PC constantly hanging, help please folks :)

  • Hi there and welcome to PC Help Forum (PCHF), a more effective way to get the Tech Support you need!
    We have Experts in all areas of Tech, including Malware Removal, Crash Fixing and BSOD's , Microsoft Windows, Computer DIY and PC Hardware, Networking, Gaming, Tablets and iPads, General and Specific Software Support and so much more.

    Why not Click Here To Sign Up and start enjoying great FREE Tech Support.

    This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.
  • Hello everyone We want to personally apologize to everyone for the downtime that we've experienced. We are working to get everything back up as quickly as possible. Due to the issues we've had, your password will need to be reset. Please click the button that says "Forgot Your Password" and change it. We are working to have things back to normal. Emails are fixed and should now send properly. Thank you all for your patience. Thanks, PCHF Management
Status
Not open for further replies.

Stee41*

PCHF Member
Dec 17, 2021
15
0
63
Acer Aspire XC 1600
12GB RAM
Windows 11 home
Intel i3 3.7GHz
150mb internet service via ethernet cable

This PC is only a couple of months old and it constantly hangs for maybe 30 seconds each time, it is my wifes office PC which obviously causes her frustrations while working.

I tried 2 fresh installs on WIN 10 but it never helped so upgraded to WIN 11 but the issue is still there.

it has been defragged and cleaned up several times but nothing helps, can anyone give me some clue what to do as the PC is pretty useless as it is?

Thanks everyone
Stee ;)
 
Download then run Speccy (free) and post the resultant url for us, details here, this will provide us with information about your computer hardware + any software that you have installed that may explain the present issue/s.

To publish a Speccy profile to the Web:

In Speccy, click File, and then click Publish Snapshot.

In the Publish Snapshot dialog box, click Yes to enable Speccy to proceed.

Speccy publishes the profile and displays a second Publish Snapshot. You can open the URL in your default browser, copy it to the clipboard, or close the dialog box.
 
See a couple of problems straight away;

Windows Defender
Windows Defender: Enabled
Firewall
Firewall: Enabled
Display Name: Norton Security Ultra
Antivirus
Windows Defender
Antivirus: Enabled

Virus Signature Database: Up to date
Norton Security Ultra
Antivirus: Enabled

Virus Signature Database: Up to date

Having more than one AV or Firewall installed on your computer is bad, it will slow down the computer, cause internet connection problems and leave you with no AV protection at all if they cancel each other out as they fight for resources.

Windows 8, 8.1, 10 and 11 come with an improved Windows Defender, it offers the same real-time anti-virus/anti-malware protection as Microsoft Security Essentials. Windows Defender also shares the same malware signature definitions as Microsoft Security Essentials, and Forefront Endpoint Protection. Technically, Microsoft Security Essentials has not been renamed Windows Defender, or combined with it in Windows 8, 8.1 and 10.

If any AV product that you have is a paid for version you should always make sure that you have a copy of the product key kept somewhere safe just in case you ever wish to reinstall it.

Norton uninstall info here

Once Norton has been correctly uninstalled, check to see if Windows Defender has auto enabled and allow it to update and carry out a full scan of your computer.

Running: Advanced SystemCare Service 15

You will not see anything like this recommended on any reputable forum, they are at best a gimmick and at worse a danger to the operating systems registry, it is an old article but the author is still highly respected and tbh Ive not seen it explained better than at the miekiemoes' Blog here

Once both the above have been done, restart, test by using the computer as you normally would, post back with an update when you are ready.
 
Hi

Okay, I have done every stage of your instructions and deleted Advanced system care, I still have the same issue, any ideas please?
 
Can we have a new Speccy url so that we can make sure that Norton has gone.

No rush as I have to head out and may not be around until the morning now.
 
Yes Norton is still there and still causing problems by the looks of it, Norton is not on it`s own when it comes to being a pain to get rid of, Avast among others is also troublesome.

We will concentrate on getting rid of Norton for now but there are other things to address and just so you are aware being a brand name PC you have Acer bloatware installed and that is always a nuisance.

Post an Autoruns log for us, see here

1: Extract the Autoruns Zip file contents to a folder.

2: Double-click the "Autoruns.exe".

3: Click on the "Hide Signed Microsoft and Windows Entries” option.

4: Go to File then to Export As or Save in some versions.

5: Save AutoRuns.txt file to known location like your Desktop > when you click on File > Save you will then get the option to Save as type, click the drop down tab, change it to Text and then click the Save button.

6: Attach to your next reply.


Tutorial here
 
Here you go, thanks again..
[Logon]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System\Shell]
[HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell]
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
+ "CCleaner Smart Cleaning" "CCleaner" "(Verified) Piriform Software Ltd" "C:\Program Files\CCleaner\CCleaner64.exe" "Tue Dec 7 19:06:42 2021" "
+ "Norton Download Manager{NSBU222005-SHPD-FSD52405}" "Norton Download Manager" "(Verified) NortonLifeLock Inc." "C:\Users\Public\Downloads\Norton\{NSBU222005-SHPD-FSD52405}\FSDUI_Custom.exe" "Fri Dec 17 16:35:00 2021" "
+ "OneDrive" "Microsoft OneDrive" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\OneDrive.exe" "Tue Dec 7 07:14:41 2021" "
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx]
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
[HKCU\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
[HKCU\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce]
[HKCU\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnceEx]
[HKCU\Environment\UserInitMprLogonScript]
[HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows\Load]
[HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows\Run]
[HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\RunOnce]
[HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\RunOnceEx]
[HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\Run]
[HKLM\System\CurrentControlSet\Control\Terminal Server\Wds\rdpwd\StartupPrograms]
+ "rdpclip" "RDP Clipboard Monitor" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\rdpclip.exe" "Thu Dec 16 07:56:43 2021" "
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\AppSetup]
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
+ "RtkAudUService" "Realtek HD Audio Universal Service" "(Verified) Realtek Semiconductor Corp." "C:\WINDOWS\System32\DriverStore\FileRepository\realtekservice.inf_amd64_f043f909bedcd504\RtkAudUService64.exe" "Wed Oct 6 20:03:40 2021" "
+ "SecurityHealth" "Windows Security notification icon" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\SecurityHealthSystray.exe" "Thu Dec 16 07:53:16 2021" "
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
+ "msedge_cleanup_{F3017226-FE2A-4295-8BDF-00C3A9A7E4C5}" "Microsoft Edge Installer" "(Verified) Microsoft Corporation" "C:\Program Files (x86)\Microsoft\EdgeWebView\Application\96.0.1054.57\Installer\setup.exe" "Thu Dec 16 17:39:31 2021" "
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\Shell]
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell]
+ "explorer.exe" "Windows Explorer" "(Verified) Microsoft Windows" "C:\WINDOWS\explorer.exe" "Thu Dec 16 07:51:50 2021" "
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\AlternateShell]
+ "cmd.exe" "Windows Command Processor" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\cmd.exe" "Sat Jun 5 13:05:12 2021" "
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\TaskMan]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\UserInit]
+ "C:\Windows\system32\userinit.exe" "Userinit Log-on Application" "(Verified) Microsoft Windows" "C:\Windows\system32\userinit.exe" "Thu Dec 16 07:53:45 2021" "
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\VmApplet]
+ "SystemPropertiesPerformance.exe /pagefile" "Change Computer Performance Settings" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\SystemPropertiesPerformance.exe" "Sat Jun 5 13:05:34 2021" "
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\AlternateShells\AvailableShells]
[HKLM\Environment\UserInitMprLogonScript]
[HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components]
+ "Google Chrome" "Google Chrome Installer" "(Verified) Google LLC" "C:\Program Files\Google\Chrome\Application\96.0.4664.110\Installer\chrmstp.exe" "Wed Dec 15 22:49:20 2021" "
+ "Microsoft Edge" "Microsoft Edge Installer" "(Verified) Microsoft Corporation" "C:\Program Files (x86)\Microsoft\Edge\Application\96.0.1054.57\Installer\setup.exe" "Thu Dec 16 17:39:31 2021" "
+ "Microsoft Windows Media Player" "Microsoft Windows Media Player Setup Utility" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\unregmp2.exe" "Sat Jun 5 02:35:00 2021" "
+ "Microsoft Windows Media Player" "Microsoft Windows Media Player Setup Utility" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\unregmp2.exe" "Sat Jun 5 02:35:00 2021" "
+ "n/a" "Microsoft .NET IE SECURITY REGISTRATION" "(Verified) Microsoft Corporation" "C:\Windows\System32\mscories.dll" "Sat Jun 5 13:06:26 2021" "
+ "Themes Setup" "Windows Theme API" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\themeui.dll" "Thu Dec 16 07:52:59 2021" "
+ "Web Platform Customizations" "IE Per-User Initialisation Utility" "(Verified) Microsoft Windows" "C:\Windows\System32\ie4uinit.exe" "Thu Dec 16 07:56:33 2021" "
+ "Windows Desktop Update" "Windows Shell Common Dll" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\shell32.dll" "Thu Dec 16 07:54:27 2021" "
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows\IconServiceLib]
+ "IconCodecService.dll" "Converts a PNG part of the icon to a legacy bmp icon" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\IconCodecService.dll" "Sat Jun 5 13:05:29 2021" "
[HKLM\SOFTWARE\Microsoft\Windows CE Services\AutoStartOnConnect]
[HKLM\SOFTWARE\Microsoft\Windows CE Services\AutoStartDisconnect]
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
+ "msedge_cleanup_{F3017226-FE2A-4295-8BDF-00C3A9A7E4C5}" "Microsoft Edge Installer" "(Verified) Microsoft Corporation" "C:\Program Files (x86)\Microsoft\EdgeWebView\Application\96.0.1054.57\Installer\setup.exe" "Thu Dec 16 17:39:31 2021" "
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce]
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnceEx]
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Active Setup\Installed Components]
+ "Microsoft Windows Media Player" "Microsoft Windows Media Player Setup Utility" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\unregmp2.exe" "Sat Jun 5 01:03:00 2021" "
+ "Microsoft Windows Media Player" "Microsoft Windows Media Player Setup Utility" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\unregmp2.exe" "Sat Jun 5 01:03:00 2021" "
+ "n/a" "Microsoft .NET IE SECURITY REGISTRATION" "(Verified) Microsoft Corporation" "C:\Windows\System32\mscories.dll" "Sat Jun 5 13:06:26 2021" "
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows CE Services\AutoStartOnConnect]
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows CE Services\AutoStartOnDisconnect]
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\RunOnce]
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\RunOnceEx]
[HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp\InitialProgram]
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
[C:\Users\chris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup]
[C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup]
[%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup]
[HKCU\Software\Policies\Microsoft\Windows\System\Scripts\Logon]
[HKCU\Software\Policies\Microsoft\Windows\System\Scripts\Logoff]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Startup]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Logon]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Logoff]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Shutdown]
[HKLM\Software\Policies\Microsoft\Windows\System\Scripts\Startup]
[HKLM\Software\Policies\Microsoft\Windows\System\Scripts\Logon]
[HKLM\Software\Policies\Microsoft\Windows\System\Scripts\Logoff]
[HKLM\Software\Policies\Microsoft\Windows\System\Scripts\Shutdown]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Shutdown]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Logoff]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Logon]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Startup]
[Explorer]
[HKCU\SOFTWARE\Classes\Protocols\Filter]
[HKCU\SOFTWARE\Classes\Protocols\Handler]
[HKCU\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components]
[HKCU\Software\Classes\*\ShellEx\ContextMenuHandlers]
[HKCU\Software\Classes\Drive\ShellEx\ContextMenuHandlers]
[HKCU\Software\Classes\*\ShellEx\PropertySheetHandlers]
[HKCU\Software\Classes\AllFileSystemObjects\ShellEx\ContextMenuHandlers]
[HKCU\Software\Classes\AllFileSystemObjects\ShellEx\DragDropHandlers]
[HKCU\Software\Classes\AllFileSystemObjects\ShellEx\PropertySheetHandlers]
[HKCU\Software\Classes\Directory\ShellEx\ContextMenuHandlers]
[HKCU\Software\Classes\Directory\ShellEx\DragDropHandlers]
[HKCU\Software\Classes\Directory\ShellEx\PropertySheetHandlers]
[HKCU\Software\Classes\Directory\ShellEx\CopyHookHandlers]
[HKCU\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers]
[HKCU\Software\Classes\Folder\ShellEx\ContextMenuHandlers]
[HKCU\Software\Classes\Folder\ShellEx\DragDropHandlers]
[HKCU\Software\Classes\Folder\ShellEx\PropertySheetHandlers]
[HKCU\Software\Classes\Folder\ShellEx\ColumnHandlers]
[HKCU\Software\Classes\Folder\ShellEx\ExtShellFolderViews]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers]
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
[HKCU\Software\Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\InProcServer32]
[HKCU\Software\Microsoft\Ctf\LangBarAddin]
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellServiceObjects]
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellServiceObjects]
+ "Published Items Shell Service Object" "Windows Shell Common Dll" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\shell32.dll" "Thu Dec 16 07:54:27 2021" "
+ "Microsoft VolumeControlService Class" "SCA Volume" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\SndVolSSO.dll" "Thu Dec 16 07:53:36 2021" "
+ "Windows To Go Shell Service Object" "Windows To Go Shell Service Object" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\pwsso.dll" "Sat Jun 5 13:06:10 2021" "
+ "Device Stage Shell Extension" "Device Stage Shell Extension" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\dxp.dll" "Sat Jun 5 13:06:05 2021" "
+ "Cloud Cache Invalidator SSO" "Cloud Data Store" "(Verified) Microsoft Windows" "C:\Windows\System32\Windows.CloudStore.dll" "Thu Dec 16 07:52:04 2021" "
+ "UnexpectedShutdownReason" "Systray shell service object" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\stobject.dll" "Thu Dec 16 07:51:51 2021" "
+ "PostBootReminder object" "Windows Shell Common Dll" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\shell32.dll" "Thu Dec 16 07:54:27 2021" "
+ "OneDrive network states cache SSO" "Windows.FileExplorer.Common" "(Verified) Microsoft Windows" "C:\Windows\System32\Windows.FileExplorer.Common.dll" "Thu Dec 16 07:54:27 2021" "
+ "Library Group Policy Shell Service Object" "Microsoft WinRT Storage API" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\windows.storage.dll" "Thu Dec 16 07:52:34 2021" "
+ "Windows System Reset SSO" "Windows System Reset Platform SSO" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\SystemResetPlatform\SystemResetSSO.dll" "Sat Jun 5 13:06:11 2021" "
+ "User Account Control Check Service" "Security and Maintenance Providers" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\hcproviders.dll" "Sat Jun 5 13:05:29 2021" "
+ "WPDShServiceObj Class" "Windows Portable Device Shell Service Object" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wpdshserviceobj.dll" "Sat Jun 5 18:16:58 2021" "
+ "Network Tray SSO" "Network System Icon" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\pnidui.dll" "Thu Dec 16 07:54:50 2021" "
+ "Windows Search Shell Service Object" "Indexing Options" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\srchadmin.dll" "Sat Jun 5 13:05:40 2021" "
+ "WebCheck" "Shell Doc Object and Control Library" "(Verified) Microsoft Windows" "C:\Windows\System32\shdocvw.dll" "Thu Dec 16 07:54:26 2021" "
+ "Bluetooth Authentication Agent SSO" "Bluetooth Control Panel Applet" "(Verified) Microsoft Windows" "C:\Windows\System32\bthprops.cpl" "Sat Jun 5 13:05:23 2021" "
+ "Sync Center Shell Service Object (Internal)" "Microsoft Sync Centre" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\SyncCenter.dll" "Sat Jun 5 13:06:11 2021" "
+ "Security and Maintenance Shell Service Object" "Security and Maintenance" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Actioncenter.dll" "Sat Jun 5 13:05:29 2021" "
+ "ShellFolder for CD Burning" "Windows Shell Common Dll" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\shell32.dll" "Thu Dec 16 07:54:27 2021" "
+ "HomeGroup SSO" "HomeGroup Control Panel" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\hgcpl.dll" "Sat Jun 5 13:05:29 2021" "
[HKLM\SOFTWARE\Classes\Protocols\Filter]
+ "application/octet-stream" "Microsoft .NET Runtime Execution Engine" "(Verified) Microsoft Windows" "C:\Windows\System32\mscoree.dll" "Sat Jun 5 13:06:26 2021" "
+ "application/x-complus" "Microsoft .NET Runtime Execution Engine" "(Verified) Microsoft Windows" "C:\Windows\System32\mscoree.dll" "Sat Jun 5 13:06:26 2021" "
+ "application/x-msdownload" "Microsoft .NET Runtime Execution Engine" "(Verified) Microsoft Windows" "C:\Windows\System32\mscoree.dll" "Sat Jun 5 13:06:26 2021" "
+ "text/xml" "Microsoft Office XML MIME Filter" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\MSOXMLMF.DLL" "Fri Dec 10 12:44:05 2021" "
[HKLM\SOFTWARE\Classes\Protocols\Handler]
+ "about" "Microsoft (R) HTML Viewer" "(Verified) Microsoft Windows" "C:\Windows\System32\mshtml.dll" "Thu Dec 16 07:56:36 2021" "
+ "cdl" "OLE32 Extensions for Win32" "(Verified) Microsoft Windows" "C:\Windows\System32\urlmon.dll" "Thu Dec 16 07:54:22 2021" "
+ "dvd" "ActiveX control for streaming video" "(Verified) Microsoft Windows" "C:\Windows\System32\msvidctl.dll" "Sat Jun 5 13:06:14 2021" "
+ "file" "OLE32 Extensions for Win32" "(Verified) Microsoft Windows" "C:\Windows\System32\urlmon.dll" "Thu Dec 16 07:54:22 2021" "
+ "ftp" "OLE32 Extensions for Win32" "(Verified) Microsoft Windows" "C:\Windows\System32\urlmon.dll" "Thu Dec 16 07:54:22 2021" "
+ "http" "OLE32 Extensions for Win32" "(Verified) Microsoft Windows" "C:\Windows\System32\urlmon.dll" "Thu Dec 16 07:54:22 2021" "
+ "https" "OLE32 Extensions for Win32" "(Verified) Microsoft Windows" "C:\Windows\System32\urlmon.dll" "Thu Dec 16 07:54:22 2021" "
+ "its" "Microsoft® InfoTech Storage System Library" "(Verified) Microsoft Windows" "C:\Windows\System32\itss.dll" "Sat Jun 5 13:06:05 2021" "
+ "javascript" "Microsoft (R) HTML Viewer" "(Verified) Microsoft Windows" "C:\Windows\System32\mshtml.dll" "Thu Dec 16 07:56:36 2021" "
+ "local" "OLE32 Extensions for Win32" "(Verified) Microsoft Windows" "C:\Windows\System32\urlmon.dll" "Thu Dec 16 07:54:22 2021" "
+ "mailto" "Microsoft (R) HTML Viewer" "(Verified) Microsoft Windows" "C:\Windows\System32\mshtml.dll" "Thu Dec 16 07:56:36 2021" "
+ "mhtml" "Microsoft Internet Messaging API Resources" "(Verified) Microsoft Windows" "C:\Windows\System32\inetcomm.dll" "Sat Jun 5 13:06:07 2021" "
+ "mk" "OLE32 Extensions for Win32" "(Verified) Microsoft Windows" "C:\Windows\System32\urlmon.dll" "Thu Dec 16 07:54:22 2021" "
+ "ms-its" "Microsoft® InfoTech Storage System Library" "(Verified) Microsoft Windows" "C:\Windows\System32\itss.dll" "Sat Jun 5 13:06:05 2021" "
+ "mso-minsb-roaming.16" "Microsoft Office component" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL" "Fri Dec 10 12:41:11 2021" "
+ "mso-minsb.16" "Microsoft Office component" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL" "Fri Dec 10 12:41:11 2021" "
+ "osf-roaming.16" "Microsoft Office component" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL" "Fri Dec 10 12:41:11 2021" "
+ "osf.16" "Microsoft Office component" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL" "Fri Dec 10 12:41:11 2021" "
+ "res" "Microsoft (R) HTML Viewer" "(Verified) Microsoft Windows" "C:\Windows\System32\mshtml.dll" "Thu Dec 16 07:56:36 2021" "
+ "tbauth" "TBAuth protocol handler" "(Verified) Microsoft Windows" "C:\Windows\System32\tbauth.dll" "Thu Dec 16 07:52:14 2021" "
+ "tv" "ActiveX control for streaming video" "(Verified) Microsoft Windows" "C:\Windows\System32\msvidctl.dll" "Sat Jun 5 13:06:14 2021" "
+ "vbscript" "Microsoft (R) HTML Viewer" "(Verified) Microsoft Windows" "C:\Windows\System32\mshtml.dll" "Thu Dec 16 07:56:36 2021" "
+ "windows.tbauth" "TBAuth protocol handler" "(Verified) Microsoft Windows" "C:\Windows\System32\tbauth.dll" "Thu Dec 16 07:52:14 2021" "
[HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers]
+ " FileSyncEx" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ "EPP" "Microsoft Security Client Shell Extension" "(Verified) Microsoft Windows" "C:\Program Files\Windows Defender\shellext.dll" "Sat Jun 5 13:04:55 2021" "
+ "Open With" "Windows Shell Common Dll" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\shell32.dll" "Thu Dec 16 07:54:27 2021" "
+ "Open With EncryptionMenu" "Windows Shell Common Dll" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\shell32.dll" "Thu Dec 16 07:54:27 2021" "
+ "Sharing" "Shell extensions for sharing" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\ntshrui.dll" "Thu Dec 16 07:54:27 2021" "
+ "WorkFolders" "Microsoft (C) Work Folders Shell Extension" "(Verified) Microsoft Windows" "C:\Windows\System32\WorkfoldersShell.dll" "Sat Jun 5 13:06:16 2021" "
+ "Taskband Pin" "Windows Shell Common Dll" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\shell32.dll" "Thu Dec 16 07:54:27 2021" "
+ "Start Menu Pin" "Windows Shell Common Dll" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\shell32.dll" "Thu Dec 16 07:54:27 2021" "
[HKLM\Software\Classes\Drive\ShellEx\ContextMenuHandlers]
+ "EnhancedStorageShell" "Windows Enhanced Storage Shell Extension DLL" "(Verified) Microsoft Windows" "C:\Windows\System32\EhStorShell.dll" "Sat Jun 5 13:05:29 2021" "
+ "EPP" "Microsoft Security Client Shell Extension" "(Verified) Microsoft Windows" "C:\Program Files\Windows Defender\shellext.dll" "Sat Jun 5 13:04:55 2021" "
+ "Sharing" "Shell extensions for sharing" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\ntshrui.dll" "Thu Dec 16 07:54:27 2021" "
+ "Previous Versions Property Page" "Previous Versions property page" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\twext.dll" "Sat Jun 5 13:05:33 2021" "
+ "Portable Devices Menu" "Portable Devices Shell Extension" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wpdshext.dll" "Sat Jun 5 18:16:58 2021" "
+ "ShellFolder for CD Burning" "Windows Shell Common Dll" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\shell32.dll" "Thu Dec 16 07:54:27 2021" "
[HKLM\Software\Classes\*\ShellEx\PropertySheetHandlers]
+ "CryptoSignMenu" "Crypto Shell Extensions" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\cryptext.dll" "Sat Jun 5 13:05:27 2021" "
+ "Security Shell Extension" "Security Shell Extension" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\rshx32.dll" "Sat Jun 5 13:06:02 2021" "
+ "OLE DocFile Property Page" "OLE DocFile Property Page" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\docprop.dll" "Sat Jun 5 13:05:33 2021" "
+ "Summary Properties Page" "Windows Shell Common Dll" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\shell32.dll" "Thu Dec 16 07:54:27 2021" "
[HKLM\Software\Classes\AllFileSystemObjects\ShellEx\ContextMenuHandlers]
+ "CopyAsPathMenu" "Windows Shell Common Dll" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\shell32.dll" "Thu Dec 16 07:54:27 2021" "
+ "ModernSharing" "Shell extensions for sharing" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\ntshrui.dll" "Thu Dec 16 07:54:27 2021" "
+ "SendTo" "Windows Shell Common Dll" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\shell32.dll" "Thu Dec 16 07:54:27 2021" "
+ "Previous Versions Property Page" "Previous Versions property page" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\twext.dll" "Sat Jun 5 13:05:33 2021" "
+ "Start Menu Pin" "Windows Shell Common Dll" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\shell32.dll" "Thu Dec 16 07:54:27 2021" "
[HKLM\Software\Classes\AllFileSystemObjects\ShellEx\DragDropHandlers]
[HKLM\Software\Classes\AllFileSystemObjects\ShellEx\PropertySheetHandlers]
+ "Previous Versions Property Page" "Previous Versions property page" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\twext.dll" "Sat Jun 5 13:05:33 2021" "
[HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers]
+ " FileSyncEx" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ "EncryptionMenu" "Windows Shell Common Dll" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\shell32.dll" "Thu Dec 16 07:54:27 2021" "
+ "EPP" "Microsoft Security Client Shell Extension" "(Verified) Microsoft Windows" "C:\Program Files\Windows Defender\shellext.dll" "Sat Jun 5 13:04:55 2021" "
+ "Sharing" "Shell extensions for sharing" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\ntshrui.dll" "Thu Dec 16 07:54:27 2021" "
+ "WorkFolders" "Microsoft (C) Work Folders Shell Extension" "(Verified) Microsoft Windows" "C:\Windows\System32\WorkfoldersShell.dll" "Sat Jun 5 13:06:16 2021" "
+ "Previous Versions Property Page" "Previous Versions property page" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\twext.dll" "Sat Jun 5 13:05:33 2021" "
[HKLM\Software\Classes\Directory\ShellEx\DragDropHandlers]
[HKLM\Software\Classes\Directory\ShellEx\PropertySheetHandlers]
+ "Sharing" "Shell extensions for sharing" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\ntshrui.dll" "Thu Dec 16 07:54:27 2021" "
+ "Security Shell Extension" "Security Shell Extension" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\rshx32.dll" "Sat Jun 5 13:06:02 2021" "
+ "MyFolder menu and properties" "My Documents Folder UI" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mydocs.dll" "Sat Jun 5 13:05:14 2021" "
+ "Previous Versions Property Page" "Previous Versions property page" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\twext.dll" "Sat Jun 5 13:05:33 2021" "
+ "DfsShell Class" "Distributed File System shell extension" "(Verified) Microsoft Windows" "C:\Windows\System32\DfsShlEx.dll" "Sat Jun 5 13:05:37 2021" "
+ "Folder Customization Tab" "Windows Shell Common Dll" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\shell32.dll" "Thu Dec 16 07:54:27 2021" "
[HKLM\Software\Classes\Directory\ShellEx\CopyHookHandlers]
+ "FileSystem" "Windows Shell Common Dll" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\shell32.dll" "Thu Dec 16 07:54:27 2021" "
+ "Sharing" "Shell extensions for sharing" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\ntshrui.dll" "Thu Dec 16 07:54:27 2021" "
[HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers]
+ " FileSyncEx" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ "New" "Windows Shell Common Dll" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\shell32.dll" "Thu Dec 16 07:54:27 2021" "
+ "Sharing" "Shell extensions for sharing" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\ntshrui.dll" "Thu Dec 16 07:54:27 2021" "
+ "WorkFolders" "Microsoft (C) Work Folders Shell Extension" "(Verified) Microsoft Windows" "C:\Windows\System32\WorkfoldersShell.dll" "Sat Jun 5 13:06:16 2021" "
[HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers]
+ "Library Location" "Windows Shell Common Dll" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\shell32.dll" "Thu Dec 16 07:54:27 2021" "
+ "PintoStartScreen" "App Resolver" "(Verified) Microsoft Windows" "C:\Windows\System32\appresolver.dll" "Thu Dec 16 07:53:11 2021" "
+ "Start Menu Pin" "Windows Shell Common Dll" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\shell32.dll" "Thu Dec 16 07:54:27 2021" "
[HKLM\Software\Classes\Folder\ShellEx\DragDropHandlers]
+ "Compressed (zipped) Folder Right Drag Handler" "Compressed (zipped) Folders" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\zipfldr.dll" "Thu Dec 16 07:53:41 2021" "
[HKLM\Software\Classes\Folder\ShellEx\PropertySheetHandlers]
[HKLM\Software\Classes\Folder\ShellEx\ColumnHandlers]
[HKLM\Software\Classes\Folder\ShellEx\ExtShellFolderViews]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers]
+ " OneDrive1" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ " OneDrive2" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ " OneDrive3" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ " OneDrive4" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ " OneDrive5" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ " OneDrive6" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ " OneDrive7" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ " OneDrive1" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ " OneDrive2" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ " OneDrive3" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ " OneDrive4" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ " OneDrive5" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ " OneDrive6" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ " OneDrive7" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ "EnhancedStorageShell" "Windows Enhanced Storage Shell Extension DLL" "(Verified) Microsoft Windows" "C:\Windows\System32\EhStorShell.dll" "Sat Jun 5 13:05:29 2021" "
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
[HKLM\Software\Microsoft\Ctf\LangBarAddin]
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
[HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellServiceObjects]
+ "Published Items Shell Service Object" "Windows Shell Common Dll" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\shell32.dll" "Thu Dec 16 07:56:19 2021" "
+ "Microsoft VolumeControlService Class" "SCA Volume" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\SndVolSSO.dll" "Thu Dec 16 07:55:56 2021" "
+ "UnexpectedShutdownReason" "Systray shell service object" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\stobject.dll" "Thu Dec 16 07:55:17 2021" "
+ "PostBootReminder object" "Windows Shell Common Dll" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\shell32.dll" "Thu Dec 16 07:56:19 2021" "
+ "OneDrive network states cache SSO" "Windows.FileExplorer.Common" "(Verified) Microsoft Windows" "C:\Windows\Syswow64\Windows.FileExplorer.Common.dll" "Thu Dec 16 07:56:19 2021" "
+ "Library Group Policy Shell Service Object" "Microsoft WinRT Storage API" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\windows.storage.dll" "Thu Dec 16 07:55:47 2021" "
+ "User Account Control Check Service" "Security and Maintenance Providers" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\hcproviders.dll" "Sat Jun 5 13:05:55 2021" "
+ "WPDShServiceObj Class" "Windows Portable Device Shell Service Object" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\wpdshserviceobj.dll" "Sat Jun 5 18:17:05 2021" "
+ "Windows Search Shell Service Object" "Indexing Options" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\srchadmin.dll" "Sat Jun 5 13:06:00 2021" "
+ "WebCheck" "Shell Doc Object and Control Library" "(Verified) Microsoft Windows" "C:\Windows\Syswow64\shdocvw.dll" "Thu Dec 16 07:56:18 2021" "
+ "Bluetooth Authentication Agent SSO" "Bluetooth Control Panel Applet" "(Verified) Microsoft Windows" "C:\Windows\Syswow64\bthprops.cpl" "Sat Jun 5 13:05:53 2021" "
+ "Sync Center Shell Service Object (Internal)" "Microsoft Sync Center" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\SyncCenter.dll" "Sat Jun 5 13:06:24 2021" "
+ "Security and Maintenance Shell Service Object" "Security and Maintenance" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\Actioncenter.dll" "Sat Jun 5 13:05:55 2021" "
+ "ShellFolder for CD Burning" "Windows Shell Common Dll" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\shell32.dll" "Thu Dec 16 07:56:19 2021" "
+ "HomeGroup SSO" "HomeGroup Control Panel" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\hgcpl.dll" "Sat Jun 5 13:05:55 2021" "
[HKLM\Software\Wow6432Node\Classes\*\ShellEx\ContextMenuHandlers]
[HKLM\Software\Wow6432Node\Classes\Drive\ShellEx\ContextMenuHandlers]
[HKLM\Software\Wow6432Node\Classes\*\ShellEx\PropertySheetHandlers]
[HKLM\Software\Wow6432Node\Classes\AllFileSystemObjects\ShellEx\ContextMenuHandlers]
[HKLM\Software\Wow6432Node\Classes\AllFileSystemObjects\ShellEx\DragDropHandlers]
[HKLM\Software\Wow6432Node\Classes\AllFileSystemObjects\ShellEx\PropertySheetHandlers]
[HKLM\Software\Wow6432Node\Classes\Directory\ShellEx\ContextMenuHandlers]
[HKLM\Software\Wow6432Node\Classes\Directory\ShellEx\DragDropHandlers]
[HKLM\Software\Wow6432Node\Classes\Directory\ShellEx\PropertySheetHandlers]
[HKLM\Software\Wow6432Node\Classes\Directory\ShellEx\CopyHookHandlers]
[HKLM\Software\Wow6432Node\Classes\Directory\Background\ShellEx\ContextMenuHandlers]
[HKLM\Software\Wow6432Node\Classes\Folder\ShellEx\ContextMenuHandlers]
[HKLM\Software\Wow6432Node\Classes\Folder\ShellEx\DragDropHandlers]
[HKLM\Software\Wow6432Node\Classes\Folder\ShellEx\PropertySheetHandlers]
[HKLM\Software\Wow6432Node\Classes\Folder\ShellEx\ColumnHandlers]
[HKLM\Software\Wow6432Node\Classes\Folder\ShellEx\ExtShellFolderViews]
[HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers]
+ " OneDrive1" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ " OneDrive2" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ " OneDrive3" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ " OneDrive4" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ " OneDrive5" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ " OneDrive6" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ " OneDrive7" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ " OneDrive1" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ " OneDrive2" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ " OneDrive3" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ " OneDrive4" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ " OneDrive5" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ " OneDrive6" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ " OneDrive7" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
[HKLM\Software\Wow6432Node\Microsoft\Ctf\LangBarAddin]
[Internet Explorer]
[HKCU\Software\Microsoft\Internet Explorer\UrlSearchHooks]
+ "Microsoft Url Search Hook" "Internet Browser" "(Verified) Microsoft Windows" "C:\Windows\System32\ieframe.dll" "Thu Dec 16 07:56:37 2021" "
[HKCU\Software\Microsoft\Internet Explorer\Explorer Bars]
[HKCU\Software\Microsoft\Internet Explorer\Extensions]
[HKCU\Software\Wow6432Node\Microsoft\Internet Explorer\Explorer Bars]
[HKCU\Software\Wow6432Node\Microsoft\Internet Explorer\Extensions]
[HKLM\Software\Microsoft\Internet Explorer\Toolbar]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
+ "IEToEdge BHO" "IEToEdge BHO" "(Verified) Microsoft Corporation" "C:\Program Files (x86)\Microsoft\Edge\Application\96.0.1054.57\BHO\ie_to_edge_bho_64.dll" "Tue Dec 14 03:28:07 2021" "
[HKLM\Software\Microsoft\Internet Explorer\Explorer Bars]
[HKLM\Software\Microsoft\Internet Explorer\Extensions]
+ "OneNote Lin&ked Notes" "Microsoft OneNote Internet Explorer Add-in" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft Office\root\Office16\ONBttnIELinkedNotes.dll" "Fri Dec 10 12:41:14 2021" "
+ "Se&nd to OneNote" "Microsoft OneNote Internet Explorer Add-in" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft Office\root\Office16\ONBttnIE.dll" "Fri Dec 10 12:41:14 2021" "
[HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
[HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
+ "IEToEdge BHO" "IEToEdge BHO" "(Verified) Microsoft Corporation" "C:\Program Files (x86)\Microsoft\Edge\Application\96.0.1054.57\BHO\ie_to_edge_bho.dll" "Tue Dec 14 03:27:52 2021" "
+ "Skype for Business Browser Helper" "Skype for Business" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll" "Mon Nov 1 13:01:20 2021" "
[HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Explorer Bars]
[HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Extensions]
+ "Lync Click to Call" "Skype for Business" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll" "Mon Nov 1 13:01:20 2021" "
+ "OneNote Lin&ked Notes" "Microsoft OneNote Internet Explorer Add-in" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\ONBttnIELinkedNotes.dll" "Fri Dec 10 12:43:31 2021" "
+ "Se&nd to OneNote" "Microsoft OneNote Internet Explorer Add-in" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\ONBttnIE.dll" "Fri Dec 10 12:43:31 2021" "
[Scheduled Tasks]
[Task Scheduler]
+ "\ACCBackgroundApplication" "Acer Care Center background application" "(Verified) Acer Incorporated" "C:\Program Files (x86)\Acer\Care Center\ACCStd.exe" "Wed Nov 17 15:08:30 2021" "
+ "\App Explorer" "Host App Service Updater" "(Verified) SweetLabs Inc." "C:\Users\chris\AppData\Local\Host App Service\Engine\HostAppServiceUpdater.exe" "Mon Nov 15 21:29:44 2021" "
+ "\Christmas Task (One-Time)" "" "" "File not found: C:\Program Files (x86)\IObit\Advanced SystemCare\xmas.exe" "" "
+ "\GoTrust ID Driver" "GoTrust ID Driver" "(Verified) GoTrustID Inc" "C:\Program Files\GoTrust ID Plugin\Resource\GO-Trust_ID_Driver.exe" "Tue Sep 8 09:48:02 2020" "
+ "\OneDrive Per-Machine Standalone Update Task" "Standalone Updater" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe" "Tue Dec 7 07:14:41 2021" "
+ "\OneDrive Reporting Task-S-1-5-21-118655992-338211945-2329846050-1001" "Standalone Updater" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe" "Tue Dec 7 07:14:41 2021" "
+ "\Quick Access" "This task is for Quick Access" "(Verified) Acer Incorporated" "C:\Program Files\Acer\Quick Access Service\QALauncher.exe" "Thu Sep 10 13:58:18 2020" "
+ "\Software Update Application" "Software Updater Scheduler" "(Verified) Acer Incorporated" "C:\ProgramData\OEM\UpgradeTool\ListCheck.exe" "Wed Nov 17 15:08:26 2021" "
+ X "\Agent Activation Runtime\S-1-5-21-118655992-338211945-2329846050-1001" "" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\AgentActivationRuntimeStarter.exe" "Sat Jun 5 13:04:52 2021" "
+ "\Microsoft\Office\Office Automatic Updates 2.0" "This task ensures that your Microsoft Office installation can check for updates." "(Verified) Microsoft Corporation" "C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe" "Thu Dec 2 19:28:12 2021" "
+ "\Microsoft\Office\Office ClickToRun Service Monitor" "This task monitors the state of your Microsoft Office ClickToRunSvc and sends crash and error logs to Microsoft." "(Verified) Microsoft Corporation" "C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe" "Thu Dec 2 19:28:12 2021" "
+ "\Microsoft\Office\Office Feature Updates" "This task ensures that your Microsoft Office installation can check for feature updates." "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe" "Fri Dec 10 12:41:22 2021" "
+ "\Microsoft\Office\Office Feature Updates Logon" "This task ensures that your Microsoft Office installation can check for feature updates." "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe" "Fri Dec 10 12:41:22 2021" "
+ "\Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319" "Microsoft .NET Runtime Execution Engine" "(Verified) Microsoft Windows" "C:\Windows\System32\mscoree.dll" "Sat Jun 5 13:06:26 2021" "
+ "\Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 64" "Microsoft .NET Runtime Execution Engine" "(Verified) Microsoft Windows" "C:\Windows\System32\mscoree.dll" "Sat Jun 5 13:06:26 2021" "
+ X "\Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 64 Critical" "Microsoft .NET Runtime Execution Engine" "(Verified) Microsoft Windows" "C:\Windows\System32\mscoree.dll" "Sat Jun 5 13:06:26 2021" "
+ X "\Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 Critical" "Microsoft .NET Runtime Execution Engine" "(Verified) Microsoft Windows" "C:\Windows\System32\mscoree.dll" "Sat Jun 5 13:06:26 2021" "
+ X "\Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Automated)" "Windows Rights Management client" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\msdrm.dll" "Sat Jun 5 13:04:58 2021" "
+ "\Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Manual)" "Windows Rights Management client" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\msdrm.dll" "Sat Jun 5 13:04:58 2021" "
+ X "\Microsoft\Windows\AppID\PolicyConverter" "Converts the software restriction policies policy from XML into binary format." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\appidpolicyconverter.exe" "Sat Jun 5 13:05:23 2021" "
+ X "\Microsoft\Windows\AppID\VerifiedPublisherCertStoreCheck" "Inspects the AppID certificate cache for invalid or revoked certificates." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\appidcertstorecheck.exe" "Sat Jun 5 13:05:23 2021" "
+ "\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser" "Collects program telemetry information if opted-in to the Microsoft Customer Experience Improvement Program." "(Verified) Microsoft Corporation" "C:\WINDOWS\system32\compattelrunner.exe" "Sat Jun 5 13:05:21 2021" "
+ "\Microsoft\Windows\Application Experience\PcaPatchDbTask" "Updates compatibility database" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\PcaSvc.dll" "Thu Dec 16 07:53:34 2021" "
+ "\Microsoft\Windows\Application Experience\ProgramDataUpdater" "Collects program telemetry information if opted-in to the Microsoft Customer Experience Improvement Program" "(Verified) Microsoft Corporation" "C:\WINDOWS\system32\compattelrunner.exe" "Sat Jun 5 13:05:21 2021" "
+ "\Microsoft\Windows\Application Experience\StartupAppTask" "Scans startup entries and raises notification to the user if there are too many startup entries." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\Startupscan.dll" "Sat Jun 5 13:05:29 2021" "
+ "\Microsoft\Windows\ApplicationData\appuriverifierdaily" "Verifies AppUriHandler host registrations." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\AppHostRegistrationVerifier.exe" "Sat Jun 5 13:05:02 2021" "
+ "\Microsoft\Windows\ApplicationData\appuriverifierinstall" "Verifies AppUriHandler host registrations." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\AppHostRegistrationVerifier.exe" "Sat Jun 5 13:05:02 2021" "
+ "\Microsoft\Windows\ApplicationData\CleanupTemporaryState" "Cleans up each package's unused temporary files." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\Windows.Storage.ApplicationData.dll" "Sat Jun 5 13:05:12 2021" "
+ "\Microsoft\Windows\ApplicationData\DsSvcCleanup" "Performs maintenance for the Data Sharing Service." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\dstokenclean.exe" "Sat Jun 5 13:05:02 2021" "
+ "\Microsoft\Windows\AppListBackup\Backup" "AppListBackupLauncher" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\AppListBackupLauncher.dll" "Thu Dec 16 07:51:30 2021" "
+ X "\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup" "AppX Deployment Client DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\AppxDeploymentClient.dll" "Thu Dec 16 07:52:35 2021" "
+ "\Microsoft\Windows\Autochk\Proxy" "This task collects and uploads autochk SQM data if opted-in to the Microsoft Customer Experience Improvement Program." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\acproxy.dll" "Sat Jun 5 13:06:02 2021" "
+ "\Microsoft\Windows\BitLocker\BitLocker Encrypt All Drives" "EdpTask Task" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\edptask.dll" "Sat Jun 5 13:05:29 2021" "
+ "\Microsoft\Windows\BitLocker\BitLocker MDM policy Refresh" "EdpTask Task" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\edptask.dll" "Sat Jun 5 13:05:29 2021" "
+ "\Microsoft\Windows\Bluetooth\UninstallDeviceTask" "Uninstalls the PnP device associated with the specified Bluetooth service ID" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\BthUdTask.exe" "Sat Jun 5 13:05:23 2021" "
+ "\Microsoft\Windows\capabilityaccessmanager\maintenancetasks" "Capability Access Manager Maintenance Tasks" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\CapabilityAccessManager.dll" "Thu Dec 16 07:52:51 2021" "
+ "\Microsoft\Windows\CertificateServicesClient\UserTask" "DIMS Job DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\dimsjob.dll" "Sat Jun 5 13:06:05 2021" "
+ "\Microsoft\Windows\CertificateServicesClient\UserTask-Roam" "DIMS Job DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\dimsjob.dll" "Sat Jun 5 13:06:05 2021" "
+ "\Microsoft\Windows\Chkdsk\ProactiveScan" "pstask Task" "(Verified) Microsoft Windows" "C:\Windows\System32\pstask.dll" "Sat Jun 5 13:06:15 2021" "
+ "\Microsoft\Windows\Chkdsk\SyspartRepair" "Bcdboot utility" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\bcdboot.exe" "Thu Dec 16 07:51:37 2021" "
+ "\Microsoft\Windows\CloudExperienceHost\CreateObjectTask" "CloudExperienceHost Broker" "(Verified) Microsoft Windows" "C:\Windows\System32\CloudExperienceHostBroker.exe" "Sat Jun 5 13:05:20 2021" "
+ "\Microsoft\Windows\Customer Experience Improvement Program\Consolidator" "If the user has consented to participate in the Windows Customer Experience Improvement Program, this job collects and sends usage data to Microsoft." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\wsqmcons.exe" "Sat Jun 5 13:05:23 2021" "
+ "\Microsoft\Windows\Customer Experience Improvement Program\UsbCeip" "USBCEIP Task" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\usbceip.dll" "Sat Jun 5 13:05:27 2021" "
+ "\Microsoft\Windows\Data Integrity Scan\Data Integrity Check And Scan" "Data Integrity Scan Task" "(Verified) Microsoft Windows" "C:\Windows\System32\discan.dll" "Sat Jun 5 13:06:00 2021" "
+ "\Microsoft\Windows\Data Integrity Scan\Data Integrity Scan" "Data Integrity Scan Task" "(Verified) Microsoft Windows" "C:\Windows\System32\discan.dll" "Sat Jun 5 13:06:00 2021" "
+ "\Microsoft\Windows\Data Integrity Scan\Data Integrity Scan for Crash Recovery" "Data Integrity Scan Task" "(Verified) Microsoft Windows" "C:\Windows\System32\discan.dll" "Sat Jun 5 13:06:00 2021" "
+ "\Microsoft\Windows\Defrag\ScheduledDefrag" "This task optimises local storage drives." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\defrag.exe" "Sat Jun 5 13:06:05 2021" "
+ "\Microsoft\Windows\Device Information\Device" "Device Census" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\devicecensus.exe" "Sat Jun 5 13:05:23 2021" "
+ "\Microsoft\Windows\Device Information\Device User" "Device Census" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\devicecensus.exe" "Sat Jun 5 13:05:23 2021" "
+ "\Microsoft\Windows\Diagnosis\RecommendedTroubleshootingScanner" "MitigationClient" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\MitigationClient.dll" "Sat Jun 5 13:04:52 2021" "
+ "\Microsoft\Windows\Diagnosis\Scheduled" "Scripted Diagnostics Scheduled Task" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\sdiagschd.dll" "Sat Jun 5 13:06:14 2021" "
+ "\Microsoft\Windows\DirectX\DirectXDatabaseUpdater" "DirectX Database Updater" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\directxdatabaseupdater.exe" "Thu Dec 16 07:52:23 2021" "
+ "\Microsoft\Windows\DirectX\DXGIAdapterCache" "DXGI Adapter Cache" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\dxgiadaptercache.exe" "Sat Jun 5 13:05:06 2021" "
+ "\Microsoft\Windows\DiskCleanup\SilentCleanup" "Maintenance task used by the system to launch a silent automatic disk clean-up when free disk space is running low." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\cleanmgr.exe" "Sat Jun 5 13:06:02 2021" "
+ "\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector" "The Windows Disk Diagnostic reports general disk and system information to Microsoft for users participating in the Customer Experience Program." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\dfdts.dll" "Sat Jun 5 13:06:05 2021" "
+ X "\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticResolver" "The Microsoft-Windows-DiskDiagnosticResolver warns users about faults reported by hard disks that support the Self Monitoring and Reporting Technology (S.M.A.R.T.) standard. This task is triggered automatically by the Diagnostic Policy Service when a S.M.A.R.T. fault is detected." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\DFDWiz.exe" "Sat Jun 5 13:06:05 2021" "
+ "\Microsoft\Windows\DiskFootprint\Diagnostics" "DiskSnapshot.exe" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\disksnapshot.exe" "Sat Jun 5 13:05:16 2021" "
+ "\Microsoft\Windows\DiskFootprint\StorageSense" "Storage Usage" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\StorageUsage.dll" "Thu Dec 16 07:56:31 2021" "
+ "\Microsoft\Windows\DUSM\dusmtask" "DUSM Task" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\dusmtask.exe" "Thu Dec 16 07:56:20 2021" "
+ "\Microsoft\Windows\EDP\EDP App Launch Task" "EdpTask Task" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\edptask.dll" "Sat Jun 5 13:05:29 2021" "
+ "\Microsoft\Windows\EDP\EDP Auth Task" "EdpTask Task" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\edptask.dll" "Sat Jun 5 13:05:29 2021" "
+ "\Microsoft\Windows\EDP\EDP Inaccessible Credentials Task" "EdpTask Task" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\edptask.dll" "Sat Jun 5 13:05:29 2021" "
+ "\Microsoft\Windows\EDP\StorageCardEncryption Task" "EdpTask Task" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\edptask.dll" "Sat Jun 5 13:05:29 2021" "
+ "\Microsoft\Windows\ExploitGuard\ExploitGuard MDM policy Refresh" "Exploit Guard Configuration Helper" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\MitigationConfiguration.dll" "Sat Jun 5 13:05:40 2021" "
+ "\Microsoft\Windows\Feedback\Siuf\DmClient" "Update SIUF strings" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\dmclient.exe" "Sat Jun 5 13:04:59 2021" "
+ "\Microsoft\Windows\Feedback\Siuf\DmClientOnScenarioDownload" "Update SIUF strings" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\dmclient.exe" "Sat Jun 5 13:04:59 2021" "
+ "\Microsoft\Windows\FileHistory\File History (maintenance mode)" "File History Task Handler" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\fhtask.dll" "Thu Dec 16 07:56:54 2021" "
+ "\Microsoft\Windows\Flighting\FeatureConfig\ReconcileFeatures" "Feature Configuration" "(Verified) Microsoft Windows" "C:\Windows\System32\fcon.dll" "Sat Jun 5 13:04:52 2021" "
+ "\Microsoft\Windows\Flighting\FeatureConfig\UsageDataFlushing" "Feature Configuration" "(Verified) Microsoft Windows" "C:\Windows\System32\fcon.dll" "Sat Jun 5 13:04:52 2021" "
+ "\Microsoft\Windows\Flighting\FeatureConfig\UsageDataReporting" "Feature Configuration" "(Verified) Microsoft Windows" "C:\Windows\System32\fcon.dll" "Sat Jun 5 13:04:52 2021" "
+ "\Microsoft\Windows\Flighting\OneSettings\RefreshCache" "Windows OneSettings Client" "(Verified) Microsoft Windows" "C:\Windows\System32\wosc.dll" "Thu Dec 16 07:51:24 2021" "
+ "\Microsoft\Windows\Input\LocalUserSyncDataAvailable" "Windows Input Cloud Store Task Handlers" "(Verified) Microsoft Windows" "C:\Windows\System32\InputCloudStore.dll" "Sat Jun 5 13:05:20 2021" "
+ "\Microsoft\Windows\Input\MouseSyncDataAvailable" "Windows Input Cloud Store Task Handlers" "(Verified) Microsoft Windows" "C:\Windows\System32\InputCloudStore.dll" "Sat Jun 5 13:05:20 2021" "
+ "\Microsoft\Windows\Input\PenSyncDataAvailable" "Windows Input Cloud Store Task Handlers" "(Verified) Microsoft Windows" "C:\Windows\System32\InputCloudStore.dll" "Sat Jun 5 13:05:20 2021" "
+ "\Microsoft\Windows\Input\TouchpadSyncDataAvailable" "Windows Input Cloud Store Task Handlers" "(Verified) Microsoft Windows" "C:\Windows\System32\InputCloudStore.dll" "Sat Jun 5 13:05:20 2021" "
+ "\Microsoft\Windows\InstallService\ScanForUpdates" "InstallService Tasks" "(Verified) Microsoft Windows" "C:\Windows\System32\InstallServiceTasks.dll" "Thu Dec 16 07:52:32 2021" "
+ "\Microsoft\Windows\InstallService\ScanForUpdatesAsUser" "InstallService Tasks" "(Verified) Microsoft Windows" "C:\Windows\System32\InstallServiceTasks.dll" "Thu Dec 16 07:52:32 2021" "
+ X "\Microsoft\Windows\InstallService\WakeUpAndContinueUpdates" "InstallService Tasks" "(Verified) Microsoft Windows" "C:\Windows\System32\InstallServiceTasks.dll" "Thu Dec 16 07:52:32 2021" "
+ X "\Microsoft\Windows\InstallService\WakeUpAndScanForUpdates" "InstallService Tasks" "(Verified) Microsoft Windows" "C:\Windows\System32\InstallServiceTasks.dll" "Thu Dec 16 07:52:32 2021" "
+ "\Microsoft\Windows\International\Synchronize Language Settings" "Core Globalization Configuration" "(Verified) Microsoft Windows" "C:\Windows\System32\CoreGlobConfig.dll" "Sat Jun 5 13:05:09 2021" "
+ "\Microsoft\Windows\Kernel\La57Cleanup" "This task cleans up 5-level paging binaries on systems that do not support 5-level paging." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\la57setup.exe" "Thu Dec 16 07:54:22 2021" "
+ "\Microsoft\Windows\LanguageComponentsInstaller\Installation" "LanguageComponentsInstaller Task" "(Verified) Microsoft Windows" "C:\Windows\System32\LanguageComponentsInstaller.dll" "Thu Dec 16 07:54:22 2021" "
+ "\Microsoft\Windows\Location\Notifications" "Location Notification" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\LocationNotificationWindows.exe" "Sat Jun 5 13:06:10 2021" "
+ "\Microsoft\Windows\Location\WindowsActionDialog" "Location Notification" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\WindowsActionDialog.exe" "Sat Jun 5 13:06:10 2021" "
+ "\Microsoft\Windows\Maintenance\WinSAT" "Windows System Assessment Tool API" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\WinSATAPI.dll" "Sat Jun 5 13:06:16 2021" "
+ "\Microsoft\Windows\Management\Provisioning\Cellular" "Provisioning package runtime processing tool" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\ProvTool.exe" "Thu Dec 16 07:51:45 2021" "
+ "\Microsoft\Windows\Management\Provisioning\Logon" "Provisioning package runtime processing tool" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\ProvTool.exe" "Thu Dec 16 07:51:45 2021" "
+ X "\Microsoft\Windows\Management\Provisioning\MdmDiagnosticsCleanup" "MdmDiagnosticsTool" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\MdmDiagnosticsTool.exe" "Sat Jun 5 13:05:12 2021" "
+ X "\Microsoft\Windows\Management\Provisioning\Retry" "Provisioning package runtime processing tool" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\ProvTool.exe" "Thu Dec 16 07:51:45 2021" "
+ X "\Microsoft\Windows\Management\Provisioning\RunOnReboot" "Provisioning package runtime processing tool" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\ProvTool.exe" "Thu Dec 16 07:51:45 2021" "
+ "\Microsoft\Windows\Maps\MapsToastTask" "MapsToastTask Task" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\mapstoasttask.dll" "Thu Dec 16 07:52:30 2021" "
+ X "\Microsoft\Windows\Maps\MapsUpdateTask" "MapsUpdateTask Task" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\mapsupdatetask.dll" "Thu Dec 16 07:52:29 2021" "
+ "\Microsoft\Windows\MemoryDiagnostic\ProcessMemoryDiagnosticEvents" "Microsoft Windows Memory Diagnostic Task Handler" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\MemoryDiagnostic.dll" "Sat Jun 5 13:06:16 2021" "
+ "\Microsoft\Windows\MemoryDiagnostic\RunFullMemoryDiagnostic" "Microsoft Windows Memory Diagnostic Task Handler" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\MemoryDiagnostic.dll" "Sat Jun 5 13:06:16 2021" "
+ "\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser" "$(@%SystemRoot%\system32\MbaeParserTask.exe,-1903)" "" "File not found: C:\WINDOWS\System32\MbaeParserTask.exe" "" "
+ "\Microsoft\Windows\MUI\LPRemove" "Launch language clean-up tool" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\lpremove.exe" "Thu Dec 16 07:54:22 2021" "
+ "\Microsoft\Windows\Multimedia\SystemSoundsService" "PlaySound Service" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\PlaySndSrv.dll" "Thu Dec 16 07:51:30 2021" "
+ "\Microsoft\Windows\NetTrace\GatherNetworkInfo" "Network information collector" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\gatherNetworkInfo.vbs" "Sat Jun 5 13:06:02 2021" "
+ "\Microsoft\Windows\NlaSvc\WiFiTask" "Background task for performing per user and web interactions" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\WiFiTask.exe" "Thu Dec 16 07:51:50 2021" "
+ "\Microsoft\Windows\Plug and Play\Device Install Group Policy" "pnppolicy Task" "(Verified) Microsoft Windows" "C:\Windows\System32\pnppolicy.dll" "Sat Jun 5 13:05:39 2021" "
+ "\Microsoft\Windows\Plug and Play\Device Install Reboot Required" "Plug and Play User Interface DLL" "(Verified) Microsoft Windows" "C:\Windows\System32\pnpui.dll" "Sat Jun 5 13:05:39 2021" "
+ "\Microsoft\Windows\Plug and Play\Sysprep Generalize Drivers" "Generalise driver state in order to prepare the system to be bootable on any hardware configuration." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drvinst.exe" "Sat Jun 5 13:05:39 2021" "
+ "\Microsoft\Windows\Power Efficiency Diagnostics\AnalyzeSystem" "Power Efficiency Diagnostics Task" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\energytask.dll" "Sat Jun 5 13:06:11 2021" "
+ "\Microsoft\Windows\Printing\EduPrintProv" "Printer Provision Utility for EDU" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\eduprintprov.exe" "Sat Jun 5 13:06:16 2021" "
+ "\Microsoft\Windows\Printing\PrinterCleanupTask" "Windows Printer Cleanup Task" "(Verified) Microsoft Windows" "C:\Windows\System32\PrinterCleanupTask.dll" "Thu Dec 16 07:51:44 2021" "
+ "\Microsoft\Windows\RecoveryEnvironment\VerifyWinRE" "Microsoft Windows Recovery Agent Task Handler" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\ReAgentTask.dll" "Sat Jun 5 13:05:27 2021" "
+ "\Microsoft\Windows\Registry\RegIdleBackup" "RegIdle Backup Task" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\regidle.dll" "Sat Jun 5 13:06:11 2021" "
+ "\Microsoft\Windows\Setup\SetupCleanupTask" "SetupCleanupTask Task" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\oobe\SetupCleanupTask.dll" "Thu Dec 16 07:55:10 2021" "
+ X "\Microsoft\Windows\SharedPC\Account Cleanup" "SharedPC.AccountManager" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Windows.SharedPC.AccountManager.dll" "Sat Jun 5 13:05:19 2021" "
+ "\Microsoft\Windows\Shell\CreateObjectTask" "Windows Shell Common Dll" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\shell32.dll" "Thu Dec 16 07:54:27 2021" "
+ "\Microsoft\Windows\Shell\FamilySafetyMonitor" "Initialises Family Safety monitoring and enforcement." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\wpcmon.exe" "Thu Dec 16 07:51:41 2021" "
+ "\Microsoft\Windows\Shell\FamilySafetyRefreshTask" "Family Safety Refresh Task" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\WpcRefreshTask.dll" "Thu Dec 16 07:51:42 2021" "
+ "\Microsoft\Windows\Shell\IndexerAutomaticMaintenance" "Indexing Options" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\srchadmin.dll" "Sat Jun 5 13:05:40 2021" "
+ "\Microsoft\Windows\Shell\ThemesSyncedImageDownload" "ThemesSyncedImageDownload Task" "(Verified) Microsoft Windows" "C:\Windows\System32\Themes.SsfDownload.ScheduledTask.dll" "Sat Jun 5 13:04:58 2021" "
+ X "\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTaskLogon" "Software Protection Platform Client Extension Dll" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\sppcext.dll" "Thu Dec 16 07:54:29 2021" "
+ "\Microsoft\Windows\SpacePort\SpaceAgentTask" "Storage Spaces Settings" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\SpaceAgent.exe" "Sat Jun 5 13:06:17 2021" "
+ "\Microsoft\Windows\SpacePort\SpaceManagerTask" "$(@%SystemRoot%\system32\spaceman.exe,-3)" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\spaceman.exe" "Sat Jun 5 13:06:02 2021" "
+ "\Microsoft\Windows\StateRepository\MaintenanceTasks" "$(@%SystemRoot%\system32\Windows.StateRepositoryClient.dll,-602)" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\Windows.StateRepositoryClient.dll" "Thu Dec 16 07:52:37 2021" "
+ "\Microsoft\Windows\Storage Tiers Management\Storage Tiers Management Initialization" "Storage Tiers Management" "(Verified) Microsoft Windows" "C:\Windows\System32\TieringEngineService.exe" "Sat Jun 5 13:06:13 2021" "
+ X "\Microsoft\Windows\Storage Tiers Management\Storage Tiers Optimization" "Optimizes the placement of data in storage tiers on all tiered storage spaces in the system." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\defrag.exe" "Sat Jun 5 13:06:05 2021" "
+ "\Microsoft\Windows\Subscription\EnableLicenseAcquisition" "Enable susbscription license acquisition" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\ClipRenew.exe" "Sat Jun 5 18:17:02 2021" "
+ X "\Microsoft\Windows\Subscription\LicenseAcquisition" "Susbscription license acquisition" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\ClipRenew.exe" "Sat Jun 5 18:17:02 2021" "
+ X "\Microsoft\Windows\Sysmain\HybridDriveCachePrepopulate" "SysMain Service Host" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\sysmain.dll" "Thu Dec 16 07:56:56 2021" "
+ X "\Microsoft\Windows\Sysmain\HybridDriveCacheRebalance" "SysMain Service Host" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\sysmain.dll" "Thu Dec 16 07:56:56 2021" "
+ "\Microsoft\Windows\Sysmain\ResPriStaticDbSync" "SysMain Service Host" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\sysmain.dll" "Thu Dec 16 07:56:56 2021" "
+ "\Microsoft\Windows\Sysmain\WsSwapAssessmentTask" "Working set swap assessment maintenance task" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\sysmain.dll" "Thu Dec 16 07:56:56 2021" "
+ "\Microsoft\Windows\SystemRestore\SR" "This task creates regular system protection points." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\srtasks.exe" "Sat Jun 5 13:06:17 2021" "
+ "\Microsoft\Windows\Task Manager\Interactive" "Performance Monitor" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wdc.dll" "Sat Jun 5 13:06:10 2021" "
+ "\Microsoft\Windows\TextServicesFramework\MsCtfMonitor" "MsCtfMonitor DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\MsCtfMonitor.dll" "Sat Jun 5 13:05:12 2021" "
+ "\Microsoft\Windows\Time Synchronization\ForceSynchronizeTime" "Time Synchronization Task" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\TimeSyncTask.dll" "Sat Jun 5 13:04:59 2021" "
+ "\Microsoft\Windows\Time Synchronization\SynchronizeTime" "Maintains date and time synchronization on all clients and servers in the network. If this service is stopped, date and time synchronization will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\sc.exe" "Sat Jun 5 13:06:02 2021" "
+ "\Microsoft\Windows\Time Zone\SynchronizeTimeZone" "Updates timezone information. If this task is stopped, local time may not be accurate for some time zones." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\tzsync.exe" "Sat Jun 5 13:05:14 2021" "
+ X "\Microsoft\Windows\UNP\RunUpdateNotificationMgr" "Update Notification Pipeline Manager" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\UNP\UpdateNotificationMgr.exe" "Sat Jun 5 13:06:16 2021" "
+ "\Microsoft\Windows\UPnP\UPnPHostConfig" "Set UPnPHost service to Auto-Start" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\sc.exe" "Sat Jun 5 13:06:02 2021" "
+ "\Microsoft\Windows\USB\Usb-Notifications" "UsbTask" "(Verified) Microsoft Windows" "C:\Windows\System32\UsbTask.dll" "Sat Jun 5 13:04:52 2021" "
+ "\Microsoft\Windows\WCM\WiFiTask" "Background task for performing per user and web interactions" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\WiFiTask.exe" "Thu Dec 16 07:51:50 2021" "
+ "\Microsoft\Windows\WDI\ResolutionHost" "Windows Diagnostic Infrastructure" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\wdi.dll" "Sat Jun 5 13:05:29 2021" "
+ "\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance" "Periodic maintenance task." "(Verified) Microsoft Windows Publisher" "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2111.5-0\MpCmdRun.exe" "Thu Dec 16 00:20:53 2021" "
+ "\Microsoft\Windows\Windows Defender\Windows Defender Cleanup" "Periodic clean-up task." "(Verified) Microsoft Windows Publisher" "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2111.5-0\MpCmdRun.exe" "Thu Dec 16 00:20:53 2021" "
+ "\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan" "Periodic scan task." "(Verified) Microsoft Windows Publisher" "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2111.5-0\MpCmdRun.exe" "Thu Dec 16 00:20:53 2021" "
+ "\Microsoft\Windows\Windows Defender\Windows Defender Verification" "Periodic verification task." "(Verified) Microsoft Windows Publisher" "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2111.5-0\MpCmdRun.exe" "Thu Dec 16 00:20:53 2021" "
+ "\Microsoft\Windows\Windows Error Reporting\QueueReporting" "Windows Error Reporting task to process queued reports." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wermgr.exe" "Sat Jun 5 13:05:25 2021" "
+ "\Microsoft\Windows\Windows Filtering Platform\BfeOnServiceStartTypeChange" "This task adjusts the start type for firewall-triggered services when the start type of the Base Filtering Engine (BFE) is disabled." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\bfe.dll" "Thu Dec 16 07:52:47 2021" "
+ "\Microsoft\Windows\Windows Media Sharing\UpdateLibrary" "This task updates the cached list of folders and the security permissions on any new files in a user’s shared media library." "(Verified) Microsoft Windows" "C:\Program Files\Windows Media Player\wmpnscfg.exe" "Sat Jun 5 02:36:00 2021" "
+ "\Microsoft\Windows\WindowsColorSystem\Calibration Loader" "Microsoft Colour Matching System DLL" "(Verified) Microsoft Windows" "C:\Windows\System32\mscms.dll" "Thu Dec 16 07:52:23 2021" "
+ "\Microsoft\Windows\WindowsUpdate\Scheduled Start" "This task is used to start the Windows Update service when needed to perform scheduled operations such as scans." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\sc.exe" "Sat Jun 5 13:06:02 2021" "
+ "\Microsoft\Windows\Wininet\CacheTask" "Internet Extensions for Win32" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wininet.dll" "Thu Dec 16 07:54:21 2021" "
+ "\Microsoft\Windows\WlanSvc\CDSSync" "Windows WiFi Sync Provider DLL" "(Verified) Microsoft Windows" "C:\Windows\System32\WiFiCloudStore.dll" "Sat Jun 5 13:05:00 2021" "
+ "\Microsoft\Windows\Work Folders\Work Folders Logon Synchronization" "Microsoft (C) Work Folders Shell Extension" "(Verified) Microsoft Windows" "C:\Windows\System32\WorkFoldersShell.dll" "Sat Jun 5 13:06:16 2021" "
+ "\Microsoft\Windows\Work Folders\Work Folders Maintenance Work" "Microsoft (C) Work Folders Shell Extension" "(Verified) Microsoft Windows" "C:\Windows\System32\WorkFoldersShell.dll" "Sat Jun 5 13:06:16 2021" "
+ X "\Microsoft\Windows\Workplace Join\Automatic-Device-Join" "Register this computer if the computer is already joined to an Active Directory domain." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\dsregcmd.exe" "Sat Jun 5 13:04:59 2021" "
+ X "\Microsoft\Windows\Workplace Join\Device-Sync" "DSREG task handler" "(Verified) Microsoft Windows" "C:\Windows\System32\dsregtask.dll" "Sat Jun 5 13:04:59 2021" "
+ X "\Microsoft\Windows\Workplace Join\Recovery-Check" "Performs recovery check." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\dsregcmd.exe" "Sat Jun 5 13:04:59 2021" "
+ "\Microsoft\Windows\WwanSvc\NotificationTask" "Background task for performing per user and web interactions" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\WiFiTask.exe" "Thu Dec 16 07:51:50 2021" "
+ "\Microsoft\Windows\WwanSvc\OobeDiscovery" "Windows MB Media Manager DLL" "(Verified) Microsoft Windows" "C:\Windows\System32\MBMediaManager.dll" "Thu Dec 16 07:53:07 2021" "
+ "\Microsoft\XblGameSave\XblGameSaveTask" "XblGameSave Standby Task" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\XblGameSaveTask.exe" "Sat Jun 5 13:04:52 2021" "
+ "\UbtFrameworkService" "User Experience Improvement Program Framework Service" "(Verified) Acer Incorporated" "C:\Program Files\Acer\User Experience Improvement Program Service\Framework\TriggerFramework.exe" "Fri Aug 7 12:56:32 2020" "
+ "\UEIPInvitation" "User Experience Improvement Program Framework Invitation" "(Verified) Acer Incorporated" "C:\Program Files\Acer\User Experience Improvement Program Service\Framework\UEIPOOBECheck.exe" "Fri Aug 7 12:56:32 2020" "
[Services]
[HKLM\System\CurrentControlSet\Services]
+ "AarSvc" "Agent Activation Runtime: Runtime for activating conversational agent applications" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\AarSvc.dll" "Sat Jun 5 13:04:52 2021" "
+ "AarSvc_6a9e6" "Agent Activation Runtime_6a9e6: Runtime for activating conversational agent applications" "(Verified) Microsoft Windows Publisher" "C:\WINDOWS\system32\svchost.exe" "Sat Jun 5 13:05:23 2021" "
+ "ACCSvc" "ACC Service: ACC Service" "(Verified) Acer Incorporated" "C:\Program Files (x86)\Acer\Care Center\ACCSvc.exe" "Wed Nov 17 15:08:30 2021" "
+ "AJRouter" "AllJoyn Router Service: Routes AllJoyn messages for the local AllJoyn clients. If this service is stopped the AllJoyn clients that do not have their own bundled routers will be unable to run." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\AJRouter.dll" "Sat Jun 5 13:05:03 2021" "
+ "ALG" "Application Layer Gateway Service: Provides support for 3rd party protocol plug-ins for Internet Connection Sharing" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\alg.exe" "Sat Jun 5 13:05:12 2021" "
+ "AppIDSvc" "Application Identity: Determines and verifies the identity of an application. Disabling this service will prevent AppLocker from being enforced." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\appidsvc.dll" "Sat Jun 5 13:05:23 2021" "
+ "Appinfo" "Application Information: Facilitates the running of interactive applications with additional administrative privileges. If this service is stopped, users will be unable to launch applications with the additional administrative privileges they may require to perform desired user tasks." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\appinfo.dll" "Thu Dec 16 07:52:14 2021" "
+ "AppReadiness" "App Readiness: Gets apps ready for use the first time a user signs in to this PC and when adding new apps." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\AppReadiness.dll" "Thu Dec 16 08:01:09 2021" "
+ "AppXSvc" "AppX Deployment Service (AppXSVC): Provides infrastructure support for deploying Store applications. This service is started on demand and if disabled Store applications will not be deployed to the system, and may not function properly." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\appxdeploymentserver.dll" "Thu Dec 16 07:54:08 2021" "
+ "AtherosSvc" "AtherosSvc: Windows Setup API" "(Verified) Microsoft Windows Hardware Compatibility Publisher" "C:\WINDOWS\System32\drivers\AdminService.exe" "Mon Jul 19 21:46:00 2021" "
+ "AudioEndpointBuilder" "Windows Audio Endpoint Builder: Manages audio devices for the Windows Audio service. If this service is stopped, audio devices and effects will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\AudioEndpointBuilder.dll" "Thu Dec 16 07:51:31 2021" "
+ "Audiosrv" "Windows Audio: Manages audio for Windows-based programs. If this service is stopped, audio devices and effects will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Audiosrv.dll" "Thu Dec 16 07:51:31 2021" "
+ "autotimesvc" "Cellular Time: This service sets time based on NITZ messages from a Mobile Network" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\autotimesvc.dll" "Sat Jun 5 13:06:00 2021" "
+ "AxInstSV" "ActiveX Installer (AxInstSV): Provides User Account Control validation for the installation of ActiveX controls from the Internet and enables management of ActiveX control installation based on Group Policy settings. This service is started on demand and if disabled the installation of ActiveX controls will behave according to default browser settings." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\AxInstSV.dll" "Thu Dec 16 07:54:24 2021" "
+ "BcastDVRUserService" "GameDVR and Broadcast User Service: This user service is used for Game Recordings and Live Broadcasts" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\BcastDVRUserService.dll" "Thu Dec 16 07:56:19 2021" "
+ "BcastDVRUserService_6a9e6" "GameDVR and Broadcast User Service_6a9e6: This user service is used for Game Recordings and Live Broadcasts" "(Verified) Microsoft Windows Publisher" "C:\WINDOWS\system32\svchost.exe" "Sat Jun 5 13:05:23 2021" "
+ "BDESVC" "BitLocker Drive Encryption Service: BDESVC hosts the BitLocker Drive Encryption service. BitLocker Drive Encryption provides secure startup for the operating system, as well as full volume encryption for OS, fixed or removable volumes. This service allows BitLocker to prompt users for various actions related to their volumes when mounted, and unlocks volumes automatically without user interaction. Additionally, it stores recovery information to Active Directory, if available, and, if necessary, ensures the most recent recovery certificates are used. Stopping or disabling the service would prevent users from leveraging this functionality." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\bdesvc.dll" "Thu Dec 16 08:01:15 2021" "
+ "BFE" "Base Filtering Engine: The Base Filtering Engine (BFE) is a service that manages firewall and Internet Protocol security (IPsec) policies and implements user mode filtering. Stopping or disabling the BFE service will significantly reduce the security of the system. It will also result in unpredictable behavior in IPsec management and firewall applications." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\bfe.dll" "Thu Dec 16 07:52:47 2021" "
+ "BITS" "Background Intelligent Transfer Service: Transfers files in the background using idle network bandwidth. If the service is disabled, then any applications that depend on BITS, such as Windows Update or MSN Explorer, will be unable to automatically download programs and other information." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\qmgr.dll" "Sat Jun 5 13:05:03 2021" "
+ "BluetoothUserService" "Bluetooth User Support Service: The Bluetooth user service supports proper functionality of Bluetooth features relevant to each user session." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Microsoft.Bluetooth.UserService.dll" "Sat Jun 5 13:04:50 2021" "
+ "BluetoothUserService_6a9e6" "Bluetooth User Support Service_6a9e6: The Bluetooth user service supports proper functionality of Bluetooth features relevant to each user session." "(Verified) Microsoft Windows Publisher" "C:\WINDOWS\system32\svchost.exe" "Sat Jun 5 13:05:23 2021" "
+ "BrokerInfrastructure" "Background Tasks Infrastructure Service: Windows infrastructure service that controls which background tasks can run on the system." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\psmsrv.dll" "Sat Jun 5 13:05:10 2021" "
+ "BTAGService" "Bluetooth Audio Gateway Service: Service supporting the audio gateway role of the Bluetooth Handsfree Profile." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\BTAGService.dll" "Thu Dec 16 07:51:22 2021" "
+ "BthAvctpSvc" "AVCTP service: This is Audio Video Control Transport Protocol service" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\BthAvctpSvc.dll" "Sat Jun 5 13:04:50 2021" "
+ "bthserv" "Bluetooth Support Service: The Bluetooth service supports discovery and association of remote Bluetooth devices. Stopping or disabling this service may cause already installed Bluetooth devices to fail to operate properly and prevent new devices from being discovered or associated." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\bthserv.dll" "Sat Jun 5 13:05:16 2021" "
+ "camsvc" "Capability Access Manager Service: Provides facilities for managing UWP apps access to app capabilities as well as checking an app's access to specific app capabilities" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\CapabilityAccessManager.dll" "Thu Dec 16 07:52:51 2021" "
+ "CaptureService" "CaptureService: Enables optional screen capture functionality for applications that call the Windows.Graphics.Capture API." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\CaptureService.dll" "Sat Jun 5 13:05:23 2021" "
+ "CaptureService_6a9e6" "CaptureService_6a9e6: Enables optional screen capture functionality for applications that call the Windows.Graphics.Capture API." "(Verified) Microsoft Windows Publisher" "C:\WINDOWS\system32\svchost.exe" "Sat Jun 5 13:05:23 2021" "
+ "cbdhsvc" "Clipboard User Service: This user service is used for Clipboard scenarios" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\cbdhsvc.dll" "Thu Dec 16 07:56:28 2021" "
+ "cbdhsvc_6a9e6" "Clipboard User Service_6a9e6: This user service is used for Clipboard scenarios" "(Verified) Microsoft Windows Publisher" "C:\WINDOWS\system32\svchost.exe" "Sat Jun 5 13:05:23 2021" "
+ "CDPSvc" "Connected Devices Platform Service: This service is used for Connected Devices Platform scenarios" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\CDPSvc.dll" "Sat Jun 5 13:05:02 2021" "
+ "CDPUserSvc" "Connected Devices Platform User Service: This user service is used for Connected Devices Platform scenarios" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\CDPUserSvc.dll" "Sat Jun 5 13:05:02 2021" "
+ "CDPUserSvc_6a9e6" "Connected Devices Platform User Service_6a9e6: This user service is used for Connected Devices Platform scenarios" "(Verified) Microsoft Windows Publisher" "C:\WINDOWS\system32\svchost.exe" "Sat Jun 5 13:05:23 2021" "
+ X "CertPropSvc" "Certificate Propagation: Copies user certificates and root certificates from smart cards into the current user's certificate store, detects when a smart card is inserted into a smart card reader, and, if needed, installs the smart card Plug and Play minidriver." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\certprop.dll" "Sat Jun 5 13:05:34 2021" "
+ "ClickToRunSvc" "Microsoft Office Click-to-Run Service: ‪Manages resource coordination, background streaming, and system integration of Microsoft Office products and their related updates. This service is required to run during the use of any Microsoft Office program, during initial streaming installation and all subsequent updates.‬" "(Verified) Microsoft Corporation" "C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe" "Thu Dec 2 19:28:12 2021" "
+ "ClipSVC" "Client Licence Service (ClipSVC): Provides infrastructure support for the Microsoft Store. This service is started on demand and if disabled applications bought using Windows Store will not behave correctly." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\ClipSVC.dll" "Thu Dec 16 07:52:51 2021" "
+ "COMSysApp" "COM+ System Application: Manages the configuration and tracking of Component Object Model (COM)+-based components. If the service is stopped, most COM+-based components will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\dllhost.exe" "Sat Jun 5 13:05:23 2021" "
+ "ConsentUxUserSvc" "ConsentUX User Service: Allows the system to request user consent to allow apps to access sensitive resources and information such as the device's location" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\ConsentUxClient.dll" "Sat Jun 5 13:06:02 2021" "
+ "ConsentUxUserSvc_6a9e6" "ConsentUX User Service_6a9e6: Allows the system to request user consent to allow apps to access sensitive resources and information such as the device's location" "(Verified) Microsoft Windows Publisher" "C:\WINDOWS\system32\svchost.exe" "Sat Jun 5 13:05:23 2021" "
+ "CoreMessagingRegistrar" "CoreMessaging: Manages communication between system components." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\coremessaging.dll" "Thu Dec 16 07:53:41 2021" "
+ "cphs" "Intel(R) Content Protection HECI Service: Intel(R) Content Protection HECI Service - enables communication with the Content Protection FW" "(Verified) Intel(R) pGFX 2020" "C:\WINDOWS\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_e36b8067470714bb\IntelCpHeciSvc.exe" "Mon Jan 18 03:53:04 2021" "
+ "cplspcon" "Intel(R) Content Protection HDCP Service: Intel(R) Content Protection HDCP Service - enables communication with Content Protection HDCP HW" "(Verified) Intel(R) pGFX 2020" "C:\WINDOWS\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_e36b8067470714bb\IntelCpHDCPSvc.exe" "Mon Jan 18 03:53:04 2021" "
+ "CredentialEnrollmentManagerUserSvc" "CredentialEnrollmentManagerUserSvc: Credential Enrollment Manager" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\CredentialEnrollmentManager.exe" "Thu Dec 16 07:51:55 2021" "
+ "CredentialEnrollmentManagerUserSvc_6a9e6" "CredentialEnrollmentManagerUserSvc_6a9e6: Credential Enrollment Manager" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\CredentialEnrollmentManager.exe" "Thu Dec 16 07:51:55 2021" "
+ "CryptSvc" "Cryptographic Services: Provides three management services: Catalog Database Service, which confirms the signatures of Windows files and allows new programs to be installed; Protected Root Service, which adds and removes Trusted Root Certification Authority certificates from this computer; and Automatic Root Certificate Update Service, which retrieves root certificates from Windows Update and enable scenarios such as SSL. If this service is stopped, these management services will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\cryptsvc.dll" "Sat Jun 5 13:05:23 2021" "
+ "DcomLaunch" "DCOM Server Process Launcher: The DCOMLAUNCH service launches COM and DCOM servers in response to object activation requests. If this service is stopped or disabled, programs using COM or DCOM will not function properly. It is strongly recommended that you have the DCOMLAUNCH service running." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\rpcss.dll" "Thu Dec 16 07:53:43 2021" "
+ "defragsvc" "Optimise drives: Helps the computer run more efficiently by optimising files on storage drives." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\defragsvc.dll" "Thu Dec 16 07:56:30 2021" "
+ "DeviceAssociationBrokerSvc" "DeviceAssociationBroker: Enables apps to pair devices" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\deviceaccess.dll" "Sat Jun 5 13:05:12 2021" "
+ "DeviceAssociationBrokerSvc_6a9e6" "DeviceAssociationBroker_6a9e6: Enables apps to pair devices" "(Verified) Microsoft Windows Publisher" "C:\WINDOWS\system32\svchost.exe" "Sat Jun 5 13:05:23 2021" "
+ "DeviceAssociationService" "Device Association Service: Enables pairing between the system and wired or wireless devices." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\das.dll" "Sat Jun 5 13:05:16 2021" "
+ "DeviceInstall" "Device Install Service: Enables a computer to recognize and adapt to hardware changes with little or no user input. Stopping or disabling this service will result in system instability." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\umpnpmgr.dll" "Sat Jun 5 13:05:39 2021" "
+ "DevicePickerUserSvc" "DevicePicker: This user service is used for managing the Miracast, DLNA and DIAL UI" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Windows.Devices.Picker.dll" "Sat Jun 5 13:06:46 2021" "
+ "DevicePickerUserSvc_6a9e6" "DevicePicker_6a9e6: This user service is used for managing the Miracast, DLNA and DIAL UI" "(Verified) Microsoft Windows Publisher" "C:\WINDOWS\system32\svchost.exe" "Sat Jun 5 13:05:23 2021" "
+ "DevicesFlowUserSvc" "DevicesFlow: Allows ConnectUX and PC Settings to Connect and Pair with WiFi displays and Bluetooth devices." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DevicesFlowBroker.dll" "Sat Jun 5 13:05:20 2021" "
+ "DevicesFlowUserSvc_6a9e6" "DevicesFlow_6a9e6: Allows ConnectUX and PC Settings to Connect and Pair with WiFi displays and Bluetooth devices." "(Verified) Microsoft Windows Publisher" "C:\WINDOWS\system32\svchost.exe" "Sat Jun 5 13:05:23 2021" "
+ "DevQueryBroker" "DevQuery Background Discovery Broker: Enables apps to discover devices with a backgroud task" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\DevQueryBroker.dll" "Sat Jun 5 13:05:09 2021" "
+ "Dhcp" "DHCP Client: Registers and updates IP addresses and DNS records for this computer. If this service is stopped, this computer will not receive dynamic IP addresses and DNS updates. If this service is disabled, any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\dhcpcore.dll" "Thu Dec 16 07:53:42 2021" "
+ "diagnosticshub.standardcollector.service" "Microsoft (R) Diagnostics Hub Standard Collector Service: Diagnostics Hub Standard Collector Service. When running, this service collects real time ETW events and processes them." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe" "Thu Dec 16 07:53:52 2021" "
+ "diagsvc" "Diagnostic Execution Service: Executes diagnostic actions for troubleshooting support" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\DiagSvc.dll" "Sat Jun 5 13:06:16 2021" "
+ X "DiagTrack" "Connected User Experiences and Telemetry: The Connected User Experiences and Telemetry service enables features that support in-application and connected user experiences. Additionally, this service manages the event driven collection and transmission of diagnostic and usage information (used to improve the experience and quality of the Windows Platform) when the diagnostics and usage privacy option settings are enabled under Feedback and Diagnostics." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\diagtrack.dll" "Thu Dec 16 07:53:46 2021" "
+ "DispBrokerDesktopSvc" "Display Policy Service: Manages the connection and configuration of local and remote displays" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DispBroker.Desktop.dll" "Thu Dec 16 07:56:31 2021" "
+ "DisplayEnhancementService" "Display Enhancement Service: A service for managing display enhancement such as brightness control." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\Microsoft.Graphics.Display.DisplayEnhancementService.dll" "Thu Dec 16 07:56:20 2021" "
+ "DmEnrollmentSvc" "Device Management Enrollment Service: Performs Device Enrollment Activities for Device Management" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\Windows.Internal.Management.dll" "Sat Jun 5 13:05:29 2021" "
+ "dmwappushservice" "Device Management Wireless Application Protocol (WAP) Push message Routing Service: Routes Wireless Application Protocol (WAP) Push messages received by the device and synchronizes Device Management sessions" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\dmwappushsvc.dll" "Sat Jun 5 13:05:29 2021" "
+ "Dnscache" "DNS Client: The DNS Client service (dnscache) caches Domain Name System (DNS) names and registers the full computer name for this computer. If the service is stopped, DNS names will continue to be resolved. However, the results of DNS name queries will not be cached and the computer's name will not be registered. If the service is disabled, any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\dnsrslvr.dll" "Thu Dec 16 07:53:42 2021" "
+ "DoSvc" "Delivery Optimization: Performs content delivery optimization tasks" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\dosvc.dll" "Thu Dec 16 07:52:21 2021" "
+ "dot3svc" "Wired AutoConfig: The Wired AutoConfig (DOT3SVC) service is responsible for performing IEEE 802.1X authentication on Ethernet interfaces. If your current wired network deployment enforces 802.1X authentication, the DOT3SVC service should be configured to run for establishing Layer 2 connectivity and/or providing access to network resources. Wired networks that do not enforce 802.1X authentication are unaffected by the DOT3SVC service." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\dot3svc.dll" "Thu Dec 16 07:51:51 2021" "
+ "DPS" "Diagnostic Policy Service: The Diagnostic Policy Service enables problem detection, troubleshooting and resolution for Windows components. If this service is stopped, diagnostics will no longer function." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\dps.dll" "Sat Jun 5 13:06:13 2021" "
+ "DsmSvc" "Device Setup Manager: Enables the detection, download and installation of device-related software. If this service is disabled, devices may be configured with outdated software, and may not work correctly." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DeviceSetupManager.dll" "Sat Jun 5 13:05:06 2021" "
+ "DsSvc" "Data Sharing Service: Provides data brokering between applications." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DsSvc.dll" "Sat Jun 5 13:05:02 2021" "
+ "DusmSvc" "Data Usage: Network data usage, data limit, restrict background data, metered networks." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\dusmsvc.dll" "Thu Dec 16 07:56:20 2021" "
+ "EapHost" "Extensible Authentication Protocol: The Extensible Authentication Protocol (EAP) service provides network authentication in such scenarios as 802.1x wired and wireless, VPN, and Network Access Protection (NAP). EAP also provides application programming interfaces (APIs) that are used by network access clients, including wireless and VPN clients, during the authentication process. If you disable this service, this computer is prevented from accessing networks that require EAP authentication." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\eapsvc.dll" "Sat Jun 5 13:04:57 2021" "
+ "edgeupdate" "Microsoft Edge Update Service (edgeupdate): Keeps your Microsoft software up to date. If this service is disabled or stopped, your Microsoft software will not be kept up to date, meaning security vulnerabilities that may arise cannot be fixed and features may not work. This service uninstalls itself when there is no Microsoft software using it." "(Verified) Microsoft Corporation" "C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" "Thu Apr 1 20:17:37 2021" "
+ "edgeupdatem" "Microsoft Edge Update Service (edgeupdatem): Keeps your Microsoft software up to date. If this service is disabled or stopped, your Microsoft software will not be kept up to date, meaning security vulnerabilities that may arise cannot be fixed and features may not work. This service uninstalls itself when there is no Microsoft software using it." "(Verified) Microsoft Corporation" "C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" "Thu Apr 1 20:17:37 2021" "
+ "EFS" "Encrypting File System (EFS): Provides the core file encryption technology used to store encrypted files on NTFS file system volumes. If this service is stopped or disabled, applications will be unable to access encrypted files." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\efssvc.dll" "Thu Dec 16 07:54:17 2021" "
+ "embeddedmode" "Embedded Mode: The Embedded Mode service enables scenarios related to Background Applications. Disabling this service will prevent Background Applications from being activated." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\embeddedmodesvc.dll" "Sat Jun 5 13:05:02 2021" "
+ "EntAppSvc" "Enterprise App Management Service: Enables enterprise application management." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\EnterpriseAppMgmtSvc.dll" "Sat Jun 5 13:05:16 2021" "
+ "EventLog" "Windows Event Log: This service manages events and event logs. It supports logging events, querying events, subscribing to events, archiving event logs, and managing event metadata. It can display events in both XML and plain text format. Stopping this service may compromise security and reliability of the system." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\wevtsvc.dll" "Thu Dec 16 07:53:06 2021" "
+ "EventSystem" "COM+ Event System: Supports System Event Notification Service (SENS), which provides automatic distribution of events to subscribing Component Object Model (COM) components. If the service is stopped, SENS will close and will not be able to provide logon and logoff notifications. If this service is disabled, any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\es.dll" "Sat Jun 5 13:05:23 2021" "
+ "Fax" "Fax: Enables you to send and receive faxes, using fax resources available on this computer or on the network." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\fxssvc.exe" "Sat Jun 5 02:34:00 2021" "
+ "fdPHost" "Function Discovery Provider Host: The FDPHOST service hosts the Function Discovery (FD) network discovery providers. These FD providers supply network discovery services for the Simple Services Discovery Protocol (SSDP) and Web Services – Discovery (WS-D) protocol. Stopping or disabling the FDPHOST service will disable network discovery for these protocols when using FD. When this service is unavailable, network services using FD and relying on these discovery protocols will be unable to find network devices or resources." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\fdPHost.dll" "Sat Jun 5 13:05:29 2021" "
+ "FDResPub" "Function Discovery Resource Publication: Publishes this computer and resources attached to this computer so they can be discovered over the network. If this service is stopped, network resources will no longer be published and they will not be discovered by other computers on the network." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\fdrespub.dll" "Sat Jun 5 13:05:29 2021" "
+ "fhsvc" "File History Service: Protects user files from accidental loss by copying them to a backup location" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\fhsvc.dll" "Thu Dec 16 07:56:54 2021" "
+ "FileSyncHelper" "FileSyncHelper: Helper service for OneDrive" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncHelper.exe" "Tue Dec 7 07:14:38 2021" "
+ "FontCache" "Windows Font Cache Service: Optimizes performance of applications by caching commonly used font data. Applications will start this service if it is not already running. It can be disabled, though doing so will degrade application performance." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\FntCache.dll" "Thu Dec 16 07:52:22 2021" "
+ "FontCache3.0.0.0" "Windows Presentation Foundation Font Cache 3.0.0.0: Optimizes performance of Windows Presentation Foundation (WPF) applications by caching commonly used font data. WPF applications will start this service if it is not already running. It can be disabled, though doing so will degrade the performance of WPF applications." "(Verified) Microsoft Corporation" "C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe" "Tue Jun 1 15:27:00 2021" "
+ "FrameServer" "Windows Camera Frame Server: Enables multiple clients to access video frames from camera devices." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\FrameServer.dll" "Thu Dec 16 07:56:42 2021" "
+ "FrameServerMonitor" "Windows Camera Frame Server Monitor: Monitors the health and state for the Windows Camera Frame Server service." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\FrameServerMonitor.dll" "Thu Dec 16 07:56:42 2021" "
+ "GoogleChromeElevationService" "Google Chrome Elevation Service (GoogleChromeElevationService): Google Chrome" "(Verified) Google LLC" "C:\Program Files\Google\Chrome\Application\96.0.4664.110\elevation_service.exe" "Sun Dec 12 08:19:40 2021" "
+ "GoTrust ID Plugin" "GoTrust ID Plugin: GoTrust ID Plugin" "(Not Verified) GOTrustID Inc." "C:\Program Files\GoTrust ID Plugin\GoTrust ID Plugin\GTFidoService.exe" "Tue Sep 8 09:46:46 2020" "
+ "GoTrustID Service" "GoTrustID Service: GoTrustID Service" "(Verified) GoTrustID Inc" "C:\Program Files\GoTrust ID Plugin\Bridge_Service.exe" "Tue Sep 8 09:47:36 2020" "
+ "gpsvc" "Group Policy Client: The service is responsible for applying settings configured by administrators for the computer and users through the Group Policy component. If the service is disabled, the settings will not be applied and applications and components will not be manageable through Group Policy. Any components or applications that depend on the Group Policy component might not be functional if the service is disabled." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\gpsvc.dll" "Thu Dec 16 07:54:21 2021" "
+ "GraphicsPerfSvc" "GraphicsPerfSvc: Graphics performance monitor service" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\GraphicsPerfSvc.dll" "Sat Jun 5 13:05:06 2021" "
+ "gupdate" "Google Update Service (gupdate): Keeps your Google software up to date. If this service is disabled or stopped, your Google software will not be kept up to date, meaning security vulnerabilities that may arise cannot be fixed and features may not work. This service uninstalls itself when there is no Google software using it." "(Verified) Google LLC" "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" "Tue Oct 12 17:43:19 2021" "
+ "gupdatem" "Google Update Service (gupdatem): Keeps your Google software up to date. If this service is disabled or stopped, your Google software will not be kept up to date, meaning security vulnerabilities that may arise cannot be fixed and features may not work. This service uninstalls itself when there is no Google software using it." "(Verified) Google LLC" "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" "Tue Oct 12 17:43:19 2021" "
+ X "HfcDisableService" "Intel(R) RST HFC Disable Service: Turns off hiberfile caching in Intel(R) RST driver." "(Verified) Intel(R) Rapid Storage Technology" "C:\WINDOWS\System32\DriverStore\FileRepository\iastorac.inf_amd64_34f570cbe7f3d6c7\HfcDisableService.exe" "Sun Oct 10 17:41:43 2021" "
+ "hidserv" "Human Interface Device Service: Activates and maintains the use of hot buttons on keyboards, remote controls and other multimedia devices. It is recommended that you keep this service running." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\hidserv.dll" "Sat Jun 5 13:05:29 2021" "
+ "HPPrintScanDoctorService" "HP Print Scan Doctor Service: " "(Verified) HP Inc." "C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe" "Mon Nov 1 19:37:39 2021" "
+ "HvHost" "HV Host Service: Provides an interface for the Hyper-V hypervisor to provide per-partition performance counters to the host operating system." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\hvhostsvc.dll" "Sat Jun 5 13:06:00 2021" "
+ "iaStorAfsService" "Intel(R) Optane(TM) Memory Service: Enables amazing system performance and responsiveness by accelerating frequently used files" "(Verified) Intel(R) Rapid Storage Technology" "C:\WINDOWS\System32\iaStorAfsService.exe" "Sun Oct 10 17:41:43 2021" "
+ "icssvc" "Windows Mobile Hotspot Service: Provides the ability to share a mobile data connection with another device." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\tetheringservice.dll" "Thu Dec 16 07:51:29 2021" "
+ "igccservice" "Intel(R) Graphics Command Center Service: Service for Intel(R) Graphics Command Center" "(Verified) Intel(R) pGFX 2020" "C:\WINDOWS\System32\DriverStore\FileRepository\igcc_dch.inf_amd64_3636ad46b8d9530e\OneApp.IGCC.WinService.exe" "Mon Jan 18 03:53:50 2021" "
+ "igfxCUIService2.0.0.0" "Intel(R) HD Graphics Control Panel Service: Service for Intel(R) HD Graphics Control Panel" "(Verified) Intel(R) pGFX 2020" "C:\WINDOWS\System32\DriverStore\FileRepository\cui_dch.inf_amd64_1e4c5c6397177db7\igfxCUIService.exe" "Mon Jan 18 03:52:30 2021" "
+ "IKEEXT" "IKE and AuthIP IPsec Keying Modules: The IKEEXT service hosts the Internet Key Exchange (IKE) and Authenticated Internet Protocol (AuthIP) keying modules. These keying modules are used for authentication and key exchange in Internet Protocol security (IPsec). Stopping or disabling the IKEEXT service will disable IKE and AuthIP key exchange with peer computers. IPsec is typically configured to use IKE or AuthIP; therefore, stopping or disabling the IKEEXT service might result in an IPsec failure and might compromise the security of the system. It is strongly recommended that you have the IKEEXT service running." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\ikeext.dll" "Thu Dec 16 07:52:47 2021" "
+ "InstallService" "Microsoft Store Install Service: Provides infrastructure support for the Microsoft Store. This service is started on demand, and if disabled then installations will not function properly." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\InstallService.dll" "Thu Dec 16 07:52:32 2021" "
+ "Intel(R) Capability Licensing Service TCP IP Interface" "Intel(R) Capability Licensing Service TCP IP Interface: Version: 1.62.321.1" "(Verified) Intel(R) Trust Services" "C:\WINDOWS\System32\DriverStore\FileRepository\iclsclient.inf_amd64_a93205b6238060e4\lib\SocketHeciServer.exe" "Thu Feb 18 04:18:02 2021" "
+ "Intel(R) TPM Provisioning Service" "Intel(R) TPM Provisioning Service: Version: 1.62.321.1" "(Verified) Intel(R) Trust Services" "C:\WINDOWS\System32\DriverStore\FileRepository\iclsclient.inf_amd64_a93205b6238060e4\lib\TPMProvisioningService.exe" "Thu Feb 18 04:18:02 2021" "
+ "iphlpsvc" "IP Helper: Provides tunnel connectivity using IPv6 transition technologies (6to4, ISATAP, Port Proxy, and Teredo), and IP-HTTPS. If this service is stopped, the computer will not have the enhanced connectivity benefits that these technologies offer." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\iphlpsvc.dll" "Thu Dec 16 07:54:50 2021" "
+ "IpxlatCfgSvc" "IP Translation Configuration Service: Configures and enables translation from v4 to v6 and vice versa" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\IpxlatCfg.dll" "Sat Jun 5 13:04:50 2021" "
+ "jhi_service" "Intel(R) Dynamic Application Loader Host Interface Service: Intel(R) Dynamic Application Loader Host Interface Service - Allows applications to access the local Intel (R) DAL" "(Verified) Intel(R) Embedded Subsystems and IP Blocks Group" "C:\WINDOWS\System32\DriverStore\FileRepository\dal.inf_amd64_b5484efd38adbe8d\jhi_service.exe" "Thu Feb 18 04:18:02 2021" "
+ "KeyIso" "CNG Key Isolation: The CNG key isolation service is hosted in the LSA process. The service provides key process isolation to private keys and associated cryptographic operations as required by the Common Criteria. The service stores and uses long-lived keys in a secure process complying with Common Criteria requirements." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\keyiso.dll" "Sat Jun 5 13:05:25 2021" "
+ "KtmRm" "KtmRm for Distributed Transaction Coordinator: Coordinates transactions between the Distributed Transaction Coordinator (MSDTC) and the Kernel Transaction Manager (KTM). If it is not needed, it is recommended that this service remain stopped. If it is needed, both MSDTC and KTM will start this service automatically. If this service is disabled, any MSDTC transaction interacting with a Kernel Resource Manager will fail and any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\msdtckrm.dll" "Sat Jun 5 13:06:02 2021" "
+ "LanmanServer" "Server: Supports file, print, and named-pipe sharing over the network for this computer. If this service is stopped, these functions will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\srvsvc.dll" "Thu Dec 16 07:53:52 2021" "
+ "LanmanWorkstation" "Workstation: Creates and maintains client network connections to remote servers using the SMB protocol. If this service is stopped, these connections will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\wkssvc.dll" "Sat Jun 5 13:05:25 2021" "
+ "lfsvc" "Geolocation Service: This service monitors the current location of the system and manages geofences (a geographical location with associated events). If you turn off this service, applications will be unable to use or receive notifications for geolocation or geofences." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\lfsvc.dll" "Sat Jun 5 13:05:29 2021" "
+ "LicenseManager" "Windows License Manager Service: Provides infrastructure support for the Microsoft Store. This service is started on demand and if disabled then content acquired through the Microsoft Store will not function properly." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\LicenseManagerSvc.dll" "Thu Dec 16 07:52:32 2021" "
+ "lltdsvc" "Link-Layer Topology Discovery Mapper: Creates a Network Map, consisting of PC and device topology (connectivity) information, and metadata describing each PC and device. If this service is disabled, the Network Map will not function properly." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\lltdsvc.dll" "Sat Jun 5 13:05:29 2021" "
+ "lmhosts" "TCP/IP NetBIOS Helper: Provides support for the NetBIOS over TCP/IP (NetBT) service and NetBIOS name resolution for clients on the network, therefore enabling users to share files, print, and log on to the network. If this service is stopped, these functions might be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows Publisher" "C:\WINDOWS\System32\svchost.exe" "Sat Jun 5 13:05:23 2021" "
+ "LMS" "Intel(R) Management and Security Application Local Management Service: Intel(R) Management and Security Application Local Management Service - Provides OS-related Intel(R) ME functionality." "(Verified) Intel Corporation" "C:\WINDOWS\System32\DriverStore\FileRepository\lms.inf_amd64_fddb643595e0b8d0\LMS.exe" "Thu Sep 2 03:06:42 2021" "
+ "LSM" "Local Session Manager: Core Windows Service that manages local user sessions. Stopping or disabling this service will result in system instability." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\lsm.dll" "Thu Dec 16 07:53:00 2021" "
+ "LxpSvc" "Language Experience Service: Provides infrastructure support for deploying and configuring localized Windows resources. This service is started on demand and, if disabled, additional Windows languages will not be deployed to the system, and Windows may not function properly." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\LanguageOverlayServer.dll" "Thu Dec 16 07:51:41 2021" "
+ "MapsBroker" "Downloaded Maps Manager: Windows service for application access to downloaded maps. This service is started on-demand by applications accessing downloaded maps. Disabling this service will prevent apps from accessing maps." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\moshost.dll" "Thu Dec 16 07:52:29 2021" "
+ "McpManagementService" "McpManagementService: Universal Print Management Service" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\McpManagementService.dll" "Thu Dec 16 07:56:40 2021" "
+ "MessagingService" "MessagingService: Service supporting text messaging and related functionality." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\MessagingService.dll" "Sat Jun 5 13:04:52 2021" "
+ "MessagingService_6a9e6" "MessagingService_6a9e6: Service supporting text messaging and related functionality." "(Verified) Microsoft Windows Publisher" "C:\WINDOWS\system32\svchost.exe" "Sat Jun 5 13:05:23 2021" "
+ "MicrosoftEdgeElevationService" "Microsoft Edge Elevation Service (MicrosoftEdgeElevationService): Keeps Microsoft Edge up to update. If this service is disabled, the application will not be kept up to date." "(Verified) Microsoft Corporation" "C:\Program Files (x86)\Microsoft\Edge\Application\96.0.1054.57\elevation_service.exe" "Tue Dec 14 03:28:21 2021" "
+ "MixedRealityOpenXRSvc" "Windows Mixed Reality OpenXR Service: Enables Mixed Reality OpenXR runtime functionality" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\MixedRealityRuntime.dll" "Sat Jun 5 18:17:04 2021" "
+ "mpssvc" "Windows Defender Firewall: Windows Defender Firewall helps to protect your computer by preventing unauthorised users from gaining access to your computer through the Internet or a network." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mpssvc.dll" "Thu Dec 16 07:52:47 2021" "
+ "MSDTC" "Distributed Transaction Coordinator: Coordinates transactions that span multiple resource managers, such as databases, message queues, and file systems. If this service is stopped, these transactions will fail. If this service is disabled, any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\msdtc.exe" "Sat Jun 5 13:06:02 2021" "
+ X "MSiSCSI" "Microsoft iSCSI Initiator Service: Manages Internet SCSI (iSCSI) sessions from this computer to remote iSCSI target devices. If this service is stopped, this computer will not be able to login or access iSCSI targets. If this service is disabled, any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\iscsiexe.dll" "Sat Jun 5 13:06:07 2021" "
+ "msiserver" "Windows Installer: Adds, modifies and removes applications provided as a Windows Installer or APPX package (*.msi, *.msp, *.appx). If this service is disabled, any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\msiexec.exe" "Sat Jun 5 13:06:10 2021" "
+ "NaturalAuthentication" "Natural Authentication: Signal aggregator service, that evaluates signals based on time, network, geolocation, bluetooth and cdf factors. Supported features are Device Unlock, Dynamic Lock and Dynamo MDM policies" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\NaturalAuth.dll" "Thu Dec 16 07:51:46 2021" "
+ "NcaSvc" "Network Connectivity Assistant: Provides DirectAccess status notification for UI components" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\ncasvc.dll" "Sat Jun 5 13:05:29 2021" "
+ "NcbService" "Network Connection Broker: Brokers connections that allow Windows Store Apps to receive notifications from the internet." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\ncbservice.dll" "Sat Jun 5 13:05:09 2021" "
+ "NcdAutoSetup" "Network Connected Devices Auto-Setup: Network Connected Devices Auto-Setup service monitors and installs qualified devices that connect to a qualified network. Stopping or disabling this service will prevent Windows from discovering and installing qualified network connected devices automatically. Users can still manually add network connected devices to a PC through the user interface." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\NcdAutoSetup.dll" "Sat Jun 5 13:06:16 2021" "
+ "Netlogon" "Netlogon: Maintains a secure channel between this computer and the domain controller for authenticating users and services. If this service is stopped, the computer may not authenticate users and services and the domain controller cannot register DNS records. If this service is disabled, any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\netlogon.dll" "Thu Dec 16 07:53:51 2021" "
+ "Netman" "Network Connections: Manages objects in the Network and Dial-Up Connections folder, in which you can view both local area network and remote connections." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\netman.dll" "Sat Jun 5 13:04:58 2021" "
+ "netprofm" "Network List Service: Identifies the networks the computer has connected to, collects and stores properties for these networks, and notifies applications when these properties change." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\netprofmsvc.dll" "Thu Dec 16 07:54:51 2021" "
+ "NetSetupSvc" "Network Setup Service: The Network Setup Service manages the installation of network drivers and permits the configuration of low-level network settings. If this service is stopped, any driver installations that are in progress may be cancelled." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\NetSetupSvc.dll" "Sat Jun 5 13:05:25 2021" "
+ X "NetTcpPortSharing" "Net.Tcp Port Sharing Service: Provides ability to share TCP ports over the net.tcp protocol." "(Verified) Microsoft Corporation" "C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe" "Sat Jun 5 13:06:50 2021" "
+ "NgcCtnrSvc" "Microsoft Passport Container: Manages local user identity keys used to authenticate the user to identity providers, as well as TPM virtual smart cards. If this service is disabled, local user identity keys and TPM virtual smart cards will not be accessible. It is recommended that you do not reconfigure this service." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\NgcCtnrSvc.dll" "Thu Dec 16 07:52:53 2021" "
+ "NgcSvc" "Microsoft Passport: Provides process isolation for cryptographic keys used to provide authentication to a user’s associated identity providers. If this service is disabled, all uses and management of these keys will not be available, which includes machine log-on and single sign-on for apps and websites. This service starts and stops automatically. It is recommended that you do not reconfigure this service." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\ngcsvc.dll" "Thu Dec 16 07:52:53 2021" "
+ "NlaSvc" "Network Location Awareness: Collects and stores configuration information for the network and notifies programmes when this information is modified. If this service is stopped, configuration information might be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\netprofmsvc.dll" "Thu Dec 16 07:54:51 2021" "
+ "NPSMSvc" "NPSMSvc: NPSM" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\npsm.dll" "Sat Jun 5 13:05:09 2021" "
+ "NPSMSvc_6a9e6" "NPSMSvc_6a9e6: Host Process for Windows Services" "(Verified) Microsoft Windows Publisher" "C:\WINDOWS\system32\svchost.exe" "Sat Jun 5 13:05:23 2021" "
+ "nsi" "Network Store Interface Service: This service delivers network notifications (e.g. interface addition/deleting etc) to user mode clients. Stopping this service will cause loss of network connectivity. If this service is disabled, any other services that explicitly depend on this service will fail to start." "(Verified) Microsoft Windows Publisher" "C:\WINDOWS\system32\svchost.exe" "Sat Jun 5 13:05:23 2021" "
+ "OneDrive Updater Service" "OneDrive Updater Service: Keeps your OneDrive up to date." "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\OneDriveUpdaterService.exe" "Tue Dec 7 07:14:41 2021" "
+ "OneSyncSvc" "Sync Host: This service synchronizes mail, contacts, calendar and various other user data. Mail and other applications dependent on this functionality will not work properly when this service is not running." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\APHostService.dll" "Fri Jun 4 20:12:00 2021" "
+ "OneSyncSvc_6a9e6" "Sync Host_6a9e6: This service synchronizes mail, contacts, calendar and various other user data. Mail and other applications dependent on this functionality will not work properly when this service is not running." "(Verified) Microsoft Windows Publisher" "C:\WINDOWS\system32\svchost.exe" "Sat Jun 5 13:05:23 2021" "
+ "p2pimsvc" "Peer Networking Identity Manager: Provides identity services for the Peer Name Resolution Protocol (PNRP) and Peer-to-Peer Grouping services. If disabled, the Peer Name Resolution Protocol (PNRP) and Peer-to-Peer Grouping services may not function, and some applications, such as HomeGroup and Remote Assistance, may not function correctly." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\pnrpsvc.dll" "Sat Jun 5 13:06:16 2021" "
+ "p2psvc" "Peer Networking Grouping: Enables multi-party communication using Peer-to-Peer Grouping. If disabled, some applications, such as HomeGroup, may not function." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\p2psvc.dll" "Sat Jun 5 13:06:16 2021" "
+ "P9RdrService" "P9RdrService: Enables trigger-starting plan9 file servers." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\p9rdrservice.dll" "Sat Jun 5 13:06:17 2021" "
+ "P9RdrService_6a9e6" "P9RdrService_6a9e6: Enables trigger-starting plan9 file servers." "(Verified) Microsoft Windows Publisher" "C:\WINDOWS\system32\svchost.exe" "Sat Jun 5 13:05:23 2021" "
+ "PcaSvc" "Program Compatibility Assistant Service: This service provides support for the Program Compatibility Assistant (PCA). PCA monitors programs installed and run by the user and detects known compatibility problems. If this service is stopped, PCA will not function properly." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\pcasvc.dll" "Thu Dec 16 07:53:34 2021" "
+ "PenService" "PenService: Pen Service" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\PenService.dll" "Thu Dec 16 07:56:21 2021" "
+ "PenService_6a9e6" "PenService_6a9e6: Pen Service" "(Verified) Microsoft Windows Publisher" "C:\WINDOWS\system32\svchost.exe" "Sat Jun 5 13:05:23 2021" "
+ "perceptionsimulation" "Windows Perception Simulation Service: Enables spatial perception simulation, virtual camera management and spatial input simulation." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\PerceptionSimulation\PerceptionSimulationService.exe" "Sat Jun 5 13:06:00 2021" "
+ "PerfHost" "Performance Counter DLL Host: Enables remote users and 64-bit processes to query performance counters provided by 32-bit DLLs. If this service is stopped, only local users and 32-bit processes will be able to query performance counters provided by 32-bit DLLs." "(Verified) Microsoft Windows" "C:\WINDOWS\SysWow64\perfhost.exe" "Sat Jun 5 13:05:55 2021" "
+ "PhoneSvc" "Phone Service: Manages the telephony state on the device" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\PhoneService.dll" "Thu Dec 16 07:51:29 2021" "
+ "PimIndexMaintenanceSvc" "Contact Data: Indexes contact data for fast contact searching. If you stop or disable this service, contacts might be missing from your search results." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\PimIndexMaintenance.dll" "Sat Jun 5 13:05:09 2021" "
+ "PimIndexMaintenanceSvc_6a9e6" "Contact Data_6a9e6: Indexes contact data for fast contact searching. If you stop or disable this service, contacts might be missing from your search results." "(Verified) Microsoft Windows Publisher" "C:\WINDOWS\system32\svchost.exe" "Sat Jun 5 13:05:23 2021" "
+ "pla" "Performance Logs & Alerts: Performance Logs and Alerts Collects performance data from local or remote computers based on preconfigured schedule parameters, then writes the data to a log or triggers an alert. If this service is stopped, performance information will not be collected. If this service is disabled, any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\pla.dll" "Sat Jun 5 13:06:10 2021" "
+ "PlugPlay" "Plug and Play: Enables a computer to recognize and adapt to hardware changes with little or no user input. Stopping or disabling this service will result in system instability." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\umpnpmgr.dll" "Sat Jun 5 13:05:39 2021" "
+ "PNRPAutoReg" "PNRP Machine Name Publication Service: This service publishes a machine name using the Peer Name Resolution Protocol. Configuration is managed via the netsh context 'p2p pnrp peer' " "(Verified) Microsoft Windows" "C:\WINDOWS\system32\pnrpauto.dll" "Sat Jun 5 13:06:16 2021" "
+ "PNRPsvc" "Peer Name Resolution Protocol: Enables serverless peer name resolution over the Internet using the Peer Name Resolution Protocol (PNRP). If disabled, some peer-to-peer and collaborative applications, such as Remote Assistance, may not function." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\pnrpsvc.dll" "Sat Jun 5 13:06:16 2021" "
+ "PolicyAgent" "IPsec Policy Agent: Internet Protocol security (IPsec) supports network-level peer authentication, data origin authentication, data integrity, data confidentiality (encryption), and replay protection. This service enforces IPsec policies created through the IP Security Policies snap-in or the command-line tool "netsh ipsec". If you stop this service, you may experience network connectivity issues if your policy requires that connections use IPsec. Also,remote management of Windows Defender Firewall is not available when this service is stopped." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\ipsecsvc.dll" "Sat Jun 5 13:05:29 2021" "
+ "Power" "Power: Manages power policy and power policy notification delivery." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\umpo.dll" "Sat Jun 5 13:04:52 2021" "
+ "PrintNotify" "Printer Extensions and Notifications: This service opens custom printer dialogue boxes and handles notifications from a remote print server or a printer. If you turn this service off, you won’t be able to see printer extensions or notifications." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\spool\drivers\x64\3\PrintConfig.dll" "Thu Dec 16 07:50:54 2021" "
+ "PrintWorkflowUserSvc" "PrintWorkflow: Provides support for Print Workflow applications. If you turn off this service, you may not be able to print successfully." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\PrintWorkflowService.dll" "Thu Dec 16 07:54:54 2021" "
+ "PrintWorkflowUserSvc_6a9e6" "PrintWorkflow_6a9e6: Provides support for Print Workflow applications. If you turn off this service, you may not be able to print successfully." "(Verified) Microsoft Windows Publisher" "C:\WINDOWS\system32\svchost.exe" "Sat Jun 5 13:05:23 2021" "
+ "ProfSvc" "User Profile Service: This service is responsible for loading and unloading user profiles. If this service is stopped or disabled, users will no longer be able to successfully sign in or sign out, apps might have problems getting to users' data, and components registered to receive profile event notifications won't receive them." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\profsvc.dll" "Thu Dec 16 07:53:44 2021" "
+ "PushToInstall" "Windows PushToInstall Service: Provides infrastructure support for the Microsoft Store. This service is started automatically and if disabled then remote installations will not function properly." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\PushToInstall.dll" "Thu Dec 16 07:52:32 2021" "
+ "QASvc" "Quick Access Service: Quick Access Service" "(Verified) Acer Incorporated" "C:\Program Files\Acer\Quick Access Service\QASvc.exe" "Thu Sep 10 13:58:18 2020" "
+ "QcomWlanSrv" "Qualcomm Atheros WLAN Driver Service: " "(Verified) Qualcomm Atheros, Inc." "C:\WINDOWS\System32\drivers\QcomWlanSrvx64.exe" "Sun Jul 18 20:19:12 2021" "
+ "QWAVE" "Quality Windows Audio Video Experience: Quality Windows Audio Video Experience (qWave) is a networking platform for Audio Video (AV) streaming applications on IP home networks. qWave enhances AV streaming performance and reliability by ensuring network quality-of-service (QoS) for AV applications. It provides mechanisms for admission control, run time monitoring and enforcement, application feedback, and traffic prioritization." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\qwave.dll" "Sat Jun 5 13:05:39 2021" "
+ "RasAuto" "Remote Access Auto Connection Manager: Creates a connection to a remote network whenever a program references a remote DNS or NetBIOS name or address." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\rasauto.dll" "Sat Jun 5 13:05:40 2021" "
+ "RasMan" "Remote Access Connection Manager: Manages dial-up and virtual private network (VPN) connections from this computer to the Internet or other remote networks. If this service is disabled, any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\rasmans.dll" "Thu Dec 16 07:54:56 2021" "
+ X "RemoteAccess" "Routing and Remote Access: Offers routing services to businesses in local area and wide area network environments." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\mprdim.dll" "Sat Jun 5 13:05:40 2021" "
+ X "RemoteRegistry" "Remote Registry: Enables remote users to modify registry settings on this computer. If this service is stopped, the registry can be modified only by users on this computer. If this service is disabled, any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\regsvc.dll" "Sat Jun 5 13:06:02 2021" "
+ "RetailDemo" "Retail Demo Service: The Retail Demo service controls device activity while the device is in retail demo mode." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\RDXService.dll" "Sat Jun 5 13:06:00 2021" "
+ "RmSvc" "Radio Management Service: Radio Management and Airplane Mode Service" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\RMapi.dll" "Sat Jun 5 13:05:40 2021" "
+ "RpcEptMapper" "RPC Endpoint Mapper: Resolves RPC interfaces identifiers to transport endpoints. If this service is stopped or disabled, programs using Remote Procedure Call (RPC) services will not function properly." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\RpcEpMap.dll" "Sat Jun 5 13:05:25 2021" "
+ "RpcLocator" "Remote Procedure Call (RPC) Locator: In Windows 2003 and earlier versions of Windows, the Remote Procedure Call (RPC) Locator service manages the RPC name service database. In Windows Vista and later versions of Windows, this service does not provide any functionality and is present for application compatibility." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\locator.exe" "Sat Jun 5 13:05:23 2021" "
+ "RpcSs" "Remote Procedure Call (RPC): The RPCSS service is the Service Control Manager for COM and DCOM servers. It performs object activations requests, object exporter resolutions and distributed garbage collection for COM and DCOM servers. If this service is stopped or disabled, programs using COM or DCOM will not function properly. It is strongly recommended that you have the RPCSS service running." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\rpcss.dll" "Thu Dec 16 07:53:43 2021" "
+ "RstMwService" "Intel(R) Storage Middleware Service: RPC endpoint service which allows communication between driver and Windows Store Application" "(Verified) Intel(R) Rapid Storage Technology" "C:\WINDOWS\System32\DriverStore\FileRepository\iastorac.inf_amd64_34f570cbe7f3d6c7\RstMwService.exe" "Sun Oct 10 17:41:43 2021" "
+ "RtkAudioUniversalService" "Realtek Audio Universal Service: Realtek Audio Universal Service" "(Verified) Realtek Semiconductor Corp." "C:\WINDOWS\System32\DriverStore\FileRepository\realtekservice.inf_amd64_f043f909bedcd504\RtkAudUService64.exe" "Wed Oct 6 20:03:40 2021" "
+ "SamSs" "Security Accounts Manager: The startup of this service signals other services that the Security Accounts Manager (SAM) is ready to accept requests. Disabling this service will prevent other services in the system from being notified when the SAM is ready, which may in turn cause those services to fail to start correctly. This service should not be disabled." "(Verified) Microsoft Windows Publisher" "C:\WINDOWS\system32\lsass.exe" "Thu Dec 16 07:53:50 2021" "
+ "SCardSvr" "Smart Card: Manages access to smart cards read by this computer. If this service is stopped, this computer will be unable to read smart cards. If this service is disabled, any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\SCardSvr.dll" "Sat Jun 5 13:05:34 2021" "
+ "ScDeviceEnum" "Smart Card Device Enumeration Service: Creates software device nodes for all smart card readers accessible to a given session. If this service is disabled, WinRT APIs will not be able to enumerate smart card readers." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\ScDeviceEnum.dll" "Sat Jun 5 13:05:34 2021" "
+ "Schedule" "Task Scheduler: Enables a user to configure and schedule automated tasks on this computer. The service also hosts multiple Windows system-critical tasks. If this service is stopped or disabled, these tasks will not be run at their scheduled times. If this service is disabled, any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\schedsvc.dll" "Sat Jun 5 13:05:12 2021" "
+ "SCPolicySvc" "Smart Card Removal Policy: Allows the system to be configured to lock the user desktop upon smart card removal." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\certprop.dll" "Sat Jun 5 13:05:34 2021" "
+ "SDRSVC" "Windows Backup: Provides Windows Backup and Restore capabilities." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\SDRSVC.dll" "Sat Jun 5 13:06:00 2021" "
+ "seclogon" "Secondary Logon: Enables starting processes under alternate credentials. If this service is stopped, this type of log-on access will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\seclogon.dll" "Sat Jun 5 13:05:39 2021" "
+ "SecurityHealthService" "Windows Security Service: Windows Security Service handles unified device protection and health information" "(Verified) Microsoft Windows Publisher" "C:\WINDOWS\system32\SecurityHealthService.exe" "Thu Dec 16 07:54:13 2021" "
+ "SEMgrSvc" "Payments and NFC/SE Manager: Manages payments and Near Field Communication (NFC) based secure elements." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\SEMgrSvc.dll" "Sat Jun 5 13:05:05 2021" "
+ "SENS" "System Event Notification Service: Monitors system events and notifies subscribers to COM+ Event System of these events." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\sens.dll" "Sat Jun 5 13:05:40 2021" "
+ "SensorDataService" "Sensor Data Service: Delivers data from a variety of sensors" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\SensorDataService.exe" "Sat Jun 5 13:05:27 2021" "
+ "SensorService" "Sensor Service: A service for sensors that manages different sensors' functionality. Manages Simple Device Orientation (SDO) and History for sensors. Loads the SDO sensor that reports device orientation changes. If this service is stopped or disabled, the SDO sensor will not be loaded and so auto-rotation will not occur. History collection from Sensors will also be stopped." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\SensorService.dll" "Thu Dec 16 07:53:06 2021" "
+ "SensrSvc" "Sensor Monitoring Service: Monitors various sensors in order to expose data and adapt to system and user state. If this service is stopped or disabled, the display brightness will not adapt to lighting conditions. Stopping this service may affect other system functionality and features as well." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\sensrsvc.dll" "Sat Jun 5 13:05:33 2021" "
+ "SessionEnv" "Remote Desktop Configuration: Remote Desktop Configuration service (RDCS) is responsible for all Remote Desktop Services and Remote Desktop related configuration and session maintenance activities that require SYSTEM context. These include per-session temporary folders, RD themes, and RD certificates." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\sessenv.dll" "Sat Jun 5 13:06:14 2021" "
+ "SgrmBroker" "System Guard Runtime Monitor Broker: Monitors and attests to the integrity of the Windows platform." "(Verified) Microsoft Windows Publisher" "C:\WINDOWS\system32\SgrmBroker.exe" "Sat Jun 5 13:06:00 2021" "
+ "SharedAccess" "Internet Connection Sharing (ICS): Provides network address translation, addressing, name resolution and/or intrusion prevention services for a home or small office network." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\ipnathlp.dll" "Sat Jun 5 13:05:40 2021" "
+ "SharedRealitySvc" "Spatial Data Service: This service is used for Spatial Perception scenarios" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\SharedRealitySvc.dll" "Sat Jun 5 13:06:16 2021" "
+ "ShellHWDetection" "Shell Hardware Detection: Provides notifications for AutoPlay hardware events." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\shsvcs.dll" "Sat Jun 5 13:06:05 2021" "
+ X "shpamsvc" "Shared PC Account Manager: Manages profiles and accounts on a SharedPC configured device" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\Windows.SharedPC.AccountManager.dll" "Sat Jun 5 13:05:19 2021" "
+ "smphost" "Microsoft Storage Spaces SMP: Host service for the Microsoft Storage Spaces management provider. If this service is stopped or disabled, Storage Spaces cannot be managed." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\smphost.dll" "Sat Jun 5 13:06:02 2021" "
+ "SmsRouter" "Microsoft Windows SMS Router Service.: Routes messages based on rules to appropriate clients." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\SmsRouterSvc.dll" "Thu Dec 16 07:56:20 2021" "
+ X "SNMPTrap" "SNMP Trap: Receives trap messages generated by local or remote Simple Network Management Protocol (SNMP) agents and forwards the messages to SNMP management programs running on this computer. If this service is stopped, SNMP-based programs on this computer will not receive SNMP trap messages. If this service is disabled, any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\snmptrap.exe" "Sat Jun 5 13:05:34 2021" "
+ "spectrum" "Windows Perception Service: Enables spatial perception, spatial input, and holographic rendering." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\spectrum.exe" "Thu Dec 16 07:56:55 2021" "
+ "Spooler" "Print Spooler: This service spools print jobs and handles interaction with the printer. If you turn off this service, you won’t be able to print or see your printers." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\spoolsv.exe" "Thu Dec 16 07:51:44 2021" "
+ "sppsvc" "Software Protection: Enables the download, installation and enforcement of digital licenses for Windows and Windows applications. If the service is disabled, the operating system and licensed applications may run in a notification mode. It is strongly recommended that you not disable the Software Protection service." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\sppsvc.exe" "Thu Dec 16 07:54:28 2021" "
+ "SSDPSRV" "SSDP Discovery: Discovers networked devices and services that use the SSDP discovery protocol, such as UPnP devices. Also announces SSDP devices and services running on the local computer. If this service is stopped, SSDP-based devices will not be discovered. If this service is disabled, any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\ssdpsrv.dll" "Sat Jun 5 13:06:00 2021" "
+ X "ssh-agent" "OpenSSH Authentication Agent: Agent to hold private keys used for public key authentication." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\OpenSSH\ssh-agent.exe" "Fri Jun 4 18:53:00 2021" "
+ "SstpSvc" "Secure Socket Tunneling Protocol Service: Provides support for the Secure Socket Tunneling Protocol (SSTP) to connect to remote computers using VPN. If this service is disabled, users will not be able to use SSTP to access remote servers." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\sstpsvc.dll" "Sat Jun 5 13:05:40 2021" "
+ "StateRepository" "State Repository Service: Provides required infrastructure support for the application model." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\windows.staterepository.dll" "Thu Dec 16 07:52:36 2021" "
+ "StiSvc" "Windows Image Acquisition (WIA): Provides image acquisition services for scanners and cameras" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\wiaservc.dll" "Thu Dec 16 07:56:31 2021" "
+ "StorSvc" "Storage Service: Provides enabling services for storage settings and external storage expansion" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\storsvc.dll" "Thu Dec 16 07:56:31 2021" "
+ "svsvc" "Spot Verifier: Verifies potential file system corruptions." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\svsvc.dll" "Sat Jun 5 13:06:15 2021" "
+ "swprv" "Microsoft Software Shadow Copy Provider: Manages software-based volume shadow copies taken by the Volume Shadow Copy service. If this service is stopped, software-based volume shadow copies cannot be managed. If this service is disabled, any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\swprv.dll" "Thu Dec 16 07:53:11 2021" "
+ "SysMain" "SysMain: Maintains and improves system performance over time." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\sysmain.dll" "Thu Dec 16 07:56:56 2021" "
+ "SystemEventsBroker" "System Events Broker: Coordinates execution of background work for WinRT application. If this service is stopped or disabled, then background work might not be triggered." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\SystemEventsBrokerServer.dll" "Sat Jun 5 13:05:09 2021" "
+ "TabletInputService" "Touch Keyboard and Handwriting Panel Service: Enables Touch Keyboard and Handwriting Panel pen and ink functionality" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\TabSvc.dll" "Sat Jun 5 13:05:12 2021" "
+ "TapiSrv" "Telephony: Provides Telephony API (TAPI) support for programs that control telephony devices on the local computer and, through the LAN, on servers that are also running the service." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\tapisrv.dll" "Sat Jun 5 13:06:13 2021" "
+ "TermService" "Remote Desktop Services: Allows users to connect interactively to a remote computer. Remote Desktop and Remote Desktop Session Host Server depend on this service. To prevent remote use of this computer, clear the checkboxes on the Remote tab of the System properties control panel item." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\termsrv.dll" "Thu Dec 16 07:56:44 2021" "
+ "Themes" "Themes: Provides user experience theme management." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\themeservice.dll" "Sat Jun 5 13:05:14 2021" "
+ "TieringEngineService" "Storage Tiers Management: Optimizes the placement of data in storage tiers on all tiered storage spaces in the system." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\TieringEngineService.exe" "Sat Jun 5 13:06:13 2021" "
+ "TimeBrokerSvc" "Time Broker: Coordinates execution of background work for WinRT application. If this service is stopped or disabled, then background work might not be triggered." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\TimeBrokerServer.dll" "Sat Jun 5 13:05:09 2021" "
+ "TokenBroker" "Web Account Manager: This service is used by Web Account Manager to provide single-sign-on to apps and services." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\TokenBroker.dll" "Thu Dec 16 07:52:14 2021" "
+ "TrkWks" "Distributed Link Tracking Client: Maintains links between NTFS files within a computer or across computers in a network." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\trkwks.dll" "Sat Jun 5 13:05:23 2021" "
+ "TroubleshootingSvc" "Recommended Troubleshooting Service: Enables automatic mitigation for known problems by applying recommended troubleshooting. If stopped, your device will not get recommended troubleshooting for problems on your device." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\MitigationClient.dll" "Sat Jun 5 13:04:52 2021" "
+ "TrustedInstaller" "Windows Modules Installer: Enables installation, modification, and removal of Windows updates and optional components. If this service is disabled, install or uninstall of Windows updates might fail for this computer." "(Verified) Microsoft Windows" "C:\WINDOWS\servicing\TrustedInstaller.exe" "Thu Dec 16 07:55:09 2021" "
+ X "tzautoupdate" "Auto Time Zone Updater: Automatically sets the system time zone." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\tzautoupdate.dll" "Thu Dec 16 07:52:51 2021" "
+ "UdkUserSvc" "Udk User Service: Shell components service" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\windowsudkservices.shellcommon.dll" "Thu Dec 16 07:53:02 2021" "
+ "UdkUserSvc_6a9e6" "Udk User Service_6a9e6: Shell components service" "(Verified) Microsoft Windows Publisher" "C:\WINDOWS\system32\svchost.exe" "Sat Jun 5 13:05:23 2021" "
+ "UEIPSvc" "User Experience Improvement Program: UEIPSvc" "(Verified) Acer Incorporated" "C:\Program Files\Acer\User Experience Improvement Program Service\Framework\UBTService.exe" "Sun Aug 9 21:39:42 2020" "
+ X "uhssvc" "Microsoft Update Health Service: Maintains Update Health" "(Verified) Microsoft Windows" "C:\Program Files\Microsoft Update Health Tools\uhssvc.exe" "Mon Oct 25 22:43:24 2021" "
+ "UmRdpService" "Remote Desktop Services UserMode Port Redirector: Allows the redirection of Printers/Drives/Ports for RDP connections" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\umrdp.dll" "Sat Jun 5 13:06:13 2021" "
+ "UnistoreSvc" "User Data Storage: Handles storage of structured user data, including contact info, calendars, messages and other content. If you stop or disable this service, apps that use this data might not work correctly." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\unistore.dll" "Sat Jun 5 13:05:09 2021" "
+ "UnistoreSvc_6a9e6" "User Data Storage_6a9e6: Handles storage of structured user data, including contact info, calendars, messages and other content. If you stop or disable this service, apps that use this data might not work correctly." "(Verified) Microsoft Windows Publisher" "C:\WINDOWS\System32\svchost.exe" "Sat Jun 5 13:05:23 2021" "
+ "upnphost" "UPnP Device Host: Allows UPnP devices to be hosted on this computer. If this service is stopped, any hosted UPnP devices will stop functioning and no additional hosted devices can be added. If this service is disabled, any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\upnphost.dll" "Sat Jun 5 13:06:00 2021" "
+ "UserDataSvc" "User Data Access: Provides apps with access to structured user data, including contact info, calendars, messages and other content. If you stop or disable this service, apps that use this data might not work correctly." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\userdataservice.dll" "Sat Jun 5 13:05:09 2021" "
+ "UserDataSvc_6a9e6" "User Data Access_6a9e6: Provides apps with access to structured user data, including contact info, calendars, messages and other content. If you stop or disable this service, apps that use this data might not work correctly." "(Verified) Microsoft Windows Publisher" "C:\WINDOWS\system32\svchost.exe" "Sat Jun 5 13:05:23 2021" "
+ "UserManager" "User Manager: User Manager provides the runtime components required for multi-user interaction. If this service is stopped, some applications may not operate correctly." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\usermgr.dll" "Thu Dec 16 07:53:54 2021" "
+ "UsoSvc" "Update Orchestrator Service: Manages Windows Updates. If stopped, your devices will not be able to download and install the latest updates." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\usosvc.dll" "Thu Dec 16 07:53:09 2021" "
+ "VacSvc" "Volumetric Audio Compositor Service: Hosts spatial analysis for Mixed Reality audio simulation." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\vac.dll" "Sat Jun 5 13:04:53 2021" "
+ "VaultSvc" "Credential Manager: Provides secure storage and retrieval of credentials to users, applications and security service packages." "(Verified) Microsoft Windows" "C:\Windows\System32\vaultsvc.dll" "Sat Jun 5 13:05:12 2021" "
+ "vds" "Virtual Disk: Provides management services for disks, volumes, file systems, and storage arrays." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\vds.exe" "Thu Dec 16 07:53:03 2021" "
+ "vmicguestinterface" "Hyper-V Guest Service Interface: Provides an interface for the Hyper-V host to interact with specific services running inside the virtual machine." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\icsvc.dll" "Sat Jun 5 13:06:16 2021" "
+ "vmicheartbeat" "Hyper-V Heartbeat Service: Monitors the state of this virtual machine by reporting a heartbeat at regular intervals. This service helps you identify running virtual machines that have stopped responding." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\icsvc.dll" "Sat Jun 5 13:06:16 2021" "
+ "vmickvpexchange" "Hyper-V Data Exchange Service: Provides a mechanism to exchange data between the virtual machine and the operating system running on the physical computer." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\icsvc.dll" "Sat Jun 5 13:06:16 2021" "
+ "vmicrdv" "Hyper-V Remote Desktop Virtualization Service: Provides a platform for communication between the virtual machine and the operating system running on the physical computer." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\icsvcext.dll" "Sat Jun 5 13:06:16 2021" "
+ "vmicshutdown" "Hyper-V Guest Shutdown Service: Provides a mechanism to shut down the operating system of this virtual machine from the management interfaces on the physical computer." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\icsvc.dll" "Sat Jun 5 13:06:16 2021" "
+ "vmictimesync" "Hyper-V Time Synchronization Service: Synchronizes the system time of this virtual machine with the system time of the physical computer." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\icsvc.dll" "Sat Jun 5 13:06:16 2021" "
+ "vmicvmsession" "Hyper-V PowerShell Direct Service: Provides a mechanism to manage virtual machine with PowerShell via VM session without a virtual network." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\icsvc.dll" "Sat Jun 5 13:06:16 2021" "
+ "vmicvss" "Hyper-V Volume Shadow Copy Requestor: Coordinates the communications that are required to use Volume Shadow Copy Service to back up applications and data on this virtual machine from the operating system on the physical computer." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\icsvcvss.dll" "Sat Jun 5 13:06:16 2021" "
+ "VSS" "Volume Shadow Copy: Manages and implements Volume Shadow Copies used for backup and other purposes. If this service is stopped, shadow copies will be unavailable for backup and the backup may fail. If this service is disabled, any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\vssvc.exe" "Thu Dec 16 07:53:11 2021" "
+ "W32Time" "Windows Time: Maintains date and time synchronization on all clients and servers in the network. If this service is stopped, date and time synchronization will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\w32time.dll" "Thu Dec 16 07:51:50 2021" "
+ "WaaSMedicSvc" "Windows Update Medic Service: Enables remediation and protection of Windows Update components." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\WaaSMedicSvc.dll" "Thu Dec 16 07:52:33 2021" "
+ "WalletService" "WalletService: Hosts objects used by clients of the wallet" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\WalletService.dll" "Thu Dec 16 08:01:10 2021" "
+ "WarpJITSvc" "Warp JIT Service: Enables JIT compilation support in d3d10warp.dll for processes in which code generation is disabled." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Windows.WARP.JITService.dll" "Sat Jun 5 13:05:06 2021" "
+ "wbengine" "Block Level Backup Engine Service: The WBENGINE service is used by Windows Backup to perform backup and recovery operations. If this service is stopped by a user, it may cause the currently running backup or recovery operation to fail. Disabling this service may disable backup and recovery operations using Windows Backup on this computer." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wbengine.exe" "Sat Jun 5 13:06:48 2021" "
+ "WbioSrvc" "Windows Biometric Service: The Windows biometric service gives client applications the ability to capture, compare, manipulate, and store biometric data without gaining direct access to any biometric hardware or samples. The service is hosted in a privileged SVCHOST process." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\wbiosrvc.dll" "Sat Jun 5 13:05:16 2021" "
+ "Wcmsvc" "Windows Connection Manager: Makes automatic connect/disconnect decisions based on the network connectivity options currently available to the PC and enables management of network connectivity based on Group Policy settings." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\wcmsvc.dll" "Thu Dec 16 07:51:50 2021" "
+ "wcncsvc" "Windows Connect Now - Config Registrar: WCNCSVC hosts the Windows Connect Now Configuration, which is Microsoft's Implementation of the Wireless Protected Setup (WPS) protocol. This is used to configure Wireless LAN settings for an Access Point (AP) or a Wireless Device. The service is started programmatically as needed." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\wcncsvc.dll" "Sat Jun 5 13:04:59 2021" "
+ "WdiServiceHost" "Diagnostic Service Host: The Diagnostic Service Host is used by the Diagnostic Policy Service to host diagnostics that need to run in a Local Service context. If this service is stopped, any diagnostics that depend on it will no longer function." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wdi.dll" "Sat Jun 5 13:05:29 2021" "
+ "WdiSystemHost" "Diagnostic System Host: The Diagnostic System Host is used by the Diagnostic Policy Service to host diagnostics that need to run in a Local System context. If this service is stopped, any diagnostics that depend on it will no longer function." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wdi.dll" "Sat Jun 5 13:05:29 2021" "
+ "WdNisSvc" "Microsoft Defender Antivirus Network Inspection Service: Helps guard against intrusion attempts targeting known and newly discovered vulnerabilities in network protocols" "(Verified) Microsoft Windows Publisher" "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2111.5-0\NisSrv.exe" "Thu Dec 16 00:20:53 2021" "
+ "WebClient" "WebClient: Enables Windows-based programs to create, access, and modify Internet-based files. If this service is stopped, these functions will not be available. If this service is disabled, any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\webclnt.dll" "Thu Dec 16 07:56:56 2021" "
+ "Wecsvc" "Windows Event Collector: This service manages persistent subscriptions to events from remote sources that support WS-Management protocol. This includes Windows Vista event logs, hardware and IPMI-enabled event sources. The service stores forwarded events in a local Event Log. If this service is stopped or disabled event subscriptions cannot be created and forwarded events cannot be accepted." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wecsvc.dll" "Sat Jun 5 13:06:05 2021" "
+ "WEPHOSTSVC" "Windows Encryption Provider Host Service: Windows Encryption Provider Host Service brokers encryption related functionalities from 3rd Party Encryption Providers to processes that need to evaluate and apply EAS policies. Stopping this will compromise EAS compliancy checks that have been established by the connected Mail Accounts" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wephostsvc.dll" "Sat Jun 5 13:06:05 2021" "
+ "wercplsupport" "Problem Reports Control Panel Support: This service provides support for viewing, sending and deletion of system-level problem reports for the Problem Reports control panel." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\wercplsupport.dll" "Sat Jun 5 13:06:05 2021" "
+ "WerSvc" "Windows Error Reporting Service: Allows errors to be reported when programs stop working or responding and allows existing solutions to be delivered. Also allows logs to be generated for diagnostic and repair services. If this service is stopped, error reporting might not work correctly and results of diagnostic services and repairs might not be displayed." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\WerSvc.dll" "Sat Jun 5 13:05:25 2021" "
+ "WFDSConMgrSvc" "Wi-Fi Direct Services Connection Manager Service: Manages connections to wireless services, including wireless display and docking." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\wfdsconmgrsvc.dll" "Sat Jun 5 13:05:00 2021" "
+ "WiaRpc" "Still Image Acquisition Events: Launches applications associated with still image acquisition events." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\wiarpc.dll" "Thu Dec 16 07:56:31 2021" "
+ "WinDefend" "Microsoft Defender Antivirus Service: Helps protect users from malware and other potentially unwanted software" "(Verified) Microsoft Windows Publisher" "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2111.5-0\MsMpEng.exe" "Thu Dec 16 00:20:53 2021" "
+ "WinHttpAutoProxySvc" "WinHTTP Web Proxy Auto-Discovery Service: WinHTTP implements the client HTTP stack and provides developers with a Win32 API and COM Automation component for sending HTTP requests and receiving responses. In addition, WinHTTP provides support for auto-discovering a proxy configuration via its implementation of the Web Proxy Auto-Discovery (WPAD) protocol." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\winhttp.dll" "Sat Jun 5 13:05:25 2021" "
+ "Winmgmt" "Windows Management Instrumentation: Provides a common interface and object model to access management information about operating system, devices, applications and services. If this service is stopped, most Windows-based software will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wbem\WMIsvc.dll" "Sat Jun 5 13:05:14 2021" "
+ "WinRM" "Windows Remote Management (WS-Management): Windows Remote Management (WinRM) service implements the WS-Management protocol for remote management. WS-Management is a standard web services protocol used for remote software and hardware management. The WinRM service listens on the network for WS-Management requests and processes them. The WinRM Service needs to be configured with a listener using winrm.cmd command line tool or through Group Policy in order for it to listen over the network. The WinRM service provides access to WMI data and enables event collection. Event collection and subscription to events require that the service is running. WinRM messages use HTTP and HTTPS as transports. The WinRM service does not depend on IIS but is preconfigured to share a port with IIS on the same machine. The WinRM service reserves the /wsman URL prefix. To prevent conflicts with IIS, administrators should ensure that any websites hosted on IIS do not use the /wsman URL prefix." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\WsmSvc.dll" "Thu Dec 16 07:53:04 2021" "
+ "wisvc" "Windows Insider Service: Provides infrastructure support for the Windows Insider Programme. This service must remain enabled for the Windows Insider Programme to work." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\flightsettings.dll" "Thu Dec 16 07:51:40 2021" "
+ "WlanSvc" "WLAN AutoConfig: The WLANSVC service provides the logic required to configure, discover, connect to and disconnect from a wireless local area network (WLAN) as defined by IEEE 802.11 standards. It also contains the logic to turn your computer into a software access point so that other devices or computers can connect to your computer wirelessly using a WLAN adapter that can support this. Stopping or disabling the WLANSVC service will make all WLAN adapters on your computer inaccessible from the Windows networking UI. It is strongly recommended that you have the WLANSVC service running if your computer has a WLAN adapter." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\wlansvc.dll" "Thu Dec 16 07:51:52 2021" "
+ "wlidsvc" "Microsoft Account Sign-in Assistant: Enables user sign-in through Microsoft account identity services. If this service is stopped, users will not be able to logon to the computer with their Microsoft account." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wlidsvc.dll" "Thu Dec 16 07:52:13 2021" "
+ "wlpasvc" "Local Profile Assistant Service: This service provides profile management for subscriber identity modules" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\lpasvc.dll" "Thu Dec 16 07:51:22 2021" "
+ "WManSvc" "Windows Management Service: Performs management including Provisioning and Enrollment activities" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\Windows.Management.Service.dll" "Sat Jun 5 13:04:52 2021" "
+ "wmiApSrv" "WMI Performance Adapter: Provides performance library information from Windows Management Instrumentation (WMI) providers to clients on the network. This service only runs when Performance Data Helper is activated." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wbem\WmiApSrv.exe" "Sat Jun 5 13:04:58 2021" "
+ "WMPNetworkSvc" "Windows Media Player Network Sharing Service: Shares Windows Media Player libraries with other networked players and media devices using Universal Plug and Play" "(Verified) Microsoft Windows" "C:\Program Files\Windows Media Player\wmpnetwk.exe" "Sat Jun 5 02:32:00 2021" "
+ "workfolderssvc" "Work Folders: This service syncs files with the Work Folders server, enabling you to use the files on any of the PCs and devices on which you've set up Work Folders." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\workfolderssvc.dll" "Thu Dec 16 07:56:45 2021" "
+ "WpcMonSvc" "Parental Controls: Enforces parental controls for child accounts in Windows. If this service is stopped or disabled, parental controls may not be enforced." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\WpcDesktopMonSvc.dll" "Thu Dec 16 07:51:42 2021" "
+ "WPDBusEnum" "Portable Device Enumerator Service: Enforces group policy for removable mass-storage devices. Enables applications such as Windows Media Player and Image Import Wizard to transfer and synchronize content using removable mass-storage devices." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wpdbusenum.dll" "Sat Jun 5 18:17:02 2021" "
+ "WpnService" "Windows Push Notifications System Service: This service runs in session 0 and hosts the notification platform and connection provider which handles the connection between the device and WNS server." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\WpnService.dll" "Thu Dec 16 07:52:48 2021" "
+ "WpnUserService" "Windows Push Notifications User Service: This service hosts the Windows notification platform which provides support for local and push notifications. Supported notifications are tile, toast and raw." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\WpnUserService.dll" "Sat Jun 5 13:05:10 2021" "
+ "WpnUserService_6a9e6" "Windows Push Notifications User Service_6a9e6: This service hosts the Windows notification platform which provides support for local and push notifications. Supported notifications are tile, toast and raw." "(Verified) Microsoft Windows Publisher" "C:\WINDOWS\system32\svchost.exe" "Sat Jun 5 13:05:23 2021" "
+ "wscsvc" "Security Center: The WSCSVC (Windows Security Center) service monitors and reports security health settings on the computer. The health settings include firewall (on/off), antivirus (on/off/out of date), antispyware (on/off/out of date), Windows Update (automatically/manually download and install updates), User Account Control (on/off), and Internet settings (recommended/not recommended). The service provides COM APIs for independent software vendors to register and record the state of their products to the Security Center service. The Security and Maintenance UI uses the service to provide systray alerts and a graphical view of the security health states in the Security and Maintenance control panel. Network Access Protection (NAP) uses the service to report the security health states of clients to the NAP Network Policy Server to make network quarantine decisions. The service also has a public API that allows external consumers to programmatically retrieve the aggregated security health state of the system." "(Verified) Microsoft Windows Publisher" "C:\WINDOWS\System32\wscsvc.dll" "Sat Jun 5 13:04:58 2021" "
+ "WSearch" "Windows Search: Provides content indexing, property caching, and search results for files, e-mail, and other content." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\SearchIndexer.exe" "Thu Dec 16 07:52:24 2021" "
+ "wuauserv" "Windows Update: Enables the detection, download and installation of updates for Windows and other programs. If this service is disabled, users of this computer will not be able to use Windows Update or its automatic updating feature, and programs will not be able to use the Windows Update Agent (WUA) API." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wuaueng.dll" "Thu Dec 16 07:53:10 2021" "
+ "WwanSvc" "WWAN AutoConfig: This service manages mobile broadband (GSM & CDMA) data card/embedded module adapters and connections by auto-configuring the networks. It is strongly recommended that this service be kept running for best user experience of mobile broadband devices." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\wwansvc.dll" "Thu Dec 16 07:51:22 2021" "
+ "XblAuthManager" "Xbox Live Auth Manager: Provides authentication and authorisation services for interacting with Xbox Live. If this service is stopped, some applications may not operate correctly." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\XblAuthManager.dll" "Sat Jun 5 13:04:52 2021" "
+ "XblGameSave" "Xbox Live Game Save: This service syncs save data for Xbox Live save enabled games. If this service is stopped, game save data will not upload to or download from Xbox Live." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\XblGameSave.dll" "Sat Jun 5 13:04:52 2021" "
+ "XboxGipSvc" "Xbox Accessory Management Service: This service manages connected Xbox Accessories." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\XboxGipSvc.dll" "Sat Jun 5 13:04:52 2021" "
+ "XboxNetApiSvc" "Xbox Live Networking Service: This service supports the Windows.Networking.XboxLive application programming interface." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\XboxNetApiSvc.dll" "Sat Jun 5 13:06:00 2021" "
[Drivers]
[HKLM\System\CurrentControlSet\Services]
+ "1394ohci" "1394 OHCI Compliant Host Controller: 1394 OpenHCI Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\1394ohci.sys" "Sat Jun 5 13:04:44 2021" "
+ "3ware" "3ware: LSI 3ware SCSI Storport Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\3ware.sys" "Sat Jun 5 13:04:44 2021" "
+ "ACPI" "Microsoft ACPI Driver: ACPI Driver for NT" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\ACPI.sys" "Thu Dec 16 07:50:55 2021" "
+ "AcpiDev" "ACPI Devices driver: ACPI Devices Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\AcpiDev.sys" "Sat Jun 5 13:04:44 2021" "
+ "acpiex" "Microsoft ACPIEx Driver: ACPIEx Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Drivers\acpiex.sys" "Sat Jun 5 13:04:57 2021" "
+ "acpipagr" "ACPI Processor Aggregator Driver: ACPI Processor Aggregator Device Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\acpipagr.sys" "Sat Jun 5 13:04:45 2021" "
+ "AcpiPmi" "ACPI Power Meter Driver: ACPI Power Metering Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\acpipmi.sys" "Sat Jun 5 13:04:44 2021" "
+ "acpitime" "ACPI Wake Alarm Driver: ACPI Wake Alarm" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\acpitime.sys" "Sat Jun 5 13:04:45 2021" "
+ "Acx01000" "Acx01000: Audio KMDF Class Extension" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\Acx01000.sys" "Sat Jun 5 13:04:57 2021" "
+ "ADP80XX" "ADP80XX: PMC-Sierra Storport Driver For SPC8x6G SAS/SATA controller" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\ADP80XX.SYS" "Sat Jun 5 13:04:44 2021" "
+ "AFD" "Ancillary Function Driver for Winsock: Ancillary Function Driver for Winsock" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\afd.sys" "Thu Dec 16 07:53:51 2021" "
+ "afunix" "afunix: AF_UNIX socket provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\afunix.sys" "Thu Dec 16 07:54:51 2021" "
+ "ahcache" "Application Compatibility Cache: Cache Compatibility Data and Attributes for Individual PE File" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\DRIVERS\ahcache.sys" "Sat Jun 5 13:05:33 2021" "
+ "amdgpio2" "AMD GPIO Client Driver: AMD GPIO Controller Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\amdgpio2.sys" "Sat Jun 5 13:04:42 2021" "
+ "amdi2c" "AMD I2C Controller Service: AMD I2C Controller Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\amdi2c.sys" "Sat Jun 5 13:04:42 2021" "
+ "AmdK8" "AMD K8 Processor Driver: Processor Device Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\amdk8.sys" "Sat Jun 5 13:04:44 2021" "
+ "AmdPPM" "AMD Processor Driver: Processor Device Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\amdppm.sys" "Sat Jun 5 13:04:44 2021" "
+ "amdsata" "amdsata: AHCI 1.3 Device Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\amdsata.sys" "Sat Jun 5 13:04:44 2021" "
+ "amdsbs" "amdsbs: AMD Technology AHCI Compatible Controller Driver for Windows - AMD64 platform" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\amdsbs.sys" "Sat Jun 5 13:04:44 2021" "
+ "amdxata" "amdxata: Storage Filter Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\amdxata.sys" "Sat Jun 5 13:04:44 2021" "
+ "AppID" "AppID Driver: Identifies an application and enforces software restriction policies." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\appid.sys" "Thu Dec 16 07:53:35 2021" "
+ "AppleSSD" "Apple Solid State Drive Device: Apple Solid State Drive Device" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\AppleSSD.sys" "Sat Jun 5 13:04:42 2021" "
+ "applockerfltr" "Smartlocker Filter Driver: Identifies files created by authorized installers." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\applockerfltr.sys" "Sat Jun 5 13:05:21 2021" "
+ "arcsas" "Adaptec SAS/SATA-II RAID Storport's Miniport Driver: Adaptec SAS RAID WS03 Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\arcsas.sys" "Sat Jun 5 13:04:44 2021" "
+ "AsyncMac" "RAS Asynchronous Media Driver: RAS Asynchronous Media Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\asyncmac.sys" "Sat Jun 5 13:05:40 2021" "
+ "atapi" "IDE Channel: ATAPI IDE Miniport Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\atapi.sys" "Thu Dec 16 07:50:56 2021" "
+ "b06bdrv" "QLogic Network Adapter VBD: QLogic Gigabit Ethernet VBD" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\bxvbda.sys" "Sat Jun 5 13:04:44 2021" "
+ "bam" "Background Activity Moderator Driver: Controls activity of background applications" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\bam.sys" "Sat Jun 5 13:05:27 2021" "
+ "BasicDisplay" "BasicDisplay: Microsoft Basic Display Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DriverStore\FileRepository\basicdisplay.inf_amd64_a3f9d7c24b3377b3\BasicDisplay.sys" "Sat Jun 5 13:04:45 2021" "
+ "BasicRender" "BasicRender: Microsoft Basic Render Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DriverStore\FileRepository\basicrender.inf_amd64_e1a5502a3a50be4e\BasicRender.sys" "Sat Jun 5 13:04:45 2021" "
+ "bcmfn2" "bcmfn2 Service: BCM Function 2 Device Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\bcmfn2.sys" "Sat Jun 5 13:04:42 2021" "
+ "Beep" "Beep: BEEP Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Drivers\Beep.sys" "Sat Jun 5 13:05:34 2021" "
+ "bindflt" "Windows Bind Filter Driver: Binds filesystem namespaces to different locations and hides this remapping from the user" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\bindflt.sys" "Thu Dec 16 07:52:56 2021" "
+ "bowser" "Browser: NT Lan Manager Datagram Receiver Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\DRIVERS\bowser.sys" "Thu Dec 16 07:51:46 2021" "
+ "BtFilter" "BtFilter: BT Filter" "(Verified) Qualcomm Atheros, Inc." "C:\WINDOWS\System32\drivers\btfilter.sys" "Mon Jul 19 21:46:02 2021" "
+ "BthA2dp" "Microsoft Bluetooth A2dp driver: Bluetooth A2DP Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\BthA2dp.sys" "Thu Dec 16 07:50:51 2021" "
+ "BthEnum" "Bluetooth Enumerator Service: Bluetooth Bus Extender" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\BthEnum.sys" "Thu Dec 16 07:50:57 2021" "
+ "BthHFEnum" "Microsoft Bluetooth Hands-Free Profile driver: Bluetooth Hands-Free Audio and Call Control HID Enumerator" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\bthhfenum.sys" "Thu Dec 16 07:50:51 2021" "
+ "BthLEEnum" "Bluetooth Low Energy Driver: Legacy Bluetooth LE Bus Enumerator" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\Microsoft.Bluetooth.Legacy.LEEnumerator.sys" "Sat Jun 5 13:04:46 2021" "
+ "BthMini" "Bluetooth Radio Driver: Bluetooth Transport Extensibility Miniport Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\BTHMINI.sys" "Thu Dec 16 07:50:57 2021" "
+ "BTHMODEM" "Bluetooth Modem Communications Driver: Bluetooth Communications Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\bthmodem.sys" "Sat Jun 5 13:04:43 2021" "
+ "BthPan" "Bluetooth Device (Personal Area Network): Bluetooth Device (Personal Area Network)" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\bthpan.sys" "Sat Jun 5 13:04:46 2021" "
+ "BTHPORT" "Bluetooth Port Driver: Bluetooth Bus Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\BTHport.sys" "Thu Dec 16 07:50:57 2021" "
+ "BTHUSB" "Bluetooth Radio USB Driver: Bluetooth Miniport Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\BTHUSB.sys" "Thu Dec 16 07:50:57 2021" "
+ "bttflt" "Microsoft Hyper-V VHDPMEM BTT Filter: VHD BTT Filter Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\bttflt.sys" "Sat Jun 5 13:04:45 2021" "
+ "buttonconverter" "Service for Portable Device Control devices: Button Converter Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\buttonconverter.sys" "Sat Jun 5 13:04:46 2021" "
+ "CAD" "Charge Arbitration Driver: Charge Arbiration Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\CAD.sys" "Sat Jun 5 13:04:42 2021" "
+ X "cdfs" "CD/DVD File System Reader: ISO9660/Joliet File System Reader for CD/DVDs. (Core) (All pieces)" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\DRIVERS\cdfs.sys" "Sat Jun 5 13:06:02 2021" "
+ "cdrom" "CD-ROM Driver: SCSI CD-ROM Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\cdrom.sys" "Sat Jun 5 13:04:44 2021" "
+ "cht4iscsi" "cht4iscsi: Chelsio iSCSI VMiniport Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\cht4sx64.sys" "Sat Jun 5 13:04:45 2021" "
+ "cht4vbd" "Chelsio Virtual Bus Driver: Virtual Bus Driver for Chelsio ® T5/T6 Chipset" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\cht4vx64.sys" "Sat Jun 5 13:04:45 2021" "
+ "CimFS" "CimFS: CimFS driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Drivers\CimFS.sys" "Thu Dec 16 07:52:56 2021" "
+ "circlass" "Consumer IR Devices: Consumer IR Class Driver for eHome" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\circlass.sys" "Sat Jun 5 13:04:42 2021" "
+ "CldFlt" "Windows Cloud Files Filter Driver: Cloud Files Mini Filter Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\cldflt.sys" "Thu Dec 16 07:53:39 2021" "
+ "CLFS" "Common Log (CLFS): General-purpose logging service" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\CLFS.sys" "Thu Dec 16 07:53:53 2021" "
+ "CmBatt" "Microsoft ACPI Control Method Battery Driver: Control Method Battery Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\CmBatt.sys" "Sat Jun 5 13:04:45 2021" "
+ "CNG" "CNG: Kernel Cryptography, Next Generation" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Drivers\cng.sys" "Thu Dec 16 07:53:45 2021" "
+ X "cnghwassist" "CNG Hardware Assist algorithm provider: CNG Hardware Assist algorithm provider" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DRIVERS\cnghwassist.sys" "Sat Jun 5 13:05:16 2021" "
+ "CompositeBus" "Composite Bus Enumerator Driver: Multi-Transport Composite Bus Enumerator" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DriverStore\FileRepository\compositebus.inf_amd64_ab6e2caeac172387\CompositeBus.sys" "Sat Jun 5 13:04:42 2021" "
+ "condrv" "Console Driver: Console Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\condrv.sys" "Thu Dec 16 07:52:57 2021" "
+ "cpuz150" "cpuz150: " "" "File not found: C:\WINDOWS\temp\cpuz150\cpuz150_x64.sys" "Thu Dec 16 10:24:44 2021" "
+ "dam" "Desktop Activity Moderator Driver: Controls activity of desktop applications" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\dam.sys" "Thu Dec 16 07:54:08 2021" "
+ "Dfsc" "DFS Namespace Client Driver: Client driver for access to DFS Namespaces" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Drivers\dfsc.sys" "Sat Jun 5 13:05:27 2021" "
+ "dg_ssudbus" "SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.): SAMSUNG USB Composite Device Driver" "(Verified) Samsung Electronics Co., Ltd." "C:\WINDOWS\System32\drivers\ssudbus2.sys" "Tue Jun 29 05:43:52 2021" "
+ "disk" "Disk Driver: PnP Disk Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\disk.sys" "Sat Jun 5 13:04:44 2021" "
+ "dmvsc" "dmvsc: Dynamic Memory" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\dmvsc.sys" "Sat Jun 5 13:04:47 2021" "
+ "drmkaud" "Microsoft Trusted Audio Drivers: Microsoft Trusted Audio Drivers" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\drmkaud.sys" "Thu Dec 16 07:50:52 2021" "
+ "DXGKrnl" "LDDM Graphics Subsystem: Controls the underlying video driver stacks to provide fully-featured display capabilities." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\dxgkrnl.sys" "Thu Dec 16 07:52:52 2021" "
+ "ebdrv" "QLogic 10 Gigabit Ethernet Adapter VBD: QLogic 10 GigE VBD" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\evbda.sys" "Sat Jun 5 13:04:44 2021" "
+ "ebdrv0" "QLogic Legacy Ethernet Adapter VBD: QLogic 10 GigE VBD" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\evbd0a.sys" "Sat Jun 5 13:04:44 2021" "
+ "EhStorClass" "Enhanced Storage Filter Driver: Enhanced Storage Filter Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\EhStorClass.sys" "Sat Jun 5 13:06:05 2021" "
+ "EhStorTcgDrv" "Microsoft driver for storage devices supporting IEEE 1667 and TCG protocols: Microsoft driver for storage devices supporting IEEE 1667 and TCG protocols" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\EhStorTcgDrv.sys" "Sat Jun 5 13:04:42 2021" "
+ "ErrDev" "Microsoft Hardware Error Device Driver: Error Device Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\errdev.sys" "Sat Jun 5 13:04:45 2021" "
+ "ExecutionContext" "CPU Scheduler for High Performance I/O: CPU Scheduler for High Performance I/O" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Drivers\ExecutionContext.sys" "Sat Jun 5 13:05:25 2021" "
+ "exfat" "exFAT File System Driver: exFAT File System Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Drivers\exfat.sys" "Thu Dec 16 07:51:23 2021" "
+ "fastfat" "FAT12/16/32 File System Driver: Note - dependance on CDROM.SYS only if required to read/write DVD-RAM media (which appears as CD class device). (Core) (All pieces)" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Drivers\fastfat.sys" "Thu Dec 16 07:51:23 2021" "
+ "fdc" "Floppy Disk Controller Driver: Floppy Disk Controller Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\fdc.sys" "Sat Jun 5 13:04:45 2021" "
+ "FileCrypt" "FileCrypt: Windows sandboxing and encryption filter." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\filecrypt.sys" "Sat Jun 5 13:04:57 2021" "
+ "FileInfo" "File Information FS MiniFilter: Collects information about files in memory to be consumed by other system services." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\fileinfo.sys" "Sat Jun 5 13:05:23 2021" "
+ "Filetrace" "Filetrace: ETW File Trace Filter" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\filetrace.sys" "Sat Jun 5 13:05:23 2021" "
+ "flpydisk" "Floppy Disk Driver: Floppy Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\flpydisk.sys" "Sat Jun 5 13:04:45 2021" "
+ "FltMgr" "FltMgr: File System Filter Manager Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\fltmgr.sys" "Sat Jun 5 13:05:25 2021" "
+ "FsDepends" "File System Dependency Minifilter: This minifilter tracks the dependencies associated with the various nested volumes/filesystems" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\FsDepends.sys" "Sat Jun 5 13:04:57 2021" "
+ "fvevol" "BitLocker Drive Encryption Filter Driver: BitLocker Drive Encryption Filter Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DRIVERS\fvevol.sys" "Thu Dec 16 08:01:18 2021" "
+ "gencounter" "Microsoft Hyper-V Generation Counter: Virtual Machine Generation Counter" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\vmgencounter.sys" "Sat Jun 5 13:04:47 2021" "
+ "genericusbfn" "Generic USB Function Class: Generic USB Function Class Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DriverStore\FileRepository\genericusbfn.inf_amd64_dc3260bbd08046c4\genericusbfn.sys" "Sat Jun 5 13:04:46 2021" "
+ "GPIOClx0101" "Microsoft GPIO Class Extension Driver: GPIO Class Extension Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Drivers\msgpioclx.sys" "Sat Jun 5 13:05:12 2021" "
+ "GpuEnergyDrv" "GPU Energy Driver: Computes energy consumed by GPU" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\gpuenergydrv.sys" "Sat Jun 5 13:04:52 2021" "
+ "HdAudAddService" "Microsoft 1.1 UAA Function Driver for High Definition Audio Service: High Definition Audio Function Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\HdAudio.sys" "Sat Jun 5 13:04:43 2021" "
+ "HDAudBus" "Microsoft UAA Bus Driver for High Definition Audio: High Definition Audio Bus Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\HDAudBus.sys" "Sat Jun 5 13:04:43 2021" "
+ "HidBatt" "HID UPS Battery Driver: Hid Battery Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\HidBatt.sys" "Sat Jun 5 13:04:45 2021" "
+ "HidBth" "Microsoft Bluetooth HID Miniport: Bluetooth Miniport Driver for HID Devices" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\hidbth.sys" "Sat Jun 5 13:04:46 2021" "
+ "hidi2c" "Microsoft I2C HID Miniport Driver: I2C HID Miniport Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\hidi2c.sys" "Sat Jun 5 13:04:46 2021" "
+ "hidinterrupt" "Common Driver for HID Buttons implemented with interrupts: HID Button over Interrupt Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\hidinterrupt.sys" "Sat Jun 5 13:04:46 2021" "
+ "HidIr" "Microsoft Infrared HID Driver: Infrared Miniport Driver for Input Devices" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\hidir.sys" "Sat Jun 5 13:04:43 2021" "
+ "hidspi" "Microsoft SPI HID Miniport Driver: SPI HID Miniport Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\hidspi.sys" "Sat Jun 5 13:04:46 2021" "
+ "HidSpiCx" "HidSpi KMDF Class Extension: HidSpi KMDF Class Extension" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\HidSpiCx.sys" "Sat Jun 5 13:05:16 2021" "
+ "HidUsb" "Microsoft HID Class Driver: USB Miniport Driver for Input Devices" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\hidusb.sys" "Sat Jun 5 13:04:46 2021" "
+ "HpSAMD" "HpSAMD: Smart Array SAS/SATA Controller Media Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\HpSAMD.sys" "Sat Jun 5 13:04:45 2021" "
+ "Hsp" "Microsoft Pluton Service: HSP Device Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\Hsp.sys" "Thu Dec 16 07:50:57 2021" "
+ "HTTP" "HTTP Service: HTTP Service" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\HTTP.sys" "Thu Dec 16 07:53:45 2021" "
+ X "hvcrash" "hvcrash: Hyper-V Crashdump" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\hvcrash.sys" "Sat Jun 5 13:04:47 2021" "
+ "hvservice" "Microsoft Hypervisor Service Driver: Hypervisor Boot Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\hvservice.sys" "Thu Dec 16 07:51:02 2021" "
+ "HwNClx0101" "Microsoft Hardware Notifications Class Extension Driver: Hardware Notification Class Extension Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Drivers\mshwnclx.sys" "Sat Jun 5 13:05:16 2021" "
+ "hwpolicy" "Hardware Policy Driver: Contains Processor and other policies" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\hwpolicy.sys" "Sat Jun 5 13:05:25 2021" "
+ "hyperkbd" "hyperkbd: Microsoft VMBus Synthetic Keyboard Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\hyperkbd.sys" "Sat Jun 5 13:04:47 2021" "
+ "HyperVideo" "HyperVideo: Microsoft VMBus Video Device Miniport Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\HyperVideo.sys" "Sat Jun 5 13:04:47 2021" "
+ "i8042prt" "i8042 Keyboard and PS/2 Mouse Port Driver: i8042 Port Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\i8042prt.sys" "Sat Jun 5 13:04:46 2021" "
+ "iagpio" "Intel Serial IO GPIO Controller Driver: Intel(R) Serial IO GPIO Controller Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\iagpio.sys" "Sat Jun 5 13:04:42 2021" "
+ "iai2c" "Intel(R) Serial IO I2C Host Controller: Intel(R) Serial IO I2C Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\iai2c.sys" "Sat Jun 5 13:04:42 2021" "
+ "iaLPSS2i_GPIO2" "Intel(R) Serial IO GPIO Driver v2: Intel(R) Serial IO GPIO Driver v2" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2.sys" "Sat Jun 5 13:04:42 2021" "
+ "iaLPSS2i_GPIO2_BXT_P" "Intel(R) Serial IO GPIO Driver v2: Intel(R) Serial IO GPIO Driver v2" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2_BXT_P.sys" "Sat Jun 5 13:04:42 2021" "
+ "iaLPSS2i_GPIO2_CNL" "Intel(R) Serial IO GPIO Driver v2: Intel(R) Serial IO GPIO Driver v2" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2_CNL.sys" "Sat Jun 5 13:04:42 2021" "
+ "iaLPSS2i_GPIO2_GLK" "Intel(R) Serial IO GPIO Driver v2: Intel(R) Serial IO GPIO Driver v2" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2_GLK.sys" "Sat Jun 5 13:04:42 2021" "
+ "iaLPSS2i_I2C" "Intel(R) Serial IO I2C Driver v2: Intel(R) Serial IO I2C Driver v2" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\iaLPSS2i_I2C.sys" "Sat Jun 5 13:04:42 2021" "
+ "iaLPSS2i_I2C_BXT_P" "Intel(R) Serial IO I2C Driver v2: Intel(R) Serial IO I2C Driver v2" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\iaLPSS2i_I2C_BXT_P.sys" "Sat Jun 5 13:04:42 2021" "
+ "iaLPSS2i_I2C_CNL" "Intel(R) Serial IO I2C Driver v2: Intel(R) Serial IO I2C Driver v2" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\iaLPSS2i_I2C_CNL.sys" "Sat Jun 5 13:04:42 2021" "
+ "iaLPSS2i_I2C_GLK" "Intel(R) Serial IO I2C Driver v2: Intel(R) Serial IO I2C Driver v2" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\iaLPSS2i_I2C_GLK.sys" "Sat Jun 5 13:04:42 2021" "
+ "iaLPSS2_GPIO2_TGL" "Intel(R) Serial IO GPIO Driver v2: Intel(R) Serial IO GPIO Driver v2" "(Verified) Intel Corporation" "C:\WINDOWS\System32\DriverStore\FileRepository\ialpss2_gpio2_tgl.inf_amd64_c330c09d72f3e083\iaLPSS2_GPIO2_TGL.sys" "Sun Oct 10 17:41:10 2021" "
+ "iaLPSSi_GPIO" "Intel(R) Serial IO GPIO Controller Driver: Intel(R) Serial IO GPIO Controller Driver" "(Verified) Intel Corporation - Client Components Group" "C:\WINDOWS\System32\drivers\iaLPSSi_GPIO.sys" "Sat Jun 5 13:04:44 2021" "
+ "iaLPSSi_I2C" "Intel(R) Serial IO I2C Controller Driver: Intel(R) Serial IO I2C Controller Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\iaLPSSi_I2C.sys" "Sat Jun 5 13:04:43 2021" "
+ "iaStorAC" "Intel(R) Chipset SATA/PCIe RST Premium Controller: Intel(R) Rapid Storage Technology driver - x64" "(Verified) Intel(R) Rapid Storage Technology" "C:\WINDOWS\System32\drivers\iaStorAC.sys" "Sun Oct 10 17:41:43 2021" "
+ "iaStorAfs" "iaStorAfs: Identifies frequently used files for acceleration with Intel(R) Optane(TM) memory" "(Verified) Intel(R) Rapid Storage Technology" "C:\WINDOWS\System32\drivers\iaStorAfs.sys" "Sun Oct 10 17:41:43 2021" "
+ "iaStorAVC" "Intel Chipset SATA RAID Controller: Intel(R) Rapid Storage Technology driver (inbox) - x64" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\iaStorAVC.sys" "Sat Jun 5 13:04:45 2021" "
+ "iaStorV" "Intel RAID Controller Windows 7: Intel Matrix Storage Manager driver - x64" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\iaStorV.sys" "Sat Jun 5 13:04:45 2021" "
+ "ibbus" "Mellanox InfiniBand Bus/AL (Filter Driver): InfiniBand Fabric Bus Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\ibbus.sys" "Sat Jun 5 13:04:45 2021" "
+ "igfx" "igfx: Intel Graphics Kernel Mode Driver" "(Verified) Intel(R) pGFX 2020" "C:\WINDOWS\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_e36b8067470714bb\igdkmd64.sys" "Mon Jan 18 03:52:22 2021" "
+ "IndirectKmd" "Indirect Displays Kernel-Mode Driver: Kernel mode driver that implements the Indirect Displays framework." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\IndirectKmd.sys" "Sat Jun 5 13:05:16 2021" "
+ "IntcAzAudAddService" "Service for Realtek HD Audio (WDM): Realtek(r) High Definition Audio Function Driver" "(Verified) Realtek Semiconductor Corp." "C:\WINDOWS\system32\drivers\RTKVHD64.sys" "Mon May 17 19:23:48 2021" "
+ "IntcDAud" "Intel(R) Display Audio: Intel(R) Display Audio Driver" "(Verified) Intel Corporation" "C:\WINDOWS\System32\DriverStore\FileRepository\intcdaud.inf_amd64_0d1975b386430ef8\IntcDAud.sys" "Sun Oct 10 17:41:56 2021" "
+ "intelide" "intelide: Intel PCI IDE Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\intelide.sys" "Thu Dec 16 07:50:56 2021" "
+ "intelpep" "Intel(R) Power Engine Plug-in Driver: Intel Power Engine Plugin" "(Verified) Microsoft Windows Hardware Abstraction Layer Publisher" "C:\WINDOWS\System32\drivers\intelpep.sys" "Thu Dec 16 07:50:57 2021" "
+ "intelpmax" "Intel(R) Dynamic Device Peak Power Manager Driver: Intel Power Limit Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\intelpmax.sys" "Sat Jun 5 13:04:42 2021" "
+ "IntelPMT" "Intel(R) Platform Monitoring Technology Service: Intel Platform Monitoring Driver" "(Verified) Microsoft Windows Hardware Abstraction Layer Publisher" "C:\WINDOWS\System32\drivers\IntelPMT.sys" "Sat Jun 5 13:04:46 2021" "
+ "intelppm" "Intel Processor Driver: Processor Device Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\intelppm.sys" "Sat Jun 5 13:04:44 2021" "
+ "iorate" "Disk I/O Rate Filter Driver: Provides rate control for disk I/O traffic." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\iorate.sys" "Thu Dec 16 07:51:18 2021" "
+ "IpFilterDriver" "IP Traffic Filter Driver: IP Traffic Filter Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys" "Sat Jun 5 13:05:40 2021" "
+ "IPMIDRV" "IPMIDRV: WMI IPMI DRIVER" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\IPMIDrv.sys" "Sat Jun 5 13:04:45 2021" "
+ "IPNAT" "IP Network Address Translator: IP Network Address Translator" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\ipnat.sys" "Sat Jun 5 13:05:12 2021" "
+ "IPT" "IPT: IPT Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\ipt.sys" "Sat Jun 5 13:04:54 2021" "
+ "isapnp" "isapnp: PNP ISA Bus Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\isapnp.sys" "Sat Jun 5 13:04:45 2021" "
+ "iScsiPrt" "iScsiPort Driver: Microsoft iSCSI Initiator Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\msiscsi.sys" "Sat Jun 5 13:04:45 2021" "
+ "ItSas35i" "ItSas35i: Avago SAS Gen3.5 Driver (StorPort)" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\ItSas35i.sys" "Sat Jun 5 13:04:45 2021" "
+ "kbdclass" "Keyboard Class Driver: Keyboard Class Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\kbdclass.sys" "Sat Jun 5 13:04:46 2021" "
+ "kbdhid" "Keyboard HID Driver: HID Keyboard Filter Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\kbdhid.sys" "Sat Jun 5 13:04:46 2021" "
+ "kdnic" "Microsoft Kernel Debug Network Miniport (NDIS 6.20): Microsoft Kernel Debugger Network Miniport" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\kdnic.sys" "Sat Jun 5 13:04:46 2021" "
+ "KSecDD" "KSecDD: Kernel Security Support Provider Interface" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Drivers\ksecdd.sys" "Thu Dec 16 07:53:50 2021" "
+ "KSecPkg" "KSecPkg: Kernel Security Support Provider Interface Packages" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Drivers\ksecpkg.sys" "Thu Dec 16 07:53:45 2021" "
+ "ksthunk" "Kernel Streaming Thunks: Kernel Streaming WOW Thunk Service" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\ksthunk.sys" "Sat Jun 5 13:05:31 2021" "
+ "LHidFilt" "Logicool SetPoint KMDF HID Filter Driver: Logitech HID Filter Driver." "(Verified) Logitech Inc" "C:\WINDOWS\system32\DRIVERS\LHidFilt.Sys" "Sun Oct 25 08:32:28 2020" "
+ "lltdio" "Link-Layer Topology Discovery Mapper I/O Driver: Link-Layer Topology Discovery Mapper I/O Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\lltdio.sys" "Sat Jun 5 13:05:29 2021" "
+ "LMouFilt" "Logicool SetPoint KMDF Mouse Filter Driver: Logitech Mouse Filter Driver." "(Verified) Logitech Inc" "C:\WINDOWS\system32\DRIVERS\LMouFilt.Sys" "Sun Oct 25 08:32:30 2020" "
+ "LSI_SAS" "LSI_SAS: LSI Fusion-MPT SAS Driver (StorPort)" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\lsi_sas.sys" "Sat Jun 5 13:04:45 2021" "
+ "LSI_SAS2i" "LSI_SAS2i: LSI SAS Gen2 Driver (StorPort)" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\lsi_sas2i.sys" "Sat Jun 5 13:04:45 2021" "
+ "LSI_SAS3i" "LSI_SAS3i: Avago SAS Gen3 Driver (StorPort)" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\lsi_sas3i.sys" "Sat Jun 5 13:04:45 2021" "
+ "luafv" "UAC File Virtualization: Virtualizes file write failures to per-user locations." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\luafv.sys" "Sat Jun 5 13:05:33 2021" "
+ "mausbhost" "MA-USB Host Controller Driver: MA-USB Host Controller Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\mausbhost.sys" "Sat Jun 5 13:04:45 2021" "
+ "mausbip" "MA-USB IP Filter Driver: MA-USB IP Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\mausbip.sys" "Sat Jun 5 13:04:45 2021" "
+ "MbbCx" "MBB Network Adapter Class Extension: Windows Mobile Broadband Class Extension" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\MbbCx.sys" "Sat Jun 5 13:04:50 2021" "
+ "megasas2i" "megasas2i: MEGASAS2i RAID Controller Driver for Windows" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\MegaSas2i.sys" "Sat Jun 5 13:04:45 2021" "
+ "megasas35i" "megasas35i: MEGASAS RAID Controller Driver for Windows" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\megasas35i.sys" "Sat Jun 5 13:04:45 2021" "
+ "megasr" "megasr: LSI MegaRAID Software RAID Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\megasr.sys" "Sat Jun 5 13:04:45 2021" "
+ "MEIx64" "Intel(R) Management Engine Interface : Intel(R) Management Engine Interface" "(Verified) Intel(R) Embedded Subsystems and IP Blocks Group" "C:\WINDOWS\System32\DriverStore\FileRepository\heci.inf_amd64_605dda426937489f\x64\TeeDriverW10x64.sys" "Sun Oct 10 17:41:23 2021" "
+ "Microsoft_Bluetooth_AvrcpTransport" "Microsoft Bluetooth Avrcp Transport Driver: Microsoft Bluetooth Avrcp Transport Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\Microsoft.Bluetooth.AvrcpTransport.sys" "Sat Jun 5 13:04:42 2021" "
+ "mlx4_bus" "Mellanox ConnectX Bus Enumerator: MLX4 Bus Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\mlx4_bus.sys" "Sat Jun 5 13:04:45 2021" "
+ "MMCSS" "Multimedia Class Scheduler: Enables relative prioritization of work based on system-wide task priorities. This is intended mainly for multimedia applications. If this service is stopped, individual tasks resort to their default priority." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\mmcss.sys" "Sat Jun 5 13:04:54 2021" "
+ "Modem" "Modem: Modem Device Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\modem.sys" "Sat Jun 5 13:06:15 2021" "
+ "monitor" "Microsoft Monitor Class Function Driver Service: Monitor Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\monitor.sys" "Sat Jun 5 13:04:44 2021" "
+ "mouclass" "Mouse Class Driver: Mouse Class Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\mouclass.sys" "Sat Jun 5 13:04:46 2021" "
+ "mouhid" "Mouse HID Driver: HID Mouse Filter Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\mouhid.sys" "Sat Jun 5 13:04:46 2021" "
+ "mountmgr" "Mount Point Manager: Driver responsible with maintaining persistent drive letters and names for volumes" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\mountmgr.sys" "Sat Jun 5 13:05:25 2021" "
+ "mpi3drvi" "mpi3drvi: Broadcom MPI 3.0 Driver (StorPort)" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\mpi3drvi.sys" "Sat Jun 5 13:04:45 2021" "
+ "MpKsl7616e6c3" "MpKsl7616e6c3: KSLD" "(Verified) Microsoft Windows" "C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{F42925BB-0AEB-4DB0-B842-45B31F24039E}\MpKslDrv.sys" "Sat Dec 18 12:32:11 2021" "
+ "mpsdrv" "Windows Defender Firewall Authorization Driver: Windows Defender Firewall Authorization Driver is a kernel mode driver that provides deep inspection services on inbound and outbound network traffic." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\mpsdrv.sys" "Sat Jun 5 13:05:09 2021" "
+ "MRxDAV" "WebDav Client Redirector Driver: Network Redirector that provides WebDAV file access for the WebClient service" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\mrxdav.sys" "Thu Dec 16 07:56:56 2021" "
+ "mrxsmb" "SMB MiniRedirector Wrapper and Engine: Implements the framework for the SMB filesystem redirector" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\DRIVERS\mrxsmb.sys" "Thu Dec 16 07:53:54 2021" "
+ "mrxsmb20" "SMB 2.0 MiniRedirector: Implements the SMB 2.0 protocol, which provides connectivity to network resources on Windows Vista and later servers" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\DRIVERS\mrxsmb20.sys" "Thu Dec 16 07:53:54 2021" "
+ "MsBridge" "Microsoft MAC Bridge: Microsoft MAC Bridge" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\bridge.sys" "Sat Jun 5 13:06:05 2021" "
+ "Msfs" "Msfs: Mailslot driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Drivers\Msfs.sys" "Sat Jun 5 13:05:25 2021" "
+ "msgpiowin32" "Common Driver for Buttons, DockMode and Laptop/Slate Indicator: GPIO Button Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\msgpiowin32.sys" "Sat Jun 5 13:04:46 2021" "
+ "mshidkmdf" "Pass-through HID to KMDF Filter Driver: Device Filter to provide pass-through interface between HIDCLASS and KMDF" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\mshidkmdf.sys" "Sat Jun 5 13:05:16 2021" "
+ "mshidumdf" "Pass-through HID to UMDF Driver: Device Driver to provide pass-through interface between HIDCLASS and UMDF" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\mshidumdf.sys" "Sat Jun 5 13:05:14 2021" "
+ "msisadrv" "msisadrv: ISA Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\msisadrv.sys" "Sat Jun 5 13:04:45 2021" "
+ "MSKSSRV" "Microsoft Streaming Service Proxy: MS KS Server" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\MSKSSRV.sys" "Sat Jun 5 13:05:31 2021" "
+ "MsLldp" "Microsoft Link-Layer Discovery Protocol Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\mslldp.sys" "Sat Jun 5 13:05:39 2021" "
+ "MSPCLOCK" "Microsoft Streaming Clock Proxy: MS Proxy Clock" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\MSPCLOCK.sys" "Sat Jun 5 13:05:31 2021" "
+ "MSPQM" "Microsoft Streaming Quality Manager Proxy: MS Proxy Quality Manager" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\MSPQM.sys" "Sat Jun 5 13:05:31 2021" "
+ "MsQuic" "MsQuic: Microsoft® QUIC Library" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\msquic.sys" "Thu Dec 16 07:53:42 2021" "
+ "MsRPC" "MsRPC: Kernel Remote Procedure Call Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Drivers\MsRPC.sys" "Thu Dec 16 07:53:50 2021" "
+ "mssmbios" "Microsoft System Management BIOS Driver: System Management BIOS Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\mssmbios.sys" "Sat Jun 5 13:04:45 2021" "
+ "MSTEE" "Microsoft Streaming Tee/Sink-to-Sink Converter: WDM Tee/Communication Transform Filter " "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\MSTEE.sys" "Sat Jun 5 13:05:31 2021" "
+ "MTConfig" "Microsoft Input Configuration Driver: Microsoft Multi-Touch HID Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\MTConfig.sys" "Sat Jun 5 13:04:44 2021" "
+ "Mup" "Mup: Multiple UNC Provider Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Drivers\mup.sys" "Sat Jun 5 13:05:27 2021" "
+ "mvumis" "mvumis: Marvell Flash Controller Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\mvumis.sys" "Sat Jun 5 13:04:45 2021" "
+ "NativeWifiP" "NativeWiFi Filter: NativeWiFi Miniport Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\DRIVERS\nwifi.sys" "Thu Dec 16 07:51:52 2021" "
+ "ndfltr" "NetworkDirect Service: NetworkDirect Support Filter Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\ndfltr.sys" "Sat Jun 5 13:04:45 2021" "
+ "NDIS" "NDIS System Driver: NDIS System Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\ndis.sys" "Thu Dec 16 07:53:50 2021" "
+ "NdisCap" "Microsoft NDIS Capture: Microsoft NDIS Capture" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\ndiscap.sys" "Sat Jun 5 13:06:13 2021" "
+ "NdisImPlatform" "Microsoft Network Adapter Multiplexor Protocol: Microsoft Network Adapter Multiplexor Protocol" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\NdisImPlatform.sys" "Sat Jun 5 13:05:39 2021" "
+ "NdisTapi" "Remote Access NDIS TAPI Driver: Remote Access NDIS TAPI Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DRIVERS\ndistapi.sys" "Sat Jun 5 13:05:40 2021" "
+ "Ndisuio" "NDIS Usermode I/O Protocol: NDIS User mode I/O driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\ndisuio.sys" "Sat Jun 5 13:05:25 2021" "
+ "NdisVirtualBus" "Microsoft Virtual Network Adapter Enumerator: Microsoft Virtual Network Adapter Enumerator" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\NdisVirtualBus.sys" "Sat Jun 5 13:05:39 2021" "
+ "NdisWan" "Remote Access NDIS WAN Driver: Remote Access NDIS WAN Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\ndiswan.sys" "Thu Dec 16 07:54:56 2021" "
+ "ndiswanlegacy" "Remote Access LEGACY NDIS WAN Driver: Remote Access LEGACY NDIS WAN Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DRIVERS\ndiswan.sys" "Thu Dec 16 07:54:56 2021" "
+ "NDKPerf" "NDKPerf Driver: " "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\NDKPerf.sys" "Sat Jun 5 13:06:13 2021" "
+ "NDKPing" "NDKPing Driver: RDMA Sample Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\NDKPing.sys" "Sat Jun 5 13:06:13 2021" "
+ "ndproxy" "NDIS Proxy Driver: NDIS Proxy Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DRIVERS\NDProxy.sys" "Sat Jun 5 13:05:40 2021" "
+ "Ndu" "Windows Network Data Usage Monitoring Driver: This service provides network data usage monitoring functionality" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\Ndu.sys" "Sat Jun 5 13:06:00 2021" "
+ "NetAdapterCx" "Network Adapter Wdf Class Extension Library: Network Adapter Class Extension for WDF" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\NetAdapterCx.sys" "Thu Dec 16 07:53:51 2021" "
+ "NetBIOS" "NetBIOS Interface: NetBIOS Interface" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\netbios.sys" "Sat Jun 5 13:05:37 2021" "
+ "NetBT" "NetBT: This service implements NetBios over TCP/IP." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DRIVERS\netbt.sys" "Sat Jun 5 13:05:39 2021" "
+ "netvsc" "netvsc: Virtual NDIS Miniport" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\netvsc.sys" "Thu Dec 16 07:51:04 2021" "
+ "Npfs" "Npfs: NPFS Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Drivers\Npfs.sys" "Sat Jun 5 13:05:25 2021" "
+ "npsvctrig" "Named pipe service trigger provider: Named pipe service triggers" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\npsvctrig.sys" "Sat Jun 5 13:04:46 2021" "
+ "nsiproxy" "NSI Proxy Service Driver: NSI Proxy Service" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\nsiproxy.sys" "Sat Jun 5 13:05:25 2021" "
+ "nsvst_NGC" "NortonLifeLock Split Tunneling WFP Callout driver: " "" "File not found: C:\WINDOWS\System32\drivers\NGCx64\16150A0.028\nsvst.sys" "Thu Dec 16 09:32:35 2021" "
+ "Ntfs" "Ntfs: NT File System Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Drivers\Ntfs.sys" "Thu Dec 16 07:53:48 2021" "
+ "Null" "Null: NULL Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Drivers\Null.sys" "Sat Jun 5 13:05:25 2021" "
+ "nvdimm" "Microsoft NVDIMM device driver: NVDIMM device driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\nvdimm.sys" "Sat Jun 5 13:04:45 2021" "
+ "nvmedisk" "Microsoft NVMe disk driver: Nvme Disk Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\nvmedisk.sys" "Sat Jun 5 13:04:44 2021" "
+ "nvraid" "nvraid: NVIDIA® nForce(TM) RAID Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\nvraid.sys" "Sat Jun 5 13:04:45 2021" "
+ "nvstor" "nvstor: NVIDIA® nForce(TM) Sata Performance Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\nvstor.sys" "Sat Jun 5 13:04:45 2021" "
+ "P9Rdr" "Plan 9 Redirector Driver: Plan 9 Redirector Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\p9rdr.sys" "Sat Jun 5 13:06:17 2021" "
+ "Parport" "Parallel port driver: Parallel Port Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\parport.sys" "Sat Jun 5 13:04:45 2021" "
+ "partmgr" "Partition driver: Disk class filter driver that manages and auctions out partitions to volume managers." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\partmgr.sys" "Thu Dec 16 07:53:49 2021" "
+ "pci" "PCI Bus Driver: NT Plug and Play PCI Enumerator" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\pci.sys" "Thu Dec 16 07:50:56 2021" "
+ "pciide" "pciide: Generic PCI IDE Bus Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\pciide.sys" "Thu Dec 16 07:50:56 2021" "
+ "pcmcia" "pcmcia: PCMCIA Bus Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\pcmcia.sys" "Sat Jun 5 13:04:42 2021" "
+ "pcw" "Performance Counters for Windows Driver: Performance Counters for Windows Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\pcw.sys" "Sat Jun 5 13:05:25 2021" "
+ "pdc" "pdc: Power Dependency Coordinator Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\pdc.sys" "Sat Jun 5 13:04:57 2021" "
+ "PEAUTH" "PEAUTH: Protected Environment Authentication and Authorization Export Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\peauth.sys" "Thu Dec 16 07:51:39 2021" "
+ "percsas2i" "percsas2i: MEGASAS RAID Controller Driver for Windows" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\percsas2i.sys" "Sat Jun 5 13:04:45 2021" "
+ "percsas3i" "percsas3i: MEGASAS RAID Controller Driver for Windows" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\percsas3i.sys" "Sat Jun 5 13:04:45 2021" "
+ "PktMon" "Packet Monitor Driver: Packet Monitor Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\PktMon.sys" "Thu Dec 16 07:56:43 2021" "
+ "pmem" "Microsoft persistent memory disk driver: Persistent memory driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\pmem.sys" "Sat Jun 5 13:04:45 2021" "
+ "PNPMEM" "Microsoft Memory Module Driver: Plug and Play Memory Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\pnpmem.sys" "Sat Jun 5 13:04:44 2021" "
+ "portcfg" "portcfg: Port Device Class Configuration Filter Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\portcfg.sys" "Sat Jun 5 13:05:16 2021" "
+ "PptpMiniport" "WAN Miniport (PPTP): WAN Miniport (PPTP)" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\raspptp.sys" "Sat Jun 5 13:05:40 2021" "
+ "PRM" "Microsoft PRM Driver: Windows PRM Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DriverStore\FileRepository\prm.inf_amd64_7fc9bb8ba2b73803\PRM.sys" "Sat Jun 5 13:04:44 2021" "
+ "Processor" "Processor Driver: Processor Device Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\processr.sys" "Sat Jun 5 13:04:44 2021" "
+ "Psched" "QoS Packet Scheduler: QoS Packet Scheduler" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\pacer.sys" "Sat Jun 5 13:05:09 2021" "
+ "Qcamain10x64" "Qualcomm Atheros Extensible Wireless LAN 11AC device driver: Qualcomm Atheros Extensible Wireless LAN device driver" "(Verified) Qualcomm Atheros, Inc." "C:\WINDOWS\System32\drivers\Qcamain10x64.sys" "Sun Jul 18 20:19:10 2021" "
+ "QWAVEdrv" "QWAVE driver: Quality Windows Audio/Video Experience component driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\qwavedrv.sys" "Sat Jun 5 13:05:39 2021" "
+ "Ramdisk" "Windows RAM Disk Driver: RAM Disk Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\DRIVERS\ramdisk.sys" "Sat Jun 5 13:04:57 2021" "
+ "RasAcd" "Remote Access Auto Connection Driver: Remote Access Auto Connection Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DRIVERS\rasacd.sys" "Sat Jun 5 13:05:40 2021" "
+ "RasAgileVpn" "WAN Miniport (IKEv2): WAN Miniport (IKEv2)" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\AgileVpn.sys" "Thu Dec 16 07:54:56 2021" "
+ "Rasl2tp" "WAN Miniport (L2TP): WAN Miniport (L2TP)" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\rasl2tp.sys" "Sat Jun 5 13:05:40 2021" "
+ "RasPppoe" "Remote Access PPPOE Driver: Remote Access PPPOE Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DRIVERS\raspppoe.sys" "Sat Jun 5 13:05:40 2021" "
+ "RasSstp" "WAN Miniport (SSTP): WAN Miniport (SSTP)" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\rassstp.sys" "Sat Jun 5 13:05:40 2021" "
+ "rdbss" "Redirected Buffering Sub System: Provides the framework for network mini-redirectors" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\DRIVERS\rdbss.sys" "Thu Dec 16 07:53:53 2021" "
+ "rdpbus" "Remote Desktop Device Redirector Bus Driver: Microsoft RDP Bus Device driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\rdpbus.sys" "Sat Jun 5 13:04:47 2021" "
+ "RDPDR" "Remote Desktop Device Redirector Driver: Remote Desktop Device Redirector Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\rdpdr.sys" "Sat Jun 5 13:06:13 2021" "
+ "RdpVideoMiniport" "Remote Desktop Video Miniport Driver: Microsoft RDP Video Miniport driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\rdpvideominiport.sys" "Thu Dec 16 07:56:41 2021" "
+ "rdyboost" "ReadyBoost: ReadyBoost" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\rdyboost.sys" "Sat Jun 5 13:06:16 2021" "
+ "ReFS" "ReFS: NT ReFS FS Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Drivers\ReFS.sys" "Thu Dec 16 07:53:37 2021" "
+ "ReFSv1" "ReFSv1: NT ReFS FS Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Drivers\ReFSv1.sys" "Sat Jun 5 13:05:23 2021" "
+ "RFCOMM" "Bluetooth Device (RFCOMM Protocol TDI): Bluetooth Device (RFCOMM Protocol TDI)" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\rfcomm.sys" "Sat Jun 5 13:04:46 2021" "
+ "rhproxy" "Resource Hub proxy driver: ResourceHub Proxy Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\rhproxy.sys" "Sat Jun 5 13:04:44 2021" "
+ "rspndr" "Link-Layer Topology Discovery Responder: Link-Layer Topology Discovery Responder" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\rspndr.sys" "Sat Jun 5 13:05:29 2021" "
+ "rt640x64" "Realtek RT640 NT Driver: Realtek 8125/8136/8168/8169 NDIS 6.40 64-bit Driver " "(Verified) Microsoft Windows Hardware Compatibility Publisher" "C:\WINDOWS\System32\drivers\rt640x64.sys" "Wed Aug 18 05:58:04 2021" "
+ "s3cap" "s3cap: Microsoft S3 Emulated Device Cap Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\vms3cap.sys" "Sat Jun 5 13:04:47 2021" "
+ "sbp2port" "SBP-2 Transport/Protocol Bus Driver: SBP-2 Protocol Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\sbp2port.sys" "Thu Dec 16 07:50:55 2021" "
+ "scfilter" "Smart card PnP Class Filter Driver: Smart card reader filter driver enabling smart card PnP." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DRIVERS\scfilter.sys" "Sat Jun 5 13:05:34 2021" "
+ "scmbus" "Microsoft Storage Class Memory Bus Driver: Storage Class Memory Bus Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\scmbus.sys" "Thu Dec 16 07:50:56 2021" "
+ "sdbus" "sdbus: SecureDigital Bus Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\sdbus.sys" "Sat Jun 5 13:04:46 2021" "
+ "SDFRd" "SDF Reflector: SDF Reflector" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\SDFRd.sys" "Sat Jun 5 13:04:44 2021" "
+ "sdstor" "SD Storage Port Driver: SD Storage Class Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\sdstor.sys" "Thu Dec 16 07:51:00 2021" "
+ "SerCx" "Serial UART Support Library: Serial Class Extension" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\SerCx.sys" "Sat Jun 5 13:05:16 2021" "
+ "SerCx2" "Serial UART Support Library: Serial Class Extension V2" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\SerCx2.sys" "Sat Jun 5 13:05:16 2021" "
+ "Serenum" "Serenum Filter Driver: Serial Port Enumerator" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\serenum.sys" "Sat Jun 5 13:04:45 2021" "
+ "Serial" "Serial port driver: Serial Device Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\serial.sys" "Sat Jun 5 13:04:45 2021" "
+ "sermouse" "Serial Mouse Driver: Serial Mouse Filter Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\sermouse.sys" "Sat Jun 5 13:04:46 2021" "
+ "sfloppy" "High-Capacity Floppy Disk Drive: SCSI Floppy Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\sfloppy.sys" "Sat Jun 5 13:04:45 2021" "
+ "SgrmAgent" "System Guard Runtime Monitor Agent: System Guard Runtime Monitor Agent Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\SgrmAgent.sys" "Sat Jun 5 13:06:00 2021" "
+ "SiSRaid2" "SiSRaid2: SiS RAID Stor Miniport Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\SiSRaid2.sys" "Sat Jun 5 13:04:45 2021" "
+ "SiSRaid4" "SiSRaid4: SiS AHCI Stor-Miniport Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\sisraid4.sys" "Sat Jun 5 13:04:45 2021" "
+ "SmartSAMD" "SmartSAMD: Storport Miniport Driver for SmartRAID/SmartHBA Controllers" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\SmartSAMD.sys" "Sat Jun 5 13:04:45 2021" "
+ "spaceparser" "spaceparser: Storage Spaces Parser driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\spaceparser.sys" "Sat Jun 5 13:06:02 2021" "
+ "spaceport" "Storage Spaces Driver: Storage Spaces Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\spaceport.sys" "Thu Dec 16 07:50:55 2021" "
+ "SpatialGraphFilter" "Holographic Spatial Graph Filter: Holographic Spatial Graph Filter" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\SpatialGraphFilter.sys" "Sat Jun 5 18:17:02 2021" "
+ "SpbCx" "Simple Peripheral Bus Support Library: SPB Class Extension" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\SpbCx.sys" "Sat Jun 5 13:05:16 2021" "
+ "srv2" "Server SMB 2.xxx Driver: Enables connectivity from Windows Vista and later clients" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DRIVERS\srv2.sys" "Thu Dec 16 07:53:54 2021" "
+ "srvnet" "srvnet: Server Network driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DRIVERS\srvnet.sys" "Thu Dec 16 07:53:54 2021" "
+ "ssudqcfilter" "SAMSUNG Mobile USB QCRMNET Filter Driver: Filter Driver for the Qualcomm USB Driver Stack" "(Verified) Samsung Electronics Co., Ltd." "C:\WINDOWS\System32\drivers\ssudqcfilter.sys" "Tue Jun 29 05:44:08 2021" "
+ "stexstor" "stexstor: Promise SuperTrak EX Series Driver for Windows x64" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\stexstor.sys" "Sat Jun 5 13:04:45 2021" "
+ "storahci" "Microsoft Standard SATA AHCI Driver: MS AHCI Storport Miniport Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\storahci.sys" "Thu Dec 16 07:50:56 2021" "
+ "storflt" "Microsoft Hyper-V Storage Accelerator: Virtual Storage Filter Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\vmstorfl.sys" "Sat Jun 5 13:04:47 2021" "
+ "stornvme" "Microsoft Standard NVM Express Driver: Microsoft NVM Express Storport Miniport Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\stornvme.sys" "Thu Dec 16 07:50:57 2021" "
+ "storqosflt" "Storage QoS Filter Driver: Provides Quality of Service for storage I/O traffic." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\storqosflt.sys" "Sat Jun 5 13:05:16 2021" "
+ "storufs" "Microsoft Universal Flash Storage (UFS) Driver: MS UFS Storport Miniport Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\storufs.sys" "Thu Dec 16 07:50:57 2021" "
+ "storvsc" "storvsc: Storage VSC Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\storvsc.sys" "Sat Jun 5 13:04:47 2021" "
+ "swenum" "Software Bus Driver: Plug and Play Software Device Enumerator" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DriverStore\FileRepository\swenum.inf_amd64_3bf6c0d173eb26c6\swenum.sys" "Sat Jun 5 13:04:44 2021" "
+ "SymEvnt" "Symantec Eventing Platform: " "" "File not found: C:\Program Files\Norton Security\NortonData\22.20.5.40\SymPlatform\SymEvnt.sys" "Thu Dec 16 09:32:35 2021" "
+ "Tcpip" "TCP/IP Protocol Driver: TCP/IP Protocol Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\tcpip.sys" "Thu Dec 16 07:53:51 2021" "
+ "Tcpip6" "@todo.dll,-100;Microsoft IPv6 Protocol Driver: @todo.dll,-100;Microsoft IPv6 Protocol Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\tcpip.sys" "Thu Dec 16 07:53:51 2021" "
+ "tcpipreg" "@%SystemRoot%\System32\drivers\tcpipreg.sys,-10110,: TCP/IP Registry Compatibility Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\tcpipreg.sys" "Thu Dec 16 07:53:51 2021" "
+ "tdx" "NetIO Legacy TDI Support Driver: NetIO Legacy TDI Support Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\DRIVERS\tdx.sys" "Thu Dec 16 07:56:20 2021" "
+ "terminpt" "Microsoft Remote Desktop Input Driver: Terminal Server Input Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\terminpt.sys" "Sat Jun 5 13:04:47 2021" "
+ "TPM" "TPM: TPM Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\tpm.sys" "Thu Dec 16 07:51:00 2021" "
+ "TsUsbFlt" "Remote Desktop USB Hub Class Filter Driver: Remote Desktop USB Hub Class Filter Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\tsusbflt.sys" "Sat Jun 5 13:04:57 2021" "
+ "TsUsbGD" "Remote Desktop Generic USB Device: Remote Desktop Generic USB Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\TsUsbGD.sys" "Sat Jun 5 13:04:46 2021" "
+ "tunnel" "Microsoft Tunnel Miniport Adapter Driver: Microsoft Tunnel Interface Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\tunnel.sys" "Sat Jun 5 13:05:37 2021" "
+ "UASPStor" "USB Attached SCSI (UAS) Driver: Microsoft Uasp Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\uaspstor.sys" "Sat Jun 5 13:04:45 2021" "
+ "UcmCx0101" "USB Connector Manager KMDF Class Extension: USB Connector Manager KMDF Class Extension" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Drivers\UcmCx.sys" "Sat Jun 5 13:05:16 2021" "
+ "UcmTcpciCx0101" "UCM-TCPCI KMDF Class Extension: UCM-TCPCI KMDF Class Extension" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Drivers\UcmTcpciCx.sys" "Sat Jun 5 13:05:16 2021" "
+ "UcmUcsiAcpiClient" "UCM-UCSI ACPI Client: UCM-UCSI ACPI Client Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\UcmUcsiAcpiClient.sys" "Sat Jun 5 13:04:46 2021" "
+ "UcmUcsiCx0101" "UCM-UCSI KMDF Class Extension: UCM-UCSI KMDF Class Extension" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Drivers\UcmUcsiCx.sys" "Sat Jun 5 13:05:16 2021" "
+ "Ucx01000" "USB Host Support Library: USB Controller Extension" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\ucx01000.sys" "Sat Jun 5 13:04:57 2021" "
+ "UdeCx" "USB Device Emulation Support Library: "udecx.DRIVER"" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\udecx.sys" "Sat Jun 5 13:04:57 2021" "
+ X "udfs" "udfs: Reads/Writes UDF 1.02,1.5,2.0x,2.5 disc formats, usually found on C/DVD discs. (Core) (All pieces)" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\DRIVERS\udfs.sys" "Sat Jun 5 13:06:14 2021" "
+ "UEFI" "Microsoft UEFI Driver: UEFI Driver for NT" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DriverStore\FileRepository\uefi.inf_amd64_fb341504564fabc5\UEFI.sys" "Sat Jun 5 13:04:44 2021" "
+ "Ufx01000" "USB Function Class Extension: USB Function Driver Class Extension" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\ufx01000.sys" "Sat Jun 5 13:05:16 2021" "
+ "UfxChipidea" "USB Chipidea Controller: UFX Chipidea Client Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DriverStore\FileRepository\ufxchipidea.inf_amd64_a517b810ee0e44a2\UfxChipidea.sys" "Sat Jun 5 13:04:46 2021" "
+ "ufxsynopsys" "USB Synopsys Controller: UFX Synopsys Client Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\ufxsynopsys.sys" "Sat Jun 5 13:04:46 2021" "
+ "umbus" "UMBus Enumerator Driver: User-Mode Bus Enumerator" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DriverStore\FileRepository\umbus.inf_amd64_0a89aff902a5c3a9\umbus.sys" "Sat Jun 5 13:04:45 2021" "
+ "UmPass" "Microsoft UMPass Driver: Generic pass-through driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\umpass.sys" "Sat Jun 5 13:04:46 2021" "
+ "UrsChipidea" "Chipidea USB Role-Switch Driver: USB Role-Switch Driver for Chipidea Core" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DriverStore\FileRepository\urschipidea.inf_amd64_4bd4df2779fd9e16\urschipidea.sys" "Sat Jun 5 13:04:46 2021" "
+ "UrsCx01000" "USB Role-Switch Support Library: USB Role-Switch Class Extension" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\urscx01000.sys" "Sat Jun 5 13:05:16 2021" "
+ "UrsSynopsys" "Synopsys USB Role-Switch Driver: USB Role-Switch Driver for Synopsys Core" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DriverStore\FileRepository\urssynopsys.inf_amd64_28522251903b4825\urssynopsys.sys" "Sat Jun 5 13:04:46 2021" "
+ "Usb4DeviceRouter" "USB4 Device Router Service: USB4(TM) Device Router Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DriverStore\FileRepository\usb4devicerouter.inf_amd64_8d9a17bd8e5b4b11\Usb4DeviceRouter.sys" "Thu Dec 16 07:50:57 2021" "
+ "Usb4HostRouter" "USB4 Host Router Service: USB4(TM) Host Router Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DriverStore\FileRepository\usb4hostrouter.inf_amd64_acb1b78bb0ae3528\Usb4HostRouter.sys" "Thu Dec 16 07:50:58 2021" "
+ "usbaudio" "USB Audio Driver (WDM): USB Audio Class Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\usbaudio.sys" "Sat Jun 5 13:04:43 2021" "
+ "usbaudio2" "USB Audio 2.0 Service: Microsoft USB Audio Class 2.0 Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\usbaudio2.sys" "Sat Jun 5 13:04:43 2021" "
+ "usbccgp" "Microsoft USB Generic Parent Driver: USB Common Class Generic Parent Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\usbccgp.sys" "Sat Jun 5 13:04:46 2021" "
+ "usbcir" "eHome Infrared Receiver (USBCIR): USB Consumer IR Driver for eHome" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\usbcir.sys" "Sat Jun 5 13:04:43 2021" "
+ "usbehci" "Microsoft USB 2.0 Enhanced Host Controller Miniport Driver: EHCI eUSB Miniport Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\usbehci.sys" "Sat Jun 5 13:04:46 2021" "
+ "usbhub" "Microsoft USB Standard Hub Driver: Default Hub Driver for USB" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\usbhub.sys" "Sat Jun 5 13:04:46 2021" "
+ "USBHUB3" "SuperSpeed Hub: USB3 HUB Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\UsbHub3.sys" "Thu Dec 16 07:51:00 2021" "
+ "usbohci" "Microsoft USB Open Host Controller Miniport Driver: OHCI USB Miniport Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\usbohci.sys" "Sat Jun 5 13:04:46 2021" "
+ "usbprint" "Microsoft USB PRINTER Class: USB Printer driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\usbprint.sys" "Thu Dec 16 07:50:55 2021" "
+ "usbser" "Microsoft USB Serial Driver: USB Serial Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\usbser.sys" "Sat Jun 5 13:04:45 2021" "
+ "USBSTOR" "USB Mass Storage Driver: USB Mass Storage Class Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\USBSTOR.SYS" "Thu Dec 16 07:51:00 2021" "
+ "usbuhci" "Microsoft USB Universal Host Controller Miniport Driver: UHCI USB Miniport Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\usbuhci.sys" "Sat Jun 5 13:04:46 2021" "
+ "usbvideo" "USB Video Device (WDM): USB Video Class Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Drivers\usbvideo.sys" "Thu Dec 16 07:50:55 2021" "
+ "USBXHCI" "USB xHCI Compliant Host Controller: USB XHCI Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\USBXHCI.SYS" "Thu Dec 16 07:51:00 2021" "
+ "vdrvroot" "Microsoft Virtual Drive Enumerator: Virtual Drive Root Enumerator" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\vdrvroot.sys" "Sat Jun 5 13:04:45 2021" "
+ "VerifierExt" "Driver Verifier Extension: Driver Verifier component to help find bugs in device drivers." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\VerifierExt.sys" "Thu Dec 16 07:53:47 2021" "
+ "vhdmp" "vhdmp: VHD Miniport Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\vhdmp.sys" "Sat Jun 5 13:04:45 2021" "
+ "vhf" "Virtual HID Framework (VHF) Driver: Kernel mode driver that implements the Virtual HID Framework (VHF)" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\vhf.sys" "Sat Jun 5 13:04:45 2021" "
+ "Vid" "Vid: Microsoft Hyper-V Virtualization Infrastructure Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\Vid.sys" "Thu Dec 16 07:51:02 2021" "
+ "VirtualRender" "VirtualRender: Microsoft Virtual Render Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DriverStore\FileRepository\vrd.inf_amd64_346f3764318c1681\vrd.sys" "Sat Jun 5 13:04:47 2021" "
+ "vmbus" "Virtual Machine Bus: Microsoft Hyper-V Virtual Machine Bus Child Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\vmbus.sys" "Thu Dec 16 07:51:03 2021" "
+ "VMBusHID" "VMBusHID: Microsoft VMBus HID Miniport" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\VMBusHID.sys" "Sat Jun 5 13:04:47 2021" "
+ "vmgid" "Microsoft Hyper-V Guest Infrastructure Driver: Virtual Machine Guest Infrastructure Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\vmgid.sys" "Sat Jun 5 13:04:47 2021" "
+ "volmgr" "Volume Manager Driver: Volume Manager Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\volmgr.sys" "Thu Dec 16 07:50:56 2021" "
+ "volmgrx" "Dynamic Volume Manager: Extension of the volume manager driver that manages software RAID volumes (spanned, striped, mirrored, RAID-5) on dynamic disks" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\volmgrx.sys" "Sat Jun 5 13:06:02 2021" "
+ "volsnap" "Volume Shadow Copy driver: Volume class filter driver that takes and manages snapshots." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\volsnap.sys" "Sat Jun 5 13:05:14 2021" "
+ "volume" "Volume driver: Volume driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\volume.sys" "Sat Jun 5 13:04:44 2021" "
+ "vpci" "Microsoft Hyper-V Virtual PCI Bus: Virtual PCI Bus" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\vpci.sys" "Sat Jun 5 13:04:47 2021" "
+ "vsmraid" "vsmraid: VIA RAID DRIVER FOR AMD-X86-64" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\vsmraid.sys" "Sat Jun 5 13:04:45 2021" "
+ "VSTXRAID" "VIA StorX Storage RAID Controller Windows Driver: VIA StorX RAID Controller Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\vstxraid.sys" "Sat Jun 5 13:04:45 2021" "
+ "vwifibus" "Virtual Wireless Bus Driver: Implements bus functionality for Virtual Wireless" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\vwifibus.sys" "Sat Jun 5 13:05:00 2021" "
+ "vwififlt" "Virtual WiFi Filter Driver: Virtual WiFi Filter Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\vwififlt.sys" "Sat Jun 5 13:05:00 2021" "
+ "vwifimp" "Virtual WiFi Miniport Service: Virtual WiFi Miniport Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\vwifimp.sys" "Sat Jun 5 13:05:00 2021" "
+ "WacomPen" "Wacom Serial Pen HID Driver: Wacom Serial Pen Tablet HID Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\wacompen.sys" "Sat Jun 5 13:04:44 2021" "
+ "wanarp" "Remote Access IP ARP Driver: Remote Access IP ARP Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DRIVERS\wanarp.sys" "Sat Jun 5 13:05:40 2021" "
+ "wanarpv6" "Remote Access IPv6 ARP Driver: Remote Access IPv6 ARP Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DRIVERS\wanarp.sys" "Sat Jun 5 13:05:40 2021" "
+ "wcifs" "Windows Container Isolation: Provides a virtual filesystem view for processes running within Windows Containers" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\wcifs.sys" "Thu Dec 16 07:52:57 2021" "
+ "WdBoot" "Microsoft Defender Antivirus Boot Driver: Microsoft Defender Antivirus Boot Driver" "(Verified) Microsoft Windows Early Launch Anti-malware Publisher" "C:\WINDOWS\system32\drivers\wd\WdBoot.sys" "Thu Dec 16 00:21:01 2021" "
+ "Wdf01000" "Kernel Mode Driver Frameworks service: Kernel Mode Driver Framework Runtime" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\Wdf01000.sys" "Sat Jun 5 13:05:25 2021" "
+ "WdFilter" "Microsoft Defender Antivirus Mini-Filter Driver: Microsoft Defender Antivirus On-Access Malware Protection Mini-Filter Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\wd\WdFilter.sys" "Thu Dec 16 00:21:02 2021" "
+ "wdiwifi" "WDI Driver Framework: WDI Driver Framework Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\DRIVERS\wdiwifi.sys" "Thu Dec 16 07:51:52 2021" "
+ "WdmCompanionFilter" "WdmCompanionFilter: WDM Companion Filter" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\WdmCompanionFilter.sys" "Sat Jun 5 13:05:19 2021" "
+ "WdNisDrv" "Microsoft Defender Antivirus Network Inspection System Driver: Helps guard against intrusion attempts targeting known and newly discovered vulnerabilities in network protocols" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\wd\WdNisDrv.sys" "Thu Dec 16 00:21:02 2021" "
+ "WFPLWFS" "Microsoft Windows Filtering Platform: Microsoft Windows Filtering Platform" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\wfplwfs.sys" "Thu Dec 16 07:52:48 2021" "
+ "WifiCx" "Wifi Network Adapter Class Extension: Windows Wifi Class Extension" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\WifiCx.sys" "Thu Dec 16 07:51:53 2021" "
+ "WIMMount" "WIMMount: WIM Image mount service driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\wimmount.sys" "Thu Dec 16 07:53:40 2021" "
+ "WindowsTrustedRT" "Windows Trusted Execution Environment Class Extension: Windows Trusted Runtime Interface Driver" "(Verified) Microsoft Windows Hardware Abstraction Layer Publisher" "C:\WINDOWS\system32\drivers\WindowsTrustedRT.sys" "Sat Jun 5 13:05:16 2021" "
+ "WindowsTrustedRTProxy" "Microsoft Windows Trusted Runtime Secure Service: Windows Trusted Runtime Service Proxy Driver" "(Verified) Microsoft Windows Hardware Abstraction Layer Publisher" "C:\WINDOWS\System32\drivers\WindowsTrustedRTProxy.sys" "Sat Jun 5 13:04:46 2021" "
+ "WinMad" "WinMad Service: Kernel WinMad" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\winmad.sys" "Sat Jun 5 13:04:45 2021" "
+ "WinNat" "Windows NAT Driver: This service provides network address translation functionality" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\winnat.sys" "Thu Dec 16 07:51:30 2021" "
+ "WinSetupMon" "WinSetupMon: SetupPlatform Monitor Mini-Filter" "" "File not found: C:\WINDOWS\system32\DRIVERS\WinSetupMon.sys" "Thu Dec 16 09:46:21 2021" "
+ "WINUSB" "WinUsb Driver: Generic driver for USB devices" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\WinUSB.SYS" "Sat Jun 5 13:04:46 2021" "
+ "WinVerbs" "WinVerbs Service: Kernel WinVerbs" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\winverbs.sys" "Sat Jun 5 13:04:45 2021" "
+ "WmiAcpi" "Microsoft Windows Management Interface for ACPI: Windows Management Interface for ACPI" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\wmiacpi.sys" "Sat Jun 5 13:04:45 2021" "
+ "Wof" "Windows Overlay File System Filter Driver: Windows Overlay Filter" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Drivers\Wof.sys" "Sat Jun 5 13:05:23 2021" "
+ "WpdUpFltr" "WPD Upper Class Filter Driver: WPD Upper Class Filter Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\WpdUpFltr.sys" "Sat Jun 5 18:17:03 2021" "
+ X "ws2ifsl" "Winsock IFS Driver: Winsock IFS Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\ws2ifsl.sys" "Sat Jun 5 13:05:27 2021" "
+ "WSDPrintDevice" "WSD Print Support: Web Services Print Device Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\WSDPrint.sys" "Sat Jun 5 13:04:44 2021" "
+ "WSDScan" "WSD Scan Support: Web Service Based Scan Device Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\DRIVERS\WSDScan.sys" "Sat Jun 5 13:04:44 2021" "
+ "WudfPf" "User Mode Driver Frameworks Platform Driver: A kernel mode driver that uses message-based interprocess communication mechanism to communicate with the driver manager and secure host process to facilitate secure companions" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\WudfPf.sys" "Sat Jun 5 13:05:33 2021" "
+ "xboxgip" "Xbox Game Input Protocol Driver: Xbox Game Input Protocol Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\xboxgip.sys" "Thu Dec 16 07:50:51 2021" "
+ "xinputhid" "XINPUT HID Filter Driver: XINPUT filter driver for HID" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\xinputhid.sys" "Sat Jun 5 13:04:42 2021" "
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Font Drivers]
+ "Adobe Type Manager" "" "" "File not found: atmfd.dll" "" "
[Codecs]
[HKCU\Software\Microsoft\Windows NT\CurrentVersion\Drivers32]
[HKCU\Software\Classes\Filter]
[HKCU\Software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance]
[HKCU\Software\Classes\CLSID\{AC757296-3522-4E11-9862-C17BE5A1767E}\Instance]
[HKCU\Software\Classes\CLSID\{7ED96837-96F0-4812-B211-F13C24117ED3}\Instance]
[HKCU\Software\Classes\CLSID\{ABE3B9A4-257D-4B97-BD1A-294AF496222E}\Instance]
[HKCU\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32]
[HKCU\Software\Wow6432Node\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance]
[HKCU\Software\Wow6432Node\Classes\CLSID\{AC757296-3522-4E11-9862-C17BE5A1767E}\Instance]
[HKCU\Software\Wow6432Node\Classes\CLSID\{7ED96837-96F0-4812-B211-F13C24117ED3}\Instance]
[HKCU\Software\Wow6432Node\Classes\CLSID\{ABE3B9A4-257D-4B97-BD1A-294AF496222E}\Instance]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32]
+ "aux" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wdmaud.drv" "Sat Jun 5 13:04:54 2021" "
+ "aux1" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wdmaud.drv" "Sat Jun 5 13:04:54 2021" "
+ "aux2" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wdmaud.drv" "Sat Jun 5 13:04:54 2021" "
+ "aux3" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wdmaud.drv" "Sat Jun 5 13:04:54 2021" "
+ "midi" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wdmaud.drv" "Sat Jun 5 13:04:54 2021" "
+ "midi1" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wdmaud.drv" "Sat Jun 5 13:04:54 2021" "
+ "midi2" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wdmaud.drv" "Sat Jun 5 13:04:54 2021" "
+ "midi3" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wdmaud.drv" "Sat Jun 5 13:04:54 2021" "
+ "midimapper" "Microsoft MIDI Mapper" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\midimap.dll" "Sat Jun 5 13:04:54 2021" "
+ "mixer" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wdmaud.drv" "Sat Jun 5 13:04:54 2021" "
+ "mixer1" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wdmaud.drv" "Sat Jun 5 13:04:54 2021" "
+ "mixer2" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wdmaud.drv" "Sat Jun 5 13:04:54 2021" "
+ "mixer3" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wdmaud.drv" "Sat Jun 5 13:04:54 2021" "
+ "msacm.imaadpcm" "IMA ADPCM CODEC for MSACM" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\imaadp32.acm" "Sat Jun 5 13:04:54 2021" "
+ "msacm.l3acm" "MPEG Layer-3 Audio Codec for MSACM" "(Verified) Microsoft Windows" "C:\Windows\System32\l3codeca.acm" "Sat Jun 5 18:17:05 2021" "
+ "msacm.msadpcm" "Microsoft ADPCM CODEC for MSACM" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\msadp32.acm" "Sat Jun 5 13:04:54 2021" "
+ "msacm.msg711" "Microsoft CCITT G.711 (A-Law and u-Law) CODEC for MSACM" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\msg711.acm" "Sat Jun 5 13:04:54 2021" "
+ "msacm.msgsm610" "Microsoft GSM 6.10 Audio CODEC for MSACM" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\msgsm32.acm" "Sat Jun 5 13:04:54 2021" "
+ "MSVideo8" "VfW MM Driver for WDM Video Capture Devices" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\VfWWDM32.dll" "Thu Dec 16 07:56:42 2021" "
+ "vidc.i420" "Intel Indeo(R) Video YUV Codec" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\iyuv_32.dll" "Sat Jun 5 13:06:11 2021" "
+ "vidc.iyuv" "Intel Indeo(R) Video YUV Codec" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\iyuv_32.dll" "Sat Jun 5 13:06:11 2021" "
+ "vidc.mrle" "Microsoft RLE Compressor" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\msrle32.dll" "Sat Jun 5 13:06:11 2021" "
+ "vidc.msvc" "Microsoft Video 1 Compressor" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\msvidc32.dll" "Sat Jun 5 13:06:11 2021" "
+ "vidc.uyvy" "Microsoft UYVY Video Decompressor" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\msyuv.dll" "Sat Jun 5 13:06:11 2021" "
+ "vidc.yuy2" "Microsoft UYVY Video Decompressor" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\msyuv.dll" "Sat Jun 5 13:06:11 2021" "
+ "vidc.yvu9" "Toshiba Video Codec" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\tsbyuv.dll" "Sat Jun 5 13:06:11 2021" "
+ "vidc.yvyu" "Microsoft UYVY Video Decompressor" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\msyuv.dll" "Sat Jun 5 13:06:11 2021" "
+ "wave" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wdmaud.drv" "Sat Jun 5 13:04:54 2021" "
+ "wave1" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wdmaud.drv" "Sat Jun 5 13:04:54 2021" "
+ "wave2" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wdmaud.drv" "Sat Jun 5 13:04:54 2021" "
+ "wave3" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wdmaud.drv" "Sat Jun 5 13:04:54 2021" "
+ "wavemapper" "Microsoft Sound Mapper" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\msacm32.drv" "Sat Jun 5 13:04:54 2021" "
[HKLM\Software\Classes\Filter]
[HKLM\Software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance]
+ "AC3 Parser Filter" "DirectShow MPEG-2 Splitter." "(Verified) Microsoft Windows" "C:\Windows\System32\mpg2splt.ax" "Sat Jun 5 13:06:14 2021" "
+ "ACM Wrapper" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\quartz.dll" "Sat Jun 5 13:06:11 2021" "
+ "AVI Decompressor" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\quartz.dll" "Sat Jun 5 13:06:11 2021" "
+ "AVI Draw Filter" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\quartz.dll" "Sat Jun 5 13:06:11 2021" "
+ "AVI mux" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\qcap.dll" "Sat Jun 5 13:06:11 2021" "
+ "AVI Splitter" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\quartz.dll" "Sat Jun 5 13:06:11 2021" "
+ "AVI/WAV File Source" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\quartz.dll" "Sat Jun 5 13:06:11 2021" "
+ "BDA MPEG2 Transport Information Filter" "Microsoft Transport Information Filter for MPEG2 based networks." "(Verified) Microsoft Windows" "C:\Windows\System32\psisrndr.ax" "Sat Jun 5 13:06:14 2021" "
+ "Closed Captions Analysis Filter" "CCA DirectShow Filter." "(Verified) Microsoft Windows" "C:\Windows\System32\cca.dll" "Sat Jun 5 13:06:14 2021" "
+ "Color Space Converter" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\quartz.dll" "Sat Jun 5 13:06:11 2021" "
+ "Default Video Renderer" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\quartz.dll" "Sat Jun 5 13:06:11 2021" "
+ "DV Muxer" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\qdv.dll" "Sat Jun 5 13:06:11 2021" "
+ "DV Splitter" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\qdv.dll" "Sat Jun 5 13:06:11 2021" "
+ "DV Video Decoder" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\qdv.dll" "Sat Jun 5 13:06:11 2021" "
+ "DVD Navigator" "DirectShow DVD PlayBack Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\qdvd.dll" "Sat Jun 5 13:06:11 2021" "
+ "Enhanced Video Renderer" "Enhanced Video Renderer DLL" "(Verified) Microsoft Windows" "C:\Windows\System32\evr.dll" "Sat Jun 5 18:17:05 2021" "
+ "File Source (Async.)" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\quartz.dll" "Sat Jun 5 13:06:11 2021" "
+ "File Source (URL)" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\quartz.dll" "Sat Jun 5 13:06:11 2021" "
+ "File stream renderer" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\quartz.dll" "Sat Jun 5 13:06:11 2021" "
+ "File Writer" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\qcap.dll" "Sat Jun 5 13:06:11 2021" "
+ "Infinite Pin Tee Filter" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\qcap.dll" "Sat Jun 5 13:06:11 2021" "
+ "Internal Text Renderer" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\quartz.dll" "Sat Jun 5 13:06:11 2021" "
+ "Line 21 Decoder 2" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\quartz.dll" "Sat Jun 5 13:06:11 2021" "
+ "Microsoft AC3 Encoder" "Microsoft AC-3 Encoder" "(Verified) Microsoft Windows" "C:\Windows\System32\msac3enc.dll" "Thu Dec 16 07:57:12 2021" "
+ "Microsoft DTV-DVD Audio Decoder" "Microsoft DTV-DVD Audio Decoder" "(Verified) Microsoft Windows" "C:\Windows\System32\msmpeg2adec.dll" "Thu Dec 16 07:57:13 2021" "
+ "Microsoft DTV-DVD Video Decoder" "Microsoft DTV-DVD Video Decoder" "(Verified) Microsoft Windows" "C:\Windows\System32\msmpeg2vdec.dll" "Thu Dec 16 07:57:13 2021" "
+ "Microsoft MPEG-2 Audio Encoder" "Microsoft MPEG-2 Encoder" "(Verified) Microsoft Windows" "C:\Windows\System32\msmpeg2enc.dll" "Thu Dec 16 07:57:12 2021" "
+ "Microsoft MPEG-2 Encoder" "Microsoft MPEG-2 Encoder" "(Verified) Microsoft Windows" "C:\Windows\System32\msmpeg2enc.dll" "Thu Dec 16 07:57:12 2021" "
+ "Microsoft MPEG-2 Video Encoder" "Microsoft MPEG-2 Encoder" "(Verified) Microsoft Windows" "C:\Windows\System32\msmpeg2enc.dll" "Thu Dec 16 07:57:12 2021" "
+ "MIDI Parser" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\quartz.dll" "Sat Jun 5 13:06:11 2021" "
+ "MJPEG Decompressor" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\quartz.dll" "Sat Jun 5 13:06:11 2021" "
+ "MPEG Audio Codec" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\quartz.dll" "Sat Jun 5 13:06:11 2021" "
+ "MPEG Video Codec" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\quartz.dll" "Sat Jun 5 13:06:11 2021" "
+ "MPEG-2 Demultiplexer" "DirectShow MPEG-2 Splitter." "(Verified) Microsoft Windows" "C:\Windows\System32\mpg2splt.ax" "Sat Jun 5 13:06:14 2021" "
+ "MPEG-2 Sections and Tables" "Microsoft MPEG-2 Section and Table Acquisition Module" "(Verified) Microsoft Windows" "C:\Windows\System32\Mpeg2Data.ax" "Sat Jun 5 13:06:14 2021" "
+ "MPEG-2 Splitter" "DirectShow MPEG-2 Splitter." "(Verified) Microsoft Windows" "C:\Windows\System32\mpg2splt.ax" "Sat Jun 5 13:06:14 2021" "
+ "Mpeg-2 Video Stream Analysis" "DirectShow Stream Buffer Filter." "(Verified) Microsoft Windows" "C:\Windows\System32\sbe.dll" "Thu Dec 16 07:56:44 2021" "
+ "MPEG-I Stream Splitter" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\quartz.dll" "Sat Jun 5 13:06:11 2021" "
+ "Multi-file Parser" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\quartz.dll" "Sat Jun 5 13:06:11 2021" "
+ "Null Renderer" "DirectShow editing." "(Verified) Microsoft Windows" "C:\Windows\System32\qedit.dll" "Sat Jun 5 13:06:16 2021" "
+ "SAMI (CC) Reader" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\quartz.dll" "Sat Jun 5 13:06:11 2021" "
+ "Sample Grabber" "DirectShow editing." "(Verified) Microsoft Windows" "C:\Windows\System32\qedit.dll" "Sat Jun 5 13:06:16 2021" "
+ "SBE2 Sink" "DirectShow Stream Buffer Filter." "(Verified) Microsoft Windows" "C:\Windows\System32\sbe.dll" "Thu Dec 16 07:56:44 2021" "
+ "SBE2FileScan" "DirectShow Stream Buffer Filter." "(Verified) Microsoft Windows" "C:\Windows\System32\sbe.dll" "Thu Dec 16 07:56:44 2021" "
+ "SBE2MediaTypeProfile" "DirectShow Stream Buffer Filter." "(Verified) Microsoft Windows" "C:\Windows\System32\sbe.dll" "Thu Dec 16 07:56:44 2021" "
+ "Smart Tee Filter" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\qcap.dll" "Sat Jun 5 13:06:11 2021" "
+ "StreamBufferSink" "DirectShow Stream Buffer Filter." "(Verified) Microsoft Windows" "C:\Windows\System32\sbe.dll" "Thu Dec 16 07:56:44 2021" "
+ "StreamBufferSource" "DirectShow Stream Buffer Filter." "(Verified) Microsoft Windows" "C:\Windows\System32\sbe.dll" "Thu Dec 16 07:56:44 2021" "
+ "VBI Codec" "Microsoft VBI Codec" "(Verified) Microsoft Windows" "C:\Windows\System32\VBICodec.ax" "Sat Jun 5 13:06:14 2021" "
+ "VBI Surface Allocator" "VBI Surface Allocator Filter" "(Verified) Microsoft Windows" "C:\Windows\System32\vbisurf.ax" "Thu Dec 16 07:56:44 2021" "
+ "VGA 16 color ditherer" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\quartz.dll" "Sat Jun 5 13:06:11 2021" "
+ "Video Mixing Renderer 9" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\quartz.dll" "Sat Jun 5 13:06:11 2021" "
+ "Video Port Manager" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\quartz.dll" "Sat Jun 5 13:06:11 2021" "
+ "Video Renderer" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\quartz.dll" "Sat Jun 5 13:06:11 2021" "
+ "VPS Decoder" "Microsoft Teletext Server" "(Verified) Microsoft Windows" "C:\Windows\System32\WSTPager.ax" "Sat Jun 5 13:06:14 2021" "
+ "Wave Parser" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\quartz.dll" "Sat Jun 5 13:06:11 2021" "
+ "WM ASF Reader" "DirectShow ASF Support" "(Verified) Microsoft Windows" "C:\Windows\System32\qasf.dll" "Thu Dec 16 07:56:30 2021" "
+ "WM ASF Writer" "DirectShow ASF Support" "(Verified) Microsoft Windows" "C:\Windows\System32\qasf.dll" "Thu Dec 16 07:56:30 2021" "
+ "WST Pager" "Microsoft Teletext Server" "(Verified) Microsoft Windows" "C:\Windows\System32\WSTPager.ax" "Sat Jun 5 13:06:14 2021" "
[HKLM\Software\Classes\CLSID\{AC757296-3522-4E11-9862-C17BE5A1767E}\Instance]
[HKLM\Software\Classes\CLSID\{7ED96837-96F0-4812-B211-F13C24117ED3}\Instance]
+ "{41945702-8302-44A6-9445-AC98E8AFA086}" "MS RAW Image Decoder DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\MSRAWImage.dll" "Sat Jun 5 18:17:05 2021" "
+ "{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}" "Microsoft Camera Codec Pack" "(Verified) Microsoft Windows" "C:\Windows\System32\WindowsCodecsRaw.dll" "Thu Dec 16 07:57:08 2021" "
[HKLM\Software\Classes\CLSID\{ABE3B9A4-257D-4B97-BD1A-294AF496222E}\Instance]
[HKLM\Software\Wow6432Node\Classes\Filter]
[HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32]
+ "aux" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\wdmaud.drv" "Sat Jun 5 13:05:45 2021" "
+ "aux1" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\wdmaud.drv" "Sat Jun 5 13:05:45 2021" "
+ "aux2" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\wdmaud.drv" "Sat Jun 5 13:05:45 2021" "
+ "aux3" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\wdmaud.drv" "Sat Jun 5 13:05:45 2021" "
+ "midi" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\wdmaud.drv" "Sat Jun 5 13:05:45 2021" "
+ "midi1" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\wdmaud.drv" "Sat Jun 5 13:05:45 2021" "
+ "midi2" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\wdmaud.drv" "Sat Jun 5 13:05:45 2021" "
+ "midi3" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\wdmaud.drv" "Sat Jun 5 13:05:45 2021" "
+ "midimapper" "Microsoft MIDI Mapper" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\midimap.dll" "Sat Jun 5 13:05:43 2021" "
+ "mixer" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\wdmaud.drv" "Sat Jun 5 13:05:45 2021" "
+ "mixer1" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\wdmaud.drv" "Sat Jun 5 13:05:45 2021" "
+ "mixer2" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\wdmaud.drv" "Sat Jun 5 13:05:45 2021" "
+ "mixer3" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\wdmaud.drv" "Sat Jun 5 13:05:45 2021" "
+ "msacm.imaadpcm" "IMA ADPCM CODEC for MSACM" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\imaadp32.acm" "Sat Jun 5 13:05:43 2021" "
+ "msacm.l3acm" "MPEG Layer-3 Audio Codec for MSACM" "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\l3codeca.acm" "Sat Jun 5 18:17:04 2021" "
+ "msacm.msadpcm" "Microsoft ADPCM CODEC for MSACM" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\msadp32.acm" "Sat Jun 5 13:05:43 2021" "
+ "msacm.msg711" "Microsoft CCITT G.711 (A-Law and u-Law) CODEC for MSACM" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\msg711.acm" "Sat Jun 5 13:05:43 2021" "
+ "msacm.msgsm610" "Microsoft GSM 6.10 Audio CODEC for MSACM" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\msgsm32.acm" "Sat Jun 5 13:05:45 2021" "
+ "vidc.cvid" "Cinepak® Codec" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\iccvid.dll" "Sat Jun 5 13:06:24 2021" "
+ "vidc.i420" "Intel Indeo(R) Video YUV Codec" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\iyuv_32.dll" "Sat Jun 5 13:06:24 2021" "
+ "vidc.iyuv" "Intel Indeo(R) Video YUV Codec" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\iyuv_32.dll" "Sat Jun 5 13:06:24 2021" "
+ "vidc.mrle" "Microsoft RLE Compressor" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\msrle32.dll" "Sat Jun 5 13:06:24 2021" "
+ "vidc.msvc" "Microsoft Video 1 Compressor" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\msvidc32.dll" "Sat Jun 5 13:06:24 2021" "
+ "vidc.uyvy" "Microsoft UYVY Video Decompressor" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\msyuv.dll" "Sat Jun 5 13:06:24 2021" "
+ "vidc.yuy2" "Microsoft UYVY Video Decompressor" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\msyuv.dll" "Sat Jun 5 13:06:24 2021" "
+ "vidc.yvu9" "Toshiba Video Codec" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\tsbyuv.dll" "Sat Jun 5 13:06:24 2021" "
+ "vidc.yvyu" "Microsoft UYVY Video Decompressor" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\msyuv.dll" "Sat Jun 5 13:06:24 2021" "
+ "wave" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\wdmaud.drv" "Sat Jun 5 13:05:45 2021" "
+ "wave1" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\wdmaud.drv" "Sat Jun 5 13:05:45 2021" "
+ "wave2" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\wdmaud.drv" "Sat Jun 5 13:05:45 2021" "
+ "wave3" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\wdmaud.drv" "Sat Jun 5 13:05:45 2021" "
+ "wavemapper" "Microsoft Sound Mapper" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\msacm32.drv" "Sat Jun 5 13:05:43 2021" "
[HKLM\Software\Wow6432Node\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance]
+ "AC3 Parser Filter" "DirectShow MPEG-2 Splitter." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\mpg2splt.ax" "Sat Jun 5 13:06:24 2021" "
+ "ACM Wrapper" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\quartz.dll" "Sat Jun 5 13:06:24 2021" "
+ "AVI Decompressor" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\quartz.dll" "Sat Jun 5 13:06:24 2021" "
+ "AVI Draw Filter" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\quartz.dll" "Sat Jun 5 13:06:24 2021" "
+ "AVI mux" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\qcap.dll" "Sat Jun 5 13:06:24 2021" "
+ "AVI Splitter" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\quartz.dll" "Sat Jun 5 13:06:24 2021" "
+ "AVI/WAV File Source" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\quartz.dll" "Sat Jun 5 13:06:24 2021" "
+ "BDA MPEG2 Transport Information Filter" "Microsoft Transport Information Filter for MPEG2 based networks." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\psisrndr.ax" "Sat Jun 5 13:06:24 2021" "
+ "Closed Captions Analysis Filter" "CCA DirectShow Filter." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\cca.dll" "Sat Jun 5 13:06:24 2021" "
+ "Color Space Converter" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\quartz.dll" "Sat Jun 5 13:06:24 2021" "
+ "Default Video Renderer" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\quartz.dll" "Sat Jun 5 13:06:24 2021" "
+ "DV Muxer" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\qdv.dll" "Sat Jun 5 13:06:24 2021" "
+ "DV Splitter" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\qdv.dll" "Sat Jun 5 13:06:24 2021" "
+ "DV Video Decoder" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\qdv.dll" "Sat Jun 5 13:06:24 2021" "
+ "DVD Navigator" "DirectShow DVD PlayBack Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\qdvd.dll" "Sat Jun 5 13:06:24 2021" "
+ "Enhanced Video Renderer" "Enhanced Video Renderer DLL" "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\evr.dll" "Sat Jun 5 18:17:04 2021" "
+ "File Source (Async.)" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\quartz.dll" "Sat Jun 5 13:06:24 2021" "
+ "File Source (URL)" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\quartz.dll" "Sat Jun 5 13:06:24 2021" "
+ "File stream renderer" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\quartz.dll" "Sat Jun 5 13:06:24 2021" "
+ "File Writer" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\qcap.dll" "Sat Jun 5 13:06:24 2021" "
+ "Infinite Pin Tee Filter" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\qcap.dll" "Sat Jun 5 13:06:24 2021" "
+ "Internal Text Renderer" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\quartz.dll" "Sat Jun 5 13:06:24 2021" "
+ "Line 21 Decoder" "DirectShow DVD PlayBack Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\qdvd.dll" "Sat Jun 5 13:06:24 2021" "
+ "Line 21 Decoder 2" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\quartz.dll" "Sat Jun 5 13:06:24 2021" "
+ "Microsoft AC3 Encoder" "Microsoft AC-3 Encoder" "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\msac3enc.dll" "Thu Dec 16 07:57:16 2021" "
+ "Microsoft DTV-DVD Audio Decoder" "Microsoft DTV-DVD Audio Decoder" "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\msmpeg2adec.dll" "Thu Dec 16 07:57:17 2021" "
+ "Microsoft DTV-DVD Video Decoder" "Microsoft DTV-DVD Video Decoder" "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\msmpeg2vdec.dll" "Thu Dec 16 07:57:16 2021" "
+ "Microsoft MPEG-2 Audio Encoder" "Microsoft MPEG-2 Encoder" "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\msmpeg2enc.dll" "Thu Dec 16 07:57:16 2021" "
+ "Microsoft MPEG-2 Encoder" "Microsoft MPEG-2 Encoder" "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\msmpeg2enc.dll" "Thu Dec 16 07:57:16 2021" "
+ "Microsoft MPEG-2 Video Encoder" "Microsoft MPEG-2 Encoder" "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\msmpeg2enc.dll" "Thu Dec 16 07:57:16 2021" "
+ "MIDI Parser" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\quartz.dll" "Sat Jun 5 13:06:24 2021" "
+ "MJPEG Decompressor" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\quartz.dll" "Sat Jun 5 13:06:24 2021" "
+ "MPEG Audio Codec" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\quartz.dll" "Sat Jun 5 13:06:24 2021" "
+ "MPEG Video Codec" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\quartz.dll" "Sat Jun 5 13:06:24 2021" "
+ "MPEG-2 Demultiplexer" "DirectShow MPEG-2 Splitter." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\mpg2splt.ax" "Sat Jun 5 13:06:24 2021" "
+ "MPEG-2 Sections and Tables" "Microsoft MPEG-2 Section and Table Acquisition Module" "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\Mpeg2Data.ax" "Sat Jun 5 13:06:24 2021" "
+ "MPEG-2 Splitter" "DirectShow MPEG-2 Splitter." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\mpg2splt.ax" "Sat Jun 5 13:06:24 2021" "
+ "Mpeg-2 Video Stream Analysis" "DirectShow Stream Buffer Filter." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\sbe.dll" "Sat Jun 5 13:06:24 2021" "
+ "MPEG-I Stream Splitter" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\quartz.dll" "Sat Jun 5 13:06:24 2021" "
+ "Multi-file Parser" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\quartz.dll" "Sat Jun 5 13:06:24 2021" "
+ "Null Renderer" "DirectShow editing." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\qedit.dll" "Sat Jun 5 13:06:24 2021" "
+ "Overlay Mixer" "DirectShow DVD PlayBack Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\qdvd.dll" "Sat Jun 5 13:06:24 2021" "
+ "Overlay Mixer2" "DirectShow DVD PlayBack Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\qdvd.dll" "Sat Jun 5 13:06:24 2021" "
+ "SAMI (CC) Reader" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\quartz.dll" "Sat Jun 5 13:06:24 2021" "
+ "Sample Grabber" "DirectShow editing." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\qedit.dll" "Sat Jun 5 13:06:24 2021" "
+ "SBE2 Sink" "DirectShow Stream Buffer Filter." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\sbe.dll" "Sat Jun 5 13:06:24 2021" "
+ "SBE2FileScan" "DirectShow Stream Buffer Filter." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\sbe.dll" "Sat Jun 5 13:06:24 2021" "
+ "SBE2MediaTypeProfile" "DirectShow Stream Buffer Filter." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\sbe.dll" "Sat Jun 5 13:06:24 2021" "
+ "Smart Tee Filter" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\qcap.dll" "Sat Jun 5 13:06:24 2021" "
+ "StreamBufferSink" "DirectShow Stream Buffer Filter." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\sbe.dll" "Sat Jun 5 13:06:24 2021" "
+ "StreamBufferSource" "DirectShow Stream Buffer Filter." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\sbe.dll" "Sat Jun 5 13:06:24 2021" "
+ "VBI Codec" "Microsoft VBI Codec" "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\VBICodec.ax" "Sat Jun 5 13:06:24 2021" "
+ "VBI Surface Allocator" "VBI Surface Allocator Filter" "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\vbisurf.ax" "Thu Dec 16 07:57:07 2021" "
+ "VGA 16 color ditherer" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\quartz.dll" "Sat Jun 5 13:06:24 2021" "
+ "Video Mixing Renderer 9" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\quartz.dll" "Sat Jun 5 13:06:24 2021" "
+ "Video Port Manager" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\quartz.dll" "Sat Jun 5 13:06:24 2021" "
+ "Video Renderer" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\quartz.dll" "Sat Jun 5 13:06:24 2021" "
+ "VPS Decoder" "Microsoft Teletext Server" "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\WSTPager.ax" "Sat Jun 5 13:06:24 2021" "
+ "Wave Parser" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\quartz.dll" "Sat Jun 5 13:06:24 2021" "
+ "WM ASF Reader" "DirectShow ASF Support" "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\qasf.dll" "Thu Dec 16 07:57:01 2021" "
+ "WM ASF Writer" "DirectShow ASF Support" "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\qasf.dll" "Thu Dec 16 07:57:01 2021" "
+ "WST Pager" "Microsoft Teletext Server" "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\WSTPager.ax" "Sat Jun 5 13:06:24 2021" "
[HKLM\Software\Wow6432Node\Classes\CLSID\{AC757296-3522-4E11-9862-C17BE5A1767E}\Instance]
[HKLM\Software\Wow6432Node\Classes\CLSID\{7ED96837-96F0-4812-B211-F13C24117ED3}\Instance]
+ "{41945702-8302-44A6-9445-AC98E8AFA086}" "MS RAW Image Decoder DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\MSRAWImage.dll" "Sat Jun 5 18:17:04 2021" "
+ "{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}" "Microsoft Camera Codec Pack" "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\WindowsCodecsRaw.dll" "Thu Dec 16 07:57:10 2021" "
[HKLM\Software\Wow6432Node\Classes\CLSID\{ABE3B9A4-257D-4B97-BD1A-294AF496222E}\Instance]
[Boot Execute]
[HKLM\System\CurrentControlSet\Control\Session Manager\BootExecute]
+ "autocheck autochk *" "Auto Check Utility" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\autochk.exe" "Sat Jun 5 13:05:23 2021" "
[HKLM\System\CurrentControlSet\Control\Session Manager\SetupExecute]
[HKLM\System\CurrentControlSet\Control\Session Manager\Execute]
[HKLM\System\CurrentControlSet\Control\Session Manager\S0InitialCommand]
[Image Hijacks]
[HKCU\Software\Microsoft\Command Processor\Autorun]
[HKCU\SOFTWARE\Classes\Exefile\Shell\Open\Command\(Default)]
[HKCU\SOFTWARE\Classes\Htmlfile\Shell\Open\Command\(Default)]
[HKCU\Software\Classes\.exe]
[HKCU\Software\Classes\.cmd]
[HKLM\Software\Microsoft\Command Processor\Autorun]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
[HKLM\SOFTWARE\Classes\Exefile\Shell\Open\Command\(Default)]
[HKLM\SOFTWARE\Classes\Htmlfile\Shell\Open\Command\(Default)]
+ "C:\Program Files\Internet Explorer\iexplore.exe" "Internet Explorer" "(Verified) Microsoft Corporation" "C:\Program Files\Internet Explorer\iexplore.exe" "Thu Dec 16 08:01:20 2021" "
[HKLM\Software\Classes\.exe]
[HKLM\Software\Classes\.cmd]
[HKLM\Software\Wow6432Node\Microsoft\Command Processor\Autorun]
[HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
[AppInit]
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Appinit_Dlls]
[HKLM\System\CurrentControlSet\Control\Session Manager\AppCertDlls]
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Windows\Appinit_Dlls]
[Known DLLs]
[HKLM\System\CurrentControlSet\Control\Session Manager\KnownDlls]
+ "*kernel32" "Windows NT BASE API Client DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\kernel32.dll" "Thu Dec 16 07:53:03 2021" "
+ "*kernel32" "Windows NT BASE API Client DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\kernel32.dll" "Thu Dec 16 07:55:22 2021" "
+ "_wow64cpu" "AMD64 Wow64 CPU " "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wow64cpu.dll" "Sat Jun 5 13:05:27 2021" "
+ "_wow64cpu" "" "" "File not found: C:\WINDOWS\Syswow64\wow64cpu.dll" "" "
+ "_wowarmhw" "" "" "File not found: C:\WINDOWS\system32\wowarmhw.dll" "" "
+ "_wowarmhw" "" "" "File not found: C:\WINDOWS\Syswow64\wowarmhw.dll" "" "
+ "_xtajit" "" "" "File not found: C:\WINDOWS\system32\xtajit.dll" "" "
+ "_xtajit" "" "" "File not found: C:\WINDOWS\Syswow64\xtajit.dll" "" "
+ "advapi32" "Advanced Windows 32 Base API" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\advapi32.dll" "Thu Dec 16 07:51:50 2021" "
+ "advapi32" "Advanced Windows 32 Base API" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\advapi32.dll" "Thu Dec 16 07:55:17 2021" "
+ "clbcatq" "COM+ Configuration Catalog" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\clbcatq.dll" "Sat Jun 5 13:05:23 2021" "
+ "clbcatq" "COM+ Configuration Catalog" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\clbcatq.dll" "Sat Jun 5 13:05:53 2021" "
+ "combase" "Microsoft COM for Windows" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\combase.dll" "Thu Dec 16 07:53:43 2021" "
+ "combase" "Microsoft COM for Windows" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\combase.dll" "Thu Dec 16 07:55:58 2021" "
+ "COMDLG32" "Common Dialogues DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\COMDLG32.dll" "Thu Dec 16 07:54:26 2021" "
+ "COMDLG32" "Common Dialogs DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\COMDLG32.dll" "Thu Dec 16 07:56:18 2021" "
+ "coml2" "Microsoft COM for Windows" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\coml2.dll" "Sat Jun 5 13:05:09 2021" "
+ "coml2" "Microsoft COM for Windows" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\coml2.dll" "Sat Jun 5 13:05:51 2021" "
+ "DifxApi" "Driver Install Frameworks for API library module" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\difxapi.dll" "Sat Jun 5 13:05:39 2021" "
+ "DifxApi" "Driver Install Frameworks for API library module" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\difxapi.dll" "Sat Jun 5 13:05:59 2021" "
+ "gdi32" "GDI Client DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\gdi32.dll" "Sat Jun 5 13:05:06 2021" "
+ "gdi32" "GDI Client DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\gdi32.dll" "Sat Jun 5 13:05:48 2021" "
+ "gdiplus" "Microsoft GDI+" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\gdiplus.dll" "Thu Dec 16 07:54:20 2021" "
+ "gdiplus" "Microsoft GDI+" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\gdiplus.dll" "Thu Dec 16 07:56:02 2021" "
+ "IMAGEHLP" "Windows NT Image Helper" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\IMAGEHLP.dll" "Sat Jun 5 13:05:25 2021" "
+ "IMAGEHLP" "Windows NT Image Helper" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\IMAGEHLP.dll" "Sat Jun 5 13:05:25 2021" "
+ "IMM32" "Multi-User Windows IMM32 API Client DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\IMM32.dll" "Sat Jun 5 13:05:27 2021" "
+ "IMM32" "Multi-User Windows IMM32 API Client DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\IMM32.dll" "Sat Jun 5 13:05:53 2021" "
+ "MSCTF" "MSCTF Server DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\MSCTF.dll" "Thu Dec 16 07:52:59 2021" "
+ "MSCTF" "MSCTF Server DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\MSCTF.dll" "Thu Dec 16 07:55:19 2021" "
+ "MSVCRT" "Windows NT CRT DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\MSVCRT.dll" "Sat Jun 5 13:05:25 2021" "
+ "MSVCRT" "Windows NT CRT DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\MSVCRT.dll" "Sat Jun 5 13:05:45 2021" "
+ "NORMALIZ" "Unicode Normalization DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\NORMALIZ.dll" "Sat Jun 5 13:05:27 2021" "
+ "NORMALIZ" "Unicode Normalization DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\NORMALIZ.dll" "Sat Jun 5 13:05:53 2021" "
+ "NSI" "NSI User-mode interface DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\NSI.dll" "Sat Jun 5 13:05:25 2021" "
+ "NSI" "NSI User-mode interface DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\NSI.dll" "Sat Jun 5 13:05:25 2021" "
+ "ole32" "Microsoft OLE for Windows" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\ole32.dll" "Thu Dec 16 07:53:40 2021" "
+ "ole32" "Microsoft OLE for Windows" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\ole32.dll" "Thu Dec 16 07:55:57 2021" "
+ "OLEAUT32" "OLEAUT32.DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\OLEAUT32.dll" "Sat Jun 5 13:05:25 2021" "
+ "OLEAUT32" "OLEAUT32.DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\OLEAUT32.dll" "Sat Jun 5 13:05:53 2021" "
+ "PSAPI" "Process Status Helper" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\PSAPI.DLL" "Sat Jun 5 13:05:23 2021" "
+ "PSAPI" "Process Status Helper" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\PSAPI.DLL" "Sat Jun 5 13:05:53 2021" "
+ "rpcrt4" "Remote Procedure Call Runtime" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\rpcrt4.dll" "Thu Dec 16 07:53:50 2021" "
+ "rpcrt4" "Remote Procedure Call Runtime" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\rpcrt4.dll" "Thu Dec 16 07:55:15 2021" "
+ "sechost" "Host for SCM/SDDL/LSA Lookup APIs" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\sechost.dll" "Thu Dec 16 07:53:50 2021" "
+ "sechost" "Host for SCM/SDDL/LSA Lookup APIs" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\sechost.dll" "Thu Dec 16 07:55:15 2021" "
+ "Setupapi" "Windows Setup API" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\Setupapi.dll" "Thu Dec 16 07:54:53 2021" "
+ "Setupapi" "Windows Setup API" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\Setupapi.dll" "Thu Dec 16 07:56:16 2021" "
+ "SHCORE" "SHCORE" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\SHCORE.dll" "Thu Dec 16 07:53:07 2021" "
+ "SHCORE" "SHCORE" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\SHCORE.dll" "Thu Dec 16 07:55:52 2021" "
+ "SHELL32" "Windows Shell Common Dll" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\SHELL32.dll" "Thu Dec 16 07:54:27 2021" "
+ "SHELL32" "Windows Shell Common Dll" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\SHELL32.dll" "Thu Dec 16 07:56:19 2021" "
+ "SHLWAPI" "Shell Light-weight Utility Library" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\SHLWAPI.dll" "Sat Jun 5 13:05:33 2021" "
+ "SHLWAPI" "Shell Light-weight Utility Library" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\SHLWAPI.dll" "Sat Jun 5 13:06:00 2021" "
+ "user32" "Multi-User Windows USER API Client DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\user32.dll" "Thu Dec 16 07:52:55 2021" "
+ "user32" "Multi-User Windows USER API Client DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\user32.dll" "Thu Dec 16 07:55:51 2021" "
+ "WLDAP32" "Win32 LDAP API DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\WLDAP32.dll" "Sat Jun 5 13:05:23 2021" "
+ "WLDAP32" "Win32 LDAP API DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\WLDAP32.dll" "Sat Jun 5 13:05:53 2021" "
+ "wow64" "Win32 Emulation on NT64" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wow64.dll" "Thu Dec 16 07:54:09 2021" "
+ "wow64" "" "" "File not found: C:\WINDOWS\Syswow64\wow64.dll" "" "
+ "wow64base" "" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wow64base.dll" "Sat Jun 5 13:05:27 2021" "
+ "wow64base" "" "" "File not found: C:\WINDOWS\Syswow64\wow64base.dll" "" "
+ "wow64con" "" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wow64con.dll" "Thu Dec 16 07:54:09 2021" "
+ "wow64con" "" "" "File not found: C:\WINDOWS\Syswow64\wow64con.dll" "" "
+ "wow64win" "Wow64 Console and Win32 API Logging" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wow64win.dll" "Thu Dec 16 07:54:09 2021" "
+ "wow64win" "" "" "File not found: C:\WINDOWS\Syswow64\wow64win.dll" "" "
+ "WS2_32" "Windows Socket 2.0 32-Bit DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\WS2_32.dll" "Sat Jun 5 13:05:25 2021" "
+ "WS2_32" "Windows Socket 2.0 32-Bit DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\WS2_32.dll" "Sat Jun 5 13:05:45 2021" "
+ "xtajit64" "" "" "File not found: C:\WINDOWS\system32\xtajit64.dll" "" "
+ "xtajit64" "" "" "File not found: C:\WINDOWS\Syswow64\xtajit64.dll" "" "
[WinLogon]
[HKCU\SOFTWARE\Policies\Microsoft\Windows\Control Panel\Desktop\Scrnsave.exe]
[HKCU\Control Panel\Desktop\Scrnsave.exe]
[HKLM\SYSTEM\Setup\CmdLine]
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Taskman]
[HKLM\System\CurrentControlSet\Control\BootVerificationProgram\ImagePath]
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\Credential Providers]
+ "Automatic Redeployment Credential Provider" "Autopilot Reset Credential Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mgmtrefreshcredprov.dll" "Sat Jun 5 13:06:16 2021" "
+ "CCertProvider" "Cert Credential Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\certCredProvider.dll" "Sat Jun 5 13:05:27 2021" "
+ "Cloud Experience Credential Provider" "Cloud Experience Credential Provider" "(Verified) Microsoft Windows" "C:\Windows\System32\cxcredprov.dll" "Sat Jun 5 13:05:23 2021" "
+ "CngCredUICredentialProvider" "Microsoft CNG CredUI Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\cngcredui.dll" "Sat Jun 5 13:05:40 2021" "
+ "FaceCredentialProvider" "Face Credential Provider" "(Verified) Microsoft Windows" "C:\Windows\System32\FaceCredentialProvider.dll" "Thu Dec 16 07:56:20 2021" "
+ "FIDO Credential Provider" "FIDO Credential Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\fidocredprov.dll" "Thu Dec 16 07:52:31 2021" "
+ "GenericProvider" "Credential Providers" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\credprovs.dll" "Sat Jun 5 13:05:27 2021" "
+ "NGC Credential Provider" "Microsoft Passport Credential Provider" "(Verified) Microsoft Windows" "C:\Windows\System32\ngccredprov.dll" "Thu Dec 16 07:52:53 2021" "
+ "NPProvider" "Credential Providers" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\credprovs.dll" "Sat Jun 5 13:05:27 2021" "
+ "PasswordProvider" "Credential Providers" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\credprovs.dll" "Sat Jun 5 13:05:27 2021" "
+ "PicturePasswordLogonProvider" "Credentials Providers Legacy" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\credprovslegacy.dll" "Thu Dec 16 07:54:15 2021" "
+ "PINLogonProvider" "Credentials Providers Legacy" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\credprovslegacy.dll" "Thu Dec 16 07:54:15 2021" "
+ "Second Authentication Factor Credential Provider" "Microsoft Companion Authenticator Credentials Provider" "(Verified) Microsoft Windows" "C:\Windows\System32\devicengccredprov.dll" "Thu Dec 16 07:54:15 2021" "
+ "Smartcard Credential Provider" "Windows Smartcard Credential Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\SmartcardCredentialProvider.dll" "Sat Jun 5 13:05:34 2021" "
+ "Smartcard Pin Provider" "Windows Smartcard Credential Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\SmartcardCredentialProvider.dll" "Sat Jun 5 13:05:34 2021" "
+ "Smartcard Reader Selection Provider" "Windows Smartcard Credential Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\SmartcardCredentialProvider.dll" "Sat Jun 5 13:05:34 2021" "
+ "Smartcard WinRT Provider" "Windows Smartcard Credential Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\SmartcardCredentialProvider.dll" "Sat Jun 5 13:05:34 2021" "
+ "TrustedSignal Credential Provider" "Trusted Signal Credential Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\TrustedSignalCredProv.dll" "Sat Jun 5 13:05:27 2021" "
+ "WinBio Credential Provider" "WinBio Credential Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\BioCredProv.dll" "Thu Dec 16 07:53:05 2021" "
+ "WLIDCredentialProvider" "Microsoft® Account Credential Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wlidcredprov.dll" "Sat Jun 5 13:05:31 2021" "
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\Credential Provider Filters]
+ "GenericFilter" "Credential Providers" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\credprovs.dll" "Sat Jun 5 13:05:27 2021" "
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\PLAP Providers]
+ "CRasProvider" "RAS PLAP Credential Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\rasplap.dll" "Sat Jun 5 13:05:40 2021" "
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GpExtensions]
+ "@wlgpclnt.dll,-100" "802.11 Group Policy Client" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wlgpclnt.dll" "Sat Jun 5 13:05:00 2021" "
+ "Central Access" "Windows Audit Settings CSE" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\auditcse.dll" "Sat Jun 5 13:05:40 2021" "
+ "Folder Redirection" "Folder Redirection Group Policy Extension" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\fdeploy.dll" "Sat Jun 5 13:05:14 2021" "
+ "Microsoft Disk Quota" "Windows Shell Disk Quota Support DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\dskquota.dll" "Sat Jun 5 13:06:05 2021" "
+ "QoS Packet Scheduler" "GPTExt" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\gptext.dll" "Sat Jun 5 13:05:29 2021" "
+ "Remote Desktop USB Redirection" "Remote Desktop USB Redirection GP Extension" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\TsUsbRedirectionGroupPolicyExtension.dll" "Sat Jun 5 13:04:57 2021" "
+ "@C:\Windows\System32\iedkcs32.dll,-3051" "IEAK branding" "(Verified) Microsoft Windows" "C:\Windows\System32\iedkcs32.dll" "Sat Jun 5 13:06:07 2021" "
+ "{4D2F9B6F-1E52-4711-A382-6A8B1A003DE6}" "RemoteApp and Desktop Connection Component" "(Verified) Microsoft Windows" "C:\Windows\System32\tsworkspace.dll" "Thu Dec 16 07:53:00 2021" "
+ "Work Folders" "Microsoft (C) Work Folders Group Policy Client Extension" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\WorkFoldersGPExt.dll" "Sat Jun 5 13:06:16 2021" "
+ "MDM Policy" "Enroll Engine DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\dmenrollengine.dll" "Thu Dec 16 07:54:17 2021" "
+ "Windows Search Group Policy Extension" "Indexing Options" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\srchadmin.dll" "Sat Jun 5 13:05:40 2021" "
+ "@C:\Windows\System32\iedkcs32.dll,-3051" "IEAK branding" "(Verified) Microsoft Windows" "C:\Windows\System32\iedkcs32.dll" "Sat Jun 5 13:06:07 2021" "
+ "Security" "Windows Security Configuration Editor Client Engine" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\scecli.dll" "Sat Jun 5 13:05:40 2021" "
+ "Start Layout Group Policy" "Start Tile Data InProc Server" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\StartTileData.dll" "Thu Dec 16 07:52:03 2021" "
+ "Deployed Printer Connections" "Group Policy Printer Extension" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\gpprnext.dll" "Sat Jun 5 13:04:58 2021" "
+ "@dot3gpclnt.dll,-100" "802.3 Group Policy Client" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\dot3gpclnt.dll" "Sat Jun 5 13:05:00 2021" "
+ "Windows To Go Startup Options" "Windows To Go Launcher" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\pwlauncher.dll" "Sat Jun 5 13:06:10 2021" "
+ "Windows To Go Hibernate Options" "Windows To Go Launcher" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\pwlauncher.dll" "Sat Jun 5 13:06:10 2021" "
+ "TCPIP" "GPTExt" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\gptext.dll" "Sat Jun 5 13:05:29 2021" "
+ "@C:\Windows\System32\iedkcs32.dll,-3051" "IEAK branding" "(Verified) Microsoft Windows" "C:\Windows\System32\iedkcs32.dll" "Sat Jun 5 13:06:07 2021" "
+ "Delivery Optimization GP extension" "Delivery Optimisation Management" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\domgmt.dll" "Thu Dec 16 07:52:21 2021" "
+ "Internet Protocol Security Policies" "Policy Storage dll" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\polstore.dll" "Sat Jun 5 13:05:29 2021" "
+ "Audit" "Windows Audit Settings CSE" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\auditcse.dll" "Sat Jun 5 13:05:40 2021" "
+ "Policy-based QoS" "GPTExt" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\gptext.dll" "Sat Jun 5 13:05:29 2021" "
+ "Connectivity Platform" "GPTExt" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\gptext.dll" "Sat Jun 5 13:05:29 2021" "
[Winsock Providers]
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries]
+ "AF_UNIX" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mswsock.dll" "Sat Jun 5 13:05:23 2021" "
+ "Hyper-V RAW" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mswsock.dll" "Sat Jun 5 13:05:23 2021" "
+ "MSAFD L2CAP [Bluetooth]" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mswsock.dll" "Sat Jun 5 13:05:23 2021" "
+ "MSAFD RfComm [Bluetooth]" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mswsock.dll" "Sat Jun 5 13:05:23 2021" "
+ "MSAFD Tcpip [RAW/IP]" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mswsock.dll" "Sat Jun 5 13:05:23 2021" "
+ "MSAFD Tcpip [RAW/IPv6]" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mswsock.dll" "Sat Jun 5 13:05:23 2021" "
+ "MSAFD Tcpip [TCP/IP]" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mswsock.dll" "Sat Jun 5 13:05:23 2021" "
+ "MSAFD Tcpip [TCP/IPv6]" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mswsock.dll" "Sat Jun 5 13:05:23 2021" "
+ "MSAFD Tcpip [UDP/IP]" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mswsock.dll" "Sat Jun 5 13:05:23 2021" "
+ "MSAFD Tcpip [UDP/IPv6]" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mswsock.dll" "Sat Jun 5 13:05:23 2021" "
+ "RSVP TCP Service Provider" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mswsock.dll" "Sat Jun 5 13:05:23 2021" "
+ "RSVP TCPv6 Service Provider" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mswsock.dll" "Sat Jun 5 13:05:23 2021" "
+ "RSVP UDP Service Provider" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mswsock.dll" "Sat Jun 5 13:05:23 2021" "
+ "RSVP UDPv6 Service Provider" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mswsock.dll" "Sat Jun 5 13:05:23 2021" "
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries]
+ "@%SystemRoot%\system32\nlasvc.dll,-1000" "NLA Namespace Service Provider DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\nlansp_c.dll" "Sat Jun 5 13:05:39 2021" "
+ "Bluetooth Namespace" "Windows Sockets Helper DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wshbth.dll" "Thu Dec 16 07:53:06 2021" "
+ "E-mail Naming Shim Provider" "E-mail Naming Shim Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\napinsp.dll" "Sat Jun 5 13:05:27 2021" "
+ "NTDS" "LDAP RnR Provider DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\winrnr.dll" "Sat Jun 5 13:05:29 2021" "
+ "PNRP Cloud Namespace Provider" "PNRP Name Space Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\pnrpnsp.dll" "Sat Jun 5 13:06:16 2021" "
+ "PNRP Name Namespace Provider" "PNRP Name Space Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\pnrpnsp.dll" "Sat Jun 5 13:06:16 2021" "
+ "Tcpip" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\mswsock.dll" "Sat Jun 5 13:05:23 2021" "
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64]
+ "AF_UNIX" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mswsock.dll" "Sat Jun 5 13:05:23 2021" "
+ "Hyper-V RAW" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mswsock.dll" "Sat Jun 5 13:05:23 2021" "
+ "MSAFD L2CAP [Bluetooth]" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mswsock.dll" "Sat Jun 5 13:05:23 2021" "
+ "MSAFD RfComm [Bluetooth]" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mswsock.dll" "Sat Jun 5 13:05:23 2021" "
+ "MSAFD Tcpip [RAW/IP]" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mswsock.dll" "Sat Jun 5 13:05:23 2021" "
+ "MSAFD Tcpip [RAW/IPv6]" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mswsock.dll" "Sat Jun 5 13:05:23 2021" "
+ "MSAFD Tcpip [TCP/IP]" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mswsock.dll" "Sat Jun 5 13:05:23 2021" "
+ "MSAFD Tcpip [TCP/IPv6]" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mswsock.dll" "Sat Jun 5 13:05:23 2021" "
+ "MSAFD Tcpip [UDP/IP]" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mswsock.dll" "Sat Jun 5 13:05:23 2021" "
+ "MSAFD Tcpip [UDP/IPv6]" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mswsock.dll" "Sat Jun 5 13:05:23 2021" "
+ "RSVP TCP Service Provider" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mswsock.dll" "Sat Jun 5 13:05:23 2021" "
+ "RSVP TCPv6 Service Provider" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mswsock.dll" "Sat Jun 5 13:05:23 2021" "
+ "RSVP UDP Service Provider" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mswsock.dll" "Sat Jun 5 13:05:23 2021" "
+ "RSVP UDPv6 Service Provider" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mswsock.dll" "Sat Jun 5 13:05:23 2021" "
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64]
+ "@%SystemRoot%\system32\nlasvc.dll,-1000" "NLA Namespace Service Provider DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\nlansp_c.dll" "Sat Jun 5 13:05:39 2021" "
+ "Bluetooth Namespace" "Windows Sockets Helper DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wshbth.dll" "Thu Dec 16 07:53:06 2021" "
+ "E-mail Naming Shim Provider" "E-mail Naming Shim Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\napinsp.dll" "Sat Jun 5 13:05:27 2021" "
+ "NTDS" "LDAP RnR Provider DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\winrnr.dll" "Sat Jun 5 13:05:29 2021" "
+ "PNRP Cloud Namespace Provider" "PNRP Name Space Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\pnrpnsp.dll" "Sat Jun 5 13:06:16 2021" "
+ "PNRP Name Namespace Provider" "PNRP Name Space Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\pnrpnsp.dll" "Sat Jun 5 13:06:16 2021" "
+ "Tcpip" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\mswsock.dll" "Sat Jun 5 13:05:23 2021" "
[Print Monitors]
[HKLM\System\CurrentControlSet\Control\Print\Monitors]
+ "Appmon" "App Printer" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\AppMon.dll" "Sat Jun 5 13:06:16 2021" "
+ "Local Port" "Local Spooler DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\localspl.dll" "Thu Dec 16 07:51:44 2021" "
+ "Microsoft Shared Fax Monitor" "Microsoft Fax Print Monitor" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\FXSMON.DLL" "Sat Jun 5 02:37:00 2021" "
+ "Standard TCP/IP Port" "Standard TCP/IP Port Monitor DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\tcpmon.dll" "Sat Jun 5 13:05:39 2021" "
+ "USB Monitor" "Standard Dynamic Printing Port Monitor DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\usbmon.dll" "Thu Dec 16 07:51:54 2021" "
+ "WSD Port" "Adaptive Port Monitor" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\APMon.dll" "Thu Dec 16 07:54:54 2021" "
[HKLM\System\CurrentControlSet\Control\Print\Providers]
+ "HTTP Print Services" "Internet Print Provider DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\inetpp.dll" "Thu Dec 16 07:56:55 2021" "
+ "LanMan Print Services" "Client Side Rendering Print Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\win32spl.dll" "Thu Dec 16 07:51:44 2021" "
[LSA Providers]
[HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\SecurityProviders]
+ "credssp.dll" "Credential Delegation Security Package" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\credssp.dll" "Thu Dec 16 07:54:57 2021" "
[HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Authentication Packages]
+ "msv1_0" "Microsoft Authentication Package v1.0" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\msv1_0.dll" "Thu Dec 16 07:53:45 2021" "
[HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Notification Packages]
+ "scecli" "Windows Security Configuration Editor Client Engine" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\scecli.dll" "Sat Jun 5 13:05:40 2021" "
[HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Security Packages]
[HKLM\SYSTEM\CurrentControlSet\Control\Lsa\OSConfig\Security Packages]
[Network Providers]
[HKLM\SYSTEM\CurrentControlSet\Control\NetworkProvider\Order]
+ "LanmanWorkstation" "Microsoft Windows Network" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\ntlanman.dll" "Thu Dec 16 07:53:53 2021" "
+ "P9NP" "Plan 9 Network Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\p9np.dll" "Sat Jun 5 13:06:17 2021" "
+ "RDPNP" "Microsoft Terminal Services" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drprov.dll" "Sat Jun 5 13:06:14 2021" "
+ "webclient" "Web Client Network" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\davclnt.dll" "Sat Jun 5 13:06:17 2021" "
[WMI]
[WMI Database Entries - run as Administrator for complete scan]
[Office]
[HKCU\Software\Microsoft\Office\Outlook\Addins]
[HKCU\Software\Microsoft\Office\Excel\Addins]
[HKCU\Software\Microsoft\Office\PowerPoint\Addins]
[HKCU\Software\Microsoft\Office\Word\Addins]
[HKCU\Software\Microsoft\Office\Access\Addins]
[HKCU\Software\Microsoft\Office\OneNote\Addins]
[HKCU\SOFTWARE\Microsoft\Office test\Special\Perf\(Default)]
[HKCU\Software\Wow6432Node\Microsoft\Office\Outlook\Addins]
[HKCU\Software\Wow6432Node\Microsoft\Office\Excel\Addins]
[HKCU\Software\Wow6432Node\Microsoft\Office\PowerPoint\Addins]
[HKCU\Software\Wow6432Node\Microsoft\Office\Word\Addins]
[HKCU\Software\Wow6432Node\Microsoft\Office\Access\Addins]
[HKCU\Software\Wow6432Node\Microsoft\Office\OneNote\Addins]
[HKCU\SOFTWARE\Wow6432Node\Microsoft\Office test\Special\Perf\(Default)]
[HKLM\Software\Microsoft\Office\Outlook\Addins]
[HKLM\Software\Microsoft\Office\Excel\Addins]
[HKLM\Software\Microsoft\Office\PowerPoint\Addins]
[HKLM\Software\Microsoft\Office\Word\Addins]
[HKLM\Software\Microsoft\Office\Access\Addins]
[HKLM\Software\Microsoft\Office\OneNote\Addins]
[HKLM\SOFTWARE\Microsoft\Office test\Special\Perf\(Default)]
[HKLM\Software\Wow6432Node\Microsoft\Office\Outlook\Addins]
[HKLM\Software\Wow6432Node\Microsoft\Office\Excel\Addins]
[HKLM\Software\Wow6432Node\Microsoft\Office\PowerPoint\Addins]
[HKLM\Software\Wow6432Node\Microsoft\Office\Word\Addins]
[HKLM\Software\Wow6432Node\Microsoft\Office\Access\Addins]
[HKLM\Software\Wow6432Node\Microsoft\Office\OneNote\Addins]
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Office test\Special\Perf\(Default)]
 
3: Click on the "Hide Signed Microsoft and Windows Entries” option.

Sorry but you have not done as was asked, we need the info saving as a text file so that it can be attached to your reply + there is a whole lot of MS stuff there that we do not need, I`m afraid that makes it harder to find anything in the log that should not be there.

From the tutorial link link that was provided ;) To Disable or Delete?

The three items below need to go, delete them in AutoRuns, run the tool again but this time be sure to hide the Microsoft results and to save the log a Text before you attach it.


+ "Norton Download Manager{NSBU222005-SHPD-FSD52405}" "Norton Download Manager" "(Verified) NortonLifeLock Inc."

"C:\Users\Public\Downloads\Norton\{NSBU222005-SHPD-FSD52405}\FSDUI_Custom.exe" "Fri Dec 17 16:35:00 2021" "


+ "\Christmas Task (One-Time)" "" "" "File not found: C:\Program Files (x86)\IObit\Advanced SystemCare\xmas.exe" "" "
 
Oh thats not it sorry, here it is ..

[Logon]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System\Shell]
[HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell]
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
+ X "CCleaner Smart Cleaning" "CCleaner" "(Verified) Piriform Software Ltd" "C:\Program Files\CCleaner\CCleaner64.exe" "Tue Dec 7 19:06:42 2021" "
+ "OneDrive" "Microsoft OneDrive" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\OneDrive.exe" "Tue Dec 7 07:14:41 2021" "
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx]
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
[HKCU\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
[HKCU\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce]
[HKCU\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnceEx]
[HKCU\Environment\UserInitMprLogonScript]
[HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows\Load]
[HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows\Run]
[HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\RunOnce]
[HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\RunOnceEx]
[HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\Run]
[HKLM\System\CurrentControlSet\Control\Terminal Server\Wds\rdpwd\StartupPrograms]
+ "rdpclip" "RDP Clipboard Monitor" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\rdpclip.exe" "Thu Dec 16 07:56:43 2021" "
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\AppSetup]
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
+ "RtkAudUService" "Realtek HD Audio Universal Service" "(Verified) Realtek Semiconductor Corp." "C:\WINDOWS\System32\DriverStore\FileRepository\realtekservice.inf_amd64_f043f909bedcd504\RtkAudUService64.exe" "Wed Oct 6 20:03:40 2021" "
+ "SecurityHealth" "Windows Security notification icon" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\SecurityHealthSystray.exe" "Thu Dec 16 07:53:16 2021" "
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
+ "msedge_cleanup_{F3017226-FE2A-4295-8BDF-00C3A9A7E4C5}" "Microsoft Edge Installer" "(Verified) Microsoft Corporation" "C:\Program Files (x86)\Microsoft\EdgeWebView\Application\96.0.1054.57\Installer\setup.exe" "Thu Dec 16 17:39:31 2021" "
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\Shell]
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell]
+ "explorer.exe" "Windows Explorer" "(Verified) Microsoft Windows" "C:\WINDOWS\explorer.exe" "Thu Dec 16 07:51:50 2021" "
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\AlternateShell]
+ "cmd.exe" "Windows Command Processor" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\cmd.exe" "Sat Jun 5 13:05:12 2021" "
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\TaskMan]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\UserInit]
+ "C:\Windows\system32\userinit.exe" "Userinit Log-on Application" "(Verified) Microsoft Windows" "C:\Windows\system32\userinit.exe" "Thu Dec 16 07:53:45 2021" "
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\VmApplet]
+ "SystemPropertiesPerformance.exe /pagefile" "Change Computer Performance Settings" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\SystemPropertiesPerformance.exe" "Sat Jun 5 13:05:34 2021" "
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\AlternateShells\AvailableShells]
[HKLM\Environment\UserInitMprLogonScript]
[HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components]
+ "Google Chrome" "Google Chrome Installer" "(Verified) Google LLC" "C:\Program Files\Google\Chrome\Application\96.0.4664.110\Installer\chrmstp.exe" "Wed Dec 15 22:49:20 2021" "
+ "Microsoft Edge" "Microsoft Edge Installer" "(Verified) Microsoft Corporation" "C:\Program Files (x86)\Microsoft\Edge\Application\96.0.1054.62\Installer\setup.exe" "Sun Dec 19 15:21:26 2021" "
+ "Microsoft Windows Media Player" "Microsoft Windows Media Player Setup Utility" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\unregmp2.exe" "Sat Jun 5 02:35:00 2021" "
+ "Microsoft Windows Media Player" "Microsoft Windows Media Player Setup Utility" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\unregmp2.exe" "Sat Jun 5 02:35:00 2021" "
+ "n/a" "Microsoft .NET IE SECURITY REGISTRATION" "(Verified) Microsoft Corporation" "C:\Windows\System32\mscories.dll" "Sat Jun 5 13:06:26 2021" "
+ "Themes Setup" "Windows Theme API" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\themeui.dll" "Thu Dec 16 07:52:59 2021" "
+ "Web Platform Customizations" "IE Per-User Initialisation Utility" "(Verified) Microsoft Windows" "C:\Windows\System32\ie4uinit.exe" "Thu Dec 16 07:56:33 2021" "
+ "Windows Desktop Update" "Windows Shell Common Dll" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\shell32.dll" "Thu Dec 16 07:54:27 2021" "
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows\IconServiceLib]
+ "IconCodecService.dll" "Converts a PNG part of the icon to a legacy bmp icon" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\IconCodecService.dll" "Sat Jun 5 13:05:29 2021" "
[HKLM\SOFTWARE\Microsoft\Windows CE Services\AutoStartOnConnect]
[HKLM\SOFTWARE\Microsoft\Windows CE Services\AutoStartDisconnect]
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
+ "msedge_cleanup_{F3017226-FE2A-4295-8BDF-00C3A9A7E4C5}" "Microsoft Edge Installer" "(Verified) Microsoft Corporation" "C:\Program Files (x86)\Microsoft\EdgeWebView\Application\96.0.1054.57\Installer\setup.exe" "Thu Dec 16 17:39:31 2021" "
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce]
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnceEx]
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Active Setup\Installed Components]
+ "Microsoft Windows Media Player" "Microsoft Windows Media Player Setup Utility" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\unregmp2.exe" "Sat Jun 5 01:03:00 2021" "
+ "Microsoft Windows Media Player" "Microsoft Windows Media Player Setup Utility" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\unregmp2.exe" "Sat Jun 5 01:03:00 2021" "
+ "n/a" "Microsoft .NET IE SECURITY REGISTRATION" "(Verified) Microsoft Corporation" "C:\Windows\System32\mscories.dll" "Sat Jun 5 13:06:26 2021" "
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows CE Services\AutoStartOnConnect]
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows CE Services\AutoStartOnDisconnect]
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\RunOnce]
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\RunOnceEx]
[HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp\InitialProgram]
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
[C:\Users\chris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup]
[C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup]
[%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup]
[HKCU\Software\Policies\Microsoft\Windows\System\Scripts\Logon]
[HKCU\Software\Policies\Microsoft\Windows\System\Scripts\Logoff]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Startup]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Logon]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Logoff]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Shutdown]
[HKLM\Software\Policies\Microsoft\Windows\System\Scripts\Startup]
[HKLM\Software\Policies\Microsoft\Windows\System\Scripts\Logon]
[HKLM\Software\Policies\Microsoft\Windows\System\Scripts\Logoff]
[HKLM\Software\Policies\Microsoft\Windows\System\Scripts\Shutdown]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Shutdown]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Logoff]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Logon]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Startup]
[Explorer]
[HKCU\SOFTWARE\Classes\Protocols\Filter]
[HKCU\SOFTWARE\Classes\Protocols\Handler]
[HKCU\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components]
[HKCU\Software\Classes\*\ShellEx\ContextMenuHandlers]
[HKCU\Software\Classes\Drive\ShellEx\ContextMenuHandlers]
[HKCU\Software\Classes\*\ShellEx\PropertySheetHandlers]
[HKCU\Software\Classes\AllFileSystemObjects\ShellEx\ContextMenuHandlers]
[HKCU\Software\Classes\AllFileSystemObjects\ShellEx\DragDropHandlers]
[HKCU\Software\Classes\AllFileSystemObjects\ShellEx\PropertySheetHandlers]
[HKCU\Software\Classes\Directory\ShellEx\ContextMenuHandlers]
[HKCU\Software\Classes\Directory\ShellEx\DragDropHandlers]
[HKCU\Software\Classes\Directory\ShellEx\PropertySheetHandlers]
[HKCU\Software\Classes\Directory\ShellEx\CopyHookHandlers]
[HKCU\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers]
[HKCU\Software\Classes\Folder\ShellEx\ContextMenuHandlers]
[HKCU\Software\Classes\Folder\ShellEx\DragDropHandlers]
[HKCU\Software\Classes\Folder\ShellEx\PropertySheetHandlers]
[HKCU\Software\Classes\Folder\ShellEx\ColumnHandlers]
[HKCU\Software\Classes\Folder\ShellEx\ExtShellFolderViews]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers]
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
[HKCU\Software\Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\InProcServer32]
[HKCU\Software\Microsoft\Ctf\LangBarAddin]
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellServiceObjects]
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellServiceObjects]
+ "Published Items Shell Service Object" "Windows Shell Common Dll" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\shell32.dll" "Thu Dec 16 07:54:27 2021" "
+ "Microsoft VolumeControlService Class" "SCA Volume" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\SndVolSSO.dll" "Thu Dec 16 07:53:36 2021" "
+ "Windows To Go Shell Service Object" "Windows To Go Shell Service Object" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\pwsso.dll" "Sat Jun 5 13:06:10 2021" "
+ "Device Stage Shell Extension" "Device Stage Shell Extension" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\dxp.dll" "Sat Jun 5 13:06:05 2021" "
+ "Cloud Cache Invalidator SSO" "Cloud Data Store" "(Verified) Microsoft Windows" "C:\Windows\System32\Windows.CloudStore.dll" "Thu Dec 16 07:52:04 2021" "
+ "UnexpectedShutdownReason" "Systray shell service object" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\stobject.dll" "Thu Dec 16 07:51:51 2021" "
+ "PostBootReminder object" "Windows Shell Common Dll" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\shell32.dll" "Thu Dec 16 07:54:27 2021" "
+ "OneDrive network states cache SSO" "Windows.FileExplorer.Common" "(Verified) Microsoft Windows" "C:\Windows\System32\Windows.FileExplorer.Common.dll" "Thu Dec 16 07:54:27 2021" "
+ "Library Group Policy Shell Service Object" "Microsoft WinRT Storage API" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\windows.storage.dll" "Thu Dec 16 07:52:34 2021" "
+ "Windows System Reset SSO" "Windows System Reset Platform SSO" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\SystemResetPlatform\SystemResetSSO.dll" "Sat Jun 5 13:06:11 2021" "
+ "User Account Control Check Service" "Security and Maintenance Providers" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\hcproviders.dll" "Sat Jun 5 13:05:29 2021" "
+ "WPDShServiceObj Class" "Windows Portable Device Shell Service Object" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wpdshserviceobj.dll" "Sat Jun 5 18:16:58 2021" "
+ "Network Tray SSO" "Network System Icon" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\pnidui.dll" "Thu Dec 16 07:54:50 2021" "
+ "Windows Search Shell Service Object" "Indexing Options" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\srchadmin.dll" "Sat Jun 5 13:05:40 2021" "
+ "WebCheck" "Shell Doc Object and Control Library" "(Verified) Microsoft Windows" "C:\Windows\System32\shdocvw.dll" "Thu Dec 16 07:54:26 2021" "
+ "Bluetooth Authentication Agent SSO" "Bluetooth Control Panel Applet" "(Verified) Microsoft Windows" "C:\Windows\System32\bthprops.cpl" "Sat Jun 5 13:05:23 2021" "
+ "Sync Center Shell Service Object (Internal)" "Microsoft Sync Centre" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\SyncCenter.dll" "Sat Jun 5 13:06:11 2021" "
+ "Security and Maintenance Shell Service Object" "Security and Maintenance" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Actioncenter.dll" "Sat Jun 5 13:05:29 2021" "
+ "ShellFolder for CD Burning" "Windows Shell Common Dll" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\shell32.dll" "Thu Dec 16 07:54:27 2021" "
+ "HomeGroup SSO" "HomeGroup Control Panel" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\hgcpl.dll" "Sat Jun 5 13:05:29 2021" "
[HKLM\SOFTWARE\Classes\Protocols\Filter]
+ "application/octet-stream" "Microsoft .NET Runtime Execution Engine" "(Verified) Microsoft Windows" "C:\Windows\System32\mscoree.dll" "Sat Jun 5 13:06:26 2021" "
+ "application/x-complus" "Microsoft .NET Runtime Execution Engine" "(Verified) Microsoft Windows" "C:\Windows\System32\mscoree.dll" "Sat Jun 5 13:06:26 2021" "
+ "application/x-msdownload" "Microsoft .NET Runtime Execution Engine" "(Verified) Microsoft Windows" "C:\Windows\System32\mscoree.dll" "Sat Jun 5 13:06:26 2021" "
+ "text/xml" "Microsoft Office XML MIME Filter" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\MSOXMLMF.DLL" "Fri Dec 10 12:44:05 2021" "
[HKLM\SOFTWARE\Classes\Protocols\Handler]
+ "about" "Microsoft (R) HTML Viewer" "(Verified) Microsoft Windows" "C:\Windows\System32\mshtml.dll" "Thu Dec 16 07:56:36 2021" "
+ "cdl" "OLE32 Extensions for Win32" "(Verified) Microsoft Windows" "C:\Windows\System32\urlmon.dll" "Thu Dec 16 07:54:22 2021" "
+ "dvd" "ActiveX control for streaming video" "(Verified) Microsoft Windows" "C:\Windows\System32\msvidctl.dll" "Sat Jun 5 13:06:14 2021" "
+ "file" "OLE32 Extensions for Win32" "(Verified) Microsoft Windows" "C:\Windows\System32\urlmon.dll" "Thu Dec 16 07:54:22 2021" "
+ "ftp" "OLE32 Extensions for Win32" "(Verified) Microsoft Windows" "C:\Windows\System32\urlmon.dll" "Thu Dec 16 07:54:22 2021" "
+ "http" "OLE32 Extensions for Win32" "(Verified) Microsoft Windows" "C:\Windows\System32\urlmon.dll" "Thu Dec 16 07:54:22 2021" "
+ "https" "OLE32 Extensions for Win32" "(Verified) Microsoft Windows" "C:\Windows\System32\urlmon.dll" "Thu Dec 16 07:54:22 2021" "
+ "its" "Microsoft® InfoTech Storage System Library" "(Verified) Microsoft Windows" "C:\Windows\System32\itss.dll" "Sat Jun 5 13:06:05 2021" "
+ "javascript" "Microsoft (R) HTML Viewer" "(Verified) Microsoft Windows" "C:\Windows\System32\mshtml.dll" "Thu Dec 16 07:56:36 2021" "
+ "local" "OLE32 Extensions for Win32" "(Verified) Microsoft Windows" "C:\Windows\System32\urlmon.dll" "Thu Dec 16 07:54:22 2021" "
+ "mailto" "Microsoft (R) HTML Viewer" "(Verified) Microsoft Windows" "C:\Windows\System32\mshtml.dll" "Thu Dec 16 07:56:36 2021" "
+ "mhtml" "Microsoft Internet Messaging API Resources" "(Verified) Microsoft Windows" "C:\Windows\System32\inetcomm.dll" "Sat Jun 5 13:06:07 2021" "
+ "mk" "OLE32 Extensions for Win32" "(Verified) Microsoft Windows" "C:\Windows\System32\urlmon.dll" "Thu Dec 16 07:54:22 2021" "
+ "ms-its" "Microsoft® InfoTech Storage System Library" "(Verified) Microsoft Windows" "C:\Windows\System32\itss.dll" "Sat Jun 5 13:06:05 2021" "
+ "mso-minsb-roaming.16" "Microsoft Office component" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL" "Fri Dec 10 12:41:11 2021" "
+ "mso-minsb.16" "Microsoft Office component" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL" "Fri Dec 10 12:41:11 2021" "
+ "osf-roaming.16" "Microsoft Office component" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL" "Fri Dec 10 12:41:11 2021" "
+ "osf.16" "Microsoft Office component" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL" "Fri Dec 10 12:41:11 2021" "
+ "res" "Microsoft (R) HTML Viewer" "(Verified) Microsoft Windows" "C:\Windows\System32\mshtml.dll" "Thu Dec 16 07:56:36 2021" "
+ "tbauth" "TBAuth protocol handler" "(Verified) Microsoft Windows" "C:\Windows\System32\tbauth.dll" "Thu Dec 16 07:52:14 2021" "
+ "tv" "ActiveX control for streaming video" "(Verified) Microsoft Windows" "C:\Windows\System32\msvidctl.dll" "Sat Jun 5 13:06:14 2021" "
+ "vbscript" "Microsoft (R) HTML Viewer" "(Verified) Microsoft Windows" "C:\Windows\System32\mshtml.dll" "Thu Dec 16 07:56:36 2021" "
+ "windows.tbauth" "TBAuth protocol handler" "(Verified) Microsoft Windows" "C:\Windows\System32\tbauth.dll" "Thu Dec 16 07:52:14 2021" "
[HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers]
+ " FileSyncEx" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ "EPP" "Microsoft Security Client Shell Extension" "(Not Verified) Microsoft Corporation" "C:\Program Files\Windows Defender\shellext.dll" "Sat Jun 5 13:04:55 2021" "
+ "Open With" "Windows Shell Common Dll" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\shell32.dll" "Thu Dec 16 07:54:27 2021" "
+ "Open With EncryptionMenu" "Windows Shell Common Dll" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\shell32.dll" "Thu Dec 16 07:54:27 2021" "
+ "Sharing" "Shell extensions for sharing" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\ntshrui.dll" "Thu Dec 16 07:54:27 2021" "
+ "WorkFolders" "Microsoft (C) Work Folders Shell Extension" "(Verified) Microsoft Windows" "C:\Windows\System32\WorkfoldersShell.dll" "Sat Jun 5 13:06:16 2021" "
+ "Taskband Pin" "Windows Shell Common Dll" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\shell32.dll" "Thu Dec 16 07:54:27 2021" "
+ "Start Menu Pin" "Windows Shell Common Dll" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\shell32.dll" "Thu Dec 16 07:54:27 2021" "
[HKLM\Software\Classes\Drive\ShellEx\ContextMenuHandlers]
+ "EnhancedStorageShell" "Windows Enhanced Storage Shell Extension DLL" "(Verified) Microsoft Windows" "C:\Windows\System32\EhStorShell.dll" "Sat Jun 5 13:05:29 2021" "
+ "EPP" "Microsoft Security Client Shell Extension" "(Not Verified) Microsoft Corporation" "C:\Program Files\Windows Defender\shellext.dll" "Sat Jun 5 13:04:55 2021" "
+ "Sharing" "Shell extensions for sharing" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\ntshrui.dll" "Thu Dec 16 07:54:27 2021" "
+ "Previous Versions Property Page" "Previous Versions property page" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\twext.dll" "Sat Jun 5 13:05:33 2021" "
+ "Portable Devices Menu" "Portable Devices Shell Extension" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wpdshext.dll" "Sat Jun 5 18:16:58 2021" "
+ "ShellFolder for CD Burning" "Windows Shell Common Dll" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\shell32.dll" "Thu Dec 16 07:54:27 2021" "
[HKLM\Software\Classes\*\ShellEx\PropertySheetHandlers]
+ "CryptoSignMenu" "Crypto Shell Extensions" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\cryptext.dll" "Sat Jun 5 13:05:27 2021" "
+ "Security Shell Extension" "Security Shell Extension" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\rshx32.dll" "Sat Jun 5 13:06:02 2021" "
+ "OLE DocFile Property Page" "OLE DocFile Property Page" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\docprop.dll" "Sat Jun 5 13:05:33 2021" "
+ "Summary Properties Page" "Windows Shell Common Dll" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\shell32.dll" "Thu Dec 16 07:54:27 2021" "
[HKLM\Software\Classes\AllFileSystemObjects\ShellEx\ContextMenuHandlers]
+ "CopyAsPathMenu" "Windows Shell Common Dll" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\shell32.dll" "Thu Dec 16 07:54:27 2021" "
+ "ModernSharing" "Shell extensions for sharing" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\ntshrui.dll" "Thu Dec 16 07:54:27 2021" "
+ "SendTo" "Windows Shell Common Dll" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\shell32.dll" "Thu Dec 16 07:54:27 2021" "
+ "Previous Versions Property Page" "Previous Versions property page" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\twext.dll" "Sat Jun 5 13:05:33 2021" "
+ "Start Menu Pin" "Windows Shell Common Dll" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\shell32.dll" "Thu Dec 16 07:54:27 2021" "
[HKLM\Software\Classes\AllFileSystemObjects\ShellEx\DragDropHandlers]
[HKLM\Software\Classes\AllFileSystemObjects\ShellEx\PropertySheetHandlers]
+ "Previous Versions Property Page" "Previous Versions property page" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\twext.dll" "Sat Jun 5 13:05:33 2021" "
[HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers]
+ " FileSyncEx" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ "EncryptionMenu" "Windows Shell Common Dll" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\shell32.dll" "Thu Dec 16 07:54:27 2021" "
+ "EPP" "Microsoft Security Client Shell Extension" "(Not Verified) Microsoft Corporation" "C:\Program Files\Windows Defender\shellext.dll" "Sat Jun 5 13:04:55 2021" "
+ "Sharing" "Shell extensions for sharing" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\ntshrui.dll" "Thu Dec 16 07:54:27 2021" "
+ "WorkFolders" "Microsoft (C) Work Folders Shell Extension" "(Verified) Microsoft Windows" "C:\Windows\System32\WorkfoldersShell.dll" "Sat Jun 5 13:06:16 2021" "
+ "Previous Versions Property Page" "Previous Versions property page" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\twext.dll" "Sat Jun 5 13:05:33 2021" "
[HKLM\Software\Classes\Directory\ShellEx\DragDropHandlers]
[HKLM\Software\Classes\Directory\ShellEx\PropertySheetHandlers]
+ "Sharing" "Shell extensions for sharing" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\ntshrui.dll" "Thu Dec 16 07:54:27 2021" "
+ "Security Shell Extension" "Security Shell Extension" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\rshx32.dll" "Sat Jun 5 13:06:02 2021" "
+ "MyFolder menu and properties" "My Documents Folder UI" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mydocs.dll" "Sat Jun 5 13:05:14 2021" "
+ "Previous Versions Property Page" "Previous Versions property page" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\twext.dll" "Sat Jun 5 13:05:33 2021" "
+ "DfsShell Class" "Distributed File System shell extension" "(Verified) Microsoft Windows" "C:\Windows\System32\DfsShlEx.dll" "Sat Jun 5 13:05:37 2021" "
+ "Folder Customization Tab" "Windows Shell Common Dll" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\shell32.dll" "Thu Dec 16 07:54:27 2021" "
[HKLM\Software\Classes\Directory\ShellEx\CopyHookHandlers]
+ "FileSystem" "Windows Shell Common Dll" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\shell32.dll" "Thu Dec 16 07:54:27 2021" "
+ "Sharing" "Shell extensions for sharing" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\ntshrui.dll" "Thu Dec 16 07:54:27 2021" "
[HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers]
+ " FileSyncEx" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ "New" "Windows Shell Common Dll" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\shell32.dll" "Thu Dec 16 07:54:27 2021" "
+ "Sharing" "Shell extensions for sharing" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\ntshrui.dll" "Thu Dec 16 07:54:27 2021" "
+ "WorkFolders" "Microsoft (C) Work Folders Shell Extension" "(Verified) Microsoft Windows" "C:\Windows\System32\WorkfoldersShell.dll" "Sat Jun 5 13:06:16 2021" "
[HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers]
+ "Library Location" "Windows Shell Common Dll" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\shell32.dll" "Thu Dec 16 07:54:27 2021" "
+ "PintoStartScreen" "App Resolver" "(Verified) Microsoft Windows" "C:\Windows\System32\appresolver.dll" "Thu Dec 16 07:53:11 2021" "
+ "Start Menu Pin" "Windows Shell Common Dll" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\shell32.dll" "Thu Dec 16 07:54:27 2021" "
[HKLM\Software\Classes\Folder\ShellEx\DragDropHandlers]
+ "Compressed (zipped) Folder Right Drag Handler" "Compressed (zipped) Folders" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\zipfldr.dll" "Thu Dec 16 07:53:41 2021" "
[HKLM\Software\Classes\Folder\ShellEx\PropertySheetHandlers]
[HKLM\Software\Classes\Folder\ShellEx\ColumnHandlers]
[HKLM\Software\Classes\Folder\ShellEx\ExtShellFolderViews]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers]
+ " OneDrive1" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ " OneDrive2" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ " OneDrive3" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ " OneDrive4" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ " OneDrive5" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ " OneDrive6" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ " OneDrive7" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ " OneDrive1" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ " OneDrive2" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ " OneDrive3" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ " OneDrive4" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ " OneDrive5" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ " OneDrive6" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ " OneDrive7" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ "EnhancedStorageShell" "Windows Enhanced Storage Shell Extension DLL" "(Verified) Microsoft Windows" "C:\Windows\System32\EhStorShell.dll" "Sat Jun 5 13:05:29 2021" "
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
[HKLM\Software\Microsoft\Ctf\LangBarAddin]
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
[HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellServiceObjects]
+ "Published Items Shell Service Object" "Windows Shell Common Dll" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\shell32.dll" "Thu Dec 16 07:56:19 2021" "
+ "Microsoft VolumeControlService Class" "SCA Volume" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\SndVolSSO.dll" "Thu Dec 16 07:55:56 2021" "
+ "UnexpectedShutdownReason" "Systray shell service object" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\stobject.dll" "Thu Dec 16 07:55:17 2021" "
+ "PostBootReminder object" "Windows Shell Common Dll" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\shell32.dll" "Thu Dec 16 07:56:19 2021" "
+ "OneDrive network states cache SSO" "Windows.FileExplorer.Common" "(Verified) Microsoft Windows" "C:\Windows\Syswow64\Windows.FileExplorer.Common.dll" "Thu Dec 16 07:56:19 2021" "
+ "Library Group Policy Shell Service Object" "Microsoft WinRT Storage API" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\windows.storage.dll" "Thu Dec 16 07:55:47 2021" "
+ "User Account Control Check Service" "Security and Maintenance Providers" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\hcproviders.dll" "Sat Jun 5 13:05:55 2021" "
+ "WPDShServiceObj Class" "Windows Portable Device Shell Service Object" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\wpdshserviceobj.dll" "Sat Jun 5 18:17:05 2021" "
+ "Windows Search Shell Service Object" "Indexing Options" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\srchadmin.dll" "Sat Jun 5 13:06:00 2021" "
+ "WebCheck" "Shell Doc Object and Control Library" "(Verified) Microsoft Windows" "C:\Windows\Syswow64\shdocvw.dll" "Thu Dec 16 07:56:18 2021" "
+ "Bluetooth Authentication Agent SSO" "Bluetooth Control Panel Applet" "(Verified) Microsoft Windows" "C:\Windows\Syswow64\bthprops.cpl" "Sat Jun 5 13:05:53 2021" "
+ "Sync Center Shell Service Object (Internal)" "Microsoft Sync Centre" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\SyncCenter.dll" "Sat Jun 5 13:06:24 2021" "
+ "Security and Maintenance Shell Service Object" "Security and Maintenance" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\Actioncenter.dll" "Sat Jun 5 13:05:55 2021" "
+ "ShellFolder for CD Burning" "Windows Shell Common Dll" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\shell32.dll" "Thu Dec 16 07:56:19 2021" "
+ "HomeGroup SSO" "HomeGroup Control Panel" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\hgcpl.dll" "Sat Jun 5 13:05:55 2021" "
[HKLM\Software\Wow6432Node\Classes\*\ShellEx\ContextMenuHandlers]
[HKLM\Software\Wow6432Node\Classes\Drive\ShellEx\ContextMenuHandlers]
[HKLM\Software\Wow6432Node\Classes\*\ShellEx\PropertySheetHandlers]
[HKLM\Software\Wow6432Node\Classes\AllFileSystemObjects\ShellEx\ContextMenuHandlers]
[HKLM\Software\Wow6432Node\Classes\AllFileSystemObjects\ShellEx\DragDropHandlers]
[HKLM\Software\Wow6432Node\Classes\AllFileSystemObjects\ShellEx\PropertySheetHandlers]
[HKLM\Software\Wow6432Node\Classes\Directory\ShellEx\ContextMenuHandlers]
[HKLM\Software\Wow6432Node\Classes\Directory\ShellEx\DragDropHandlers]
[HKLM\Software\Wow6432Node\Classes\Directory\ShellEx\PropertySheetHandlers]
[HKLM\Software\Wow6432Node\Classes\Directory\ShellEx\CopyHookHandlers]
[HKLM\Software\Wow6432Node\Classes\Directory\Background\ShellEx\ContextMenuHandlers]
[HKLM\Software\Wow6432Node\Classes\Folder\ShellEx\ContextMenuHandlers]
[HKLM\Software\Wow6432Node\Classes\Folder\ShellEx\DragDropHandlers]
[HKLM\Software\Wow6432Node\Classes\Folder\ShellEx\PropertySheetHandlers]
[HKLM\Software\Wow6432Node\Classes\Folder\ShellEx\ColumnHandlers]
[HKLM\Software\Wow6432Node\Classes\Folder\ShellEx\ExtShellFolderViews]
[HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers]
+ " OneDrive1" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ " OneDrive2" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ " OneDrive3" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ " OneDrive4" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ " OneDrive5" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ " OneDrive6" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ " OneDrive7" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ " OneDrive1" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ " OneDrive2" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ " OneDrive3" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ " OneDrive4" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ " OneDrive5" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ " OneDrive6" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ " OneDrive7" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
[HKLM\Software\Wow6432Node\Microsoft\Ctf\LangBarAddin]
[Internet Explorer]
[HKCU\Software\Microsoft\Internet Explorer\UrlSearchHooks]
+ "Microsoft Url Search Hook" "Internet Browser" "(Verified) Microsoft Windows" "C:\Windows\System32\ieframe.dll" "Thu Dec 16 07:56:37 2021" "
[HKCU\Software\Microsoft\Internet Explorer\Explorer Bars]
[HKCU\Software\Microsoft\Internet Explorer\Extensions]
[HKCU\Software\Wow6432Node\Microsoft\Internet Explorer\Explorer Bars]
[HKCU\Software\Wow6432Node\Microsoft\Internet Explorer\Extensions]
[HKLM\Software\Microsoft\Internet Explorer\Toolbar]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
+ "IEToEdge BHO" "IEToEdge BHO" "(Verified) Microsoft Corporation" "C:\Program Files (x86)\Microsoft\Edge\Application\96.0.1054.62\BHO\ie_to_edge_bho_64.dll" "Thu Dec 16 22:46:17 2021" "
[HKLM\Software\Microsoft\Internet Explorer\Explorer Bars]
[HKLM\Software\Microsoft\Internet Explorer\Extensions]
+ "OneNote Lin&ked Notes" "Microsoft OneNote Internet Explorer Add-in" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft Office\root\Office16\ONBttnIELinkedNotes.dll" "Sat Dec 18 15:21:43 2021" "
+ "Se&nd to OneNote" "Microsoft OneNote Internet Explorer Add-in" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft Office\root\Office16\ONBttnIE.dll" "Fri Dec 10 12:41:14 2021" "
[HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
[HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
+ "IEToEdge BHO" "IEToEdge BHO" "(Verified) Microsoft Corporation" "C:\Program Files (x86)\Microsoft\Edge\Application\96.0.1054.62\BHO\ie_to_edge_bho.dll" "Thu Dec 16 22:46:17 2021" "
+ "Skype for Business Browser Helper" "Skype for Business" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll" "Mon Nov 1 13:01:20 2021" "
[HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Explorer Bars]
[HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Extensions]
+ "Lync Click to Call" "Skype for Business" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll" "Mon Nov 1 13:01:20 2021" "
+ "OneNote Lin&ked Notes" "Microsoft OneNote Internet Explorer Add-in" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\ONBttnIELinkedNotes.dll" "Sat Dec 18 15:22:07 2021" "
+ "Se&nd to OneNote" "Microsoft OneNote Internet Explorer Add-in" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\ONBttnIE.dll" "Fri Dec 10 12:43:31 2021" "
[Scheduled Tasks]
[Task Scheduler]
+ "\ACC" "This task is for Care Center" "(Verified) Acer Incorporated" "C:\Program Files (x86)\Acer\Care Center\LiveUpdateChecker.exe" "Wed Nov 17 15:08:26 2021" "
+ "\ACCAgent" "This task is for Care Center agent" "(Verified) Acer Incorporated" "C:\Program Files (x86)\Acer\Care Center\LiveUpdateAgent.exe" "Wed Nov 17 15:08:26 2021" "
+ "\ACCBackgroundApplication" "Acer Care Center background application" "(Verified) Acer Incorporated" "C:\Program Files (x86)\Acer\Care Center\ACCStd.exe" "Wed Nov 17 15:08:30 2021" "
+ "\AcerCMUpdateTask2.1.20250" "Start Acer Configuration Manager and keep manufacturer software up to date." "(Verified) Acer Incorporated" "C:\Program Files (x86)\Acer\Amundsen\2.1.20250\AWC.exe" "Wed Sep 2 14:59:00 2020" "
+ "\App Explorer" "Host App Service Updater" "(Verified) SweetLabs Inc." "C:\Users\chris\AppData\Local\Host App Service\Engine\HostAppServiceUpdater.exe" "Mon Nov 15 21:29:44 2021" "
+ "\CCleaner Update" "Piriform CCleaner emergency updater" "(Verified) Piriform Software Ltd" "C:\Program Files\CCleaner\CCUpdate.exe" "Tue Dec 7 19:06:56 2021" "
+ "\GoogleUpdateTaskMachineCore" "Keeps your Google software up to date. If this task is disabled or stopped, your Google software will not be kept up to date, meaning security vulnerabilities that may arise cannot be fixed and features may not work. This task uninstalls itself when there is no Google software using it." "(Verified) Google LLC" "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" "Tue Oct 12 17:43:19 2021" "
+ "\GoogleUpdateTaskMachineUA" "Keeps your Google software up to date. If this task is disabled or stopped, your Google software will not be kept up to date, meaning security vulnerabilities that may arise cannot be fixed and features may not work. This task uninstalls itself when there is no Google software using it." "(Verified) Google LLC" "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" "Tue Oct 12 17:43:19 2021" "
+ "\GoTrust ID Driver" "GoTrust ID Driver" "(Verified) GoTrustID Inc" "C:\Program Files\GoTrust ID Plugin\Resource\GO-Trust_ID_Driver.exe" "Tue Sep 8 09:48:02 2020" "
+ "\MicrosoftEdgeUpdateTaskMachineCore" "Keeps your Microsoft software up to date. If this task is disabled or stopped, your Microsoft software will not be kept up to date, meaning security vulnerabilities that may arise cannot be fixed and features may not work. This task uninstalls itself when there is no Microsoft software using it." "(Verified) Microsoft Corporation" "C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" "Thu Apr 1 20:17:37 2021" "
+ "\MicrosoftEdgeUpdateTaskMachineUA" "Keeps your Microsoft software up to date. If this task is disabled or stopped, your Microsoft software will not be kept up to date, meaning security vulnerabilities that may arise cannot be fixed and features may not work. This task uninstalls itself when there is no Microsoft software using it." "(Verified) Microsoft Corporation" "C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" "Thu Apr 1 20:17:37 2021" "
+ X "\Agent Activation Runtime\S-1-5-21-118655992-338211945-2329846050-1001" "" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\AgentActivationRuntimeStarter.exe" "Sat Jun 5 13:04:52 2021" "
+ "\Microsoft\Office\Office Automatic Updates 2.0" "This task ensures that your Microsoft Office installation can check for updates." "(Verified) Microsoft Corporation" "C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe" "Fri Dec 10 00:10:56 2021" "
+ "\Microsoft\Office\Office ClickToRun Service Monitor" "This task monitors the state of your Microsoft Office ClickToRunSvc and sends crash and error logs to Microsoft." "(Verified) Microsoft Corporation" "C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe" "Fri Dec 10 00:10:56 2021" "
+ "\Microsoft\Office\Office Feature Updates" "This task ensures that your Microsoft Office installation can check for feature updates." "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe" "Sat Dec 18 15:21:51 2021" "
+ "\Microsoft\Office\Office Feature Updates Logon" "This task ensures that your Microsoft Office installation can check for feature updates." "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe" "Sat Dec 18 15:21:51 2021" "
+ "\Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319" "Microsoft .NET Runtime Execution Engine" "(Verified) Microsoft Windows" "C:\Windows\System32\mscoree.dll" "Sat Jun 5 13:06:26 2021" "
+ "\Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 64" "Microsoft .NET Runtime Execution Engine" "(Verified) Microsoft Windows" "C:\Windows\System32\mscoree.dll" "Sat Jun 5 13:06:26 2021" "
+ X "\Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 64 Critical" "Microsoft .NET Runtime Execution Engine" "(Verified) Microsoft Windows" "C:\Windows\System32\mscoree.dll" "Sat Jun 5 13:06:26 2021" "
+ X "\Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 Critical" "Microsoft .NET Runtime Execution Engine" "(Verified) Microsoft Windows" "C:\Windows\System32\mscoree.dll" "Sat Jun 5 13:06:26 2021" "
+ X "\Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Automated)" "Windows Rights Management client" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\msdrm.dll" "Sat Jun 5 13:04:58 2021" "
+ "\Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Manual)" "Windows Rights Management client" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\msdrm.dll" "Sat Jun 5 13:04:58 2021" "
+ "\Microsoft\Windows\AppID\EDP Policy Manager" "AppLockerCSP" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\AppLockerCsp.dll" "Thu Dec 16 07:53:35 2021" "
+ X "\Microsoft\Windows\AppID\PolicyConverter" "Converts the software restriction policies policy from XML into binary format." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\appidpolicyconverter.exe" "Sat Jun 5 13:05:23 2021" "
+ X "\Microsoft\Windows\AppID\VerifiedPublisherCertStoreCheck" "Inspects the AppID certificate cache for invalid or revoked certificates." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\appidcertstorecheck.exe" "Sat Jun 5 13:05:23 2021" "
+ "\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser" "Collects program telemetry information if opted-in to the Microsoft Customer Experience Improvement Program." "(Verified) Microsoft Corporation" "C:\WINDOWS\system32\compattelrunner.exe" "Sat Jun 5 13:05:21 2021" "
+ "\Microsoft\Windows\Application Experience\PcaPatchDbTask" "Updates compatibility database" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\PcaSvc.dll" "Thu Dec 16 07:53:34 2021" "
+ "\Microsoft\Windows\Application Experience\ProgramDataUpdater" "Collects program telemetry information if opted-in to the Microsoft Customer Experience Improvement Program" "(Verified) Microsoft Corporation" "C:\WINDOWS\system32\compattelrunner.exe" "Sat Jun 5 13:05:21 2021" "
+ "\Microsoft\Windows\Application Experience\StartupAppTask" "Scans startup entries and raises notification to the user if there are too many startup entries." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\Startupscan.dll" "Sat Jun 5 13:05:29 2021" "
+ "\Microsoft\Windows\ApplicationData\appuriverifierdaily" "Verifies AppUriHandler host registrations." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\AppHostRegistrationVerifier.exe" "Sat Jun 5 13:05:02 2021" "
+ "\Microsoft\Windows\ApplicationData\appuriverifierinstall" "Verifies AppUriHandler host registrations." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\AppHostRegistrationVerifier.exe" "Sat Jun 5 13:05:02 2021" "
+ "\Microsoft\Windows\ApplicationData\CleanupTemporaryState" "Cleans up each package's unused temporary files." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\Windows.Storage.ApplicationData.dll" "Sat Jun 5 13:05:12 2021" "
+ "\Microsoft\Windows\ApplicationData\DsSvcCleanup" "Performs maintenance for the Data Sharing Service." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\dstokenclean.exe" "Sat Jun 5 13:05:02 2021" "
+ "\Microsoft\Windows\AppListBackup\Backup" "AppListBackupLauncher" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\AppListBackupLauncher.dll" "Thu Dec 16 07:51:30 2021" "
+ X "\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup" "AppX Deployment Client DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\AppxDeploymentClient.dll" "Thu Dec 16 07:52:35 2021" "
+ "\Microsoft\Windows\Autochk\Proxy" "This task collects and uploads autochk SQM data if opted-in to the Microsoft Customer Experience Improvement Program." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\acproxy.dll" "Sat Jun 5 13:06:02 2021" "
+ "\Microsoft\Windows\BitLocker\BitLocker Encrypt All Drives" "EdpTask Task" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\edptask.dll" "Sat Jun 5 13:05:29 2021" "
+ "\Microsoft\Windows\BitLocker\BitLocker MDM policy Refresh" "EdpTask Task" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\edptask.dll" "Sat Jun 5 13:05:29 2021" "
+ "\Microsoft\Windows\Bluetooth\UninstallDeviceTask" "Uninstalls the PnP device associated with the specified Bluetooth service ID" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\BthUdTask.exe" "Sat Jun 5 13:05:23 2021" "
+ "\Microsoft\Windows\capabilityaccessmanager\maintenancetasks" "Capability Access Manager Maintenance Tasks" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\CapabilityAccessManager.dll" "Thu Dec 16 07:52:51 2021" "
+ "\Microsoft\Windows\CertificateServicesClient\AikCertEnrollTask" "Microsoft Passport Tasks" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\ngctasks.dll" "Thu Dec 16 07:54:57 2021" "
+ "\Microsoft\Windows\CertificateServicesClient\CryptoPolicyTask" "Microsoft Passport Tasks" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\ngctasks.dll" "Thu Dec 16 07:54:57 2021" "
+ "\Microsoft\Windows\CertificateServicesClient\KeyPreGenTask" "Microsoft Passport Tasks" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\ngctasks.dll" "Thu Dec 16 07:54:57 2021" "
+ "\Microsoft\Windows\CertificateServicesClient\SystemTask" "DIMS Job DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\dimsjob.dll" "Sat Jun 5 13:06:05 2021" "
+ "\Microsoft\Windows\CertificateServicesClient\UserTask" "DIMS Job DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\dimsjob.dll" "Sat Jun 5 13:06:05 2021" "
+ "\Microsoft\Windows\CertificateServicesClient\UserTask-Roam" "DIMS Job DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\dimsjob.dll" "Sat Jun 5 13:06:05 2021" "
+ "\Microsoft\Windows\Chkdsk\ProactiveScan" "pstask Task" "(Verified) Microsoft Windows" "C:\Windows\System32\pstask.dll" "Sat Jun 5 13:06:15 2021" "
+ "\Microsoft\Windows\Chkdsk\SyspartRepair" "Bcdboot utility" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\bcdboot.exe" "Thu Dec 16 07:51:37 2021" "
+ X "\Microsoft\Windows\Clip\License Validation" "Windows Store legacy license migration task" "(Verified) Microsoft Windows Publisher" "C:\WINDOWS\system32\ClipUp.exe" "Thu Dec 16 07:56:28 2021" "
+ "\Microsoft\Windows\CloudExperienceHost\CreateObjectTask" "CloudExperienceHost Broker" "(Verified) Microsoft Windows" "C:\Windows\System32\CloudExperienceHostBroker.exe" "Sat Jun 5 13:05:20 2021" "
+ "\Microsoft\Windows\Customer Experience Improvement Program\Consolidator" "If the user has consented to participate in the Windows Customer Experience Improvement Program, this job collects and sends usage data to Microsoft." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\wsqmcons.exe" "Sat Jun 5 13:05:23 2021" "
+ "\Microsoft\Windows\Customer Experience Improvement Program\UsbCeip" "USBCEIP Task" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\usbceip.dll" "Sat Jun 5 13:05:27 2021" "
+ "\Microsoft\Windows\Data Integrity Scan\Data Integrity Check And Scan" "Data Integrity Scan Task" "(Verified) Microsoft Windows" "C:\Windows\System32\discan.dll" "Sat Jun 5 13:06:00 2021" "
+ "\Microsoft\Windows\Data Integrity Scan\Data Integrity Scan" "Data Integrity Scan Task" "(Verified) Microsoft Windows" "C:\Windows\System32\discan.dll" "Sat Jun 5 13:06:00 2021" "
+ "\Microsoft\Windows\Data Integrity Scan\Data Integrity Scan for Crash Recovery" "Data Integrity Scan Task" "(Verified) Microsoft Windows" "C:\Windows\System32\discan.dll" "Sat Jun 5 13:06:00 2021" "
+ "\Microsoft\Windows\Defrag\ScheduledDefrag" "This task optimises local storage drives." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\defrag.exe" "Sat Jun 5 13:06:05 2021" "
+ "\Microsoft\Windows\Device Information\Device" "Device Census" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\devicecensus.exe" "Sat Jun 5 13:05:23 2021" "
+ "\Microsoft\Windows\Device Information\Device User" "Device Census" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\devicecensus.exe" "Sat Jun 5 13:05:23 2021" "
+ "\Microsoft\Windows\Device Setup\Metadata Refresh" "Device Setup Manager Client API" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DeviceSetupManagerAPI.dll" "Sat Jun 5 13:05:29 2021" "
+ "\Microsoft\Windows\DeviceDirectoryClient\HandleCommand" "DeviceDirectoryClient Task" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\DeviceDirectoryClient.dll" "Sat Jun 5 13:04:57 2021" "
+ "\Microsoft\Windows\DeviceDirectoryClient\HandleWnsCommand" "DeviceDirectoryClient Task" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\DeviceDirectoryClient.dll" "Sat Jun 5 13:04:57 2021" "
+ X "\Microsoft\Windows\DeviceDirectoryClient\IntegrityCheck" "DeviceDirectoryClient Task" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\DeviceDirectoryClient.dll" "Sat Jun 5 13:04:57 2021" "
+ "\Microsoft\Windows\DeviceDirectoryClient\LocateCommandUserSession" "DeviceDirectoryClient Task" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\DeviceDirectoryClient.dll" "Sat Jun 5 13:04:57 2021" "
+ "\Microsoft\Windows\DeviceDirectoryClient\RegisterDeviceAccountChange" "DeviceDirectoryClient Task" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\DeviceDirectoryClient.dll" "Sat Jun 5 13:04:57 2021" "
+ "\Microsoft\Windows\DeviceDirectoryClient\RegisterDeviceLocationRightsChange" "DeviceDirectoryClient Task" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\DeviceDirectoryClient.dll" "Sat Jun 5 13:04:57 2021" "
+ "\Microsoft\Windows\DeviceDirectoryClient\RegisterDevicePeriodic24" "DeviceDirectoryClient Task" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\DeviceDirectoryClient.dll" "Sat Jun 5 13:04:57 2021" "
+ "\Microsoft\Windows\DeviceDirectoryClient\RegisterDevicePolicyChange" "DeviceDirectoryClient Task" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\DeviceDirectoryClient.dll" "Sat Jun 5 13:04:57 2021" "
+ "\Microsoft\Windows\DeviceDirectoryClient\RegisterDeviceProtectionStateChanged" "DeviceDirectoryClient Task" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\DeviceDirectoryClient.dll" "Sat Jun 5 13:04:57 2021" "
+ "\Microsoft\Windows\DeviceDirectoryClient\RegisterDeviceSettingChange" "DeviceDirectoryClient Task" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\DeviceDirectoryClient.dll" "Sat Jun 5 13:04:57 2021" "
+ "\Microsoft\Windows\DeviceDirectoryClient\RegisterDeviceWnsFallback" "DeviceDirectoryClient Task" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\DeviceDirectoryClient.dll" "Sat Jun 5 13:04:57 2021" "
+ "\Microsoft\Windows\DeviceDirectoryClient\RegisterUserDevice" "DeviceDirectoryClient Task" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\DeviceDirectoryClient.dll" "Sat Jun 5 13:04:57 2021" "
+ "\Microsoft\Windows\Diagnosis\RecommendedTroubleshootingScanner" "MitigationClient" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\MitigationClient.dll" "Sat Jun 5 13:04:52 2021" "
+ "\Microsoft\Windows\Diagnosis\Scheduled" "Scripted Diagnostics Scheduled Task" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\sdiagschd.dll" "Sat Jun 5 13:06:14 2021" "
+ "\Microsoft\Windows\DirectX\DirectXDatabaseUpdater" "DirectX Database Updater" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\directxdatabaseupdater.exe" "Thu Dec 16 07:52:23 2021" "
+ "\Microsoft\Windows\DirectX\DXGIAdapterCache" "DXGI Adapter Cache" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\dxgiadaptercache.exe" "Sat Jun 5 13:05:06 2021" "
+ "\Microsoft\Windows\DiskCleanup\SilentCleanup" "Maintenance task used by the system to launch a silent automatic disk clean-up when free disk space is running low." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\cleanmgr.exe" "Sat Jun 5 13:06:02 2021" "
+ "\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector" "The Windows Disk Diagnostic reports general disk and system information to Microsoft for users participating in the Customer Experience Program." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\dfdts.dll" "Sat Jun 5 13:06:05 2021" "
+ X "\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticResolver" "The Microsoft-Windows-DiskDiagnosticResolver warns users about faults reported by hard disks that support the Self Monitoring and Reporting Technology (S.M.A.R.T.) standard. This task is triggered automatically by the Diagnostic Policy Service when a S.M.A.R.T. fault is detected." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\DFDWiz.exe" "Sat Jun 5 13:06:05 2021" "
+ "\Microsoft\Windows\DiskFootprint\Diagnostics" "DiskSnapshot.exe" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\disksnapshot.exe" "Sat Jun 5 13:05:16 2021" "
+ "\Microsoft\Windows\DiskFootprint\StorageSense" "Storage Usage" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\StorageUsage.dll" "Thu Dec 16 07:56:31 2021" "
+ "\Microsoft\Windows\DUSM\dusmtask" "DUSM Task" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\dusmtask.exe" "Thu Dec 16 07:56:20 2021" "
+ "\Microsoft\Windows\EDP\EDP App Launch Task" "EdpTask Task" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\edptask.dll" "Sat Jun 5 13:05:29 2021" "
+ "\Microsoft\Windows\EDP\EDP Auth Task" "EdpTask Task" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\edptask.dll" "Sat Jun 5 13:05:29 2021" "
+ "\Microsoft\Windows\EDP\EDP Inaccessible Credentials Task" "EdpTask Task" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\edptask.dll" "Sat Jun 5 13:05:29 2021" "
+ "\Microsoft\Windows\EDP\StorageCardEncryption Task" "EdpTask Task" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\edptask.dll" "Sat Jun 5 13:05:29 2021" "
+ "\Microsoft\Windows\EnterpriseMgmt\MDMMaintenenceTask" "MDMAgent" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\MDMAgent.exe" "Sat Jun 5 13:04:57 2021" "
+ "\Microsoft\Windows\ExploitGuard\ExploitGuard MDM policy Refresh" "Exploit Guard Configuration Helper" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\MitigationConfiguration.dll" "Sat Jun 5 13:05:40 2021" "
+ "\Microsoft\Windows\Feedback\Siuf\DmClient" "Update SIUF strings" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\dmclient.exe" "Sat Jun 5 13:04:59 2021" "
+ "\Microsoft\Windows\Feedback\Siuf\DmClientOnScenarioDownload" "Update SIUF strings" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\dmclient.exe" "Sat Jun 5 13:04:59 2021" "
+ "\Microsoft\Windows\FileHistory\File History (maintenance mode)" "File History Task Handler" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\fhtask.dll" "Thu Dec 16 07:56:54 2021" "
+ "\Microsoft\Windows\Flighting\FeatureConfig\ReconcileFeatures" "Feature Configuration" "(Verified) Microsoft Windows" "C:\Windows\System32\fcon.dll" "Sat Jun 5 13:04:52 2021" "
+ "\Microsoft\Windows\Flighting\FeatureConfig\UsageDataFlushing" "Feature Configuration" "(Verified) Microsoft Windows" "C:\Windows\System32\fcon.dll" "Sat Jun 5 13:04:52 2021" "
+ "\Microsoft\Windows\Flighting\FeatureConfig\UsageDataReporting" "Feature Configuration" "(Verified) Microsoft Windows" "C:\Windows\System32\fcon.dll" "Sat Jun 5 13:04:52 2021" "
+ "\Microsoft\Windows\Flighting\OneSettings\RefreshCache" "Windows OneSettings Client" "(Verified) Microsoft Windows" "C:\Windows\System32\wosc.dll" "Thu Dec 16 07:51:24 2021" "
+ "\Microsoft\Windows\HelloFace\FODCleanupTask" "" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\WinBioPlugIns\FaceFodUninstaller.exe" "Thu Dec 16 07:56:20 2021" "
+ "\Microsoft\Windows\Input\LocalUserSyncDataAvailable" "Windows Input Cloud Store Task Handlers" "(Verified) Microsoft Windows" "C:\Windows\System32\InputCloudStore.dll" "Sat Jun 5 13:05:20 2021" "
+ "\Microsoft\Windows\Input\MouseSyncDataAvailable" "Windows Input Cloud Store Task Handlers" "(Verified) Microsoft Windows" "C:\Windows\System32\InputCloudStore.dll" "Sat Jun 5 13:05:20 2021" "
+ "\Microsoft\Windows\Input\PenSyncDataAvailable" "Windows Input Cloud Store Task Handlers" "(Verified) Microsoft Windows" "C:\Windows\System32\InputCloudStore.dll" "Sat Jun 5 13:05:20 2021" "
+ "\Microsoft\Windows\Input\TouchpadSyncDataAvailable" "Windows Input Cloud Store Task Handlers" "(Verified) Microsoft Windows" "C:\Windows\System32\InputCloudStore.dll" "Sat Jun 5 13:05:20 2021" "
+ "\Microsoft\Windows\InstallService\ScanForUpdates" "InstallService Tasks" "(Verified) Microsoft Windows" "C:\Windows\System32\InstallServiceTasks.dll" "Thu Dec 16 07:52:32 2021" "
+ "\Microsoft\Windows\InstallService\ScanForUpdatesAsUser" "InstallService Tasks" "(Verified) Microsoft Windows" "C:\Windows\System32\InstallServiceTasks.dll" "Thu Dec 16 07:52:32 2021" "
+ "\Microsoft\Windows\InstallService\SmartRetry" "InstallService Tasks" "(Verified) Microsoft Windows" "C:\Windows\System32\InstallServiceTasks.dll" "Thu Dec 16 07:52:32 2021" "
+ X "\Microsoft\Windows\InstallService\WakeUpAndContinueUpdates" "InstallService Tasks" "(Verified) Microsoft Windows" "C:\Windows\System32\InstallServiceTasks.dll" "Thu Dec 16 07:52:32 2021" "
+ X "\Microsoft\Windows\InstallService\WakeUpAndScanForUpdates" "InstallService Tasks" "(Verified) Microsoft Windows" "C:\Windows\System32\InstallServiceTasks.dll" "Thu Dec 16 07:52:32 2021" "
+ "\Microsoft\Windows\International\Synchronize Language Settings" "Core Globalization Configuration" "(Verified) Microsoft Windows" "C:\Windows\System32\CoreGlobConfig.dll" "Sat Jun 5 13:05:09 2021" "
+ "\Microsoft\Windows\Kernel\La57Cleanup" "This task cleans up 5-level paging binaries on systems that do not support 5-level paging." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\la57setup.exe" "Thu Dec 16 07:54:22 2021" "
+ "\Microsoft\Windows\LanguageComponentsInstaller\Installation" "LanguageComponentsInstaller Task" "(Verified) Microsoft Windows" "C:\Windows\System32\LanguageComponentsInstaller.dll" "Thu Dec 16 07:54:22 2021" "
+ "\Microsoft\Windows\LanguageComponentsInstaller\Uninstallation" "LanguageComponentsInstaller Task" "(Verified) Microsoft Windows" "C:\Windows\System32\LanguageComponentsInstaller.dll" "Thu Dec 16 07:54:22 2021" "
+ "\Microsoft\Windows\License Manager\TempSignedLicenseExchange" "TempSignedLicenseExchangeTask Task" "(Verified) Microsoft Windows" "C:\Windows\System32\TempSignedLicenseExchangeTask.dll" "Sat Jun 5 13:05:06 2021" "
+ "\Microsoft\Windows\Location\Notifications" "Location Notification" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\LocationNotificationWindows.exe" "Sat Jun 5 13:06:10 2021" "
+ "\Microsoft\Windows\Location\WindowsActionDialog" "Location Notification" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\WindowsActionDialog.exe" "Sat Jun 5 13:06:10 2021" "
+ "\Microsoft\Windows\Maintenance\WinSAT" "Windows System Assessment Tool API" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\WinSATAPI.dll" "Sat Jun 5 13:06:16 2021" "
+ "\Microsoft\Windows\Management\Provisioning\Cellular" "Provisioning package runtime processing tool" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\ProvTool.exe" "Thu Dec 16 07:51:45 2021" "
+ "\Microsoft\Windows\Management\Provisioning\Logon" "Provisioning package runtime processing tool" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\ProvTool.exe" "Thu Dec 16 07:51:45 2021" "
+ X "\Microsoft\Windows\Management\Provisioning\MdmDiagnosticsCleanup" "MdmDiagnosticsTool" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\MdmDiagnosticsTool.exe" "Sat Jun 5 13:05:12 2021" "
+ X "\Microsoft\Windows\Management\Provisioning\Retry" "Provisioning package runtime processing tool" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\ProvTool.exe" "Thu Dec 16 07:51:45 2021" "
+ X "\Microsoft\Windows\Management\Provisioning\RunOnReboot" "Provisioning package runtime processing tool" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\ProvTool.exe" "Thu Dec 16 07:51:45 2021" "
+ "\Microsoft\Windows\Maps\MapsToastTask" "MapsToastTask Task" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\mapstoasttask.dll" "Thu Dec 16 07:52:30 2021" "
+ X "\Microsoft\Windows\Maps\MapsUpdateTask" "MapsUpdateTask Task" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\mapsupdatetask.dll" "Thu Dec 16 07:52:29 2021" "
+ "\Microsoft\Windows\MemoryDiagnostic\ProcessMemoryDiagnosticEvents" "Microsoft Windows Memory Diagnostic Task Handler" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\MemoryDiagnostic.dll" "Sat Jun 5 13:06:16 2021" "
+ "\Microsoft\Windows\MemoryDiagnostic\RunFullMemoryDiagnostic" "Microsoft Windows Memory Diagnostic Task Handler" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\MemoryDiagnostic.dll" "Sat Jun 5 13:06:16 2021" "
+ "\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser" "$(@%SystemRoot%\system32\MbaeParserTask.exe,-1903)" "" "File not found: C:\WINDOWS\Syswow64\MbaeParserTask.exe" "" "
+ "\Microsoft\Windows\MUI\LPRemove" "Launch language clean-up tool" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\lpremove.exe" "Thu Dec 16 07:54:22 2021" "
+ "\Microsoft\Windows\Multimedia\SystemSoundsService" "PlaySound Service" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\PlaySndSrv.dll" "Thu Dec 16 07:51:30 2021" "
+ "\Microsoft\Windows\NetTrace\GatherNetworkInfo" "Network information collector" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\gatherNetworkInfo.vbs" "Sat Jun 5 13:06:02 2021" "
+ "\Microsoft\Windows\NlaSvc\WiFiTask" "Background task for performing per user and web interactions" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\WiFiTask.exe" "Thu Dec 16 07:51:50 2021" "
+ "\Microsoft\Windows\PI\Secure-Boot-Update" "TPM Maintenance Tasks" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\TpmTasks.dll" "Thu Dec 16 07:51:49 2021" "
+ "\Microsoft\Windows\PI\Sqm-Tasks" "TPM Maintenance Tasks" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\TpmTasks.dll" "Thu Dec 16 07:51:49 2021" "
+ "\Microsoft\Windows\Plug and Play\Device Install Group Policy" "pnppolicy Task" "(Verified) Microsoft Windows" "C:\Windows\System32\pnppolicy.dll" "Sat Jun 5 13:05:39 2021" "
+ "\Microsoft\Windows\Plug and Play\Device Install Reboot Required" "Plug and Play User Interface DLL" "(Verified) Microsoft Windows" "C:\Windows\System32\pnpui.dll" "Sat Jun 5 13:05:39 2021" "
+ "\Microsoft\Windows\Plug and Play\Sysprep Generalize Drivers" "Generalise driver state in order to prepare the system to be bootable on any hardware configuration." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drvinst.exe" "Sat Jun 5 13:05:39 2021" "
+ "\Microsoft\Windows\Power Efficiency Diagnostics\AnalyzeSystem" "Power Efficiency Diagnostics Task" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\energytask.dll" "Sat Jun 5 13:06:11 2021" "
+ "\Microsoft\Windows\Printing\EduPrintProv" "Printer Provision Utility for EDU" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\eduprintprov.exe" "Sat Jun 5 13:06:16 2021" "
+ "\Microsoft\Windows\Printing\PrinterCleanupTask" "Windows Printer Cleanup Task" "(Verified) Microsoft Windows" "C:\Windows\System32\PrinterCleanupTask.dll" "Thu Dec 16 07:51:44 2021" "
+ X "\Microsoft\Windows\PushToInstall\LoginCheck" "Service Control Manager Configuration Tool" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\sc.exe" "Sat Jun 5 13:06:02 2021" "
+ "\Microsoft\Windows\PushToInstall\Registration" "Service Control Manager Configuration Tool" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\sc.exe" "Sat Jun 5 13:06:02 2021" "
+ "\Microsoft\Windows\Ras\MobilityManager" "Provides support for the switching of mobility enabled VPN connections if their underlying interface goes down." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\rasmbmgr.dll" "Sat Jun 5 13:05:40 2021" "
+ "\Microsoft\Windows\RecoveryEnvironment\VerifyWinRE" "Microsoft Windows Recovery Agent Task Handler" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\ReAgentTask.dll" "Sat Jun 5 13:05:27 2021" "
+ "\Microsoft\Windows\Registry\RegIdleBackup" "RegIdle Backup Task" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\regidle.dll" "Sat Jun 5 13:06:11 2021" "
+ "\Microsoft\Windows\RemoteAssistance\RemoteAssistanceTask" "Checks group policy for changes relevant to Remote Assistance" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\RAServer.exe" "Thu Dec 16 08:01:14 2021" "
+ "\Microsoft\Windows\Setup\SetupCleanupTask" "SetupCleanupTask Task" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\oobe\SetupCleanupTask.dll" "Thu Dec 16 07:55:10 2021" "
+ X "\Microsoft\Windows\SharedPC\Account Cleanup" "SharedPC.AccountManager" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Windows.SharedPC.AccountManager.dll" "Sat Jun 5 13:05:19 2021" "
+ "\Microsoft\Windows\Shell\CreateObjectTask" "Windows Shell Common Dll" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\shell32.dll" "Thu Dec 16 07:54:27 2021" "
+ "\Microsoft\Windows\Shell\FamilySafetyMonitor" "Initialises Family Safety monitoring and enforcement." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\wpcmon.exe" "Thu Dec 16 07:51:41 2021" "
+ "\Microsoft\Windows\Shell\FamilySafetyRefreshTask" "Family Safety Refresh Task" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\WpcRefreshTask.dll" "Thu Dec 16 07:51:42 2021" "
+ "\Microsoft\Windows\Shell\IndexerAutomaticMaintenance" "Indexing Options" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\srchadmin.dll" "Sat Jun 5 13:05:40 2021" "
+ "\Microsoft\Windows\Shell\ThemesSyncedImageDownload" "ThemesSyncedImageDownload Task" "(Verified) Microsoft Windows" "C:\Windows\System32\Themes.SsfDownload.ScheduledTask.dll" "Sat Jun 5 13:04:58 2021" "
+ "\Microsoft\Windows\Shell\UpdateUserPictureTask" "WINDOWS.UI.IMMERSIVE" "(Verified) Microsoft Windows" "C:\Windows\System32\Windows.UI.Immersive.dll" "Thu Dec 16 07:54:21 2021" "
+ "\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask" "Software Protection Platform Client Extension Dll" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\sppcext.dll" "Thu Dec 16 07:54:29 2021" "
+ X "\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTaskLogon" "Software Protection Platform Client Extension Dll" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\sppcext.dll" "Thu Dec 16 07:54:29 2021" "
+ X "\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTaskNetwork" "Software Protection Platform Client Extension Dll" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\sppcext.dll" "Thu Dec 16 07:54:29 2021" "
+ "\Microsoft\Windows\SpacePort\SpaceAgentTask" "Storage Spaces Settings" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\SpaceAgent.exe" "Sat Jun 5 13:06:17 2021" "
+ "\Microsoft\Windows\SpacePort\SpaceManagerTask" "$(@%SystemRoot%\system32\spaceman.exe,-3)" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\spaceman.exe" "Sat Jun 5 13:06:02 2021" "
+ "\Microsoft\Windows\Speech\SpeechModelDownloadTask" "Speech Model Download Executable" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\speech_onecore\common\SpeechModelDownload.exe" "Sat Jun 5 13:05:17 2021" "
+ "\Microsoft\Windows\StateRepository\MaintenanceTasks" "$(@%SystemRoot%\system32\Windows.StateRepositoryClient.dll,-602)" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\Windows.StateRepositoryClient.dll" "Thu Dec 16 07:52:37 2021" "
+ "\Microsoft\Windows\Storage Tiers Management\Storage Tiers Management Initialization" "Storage Tiers Management" "(Verified) Microsoft Windows" "C:\Windows\System32\TieringEngineService.exe" "Sat Jun 5 13:06:13 2021" "
+ X "\Microsoft\Windows\Storage Tiers Management\Storage Tiers Optimization" "Optimizes the placement of data in storage tiers on all tiered storage spaces in the system." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\defrag.exe" "Sat Jun 5 13:06:05 2021" "
+ "\Microsoft\Windows\Subscription\EnableLicenseAcquisition" "Enable susbscription license acquisition" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\ClipRenew.exe" "Sat Jun 5 18:17:02 2021" "
+ X "\Microsoft\Windows\Subscription\LicenseAcquisition" "Susbscription license acquisition" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\ClipRenew.exe" "Sat Jun 5 18:17:02 2021" "
+ X "\Microsoft\Windows\Sysmain\HybridDriveCachePrepopulate" "SysMain Service Host" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\sysmain.dll" "Thu Dec 16 07:56:56 2021" "
+ X "\Microsoft\Windows\Sysmain\HybridDriveCacheRebalance" "SysMain Service Host" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\sysmain.dll" "Thu Dec 16 07:56:56 2021" "
+ "\Microsoft\Windows\Sysmain\ResPriStaticDbSync" "SysMain Service Host" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\sysmain.dll" "Thu Dec 16 07:56:56 2021" "
+ "\Microsoft\Windows\Sysmain\WsSwapAssessmentTask" "Working set swap assessment maintenance task" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\sysmain.dll" "Thu Dec 16 07:56:56 2021" "
+ "\Microsoft\Windows\SystemRestore\SR" "This task creates regular system protection points." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\srtasks.exe" "Sat Jun 5 13:06:17 2021" "
+ "\Microsoft\Windows\Task Manager\Interactive" "Performance Monitor" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wdc.dll" "Sat Jun 5 13:06:10 2021" "
+ "\Microsoft\Windows\TextServicesFramework\MsCtfMonitor" "MsCtfMonitor DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\MsCtfMonitor.dll" "Sat Jun 5 13:05:12 2021" "
+ "\Microsoft\Windows\Time Synchronization\ForceSynchronizeTime" "Time Synchronization Task" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\TimeSyncTask.dll" "Sat Jun 5 13:04:59 2021" "
+ "\Microsoft\Windows\Time Synchronization\SynchronizeTime" "Maintains date and time synchronization on all clients and servers in the network. If this service is stopped, date and time synchronization will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\sc.exe" "Sat Jun 5 13:06:02 2021" "
+ "\Microsoft\Windows\Time Zone\SynchronizeTimeZone" "Updates timezone information. If this task is stopped, local time may not be accurate for some time zones." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\tzsync.exe" "Sat Jun 5 13:05:14 2021" "
+ "\Microsoft\Windows\TPM\Tpm-HASCertRetr" "TPM Maintenance Tasks" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\TpmTasks.dll" "Thu Dec 16 07:51:49 2021" "
+ "\Microsoft\Windows\TPM\Tpm-Maintenance" "TPM Maintenance Tasks" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\TpmTasks.dll" "Thu Dec 16 07:51:49 2021" "
+ X "\Microsoft\Windows\UNP\RunUpdateNotificationMgr" "Update Notification Pipeline Manager" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\UNP\UpdateNotificationMgr.exe" "Sat Jun 5 13:06:16 2021" "
+ X "\Microsoft\Windows\UpdateOrchestrator\Reboot_AC" "MusNotificationBroker" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\MusNotification.exe" "Thu Dec 16 07:53:09 2021" "
+ X "\Microsoft\Windows\UpdateOrchestrator\Reboot_Battery" "MusNotificationBroker" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\MusNotification.exe" "Thu Dec 16 07:53:09 2021" "
+ "\Microsoft\Windows\UpdateOrchestrator\Report policies" "UsoClient" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\usoclient.exe" "Thu Dec 16 07:53:09 2021" "
+ X "\Microsoft\Windows\UpdateOrchestrator\Schedule Maintenance Work" "UsoClient" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\usoclient.exe" "Thu Dec 16 07:53:09 2021" "
+ "\Microsoft\Windows\UpdateOrchestrator\Schedule Scan" "UsoClient" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\usoclient.exe" "Thu Dec 16 07:53:09 2021" "
+ "\Microsoft\Windows\UpdateOrchestrator\Schedule Scan Static Task" "This task performs a scheduled Windows Update scan." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\usoclient.exe" "Thu Dec 16 07:53:09 2021" "
+ X "\Microsoft\Windows\UpdateOrchestrator\Schedule Wake To Work" "UsoClient" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\usoclient.exe" "Thu Dec 16 07:53:09 2021" "
+ "\Microsoft\Windows\UpdateOrchestrator\Schedule Work" "UsoClient" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\usoclient.exe" "Thu Dec 16 07:53:09 2021" "
+ X "\Microsoft\Windows\UpdateOrchestrator\Start Oobe Expedite Work" "This task performs a scheduled Windows Update scan." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\usoclient.exe" "Thu Dec 16 07:53:09 2021" "
+ "\Microsoft\Windows\UpdateOrchestrator\StartOobeAppsScan" "This task performs a scheduled Windows Update scan." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\usoclient.exe" "Thu Dec 16 07:53:09 2021" "
+ "\Microsoft\Windows\UpdateOrchestrator\UpdateModelTask" "This task updates ML Models." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\usoclient.exe" "Thu Dec 16 07:53:09 2021" "
+ "\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker" "This task triggers a system reboot following update installation." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\MusNotification.exe" "Thu Dec 16 07:53:09 2021" "
+ "\Microsoft\Windows\UpdateOrchestrator\UUS Failover Task" "$(@%systemRoot%\system32\update\uusbrain.dll,-103)" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\usoclient.exe" "Thu Dec 16 07:53:09 2021" "
+ "\Microsoft\Windows\UPnP\UPnPHostConfig" "Set UPnPHost service to Auto-Start" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\sc.exe" "Sat Jun 5 13:06:02 2021" "
+ "\Microsoft\Windows\USB\Usb-Notifications" "UsbTask" "(Verified) Microsoft Windows" "C:\Windows\System32\UsbTask.dll" "Sat Jun 5 13:04:52 2021" "
+ "\Microsoft\Windows\WCM\WiFiTask" "Background task for performing per user and web interactions" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\WiFiTask.exe" "Thu Dec 16 07:51:50 2021" "
+ "\Microsoft\Windows\WDI\ResolutionHost" "Windows Diagnostic Infrastructure" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\wdi.dll" "Sat Jun 5 13:05:29 2021" "
+ "\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance" "Periodic maintenance task." "(Verified) Microsoft Windows Publisher" "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2111.5-0\MpCmdRun.exe" "Thu Dec 16 00:20:53 2021" "
+ "\Microsoft\Windows\Windows Defender\Windows Defender Cleanup" "Periodic clean-up task." "(Verified) Microsoft Windows Publisher" "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2111.5-0\MpCmdRun.exe" "Thu Dec 16 00:20:53 2021" "
+ "\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan" "Periodic scan task." "(Verified) Microsoft Windows Publisher" "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2111.5-0\MpCmdRun.exe" "Thu Dec 16 00:20:53 2021" "
+ "\Microsoft\Windows\Windows Defender\Windows Defender Verification" "Periodic verification task." "(Verified) Microsoft Windows Publisher" "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2111.5-0\MpCmdRun.exe" "Thu Dec 16 00:20:53 2021" "
+ "\Microsoft\Windows\Windows Error Reporting\QueueReporting" "Windows Error Reporting task to process queued reports." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wermgr.exe" "Sat Jun 5 13:05:25 2021" "
+ "\Microsoft\Windows\Windows Filtering Platform\BfeOnServiceStartTypeChange" "This task adjusts the start type for firewall-triggered services when the start type of the Base Filtering Engine (BFE) is disabled." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\bfe.dll" "Thu Dec 16 07:52:47 2021" "
+ "\Microsoft\Windows\Windows Media Sharing\UpdateLibrary" "This task updates the cached list of folders and the security permissions on any new files in a user’s shared media library." "(Not Verified) Microsoft Corporation" "C:\Program Files\Windows Media Player\wmpnscfg.exe" "Sat Jun 5 02:36:00 2021" "
+ "\Microsoft\Windows\WindowsColorSystem\Calibration Loader" "Microsoft Colour Matching System DLL" "(Verified) Microsoft Windows" "C:\Windows\System32\mscms.dll" "Thu Dec 16 07:52:23 2021" "
+ "\Microsoft\Windows\WindowsUpdate\Scheduled Start" "This task is used to start the Windows Update service when needed to perform scheduled operations such as scans." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\sc.exe" "Sat Jun 5 13:06:02 2021" "
+ "\Microsoft\Windows\Wininet\CacheTask" "Internet Extensions for Win32" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wininet.dll" "Thu Dec 16 07:54:21 2021" "
+ "\Microsoft\Windows\WlanSvc\CDSSync" "Windows WiFi Sync Provider DLL" "(Verified) Microsoft Windows" "C:\Windows\System32\WiFiCloudStore.dll" "Sat Jun 5 13:05:00 2021" "
+ "\Microsoft\Windows\WOF\WIM-Hash-Management" "WIM Boot Tasks" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\WofTasks.dll" "Sat Jun 5 18:17:03 2021" "
+ "\Microsoft\Windows\WOF\WIM-Hash-Validation" "WIM Boot Tasks" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\WofTasks.dll" "Sat Jun 5 18:17:03 2021" "
+ "\Microsoft\Windows\Work Folders\Work Folders Logon Synchronization" "Microsoft (C) Work Folders Shell Extension" "(Verified) Microsoft Windows" "C:\Windows\System32\WorkFoldersShell.dll" "Sat Jun 5 13:06:16 2021" "
+ "\Microsoft\Windows\Work Folders\Work Folders Maintenance Work" "Microsoft (C) Work Folders Shell Extension" "(Verified) Microsoft Windows" "C:\Windows\System32\WorkFoldersShell.dll" "Sat Jun 5 13:06:16 2021" "
+ X "\Microsoft\Windows\Workplace Join\Automatic-Device-Join" "Register this computer if the computer is already joined to an Active Directory domain." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\dsregcmd.exe" "Sat Jun 5 13:04:59 2021" "
+ X "\Microsoft\Windows\Workplace Join\Device-Sync" "DSREG task handler" "(Verified) Microsoft Windows" "C:\Windows\System32\dsregtask.dll" "Sat Jun 5 13:04:59 2021" "
+ X "\Microsoft\Windows\Workplace Join\Recovery-Check" "Performs recovery check." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\dsregcmd.exe" "Sat Jun 5 13:04:59 2021" "
+ "\Microsoft\Windows\WwanSvc\NotificationTask" "Background task for performing per user and web interactions" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\WiFiTask.exe" "Thu Dec 16 07:51:50 2021" "
+ "\Microsoft\Windows\WwanSvc\OobeDiscovery" "Windows MB Media Manager DLL" "(Verified) Microsoft Windows" "C:\Windows\System32\MBMediaManager.dll" "Thu Dec 16 07:53:07 2021" "
+ "\Microsoft\XblGameSave\XblGameSaveTask" "XblGameSave Standby Task" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\XblGameSaveTask.exe" "Sat Jun 5 13:04:52 2021" "
+ "\OneDrive Per-Machine Standalone Update Task" "Standalone Updater" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe" "Tue Dec 7 07:14:41 2021" "
+ "\OneDrive Reporting Task-S-1-5-21-118655992-338211945-2329846050-1001" "Standalone Updater" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe" "Tue Dec 7 07:14:41 2021" "
+ "\Quick Access" "This task is for Quick Access" "(Verified) Acer Incorporated" "C:\Program Files\Acer\Quick Access Service\QALauncher.exe" "Thu Sep 10 13:58:18 2020" "
+ "\Software Update Application" "Software Updater Scheduler" "(Verified) Acer Incorporated" "C:\ProgramData\OEM\UpgradeTool\ListCheck.exe" "Wed Nov 17 15:08:26 2021" "
+ "\UbtFrameworkService" "User Experience Improvement Program Framework Service" "(Verified) Acer Incorporated" "C:\Program Files\Acer\User Experience Improvement Program Service\Framework\TriggerFramework.exe" "Fri Aug 7 12:56:32 2020" "
+ "\UEIPInvitation" "User Experience Improvement Program Framework Invitation" "(Verified) Acer Incorporated" "C:\Program Files\Acer\User Experience Improvement Program Service\Framework\UEIPOOBECheck.exe" "Fri Aug 7 12:56:32 2020" "
[Services]
[HKLM\System\CurrentControlSet\Services]
+ "AarSvc" "Agent Activation Runtime: Runtime for activating conversational agent applications" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\AarSvc.dll" "Sat Jun 5 13:04:52 2021" "
+ "AarSvc_6a9e6" "Agent Activation Runtime_6a9e6: Runtime for activating conversational agent applications" "(Verified) Microsoft Windows Publisher" "C:\WINDOWS\system32\svchost.exe" "Sat Jun 5 13:05:23 2021" "
+ "ACCSvc" "ACC Service: ACC Service" "(Verified) Acer Incorporated" "C:\Program Files (x86)\Acer\Care Center\ACCSvc.exe" "Wed Nov 17 15:08:30 2021" "
+ "AJRouter" "AllJoyn Router Service: Routes AllJoyn messages for the local AllJoyn clients. If this service is stopped the AllJoyn clients that do not have their own bundled routers will be unable to run." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\AJRouter.dll" "Sat Jun 5 13:05:03 2021" "
+ "ALG" "Application Layer Gateway Service: Provides support for 3rd party protocol plug-ins for Internet Connection Sharing" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\alg.exe" "Sat Jun 5 13:05:12 2021" "
+ "AppIDSvc" "Application Identity: Determines and verifies the identity of an application. Disabling this service will prevent AppLocker from being enforced." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\appidsvc.dll" "Sat Jun 5 13:05:23 2021" "
+ "Appinfo" "Application Information: Facilitates the running of interactive applications with additional administrative privileges. If this service is stopped, users will be unable to launch applications with the additional administrative privileges they may require to perform desired user tasks." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\appinfo.dll" "Thu Dec 16 07:52:14 2021" "
+ "AppReadiness" "App Readiness: Gets apps ready for use the first time a user signs in to this PC and when adding new apps." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\AppReadiness.dll" "Thu Dec 16 08:01:09 2021" "
+ "AppXSvc" "AppX Deployment Service (AppXSVC): Provides infrastructure support for deploying Store applications. This service is started on demand and if disabled Store applications will not be deployed to the system, and may not function properly." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\appxdeploymentserver.dll" "Thu Dec 16 07:54:08 2021" "
+ "AtherosSvc" "AtherosSvc: Windows Setup API" "(Verified) Microsoft Windows Hardware Compatibility Publisher" "C:\WINDOWS\System32\drivers\AdminService.exe" "Mon Jul 19 21:46:00 2021" "
+ "AudioEndpointBuilder" "Windows Audio Endpoint Builder: Manages audio devices for the Windows Audio service. If this service is stopped, audio devices and effects will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\AudioEndpointBuilder.dll" "Thu Dec 16 07:51:31 2021" "
+ "Audiosrv" "Windows Audio: Manages audio for Windows-based programs. If this service is stopped, audio devices and effects will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Audiosrv.dll" "Thu Dec 16 07:51:31 2021" "
+ "autotimesvc" "Cellular Time: This service sets time based on NITZ messages from a Mobile Network" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\autotimesvc.dll" "Sat Jun 5 13:06:00 2021" "
+ "AxInstSV" "ActiveX Installer (AxInstSV): Provides User Account Control validation for the installation of ActiveX controls from the Internet and enables management of ActiveX control installation based on Group Policy settings. This service is started on demand and if disabled the installation of ActiveX controls will behave according to default browser settings." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\AxInstSV.dll" "Thu Dec 16 07:54:24 2021" "
+ "BcastDVRUserService" "GameDVR and Broadcast User Service: This user service is used for Game Recordings and Live Broadcasts" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\BcastDVRUserService.dll" "Thu Dec 16 07:56:19 2021" "
+ "BcastDVRUserService_6a9e6" "GameDVR and Broadcast User Service_6a9e6: This user service is used for Game Recordings and Live Broadcasts" "(Verified) Microsoft Windows Publisher" "C:\WINDOWS\system32\svchost.exe" "Sat Jun 5 13:05:23 2021" "
+ "BDESVC" "BitLocker Drive Encryption Service: BDESVC hosts the BitLocker Drive Encryption service. BitLocker Drive Encryption provides secure startup for the operating system, as well as full volume encryption for OS, fixed or removable volumes. This service allows BitLocker to prompt users for various actions related to their volumes when mounted, and unlocks volumes automatically without user interaction. Additionally, it stores recovery information to Active Directory, if available, and, if necessary, ensures the most recent recovery certificates are used. Stopping or disabling the service would prevent users from leveraging this functionality." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\bdesvc.dll" "Thu Dec 16 08:01:15 2021" "
+ "BFE" "Base Filtering Engine: The Base Filtering Engine (BFE) is a service that manages firewall and Internet Protocol security (IPsec) policies and implements user mode filtering. Stopping or disabling the BFE service will significantly reduce the security of the system. It will also result in unpredictable behavior in IPsec management and firewall applications." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\bfe.dll" "Thu Dec 16 07:52:47 2021" "
+ "BITS" "Background Intelligent Transfer Service: Transfers files in the background using idle network bandwidth. If the service is disabled, then any applications that depend on BITS, such as Windows Update or MSN Explorer, will be unable to automatically download programs and other information." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\qmgr.dll" "Sat Jun 5 13:05:03 2021" "
+ "BluetoothUserService" "Bluetooth User Support Service: The Bluetooth user service supports proper functionality of Bluetooth features relevant to each user session." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Microsoft.Bluetooth.UserService.dll" "Sat Jun 5 13:04:50 2021" "
+ "BluetoothUserService_6a9e6" "Bluetooth User Support Service_6a9e6: The Bluetooth user service supports proper functionality of Bluetooth features relevant to each user session." "(Verified) Microsoft Windows Publisher" "C:\WINDOWS\system32\svchost.exe" "Sat Jun 5 13:05:23 2021" "
+ "BrokerInfrastructure" "Background Tasks Infrastructure Service: Windows infrastructure service that controls which background tasks can run on the system." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\psmsrv.dll" "Sat Jun 5 13:05:10 2021" "
+ "BTAGService" "Bluetooth Audio Gateway Service: Service supporting the audio gateway role of the Bluetooth Handsfree Profile." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\BTAGService.dll" "Thu Dec 16 07:51:22 2021" "
+ "BthAvctpSvc" "AVCTP service: This is Audio Video Control Transport Protocol service" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\BthAvctpSvc.dll" "Sat Jun 5 13:04:50 2021" "
+ "bthserv" "Bluetooth Support Service: The Bluetooth service supports discovery and association of remote Bluetooth devices. Stopping or disabling this service may cause already installed Bluetooth devices to fail to operate properly and prevent new devices from being discovered or associated." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\bthserv.dll" "Sat Jun 5 13:05:16 2021" "
+ "camsvc" "Capability Access Manager Service: Provides facilities for managing UWP apps access to app capabilities as well as checking an app's access to specific app capabilities" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\CapabilityAccessManager.dll" "Thu Dec 16 07:52:51 2021" "
+ "CaptureService" "CaptureService: Enables optional screen capture functionality for applications that call the Windows.Graphics.Capture API." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\CaptureService.dll" "Sat Jun 5 13:05:23 2021" "
+ "CaptureService_6a9e6" "CaptureService_6a9e6: Enables optional screen capture functionality for applications that call the Windows.Graphics.Capture API." "(Verified) Microsoft Windows Publisher" "C:\WINDOWS\system32\svchost.exe" "Sat Jun 5 13:05:23 2021" "
+ "cbdhsvc" "Clipboard User Service: This user service is used for Clipboard scenarios" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\cbdhsvc.dll" "Thu Dec 16 07:56:28 2021" "
+ "cbdhsvc_6a9e6" "Clipboard User Service_6a9e6: This user service is used for Clipboard scenarios" "(Verified) Microsoft Windows Publisher" "C:\WINDOWS\system32\svchost.exe" "Sat Jun 5 13:05:23 2021" "
+ "CDPSvc" "Connected Devices Platform Service: This service is used for Connected Devices Platform scenarios" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\CDPSvc.dll" "Sat Jun 5 13:05:02 2021" "
+ "CDPUserSvc" "Connected Devices Platform User Service: This user service is used for Connected Devices Platform scenarios" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\CDPUserSvc.dll" "Sat Jun 5 13:05:02 2021" "
+ "CDPUserSvc_6a9e6" "Connected Devices Platform User Service_6a9e6: This user service is used for Connected Devices Platform scenarios" "(Verified) Microsoft Windows Publisher" "C:\WINDOWS\system32\svchost.exe" "Sat Jun 5 13:05:23 2021" "
+ X "CertPropSvc" "Certificate Propagation: Copies user certificates and root certificates from smart cards into the current user's certificate store, detects when a smart card is inserted into a smart card reader, and, if needed, installs the smart card Plug and Play minidriver." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\certprop.dll" "Sat Jun 5 13:05:34 2021" "
+ "ClickToRunSvc" "Microsoft Office Click-to-Run Service: ‪Manages resource coordination, background streaming, and system integration of Microsoft Office products and their related updates. This service is required to run during the use of any Microsoft Office program, during initial streaming installation and all subsequent updates.‬" "(Verified) Microsoft Corporation" "C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe" "Fri Dec 10 00:10:56 2021" "
+ "ClipSVC" "Client Licence Service (ClipSVC): Provides infrastructure support for the Microsoft Store. This service is started on demand and if disabled applications bought using Windows Store will not behave correctly." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\ClipSVC.dll" "Thu Dec 16 07:52:51 2021" "
+ "COMSysApp" "COM+ System Application: Manages the configuration and tracking of Component Object Model (COM)+-based components. If the service is stopped, most COM+-based components will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\dllhost.exe" "Sat Jun 5 13:05:23 2021" "
+ "ConsentUxUserSvc" "ConsentUX User Service: Allows the system to request user consent to allow apps to access sensitive resources and information such as the device's location" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\ConsentUxClient.dll" "Sat Jun 5 13:06:02 2021" "
+ "ConsentUxUserSvc_6a9e6" "ConsentUX User Service_6a9e6: Allows the system to request user consent to allow apps to access sensitive resources and information such as the device's location" "(Verified) Microsoft Windows Publisher" "C:\WINDOWS\system32\svchost.exe" "Sat Jun 5 13:05:23 2021" "
+ "CoreMessagingRegistrar" "CoreMessaging: Manages communication between system components." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\coremessaging.dll" "Thu Dec 16 07:53:41 2021" "
+ "cphs" "Intel(R) Content Protection HECI Service: Intel(R) Content Protection HECI Service - enables communication with the Content Protection FW" "(Verified) Intel(R) pGFX 2020" "C:\WINDOWS\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_e36b8067470714bb\IntelCpHeciSvc.exe" "Mon Jan 18 03:53:04 2021" "
+ "cplspcon" "Intel(R) Content Protection HDCP Service: Intel(R) Content Protection HDCP Service - enables communication with Content Protection HDCP HW" "(Verified) Intel(R) pGFX 2020" "C:\WINDOWS\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_e36b8067470714bb\IntelCpHDCPSvc.exe" "Mon Jan 18 03:53:04 2021" "
+ "CredentialEnrollmentManagerUserSvc" "CredentialEnrollmentManagerUserSvc: Credential Enrollment Manager" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\CredentialEnrollmentManager.exe" "Thu Dec 16 07:51:55 2021" "
+ "CredentialEnrollmentManagerUserSvc_6a9e6" "CredentialEnrollmentManagerUserSvc_6a9e6: Credential Enrollment Manager" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\CredentialEnrollmentManager.exe" "Thu Dec 16 07:51:55 2021" "
+ "CryptSvc" "Cryptographic Services: Provides three management services: Catalog Database Service, which confirms the signatures of Windows files and allows new programs to be installed; Protected Root Service, which adds and removes Trusted Root Certification Authority certificates from this computer; and Automatic Root Certificate Update Service, which retrieves root certificates from Windows Update and enable scenarios such as SSL. If this service is stopped, these management services will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\cryptsvc.dll" "Sat Jun 5 13:05:23 2021" "
+ "DcomLaunch" "DCOM Server Process Launcher: The DCOMLAUNCH service launches COM and DCOM servers in response to object activation requests. If this service is stopped or disabled, programs using COM or DCOM will not function properly. It is strongly recommended that you have the DCOMLAUNCH service running." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\rpcss.dll" "Thu Dec 16 07:53:43 2021" "
+ "defragsvc" "Optimise drives: Helps the computer run more efficiently by optimising files on storage drives." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\defragsvc.dll" "Thu Dec 16 07:56:30 2021" "
+ "DeviceAssociationBrokerSvc" "DeviceAssociationBroker: Enables apps to pair devices" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\deviceaccess.dll" "Sat Jun 5 13:05:12 2021" "
+ "DeviceAssociationBrokerSvc_6a9e6" "DeviceAssociationBroker_6a9e6: Enables apps to pair devices" "(Verified) Microsoft Windows Publisher" "C:\WINDOWS\system32\svchost.exe" "Sat Jun 5 13:05:23 2021" "
+ "DeviceAssociationService" "Device Association Service: Enables pairing between the system and wired or wireless devices." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\das.dll" "Sat Jun 5 13:05:16 2021" "
+ "DeviceInstall" "Device Install Service: Enables a computer to recognize and adapt to hardware changes with little or no user input. Stopping or disabling this service will result in system instability." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\umpnpmgr.dll" "Sat Jun 5 13:05:39 2021" "
+ "DevicePickerUserSvc" "DevicePicker: This user service is used for managing the Miracast, DLNA and DIAL UI" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Windows.Devices.Picker.dll" "Sat Jun 5 13:06:46 2021" "
+ "DevicePickerUserSvc_6a9e6" "DevicePicker_6a9e6: This user service is used for managing the Miracast, DLNA and DIAL UI" "(Verified) Microsoft Windows Publisher" "C:\WINDOWS\system32\svchost.exe" "Sat Jun 5 13:05:23 2021" "
+ "DevicesFlowUserSvc" "DevicesFlow: Allows ConnectUX and PC Settings to Connect and Pair with WiFi displays and Bluetooth devices." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DevicesFlowBroker.dll" "Sat Jun 5 13:05:20 2021" "
+ "DevicesFlowUserSvc_6a9e6" "DevicesFlow_6a9e6: Allows ConnectUX and PC Settings to Connect and Pair with WiFi displays and Bluetooth devices." "(Verified) Microsoft Windows Publisher" "C:\WINDOWS\system32\svchost.exe" "Sat Jun 5 13:05:23 2021" "
+ "DevQueryBroker" "DevQuery Background Discovery Broker: Enables apps to discover devices with a backgroud task" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\DevQueryBroker.dll" "Sat Jun 5 13:05:09 2021" "
+ "Dhcp" "DHCP Client: Registers and updates IP addresses and DNS records for this computer. If this service is stopped, this computer will not receive dynamic IP addresses and DNS updates. If this service is disabled, any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\dhcpcore.dll" "Thu Dec 16 07:53:42 2021" "
+ "diagnosticshub.standardcollector.service" "Microsoft (R) Diagnostics Hub Standard Collector Service: Diagnostics Hub Standard Collector Service. When running, this service collects real time ETW events and processes them." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe" "Thu Dec 16 07:53:52 2021" "
+ "diagsvc" "Diagnostic Execution Service: Executes diagnostic actions for troubleshooting support" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\DiagSvc.dll" "Sat Jun 5 13:06:16 2021" "
+ X "DiagTrack" "Connected User Experiences and Telemetry: The Connected User Experiences and Telemetry service enables features that support in-application and connected user experiences. Additionally, this service manages the event driven collection and transmission of diagnostic and usage information (used to improve the experience and quality of the Windows Platform) when the diagnostics and usage privacy option settings are enabled under Feedback and Diagnostics." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\diagtrack.dll" "Thu Dec 16 07:53:46 2021" "
+ "DispBrokerDesktopSvc" "Display Policy Service: Manages the connection and configuration of local and remote displays" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DispBroker.Desktop.dll" "Thu Dec 16 07:56:31 2021" "
+ "DisplayEnhancementService" "Display Enhancement Service: A service for managing display enhancement such as brightness control." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\Microsoft.Graphics.Display.DisplayEnhancementService.dll" "Thu Dec 16 07:56:20 2021" "
+ "DmEnrollmentSvc" "Device Management Enrollment Service: Performs Device Enrollment Activities for Device Management" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\Windows.Internal.Management.dll" "Sat Jun 5 13:05:29 2021" "
+ "dmwappushservice" "Device Management Wireless Application Protocol (WAP) Push message Routing Service: Routes Wireless Application Protocol (WAP) Push messages received by the device and synchronizes Device Management sessions" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\dmwappushsvc.dll" "Sat Jun 5 13:05:29 2021" "
+ "Dnscache" "DNS Client: The DNS Client service (dnscache) caches Domain Name System (DNS) names and registers the full computer name for this computer. If the service is stopped, DNS names will continue to be resolved. However, the results of DNS name queries will not be cached and the computer's name will not be registered. If the service is disabled, any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\dnsrslvr.dll" "Thu Dec 16 07:53:42 2021" "
+ "DoSvc" "Delivery Optimization: Performs content delivery optimization tasks" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\dosvc.dll" "Thu Dec 16 07:52:21 2021" "
+ "dot3svc" "Wired AutoConfig: The Wired AutoConfig (DOT3SVC) service is responsible for performing IEEE 802.1X authentication on Ethernet interfaces. If your current wired network deployment enforces 802.1X authentication, the DOT3SVC service should be configured to run for establishing Layer 2 connectivity and/or providing access to network resources. Wired networks that do not enforce 802.1X authentication are unaffected by the DOT3SVC service." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\dot3svc.dll" "Thu Dec 16 07:51:51 2021" "
+ "DPS" "Diagnostic Policy Service: The Diagnostic Policy Service enables problem detection, troubleshooting and resolution for Windows components. If this service is stopped, diagnostics will no longer function." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\dps.dll" "Sat Jun 5 13:06:13 2021" "
+ "DsmSvc" "Device Setup Manager: Enables the detection, download and installation of device-related software. If this service is disabled, devices may be configured with outdated software, and may not work correctly." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DeviceSetupManager.dll" "Sat Jun 5 13:05:06 2021" "
+ "DsSvc" "Data Sharing Service: Provides data brokering between applications." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DsSvc.dll" "Sat Jun 5 13:05:02 2021" "
+ "DusmSvc" "Data Usage: Network data usage, data limit, restrict background data, metered networks." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\dusmsvc.dll" "Thu Dec 16 07:56:20 2021" "
+ "EapHost" "Extensible Authentication Protocol: The Extensible Authentication Protocol (EAP) service provides network authentication in such scenarios as 802.1x wired and wireless, VPN, and Network Access Protection (NAP). EAP also provides application programming interfaces (APIs) that are used by network access clients, including wireless and VPN clients, during the authentication process. If you disable this service, this computer is prevented from accessing networks that require EAP authentication." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\eapsvc.dll" "Sat Jun 5 13:04:57 2021" "
+ "edgeupdate" "Microsoft Edge Update Service (edgeupdate): Keeps your Microsoft software up to date. If this service is disabled or stopped, your Microsoft software will not be kept up to date, meaning security vulnerabilities that may arise cannot be fixed and features may not work. This service uninstalls itself when there is no Microsoft software using it." "(Verified) Microsoft Corporation" "C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" "Thu Apr 1 20:17:37 2021" "
+ "edgeupdatem" "Microsoft Edge Update Service (edgeupdatem): Keeps your Microsoft software up to date. If this service is disabled or stopped, your Microsoft software will not be kept up to date, meaning security vulnerabilities that may arise cannot be fixed and features may not work. This service uninstalls itself when there is no Microsoft software using it." "(Verified) Microsoft Corporation" "C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" "Thu Apr 1 20:17:37 2021" "
+ "EFS" "Encrypting File System (EFS): Provides the core file encryption technology used to store encrypted files on NTFS file system volumes. If this service is stopped or disabled, applications will be unable to access encrypted files." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\efssvc.dll" "Thu Dec 16 07:54:17 2021" "
+ "embeddedmode" "Embedded Mode: The Embedded Mode service enables scenarios related to Background Applications. Disabling this service will prevent Background Applications from being activated." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\embeddedmodesvc.dll" "Sat Jun 5 13:05:02 2021" "
+ "EntAppSvc" "Enterprise App Management Service: Enables enterprise application management." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\EnterpriseAppMgmtSvc.dll" "Sat Jun 5 13:05:16 2021" "
+ "EventLog" "Windows Event Log: This service manages events and event logs. It supports logging events, querying events, subscribing to events, archiving event logs, and managing event metadata. It can display events in both XML and plain text format. Stopping this service may compromise security and reliability of the system." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\wevtsvc.dll" "Thu Dec 16 07:53:06 2021" "
+ "EventSystem" "COM+ Event System: Supports System Event Notification Service (SENS), which provides automatic distribution of events to subscribing Component Object Model (COM) components. If the service is stopped, SENS will close and will not be able to provide logon and logoff notifications. If this service is disabled, any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\es.dll" "Sat Jun 5 13:05:23 2021" "
+ "Fax" "Fax: Enables you to send and receive faxes, using fax resources available on this computer or on the network." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\fxssvc.exe" "Sat Jun 5 02:34:00 2021" "
+ "fdPHost" "Function Discovery Provider Host: The FDPHOST service hosts the Function Discovery (FD) network discovery providers. These FD providers supply network discovery services for the Simple Services Discovery Protocol (SSDP) and Web Services – Discovery (WS-D) protocol. Stopping or disabling the FDPHOST service will disable network discovery for these protocols when using FD. When this service is unavailable, network services using FD and relying on these discovery protocols will be unable to find network devices or resources." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\fdPHost.dll" "Sat Jun 5 13:05:29 2021" "
+ "FDResPub" "Function Discovery Resource Publication: Publishes this computer and resources attached to this computer so they can be discovered over the network. If this service is stopped, network resources will no longer be published and they will not be discovered by other computers on the network." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\fdrespub.dll" "Sat Jun 5 13:05:29 2021" "
+ "fhsvc" "File History Service: Protects user files from accidental loss by copying them to a backup location" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\fhsvc.dll" "Thu Dec 16 07:56:54 2021" "
+ "FileSyncHelper" "FileSyncHelper: Helper service for OneDrive" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncHelper.exe" "Tue Dec 7 07:14:38 2021" "
+ "FontCache" "Windows Font Cache Service: Optimizes performance of applications by caching commonly used font data. Applications will start this service if it is not already running. It can be disabled, though doing so will degrade application performance." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\FntCache.dll" "Thu Dec 16 07:52:22 2021" "
+ "FontCache3.0.0.0" "Windows Presentation Foundation Font Cache 3.0.0.0: Optimizes performance of Windows Presentation Foundation (WPF) applications by caching commonly used font data. WPF applications will start this service if it is not already running. It can be disabled, though doing so will degrade the performance of WPF applications." "(Verified) Microsoft Corporation" "C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe" "Tue Jun 1 15:27:00 2021" "
+ "FrameServer" "Windows Camera Frame Server: Enables multiple clients to access video frames from camera devices." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\FrameServer.dll" "Thu Dec 16 07:56:42 2021" "
+ "FrameServerMonitor" "Windows Camera Frame Server Monitor: Monitors the health and state for the Windows Camera Frame Server service." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\FrameServerMonitor.dll" "Thu Dec 16 07:56:42 2021" "
+ "GoogleChromeElevationService" "Google Chrome Elevation Service (GoogleChromeElevationService): Google Chrome" "(Verified) Google LLC" "C:\Program Files\Google\Chrome\Application\96.0.4664.110\elevation_service.exe" "Sun Dec 12 08:19:40 2021" "
+ "GoTrust ID Plugin" "GoTrust ID Plugin: GoTrust ID Plugin" "(Not Verified) GOTrustID Inc." "C:\Program Files\GoTrust ID Plugin\GoTrust ID Plugin\GTFidoService.exe" "Tue Sep 8 09:46:46 2020" "
+ "GoTrustID Service" "GoTrustID Service: GoTrustID Service" "(Verified) GoTrustID Inc" "C:\Program Files\GoTrust ID Plugin\Bridge_Service.exe" "Tue Sep 8 09:47:36 2020" "
+ "gpsvc" "Group Policy Client: The service is responsible for applying settings configured by administrators for the computer and users through the Group Policy component. If the service is disabled, the settings will not be applied and applications and components will not be manageable through Group Policy. Any components or applications that depend on the Group Policy component might not be functional if the service is disabled." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\gpsvc.dll" "Thu Dec 16 07:54:21 2021" "
+ "GraphicsPerfSvc" "GraphicsPerfSvc: Graphics performance monitor service" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\GraphicsPerfSvc.dll" "Sat Jun 5 13:05:06 2021" "
+ "gupdate" "Google Update Service (gupdate): Keeps your Google software up to date. If this service is disabled or stopped, your Google software will not be kept up to date, meaning security vulnerabilities that may arise cannot be fixed and features may not work. This service uninstalls itself when there is no Google software using it." "(Verified) Google LLC" "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" "Tue Oct 12 17:43:19 2021" "
+ "gupdatem" "Google Update Service (gupdatem): Keeps your Google software up to date. If this service is disabled or stopped, your Google software will not be kept up to date, meaning security vulnerabilities that may arise cannot be fixed and features may not work. This service uninstalls itself when there is no Google software using it." "(Verified) Google LLC" "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" "Tue Oct 12 17:43:19 2021" "
+ X "HfcDisableService" "Intel(R) RST HFC Disable Service: Turns off hiberfile caching in Intel(R) RST driver." "(Verified) Intel(R) Rapid Storage Technology" "C:\WINDOWS\System32\DriverStore\FileRepository\iastorac.inf_amd64_34f570cbe7f3d6c7\HfcDisableService.exe" "Sun Oct 10 17:41:43 2021" "
+ "hidserv" "Human Interface Device Service: Activates and maintains the use of hot buttons on keyboards, remote controls and other multimedia devices. It is recommended that you keep this service running." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\hidserv.dll" "Sat Jun 5 13:05:29 2021" "
+ "HPPrintScanDoctorService" "HP Print Scan Doctor Service: " "(Verified) HP Inc." "C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe" "Mon Nov 1 19:37:39 2021" "
+ "HvHost" "HV Host Service: Provides an interface for the Hyper-V hypervisor to provide per-partition performance counters to the host operating system." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\hvhostsvc.dll" "Sat Jun 5 13:06:00 2021" "
+ "iaStorAfsService" "Intel(R) Optane(TM) Memory Service: Enables amazing system performance and responsiveness by accelerating frequently used files" "(Verified) Intel(R) Rapid Storage Technology" "C:\WINDOWS\System32\iaStorAfsService.exe" "Sun Oct 10 17:41:43 2021" "
+ "icssvc" "Windows Mobile Hotspot Service: Provides the ability to share a mobile data connection with another device." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\tetheringservice.dll" "Thu Dec 16 07:51:29 2021" "
+ "igccservice" "Intel(R) Graphics Command Center Service: Service for Intel(R) Graphics Command Center" "(Verified) Intel(R) pGFX 2020" "C:\WINDOWS\System32\DriverStore\FileRepository\igcc_dch.inf_amd64_3636ad46b8d9530e\OneApp.IGCC.WinService.exe" "Mon Jan 18 03:53:50 2021" "
+ "igfxCUIService2.0.0.0" "Intel(R) HD Graphics Control Panel Service: Service for Intel(R) HD Graphics Control Panel" "(Verified) Intel(R) pGFX 2020" "C:\WINDOWS\System32\DriverStore\FileRepository\cui_dch.inf_amd64_1e4c5c6397177db7\igfxCUIService.exe" "Mon Jan 18 03:52:30 2021" "
+ "IKEEXT" "IKE and AuthIP IPsec Keying Modules: The IKEEXT service hosts the Internet Key Exchange (IKE) and Authenticated Internet Protocol (AuthIP) keying modules. These keying modules are used for authentication and key exchange in Internet Protocol security (IPsec). Stopping or disabling the IKEEXT service will disable IKE and AuthIP key exchange with peer computers. IPsec is typically configured to use IKE or AuthIP; therefore, stopping or disabling the IKEEXT service might result in an IPsec failure and might compromise the security of the system. It is strongly recommended that you have the IKEEXT service running." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\ikeext.dll" "Thu Dec 16 07:52:47 2021" "
+ "InstallService" "Microsoft Store Install Service: Provides infrastructure support for the Microsoft Store. This service is started on demand, and if disabled then installations will not function properly." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\InstallService.dll" "Thu Dec 16 07:52:32 2021" "
+ "Intel(R) Capability Licensing Service TCP IP Interface" "Intel(R) Capability Licensing Service TCP IP Interface: Version: 1.62.321.1" "(Verified) Intel(R) Trust Services" "C:\WINDOWS\System32\DriverStore\FileRepository\iclsclient.inf_amd64_a93205b6238060e4\lib\SocketHeciServer.exe" "Thu Feb 18 04:18:02 2021" "
+ "Intel(R) TPM Provisioning Service" "Intel(R) TPM Provisioning Service: Version: 1.62.321.1" "(Verified) Intel(R) Trust Services" "C:\WINDOWS\System32\DriverStore\FileRepository\iclsclient.inf_amd64_a93205b6238060e4\lib\TPMProvisioningService.exe" "Thu Feb 18 04:18:02 2021" "
+ "iphlpsvc" "IP Helper: Provides tunnel connectivity using IPv6 transition technologies (6to4, ISATAP, Port Proxy, and Teredo), and IP-HTTPS. If this service is stopped, the computer will not have the enhanced connectivity benefits that these technologies offer." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\iphlpsvc.dll" "Thu Dec 16 07:54:50 2021" "
+ "IpxlatCfgSvc" "IP Translation Configuration Service: Configures and enables translation from v4 to v6 and vice versa" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\IpxlatCfg.dll" "Sat Jun 5 13:04:50 2021" "
+ "jhi_service" "Intel(R) Dynamic Application Loader Host Interface Service: Intel(R) Dynamic Application Loader Host Interface Service - Allows applications to access the local Intel (R) DAL" "(Verified) Intel(R) Embedded Subsystems and IP Blocks Group" "C:\WINDOWS\System32\DriverStore\FileRepository\dal.inf_amd64_b5484efd38adbe8d\jhi_service.exe" "Thu Feb 18 04:18:02 2021" "
+ "KeyIso" "CNG Key Isolation: The CNG key isolation service is hosted in the LSA process. The service provides key process isolation to private keys and associated cryptographic operations as required by the Common Criteria. The service stores and uses long-lived keys in a secure process complying with Common Criteria requirements." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\keyiso.dll" "Sat Jun 5 13:05:25 2021" "
+ "KtmRm" "KtmRm for Distributed Transaction Coordinator: Coordinates transactions between the Distributed Transaction Coordinator (MSDTC) and the Kernel Transaction Manager (KTM). If it is not needed, it is recommended that this service remain stopped. If it is needed, both MSDTC and KTM will start this service automatically. If this service is disabled, any MSDTC transaction interacting with a Kernel Resource Manager will fail and any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\msdtckrm.dll" "Sat Jun 5 13:06:02 2021" "
+ "LanmanServer" "Server: Supports file, print, and named-pipe sharing over the network for this computer. If this service is stopped, these functions will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\srvsvc.dll" "Thu Dec 16 07:53:52 2021" "
+ "LanmanWorkstation" "Workstation: Creates and maintains client network connections to remote servers using the SMB protocol. If this service is stopped, these connections will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\wkssvc.dll" "Sat Jun 5 13:05:25 2021" "
+ "lfsvc" "Geolocation Service: This service monitors the current location of the system and manages geofences (a geographical location with associated events). If you turn off this service, applications will be unable to use or receive notifications for geolocation or geofences." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\lfsvc.dll" "Sat Jun 5 13:05:29 2021" "
+ "LicenseManager" "Windows License Manager Service: Provides infrastructure support for the Microsoft Store. This service is started on demand and if disabled then content acquired through the Microsoft Store will not function properly." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\LicenseManagerSvc.dll" "Thu Dec 16 07:52:32 2021" "
+ "lltdsvc" "Link-Layer Topology Discovery Mapper: Creates a Network Map, consisting of PC and device topology (connectivity) information, and metadata describing each PC and device. If this service is disabled, the Network Map will not function properly." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\lltdsvc.dll" "Sat Jun 5 13:05:29 2021" "
+ "lmhosts" "TCP/IP NetBIOS Helper: Provides support for the NetBIOS over TCP/IP (NetBT) service and NetBIOS name resolution for clients on the network, therefore enabling users to share files, print, and log on to the network. If this service is stopped, these functions might be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\lmhsvc.dll" "Sat Jun 5 13:05:25 2021" "
+ "LMS" "Intel(R) Management and Security Application Local Management Service: Intel(R) Management and Security Application Local Management Service - Provides OS-related Intel(R) ME functionality." "(Verified) Intel Corporation" "C:\WINDOWS\System32\DriverStore\FileRepository\lms.inf_amd64_fddb643595e0b8d0\LMS.exe" "Thu Sep 2 03:06:42 2021" "
+ "LSM" "Local Session Manager: Core Windows Service that manages local user sessions. Stopping or disabling this service will result in system instability." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\lsm.dll" "Thu Dec 16 07:53:00 2021" "
+ "LxpSvc" "Language Experience Service: Provides infrastructure support for deploying and configuring localized Windows resources. This service is started on demand and, if disabled, additional Windows languages will not be deployed to the system, and Windows may not function properly." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\LanguageOverlayServer.dll" "Thu Dec 16 07:51:41 2021" "
+ "MapsBroker" "Downloaded Maps Manager: Windows service for application access to downloaded maps. This service is started on-demand by applications accessing downloaded maps. Disabling this service will prevent apps from accessing maps." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\moshost.dll" "Thu Dec 16 07:52:29 2021" "
+ "McpManagementService" "McpManagementService: Universal Print Management Service" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\McpManagementService.dll" "Thu Dec 16 07:56:40 2021" "
+ "MessagingService" "MessagingService: Service supporting text messaging and related functionality." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\MessagingService.dll" "Sat Jun 5 13:04:52 2021" "
+ "MessagingService_6a9e6" "MessagingService_6a9e6: Service supporting text messaging and related functionality." "(Verified) Microsoft Windows Publisher" "C:\WINDOWS\system32\svchost.exe" "Sat Jun 5 13:05:23 2021" "
+ "MicrosoftEdgeElevationService" "Microsoft Edge Elevation Service (MicrosoftEdgeElevationService): Keeps Microsoft Edge up to update. If this service is disabled, the application will not be kept up to date." "(Verified) Microsoft Corporation" "C:\Program Files (x86)\Microsoft\Edge\Application\96.0.1054.62\elevation_service.exe" "Thu Dec 16 22:46:30 2021" "
+ "MixedRealityOpenXRSvc" "Windows Mixed Reality OpenXR Service: Enables Mixed Reality OpenXR runtime functionality" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\MixedRealityRuntime.dll" "Sat Jun 5 18:17:04 2021" "
+ "mpssvc" "Windows Defender Firewall: Windows Defender Firewall helps to protect your computer by preventing unauthorised users from gaining access to your computer through the Internet or a network." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mpssvc.dll" "Thu Dec 16 07:52:47 2021" "
+ "MSDTC" "Distributed Transaction Coordinator: Coordinates transactions that span multiple resource managers, such as databases, message queues, and file systems. If this service is stopped, these transactions will fail. If this service is disabled, any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\msdtc.exe" "Sat Jun 5 13:06:02 2021" "
+ X "MSiSCSI" "Microsoft iSCSI Initiator Service: Manages Internet SCSI (iSCSI) sessions from this computer to remote iSCSI target devices. If this service is stopped, this computer will not be able to login or access iSCSI targets. If this service is disabled, any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\iscsiexe.dll" "Sat Jun 5 13:06:07 2021" "
+ "msiserver" "Windows Installer: Adds, modifies and removes applications provided as a Windows Installer or APPX package (*.msi, *.msp, *.appx). If this service is disabled, any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\msiexec.exe" "Sat Jun 5 13:06:10 2021" "
+ "NaturalAuthentication" "Natural Authentication: Signal aggregator service, that evaluates signals based on time, network, geolocation, bluetooth and cdf factors. Supported features are Device Unlock, Dynamic Lock and Dynamo MDM policies" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\NaturalAuth.dll" "Thu Dec 16 07:51:46 2021" "
+ "NcaSvc" "Network Connectivity Assistant: Provides DirectAccess status notification for UI components" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\ncasvc.dll" "Sat Jun 5 13:05:29 2021" "
+ "NcbService" "Network Connection Broker: Brokers connections that allow Windows Store Apps to receive notifications from the internet." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\ncbservice.dll" "Sat Jun 5 13:05:09 2021" "
+ "NcdAutoSetup" "Network Connected Devices Auto-Setup: Network Connected Devices Auto-Setup service monitors and installs qualified devices that connect to a qualified network. Stopping or disabling this service will prevent Windows from discovering and installing qualified network connected devices automatically. Users can still manually add network connected devices to a PC through the user interface." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\NcdAutoSetup.dll" "Sat Jun 5 13:06:16 2021" "
+ "Netlogon" "Netlogon: Maintains a secure channel between this computer and the domain controller for authenticating users and services. If this service is stopped, the computer may not authenticate users and services and the domain controller cannot register DNS records. If this service is disabled, any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\netlogon.dll" "Thu Dec 16 07:53:51 2021" "
+ "Netman" "Network Connections: Manages objects in the Network and Dial-Up Connections folder, in which you can view both local area network and remote connections." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\netman.dll" "Sat Jun 5 13:04:58 2021" "
+ "netprofm" "Network List Service: Identifies the networks the computer has connected to, collects and stores properties for these networks, and notifies applications when these properties change." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\netprofmsvc.dll" "Thu Dec 16 07:54:51 2021" "
+ "NetSetupSvc" "Network Setup Service: The Network Setup Service manages the installation of network drivers and permits the configuration of low-level network settings. If this service is stopped, any driver installations that are in progress may be cancelled." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\NetSetupSvc.dll" "Sat Jun 5 13:05:25 2021" "
+ X "NetTcpPortSharing" "Net.Tcp Port Sharing Service: Provides ability to share TCP ports over the net.tcp protocol." "(Verified) Microsoft Corporation" "C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe" "Sat Jun 5 13:06:50 2021" "
+ "NgcCtnrSvc" "Microsoft Passport Container: Manages local user identity keys used to authenticate the user to identity providers, as well as TPM virtual smart cards. If this service is disabled, local user identity keys and TPM virtual smart cards will not be accessible. It is recommended that you do not reconfigure this service." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\NgcCtnrSvc.dll" "Thu Dec 16 07:52:53 2021" "
+ "NgcSvc" "Microsoft Passport: Provides process isolation for cryptographic keys used to provide authentication to a user’s associated identity providers. If this service is disabled, all uses and management of these keys will not be available, which includes machine log-on and single sign-on for apps and websites. This service starts and stops automatically. It is recommended that you do not reconfigure this service." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\ngcsvc.dll" "Thu Dec 16 07:52:53 2021" "
+ "NlaSvc" "Network Location Awareness: Collects and stores configuration information for the network and notifies programmes when this information is modified. If this service is stopped, configuration information might be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\netprofmsvc.dll" "Thu Dec 16 07:54:51 2021" "
+ "NPSMSvc" "NPSMSvc: NPSM" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\npsm.dll" "Sat Jun 5 13:05:09 2021" "
+ "NPSMSvc_6a9e6" "NPSMSvc_6a9e6: Host Process for Windows Services" "(Verified) Microsoft Windows Publisher" "C:\WINDOWS\system32\svchost.exe" "Sat Jun 5 13:05:23 2021" "
+ "nsi" "Network Store Interface Service: This service delivers network notifications (e.g. interface addition/deleting etc) to user mode clients. Stopping this service will cause loss of network connectivity. If this service is disabled, any other services that explicitly depend on this service will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\nsisvc.dll" "Sat Jun 5 13:05:25 2021" "
+ "OneDrive Updater Service" "OneDrive Updater Service: Keeps your OneDrive up to date." "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\OneDriveUpdaterService.exe" "Tue Dec 7 07:14:41 2021" "
+ "OneSyncSvc" "Sync Host: This service synchronizes mail, contacts, calendar and various other user data. Mail and other applications dependent on this functionality will not work properly when this service is not running." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\APHostService.dll" "Fri Jun 4 20:12:00 2021" "
+ "OneSyncSvc_6a9e6" "Sync Host_6a9e6: This service synchronizes mail, contacts, calendar and various other user data. Mail and other applications dependent on this functionality will not work properly when this service is not running." "(Verified) Microsoft Windows Publisher" "C:\WINDOWS\system32\svchost.exe" "Sat Jun 5 13:05:23 2021" "
+ "p2pimsvc" "Peer Networking Identity Manager: Provides identity services for the Peer Name Resolution Protocol (PNRP) and Peer-to-Peer Grouping services. If disabled, the Peer Name Resolution Protocol (PNRP) and Peer-to-Peer Grouping services may not function, and some applications, such as HomeGroup and Remote Assistance, may not function correctly." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\pnrpsvc.dll" "Sat Jun 5 13:06:16 2021" "
+ "p2psvc" "Peer Networking Grouping: Enables multi-party communication using Peer-to-Peer Grouping. If disabled, some applications, such as HomeGroup, may not function." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\p2psvc.dll" "Sat Jun 5 13:06:16 2021" "
+ "P9RdrService" "P9RdrService: Enables trigger-starting plan9 file servers." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\p9rdrservice.dll" "Sat Jun 5 13:06:17 2021" "
+ "P9RdrService_6a9e6" "P9RdrService_6a9e6: Enables trigger-starting plan9 file servers." "(Verified) Microsoft Windows Publisher" "C:\WINDOWS\system32\svchost.exe" "Sat Jun 5 13:05:23 2021" "
+ "PcaSvc" "Program Compatibility Assistant Service: This service provides support for the Program Compatibility Assistant (PCA). PCA monitors programs installed and run by the user and detects known compatibility problems. If this service is stopped, PCA will not function properly." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\pcasvc.dll" "Thu Dec 16 07:53:34 2021" "
+ "PenService" "PenService: Pen Service" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\PenService.dll" "Thu Dec 16 07:56:21 2021" "
+ "PenService_6a9e6" "PenService_6a9e6: Pen Service" "(Verified) Microsoft Windows Publisher" "C:\WINDOWS\system32\svchost.exe" "Sat Jun 5 13:05:23 2021" "
+ "perceptionsimulation" "Windows Perception Simulation Service: Enables spatial perception simulation, virtual camera management and spatial input simulation." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\PerceptionSimulation\PerceptionSimulationService.exe" "Sat Jun 5 13:06:00 2021" "
+ "PerfHost" "Performance Counter DLL Host: Enables remote users and 64-bit processes to query performance counters provided by 32-bit DLLs. If this service is stopped, only local users and 32-bit processes will be able to query performance counters provided by 32-bit DLLs." "(Verified) Microsoft Windows" "C:\WINDOWS\SysWow64\perfhost.exe" "Sat Jun 5 13:05:55 2021" "
+ "PhoneSvc" "Phone Service: Manages the telephony state on the device" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\PhoneService.dll" "Thu Dec 16 07:51:29 2021" "
+ "PimIndexMaintenanceSvc" "Contact Data: Indexes contact data for fast contact searching. If you stop or disable this service, contacts might be missing from your search results." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\PimIndexMaintenance.dll" "Sat Jun 5 13:05:09 2021" "
+ "PimIndexMaintenanceSvc_6a9e6" "Contact Data_6a9e6: Indexes contact data for fast contact searching. If you stop or disable this service, contacts might be missing from your search results." "(Verified) Microsoft Windows Publisher" "C:\WINDOWS\system32\svchost.exe" "Sat Jun 5 13:05:23 2021" "
+ "pla" "Performance Logs & Alerts: Performance Logs and Alerts Collects performance data from local or remote computers based on preconfigured schedule parameters, then writes the data to a log or triggers an alert. If this service is stopped, performance information will not be collected. If this service is disabled, any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\pla.dll" "Sat Jun 5 13:06:10 2021" "
+ "PlugPlay" "Plug and Play: Enables a computer to recognize and adapt to hardware changes with little or no user input. Stopping or disabling this service will result in system instability." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\umpnpmgr.dll" "Sat Jun 5 13:05:39 2021" "
+ "PNRPAutoReg" "PNRP Machine Name Publication Service: This service publishes a machine name using the Peer Name Resolution Protocol. Configuration is managed via the netsh context 'p2p pnrp peer' " "(Verified) Microsoft Windows" "C:\WINDOWS\system32\pnrpauto.dll" "Sat Jun 5 13:06:16 2021" "
+ "PNRPsvc" "Peer Name Resolution Protocol: Enables serverless peer name resolution over the Internet using the Peer Name Resolution Protocol (PNRP). If disabled, some peer-to-peer and collaborative applications, such as Remote Assistance, may not function." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\pnrpsvc.dll" "Sat Jun 5 13:06:16 2021" "
+ "PolicyAgent" "IPsec Policy Agent: Internet Protocol security (IPsec) supports network-level peer authentication, data origin authentication, data integrity, data confidentiality (encryption), and replay protection. This service enforces IPsec policies created through the IP Security Policies snap-in or the command-line tool "netsh ipsec". If you stop this service, you may experience network connectivity issues if your policy requires that connections use IPsec. Also,remote management of Windows Defender Firewall is not available when this service is stopped." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\ipsecsvc.dll" "Sat Jun 5 13:05:29 2021" "
+ "Power" "Power: Manages power policy and power policy notification delivery." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\umpo.dll" "Sat Jun 5 13:04:52 2021" "
+ "PrintNotify" "Printer Extensions and Notifications: This service opens custom printer dialogue boxes and handles notifications from a remote print server or a printer. If you turn this service off, you won’t be able to see printer extensions or notifications." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\spool\drivers\x64\3\PrintConfig.dll" "Thu Dec 16 07:50:54 2021" "
+ "PrintWorkflowUserSvc" "PrintWorkflow: Provides support for Print Workflow applications. If you turn off this service, you may not be able to print successfully." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\PrintWorkflowService.dll" "Thu Dec 16 07:54:54 2021" "
+ "PrintWorkflowUserSvc_6a9e6" "PrintWorkflow_6a9e6: Provides support for Print Workflow applications. If you turn off this service, you may not be able to print successfully." "(Verified) Microsoft Windows Publisher" "C:\WINDOWS\system32\svchost.exe" "Sat Jun 5 13:05:23 2021" "
+ "ProfSvc" "User Profile Service: This service is responsible for loading and unloading user profiles. If this service is stopped or disabled, users will no longer be able to successfully sign in or sign out, apps might have problems getting to users' data, and components registered to receive profile event notifications won't receive them." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\profsvc.dll" "Thu Dec 16 07:53:44 2021" "
+ "PushToInstall" "Windows PushToInstall Service: Provides infrastructure support for the Microsoft Store. This service is started automatically and if disabled then remote installations will not function properly." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\PushToInstall.dll" "Thu Dec 16 07:52:32 2021" "
+ "QASvc" "Quick Access Service: Quick Access Service" "(Verified) Acer Incorporated" "C:\Program Files\Acer\Quick Access Service\QASvc.exe" "Thu Sep 10 13:58:18 2020" "
+ "QcomWlanSrv" "Qualcomm Atheros WLAN Driver Service: " "(Verified) Qualcomm Atheros, Inc." "C:\WINDOWS\System32\drivers\QcomWlanSrvx64.exe" "Sun Jul 18 20:19:12 2021" "
+ "QWAVE" "Quality Windows Audio Video Experience: Quality Windows Audio Video Experience (qWave) is a networking platform for Audio Video (AV) streaming applications on IP home networks. qWave enhances AV streaming performance and reliability by ensuring network quality-of-service (QoS) for AV applications. It provides mechanisms for admission control, run time monitoring and enforcement, application feedback, and traffic prioritization." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\qwave.dll" "Sat Jun 5 13:05:39 2021" "
+ "RasAuto" "Remote Access Auto Connection Manager: Creates a connection to a remote network whenever a program references a remote DNS or NetBIOS name or address." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\rasauto.dll" "Sat Jun 5 13:05:40 2021" "
+ "RasMan" "Remote Access Connection Manager: Manages dial-up and virtual private network (VPN) connections from this computer to the Internet or other remote networks. If this service is disabled, any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\rasmans.dll" "Thu Dec 16 07:54:56 2021" "
+ X "RemoteAccess" "Routing and Remote Access: Offers routing services to businesses in local area and wide area network environments." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\mprdim.dll" "Sat Jun 5 13:05:40 2021" "
+ X "RemoteRegistry" "Remote Registry: Enables remote users to modify registry settings on this computer. If this service is stopped, the registry can be modified only by users on this computer. If this service is disabled, any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\regsvc.dll" "Sat Jun 5 13:06:02 2021" "
+ "RetailDemo" "Retail Demo Service: The Retail Demo service controls device activity while the device is in retail demo mode." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\RDXService.dll" "Sat Jun 5 13:06:00 2021" "
+ "RmSvc" "Radio Management Service: Radio Management and Airplane Mode Service" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\RMapi.dll" "Sat Jun 5 13:05:40 2021" "
+ "RpcEptMapper" "RPC Endpoint Mapper: Resolves RPC interfaces identifiers to transport endpoints. If this service is stopped or disabled, programs using Remote Procedure Call (RPC) services will not function properly." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\RpcEpMap.dll" "Sat Jun 5 13:05:25 2021" "
+ "RpcLocator" "Remote Procedure Call (RPC) Locator: In Windows 2003 and earlier versions of Windows, the Remote Procedure Call (RPC) Locator service manages the RPC name service database. In Windows Vista and later versions of Windows, this service does not provide any functionality and is present for application compatibility." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\locator.exe" "Sat Jun 5 13:05:23 2021" "
+ "RpcSs" "Remote Procedure Call (RPC): The RPCSS service is the Service Control Manager for COM and DCOM servers. It performs object activations requests, object exporter resolutions and distributed garbage collection for COM and DCOM servers. If this service is stopped or disabled, programs using COM or DCOM will not function properly. It is strongly recommended that you have the RPCSS service running." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\rpcss.dll" "Thu Dec 16 07:53:43 2021" "
+ "RstMwService" "Intel(R) Storage Middleware Service: RPC endpoint service which allows communication between driver and Windows Store Application" "(Verified) Intel(R) Rapid Storage Technology" "C:\WINDOWS\System32\DriverStore\FileRepository\iastorac.inf_amd64_34f570cbe7f3d6c7\RstMwService.exe" "Sun Oct 10 17:41:43 2021" "
+ "RtkAudioUniversalService" "Realtek Audio Universal Service: Realtek Audio Universal Service" "(Verified) Realtek Semiconductor Corp." "C:\WINDOWS\System32\DriverStore\FileRepository\realtekservice.inf_amd64_f043f909bedcd504\RtkAudUService64.exe" "Wed Oct 6 20:03:40 2021" "
+ "SamSs" "Security Accounts Manager: The startup of this service signals other services that the Security Accounts Manager (SAM) is ready to accept requests. Disabling this service will prevent other services in the system from being notified when the SAM is ready, which may in turn cause those services to fail to start correctly. This service should not be disabled." "(Verified) Microsoft Windows Publisher" "C:\WINDOWS\system32\lsass.exe" "Thu Dec 16 07:53:50 2021" "
+ "SCardSvr" "Smart Card: Manages access to smart cards read by this computer. If this service is stopped, this computer will be unable to read smart cards. If this service is disabled, any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\SCardSvr.dll" "Sat Jun 5 13:05:34 2021" "
+ "ScDeviceEnum" "Smart Card Device Enumeration Service: Creates software device nodes for all smart card readers accessible to a given session. If this service is disabled, WinRT APIs will not be able to enumerate smart card readers." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\ScDeviceEnum.dll" "Sat Jun 5 13:05:34 2021" "
+ "Schedule" "Task Scheduler: Enables a user to configure and schedule automated tasks on this computer. The service also hosts multiple Windows system-critical tasks. If this service is stopped or disabled, these tasks will not be run at their scheduled times. If this service is disabled, any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\schedsvc.dll" "Sat Jun 5 13:05:12 2021" "
+ "SCPolicySvc" "Smart Card Removal Policy: Allows the system to be configured to lock the user desktop upon smart card removal." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\certprop.dll" "Sat Jun 5 13:05:34 2021" "
+ "SDRSVC" "Windows Backup: Provides Windows Backup and Restore capabilities." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\SDRSVC.dll" "Sat Jun 5 13:06:00 2021" "
+ "seclogon" "Secondary Logon: Enables starting processes under alternate credentials. If this service is stopped, this type of log-on access will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\seclogon.dll" "Sat Jun 5 13:05:39 2021" "
+ "SecurityHealthService" "Windows Security Service: Windows Security Service handles unified device protection and health information" "(Verified) Microsoft Windows Publisher" "C:\WINDOWS\system32\SecurityHealthService.exe" "Thu Dec 16 07:54:13 2021" "
+ "SEMgrSvc" "Payments and NFC/SE Manager: Manages payments and Near Field Communication (NFC) based secure elements." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\SEMgrSvc.dll" "Sat Jun 5 13:05:05 2021" "
+ "SENS" "System Event Notification Service: Monitors system events and notifies subscribers to COM+ Event System of these events." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\sens.dll" "Sat Jun 5 13:05:40 2021" "
+ "SensorDataService" "Sensor Data Service: Delivers data from a variety of sensors" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\SensorDataService.exe" "Sat Jun 5 13:05:27 2021" "
+ "SensorService" "Sensor Service: A service for sensors that manages different sensors' functionality. Manages Simple Device Orientation (SDO) and History for sensors. Loads the SDO sensor that reports device orientation changes. If this service is stopped or disabled, the SDO sensor will not be loaded and so auto-rotation will not occur. History collection from Sensors will also be stopped." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\SensorService.dll" "Thu Dec 16 07:53:06 2021" "
+ "SensrSvc" "Sensor Monitoring Service: Monitors various sensors in order to expose data and adapt to system and user state. If this service is stopped or disabled, the display brightness will not adapt to lighting conditions. Stopping this service may affect other system functionality and features as well." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\sensrsvc.dll" "Sat Jun 5 13:05:33 2021" "
+ "SessionEnv" "Remote Desktop Configuration: Remote Desktop Configuration service (RDCS) is responsible for all Remote Desktop Services and Remote Desktop related configuration and session maintenance activities that require SYSTEM context. These include per-session temporary folders, RD themes, and RD certificates." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\sessenv.dll" "Sat Jun 5 13:06:14 2021" "
+ "SgrmBroker" "System Guard Runtime Monitor Broker: Monitors and attests to the integrity of the Windows platform." "(Verified) Microsoft Windows Publisher" "C:\WINDOWS\system32\SgrmBroker.exe" "Sat Jun 5 13:06:00 2021" "
+ "SharedAccess" "Internet Connection Sharing (ICS): Provides network address translation, addressing, name resolution and/or intrusion prevention services for a home or small office network." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\ipnathlp.dll" "Sat Jun 5 13:05:40 2021" "
+ "SharedRealitySvc" "Spatial Data Service: This service is used for Spatial Perception scenarios" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\SharedRealitySvc.dll" "Sat Jun 5 13:06:16 2021" "
+ "ShellHWDetection" "Shell Hardware Detection: Provides notifications for AutoPlay hardware events." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\shsvcs.dll" "Sat Jun 5 13:06:05 2021" "
+ X "shpamsvc" "Shared PC Account Manager: Manages profiles and accounts on a SharedPC configured device" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\Windows.SharedPC.AccountManager.dll" "Sat Jun 5 13:05:19 2021" "
+ "smphost" "Microsoft Storage Spaces SMP: Host service for the Microsoft Storage Spaces management provider. If this service is stopped or disabled, Storage Spaces cannot be managed." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\smphost.dll" "Sat Jun 5 13:06:02 2021" "
+ "SmsRouter" "Microsoft Windows SMS Router Service.: Routes messages based on rules to appropriate clients." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\SmsRouterSvc.dll" "Thu Dec 16 07:56:20 2021" "
+ X "SNMPTrap" "SNMP Trap: Receives trap messages generated by local or remote Simple Network Management Protocol (SNMP) agents and forwards the messages to SNMP management programs running on this computer. If this service is stopped, SNMP-based programs on this computer will not receive SNMP trap messages. If this service is disabled, any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\snmptrap.exe" "Sat Jun 5 13:05:34 2021" "
+ "spectrum" "Windows Perception Service: Enables spatial perception, spatial input, and holographic rendering." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\spectrum.exe" "Thu Dec 16 07:56:55 2021" "
+ "Spooler" "Print Spooler: This service spools print jobs and handles interaction with the printer. If you turn off this service, you won’t be able to print or see your printers." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\spoolsv.exe" "Thu Dec 16 07:51:44 2021" "
+ "sppsvc" "Software Protection: Enables the download, installation and enforcement of digital licenses for Windows and Windows applications. If the service is disabled, the operating system and licensed applications may run in a notification mode. It is strongly recommended that you not disable the Software Protection service." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\sppsvc.exe" "Thu Dec 16 07:54:28 2021" "
+ "SSDPSRV" "SSDP Discovery: Discovers networked devices and services that use the SSDP discovery protocol, such as UPnP devices. Also announces SSDP devices and services running on the local computer. If this service is stopped, SSDP-based devices will not be discovered. If this service is disabled, any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\ssdpsrv.dll" "Sat Jun 5 13:06:00 2021" "
+ X "ssh-agent" "OpenSSH Authentication Agent: Agent to hold private keys used for public key authentication." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\OpenSSH\ssh-agent.exe" "Fri Jun 4 18:53:00 2021" "
+ "SstpSvc" "Secure Socket Tunneling Protocol Service: Provides support for the Secure Socket Tunneling Protocol (SSTP) to connect to remote computers using VPN. If this service is disabled, users will not be able to use SSTP to access remote servers." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\sstpsvc.dll" "Sat Jun 5 13:05:40 2021" "
+ "StateRepository" "State Repository Service: Provides required infrastructure support for the application model." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\windows.staterepository.dll" "Thu Dec 16 07:52:36 2021" "
+ "StiSvc" "Windows Image Acquisition (WIA): Provides image acquisition services for scanners and cameras" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\wiaservc.dll" "Thu Dec 16 07:56:31 2021" "
+ "StorSvc" "Storage Service: Provides enabling services for storage settings and external storage expansion" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\storsvc.dll" "Thu Dec 16 07:56:31 2021" "
+ "svsvc" "Spot Verifier: Verifies potential file system corruptions." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\svsvc.dll" "Sat Jun 5 13:06:15 2021" "
+ "swprv" "Microsoft Software Shadow Copy Provider: Manages software-based volume shadow copies taken by the Volume Shadow Copy service. If this service is stopped, software-based volume shadow copies cannot be managed. If this service is disabled, any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\swprv.dll" "Thu Dec 16 07:53:11 2021" "
+ "SysMain" "SysMain: Maintains and improves system performance over time." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\sysmain.dll" "Thu Dec 16 07:56:56 2021" "
+ "SystemEventsBroker" "System Events Broker: Coordinates execution of background work for WinRT application. If this service is stopped or disabled, then background work might not be triggered." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\SystemEventsBrokerServer.dll" "Sat Jun 5 13:05:09 2021" "
+ "TabletInputService" "Touch Keyboard and Handwriting Panel Service: Enables Touch Keyboard and Handwriting Panel pen and ink functionality" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\TabSvc.dll" "Sat Jun 5 13:05:12 2021" "
+ "TapiSrv" "Telephony: Provides Telephony API (TAPI) support for programs that control telephony devices on the local computer and, through the LAN, on servers that are also running the service." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\tapisrv.dll" "Sat Jun 5 13:06:13 2021" "
+ "TermService" "Remote Desktop Services: Allows users to connect interactively to a remote computer. Remote Desktop and Remote Desktop Session Host Server depend on this service. To prevent remote use of this computer, clear the checkboxes on the Remote tab of the System properties control panel item." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\termsrv.dll" "Thu Dec 16 07:56:44 2021" "
+ "Themes" "Themes: Provides user experience theme management." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\themeservice.dll" "Sat Jun 5 13:05:14 2021" "
+ "TieringEngineService" "Storage Tiers Management: Optimizes the placement of data in storage tiers on all tiered storage spaces in the system." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\TieringEngineService.exe" "Sat Jun 5 13:06:13 2021" "
+ "TimeBrokerSvc" "Time Broker: Coordinates execution of background work for WinRT application. If this service is stopped or disabled, then background work might not be triggered." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\TimeBrokerServer.dll" "Sat Jun 5 13:05:09 2021" "
+ "TokenBroker" "Web Account Manager: This service is used by Web Account Manager to provide single-sign-on to apps and services." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\TokenBroker.dll" "Thu Dec 16 07:52:14 2021" "
+ "TrkWks" "Distributed Link Tracking Client: Maintains links between NTFS files within a computer or across computers in a network." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\trkwks.dll" "Sat Jun 5 13:05:23 2021" "
+ "TroubleshootingSvc" "Recommended Troubleshooting Service: Enables automatic mitigation for known problems by applying recommended troubleshooting. If stopped, your device will not get recommended troubleshooting for problems on your device." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\MitigationClient.dll" "Sat Jun 5 13:04:52 2021" "
+ "TrustedInstaller" "Windows Modules Installer: Enables installation, modification, and removal of Windows updates and optional components. If this service is disabled, install or uninstall of Windows updates might fail for this computer." "(Verified) Microsoft Windows" "C:\WINDOWS\servicing\TrustedInstaller.exe" "Thu Dec 16 07:55:09 2021" "
+ X "tzautoupdate" "Auto Time Zone Updater: Automatically sets the system time zone." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\tzautoupdate.dll" "Thu Dec 16 07:52:51 2021" "
+ "UdkUserSvc" "Udk User Service: Shell components service" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\windowsudkservices.shellcommon.dll" "Thu Dec 16 07:53:02 2021" "
+ "UdkUserSvc_6a9e6" "Udk User Service_6a9e6: Shell components service" "(Verified) Microsoft Windows Publisher" "C:\WINDOWS\system32\svchost.exe" "Sat Jun 5 13:05:23 2021" "
+ "UEIPSvc" "User Experience Improvement Program: UEIPSvc" "(Verified) Acer Incorporated" "C:\Program Files\Acer\User Experience Improvement Program Service\Framework\UBTService.exe" "Sun Aug 9 21:39:42 2020" "
+ X "uhssvc" "Microsoft Update Health Service: Maintains Update Health" "(Not Verified) Microsoft Corporation" "C:\Program Files\Microsoft Update Health Tools\uhssvc.exe" "Mon Oct 25 22:43:24 2021" "
+ "UmRdpService" "Remote Desktop Services UserMode Port Redirector: Allows the redirection of Printers/Drives/Ports for RDP connections" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\umrdp.dll" "Sat Jun 5 13:06:13 2021" "
+ "UnistoreSvc" "User Data Storage: Handles storage of structured user data, including contact info, calendars, messages and other content. If you stop or disable this service, apps that use this data might not work correctly." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\unistore.dll" "Sat Jun 5 13:05:09 2021" "
+ "UnistoreSvc_6a9e6" "User Data Storage_6a9e6: Handles storage of structured user data, including contact info, calendars, messages and other content. If you stop or disable this service, apps that use this data might not work correctly." "(Verified) Microsoft Windows Publisher" "C:\WINDOWS\System32\svchost.exe" "Sat Jun 5 13:05:23 2021" "
+ "upnphost" "UPnP Device Host: Allows UPnP devices to be hosted on this computer. If this service is stopped, any hosted UPnP devices will stop functioning and no additional hosted devices can be added. If this service is disabled, any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\upnphost.dll" "Sat Jun 5 13:06:00 2021" "
+ "UserDataSvc" "User Data Access: Provides apps with access to structured user data, including contact info, calendars, messages and other content. If you stop or disable this service, apps that use this data might not work correctly." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\userdataservice.dll" "Sat Jun 5 13:05:09 2021" "
+ "UserDataSvc_6a9e6" "User Data Access_6a9e6: Provides apps with access to structured user data, including contact info, calendars, messages and other content. If you stop or disable this service, apps that use this data might not work correctly." "(Verified) Microsoft Windows Publisher" "C:\WINDOWS\system32\svchost.exe" "Sat Jun 5 13:05:23 2021" "
+ "UserManager" "User Manager: User Manager provides the runtime components required for multi-user interaction. If this service is stopped, some applications may not operate correctly." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\usermgr.dll" "Thu Dec 16 07:53:54 2021" "
+ "UsoSvc" "Update Orchestrator Service: Manages Windows Updates. If stopped, your devices will not be able to download and install the latest updates." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\usosvc.dll" "Thu Dec 16 07:53:09 2021" "
+ "VacSvc" "Volumetric Audio Compositor Service: Hosts spatial analysis for Mixed Reality audio simulation." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\vac.dll" "Sat Jun 5 13:04:53 2021" "
+ "VaultSvc" "Credential Manager: Provides secure storage and retrieval of credentials to users, applications and security service packages." "(Verified) Microsoft Windows" "C:\Windows\System32\vaultsvc.dll" "Sat Jun 5 13:05:12 2021" "
+ "vds" "Virtual Disk: Provides management services for disks, volumes, file systems, and storage arrays." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\vds.exe" "Thu Dec 16 07:53:03 2021" "
+ "vmicguestinterface" "Hyper-V Guest Service Interface: Provides an interface for the Hyper-V host to interact with specific services running inside the virtual machine." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\icsvc.dll" "Sat Jun 5 13:06:16 2021" "
+ "vmicheartbeat" "Hyper-V Heartbeat Service: Monitors the state of this virtual machine by reporting a heartbeat at regular intervals. This service helps you identify running virtual machines that have stopped responding." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\icsvc.dll" "Sat Jun 5 13:06:16 2021" "
+ "vmickvpexchange" "Hyper-V Data Exchange Service: Provides a mechanism to exchange data between the virtual machine and the operating system running on the physical computer." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\icsvc.dll" "Sat Jun 5 13:06:16 2021" "
+ "vmicrdv" "Hyper-V Remote Desktop Virtualization Service: Provides a platform for communication between the virtual machine and the operating system running on the physical computer." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\icsvcext.dll" "Sat Jun 5 13:06:16 2021" "
+ "vmicshutdown" "Hyper-V Guest Shutdown Service: Provides a mechanism to shut down the operating system of this virtual machine from the management interfaces on the physical computer." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\icsvc.dll" "Sat Jun 5 13:06:16 2021" "
+ "vmictimesync" "Hyper-V Time Synchronization Service: Synchronizes the system time of this virtual machine with the system time of the physical computer." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\icsvc.dll" "Sat Jun 5 13:06:16 2021" "
+ "vmicvmsession" "Hyper-V PowerShell Direct Service: Provides a mechanism to manage virtual machine with PowerShell via VM session without a virtual network." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\icsvc.dll" "Sat Jun 5 13:06:16 2021" "
+ "vmicvss" "Hyper-V Volume Shadow Copy Requestor: Coordinates the communications that are required to use Volume Shadow Copy Service to back up applications and data on this virtual machine from the operating system on the physical computer." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\icsvcvss.dll" "Sat Jun 5 13:06:16 2021" "
+ "VSS" "Volume Shadow Copy: Manages and implements Volume Shadow Copies used for backup and other purposes. If this service is stopped, shadow copies will be unavailable for backup and the backup may fail. If this service is disabled, any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\vssvc.exe" "Thu Dec 16 07:53:11 2021" "
+ "W32Time" "Windows Time: Maintains date and time synchronization on all clients and servers in the network. If this service is stopped, date and time synchronization will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\w32time.dll" "Thu Dec 16 07:51:50 2021" "
+ "WaaSMedicSvc" "Windows Update Medic Service: Enables remediation and protection of Windows Update components." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\WaaSMedicSvc.dll" "Thu Dec 16 07:52:33 2021" "
+ "WalletService" "WalletService: Hosts objects used by clients of the wallet" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\WalletService.dll" "Thu Dec 16 08:01:10 2021" "
+ "WarpJITSvc" "Warp JIT Service: Enables JIT compilation support in d3d10warp.dll for processes in which code generation is disabled." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Windows.WARP.JITService.dll" "Sat Jun 5 13:05:06 2021" "
+ "wbengine" "Block Level Backup Engine Service: The WBENGINE service is used by Windows Backup to perform backup and recovery operations. If this service is stopped by a user, it may cause the currently running backup or recovery operation to fail. Disabling this service may disable backup and recovery operations using Windows Backup on this computer." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wbengine.exe" "Sat Jun 5 13:06:48 2021" "
+ "WbioSrvc" "Windows Biometric Service: The Windows biometric service gives client applications the ability to capture, compare, manipulate, and store biometric data without gaining direct access to any biometric hardware or samples. The service is hosted in a privileged SVCHOST process." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\wbiosrvc.dll" "Sat Jun 5 13:05:16 2021" "
+ "Wcmsvc" "Windows Connection Manager: Makes automatic connect/disconnect decisions based on the network connectivity options currently available to the PC and enables management of network connectivity based on Group Policy settings." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\wcmsvc.dll" "Thu Dec 16 07:51:50 2021" "
+ "wcncsvc" "Windows Connect Now - Config Registrar: WCNCSVC hosts the Windows Connect Now Configuration, which is Microsoft's Implementation of the Wireless Protected Setup (WPS) protocol. This is used to configure Wireless LAN settings for an Access Point (AP) or a Wireless Device. The service is started programmatically as needed." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\wcncsvc.dll" "Sat Jun 5 13:04:59 2021" "
+ "WdiServiceHost" "Diagnostic Service Host: The Diagnostic Service Host is used by the Diagnostic Policy Service to host diagnostics that need to run in a Local Service context. If this service is stopped, any diagnostics that depend on it will no longer function." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wdi.dll" "Sat Jun 5 13:05:29 2021" "
+ "WdiSystemHost" "Diagnostic System Host: The Diagnostic System Host is used by the Diagnostic Policy Service to host diagnostics that need to run in a Local System context. If this service is stopped, any diagnostics that depend on it will no longer function." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wdi.dll" "Sat Jun 5 13:05:29 2021" "
+ "WdNisSvc" "Microsoft Defender Antivirus Network Inspection Service: Helps guard against intrusion attempts targeting known and newly discovered vulnerabilities in network protocols" "(Verified) Microsoft Windows Publisher" "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2111.5-0\NisSrv.exe" "Thu Dec 16 00:20:53 2021" "
+ "WebClient" "WebClient: Enables Windows-based programs to create, access, and modify Internet-based files. If this service is stopped, these functions will not be available. If this service is disabled, any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\webclnt.dll" "Thu Dec 16 07:56:56 2021" "
+ "Wecsvc" "Windows Event Collector: This service manages persistent subscriptions to events from remote sources that support WS-Management protocol. This includes Windows Vista event logs, hardware and IPMI-enabled event sources. The service stores forwarded events in a local Event Log. If this service is stopped or disabled event subscriptions cannot be created and forwarded events cannot be accepted." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wecsvc.dll" "Sat Jun 5 13:06:05 2021" "
+ "WEPHOSTSVC" "Windows Encryption Provider Host Service: Windows Encryption Provider Host Service brokers encryption related functionalities from 3rd Party Encryption Providers to processes that need to evaluate and apply EAS policies. Stopping this will compromise EAS compliancy checks that have been established by the connected Mail Accounts" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wephostsvc.dll" "Sat Jun 5 13:06:05 2021" "
+ "wercplsupport" "Problem Reports Control Panel Support: This service provides support for viewing, sending and deletion of system-level problem reports for the Problem Reports control panel." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\wercplsupport.dll" "Sat Jun 5 13:06:05 2021" "
+ "WerSvc" "Windows Error Reporting Service: Allows errors to be reported when programs stop working or responding and allows existing solutions to be delivered. Also allows logs to be generated for diagnostic and repair services. If this service is stopped, error reporting might not work correctly and results of diagnostic services and repairs might not be displayed." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\WerSvc.dll" "Sat Jun 5 13:05:25 2021" "
+ "WFDSConMgrSvc" "Wi-Fi Direct Services Connection Manager Service: Manages connections to wireless services, including wireless display and docking." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\wfdsconmgrsvc.dll" "Sat Jun 5 13:05:00 2021" "
+ "WiaRpc" "Still Image Acquisition Events: Launches applications associated with still image acquisition events." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\wiarpc.dll" "Thu Dec 16 07:56:31 2021" "
+ "WinDefend" "Microsoft Defender Antivirus Service: Helps protect users from malware and other potentially unwanted software" "(Verified) Microsoft Windows Publisher" "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2111.5-0\MsMpEng.exe" "Thu Dec 16 00:20:53 2021" "
+ "WinHttpAutoProxySvc" "WinHTTP Web Proxy Auto-Discovery Service: WinHTTP implements the client HTTP stack and provides developers with a Win32 API and COM Automation component for sending HTTP requests and receiving responses. In addition, WinHTTP provides support for auto-discovering a proxy configuration via its implementation of the Web Proxy Auto-Discovery (WPAD) protocol." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\winhttp.dll" "Sat Jun 5 13:05:25 2021" "
+ "Winmgmt" "Windows Management Instrumentation: Provides a common interface and object model to access management information about operating system, devices, applications and services. If this service is stopped, most Windows-based software will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wbem\WMIsvc.dll" "Sat Jun 5 13:05:14 2021" "
+ "WinRM" "Windows Remote Management (WS-Management): Windows Remote Management (WinRM) service implements the WS-Management protocol for remote management. WS-Management is a standard web services protocol used for remote software and hardware management. The WinRM service listens on the network for WS-Management requests and processes them. The WinRM Service needs to be configured with a listener using winrm.cmd command line tool or through Group Policy in order for it to listen over the network. The WinRM service provides access to WMI data and enables event collection. Event collection and subscription to events require that the service is running. WinRM messages use HTTP and HTTPS as transports. The WinRM service does not depend on IIS but is preconfigured to share a port with IIS on the same machine. The WinRM service reserves the /wsman URL prefix. To prevent conflicts with IIS, administrators should ensure that any websites hosted on IIS do not use the /wsman URL prefix." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\WsmSvc.dll" "Thu Dec 16 07:53:04 2021" "
+ "wisvc" "Windows Insider Service: Provides infrastructure support for the Windows Insider Programme. This service must remain enabled for the Windows Insider Programme to work." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\flightsettings.dll" "Thu Dec 16 07:51:40 2021" "
+ "WlanSvc" "WLAN AutoConfig: The WLANSVC service provides the logic required to configure, discover, connect to and disconnect from a wireless local area network (WLAN) as defined by IEEE 802.11 standards. It also contains the logic to turn your computer into a software access point so that other devices or computers can connect to your computer wirelessly using a WLAN adapter that can support this. Stopping or disabling the WLANSVC service will make all WLAN adapters on your computer inaccessible from the Windows networking UI. It is strongly recommended that you have the WLANSVC service running if your computer has a WLAN adapter." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\wlansvc.dll" "Thu Dec 16 07:51:52 2021" "
+ "wlidsvc" "Microsoft Account Sign-in Assistant: Enables user sign-in through Microsoft account identity services. If this service is stopped, users will not be able to logon to the computer with their Microsoft account." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wlidsvc.dll" "Thu Dec 16 07:52:13 2021" "
+ "wlpasvc" "Local Profile Assistant Service: This service provides profile management for subscriber identity modules" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\lpasvc.dll" "Thu Dec 16 07:51:22 2021" "
+ "WManSvc" "Windows Management Service: Performs management including Provisioning and Enrollment activities" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\Windows.Management.Service.dll" "Sat Jun 5 13:04:52 2021" "
+ "wmiApSrv" "WMI Performance Adapter: Provides performance library information from Windows Management Instrumentation (WMI) providers to clients on the network. This service only runs when Performance Data Helper is activated." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wbem\WmiApSrv.exe" "Sat Jun 5 13:04:58 2021" "
+ "WMPNetworkSvc" "Windows Media Player Network Sharing Service: Shares Windows Media Player libraries with other networked players and media devices using Universal Plug and Play" "(Not Verified) Microsoft Corporation" "C:\Program Files\Windows Media Player\wmpnetwk.exe" "Sat Jun 5 02:32:00 2021" "
+ "workfolderssvc" "Work Folders: This service syncs files with the Work Folders server, enabling you to use the files on any of the PCs and devices on which you've set up Work Folders." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\workfolderssvc.dll" "Thu Dec 16 07:56:45 2021" "
+ "WpcMonSvc" "Parental Controls: Enforces parental controls for child accounts in Windows. If this service is stopped or disabled, parental controls may not be enforced." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\WpcDesktopMonSvc.dll" "Thu Dec 16 07:51:42 2021" "
+ "WPDBusEnum" "Portable Device Enumerator Service: Enforces group policy for removable mass-storage devices. Enables applications such as Windows Media Player and Image Import Wizard to transfer and synchronize content using removable mass-storage devices." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wpdbusenum.dll" "Sat Jun 5 18:17:02 2021" "
+ "WpnService" "Windows Push Notifications System Service: This service runs in session 0 and hosts the notification platform and connection provider which handles the connection between the device and WNS server." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\WpnService.dll" "Thu Dec 16 07:52:48 2021" "
+ "WpnUserService" "Windows Push Notifications User Service: This service hosts the Windows notification platform which provides support for local and push notifications. Supported notifications are tile, toast and raw." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\WpnUserService.dll" "Sat Jun 5 13:05:10 2021" "
+ "WpnUserService_6a9e6" "Windows Push Notifications User Service_6a9e6: This service hosts the Windows notification platform which provides support for local and push notifications. Supported notifications are tile, toast and raw." "(Verified) Microsoft Windows Publisher" "C:\WINDOWS\system32\svchost.exe" "Sat Jun 5 13:05:23 2021" "
+ "wscsvc" "Security Center: The WSCSVC (Windows Security Center) service monitors and reports security health settings on the computer. The health settings include firewall (on/off), antivirus (on/off/out of date), antispyware (on/off/out of date), Windows Update (automatically/manually download and install updates), User Account Control (on/off), and Internet settings (recommended/not recommended). The service provides COM APIs for independent software vendors to register and record the state of their products to the Security Center service. The Security and Maintenance UI uses the service to provide systray alerts and a graphical view of the security health states in the Security and Maintenance control panel. Network Access Protection (NAP) uses the service to report the security health states of clients to the NAP Network Policy Server to make network quarantine decisions. The service also has a public API that allows external consumers to programmatically retrieve the aggregated security health state of the system." "(Verified) Microsoft Windows Publisher" "C:\WINDOWS\System32\wscsvc.dll" "Sat Jun 5 13:04:58 2021" "
+ "WSearch" "Windows Search: Provides content indexing, property caching, and search results for files, e-mail, and other content." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\SearchIndexer.exe" "Thu Dec 16 07:52:24 2021" "
+ "wuauserv" "Windows Update: Enables the detection, download and installation of updates for Windows and other programs. If this service is disabled, users of this computer will not be able to use Windows Update or its automatic updating feature, and programs will not be able to use the Windows Update Agent (WUA) API." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wuaueng.dll" "Thu Dec 16 07:53:10 2021" "
+ "WwanSvc" "WWAN AutoConfig: This service manages mobile broadband (GSM & CDMA) data card/embedded module adapters and connections by auto-configuring the networks. It is strongly recommended that this service be kept running for best user experience of mobile broadband devices." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\wwansvc.dll" "Thu Dec 16 07:51:22 2021" "
+ "XblAuthManager" "Xbox Live Auth Manager: Provides authentication and authorisation services for interacting with Xbox Live. If this service is stopped, some applications may not operate correctly." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\XblAuthManager.dll" "Sat Jun 5 13:04:52 2021" "
+ "XblGameSave" "Xbox Live Game Save: This service syncs save data for Xbox Live save enabled games. If this service is stopped, game save data will not upload to or download from Xbox Live." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\XblGameSave.dll" "Sat Jun 5 13:04:52 2021" "
+ "XboxGipSvc" "Xbox Accessory Management Service: This service manages connected Xbox Accessories." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\XboxGipSvc.dll" "Sat Jun 5 13:04:52 2021" "
+ "XboxNetApiSvc" "Xbox Live Networking Service: This service supports the Windows.Networking.XboxLive application programming interface." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\XboxNetApiSvc.dll" "Sat Jun 5 13:06:00 2021" "
[Drivers]
[HKLM\System\CurrentControlSet\Services]
+ "1394ohci" "1394 OHCI Compliant Host Controller: 1394 OpenHCI Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\1394ohci.sys" "Sat Jun 5 13:04:44 2021" "
+ "3ware" "3ware: LSI 3ware SCSI Storport Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\3ware.sys" "Sat Jun 5 13:04:44 2021" "
+ "ACPI" "Microsoft ACPI Driver: ACPI Driver for NT" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\ACPI.sys" "Thu Dec 16 07:50:55 2021" "
+ "AcpiDev" "ACPI Devices driver: ACPI Devices Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\AcpiDev.sys" "Sat Jun 5 13:04:44 2021" "
+ "acpiex" "Microsoft ACPIEx Driver: ACPIEx Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Drivers\acpiex.sys" "Sat Jun 5 13:04:57 2021" "
+ "acpipagr" "ACPI Processor Aggregator Driver: ACPI Processor Aggregator Device Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\acpipagr.sys" "Sat Jun 5 13:04:45 2021" "
+ "AcpiPmi" "ACPI Power Meter Driver: ACPI Power Metering Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\acpipmi.sys" "Sat Jun 5 13:04:44 2021" "
+ "acpitime" "ACPI Wake Alarm Driver: ACPI Wake Alarm" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\acpitime.sys" "Sat Jun 5 13:04:45 2021" "
+ "Acx01000" "Acx01000: Audio KMDF Class Extension" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\Acx01000.sys" "Sat Jun 5 13:04:57 2021" "
+ "ADP80XX" "ADP80XX: PMC-Sierra Storport Driver For SPC8x6G SAS/SATA controller" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\ADP80XX.SYS" "Sat Jun 5 13:04:44 2021" "
+ "AFD" "Ancillary Function Driver for Winsock: Ancillary Function Driver for Winsock" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\afd.sys" "Thu Dec 16 07:53:51 2021" "
+ "afunix" "afunix: AF_UNIX socket provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\afunix.sys" "Thu Dec 16 07:54:51 2021" "
+ "ahcache" "Application Compatibility Cache: Cache Compatibility Data and Attributes for Individual PE File" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\DRIVERS\ahcache.sys" "Sat Jun 5 13:05:33 2021" "
+ "amdgpio2" "AMD GPIO Client Driver: AMD GPIO Controller Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\amdgpio2.sys" "Sat Jun 5 13:04:42 2021" "
+ "amdi2c" "AMD I2C Controller Service: AMD I2C Controller Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\amdi2c.sys" "Sat Jun 5 13:04:42 2021" "
+ "AmdK8" "AMD K8 Processor Driver: Processor Device Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\amdk8.sys" "Sat Jun 5 13:04:44 2021" "
+ "AmdPPM" "AMD Processor Driver: Processor Device Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\amdppm.sys" "Sat Jun 5 13:04:44 2021" "
+ "amdsata" "amdsata: AHCI 1.3 Device Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\amdsata.sys" "Sat Jun 5 13:04:44 2021" "
+ "amdsbs" "amdsbs: AMD Technology AHCI Compatible Controller Driver for Windows - AMD64 platform" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\amdsbs.sys" "Sat Jun 5 13:04:44 2021" "
+ "amdxata" "amdxata: Storage Filter Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\amdxata.sys" "Sat Jun 5 13:04:44 2021" "
+ "AppID" "AppID Driver: Identifies an application and enforces software restriction policies." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\appid.sys" "Thu Dec 16 07:53:35 2021" "
+ "AppleSSD" "Apple Solid State Drive Device: Apple Solid State Drive Device" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\AppleSSD.sys" "Sat Jun 5 13:04:42 2021" "
+ "applockerfltr" "Smartlocker Filter Driver: Identifies files created by authorized installers." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\applockerfltr.sys" "Sat Jun 5 13:05:21 2021" "
+ "arcsas" "Adaptec SAS/SATA-II RAID Storport's Miniport Driver: Adaptec SAS RAID WS03 Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\arcsas.sys" "Sat Jun 5 13:04:44 2021" "
+ "AsyncMac" "RAS Asynchronous Media Driver: RAS Asynchronous Media Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\asyncmac.sys" "Sat Jun 5 13:05:40 2021" "
+ "atapi" "IDE Channel: ATAPI IDE Miniport Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\atapi.sys" "Thu Dec 16 07:50:56 2021" "
+ "b06bdrv" "QLogic Network Adapter VBD: QLogic Gigabit Ethernet VBD" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\bxvbda.sys" "Sat Jun 5 13:04:44 2021" "
+ "bam" "Background Activity Moderator Driver: Controls activity of background applications" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\bam.sys" "Sat Jun 5 13:05:27 2021" "
+ "BasicDisplay" "BasicDisplay: Microsoft Basic Display Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DriverStore\FileRepository\basicdisplay.inf_amd64_a3f9d7c24b3377b3\BasicDisplay.sys" "Sat Jun 5 13:04:45 2021" "
+ "BasicRender" "BasicRender: Microsoft Basic Render Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DriverStore\FileRepository\basicrender.inf_amd64_e1a5502a3a50be4e\BasicRender.sys" "Sat Jun 5 13:04:45 2021" "
+ "bcmfn2" "bcmfn2 Service: BCM Function 2 Device Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\bcmfn2.sys" "Sat Jun 5 13:04:42 2021" "
+ "Beep" "Beep: BEEP Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Drivers\Beep.sys" "Sat Jun 5 13:05:34 2021" "
+ "bindflt" "Windows Bind Filter Driver: Binds filesystem namespaces to different locations and hides this remapping from the user" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\bindflt.sys" "Thu Dec 16 07:52:56 2021" "
+ "bowser" "Browser: NT Lan Manager Datagram Receiver Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\DRIVERS\bowser.sys" "Thu Dec 16 07:51:46 2021" "
+ "BtFilter" "BtFilter: BT Filter" "(Verified) Qualcomm Atheros, Inc." "C:\WINDOWS\System32\drivers\btfilter.sys" "Mon Jul 19 21:46:02 2021" "
+ "BthA2dp" "Microsoft Bluetooth A2dp driver: Bluetooth A2DP Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\BthA2dp.sys" "Thu Dec 16 07:50:51 2021" "
+ "BthEnum" "Bluetooth Enumerator Service: Bluetooth Bus Extender" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\BthEnum.sys" "Thu Dec 16 07:50:57 2021" "
+ "BthHFEnum" "Microsoft Bluetooth Hands-Free Profile driver: Bluetooth Hands-Free Audio and Call Control HID Enumerator" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\bthhfenum.sys" "Thu Dec 16 07:50:51 2021" "
+ "BthLEEnum" "Bluetooth Low Energy Driver: Legacy Bluetooth LE Bus Enumerator" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\Microsoft.Bluetooth.Legacy.LEEnumerator.sys" "Sat Jun 5 13:04:46 2021" "
+ "BthMini" "Bluetooth Radio Driver: Bluetooth Transport Extensibility Miniport Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\BTHMINI.sys" "Thu Dec 16 07:50:57 2021" "
+ "BTHMODEM" "Bluetooth Modem Communications Driver: Bluetooth Communications Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\bthmodem.sys" "Sat Jun 5 13:04:43 2021" "
+ "BthPan" "Bluetooth Device (Personal Area Network): Bluetooth Device (Personal Area Network)" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\bthpan.sys" "Sat Jun 5 13:04:46 2021" "
+ "BTHPORT" "Bluetooth Port Driver: Bluetooth Bus Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\BTHport.sys" "Thu Dec 16 07:50:57 2021" "
+ "BTHUSB" "Bluetooth Radio USB Driver: Bluetooth Miniport Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\BTHUSB.sys" "Thu Dec 16 07:50:57 2021" "
+ "bttflt" "Microsoft Hyper-V VHDPMEM BTT Filter: VHD BTT Filter Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\bttflt.sys" "Sat Jun 5 13:04:45 2021" "
+ "buttonconverter" "Service for Portable Device Control devices: Button Converter Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\buttonconverter.sys" "Sat Jun 5 13:04:46 2021" "
+ "CAD" "Charge Arbitration Driver: Charge Arbiration Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\CAD.sys" "Sat Jun 5 13:04:42 2021" "
+ X "cdfs" "CD/DVD File System Reader: ISO9660/Joliet File System Reader for CD/DVDs. (Core) (All pieces)" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\DRIVERS\cdfs.sys" "Sat Jun 5 13:06:02 2021" "
+ "cdrom" "CD-ROM Driver: SCSI CD-ROM Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\cdrom.sys" "Sat Jun 5 13:04:44 2021" "
+ "cht4iscsi" "cht4iscsi: Chelsio iSCSI VMiniport Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\cht4sx64.sys" "Sat Jun 5 13:04:45 2021" "
+ "cht4vbd" "Chelsio Virtual Bus Driver: Virtual Bus Driver for Chelsio ® T5/T6 Chipset" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\cht4vx64.sys" "Sat Jun 5 13:04:45 2021" "
+ "CimFS" "CimFS: CimFS driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Drivers\CimFS.sys" "Thu Dec 16 07:52:56 2021" "
+ "circlass" "Consumer IR Devices: Consumer IR Class Driver for eHome" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\circlass.sys" "Sat Jun 5 13:04:42 2021" "
+ "CldFlt" "Windows Cloud Files Filter Driver: Cloud Files Mini Filter Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\cldflt.sys" "Thu Dec 16 07:53:39 2021" "
+ "CLFS" "Common Log (CLFS): General-purpose logging service" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\CLFS.sys" "Thu Dec 16 07:53:53 2021" "
+ "CmBatt" "Microsoft ACPI Control Method Battery Driver: Control Method Battery Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\CmBatt.sys" "Sat Jun 5 13:04:45 2021" "
+ "CNG" "CNG: Kernel Cryptography, Next Generation" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Drivers\cng.sys" "Thu Dec 16 07:53:45 2021" "
+ X "cnghwassist" "CNG Hardware Assist algorithm provider: CNG Hardware Assist algorithm provider" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DRIVERS\cnghwassist.sys" "Sat Jun 5 13:05:16 2021" "
+ "CompositeBus" "Composite Bus Enumerator Driver: Multi-Transport Composite Bus Enumerator" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DriverStore\FileRepository\compositebus.inf_amd64_ab6e2caeac172387\CompositeBus.sys" "Sat Jun 5 13:04:42 2021" "
+ "condrv" "Console Driver: Console Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\condrv.sys" "Thu Dec 16 07:52:57 2021" "
+ "cpuz150" "cpuz150: CPUID Driver" "(Verified) CPUID S.A.R.L.U." "C:\WINDOWS\temp\cpuz150\cpuz150_x64.sys" "Fri Dec 17 16:06:02 2021" "
+ "dam" "Desktop Activity Moderator Driver: Controls activity of desktop applications" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\dam.sys" "Thu Dec 16 07:54:08 2021" "
+ "Dfsc" "DFS Namespace Client Driver: Client driver for access to DFS Namespaces" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Drivers\dfsc.sys" "Sat Jun 5 13:05:27 2021" "
+ "dg_ssudbus" "SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.): SAMSUNG USB Composite Device Driver" "(Verified) Samsung Electronics Co., Ltd." "C:\WINDOWS\System32\drivers\ssudbus2.sys" "Tue Jun 29 05:43:52 2021" "
+ "disk" "Disk Driver: PnP Disk Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\disk.sys" "Sat Jun 5 13:04:44 2021" "
+ "dmvsc" "dmvsc: Dynamic Memory" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\dmvsc.sys" "Sat Jun 5 13:04:47 2021" "
+ "drmkaud" "Microsoft Trusted Audio Drivers: Microsoft Trusted Audio Drivers" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\drmkaud.sys" "Thu Dec 16 07:50:52 2021" "
+ "DXGKrnl" "LDDM Graphics Subsystem: Controls the underlying video driver stacks to provide fully-featured display capabilities." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\dxgkrnl.sys" "Thu Dec 16 07:52:52 2021" "
+ "ebdrv" "QLogic 10 Gigabit Ethernet Adapter VBD: QLogic 10 GigE VBD" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\evbda.sys" "Sat Jun 5 13:04:44 2021" "
+ "ebdrv0" "QLogic Legacy Ethernet Adapter VBD: QLogic 10 GigE VBD" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\evbd0a.sys" "Sat Jun 5 13:04:44 2021" "
+ "EhStorClass" "Enhanced Storage Filter Driver: Enhanced Storage Filter Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\EhStorClass.sys" "Sat Jun 5 13:06:05 2021" "
+ "EhStorTcgDrv" "Microsoft driver for storage devices supporting IEEE 1667 and TCG protocols: Microsoft driver for storage devices supporting IEEE 1667 and TCG protocols" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\EhStorTcgDrv.sys" "Sat Jun 5 13:04:42 2021" "
+ "ErrDev" "Microsoft Hardware Error Device Driver: Error Device Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\errdev.sys" "Sat Jun 5 13:04:45 2021" "
+ "ExecutionContext" "CPU Scheduler for High Performance I/O: CPU Scheduler for High Performance I/O" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Drivers\ExecutionContext.sys" "Sat Jun 5 13:05:25 2021" "
+ "exfat" "exFAT File System Driver: exFAT File System Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Drivers\exfat.sys" "Thu Dec 16 07:51:23 2021" "
+ "fastfat" "FAT12/16/32 File System Driver: Note - dependance on CDROM.SYS only if required to read/write DVD-RAM media (which appears as CD class device). (Core) (All pieces)" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Drivers\fastfat.sys" "Thu Dec 16 07:51:23 2021" "
+ "fdc" "Floppy Disk Controller Driver: Floppy Disk Controller Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\fdc.sys" "Sat Jun 5 13:04:45 2021" "
+ "FileCrypt" "FileCrypt: Windows sandboxing and encryption filter." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\filecrypt.sys" "Sat Jun 5 13:04:57 2021" "
+ "FileInfo" "File Information FS MiniFilter: Collects information about files in memory to be consumed by other system services." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\fileinfo.sys" "Sat Jun 5 13:05:23 2021" "
+ "Filetrace" "Filetrace: ETW File Trace Filter" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\filetrace.sys" "Sat Jun 5 13:05:23 2021" "
+ "flpydisk" "Floppy Disk Driver: Floppy Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\flpydisk.sys" "Sat Jun 5 13:04:45 2021" "
+ "FltMgr" "FltMgr: File System Filter Manager Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\fltmgr.sys" "Sat Jun 5 13:05:25 2021" "
+ "FsDepends" "File System Dependency Minifilter: This minifilter tracks the dependencies associated with the various nested volumes/filesystems" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\FsDepends.sys" "Sat Jun 5 13:04:57 2021" "
+ "fvevol" "BitLocker Drive Encryption Filter Driver: BitLocker Drive Encryption Filter Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DRIVERS\fvevol.sys" "Thu Dec 16 08:01:18 2021" "
+ "gencounter" "Microsoft Hyper-V Generation Counter: Virtual Machine Generation Counter" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\vmgencounter.sys" "Sat Jun 5 13:04:47 2021" "
+ "genericusbfn" "Generic USB Function Class: Generic USB Function Class Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DriverStore\FileRepository\genericusbfn.inf_amd64_dc3260bbd08046c4\genericusbfn.sys" "Sat Jun 5 13:04:46 2021" "
+ "GPIOClx0101" "Microsoft GPIO Class Extension Driver: GPIO Class Extension Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Drivers\msgpioclx.sys" "Sat Jun 5 13:05:12 2021" "
+ "GpuEnergyDrv" "GPU Energy Driver: Computes energy consumed by GPU" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\gpuenergydrv.sys" "Sat Jun 5 13:04:52 2021" "
+ "HdAudAddService" "Microsoft 1.1 UAA Function Driver for High Definition Audio Service: High Definition Audio Function Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\HdAudio.sys" "Sat Jun 5 13:04:43 2021" "
+ "HDAudBus" "Microsoft UAA Bus Driver for High Definition Audio: High Definition Audio Bus Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\HDAudBus.sys" "Sat Jun 5 13:04:43 2021" "
+ "HidBatt" "HID UPS Battery Driver: Hid Battery Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\HidBatt.sys" "Sat Jun 5 13:04:45 2021" "
+ "HidBth" "Microsoft Bluetooth HID Miniport: Bluetooth Miniport Driver for HID Devices" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\hidbth.sys" "Sat Jun 5 13:04:46 2021" "
+ "hidi2c" "Microsoft I2C HID Miniport Driver: I2C HID Miniport Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\hidi2c.sys" "Sat Jun 5 13:04:46 2021" "
+ "hidinterrupt" "Common Driver for HID Buttons implemented with interrupts: HID Button over Interrupt Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\hidinterrupt.sys" "Sat Jun 5 13:04:46 2021" "
+ "HidIr" "Microsoft Infrared HID Driver: Infrared Miniport Driver for Input Devices" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\hidir.sys" "Sat Jun 5 13:04:43 2021" "
+ "hidspi" "Microsoft SPI HID Miniport Driver: SPI HID Miniport Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\hidspi.sys" "Sat Jun 5 13:04:46 2021" "
+ "HidSpiCx" "HidSpi KMDF Class Extension: HidSpi KMDF Class Extension" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\HidSpiCx.sys" "Sat Jun 5 13:05:16 2021" "
+ "HidUsb" "Microsoft HID Class Driver: USB Miniport Driver for Input Devices" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\hidusb.sys" "Sat Jun 5 13:04:46 2021" "
+ "HpSAMD" "HpSAMD: Smart Array SAS/SATA Controller Media Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\HpSAMD.sys" "Sat Jun 5 13:04:45 2021" "
+ "Hsp" "Microsoft Pluton Service: HSP Device Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\Hsp.sys" "Thu Dec 16 07:50:57 2021" "
+ "HTTP" "HTTP Service: HTTP Service" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\HTTP.sys" "Thu Dec 16 07:53:45 2021" "
+ X "hvcrash" "hvcrash: Hyper-V Crashdump" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\hvcrash.sys" "Sat Jun 5 13:04:47 2021" "
+ "hvservice" "Microsoft Hypervisor Service Driver: Hypervisor Boot Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\hvservice.sys" "Thu Dec 16 07:51:02 2021" "
+ "HwNClx0101" "Microsoft Hardware Notifications Class Extension Driver: Hardware Notification Class Extension Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Drivers\mshwnclx.sys" "Sat Jun 5 13:05:16 2021" "
+ "hwpolicy" "Hardware Policy Driver: Contains Processor and other policies" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\hwpolicy.sys" "Sat Jun 5 13:05:25 2021" "
+ "hyperkbd" "hyperkbd: Microsoft VMBus Synthetic Keyboard Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\hyperkbd.sys" "Sat Jun 5 13:04:47 2021" "
+ "HyperVideo" "HyperVideo: Microsoft VMBus Video Device Miniport Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\HyperVideo.sys" "Sat Jun 5 13:04:47 2021" "
+ "i8042prt" "i8042 Keyboard and PS/2 Mouse Port Driver: i8042 Port Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\i8042prt.sys" "Sat Jun 5 13:04:46 2021" "
+ "iagpio" "Intel Serial IO GPIO Controller Driver: Intel(R) Serial IO GPIO Controller Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\iagpio.sys" "Sat Jun 5 13:04:42 2021" "
+ "iai2c" "Intel(R) Serial IO I2C Host Controller: Intel(R) Serial IO I2C Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\iai2c.sys" "Sat Jun 5 13:04:42 2021" "
+ "iaLPSS2i_GPIO2" "Intel(R) Serial IO GPIO Driver v2: Intel(R) Serial IO GPIO Driver v2" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2.sys" "Sat Jun 5 13:04:42 2021" "
+ "iaLPSS2i_GPIO2_BXT_P" "Intel(R) Serial IO GPIO Driver v2: Intel(R) Serial IO GPIO Driver v2" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2_BXT_P.sys" "Sat Jun 5 13:04:42 2021" "
+ "iaLPSS2i_GPIO2_CNL" "Intel(R) Serial IO GPIO Driver v2: Intel(R) Serial IO GPIO Driver v2" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2_CNL.sys" "Sat Jun 5 13:04:42 2021" "
+ "iaLPSS2i_GPIO2_GLK" "Intel(R) Serial IO GPIO Driver v2: Intel(R) Serial IO GPIO Driver v2" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2_GLK.sys" "Sat Jun 5 13:04:42 2021" "
+ "iaLPSS2i_I2C" "Intel(R) Serial IO I2C Driver v2: Intel(R) Serial IO I2C Driver v2" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\iaLPSS2i_I2C.sys" "Sat Jun 5 13:04:42 2021" "
+ "iaLPSS2i_I2C_BXT_P" "Intel(R) Serial IO I2C Driver v2: Intel(R) Serial IO I2C Driver v2" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\iaLPSS2i_I2C_BXT_P.sys" "Sat Jun 5 13:04:42 2021" "
+ "iaLPSS2i_I2C_CNL" "Intel(R) Serial IO I2C Driver v2: Intel(R) Serial IO I2C Driver v2" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\iaLPSS2i_I2C_CNL.sys" "Sat Jun 5 13:04:42 2021" "
+ "iaLPSS2i_I2C_GLK" "Intel(R) Serial IO I2C Driver v2: Intel(R) Serial IO I2C Driver v2" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\iaLPSS2i_I2C_GLK.sys" "Sat Jun 5 13:04:42 2021" "
+ "iaLPSS2_GPIO2_TGL" "Intel(R) Serial IO GPIO Driver v2: Intel(R) Serial IO GPIO Driver v2" "(Verified) Intel Corporation" "C:\WINDOWS\System32\DriverStore\FileRepository\ialpss2_gpio2_tgl.inf_amd64_c330c09d72f3e083\iaLPSS2_GPIO2_TGL.sys" "Sun Oct 10 17:41:10 2021" "
+ "iaLPSSi_GPIO" "Intel(R) Serial IO GPIO Controller Driver: Intel(R) Serial IO GPIO Controller Driver" "(Verified) Intel Corporation - Client Components Group" "C:\WINDOWS\System32\drivers\iaLPSSi_GPIO.sys" "Sat Jun 5 13:04:44 2021" "
+ "iaLPSSi_I2C" "Intel(R) Serial IO I2C Controller Driver: Intel(R) Serial IO I2C Controller Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\iaLPSSi_I2C.sys" "Sat Jun 5 13:04:43 2021" "
+ "iaStorAC" "Intel(R) Chipset SATA/PCIe RST Premium Controller: Intel(R) Rapid Storage Technology driver - x64" "(Verified) Intel(R) Rapid Storage Technology" "C:\WINDOWS\System32\drivers\iaStorAC.sys" "Sun Oct 10 17:41:43 2021" "
+ "iaStorAfs" "iaStorAfs: Identifies frequently used files for acceleration with Intel(R) Optane(TM) memory" "(Verified) Intel(R) Rapid Storage Technology" "C:\WINDOWS\System32\drivers\iaStorAfs.sys" "Sun Oct 10 17:41:43 2021" "
+ "iaStorAVC" "Intel Chipset SATA RAID Controller: Intel(R) Rapid Storage Technology driver (inbox) - x64" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\iaStorAVC.sys" "Sat Jun 5 13:04:45 2021" "
+ "iaStorV" "Intel RAID Controller Windows 7: Intel Matrix Storage Manager driver - x64" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\iaStorV.sys" "Sat Jun 5 13:04:45 2021" "
+ "ibbus" "Mellanox InfiniBand Bus/AL (Filter Driver): InfiniBand Fabric Bus Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\ibbus.sys" "Sat Jun 5 13:04:45 2021" "
+ "igfx" "igfx: Intel Graphics Kernel Mode Driver" "(Verified) Intel(R) pGFX 2020" "C:\WINDOWS\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_e36b8067470714bb\igdkmd64.sys" "Mon Jan 18 03:52:22 2021" "
+ "IndirectKmd" "Indirect Displays Kernel-Mode Driver: Kernel mode driver that implements the Indirect Displays framework." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\IndirectKmd.sys" "Sat Jun 5 13:05:16 2021" "
+ "IntcAzAudAddService" "Service for Realtek HD Audio (WDM): Realtek(r) High Definition Audio Function Driver" "(Verified) Realtek Semiconductor Corp." "C:\WINDOWS\system32\drivers\RTKVHD64.sys" "Mon May 17 19:23:48 2021" "
+ "IntcDAud" "Intel(R) Display Audio: Intel(R) Display Audio Driver" "(Verified) Intel Corporation" "C:\WINDOWS\System32\DriverStore\FileRepository\intcdaud.inf_amd64_0d1975b386430ef8\IntcDAud.sys" "Sun Oct 10 17:41:56 2021" "
+ "intelide" "intelide: Intel PCI IDE Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\intelide.sys" "Thu Dec 16 07:50:56 2021" "
+ "intelpep" "Intel(R) Power Engine Plug-in Driver: Intel Power Engine Plugin" "(Verified) Microsoft Windows Hardware Abstraction Layer Publisher" "C:\WINDOWS\System32\drivers\intelpep.sys" "Thu Dec 16 07:50:57 2021" "
+ "intelpmax" "Intel(R) Dynamic Device Peak Power Manager Driver: Intel Power Limit Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\intelpmax.sys" "Sat Jun 5 13:04:42 2021" "
+ "IntelPMT" "Intel(R) Platform Monitoring Technology Service: Intel Platform Monitoring Driver" "(Verified) Microsoft Windows Hardware Abstraction Layer Publisher" "C:\WINDOWS\System32\drivers\IntelPMT.sys" "Sat Jun 5 13:04:46 2021" "
+ "intelppm" "Intel Processor Driver: Processor Device Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\intelppm.sys" "Sat Jun 5 13:04:44 2021" "
+ "iorate" "Disk I/O Rate Filter Driver: Provides rate control for disk I/O traffic." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\iorate.sys" "Thu Dec 16 07:51:18 2021" "
+ "IpFilterDriver" "IP Traffic Filter Driver: IP Traffic Filter Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys" "Sat Jun 5 13:05:40 2021" "
+ "IPMIDRV" "IPMIDRV: WMI IPMI DRIVER" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\IPMIDrv.sys" "Sat Jun 5 13:04:45 2021" "
+ "IPNAT" "IP Network Address Translator: IP Network Address Translator" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\ipnat.sys" "Sat Jun 5 13:05:12 2021" "
+ "IPT" "IPT: IPT Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\ipt.sys" "Sat Jun 5 13:04:54 2021" "
+ "isapnp" "isapnp: PNP ISA Bus Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\isapnp.sys" "Sat Jun 5 13:04:45 2021" "
+ "iScsiPrt" "iScsiPort Driver: Microsoft iSCSI Initiator Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\msiscsi.sys" "Sat Jun 5 13:04:45 2021" "
+ "ItSas35i" "ItSas35i: Avago SAS Gen3.5 Driver (StorPort)" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\ItSas35i.sys" "Sat Jun 5 13:04:45 2021" "
+ "kbdclass" "Keyboard Class Driver: Keyboard Class Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\kbdclass.sys" "Sat Jun 5 13:04:46 2021" "
+ "kbdhid" "Keyboard HID Driver: HID Keyboard Filter Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\kbdhid.sys" "Sat Jun 5 13:04:46 2021" "
+ "kdnic" "Microsoft Kernel Debug Network Miniport (NDIS 6.20): Microsoft Kernel Debugger Network Miniport" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\kdnic.sys" "Sat Jun 5 13:04:46 2021" "
+ "KSecDD" "KSecDD: Kernel Security Support Provider Interface" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Drivers\ksecdd.sys" "Thu Dec 16 07:53:50 2021" "
+ "KSecPkg" "KSecPkg: Kernel Security Support Provider Interface Packages" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Drivers\ksecpkg.sys" "Thu Dec 16 07:53:45 2021" "
+ "ksthunk" "Kernel Streaming Thunks: Kernel Streaming WOW Thunk Service" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\ksthunk.sys" "Sat Jun 5 13:05:31 2021" "
+ "LHidFilt" "Logicool SetPoint KMDF HID Filter Driver: Logitech HID Filter Driver." "(Verified) Logitech Inc" "C:\WINDOWS\system32\DRIVERS\LHidFilt.Sys" "Sun Oct 25 08:32:28 2020" "
+ "lltdio" "Link-Layer Topology Discovery Mapper I/O Driver: Link-Layer Topology Discovery Mapper I/O Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\lltdio.sys" "Sat Jun 5 13:05:29 2021" "
+ "LMouFilt" "Logicool SetPoint KMDF Mouse Filter Driver: Logitech Mouse Filter Driver." "(Verified) Logitech Inc" "C:\WINDOWS\system32\DRIVERS\LMouFilt.Sys" "Sun Oct 25 08:32:30 2020" "
+ "LSI_SAS" "LSI_SAS: LSI Fusion-MPT SAS Driver (StorPort)" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\lsi_sas.sys" "Sat Jun 5 13:04:45 2021" "
+ "LSI_SAS2i" "LSI_SAS2i: LSI SAS Gen2 Driver (StorPort)" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\lsi_sas2i.sys" "Sat Jun 5 13:04:45 2021" "
+ "LSI_SAS3i" "LSI_SAS3i: Avago SAS Gen3 Driver (StorPort)" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\lsi_sas3i.sys" "Sat Jun 5 13:04:45 2021" "
+ "luafv" "UAC File Virtualization: Virtualizes file write failures to per-user locations." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\luafv.sys" "Sat Jun 5 13:05:33 2021" "
+ "mausbhost" "MA-USB Host Controller Driver: MA-USB Host Controller Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\mausbhost.sys" "Sat Jun 5 13:04:45 2021" "
+ "mausbip" "MA-USB IP Filter Driver: MA-USB IP Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\mausbip.sys" "Sat Jun 5 13:04:45 2021" "
+ "MbbCx" "MBB Network Adapter Class Extension: Windows Mobile Broadband Class Extension" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\MbbCx.sys" "Sat Jun 5 13:04:50 2021" "
+ "megasas2i" "megasas2i: MEGASAS2i RAID Controller Driver for Windows" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\MegaSas2i.sys" "Sat Jun 5 13:04:45 2021" "
+ "megasas35i" "megasas35i: MEGASAS RAID Controller Driver for Windows" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\megasas35i.sys" "Sat Jun 5 13:04:45 2021" "
+ "megasr" "megasr: LSI MegaRAID Software RAID Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\megasr.sys" "Sat Jun 5 13:04:45 2021" "
+ "MEIx64" "Intel(R) Management Engine Interface : Intel(R) Management Engine Interface" "(Verified) Intel(R) Embedded Subsystems and IP Blocks Group" "C:\WINDOWS\System32\DriverStore\FileRepository\heci.inf_amd64_605dda426937489f\x64\TeeDriverW10x64.sys" "Sun Oct 10 17:41:23 2021" "
+ "Microsoft_Bluetooth_AvrcpTransport" "Microsoft Bluetooth Avrcp Transport Driver: Microsoft Bluetooth Avrcp Transport Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\Microsoft.Bluetooth.AvrcpTransport.sys" "Sat Jun 5 13:04:42 2021" "
+ "mlx4_bus" "Mellanox ConnectX Bus Enumerator: MLX4 Bus Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\mlx4_bus.sys" "Sat Jun 5 13:04:45 2021" "
+ "MMCSS" "Multimedia Class Scheduler: Enables relative prioritization of work based on system-wide task priorities. This is intended mainly for multimedia applications. If this service is stopped, individual tasks resort to their default priority." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\mmcss.sys" "Sat Jun 5 13:04:54 2021" "
+ "Modem" "Modem: Modem Device Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\modem.sys" "Sat Jun 5 13:06:15 2021" "
+ "monitor" "Microsoft Monitor Class Function Driver Service: Monitor Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\monitor.sys" "Sat Jun 5 13:04:44 2021" "
+ "mouclass" "Mouse Class Driver: Mouse Class Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\mouclass.sys" "Sat Jun 5 13:04:46 2021" "
+ "mouhid" "Mouse HID Driver: HID Mouse Filter Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\mouhid.sys" "Sat Jun 5 13:04:46 2021" "
+ "mountmgr" "Mount Point Manager: Driver responsible with maintaining persistent drive letters and names for volumes" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\mountmgr.sys" "Sat Jun 5 13:05:25 2021" "
+ "mpi3drvi" "mpi3drvi: Broadcom MPI 3.0 Driver (StorPort)" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\mpi3drvi.sys" "Sat Jun 5 13:04:45 2021" "
+ "mpsdrv" "Windows Defender Firewall Authorization Driver: Windows Defender Firewall Authorization Driver is a kernel mode driver that provides deep inspection services on inbound and outbound network traffic." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\mpsdrv.sys" "Sat Jun 5 13:05:09 2021" "
+ "MRxDAV" "WebDav Client Redirector Driver: Network Redirector that provides WebDAV file access for the WebClient service" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\mrxdav.sys" "Thu Dec 16 07:56:56 2021" "
+ "mrxsmb" "SMB MiniRedirector Wrapper and Engine: Implements the framework for the SMB filesystem redirector" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\DRIVERS\mrxsmb.sys" "Thu Dec 16 07:53:54 2021" "
+ "mrxsmb20" "SMB 2.0 MiniRedirector: Implements the SMB 2.0 protocol, which provides connectivity to network resources on Windows Vista and later servers" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\DRIVERS\mrxsmb20.sys" "Thu Dec 16 07:53:54 2021" "
+ "MsBridge" "Microsoft MAC Bridge: Microsoft MAC Bridge" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\bridge.sys" "Sat Jun 5 13:06:05 2021" "
+ "Msfs" "Msfs: Mailslot driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Drivers\Msfs.sys" "Sat Jun 5 13:05:25 2021" "
+ "msgpiowin32" "Common Driver for Buttons, DockMode and Laptop/Slate Indicator: GPIO Button Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\msgpiowin32.sys" "Sat Jun 5 13:04:46 2021" "
+ "mshidkmdf" "Pass-through HID to KMDF Filter Driver: Device Filter to provide pass-through interface between HIDCLASS and KMDF" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\mshidkmdf.sys" "Sat Jun 5 13:05:16 2021" "
+ "mshidumdf" "Pass-through HID to UMDF Driver: Device Driver to provide pass-through interface between HIDCLASS and UMDF" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\mshidumdf.sys" "Sat Jun 5 13:05:14 2021" "
+ "msisadrv" "msisadrv: ISA Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\msisadrv.sys" "Sat Jun 5 13:04:45 2021" "
+ "MSKSSRV" "Microsoft Streaming Service Proxy: MS KS Server" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\MSKSSRV.sys" "Sat Jun 5 13:05:31 2021" "
+ "MsLldp" "Microsoft Link-Layer Discovery Protocol: Microsoft Link-Layer Discovery Protocol Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\mslldp.sys" "Sat Jun 5 13:05:39 2021" "
+ "MSPCLOCK" "Microsoft Streaming Clock Proxy: MS Proxy Clock" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\MSPCLOCK.sys" "Sat Jun 5 13:05:31 2021" "
+ "MSPQM" "Microsoft Streaming Quality Manager Proxy: MS Proxy Quality Manager" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\MSPQM.sys" "Sat Jun 5 13:05:31 2021" "
+ "MsQuic" "MsQuic: Microsoft® QUIC Library" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\msquic.sys" "Thu Dec 16 07:53:42 2021" "
+ "MsRPC" "MsRPC: Kernel Remote Procedure Call Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Drivers\MsRPC.sys" "Thu Dec 16 07:53:50 2021" "
+ "mssmbios" "Microsoft System Management BIOS Driver: System Management BIOS Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\mssmbios.sys" "Sat Jun 5 13:04:45 2021" "
+ "MSTEE" "Microsoft Streaming Tee/Sink-to-Sink Converter: WDM Tee/Communication Transform Filter " "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\MSTEE.sys" "Sat Jun 5 13:05:31 2021" "
+ "MTConfig" "Microsoft Input Configuration Driver: Microsoft Multi-Touch HID Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\MTConfig.sys" "Sat Jun 5 13:04:44 2021" "
+ "Mup" "Mup: Multiple UNC Provider Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Drivers\mup.sys" "Sat Jun 5 13:05:27 2021" "
+ "mvumis" "mvumis: Marvell Flash Controller Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\mvumis.sys" "Sat Jun 5 13:04:45 2021" "
+ "NativeWifiP" "NativeWiFi Filter: NativeWiFi Miniport Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\DRIVERS\nwifi.sys" "Thu Dec 16 07:51:52 2021" "
+ "ndfltr" "NetworkDirect Service: NetworkDirect Support Filter Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\ndfltr.sys" "Sat Jun 5 13:04:45 2021" "
+ "NDIS" "NDIS System Driver: NDIS System Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\ndis.sys" "Thu Dec 16 07:53:50 2021" "
+ "NdisCap" "Microsoft NDIS Capture: Microsoft NDIS Capture" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\ndiscap.sys" "Sat Jun 5 13:06:13 2021" "
+ "NdisImPlatform" "Microsoft Network Adapter Multiplexor Protocol: Microsoft Network Adapter Multiplexor Protocol" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\NdisImPlatform.sys" "Sat Jun 5 13:05:39 2021" "
+ "NdisTapi" "Remote Access NDIS TAPI Driver: Remote Access NDIS TAPI Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DRIVERS\ndistapi.sys" "Sat Jun 5 13:05:40 2021" "
+ "Ndisuio" "NDIS Usermode I/O Protocol: NDIS User mode I/O driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\ndisuio.sys" "Sat Jun 5 13:05:25 2021" "
+ "NdisVirtualBus" "Microsoft Virtual Network Adapter Enumerator: Microsoft Virtual Network Adapter Enumerator" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\NdisVirtualBus.sys" "Sat Jun 5 13:05:39 2021" "
+ "NdisWan" "Remote Access NDIS WAN Driver: Remote Access NDIS WAN Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\ndiswan.sys" "Thu Dec 16 07:54:56 2021" "
+ "ndiswanlegacy" "Remote Access LEGACY NDIS WAN Driver: Remote Access LEGACY NDIS WAN Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DRIVERS\ndiswan.sys" "Thu Dec 16 07:54:56 2021" "
+ "NDKPerf" "NDKPerf Driver: " "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\NDKPerf.sys" "Sat Jun 5 13:06:13 2021" "
+ "NDKPing" "NDKPing Driver: RDMA Sample Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\NDKPing.sys" "Sat Jun 5 13:06:13 2021" "
+ "ndproxy" "NDIS Proxy Driver: NDIS Proxy Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DRIVERS\NDProxy.sys" "Sat Jun 5 13:05:40 2021" "
+ "Ndu" "Windows Network Data Usage Monitoring Driver: This service provides network data usage monitoring functionality" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\Ndu.sys" "Sat Jun 5 13:06:00 2021" "
+ "NetAdapterCx" "Network Adapter Wdf Class Extension Library: Network Adapter Class Extension for WDF" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\NetAdapterCx.sys" "Thu Dec 16 07:53:51 2021" "
+ "NetBIOS" "NetBIOS Interface: NetBIOS Interface" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\netbios.sys" "Sat Jun 5 13:05:37 2021" "
+ "NetBT" "NetBT: This service implements NetBios over TCP/IP." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DRIVERS\netbt.sys" "Sat Jun 5 13:05:39 2021" "
+ "netvsc" "netvsc: Virtual NDIS Miniport" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\netvsc.sys" "Thu Dec 16 07:51:04 2021" "
+ "Npfs" "Npfs: NPFS Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Drivers\Npfs.sys" "Sat Jun 5 13:05:25 2021" "
+ "npsvctrig" "Named pipe service trigger provider: Named pipe service triggers" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\npsvctrig.sys" "Sat Jun 5 13:04:46 2021" "
+ "nsiproxy" "NSI Proxy Service Driver: NSI Proxy Service" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\nsiproxy.sys" "Sat Jun 5 13:05:25 2021" "
+ "nsvst_NGC" "NortonLifeLock Split Tunneling WFP Callout driver: " "" "File not found: C:\WINDOWS\System32\drivers\NGCx64\16150A0.028\nsvst.sys" "Thu Dec 16 09:32:35 2021" "
+ "Ntfs" "Ntfs: NT File System Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Drivers\Ntfs.sys" "Thu Dec 16 07:53:48 2021" "
+ "Null" "Null: NULL Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Drivers\Null.sys" "Sat Jun 5 13:05:25 2021" "
+ "nvdimm" "Microsoft NVDIMM device driver: NVDIMM device driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\nvdimm.sys" "Sat Jun 5 13:04:45 2021" "
+ "nvmedisk" "Microsoft NVMe disk driver: Nvme Disk Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\nvmedisk.sys" "Sat Jun 5 13:04:44 2021" "
+ "nvraid" "nvraid: NVIDIA® nForce(TM) RAID Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\nvraid.sys" "Sat Jun 5 13:04:45 2021" "
+ "nvstor" "nvstor: NVIDIA® nForce(TM) Sata Performance Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\nvstor.sys" "Sat Jun 5 13:04:45 2021" "
+ "P9Rdr" "Plan 9 Redirector Driver: Plan 9 Redirector Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\p9rdr.sys" "Sat Jun 5 13:06:17 2021" "
+ "Parport" "Parallel port driver: Parallel Port Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\parport.sys" "Sat Jun 5 13:04:45 2021" "
+ "partmgr" "Partition driver: Disk class filter driver that manages and auctions out partitions to volume managers." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\partmgr.sys" "Thu Dec 16 07:53:49 2021" "
+ "pci" "PCI Bus Driver: NT Plug and Play PCI Enumerator" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\pci.sys" "Thu Dec 16 07:50:56 2021" "
+ "pciide" "pciide: Generic PCI IDE Bus Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\pciide.sys" "Thu Dec 16 07:50:56 2021" "
+ "pcmcia" "pcmcia: PCMCIA Bus Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\pcmcia.sys" "Sat Jun 5 13:04:42 2021" "
+ "pcw" "Performance Counters for Windows Driver: Performance Counters for Windows Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\pcw.sys" "Sat Jun 5 13:05:25 2021" "
+ "pdc" "pdc: Power Dependency Coordinator Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\pdc.sys" "Sat Jun 5 13:04:57 2021" "
+ "PEAUTH" "PEAUTH: Protected Environment Authentication and Authorization Export Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\peauth.sys" "Thu Dec 16 07:51:39 2021" "
+ "percsas2i" "percsas2i: MEGASAS RAID Controller Driver for Windows" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\percsas2i.sys" "Sat Jun 5 13:04:45 2021" "
+ "percsas3i" "percsas3i: MEGASAS RAID Controller Driver for Windows" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\percsas3i.sys" "Sat Jun 5 13:04:45 2021" "
+ "PktMon" "Packet Monitor Driver: Packet Monitor Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\PktMon.sys" "Thu Dec 16 07:56:43 2021" "
+ "pmem" "Microsoft persistent memory disk driver: Persistent memory driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\pmem.sys" "Sat Jun 5 13:04:45 2021" "
+ "PNPMEM" "Microsoft Memory Module Driver: Plug and Play Memory Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\pnpmem.sys" "Sat Jun 5 13:04:44 2021" "
+ "portcfg" "portcfg: Port Device Class Configuration Filter Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\portcfg.sys" "Sat Jun 5 13:05:16 2021" "
+ "PptpMiniport" "WAN Miniport (PPTP): WAN Miniport (PPTP)" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\raspptp.sys" "Sat Jun 5 13:05:40 2021" "
+ "PRM" "Microsoft PRM Driver: Windows PRM Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DriverStore\FileRepository\prm.inf_amd64_7fc9bb8ba2b73803\PRM.sys" "Sat Jun 5 13:04:44 2021" "
+ "Processor" "Processor Driver: Processor Device Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\processr.sys" "Sat Jun 5 13:04:44 2021" "
+ "Psched" "QoS Packet Scheduler: QoS Packet Scheduler" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\pacer.sys" "Sat Jun 5 13:05:09 2021" "
+ "Qcamain10x64" "Qualcomm Atheros Extensible Wireless LAN 11AC device driver: Qualcomm Atheros Extensible Wireless LAN device driver" "(Verified) Qualcomm Atheros, Inc." "C:\WINDOWS\System32\drivers\Qcamain10x64.sys" "Sun Jul 18 20:19:10 2021" "
+ "QWAVEdrv" "QWAVE driver: Quality Windows Audio/Video Experience component driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\qwavedrv.sys" "Sat Jun 5 13:05:39 2021" "
+ "Ramdisk" "Windows RAM Disk Driver: RAM Disk Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\DRIVERS\ramdisk.sys" "Sat Jun 5 13:04:57 2021" "
+ "RasAcd" "Remote Access Auto Connection Driver: Remote Access Auto Connection Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DRIVERS\rasacd.sys" "Sat Jun 5 13:05:40 2021" "
+ "RasAgileVpn" "WAN Miniport (IKEv2): WAN Miniport (IKEv2)" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\AgileVpn.sys" "Thu Dec 16 07:54:56 2021" "
+ "Rasl2tp" "WAN Miniport (L2TP): WAN Miniport (L2TP)" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\rasl2tp.sys" "Sat Jun 5 13:05:40 2021" "
+ "RasPppoe" "Remote Access PPPOE Driver: Remote Access PPPOE Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DRIVERS\raspppoe.sys" "Sat Jun 5 13:05:40 2021" "
+ "RasSstp" "WAN Miniport (SSTP): WAN Miniport (SSTP)" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\rassstp.sys" "Sat Jun 5 13:05:40 2021" "
+ "rdbss" "Redirected Buffering Sub System: Provides the framework for network mini-redirectors" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\DRIVERS\rdbss.sys" "Thu Dec 16 07:53:53 2021" "
+ "rdpbus" "Remote Desktop Device Redirector Bus Driver: Microsoft RDP Bus Device driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\rdpbus.sys" "Sat Jun 5 13:04:47 2021" "
+ "RDPDR" "Remote Desktop Device Redirector Driver: Remote Desktop Device Redirector Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\rdpdr.sys" "Sat Jun 5 13:06:13 2021" "
+ "RdpVideoMiniport" "Remote Desktop Video Miniport Driver: Microsoft RDP Video Miniport driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\rdpvideominiport.sys" "Thu Dec 16 07:56:41 2021" "
+ "rdyboost" "ReadyBoost: ReadyBoost" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\rdyboost.sys" "Sat Jun 5 13:06:16 2021" "
+ "ReFS" "ReFS: NT ReFS FS Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Drivers\ReFS.sys" "Thu Dec 16 07:53:37 2021" "
+ "ReFSv1" "ReFSv1: NT ReFS FS Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Drivers\ReFSv1.sys" "Sat Jun 5 13:05:23 2021" "
+ "RFCOMM" "Bluetooth Device (RFCOMM Protocol TDI): Bluetooth Device (RFCOMM Protocol TDI)" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\rfcomm.sys" "Sat Jun 5 13:04:46 2021" "
+ "rhproxy" "Resource Hub proxy driver: ResourceHub Proxy Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\rhproxy.sys" "Sat Jun 5 13:04:44 2021" "
+ "rspndr" "Link-Layer Topology Discovery Responder: Link-Layer Topology Discovery Responder" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\rspndr.sys" "Sat Jun 5 13:05:29 2021" "
+ "rt640x64" "Realtek RT640 NT Driver: Realtek 8125/8136/8168/8169 NDIS 6.40 64-bit Driver " "(Verified) Microsoft Windows Hardware Compatibility Publisher" "C:\WINDOWS\System32\drivers\rt640x64.sys" "Wed Aug 18 05:58:04 2021" "
+ "s3cap" "s3cap: Microsoft S3 Emulated Device Cap Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\vms3cap.sys" "Sat Jun 5 13:04:47 2021" "
+ "sbp2port" "SBP-2 Transport/Protocol Bus Driver: SBP-2 Protocol Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\sbp2port.sys" "Thu Dec 16 07:50:55 2021" "
+ "scfilter" "Smart card PnP Class Filter Driver: Smart card reader filter driver enabling smart card PnP." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DRIVERS\scfilter.sys" "Sat Jun 5 13:05:34 2021" "
+ "scmbus" "Microsoft Storage Class Memory Bus Driver: Storage Class Memory Bus Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\scmbus.sys" "Thu Dec 16 07:50:56 2021" "
+ "sdbus" "sdbus: SecureDigital Bus Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\sdbus.sys" "Sat Jun 5 13:04:46 2021" "
+ "SDFRd" "SDF Reflector: SDF Reflector" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\SDFRd.sys" "Sat Jun 5 13:04:44 2021" "
+ "sdstor" "SD Storage Port Driver: SD Storage Class Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\sdstor.sys" "Thu Dec 16 07:51:00 2021" "
+ "SerCx" "Serial UART Support Library: Serial Class Extension" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\SerCx.sys" "Sat Jun 5 13:05:16 2021" "
+ "SerCx2" "Serial UART Support Library: Serial Class Extension V2" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\SerCx2.sys" "Sat Jun 5 13:05:16 2021" "
+ "Serenum" "Serenum Filter Driver: Serial Port Enumerator" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\serenum.sys" "Sat Jun 5 13:04:45 2021" "
+ "Serial" "Serial port driver: Serial Device Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\serial.sys" "Sat Jun 5 13:04:45 2021" "
+ "sermouse" "Serial Mouse Driver: Serial Mouse Filter Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\sermouse.sys" "Sat Jun 5 13:04:46 2021" "
+ "sfloppy" "High-Capacity Floppy Disk Drive: SCSI Floppy Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\sfloppy.sys" "Sat Jun 5 13:04:45 2021" "
+ "SgrmAgent" "System Guard Runtime Monitor Agent: System Guard Runtime Monitor Agent Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\SgrmAgent.sys" "Sat Jun 5 13:06:00 2021" "
+ "SiSRaid2" "SiSRaid2: SiS RAID Stor Miniport Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\SiSRaid2.sys" "Sat Jun 5 13:04:45 2021" "
+ "SiSRaid4" "SiSRaid4: SiS AHCI Stor-Miniport Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\sisraid4.sys" "Sat Jun 5 13:04:45 2021" "
+ "SmartSAMD" "SmartSAMD: Storport Miniport Driver for SmartRAID/SmartHBA Controllers" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\SmartSAMD.sys" "Sat Jun 5 13:04:45 2021" "
+ "spaceparser" "spaceparser: Storage Spaces Parser driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\spaceparser.sys" "Sat Jun 5 13:06:02 2021" "
+ "spaceport" "Storage Spaces Driver: Storage Spaces Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\spaceport.sys" "Thu Dec 16 07:50:55 2021" "
+ "SpatialGraphFilter" "Holographic Spatial Graph Filter: Holographic Spatial Graph Filter" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\SpatialGraphFilter.sys" "Sat Jun 5 18:17:02 2021" "
+ "SpbCx" "Simple Peripheral Bus Support Library: SPB Class Extension" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\SpbCx.sys" "Sat Jun 5 13:05:16 2021" "
+ "srv2" "Server SMB 2.xxx Driver: Enables connectivity from Windows Vista and later clients" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DRIVERS\srv2.sys" "Thu Dec 16 07:53:54 2021" "
+ "srvnet" "srvnet: Server Network driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DRIVERS\srvnet.sys" "Thu Dec 16 07:53:54 2021" "
+ "ssudqcfilter" "SAMSUNG Mobile USB QCRMNET Filter Driver: Filter Driver for the Qualcomm USB Driver Stack" "(Verified) Samsung Electronics Co., Ltd." "C:\WINDOWS\System32\drivers\ssudqcfilter.sys" "Tue Jun 29 05:44:08 2021" "
+ "stexstor" "stexstor: Promise SuperTrak EX Series Driver for Windows x64" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\stexstor.sys" "Sat Jun 5 13:04:45 2021" "
+ "storahci" "Microsoft Standard SATA AHCI Driver: MS AHCI Storport Miniport Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\storahci.sys" "Thu Dec 16 07:50:56 2021" "
+ "storflt" "Microsoft Hyper-V Storage Accelerator: Virtual Storage Filter Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\vmstorfl.sys" "Sat Jun 5 13:04:47 2021" "
+ "stornvme" "Microsoft Standard NVM Express Driver: Microsoft NVM Express Storport Miniport Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\stornvme.sys" "Thu Dec 16 07:50:57 2021" "
+ "storqosflt" "Storage QoS Filter Driver: Provides Quality of Service for storage I/O traffic." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\storqosflt.sys" "Sat Jun 5 13:05:16 2021" "
+ "storufs" "Microsoft Universal Flash Storage (UFS) Driver: MS UFS Storport Miniport Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\storufs.sys" "Thu Dec 16 07:50:57 2021" "
+ "storvsc" "storvsc: Storage VSC Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\storvsc.sys" "Sat Jun 5 13:04:47 2021" "
+ "swenum" "Software Bus Driver: Plug and Play Software Device Enumerator" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DriverStore\FileRepository\swenum.inf_amd64_3bf6c0d173eb26c6\swenum.sys" "Sat Jun 5 13:04:44 2021" "
+ "SymEvnt" "Symantec Eventing Platform: " "" "File not found: C:\Program Files\Norton Security\NortonData\22.20.5.40\SymPlatform\SymEvnt.sys" "Thu Dec 16 09:32:35 2021" "
+ "Tcpip" "TCP/IP Protocol Driver: TCP/IP Protocol Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\tcpip.sys" "Thu Dec 16 07:53:51 2021" "
+ "Tcpip6" "@todo.dll,-100;Microsoft IPv6 Protocol Driver: @todo.dll,-100;Microsoft IPv6 Protocol Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\tcpip.sys" "Thu Dec 16 07:53:51 2021" "
+ "tcpipreg" "@%SystemRoot%\System32\drivers\tcpipreg.sys,-10110,: TCP/IP Registry Compatibility Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\tcpipreg.sys" "Thu Dec 16 07:53:51 2021" "
+ "tdx" "NetIO Legacy TDI Support Driver: NetIO Legacy TDI Support Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\DRIVERS\tdx.sys" "Thu Dec 16 07:56:20 2021" "
+ "terminpt" "Microsoft Remote Desktop Input Driver: Terminal Server Input Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\terminpt.sys" "Sat Jun 5 13:04:47 2021" "
+ "TPM" "TPM: TPM Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\tpm.sys" "Thu Dec 16 07:51:00 2021" "
+ "TsUsbFlt" "Remote Desktop USB Hub Class Filter Driver: Remote Desktop USB Hub Class Filter Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\tsusbflt.sys" "Sat Jun 5 13:04:57 2021" "
+ "TsUsbGD" "Remote Desktop Generic USB Device: Remote Desktop Generic USB Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\TsUsbGD.sys" "Sat Jun 5 13:04:46 2021" "
+ "tunnel" "Microsoft Tunnel Miniport Adapter Driver: Microsoft Tunnel Interface Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\tunnel.sys" "Sat Jun 5 13:05:37 2021" "
+ "UASPStor" "USB Attached SCSI (UAS) Driver: Microsoft Uasp Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\uaspstor.sys" "Sat Jun 5 13:04:45 2021" "
+ "UcmCx0101" "USB Connector Manager KMDF Class Extension: USB Connector Manager KMDF Class Extension" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Drivers\UcmCx.sys" "Sat Jun 5 13:05:16 2021" "
+ "UcmTcpciCx0101" "UCM-TCPCI KMDF Class Extension: UCM-TCPCI KMDF Class Extension" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Drivers\UcmTcpciCx.sys" "Sat Jun 5 13:05:16 2021" "
+ "UcmUcsiAcpiClient" "UCM-UCSI ACPI Client: UCM-UCSI ACPI Client Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\UcmUcsiAcpiClient.sys" "Sat Jun 5 13:04:46 2021" "
+ "UcmUcsiCx0101" "UCM-UCSI KMDF Class Extension: UCM-UCSI KMDF Class Extension" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Drivers\UcmUcsiCx.sys" "Sat Jun 5 13:05:16 2021" "
+ "Ucx01000" "USB Host Support Library: USB Controller Extension" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\ucx01000.sys" "Sat Jun 5 13:04:57 2021" "
+ "UdeCx" "USB Device Emulation Support Library: "udecx.DRIVER"" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\udecx.sys" "Sat Jun 5 13:04:57 2021" "
+ X "udfs" "udfs: Reads/Writes UDF 1.02,1.5,2.0x,2.5 disc formats, usually found on C/DVD discs. (Core) (All pieces)" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\DRIVERS\udfs.sys" "Sat Jun 5 13:06:14 2021" "
+ "UEFI" "Microsoft UEFI Driver: UEFI Driver for NT" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DriverStore\FileRepository\uefi.inf_amd64_fb341504564fabc5\UEFI.sys" "Sat Jun 5 13:04:44 2021" "
+ "Ufx01000" "USB Function Class Extension: USB Function Driver Class Extension" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\ufx01000.sys" "Sat Jun 5 13:05:16 2021" "
+ "UfxChipidea" "USB Chipidea Controller: UFX Chipidea Client Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DriverStore\FileRepository\ufxchipidea.inf_amd64_a517b810ee0e44a2\UfxChipidea.sys" "Sat Jun 5 13:04:46 2021" "
+ "ufxsynopsys" "USB Synopsys Controller: UFX Synopsys Client Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\ufxsynopsys.sys" "Sat Jun 5 13:04:46 2021" "
+ "umbus" "UMBus Enumerator Driver: User-Mode Bus Enumerator" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DriverStore\FileRepository\umbus.inf_amd64_0a89aff902a5c3a9\umbus.sys" "Sat Jun 5 13:04:45 2021" "
+ "UmPass" "Microsoft UMPass Driver: Generic pass-through driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\umpass.sys" "Sat Jun 5 13:04:46 2021" "
+ "UrsChipidea" "Chipidea USB Role-Switch Driver: USB Role-Switch Driver for Chipidea Core" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DriverStore\FileRepository\urschipidea.inf_amd64_4bd4df2779fd9e16\urschipidea.sys" "Sat Jun 5 13:04:46 2021" "
+ "UrsCx01000" "USB Role-Switch Support Library: USB Role-Switch Class Extension" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\urscx01000.sys" "Sat Jun 5 13:05:16 2021" "
+ "UrsSynopsys" "Synopsys USB Role-Switch Driver: USB Role-Switch Driver for Synopsys Core" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DriverStore\FileRepository\urssynopsys.inf_amd64_28522251903b4825\urssynopsys.sys" "Sat Jun 5 13:04:46 2021" "
+ "Usb4DeviceRouter" "USB4 Device Router Service: USB4(TM) Device Router Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DriverStore\FileRepository\usb4devicerouter.inf_amd64_8d9a17bd8e5b4b11\Usb4DeviceRouter.sys" "Thu Dec 16 07:50:57 2021" "
+ "Usb4HostRouter" "USB4 Host Router Service: USB4(TM) Host Router Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DriverStore\FileRepository\usb4hostrouter.inf_amd64_acb1b78bb0ae3528\Usb4HostRouter.sys" "Thu Dec 16 07:50:58 2021" "
+ "usbaudio" "USB Audio Driver (WDM): USB Audio Class Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\usbaudio.sys" "Sat Jun 5 13:04:43 2021" "
+ "usbaudio2" "USB Audio 2.0 Service: Microsoft USB Audio Class 2.0 Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\usbaudio2.sys" "Sat Jun 5 13:04:43 2021" "
+ "usbccgp" "Microsoft USB Generic Parent Driver: USB Common Class Generic Parent Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\usbccgp.sys" "Sat Jun 5 13:04:46 2021" "
+ "usbcir" "eHome Infrared Receiver (USBCIR): USB Consumer IR Driver for eHome" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\usbcir.sys" "Sat Jun 5 13:04:43 2021" "
+ "usbehci" "Microsoft USB 2.0 Enhanced Host Controller Miniport Driver: EHCI eUSB Miniport Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\usbehci.sys" "Sat Jun 5 13:04:46 2021" "
+ "usbhub" "Microsoft USB Standard Hub Driver: Default Hub Driver for USB" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\usbhub.sys" "Sat Jun 5 13:04:46 2021" "
+ "USBHUB3" "SuperSpeed Hub: USB3 HUB Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\UsbHub3.sys" "Thu Dec 16 07:51:00 2021" "
+ "usbohci" "Microsoft USB Open Host Controller Miniport Driver: OHCI USB Miniport Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\usbohci.sys" "Sat Jun 5 13:04:46 2021" "
+ "usbprint" "Microsoft USB PRINTER Class: USB Printer driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\usbprint.sys" "Thu Dec 16 07:50:55 2021" "
+ "usbser" "Microsoft USB Serial Driver: USB Serial Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\usbser.sys" "Sat Jun 5 13:04:45 2021" "
+ "USBSTOR" "USB Mass Storage Driver: USB Mass Storage Class Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\USBSTOR.SYS" "Thu Dec 16 07:51:00 2021" "
+ "usbuhci" "Microsoft USB Universal Host Controller Miniport Driver: UHCI USB Miniport Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\usbuhci.sys" "Sat Jun 5 13:04:46 2021" "
+ "usbvideo" "USB Video Device (WDM): USB Video Class Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Drivers\usbvideo.sys" "Thu Dec 16 07:50:55 2021" "
+ "USBXHCI" "USB xHCI Compliant Host Controller: USB XHCI Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\USBXHCI.SYS" "Thu Dec 16 07:51:00 2021" "
+ "vdrvroot" "Microsoft Virtual Drive Enumerator: Virtual Drive Root Enumerator" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\vdrvroot.sys" "Sat Jun 5 13:04:45 2021" "
+ "VerifierExt" "Driver Verifier Extension: Driver Verifier component to help find bugs in device drivers." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\VerifierExt.sys" "Thu Dec 16 07:53:47 2021" "
+ "vhdmp" "vhdmp: VHD Miniport Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\vhdmp.sys" "Sat Jun 5 13:04:45 2021" "
+ "vhf" "Virtual HID Framework (VHF) Driver: Kernel mode driver that implements the Virtual HID Framework (VHF)" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\vhf.sys" "Sat Jun 5 13:04:45 2021" "
+ "Vid" "Vid: Microsoft Hyper-V Virtualization Infrastructure Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\Vid.sys" "Thu Dec 16 07:51:02 2021" "
+ "VirtualRender" "VirtualRender: Microsoft Virtual Render Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DriverStore\FileRepository\vrd.inf_amd64_346f3764318c1681\vrd.sys" "Sat Jun 5 13:04:47 2021" "
+ "vmbus" "Virtual Machine Bus: Microsoft Hyper-V Virtual Machine Bus Child Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\vmbus.sys" "Thu Dec 16 07:51:03 2021" "
+ "VMBusHID" "VMBusHID: Microsoft VMBus HID Miniport" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\VMBusHID.sys" "Sat Jun 5 13:04:47 2021" "
+ "vmgid" "Microsoft Hyper-V Guest Infrastructure Driver: Virtual Machine Guest Infrastructure Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\vmgid.sys" "Sat Jun 5 13:04:47 2021" "
+ "volmgr" "Volume Manager Driver: Volume Manager Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\volmgr.sys" "Thu Dec 16 07:50:56 2021" "
+ "volmgrx" "Dynamic Volume Manager: Extension of the volume manager driver that manages software RAID volumes (spanned, striped, mirrored, RAID-5) on dynamic disks" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\volmgrx.sys" "Sat Jun 5 13:06:02 2021" "
+ "volsnap" "Volume Shadow Copy driver: Volume class filter driver that takes and manages snapshots." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\volsnap.sys" "Sat Jun 5 13:05:14 2021" "
+ "volume" "Volume driver: Volume driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\volume.sys" "Sat Jun 5 13:04:44 2021" "
+ "vpci" "Microsoft Hyper-V Virtual PCI Bus: Virtual PCI Bus" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\vpci.sys" "Sat Jun 5 13:04:47 2021" "
+ "vsmraid" "vsmraid: VIA RAID DRIVER FOR AMD-X86-64" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\vsmraid.sys" "Sat Jun 5 13:04:45 2021" "
+ "VSTXRAID" "VIA StorX Storage RAID Controller Windows Driver: VIA StorX RAID Controller Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\vstxraid.sys" "Sat Jun 5 13:04:45 2021" "
+ "vwifibus" "Virtual Wireless Bus Driver: Implements bus functionality for Virtual Wireless" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\vwifibus.sys" "Sat Jun 5 13:05:00 2021" "
+ "vwififlt" "Virtual WiFi Filter Driver: Virtual WiFi Filter Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\vwififlt.sys" "Sat Jun 5 13:05:00 2021" "
+ "vwifimp" "Virtual WiFi Miniport Service: Virtual WiFi Miniport Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\vwifimp.sys" "Sat Jun 5 13:05:00 2021" "
+ "WacomPen" "Wacom Serial Pen HID Driver: Wacom Serial Pen Tablet HID Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\wacompen.sys" "Sat Jun 5 13:04:44 2021" "
+ "wanarp" "Remote Access IP ARP Driver: Remote Access IP ARP Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DRIVERS\wanarp.sys" "Sat Jun 5 13:05:40 2021" "
+ "wanarpv6" "Remote Access IPv6 ARP Driver: Remote Access IPv6 ARP Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DRIVERS\wanarp.sys" "Sat Jun 5 13:05:40 2021" "
+ "wcifs" "Windows Container Isolation: Provides a virtual filesystem view for processes running within Windows Containers" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\wcifs.sys" "Thu Dec 16 07:52:57 2021" "
+ "WdBoot" "Microsoft Defender Antivirus Boot Driver: Microsoft Defender Antivirus Boot Driver" "(Verified) Microsoft Windows Early Launch Anti-malware Publisher" "C:\WINDOWS\system32\drivers\wd\WdBoot.sys" "Thu Dec 16 00:21:01 2021" "
+ "Wdf01000" "Kernel Mode Driver Frameworks service: Kernel Mode Driver Framework Runtime" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\Wdf01000.sys" "Sat Jun 5 13:05:25 2021" "
+ "WdFilter" "Microsoft Defender Antivirus Mini-Filter Driver: Microsoft Defender Antivirus On-Access Malware Protection Mini-Filter Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\wd\WdFilter.sys" "Thu Dec 16 00:21:02 2021" "
+ "wdiwifi" "WDI Driver Framework: WDI Driver Framework Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\DRIVERS\wdiwifi.sys" "Thu Dec 16 07:51:52 2021" "
+ "WdmCompanionFilter" "WdmCompanionFilter: WDM Companion Filter" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\WdmCompanionFilter.sys" "Sat Jun 5 13:05:19 2021" "
+ "WdNisDrv" "Microsoft Defender Antivirus Network Inspection System Driver: Helps guard against intrusion attempts targeting known and newly discovered vulnerabilities in network protocols" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\wd\WdNisDrv.sys" "Thu Dec 16 00:21:02 2021" "
+ "WFPLWFS" "Microsoft Windows Filtering Platform: Microsoft Windows Filtering Platform" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\wfplwfs.sys" "Thu Dec 16 07:52:48 2021" "
+ "WifiCx" "Wifi Network Adapter Class Extension: Windows Wifi Class Extension" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\WifiCx.sys" "Thu Dec 16 07:51:53 2021" "
+ "WIMMount" "WIMMount: WIM Image mount service driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\wimmount.sys" "Thu Dec 16 07:53:40 2021" "
+ "WindowsTrustedRT" "Windows Trusted Execution Environment Class Extension: Windows Trusted Runtime Interface Driver" "(Verified) Microsoft Windows Hardware Abstraction Layer Publisher" "C:\WINDOWS\system32\drivers\WindowsTrustedRT.sys" "Sat Jun 5 13:05:16 2021" "
+ "WindowsTrustedRTProxy" "Microsoft Windows Trusted Runtime Secure Service: Windows Trusted Runtime Service Proxy Driver" "(Verified) Microsoft Windows Hardware Abstraction Layer Publisher" "C:\WINDOWS\System32\drivers\WindowsTrustedRTProxy.sys" "Sat Jun 5 13:04:46 2021" "
+ "WinMad" "WinMad Service: Kernel WinMad" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\winmad.sys" "Sat Jun 5 13:04:45 2021" "
+ "WinNat" "Windows NAT Driver: This service provides network address translation functionality" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\winnat.sys" "Thu Dec 16 07:51:30 2021" "
+ "WinSetupMon" "WinSetupMon: SetupPlatform Monitor Mini-Filter" "" "File not found: C:\WINDOWS\system32\DRIVERS\WinSetupMon.sys" "Thu Dec 16 09:46:21 2021" "
+ "WINUSB" "WinUsb Driver: Generic driver for USB devices" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\WinUSB.SYS" "Sat Jun 5 13:04:46 2021" "
+ "WinVerbs" "WinVerbs Service: Kernel WinVerbs" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\winverbs.sys" "Sat Jun 5 13:04:45 2021" "
+ "WmiAcpi" "Microsoft Windows Management Interface for ACPI: Windows Management Interface for ACPI" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\wmiacpi.sys" "Sat Jun 5 13:04:45 2021" "
+ "Wof" "Windows Overlay File System Filter Driver: Windows Overlay Filter" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Drivers\Wof.sys" "Sat Jun 5 13:05:23 2021" "
+ "WpdUpFltr" "WPD Upper Class Filter Driver: WPD Upper Class Filter Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\WpdUpFltr.sys" "Sat Jun 5 18:17:03 2021" "
+ X "ws2ifsl" "Winsock IFS Driver: Winsock IFS Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\ws2ifsl.sys" "Sat Jun 5 13:05:27 2021" "
+ "WSDPrintDevice" "WSD Print Support: Web Services Print Device Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\WSDPrint.sys" "Sat Jun 5 13:04:44 2021" "
+ "WSDScan" "WSD Scan Support: Web Service Based Scan Device Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\DRIVERS\WSDScan.sys" "Sat Jun 5 13:04:44 2021" "
+ "WudfPf" "User Mode Driver Frameworks Platform Driver: A kernel mode driver that uses message-based interprocess communication mechanism to communicate with the driver manager and secure host process to facilitate secure companions" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\WudfPf.sys" "Sat Jun 5 13:05:33 2021" "
+ "xboxgip" "Xbox Game Input Protocol Driver: Xbox Game Input Protocol Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\xboxgip.sys" "Thu Dec 16 07:50:51 2021" "
+ "xinputhid" "XINPUT HID Filter Driver: XINPUT filter driver for HID" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\xinputhid.sys" "Sat Jun 5 13:04:42 2021" "
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Font Drivers]
+ "Adobe Type Manager" "" "" "File not found: atmfd.dll" "" "
[Codecs]
[HKCU\Software\Microsoft\Windows NT\CurrentVersion\Drivers32]
[HKCU\Software\Classes\Filter]
[HKCU\Software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance]
[HKCU\Software\Classes\CLSID\{AC757296-3522-4E11-9862-C17BE5A1767E}\Instance]
[HKCU\Software\Classes\CLSID\{7ED96837-96F0-4812-B211-F13C24117ED3}\Instance]
[HKCU\Software\Classes\CLSID\{ABE3B9A4-257D-4B97-BD1A-294AF496222E}\Instance]
[HKCU\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32]
[HKCU\Software\Wow6432Node\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance]
[HKCU\Software\Wow6432Node\Classes\CLSID\{AC757296-3522-4E11-9862-C17BE5A1767E}\Instance]
[HKCU\Software\Wow6432Node\Classes\CLSID\{7ED96837-96F0-4812-B211-F13C24117ED3}\Instance]
[HKCU\Software\Wow6432Node\Classes\CLSID\{ABE3B9A4-257D-4B97-BD1A-294AF496222E}\Instance]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32]
+ "aux" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wdmaud.drv" "Sat Jun 5 13:04:54 2021" "
+ "aux1" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wdmaud.drv" "Sat Jun 5 13:04:54 2021" "
+ "aux2" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wdmaud.drv" "Sat Jun 5 13:04:54 2021" "
+ "aux3" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wdmaud.drv" "Sat Jun 5 13:04:54 2021" "
+ "midi" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wdmaud.drv" "Sat Jun 5 13:04:54 2021" "
+ "midi1" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wdmaud.drv" "Sat Jun 5 13:04:54 2021" "
+ "midi2" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wdmaud.drv" "Sat Jun 5 13:04:54 2021" "
+ "midi3" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wdmaud.drv" "Sat Jun 5 13:04:54 2021" "
+ "midimapper" "Microsoft MIDI Mapper" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\midimap.dll" "Sat Jun 5 13:04:54 2021" "
+ "mixer" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wdmaud.drv" "Sat Jun 5 13:04:54 2021" "
+ "mixer1" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wdmaud.drv" "Sat Jun 5 13:04:54 2021" "
+ "mixer2" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wdmaud.drv" "Sat Jun 5 13:04:54 2021" "
+ "mixer3" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wdmaud.drv" "Sat Jun 5 13:04:54 2021" "
+ "msacm.imaadpcm" "IMA ADPCM CODEC for MSACM" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\imaadp32.acm" "Sat Jun 5 13:04:54 2021" "
+ "msacm.l3acm" "MPEG Layer-3 Audio Codec for MSACM" "(Verified) Microsoft Windows" "C:\Windows\System32\l3codeca.acm" "Sat Jun 5 18:17:05 2021" "
+ "msacm.msadpcm" "Microsoft ADPCM CODEC for MSACM" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\msadp32.acm" "Sat Jun 5 13:04:54 2021" "
+ "msacm.msg711" "Microsoft CCITT G.711 (A-Law and u-Law) CODEC for MSACM" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\msg711.acm" "Sat Jun 5 13:04:54 2021" "
+ "msacm.msgsm610" "Microsoft GSM 6.10 Audio CODEC for MSACM" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\msgsm32.acm" "Sat Jun 5 13:04:54 2021" "
+ "MSVideo8" "VfW MM Driver for WDM Video Capture Devices" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\VfWWDM32.dll" "Thu Dec 16 07:56:42 2021" "
+ "vidc.i420" "Intel Indeo(R) Video YUV Codec" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\iyuv_32.dll" "Sat Jun 5 13:06:11 2021" "
+ "vidc.iyuv" "Intel Indeo(R) Video YUV Codec" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\iyuv_32.dll" "Sat Jun 5 13:06:11 2021" "
+ "vidc.mrle" "Microsoft RLE Compressor" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\msrle32.dll" "Sat Jun 5 13:06:11 2021" "
+ "vidc.msvc" "Microsoft Video 1 Compressor" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\msvidc32.dll" "Sat Jun 5 13:06:11 2021" "
+ "vidc.uyvy" "Microsoft UYVY Video Decompressor" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\msyuv.dll" "Sat Jun 5 13:06:11 2021" "
+ "vidc.yuy2" "Microsoft UYVY Video Decompressor" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\msyuv.dll" "Sat Jun 5 13:06:11 2021" "
+ "vidc.yvu9" "Toshiba Video Codec" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\tsbyuv.dll" "Sat Jun 5 13:06:11 2021" "
+ "vidc.yvyu" "Microsoft UYVY Video Decompressor" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\msyuv.dll" "Sat Jun 5 13:06:11 2021" "
+ "wave" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wdmaud.drv" "Sat Jun 5 13:04:54 2021" "
+ "wave1" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wdmaud.drv" "Sat Jun 5 13:04:54 2021" "
+ "wave2" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wdmaud.drv" "Sat Jun 5 13:04:54 2021" "
+ "wave3" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wdmaud.drv" "Sat Jun 5 13:04:54 2021" "
+ "wavemapper" "Microsoft Sound Mapper" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\msacm32.drv" "Sat Jun 5 13:04:54 2021" "
[HKLM\Software\Classes\Filter]
[HKLM\Software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance]
+ "AC3 Parser Filter" "DirectShow MPEG-2 Splitter." "(Verified) Microsoft Windows" "C:\Windows\System32\mpg2splt.ax" "Sat Jun 5 13:06:14 2021" "
+ "ACM Wrapper" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\quartz.dll" "Sat Jun 5 13:06:11 2021" "
+ "AVI Decompressor" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\quartz.dll" "Sat Jun 5 13:06:11 2021" "
+ "AVI Draw Filter" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\quartz.dll" "Sat Jun 5 13:06:11 2021" "
+ "AVI mux" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\qcap.dll" "Sat Jun 5 13:06:11 2021" "
+ "AVI Splitter" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\quartz.dll" "Sat Jun 5 13:06:11 2021" "
+ "AVI/WAV File Source" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\quartz.dll" "Sat Jun 5 13:06:11 2021" "
+ "BDA MPEG2 Transport Information Filter" "Microsoft Transport Information Filter for MPEG2 based networks." "(Verified) Microsoft Windows" "C:\Windows\System32\psisrndr.ax" "Sat Jun 5 13:06:14 2021" "
+ "Closed Captions Analysis Filter" "CCA DirectShow Filter." "(Verified) Microsoft Windows" "C:\Windows\System32\cca.dll" "Sat Jun 5 13:06:14 2021" "
+ "Color Space Converter" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\quartz.dll" "Sat Jun 5 13:06:11 2021" "
+ "Default Video Renderer" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\quartz.dll" "Sat Jun 5 13:06:11 2021" "
+ "DV Muxer" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\qdv.dll" "Sat Jun 5 13:06:11 2021" "
+ "DV Splitter" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\qdv.dll" "Sat Jun 5 13:06:11 2021" "
+ "DV Video Decoder" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\qdv.dll" "Sat Jun 5 13:06:11 2021" "
+ "DVD Navigator" "DirectShow DVD PlayBack Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\qdvd.dll" "Sat Jun 5 13:06:11 2021" "
+ "Enhanced Video Renderer" "Enhanced Video Renderer DLL" "(Verified) Microsoft Windows" "C:\Windows\System32\evr.dll" "Sat Jun 5 18:17:05 2021" "
+ "File Source (Async.)" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\quartz.dll" "Sat Jun 5 13:06:11 2021" "
+ "File Source (URL)" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\quartz.dll" "Sat Jun 5 13:06:11 2021" "
+ "File stream renderer" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\quartz.dll" "Sat Jun 5 13:06:11 2021" "
+ "File Writer" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\qcap.dll" "Sat Jun 5 13:06:11 2021" "
+ "Infinite Pin Tee Filter" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\qcap.dll" "Sat Jun 5 13:06:11 2021" "
+ "Internal Text Renderer" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\quartz.dll" "Sat Jun 5 13:06:11 2021" "
+ "Line 21 Decoder 2" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\quartz.dll" "Sat Jun 5 13:06:11 2021" "
+ "Microsoft AC3 Encoder" "Microsoft AC-3 Encoder" "(Verified) Microsoft Windows" "C:\Windows\System32\msac3enc.dll" "Thu Dec 16 07:57:12 2021" "
+ "Microsoft DTV-DVD Audio Decoder" "Microsoft DTV-DVD Audio Decoder" "(Verified) Microsoft Windows" "C:\Windows\System32\msmpeg2adec.dll" "Thu Dec 16 07:57:13 2021" "
+ "Microsoft DTV-DVD Video Decoder" "Microsoft DTV-DVD Video Decoder" "(Verified) Microsoft Windows" "C:\Windows\System32\msmpeg2vdec.dll" "Thu Dec 16 07:57:13 2021" "
+ "Microsoft MPEG-2 Audio Encoder" "Microsoft MPEG-2 Encoder" "(Verified) Microsoft Windows" "C:\Windows\System32\msmpeg2enc.dll" "Thu Dec 16 07:57:12 2021" "
+ "Microsoft MPEG-2 Encoder" "Microsoft MPEG-2 Encoder" "(Verified) Microsoft Windows" "C:\Windows\System32\msmpeg2enc.dll" "Thu Dec 16 07:57:12 2021" "
+ "Microsoft MPEG-2 Video Encoder" "Microsoft MPEG-2 Encoder" "(Verified) Microsoft Windows" "C:\Windows\System32\msmpeg2enc.dll" "Thu Dec 16 07:57:12 2021" "
+ "MIDI Parser" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\quartz.dll" "Sat Jun 5 13:06:11 2021" "
+ "MJPEG Decompressor" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\quartz.dll" "Sat Jun 5 13:06:11 2021" "
+ "MPEG Audio Codec" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\quartz.dll" "Sat Jun 5 13:06:11 2021" "
+ "MPEG Video Codec" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\quartz.dll" "Sat Jun 5 13:06:11 2021" "
+ "MPEG-2 Demultiplexer" "DirectShow MPEG-2 Splitter." "(Verified) Microsoft Windows" "C:\Windows\System32\mpg2splt.ax" "Sat Jun 5 13:06:14 2021" "
+ "MPEG-2 Sections and Tables" "Microsoft MPEG-2 Section and Table Acquisition Module" "(Verified) Microsoft Windows" "C:\Windows\System32\Mpeg2Data.ax" "Sat Jun 5 13:06:14 2021" "
+ "MPEG-2 Splitter" "DirectShow MPEG-2 Splitter." "(Verified) Microsoft Windows" "C:\Windows\System32\mpg2splt.ax" "Sat Jun 5 13:06:14 2021" "
+ "Mpeg-2 Video Stream Analysis" "DirectShow Stream Buffer Filter." "(Verified) Microsoft Windows" "C:\Windows\System32\sbe.dll" "Thu Dec 16 07:56:44 2021" "
+ "MPEG-I Stream Splitter" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\quartz.dll" "Sat Jun 5 13:06:11 2021" "
+ "Multi-file Parser" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\quartz.dll" "Sat Jun 5 13:06:11 2021" "
+ "Null Renderer" "DirectShow editing." "(Verified) Microsoft Windows" "C:\Windows\System32\qedit.dll" "Sat Jun 5 13:06:16 2021" "
+ "SAMI (CC) Reader" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\quartz.dll" "Sat Jun 5 13:06:11 2021" "
+ "Sample Grabber" "DirectShow editing." "(Verified) Microsoft Windows" "C:\Windows\System32\qedit.dll" "Sat Jun 5 13:06:16 2021" "
+ "SBE2 Sink" "DirectShow Stream Buffer Filter." "(Verified) Microsoft Windows" "C:\Windows\System32\sbe.dll" "Thu Dec 16 07:56:44 2021" "
+ "SBE2FileScan" "DirectShow Stream Buffer Filter." "(Verified) Microsoft Windows" "C:\Windows\System32\sbe.dll" "Thu Dec 16 07:56:44 2021" "
+ "SBE2MediaTypeProfile" "DirectShow Stream Buffer Filter." "(Verified) Microsoft Windows" "C:\Windows\System32\sbe.dll" "Thu Dec 16 07:56:44 2021" "
+ "Smart Tee Filter" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\qcap.dll" "Sat Jun 5 13:06:11 2021" "
+ "StreamBufferSink" "DirectShow Stream Buffer Filter." "(Verified) Microsoft Windows" "C:\Windows\System32\sbe.dll" "Thu Dec 16 07:56:44 2021" "
+ "StreamBufferSource" "DirectShow Stream Buffer Filter." "(Verified) Microsoft Windows" "C:\Windows\System32\sbe.dll" "Thu Dec 16 07:56:44 2021" "
+ "VBI Codec" "Microsoft VBI Codec" "(Verified) Microsoft Windows" "C:\Windows\System32\VBICodec.ax" "Sat Jun 5 13:06:14 2021" "
+ "VBI Surface Allocator" "VBI Surface Allocator Filter" "(Verified) Microsoft Windows" "C:\Windows\System32\vbisurf.ax" "Thu Dec 16 07:56:44 2021" "
+ "VGA 16 color ditherer" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\quartz.dll" "Sat Jun 5 13:06:11 2021" "
+ "Video Mixing Renderer 9" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\quartz.dll" "Sat Jun 5 13:06:11 2021" "
+ "Video Port Manager" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\quartz.dll" "Sat Jun 5 13:06:11 2021" "
+ "Video Renderer" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\quartz.dll" "Sat Jun 5 13:06:11 2021" "
+ "VPS Decoder" "Microsoft Teletext Server" "(Verified) Microsoft Windows" "C:\Windows\System32\WSTPager.ax" "Sat Jun 5 13:06:14 2021" "
+ "Wave Parser" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\quartz.dll" "Sat Jun 5 13:06:11 2021" "
+ "WM ASF Reader" "DirectShow ASF Support" "(Verified) Microsoft Windows" "C:\Windows\System32\qasf.dll" "Thu Dec 16 07:56:30 2021" "
+ "WM ASF Writer" "DirectShow ASF Support" "(Verified) Microsoft Windows" "C:\Windows\System32\qasf.dll" "Thu Dec 16 07:56:30 2021" "
+ "WST Pager" "Microsoft Teletext Server" "(Verified) Microsoft Windows" "C:\Windows\System32\WSTPager.ax" "Sat Jun 5 13:06:14 2021" "
[HKLM\Software\Classes\CLSID\{AC757296-3522-4E11-9862-C17BE5A1767E}\Instance]
[HKLM\Software\Classes\CLSID\{7ED96837-96F0-4812-B211-F13C24117ED3}\Instance]
+ "{41945702-8302-44A6-9445-AC98E8AFA086}" "MS RAW Image Decoder DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\MSRAWImage.dll" "Sat Jun 5 18:17:05 2021" "
+ "{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}" "Microsoft Camera Codec Pack" "(Verified) Microsoft Windows" "C:\Windows\System32\WindowsCodecsRaw.dll" "Thu Dec 16 07:57:08 2021" "
[HKLM\Software\Classes\CLSID\{ABE3B9A4-257D-4B97-BD1A-294AF496222E}\Instance]
[HKLM\Software\Wow6432Node\Classes\Filter]
[HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32]
+ "aux" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\wdmaud.drv" "Sat Jun 5 13:05:45 2021" "
+ "aux1" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\wdmaud.drv" "Sat Jun 5 13:05:45 2021" "
+ "aux2" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\wdmaud.drv" "Sat Jun 5 13:05:45 2021" "
+ "aux3" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\wdmaud.drv" "Sat Jun 5 13:05:45 2021" "
+ "midi" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\wdmaud.drv" "Sat Jun 5 13:05:45 2021" "
+ "midi1" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\wdmaud.drv" "Sat Jun 5 13:05:45 2021" "
+ "midi2" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\wdmaud.drv" "Sat Jun 5 13:05:45 2021" "
+ "midi3" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\wdmaud.drv" "Sat Jun 5 13:05:45 2021" "
+ "midimapper" "Microsoft MIDI Mapper" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\midimap.dll" "Sat Jun 5 13:05:43 2021" "
+ "mixer" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\wdmaud.drv" "Sat Jun 5 13:05:45 2021" "
+ "mixer1" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\wdmaud.drv" "Sat Jun 5 13:05:45 2021" "
+ "mixer2" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\wdmaud.drv" "Sat Jun 5 13:05:45 2021" "
+ "mixer3" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\wdmaud.drv" "Sat Jun 5 13:05:45 2021" "
+ "msacm.imaadpcm" "IMA ADPCM CODEC for MSACM" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\imaadp32.acm" "Sat Jun 5 13:05:43 2021" "
+ "msacm.l3acm" "MPEG Layer-3 Audio Codec for MSACM" "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\l3codeca.acm" "Sat Jun 5 18:17:04 2021" "
+ "msacm.msadpcm" "Microsoft ADPCM CODEC for MSACM" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\msadp32.acm" "Sat Jun 5 13:05:43 2021" "
+ "msacm.msg711" "Microsoft CCITT G.711 (A-Law and u-Law) CODEC for MSACM" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\msg711.acm" "Sat Jun 5 13:05:43 2021" "
+ "msacm.msgsm610" "Microsoft GSM 6.10 Audio CODEC for MSACM" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\msgsm32.acm" "Sat Jun 5 13:05:45 2021" "
+ "vidc.cvid" "Cinepak® Codec" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\iccvid.dll" "Sat Jun 5 13:06:24 2021" "
+ "vidc.i420" "Intel Indeo(R) Video YUV Codec" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\iyuv_32.dll" "Sat Jun 5 13:06:24 2021" "
+ "vidc.iyuv" "Intel Indeo(R) Video YUV Codec" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\iyuv_32.dll" "Sat Jun 5 13:06:24 2021" "
+ "vidc.mrle" "Microsoft RLE Compressor" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\msrle32.dll" "Sat Jun 5 13:06:24 2021" "
+ "vidc.msvc" "Microsoft Video 1 Compressor" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\msvidc32.dll" "Sat Jun 5 13:06:24 2021" "
+ "vidc.uyvy" "Microsoft UYVY Video Decompressor" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\msyuv.dll" "Sat Jun 5 13:06:24 2021" "
+ "vidc.yuy2" "Microsoft UYVY Video Decompressor" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\msyuv.dll" "Sat Jun 5 13:06:24 2021" "
+ "vidc.yvu9" "Toshiba Video Codec" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\tsbyuv.dll" "Sat Jun 5 13:06:24 2021" "
+ "vidc.yvyu" "Microsoft UYVY Video Decompressor" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\msyuv.dll" "Sat Jun 5 13:06:24 2021" "
+ "wave" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\wdmaud.drv" "Sat Jun 5 13:05:45 2021" "
+ "wave1" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\wdmaud.drv" "Sat Jun 5 13:05:45 2021" "
+ "wave2" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\wdmaud.drv" "Sat Jun 5 13:05:45 2021" "
+ "wave3" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\wdmaud.drv" "Sat Jun 5 13:05:45 2021" "
+ "wavemapper" "Microsoft Sound Mapper" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\msacm32.drv" "Sat Jun 5 13:05:43 2021" "
[HKLM\Software\Wow6432Node\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance]
+ "AC3 Parser Filter" "DirectShow MPEG-2 Splitter." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\mpg2splt.ax" "Sat Jun 5 13:06:24 2021" "
+ "ACM Wrapper" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\quartz.dll" "Sat Jun 5 13:06:24 2021" "
+ "AVI Decompressor" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\quartz.dll" "Sat Jun 5 13:06:24 2021" "
+ "AVI Draw Filter" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\quartz.dll" "Sat Jun 5 13:06:24 2021" "
+ "AVI mux" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\qcap.dll" "Sat Jun 5 13:06:24 2021" "
+ "AVI Splitter" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\quartz.dll" "Sat Jun 5 13:06:24 2021" "
+ "AVI/WAV File Source" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\quartz.dll" "Sat Jun 5 13:06:24 2021" "
+ "BDA MPEG2 Transport Information Filter" "Microsoft Transport Information Filter for MPEG2 based networks." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\psisrndr.ax" "Sat Jun 5 13:06:24 2021" "
+ "Closed Captions Analysis Filter" "CCA DirectShow Filter." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\cca.dll" "Sat Jun 5 13:06:24 2021" "
+ "Color Space Converter" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\quartz.dll" "Sat Jun 5 13:06:24 2021" "
+ "Default Video Renderer" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\quartz.dll" "Sat Jun 5 13:06:24 2021" "
+ "DV Muxer" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\qdv.dll" "Sat Jun 5 13:06:24 2021" "
+ "DV Splitter" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\qdv.dll" "Sat Jun 5 13:06:24 2021" "
+ "DV Video Decoder" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\qdv.dll" "Sat Jun 5 13:06:24 2021" "
+ "DVD Navigator" "DirectShow DVD PlayBack Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\qdvd.dll" "Sat Jun 5 13:06:24 2021" "
+ "Enhanced Video Renderer" "Enhanced Video Renderer DLL" "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\evr.dll" "Sat Jun 5 18:17:04 2021" "
+ "File Source (Async.)" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\quartz.dll" "Sat Jun 5 13:06:24 2021" "
+ "File Source (URL)" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\quartz.dll" "Sat Jun 5 13:06:24 2021" "
+ "File stream renderer" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\quartz.dll" "Sat Jun 5 13:06:24 2021" "
+ "File Writer" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\qcap.dll" "Sat Jun 5 13:06:24 2021" "
+ "Infinite Pin Tee Filter" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\qcap.dll" "Sat Jun 5 13:06:24 2021" "
+ "Internal Text Renderer" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\quartz.dll" "Sat Jun 5 13:06:24 2021" "
+ "Line 21 Decoder" "DirectShow DVD PlayBack Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\qdvd.dll" "Sat Jun 5 13:06:24 2021" "
+ "Line 21 Decoder 2" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\quartz.dll" "Sat Jun 5 13:06:24 2021" "
+ "Microsoft AC3 Encoder" "Microsoft AC-3 Encoder" "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\msac3enc.dll" "Thu Dec 16 07:57:16 2021" "
+ "Microsoft DTV-DVD Audio Decoder" "Microsoft DTV-DVD Audio Decoder" "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\msmpeg2adec.dll" "Thu Dec 16 07:57:17 2021" "
+ "Microsoft DTV-DVD Video Decoder" "Microsoft DTV-DVD Video Decoder" "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\msmpeg2vdec.dll" "Thu Dec 16 07:57:16 2021" "
+ "Microsoft MPEG-2 Audio Encoder" "Microsoft MPEG-2 Encoder" "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\msmpeg2enc.dll" "Thu Dec 16 07:57:16 2021" "
+ "Microsoft MPEG-2 Encoder" "Microsoft MPEG-2 Encoder" "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\msmpeg2enc.dll" "Thu Dec 16 07:57:16 2021" "
+ "Microsoft MPEG-2 Video Encoder" "Microsoft MPEG-2 Encoder" "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\msmpeg2enc.dll" "Thu Dec 16 07:57:16 2021" "
+ "MIDI Parser" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\quartz.dll" "Sat Jun 5 13:06:24 2021" "
+ "MJPEG Decompressor" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\quartz.dll" "Sat Jun 5 13:06:24 2021" "
+ "MPEG Audio Codec" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\quartz.dll" "Sat Jun 5 13:06:24 2021" "
+ "MPEG Video Codec" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\quartz.dll" "Sat Jun 5 13:06:24 2021" "
+ "MPEG-2 Demultiplexer" "DirectShow MPEG-2 Splitter." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\mpg2splt.ax" "Sat Jun 5 13:06:24 2021" "
+ "MPEG-2 Sections and Tables" "Microsoft MPEG-2 Section and Table Acquisition Module" "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\Mpeg2Data.ax" "Sat Jun 5 13:06:24 2021" "
+ "MPEG-2 Splitter" "DirectShow MPEG-2 Splitter." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\mpg2splt.ax" "Sat Jun 5 13:06:24 2021" "
+ "Mpeg-2 Video Stream Analysis" "DirectShow Stream Buffer Filter." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\sbe.dll" "Sat Jun 5 13:06:24 2021" "
+ "MPEG-I Stream Splitter" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\quartz.dll" "Sat Jun 5 13:06:24 2021" "
+ "Multi-file Parser" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\quartz.dll" "Sat Jun 5 13:06:24 2021" "
+ "Null Renderer" "DirectShow editing." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\qedit.dll" "Sat Jun 5 13:06:24 2021" "
+ "Overlay Mixer" "DirectShow DVD PlayBack Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\qdvd.dll" "Sat Jun 5 13:06:24 2021" "
+ "Overlay Mixer2" "DirectShow DVD PlayBack Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\qdvd.dll" "Sat Jun 5 13:06:24 2021" "
+ "SAMI (CC) Reader" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\quartz.dll" "Sat Jun 5 13:06:24 2021" "
+ "Sample Grabber" "DirectShow editing." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\qedit.dll" "Sat Jun 5 13:06:24 2021" "
+ "SBE2 Sink" "DirectShow Stream Buffer Filter." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\sbe.dll" "Sat Jun 5 13:06:24 2021" "
+ "SBE2FileScan" "DirectShow Stream Buffer Filter." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\sbe.dll" "Sat Jun 5 13:06:24 2021" "
+ "SBE2MediaTypeProfile" "DirectShow Stream Buffer Filter." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\sbe.dll" "Sat Jun 5 13:06:24 2021" "
+ "Smart Tee Filter" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\qcap.dll" "Sat Jun 5 13:06:24 2021" "
+ "StreamBufferSink" "DirectShow Stream Buffer Filter." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\sbe.dll" "Sat Jun 5 13:06:24 2021" "
+ "StreamBufferSource" "DirectShow Stream Buffer Filter." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\sbe.dll" "Sat Jun 5 13:06:24 2021" "
+ "VBI Codec" "Microsoft VBI Codec" "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\VBICodec.ax" "Sat Jun 5 13:06:24 2021" "
+ "VBI Surface Allocator" "VBI Surface Allocator Filter" "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\vbisurf.ax" "Thu Dec 16 07:57:07 2021" "
+ "VGA 16 color ditherer" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\quartz.dll" "Sat Jun 5 13:06:24 2021" "
+ "Video Mixing Renderer 9" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\quartz.dll" "Sat Jun 5 13:06:24 2021" "
+ "Video Port Manager" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\quartz.dll" "Sat Jun 5 13:06:24 2021" "
+ "Video Renderer" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\quartz.dll" "Sat Jun 5 13:06:24 2021" "
+ "VPS Decoder" "Microsoft Teletext Server" "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\WSTPager.ax" "Sat Jun 5 13:06:24 2021" "
+ "Wave Parser" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\quartz.dll" "Sat Jun 5 13:06:24 2021" "
+ "WM ASF Reader" "DirectShow ASF Support" "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\qasf.dll" "Thu Dec 16 07:57:01 2021" "
+ "WM ASF Writer" "DirectShow ASF Support" "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\qasf.dll" "Thu Dec 16 07:57:01 2021" "
+ "WST Pager" "Microsoft Teletext Server" "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\WSTPager.ax" "Sat Jun 5 13:06:24 2021" "
[HKLM\Software\Wow6432Node\Classes\CLSID\{AC757296-3522-4E11-9862-C17BE5A1767E}\Instance]
[HKLM\Software\Wow6432Node\Classes\CLSID\{7ED96837-96F0-4812-B211-F13C24117ED3}\Instance]
+ "{41945702-8302-44A6-9445-AC98E8AFA086}" "MS RAW Image Decoder DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\MSRAWImage.dll" "Sat Jun 5 18:17:04 2021" "
+ "{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}" "Microsoft Camera Codec Pack" "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\WindowsCodecsRaw.dll" "Thu Dec 16 07:57:10 2021" "
[HKLM\Software\Wow6432Node\Classes\CLSID\{ABE3B9A4-257D-4B97-BD1A-294AF496222E}\Instance]
[Boot Execute]
[HKLM\System\CurrentControlSet\Control\Session Manager\BootExecute]
+ "autocheck autochk *" "Auto Check Utility" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\autochk.exe" "Sat Jun 5 13:05:23 2021" "
[HKLM\System\CurrentControlSet\Control\Session Manager\SetupExecute]
[HKLM\System\CurrentControlSet\Control\Session Manager\Execute]
[HKLM\System\CurrentControlSet\Control\Session Manager\S0InitialCommand]
[Image Hijacks]
[HKCU\Software\Microsoft\Command Processor\Autorun]
[HKCU\SOFTWARE\Classes\Exefile\Shell\Open\Command\(Default)]
[HKCU\SOFTWARE\Classes\Htmlfile\Shell\Open\Command\(Default)]
[HKCU\Software\Classes\.exe]
[HKCU\Software\Classes\.cmd]
[HKLM\Software\Microsoft\Command Processor\Autorun]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
[HKLM\SOFTWARE\Classes\Exefile\Shell\Open\Command\(Default)]
[HKLM\SOFTWARE\Classes\Htmlfile\Shell\Open\Command\(Default)]
+ "C:\Program Files\Internet Explorer\iexplore.exe" "Internet Explorer" "(Verified) Microsoft Corporation" "C:\Program Files\Internet Explorer\iexplore.exe" "Thu Dec 16 08:01:20 2021" "
[HKLM\Software\Classes\.exe]
[HKLM\Software\Classes\.cmd]
[HKLM\Software\Wow6432Node\Microsoft\Command Processor\Autorun]
[HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
[AppInit]
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Appinit_Dlls]
[HKLM\System\CurrentControlSet\Control\Session Manager\AppCertDlls]
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Windows\Appinit_Dlls]
[Known DLLs]
[HKLM\System\CurrentControlSet\Control\Session Manager\KnownDlls]
+ "*kernel32" "Windows NT BASE API Client DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\kernel32.dll" "Thu Dec 16 07:53:03 2021" "
+ "*kernel32" "Windows NT BASE API Client DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\kernel32.dll" "Thu Dec 16 07:55:22 2021" "
+ "_wow64cpu" "AMD64 Wow64 CPU " "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wow64cpu.dll" "Sat Jun 5 13:05:27 2021" "
+ "_wow64cpu" "" "" "File not found: C:\WINDOWS\Syswow64\wow64cpu.dll" "" "
+ "_wowarmhw" "" "" "File not found: C:\WINDOWS\system32\wowarmhw.dll" "" "
+ "_wowarmhw" "" "" "File not found: C:\WINDOWS\Syswow64\wowarmhw.dll" "" "
+ "_xtajit" "" "" "File not found: C:\WINDOWS\system32\xtajit.dll" "" "
+ "_xtajit" "" "" "File not found: C:\WINDOWS\Syswow64\xtajit.dll" "" "
+ "advapi32" "Advanced Windows 32 Base API" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\advapi32.dll" "Thu Dec 16 07:51:50 2021" "
+ "advapi32" "Advanced Windows 32 Base API" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\advapi32.dll" "Thu Dec 16 07:55:17 2021" "
+ "clbcatq" "COM+ Configuration Catalog" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\clbcatq.dll" "Sat Jun 5 13:05:23 2021" "
+ "clbcatq" "COM+ Configuration Catalog" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\clbcatq.dll" "Sat Jun 5 13:05:53 2021" "
+ "combase" "Microsoft COM for Windows" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\combase.dll" "Thu Dec 16 07:53:43 2021" "
+ "combase" "Microsoft COM for Windows" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\combase.dll" "Thu Dec 16 07:55:58 2021" "
+ "COMDLG32" "Common Dialogues DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\COMDLG32.dll" "Thu Dec 16 07:54:26 2021" "
+ "COMDLG32" "Common Dialogues DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\COMDLG32.dll" "Thu Dec 16 07:56:18 2021" "
+ "coml2" "Microsoft COM for Windows" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\coml2.dll" "Sat Jun 5 13:05:09 2021" "
+ "coml2" "Microsoft COM for Windows" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\coml2.dll" "Sat Jun 5 13:05:51 2021" "
+ "DifxApi" "Driver Install Frameworks for API library module" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\difxapi.dll" "Sat Jun 5 13:05:39 2021" "
+ "DifxApi" "Driver Install Frameworks for API library module" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\difxapi.dll" "Sat Jun 5 13:05:59 2021" "
+ "gdi32" "GDI Client DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\gdi32.dll" "Sat Jun 5 13:05:06 2021" "
+ "gdi32" "GDI Client DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\gdi32.dll" "Sat Jun 5 13:05:48 2021" "
+ "gdiplus" "Microsoft GDI+" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\gdiplus.dll" "Thu Dec 16 07:54:20 2021" "
+ "gdiplus" "Microsoft GDI+" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\gdiplus.dll" "Thu Dec 16 07:56:02 2021" "
+ "IMAGEHLP" "Windows NT Image Helper" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\IMAGEHLP.dll" "Sat Jun 5 13:05:25 2021" "
+ "IMAGEHLP" "Windows NT Image Helper" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\IMAGEHLP.dll" "Sat Jun 5 13:05:25 2021" "
+ "IMM32" "Multi-User Windows IMM32 API Client DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\IMM32.dll" "Sat Jun 5 13:05:27 2021" "
+ "IMM32" "Multi-User Windows IMM32 API Client DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\IMM32.dll" "Sat Jun 5 13:05:53 2021" "
+ "MSCTF" "MSCTF Server DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\MSCTF.dll" "Thu Dec 16 07:52:59 2021" "
+ "MSCTF" "MSCTF Server DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\MSCTF.dll" "Thu Dec 16 07:55:19 2021" "
+ "MSVCRT" "Windows NT CRT DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\MSVCRT.dll" "Sat Jun 5 13:05:25 2021" "
+ "MSVCRT" "Windows NT CRT DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\MSVCRT.dll" "Sat Jun 5 13:05:45 2021" "
+ "NORMALIZ" "Unicode Normalization DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\NORMALIZ.dll" "Sat Jun 5 13:05:27 2021" "
+ "NORMALIZ" "Unicode Normalization DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\NORMALIZ.dll" "Sat Jun 5 13:05:53 2021" "
+ "NSI" "NSI User-mode interface DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\NSI.dll" "Sat Jun 5 13:05:25 2021" "
+ "NSI" "NSI User-mode interface DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\NSI.dll" "Sat Jun 5 13:05:25 2021" "
+ "ole32" "Microsoft OLE for Windows" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\ole32.dll" "Thu Dec 16 07:53:40 2021" "
+ "ole32" "Microsoft OLE for Windows" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\ole32.dll" "Thu Dec 16 07:55:57 2021" "
+ "OLEAUT32" "OLEAUT32.DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\OLEAUT32.dll" "Sat Jun 5 13:05:25 2021" "
+ "OLEAUT32" "OLEAUT32.DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\OLEAUT32.dll" "Sat Jun 5 13:05:53 2021" "
+ "PSAPI" "Process Status Helper" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\PSAPI.DLL" "Sat Jun 5 13:05:23 2021" "
+ "PSAPI" "Process Status Helper" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\PSAPI.DLL" "Sat Jun 5 13:05:53 2021" "
+ "rpcrt4" "Remote Procedure Call Runtime" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\rpcrt4.dll" "Thu Dec 16 07:53:50 2021" "
+ "rpcrt4" "Remote Procedure Call Runtime" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\rpcrt4.dll" "Thu Dec 16 07:55:15 2021" "
+ "sechost" "Host for SCM/SDDL/LSA Lookup APIs" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\sechost.dll" "Thu Dec 16 07:53:50 2021" "
+ "sechost" "Host for SCM/SDDL/LSA Lookup APIs" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\sechost.dll" "Thu Dec 16 07:55:15 2021" "
+ "Setupapi" "Windows Setup API" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\Setupapi.dll" "Thu Dec 16 07:54:53 2021" "
+ "Setupapi" "Windows Setup API" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\Setupapi.dll" "Thu Dec 16 07:56:16 2021" "
+ "SHCORE" "SHCORE" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\SHCORE.dll" "Thu Dec 16 07:53:07 2021" "
+ "SHCORE" "SHCORE" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\SHCORE.dll" "Thu Dec 16 07:55:52 2021" "
+ "SHELL32" "Windows Shell Common Dll" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\SHELL32.dll" "Thu Dec 16 07:54:27 2021" "
+ "SHELL32" "Windows Shell Common Dll" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\SHELL32.dll" "Thu Dec 16 07:56:19 2021" "
+ "SHLWAPI" "Shell Light-weight Utility Library" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\SHLWAPI.dll" "Sat Jun 5 13:05:33 2021" "
+ "SHLWAPI" "Shell Light-weight Utility Library" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\SHLWAPI.dll" "Sat Jun 5 13:06:00 2021" "
+ "user32" "Multi-User Windows USER API Client DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\user32.dll" "Thu Dec 16 07:52:55 2021" "
+ "user32" "Multi-User Windows USER API Client DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\user32.dll" "Thu Dec 16 07:55:51 2021" "
+ "WLDAP32" "Win32 LDAP API DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\WLDAP32.dll" "Sat Jun 5 13:05:23 2021" "
+ "WLDAP32" "Win32 LDAP API DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\WLDAP32.dll" "Sat Jun 5 13:05:53 2021" "
+ "wow64" "Win32 Emulation on NT64" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wow64.dll" "Thu Dec 16 07:54:09 2021" "
+ "wow64" "" "" "File not found: C:\WINDOWS\Syswow64\wow64.dll" "" "
+ "wow64base" "" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wow64base.dll" "Sat Jun 5 13:05:27 2021" "
+ "wow64base" "" "" "File not found: C:\WINDOWS\Syswow64\wow64base.dll" "" "
+ "wow64con" "" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wow64con.dll" "Thu Dec 16 07:54:09 2021" "
+ "wow64con" "" "" "File not found: C:\WINDOWS\Syswow64\wow64con.dll" "" "
+ "wow64win" "Wow64 Console and Win32 API Logging" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wow64win.dll" "Thu Dec 16 07:54:09 2021" "
+ "wow64win" "" "" "File not found: C:\WINDOWS\Syswow64\wow64win.dll" "" "
+ "WS2_32" "Windows Socket 2.0 32-Bit DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\WS2_32.dll" "Sat Jun 5 13:05:25 2021" "
+ "WS2_32" "Windows Socket 2.0 32-Bit DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\WS2_32.dll" "Sat Jun 5 13:05:45 2021" "
+ "xtajit64" "" "" "File not found: C:\WINDOWS\system32\xtajit64.dll" "" "
+ "xtajit64" "" "" "File not found: C:\WINDOWS\Syswow64\xtajit64.dll" "" "
[WinLogon]
[HKCU\SOFTWARE\Policies\Microsoft\Windows\Control Panel\Desktop\Scrnsave.exe]
[HKCU\Control Panel\Desktop\Scrnsave.exe]
[HKLM\SYSTEM\Setup\CmdLine]
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Taskman]
[HKLM\System\CurrentControlSet\Control\BootVerificationProgram\ImagePath]
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\Credential Providers]
+ "Automatic Redeployment Credential Provider" "Autopilot Reset Credential Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mgmtrefreshcredprov.dll" "Sat Jun 5 13:06:16 2021" "
+ "CCertProvider" "Cert Credential Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\certCredProvider.dll" "Sat Jun 5 13:05:27 2021" "
+ "Cloud Experience Credential Provider" "Cloud Experience Credential Provider" "(Verified) Microsoft Windows" "C:\Windows\System32\cxcredprov.dll" "Sat Jun 5 13:05:23 2021" "
+ "CngCredUICredentialProvider" "Microsoft CNG CredUI Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\cngcredui.dll" "Sat Jun 5 13:05:40 2021" "
+ "FaceCredentialProvider" "Face Credential Provider" "(Verified) Microsoft Windows" "C:\Windows\System32\FaceCredentialProvider.dll" "Thu Dec 16 07:56:20 2021" "
+ "FIDO Credential Provider" "FIDO Credential Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\fidocredprov.dll" "Thu Dec 16 07:52:31 2021" "
+ "GenericProvider" "Credential Providers" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\credprovs.dll" "Sat Jun 5 13:05:27 2021" "
+ "NGC Credential Provider" "Microsoft Passport Credential Provider" "(Verified) Microsoft Windows" "C:\Windows\System32\ngccredprov.dll" "Thu Dec 16 07:52:53 2021" "
+ "NPProvider" "Credential Providers" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\credprovs.dll" "Sat Jun 5 13:05:27 2021" "
+ "PasswordProvider" "Credential Providers" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\credprovs.dll" "Sat Jun 5 13:05:27 2021" "
+ "PicturePasswordLogonProvider" "Credentials Providers Legacy" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\credprovslegacy.dll" "Thu Dec 16 07:54:15 2021" "
+ "PINLogonProvider" "Credentials Providers Legacy" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\credprovslegacy.dll" "Thu Dec 16 07:54:15 2021" "
+ "Second Authentication Factor Credential Provider" "Microsoft Companion Authenticator Credentials Provider" "(Verified) Microsoft Windows" "C:\Windows\System32\devicengccredprov.dll" "Thu Dec 16 07:54:15 2021" "
+ "Smartcard Credential Provider" "Windows Smartcard Credential Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\SmartcardCredentialProvider.dll" "Sat Jun 5 13:05:34 2021" "
+ "Smartcard Pin Provider" "Windows Smartcard Credential Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\SmartcardCredentialProvider.dll" "Sat Jun 5 13:05:34 2021" "
+ "Smartcard Reader Selection Provider" "Windows Smartcard Credential Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\SmartcardCredentialProvider.dll" "Sat Jun 5 13:05:34 2021" "
+ "Smartcard WinRT Provider" "Windows Smartcard Credential Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\SmartcardCredentialProvider.dll" "Sat Jun 5 13:05:34 2021" "
+ "TrustedSignal Credential Provider" "Trusted Signal Credential Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\TrustedSignalCredProv.dll" "Sat Jun 5 13:05:27 2021" "
+ "WinBio Credential Provider" "WinBio Credential Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\BioCredProv.dll" "Thu Dec 16 07:53:05 2021" "
+ "WLIDCredentialProvider" "Microsoft® Account Credential Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wlidcredprov.dll" "Sat Jun 5 13:05:31 2021" "
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\Credential Provider Filters]
+ "GenericFilter" "Credential Providers" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\credprovs.dll" "Sat Jun 5 13:05:27 2021" "
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\PLAP Providers]
+ "CRasProvider" "RAS PLAP Credential Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\rasplap.dll" "Sat Jun 5 13:05:40 2021" "
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GpExtensions]
+ "@wlgpclnt.dll,-100" "802.11 Group Policy Client" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wlgpclnt.dll" "Sat Jun 5 13:05:00 2021" "
+ "Central Access" "Windows Audit Settings CSE" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\auditcse.dll" "Sat Jun 5 13:05:40 2021" "
+ "Folder Redirection" "Folder Redirection Group Policy Extension" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\fdeploy.dll" "Sat Jun 5 13:05:14 2021" "
+ "Microsoft Disk Quota" "Windows Shell Disk Quota Support DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\dskquota.dll" "Sat Jun 5 13:06:05 2021" "
+ "QoS Packet Scheduler" "GPTExt" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\gptext.dll" "Sat Jun 5 13:05:29 2021" "
+ "Remote Desktop USB Redirection" "Remote Desktop USB Redirection GP Extension" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\TsUsbRedirectionGroupPolicyExtension.dll" "Sat Jun 5 13:04:57 2021" "
+ "@C:\Windows\System32\iedkcs32.dll,-3051" "IEAK branding" "(Verified) Microsoft Windows" "C:\Windows\System32\iedkcs32.dll" "Sat Jun 5 13:06:07 2021" "
+ "{4D2F9B6F-1E52-4711-A382-6A8B1A003DE6}" "RemoteApp and Desktop Connection Component" "(Verified) Microsoft Windows" "C:\Windows\System32\tsworkspace.dll" "Thu Dec 16 07:53:00 2021" "
+ "Work Folders" "Microsoft (C) Work Folders Group Policy Client Extension" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\WorkFoldersGPExt.dll" "Sat Jun 5 13:06:16 2021" "
+ "MDM Policy" "Enroll Engine DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\dmenrollengine.dll" "Thu Dec 16 07:54:17 2021" "
+ "Windows Search Group Policy Extension" "Indexing Options" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\srchadmin.dll" "Sat Jun 5 13:05:40 2021" "
+ "@C:\Windows\System32\iedkcs32.dll,-3051" "IEAK branding" "(Verified) Microsoft Windows" "C:\Windows\System32\iedkcs32.dll" "Sat Jun 5 13:06:07 2021" "
+ "Security" "Windows Security Configuration Editor Client Engine" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\scecli.dll" "Sat Jun 5 13:05:40 2021" "
+ "Start Layout Group Policy" "Start Tile Data InProc Server" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\StartTileData.dll" "Thu Dec 16 07:52:03 2021" "
+ "Deployed Printer Connections" "Group Policy Printer Extension" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\gpprnext.dll" "Sat Jun 5 13:04:58 2021" "
+ "@dot3gpclnt.dll,-100" "802.3 Group Policy Client" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\dot3gpclnt.dll" "Sat Jun 5 13:05:00 2021" "
+ "Windows To Go Startup Options" "Windows To Go Launcher" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\pwlauncher.dll" "Sat Jun 5 13:06:10 2021" "
+ "Windows To Go Hibernate Options" "Windows To Go Launcher" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\pwlauncher.dll" "Sat Jun 5 13:06:10 2021" "
+ "TCPIP" "GPTExt" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\gptext.dll" "Sat Jun 5 13:05:29 2021" "
+ "@C:\Windows\System32\iedkcs32.dll,-3051" "IEAK branding" "(Verified) Microsoft Windows" "C:\Windows\System32\iedkcs32.dll" "Sat Jun 5 13:06:07 2021" "
+ "Delivery Optimization GP extension" "Delivery Optimisation Management" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\domgmt.dll" "Thu Dec 16 07:52:21 2021" "
+ "Internet Protocol Security Policies" "Policy Storage dll" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\polstore.dll" "Sat Jun 5 13:05:29 2021" "
+ "Audit" "Windows Audit Settings CSE" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\auditcse.dll" "Sat Jun 5 13:05:40 2021" "
+ "Policy-based QoS" "GPTExt" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\gptext.dll" "Sat Jun 5 13:05:29 2021" "
+ "Connectivity Platform" "GPTExt" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\gptext.dll" "Sat Jun 5 13:05:29 2021" "
[Winsock Providers]
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries]
+ "AF_UNIX" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mswsock.dll" "Sat Jun 5 13:05:53 2021" "
+ "Hyper-V RAW" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mswsock.dll" "Sat Jun 5 13:05:53 2021" "
+ "MSAFD L2CAP [Bluetooth]" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mswsock.dll" "Sat Jun 5 13:05:53 2021" "
+ "MSAFD RfComm [Bluetooth]" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mswsock.dll" "Sat Jun 5 13:05:53 2021" "
+ "MSAFD Tcpip [RAW/IP]" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mswsock.dll" "Sat Jun 5 13:05:53 2021" "
+ "MSAFD Tcpip [RAW/IPv6]" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mswsock.dll" "Sat Jun 5 13:05:53 2021" "
+ "MSAFD Tcpip [TCP/IP]" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mswsock.dll" "Sat Jun 5 13:05:53 2021" "
+ "MSAFD Tcpip [TCP/IPv6]" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mswsock.dll" "Sat Jun 5 13:05:53 2021" "
+ "MSAFD Tcpip [UDP/IP]" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mswsock.dll" "Sat Jun 5 13:05:53 2021" "
+ "MSAFD Tcpip [UDP/IPv6]" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mswsock.dll" "Sat Jun 5 13:05:53 2021" "
+ "RSVP TCP Service Provider" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mswsock.dll" "Sat Jun 5 13:05:53 2021" "
+ "RSVP TCPv6 Service Provider" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mswsock.dll" "Sat Jun 5 13:05:53 2021" "
+ "RSVP UDP Service Provider" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mswsock.dll" "Sat Jun 5 13:05:53 2021" "
+ "RSVP UDPv6 Service Provider" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mswsock.dll" "Sat Jun 5 13:05:53 2021" "
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries]
+ "@%SystemRoot%\system32\nlasvc.dll,-1000" "NLA Namespace Service Provider DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\nlansp_c.dll" "Sat Jun 5 13:05:59 2021" "
+ "Bluetooth Namespace" "Windows Sockets Helper DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wshbth.dll" "Thu Dec 16 07:55:52 2021" "
+ "E-mail Naming Shim Provider" "E-mail Naming Shim Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\napinsp.dll" "Sat Jun 5 13:05:48 2021" "
+ "NTDS" "LDAP RnR Provider DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\winrnr.dll" "Sat Jun 5 13:05:55 2021" "
+ "PNRP Cloud Namespace Provider" "PNRP Name Space Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\pnrpnsp.dll" "Sat Jun 5 13:06:26 2021" "
+ "PNRP Name Namespace Provider" "PNRP Name Space Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\pnrpnsp.dll" "Sat Jun 5 13:06:26 2021" "
+ "Tcpip" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\mswsock.dll" "Sat Jun 5 13:05:53 2021" "
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64]
+ "AF_UNIX" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mswsock.dll" "Sat Jun 5 13:05:23 2021" "
+ "Hyper-V RAW" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mswsock.dll" "Sat Jun 5 13:05:23 2021" "
+ "MSAFD L2CAP [Bluetooth]" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mswsock.dll" "Sat Jun 5 13:05:23 2021" "
+ "MSAFD RfComm [Bluetooth]" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mswsock.dll" "Sat Jun 5 13:05:23 2021" "
+ "MSAFD Tcpip [RAW/IP]" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mswsock.dll" "Sat Jun 5 13:05:23 2021" "
+ "MSAFD Tcpip [RAW/IPv6]" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mswsock.dll" "Sat Jun 5 13:05:23 2021" "
+ "MSAFD Tcpip [TCP/IP]" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mswsock.dll" "Sat Jun 5 13:05:23 2021" "
+ "MSAFD Tcpip [TCP/IPv6]" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mswsock.dll" "Sat Jun 5 13:05:23 2021" "
+ "MSAFD Tcpip [UDP/IP]" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mswsock.dll" "Sat Jun 5 13:05:23 2021" "
+ "MSAFD Tcpip [UDP/IPv6]" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mswsock.dll" "Sat Jun 5 13:05:23 2021" "
+ "RSVP TCP Service Provider" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mswsock.dll" "Sat Jun 5 13:05:23 2021" "
+ "RSVP TCPv6 Service Provider" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mswsock.dll" "Sat Jun 5 13:05:23 2021" "
+ "RSVP UDP Service Provider" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mswsock.dll" "Sat Jun 5 13:05:23 2021" "
+ "RSVP UDPv6 Service Provider" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mswsock.dll" "Sat Jun 5 13:05:23 2021" "
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64]
+ "@%SystemRoot%\system32\nlasvc.dll,-1000" "NLA Namespace Service Provider DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\nlansp_c.dll" "Sat Jun 5 13:05:39 2021" "
+ "Bluetooth Namespace" "Windows Sockets Helper DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wshbth.dll" "Thu Dec 16 07:53:06 2021" "
+ "E-mail Naming Shim Provider" "E-mail Naming Shim Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\napinsp.dll" "Sat Jun 5 13:05:27 2021" "
+ "NTDS" "LDAP RnR Provider DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\winrnr.dll" "Sat Jun 5 13:05:29 2021" "
+ "PNRP Cloud Namespace Provider" "PNRP Name Space Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\pnrpnsp.dll" "Sat Jun 5 13:06:16 2021" "
+ "PNRP Name Namespace Provider" "PNRP Name Space Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\pnrpnsp.dll" "Sat Jun 5 13:06:16 2021" "
+ "Tcpip" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\mswsock.dll" "Sat Jun 5 13:05:23 2021" "
[Print Monitors]
[HKLM\System\CurrentControlSet\Control\Print\Monitors]
+ "Appmon" "App Printer" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\AppMon.dll" "Sat Jun 5 13:06:16 2021" "
+ "Local Port" "Local Spooler DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\localspl.dll" "Thu Dec 16 07:51:44 2021" "
+ "Microsoft Shared Fax Monitor" "Microsoft Fax Print Monitor" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\FXSMON.DLL" "Sat Jun 5 02:37:00 2021" "
+ "Standard TCP/IP Port" "Standard TCP/IP Port Monitor DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\tcpmon.dll" "Sat Jun 5 13:05:39 2021" "
+ "USB Monitor" "Standard Dynamic Printing Port Monitor DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\usbmon.dll" "Thu Dec 16 07:51:54 2021" "
+ "WSD Port" "Adaptive Port Monitor" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\APMon.dll" "Thu Dec 16 07:54:54 2021" "
[HKLM\System\CurrentControlSet\Control\Print\Providers]
+ "HTTP Print Services" "Internet Print Provider DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\inetpp.dll" "Thu Dec 16 07:56:55 2021" "
+ "LanMan Print Services" "Client Side Rendering Print Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\win32spl.dll" "Thu Dec 16 07:51:44 2021" "
[LSA Providers]
[HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\SecurityProviders]
+ "credssp.dll" "Credential Delegation Security Package" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\credssp.dll" "Thu Dec 16 07:54:57 2021" "
[HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Authentication Packages]
+ "msv1_0" "Microsoft Authentication Package v1.0" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\msv1_0.dll" "Thu Dec 16 07:53:45 2021" "
[HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Notification Packages]
+ "scecli" "Windows Security Configuration Editor Client Engine" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\scecli.dll" "Sat Jun 5 13:05:40 2021" "
[HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Security Packages]
[HKLM\SYSTEM\CurrentControlSet\Control\Lsa\OSConfig\Security Packages]
[Network Providers]
[HKLM\SYSTEM\CurrentControlSet\Control\NetworkProvider\Order]
+ "LanmanWorkstation" "Microsoft Windows Network" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\ntlanman.dll" "Thu Dec 16 07:53:53 2021" "
+ "P9NP" "Plan 9 Network Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\p9np.dll" "Sat Jun 5 13:06:17 2021" "
+ "RDPNP" "Microsoft Terminal Services" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drprov.dll" "Sat Jun 5 13:06:14 2021" "
+ "webclient" "Web Client Network" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\davclnt.dll" "Sat Jun 5 13:06:17 2021" "
[WMI]
[WMI Database Entries]
[Office]
[HKCU\Software\Microsoft\Office\Outlook\Addins]
[HKCU\Software\Microsoft\Office\Excel\Addins]
[HKCU\Software\Microsoft\Office\PowerPoint\Addins]
[HKCU\Software\Microsoft\Office\Word\Addins]
[HKCU\Software\Microsoft\Office\Access\Addins]
[HKCU\Software\Microsoft\Office\OneNote\Addins]
[HKCU\SOFTWARE\Microsoft\Office test\Special\Perf\(Default)]
[HKCU\Software\Wow6432Node\Microsoft\Office\Outlook\Addins]
[HKCU\Software\Wow6432Node\Microsoft\Office\Excel\Addins]
[HKCU\Software\Wow6432Node\Microsoft\Office\PowerPoint\Addins]
[HKCU\Software\Wow6432Node\Microsoft\Office\Word\Addins]
[HKCU\Software\Wow6432Node\Microsoft\Office\Access\Addins]
[HKCU\Software\Wow6432Node\Microsoft\Office\OneNote\Addins]
[HKCU\SOFTWARE\Wow6432Node\Microsoft\Office test\Special\Perf\(Default)]
[HKLM\Software\Microsoft\Office\Outlook\Addins]
[HKLM\Software\Microsoft\Office\Excel\Addins]
[HKLM\Software\Microsoft\Office\PowerPoint\Addins]
[HKLM\Software\Microsoft\Office\Word\Addins]
[HKLM\Software\Microsoft\Office\Access\Addins]
[HKLM\Software\Microsoft\Office\OneNote\Addins]
[HKLM\SOFTWARE\Microsoft\Office test\Special\Perf\(Default)]
[HKLM\Software\Wow6432Node\Microsoft\Office\Outlook\Addins]
[HKLM\Software\Wow6432Node\Microsoft\Office\Excel\Addins]
[HKLM\Software\Wow6432Node\Microsoft\Office\PowerPoint\Addins]
[HKLM\Software\Wow6432Node\Microsoft\Office\Word\Addins]
[HKLM\Software\Wow6432Node\Microsoft\Office\Access\Addins]
[HKLM\Software\Wow6432Node\Microsoft\Office\OneNote\Addins]
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Office test\Special\Perf\(Default)]
 
Hope this is correct :)

[Logon]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System\Shell]
[HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell]
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
+ "CCleaner Smart Cleaning" "CCleaner" "(Verified) Piriform Software Ltd" "C:\Program Files\CCleaner\CCleaner64.exe" "Tue Dec 7 19:06:42 2021" "
+ "Norton Download Manager{NSBU222005-SHPD-FSD52405}" "Norton Download Manager" "(Verified) NortonLifeLock Inc." "C:\Users\Public\Downloads\Norton\{NSBU222005-SHPD-FSD52405}\FSDUI_Custom.exe" "Fri Dec 17 16:35:00 2021" "
+ "OneDrive" "Microsoft OneDrive" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\OneDrive.exe" "Tue Dec 7 07:14:41 2021" "
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx]
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
[HKCU\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
[HKCU\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce]
[HKCU\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnceEx]
[HKCU\Environment\UserInitMprLogonScript]
[HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows\Load]
[HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows\Run]
[HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\RunOnce]
[HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\RunOnceEx]
[HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\Run]
[HKLM\System\CurrentControlSet\Control\Terminal Server\Wds\rdpwd\StartupPrograms]
+ "rdpclip" "RDP Clipboard Monitor" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\rdpclip.exe" "Thu Dec 16 07:56:43 2021" "
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\AppSetup]
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
+ "RtkAudUService" "Realtek HD Audio Universal Service" "(Verified) Realtek Semiconductor Corp." "C:\WINDOWS\System32\DriverStore\FileRepository\realtekservice.inf_amd64_f043f909bedcd504\RtkAudUService64.exe" "Wed Oct 6 20:03:40 2021" "
+ "SecurityHealth" "Windows Security notification icon" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\SecurityHealthSystray.exe" "Thu Dec 16 07:53:16 2021" "
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
+ "msedge_cleanup_{F3017226-FE2A-4295-8BDF-00C3A9A7E4C5}" "Microsoft Edge Installer" "(Verified) Microsoft Corporation" "C:\Program Files (x86)\Microsoft\EdgeWebView\Application\96.0.1054.57\Installer\setup.exe" "Thu Dec 16 17:39:31 2021" "
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\Shell]
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell]
+ "explorer.exe" "Windows Explorer" "(Verified) Microsoft Windows" "C:\WINDOWS\explorer.exe" "Thu Dec 16 07:51:50 2021" "
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\AlternateShell]
+ "cmd.exe" "Windows Command Processor" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\cmd.exe" "Sat Jun 5 13:05:12 2021" "
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\TaskMan]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\UserInit]
+ "C:\Windows\system32\userinit.exe" "Userinit Log-on Application" "(Verified) Microsoft Windows" "C:\Windows\system32\userinit.exe" "Thu Dec 16 07:53:45 2021" "
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\VmApplet]
+ "SystemPropertiesPerformance.exe /pagefile" "Change Computer Performance Settings" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\SystemPropertiesPerformance.exe" "Sat Jun 5 13:05:34 2021" "
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\AlternateShells\AvailableShells]
[HKLM\Environment\UserInitMprLogonScript]
[HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components]
+ "Google Chrome" "Google Chrome Installer" "(Verified) Google LLC" "C:\Program Files\Google\Chrome\Application\96.0.4664.110\Installer\chrmstp.exe" "Wed Dec 15 22:49:20 2021" "
+ "Microsoft Edge" "Microsoft Edge Installer" "(Verified) Microsoft Corporation" "C:\Program Files (x86)\Microsoft\Edge\Application\96.0.1054.62\Installer\setup.exe" "Sun Dec 19 15:21:26 2021" "
+ "Microsoft Windows Media Player" "Microsoft Windows Media Player Setup Utility" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\unregmp2.exe" "Sat Jun 5 02:35:00 2021" "
+ "Microsoft Windows Media Player" "Microsoft Windows Media Player Setup Utility" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\unregmp2.exe" "Sat Jun 5 02:35:00 2021" "
+ "n/a" "Microsoft .NET IE SECURITY REGISTRATION" "(Verified) Microsoft Corporation" "C:\Windows\System32\mscories.dll" "Sat Jun 5 13:06:26 2021" "
+ "Themes Setup" "Windows Theme API" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\themeui.dll" "Thu Dec 16 07:52:59 2021" "
+ "Web Platform Customizations" "IE Per-User Initialisation Utility" "(Verified) Microsoft Windows" "C:\Windows\System32\ie4uinit.exe" "Thu Dec 16 07:56:33 2021" "
+ "Windows Desktop Update" "Windows Shell Common Dll" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\shell32.dll" "Thu Dec 16 07:54:27 2021" "
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows\IconServiceLib]
+ "IconCodecService.dll" "Converts a PNG part of the icon to a legacy bmp icon" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\IconCodecService.dll" "Sat Jun 5 13:05:29 2021" "
[HKLM\SOFTWARE\Microsoft\Windows CE Services\AutoStartOnConnect]
[HKLM\SOFTWARE\Microsoft\Windows CE Services\AutoStartDisconnect]
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
+ "msedge_cleanup_{F3017226-FE2A-4295-8BDF-00C3A9A7E4C5}" "Microsoft Edge Installer" "(Verified) Microsoft Corporation" "C:\Program Files (x86)\Microsoft\EdgeWebView\Application\96.0.1054.57\Installer\setup.exe" "Thu Dec 16 17:39:31 2021" "
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce]
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnceEx]
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Active Setup\Installed Components]
+ "Microsoft Windows Media Player" "Microsoft Windows Media Player Setup Utility" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\unregmp2.exe" "Sat Jun 5 01:03:00 2021" "
+ "Microsoft Windows Media Player" "Microsoft Windows Media Player Setup Utility" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\unregmp2.exe" "Sat Jun 5 01:03:00 2021" "
+ "n/a" "Microsoft .NET IE SECURITY REGISTRATION" "(Verified) Microsoft Corporation" "C:\Windows\System32\mscories.dll" "Sat Jun 5 13:06:26 2021" "
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows CE Services\AutoStartOnConnect]
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows CE Services\AutoStartOnDisconnect]
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\RunOnce]
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\RunOnceEx]
[HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp\InitialProgram]
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
[C:\Users\chris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup]
[C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup]
[%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup]
[HKCU\Software\Policies\Microsoft\Windows\System\Scripts\Logon]
[HKCU\Software\Policies\Microsoft\Windows\System\Scripts\Logoff]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Startup]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Logon]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Logoff]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Shutdown]
[HKLM\Software\Policies\Microsoft\Windows\System\Scripts\Startup]
[HKLM\Software\Policies\Microsoft\Windows\System\Scripts\Logon]
[HKLM\Software\Policies\Microsoft\Windows\System\Scripts\Logoff]
[HKLM\Software\Policies\Microsoft\Windows\System\Scripts\Shutdown]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Shutdown]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Logoff]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Logon]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Startup]
[Explorer]
[HKCU\SOFTWARE\Classes\Protocols\Filter]
[HKCU\SOFTWARE\Classes\Protocols\Handler]
[HKCU\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components]
[HKCU\Software\Classes\*\ShellEx\ContextMenuHandlers]
[HKCU\Software\Classes\Drive\ShellEx\ContextMenuHandlers]
[HKCU\Software\Classes\*\ShellEx\PropertySheetHandlers]
[HKCU\Software\Classes\AllFileSystemObjects\ShellEx\ContextMenuHandlers]
[HKCU\Software\Classes\AllFileSystemObjects\ShellEx\DragDropHandlers]
[HKCU\Software\Classes\AllFileSystemObjects\ShellEx\PropertySheetHandlers]
[HKCU\Software\Classes\Directory\ShellEx\ContextMenuHandlers]
[HKCU\Software\Classes\Directory\ShellEx\DragDropHandlers]
[HKCU\Software\Classes\Directory\ShellEx\PropertySheetHandlers]
[HKCU\Software\Classes\Directory\ShellEx\CopyHookHandlers]
[HKCU\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers]
[HKCU\Software\Classes\Folder\ShellEx\ContextMenuHandlers]
[HKCU\Software\Classes\Folder\ShellEx\DragDropHandlers]
[HKCU\Software\Classes\Folder\ShellEx\PropertySheetHandlers]
[HKCU\Software\Classes\Folder\ShellEx\ColumnHandlers]
[HKCU\Software\Classes\Folder\ShellEx\ExtShellFolderViews]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers]
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
[HKCU\Software\Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\InProcServer32]
[HKCU\Software\Microsoft\Ctf\LangBarAddin]
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellServiceObjects]
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellServiceObjects]
+ "Published Items Shell Service Object" "Windows Shell Common Dll" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\shell32.dll" "Thu Dec 16 07:54:27 2021" "
+ "Microsoft VolumeControlService Class" "SCA Volume" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\SndVolSSO.dll" "Thu Dec 16 07:53:36 2021" "
+ "Windows To Go Shell Service Object" "Windows To Go Shell Service Object" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\pwsso.dll" "Sat Jun 5 13:06:10 2021" "
+ "Device Stage Shell Extension" "Device Stage Shell Extension" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\dxp.dll" "Sat Jun 5 13:06:05 2021" "
+ "Cloud Cache Invalidator SSO" "Cloud Data Store" "(Verified) Microsoft Windows" "C:\Windows\System32\Windows.CloudStore.dll" "Thu Dec 16 07:52:04 2021" "
+ "UnexpectedShutdownReason" "Systray shell service object" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\stobject.dll" "Thu Dec 16 07:51:51 2021" "
+ "PostBootReminder object" "Windows Shell Common Dll" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\shell32.dll" "Thu Dec 16 07:54:27 2021" "
+ "OneDrive network states cache SSO" "Windows.FileExplorer.Common" "(Verified) Microsoft Windows" "C:\Windows\System32\Windows.FileExplorer.Common.dll" "Thu Dec 16 07:54:27 2021" "
+ "Library Group Policy Shell Service Object" "Microsoft WinRT Storage API" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\windows.storage.dll" "Thu Dec 16 07:52:34 2021" "
+ "Windows System Reset SSO" "Windows System Reset Platform SSO" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\SystemResetPlatform\SystemResetSSO.dll" "Sat Jun 5 13:06:11 2021" "
+ "User Account Control Check Service" "Security and Maintenance Providers" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\hcproviders.dll" "Sat Jun 5 13:05:29 2021" "
+ "WPDShServiceObj Class" "Windows Portable Device Shell Service Object" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wpdshserviceobj.dll" "Sat Jun 5 18:16:58 2021" "
+ "Network Tray SSO" "Network System Icon" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\pnidui.dll" "Thu Dec 16 07:54:50 2021" "
+ "Windows Search Shell Service Object" "Indexing Options" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\srchadmin.dll" "Sat Jun 5 13:05:40 2021" "
+ "WebCheck" "Shell Doc Object and Control Library" "(Verified) Microsoft Windows" "C:\Windows\System32\shdocvw.dll" "Thu Dec 16 07:54:26 2021" "
+ "Bluetooth Authentication Agent SSO" "Bluetooth Control Panel Applet" "(Verified) Microsoft Windows" "C:\Windows\System32\bthprops.cpl" "Sat Jun 5 13:05:23 2021" "
+ "Sync Center Shell Service Object (Internal)" "Microsoft Sync Centre" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\SyncCenter.dll" "Sat Jun 5 13:06:11 2021" "
+ "Security and Maintenance Shell Service Object" "Security and Maintenance" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Actioncenter.dll" "Sat Jun 5 13:05:29 2021" "
+ "ShellFolder for CD Burning" "Windows Shell Common Dll" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\shell32.dll" "Thu Dec 16 07:54:27 2021" "
+ "HomeGroup SSO" "HomeGroup Control Panel" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\hgcpl.dll" "Sat Jun 5 13:05:29 2021" "
[HKLM\SOFTWARE\Classes\Protocols\Filter]
+ "application/octet-stream" "Microsoft .NET Runtime Execution Engine" "(Verified) Microsoft Windows" "C:\Windows\System32\mscoree.dll" "Sat Jun 5 13:06:26 2021" "
+ "application/x-complus" "Microsoft .NET Runtime Execution Engine" "(Verified) Microsoft Windows" "C:\Windows\System32\mscoree.dll" "Sat Jun 5 13:06:26 2021" "
+ "application/x-msdownload" "Microsoft .NET Runtime Execution Engine" "(Verified) Microsoft Windows" "C:\Windows\System32\mscoree.dll" "Sat Jun 5 13:06:26 2021" "
+ "text/xml" "Microsoft Office XML MIME Filter" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\MSOXMLMF.DLL" "Fri Dec 10 12:44:05 2021" "
[HKLM\SOFTWARE\Classes\Protocols\Handler]
+ "about" "Microsoft (R) HTML Viewer" "(Verified) Microsoft Windows" "C:\Windows\System32\mshtml.dll" "Thu Dec 16 07:56:36 2021" "
+ "cdl" "OLE32 Extensions for Win32" "(Verified) Microsoft Windows" "C:\Windows\System32\urlmon.dll" "Thu Dec 16 07:54:22 2021" "
+ "dvd" "ActiveX control for streaming video" "(Verified) Microsoft Windows" "C:\Windows\System32\msvidctl.dll" "Sat Jun 5 13:06:14 2021" "
+ "file" "OLE32 Extensions for Win32" "(Verified) Microsoft Windows" "C:\Windows\System32\urlmon.dll" "Thu Dec 16 07:54:22 2021" "
+ "ftp" "OLE32 Extensions for Win32" "(Verified) Microsoft Windows" "C:\Windows\System32\urlmon.dll" "Thu Dec 16 07:54:22 2021" "
+ "http" "OLE32 Extensions for Win32" "(Verified) Microsoft Windows" "C:\Windows\System32\urlmon.dll" "Thu Dec 16 07:54:22 2021" "
+ "https" "OLE32 Extensions for Win32" "(Verified) Microsoft Windows" "C:\Windows\System32\urlmon.dll" "Thu Dec 16 07:54:22 2021" "
+ "its" "Microsoft® InfoTech Storage System Library" "(Verified) Microsoft Windows" "C:\Windows\System32\itss.dll" "Sat Jun 5 13:06:05 2021" "
+ "javascript" "Microsoft (R) HTML Viewer" "(Verified) Microsoft Windows" "C:\Windows\System32\mshtml.dll" "Thu Dec 16 07:56:36 2021" "
+ "local" "OLE32 Extensions for Win32" "(Verified) Microsoft Windows" "C:\Windows\System32\urlmon.dll" "Thu Dec 16 07:54:22 2021" "
+ "mailto" "Microsoft (R) HTML Viewer" "(Verified) Microsoft Windows" "C:\Windows\System32\mshtml.dll" "Thu Dec 16 07:56:36 2021" "
+ "mhtml" "Microsoft Internet Messaging API Resources" "(Verified) Microsoft Windows" "C:\Windows\System32\inetcomm.dll" "Sat Jun 5 13:06:07 2021" "
+ "mk" "OLE32 Extensions for Win32" "(Verified) Microsoft Windows" "C:\Windows\System32\urlmon.dll" "Thu Dec 16 07:54:22 2021" "
+ "ms-its" "Microsoft® InfoTech Storage System Library" "(Verified) Microsoft Windows" "C:\Windows\System32\itss.dll" "Sat Jun 5 13:06:05 2021" "
+ "mso-minsb-roaming.16" "Microsoft Office component" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL" "Fri Dec 10 12:41:11 2021" "
+ "mso-minsb.16" "Microsoft Office component" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL" "Fri Dec 10 12:41:11 2021" "
+ "osf-roaming.16" "Microsoft Office component" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL" "Fri Dec 10 12:41:11 2021" "
+ "osf.16" "Microsoft Office component" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL" "Fri Dec 10 12:41:11 2021" "
+ "res" "Microsoft (R) HTML Viewer" "(Verified) Microsoft Windows" "C:\Windows\System32\mshtml.dll" "Thu Dec 16 07:56:36 2021" "
+ "tbauth" "TBAuth protocol handler" "(Verified) Microsoft Windows" "C:\Windows\System32\tbauth.dll" "Thu Dec 16 07:52:14 2021" "
+ "tv" "ActiveX control for streaming video" "(Verified) Microsoft Windows" "C:\Windows\System32\msvidctl.dll" "Sat Jun 5 13:06:14 2021" "
+ "vbscript" "Microsoft (R) HTML Viewer" "(Verified) Microsoft Windows" "C:\Windows\System32\mshtml.dll" "Thu Dec 16 07:56:36 2021" "
+ "windows.tbauth" "TBAuth protocol handler" "(Verified) Microsoft Windows" "C:\Windows\System32\tbauth.dll" "Thu Dec 16 07:52:14 2021" "
[HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers]
+ " FileSyncEx" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ "EPP" "Microsoft Security Client Shell Extension" "(Verified) Microsoft Windows" "C:\Program Files\Windows Defender\shellext.dll" "Sat Jun 5 13:04:55 2021" "
+ "Open With" "Windows Shell Common Dll" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\shell32.dll" "Thu Dec 16 07:54:27 2021" "
+ "Open With EncryptionMenu" "Windows Shell Common Dll" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\shell32.dll" "Thu Dec 16 07:54:27 2021" "
+ "Sharing" "Shell extensions for sharing" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\ntshrui.dll" "Thu Dec 16 07:54:27 2021" "
+ "WorkFolders" "Microsoft (C) Work Folders Shell Extension" "(Verified) Microsoft Windows" "C:\Windows\System32\WorkfoldersShell.dll" "Sat Jun 5 13:06:16 2021" "
+ "Taskband Pin" "Windows Shell Common Dll" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\shell32.dll" "Thu Dec 16 07:54:27 2021" "
+ "Start Menu Pin" "Windows Shell Common Dll" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\shell32.dll" "Thu Dec 16 07:54:27 2021" "
[HKLM\Software\Classes\Drive\ShellEx\ContextMenuHandlers]
+ "EnhancedStorageShell" "Windows Enhanced Storage Shell Extension DLL" "(Verified) Microsoft Windows" "C:\Windows\System32\EhStorShell.dll" "Sat Jun 5 13:05:29 2021" "
+ "EPP" "Microsoft Security Client Shell Extension" "(Verified) Microsoft Windows" "C:\Program Files\Windows Defender\shellext.dll" "Sat Jun 5 13:04:55 2021" "
+ "Sharing" "Shell extensions for sharing" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\ntshrui.dll" "Thu Dec 16 07:54:27 2021" "
+ "Previous Versions Property Page" "Previous Versions property page" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\twext.dll" "Sat Jun 5 13:05:33 2021" "
+ "Portable Devices Menu" "Portable Devices Shell Extension" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wpdshext.dll" "Sat Jun 5 18:16:58 2021" "
+ "ShellFolder for CD Burning" "Windows Shell Common Dll" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\shell32.dll" "Thu Dec 16 07:54:27 2021" "
[HKLM\Software\Classes\*\ShellEx\PropertySheetHandlers]
+ "CryptoSignMenu" "Crypto Shell Extensions" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\cryptext.dll" "Sat Jun 5 13:05:27 2021" "
+ "Security Shell Extension" "Security Shell Extension" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\rshx32.dll" "Sat Jun 5 13:06:02 2021" "
+ "OLE DocFile Property Page" "OLE DocFile Property Page" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\docprop.dll" "Sat Jun 5 13:05:33 2021" "
+ "Summary Properties Page" "Windows Shell Common Dll" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\shell32.dll" "Thu Dec 16 07:54:27 2021" "
[HKLM\Software\Classes\AllFileSystemObjects\ShellEx\ContextMenuHandlers]
+ "CopyAsPathMenu" "Windows Shell Common Dll" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\shell32.dll" "Thu Dec 16 07:54:27 2021" "
+ "ModernSharing" "Shell extensions for sharing" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\ntshrui.dll" "Thu Dec 16 07:54:27 2021" "
+ "SendTo" "Windows Shell Common Dll" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\shell32.dll" "Thu Dec 16 07:54:27 2021" "
+ "Previous Versions Property Page" "Previous Versions property page" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\twext.dll" "Sat Jun 5 13:05:33 2021" "
+ "Start Menu Pin" "Windows Shell Common Dll" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\shell32.dll" "Thu Dec 16 07:54:27 2021" "
[HKLM\Software\Classes\AllFileSystemObjects\ShellEx\DragDropHandlers]
[HKLM\Software\Classes\AllFileSystemObjects\ShellEx\PropertySheetHandlers]
+ "Previous Versions Property Page" "Previous Versions property page" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\twext.dll" "Sat Jun 5 13:05:33 2021" "
[HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers]
+ " FileSyncEx" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ "EncryptionMenu" "Windows Shell Common Dll" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\shell32.dll" "Thu Dec 16 07:54:27 2021" "
+ "EPP" "Microsoft Security Client Shell Extension" "(Verified) Microsoft Windows" "C:\Program Files\Windows Defender\shellext.dll" "Sat Jun 5 13:04:55 2021" "
+ "Sharing" "Shell extensions for sharing" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\ntshrui.dll" "Thu Dec 16 07:54:27 2021" "
+ "WorkFolders" "Microsoft (C) Work Folders Shell Extension" "(Verified) Microsoft Windows" "C:\Windows\System32\WorkfoldersShell.dll" "Sat Jun 5 13:06:16 2021" "
+ "Previous Versions Property Page" "Previous Versions property page" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\twext.dll" "Sat Jun 5 13:05:33 2021" "
[HKLM\Software\Classes\Directory\ShellEx\DragDropHandlers]
[HKLM\Software\Classes\Directory\ShellEx\PropertySheetHandlers]
+ "Sharing" "Shell extensions for sharing" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\ntshrui.dll" "Thu Dec 16 07:54:27 2021" "
+ "Security Shell Extension" "Security Shell Extension" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\rshx32.dll" "Sat Jun 5 13:06:02 2021" "
+ "MyFolder menu and properties" "My Documents Folder UI" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mydocs.dll" "Sat Jun 5 13:05:14 2021" "
+ "Previous Versions Property Page" "Previous Versions property page" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\twext.dll" "Sat Jun 5 13:05:33 2021" "
+ "DfsShell Class" "Distributed File System shell extension" "(Verified) Microsoft Windows" "C:\Windows\System32\DfsShlEx.dll" "Sat Jun 5 13:05:37 2021" "
+ "Folder Customization Tab" "Windows Shell Common Dll" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\shell32.dll" "Thu Dec 16 07:54:27 2021" "
[HKLM\Software\Classes\Directory\ShellEx\CopyHookHandlers]
+ "FileSystem" "Windows Shell Common Dll" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\shell32.dll" "Thu Dec 16 07:54:27 2021" "
+ "Sharing" "Shell extensions for sharing" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\ntshrui.dll" "Thu Dec 16 07:54:27 2021" "
[HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers]
+ " FileSyncEx" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ "New" "Windows Shell Common Dll" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\shell32.dll" "Thu Dec 16 07:54:27 2021" "
+ "Sharing" "Shell extensions for sharing" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\ntshrui.dll" "Thu Dec 16 07:54:27 2021" "
+ "WorkFolders" "Microsoft (C) Work Folders Shell Extension" "(Verified) Microsoft Windows" "C:\Windows\System32\WorkfoldersShell.dll" "Sat Jun 5 13:06:16 2021" "
[HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers]
+ "Library Location" "Windows Shell Common Dll" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\shell32.dll" "Thu Dec 16 07:54:27 2021" "
+ "PintoStartScreen" "App Resolver" "(Verified) Microsoft Windows" "C:\Windows\System32\appresolver.dll" "Thu Dec 16 07:53:11 2021" "
+ "Start Menu Pin" "Windows Shell Common Dll" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\shell32.dll" "Thu Dec 16 07:54:27 2021" "
[HKLM\Software\Classes\Folder\ShellEx\DragDropHandlers]
+ "Compressed (zipped) Folder Right Drag Handler" "Compressed (zipped) Folders" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\zipfldr.dll" "Thu Dec 16 07:53:41 2021" "
[HKLM\Software\Classes\Folder\ShellEx\PropertySheetHandlers]
[HKLM\Software\Classes\Folder\ShellEx\ColumnHandlers]
[HKLM\Software\Classes\Folder\ShellEx\ExtShellFolderViews]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers]
+ " OneDrive1" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ " OneDrive2" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ " OneDrive3" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ " OneDrive4" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ " OneDrive5" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ " OneDrive6" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ " OneDrive7" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ " OneDrive1" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ " OneDrive2" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ " OneDrive3" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ " OneDrive4" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ " OneDrive5" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ " OneDrive6" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ " OneDrive7" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ "EnhancedStorageShell" "Windows Enhanced Storage Shell Extension DLL" "(Verified) Microsoft Windows" "C:\Windows\System32\EhStorShell.dll" "Sat Jun 5 13:05:29 2021" "
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
[HKLM\Software\Microsoft\Ctf\LangBarAddin]
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
[HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellServiceObjects]
+ "Published Items Shell Service Object" "Windows Shell Common Dll" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\shell32.dll" "Thu Dec 16 07:56:19 2021" "
+ "Microsoft VolumeControlService Class" "SCA Volume" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\SndVolSSO.dll" "Thu Dec 16 07:55:56 2021" "
+ "UnexpectedShutdownReason" "Systray shell service object" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\stobject.dll" "Thu Dec 16 07:55:17 2021" "
+ "PostBootReminder object" "Windows Shell Common Dll" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\shell32.dll" "Thu Dec 16 07:56:19 2021" "
+ "OneDrive network states cache SSO" "Windows.FileExplorer.Common" "(Verified) Microsoft Windows" "C:\Windows\Syswow64\Windows.FileExplorer.Common.dll" "Thu Dec 16 07:56:19 2021" "
+ "Library Group Policy Shell Service Object" "Microsoft WinRT Storage API" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\windows.storage.dll" "Thu Dec 16 07:55:47 2021" "
+ "User Account Control Check Service" "Security and Maintenance Providers" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\hcproviders.dll" "Sat Jun 5 13:05:55 2021" "
+ "WPDShServiceObj Class" "Windows Portable Device Shell Service Object" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\wpdshserviceobj.dll" "Sat Jun 5 18:17:05 2021" "
+ "Windows Search Shell Service Object" "Indexing Options" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\srchadmin.dll" "Sat Jun 5 13:06:00 2021" "
+ "WebCheck" "Shell Doc Object and Control Library" "(Verified) Microsoft Windows" "C:\Windows\Syswow64\shdocvw.dll" "Thu Dec 16 07:56:18 2021" "
+ "Bluetooth Authentication Agent SSO" "Bluetooth Control Panel Applet" "(Verified) Microsoft Windows" "C:\Windows\Syswow64\bthprops.cpl" "Sat Jun 5 13:05:53 2021" "
+ "Sync Center Shell Service Object (Internal)" "Microsoft Sync Center" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\SyncCenter.dll" "Sat Jun 5 13:06:24 2021" "
+ "Security and Maintenance Shell Service Object" "Security and Maintenance" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\Actioncenter.dll" "Sat Jun 5 13:05:55 2021" "
+ "ShellFolder for CD Burning" "Windows Shell Common Dll" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\shell32.dll" "Thu Dec 16 07:56:19 2021" "
+ "HomeGroup SSO" "HomeGroup Control Panel" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\hgcpl.dll" "Sat Jun 5 13:05:55 2021" "
[HKLM\Software\Wow6432Node\Classes\*\ShellEx\ContextMenuHandlers]
[HKLM\Software\Wow6432Node\Classes\Drive\ShellEx\ContextMenuHandlers]
[HKLM\Software\Wow6432Node\Classes\*\ShellEx\PropertySheetHandlers]
[HKLM\Software\Wow6432Node\Classes\AllFileSystemObjects\ShellEx\ContextMenuHandlers]
[HKLM\Software\Wow6432Node\Classes\AllFileSystemObjects\ShellEx\DragDropHandlers]
[HKLM\Software\Wow6432Node\Classes\AllFileSystemObjects\ShellEx\PropertySheetHandlers]
[HKLM\Software\Wow6432Node\Classes\Directory\ShellEx\ContextMenuHandlers]
[HKLM\Software\Wow6432Node\Classes\Directory\ShellEx\DragDropHandlers]
[HKLM\Software\Wow6432Node\Classes\Directory\ShellEx\PropertySheetHandlers]
[HKLM\Software\Wow6432Node\Classes\Directory\ShellEx\CopyHookHandlers]
[HKLM\Software\Wow6432Node\Classes\Directory\Background\ShellEx\ContextMenuHandlers]
[HKLM\Software\Wow6432Node\Classes\Folder\ShellEx\ContextMenuHandlers]
[HKLM\Software\Wow6432Node\Classes\Folder\ShellEx\DragDropHandlers]
[HKLM\Software\Wow6432Node\Classes\Folder\ShellEx\PropertySheetHandlers]
[HKLM\Software\Wow6432Node\Classes\Folder\ShellEx\ColumnHandlers]
[HKLM\Software\Wow6432Node\Classes\Folder\ShellEx\ExtShellFolderViews]
[HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers]
+ " OneDrive1" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ " OneDrive2" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ " OneDrive3" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ " OneDrive4" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ " OneDrive5" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ " OneDrive6" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ " OneDrive7" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ " OneDrive1" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ " OneDrive2" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ " OneDrive3" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ " OneDrive4" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ " OneDrive5" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ " OneDrive6" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
+ " OneDrive7" "Microsoft OneDrive Shell Extension" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncShell64.dll" "Tue Dec 7 07:14:38 2021" "
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
[HKLM\Software\Wow6432Node\Microsoft\Ctf\LangBarAddin]
[Internet Explorer]
[HKCU\Software\Microsoft\Internet Explorer\UrlSearchHooks]
+ "Microsoft Url Search Hook" "Internet Browser" "(Verified) Microsoft Windows" "C:\Windows\System32\ieframe.dll" "Thu Dec 16 07:56:37 2021" "
[HKCU\Software\Microsoft\Internet Explorer\Explorer Bars]
[HKCU\Software\Microsoft\Internet Explorer\Extensions]
[HKCU\Software\Wow6432Node\Microsoft\Internet Explorer\Explorer Bars]
[HKCU\Software\Wow6432Node\Microsoft\Internet Explorer\Extensions]
[HKLM\Software\Microsoft\Internet Explorer\Toolbar]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
+ "IEToEdge BHO" "IEToEdge BHO" "(Verified) Microsoft Corporation" "C:\Program Files (x86)\Microsoft\Edge\Application\96.0.1054.62\BHO\ie_to_edge_bho_64.dll" "Thu Dec 16 22:46:17 2021" "
[HKLM\Software\Microsoft\Internet Explorer\Explorer Bars]
[HKLM\Software\Microsoft\Internet Explorer\Extensions]
+ "OneNote Lin&ked Notes" "Microsoft OneNote Internet Explorer Add-in" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft Office\root\Office16\ONBttnIELinkedNotes.dll" "Sat Dec 18 15:21:43 2021" "
+ "Se&nd to OneNote" "Microsoft OneNote Internet Explorer Add-in" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft Office\root\Office16\ONBttnIE.dll" "Fri Dec 10 12:41:14 2021" "
[HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
[HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
+ "IEToEdge BHO" "IEToEdge BHO" "(Verified) Microsoft Corporation" "C:\Program Files (x86)\Microsoft\Edge\Application\96.0.1054.62\BHO\ie_to_edge_bho.dll" "Thu Dec 16 22:46:17 2021" "
+ "Skype for Business Browser Helper" "Skype for Business" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll" "Mon Nov 1 13:01:20 2021" "
[HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Explorer Bars]
[HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Extensions]
+ "Lync Click to Call" "Skype for Business" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll" "Mon Nov 1 13:01:20 2021" "
+ "OneNote Lin&ked Notes" "Microsoft OneNote Internet Explorer Add-in" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\ONBttnIELinkedNotes.dll" "Sat Dec 18 15:22:07 2021" "
+ "Se&nd to OneNote" "Microsoft OneNote Internet Explorer Add-in" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\ONBttnIE.dll" "Fri Dec 10 12:43:31 2021" "
[Scheduled Tasks]
[Task Scheduler]
+ "\ACCBackgroundApplication" "Acer Care Center background application" "(Verified) Acer Incorporated" "C:\Program Files (x86)\Acer\Care Center\ACCStd.exe" "Wed Nov 17 15:08:30 2021" "
+ "\App Explorer" "Host App Service Updater" "(Verified) SweetLabs Inc." "C:\Users\chris\AppData\Local\Host App Service\Engine\HostAppServiceUpdater.exe" "Mon Nov 15 21:29:44 2021" "
+ "\Christmas Task (One-Time)" "" "" "File not found: C:\Program Files (x86)\IObit\Advanced SystemCare\xmas.exe" "" "
+ "\GoTrust ID Driver" "GoTrust ID Driver" "(Verified) GoTrustID Inc" "C:\Program Files\GoTrust ID Plugin\Resource\GO-Trust_ID_Driver.exe" "Tue Sep 8 09:48:02 2020" "
+ "\OneDrive Per-Machine Standalone Update Task" "Standalone Updater" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe" "Tue Dec 7 07:14:41 2021" "
+ "\OneDrive Reporting Task-S-1-5-21-118655992-338211945-2329846050-1001" "Standalone Updater" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe" "Tue Dec 7 07:14:41 2021" "
+ X "\Agent Activation Runtime\S-1-5-21-118655992-338211945-2329846050-1001" "" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\AgentActivationRuntimeStarter.exe" "Sat Jun 5 13:04:52 2021" "
+ "\Microsoft\Office\Office Automatic Updates 2.0" "This task ensures that your Microsoft Office installation can check for updates." "(Verified) Microsoft Corporation" "C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe" "Fri Dec 10 00:10:56 2021" "
+ "\Microsoft\Office\Office ClickToRun Service Monitor" "This task monitors the state of your Microsoft Office ClickToRunSvc and sends crash and error logs to Microsoft." "(Verified) Microsoft Corporation" "C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe" "Fri Dec 10 00:10:56 2021" "
+ "\Microsoft\Office\Office Feature Updates" "This task ensures that your Microsoft Office installation can check for feature updates." "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe" "Sat Dec 18 15:21:51 2021" "
+ "\Microsoft\Office\Office Feature Updates Logon" "This task ensures that your Microsoft Office installation can check for feature updates." "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe" "Sat Dec 18 15:21:51 2021" "
+ "\Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319" "Microsoft .NET Runtime Execution Engine" "(Verified) Microsoft Windows" "C:\Windows\System32\mscoree.dll" "Sat Jun 5 13:06:26 2021" "
+ "\Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 64" "Microsoft .NET Runtime Execution Engine" "(Verified) Microsoft Windows" "C:\Windows\System32\mscoree.dll" "Sat Jun 5 13:06:26 2021" "
+ X "\Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 64 Critical" "Microsoft .NET Runtime Execution Engine" "(Verified) Microsoft Windows" "C:\Windows\System32\mscoree.dll" "Sat Jun 5 13:06:26 2021" "
+ X "\Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 Critical" "Microsoft .NET Runtime Execution Engine" "(Verified) Microsoft Windows" "C:\Windows\System32\mscoree.dll" "Sat Jun 5 13:06:26 2021" "
+ X "\Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Automated)" "Windows Rights Management client" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\msdrm.dll" "Sat Jun 5 13:04:58 2021" "
+ "\Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Manual)" "Windows Rights Management client" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\msdrm.dll" "Sat Jun 5 13:04:58 2021" "
+ X "\Microsoft\Windows\AppID\PolicyConverter" "Converts the software restriction policies policy from XML into binary format." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\appidpolicyconverter.exe" "Sat Jun 5 13:05:23 2021" "
+ X "\Microsoft\Windows\AppID\VerifiedPublisherCertStoreCheck" "Inspects the AppID certificate cache for invalid or revoked certificates." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\appidcertstorecheck.exe" "Sat Jun 5 13:05:23 2021" "
+ "\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser" "Collects program telemetry information if opted-in to the Microsoft Customer Experience Improvement Program." "(Verified) Microsoft Corporation" "C:\WINDOWS\system32\compattelrunner.exe" "Sat Jun 5 13:05:21 2021" "
+ "\Microsoft\Windows\Application Experience\PcaPatchDbTask" "Updates compatibility database" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\PcaSvc.dll" "Thu Dec 16 07:53:34 2021" "
+ "\Microsoft\Windows\Application Experience\ProgramDataUpdater" "Collects program telemetry information if opted-in to the Microsoft Customer Experience Improvement Program" "(Verified) Microsoft Corporation" "C:\WINDOWS\system32\compattelrunner.exe" "Sat Jun 5 13:05:21 2021" "
+ "\Microsoft\Windows\Application Experience\StartupAppTask" "Scans startup entries and raises notification to the user if there are too many startup entries." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\Startupscan.dll" "Sat Jun 5 13:05:29 2021" "
+ "\Microsoft\Windows\ApplicationData\appuriverifierdaily" "Verifies AppUriHandler host registrations." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\AppHostRegistrationVerifier.exe" "Sat Jun 5 13:05:02 2021" "
+ "\Microsoft\Windows\ApplicationData\appuriverifierinstall" "Verifies AppUriHandler host registrations." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\AppHostRegistrationVerifier.exe" "Sat Jun 5 13:05:02 2021" "
+ "\Microsoft\Windows\ApplicationData\CleanupTemporaryState" "Cleans up each package's unused temporary files." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\Windows.Storage.ApplicationData.dll" "Sat Jun 5 13:05:12 2021" "
+ "\Microsoft\Windows\ApplicationData\DsSvcCleanup" "Performs maintenance for the Data Sharing Service." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\dstokenclean.exe" "Sat Jun 5 13:05:02 2021" "
+ "\Microsoft\Windows\AppListBackup\Backup" "AppListBackupLauncher" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\AppListBackupLauncher.dll" "Thu Dec 16 07:51:30 2021" "
+ X "\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup" "AppX Deployment Client DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\AppxDeploymentClient.dll" "Thu Dec 16 07:52:35 2021" "
+ "\Microsoft\Windows\Autochk\Proxy" "This task collects and uploads autochk SQM data if opted-in to the Microsoft Customer Experience Improvement Program." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\acproxy.dll" "Sat Jun 5 13:06:02 2021" "
+ "\Microsoft\Windows\BitLocker\BitLocker Encrypt All Drives" "EdpTask Task" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\edptask.dll" "Sat Jun 5 13:05:29 2021" "
+ "\Microsoft\Windows\BitLocker\BitLocker MDM policy Refresh" "EdpTask Task" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\edptask.dll" "Sat Jun 5 13:05:29 2021" "
+ "\Microsoft\Windows\Bluetooth\UninstallDeviceTask" "Uninstalls the PnP device associated with the specified Bluetooth service ID" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\BthUdTask.exe" "Sat Jun 5 13:05:23 2021" "
+ "\Microsoft\Windows\capabilityaccessmanager\maintenancetasks" "Capability Access Manager Maintenance Tasks" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\CapabilityAccessManager.dll" "Thu Dec 16 07:52:51 2021" "
+ "\Microsoft\Windows\CertificateServicesClient\UserTask" "DIMS Job DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\dimsjob.dll" "Sat Jun 5 13:06:05 2021" "
+ "\Microsoft\Windows\CertificateServicesClient\UserTask-Roam" "DIMS Job DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\dimsjob.dll" "Sat Jun 5 13:06:05 2021" "
+ "\Microsoft\Windows\Chkdsk\ProactiveScan" "pstask Task" "(Verified) Microsoft Windows" "C:\Windows\System32\pstask.dll" "Sat Jun 5 13:06:15 2021" "
+ "\Microsoft\Windows\Chkdsk\SyspartRepair" "Bcdboot utility" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\bcdboot.exe" "Thu Dec 16 07:51:37 2021" "
+ "\Microsoft\Windows\CloudExperienceHost\CreateObjectTask" "CloudExperienceHost Broker" "(Verified) Microsoft Windows" "C:\Windows\System32\CloudExperienceHostBroker.exe" "Sat Jun 5 13:05:20 2021" "
+ "\Microsoft\Windows\Customer Experience Improvement Program\Consolidator" "If the user has consented to participate in the Windows Customer Experience Improvement Program, this job collects and sends usage data to Microsoft." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\wsqmcons.exe" "Sat Jun 5 13:05:23 2021" "
+ "\Microsoft\Windows\Customer Experience Improvement Program\UsbCeip" "USBCEIP Task" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\usbceip.dll" "Sat Jun 5 13:05:27 2021" "
+ "\Microsoft\Windows\Data Integrity Scan\Data Integrity Check And Scan" "Data Integrity Scan Task" "(Verified) Microsoft Windows" "C:\Windows\System32\discan.dll" "Sat Jun 5 13:06:00 2021" "
+ "\Microsoft\Windows\Data Integrity Scan\Data Integrity Scan" "Data Integrity Scan Task" "(Verified) Microsoft Windows" "C:\Windows\System32\discan.dll" "Sat Jun 5 13:06:00 2021" "
+ "\Microsoft\Windows\Data Integrity Scan\Data Integrity Scan for Crash Recovery" "Data Integrity Scan Task" "(Verified) Microsoft Windows" "C:\Windows\System32\discan.dll" "Sat Jun 5 13:06:00 2021" "
+ "\Microsoft\Windows\Defrag\ScheduledDefrag" "This task optimises local storage drives." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\defrag.exe" "Sat Jun 5 13:06:05 2021" "
+ "\Microsoft\Windows\Device Information\Device" "Device Census" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\devicecensus.exe" "Sat Jun 5 13:05:23 2021" "
+ "\Microsoft\Windows\Device Information\Device User" "Device Census" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\devicecensus.exe" "Sat Jun 5 13:05:23 2021" "
+ "\Microsoft\Windows\Diagnosis\RecommendedTroubleshootingScanner" "MitigationClient" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\MitigationClient.dll" "Sat Jun 5 13:04:52 2021" "
+ "\Microsoft\Windows\Diagnosis\Scheduled" "Scripted Diagnostics Scheduled Task" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\sdiagschd.dll" "Sat Jun 5 13:06:14 2021" "
+ "\Microsoft\Windows\DirectX\DirectXDatabaseUpdater" "DirectX Database Updater" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\directxdatabaseupdater.exe" "Thu Dec 16 07:52:23 2021" "
+ "\Microsoft\Windows\DirectX\DXGIAdapterCache" "DXGI Adapter Cache" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\dxgiadaptercache.exe" "Sat Jun 5 13:05:06 2021" "
+ "\Microsoft\Windows\DiskCleanup\SilentCleanup" "Maintenance task used by the system to launch a silent automatic disk clean-up when free disk space is running low." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\cleanmgr.exe" "Sat Jun 5 13:06:02 2021" "
+ "\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector" "The Windows Disk Diagnostic reports general disk and system information to Microsoft for users participating in the Customer Experience Program." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\dfdts.dll" "Sat Jun 5 13:06:05 2021" "
+ X "\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticResolver" "The Microsoft-Windows-DiskDiagnosticResolver warns users about faults reported by hard disks that support the Self Monitoring and Reporting Technology (S.M.A.R.T.) standard. This task is triggered automatically by the Diagnostic Policy Service when a S.M.A.R.T. fault is detected." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\DFDWiz.exe" "Sat Jun 5 13:06:05 2021" "
+ "\Microsoft\Windows\DiskFootprint\Diagnostics" "DiskSnapshot.exe" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\disksnapshot.exe" "Sat Jun 5 13:05:16 2021" "
+ "\Microsoft\Windows\DiskFootprint\StorageSense" "Storage Usage" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\StorageUsage.dll" "Thu Dec 16 07:56:31 2021" "
+ "\Microsoft\Windows\DUSM\dusmtask" "DUSM Task" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\dusmtask.exe" "Thu Dec 16 07:56:20 2021" "
+ "\Microsoft\Windows\EDP\EDP App Launch Task" "EdpTask Task" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\edptask.dll" "Sat Jun 5 13:05:29 2021" "
+ "\Microsoft\Windows\EDP\EDP Auth Task" "EdpTask Task" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\edptask.dll" "Sat Jun 5 13:05:29 2021" "
+ "\Microsoft\Windows\EDP\EDP Inaccessible Credentials Task" "EdpTask Task" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\edptask.dll" "Sat Jun 5 13:05:29 2021" "
+ "\Microsoft\Windows\EDP\StorageCardEncryption Task" "EdpTask Task" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\edptask.dll" "Sat Jun 5 13:05:29 2021" "
+ "\Microsoft\Windows\ExploitGuard\ExploitGuard MDM policy Refresh" "Exploit Guard Configuration Helper" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\MitigationConfiguration.dll" "Sat Jun 5 13:05:40 2021" "
+ "\Microsoft\Windows\Feedback\Siuf\DmClient" "Update SIUF strings" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\dmclient.exe" "Sat Jun 5 13:04:59 2021" "
+ "\Microsoft\Windows\Feedback\Siuf\DmClientOnScenarioDownload" "Update SIUF strings" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\dmclient.exe" "Sat Jun 5 13:04:59 2021" "
+ "\Microsoft\Windows\FileHistory\File History (maintenance mode)" "File History Task Handler" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\fhtask.dll" "Thu Dec 16 07:56:54 2021" "
+ "\Microsoft\Windows\Flighting\FeatureConfig\ReconcileFeatures" "Feature Configuration" "(Verified) Microsoft Windows" "C:\Windows\System32\fcon.dll" "Sat Jun 5 13:04:52 2021" "
+ "\Microsoft\Windows\Flighting\FeatureConfig\UsageDataFlushing" "Feature Configuration" "(Verified) Microsoft Windows" "C:\Windows\System32\fcon.dll" "Sat Jun 5 13:04:52 2021" "
+ "\Microsoft\Windows\Flighting\FeatureConfig\UsageDataReporting" "Feature Configuration" "(Verified) Microsoft Windows" "C:\Windows\System32\fcon.dll" "Sat Jun 5 13:04:52 2021" "
+ "\Microsoft\Windows\Flighting\OneSettings\RefreshCache" "Windows OneSettings Client" "(Verified) Microsoft Windows" "C:\Windows\System32\wosc.dll" "Thu Dec 16 07:51:24 2021" "
+ "\Microsoft\Windows\Input\LocalUserSyncDataAvailable" "Windows Input Cloud Store Task Handlers" "(Verified) Microsoft Windows" "C:\Windows\System32\InputCloudStore.dll" "Sat Jun 5 13:05:20 2021" "
+ "\Microsoft\Windows\Input\MouseSyncDataAvailable" "Windows Input Cloud Store Task Handlers" "(Verified) Microsoft Windows" "C:\Windows\System32\InputCloudStore.dll" "Sat Jun 5 13:05:20 2021" "
+ "\Microsoft\Windows\Input\PenSyncDataAvailable" "Windows Input Cloud Store Task Handlers" "(Verified) Microsoft Windows" "C:\Windows\System32\InputCloudStore.dll" "Sat Jun 5 13:05:20 2021" "
+ "\Microsoft\Windows\Input\TouchpadSyncDataAvailable" "Windows Input Cloud Store Task Handlers" "(Verified) Microsoft Windows" "C:\Windows\System32\InputCloudStore.dll" "Sat Jun 5 13:05:20 2021" "
+ "\Microsoft\Windows\InstallService\ScanForUpdates" "InstallService Tasks" "(Verified) Microsoft Windows" "C:\Windows\System32\InstallServiceTasks.dll" "Thu Dec 16 07:52:32 2021" "
+ "\Microsoft\Windows\InstallService\ScanForUpdatesAsUser" "InstallService Tasks" "(Verified) Microsoft Windows" "C:\Windows\System32\InstallServiceTasks.dll" "Thu Dec 16 07:52:32 2021" "
+ X "\Microsoft\Windows\InstallService\WakeUpAndContinueUpdates" "InstallService Tasks" "(Verified) Microsoft Windows" "C:\Windows\System32\InstallServiceTasks.dll" "Thu Dec 16 07:52:32 2021" "
+ X "\Microsoft\Windows\InstallService\WakeUpAndScanForUpdates" "InstallService Tasks" "(Verified) Microsoft Windows" "C:\Windows\System32\InstallServiceTasks.dll" "Thu Dec 16 07:52:32 2021" "
+ "\Microsoft\Windows\International\Synchronize Language Settings" "Core Globalization Configuration" "(Verified) Microsoft Windows" "C:\Windows\System32\CoreGlobConfig.dll" "Sat Jun 5 13:05:09 2021" "
+ "\Microsoft\Windows\Kernel\La57Cleanup" "This task cleans up 5-level paging binaries on systems that do not support 5-level paging." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\la57setup.exe" "Thu Dec 16 07:54:22 2021" "
+ "\Microsoft\Windows\LanguageComponentsInstaller\Installation" "LanguageComponentsInstaller Task" "(Verified) Microsoft Windows" "C:\Windows\System32\LanguageComponentsInstaller.dll" "Thu Dec 16 07:54:22 2021" "
+ "\Microsoft\Windows\Location\Notifications" "Location Notification" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\LocationNotificationWindows.exe" "Sat Jun 5 13:06:10 2021" "
+ "\Microsoft\Windows\Location\WindowsActionDialog" "Location Notification" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\WindowsActionDialog.exe" "Sat Jun 5 13:06:10 2021" "
+ "\Microsoft\Windows\Maintenance\WinSAT" "Windows System Assessment Tool API" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\WinSATAPI.dll" "Sat Jun 5 13:06:16 2021" "
+ "\Microsoft\Windows\Management\Provisioning\Cellular" "Provisioning package runtime processing tool" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\ProvTool.exe" "Thu Dec 16 07:51:45 2021" "
+ "\Microsoft\Windows\Management\Provisioning\Logon" "Provisioning package runtime processing tool" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\ProvTool.exe" "Thu Dec 16 07:51:45 2021" "
+ X "\Microsoft\Windows\Management\Provisioning\MdmDiagnosticsCleanup" "MdmDiagnosticsTool" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\MdmDiagnosticsTool.exe" "Sat Jun 5 13:05:12 2021" "
+ X "\Microsoft\Windows\Management\Provisioning\Retry" "Provisioning package runtime processing tool" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\ProvTool.exe" "Thu Dec 16 07:51:45 2021" "
+ X "\Microsoft\Windows\Management\Provisioning\RunOnReboot" "Provisioning package runtime processing tool" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\ProvTool.exe" "Thu Dec 16 07:51:45 2021" "
+ "\Microsoft\Windows\Maps\MapsToastTask" "MapsToastTask Task" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\mapstoasttask.dll" "Thu Dec 16 07:52:30 2021" "
+ X "\Microsoft\Windows\Maps\MapsUpdateTask" "MapsUpdateTask Task" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\mapsupdatetask.dll" "Thu Dec 16 07:52:29 2021" "
+ "\Microsoft\Windows\MemoryDiagnostic\ProcessMemoryDiagnosticEvents" "Microsoft Windows Memory Diagnostic Task Handler" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\MemoryDiagnostic.dll" "Sat Jun 5 13:06:16 2021" "
+ "\Microsoft\Windows\MemoryDiagnostic\RunFullMemoryDiagnostic" "Microsoft Windows Memory Diagnostic Task Handler" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\MemoryDiagnostic.dll" "Sat Jun 5 13:06:16 2021" "
+ "\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser" "$(@%SystemRoot%\system32\MbaeParserTask.exe,-1903)" "" "File not found: C:\WINDOWS\System32\MbaeParserTask.exe" "" "
+ "\Microsoft\Windows\MUI\LPRemove" "Launch language clean-up tool" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\lpremove.exe" "Thu Dec 16 07:54:22 2021" "
+ "\Microsoft\Windows\Multimedia\SystemSoundsService" "PlaySound Service" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\PlaySndSrv.dll" "Thu Dec 16 07:51:30 2021" "
+ "\Microsoft\Windows\NetTrace\GatherNetworkInfo" "Network information collector" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\gatherNetworkInfo.vbs" "Sat Jun 5 13:06:02 2021" "
+ "\Microsoft\Windows\NlaSvc\WiFiTask" "Background task for performing per user and web interactions" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\WiFiTask.exe" "Thu Dec 16 07:51:50 2021" "
+ "\Microsoft\Windows\Plug and Play\Device Install Group Policy" "pnppolicy Task" "(Verified) Microsoft Windows" "C:\Windows\System32\pnppolicy.dll" "Sat Jun 5 13:05:39 2021" "
+ "\Microsoft\Windows\Plug and Play\Device Install Reboot Required" "Plug and Play User Interface DLL" "(Verified) Microsoft Windows" "C:\Windows\System32\pnpui.dll" "Sat Jun 5 13:05:39 2021" "
+ "\Microsoft\Windows\Plug and Play\Sysprep Generalize Drivers" "Generalise driver state in order to prepare the system to be bootable on any hardware configuration." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drvinst.exe" "Sat Jun 5 13:05:39 2021" "
+ "\Microsoft\Windows\Power Efficiency Diagnostics\AnalyzeSystem" "Power Efficiency Diagnostics Task" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\energytask.dll" "Sat Jun 5 13:06:11 2021" "
+ "\Microsoft\Windows\Printing\EduPrintProv" "Printer Provision Utility for EDU" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\eduprintprov.exe" "Sat Jun 5 13:06:16 2021" "
+ "\Microsoft\Windows\Printing\PrinterCleanupTask" "Windows Printer Cleanup Task" "(Verified) Microsoft Windows" "C:\Windows\System32\PrinterCleanupTask.dll" "Thu Dec 16 07:51:44 2021" "
+ "\Microsoft\Windows\RecoveryEnvironment\VerifyWinRE" "Microsoft Windows Recovery Agent Task Handler" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\ReAgentTask.dll" "Sat Jun 5 13:05:27 2021" "
+ "\Microsoft\Windows\Registry\RegIdleBackup" "RegIdle Backup Task" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\regidle.dll" "Sat Jun 5 13:06:11 2021" "
+ "\Microsoft\Windows\Setup\SetupCleanupTask" "SetupCleanupTask Task" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\oobe\SetupCleanupTask.dll" "Thu Dec 16 07:55:10 2021" "
+ X "\Microsoft\Windows\SharedPC\Account Cleanup" "SharedPC.AccountManager" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Windows.SharedPC.AccountManager.dll" "Sat Jun 5 13:05:19 2021" "
+ "\Microsoft\Windows\Shell\CreateObjectTask" "Windows Shell Common Dll" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\shell32.dll" "Thu Dec 16 07:54:27 2021" "
+ "\Microsoft\Windows\Shell\FamilySafetyMonitor" "Initialises Family Safety monitoring and enforcement." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\wpcmon.exe" "Thu Dec 16 07:51:41 2021" "
+ "\Microsoft\Windows\Shell\FamilySafetyRefreshTask" "Family Safety Refresh Task" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\WpcRefreshTask.dll" "Thu Dec 16 07:51:42 2021" "
+ "\Microsoft\Windows\Shell\IndexerAutomaticMaintenance" "Indexing Options" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\srchadmin.dll" "Sat Jun 5 13:05:40 2021" "
+ "\Microsoft\Windows\Shell\ThemesSyncedImageDownload" "ThemesSyncedImageDownload Task" "(Verified) Microsoft Windows" "C:\Windows\System32\Themes.SsfDownload.ScheduledTask.dll" "Sat Jun 5 13:04:58 2021" "
+ X "\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTaskLogon" "Software Protection Platform Client Extension Dll" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\sppcext.dll" "Thu Dec 16 07:54:29 2021" "
+ "\Microsoft\Windows\SpacePort\SpaceAgentTask" "Storage Spaces Settings" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\SpaceAgent.exe" "Sat Jun 5 13:06:17 2021" "
+ "\Microsoft\Windows\SpacePort\SpaceManagerTask" "$(@%SystemRoot%\system32\spaceman.exe,-3)" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\spaceman.exe" "Sat Jun 5 13:06:02 2021" "
+ "\Microsoft\Windows\StateRepository\MaintenanceTasks" "$(@%SystemRoot%\system32\Windows.StateRepositoryClient.dll,-602)" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\Windows.StateRepositoryClient.dll" "Thu Dec 16 07:52:37 2021" "
+ "\Microsoft\Windows\Storage Tiers Management\Storage Tiers Management Initialization" "Storage Tiers Management" "(Verified) Microsoft Windows" "C:\Windows\System32\TieringEngineService.exe" "Sat Jun 5 13:06:13 2021" "
+ X "\Microsoft\Windows\Storage Tiers Management\Storage Tiers Optimization" "Optimizes the placement of data in storage tiers on all tiered storage spaces in the system." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\defrag.exe" "Sat Jun 5 13:06:05 2021" "
+ "\Microsoft\Windows\Subscription\EnableLicenseAcquisition" "Enable susbscription license acquisition" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\ClipRenew.exe" "Sat Jun 5 18:17:02 2021" "
+ X "\Microsoft\Windows\Subscription\LicenseAcquisition" "Susbscription license acquisition" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\ClipRenew.exe" "Sat Jun 5 18:17:02 2021" "
+ X "\Microsoft\Windows\Sysmain\HybridDriveCachePrepopulate" "SysMain Service Host" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\sysmain.dll" "Thu Dec 16 07:56:56 2021" "
+ X "\Microsoft\Windows\Sysmain\HybridDriveCacheRebalance" "SysMain Service Host" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\sysmain.dll" "Thu Dec 16 07:56:56 2021" "
+ "\Microsoft\Windows\Sysmain\ResPriStaticDbSync" "SysMain Service Host" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\sysmain.dll" "Thu Dec 16 07:56:56 2021" "
+ "\Microsoft\Windows\Sysmain\WsSwapAssessmentTask" "Working set swap assessment maintenance task" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\sysmain.dll" "Thu Dec 16 07:56:56 2021" "
+ "\Microsoft\Windows\SystemRestore\SR" "This task creates regular system protection points." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\srtasks.exe" "Sat Jun 5 13:06:17 2021" "
+ "\Microsoft\Windows\Task Manager\Interactive" "Performance Monitor" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wdc.dll" "Sat Jun 5 13:06:10 2021" "
+ "\Microsoft\Windows\TextServicesFramework\MsCtfMonitor" "MsCtfMonitor DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\MsCtfMonitor.dll" "Sat Jun 5 13:05:12 2021" "
+ "\Microsoft\Windows\Time Synchronization\ForceSynchronizeTime" "Time Synchronization Task" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\TimeSyncTask.dll" "Sat Jun 5 13:04:59 2021" "
+ "\Microsoft\Windows\Time Synchronization\SynchronizeTime" "Maintains date and time synchronization on all clients and servers in the network. If this service is stopped, date and time synchronization will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\sc.exe" "Sat Jun 5 13:06:02 2021" "
+ "\Microsoft\Windows\Time Zone\SynchronizeTimeZone" "Updates timezone information. If this task is stopped, local time may not be accurate for some time zones." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\tzsync.exe" "Sat Jun 5 13:05:14 2021" "
+ X "\Microsoft\Windows\UNP\RunUpdateNotificationMgr" "Update Notification Pipeline Manager" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\UNP\UpdateNotificationMgr.exe" "Sat Jun 5 13:06:16 2021" "
+ "\Microsoft\Windows\UPnP\UPnPHostConfig" "Set UPnPHost service to Auto-Start" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\sc.exe" "Sat Jun 5 13:06:02 2021" "
+ "\Microsoft\Windows\USB\Usb-Notifications" "UsbTask" "(Verified) Microsoft Windows" "C:\Windows\System32\UsbTask.dll" "Sat Jun 5 13:04:52 2021" "
+ "\Microsoft\Windows\WCM\WiFiTask" "Background task for performing per user and web interactions" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\WiFiTask.exe" "Thu Dec 16 07:51:50 2021" "
+ "\Microsoft\Windows\WDI\ResolutionHost" "Windows Diagnostic Infrastructure" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\wdi.dll" "Sat Jun 5 13:05:29 2021" "
+ "\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance" "Periodic maintenance task." "(Verified) Microsoft Windows Publisher" "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2111.5-0\MpCmdRun.exe" "Thu Dec 16 00:20:53 2021" "
+ "\Microsoft\Windows\Windows Defender\Windows Defender Cleanup" "Periodic clean-up task." "(Verified) Microsoft Windows Publisher" "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2111.5-0\MpCmdRun.exe" "Thu Dec 16 00:20:53 2021" "
+ "\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan" "Periodic scan task." "(Verified) Microsoft Windows Publisher" "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2111.5-0\MpCmdRun.exe" "Thu Dec 16 00:20:53 2021" "
+ "\Microsoft\Windows\Windows Defender\Windows Defender Verification" "Periodic verification task." "(Verified) Microsoft Windows Publisher" "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2111.5-0\MpCmdRun.exe" "Thu Dec 16 00:20:53 2021" "
+ "\Microsoft\Windows\Windows Error Reporting\QueueReporting" "Windows Error Reporting task to process queued reports." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wermgr.exe" "Sat Jun 5 13:05:25 2021" "
+ "\Microsoft\Windows\Windows Filtering Platform\BfeOnServiceStartTypeChange" "This task adjusts the start type for firewall-triggered services when the start type of the Base Filtering Engine (BFE) is disabled." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\bfe.dll" "Thu Dec 16 07:52:47 2021" "
+ "\Microsoft\Windows\Windows Media Sharing\UpdateLibrary" "This task updates the cached list of folders and the security permissions on any new files in a user’s shared media library." "(Verified) Microsoft Windows" "C:\Program Files\Windows Media Player\wmpnscfg.exe" "Sat Jun 5 02:36:00 2021" "
+ "\Microsoft\Windows\WindowsColorSystem\Calibration Loader" "Microsoft Colour Matching System DLL" "(Verified) Microsoft Windows" "C:\Windows\System32\mscms.dll" "Thu Dec 16 07:52:23 2021" "
+ "\Microsoft\Windows\WindowsUpdate\Scheduled Start" "This task is used to start the Windows Update service when needed to perform scheduled operations such as scans." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\sc.exe" "Sat Jun 5 13:06:02 2021" "
+ "\Microsoft\Windows\Wininet\CacheTask" "Internet Extensions for Win32" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wininet.dll" "Thu Dec 16 07:54:21 2021" "
+ "\Microsoft\Windows\WlanSvc\CDSSync" "Windows WiFi Sync Provider DLL" "(Verified) Microsoft Windows" "C:\Windows\System32\WiFiCloudStore.dll" "Sat Jun 5 13:05:00 2021" "
+ "\Microsoft\Windows\Work Folders\Work Folders Logon Synchronization" "Microsoft (C) Work Folders Shell Extension" "(Verified) Microsoft Windows" "C:\Windows\System32\WorkFoldersShell.dll" "Sat Jun 5 13:06:16 2021" "
+ "\Microsoft\Windows\Work Folders\Work Folders Maintenance Work" "Microsoft (C) Work Folders Shell Extension" "(Verified) Microsoft Windows" "C:\Windows\System32\WorkFoldersShell.dll" "Sat Jun 5 13:06:16 2021" "
+ X "\Microsoft\Windows\Workplace Join\Automatic-Device-Join" "Register this computer if the computer is already joined to an Active Directory domain." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\dsregcmd.exe" "Sat Jun 5 13:04:59 2021" "
+ X "\Microsoft\Windows\Workplace Join\Device-Sync" "DSREG task handler" "(Verified) Microsoft Windows" "C:\Windows\System32\dsregtask.dll" "Sat Jun 5 13:04:59 2021" "
+ X "\Microsoft\Windows\Workplace Join\Recovery-Check" "Performs recovery check." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\dsregcmd.exe" "Sat Jun 5 13:04:59 2021" "
+ "\Microsoft\Windows\WwanSvc\NotificationTask" "Background task for performing per user and web interactions" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\WiFiTask.exe" "Thu Dec 16 07:51:50 2021" "
+ "\Microsoft\Windows\WwanSvc\OobeDiscovery" "Windows MB Media Manager DLL" "(Verified) Microsoft Windows" "C:\Windows\System32\MBMediaManager.dll" "Thu Dec 16 07:53:07 2021" "
+ "\Microsoft\XblGameSave\XblGameSaveTask" "XblGameSave Standby Task" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\XblGameSaveTask.exe" "Sat Jun 5 13:04:52 2021" "
+ "\Quick Access" "This task is for Quick Access" "(Verified) Acer Incorporated" "C:\Program Files\Acer\Quick Access Service\QALauncher.exe" "Thu Sep 10 13:58:18 2020" "
+ "\Software Update Application" "Software Updater Scheduler" "(Verified) Acer Incorporated" "C:\ProgramData\OEM\UpgradeTool\ListCheck.exe" "Wed Nov 17 15:08:26 2021" "
+ "\UbtFrameworkService" "User Experience Improvement Program Framework Service" "(Verified) Acer Incorporated" "C:\Program Files\Acer\User Experience Improvement Program Service\Framework\TriggerFramework.exe" "Fri Aug 7 12:56:32 2020" "
+ "\UEIPInvitation" "User Experience Improvement Program Framework Invitation" "(Verified) Acer Incorporated" "C:\Program Files\Acer\User Experience Improvement Program Service\Framework\UEIPOOBECheck.exe" "Fri Aug 7 12:56:32 2020" "
[Services]
[HKLM\System\CurrentControlSet\Services]
+ "AarSvc" "Agent Activation Runtime: Runtime for activating conversational agent applications" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\AarSvc.dll" "Sat Jun 5 13:04:52 2021" "
+ "AarSvc_6a9e6" "Agent Activation Runtime_6a9e6: Runtime for activating conversational agent applications" "(Verified) Microsoft Windows Publisher" "C:\WINDOWS\system32\svchost.exe" "Sat Jun 5 13:05:23 2021" "
+ "ACCSvc" "ACC Service: ACC Service" "(Verified) Acer Incorporated" "C:\Program Files (x86)\Acer\Care Center\ACCSvc.exe" "Wed Nov 17 15:08:30 2021" "
+ "AJRouter" "AllJoyn Router Service: Routes AllJoyn messages for the local AllJoyn clients. If this service is stopped the AllJoyn clients that do not have their own bundled routers will be unable to run." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\AJRouter.dll" "Sat Jun 5 13:05:03 2021" "
+ "ALG" "Application Layer Gateway Service: Provides support for 3rd party protocol plug-ins for Internet Connection Sharing" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\alg.exe" "Sat Jun 5 13:05:12 2021" "
+ "AppIDSvc" "Application Identity: Determines and verifies the identity of an application. Disabling this service will prevent AppLocker from being enforced." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\appidsvc.dll" "Sat Jun 5 13:05:23 2021" "
+ "Appinfo" "Application Information: Facilitates the running of interactive applications with additional administrative privileges. If this service is stopped, users will be unable to launch applications with the additional administrative privileges they may require to perform desired user tasks." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\appinfo.dll" "Thu Dec 16 07:52:14 2021" "
+ "AppReadiness" "App Readiness: Gets apps ready for use the first time a user signs in to this PC and when adding new apps." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\AppReadiness.dll" "Thu Dec 16 08:01:09 2021" "
+ "AppXSvc" "AppX Deployment Service (AppXSVC): Provides infrastructure support for deploying Store applications. This service is started on demand and if disabled Store applications will not be deployed to the system, and may not function properly." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\appxdeploymentserver.dll" "Thu Dec 16 07:54:08 2021" "
+ "AtherosSvc" "AtherosSvc: Windows Setup API" "(Verified) Microsoft Windows Hardware Compatibility Publisher" "C:\WINDOWS\System32\drivers\AdminService.exe" "Mon Jul 19 21:46:00 2021" "
+ "AudioEndpointBuilder" "Windows Audio Endpoint Builder: Manages audio devices for the Windows Audio service. If this service is stopped, audio devices and effects will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\AudioEndpointBuilder.dll" "Thu Dec 16 07:51:31 2021" "
+ "Audiosrv" "Windows Audio: Manages audio for Windows-based programs. If this service is stopped, audio devices and effects will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Audiosrv.dll" "Thu Dec 16 07:51:31 2021" "
+ "autotimesvc" "Cellular Time: This service sets time based on NITZ messages from a Mobile Network" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\autotimesvc.dll" "Sat Jun 5 13:06:00 2021" "
+ "AxInstSV" "ActiveX Installer (AxInstSV): Provides User Account Control validation for the installation of ActiveX controls from the Internet and enables management of ActiveX control installation based on Group Policy settings. This service is started on demand and if disabled the installation of ActiveX controls will behave according to default browser settings." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\AxInstSV.dll" "Thu Dec 16 07:54:24 2021" "
+ "BcastDVRUserService" "GameDVR and Broadcast User Service: This user service is used for Game Recordings and Live Broadcasts" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\BcastDVRUserService.dll" "Thu Dec 16 07:56:19 2021" "
+ "BcastDVRUserService_6a9e6" "GameDVR and Broadcast User Service_6a9e6: This user service is used for Game Recordings and Live Broadcasts" "(Verified) Microsoft Windows Publisher" "C:\WINDOWS\system32\svchost.exe" "Sat Jun 5 13:05:23 2021" "
+ "BDESVC" "BitLocker Drive Encryption Service: BDESVC hosts the BitLocker Drive Encryption service. BitLocker Drive Encryption provides secure startup for the operating system, as well as full volume encryption for OS, fixed or removable volumes. This service allows BitLocker to prompt users for various actions related to their volumes when mounted, and unlocks volumes automatically without user interaction. Additionally, it stores recovery information to Active Directory, if available, and, if necessary, ensures the most recent recovery certificates are used. Stopping or disabling the service would prevent users from leveraging this functionality." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\bdesvc.dll" "Thu Dec 16 08:01:15 2021" "
+ "BFE" "Base Filtering Engine: The Base Filtering Engine (BFE) is a service that manages firewall and Internet Protocol security (IPsec) policies and implements user mode filtering. Stopping or disabling the BFE service will significantly reduce the security of the system. It will also result in unpredictable behavior in IPsec management and firewall applications." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\bfe.dll" "Thu Dec 16 07:52:47 2021" "
+ "BITS" "Background Intelligent Transfer Service: Transfers files in the background using idle network bandwidth. If the service is disabled, then any applications that depend on BITS, such as Windows Update or MSN Explorer, will be unable to automatically download programs and other information." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\qmgr.dll" "Sat Jun 5 13:05:03 2021" "
+ "BluetoothUserService" "Bluetooth User Support Service: The Bluetooth user service supports proper functionality of Bluetooth features relevant to each user session." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Microsoft.Bluetooth.UserService.dll" "Sat Jun 5 13:04:50 2021" "
+ "BluetoothUserService_6a9e6" "Bluetooth User Support Service_6a9e6: The Bluetooth user service supports proper functionality of Bluetooth features relevant to each user session." "(Verified) Microsoft Windows Publisher" "C:\WINDOWS\system32\svchost.exe" "Sat Jun 5 13:05:23 2021" "
+ "BrokerInfrastructure" "Background Tasks Infrastructure Service: Windows infrastructure service that controls which background tasks can run on the system." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\psmsrv.dll" "Sat Jun 5 13:05:10 2021" "
+ "BTAGService" "Bluetooth Audio Gateway Service: Service supporting the audio gateway role of the Bluetooth Handsfree Profile." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\BTAGService.dll" "Thu Dec 16 07:51:22 2021" "
+ "BthAvctpSvc" "AVCTP service: This is Audio Video Control Transport Protocol service" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\BthAvctpSvc.dll" "Sat Jun 5 13:04:50 2021" "
+ "bthserv" "Bluetooth Support Service: The Bluetooth service supports discovery and association of remote Bluetooth devices. Stopping or disabling this service may cause already installed Bluetooth devices to fail to operate properly and prevent new devices from being discovered or associated." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\bthserv.dll" "Sat Jun 5 13:05:16 2021" "
+ "camsvc" "Capability Access Manager Service: Provides facilities for managing UWP apps access to app capabilities as well as checking an app's access to specific app capabilities" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\CapabilityAccessManager.dll" "Thu Dec 16 07:52:51 2021" "
+ "CaptureService" "CaptureService: Enables optional screen capture functionality for applications that call the Windows.Graphics.Capture API." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\CaptureService.dll" "Sat Jun 5 13:05:23 2021" "
+ "CaptureService_6a9e6" "CaptureService_6a9e6: Enables optional screen capture functionality for applications that call the Windows.Graphics.Capture API." "(Verified) Microsoft Windows Publisher" "C:\WINDOWS\system32\svchost.exe" "Sat Jun 5 13:05:23 2021" "
+ "cbdhsvc" "Clipboard User Service: This user service is used for Clipboard scenarios" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\cbdhsvc.dll" "Thu Dec 16 07:56:28 2021" "
+ "cbdhsvc_6a9e6" "Clipboard User Service_6a9e6: This user service is used for Clipboard scenarios" "(Verified) Microsoft Windows Publisher" "C:\WINDOWS\system32\svchost.exe" "Sat Jun 5 13:05:23 2021" "
+ "CDPSvc" "Connected Devices Platform Service: This service is used for Connected Devices Platform scenarios" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\CDPSvc.dll" "Sat Jun 5 13:05:02 2021" "
+ "CDPUserSvc" "Connected Devices Platform User Service: This user service is used for Connected Devices Platform scenarios" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\CDPUserSvc.dll" "Sat Jun 5 13:05:02 2021" "
+ "CDPUserSvc_6a9e6" "Connected Devices Platform User Service_6a9e6: This user service is used for Connected Devices Platform scenarios" "(Verified) Microsoft Windows Publisher" "C:\WINDOWS\system32\svchost.exe" "Sat Jun 5 13:05:23 2021" "
+ X "CertPropSvc" "Certificate Propagation: Copies user certificates and root certificates from smart cards into the current user's certificate store, detects when a smart card is inserted into a smart card reader, and, if needed, installs the smart card Plug and Play minidriver." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\certprop.dll" "Sat Jun 5 13:05:34 2021" "
+ "ClickToRunSvc" "Microsoft Office Click-to-Run Service: ‪Manages resource coordination, background streaming, and system integration of Microsoft Office products and their related updates. This service is required to run during the use of any Microsoft Office program, during initial streaming installation and all subsequent updates.‬" "(Verified) Microsoft Corporation" "C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe" "Fri Dec 10 00:10:56 2021" "
+ "ClipSVC" "Client Licence Service (ClipSVC): Provides infrastructure support for the Microsoft Store. This service is started on demand and if disabled applications bought using Windows Store will not behave correctly." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\ClipSVC.dll" "Thu Dec 16 07:52:51 2021" "
+ "COMSysApp" "COM+ System Application: Manages the configuration and tracking of Component Object Model (COM)+-based components. If the service is stopped, most COM+-based components will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\dllhost.exe" "Sat Jun 5 13:05:23 2021" "
+ "ConsentUxUserSvc" "ConsentUX User Service: Allows the system to request user consent to allow apps to access sensitive resources and information such as the device's location" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\ConsentUxClient.dll" "Sat Jun 5 13:06:02 2021" "
+ "ConsentUxUserSvc_6a9e6" "ConsentUX User Service_6a9e6: Allows the system to request user consent to allow apps to access sensitive resources and information such as the device's location" "(Verified) Microsoft Windows Publisher" "C:\WINDOWS\system32\svchost.exe" "Sat Jun 5 13:05:23 2021" "
+ "CoreMessagingRegistrar" "CoreMessaging: Manages communication between system components." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\coremessaging.dll" "Thu Dec 16 07:53:41 2021" "
+ "cphs" "Intel(R) Content Protection HECI Service: Intel(R) Content Protection HECI Service - enables communication with the Content Protection FW" "(Verified) Intel(R) pGFX 2020" "C:\WINDOWS\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_e36b8067470714bb\IntelCpHeciSvc.exe" "Mon Jan 18 03:53:04 2021" "
+ "cplspcon" "Intel(R) Content Protection HDCP Service: Intel(R) Content Protection HDCP Service - enables communication with Content Protection HDCP HW" "(Verified) Intel(R) pGFX 2020" "C:\WINDOWS\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_e36b8067470714bb\IntelCpHDCPSvc.exe" "Mon Jan 18 03:53:04 2021" "
+ "CredentialEnrollmentManagerUserSvc" "CredentialEnrollmentManagerUserSvc: Credential Enrollment Manager" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\CredentialEnrollmentManager.exe" "Thu Dec 16 07:51:55 2021" "
+ "CredentialEnrollmentManagerUserSvc_6a9e6" "CredentialEnrollmentManagerUserSvc_6a9e6: Credential Enrollment Manager" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\CredentialEnrollmentManager.exe" "Thu Dec 16 07:51:55 2021" "
+ "CryptSvc" "Cryptographic Services: Provides three management services: Catalog Database Service, which confirms the signatures of Windows files and allows new programs to be installed; Protected Root Service, which adds and removes Trusted Root Certification Authority certificates from this computer; and Automatic Root Certificate Update Service, which retrieves root certificates from Windows Update and enable scenarios such as SSL. If this service is stopped, these management services will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\cryptsvc.dll" "Sat Jun 5 13:05:23 2021" "
+ "DcomLaunch" "DCOM Server Process Launcher: The DCOMLAUNCH service launches COM and DCOM servers in response to object activation requests. If this service is stopped or disabled, programs using COM or DCOM will not function properly. It is strongly recommended that you have the DCOMLAUNCH service running." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\rpcss.dll" "Thu Dec 16 07:53:43 2021" "
+ "defragsvc" "Optimise drives: Helps the computer run more efficiently by optimising files on storage drives." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\defragsvc.dll" "Thu Dec 16 07:56:30 2021" "
+ "DeviceAssociationBrokerSvc" "DeviceAssociationBroker: Enables apps to pair devices" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\deviceaccess.dll" "Sat Jun 5 13:05:12 2021" "
+ "DeviceAssociationBrokerSvc_6a9e6" "DeviceAssociationBroker_6a9e6: Enables apps to pair devices" "(Verified) Microsoft Windows Publisher" "C:\WINDOWS\system32\svchost.exe" "Sat Jun 5 13:05:23 2021" "
+ "DeviceAssociationService" "Device Association Service: Enables pairing between the system and wired or wireless devices." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\das.dll" "Sat Jun 5 13:05:16 2021" "
+ "DeviceInstall" "Device Install Service: Enables a computer to recognize and adapt to hardware changes with little or no user input. Stopping or disabling this service will result in system instability." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\umpnpmgr.dll" "Sat Jun 5 13:05:39 2021" "
+ "DevicePickerUserSvc" "DevicePicker: This user service is used for managing the Miracast, DLNA and DIAL UI" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Windows.Devices.Picker.dll" "Sat Jun 5 13:06:46 2021" "
+ "DevicePickerUserSvc_6a9e6" "DevicePicker_6a9e6: This user service is used for managing the Miracast, DLNA and DIAL UI" "(Verified) Microsoft Windows Publisher" "C:\WINDOWS\system32\svchost.exe" "Sat Jun 5 13:05:23 2021" "
+ "DevicesFlowUserSvc" "DevicesFlow: Allows ConnectUX and PC Settings to Connect and Pair with WiFi displays and Bluetooth devices." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DevicesFlowBroker.dll" "Sat Jun 5 13:05:20 2021" "
+ "DevicesFlowUserSvc_6a9e6" "DevicesFlow_6a9e6: Allows ConnectUX and PC Settings to Connect and Pair with WiFi displays and Bluetooth devices." "(Verified) Microsoft Windows Publisher" "C:\WINDOWS\system32\svchost.exe" "Sat Jun 5 13:05:23 2021" "
+ "DevQueryBroker" "DevQuery Background Discovery Broker: Enables apps to discover devices with a backgroud task" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\DevQueryBroker.dll" "Sat Jun 5 13:05:09 2021" "
+ "Dhcp" "DHCP Client: Registers and updates IP addresses and DNS records for this computer. If this service is stopped, this computer will not receive dynamic IP addresses and DNS updates. If this service is disabled, any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\dhcpcore.dll" "Thu Dec 16 07:53:42 2021" "
+ "diagnosticshub.standardcollector.service" "Microsoft (R) Diagnostics Hub Standard Collector Service: Diagnostics Hub Standard Collector Service. When running, this service collects real time ETW events and processes them." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe" "Thu Dec 16 07:53:52 2021" "
+ "diagsvc" "Diagnostic Execution Service: Executes diagnostic actions for troubleshooting support" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\DiagSvc.dll" "Sat Jun 5 13:06:16 2021" "
+ X "DiagTrack" "Connected User Experiences and Telemetry: The Connected User Experiences and Telemetry service enables features that support in-application and connected user experiences. Additionally, this service manages the event driven collection and transmission of diagnostic and usage information (used to improve the experience and quality of the Windows Platform) when the diagnostics and usage privacy option settings are enabled under Feedback and Diagnostics." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\diagtrack.dll" "Thu Dec 16 07:53:46 2021" "
+ "DispBrokerDesktopSvc" "Display Policy Service: Manages the connection and configuration of local and remote displays" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DispBroker.Desktop.dll" "Thu Dec 16 07:56:31 2021" "
+ "DisplayEnhancementService" "Display Enhancement Service: A service for managing display enhancement such as brightness control." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\Microsoft.Graphics.Display.DisplayEnhancementService.dll" "Thu Dec 16 07:56:20 2021" "
+ "DmEnrollmentSvc" "Device Management Enrollment Service: Performs Device Enrollment Activities for Device Management" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\Windows.Internal.Management.dll" "Sat Jun 5 13:05:29 2021" "
+ "dmwappushservice" "Device Management Wireless Application Protocol (WAP) Push message Routing Service: Routes Wireless Application Protocol (WAP) Push messages received by the device and synchronizes Device Management sessions" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\dmwappushsvc.dll" "Sat Jun 5 13:05:29 2021" "
+ "Dnscache" "DNS Client: The DNS Client service (dnscache) caches Domain Name System (DNS) names and registers the full computer name for this computer. If the service is stopped, DNS names will continue to be resolved. However, the results of DNS name queries will not be cached and the computer's name will not be registered. If the service is disabled, any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\dnsrslvr.dll" "Thu Dec 16 07:53:42 2021" "
+ "DoSvc" "Delivery Optimization: Performs content delivery optimization tasks" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\dosvc.dll" "Thu Dec 16 07:52:21 2021" "
+ "dot3svc" "Wired AutoConfig: The Wired AutoConfig (DOT3SVC) service is responsible for performing IEEE 802.1X authentication on Ethernet interfaces. If your current wired network deployment enforces 802.1X authentication, the DOT3SVC service should be configured to run for establishing Layer 2 connectivity and/or providing access to network resources. Wired networks that do not enforce 802.1X authentication are unaffected by the DOT3SVC service." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\dot3svc.dll" "Thu Dec 16 07:51:51 2021" "
+ "DPS" "Diagnostic Policy Service: The Diagnostic Policy Service enables problem detection, troubleshooting and resolution for Windows components. If this service is stopped, diagnostics will no longer function." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\dps.dll" "Sat Jun 5 13:06:13 2021" "
+ "DsmSvc" "Device Setup Manager: Enables the detection, download and installation of device-related software. If this service is disabled, devices may be configured with outdated software, and may not work correctly." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DeviceSetupManager.dll" "Sat Jun 5 13:05:06 2021" "
+ "DsSvc" "Data Sharing Service: Provides data brokering between applications." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DsSvc.dll" "Sat Jun 5 13:05:02 2021" "
+ "DusmSvc" "Data Usage: Network data usage, data limit, restrict background data, metered networks." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\dusmsvc.dll" "Thu Dec 16 07:56:20 2021" "
+ "EapHost" "Extensible Authentication Protocol: The Extensible Authentication Protocol (EAP) service provides network authentication in such scenarios as 802.1x wired and wireless, VPN, and Network Access Protection (NAP). EAP also provides application programming interfaces (APIs) that are used by network access clients, including wireless and VPN clients, during the authentication process. If you disable this service, this computer is prevented from accessing networks that require EAP authentication." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\eapsvc.dll" "Sat Jun 5 13:04:57 2021" "
+ "edgeupdate" "Microsoft Edge Update Service (edgeupdate): Keeps your Microsoft software up to date. If this service is disabled or stopped, your Microsoft software will not be kept up to date, meaning security vulnerabilities that may arise cannot be fixed and features may not work. This service uninstalls itself when there is no Microsoft software using it." "(Verified) Microsoft Corporation" "C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" "Thu Apr 1 20:17:37 2021" "
+ "edgeupdatem" "Microsoft Edge Update Service (edgeupdatem): Keeps your Microsoft software up to date. If this service is disabled or stopped, your Microsoft software will not be kept up to date, meaning security vulnerabilities that may arise cannot be fixed and features may not work. This service uninstalls itself when there is no Microsoft software using it." "(Verified) Microsoft Corporation" "C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" "Thu Apr 1 20:17:37 2021" "
+ "EFS" "Encrypting File System (EFS): Provides the core file encryption technology used to store encrypted files on NTFS file system volumes. If this service is stopped or disabled, applications will be unable to access encrypted files." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\efssvc.dll" "Thu Dec 16 07:54:17 2021" "
+ "embeddedmode" "Embedded Mode: The Embedded Mode service enables scenarios related to Background Applications. Disabling this service will prevent Background Applications from being activated." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\embeddedmodesvc.dll" "Sat Jun 5 13:05:02 2021" "
+ "EntAppSvc" "Enterprise App Management Service: Enables enterprise application management." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\EnterpriseAppMgmtSvc.dll" "Sat Jun 5 13:05:16 2021" "
+ "EventLog" "Windows Event Log: This service manages events and event logs. It supports logging events, querying events, subscribing to events, archiving event logs, and managing event metadata. It can display events in both XML and plain text format. Stopping this service may compromise security and reliability of the system." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\wevtsvc.dll" "Thu Dec 16 07:53:06 2021" "
+ "EventSystem" "COM+ Event System: Supports System Event Notification Service (SENS), which provides automatic distribution of events to subscribing Component Object Model (COM) components. If the service is stopped, SENS will close and will not be able to provide logon and logoff notifications. If this service is disabled, any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\es.dll" "Sat Jun 5 13:05:23 2021" "
+ "Fax" "Fax: Enables you to send and receive faxes, using fax resources available on this computer or on the network." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\fxssvc.exe" "Sat Jun 5 02:34:00 2021" "
+ "fdPHost" "Function Discovery Provider Host: The FDPHOST service hosts the Function Discovery (FD) network discovery providers. These FD providers supply network discovery services for the Simple Services Discovery Protocol (SSDP) and Web Services – Discovery (WS-D) protocol. Stopping or disabling the FDPHOST service will disable network discovery for these protocols when using FD. When this service is unavailable, network services using FD and relying on these discovery protocols will be unable to find network devices or resources." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\fdPHost.dll" "Sat Jun 5 13:05:29 2021" "
+ "FDResPub" "Function Discovery Resource Publication: Publishes this computer and resources attached to this computer so they can be discovered over the network. If this service is stopped, network resources will no longer be published and they will not be discovered by other computers on the network." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\fdrespub.dll" "Sat Jun 5 13:05:29 2021" "
+ "fhsvc" "File History Service: Protects user files from accidental loss by copying them to a backup location" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\fhsvc.dll" "Thu Dec 16 07:56:54 2021" "
+ "FileSyncHelper" "FileSyncHelper: Helper service for OneDrive" "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\FileSyncHelper.exe" "Tue Dec 7 07:14:38 2021" "
+ "FontCache" "Windows Font Cache Service: Optimizes performance of applications by caching commonly used font data. Applications will start this service if it is not already running. It can be disabled, though doing so will degrade application performance." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\FntCache.dll" "Thu Dec 16 07:52:22 2021" "
+ "FontCache3.0.0.0" "Windows Presentation Foundation Font Cache 3.0.0.0: Optimizes performance of Windows Presentation Foundation (WPF) applications by caching commonly used font data. WPF applications will start this service if it is not already running. It can be disabled, though doing so will degrade the performance of WPF applications." "(Verified) Microsoft Corporation" "C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe" "Tue Jun 1 15:27:00 2021" "
+ "FrameServer" "Windows Camera Frame Server: Enables multiple clients to access video frames from camera devices." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\FrameServer.dll" "Thu Dec 16 07:56:42 2021" "
+ "FrameServerMonitor" "Windows Camera Frame Server Monitor: Monitors the health and state for the Windows Camera Frame Server service." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\FrameServerMonitor.dll" "Thu Dec 16 07:56:42 2021" "
+ "GoogleChromeElevationService" "Google Chrome Elevation Service (GoogleChromeElevationService): Google Chrome" "(Verified) Google LLC" "C:\Program Files\Google\Chrome\Application\96.0.4664.110\elevation_service.exe" "Sun Dec 12 08:19:40 2021" "
+ "GoTrust ID Plugin" "GoTrust ID Plugin: GoTrust ID Plugin" "(Not Verified) GOTrustID Inc." "C:\Program Files\GoTrust ID Plugin\GoTrust ID Plugin\GTFidoService.exe" "Tue Sep 8 09:46:46 2020" "
+ "GoTrustID Service" "GoTrustID Service: GoTrustID Service" "(Verified) GoTrustID Inc" "C:\Program Files\GoTrust ID Plugin\Bridge_Service.exe" "Tue Sep 8 09:47:36 2020" "
+ "gpsvc" "Group Policy Client: The service is responsible for applying settings configured by administrators for the computer and users through the Group Policy component. If the service is disabled, the settings will not be applied and applications and components will not be manageable through Group Policy. Any components or applications that depend on the Group Policy component might not be functional if the service is disabled." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\gpsvc.dll" "Thu Dec 16 07:54:21 2021" "
+ "GraphicsPerfSvc" "GraphicsPerfSvc: Graphics performance monitor service" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\GraphicsPerfSvc.dll" "Sat Jun 5 13:05:06 2021" "
+ "gupdate" "Google Update Service (gupdate): Keeps your Google software up to date. If this service is disabled or stopped, your Google software will not be kept up to date, meaning security vulnerabilities that may arise cannot be fixed and features may not work. This service uninstalls itself when there is no Google software using it." "(Verified) Google LLC" "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" "Tue Oct 12 17:43:19 2021" "
+ "gupdatem" "Google Update Service (gupdatem): Keeps your Google software up to date. If this service is disabled or stopped, your Google software will not be kept up to date, meaning security vulnerabilities that may arise cannot be fixed and features may not work. This service uninstalls itself when there is no Google software using it." "(Verified) Google LLC" "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" "Tue Oct 12 17:43:19 2021" "
+ X "HfcDisableService" "Intel(R) RST HFC Disable Service: Turns off hiberfile caching in Intel(R) RST driver." "(Verified) Intel(R) Rapid Storage Technology" "C:\WINDOWS\System32\DriverStore\FileRepository\iastorac.inf_amd64_34f570cbe7f3d6c7\HfcDisableService.exe" "Sun Oct 10 17:41:43 2021" "
+ "hidserv" "Human Interface Device Service: Activates and maintains the use of hot buttons on keyboards, remote controls and other multimedia devices. It is recommended that you keep this service running." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\hidserv.dll" "Sat Jun 5 13:05:29 2021" "
+ "HPPrintScanDoctorService" "HP Print Scan Doctor Service: " "(Verified) HP Inc." "C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe" "Mon Nov 1 19:37:39 2021" "
+ "HvHost" "HV Host Service: Provides an interface for the Hyper-V hypervisor to provide per-partition performance counters to the host operating system." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\hvhostsvc.dll" "Sat Jun 5 13:06:00 2021" "
+ "iaStorAfsService" "Intel(R) Optane(TM) Memory Service: Enables amazing system performance and responsiveness by accelerating frequently used files" "(Verified) Intel(R) Rapid Storage Technology" "C:\WINDOWS\System32\iaStorAfsService.exe" "Sun Oct 10 17:41:43 2021" "
+ "icssvc" "Windows Mobile Hotspot Service: Provides the ability to share a mobile data connection with another device." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\tetheringservice.dll" "Thu Dec 16 07:51:29 2021" "
+ "igccservice" "Intel(R) Graphics Command Center Service: Service for Intel(R) Graphics Command Center" "(Verified) Intel(R) pGFX 2020" "C:\WINDOWS\System32\DriverStore\FileRepository\igcc_dch.inf_amd64_3636ad46b8d9530e\OneApp.IGCC.WinService.exe" "Mon Jan 18 03:53:50 2021" "
+ "igfxCUIService2.0.0.0" "Intel(R) HD Graphics Control Panel Service: Service for Intel(R) HD Graphics Control Panel" "(Verified) Intel(R) pGFX 2020" "C:\WINDOWS\System32\DriverStore\FileRepository\cui_dch.inf_amd64_1e4c5c6397177db7\igfxCUIService.exe" "Mon Jan 18 03:52:30 2021" "
+ "IKEEXT" "IKE and AuthIP IPsec Keying Modules: The IKEEXT service hosts the Internet Key Exchange (IKE) and Authenticated Internet Protocol (AuthIP) keying modules. These keying modules are used for authentication and key exchange in Internet Protocol security (IPsec). Stopping or disabling the IKEEXT service will disable IKE and AuthIP key exchange with peer computers. IPsec is typically configured to use IKE or AuthIP; therefore, stopping or disabling the IKEEXT service might result in an IPsec failure and might compromise the security of the system. It is strongly recommended that you have the IKEEXT service running." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\ikeext.dll" "Thu Dec 16 07:52:47 2021" "
+ "InstallService" "Microsoft Store Install Service: Provides infrastructure support for the Microsoft Store. This service is started on demand, and if disabled then installations will not function properly." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\InstallService.dll" "Thu Dec 16 07:52:32 2021" "
+ "Intel(R) Capability Licensing Service TCP IP Interface" "Intel(R) Capability Licensing Service TCP IP Interface: Version: 1.62.321.1" "(Verified) Intel(R) Trust Services" "C:\WINDOWS\System32\DriverStore\FileRepository\iclsclient.inf_amd64_a93205b6238060e4\lib\SocketHeciServer.exe" "Thu Feb 18 04:18:02 2021" "
+ "Intel(R) TPM Provisioning Service" "Intel(R) TPM Provisioning Service: Version: 1.62.321.1" "(Verified) Intel(R) Trust Services" "C:\WINDOWS\System32\DriverStore\FileRepository\iclsclient.inf_amd64_a93205b6238060e4\lib\TPMProvisioningService.exe" "Thu Feb 18 04:18:02 2021" "
+ "iphlpsvc" "IP Helper: Provides tunnel connectivity using IPv6 transition technologies (6to4, ISATAP, Port Proxy, and Teredo), and IP-HTTPS. If this service is stopped, the computer will not have the enhanced connectivity benefits that these technologies offer." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\iphlpsvc.dll" "Thu Dec 16 07:54:50 2021" "
+ "IpxlatCfgSvc" "IP Translation Configuration Service: Configures and enables translation from v4 to v6 and vice versa" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\IpxlatCfg.dll" "Sat Jun 5 13:04:50 2021" "
+ "jhi_service" "Intel(R) Dynamic Application Loader Host Interface Service: Intel(R) Dynamic Application Loader Host Interface Service - Allows applications to access the local Intel (R) DAL" "(Verified) Intel(R) Embedded Subsystems and IP Blocks Group" "C:\WINDOWS\System32\DriverStore\FileRepository\dal.inf_amd64_b5484efd38adbe8d\jhi_service.exe" "Thu Feb 18 04:18:02 2021" "
+ "KeyIso" "CNG Key Isolation: The CNG key isolation service is hosted in the LSA process. The service provides key process isolation to private keys and associated cryptographic operations as required by the Common Criteria. The service stores and uses long-lived keys in a secure process complying with Common Criteria requirements." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\keyiso.dll" "Sat Jun 5 13:05:25 2021" "
+ "KtmRm" "KtmRm for Distributed Transaction Coordinator: Coordinates transactions between the Distributed Transaction Coordinator (MSDTC) and the Kernel Transaction Manager (KTM). If it is not needed, it is recommended that this service remain stopped. If it is needed, both MSDTC and KTM will start this service automatically. If this service is disabled, any MSDTC transaction interacting with a Kernel Resource Manager will fail and any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\msdtckrm.dll" "Sat Jun 5 13:06:02 2021" "
+ "LanmanServer" "Server: Supports file, print, and named-pipe sharing over the network for this computer. If this service is stopped, these functions will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\srvsvc.dll" "Thu Dec 16 07:53:52 2021" "
+ "LanmanWorkstation" "Workstation: Creates and maintains client network connections to remote servers using the SMB protocol. If this service is stopped, these connections will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\wkssvc.dll" "Sat Jun 5 13:05:25 2021" "
+ "lfsvc" "Geolocation Service: This service monitors the current location of the system and manages geofences (a geographical location with associated events). If you turn off this service, applications will be unable to use or receive notifications for geolocation or geofences." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\lfsvc.dll" "Sat Jun 5 13:05:29 2021" "
+ "LicenseManager" "Windows License Manager Service: Provides infrastructure support for the Microsoft Store. This service is started on demand and if disabled then content acquired through the Microsoft Store will not function properly." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\LicenseManagerSvc.dll" "Thu Dec 16 07:52:32 2021" "
+ "lltdsvc" "Link-Layer Topology Discovery Mapper: Creates a Network Map, consisting of PC and device topology (connectivity) information, and metadata describing each PC and device. If this service is disabled, the Network Map will not function properly." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\lltdsvc.dll" "Sat Jun 5 13:05:29 2021" "
+ "lmhosts" "TCP/IP NetBIOS Helper: Provides support for the NetBIOS over TCP/IP (NetBT) service and NetBIOS name resolution for clients on the network, therefore enabling users to share files, print, and log on to the network. If this service is stopped, these functions might be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows Publisher" "C:\WINDOWS\System32\svchost.exe" "Sat Jun 5 13:05:23 2021" "
+ "LMS" "Intel(R) Management and Security Application Local Management Service: Intel(R) Management and Security Application Local Management Service - Provides OS-related Intel(R) ME functionality." "(Verified) Intel Corporation" "C:\WINDOWS\System32\DriverStore\FileRepository\lms.inf_amd64_fddb643595e0b8d0\LMS.exe" "Thu Sep 2 03:06:42 2021" "
+ "LSM" "Local Session Manager: Core Windows Service that manages local user sessions. Stopping or disabling this service will result in system instability." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\lsm.dll" "Thu Dec 16 07:53:00 2021" "
+ "LxpSvc" "Language Experience Service: Provides infrastructure support for deploying and configuring localized Windows resources. This service is started on demand and, if disabled, additional Windows languages will not be deployed to the system, and Windows may not function properly." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\LanguageOverlayServer.dll" "Thu Dec 16 07:51:41 2021" "
+ "MapsBroker" "Downloaded Maps Manager: Windows service for application access to downloaded maps. This service is started on-demand by applications accessing downloaded maps. Disabling this service will prevent apps from accessing maps." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\moshost.dll" "Thu Dec 16 07:52:29 2021" "
+ "McpManagementService" "McpManagementService: Universal Print Management Service" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\McpManagementService.dll" "Thu Dec 16 07:56:40 2021" "
+ "MessagingService" "MessagingService: Service supporting text messaging and related functionality." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\MessagingService.dll" "Sat Jun 5 13:04:52 2021" "
+ "MessagingService_6a9e6" "MessagingService_6a9e6: Service supporting text messaging and related functionality." "(Verified) Microsoft Windows Publisher" "C:\WINDOWS\system32\svchost.exe" "Sat Jun 5 13:05:23 2021" "
+ "MicrosoftEdgeElevationService" "Microsoft Edge Elevation Service (MicrosoftEdgeElevationService): Keeps Microsoft Edge up to update. If this service is disabled, the application will not be kept up to date." "(Verified) Microsoft Corporation" "C:\Program Files (x86)\Microsoft\Edge\Application\96.0.1054.62\elevation_service.exe" "Thu Dec 16 22:46:30 2021" "
+ "MixedRealityOpenXRSvc" "Windows Mixed Reality OpenXR Service: Enables Mixed Reality OpenXR runtime functionality" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\MixedRealityRuntime.dll" "Sat Jun 5 18:17:04 2021" "
+ "mpssvc" "Windows Defender Firewall: Windows Defender Firewall helps to protect your computer by preventing unauthorised users from gaining access to your computer through the Internet or a network." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mpssvc.dll" "Thu Dec 16 07:52:47 2021" "
+ "MSDTC" "Distributed Transaction Coordinator: Coordinates transactions that span multiple resource managers, such as databases, message queues, and file systems. If this service is stopped, these transactions will fail. If this service is disabled, any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\msdtc.exe" "Sat Jun 5 13:06:02 2021" "
+ X "MSiSCSI" "Microsoft iSCSI Initiator Service: Manages Internet SCSI (iSCSI) sessions from this computer to remote iSCSI target devices. If this service is stopped, this computer will not be able to login or access iSCSI targets. If this service is disabled, any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\iscsiexe.dll" "Sat Jun 5 13:06:07 2021" "
+ "msiserver" "Windows Installer: Adds, modifies and removes applications provided as a Windows Installer or APPX package (*.msi, *.msp, *.appx). If this service is disabled, any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\msiexec.exe" "Sat Jun 5 13:06:10 2021" "
+ "NaturalAuthentication" "Natural Authentication: Signal aggregator service, that evaluates signals based on time, network, geolocation, bluetooth and cdf factors. Supported features are Device Unlock, Dynamic Lock and Dynamo MDM policies" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\NaturalAuth.dll" "Thu Dec 16 07:51:46 2021" "
+ "NcaSvc" "Network Connectivity Assistant: Provides DirectAccess status notification for UI components" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\ncasvc.dll" "Sat Jun 5 13:05:29 2021" "
+ "NcbService" "Network Connection Broker: Brokers connections that allow Windows Store Apps to receive notifications from the internet." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\ncbservice.dll" "Sat Jun 5 13:05:09 2021" "
+ "NcdAutoSetup" "Network Connected Devices Auto-Setup: Network Connected Devices Auto-Setup service monitors and installs qualified devices that connect to a qualified network. Stopping or disabling this service will prevent Windows from discovering and installing qualified network connected devices automatically. Users can still manually add network connected devices to a PC through the user interface." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\NcdAutoSetup.dll" "Sat Jun 5 13:06:16 2021" "
+ "Netlogon" "Netlogon: Maintains a secure channel between this computer and the domain controller for authenticating users and services. If this service is stopped, the computer may not authenticate users and services and the domain controller cannot register DNS records. If this service is disabled, any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\netlogon.dll" "Thu Dec 16 07:53:51 2021" "
+ "Netman" "Network Connections: Manages objects in the Network and Dial-Up Connections folder, in which you can view both local area network and remote connections." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\netman.dll" "Sat Jun 5 13:04:58 2021" "
+ "netprofm" "Network List Service: Identifies the networks the computer has connected to, collects and stores properties for these networks, and notifies applications when these properties change." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\netprofmsvc.dll" "Thu Dec 16 07:54:51 2021" "
+ "NetSetupSvc" "Network Setup Service: The Network Setup Service manages the installation of network drivers and permits the configuration of low-level network settings. If this service is stopped, any driver installations that are in progress may be cancelled." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\NetSetupSvc.dll" "Sat Jun 5 13:05:25 2021" "
+ X "NetTcpPortSharing" "Net.Tcp Port Sharing Service: Provides ability to share TCP ports over the net.tcp protocol." "(Verified) Microsoft Corporation" "C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe" "Sat Jun 5 13:06:50 2021" "
+ "NgcCtnrSvc" "Microsoft Passport Container: Manages local user identity keys used to authenticate the user to identity providers, as well as TPM virtual smart cards. If this service is disabled, local user identity keys and TPM virtual smart cards will not be accessible. It is recommended that you do not reconfigure this service." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\NgcCtnrSvc.dll" "Thu Dec 16 07:52:53 2021" "
+ "NgcSvc" "Microsoft Passport: Provides process isolation for cryptographic keys used to provide authentication to a user’s associated identity providers. If this service is disabled, all uses and management of these keys will not be available, which includes machine log-on and single sign-on for apps and websites. This service starts and stops automatically. It is recommended that you do not reconfigure this service." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\ngcsvc.dll" "Thu Dec 16 07:52:53 2021" "
+ "NlaSvc" "Network Location Awareness: Collects and stores configuration information for the network and notifies programmes when this information is modified. If this service is stopped, configuration information might be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\netprofmsvc.dll" "Thu Dec 16 07:54:51 2021" "
+ "NPSMSvc" "NPSMSvc: NPSM" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\npsm.dll" "Sat Jun 5 13:05:09 2021" "
+ "NPSMSvc_6a9e6" "NPSMSvc_6a9e6: Host Process for Windows Services" "(Verified) Microsoft Windows Publisher" "C:\WINDOWS\system32\svchost.exe" "Sat Jun 5 13:05:23 2021" "
+ "nsi" "Network Store Interface Service: This service delivers network notifications (e.g. interface addition/deleting etc) to user mode clients. Stopping this service will cause loss of network connectivity. If this service is disabled, any other services that explicitly depend on this service will fail to start." "(Verified) Microsoft Windows Publisher" "C:\WINDOWS\system32\svchost.exe" "Sat Jun 5 13:05:23 2021" "
+ "OneDrive Updater Service" "OneDrive Updater Service: Keeps your OneDrive up to date." "(Verified) Microsoft Corporation" "C:\Program Files\Microsoft OneDrive\21.230.1107.0004\OneDriveUpdaterService.exe" "Tue Dec 7 07:14:41 2021" "
+ "OneSyncSvc" "Sync Host: This service synchronizes mail, contacts, calendar and various other user data. Mail and other applications dependent on this functionality will not work properly when this service is not running." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\APHostService.dll" "Fri Jun 4 20:12:00 2021" "
+ "OneSyncSvc_6a9e6" "Sync Host_6a9e6: This service synchronizes mail, contacts, calendar and various other user data. Mail and other applications dependent on this functionality will not work properly when this service is not running." "(Verified) Microsoft Windows Publisher" "C:\WINDOWS\system32\svchost.exe" "Sat Jun 5 13:05:23 2021" "
+ "p2pimsvc" "Peer Networking Identity Manager: Provides identity services for the Peer Name Resolution Protocol (PNRP) and Peer-to-Peer Grouping services. If disabled, the Peer Name Resolution Protocol (PNRP) and Peer-to-Peer Grouping services may not function, and some applications, such as HomeGroup and Remote Assistance, may not function correctly." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\pnrpsvc.dll" "Sat Jun 5 13:06:16 2021" "
+ "p2psvc" "Peer Networking Grouping: Enables multi-party communication using Peer-to-Peer Grouping. If disabled, some applications, such as HomeGroup, may not function." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\p2psvc.dll" "Sat Jun 5 13:06:16 2021" "
+ "P9RdrService" "P9RdrService: Enables trigger-starting plan9 file servers." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\p9rdrservice.dll" "Sat Jun 5 13:06:17 2021" "
+ "P9RdrService_6a9e6" "P9RdrService_6a9e6: Enables trigger-starting plan9 file servers." "(Verified) Microsoft Windows Publisher" "C:\WINDOWS\system32\svchost.exe" "Sat Jun 5 13:05:23 2021" "
+ "PcaSvc" "Program Compatibility Assistant Service: This service provides support for the Program Compatibility Assistant (PCA). PCA monitors programs installed and run by the user and detects known compatibility problems. If this service is stopped, PCA will not function properly." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\pcasvc.dll" "Thu Dec 16 07:53:34 2021" "
+ "PenService" "PenService: Pen Service" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\PenService.dll" "Thu Dec 16 07:56:21 2021" "
+ "PenService_6a9e6" "PenService_6a9e6: Pen Service" "(Verified) Microsoft Windows Publisher" "C:\WINDOWS\system32\svchost.exe" "Sat Jun 5 13:05:23 2021" "
+ "perceptionsimulation" "Windows Perception Simulation Service: Enables spatial perception simulation, virtual camera management and spatial input simulation." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\PerceptionSimulation\PerceptionSimulationService.exe" "Sat Jun 5 13:06:00 2021" "
+ "PerfHost" "Performance Counter DLL Host: Enables remote users and 64-bit processes to query performance counters provided by 32-bit DLLs. If this service is stopped, only local users and 32-bit processes will be able to query performance counters provided by 32-bit DLLs." "(Verified) Microsoft Windows" "C:\WINDOWS\SysWow64\perfhost.exe" "Sat Jun 5 13:05:55 2021" "
+ "PhoneSvc" "Phone Service: Manages the telephony state on the device" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\PhoneService.dll" "Thu Dec 16 07:51:29 2021" "
+ "PimIndexMaintenanceSvc" "Contact Data: Indexes contact data for fast contact searching. If you stop or disable this service, contacts might be missing from your search results." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\PimIndexMaintenance.dll" "Sat Jun 5 13:05:09 2021" "
+ "PimIndexMaintenanceSvc_6a9e6" "Contact Data_6a9e6: Indexes contact data for fast contact searching. If you stop or disable this service, contacts might be missing from your search results." "(Verified) Microsoft Windows Publisher" "C:\WINDOWS\system32\svchost.exe" "Sat Jun 5 13:05:23 2021" "
+ "pla" "Performance Logs & Alerts: Performance Logs and Alerts Collects performance data from local or remote computers based on preconfigured schedule parameters, then writes the data to a log or triggers an alert. If this service is stopped, performance information will not be collected. If this service is disabled, any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\pla.dll" "Sat Jun 5 13:06:10 2021" "
+ "PlugPlay" "Plug and Play: Enables a computer to recognize and adapt to hardware changes with little or no user input. Stopping or disabling this service will result in system instability." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\umpnpmgr.dll" "Sat Jun 5 13:05:39 2021" "
+ "PNRPAutoReg" "PNRP Machine Name Publication Service: This service publishes a machine name using the Peer Name Resolution Protocol. Configuration is managed via the netsh context 'p2p pnrp peer' " "(Verified) Microsoft Windows" "C:\WINDOWS\system32\pnrpauto.dll" "Sat Jun 5 13:06:16 2021" "
+ "PNRPsvc" "Peer Name Resolution Protocol: Enables serverless peer name resolution over the Internet using the Peer Name Resolution Protocol (PNRP). If disabled, some peer-to-peer and collaborative applications, such as Remote Assistance, may not function." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\pnrpsvc.dll" "Sat Jun 5 13:06:16 2021" "
+ "PolicyAgent" "IPsec Policy Agent: Internet Protocol security (IPsec) supports network-level peer authentication, data origin authentication, data integrity, data confidentiality (encryption), and replay protection. This service enforces IPsec policies created through the IP Security Policies snap-in or the command-line tool "netsh ipsec". If you stop this service, you may experience network connectivity issues if your policy requires that connections use IPsec. Also,remote management of Windows Defender Firewall is not available when this service is stopped." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\ipsecsvc.dll" "Sat Jun 5 13:05:29 2021" "
+ "Power" "Power: Manages power policy and power policy notification delivery." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\umpo.dll" "Sat Jun 5 13:04:52 2021" "
+ "PrintNotify" "Printer Extensions and Notifications: This service opens custom printer dialogue boxes and handles notifications from a remote print server or a printer. If you turn this service off, you won’t be able to see printer extensions or notifications." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\spool\drivers\x64\3\PrintConfig.dll" "Thu Dec 16 07:50:54 2021" "
+ "PrintWorkflowUserSvc" "PrintWorkflow: Provides support for Print Workflow applications. If you turn off this service, you may not be able to print successfully." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\PrintWorkflowService.dll" "Thu Dec 16 07:54:54 2021" "
+ "PrintWorkflowUserSvc_6a9e6" "PrintWorkflow_6a9e6: Provides support for Print Workflow applications. If you turn off this service, you may not be able to print successfully." "(Verified) Microsoft Windows Publisher" "C:\WINDOWS\system32\svchost.exe" "Sat Jun 5 13:05:23 2021" "
+ "ProfSvc" "User Profile Service: This service is responsible for loading and unloading user profiles. If this service is stopped or disabled, users will no longer be able to successfully sign in or sign out, apps might have problems getting to users' data, and components registered to receive profile event notifications won't receive them." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\profsvc.dll" "Thu Dec 16 07:53:44 2021" "
+ "PushToInstall" "Windows PushToInstall Service: Provides infrastructure support for the Microsoft Store. This service is started automatically and if disabled then remote installations will not function properly." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\PushToInstall.dll" "Thu Dec 16 07:52:32 2021" "
+ "QASvc" "Quick Access Service: Quick Access Service" "(Verified) Acer Incorporated" "C:\Program Files\Acer\Quick Access Service\QASvc.exe" "Thu Sep 10 13:58:18 2020" "
+ "QcomWlanSrv" "Qualcomm Atheros WLAN Driver Service: " "(Verified) Qualcomm Atheros, Inc." "C:\WINDOWS\System32\drivers\QcomWlanSrvx64.exe" "Sun Jul 18 20:19:12 2021" "
+ "QWAVE" "Quality Windows Audio Video Experience: Quality Windows Audio Video Experience (qWave) is a networking platform for Audio Video (AV) streaming applications on IP home networks. qWave enhances AV streaming performance and reliability by ensuring network quality-of-service (QoS) for AV applications. It provides mechanisms for admission control, run time monitoring and enforcement, application feedback, and traffic prioritization." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\qwave.dll" "Sat Jun 5 13:05:39 2021" "
+ "RasAuto" "Remote Access Auto Connection Manager: Creates a connection to a remote network whenever a program references a remote DNS or NetBIOS name or address." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\rasauto.dll" "Sat Jun 5 13:05:40 2021" "
+ "RasMan" "Remote Access Connection Manager: Manages dial-up and virtual private network (VPN) connections from this computer to the Internet or other remote networks. If this service is disabled, any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\rasmans.dll" "Thu Dec 16 07:54:56 2021" "
+ X "RemoteAccess" "Routing and Remote Access: Offers routing services to businesses in local area and wide area network environments." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\mprdim.dll" "Sat Jun 5 13:05:40 2021" "
+ X "RemoteRegistry" "Remote Registry: Enables remote users to modify registry settings on this computer. If this service is stopped, the registry can be modified only by users on this computer. If this service is disabled, any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\regsvc.dll" "Sat Jun 5 13:06:02 2021" "
+ "RetailDemo" "Retail Demo Service: The Retail Demo service controls device activity while the device is in retail demo mode." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\RDXService.dll" "Sat Jun 5 13:06:00 2021" "
+ "RmSvc" "Radio Management Service: Radio Management and Airplane Mode Service" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\RMapi.dll" "Sat Jun 5 13:05:40 2021" "
+ "RpcEptMapper" "RPC Endpoint Mapper: Resolves RPC interfaces identifiers to transport endpoints. If this service is stopped or disabled, programs using Remote Procedure Call (RPC) services will not function properly." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\RpcEpMap.dll" "Sat Jun 5 13:05:25 2021" "
+ "RpcLocator" "Remote Procedure Call (RPC) Locator: In Windows 2003 and earlier versions of Windows, the Remote Procedure Call (RPC) Locator service manages the RPC name service database. In Windows Vista and later versions of Windows, this service does not provide any functionality and is present for application compatibility." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\locator.exe" "Sat Jun 5 13:05:23 2021" "
+ "RpcSs" "Remote Procedure Call (RPC): The RPCSS service is the Service Control Manager for COM and DCOM servers. It performs object activations requests, object exporter resolutions and distributed garbage collection for COM and DCOM servers. If this service is stopped or disabled, programs using COM or DCOM will not function properly. It is strongly recommended that you have the RPCSS service running." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\rpcss.dll" "Thu Dec 16 07:53:43 2021" "
+ "RstMwService" "Intel(R) Storage Middleware Service: RPC endpoint service which allows communication between driver and Windows Store Application" "(Verified) Intel(R) Rapid Storage Technology" "C:\WINDOWS\System32\DriverStore\FileRepository\iastorac.inf_amd64_34f570cbe7f3d6c7\RstMwService.exe" "Sun Oct 10 17:41:43 2021" "
+ "RtkAudioUniversalService" "Realtek Audio Universal Service: Realtek Audio Universal Service" "(Verified) Realtek Semiconductor Corp." "C:\WINDOWS\System32\DriverStore\FileRepository\realtekservice.inf_amd64_f043f909bedcd504\RtkAudUService64.exe" "Wed Oct 6 20:03:40 2021" "
+ "SamSs" "Security Accounts Manager: The startup of this service signals other services that the Security Accounts Manager (SAM) is ready to accept requests. Disabling this service will prevent other services in the system from being notified when the SAM is ready, which may in turn cause those services to fail to start correctly. This service should not be disabled." "(Verified) Microsoft Windows Publisher" "C:\WINDOWS\system32\lsass.exe" "Thu Dec 16 07:53:50 2021" "
+ "SCardSvr" "Smart Card: Manages access to smart cards read by this computer. If this service is stopped, this computer will be unable to read smart cards. If this service is disabled, any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\SCardSvr.dll" "Sat Jun 5 13:05:34 2021" "
+ "ScDeviceEnum" "Smart Card Device Enumeration Service: Creates software device nodes for all smart card readers accessible to a given session. If this service is disabled, WinRT APIs will not be able to enumerate smart card readers." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\ScDeviceEnum.dll" "Sat Jun 5 13:05:34 2021" "
+ "Schedule" "Task Scheduler: Enables a user to configure and schedule automated tasks on this computer. The service also hosts multiple Windows system-critical tasks. If this service is stopped or disabled, these tasks will not be run at their scheduled times. If this service is disabled, any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\schedsvc.dll" "Sat Jun 5 13:05:12 2021" "
+ "SCPolicySvc" "Smart Card Removal Policy: Allows the system to be configured to lock the user desktop upon smart card removal." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\certprop.dll" "Sat Jun 5 13:05:34 2021" "
+ "SDRSVC" "Windows Backup: Provides Windows Backup and Restore capabilities." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\SDRSVC.dll" "Sat Jun 5 13:06:00 2021" "
+ "seclogon" "Secondary Logon: Enables starting processes under alternate credentials. If this service is stopped, this type of log-on access will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\seclogon.dll" "Sat Jun 5 13:05:39 2021" "
+ "SecurityHealthService" "Windows Security Service: Windows Security Service handles unified device protection and health information" "(Verified) Microsoft Windows Publisher" "C:\WINDOWS\system32\SecurityHealthService.exe" "Thu Dec 16 07:54:13 2021" "
+ "SEMgrSvc" "Payments and NFC/SE Manager: Manages payments and Near Field Communication (NFC) based secure elements." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\SEMgrSvc.dll" "Sat Jun 5 13:05:05 2021" "
+ "SENS" "System Event Notification Service: Monitors system events and notifies subscribers to COM+ Event System of these events." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\sens.dll" "Sat Jun 5 13:05:40 2021" "
+ "SensorDataService" "Sensor Data Service: Delivers data from a variety of sensors" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\SensorDataService.exe" "Sat Jun 5 13:05:27 2021" "
+ "SensorService" "Sensor Service: A service for sensors that manages different sensors' functionality. Manages Simple Device Orientation (SDO) and History for sensors. Loads the SDO sensor that reports device orientation changes. If this service is stopped or disabled, the SDO sensor will not be loaded and so auto-rotation will not occur. History collection from Sensors will also be stopped." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\SensorService.dll" "Thu Dec 16 07:53:06 2021" "
+ "SensrSvc" "Sensor Monitoring Service: Monitors various sensors in order to expose data and adapt to system and user state. If this service is stopped or disabled, the display brightness will not adapt to lighting conditions. Stopping this service may affect other system functionality and features as well." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\sensrsvc.dll" "Sat Jun 5 13:05:33 2021" "
+ "SessionEnv" "Remote Desktop Configuration: Remote Desktop Configuration service (RDCS) is responsible for all Remote Desktop Services and Remote Desktop related configuration and session maintenance activities that require SYSTEM context. These include per-session temporary folders, RD themes, and RD certificates." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\sessenv.dll" "Sat Jun 5 13:06:14 2021" "
+ "SgrmBroker" "System Guard Runtime Monitor Broker: Monitors and attests to the integrity of the Windows platform." "(Verified) Microsoft Windows Publisher" "C:\WINDOWS\system32\SgrmBroker.exe" "Sat Jun 5 13:06:00 2021" "
+ "SharedAccess" "Internet Connection Sharing (ICS): Provides network address translation, addressing, name resolution and/or intrusion prevention services for a home or small office network." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\ipnathlp.dll" "Sat Jun 5 13:05:40 2021" "
+ "SharedRealitySvc" "Spatial Data Service: This service is used for Spatial Perception scenarios" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\SharedRealitySvc.dll" "Sat Jun 5 13:06:16 2021" "
+ "ShellHWDetection" "Shell Hardware Detection: Provides notifications for AutoPlay hardware events." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\shsvcs.dll" "Sat Jun 5 13:06:05 2021" "
+ X "shpamsvc" "Shared PC Account Manager: Manages profiles and accounts on a SharedPC configured device" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\Windows.SharedPC.AccountManager.dll" "Sat Jun 5 13:05:19 2021" "
+ "smphost" "Microsoft Storage Spaces SMP: Host service for the Microsoft Storage Spaces management provider. If this service is stopped or disabled, Storage Spaces cannot be managed." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\smphost.dll" "Sat Jun 5 13:06:02 2021" "
+ "SmsRouter" "Microsoft Windows SMS Router Service.: Routes messages based on rules to appropriate clients." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\SmsRouterSvc.dll" "Thu Dec 16 07:56:20 2021" "
+ X "SNMPTrap" "SNMP Trap: Receives trap messages generated by local or remote Simple Network Management Protocol (SNMP) agents and forwards the messages to SNMP management programs running on this computer. If this service is stopped, SNMP-based programs on this computer will not receive SNMP trap messages. If this service is disabled, any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\snmptrap.exe" "Sat Jun 5 13:05:34 2021" "
+ "spectrum" "Windows Perception Service: Enables spatial perception, spatial input, and holographic rendering." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\spectrum.exe" "Thu Dec 16 07:56:55 2021" "
+ "Spooler" "Print Spooler: This service spools print jobs and handles interaction with the printer. If you turn off this service, you won’t be able to print or see your printers." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\spoolsv.exe" "Thu Dec 16 07:51:44 2021" "
+ "sppsvc" "Software Protection: Enables the download, installation and enforcement of digital licenses for Windows and Windows applications. If the service is disabled, the operating system and licensed applications may run in a notification mode. It is strongly recommended that you not disable the Software Protection service." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\sppsvc.exe" "Thu Dec 16 07:54:28 2021" "
+ "SSDPSRV" "SSDP Discovery: Discovers networked devices and services that use the SSDP discovery protocol, such as UPnP devices. Also announces SSDP devices and services running on the local computer. If this service is stopped, SSDP-based devices will not be discovered. If this service is disabled, any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\ssdpsrv.dll" "Sat Jun 5 13:06:00 2021" "
+ X "ssh-agent" "OpenSSH Authentication Agent: Agent to hold private keys used for public key authentication." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\OpenSSH\ssh-agent.exe" "Fri Jun 4 18:53:00 2021" "
+ "SstpSvc" "Secure Socket Tunneling Protocol Service: Provides support for the Secure Socket Tunneling Protocol (SSTP) to connect to remote computers using VPN. If this service is disabled, users will not be able to use SSTP to access remote servers." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\sstpsvc.dll" "Sat Jun 5 13:05:40 2021" "
+ "StateRepository" "State Repository Service: Provides required infrastructure support for the application model." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\windows.staterepository.dll" "Thu Dec 16 07:52:36 2021" "
+ "StiSvc" "Windows Image Acquisition (WIA): Provides image acquisition services for scanners and cameras" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\wiaservc.dll" "Thu Dec 16 07:56:31 2021" "
+ "StorSvc" "Storage Service: Provides enabling services for storage settings and external storage expansion" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\storsvc.dll" "Thu Dec 16 07:56:31 2021" "
+ "svsvc" "Spot Verifier: Verifies potential file system corruptions." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\svsvc.dll" "Sat Jun 5 13:06:15 2021" "
+ "swprv" "Microsoft Software Shadow Copy Provider: Manages software-based volume shadow copies taken by the Volume Shadow Copy service. If this service is stopped, software-based volume shadow copies cannot be managed. If this service is disabled, any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\swprv.dll" "Thu Dec 16 07:53:11 2021" "
+ "SysMain" "SysMain: Maintains and improves system performance over time." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\sysmain.dll" "Thu Dec 16 07:56:56 2021" "
+ "SystemEventsBroker" "System Events Broker: Coordinates execution of background work for WinRT application. If this service is stopped or disabled, then background work might not be triggered." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\SystemEventsBrokerServer.dll" "Sat Jun 5 13:05:09 2021" "
+ "TabletInputService" "Touch Keyboard and Handwriting Panel Service: Enables Touch Keyboard and Handwriting Panel pen and ink functionality" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\TabSvc.dll" "Sat Jun 5 13:05:12 2021" "
+ "TapiSrv" "Telephony: Provides Telephony API (TAPI) support for programs that control telephony devices on the local computer and, through the LAN, on servers that are also running the service." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\tapisrv.dll" "Sat Jun 5 13:06:13 2021" "
+ "TermService" "Remote Desktop Services: Allows users to connect interactively to a remote computer. Remote Desktop and Remote Desktop Session Host Server depend on this service. To prevent remote use of this computer, clear the checkboxes on the Remote tab of the System properties control panel item." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\termsrv.dll" "Thu Dec 16 07:56:44 2021" "
+ "Themes" "Themes: Provides user experience theme management." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\themeservice.dll" "Sat Jun 5 13:05:14 2021" "
+ "TieringEngineService" "Storage Tiers Management: Optimizes the placement of data in storage tiers on all tiered storage spaces in the system." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\TieringEngineService.exe" "Sat Jun 5 13:06:13 2021" "
+ "TimeBrokerSvc" "Time Broker: Coordinates execution of background work for WinRT application. If this service is stopped or disabled, then background work might not be triggered." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\TimeBrokerServer.dll" "Sat Jun 5 13:05:09 2021" "
+ "TokenBroker" "Web Account Manager: This service is used by Web Account Manager to provide single-sign-on to apps and services." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\TokenBroker.dll" "Thu Dec 16 07:52:14 2021" "
+ "TrkWks" "Distributed Link Tracking Client: Maintains links between NTFS files within a computer or across computers in a network." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\trkwks.dll" "Sat Jun 5 13:05:23 2021" "
+ "TroubleshootingSvc" "Recommended Troubleshooting Service: Enables automatic mitigation for known problems by applying recommended troubleshooting. If stopped, your device will not get recommended troubleshooting for problems on your device." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\MitigationClient.dll" "Sat Jun 5 13:04:52 2021" "
+ "TrustedInstaller" "Windows Modules Installer: Enables installation, modification, and removal of Windows updates and optional components. If this service is disabled, install or uninstall of Windows updates might fail for this computer." "(Verified) Microsoft Windows" "C:\WINDOWS\servicing\TrustedInstaller.exe" "Thu Dec 16 07:55:09 2021" "
+ X "tzautoupdate" "Auto Time Zone Updater: Automatically sets the system time zone." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\tzautoupdate.dll" "Thu Dec 16 07:52:51 2021" "
+ "UdkUserSvc" "Udk User Service: Shell components service" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\windowsudkservices.shellcommon.dll" "Thu Dec 16 07:53:02 2021" "
+ "UdkUserSvc_6a9e6" "Udk User Service_6a9e6: Shell components service" "(Verified) Microsoft Windows Publisher" "C:\WINDOWS\system32\svchost.exe" "Sat Jun 5 13:05:23 2021" "
+ "UEIPSvc" "User Experience Improvement Program: UEIPSvc" "(Verified) Acer Incorporated" "C:\Program Files\Acer\User Experience Improvement Program Service\Framework\UBTService.exe" "Sun Aug 9 21:39:42 2020" "
+ X "uhssvc" "Microsoft Update Health Service: Maintains Update Health" "(Verified) Microsoft Windows" "C:\Program Files\Microsoft Update Health Tools\uhssvc.exe" "Mon Oct 25 22:43:24 2021" "
+ "UmRdpService" "Remote Desktop Services UserMode Port Redirector: Allows the redirection of Printers/Drives/Ports for RDP connections" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\umrdp.dll" "Sat Jun 5 13:06:13 2021" "
+ "UnistoreSvc" "User Data Storage: Handles storage of structured user data, including contact info, calendars, messages and other content. If you stop or disable this service, apps that use this data might not work correctly." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\unistore.dll" "Sat Jun 5 13:05:09 2021" "
+ "UnistoreSvc_6a9e6" "User Data Storage_6a9e6: Handles storage of structured user data, including contact info, calendars, messages and other content. If you stop or disable this service, apps that use this data might not work correctly." "(Verified) Microsoft Windows Publisher" "C:\WINDOWS\System32\svchost.exe" "Sat Jun 5 13:05:23 2021" "
+ "upnphost" "UPnP Device Host: Allows UPnP devices to be hosted on this computer. If this service is stopped, any hosted UPnP devices will stop functioning and no additional hosted devices can be added. If this service is disabled, any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\upnphost.dll" "Sat Jun 5 13:06:00 2021" "
+ "UserDataSvc" "User Data Access: Provides apps with access to structured user data, including contact info, calendars, messages and other content. If you stop or disable this service, apps that use this data might not work correctly." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\userdataservice.dll" "Sat Jun 5 13:05:09 2021" "
+ "UserDataSvc_6a9e6" "User Data Access_6a9e6: Provides apps with access to structured user data, including contact info, calendars, messages and other content. If you stop or disable this service, apps that use this data might not work correctly." "(Verified) Microsoft Windows Publisher" "C:\WINDOWS\system32\svchost.exe" "Sat Jun 5 13:05:23 2021" "
+ "UserManager" "User Manager: User Manager provides the runtime components required for multi-user interaction. If this service is stopped, some applications may not operate correctly." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\usermgr.dll" "Thu Dec 16 07:53:54 2021" "
+ "UsoSvc" "Update Orchestrator Service: Manages Windows Updates. If stopped, your devices will not be able to download and install the latest updates." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\usosvc.dll" "Thu Dec 16 07:53:09 2021" "
+ "VacSvc" "Volumetric Audio Compositor Service: Hosts spatial analysis for Mixed Reality audio simulation." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\vac.dll" "Sat Jun 5 13:04:53 2021" "
+ "VaultSvc" "Credential Manager: Provides secure storage and retrieval of credentials to users, applications and security service packages." "(Verified) Microsoft Windows" "C:\Windows\System32\vaultsvc.dll" "Sat Jun 5 13:05:12 2021" "
+ "vds" "Virtual Disk: Provides management services for disks, volumes, file systems, and storage arrays." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\vds.exe" "Thu Dec 16 07:53:03 2021" "
+ "vmicguestinterface" "Hyper-V Guest Service Interface: Provides an interface for the Hyper-V host to interact with specific services running inside the virtual machine." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\icsvc.dll" "Sat Jun 5 13:06:16 2021" "
+ "vmicheartbeat" "Hyper-V Heartbeat Service: Monitors the state of this virtual machine by reporting a heartbeat at regular intervals. This service helps you identify running virtual machines that have stopped responding." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\icsvc.dll" "Sat Jun 5 13:06:16 2021" "
+ "vmickvpexchange" "Hyper-V Data Exchange Service: Provides a mechanism to exchange data between the virtual machine and the operating system running on the physical computer." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\icsvc.dll" "Sat Jun 5 13:06:16 2021" "
+ "vmicrdv" "Hyper-V Remote Desktop Virtualization Service: Provides a platform for communication between the virtual machine and the operating system running on the physical computer." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\icsvcext.dll" "Sat Jun 5 13:06:16 2021" "
+ "vmicshutdown" "Hyper-V Guest Shutdown Service: Provides a mechanism to shut down the operating system of this virtual machine from the management interfaces on the physical computer." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\icsvc.dll" "Sat Jun 5 13:06:16 2021" "
+ "vmictimesync" "Hyper-V Time Synchronization Service: Synchronizes the system time of this virtual machine with the system time of the physical computer." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\icsvc.dll" "Sat Jun 5 13:06:16 2021" "
+ "vmicvmsession" "Hyper-V PowerShell Direct Service: Provides a mechanism to manage virtual machine with PowerShell via VM session without a virtual network." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\icsvc.dll" "Sat Jun 5 13:06:16 2021" "
+ "vmicvss" "Hyper-V Volume Shadow Copy Requestor: Coordinates the communications that are required to use Volume Shadow Copy Service to back up applications and data on this virtual machine from the operating system on the physical computer." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\icsvcvss.dll" "Sat Jun 5 13:06:16 2021" "
+ "VSS" "Volume Shadow Copy: Manages and implements Volume Shadow Copies used for backup and other purposes. If this service is stopped, shadow copies will be unavailable for backup and the backup may fail. If this service is disabled, any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\vssvc.exe" "Thu Dec 16 07:53:11 2021" "
+ "W32Time" "Windows Time: Maintains date and time synchronization on all clients and servers in the network. If this service is stopped, date and time synchronization will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\w32time.dll" "Thu Dec 16 07:51:50 2021" "
+ "WaaSMedicSvc" "Windows Update Medic Service: Enables remediation and protection of Windows Update components." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\WaaSMedicSvc.dll" "Thu Dec 16 07:52:33 2021" "
+ "WalletService" "WalletService: Hosts objects used by clients of the wallet" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\WalletService.dll" "Thu Dec 16 08:01:10 2021" "
+ "WarpJITSvc" "Warp JIT Service: Enables JIT compilation support in d3d10warp.dll for processes in which code generation is disabled." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Windows.WARP.JITService.dll" "Sat Jun 5 13:05:06 2021" "
+ "wbengine" "Block Level Backup Engine Service: The WBENGINE service is used by Windows Backup to perform backup and recovery operations. If this service is stopped by a user, it may cause the currently running backup or recovery operation to fail. Disabling this service may disable backup and recovery operations using Windows Backup on this computer." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wbengine.exe" "Sat Jun 5 13:06:48 2021" "
+ "WbioSrvc" "Windows Biometric Service: The Windows biometric service gives client applications the ability to capture, compare, manipulate, and store biometric data without gaining direct access to any biometric hardware or samples. The service is hosted in a privileged SVCHOST process." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\wbiosrvc.dll" "Sat Jun 5 13:05:16 2021" "
+ "Wcmsvc" "Windows Connection Manager: Makes automatic connect/disconnect decisions based on the network connectivity options currently available to the PC and enables management of network connectivity based on Group Policy settings." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\wcmsvc.dll" "Thu Dec 16 07:51:50 2021" "
+ "wcncsvc" "Windows Connect Now - Config Registrar: WCNCSVC hosts the Windows Connect Now Configuration, which is Microsoft's Implementation of the Wireless Protected Setup (WPS) protocol. This is used to configure Wireless LAN settings for an Access Point (AP) or a Wireless Device. The service is started programmatically as needed." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\wcncsvc.dll" "Sat Jun 5 13:04:59 2021" "
+ "WdiServiceHost" "Diagnostic Service Host: The Diagnostic Service Host is used by the Diagnostic Policy Service to host diagnostics that need to run in a Local Service context. If this service is stopped, any diagnostics that depend on it will no longer function." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wdi.dll" "Sat Jun 5 13:05:29 2021" "
+ "WdiSystemHost" "Diagnostic System Host: The Diagnostic System Host is used by the Diagnostic Policy Service to host diagnostics that need to run in a Local System context. If this service is stopped, any diagnostics that depend on it will no longer function." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wdi.dll" "Sat Jun 5 13:05:29 2021" "
+ "WdNisSvc" "Microsoft Defender Antivirus Network Inspection Service: Helps guard against intrusion attempts targeting known and newly discovered vulnerabilities in network protocols" "(Verified) Microsoft Windows Publisher" "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2111.5-0\NisSrv.exe" "Thu Dec 16 00:20:53 2021" "
+ "WebClient" "WebClient: Enables Windows-based programs to create, access, and modify Internet-based files. If this service is stopped, these functions will not be available. If this service is disabled, any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\webclnt.dll" "Thu Dec 16 07:56:56 2021" "
+ "Wecsvc" "Windows Event Collector: This service manages persistent subscriptions to events from remote sources that support WS-Management protocol. This includes Windows Vista event logs, hardware and IPMI-enabled event sources. The service stores forwarded events in a local Event Log. If this service is stopped or disabled event subscriptions cannot be created and forwarded events cannot be accepted." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wecsvc.dll" "Sat Jun 5 13:06:05 2021" "
+ "WEPHOSTSVC" "Windows Encryption Provider Host Service: Windows Encryption Provider Host Service brokers encryption related functionalities from 3rd Party Encryption Providers to processes that need to evaluate and apply EAS policies. Stopping this will compromise EAS compliancy checks that have been established by the connected Mail Accounts" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wephostsvc.dll" "Sat Jun 5 13:06:05 2021" "
+ "wercplsupport" "Problem Reports Control Panel Support: This service provides support for viewing, sending and deletion of system-level problem reports for the Problem Reports control panel." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\wercplsupport.dll" "Sat Jun 5 13:06:05 2021" "
+ "WerSvc" "Windows Error Reporting Service: Allows errors to be reported when programs stop working or responding and allows existing solutions to be delivered. Also allows logs to be generated for diagnostic and repair services. If this service is stopped, error reporting might not work correctly and results of diagnostic services and repairs might not be displayed." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\WerSvc.dll" "Sat Jun 5 13:05:25 2021" "
+ "WFDSConMgrSvc" "Wi-Fi Direct Services Connection Manager Service: Manages connections to wireless services, including wireless display and docking." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\wfdsconmgrsvc.dll" "Sat Jun 5 13:05:00 2021" "
+ "WiaRpc" "Still Image Acquisition Events: Launches applications associated with still image acquisition events." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\wiarpc.dll" "Thu Dec 16 07:56:31 2021" "
+ "WinDefend" "Microsoft Defender Antivirus Service: Helps protect users from malware and other potentially unwanted software" "(Verified) Microsoft Windows Publisher" "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2111.5-0\MsMpEng.exe" "Thu Dec 16 00:20:53 2021" "
+ "WinHttpAutoProxySvc" "WinHTTP Web Proxy Auto-Discovery Service: WinHTTP implements the client HTTP stack and provides developers with a Win32 API and COM Automation component for sending HTTP requests and receiving responses. In addition, WinHTTP provides support for auto-discovering a proxy configuration via its implementation of the Web Proxy Auto-Discovery (WPAD) protocol." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\winhttp.dll" "Sat Jun 5 13:05:25 2021" "
+ "Winmgmt" "Windows Management Instrumentation: Provides a common interface and object model to access management information about operating system, devices, applications and services. If this service is stopped, most Windows-based software will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wbem\WMIsvc.dll" "Sat Jun 5 13:05:14 2021" "
+ "WinRM" "Windows Remote Management (WS-Management): Windows Remote Management (WinRM) service implements the WS-Management protocol for remote management. WS-Management is a standard web services protocol used for remote software and hardware management. The WinRM service listens on the network for WS-Management requests and processes them. The WinRM Service needs to be configured with a listener using winrm.cmd command line tool or through Group Policy in order for it to listen over the network. The WinRM service provides access to WMI data and enables event collection. Event collection and subscription to events require that the service is running. WinRM messages use HTTP and HTTPS as transports. The WinRM service does not depend on IIS but is preconfigured to share a port with IIS on the same machine. The WinRM service reserves the /wsman URL prefix. To prevent conflicts with IIS, administrators should ensure that any websites hosted on IIS do not use the /wsman URL prefix." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\WsmSvc.dll" "Thu Dec 16 07:53:04 2021" "
+ "wisvc" "Windows Insider Service: Provides infrastructure support for the Windows Insider Programme. This service must remain enabled for the Windows Insider Programme to work." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\flightsettings.dll" "Thu Dec 16 07:51:40 2021" "
+ "WlanSvc" "WLAN AutoConfig: The WLANSVC service provides the logic required to configure, discover, connect to and disconnect from a wireless local area network (WLAN) as defined by IEEE 802.11 standards. It also contains the logic to turn your computer into a software access point so that other devices or computers can connect to your computer wirelessly using a WLAN adapter that can support this. Stopping or disabling the WLANSVC service will make all WLAN adapters on your computer inaccessible from the Windows networking UI. It is strongly recommended that you have the WLANSVC service running if your computer has a WLAN adapter." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\wlansvc.dll" "Thu Dec 16 07:51:52 2021" "
+ "wlidsvc" "Microsoft Account Sign-in Assistant: Enables user sign-in through Microsoft account identity services. If this service is stopped, users will not be able to logon to the computer with their Microsoft account." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wlidsvc.dll" "Thu Dec 16 07:52:13 2021" "
+ "wlpasvc" "Local Profile Assistant Service: This service provides profile management for subscriber identity modules" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\lpasvc.dll" "Thu Dec 16 07:51:22 2021" "
+ "WManSvc" "Windows Management Service: Performs management including Provisioning and Enrollment activities" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\Windows.Management.Service.dll" "Sat Jun 5 13:04:52 2021" "
+ "wmiApSrv" "WMI Performance Adapter: Provides performance library information from Windows Management Instrumentation (WMI) providers to clients on the network. This service only runs when Performance Data Helper is activated." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wbem\WmiApSrv.exe" "Sat Jun 5 13:04:58 2021" "
+ "WMPNetworkSvc" "Windows Media Player Network Sharing Service: Shares Windows Media Player libraries with other networked players and media devices using Universal Plug and Play" "(Verified) Microsoft Windows" "C:\Program Files\Windows Media Player\wmpnetwk.exe" "Sat Jun 5 02:32:00 2021" "
+ "workfolderssvc" "Work Folders: This service syncs files with the Work Folders server, enabling you to use the files on any of the PCs and devices on which you've set up Work Folders." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\workfolderssvc.dll" "Thu Dec 16 07:56:45 2021" "
+ "WpcMonSvc" "Parental Controls: Enforces parental controls for child accounts in Windows. If this service is stopped or disabled, parental controls may not be enforced." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\WpcDesktopMonSvc.dll" "Thu Dec 16 07:51:42 2021" "
+ "WPDBusEnum" "Portable Device Enumerator Service: Enforces group policy for removable mass-storage devices. Enables applications such as Windows Media Player and Image Import Wizard to transfer and synchronize content using removable mass-storage devices." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wpdbusenum.dll" "Sat Jun 5 18:17:02 2021" "
+ "WpnService" "Windows Push Notifications System Service: This service runs in session 0 and hosts the notification platform and connection provider which handles the connection between the device and WNS server." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\WpnService.dll" "Thu Dec 16 07:52:48 2021" "
+ "WpnUserService" "Windows Push Notifications User Service: This service hosts the Windows notification platform which provides support for local and push notifications. Supported notifications are tile, toast and raw." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\WpnUserService.dll" "Sat Jun 5 13:05:10 2021" "
+ "WpnUserService_6a9e6" "Windows Push Notifications User Service_6a9e6: This service hosts the Windows notification platform which provides support for local and push notifications. Supported notifications are tile, toast and raw." "(Verified) Microsoft Windows Publisher" "C:\WINDOWS\system32\svchost.exe" "Sat Jun 5 13:05:23 2021" "
+ "wscsvc" "Security Center: The WSCSVC (Windows Security Center) service monitors and reports security health settings on the computer. The health settings include firewall (on/off), antivirus (on/off/out of date), antispyware (on/off/out of date), Windows Update (automatically/manually download and install updates), User Account Control (on/off), and Internet settings (recommended/not recommended). The service provides COM APIs for independent software vendors to register and record the state of their products to the Security Center service. The Security and Maintenance UI uses the service to provide systray alerts and a graphical view of the security health states in the Security and Maintenance control panel. Network Access Protection (NAP) uses the service to report the security health states of clients to the NAP Network Policy Server to make network quarantine decisions. The service also has a public API that allows external consumers to programmatically retrieve the aggregated security health state of the system." "(Verified) Microsoft Windows Publisher" "C:\WINDOWS\System32\wscsvc.dll" "Sat Jun 5 13:04:58 2021" "
+ "WSearch" "Windows Search: Provides content indexing, property caching, and search results for files, e-mail, and other content." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\SearchIndexer.exe" "Thu Dec 16 07:52:24 2021" "
+ "wuauserv" "Windows Update: Enables the detection, download and installation of updates for Windows and other programs. If this service is disabled, users of this computer will not be able to use Windows Update or its automatic updating feature, and programs will not be able to use the Windows Update Agent (WUA) API." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wuaueng.dll" "Thu Dec 16 07:53:10 2021" "
+ "WwanSvc" "WWAN AutoConfig: This service manages mobile broadband (GSM & CDMA) data card/embedded module adapters and connections by auto-configuring the networks. It is strongly recommended that this service be kept running for best user experience of mobile broadband devices." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\wwansvc.dll" "Thu Dec 16 07:51:22 2021" "
+ "XblAuthManager" "Xbox Live Auth Manager: Provides authentication and authorisation services for interacting with Xbox Live. If this service is stopped, some applications may not operate correctly." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\XblAuthManager.dll" "Sat Jun 5 13:04:52 2021" "
+ "XblGameSave" "Xbox Live Game Save: This service syncs save data for Xbox Live save enabled games. If this service is stopped, game save data will not upload to or download from Xbox Live." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\XblGameSave.dll" "Sat Jun 5 13:04:52 2021" "
+ "XboxGipSvc" "Xbox Accessory Management Service: This service manages connected Xbox Accessories." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\XboxGipSvc.dll" "Sat Jun 5 13:04:52 2021" "
+ "XboxNetApiSvc" "Xbox Live Networking Service: This service supports the Windows.Networking.XboxLive application programming interface." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\XboxNetApiSvc.dll" "Sat Jun 5 13:06:00 2021" "
[Drivers]
[HKLM\System\CurrentControlSet\Services]
+ "1394ohci" "1394 OHCI Compliant Host Controller: 1394 OpenHCI Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\1394ohci.sys" "Sat Jun 5 13:04:44 2021" "
+ "3ware" "3ware: LSI 3ware SCSI Storport Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\3ware.sys" "Sat Jun 5 13:04:44 2021" "
+ "ACPI" "Microsoft ACPI Driver: ACPI Driver for NT" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\ACPI.sys" "Thu Dec 16 07:50:55 2021" "
+ "AcpiDev" "ACPI Devices driver: ACPI Devices Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\AcpiDev.sys" "Sat Jun 5 13:04:44 2021" "
+ "acpiex" "Microsoft ACPIEx Driver: ACPIEx Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Drivers\acpiex.sys" "Sat Jun 5 13:04:57 2021" "
+ "acpipagr" "ACPI Processor Aggregator Driver: ACPI Processor Aggregator Device Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\acpipagr.sys" "Sat Jun 5 13:04:45 2021" "
+ "AcpiPmi" "ACPI Power Meter Driver: ACPI Power Metering Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\acpipmi.sys" "Sat Jun 5 13:04:44 2021" "
+ "acpitime" "ACPI Wake Alarm Driver: ACPI Wake Alarm" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\acpitime.sys" "Sat Jun 5 13:04:45 2021" "
+ "Acx01000" "Acx01000: Audio KMDF Class Extension" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\Acx01000.sys" "Sat Jun 5 13:04:57 2021" "
+ "ADP80XX" "ADP80XX: PMC-Sierra Storport Driver For SPC8x6G SAS/SATA controller" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\ADP80XX.SYS" "Sat Jun 5 13:04:44 2021" "
+ "AFD" "Ancillary Function Driver for Winsock: Ancillary Function Driver for Winsock" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\afd.sys" "Thu Dec 16 07:53:51 2021" "
+ "afunix" "afunix: AF_UNIX socket provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\afunix.sys" "Thu Dec 16 07:54:51 2021" "
+ "ahcache" "Application Compatibility Cache: Cache Compatibility Data and Attributes for Individual PE File" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\DRIVERS\ahcache.sys" "Sat Jun 5 13:05:33 2021" "
+ "amdgpio2" "AMD GPIO Client Driver: AMD GPIO Controller Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\amdgpio2.sys" "Sat Jun 5 13:04:42 2021" "
+ "amdi2c" "AMD I2C Controller Service: AMD I2C Controller Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\amdi2c.sys" "Sat Jun 5 13:04:42 2021" "
+ "AmdK8" "AMD K8 Processor Driver: Processor Device Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\amdk8.sys" "Sat Jun 5 13:04:44 2021" "
+ "AmdPPM" "AMD Processor Driver: Processor Device Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\amdppm.sys" "Sat Jun 5 13:04:44 2021" "
+ "amdsata" "amdsata: AHCI 1.3 Device Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\amdsata.sys" "Sat Jun 5 13:04:44 2021" "
+ "amdsbs" "amdsbs: AMD Technology AHCI Compatible Controller Driver for Windows - AMD64 platform" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\amdsbs.sys" "Sat Jun 5 13:04:44 2021" "
+ "amdxata" "amdxata: Storage Filter Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\amdxata.sys" "Sat Jun 5 13:04:44 2021" "
+ "AppID" "AppID Driver: Identifies an application and enforces software restriction policies." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\appid.sys" "Thu Dec 16 07:53:35 2021" "
+ "AppleSSD" "Apple Solid State Drive Device: Apple Solid State Drive Device" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\AppleSSD.sys" "Sat Jun 5 13:04:42 2021" "
+ "applockerfltr" "Smartlocker Filter Driver: Identifies files created by authorized installers." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\applockerfltr.sys" "Sat Jun 5 13:05:21 2021" "
+ "arcsas" "Adaptec SAS/SATA-II RAID Storport's Miniport Driver: Adaptec SAS RAID WS03 Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\arcsas.sys" "Sat Jun 5 13:04:44 2021" "
+ "AsyncMac" "RAS Asynchronous Media Driver: RAS Asynchronous Media Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\asyncmac.sys" "Sat Jun 5 13:05:40 2021" "
+ "atapi" "IDE Channel: ATAPI IDE Miniport Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\atapi.sys" "Thu Dec 16 07:50:56 2021" "
+ "b06bdrv" "QLogic Network Adapter VBD: QLogic Gigabit Ethernet VBD" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\bxvbda.sys" "Sat Jun 5 13:04:44 2021" "
+ "bam" "Background Activity Moderator Driver: Controls activity of background applications" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\bam.sys" "Sat Jun 5 13:05:27 2021" "
+ "BasicDisplay" "BasicDisplay: Microsoft Basic Display Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DriverStore\FileRepository\basicdisplay.inf_amd64_a3f9d7c24b3377b3\BasicDisplay.sys" "Sat Jun 5 13:04:45 2021" "
+ "BasicRender" "BasicRender: Microsoft Basic Render Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DriverStore\FileRepository\basicrender.inf_amd64_e1a5502a3a50be4e\BasicRender.sys" "Sat Jun 5 13:04:45 2021" "
+ "bcmfn2" "bcmfn2 Service: BCM Function 2 Device Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\bcmfn2.sys" "Sat Jun 5 13:04:42 2021" "
+ "Beep" "Beep: BEEP Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Drivers\Beep.sys" "Sat Jun 5 13:05:34 2021" "
+ "bindflt" "Windows Bind Filter Driver: Binds filesystem namespaces to different locations and hides this remapping from the user" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\bindflt.sys" "Thu Dec 16 07:52:56 2021" "
+ "bowser" "Browser: NT Lan Manager Datagram Receiver Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\DRIVERS\bowser.sys" "Thu Dec 16 07:51:46 2021" "
+ "BtFilter" "BtFilter: BT Filter" "(Verified) Qualcomm Atheros, Inc." "C:\WINDOWS\System32\drivers\btfilter.sys" "Mon Jul 19 21:46:02 2021" "
+ "BthA2dp" "Microsoft Bluetooth A2dp driver: Bluetooth A2DP Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\BthA2dp.sys" "Thu Dec 16 07:50:51 2021" "
+ "BthEnum" "Bluetooth Enumerator Service: Bluetooth Bus Extender" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\BthEnum.sys" "Thu Dec 16 07:50:57 2021" "
+ "BthHFEnum" "Microsoft Bluetooth Hands-Free Profile driver: Bluetooth Hands-Free Audio and Call Control HID Enumerator" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\bthhfenum.sys" "Thu Dec 16 07:50:51 2021" "
+ "BthLEEnum" "Bluetooth Low Energy Driver: Legacy Bluetooth LE Bus Enumerator" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\Microsoft.Bluetooth.Legacy.LEEnumerator.sys" "Sat Jun 5 13:04:46 2021" "
+ "BthMini" "Bluetooth Radio Driver: Bluetooth Transport Extensibility Miniport Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\BTHMINI.sys" "Thu Dec 16 07:50:57 2021" "
+ "BTHMODEM" "Bluetooth Modem Communications Driver: Bluetooth Communications Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\bthmodem.sys" "Sat Jun 5 13:04:43 2021" "
+ "BthPan" "Bluetooth Device (Personal Area Network): Bluetooth Device (Personal Area Network)" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\bthpan.sys" "Sat Jun 5 13:04:46 2021" "
+ "BTHPORT" "Bluetooth Port Driver: Bluetooth Bus Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\BTHport.sys" "Thu Dec 16 07:50:57 2021" "
+ "BTHUSB" "Bluetooth Radio USB Driver: Bluetooth Miniport Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\BTHUSB.sys" "Thu Dec 16 07:50:57 2021" "
+ "bttflt" "Microsoft Hyper-V VHDPMEM BTT Filter: VHD BTT Filter Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\bttflt.sys" "Sat Jun 5 13:04:45 2021" "
+ "buttonconverter" "Service for Portable Device Control devices: Button Converter Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\buttonconverter.sys" "Sat Jun 5 13:04:46 2021" "
+ "CAD" "Charge Arbitration Driver: Charge Arbiration Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\CAD.sys" "Sat Jun 5 13:04:42 2021" "
+ X "cdfs" "CD/DVD File System Reader: ISO9660/Joliet File System Reader for CD/DVDs. (Core) (All pieces)" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\DRIVERS\cdfs.sys" "Sat Jun 5 13:06:02 2021" "
+ "cdrom" "CD-ROM Driver: SCSI CD-ROM Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\cdrom.sys" "Sat Jun 5 13:04:44 2021" "
+ "cht4iscsi" "cht4iscsi: Chelsio iSCSI VMiniport Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\cht4sx64.sys" "Sat Jun 5 13:04:45 2021" "
+ "cht4vbd" "Chelsio Virtual Bus Driver: Virtual Bus Driver for Chelsio ® T5/T6 Chipset" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\cht4vx64.sys" "Sat Jun 5 13:04:45 2021" "
+ "CimFS" "CimFS: CimFS driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Drivers\CimFS.sys" "Thu Dec 16 07:52:56 2021" "
+ "circlass" "Consumer IR Devices: Consumer IR Class Driver for eHome" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\circlass.sys" "Sat Jun 5 13:04:42 2021" "
+ "CldFlt" "Windows Cloud Files Filter Driver: Cloud Files Mini Filter Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\cldflt.sys" "Thu Dec 16 07:53:39 2021" "
+ "CLFS" "Common Log (CLFS): General-purpose logging service" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\CLFS.sys" "Thu Dec 16 07:53:53 2021" "
+ "CmBatt" "Microsoft ACPI Control Method Battery Driver: Control Method Battery Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\CmBatt.sys" "Sat Jun 5 13:04:45 2021" "
+ "CNG" "CNG: Kernel Cryptography, Next Generation" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Drivers\cng.sys" "Thu Dec 16 07:53:45 2021" "
+ X "cnghwassist" "CNG Hardware Assist algorithm provider: CNG Hardware Assist algorithm provider" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DRIVERS\cnghwassist.sys" "Sat Jun 5 13:05:16 2021" "
+ "CompositeBus" "Composite Bus Enumerator Driver: Multi-Transport Composite Bus Enumerator" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DriverStore\FileRepository\compositebus.inf_amd64_ab6e2caeac172387\CompositeBus.sys" "Sat Jun 5 13:04:42 2021" "
+ "condrv" "Console Driver: Console Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\condrv.sys" "Thu Dec 16 07:52:57 2021" "
+ "cpuz150" "cpuz150: " "" "File not found: C:\WINDOWS\temp\cpuz150\cpuz150_x64.sys" "Thu Dec 16 10:24:44 2021" "
+ "dam" "Desktop Activity Moderator Driver: Controls activity of desktop applications" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\dam.sys" "Thu Dec 16 07:54:08 2021" "
+ "Dfsc" "DFS Namespace Client Driver: Client driver for access to DFS Namespaces" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Drivers\dfsc.sys" "Sat Jun 5 13:05:27 2021" "
+ "dg_ssudbus" "SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.): SAMSUNG USB Composite Device Driver" "(Verified) Samsung Electronics Co., Ltd." "C:\WINDOWS\System32\drivers\ssudbus2.sys" "Tue Jun 29 05:43:52 2021" "
+ "disk" "Disk Driver: PnP Disk Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\disk.sys" "Sat Jun 5 13:04:44 2021" "
+ "dmvsc" "dmvsc: Dynamic Memory" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\dmvsc.sys" "Sat Jun 5 13:04:47 2021" "
+ "drmkaud" "Microsoft Trusted Audio Drivers: Microsoft Trusted Audio Drivers" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\drmkaud.sys" "Thu Dec 16 07:50:52 2021" "
+ "DXGKrnl" "LDDM Graphics Subsystem: Controls the underlying video driver stacks to provide fully-featured display capabilities." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\dxgkrnl.sys" "Thu Dec 16 07:52:52 2021" "
+ "ebdrv" "QLogic 10 Gigabit Ethernet Adapter VBD: QLogic 10 GigE VBD" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\evbda.sys" "Sat Jun 5 13:04:44 2021" "
+ "ebdrv0" "QLogic Legacy Ethernet Adapter VBD: QLogic 10 GigE VBD" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\evbd0a.sys" "Sat Jun 5 13:04:44 2021" "
+ "EhStorClass" "Enhanced Storage Filter Driver: Enhanced Storage Filter Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\EhStorClass.sys" "Sat Jun 5 13:06:05 2021" "
+ "EhStorTcgDrv" "Microsoft driver for storage devices supporting IEEE 1667 and TCG protocols: Microsoft driver for storage devices supporting IEEE 1667 and TCG protocols" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\EhStorTcgDrv.sys" "Sat Jun 5 13:04:42 2021" "
+ "ErrDev" "Microsoft Hardware Error Device Driver: Error Device Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\errdev.sys" "Sat Jun 5 13:04:45 2021" "
+ "ExecutionContext" "CPU Scheduler for High Performance I/O: CPU Scheduler for High Performance I/O" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Drivers\ExecutionContext.sys" "Sat Jun 5 13:05:25 2021" "
+ "exfat" "exFAT File System Driver: exFAT File System Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Drivers\exfat.sys" "Thu Dec 16 07:51:23 2021" "
+ "fastfat" "FAT12/16/32 File System Driver: Note - dependance on CDROM.SYS only if required to read/write DVD-RAM media (which appears as CD class device). (Core) (All pieces)" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Drivers\fastfat.sys" "Thu Dec 16 07:51:23 2021" "
+ "fdc" "Floppy Disk Controller Driver: Floppy Disk Controller Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\fdc.sys" "Sat Jun 5 13:04:45 2021" "
+ "FileCrypt" "FileCrypt: Windows sandboxing and encryption filter." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\filecrypt.sys" "Sat Jun 5 13:04:57 2021" "
+ "FileInfo" "File Information FS MiniFilter: Collects information about files in memory to be consumed by other system services." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\fileinfo.sys" "Sat Jun 5 13:05:23 2021" "
+ "Filetrace" "Filetrace: ETW File Trace Filter" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\filetrace.sys" "Sat Jun 5 13:05:23 2021" "
+ "flpydisk" "Floppy Disk Driver: Floppy Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\flpydisk.sys" "Sat Jun 5 13:04:45 2021" "
+ "FltMgr" "FltMgr: File System Filter Manager Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\fltmgr.sys" "Sat Jun 5 13:05:25 2021" "
+ "FsDepends" "File System Dependency Minifilter: This minifilter tracks the dependencies associated with the various nested volumes/filesystems" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\FsDepends.sys" "Sat Jun 5 13:04:57 2021" "
+ "fvevol" "BitLocker Drive Encryption Filter Driver: BitLocker Drive Encryption Filter Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DRIVERS\fvevol.sys" "Thu Dec 16 08:01:18 2021" "
+ "gencounter" "Microsoft Hyper-V Generation Counter: Virtual Machine Generation Counter" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\vmgencounter.sys" "Sat Jun 5 13:04:47 2021" "
+ "genericusbfn" "Generic USB Function Class: Generic USB Function Class Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DriverStore\FileRepository\genericusbfn.inf_amd64_dc3260bbd08046c4\genericusbfn.sys" "Sat Jun 5 13:04:46 2021" "
+ "GPIOClx0101" "Microsoft GPIO Class Extension Driver: GPIO Class Extension Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Drivers\msgpioclx.sys" "Sat Jun 5 13:05:12 2021" "
+ "GpuEnergyDrv" "GPU Energy Driver: Computes energy consumed by GPU" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\gpuenergydrv.sys" "Sat Jun 5 13:04:52 2021" "
+ "HdAudAddService" "Microsoft 1.1 UAA Function Driver for High Definition Audio Service: High Definition Audio Function Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\HdAudio.sys" "Sat Jun 5 13:04:43 2021" "
+ "HDAudBus" "Microsoft UAA Bus Driver for High Definition Audio: High Definition Audio Bus Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\HDAudBus.sys" "Sat Jun 5 13:04:43 2021" "
+ "HidBatt" "HID UPS Battery Driver: Hid Battery Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\HidBatt.sys" "Sat Jun 5 13:04:45 2021" "
+ "HidBth" "Microsoft Bluetooth HID Miniport: Bluetooth Miniport Driver for HID Devices" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\hidbth.sys" "Sat Jun 5 13:04:46 2021" "
+ "hidi2c" "Microsoft I2C HID Miniport Driver: I2C HID Miniport Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\hidi2c.sys" "Sat Jun 5 13:04:46 2021" "
+ "hidinterrupt" "Common Driver for HID Buttons implemented with interrupts: HID Button over Interrupt Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\hidinterrupt.sys" "Sat Jun 5 13:04:46 2021" "
+ "HidIr" "Microsoft Infrared HID Driver: Infrared Miniport Driver for Input Devices" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\hidir.sys" "Sat Jun 5 13:04:43 2021" "
+ "hidspi" "Microsoft SPI HID Miniport Driver: SPI HID Miniport Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\hidspi.sys" "Sat Jun 5 13:04:46 2021" "
+ "HidSpiCx" "HidSpi KMDF Class Extension: HidSpi KMDF Class Extension" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\HidSpiCx.sys" "Sat Jun 5 13:05:16 2021" "
+ "HidUsb" "Microsoft HID Class Driver: USB Miniport Driver for Input Devices" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\hidusb.sys" "Sat Jun 5 13:04:46 2021" "
+ "HpSAMD" "HpSAMD: Smart Array SAS/SATA Controller Media Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\HpSAMD.sys" "Sat Jun 5 13:04:45 2021" "
+ "Hsp" "Microsoft Pluton Service: HSP Device Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\Hsp.sys" "Thu Dec 16 07:50:57 2021" "
+ "HTTP" "HTTP Service: HTTP Service" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\HTTP.sys" "Thu Dec 16 07:53:45 2021" "
+ X "hvcrash" "hvcrash: Hyper-V Crashdump" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\hvcrash.sys" "Sat Jun 5 13:04:47 2021" "
+ "hvservice" "Microsoft Hypervisor Service Driver: Hypervisor Boot Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\hvservice.sys" "Thu Dec 16 07:51:02 2021" "
+ "HwNClx0101" "Microsoft Hardware Notifications Class Extension Driver: Hardware Notification Class Extension Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Drivers\mshwnclx.sys" "Sat Jun 5 13:05:16 2021" "
+ "hwpolicy" "Hardware Policy Driver: Contains Processor and other policies" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\hwpolicy.sys" "Sat Jun 5 13:05:25 2021" "
+ "hyperkbd" "hyperkbd: Microsoft VMBus Synthetic Keyboard Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\hyperkbd.sys" "Sat Jun 5 13:04:47 2021" "
+ "HyperVideo" "HyperVideo: Microsoft VMBus Video Device Miniport Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\HyperVideo.sys" "Sat Jun 5 13:04:47 2021" "
+ "i8042prt" "i8042 Keyboard and PS/2 Mouse Port Driver: i8042 Port Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\i8042prt.sys" "Sat Jun 5 13:04:46 2021" "
+ "iagpio" "Intel Serial IO GPIO Controller Driver: Intel(R) Serial IO GPIO Controller Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\iagpio.sys" "Sat Jun 5 13:04:42 2021" "
+ "iai2c" "Intel(R) Serial IO I2C Host Controller: Intel(R) Serial IO I2C Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\iai2c.sys" "Sat Jun 5 13:04:42 2021" "
+ "iaLPSS2i_GPIO2" "Intel(R) Serial IO GPIO Driver v2: Intel(R) Serial IO GPIO Driver v2" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2.sys" "Sat Jun 5 13:04:42 2021" "
+ "iaLPSS2i_GPIO2_BXT_P" "Intel(R) Serial IO GPIO Driver v2: Intel(R) Serial IO GPIO Driver v2" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2_BXT_P.sys" "Sat Jun 5 13:04:42 2021" "
+ "iaLPSS2i_GPIO2_CNL" "Intel(R) Serial IO GPIO Driver v2: Intel(R) Serial IO GPIO Driver v2" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2_CNL.sys" "Sat Jun 5 13:04:42 2021" "
+ "iaLPSS2i_GPIO2_GLK" "Intel(R) Serial IO GPIO Driver v2: Intel(R) Serial IO GPIO Driver v2" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2_GLK.sys" "Sat Jun 5 13:04:42 2021" "
+ "iaLPSS2i_I2C" "Intel(R) Serial IO I2C Driver v2: Intel(R) Serial IO I2C Driver v2" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\iaLPSS2i_I2C.sys" "Sat Jun 5 13:04:42 2021" "
+ "iaLPSS2i_I2C_BXT_P" "Intel(R) Serial IO I2C Driver v2: Intel(R) Serial IO I2C Driver v2" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\iaLPSS2i_I2C_BXT_P.sys" "Sat Jun 5 13:04:42 2021" "
+ "iaLPSS2i_I2C_CNL" "Intel(R) Serial IO I2C Driver v2: Intel(R) Serial IO I2C Driver v2" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\iaLPSS2i_I2C_CNL.sys" "Sat Jun 5 13:04:42 2021" "
+ "iaLPSS2i_I2C_GLK" "Intel(R) Serial IO I2C Driver v2: Intel(R) Serial IO I2C Driver v2" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\iaLPSS2i_I2C_GLK.sys" "Sat Jun 5 13:04:42 2021" "
+ "iaLPSS2_GPIO2_TGL" "Intel(R) Serial IO GPIO Driver v2: Intel(R) Serial IO GPIO Driver v2" "(Verified) Intel Corporation" "C:\WINDOWS\System32\DriverStore\FileRepository\ialpss2_gpio2_tgl.inf_amd64_c330c09d72f3e083\iaLPSS2_GPIO2_TGL.sys" "Sun Oct 10 17:41:10 2021" "
+ "iaLPSSi_GPIO" "Intel(R) Serial IO GPIO Controller Driver: Intel(R) Serial IO GPIO Controller Driver" "(Verified) Intel Corporation - Client Components Group" "C:\WINDOWS\System32\drivers\iaLPSSi_GPIO.sys" "Sat Jun 5 13:04:44 2021" "
+ "iaLPSSi_I2C" "Intel(R) Serial IO I2C Controller Driver: Intel(R) Serial IO I2C Controller Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\iaLPSSi_I2C.sys" "Sat Jun 5 13:04:43 2021" "
+ "iaStorAC" "Intel(R) Chipset SATA/PCIe RST Premium Controller: Intel(R) Rapid Storage Technology driver - x64" "(Verified) Intel(R) Rapid Storage Technology" "C:\WINDOWS\System32\drivers\iaStorAC.sys" "Sun Oct 10 17:41:43 2021" "
+ "iaStorAfs" "iaStorAfs: Identifies frequently used files for acceleration with Intel(R) Optane(TM) memory" "(Verified) Intel(R) Rapid Storage Technology" "C:\WINDOWS\System32\drivers\iaStorAfs.sys" "Sun Oct 10 17:41:43 2021" "
+ "iaStorAVC" "Intel Chipset SATA RAID Controller: Intel(R) Rapid Storage Technology driver (inbox) - x64" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\iaStorAVC.sys" "Sat Jun 5 13:04:45 2021" "
+ "iaStorV" "Intel RAID Controller Windows 7: Intel Matrix Storage Manager driver - x64" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\iaStorV.sys" "Sat Jun 5 13:04:45 2021" "
+ "ibbus" "Mellanox InfiniBand Bus/AL (Filter Driver): InfiniBand Fabric Bus Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\ibbus.sys" "Sat Jun 5 13:04:45 2021" "
+ "igfx" "igfx: Intel Graphics Kernel Mode Driver" "(Verified) Intel(R) pGFX 2020" "C:\WINDOWS\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_e36b8067470714bb\igdkmd64.sys" "Mon Jan 18 03:52:22 2021" "
+ "IndirectKmd" "Indirect Displays Kernel-Mode Driver: Kernel mode driver that implements the Indirect Displays framework." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\IndirectKmd.sys" "Sat Jun 5 13:05:16 2021" "
+ "IntcAzAudAddService" "Service for Realtek HD Audio (WDM): Realtek(r) High Definition Audio Function Driver" "(Verified) Realtek Semiconductor Corp." "C:\WINDOWS\system32\drivers\RTKVHD64.sys" "Mon May 17 19:23:48 2021" "
+ "IntcDAud" "Intel(R) Display Audio: Intel(R) Display Audio Driver" "(Verified) Intel Corporation" "C:\WINDOWS\System32\DriverStore\FileRepository\intcdaud.inf_amd64_0d1975b386430ef8\IntcDAud.sys" "Sun Oct 10 17:41:56 2021" "
+ "intelide" "intelide: Intel PCI IDE Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\intelide.sys" "Thu Dec 16 07:50:56 2021" "
+ "intelpep" "Intel(R) Power Engine Plug-in Driver: Intel Power Engine Plugin" "(Verified) Microsoft Windows Hardware Abstraction Layer Publisher" "C:\WINDOWS\System32\drivers\intelpep.sys" "Thu Dec 16 07:50:57 2021" "
+ "intelpmax" "Intel(R) Dynamic Device Peak Power Manager Driver: Intel Power Limit Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\intelpmax.sys" "Sat Jun 5 13:04:42 2021" "
+ "IntelPMT" "Intel(R) Platform Monitoring Technology Service: Intel Platform Monitoring Driver" "(Verified) Microsoft Windows Hardware Abstraction Layer Publisher" "C:\WINDOWS\System32\drivers\IntelPMT.sys" "Sat Jun 5 13:04:46 2021" "
+ "intelppm" "Intel Processor Driver: Processor Device Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\intelppm.sys" "Sat Jun 5 13:04:44 2021" "
+ "iorate" "Disk I/O Rate Filter Driver: Provides rate control for disk I/O traffic." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\iorate.sys" "Thu Dec 16 07:51:18 2021" "
+ "IpFilterDriver" "IP Traffic Filter Driver: IP Traffic Filter Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys" "Sat Jun 5 13:05:40 2021" "
+ "IPMIDRV" "IPMIDRV: WMI IPMI DRIVER" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\IPMIDrv.sys" "Sat Jun 5 13:04:45 2021" "
+ "IPNAT" "IP Network Address Translator: IP Network Address Translator" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\ipnat.sys" "Sat Jun 5 13:05:12 2021" "
+ "IPT" "IPT: IPT Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\ipt.sys" "Sat Jun 5 13:04:54 2021" "
+ "isapnp" "isapnp: PNP ISA Bus Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\isapnp.sys" "Sat Jun 5 13:04:45 2021" "
+ "iScsiPrt" "iScsiPort Driver: Microsoft iSCSI Initiator Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\msiscsi.sys" "Sat Jun 5 13:04:45 2021" "
+ "ItSas35i" "ItSas35i: Avago SAS Gen3.5 Driver (StorPort)" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\ItSas35i.sys" "Sat Jun 5 13:04:45 2021" "
+ "kbdclass" "Keyboard Class Driver: Keyboard Class Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\kbdclass.sys" "Sat Jun 5 13:04:46 2021" "
+ "kbdhid" "Keyboard HID Driver: HID Keyboard Filter Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\kbdhid.sys" "Sat Jun 5 13:04:46 2021" "
+ "kdnic" "Microsoft Kernel Debug Network Miniport (NDIS 6.20): Microsoft Kernel Debugger Network Miniport" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\kdnic.sys" "Sat Jun 5 13:04:46 2021" "
+ "KSecDD" "KSecDD: Kernel Security Support Provider Interface" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Drivers\ksecdd.sys" "Thu Dec 16 07:53:50 2021" "
+ "KSecPkg" "KSecPkg: Kernel Security Support Provider Interface Packages" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Drivers\ksecpkg.sys" "Thu Dec 16 07:53:45 2021" "
+ "ksthunk" "Kernel Streaming Thunks: Kernel Streaming WOW Thunk Service" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\ksthunk.sys" "Sat Jun 5 13:05:31 2021" "
+ "LHidFilt" "Logicool SetPoint KMDF HID Filter Driver: Logitech HID Filter Driver." "(Verified) Logitech Inc" "C:\WINDOWS\system32\DRIVERS\LHidFilt.Sys" "Sun Oct 25 08:32:28 2020" "
+ "lltdio" "Link-Layer Topology Discovery Mapper I/O Driver: Link-Layer Topology Discovery Mapper I/O Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\lltdio.sys" "Sat Jun 5 13:05:29 2021" "
+ "LMouFilt" "Logicool SetPoint KMDF Mouse Filter Driver: Logitech Mouse Filter Driver." "(Verified) Logitech Inc" "C:\WINDOWS\system32\DRIVERS\LMouFilt.Sys" "Sun Oct 25 08:32:30 2020" "
+ "LSI_SAS" "LSI_SAS: LSI Fusion-MPT SAS Driver (StorPort)" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\lsi_sas.sys" "Sat Jun 5 13:04:45 2021" "
+ "LSI_SAS2i" "LSI_SAS2i: LSI SAS Gen2 Driver (StorPort)" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\lsi_sas2i.sys" "Sat Jun 5 13:04:45 2021" "
+ "LSI_SAS3i" "LSI_SAS3i: Avago SAS Gen3 Driver (StorPort)" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\lsi_sas3i.sys" "Sat Jun 5 13:04:45 2021" "
+ "luafv" "UAC File Virtualization: Virtualizes file write failures to per-user locations." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\luafv.sys" "Sat Jun 5 13:05:33 2021" "
+ "mausbhost" "MA-USB Host Controller Driver: MA-USB Host Controller Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\mausbhost.sys" "Sat Jun 5 13:04:45 2021" "
+ "mausbip" "MA-USB IP Filter Driver: MA-USB IP Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\mausbip.sys" "Sat Jun 5 13:04:45 2021" "
+ "MbbCx" "MBB Network Adapter Class Extension: Windows Mobile Broadband Class Extension" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\MbbCx.sys" "Sat Jun 5 13:04:50 2021" "
+ "megasas2i" "megasas2i: MEGASAS2i RAID Controller Driver for Windows" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\MegaSas2i.sys" "Sat Jun 5 13:04:45 2021" "
+ "megasas35i" "megasas35i: MEGASAS RAID Controller Driver for Windows" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\megasas35i.sys" "Sat Jun 5 13:04:45 2021" "
+ "megasr" "megasr: LSI MegaRAID Software RAID Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\megasr.sys" "Sat Jun 5 13:04:45 2021" "
+ "MEIx64" "Intel(R) Management Engine Interface : Intel(R) Management Engine Interface" "(Verified) Intel(R) Embedded Subsystems and IP Blocks Group" "C:\WINDOWS\System32\DriverStore\FileRepository\heci.inf_amd64_605dda426937489f\x64\TeeDriverW10x64.sys" "Sun Oct 10 17:41:23 2021" "
+ "Microsoft_Bluetooth_AvrcpTransport" "Microsoft Bluetooth Avrcp Transport Driver: Microsoft Bluetooth Avrcp Transport Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\Microsoft.Bluetooth.AvrcpTransport.sys" "Sat Jun 5 13:04:42 2021" "
+ "mlx4_bus" "Mellanox ConnectX Bus Enumerator: MLX4 Bus Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\mlx4_bus.sys" "Sat Jun 5 13:04:45 2021" "
+ "MMCSS" "Multimedia Class Scheduler: Enables relative prioritization of work based on system-wide task priorities. This is intended mainly for multimedia applications. If this service is stopped, individual tasks resort to their default priority." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\mmcss.sys" "Sat Jun 5 13:04:54 2021" "
+ "Modem" "Modem: Modem Device Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\modem.sys" "Sat Jun 5 13:06:15 2021" "
+ "monitor" "Microsoft Monitor Class Function Driver Service: Monitor Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\monitor.sys" "Sat Jun 5 13:04:44 2021" "
+ "mouclass" "Mouse Class Driver: Mouse Class Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\mouclass.sys" "Sat Jun 5 13:04:46 2021" "
+ "mouhid" "Mouse HID Driver: HID Mouse Filter Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\mouhid.sys" "Sat Jun 5 13:04:46 2021" "
+ "mountmgr" "Mount Point Manager: Driver responsible with maintaining persistent drive letters and names for volumes" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\mountmgr.sys" "Sat Jun 5 13:05:25 2021" "
+ "mpi3drvi" "mpi3drvi: Broadcom MPI 3.0 Driver (StorPort)" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\mpi3drvi.sys" "Sat Jun 5 13:04:45 2021" "
+ "mpsdrv" "Windows Defender Firewall Authorization Driver: Windows Defender Firewall Authorization Driver is a kernel mode driver that provides deep inspection services on inbound and outbound network traffic." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\mpsdrv.sys" "Sat Jun 5 13:05:09 2021" "
+ "MRxDAV" "WebDav Client Redirector Driver: Network Redirector that provides WebDAV file access for the WebClient service" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\mrxdav.sys" "Thu Dec 16 07:56:56 2021" "
+ "mrxsmb" "SMB MiniRedirector Wrapper and Engine: Implements the framework for the SMB filesystem redirector" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\DRIVERS\mrxsmb.sys" "Thu Dec 16 07:53:54 2021" "
+ "mrxsmb20" "SMB 2.0 MiniRedirector: Implements the SMB 2.0 protocol, which provides connectivity to network resources on Windows Vista and later servers" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\DRIVERS\mrxsmb20.sys" "Thu Dec 16 07:53:54 2021" "
+ "MsBridge" "Microsoft MAC Bridge: Microsoft MAC Bridge" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\bridge.sys" "Sat Jun 5 13:06:05 2021" "
+ "Msfs" "Msfs: Mailslot driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Drivers\Msfs.sys" "Sat Jun 5 13:05:25 2021" "
+ "msgpiowin32" "Common Driver for Buttons, DockMode and Laptop/Slate Indicator: GPIO Button Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\msgpiowin32.sys" "Sat Jun 5 13:04:46 2021" "
+ "mshidkmdf" "Pass-through HID to KMDF Filter Driver: Device Filter to provide pass-through interface between HIDCLASS and KMDF" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\mshidkmdf.sys" "Sat Jun 5 13:05:16 2021" "
+ "mshidumdf" "Pass-through HID to UMDF Driver: Device Driver to provide pass-through interface between HIDCLASS and UMDF" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\mshidumdf.sys" "Sat Jun 5 13:05:14 2021" "
+ "msisadrv" "msisadrv: ISA Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\msisadrv.sys" "Sat Jun 5 13:04:45 2021" "
+ "MSKSSRV" "Microsoft Streaming Service Proxy: MS KS Server" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\MSKSSRV.sys" "Sat Jun 5 13:05:31 2021" "
+ "MsLldp" "Microsoft Link-Layer Discovery Protocol Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\mslldp.sys" "Sat Jun 5 13:05:39 2021" "
+ "MSPCLOCK" "Microsoft Streaming Clock Proxy: MS Proxy Clock" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\MSPCLOCK.sys" "Sat Jun 5 13:05:31 2021" "
+ "MSPQM" "Microsoft Streaming Quality Manager Proxy: MS Proxy Quality Manager" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\MSPQM.sys" "Sat Jun 5 13:05:31 2021" "
+ "MsQuic" "MsQuic: Microsoft® QUIC Library" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\msquic.sys" "Thu Dec 16 07:53:42 2021" "
+ "MsRPC" "MsRPC: Kernel Remote Procedure Call Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Drivers\MsRPC.sys" "Thu Dec 16 07:53:50 2021" "
+ "mssmbios" "Microsoft System Management BIOS Driver: System Management BIOS Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\mssmbios.sys" "Sat Jun 5 13:04:45 2021" "
+ "MSTEE" "Microsoft Streaming Tee/Sink-to-Sink Converter: WDM Tee/Communication Transform Filter " "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\MSTEE.sys" "Sat Jun 5 13:05:31 2021" "
+ "MTConfig" "Microsoft Input Configuration Driver: Microsoft Multi-Touch HID Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\MTConfig.sys" "Sat Jun 5 13:04:44 2021" "
+ "Mup" "Mup: Multiple UNC Provider Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Drivers\mup.sys" "Sat Jun 5 13:05:27 2021" "
+ "mvumis" "mvumis: Marvell Flash Controller Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\mvumis.sys" "Sat Jun 5 13:04:45 2021" "
+ "NativeWifiP" "NativeWiFi Filter: NativeWiFi Miniport Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\DRIVERS\nwifi.sys" "Thu Dec 16 07:51:52 2021" "
+ "ndfltr" "NetworkDirect Service: NetworkDirect Support Filter Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\ndfltr.sys" "Sat Jun 5 13:04:45 2021" "
+ "NDIS" "NDIS System Driver: NDIS System Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\ndis.sys" "Thu Dec 16 07:53:50 2021" "
+ "NdisCap" "Microsoft NDIS Capture: Microsoft NDIS Capture" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\ndiscap.sys" "Sat Jun 5 13:06:13 2021" "
+ "NdisImPlatform" "Microsoft Network Adapter Multiplexor Protocol: Microsoft Network Adapter Multiplexor Protocol" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\NdisImPlatform.sys" "Sat Jun 5 13:05:39 2021" "
+ "NdisTapi" "Remote Access NDIS TAPI Driver: Remote Access NDIS TAPI Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DRIVERS\ndistapi.sys" "Sat Jun 5 13:05:40 2021" "
+ "Ndisuio" "NDIS Usermode I/O Protocol: NDIS User mode I/O driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\ndisuio.sys" "Sat Jun 5 13:05:25 2021" "
+ "NdisVirtualBus" "Microsoft Virtual Network Adapter Enumerator: Microsoft Virtual Network Adapter Enumerator" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\NdisVirtualBus.sys" "Sat Jun 5 13:05:39 2021" "
+ "NdisWan" "Remote Access NDIS WAN Driver: Remote Access NDIS WAN Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\ndiswan.sys" "Thu Dec 16 07:54:56 2021" "
+ "ndiswanlegacy" "Remote Access LEGACY NDIS WAN Driver: Remote Access LEGACY NDIS WAN Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DRIVERS\ndiswan.sys" "Thu Dec 16 07:54:56 2021" "
+ "NDKPerf" "NDKPerf Driver: " "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\NDKPerf.sys" "Sat Jun 5 13:06:13 2021" "
+ "NDKPing" "NDKPing Driver: RDMA Sample Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\NDKPing.sys" "Sat Jun 5 13:06:13 2021" "
+ "ndproxy" "NDIS Proxy Driver: NDIS Proxy Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DRIVERS\NDProxy.sys" "Sat Jun 5 13:05:40 2021" "
+ "Ndu" "Windows Network Data Usage Monitoring Driver: This service provides network data usage monitoring functionality" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\Ndu.sys" "Sat Jun 5 13:06:00 2021" "
+ "NetAdapterCx" "Network Adapter Wdf Class Extension Library: Network Adapter Class Extension for WDF" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\NetAdapterCx.sys" "Thu Dec 16 07:53:51 2021" "
+ "NetBIOS" "NetBIOS Interface: NetBIOS Interface" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\netbios.sys" "Sat Jun 5 13:05:37 2021" "
+ "NetBT" "NetBT: This service implements NetBios over TCP/IP." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DRIVERS\netbt.sys" "Sat Jun 5 13:05:39 2021" "
+ "netvsc" "netvsc: Virtual NDIS Miniport" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\netvsc.sys" "Thu Dec 16 07:51:04 2021" "
+ "Npfs" "Npfs: NPFS Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Drivers\Npfs.sys" "Sat Jun 5 13:05:25 2021" "
+ "npsvctrig" "Named pipe service trigger provider: Named pipe service triggers" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\npsvctrig.sys" "Sat Jun 5 13:04:46 2021" "
+ "nsiproxy" "NSI Proxy Service Driver: NSI Proxy Service" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\nsiproxy.sys" "Sat Jun 5 13:05:25 2021" "
+ "nsvst_NGC" "NortonLifeLock Split Tunneling WFP Callout driver: " "" "File not found: C:\WINDOWS\System32\drivers\NGCx64\16150A0.028\nsvst.sys" "Thu Dec 16 09:32:35 2021" "
+ "Ntfs" "Ntfs: NT File System Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Drivers\Ntfs.sys" "Thu Dec 16 07:53:48 2021" "
+ "Null" "Null: NULL Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Drivers\Null.sys" "Sat Jun 5 13:05:25 2021" "
+ "nvdimm" "Microsoft NVDIMM device driver: NVDIMM device driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\nvdimm.sys" "Sat Jun 5 13:04:45 2021" "
+ "nvmedisk" "Microsoft NVMe disk driver: Nvme Disk Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\nvmedisk.sys" "Sat Jun 5 13:04:44 2021" "
+ "nvraid" "nvraid: NVIDIA® nForce(TM) RAID Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\nvraid.sys" "Sat Jun 5 13:04:45 2021" "
+ "nvstor" "nvstor: NVIDIA® nForce(TM) Sata Performance Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\nvstor.sys" "Sat Jun 5 13:04:45 2021" "
+ "P9Rdr" "Plan 9 Redirector Driver: Plan 9 Redirector Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\p9rdr.sys" "Sat Jun 5 13:06:17 2021" "
+ "Parport" "Parallel port driver: Parallel Port Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\parport.sys" "Sat Jun 5 13:04:45 2021" "
+ "partmgr" "Partition driver: Disk class filter driver that manages and auctions out partitions to volume managers." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\partmgr.sys" "Thu Dec 16 07:53:49 2021" "
+ "pci" "PCI Bus Driver: NT Plug and Play PCI Enumerator" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\pci.sys" "Thu Dec 16 07:50:56 2021" "
+ "pciide" "pciide: Generic PCI IDE Bus Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\pciide.sys" "Thu Dec 16 07:50:56 2021" "
+ "pcmcia" "pcmcia: PCMCIA Bus Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\pcmcia.sys" "Sat Jun 5 13:04:42 2021" "
+ "pcw" "Performance Counters for Windows Driver: Performance Counters for Windows Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\pcw.sys" "Sat Jun 5 13:05:25 2021" "
+ "pdc" "pdc: Power Dependency Coordinator Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\pdc.sys" "Sat Jun 5 13:04:57 2021" "
+ "PEAUTH" "PEAUTH: Protected Environment Authentication and Authorization Export Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\peauth.sys" "Thu Dec 16 07:51:39 2021" "
+ "percsas2i" "percsas2i: MEGASAS RAID Controller Driver for Windows" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\percsas2i.sys" "Sat Jun 5 13:04:45 2021" "
+ "percsas3i" "percsas3i: MEGASAS RAID Controller Driver for Windows" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\percsas3i.sys" "Sat Jun 5 13:04:45 2021" "
+ "PktMon" "Packet Monitor Driver: Packet Monitor Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\PktMon.sys" "Thu Dec 16 07:56:43 2021" "
+ "pmem" "Microsoft persistent memory disk driver: Persistent memory driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\pmem.sys" "Sat Jun 5 13:04:45 2021" "
+ "PNPMEM" "Microsoft Memory Module Driver: Plug and Play Memory Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\pnpmem.sys" "Sat Jun 5 13:04:44 2021" "
+ "portcfg" "portcfg: Port Device Class Configuration Filter Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\portcfg.sys" "Sat Jun 5 13:05:16 2021" "
+ "PptpMiniport" "WAN Miniport (PPTP): WAN Miniport (PPTP)" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\raspptp.sys" "Sat Jun 5 13:05:40 2021" "
+ "PRM" "Microsoft PRM Driver: Windows PRM Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DriverStore\FileRepository\prm.inf_amd64_7fc9bb8ba2b73803\PRM.sys" "Sat Jun 5 13:04:44 2021" "
+ "Processor" "Processor Driver: Processor Device Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\processr.sys" "Sat Jun 5 13:04:44 2021" "
+ "Psched" "QoS Packet Scheduler: QoS Packet Scheduler" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\pacer.sys" "Sat Jun 5 13:05:09 2021" "
+ "Qcamain10x64" "Qualcomm Atheros Extensible Wireless LAN 11AC device driver: Qualcomm Atheros Extensible Wireless LAN device driver" "(Verified) Qualcomm Atheros, Inc." "C:\WINDOWS\System32\drivers\Qcamain10x64.sys" "Sun Jul 18 20:19:10 2021" "
+ "QWAVEdrv" "QWAVE driver: Quality Windows Audio/Video Experience component driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\qwavedrv.sys" "Sat Jun 5 13:05:39 2021" "
+ "Ramdisk" "Windows RAM Disk Driver: RAM Disk Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\DRIVERS\ramdisk.sys" "Sat Jun 5 13:04:57 2021" "
+ "RasAcd" "Remote Access Auto Connection Driver: Remote Access Auto Connection Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DRIVERS\rasacd.sys" "Sat Jun 5 13:05:40 2021" "
+ "RasAgileVpn" "WAN Miniport (IKEv2): WAN Miniport (IKEv2)" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\AgileVpn.sys" "Thu Dec 16 07:54:56 2021" "
+ "Rasl2tp" "WAN Miniport (L2TP): WAN Miniport (L2TP)" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\rasl2tp.sys" "Sat Jun 5 13:05:40 2021" "
+ "RasPppoe" "Remote Access PPPOE Driver: Remote Access PPPOE Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DRIVERS\raspppoe.sys" "Sat Jun 5 13:05:40 2021" "
+ "RasSstp" "WAN Miniport (SSTP): WAN Miniport (SSTP)" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\rassstp.sys" "Sat Jun 5 13:05:40 2021" "
+ "rdbss" "Redirected Buffering Sub System: Provides the framework for network mini-redirectors" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\DRIVERS\rdbss.sys" "Thu Dec 16 07:53:53 2021" "
+ "rdpbus" "Remote Desktop Device Redirector Bus Driver: Microsoft RDP Bus Device driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\rdpbus.sys" "Sat Jun 5 13:04:47 2021" "
+ "RDPDR" "Remote Desktop Device Redirector Driver: Remote Desktop Device Redirector Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\rdpdr.sys" "Sat Jun 5 13:06:13 2021" "
+ "RdpVideoMiniport" "Remote Desktop Video Miniport Driver: Microsoft RDP Video Miniport driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\rdpvideominiport.sys" "Thu Dec 16 07:56:41 2021" "
+ "rdyboost" "ReadyBoost: ReadyBoost" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\rdyboost.sys" "Sat Jun 5 13:06:16 2021" "
+ "ReFS" "ReFS: NT ReFS FS Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Drivers\ReFS.sys" "Thu Dec 16 07:53:37 2021" "
+ "ReFSv1" "ReFSv1: NT ReFS FS Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Drivers\ReFSv1.sys" "Sat Jun 5 13:05:23 2021" "
+ "RFCOMM" "Bluetooth Device (RFCOMM Protocol TDI): Bluetooth Device (RFCOMM Protocol TDI)" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\rfcomm.sys" "Sat Jun 5 13:04:46 2021" "
+ "rhproxy" "Resource Hub proxy driver: ResourceHub Proxy Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\rhproxy.sys" "Sat Jun 5 13:04:44 2021" "
+ "rspndr" "Link-Layer Topology Discovery Responder: Link-Layer Topology Discovery Responder" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\rspndr.sys" "Sat Jun 5 13:05:29 2021" "
+ "rt640x64" "Realtek RT640 NT Driver: Realtek 8125/8136/8168/8169 NDIS 6.40 64-bit Driver " "(Verified) Microsoft Windows Hardware Compatibility Publisher" "C:\WINDOWS\System32\drivers\rt640x64.sys" "Wed Aug 18 05:58:04 2021" "
+ "s3cap" "s3cap: Microsoft S3 Emulated Device Cap Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\vms3cap.sys" "Sat Jun 5 13:04:47 2021" "
+ "sbp2port" "SBP-2 Transport/Protocol Bus Driver: SBP-2 Protocol Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\sbp2port.sys" "Thu Dec 16 07:50:55 2021" "
+ "scfilter" "Smart card PnP Class Filter Driver: Smart card reader filter driver enabling smart card PnP." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DRIVERS\scfilter.sys" "Sat Jun 5 13:05:34 2021" "
+ "scmbus" "Microsoft Storage Class Memory Bus Driver: Storage Class Memory Bus Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\scmbus.sys" "Thu Dec 16 07:50:56 2021" "
+ "sdbus" "sdbus: SecureDigital Bus Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\sdbus.sys" "Sat Jun 5 13:04:46 2021" "
+ "SDFRd" "SDF Reflector: SDF Reflector" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\SDFRd.sys" "Sat Jun 5 13:04:44 2021" "
+ "sdstor" "SD Storage Port Driver: SD Storage Class Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\sdstor.sys" "Thu Dec 16 07:51:00 2021" "
+ "SerCx" "Serial UART Support Library: Serial Class Extension" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\SerCx.sys" "Sat Jun 5 13:05:16 2021" "
+ "SerCx2" "Serial UART Support Library: Serial Class Extension V2" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\SerCx2.sys" "Sat Jun 5 13:05:16 2021" "
+ "Serenum" "Serenum Filter Driver: Serial Port Enumerator" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\serenum.sys" "Sat Jun 5 13:04:45 2021" "
+ "Serial" "Serial port driver: Serial Device Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\serial.sys" "Sat Jun 5 13:04:45 2021" "
+ "sermouse" "Serial Mouse Driver: Serial Mouse Filter Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\sermouse.sys" "Sat Jun 5 13:04:46 2021" "
+ "sfloppy" "High-Capacity Floppy Disk Drive: SCSI Floppy Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\sfloppy.sys" "Sat Jun 5 13:04:45 2021" "
+ "SgrmAgent" "System Guard Runtime Monitor Agent: System Guard Runtime Monitor Agent Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\SgrmAgent.sys" "Sat Jun 5 13:06:00 2021" "
+ "SiSRaid2" "SiSRaid2: SiS RAID Stor Miniport Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\SiSRaid2.sys" "Sat Jun 5 13:04:45 2021" "
+ "SiSRaid4" "SiSRaid4: SiS AHCI Stor-Miniport Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\sisraid4.sys" "Sat Jun 5 13:04:45 2021" "
+ "SmartSAMD" "SmartSAMD: Storport Miniport Driver for SmartRAID/SmartHBA Controllers" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\SmartSAMD.sys" "Sat Jun 5 13:04:45 2021" "
+ "spaceparser" "spaceparser: Storage Spaces Parser driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\spaceparser.sys" "Sat Jun 5 13:06:02 2021" "
+ "spaceport" "Storage Spaces Driver: Storage Spaces Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\spaceport.sys" "Thu Dec 16 07:50:55 2021" "
+ "SpatialGraphFilter" "Holographic Spatial Graph Filter: Holographic Spatial Graph Filter" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\SpatialGraphFilter.sys" "Sat Jun 5 18:17:02 2021" "
+ "SpbCx" "Simple Peripheral Bus Support Library: SPB Class Extension" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\SpbCx.sys" "Sat Jun 5 13:05:16 2021" "
+ "srv2" "Server SMB 2.xxx Driver: Enables connectivity from Windows Vista and later clients" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DRIVERS\srv2.sys" "Thu Dec 16 07:53:54 2021" "
+ "srvnet" "srvnet: Server Network driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DRIVERS\srvnet.sys" "Thu Dec 16 07:53:54 2021" "
+ "ssudqcfilter" "SAMSUNG Mobile USB QCRMNET Filter Driver: Filter Driver for the Qualcomm USB Driver Stack" "(Verified) Samsung Electronics Co., Ltd." "C:\WINDOWS\System32\drivers\ssudqcfilter.sys" "Tue Jun 29 05:44:08 2021" "
+ "stexstor" "stexstor: Promise SuperTrak EX Series Driver for Windows x64" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\stexstor.sys" "Sat Jun 5 13:04:45 2021" "
+ "storahci" "Microsoft Standard SATA AHCI Driver: MS AHCI Storport Miniport Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\storahci.sys" "Thu Dec 16 07:50:56 2021" "
+ "storflt" "Microsoft Hyper-V Storage Accelerator: Virtual Storage Filter Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\vmstorfl.sys" "Sat Jun 5 13:04:47 2021" "
+ "stornvme" "Microsoft Standard NVM Express Driver: Microsoft NVM Express Storport Miniport Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\stornvme.sys" "Thu Dec 16 07:50:57 2021" "
+ "storqosflt" "Storage QoS Filter Driver: Provides Quality of Service for storage I/O traffic." "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\storqosflt.sys" "Sat Jun 5 13:05:16 2021" "
+ "storufs" "Microsoft Universal Flash Storage (UFS) Driver: MS UFS Storport Miniport Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\storufs.sys" "Thu Dec 16 07:50:57 2021" "
+ "storvsc" "storvsc: Storage VSC Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\storvsc.sys" "Sat Jun 5 13:04:47 2021" "
+ "swenum" "Software Bus Driver: Plug and Play Software Device Enumerator" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DriverStore\FileRepository\swenum.inf_amd64_3bf6c0d173eb26c6\swenum.sys" "Sat Jun 5 13:04:44 2021" "
+ "SymEvnt" "Symantec Eventing Platform: " "" "File not found: C:\Program Files\Norton Security\NortonData\22.20.5.40\SymPlatform\SymEvnt.sys" "Thu Dec 16 09:32:35 2021" "
+ "Tcpip" "TCP/IP Protocol Driver: TCP/IP Protocol Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\tcpip.sys" "Thu Dec 16 07:53:51 2021" "
+ "Tcpip6" "@todo.dll,-100;Microsoft IPv6 Protocol Driver: @todo.dll,-100;Microsoft IPv6 Protocol Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\tcpip.sys" "Thu Dec 16 07:53:51 2021" "
+ "tcpipreg" "@%SystemRoot%\System32\drivers\tcpipreg.sys,-10110,: TCP/IP Registry Compatibility Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\tcpipreg.sys" "Thu Dec 16 07:53:51 2021" "
+ "tdx" "NetIO Legacy TDI Support Driver: NetIO Legacy TDI Support Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\DRIVERS\tdx.sys" "Thu Dec 16 07:56:20 2021" "
+ "terminpt" "Microsoft Remote Desktop Input Driver: Terminal Server Input Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\terminpt.sys" "Sat Jun 5 13:04:47 2021" "
+ "TPM" "TPM: TPM Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\tpm.sys" "Thu Dec 16 07:51:00 2021" "
+ "TsUsbFlt" "Remote Desktop USB Hub Class Filter Driver: Remote Desktop USB Hub Class Filter Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\tsusbflt.sys" "Sat Jun 5 13:04:57 2021" "
+ "TsUsbGD" "Remote Desktop Generic USB Device: Remote Desktop Generic USB Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\TsUsbGD.sys" "Sat Jun 5 13:04:46 2021" "
+ "tunnel" "Microsoft Tunnel Miniport Adapter Driver: Microsoft Tunnel Interface Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\tunnel.sys" "Sat Jun 5 13:05:37 2021" "
+ "UASPStor" "USB Attached SCSI (UAS) Driver: Microsoft Uasp Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\uaspstor.sys" "Sat Jun 5 13:04:45 2021" "
+ "UcmCx0101" "USB Connector Manager KMDF Class Extension: USB Connector Manager KMDF Class Extension" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Drivers\UcmCx.sys" "Sat Jun 5 13:05:16 2021" "
+ "UcmTcpciCx0101" "UCM-TCPCI KMDF Class Extension: UCM-TCPCI KMDF Class Extension" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Drivers\UcmTcpciCx.sys" "Sat Jun 5 13:05:16 2021" "
+ "UcmUcsiAcpiClient" "UCM-UCSI ACPI Client: UCM-UCSI ACPI Client Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\UcmUcsiAcpiClient.sys" "Sat Jun 5 13:04:46 2021" "
+ "UcmUcsiCx0101" "UCM-UCSI KMDF Class Extension: UCM-UCSI KMDF Class Extension" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Drivers\UcmUcsiCx.sys" "Sat Jun 5 13:05:16 2021" "
+ "Ucx01000" "USB Host Support Library: USB Controller Extension" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\ucx01000.sys" "Sat Jun 5 13:04:57 2021" "
+ "UdeCx" "USB Device Emulation Support Library: "udecx.DRIVER"" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\udecx.sys" "Sat Jun 5 13:04:57 2021" "
+ X "udfs" "udfs: Reads/Writes UDF 1.02,1.5,2.0x,2.5 disc formats, usually found on C/DVD discs. (Core) (All pieces)" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\DRIVERS\udfs.sys" "Sat Jun 5 13:06:14 2021" "
+ "UEFI" "Microsoft UEFI Driver: UEFI Driver for NT" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DriverStore\FileRepository\uefi.inf_amd64_fb341504564fabc5\UEFI.sys" "Sat Jun 5 13:04:44 2021" "
+ "Ufx01000" "USB Function Class Extension: USB Function Driver Class Extension" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\ufx01000.sys" "Sat Jun 5 13:05:16 2021" "
+ "UfxChipidea" "USB Chipidea Controller: UFX Chipidea Client Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DriverStore\FileRepository\ufxchipidea.inf_amd64_a517b810ee0e44a2\UfxChipidea.sys" "Sat Jun 5 13:04:46 2021" "
+ "ufxsynopsys" "USB Synopsys Controller: UFX Synopsys Client Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\ufxsynopsys.sys" "Sat Jun 5 13:04:46 2021" "
+ "umbus" "UMBus Enumerator Driver: User-Mode Bus Enumerator" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DriverStore\FileRepository\umbus.inf_amd64_0a89aff902a5c3a9\umbus.sys" "Sat Jun 5 13:04:45 2021" "
+ "UmPass" "Microsoft UMPass Driver: Generic pass-through driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\umpass.sys" "Sat Jun 5 13:04:46 2021" "
+ "UrsChipidea" "Chipidea USB Role-Switch Driver: USB Role-Switch Driver for Chipidea Core" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DriverStore\FileRepository\urschipidea.inf_amd64_4bd4df2779fd9e16\urschipidea.sys" "Sat Jun 5 13:04:46 2021" "
+ "UrsCx01000" "USB Role-Switch Support Library: USB Role-Switch Class Extension" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\urscx01000.sys" "Sat Jun 5 13:05:16 2021" "
+ "UrsSynopsys" "Synopsys USB Role-Switch Driver: USB Role-Switch Driver for Synopsys Core" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DriverStore\FileRepository\urssynopsys.inf_amd64_28522251903b4825\urssynopsys.sys" "Sat Jun 5 13:04:46 2021" "
+ "Usb4DeviceRouter" "USB4 Device Router Service: USB4(TM) Device Router Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DriverStore\FileRepository\usb4devicerouter.inf_amd64_8d9a17bd8e5b4b11\Usb4DeviceRouter.sys" "Thu Dec 16 07:50:57 2021" "
+ "Usb4HostRouter" "USB4 Host Router Service: USB4(TM) Host Router Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DriverStore\FileRepository\usb4hostrouter.inf_amd64_acb1b78bb0ae3528\Usb4HostRouter.sys" "Thu Dec 16 07:50:58 2021" "
+ "usbaudio" "USB Audio Driver (WDM): USB Audio Class Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\usbaudio.sys" "Sat Jun 5 13:04:43 2021" "
+ "usbaudio2" "USB Audio 2.0 Service: Microsoft USB Audio Class 2.0 Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\usbaudio2.sys" "Sat Jun 5 13:04:43 2021" "
+ "usbccgp" "Microsoft USB Generic Parent Driver: USB Common Class Generic Parent Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\usbccgp.sys" "Sat Jun 5 13:04:46 2021" "
+ "usbcir" "eHome Infrared Receiver (USBCIR): USB Consumer IR Driver for eHome" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\usbcir.sys" "Sat Jun 5 13:04:43 2021" "
+ "usbehci" "Microsoft USB 2.0 Enhanced Host Controller Miniport Driver: EHCI eUSB Miniport Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\usbehci.sys" "Sat Jun 5 13:04:46 2021" "
+ "usbhub" "Microsoft USB Standard Hub Driver: Default Hub Driver for USB" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\usbhub.sys" "Sat Jun 5 13:04:46 2021" "
+ "USBHUB3" "SuperSpeed Hub: USB3 HUB Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\UsbHub3.sys" "Thu Dec 16 07:51:00 2021" "
+ "usbohci" "Microsoft USB Open Host Controller Miniport Driver: OHCI USB Miniport Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\usbohci.sys" "Sat Jun 5 13:04:46 2021" "
+ "usbprint" "Microsoft USB PRINTER Class: USB Printer driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\usbprint.sys" "Thu Dec 16 07:50:55 2021" "
+ "usbser" "Microsoft USB Serial Driver: USB Serial Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\usbser.sys" "Sat Jun 5 13:04:45 2021" "
+ "USBSTOR" "USB Mass Storage Driver: USB Mass Storage Class Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\USBSTOR.SYS" "Thu Dec 16 07:51:00 2021" "
+ "usbuhci" "Microsoft USB Universal Host Controller Miniport Driver: UHCI USB Miniport Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\usbuhci.sys" "Sat Jun 5 13:04:46 2021" "
+ "usbvideo" "USB Video Device (WDM): USB Video Class Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Drivers\usbvideo.sys" "Thu Dec 16 07:50:55 2021" "
+ "USBXHCI" "USB xHCI Compliant Host Controller: USB XHCI Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\USBXHCI.SYS" "Thu Dec 16 07:51:00 2021" "
+ "vdrvroot" "Microsoft Virtual Drive Enumerator: Virtual Drive Root Enumerator" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\vdrvroot.sys" "Sat Jun 5 13:04:45 2021" "
+ "VerifierExt" "Driver Verifier Extension: Driver Verifier component to help find bugs in device drivers." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\VerifierExt.sys" "Thu Dec 16 07:53:47 2021" "
+ "vhdmp" "vhdmp: VHD Miniport Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\vhdmp.sys" "Sat Jun 5 13:04:45 2021" "
+ "vhf" "Virtual HID Framework (VHF) Driver: Kernel mode driver that implements the Virtual HID Framework (VHF)" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\vhf.sys" "Sat Jun 5 13:04:45 2021" "
+ "Vid" "Vid: Microsoft Hyper-V Virtualization Infrastructure Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\Vid.sys" "Thu Dec 16 07:51:02 2021" "
+ "VirtualRender" "VirtualRender: Microsoft Virtual Render Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DriverStore\FileRepository\vrd.inf_amd64_346f3764318c1681\vrd.sys" "Sat Jun 5 13:04:47 2021" "
+ "vmbus" "Virtual Machine Bus: Microsoft Hyper-V Virtual Machine Bus Child Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\vmbus.sys" "Thu Dec 16 07:51:03 2021" "
+ "VMBusHID" "VMBusHID: Microsoft VMBus HID Miniport" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\VMBusHID.sys" "Sat Jun 5 13:04:47 2021" "
+ "vmgid" "Microsoft Hyper-V Guest Infrastructure Driver: Virtual Machine Guest Infrastructure Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\vmgid.sys" "Sat Jun 5 13:04:47 2021" "
+ "volmgr" "Volume Manager Driver: Volume Manager Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\volmgr.sys" "Thu Dec 16 07:50:56 2021" "
+ "volmgrx" "Dynamic Volume Manager: Extension of the volume manager driver that manages software RAID volumes (spanned, striped, mirrored, RAID-5) on dynamic disks" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\volmgrx.sys" "Sat Jun 5 13:06:02 2021" "
+ "volsnap" "Volume Shadow Copy driver: Volume class filter driver that takes and manages snapshots." "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\volsnap.sys" "Sat Jun 5 13:05:14 2021" "
+ "volume" "Volume driver: Volume driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\volume.sys" "Sat Jun 5 13:04:44 2021" "
+ "vpci" "Microsoft Hyper-V Virtual PCI Bus: Virtual PCI Bus" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\vpci.sys" "Sat Jun 5 13:04:47 2021" "
+ "vsmraid" "vsmraid: VIA RAID DRIVER FOR AMD-X86-64" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\vsmraid.sys" "Sat Jun 5 13:04:45 2021" "
+ "VSTXRAID" "VIA StorX Storage RAID Controller Windows Driver: VIA StorX RAID Controller Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\vstxraid.sys" "Sat Jun 5 13:04:45 2021" "
+ "vwifibus" "Virtual Wireless Bus Driver: Implements bus functionality for Virtual Wireless" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\vwifibus.sys" "Sat Jun 5 13:05:00 2021" "
+ "vwififlt" "Virtual WiFi Filter Driver: Virtual WiFi Filter Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\vwififlt.sys" "Sat Jun 5 13:05:00 2021" "
+ "vwifimp" "Virtual WiFi Miniport Service: Virtual WiFi Miniport Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\vwifimp.sys" "Sat Jun 5 13:05:00 2021" "
+ "WacomPen" "Wacom Serial Pen HID Driver: Wacom Serial Pen Tablet HID Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\wacompen.sys" "Sat Jun 5 13:04:44 2021" "
+ "wanarp" "Remote Access IP ARP Driver: Remote Access IP ARP Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DRIVERS\wanarp.sys" "Sat Jun 5 13:05:40 2021" "
+ "wanarpv6" "Remote Access IPv6 ARP Driver: Remote Access IPv6 ARP Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\DRIVERS\wanarp.sys" "Sat Jun 5 13:05:40 2021" "
+ "wcifs" "Windows Container Isolation: Provides a virtual filesystem view for processes running within Windows Containers" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\wcifs.sys" "Thu Dec 16 07:52:57 2021" "
+ "WdBoot" "Microsoft Defender Antivirus Boot Driver: Microsoft Defender Antivirus Boot Driver" "(Verified) Microsoft Windows Early Launch Anti-malware Publisher" "C:\WINDOWS\system32\drivers\wd\WdBoot.sys" "Thu Dec 16 00:21:01 2021" "
+ "Wdf01000" "Kernel Mode Driver Frameworks service: Kernel Mode Driver Framework Runtime" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\Wdf01000.sys" "Sat Jun 5 13:05:25 2021" "
+ "WdFilter" "Microsoft Defender Antivirus Mini-Filter Driver: Microsoft Defender Antivirus On-Access Malware Protection Mini-Filter Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\wd\WdFilter.sys" "Thu Dec 16 00:21:02 2021" "
+ "wdiwifi" "WDI Driver Framework: WDI Driver Framework Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\DRIVERS\wdiwifi.sys" "Thu Dec 16 07:51:52 2021" "
+ "WdmCompanionFilter" "WdmCompanionFilter: WDM Companion Filter" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\WdmCompanionFilter.sys" "Sat Jun 5 13:05:19 2021" "
+ "WdNisDrv" "Microsoft Defender Antivirus Network Inspection System Driver: Helps guard against intrusion attempts targeting known and newly discovered vulnerabilities in network protocols" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\wd\WdNisDrv.sys" "Thu Dec 16 00:21:02 2021" "
+ "WFPLWFS" "Microsoft Windows Filtering Platform: Microsoft Windows Filtering Platform" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\wfplwfs.sys" "Thu Dec 16 07:52:48 2021" "
+ "WifiCx" "Wifi Network Adapter Class Extension: Windows Wifi Class Extension" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\WifiCx.sys" "Thu Dec 16 07:51:53 2021" "
+ "WIMMount" "WIMMount: WIM Image mount service driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\wimmount.sys" "Thu Dec 16 07:53:40 2021" "
+ "WindowsTrustedRT" "Windows Trusted Execution Environment Class Extension: Windows Trusted Runtime Interface Driver" "(Verified) Microsoft Windows Hardware Abstraction Layer Publisher" "C:\WINDOWS\system32\drivers\WindowsTrustedRT.sys" "Sat Jun 5 13:05:16 2021" "
+ "WindowsTrustedRTProxy" "Microsoft Windows Trusted Runtime Secure Service: Windows Trusted Runtime Service Proxy Driver" "(Verified) Microsoft Windows Hardware Abstraction Layer Publisher" "C:\WINDOWS\System32\drivers\WindowsTrustedRTProxy.sys" "Sat Jun 5 13:04:46 2021" "
+ "WinMad" "WinMad Service: Kernel WinMad" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\winmad.sys" "Sat Jun 5 13:04:45 2021" "
+ "WinNat" "Windows NAT Driver: This service provides network address translation functionality" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\winnat.sys" "Thu Dec 16 07:51:30 2021" "
+ "WinSetupMon" "WinSetupMon: SetupPlatform Monitor Mini-Filter" "" "File not found: C:\WINDOWS\system32\DRIVERS\WinSetupMon.sys" "Thu Dec 16 09:46:21 2021" "
+ "WINUSB" "WinUsb Driver: Generic driver for USB devices" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\WinUSB.SYS" "Sat Jun 5 13:04:46 2021" "
+ "WinVerbs" "WinVerbs Service: Kernel WinVerbs" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\winverbs.sys" "Sat Jun 5 13:04:45 2021" "
+ "WmiAcpi" "Microsoft Windows Management Interface for ACPI: Windows Management Interface for ACPI" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\wmiacpi.sys" "Sat Jun 5 13:04:45 2021" "
+ "Wof" "Windows Overlay File System Filter Driver: Windows Overlay Filter" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\Drivers\Wof.sys" "Sat Jun 5 13:05:23 2021" "
+ "WpdUpFltr" "WPD Upper Class Filter Driver: WPD Upper Class Filter Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\WpdUpFltr.sys" "Sat Jun 5 18:17:03 2021" "
+ X "ws2ifsl" "Winsock IFS Driver: Winsock IFS Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\ws2ifsl.sys" "Sat Jun 5 13:05:27 2021" "
+ "WSDPrintDevice" "WSD Print Support: Web Services Print Device Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\WSDPrint.sys" "Sat Jun 5 13:04:44 2021" "
+ "WSDScan" "WSD Scan Support: Web Service Based Scan Device Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\DRIVERS\WSDScan.sys" "Sat Jun 5 13:04:44 2021" "
+ "WudfPf" "User Mode Driver Frameworks Platform Driver: A kernel mode driver that uses message-based interprocess communication mechanism to communicate with the driver manager and secure host process to facilitate secure companions" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\drivers\WudfPf.sys" "Sat Jun 5 13:05:33 2021" "
+ "xboxgip" "Xbox Game Input Protocol Driver: Xbox Game Input Protocol Driver" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\xboxgip.sys" "Thu Dec 16 07:50:51 2021" "
+ "xinputhid" "XINPUT HID Filter Driver: XINPUT filter driver for HID" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drivers\xinputhid.sys" "Sat Jun 5 13:04:42 2021" "
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Font Drivers]
+ "Adobe Type Manager" "" "" "File not found: atmfd.dll" "" "
[Codecs]
[HKCU\Software\Microsoft\Windows NT\CurrentVersion\Drivers32]
[HKCU\Software\Classes\Filter]
[HKCU\Software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance]
[HKCU\Software\Classes\CLSID\{AC757296-3522-4E11-9862-C17BE5A1767E}\Instance]
[HKCU\Software\Classes\CLSID\{7ED96837-96F0-4812-B211-F13C24117ED3}\Instance]
[HKCU\Software\Classes\CLSID\{ABE3B9A4-257D-4B97-BD1A-294AF496222E}\Instance]
[HKCU\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32]
[HKCU\Software\Wow6432Node\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance]
[HKCU\Software\Wow6432Node\Classes\CLSID\{AC757296-3522-4E11-9862-C17BE5A1767E}\Instance]
[HKCU\Software\Wow6432Node\Classes\CLSID\{7ED96837-96F0-4812-B211-F13C24117ED3}\Instance]
[HKCU\Software\Wow6432Node\Classes\CLSID\{ABE3B9A4-257D-4B97-BD1A-294AF496222E}\Instance]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32]
+ "aux" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wdmaud.drv" "Sat Jun 5 13:04:54 2021" "
+ "aux1" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wdmaud.drv" "Sat Jun 5 13:04:54 2021" "
+ "aux2" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wdmaud.drv" "Sat Jun 5 13:04:54 2021" "
+ "aux3" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wdmaud.drv" "Sat Jun 5 13:04:54 2021" "
+ "midi" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wdmaud.drv" "Sat Jun 5 13:04:54 2021" "
+ "midi1" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wdmaud.drv" "Sat Jun 5 13:04:54 2021" "
+ "midi2" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wdmaud.drv" "Sat Jun 5 13:04:54 2021" "
+ "midi3" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wdmaud.drv" "Sat Jun 5 13:04:54 2021" "
+ "midimapper" "Microsoft MIDI Mapper" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\midimap.dll" "Sat Jun 5 13:04:54 2021" "
+ "mixer" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wdmaud.drv" "Sat Jun 5 13:04:54 2021" "
+ "mixer1" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wdmaud.drv" "Sat Jun 5 13:04:54 2021" "
+ "mixer2" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wdmaud.drv" "Sat Jun 5 13:04:54 2021" "
+ "mixer3" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wdmaud.drv" "Sat Jun 5 13:04:54 2021" "
+ "msacm.imaadpcm" "IMA ADPCM CODEC for MSACM" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\imaadp32.acm" "Sat Jun 5 13:04:54 2021" "
+ "msacm.l3acm" "MPEG Layer-3 Audio Codec for MSACM" "(Verified) Microsoft Windows" "C:\Windows\System32\l3codeca.acm" "Sat Jun 5 18:17:05 2021" "
+ "msacm.msadpcm" "Microsoft ADPCM CODEC for MSACM" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\msadp32.acm" "Sat Jun 5 13:04:54 2021" "
+ "msacm.msg711" "Microsoft CCITT G.711 (A-Law and u-Law) CODEC for MSACM" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\msg711.acm" "Sat Jun 5 13:04:54 2021" "
+ "msacm.msgsm610" "Microsoft GSM 6.10 Audio CODEC for MSACM" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\msgsm32.acm" "Sat Jun 5 13:04:54 2021" "
+ "MSVideo8" "VfW MM Driver for WDM Video Capture Devices" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\VfWWDM32.dll" "Thu Dec 16 07:56:42 2021" "
+ "vidc.i420" "Intel Indeo(R) Video YUV Codec" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\iyuv_32.dll" "Sat Jun 5 13:06:11 2021" "
+ "vidc.iyuv" "Intel Indeo(R) Video YUV Codec" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\iyuv_32.dll" "Sat Jun 5 13:06:11 2021" "
+ "vidc.mrle" "Microsoft RLE Compressor" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\msrle32.dll" "Sat Jun 5 13:06:11 2021" "
+ "vidc.msvc" "Microsoft Video 1 Compressor" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\msvidc32.dll" "Sat Jun 5 13:06:11 2021" "
+ "vidc.uyvy" "Microsoft UYVY Video Decompressor" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\msyuv.dll" "Sat Jun 5 13:06:11 2021" "
+ "vidc.yuy2" "Microsoft UYVY Video Decompressor" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\msyuv.dll" "Sat Jun 5 13:06:11 2021" "
+ "vidc.yvu9" "Toshiba Video Codec" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\tsbyuv.dll" "Sat Jun 5 13:06:11 2021" "
+ "vidc.yvyu" "Microsoft UYVY Video Decompressor" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\msyuv.dll" "Sat Jun 5 13:06:11 2021" "
+ "wave" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wdmaud.drv" "Sat Jun 5 13:04:54 2021" "
+ "wave1" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wdmaud.drv" "Sat Jun 5 13:04:54 2021" "
+ "wave2" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wdmaud.drv" "Sat Jun 5 13:04:54 2021" "
+ "wave3" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wdmaud.drv" "Sat Jun 5 13:04:54 2021" "
+ "wavemapper" "Microsoft Sound Mapper" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\msacm32.drv" "Sat Jun 5 13:04:54 2021" "
[HKLM\Software\Classes\Filter]
[HKLM\Software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance]
+ "AC3 Parser Filter" "DirectShow MPEG-2 Splitter." "(Verified) Microsoft Windows" "C:\Windows\System32\mpg2splt.ax" "Sat Jun 5 13:06:14 2021" "
+ "ACM Wrapper" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\quartz.dll" "Sat Jun 5 13:06:11 2021" "
+ "AVI Decompressor" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\quartz.dll" "Sat Jun 5 13:06:11 2021" "
+ "AVI Draw Filter" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\quartz.dll" "Sat Jun 5 13:06:11 2021" "
+ "AVI mux" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\qcap.dll" "Sat Jun 5 13:06:11 2021" "
+ "AVI Splitter" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\quartz.dll" "Sat Jun 5 13:06:11 2021" "
+ "AVI/WAV File Source" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\quartz.dll" "Sat Jun 5 13:06:11 2021" "
+ "BDA MPEG2 Transport Information Filter" "Microsoft Transport Information Filter for MPEG2 based networks." "(Verified) Microsoft Windows" "C:\Windows\System32\psisrndr.ax" "Sat Jun 5 13:06:14 2021" "
+ "Closed Captions Analysis Filter" "CCA DirectShow Filter." "(Verified) Microsoft Windows" "C:\Windows\System32\cca.dll" "Sat Jun 5 13:06:14 2021" "
+ "Color Space Converter" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\quartz.dll" "Sat Jun 5 13:06:11 2021" "
+ "Default Video Renderer" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\quartz.dll" "Sat Jun 5 13:06:11 2021" "
+ "DV Muxer" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\qdv.dll" "Sat Jun 5 13:06:11 2021" "
+ "DV Splitter" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\qdv.dll" "Sat Jun 5 13:06:11 2021" "
+ "DV Video Decoder" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\qdv.dll" "Sat Jun 5 13:06:11 2021" "
+ "DVD Navigator" "DirectShow DVD PlayBack Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\qdvd.dll" "Sat Jun 5 13:06:11 2021" "
+ "Enhanced Video Renderer" "Enhanced Video Renderer DLL" "(Verified) Microsoft Windows" "C:\Windows\System32\evr.dll" "Sat Jun 5 18:17:05 2021" "
+ "File Source (Async.)" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\quartz.dll" "Sat Jun 5 13:06:11 2021" "
+ "File Source (URL)" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\quartz.dll" "Sat Jun 5 13:06:11 2021" "
+ "File stream renderer" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\quartz.dll" "Sat Jun 5 13:06:11 2021" "
+ "File Writer" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\qcap.dll" "Sat Jun 5 13:06:11 2021" "
+ "Infinite Pin Tee Filter" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\qcap.dll" "Sat Jun 5 13:06:11 2021" "
+ "Internal Text Renderer" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\quartz.dll" "Sat Jun 5 13:06:11 2021" "
+ "Line 21 Decoder 2" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\quartz.dll" "Sat Jun 5 13:06:11 2021" "
+ "Microsoft AC3 Encoder" "Microsoft AC-3 Encoder" "(Verified) Microsoft Windows" "C:\Windows\System32\msac3enc.dll" "Thu Dec 16 07:57:12 2021" "
+ "Microsoft DTV-DVD Audio Decoder" "Microsoft DTV-DVD Audio Decoder" "(Verified) Microsoft Windows" "C:\Windows\System32\msmpeg2adec.dll" "Thu Dec 16 07:57:13 2021" "
+ "Microsoft DTV-DVD Video Decoder" "Microsoft DTV-DVD Video Decoder" "(Verified) Microsoft Windows" "C:\Windows\System32\msmpeg2vdec.dll" "Thu Dec 16 07:57:13 2021" "
+ "Microsoft MPEG-2 Audio Encoder" "Microsoft MPEG-2 Encoder" "(Verified) Microsoft Windows" "C:\Windows\System32\msmpeg2enc.dll" "Thu Dec 16 07:57:12 2021" "
+ "Microsoft MPEG-2 Encoder" "Microsoft MPEG-2 Encoder" "(Verified) Microsoft Windows" "C:\Windows\System32\msmpeg2enc.dll" "Thu Dec 16 07:57:12 2021" "
+ "Microsoft MPEG-2 Video Encoder" "Microsoft MPEG-2 Encoder" "(Verified) Microsoft Windows" "C:\Windows\System32\msmpeg2enc.dll" "Thu Dec 16 07:57:12 2021" "
+ "MIDI Parser" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\quartz.dll" "Sat Jun 5 13:06:11 2021" "
+ "MJPEG Decompressor" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\quartz.dll" "Sat Jun 5 13:06:11 2021" "
+ "MPEG Audio Codec" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\quartz.dll" "Sat Jun 5 13:06:11 2021" "
+ "MPEG Video Codec" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\quartz.dll" "Sat Jun 5 13:06:11 2021" "
+ "MPEG-2 Demultiplexer" "DirectShow MPEG-2 Splitter." "(Verified) Microsoft Windows" "C:\Windows\System32\mpg2splt.ax" "Sat Jun 5 13:06:14 2021" "
+ "MPEG-2 Sections and Tables" "Microsoft MPEG-2 Section and Table Acquisition Module" "(Verified) Microsoft Windows" "C:\Windows\System32\Mpeg2Data.ax" "Sat Jun 5 13:06:14 2021" "
+ "MPEG-2 Splitter" "DirectShow MPEG-2 Splitter." "(Verified) Microsoft Windows" "C:\Windows\System32\mpg2splt.ax" "Sat Jun 5 13:06:14 2021" "
+ "Mpeg-2 Video Stream Analysis" "DirectShow Stream Buffer Filter." "(Verified) Microsoft Windows" "C:\Windows\System32\sbe.dll" "Thu Dec 16 07:56:44 2021" "
+ "MPEG-I Stream Splitter" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\quartz.dll" "Sat Jun 5 13:06:11 2021" "
+ "Multi-file Parser" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\quartz.dll" "Sat Jun 5 13:06:11 2021" "
+ "Null Renderer" "DirectShow editing." "(Verified) Microsoft Windows" "C:\Windows\System32\qedit.dll" "Sat Jun 5 13:06:16 2021" "
+ "SAMI (CC) Reader" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\quartz.dll" "Sat Jun 5 13:06:11 2021" "
+ "Sample Grabber" "DirectShow editing." "(Verified) Microsoft Windows" "C:\Windows\System32\qedit.dll" "Sat Jun 5 13:06:16 2021" "
+ "SBE2 Sink" "DirectShow Stream Buffer Filter." "(Verified) Microsoft Windows" "C:\Windows\System32\sbe.dll" "Thu Dec 16 07:56:44 2021" "
+ "SBE2FileScan" "DirectShow Stream Buffer Filter." "(Verified) Microsoft Windows" "C:\Windows\System32\sbe.dll" "Thu Dec 16 07:56:44 2021" "
+ "SBE2MediaTypeProfile" "DirectShow Stream Buffer Filter." "(Verified) Microsoft Windows" "C:\Windows\System32\sbe.dll" "Thu Dec 16 07:56:44 2021" "
+ "Smart Tee Filter" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\qcap.dll" "Sat Jun 5 13:06:11 2021" "
+ "StreamBufferSink" "DirectShow Stream Buffer Filter." "(Verified) Microsoft Windows" "C:\Windows\System32\sbe.dll" "Thu Dec 16 07:56:44 2021" "
+ "StreamBufferSource" "DirectShow Stream Buffer Filter." "(Verified) Microsoft Windows" "C:\Windows\System32\sbe.dll" "Thu Dec 16 07:56:44 2021" "
+ "VBI Codec" "Microsoft VBI Codec" "(Verified) Microsoft Windows" "C:\Windows\System32\VBICodec.ax" "Sat Jun 5 13:06:14 2021" "
+ "VBI Surface Allocator" "VBI Surface Allocator Filter" "(Verified) Microsoft Windows" "C:\Windows\System32\vbisurf.ax" "Thu Dec 16 07:56:44 2021" "
+ "VGA 16 color ditherer" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\quartz.dll" "Sat Jun 5 13:06:11 2021" "
+ "Video Mixing Renderer 9" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\quartz.dll" "Sat Jun 5 13:06:11 2021" "
+ "Video Port Manager" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\quartz.dll" "Sat Jun 5 13:06:11 2021" "
+ "Video Renderer" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\quartz.dll" "Sat Jun 5 13:06:11 2021" "
+ "VPS Decoder" "Microsoft Teletext Server" "(Verified) Microsoft Windows" "C:\Windows\System32\WSTPager.ax" "Sat Jun 5 13:06:14 2021" "
+ "Wave Parser" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\System32\quartz.dll" "Sat Jun 5 13:06:11 2021" "
+ "WM ASF Reader" "DirectShow ASF Support" "(Verified) Microsoft Windows" "C:\Windows\System32\qasf.dll" "Thu Dec 16 07:56:30 2021" "
+ "WM ASF Writer" "DirectShow ASF Support" "(Verified) Microsoft Windows" "C:\Windows\System32\qasf.dll" "Thu Dec 16 07:56:30 2021" "
+ "WST Pager" "Microsoft Teletext Server" "(Verified) Microsoft Windows" "C:\Windows\System32\WSTPager.ax" "Sat Jun 5 13:06:14 2021" "
[HKLM\Software\Classes\CLSID\{AC757296-3522-4E11-9862-C17BE5A1767E}\Instance]
[HKLM\Software\Classes\CLSID\{7ED96837-96F0-4812-B211-F13C24117ED3}\Instance]
+ "{41945702-8302-44A6-9445-AC98E8AFA086}" "MS RAW Image Decoder DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\MSRAWImage.dll" "Sat Jun 5 18:17:05 2021" "
+ "{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}" "Microsoft Camera Codec Pack" "(Verified) Microsoft Windows" "C:\Windows\System32\WindowsCodecsRaw.dll" "Thu Dec 16 07:57:08 2021" "
[HKLM\Software\Classes\CLSID\{ABE3B9A4-257D-4B97-BD1A-294AF496222E}\Instance]
[HKLM\Software\Wow6432Node\Classes\Filter]
[HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32]
+ "aux" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\wdmaud.drv" "Sat Jun 5 13:05:45 2021" "
+ "aux1" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\wdmaud.drv" "Sat Jun 5 13:05:45 2021" "
+ "aux2" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\wdmaud.drv" "Sat Jun 5 13:05:45 2021" "
+ "aux3" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\wdmaud.drv" "Sat Jun 5 13:05:45 2021" "
+ "midi" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\wdmaud.drv" "Sat Jun 5 13:05:45 2021" "
+ "midi1" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\wdmaud.drv" "Sat Jun 5 13:05:45 2021" "
+ "midi2" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\wdmaud.drv" "Sat Jun 5 13:05:45 2021" "
+ "midi3" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\wdmaud.drv" "Sat Jun 5 13:05:45 2021" "
+ "midimapper" "Microsoft MIDI Mapper" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\midimap.dll" "Sat Jun 5 13:05:43 2021" "
+ "mixer" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\wdmaud.drv" "Sat Jun 5 13:05:45 2021" "
+ "mixer1" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\wdmaud.drv" "Sat Jun 5 13:05:45 2021" "
+ "mixer2" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\wdmaud.drv" "Sat Jun 5 13:05:45 2021" "
+ "mixer3" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\wdmaud.drv" "Sat Jun 5 13:05:45 2021" "
+ "msacm.imaadpcm" "IMA ADPCM CODEC for MSACM" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\imaadp32.acm" "Sat Jun 5 13:05:43 2021" "
+ "msacm.l3acm" "MPEG Layer-3 Audio Codec for MSACM" "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\l3codeca.acm" "Sat Jun 5 18:17:04 2021" "
+ "msacm.msadpcm" "Microsoft ADPCM CODEC for MSACM" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\msadp32.acm" "Sat Jun 5 13:05:43 2021" "
+ "msacm.msg711" "Microsoft CCITT G.711 (A-Law and u-Law) CODEC for MSACM" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\msg711.acm" "Sat Jun 5 13:05:43 2021" "
+ "msacm.msgsm610" "Microsoft GSM 6.10 Audio CODEC for MSACM" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\msgsm32.acm" "Sat Jun 5 13:05:45 2021" "
+ "vidc.cvid" "Cinepak® Codec" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\iccvid.dll" "Sat Jun 5 13:06:24 2021" "
+ "vidc.i420" "Intel Indeo(R) Video YUV Codec" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\iyuv_32.dll" "Sat Jun 5 13:06:24 2021" "
+ "vidc.iyuv" "Intel Indeo(R) Video YUV Codec" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\iyuv_32.dll" "Sat Jun 5 13:06:24 2021" "
+ "vidc.mrle" "Microsoft RLE Compressor" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\msrle32.dll" "Sat Jun 5 13:06:24 2021" "
+ "vidc.msvc" "Microsoft Video 1 Compressor" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\msvidc32.dll" "Sat Jun 5 13:06:24 2021" "
+ "vidc.uyvy" "Microsoft UYVY Video Decompressor" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\msyuv.dll" "Sat Jun 5 13:06:24 2021" "
+ "vidc.yuy2" "Microsoft UYVY Video Decompressor" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\msyuv.dll" "Sat Jun 5 13:06:24 2021" "
+ "vidc.yvu9" "Toshiba Video Codec" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\tsbyuv.dll" "Sat Jun 5 13:06:24 2021" "
+ "vidc.yvyu" "Microsoft UYVY Video Decompressor" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\msyuv.dll" "Sat Jun 5 13:06:24 2021" "
+ "wave" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\wdmaud.drv" "Sat Jun 5 13:05:45 2021" "
+ "wave1" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\wdmaud.drv" "Sat Jun 5 13:05:45 2021" "
+ "wave2" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\wdmaud.drv" "Sat Jun 5 13:05:45 2021" "
+ "wave3" "Winmm audio system driver" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\wdmaud.drv" "Sat Jun 5 13:05:45 2021" "
+ "wavemapper" "Microsoft Sound Mapper" "(Verified) Microsoft Windows" "C:\WINDOWS\SysWOW64\msacm32.drv" "Sat Jun 5 13:05:43 2021" "
[HKLM\Software\Wow6432Node\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance]
+ "AC3 Parser Filter" "DirectShow MPEG-2 Splitter." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\mpg2splt.ax" "Sat Jun 5 13:06:24 2021" "
+ "ACM Wrapper" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\quartz.dll" "Sat Jun 5 13:06:24 2021" "
+ "AVI Decompressor" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\quartz.dll" "Sat Jun 5 13:06:24 2021" "
+ "AVI Draw Filter" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\quartz.dll" "Sat Jun 5 13:06:24 2021" "
+ "AVI mux" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\qcap.dll" "Sat Jun 5 13:06:24 2021" "
+ "AVI Splitter" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\quartz.dll" "Sat Jun 5 13:06:24 2021" "
+ "AVI/WAV File Source" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\quartz.dll" "Sat Jun 5 13:06:24 2021" "
+ "BDA MPEG2 Transport Information Filter" "Microsoft Transport Information Filter for MPEG2 based networks." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\psisrndr.ax" "Sat Jun 5 13:06:24 2021" "
+ "Closed Captions Analysis Filter" "CCA DirectShow Filter." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\cca.dll" "Sat Jun 5 13:06:24 2021" "
+ "Color Space Converter" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\quartz.dll" "Sat Jun 5 13:06:24 2021" "
+ "Default Video Renderer" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\quartz.dll" "Sat Jun 5 13:06:24 2021" "
+ "DV Muxer" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\qdv.dll" "Sat Jun 5 13:06:24 2021" "
+ "DV Splitter" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\qdv.dll" "Sat Jun 5 13:06:24 2021" "
+ "DV Video Decoder" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\qdv.dll" "Sat Jun 5 13:06:24 2021" "
+ "DVD Navigator" "DirectShow DVD PlayBack Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\qdvd.dll" "Sat Jun 5 13:06:24 2021" "
+ "Enhanced Video Renderer" "Enhanced Video Renderer DLL" "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\evr.dll" "Sat Jun 5 18:17:04 2021" "
+ "File Source (Async.)" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\quartz.dll" "Sat Jun 5 13:06:24 2021" "
+ "File Source (URL)" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\quartz.dll" "Sat Jun 5 13:06:24 2021" "
+ "File stream renderer" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\quartz.dll" "Sat Jun 5 13:06:24 2021" "
+ "File Writer" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\qcap.dll" "Sat Jun 5 13:06:24 2021" "
+ "Infinite Pin Tee Filter" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\qcap.dll" "Sat Jun 5 13:06:24 2021" "
+ "Internal Text Renderer" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\quartz.dll" "Sat Jun 5 13:06:24 2021" "
+ "Line 21 Decoder" "DirectShow DVD PlayBack Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\qdvd.dll" "Sat Jun 5 13:06:24 2021" "
+ "Line 21 Decoder 2" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\quartz.dll" "Sat Jun 5 13:06:24 2021" "
+ "Microsoft AC3 Encoder" "Microsoft AC-3 Encoder" "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\msac3enc.dll" "Thu Dec 16 07:57:16 2021" "
+ "Microsoft DTV-DVD Audio Decoder" "Microsoft DTV-DVD Audio Decoder" "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\msmpeg2adec.dll" "Thu Dec 16 07:57:17 2021" "
+ "Microsoft DTV-DVD Video Decoder" "Microsoft DTV-DVD Video Decoder" "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\msmpeg2vdec.dll" "Thu Dec 16 07:57:16 2021" "
+ "Microsoft MPEG-2 Audio Encoder" "Microsoft MPEG-2 Encoder" "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\msmpeg2enc.dll" "Thu Dec 16 07:57:16 2021" "
+ "Microsoft MPEG-2 Encoder" "Microsoft MPEG-2 Encoder" "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\msmpeg2enc.dll" "Thu Dec 16 07:57:16 2021" "
+ "Microsoft MPEG-2 Video Encoder" "Microsoft MPEG-2 Encoder" "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\msmpeg2enc.dll" "Thu Dec 16 07:57:16 2021" "
+ "MIDI Parser" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\quartz.dll" "Sat Jun 5 13:06:24 2021" "
+ "MJPEG Decompressor" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\quartz.dll" "Sat Jun 5 13:06:24 2021" "
+ "MPEG Audio Codec" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\quartz.dll" "Sat Jun 5 13:06:24 2021" "
+ "MPEG Video Codec" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\quartz.dll" "Sat Jun 5 13:06:24 2021" "
+ "MPEG-2 Demultiplexer" "DirectShow MPEG-2 Splitter." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\mpg2splt.ax" "Sat Jun 5 13:06:24 2021" "
+ "MPEG-2 Sections and Tables" "Microsoft MPEG-2 Section and Table Acquisition Module" "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\Mpeg2Data.ax" "Sat Jun 5 13:06:24 2021" "
+ "MPEG-2 Splitter" "DirectShow MPEG-2 Splitter." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\mpg2splt.ax" "Sat Jun 5 13:06:24 2021" "
+ "Mpeg-2 Video Stream Analysis" "DirectShow Stream Buffer Filter." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\sbe.dll" "Sat Jun 5 13:06:24 2021" "
+ "MPEG-I Stream Splitter" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\quartz.dll" "Sat Jun 5 13:06:24 2021" "
+ "Multi-file Parser" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\quartz.dll" "Sat Jun 5 13:06:24 2021" "
+ "Null Renderer" "DirectShow editing." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\qedit.dll" "Sat Jun 5 13:06:24 2021" "
+ "Overlay Mixer" "DirectShow DVD PlayBack Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\qdvd.dll" "Sat Jun 5 13:06:24 2021" "
+ "Overlay Mixer2" "DirectShow DVD PlayBack Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\qdvd.dll" "Sat Jun 5 13:06:24 2021" "
+ "SAMI (CC) Reader" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\quartz.dll" "Sat Jun 5 13:06:24 2021" "
+ "Sample Grabber" "DirectShow editing." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\qedit.dll" "Sat Jun 5 13:06:24 2021" "
+ "SBE2 Sink" "DirectShow Stream Buffer Filter." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\sbe.dll" "Sat Jun 5 13:06:24 2021" "
+ "SBE2FileScan" "DirectShow Stream Buffer Filter." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\sbe.dll" "Sat Jun 5 13:06:24 2021" "
+ "SBE2MediaTypeProfile" "DirectShow Stream Buffer Filter." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\sbe.dll" "Sat Jun 5 13:06:24 2021" "
+ "Smart Tee Filter" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\qcap.dll" "Sat Jun 5 13:06:24 2021" "
+ "StreamBufferSink" "DirectShow Stream Buffer Filter." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\sbe.dll" "Sat Jun 5 13:06:24 2021" "
+ "StreamBufferSource" "DirectShow Stream Buffer Filter." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\sbe.dll" "Sat Jun 5 13:06:24 2021" "
+ "VBI Codec" "Microsoft VBI Codec" "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\VBICodec.ax" "Sat Jun 5 13:06:24 2021" "
+ "VBI Surface Allocator" "VBI Surface Allocator Filter" "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\vbisurf.ax" "Thu Dec 16 07:57:07 2021" "
+ "VGA 16 color ditherer" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\quartz.dll" "Sat Jun 5 13:06:24 2021" "
+ "Video Mixing Renderer 9" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\quartz.dll" "Sat Jun 5 13:06:24 2021" "
+ "Video Port Manager" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\quartz.dll" "Sat Jun 5 13:06:24 2021" "
+ "Video Renderer" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\quartz.dll" "Sat Jun 5 13:06:24 2021" "
+ "VPS Decoder" "Microsoft Teletext Server" "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\WSTPager.ax" "Sat Jun 5 13:06:24 2021" "
+ "Wave Parser" "DirectShow Runtime." "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\quartz.dll" "Sat Jun 5 13:06:24 2021" "
+ "WM ASF Reader" "DirectShow ASF Support" "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\qasf.dll" "Thu Dec 16 07:57:01 2021" "
+ "WM ASF Writer" "DirectShow ASF Support" "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\qasf.dll" "Thu Dec 16 07:57:01 2021" "
+ "WST Pager" "Microsoft Teletext Server" "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\WSTPager.ax" "Sat Jun 5 13:06:24 2021" "
[HKLM\Software\Wow6432Node\Classes\CLSID\{AC757296-3522-4E11-9862-C17BE5A1767E}\Instance]
[HKLM\Software\Wow6432Node\Classes\CLSID\{7ED96837-96F0-4812-B211-F13C24117ED3}\Instance]
+ "{41945702-8302-44A6-9445-AC98E8AFA086}" "MS RAW Image Decoder DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\MSRAWImage.dll" "Sat Jun 5 18:17:04 2021" "
+ "{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}" "Microsoft Camera Codec Pack" "(Verified) Microsoft Windows" "C:\Windows\SysWOW64\WindowsCodecsRaw.dll" "Thu Dec 16 07:57:10 2021" "
[HKLM\Software\Wow6432Node\Classes\CLSID\{ABE3B9A4-257D-4B97-BD1A-294AF496222E}\Instance]
[Boot Execute]
[HKLM\System\CurrentControlSet\Control\Session Manager\BootExecute]
+ "autocheck autochk *" "Auto Check Utility" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\autochk.exe" "Sat Jun 5 13:05:23 2021" "
[HKLM\System\CurrentControlSet\Control\Session Manager\SetupExecute]
[HKLM\System\CurrentControlSet\Control\Session Manager\Execute]
[HKLM\System\CurrentControlSet\Control\Session Manager\S0InitialCommand]
[Image Hijacks]
[HKCU\Software\Microsoft\Command Processor\Autorun]
[HKCU\SOFTWARE\Classes\Exefile\Shell\Open\Command\(Default)]
[HKCU\SOFTWARE\Classes\Htmlfile\Shell\Open\Command\(Default)]
[HKCU\Software\Classes\.exe]
[HKCU\Software\Classes\.cmd]
[HKLM\Software\Microsoft\Command Processor\Autorun]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
[HKLM\SOFTWARE\Classes\Exefile\Shell\Open\Command\(Default)]
[HKLM\SOFTWARE\Classes\Htmlfile\Shell\Open\Command\(Default)]
+ "C:\Program Files\Internet Explorer\iexplore.exe" "Internet Explorer" "(Verified) Microsoft Corporation" "C:\Program Files\Internet Explorer\iexplore.exe" "Thu Dec 16 08:01:20 2021" "
[HKLM\Software\Classes\.exe]
[HKLM\Software\Classes\.cmd]
[HKLM\Software\Wow6432Node\Microsoft\Command Processor\Autorun]
[HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
[AppInit]
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Appinit_Dlls]
[HKLM\System\CurrentControlSet\Control\Session Manager\AppCertDlls]
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Windows\Appinit_Dlls]
[Known DLLs]
[HKLM\System\CurrentControlSet\Control\Session Manager\KnownDlls]
+ "*kernel32" "Windows NT BASE API Client DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\kernel32.dll" "Thu Dec 16 07:53:03 2021" "
+ "*kernel32" "Windows NT BASE API Client DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\kernel32.dll" "Thu Dec 16 07:55:22 2021" "
+ "_wow64cpu" "AMD64 Wow64 CPU " "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wow64cpu.dll" "Sat Jun 5 13:05:27 2021" "
+ "_wow64cpu" "" "" "File not found: C:\WINDOWS\Syswow64\wow64cpu.dll" "" "
+ "_wowarmhw" "" "" "File not found: C:\WINDOWS\system32\wowarmhw.dll" "" "
+ "_wowarmhw" "" "" "File not found: C:\WINDOWS\Syswow64\wowarmhw.dll" "" "
+ "_xtajit" "" "" "File not found: C:\WINDOWS\system32\xtajit.dll" "" "
+ "_xtajit" "" "" "File not found: C:\WINDOWS\Syswow64\xtajit.dll" "" "
+ "advapi32" "Advanced Windows 32 Base API" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\advapi32.dll" "Thu Dec 16 07:51:50 2021" "
+ "advapi32" "Advanced Windows 32 Base API" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\advapi32.dll" "Thu Dec 16 07:55:17 2021" "
+ "clbcatq" "COM+ Configuration Catalog" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\clbcatq.dll" "Sat Jun 5 13:05:23 2021" "
+ "clbcatq" "COM+ Configuration Catalog" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\clbcatq.dll" "Sat Jun 5 13:05:53 2021" "
+ "combase" "Microsoft COM for Windows" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\combase.dll" "Thu Dec 16 07:53:43 2021" "
+ "combase" "Microsoft COM for Windows" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\combase.dll" "Thu Dec 16 07:55:58 2021" "
+ "COMDLG32" "Common Dialogues DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\COMDLG32.dll" "Thu Dec 16 07:54:26 2021" "
+ "COMDLG32" "Common Dialogs DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\COMDLG32.dll" "Thu Dec 16 07:56:18 2021" "
+ "coml2" "Microsoft COM for Windows" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\coml2.dll" "Sat Jun 5 13:05:09 2021" "
+ "coml2" "Microsoft COM for Windows" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\coml2.dll" "Sat Jun 5 13:05:51 2021" "
+ "DifxApi" "Driver Install Frameworks for API library module" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\difxapi.dll" "Sat Jun 5 13:05:39 2021" "
+ "DifxApi" "Driver Install Frameworks for API library module" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\difxapi.dll" "Sat Jun 5 13:05:59 2021" "
+ "gdi32" "GDI Client DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\gdi32.dll" "Sat Jun 5 13:05:06 2021" "
+ "gdi32" "GDI Client DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\gdi32.dll" "Sat Jun 5 13:05:48 2021" "
+ "gdiplus" "Microsoft GDI+" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\gdiplus.dll" "Thu Dec 16 07:54:20 2021" "
+ "gdiplus" "Microsoft GDI+" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\gdiplus.dll" "Thu Dec 16 07:56:02 2021" "
+ "IMAGEHLP" "Windows NT Image Helper" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\IMAGEHLP.dll" "Sat Jun 5 13:05:25 2021" "
+ "IMAGEHLP" "Windows NT Image Helper" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\IMAGEHLP.dll" "Sat Jun 5 13:05:25 2021" "
+ "IMM32" "Multi-User Windows IMM32 API Client DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\IMM32.dll" "Sat Jun 5 13:05:27 2021" "
+ "IMM32" "Multi-User Windows IMM32 API Client DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\IMM32.dll" "Sat Jun 5 13:05:53 2021" "
+ "MSCTF" "MSCTF Server DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\MSCTF.dll" "Thu Dec 16 07:52:59 2021" "
+ "MSCTF" "MSCTF Server DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\MSCTF.dll" "Thu Dec 16 07:55:19 2021" "
+ "MSVCRT" "Windows NT CRT DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\MSVCRT.dll" "Sat Jun 5 13:05:25 2021" "
+ "MSVCRT" "Windows NT CRT DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\MSVCRT.dll" "Sat Jun 5 13:05:45 2021" "
+ "NORMALIZ" "Unicode Normalization DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\NORMALIZ.dll" "Sat Jun 5 13:05:27 2021" "
+ "NORMALIZ" "Unicode Normalization DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\NORMALIZ.dll" "Sat Jun 5 13:05:53 2021" "
+ "NSI" "NSI User-mode interface DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\NSI.dll" "Sat Jun 5 13:05:25 2021" "
+ "NSI" "NSI User-mode interface DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\NSI.dll" "Sat Jun 5 13:05:25 2021" "
+ "ole32" "Microsoft OLE for Windows" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\ole32.dll" "Thu Dec 16 07:53:40 2021" "
+ "ole32" "Microsoft OLE for Windows" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\ole32.dll" "Thu Dec 16 07:55:57 2021" "
+ "OLEAUT32" "OLEAUT32.DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\OLEAUT32.dll" "Sat Jun 5 13:05:25 2021" "
+ "OLEAUT32" "OLEAUT32.DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\OLEAUT32.dll" "Sat Jun 5 13:05:53 2021" "
+ "PSAPI" "Process Status Helper" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\PSAPI.DLL" "Sat Jun 5 13:05:23 2021" "
+ "PSAPI" "Process Status Helper" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\PSAPI.DLL" "Sat Jun 5 13:05:53 2021" "
+ "rpcrt4" "Remote Procedure Call Runtime" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\rpcrt4.dll" "Thu Dec 16 07:53:50 2021" "
+ "rpcrt4" "Remote Procedure Call Runtime" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\rpcrt4.dll" "Thu Dec 16 07:55:15 2021" "
+ "sechost" "Host for SCM/SDDL/LSA Lookup APIs" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\sechost.dll" "Thu Dec 16 07:53:50 2021" "
+ "sechost" "Host for SCM/SDDL/LSA Lookup APIs" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\sechost.dll" "Thu Dec 16 07:55:15 2021" "
+ "Setupapi" "Windows Setup API" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\Setupapi.dll" "Thu Dec 16 07:54:53 2021" "
+ "Setupapi" "Windows Setup API" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\Setupapi.dll" "Thu Dec 16 07:56:16 2021" "
+ "SHCORE" "SHCORE" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\SHCORE.dll" "Thu Dec 16 07:53:07 2021" "
+ "SHCORE" "SHCORE" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\SHCORE.dll" "Thu Dec 16 07:55:52 2021" "
+ "SHELL32" "Windows Shell Common Dll" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\SHELL32.dll" "Thu Dec 16 07:54:27 2021" "
+ "SHELL32" "Windows Shell Common Dll" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\SHELL32.dll" "Thu Dec 16 07:56:19 2021" "
+ "SHLWAPI" "Shell Light-weight Utility Library" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\SHLWAPI.dll" "Sat Jun 5 13:05:33 2021" "
+ "SHLWAPI" "Shell Light-weight Utility Library" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\SHLWAPI.dll" "Sat Jun 5 13:06:00 2021" "
+ "user32" "Multi-User Windows USER API Client DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\user32.dll" "Thu Dec 16 07:52:55 2021" "
+ "user32" "Multi-User Windows USER API Client DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\user32.dll" "Thu Dec 16 07:55:51 2021" "
+ "WLDAP32" "Win32 LDAP API DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\WLDAP32.dll" "Sat Jun 5 13:05:23 2021" "
+ "WLDAP32" "Win32 LDAP API DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\WLDAP32.dll" "Sat Jun 5 13:05:53 2021" "
+ "wow64" "Win32 Emulation on NT64" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wow64.dll" "Thu Dec 16 07:54:09 2021" "
+ "wow64" "" "" "File not found: C:\WINDOWS\Syswow64\wow64.dll" "" "
+ "wow64base" "" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wow64base.dll" "Sat Jun 5 13:05:27 2021" "
+ "wow64base" "" "" "File not found: C:\WINDOWS\Syswow64\wow64base.dll" "" "
+ "wow64con" "" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wow64con.dll" "Thu Dec 16 07:54:09 2021" "
+ "wow64con" "" "" "File not found: C:\WINDOWS\Syswow64\wow64con.dll" "" "
+ "wow64win" "Wow64 Console and Win32 API Logging" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wow64win.dll" "Thu Dec 16 07:54:09 2021" "
+ "wow64win" "" "" "File not found: C:\WINDOWS\Syswow64\wow64win.dll" "" "
+ "WS2_32" "Windows Socket 2.0 32-Bit DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\WS2_32.dll" "Sat Jun 5 13:05:25 2021" "
+ "WS2_32" "Windows Socket 2.0 32-Bit DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\Syswow64\WS2_32.dll" "Sat Jun 5 13:05:45 2021" "
+ "xtajit64" "" "" "File not found: C:\WINDOWS\system32\xtajit64.dll" "" "
+ "xtajit64" "" "" "File not found: C:\WINDOWS\Syswow64\xtajit64.dll" "" "
[WinLogon]
[HKCU\SOFTWARE\Policies\Microsoft\Windows\Control Panel\Desktop\Scrnsave.exe]
[HKCU\Control Panel\Desktop\Scrnsave.exe]
[HKLM\SYSTEM\Setup\CmdLine]
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Taskman]
[HKLM\System\CurrentControlSet\Control\BootVerificationProgram\ImagePath]
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\Credential Providers]
+ "Automatic Redeployment Credential Provider" "Autopilot Reset Credential Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mgmtrefreshcredprov.dll" "Sat Jun 5 13:06:16 2021" "
+ "CCertProvider" "Cert Credential Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\certCredProvider.dll" "Sat Jun 5 13:05:27 2021" "
+ "Cloud Experience Credential Provider" "Cloud Experience Credential Provider" "(Verified) Microsoft Windows" "C:\Windows\System32\cxcredprov.dll" "Sat Jun 5 13:05:23 2021" "
+ "CngCredUICredentialProvider" "Microsoft CNG CredUI Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\cngcredui.dll" "Sat Jun 5 13:05:40 2021" "
+ "FaceCredentialProvider" "Face Credential Provider" "(Verified) Microsoft Windows" "C:\Windows\System32\FaceCredentialProvider.dll" "Thu Dec 16 07:56:20 2021" "
+ "FIDO Credential Provider" "FIDO Credential Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\fidocredprov.dll" "Thu Dec 16 07:52:31 2021" "
+ "GenericProvider" "Credential Providers" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\credprovs.dll" "Sat Jun 5 13:05:27 2021" "
+ "NGC Credential Provider" "Microsoft Passport Credential Provider" "(Verified) Microsoft Windows" "C:\Windows\System32\ngccredprov.dll" "Thu Dec 16 07:52:53 2021" "
+ "NPProvider" "Credential Providers" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\credprovs.dll" "Sat Jun 5 13:05:27 2021" "
+ "PasswordProvider" "Credential Providers" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\credprovs.dll" "Sat Jun 5 13:05:27 2021" "
+ "PicturePasswordLogonProvider" "Credentials Providers Legacy" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\credprovslegacy.dll" "Thu Dec 16 07:54:15 2021" "
+ "PINLogonProvider" "Credentials Providers Legacy" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\credprovslegacy.dll" "Thu Dec 16 07:54:15 2021" "
+ "Second Authentication Factor Credential Provider" "Microsoft Companion Authenticator Credentials Provider" "(Verified) Microsoft Windows" "C:\Windows\System32\devicengccredprov.dll" "Thu Dec 16 07:54:15 2021" "
+ "Smartcard Credential Provider" "Windows Smartcard Credential Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\SmartcardCredentialProvider.dll" "Sat Jun 5 13:05:34 2021" "
+ "Smartcard Pin Provider" "Windows Smartcard Credential Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\SmartcardCredentialProvider.dll" "Sat Jun 5 13:05:34 2021" "
+ "Smartcard Reader Selection Provider" "Windows Smartcard Credential Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\SmartcardCredentialProvider.dll" "Sat Jun 5 13:05:34 2021" "
+ "Smartcard WinRT Provider" "Windows Smartcard Credential Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\SmartcardCredentialProvider.dll" "Sat Jun 5 13:05:34 2021" "
+ "TrustedSignal Credential Provider" "Trusted Signal Credential Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\TrustedSignalCredProv.dll" "Sat Jun 5 13:05:27 2021" "
+ "WinBio Credential Provider" "WinBio Credential Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\BioCredProv.dll" "Thu Dec 16 07:53:05 2021" "
+ "WLIDCredentialProvider" "Microsoft® Account Credential Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wlidcredprov.dll" "Sat Jun 5 13:05:31 2021" "
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\Credential Provider Filters]
+ "GenericFilter" "Credential Providers" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\credprovs.dll" "Sat Jun 5 13:05:27 2021" "
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\PLAP Providers]
+ "CRasProvider" "RAS PLAP Credential Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\rasplap.dll" "Sat Jun 5 13:05:40 2021" "
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GpExtensions]
+ "@wlgpclnt.dll,-100" "802.11 Group Policy Client" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wlgpclnt.dll" "Sat Jun 5 13:05:00 2021" "
+ "Central Access" "Windows Audit Settings CSE" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\auditcse.dll" "Sat Jun 5 13:05:40 2021" "
+ "Folder Redirection" "Folder Redirection Group Policy Extension" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\fdeploy.dll" "Sat Jun 5 13:05:14 2021" "
+ "Microsoft Disk Quota" "Windows Shell Disk Quota Support DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\dskquota.dll" "Sat Jun 5 13:06:05 2021" "
+ "QoS Packet Scheduler" "GPTExt" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\gptext.dll" "Sat Jun 5 13:05:29 2021" "
+ "Remote Desktop USB Redirection" "Remote Desktop USB Redirection GP Extension" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\TsUsbRedirectionGroupPolicyExtension.dll" "Sat Jun 5 13:04:57 2021" "
+ "@C:\Windows\System32\iedkcs32.dll,-3051" "IEAK branding" "(Verified) Microsoft Windows" "C:\Windows\System32\iedkcs32.dll" "Sat Jun 5 13:06:07 2021" "
+ "{4D2F9B6F-1E52-4711-A382-6A8B1A003DE6}" "RemoteApp and Desktop Connection Component" "(Verified) Microsoft Windows" "C:\Windows\System32\tsworkspace.dll" "Thu Dec 16 07:53:00 2021" "
+ "Work Folders" "Microsoft (C) Work Folders Group Policy Client Extension" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\WorkFoldersGPExt.dll" "Sat Jun 5 13:06:16 2021" "
+ "MDM Policy" "Enroll Engine DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\dmenrollengine.dll" "Thu Dec 16 07:54:17 2021" "
+ "Windows Search Group Policy Extension" "Indexing Options" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\srchadmin.dll" "Sat Jun 5 13:05:40 2021" "
+ "@C:\Windows\System32\iedkcs32.dll,-3051" "IEAK branding" "(Verified) Microsoft Windows" "C:\Windows\System32\iedkcs32.dll" "Sat Jun 5 13:06:07 2021" "
+ "Security" "Windows Security Configuration Editor Client Engine" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\scecli.dll" "Sat Jun 5 13:05:40 2021" "
+ "Start Layout Group Policy" "Start Tile Data InProc Server" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\StartTileData.dll" "Thu Dec 16 07:52:03 2021" "
+ "Deployed Printer Connections" "Group Policy Printer Extension" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\gpprnext.dll" "Sat Jun 5 13:04:58 2021" "
+ "@dot3gpclnt.dll,-100" "802.3 Group Policy Client" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\dot3gpclnt.dll" "Sat Jun 5 13:05:00 2021" "
+ "Windows To Go Startup Options" "Windows To Go Launcher" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\pwlauncher.dll" "Sat Jun 5 13:06:10 2021" "
+ "Windows To Go Hibernate Options" "Windows To Go Launcher" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\pwlauncher.dll" "Sat Jun 5 13:06:10 2021" "
+ "TCPIP" "GPTExt" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\gptext.dll" "Sat Jun 5 13:05:29 2021" "
+ "@C:\Windows\System32\iedkcs32.dll,-3051" "IEAK branding" "(Verified) Microsoft Windows" "C:\Windows\System32\iedkcs32.dll" "Sat Jun 5 13:06:07 2021" "
+ "Delivery Optimization GP extension" "Delivery Optimisation Management" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\domgmt.dll" "Thu Dec 16 07:52:21 2021" "
+ "Internet Protocol Security Policies" "Policy Storage dll" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\polstore.dll" "Sat Jun 5 13:05:29 2021" "
+ "Audit" "Windows Audit Settings CSE" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\auditcse.dll" "Sat Jun 5 13:05:40 2021" "
+ "Policy-based QoS" "GPTExt" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\gptext.dll" "Sat Jun 5 13:05:29 2021" "
+ "Connectivity Platform" "GPTExt" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\gptext.dll" "Sat Jun 5 13:05:29 2021" "
[Winsock Providers]
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries]
+ "AF_UNIX" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mswsock.dll" "Sat Jun 5 13:05:23 2021" "
+ "Hyper-V RAW" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mswsock.dll" "Sat Jun 5 13:05:23 2021" "
+ "MSAFD L2CAP [Bluetooth]" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mswsock.dll" "Sat Jun 5 13:05:23 2021" "
+ "MSAFD RfComm [Bluetooth]" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mswsock.dll" "Sat Jun 5 13:05:23 2021" "
+ "MSAFD Tcpip [RAW/IP]" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mswsock.dll" "Sat Jun 5 13:05:23 2021" "
+ "MSAFD Tcpip [RAW/IPv6]" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mswsock.dll" "Sat Jun 5 13:05:23 2021" "
+ "MSAFD Tcpip [TCP/IP]" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mswsock.dll" "Sat Jun 5 13:05:23 2021" "
+ "MSAFD Tcpip [TCP/IPv6]" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mswsock.dll" "Sat Jun 5 13:05:23 2021" "
+ "MSAFD Tcpip [UDP/IP]" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mswsock.dll" "Sat Jun 5 13:05:23 2021" "
+ "MSAFD Tcpip [UDP/IPv6]" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mswsock.dll" "Sat Jun 5 13:05:23 2021" "
+ "RSVP TCP Service Provider" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mswsock.dll" "Sat Jun 5 13:05:23 2021" "
+ "RSVP TCPv6 Service Provider" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mswsock.dll" "Sat Jun 5 13:05:23 2021" "
+ "RSVP UDP Service Provider" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mswsock.dll" "Sat Jun 5 13:05:23 2021" "
+ "RSVP UDPv6 Service Provider" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mswsock.dll" "Sat Jun 5 13:05:23 2021" "
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries]
+ "@%SystemRoot%\system32\nlasvc.dll,-1000" "NLA Namespace Service Provider DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\nlansp_c.dll" "Sat Jun 5 13:05:39 2021" "
+ "Bluetooth Namespace" "Windows Sockets Helper DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wshbth.dll" "Thu Dec 16 07:53:06 2021" "
+ "E-mail Naming Shim Provider" "E-mail Naming Shim Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\napinsp.dll" "Sat Jun 5 13:05:27 2021" "
+ "NTDS" "LDAP RnR Provider DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\winrnr.dll" "Sat Jun 5 13:05:29 2021" "
+ "PNRP Cloud Namespace Provider" "PNRP Name Space Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\pnrpnsp.dll" "Sat Jun 5 13:06:16 2021" "
+ "PNRP Name Namespace Provider" "PNRP Name Space Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\pnrpnsp.dll" "Sat Jun 5 13:06:16 2021" "
+ "Tcpip" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\mswsock.dll" "Sat Jun 5 13:05:23 2021" "
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64]
+ "AF_UNIX" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mswsock.dll" "Sat Jun 5 13:05:23 2021" "
+ "Hyper-V RAW" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mswsock.dll" "Sat Jun 5 13:05:23 2021" "
+ "MSAFD L2CAP [Bluetooth]" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mswsock.dll" "Sat Jun 5 13:05:23 2021" "
+ "MSAFD RfComm [Bluetooth]" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mswsock.dll" "Sat Jun 5 13:05:23 2021" "
+ "MSAFD Tcpip [RAW/IP]" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mswsock.dll" "Sat Jun 5 13:05:23 2021" "
+ "MSAFD Tcpip [RAW/IPv6]" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mswsock.dll" "Sat Jun 5 13:05:23 2021" "
+ "MSAFD Tcpip [TCP/IP]" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mswsock.dll" "Sat Jun 5 13:05:23 2021" "
+ "MSAFD Tcpip [TCP/IPv6]" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mswsock.dll" "Sat Jun 5 13:05:23 2021" "
+ "MSAFD Tcpip [UDP/IP]" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mswsock.dll" "Sat Jun 5 13:05:23 2021" "
+ "MSAFD Tcpip [UDP/IPv6]" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mswsock.dll" "Sat Jun 5 13:05:23 2021" "
+ "RSVP TCP Service Provider" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mswsock.dll" "Sat Jun 5 13:05:23 2021" "
+ "RSVP TCPv6 Service Provider" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mswsock.dll" "Sat Jun 5 13:05:23 2021" "
+ "RSVP UDP Service Provider" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mswsock.dll" "Sat Jun 5 13:05:23 2021" "
+ "RSVP UDPv6 Service Provider" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\mswsock.dll" "Sat Jun 5 13:05:23 2021" "
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64]
+ "@%SystemRoot%\system32\nlasvc.dll,-1000" "NLA Namespace Service Provider DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\nlansp_c.dll" "Sat Jun 5 13:05:39 2021" "
+ "Bluetooth Namespace" "Windows Sockets Helper DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\wshbth.dll" "Thu Dec 16 07:53:06 2021" "
+ "E-mail Naming Shim Provider" "E-mail Naming Shim Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\napinsp.dll" "Sat Jun 5 13:05:27 2021" "
+ "NTDS" "LDAP RnR Provider DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\winrnr.dll" "Sat Jun 5 13:05:29 2021" "
+ "PNRP Cloud Namespace Provider" "PNRP Name Space Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\pnrpnsp.dll" "Sat Jun 5 13:06:16 2021" "
+ "PNRP Name Namespace Provider" "PNRP Name Space Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\pnrpnsp.dll" "Sat Jun 5 13:06:16 2021" "
+ "Tcpip" "Microsoft Windows Sockets 2.0 Service Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\mswsock.dll" "Sat Jun 5 13:05:23 2021" "
[Print Monitors]
[HKLM\System\CurrentControlSet\Control\Print\Monitors]
+ "Appmon" "App Printer" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\AppMon.dll" "Sat Jun 5 13:06:16 2021" "
+ "Local Port" "Local Spooler DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\localspl.dll" "Thu Dec 16 07:51:44 2021" "
+ "Microsoft Shared Fax Monitor" "Microsoft Fax Print Monitor" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\FXSMON.DLL" "Sat Jun 5 02:37:00 2021" "
+ "Standard TCP/IP Port" "Standard TCP/IP Port Monitor DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\tcpmon.dll" "Sat Jun 5 13:05:39 2021" "
+ "USB Monitor" "Standard Dynamic Printing Port Monitor DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\usbmon.dll" "Thu Dec 16 07:51:54 2021" "
+ "WSD Port" "Adaptive Port Monitor" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\APMon.dll" "Thu Dec 16 07:54:54 2021" "
[HKLM\System\CurrentControlSet\Control\Print\Providers]
+ "HTTP Print Services" "Internet Print Provider DLL" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\inetpp.dll" "Thu Dec 16 07:56:55 2021" "
+ "LanMan Print Services" "Client Side Rendering Print Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\win32spl.dll" "Thu Dec 16 07:51:44 2021" "
[LSA Providers]
[HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\SecurityProviders]
+ "credssp.dll" "Credential Delegation Security Package" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\credssp.dll" "Thu Dec 16 07:54:57 2021" "
[HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Authentication Packages]
+ "msv1_0" "Microsoft Authentication Package v1.0" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\msv1_0.dll" "Thu Dec 16 07:53:45 2021" "
[HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Notification Packages]
+ "scecli" "Windows Security Configuration Editor Client Engine" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\scecli.dll" "Sat Jun 5 13:05:40 2021" "
[HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Security Packages]
[HKLM\SYSTEM\CurrentControlSet\Control\Lsa\OSConfig\Security Packages]
[Network Providers]
[HKLM\SYSTEM\CurrentControlSet\Control\NetworkProvider\Order]
+ "LanmanWorkstation" "Microsoft Windows Network" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\ntlanman.dll" "Thu Dec 16 07:53:53 2021" "
+ "P9NP" "Plan 9 Network Provider" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\p9np.dll" "Sat Jun 5 13:06:17 2021" "
+ "RDPNP" "Microsoft Terminal Services" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\drprov.dll" "Sat Jun 5 13:06:14 2021" "
+ "webclient" "Web Client Network" "(Verified) Microsoft Windows" "C:\WINDOWS\System32\davclnt.dll" "Sat Jun 5 13:06:17 2021" "
[WMI]
[WMI Database Entries - run as Administrator for complete scan]
[Office]
[HKCU\Software\Microsoft\Office\Outlook\Addins]
[HKCU\Software\Microsoft\Office\Excel\Addins]
[HKCU\Software\Microsoft\Office\PowerPoint\Addins]
[HKCU\Software\Microsoft\Office\Word\Addins]
[HKCU\Software\Microsoft\Office\Access\Addins]
[HKCU\Software\Microsoft\Office\OneNote\Addins]
[HKCU\SOFTWARE\Microsoft\Office test\Special\Perf\(Default)]
[HKCU\Software\Wow6432Node\Microsoft\Office\Outlook\Addins]
[HKCU\Software\Wow6432Node\Microsoft\Office\Excel\Addins]
[HKCU\Software\Wow6432Node\Microsoft\Office\PowerPoint\Addins]
[HKCU\Software\Wow6432Node\Microsoft\Office\Word\Addins]
[HKCU\Software\Wow6432Node\Microsoft\Office\Access\Addins]
[HKCU\Software\Wow6432Node\Microsoft\Office\OneNote\Addins]
[HKCU\SOFTWARE\Wow6432Node\Microsoft\Office test\Special\Perf\(Default)]
[HKLM\Software\Microsoft\Office\Outlook\Addins]
[HKLM\Software\Microsoft\Office\Excel\Addins]
[HKLM\Software\Microsoft\Office\PowerPoint\Addins]
[HKLM\Software\Microsoft\Office\Word\Addins]
[HKLM\Software\Microsoft\Office\Access\Addins]
[HKLM\Software\Microsoft\Office\OneNote\Addins]
[HKLM\SOFTWARE\Microsoft\Office test\Special\Perf\(Default)]
[HKLM\Software\Wow6432Node\Microsoft\Office\Outlook\Addins]
[HKLM\Software\Wow6432Node\Microsoft\Office\Excel\Addins]
[HKLM\Software\Wow6432Node\Microsoft\Office\PowerPoint\Addins]
[HKLM\Software\Wow6432Node\Microsoft\Office\Word\Addins]
[HKLM\Software\Wow6432Node\Microsoft\Office\Access\Addins]
[HKLM\Software\Wow6432Node\Microsoft\Office\OneNote\Addins]
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Office test\Special\Perf\(Default)]
 
You have still not provided the information as it has been requested which as previously mentioned makes life more difficult, should we need an another AutoRuns log, hide the Microsoft results, save the File as Text and attach that file to your reply, copy/pasting a whole load of needless info helps neither of us.

Can you post a new Speccy url for us.
 
You have still not provided the information as it has been requested which as previously mentioned makes life more difficult, should we need an another AutoRuns log, hide the Microsoft results, save the File as Text and attach that file to your reply, copy/pasting a whole load of needless info helps neither of us.

Can you post a new Speccy url for us.
Hi
I have followed the Autoruns tutorial, hidden the Microsoft results each time but it still saves this to the text doc , see screen shot below am I missing something?? Here is the new Speccy snapshot too :) http://speccy.piriform.com/results/8nRZgZ2HS0zC60loDy3P4Ts
1640197399976.png
 
Norton is still there :(
 

Attachments

  • Autoruns steps (2018_02_02 10_53_58 UTC).jpg
    Autoruns steps (2018_02_02 10_53_58 UTC).jpg
    169.3 KB · Views: 64
Okay, I have managed to get rid of all Norton entries, I have saved a snapshot again as you have described , please see below :)
 

Attachments

Great and that log was so much easier to check (y)

No signs of any Norton or Iobit garbage but have you restarted to see how the computer behaves now.
 
Status
Not open for further replies.