Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- "Silent Runners.vbs", revision 71, http://www.silentrunners.org/
- Operating System: Microsoft Windows 10 Pro (64-bit), Version 1703
- Output limited to non-default values, except where indicated by "{++}"
- Startup items buried in registry:
- ---------------------------------
- HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++}
- OneDrive = "C:\Users\bgrze\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background [MS]
- f.lux = "C:\Users\bgrze\AppData\Local\FluxSoftware\Flux\flux.exe" /noshow [Flux Software LLC]
- Steam = "D:\Steam\steam.exe" -silent [Valve Corporation]
- Discord = C:\Users\bgrze\AppData\Local\Discord\app-0.0.298\Discord.exe [Discord Inc.]
- CCleaner Monitoring = "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR [Piriform Ltd]
- GalaxyClient = D:\Gry\GOG Galaxy\GalaxyClient.exe /launchViaAutoStart [GOG.com]
- MiPhoneManager = "C:\Users\bgrze\AppData\Local\MiPhoneManager\main\MiPhoneHelper.exe" [null data]
- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
- SecurityHealth = C:\Program Files\Windows Defender\MSASCuiL.exe
- RTHDVCPL = "C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s [Realtek Semiconductor]
- AdobeAAMUpdater-1.0 = "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [Adobe Systems Incorporated]
- XboxStat = "C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe" silentrun [MS]
- AdAwareTray = "C:\Program Files\adaware\adaware antivirus\adaware antivirus\12.0.649.11190\AdAwareTray.exe" [adaware]
- HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\ {++}
- Immunet Protect = "C:\Program Files\Immunet\6.0.6\iptray.exe" [Immunet]
- Razer Imperator Driver = C:\Program Files (x86)\Razer\Imperator\RazerImperatorSysTray.exe [Razer USA Ltd]
- LogMeIn Hamachi Ui = "D:\Programy\Hamachi\hamachi-2-ui.exe" --auto-start [LogMeIn Inc.]
- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\
- OneDrive6\(Default) = {9AA2F32D-362A-42D9-9328-24A483E2CCC3}
- -> {HKCU...CLSID} = ReadOnlyOverlayHandler Class
- \InProcServer32\(Default) = C:\Users\bgrze\AppData\Local\Microsoft\OneDrive\17.3.6998.0830\amd64\FileSyncShell64.dll [MS]
- EldosIconOverlay-cbfs6\(Default) = {384C8B1A-AA4E-4EBB-BF07-375123BDCCCD}
- -> {HKLM...CLSID} = VSMntNtfOverlayIcon Class
- \InProcServer32\(Default) = C:\WINDOWS\system32\cbfsMntNtf6.dll [/n software, Inc.]
- HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\
- OneDrive6\(Default) = {9AA2F32D-362A-42D9-9328-24A483E2CCC3}
- -> {HKCU...Wow...CLSID} = ReadOnlyOverlayHandler Class
- \InProcServer32\(Default) = C:\Users\bgrze\AppData\Local\Microsoft\OneDrive\17.3.6998.0830\FileSyncShell.dll [MS]
- EldosIconOverlay-cbfs6\(Default) = {384C8B1A-AA4E-4EBB-BF07-375123BDCCCD}
- -> {HKLM...Wow...CLSID} = VSMntNtfOverlayIcon Class
- \InProcServer32\(Default) = C:\WINDOWS\SysWOW64\cbfsMntNtf6.dll [/n software, Inc.]
- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellServiceObjects\
- {29719B01-1E78-4989-A847-FE24ECE23992}
- -> {HKLM...CLSID} = Virtual Storage Mount Notification
- \InProcServer32\(Default) = C:\WINDOWS\system32\cbfsMntNtf6.dll [/n software, Inc.]
- HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellServiceObjects\
- {29719B01-1E78-4989-A847-FE24ECE23992}
- -> {HKLM...Wow...CLSID} = Virtual Storage Mount Notification
- \InProcServer32\(Default) = C:\WINDOWS\SysWOW64\cbfsMntNtf6.dll [/n software, Inc.]
- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
- {09A47860-11B0-4DA5-AFA5-26D86198A780} = EPP
- -> {HKLM...CLSID} = (no title provided)
- \InProcServer32\(Default) = C:\Program Files\Windows Defender\ShellExt.dll [MS]
- {A70C977A-BF00-412C-90B7-034C51DA2439} = NvCpl DesktopContext Class
- -> {HKLM...CLSID} = DesktopContext Class
- \InProcServer32\(Default) = C:\Program Files\NVIDIA Corporation\Display\nvui.dll [NVIDIA Corporation]
- {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} = NVIDIA Play On My TV Context Menu Extension
- -> {HKLM...CLSID} = NVIDIA CPL Context Menu Extension
- \InProcServer32\(Default) = C:\WINDOWS\system32\nvshext.dll [NVIDIA Corporation]
- {A929C4CE-FD36-4270-B4F5-34ECAC5BD63C} = NvAppShExt extension
- -> {HKLM...CLSID} = NvAppShExt Class
- \InProcServer32\(Default) = C:\WINDOWS\system32\nv3dappshext.dll [NVIDIA Corporation]
- {E97DEC16-A50D-49bb-AE24-CF682282E08D} = OpenGLShExt extension
- -> {HKLM...CLSID} = OpenGLShExt Class
- \InProcServer32\(Default) = C:\WINDOWS\system32\nv3dappshext.dll [NVIDIA Corporation]
- {c5aec3ec-e812-4677-a9a7-4fee1f9aa000} = Icaros Thumbnail Provider
- -> {HKLM...CLSID} = Icaros Thumbnail Provider
- \InProcServer32\(Default) = C:\Program Files (x86)\K-Lite Codec Pack\Icaros\64-bit\IcarosThumbnailProvider.dll [Tabibito Technology]
- {0C08E3BB-D10B-4CC9-B1B3-701F5BE9D6EC} = Icaros Property Handler
- -> {HKLM...CLSID} = Icaros Property Handler
- \InProcServer32\(Default) = C:\Program Files (x86)\K-Lite Codec Pack\Icaros\64-bit\IcarosPropertyHandler.dll [Tabibito Technology]
- {AD392E40-428C-459F-961E-9B147782D099} = UltraISO
- -> {HKLM...CLSID} = UIContextMenu Class
- \InProcServer32\(Default) = C:\Program Files (x86)\UltraISO\isoshl64.dll [EZB Systems, Inc.]
- {AE424E85-F6DF-4910-A6A9-438797986431} = OpenOffice Property Handler
- -> {HKLM...CLSID} = OpenOffice Property Handler
- \InProcServer32\(Default) = C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\propertyhdl_x64.dll [Apache Software Foundation]
- {29719B01-1E78-4989-A847-FE24ECE23992} = Virtual Storage Mount Notification
- -> {HKLM...CLSID} = Virtual Storage Mount Notification
- \InProcServer32\(Default) = C:\WINDOWS\system32\cbfsMntNtf6.dll [/n software, Inc.]
- HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
- {c5aec3ec-e812-4677-a9a7-4fee1f9aa000} = Icaros Thumbnail Provider
- -> {HKLM...Wow...CLSID} = Icaros Thumbnail Provider
- \InProcServer32\(Default) = C:\Program Files (x86)\K-Lite Codec Pack\Icaros\32-bit\IcarosThumbnailProvider.dll [Tabibito Technology]
- {0C08E3BB-D10B-4CC9-B1B3-701F5BE9D6EC} = Icaros Property Handler
- -> {HKLM...Wow...CLSID} = Icaros Property Handler
- \InProcServer32\(Default) = C:\Program Files (x86)\K-Lite Codec Pack\Icaros\32-bit\IcarosPropertyHandler.dll [Tabibito Technology]
- {B41DB860-8EE4-11D2-9906-E49FADC173CA} = WinRAR shell extension
- -> {HKLM...Wow...CLSID} = WinRAR
- \InProcServer32\(Default) = C:\Program Files (x86)\WinRAR\rarext.dll [Alexander Roshal]
- {AE424E85-F6DF-4910-A6A9-438797986431} = OpenOffice Property Handler
- -> {HKLM...Wow...CLSID} = OpenOffice Property Handler
- \InProcServer32\(Default) = C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\propertyhdl.dll [Apache Software Foundation]
- {C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} = OpenOffice Column Handler
- -> {HKLM...Wow...CLSID} = (no title provided)
- \InProcServer32\(Default) = C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl.dll [Apache Software Foundation]
- {087B3AE3-E237-4467-B8DB-5A38AB959AC9} = OpenOffice Infotip Handler
- -> {HKLM...Wow...CLSID} = (no title provided)
- \InProcServer32\(Default) = C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl.dll [Apache Software Foundation]
- {63542C48-9552-494A-84F7-73AA6A7C99C1} = OpenOffice Property Sheet Handler
- -> {HKLM...Wow...CLSID} = (no title provided)
- \InProcServer32\(Default) = C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl.dll [Apache Software Foundation]
- {3B092F0C-7696-40E3-A80F-68D74DA84210} = OpenOffice Thumbnail Viewer
- -> {HKLM...Wow...CLSID} = (no title provided)
- \InProcServer32\(Default) = C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl.dll [Apache Software Foundation]
- {00F33137-EE26-412F-8D71-F84E4C2C6625} = (no title provided)
- -> {HKLM...Wow...CLSID} = Windows Live Photo Gallery Viewer Autoplay Shim
- \InProcServer32\(Default) = C:\Program Files (x86)\Windows Live\Photo Gallery\PhotoViewerShim.dll [MS]
- {00F346CB-35A4-465B-8B8F-65A29DBAB1F6} = Windows Live Photo Gallery Viewer Drop Target Shim
- -> {HKLM...Wow...CLSID} = Windows Live Photo Gallery Viewer Shim
- \InProcServer32\(Default) = C:\Program Files (x86)\Windows Live\Photo Gallery\PhotoViewerShim.dll [MS]
- {00F3712A-CA79-45B4-9E4D-D7891E7F8B9D} = Windows Live Photo Gallery Editor Drop Target Shim
- -> {HKLM...Wow...CLSID} = Windows Live Photo Gallery Editor Shim
- \InProcServer32\(Default) = C:\Program Files (x86)\Windows Live\Photo Gallery\PhotoViewerShim.dll [MS]
- {00F30F90-3E96-453B-AFCD-D71989ECC2C7} = Windows Live Photo Gallery Autoplay Drop Target Shim
- -> {HKLM...Wow...CLSID} = Windows Live Photo Gallery Viewer Autoplay Shim
- \InProcServer32\(Default) = C:\Program Files (x86)\Windows Live\Photo Gallery\PhotoViewerShim.dll [MS]
- {29719B01-1E78-4989-A847-FE24ECE23992} = Virtual Storage Mount Notification
- -> {HKLM...Wow...CLSID} = Virtual Storage Mount Notification
- \InProcServer32\(Default) = C:\WINDOWS\SysWOW64\cbfsMntNtf6.dll [/n software, Inc.]
- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\
- <<!>> {29719B01-1E78-4989-A847-FE24ECE23992} = Virtual Storage Mount Notification
- -> {HKLM...CLSID} = Virtual Storage Mount Notification
- \InProcServer32\(Default) = C:\WINDOWS\system32\cbfsMntNtf6.dll [/n software, Inc.]
- HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\
- <<!>> {29719B01-1E78-4989-A847-FE24ECE23992} = Virtual Storage Mount Notification
- -> {HKLM...Wow...CLSID} = Virtual Storage Mount Notification
- \InProcServer32\(Default) = C:\WINDOWS\SysWOW64\cbfsMntNtf6.dll [/n software, Inc.]
- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\
- EldosMountNotificator-cbfs6 = {29719B01-1E78-4989-A847-FE24ECE23992}
- -> {HKLM...CLSID} = Virtual Storage Mount Notification
- \InProcServer32\(Default) = C:\WINDOWS\system32\cbfsMntNtf6.dll [/n software, Inc.]
- HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\
- EldosMountNotificator-cbfs6 = {29719B01-1E78-4989-A847-FE24ECE23992}
- -> {HKLM...Wow...CLSID} = Virtual Storage Mount Notification
- \InProcServer32\(Default) = C:\WINDOWS\SysWOW64\cbfsMntNtf6.dll [/n software, Inc.]
- HKLM\SYSTEM\CurrentControlSet\Control\Lsa\
- <<!>> ("" [file not found]) Security Packages = ""
- HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\
- {169EBF44-942F-4C43-87CE-13C93996EBBE}\DllName = AppManagementConfiguration.dll [MS]
- {2A8FDC61-2347-4C87-92F6-B05EB91A201A}\DllName = C:\Windows\System32\gpprefcl.dll [MS]
- {2BFCC077-22D2-48DE-BDE1-2F618D9B476D}\DllName = AppManagementConfiguration.dll [MS]
- {4B7C3B0F-E993-4E06-A241-3FBE06943684}\DllName = C:\Windows\System32\gpprefcl.dll [MS]
- {9650FDBC-053A-4715-AD14-FC2DC65E8330}\DllName = hvsigpext.dll [null data]
- {F312195E-3D9D-447A-A3F5-08DFFA24735E}\DllName = dggpext.dll [MS]
- {FC491EF1-C4AA-4CE1-B329-414B101DB823}\DllName = dggpext.dll [MS]
- HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\
- {2A8FDC61-2347-4C87-92F6-B05EB91A201A}\DllName = C:\Windows\SysWOW64\gpprefcl.dll [MS]
- {4B7C3B0F-E993-4E06-A241-3FBE06943684}\DllName = C:\Windows\SysWOW64\gpprefcl.dll [MS]
- HKLM\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\
- WinRAR\(Default) = {B41DB860-64E4-11D2-9906-E49FADC173CA}
- -> {HKLM...CLSID} = WinRAR
- \InProcServer32\(Default) = C:\Program Files (x86)\WinRAR\rarext64.dll [Alexander Roshal]
- WinRAR32\(Default) = {B41DB860-8EE4-11D2-9906-E49FADC173CA}
- -> {HKLM...Wow...CLSID} = WinRAR
- \InProcServer32\(Default) = C:\Program Files (x86)\WinRAR\rarext.dll [Alexander Roshal]
- {73C0B1F1-F242-4213-944E-31584749AB2C}\(Default) = (no title provided)
- -> {HKLM...CLSID} = Immunet Protect Context Menu Handler
- \InProcServer32\(Default) = C:\Program Files\Immunet\6.0.6\dcm.dll [Immunet Corporation]
- HKLM\SOFTWARE\Classes\AllFilesystemObjects\shellex\ContextMenuHandlers\
- AdAwareContextMenu\(Default) = {5B64240D-5B36-4B9F-A75F-4925B6A53D5B}
- -> {HKLM...CLSID} = AdAwareContextMenu Class
- \InProcServer32\(Default) = C:\Program Files\adaware\adaware antivirus\adaware antivirus\12.0.649.11190\AdAwareShellExtension.dll [adaware]
- HKLM\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\
- UltraISO\(Default) = {AD392E40-428C-459F-961E-9B147782D099}
- -> {HKLM...CLSID} = UIContextMenu Class
- \InProcServer32\(Default) = C:\Program Files (x86)\UltraISO\isoshl64.dll [EZB Systems, Inc.]
- {73C0B1F1-F242-4213-944E-31584749AB2C}\(Default) = (no title provided)
- -> {HKLM...CLSID} = Immunet Protect Context Menu Handler
- \InProcServer32\(Default) = C:\Program Files\Immunet\6.0.6\dcm.dll [Immunet Corporation]
- HKLM\SOFTWARE\Classes\Directory\Background\shellex\ContextMenuHandlers\
- NvCplDesktopContext\(Default) = {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9}
- -> {HKLM...CLSID} = NVIDIA CPL Context Menu Extension
- \InProcServer32\(Default) = C:\WINDOWS\system32\nvshext.dll [NVIDIA Corporation]
- HKLM\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\
- {C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}\(Default) = OpenOffice Column Handler
- -> {HKLM...CLSID} = (no title provided)
- \InProcServer32\(Default) = C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl_x64.dll [Apache Software Foundation]
- -> {HKLM...Wow...CLSID} = (no title provided)
- \InProcServer32\(Default) = C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl.dll [Apache Software Foundation]
- HKLM\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\
- PintoStartScreen\(Default) = {470C0EBD-5D73-4d58-9CED-E91E22E23282}
- -> {HKLM...CLSID} = Pin To Start Screen verb handler
- \InProcServer32\(Default) = C:\Windows\System32\appresolver.dll [MS]
- -> {HKLM...Wow...CLSID} = Pin To Start Screen verb handler
- \InProcServer32\(Default) = C:\Windows\SysWOW64\appresolver.dll [MS]
- UltraISO\(Default) = {AD392E40-428C-459F-961E-9B147782D099}
- -> {HKLM...CLSID} = UIContextMenu Class
- \InProcServer32\(Default) = C:\Program Files (x86)\UltraISO\isoshl64.dll [EZB Systems, Inc.]
- WinRAR\(Default) = {B41DB860-64E4-11D2-9906-E49FADC173CA}
- -> {HKLM...CLSID} = WinRAR
- \InProcServer32\(Default) = C:\Program Files (x86)\WinRAR\rarext64.dll [Alexander Roshal]
- WinRAR32\(Default) = {B41DB860-8EE4-11D2-9906-E49FADC173CA}
- -> {HKLM...Wow...CLSID} = WinRAR
- \InProcServer32\(Default) = C:\Program Files (x86)\WinRAR\rarext.dll [Alexander Roshal]
- {73C0B1F1-F242-4213-944E-31584749AB2C}\(Default) = (no title provided)
- -> {HKLM...CLSID} = Immunet Protect Context Menu Handler
- \InProcServer32\(Default) = C:\Program Files\Immunet\6.0.6\dcm.dll [Immunet Corporation]
- HKLM\SOFTWARE\Classes\Folder\shellex\DragDropHandlers\
- WinRAR\(Default) = {B41DB860-64E4-11D2-9906-E49FADC173CA}
- -> {HKLM...CLSID} = WinRAR
- \InProcServer32\(Default) = C:\Program Files (x86)\WinRAR\rarext64.dll [Alexander Roshal]
- WinRAR32\(Default) = {B41DB860-8EE4-11D2-9906-E49FADC173CA}
- -> {HKLM...Wow...CLSID} = WinRAR
- \InProcServer32\(Default) = C:\Program Files (x86)\WinRAR\rarext.dll [Alexander Roshal]
- Group Policies {GPedit.msc branch and setting}:
- -----------------------------------------------
- Note: detected settings may not have any effect.
- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\
- NoRecentDocsHistory = (REG_DWORD) dword:0x00000000
- {unrecognized setting}
- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\
- DSCAutomationHostEnabled = (REG_DWORD) dword:0x00000002
- {unrecognized setting}
- EnableCursorSuppression = (REG_DWORD) dword:0x00000001
- {unrecognized setting}
- PromptOnSecureDesktop = (REG_DWORD) dword:0x00000000
- {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|
- User Account Control: Switch to the secure desktop when prompting for elevation}
- Active Desktop and Wallpaper:
- -----------------------------
- Active Desktop may be disabled at this entry:
- HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState
- Displayed if Active Desktop disabled and wallpaper not set by Group Policy:
- HKCU\Control Panel\Desktop\
- Wallpaper = C:\WINDOWS\web\wallpaper\Windows\img0.jpg
- Windows Portable Device AutoPlay Handlers
- -----------------------------------------
- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\
- FindAppPlayDVDMovieOnArrival\
- Provider = @mferror.dll,-115
- InvokeProgID = FindApp.DVD
- InvokeVerb = play
- HKLM\SOFTWARE\Classes\FindApp.DVD\shell\play\command\(Default) = explorer "ms-windows-store://search/?query=DVD" [MS]
- MPCPlayBluRayOnArrival\
- Provider = Media Player Classic
- InvokeProgID = MediaPlayerClassic.Autorun
- InvokeVerb = PlayBlurayMovie
- HKLM\SOFTWARE\Classes\MediaPlayerClassic.Autorun\shell\PlayBlurayMovie\command\(Default) = "C:\Program Files (x86)\K-Lite Codec Pack\MPC-HC64\mpc-hc64.exe" %L\BDMV\INDEX.BDMV [MPC-HC Team]
- MPCPlayCDAudioOnArrival\
- Provider = Media Player Classic
- InvokeProgID = MediaPlayerClassic.Autorun
- InvokeVerb = PlayCDAudio
- HKLM\SOFTWARE\Classes\MediaPlayerClassic.Autorun\shell\PlayCDAudio\command\(Default) = "C:\Program Files (x86)\K-Lite Codec Pack\MPC-HC64\mpc-hc64.exe" %1 /cd [MPC-HC Team]
- MPCPlayDVDMovieOnArrival\
- Provider = Media Player Classic
- InvokeProgID = MediaPlayerClassic.Autorun
- InvokeVerb = PlayDVDMovie
- HKLM\SOFTWARE\Classes\MediaPlayerClassic.Autorun\shell\PlayDVDMovie\command\(Default) = "C:\Program Files (x86)\K-Lite Codec Pack\MPC-HC64\mpc-hc64.exe" %1 /dvd [MPC-HC Team]
- MPCPlayMusicFilesOnArrival\
- Provider = Media Player Classic
- InvokeProgID = MediaPlayerClassic.Autorun
- InvokeVerb = PlayMusicFiles
- HKLM\SOFTWARE\Classes\MediaPlayerClassic.Autorun\shell\PlayMusicFiles\command\(Default) = "C:\Program Files (x86)\K-Lite Codec Pack\MPC-HC64\mpc-hc64.exe" %1 [MPC-HC Team]
- MPCPlayVideoFilesOnArrival\
- Provider = Media Player Classic
- InvokeProgID = MediaPlayerClassic.Autorun
- InvokeVerb = PlayVideoFiles
- HKLM\SOFTWARE\Classes\MediaPlayerClassic.Autorun\shell\PlayVideoFiles\command\(Default) = "C:\Program Files (x86)\K-Lite Codec Pack\MPC-HC64\mpc-hc64.exe" %1 [MPC-HC Team]
- MSFhConfigBackup\
- Provider = @C:\WINDOWS\system32\fhautoplay.dll,-100
- InvokeProgID = FHConfig.AutoPlayHandler
- InvokeVerb = config
- HKLM\SOFTWARE\Classes\FHConfig.AutoPlayHandler\shell\config\command\(Default) = fhmanagew -autoplay [MS]
- MSLiveShowPicturesOnArrival\
- Provider = @%ProgramFiles(x86)%\Windows Live\Photo Gallery\regres.dll,-10
- InvokeProgID = Microsoft.Photos.LiveAutoplayShim.1
- InvokeVerb = open
- HKLM\SOFTWARE\Classes\Microsoft.Photos.LiveAutoplayShim.1\shell\open\DropTarget\CLSID = {00F30F90-3E96-453B-AFCD-D71989ECC2C7}
- -> {HKLM...CLSID} = Windows Live Photo Gallery Viewer Autoplay Shim
- \InProcServer32\(Default) = C:\Program Files (x86)\Windows Live\Photo Gallery\PhotoViewerShimx64.dll [MS]
- MSPlayCDAudioOnArrival\
- Provider = @wmploc.dll,-6502
- InvokeProgID = WMP.AudioCD
- InvokeVerb = play
- HKLM\SOFTWARE\Classes\WMP.AudioCD\shell\play\command\(Default) = "C:\Program Files (x86)\Windows Media Player\wmplayer.exe" /prefetch:3 /device:AudioCD "%L" [MS]
- MSPlayDVDMovieOnArrival\
- Provider = @wmploc.dll,-6502
- InvokeProgID = WMP.DVD
- InvokeVerb = play
- HKLM\SOFTWARE\Classes\WMP.DVD\shell\play\command\(Default) = "C:\Program Files (x86)\Windows Media Player\wmplayer.exe" /prefetch:4 /device:DVD "%L" [MS]
- MSPlaySuperVideoCDMovieOnArrival\
- Provider = @wmploc.dll,-6502
- InvokeProgID = WMP.VCD
- InvokeVerb = play
- HKLM\SOFTWARE\Classes\WMP.VCD\shell\play\command\(Default) = "C:\Program Files (x86)\Windows Media Player\wmplayer.exe" /prefetch:4 /device:VCD "%L" [MS]
- MSPlayVideoCDMovieOnArrival\
- Provider = @wmploc.dll,-6502
- InvokeProgID = WMP.VCD
- InvokeVerb = play
- HKLM\SOFTWARE\Classes\WMP.VCD\shell\play\command\(Default) = "C:\Program Files (x86)\Windows Media Player\wmplayer.exe" /prefetch:4 /device:VCD "%L" [MS]
- MSPromptEachTime\
- Provider = @C:\WINDOWS\system32\shell32.dll,-17411
- ProgID = Shell.Autoplay
- InitCmdLine = PromptEachTime
- HKLM\SOFTWARE\Classes\Shell.Autoplay\CLSID\(Default) = {995C996E-D918-4a8c-A302-45719A6F4EA7}
- -> {HKLM...CLSID} = Shell Hardware Mixed Content Handler
- \LocalServer32\(Default) = C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {995C996E-D918-4a8c-A302-45719A6F4EA7} [MS]
- MSPromptEachTimeNoContent\
- Provider = @C:\WINDOWS\system32\shell32.dll,-17411
- ProgID = Shell.Autoplay
- InitCmdLine = PromptEachTimeNoContent
- HKLM\SOFTWARE\Classes\Shell.Autoplay\CLSID\(Default) = {995C996E-D918-4a8c-A302-45719A6F4EA7}
- -> {HKLM...CLSID} = Shell Hardware Mixed Content Handler
- \LocalServer32\(Default) = C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {995C996E-D918-4a8c-A302-45719A6F4EA7} [MS]
- MSStorageSense\
- Provider = @C:\WINDOWS\System32\SettingsHandlers_StorageSense.dll,-100
- InvokeProgID = MSStorageSense
- InvokeVerb = open
- HKLM\SOFTWARE\Classes\MSStorageSense\shell\open\command\(Default) = explorer ms-settings:storagesense [MS]
- MSWMPBurnCDOnArrival\
- Provider = @wmploc.dll,-6502
- InvokeProgID = WMP.BurnCD
- InvokeVerb = Burn
- HKLM\SOFTWARE\Classes\WMP.BurnCD\shell\Burn\Command\(Default) = "C:\Program Files (x86)\Windows Media Player\wmplayer.exe" /prefetch:3 /Task:CDWrite /Device:"%L" [MS]
- Startup items in "bgrze" & "All Users" startup folders:
- -------------------------------------------------------
- C:\Users\bgrze\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup {++}
- <<!>> CurseClientStartup.ccip [null data]
- Twitch -> shortcut to: C:\Users\bgrze\AppData\Roaming\Twitch\Bin\Twitch.exe /startup [null data]
- Non-disabled Scheduled Tasks: {++}
- -----------------------------
- C:\Windows\System32\Tasks
- Adobe Flash Player PPAPI Notifier -> launches: C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_27_0_0_170_pepper.exe -check pepperplugin [Adobe Systems Incorporated]
- AdobeAAMUpdater-1.0-MicrosoftAccount-b.grzegorz90@gmail.com -> launches: C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe -mode=scheduled [Adobe Systems Incorporated]
- CCleanerSkipUAC -> launches: "C:\Program Files\CCleaner\CCleaner.exe" $(Arg0) [Piriform Ltd]
- GoogleUpdateTaskMachineCore -> launches: C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c [Google Inc.]
- GoogleUpdateTaskMachineUA -> launches: C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler [Google Inc.]
- MurGeeAutoMouseMover -> launches: D:\PROGRA~1\AUTOMO~1\AUTOMO~1.EXE :silent :sccontrol [MurGee.com]
- NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} -> launches: C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe -d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log [NVIDIA Corporation]
- NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} -> launches: "C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe" [NVIDIA Corporation]
- NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} -> launches: C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe --launcher=TaskScheduler [NVIDIA Corporation]
- NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} -> launches: C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [NVIDIA Corporation]
- NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} -> launches: C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [NVIDIA Corporation]
- NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} -> launches: C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [NVIDIA Corporation]
- NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} -> launches: C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe --logon [NVIDIA Corporation]
- NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} -> launches: C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [NVIDIA Corporation]
- OneDrive Standalone Update Task-S-1-5-21-966451903-2946700475-3315859100-1001 -> launches: %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe [MS]
- SystemMaintanceService -> (HIDDEN!) launches: C:\Users\bgrze\AppData\Roaming\Youtubers.Life.v1.0.4.Repack\rgnmo.exe /upgradeid=f561932c-0bef-41b9-9289-b7d5c099b86b [file not found]
- {62B2D9F5-0EB6-430D-957C-2EE0B59E3ABC} -> launches: C:\WINDOWS\system32\pcalua.exe -a C:\Users\bgrze\Desktop\xbox\Software\setupstb.exe -d C:\Users\bgrze\Desktop\xbox\Software [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\.NET Framework
- .NET Framework NGEN v4.0.30319 -> (HIDDEN!) launches: {84F0FAE1-C27B-4F6F-807B-28CF6F96287D}
- -> {HKLM...CLSID} = (no title provided)
- \InProcServer32\(Default) = C:\Windows\System32\mscoree.dll [MS]
- .NET Framework NGEN v4.0.30319 64 -> (HIDDEN!) launches: {429BC048-379E-45E0-80E4-EB1977941B5C}
- -> {HKLM...CLSID} = (no title provided)
- \InProcServer32\(Default) = C:\Windows\System32\mscoree.dll [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\Active Directory Rights Management Services Client
- AD RMS Rights Policy Template Management (Manual) -> launches: {BF5CB148-7C77-4D8A-A53E-D81C70CF743C}
- -> {HKLM...CLSID} = AD RMS Rights Policy Template Management (Manual) Task Handler
- \InProcServer32\(Default) = C:\WINDOWS\system32\msdrm.dll [MS]
- -> {HKLM...Wow...CLSID} = AD RMS Rights Policy Template Management (Manual) Task Handler
- \InProcServer32\(Default) = C:\WINDOWS\system32\msdrm.dll [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\AppID
- EDP Policy Manager -> launches: {DECA92E0-AF85-439E-9204-86679978DA08}
- -> {HKLM...CLSID} = EDP Policy Manager Task Handler
- \InProcServer32\(Default) = C:\WINDOWS\System32\AppLockerCsp.dll [MS]
- SmartScreenSpecific -> launches: {9F2B0085-9218-42A1-88B0-9F0E65851666} [InProcServer32 entry not found]
- C:\Windows\System32\Tasks\Microsoft\Windows\Application Experience
- Microsoft Compatibility Appraiser -> launches: %windir%\system32\compattelrunner.exe [MS]
- ProgramDataUpdater -> launches: %windir%\system32\compattelrunner.exe -maintenance [MS]
- StartupAppTask -> launches: %windir%\system32\rundll32.exe Startupscan.dll,SusRunTask [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\ApplicationData
- appuriverifierdaily -> launches: %windir%\system32\AppHostRegistrationVerifier.exe [MS]
- appuriverifierinstall -> launches: %windir%\system32\AppHostRegistrationVerifier.exe [MS]
- CleanupTemporaryState -> launches: %windir%\system32\rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState [MS]
- DsSvcCleanup -> launches: %windir%\system32\dstokenclean.exe [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\Autochk
- Proxy -> launches: %windir%\system32\rundll32.exe /d acproxy.dll,PerformAutochkOperations [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\BitLocker
- BitLocker MDM policy Refresh -> launches: {61BCD1B9-340C-40EC-9D41-D7F1C0632F05}
- -> {HKLM...CLSID} = (no title provided)
- \InProcServer32\(Default) = C:\WINDOWS\System32\edptask.dll [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\Bluetooth
- UninstallDeviceTask -> launches: BthUdTask.exe $(Arg0) [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\BrokerInfrastructure
- BgTaskRegistrationMaintenanceTask -> launches: {E984D939-0E00-4DD9-AC3A-7ACA04745521} [InProcServer32 entry not found]
- C:\Windows\System32\Tasks\Microsoft\Windows\CertificateServicesClient
- AikCertEnrollTask -> launches: {47E30D54-DAC1-473A-AFF7-2355BF78881F}
- -> {HKLM...CLSID} = NGC Pregeneration Task Handler
- \InProcServer32\(Default) = C:\WINDOWS\system32\ngctasks.dll [MS]
- CryptoPolicyTask -> launches: {47E30D54-DAC1-473A-AFF7-2355BF78881F}
- -> {HKLM...CLSID} = NGC Pregeneration Task Handler
- \InProcServer32\(Default) = C:\WINDOWS\system32\ngctasks.dll [MS]
- KeyPreGenTask -> launches: {47E30D54-DAC1-473A-AFF7-2355BF78881F}
- -> {HKLM...CLSID} = NGC Pregeneration Task Handler
- \InProcServer32\(Default) = C:\WINDOWS\system32\ngctasks.dll [MS]
- SystemTask -> launches: {58FB76B9-AC85-4E55-AC04-427593B1D060}
- -> {HKLM...CLSID} = Certificate Services Client Task Handler
- \InProcServer32\(Default) = C:\WINDOWS\system32\dimsjob.dll [MS]
- -> {HKLM...Wow...CLSID} = Certificate Services Client Task Handler
- \InProcServer32\(Default) = C:\WINDOWS\system32\dimsjob.dll [MS]
- UserTask -> launches: {58FB76B9-AC85-4E55-AC04-427593B1D060}
- -> {HKLM...CLSID} = Certificate Services Client Task Handler
- \InProcServer32\(Default) = C:\WINDOWS\system32\dimsjob.dll [MS]
- -> {HKLM...Wow...CLSID} = Certificate Services Client Task Handler
- \InProcServer32\(Default) = C:\WINDOWS\system32\dimsjob.dll [MS]
- UserTask-Roam -> launches: {58FB76B9-AC85-4E55-AC04-427593B1D060}
- -> {HKLM...CLSID} = Certificate Services Client Task Handler
- \InProcServer32\(Default) = C:\WINDOWS\system32\dimsjob.dll [MS]
- -> {HKLM...Wow...CLSID} = Certificate Services Client Task Handler
- \InProcServer32\(Default) = C:\WINDOWS\system32\dimsjob.dll [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\Chkdsk
- ProactiveScan -> launches: {CF4270F5-2E43-4468-83B3-A8C45BB33EA1}
- -> {HKLM...CLSID} = Proactive Scan
- \InProcServer32\(Default) = C:\Windows\System32\pstask.dll [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\CloudExperienceHost
- CreateObjectTask -> (HIDDEN!) launches: {E4544ABA-62BF-4C54-AAB2-EC246342626C} [InProcServer32 entry not found]
- C:\Windows\System32\Tasks\Microsoft\Windows\Customer Experience Improvement Program
- Consolidator -> launches: %SystemRoot%\System32\wsqmcons.exe [MS]
- KernelCeipTask -> (HIDDEN!) launches: {E7ED314F-2816-4C26-AEB5-54A34D02404C}
- -> {HKLM...CLSID} = KernelCeipCustomHandler
- \InProcServer32\(Default) = C:\WINDOWS\System32\kernelceip.dll [MS]
- UsbCeip -> (HIDDEN!) launches: {C27F6B1D-FE0B-45E4-9257-38799FA69BC8}
- -> {HKLM...CLSID} = UsbCeip
- \InProcServer32\(Default) = C:\WINDOWS\System32\usbceip.dll [MS]
- -> {HKLM...Wow...CLSID} = UsbCeip
- \InProcServer32\(Default) = C:\WINDOWS\System32\usbceip.dll [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\Data Integrity Scan
- Data Integrity Scan -> launches: {DCFD3EA8-D960-4719-8206-490AE315F94F}
- -> {HKLM...CLSID} = Data Integrity Scan
- \InProcServer32\(Default) = C:\Windows\System32\discan.dll [MS]
- Data Integrity Scan for Crash Recovery -> (HIDDEN!) launches: {DCFD3EA8-D960-4719-8206-490AE315F94F}
- -> {HKLM...CLSID} = Data Integrity Scan
- \InProcServer32\(Default) = C:\Windows\System32\discan.dll [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\Defrag
- ScheduledDefrag -> launches: %windir%\system32\defrag.exe -c -h -o -$ [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\Device Information
- Device -> launches: %windir%\system32\devicecensus.exe [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\Device Setup
- Metadata Refresh -> (HIDDEN!) launches: {23C1F3CF-C110-4512-ACA9-7B6174ECE888}
- -> {HKLM...CLSID} = DsmRefreshTask Class
- \InProcServer32\(Default) = C:\WINDOWS\System32\DeviceSetupManagerAPI.dll [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\DeviceDirectoryClient
- HandleCommand -> (HIDDEN!) launches: {AE31B729-D5FD-401E-AF42-784074835AFE}
- -> {HKLM...CLSID} = Device Directory Client Handler
- \InProcServer32\(Default) = C:\WINDOWS\system32\DeviceDirectoryClient.dll [MS]
- HandleWnsCommand -> (HIDDEN!) launches: {AE31B729-D5FD-401E-AF42-784074835AFE}
- -> {HKLM...CLSID} = Device Directory Client Handler
- \InProcServer32\(Default) = C:\WINDOWS\system32\DeviceDirectoryClient.dll [MS]
- LocateCommandUserSession -> (HIDDEN!) launches: {AE31B729-D5FD-401E-AF42-784074835AFE}
- -> {HKLM...CLSID} = Device Directory Client Handler
- \InProcServer32\(Default) = C:\WINDOWS\system32\DeviceDirectoryClient.dll [MS]
- RegisterDeviceAccountChange -> (HIDDEN!) launches: {AE31B729-D5FD-401E-AF42-784074835AFE}
- -> {HKLM...CLSID} = Device Directory Client Handler
- \InProcServer32\(Default) = C:\WINDOWS\system32\DeviceDirectoryClient.dll [MS]
- RegisterDeviceLocationRightsChange -> (HIDDEN!) launches: {AE31B729-D5FD-401E-AF42-784074835AFE}
- -> {HKLM...CLSID} = Device Directory Client Handler
- \InProcServer32\(Default) = C:\WINDOWS\system32\DeviceDirectoryClient.dll [MS]
- RegisterDevicePeriodic24 -> (HIDDEN!) launches: {AE31B729-D5FD-401E-AF42-784074835AFE}
- -> {HKLM...CLSID} = Device Directory Client Handler
- \InProcServer32\(Default) = C:\WINDOWS\system32\DeviceDirectoryClient.dll [MS]
- RegisterDevicePolicyChange -> (HIDDEN!) launches: {AE31B729-D5FD-401E-AF42-784074835AFE}
- -> {HKLM...CLSID} = Device Directory Client Handler
- \InProcServer32\(Default) = C:\WINDOWS\system32\DeviceDirectoryClient.dll [MS]
- RegisterDeviceProtectionStateChanged -> (HIDDEN!) launches: {AE31B729-D5FD-401E-AF42-784074835AFE}
- -> {HKLM...CLSID} = Device Directory Client Handler
- \InProcServer32\(Default) = C:\WINDOWS\system32\DeviceDirectoryClient.dll [MS]
- RegisterDeviceSettingChange -> (HIDDEN!) launches: {AE31B729-D5FD-401E-AF42-784074835AFE}
- -> {HKLM...CLSID} = Device Directory Client Handler
- \InProcServer32\(Default) = C:\WINDOWS\system32\DeviceDirectoryClient.dll [MS]
- RegisterUserDevice -> (HIDDEN!) launches: {AE31B729-D5FD-401E-AF42-784074835AFE}
- -> {HKLM...CLSID} = Device Directory Client Handler
- \InProcServer32\(Default) = C:\WINDOWS\system32\DeviceDirectoryClient.dll [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\Diagnosis
- Scheduled -> (HIDDEN!) launches: {C1F85EF8-BCC2-4606-BB39-70C523715EB3}
- -> {HKLM...CLSID} = ScheduledDiagnosticCustomHandler
- \InProcServer32\(Default) = C:\WINDOWS\System32\sdiagschd.dll [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\DiskCleanup
- SilentCleanup -> launches: %windir%\system32\cleanmgr.exe /autoclean /d %systemdrive% [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\DiskDiagnostic
- Microsoft-Windows-DiskDiagnosticDataCollector -> (HIDDEN!) launches: %windir%\system32\rundll32.exe dfdts.dll,DfdGetDefaultPolicyAndSMART [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\DiskFootprint
- Diagnostics -> launches: %windir%\system32\disksnapshot.exe -z [MS]
- StorageSense -> launches: {AB2A519B-03B0-43CE-940A-A73DF850B49A}
- -> {HKLM...CLSID} = StorageUsage State Reporter Task Handler
- \InProcServer32\(Default) = C:\WINDOWS\system32\StorageUsage.dll [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\DUSM
- dusmtask -> launches: %SystemRoot%\System32\dusmtask.exe [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\EDP
- EDP App Launch Task -> launches: {61BCD1B9-340C-40EC-9D41-D7F1C0632F05}
- -> {HKLM...CLSID} = (no title provided)
- \InProcServer32\(Default) = C:\WINDOWS\System32\edptask.dll [MS]
- EDP Auth Task -> launches: {61BCD1B9-340C-40EC-9D41-D7F1C0632F05}
- -> {HKLM...CLSID} = (no title provided)
- \InProcServer32\(Default) = C:\WINDOWS\System32\edptask.dll [MS]
- EDP Inaccessible Credentials Task -> launches: {61BCD1B9-340C-40EC-9D41-D7F1C0632F05}
- -> {HKLM...CLSID} = (no title provided)
- \InProcServer32\(Default) = C:\WINDOWS\System32\edptask.dll [MS]
- StorageCardEncryption Task -> launches: {61BCD1B9-340C-40EC-9D41-D7F1C0632F05}
- -> {HKLM...CLSID} = (no title provided)
- \InProcServer32\(Default) = C:\WINDOWS\System32\edptask.dll [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\EnterpriseMgmt
- MDMMaintenenceTask -> launches: %windir%\system32\MDMAgent.exe [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\ErrorDetails
- EnableErrorDetailsUpdate -> launches: {FE285C8C-5360-41C1-A700-045501C740DE} [InProcServer32 entry not found]
- C:\Windows\System32\Tasks\Microsoft\Windows\Feedback\Siuf
- DmClient -> launches: %windir%\system32\dmclient.exe [MS]
- DmClientOnScenarioDownload -> launches: %windir%\system32\dmclient.exe utcwnf [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\FileHistory
- File History (maintenance mode) -> launches: {89917B7C-A1A6-11DF-8BF6-18A90531A85A}
- -> {HKLM...CLSID} = FhTaskHandler Class
- \InProcServer32\(Default) = C:\WINDOWS\System32\fhtask.dll [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\LanguageComponentsInstaller
- Installation -> launches: {6F58F65F-EC0E-4ACA-99FE-FC5A1A25E4BE}
- -> {HKLM...CLSID} = Language Components Installer
- \InProcServer32\(Default) = C:\Windows\System32\LanguageComponentsInstaller.dll [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\License Manager
- TempSignedLicenseExchange -> (HIDDEN!) launches: {77646A68-AD14-4D53-897D-7BE4DDE5F929}
- -> {HKLM...CLSID} = TempSignedLicenseExchangeTask
- \InProcServer32\(Default) = C:\Windows\System32\TempSignedLicenseExchangeTask.dll [MS]
- -> {HKLM...Wow...CLSID} = TempSignedLicenseExchangeTask
- \InProcServer32\(Default) = C:\Windows\SysWOW64\TempSignedLicenseExchangeTask.dll [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\Location
- Notifications -> launches: %windir%\System32\LocationNotificationWindows.exe [MS]
- WindowsActionDialog -> launches: %windir%\System32\WindowsActionDialog.exe [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\Maintenance
- WinSAT -> launches: {A9A33436-678B-4C9C-A211-7CC38785E79D}
- -> {HKLM...CLSID} = WinSAT Task Manger Task
- \InProcServer32\(Default) = C:\WINDOWS\system32\WinSATAPI.dll [MS]
- -> {HKLM...Wow...CLSID} = WinSAT Task Manger Task
- \InProcServer32\(Default) = C:\WINDOWS\system32\WinSATAPI.dll [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\Management\Provisioning
- Cellular -> (HIDDEN!) launches: %windir%\system32\ProvTool.exe /turn 7 /source CellStateChangeTask [MS]
- Logon -> (HIDDEN!) launches: %windir%\system32\ProvTool.exe /turn 5 /source LogonIdleTask [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\Maps
- MapsToastTask -> (HIDDEN!) launches: {9885AEF2-BD9F-41E0-B15E-B3141395E803}
- -> {HKLM...CLSID} = (no title provided)
- \InProcServer32\(Default) = C:\WINDOWS\System32\mapstoasttask.dll [MS]
- -> {HKLM...Wow...CLSID} = (no title provided)
- \InProcServer32\(Default) = C:\WINDOWS\System32\mapstoasttask.dll [MS]
- MapsUpdateTask -> launches: {B9033E87-33CF-4D77-BC9B-895AFBBA72E4}
- -> {HKLM...CLSID} = (no title provided)
- \InProcServer32\(Default) = C:\WINDOWS\System32\mapsupdatetask.dll [MS]
- -> {HKLM...Wow...CLSID} = (no title provided)
- \InProcServer32\(Default) = C:\WINDOWS\System32\mapsupdatetask.dll [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\MemoryDiagnostic
- ProcessMemoryDiagnosticEvents -> (HIDDEN!) launches: {8168E74A-B39F-46D8-ADCD-7BED477B80A3}
- -> {HKLM...CLSID} = MemoryDiagnosticTaskHandler
- \InProcServer32\(Default) = C:\WINDOWS\System32\MemoryDiagnostic.dll [MS]
- RunFullMemoryDiagnostic -> (HIDDEN!) launches: {8168E74A-B39F-46D8-ADCD-7BED477B80A3}
- -> {HKLM...CLSID} = MemoryDiagnosticTaskHandler
- \InProcServer32\(Default) = C:\WINDOWS\System32\MemoryDiagnostic.dll [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\Mobile Broadband Accounts
- MNO Metadata Parser -> launches: %SystemRoot%\System32\MbaeParserTask.exe [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\MUI
- LPRemove -> launches: %windir%\system32\lpremove.exe [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\Multimedia
- SystemSoundsService -> launches: {2DEA658F-54C1-4227-AF9B-260AB5FC3543}
- -> {HKLM...CLSID} = Microsoft PlaySoundService Class
- \InProcServer32\(Default) = C:\WINDOWS\System32\PlaySndSrv.dll [MS]
- -> {HKLM...Wow...CLSID} = Microsoft PlaySoundService Class
- \InProcServer32\(Default) = C:\WINDOWS\System32\PlaySndSrv.dll [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\NetTrace
- GatherNetworkInfo -> launches: %windir%\system32\gatherNetworkInfo.vbs [null data]
- C:\Windows\System32\Tasks\Microsoft\Windows\NlaSvc
- WiFiTask -> (HIDDEN!) launches: %SystemRoot%\System32\WiFiTask.exe nla [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\PI
- Secure-Boot-Update -> launches: {5014B7C8-934E-4262-9816-887FA745A6C4}
- -> {HKLM...CLSID} = TPM Maintenance Task Handler
- \InProcServer32\(Default) = C:\WINDOWS\system32\TpmTasks.dll [MS]
- Sqm-Tasks -> launches: {5014B7C8-934E-4262-9816-887FA745A6C4}
- -> {HKLM...CLSID} = TPM Maintenance Task Handler
- \InProcServer32\(Default) = C:\WINDOWS\system32\TpmTasks.dll [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\Plug and Play
- Device Install Group Policy -> (HIDDEN!) launches: {60400283-B242-4FA8-8C25-CAF695B88209}
- -> {HKLM...CLSID} = Device Installation Group Policy Task Handler
- \InProcServer32\(Default) = C:\Windows\System32\pnppolicy.dll [MS]
- Device Install Reboot Required -> (HIDDEN!) launches: {48794782-6A1F-47B9-BD52-1D5F95D49C1B}
- -> {HKLM...CLSID} = Device Installation Reboot Dialog Task
- \InProcServer32\(Default) = C:\Windows\System32\pnpui.dll [MS]
- Plug and Play Cleanup -> launches: {DEF03232-9688-11E2-BE7F-B4B52FD966FF} [InProcServer32 entry not found]
- Sysprep Generalize Drivers -> launches: %SystemRoot%\System32\drvinst.exe 6 [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\Power Efficiency Diagnostics
- AnalyzeSystem -> launches: {927EA2AF-1C54-43D5-825E-0074CE028EEE}
- -> {HKLM...CLSID} = (no title provided)
- \InProcServer32\(Default) = C:\WINDOWS\System32\energytask.dll [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\Ras
- MobilityManager -> launches: {C463A0FC-794F-4FDF-9201-01938CEACAFA}
- -> {HKLM...CLSID} = RasMobilityManager
- \InProcServer32\(Default) = C:\WINDOWS\system32\rasmbmgr.dll [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\Registry
- RegIdleBackup -> (HIDDEN!) launches: {CA767AA8-9157-4604-B64B-40747123D5F2}
- -> {HKLM...CLSID} = RegistryIdleBackupHandler
- \InProcServer32\(Default) = C:\WINDOWS\System32\regidle.dll [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\RemoteAssistance
- RemoteAssistanceTask -> (HIDDEN!) launches: %windir%\system32\RAServer.exe /offerraupdate [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\RemovalTools
- MRT_HB -> launches: C:\WINDOWS\system32\MRT.exe /EHB /Q [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\Servicing
- StartComponentCleanup -> launches: {752073A1-23F2-4396-85F0-8FDB879ED0ED} [InProcServer32 entry not found]
- C:\Windows\System32\Tasks\Microsoft\Windows\SettingSync
- BackgroundUploadTask -> (HIDDEN!) launches: {59B9640B-3F70-4D1C-B159-F26EEB8A4C87}
- -> {HKLM...CLSID} = Delayed Background Upload Task Handler
- \InProcServer32\(Default) = C:\WINDOWS\system32\SettingSyncCore.dll [MS]
- -> {HKLM...Wow...CLSID} = Delayed Background Upload Task Handler
- \InProcServer32\(Default) = C:\WINDOWS\system32\SettingSyncCore.dll [MS]
- BackupTask -> (HIDDEN!) launches: {60A4C78C-E2B8-4E6E-876F-DA203B02C05E}
- -> {HKLM...CLSID} = Backup Upload Task Handler
- \InProcServer32\(Default) = C:\WINDOWS\system32\SettingSyncCore.dll [MS]
- -> {HKLM...Wow...CLSID} = Backup Upload Task Handler
- \InProcServer32\(Default) = C:\WINDOWS\system32\SettingSyncCore.dll [MS]
- NetworkStateChangeTask -> (HIDDEN!) launches: {A4173A49-F373-4475-9A0F-2D615204DC20}
- -> {HKLM...CLSID} = Network State Change Task Handler
- \InProcServer32\(Default) = C:\WINDOWS\system32\SettingSyncCore.dll [MS]
- -> {HKLM...Wow...CLSID} = Network State Change Task Handler
- \InProcServer32\(Default) = C:\WINDOWS\system32\SettingSyncCore.dll [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\Shell
- CreateObjectTask -> (HIDDEN!) launches: {990A9F8F-301F-45F7-8D0E-68C5952DBA43}
- -> {HKLM...CLSID} = Shell Create Object Task Delegate
- \InProcServer32\(Default) = C:\WINDOWS\system32\shell32.dll [MS]
- -> {HKLM...Wow...CLSID} = Shell Create Object Task Delegate
- \InProcServer32\(Default) = C:\WINDOWS\system32\shell32.dll [MS]
- FamilySafetyMonitor -> launches: %windir%\System32\wpcmon.exe [MS]
- FamilySafetyRefreshTask -> launches: {C844C79D-AED8-4DCE-AB25-4D359BED84F8}
- -> {HKLM...CLSID} = FamilySafetyRefreshTask
- \InProcServer32\(Default) = C:\WINDOWS\System32\WpcRefreshTask.dll [MS]
- IndexerAutomaticMaintenance -> launches: {3FBA60A6-7BF5-4868-A2CA-6623B3DFFEA6}
- -> {HKLM...CLSID} = Automatic Maintenance task to enable Windows Search to make progress while in Connected Standby
- \InProcServer32\(Default) = C:\WINDOWS\System32\srchadmin.dll [MS]
- -> {HKLM...Wow...CLSID} = Automatic Maintenance task to enable Windows Search to make progress while in Connected Standby
- \InProcServer32\(Default) = C:\WINDOWS\System32\srchadmin.dll [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\SoftwareProtectionPlatform
- SvcRestartTask -> (HIDDEN!) launches: {B1AEBB5D-EAD9-4476-B375-9C3ED9F32AFC}
- -> {HKLM...CLSID} = SppSvcRestartTaskHandler Class
- \InProcServer32\(Default) = C:\WINDOWS\System32\sppcext.dll [MS]
- -> {HKLM...Wow...CLSID} = SppSvcRestartTaskHandler Class
- \InProcServer32\(Default) = C:\WINDOWS\System32\sppcext.dll [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\SpacePort
- SpaceAgentTask -> launches: %windir%\system32\SpaceAgent.exe [MS]
- SpaceManagerTask -> launches: %windir%\system32\spaceman.exe /Work [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\Speech
- SpeechModelDownloadTask -> launches: %windir%\system32\speech_onecore\common\SpeechModelDownload.exe [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\Storage Tiers Management
- Storage Tiers Management Initialization -> launches: {5C9AB547-345D-4175-9AF6-65133463A100} [InProcServer32 entry not found]
- C:\Windows\System32\Tasks\Microsoft\Windows\Subscription
- EnableLicenseAcquisition -> (HIDDEN!) launches: %SystemRoot%\system32\ClipRenew.exe -e [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\Sysmain
- ResPriStaticDbSync -> launches: {297EE78C-BA95-4E94-81D3-D6E7F089C7B5}
- -> {HKLM...CLSID} = Reserved Priority Static Db Sync Task
- \InProcServer32\(Default) = C:\WINDOWS\system32\sysmain.dll [MS]
- WsSwapAssessmentTask -> launches: %windir%\system32\rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\SystemRestore
- SR -> launches: %windir%\system32\srtasks.exe ExecuteScheduledSPPCreation [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\Task Manager
- Interactive -> (HIDDEN!) launches: {855FEC53-D2E4-4999-9E87-3414E9CF0FF4}
- -> {HKLM...CLSID} = RunTask
- \InProcServer32\(Default) = C:\WINDOWS\system32\wdc.dll [MS]
- -> {HKLM...Wow...CLSID} = RunTask
- \InProcServer32\(Default) = C:\WINDOWS\system32\wdc.dll [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\TextServicesFramework
- MsCtfMonitor -> (HIDDEN!) launches: {01575CFE-9A55-4003-A5E1-F38D1EBDCBE1}
- -> {HKLM...CLSID} = MsCtfMonitor task handler
- \InProcServer32\(Default) = C:\WINDOWS\system32\MsCtfMonitor.dll [MS]
- -> {HKLM...Wow...CLSID} = MsCtfMonitor task handler
- \InProcServer32\(Default) = C:\WINDOWS\system32\MsCtfMonitor.dll [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\Time Synchronization
- ForceSynchronizeTime -> launches: {A31AD6C2-FF4C-43D4-8E90-7101023096F9}
- -> {HKLM...CLSID} = Time Synchronization Task Handler
- \InProcServer32\(Default) = C:\WINDOWS\system32\TimeSyncTask.dll [MS]
- SynchronizeTime -> launches: %windir%\system32\sc.exe start w32time task_started [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\Time Zone
- SynchronizeTimeZone -> launches: %windir%\system32\tzsync.exe [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\TPM
- Tpm-HASCertRetr -> launches: {5014B7C8-934E-4262-9816-887FA745A6C4}
- -> {HKLM...CLSID} = TPM Maintenance Task Handler
- \InProcServer32\(Default) = C:\WINDOWS\system32\TpmTasks.dll [MS]
- Tpm-Maintenance -> launches: {5014B7C8-934E-4262-9816-887FA745A6C4}
- -> {HKLM...CLSID} = TPM Maintenance Task Handler
- \InProcServer32\(Default) = C:\WINDOWS\system32\TpmTasks.dll [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\UNP
- RunCampaignManager -> launches: %windir%\System32\UNP\UNPCampaignManager.exe [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\UpdateOrchestrator
- Refresh Settings -> launches: %systemroot%\system32\usoclient.exe RefreshSettings [MS]
- Schedule Scan -> launches: %systemroot%\system32\usoclient.exe StartScan [MS]
- USO_UxBroker_Display -> launches: %systemroot%\system32\MusNotification.exe Display [MS]
- USO_UxBroker_ReadyToReboot -> launches: %systemroot%\system32\MusNotification.exe ReadyToReboot [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\UPnP
- UPnPHostConfig -> launches: sc.exe config upnphost start= auto [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\WCM
- WiFiTask -> (HIDDEN!) launches: %SystemRoot%\System32\WiFiTask.exe [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\WDI
- ResolutionHost -> (HIDDEN!) launches: {900BE39D-6BE8-461A-BC4D-B0FA71F5ECB1}
- -> {HKLM...CLSID} = DiagnosticInfrastructureCustomHandler
- \InProcServer32\(Default) = C:\WINDOWS\System32\wdi.dll [MS]
- -> {HKLM...Wow...CLSID} = DiagnosticInfrastructureCustomHandler
- \InProcServer32\(Default) = C:\WINDOWS\System32\wdi.dll [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\Windows Error Reporting
- QueueReporting -> launches: %windir%\system32\wermgr.exe -upload [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\Windows Filtering Platform
- BfeOnServiceStartTypeChange -> (HIDDEN!) launches: %windir%\system32\rundll32.exe bfe.dll,BfeOnServiceStartTypeChange [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\Windows Media Sharing
- UpdateLibrary -> launches: "%ProgramFiles%\Windows Media Player\wmpnscfg.exe" [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\WindowsUpdate
- Automatic App Update -> launches: {A6BA00FE-40E8-477C-B713-C64A14F18ADB}
- -> {HKLM...CLSID} = (no title provided)
- \InProcServer32\(Default) = C:\Windows\System32\wuautoappupdate.dll [MS]
- Scheduled Start -> launches: C:\WINDOWS\system32\sc.exe start wuauserv [MS]
- sih -> (HIDDEN!) launches: %systemroot%\System32\sihclient.exe [MS]
- sihboot -> (HIDDEN!) launches: %systemroot%\System32\sihclient.exe /boot [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\Wininet
- CacheTask -> launches: {0358B920-0AC7-461F-98F4-58E32CD89148}
- -> {HKLM...CLSID} = Wininet Cache task object
- \InProcServer32\(Default) = C:\WINDOWS\system32\wininet.dll [MS]
- -> {HKLM...Wow...CLSID} = Wininet Cache task object
- \InProcServer32\(Default) = C:\WINDOWS\system32\wininet.dll [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\WOF
- WIM-Hash-Management -> launches: {B7BFFB5A-EFA8-4D8C-BBDE-C8D5FAAF54A1}
- -> {HKLM...CLSID} = WOF Task Handler
- \InProcServer32\(Default) = C:\WINDOWS\system32\WofTasks.dll [MS]
- WIM-Hash-Validation -> launches: {B7BFFB5A-EFA8-4D8C-BBDE-C8D5FAAF54A1}
- -> {HKLM...CLSID} = WOF Task Handler
- \InProcServer32\(Default) = C:\WINDOWS\system32\WofTasks.dll [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\Work Folders
- Work Folders Logon Synchronization -> launches: {97D47D56-3777-49FB-8E8F-90D7E30E1A1E}
- -> {HKLM...CLSID} = Work Folder Logon Trigger Class
- \InProcServer32\(Default) = C:\Windows\System32\WorkFoldersShell.dll [MS]
- Work Folders Maintenance Work -> launches: {63260BCE-A3FB-4A34-AA51-D4D8E877B62B}
- -> {HKLM...CLSID} = Work Folder Maintenance Task Class
- \InProcServer32\(Default) = C:\Windows\System32\WorkFoldersShell.dll [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\WwanSvc
- NotificationTask -> (HIDDEN!) launches: %SystemRoot%\System32\WiFiTask.exe wwan [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows Live\SOXE
- Extractor Definitions Update Task -> launches: {3519154C-227E-47F3-9CC9-12C3F05817F1}
- -> {HKLM...Wow...CLSID} = Windows Live Social Object Extractor Engine Definition Updater
- \InProcServer32\(Default) = C:\Program Files (x86)\Windows Live\SOXE\wlsoxe.dll [MS]
- C:\Windows\System32\Tasks\Microsoft\XblGameSave
- XblGameSaveTask -> launches: %windir%\System32\XblGameSaveTask.exe standby [MS]
- XblGameSaveTaskLogon -> launches: %windir%\System32\XblGameSaveTask.exe logon [MS]
- Winsock2 Service Provider DLLs:
- -------------------------------
- Namespace Service Providers
- HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
- 000000000001\LibraryPath = %SystemRoot%\system32\napinsp.dll [MS]
- 000000000002\LibraryPath = %SystemRoot%\system32\pnrpnsp.dll [MS]
- 000000000003\LibraryPath = %SystemRoot%\system32\pnrpnsp.dll [MS]
- 000000000004\LibraryPath = %SystemRoot%\system32\NLAapi.dll [MS]
- 000000000005\LibraryPath = %SystemRoot%\System32\mswsock.dll [MS]
- 000000000006\LibraryPath = %SystemRoot%\System32\winrnr.dll [MS]
- 000000000007\LibraryPath = %SystemRoot%\System32\wshbth.dll [MS]
- HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\ {++}
- 000000000001\LibraryPath = %SystemRoot%\system32\napinsp.dll [MS]
- 000000000002\LibraryPath = %SystemRoot%\system32\pnrpnsp.dll [MS]
- 000000000003\LibraryPath = %SystemRoot%\system32\pnrpnsp.dll [MS]
- 000000000004\LibraryPath = %SystemRoot%\system32\NLAapi.dll [MS]
- 000000000005\LibraryPath = %SystemRoot%\System32\mswsock.dll [MS]
- 000000000006\LibraryPath = %SystemRoot%\System32\winrnr.dll [MS]
- 000000000007\LibraryPath = %SystemRoot%\System32\wshbth.dll [MS]
- Transport Service Providers
- HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
- 0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
- %SystemRoot%\system32\mswsock.dll [MS], 01 - 13
- HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries64\ {++}
- 0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
- %SystemRoot%\system32\mswsock.dll [MS], 01 - 13
- Running Services (Display Name, Service Name, Path {Service DLL}):
- ------------------------------------------------------------------
- Chrome Remote Desktop Service, chromoting, "C:\Program Files (x86)\Google\Chrome Remote Desktop\61.0.3163.20\remoting_host.exe" --type=daemon --host-config="C:\ProgramData\Google\Chrome Remote Desktop\host.json" [Google Inc.]
- Immunet 6.0.6, ImmunetProtect_6.0.6, "C:\Program Files\Immunet\6.0.6\sfc.exe" [Cisco Systems, Inc.]
- NVIDIA Display Container LS, NVDisplay.ContainerLocalSystem, "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000 [NVIDIA Corporation]
- NVIDIA LocalSystem Container, NvContainerLocalSystem, "C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe" -s NvContainerLocalSystem -f "C:\ProgramData\NVIDIA\NvContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\NvContainer\plugins\LocalSystem" -r -p 30000 -st "C:\Program Files\NVIDIA Corporation\NvContainer\NvContainerTelemetryApi.dll" [NVIDIA Corporation]
- NVIDIA Telemetry Container, NvTelemetryContainer, "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe" -s NvTelemetryContainer -f "C:\ProgramData\NVIDIA\NvTelemetryContainer.log" -l 3 -d "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\plugins" -r [NVIDIA Corporation]
- Origin Web Helper Service, Origin Web Helper Service, "C:\Program Files (x86)\Origin\OriginWebHelperService.exe" [Electronic Arts]
- PnkBstrA, PnkBstrA, C:\WINDOWS\system32\PnkBstrA.exe [file not found]
- TokenBroker, TokenBroker, (null value) [file not found]
- Safe Mode Drivers & Services (subkey name, subkey default value):
- -----------------------------------------------------------------
- HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\
- <<!>> iai2c.sys, Driver
- <<!>> {F2E7DD72-6468-4E36-B6F1-6488F42C1B52}, Firmware
- HKLM\System\CurrentControlSet\Control\SafeBoot\Network\
- <<!>> NetSetupSvc, Service
- <<!>> {F2E7DD72-6468-4E36-B6F1-6488F42C1B52}, Firmware
- Print Monitors:
- ---------------
- HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors\
- Appmon\Driver = AppMon.dll [MS]
- IppMon\Driver = IPPMon.dll [MS]
- ---------- (launch time: 2017-10-24 16:54:15)
- <<!>>: Suspicious data at a malware launch point.
- + This report excludes default entries except where indicated.
- + To see *everywhere* the script checks and *everything* it finds,
- launch it from a command prompt or a shortcut with the -all parameter.
- + The search for DESKTOP.INI DLL launch points on all local fixed drives
- took 270 seconds.
- ---------- (total run time: 336 seconds)
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement