Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- FRST TXT:
- Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 28-05-2017
- Ran by Cory Smith (administrator) on DESKTOP-GU6TEMK (29-05-2017 14:53:16)
- Running from C:\Users\Cory Smith\Downloads
- Loaded Profiles: Cory Smith (Available Profiles: Cory Smith)
- Platform: Windows 10 Home Version 1703 (X64) Language: English (United Kingdom)
- Internet Explorer Version 11 (Default browser: Edge)
- Boot Mode: Normal
- Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
- ==================== Processes (Whitelisted) =================
- (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
- (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\tbaseprovisioning.exe
- (Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
- (Reimage®) C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe
- (Megaify Software Co., Ltd.) C:\Program Files (x86)\DriverToolkit\DriverToolkit.exe
- (Reimage®) C:\Program Files\Reimage\Reimage Protector\ReiSystem.exe
- (Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
- (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
- (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
- (Micro-Star INT'L CO., LTD.) C:\MSI\MSIRegister\MSIRegister.exe
- (Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
- (Microsoft Corporation) C:\Windows\System32\browser_broker.exe
- (Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
- (Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
- (Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
- (Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
- (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
- (Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\SecHealthUI.exe
- (Microsoft Corporation) C:\Windows\System32\dllhost.exe
- (Microsoft Corporation) C:\Windows\System32\smartscreen.exe
- (Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
- (Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
- (Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
- (Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
- (Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe
- ==================== Registry (Whitelisted) ====================
- (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
- HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [629152 2017-03-18] (Microsoft Corporation)
- HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2585744 2015-03-13] (NVIDIA Corporation)
- HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
- HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [9198592 2017-02-10] (Realtek Semiconductor)
- HKLM-x32\...\Run: [MSIRegister] => C:\MSI\MSIRegister\MSIRegister.exe [1258448 2016-11-09] (Micro-Star INT'L CO., LTD.)
- HKU\S-1-5-21-3729940396-3466973117-3832101617-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3019552 2017-04-26] (Valve Corporation)
- HKU\S-1-5-21-3729940396-3466973117-3832101617-1001\...\MountPoints2: {68d6cd8e-4312-11e7-a2a2-806e6f6e6963} - "E:\DVDSetup.exe"
- ==================== Internet (Whitelisted) ====================
- (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
- Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
- Tcpip\..\Interfaces\{8e718f8d-bb18-4e6e-822f-2282f5ca7ca0}: [DhcpNameServer] 192.168.1.1
- Tcpip\..\Interfaces\{f9eb04e3-132c-4eb8-9fed-af41e4fe0996}: [DhcpNameServer] 192.168.1.1
- Internet Explorer:
- ==================
- FireFox:
- ========
- FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2017-02-23] (NVIDIA Corporation)
- FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2017-02-23] (NVIDIA Corporation)
- FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-05-28] (Google Inc.)
- FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-05-28] (Google Inc.)
- Chrome:
- =======
- CHR Profile: C:\Users\Cory Smith\AppData\Local\Google\Chrome\User Data\Default [2017-05-28]
- CHR Extension: (Google Docs) - C:\Users\Cory Smith\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-05-28]
- CHR Extension: (Google Drive) - C:\Users\Cory Smith\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-05-28]
- CHR Extension: (YouTube) - C:\Users\Cory Smith\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-05-28]
- CHR Extension: (Google Docs Offline) - C:\Users\Cory Smith\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-05-28]
- CHR Extension: (Chrome Web Store Payments) - C:\Users\Cory Smith\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-05-28]
- CHR Extension: (Gmail) - C:\Users\Cory Smith\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-05-28]
- ==================== Services (Whitelisted) ====================
- (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
- S3 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1148560 2015-03-13] (NVIDIA Corporation)
- S3 MSIREGISTER_MR; C:\MSI\MSIRegister\MSIRegisterService.exe [132048 2016-10-07] (Micro-Star INT'L CO., LTD.)
- S3 NVDisplay.ContainerLocalSystem; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [462784 2017-02-23] (NVIDIA Corporation)
- R3 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1706128 2015-03-13] (NVIDIA Corporation)
- S3 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [21833360 2015-03-13] (NVIDIA Corporation)
- R2 ReimageRealTimeProtector; C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe [8515952 2017-05-14] (Reimage®)
- R2 tbaseprovisioning; C:\Windows\SysWOW64\tbaseprovisioning.exe [51208 2017-01-09] (Advanced Micro Devices, Inc.)
- S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [342264 2017-03-18] (Microsoft Corporation)
- R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [102816 2017-03-18] (Microsoft Corporation)
- ===================== Drivers (Whitelisted) ======================
- (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
- R3 amdgpio2; C:\Windows\System32\drivers\amdgpio2.sys [43400 2017-03-01] (Advanced Micro Devices, Inc)
- R3 amdgpio3; C:\Windows\System32\drivers\amdgpio3.sys [24424 2016-08-12] (Advanced Micro Devices, Inc)
- S3 amdkmcsp; C:\Windows\system32\DRIVERS\amdkmcsp.sys [100744 2017-01-09] (Advanced Micro Devices, Inc. )
- R0 amdpsp; C:\Windows\System32\DRIVERS\amdpsp.sys [255368 2017-01-09] (Advanced Micro Devices, Inc. )
- S3 NTIOLib_1_0_C; E:\NTIOLib_X64.sys [11888 2011-06-29] (MSI) [File not signed]
- R3 nvlddmkm; C:\Windows\System32\DriverStore\FileRepository\nv_dispiwu.inf_amd64_e619501ce2023445\nvlddmkm.sys [14569520 2017-03-23] (NVIDIA Corporation)
- S3 NVVADARM; C:\Windows\system32\drivers\nvvadarm.sys [40136 2015-03-13] (NVIDIA Corporation)
- R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [38032 2015-03-13] (NVIDIA Corporation)
- R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [943112 2016-08-22] (Realtek )
- R3 RtlWlanu_OldIC; C:\Windows\System32\drivers\rtwlanu_oldIC.sys [3814400 2017-03-18] (Realtek Semiconductor Corporation )
- S3 SDFRd; C:\Windows\System32\drivers\SDFRd.sys [31128 2017-03-18] ()
- S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44632 2017-03-18] (Microsoft Corporation)
- R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [294816 2017-03-18] (Microsoft Corporation)
- S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [121248 2017-03-18] (Microsoft Corporation)
- S3 NAVENG; \??\C:\Program Files (x86)\Norton Security\NortonData\22.7.0.76\Definitions\SDSDefs\20170527.002\ENG64.SYS [X]
- S3 NAVEX15; \??\C:\Program Files (x86)\Norton Security\NortonData\22.7.0.76\Definitions\SDSDefs\20170527.002\EX64.SYS [X]
- ==================== NetSvcs (Whitelisted) ===================
- (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
- ==================== One Month Created files and folders ========
- (If an entry is included in the fixlist, the file/folder will be moved.)
- 2017-05-29 14:53 - 2017-05-29 14:53 - 00009377 _____ C:\Users\Cory Smith\Downloads\FRST.txt
- 2017-05-29 14:52 - 2017-05-29 14:53 - 00000000 ____D C:\FRST
- 2017-05-29 14:51 - 2017-05-29 14:51 - 02429952 _____ (Farbar) C:\Users\Cory Smith\Downloads\FRST64.exe
- 2017-05-29 14:45 - 2017-05-29 14:50 - 00003808 _____ C:\Windows\System32\Tasks\AutoKMS
- 2017-05-29 14:45 - 2017-05-29 14:49 - 00000000 ____D C:\Windows\AutoKMS
- 2017-05-29 14:44 - 2017-05-29 14:44 - 00000000 ____D C:\ProgramData\Microsoft Toolkit
- 2017-05-29 14:26 - 2017-05-29 14:31 - 55165315 _____ C:\Users\Cory Smith\Downloads\mstoolkit.zip
- 2017-05-29 14:16 - 2017-05-29 14:16 - 00000000 ____D C:\Users\Cory Smith\Documents\FeedbackHub
- 2017-05-28 21:05 - 2017-05-28 21:05 - 00004362 _____ C:\Windows\System32\Tasks\ReimageUpdater
- 2017-05-28 21:05 - 2017-05-28 21:05 - 00003568 _____ C:\Windows\System32\Tasks\Reimage Reminder
- 2017-05-28 21:04 - 2017-05-28 21:05 - 00000000 ____D C:\rei
- 2017-05-28 21:04 - 2017-05-28 21:05 - 00000000 ____D C:\ProgramData\Reimage Protector
- 2017-05-28 21:04 - 2017-05-28 21:05 - 00000000 ____D C:\Program Files\Reimage
- 2017-05-28 21:04 - 2017-05-28 21:04 - 00001984 _____ C:\Users\Public\Desktop\PC Scan & Repair by Reimage.lnk
- 2017-05-28 21:04 - 2017-05-28 21:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Reimage Repair
- 2017-05-28 21:03 - 2017-05-28 21:05 - 00000140 _____ C:\Windows\Reimage.ini
- 2017-05-28 20:26 - 2017-05-28 20:26 - 00000000 ____D C:\Windows\LastGood
- 2017-05-28 19:55 - 2017-05-28 19:55 - 00000222 _____ C:\Users\Cory Smith\Desktop\Arma 3.url
- 2017-05-28 19:49 - 2017-05-28 19:49 - 00000000 ____D C:\Users\Cory Smith\AppData\Local\Steam
- 2017-05-28 19:49 - 2017-05-28 19:49 - 00000000 ____D C:\Users\Cory Smith\AppData\Local\CEF
- 2017-05-28 19:39 - 2017-05-28 19:39 - 00000000 ____D C:\Users\Cory Smith\AppData\Roaming\Macromedia
- 2017-05-28 19:38 - 2017-05-29 14:52 - 00000000 ____D C:\Program Files (x86)\Steam
- 2017-05-28 19:38 - 2017-05-28 19:38 - 00001036 _____ C:\Users\Public\Desktop\Steam.lnk
- 2017-05-28 19:38 - 2017-05-28 19:38 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
- 2017-05-28 19:37 - 2017-05-28 19:37 - 01446792 _____ C:\Users\Cory Smith\Downloads\SteamSetup.exe
- 2017-05-28 18:27 - 2017-05-29 14:41 - 00000000 ____D C:\Windows\System32\Tasks\Remediation
- 2017-05-28 18:27 - 2017-05-28 18:27 - 00000000 ____D C:\Program Files\Common Files\AV
- 2017-05-28 17:52 - 2017-05-28 17:52 - 00000000 ____D C:\Program Files (x86)\VulkanRT
- 2017-05-28 17:52 - 2017-02-23 09:28 - 00548288 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshext.dll
- 2017-05-28 17:52 - 2017-02-23 09:28 - 00083512 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshextr.dll
- 2017-05-28 17:52 - 2017-02-23 09:17 - 00136064 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe
- 2017-05-28 17:52 - 2017-01-26 01:13 - 00103936 _____ C:\Windows\SysWOW64\vulkaninfo.exe
- 2017-05-28 17:52 - 2017-01-26 01:12 - 00326656 _____ C:\Windows\SysWOW64\vulkan-1.dll
- 2017-05-28 17:52 - 2017-01-26 01:09 - 00322560 _____ C:\Windows\system32\vulkan-1.dll
- 2017-05-28 17:52 - 2017-01-26 01:09 - 00118272 _____ C:\Windows\system32\vulkaninfo.exe
- 2017-05-28 17:51 - 2017-02-23 09:43 - 00001951 _____ C:\Windows\NvContainerRecovery.bat
- 2017-05-28 17:50 - 2017-05-28 17:52 - 00000000 ____D C:\Windows\LastGood.Tmp
- 2017-05-28 17:45 - 2017-05-28 17:45 - 00000000 ____D C:\Users\Cory Smith\AppData\Local\Google
- 2017-05-28 17:44 - 2017-05-29 14:49 - 00000000 ____D C:\ProgramData\Norton
- 2017-05-28 17:44 - 2017-05-29 14:49 - 00000000 ____D C:\Program Files (x86)\Norton Security
- 2017-05-28 17:44 - 2017-05-29 14:06 - 00002272 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
- 2017-05-28 17:44 - 2017-05-29 14:06 - 00002260 _____ C:\Users\Public\Desktop\Google Chrome.lnk
- 2017-05-28 17:44 - 2017-05-28 17:44 - 00000000 ____D C:\ProgramData\NortonInstaller
- 2017-05-28 17:43 - 2017-05-28 17:50 - 00003416 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
- 2017-05-28 17:43 - 2017-05-28 17:50 - 00003292 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
- 2017-05-28 17:43 - 2017-05-28 17:43 - 00000000 ____D C:\Program Files (x86)\Google
- 2017-05-28 17:25 - 2017-05-28 17:25 - 00007606 _____ C:\Users\Cory Smith\AppData\Local\Resmon.ResmonCfg
- 2017-05-28 17:18 - 2017-05-28 16:09 - 00532136 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
- 2017-05-28 16:38 - 2017-05-28 16:38 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
- 2017-05-28 16:38 - 2017-05-28 16:38 - 00000000 ____D C:\Program Files\7-Zip
- 2017-05-28 16:32 - 2017-05-28 16:32 - 00002705 _____ C:\Users\Cory Smith\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk
- 2017-05-28 16:31 - 2017-05-28 17:36 - 00000000 ____D C:\Users\Cory Smith\AppData\Roaming\uTorrent
- 2017-05-28 16:30 - 2017-05-28 16:31 - 02240192 _____ (BitTorrent Inc.) C:\Users\Cory Smith\Downloads\uTorrent.exe
- 2017-05-28 16:28 - 2017-05-28 16:28 - 00201030 _____ C:\Users\Cory Smith\Downloads\lspfix.zip
- 2017-05-28 11:08 - 2017-05-28 11:08 - 00000000 ____H C:\ProgramData\DP45977C.lfl
- 2017-05-28 11:08 - 2017-05-28 11:08 - 00000000 ____D C:\Windows\SysWOW64\RTCOM
- 2017-05-28 11:08 - 2017-05-28 11:08 - 00000000 ____D C:\Windows\system32\DAX3
- 2017-05-28 11:08 - 2017-05-28 11:08 - 00000000 ____D C:\Windows\system32\DAX2
- 2017-05-28 11:08 - 2017-05-28 11:08 - 00000000 ____D C:\ProgramData\Audyssey Labs
- 2017-05-28 11:08 - 2017-05-28 11:08 - 00000000 ____D C:\Program Files\Realtek
- 2017-05-28 11:07 - 2017-02-10 05:53 - 72520712 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RCoRes64.dat
- 2017-05-28 11:07 - 2017-02-10 05:53 - 15202032 _____ (Yamaha Corporation) C:\Windows\system32\YamahaAE3.dll
- 2017-05-28 11:07 - 2017-02-10 05:53 - 10283532 _____ C:\Windows\system32\Drivers\RTAIODAT.DAT
- 2017-05-28 11:07 - 2017-02-10 05:53 - 05804772 _____ C:\Windows\system32\Drivers\rtvienna.dat
- 2017-05-28 11:07 - 2017-02-10 05:53 - 05611520 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\Drivers\RTKVHD64.sys
- 2017-05-28 11:07 - 2017-02-10 05:53 - 03503040 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkApi64.dll
- 2017-05-28 11:07 - 2017-02-10 05:53 - 03410832 _____ (DTS, Inc.) C:\Windows\system32\slcnt64.dll
- 2017-05-28 11:07 - 2017-02-10 05:53 - 03299816 _____ (Yamaha Corporation) C:\Windows\system32\YamahaAE2.dll
- 2017-05-28 11:07 - 2017-02-10 05:53 - 03203584 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtPgEx64.dll
- 2017-05-28 11:07 - 2017-02-10 05:53 - 03203416 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RltkAPO64.dll
- 2017-05-28 11:07 - 2017-02-10 05:53 - 03122648 _____ (DTS, Inc.) C:\Windows\system32\sltech64.dll
- 2017-05-28 11:07 - 2017-02-10 05:53 - 03014656 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTSnMg64.cpl
- 2017-05-28 11:07 - 2017-02-10 05:53 - 02830480 _____ (Realtek Semiconductor Corp.) C:\Windows\SysWOW64\RltkAPO.dll
- 2017-05-28 11:07 - 2017-02-10 05:53 - 02202624 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RCoInstII64.dll
- 2017-05-28 11:07 - 2017-02-10 05:53 - 02190976 _____ (Yamaha Corporation) C:\Windows\system32\YamahaAE.dll
- 2017-05-28 11:07 - 2017-02-10 05:53 - 01435136 _____ (Synopsys, Inc.) C:\Windows\system32\SRRPTR64.dll
- 2017-05-28 11:07 - 2017-02-10 05:53 - 01382232 _____ (TOSHIBA Corporation) C:\Windows\system32\tosade.dll
- 2017-05-28 11:07 - 2017-02-10 05:53 - 01353816 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTCOM64.dll
- 2017-05-28 11:07 - 2017-02-10 05:53 - 01337632 _____ (Toshiba Client Solutions Co., Ltd.) C:\Windows\system32\tossaeapo64.dll
- 2017-05-28 11:07 - 2017-02-10 05:53 - 01003512 _____ (Sound Research, Corp.) C:\Windows\system32\SEHDHF64.dll
- 2017-05-28 11:07 - 2017-02-10 05:53 - 00984904 _____ (DTS, Inc.) C:\Windows\system32\sl3apo64.dll
- 2017-05-28 11:07 - 2017-02-10 05:53 - 00965016 _____ (Sony Corporation) C:\Windows\system32\SFSS_APO.dll
- 2017-05-28 11:07 - 2017-02-10 05:53 - 00962120 _____ (Toshiba Client Solutions Co., Ltd.) C:\Windows\system32\tosasfapo64.dll
- 2017-05-28 11:07 - 2017-02-10 05:53 - 00873464 _____ (TOSHIBA Corporation) C:\Windows\system32\tadefxapo264.dll
- 2017-05-28 11:07 - 2017-02-10 05:53 - 00866096 _____ (Sound Research, Corp.) C:\Windows\SysWOW64\SEHDHF32.dll
- 2017-05-28 11:07 - 2017-02-10 05:53 - 00859912 _____ (Sound Research, Corp.) C:\Windows\system32\SEHDRA64.dll
- 2017-05-28 11:07 - 2017-02-10 05:53 - 00856296 _____ (Sound Research, Corp.) C:\Windows\system32\SECOMN64.dll
- 2017-05-28 11:07 - 2017-02-10 05:53 - 00726632 _____ (Sound Research, Corp.) C:\Windows\SysWOW64\SECOMN32.dll
- 2017-05-28 11:07 - 2017-02-10 05:53 - 00689872 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtDataProc64.dll
- 2017-05-28 11:07 - 2017-02-10 05:53 - 00601144 _____ (Toshiba Client Solutions Co., Ltd.) C:\Windows\system32\tossaemaxapo64.dll
- 2017-05-28 11:07 - 2017-02-10 05:53 - 00532376 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSTSX64.dll
- 2017-05-28 11:07 - 2017-02-10 05:53 - 00518528 _____ (Sound Research, Corp.) C:\Windows\system32\SEAPO64.dll
- 2017-05-28 11:07 - 2017-02-10 05:53 - 00467152 _____ (Synopsys, Inc.) C:\Windows\system32\SRAPO64.dll
- 2017-05-28 11:07 - 2017-02-10 05:53 - 00447176 _____ (Toshiba Client Solutions Co., Ltd.) C:\Windows\system32\toseaeapo64.dll
- 2017-05-28 11:07 - 2017-02-10 05:53 - 00387312 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEP64A.dll
- 2017-05-28 11:07 - 2017-02-10 05:53 - 00381400 _____ (Synopsys, Inc.) C:\Windows\system32\SRCOM64.dll
- 2017-05-28 11:07 - 2017-02-10 05:53 - 00343704 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtlCPAPI64.dll
- 2017-05-28 11:07 - 2017-02-10 05:53 - 00341144 _____ (Synopsys, Inc.) C:\Windows\SysWOW64\SRCOM.dll
- 2017-05-28 11:07 - 2017-02-10 05:53 - 00341144 _____ (Synopsys, Inc.) C:\Windows\system32\SRCOM.dll
- 2017-05-28 11:07 - 2017-02-10 05:53 - 00321712 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DHT64.dll
- 2017-05-28 11:07 - 2017-02-10 05:53 - 00321712 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DAA64.dll
- 2017-05-28 11:07 - 2017-02-10 05:53 - 00258856 _____ (TODO: <Company name>) C:\Windows\system32\slprp64.dll
- 2017-05-28 11:07 - 2017-02-10 05:53 - 00231912 _____ (Synopsys, Inc.) C:\Windows\system32\SFNHK64.dll
- 2017-05-28 11:07 - 2017-02-10 05:53 - 00221968 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSTSH64.dll
- 2017-05-28 11:07 - 2017-02-10 05:53 - 00214824 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEED64A.dll
- 2017-05-28 11:07 - 2017-02-10 05:53 - 00209536 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSHP64.dll
- 2017-05-28 11:07 - 2017-02-10 05:53 - 00192976 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCfg64.dll
- 2017-05-28 11:07 - 2017-02-10 05:53 - 00166200 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSWOW64.dll
- 2017-05-28 11:07 - 2017-02-10 05:53 - 00158688 _____ (TOSHIBA Corporation) C:\Windows\system32\tadefxapo.dll
- 2017-05-28 11:07 - 2017-02-10 05:53 - 00110976 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEL64A.dll
- 2017-05-28 11:07 - 2017-02-10 05:53 - 00105304 _____ C:\Windows\system32\audioLibVc.dll
- 2017-05-28 11:07 - 2017-02-10 05:53 - 00090912 _____ (Synopsys, Inc.) C:\Windows\system32\SFCOM64.dll
- 2017-05-28 11:07 - 2017-02-10 05:53 - 00088344 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEG64A.dll
- 2017-05-28 11:07 - 2017-02-10 05:53 - 00088320 _____ (Synopsys, Inc.) C:\Windows\system32\SFAPO64.dll
- 2017-05-28 11:07 - 2017-02-10 05:53 - 00083616 _____ (Virage Logic Corporation / Sonic Focus) C:\Windows\SysWOW64\SFCOM.dll
- 2017-05-28 11:07 - 2017-02-10 05:53 - 00075536 _____ (TOSHIBA CORPORATION.) C:\Windows\system32\tepeqapo64.dll
- 2017-05-28 11:07 - 2017-02-10 05:53 - 00023688 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCoLDR64.dll
- 2017-05-28 11:06 - 2017-05-28 11:08 - 00000000 ___HD C:\Program Files (x86)\Temp
- 2017-05-28 11:06 - 2017-02-10 05:53 - 07172912 _____ (Dolby Laboratories) C:\Windows\system32\R4EEP64A.dll
- 2017-05-28 11:06 - 2017-02-10 05:53 - 07096184 _____ (Dolby Laboratories) C:\Windows\system32\DDPP64A.dll
- 2017-05-28 11:06 - 2017-02-10 05:53 - 06264632 _____ (Dolby Laboratories) C:\Windows\system32\DDPP64AF3.dll
- 2017-05-28 11:06 - 2017-02-10 05:53 - 05347000 _____ (Dolby Laboratories) C:\Windows\system32\DolbyDAX2APOv211.dll
- 2017-05-28 11:06 - 2017-02-10 05:53 - 02993712 _____ (Audyssey Labs) C:\Windows\system32\AudysseyEfx.dll
- 2017-05-28 11:06 - 2017-02-10 05:53 - 02444688 _____ (Dolby Laboratories) C:\Windows\system32\DolbyDAX2APOv201.dll
- 2017-05-28 11:06 - 2017-02-10 05:53 - 01965808 _____ (Dolby Laboratories) C:\Windows\system32\DDPD64A.dll
- 2017-05-28 11:06 - 2017-02-10 05:53 - 01959600 _____ (Dolby Laboratories) C:\Windows\system32\DDPD64AF3.dll
- 2017-05-28 11:06 - 2017-02-10 05:53 - 01780616 _____ (DTS) C:\Windows\system32\DTSS2SpeakerDLL64.dll
- 2017-05-28 11:06 - 2017-02-10 05:53 - 01591056 _____ (DTS) C:\Windows\system32\DTSS2HeadphoneDLL64.dll
- 2017-05-28 11:06 - 2017-02-10 05:53 - 01516896 _____ (Dolby Laboratories) C:\Windows\system32\DAX3APOProp.dll
- 2017-05-28 11:06 - 2017-02-10 05:53 - 01508928 _____ (DTS) C:\Windows\system32\DTSBoostDLL64.dll
- 2017-05-28 11:06 - 2017-02-10 05:53 - 01363096 _____ (Dolby Laboratories) C:\Windows\system32\DAX3APOv251.dll
- 2017-05-28 11:06 - 2017-02-10 05:53 - 01133584 _____ (Dolby Laboratories) C:\Windows\system32\DolbyDAX2APOProp.dll
- 2017-05-28 11:06 - 2017-02-10 05:53 - 00785608 _____ (Dolby Laboratories) C:\Windows\system32\DolbyDAX2APOvlldp.dll
- 2017-05-28 11:06 - 2017-02-10 05:53 - 00743960 _____ (DTS) C:\Windows\system32\DTSBassEnhancementDLL64.dll
- 2017-05-28 11:06 - 2017-02-10 05:53 - 00727432 _____ (DTS) C:\Windows\system32\DTSSymmetryDLL64.dll
- 2017-05-28 11:06 - 2017-02-10 05:53 - 00708304 _____ (DTS) C:\Windows\system32\DTSVoiceClarityDLL64.dll
- 2017-05-28 11:06 - 2017-02-10 05:53 - 00680504 _____ (ICEpower a/s) C:\Windows\system32\ICEsoundAPO64.dll
- 2017-05-28 11:06 - 2017-02-10 05:53 - 00504304 _____ (DTS) C:\Windows\system32\DTSNeoPCDLL64.dll
- 2017-05-28 11:06 - 2017-02-10 05:53 - 00447712 _____ (Dolby Laboratories) C:\Windows\system32\R4EED64A.dll
- 2017-05-28 11:06 - 2017-02-10 05:53 - 00445400 _____ (DTS) C:\Windows\system32\DTSLimiterDLL64.dll
- 2017-05-28 11:06 - 2017-02-10 05:53 - 00441264 _____ (DTS) C:\Windows\system32\DTSGainCompensatorDLL64.dll
- 2017-05-28 11:06 - 2017-02-10 05:53 - 00426560 _____ (Dolby Laboratories) C:\Windows\system32\HiFiDAX2APIPCLL.dll
- 2017-05-28 11:06 - 2017-02-10 05:53 - 00416504 _____ (Harman) C:\Windows\system32\HMUI.dll
- 2017-05-28 11:06 - 2017-02-10 05:53 - 00378384 _____ (Dolby Laboratories) C:\Windows\system32\HiFiDAX2API.dll
- 2017-05-28 11:06 - 2017-02-10 05:53 - 00366112 _____ (Windows (R) Win 7 DDK provider) C:\Windows\system32\HMAPO.dll
- 2017-05-28 11:06 - 2017-02-10 05:53 - 00362048 _____ (Dolby Laboratories) C:\Windows\system32\DDPO64AF3.dll
- 2017-05-28 11:06 - 2017-02-10 05:53 - 00360336 _____ (Harman) C:\Windows\system32\HMClariFi.dll
- 2017-05-28 11:06 - 2017-02-10 05:53 - 00327456 _____ (Dolby Laboratories) C:\Windows\system32\DDPO64A.dll
- 2017-05-28 11:06 - 2017-02-10 05:53 - 00310416 _____ (Dolby Laboratories) C:\Windows\system32\DDPA64F3.dll
- 2017-05-28 11:06 - 2017-02-10 05:53 - 00272712 _____ (Dolby Laboratories) C:\Windows\system32\DDPA64.dll
- 2017-05-28 11:06 - 2017-02-10 05:53 - 00253896 _____ (DTS) C:\Windows\system32\DTSGFXAPO64.dll
- 2017-05-28 11:06 - 2017-02-10 05:53 - 00253864 _____ (DTS) C:\Windows\system32\DTSLFXAPO64.dll
- 2017-05-28 11:06 - 2017-02-10 05:53 - 00252872 _____ (DTS) C:\Windows\system32\DTSGFXAPONS64.dll
- 2017-05-28 11:06 - 2017-02-10 05:53 - 00203832 _____ (Harman) C:\Windows\system32\HMHVS.dll
- 2017-05-28 11:06 - 2017-02-10 05:53 - 00190928 _____ (Harman) C:\Windows\system32\HMEQ_Voice.dll
- 2017-05-28 11:06 - 2017-02-10 05:53 - 00190928 _____ (Harman) C:\Windows\system32\HMEQ.dll
- 2017-05-28 11:06 - 2017-02-10 05:53 - 00179592 _____ (Harman) C:\Windows\system32\HMLimiter.dll
- 2017-05-28 11:06 - 2017-02-10 05:53 - 00154360 _____ (Harman) C:\Windows\system32\HarmanAudioInterface.dll
- 2017-05-28 11:06 - 2017-02-10 05:53 - 00151784 _____ (Dolby Laboratories) C:\Windows\system32\R4EEL64A.dll
- 2017-05-28 11:06 - 2017-02-10 05:53 - 00134192 _____ (Dolby Laboratories) C:\Windows\system32\R4EEA64A.dll
- 2017-05-28 11:06 - 2017-02-10 05:53 - 00122320 _____ (Real Sound Lab SIA) C:\Windows\system32\CONEQMSAPOGUILibrary.dll
- 2017-05-28 11:06 - 2017-02-10 05:53 - 00118592 _____ C:\Windows\system32\AcpiServiceVnA64.dll
- 2017-05-28 11:06 - 2017-02-10 05:53 - 00084608 _____ (Dolby Laboratories) C:\Windows\system32\R4EEG64A.dll
- 2017-05-28 11:06 - 2016-09-22 07:55 - 02839520 ____R (Realtek Semiconductor Corp.) C:\Windows\RtlExUpd.dll
- 2017-05-28 11:04 - 2017-05-28 11:06 - 00000000 ____D C:\Program Files (x86)\Realtek
- 2017-05-28 11:04 - 2017-05-28 11:04 - 00000000 ____D C:\ProgramData\Package Cache
- 2017-05-28 11:04 - 2017-05-28 11:04 - 00000000 ____D C:\Program Files (x86)\ATI Technologies
- 2017-05-28 11:04 - 2016-08-22 21:19 - 00943112 _____ (Realtek ) C:\Windows\system32\Drivers\rt640x64.sys
- 2017-05-28 11:04 - 2016-08-22 21:19 - 00082544 _____ (Realtek Semiconductor Corporation) C:\Windows\system32\RtNicProp64.dll
- 2017-05-28 11:03 - 2017-05-28 11:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MSI
- 2017-05-28 11:03 - 2017-05-28 11:03 - 00000000 ____D C:\Program Files\AMD
- 2017-05-28 11:03 - 2017-05-28 11:03 - 00000000 ____D C:\MSI
- 2017-05-27 21:19 - 2017-05-29 14:49 - 00000400 _____ C:\Windows\Tasks\DriverToolkit Autorun.job
- 2017-05-27 21:19 - 2017-05-27 21:19 - 00002838 _____ C:\Windows\System32\Tasks\DriverToolkit Autorun
- 2017-05-27 21:11 - 2017-05-27 21:11 - 00001140 _____ C:\Users\Public\Desktop\DriverToolkit.lnk
- 2017-05-27 21:11 - 2017-05-27 21:11 - 00000000 ____D C:\Users\Cory Smith\AppData\Local\DriverToolkit
- 2017-05-27 21:11 - 2017-05-27 21:11 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DriverToolkit
- 2017-05-27 21:11 - 2017-05-27 21:11 - 00000000 ____D C:\Program Files (x86)\DriverToolkit
- 2017-05-27 21:02 - 2017-05-27 21:08 - 02458632 _____ (Megaify Software ) C:\Users\Cory Smith\Downloads\DriverToolkitInstaller.exe
- 2017-05-27 20:49 - 2017-05-27 20:49 - 00000000 ____D C:\Users\Cory Smith\AppData\Local\DBG
- 2017-05-27 20:46 - 2017-05-27 20:46 - 00000000 ____D C:\Users\Cory Smith\AppData\Local\NVIDIA Corporation
- 2017-05-27 20:45 - 2017-05-27 20:48 - 00000000 ____D C:\Users\Cory Smith\AppData\Local\NVIDIA
- 2017-05-27 20:45 - 2017-05-27 20:45 - 00001424 _____ C:\Users\Public\Desktop\GeForce Experience.lnk
- 2017-05-27 20:45 - 2017-05-27 20:45 - 00000000 ____D C:\Program Files (x86)\AGEIA Technologies
- 2017-05-27 20:45 - 2015-03-13 20:41 - 01756424 _____ (NVIDIA Corporation) C:\Windows\system32\nvspbridge64.dll
- 2017-05-27 20:45 - 2015-03-13 20:41 - 01514528 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll
- 2017-05-27 20:45 - 2015-03-13 20:41 - 01316184 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspbridge.dll
- 2017-05-27 20:45 - 2015-03-13 20:41 - 01278920 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll
- 2017-05-27 20:45 - 2010-05-26 11:41 - 02401112 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_43.dll
- 2017-05-27 20:45 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_43.dll
- 2017-05-27 20:45 - 2010-05-26 11:41 - 00511328 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_43.dll
- 2017-05-27 20:45 - 2010-05-26 11:41 - 00470880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_43.dll
- 2017-05-27 20:45 - 2010-05-26 11:41 - 00276832 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_43.dll
- 2017-05-27 20:45 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_43.dll
- 2017-05-27 20:44 - 2017-05-28 18:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
- 2017-05-27 20:44 - 2017-05-28 18:13 - 00000000 ____D C:\ProgramData\NVIDIA
- 2017-05-27 20:44 - 2017-02-23 09:28 - 06401984 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll
- 2017-05-27 20:44 - 2017-02-23 09:28 - 02479160 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll
- 2017-05-27 20:44 - 2017-02-23 09:28 - 01764408 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll
- 2017-05-27 20:44 - 2017-02-23 09:28 - 00392128 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll
- 2017-05-27 20:44 - 2017-02-23 09:28 - 00069568 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll
- 2017-05-27 20:44 - 2017-02-23 07:38 - 07807027 _____ C:\Windows\system32\nvcoproc.bin
- 2017-05-27 20:43 - 2017-05-28 17:52 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
- 2017-05-27 20:43 - 2017-05-28 17:51 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
- 2017-05-27 20:43 - 2017-03-23 15:44 - 00521656 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll
- 2017-05-27 20:43 - 2017-03-23 15:44 - 00427448 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
- 2017-05-27 20:43 - 2017-03-23 15:34 - 04122584 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll
- 2017-05-27 20:43 - 2017-03-23 12:15 - 00043566 _____ C:\Windows\system32\nvinfo.pb
- 2017-05-27 20:43 - 2015-03-13 20:41 - 18580512 ____N (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll
- 2017-05-27 20:43 - 2015-03-13 20:41 - 16022016 ____N (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
- 2017-05-27 20:43 - 2015-03-13 20:41 - 10262160 ____N (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
- 2017-05-27 20:43 - 2015-03-13 20:41 - 01896136 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6434788.dll
- 2017-05-27 20:43 - 2015-03-13 20:41 - 01557648 _____ (NVIDIA Corporation) C:\Windows\system32\nvmcvadgenco64.dll
- 2017-05-27 20:43 - 2015-03-13 20:41 - 01557648 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6434788.dll
- 2017-05-27 20:43 - 2015-03-13 20:41 - 00997856 ____N (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll
- 2017-05-27 20:43 - 2015-03-13 20:41 - 00101576 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcaparm.dll
- 2017-05-27 20:43 - 2015-03-13 20:41 - 00040136 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvadarm.sys
- 2017-05-27 20:43 - 2015-03-13 20:41 - 00038032 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys
- 2017-05-27 20:43 - 2015-03-13 20:41 - 00035472 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap64v.dll
- 2017-05-27 20:43 - 2015-03-13 20:41 - 00032400 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll
- 2017-05-27 20:42 - 2017-05-28 17:52 - 00000000 ____D C:\Program Files\NVIDIA Corporation
- 2017-05-27 20:41 - 2017-05-27 20:41 - 00000000 ____D C:\NVIDIA
- 2017-05-27 20:40 - 2017-05-27 20:40 - 00000000 ____D C:\Windows\tbaseregistry
- 2017-05-27 20:40 - 2017-03-18 21:56 - 00407552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEShims.dll
- 2017-05-27 20:26 - 2017-05-27 19:29 - 00000000 ____D C:\Windows\Panther
- 2017-05-27 19:56 - 2017-05-28 11:06 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
- 2017-05-27 19:56 - 2017-05-27 19:56 - 00000000 ____D C:\ProgramData\Ralink Driver
- 2017-05-27 19:56 - 2017-05-27 19:56 - 00000000 ____D C:\Program Files (x86)\Ralink
- 2017-05-27 19:56 - 2012-09-25 16:16 - 02042952 _____ (Ralink Technology, Corp.) C:\Windows\system32\Drivers\netr28x.sys
- 2017-05-27 19:56 - 2012-09-25 15:03 - 00327008 _____ (Ralink Technology, Inc.) C:\Windows\system32\RaCoInstx.dll
- 2017-05-27 19:56 - 2012-09-25 15:03 - 00014119 ____R C:\Windows\SysWOW64\RaCoInst.dat
- 2017-05-27 19:56 - 2012-09-25 15:03 - 00014119 ____R C:\Windows\system32\RaCoInst.dat
- 2017-05-27 19:56 - 2012-05-10 22:01 - 01503744 _____ (The OpenSSL Project, hxxp://www.openssl.org/) C:\Windows\system32\libeay32.dll
- 2017-05-27 19:56 - 2012-05-10 22:01 - 00308736 _____ (The OpenSSL Project, hxxp://www.openssl.org/) C:\Windows\system32\ssleay32.dll
- 2017-05-27 19:48 - 2017-05-27 19:48 - 00000000 ____D C:\ProgramData\USOShared
- 2017-05-27 19:45 - 2017-05-27 19:45 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_amdpsp_01011.Wdf
- 2017-05-27 19:42 - 2017-05-27 19:42 - 00003300 _____ C:\Windows\System32\Tasks\OneDrive Standalone Update Task v2
- 2017-05-27 19:42 - 2017-05-27 19:42 - 00002382 _____ C:\Users\Cory Smith\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
- 2017-05-27 19:42 - 2017-05-27 19:42 - 00000000 ___RD C:\Users\Cory Smith\OneDrive
- 2017-05-27 19:42 - 2017-05-27 19:42 - 00000000 ____D C:\Users\Cory Smith\AppData\Local\Comms
- 2017-05-27 19:41 - 2017-05-27 21:00 - 00000000 ____D C:\Users\Cory Smith\AppData\Local\MicrosoftEdge
- 2017-05-27 19:40 - 2017-05-27 19:40 - 00000000 ____D C:\Users\Cory Smith\AppData\Local\Publishers
- 2017-05-27 19:40 - 2017-05-27 19:40 - 00000000 ____D C:\ProgramData\Microsoft OneDrive
- 2017-05-27 19:37 - 2017-05-28 18:20 - 00000000 ____D C:\Users\Cory Smith\AppData\Local\Packages
- 2017-05-27 19:37 - 2017-05-28 18:12 - 00000000 ____D C:\Users\Cory Smith
- 2017-05-27 19:37 - 2017-05-27 19:37 - 00000020 ___SH C:\Users\Cory Smith\ntuser.ini
- 2017-05-27 19:37 - 2017-05-27 19:37 - 00000000 __RHD C:\Users\Public\AccountPictures
- 2017-05-27 19:37 - 2017-05-27 19:37 - 00000000 ____D C:\Users\Cory Smith\AppData\Roaming\Adobe
- 2017-05-27 19:37 - 2017-05-27 19:37 - 00000000 ____D C:\Users\Cory Smith\AppData\Local\VirtualStore
- 2017-05-27 19:37 - 2017-05-27 19:37 - 00000000 ____D C:\Users\Cory Smith\AppData\Local\TileDataLayer
- 2017-05-27 19:37 - 2017-05-27 19:37 - 00000000 ____D C:\Users\Cory Smith\AppData\Local\ConnectedDevicesPlatform
- 2017-05-27 19:35 - 2017-05-28 20:55 - 00927954 _____ C:\Windows\system32\PerfStringBackup.INI
- 2017-05-27 19:33 - 2017-03-18 21:56 - 02233344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PrintConfig.dll
- 2017-05-27 19:27 - 2017-05-29 14:49 - 00000006 ____H C:\Windows\Tasks\SA.DAT
- 2017-05-27 19:27 - 2017-05-27 19:27 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
- 2017-05-27 19:26 - 2017-05-28 19:31 - 00000000 ____D C:\Windows\system32\SleepStudy
- 2017-05-27 19:26 - 2017-05-27 19:27 - 00217000 _____ C:\Windows\system32\FNTCACHE.DAT
- 2017-05-27 19:26 - 2017-05-27 19:26 - 00000000 ____D C:\Windows\ServiceProfiles
- ==================== One Month Modified files and folders ========
- (If an entry is included in the fixlist, the file/folder will be moved.)
- 2017-05-29 14:48 - 2017-03-18 12:40 - 00524288 _____ C:\Windows\system32\config\BBI
- 2017-05-29 14:41 - 2017-03-18 22:03 - 00000000 ___HD C:\Windows\ELAMBKUP
- 2017-05-29 14:41 - 2017-03-18 12:40 - 00032768 _____ C:\Windows\system32\config\ELAM
- 2017-05-28 20:26 - 2017-03-18 22:01 - 00000000 ____D C:\Windows\INF
- 2017-05-28 18:25 - 2017-03-18 22:03 - 00000000 ___HD C:\Program Files\WindowsApps
- 2017-05-28 18:25 - 2017-03-18 22:03 - 00000000 ____D C:\Windows\AppReadiness
- 2017-05-28 17:20 - 2017-03-18 21:51 - 00000000 ____D C:\Windows\CbsTemp
- 2017-05-28 11:52 - 2017-03-18 22:03 - 00000000 ____D C:\Windows\system32\NDF
- 2017-05-28 10:56 - 2017-03-18 22:03 - 00000000 ____D C:\Windows\appcompat
- 2017-05-27 20:44 - 2017-03-18 22:03 - 00000000 ____D C:\Windows\Help
- 2017-05-27 20:25 - 2017-03-18 22:03 - 00028672 _____ C:\Windows\system32\config\BCD-Template
- 2017-05-27 19:48 - 2017-03-18 22:03 - 00000000 ____D C:\ProgramData\USOPrivate
- 2017-05-27 19:37 - 2017-03-18 22:03 - 00000000 ____D C:\Windows\system32\WinBioDatabase
- 2017-05-27 19:33 - 2017-03-18 22:03 - 00000000 ____D C:\Windows\system32\spool
- 2017-05-27 19:33 - 2017-03-18 22:03 - 00000000 ____D C:\Windows\system32\FxsTmp
- 2017-05-27 19:32 - 2017-03-18 22:03 - 00000000 ____D C:\Windows\rescache
- 2017-05-27 19:29 - 2017-03-18 12:40 - 00000000 ____D C:\Windows\system32\Sysprep
- 2017-05-27 19:28 - 2017-03-18 22:03 - 00000000 ___RD C:\Windows\PrintDialog
- 2017-05-27 19:28 - 2017-03-18 22:03 - 00000000 ___RD C:\Windows\MiracastView
- 2017-05-27 19:28 - 2017-03-18 22:03 - 00000000 ___RD C:\Windows\ImmersiveControlPanel
- 2017-05-27 19:27 - 2017-03-20 04:44 - 00000000 ____D C:\Windows\HoloShell
- ==================== Files in the root of some directories =======
- 2017-05-28 17:25 - 2017-05-28 17:25 - 0007606 _____ () C:\Users\Cory Smith\AppData\Local\Resmon.ResmonCfg
- 2017-05-28 11:08 - 2017-05-28 11:08 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
- Some files in TEMP:
- ====================
- 2017-05-28 21:03 - 2017-05-28 21:04 - 13460656 _____ (Reimage) C:\Users\Cory Smith\AppData\Local\Temp\ReimagePackage.exe
- 2017-05-28 18:12 - 2017-05-28 18:12 - 0000000 _____ () C:\Users\Cory Smith\AppData\Local\Temp\{A528772F-EC96-4F45-ABD2-61CD1F4C5DE4}-58.0.3029.110_chrome_installer.exe
- ==================== Bamital & volsnap ======================
- (There is no automatic fix for files that do not pass verification.)
- C:\Windows\system32\winlogon.exe => File is digitally signed
- C:\Windows\system32\wininit.exe => File is digitally signed
- C:\Windows\explorer.exe => File is digitally signed
- C:\Windows\SysWOW64\explorer.exe => File is digitally signed
- C:\Windows\system32\svchost.exe => File is digitally signed
- C:\Windows\SysWOW64\svchost.exe => File is digitally signed
- C:\Windows\system32\services.exe => File is digitally signed
- C:\Windows\system32\User32.dll => File is digitally signed
- C:\Windows\SysWOW64\User32.dll => File is digitally signed
- C:\Windows\system32\userinit.exe => File is digitally signed
- C:\Windows\SysWOW64\userinit.exe => File is digitally signed
- C:\Windows\system32\rpcss.dll => File is digitally signed
- C:\Windows\system32\dnsapi.dll => File is digitally signed
- C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
- C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
- LastRegBack: 2017-05-27 19:26
- ==================== End of FRST.txt ============================
- ADDITION TXT:
- Additional scan result of Farbar Recovery Scan Tool (x64) Version: 28-05-2017
- Ran by Cory Smith (29-05-2017 14:53:56)
- Running from C:\Users\Cory Smith\Downloads
- Windows 10 Home Version 1703 (X64) (2017-05-27 18:31:46)
- Boot Mode: Normal
- ==========================================================
- ==================== Accounts: =============================
- Administrator (S-1-5-21-3729940396-3466973117-3832101617-500 - Administrator - Disabled)
- Cory Smith (S-1-5-21-3729940396-3466973117-3832101617-1001 - Administrator - Enabled) => C:\Users\Cory Smith
- DefaultAccount (S-1-5-21-3729940396-3466973117-3832101617-503 - Limited - Disabled)
- Guest (S-1-5-21-3729940396-3466973117-3832101617-501 - Limited - Disabled)
- ==================== Security Center ========================
- (If an entry is included in the fixlist, it will be removed.)
- AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
- AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
- ==================== Installed Programs ======================
- (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
- µTorrent (HKU\S-1-5-21-3729940396-3466973117-3832101617-1001\...\uTorrent) (Version: 3.5.0.43804 - BitTorrent Inc.)
- 7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov)
- AMD Software (HKLM\...\AMD Catalyst Install Manager) (Version: 9.0.000.8 - Advanced Micro Devices, Inc.)
- Ansel (Version: 378.78 - NVIDIA Corporation) Hidden
- Arma 3 (HKLM\...\Steam App 107410) (Version: - Bohemia Interactive)
- DriverToolkit version 8.5.1.0 (HKLM-x32\...\{D66BF89F-B0A2-48F5-A2E4-242EB645AB76}_is1) (Version: 8.5.1.0 - Megaify Software)
- Google Chrome (HKLM-x32\...\Google Chrome) (Version: 58.0.3029.110 - Google Inc.)
- Google Update Helper (x32 Version: 1.3.33.5 - Google Inc.) Hidden
- Microsoft OneDrive (HKU\S-1-5-21-3729940396-3466973117-3832101617-1001\...\OneDriveSetup.exe) (Version: 17.3.6816.0313 - Microsoft Corporation)
- Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
- Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
- MSIRegister (HKLM-x32\...\{80B995A4-3A86-4690-98A6-563F1A788835}_is1) (Version: 2.0.0.05 - MSI)
- NVIDIA 3D Vision Controller Driver 347.09 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 347.09 - NVIDIA Corporation)
- NVIDIA 3D Vision Driver 378.78 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 378.78 - NVIDIA Corporation)
- NVIDIA GeForce Experience 2.2.2 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.2.2 - NVIDIA Corporation)
- NVIDIA Graphics Driver 378.78 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 378.78 - NVIDIA Corporation)
- NVIDIA HD Audio Driver 1.3.34.23 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.23 - NVIDIA Corporation)
- NVIDIA Miracast Virtual Audio 347.88 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Miracast.VirtualAudio) (Version: 347.88 - NVIDIA Corporation)
- NVIDIA PhysX System Software 9.14.0702 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.14.0702 - NVIDIA Corporation)
- OEM Application Profile (HKLM-x32\...\{7F5DCD33-1039-C3B2-9538-B645B65BBA63}) (Version: 1.00.0000 - Advanced Micro Devices, Inc.)
- Ralink RT2860 Wireless LAN Card (HKLM-x32\...\{8FC4F1DD-F7FD-4766-804D-3C8FF1D309AF}) (Version: 1.5.24.0 - Ralink)
- Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 10.10.714.2016 - Realtek)
- Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.8059 - Realtek Semiconductor Corp.)
- Reimage Repair (HKLM\...\Reimage Repair) (Version: 1.8.5.8 - Reimage) <==== ATTENTION
- SHIELD Streaming (Version: 4.0.1000 - NVIDIA Corporation) Hidden
- SHIELD Wireless Controller Driver (Version: 17.12.8 - NVIDIA Corporation) Hidden
- Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
- Vulkan Run Time Libraries 1.0.39.1 (HKLM\...\VulkanRT1.0.39.1) (Version: 1.0.39.1 - LunarG, Inc.)
- ==================== Custom CLSID (Whitelisted): ==========================
- (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
- ==================== Scheduled Tasks (Whitelisted) =============
- (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
- Task: {09BF8E29-5E32-4253-A671-B5DD1C722474} - System32\Tasks\Reimage Reminder => C:\Program Files\Reimage\Reimage Repair\ReimageReminder.exe [2017-05-10] (Reimage ltd.) <==== ATTENTION
- Task: {6817078E-C16D-4600-ABD7-51634159774A} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-05-28] (Google Inc.)
- Task: {68EEE93F-D498-496A-8FFB-70EF41F9D189} - System32\Tasks\AutoKMS => C:\Windows\AutoKMS\AutoKMS.exe [2017-05-29] ()
- Task: {7953A384-146C-4CD6-8AF9-B4F8B21A7A51} - System32\Tasks\DriverToolkit Autorun => C:\Program Files (x86)\DriverToolkit\DriverToolkit.exe [2017-05-15] (Megaify Software Co., Ltd.)
- Task: {C4FDBD42-8E9E-4C9F-9604-D781E99A55D7} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-05-28] (Google Inc.)
- Task: {FF340766-4B98-4433-AFB6-2580906B53ED} - System32\Tasks\ReimageUpdater => C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe [2017-05-14] (Reimage®) <==== ATTENTION
- (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
- Task: C:\Windows\Tasks\DriverToolkit Autorun.job => C:\Program Files (x86)\DriverToolkit\DriverToolkit.exe
- ==================== Shortcuts =============================
- (The entries could be listed to be restored or removed.)
- ==================== Loaded Modules (Whitelisted) ==============
- 2017-03-18 21:58 - 2017-03-18 21:58 - 00138000 _____ () C:\Windows\SYSTEM32\inputhost.dll
- 2017-03-18 21:59 - 2017-03-20 04:43 - 01731072 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
- 2017-03-18 21:58 - 2017-03-18 21:58 - 00047616 _____ () C:\Windows\SystemApps\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\SecHealthUITelemetry.dll
- 2017-03-18 21:58 - 2017-03-18 21:58 - 02328576 _____ () C:\Windows\SystemApps\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\SecHealthUIViewModels.dll
- 2017-03-18 21:58 - 2017-03-18 21:58 - 02836480 _____ () C:\Windows\SystemApps\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\SecHealthUIDataModel.dll
- 2017-05-27 21:11 - 2014-02-17 19:13 - 00092984 _____ () C:\Program Files (x86)\DriverToolkit\zlibwapi.dll
- 2017-05-28 19:46 - 2017-03-10 01:13 - 00674592 _____ () C:\Program Files (x86)\Steam\SDL2.dll
- 2017-05-28 19:46 - 2017-04-26 00:55 - 02465056 _____ () C:\Program Files (x86)\Steam\video.dll
- 2017-05-28 19:46 - 2016-01-27 08:49 - 02549760 _____ () C:\Program Files (x86)\Steam\libavcodec-56.dll
- 2017-05-28 19:46 - 2016-01-27 08:49 - 00442880 _____ () C:\Program Files (x86)\Steam\libavutil-54.dll
- 2017-05-28 19:46 - 2016-09-01 02:02 - 04969248 _____ () C:\Program Files (x86)\Steam\v8.dll
- 2017-05-28 19:46 - 2016-01-27 08:49 - 00491008 _____ () C:\Program Files (x86)\Steam\libavformat-56.dll
- 2017-05-28 19:46 - 2016-01-27 08:49 - 00332800 _____ () C:\Program Files (x86)\Steam\libavresample-2.dll
- 2017-05-28 19:46 - 2016-09-01 02:02 - 01195296 _____ () C:\Program Files (x86)\Steam\icuuc.dll
- 2017-05-28 19:46 - 2016-09-01 02:02 - 01563936 _____ () C:\Program Files (x86)\Steam\icui18n.dll
- 2017-05-28 19:46 - 2016-01-27 08:49 - 00485888 _____ () C:\Program Files (x86)\Steam\libswscale-3.dll
- 2017-05-28 19:46 - 2017-04-26 00:55 - 00848672 _____ () C:\Program Files (x86)\Steam\bin\chromehtml.DLL
- 2017-05-28 19:46 - 2016-07-04 23:17 - 00266560 _____ () C:\Program Files (x86)\Steam\openvr_api.dll
- 2017-05-28 19:49 - 2017-01-30 22:41 - 68875552 _____ () C:\Program Files (x86)\Steam\bin\cef\cef.win7\libcef.dll
- 2017-05-28 19:46 - 2015-09-25 00:52 - 00119208 _____ () C:\Program Files (x86)\Steam\winh264.dll
- ==================== Alternate Data Streams (Whitelisted) =========
- (If an entry is included in the fixlist, only the ADS will be removed.)
- ==================== Safe Mode (Whitelisted) ===================
- (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
- ==================== Association (Whitelisted) ===============
- (If an entry is included in the fixlist, the registry item will be restored to default or removed.)
- ==================== Internet Explorer trusted/restricted ===============
- (If an entry is included in the fixlist, it will be removed from the registry.)
- ==================== Hosts content: ===============================
- (If needed Hosts: directive could be included in the fixlist to reset Hosts.)
- 2017-03-18 22:03 - 2017-03-18 22:01 - 00000824 _____ C:\Windows\system32\Drivers\etc\hosts
- ==================== Other Areas ============================
- (Currently there is no automatic fix for this section.)
- HKU\S-1-5-21-3729940396-3466973117-3832101617-1001\Control Panel\Desktop\\Wallpaper -> C:\Windows\web\wallpaper\Windows\img0.jpg
- DNS Servers: 192.168.1.1
- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
- Windows Firewall is disabled.
- ==================== MSCONFIG/TASK MANAGER disabled items ==
- HKU\S-1-5-21-3729940396-3466973117-3832101617-1001\...\StartupApproved\Run: => "Steam"
- ==================== FirewallRules (Whitelisted) ===============
- (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
- FirewallRules: [{515A9A5D-8388-4182-8A21-26DFEF2BAA78}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
- FirewallRules: [{57B0740E-187E-4627-99F0-A11C2268E866}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
- FirewallRules: [{D0BF19E7-67A2-4338-B1B7-B15EC7D0C7EA}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
- FirewallRules: [{6C2BBCFB-69D6-4ECC-A776-6D6B52983D73}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
- FirewallRules: [{42608FC1-AD69-41D7-8883-D1225A5F6F76}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
- FirewallRules: [{4C5B9436-7364-4F6A-958D-FBA5E3CA9511}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
- FirewallRules: [{7A0BAC4B-8FF7-4DBB-9AFA-D71FFAAF0B52}] => (Allow) C:\Users\Cory Smith\AppData\Roaming\uTorrent\uTorrent.exe
- FirewallRules: [{DBE02383-6718-4A5D-87DD-5ED832D7C1BD}] => (Allow) C:\Users\Cory Smith\AppData\Roaming\uTorrent\uTorrent.exe
- FirewallRules: [{661D403E-FCB1-4CCC-94CD-7F7D5B3DED64}] => (Allow) C:\Users\Cory Smith\AppData\Roaming\uTorrent\uTorrent.exe
- FirewallRules: [{9111CA6B-1F7B-4948-99D8-1BAAA58CB1BD}] => (Allow) C:\Users\Cory Smith\AppData\Roaming\uTorrent\uTorrent.exe
- FirewallRules: [{08D6F8B2-D05A-4692-9B34-6CFD0B159335}] => (Allow) C:\Users\Cory Smith\AppData\Roaming\uTorrent\uTorrent.exe
- FirewallRules: [{FF477E30-34D5-4F47-9714-9DD38AB40DEB}] => (Allow) C:\Users\Cory Smith\AppData\Roaming\uTorrent\uTorrent.exe
- FirewallRules: [{95322A27-5273-4644-BF80-950F221F5DA9}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
- FirewallRules: [{95BDABD8-BB23-46F7-9373-060052BED6CF}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
- FirewallRules: [{200D6A59-4888-4644-9158-0F2B04DA14A3}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
- FirewallRules: [{DDE776C0-4E99-4706-B010-277F2872C688}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
- FirewallRules: [{C9C62B4B-692B-4B22-87FE-B89425580166}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- ==================== Restore Points =========================
- 27-05-2017 19:44:41 Windows Update
- ==================== Faulty Device Manager Devices =============
- ==================== Event log errors: =========================
- Application errors:
- ==================
- Error: (05/29/2017 02:46:32 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
- Description: License Activation (slui.exe) failed with the following error code:
- hr=0xC004F074
- Command-line arguments:
- RuleId=eeba1977-569e-4571-b639-7623d8bfecc0;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=58e97c99-f377-4ef1-81d5-4ad5522b5fd8;NotificationInterval=1440;Trigger=TimerEvent
- Error: (05/29/2017 02:41:27 PM) (Source: Application Error) (EventID: 1000) (User: )
- Description: Faulting application name: SecHealthUI.exe, version: 10.0.15063.0, time stamp: 0x58ccbce5
- Faulting module name: SecHealthUIDataModel.dll, version: 0.0.0.0, time stamp: 0x58ccbc8d
- Exception code: 0xc0000005
- Fault offset: 0x000000000015b847
- Faulting process ID: 0x4f0
- Faulting application start time: 0x01d2d8811c575de4
- Faulting application path: C:\Windows\SystemApps\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\SecHealthUI.exe
- Faulting module path: C:\Windows\SystemApps\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\SecHealthUIDataModel.dll
- Report ID: be33e280-de4e-4d56-b954-19d8e1f79f1e
- Faulting package full name: Microsoft.Windows.SecHealthUI_10.0.15063.0_neutral__cw5n1h2txyewy
- Faulting package-relative application ID: SecHealthUI
- Error: (05/29/2017 02:06:05 PM) (Source: SideBySide) (EventID: 33) (User: )
- Description: Activation context generation failed for "c:\program files\amd\cim\bin64\SetACL64.exe".
- Dependent Assembly Microsoft.VC80.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0" could not be found.
- Please use sxstrace.exe for detailed diagnosis.
- Error: (05/29/2017 02:05:36 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
- Description: License Activation (slui.exe) failed with the following error code:
- hr=0x80070422
- Command-line arguments:
- RuleId=31e71c49-8da7-4a2f-ad92-45d98a1c79ba;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=2b1f36bb-c1cd-4306-bf5c-a0367c2d97d8;NotificationInterval=1440;Trigger=UserLogon;SessionId=2
- Error: (05/29/2017 02:03:07 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
- Description: License Activation (slui.exe) failed with the following error code:
- hr=0x8007139F
- Command-line arguments:
- RuleId=31e71c49-8da7-4a2f-ad92-45d98a1c79ba;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=2b1f36bb-c1cd-4306-bf5c-a0367c2d97d8;NotificationInterval=1440;Trigger=NetworkAvailable
- Error: (05/29/2017 02:02:40 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
- Description: License Activation (slui.exe) failed with the following error code:
- hr=0x8007139F
- Command-line arguments:
- RuleId=31e71c49-8da7-4a2f-ad92-45d98a1c79ba;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=2b1f36bb-c1cd-4306-bf5c-a0367c2d97d8;NotificationInterval=1440;Trigger=NetworkAvailable
- Error: (05/28/2017 09:12:11 PM) (Source: SideBySide) (EventID: 33) (User: )
- Description: Activation context generation failed for "c:\program files\amd\cim\bin64\SetACL64.exe".
- Dependent Assembly Microsoft.VC80.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0" could not be found.
- Please use sxstrace.exe for detailed diagnosis.
- Error: (05/28/2017 09:06:01 PM) (Source: SideBySide) (EventID: 33) (User: )
- Description: Activation context generation failed for "c:\program files\amd\cim\bin64\SetACL64.exe".
- Dependent Assembly Microsoft.VC80.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0" could not be found.
- Please use sxstrace.exe for detailed diagnosis.
- Error: (05/28/2017 08:55:34 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
- Description: License Activation (slui.exe) failed with the following error code:
- hr=0x80070422
- Command-line arguments:
- RuleId=31e71c49-8da7-4a2f-ad92-45d98a1c79ba;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=2b1f36bb-c1cd-4306-bf5c-a0367c2d97d8;NotificationInterval=1440;Trigger=NetworkAvailable
- Error: (05/28/2017 08:55:34 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
- Description: License Activation (slui.exe) failed with the following error code:
- hr=0x80070422
- Command-line arguments:
- RuleId=31e71c49-8da7-4a2f-ad92-45d98a1c79ba;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=2b1f36bb-c1cd-4306-bf5c-a0367c2d97d8;NotificationInterval=1440;Trigger=NetworkAvailable
- System errors:
- =============
- Error: (05/29/2017 02:49:04 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
- Description: The CldFlt service failed to start due to the following error:
- The request is not supported.
- Error: (05/28/2017 08:48:26 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
- Description: The CldFlt service failed to start due to the following error:
- The request is not supported.
- Error: (05/28/2017 08:47:22 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-GU6TEMK)
- Description: The server {0002DF02-0000-0000-C000-000000000046} did not register with DCOM within the required timeout.
- Error: (05/28/2017 08:47:22 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-GU6TEMK)
- Description: The server {0002DF02-0000-0000-C000-000000000046} did not register with DCOM within the required timeout.
- Error: (05/28/2017 08:27:21 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
- Description: The CldFlt service failed to start due to the following error:
- The request is not supported.
- Error: (05/28/2017 08:26:24 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-GU6TEMK)
- Description: The server {0002DF02-0000-0000-C000-000000000046} did not register with DCOM within the required timeout.
- Error: (05/28/2017 08:26:24 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-GU6TEMK)
- Description: The server {0002DF02-0000-0000-C000-000000000046} did not register with DCOM within the required timeout.
- Error: (05/28/2017 07:49:43 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
- Description: The Steam Client Service service failed to start due to the following error:
- The service did not respond to the start or control request in a timely fashion.
- Error: (05/28/2017 07:49:43 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
- Description: A timeout was reached (30000 milliseconds) while waiting for the Steam Client Service service to connect.
- Error: (05/28/2017 07:32:00 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
- Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
- {D63B10C5-BB46-4990-A94F-E40B9D520160}
- and APPID
- {9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
- to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
- ==================== Memory info ===========================
- Processor: AMD Ryzen 5 1500X Quad-Core Processor
- Percentage of memory in use: 25%
- Total physical RAM: 8144.74 MB
- Available physical RAM: 6064.52 MB
- Total Virtual: 10064.74 MB
- Available Virtual: 7802.2 MB
- ==================== Drives ================================
- Drive c: () (Fixed) (Total:930.96 GB) (Free:883.39 GB) NTFS
- Drive e: (G71-MAD1038) (CDROM) (Total:4.18 GB) (Free:0 GB) CDFS
- ==================== MBR & Partition Table ==================
- ========================================================
- Disk: 0 (Size: 931.5 GB) (Disk ID: EE7BE432)
- Partition: GPT.
- ==================== End of Addition.txt ============================
- Scan_Registery_Run_Key:
- **************************************************************************************************************************************************
- Started on 29/05/2017 15:00:34.76 "Scan_Registery_Run_Key.bat" with username : "Cory Smith" on Computer "DESKTOP-GU6TEMK"
- **************************************************************************************************************************************************
- ***************************** General infos ***********************************
- Running under: Cory Smith on profile: C:\Users\Cory Smith
- Computer name: DESKTOP-GU6TEMK
- Host Name: DESKTOP-GU6TEMK
- OS Name: Microsoft Windows 10 Home
- OS Version: 10.0.15063 N/A Build 15063
- OS Manufacturer: Microsoft Corporation
- OS Configuration: Standalone Workstation
- OS Build Type: Multiprocessor Free
- Registered Owner: Windows User
- Registered Organization:
- Product ID: 00326-30000-00001-AA717
- Original Install Date: 27/05/2017, 19:31:46
- System Boot Time: 29/05/2017, 14:48:48
- System Manufacturer: MSI
- System Model: MS-7A39
- System Type: x64-based PC
- Processor(s): 1 Processor(s) Installed.
- [01]: AMD64 Family 23 Model 1 Stepping 1 AuthenticAMD ~1550 Mhz
- BIOS Version: American Megatrends Inc. 2.30, 24/03/2017
- Windows Directory: C:\Windows
- System Directory: C:\Windows\system32
- Boot Device: \Device\HarddiskVolume2
- System Locale: en-gb;English (United Kingdom)
- Input Locale: en-gb;English (United Kingdom)
- Time Zone: (UTC+00:00) Dublin, Edinburgh, Lisbon, London
- Total Physical Memory: 8,145 MB
- Available Physical Memory: 6,030 MB
- Virtual Memory: Max Size: 10,065 MB
- Virtual Memory: Available: 7,682 MB
- Virtual Memory: In Use: 2,383 MB
- Page File Location(s): C:\pagefile.sys
- Domain: WORKGROUP
- Logon Server: \\DESKTOP-GU6TEMK
- Hotfix(s): N/A
- Network Card(s): 3 NIC(s) Installed.
- [01]: Realtek PCIe GBE Family Controller
- Connection Name: Ethernet
- Status: Media disconnected
- [02]: 802.11n Wireless LAN Card
- Connection Name: WiFi
- Status: Media disconnected
- [03]: N300 USB Network Adapter
- Connection Name: WiFi 2
- DHCP Enabled: Yes
- DHCP Server: 192.168.1.1
- IP address(es)
- [01]: 192.168.1.62
- [02]: fe80::e8eb:65c6:13c9:ccb4
- Hyper-V Requirements: VM Monitor Mode Extensions: Yes
- Virtualization Enabled In Firmware: No
- Second Level Address Translation: Yes
- Data Execution Prevention Available: Yes
- Operating System:
- Microsoft Windows 10 Home
- PROCESSOR ARCHITECTURE : AMD64
- NUMBER_OF_PROCESSORS : 8
- PROCESSOR_IDENTIFIER : AMD64 Family 23 Model 1 Stepping 1, AuthenticAMD
- PROCESSOR_LEVEL : 23
- PROCESSOR_REVISION : 0101
- OS TYPE : Windows_NT
- CMD PATH : C:\Windows\system32\cmd.exe
- EXTENSIONS : .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
- PATH : "C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Users\Cory Smith\AppData\Local\Microsoft\WindowsApps"
- Program files path : C:\Program Files
- Program files(86) path :
- ProgramW6432 path : C:\Program Files
- PSModulePath : C:\Program Files\WindowsPowerShell\Modules;C:\Windows\system32\WindowsPowerShell\v1.0\Modules
- SystemRoot : C:\Windows
- Temp Folder : C:\Users\CORYSM~1\AppData\Local\Temp
- Boot Mode:
- Normal boot
- Antivirus software installed:
- Windows Defender
- **************************** Drives infos *************************************
- Listing currently attached drives:
- Caption Description VolumeName
- C: Local Fixed Disk
- E: CD-ROM Disc G71-MAD1038
- Physical drives information:
- C: \Device\HarddiskVolume4 NTFS
- E: \Device\CdRom0 CDFS
- ************************** DriverQuery infos **********************************
- Module Name Display Name Driver Type Link Date
- ============ ====================== ============= ======================
- 1394ohci 1394 OHCI Compliant Ho Kernel 10/12/2006 21:44:38
- 3ware 3ware Kernel 18/05/2015 23:28:03
- ACPI Microsoft ACPI Driver Kernel 09/12/1975 11:17:08
- AcpiDev ACPI Devices driver Kernel 07/12/1993 11:22:19
- acpiex Microsoft ACPIEx Drive Kernel 01/03/2087 13:53:50
- acpipagr ACPI Processor Aggrega Kernel 24/01/2081 13:36:36
- AcpiPmi ACPI Power Meter Drive Kernel 20/11/2006 02:20:15
- acpitime ACPI Wake Alarm Driver Kernel 09/02/1974 12:10:30
- ADP80XX ADP80XX Kernel 09/04/2015 21:49:48
- AFD Ancillary Function Dri Kernel 25/03/2096 17:36:43
- ahcache Application Compatibil Kernel 29/07/2004 05:52:50
- amdgpio2 AMD GPIO Client Driver Kernel 09/08/2016 11:05:07
- amdgpio3 AMD GPIO Client Driver Kernel 14/03/2016 10:19:36
- AmdK8 AMD K8 Processor Drive Kernel 16/06/2040 08:17:43
- amdkmcsp AMD Kernel Mode CSP Se Kernel 06/12/2016 16:55:14
- AmdPPM AMD Processor Driver Kernel 23/12/2077 21:48:10
- amdpsp AMD PSP Service Kernel 06/12/2016 16:53:23
- amdsata amdsata Kernel 14/05/2015 13:14:52
- amdsbs amdsbs Kernel 11/12/2012 21:21:44
- amdxata amdxata Kernel 01/05/2015 01:55:35
- AppID AppID Driver Kernel 18/03/2072 00:13:51
- applockerflt Smartlocker Filter Dri Kernel 17/09/2101 10:17:41
- arcsas Adaptec SAS/SATA-II RA Kernel 09/04/2015 20:12:07
- AsyncMac RAS Asynchronous Media Kernel 08/08/2097 15:12:49
- atapi IDE Channel Kernel 27/11/2000 23:57:51
- b06bdrv QLogic Network Adapter Kernel 25/05/2016 08:03:08
- BasicDisplay BasicDisplay Kernel 22/02/2093 15:33:08
- BasicRender BasicRender Kernel 04/04/2070 19:19:55
- bcmfn2 bcmfn2 Service Kernel 01/11/2016 02:09:15
- Beep Beep Kernel 01/01/2060 16:27:10
- bowser Browser Support Driver File System 14/11/2063 22:49:42
- BthAvrcpTg Bluetooth Audio/Video Kernel 11/09/2022 20:32:06
- BthHFEnum Bluetooth Hands-Free A Kernel 19/04/2004 05:32:55
- bthhfhid Bluetooth Hands-Free C Kernel 25/04/2011 05:21:49
- BTHMODEM Bluetooth Modem Commun Kernel 04/04/2079 10:31:37
- buttonconver Service for Portable D Kernel 19/11/2000 03:01:50
- CAD Charge Arbitration Dri Kernel 03/12/2017 09:31:49
- CapImg HID driver for CapImg Kernel 27/12/2059 15:11:50
- cdfs CD/DVD File System Rea File System 06/01/2064 18:54:26
- cdrom CD-ROM Driver Kernel 20/07/1972 23:39:41
- cht4iscsi cht4iscsi Kernel 20/04/2016 10:54:30
- cht4vbd Chelsio Virtual Bus Dr Kernel 15/04/2016 08:32:54
- circlass Consumer IR Devices Kernel 11/07/2094 04:26:42
- CldFlt Windows Cloud Files Fi File System 17/05/2064 10:03:21
- CLFS Common Log (CLFS) Kernel 09/08/2066 16:12:22
- clreg Virtual Registry for C Kernel 16/08/2055 10:08:54
- CmBatt Microsoft ACPI Control Kernel 26/07/2053 13:56:57
- CNG CNG Kernel 21/02/2099 13:35:34
- cnghwassist CNG Hardware Assist al Kernel 16/02/2009 02:39:48
- CompositeBus Composite Bus Enumerat Kernel 16/06/2056 14:59:53
- condrv Console Driver Kernel 26/06/2031 02:27:43
- dam Desktop Activity Moder Kernel 06/12/2087 09:31:06
- Dfsc DFS Namespace Client D File System 04/03/2023 10:04:07
- Disk Disk Driver Kernel 28/03/2009 18:37:28
- dmvsc dmvsc Kernel 14/03/2099 09:44:35
- drmkaud Microsoft Trusted Audi Kernel 26/09/1996 17:21:58
- DXGKrnl LDDM Graphics Subsyste Kernel 04/02/2025 08:30:42
- ebdrv QLogic 10 Gigabit Ethe Kernel 25/05/2016 08:01:05
- EhStorClass Enhanced Storage Filte Kernel 03/01/2088 01:18:11
- EhStorTcgDrv Microsoft driver for s Kernel 13/06/2100 03:14:48
- ErrDev Microsoft Hardware Err Kernel 27/02/2013 20:51:53
- exfat exFAT File System Driv File System 27/09/2034 11:25:11
- fastfat FAT12/16/32 File Syste File System 17/05/1977 04:56:00
- fdc Floppy Disk Controller Kernel 02/02/1975 16:36:16
- FileCrypt FileCrypt File System 28/05/2030 09:10:59
- FileInfo File Information FS Mi File System 30/06/2042 15:43:32
- Filetrace Filetrace File System 24/02/2101 18:55:03
- flpydisk Floppy Disk Driver Kernel 21/05/2084 16:16:11
- FltMgr FltMgr File System 01/01/2047 11:09:19
- FsDepends File System Dependency File System 21/04/2018 00:09:27
- fvevol BitLocker Drive Encryp Kernel 03/02/1999 07:04:49
- gencounter Microsoft Hyper-V Gene Kernel 05/05/1995 05:36:10
- genericusbfn Generic USB Function C Kernel 15/05/2006 16:31:15
- GPIOClx0101 Microsoft GPIO Class E Kernel 17/06/2039 21:01:13
- GpuEnergyDrv GPU Energy Driver Kernel 11/11/1972 08:01:57
- HdAudAddServ Microsoft 1.1 UAA Func Kernel 24/06/1988 03:07:39
- HDAudBus Microsoft UAA Bus Driv Kernel 27/01/1988 06:21:45
- HidBatt HID UPS Battery Driver Kernel 03/07/2016 11:25:51
- HidBth Microsoft Bluetooth HI Kernel 03/06/1986 22:53:22
- hidi2c Microsoft I2C HID Mini Kernel 04/03/2045 20:13:23
- hidinterrupt Common Driver for HID Kernel 06/07/1991 08:10:26
- HidIr Microsoft Infrared HID Kernel 30/03/2078 22:28:49
- HidUsb Microsoft HID Class Dr Kernel 03/05/2016 08:23:27
- HpSAMD HpSAMD Kernel 26/03/2013 21:36:54
- HTTP HTTP Service Kernel 27/12/2076 02:18:09
- hvservice Hypervisor/Virtual Mac Kernel 09/06/1977 15:05:34
- hwpolicy Hardware Policy Driver Kernel 04/02/2045 11:49:56
- hyperkbd hyperkbd Kernel 08/11/2104 23:18:45
- i8042prt PS/2 Keyboard and Mous Kernel 10/11/1995 17:53:53
- iagpio Intel Serial IO GPIO C Kernel 18/02/2016 07:35:09
- iai2c Intel(R) Serial IO I2C Kernel 22/09/2015 07:53:03
- iaLPSS2i_GPI Intel(R) Serial IO GPI Kernel 09/08/2016 03:23:09
- iaLPSS2i_GPI Intel(R) Serial IO GPI Kernel 03/02/2017 05:51:05
- iaLPSS2i_I2C Intel(R) Serial IO I2C Kernel 09/08/2016 03:22:47
- iaLPSS2i_I2C Intel(R) Serial IO I2C Kernel 03/02/2017 05:50:37
- iaLPSSi_GPIO Intel(R) Serial IO GPI Kernel 02/02/2015 09:00:09
- iaLPSSi_I2C Intel(R) Serial IO I2C Kernel 24/02/2015 15:52:07
- iaStorAV Intel(R) SATA RAID Con Kernel 19/02/2015 12:08:39
- iaStorV Intel RAID Controller Kernel 11/04/2011 19:48:16
- ibbus Mellanox InfiniBand Bu Kernel 10/04/2016 14:46:21
- IndirectKmd Indirect Displays Kern Kernel 24/02/2060 02:30:57
- IntcAzAudAdd Service for Realtek HD Kernel 07/02/2017 11:19:23
- intelide intelide Kernel 07/12/2008 05:16:35
- intelpep Intel(R) Power Engine Kernel 19/04/2007 09:53:10
- intelppm Intel Processor Driver Kernel 07/06/2079 05:38:54
- iorate Disk I/O Rate Filter D Kernel 01/02/2013 23:15:43
- IpFilterDriv IP Traffic Filter Driv Kernel 25/05/2028 05:01:58
- IPMIDRV IPMIDRV Kernel 03/05/1995 12:19:39
- IPNAT IP Network Address Tra Kernel 03/09/2077 01:24:53
- irda irda Kernel 06/10/2004 00:00:37
- IRENUM IR Bus Enumerator Kernel 22/12/2038 21:31:52
- isapnp isapnp Kernel 08/12/2055 17:46:48
- iScsiPrt iScsiPort Driver Kernel 25/12/2067 07:56:36
- kbdclass Keyboard Class Driver Kernel 11/01/2084 06:17:01
- kbdhid Keyboard HID Driver Kernel 24/04/2022 05:10:44
- kdnic Microsoft Kernel Debug Kernel 21/08/2093 09:38:50
- KSecDD KSecDD Kernel 01/03/2041 17:51:04
- KSecPkg KSecPkg Kernel 02/09/2061 04:23:07
- ksthunk Kernel Streaming Thunk Kernel 13/06/2020 00:29:26
- lltdio Link-Layer Topology Di Kernel 12/09/2087 12:48:37
- LSI_SAS LSI_SAS Kernel 25/03/2015 19:36:48
- LSI_SAS2i LSI_SAS2i Kernel 05/08/2016 15:08:34
- LSI_SAS3i LSI_SAS3i Kernel 08/08/2016 13:07:48
- LSI_SSS LSI_SSS Kernel 15/03/2013 23:39:38
- luafv UAC File Virtualizatio File System 08/06/2037 10:55:59
- mausbhost MA-USB Host Controller Kernel 18/07/2039 00:48:45
- mausbip MA-USB IP Filter Drive Kernel 18/07/2100 00:05:24
- megasas megasas Kernel 05/03/2015 02:36:29
- megasas2i megasas2i Kernel 22/07/2016 22:36:46
- megasr megasr Kernel 03/06/2013 23:02:39
- mlx4_bus Mellanox ConnectX Bus Kernel 10/04/2016 14:49:39
- MMCSS Multimedia Class Sched Kernel 15/09/2049 02:25:49
- Modem Modem Kernel 13/09/2094 13:41:38
- monitor Microsoft Monitor Clas Kernel 18/11/2014 01:45:15
- mouclass Mouse Class Driver Kernel 23/10/2035 15:38:45
- mouhid Mouse HID Driver Kernel 26/05/2090 11:52:31
- mountmgr Mount Point Manager Kernel 27/07/2094 16:10:51
- mpsdrv Windows Firewall Autho Kernel 27/11/1980 02:16:18
- MRxDAV WebDav Client Redirect File System 01/03/2052 05:11:57
- mrxsmb SMB MiniRedirector Wra File System 16/10/2004 02:47:34
- mrxsmb10 SMB 1.x MiniRedirector File System 06/09/2053 16:34:23
- mrxsmb20 SMB 2.0 MiniRedirector File System 13/09/2080 04:14:32
- MsBridge Microsoft MAC Bridge Kernel 12/05/1975 11:26:23
- Msfs Msfs File System 24/10/2000 12:07:15
- msgpiowin32 Common Driver for Butt Kernel 11/01/1982 06:02:43
- mshidkmdf Pass-through HID to KM Kernel 17/12/2018 13:08:26
- mshidumdf Pass-through HID to UM Kernel 14/07/2086 18:42:47
- msisadrv msisadrv Kernel 24/05/2069 17:53:03
- MSKSSRV Microsoft Streaming Se Kernel 04/02/2044 17:59:04
- MsLldp Microsoft Link-Layer D Kernel 16/10/2073 19:14:38
- MSPCLOCK Microsoft Streaming Cl Kernel 10/02/1993 13:28:02
- MSPQM Microsoft Streaming Qu Kernel 23/03/2058 10:23:03
- MsRPC MsRPC Kernel 17/01/1982 12:05:49
- mssmbios Microsoft System Manag Kernel 10/02/2070 05:40:28
- MSTEE Microsoft Streaming Te Kernel 28/10/1990 02:17:55
- MTConfig Microsoft Input Config Kernel 18/06/2024 04:06:38
- Mup Mup File System 30/11/2050 14:03:56
- mvumis mvumis Kernel 23/05/2014 21:39:04
- NativeWifiP NativeWiFi Filter Kernel 13/02/2003 08:44:49
- ndfltr NetworkDirect Service Kernel 10/04/2016 14:46:09
- NDIS NDIS System Driver Kernel 15/12/1981 05:19:38
- NdisCap Microsoft NDIS Capture Kernel 29/10/1982 06:29:24
- NdisImPlatfo Microsoft Network Adap Kernel 14/06/1978 03:11:23
- NdisTapi Remote Access NDIS TAP Kernel 11/04/2012 05:36:41
- Ndisuio NDIS Usermode I/O Prot Kernel 14/02/2104 04:22:17
- NdisVirtualB Microsoft Virtual Netw Kernel 05/01/2065 21:02:04
- NdisWan Remote Access NDIS WAN Kernel 30/11/2097 08:10:29
- ndiswanlegac Remote Access LEGACY N Kernel 30/11/2097 08:10:29
- ndproxy @%SystemRoot%\system32 Kernel 15/11/1988 07:08:24
- Ndu Windows Network Data U Kernel 08/07/2040 10:00:03
- NetAdapterCx Network Adapter Wdf Cl Kernel 24/08/2091 23:40:33
- NetBIOS NetBIOS Interface File System 21/07/2048 20:30:47
- NetBT NetBT Kernel 28/12/2064 12:10:38
- netr28x Ralink 802.11n Extensi Kernel 25/09/2012 09:10:07
- netvsc netvsc Kernel 25/12/1973 23:52:13
- Npfs Npfs File System 14/07/2030 23:34:01
- npsvctrig Named pipe service tri Kernel 25/07/2097 11:18:05
- nsiproxy NSI Proxy Service Driv Kernel 14/02/2093 00:25:01
- NTFS NTFS File System 06/07/1994 05:59:02
- NTIOLib_1_0_ NTIOLib_1_0_C Kernel 29/06/2011 02:57:56
- Null Null Kernel 15/07/2081 07:14:03
- nvdimmn Microsoft NVDIMM-N dev Kernel 21/10/2087 00:03:12
- NVHDA Service for NVIDIA Hig Kernel 08/02/2017 12:32:14
- nvlddmkm nvlddmkm Kernel 23/02/2017 07:38:50
- nvraid nvraid Kernel 21/04/2014 19:28:42
- nvstor nvstor Kernel 21/04/2014 19:34:03
- NVVADARM NVIDIA Miracast Audio Kernel 13/03/2015 16:15:56
- nvvad_WaveEx NVIDIA Virtual Audio D Kernel 20/11/2014 15:33:54
- Parport Parallel port driver Kernel 10/05/2059 02:00:32
- partmgr Partition driver Kernel 23/12/2025 13:10:05
- pci PCI Bus Driver Kernel 02/08/2025 10:15:37
- pciide pciide Kernel 15/04/1992 02:00:15
- pcmcia pcmcia Kernel 04/05/2055 04:46:24
- pcw Performance Counters f Kernel 10/01/1970 19:29:41
- pdc pdc Kernel 12/03/2034 12:41:46
- PEAUTH PEAUTH Kernel 10/12/1989 02:03:08
- percsas2i percsas2i Kernel 15/03/2016 00:50:11
- percsas3i percsas3i Kernel 04/03/2016 21:22:10
- pmem Microsoft persistent m Kernel 21/10/2067 05:47:22
- PptpMiniport WAN Miniport (PPTP) Kernel 10/02/2097 07:13:17
- Processor Processor Driver Kernel 06/03/1995 16:17:51
- Psched QoS Packet Scheduler Kernel 03/05/2072 01:51:28
- QWAVEdrv QWAVE driver Kernel 06/05/2100 18:01:39
- RasAcd Remote Access Auto Con Kernel 16/08/2004 23:15:01
- RasAgileVpn WAN Miniport (IKEv2) Kernel 04/05/2078 00:47:35
- Rasl2tp WAN Miniport (L2TP) Kernel 16/12/2073 14:16:30
- RasPppoe Remote Access PPPOE Dr Kernel 21/07/2061 08:38:01
- RasSstp WAN Miniport (SSTP) Kernel 06/12/2052 05:50:21
- rdbss Redirected Buffering S File System 15/06/2090 08:46:18
- rdpbus Remote Desktop Device Kernel 01/02/2004 21:17:30
- RDPDR Remote Desktop Device Kernel 10/03/2085 00:28:19
- RdpVideoMini Remote Desktop Video M Kernel 22/02/2001 04:39:13
- rdyboost ReadyBoost Kernel 30/08/2077 22:53:16
- ReFS ReFS File System 13/04/2042 07:13:32
- ReFSv1 ReFSv1 File System 08/05/1970 08:19:18
- rspndr Link-Layer Topology Di Kernel 20/05/1991 03:37:53
- rt640x64 Realtek RT640 NT Drive Kernel 14/07/2016 10:04:28
- RtlWlanu_Old Realtek Wireless LAN 8 Kernel 21/04/2016 02:43:34
- s3cap s3cap Kernel 20/11/2091 02:09:03
- sbp2port SBP-2 Transport/Protoc Kernel 14/09/2033 17:32:13
- scfilter Smart card PnP Class F Kernel 11/03/2088 06:32:31
- scmbus Microsoft Storage Clas Kernel 23/11/2077 11:35:32
- sdbus sdbus Kernel 10/10/1975 08:57:39
- SDFRd SDF Reflector Kernel 10/05/2089 04:19:49
- sdstor SD Storage Port Driver Kernel 04/01/2035 13:59:31
- SerCx Serial UART Support Li Kernel 13/04/2089 21:38:00
- SerCx2 Serial UART Support Li Kernel 31/10/2091 15:34:54
- Serenum Serenum Filter Driver Kernel 11/03/2095 12:29:34
- Serial Serial port driver Kernel 27/07/2023 02:01:20
- sermouse Serial Mouse Driver Kernel 26/08/1982 03:31:45
- sfloppy High-Capacity Floppy D Kernel 04/07/2008 18:35:22
- SiSRaid2 SiSRaid2 Kernel 24/09/2008 19:28:20
- SiSRaid4 SiSRaid4 Kernel 01/10/2008 22:56:04
- spaceport Storage Spaces Driver Kernel 25/04/2035 06:38:08
- SpatialGraph Holographic Spatial Gr Kernel 31/03/1994 18:54:15
- SpbCx Simple Peripheral Bus Kernel 22/12/2033 19:05:51
- srv Server SMB 1.xxx Drive File System 09/12/2041 14:57:28
- srv2 Server SMB 2.xxx Drive File System 08/04/2056 04:49:55
- srvnet srvnet File System 16/10/2013 16:29:36
- stexstor stexstor Kernel 27/11/2012 00:02:51
- storahci Microsoft Standard SAT Kernel 28/12/2071 08:20:00
- storflt Microsoft Hyper-V Stor Kernel 08/08/1988 18:12:33
- stornvme Microsoft Standard NVM Kernel 13/03/2001 07:19:09
- storqosflt Storage QoS Filter Dri File System 18/12/2015 03:36:27
- storufs Microsoft Universal Fl Kernel 08/12/2102 09:44:50
- storvsc storvsc Kernel 11/10/2000 13:58:13
- swenum Software Bus Driver Kernel 19/10/2068 23:12:20
- Synth3dVsc Synth3dVsc Kernel 17/01/2000 02:20:23
- Tcpip TCP/IP Protocol Driver Kernel 19/03/2092 18:08:44
- Tcpip6 @todo.dll,-100;Microso Kernel 19/03/2092 18:08:44
- tcpipreg TCP/IP Registry Compat Kernel 02/12/2097 03:06:07
- tdx NetIO Legacy TDI Suppo Kernel 01/04/2092 06:48:54
- terminpt Microsoft Remote Deskt Kernel 19/08/2067 03:33:46
- TPM TPM Kernel 18/04/2003 22:45:38
- TsUsbFlt Remote Desktop USB Hub Kernel 15/02/2055 00:14:40
- TsUsbGD Remote Desktop Generic Kernel 11/10/2001 15:37:50
- tunnel Microsoft Tunnel Minip Kernel 04/06/1981 23:42:24
- UASPStor USB Attached SCSI (UAS Kernel 12/06/2038 21:41:49
- UcmCx0101 USB Connector Manager Kernel 07/09/2029 05:11:02
- UcmTcpciCx01 UCM-TCPCI KMDF Class E Kernel 26/11/2018 15:10:48
- UcmUcsi USB Connector Manager Kernel 17/11/2030 01:56:35
- Ucx01000 USB Host Support Libra Kernel 22/02/1994 14:51:48
- UdeCx USB Device Emulation S Kernel 20/10/2094 03:28:22
- udfs udfs File System 10/06/1983 05:21:25
- UEFI Microsoft UEFI Driver Kernel 30/09/2022 22:36:44
- Ufx01000 USB Function Class Ext Kernel 24/06/1992 01:13:13
- UfxChipidea USB Chipidea Controlle Kernel 16/12/2030 16:45:43
- ufxsynopsys USB Synopsys Controlle Kernel 12/12/2018 20:36:49
- umbus UMBus Enumerator Drive Kernel 01/07/2025 15:26:17
- UmPass Microsoft UMPass Drive Kernel 29/09/2075 16:24:55
- UrsChipidea Chipidea USB Role-Swit Kernel 04/10/1990 15:28:10
- UrsCx01000 USB Role-Switch Suppor Kernel 19/08/2090 22:54:46
- UrsSynopsys Synopsys USB Role-Swit Kernel 06/07/2082 01:10:18
- usbccgp Microsoft USB Generic Kernel 21/07/2018 11:16:10
- usbcir eHome Infrared Receive Kernel 14/08/2021 20:58:51
- usbehci Microsoft USB 2.0 Enha Kernel 03/05/2066 15:42:10
- usbhub Microsoft USB Standard Kernel 22/01/1980 06:58:50
- USBHUB3 SuperSpeed Hub Kernel 07/09/2068 06:39:25
- usbohci Microsoft USB Open Hos Kernel 17/01/2047 13:50:11
- usbprint Microsoft USB PRINTER Kernel 13/08/1983 06:49:14
- usbser Microsoft USB Serial D Kernel 20/07/1978 08:09:07
- USBSTOR USB Mass Storage Drive Kernel 06/12/2090 10:31:44
- usbuhci Microsoft USB Universa Kernel 07/07/2079 13:39:02
- USBXHCI USB xHCI Compliant Hos Kernel 08/07/1989 06:08:55
- vdrvroot Microsoft Virtual Driv Kernel 27/06/2072 11:54:08
- VerifierExt VerifierExt Kernel 19/09/2105 17:47:11
- vhdmp vhdmp Kernel 07/12/1996 07:17:17
- vhf Virtual HID Framework Kernel 18/12/2014 02:46:15
- vmbus Virtual Machine Bus Kernel 20/03/2007 03:41:59
- VMBusHID VMBusHID Kernel 05/02/2016 19:49:01
- vmgid Microsoft Hyper-V Gues Kernel 20/03/2038 10:11:49
- volmgr Volume Manager Driver Kernel 05/05/2084 11:30:31
- volmgrx Dynamic Volume Manager Kernel 02/10/2082 04:55:30
- volsnap Volume Shadow Copy dri Kernel 08/01/2087 18:12:33
- volume Volume driver Kernel 02/05/2053 01:05:11
- vpci Microsoft Hyper-V Virt Kernel 10/10/2087 23:02:48
- vsmraid vsmraid Kernel 22/04/2014 20:21:41
- VSTXRAID VIA StorX Storage RAID Kernel 21/01/2013 19:00:28
- vwifibus Virtual Wireless Bus D Kernel 09/04/2065 14:36:26
- vwififlt Virtual WiFi Filter Dr Kernel 12/06/2032 13:15:16
- vwifimp Virtual WiFi Miniport Kernel 28/12/2104 03:12:46
- WacomPen Wacom Serial Pen HID D Kernel 31/03/2030 10:19:11
- wanarp Remote Access IP ARP D Kernel 28/05/1982 08:51:08
- wanarpv6 Remote Access IPv6 ARP Kernel 28/05/1982 08:51:08
- wcifs Windows Container Isol File System 14/02/2001 03:10:20
- wcnfs Windows Container Name File System 30/08/1990 10:18:50
- WdBoot Windows Defender Antiv Kernel 26/10/2038 04:26:40
- Wdf01000 Kernel Mode Driver Fra Kernel 13/09/1990 02:32:07
- WdFilter Windows Defender Antiv File System 04/10/2102 17:25:01
- wdiwifi WDI Driver Framework Kernel 19/10/2030 08:03:39
- WdNisDrv Windows Defender Antiv Kernel 17/11/1981 06:07:50
- WFPLWFS Microsoft Windows Filt Kernel 05/04/2010 20:35:50
- WIMMount WIMMount File System 20/06/2037 14:23:38
- WindowsTrust Windows Trusted Execut Kernel 19/03/2091 16:08:22
- WindowsTrust Microsoft Windows Trus Kernel 28/07/2006 14:32:40
- WinMad WinMad Service Kernel 10/04/2016 14:46:08
- WinNat Windows NAT Driver Kernel 05/08/2097 16:23:01
- WINUSB WinUsb Driver Kernel 18/07/1979 01:27:52
- WinVerbs WinVerbs Service Kernel 10/04/2016 14:46:10
- WmiAcpi Microsoft Windows Mana Kernel 23/07/1981 18:29:52
- Wof Windows Overlay File S File System 11/03/1974 22:47:45
- WpdUpFltr WPD Upper Class Filter Kernel 08/04/2102 12:39:04
- ws2ifsl Winsock IFS Driver Kernel 19/03/2010 00:40:36
- WudfPf User Mode Driver Frame Kernel 19/06/1986 04:58:15
- WUDFRd WUDFRd Kernel 15/03/2045 17:40:54
- WUDFWpdFs WUDFWpdFs Kernel 15/03/2045 17:40:54
- xboxgip Xbox Game Input Protoc Kernel 28/04/2055 09:35:57
- xinputhid XINPUT HID Filter Driv Kernel 14/09/2001 21:07:23
- *******************************************************************************
- ************************** GPresult infos **********************************
- Microsoft (R) Windows (R) Operating System Group Policy Result tool v2.0
- © 2017 Microsoft Corporation. All rights reserved.
- Created on ?29/?05/?2017 at 15:00:41
- RSOP data for DESKTOP-GU6TEMK\Cory Smith on DESKTOP-GU6TEMK : Logging Mode
- ---------------------------------------------------------------------------
- OS Configuration: Standalone Workstation
- OS Version: 10.0.15063
- Site Name: N/A
- Roaming Profile: N/A
- Local Profile: C:\Users\Cory Smith
- Connected over a slow link?: No
- USER SETTINGS
- --------------
- Last time Group Policy was applied: 29/05/2017 at 14:49:37
- Group Policy was applied from: N/A
- Group Policy slow link threshold: 500 kbps
- Domain Name: DESKTOP-GU6TEMK
- Domain Type: <Local Computer>
- Applied Group Policy Objects
- -----------------------------
- N/A
- The following GPOs were not applied because they were filtered out
- -------------------------------------------------------------------
- Local Group Policy
- Filtering: Not Applied (Empty)
- The user is a part of the following security groups
- ---------------------------------------------------
- None
- Everyone
- Local account and member of Administrators group
- BUILTIN\Administrators
- BUILTIN\Users
- NT AUTHORITY\INTERACTIVE
- CONSOLE LOGON
- NT AUTHORITY\Authenticated Users
- This Organization
- Local account
- LOCAL
- NTLM Authentication
- High Mandatory Level
- The user has the following security privileges
- ----------------------------------------------
- Bypass traverse checking
- Manage auditing and security log
- Back up files and directories
- Restore files and directories
- Change the system time
- Shut down the system
- Force shutdown from a remote system
- Take ownership of files or other objects
- Debug programs
- Modify firmware environment values
- Profile system performance
- Profile single process
- Increase scheduling priority
- Load and unload device drivers
- Create a pagefile
- Adjust memory quotas for a process
- Remove computer from docking station
- Perform volume maintenance tasks
- Impersonate a client after authentication
- Create global objects
- Change the time zone
- Create symbolic links
- Obtain an impersonation token for another user in the same session
- Increase a process working set
- Resultant Set Of Policies for User
- -----------------------------------
- Software Installations
- ----------------------
- N/A
- Logon Scripts
- -------------
- N/A
- Logoff Scripts
- --------------
- N/A
- Public Key Policies
- -------------------
- N/A
- Administrative Templates
- ------------------------
- N/A
- Folder Redirection
- ------------------
- N/A
- Internet Explorer Browser User Interface
- ----------------------------------------
- N/A
- Internet Explorer Connection
- ----------------------------
- N/A
- Internet Explorer URLs
- ----------------------
- N/A
- Internet Explorer Security
- --------------------------
- N/A
- Internet Explorer Programs
- --------------------------
- N/A
- *******************************************************************************
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
- OneDrive REG_SZ "C:\Users\Cory Smith\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
- Steam REG_SZ "C:\Program Files (x86)\Steam\steam.exe" -silent
- *************************************************************************************************
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
- SecurityHealth REG_EXPAND_SZ %PROGRAMFILES%\Windows Defender\MSASCuiL.exe
- NvBackend REG_SZ "C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
- ShadowPlay REG_SZ C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
- RTHDVCPL REG_SZ "C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
- *************************************************************************************************
- *************************************************************************************************
- *************************************************************************************************
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WinLogon
- ExcludeProfileDirs REG_SZ AppData\Local;AppData\LocalLow;$Recycle.Bin;OneDrive;Work Folders
- BuildNumber REG_DWORD 0x3ad7
- FirstLogon REG_DWORD 0x0
- PUUActive REG_BINARY 3A3934BC010001000B001000894F0000B75100008C090200D100000002000900D9F26CD45D2202009D6C000025270000C4210000F7050000000000004A6700000B0B00004200000003FA963282D8D201894F0000000000000100000000000000
- DP REG_BINARY CE005800030001000B0000003A3934BCF5FC26000000000003FA963282D8D201B8639D3F7CD8D201DB392500000000001BB6110000000000000000000000000000000000A41E000000000000000000000000000000000000
- ParseAutoexec REG_SZ 1
- *************************************************************************************************
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WinLogon
- AutoRestartShell REG_DWORD 0x1
- Background REG_SZ 0 0 0
- CachedLogonsCount REG_SZ 10
- DebugServerCommand REG_SZ no
- DefaultDomainName REG_SZ
- DefaultUserName REG_SZ Cory Smith
- DisableBackButton REG_DWORD 0x1
- EnableSIHostIntegration REG_DWORD 0x1
- ForceUnlockLogon REG_DWORD 0x0
- LegalNoticeCaption REG_SZ
- LegalNoticeText REG_SZ
- PasswordExpiryWarning REG_DWORD 0x5
- PowerdownAfterShutdown REG_SZ 0
- PreCreateKnownFolders REG_SZ {A520A1A4-1780-4FF6-BD18-167343C5AF16}
- ReportBootOk REG_SZ 1
- Shell REG_SZ explorer.exe
- ShellCritical REG_DWORD 0x0
- ShellInfrastructure REG_SZ sihost.exe
- SiHostCritical REG_DWORD 0x0
- SiHostReadyTimeOut REG_DWORD 0x0
- SiHostRestartCountLimit REG_DWORD 0x0
- SiHostRestartTimeGap REG_DWORD 0x0
- Userinit REG_SZ C:\Windows\system32\userinit.exe,
- VMApplet REG_SZ SystemPropertiesPerformance.exe /pagefile
- WinStationsDisabled REG_SZ 0
- scremoveoption REG_SZ 0
- DisableCAD REG_DWORD 0x1
- LastLogOffEndTimePerfCounter REG_QWORD 0x33788de650
- ShutdownFlags REG_DWORD 0xa7
- AutoAdminLogon REG_SZ 0
- DisableLockWorkstation REG_DWORD 0x0
- EnableFirstLogonAnimation REG_DWORD 0x1
- AutoLogonSID REG_SZ S-1-5-21-3729940396-3466973117-3832101617-1001
- LastUsedUsername REG_SZ Cory Smith
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WinLogon\AlternateShells
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WinLogon\GPExtensions
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WinLogon\GPExtensions\{0ACDD40C-75AC-47ab-BAA0-BF6DE7E7FE63}
- (Default) REG_SZ Wireless Group Policy
- DisplayName REG_EXPAND_SZ @wlgpclnt.dll,-100
- DllName REG_EXPAND_SZ wlgpclnt.dll
- GenerateGroupPolicy REG_SZ GenerateWLANPolicy
- NoGPOListChanges REG_DWORD 0x1
- NoUserPolicy REG_DWORD 0x1
- ProcessGroupPolicyEx REG_SZ ProcessWLANPolicyEx
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WinLogon\GPExtensions\{16be69fa-4209-4250-88cb-716cf41954e0}
- (Default) REG_SZ Central Access Policy Configuration
- DisplayName REG_EXPAND_SZ @auditcse.dll,-4000
- DllName REG_EXPAND_SZ auditcse.dll
- EnableAsynchronousProcessing REG_DWORD 0x1
- ForceRefreshFG REG_DWORD 0x0
- GenerateGroupPolicy REG_SZ GenerateGroupPolicyCap
- MaxNoGPOListChangesInterval REG_DWORD 0x78
- NoUserPolicy REG_DWORD 0x1
- ProcessGroupPolicyEx REG_SZ ProcessGroupPolicyExCap
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WinLogon\GPExtensions\{25537BA6-77A8-11D2-9B6C-0000F8080861}
- (Default) REG_SZ Folder Redirection
- DisplayName REG_EXPAND_SZ @fdeploy.dll,-261
- DllName REG_EXPAND_SZ fdeploy.dll
- EventSources REG_MULTI_SZ (Folder Redirection,Application)
- GenerateGroupPolicy REG_SZ GenerateGroupPolicy
- NoBackgroundPolicy REG_DWORD 0x0
- NoGPOListChanges REG_DWORD 0x0
- NoMachinePolicy REG_DWORD 0x1
- NoSlowLink REG_DWORD 0x1
- PerUserLocalSettings REG_DWORD 0x1
- ProcessGroupPolicyEx REG_SZ ProcessGroupPolicyEx
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WinLogon\GPExtensions\{35378EAC-683F-11D2-A89A-00C04FBBCFA2}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WinLogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66}
- (Default) REG_SZ Microsoft Disk Quota
- DisplayName REG_EXPAND_SZ @%SystemRoot%\System32\dskquota.dll,-100
- DllName REG_EXPAND_SZ %SystemRoot%\System32\dskquota.dll
- EnableAsynchronousProcessing REG_DWORD 0x0
- NoBackgroundPolicy REG_DWORD 0x0
- NoGPOListChanges REG_DWORD 0x1
- NoMachinePolicy REG_DWORD 0x0
- NoSlowLink REG_DWORD 0x1
- NoUserPolicy REG_DWORD 0x1
- PerUserLocalSettings REG_DWORD 0x0
- ProcessGroupPolicy REG_SZ ProcessGroupPolicy
- RequiresSuccessfulRegistry REG_DWORD 0x1
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WinLogon\GPExtensions\{426031c0-0b47-4852-b0ca-ac3d37bfcb39}
- (Default) REG_SZ QoS Packet Scheduler
- DisplayName REG_EXPAND_SZ @gptext.dll,-201
- DllName REG_EXPAND_SZ gptext.dll
- NoGPOListChanges REG_DWORD 0x1
- NoUserPolicy REG_DWORD 0x1
- ProcessGroupPolicy REG_SZ ProcessPSCHEDPolicy
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WinLogon\GPExtensions\{4bcd6cde-777b-48b6-9804-43568e23545d}
- (Default) REG_SZ Remote Desktop USB Redirection
- DisplayName REG_EXPAND_SZ @%SystemRoot%\System32\TsUsbRedirectionGroupPolicyExtension.dll,-100
- DllName REG_EXPAND_SZ %SystemRoot%\System32\TsUsbRedirectionGroupPolicyExtension.dll
- NoBackgroundPolicy REG_DWORD 0x0
- NoGPOListChanges REG_DWORD 0x1
- NoUserPolicy REG_DWORD 0x1
- ProcessGroupPolicyEx REG_SZ ProcessGroupPolicyEx
- RequiresSuccessfulRegistry REG_DWORD 0x1
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WinLogon\GPExtensions\{4CFB60C1-FAA6-47f1-89AA-0B18730C9FD3}
- (Default) REG_SZ Internet Explorer Zonemapping
- DisplayName REG_SZ @C:\Windows\System32\iedkcs32.dll,-3051
- DllName REG_SZ C:\Windows\System32\iedkcs32.dll
- NoGPOListChanges REG_DWORD 0x1
- ProcessGroupPolicy REG_SZ ProcessGroupPolicyForZoneMap
- RequiresSuccessfulRegistry REG_DWORD 0x1
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WinLogon\GPExtensions\{4D2F9B6F-1E52-4711-A382-6A8B1A003DE6}
- DllName REG_SZ C:\Windows\System32\tsworkspace.dll
- NoMachinePolicy REG_DWORD 0x1
- PerUserLocalSettings REG_DWORD 0x1
- ProcessGroupPolicyEx REG_SZ RADCProcessGroupPolicyEx
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WinLogon\GPExtensions\{4d968b55-cac2-4ff5-983f-0a54603781a3}
- (Default) REG_SZ Work Folders
- DisplayName REG_EXPAND_SZ @WorkFoldersGPExt.dll,-261
- DllName REG_EXPAND_SZ WorkFoldersGPExt.dll
- EnableAsynchronousProcessing REG_DWORD 0x0
- NoBackgroundPolicy REG_DWORD 0x0
- NoGPOListChanges REG_DWORD 0x0
- NoMachinePolicy REG_DWORD 0x0
- NoSlowLink REG_DWORD 0x0
- NoUserPolicy REG_DWORD 0x0
- PerUserLocalSettings REG_DWORD 0x0
- ProcessGroupPolicy REG_SZ ProcessGroupPolicy
- RequiresSuccessfulRegistry REG_DWORD 0x1
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WinLogon\GPExtensions\{7933F41E-56F8-41d6-A31C-4148A711EE93}
- (Default) REG_SZ Windows Search Group Policy Extension
- DllName REG_EXPAND_SZ %SystemRoot%\System32\srchadmin.dll
- EnableAsynchronousProcessing REG_DWORD 0x1
- NoBackgroundPolicy REG_DWORD 0x0
- NoGPOListChanges REG_DWORD 0x1
- NoMachinePolicy REG_DWORD 0x0
- NoSlowLink REG_DWORD 0x0
- NoUserPolicy REG_DWORD 0x0
- PerUserLocalSettings REG_DWORD 0x0
- ProcessGroupPolicy REG_SZ ProcessGroupPolicy
- RequiresSuccessfulRegistry REG_DWORD 0x1
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WinLogon\GPExtensions\{7B849a69-220F-451E-B3FE-2CB811AF94AE}
- (Default) REG_SZ Internet Explorer User Accelerators
- DisplayName REG_SZ @C:\Windows\System32\iedkcs32.dll,-3051
- DllName REG_SZ C:\Windows\System32\iedkcs32.dll
- NoGPOListChanges REG_DWORD 0x1
- ProcessGroupPolicy REG_SZ ProcessGroupPolicyForActivities
- ProcessGroupPolicyEx REG_SZ ProcessGroupPolicyForActivitiesEx
- RequiresSuccessfulRegistry REG_DWORD 0x1
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WinLogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A}
- (Default) REG_SZ Security
- DisplayName REG_EXPAND_SZ @(runtime.system32)\scecli.dll,-7650
- DllName REG_EXPAND_SZ scecli.dll
- EnableAsynchronousProcessing REG_DWORD 0x1
- ExtensionDebugLevel REG_DWORD 0x0
- ExtensionRsopPlanningDebugLevel REG_DWORD 0x1
- GenerateGroupPolicy REG_SZ SceGenerateGroupPolicy
- MaxNoGPOListChangesInterval REG_DWORD 0x1
- NoGPOListChanges REG_DWORD 0x1
- NoUserPolicy REG_DWORD 0x1
- ProcessGroupPolicy REG_SZ SceProcessSecurityPolicyGPO
- ProcessGroupPolicyEx REG_SZ SceProcessSecurityPolicyGPOEx
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WinLogon\GPExtensions\{8A28E2C5-8D06-49A4-A08C-632DAA493E17}
- (Default) REG_SZ Deployed Printer Connections
- DisplayName REG_EXPAND_SZ @%systemroot%\system32\gpprnext.dll,-1
- DllName REG_EXPAND_SZ %systemroot%\system32\gpprnext.dll
- EnableAsynchronousProcessing REG_DWORD 0x1
- ExtensionEventSource REG_SZ
- GenerateGroupPolicy REG_SZ PrinterGenerateGroupPolicy
- MaxNoGPOListChangesInterval REG_DWORD 0x0
- NoBackgroundPolicy REG_DWORD 0x0
- NoGPOListChanges REG_DWORD 0x0
- NoMachinePolicy REG_DWORD 0x0
- NoSlowLink REG_DWORD 0x1
- NotifyLinkTransition REG_DWORD 0x0
- NoUserPolicy REG_DWORD 0x0
- PerUserLocalSettings REG_DWORD 0x0
- ProcessGroupPolicy REG_SZ PrinterProcessGroupPolicy
- ProcessGroupPolicyEx REG_SZ PrinterProcessGroupPolicyEx
- RequiresSuccessfulRegistry REG_DWORD 0x0
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WinLogon\GPExtensions\{B587E2B1-4D59-4e7e-AED9-22B9DF11D053}
- (Default) REG_SZ 802.3 Group Policy
- DisplayName REG_EXPAND_SZ @dot3gpclnt.dll,-100
- DllName REG_EXPAND_SZ dot3gpclnt.dll
- GenerateGroupPolicy REG_SZ GenerateLANPolicy
- NoGPOListChanges REG_DWORD 0x1
- NoUserPolicy REG_DWORD 0x1
- ProcessGroupPolicyEx REG_SZ ProcessLANPolicyEx
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WinLogon\GPExtensions\{BA649533-0AAC-4E04-B9BC-4DBAE0325B12}
- (Default) REG_SZ Windows To Go Startup Options
- DllName REG_EXPAND_SZ pwlauncher.dll
- ProcessGroupPolicy REG_SZ ProcessLauncherGroupPolicy
- RequiresSuccessfulRegistry REG_DWORD 0x1
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WinLogon\GPExtensions\{C34B2751-1CF4-44F5-9262-C3FC39666591}
- (Default) REG_SZ Windows To Go Hibernate Options
- DllName REG_EXPAND_SZ pwlauncher.dll
- ProcessGroupPolicy REG_SZ ProcessHibernateGroupPolicy
- RequiresSuccessfulRegistry REG_DWORD 0x1
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WinLogon\GPExtensions\{cdeafc3d-948d-49dd-ab12-e578ba4af7aa}
- (Default) REG_SZ TCPIP
- DisplayName REG_EXPAND_SZ @gptext.dll,-204
- DllName REG_EXPAND_SZ gptext.dll
- NoGPOListChanges REG_DWORD 0x1
- NoUserPolicy REG_DWORD 0x1
- ProcessGroupPolicy REG_SZ ProcessTCPIPPolicy
- RequiresSuccessfulRegistry REG_DWORD 0x1
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WinLogon\GPExtensions\{CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}
- (Default) REG_SZ Internet Explorer Machine Accelerators
- DisplayName REG_SZ @C:\Windows\System32\iedkcs32.dll,-3051
- DllName REG_SZ C:\Windows\System32\iedkcs32.dll
- NoGPOListChanges REG_DWORD 0x1
- ProcessGroupPolicy REG_SZ ProcessGroupPolicyForActivities
- ProcessGroupPolicyEx REG_SZ ProcessGroupPolicyForActivitiesEx
- RequiresSuccessfulRegistry REG_DWORD 0x1
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WinLogon\GPExtensions\{e437bc1c-aa7d-11d2-a382-00c04f991e27}
- (Default) REG_SZ IP Security
- DisplayName REG_EXPAND_SZ @C:\Windows\System32\polstore.dll,-5012
- DllName REG_EXPAND_SZ %SystemRoot%\System32\polstore.dll
- GenerateGroupPolicy REG_SZ GenerateIPSECPolicy
- NoGPOListChanges REG_DWORD 0x0
- NoUserPolicy REG_DWORD 0x1
- ProcessGroupPolicyEx REG_SZ ProcessIPSECPolicyEx
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WinLogon\GPExtensions\{f3ccc681-b74c-4060-9f26-cd84525dca2a}
- (Default) REG_SZ Audit Policy Configuration
- DisplayName REG_EXPAND_SZ @auditcse.dll,-3000
- DllName REG_EXPAND_SZ auditcse.dll
- EnableAsynchronousProcessing REG_DWORD 0x1
- ForceRefreshFG REG_DWORD 0x0
- GenerateGroupPolicy REG_SZ GenerateGroupPolicy
- MaxNoGPOListChangesInterval REG_DWORD 0x3c0
- NoUserPolicy REG_DWORD 0x1
- ProcessGroupPolicyEx REG_SZ ProcessGroupPolicyEx
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WinLogon\GPExtensions\{FB2CA36D-0B40-4307-821B-A13B252DE56C}
- (Default) REG_SZ Enterprise QoS
- DisplayName REG_EXPAND_SZ @gptext.dll,-203
- DllName REG_EXPAND_SZ gptext.dll
- ProcessGroupPolicy REG_SZ ProcessEQoSPolicy
- RequiresSuccessfulRegistry REG_DWORD 0x1
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WinLogon\GPExtensions\{fbf687e6-f063-4d9f-9f4f-fd9a26acdd5f}
- (Default) REG_SZ CP
- DisplayName REG_EXPAND_SZ @gptext.dll,-205
- DllName REG_EXPAND_SZ gptext.dll
- NoGPOListChanges REG_DWORD 0x1
- NoUserPolicy REG_DWORD 0x1
- ProcessGroupPolicy REG_SZ ProcessConnectivityPlatformPolicy
- RequiresSuccessfulRegistry REG_DWORD 0x1
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WinLogon\AutoLogonChecked
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WinLogon\VolatileUserMgrKey
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WinLogon\VolatileUserMgrKey\1
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WinLogon\VolatileUserMgrKey\1\S-1-5-21-3729940396-3466973117-3832101617-1001
- contextLuid REG_QWORD 0x3875f
- *************************************************************************************************
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
- Device REG_SZ
- IsMRUEstablished REG_DWORD 0xffffffff
- LegacyDefaultPrinterMode REG_DWORD 0xffffffff
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\InteractiveControl
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Pen
- PenArbitrationType REG_DWORD 0x3
- *************************************************************************************************
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
- (Default) REG_SZ mnmsrvc
- AppInit_DLLs REG_SZ
- DdeSendTimeout REG_DWORD 0x0
- DesktopHeapLogging REG_DWORD 0x1
- DeviceNotSelectedTimeout REG_SZ 15
- DwmInputUsesIoCompletionPort REG_DWORD 0x1
- EnableDwmInputProcessing REG_DWORD 0x7
- EnableMitInputProcessing REG_DWORD 0x7
- GDIProcessHandleQuota REG_DWORD 0x2710
- IconServiceLib REG_SZ IconCodecService.dll
- LoadAppInit_DLLs REG_DWORD 0x0
- NaturalInputHandler REG_SZ Ninput.dll
- ShutdownWarningDialogTimeout REG_DWORD 0xffffffff
- Spooler REG_SZ yes
- ThreadUnresponsiveLogTimeout REG_DWORD 0x1f4
- TransmissionRetryTimeout REG_SZ 90
- USERNestedWindowLimit REG_DWORD 0x32
- USERPostMessageLimit REG_DWORD 0x2710
- USERProcessHandleQuota REG_DWORD 0x2710
- Win32kLastWriteTime REG_SZ 1D2A02A4539A47C
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Win32kWPP
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Win32kWPP\Parameters
- ForceLogsInMiniDump REG_DWORD 0x1
- LogPages REG_DWORD 0x14
- Verbose REG_DWORD 0x1
- WppRecorder_PerBufferMaxBytes REG_DWORD 0x14000
- WppRecorder_PerBufferMinBytes REG_DWORD 0x200
- WppRecorder_TraceGuid REG_SZ {335d5e04-5638-4e58-aa36-7ed1cfe76fd6}
- *************************************************************************************************
- HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
- Anchor Underline REG_SZ yes
- Cache_Update_Frequency REG_SZ yes
- Disable Script Debugger REG_SZ yes
- DisableScriptDebuggerIE REG_SZ yes
- Display Inline Images REG_SZ yes
- Do404Search REG_BINARY 01000000
- Local Page REG_SZ %11%\blank.htm
- Save_Session_History_On_Exit REG_SZ no
- Search Page REG_SZ http://go.microsoft.com/fwlink/?LinkId=54896
- Show_FullURL REG_SZ no
- Show_StatusBar REG_SZ yes
- Show_ToolBar REG_SZ yes
- Show_URLinStatusBar REG_SZ yes
- Show_URLToolBar REG_SZ yes
- Use_DlgBox_Colors REG_SZ yes
- UseClearType REG_SZ no
- XMLHTTP REG_DWORD 0x1
- Enable Browser Extensions REG_SZ yes
- Play_Background_Sounds REG_SZ yes
- Play_Animations REG_SZ yes
- Start Page REG_SZ http://go.microsoft.com/fwlink/p/?LinkId=255141
- ImageStoreRandomFolder REG_SZ 7lopntm
- HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl
- HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION
- OneDrive.exe REG_DWORD 0x2af8
- HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_CROSS_DOMAIN_REDIRECT_MITIGATION
- HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SCRIPTURL_MITIGATION
- *************************************************************************************************
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\chrome.exe
- MaxLoaderThreads REG_DWORD 0x1
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cscript.exe
- DisableExceptionChainValidation REG_DWORD 0x3
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dllhost.exe
- DisableExceptionChainValidation REG_DWORD 0x3
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions
- Apitrap.dll REG_DWORD 0x1
- ASSTE.dll REG_DWORD 0x1
- AVSTE.dll REG_DWORD 0x1
- Cleanup.dll REG_DWORD 0x1
- divx.dll REG_DWORD 0x1
- divxdec.ax REG_DWORD 0x1
- DJSMAR00.dll REG_DWORD 0x1
- DRMINST.dll REG_DWORD 0x1
- eMigrationmmc.dll REG_DWORD 0x1
- EncryptPatchVer.dll REG_DWORD 0x1
- eProcedureMMC.dll REG_DWORD 0x1
- eQueryMMC.dll REG_DWORD 0x1
- fullsoft.dll REG_DWORD 0x1
- ISSTE.dll REG_DWORD 0x1
- javai.dll REG_DWORD 0x1
- jvm.dll REG_DWORD 0x1
- jvm_g.dll REG_DWORD 0x1
- main123w.dll REG_DWORD 0x1
- msci_uno.dll REG_DWORD 0x1
- mscoree.dll REG_DWORD 0x1
- mscorsvr.dll REG_DWORD 0x1
- mscorwks.dll REG_DWORD 0x1
- msjava.dll REG_DWORD 0x1
- mso.dll REG_DWORD 0x1
- NAVOPTRF.dll REG_DWORD 0x1
- NPMLIC.dll REG_DWORD 0x1
- NSWSTE.dll REG_DWORD 0x1
- PMSTE.dll REG_DWORD 0x1
- ppw32hlp.dll REG_DWORD 0x1
- symlcnet.dll REG_DWORD 0x1
- TFDTCTT8.dll REG_DWORD 0x1
- udtapi.dll REG_DWORD 0x1
- ums.dll REG_DWORD 0x1
- vb40032.dll REG_DWORD 0x1
- vbe6.dll REG_DWORD 0x1
- Vegas60k.dll REG_DWORD 0x1
- xlmlEN.dll REG_DWORD 0x1
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\drvinst.exe
- DisableExceptionChainValidation REG_DWORD 0x3
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ehexthost32.exe
- DisableExceptionChainValidation REG_DWORD 0x3
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\explorer.exe
- DisableExceptionChainValidation REG_DWORD 0x3
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ExtExport.exe
- MitigationOptions REG_QWORD 0x100
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GoogleUpdate.exe
- DisableExceptionChainValidation REG_DWORD 0x0
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ie4uinit.exe
- MitigationOptions REG_QWORD 0x100
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ieinstal.exe
- MitigationOptions REG_QWORD 0x100
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ielowutil.exe
- MitigationOptions REG_QWORD 0x100
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ieUnatt.exe
- MitigationOptions REG_QWORD 0x100
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iexplore.exe
- DisableExceptionChainValidation REG_DWORD 0x0
- DisableUserModeCallbackFilter REG_DWORD 0x1
- MitigationOptions REG_QWORD 0x100
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MiracastView.exe
- MitigationOptions REG_QWORD 0x100000000
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mmc.exe
- DisableExceptionChainValidation REG_DWORD 0x3
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MRT.exe
- CFGOptions REG_DWORD 0x1
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mscorsvw.exe
- MitigationOptions REG_QWORD 0x100000000
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msfeedssync.exe
- MitigationOptions REG_QWORD 0x100
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mshta.exe
- MitigationOptions REG_QWORD 0x100
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MsMpEng.exe
- CFGOptions REG_DWORD 0x1
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ngen.exe
- MitigationOptions REG_QWORD 0x100000000
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ngentask.exe
- MitigationOptions REG_QWORD 0x100000000
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PresentationHost.exe
- MitigationOptions REG_QWORD 0x111111
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PrintDialog.exe
- MitigationOptions REG_QWORD 0x100000000
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PrintIsolationHost.exe
- MitigationOptions REG_QWORD 0x200000
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rundll32.exe
- DisableExceptionChainValidation REG_DWORD 0x3
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\runtimebroker.exe
- MitigationOptions REG_QWORD 0x100000000
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotocolhost.exe
- DisableExceptionChainValidation REG_DWORD 0x3
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\splwow64.exe
- MitigationOptions REG_QWORD 0x200000
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\spoolsv.exe
- DisableExceptionChainValidation REG_DWORD 0x3
- MitigationOptions REG_QWORD 0x200000
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\svchost.exe
- MinimumStackCommitInBytes REG_DWORD 0x8000
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SystemSettings.exe
- MitigationOptions REG_QWORD 0x100000000
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wscript.exe
- DisableExceptionChainValidation REG_DWORD 0x3
- *************************************************************************************************
- Startup files in Startup folders
- *****************************************************************************************************
- ******************************************************************************
- ******************************************************************************
- STARTUP List
- ******************************************************************************
- Caption=OneDriveSetup
- Command=C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup
- Description=OneDriveSetup
- Location=HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
- Name=OneDriveSetup
- SettingID=
- User=NT AUTHORITY\LOCAL SERVICE
- UserSID=S-1-5-19
- Caption=OneDriveSetup
- Command=C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup
- Description=OneDriveSetup
- Location=HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
- Name=OneDriveSetup
- SettingID=
- User=NT AUTHORITY\NETWORK SERVICE
- UserSID=S-1-5-20
- Caption=OneDrive
- Command="C:\Users\Cory Smith\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
- Description=OneDrive
- Location=HKU\S-1-5-21-3729940396-3466973117-3832101617-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
- Name=OneDrive
- SettingID=
- User=DESKTOP-GU6TEMK\Cory Smith
- UserSID=S-1-5-21-3729940396-3466973117-3832101617-1001
- Caption=Steam
- Command="C:\Program Files (x86)\Steam\steam.exe" -silent
- Description=Steam
- Location=HKU\S-1-5-21-3729940396-3466973117-3832101617-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
- Name=Steam
- SettingID=
- User=DESKTOP-GU6TEMK\Cory Smith
- UserSID=S-1-5-21-3729940396-3466973117-3832101617-1001
- Caption=SecurityHealth
- Command=%PROGRAMFILES%\Windows Defender\MSASCuiL.exe
- Description=SecurityHealth
- Location=HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
- Name=SecurityHealth
- SettingID=
- User=Public
- UserSID=
- Caption=NvBackend
- Command="C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
- Description=NvBackend
- Location=HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
- Name=NvBackend
- SettingID=
- User=Public
- UserSID=
- Caption=ShadowPlay
- Command=C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
- Description=ShadowPlay
- Location=HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
- Name=ShadowPlay
- SettingID=
- User=Public
- UserSID=
- Caption=RTHDVCPL
- Command="C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
- Description=RTHDVCPL
- Location=HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
- Name=RTHDVCPL
- SettingID=
- User=Public
- UserSID=
- ******************************************************************************
- Process List
- ******************************************************************************
- ProcessID : 0
- ProcessName : System Idle Process
- Handle : 0
- commandline :
- ExecutablePath :
- ProcessID : 4
- ProcessName : System
- Handle : 4
- commandline :
- ExecutablePath :
- ProcessID : 428
- ProcessName : smss.exe
- Handle : 428
- commandline :
- ExecutablePath :
- ProcessID : 628
- ProcessName : csrss.exe
- Handle : 628
- commandline :
- ExecutablePath :
- ProcessID : 732
- ProcessName : wininit.exe
- Handle : 732
- commandline :
- ExecutablePath :
- ProcessID : 748
- ProcessName : csrss.exe
- Handle : 748
- commandline :
- ExecutablePath :
- ProcessID : 808
- ProcessName : services.exe
- Handle : 808
- commandline :
- ExecutablePath :
- ProcessID : 816
- ProcessName : lsass.exe
- Handle : 816
- commandline : C:\Windows\system32\lsass.exe
- ExecutablePath : C:\Windows\system32\lsass.exe
- ProcessID : 896
- ProcessName : winlogon.exe
- Handle : 896
- commandline : winlogon.exe
- ExecutablePath : C:\Windows\system32\winlogon.exe
- ProcessID : 996
- ProcessName : svchost.exe
- Handle : 996
- commandline : c:\windows\system32\svchost.exe -k dcomlaunch -s PlugPlay
- ExecutablePath : c:\windows\system32\svchost.exe
- ProcessID : 1004
- ProcessName : fontdrvhost.exe
- Handle : 1004
- commandline : "fontdrvhost.exe"
- ExecutablePath : C:\Windows\system32\fontdrvhost.exe
- ProcessID : 1012
- ProcessName : fontdrvhost.exe
- Handle : 1012
- commandline : "fontdrvhost.exe"
- ExecutablePath : C:\Windows\system32\fontdrvhost.exe
- ProcessID : 496
- ProcessName : svchost.exe
- Handle : 496
- commandline : C:\Windows\system32\svchost.exe -k DcomLaunch
- ExecutablePath : C:\Windows\system32\svchost.exe
- ProcessID : 512
- ProcessName : svchost.exe
- Handle : 512
- commandline : c:\windows\system32\svchost.exe -k rpcss
- ExecutablePath : c:\windows\system32\svchost.exe
- ProcessID : 1052
- ProcessName : svchost.exe
- Handle : 1052
- commandline : c:\windows\system32\svchost.exe -k dcomlaunch -s LSM
- ExecutablePath : c:\windows\system32\svchost.exe
- ProcessID : 1128
- ProcessName : dwm.exe
- Handle : 1128
- commandline : "dwm.exe"
- ExecutablePath : C:\Windows\system32\dwm.exe
- ProcessID : 1264
- ProcessName : svchost.exe
- Handle : 1264
- commandline : C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
- ExecutablePath : C:\Windows\system32\svchost.exe
- ProcessID : 1316
- ProcessName : svchost.exe
- Handle : 1316
- commandline : c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s NcbService
- ExecutablePath : c:\windows\system32\svchost.exe
- ProcessID : 1324
- ProcessName : svchost.exe
- Handle : 1324
- commandline : c:\windows\system32\svchost.exe -k localservicenetworkrestricted -s TimeBrokerSvc
- ExecutablePath : c:\windows\system32\svchost.exe
- ProcessID : 1384
- ProcessName : svchost.exe
- Handle : 1384
- commandline : c:\windows\system32\svchost.exe -k netsvcs -s Schedule
- ExecutablePath : c:\windows\system32\svchost.exe
- ProcessID : 1432
- ProcessName : svchost.exe
- Handle : 1432
- commandline : c:\windows\system32\svchost.exe -k netsvcs -s ProfSvc
- ExecutablePath : c:\windows\system32\svchost.exe
- ProcessID : 1476
- ProcessName : svchost.exe
- Handle : 1476
- commandline : c:\windows\system32\svchost.exe -k localservicenetworkrestricted -s EventLog
- ExecutablePath : c:\windows\system32\svchost.exe
- ProcessID : 1544
- ProcessName : svchost.exe
- Handle : 1544
- commandline : c:\windows\system32\svchost.exe -k netsvcs -s UserManager
- ExecutablePath : c:\windows\system32\svchost.exe
- ProcessID : 1568
- ProcessName : svchost.exe
- Handle : 1568
- commandline : c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s hidserv
- ExecutablePath : c:\windows\system32\svchost.exe
- ProcessID : 1672
- ProcessName : tbaseprovisioning.exe
- Handle : 1672
- commandline : C:\Windows\SysWOW64\tbaseprovisioning.exe
- ExecutablePath : C:\Windows\SysWOW64\tbaseprovisioning.exe
- ProcessID : 1748
- ProcessName : svchost.exe
- Handle : 1748
- commandline : c:\windows\system32\svchost.exe -k localservice -s nsi
- ExecutablePath : c:\windows\system32\svchost.exe
- ProcessID : 1788
- ProcessName : svchost.exe
- Handle : 1788
- commandline : c:\windows\system32\svchost.exe -k localservicenetworkrestricted -s Dhcp
- ExecutablePath : c:\windows\system32\svchost.exe
- ProcessID : 1848
- ProcessName : svchost.exe
- Handle : 1848
- commandline : c:\windows\system32\svchost.exe -k networkservice -s NlaSvc
- ExecutablePath : c:\windows\system32\svchost.exe
- ProcessID : 1916
- ProcessName : svchost.exe
- Handle : 1916
- commandline : c:\windows\system32\svchost.exe -k netsvcs -s Themes
- ExecutablePath : c:\windows\system32\svchost.exe
- ProcessID : 1924
- ProcessName : svchost.exe
- Handle : 1924
- commandline : c:\windows\system32\svchost.exe -k localservice -s EventSystem
- ExecutablePath : c:\windows\system32\svchost.exe
- ProcessID : 2000
- ProcessName : svchost.exe
- Handle : 2000
- commandline : c:\windows\system32\svchost.exe -k localservice -s netprofm
- ExecutablePath : c:\windows\system32\svchost.exe
- ProcessID : 1868
- ProcessName : svchost.exe
- Handle : 1868
- commandline : c:\windows\system32\svchost.exe -k netsvcs -s SENS
- ExecutablePath : c:\windows\system32\svchost.exe
- ProcessID : 2076
- ProcessName : svchost.exe
- Handle : 2076
- commandline : c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s AudioEndpointBuilder
- ExecutablePath : c:\windows\system32\svchost.exe
- ProcessID : 2084
- ProcessName : svchost.exe
- Handle : 2084
- commandline : c:\windows\system32\svchost.exe -k localservice -s FontCache
- ExecutablePath : c:\windows\system32\svchost.exe
- ProcessID : 2152
- ProcessName : svchost.exe
- Handle : 2152
- commandline : c:\windows\system32\svchost.exe -k netsvcs -s Winmgmt
- ExecutablePath : c:\windows\system32\svchost.exe
- ProcessID : 2284
- ProcessName : svchost.exe
- Handle : 2284
- commandline : C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
- ExecutablePath : C:\Windows\System32\svchost.exe
- ProcessID : 2364
- ProcessName : svchost.exe
- Handle : 2364
- commandline : C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
- ExecutablePath : C:\Windows\System32\svchost.exe
- ProcessID : 2372
- ProcessName : svchost.exe
- Handle : 2372
- commandline : c:\windows\system32\svchost.exe -k networkservice -s Dnscache
- ExecutablePath : c:\windows\system32\svchost.exe
- ProcessID : 2416
- ProcessName : svchost.exe
- Handle : 2416
- commandline : c:\windows\system32\svchost.exe -k appmodel -s StateRepository
- ExecutablePath : c:\windows\system32\svchost.exe
- ProcessID : 2488
- ProcessName : svchost.exe
- Handle : 2488
- commandline : C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted
- ExecutablePath : C:\Windows\system32\svchost.exe
- ProcessID : 2612
- ProcessName : svchost.exe
- Handle : 2612
- commandline : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
- ExecutablePath : C:\Windows\system32\svchost.exe
- ProcessID : 2680
- ProcessName : svchost.exe
- Handle : 2680
- commandline : c:\windows\system32\svchost.exe -k netsvcs -s ShellHWDetection
- ExecutablePath : c:\windows\system32\svchost.exe
- ProcessID : 2744
- ProcessName : spoolsv.exe
- Handle : 2744
- commandline : C:\Windows\System32\spoolsv.exe
- ExecutablePath : C:\Windows\System32\spoolsv.exe
- ProcessID : 2796
- ProcessName : svchost.exe
- Handle : 2796
- commandline : c:\windows\system32\svchost.exe -k networkservice -s LanmanWorkstation
- ExecutablePath : c:\windows\system32\svchost.exe
- ProcessID : 3012
- ProcessName : svchost.exe
- Handle : 3012
- commandline : c:\windows\system32\svchost.exe -k networkservice -s CryptSvc
- ExecutablePath : c:\windows\system32\svchost.exe
- ProcessID : 3020
- ProcessName : svchost.exe
- Handle : 3020
- commandline : c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s SysMain
- ExecutablePath : c:\windows\system32\svchost.exe
- ProcessID : 3032
- ProcessName : svchost.exe
- Handle : 3032
- commandline : C:\Windows\System32\svchost.exe -k utcsvc
- ExecutablePath : C:\Windows\System32\svchost.exe
- ProcessID : 3040
- ProcessName : svchost.exe
- Handle : 3040
- commandline : c:\windows\system32\svchost.exe -k netsvcs -s WpnService
- ExecutablePath : c:\windows\system32\svchost.exe
- ProcessID : 3048
- ProcessName : svchost.exe
- Handle : 3048
- commandline : c:\windows\system32\svchost.exe -k netsvcs -s IKEEXT
- ExecutablePath : c:\windows\system32\svchost.exe
- ProcessID : 3056
- ProcessName : svchost.exe
- Handle : 3056
- commandline : c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s TrkWks
- ExecutablePath : c:\windows\system32\svchost.exe
- ProcessID : 3064
- ProcessName : svchost.exe
- Handle : 3064
- commandline : c:\windows\system32\svchost.exe -k appmodel -s tiledatamodelsvc
- ExecutablePath : c:\windows\system32\svchost.exe
- ProcessID : 1964
- ProcessName : svchost.exe
- Handle : 1964
- commandline : c:\windows\system32\svchost.exe -k localservicenonetwork -s DPS
- ExecutablePath : c:\windows\system32\svchost.exe
- ProcessID : 2072
- ProcessName : SecurityHealthService.exe
- Handle : 2072
- commandline :
- ExecutablePath :
- ProcessID : 2304
- ProcessName : svchost.exe
- Handle : 2304
- commandline : c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s PcaSvc
- ExecutablePath : c:\windows\system32\svchost.exe
- ProcessID : 3076
- ProcessName : svchost.exe
- Handle : 3076
- commandline : c:\windows\system32\svchost.exe -k localservice -s WinHttpAutoProxySvc
- ExecutablePath : c:\windows\system32\svchost.exe
- ProcessID : 3176
- ProcessName : svchost.exe
- Handle : 3176
- commandline : c:\windows\system32\svchost.exe -k netsvcs -s LanmanServer
- ExecutablePath : c:\windows\system32\svchost.exe
- ProcessID : 3312
- ProcessName : svchost.exe
- Handle : 3312
- commandline : c:\windows\system32\svchost.exe -k netsvcs -s iphlpsvc
- ExecutablePath : c:\windows\system32\svchost.exe
- ProcessID : 3344
- ProcessName : MsMpEng.exe
- Handle : 3344
- commandline :
- ExecutablePath :
- ProcessID : 3460
- ProcessName : svchost.exe
- Handle : 3460
- commandline : c:\windows\system32\svchost.exe -k localservice -s WdiServiceHost
- ExecutablePath : c:\windows\system32\svchost.exe
- ProcessID : 3728
- ProcessName : Memory Compression
- Handle : 3728
- commandline :
- ExecutablePath :
- ProcessID : 3780
- ProcessName : ReiGuard.exe
- Handle : 3780
- commandline : "C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe"
- ExecutablePath : C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe
- ProcessID : 4008
- ProcessName : svchost.exe
- Handle : 4008
- commandline : c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s DeviceAssociationService
- ExecutablePath : c:\windows\system32\svchost.exe
- ProcessID : 2140
- ProcessName : svchost.exe
- Handle : 2140
- commandline : c:\windows\system32\svchost.exe -k localservicenetworkrestricted -s lmhosts
- ExecutablePath : c:\windows\system32\svchost.exe
- ProcessID : 4684
- ProcessName : sihost.exe
- Handle : 4684
- commandline : sihost.exe
- ExecutablePath : c:\windows\system32\sihost.exe
- ProcessID : 4708
- ProcessName : svchost.exe
- Handle : 4708
- commandline : c:\windows\system32\svchost.exe -k unistacksvcgroup -s CDPUserSvc
- ExecutablePath : c:\windows\system32\svchost.exe
- ProcessID : 4748
- ProcessName : svchost.exe
- Handle : 4748
- commandline : c:\windows\system32\svchost.exe -k unistacksvcgroup -s WpnUserService
- ExecutablePath : c:\windows\system32\svchost.exe
- ProcessID : 4804
- ProcessName : svchost.exe
- Handle : 4804
- commandline : c:\windows\system32\svchost.exe -k netsvcs -s TokenBroker
- ExecutablePath : c:\windows\system32\svchost.exe
- ProcessID : 4952
- ProcessName : DriverToolkit.exe
- Handle : 4952
- commandline : "C:\Program Files (x86)\DriverToolkit\DriverToolkit.exe" --autorun
- ExecutablePath : C:\Program Files (x86)\DriverToolkit\DriverToolkit.exe
- ProcessID : 4968
- ProcessName : taskhostw.exe
- Handle : 4968
- commandline : taskhostw.exe {222A245B-E637-4AE9-A93F-A59CA119A75E}
- ExecutablePath : c:\windows\system32\taskhostw.exe
- ProcessID : 5108
- ProcessName : explorer.exe
- Handle : 5108
- commandline : C:\Windows\Explorer.EXE
- ExecutablePath : C:\Windows\Explorer.EXE
- ProcessID : 4232
- ProcessName : ReiSystem.exe
- Handle : 4232
- commandline : "C:\Program Files\Reimage\Reimage Protector\ReiSystem.exe"
- ExecutablePath : C:\Program Files\Reimage\Reimage Protector\ReiSystem.exe
- ProcessID : 4320
- ProcessName : SearchIndexer.exe
- Handle : 4320
- commandline : C:\Windows\system32\SearchIndexer.exe /Embedding
- ExecutablePath : C:\Windows\system32\SearchIndexer.exe
- ProcessID : 4316
- ProcessName : ShellExperienceHost.exe
- Handle : 4316
- commandline : "C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe"
- -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca
- ExecutablePath : C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe
- ProcessID : 2816
- ProcessName : SearchUI.exe
- Handle : 2816
- commandline : "C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe"
- -ServerName:CortanaUI.AppXa50dqqa5gqv4a428c9y1jjw7m3btvepj.mca
- ExecutablePath : C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe
- ProcessID : 5220
- ProcessName : WmiPrvSE.exe
- Handle : 5220
- commandline : C:\Windows\system32\wbem\wmiprvse.exe
- ExecutablePath : C:\Windows\system32\wbem\wmiprvse.exe
- ProcessID : 5260
- ProcessName : RuntimeBroker.exe
- Handle : 5260
- commandline : C:\Windows\System32\RuntimeBroker.exe -Embedding
- ExecutablePath : C:\Windows\System32\RuntimeBroker.exe
- ProcessID : 6576
- ProcessName : svchost.exe
- Handle : 6576
- commandline : c:\windows\system32\svchost.exe -k localservice -s CDPSvc
- ExecutablePath : c:\windows\system32\svchost.exe
- ProcessID : 6996
- ProcessName : MSASCuiL.exe
- Handle : 6996
- commandline : "C:\Program Files\Windows Defender\MSASCuiL.exe"
- ExecutablePath : C:\Program Files\Windows Defender\MSASCuiL.exe
- ProcessID : 7104
- ProcessName : NvBackend.exe
- Handle : 7104
- commandline : "C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
- ExecutablePath : C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
- ProcessID : 7096
- ProcessName : RtkNGUI64.exe
- Handle : 7096
- commandline : "C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
- ExecutablePath : C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
- ProcessID : 7156
- ProcessName : OneDrive.exe
- Handle : 7156
- commandline : "C:\Users\Cory Smith\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
- ExecutablePath : C:\Users\Cory Smith\AppData\Local\Microsoft\OneDrive\OneDrive.exe
- ProcessID : 7060
- ProcessName : MSIRegister.exe
- Handle : 7060
- commandline : "C:\MSI\MSIRegister\MSIRegister.exe"
- ExecutablePath : C:\MSI\MSIRegister\MSIRegister.exe
- ProcessID : 5176
- ProcessName : svchost.exe
- Handle : 5176
- commandline : c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s WdiSystemHost
- ExecutablePath : c:\windows\system32\svchost.exe
- ProcessID : 5360
- ProcessName : SystemSettingsBroker.exe
- Handle : 5360
- commandline : C:\Windows\System32\SystemSettingsBroker.exe -Embedding
- ExecutablePath : C:\Windows\System32\SystemSettingsBroker.exe
- ProcessID : 4176
- ProcessName : svchost.exe
- Handle : 4176
- commandline : c:\windows\system32\svchost.exe -k netsvcs -s lfsvc
- ExecutablePath : c:\windows\system32\svchost.exe
- ProcessID : 4508
- ProcessName : ApplicationFrameHost.exe
- Handle : 4508
- commandline : C:\Windows\system32\ApplicationFrameHost.exe -Embedding
- ExecutablePath : C:\Windows\system32\ApplicationFrameHost.exe
- ProcessID : 1284
- ProcessName : MicrosoftEdge.exe
- Handle : 1284
- commandline : "C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe"
- -ServerName:MicrosoftEdge.AppXdnhjhccw3zf0j06tkg3jtqr00qdm0khc.mca
- ExecutablePath : C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
- ProcessID : 1948
- ProcessName : browser_broker.exe
- Handle : 1948
- commandline : C:\Windows\system32\browser_broker.exe -Embedding
- ExecutablePath : C:\Windows\system32\browser_broker.exe
- ProcessID : 3976
- ProcessName : MicrosoftEdgeCP.exe
- Handle : 3976
- commandline : "C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe"
- -ServerName:ContentProcess.AppX6z3cwk4fvgady6zya12j1cw28d228a7k.mca
- ExecutablePath : C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
- ProcessID : 7756
- ProcessName : MicrosoftEdgeCP.exe
- Handle : 7756
- commandline : "C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe"
- -ServerName:ContentProcess.AppX6z3cwk4fvgady6zya12j1cw28d228a7k.mca
- ExecutablePath : C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
- ProcessID : 7220
- ProcessName : audiodg.exe
- Handle : 7220
- commandline : C:\Windows\system32\AUDIODG.EXE 0x474
- ExecutablePath : C:\Windows\system32\AUDIODG.EXE
- ProcessID : 6596
- ProcessName : svchost.exe
- Handle : 6596
- commandline : c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s SensorService
- ExecutablePath : c:\windows\system32\svchost.exe
- ProcessID : 5068
- ProcessName : SystemSettings.exe
- Handle : 5068
- commandline : "C:\Windows\ImmersiveControlPanel\SystemSettings.exe"
- -ServerName:microsoft.windows.immersivecontrolpanel
- ExecutablePath : C:\Windows\ImmersiveControlPanel\SystemSettings.exe
- ProcessID : 6796
- ProcessName : NvNetworkService.exe
- Handle : 6796
- commandline : "C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe"
- ExecutablePath : C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
- ProcessID : 4172
- ProcessName : SecHealthUI.exe
- Handle : 4172
- commandline : "C:\Windows\SystemApps\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\SecHealthUI.exe"
- -ServerName:SecHealthUI.AppXep4x2tbtjws1v9qqs0rmb3hxykvkpqtn.mca
- ExecutablePath : C:\Windows\SystemApps\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\SecHealthUI.exe
- ProcessID : 8232
- ProcessName : dllhost.exe
- Handle : 8232
- commandline : C:\Windows\system32\DllHost.exe /Processid:{7E55A26D-EF95-4A45-9F55-21E52ADF9887}
- ExecutablePath : C:\Windows\system32\DllHost.exe
- ProcessID : 8456
- ProcessName : svchost.exe
- Handle : 8456
- commandline : c:\windows\system32\svchost.exe -k netsvcs -s Appinfo
- ExecutablePath : c:\windows\system32\svchost.exe
- ProcessID : 9004
- ProcessName : svchost.exe
- Handle : 9004
- commandline : c:\windows\system32\svchost.exe -k netsvcs -s DoSvc
- ExecutablePath : c:\windows\system32\svchost.exe
- ProcessID : 8644
- ProcessName : svchost.exe
- Handle : 8644
- commandline : c:\windows\system32\svchost.exe -k localservicenetworkrestricted -s wscsvc
- ExecutablePath : c:\windows\system32\svchost.exe
- ProcessID : 4372
- ProcessName : svchost.exe
- Handle : 4372
- commandline : c:\windows\system32\svchost.exe -k unistacksvcgroup
- ExecutablePath : c:\windows\system32\svchost.exe
- ProcessID : 8908
- ProcessName : svchost.exe
- Handle : 8908
- commandline : c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s StorSvc
- ExecutablePath : c:\windows\system32\svchost.exe
- ProcessID : 5688
- ProcessName : svchost.exe
- Handle : 5688
- commandline : c:\windows\system32\svchost.exe -k netsvcs -s Browser
- ExecutablePath : c:\windows\system32\svchost.exe
- ProcessID : 5004
- ProcessName : svchost.exe
- Handle : 5004
- commandline : c:\windows\system32\svchost.exe -k networkservicenetworkrestricted -s PolicyAgent
- ExecutablePath : c:\windows\system32\svchost.exe
- ProcessID : 8860
- ProcessName : FRST64.exe
- Handle : 8860
- commandline : "C:\Users\Cory Smith\Downloads\FRST64.exe"
- ExecutablePath : C:\Users\Cory Smith\Downloads\FRST64.exe
- ProcessID : 8720
- ProcessName : Steam.exe
- Handle : 8720
- commandline : "C:\Program Files (x86)\Steam\Steam.exe"
- ExecutablePath : C:\Program Files (x86)\Steam\Steam.exe
- ProcessID : 8712
- ProcessName : steamwebhelper.exe
- Handle : 8712
- commandline : "C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe" "-cachedir=C:\Users\Cory
- Smith\AppData\Local\Steam\htmlcache" "-steampid=8720" "-buildid=1493162727" "-steamid=0"
- --disable-gpu-compositing --disable-gpu --process-per-tab --disable-spell-checking
- --disable-out-of-process-pac --disable-smooth-scrolling --enable-direct-write
- "--log-file=C:\Program Files (x86)\Steam\logs\cef_log.txt"
- ExecutablePath : C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
- ProcessID : 5796
- ProcessName : SteamService.exe
- Handle : 5796
- commandline : "C:\Program Files (x86)\Common Files\Steam\SteamService.exe" /RunAsService
- ExecutablePath : C:\Program Files (x86)\Common Files\Steam\SteamService.exe
- ProcessID : 6836
- ProcessName : steamwebhelper.exe
- Handle : 6836
- commandline : "C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe" --type=renderer
- --disable-gpu-compositing --disable-smooth-scrolling --enable-pinch
- --primordial-pipe-token=009587B9E01818F6699E9C4B1E164D38 --lang=en-US --lang=en-GB
- --log-file="C:\Program Files (x86)\Steam\logs\cef_log.txt" --product-version="Valve Steam
- Client" --disable-spell-checking --enable-pinch --device-scale-factor=1
- --num-raster-threads=4 --enable-main-frame-before-activation --content-image-texture-target=
- 0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,
- 10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,355
- 3;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3
- 553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3
- 553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3
- ,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,
- 11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553 --disable-accelerated-video-decode
- --disable-webrtc-hw-encoding --disable-gpu-compositing
- --service-request-channel-token=009587B9E01818F6699E9C4B1E164D38 --renderer-client-id=2
- --mojo-platform-channel-handle=2192 /prefetch:1
- ExecutablePath : C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
- ProcessID : 7588
- ProcessName : svchost.exe
- Handle : 7588
- commandline : c:\windows\system32\svchost.exe -k localserviceandnoimpersonation -s SSDPSRV
- ExecutablePath : c:\windows\system32\svchost.exe
- ProcessID : 1248
- ProcessName : notepad.exe
- Handle : 1248
- commandline : notepad "C:\Users\Cory Smith\Downloads\FRST.txt"
- ExecutablePath : C:\Windows\SYSTEM32\notepad.exe
- ProcessID : 5236
- ProcessName : notepad.exe
- Handle : 5236
- commandline : notepad "C:\Users\Cory Smith\Downloads\Addition.txt"
- ExecutablePath : C:\Windows\SYSTEM32\notepad.exe
- ProcessID : 8380
- ProcessName : MicrosoftEdgeCP.exe
- Handle : 8380
- commandline : "C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe"
- -ServerName:ContentProcess.AppX6z3cwk4fvgady6zya12j1cw28d228a7k.mca
- ExecutablePath : C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
- ProcessID : 8440
- ProcessName : MicrosoftEdgeCP.exe
- Handle : 8440
- commandline : "C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe"
- -ServerName:ContentProcess.AppX6z3cwk4fvgady6zya12j1cw28d228a7k.mca
- ExecutablePath : C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
- ProcessID : 8268
- ProcessName : SearchProtocolHost.exe
- Handle : 8268
- commandline : "C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe5_
- Global\UsGthrCtrlFltPipeMssGthrPipe5 1 -2147483646 "Software\Microsoft\Windows Search"
- "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)"
- "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
- ExecutablePath : C:\Windows\system32\SearchProtocolHost.exe
- ProcessID : 7216
- ProcessName : svchost.exe
- Handle : 7216
- commandline : C:\Windows\system32\svchost.exe -k netsvcs -s gpsvc
- ExecutablePath : C:\Windows\system32\svchost.exe
- ProcessID : 8792
- ProcessName : dllhost.exe
- Handle : 8792
- commandline : C:\Windows\system32\DllHost.exe /Processid:{973D20D7-562D-44B9-B70B-5A0F49CCDF3F}
- ExecutablePath : C:\Windows\system32\DllHost.exe
- ProcessID : 7532
- ProcessName : backgroundTaskHost.exe
- Handle : 7532
- commandline : "C:\Windows\system32\backgroundTaskHost.exe"
- -ServerName:CortanaUI.AppXy7vb4pc2dr3kc93kfc509b1d0arkfb2x.mca
- ExecutablePath : C:\Windows\system32\backgroundTaskHost.exe
- ProcessID : 5388
- ProcessName : SearchFilterHost.exe
- Handle : 5388
- commandline : "C:\Windows\system32\SearchFilterHost.exe" 0 688 692 700 8192 696
- ExecutablePath : C:\Windows\system32\SearchFilterHost.exe
- ProcessID : 6516
- ProcessName : cmd.exe
- Handle : 6516
- commandline : "C:\Windows\System32\cmd.exe" /c "C:\Users\CORYSM~1\DOCUME~1\SCAN_R~1.BAT"
- ExecutablePath : C:\Windows\System32\cmd.exe
- ProcessID : 7980
- ProcessName : conhost.exe
- Handle : 7980
- commandline : \??\C:\Windows\system32\conhost.exe 0x4
- ExecutablePath : C:\Windows\system32\conhost.exe
- ProcessID : 2264
- ProcessName : WmiPrvSE.exe
- Handle : 2264
- commandline : C:\Windows\system32\wbem\wmiprvse.exe
- ExecutablePath : C:\Windows\system32\wbem\wmiprvse.exe
- ProcessID : 6952
- ProcessName : TrustedInstaller.exe
- Handle : 6952
- commandline : C:\Windows\servicing\TrustedInstaller.exe
- ExecutablePath : C:\Windows\servicing\TrustedInstaller.exe
- ProcessID : 4776
- ProcessName : TiWorker.exe
- Handle : 4776
- commandline : C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.15063.0_none_
- 1a733a82001933cc\TiWorker.exe -Embedding
- ExecutablePath : C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.15063.0_none_
- 1a733a82001933cc\TiWorker.exe
- ProcessID : 2624
- ProcessName : powershell.exe
- Handle : 2624
- commandline : Powershell.exe Get-WmiObject Win32_Process | select
- ProcessID,ProcessName,Handle,commandline,ExecutablePath | Out-File -Append
- "C:\Users\CORYSM~1\AppData\Local\Temp\TmpLog_Keys.txt" -Encoding ascii
- ExecutablePath : C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
- ******************************************************************************
- Services List
- ******************************************************************************
- SERVICE_NAME: Appinfo
- DISPLAY_NAME: Application Information
- TYPE : 30 WIN32
- STATE : 4 RUNNING
- (STOPPABLE, NOT_PAUSABLE, IGNORES_SHUTDOWN)
- WIN32_EXIT_CODE : 0 (0x0)
- SERVICE_EXIT_CODE : 0 (0x0)
- CHECKPOINT : 0x0
- WAIT_HINT : 0x0
- PID : 8456
- FLAGS :
- SERVICE_NAME: AudioEndpointBuilder
- DISPLAY_NAME: Windows Audio Endpoint Builder
- TYPE : 30 WIN32
- STATE : 4 RUNNING
- (STOPPABLE, NOT_PAUSABLE, IGNORES_SHUTDOWN)
- WIN32_EXIT_CODE : 0 (0x0)
- SERVICE_EXIT_CODE : 0 (0x0)
- CHECKPOINT : 0x0
- WAIT_HINT : 0x0
- PID : 2076
- FLAGS :
- SERVICE_NAME: Audiosrv
- DISPLAY_NAME: Windows Audio
- TYPE : 10 WIN32_OWN_PROCESS
- STATE : 4 RUNNING
- (STOPPABLE, NOT_PAUSABLE, IGNORES_SHUTDOWN)
- WIN32_EXIT_CODE : 0 (0x0)
- SERVICE_EXIT_CODE : 0 (0x0)
- CHECKPOINT : 0x0
- WAIT_HINT : 0x0
- PID : 2284
- FLAGS :
- SERVICE_NAME: BFE
- DISPLAY_NAME: Base Filtering Engine
- TYPE : 20 WIN32_SHARE_PROCESS
- STATE : 4 RUNNING
- (STOPPABLE, NOT_PAUSABLE, IGNORES_SHUTDOWN)
- WIN32_EXIT_CODE : 0 (0x0)
- SERVICE_EXIT_CODE : 0 (0x0)
- CHECKPOINT : 0x0
- WAIT_HINT : 0x0
- PID : 1264
- FLAGS :
- SERVICE_NAME: BrokerInfrastructure
- DISPLAY_NAME: Background Tasks Infrastructure Service
- TYPE : 20 WIN32_SHARE_PROCESS
- STATE : 4 RUNNING
- (NOT_STOPPABLE, NOT_PAUSABLE, IGNORES_SHUTDOWN)
- WIN32_EXIT_CODE : 0 (0x0)
- SERVICE_EXIT_CODE : 0 (0x0)
- CHECKPOINT : 0x0
- WAIT_HINT : 0x0
- PID : 496
- FLAGS :
- SERVICE_NAME: Browser
- DISPLAY_NAME: Computer Browser
- TYPE : 30 WIN32
- STATE : 4 RUNNING
- (STOPPABLE, NOT_PAUSABLE, IGNORES_SHUTDOWN)
- WIN32_EXIT_CODE : 0 (0x0)
- SERVICE_EXIT_CODE : 0 (0x0)
- CHECKPOINT : 0x0
- WAIT_HINT : 0x0
- PID : 5688
- FLAGS :
- SERVICE_NAME: CDPSvc
- DISPLAY_NAME: Connected Devices Platform Service
- TYPE : 30 WIN32
- STATE : 4 RUNNING
- (STOPPABLE, NOT_PAUSABLE, IGNORES_SHUTDOWN)
- WIN32_EXIT_CODE : 0 (0x0)
- SERVICE_EXIT_CODE : 0 (0x0)
- CHECKPOINT : 0x0
- WAIT_HINT : 0x0
- PID : 6576
- FLAGS :
- SERVICE_NAME: CoreMessagingRegistrar
- DISPLAY_NAME: CoreMessaging
- TYPE : 20 WIN32_SHARE_PROCESS
- STATE : 4 RUNNING
- (NOT_STOPPABLE, NOT_PAUSABLE, IGNORES_SHUTDOWN)
- WIN32_EXIT_CODE : 0 (0x0)
- SERVICE_EXIT_CODE : 0 (0x0)
- CHECKPOINT : 0x0
- WAIT_HINT : 0x0
- PID : 1264
- FLAGS :
- SERVICE_NAME: CryptSvc
- DISPLAY_NAME: Cryptographic Services
- TYPE : 30 WIN32
- STATE : 4 RUNNING
- (STOPPABLE, NOT_PAUSABLE, ACCEPTS_SHUTDOWN)
- WIN32_EXIT_CODE : 0 (0x0)
- SERVICE_EXIT_CODE : 0 (0x0)
- CHECKPOINT : 0x0
- WAIT_HINT : 0x0
- PID : 3012
- FLAGS :
- SERVICE_NAME: DcomLaunch
- DISPLAY_NAME: DCOM Server Process Launcher
- TYPE : 20 WIN32_SHARE_PROCESS
- STATE : 4 RUNNING
- (NOT_STOPPABLE, NOT_PAUSABLE, IGNORES_SHUTDOWN)
- WIN32_EXIT_CODE : 0 (0x0)
- SERVICE_EXIT_CODE : 0 (0x0)
- CHECKPOINT : 0x0
- WAIT_HINT : 0x0
- PID : 496
- FLAGS :
- SERVICE_NAME: DeviceAssociationService
- DISPLAY_NAME: Device Association Service
- TYPE : 30 WIN32
- STATE : 4 RUNNING
- (STOPPABLE, NOT_PAUSABLE, ACCEPTS_SHUTDOWN)
- WIN32_EXIT_CODE : 0 (0x0)
- SERVICE_EXIT_CODE : 0 (0x0)
- CHECKPOINT : 0x0
- WAIT_HINT : 0x0
- PID : 4008
- FLAGS :
- SERVICE_NAME: Dhcp
- DISPLAY_NAME: DHCP Client
- TYPE : 30 WIN32
- STATE : 4 RUNNING
- (STOPPABLE, NOT_PAUSABLE, ACCEPTS_SHUTDOWN)
- WIN32_EXIT_CODE : 0 (0x0)
- SERVICE_EXIT_CODE : 0 (0x0)
- CHECKPOINT : 0x0
- WAIT_HINT : 0x0
- PID : 1788
- FLAGS :
- SERVICE_NAME: DiagTrack
- DISPLAY_NAME: Connected User Experiences and Telemetry
- TYPE : 10 WIN32_OWN_PROCESS
- STATE : 4 RUNNING
- (STOPPABLE, NOT_PAUSABLE, ACCEPTS_PRESHUTDOWN)
- WIN32_EXIT_CODE : 0 (0x0)
- SERVICE_EXIT_CODE : 0 (0x0)
- CHECKPOINT : 0x0
- WAIT_HINT : 0x0
- PID : 3032
- FLAGS :
- SERVICE_NAME: Dnscache
- DISPLAY_NAME: DNS Client
- TYPE : 30 WIN32
- STATE : 4 RUNNING
- (STOPPABLE, NOT_PAUSABLE, IGNORES_SHUTDOWN)
- WIN32_EXIT_CODE : 0 (0x0)
- SERVICE_EXIT_CODE : 0 (0x0)
- CHECKPOINT : 0x0
- WAIT_HINT : 0x0
- PID : 2372
- FLAGS :
- SERVICE_NAME: DoSvc
- DISPLAY_NAME: Delivery Optimization
- TYPE : 30 WIN32
- STATE : 4 RUNNING
- (STOPPABLE, NOT_PAUSABLE, ACCEPTS_PRESHUTDOWN)
- WIN32_EXIT_CODE : 0 (0x0)
- SERVICE_EXIT_CODE : 0 (0x0)
- CHECKPOINT : 0x0
- WAIT_HINT : 0x0
- PID : 9004
- FLAGS :
- SERVICE_NAME: DPS
- DISPLAY_NAME: Diagnostic Policy Service
- TYPE : 30 WIN32
- STATE : 4 RUNNING
- (STOPPABLE, NOT_PAUSABLE, ACCEPTS_SHUTDOWN)
- WIN32_EXIT_CODE : 0 (0x0)
- SERVICE_EXIT_CODE : 0 (0x0)
- CHECKPOINT : 0x0
- WAIT_HINT : 0x0
- PID : 1964
- FLAGS :
- SERVICE_NAME: DusmSvc
- DISPLAY_NAME: Data Usage
- TYPE : 10 WIN32_OWN_PROCESS
- STATE : 4 RUNNING
- (STOPPABLE, NOT_PAUSABLE, IGNORES_SHUTDOWN)
- WIN32_EXIT_CODE : 0 (0x0)
- SERVICE_EXIT_CODE : 0 (0x0)
- CHECKPOINT : 0x0
- WAIT_HINT : 0x0
- PID : 2364
- FLAGS :
- SERVICE_NAME: EventLog
- DISPLAY_NAME: Windows Event Log
- TYPE : 30 WIN32
- STATE : 4 RUNNING
- (STOPPABLE, NOT_PAUSABLE, ACCEPTS_SHUTDOWN)
- WIN32_EXIT_CODE : 0 (0x0)
- SERVICE_EXIT_CODE : 0 (0x0)
- CHECKPOINT : 0x0
- WAIT_HINT : 0x0
- PID : 1476
- FLAGS :
- SERVICE_NAME: EventSystem
- DISPLAY_NAME: COM+ Event System
- TYPE : 30 WIN32
- STATE : 4 RUNNING
- (STOPPABLE, NOT_PAUSABLE, IGNORES_SHUTDOWN)
- WIN32_EXIT_CODE : 0 (0x0)
- SERVICE_EXIT_CODE : 0 (0x0)
- CHECKPOINT : 0x0
- WAIT_HINT : 0x0
- PID : 1924
- FLAGS :
- SERVICE_NAME: FontCache
- DISPLAY_NAME: Windows Font Cache Service
- TYPE : 30 WIN32
- STATE : 4 RUNNING
- (STOPPABLE, NOT_PAUSABLE, ACCEPTS_SHUTDOWN)
- WIN32_EXIT_CODE : 0 (0x0)
- SERVICE_EXIT_CODE : 0 (0x0)
- CHECKPOINT : 0x0
- WAIT_HINT : 0x0
- PID : 2084
- FLAGS :
- SERVICE_NAME: gpsvc
- DISPLAY_NAME: Group Policy Client
- TYPE : 30 WIN32
- STATE : 4 RUNNING
- (STOPPABLE, NOT_PAUSABLE, ACCEPTS_PRESHUTDOWN)
- WIN32_EXIT_CODE : 0 (0x0)
- SERVICE_EXIT_CODE : 0 (0x0)
- CHECKPOINT : 0x0
- WAIT_HINT : 0x0
- PID : 7216
- FLAGS :
- SERVICE_NAME: hidserv
- DISPLAY_NAME: Human Interface Device Service
- TYPE : 30 WIN32
- STATE : 4 RUNNING
- (STOPPABLE, NOT_PAUSABLE, ACCEPTS_SHUTDOWN)
- WIN32_EXIT_CODE : 0 (0x0)
- SERVICE_EXIT_CODE : 0 (0x0)
- CHECKPOINT : 0x0
- WAIT_HINT : 0x0
- PID : 1568
- FLAGS :
- SERVICE_NAME: IKEEXT
- DISPLAY_NAME: IKE and AuthIP IPsec Keying Modules
- TYPE : 30 WIN32
- STATE : 4 RUNNING
- (STOPPABLE, NOT_PAUSABLE, ACCEPTS_SHUTDOWN)
- WIN32_EXIT_CODE : 0 (0x0)
- SERVICE_EXIT_CODE : 0 (0x0)
- CHECKPOINT : 0x0
- WAIT_HINT : 0x0
- PID : 3048
- FLAGS :
- SERVICE_NAME: iphlpsvc
- DISPLAY_NAME: IP Helper
- TYPE : 30 WIN32
- STATE : 4 RUNNING
- (STOPPABLE, NOT_PAUSABLE, IGNORES_SHUTDOWN)
- WIN32_EXIT_CODE : 0 (0x0)
- SERVICE_EXIT_CODE : 0 (0x0)
- CHECKPOINT : 0x0
- WAIT_HINT : 0x0
- PID : 3312
- FLAGS :
- SERVICE_NAME: KeyIso
- DISPLAY_NAME: CNG Key Isolation
- TYPE : 20 WIN32_SHARE_PROCESS
- STATE : 4 RUNNING
- (STOPPABLE, NOT_PAUSABLE, IGNORES_SHUTDOWN)
- WIN32_EXIT_CODE : 0 (0x0)
- SERVICE_EXIT_CODE : 0 (0x0)
- CHECKPOINT : 0x0
- WAIT_HINT : 0x0
- PID : 816
- FLAGS : RUNS_IN_SYSTEM_PROCESS
- SERVICE_NAME: LanmanServer
- DISPLAY_NAME: Server
- TYPE : 30 WIN32
- STATE : 4 RUNNING
- (STOPPABLE, NOT_PAUSABLE, IGNORES_SHUTDOWN)
- WIN32_EXIT_CODE : 0 (0x0)
- SERVICE_EXIT_CODE : 0 (0x0)
- CHECKPOINT : 0x0
- WAIT_HINT : 0x0
- PID : 3176
- FLAGS :
- SERVICE_NAME: LanmanWorkstation
- DISPLAY_NAME: Workstation
- TYPE : 30 WIN32
- STATE : 4 RUNNING
- (STOPPABLE, PAUSABLE, IGNORES_SHUTDOWN)
- WIN32_EXIT_CODE : 0 (0x0)
- SERVICE_EXIT_CODE : 0 (0x0)
- CHECKPOINT : 0x0
- WAIT_HINT : 0x0
- PID : 2796
- FLAGS :
- SERVICE_NAME: lfsvc
- DISPLAY_NAME: Geolocation Service
- TYPE : 30 WIN32
- STATE : 4 RUNNING
- (STOPPABLE, NOT_PAUSABLE, IGNORES_SHUTDOWN)
- WIN32_EXIT_CODE : 0 (0x0)
- SERVICE_EXIT_CODE : 0 (0x0)
- CHECKPOINT : 0x0
- WAIT_HINT : 0x0
- PID : 4176
- FLAGS :
- SERVICE_NAME: lmhosts
- DISPLAY_NAME: TCP/IP NetBIOS Helper
- TYPE : 30 WIN32
- STATE : 4 RUNNING
- (STOPPABLE, NOT_PAUSABLE, IGNORES_SHUTDOWN)
- WIN32_EXIT_CODE : 0 (0x0)
- SERVICE_EXIT_CODE : 0 (0x0)
- CHECKPOINT : 0x0
- WAIT_HINT : 0x0
- PID : 2140
- FLAGS :
- SERVICE_NAME: LSM
- DISPLAY_NAME: Local Session Manager
- TYPE : 30 WIN32
- STATE : 4 RUNNING
- (NOT_STOPPABLE, NOT_PAUSABLE, IGNORES_SHUTDOWN)
- WIN32_EXIT_CODE : 0 (0x0)
- SERVICE_EXIT_CODE : 0 (0x0)
- CHECKPOINT : 0x0
- WAIT_HINT : 0x0
- PID : 1052
- FLAGS :
- SERVICE_NAME: MpsSvc
- DISPLAY_NAME: Windows Firewall
- TYPE : 20 WIN32_SHARE_PROCESS
- STATE : 4 RUNNING
- (STOPPABLE, NOT_PAUSABLE, IGNORES_SHUTDOWN)
- WIN32_EXIT_CODE : 0 (0x0)
- SERVICE_EXIT_CODE : 0 (0x0)
- CHECKPOINT : 0x0
- WAIT_HINT : 0x0
- PID : 1264
- FLAGS :
- SERVICE_NAME: NcbService
- DISPLAY_NAME: Network Connection Broker
- TYPE : 30 WIN32
- STATE : 4 RUNNING
- (STOPPABLE, NOT_PAUSABLE, IGNORES_SHUTDOWN)
- WIN32_EXIT_CODE : 0 (0x0)
- SERVICE_EXIT_CODE : 0 (0x0)
- CHECKPOINT : 0x0
- WAIT_HINT : 0x0
- PID : 1316
- FLAGS :
- SERVICE_NAME: netprofm
- DISPLAY_NAME: Network List Service
- TYPE : 30 WIN32
- STATE : 4 RUNNING
- (STOPPABLE, NOT_PAUSABLE, IGNORES_SHUTDOWN)
- WIN32_EXIT_CODE : 0 (0x0)
- SERVICE_EXIT_CODE : 0 (0x0)
- CHECKPOINT : 0x0
- WAIT_HINT : 0x0
- PID : 2000
- FLAGS :
- SERVICE_NAME: NlaSvc
- DISPLAY_NAME: Network Location Awareness
- TYPE : 30 WIN32
- STATE : 4 RUNNING
- (STOPPABLE, NOT_PAUSABLE, IGNORES_SHUTDOWN)
- WIN32_EXIT_CODE : 0 (0x0)
- SERVICE_EXIT_CODE : 0 (0x0)
- CHECKPOINT : 0x0
- WAIT_HINT : 0x0
- PID : 1848
- FLAGS :
- SERVICE_NAME: nsi
- DISPLAY_NAME: Network Store Interface Service
- TYPE : 30 WIN32
- STATE : 4 RUNNING
- (STOPPABLE, NOT_PAUSABLE, IGNORES_SHUTDOWN)
- WIN32_EXIT_CODE : 0 (0x0)
- SERVICE_EXIT_CODE : 0 (0x0)
- CHECKPOINT : 0x0
- WAIT_HINT : 0x0
- PID : 1748
- FLAGS :
- SERVICE_NAME: NvNetworkService
- DISPLAY_NAME: NVIDIA Network Service
- TYPE : 10 WIN32_OWN_PROCESS
- STATE : 4 RUNNING
- (STOPPABLE, NOT_PAUSABLE, ACCEPTS_SHUTDOWN)
- WIN32_EXIT_CODE : 0 (0x0)
- SERVICE_EXIT_CODE : 0 (0x0)
- CHECKPOINT : 0x0
- WAIT_HINT : 0x0
- PID : 6796
- FLAGS :
- SERVICE_NAME: PcaSvc
- DISPLAY_NAME: Program Compatibility Assistant Service
- TYPE : 30 WIN32
- STATE : 4 RUNNING
- (STOPPABLE, NOT_PAUSABLE, ACCEPTS_SHUTDOWN)
- WIN32_EXIT_CODE : 0 (0x0)
- SERVICE_EXIT_CODE : 0 (0x0)
- CHECKPOINT : 0x0
- WAIT_HINT : 0x0
- PID : 2304
- FLAGS :
- SERVICE_NAME: PlugPlay
- DISPLAY_NAME: Plug and Play
- TYPE : 30 WIN32
- STATE : 4 RUNNING
- (STOPPABLE, NOT_PAUSABLE, ACCEPTS_SHUTDOWN)
- WIN32_EXIT_CODE : 0 (0x0)
- SERVICE_EXIT_CODE : 0 (0x0)
- CHECKPOINT : 0x0
- WAIT_HINT : 0x0
- PID : 996
- FLAGS :
- SERVICE_NAME: PolicyAgent
- DISPLAY_NAME: IPsec Policy Agent
- TYPE : 30 WIN32
- STATE : 4 RUNNING
- (STOPPABLE, NOT_PAUSABLE, ACCEPTS_SHUTDOWN)
- WIN32_EXIT_CODE : 0 (0x0)
- SERVICE_EXIT_CODE : 0 (0x0)
- CHECKPOINT : 0x0
- WAIT_HINT : 0x0
- PID : 5004
- FLAGS :
- SERVICE_NAME: Power
- DISPLAY_NAME: Power
- TYPE : 20 WIN32_SHARE_PROCESS
- STATE : 4 RUNNING
- (NOT_STOPPABLE, NOT_PAUSABLE, IGNORES_SHUTDOWN)
- WIN32_EXIT_CODE : 0 (0x0)
- SERVICE_EXIT_CODE : 0 (0x0)
- CHECKPOINT : 0x0
- WAIT_HINT : 0x0
- PID : 496
- FLAGS :
- SERVICE_NAME: ProfSvc
- DISPLAY_NAME: User Profile Service
- TYPE : 30 WIN32
- STATE : 4 RUNNING
- (STOPPABLE, NOT_PAUSABLE, ACCEPTS_SHUTDOWN)
- WIN32_EXIT_CODE : 0 (0x0)
- SERVICE_EXIT_CODE : 0 (0x0)
- CHECKPOINT : 0x0
- WAIT_HINT : 0x0
- PID : 1432
- FLAGS :
- SERVICE_NAME: ReimageRealTimeProtector
- DISPLAY_NAME: Reimage Real Time Protector
- TYPE : 10 WIN32_OWN_PROCESS
- STATE : 4 RUNNING
- (STOPPABLE, NOT_PAUSABLE, ACCEPTS_SHUTDOWN)
- WIN32_EXIT_CODE : 0 (0x0)
- SERVICE_EXIT_CODE : 0 (0x0)
- CHECKPOINT : 0x0
- WAIT_HINT : 0x0
- PID : 3780
- FLAGS :
- SERVICE_NAME: RpcEptMapper
- DISPLAY_NAME: RPC Endpoint Mapper
- TYPE : 20 WIN32_SHARE_PROCESS
- STATE : 4 RUNNING
- (NOT_STOPPABLE, NOT_PAUSABLE, IGNORES_SHUTDOWN)
- WIN32_EXIT_CODE : 0 (0x0)
- SERVICE_EXIT_CODE : 0 (0x0)
- CHECKPOINT : 0x0
- WAIT_HINT : 0x0
- PID : 512
- FLAGS :
- SERVICE_NAME: RpcSs
- DISPLAY_NAME: Remote Procedure Call (RPC)
- TYPE : 20 WIN32_SHARE_PROCESS
- STATE : 4 RUNNING
- (NOT_STOPPABLE, NOT_PAUSABLE, IGNORES_SHUTDOWN)
- WIN32_EXIT_CODE : 0 (0x0)
- SERVICE_EXIT_CODE : 0 (0x0)
- CHECKPOINT : 0x0
- WAIT_HINT : 0x0
- PID : 512
- FLAGS :
- SERVICE_NAME: SamSs
- DISPLAY_NAME: Security Accounts Manager
- TYPE : 20 WIN32_SHARE_PROCESS
- STATE : 4 RUNNING
- (NOT_STOPPABLE, NOT_PAUSABLE, IGNORES_SHUTDOWN)
- WIN32_EXIT_CODE : 0 (0x0)
- SERVICE_EXIT_CODE : 0 (0x0)
- CHECKPOINT : 0x0
- WAIT_HINT : 0x0
- PID : 816
- FLAGS : RUNS_IN_SYSTEM_PROCESS
- SERVICE_NAME: Schedule
- DISPLAY_NAME: Task Scheduler
- TYPE : 30 WIN32
- STATE : 4 RUNNING
- (STOPPABLE, NOT_PAUSABLE, ACCEPTS_SHUTDOWN)
- WIN32_EXIT_CODE : 0 (0x0)
- SERVICE_EXIT_CODE : 0 (0x0)
- CHECKPOINT : 0x0
- WAIT_HINT : 0x0
- PID : 1384
- FLAGS :
- SERVICE_NAME: SecurityHealthService
- DISPLAY_NAME: Windows Defender Security Centre Service
- TYPE : 10 WIN32_OWN_PROCESS
- STATE : 4 RUNNING
- (STOPPABLE, NOT_PAUSABLE, IGNORES_SHUTDOWN)
- WIN32_EXIT_CODE : 0 (0x0)
- SERVICE_EXIT_CODE : 0 (0x0)
- CHECKPOINT : 0x0
- WAIT_HINT : 0x0
- PID : 2072
- FLAGS :
- SERVICE_NAME: SENS
- DISPLAY_NAME: System Event Notification Service
- TYPE : 30 WIN32
- STATE : 4 RUNNING
- (STOPPABLE, NOT_PAUSABLE, IGNORES_SHUTDOWN)
- WIN32_EXIT_CODE : 0 (0x0)
- SERVICE_EXIT_CODE : 0 (0x0)
- CHECKPOINT : 0x0
- WAIT_HINT : 0x0
- PID : 1868
- FLAGS :
- SERVICE_NAME: SensorService
- DISPLAY_NAME: Sensor Service
- TYPE : 30 WIN32
- STATE : 4 RUNNING
- (STOPPABLE, NOT_PAUSABLE, ACCEPTS_PRESHUTDOWN)
- WIN32_EXIT_CODE : 0 (0x0)
- SERVICE_EXIT_CODE : 0 (0x0)
- CHECKPOINT : 0x0
- WAIT_HINT : 0x0
- PID : 6596
- FLAGS :
- SERVICE_NAME: ShellHWDetection
- DISPLAY_NAME: Shell Hardware Detection
- TYPE : 30 WIN32
- STATE : 4 RUNNING
- (STOPPABLE, NOT_PAUSABLE, IGNORES_SHUTDOWN)
- WIN32_EXIT_CODE : 0 (0x0)
- SERVICE_EXIT_CODE : 0 (0x0)
- CHECKPOINT : 0x0
- WAIT_HINT : 0x0
- PID : 2680
- FLAGS :
- SERVICE_NAME: Spooler
- DISPLAY_NAME: Print Spooler
- TYPE : 110 WIN32_OWN_PROCESS (interactive)
- STATE : 4 RUNNING
- (STOPPABLE, NOT_PAUSABLE, IGNORES_SHUTDOWN)
- WIN32_EXIT_CODE : 0 (0x0)
- SERVICE_EXIT_CODE : 0 (0x0)
- CHECKPOINT : 0x0
- WAIT_HINT : 0x0
- PID : 2744
- FLAGS :
- SERVICE_NAME: SSDPSRV
- DISPLAY_NAME: SSDP Discovery
- TYPE : 30 WIN32
- STATE : 4 RUNNING
- (STOPPABLE, NOT_PAUSABLE, ACCEPTS_SHUTDOWN)
- WIN32_EXIT_CODE : 0 (0x0)
- SERVICE_EXIT_CODE : 0 (0x0)
- CHECKPOINT : 0x0
- WAIT_HINT : 0x0
- PID : 7588
- FLAGS :
- SERVICE_NAME: StateRepository
- DISPLAY_NAME: State Repository Service
- TYPE : 30 WIN32
- STATE : 4 RUNNING
- (STOPPABLE, NOT_PAUSABLE, ACCEPTS_SHUTDOWN)
- WIN32_EXIT_CODE : 0 (0x0)
- SERVICE_EXIT_CODE : 0 (0x0)
- CHECKPOINT : 0x0
- WAIT_HINT : 0x0
- PID : 2416
- FLAGS :
- SERVICE_NAME: Steam Client Service
- DISPLAY_NAME: Steam Client Service
- TYPE : 10 WIN32_OWN_PROCESS
- STATE : 4 RUNNING
- (STOPPABLE, NOT_PAUSABLE, IGNORES_SHUTDOWN)
- WIN32_EXIT_CODE : 0 (0x0)
- SERVICE_EXIT_CODE : 0 (0x0)
- CHECKPOINT : 0x0
- WAIT_HINT : 0x0
- PID : 5796
- FLAGS :
- SERVICE_NAME: StorSvc
- DISPLAY_NAME: Storage Service
- TYPE : 30 WIN32
- STATE : 4 RUNNING
- (STOPPABLE, NOT_PAUSABLE, ACCEPTS_PRESHUTDOWN)
- WIN32_EXIT_CODE : 0 (0x0)
- SERVICE_EXIT_CODE : 0 (0x0)
- CHECKPOINT : 0x0
- WAIT_HINT : 0x0
- PID : 8908
- FLAGS :
- SERVICE_NAME: SysMain
- DISPLAY_NAME: Superfetch
- TYPE : 30 WIN32
- STATE : 4 RUNNING
- (STOPPABLE, NOT_PAUSABLE, ACCEPTS_SHUTDOWN)
- WIN32_EXIT_CODE : 0 (0x0)
- SERVICE_EXIT_CODE : 0 (0x0)
- CHECKPOINT : 0x0
- WAIT_HINT : 0x0
- PID : 3020
- FLAGS :
- SERVICE_NAME: SystemEventsBroker
- DISPLAY_NAME: System Events Broker
- TYPE : 20 WIN32_SHARE_PROCESS
- STATE : 4 RUNNING
- (STOPPABLE, NOT_PAUSABLE, IGNORES_SHUTDOWN)
- WIN32_EXIT_CODE : 0 (0x0)
- SERVICE_EXIT_CODE : 0 (0x0)
- CHECKPOINT : 0x0
- WAIT_HINT : 0x0
- PID : 496
- FLAGS :
- SERVICE_NAME: tbaseprovisioning
- DISPLAY_NAME: tbaseprovisioning
- TYPE : 10 WIN32_OWN_PROCESS
- STATE : 4 RUNNING
- (STOPPABLE, NOT_PAUSABLE, ACCEPTS_SHUTDOWN)
- WIN32_EXIT_CODE : 0 (0x0)
- SERVICE_EXIT_CODE : 0 (0x0)
- CHECKPOINT : 0x0
- WAIT_HINT : 0x0
- PID : 1672
- FLAGS :
- SERVICE_NAME: Themes
- DISPLAY_NAME: Themes
- TYPE : 30 WIN32
- STATE : 4 RUNNING
- (STOPPABLE, NOT_PAUSABLE, IGNORES_SHUTDOWN)
- WIN32_EXIT_CODE : 0 (0x0)
- SERVICE_EXIT_CODE : 0 (0x0)
- CHECKPOINT : 0x0
- WAIT_HINT : 0x0
- PID : 1916
- FLAGS :
- SERVICE_NAME: tiledatamodelsvc
- DISPLAY_NAME: Tile Data model server
- TYPE : 30 WIN32
- STATE : 4 RUNNING
- (STOPPABLE, NOT_PAUSABLE, ACCEPTS_PRESHUTDOWN)
- WIN32_EXIT_CODE : 0 (0x0)
- SERVICE_EXIT_CODE : 0 (0x0)
- CHECKPOINT : 0x0
- WAIT_HINT : 0x0
- PID : 3064
- FLAGS :
- SERVICE_NAME: TimeBrokerSvc
- DISPLAY_NAME: Time Broker
- TYPE : 30 WIN32
- STATE : 4 RUNNING
- (STOPPABLE, NOT_PAUSABLE, IGNORES_SHUTDOWN)
- WIN32_EXIT_CODE : 0 (0x0)
- SERVICE_EXIT_CODE : 0 (0x0)
- CHECKPOINT : 0x0
- WAIT_HINT : 0x0
- PID : 1324
- FLAGS :
- SERVICE_NAME: TokenBroker
- DISPLAY_NAME: TokenBroker
- TYPE : 30 WIN32
- STATE : 4 RUNNING
- (STOPPABLE, NOT_PAUSABLE, IGNORES_SHUTDOWN)
- WIN32_EXIT_CODE : 0 (0x0)
- SERVICE_EXIT_CODE : 0 (0x0)
- CHECKPOINT : 0x0
- WAIT_HINT : 0x0
- PID : 4804
- FLAGS :
- SERVICE_NAME: TrkWks
- DISPLAY_NAME: Distributed Link Tracking Client
- TYPE : 30 WIN32
- STATE : 4 RUNNING
- (STOPPABLE, NOT_PAUSABLE, ACCEPTS_SHUTDOWN)
- WIN32_EXIT_CODE : 0 (0x0)
- SERVICE_EXIT_CODE : 0 (0x0)
- CHECKPOINT : 0x0
- WAIT_HINT : 0x0
- PID : 3056
- FLAGS :
- SERVICE_NAME: TrustedInstaller
- DISPLAY_NAME: Windows Modules Installer
- TYPE : 10 WIN32_OWN_PROCESS
- STATE : 4 RUNNING
- (STOPPABLE, NOT_PAUSABLE, ACCEPTS_PRESHUTDOWN)
- WIN32_EXIT_CODE : 0 (0x0)
- SERVICE_EXIT_CODE : 0 (0x0)
- CHECKPOINT : 0x0
- WAIT_HINT : 0x0
- PID : 6952
- FLAGS :
- SERVICE_NAME: UserManager
- DISPLAY_NAME: User Manager
- TYPE : 30 WIN32
- STATE : 4 RUNNING
- (STOPPABLE, NOT_PAUSABLE, IGNORES_SHUTDOWN)
- WIN32_EXIT_CODE : 0 (0x0)
- SERVICE_EXIT_CODE : 0 (0x0)
- CHECKPOINT : 0x0
- WAIT_HINT : 0x0
- PID : 1544
- FLAGS :
- SERVICE_NAME: VaultSvc
- DISPLAY_NAME: Credential Manager
- TYPE : 20 WIN32_SHARE_PROCESS
- STATE : 4 RUNNING
- (STOPPABLE, NOT_PAUSABLE, ACCEPTS_SHUTDOWN)
- WIN32_EXIT_CODE : 0 (0x0)
- SERVICE_EXIT_CODE : 0 (0x0)
- CHECKPOINT : 0x0
- WAIT_HINT : 0x0
- PID : 816
- FLAGS : RUNS_IN_SYSTEM_PROCESS
- SERVICE_NAME: Wcmsvc
- DISPLAY_NAME: Windows Connection Manager
- TYPE : 10 WIN32_OWN_PROCESS
- STATE : 4 RUNNING
- (STOPPABLE, NOT_PAUSABLE, ACCEPTS_SHUTDOWN)
- WIN32_EXIT_CODE : 0 (0x0)
- SERVICE_EXIT_CODE : 0 (0x0)
- CHECKPOINT : 0x0
- WAIT_HINT : 0x0
- PID : 2488
- FLAGS :
- SERVICE_NAME: WdiServiceHost
- DISPLAY_NAME: Diagnostic Service Host
- TYPE : 30 WIN32
- STATE : 4 RUNNING
- (STOPPABLE, NOT_PAUSABLE, ACCEPTS_SHUTDOWN)
- WIN32_EXIT_CODE : 0 (0x0)
- SERVICE_EXIT_CODE : 0 (0x0)
- CHECKPOINT : 0x0
- WAIT_HINT : 0x0
- PID : 3460
- FLAGS :
- SERVICE_NAME: WdiSystemHost
- DISPLAY_NAME: Diagnostic System Host
- TYPE : 30 WIN32
- STATE : 4 RUNNING
- (STOPPABLE, NOT_PAUSABLE, ACCEPTS_SHUTDOWN)
- WIN32_EXIT_CODE : 0 (0x0)
- SERVICE_EXIT_CODE : 0 (0x0)
- CHECKPOINT : 0x0
- WAIT_HINT : 0x0
- PID : 5176
- FLAGS :
- SERVICE_NAME: WinDefend
- DISPLAY_NAME: Windows Defender Antivirus Service
- TYPE : 10 WIN32_OWN_PROCESS
- STATE : 4 RUNNING
- (STOPPABLE, NOT_PAUSABLE, ACCEPTS_SHUTDOWN)
- WIN32_EXIT_CODE : 0 (0x0)
- SERVICE_EXIT_CODE : 0 (0x0)
- CHECKPOINT : 0x0
- WAIT_HINT : 0x0
- PID : 3344
- FLAGS :
- SERVICE_NAME: WinHttpAutoProxySvc
- DISPLAY_NAME: WinHTTP Web Proxy Auto-Discovery Service
- TYPE : 30 WIN32
- STATE : 4 RUNNING
- (STOPPABLE, NOT_PAUSABLE, IGNORES_SHUTDOWN)
- WIN32_EXIT_CODE : 0 (0x0)
- SERVICE_EXIT_CODE : 0 (0x0)
- CHECKPOINT : 0x0
- WAIT_HINT : 0x0
- PID : 3076
- FLAGS :
- SERVICE_NAME: Winmgmt
- DISPLAY_NAME: Windows Management Instrumentation
- TYPE : 30 WIN32
- STATE : 4 RUNNING
- (STOPPABLE, PAUSABLE, ACCEPTS_SHUTDOWN)
- WIN32_EXIT_CODE : 0 (0x0)
- SERVICE_EXIT_CODE : 0 (0x0)
- CHECKPOINT : 0x0
- WAIT_HINT : 0x0
- PID : 2152
- FLAGS :
- SERVICE_NAME: WlanSvc
- DISPLAY_NAME: WLAN AutoConfig
- TYPE : 10 WIN32_OWN_PROCESS
- STATE : 4 RUNNING
- (STOPPABLE, NOT_PAUSABLE, ACCEPTS_SHUTDOWN)
- WIN32_EXIT_CODE : 0 (0x0)
- SERVICE_EXIT_CODE : 0 (0x0)
- CHECKPOINT : 0x0
- WAIT_HINT : 0x0
- PID : 2612
- FLAGS :
- SERVICE_NAME: WpnService
- DISPLAY_NAME: Windows Push Notifications System Service
- TYPE : 30 WIN32
- STATE : 4 RUNNING
- (STOPPABLE, NOT_PAUSABLE, IGNORES_SHUTDOWN)
- WIN32_EXIT_CODE : 0 (0x0)
- SERVICE_EXIT_CODE : 0 (0x0)
- CHECKPOINT : 0x0
- WAIT_HINT : 0x0
- PID : 3040
- FLAGS :
- SERVICE_NAME: wscsvc
- DISPLAY_NAME: Security Center
- TYPE : 30 WIN32
- STATE : 4 RUNNING
- (STOPPABLE, NOT_PAUSABLE, ACCEPTS_SHUTDOWN)
- WIN32_EXIT_CODE : 0 (0x0)
- SERVICE_EXIT_CODE : 0 (0x0)
- CHECKPOINT : 0x0
- WAIT_HINT : 0x0
- PID : 8644
- FLAGS :
- SERVICE_NAME: WSearch
- DISPLAY_NAME: Windows Search
- TYPE : 10 WIN32_OWN_PROCESS
- STATE : 4 RUNNING
- (STOPPABLE, NOT_PAUSABLE, ACCEPTS_SHUTDOWN)
- WIN32_EXIT_CODE : 0 (0x0)
- SERVICE_EXIT_CODE : 0 (0x0)
- CHECKPOINT : 0x0
- WAIT_HINT : 0x0
- PID : 4320
- FLAGS :
- SERVICE_NAME: CDPUserSvc_3875f
- DISPLAY_NAME: Connected Devices Platform User Service_3875f
- TYPE : f0 ERROR
- STATE : 4 RUNNING
- (STOPPABLE, NOT_PAUSABLE, IGNORES_SHUTDOWN)
- WIN32_EXIT_CODE : 0 (0x0)
- SERVICE_EXIT_CODE : 0 (0x0)
- CHECKPOINT : 0x0
- WAIT_HINT : 0x0
- PID : 4708
- FLAGS :
- SERVICE_NAME: OneSyncSvc_3875f
- DISPLAY_NAME: Sync Host_3875f
- TYPE : e0 USER_SHARE_PROCESS INSTANCE
- STATE : 4 RUNNING
- (STOPPABLE, NOT_PAUSABLE, IGNORES_SHUTDOWN)
- WIN32_EXIT_CODE : 0 (0x0)
- SERVICE_EXIT_CODE : 0 (0x0)
- CHECKPOINT : 0x0
- WAIT_HINT : 0x0
- PID : 4372
- FLAGS :
- SERVICE_NAME: WpnUserService_3875f
- DISPLAY_NAME: Windows Push Notifications User Service_3875f
- TYPE : f0 ERROR
- STATE : 4 RUNNING
- (STOPPABLE, NOT_PAUSABLE, ACCEPTS_PRESHUTDOWN)
- WIN32_EXIT_CODE : 0 (0x0)
- SERVICE_EXIT_CODE : 0 (0x0)
- CHECKPOINT : 0x0
- WAIT_HINT : 0x0
- PID : 4748
- FLAGS :
- ******************************************************************************
- Scheduled task list
- ******************************************************************************
- Folder: \
- HostName: DESKTOP-GU6TEMK
- TaskName: \AutoKMS
- Next Run Time: 30/05/2017 14:50:01
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \AutoKMS
- Next Run Time: 30/05/2017 14:50:01
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \AutoKMS
- Next Run Time: 30/05/2017 14:50:01
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \DriverToolkit Autorun
- Next Run Time: N/A
- Status: Running
- Logon Mode: Interactive only
- HostName: DESKTOP-GU6TEMK
- TaskName: \GoogleUpdateTaskMachineCore
- Next Run Time: 29/05/2017 17:55:17
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \GoogleUpdateTaskMachineCore
- Next Run Time: 29/05/2017 17:55:17
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \GoogleUpdateTaskMachineUA
- Next Run Time: 29/05/2017 15:55:17
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \OneDrive Standalone Update Task v2
- Next Run Time: 30/05/2017 13:28:17
- Status: Ready
- Logon Mode: Interactive only
- HostName: DESKTOP-GU6TEMK
- TaskName: \Reimage Reminder
- Next Run Time: 31/05/2017 21:05:00
- Status: Ready
- Logon Mode: Interactive only
- HostName: DESKTOP-GU6TEMK
- TaskName: \ReimageUpdater
- Next Run Time: 29/05/2017 15:05:12
- Status: Ready
- Logon Mode: Interactive only
- HostName: DESKTOP-GU6TEMK
- TaskName: \ReimageUpdater
- Next Run Time: 29/05/2017 15:05:12
- Status: Ready
- Logon Mode: Interactive only
- Folder: \Microsoft
- INFO: There are no scheduled tasks presently available at your access level.
- Folder: \Microsoft\Windows
- INFO: There are no scheduled tasks presently available at your access level.
- Folder: \Microsoft\Windows\.NET Framework
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 64
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 64 Critical
- Next Run Time: N/A
- Status: Disabled
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 Critical
- Next Run Time: N/A
- Status: Disabled
- Logon Mode: Interactive/Background
- Folder: \Microsoft\Windows\Active Directory Rights Management Services Client
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Automated)
- Next Run Time: N/A
- Status: Disabled
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Automated)
- Next Run Time: N/A
- Status: Disabled
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Manual)
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- Folder: \Microsoft\Windows\AppID
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\AppID\EDP Policy Manager
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\AppID\EDP Policy Manager
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\AppID\PolicyConverter
- Next Run Time: N/A
- Status: Disabled
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\AppID\VerifiedPublisherCertStoreCheck
- Next Run Time: N/A
- Status: Disabled
- Logon Mode: Interactive/Background
- Folder: \Microsoft\Windows\Application Experience
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser
- Next Run Time: 30/05/2017 04:18:39
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser
- Next Run Time: 30/05/2017 03:04:04
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\Application Experience\ProgramDataUpdater
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\Application Experience\StartupAppTask
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- Folder: \Microsoft\Windows\ApplicationData
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\ApplicationData\appuriverifierdaily
- Next Run Time: 30/05/2017 03:00:00
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\ApplicationData\appuriverifierinstall
- Next Run Time: 03/06/2017 03:00:00
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\ApplicationData\appuriverifierinstall
- Next Run Time: 03/06/2017 03:00:00
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\ApplicationData\CleanupTemporaryState
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\ApplicationData\DsSvcCleanup
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- Folder: \Microsoft\Windows\AppxDeploymentClient
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup
- Next Run Time: N/A
- Status: Disabled
- Logon Mode: Interactive/Background
- Folder: \Microsoft\Windows\Autochk
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\Autochk\Proxy
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- Folder: \Microsoft\Windows\BitLocker
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\BitLocker\BitLocker MDM policy Refresh
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- Folder: \Microsoft\Windows\Bluetooth
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\Bluetooth\UninstallDeviceTask
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- Folder: \Microsoft\Windows\BrokerInfrastructure
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\BrokerInfrastructure\BgTaskRegistrationMaintenanceTask
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- Folder: \Microsoft\Windows\CertificateServicesClient
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\CertificateServicesClient\AikCertEnrollTask
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\CertificateServicesClient\CryptoPolicyTask
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\CertificateServicesClient\KeyPreGenTask
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\CertificateServicesClient\KeyPreGenTask
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\CertificateServicesClient\KeyPreGenTask
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\CertificateServicesClient\KeyPreGenTask
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\CertificateServicesClient\KeyPreGenTask
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\CertificateServicesClient\SystemTask
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\CertificateServicesClient\SystemTask
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\CertificateServicesClient\SystemTask
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\CertificateServicesClient\UserTask
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\CertificateServicesClient\UserTask
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\CertificateServicesClient\UserTask
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\CertificateServicesClient\UserTask
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\CertificateServicesClient\UserTask-Roam
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\CertificateServicesClient\UserTask-Roam
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- Folder: \Microsoft\Windows\Chkdsk
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\Chkdsk\ProactiveScan
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- Folder: \Microsoft\Windows\Clip
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\Clip\License Validation
- Next Run Time: N/A
- Status: Disabled
- Logon Mode: Interactive/Background
- Folder: \Microsoft\Windows\CloudExperienceHost
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\CloudExperienceHost\CreateObjectTask
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- Folder: \Microsoft\Windows\Customer Experience Improvement Program
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\Customer Experience Improvement Program\Consolidator
- Next Run Time: 29/05/2017 18:00:00
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\Customer Experience Improvement Program\KernelCeipTask
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\Customer Experience Improvement Program\UsbCeip
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- Folder: \Microsoft\Windows\Data Integrity Scan
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\Data Integrity Scan\Data Integrity Scan
- Next Run Time: 17/06/2017 12:31:51
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\Data Integrity Scan\Data Integrity Scan
- Next Run Time: 16/06/2017 08:23:46
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\Data Integrity Scan\Data Integrity Scan for Crash Recovery
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- Folder: \Microsoft\Windows\Defrag
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\Defrag\ScheduledDefrag
- Next Run Time: N/A
- Status: Disabled
- Logon Mode: Interactive/Background
- Folder: \Microsoft\Windows\Device Information
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\Device Information\Device
- Next Run Time: 30/05/2017 03:40:03
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\Device Information\Device
- Next Run Time: 30/05/2017 04:48:57
- Status: Ready
- Logon Mode: Interactive/Background
- Folder: \Microsoft\Windows\Device Setup
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\Device Setup\Metadata Refresh
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- Folder: \Microsoft\Windows\DeviceDirectoryClient
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\DeviceDirectoryClient\HandleCommand
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\DeviceDirectoryClient\HandleWnsCommand
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\DeviceDirectoryClient\IntegrityCheck
- Next Run Time: 02/06/2017 12:15:46
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\DeviceDirectoryClient\LocateCommandUserSession
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\DeviceDirectoryClient\RegisterDeviceAccountChange
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\DeviceDirectoryClient\RegisterDeviceAccountChange
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\DeviceDirectoryClient\RegisterDeviceLocationRightsChange
- Next Run Time: N/A
- Status: Disabled
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\DeviceDirectoryClient\RegisterDevicePeriodic24
- Next Run Time: N/A
- Status: Disabled
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\DeviceDirectoryClient\RegisterDevicePolicyChange
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\DeviceDirectoryClient\RegisterDevicePolicyChange
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\DeviceDirectoryClient\RegisterDeviceProtectionStateChanged
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\DeviceDirectoryClient\RegisterDeviceSettingChange
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\DeviceDirectoryClient\RegisterDeviceSettingChange
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\DeviceDirectoryClient\RegisterUserDevice
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\DeviceDirectoryClient\RegisterUserDevice
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- Folder: \Microsoft\Windows\Diagnosis
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\Diagnosis\Scheduled
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- Folder: \Microsoft\Windows\DiskCleanup
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\DiskCleanup\SilentCleanup
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- Folder: \Microsoft\Windows\DiskDiagnostic
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticResolver
- Next Run Time: N/A
- Status: Disabled
- Logon Mode: Interactive/Background
- Folder: \Microsoft\Windows\DiskFootprint
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\DiskFootprint\Diagnostics
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\DiskFootprint\StorageSense
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- Folder: \Microsoft\Windows\DUSM
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\DUSM\dusmtask
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- Folder: \Microsoft\Windows\EDP
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\EDP\EDP App Launch Task
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\EDP\EDP Auth Task
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\EDP\EDP Inaccessible Credentials Task
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\EDP\StorageCardEncryption Task
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- Folder: \Microsoft\Windows\Feedback
- INFO: There are no scheduled tasks presently available at your access level.
- Folder: \Microsoft\Windows\Feedback\Siuf
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\Feedback\Siuf\DmClient
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\Feedback\Siuf\DmClientOnScenarioDownload
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- Folder: \Microsoft\Windows\FileHistory
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\FileHistory\File History (maintenance mode)
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- Folder: \Microsoft\Windows\LanguageComponentsInstaller
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\LanguageComponentsInstaller\Installation
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\LanguageComponentsInstaller\Installation
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\LanguageComponentsInstaller\Uninstallation
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- Folder: \Microsoft\Windows\License Manager
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\License Manager\TempSignedLicenseExchange
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- Folder: \Microsoft\Windows\Live
- INFO: There are no scheduled tasks presently available at your access level.
- Folder: \Microsoft\Windows\Location
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\Location\Notifications
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\Location\WindowsActionDialog
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- Folder: \Microsoft\Windows\Maintenance
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\Maintenance\WinSAT
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- Folder: \Microsoft\Windows\Management
- INFO: There are no scheduled tasks presently available at your access level.
- Folder: \Microsoft\Windows\Management\Provisioning
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\Management\Provisioning\Cellular
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\Management\Provisioning\Logon
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- Folder: \Microsoft\Windows\Maps
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\Maps\MapsToastTask
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\Maps\MapsUpdateTask
- Next Run Time: N/A
- Status: Disabled
- Logon Mode: Interactive/Background
- Folder: \Microsoft\Windows\MemoryDiagnostic
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\MemoryDiagnostic\ProcessMemoryDiagnosticEvents
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\MemoryDiagnostic\ProcessMemoryDiagnosticEvents
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\MemoryDiagnostic\ProcessMemoryDiagnosticEvents
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\MemoryDiagnostic\ProcessMemoryDiagnosticEvents
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\MemoryDiagnostic\RunFullMemoryDiagnostic
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- Folder: \Microsoft\Windows\Mobile Broadband Accounts
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- Folder: \Microsoft\Windows\MUI
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\MUI\LPRemove
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- Folder: \Microsoft\Windows\Multimedia
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\Multimedia\SystemSoundsService
- Next Run Time: N/A
- Status: Running
- Logon Mode: Interactive/Background
- Folder: \Microsoft\Windows\NetTrace
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\NetTrace\GatherNetworkInfo
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- Folder: \Microsoft\Windows\NlaSvc
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\NlaSvc\WiFiTask
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- Folder: \Microsoft\Windows\PI
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\PI\Secure-Boot-Update
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\PI\Sqm-Tasks
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- Folder: \Microsoft\Windows\PLA
- INFO: There are no scheduled tasks presently available at your access level.
- Folder: \Microsoft\Windows\Plug and Play
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\Plug and Play\Device Install Group Policy
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\Plug and Play\Device Install Reboot Required
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\Plug and Play\Device Install Reboot Required
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\Plug and Play\Sysprep Generalize Drivers
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- Folder: \Microsoft\Windows\Power Efficiency Diagnostics
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\Power Efficiency Diagnostics\AnalyzeSystem
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- Folder: \Microsoft\Windows\Ras
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\Ras\MobilityManager
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- Folder: \Microsoft\Windows\RecoveryEnvironment
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\RecoveryEnvironment\VerifyWinRE
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- Folder: \Microsoft\Windows\Registry
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\Registry\RegIdleBackup
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- Folder: \Microsoft\Windows\RemoteAssistance
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\RemoteAssistance\RemoteAssistanceTask
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\RemoteAssistance\RemoteAssistanceTask
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- Folder: \Microsoft\Windows\RetailDemo
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\RetailDemo\CleanupOfflineContent
- Next Run Time: 03/06/2017 19:31:11
- Status: Ready
- Logon Mode: Interactive/Background
- Folder: \Microsoft\Windows\Servicing
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\Servicing\StartComponentCleanup
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- Folder: \Microsoft\Windows\SettingSync
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\SettingSync\BackgroundUploadTask
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\SettingSync\BackupTask
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\SettingSync\NetworkStateChangeTask
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\SettingSync\NetworkStateChangeTask
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- Folder: \Microsoft\Windows\Setup
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\Setup\SetupCleanupTask
- Next Run Time: 02/06/2017 06:00:00
- Status: Ready
- Logon Mode: Interactive/Background
- Folder: \Microsoft\Windows\SharedPC
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\SharedPC\Account Cleanup
- Next Run Time: N/A
- Status: Disabled
- Logon Mode: Interactive/Background
- Folder: \Microsoft\Windows\Shell
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\Shell\CreateObjectTask
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\Shell\FamilySafetyMonitor
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\Shell\FamilySafetyMonitorToastTask
- Next Run Time: N/A
- Status: Disabled
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\Shell\FamilySafetyRefreshTask
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\Shell\IndexerAutomaticMaintenance
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- Folder: \Microsoft\Windows\SoftwareProtectionPlatform
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask
- Next Run Time: 28/06/2017 14:45:39
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTaskLogon
- Next Run Time: N/A
- Status: Disabled
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTaskNetwork
- Next Run Time: N/A
- Status: Disabled
- Logon Mode: Interactive/Background
- Folder: \Microsoft\Windows\SpacePort
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\SpacePort\SpaceAgentTask
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\SpacePort\SpaceAgentTask
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\SpacePort\SpaceManagerTask
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\SpacePort\SpaceManagerTask
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- Folder: \Microsoft\Windows\Speech
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\Speech\SpeechModelDownloadTask
- Next Run Time: 30/05/2017 00:00:00
- Status: Ready
- Logon Mode: Interactive/Background
- Folder: \Microsoft\Windows\Storage Tiers Management
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\Storage Tiers Management\Storage Tiers Management Initialization
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\Storage Tiers Management\Storage Tiers Optimization
- Next Run Time: N/A
- Status: Disabled
- Logon Mode: Interactive/Background
- Folder: \Microsoft\Windows\Subscription
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\Subscription\EnableLicenseAcquisition
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\Subscription\EnableLicenseAcquisition
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\Subscription\EnableLicenseAcquisition
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\Subscription\LicenseAcquisition
- Next Run Time: N/A
- Status: Disabled
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\Subscription\LicenseAcquisition
- Next Run Time: N/A
- Status: Disabled
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\Subscription\LicenseAcquisition
- Next Run Time: N/A
- Status: Disabled
- Logon Mode: Interactive/Background
- Folder: \Microsoft\Windows\Sysmain
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\Sysmain\HybridDriveCachePrepopulate
- Next Run Time: N/A
- Status: Disabled
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\Sysmain\HybridDriveCacheRebalance
- Next Run Time: N/A
- Status: Disabled
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\Sysmain\ResPriStaticDbSync
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\Sysmain\WsSwapAssessmentTask
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- Folder: \Microsoft\Windows\SystemRestore
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\SystemRestore\SR
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- Folder: \Microsoft\Windows\Task Manager
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\Task Manager\Interactive
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- Folder: \Microsoft\Windows\TextServicesFramework
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\TextServicesFramework\MsCtfMonitor
- Next Run Time: N/A
- Status: Running
- Logon Mode: Interactive/Background
- Folder: \Microsoft\Windows\Time Synchronization
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\Time Synchronization\ForceSynchronizeTime
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\Time Synchronization\SynchronizeTime
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- Folder: \Microsoft\Windows\Time Zone
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\Time Zone\SynchronizeTimeZone
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- Folder: \Microsoft\Windows\TPM
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\TPM\Tpm-HASCertRetr
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\TPM\Tpm-Maintenance
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\TPM\Tpm-Maintenance
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\TPM\Tpm-Maintenance
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- Folder: \Microsoft\Windows\UpdateOrchestrator
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\UpdateOrchestrator\Combined Scan Download Install
- Next Run Time: N/A
- Status: Disabled
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\UpdateOrchestrator\Maintenance Install
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\UpdateOrchestrator\Policy Install
- Next Run Time: N/A
- Status: Disabled
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\UpdateOrchestrator\Reboot
- Next Run Time: N/A
- Status: Disabled
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\UpdateOrchestrator\Refresh Settings
- Next Run Time: 30/05/2017 03:23:34
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\UpdateOrchestrator\Resume On Boot
- Next Run Time: N/A
- Status: Disabled
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\UpdateOrchestrator\Schedule Scan
- Next Run Time: 29/05/2017 17:17:47
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\UpdateOrchestrator\Schedule Scan
- Next Run Time: 29/05/2017 19:05:30
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\UpdateOrchestrator\Schedule Scan
- Next Run Time: 29/05/2017 19:40:00
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\UpdateOrchestrator\USO_UxBroker_Display
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\UpdateOrchestrator\USO_UxBroker_ReadyToReboot
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- Folder: \Microsoft\Windows\UPnP
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\UPnP\UPnPHostConfig
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- Folder: \Microsoft\Windows\User Profile Service
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\User Profile Service\HiveUploadTask
- Next Run Time: N/A
- Status: Disabled
- Logon Mode: Interactive/Background
- Folder: \Microsoft\Windows\WCM
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\WCM\WiFiTask
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- Folder: \Microsoft\Windows\WDI
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\WDI\ResolutionHost
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- Folder: \Microsoft\Windows\Windows Defender
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\Windows Defender\Windows Defender Cleanup
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\Windows Defender\Windows Defender Verification
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- Folder: \Microsoft\Windows\Windows Error Reporting
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\Windows Error Reporting\QueueReporting
- Next Run Time: 29/05/2017 18:31:26
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\Windows Error Reporting\QueueReporting
- Next Run Time: 29/05/2017 20:57:18
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\Windows Error Reporting\QueueReporting
- Next Run Time: 29/05/2017 20:35:44
- Status: Ready
- Logon Mode: Interactive/Background
- Folder: \Microsoft\Windows\Windows Filtering Platform
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\Windows Filtering Platform\BfeOnServiceStartTypeChange
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- Folder: \Microsoft\Windows\Windows Media Sharing
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\Windows Media Sharing\UpdateLibrary
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- Folder: \Microsoft\Windows\WindowsColorSystem
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\WindowsColorSystem\Calibration Loader
- Next Run Time: N/A
- Status: Disabled
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\WindowsColorSystem\Calibration Loader
- Next Run Time: N/A
- Status: Disabled
- Logon Mode: Interactive/Background
- Folder: \Microsoft\Windows\WindowsUpdate
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\WindowsUpdate\Automatic App Update
- Next Run Time: 29/05/2017 18:56:32
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\WindowsUpdate\Automatic App Update
- Next Run Time: 29/05/2017 18:53:16
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\WindowsUpdate\Scheduled Start
- Next Run Time: 29/05/2017 19:31:50
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\WindowsUpdate\Scheduled Start
- Next Run Time: 29/05/2017 19:31:43
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\WindowsUpdate\Scheduled Start
- Next Run Time: 29/05/2017 19:31:25
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\WindowsUpdate\Scheduled Start
- Next Run Time: 29/05/2017 19:31:37
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\WindowsUpdate\sih
- Next Run Time: 30/05/2017 02:14:54
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\WindowsUpdate\sihboot
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- Folder: \Microsoft\Windows\Wininet
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\Wininet\CacheTask
- Next Run Time: N/A
- Status: Running
- Logon Mode: Interactive/Background
- Folder: \Microsoft\Windows\WOF
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\WOF\WIM-Hash-Management
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\WOF\WIM-Hash-Management
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\WOF\WIM-Hash-Validation
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- Folder: \Microsoft\Windows\Work Folders
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\Work Folders\Work Folders Logon Synchronization
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\Work Folders\Work Folders Maintenance Work
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- Folder: \Microsoft\Windows\Workplace Join
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\Workplace Join\Automatic-Device-Join
- Next Run Time: N/A
- Status: Disabled
- Logon Mode: Interactive/Background
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\Workplace Join\Automatic-Device-Join
- Next Run Time: N/A
- Status: Disabled
- Logon Mode: Interactive/Background
- Folder: \Microsoft\Windows\WwanSvc
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\Windows\WwanSvc\NotificationTask
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- Folder: \Microsoft\XblGameSave
- HostName: DESKTOP-GU6TEMK
- TaskName: \Microsoft\XblGameSave\XblGameSaveTask
- Next Run Time: N/A
- Status: Ready
- Logon Mode: Interactive/Background
- ******************************************************************************
- Contents of the Hosts file
- ******************************************************************************
- # Copyright (c) 1993-2009 Microsoft Corp.
- #
- # This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
- #
- # This file contains the mappings of IP addresses to host names. Each
- # entry should be kept on an individual line. The IP address should
- # be placed in the first column followed by the corresponding host name.
- # The IP address and the host name should be separated by at least one
- # space.
- #
- # Additionally, comments (such as these) may be inserted on individual
- # lines or following the machine name denoted by a '#' symbol.
- #
- # For example:
- #
- # 102.54.94.97 rhino.acme.com # source server
- # 38.25.63.10 x.acme.com # x client host
- # localhost name resolution is handled within DNS itself.
- # 127.0.0.1 localhost
- # ::1 localhost
- ******************************************************************************
- NetWork Connections
- ******************************************************************************
- Active Connections
- Proto Local Address Foreign Address State
- TCP 0.0.0.0:135 DESKTOP-GU6TEMK:0 LISTENING
- TCP 0.0.0.0:445 DESKTOP-GU6TEMK:0 LISTENING
- TCP 0.0.0.0:8732 DESKTOP-GU6TEMK:0 LISTENING
- TCP 0.0.0.0:27036 DESKTOP-GU6TEMK:0 LISTENING
- TCP 0.0.0.0:49664 DESKTOP-GU6TEMK:0 LISTENING
- TCP 0.0.0.0:49665 DESKTOP-GU6TEMK:0 LISTENING
- TCP 0.0.0.0:49666 DESKTOP-GU6TEMK:0 LISTENING
- TCP 0.0.0.0:49667 DESKTOP-GU6TEMK:0 LISTENING
- TCP 0.0.0.0:49668 DESKTOP-GU6TEMK:0 LISTENING
- TCP 0.0.0.0:49670 DESKTOP-GU6TEMK:0 LISTENING
- TCP 0.0.0.0:49805 DESKTOP-GU6TEMK:0 LISTENING
- TCP 127.0.0.1:9990 DESKTOP-GU6TEMK:0 LISTENING
- TCP 127.0.0.1:23401 DESKTOP-GU6TEMK:0 LISTENING
- TCP 192.168.1.62:139 DESKTOP-GU6TEMK:0 LISTENING
- TCP 192.168.1.62:49978 104.20.209.21:https TIME_WAIT
- TCP 192.168.1.62:49979 185.33.223.198:https CLOSE_WAIT
- TCP 192.168.1.62:49980 185.33.223.198:https CLOSE_WAIT
- TCP 192.168.1.62:49986 13.107.21.200:https ESTABLISHED
- TCP [::]:135 DESKTOP-GU6TEMK:0 LISTENING
- TCP [::]:445 DESKTOP-GU6TEMK:0 LISTENING
- TCP [::]:8732 DESKTOP-GU6TEMK:0 LISTENING
- TCP [::]:49664 DESKTOP-GU6TEMK:0 LISTENING
- TCP [::]:49665 DESKTOP-GU6TEMK:0 LISTENING
- TCP [::]:49666 DESKTOP-GU6TEMK:0 LISTENING
- TCP [::]:49667 DESKTOP-GU6TEMK:0 LISTENING
- TCP [::]:49668 DESKTOP-GU6TEMK:0 LISTENING
- TCP [::]:49670 DESKTOP-GU6TEMK:0 LISTENING
- TCP [::]:49805 DESKTOP-GU6TEMK:0 LISTENING
- UDP 0.0.0.0:500 *:*
- UDP 0.0.0.0:4500 *:*
- UDP 0.0.0.0:5050 *:*
- UDP 0.0.0.0:5353 *:*
- UDP 0.0.0.0:5355 *:*
- UDP 0.0.0.0:27036 *:*
- UDP 0.0.0.0:56662 *:*
- UDP 127.0.0.1:1900 *:*
- UDP 127.0.0.1:48200 *:*
- UDP 127.0.0.1:54634 *:*
- UDP 192.168.1.62:137 *:*
- UDP 192.168.1.62:138 *:*
- UDP 192.168.1.62:1900 *:*
- UDP 192.168.1.62:54633 *:*
- UDP [::]:500 *:*
- UDP [::]:4500 *:*
- UDP [::]:5353 *:*
- UDP [::]:5355 *:*
- UDP [::1]:1900 *:*
- UDP [::1]:54632 *:*
- UDP [fe80::e8eb:65c6:13c9:ccb4%17]:1900 *:*
- UDP [fe80::e8eb:65c6:13c9:ccb4%17]:54631 *:*
- ******************************************************************************
- DNS Cache
- ******************************************************************************
- Windows IP Configuration
- fw.adsafeprotected.com
- ----------------------------------------
- Record Name . . . . . : fw.adsafeprotected.com
- Record Type . . . . . : 5
- Time To Live . . . . : 710
- Data Length . . . . . : 8
- Section . . . . . . . : Answer
- CNAME Record . . . . : anycast.fw.adsafeprotected.com
- Record Name . . . . . : anycast.fw.adsafeprotected.com
- Record Type . . . . . : 1
- Time To Live . . . . : 710
- Data Length . . . . . : 4
- Section . . . . . . . : Answer
- A (Host) Record . . . : 69.172.216.56
- Record Name . . . . . : dns1.p05.nsone.net
- Record Type . . . . . : 1
- Time To Live . . . . : 710
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 198.51.44.5
- Record Name . . . . . : dns2.p05.nsone.net
- Record Type . . . . . : 1
- Time To Live . . . . : 710
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 198.51.45.5
- Record Name . . . . . : dns3.p05.nsone.net
- Record Type . . . . . : 1
- Time To Live . . . . : 710
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 198.51.44.69
- Record Name . . . . . : dns4.p05.nsone.net
- Record Type . . . . . : 1
- Time To Live . . . . : 710
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 198.51.45.69
- gds2.steampowered.com
- ----------------------------------------
- Record Name . . . . . : gds2.steampowered.com
- Record Type . . . . . : 1
- Time To Live . . . . : 616
- Data Length . . . . . : 4
- Section . . . . . . . : Answer
- A (Host) Record . . . : 208.64.201.136
- Record Name . . . . . : a8-66.akam.net
- Record Type . . . . . : 1
- Time To Live . . . . : 616
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 2.16.40.66
- Record Name . . . . . : a9-67.akam.net
- Record Type . . . . . : 1
- Time To Live . . . . : 616
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 184.85.248.67
- Record Name . . . . . : a9-67.akam.net
- Record Type . . . . . : 28
- Time To Live . . . . : 616
- Data Length . . . . . : 16
- Section . . . . . . . : Additional
- AAAA Record . . . . . : 2a02:26f0:117::43
- Record Name . . . . . : a1-164.akam.net
- Record Type . . . . . : 1
- Time To Live . . . . : 616
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 193.108.91.164
- Record Name . . . . . : a1-164.akam.net
- Record Type . . . . . : 28
- Time To Live . . . . : 616
- Data Length . . . . . : 16
- Section . . . . . . . : Additional
- AAAA Record . . . . . : 2600:1401:2::a4
- Record Name . . . . . : a11-67.akam.net
- Record Type . . . . . : 1
- Time To Live . . . . : 616
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 84.53.139.67
- Record Name . . . . . : a11-67.akam.net
- Record Type . . . . . : 28
- Time To Live . . . . : 616
- Data Length . . . . . : 16
- Section . . . . . . . : Additional
- AAAA Record . . . . . : 2600:1480:1::43
- Record Name . . . . . : a24-64.akam.net
- Record Type . . . . . : 1
- Time To Live . . . . : 616
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 2.16.130.64
- Record Name . . . . . : a26-65.akam.net
- Record Type . . . . . : 1
- Time To Live . . . . : 616
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 23.74.25.65
- pastebin.com
- ----------------------------------------
- Record Name . . . . . : pastebin.com
- Record Type . . . . . : 1
- Time To Live . . . . : 71
- Data Length . . . . . : 4
- Section . . . . . . . : Answer
- A (Host) Record . . . : 104.20.209.21
- Record Name . . . . . : pastebin.com
- Record Type . . . . . : 1
- Time To Live . . . . : 71
- Data Length . . . . . : 4
- Section . . . . . . . : Answer
- A (Host) Record . . . : 104.20.208.21
- Record Name . . . . . : sue.ns.cloudflare.com
- Record Type . . . . . : 1
- Time To Live . . . . : 71
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 173.245.58.145
- Record Name . . . . . : sue.ns.cloudflare.com
- Record Type . . . . . : 28
- Time To Live . . . . : 71
- Data Length . . . . . : 16
- Section . . . . . . . : Additional
- AAAA Record . . . . . : 2400:cb00:2049:1::adf5:3a91
- Record Name . . . . . : todd.ns.cloudflare.com
- Record Type . . . . . : 1
- Time To Live . . . . : 71
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 173.245.59.146
- Record Name . . . . . : todd.ns.cloudflare.com
- Record Type . . . . . : 28
- Time To Live . . . . : 71
- Data Length . . . . . : 16
- Section . . . . . . . : Additional
- AAAA Record . . . . . : 2400:cb00:2049:1::adf5:3b92
- gds4.steampowered.com
- ----------------------------------------
- Record Name . . . . . : gds4.steampowered.com
- Record Type . . . . . : 1
- Time To Live . . . . : 2698
- Data Length . . . . . : 4
- Section . . . . . . . : Answer
- A (Host) Record . . . : 208.64.201.136
- Record Name . . . . . : a8-66.akam.net
- Record Type . . . . . : 1
- Time To Live . . . . : 2698
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 2.16.40.66
- Record Name . . . . . : a8-66.akam.net
- Record Type . . . . . : 28
- Time To Live . . . . : 2698
- Data Length . . . . . : 16
- Section . . . . . . . : Additional
- AAAA Record . . . . . : 2600:1403:a::42
- Record Name . . . . . : a9-67.akam.net
- Record Type . . . . . : 1
- Time To Live . . . . : 2698
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 184.85.248.67
- Record Name . . . . . : a1-164.akam.net
- Record Type . . . . . : 1
- Time To Live . . . . : 2698
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 193.108.91.164
- Record Name . . . . . : a1-164.akam.net
- Record Type . . . . . : 28
- Time To Live . . . . : 2698
- Data Length . . . . . : 16
- Section . . . . . . . : Additional
- AAAA Record . . . . . : 2600:1401:2::a4
- Record Name . . . . . : a11-67.akam.net
- Record Type . . . . . : 1
- Time To Live . . . . : 2698
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 84.53.139.67
- Record Name . . . . . : a24-64.akam.net
- Record Type . . . . . : 1
- Time To Live . . . . : 2698
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 2.16.130.64
- Record Name . . . . . : a26-65.akam.net
- Record Type . . . . . : 1
- Time To Live . . . . : 2698
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 23.74.25.65
- dt.adsafeprotected.com
- ----------------------------------------
- Record Name . . . . . : dt.adsafeprotected.com
- Record Type . . . . . : 5
- Time To Live . . . . : 4669
- Data Length . . . . . : 8
- Section . . . . . . . : Answer
- CNAME Record . . . . : anycast.dt.adsafeprotected.com
- Record Name . . . . . : anycast.dt.adsafeprotected.com
- Record Type . . . . . : 1
- Time To Live . . . . : 4669
- Data Length . . . . . : 4
- Section . . . . . . . : Answer
- A (Host) Record . . . : 69.172.216.111
- Record Name . . . . . : dns1.p05.nsone.net
- Record Type . . . . . : 1
- Time To Live . . . . : 4669
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 198.51.44.5
- Record Name . . . . . : dns2.p05.nsone.net
- Record Type . . . . . : 1
- Time To Live . . . . : 4669
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 198.51.45.5
- Record Name . . . . . : dns3.p05.nsone.net
- Record Type . . . . . : 1
- Time To Live . . . . : 4669
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 198.51.44.69
- Record Name . . . . . : dns4.p05.nsone.net
- Record Type . . . . . : 1
- Time To Live . . . . : 4669
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 198.51.45.69
- s1.wp.com
- ----------------------------------------
- Record Name . . . . . : s1.wp.com
- Record Type . . . . . : 1
- Time To Live . . . . : 6823
- Data Length . . . . . : 4
- Section . . . . . . . : Answer
- A (Host) Record . . . : 192.0.77.32
- Record Name . . . . . : ns1.automattic.com
- Record Type . . . . . : 1
- Time To Live . . . . : 6823
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 198.181.116.5
- Record Name . . . . . : ns1.automattic.com
- Record Type . . . . . : 28
- Time To Live . . . . : 6823
- Data Length . . . . . : 16
- Section . . . . . . . : Additional
- AAAA Record . . . . . : 2a04:fa87:ffff::c6b5:7405
- Record Name . . . . . : ns2.automattic.com
- Record Type . . . . . : 1
- Time To Live . . . . : 6823
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 198.181.117.5
- Record Name . . . . . : ns2.automattic.com
- Record Type . . . . . : 28
- Time To Live . . . . : 6823
- Data Length . . . . . : 16
- Section . . . . . . . : Additional
- AAAA Record . . . . . : 2a04:fa87:ffff::c6b5:7505
- Record Name . . . . . : ns3.automattic.com
- Record Type . . . . . : 1
- Time To Live . . . . : 6823
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 192.0.74.5
- Record Name . . . . . : ns3.automattic.com
- Record Type . . . . . : 28
- Time To Live . . . . : 6823
- Data Length . . . . . : 16
- Section . . . . . . . : Additional
- AAAA Record . . . . . : 2620:115:c00f::c000:4a05
- s2.wp.com
- ----------------------------------------
- Record Name . . . . . : s2.wp.com
- Record Type . . . . . : 1
- Time To Live . . . . : 155
- Data Length . . . . . : 4
- Section . . . . . . . : Answer
- A (Host) Record . . . : 192.0.77.32
- Record Name . . . . . : ns1.automattic.com
- Record Type . . . . . : 1
- Time To Live . . . . : 155
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 198.181.116.5
- Record Name . . . . . : ns1.automattic.com
- Record Type . . . . . : 28
- Time To Live . . . . : 155
- Data Length . . . . . : 16
- Section . . . . . . . : Additional
- AAAA Record . . . . . : 2a04:fa87:ffff::c6b5:7405
- Record Name . . . . . : ns2.automattic.com
- Record Type . . . . . : 1
- Time To Live . . . . : 155
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 198.181.117.5
- Record Name . . . . . : ns2.automattic.com
- Record Type . . . . . : 28
- Time To Live . . . . : 155
- Data Length . . . . . : 16
- Section . . . . . . . : Additional
- AAAA Record . . . . . : 2a04:fa87:ffff::c6b5:7505
- Record Name . . . . . : ns3.automattic.com
- Record Type . . . . . : 1
- Time To Live . . . . : 155
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 192.0.74.5
- Record Name . . . . . : ns3.automattic.com
- Record Type . . . . . : 28
- Time To Live . . . . : 155
- Data Length . . . . . : 16
- Section . . . . . . . : Additional
- AAAA Record . . . . . : 2620:115:c00f::c000:4a05
- valve418.steampipe.steamcontent.com
- ----------------------------------------
- Record Name . . . . . : valve418.steampipe.steamcontent.com
- Record Type . . . . . : 5
- Time To Live . . . . : 6007
- Data Length . . . . . : 8
- Section . . . . . . . : Answer
- CNAME Record . . . . : valve418.steamcontent.com
- Record Name . . . . . : valve418.steamcontent.com
- Record Type . . . . . : 1
- Time To Live . . . . : 6007
- Data Length . . . . . : 4
- Section . . . . . . . : Answer
- A (Host) Record . . . : 162.254.196.28
- Record Name . . . . . : a8-66.akam.net
- Record Type . . . . . : 1
- Time To Live . . . . : 6007
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 2.16.40.66
- Record Name . . . . . : a9-67.akam.net
- Record Type . . . . . : 1
- Time To Live . . . . : 6007
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 184.85.248.67
- Record Name . . . . . : a9-67.akam.net
- Record Type . . . . . : 28
- Time To Live . . . . : 6007
- Data Length . . . . . : 16
- Section . . . . . . . : Additional
- AAAA Record . . . . . : 2a02:26f0:117::43
- Record Name . . . . . : a1-164.akam.net
- Record Type . . . . . : 1
- Time To Live . . . . : 6007
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 193.108.91.164
- Record Name . . . . . : a1-164.akam.net
- Record Type . . . . . : 28
- Time To Live . . . . : 6007
- Data Length . . . . . : 16
- Section . . . . . . . : Additional
- AAAA Record . . . . . : 2600:1401:2::a4
- Record Name . . . . . : a11-67.akam.net
- Record Type . . . . . : 1
- Time To Live . . . . : 6007
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 84.53.139.67
- Record Name . . . . . : a11-67.akam.net
- Record Type . . . . . : 28
- Time To Live . . . . : 6007
- Data Length . . . . . : 16
- Section . . . . . . . : Additional
- AAAA Record . . . . . : 2600:1480:1::43
- Record Name . . . . . : a24-64.akam.net
- Record Type . . . . . : 1
- Time To Live . . . . : 6007
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 2.16.130.64
- Record Name . . . . . : a26-65.akam.net
- Record Type . . . . . : 1
- Time To Live . . . . : 6007
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 23.74.25.65
- cat.fr.eu.criteo.com
- ----------------------------------------
- Record Name . . . . . : cat.fr.eu.criteo.com
- Record Type . . . . . : 1
- Time To Live . . . . : 696
- Data Length . . . . . : 4
- Section . . . . . . . : Answer
- A (Host) Record . . . : 178.250.0.66
- Record Name . . . . . : ns1.criteo.com
- Record Type . . . . . : 1
- Time To Live . . . . : 696
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 178.250.0.4
- Record Name . . . . . : ns4.criteo.com
- Record Type . . . . . : 1
- Time To Live . . . . : 696
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 74.119.118.4
- Record Name . . . . . : ns6.criteo.com
- Record Type . . . . . : 1
- Time To Live . . . . : 696
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 182.161.73.4
- Record Name . . . . . : ns13.criteo.com
- Record Type . . . . . : 1
- Time To Live . . . . : 696
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 74.119.117.5
- Record Name . . . . . : ns17.criteo.com
- Record Type . . . . . : 1
- Time To Live . . . . : 696
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 178.250.6.6
- valve423.steampipe.steamcontent.com
- ----------------------------------------
- Record Name . . . . . : valve423.steampipe.steamcontent.com
- Record Type . . . . . : 5
- Time To Live . . . . : 5277
- Data Length . . . . . : 8
- Section . . . . . . . : Answer
- CNAME Record . . . . : valve423.steamcontent.com
- Record Name . . . . . : valve423.steamcontent.com
- Record Type . . . . . : 1
- Time To Live . . . . : 5277
- Data Length . . . . . : 4
- Section . . . . . . . : Answer
- A (Host) Record . . . : 162.254.196.33
- Record Name . . . . . : a8-66.akam.net
- Record Type . . . . . : 1
- Time To Live . . . . : 5277
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 2.16.40.66
- Record Name . . . . . : a8-66.akam.net
- Record Type . . . . . : 28
- Time To Live . . . . : 5277
- Data Length . . . . . : 16
- Section . . . . . . . : Additional
- AAAA Record . . . . . : 2600:1403:a::42
- Record Name . . . . . : a9-67.akam.net
- Record Type . . . . . : 1
- Time To Live . . . . : 5277
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 184.85.248.67
- Record Name . . . . . : a1-164.akam.net
- Record Type . . . . . : 1
- Time To Live . . . . : 5277
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 193.108.91.164
- Record Name . . . . . : a1-164.akam.net
- Record Type . . . . . : 28
- Time To Live . . . . : 5277
- Data Length . . . . . : 16
- Section . . . . . . . : Additional
- AAAA Record . . . . . : 2600:1401:2::a4
- Record Name . . . . . : a11-67.akam.net
- Record Type . . . . . : 1
- Time To Live . . . . : 5277
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 84.53.139.67
- Record Name . . . . . : a24-64.akam.net
- Record Type . . . . . : 1
- Time To Live . . . . : 5277
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 2.16.130.64
- Record Name . . . . . : a26-65.akam.net
- Record Type . . . . . : 1
- Time To Live . . . . : 5277
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 23.74.25.65
- aka-cdn.adtechus.com
- ----------------------------------------
- Record Name . . . . . : aka-cdn.adtechus.com
- Record Type . . . . . : 5
- Time To Live . . . . : 2791
- Data Length . . . . . : 8
- Section . . . . . . . : Answer
- CNAME Record . . . . : cs696.wac.thetacdn.net
- Record Name . . . . . : cs696.wac.thetacdn.net
- Record Type . . . . . : 1
- Time To Live . . . . : 2791
- Data Length . . . . . : 4
- Section . . . . . . . : Answer
- A (Host) Record . . . : 192.229.233.248
- Record Name . . . . . : a.gtld-servers.net
- Record Type . . . . . : 1
- Time To Live . . . . : 2791
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 192.5.6.30
- Record Name . . . . . : a.gtld-servers.net
- Record Type . . . . . : 28
- Time To Live . . . . : 2791
- Data Length . . . . . : 16
- Section . . . . . . . : Additional
- AAAA Record . . . . . : 2001:503:a83e::2:30
- Record Name . . . . . : b.gtld-servers.net
- Record Type . . . . . : 1
- Time To Live . . . . : 2791
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 192.33.14.30
- Record Name . . . . . : b.gtld-servers.net
- Record Type . . . . . : 28
- Time To Live . . . . : 2791
- Data Length . . . . . : 16
- Section . . . . . . . : Additional
- AAAA Record . . . . . : 2001:503:231d::2:30
- Record Name . . . . . : c.gtld-servers.net
- Record Type . . . . . : 1
- Time To Live . . . . : 2791
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 192.26.92.30
- Record Name . . . . . : d.gtld-servers.net
- Record Type . . . . . : 1
- Time To Live . . . . : 2791
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 192.31.80.30
- Record Name . . . . . : e.gtld-servers.net
- Record Type . . . . . : 1
- Time To Live . . . . : 2791
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 192.12.94.30
- Record Name . . . . . : f.gtld-servers.net
- Record Type . . . . . : 1
- Time To Live . . . . : 2791
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 192.35.51.30
- Record Name . . . . . : g.gtld-servers.net
- Record Type . . . . . : 1
- Time To Live . . . . : 2791
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 192.42.93.30
- Record Name . . . . . : h.gtld-servers.net
- Record Type . . . . . : 1
- Time To Live . . . . : 2791
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 192.54.112.30
- Record Name . . . . . : i.gtld-servers.net
- Record Type . . . . . : 1
- Time To Live . . . . : 2791
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 192.43.172.30
- r5---sn-cu-auoe.googlevideo.com
- ----------------------------------------
- Record Name . . . . . : r5---sn-cu-auoe.googlevideo.com
- Record Type . . . . . : 5
- Time To Live . . . . : 305
- Data Length . . . . . : 8
- Section . . . . . . . : Answer
- CNAME Record . . . . : r5.sn-cu-auoe.googlevideo.com
- Record Name . . . . . : r5.sn-cu-auoe.googlevideo.com
- Record Type . . . . . : 1
- Time To Live . . . . : 305
- Data Length . . . . . : 4
- Section . . . . . . . : Answer
- A (Host) Record . . . : 109.144.0.20
- Record Name . . . . . : ns1.google.com
- Record Type . . . . . : 1
- Time To Live . . . . : 305
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 216.239.32.10
- Record Name . . . . . : ns2.google.com
- Record Type . . . . . : 1
- Time To Live . . . . : 305
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 216.239.34.10
- Record Name . . . . . : ns3.google.com
- Record Type . . . . . : 1
- Time To Live . . . . : 305
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 216.239.36.10
- Record Name . . . . . : ns4.google.com
- Record Type . . . . . : 1
- Time To Live . . . . : 305
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 216.239.38.10
- ocsp.digicert.com
- ----------------------------------------
- Record Name . . . . . : ocsp.digicert.com
- Record Type . . . . . : 5
- Time To Live . . . . : 540
- Data Length . . . . . : 8
- Section . . . . . . . : Answer
- CNAME Record . . . . : cs9.wac.phicdn.net
- Record Name . . . . . : cs9.wac.phicdn.net
- Record Type . . . . . : 1
- Time To Live . . . . : 540
- Data Length . . . . . : 4
- Section . . . . . . . : Answer
- A (Host) Record . . . : 93.184.220.29
- Record Name . . . . . : ns1.phicdn.net
- Record Type . . . . . : 1
- Time To Live . . . . : 540
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 72.21.80.5
- Record Name . . . . . : ns1.phicdn.net
- Record Type . . . . . : 28
- Time To Live . . . . : 540
- Data Length . . . . . : 16
- Section . . . . . . . : Additional
- AAAA Record . . . . . : 2606:2800:1::5
- Record Name . . . . . : ns2.phicdn.net
- Record Type . . . . . : 1
- Time To Live . . . . : 540
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 72.21.80.6
- Record Name . . . . . : ns2.phicdn.net
- Record Type . . . . . : 28
- Time To Live . . . . : 540
- Data Length . . . . . : 16
- Section . . . . . . . : Additional
- AAAA Record . . . . . : 2606:2800:1::6
- stats.wp.com
- ----------------------------------------
- Record Name . . . . . : stats.wp.com
- Record Type . . . . . : 1
- Time To Live . . . . : 11578
- Data Length . . . . . : 4
- Section . . . . . . . : Answer
- A (Host) Record . . . : 192.0.76.3
- Record Name . . . . . : ns1.automattic.com
- Record Type . . . . . : 1
- Time To Live . . . . : 11578
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 198.181.116.5
- Record Name . . . . . : ns1.automattic.com
- Record Type . . . . . : 28
- Time To Live . . . . : 11578
- Data Length . . . . . : 16
- Section . . . . . . . : Additional
- AAAA Record . . . . . : 2a04:fa87:ffff::c6b5:7405
- Record Name . . . . . : ns2.automattic.com
- Record Type . . . . . : 1
- Time To Live . . . . : 11578
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 198.181.117.5
- Record Name . . . . . : ns2.automattic.com
- Record Type . . . . . : 28
- Time To Live . . . . : 11578
- Data Length . . . . . : 16
- Section . . . . . . . : Additional
- AAAA Record . . . . . : 2a04:fa87:ffff::c6b5:7505
- Record Name . . . . . : ns3.automattic.com
- Record Type . . . . . : 1
- Time To Live . . . . : 11578
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 192.0.74.5
- Record Name . . . . . : ns3.automattic.com
- Record Type . . . . . : 28
- Time To Live . . . . : 11578
- Data Length . . . . . : 16
- Section . . . . . . . : Additional
- AAAA Record . . . . . : 2620:115:c00f::c000:4a05
- client-download.steampowered.com
- ----------------------------------------
- Record Name . . . . . : client-download.steampowered.com
- Record Type . . . . . : 1
- Time To Live . . . . : 515
- Data Length . . . . . : 4
- Section . . . . . . . : Answer
- A (Host) Record . . . : 162.254.192.19
- Record Name . . . . . : client-download.steampowered.com
- Record Type . . . . . : 1
- Time To Live . . . . : 515
- Data Length . . . . . : 4
- Section . . . . . . . : Answer
- A (Host) Record . . . : 162.254.193.37
- Record Name . . . . . : client-download.steampowered.com
- Record Type . . . . . : 1
- Time To Live . . . . : 515
- Data Length . . . . . : 4
- Section . . . . . . . : Answer
- A (Host) Record . . . : 162.254.195.13
- Record Name . . . . . : client-download.steampowered.com
- Record Type . . . . . : 1
- Time To Live . . . . : 515
- Data Length . . . . . : 4
- Section . . . . . . . : Answer
- A (Host) Record . . . : 162.254.192.16
- Record Name . . . . . : client-download.steampowered.com
- Record Type . . . . . : 1
- Time To Live . . . . : 515
- Data Length . . . . . : 4
- Section . . . . . . . : Answer
- A (Host) Record . . . : 162.254.192.22
- Record Name . . . . . : client-download.steampowered.com
- Record Type . . . . . : 1
- Time To Live . . . . : 515
- Data Length . . . . . : 4
- Section . . . . . . . : Answer
- A (Host) Record . . . : 162.254.195.14
- Record Name . . . . . : client-download.steampowered.com
- Record Type . . . . . : 1
- Time To Live . . . . : 515
- Data Length . . . . . : 4
- Section . . . . . . . : Answer
- A (Host) Record . . . : 162.254.195.19
- Record Name . . . . . : client-download.steampowered.com
- Record Type . . . . . : 1
- Time To Live . . . . : 515
- Data Length . . . . . : 4
- Section . . . . . . . : Answer
- A (Host) Record . . . : 162.254.193.38
- Record Name . . . . . : client-download.steampowered.com
- Record Type . . . . . : 1
- Time To Live . . . . : 515
- Data Length . . . . . : 4
- Section . . . . . . . : Answer
- A (Host) Record . . . : 162.254.192.21
- Record Name . . . . . : client-download.steampowered.com
- Record Type . . . . . : 1
- Time To Live . . . . : 515
- Data Length . . . . . : 4
- Section . . . . . . . : Answer
- A (Host) Record . . . : 205.196.6.132
- Record Name . . . . . : client-download.steampowered.com
- Record Type . . . . . : 1
- Time To Live . . . . : 515
- Data Length . . . . . : 4
- Section . . . . . . . : Answer
- A (Host) Record . . . : 205.196.6.150
- Record Name . . . . . : client-download.steampowered.com
- Record Type . . . . . : 1
- Time To Live . . . . : 515
- Data Length . . . . . : 4
- Section . . . . . . . : Answer
- A (Host) Record . . . : 205.196.6.151
- Record Name . . . . . : client-download.steampowered.com
- Record Type . . . . . : 1
- Time To Live . . . . : 515
- Data Length . . . . . : 4
- Section . . . . . . . : Answer
- A (Host) Record . . . : 205.196.6.152
- Record Name . . . . . : client-download.steampowered.com
- Record Type . . . . . : 1
- Time To Live . . . . : 515
- Data Length . . . . . : 4
- Section . . . . . . . : Answer
- A (Host) Record . . . : 162.254.192.20
- Record Name . . . . . : client-download.steampowered.com
- Record Type . . . . . : 1
- Time To Live . . . . : 515
- Data Length . . . . . : 4
- Section . . . . . . . : Answer
- A (Host) Record . . . : 162.254.195.18
- Record Name . . . . . : client-download.steampowered.com
- Record Type . . . . . : 1
- Time To Live . . . . : 515
- Data Length . . . . . : 4
- Section . . . . . . . : Answer
- A (Host) Record . . . : 162.254.193.39
- Record Name . . . . . : client-download.steampowered.com
- Record Type . . . . . : 1
- Time To Live . . . . : 515
- Data Length . . . . . : 4
- Section . . . . . . . : Answer
- A (Host) Record . . . : 162.254.193.40
- Record Name . . . . . : client-download.steampowered.com
- Record Type . . . . . : 1
- Time To Live . . . . : 515
- Data Length . . . . . : 4
- Section . . . . . . . : Answer
- A (Host) Record . . . : 162.254.192.17
- Record Name . . . . . : a8-66.akam.net
- Record Type . . . . . : 1
- Time To Live . . . . : 515
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 2.16.40.66
- Record Name . . . . . : a9-67.akam.net
- Record Type . . . . . : 1
- Time To Live . . . . : 515
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 184.85.248.67
- www.sosvirus.net
- ----------------------------------------
- Record Name . . . . . : www.sosvirus.net
- Record Type . . . . . : 1
- Time To Live . . . . : 2942
- Data Length . . . . . : 4
- Section . . . . . . . : Answer
- A (Host) Record . . . : 151.80.21.61
- Record Name . . . . . : ns200.anycast.me
- Record Type . . . . . : 1
- Time To Live . . . . : 2942
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 46.105.207.200
- Record Name . . . . . : dns200.anycast.me
- Record Type . . . . . : 1
- Time To Live . . . . : 2942
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 46.105.206.200
- s4.histats.com
- ----------------------------------------
- Record Name . . . . . : s4.histats.com
- Record Type . . . . . : 1
- Time To Live . . . . : 993
- Data Length . . . . . : 4
- Section . . . . . . . : Answer
- A (Host) Record . . . : 208.43.241.178
- Record Name . . . . . : s4.histats.com
- Record Type . . . . . : 1
- Time To Live . . . . : 993
- Data Length . . . . . : 4
- Section . . . . . . . : Answer
- A (Host) Record . . . : 208.43.241.179
- Record Name . . . . . : s4.histats.com
- Record Type . . . . . : 1
- Time To Live . . . . : 993
- Data Length . . . . . : 4
- Section . . . . . . . : Answer
- A (Host) Record . . . : 208.43.241.181
- Record Name . . . . . : s4.histats.com
- Record Type . . . . . : 1
- Time To Live . . . . : 993
- Data Length . . . . . : 4
- Section . . . . . . . : Answer
- A (Host) Record . . . : 184.173.167.98
- Record Name . . . . . : ns1.softlayer.com
- Record Type . . . . . : 1
- Time To Live . . . . : 993
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 67.228.254.4
- Record Name . . . . . : ns1.softlayer.com
- Record Type . . . . . : 28
- Time To Live . . . . : 993
- Data Length . . . . . : 16
- Section . . . . . . . : Additional
- AAAA Record . . . . . : 2607:f0d0:0:f:1::1
- Record Name . . . . . : ns2.softlayer.com
- Record Type . . . . . : 1
- Time To Live . . . . : 993
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 67.228.255.5
- Record Name . . . . . : ns2.softlayer.com
- Record Type . . . . . : 28
- Time To Live . . . . : 993
- Data Length . . . . . : 16
- Section . . . . . . . : Additional
- AAAA Record . . . . . : 2607:f0d0:0:f:2::1
- gds1.steampowered.com
- ----------------------------------------
- Record Name . . . . . : gds1.steampowered.com
- Record Type . . . . . : 1
- Time To Live . . . . : 6196
- Data Length . . . . . : 4
- Section . . . . . . . : Answer
- A (Host) Record . . . : 208.64.201.136
- Record Name . . . . . : a8-66.akam.net
- Record Type . . . . . : 1
- Time To Live . . . . : 6196
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 2.16.40.66
- Record Name . . . . . : a9-67.akam.net
- Record Type . . . . . : 1
- Time To Live . . . . : 6196
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 184.85.248.67
- Record Name . . . . . : a9-67.akam.net
- Record Type . . . . . : 28
- Time To Live . . . . : 6196
- Data Length . . . . . : 16
- Section . . . . . . . : Additional
- AAAA Record . . . . . : 2a02:26f0:117::43
- Record Name . . . . . : a1-164.akam.net
- Record Type . . . . . : 1
- Time To Live . . . . : 6196
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 193.108.91.164
- Record Name . . . . . : a1-164.akam.net
- Record Type . . . . . : 28
- Time To Live . . . . : 6196
- Data Length . . . . . : 16
- Section . . . . . . . : Additional
- AAAA Record . . . . . : 2600:1401:2::a4
- Record Name . . . . . : a11-67.akam.net
- Record Type . . . . . : 1
- Time To Live . . . . : 6196
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 84.53.139.67
- Record Name . . . . . : a11-67.akam.net
- Record Type . . . . . : 28
- Time To Live . . . . : 6196
- Data Length . . . . . : 16
- Section . . . . . . . : Additional
- AAAA Record . . . . . : 2600:1480:1::43
- Record Name . . . . . : a24-64.akam.net
- Record Type . . . . . : 1
- Time To Live . . . . : 6196
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 2.16.130.64
- Record Name . . . . . : a26-65.akam.net
- Record Type . . . . . : 1
- Time To Live . . . . : 6196
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 23.74.25.65
- ad.afy11.net
- ----------------------------------------
- Record Name . . . . . : ad.afy11.net
- Record Type . . . . . : 1
- Time To Live . . . . : 1488
- Data Length . . . . . : 4
- Section . . . . . . . : Answer
- A (Host) Record . . . : 74.117.199.102
- Record Name . . . . . : ns1.p07.dynect.net
- Record Type . . . . . : 1
- Time To Live . . . . : 1488
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 208.78.70.7
- Record Name . . . . . : ns2.p07.dynect.net
- Record Type . . . . . : 1
- Time To Live . . . . : 1488
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 204.13.250.7
- Record Name . . . . . : ns3.p07.dynect.net
- Record Type . . . . . : 1
- Time To Live . . . . : 1488
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 208.78.71.7
- Record Name . . . . . : ns4.p07.dynect.net
- Record Type . . . . . : 1
- Time To Live . . . . : 1488
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 204.13.251.7
- valve406.steampipe.steamcontent.com
- ----------------------------------------
- Record Name . . . . . : valve406.steampipe.steamcontent.com
- Record Type . . . . . : 5
- Time To Live . . . . : 10276
- Data Length . . . . . : 8
- Section . . . . . . . : Answer
- CNAME Record . . . . : valve406.steamcontent.com
- Record Name . . . . . : valve406.steamcontent.com
- Record Type . . . . . : 1
- Time To Live . . . . : 10276
- Data Length . . . . . : 4
- Section . . . . . . . : Answer
- A (Host) Record . . . : 162.254.196.16
- Record Name . . . . . : a8-66.akam.net
- Record Type . . . . . : 1
- Time To Live . . . . : 10276
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 2.16.40.66
- Record Name . . . . . : a8-66.akam.net
- Record Type . . . . . : 28
- Time To Live . . . . : 10276
- Data Length . . . . . : 16
- Section . . . . . . . : Additional
- AAAA Record . . . . . : 2600:1403:a::42
- Record Name . . . . . : a9-67.akam.net
- Record Type . . . . . : 1
- Time To Live . . . . : 10276
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 184.85.248.67
- Record Name . . . . . : a1-164.akam.net
- Record Type . . . . . : 1
- Time To Live . . . . : 10276
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 193.108.91.164
- Record Name . . . . . : a1-164.akam.net
- Record Type . . . . . : 28
- Time To Live . . . . : 10276
- Data Length . . . . . : 16
- Section . . . . . . . : Additional
- AAAA Record . . . . . : 2600:1401:2::a4
- Record Name . . . . . : a11-67.akam.net
- Record Type . . . . . : 1
- Time To Live . . . . : 10276
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 84.53.139.67
- Record Name . . . . . : a24-64.akam.net
- Record Type . . . . . : 1
- Time To Live . . . . : 10276
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 2.16.130.64
- Record Name . . . . . : a26-65.akam.net
- Record Type . . . . . : 1
- Time To Live . . . . : 10276
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 23.74.25.65
- sc.iasds01.com
- ----------------------------------------
- Record Name . . . . . : sc.iasds01.com
- Record Type . . . . . : 5
- Time To Live . . . . : 871
- Data Length . . . . . : 8
- Section . . . . . . . : Answer
- CNAME Record . . . . : anycast.sc.iasds01.com
- Record Name . . . . . : anycast.sc.iasds01.com
- Record Type . . . . . : 1
- Time To Live . . . . : 871
- Data Length . . . . . : 4
- Section . . . . . . . : Answer
- A (Host) Record . . . : 199.166.0.200
- Record Name . . . . . : dns1.p05.nsone.net
- Record Type . . . . . : 1
- Time To Live . . . . : 871
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 198.51.44.5
- Record Name . . . . . : dns2.p05.nsone.net
- Record Type . . . . . : 1
- Time To Live . . . . : 871
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 198.51.45.5
- Record Name . . . . . : dns3.p05.nsone.net
- Record Type . . . . . : 1
- Time To Live . . . . : 871
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 198.51.44.69
- Record Name . . . . . : dns4.p05.nsone.net
- Record Type . . . . . : 1
- Time To Live . . . . : 871
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 198.51.45.69
- valve422.steampipe.steamcontent.com
- ----------------------------------------
- Record Name . . . . . : valve422.steampipe.steamcontent.com
- Record Type . . . . . : 5
- Time To Live . . . . : 3157
- Data Length . . . . . : 8
- Section . . . . . . . : Answer
- CNAME Record . . . . : valve422.steamcontent.com
- Record Name . . . . . : valve422.steamcontent.com
- Record Type . . . . . : 1
- Time To Live . . . . : 3157
- Data Length . . . . . : 4
- Section . . . . . . . : Answer
- A (Host) Record . . . : 162.254.196.32
- Record Name . . . . . : a8-66.akam.net
- Record Type . . . . . : 1
- Time To Live . . . . : 3157
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 2.16.40.66
- Record Name . . . . . : a8-66.akam.net
- Record Type . . . . . : 28
- Time To Live . . . . : 3157
- Data Length . . . . . : 16
- Section . . . . . . . : Additional
- AAAA Record . . . . . : 2600:1403:a::42
- Record Name . . . . . : a9-67.akam.net
- Record Type . . . . . : 1
- Time To Live . . . . : 3157
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 184.85.248.67
- Record Name . . . . . : a1-164.akam.net
- Record Type . . . . . : 1
- Time To Live . . . . : 3157
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 193.108.91.164
- Record Name . . . . . : a1-164.akam.net
- Record Type . . . . . : 28
- Time To Live . . . . : 3157
- Data Length . . . . . : 16
- Section . . . . . . . : Additional
- AAAA Record . . . . . : 2600:1401:2::a4
- Record Name . . . . . : a11-67.akam.net
- Record Type . . . . . : 1
- Time To Live . . . . : 3157
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 84.53.139.67
- Record Name . . . . . : a24-64.akam.net
- Record Type . . . . . : 1
- Time To Live . . . . : 3157
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 2.16.130.64
- Record Name . . . . . : a26-65.akam.net
- Record Type . . . . . : 1
- Time To Live . . . . : 3157
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 23.74.25.65
- rp.gwallet.com
- ----------------------------------------
- Record Name . . . . . : rp.gwallet.com
- Record Type . . . . . : 1
- Time To Live . . . . : 119
- Data Length . . . . . : 4
- Section . . . . . . . : Answer
- A (Host) Record . . . : 208.146.36.220
- Record Name . . . . . : pdns1.ultradns.net
- Record Type . . . . . : 1
- Time To Live . . . . : 119
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 204.74.108.1
- Record Name . . . . . : pdns2.ultradns.net
- Record Type . . . . . : 1
- Time To Live . . . . : 119
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 204.74.109.1
- Record Name . . . . . : pdns2.ultradns.net
- Record Type . . . . . : 28
- Time To Live . . . . : 119
- Data Length . . . . . : 16
- Section . . . . . . . : Additional
- AAAA Record . . . . . : 2610:a1:1014::1
- Record Name . . . . . : pdns3.ultradns.org
- Record Type . . . . . : 1
- Time To Live . . . . : 119
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 199.7.68.1
- Record Name . . . . . : pdns3.ultradns.org
- Record Type . . . . . : 28
- Time To Live . . . . : 119
- Data Length . . . . . : 16
- Section . . . . . . . : Additional
- AAAA Record . . . . . : 2610:a1:1015::1
- Record Name . . . . . : pdns4.ultradns.org
- Record Type . . . . . : 1
- Time To Live . . . . : 119
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 199.7.69.1
- Record Name . . . . . : pdns4.ultradns.org
- Record Type . . . . . : 28
- Time To Live . . . . : 119
- Data Length . . . . . : 16
- Section . . . . . . . : Additional
- AAAA Record . . . . . : 2001:502:4612::1
- Record Name . . . . . : pdns5.ultradns.info
- Record Type . . . . . : 1
- Time To Live . . . . : 119
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 204.74.114.1
- Record Name . . . . . : pdns5.ultradns.info
- Record Type . . . . . : 28
- Time To Live . . . . : 119
- Data Length . . . . . : 16
- Section . . . . . . . : Additional
- AAAA Record . . . . . : 2610:a1:1016::1
- Record Name . . . . . : pdns6.ultradns.co.uk
- Record Type . . . . . : 1
- Time To Live . . . . : 119
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 204.74.115.1
- www.kmspico2k.com
- ----------------------------------------
- Record Name . . . . . : www.kmspico2k.com
- Record Type . . . . . : 5
- Time To Live . . . . : 531
- Data Length . . . . . : 8
- Section . . . . . . . : Answer
- CNAME Record . . . . : kmspico2k.com
- Record Name . . . . . : kmspico2k.com
- Record Type . . . . . : 1
- Time To Live . . . . : 531
- Data Length . . . . . : 4
- Section . . . . . . . : Answer
- A (Host) Record . . . : 108.167.165.241
- Record Name . . . . . : cns49.hostgator.com
- Record Type . . . . . : 1
- Time To Live . . . . : 531
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 108.167.165.238
- Record Name . . . . . : cns50.hostgator.com
- Record Type . . . . . : 1
- Time To Live . . . . : 531
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 108.167.165.239
- pixel.wp.com
- ----------------------------------------
- Record Name . . . . . : pixel.wp.com
- Record Type . . . . . : 1
- Time To Live . . . . : 12916
- Data Length . . . . . : 4
- Section . . . . . . . : Answer
- A (Host) Record . . . : 192.0.76.3
- Record Name . . . . . : ns1.automattic.com
- Record Type . . . . . : 1
- Time To Live . . . . : 12916
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 198.181.116.5
- Record Name . . . . . : ns1.automattic.com
- Record Type . . . . . : 28
- Time To Live . . . . : 12916
- Data Length . . . . . : 16
- Section . . . . . . . : Additional
- AAAA Record . . . . . : 2a04:fa87:ffff::c6b5:7405
- Record Name . . . . . : ns2.automattic.com
- Record Type . . . . . : 1
- Time To Live . . . . : 12916
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 198.181.117.5
- Record Name . . . . . : ns2.automattic.com
- Record Type . . . . . : 28
- Time To Live . . . . : 12916
- Data Length . . . . . : 16
- Section . . . . . . . : Additional
- AAAA Record . . . . . : 2a04:fa87:ffff::c6b5:7505
- Record Name . . . . . : ns3.automattic.com
- Record Type . . . . . : 1
- Time To Live . . . . : 12916
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 192.0.74.5
- Record Name . . . . . : ns3.automattic.com
- Record Type . . . . . : 28
- Time To Live . . . . : 12916
- Data Length . . . . . : 16
- Section . . . . . . . : Additional
- AAAA Record . . . . . : 2620:115:c00f::c000:4a05
- aka-cdn-ns.adtechus.com
- ----------------------------------------
- Record Name . . . . . : aka-cdn-ns.adtechus.com
- Record Type . . . . . : 5
- Time To Live . . . . : 2791
- Data Length . . . . . : 8
- Section . . . . . . . : Answer
- CNAME Record . . . . : cs696.wac.thetacdn.net
- Record Name . . . . . : cs696.wac.thetacdn.net
- Record Type . . . . . : 1
- Time To Live . . . . : 2791
- Data Length . . . . . : 4
- Section . . . . . . . : Answer
- A (Host) Record . . . : 192.229.233.248
- Record Name . . . . . : a.gtld-servers.net
- Record Type . . . . . : 1
- Time To Live . . . . : 2791
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 192.5.6.30
- Record Name . . . . . : a.gtld-servers.net
- Record Type . . . . . : 28
- Time To Live . . . . : 2791
- Data Length . . . . . : 16
- Section . . . . . . . : Additional
- AAAA Record . . . . . : 2001:503:a83e::2:30
- Record Name . . . . . : b.gtld-servers.net
- Record Type . . . . . : 1
- Time To Live . . . . : 2791
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 192.33.14.30
- Record Name . . . . . : b.gtld-servers.net
- Record Type . . . . . : 28
- Time To Live . . . . : 2791
- Data Length . . . . . : 16
- Section . . . . . . . : Additional
- AAAA Record . . . . . : 2001:503:231d::2:30
- Record Name . . . . . : c.gtld-servers.net
- Record Type . . . . . : 1
- Time To Live . . . . : 2791
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 192.26.92.30
- Record Name . . . . . : d.gtld-servers.net
- Record Type . . . . . : 1
- Time To Live . . . . : 2791
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 192.31.80.30
- Record Name . . . . . : e.gtld-servers.net
- Record Type . . . . . : 1
- Time To Live . . . . : 2791
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 192.12.94.30
- Record Name . . . . . : f.gtld-servers.net
- Record Type . . . . . : 1
- Time To Live . . . . : 2791
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 192.35.51.30
- Record Name . . . . . : g.gtld-servers.net
- Record Type . . . . . : 1
- Time To Live . . . . : 2791
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 192.42.93.30
- Record Name . . . . . : h.gtld-servers.net
- Record Type . . . . . : 1
- Time To Live . . . . : 2791
- Data Length . . . . . : 4
- Section . . . . . . . : Additional
- A (Host) Record . . . : 192.54.112.30
Add Comment
Please, Sign In to add comment