Advertisement
Guest User

Untitled

a guest
Jan 24th, 2020
1,616
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 14.57 KB | None | 0 0
  1. "HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\AlternateShell" "" "" "" "3/19/2019 7:53 AM" ""
  2. + "cmd.exe" "Windows Command Processor" "(Verified) Microsoft Windows" "c:\windows\system32\cmd.exe" "5/14/1935 8:40 AM" ""
  3. "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" "" "" "" "1/22/2020 7:30 PM" ""
  4. + "IDMan" "Internet Download Manager (IDM)" "(Not Verified) Tonec Inc." "c:\program files (x86)\internet download manager\idman.exe" "1/21/2020 7:40 PM" ""
  5. "HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components" "" "" "" "5/25/2019 4:09 PM" ""
  6. + "n/a" "Microsoft .NET IE SECURITY REGISTRATION" "(Verified) Microsoft Corporation" "c:\windows\system32\mscories.dll" "3/4/2019 3:54 PM" ""
  7. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Active Setup\Installed Components" "" "" "" "1/21/2020 10:40 PM" ""
  8. + "Google Chrome" "Google Chrome Installer" "(Verified) Google LLC" "c:\program files (x86)\google\chrome\application\79.0.3945.130\installer\chrmstp.exe" "1/16/2020 1:54 AM" ""
  9. + "n/a" "Microsoft .NET IE SECURITY REGISTRATION" "(Verified) Microsoft Corporation" "c:\windows\syswow64\mscories.dll" "3/4/2019 9:12 PM" ""
  10. "HKLM\SOFTWARE\Classes\Protocols\Filter" "" "" "" "1/21/2020 4:49 PM" ""
  11. + "text/xml" "Microsoft Office XML MIME Filter" "(Verified) Microsoft Corporation" "c:\program files\microsoft office\root\vfs\programfilescommonx64\microsoft shared\office16\msoxmlmf.dll" "8/2/2019 7:43 AM" ""
  12. "HKLM\SOFTWARE\Classes\Protocols\Handler" "" "" "" "1/21/2020 4:49 PM" ""
  13. + "mso-minsb-roaming.16" "Microsoft Office component" "(Verified) Microsoft Corporation" "c:\program files\microsoft office\root\office16\msosb.dll" "8/8/2019 12:03 AM" ""
  14. + "mso-minsb.16" "Microsoft Office component" "(Verified) Microsoft Corporation" "c:\program files\microsoft office\root\office16\msosb.dll" "8/8/2019 12:03 AM" ""
  15. + "osf-roaming.16" "Microsoft Office component" "(Verified) Microsoft Corporation" "c:\program files\microsoft office\root\office16\msosb.dll" "8/8/2019 12:03 AM" ""
  16. + "osf.16" "Microsoft Office component" "(Verified) Microsoft Corporation" "c:\program files\microsoft office\root\office16\msosb.dll" "8/8/2019 12:03 AM" ""
  17. "HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers" "" "" "" "1/21/2020 5:14 PM" ""
  18. + "WinRAR" "WinRAR shell extension" "(Verified) win.rar GmbH" "c:\program files\winrar\rarext.dll" "4/27/2019 11:03 PM" ""
  19. "HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers" "" "" "" "1/21/2020 5:14 PM" ""
  20. + "WinRAR" "WinRAR shell extension" "(Verified) win.rar GmbH" "c:\program files\winrar\rarext.dll" "4/27/2019 11:03 PM" ""
  21. "HKLM\Software\Classes\Folder\ShellEx\DragDropHandlers" "" "" "" "1/21/2020 5:14 PM" ""
  22. + "WinRAR" "WinRAR shell extension" "(Verified) win.rar GmbH" "c:\program files\winrar\rarext.dll" "4/27/2019 11:03 PM" ""
  23. "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers" "" "" "" "1/22/2020 7:30 PM" ""
  24. + " IDM Shell Extension" "Internet Download Manager module" "(Verified) Tonec Inc." "c:\program files (x86)\internet download manager\idmshellext64.dll" "5/1/2019 7:48 PM" ""
  25. "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects" "" "" "" "1/22/2020 7:29 PM" ""
  26. + "IDM integration (IDMIEHlprObj Class)" "IDM Browser Helper Object" "(Verified) Tonec Inc." "c:\program files (x86)\internet download manager\idmiecc64.dll" "1/21/2020 4:34 AM" ""
  27. + "Skype for Business Browser Helper" "Skype for Business" "(Verified) Microsoft Corporation" "c:\program files\microsoft office\root\office16\ochelper.dll" "6/7/2019 12:18 AM" ""
  28. "HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects" "" "" "" "1/22/2020 7:29 PM" ""
  29. + "IDM integration (IDMIEHlprObj Class)" "IDM Browser Helper Object" "(Verified) Tonec Inc." "c:\program files (x86)\internet download manager\idmiecc.dll" "1/21/2020 4:35 AM" ""
  30. + "Skype for Business Browser Helper" "Skype for Business" "(Verified) Microsoft Corporation" "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\ochelper.dll" "2/27/2019 11:49 PM" ""
  31. "HKLM\Software\Microsoft\Internet Explorer\Extensions" "" "" "" "1/21/2020 4:49 PM" ""
  32. + "Lync Click to Call" "Skype for Business" "(Verified) Microsoft Corporation" "c:\program files\microsoft office\root\office16\ochelper.dll" "6/7/2019 12:18 AM" ""
  33. "HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Extensions" "" "" "" "1/21/2020 4:49 PM" ""
  34. + "Lync Click to Call" "Skype for Business" "(Verified) Microsoft Corporation" "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\ochelper.dll" "2/27/2019 11:49 PM" ""
  35. + "OneNote Lin&ked Notes" "Microsoft OneNote Internet Explorer Add-in" "(Verified) Microsoft Corporation" "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\onbttnielinkednotes.dll" "8/10/2019 3:54 AM" ""
  36. + "Se&nd to OneNote" "Microsoft OneNote Internet Explorer Add-in" "(Verified) Microsoft Corporation" "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\onbttnie.dll" "8/10/2019 3:51 AM" ""
  37. "Task Scheduler" "" "" "" "" ""
  38. + "\DriverToolkit Autorun" "DriverToolkit" "(Verified) Megaify Software Co.,Ltd." "c:\program files (x86)\drivertoolkit\drivertoolkit.exe" "7/1/2015 7:51 AM" ""
  39. + "\GoogleUpdateTaskMachineCore" "Google Installer" "(Verified) Google LLC" "c:\program files (x86)\google\update\googleupdate.exe" "12/3/2019 2:32 AM" ""
  40. + "\GoogleUpdateTaskMachineUA" "Google Installer" "(Verified) Google LLC" "c:\program files (x86)\google\update\googleupdate.exe" "12/3/2019 2:32 AM" ""
  41. + "\Microsoft\Office\Office Automatic Updates 2.0" "Microsoft Office Click-to-Run Client" "(Verified) Microsoft Corporation" "c:\program files\common files\microsoft shared\clicktorun\officec2rclient.exe" "9/28/2019 7:47 AM" ""
  42. + "\Microsoft\Office\Office ClickToRun Service Monitor" "Microsoft Office Click-to-Run Client" "(Verified) Microsoft Corporation" "c:\program files\common files\microsoft shared\clicktorun\officec2rclient.exe" "9/28/2019 7:47 AM" ""
  43. + "\Microsoft\Office\Office Feature Updates" "Microsoft Office SDX Helper" "(Verified) Microsoft Corporation" "c:\program files\microsoft office\root\vfs\programfilescommonx64\microsoft shared\office16\sdxhelper.exe" "9/28/2019 4:52 PM" ""
  44. + "\Microsoft\Office\Office Feature Updates Logon" "Microsoft Office SDX Helper" "(Verified) Microsoft Corporation" "c:\program files\microsoft office\root\vfs\programfilescommonx64\microsoft shared\office16\sdxhelper.exe" "9/28/2019 4:52 PM" ""
  45. + "\Microsoft\Office\OfficeBackgroundTaskHandlerLogon" "Background task for Office flighting system" "(Verified) Microsoft Corporation" "c:\program files\microsoft office\root\office16\officebackgroundtaskhandler.exe" "9/28/2019 4:38 PM" ""
  46. + "\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration" "Background task for Office flighting system" "(Verified) Microsoft Corporation" "c:\program files\microsoft office\root\office16\officebackgroundtaskhandler.exe" "9/28/2019 4:38 PM" ""
  47. + "\Microsoft\Office\OfficeTelemetryAgentFallBack2016" "Office Telemetry Dashboard Agent (OTD msoia)" "(Verified) Microsoft Corporation" "c:\program files\microsoft office\root\office16\msoia.exe" "9/28/2019 7:46 AM" ""
  48. + "\Microsoft\Office\OfficeTelemetryAgentLogOn2016" "Office Telemetry Dashboard Agent (OTD msoia)" "(Verified) Microsoft Corporation" "c:\program files\microsoft office\root\office16\msoia.exe" "9/28/2019 7:46 AM" ""
  49. + "\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser" "Microsoft Compatibility Telemetry" "(Verified) Microsoft Corporation" "c:\windows\system32\compattelrunner.exe" "12/1/1945 11:29 PM" ""
  50. + "\Microsoft\Windows\Application Experience\ProgramDataUpdater" "Microsoft Compatibility Telemetry" "(Verified) Microsoft Corporation" "c:\windows\system32\compattelrunner.exe" "12/1/1945 11:29 PM" ""
  51. + "\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance" "Microsoft Malware Protection Command Line Utility" "(Verified) Microsoft Corporation" "c:\program files\windows defender\mpcmdrun.exe" "3/21/1955 3:53 PM" ""
  52. + "\Microsoft\Windows\Windows Defender\Windows Defender Cleanup" "Microsoft Malware Protection Command Line Utility" "(Verified) Microsoft Corporation" "c:\program files\windows defender\mpcmdrun.exe" "3/21/1955 3:53 PM" ""
  53. + "\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan" "Microsoft Malware Protection Command Line Utility" "(Verified) Microsoft Corporation" "c:\program files\windows defender\mpcmdrun.exe" "3/21/1955 3:53 PM" ""
  54. + "\Microsoft\Windows\Windows Defender\Windows Defender Verification" "Microsoft Malware Protection Command Line Utility" "(Verified) Microsoft Corporation" "c:\program files\windows defender\mpcmdrun.exe" "3/21/1955 3:53 PM" ""
  55. + "\OneDrive Standalone Update Task-S-1-5-21-430849976-2679684804-3630965374-1001" "Standalone Updater" "(Verified) Microsoft Corporation" "c:\users\jamal mohammed\appdata\local\microsoft\onedrive\onedrivestandaloneupdater.exe" "10/17/2019 8:23 PM" ""
  56. "HKLM\System\CurrentControlSet\Services" "" "" "" "1/24/2020 4:55 PM" ""
  57. + "ClickToRunSvc" "خدمة التشغيل الفوري من Microsoft Office: ‫إدارة تنسيق الموارد ودفق الخلفية وتكامل النظام لمنتجات Microsoft Office والتحديثات المرتبطة بها. يجب تشغيل هذه الخدمة أثناء استخدام أي من برامج Microsoft Office وأثناء تثبيت الدفق الأولي وكل التحديثات اللاحقة.‬" "(Verified) Microsoft Corporation" "c:\program files\common files\microsoft shared\clicktorun\officeclicktorun.exe" "9/28/2019 7:40 AM" ""
  58. + "FontCache3.0.0.0" "Windows Presentation Foundation Font Cache 3.0.0.0: Optimizes performance of Windows Presentation Foundation (WPF) applications by caching commonly used font data. WPF applications will start this service if it is not already running. It can be disabled, though doing so will degrade the performance of WPF applications." "(Verified) Microsoft Corporation" "c:\windows\microsoft.net\framework64\v3.0\wpf\presentationfontcache.exe" "1/26/2019 7:17 AM" ""
  59. + "GoogleChromeElevationService" "Google Chrome Elevation Service: Google Chrome" "(Verified) Google LLC" "c:\program files (x86)\google\chrome\application\79.0.3945.130\elevation_service.exe" "1/16/2020 1:54 AM" ""
  60. + "gupdate" "Google Update Service (gupdate): Keeps your Google software up to date. If this service is disabled or stopped, your Google software will not be kept up to date, meaning security vulnerabilities that may arise cannot be fixed and features may not work. This service uninstalls itself when there is no Google software using it." "(Verified) Google LLC" "c:\program files (x86)\google\update\googleupdate.exe" "12/3/2019 2:32 AM" ""
  61. + "gupdatem" "Google Update Service (gupdatem): Keeps your Google software up to date. If this service is disabled or stopped, your Google software will not be kept up to date, meaning security vulnerabilities that may arise cannot be fixed and features may not work. This service uninstalls itself when there is no Google software using it." "(Verified) Google LLC" "c:\program files (x86)\google\update\googleupdate.exe" "12/3/2019 2:32 AM" ""
  62. + "ose64" "Office 64 Source Engine: Saves installation files used for updates and repairs and is required for the downloading of Setup updates and Watson error reports." "(Verified) Microsoft Corporation" "c:\program files\common files\microsoft shared\source engine\ose.exe" "9/17/2019 2:13 AM" ""
  63. + "ProtonVPN Service" "ProtonVPN Service: ProtonVPN" "(Verified) ProtonVPN AG" "c:\program files (x86)\proton technologies\protonvpn\protonvpnservice.exe" "8/12/2019 1:08 PM" ""
  64. + "WdNisSvc" "Windows Defender Antivirus Network Inspection Service: Helps guard against intrusion attempts targeting known and newly discovered vulnerabilities in network protocols" "(Verified) Microsoft Corporation" "c:\program files\windows defender\nissrv.exe" "10/29/1967 6:25 PM" ""
  65. + "WinDefend" "Windows Defender Antivirus Service: Helps protect users from malware and other potentially unwanted software" "(Verified) Microsoft Corporation" "c:\program files\windows defender\msmpeng.exe" "10/30/1943 7:45 AM" ""
  66. "HKLM\System\CurrentControlSet\Services" "" "" "" "1/24/2020 4:55 PM" ""
  67. + "atillk64" "atillk64: ATI Diagnostics Hardware Abstraction Sys" "(Verified) ATI Technologies, Inc" "c:\users\jamal mohammed\documents\amd_radeon_vii_bios_v105_x64\amd_radeon_vii_bios_v105_x64\atillk64.sys" "9/9/2005 9:40 PM" ""
  68. + "iaLPSSi_GPIO" "Intel(R) Serial IO GPIO Controller Driver: Intel(R) Serial IO GPIO Controller Driver" "(Verified) Intel Corporation - Client Components Group" "c:\windows\system32\drivers\ialpssi_gpio.sys" "2/2/2015 12:00 PM" ""
  69. + "IDMWFP" "IDMWFP: Internet Download Manager WFP Driver" "(Verified) Tonec Inc." "c:\windows\system32\drivers\idmwfp.sys" "12/19/2018 5:52 PM" ""
  70. + "pwdrvio" "pwdrvio: " "(Verified) MiniTool Solution Ltd" "c:\windows\system32\pwdrvio.sys" "6/16/2009 4:43 AM" ""
  71. + "pwdspio" "pwdspio: " "(Verified) MiniTool Solution Ltd" "c:\windows\system32\pwdspio.sys" "7/15/2009 6:18 AM" ""
  72. + "RSPCIESTOR" "Realtek PCIE CardReader Driver: Realtek Pcie CardReader Driver for 2K/XP/Vista/Win7/Win8" "(Verified) Realtek Semiconductor Corp" "c:\windows\system32\drivers\rtspstor.sys" "5/15/2015 10:11 AM" ""
  73. + "rt640x64" "Realtek RT640 NT Driver: Realtek 8125/8136/8168/8169 NDIS 6.40 64-bit Driver " "(Verified) Realtek Semiconductor Corp." "c:\windows\system32\drivers\rt640x64.sys" "5/24/2019 11:47 AM" ""
  74. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Font Drivers" "" "" "" "3/19/2019 7:55 AM" ""
  75. + "Adobe Type Manager" "" "" "File not found: atmfd.dll" "" ""
  76. "HKLM\SOFTWARE\Classes\Htmlfile\Shell\Open\Command\(Default)" "" "" "" "1/21/2020 3:53 PM" ""
  77. + "C:\Program Files\Internet Explorer\iexplore.exe" "Internet Explorer" "(Verified) Microsoft Corporation" "c:\program files\internet explorer\iexplore.exe" "4/20/2022 10:38 PM" ""
  78. "HKLM\System\CurrentControlSet\Control\Session Manager\KnownDlls" "" "" "" "3/19/2019 7:53 AM" ""
  79. + "_wow64cpu" "" "" "c:\windows\syswow64\wow64cpu.dll" "" ""
  80. + "_wowarmhw" "" "" "c:\windows\system32\wowarmhw.dll" "" ""
  81. + "_wowarmhw" "" "" "c:\windows\syswow64\wowarmhw.dll" "" ""
  82. + "_xtajit" "" "" "c:\windows\system32\xtajit.dll" "" ""
  83. + "_xtajit" "" "" "c:\windows\syswow64\xtajit.dll" "" ""
  84. + "wow64" "" "" "c:\windows\syswow64\wow64.dll" "" ""
  85. + "wow64win" "" "" "c:\windows\syswow64\wow64win.dll" "" ""
  86. "HKLM\Software\Microsoft\Office\Outlook\Addins" "" "" "" "1/21/2020 4:49 PM" ""
  87. + "LyncAddin Class" "Skype for Business" "(Verified) Microsoft Corporation" "c:\program files\microsoft office\root\office16\ucaddin.dll" "8/2/2019 6:10 AM" ""
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement