PCI IDE Bus Driver VIA Technologies, Inc. 6.0.6000.170 c:\windows\system32\drivers\viaide.sys 8/22/2013 7:40 AM Vid \SystemRoot\System32\drivers\Vid.sys Microsoft Hyper-V Virtualization Infrastructure Driver Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\vid.sys 8/22/2013 7:37 AM vmbus System32\drivers\vmbus.sys Microsoft Hyper-V Virtual Machine Bus Child Driver Microsoft Corporation 6.3.9600.17415 c:\windows\system32\drivers\vmbus.sys 10/28/2014 10:46 PM VMBusHID \SystemRoot\System32\drivers\VMBusHID.sys Microsoft VMBus HID Miniport Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\vmbushid.sys 8/22/2013 7:37 AM vmbusr \SystemRoot\System32\drivers\vmbusr.sys Microsoft Hyper-V Virtual Machine Bus Root Driver Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\vmbusr.sys 8/22/2013 7:36 AM vmci System32\drivers\vmci.sys VMware PCI VMCI Bus Device VMware, Inc. 9.5.10.0 c:\windows\system32\drivers\vmci.sys 5/17/2013 9:19 PM VMnetAdapter \SystemRoot\system32\DRIVERS\vmnetadapter.sys @oem26.inf,%VMnetAdapter.Service.Desc%;Driver for VMware's Virtual Ethernet Adapters Ver. 2 VMware, Inc. 4.2.3.0 c:\windows\system32\drivers\vmnetadapter.sys 7/27/2014 9:30 AM VMnetBridge \SystemRoot\system32\DRIVERS\vmnetbridge.sys @oem4.inf,%VMware_Desc%;VMware Bridge Protocol VMware, Inc. 4.2.3.0 c:\windows\system32\drivers\vmnetbridge.sys 7/27/2014 9:30 AM VMnetuserif \??\C:\Windows\system32\drivers\vmnetuserif.sys Allows VMware applications to use virtual networks. VMware, Inc. 4.2.3.0 c:\windows\system32\drivers\vmnetuserif.sys 5/5/2016 4:08 AM vmx86 \??\C:\Windows\system32\drivers\vmx86.sys VMware Virtualization Driver. VMware, Inc. 11.1.4.7549 c:\windows\system32\drivers\vmx86.sys 5/5/2016 5:33 AM volmgr System32\drivers\volmgr.sys Volume Manager Driver Microsoft Corporation 6.3.9600.18302 c:\windows\system32\drivers\volmgr.sys 4/9/2016 5:31 PM volmgrx System32\drivers\volmgrx.sys Extension of the volume manager driver that manages software RAID volumes (spanned, striped, mirrored, RAID-5) on dynamic disks Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\volmgrx.sys 8/22/2013 7:40 AM volsnap System32\drivers\volsnap.sys Volume Shadow Copy Driver Microsoft Corporation 6.3.9600.18265 c:\windows\system32\drivers\volsnap.sys 3/11/2016 10:44 AM vpci \SystemRoot\System32\drivers\vpci.sys Virtual PCI Bus Microsoft Corporation 6.3.9600.18219 c:\windows\system32\drivers\vpci.sys 1/26/2016 10:48 AM vpcivsp \SystemRoot\System32\drivers\vpcivsp.sys Virtual PCI VSP Driver Microsoft Corporation 6.3.9600.18575 c:\windows\system32\drivers\vpcivsp.sys 1/12/2017 11:03 AM vsmraid System32\drivers\vsmraid.sys VIA RAID DRIVER FOR AMD-X86-64 VIA Technologies Inc.,Ltd 7.0.9200.6320 c:\windows\system32\drivers\vsmraid.sys 1/23/2013 4:35 PM vsock system32\drivers\vsock.sys vSockets Driver VMware, Inc. 9.6.2.0 c:\windows\system32\drivers\vsock.sys 6/29/2014 8:37 PM VST64HWBS2 \SystemRoot\system32\DRIVERS\VSTBS26.SYS HSF_HWB2 WDM driver Conexant Systems, Inc. 7.80.2.0 c:\windows\system32\drivers\vstbs26.sys 10/15/2008 8:54 PM VST64_DPV \SystemRoot\system32\DRIVERS\VSTDPV6.SYS HSF_DP driver Conexant Systems, Inc. 7.80.2.0 c:\windows\system32\drivers\vstdpv6.sys 10/15/2008 8:57 PM vstor2-mntapi20-shared SysWOW64\drivers\vstor2-mntapi20-shared.sys VMware Virtual Storage Volume Driver VMware, Inc. 5.5.0.160 c:\windows\syswow64\drivers\vstor2-mntapi20-shared.sys 8/28/2013 6:25 AM VSTXRAID System32\drivers\vstxraid.sys VIA StorX RAID Controller Driver VIA Corporation 8.0.9200.8110 c:\windows\system32\drivers\vstxraid.sys 1/21/2013 3:00 PM vwifibus \SystemRoot\System32\drivers\vwifibus.sys Implements bus functionality for Virtual WiFi Microsoft Corporation 6.3.9600.18438 c:\windows\system32\drivers\vwifibus.sys 8/12/2016 8:03 PM WacomPen \SystemRoot\System32\drivers\wacompen.sys Wacom Serial Pen Tablet HID Driver Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\wacompen.sys 8/22/2013 7:39 AM WANARP \SystemRoot\system32\DRIVERS\wanarp.sys Remote Access IP ARP Driver Microsoft Corporation 6.3.9600.17626 c:\windows\system32\drivers\wanarp.sys 1/5/2015 10:59 PM Wanarpv6 \SystemRoot\system32\DRIVERS\wanarp.sys Remote Access IPv6 ARP Driver Microsoft Corporation 6.3.9600.17626 c:\windows\system32\drivers\wanarp.sys 1/5/2015 10:59 PM WdBoot \SystemRoot\system32\drivers\WdBoot.sys Windows Defender Boot Driver Microsoft Corporation 4.10.209.0 c:\windows\system32\drivers\wdboot.sys 11/15/2016 12:52 AM WDC_SAM \SystemRoot\System32\drivers\wdcsam64.sys @oem35.inf,%WDC_SAM_ServiceDesc%;Manages WD external storage products. Western Digital Technologies, Inc. 1.1.0.0 c:\windows\system32\drivers\wdcsam64.sys 10/9/2015 4:31 PM Wdf01000 system32\drivers\Wdf01000.sys Kernel Mode Driver Framework Runtime Microsoft Corporation 1.13.9600.16384 c:\windows\system32\drivers\wdf01000.sys 8/22/2013 7:38 AM WdFilter \SystemRoot\system32\drivers\WdFilter.sys Windows Defender On-Access Malware Protection Mini-Filter Driver Microsoft Corporation 4.10.209.0 c:\windows\system32\drivers\wdfilter.sys 11/15/2016 12:52 AM WdNisDrv system32\Drivers\WdNisDrv.sys Helps guard against intrusion attempts targeting known and newly discovered vulnerabilities in network protocols Microsoft Corporation 4.10.209.0 c:\windows\system32\drivers\wdnisdrv.sys 11/15/2016 12:52 AM WFPLWFS system32\DRIVERS\wfplwfs.sys Microsoft Windows Filtering Platform Microsoft Corporation 6.3.9600.17485 c:\windows\system32\drivers\wfplwfs.sys 11/9/2014 10:57 PM WIMMount system32\drivers\wimmount.sys WIM Image mount service driver Microsoft Corporation 6.3.9600.17415 c:\windows\system32\drivers\wimmount.sys 10/28/2014 10:47 PM winachsf \SystemRoot\system32\DRIVERS\VSTCNXT6.SYS HSF_CNXT driver Conexant Systems, Inc. 7.80.2.0 c:\windows\system32\drivers\vstcnxt6.sys 10/15/2008 8:52 PM Windows10FirewallControl \??\C:\Program Files\Windows10FirewallControl\Windows10FirewallControl.sys Windows 10 Firewall Control Sphinx Software 8.0.0.14 c:\program files\windows10firewallcontrol\windows10firewallcontrol.sys 11/19/2016 8:46 AM WinUsb \SystemRoot\System32\drivers\WinUsb.sys Windows WinUSB Class Driver Microsoft Corporation 6.3.9600.18088 c:\windows\system32\drivers\winusb.sys 10/10/2015 2:40 PM WmiAcpi \SystemRoot\System32\drivers\wmiacpi.sys Windows Management Interface for ACPI Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\wmiacpi.sys 8/22/2013 7:40 AM Wof Wof Windows Overlay Filter Microsoft Corporation 6.3.9600.17050 c:\windows\system32\drivers\wof.sys 3/13/2014 4:27 AM wpcfltr system32\DRIVERS\wpcfltr.sys Family Safety Filter Driver Microsoft Corporation 6.3.9600.17415 c:\windows\system32\drivers\wpcfltr.sys 10/28/2014 10:46 PM WpdUpFltr System32\drivers\WpdUpFltr.sys WPD Upper Class Filter Driver Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\wpdupfltr.sys 8/22/2013 7:38 AM ws2ifsl \SystemRoot\system32\drivers\ws2ifsl.sys Winsock IFS Driver Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\ws2ifsl.sys 8/22/2013 7:40 AM WSDPrintDevice \SystemRoot\System32\drivers\WSDPrint.sys Web Services Print Device Driver Microsoft Corporation 6.3.9600.16384 c:\windows\system32\drivers\wsdprint.sys 8/22/2013 7:39 AM WSDScan \SystemRoot\System32\drivers\WSDScan.sys Web Service Based Scan Device Driver Microsoft Corporation 6.3.9600.17415 c:\windows\system32\drivers\wsdscan.sys 10/28/2014 10:47 PM WudfPf system32\drivers\WudfPf.sys Windows Driver Foundation - User-mode Driver Framework Platform Driver Microsoft Corporation 6.3.9600.17415 c:\windows\system32\drivers\wudfpf.sys 10/28/2014 10:46 PM WUDFRd \SystemRoot\System32\drivers\WUDFRd.sys Windows Driver Foundation - User-mode Driver Framework Reflector Microsoft Corporation 6.3.9600.17415 c:\windows\system32\drivers\wudfrd.sys 10/28/2014 10:46 PM WUDFSensorLP \SystemRoot\System32\drivers\WUDFRd.sys Windows Driver Foundation - User-mode Driver Framework Reflector Microsoft Corporation 6.3.9600.17415 c:\windows\system32\drivers\wudfrd.sys 10/28/2014 10:46 PM WUDFWpdFs \SystemRoot\System32\drivers\WUDFRd.sys Windows Driver Foundation - User-mode Driver Framework Reflector Microsoft Corporation 6.3.9600.17415 c:\windows\system32\drivers\wudfrd.sys 10/28/2014 10:46 PM WUDFWpdMtp \SystemRoot\System32\drivers\WUDFRd.sys Windows Driver Foundation - User-mode Driver Framework Reflector Microsoft Corporation 6.3.9600.17415 c:\windows\system32\drivers\wudfrd.sys 10/28/2014 10:46 PM HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Font Drivers [DISABLED] Adobe Type Manager atmfd.dll Windows NT OpenType/Type 1 Font Driver Adobe Systems Incorporated 5.1.2.251 c:\windows\system32\atmfd.dll 3/9/2017 5:13 PM HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\Credential Providers Smartcard Reader Selection Provider HKCR\CLSID\{1b283861-754f-4022-ad47-a5eaaa618894} Windows Smartcard Credential Provider Microsoft Corporation 6.3.9600.17415 c:\windows\system32\smartcardcredentialprovider.dll 10/28/2014 9:07 PM Smartcard WinRT Provider HKCR\CLSID\{1ee7337f-85ac-45e2-a23c-37c753209769} Windows Smartcard Credential Provider Microsoft Corporation 6.3.9600.17415 c:\windows\system32\smartcardcredentialprovider.dll 10/28/2014 9:07 PM PicturePasswordLogonProvider HKCR\CLSID\{2135f72a-90b5-4ed3-a7f1-8bb705ac276a} Windows Authentication UI Microsoft Corporation 6.3.9600.18533 c:\windows\system32\authui.dll 11/5/2016 11:56 AM GenericProvider HKCR\CLSID\{25CBB996-92ED-457e-B28C-4774084BD562} Windows Authentication UI Microsoft Corporation 6.3.9600.18533 c:\windows\system32\authui.dll 11/5/2016 11:56 AM NPProvider HKCR\CLSID\{3dd6bec0-8193-4ffe-ae25-e08e39ea4063} Windows Authentication UI Microsoft Corporation 6.3.9600.18533 c:\windows\system32\authui.dll 11/5/2016 11:56 AM CngCredUICredentialProvider HKCR\CLSID\{600e7adb-da3e-41a4-9225-3c0399e88c0c} Microsoft CNG CredUI Provider Microsoft Corporation 6.3.9600.17415 c:\windows\system32\cngcredui.dll 10/28/2014 9:21 PM PasswordProvider HKCR\CLSID\{60b78e88-ead8-445c-9cfd-0b87f74ea6cd} Windows Authentication UI Microsoft Corporation 6.3.9600.18533 c:\windows\system32\authui.dll 11/5/2016 11:56 AM Smartcard Credential Provider HKCR\CLSID\{8FD7E19C-3BF7-489B-A72C-846AB3678C96} Windows Smartcard Credential Provider Microsoft Corporation 6.3.9600.17415 c:\windows\system32\smartcardcredentialprovider.dll 10/28/2014 9:07 PM Smartcard Pin Provider HKCR\CLSID\{94596c7e-3744-41ce-893e-bbf09122f76a} Windows Smartcard Credential Provider Microsoft Corporation 6.3.9600.17415 c:\windows\system32\smartcardcredentialprovider.dll 10/28/2014 9:07 PM WinBio Credential Provider HKCR\CLSID\{BEC09223-B018-416D-A0AC-523971B639F5} WinBio Credential Provider Microsoft Corporation 6.3.9600.17415 c:\windows\system32\biocredprov.dll 10/28/2014 8:54 PM PINLogonProvider HKCR\CLSID\{cb82ea12-9f71-446d-89e1-8d0924e1256e} Windows Authentication UI Microsoft Corporation 6.3.9600.18533 c:\windows\system32\authui.dll 11/5/2016 11:56 AM CCertProvider HKCR\CLSID\{e74e57b0-6c6d-44d5-9cda-fb2df5ed7435} Cert Credential Provider Microsoft Corporation 6.3.9600.17415 c:\windows\system32\certcredprovider.dll 10/28/2014 9:14 PM WLIDCredentialProvider HKCR\CLSID\{F8A0B131-5F68-486c-8040-7E8FC3C85BB6} Microsoftr Account Credential Provider Microsoft Corporation 6.3.9600.17415 c:\windows\system32\wlidcredprov.dll 10/28/2014 8:56 PM HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\Credential Provider Filters GenericFilter HKCR\CLSID\{DDC0EED2-ADBE-40b6-A217-EDE16A79A0DE} Windows Authentication UI Microsoft Corporation 6.3.9600.18533 c:\windows\system32\authui.dll 11/5/2016 11:56 AM HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\PLAP Providers CRasProvider HKCR\CLSID\{5537E283-B1E7-4EF8-9C6E-7AB0AFE5056D} RAS PLAP Credential Provider Microsoft Corporation 6.3.9600.17415 c:\windows\system32\rasplap.dll 10/28/2014 10:25 PM HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GpExtensions {0ACDD40C-75AC-47ab-BAA0-BF6DE7E7FE63} wlgpclnt.dll 802.11 Group Policy Client Microsoft Corporation 6.3.9600.17415 c:\windows\system32\wlgpclnt.dll 10/28/2014 9:22 PM {0E28E245-9368-4853-AD84-6DA3BA35BB75} C:\Windows\System32\gpprefcl.dll Group Policy Preference Client Microsoft Corporation 6.3.9600.18339 c:\windows\system32\gpprefcl.dll 5/12/2016 12:24 PM {16be69fa-4209-4250-88cb-716cf41954e0} auditcse.dll Windows Audit Settings CSE Microsoft Corporation 6.3.9600.17415 c:\windows\system32\auditcse.dll 10/28/2014 10:19 PM {17D89FEC-5C44-4972-B12D-241CAEF74509} C:\Windows\System32\gpprefcl.dll Group Policy Preference Client Microsoft Corporation 6.3.9600.18339 c:\windows\system32\gpprefcl.dll 5/12/2016 12:24 PM {1A6364EB-776B-4120-ADE1-B63A406A76B5} C:\Windows\System32\gpprefcl.dll Group Policy Preference Client Microsoft Corporation 6.3.9600.18339 c:\windows\system32\gpprefcl.dll 5/12/2016 12:24 PM {25537BA6-77A8-11D2-9B6C-0000F8080861} fdeploy.dll Folder Redirection Group Policy Extension Microsoft Corporation 6.3.9600.17415 c:\windows\system32\fdeploy.dll 10/28/2014 8:55 PM {3610eda5-77ef-11d2-8dc5-00c04fa31a66} %SystemRoot%\System32\dskquota.dll Windows Shell Disk Quota Support DLL Microsoft Corporation 6.3.9600.17415 c:\windows\system32\dskquota.dll 10/28/2014 10:09 PM {3A0DBA37-F8B2-4356-83DE-3E90BD5C261F} C:\Windows\System32\gpprefcl.dll Group Policy Preference Client Microsoft Corporation 6.3.9600.18339 c:\windows\system32\gpprefcl.dll 5/12/2016 12:24 PM {426031c0-0b47-4852-b0ca-ac3d37bfcb39} gptext.dll GPTExt Microsoft Corporation 6.3.9600.17415 c:\windows\system32\gptext.dll 10/28/2014 10:05 PM {42B5FAAE-6536-11d2-AE5A-0000F87571E3} C:\Windows\System32\gpscript.dll Script Client Side Extension Microsoft Corporation 6.3.9600.18339 c:\windows\system32\gpscript.dll 5/12/2016 12:12 PM {4bcd6cde-777b-48b6-9804-43568e23545d} %SystemRoot%\System32\TsUsbRedirectionGroupPolicyExtension.dll Remote Desktop USB Redirection GP Extension Microsoft Corporation 6.3.9600.17415 c:\windows\system32\tsusbredirectiongrouppolicyextension.dll 10/28/2014 10:40 PM {4CFB60C1-FAA6-47f1-89AA-0B18730C9FD3} C:\Windows\System32\iedkcs32.dll IEAK branding Microsoft Corporation 18.0.9600.18639 c:\windows\system32\iedkcs32.dll 3/25/2017 1:00 PM {4D2F9B6F-1E52-4711-A382-6A8B1A003DE6} C:\Windows\System32\tsworkspace.dll RemoteApp and Desktop Connection Component Microsoft Corporation 6.3.9600.17415 c:\windows\system32\tsworkspace.dll 10/28/2014 9:34 PM {5794DAFD-BE60-433f-88A2-1A31939AC01F} C:\Windows\System32\gpprefcl.dll Group Policy Preference Client Microsoft Corporation 6.3.9600.18339 c:\windows\system32\gpprefcl.dll 5/12/2016 12:24 PM {6232C319-91AC-4931-9385-E70C2B099F0E} C:\Windows\System32\gpprefcl.dll Group Policy Preference Client Microsoft Corporation 6.3.9600.18339 c:\windows\system32\gpprefcl.dll 5/12/2016 12:24 PM {6A4C88C6-C502-4f74-8F60-2CB23EDC24E2} C:\Windows\System32\gpprefcl.dll Group Policy Preference Client Microsoft Corporation 6.3.9600.18339 c:\windows\system32\gpprefcl.dll 5/12/2016 12:24 PM {7150F9BF-48AD-4da4-A49C-29EF4A8369BA} C:\Windows\System32\gpprefcl.dll Group Policy Preference Client Microsoft Corporation 6.3.9600.18339 c:\windows\system32\gpprefcl.dll 5/12/2016 12:24 PM {728EE579-943C-4519-9EF7-AB56765798ED} C:\Windows\System32\gpprefcl.dll Group Policy Preference Client Microsoft Corporation 6.3.9600.18339 c:\windows\system32\gpprefcl.dll 5/12/2016 12:24 PM {74EE6C03-5363-4554-B161-627540339CAB} C:\Windows\System32\gpprefcl.dll Group Policy Preference Client Microsoft Corporation 6.3.9600.18339 c:\windows\system32\gpprefcl.dll 5/12/2016 12:24 PM {7933F41E-56F8-41d6-A31C-4148A711EE93} %SystemRoot%\System32\srchadmin.dll Indexing Options Microsoft Corporation 7.0.9600.17415 c:\windows\system32\srchadmin.dll 10/28/2014 10:05 PM {7B849a69-220F-451E-B3FE-2CB811AF94AE} C:\Windows\System32\iedkcs32.dll IEAK branding Microsoft Corporation 18.0.9600.18639 c:\windows\system32\iedkcs32.dll 3/25/2017 1:00 PM {827D319E-6EAC-11D2-A4EA-00C04F79F83A} scecli.dll Windows Security Configuration Editor Client Engine Microsoft Corporation 6.3.9600.17415 c:\windows\system32\scecli.dll 10/28/2014 9:23 PM {8A28E2C5-8D06-49A4-A08C-632DAA493E17} %systemroot%\system32\gpprnext.dll Group Policy Printer Extension Microsoft Corporation 6.3.9600.17415 c:\windows\system32\gpprnext.dll 10/28/2014 10:16 PM {91FBB303-0CD5-4055-BF42-E512A681B325} C:\Windows\System32\gpprefcl.dll Group Policy Preference Client Microsoft Corporation 6.3.9600.18339 c:\windows\system32\gpprefcl.dll 5/12/2016 12:24 PM {A3F3E39B-5D83-4940-B954-28315B82F0A8} C:\Windows\System32\gpprefcl.dll Group Policy Preference Client Microsoft Corporation 6.3.9600.18339 c:\windows\system32\gpprefcl.dll 5/12/2016 12:24 PM {AADCED64-746C-4633-A97C-D61349046527} C:\Windows\System32\gpprefcl.dll Group Policy Preference Client Microsoft Corporation 6.3.9600.18339 c:\windows\system32\gpprefcl.dll 5/12/2016 12:24 PM {B087BE9D-ED37-454f-AF9C-04291E351182} C:\Windows\System32\gpprefcl.dll Group Policy Preference Client Microsoft Corporation 6.3.9600.18339 c:\windows\system32\gpprefcl.dll 5/12/2016 12:24 PM {B587E2B1-4D59-4e7e-AED9-22B9DF11D053} dot3gpclnt.dll 802.3 Group Policy Client Microsoft Corporation 6.3.9600.17415 c:\windows\system32\dot3gpclnt.dll 10/28/2014 8:59 PM {BA649533-0AAC-4E04-B9BC-4DBAE0325B12} pwlauncher.dll Windows To Go Launcher Microsoft Corporation 6.3.9600.17415 c:\windows\system32\pwlauncher.dll 10/28/2014 9:57 PM {BC75B1ED-5833-4858-9BB8-CBF0B166DF9D} C:\Windows\System32\gpprefcl.dll Group Policy Preference Client Microsoft Corporation 6.3.9600.18339 c:\windows\system32\gpprefcl.dll 5/12/2016 12:24 PM {C34B2751-1CF4-44F5-9262-C3FC39666591} pwlauncher.dll Windows To Go Launcher Microsoft Corporation 6.3.9600.17415 c:\windows\system32\pwlauncher.dll 10/28/2014 9:57 PM {C418DD9D-0D14-4efb-8FBF-CFE535C8FAC7} C:\Windows\System32\gpprefcl.dll Group Policy Preference Client Microsoft Corporation 6.3.9600.18339 c:\windows\system32\gpprefcl.dll 5/12/2016 12:24 PM {C631DF4C-088F-4156-B058-4375F0853CD8} %SystemRoot%\System32\cscobj.dll In-proc COM object used by clients of CSC API Microsoft Corporation 6.3.9600.17415 c:\windows\system32\cscobj.dll 10/28/2014 10:28 PM {c6dc5466-785a-11d2-84d0-00c04fb169f7} appmgmts.dll Software installation Service Microsoft Corporation 6.3.9600.17415 c:\windows\system32\appmgmts.dll 10/28/2014 10:30 PM {cdeafc3d-948d-49dd-ab12-e578ba4af7aa} gptext.dll GPTExt Microsoft Corporation 6.3.9600.17415 c:\windows\system32\gptext.dll 10/28/2014 10:05 PM {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D} C:\Windows\System32\iedkcs32.dll IEAK branding Microsoft Corporation 18.0.9600.18639 c:\windows\system32\iedkcs32.dll 3/25/2017 1:00 PM {e437bc1c-aa7d-11d2-a382-00c04f991e27} %SystemRoot%\System32\polstore.dll Policy Storage dll Microsoft Corporation 6.3.9600.18339 c:\windows\system32\polstore.dll 5/12/2016 12:17 PM {E47248BA-94CC-49c4-BBB5-9EB7F05183D0} C:\Windows\System32\gpprefcl.dll Group Policy Preference Client Microsoft Corporation 6.3.9600.18339 c:\windows\system32\gpprefcl.dll 5/12/2016 12:24 PM {E4F48E54-F38D-4884-BFB9-D4D2E5729C18} C:\Windows\System32\gpprefcl.dll Group Policy Preference Client Microsoft Corporation 6.3.9600.18339 c:\windows\system32\gpprefcl.dll 5/12/2016 12:24 PM {E5094040-C46C-4115-B030-04FB2E545B00} C:\Windows\System32\gpprefcl.dll Group Policy Preference Client Microsoft Corporation 6.3.9600.18339 c:\windows\system32\gpprefcl.dll 5/12/2016 12:24 PM {E62688F0-25FD-4c90-BFF5-F508B9D2E31F} C:\Windows\System32\gpprefcl.dll Group Policy Preference Client Microsoft Corporation 6.3.9600.18339 c:\windows\system32\gpprefcl.dll 5/12/2016 12:24 PM {f3ccc681-b74c-4060-9f26-cd84525dca2a} auditcse.dll Windows Audit Settings CSE Microsoft Corporation 6.3.9600.17415 c:\windows\system32\auditcse.dll 10/28/2014 10:19 PM {F9C77450-3A41-477E-9310-9ACD617BD9E3} C:\Windows\System32\gpprefcl.dll Group Policy Preference Client Microsoft Corporation 6.3.9600.18339 c:\windows\system32\gpprefcl.dll 5/12/2016 12:24 PM {FB2CA36D-0B40-4307-821B-A13B252DE56C} gptext.dll GPTExt Microsoft Corporation 6.3.9600.17415 c:\windows\system32\gptext.dll 10/28/2014 10:05 PM {fbf687e6-f063-4d9f-9f4f-fd9a26acdd5f} gptext.dll GPTExt Microsoft Corporation 6.3.9600.17415 c:\windows\system32\gptext.dll 10/28/2014 10:05 PM HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors Adobe PDF Port Monitor AdobePDF.dll Adobe PDF Port Monitor DLL Adobe Systems Inc 15.5.10.63408 c:\windows\system32\adobepdf.dll 2/19/2015 1:51 AM HP BB11 Status Monitor hpinkstsBB11LM.dll Print Status Language Monitor Hewlett-Packard Co. 28.0.1175.0 c:\windows\system32\hpinkstsbb11lm.dll 6/13/2012 5:23 AM HP Discovery Port Monitor (HP ENVY 120 series) HPDiscoPMBB11.dll HP Discovery Port Monitor Hewlett-Packard Co. 28.0.1315.0 c:\windows\system32\hpdiscopmbb11.dll 10/17/2012 7:31 AM Local Port localspl.dll Local Spooler DLL Microsoft Corporation 6.3.9600.18467 c:\windows\system32\localspl.dll 9/3/2016 12:05 PM Microsoft Shared Fax Monitor FXSMON.DLL Microsoft Fax Print Monitor Microsoft Corporation 6.3.9600.17415 c:\windows\system32\fxsmon.dll 10/28/2014 10:28 PM Standard TCP/IP Port tcpmon.dll Standard TCP/IP Port Monitor DLL Microsoft Corporation 6.3.9600.17415 c:\windows\system32\tcpmon.dll 10/28/2014 8:57 PM USB Monitor usbmon.dll Standard Dynamic Printing Port Monitor DLL Microsoft Corporation 6.3.9600.17415 c:\windows\system32\usbmon.dll 10/28/2014 10:26 PM WSD Port WSDMon.dll WSD Printer Port Monitor Microsoft Corporation 6.3.9600.17481 c:\windows\system32\wsdmon.dll 11/4/2014 9:14 PM HKLM\SYSTEM\CurrentControlSet\Control\Print\Providers Internet Print Provider inetpp.dll Internet Print Provider DLL Microsoft Corporation 6.3.9600.18398 c:\windows\system32\inetpp.dll 6/25/2016 2:13 PM LanMan Print Services win32spl.dll Client Side Rendering Print Provider Microsoft Corporation 6.3.9600.18604 c:\windows\system32\win32spl.dll 2/11/2017 1:00 PM HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\SecurityProviders credssp.dll credssp.dll Credential Delegation Security Package Microsoft Corporation 6.3.9600.17415 c:\windows\system32\credssp.dll 10/28/2014 9:27 PM HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Authentication Packages msv1_0 msv1_0 Microsoft Authentication Package v1.0 Microsoft Corporation 6.3.9600.18512 c:\windows\system32\msv1_0.dll 10/8/2016 6:17 PM HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Notification Packages scecli scecli Windows Security Configuration Editor Client Engine Microsoft Corporation 6.3.9600.17415 c:\windows\system32\scecli.dll 10/28/2014 9:23 PM HKLM\SYSTEM\CurrentControlSet\Control\Lsa\OSConfig\Security Packages kerberos kerberos Kerberos Security Package Microsoft Corporation 6.3.9600.18378 c:\windows\system32\kerberos.dll 6/11/2016 12:50 PM msv1_0 msv1_0 Microsoft Authentication Package v1.0 Microsoft Corporation 6.3.9600.18512 c:\windows\system32\msv1_0.dll 10/8/2016 6:17 PM tspkg tspkg Web Service Security Package Microsoft Corporation 6.3.9600.17415 c:\windows\system32\tspkg.dll 10/28/2014 9:25 PM pku2u pku2u Pku2u Security Package Microsoft Corporation 6.3.9600.17728 c:\windows\system32\pku2u.dll 3/12/2015 10:58 PM livessp livessp Live Security Package Microsoft Corporation 6.3.9600.17415 c:\windows\system32\livessp.dll 10/28/2014 9:23 PM wdigest wdigest Microsoft Digest Access Microsoft Corporation 6.3.9600.17415 c:\windows\system32\wdigest.dll 10/28/2014 9:28 PM schannel schannel TLS / SSL Security Provider Microsoft Corporation 6.3.9600.18454 c:\windows\system32\schannel.dll 8/20/2016 7:22 PM HKLM\SYSTEM\CurrentControlSet\Control\NetworkProvider\Order RDPNP %SystemRoot%\System32\drprov.dll Microsoft Terminal Services Microsoft Corporation 6.3.9600.17415 c:\windows\system32\drprov.dll 10/28/2014 10:42 PM LanmanWorkstation %SystemRoot%\System32\ntlanman.dll Microsoft Windows Network Microsoft Corporation 6.3.9600.17415 c:\windows\system32\ntlanman.dll 10/28/2014 9:27 PM webclient %SystemRoot%\System32\davclnt.dll Web Client Network Microsoft Corporation 6.3.9600.17923 c:\windows\system32\davclnt.dll 7/1/2015 6:16 PM [DISABLED] AdobeDriveCS4_NP C:\Program Files (x86)\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll Adobe Drive CS4 Network Adobe Systems Incorporated 4.0.0.344 c:\program files (x86)\common files\adobe\adobe drive cs4\adobedrivecs4_np.dll 8/14/2008 10:39 AM HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries MSAFD Tcpip [TCP/IP] %SystemRoot%\system32\mswsock.dll Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation 6.3.9600.18340 c:\windows\system32\mswsock.dll 5/13/2016 5:58 PM MSAFD Tcpip [UDP/IP] %SystemRoot%\system32\mswsock.dll Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation 6.3.9600.18340 c:\windows\system32\mswsock.dll 5/13/2016 5:58 PM MSAFD Tcpip [RAW/IP] %SystemRoot%\system32\mswsock.dll Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation 6.3.9600.18340 c:\windows\system32\mswsock.dll 5/13/2016 5:58 PM MSAFD Tcpip [TCP/IPv6] %SystemRoot%\system32\mswsock.dll Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation 6.3.9600.18340 c:\windows\system32\mswsock.dll 5/13/2016 5:58 PM MSAFD Tcpip [UDP/IPv6] %SystemRoot%\system32\mswsock.dll Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation 6.3.9600.18340 c:\windows\system32\mswsock.dll 5/13/2016 5:58 PM MSAFD Tcpip [RAW/IPv6] %SystemRoot%\system32\mswsock.dll Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation 6.3.9600.18340 c:\windows\system32\mswsock.dll 5/13/2016 5:58 PM RSVP TCPv6 Service Provider %SystemRoot%\system32\mswsock.dll Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation 6.3.9600.18340 c:\windows\system32\mswsock.dll 5/13/2016 5:58 PM RSVP TCP Service Provider %SystemRoot%\system32\mswsock.dll Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation 6.3.9600.18340 c:\windows\system32\mswsock.dll 5/13/2016 5:58 PM RSVP UDPv6 Service Provider %SystemRoot%\system32\mswsock.dll Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation 6.3.9600.18340 c:\windows\system32\mswsock.dll 5/13/2016 5:58 PM RSVP UDP Service Provider %SystemRoot%\system32\mswsock.dll Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation 6.3.9600.18340 c:\windows\system32\mswsock.dll 5/13/2016 5:58 PM vSockets DGRAM %windir%\system32\vsocklib.dll VSockets Library VMware, Inc. 9.6.0.0 c:\windows\system32\vsocklib.dll 6/29/2014 8:35 PM vSockets STREAM %windir%\system32\vsocklib.dll VSockets Library VMware, Inc. 9.6.0.0 c:\windows\system32\vsocklib.dll 6/29/2014 8:35 PM HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries E-mail Naming Shim Provider %SystemRoot%\system32\napinsp.dll E-mail Naming Shim Provider Microsoft Corporation 6.3.9600.17415 c:\windows\system32\napinsp.dll 10/28/2014 10:42 PM PNRP Cloud Namespace Provider %SystemRoot%\system32\pnrpnsp.dll PNRP Name Space Provider Microsoft Corporation 6.3.9600.17415 c:\windows\system32\pnrpnsp.dll 10/28/2014 9:26 PM PNRP Name Namespace Provider %SystemRoot%\system32\pnrpnsp.dll PNRP Name Space Provider Microsoft Corporation 6.3.9600.17415 c:\windows\system32\pnrpnsp.dll 10/28/2014 9:26 PM Network Location Awareness Legacy (NLAv1) Namespace %SystemRoot%\system32\NLAapi.dll Network Location Awareness 2 Microsoft Corporation 6.3.9600.17415 c:\windows\system32\nlaapi.dll 10/28/2014 9:24 PM Tcpip %SystemRoot%\System32\mswsock.dll Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation 6.3.9600.18340 c:\windows\system32\mswsock.dll 5/13/2016 5:58 PM NTDS %SystemRoot%\System32\winrnr.dll LDAP RnR Provider DLL Microsoft Corporation 6.3.9600.17415 c:\windows\system32\winrnr.dll 10/28/2014 10:44 PM [DISABLED] mdnsNSP C:\Program Files (x86)\Bonjour\mdnsNSP.dll Bonjour Namespace Provider Apple Computer, Inc. 1.0.3.1 c:\program files (x86)\bonjour\mdnsnsp.dll 2/28/2006 4:42 PM HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64 MSAFD Tcpip [TCP/IP] %SystemRoot%\system32\mswsock.dll Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation 6.3.9600.18340 c:\windows\system32\mswsock.dll 5/13/2016 5:58 PM MSAFD Tcpip [UDP/IP] %SystemRoot%\system32\mswsock.dll Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation 6.3.9600.18340 c:\windows\system32\mswsock.dll 5/13/2016 5:58 PM MSAFD Tcpip [RAW/IP] %SystemRoot%\system32\mswsock.dll Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation 6.3.9600.18340 c:\windows\system32\mswsock.dll 5/13/2016 5:58 PM MSAFD Tcpip [TCP/IPv6] %SystemRoot%\system32\mswsock.dll Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation 6.3.9600.18340 c:\windows\system32\mswsock.dll 5/13/2016 5:58 PM MSAFD Tcpip [UDP/IPv6] %SystemRoot%\system32\mswsock.dll Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation 6.3.9600.18340 c:\windows\system32\mswsock.dll 5/13/2016 5:58 PM MSAFD Tcpip [RAW/IPv6] %SystemRoot%\system32\mswsock.dll Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation 6.3.9600.18340 c:\windows\system32\mswsock.dll 5/13/2016 5:58 PM RSVP TCPv6 Service Provider %SystemRoot%\system32\mswsock.dll Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation 6.3.9600.18340 c:\windows\system32\mswsock.dll 5/13/2016 5:58 PM RSVP TCP Service Provider %SystemRoot%\system32\mswsock.dll Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation 6.3.9600.18340 c:\windows\system32\mswsock.dll 5/13/2016 5:58 PM RSVP UDPv6 Service Provider %SystemRoot%\system32\mswsock.dll Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation 6.3.9600.18340 c:\windows\system32\mswsock.dll 5/13/2016 5:58 PM RSVP UDP Service Provider %SystemRoot%\system32\mswsock.dll Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation 6.3.9600.18340 c:\windows\system32\mswsock.dll 5/13/2016 5:58 PM vSockets DGRAM %windir%\system32\vsocklib.dll VSockets Library VMware, Inc. 9.6.0.0 c:\windows\system32\vsocklib.dll 6/29/2014 8:35 PM vSockets STREAM %windir%\system32\vsocklib.dll VSockets Library VMware, Inc. 9.6.0.0 c:\windows\system32\vsocklib.dll 6/29/2014 8:35 PM HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64 E-mail Naming Shim Provider %SystemRoot%\system32\napinsp.dll E-mail Naming Shim Provider Microsoft Corporation 6.3.9600.17415 c:\windows\system32\napinsp.dll 10/28/2014 10:42 PM PNRP Cloud Namespace Provider %SystemRoot%\system32\pnrpnsp.dll PNRP Name Space Provider Microsoft Corporation 6.3.9600.17415 c:\windows\system32\pnrpnsp.dll 10/28/2014 9:26 PM PNRP Name Namespace Provider %SystemRoot%\system32\pnrpnsp.dll PNRP Name Space Provider Microsoft Corporation 6.3.9600.17415 c:\windows\system32\pnrpnsp.dll 10/28/2014 9:26 PM Network Location Awareness Legacy (NLAv1) Namespace %SystemRoot%\system32\NLAapi.dll Network Location Awareness 2 Microsoft Corporation 6.3.9600.17415 c:\windows\system32\nlaapi.dll 10/28/2014 9:24 PM Tcpip %SystemRoot%\System32\mswsock.dll Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation 6.3.9600.18340 c:\windows\system32\mswsock.dll 5/13/2016 5:58 PM NTDS %SystemRoot%\System32\winrnr.dll LDAP RnR Provider DLL Microsoft Corporation 6.3.9600.17415 c:\windows\system32\winrnr.dll 10/28/2014 10:44 PM HKLM\System\CurrentControlSet\Control\Terminal Server\Wds\rdpwd\StartupPrograms rdpclip rdpclip RDP Clipboard Monitor Microsoft Corporation 6.3.9600.18402 c:\windows\system32\rdpclip.exe 7/3/2016 11:45 PM HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit C:\Windows\system32\userinit.exe C:\Windows\system32\userinit.exe Userinit Logon Application Microsoft Corporation 6.3.9600.17415 c:\windows\system32\userinit.exe 10/28/2014 9:28 PM HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\VmApplet SystemPropertiesPerformance.exe SystemPropertiesPerformance.exe Change Computer Performance Settings Microsoft Corporation 6.3.9600.17415 c:\windows\system32\systempropertiesperformance.exe 10/28/2014 10:19 PM HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Appinit_Dlls C:\AeroGlass\UxThemeSignatureBypass64.dll Big Muscle 1.1.0.0 c:\aeroglass\uxthemesignaturebypass64.dll 3/8/2015 1:30 PM HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Windows\Appinit_Dlls C:\AeroGlass\UxThemeSignatureBypass32.dll Big Muscle 1.1.0.0 c:\aeroglass\uxthemesignaturebypass32.dll 3/8/2015 1:30 PM HKLM\System\CurrentControlSet\Control\Session Manager\KnownDlls rpcrt4 rpcrt4.dll Remote Procedure Call Runtime Microsoft Corporation 6.3.9600.18292 c:\windows\system32\rpcrt4.dll 3/31/2016 12:13 AM combase combase.dll Microsoft COM for Windows Microsoft Corporation 6.3.9600.18202 c:\windows\system32\combase.dll 1/19/2016 1:14 PM gdiplus gdiplus.dll Microsoft GDI+ Microsoft Corporation 6.3.9600.18589 c:\windows\system32\gdiplus.dll 2/4/2017 1:39 PM IMAGEHLP IMAGEHLP.dll Windows NT Image Helper Microsoft Corporation 6.3.9600.17415 c:\windows\system32\imagehlp.dll 10/28/2014 9:21 PM MSVCRT MSVCRT.dll Windows NT CRT DLL Microsoft Corporation 7.0.9600.17415 c:\windows\system32\msvcrt.dll 10/28/2014 10:50 PM SHLWAPI SHLWAPI.dll Shell Light-weight Utility Library Microsoft Corporation 6.3.9600.17415 c:\windows\system32\shlwapi.dll 10/28/2014 8:52 PM COMDLG32 COMDLG32.dll Common Dialogs DLL Microsoft Corporation 6.3.9600.17415 c:\windows\system32\comdlg32.dll 10/28/2014 9:44 PM NORMALIZ NORMALIZ.dll Unicode Normalization DLL Microsoft Corporation 6.3.9600.17415 c:\windows\system32\normaliz.dll 10/28/2014 10:45 PM PSAPI PSAPI.DLL Process Status Helper Microsoft Corporation 6.3.9600.17415 c:\windows\system32\psapi.dll 10/28/2014 9:30 PM WLDAP32 WLDAP32.dll Win32 LDAP API DLL Microsoft Corporation 6.3.9600.17415 c:\windows\system32\wldap32.dll 10/28/2014 9:30 PM ole32 ole32.dll Microsoft OLE for Windows Microsoft Corporation 6.3.9600.18619 c:\windows\system32\ole32.dll 3/4/2017 1:07 PM IMM32 IMM32.dll Multi-User Windows IMM32 API Client DLL Microsoft Corporation 6.3.9600.17415 c:\windows\system32\imm32.dll 10/28/2014 9:23 PM _Wow64cpu Wow64cpu.dll AMD64 Wow64 CPU Microsoft Corporation 6.3.9600.17734 c:\windows\system32\wow64cpu.dll 3/20/2015 12:10 AM MSCTF MSCTF.dll MSCTF Server DLL Microsoft Corporation 6.3.9600.18514 c:\windows\system32\msctf.dll 10/11/2016 12:54 PM _Wow64win Wow64win.dll Wow64 Console and Win32 API Logging Microsoft Corporation 6.3.9600.16520 c:\windows\system32\wow64win.dll 1/27/2014 3:53 PM OLEAUT32 OLEAUT32.dll Microsoft Corporation 6.3.9600.18434 c:\windows\system32\oleaut32.dll 8/6/2016 12:59 PM LPK LPK.dll Language Pack Microsoft Corporation 6.3.9600.17415 c:\windows\system32\lpk.dll 10/28/2014 10:49 PM clbcatq clbcatq.dll COM+ Configuration Catalog Microsoft Corporation 2001.12.10530.17415 c:\windows\system32\clbcatq.dll 10/28/2014 8:56 PM WS2_32 WS2_32.dll Windows Socket 2.0 32-Bit DLL Microsoft Corporation 6.3.9600.18340 c:\windows\system32\ws2_32.dll 5/13/2016 5:58 PM SHELL32 SHELL32.dll Windows Shell Common Dll Microsoft Corporation 6.3.9600.18460 c:\windows\system32\shell32.dll 8/27/2016 12:12 PM gdi32 gdi32.dll GDI Client DLL Microsoft Corporation 6.3.9600.18638 c:\windows\system32\gdi32.dll 3/24/2017 4:04 PM _Wow64 Wow64.dll Win32 Emulation on NT64 Microsoft Corporation 6.3.9600.18589 c:\windows\system32\wow64.dll 2/4/2017 3:30 PM DifxApi difxapi.dll Driver Install Frameworks for API library module Microsoft Corporation 2.1.0.0 c:\windows\system32\difxapi.dll 10/28/2014 10:08 PM Setupapi Setupapi.dll Windows Setup API Microsoft Corporation 6.3.9600.17415 c:\windows\system32\setupapi.dll 10/28/2014 8:54 PM kernel32 kernel32.dll Windows NT BASE API Client DLL Microsoft Corporation 6.3.9600.17415 c:\windows\system32\kernel32.dll 10/28/2014 10:45 PM advapi32 advapi32.dll Advanced Windows 32 Base API Microsoft Corporation 6.3.9600.18155 c:\windows\system32\advapi32.dll 12/4/2015 10:59 AM user32 user32.dll Multi-User Windows USER API Client DLL Microsoft Corporation 6.3.9600.18535 c:\windows\system32\user32.dll 11/9/2016 1:49 PM NSI NSI.dll NSI User-mode interface DLL Microsoft Corporation 6.3.9600.17415 c:\windows\system32\nsi.dll 10/28/2014 10:48 PM sechost sechost.dll Host for SCM/SDDL/LSA Lookup APIs Microsoft Corporation 6.3.9600.17734 c:\windows\system32\sechost.dll 3/20/2015 12:08 AM rpcrt4 rpcrt4.dll Remote Procedure Call Runtime Microsoft Corporation 6.3.9600.18292 c:\windows\syswow64\rpcrt4.dll 3/30/2016 11:40 PM combase combase.dll Microsoft COM for Windows Microsoft Corporation 6.3.9600.18202 c:\windows\syswow64\combase.dll 1/19/2016 12:42 PM gdiplus gdiplus.dll Microsoft GDI+ Microsoft Corporation 6.3.9600.18589 c:\windows\syswow64\gdiplus.dll 2/4/2017 1:10 PM IMAGEHLP IMAGEHLP.dll Windows NT Image Helper Microsoft Corporation 6.3.9600.17415 c:\windows\syswow64\imagehlp.dll 10/28/2014 9:00 PM MSVCRT MSVCRT.dll Windows NT CRT DLL Microsoft Corporation 7.0.9600.17415 c:\windows\syswow64\msvcrt.dll 10/28/2014 10:04 PM SHLWAPI SHLWAPI.dll Shell Light-weight Utility Library Microsoft Corporation 6.3.9600.17415 c:\windows\syswow64\shlwapi.dll 10/28/2014 8:43 PM COMDLG32 COMDLG32.dll Common Dialogs DLL Microsoft Corporation 6.3.9600.17415 c:\windows\syswow64\comdlg32.dll 10/28/2014 9:14 PM NORMALIZ NORMALIZ.dll Unicode Normalization DLL Microsoft Corporation 6.3.9600.17415 c:\windows\syswow64\normaliz.dll 10/28/2014 10:00 PM PSAPI PSAPI.DLL Process Status Helper Microsoft Corporation 6.3.9600.17415 c:\windows\syswow64\psapi.dll 10/28/2014 9:06 PM WLDAP32 WLDAP32.dll Win32 LDAP API DLL Microsoft Corporation 6.3.9600.17415 c:\windows\syswow64\wldap32.dll 10/28/2014 9:06 PM ole32 ole32.dll Microsoft OLE for Windows Microsoft Corporation 6.3.9600.18619 c:\windows\syswow64\ole32.dll 3/4/2017 12:57 PM IMM32 IMM32.dll Multi-User Windows IMM32 API Client DLL Microsoft Corporation 6.3.9600.17415 c:\windows\syswow64\imm32.dll 10/28/2014 9:59 PM _Wow64cpu Wow64cpu.dll File not found: C:\Windows\SysWOW64\Wow64cpu.dll MSCTF MSCTF.dll MSCTF Server DLL Microsoft Corporation 6.3.9600.18514 c:\windows\syswow64\msctf.dll 10/11/2016 12:23 PM _Wow64win Wow64win.dll File not found: C:\Windows\SysWOW64\Wow64win.dll OLEAUT32 OLEAUT32.dll Microsoft Corporation 6.3.9600.18434 c:\windows\syswow64\oleaut32.dll 8/6/2016 12:33 PM LPK LPK.dll Language Pack Microsoft Corporation 6.3.9600.17415 c:\windows\syswow64\lpk.dll 10/28/2014 10:04 PM clbcatq clbcatq.dll COM+ Configuration Catalog Microsoft Corporation 2001.12.10530.17415 c:\windows\syswow64\clbcatq.dll 10/28/2014 8:44 PM WS2_32 WS2_32.dll Windows Socket 2.0 32-Bit DLL Microsoft Corporation 6.3.9600.18340 c:\windows\syswow64\ws2_32.dll 5/13/2016 5:35 PM SHELL32 SHELL32.dll Windows Shell Common Dll Microsoft Corporation 6.3.9600.18460 c:\windows\syswow64\shell32.dll 8/27/2016 12:00 PM gdi32 gdi32.dll GDI Client DLL Microsoft Corporation 6.3.9600.18638 c:\windows\syswow64\gdi32.dll 3/24/2017 2:24 PM _Wow64 Wow64.dll File not found: C:\Windows\SysWOW64\Wow64.dll DifxApi difxapi.dll Driver Install Frameworks for API library module Microsoft Corporation 2.1.0.0 c:\windows\syswow64\difxapi.dll 10/28/2014 9:34 PM Setupapi Setupapi.dll Windows Setup API Microsoft Corporation 6.3.9600.17415 c:\windows\syswow64\setupapi.dll 10/28/2014 8:43 PM kernel32 kernel32.dll Windows NT BASE API Client DLL Microsoft Corporation 6.3.9600.17415 c:\windows\syswow64\kernel32.dll 10/28/2014 9:58 PM advapi32 advapi32.dll Advanced Windows 32 Base API Microsoft Corporation 6.3.9600.18155 c:\windows\syswow64\advapi32.dll 12/4/2015 10:57 AM user32 user32.dll Multi-User Windows USER API Client DLL Microsoft Corporation 6.3.9600.18535 c:\windows\syswow64\user32.dll 11/9/2016 1:25 PM NSI NSI.dll NSI User-mode interface DLL Microsoft Corporation 6.3.9600.17415 c:\windows\syswow64\nsi.dll 10/28/2014 10:03 PM sechost sechost.dll Host for SCM/SDDL/LSA Lookup APIs Microsoft Corporation 6.3.9600.17734 c:\windows\syswow64\sechost.dll 3/19/2015 11:20 PM HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell explorer.exe explorer.exe Windows Explorer Microsoft Corporation 6.3.9600.18460 c:\windows\explorer.exe 8/27/2016 11:58 AM HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\AlternateShell cmd.exe cmd.exe Windows Command Processor Microsoft Corporation 6.3.9600.17415 c:\windows\system32\cmd.exe 10/28/2014 9:28 PM HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Classic Start Menu "C:\Program Files\Classic Shell\ClassicStartMenu.exe" -autorun Classic Start Menu IvoSoft 4.3.0.0 c:\program files\classic shell\classicstartmenu.exe 7/30/2016 12:04 PM Windows10FirewallControl C:\Program Files\Windows10FirewallControl\Windows10FirewallControl.exe Windows 10 Firewall Control Sphinx Software 8.2.0.29 c:\program files\windows10firewallcontrol\windows10firewallcontrol.exe 3/28/2017 2:00 PM [DISABLED] AdobeAAMUpdater-1.0 "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" Adobe Updater Startup Utility Adobe Systems Incorporated 9.0.0.30 c:\program files (x86)\common files\adobe\oobe\pdapp\uwa\updaterstartuputility.exe 6/29/2016 3:29 AM [DISABLED] Malwarebytes TrayApp C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe Malwarebytes Tray Application Malwarebytes 3.0.0.1068 c:\program files\malwarebytes\anti-malware\mbamtray.exe 5/9/2017 8:22 PM HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run [DISABLED] AdobeCS4ServiceManager "C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin Adobe CS4 Service Manager Adobe Systems Incorporated 4.0.0.344 c:\program files (x86)\common files\adobe\cs4servicemanager\cs4servicemanager.exe 8/14/2008 10:28 AM [DISABLED] SwitchBoard C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe SwitchBoard Server (32 bit) Adobe Systems Incorporated 2.0.13.7486 c:\program files (x86)\common files\adobe\switchboard\switchboard.exe 2/19/2010 4:50 PM [DISABLED] Adobe Creative Cloud "C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" --showwindow=false --onOSstartup=true Adobe Creative Cloud Adobe Systems Incorporated 4.0.0.184 c:\program files (x86)\adobe\adobe creative cloud\acc\creative cloud.exe 3/10/2017 10:14 AM [DISABLED] AdobeCEPServiceManager "C:\Program Files (x86)\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe" -launchedbylogin Adobe CEP Service Manager Adobe Systems Incorporated 4.0.2.49 c:\program files (x86)\common files\adobe\cepservicemanager4\cepservicemanager.exe 12/26/2013 4:45 AM [DISABLED] Display C:\Program Files (x86)\APC\PowerChute Personal Edition\DataCollectionLauncher.exe Startup Notification Module Schneider Electric 3.0.2.0 c:\program files (x86)\apc\powerchute personal edition\datacollectionlauncher.exe 1/24/2012 6:31 AM [DISABLED] vmware-tray.exe "C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe" VMware Tray Process VMware, Inc. 11.1.4.7549 c:\program files (x86)\vmware\vmware workstation\vmware-tray.exe 5/5/2016 4:46 AM [DISABLED] Adobe ARM "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" Adobe Reader and Acrobat Manager Adobe Systems Incorporated 1.824.16.1310 c:\program files (x86)\common files\adobe\arm\1.0\adobearm.exe 10/28/2015 9:42 PM [DISABLED] AdobeCS5ServiceManager "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin Adobe CS5 Service Manager Adobe Systems Incorporated 5.0.1.134 c:\program files (x86)\common files\adobe\cs5servicemanager\cs5servicemanager.exe 7/22/2010 4:10 PM [DISABLED] CLVirtualDrive9 "C:\Program Files (x86)\CyberLink\Power2Go9\VirtualDrive9.exe" /R CyberLink Virtual Drive CyberLink Corp. 9.0.1002.0 c:\program files (x86)\cyberlink\power2go9\virtualdrive9.exe 10/2/2013 4:28 AM [DISABLED] AdobeCS6ServiceManager "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin Adobe CS6 Service Manager Adobe Systems Incorporated 3.0.3.58 c:\program files (x86)\common files\adobe\cs6servicemanager\cs6servicemanager.exe 4/25/2013 6:41 AM [DISABLED] Acrobat Assistant 8.0 "C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Acrotray.exe" AcroTray Adobe Systems Inc. 15.9.20069.28170 c:\program files (x86)\adobe\acrobat dc\acrobat\acrotray.exe 9/30/2015 2:06 PM [DISABLED] HP Software Update C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe hpwuSchd Application Hewlett-Packard 80.1.1.0 c:\program files (x86)\hp\hp software update\hpwuschd2.exe 5/30/2013 3:49 PM HKLM\SOFTWARE\Classes\Protocols\Filter application/octet-stream HKCR\CLSID\{1E66F26B-79EE-11D2-8710-00C04F79ED0D} Microsoft .NET Runtime Execution Engine Microsoft Corporation 6.3.9600.16384 c:\windows\system32\mscoree.dll 8/22/2013 7:04 AM application/x-complus HKCR\CLSID\{1E66F26B-79EE-11D2-8710-00C04F79ED0D} Microsoft .NET Runtime Execution Engine Microsoft Corporation 6.3.9600.16384 c:\windows\system32\mscoree.dll 8/22/2013 7:04 AM application/x-msdownload HKCR\CLSID\{1E66F26B-79EE-11D2-8710-00C04F79ED0D} Microsoft .NET Runtime Execution Engine Microsoft Corporation 6.3.9600.16384 c:\windows\system32\mscoree.dll 8/22/2013 7:04 AM text/xml HKCR\CLSID\{807573E5-5146-11D5-A672-00B0D022E945} Microsoft Office XML MIME Filter Microsoft Corporation 14.0.4750.1000 c:\program files\common files\microsoft shared\office14\msoxmlmf.dll 2/28/2010 5:24 AM HKLM\SOFTWARE\Classes\Protocols\Handler about HKCR\CLSID\{3050F406-98B5-11CF-BB82-00AA00BDCE0B} Microsoft (R) HTML Viewer Microsoft Corporation 11.0.9600.18639 c:\windows\system32\mshtml.dll 3/25/2017 1:35 PM cdl HKCR\CLSID\{3dd53d40-7b8b-11D0-b013-00aa0059ce02} OLE32 Extensions for Win32 Microsoft Corporation 11.0.9600.18639 c:\windows\system32\urlmon.dll 3/25/2017 12:10 PM dvd HKCR\CLSID\{12D51199-0DB5-46FE-A120-47A3D7D937CC} ActiveX control for streaming video Microsoft Corporation 6.5.9600.18512 c:\windows\system32\msvidctl.dll 10/8/2016 6:53 PM file HKCR\CLSID\{79eac9e7-baf9-11ce-8c82-00aa004ba90b} OLE32 Extensions for Win32 Microsoft Corporation 11.0.9600.18639 c:\windows\system32\urlmon.dll 3/25/2017 12:10 PM ftp HKCR\CLSID\{79eac9e3-baf9-11ce-8c82-00aa004ba90b} OLE32 Extensions for Win32 Microsoft Corporation 11.0.9600.18639 c:\windows\system32\urlmon.dll 3/25/2017 12:10 PM http HKCR\CLSID\{79eac9e2-baf9-11ce-8c82-00aa004ba90b} OLE32 Extensions for Win32 Microsoft Corporation 11.0.9600.18639 c:\windows\system32\urlmon.dll 3/25/2017 12:10 PM https HKCR\CLSID\{79eac9e5-baf9-11ce-8c82-00aa004ba90b} OLE32 Extensions for Win32 Microsoft Corporation 11.0.9600.18639 c:\windows\system32\urlmon.dll 3/25/2017 12:10 PM its HKCR\CLSID\{9D148291-B9C8-11D0-A4CC-0000F80149F6} Microsoftr InfoTech Storage System Library Microsoft Corporation 6.3.9600.17415 c:\windows\system32\itss.dll 10/28/2014 9:55 PM javascript HKCR\CLSID\{3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} Microsoft (R) HTML Viewer Microsoft Corporation 11.0.9600.18639 c:\windows\system32\mshtml.dll 3/25/2017 1:35 PM local HKCR\CLSID\{79eac9e7-baf9-11ce-8c82-00aa004ba90b} OLE32 Extensions for Win32 Microsoft Corporation 11.0.9600.18639 c:\windows\system32\urlmon.dll 3/25/2017 12:10 PM mailto HKCR\CLSID\{3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} Microsoft (R) HTML Viewer Microsoft Corporation 11.0.9600.18639 c:\windows\system32\mshtml.dll 3/25/2017 1:35 PM mhtml HKCR\CLSID\{05300401-BCBC-11d0-85E3-00C04FD85AB4} Microsoft Internet Messaging API Resources Microsoft Corporation 6.3.9600.18639 c:\windows\system32\inetcomm.dll 3/25/2017 1:12 PM mk HKCR\CLSID\{79eac9e6-baf9-11ce-8c82-00aa004ba90b} OLE32 Extensions for Win32 Microsoft Corporation 11.0.9600.18639 c:\windows\system32\urlmon.dll 3/25/2017 12:10 PM ms-help HKCR\CLSID\{314111c7-a502-11d2-bbca-00c04f8ec294} Microsoftr Help Data Services Module Microsoft Corporation 5.70.51021.0 c:\program files\common files\microsoft shared\help\hxds.dll 11/7/2012 8:17 AM ms-its HKCR\CLSID\{9D148291-B9C8-11D0-A4CC-0000F80149F6} Microsoftr InfoTech Storage System Library Microsoft Corporation 6.3.9600.17415 c:\windows\system32\itss.dll 10/28/2014 9:55 PM res HKCR\CLSID\{3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} Microsoft (R) HTML Viewer Microsoft Corporation 11.0.9600.18639 c:\windows\system32\mshtml.dll 3/25/2017 1:35 PM tv HKCR\CLSID\{CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} ActiveX control for streaming video Microsoft Corporation 6.5.9600.18512 c:\windows\system32\msvidctl.dll 10/8/2016 6:53 PM vbscript HKCR\CLSID\{3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} Microsoft (R) HTML Viewer Microsoft Corporation 11.0.9600.18639 c:\windows\system32\mshtml.dll 3/25/2017 1:35 PM C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup [DISABLED] Adobe Gamma Loader.exe.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AutorunsDisabled\Adobe Gamma Loader.exe.lnk Adobe Gamma Loader Adobe Systems, Inc. 1.0.0.1 c:\program files (x86)\common files\adobe\calibration\adobe gamma loader.exe 11/4/1999 6:06 PM [DISABLED] APC UPS Status.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AutorunsDisabled\APC UPS Status.lnk Startup Notification Module Schneider Electric 3.0.2.0 c:\program files (x86)\apc\powerchute personal edition\display.exe 1/24/2012 6:24 AM [DISABLED] PopMenuStartUp exe.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AutorunsDisabled\PopMenuStartUp exe.lnk PopMenuStartUp Wilson WindowWare, Inc. 1.0.0.0 c:\program files (x86)\winbatch\system\popmenustartup.exe 7/29/2014 5:22 PM HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components Microsoft Windows Media Player %SystemRoot%\system32\unregmp2.exe /ShowWMP Microsoft Windows Media Player Setup Utility Microsoft Corporation 12.0.9600.17415 c:\windows\system32\unregmp2.exe 10/28/2014 9:32 PM Themes Setup themeui.dll Windows Theme API Microsoft Corporation 6.3.9600.17415 c:\windows\system32\themeui.dll 10/28/2014 10:06 PM Enable TLS1.1 and 1.2 C:\Windows\System32\ie4uinit.exe -EnableTLS IE Per-User Initialization Utility Microsoft Corporation 11.0.9600.18639 c:\windows\system32\ie4uinit.exe 3/25/2017 1:00 PM Microsoft Windows Media Player %SystemRoot%\system32\unregmp2.exe /FirstLogon Microsoft Windows Media Player Setup Utility Microsoft Corporation 12.0.9600.17415 c:\windows\system32\unregmp2.exe 10/28/2014 9:32 PM Windows Desktop Update shell32.dll Windows Shell Common Dll Microsoft Corporation 6.3.9600.18460 c:\windows\system32\shell32.dll 8/27/2016 12:12 PM Web Platform Customizations C:\Windows\System32\ie4uinit.exe -UserConfig IE Per-User Initialization Utility Microsoft Corporation 11.0.9600.18639 c:\windows\system32\ie4uinit.exe 3/25/2017 1:00 PM n/a C:\Windows\System32\Rundll32.exe C:\Windows\System32\mscories.dll,Install Microsoft .NET IE SECURITY REGISTRATION Microsoft Corporation 2.0.50727.7905 c:\windows\system32\mscories.dll 8/14/2013 12:56 AM [DISABLED] Microsoft Windows "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE Windows Mail Microsoft Corporation 6.3.9600.17415 c:\program files\windows mail\winmail.exe 10/28/2014 9:52 PM [DISABLED] Disable SSL3 C:\Windows\System32\ie4uinit.exe -DisableSSL3 IE Per-User Initialization Utility Microsoft Corporation 11.0.9600.18639 c:\windows\system32\ie4uinit.exe 3/25/2017 1:00 PM HKLM\SOFTWARE\Wow6432Node\Microsoft\Active Setup\Installed Components Microsoft Windows Media Player %SystemRoot%\system32\unregmp2.exe /ShowWMP Microsoft Windows Media Player Setup Utility Microsoft Corporation 12.0.9600.17415 c:\windows\syswow64\unregmp2.exe 10/28/2014 9:07 PM Microsoft Windows Media Player %SystemRoot%\system32\unregmp2.exe /FirstLogon Microsoft Windows Media Player Setup Utility Microsoft Corporation 12.0.9600.17415 c:\windows\syswow64\unregmp2.exe 10/28/2014 9:07 PM n/a C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install Microsoft .NET IE SECURITY REGISTRATION Microsoft Corporation 2.0.50727.7905 c:\windows\syswow64\mscories.dll 8/14/2013 1:35 AM [DISABLED] Microsoft Windows "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE Windows Mail Microsoft Corporation 6.3.9600.17415 c:\program files (x86)\windows mail\winmail.exe 10/28/2014 9:20 PM HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows\IconServiceLib IconCodecService.dll IconCodecService.dll Converts a PNG part of the icon to a legacy bmp icon Microsoft Corporation 6.3.9600.17415 c:\windows\system32\iconcodecservice.dll 10/28/2014 10:42 PM HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellServiceObjects Published Items Shell Service Object HKCR\CLSID\{003e0278-eca8-4bb8-a256-3689ca1c2600} Windows Shell Common Dll Microsoft Corporation 6.3.9600.18460 c:\windows\system32\shell32.dll 8/27/2016 12:12 PM Microsoft VolumeControlService Class HKCR\CLSID\{3BF043EF-A974-49B3-8322-B853CF1E5EC5} SCA Volume Microsoft Corporation 6.3.9600.17415 c:\windows\system32\sndvolsso.dll 10/28/2014 8:35 PM Windows To Go Shell Service Object HKCR\CLSID\{4DC9C264-730E-4CF6-8374-70F079E4F82B} Windows To Go Shell Service Object Microsoft Corporation 6.3.9600.17415 c:\windows\system32\pwsso.dll 10/28/2014 10:16 PM {566296fe-e0e8-475f-ba9c-a31ad31620b1} HKCR\CLSID\{566296fe-e0e8-475f-ba9c-a31ad31620b1} Device Stage Shell Extension Microsoft Corporation 6.3.9600.17415 c:\windows\system32\dxp.dll 10/28/2014 9:44 PM Toast Manager SSO HKCR\CLSID\{59EFE487-E5B8-4fae-9D2C-FCDF0B70CE70} TWINUI Microsoft Corporation 6.3.9600.18460 c:\windows\system32\twinui.dll 8/27/2016 12:07 PM UnexpectedShutdownReason HKCR\CLSID\{68ddbb56-9d1d-4fd9-89c5-c0da2a625392} Systray shell service object Microsoft Corporation 6.3.9600.18231 c:\windows\system32\stobject.dll 2/8/2016 12:58 PM MediaCenterSSO Class HKCR\CLSID\{6FDEDD65-AC51-43CA-B2D0-9EB5D1155D03} Windows Media Center Shell Service Object Microsoft Corporation 6.3.9600.16384 c:\windows\ehome\ehsso.dll 8/22/2013 5:19 AM PostBootReminder object HKCR\CLSID\{7849596a-48ea-486e-8937-a2a3009f31a9} Windows Shell Common Dll Microsoft Corporation 6.3.9600.18460 c:\windows\system32\shell32.dll 8/27/2016 12:12 PM SkyDrive network states cache SSO HKCR\CLSID\{78DE489B-7931-4f14-83B4-C56D38AC9FFA} Windows Shell Common Dll Microsoft Corporation 6.3.9600.18460 c:\windows\system32\shell32.dll 8/27/2016 12:12 PM Library Group Policy Shell Service Object HKCR\CLSID\{811F592B-CDE7-4ca4-A6D4-7BB3F60AD8FB} Windows Shell Common Dll Microsoft Corporation 6.3.9600.18460 c:\windows\system32\shell32.dll 8/27/2016 12:12 PM Windows System Reset SSO HKCR\CLSID\{872f8dc8-dde4-43bd-ac7a-e3d9fe86ceac} Windows System Reset Platform SSO Microsoft Corporation 6.3.9600.17415 c:\windows\system32\systemresetplatform\systemresetsso.dll 10/28/2014 9:27 PM User Account Control Check Service HKCR\CLSID\{900c0763-5cad-4a34-bc1f-40cd513679d5} Action Center Providers Microsoft Corporation 6.3.9600.17415 c:\windows\system32\hcproviders.dll 10/28/2014 10:17 PM AltTab HKCR\CLSID\{A1607060-5D4C-467a-B711-2B59A6F25957} Windows Shell Alt Tab Microsoft Corporation 6.3.9600.17415 c:\windows\system32\alttab.dll 10/28/2014 8:53 PM Access Page Setting SSO HKCR\CLSID\{A8CD0ADC-23D6-4B79-BCC9-D3309DF34760} Windows Authentication UI Microsoft Corporation 6.3.9600.18533 c:\windows\system32\authui.dll 11/5/2016 11:56 AM WPDShServiceObj Class HKCR\CLSID\{AAA288BA-9A4C-45B0-95D7-94D524869DB5} Windows Portable Device Shell Service Object Microsoft Corporation 6.3.9600.17415 c:\windows\system32\wpdshserviceobj.dll 10/28/2014 9:54 PM Setting Sync Monitor Shell Service Object HKCR\CLSID\{B5CFEB0E-9C01-4942-A5CB-F62EB09D808F} Setting Synchronization Change Monitor Microsoft Corporation 6.3.9600.18231 c:\windows\system32\settingmonitor.dll 2/8/2016 12:55 PM Network Tray SSO HKCR\CLSID\{C2796011-81BA-4148-8FCA-C6643245113F} Network System Icon Microsoft Corporation 6.3.9600.18437 c:\windows\system32\pnidui.dll 8/11/2016 12:17 PM Setting Sync WLS Notifier Shell Service Object HKCR\CLSID\{D46A0B4F-4EEC-4A83-8DE5-9C86F0DFA34D} Setting Synchronization Change Monitor Microsoft Corporation 6.3.9600.18231 c:\windows\system32\settingmonitor.dll 2/8/2016 12:55 PM Windows Search Shell Service Object HKCR\CLSID\{DA67B8AD-E81B-4c70-9B91-B417B5E33527} Indexing Options Microsoft Corporation 7.0.9600.17415 c:\windows\system32\srchadmin.dll 10/28/2014 10:05 PM WebCheck HKCR\CLSID\{EF4D1E1A-1C87-4AA8-8934-E68E4367468D} Shell Doc Object and Control Library Microsoft Corporation 6.3.9600.17415 c:\windows\system32\shdocvw.dll 10/28/2014 10:45 PM Bluetooth Authentication Agent SSO HKCR\CLSID\{F08C5AC2-E722-4116-ADB7-CE41B527994B} Bluetooth Control Panel Applet Microsoft Corporation 6.3.9600.17415 c:\windows\system32\bthprops.cpl 10/28/2014 8:50 PM Sync Center Shell Service Object (Internal) HKCR\CLSID\{F20487CC-FC04-4B1E-863F-D9801796130B} Microsoft Sync Center Microsoft Corporation 6.3.9600.17415 c:\windows\system32\synccenter.dll 10/28/2014 10:03 PM Action Center Shell Service Object HKCR\CLSID\{F56F6FDD-AA9D-4618-A949-C1B91AF43B1A} Action Center Microsoft Corporation 6.3.9600.17415 c:\windows\system32\actioncenter.dll 10/28/2014 9:58 PM ShellFolder for CD Burning HKCR\CLSID\{fbeb8a05-beee-4442-804e-409d6c4515e9} Windows Shell Common Dll Microsoft Corporation 6.3.9600.18460 c:\windows\system32\shell32.dll 8/27/2016 12:12 PM HomeGroup SSO HKCR\CLSID\{ff363bfe-4941-4179-a81c-f3f1ca72d820} HomeGroup Control Panel Microsoft Corporation 6.3.9600.18231 c:\windows\system32\hgcpl.dll 2/8/2016 1:00 PM [DISABLED] SkyDrive network states cache SSO HKCR\CLSID\{78DE489B-7931-4f14-83B4-C56D38AC9FFA} Windows Shell Common Dll Microsoft Corporation 6.3.9600.18460 c:\windows\system32\shell32.dll 8/27/2016 12:12 PM [DISABLED] {C51F0A6B-2A63-4cf4-8938-24404EAEF422} HKCR\CLSID\{C51F0A6B-2A63-4cf4-8938-24404EAEF422} Client Side Caching UI Microsoft Corporation 6.3.9600.17415 c:\windows\system32\cscui.dll 10/28/2014 10:01 PM HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellServiceObjects Published Items Shell Service Object HKCR\CLSID\{003e0278-eca8-4bb8-a256-3689ca1c2600} Windows Shell Common Dll Microsoft Corporation 6.3.9600.18460 c:\windows\syswow64\shell32.dll 8/27/2016 12:00 PM Microsoft VolumeControlService Class HKCR\CLSID\{3BF043EF-A974-49B3-8322-B853CF1E5EC5} SCA Volume Microsoft Corporation 6.3.9600.17415 c:\windows\syswow64\sndvolsso.dll 10/28/2014 8:30 PM Toast Manager SSO HKCR\CLSID\{59EFE487-E5B8-4fae-9D2C-FCDF0B70CE70} TWINUI Microsoft Corporation 6.3.9600.18460 c:\windows\syswow64\twinui.dll 8/27/2016 11:54 AM UnexpectedShutdownReason HKCR\CLSID\{68ddbb56-9d1d-4fd9-89c5-c0da2a625392} Systray shell service object Microsoft Corporation 6.3.9600.18231 c:\windows\syswow64\stobject.dll 2/8/2016 3:39 PM PostBootReminder object HKCR\CLSID\{7849596a-48ea-486e-8937-a2a3009f31a9} Windows Shell Common Dll Microsoft Corporation 6.3.9600.18460 c:\windows\syswow64\shell32.dll 8/27/2016 12:00 PM SkyDrive network states cache SSO HKCR\CLSID\{78DE489B-7931-4f14-83B4-C56D38AC9FFA} Windows Shell Common Dll Microsoft Corporation 6.3.9600.18460 c:\windows\syswow64\shell32.dll 8/27/2016 12:00 PM Library Group Policy Shell Service Object HKCR\CLSID\{811F592B-CDE7-4ca4-A6D4-7BB3F60AD8FB} Windows Shell Common Dll Microsoft Corporation 6.3.9600.18460 c:\windows\syswow64\shell32.dll 8/27/2016 12:00 PM User Account Control Check Service HKCR\CLSID\{900c0763-5cad-4a34-bc1f-40cd513679d5} Action Center Providers Microsoft Corporation 6.3.9600.17415 c:\windows\syswow64\hcproviders.dll 10/28/2014 9:38 PM Access Page Setting SSO HKCR\CLSID\{A8CD0ADC-23D6-4B79-BCC9-D3309DF34760} Windows Authentication UI Microsoft Corporation 6.3.9600.18533 c:\windows\syswow64\authui.dll 11/5/2016 11:46 AM WPDShServiceObj Class HKCR\CLSID\{AAA288BA-9A4C-45B0-95D7-94D524869DB5} Windows Portable Device Shell Service Object Microsoft Corporation 6.3.9600.17415 c:\windows\syswow64\wpdshserviceobj.dll 10/28/2014 9:22 PM Setting Sync Monitor Shell Service Object HKCR\CLSID\{B5CFEB0E-9C01-4942-A5CB-F62EB09D808F} Setting Synchronization Change Monitor Microsoft Corporation 6.3.9600.18231 c:\windows\syswow64\settingmonitor.dll 2/8/2016 3:37 PM Setting Sync WLS Notifier Shell Service Object HKCR\CLSID\{D46A0B4F-4EEC-4A83-8DE5-9C86F0DFA34D} Setting Synchronization Change Monitor Microsoft Corporation 6.3.9600.18231 c:\windows\syswow64\settingmonitor.dll 2/8/2016 3:37 PM Windows Search Shell Service Object HKCR\CLSID\{DA67B8AD-E81B-4c70-9B91-B417B5E33527} Indexing Options Microsoft Corporation 7.0.9600.17415 c:\windows\syswow64\srchadmin.dll 10/28/2014 9:29 PM WebCheck HKCR\CLSID\{EF4D1E1A-1C87-4AA8-8934-E68E4367468D} Shell Doc Object and Control Library Microsoft Corporation 6.3.9600.17415 c:\windows\syswow64\shdocvw.dll 10/28/2014 10:00 PM Bluetooth Authentication Agent SSO HKCR\CLSID\{F08C5AC2-E722-4116-ADB7-CE41B527994B} Bluetooth Control Panel Applet Microsoft Corporation 6.3.9600.17415 c:\windows\syswow64\bthprops.cpl 10/28/2014 8:42 PM Sync Center Shell Service Object (Internal) HKCR\CLSID\{F20487CC-FC04-4B1E-863F-D9801796130B} Microsoft Sync Center Microsoft Corporation 6.3.9600.17415 c:\windows\syswow64\synccenter.dll 10/28/2014 9:28 PM Action Center Shell Service Object HKCR\CLSID\{F56F6FDD-AA9D-4618-A949-C1B91AF43B1A} Action Center Microsoft Corporation 6.3.9600.17415 c:\windows\syswow64\actioncenter.dll 10/28/2014 9:22 PM ShellFolder for CD Burning HKCR\CLSID\{fbeb8a05-beee-4442-804e-409d6c4515e9} Windows Shell Common Dll Microsoft Corporation 6.3.9600.18460 c:\windows\syswow64\shell32.dll 8/27/2016 12:00 PM HomeGroup SSO HKCR\CLSID\{ff363bfe-4941-4179-a81c-f3f1ca72d820} HomeGroup Control Panel Microsoft Corporation 6.3.9600.18231 c:\windows\syswow64\hgcpl.dll 2/8/2016 3:40 PM [DISABLED] SkyDrive network states cache SSO HKCR\CLSID\{78DE489B-7931-4f14-83B4-C56D38AC9FFA} Windows Shell Common Dll Microsoft Corporation 6.3.9600.18460 c:\windows\syswow64\shell32.dll 8/27/2016 12:00 PM Task Scheduler [DISABLED] \Adobe Acrobat Update Task "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" Adobe Reader and Acrobat Manager Adobe Systems Incorporated 1.824.16.1310 c:\program files (x86)\common files\adobe\arm\1.0\adobearm.exe 10/28/2015 9:42 PM \Aero Glass "C:\AeroGlass\aerohost.exe" Aero Glass extension loader for Desktop Window Manager Big Muscle 1.3.0.0 c:\aeroglass\aerohost.exe 12/21/2015 4:50 AM [DISABLED] \AMD Updater "C:\Program Files\AMD\CIM\\Bin64\InstallManagerApp.exe" /AUTOUPDATEIN File not found: C:\Program Files\AMD\CIM\Bin64\InstallManagerApp.exe [DISABLED] \Hosts Compiler "HostsCompiler.bat" NoPrompt >>C:\Users\NoelC\Log\HostsCompiler.log 2>&1 c:\common\hostscompiler.bat 9/12/2016 5:17 PM \LogSystemInfo "LogSystemInfo.bat" >C:\Users\NoelC\Log\LogSystemInfo.log 2>&1 c:\common\logsysteminfo.bat 5/20/2017 3:12 AM \Nightly File Backup "C:\Backup\DoBackup.bat" >>c:\Backup\DoBackup.log 2>&1 c:\backup\dobackup.bat 1/24/2017 3:34 PM \Nightly System Image Backup "wbadmin" start backup -allCritical -vssFull -quiet -backupTarget:G:\ Command Line Interface for Microsoftr BLB Backup Microsoft Corporation 6.3.9600.17415 c:\windows\system32\wbadmin.exe 10/28/2014 9:59 PM [DISABLED] \Optimize Start Menu Cache Files-S-1-5-21-3441778262-1243350346-4227163889-1001 HKCR\CLSID\{2D3F8A1B-6DCD-4ED5-BDBA-A096594B98EF} twinapi Microsoft Corporation 6.3.9600.17415 c:\windows\system32\twinapi.dll 10/28/2014 8:52 PM \RAID Health Check "StartHighPointRAIDManagementServiceBriefly.bat" >>C:\Users\NoelC\Log\StartHighPointRAIDManagementServiceBriefly.log 2>&1 c:\common\starthighpointraidmanagementservicebriefly.bat 2/22/2016 11:40 AM \Scan with MalwareBytes AntiMalware "C:\BIN\SecurityReminder.exe" SecurityReminder 1.0.0.0 c:\bin\securityreminder.exe 7/29/2014 5:22 PM [DISABLED] \SVN Backup "C:\Backup\DoSVNBackup.bat" >>C:\Backup\DoBackup.log 2>&1 c:\backup\dosvnbackup.bat 1/10/2017 8:01 AM \Task Scheduler Test Job "TaskSchedulerTest.bat" >C:\Users\NoelC\Log\TaskSchedulerTest.log 2>&1 c:\bin\taskschedulertest.bat 11/18/2016 3:53 PM \Time Sync "NISTTimeSync.bat" >>C:\Users\NoelC\Log\NISTTimeSync.log 2>&1 c:\common\nisttimesync.bat 4/8/2017 9:11 PM \WizMouse "C:\Program Files (x86)\WizMouse\WizMouseLaunch.exe" /admin c:\program files (x86)\wizmouse\wizmouselaunch.exe 9/9/2013 5:09 AM [DISABLED] \{1E52E3A4-C4CA-40F3-974A-912A9CE57D85} "c:\program files\internet explorer\iexplore.exe" https://ui.skype.com/ui/0/7.35.0.103/en/eula Internet Explorer Microsoft Corporation 11.0.9600.18123 c:\program files\internet explorer\iexplore.exe 11/8/2015 4:24 PM [DISABLED] \Microsoft\VisualStudio\VSIX Auto Update 14 "C:\Program Files (x86)\Microsoft Visual Studio 14.0\Common7\IDE\VSIXAutoUpdate.exe" VSIXAutoUpdate.exe Microsoft Corporation 14.0.25420.1 c:\program files (x86)\microsoft visual studio 14.0\common7\ide\vsixautoupdate.exe 6/20/2016 4:31 PM [DISABLED] \Microsoft\VisualStudio\VSIX Auto Update 15.0.26403.7 "C:\Program Files (x86)\Microsoft Visual Studio\2017\Community\Common7\IDE\VSIXAutoUpdate.exe" VSIXAutoUpdate.exe Microsoft Corporation 15.0.26430.4 c:\program files (x86)\microsoft visual studio\2017\community\common7\ide\vsixautoupdate.exe 5/4/2017 10:19 PM [DISABLED] \Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 HKCR\CLSID\{84F0FAE1-C27B-4F6F-807B-28CF6F96287D} Microsoft .NET Runtime Execution Engine Microsoft Corporation 6.3.9600.16384 c:\windows\system32\mscoree.dll 8/22/2013 7:04 AM [DISABLED] \Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 64 HKCR\CLSID\{429BC048-379E-45E0-80E4-EB1977941B5C} Microsoft .NET Runtime Execution Engine Microsoft Corporation 6.3.9600.16384 c:\windows\system32\mscoree.dll 8/22/2013 7:04 AM [DISABLED] \Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 64 Critical HKCR\CLSID\{613FBA38-A3DF-4AB8-9674-5604984A299A} Microsoft .NET Runtime Execution Engine Microsoft Corporation 6.3.9600.16384 c:\windows\system32\mscoree.dll 8/22/2013 7:04 AM [DISABLED] \Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 Critical HKCR\CLSID\{DE434264-8FE9-4C0B-A83B-89EBEEBFF78E} Microsoft .NET Runtime Execution Engine Microsoft Corporation 6.3.9600.16384 c:\windows\system32\mscoree.dll 8/22/2013 7:04 AM [DISABLED] \Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Automated) HKCR\CLSID\{CF2CF428-325B-48D3-8CA8-7633E36E5A32} Windows Rights Management client Microsoft Corporation 6.3.9600.17415 c:\windows\system32\msdrm.dll 10/28/2014 9:01 PM [DISABLED] \Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Manual) HKCR\CLSID\{BF5CB148-7C77-4D8A-A53E-D81C70CF743C} Windows Rights Management client Microsoft Corporation 6.3.9600.17415 c:\windows\system32\msdrm.dll 10/28/2014 9:01 PM [DISABLED] \Microsoft\Windows\AppID\PolicyConverter "%windir%\system32\appidpolicyconverter.exe" AppID Policy Converter Task Microsoft Corporation 6.3.9600.17415 c:\windows\system32\appidpolicyconverter.exe 10/28/2014 10:28 PM [DISABLED] \Microsoft\Windows\AppID\SmartScreenSpecific HKCR\CLSID\{9F2B0085-9218-42A1-88B0-9F0E65851666} AppRepSync Task Microsoft Corporation 6.3.9600.17415 c:\windows\system32\apprepsync.dll 10/28/2014 9:47 PM [DISABLED] \Microsoft\Windows\AppID\VerifiedPublisherCertStoreCheck "%windir%\system32\appidcertstorecheck.exe" AppID Certificate Store Verification Task Microsoft Corporation 6.3.9600.17415 c:\windows\system32\appidcertstorecheck.exe 10/28/2014 10:41 PM [DISABLED] \Microsoft\Windows\Application Experience\AitAgent "aitagent" /increment Application Impact Telemetry Agent Microsoft Corporation 6.3.9600.17415 c:\windows\system32\aitagent.exe 10/28/2014 9:52 PM [DISABLED] \Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser "%windir%\system32\rundll32.exe" aepdu.dll,AePduRunUpdate -nolegacy Program Compatibility Data Updater Microsoft Corporation 6.3.9600.17415 c:\windows\system32\aepdu.dll 10/28/2014 8:35 PM [DISABLED] \Microsoft\Windows\Application Experience\ProgramDataUpdater "%windir%\system32\rundll32.exe" aepdu.dll,AePduRunUpdate Program Compatibility Data Updater Microsoft Corporation 6.3.9600.17415 c:\windows\system32\aepdu.dll 10/28/2014 8:35 PM [DISABLED] \Microsoft\Windows\Application Experience\StartupAppTask "%windir%\system32\rundll32.exe" Startupscan.dll,SusRunTask Startup scan task DLL Microsoft Corporation 6.3.9600.17415 c:\windows\system32\startupscan.dll 10/28/2014 8:58 PM [DISABLED] \Microsoft\Windows\ApplicationData\CleanupTemporaryState "%windir%\system32\rundll32.exe" Windows.Storage.ApplicationData.dll,CleanupTemporaryState Windows Application Data API Server Microsoft Corporation 6.3.9600.17415 c:\windows\system32\windows.storage.applicationdata.dll 10/28/2014 9:19 PM [DISABLED] \Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup "%windir%\system32\rundll32.exe" %windir%\system32\AppxDeploymentClient.dll,AppxPreStageCleanupRunTask AppX Deployment Client DLL Microsoft Corporation 6.3.9600.17415 c:\windows\system32\appxdeploymentclient.dll 10/28/2014 9:17 PM [DISABLED] \Microsoft\Windows\Autochk\Proxy "%windir%\system32\rundll32.exe" /d acproxy.dll,PerformAutochkOperations Autochk Proxy DLL Microsoft Corporation 6.3.9600.17415 c:\windows\system32\acproxy.dll 10/28/2014 10:36 PM \Microsoft\Windows\Bluetooth\UninstallDeviceTask "BthUdTask.exe" $(Arg0) Bluetooth Uninstall Device Task Microsoft Corporation 6.3.9600.17415 c:\windows\system32\bthudtask.exe 10/28/2014 10:09 PM \Microsoft\Windows\CertificateServicesClient\SystemTask HKCR\CLSID\{58FB76B9-AC85-4E55-AC04-427593B1D060} DIMS Job DLL Microsoft Corporation 6.3.9600.17415 c:\windows\system32\dimsjob.dll 10/28/2014 9:20 PM \Microsoft\Windows\CertificateServicesClient\UserTask HKCR\CLSID\{58FB76B9-AC85-4E55-AC04-427593B1D060} DIMS Job DLL Microsoft Corporation 6.3.9600.17415 c:\windows\system32\dimsjob.dll 10/28/2014 9:20 PM [DISABLED] \Microsoft\Windows\CertificateServicesClient\UserTask-Roam HKCR\CLSID\{58FB76B9-AC85-4E55-AC04-427593B1D060} DIMS Job DLL Microsoft Corporation 6.3.9600.17415 c:\windows\system32\dimsjob.dll 10/28/2014 9:20 PM \Microsoft\Windows\Chkdsk\ProactiveScan HKCR\CLSID\{CF4270F5-2E43-4468-83B3-A8C45BB33EA1} pstask Task Microsoft Corporation 6.3.9600.17415 c:\windows\system32\pstask.dll 10/28/2014 10:33 PM [DISABLED] \Microsoft\Windows\Customer Experience Improvement Program\BthSQM HKCR\CLSID\{C8367320-6F85-11E0-A1F0-0800200C9A66} Bluetooth SQM Agent Microsoft Corporation 6.3.9600.17415 c:\windows\system32\bthsqm.dll 10/28/2014 10:26 PM [DISABLED] \Microsoft\Windows\Customer Experience Improvement Program\Consolidator "%SystemRoot%\System32\wsqmcons.exe" Windows SQM Consolidator Microsoft Corporation 6.3.9600.17415 c:\windows\system32\wsqmcons.exe 10/28/2014 9:39 PM [DISABLED] \Microsoft\Windows\Customer Experience Improvement Program\KernelCeipTask HKCR\CLSID\{E7ED314F-2816-4C26-AEB5-54A34D02404C} Kernel Ceip Task Microsoft Corporation 6.3.9600.17415 c:\windows\system32\kernelceip.dll 10/28/2014 10:34 PM [DISABLED] \Microsoft\Windows\Customer Experience Improvement Program\UsbCeip HKCR\CLSID\{C27F6B1D-FE0B-45E4-9257-38799FA69BC8} USBCEIP Task Microsoft Corporation 6.3.9600.17415 c:\windows\system32\usbceip.dll 10/28/2014 10:33 PM [DISABLED] \Microsoft\Windows\Data Integrity Scan\Data Integrity Scan HKCR\CLSID\{DCFD3EA8-D960-4719-8206-490AE315F94F} Data Integrity Scan Task Microsoft Corporation 6.3.9600.17415 c:\windows\system32\discan.dll 10/28/2014 10:27 PM \Microsoft\Windows\Data Integrity Scan\Data Integrity Scan for Crash Recovery HKCR\CLSID\{DCFD3EA8-D960-4719-8206-490AE315F94F} Data Integrity Scan Task Microsoft Corporation 6.3.9600.17415 c:\windows\system32\discan.dll 10/28/2014 10:27 PM \Microsoft\Windows\Defrag\ScheduledDefrag "%windir%\system32\defrag.exe" \\?\Volume{ecaaa42e-0324-11e2-9845-005056c00008}\ -h -o -$ Disk Defragmenter Module Microsoft Corp. 6.3.9600.17415 c:\windows\system32\defrag.exe 10/28/2014 9:18 PM \Microsoft\Windows\Device Setup\Metadata Refresh HKCR\CLSID\{23C1F3CF-C110-4512-ACA9-7B6174ECE888} Device Setup Manager Client API Microsoft Corporation 6.3.9600.17415 c:\windows\system32\devicesetupmanagerapi.dll 10/28/2014 9:15 PM \Microsoft\Windows\Diagnosis\Scheduled HKCR\CLSID\{C1F85EF8-BCC2-4606-BB39-70C523715EB3} Scripted Diagnostics Scheduled Task Microsoft Corporation 6.3.9600.17415 c:\windows\system32\sdiagschd.dll 10/28/2014 10:32 PM [DISABLED] \Microsoft\Windows\DiskCleanup\SilentCleanup "%windir%\system32\cleanmgr.exe" /autoclean /d %systemdrive% Disk Space Cleanup Manager for Windows Microsoft Corporation 6.3.9600.17415 c:\windows\system32\cleanmgr.exe 10/28/2014 10:16 PM [DISABLED] \Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector "%windir%\system32\rundll32.exe" dfdts.dll,DfdGetDefaultPolicyAndSMART Windows Disk Failure Diagnostic Module Microsoft Corporation 6.3.9600.17415 c:\windows\system32\dfdts.dll 10/28/2014 10:30 PM [DISABLED] \Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticResolver "%windir%\system32\DFDWiz.exe" Windows Disk Diagnostic User Resolver Microsoft Corporation 6.3.9600.17415 c:\windows\system32\dfdwiz.exe 10/28/2014 10:08 PM \Microsoft\Windows\DiskFootprint\Diagnostics HKCR\CLSID\{5B6B6834-34F0-49B9-AD4E-81D4994C7A74} Disk Footprint Utility Library Microsoft Corporation 6.3.9600.17415 c:\windows\system32\dfpcommon.dll 10/28/2014 9:54 PM [DISABLED] \Microsoft\Windows\File Classification Infrastructure\Property Definition Sync HKCR\CLSID\{2AE64751-B728-4D6B-97A0-B2DA2E7D2A3B} Microsoftr File Server Resource Management Client Extensions Microsoft Corporation 6.3.9600.17415 c:\windows\system32\srmclient.dll 10/28/2014 9:49 PM [DISABLED] \Microsoft\Windows\FileHistory\File History (maintenance mode) HKCR\CLSID\{89917B7C-A1A6-11DF-8BF6-18A90531A85A} File History Task Handler Microsoft Corporation 6.3.9600.17415 c:\windows\system32\fhtask.dll 10/28/2014 10:17 PM [DISABLED] \Microsoft\Windows\IME\SQM data sender HKCR\CLSID\{CCB1D8CB-D39F-41C9-B793-0196214BDC4E} Microsoft IME 2012 Microsoft Corporation 15.0.9600.17415 c:\windows\system32\ime\shared\imecfm.dll 10/28/2014 9:57 PM [DISABLED] \Microsoft\Windows\Location\Notifications "%windir%\System32\LocationNotifications.exe" Location Activity Microsoft Corporation 6.3.9600.17415 c:\windows\system32\locationnotifications.exe 10/28/2014 10:24 PM \Microsoft\Windows\Maintenance\WinSAT HKCR\CLSID\{A9A33436-678B-4C9C-A211-7CC38785E79D} Windows System Assessment Tool API Microsoft Corporation 6.3.9600.17415 c:\windows\system32\winsatapi.dll 10/28/2014 8:53 PM [DISABLED] \Microsoft\Windows\Media Center\ActivateWindowsSearch "%SystemRoot%\ehome\ehPrivJob.exe" /DoActivateWindowsSearch Digital TV Tuner device registration application. Microsoft Corporation 6.3.9600.16384 c:\windows\ehome\ehprivjob.exe 8/22/2013 6:24 AM [DISABLED] \Microsoft\Windows\Media Center\ConfigureInternetTimeService "%SystemRoot%\ehome\ehPrivJob.exe" /DoConfigureInternetTimeService Digital TV Tuner device registration application. Microsoft Corporation 6.3.9600.16384 c:\windows\ehome\ehprivjob.exe 8/22/2013 6:24 AM [DISABLED] \Microsoft\Windows\Media Center\DispatchRecoveryTasks "%SystemRoot%\ehome\ehPrivJob.exe" /DoRecoveryTasks $(Arg0) Digital TV Tuner device registration application. Microsoft Corporation 6.3.9600.16384 c:\windows\ehome\ehprivjob.exe 8/22/2013 6:24 AM [DISABLED] \Microsoft\Windows\Media Center\ehDRMInit "%SystemRoot%\ehome\ehPrivJob.exe" /DRMInit Digital TV Tuner device registration application. Microsoft Corporation 6.3.9600.16384 c:\windows\ehome\ehprivjob.exe 8/22/2013 6:24 AM [DISABLED] \Microsoft\Windows\Media Center\InstallPlayReady "%SystemRoot%\ehome\ehPrivJob.exe" /InstallPlayReady $(Arg0) Digital TV Tuner device registration application. Microsoft Corporation 6.3.9600.16384 c:\windows\ehome\ehprivjob.exe 8/22/2013 6:24 AM [DISABLED] \Microsoft\Windows\Media Center\mcupdate "%SystemRoot%\ehome\mcupdate" $(Arg0) Windows Media Center Store Update Manager Microsoft Corporation 6.3.9600.16384 c:\windows\ehome\mcupdate.exe 8/22/2013 4:35 AM [DISABLED] \Microsoft\Windows\Media Center\mcupdate_scheduled "%SystemRoot%\ehome\mcupdate" -crl -hms -pscn 15 Windows Media Center Store Update Manager Microsoft Corporation 6.3.9600.16384 c:\windows\ehome\mcupdate.exe 8/22/2013 4:35 AM [DISABLED] \Microsoft\Windows\Media Center\MediaCenterRecoveryTask "%SystemRoot%\ehome\mcupdate.exe" -MediaCenterRecoveryTask Windows Media Center Store Update Manager Microsoft Corporation 6.3.9600.16384 c:\windows\ehome\mcupdate.exe 8/22/2013 4:35 AM [DISABLED] \Microsoft\Windows\Media Center\ObjectStoreRecoveryTask "%SystemRoot%\ehome\mcupdate.exe" -ObjectStoreRecoveryTask Windows Media Center Store Update Manager Microsoft Corporation 6.3.9600.16384 c:\windows\ehome\mcupdate.exe 8/22/2013 4:35 AM [DISABLED] \Microsoft\Windows\Media Center\OCURActivate "%SystemRoot%\ehome\ehPrivJob.exe" /OCURActivate Digital TV Tuner device registration application. Microsoft Corporation 6.3.9600.16384 c:\windows\ehome\ehprivjob.exe 8/22/2013 6:24 AM [DISABLED] \Microsoft\Windows\Media Center\OCURDiscovery "%SystemRoot%\ehome\ehPrivJob.exe" /OCURDiscovery $(Arg0) Digital TV Tuner device registration application. Microsoft Corporation 6.3.9600.16384 c:\windows\ehome\ehprivjob.exe 8/22/2013 6:24 AM [DISABLED] \Microsoft\Windows\Media Center\PBDADiscovery "%SystemRoot%\ehome\ehPrivJob.exe" /PBDADiscovery Digital TV Tuner device registration application. Microsoft Corporation 6.3.9600.16384 c:\windows\ehome\ehprivjob.exe 8/22/2013 6:24 AM [DISABLED] \Microsoft\Windows\Media Center\PBDADiscoveryW1 "%SystemRoot%\ehome\ehPrivJob.exe" /wait:7 /PBDADiscovery Digital TV Tuner device registration application. Microsoft Corporation 6.3.9600.16384 c:\windows\ehome\ehprivjob.exe 8/22/2013 6:24 AM [DISABLED] \Microsoft\Windows\Media Center\PBDADiscoveryW2 "%SystemRoot%\ehome\ehPrivJob.exe" /wait:90 /PBDADiscovery Digital TV Tuner device registration application. Microsoft Corporation 6.3.9600.16384 c:\windows\ehome\ehprivjob.exe 8/22/2013 6:24 AM [DISABLED] \Microsoft\Windows\Media Center\PeriodicScanRetry "%windir%\ehome\MCUpdate.exe" -pscn 0 Windows Media Center Store Update Manager Microsoft Corporation 6.3.9600.16384 c:\windows\ehome\mcupdate.exe 8/22/2013 4:35 AM [DISABLED] \Microsoft\Windows\Media Center\PvrRecoveryTask "%SystemRoot%\ehome\mcupdate.exe" -PvrRecoveryTask Windows Media Center Store Update Manager Microsoft Corporation 6.3.9600.16384 c:\windows\ehome\mcupdate.exe 8/22/2013 4:35 AM [DISABLED] \Microsoft\Windows\Media Center\PvrRecoveryTask HKCR\CLSID\{7FA3A1C3-3C87-40DE-AC16-B6E2815A4CC8} Media Center Event Trace Module Microsoft Corporation 6.3.9600.16384 c:\windows\ehome\ehtrace.dll 8/22/2013 7:01 AM [DISABLED] \Microsoft\Windows\Media Center\PvrScheduleTask "%SystemRoot%\ehome\mcupdate.exe" -PvrSchedule Windows Media Center Store Update Manager Microsoft Corporation 6.3.9600.16384 c:\windows\ehome\mcupdate.exe 8/22/2013 4:35 AM [DISABLED] \Microsoft\Windows\Media Center\RecordingRestart "%SystemRoot%\ehome\ehrec" /RestartRecording Windows Media Center Host Module Microsoft Corporation 6.3.9600.16384 c:\windows\ehome\ehrec.exe 8/22/2013 6:49 AM [DISABLED] \Microsoft\Windows\Media Center\RegisterSearch "%SystemRoot%\ehome\ehPrivJob.exe" /DoRegisterSearch $(Arg0) Digital TV Tuner device registration application. Microsoft Corporation 6.3.9600.16384 c:\windows\ehome\ehprivjob.exe 8/22/2013 6:24 AM [DISABLED] \Microsoft\Windows\Media Center\ReindexSearchRoot "%SystemRoot%\ehome\ehPrivJob.exe" /DoReindexSearchRoot Digital TV Tuner device registration application. Microsoft Corporation 6.3.9600.16384 c:\windows\ehome\ehprivjob.exe 8/22/2013 6:24 AM [DISABLED] \Microsoft\Windows\Media Center\SqlLiteRecoveryTask "%SystemRoot%\ehome\mcupdate.exe" -SqlLiteRecoveryTask Windows Media Center Store Update Manager Microsoft Corporation 6.3.9600.16384 c:\windows\ehome\mcupdate.exe 8/22/2013 4:35 AM [DISABLED] \Microsoft\Windows\Media Center\StartRecording "%SystemRoot%\ehome\ehrec" /StartRecording Windows Media Center Host Module Microsoft Corporation 6.3.9600.16384 c:\windows\ehome\ehrec.exe 8/22/2013 6:49 AM [DISABLED] \Microsoft\Windows\Media Center\UpdateRecordPath "%SystemRoot%\ehome\ehPrivJob.exe" /DoUpdateRecordPath $(Arg0) Digital TV Tuner device registration application. Microsoft Corporation 6.3.9600.16384 c:\windows\ehome\ehprivjob.exe 8/22/2013 6:24 AM \Microsoft\Windows\MemoryDiagnostic\ProcessMemoryDiagnosticEvents HKCR\CLSID\{8168E74A-B39F-46D8-ADCD-7BED477B80A3} Microsoft Windows Memory Diagnostic Task Handler Microsoft Corporation 6.3.9600.17415 c:\windows\system32\memorydiagnostic.dll 10/28/2014 10:33 PM \Microsoft\Windows\MemoryDiagnostic\RunFullMemoryDiagnostic HKCR\CLSID\{8168E74A-B39F-46D8-ADCD-7BED477B80A3} Microsoft Windows Memory Diagnostic Task Handler Microsoft Corporation 6.3.9600.17415 c:\windows\system32\memorydiagnostic.dll 10/28/2014 10:33 PM [DISABLED] \Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser "%SystemRoot%\System32\MbaeParserTask.exe" Mobile Broadband Account Experience Parser Task Microsoft Corporation 6.3.9600.17415 c:\windows\system32\mbaeparsertask.exe 10/28/2014 9:59 PM [DISABLED] \Microsoft\Windows\MUI\LPRemove "%windir%\system32\lpremove.exe" MUI Language pack cleanup Microsoft Corporation 6.3.9600.17415 c:\windows\system32\lpremove.exe 10/28/2014 10:20 PM \Microsoft\Windows\Multimedia\SystemSoundsService HKCR\CLSID\{2DEA658F-54C1-4227-AF9B-260AB5FC3543} PlaySound Service Microsoft Corporation 6.3.9600.17415 c:\windows\system32\playsndsrv.dll 10/28/2014 10:36 PM [DISABLED] \Microsoft\Windows\NetCfg\BindingWorkItemQueueHandler HKCR\CLSID\{5AA199A0-1CED-43A5-9B85-3226086738A3} Network Configuration Objects Microsoft Corporation 6.3.9600.17931 c:\windows\system32\netcfgx.dll 7/10/2015 1:36 PM [DISABLED] \Microsoft\Windows\NetTrace\GatherNetworkInfo "%windir%\system32\gatherNetworkInfo.vbs" c:\windows\system32\gathernetworkinfo.vbs 7/18/2013 11:53 AM [DISABLED] \Microsoft\Windows\Offline Files\Background Synchronization HKCR\CLSID\{FA3F3DD9-4C1A-456B-A8FA-C76EF3ED83B8} Client Side Caching UI Microsoft Corporation 6.3.9600.17415 c:\windows\system32\cscui.dll 10/28/2014 10:01 PM [DISABLED] \Microsoft\Windows\Offline Files\Logon Synchronization HKCR\CLSID\{FA3F3DD9-4C1A-456B-A8FA-C76EF3ED83B8} Client Side Caching UI Microsoft Corporation 6.3.9600.17415 c:\windows\system32\cscui.dll 10/28/2014 10:01 PM [DISABLED] \Microsoft\Windows\PerfTrack\BackgroundConfigSurveyor HKCR\CLSID\{EA9155A3-8A39-40B4-8963-D3C761B18371} Microsoft Performance PerfTrack Microsoft Corporation 6.3.9600.17415 c:\windows\system32\perftrack.dll 10/28/2014 9:01 PM [DISABLED] \Microsoft\Windows\PI\Secure-Boot-Update HKCR\CLSID\{5014B7C8-934E-4262-9816-887FA745A6C4} TPM Maintenance Tasks Microsoft Corporation 6.3.9600.18514 c:\windows\system32\tpmtasks.dll 10/11/2016 12:45 PM [DISABLED] \Microsoft\Windows\PI\Sqm-Tasks HKCR\CLSID\{5014B7C8-934E-4262-9816-887FA745A6C4} TPM Maintenance Tasks Microsoft Corporation 6.3.9600.18514 c:\windows\system32\tpmtasks.dll 10/11/2016 12:45 PM \Microsoft\Windows\Plug and Play\Device Install Group Policy HKCR\CLSID\{60400283-B242-4FA8-8C25-CAF695B88209} pnppolicy Task Microsoft Corporation 6.3.9600.17415 c:\windows\system32\pnppolicy.dll 10/28/2014 10:30 PM \Microsoft\Windows\Plug and Play\Device Install Reboot Required HKCR\CLSID\{48794782-6A1F-47B9-BD52-1D5F95D49C1B} Plug and Play User Interface DLL Microsoft Corporation 5.2.3668.0 c:\windows\system32\pnpui.dll 10/28/2014 9:59 PM \Microsoft\Windows\Plug and Play\Plug and Play Cleanup HKCR\CLSID\{DEF03232-9688-11E2-BE7F-B4B52FD966FF} Plug and Play Maintenance Task Library Microsoft Corporation 6.3.9600.17415 c:\windows\system32\pnpclean.dll 10/28/2014 10:10 PM \Microsoft\Windows\Plug and Play\Sysprep Generalize Drivers "%SystemRoot%\System32\drvinst.exe" 6 Driver Installation Module Microsoft Corporation 6.3.9600.17415 c:\windows\system32\drvinst.exe 10/28/2014 10:39 PM \Microsoft\Windows\Power Efficiency Diagnostics\AnalyzeSystem HKCR\CLSID\{927EA2AF-1C54-43D5-825E-0074CE028EEE} Power Efficiency Diagnostics Task Microsoft Corporation 6.3.9600.17415 c:\windows\system32\energytask.dll 10/28/2014 8:57 PM \Microsoft\Windows\RAC\RacTask HKCR\CLSID\{42060D27-CA53-41F5-96E4-B1E8169308A6} Reliability analysis metrics calculation engine Microsoft Corporation 6.3.9600.17415 c:\windows\system32\racengn.dll 10/28/2014 8:58 PM \Microsoft\Windows\Ras\MobilityManager HKCR\CLSID\{C463A0FC-794F-4FDF-9201-01938CEACAFA} Provides support for the switching of mobility enabled VPN connections if their underlying interface goes down. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\rasmbmgr.dll 10/28/2014 9:19 PM [DISABLED] \Microsoft\Windows\RecoveryEnvironment\VerifyWinRE HKCR\CLSID\{89D1D0C2-A3CF-490C-ABE3-B86CDE34B047} Microsoft Windows Recovery Agent Task Handler Microsoft Corporation 6.3.9600.17415 c:\windows\system32\reagenttask.dll 10/28/2014 9:20 PM \Microsoft\Windows\Registry\RegIdleBackup HKCR\CLSID\{CA767AA8-9157-4604-B64B-40747123D5F2} RegIdle Backup Task Microsoft Corporation 6.3.9600.17415 c:\windows\system32\regidle.dll 10/28/2014 10:45 PM [DISABLED] \Microsoft\Windows\RemoteAssistance\RemoteAssistanceTask "%windir%\system32\RAServer.exe" /offerraupdate Windows Remote Assistance COM Server Microsoft Corporation 6.3.9600.17415 c:\windows\system32\raserver.exe 10/28/2014 9:57 PM [DISABLED] \Microsoft\Windows\SettingSync\BackgroundUploadTask HKCR\CLSID\{59B9640B-3F70-4D1C-B159-F26EEB8A4C87} Setting Synchronization Core Microsoft Corporation 6.3.9600.18231 c:\windows\system32\settingsynccore.dll 2/8/2016 12:50 PM [DISABLED] \Microsoft\Windows\SettingSync\BackupTask HKCR\CLSID\{60A4C78C-E2B8-4E6E-876F-DA203B02C05E} Setting Synchronization Core Microsoft Corporation 6.3.9600.18231 c:\windows\system32\settingsynccore.dll 2/8/2016 12:50 PM [DISABLED] \Microsoft\Windows\SettingSync\NetworkStateChangeTask HKCR\CLSID\{A4173A49-F373-4475-9A0F-2D615204DC20} Setting Synchronization Core Microsoft Corporation 6.3.9600.18231 c:\windows\system32\settingsynccore.dll 2/8/2016 12:50 PM [DISABLED] \Microsoft\Windows\Shell\FamilySafetyMonitor "%windir%\System32\wpcmon.exe" Family Safety Monitor Microsoft Corporation 6.3.9600.17415 c:\windows\system32\wpcmon.exe 10/28/2014 9:25 PM [DISABLED] \Microsoft\Windows\Shell\FamilySafetyRefresh HKCR\CLSID\{EBF00FCB-0769-4B81-9BEC-6C05514111AA} Family Safety Web Synchronization Library Microsoft Corporation 6.3.9600.17415 c:\windows\system32\wpcwebsync.dll 10/28/2014 9:31 PM [DISABLED] \Microsoft\Windows\Shell\FamilySafetyUpload HKCR\CLSID\{EBF00FCB-0769-4B81-9BEC-6C05514111AA} Family Safety Web Synchronization Library Microsoft Corporation 6.3.9600.17415 c:\windows\system32\wpcwebsync.dll 10/28/2014 9:31 PM [DISABLED] \Microsoft\Windows\Shell\IndexerAutomaticMaintenance HKCR\CLSID\{3FBA60A6-7BF5-4868-A2CA-6623B3DFFEA6} Indexing Options Microsoft Corporation 7.0.9600.17415 c:\windows\system32\srchadmin.dll 10/28/2014 10:05 PM [DISABLED] \Microsoft\Windows\SkyDrive\Idle Sync Maintenance Task HKCR\CLSID\{BF6C1E47-86EC-4194-9CE5-13C15DCB2001} OneDrive Sync Engine Microsoft Corporation 6.3.9600.17484 c:\windows\system32\skydrive.exe 11/7/2014 9:49 PM [DISABLED] \Microsoft\Windows\SkyDrive\Routine Maintenance Task HKCR\CLSID\{1B1F472E-3221-4826-97DB-2C2324D389AE} OneDrive Sync Engine Microsoft Corporation 6.3.9600.17484 c:\windows\system32\skydrive.exe 11/7/2014 9:49 PM \Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask HKCR\CLSID\{B1AEBB5D-EAD9-4476-B375-9C3ED9F32AFC} Software Protection Platform Client Extension Dll Microsoft Corporation 6.3.9600.16384 c:\windows\system32\sppcext.dll 8/22/2013 7:08 AM [DISABLED] \Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTaskLogon HKCR\CLSID\{B1AEBB5D-EAD9-4476-B375-9C3ED9F32AFC} Software Protection Platform Client Extension Dll Microsoft Corporation 6.3.9600.16384 c:\windows\system32\sppcext.dll 8/22/2013 7:08 AM [DISABLED] \Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTaskNetwork HKCR\CLSID\{B1AEBB5D-EAD9-4476-B375-9C3ED9F32AFC} Software Protection Platform Client Extension Dll Microsoft Corporation 6.3.9600.16384 c:\windows\system32\sppcext.dll 8/22/2013 7:08 AM \Microsoft\Windows\SpacePort\SpaceAgentTask "%windir%\system32\SpaceAgent.exe" Storage Spaces Settings Microsoft Corporation 6.3.9600.17415 c:\windows\system32\spaceagent.exe 10/28/2014 9:54 PM [DISABLED] \Microsoft\Windows\Sysmain\HybridDriveCachePrepopulate HKCR\CLSID\{17C82257-654E-4C47-8E23-DCA24EAA76A0} Superfetch Service Host Microsoft Corporation 6.3.9600.17931 c:\windows\system32\sysmain.dll 7/10/2015 1:54 PM [DISABLED] \Microsoft\Windows\Sysmain\HybridDriveCacheRebalance HKCR\CLSID\{D44377B8-1F2F-4FAA-9C8E-6C4AD2928E47} Superfetch Service Host Microsoft Corporation 6.3.9600.17931 c:\windows\system32\sysmain.dll 7/10/2015 1:54 PM \Microsoft\Windows\Sysmain\WsSwapAssessmentTask "%windir%\system32\rundll32.exe" sysmain.dll,PfSvWsSwapAssessmentTask Superfetch Service Host Microsoft Corporation 6.3.9600.17931 c:\windows\system32\sysmain.dll 7/10/2015 1:54 PM \Microsoft\Windows\SystemRestore\SR "%windir%\system32\srtasks.exe" ExecuteScheduledSPPCreation Microsoftr Windows System Protection background tasks. Microsoft Corporation 6.3.9600.17415 c:\windows\system32\srtasks.exe 10/28/2014 10:04 PM \Microsoft\Windows\Task Manager\Interactive HKCR\CLSID\{855FEC53-D2E4-4999-9E87-3414E9CF0FF4} Performance Monitor Microsoft Corporation 6.3.9600.17415 c:\windows\system32\wdc.dll 10/28/2014 9:37 PM [DISABLED] \Microsoft\Windows\TaskScheduler\Idle Maintenance HKCR\CLSID\{57BFCFDD-EEE4-4DBB-A751-3CDEB169FF44} Maintenance Scheduler Microsoft Corporation 6.3.9600.17415 c:\windows\system32\msched.dll 10/28/2014 9:19 PM \Microsoft\Windows\TaskScheduler\Maintenance Configurator HKCR\CLSID\{645E29EA-4B0A-464C-8B7D-1A6B9F9D92A8} Maintenance Scheduler Microsoft Corporation 6.3.9600.17415 c:\windows\system32\msched.dll 10/28/2014 9:19 PM \Microsoft\Windows\TaskScheduler\Manual Maintenance HKCR\CLSID\{57BFCFDD-EEE4-4DBB-A751-3CDEB169FF44} Maintenance Scheduler Microsoft Corporation 6.3.9600.17415 c:\windows\system32\msched.dll 10/28/2014 9:19 PM \Microsoft\Windows\TaskScheduler\Regular Maintenance HKCR\CLSID\{57BFCFDD-EEE4-4DBB-A751-3CDEB169FF44} Maintenance Scheduler Microsoft Corporation 6.3.9600.17415 c:\windows\system32\msched.dll 10/28/2014 9:19 PM \Microsoft\Windows\TextServicesFramework\MsCtfMonitor HKCR\CLSID\{01575CFE-9A55-4003-A5E1-F38D1EBDCBE1} MsCtfMonitor DLL Microsoft Corporation 6.3.9600.17415 c:\windows\system32\msctfmonitor.dll 10/28/2014 10:31 PM [DISABLED] \Microsoft\Windows\Time Synchronization\ForceSynchronizeTime HKCR\CLSID\{A31AD6C2-FF4C-43D4-8E90-7101023096F9} Time Synchronization Task Microsoft Corporation 6.3.9600.17415 c:\windows\system32\timesynctask.dll 10/28/2014 9:21 PM [DISABLED] \Microsoft\Windows\Time Synchronization\SynchronizeTime "%windir%\system32\sc.exe" start w32time task_started Service Control Manager Configuration Tool Microsoft Corporation 6.3.9600.17415 c:\windows\system32\sc.exe 10/28/2014 9:28 PM \Microsoft\Windows\Time Zone\SynchronizeTimeZone "%windir%\system32\tzsync.exe" TimeZone Sync Task Microsoft Corporation 6.3.9600.17931 c:\windows\system32\tzsync.exe 7/10/2015 12:53 PM \Microsoft\Windows\TPM\Tpm-Maintenance HKCR\CLSID\{5014B7C8-934E-4262-9816-887FA745A6C4} TPM Maintenance Tasks Microsoft Corporation 6.3.9600.18514 c:\windows\system32\tpmtasks.dll 10/11/2016 12:45 PM \Microsoft\Windows\UPnP\UPnPHostConfig "sc.exe" config upnphost start= auto Service Control Manager Configuration Tool Microsoft Corporation 6.3.9600.17415 c:\windows\system32\sc.exe 10/28/2014 9:28 PM [DISABLED] \Microsoft\Windows\WDI\ResolutionHost HKCR\CLSID\{900BE39D-6BE8-461A-BC4D-B0FA71F5ECB1} Windows Diagnostic Infrastructure Microsoft Corporation 6.3.9600.17415 c:\windows\system32\wdi.dll 10/28/2014 9:21 PM [DISABLED] \Microsoft\Windows\Windows Error Reporting\QueueReporting "%windir%\system32\wermgr.exe" -queuereporting Windows Problem Reporting Microsoft Corporation 6.3.9600.17415 c:\windows\system32\wermgr.exe 10/28/2014 10:12 PM \Microsoft\Windows\Windows Filtering Platform\BfeOnServiceStartTypeChange "%windir%\system32\rundll32.exe" bfe.dll,BfeOnServiceStartTypeChange Base Filtering Engine Microsoft Corporation 6.3.9600.18229 c:\windows\system32\bfe.dll 2/5/2016 11:11 AM [DISABLED] \Microsoft\Windows\Windows Media Sharing\UpdateLibrary "%ProgramFiles%\Windows Media Player\wmpnscfg.exe" Windows Media Player Network Sharing Service Configuration Application Microsoft Corporation 12.0.9600.17415 c:\program files\windows media player\wmpnscfg.exe 10/28/2014 10:28 PM [DISABLED] \Microsoft\Windows\WindowsColorSystem\Calibration Loader HKCR\CLSID\{B210D694-C8DF-490D-9576-9E20CDBC20BD} Microsoft Color Matching System DLL Microsoft Corporation 6.3.9600.18589 c:\windows\system32\mscms.dll 2/4/2017 1:32 PM [DISABLED] \Microsoft\Windows\WindowsUpdate\Scheduled Start "C:\Windows\system32\sc.exe" start wuauserv Service Control Manager Configuration Tool Microsoft Corporation 6.3.9600.17415 c:\windows\system32\sc.exe 10/28/2014 9:28 PM [DISABLED] \Microsoft\Windows\WindowsUpdate\Scheduled Start With Network "C:\Windows\system32\sc.exe" start wuauserv Service Control Manager Configuration Tool Microsoft Corporation 6.3.9600.17415 c:\windows\system32\sc.exe 10/28/2014 9:28 PM \Microsoft\Windows\Wininet\CacheTask HKCR\CLSID\{0358B920-0AC7-461F-98F4-58E32CD89148} Internet Extensions for Win32 Microsoft Corporation 11.0.9600.18639 c:\windows\system32\wininet.dll 3/25/2017 12:24 PM [DISABLED] \Microsoft\Windows\WOF\WIM-Hash-Management HKCR\CLSID\{B7BFFB5A-EFA8-4D8C-BBDE-C8D5FAAF54A1} WIM Boot Tasks Microsoft Corporation 6.3.9600.17415 c:\windows\system32\woftasks.dll 10/28/2014 9:17 PM [DISABLED] \Microsoft\Windows\WOF\WIM-Hash-Validation HKCR\CLSID\{B7BFFB5A-EFA8-4D8C-BBDE-C8D5FAAF54A1} WIM Boot Tasks Microsoft Corporation 6.3.9600.17415 c:\windows\system32\woftasks.dll 10/28/2014 9:17 PM [DISABLED] \Microsoft\Windows\Workplace Join\Automatic-Workplace-Join "%SystemRoot%\System32\AutoWorkplace.exe" join Microsoft Corporation 6.3.9600.16384 c:\windows\system32\autoworkplace.exe 8/21/2013 9:40 PM [DISABLED] \Microsoft\Windows\WS\Badge Update HKCR\CLSID\{00CCDDF6-5107-424D-853D-3907AE5502DC} WinStore Microsoft Corporation 6.3.9600.17819 c:\windows\winstore\winstoreui.dll 5/3/2015 10:54 AM \Microsoft\Windows\WS\License Validation "rundll32.exe" WSClient.dll,WSpTLR licensing Windows Store Licensing Client Microsoft Corporation 6.3.9600.17415 c:\windows\system32\wsclient.dll 10/28/2014 8:55 PM [DISABLED] \Microsoft\Windows\WS\Sync Licenses HKCR\CLSID\{10F591BE-3C84-418A-86DD-BAA002E2F36E} WinStore Microsoft Corporation 6.3.9600.17819 c:\windows\winstore\winstoreui.dll 5/3/2015 10:54 AM [DISABLED] \Microsoft\Windows\WS\WSRefreshBannedAppsListTask "rundll32.exe" WSClient.dll,RefreshBannedAppsList Windows Store Licensing Client Microsoft Corporation 6.3.9600.17415 c:\windows\system32\wsclient.dll 10/28/2014 8:55 PM [DISABLED] \Microsoft\Windows\WS\WSTask HKCR\CLSID\{E52C9A25-F3E8-49E4-BAA7-FAD0EF620129} Windows Store Service Microsoft Corporation 6.3.9600.17415 c:\windows\system32\wsservice.dll 10/28/2014 9:11 PM [DISABLED] \OfficeSoftwareProtectionPlatform\SvcRestartTask "%systemroot%\system32\sc.exe" start osppsvc Service Control Manager Configuration Tool Microsoft Corporation 6.3.9600.17415 c:\windows\system32\sc.exe 10/28/2014 9:28 PM HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects ExplorerBHO Class HKCR\CLSID\{449D0D6E-2412-4E61-B68F-1CB625CD9E52} Adds classic Windows Explorer features IvoSoft 4.3.0.0 c:\program files\classic shell\classicexplorer32.dll 7/30/2016 12:05 PM ClassicIEBHO Class HKCR\CLSID\{EA801577-E6AD-4BD5-8F71-4BE0154331A4} Customizations for the title bar and status bar of IE IvoSoft 4.3.0.0 c:\program files\classic shell\classiciedll_32.dll 7/30/2016 12:05 PM [DISABLED] Adobe Acrobat Create PDF Helper HKCR\CLSID\{AE7CD045-E861-484f-8273-0445EE161910} Adobe PDF Toolbar for Internet Explorer Adobe Systems Incorporated 15.9.20069.28170 c:\program files (x86)\common files\adobe\acrobat\wcieactivex\dc\acroiefavstub.dll 9/30/2015 2:23 PM [DISABLED] Office Document Cache Handler HKCR\CLSID\{B4F3A835-0E21-4959-BA22-42B3008E02FF} Microsoft Office Document Cache Handler Microsoft Corporation 14.0.7011.1000 c:\program files (x86)\microsoft office\office14\urlredir.dll 3/6/2013 3:38 AM [DISABLED] Adobe Acrobat Create PDF from Selection HKCR\CLSID\{F4971EE7-DAA0-4053-9964-665D8EE6A077} Adobe PDF Toolbar for Internet Explorer Adobe Systems Incorporated 15.9.20069.28170 c:\program files (x86)\common files\adobe\acrobat\wcieactivex\dc\acroiefavstub.dll 9/30/2015 2:23 PM HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects ExplorerBHO Class HKCR\CLSID\{449D0D6E-2412-4E61-B68F-1CB625CD9E52} Adds classic Windows Explorer features IvoSoft 4.3.0.0 c:\program files\classic shell\classicexplorer32.dll 7/30/2016 12:05 PM ClassicIEBHO Class HKCR\CLSID\{EA801577-E6AD-4BD5-8F71-4BE0154331A4} Customizations for the title bar and status bar of IE IvoSoft 4.3.0.0 c:\program files\classic shell\classiciedll_32.dll 7/30/2016 12:05 PM [DISABLED] Adobe Acrobat Create PDF Helper HKCR\CLSID\{AE7CD045-E861-484f-8273-0445EE161910} Adobe PDF Toolbar for Internet Explorer Adobe Systems Incorporated 15.9.20069.28170 c:\program files (x86)\common files\adobe\acrobat\wcieactivex\dc\acroiefavstub.dll 9/30/2015 2:23 PM [DISABLED] Office Document Cache Handler HKCR\CLSID\{B4F3A835-0E21-4959-BA22-42B3008E02FF} Microsoft Office Document Cache Handler Microsoft Corporation 14.0.7011.1000 c:\program files (x86)\microsoft office\office14\urlredir.dll 3/6/2013 3:38 AM [DISABLED] Adobe Acrobat Create PDF from Selection HKCR\CLSID\{F4971EE7-DAA0-4053-9964-665D8EE6A077} Adobe PDF Toolbar for Internet Explorer Adobe Systems Incorporated 15.9.20069.28170 c:\program files (x86)\common files\adobe\acrobat\wcieactivex\dc\acroiefavstub.dll 9/30/2015 2:23 PM HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers 7-Zip HKCR\CLSID\{23170F69-40C1-278A-1000-000100020000} 7-Zip Shell Extension Igor Pavlov 9.38.0.0 c:\program files\7-zip\7-zip.dll 1/3/2015 1:24 PM BriefcaseMenu HKCR\CLSID\{85BBD920-42A0-1069-A2E4-08002B30309D} Windows Briefcase Microsoft Corporation 6.3.9600.17415 c:\windows\system32\syncui.dll 10/28/2014 10:45 PM CirrusShellEx HKCR\CLSID\{57FA2D12-D22D-490A-805A-5CB48E84F12A} Beyond Compare Shell Extension Scooter Software 4.2.0.21933 c:\program files\beyond compare 4\bcshellex64.dll 1/4/2017 1:20 PM Open With HKCR\CLSID\{09799AFB-AD67-11d1-ABCD-00C04FC30936} Windows Shell Common Dll Microsoft Corporation 6.3.9600.18460 c:\windows\system32\shell32.dll 8/27/2016 12:12 PM Open With EncryptionMenu HKCR\CLSID\{A470F8CF-A1E8-4f65-8335-227475AA5C46} Windows Shell Common Dll Microsoft Corporation 6.3.9600.18460 c:\windows\system32\shell32.dll 8/27/2016 12:12 PM Sharing HKCR\CLSID\{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} Shell extensions for sharing Microsoft Corporation 6.3.9600.18458 c:\windows\system32\ntshrui.dll 8/25/2016 4:50 PM TortoiseSVN HKCR\CLSID\{30351349-7B7D-4FCC-81B4-1E394CA267EB} TortoiseSVN shell extension client http://tortoisesvn.net 1.9.5.27581 c:\program files\tortoisesvn\bin\tortoisestub.dll 11/26/2016 9:26 AM Taskband Pin HKCR\CLSID\{90AA3A4E-1CBA-4233-B8BB-535773D48449} Windows Shell Common Dll Microsoft Corporation 6.3.9600.18460 c:\windows\system32\shell32.dll 8/27/2016 12:12 PM Start Menu Pin HKCR\CLSID\{a2a9545d-a0c2-42b4-9708-a0b2badd77c8} Windows Shell Common Dll Microsoft Corporation 6.3.9600.18460 c:\windows\system32\shell32.dll 8/27/2016 12:12 PM [DISABLED] AccExt HKCR\CLSID\{2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} Core Sync 2.3.0.197 c:\program files (x86)\adobe\adobe creative cloud\coresyncextension\coresync_x64.dll 10/25/2016 12:35 PM [DISABLED] Adobe.Acrobat.ContextMenu HKCR\CLSID\{A6595CD1-BF77-430A-A452-18696685F7C7} Adobe Acrobat Context Menu Adobe Systems Inc. 15.7.20033.2203 c:\program files (x86)\adobe\acrobat dc\acrobat elements\contextmenushim64.dll 3/17/2015 1:57 AM [DISABLED] CLVDShellExt9 HKCR\CLSID\{4E20B104-5D9F-4E01-A01E-100F08E345C9} Cyberlink Shell Extension dynamic link library Cyberlink 9.0.0.0 c:\program files (x86)\common files\cyberlink\shellextcomponent\clvdshellext9.dll 5/26/2013 8:56 PM [DISABLED] filemenu HKCR\CLSID\{53250000-cca9-11ce-946f-444553540000} WinBatch FileMenu shell extension DLL Wilson WindowWare, Inc. 2014.2.0.0 c:\program files\winbatch\system\filemenu.dll 7/29/2014 5:22 PM HKLM\Software\Classes\Drive\ShellEx\ContextMenuHandlers EnhancedStorageShell HKCR\CLSID\{2854F705-3548-414C-A113-93E27C808C85} Windows Enhanced Storage Shell Extension DLL Microsoft Corporation 6.3.9600.17415 c:\windows\system32\ehstorshell.dll 10/28/2014 10:07 PM Sharing HKCR\CLSID\{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} Shell extensions for sharing Microsoft Corporation 6.3.9600.18458 c:\windows\system32\ntshrui.dll 8/25/2016 4:50 PM TortoiseSVN HKCR\CLSID\{30351349-7B7D-4FCC-81B4-1E394CA267EB} TortoiseSVN shell extension client http://tortoisesvn.net 1.9.5.27581 c:\program files\tortoisesvn\bin\tortoisestub.dll 11/26/2016 9:26 AM Disk Copy Extension HKCR\CLSID\{59099400-57FF-11CE-BD94-0020AF85B590} Windows DiskCopy Microsoft Corporation 6.3.9600.17415 c:\windows\system32\diskcopy.dll 10/28/2014 10:29 PM Previous Versions Property Page HKCR\CLSID\{596AB062-B4D2-4215-9F74-E9109B0A8153} Previous Versions property page Microsoft Corporation 6.3.9600.17415 c:\windows\system32\twext.dll 10/28/2014 10:09 PM Portable Devices Menu HKCR\CLSID\{D6791A63-E7E2-4fee-BF52-5DED8E86E9B8} Portable Devices Shell Extension Microsoft Corporation 6.3.9600.17702 c:\windows\system32\wpdshext.dll 3/5/2015 11:08 PM ShellFolder for CD Burning HKCR\CLSID\{fbeb8a05-beee-4442-804e-409d6c4515e9} Windows Shell Common Dll Microsoft Corporation 6.3.9600.18460 c:\windows\system32\shell32.dll 8/27/2016 12:12 PM [DISABLED] CLVDShellExt9 HKCR\CLSID\{4E20B104-5D9F-4E01-A01E-100F08E345C9} Cyberlink Shell Extension dynamic link library Cyberlink 9.0.0.0 c:\program files (x86)\common files\cyberlink\shellextcomponent\clvdshellext9.dll 5/26/2013 8:56 PM [DISABLED] VMDiskMenuHandler64 HKCR\CLSID\{E4D28EDC-8C0B-43EE-9E7D-C8A8682334DC} VMware Workstation VMware, Inc. 11.1.4.7549 c:\program files (x86)\vmware\vmware workstation\x64\vmdkshellext64.dll 5/5/2016 4:46 AM [DISABLED] Adobe Drive CS4 HKCR\CLSID\{C95FFEAE-A32E-4122-A5C4-49B5BFB69795} Adobe Drive Menu Adobe Systems Incorporated 4.0.0.344 c:\program files\common files\adobe\adobe drive cs4\adfsmenu.dll 8/14/2008 10:47 AM HKLM\Software\Classes\*\ShellEx\PropertySheetHandlers BriefcasePage HKCR\CLSID\{85BBD920-42A0-1069-A2E4-08002B30309D} Windows Briefcase Microsoft Corporation 6.3.9600.17415 c:\windows\system32\syncui.dll 10/28/2014 10:45 PM CryptoSignMenu HKCR\CLSID\{7444C719-39BF-11D1-8CD9-00C04FC29D45} Crypto Shell Extensions Microsoft Corporation 6.3.9600.17415 c:\windows\system32\cryptext.dll 10/28/2014 10:11 PM FCI Properties HKCR\CLSID\{748F920F-FB24-4D09-B360-BAF6F199AD6D} Microsoftr File Server Resource Management Shell Extension Microsoft Corporation 6.3.9600.17415 c:\windows\system32\srmshell.dll 10/28/2014 8:58 PM TortoiseSVN HKCR\CLSID\{30351349-7B7D-4FCC-81B4-1E394CA267EB} TortoiseSVN shell extension client http://tortoisesvn.net 1.9.5.27581 c:\program files\tortoisesvn\bin\tortoisestub.dll 11/26/2016 9:26 AM Security Shell Extension HKCR\CLSID\{1f2e5c40-9550-11ce-99d2-00aa006e086c} Security Shell Extension Microsoft Corporation 6.3.9600.17415 c:\windows\system32\rshx32.dll 10/28/2014 10:07 PM VersInfoShlExt Class HKCR\CLSID\{26B48C81-DAA1-4371-9441-2D8EC2A0B0F2} VersInfoEx Shell Extension with 1.0.3 updates taken from author's comments found at http://www.codeproject.com/Articles/118909/Windows-7-File-properties-Version-Tab-Shell-Extens Software Development Laboratories 1.0.3.3139 c:\bin\versinfoex.dll 12/28/2015 1:33 PM OLE Docfile Property Page HKCR\CLSID\{3EA48300-8CF6-101B-84FB-666CCB9BCD32} OLE DocFile Property Page Microsoft Corporation 6.3.9600.17415 c:\windows\system32\docprop.dll 10/28/2014 10:20 PM Summary Properties Page HKCR\CLSID\{883373C3-BF89-11D1-BE35-080036B11A03} Windows Shell Common Dll Microsoft Corporation 6.3.9600.18460 c:\windows\system32\shell32.dll 8/27/2016 12:12 PM HKLM\Software\Classes\AllFileSystemObjects\ShellEx\ContextMenuHandlers CopyAsPathMenu HKCR\CLSID\{f3d06e7c-1e45-4a26-847e-f9fcdee59be0} Windows Shell Common Dll Microsoft Corporation 6.3.9600.18460 c:\windows\system32\shell32.dll 8/27/2016 12:12 PM MBAMShlExt HKCR\CLSID\{57CE581A-0CB6-4266-9CA0-19364C90A0B3} Malwarebytes Malwarebytes 3.0.0.26 c:\program files\malwarebytes\anti-malware\mbshlext.dll 1/25/2017 5:37 PM SendTo HKCR\CLSID\{7BA4C740-9E81-11CF-99D3-00AA004AE837} Windows Shell Common Dll Microsoft Corporation 6.3.9600.18460 c:\windows\system32\shell32.dll 8/27/2016 12:12 PM Previous Versions Property Page HKCR\CLSID\{596AB062-B4D2-4215-9F74-E9109B0A8153} Previous Versions property page Microsoft Corporation 6.3.9600.17415 c:\windows\system32\twext.dll 10/28/2014 10:09 PM Start Menu Pin HKCR\CLSID\{a2a9545d-a0c2-42b4-9708-a0b2badd77c8} Windows Shell Common Dll Microsoft Corporation 6.3.9600.18460 c:\windows\system32\shell32.dll 8/27/2016 12:12 PM [DISABLED] Client Side Caching UI HKCR\CLSID\{474C98EE-CF3D-41f5-80E3-4AAB0AB04301} Client Side Caching UI Microsoft Corporation 6.3.9600.17415 c:\windows\system32\cscui.dll 10/28/2014 10:01 PM [DISABLED] Adobe Drive CS4 HKCR\CLSID\{C95FFEAE-A32E-4122-A5C4-49B5BFB69795} Adobe Drive Menu Adobe Systems Incorporated 4.0.0.344 c:\program files\common files\adobe\adobe drive cs4\adfsmenu.dll 8/14/2008 10:47 AM HKLM\Software\Classes\AllFileSystemObjects\ShellEx\PropertySheetHandlers Previous Versions Property Page HKCR\CLSID\{596AB062-B4D2-4215-9F74-E9109B0A8153} Previous Versions property page Microsoft Corporation 6.3.9600.17415 c:\windows\system32\twext.dll 10/28/2014 10:09 PM [DISABLED] Client Side Caching UI HKCR\CLSID\{7EFA68C6-086B-43e1-A2D2-55A113531240} Client Side Caching UI Microsoft Corporation 6.3.9600.17415 c:\windows\system32\cscui.dll 10/28/2014 10:01 PM HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers 7-Zip HKCR\CLSID\{23170F69-40C1-278A-1000-000100020000} 7-Zip Shell Extension Igor Pavlov 9.38.0.0 c:\program files\7-zip\7-zip.dll 1/3/2015 1:24 PM CirrusShellEx HKCR\CLSID\{57FA2D12-D22D-490A-805A-5CB48E84F12A} Beyond Compare Shell Extension Scooter Software 4.2.0.21933 c:\program files\beyond compare 4\bcshellex64.dll 1/4/2017 1:20 PM EncryptionMenu HKCR\CLSID\{A470F8CF-A1E8-4f65-8335-227475AA5C46} Windows Shell Common Dll Microsoft Corporation 6.3.9600.18460 c:\windows\system32\shell32.dll 8/27/2016 12:12 PM Sharing HKCR\CLSID\{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} Shell extensions for sharing Microsoft Corporation 6.3.9600.18458 c:\windows\system32\ntshrui.dll 8/25/2016 4:50 PM TortoiseSVN HKCR\CLSID\{30351349-7B7D-4FCC-81B4-1E394CA267EB} TortoiseSVN shell extension client http://tortoisesvn.net 1.9.5.27581 c:\program files\tortoisesvn\bin\tortoisestub.dll 11/26/2016 9:26 AM Previous Versions Property Page HKCR\CLSID\{596AB062-B4D2-4215-9F74-E9109B0A8153} Previous Versions property page Microsoft Corporation 6.3.9600.17415 c:\windows\system32\twext.dll 10/28/2014 10:09 PM [DISABLED] Offline Files HKCR\CLSID\{474C98EE-CF3D-41f5-80E3-4AAB0AB04301} Client Side Caching UI Microsoft Corporation 6.3.9600.17415 c:\windows\system32\cscui.dll 10/28/2014 10:01 PM HKLM\Software\Classes\Directory\Shellex\DragDropHandlers 7-Zip HKCR\CLSID\{23170F69-40C1-278A-1000-000100020000} 7-Zip Shell Extension Igor Pavlov 9.38.0.0 c:\program files\7-zip\7-zip.dll 1/3/2015 1:24 PM ClassicCopyExt HKCR\CLSID\{8C83ACB1-75C3-45D2-882C-EFA32333491C} Adds classic Windows Explorer features IvoSoft 4.3.0.0 c:\program files\classic shell\classicexplorer64.dll 7/30/2016 12:04 PM TortoiseSVN HKCR\CLSID\{3035134A-7B7D-4FCC-81B4-1E394CA267EB} TortoiseSVN shell extension client http://tortoisesvn.net 1.9.5.27581 c:\program files\tortoisesvn\bin\tortoisestub.dll 11/26/2016 9:26 AM HKLM\Software\Classes\Directory\Shellex\PropertySheetHandlers Sharing HKCR\CLSID\{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} Shell extensions for sharing Microsoft Corporation 6.3.9600.18458 c:\windows\system32\ntshrui.dll 8/25/2016 4:50 PM TortoiseSVN HKCR\CLSID\{30351349-7B7D-4FCC-81B4-1E394CA267EB} TortoiseSVN shell extension client http://tortoisesvn.net 1.9.5.27581 c:\program files\tortoisesvn\bin\tortoisestub.dll 11/26/2016 9:26 AM Security Shell Extension HKCR\CLSID\{1f2e5c40-9550-11ce-99d2-00aa006e086c} Security Shell Extension Microsoft Corporation 6.3.9600.17415 c:\windows\system32\rshx32.dll 10/28/2014 10:07 PM MyFolder menu and properties HKCR\CLSID\{4a7ded0a-ad25-11d0-98a8-0800361b1103} My Documents Folder UI Microsoft Corporation 6.3.9600.17415 c:\windows\system32\mydocs.dll 10/28/2014 10:19 PM Previous Versions Property Page HKCR\CLSID\{596AB062-B4D2-4215-9F74-E9109B0A8153} Previous Versions property page Microsoft Corporation 6.3.9600.17415 c:\windows\system32\twext.dll 10/28/2014 10:09 PM DfsShell Class HKCR\CLSID\{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6} Distributed File System shell extension Microsoft Corporation 6.3.9600.17415 c:\windows\system32\dfsshlex.dll 10/28/2014 10:17 PM Folder Customization Tab HKCR\CLSID\{ef43ecfe-2ab9-4632-bf21-58909dd177f0} Windows Shell Common Dll Microsoft Corporation 6.3.9600.18460 c:\windows\system32\shell32.dll 8/27/2016 12:12 PM [DISABLED] Offline Files HKCR\CLSID\{7EFA68C6-086B-43e1-A2D2-55A113531240} Client Side Caching UI Microsoft Corporation 6.3.9600.17415 c:\windows\system32\cscui.dll 10/28/2014 10:01 PM HKLM\Software\Classes\Directory\Shellex\CopyHookHandlers FileSystem HKCR\CLSID\{217FC9C0-3AEA-1069-A2DB-08002B30309D} Windows Shell Common Dll Microsoft Corporation 6.3.9600.18460 c:\windows\system32\shell32.dll 8/27/2016 12:12 PM Sharing HKCR\CLSID\{40dd6e20-7c17-11ce-a804-00aa003ca9f6} Shell extensions for sharing Microsoft Corporation 6.3.9600.18458 c:\windows\system32\ntshrui.dll 8/25/2016 4:50 PM TortoiseSVN HKCR\CLSID\{30351349-7B7D-4FCC-81B4-1E394CA267EB} TortoiseSVN shell extension client http://tortoisesvn.net 1.9.5.27581 c:\program files\tortoisesvn\bin\tortoisestub.dll 11/26/2016 9:26 AM HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers New HKCR\CLSID\{D969A300-E7FF-11d0-A93B-00A0C90F2719} Windows Shell Common Dll Microsoft Corporation 6.3.9600.18460 c:\windows\system32\shell32.dll 8/27/2016 12:12 PM NvCplDesktopContext HKCR\CLSID\{3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} NVIDIA Display Shell Extension NVIDIA Corporation 1.2.0.1 c:\windows\system32\nvshext.dll 5/1/2017 3:02 PM Sharing HKCR\CLSID\{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} Shell extensions for sharing Microsoft Corporation 6.3.9600.18458 c:\windows\system32\ntshrui.dll 8/25/2016 4:50 PM TortoiseSVN HKCR\CLSID\{30351349-7B7D-4FCC-81B4-1E394CA267EB} TortoiseSVN shell extension client http://tortoisesvn.net 1.9.5.27581 c:\program files\tortoisesvn\bin\tortoisestub.dll 11/26/2016 9:26 AM [DISABLED] Adobe Drive CS4 HKCR\CLSID\{C95FFEAE-A32E-4122-A5C4-49B5BFB69795} Adobe Drive Menu Adobe Systems Incorporated 4.0.0.344 c:\program files\common files\adobe\adobe drive cs4\adfsmenu.dll 8/14/2008 10:47 AM HKLM\Software\Classes\Folder\Shellex\ColumnHandlers TortoiseSVN HKCR\CLSID\{30351349-7B7D-4FCC-81B4-1E394CA267EB} TortoiseSVN shell extension client http://tortoisesvn.net 1.9.5.27581 c:\program files\tortoisesvn\bin\tortoisestub.dll 11/26/2016 9:26 AM HKLM\Software\Wow6432Node\Classes\Folder\Shellex\ColumnHandlers TortoiseSVN HKCR\CLSID\{30351349-7B7D-4FCC-81B4-1E394CA267EB} TortoiseSVN shell extension client http://tortoisesvn.net 1.9.5.27581 c:\program files\tortoisesvn\bin\tortoisestub32.dll 11/26/2016 6:02 AM HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers 7-Zip HKCR\CLSID\{23170F69-40C1-278A-1000-000100020000} 7-Zip Shell Extension Igor Pavlov 9.38.0.0 c:\program files\7-zip\7-zip.dll 1/3/2015 1:24 PM BriefcaseMenu HKCR\CLSID\{85BBD920-42A0-1069-A2E4-08002B30309D} Windows Briefcase Microsoft Corporation 6.3.9600.17415 c:\windows\system32\syncui.dll 10/28/2014 10:45 PM CirrusShellEx HKCR\CLSID\{57FA2D12-D22D-490A-805A-5CB48E84F12A} Beyond Compare Shell Extension Scooter Software 4.2.0.21933 c:\program files\beyond compare 4\bcshellex64.dll 1/4/2017 1:20 PM Library Location HKCR\CLSID\{3dad6c5d-2167-4cae-9914-f99e41c12cfa} Windows Shell Common Dll Microsoft Corporation 6.3.9600.18460 c:\windows\system32\shell32.dll 8/27/2016 12:12 PM MBAMShlExt HKCR\CLSID\{57CE581A-0CB6-4266-9CA0-19364C90A0B3} Malwarebytes Malwarebytes 3.0.0.26 c:\program files\malwarebytes\anti-malware\mbshlext.dll 1/25/2017 5:37 PM StartMenuExt HKCR\CLSID\{E595F05F-903F-4318-8B0A-7F633B520D2B} Start Menu Helper Extension IvoSoft 4.3.0.0 c:\windows\system32\startmenuhelper64.dll 7/30/2016 12:04 PM TortoiseSVN HKCR\CLSID\{30351349-7B7D-4FCC-81B4-1E394CA267EB} TortoiseSVN shell extension client http://tortoisesvn.net 1.9.5.27581 c:\program files\tortoisesvn\bin\tortoisestub.dll 11/26/2016 9:26 AM Start Menu Pin HKCR\CLSID\{a2a9545d-a0c2-42b4-9708-a0b2badd77c8} Windows Shell Common Dll Microsoft Corporation 6.3.9600.18460 c:\windows\system32\shell32.dll 8/27/2016 12:12 PM [DISABLED] AccExt HKCR\CLSID\{2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} Core Sync 2.3.0.197 c:\program files (x86)\adobe\adobe creative cloud\coresyncextension\coresync_x64.dll 10/25/2016 12:35 PM [DISABLED] Adobe.Acrobat.ContextMenu HKCR\CLSID\{A6595CD1-BF77-430A-A452-18696685F7C7} Adobe Acrobat Context Menu Adobe Systems Inc. 15.7.20033.2203 c:\program files (x86)\adobe\acrobat dc\acrobat elements\contextmenushim64.dll 3/17/2015 1:57 AM [DISABLED] Offline Files HKCR\CLSID\{474C98EE-CF3D-41f5-80E3-4AAB0AB04301} Client Side Caching UI Microsoft Corporation 6.3.9600.17415 c:\windows\system32\cscui.dll 10/28/2014 10:01 PM HKLM\Software\Classes\Folder\ShellEx\DragDropHandlers ClassicCopyExt HKCR\CLSID\{8C83ACB1-75C3-45D2-882C-EFA32333491C} Adds classic Windows Explorer features IvoSoft 4.3.0.0 c:\program files\classic shell\classicexplorer64.dll 7/30/2016 12:04 PM TortoiseSVN HKCR\CLSID\{3035134A-7B7D-4FCC-81B4-1E394CA267EB} TortoiseSVN shell extension client http://tortoisesvn.net 1.9.5.27581 c:\program files\tortoisesvn\bin\tortoisestub.dll 11/26/2016 9:26 AM Compressed (zipped) Folder Right Drag Handler HKCR\CLSID\{BD472F60-27FA-11cf-B8B4-444553540000} Compressed (zipped) Folders Microsoft Corporation 6.3.9600.17415 c:\windows\system32\zipfldr.dll 10/28/2014 10:18 PM HKLM\Software\Classes\Folder\ShellEx\PropertySheetHandlers BriefcasePage HKCR\CLSID\{85BBD920-42A0-1069-A2E4-08002B30309D} Windows Briefcase Microsoft Corporation 6.3.9600.17415 c:\windows\system32\syncui.dll 10/28/2014 10:45 PM FCI Properties HKCR\CLSID\{748F920F-FB24-4D09-B360-BAF6F199AD6D} Microsoftr File Server Resource Management Shell Extension Microsoft Corporation 6.3.9600.17415 c:\windows\system32\srmshell.dll 10/28/2014 8:58 PM [DISABLED] Offline Files HKCR\CLSID\{7EFA68C6-086B-43e1-A2D2-55A113531240} Client Side Caching UI Microsoft Corporation 6.3.9600.17415 c:\windows\system32\cscui.dll 10/28/2014 10:01 PM HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers Tortoise1Normal HKCR\CLSID\{C5994560-53D9-4125-87C9-F193FC689CB2} Tortoise overlay handler shim http://tortoisesvn.net 1.1.4.26626 c:\program files\common files\tortoiseoverlays\tortoiseoverlays.dll 8/25/2015 2:58 PM Tortoise2Modified HKCR\CLSID\{C5994561-53D9-4125-87C9-F193FC689CB2} Tortoise overlay handler shim http://tortoisesvn.net 1.1.4.26626 c:\program files\common files\tortoiseoverlays\tortoiseoverlays.dll 8/25/2015 2:58 PM Tortoise3Conflict HKCR\CLSID\{C5994562-53D9-4125-87C9-F193FC689CB2} Tortoise overlay handler shim http://tortoisesvn.net 1.1.4.26626 c:\program files\common files\tortoiseoverlays\tortoiseoverlays.dll 8/25/2015 2:58 PM Tortoise4Locked HKCR\CLSID\{C5994563-53D9-4125-87C9-F193FC689CB2} Tortoise overlay handler shim http://tortoisesvn.net 1.1.4.26626 c:\program files\common files\tortoiseoverlays\tortoiseoverlays.dll 8/25/2015 2:58 PM Tortoise5ReadOnly HKCR\CLSID\{C5994564-53D9-4125-87C9-F193FC689CB2} Tortoise overlay handler shim http://tortoisesvn.net 1.1.4.26626 c:\program files\common files\tortoiseoverlays\tortoiseoverlays.dll 8/25/2015 2:58 PM Tortoise6Deleted HKCR\CLSID\{C5994565-53D9-4125-87C9-F193FC689CB2} Tortoise overlay handler shim http://tortoisesvn.net 1.1.4.26626 c:\program files\common files\tortoiseoverlays\tortoiseoverlays.dll 8/25/2015 2:58 PM Tortoise7Added HKCR\CLSID\{C5994566-53D9-4125-87C9-F193FC689CB2} Tortoise overlay handler shim http://tortoisesvn.net 1.1.4.26626 c:\program files\common files\tortoiseoverlays\tortoiseoverlays.dll 8/25/2015 2:58 PM Tortoise8Ignored HKCR\CLSID\{C5994567-53D9-4125-87C9-F193FC689CB2} Tortoise overlay handler shim http://tortoisesvn.net 1.1.4.26626 c:\program files\common files\tortoiseoverlays\tortoiseoverlays.dll 8/25/2015 2:58 PM Tortoise9Unversioned HKCR\CLSID\{C5994568-53D9-4125-87C9-F193FC689CB2} Tortoise overlay handler shim http://tortoisesvn.net 1.1.4.26626 c:\program files\common files\tortoiseoverlays\tortoiseoverlays.dll 8/25/2015 2:58 PM EnhancedStorageShell HKCR\CLSID\{D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D} Windows Enhanced Storage Shell Extension DLL Microsoft Corporation 6.3.9600.17415 c:\windows\system32\ehstorshell.dll 10/28/2014 10:07 PM ShareOverlay HKCR\CLSID\{594D4122-1F87-41E2-96C7-825FB4796516} Adds classic Windows Explorer features IvoSoft 4.3.0.0 c:\program files\classic shell\classicexplorer64.dll 7/30/2016 12:04 PM [DISABLED] AccExtIco1 HKCR\CLSID\{AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} Core Sync 2.3.0.197 c:\program files (x86)\adobe\adobe creative cloud\coresyncextension\coresync_x64.dll 10/25/2016 12:35 PM [DISABLED] AccExtIco2 HKCR\CLSID\{853B7E05-C47D-4985-909A-D0DC5C6D7303} Core Sync 2.3.0.197 c:\program files (x86)\adobe\adobe creative cloud\coresyncextension\coresync_x64.dll 10/25/2016 12:35 PM [DISABLED] AccExtIco3 HKCR\CLSID\{42D38F2E-98E9-4382-B546-E24E4D6D04BB} Core Sync 2.3.0.197 c:\program files (x86)\adobe\adobe creative cloud\coresyncextension\coresync_x64.dll 10/25/2016 12:35 PM [DISABLED] Offline Files HKCR\CLSID\{4E77131D-3629-431c-9818-C5679DC83E81} Client Side Caching UI Microsoft Corporation 6.3.9600.17415 c:\windows\system32\cscui.dll 10/28/2014 10:01 PM HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers Tortoise1Normal HKCR\CLSID\{C5994560-53D9-4125-87C9-F193FC689CB2} Tortoise overlay handler shim http://tortoisesvn.net 1.1.4.26626 c:\program files (x86)\common files\tortoiseoverlays\tortoiseoverlays.dll 8/25/2015 2:58 PM Tortoise2Modified HKCR\CLSID\{C5994561-53D9-4125-87C9-F193FC689CB2} Tortoise overlay handler shim http://tortoisesvn.net 1.1.4.26626 c:\program files (x86)\common files\tortoiseoverlays\tortoiseoverlays.dll 8/25/2015 2:58 PM Tortoise3Conflict HKCR\CLSID\{C5994562-53D9-4125-87C9-F193FC689CB2} Tortoise overlay handler shim http://tortoisesvn.net 1.1.4.26626 c:\program files (x86)\common files\tortoiseoverlays\tortoiseoverlays.dll 8/25/2015 2:58 PM Tortoise4Locked HKCR\CLSID\{C5994563-53D9-4125-87C9-F193FC689CB2} Tortoise overlay handler shim http://tortoisesvn.net 1.1.4.26626 c:\program files (x86)\common files\tortoiseoverlays\tortoiseoverlays.dll 8/25/2015 2:58 PM Tortoise5ReadOnly HKCR\CLSID\{C5994564-53D9-4125-87C9-F193FC689CB2} Tortoise overlay handler shim http://tortoisesvn.net 1.1.4.26626 c:\program files (x86)\common files\tortoiseoverlays\tortoiseoverlays.dll 8/25/2015 2:58 PM Tortoise6Deleted HKCR\CLSID\{C5994565-53D9-4125-87C9-F193FC689CB2} Tortoise overlay handler shim http://tortoisesvn.net 1.1.4.26626 c:\program files (x86)\common files\tortoiseoverlays\tortoiseoverlays.dll 8/25/2015 2:58 PM Tortoise7Added HKCR\CLSID\{C5994566-53D9-4125-87C9-F193FC689CB2} Tortoise overlay handler shim http://tortoisesvn.net 1.1.4.26626 c:\program files (x86)\common files\tortoiseoverlays\tortoiseoverlays.dll 8/25/2015 2:58 PM Tortoise8Ignored HKCR\CLSID\{C5994567-53D9-4125-87C9-F193FC689CB2} Tortoise overlay handler shim http://tortoisesvn.net 1.1.4.26626 c:\program files (x86)\common files\tortoiseoverlays\tortoiseoverlays.dll 8/25/2015 2:58 PM Tortoise9Unversioned HKCR\CLSID\{C5994568-53D9-4125-87C9-F193FC689CB2} Tortoise overlay handler shim http://tortoisesvn.net 1.1.4.26626 c:\program files (x86)\common files\tortoiseoverlays\tortoiseoverlays.dll 8/25/2015 2:58 PM ShareOverlay HKCR\CLSID\{594D4122-1F87-41E2-96C7-825FB4796516} Adds classic Windows Explorer features IvoSoft 4.3.0.0 c:\program files\classic shell\classicexplorer32.dll 7/30/2016 12:05 PM HKLM\Software\Microsoft\Internet Explorer\Toolbar &Quero HKCR\CLSID\{A411D7F4-8D11-43EF-BDE4-AA921666388A} Quero Toolbar for Internet Explorer Viktor Krammer 8.0.0.0 c:\program files\quero toolbar\x64\quero.dll 12/14/2013 6:06 PM Classic Explorer Bar HKCR\CLSID\{553891B7-A0D5-4526-BE18-D3CE461D6310} Adds classic Windows Explorer features IvoSoft 4.3.0.0 c:\program files\classic shell\classicexplorer64.dll 7/30/2016 12:04 PM [DISABLED] Adobe Acrobat Create PDF Toolbar HKCR\CLSID\{47833539-D0C5-4125-9FA8-0819E2EAAC93} Adobe PDF Toolbar for Internet Explorer Adobe Systems Incorporated 15.9.20069.28170 c:\program files (x86)\common files\adobe\acrobat\wcieactivex\dc\x64\acroiefavstub.dll 9/30/2015 2:23 PM HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Toolbar &Quero HKCR\CLSID\{A411D7F4-8D11-43EF-BDE4-AA921666388A} Quero Toolbar for Internet Explorer Viktor Krammer 8.0.0.0 c:\program files\quero toolbar\quero.dll 12/14/2013 6:06 PM Classic Explorer Bar HKCR\CLSID\{553891B7-A0D5-4526-BE18-D3CE461D6310} Adds classic Windows Explorer features IvoSoft 4.3.0.0 c:\program files\classic shell\classicexplorer32.dll 7/30/2016 12:05 PM [DISABLED] Adobe Acrobat Create PDF Toolbar HKCR\CLSID\{47833539-D0C5-4125-9FA8-0819E2EAAC93} Adobe PDF Toolbar for Internet Explorer Adobe Systems Incorporated 15.9.20069.28170 c:\program files (x86)\common files\adobe\acrobat\wcieactivex\dc\acroiefavstub.dll 9/30/2015 2:23 PM HKLM\Software\Microsoft\Internet Explorer\Extensions Classic IE Settings C:\Program Files\Classic Shell\ClassicIE_32.exe Classic IE IvoSoft 4.3.0.0 c:\program files\classic shell\classicie_32.exe 7/30/2016 12:05 PM HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Extensions Classic IE Settings C:\Program Files\Classic Shell\ClassicIE_32.exe Classic IE IvoSoft 4.3.0.0 c:\program files\classic shell\classicie_32.exe 7/30/2016 12:05 PM HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32 msacm.l3acm C:\Windows\System32\l3codeca.acm MPEG Layer-3 Audio Codec for MSACM Fraunhofer Institut Integrierte Schaltungen IIS 1.9.0.401 c:\windows\system32\l3codeca.acm 10/28/2014 10:42 PM VIDC.YUY2 msyuv.dll Microsoft UYVY Video Decompressor Microsoft Corporation 6.3.9600.17415 c:\windows\system32\msyuv.dll 10/28/2014 10:42 PM vidc.i420 lvcod64.dll Video Codec Logitech Inc. 13.80.853.0 c:\windows\system32\lvcod64.dll 10/22/2012 10:11 PM msacm.msgsm610 msgsm32.acm Microsoft GSM 6.10 Audio CODEC for MSACM Microsoft Corporation 6.3.9600.17415 c:\windows\system32\msgsm32.acm 10/28/2014 9:28 PM msacm.msg711 msg711.acm Microsoft CCITT G.711 (A-Law and u-Law) CODEC for MSACM Microsoft Corporation 6.3.9600.17415 c:\windows\system32\msg711.acm 10/28/2014 9:28 PM VIDC.YVYU msyuv.dll Microsoft UYVY Video Decompressor Microsoft Corporation 6.3.9600.17415 c:\windows\system32\msyuv.dll 10/28/2014 10:42 PM VIDC.YVU9 tsbyuv.dll Toshiba Video Codec Microsoft Corporation 6.3.9600.17415 c:\windows\system32\tsbyuv.dll 10/28/2014 10:42 PM wavemapper msacm32.drv Microsoft Sound Mapper Microsoft Corporation 6.3.9600.17415 c:\windows\system32\msacm32.drv 10/28/2014 10:37 PM midimapper midimap.dll Microsoft MIDI Mapper Microsoft Corporation 6.3.9600.17415 c:\windows\system32\midimap.dll 10/28/2014 10:42 PM VIDC.UYVY msyuv.dll Microsoft UYVY Video Decompressor Microsoft Corporation 6.3.9600.17415 c:\windows\system32\msyuv.dll 10/28/2014 10:42 PM VIDC.IYUV iyuv_32.dll Intel Indeo(R) Video YUV Codec Microsoft Corporation 6.3.9600.17415 c:\windows\system32\iyuv_32.dll 10/28/2014 10:42 PM vidc.mrle msrle32.dll Microsoft RLE Compressor Microsoft Corporation 6.3.9600.17415 c:\windows\system32\msrle32.dll 10/28/2014 10:42 PM msacm.imaadpcm imaadp32.acm IMA ADPCM CODEC for MSACM Microsoft Corporation 6.3.9600.17415 c:\windows\system32\imaadp32.acm 10/28/2014 9:27 PM msacm.msadpcm msadp32.acm Microsoft ADPCM CODEC for MSACM Microsoft Corporation 6.3.9600.17415 c:\windows\system32\msadp32.acm 10/28/2014 9:28 PM vidc.msvc msvidc32.dll Microsoft Video 1 Compressor Microsoft Corporation 6.3.9600.17415 c:\windows\system32\msvidc32.dll 10/28/2014 10:42 PM MSVideo8 VfWWDM32.dll VfW MM Driver for WDM Video Capture Devices Microsoft Corporation 6.3.9600.17415 c:\windows\system32\vfwwdm32.dll 10/28/2014 10:27 PM wave1 wdmaud.drv Winmm audio system driver Microsoft Corporation 6.3.9600.17415 c:\windows\system32\wdmaud.drv 10/28/2014 9:10 PM midi1 wdmaud.drv Winmm audio system driver Microsoft Corporation 6.3.9600.17415 c:\windows\system32\wdmaud.drv 10/28/2014 9:10 PM mixer1 wdmaud.drv Winmm audio system driver Microsoft Corporation 6.3.9600.17415 c:\windows\system32\wdmaud.drv 10/28/2014 9:10 PM aux1 wdmaud.drv Winmm audio system driver Microsoft Corporation 6.3.9600.17415 c:\windows\system32\wdmaud.drv 10/28/2014 9:10 PM wave2 wdmaud.drv Winmm audio system driver Microsoft Corporation 6.3.9600.17415 c:\windows\system32\wdmaud.drv 10/28/2014 9:10 PM midi2 wdmaud.drv Winmm audio system driver Microsoft Corporation 6.3.9600.17415 c:\windows\system32\wdmaud.drv 10/28/2014 9:10 PM mixer2 wdmaud.drv Winmm audio system driver Microsoft Corporation 6.3.9600.17415 c:\windows\system32\wdmaud.drv 10/28/2014 9:10 PM aux2 wdmaud.drv Winmm audio system driver Microsoft Corporation 6.3.9600.17415 c:\windows\system32\wdmaud.drv 10/28/2014 9:10 PM MSVideo vfwwdm32.dll VfW MM Driver for WDM Video Capture Devices Microsoft Corporation 6.3.9600.17415 c:\windows\system32\vfwwdm32.dll 10/28/2014 10:27 PM wave wdmaud.drv Winmm audio system driver Microsoft Corporation 6.3.9600.17415 c:\windows\system32\wdmaud.drv 10/28/2014 9:10 PM midi wdmaud.drv Winmm audio system driver Microsoft Corporation 6.3.9600.17415 c:\windows\system32\wdmaud.drv 10/28/2014 9:10 PM mixer wdmaud.drv Winmm audio system driver Microsoft Corporation 6.3.9600.17415 c:\windows\system32\wdmaud.drv 10/28/2014 9:10 PM aux wdmaud.drv Winmm audio system driver Microsoft Corporation 6.3.9600.17415 c:\windows\system32\wdmaud.drv 10/28/2014 9:10 PM wave3 wdmaud.drv Winmm audio system driver Microsoft Corporation 6.3.9600.17415 c:\windows\system32\wdmaud.drv 10/28/2014 9:10 PM midi3 wdmaud.drv Winmm audio system driver Microsoft Corporation 6.3.9600.17415 c:\windows\system32\wdmaud.drv 10/28/2014 9:10 PM mixer3 wdmaud.drv Winmm audio system driver Microsoft Corporation 6.3.9600.17415 c:\windows\system32\wdmaud.drv 10/28/2014 9:10 PM aux3 wdmaud.drv Winmm audio system driver Microsoft Corporation 6.3.9600.17415 c:\windows\system32\wdmaud.drv 10/28/2014 9:10 PM wave4 wdmaud.drv Winmm audio system driver Microsoft Corporation 6.3.9600.17415 c:\windows\system32\wdmaud.drv 10/28/2014 9:10 PM midi4 wdmaud.drv Winmm audio system driver Microsoft Corporation 6.3.9600.17415 c:\windows\system32\wdmaud.drv 10/28/2014 9:10 PM mixer4 wdmaud.drv Winmm audio system driver Microsoft Corporation 6.3.9600.17415 c:\windows\system32\wdmaud.drv 10/28/2014 9:10 PM aux4 wdmaud.drv Winmm audio system driver Microsoft Corporation 6.3.9600.17415 c:\windows\system32\wdmaud.drv 10/28/2014 9:10 PM HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32 msacm.msgsm610 msgsm32.acm File not found: msgsm32.acm msacm.msg711 msg711.acm File not found: msg711.acm msacm.l3acm C:\Windows\SysWOW64\l3codeca.acm MPEG Layer-3 Audio Codec for MSACM Fraunhofer Institut Integrierte Schaltungen IIS 1.9.0.401 c:\windows\syswow64\l3codeca.acm 10/28/2014 9:58 PM vidc.yuy2 msyuv.dll File not found: msyuv.dll vidc.i420 lvcodec2.dll File not found: lvcodec2.dll vidc.cvid iccvid.dll File not found: iccvid.dll vidc.yvyu msyuv.dll File not found: msyuv.dll vidc.yvu9 tsbyuv.dll File not found: tsbyuv.dll wavemapper msacm32.drv File not found: msacm32.drv midimapper midimap.dll File not found: midimap.dll vidc.uyvy msyuv.dll File not found: msyuv.dll msacm.imaadpcm imaadp32.acm File not found: imaadp32.acm msacm.msadpcm msadp32.acm File not found: msadp32.acm vidc.iyuv iyuv_32.dll File not found: iyuv_32.dll vidc.mrle msrle32.dll File not found: msrle32.dll vidc.msvc msvidc32.dll File not found: msvidc32.dll wave1 wdmaud.drv File not found: wdmaud.drv midi1 wdmaud.drv File not found: wdmaud.drv mixer1 wdmaud.drv File not found: wdmaud.drv aux1 wdmaud.drv File not found: wdmaud.drv wave2 wdmaud.drv File not found: wdmaud.drv midi2 wdmaud.drv File not found: wdmaud.drv mixer2 wdmaud.drv File not found: wdmaud.drv aux2 wdmaud.drv File not found: wdmaud.drv msacm.l3codecp l3codecp.acm File not found: l3codecp.acm wave wdmaud.drv File not found: wdmaud.drv midi wdmaud.drv File not found: wdmaud.drv mixer wdmaud.drv File not found: wdmaud.drv aux wdmaud.drv File not found: wdmaud.drv wave3 wdmaud.drv File not found: wdmaud.drv midi3 wdmaud.drv File not found: wdmaud.drv mixer3 wdmaud.drv File not found: wdmaud.drv aux3 wdmaud.drv File not found: wdmaud.drv wave4 wdmaud.drv File not found: wdmaud.drv midi4 wdmaud.drv File not found: wdmaud.drv mixer4 wdmaud.drv File not found: wdmaud.drv aux4 wdmaud.drv File not found: wdmaud.drv HKLM\Software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance DV Muxer HKCR\CLSID\{129D7E40-C10D-11D0-AFB9-00AA00B67A42} DirectShow Runtime. Microsoft Corporation 6.6.9600.17415 c:\windows\system32\qdv.dll 10/28/2014 10:27 PM Color Space Converter HKCR\CLSID\{1643E180-90F5-11CE-97D5-00AA0055595A} DirectShow Runtime. Microsoft Corporation 6.6.9600.18617 c:\windows\system32\quartz.dll 3/3/2017 11:10 AM WM ASF Reader HKCR\CLSID\{187463A0-5BB7-11D3-ACBE-0080C75E246E} DirectShow ASF Support Microsoft Corporation 12.0.9600.17415 c:\windows\system32\qasf.dll 10/28/2014 9:54 PM AVI Splitter HKCR\CLSID\{1B544C20-FD0B-11CE-8C63-00AA0044B51E} DirectShow Runtime. Microsoft Corporation 6.6.9600.18617 c:\windows\system32\quartz.dll 3/3/2017 11:10 AM VGA 16 color ditherer HKCR\CLSID\{1DA08500-9EDC-11CF-BC10-00AA00AC74F6} DirectShow Runtime. Microsoft Corporation 6.6.9600.18617 c:\windows\system32\quartz.dll 3/3/2017 11:10 AM SBE2MediaTypeProfile HKCR\CLSID\{1f26a602-2b5c-4b63-b8e8-9ea5c1a7dc2e} DirectShow Stream Buffer Filter. Microsoft Corporation 6.6.9600.17415 c:\windows\system32\sbe.dll 10/28/2014 9:47 PM Microsoft DTV-DVD Video Decoder HKCR\CLSID\{212690FB-83E5-4526-8FD7-74478B7939CD} Microsoft DTV-DVD Video Decoder Microsoft Corporation 12.0.9600.17374 c:\windows\system32\msmpeg2vdec.dll 9/12/2014 3:49 PM AC3 Parser Filter HKCR\CLSID\{280A3020-86CF-11D1-ABE6-00A0C905F375} DirectShow MPEG-2 Splitter. Microsoft Corporation 6.6.9600.17415 c:\windows\system32\mpg2splt.ax 10/28/2014 10:31 PM StreamBufferSink HKCR\CLSID\{2DB47AE5-CF39-43C2-B4D6-0CD8D90946F4} DirectShow Stream Buffer Filter. Microsoft Corporation 6.6.9600.17415 c:\windows\system32\sbe.dll 10/28/2014 9:47 PM Microsoft TV Captions Decoder HKCR\CLSID\{2F7EE4B6-6FF5-4EB4-B24A-2BFC41117171} Media Center Captioning Module Microsoft Corporation 6.3.9600.16384 c:\windows\ehome\mstvcapn.dll 8/22/2013 7:14 AM MJPEG Decompressor HKCR\CLSID\{301056D0-6DFF-11D2-9EEB-006008039E37} DirectShow Runtime. Microsoft Corporation 6.6.9600.18617 c:\windows\system32\quartz.dll 3/3/2017 11:10 AM CBVA DMO wrapper filter HKCR\CLSID\{31C88FF0-2111-44BD-A121-61DE9CD0412D} Windows Media Center Content Analysis Filter Module Microsoft Corporation 6.3.9600.16384 c:\windows\ehome\cbva.dll 8/22/2013 6:40 AM MPEG-I Stream Splitter HKCR\CLSID\{336475D0-942A-11CE-A870-00AA002FEAB5} DirectShow Runtime. Microsoft Corporation 6.6.9600.18617 c:\windows\system32\quartz.dll 3/3/2017 11:10 AM SAMI (CC) Reader HKCR\CLSID\{33FACFE0-A9BE-11D0-A520-00A0D10129C0} DirectShow Runtime. Microsoft Corporation 6.6.9600.18617 c:\windows\system32\quartz.dll 3/3/2017 11:10 AM VBI Codec HKCR\CLSID\{370A1D5D-DDEB-418C-81CD-189E0D4FA443} Microsoft VBI Codec Microsoft Corporation 6.6.9600.17415 c:\windows\system32\vbicodec.ax 10/28/2014 10:02 PM MPEG-2 Splitter HKCR\CLSID\{3AE86B20-7BE8-11D1-ABE6-00A0C905F375} DirectShow MPEG-2 Splitter. Microsoft Corporation 6.6.9600.17415 c:\windows\system32\mpg2splt.ax 10/28/2014 10:31 PM Closed Captions Analysis Filter HKCR\CLSID\{3D07A539-35CA-447C-9B05-8D85CE924F9E} CCA DirectShow Filter. Microsoft Corporation 6.6.9600.17415 c:\windows\system32\cca.dll 10/28/2014 10:31 PM SBE2FileScan HKCR\CLSID\{3E458037-0CA6-41aa-A594-2AA6C02D709B} DirectShow Stream Buffer Filter. Microsoft Corporation 6.6.9600.17415 c:\windows\system32\sbe.dll 10/28/2014 9:47 PM Microsoft MPEG-2 Video Encoder HKCR\CLSID\{42150CD9-CA9A-4EA5-9939-30EE037F6E74} Microsoft MPEG-2 Encoder Microsoft Corporation 12.0.9600.17415 c:\windows\system32\msmpeg2enc.dll 10/28/2014 10:56 PM Internal Text Renderer HKCR\CLSID\{48025243-2D39-11CE-875D-00608CB78066} DirectShow Runtime. Microsoft Corporation 6.6.9600.18617 c:\windows\system32\quartz.dll 3/3/2017 11:10 AM MPEG Audio Codec HKCR\CLSID\{4A2286E0-7BEF-11CE-9BD9-0000E202599C} DirectShow Runtime. Microsoft Corporation 6.6.9600.18617 c:\windows\system32\quartz.dll 3/3/2017 11:10 AM DV Splitter HKCR\CLSID\{4EB31670-9FC6-11CF-AF6E-00AA00B67A42} DirectShow Runtime. Microsoft Corporation 6.6.9600.17415 c:\windows\system32\qdv.dll 10/28/2014 10:27 PM Video Mixing Renderer 9 HKCR\CLSID\{51B4ABF3-748F-4E3B-A276-C828330E926A} DirectShow Runtime. Microsoft Corporation 6.6.9600.18617 c:\windows\system32\quartz.dll 3/3/2017 11:10 AM Microsoft MPEG-2 Encoder HKCR\CLSID\{5F5AFF4A-2F7F-4279-88C2-CD88EB39D144} Microsoft MPEG-2 Encoder Microsoft Corporation 12.0.9600.17415 c:\windows\system32\msmpeg2enc.dll 10/28/2014 10:56 PM ACM Wrapper HKCR\CLSID\{6A08CF80-0E18-11CF-A24D-0020AFD79767} DirectShow Runtime. Microsoft Corporation 6.6.9600.18617 c:\windows\system32\quartz.dll 3/3/2017 11:10 AM Default Video Renderer HKCR\CLSID\{6BC1CFFA-8FC1-4261-AC22-CFB4CC38DB50} DirectShow Runtime. Microsoft Corporation 6.6.9600.18617 c:\windows\system32\quartz.dll 3/3/2017 11:10 AM Mpeg-2 Video Stream Analysis HKCR\CLSID\{6CFAD761-735D-4AA5-8AFC-AF91A7D61EBA} DirectShow Stream Buffer Filter. Microsoft Corporation 6.6.9600.17415 c:\windows\system32\sbe.dll 10/28/2014 9:47 PM Video Port Manager HKCR\CLSID\{6F26A6CD-967B-47FD-874A-7AED2C9D25A2} DirectShow Runtime. Microsoft Corporation 6.6.9600.18617 c:\windows\system32\quartz.dll 3/3/2017 11:10 AM Video Renderer HKCR\CLSID\{70E102B0-5556-11CE-97C0-00AA0055595A} DirectShow Runtime. Microsoft Corporation 6.6.9600.18617 c:\windows\system32\quartz.dll 3/3/2017 11:10 AM VPS Decoder HKCR\CLSID\{7B3BC2A0-AA50-4ae7-BD44-B03649EC87C2} Microsoft Teletext Server Microsoft Corporation 6.6.9600.17415 c:\windows\system32\wstpager.ax 10/28/2014 10:31 PM WM ASF Writer HKCR\CLSID\{7C23220E-55BB-11D3-8B16-00C04FB6BD3D} DirectShow ASF Support Microsoft Corporation 12.0.9600.17415 c:\windows\system32\qasf.dll 10/28/2014 9:54 PM VBI Surface Allocator HKCR\CLSID\{814B9800-1C88-11D1-BAD9-00609744111A} VBI Surface Allocator Filter Microsoft Corporation 6.3.9600.17415 c:\windows\system32\vbisurf.ax 10/28/2014 10:26 PM File Writer HKCR\CLSID\{8596E5F0-0DA5-11D0-BD21-00A0C911CE86} DirectShow Runtime. Microsoft Corporation 6.6.9600.16384 c:\windows\system32\qcap.dll 8/22/2013 7:16 AM iTV Data Sink HKCR\CLSID\{88EBC1EE-F90A-484A-B9C5-8F9C0F37A828} iTV Data Filters. Microsoft Corporation 6.6.9600.16384 c:\windows\system32\itvdata.dll 8/22/2013 6:17 AM iTV Data Capture filter HKCR\CLSID\{8A51DC27-5A35-4E02-95A3-428BC6244A3C} iTV Data Filters. Microsoft Corporation 6.6.9600.16384 c:\windows\system32\itvdata.dll 8/22/2013 6:17 AM DVD Navigator HKCR\CLSID\{9B8C4620-2C1A-11D0-8493-00A02438AD48} DirectShow DVD PlayBack Runtime. Microsoft Corporation 6.6.9600.18154 c:\windows\system32\qdvd.dll 12/3/2015 2:07 PM Microsoft TV Subtitles Decoder HKCR\CLSID\{9F22CFEA-CE07-41ab-8BA0-C7364AF90AF9} Media Center Captioning Module Microsoft Corporation 6.3.9600.16384 c:\windows\ehome\mstvcapn.dll 8/22/2013 7:14 AM Microsoft MPEG-2 Audio Encoder HKCR\CLSID\{ACD453BC-C58A-44D1-BBF5-BFB325BE2D78} Microsoft MPEG-2 Encoder Microsoft Corporation 12.0.9600.17415 c:\windows\system32\msmpeg2enc.dll 10/28/2014 10:56 PM WST Pager HKCR\CLSID\{AD6C8934-F31B-4F43-B5E4-0541C1452F6F} Microsoft Teletext Server Microsoft Corporation 6.6.9600.17415 c:\windows\system32\wstpager.ax 10/28/2014 10:31 PM MPEG-2 Demultiplexer HKCR\CLSID\{AFB6C280-2C41-11D3-8A60-0000F81E0E4A} DirectShow MPEG-2 Splitter. Microsoft Corporation 6.6.9600.17415 c:\windows\system32\mpg2splt.ax 10/28/2014 10:31 PM DV Video Decoder HKCR\CLSID\{B1B77C00-C3E4-11CF-AF79-00AA00B67A42} DirectShow Runtime. Microsoft Corporation 6.6.9600.17415 c:\windows\system32\qdv.dll 10/28/2014 10:27 PM Sample Grabber HKCR\CLSID\{C1F400A0-3F08-11D3-9F0B-006008039E37} DirectShow Editing. Microsoft Corporation 6.6.9600.18152 c:\windows\system32\qedit.dll 12/2/2015 11:04 AM Null Renderer HKCR\CLSID\{C1F400A4-3F08-11D3-9F0B-006008039E37} DirectShow Editing. Microsoft Corporation 6.6.9600.18152 c:\windows\system32\qedit.dll 12/2/2015 11:04 AM MPEG-2 Sections and Tables HKCR\CLSID\{C666E115-BB62-4027-A113-82D643FE2D99} Microsoft MPEG-2 Section and Table Acquisition Module Microsoft Corporation 6.6.9600.17415 c:\windows\system32\mpeg2data.ax 10/28/2014 10:26 PM Microsoft AC3 Encoder HKCR\CLSID\{C6B400E2-20A7-4E58-A2FE-24619682CE6C} Microsoft AC-3 Encoder Microsoft Corporation 6.3.9600.17415 c:\windows\system32\msac3enc.dll 10/28/2014 10:06 PM StreamBufferSource HKCR\CLSID\{C9F5FE02-F851-4EB5-99EE-AD602AF1E619} DirectShow Stream Buffer Filter. Microsoft Corporation 6.6.9600.17415 c:\windows\system32\sbe.dll 10/28/2014 9:47 PM Smart Tee Filter HKCR\CLSID\{CC58E280-8AA1-11D1-B3F1-00AA003761C5} DirectShow Runtime. Microsoft Corporation 6.6.9600.16384 c:\windows\system32\qcap.dll 8/22/2013 7:16 AM AVI Decompressor HKCR\CLSID\{CF49D4E0-1115-11CE-B03A-0020AF0BA770} DirectShow Runtime. Microsoft Corporation 6.6.9600.18617 c:\windows\system32\quartz.dll 3/3/2017 11:10 AM NetBridge HKCR\CLSID\{D145BF00-4389-49E9-B3A0-4178719550CD} Media Center NetBridge Microsoft Corporation 6.3.9600.16384 c:\windows\ehome\netbridge.dll 8/22/2013 6:53 AM AVI/WAV File Source HKCR\CLSID\{D3588AB0-0781-11CE-B03A-0020AF0BA770} DirectShow Runtime. Microsoft Corporation 6.6.9600.18617 c:\windows\system32\quartz.dll 3/3/2017 11:10 AM Wave Parser HKCR\CLSID\{D51BD5A1-7548-11CF-A520-0080C77EF58A} DirectShow Runtime. Microsoft Corporation 6.6.9600.18617 c:\windows\system32\quartz.dll 3/3/2017 11:10 AM MIDI Parser HKCR\CLSID\{D51BD5A2-7548-11CF-A520-0080C77EF58A} DirectShow Runtime. Microsoft Corporation 6.6.9600.18617 c:\windows\system32\quartz.dll 3/3/2017 11:10 AM Multi-file Parser HKCR\CLSID\{D51BD5A3-7548-11CF-A520-0080C77EF58A} DirectShow Runtime. Microsoft Corporation 6.6.9600.18617 c:\windows\system32\quartz.dll 3/3/2017 11:10 AM File stream renderer HKCR\CLSID\{D51BD5A5-7548-11CF-A520-0080C77EF58A} DirectShow Runtime. Microsoft Corporation 6.6.9600.18617 c:\windows\system32\quartz.dll 3/3/2017 11:10 AM Microsoft DTV-DVD Audio Decoder HKCR\CLSID\{E1F1A0B8-BEEE-490D-BA7C-066C40B5E2B9} Microsoft DTV-DVD Audio Decoder Microsoft Corporation 12.0.9600.18145 c:\windows\system32\msmpeg2adec.dll 12/3/2015 10:41 PM SBE2 Sink HKCR\CLSID\{E2448508-95DA-4205-9A27-7EC81E723B1A} DirectShow Stream Buffer Filter. Microsoft Corporation 6.6.9600.17415 c:\windows\system32\sbe.dll 10/28/2014 9:47 PM AVI mux HKCR\CLSID\{E2510970-F137-11CE-8B67-00AA00A3F1A6} DirectShow Runtime. Microsoft Corporation 6.6.9600.16384 c:\windows\system32\qcap.dll 8/22/2013 7:16 AM Line 21 Decoder 2 HKCR\CLSID\{E4206432-01A1-4BEE-B3E1-3702C8EDC574} DirectShow Runtime. Microsoft Corporation 6.6.9600.18617 c:\windows\system32\quartz.dll 3/3/2017 11:10 AM File Source (Async.) HKCR\CLSID\{E436EBB5-524F-11CE-9F53-0020AF0BA770} DirectShow Runtime. Microsoft Corporation 6.6.9600.18617 c:\windows\system32\quartz.dll 3/3/2017 11:10 AM File Source (URL) HKCR\CLSID\{E436EBB6-524F-11CE-9F53-0020AF0BA770} DirectShow Runtime. Microsoft Corporation 6.6.9600.18617 c:\windows\system32\quartz.dll 3/3/2017 11:10 AM Media Center Extender Encryption Filter HKCR\CLSID\{E55A0B49-2F73-44D4-AD66-48966DED31BA} Media Center Extender Filter Microsoft Corporation 6.3.9600.16384 c:\windows\ehome\mcx2filter.dll 8/22/2013 6:52 AM SoundRecorder WAV Dest HKCR\CLSID\{E882F102-F626-49E9-BD68-CE2BE7E59EA0} Windows Sound Recorder Microsoft Corporation 6.3.9600.17415 c:\windows\system32\wavdest.dll 10/28/2014 10:04 PM SoundRecorder Volume Watch HKCR\CLSID\{E882F102-F626-49E9-BD68-CE2BE7E59EB0} Windows Sound Recorder Microsoft Corporation 6.3.9600.17415 c:\windows\system32\wavdest.dll 10/28/2014 10:04 PM SoundRecorder Null Renderer HKCR\CLSID\{E882F102-F626-49E9-BD68-CE2BE7E59EC0} Windows Sound Recorder Microsoft Corporation 6.3.9600.17415 c:\windows\system32\wavdest.dll 10/28/2014 10:04 PM Infinite Pin Tee Filter HKCR\CLSID\{F8388A40-D5BB-11D0-BE5A-0080C706568E} DirectShow Runtime. Microsoft Corporation 6.6.9600.16384 c:\windows\system32\qcap.dll 8/22/2013 7:16 AM Enhanced Video Renderer HKCR\CLSID\{FA10746C-9B63-4B6C-BC49-FC300EA5F256} Enhanced Video Renderer DLL Microsoft Corporation 6.3.9600.18154 c:\windows\system32\evr.dll 12/3/2015 2:06 PM BDA MPEG2 Transport Information Filter HKCR\CLSID\{FC772AB0-0C7F-11D3-8FF2-00A0C9224CF4} Microsoft Transport Information Filter for MPEG2 based networks. Microsoft Corporation 6.6.9600.17415 c:\windows\system32\psisrndr.ax 10/28/2014 10:09 PM MPEG Video Codec HKCR\CLSID\{FEB50740-7BEF-11CE-9BD9-0000E202599C} DirectShow Runtime. Microsoft Corporation 6.6.9600.18617 c:\windows\system32\quartz.dll 3/3/2017 11:10 AM HKLM\Software\Wow6432Node\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance DV Muxer HKCR\CLSID\{129D7E40-C10D-11D0-AFB9-00AA00B67A42} DirectShow Runtime. Microsoft Corporation 6.6.9600.17415 c:\windows\syswow64\qdv.dll 10/28/2014 9:46 PM Color Space Converter HKCR\CLSID\{1643E180-90F5-11CE-97D5-00AA0055595A} DirectShow Runtime. Microsoft Corporation 6.6.9600.18617 c:\windows\syswow64\quartz.dll 3/3/2017 11:05 AM WM ASF Reader HKCR\CLSID\{187463A0-5BB7-11D3-ACBE-0080C75E246E} DirectShow ASF Support Microsoft Corporation 12.0.9600.17415 c:\windows\syswow64\qasf.dll 10/28/2014 9:22 PM AVI Splitter HKCR\CLSID\{1B544C20-FD0B-11CE-8C63-00AA0044B51E} DirectShow Runtime. Microsoft Corporation 6.6.9600.18617 c:\windows\syswow64\quartz.dll 3/3/2017 11:05 AM VGA 16 color ditherer HKCR\CLSID\{1DA08500-9EDC-11CF-BC10-00AA00AC74F6} DirectShow Runtime. Microsoft Corporation 6.6.9600.18617 c:\windows\syswow64\quartz.dll 3/3/2017 11:05 AM SBE2MediaTypeProfile HKCR\CLSID\{1f26a602-2b5c-4b63-b8e8-9ea5c1a7dc2e} DirectShow Stream Buffer Filter. Microsoft Corporation 6.6.9600.17415 c:\windows\syswow64\sbe.dll 10/28/2014 9:17 PM Microsoft DTV-DVD Video Decoder HKCR\CLSID\{212690FB-83E5-4526-8FD7-74478B7939CD} Microsoft DTV-DVD Video Decoder Microsoft Corporation 12.0.9600.17374 c:\windows\syswow64\msmpeg2vdec.dll 9/12/2014 3:48 PM AC3 Parser Filter HKCR\CLSID\{280A3020-86CF-11D1-ABE6-00A0C905F375} DirectShow MPEG-2 Splitter. Microsoft Corporation 6.6.9600.17415 c:\windows\syswow64\mpg2splt.ax 10/28/2014 9:49 PM StreamBufferSink HKCR\CLSID\{2DB47AE5-CF39-43C2-B4D6-0CD8D90946F4} DirectShow Stream Buffer Filter. Microsoft Corporation 6.6.9600.17415 c:\windows\syswow64\sbe.dll 10/28/2014 9:17 PM MJPEG Decompressor HKCR\CLSID\{301056D0-6DFF-11D2-9EEB-006008039E37} DirectShow Runtime. Microsoft Corporation 6.6.9600.18617 c:\windows\syswow64\quartz.dll 3/3/2017 11:05 AM MPEG-I Stream Splitter HKCR\CLSID\{336475D0-942A-11CE-A870-00AA002FEAB5} DirectShow Runtime. Microsoft Corporation 6.6.9600.18617 c:\windows\syswow64\quartz.dll 3/3/2017 11:05 AM SAMI (CC) Reader HKCR\CLSID\{33FACFE0-A9BE-11D0-A520-00A0D10129C0} DirectShow Runtime. Microsoft Corporation 6.6.9600.18617 c:\windows\syswow64\quartz.dll 3/3/2017 11:05 AM VBI Codec HKCR\CLSID\{370A1D5D-DDEB-418C-81CD-189E0D4FA443} Microsoft VBI Codec Microsoft Corporation 6.6.9600.17415 c:\windows\syswow64\vbicodec.ax 10/28/2014 9:27 PM MPEG-2 Splitter HKCR\CLSID\{3AE86B20-7BE8-11D1-ABE6-00A0C905F375} DirectShow MPEG-2 Splitter. Microsoft Corporation 6.6.9600.17415 c:\windows\syswow64\mpg2splt.ax 10/28/2014 9:49 PM Closed Captions Analysis Filter HKCR\CLSID\{3D07A539-35CA-447C-9B05-8D85CE924F9E} CCA DirectShow Filter. Microsoft Corporation 6.6.9600.17415 c:\windows\syswow64\cca.dll 10/28/2014 9:49 PM SBE2FileScan HKCR\CLSID\{3E458037-0CA6-41aa-A594-2AA6C02D709B} DirectShow Stream Buffer Filter. Microsoft Corporation 6.6.9600.17415 c:\windows\syswow64\sbe.dll 10/28/2014 9:17 PM Microsoft MPEG-2 Video Encoder HKCR\CLSID\{42150CD9-CA9A-4EA5-9939-30EE037F6E74} Microsoft MPEG-2 Encoder Microsoft Corporation 12.0.9600.17415 c:\windows\syswow64\msmpeg2enc.dll 10/28/2014 10:11 PM Internal Text Renderer HKCR\CLSID\{48025243-2D39-11CE-875D-00608CB78066} DirectShow Runtime. Microsoft Corporation 6.6.9600.18617 c:\windows\syswow64\quartz.dll 3/3/2017 11:05 AM MPEG Audio Codec HKCR\CLSID\{4A2286E0-7BEF-11CE-9BD9-0000E202599C} DirectShow Runtime. Microsoft Corporation 6.6.9600.18617 c:\windows\syswow64\quartz.dll 3/3/2017 11:05 AM DV Splitter HKCR\CLSID\{4EB31670-9FC6-11CF-AF6E-00AA00B67A42} DirectShow Runtime. Microsoft Corporation 6.6.9600.17415 c:\windows\syswow64\qdv.dll 10/28/2014 9:46 PM Video Mixing Renderer 9 HKCR\CLSID\{51B4ABF3-748F-4E3B-A276-C828330E926A} DirectShow Runtime. Microsoft Corporation 6.6.9600.18617 c:\windows\syswow64\quartz.dll 3/3/2017 11:05 AM Microsoft MPEG-2 Encoder HKCR\CLSID\{5F5AFF4A-2F7F-4279-88C2-CD88EB39D144} Microsoft MPEG-2 Encoder Microsoft Corporation 12.0.9600.17415 c:\windows\syswow64\msmpeg2enc.dll 10/28/2014 10:11 PM ACM Wrapper HKCR\CLSID\{6A08CF80-0E18-11CF-A24D-0020AFD79767} DirectShow Runtime. Microsoft Corporation 6.6.9600.18617 c:\windows\syswow64\quartz.dll 3/3/2017 11:05 AM Default Video Renderer HKCR\CLSID\{6BC1CFFA-8FC1-4261-AC22-CFB4CC38DB50} DirectShow Runtime. Microsoft Corporation 6.6.9600.18617 c:\windows\syswow64\quartz.dll 3/3/2017 11:05 AM Mpeg-2 Video Stream Analysis HKCR\CLSID\{6CFAD761-735D-4AA5-8AFC-AF91A7D61EBA} DirectShow Stream Buffer Filter. Microsoft Corporation 6.6.9600.17415 c:\windows\syswow64\sbe.dll 10/28/2014 9:17 PM Line 21 Decoder HKCR\CLSID\{6E8D4A20-310C-11D0-B79A-00AA003767A7} DirectShow DVD PlayBack Runtime. Microsoft Corporation 6.6.9600.18154 c:\windows\syswow64\qdvd.dll 12/3/2015 1:28 PM Video Port Manager HKCR\CLSID\{6F26A6CD-967B-47FD-874A-7AED2C9D25A2} DirectShow Runtime. Microsoft Corporation 6.6.9600.18617 c:\windows\syswow64\quartz.dll 3/3/2017 11:05 AM Video Renderer HKCR\CLSID\{70E102B0-5556-11CE-97C0-00AA0055595A} DirectShow Runtime. Microsoft Corporation 6.6.9600.18617 c:\windows\syswow64\quartz.dll 3/3/2017 11:05 AM VPS Decoder HKCR\CLSID\{7B3BC2A0-AA50-4ae7-BD44-B03649EC87C2} Microsoft Teletext Server Microsoft Corporation 6.6.9600.17415 c:\windows\syswow64\wstpager.ax 10/28/2014 9:49 PM WM ASF Writer HKCR\CLSID\{7C23220E-55BB-11D3-8B16-00C04FB6BD3D} DirectShow ASF Support Microsoft Corporation 12.0.9600.17415 c:\windows\syswow64\qasf.dll 10/28/2014 9:22 PM VBI Surface Allocator HKCR\CLSID\{814B9800-1C88-11D1-BAD9-00609744111A} VBI Surface Allocator Filter Microsoft Corporation 6.3.9600.17415 c:\windows\syswow64\vbisurf.ax 10/28/2014 9:45 PM File Writer HKCR\CLSID\{8596E5F0-0DA5-11D0-BD21-00A0C911CE86} DirectShow Runtime. Microsoft Corporation 6.6.9600.16384 c:\windows\syswow64\qcap.dll 8/21/2013 11:50 PM iTV Data Sink HKCR\CLSID\{88EBC1EE-F90A-484A-B9C5-8F9C0F37A828} iTV Data Filters. Microsoft Corporation 6.6.9600.16384 c:\windows\syswow64\itvdata.dll 8/21/2013 11:04 PM iTV Data Capture filter HKCR\CLSID\{8A51DC27-5A35-4E02-95A3-428BC6244A3C} iTV Data Filters. Microsoft Corporation 6.6.9600.16384 c:\windows\syswow64\itvdata.dll 8/21/2013 11:04 PM DVD Navigator HKCR\CLSID\{9B8C4620-2C1A-11D0-8493-00A02438AD48} DirectShow DVD PlayBack Runtime. Microsoft Corporation 6.6.9600.18154 c:\windows\syswow64\qdvd.dll 12/3/2015 1:28 PM Overlay Mixer2 HKCR\CLSID\{A0025E90-E45B-11D1-ABE9-00A0C905F375} DirectShow DVD PlayBack Runtime. Microsoft Corporation 6.6.9600.18154 c:\windows\syswow64\qdvd.dll 12/3/2015 1:28 PM AVI Draw Filter HKCR\CLSID\{A888DF60-1E90-11CF-AC98-00AA004C0FA9} DirectShow Runtime. Microsoft Corporation 6.6.9600.18617 c:\windows\syswow64\quartz.dll 3/3/2017 11:05 AM Microsoft MPEG-2 Audio Encoder HKCR\CLSID\{ACD453BC-C58A-44D1-BBF5-BFB325BE2D78} Microsoft MPEG-2 Encoder Microsoft Corporation 12.0.9600.17415 c:\windows\syswow64\msmpeg2enc.dll 10/28/2014 10:11 PM WST Pager HKCR\CLSID\{AD6C8934-F31B-4F43-B5E4-0541C1452F6F} Microsoft Teletext Server Microsoft Corporation 6.6.9600.17415 c:\windows\syswow64\wstpager.ax 10/28/2014 9:49 PM MPEG-2 Demultiplexer HKCR\CLSID\{AFB6C280-2C41-11D3-8A60-0000F81E0E4A} DirectShow MPEG-2 Splitter. Microsoft Corporation 6.6.9600.17415 c:\windows\syswow64\mpg2splt.ax 10/28/2014 9:49 PM DV Video Decoder HKCR\CLSID\{B1B77C00-C3E4-11CF-AF79-00AA00B67A42} DirectShow Runtime. Microsoft Corporation 6.6.9600.17415 c:\windows\syswow64\qdv.dll 10/28/2014 9:46 PM Sample Grabber HKCR\CLSID\{C1F400A0-3F08-11D3-9F0B-006008039E37} DirectShow Editing. Microsoft Corporation 6.6.9600.18152 c:\windows\syswow64\qedit.dll 12/2/2015 11:01 AM Null Renderer HKCR\CLSID\{C1F400A4-3F08-11D3-9F0B-006008039E37} DirectShow Editing. Microsoft Corporation 6.6.9600.18152 c:\windows\syswow64\qedit.dll 12/2/2015 11:01 AM MPEG-2 Sections and Tables HKCR\CLSID\{C666E115-BB62-4027-A113-82D643FE2D99} Microsoft MPEG-2 Section and Table Acquisition Module Microsoft Corporation 6.6.9600.17415 c:\windows\syswow64\mpeg2data.ax 10/28/2014 9:45 PM Microsoft AC3 Encoder HKCR\CLSID\{C6B400E2-20A7-4E58-A2FE-24619682CE6C} Microsoft AC-3 Encoder Microsoft Corporation 6.3.9600.17415 c:\windows\syswow64\msac3enc.dll 10/28/2014 9:30 PM StreamBufferSource HKCR\CLSID\{C9F5FE02-F851-4EB5-99EE-AD602AF1E619} DirectShow Stream Buffer Filter. Microsoft Corporation 6.6.9600.17415 c:\windows\syswow64\sbe.dll 10/28/2014 9:17 PM Smart Tee Filter HKCR\CLSID\{CC58E280-8AA1-11D1-B3F1-00AA003761C5} DirectShow Runtime. Microsoft Corporation 6.6.9600.16384 c:\windows\syswow64\qcap.dll 8/21/2013 11:50 PM Overlay Mixer HKCR\CLSID\{CD8743A1-3736-11D0-9E69-00C04FD7C15B} DirectShow DVD PlayBack Runtime. Microsoft Corporation 6.6.9600.18154 c:\windows\syswow64\qdvd.dll 12/3/2015 1:28 PM AVI Decompressor HKCR\CLSID\{CF49D4E0-1115-11CE-B03A-0020AF0BA770} DirectShow Runtime. Microsoft Corporation 6.6.9600.18617 c:\windows\syswow64\quartz.dll 3/3/2017 11:05 AM AVI/WAV File Source HKCR\CLSID\{D3588AB0-0781-11CE-B03A-0020AF0BA770} DirectShow Runtime. Microsoft Corporation 6.6.9600.18617 c:\windows\syswow64\quartz.dll 3/3/2017 11:05 AM Wave Parser HKCR\CLSID\{D51BD5A1-7548-11CF-A520-0080C77EF58A} DirectShow Runtime. Microsoft Corporation 6.6.9600.18617 c:\windows\syswow64\quartz.dll 3/3/2017 11:05 AM MIDI Parser HKCR\CLSID\{D51BD5A2-7548-11CF-A520-0080C77EF58A} DirectShow Runtime. Microsoft Corporation 6.6.9600.18617 c:\windows\syswow64\quartz.dll 3/3/2017 11:05 AM Multi-file Parser HKCR\CLSID\{D51BD5A3-7548-11CF-A520-0080C77EF58A} DirectShow Runtime. Microsoft Corporation 6.6.9600.18617 c:\windows\syswow64\quartz.dll 3/3/2017 11:05 AM File stream renderer HKCR\CLSID\{D51BD5A5-7548-11CF-A520-0080C77EF58A} DirectShow Runtime. Microsoft Corporation 6.6.9600.18617 c:\windows\syswow64\quartz.dll 3/3/2017 11:05 AM Microsoft DTV-DVD Audio Decoder HKCR\CLSID\{E1F1A0B8-BEEE-490D-BA7C-066C40B5E2B9} Microsoft DTV-DVD Audio Decoder Microsoft Corporation 12.0.9600.18145 c:\windows\syswow64\msmpeg2adec.dll 12/3/2015 11:47 PM SBE2 Sink HKCR\CLSID\{E2448508-95DA-4205-9A27-7EC81E723B1A} DirectShow Stream Buffer Filter. Microsoft Corporation 6.6.9600.17415 c:\windows\syswow64\sbe.dll 10/28/2014 9:17 PM AVI mux HKCR\CLSID\{E2510970-F137-11CE-8B67-00AA00A3F1A6} DirectShow Runtime. Microsoft Corporation 6.6.9600.16384 c:\windows\syswow64\qcap.dll 8/21/2013 11:50 PM Line 21 Decoder 2 HKCR\CLSID\{E4206432-01A1-4BEE-B3E1-3702C8EDC574} DirectShow Runtime. Microsoft Corporation 6.6.9600.18617 c:\windows\syswow64\quartz.dll 3/3/2017 11:05 AM File Source (Async.) HKCR\CLSID\{E436EBB5-524F-11CE-9F53-0020AF0BA770} DirectShow Runtime. Microsoft Corporation 6.6.9600.18617 c:\windows\syswow64\quartz.dll 3/3/2017 11:05 AM File Source (URL) HKCR\CLSID\{E436EBB6-524F-11CE-9F53-0020AF0BA770} DirectShow Runtime. Microsoft Corporation 6.6.9600.18617 c:\windows\syswow64\quartz.dll 3/3/2017 11:05 AM Infinite Pin Tee Filter HKCR\CLSID\{F8388A40-D5BB-11D0-BE5A-0080C706568E} DirectShow Runtime. Microsoft Corporation 6.6.9600.16384 c:\windows\syswow64\qcap.dll 8/21/2013 11:50 PM Enhanced Video Renderer HKCR\CLSID\{FA10746C-9B63-4B6C-BC49-FC300EA5F256} Enhanced Video Renderer DLL Microsoft Corporation 6.3.9600.18154 c:\windows\syswow64\evr.dll 12/3/2015 1:28 PM BDA MPEG2 Transport Information Filter HKCR\CLSID\{FC772AB0-0C7F-11D3-8FF2-00A0C9224CF4} Microsoft Transport Information Filter for MPEG2 based networks. Microsoft Corporation 6.6.9600.17415 c:\windows\syswow64\psisrndr.ax 10/28/2014 9:32 PM MPEG Video Codec HKCR\CLSID\{FEB50740-7BEF-11CE-9BD9-0000E202599C} DirectShow Runtime. Microsoft Corporation 6.6.9600.18617 c:\windows\syswow64\quartz.dll 3/3/2017 11:05 AM HKLM\Software\Classes\CLSID\{7ED96837-96F0-4812-B211-F13C24117ED3}\Instance Google SketchUp Thumbnail Provider (FastPictureViewer Codec Pack) HKCR\CLSID\{03223D4D-1B28-4325-9A96-9C5A4C8EA8BC} Google SketchUp Thumbnail Provider Axel Rietschin Software Developments 3.8.0.96 c:\windows\wiccodecs\{a6d092a4-081a-4f0e-9356-da167e87d922}\vector formats\skp thumbnail provider\x86\skpthumbnailprovider.dll 4/26/2015 11:25 PM Adobe XMP-Based PDF Thumbnail Provider (FastPictureViewer Codec Pack) HKCR\CLSID\{11D741B8-DD31-4707-B06A-7A68E3D84884} XMP-Based PDF Thumbnail Provider Axel Rietschin Software Developments 3.8.0.96 c:\windows\wiccodecs\{a6d092a4-081a-4f0e-9356-da167e87d922}\vector formats\xmp-based thumbnail provider\x86\xmpthumbnailproviderpdf.dll 4/26/2015 11:30 PM Fuji Raw Decoder (FastPictureViewer Codec Pack) HKCR\CLSID\{1285CF5C-6BD6-4412-B23E-32EE4189AC7E} Fuji Raw Decoder Axel Rietschin Software Developments 3.8.0.96 c:\windows\wiccodecs\{a6d092a4-081a-4f0e-9356-da167e87d922}\raw formats\fuji\x86\fujicodec.dll 4/26/2015 11:20 PM Adobe Lightroomr Preview Decoder (FastPictureViewer Codec Pack) HKCR\CLSID\{1A493EAC-93D3-4646-B911-4697A475FF4B} Adobe Lightroomr Preview Decoder Axel Rietschin Software Developments 3.8.0.96 c:\windows\wiccodecs\{a6d092a4-081a-4f0e-9356-da167e87d922}\raster formats\lightroom lrprev\x86\lrprevcodec.dll 4/26/2015 11:17 PM Samsung Raw Decoder (FastPictureViewer Codec Pack) HKCR\CLSID\{1DE7F2CB-4958-4b79-9637-EC747E685BDE} Samsung Raw Decoder Axel Rietschin Software Developments 3.8.0.96 c:\windows\wiccodecs\{a6d092a4-081a-4f0e-9356-da167e87d922}\raw formats\samsung\x86\samsungcodec.dll 4/26/2015 11:30 PM Radiance HDR Decoder (FastPictureViewer Codec Pack) HKCR\CLSID\{20EF7B60-CE85-4048-A409-02CB203268EE} Radiance HDR Decoder Axel Rietschin Software Developments 3.8.0.96 c:\windows\wiccodecs\{a6d092a4-081a-4f0e-9356-da167e87d922}\raster formats\radiance hdr\x86\hdrcodec.dll 4/26/2015 11:31 PM PPM Decoder (FastPictureViewer Codec Pack) HKCR\CLSID\{242E582C-66A8-478c-8BCA-0AF9F1D38D39} Netpbm (PNM/PPM/PGM/PBM) Decoder Axel Rietschin Software Developments 3.8.0.96 c:\windows\wiccodecs\{a6d092a4-081a-4f0e-9356-da167e87d922}\raster formats\portable pixmap\x86\ppmcodec.dll 4/26/2015 11:22 PM EXR Decoder (FastPictureViewer Codec Pack) HKCR\CLSID\{29638F0C-042B-4b50-A2D2-8E8E7CA71E4F} OpenEXR Decoder Axel Rietschin Software Developments 3.8.0.96 c:\windows\wiccodecs\{a6d092a4-081a-4f0e-9356-da167e87d922}\raster formats\ilm openexr\x86\exrcodec.dll 4/26/2015 11:28 PM Hasselblad Raw Decoder (FastPictureViewer Codec Pack) HKCR\CLSID\{33AB3A51-9CC1-4CA8-88F5-49BC9B970114} Hasselblad Raw Decoder Axel Rietschin Software Developments 3.8.0.96 c:\windows\wiccodecs\{a6d092a4-081a-4f0e-9356-da167e87d922}\raw formats\hasselblad\x86\hasselbladcodec.dll 4/26/2015 11:21 PM Adobe DNG Decoder (FastPictureViewer Codec Pack) HKCR\CLSID\{35BE9A2F-B182-4bba-A609-4F9031BFE761} Adobe DNG Decoder Axel Rietschin Software Developments 3.8.0.96 c:\windows\wiccodecs\{a6d092a4-081a-4f0e-9356-da167e87d922}\raw formats\adobe\x86\adobecodec.dll 4/26/2015 11:20 PM TGA Decoder (FastPictureViewer Codec Pack) HKCR\CLSID\{3B84C2D7-708C-48ef-8ED7-0C5FC0F030C6} Truevision Targa (TGA) Decoder Axel Rietschin Software Developments 3.8.0.96 c:\windows\wiccodecs\{a6d092a4-081a-4f0e-9356-da167e87d922}\raster formats\truevision targa\x86\tgacodec.dll 4/26/2015 11:17 PM PhotoLine Thumbnail Provider (FastPictureViewer Codec Pack) HKCR\CLSID\{3D619A54-A36D-4F10-8380-B598CA94D916} PhotoLine Thumbnail Provider Axel Rietschin Software Developments 3.8.0.96 c:\windows\wiccodecs\{a6d092a4-081a-4f0e-9356-da167e87d922}\vector formats\pld thumbnail provider\x86\pldthumbnailprovider.dll 4/26/2015 11:26 PM Canon Raw Decoder (FastPictureViewer Codec Pack) HKCR\CLSID\{4C9966E0-7DAF-4670-A5A4-DE2AFF4CDC31} Canon Raw Decoder Axel Rietschin Software Developments 3.8.0.96 c:\windows\wiccodecs\{a6d092a4-081a-4f0e-9356-da167e87d922}\raw formats\canon\x86\canoncodec.dll 4/26/2015 11:20 PM Epson Raw Decoder (FastPictureViewer Codec Pack) HKCR\CLSID\{4C9E55DD-AEA6-4011-A63C-67A3E4FA58FA} Epson Raw Decoder Axel Rietschin Software Developments 3.8.0.96 c:\windows\wiccodecs\{a6d092a4-081a-4f0e-9356-da167e87d922}\raw formats\epson\x86\epsoncodec.dll 4/26/2015 11:23 PM Panasonic Raw Decoder (FastPictureViewer Codec Pack) HKCR\CLSID\{730069ED-7411-487D-9629-0FED4B30A810} Panasonic Raw Decoder Axel Rietschin Software Developments 3.8.0.96 c:\windows\wiccodecs\{a6d092a4-081a-4f0e-9356-da167e87d922}\raw formats\panasonic\x86\panasoniccodec.dll 4/26/2015 11:18 PM Adobe XMP-Based Thumbnail Provider (FastPictureViewer Codec Pack) HKCR\CLSID\{787E3340-6D04-4BF3-BCC2-2AD3630471CE} XMP-Based Thumbnail Provider Axel Rietschin Software Developments 3.8.0.96 c:\windows\wiccodecs\{a6d092a4-081a-4f0e-9356-da167e87d922}\vector formats\xmp-based thumbnail provider\x86\xmpthumbnailprovider.dll 4/26/2015 11:27 PM Nikon Raw Decoder (FastPictureViewer Codec Pack) HKCR\CLSID\{798CB867-4677-420d-8F1B-C2E12A882180} Nikon Raw Decoder Axel Rietschin Software Developments 3.8.0.96 c:\windows\wiccodecs\{a6d092a4-081a-4f0e-9356-da167e87d922}\raw formats\nikon\x86\nikoncodec.dll 4/26/2015 11:21 PM Leica Raw Decoder (FastPictureViewer Codec Pack) HKCR\CLSID\{7E865BF5-4DEA-495C-B690-296869B83753} Leica Raw Decoder Axel Rietschin Software Developments 3.8.0.96 c:\windows\wiccodecs\{a6d092a4-081a-4f0e-9356-da167e87d922}\raw formats\leica\x86\leicacodec.dll 4/26/2015 11:20 PM Sony Raw Decoder (FastPictureViewer Codec Pack) HKCR\CLSID\{82E3DCAD-555E-4FA3-938D-74C0AFFE0C67} Sony Raw Decoder Axel Rietschin Software Developments 3.8.0.96 c:\windows\wiccodecs\{a6d092a4-081a-4f0e-9356-da167e87d922}\raw formats\sony\x86\sonycodec.dll 4/26/2015 11:19 PM JPEG Derivative Handler (FastPictureViewer Codec Pack) HKCR\CLSID\{861F5797-5F25-43e6-9510-527D056BC13C} JPEG Derivative (MPO, JPS) Axel Rietschin Software Developments 3.8.0.96 c:\windows\wiccodecs\{a6d092a4-081a-4f0e-9356-da167e87d922}\raster formats\jpeg\x86\jpgderivative.dll 4/26/2015 11:25 PM Mamiya Raw Decoder (FastPictureViewer Codec Pack) HKCR\CLSID\{8729492D-2F9D-48F6-8EE0-F5C49140296D} Mamiya Raw Decoder Axel Rietschin Software Developments 3.8.0.96 c:\windows\wiccodecs\{a6d092a4-081a-4f0e-9356-da167e87d922}\raw formats\mamiya\x86\mamiyacodec.dll 4/26/2015 11:22 PM Autodesk Maya IFF Decoder (FastPictureViewer Codec Pack) HKCR\CLSID\{92561398-2ED8-42AF-86E2-66FA8E9DC46E} Autodesk Maya IFF Decoder Axel Rietschin Software Developments 3.8.0.96 c:\windows\wiccodecs\{a6d092a4-081a-4f0e-9356-da167e87d922}\raster formats\maya iff\x86\mayacodec.dll 4/26/2015 11:24 PM Minolta Raw Decoder (FastPictureViewer Codec Pack) HKCR\CLSID\{94E0E6A3-1590-42EE-8D28-ACCA2CE955D8} Minolta Raw Decoder Axel Rietschin Software Developments 3.8.0.96 c:\windows\wiccodecs\{a6d092a4-081a-4f0e-9356-da167e87d922}\raw formats\minolta\x86\minoltacodec.dll 4/26/2015 11:19 PM Rawzor Compressed Raw Format Previewer (FastPictureViewer Codec Pack) HKCR\CLSID\{97A98033-9FA1-4e80-A339-59787B43CC89} Rawzor Compressed Raw Format Previewer Axel Rietschin Software Developments 3.8.0.96 c:\windows\wiccodecs\{a6d092a4-081a-4f0e-9356-da167e87d922}\special codecs\rawzor previewer\x86\rawzorcodec.dll 4/26/2015 11:26 PM Pentax Raw Decoder (FastPictureViewer Codec Pack) HKCR\CLSID\{A4E39C16-C86F-451B-8273-471BF5666870} Pentax Raw Decoder Axel Rietschin Software Developments 3.8.0.96 c:\windows\wiccodecs\{a6d092a4-081a-4f0e-9356-da167e87d922}\raw formats\pentax\x86\pentaxcodec.dll 4/26/2015 11:19 PM Sinar Raw Decoder (FastPictureViewer Codec Pack) HKCR\CLSID\{A9173D25-E7F8-4cce-9094-FC486332018D} Sinar Raw Decoder Axel Rietschin Software Developments 3.8.0.96 c:\windows\wiccodecs\{a6d092a4-081a-4f0e-9356-da167e87d922}\raw formats\sinar\x86\sinarcodec.dll 4/26/2015 11:23 PM Kodak Raw Decoder (FastPictureViewer Codec Pack) HKCR\CLSID\{ADE56A16-A02B-4020-B537-914ADC2E07B1} Kodak Raw Decoder Axel Rietschin Software Developments 3.8.0.96 c:\windows\wiccodecs\{a6d092a4-081a-4f0e-9356-da167e87d922}\raw formats\kodak\x86\kodakcodec.dll 4/26/2015 11:22 PM DDS Decoder (FastPictureViewer Codec Pack) HKCR\CLSID\{B67DA794-42D6-4dfe-AE29-0334338228C9} DirectDraw Surface Decoder Axel Rietschin Software Developments 3.8.0.96 c:\windows\wiccodecs\{a6d092a4-081a-4f0e-9356-da167e87d922}\raster formats\directx dds\x86\ddscodec.dll 4/26/2015 11:29 PM Softimage PIC Decoder (FastPictureViewer Codec Pack) HKCR\CLSID\{C514227C-0AF4-44BB-816A-E9483A4302C9} Softimage PIC Decoder Axel Rietschin Software Developments 3.8.0.96 c:\windows\wiccodecs\{a6d092a4-081a-4f0e-9356-da167e87d922}\raster formats\softimage pic\x86\softimagecodec.dll 4/26/2015 11:23 PM Adobe Photoshopr Document Decoder (FastPictureViewer Codec Pack) HKCR\CLSID\{C55AC07F-5B51-486C-811A-750184298D58} Adobe Photoshopr Document Decoder Axel Rietschin Software Developments 3.8.0.96 c:\windows\wiccodecs\{a6d092a4-081a-4f0e-9356-da167e87d922}\raster formats\photoshop psd\x86\psdcodec.dll 4/26/2015 11:18 PM JPEG 2000 Baseline Decoder (FastPictureViewer Codec Pack) HKCR\CLSID\{C7A40493-BF23-4b53-AB2A-4A923B3EE34B} JPEG 2000 Decoder Axel Rietschin Software Developments 3.8.0.96 c:\windows\wiccodecs\{a6d092a4-081a-4f0e-9356-da167e87d922}\raster formats\jpeg 2000\x86\j2kcodec.dll 4/26/2015 11:29 PM Olympus Raw Decoder (FastPictureViewer Codec Pack) HKCR\CLSID\{DCEFAA85-F357-4859-963F-F1BB14F0829C} Olympus Raw Decoder Axel Rietschin Software Developments 3.8.0.96 c:\windows\wiccodecs\{a6d092a4-081a-4f0e-9356-da167e87d922}\raw formats\olympus\x86\olympuscodec.dll 4/26/2015 11:21 PM Sigma X3F Decoder (FastPictureViewer Codec Pack) HKCR\CLSID\{DF13C2F9-509F-4088-A39F-2D4B288B95E1} Sigma X3F Decoder Axel Rietschin Software Developments 3.8.0.96 c:\windows\wiccodecs\{a6d092a4-081a-4f0e-9356-da167e87d922}\raw formats\sigma\x86\sigmacodec.dll 4/26/2015 11:23 PM Valve Texture Format Decoder (FastPictureViewer Codec Pack) HKCR\CLSID\{E14E55A7-29C8-4389-8E5A-3EF964510FCA} Valve Texture Format Decoder Axel Rietschin Software Developments 3.8.0.96 c:\windows\wiccodecs\{a6d092a4-081a-4f0e-9356-da167e87d922}\raster formats\valve texture format\x86\vtfcodec.dll 4/26/2015 11:25 PM Silicon Graphics RGB Decoder (FastPictureViewer Codec Pack) HKCR\CLSID\{F5E30566-7C8F-4037-A8FF-A7382E251C56} Silicon Graphics RGB Decoder Axel Rietschin Software Developments 3.8.0.96 c:\windows\wiccodecs\{a6d092a4-081a-4f0e-9356-da167e87d922}\raster formats\silicon graphics rgb\x86\silicongraphicscodec.dll 4/26/2015 11:24 PM [DISABLED] {5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0} HKCR\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0} Microsoft Camera Codec Pack Microsoft Corporation 6.3.9600.17388 c:\program files\common files\microsoft shared\microsoft camera codec pack\microsoftrawcodec.dll 10/2/2014 1:06 AM HKLM\Software\Wow6432Node\Classes\CLSID\{7ED96837-96F0-4812-B211-F13C24117ED3}\Instance Google SketchUp Thumbnail Provider (FastPictureViewer Codec Pack) HKCR\CLSID\{03223D4D-1B28-4325-9A96-9C5A4C8EA8BC} Google SketchUp Thumbnail Provider Axel Rietschin Software Developments 3.8.0.96 c:\windows\wiccodecs\{a6d092a4-081a-4f0e-9356-da167e87d922}\vector formats\skp thumbnail provider\x86\skpthumbnailprovider.dll 4/26/2015 11:25 PM Adobe XMP-Based PDF Thumbnail Provider (FastPictureViewer Codec Pack) HKCR\CLSID\{11D741B8-DD31-4707-B06A-7A68E3D84884} XMP-Based PDF Thumbnail Provider Axel Rietschin Software Developments 3.8.0.96 c:\windows\wiccodecs\{a6d092a4-081a-4f0e-9356-da167e87d922}\vector formats\xmp-based thumbnail provider\x86\xmpthumbnailproviderpdf.dll 4/26/2015 11:30 PM Fuji Raw Decoder (FastPictureViewer Codec Pack) HKCR\CLSID\{1285CF5C-6BD6-4412-B23E-32EE4189AC7E} Fuji Raw Decoder Axel Rietschin Software Developments 3.8.0.96 c:\windows\wiccodecs\{a6d092a4-081a-4f0e-9356-da167e87d922}\raw formats\fuji\x86\fujicodec.dll 4/26/2015 11:20 PM Adobe Lightroomr Preview Decoder (FastPictureViewer Codec Pack) HKCR\CLSID\{1A493EAC-93D3-4646-B911-4697A475FF4B} Adobe Lightroomr Preview Decoder Axel Rietschin Software Developments 3.8.0.96 c:\windows\wiccodecs\{a6d092a4-081a-4f0e-9356-da167e87d922}\raster formats\lightroom lrprev\x86\lrprevcodec.dll 4/26/2015 11:17 PM Samsung Raw Decoder (FastPictureViewer Codec Pack) HKCR\CLSID\{1DE7F2CB-4958-4b79-9637-EC747E685BDE} Samsung Raw Decoder Axel Rietschin Software Developments 3.8.0.96 c:\windows\wiccodecs\{a6d092a4-081a-4f0e-9356-da167e87d922}\raw formats\samsung\x86\samsungcodec.dll 4/26/2015 11:30 PM Radiance HDR Decoder (FastPictureViewer Codec Pack) HKCR\CLSID\{20EF7B60-CE85-4048-A409-02CB203268EE} Radiance HDR Decoder Axel Rietschin Software Developments 3.8.0.96 c:\windows\wiccodecs\{a6d092a4-081a-4f0e-9356-da167e87d922}\raster formats\radiance hdr\x86\hdrcodec.dll 4/26/2015 11:31 PM PPM Decoder (FastPictureViewer Codec Pack) HKCR\CLSID\{242E582C-66A8-478c-8BCA-0AF9F1D38D39} Netpbm (PNM/PPM/PGM/PBM) Decoder Axel Rietschin Software Developments 3.8.0.96 c:\windows\wiccodecs\{a6d092a4-081a-4f0e-9356-da167e87d922}\raster formats\portable pixmap\x86\ppmcodec.dll 4/26/2015 11:22 PM EXR Decoder (FastPictureViewer Codec Pack) HKCR\CLSID\{29638F0C-042B-4b50-A2D2-8E8E7CA71E4F} OpenEXR Decoder Axel Rietschin Software Developments 3.8.0.96 c:\windows\wiccodecs\{a6d092a4-081a-4f0e-9356-da167e87d922}\raster formats\ilm openexr\x86\exrcodec.dll 4/26/2015 11:28 PM Hasselblad Raw Decoder (FastPictureViewer Codec Pack) HKCR\CLSID\{33AB3A51-9CC1-4CA8-88F5-49BC9B970114} Hasselblad Raw Decoder Axel Rietschin Software Developments 3.8.0.96 c:\windows\wiccodecs\{a6d092a4-081a-4f0e-9356-da167e87d922}\raw formats\hasselblad\x86\hasselbladcodec.dll 4/26/2015 11:21 PM Adobe DNG Decoder (FastPictureViewer Codec Pack) HKCR\CLSID\{35BE9A2F-B182-4bba-A609-4F9031BFE761} Adobe DNG Decoder Axel Rietschin Software Developments 3.8.0.96 c:\windows\wiccodecs\{a6d092a4-081a-4f0e-9356-da167e87d922}\raw formats\adobe\x86\adobecodec.dll 4/26/2015 11:20 PM TGA Decoder (FastPictureViewer Codec Pack) HKCR\CLSID\{3B84C2D7-708C-48ef-8ED7-0C5FC0F030C6} Truevision Targa (TGA) Decoder Axel Rietschin Software Developments 3.8.0.96 c:\windows\wiccodecs\{a6d092a4-081a-4f0e-9356-da167e87d922}\raster formats\truevision targa\x86\tgacodec.dll 4/26/2015 11:17 PM PhotoLine Thumbnail Provider (FastPictureViewer Codec Pack) HKCR\CLSID\{3D619A54-A36D-4F10-8380-B598CA94D916} PhotoLine Thumbnail Provider Axel Rietschin Software Developments 3.8.0.96 c:\windows\wiccodecs\{a6d092a4-081a-4f0e-9356-da167e87d922}\vector formats\pld thumbnail provider\x86\pldthumbnailprovider.dll 4/26/2015 11:26 PM Canon Raw Decoder (FastPictureViewer Codec Pack) HKCR\CLSID\{4C9966E0-7DAF-4670-A5A4-DE2AFF4CDC31} Canon Raw Decoder Axel Rietschin Software Developments 3.8.0.96 c:\windows\wiccodecs\{a6d092a4-081a-4f0e-9356-da167e87d922}\raw formats\canon\x86\canoncodec.dll 4/26/2015 11:20 PM Epson Raw Decoder (FastPictureViewer Codec Pack) HKCR\CLSID\{4C9E55DD-AEA6-4011-A63C-67A3E4FA58FA} Epson Raw Decoder Axel Rietschin Software Developments 3.8.0.96 c:\windows\wiccodecs\{a6d092a4-081a-4f0e-9356-da167e87d922}\raw formats\epson\x86\epsoncodec.dll 4/26/2015 11:23 PM Panasonic Raw Decoder (FastPictureViewer Codec Pack) HKCR\CLSID\{730069ED-7411-487D-9629-0FED4B30A810} Panasonic Raw Decoder Axel Rietschin Software Developments 3.8.0.96 c:\windows\wiccodecs\{a6d092a4-081a-4f0e-9356-da167e87d922}\raw formats\panasonic\x86\panasoniccodec.dll 4/26/2015 11:18 PM Adobe XMP-Based Thumbnail Provider (FastPictureViewer Codec Pack) HKCR\CLSID\{787E3340-6D04-4BF3-BCC2-2AD3630471CE} XMP-Based Thumbnail Provider Axel Rietschin Software Developments 3.8.0.96 c:\windows\wiccodecs\{a6d092a4-081a-4f0e-9356-da167e87d922}\vector formats\xmp-based thumbnail provider\x86\xmpthumbnailprovider.dll 4/26/2015 11:27 PM Nikon Raw Decoder (FastPictureViewer Codec Pack) HKCR\CLSID\{798CB867-4677-420d-8F1B-C2E12A882180} Nikon Raw Decoder Axel Rietschin Software Developments 3.8.0.96 c:\windows\wiccodecs\{a6d092a4-081a-4f0e-9356-da167e87d922}\raw formats\nikon\x86\nikoncodec.dll 4/26/2015 11:21 PM Leica Raw Decoder (FastPictureViewer Codec Pack) HKCR\CLSID\{7E865BF5-4DEA-495C-B690-296869B83753} Leica Raw Decoder Axel Rietschin Software Developments 3.8.0.96 c:\windows\wiccodecs\{a6d092a4-081a-4f0e-9356-da167e87d922}\raw formats\leica\x86\leicacodec.dll 4/26/2015 11:20 PM Sony Raw Decoder (FastPictureViewer Codec Pack) HKCR\CLSID\{82E3DCAD-555E-4FA3-938D-74C0AFFE0C67} Sony Raw Decoder Axel Rietschin Software Developments 3.8.0.96 c:\windows\wiccodecs\{a6d092a4-081a-4f0e-9356-da167e87d922}\raw formats\sony\x86\sonycodec.dll 4/26/2015 11:19 PM JPEG Derivative Handler (FastPictureViewer Codec Pack) HKCR\CLSID\{861F5797-5F25-43e6-9510-527D056BC13C} JPEG Derivative (MPO, JPS) Axel Rietschin Software Developments 3.8.0.96 c:\windows\wiccodecs\{a6d092a4-081a-4f0e-9356-da167e87d922}\raster formats\jpeg\x86\jpgderivative.dll 4/26/2015 11:25 PM Mamiya Raw Decoder (FastPictureViewer Codec Pack) HKCR\CLSID\{8729492D-2F9D-48F6-8EE0-F5C49140296D} Mamiya Raw Decoder Axel Rietschin Software Developments 3.8.0.96 c:\windows\wiccodecs\{a6d092a4-081a-4f0e-9356-da167e87d922}\raw formats\mamiya\x86\mamiyacodec.dll 4/26/2015 11:22 PM Autodesk Maya IFF Decoder (FastPictureViewer Codec Pack) HKCR\CLSID\{92561398-2ED8-42AF-86E2-66FA8E9DC46E} Autodesk Maya IFF Decoder Axel Rietschin Software Developments 3.8.0.96 c:\windows\wiccodecs\{a6d092a4-081a-4f0e-9356-da167e87d922}\raster formats\maya iff\x86\mayacodec.dll 4/26/2015 11:24 PM Minolta Raw Decoder (FastPictureViewer Codec Pack) HKCR\CLSID\{94E0E6A3-1590-42EE-8D28-ACCA2CE955D8} Minolta Raw Decoder Axel Rietschin Software Developments 3.8.0.96 c:\windows\wiccodecs\{a6d092a4-081a-4f0e-9356-da167e87d922}\raw formats\minolta\x86\minoltacodec.dll 4/26/2015 11:19 PM Rawzor Compressed Raw Format Previewer (FastPictureViewer Codec Pack) HKCR\CLSID\{97A98033-9FA1-4e80-A339-59787B43CC89} Rawzor Compressed Raw Format Previewer Axel Rietschin Software Developments 3.8.0.96 c:\windows\wiccodecs\{a6d092a4-081a-4f0e-9356-da167e87d922}\special codecs\rawzor previewer\x86\rawzorcodec.dll 4/26/2015 11:26 PM Pentax Raw Decoder (FastPictureViewer Codec Pack) HKCR\CLSID\{A4E39C16-C86F-451B-8273-471BF5666870} Pentax Raw Decoder Axel Rietschin Software Developments 3.8.0.96 c:\windows\wiccodecs\{a6d092a4-081a-4f0e-9356-da167e87d922}\raw formats\pentax\x86\pentaxcodec.dll 4/26/2015 11:19 PM Sinar Raw Decoder (FastPictureViewer Codec Pack) HKCR\CLSID\{A9173D25-E7F8-4cce-9094-FC486332018D} Sinar Raw Decoder Axel Rietschin Software Developments 3.8.0.96 c:\windows\wiccodecs\{a6d092a4-081a-4f0e-9356-da167e87d922}\raw formats\sinar\x86\sinarcodec.dll 4/26/2015 11:23 PM Kodak Raw Decoder (FastPictureViewer Codec Pack) HKCR\CLSID\{ADE56A16-A02B-4020-B537-914ADC2E07B1} Kodak Raw Decoder Axel Rietschin Software Developments 3.8.0.96 c:\windows\wiccodecs\{a6d092a4-081a-4f0e-9356-da167e87d922}\raw formats\kodak\x86\kodakcodec.dll 4/26/2015 11:22 PM DDS Decoder (FastPictureViewer Codec Pack) HKCR\CLSID\{B67DA794-42D6-4dfe-AE29-0334338228C9} DirectDraw Surface Decoder Axel Rietschin Software Developments 3.8.0.96 c:\windows\wiccodecs\{a6d092a4-081a-4f0e-9356-da167e87d922}\raster formats\directx dds\x86\ddscodec.dll 4/26/2015 11:29 PM Softimage PIC Decoder (FastPictureViewer Codec Pack) HKCR\CLSID\{C514227C-0AF4-44BB-816A-E9483A4302C9} Softimage PIC Decoder Axel Rietschin Software Developments 3.8.0.96 c:\windows\wiccodecs\{a6d092a4-081a-4f0e-9356-da167e87d922}\raster formats\softimage pic\x86\softimagecodec.dll 4/26/2015 11:23 PM Adobe Photoshopr Document Decoder (FastPictureViewer Codec Pack) HKCR\CLSID\{C55AC07F-5B51-486C-811A-750184298D58} Adobe Photoshopr Document Decoder Axel Rietschin Software Developments 3.8.0.96 c:\windows\wiccodecs\{a6d092a4-081a-4f0e-9356-da167e87d922}\raster formats\photoshop psd\x86\psdcodec.dll 4/26/2015 11:18 PM JPEG 2000 Baseline Decoder (FastPictureViewer Codec Pack) HKCR\CLSID\{C7A40493-BF23-4b53-AB2A-4A923B3EE34B} JPEG 2000 Decoder Axel Rietschin Software Developments 3.8.0.96 c:\windows\wiccodecs\{a6d092a4-081a-4f0e-9356-da167e87d922}\raster formats\jpeg 2000\x86\j2kcodec.dll 4/26/2015 11:29 PM Olympus Raw Decoder (FastPictureViewer Codec Pack) HKCR\CLSID\{DCEFAA85-F357-4859-963F-F1BB14F0829C} Olympus Raw Decoder Axel Rietschin Software Developments 3.8.0.96 c:\windows\wiccodecs\{a6d092a4-081a-4f0e-9356-da167e87d922}\raw formats\olympus\x86\olympuscodec.dll 4/26/2015 11:21 PM Sigma X3F Decoder (FastPictureViewer Codec Pack) HKCR\CLSID\{DF13C2F9-509F-4088-A39F-2D4B288B95E1} Sigma X3F Decoder Axel Rietschin Software Developments 3.8.0.96 c:\windows\wiccodecs\{a6d092a4-081a-4f0e-9356-da167e87d922}\raw formats\sigma\x86\sigmacodec.dll 4/26/2015 11:23 PM Valve Texture Format Decoder (FastPictureViewer Codec Pack) HKCR\CLSID\{E14E55A7-29C8-4389-8E5A-3EF964510FCA} Valve Texture Format Decoder Axel Rietschin Software Developments 3.8.0.96 c:\windows\wiccodecs\{a6d092a4-081a-4f0e-9356-da167e87d922}\raster formats\valve texture format\x86\vtfcodec.dll 4/26/2015 11:25 PM Silicon Graphics RGB Decoder (FastPictureViewer Codec Pack) HKCR\CLSID\{F5E30566-7C8F-4037-A8FF-A7382E251C56} Silicon Graphics RGB Decoder Axel Rietschin Software Developments 3.8.0.96 c:\windows\wiccodecs\{a6d092a4-081a-4f0e-9356-da167e87d922}\raster formats\silicon graphics rgb\x86\silicongraphicscodec.dll 4/26/2015 11:24 PM [DISABLED] Photoshop Codec HKCR\CLSID\{19F703E2-8ED8-4677-8474-A6E66E439B71} PSDCodec Microsoft Corporation 4.0.405.0 c:\program files (x86)\microsoft visual studio 12.0\blend\imaging\psdcodec.dll 12/6/2012 1:56 PM [DISABLED] {5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0} HKCR\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0} Microsoft Camera Codec Pack Microsoft Corporation 6.3.9600.17388 c:\program files (x86)\common files\microsoft shared\microsoft camera codec pack\microsoftrawcodec.dll 10/2/2014 12:34 AM HKCU\Software\Microsoft\Office\Outlook\Addins [DISABLED] Access COM Addin for Outlook HKCR\CLSID\{5B7AB748-6D2E-4827-90A5-32B426DC61B7} Access Outlook Data Collection Addin Microsoft Corporation 14.0.7162.5000 c:\program files\microsoft office\office14\addins\accolk.dll 10/14/2015 10:37 AM [DISABLED] Acrobat PDFMaker Office COM Addin HKCR\CLSID\{9177B23F-7D46-11D6-B816-00C04FC06913} PDFMOutlook Addin Module Adobe Systems Incorporated 15.7.20033.2203 c:\program files (x86)\adobe\acrobat dc\pdfmaker\mail\outlook\x64\pdfmoutlookaddin.dll 3/17/2015 2:12 AM HKCU\Control Panel\Desktop\Scrnsave.exe C:\Windows\system32\Ribbons.scr C:\Windows\system32\Ribbons.scr Ribbons Screen Saver Microsoft Corporation 6.3.9600.17415 c:\windows\system32\ribbons.scr 10/28/2014 10:25 PM HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run TortoiseSVN Monitor C:\Program Files\TortoiseSVN\bin\TortoiseProc.exe /tray TortoiseSVN client http://tortoisesvn.net 1.9.5.27581 c:\program files\tortoisesvn\bin\tortoiseproc.exe 11/26/2016 9:30 AM Skype "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun Skype Skype Technologies S.A. 7.35.0.103 c:\program files (x86)\skype\phone\skype.exe 5/4/2017 9:42 PM [DISABLED] Power2GoExpress9 "C:\Program Files (x86)\CyberLink\Power2Go9\Power2GoExpress9.exe" /Startup Power2Go Desktop Burning Gadget CyberLink Corp. 9.0.1002.0 c:\program files (x86)\cyberlink\power2go9\power2goexpress9.exe 10/2/2013 4:50 AM [DISABLED] HP ENVY 120 series (NET) "C:\Program Files\HP\HP ENVY 120 series\Bin\ScanToPCActivationApp.exe" -deviceID "CN2AR1H14P05VT:NW" -scfn "HP ENVY 120 series (NET)" -AutoStart 1 ScanToPCActivationApp Hewlett-Packard Co. 28.0.1315.0 c:\program files\hp\hp envy 120 series\bin\scantopcactivationapp.exe 10/17/2012 7:29 AM C:\Users\NoelC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup Clock.lnk C:\Users\NoelC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Clock.lnk Clock Applet Microsoft Corporation 4.0.1381.164 c:\bin\clock32.exe 2/22/1999 10:37 PM Outlook Password Workaround.lnk C:\Users\NoelC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Outlook Password Workaround.lnk OutlookPasswordWorkaround ProDigital Software 1.0.0.0 c:\common\outlookpasswordworkaround.exe 8/14/2013 12:09 PM ShellFolderFix.lnk C:\Users\NoelC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ShellFolderFix.lnk Manages explorer folder window sizes and positions 1.1.4.0 c:\program files\shellfolderfix\shellfolderfixui.exe 9/28/2010 12:52 PM [DISABLED] Adobe Gamma.lnk C:\Users\NoelC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\AutorunsDisabled\Adobe Gamma.lnk Adobe Gamma Loader Adobe Systems, Inc. 1.0.0.1 c:\program files (x86)\common files\adobe\calibration\adobe gamma loader.exe 11/4/1999 6:06 PM HKCU\Software\Microsoft\Internet Explorer\UrlSearchHooks Microsoft Url Search Hook HKCR\CLSID\{CFBFAE00-17A6-11D0-99CB-00C04FD64497} Internet Browser Microsoft Corporation 11.0.9600.18639 c:\windows\system32\ieframe.dll 3/25/2017 12:26 PM -------------------------------------------------------------------------------------------