SpyHolesList Version:18.0 Build:12.60.2021.608-64b 19.06.2021 07:06:13 Geo: FR-French WinDir=C:\WINDOWS Startup=C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Common Startup=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ Windows 10 Home (10.0.19043) Internet Explorer 9.11.19041.0 DBS Version: 2.1270 [EDGE CHROMIUM:Default:C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\] [Google Chrome Settings] :HKLM backup.homepage="" [Google Chrome Settings] :HKLM backup.session.urls_to_restore_on_startup="" [Google Chrome Settings] :HKLM session.startup_urls="" [Google Chrome Settings] :HKLM default_search_provider_data.favicon_url="" [Google Chrome Settings] :HKLM default_search_provider_data.keyword="" [Google Chrome Settings] :HKLM default_search_provider_data.short_name="" [Google Chrome Settings] :HKLM default_search_provider_data.url="" [Google Chrome Settings] :HKLM default_search_provider_data.suggestions_url="" [Google Chrome Settings] :HKLM default_search_provider_data.template_url_data.alternate_urls="" [Google Chrome Settings] :HKLM default_search_provider_data.template_url_data.favicon_url="" [Google Chrome Settings] :HKLM default_search_provider_data.template_url_data.keyword="" [Google Chrome Settings] :HKLM default_search_provider_data.template_url_data.short_name="" [Google Chrome Settings] :HKLM default_search_provider_data.template_url_data.url="" [Google Chrome Settings] :HKLM default_search_provider_data.template_url_data.suggest_url="" [Google Chrome Settings] :HKLM default_search_provider_data.template_url_data.new_tab_url="" [Google Chrome Settings] :HKLM default_search_provider_data.template_url_data.instant_url="" [Google Chrome Settings] :HKLM default_search_provider_data.template_url_data.image_url="" [Google Chrome Settings] :HKLM homepage="" [Google Chrome Settings] :HKLM session.urls_to_restore_on_startup="" [Chrome Protected Settings] session.startup_urls=["https:\/\/www.google.fr\/"] [Chrome Protected Settings] homepage=https://www.google.fr/ [Google Chrome Addons] ihmafllikibpmigkcoadcmckbfhibefp=C:\Program Files (x86)\Microsoft\Edge\Application\85.0.564.67\resources\edge_feedback ### Edge Feedback: User feedback extension [Google Chrome Addons] leffmjdabcgaflkikcefahmlgpodjkdm=C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\leffmjdabcgaflkikcefahmlgpodjkdm ### Excel: [Google Chrome Addons] ahfgeienlihckogmohjhadlkjgocpleb=C:\Program Files (x86)\Microsoft\Edge\Application\85.0.564.67\resources\web_store ### Web Store: Découvrir les extensions pour Microsoft Edge. [Google Chrome Addons] ncbjelpjchkpbikbpkcchkhkblodoama=C:\Program Files (x86)\Microsoft\Edge\Application\91.0.864.37\resources\webrtc_internals ### WebRTC Internals Extension: [Google Chrome Addons] hikhggiobiflkdfdgdajcfklmcibbopi=C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\hikhggiobiflkdfdgdajcfklmcibbopi ### Word: [Google Chrome Addons] kmendfapggjehodndflmmgagdbamhnfd=C:\Program Files (x86)\Microsoft\Edge\Application\85.0.564.67\resources\cryptotoken ### CryptoTokenExtension: CryptoToken Component Extension [Google Chrome Addons] iglcjdemknebjbklcgkfaebgojjphkec=C:\Program Files (x86)\Microsoft\Edge\Application\85.0.564.67\resources\microsoft_web_store ### Microsoft Store: Découvrir les extensions pour Microsoft Edge. [Google Chrome Addons] mhjfbmdgcfjbbpaeojofohoefgiehjai=C:\Program Files (x86)\Microsoft\Edge\Application\85.0.564.67\resources\edge_pdf ### Microsoft Edge PDF Viewer: [Google Chrome Addons] gmgoamodcdcjnbaobigkjelfplakmdhh=C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\gmgoamodcdcjnbaobigkjelfplakmdhh ### Adblock Plus - bloqueur de publicités gratuit: Bloquez les publicités YouTube™, les pop-ups et protégez-vous des logiciels malveillants ! update_url: https://edge.microsoft.com/extensionwebstorebase/v1/crx [Google Chrome Addons] bjhmmnoficofgoiacjaajpkfndojknpb=C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\bjhmmnoficofgoiacjaajpkfndojknpb ### Outlook: [Google Chrome Addons] fikbjbembnmfhppjfnmfkahdhfohhjmg=C:\Program Files (x86)\Microsoft\Edge\Application\85.0.564.67\resources\media_internals_services ### Media Internals Services Extension: [Google Chrome Addons] jdiccldimpdaibmpdkjnbmckianbfold=C:\Program Files (x86)\Microsoft\Edge\Application\85.0.564.67\resources\microsoft_voices ### Microsoft Voices: Provides access to Microsoft's online text-to-speech voices [Google Chrome Addons] dgiklkfkllikcanfonkcabmbdfmgleag=C:\Program Files (x86)\Microsoft\Edge\Application\85.0.564.67\resources\edge_clipboard ### Microsoft Clipboard Extension: This extension grants Microsoft web sites permission to read and write from the clipboard. [Google Chrome Addons] nkeimhogjdpnpccoofpliimaahmaaome=C:\Program Files (x86)\Microsoft\Edge\Application\89.0.774.76\resources\hangout_services ### Google Hangouts: [Google Chrome Addons] opfacbhaojodjaojgocnibmklknchehf=C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\opfacbhaojodjaojgocnibmklknchehf ### PowerPoint: [Google Chrome Addons] fogppepbgmgkpdkinbojbibkhoffpief=C:\Program Files (x86)\Microsoft\Edge\Application\85.0.564.67\resources\edge_collections ### Edge Collections: Collections extension [Google Chrome Addons] fdgpikaaheckgdijjmepmdjjkbceakif=C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\fdgpikaaheckgdijjmepmdjjkbceakif ### Avast Online Security: Avast Browser Security and Web Reputation Plugin. update_url: https://edge.microsoft.com/extensionwebstorebase/v1/crx [Internet Explorer] [Default Home Page] :HKLM Default_Page_URL=http://go.microsoft.com/fwlink/p/?LinkId=255141 [Current Home Page] :HKCU Start Page=http://go.microsoft.com/fwlink/p/?LinkId=255141 [Current Home Page] :HKCU HOMEOldSP="" [Current Home Page] :HKCU Default_Page_URL="" [Current Home Page] :HKLM Start Page=http://go.microsoft.com/fwlink/p/?LinkId=255141 [Current Home Page] :HKLM HOMEOldSP="" [All Users Search] :HKLM Default_Search_URL=http://go.microsoft.com/fwlink/?LinkId=54896 [All Users Search] :HKLM Search Page=http://go.microsoft.com/fwlink/?LinkId=54896 [Current Home Page(x64)] :HKLM Start Page=http://go.microsoft.com/fwlink/p/?LinkId=255141 [Current Home Page(x64)] :HKLM HOMEOldSP="" [All Users Search(x64)] :HKLM Default_Search_URL=http://go.microsoft.com/fwlink/?LinkId=54896 [All Users Search(x64)] :HKLM Search Page=http://go.microsoft.com/fwlink/?LinkId=54896 [Current Users Search] :HKCU Default_Search_URL="" [Current Users Search] :HKCU Search Page=http://go.microsoft.com/fwlink/?LinkId=54896 [Current Users Search] :HKCU Search Bar="" [IE Local Blank Page] :HKCU Local Page=%11%\blank.htm [IE Local Blank Page] :HKLM Local Page=C:\Windows\SysWOW64\blank.htm [Browser Helper Objects] {1FD49718-1D00-4B19-AF5F-070AF6D5D54C}=C:\PROGRAM FILES (X86)\MICROSOFT\EDGE\APPLICATION\91.0.864.48\BHO\IE_TO_EDGE_BHO.DLL ### IEToEdge BHO Microsoft Corporation IEToEdge BHO 91.0.864.48 ->IE_TO_EDGE_BHO_DLL !$*C:\Program Files (x86)\Microsoft\Edge\Application\91.0.864.48\BHO\ie_to_edge_bho.dll [Browser Helper Objects(x64)] {1FD49718-1D00-4B19-AF5F-070AF6D5D54C}=C:\PROGRAM FILES (X86)\MICROSOFT\EDGE\APPLICATION\91.0.864.48\BHO\IE_TO_EDGE_BHO_64.DLL ### IEToEdge BHO Microsoft Corporation IEToEdge BHO 91.0.864.48 ->IE_TO_EDGE_BHO_64_DLL !$*C:\Program Files (x86)\Microsoft\Edge\Application\91.0.864.48\BHO\ie_to_edge_bho_64.dll [Browser Helper Objects(x64)] {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\PROGRAM FILES\JAVA\JRE1.8.0_291\BIN\SSV.DLL ### Java(TM) Platform SE binary Oracle Corporation Java(TM) Platform SE 8 U291 8.0.2910.10 !$*C:\Program Files\Java\jre1.8.0_291\bin\ssv.dll [Browser Helper Objects(x64)] {DBC80044-A445-435b-BC74-9C25C1C588A9}=C:\PROGRAM FILES\JAVA\JRE1.8.0_291\BIN\JP2SSV.DLL ### Java(TM) Platform SE binary Oracle Corporation Java(TM) Platform SE 8 U291 8.0.2910.10 !$*C:\Program Files\Java\jre1.8.0_291\bin\jp2ssv.dll [Auto Search URL] :HKCU provider="" [Auto Search URL] :HKCU "Default Value"="" [Search Assistant] :HKCU SearchAssistant="" [Search Assistant] :HKLM SearchAssistant="" [Search Assistant] :HKCU CustomizeSearch="" [Search Assistant] :HKLM CustomizeSearch="" [Search Provider] {0633EE93-D776-472f-A0FF-E1416B8B2E3A}=http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02 ### Bing [Search Provider] DefaultScope={0633EE93-D776-472f-A0FF-E1416B8B2E3A} [Search Provider for All Users] {0633EE93-D776-472f-A0FF-E1416B8B2E3A}=http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC ### Bing [Search Provider for All Users] DefaultScope={0633EE93-D776-472f-A0FF-E1416B8B2E3A} [Search Provider for All Users(x64)] {0633EE93-D776-472f-A0FF-E1416B8B2E3A}=http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC ### Bing [Search Provider for All Users(x64)] DefaultScope={0633EE93-D776-472f-A0FF-E1416B8B2E3A} [Search Provider(x64)] {0633EE93-D776-472f-A0FF-E1416B8B2E3A}=http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02 ### Bing [Search Provider(x64)] DefaultScope={0633EE93-D776-472f-A0FF-E1416B8B2E3A} [CustomizeSearch] :HKLM CustomizeSearch="" [URLSearchHook] :HKCU {CFBFAE00-17A6-11D0-99CB-00C04FD64497}="" [Search URL Template] :HKLM 1="" [Search URL Template] :HKLM 2="" [Search URL Template] :HKLM 3="" [Search URL Template] :HKLM 4="" [Default Prefix] :HKLM "Default Value"=http:// [URL Default Prefixes] :HKLM ftp=ftp:// [URL Default Prefixes] :HKLM home=http:// [URL Default Prefixes] :HKLM mosaic=http:// [URL Default Prefixes] :HKLM www=http:// [AboutURLs] :HKLM blank=res://mshtml.dll/blank.htm [AboutURLs] :HKLM DesktopItemNavigationFailure=res://ieframe.dll/navcancl.htm [AboutURLs] :HKLM Home=270 [AboutURLs] :HKLM InPrivate=res://ieframe.dll/inprivate.htm [AboutURLs] :HKLM NavigationCanceled=res://ieframe.dll/navcancl.htm [AboutURLs] :HKLM NavigationFailure=res://ieframe.dll/navcancl.htm [AboutURLs] :HKLM NoAdd-ons=res://ieframe.dll/noaddon.htm [AboutURLs] :HKLM NoAdd-onsInfo=res://ieframe.dll/noaddoninfo.htm [AboutURLs] :HKLM PostNotCached=res://ieframe.dll/repost.htm [AboutURLs] :HKLM SecurityRisk=res://ieframe.dll/securityatrisk.htm [Registry IE Policy] :HKLM \Software\Policies\Microsoft\Internet Explorer\Control Panel\Connection Settings=0 [Registry IE Policy] :HKLM \Software\Policies\Microsoft\Internet Explorer\Main\DisableFirstRunCustomize=0 [User Style Sheet] :HKCU User Stylesheet="" [User Style Sheet] :HKCU Use My Stylesheet=0 [Execute unsigned ActiveX in My Computer Zone] :HKCU 1201=0 [Execute unsigned ActiveX in My Computer Zone] :HKLM 1201=1 [Execute unsigned ActiveX in Local Intranet Zone] :HKCU 1201=0 [Execute unsigned ActiveX in Local Intranet Zone] :HKLM 1201=3 [Execute unsigned ActiveX in Internet Zone] :HKCU 1201=3 [Execute unsigned ActiveX in Internet Zone] :HKLM 1201=3 [Links Toolbar] :HKCU LinksFolderName="" [AutoConfigURL] :HKCU AutoConfigURL="" [Protocols Filter] :HKLM application/octet-stream={1E66F26B-79EE-11D2-8710-00C04F79ED0D} [Protocols Filter] :HKLM application/x-complus={1E66F26B-79EE-11D2-8710-00C04F79ED0D} [Protocols Filter] :HKLM application/x-msdownload={1E66F26B-79EE-11D2-8710-00C04F79ED0D} [Protocols Handler] :HKLM about [Protocols Handler] :HKLM cdl={3dd53d40-7b8b-11D0-b013-00aa0059ce02} [Protocols Handler] :HKLM dvd={3dd53d40-7b8b-11D0-b013-00aa0059ce02} [Protocols Handler] :HKLM file={79eac9e7-baf9-11ce-8c82-00aa004ba90b} [Protocols Handler] :HKLM ftp={79eac9e3-baf9-11ce-8c82-00aa004ba90b} [Protocols Handler] :HKLM http={79eac9e2-baf9-11ce-8c82-00aa004ba90b} [Protocols Handler] :HKLM https={79eac9e5-baf9-11ce-8c82-00aa004ba90b} [Protocols Handler] :HKLM its={79eac9e5-baf9-11ce-8c82-00aa004ba90b} [Protocols Handler] :HKLM javascript={3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} [Protocols Handler] :HKLM local={79eac9e7-baf9-11ce-8c82-00aa004ba90b} [Protocols Handler] :HKLM mailto={3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} [Protocols Handler] :HKLM mhtml={3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} [Protocols Handler] :HKLM mk={79eac9e6-baf9-11ce-8c82-00aa004ba90b} [Protocols Handler] :HKLM ms-its={79eac9e6-baf9-11ce-8c82-00aa004ba90b} [Protocols Handler] :HKLM res={3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} [Protocols Handler] :HKLM tbauth={3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} [Protocols Handler] :HKLM tv={3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} [Protocols Handler] :HKLM vbscript={3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} [Protocols Handler] :HKLM windows.tbauth={3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} [Proxy] :HKCU ProxyServer="" [Proxy] :HKCU ProxyEnable=0 [Network Settings] [Name Server] {1c1e6a49-1174-4d21-b6e1-d7536e8d43e6}=8.8.8.8 ### DHCPNameServer:8.8.8.8 [Name Server] {4232e637-55f9-41ac-9ab1-41ebbab31ee9}=192.168.1.1 ### DHCPNameServer:192.168.1.1 [Name Server] {6d677394-e907-45d6-8e4d-0df41d651a85}=192.168.1.254 ### DHCPNameServer:192.168.1.254 [Name Server] {f1b71706-436b-4b66-a27e-b144dbcb62a9}=192.168.1.1 ### DHCPNameServer:192.168.1.1 DhcpDefaultGateway:192.168.1.1 DhcpServer:192.168.1.1 [Hosts File Path] :HKLM DataBasePath=%SystemRoot%\System32\drivers\etc [Disabled Remote Desktop] :HKLM fDenyTSConnections=1 [Allow Remote Assistantance] :HKLM fAllowToGetHelp=1 [Hosts File Contents] :HKLM 0.0.0.0 hss.hsselite.com [Hosts File Contents] :HKLM 0.0.0.0 www.hss.hsselite.com [Hosts File Contents] :HKLM 0.0.0.0 d1v9mrqde8r3oj.cloudfront.net [Hosts File Contents] :HKLM 0.0.0.0 www.d1v9mrqde8r3oj.cloudfront.net [Hosts File Contents] :HKLM 0.0.0.0 api.hsselite.com [Hosts File Contents] :HKLM 0.0.0.0 www.api.hsselite.com [Hosts File Contents] :HKLM 0.0.0.0 hsselite.com/trial/step2.php [Hosts File Contents] :HKLM 0.0.0.0 www.hsselite.com/trial/step2.php [Hosts File Contents] :HKLM 0.0.0.0 anchorfree.com [Hosts File Contents] :HKLM 0.0.0.0 www.anchorfree.com [Hosts File Contents] :HKLM 0.0.0.0 box.anchorfree.net [Hosts File Contents] :HKLM 0.0.0.0 www.box.anchorfree.net [Hosts File Contents] :HKLM 0.0.0.0 rpt.anchorfree.net [Hosts File Contents] :HKLM 0.0.0.0 www.rpt.anchorfree.net [Hosts File Contents] :HKLM 0.0.0.0 123.box.anchorfree.net [Hosts File Contents] :HKLM 0.0.0.0 www.123.box.anchorfree.net [Hosts File Contents] :HKLM 0.0.0.0 anchorfree.us [Hosts File Contents] :HKLM 0.0.0.0 www.anchorfree.us [Hosts File Contents] :HKLM 0.0.0.0 delivery.anchorfree.us/land.php [Hosts File Contents] :HKLM 0.0.0.0 www.delivery.anchorfree.us/land.php [Hosts File Contents] :HKLM 0.0.0.0 rss2search.com [Hosts File Contents] :HKLM 0.0.0.0 www.rss2search.com [Hosts File Contents] :HKLM 0.0.0.0 mefeedia.com [Hosts File Contents] :HKLM 0.0.0.0 www.mefeedia.com [Hosts File Contents] :HKLM 0.0.0.0 a433.com [Hosts File Contents] :HKLM 0.0.0.0 www.a433.com [Hosts File Contents] :HKLM 0.0.0.0 techbrowsing.com [Hosts File Contents] :HKLM 0.0.0.0 www.techbrowsing.com [Hosts File Contents] :HKLM 0.0.0.0 techbrowsing.com/away.php [Hosts File Contents] :HKLM 0.0.0.0 www.techbrowsing.com/away.php [Hosts File Contents] :HKLM 0.0.0.0 update.mydati.com [Hosts File Contents] :HKLM 0.0.0.0 www.update.mydati.com [Hosts File Contents] :HKLM 0.0.0.0 mydati.com [Hosts File Contents] :HKLM 0.0.0.0 www.mydati.com [Hosts File Contents] :HKLM 0.0.0.0 geo.mydati.com [Hosts File Contents] :HKLM 0.0.0.0 www.geo.mydati.com [Hosts File Contents] :HKLM 0.0.0.0 updateeu.mydati.com [Hosts File Contents] :HKLM 0.0.0.0 www.updateeu.mydati.com [Hosts File Contents] :HKLM 0.0.0.0 east.mydati.com [Hosts File Contents] :HKLM 0.0.0.0 www.east.mydati.com [Hosts File Contents] :HKLM 0.0.0.0 west.mydati.com [Hosts File Contents] :HKLM 0.0.0.0 www.west.mydati.com [Hosts File Contents] :HKLM 0.0.0.0 us.mydati.com [Hosts File Contents] :HKLM 0.0.0.0 www.us.mydati.com [Hosts File Contents] :HKLM 0.0.0.0 eu.mydati.com [Hosts File Contents] :HKLM 0.0.0.0 www.eu.mydati.com [Hosts File Contents] :HKLM 0.0.0.0 myd3.mydati.com [Hosts File Contents] :HKLM 0.0.0.0 www.myd3.mydati.com [Hosts File Contents] :HKLM 0.0.0.0 ns2.mydati.com [Hosts File Contents] :HKLM 0.0.0.0 www.ns2.mydati.com [Hosts File Contents] :HKLM 0.0.0.0 ns1.mydati.com [Hosts File Contents] :HKLM 0.0.0.0 www.ns1.mydati.com [Browsers] [Installed Browsers] Brave=C:\PROGRAM FILES\BRAVESOFTWARE\BRAVE-BROWSER\APPLICATION\BRAVE.EXE ### Default Browser Brave Browser Brave Software, Inc. Brave Browser 91.1.25.73 ->BRAVE_EXE !$*C:\PROGRAM FILES\BRAVESOFTWARE\BRAVE-BROWSER\APPLICATION\BRAVE.EXE [Installed Browsers] IEXPLORE.EXE=C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE ### Internet Explorer Microsoft Corporation Internet Explorer 11.00.19041.1 !$*C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE [Installed Browsers] Microsoft Edge=C:\PROGRAM FILES (X86)\MICROSOFT\EDGE\APPLICATION\MSEDGE.EXE ### Microsoft Edge Microsoft Corporation Microsoft Edge 91.0.864.48 ->MSEDGE_EXE !$*C:\PROGRAM FILES (X86)\MICROSOFT\EDGE\APPLICATION\MSEDGE.EXE [FireFox Settings] :HKLM browser.startup.homepage="" [FireFox Settings] :HKLM browser.startup.homepage_override_url="" [FireFox Settings] :HKLM browser.search.selectedEngine="" [FireFox Settings] :HKLM browser.search.selectedEngine,S="" [FireFox Settings] :HKLM browser.search.defaultEnginename="" [FireFox Settings] :HKLM browser.search.defaultEnginename,S="" [FireFox Settings] :HKLM browser.search.order.1="" [FireFox Settings] :HKLM browser.search.order.1,S="" [FireFox Settings] :HKLM browser.search.defaulturl="" [FireFox Settings] :HKLM browser.newtab.url="" [FireFox Settings] :HKLM keyword.URL="" [FireFox Settings] :HKLM network.proxy.autoconfig_url="" [FireFox Settings] :HKLM network.proxy.type="" [FireFox Settings] :HKLM network.proxy.http="" [FireFox Settings] :HKLM network.proxy.http_port="" [FireFox Settings] :HKLM browser.search.searchengine.hp="" [FireFox Settings] :HKLM browser.search.searchengine.sp="" [FireFox Settings] :HKLM browser.search.searchengine.url="" [FireFox Settings] :HKLM browser.search.selectedEngine="" [Firefox Search Engine (search-metadata)] :HKLM [global].searchdefault="" [Firefox Search Engine (search-metadata)] :HKLM [global].current="" [Firefox SearchDefault (mozlz4)] :HKLM metaData.searchDefault="" [Firefox SearchDefault (mozlz4)] :HKLM metaData.current="" [Google Chrome Settings] :HKLM backup.homepage="" [Google Chrome Settings] :HKLM backup.session.urls_to_restore_on_startup="" [Google Chrome Settings] :HKLM session.startup_urls="" [Google Chrome Settings] :HKLM default_search_provider_data.favicon_url="" [Google Chrome Settings] :HKLM default_search_provider_data.keyword="" [Google Chrome Settings] :HKLM default_search_provider_data.short_name="" [Google Chrome Settings] :HKLM default_search_provider_data.url="" [Google Chrome Settings] :HKLM default_search_provider_data.suggestions_url="" [Google Chrome Settings] :HKLM default_search_provider_data.template_url_data.alternate_urls="" [Google Chrome Settings] :HKLM default_search_provider_data.template_url_data.favicon_url="" [Google Chrome Settings] :HKLM default_search_provider_data.template_url_data.keyword="" [Google Chrome Settings] :HKLM default_search_provider_data.template_url_data.short_name="" [Google Chrome Settings] :HKLM default_search_provider_data.template_url_data.url="" [Google Chrome Settings] :HKLM default_search_provider_data.template_url_data.suggest_url="" [Google Chrome Settings] :HKLM default_search_provider_data.template_url_data.new_tab_url="" [Google Chrome Settings] :HKLM default_search_provider_data.template_url_data.instant_url="" [Google Chrome Settings] :HKLM default_search_provider_data.template_url_data.image_url="" [Google Chrome Settings] :HKLM homepage="" [Google Chrome Settings] :HKLM session.urls_to_restore_on_startup="" [Google Chrome Addons] felcaaldnbdncclmgdcncolpebgiejap=C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap ### Sheets: Créez et modifiez des feuilles de calcul update_url: https://clients2.google.com/service/update2/crx [Google Chrome Addons] pjkljhegncpnkpknbcohdijeoejaedia=C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia ### Gmail: Profitez d'une messagerie rapide, avec moins de spam et dotée d'une fonction de recherche. update_url: https://clients2.google.com/service/update2/crx [Google Chrome Addons] ahfgeienlihckogmohjhadlkjgocpleb=C:\Program Files\Google\Chrome\Application\88.0.4324.190\resources\web_store ### Web Store: Découvrez des applications, des jeux, des extensions et des thèmes exceptionnels pour Google Chrome. [Google Chrome Addons] aapocclcgogkmnckokdopfmhonfmgoek=C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek ### Slides: Créez et modifiez des présentations update_url: https://clients2.google.com/service/update2/crx [Google Chrome Addons] aohghmighlieiainnegkcijnfilokake=C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake ### Docs: Créez et modifiez des documents update_url: https://clients2.google.com/service/update2/crx [Google Chrome Addons] kmendfapggjehodndflmmgagdbamhnfd=C:\Program Files\Google\Chrome\Application\88.0.4324.190\resources\cryptotoken ### CryptoTokenExtension: CryptoToken Component Extension [Google Chrome Addons] mhjfbmdgcfjbbpaeojofohoefgiehjai=C:\Program Files\Google\Chrome\Application\88.0.4324.190\resources\pdf ### Chrome PDF Viewer: [Google Chrome Addons] apdfllckaahabafndbhieahigkjlhalf=C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf ### Google Drive: Google Drive : votre nouvel espace pour créer, stocker et partager update_url: https://clients2.google.com/service/update2/crx [Google Chrome Addons] neajdppkdcdipfabeoofebfddakdcjhd=C:\Program Files\Google\Chrome\Application\88.0.4324.190\resources\network_speech_synthesis ### Google Network Speech: Component extension providing speech via the Google network text-to-speech service. [Google Chrome Addons] nkeimhogjdpnpccoofpliimaahmaaome=C:\Program Files\Google\Chrome\Application\88.0.4324.190\resources\hangout_services ### Google Hangouts: [Google Chrome Addons] ghbmnnjooekpmoecnnnilnnbdlolhkhi=C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi ### Google Docs hors connexion: Modifiez, créez et consultez des documents, feuilles de calcul et présentations, sans accès à Internet. update_url: https://clients2.google.com/service/update2/crx [Google Chrome Addons] gfdkimpbcpahaombhbimeihdjnejgicl=C:\Program Files\Google\Chrome\Application\88.0.4324.190\resources\feedback ### Commentaires: Envoyer des commentaires à Google [Google Chrome Addons] mfehgcgbbipciphmccgaenjidiccnmng=C:\Program Files\Google\Chrome\Application\88.0.4324.190\resources\cloud_print ### Cloud Print: Cloud Print [Google Chrome Addons] pkedcjkdefgpdelpbcmbmeomcjbeemfm=C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm ### Chrome Media Router: Provider for discovery and services for mirroring of Chrome Media Router update_url: https://clients2.google.com/service/update2/crx [Google Chrome Addons] nmmhkkegccagdldgiimedpiccmgmieda=C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda ### Paiements via le Chrome Web Store: Paiements via le Chrome Web Store update_url: https://clients2.google.com/service/update2/crx [Google Chrome Addons] blpcfgokakmgnkcojhhkbfbldkacnbeo=C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo ### YouTube: update_url: http://clients2.google.com/service/update2/crx [Microsoft Edge Home Page] :HKCU ProtectedHomepages=about:start [Registry Chrome Policy] :HKLM \Software\Policies\Google\Chrome\ChromeCleanupEnabled=0 [Registry Chrome Policy] :HKLM \Software\Policies\Google\Chrome\ChromeCleanupReportingEnabled=0 [Network Settings] [Domain Name] :HKLM Domain="" [WinSock2 Components] napinsp.dll=C:\WINDOWS\SYSWOW64\NAPINSP.DLL ### Fournisseur Shim d’affectation de noms de messagerie Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\SYSWOW64\napinsp.dll [WinSock2 Components] pnrpnsp.dll=C:\WINDOWS\SYSWOW64\PNRPNSP.DLL ### Fournisseur d’espace de noms PNRP Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\SYSWOW64\pnrpnsp.dll [WinSock2 Components] wshbth.dll=C:\WINDOWS\SYSWOW64\WSHBTH.DLL ### Windows Sockets Helper DLL Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.546 !$*%SystemRoot%\SYSWOW64\wshbth.dll [WinSock2 Components] NLAapi.dll=C:\WINDOWS\SYSWOW64\NLAAPI.DLL ### Network Location Awareness 2 Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.546 !$*%SystemRoot%\SYSWOW64\NLAapi.dll [WinSock2 Components] mswsock.dll=C:\WINDOWS\SYSWOW64\MSWSOCK.DLL ### Fournisseur de service Sockets 2.0 de Microsoft Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\SYSWOW64\mswsock.dll [WinSock2 Components] winrnr.dll=C:\WINDOWS\SYSWOW64\WINRNR.DLL ### LDAP RnR Provider DLL Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.546 !$*%SystemRoot%\SYSWOW64\winrnr.dll [WinSock2 Components (x64)] napinsp.dll=C:\WINDOWS\SYSNATIVE\NAPINSP.DLL ### Fournisseur Shim d’affectation de noms de messagerie Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.1 !$*%SystemRoot%\SYSNATIVE\napinsp.dll [WinSock2 Components (x64)] pnrpnsp.dll=C:\WINDOWS\SYSNATIVE\PNRPNSP.DLL ### Fournisseur d’espace de noms PNRP Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.1 !$*%SystemRoot%\SYSNATIVE\pnrpnsp.dll [WinSock2 Components (x64)] wshbth.dll=C:\WINDOWS\SYSNATIVE\WSHBTH.DLL ### Windows Sockets Helper DLL Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.546 !$*%SystemRoot%\SYSNATIVE\wshbth.dll [WinSock2 Components (x64)] NLAapi.dll=C:\WINDOWS\SYSNATIVE\NLAAPI.DLL ### Network Location Awareness 2 Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1023 !$*%SystemRoot%\SYSNATIVE\NLAapi.dll [WinSock2 Components (x64)] mswsock.dll=C:\WINDOWS\SYSNATIVE\MSWSOCK.DLL ### Fournisseur de service Sockets 2.0 de Microsoft Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.1 !$*%SystemRoot%\SYSNATIVE\mswsock.dll [WinSock2 Components (x64)] winrnr.dll=C:\WINDOWS\SYSNATIVE\WINRNR.DLL ### LDAP RnR Provider DLL Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.546 !$*%SystemRoot%\SYSNATIVE\winrnr.dll [Windows Shell] [Display Scrap's Extensions] :HKLM NeverShowExt="" [ScreenSaver] :HKCU SCRNSAVE.EXE="" [System.ini] shell=explorer.exe ### Explorateur Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.1023 !$*explorer.exe [User Shell] :HKCU shell="" [Internet Shortcuts] :HKLM C:\ProgramData\Microsoft\Windows\Start Menu\Oculus\Oculus Support.lnk=HTTPS://SUPPORT.OCULUS.COM/ ### C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Oculus\OCULUS~1.LNK [Internet Shortcuts] :HKLM C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Electronic Arts\L'Avènement du Roi-sorcier™\Visiter le site officiel.lnk=HTTP://WWW.LESEIGNEURDESANNEAUX.EA.COM/ ### C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\ELECTR~1\L'AVNE~1\VISITE~1.LNK [Internet Shortcuts] :HKLM C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Electronic Arts\La Bataille pour la Terre du Milieu™ II\Visiter le site officiel.lnk=HTTP://WWW.LESEIGNEURDESANNEAUX.EA.COM/ ### C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\ELECTR~1\LABATA~1\VISITE~1.LNK [User Shortcuts] :HKLM C:\Users\user\Desktop\Applications\AOMEI Partition Assistant 9.1.lnk=C:\PROGRAM FILES (X86)\AOMEI PARTITION ASSISTANT\PARTASSIST.EXE ### AOMEI Partition Assistant AOMEI Technology Co., Ltd. AOMEI Partition Assistant 9.1.0 ->PA.EXE !$*C:\Program Files (x86)\AOMEI Partition Assistant\PartAssist.exe!$*C:\Users\user\Desktop\APPLIC~1\AOMEIP~1.LNK [User Shortcuts] :HKLM C:\Users\user\Desktop\Applications\Brave.lnk=C:\PROGRAM FILES\BRAVESOFTWARE\BRAVE-BROWSER\APPLICATION\BRAVE.EXE ### Brave Browser Brave Software, Inc. Brave Browser 91.1.25.73 ->BRAVE_EXE !$*C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe!$*C:\Users\user\Desktop\APPLIC~1\Brave.lnk [User Shortcuts] :HKLM C:\Users\user\Desktop\Applications\DAEMON Tools Lite.lnk=C:\PROGRAM FILES\DAEMON TOOLS LITE\DTLITE.EXE ### DAEMON Tools Lite Disc Soft Ltd DAEMON Tools Lite 10.14.0.1709 !$*C:\Program Files\DAEMON Tools Lite\DTLite.exe!$*C:\Users\user\Desktop\APPLIC~1\DAEMON~1.LNK [User Shortcuts] :HKLM C:\Users\user\Desktop\Applications\Discord.lnk=C:\USERS\USER\APPDATA\LOCAL\DISCORD\UPDATE.EXE ### Update GitHub Update 1.1.1.0 !$*C:\Users\user\AppData\Local\Discord\Update.exe!$*C:\Users\user\Desktop\APPLIC~1\Discord.lnk ?--processStart Discord.exe [User Shortcuts] :HKLM C:\Users\user\Desktop\Applications\DriversCloud.com - Démarrer la détection.lnk=C:\PROGRAM FILES\DRIVERSCLOUD.COM\DRIVERSCLOUD.EXE ### DriversCloud.com start detection CybelSoft DriversCloud.com 10.1.1.1 !$*C:\Program Files\DriversCloud.com\DriversCloud.exe!$*C:\Users\user\Desktop\APPLIC~1\DRIVER~1.LNK [User Shortcuts] :HKLM C:\Users\user\Desktop\Applications\GeForce Experience.lnk=C:\PROGRAM FILES\NVIDIA CORPORATION\NVIDIA GEFORCE EXPERIENCE\NVIDIA GEFORCE EXPERIENCE.EXE ### NVIDIA GeForce Experience NVIDIA Corporation NVIDIA GeForce Experience rel_03_22/c97700a !$*C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe!$*C:\Users\user\Desktop\APPLIC~1\GEFORC~1.LNK [User Shortcuts] :HKLM C:\Users\user\Desktop\Applications\Hotspot Shield.lnk=C:\PROGRAM FILES (X86)\HOTSPOT SHIELD\BIN\HSSCP.EXE ### Hotspot Shield AnchorFree Inc. Hotspot Shield 9.21.3.11422 !$*C:\Program Files (x86)\Hotspot Shield\bin\hsscp.exe!$*C:\Users\user\Desktop\APPLIC~1\HOTSPO~1.LNK ?-CONNECT [User Shortcuts] :HKLM C:\Users\user\Desktop\Applications\Malwarebytes.lnk=C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\MBAM.EXE ### Malwarebytes Malwarebytes Malwarebytes !$*C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe!$*C:\Users\user\Desktop\APPLIC~1\MALWAR~1.LNK [User Shortcuts] :HKLM C:\Users\user\Desktop\Applications\NETGEAR A7000 Genie.lnk=C:\PROGRAM FILES (X86)\NETGEAR\A7000\RESTART.EXE ### ReStart MFC Application Realtek ReStart Application 500, 1001, 719, 2007 !$*C:\Program Files (x86)\NETGEAR\A7000\ReStart.exe!$*C:\Users\user\Desktop\APPLIC~1\NETGEA~1.LNK ?/1 [User Shortcuts] :HKLM C:\Users\user\Desktop\Applications\NVIDIA GeForce NOW.lnk=C:\USERS\USER\APPDATA\LOCAL\NVIDIA CORPORATION\GEFORCENOW\CEF\GEFORCENOW.EXE ### NVIDIA GeForce NOW NVIDIA Corporation NVIDIA GeForce NOW 2.0.28.140 !$*C:\Users\user\AppData\Local\NVIDIA Corporation\GeForceNOW\CEF\GeForceNOW.exe!$*C:\Users\user\Desktop\APPLIC~1\NVIDIA~1.LNK [User Shortcuts] :HKLM C:\Users\user\Desktop\Applications\Overclocking\MSI Afterburner.lnk=D:\PROGRAM FILES (X86)\MSI AFTERBURNER\MSIAFTERBURNER.EXE ### MSIAfterburner MSIAfterburner 4, 6, 3, 16094 !$*D:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe!$*C:\Users\user\Desktop\APPLIC~1\OVERCL~1\MSIAFT~1.LNK [User Shortcuts] :HKLM C:\Users\user\Desktop\Applications\TeamViewer.lnk=C:\PROGRAM FILES\TEAMVIEWER\TEAMVIEWER.EXE ### TeamViewer TeamViewer Germany GmbH TeamViewer 15.16.8.0 !$*C:\Program Files\TeamViewer\TeamViewer.exe!$*C:\Users\user\Desktop\APPLIC~1\TEAMVI~1.LNK [User Shortcuts] :HKLM C:\Users\user\Desktop\Applications\VLC media player.lnk=C:\PROGRAM FILES\VIDEOLAN\VLC\VLC.EXE ### VLC media player VideoLAN VLC media player 3,0,11,0 !$*C:\Program Files\VideoLAN\VLC\vlc.exe!$*C:\Users\user\Desktop\APPLIC~1\VLCMED~1.LNK [User Shortcuts] :HKLM C:\Users\user\Desktop\Assistant Mise à jour de Windows 10.lnk=C:\WINDOWS10UPGRADE\WINDOWS10UPGRADERAPP.EXE ### Assistant Mise à jour de Windows 10 Microsoft Corporation Assistant Mise à jour de Windows 10 1.4.9200.23367 ->WINDOWS10UPGRADEAPP.EXE !$*C:\Windows10Upgrade\Windows10UpgraderApp.exe!$*C:\Users\user\Desktop\ASSIST~1.LNK [User Shortcuts] :HKLM C:\Users\user\Desktop\FurMark.lnk=D:\PROGRAM FILES (X86)\GEEKS3D\BENCHMARKS\FURMARK\FURMARK.EXE ### FurMark - GPU stress test and OpenGL benchmark Geeks3D (geeks3d.com) FurMark 1.26.0.0 !$*D:\Program Files (x86)\Geeks3D\Benchmarks\FurMark\FurMark.exe!$*C:\Users\user\Desktop\FurMark.lnk [User Shortcuts] :HKLM C:\Users\user\Desktop\Jeux\Dragon Ball Xenoverse 2.lnk=D:\GAMES\DRAGON BALL XENOVERSE 2\BIN\DBXV2.EXE ### DRAGON BALL XENOVERSE 2 Bandai Namco Games Inc. DRAGON BALL XENOVERSE 2 1 !$*D:\Games\Dragon Ball Xenoverse 2\bin\DBXV2.exe!$*C:\Users\user\Desktop\Jeux\DRAGON~1.LNK [User Shortcuts] :HKLM C:\Users\user\Desktop\Jeux\Emulateurs\PS2\PCSX2 1.6.0.lnk=C:\PROGRAM FILES (X86)\PCSX2\PCSX2.EXE ### !$*C:\Program Files (x86)\PCSX2\pcsx2.exe!$*C:\Users\user\Desktop\Jeux\EMULAT~1\PS2\PCSX21~1.LNK [User Shortcuts] :HKLM C:\Users\user\Desktop\Jeux\Fallout 4 VR.lnk=D:\PROGRAM FILES (X86)\FALLOUT 4 VR\FALLOUT4VR.EXE ### Fallout 4 VR Bethesda Softworks Fallout 4 VR 1.2.72.0 ->INSTITUTE !$*D:\Program Files (x86)\Fallout 4 VR\Fallout4VR.exe!$*C:\Users\user\Desktop\Jeux\FALLOU~1.LNK [User Shortcuts] :HKLM C:\Users\user\Desktop\Jeux\Grand Theft Auto V.lnk=D:\PROGRAM FILES\ROCKSTAR GAMES\GRAND THEFT AUTO V\PLAYGTAV.EXE ### Rockstar Games Launcher Redirector Rockstar Games Rockstar Games Launcher Redirector 1.0.0.0 ->ROCKSTARREDIRECTOR.EXE !$*D:\Program Files\Rockstar Games\Grand Theft Auto V\PlayGTAV.exe!$*C:\Users\user\Desktop\Jeux\GRANDT~1.LNK [User Shortcuts] :HKLM C:\Users\user\Desktop\Jeux\Home Sweet Home.lnk=D:\PROGRAM FILES\HOME SWEET HOME\HOMESWEETHOME.EXE ### !$*D:\Program Files\Home Sweet Home\HomeSweetHome.exe!$*C:\Users\user\Desktop\Jeux\HOMESW~1.LNK [User Shortcuts] :HKLM C:\Users\user\Desktop\Jeux\Launchers\Epic Games Launcher.lnk=D:\PROGRAM FILES (X86)\EPIC GAMES\LAUNCHER\PORTAL\BINARIES\WIN32\EPICGAMESLAUNCHER.EXE ### UnrealEngineLauncherProxy Epic Games, Inc. Unreal Engine 1.11.0-16657426+++Portal+Release-Live ->UNREALENGINE =>UNREALENGINELAUNCHERPROXY-WIN32-SHIPPING.EXE !$*D:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win32\EpicGamesLauncher.exe!$*C:\Users\user\Desktop\Jeux\LAUNCH~1\EPICGA~1.LNK [User Shortcuts] :HKLM C:\Users\user\Desktop\Jeux\Launchers\GOG GALAXY.lnk=C:\PROGRAM FILES (X86)\GOG GALAXY\GALAXYCLIENT.EXE ### GOG Galaxy GOG.com GOG Galaxy 2.0.37.384 =>GALAXYCLIENT !$*C:\Program Files (x86)\GOG Galaxy\GalaxyClient.exe!$*C:\Users\user\Desktop\Jeux\LAUNCH~1\GOGGAL~1.LNK [User Shortcuts] :HKLM C:\Users\user\Desktop\Jeux\Launchers\Oculus.lnk=D:\OCULUS\SUPPORT\OCULUS-CLIENT\OCULUSCLIENT.EXE ### OculusClient.exe Oculus VR, LLC Oculus 0.1.0 ->OCULUS !$*D:\Oculus\Support\oculus-client\OculusClient.exe!$*C:\Users\user\Desktop\Jeux\LAUNCH~1\Oculus.lnk [User Shortcuts] :HKLM C:\Users\user\Desktop\Jeux\Launchers\Rockstar Games Launcher.lnk=D:\PROGRAM FILES\ROCKSTAR GAMES\LAUNCHER\LAUNCHERPATCHER.EXE ### Rockstar Games Launcher Patcher Rockstar Games Rockstar Games Launcher Patcher 1.0.0.13 !$*D:\Program Files\Rockstar Games\Launcher\LauncherPatcher.exe!$*C:\Users\user\Desktop\Jeux\LAUNCH~1\ROCKST~1.LNK [User Shortcuts] :HKLM C:\Users\user\Desktop\Jeux\Launchers\Steam.lnk=D:\STEAM\STEAM.EXE ### Steam Valve Corporation Steam 01.00.00.02 ->STEAM (BUILDBOT_STEAM-RELCLIENT-WIN32-BUILDER_STEAM_REL_CLIENT_WIN32@STEAM-RELCLIENT-WIN32-BUILDER) !$*D:\Steam\steam.exe!$*C:\Users\user\Desktop\Jeux\LAUNCH~1\Steam.lnk [User Shortcuts] :HKLM C:\Users\user\Desktop\Jeux\Mass Effect Ultimate Edition.lnk=D:\PROGRAM FILES (X86)\MASS EFFECT ULTIMATE EDITION\MASSEFFECTLAUNCHER.EXE ### Launcher Application BioWare Launcher Application 1.1.0.6 ->AUTORUN.EXE !$*D:\Program Files (x86)\Mass Effect Ultimate Edition\MassEffectLauncher.exe!$*C:\Users\user\Desktop\Jeux\MASSEF~1.LNK [User Shortcuts] :HKLM C:\Users\user\Desktop\Jeux\Red Dead Redemption 2.lnk=D:\PROGRAM FILES\ROCKSTAR GAMES\RED DEAD REDEMPTION 2\RDR2.EXE ### Red Dead Redemption 2 Rockstar Games Red Dead Redemption 2 1.0.1355.30 !$*D:\Program Files\Rockstar Games\Red Dead Redemption 2\RDR2.exe!$*C:\Users\user\Desktop\Jeux\REDDEA~1.LNK [User Shortcuts] :HKLM C:\Users\user\Desktop\Jeux\Roblox Player.lnk=C:\USERS\USER\APPDATA\LOCAL\ROBLOX\VERSIONS\VERSION-8D4EA819D4EC4CF1\ROBLOXPLAYERLAUNCHER.EXE ### Roblox Roblox Corporation Roblox Bootstrapper 1, 6, 1, 423489 =>ROBLOX.EXE !$*C:\Users\user\AppData\Local\Roblox\Versions\version-8d4ea819d4ec4cf1\RobloxPlayerLauncher.exe!$*C:\Users\user\Desktop\Jeux\ROBLOX~1.LNK ?-app [User Shortcuts] :HKLM C:\Users\user\Desktop\Jeux\Roblox Studio.lnk=C:\USERS\USER\APPDATA\LOCAL\ROBLOX\VERSIONS\ROBLOXSTUDIOLAUNCHERBETA.EXE ### Roblox Roblox Corporation Roblox Bootstrapper 1, 6, 1, 423489 =>ROBLOX.EXE !$*C:\Users\user\AppData\Local\Roblox\Versions\RobloxStudioLauncherBeta.exe!$*C:\Users\user\Desktop\Jeux\ROBLOX~2.LNK ?-ide [User Shortcuts] :HKLM C:\Users\user\Desktop\Jeux\The Elder Scrolls V Skyrim VR.lnk=D:\PROGRAM FILES (X86)\THE ELDER SCROLLS V SKYRIM VR\SKYRIMVR.EXE ### Skyrim VR Bethesda Softworks TESV: Skyrim VR 1.4.15.0 ->SKYRIM VR =>TESV.EXE !$*D:\Program Files (x86)\The Elder Scrolls V Skyrim VR\SkyrimVR.exe!$*C:\Users\user\Desktop\Jeux\THEELD~1.LNK [User Shortcuts] :HKLM C:\Users\user\Desktop\Jeux\The Witcher 3 - Wild Hunt - Game of the Year Edition.lnk=C:\PROGRAM FILES (X86)\GOG GALAXY\GALAXYCLIENT.EXE ### GOG Galaxy GOG.com GOG Galaxy 2.0.37.384 =>GALAXYCLIENT !$*C:\Program Files (x86)\GOG Galaxy\GalaxyClient.exe!$*C:\Users\user\Desktop\Jeux\THEWIT~1.LNK ?/command=runGame /gameId=1495134320 /path="D:\Games\GOG Galaxy\Games\The Witcher 3 Wild Hunt GOTY" [User Shortcuts] :HKLM C:\Users\user\Desktop\Reanimator.lnk=D:\PROGRAM FILES (X86)\GREATIS\REANIMATOR\REANIMATOR.EXE ### RegRun Start Control Greatis Software RegRun Security Suite 12.60 ->REGRUN2.EXE !$*D:\Program Files (x86)\Greatis\Reanimator\reanimator.exe!$*C:\Users\user\Desktop\REANIM~1.LNK [User Shortcuts] :HKLM C:\Users\Public\Desktop\LOOT.lnk=D:\PROGRAM FILES (X86)\LOOT\LOOT.EXE ### 0.16.1 !$*D:\Program Files (x86)\LOOT\LOOT.exe!$*C:\Users\Public\Desktop\LOOT.lnk [User Shortcuts] :HKLM C:\Users\Public\Desktop\Mod Organizer.lnk=D:\MODDING\MO2\MODORGANIZER.EXE ### Mod Organizer 2 GUI Mod Organizer 2 Team Mod Organizer 2 2.4.2 ->MODORGANIZER2 !$*D:\Modding\MO2\ModOrganizer.exe!$*C:\Users\Public\Desktop\MODORG~1.LNK [User Shortcuts] :HKLM C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Brave.lnk=C:\PROGRAM FILES\BRAVESOFTWARE\BRAVE-BROWSER\APPLICATION\BRAVE.EXE ### Brave Browser Brave Software, Inc. Brave Browser 91.1.25.73 ->BRAVE_EXE !$*C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe!$*C:\Users\user\AppData\Roaming\MICROS~1\INTERN~1\QUICKL~1\Brave.lnk [User Shortcuts] :HKLM C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Microsoft Edge.lnk=C:\PROGRAM FILES (X86)\MICROSOFT\EDGE\APPLICATION\MSEDGE.EXE ### Microsoft Edge Microsoft Corporation Microsoft Edge 91.0.864.48 ->MSEDGE_EXE !$*C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe!$*C:\Users\user\AppData\Roaming\MICROS~1\INTERN~1\QUICKL~1\MICROS~1.LNK [User Shortcuts] :HKLM C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Brave.lnk=C:\PROGRAM FILES\BRAVESOFTWARE\BRAVE-BROWSER\APPLICATION\BRAVE.EXE ### Brave Browser Brave Software, Inc. Brave Browser 91.1.25.73 ->BRAVE_EXE !$*C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe!$*C:\Users\user\AppData\Roaming\MICROS~1\INTERN~1\QUICKL~1\USERPI~1\TaskBar\Brave.lnk [User Shortcuts] :HKLM C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Discord.lnk=C:\USERS\USER\APPDATA\LOCAL\DISCORD\UPDATE.EXE ### Update GitHub Update 1.1.1.0 !$*C:\Users\user\AppData\Local\Discord\Update.exe!$*C:\Users\user\AppData\Roaming\MICROS~1\INTERN~1\QUICKL~1\USERPI~1\TaskBar\Discord.lnk ?--processStart Discord.exe [User Shortcuts] :HKLM C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk=C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\MBAM.EXE ### Malwarebytes Malwarebytes Malwarebytes !$*C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe!$*C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\MALWAR~1.LNK [User Shortcuts] :HKLM C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NETGEAR A7000 Genie\Uninstall NETGEAR A7000 Software.lnk=C:\PROGRAM FILES (X86)\INSTALLSHIELD INSTALLATION INFORMATION\{E34F424D-99BB-4176-8BCB-F0A749D744B4}\SETUP.EXE ### Setup Launcher Unicode NETGEAR NETGEAR A7000 Genie 1.0.0.15 =>INSTALLSHIELD SETUP.EXE !$*C:\Program Files (x86)\installshield installation information\{E34F424D-99BB-4176-8BCB-F0A749D744B4}\setup.exe!$*C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\NETGEA~1\UNINST~1.LNK [User Shortcuts] :HKLM C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Internet Explorer.lnk=C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE ### Internet Explorer Microsoft Corporation Internet Explorer 11.00.19041.1 !$*C:\Program Files\Internet Explorer\iexplore.exe!$*C:\Users\user\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\ACCESS~1\INTERN~1.LNK [Main File Extensions] :HKLM .exe="" [Main File Extensions] :HKLM .com="" [Main File Extensions] :HKLM .pif="" [Main File Extensions] :HKLM .bat="" [Main File Extensions] :HKLM .cmd="" [Main File Extensions] :HKLM .scr="" [Main File Extensions] :HKLM .txt="" [Main File Extensions] :HKLM .reg="" [Main File Extensions] :HKLM .inf="" [Main File Extensions] :HKLM .ini="" [Main File Extensions] :HKLM .js="" [Main File Extensions] :HKLM .vbs="" [Main File Extensions] :HKLM .vbe="" [Main File Extensions] :HKLM .msc="" [Main File Extensions] :HKLM .jpg="" [Main File Extensions] :HKLM .jpeg="" [Main File Extensions] :HKLM .gif="" [Main File Extensions] :HKLM .png="" [UserInit Value] UserInit="" [UserInit Value(x64)] UserInit=C:\Windows\system32\userinit.exe, ### Application d’ouverture de session Userinit Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\Windows\system32\userinit.exe [Shell Services DelayLoad] :HKLM WebCheck={E6FB5E20-DE35-11CF-9C87-00AA005127ED} [System Shell Policies] :HKCU shell="" [System Shell Policies] :HKLM shell="" [System Shell Policies] :HKCU run="" [System Shell Policies] :HKLM run="" [Prevents Display in Control Panel from running.] :HKCU NoDispCpl=0 [Disable Registry Tools] :HKCU DisableRegistryTools =0 [Users] :HKLM Administrateur=Administrator (Disabled) [Users] :HKLM danyp=User (Disabled) [Users] :HKLM DefaultAccount=Guest (Disabled) [Users] :HKLM elya-=User (Disabled) ### elya- [Users] :HKLM flavi=User (Disabled) [Users] :HKLM Invité=Guest (Disabled) ### Invit|C3|A9 [Users] :HKLM Kiro=Administrator [Users] :HKLM kirom=User (Disabled) [Users] :HKLM mel-e=User (Disabled) ### mel-e [Users] :HKLM WDAGUtilityAccount=Guest (Disabled) [Print Monitors] :HKLM Appmon=C:\WINDOWS\SYSTEM32\APPMON.DLL ### App Printer Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*AppMon.dll [Print Monitors] :HKLM Local Port=C:\WINDOWS\SYSTEM32\LOCALSPL.DLL ### DLL de spouleur local Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.1023 !$*localspl.dll [Print Monitors] :HKLM Microsoft Shared Fax Monitor=C:\WINDOWS\SYSTEM32\FXSMON.DLL ### Microsoft Fax Print Monitor Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.804 !$*FXSMON.DLL [Print Monitors] :HKLM Standard TCP/IP Port=C:\WINDOWS\SYSTEM32\TCPMON.DLL ### DLL moniteur de port standard TCP/IP Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*tcpmon.dll [Print Monitors] :HKLM USB Monitor=C:\WINDOWS\SYSTEM32\USBMON.DLL ### DLL du moniteur de port d’impression dynamique standard Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 ->DYNAMON.DLL =>DYNAMON.DLL.MUI !$*usbmon.dll [Print Monitors] :HKLM WSD Port=C:\WINDOWS\SYSTEM32\APMON.DLL ### Moniteur de port adaptatif Microsoft Corporation Système d'exploitation Microsoft® Windows® 10.0.19041.867 !$*APMon.dll [Shell Icon Overlay Handlers] :HKLM OneDrive1={BBACC218-34EA-4666-9D7A-C78F2274A524} [Shell Icon Overlay Handlers] :HKLM OneDrive2={5AB7172C-9C11-405C-8DD5-AF20F3606282} [Shell Icon Overlay Handlers] :HKLM OneDrive3={A78ED123-AB77-406B-9962-2A5D9D2F7F30} [Shell Icon Overlay Handlers] :HKLM OneDrive4={F241C880-6982-4CE5-8CF7-7085BA96DA5A} [Shell Icon Overlay Handlers] :HKLM OneDrive5={A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} [Shell Icon Overlay Handlers] :HKLM OneDrive6={9AA2F32D-362A-42D9-9328-24A483E2CCC3} [Shell Icon Overlay Handlers] :HKLM OneDrive7={C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} [Context Menu Handlers] :HKLM EPP={09A47860-11B0-4DA5-AFA5-26D86198A780} [Context Menu Handlers] :HKLM ModernSharing={e2bf9676-5f8f-435c-97eb-11607a5bedf7} [Context Menu Handlers] :HKLM Open With={09799AFB-AD67-11d1-ABCD-00C04FC30936} [Context Menu Handlers] :HKLM Open With EncryptionMenu={A470F8CF-A1E8-4f65-8335-227475AA5C46} [Context Menu Handlers] :HKLM Sharing={f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} [Context Menu Handlers] :HKLM WinRAR={B41DB860-64E4-11D2-9906-E49FADC173CA} [Context Menu Handlers] :HKLM WinRAR32=C:\PROGRAM FILES\WINRAR\RAREXT32.DLL ### WinRAR shell extension Alexander Roshal WinRAR 6.0.0 ->WINRAR SHELL EXTENSION =>RAREXT.DLL !$*C:\Program Files\WinRAR\rarext32.dll [Context Menu Handlers] :HKLM WorkFolders=C:\PROGRAM FILES\WINRAR\RAREXT32.DLL ### WinRAR shell extension Alexander Roshal WinRAR 6.0.0 ->WINRAR SHELL EXTENSION =>RAREXT.DLL !$*C:\Program Files\WinRAR\rarext32.dll [Context Menu Handlers] :HKLM {90AA3A4E-1CBA-4233-B8BB-535773D48449}={90AA3A4E-1CBA-4233-B8BB-535773D48449} [Context Menu Handlers] :HKLM {a2a9545d-a0c2-42b4-9708-a0b2badd77c8}={a2a9545d-a0c2-42b4-9708-a0b2badd77c8} [App Paths] :HKLM brave.exe=C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe ### brave.exe Brave Browser Brave Software, Inc. Brave Browser 91.1.25.73 ->BRAVE_EXE [App Paths] :HKLM cmmgr32.exe ### cmmgr32.exe [App Paths] :HKLM dfshim.dll ### dfshim.dll [App Paths] :HKLM fsquirt.exe ### fsquirt.exe [App Paths] :HKLM IEDIAG.EXE=C:\Program Files\Internet Explorer\IEDIAGCMD.EXE ### IEDIAG.EXE Diagnostics utility for Internet Explorer Microsoft Corporation Internet Explorer 11.00.19041.1 [App Paths] :HKLM IEDIAGCMD.EXE=C:\Program Files\Internet Explorer\IEDIAGCMD.EXE ### IEDIAGCMD.EXE Diagnostics utility for Internet Explorer Microsoft Corporation Internet Explorer 11.00.19041.1 [App Paths] :HKLM IEXPLORE.EXE=C:\Program Files\Internet Explorer\IEXPLORE.EXE ### IEXPLORE.EXE Internet Explorer Microsoft Corporation Internet Explorer 11.00.19041.1 [App Paths] :HKLM install.exe ### install.exe [App Paths] :HKLM javaws.exe=C:\Program Files\Java\jre1.8.0_291\bin\javaws.exe ### javaws.exe Java(TM) Web Start Launcher Oracle Corporation Java(TM) Platform SE 8 U291 8.0.2910.10 ->JAVA(TM) WEB START LAUNCHER [App Paths] :HKLM lotrbfme2.exe=G:\Games\BFME2\lotrbfme2.exe ### lotrbfme2.exe [App Paths] :HKLM lotrbfme2ep1.exe=G:\Games\BFME2WKe\lotrbfme2ep1.exe ### lotrbfme2ep1.exe [App Paths] :HKLM mplayer2.exe=%ProgramFiles(x86)%\Windows Media Player\wmplayer.exe ### mplayer2.exe [App Paths] :HKLM msedge.exe=C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe ### msedge.exe Microsoft Edge Microsoft Corporation Microsoft Edge 91.0.864.48 ->MSEDGE_EXE [App Paths] :HKLM pbrush.exe=%SystemRoot%\System32\mspaint.exe ### pbrush.exe [App Paths] :HKLM PowerShell.exe=%SystemRoot%\system32\WindowsPowerShell\v1.0\PowerShell.exe ### PowerShell.exe [App Paths] :HKLM setup.exe ### setup.exe [App Paths] :HKLM table30.exe ### table30.exe [App Paths] :HKLM vlc.exe=C:\Program Files\VideoLAN\VLC\vlc.exe ### vlc.exe VLC media player VideoLAN VLC media player 3,0,11,0 [App Paths] :HKLM wab.exe=%ProgramFiles%\Windows Mail\wab.exe ### wab.exe [App Paths] :HKLM wabmig.exe=%ProgramFiles%\Windows Mail\wabmig.exe ### wabmig.exe [App Paths] :HKLM WinRAR.exe=C:\Program Files\WinRAR\WinRAR.exe ### WinRAR.exe WinRAR archiver Alexander Roshal WinRAR 6.0.0 [App Paths] :HKLM wmplayer.exe=%ProgramFiles(x86)%\Windows Media Player\wmplayer.exe ### wmplayer.exe [App Paths] :HKLM WORDPAD.EXE=C:\Program Files\WINDOWS NT\ACCESSORIES\WORDPAD.EXE ### WORDPAD.EXE Application Windows Wordpad Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.1 !$*"%ProgramFiles%\Windows NT\Accessories\WORDPAD.EXE" [App Paths] :HKLM WRITE.EXE="%ProgramFiles%\Windows NT\Accessories\WORDPAD.EXE" ### WRITE.EXE [Kernel Auto Boot] [ActiveSetup] >{22d6f312-b0f6-11d0-94ab-0080c74c7e95}=C:\WINDOWS\SYSTEM32\UNREGMP2.EXE ### Utilitaire d’installation du Lecteur Windows Media de Microsoft Microsoft Corporation Système d’exploitation Microsoft® Windows® 12.0.19041.867 !$*%SystemRoot%\system32\unregmp2.exe /ShowWMP [Auto Services] :HKLM AarSvc ### Service: Agent Activation Runtime Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Runtime for activating conversational agent applications Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K AARSVCGROUP -P [Auto Services] :HKLM AarSvc_1a8ea6 ### Service: Agent Activation Runtime_1a8ea6 Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Runtime for activating conversational agent applications Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K AARSVCGROUP -P [Auto Services] :HKLM AJRouter ### Service: Service de routeur AllJoyn Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Achemine les messages AllJoyn pour les clients AllJoyn locaux. Si ce service est arrêté, les clients AllJoyn ne possédant pas leur propre routeur groupé ne peuvent pas s'exécuter. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICENETWORKRESTRICTED -P [Auto Services] :HKLM ALG ### Service: Service de la passerelle de la couche Application Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\System32\ALG.EXE * Fournit la prise en charge de plug-ins de protocole tiers pour le partage de connexion Internet Service de la passerelle de la couche Application Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\ALG.EXE [Auto Services] :HKLM AppIDSvc ### Service: Identité de l’application Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Détermine et vérifie l’identité d’une application. La désactivation de ce service empêchera l’application d’AppLocker. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICENETWORKRESTRICTED -P [Auto Services] :HKLM Appinfo ### Service: Informations d’application Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Permet d’exécuter les applications interactives avec des droits d’administration supplémentaires. Si ce service est arrêté, les utilisateurs ne pourront pas lancer les applications avec les droits d’administration supplémentaires nécessaires pour effectuer les tâches utilisateur souhaitées. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS -P [Auto Services] :HKLM AppReadiness ### Service: Préparation des applications Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Prépare les applications pour la première connexion d’un utilisateur sur cet ordinateur et lors de l’ajout de nouvelles applications. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K APPREADINESS -P [Auto Services] :HKLM AppXSvc ### Service: Service de déploiement AppX (AppXSVC) Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Assure la prise en charge de l’infrastructure pour le déploiement d’applications du Store. Ce service démarre à la demande. S’il est désactivé, les applications du Store ne sont pas déployées sur le système et peuvent ne pas fonctionner correctement. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K WSAPPX -P [Auto Services] :HKLM AudioEndpointBuilder ### Service: Générateur de points de terminaison du service Audio Windows Status: Start Type: loaded automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Gère les périphériques audio pour le service Audio Windows. Si ce service est arrêté, les périphériques et les effets audio ne fonctionnent pas correctement. Si ce service est désactivé, tous les services qui en dépendent explicitement ne peuvent pas démarrer. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED -P [Auto Services] :HKLM Audiosrv ### Service: Audio Windows Status: Start Type: loaded automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Gère les périphériques audio pour les programmes compatibles Windows. Si ce service est arrêté, les périphériques et les effets audio ne fonctionneront pas correctement. S’il est désactivé, les services qui en dépendent explicitement ne démarreront pas Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICENETWORKRESTRICTED -P [Auto Services] :HKLM autotimesvc ### Service: Heure cellulaire Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Ce service définit l'heure en fonction des messages NITZ à partir d'un réseau mobile. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K AUTOTIMESVC [Auto Services] :HKLM AxInstSV ### Service: Programme d’installation ActiveX (AxInstSV) Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Valide le contrôle de compte d’utilisateur pour l’installation des contrôles ActiveX depuis Internet et permet de gérer leur installation d’après les paramètres de la stratégie de groupe. Ce service est démarré sur demande et, s’il est désactivé, l’installation des contrôles ActiveX se comporte conformément aux paramètres par défaut du navigateur. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K AXINSTSVGROUP [Auto Services] :HKLM BcastDVRUserService ### Service: Service utilisateur de diffusion et GameDVR Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Ce service utilisateur est utilisé pour les enregistrements de jeu et les diffusions en direct Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K BCASTDVRUSERSERVICE [Auto Services] :HKLM BcastDVRUserService_1a8ea6 ### Service: Service utilisateur de diffusion et GameDVR_1a8ea6 Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Ce service utilisateur est utilisé pour les enregistrements de jeu et les diffusions en direct Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K BCASTDVRUSERSERVICE [Auto Services] :HKLM BDESVC ### Service: Service de chiffrement de lecteur BitLocker Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * BDESVC héberge le service de chiffrement de lecteur BitLocker. Le chiffrement de lecteur BitLocker fournit un démarrage sécurisé pour le système d’exploitation, ainsi qu’un chiffrement total du volume pour le système d’exploitation, les volumes fixes ou les volumes amovibles. Ce service permet à BitLocker d’inviter les utilisateurs à effectuer diverses actions liées aux volumes montés, et déverrouille les volumes automatiquement sans intervention de l’utilisateur. En outre, il stocke les informations de récupération dans Active Directory, s’il est disponible, et, si nécessaire, garantit que les certificats de récupération les plus récents sont utilisés. L’arrêt ou la désactivation du service empêche les utilisateurs de tirer parti de cette fonctionnalité. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS -P [Auto Services] :HKLM BEService ### Service: BattlEye Service Status: Start Type: loaded manually on demand Actual File: C:\PROGRAM FILES (X86)\COMMON FILES\BATTLEYE\BESERVICE.EXE * !$*"C:\PROGRAM FILES (X86)\COMMON FILES\BATTLEYE\BESERVICE.EXE" [Auto Services] :HKLM BFE ### Service: Moteur de filtrage de base Status: Start Type: loaded automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Le moteur de filtrage de base est un service qui gère les stratégies de pare-feu et de sécurité IP (IPsec), et qui implémente le filtrage en mode utilisateur. L’arrêt ou la désactivation du service Moteur de filtrage de base diminue significativement la sécurité du système et aboutit également à un fonctionnement imprévisible des applications de gestion et de pare-feu IPsec. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICENONETWORKFIREWALL -P [Auto Services] :HKLM BITS ### Service: Service de transfert intelligent en arrière-plan Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Transfère des fichiers en arrière-plan en utilisant la bande passante réseau inactive. Si le service est désactivé, toutes les applications dépendant du service de transfert intelligent d’arrière-plan, telles que Windows Update ou MSN Explorer, ne pourront plus télécharger des programmes ni d’autres informations. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS -P [Auto Services] :HKLM BluetoothUserService ### Service: Service de support des utilisateurs du Bluetooth Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Le service des utilisateurs du Bluetooth prend en charge le bon fonctionnement de fonctionnalités Bluetooth pertinentes pour chaque session utilisateur. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K BTHAPPGROUP -P [Auto Services] :HKLM BluetoothUserService_1a8ea6 ### Service: Service de support des utilisateurs du Bluetooth_1a8ea6 Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Le service des utilisateurs du Bluetooth prend en charge le bon fonctionnement de fonctionnalités Bluetooth pertinentes pour chaque session utilisateur. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K BTHAPPGROUP -P [Auto Services] :HKLM brave ### Service: Service Brave Update (brave) Status: Start Type: loaded automatically by Server Manager Actual File: C:\PROGRAM FILES (X86)\BRAVESOFTWARE\UPDATE\BRAVEUPDATE.EXE * Permet de maintenir votre logiciel Brave à jour. Si ce service est désactivé ou interrompu, votre logiciel Brave ne sera plus mis à jour. Toute faille de sécurité susceptible d'apparaître ne pourrait alors pas être réparée et certaines fonctionnalités pourraient être endommagées. Ce service se désinstalle automatiquement lorsque aucun logiciel Brave ne l'utilise. BraveSoftware Update BraveSoftware Inc. BraveSoftware Update 1.3.101.0 ->BRAVESOFTWARE UPDATE !$*"C:\PROGRAM FILES (X86)\BRAVESOFTWARE\UPDATE\BRAVEUPDATE.EXE" /SVC [Auto Services] :HKLM bravem ### Service: Service Brave Update (bravem) Status: Start Type: loaded manually on demand Actual File: C:\PROGRAM FILES (X86)\BRAVESOFTWARE\UPDATE\BRAVEUPDATE.EXE * Permet de maintenir votre logiciel Brave à jour. Si ce service est désactivé ou interrompu, votre logiciel Brave ne sera plus mis à jour. Toute faille de sécurité susceptible d'apparaître ne pourrait alors pas être réparée et certaines fonctionnalités pourraient être endommagées. Ce service se désinstalle automatiquement lorsque aucun logiciel Brave ne l'utilise. BraveSoftware Update BraveSoftware Inc. BraveSoftware Update 1.3.101.0 ->BRAVESOFTWARE UPDATE !$*"C:\PROGRAM FILES (X86)\BRAVESOFTWARE\UPDATE\BRAVEUPDATE.EXE" /MEDSVC [Auto Services] :HKLM BrokerInfrastructure ### Service: Service d’infrastructure des tâches en arrière-plan Status: Start Type: loaded automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Service d’infrastructure Windows qui contrôle les tâches en arrière-plan qui peuvent s’exécuter sur le système. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K DCOMLAUNCH -P [Auto Services] :HKLM Browser ### Service: Explorateur d’ordinateurs Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Tient à jour une liste des ordinateurs présents sur le réseau et fournit cette liste aux ordinateurs désignés comme navigateurs. Si ce service est arrêté, la liste ne sera pas mise ou tenue à jour. Si ce service est désactivé, les services qui en dépendent ne pourront pas démarrer. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS -P [Auto Services] :HKLM BTAGService ### Service: Service de passerelle audio Bluetooth Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Service prenant en charge le rôle de passerelle audio du profil mains libres Bluetooth Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICENETWORKRESTRICTED [Auto Services] :HKLM BthAvctpSvc ### Service: Service AVCTP Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Ceci est le service de protocole de transport de contrôle audio vidéo Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE -P [Auto Services] :HKLM bthserv ### Service: Service de prise en charge Bluetooth Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Le service Bluetooth prend en charge la découverte et l’association d’appareils Bluetooth distants. L’arrêt ou la désactivation de ce service peut entraîner un dysfonctionnement des appareils Bluetooth déjà installés et peut empêcher la découverte et l’association de nouveaux appareils. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE -P [Auto Services] :HKLM camsvc ### Service: Service Gestionnaire d’accès aux fonctionnalités Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Fournit des fonctionnalités pour la gestion de l’accès des applications UWP aux fonctionnalités de l’application, ainsi que pour la vérification de l’accès d'une application aux fonctionnalités de l’application spécifique Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K APPMODEL -P [Auto Services] :HKLM CaptureService ### Service: CaptureService Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Active la fonctionnalité de capture d'écran facultative pour les applications qui appellent l'API Windows.Graphics.Capture. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE -P [Auto Services] :HKLM CaptureService_1a8ea6 ### Service: CaptureService_1a8ea6 Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Active la fonctionnalité de capture d'écran facultative pour les applications qui appellent l'API Windows.Graphics.Capture. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE -P [Auto Services] :HKLM cbdhsvc ### Service: Service utilisateur du Presse-papiers Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Ce service utilisateur est utilisé pour les scénarios du Presse-papiers Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K CLIPBOARDSVCGROUP -P [Auto Services] :HKLM cbdhsvc_1a8ea6 ### Service: Service utilisateur du Presse-papiers_1a8ea6 Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Ce service utilisateur est utilisé pour les scénarios du Presse-papiers Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K CLIPBOARDSVCGROUP -P [Auto Services] :HKLM cdfs ### Driver: CD/DVD File System Reader Status: Start Type: disabled Actual File: C:\WINDOWS\SYSTEM32\DRIVERS\CDFS.SYS * ISO9660/Joliet File System Reader for CD/DVDs. (Core) (All pieces) CD-ROM File System Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*C:\WINDOWS\SYSTEM32\DRIVERS\CDFS.SYS [Auto Services] :HKLM CDPSvc ### Service: Service de plateforme des appareils connectés Status: Start Type: loaded automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Ce service est utilisé pour les scénarios plateforme d’appareils connectés Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE -P [Auto Services] :HKLM CDPUserSvc ### Service: Service pour utilisateur de plateforme d’appareils connectés Status: Start Type: loaded automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Ce service utilisateur entre dans le cadre de scénarios de plateforme d’appareils connectés Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K UNISTACKSVCGROUP [Auto Services] :HKLM CDPUserSvc_1a8ea6 ### Service: Service pour utilisateur de plateforme d’appareils connectés_1a8ea6 Status: Start Type: loaded automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Ce service utilisateur entre dans le cadre de scénarios de plateforme d’appareils connectés Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K UNISTACKSVCGROUP [Auto Services] :HKLM CertPropSvc ### Service: Propagation du certificat Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Copie des certificats utilisateur et des certificats racines à partir de cartes à puce dans le magasin de certificats de l’utilisateur actuel, détecte quand une carte à puce est insérée dans un lecteur de cartes à puce, et, si nécessaire, installe le minipilote Plug and Play de cartes à puce. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS [Auto Services] :HKLM ClipSVC ### Service: Service de licences de client (ClipSVC) Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Permet la prise en charge de l'infrastructure de Microsoft Store. Ce service démarre à la demande. S'il est désactivé, les applications achetées via le Windows Store ne se comportent pas correctement. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K WSAPPX -P [Auto Services] :HKLM cnghwassist ### Driver: CNG Hardware Assist algorithm provider Status: Start Type: disabled Actual File: C:\WINDOWS\SYSTEM32\DRIVERS\CNGHWASSIST.SYS * CNG Hardware Assist algorithm provider CNG Hardware Assist algorithm provider Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*C:\WINDOWS\SYSTEM32\DRIVERS\CNGHWASSIST.SYS [Auto Services] :HKLM COMSysApp ### Service: Application système COM+ Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\DLLHOST.EXE * Gère la configuration et le suivi des composants de base COM+ (Component Object Model). Si le service est arrêté, la plupart des composants de base COM+ ne fonctionneront pas correctement. Si ce service est désactivé, les services qui en dépendent de manière explicite ne pourront pas démarrer. COM Surrogate Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.546 !$*%SYSTEMROOT%\SYSTEM32\DLLHOST.EXE /PROCESSID:{02D4B3F1-FD88-11D1-960D-00805FC79235} [Auto Services] :HKLM ConsentUxUserSvc ### Service: ConsentUX Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Permet à ConnectUX et aux Paramètres du PC de se connecter et d'effectuer le couplage avec affichages Wi-Fi et les appareils Bluetooth. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K DEVICESFLOW [Auto Services] :HKLM ConsentUxUserSvc_1a8ea6 ### Service: ConsentUX_1a8ea6 Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Permet à ConnectUX et aux Paramètres du PC de se connecter et d'effectuer le couplage avec affichages Wi-Fi et les appareils Bluetooth. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K DEVICESFLOW [Auto Services] :HKLM CoreMessagingRegistrar ### Service: CoreMessaging Status: Start Type: loaded automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Manages communication between system components. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICENONETWORK -P [Auto Services] :HKLM cphs ### Service: Intel(R) Content Protection HECI Service Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSWOW64\INTELCPHECISVC.EXE * Intel(R) Content Protection HECI Service - enables communication with the Content Protection FW IntelCpHeciSvc Executable Intel Corporation IntelCpHeciSvc Executable 9.0.31.9015 !$*%SYSTEMROOT%\SYSWOW64\INTELCPHECISVC.EXE [Auto Services] :HKLM CredentialEnrollmentManagerUserSvc ### Service: CredentialEnrollmentManagerUserSvc Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\System32\CREDENTIALENROLLMENTMANAGER.EXE * Gestionnaire d’inscription des informations d’identification Gestionnaire d’inscription des informations d’identification Microsoft Corporation Système d'exploitation Microsoft® Windows® 10.0.19041.867 ->CREDENTIAL ENROLLMENT MANAGER !$*%SYSTEMROOT%\SYSTEM32\CREDENTIALENROLLMENTMANAGER.EXE [Auto Services] :HKLM CredentialEnrollmentManagerUserSvc_1a8ea6 ### Service: CredentialEnrollmentManagerUserSvc_1a8ea6 Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\CREDENTIALENROLLMENTMANAGER.EXE * Gestionnaire d’inscription des informations d’identification Gestionnaire d’inscription des informations d’identification Microsoft Corporation Système d'exploitation Microsoft® Windows® 10.0.19041.867 ->CREDENTIAL ENROLLMENT MANAGER !$*C:\WINDOWS\SYSTEM32\CREDENTIALENROLLMENTMANAGER.EXE [Auto Services] :HKLM CryptSvc ### Service: Services de chiffrement Status: Start Type: loaded automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Fournit trois services de gestion : le service de base de données de catalogues, qui confirme les signatures des fichiers Windows et autorise l’installation de nouveaux programmes, le service de racine protégée, qui ajoute et supprime les certificats d’autorité de certification racines approuvés sur cet ordinateur, et le service de mise à jour de certificats racines automatique, qui extrait les certificats racines à partir de Windows Update et autorise les scénarios tels que SSL. Si ce service est arrêté, les services de gestion ne fonctionneront pas correctement. Si ce service est désactivé, les services en dépendant explicitement ne démarreront pas. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETWORKSERVICE -P [Auto Services] :HKLM defragsvc ### Service: Optimiser les lecteurs Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Permet à l’ordinateur de fonctionner plus efficacement en optimisant les fichiers sur les lecteurs de stockage. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K DEFRAGSVC [Auto Services] :HKLM DeviceAssociationBrokerSvc ### Service: DeviceAssociationBroker Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Enables apps to pair devices Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K DEVICESFLOW -P [Auto Services] :HKLM DeviceAssociationBrokerSvc_1a8ea6 ### Service: DeviceAssociationBroker_1a8ea6 Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Enables apps to pair devices Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K DEVICESFLOW -P [Auto Services] :HKLM DeviceAssociationService ### Service: Service d’association de périphérique Status: Start Type: loaded automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Permet de coupler des périphériques câblés ou sans fil au système. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED -P [Auto Services] :HKLM DeviceInstall ### Service: Service d’installation de périphérique Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Permet à l’ordinateur de reconnaître et d’adapter les modifications matérielles avec peu ou pas du tout d’intervention de l’utilisateur. Arrêter ou désactiver ce service provoque une instabilité du système. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K DCOMLAUNCH -P [Auto Services] :HKLM DevicePickerUserSvc ### Service: DevicePicker Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Ce service utilisateur permet de gérer l'IU Miracast, DLNA et DIAL Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K DEVICESFLOW [Auto Services] :HKLM DevicePickerUserSvc_1a8ea6 ### Service: DevicePicker_1a8ea6 Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Ce service utilisateur permet de gérer l'IU Miracast, DLNA et DIAL Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K DEVICESFLOW [Auto Services] :HKLM DevicesFlowUserSvc ### Service: Flux d’appareils Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Permet à ConnectUX et aux Paramètres du PC de se connecter et d'effectuer le couplage avec affichages Wi-Fi et les appareils Bluetooth. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K DEVICESFLOW [Auto Services] :HKLM DevicesFlowUserSvc_1a8ea6 ### Service: Flux d’appareils_1a8ea6 Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Permet à ConnectUX et aux Paramètres du PC de se connecter et d'effectuer le couplage avec affichages Wi-Fi et les appareils Bluetooth. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K DEVICESFLOW [Auto Services] :HKLM DevQueryBroker ### Service: Service Broker de découverte en arrière-plan DevQuery Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Permet aux applications de découvrir les périphériques avec une tâche en arrière-plan Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED -P [Auto Services] :HKLM Dhcp ### Service: Client DHCP Status: Start Type: loaded automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Inscrit et met à jour les adresses IP et les enregistrements DNS pour cet ordinateur. Si ce service est arrêté, cet ordinateur ne recevra pas d’adresses IP et de mises à jour DNS dynamiques. Si ce service est désactivé, tous les services qui en dépendent explicitement ne pourront pas démarrer. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICENETWORKRESTRICTED -P [Auto Services] :HKLM diagnosticshub.standardcollector.service ### Service: Service Collecteur standard du concentrateur de diagnostic Microsoft (R) Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\System32\DIAGSVCS\DIAGNOSTICSHUB.STANDARDCOLLECTOR.SERVICE.EXE * Service Collecteur standard du concentrateur de diagnostic. Lors de l'exécution, ce service collecte les événements ETW en temps réel et les traite. Microsoft (R) Diagnostics Hub Standard Collector Microsoft Corporation Internet Explorer 11.00.19041.928 !$*%SYSTEMROOT%\SYSTEM32\DIAGSVCS\DIAGNOSTICSHUB.STANDARDCOLLECTOR.SERVICE.EXE [Auto Services] :HKLM diagsvc ### Service: Diagnostic Execution Service Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Executes diagnostic actions for troubleshooting support Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K DIAGNOSTICS [Auto Services] :HKLM DiagTrack ### Service: Expériences des utilisateurs connectés et télémétrie Status: Start Type: loaded automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Le service Expériences des utilisateurs connectés et télémétrie offre des fonctionnalités qui prennent en charge les expériences des utilisateurs connectés et in-app. En outre, ce service gère la collecte et la transmission des informations de diagnostic et d'utilisation en fonction des événements (afin d'améliorer l'expérience et la qualité de la plateforme Windows) lorsque les paramètres des options de confidentialité des diagnostics et de l'utilisation sont activés sous Commentaires & diagnostics. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K UTCSVC -P [Auto Services] :HKLM Disc Soft Lite Bus Service ### Service: Disc Soft Lite Bus Service Status: Start Type: loaded manually on demand Actual File: C:\PROGRAM FILES\DAEMON TOOLS LITE\DISCSOFTBUSSERVICELITE.EXE * Emulates virtual drives for image mounting. Disc Soft Bus Service Lite Disc Soft Ltd DAEMON Tools Lite 10.14.0.1709 !$*"C:\PROGRAM FILES\DAEMON TOOLS LITE\DISCSOFTBUSSERVICELITE.EXE" [Auto Services] :HKLM DispBrokerDesktopSvc ### Service: Service de stratégie d'affichage Status: Start Type: loaded automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Gère la connexion et la configuration des affichages locaux et distants Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE -P [Auto Services] :HKLM DisplayEnhancementService ### Service: Service d'amélioration de l'affichage Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Service permettant de gérer l'amélioration de l'affichage, tel que le contrôle de la luminosité. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED -P [Auto Services] :HKLM DmEnrollmentSvc ### Service: Service d'inscription de la gestion des périphériques Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Assure les activités d'inscription de périphériques de la gestion des périphériques. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS -P [Auto Services] :HKLM dmwappushservice ### Service: Service de routage de messages Push du protocole WAP (Wireless Application Protocol) de gestion des appareils Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Achemine les messages Push du protocole WAP (Wireless Application Protocol) reçus par l'appareil et synchronise les sessions de gestion des appareils Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS -P [Auto Services] :HKLM Dnscache ### Service: Client DNS Status: Start Type: loaded automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Le service client DNS (dnscache) met en cache les noms DNS (Domain Name System) et inscrit le nom complet de cet ordinateur. Si le service est arrêté, les noms DNS continuent d’être résolus. Toutefois, les résultats des requêtes de noms DNS ne sont pas mis en cache et le nom de l’ordinateur n’est pas inscrit. Si le service est désactivé, les services qui en dépendent explicitement ne peuvent pas démarrer. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETWORKSERVICE -P [Auto Services] :HKLM DoSvc ### Service: Optimisation de livraison Status: Start Type: loaded automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Effectue des tâches d'optimisation de distribution de contenu Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETWORKSERVICE -P [Auto Services] :HKLM dot3svc ### Service: Configuration automatique de réseau câblé Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Le service Wired AutoConfig (DOT3SVC) est responsable de l’exécution de l’authentification IEEE 802.1X sur les interfaces Ethernet. Si votre déploiement de réseau câblé actuel applique l’authentification 802.1X, le service DOT3SVC doit être configuré de façon à s’exécuter pour l’établissement de la connectivité de Couche 2 et/ou fournir l’accès aux ressources réseau. Les réseaux câblés qui n’appliquent pas l’authentification 802.1X ne sont pas concernés par le service DOT3SVC. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED -P [Auto Services] :HKLM DsmSvc ### Service: Gestionnaire d’installation de périphérique Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Active la détection, le téléchargement et l’installation du logiciel associé au périphérique. Si ce service est désactivé, les périphériques risquent d’être configurés avec un logiciel obsolète et de ne pas fonctionner correctement. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS -P [Auto Services] :HKLM DsSvc ### Service: Service de partage des données Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Fournit l'intermédiation des données entre les applications. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED -P [Auto Services] :HKLM DusmSvc ### Service: Consommation des données Status: Start Type: loaded automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Consommation des données du réseau, limite de données, limiter les données d’arrière-plan, connexions réseau limitées. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICENETWORKRESTRICTED -P [Auto Services] :HKLM Eaphost ### Service: Protocole EAP (Extensible Authentication Protocol) Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Le service EAP (Extensible Authentication Protocol) permet d’authentifier le réseau dans des scénarios tels que des réseaux câblés et sans fil 802.1x, des réseaux privés virtuels et NAP (Network Access Protection). Ce service fournit également des API qui sont utilisées par les clients d’accès à distance, notamment les clients sans fil et VPN, lors de l’authentification. Si vous désactivez ce service, cet ordinateur ne pourra pas accéder aux réseaux qui nécessitent l’authentification EAP. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS -P [Auto Services] :HKLM EasyAntiCheat ### Service: EasyAntiCheat Status: Start Type: loaded manually on demand Actual File: C:\PROGRAM FILES (X86)\EASYANTICHEAT\EASYANTICHEAT.EXE * Provides integrated security and services for online multiplayer games. EasyAntiCheat Service EasyAntiCheat Ltd EasyAntiCheat 4, 0, 0, 0 !$*"C:\PROGRAM FILES (X86)\EASYANTICHEAT\EASYANTICHEAT.EXE" [Auto Services] :HKLM edgeupdate ### Service: Microsoft Edge Update Service (edgeupdate) Status: Start Type: loaded automatically by Server Manager Actual File: C:\PROGRAM FILES (X86)\MICROSOFT\EDGEUPDATE\MICROSOFTEDGEUPDATE.EXE * Keeps your Microsoft software up to date. If this service is disabled or stopped, your Microsoft software will not be kept up to date, meaning security vulnerabilities that may arise cannot be fixed and features may not work. This service uninstalls itself when there is no Microsoft software using it. Microsoft Edge Update Microsoft Corporation Microsoft Edge Update 1.3.135.29 ->MICROSOFT EDGE UPDATE =>MSEDGEUPDATE.DLL !$*"C:\PROGRAM FILES (X86)\MICROSOFT\EDGEUPDATE\MICROSOFTEDGEUPDATE.EXE" /SVC [Auto Services] :HKLM edgeupdatem ### Service: Microsoft Edge Update Service (edgeupdatem) Status: Start Type: loaded manually on demand Actual File: C:\PROGRAM FILES (X86)\MICROSOFT\EDGEUPDATE\MICROSOFTEDGEUPDATE.EXE * Keeps your Microsoft software up to date. If this service is disabled or stopped, your Microsoft software will not be kept up to date, meaning security vulnerabilities that may arise cannot be fixed and features may not work. This service uninstalls itself when there is no Microsoft software using it. Microsoft Edge Update Microsoft Corporation Microsoft Edge Update 1.3.135.29 ->MICROSOFT EDGE UPDATE =>MSEDGEUPDATE.DLL !$*"C:\PROGRAM FILES (X86)\MICROSOFT\EDGEUPDATE\MICROSOFTEDGEUPDATE.EXE" /MEDSVC [Auto Services] :HKLM EFS ### Service: Système de fichiers EFS (Encrypting File System) Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\System32\LSASS.EXE * Fournit la technologie de chiffrement des fichiers de base utilisée pour stocker les fichiers chiffrés sur les volumes NTFS. Si ce service est arrêté ou désactivé, les applications n’auront pas accès aux fichiers chiffrés. Local Security Authority Process Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.906 !$*%SYSTEMROOT%\SYSTEM32\LSASS.EXE [Auto Services] :HKLM embeddedmode ### Service: Mode incorporé Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Le service Mode incorporé active les scénarios associés aux applications d’arrière-plan. La désactivation de ce service empêche l’activation de ces applications. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED -P [Auto Services] :HKLM EntAppSvc ### Service: Service de gestion des applications d'entreprise Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Permet la gestion des applications d'entreprise. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K APPMODEL -P [Auto Services] :HKLM EventLog ### Service: Journal d’événements Windows Status: Start Type: loaded automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Ce service gère les événements et les journaux d’événements. Il prend en charge l’enregistrement des événements, les requêtes sur les événements, l’abonnement aux événements, l’archivage des journaux d’événements et la gestion des métadonnées d’événements. Il peut afficher des événements en XML et en format de texte brut. L’arrêt de ce service peut compromettre la sécurité et la fiabilité du système. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICENETWORKRESTRICTED -P [Auto Services] :HKLM EventSystem ### Service: Système d’événement COM+ Status: Start Type: loaded automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Prend en charge le service de notification d’événements système (SENS, System Event Notification Service), qui fournit une distribution automatique d’événements aux composants COM (Component Object Model) abonnés. Si le service est arrêté, SENS sera fermé et ne pourra fournir des informations d’ouverture et de fermeture de session. Si ce service est désactivé, le démarrage de tout service qui en dépend explicitement échouera. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE -P [Auto Services] :HKLM Fax ### Service: Télécopie Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\System32\FXSSVC.EXE * Vous permet d’envoyer et de recevoir des télécopies, d’utiliser les ressources de télécopie disponibles sur cet ordinateur ou le réseau. Fax Service Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.804 !$*%SYSTEMROOT%\SYSTEM32\FXSSVC.EXE [Auto Services] :HKLM fdPHost ### Service: Hôte du fournisseur de découverte de fonctions Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Le service FDPHOST héberge les fournisseurs de découverte de réseau de découverte de fonction (FD). Ces fournisseurs de découverte de fonction fournissent des services de découverte de réseau pour les protocoles SSDP (Simple Services Discovery Protocol) et WS-D (Web Services - Discovery). L’arrêt ou la désactivation du service FDPHOST désactivera la découverte de réseau pour ces protocoles lors de l’utilisation de la découverte de fonction. Lorsque ce service n’est pas disponible, les services réseau qui utilisent la découverte de fonction et qui dépendent de ces protocoles de découverte ne pourront pas trouver des périphériques ou des ressources réseau. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE -P [Auto Services] :HKLM FDResPub ### Service: Publication des ressources de découverte de fonctions Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Publie cet ordinateur et les ressources qui y sont attachées, de façon à ce que leur découverte soit possible sur le réseau. Si ce service est arrêté, les ressources réseau ne sont plus publiées et ne seront donc pas découvertes par les autres ordinateurs du réseau. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICEANDNOIMPERSONATION -P [Auto Services] :HKLM fhsvc ### Service: Service d’historique des fichiers Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Protège les fichiers utilisateurs des pertes accidentelles en les copiant dans un emplacement de sauvegarde. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED -P [Auto Services] :HKLM FontCache ### Service: Service de cache de police Windows Status: Start Type: loaded automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Optimise les performances des applications en mettant en cache les données des polices communément utilisées. Les applications démarrent ce service s’il n’est pas déjà en fonctionnement. Il peut être désactivé ; il en résulte cependant une dégradation des performances des applications. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE -P [Auto Services] :HKLM FontCache3.0.0.0 ### Service: Cache de police de Windows Presentation Foundation 3.0.0.0 Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\MICROSOFT.NET\FRAMEWORK64\V3.0\WPF\PRESENTATIONFONTCACHE.EXE * Optimise les performances des applications Windows Presentation Foundation (WPF) en mettant en cache les données de police fréquemment utilisées. Les applications WPF démarrent ce service s'il n'est pas déjà en cours d'exécution. Ce dernier peut être désactivé ; toutefois, cela entraîne une dégradation des performances des applications WPF. PresentationFontCache.exe Microsoft Corporation Microsoft® .NET Framework 3.0.6920.9141 !$*%SYSTEMROOT%\MICROSOFT.NET\FRAMEWORK64\V3.0\WPF\PRESENTATIONFONTCACHE.EXE [Auto Services] :HKLM FrameServer ### Service: Serveur de trame de la Caméra Windows Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Permettre à plusieurs clients d’accéder aux trames vidéo des appareils photo. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K CAMERA [Auto Services] :HKLM Futuremark SystemInfo Service ### Service: Futuremark SystemInfo Service Status: Start Type: loaded manually on demand Actual File: C:\PROGRAM FILES (X86)\FUTUREMARK\SYSTEMINFO\FMSISVC.EXE * Futuremark SystemInfo Service Futuremark Futuremark SystemInfo 5.39.906.0 !$*"C:\PROGRAM FILES (X86)\FUTUREMARK\SYSTEMINFO\FMSISVC.EXE" [Auto Services] :HKLM FvSvc ### Service: NVIDIA FrameView SDK service Status: Start Type: loaded manually on demand Actual File: C:\PROGRAM FILES\NVIDIA CORPORATION\FRAMEVIEWSDK\NVFVSDKSVC_X64.EXE * NVIDIA FrameView SDK service NVIDIA FrameView 1.2.4923.0 !$*"C:\PROGRAM FILES\NVIDIA CORPORATION\FRAMEVIEWSDK\NVFVSDKSVC_X64.EXE" -SERVICE [Auto Services] :HKLM GalaxyClientService ### Service: GalaxyClientService Status: Start Type: loaded manually on demand Actual File: C:\PROGRAM FILES (X86)\GOG GALAXY\GALAXYCLIENTSERVICE.EXE * GOG Galaxy component for handling privileged tasks. GalaxyClientService GOG.com GOG Galaxy 2.0.37.384 !$*"C:\PROGRAM FILES (X86)\GOG GALAXY\GALAXYCLIENTSERVICE.EXE" [Auto Services] :HKLM GalaxyCommunication ### Service: GalaxyCommunication Status: Start Type: loaded manually on demand Actual File: C:\PROGRAMDATA\GOG.COM\GALAXY\REDISTS\GALAXYCOMMUNICATION.EXE * GalaxyCommunicationService GOG.com GOG Galaxy 2.0.3.261 ->GALAXYCOMMUNICATIONSERVICE =>COMMUNICATIONSERVICE.EXE !$*"C:\PROGRAMDATA\GOG.COM\GALAXY\REDISTS\GALAXYCOMMUNICATION.EXE" [Auto Services] :HKLM GamingServices ### Service: Gaming Services Status: Start Type: loaded automatically by Server Manager Actual File: C:\PROGRAM FILES\WINDOWSAPPS\MICROSOFT.GAMINGSERVICES_2.53.17003.0_X64__8WEKYB3D8BBWE\GAMINGSERVICES.EXE * ms-resource:GamingServicesDisplayName GamingServices Microsoft Corporation Microsoft Gaming Install Services 10.0.19041.7259 !$*C:\PROGRAM FILES\WINDOWSAPPS\MICROSOFT.GAMINGSERVICES_2.53.17003.0_X64__8WEKYB3D8BBWE\GAMINGSERVICES.EXE [Auto Services] :HKLM GamingServicesNet ### Service: Gaming Services Status: Start Type: loaded automatically by Server Manager Actual File: C:\PROGRAM FILES\WINDOWSAPPS\MICROSOFT.GAMINGSERVICES_2.53.17003.0_X64__8WEKYB3D8BBWE\GAMINGSERVICESNET.EXE * ms-resource:GamingServicesDisplayName GamingServices Microsoft Corporation Microsoft Gaming Install Services 10.0.19041.7259 ->GAMINGSERVICES.EXE !$*C:\PROGRAM FILES\WINDOWSAPPS\MICROSOFT.GAMINGSERVICES_2.53.17003.0_X64__8WEKYB3D8BBWE\GAMINGSERVICESNET.EXE [Auto Services] :HKLM GraphicsPerfSvc ### Service: GraphicsPerfSvc Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Graphics performance monitor service Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K GRAPHICSPERFSVCGROUP [Auto Services] :HKLM Hamachi2Svc ### Service: LogMeIn Hamachi Tunneling Engine Status: Start Type: loaded automatically by Server Manager Actual File: C:\PROGRAM FILES (X86)\LOGMEIN HAMACHI\X64\HAMACHI-2.EXE * Hamachi Client Tunneling Engine LogMeIn Inc. Hamachi Client 2, 0, 0, 0 ->H2-ENGINE !$*"C:\PROGRAM FILES (X86)\LOGMEIN HAMACHI\X64\HAMACHI-2.EXE" -S [Auto Services] :HKLM hidserv ### Service: Service du périphérique d’interface utilisateur Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Active et maintient l’utilisation des boutons actifs sur le clavier, les contrôles à distance et d’autres périphériques multimédias. Nous vous recommandons de veiller à ce que ce service soit constamment en cours d’exécution. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED -P [Auto Services] :HKLM hshld ### Service: Hotspot Shield Service Status: Start Type: loaded automatically by Server Manager Actual File: C:\PROGRAM FILES (X86)\HOTSPOT SHIELD\BIN\CMW_SRV.EXE * Hss.Service.Application AnchorFree Inc. Hotspot Shield 9.21.3.11422 !$*"C:\PROGRAM FILES (X86)\HOTSPOT SHIELD\BIN\CMW_SRV.EXE" [Auto Services] :HKLM hvcrash ### Driver: Status: Start Type: disabled Actual File: C:\WINDOWS\SYSTEM32\DRIVERS\HVCRASH.SYS * Hyper-V Crashdump Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*C:\WINDOWS\SYSTEM32\DRIVERS\HVCRASH.SYS [Auto Services] :HKLM HvHost ### Service: Service d'hôte HV Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Propose une interface pour l’hyperviseur Hyper-V afin de fournir des compteurs de performance par partition au système d’exploitation hôte. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED -P [Auto Services] :HKLM icssvc ### Service: Service Point d'accès sans fil mobile Windows Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Permet de partager une connexion de données cellulaires avec un autre appareil. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICENETWORKRESTRICTED -P [Auto Services] :HKLM igfxCUIService2.0.0.0 ### Service: Intel(R) HD Graphics Control Panel Service Status: Start Type: loaded automatically by Server Manager Actual File: C:\WINDOWS\System32\IGFXCUISERVICE.EXE * Service for Intel(R) HD Graphics Control Panel igfxCUIService Module Intel Corporation Intel(R) Common User Interface 6.15.10.4624 !$*%SYSTEMROOT%\SYSTEM32\IGFXCUISERVICE.EXE [Auto Services] :HKLM IKEEXT ### Service: Modules de génération de clés IKE et AuthIP Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Le service IKEEXT héberge les modules de génération de clés IKE (Internet Key Exchange) et AuthIP (Authenticated Internet Protocol). Ces modules de génération de clés sont utilisés pour l’authentification et l’échange de clés dans la sécurité IP (IPsec). L’arrêt ou la désactivation du service IKEEXT entraînera la désactivation de l’échange de clés IKE et AuthIP avec des ordinateurs homologues. IPsec est généralement configuré pour utiliser IKE ou AuthIP ; par conséquent, l’arrêt ou la désactivation du service IKEEXT risque de conduire à la défaillance d’IPsec et de compromettre la sécurité du système. Il est fortement recommandé d’activer l’exécution du service IKEEXT. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS -P [Auto Services] :HKLM InstallService ### Service: Installation du service Microsoft Store Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Offre une prise en charge de l'infrastructure pour le Microsoft Store. Ce service est lancé à la demande, et les installations ne fonctionneront pas correctement, s'il est désactivé. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS -P [Auto Services] :HKLM iphlpsvc ### Service: Assistance IP Status: Start Type: loaded automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Fournit une connectivité de tunnel à l’aide des technologies de transition IPv6 (6to4, ISATAP, Proxy de port et Teredo) et IP-HTTPS. Si ce service est arrêté, l’ordinateur ne disposera pas des avantages de la connectivité améliorée offerts par ces technologies. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS -P [Auto Services] :HKLM IpxlatCfgSvc ### Service: Service de configuration de conversion IP Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Configure et permet la conversion de v4 en v6 et vice versa Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED -P [Auto Services] :HKLM KeyIso ### Service: Isolation de clé CNG Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\System32\LSASS.EXE * Le service d’isolation de clé CNG est hébergé dans le processus LSA. Le service fournit une isolation de processus de clé aux clés privés et aux opérations de chiffrement associées, conformément aux critères communs. Le service stocke et utilise des clés à long terme dans le cadre d’un processus sécurisé répondant aux exigences des critères communs. Local Security Authority Process Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.906 !$*%SYSTEMROOT%\SYSTEM32\LSASS.EXE [Auto Services] :HKLM KtmRm ### Service: Service KtmRm pour Distributed Transaction Coordinator Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Coordonne les transactions entre Distributed Transaction Coordinator (MSDTC) et le gestionnaire de transactions du noyau (KTN). S’il n’est pas requis, il est recommandé que ce service reste arrêté. S’est requis, MSDTC et KTM démarrent ce service automatiquement. Si ce service est désactivé, toute transaction MSDTC interagissant avec un gestionnaire de transactions du noyau échoue et tout service qui en dépend de façon explicite ne parvient pas à démarrer. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETWORKSERVICEANDNOIMPERSONATION -P [Auto Services] :HKLM LanmanServer ### Service: Serveur Status: Start Type: loaded automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Prend en charge le partage de fichiers, d’impression et des canaux nommés via le réseau pour cet ordinateur. Si ce service est arrêté, ces fonctions ne seront pas disponibles. Si ce service est désactivé, les services qui en dépendent ne pourront pas démarrer. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS -P [Auto Services] :HKLM LanmanWorkstation ### Service: Station de travail Status: Start Type: loaded automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Crée et maintient des connexions de réseau client à des serveurs distants à l’aide du protocole SMB. Si ce service est arrêté, ces connexions ne seront pas disponibles. Si ce service est désactivé, les services qui en dépendent explicitement ne pourront pas démarrer. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETWORKSERVICE -P [Auto Services] :HKLM lfsvc ### Service: Service de géolocalisation Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Ce service surveille l'emplacement actuel du système et gère les limites géographiques (un emplacement géographique accompagné d'événements associés). Si vous désactivez ce service, les applications ne pourront pas utiliser ni recevoir de notification pour la géolocalisation ou des limites géographiques. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS -P [Auto Services] :HKLM LicenseManager ### Service: Serveur Gestionnaire de licences Windows Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Offre une prise en charge de l'infrastructure pour le Microsoft Store. Ce service est lancé à la demande, et le contenu acquis via le Microsoft Store ne fonctionnera pas correctement, s'il est désactivé. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE -P [Auto Services] :HKLM lltdsvc ### Service: Mappage de découverte de topologie de la couche de liaison Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Crée un mappage réseau, consistant en informations sur la topologie des ordinateurs et des périphériques (connectivité) et en métadonnées décrivant chaque ordinateur et chaque périphérique. Si ce service est désactivé, le mappage réseau ne fonctionne pas correctement. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE -P [Auto Services] :HKLM lmhosts ### Service: Assistance NetBIOS sur TCP/IP Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Prend en charge le service NetBIOS sur TCP/IP (NetBT) et la résolution de noms NetBIOS pour les clients présents sur le réseau, ce qui permet aux utilisateurs de partager des fichiers, d’imprimer et d’ouvrir des sessions sur le réseau. Si ce service est arrêté, ces fonctions risquent de ne pas être disponibles. Si ce service est désactivé, les services qui en dépendent explicitement ne pourront pas démarrer. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICENETWORKRESTRICTED -P [Auto Services] :HKLM LMIGuardianSvc ### Service: LMIGuardianSvc Status: Start Type: loaded automatically by Server Manager Actual File: C:\PROGRAM FILES (X86)\LOGMEIN HAMACHI\X64\LMIGUARDIANSVC.EXE * Support LogMeIn processes with quality assurance feedback LMIGuardianSvc LogMeIn, Inc. LMIGuardianSvc 10.1.1742 !$*"C:\PROGRAM FILES (X86)\LOGMEIN HAMACHI\X64\LMIGUARDIANSVC.EXE" [Auto Services] :HKLM LSM ### Service: Gestionnaire de session locale Status: Start Type: loaded automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Service Windows de base gérant les sessions locales utilisateur. L’arrêt ou la désactivation de ce service risque d’entraîner l’instabilité du système. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K DCOMLAUNCH -P [Auto Services] :HKLM LxpSvc ### Service: Service d'expérience linguistique Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Fournit une prise en charge de l'infrastructure permettant de déployer et de configurer des ressources Windows localisées. Ce service est démarré à la demande et, s'il est désactivé, des langues Windows supplémentaires ne sont pas déployées sur le système et Windows risque de ne pas fonctionner correctement. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS [Auto Services] :HKLM MapsBroker ### Service: Gestionnaire des cartes téléchargées Status: Start Type: loaded automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Service Windows pour l’accès des applications aux cartes téléchargées. Ce service est démarré à la demande par l’application, qui accède aux cartes téléchargées. La désactivation de ce service empêche les applications d’accéder aux cartes. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETWORKSERVICE -P [Auto Services] :HKLM MBAMService ### Service: Malwarebytes Service Status: Start Type: loaded manually on demand Actual File: C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\MBAMSERVICE.EXE * Malwarebytes Service Malwarebytes Service Malwarebytes Malwarebytes Service 3.2.0.943 !$*"C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\MBAMSERVICE.EXE" [Auto Services] :HKLM MessagingService ### Service: MessagingService Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Service prenant en charge les envois de SMS et les fonctionnalités associées. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K UNISTACKSVCGROUP [Auto Services] :HKLM MessagingService_1a8ea6 ### Service: MessagingService_1a8ea6 Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Service prenant en charge les envois de SMS et les fonctionnalités associées. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K UNISTACKSVCGROUP [Auto Services] :HKLM MicrosoftEdgeElevationService ### Service: Microsoft Edge Elevation Service (MicrosoftEdgeElevationService) Status: Start Type: loaded manually on demand Actual File: C:\PROGRAM FILES (X86)\MICROSOFT\EDGE\APPLICATION\91.0.864.48\ELEVATION_SERVICE.EXE * Keeps Microsoft Edge up to update. If this service is disabled, the application will not be kept up to date. Microsoft Edge Microsoft Corporation Microsoft Edge 91.0.864.48 ->ELEVATION_SERVICE_EXE !$*"C:\PROGRAM FILES (X86)\MICROSOFT\EDGE\APPLICATION\91.0.864.48\ELEVATION_SERVICE.EXE" [Auto Services] :HKLM MixedRealityOpenXRSvc ### Service: Windows Mixed Reality OpenXR Service Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Enables Mixed Reality OpenXR runtime functionality Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED -P [Auto Services] :HKLM mpssvc ### Service: Pare-feu Windows Defender Status: Start Type: loaded automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Le Pare-feu Windows Defender vous aide à protéger votre ordinateur en empêchant les utilisateurs non autorisés d'accéder à votre ordinateur via Internet ou un réseau. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICENONETWORKFIREWALL -P [Auto Services] :HKLM mracsvc ### Service: MRAC Service Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\MRACSVC.EXE * Mail.Ru AntiCheat Service Mail.Ru AntiCheat Service LLC Mail.Ru Mail.Ru AntiCheat 3.25.0 !$*C:\WINDOWS\SYSTEM32\MRACSVC.EXE [Auto Services] :HKLM MSDTC ### Service: Coordinateur de transactions distribuées Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\System32\MSDTC.EXE * Coordonne les transactions qui comportent plusieurs gestionnaires de ressources, tels que des bases de données, des files d’attente de messages net des systèmes de fichiers. Si ce service est arrêté, ces transactions échoueront. S’il est désactivé, le démarrage de tout service qui en dépend explicitement échouera. Service Microsoft Distributed Transaction Coordinator Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\MSDTC.EXE [Auto Services] :HKLM MSiSCSI ### Service: Service Initiateur iSCSI de Microsoft Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Gère les sessions iSCSI (Internet SCSI) à partir de cet ordinateur sur les périphériques cible iSCSI distants. Si ce service est arrêté, l’ordinateur ne pourra plus ouvrir de session sur les cibles iSCSI ni y accéder. S’il est désactivé, tous les services qui dépendent explicitement de lui ne pourront plus démarrer. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS -P [Auto Services] :HKLM msiserver ### Service: Windows Installer Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\MSIEXEC.EXE * Ajoute, modifie et supprime des applications fournies en tant que package Windows Installer (*.msi, *.msp, *.appx). Si ce service est désactivé, les services qui en dépendent explicitement ne démarreront pas. Installateur Windows® Microsoft Corporation Windows Installer - Unicode 5.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\MSIEXEC.EXE /V [Auto Services] :HKLM NaturalAuthentication ### Service: Authentification naturelle Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Service d’agrégation de signaux qui évalue les signaux en fonction de l’heure, de la géolocalisation du réseau, des facteurs bluetooth et cdf. Les fonctionnalités prises en charge sont les stratégies Déverrouillage d’appareil, Verrouillage dynamique et Dynamo MDM. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS -P [Auto Services] :HKLM NcaSvc ### Service: Assistant Connectivité réseau Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Fournit la notification du statut DirectAccess aux composants de l’interface utilisateur Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS -P [Auto Services] :HKLM NcbService ### Service: Service Broker pour les connexions réseau Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Connexions du service Broker qui permettent aux applications du Windows Store de recevoir des notifications d’Internet. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED -P [Auto Services] :HKLM NcdAutoSetup ### Service: Configuration automatique des périphériques connectés au réseau Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Le service Configuration automatique des périphériques connectés au réseau supervise et installe les périphériques qualifiés qui se connectent à un réseau qualifié. L’arrêt ou la désactivation de ce service empêchent Windows de découvrir et installer automatiquement des périphériques connectés au réseau qualifié. Les utilisateurs peuvent quand même ajouter manuellement des périphériques connectés au réseau à un ordinateur via l’interface utilisateur. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICENONETWORK -P [Auto Services] :HKLM NetgearA7000 ### Service: NetgearA7000 Status: Start Type: loaded automatically by Server Manager Actual File: C:\PROGRAM FILES (X86)\NETGEAR\A7000\RTLSERVICE.EXE * Realtek RtlService Application Realtek Semiconductor Corp. Realtek RtlService Application 700, 1007, 509, 2012 !$*C:\PROGRAM FILES (X86)\NETGEAR\A7000\RTLSERVICE.EXE [Auto Services] :HKLM Netlogon ### Service: NetLogon Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\System32\LSASS.EXE * Maintient un canal sécurisé entre cet ordinateur et le contrôleur de domaine pour authentifier les utilisateurs et les services. Si ce service est arrêté, l’ordinateur peut ne pas authentifier les utilisateurs et les services et le contrôleur de domaine ne peut pas inscrire les enregistrements DNS. Si ce service est désactivé, tout service qui en dépend explicitement ne pourra pas démarrer. Local Security Authority Process Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.906 !$*%SYSTEMROOT%\SYSTEM32\LSASS.EXE [Auto Services] :HKLM Netman ### Service: Connexions réseau Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Prend en charge les objets dans le dossier Connexions réseau et accès à distance, dans lequel vous pouvez afficher à la fois les connexions du réseau local et les connexions à distance. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED -P [Auto Services] :HKLM netprofm ### Service: Service Liste des réseaux Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Identifie les réseaux auxquels l’ordinateur s’est connecté, collecte et stocke les propriétés de ces réseaux, et signale aux applications toute modification des propriétés. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE -P [Auto Services] :HKLM NetSetupSvc ### Service: Service Configuration du réseau Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Le service Configuration du réseau gère l'installation des pilotes réseau et autorise la configuration de paramètres réseau de bas niveau. Si ce service est interrompu, il se peut que les installations de pilote en cours soient annulées. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS -P [Auto Services] :HKLM NetTcpPortSharing ### Service: Service de partage de ports Net.Tcp Status: Start Type: disabled Actual File: C:\WINDOWS\MICROSOFT.NET\FRAMEWORK64\V4.0.30319\SMSVCHOST.EXE * Fournit la possibilité de partager des ports TCP sur le protocole net.tcp. SMSvcHost.exe Microsoft Corporation Microsoft® .NET Framework 4.8.4084.0 !$*%SYSTEMROOT%\MICROSOFT.NET\FRAMEWORK64\V4.0.30319\SMSVCHOST.EXE [Auto Services] :HKLM NgcCtnrSvc ### Service: Conteneur Microsoft Passport Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Gère les clés d'identité d'utilisateur local servant à authentifier l'utilisateur auprès des fournisseurs d'identité, ainsi que les cartes à puce virtuelles du module de plateforme sécurisée (TPM). Si ce service est désactivé, les clés d'identité d'utilisateur local et les cartes à puce virtuelles TPM ne seront pas accessibles. Nous vous recommandons de ne pas reconfigurer ce service. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICENETWORKRESTRICTED -P [Auto Services] :HKLM NgcSvc ### Service: Microsoft Passport Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Assure l'isolation des processus pour les clés de chiffrement servant à l'authentification auprès des fournisseurs d'identité associés à un utilisateur. Si ce service est désactivé, les fonctions d'utilisation et de gestion de ces clés, telles que l'ouverture de session et l'authentification unique pour les applications et les sites web, ne seront pas disponibles. Ce service démarre et s'arrête automatiquement. Il est recommandé de ne pas le reconfigurer. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED -P [Auto Services] :HKLM NlaSvc ### Service: Connaissance des emplacements réseau Status: Start Type: loaded automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Collecte et stocke les informations de configuration du réseau, puis notifie les programmes en cas de modification de ces informations. Si ce service est arrêté, les informations de configuration risquent de ne pas être disponibles. Si ce service est désactivé, les services qui en dépendent explicitement ne pourront pas démarrer. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETWORKSERVICE -P [Auto Services] :HKLM nsi ### Service: Service Interface du magasin réseau Status: Start Type: loaded automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Ce service fournit des notifications réseau (ajout/suppression d’interface, etc.) aux clients en mode utilisateur. L’arrêt de ce service entraîne la perte de la connectivité réseau. Si ce service est désactivé, les autres services qui en dépendent explicitement ne pourront pas démarrer. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE -P [Auto Services] :HKLM NvContainerLocalSystem ### Service: NVIDIA LocalSystem Container Status: Start Type: loaded automatically by Server Manager Actual File: C:\PROGRAM FILES\NVIDIA CORPORATION\NVCONTAINER\NVCONTAINER.EXE * Container service for NVIDIA root features NVIDIA Container NVIDIA Corporation NVIDIA Container gcomp_dev 28356155 !$*"C:\PROGRAM FILES\NVIDIA CORPORATION\NVCONTAINER\NVCONTAINER.EXE" -S NVCONTAINERLOCALSYSTEM -F "C:\PROGRAMDATA\NVIDIA\NVCONTAINERLOCALSYSTEM.LOG" -L 3 -D "C:\PROGRAM FILES\NVIDIA CORPORATION\NVCONTAINER\PLUGINS\LOCALSYSTEM" -R -P 30000 -ST "C:\PROGRAM FILES\NVIDIA CORPORATION\NVCONTAINER\NVCONTAINERTELEMETRYAPI.DLL" [Auto Services] :HKLM NVDisplay.ContainerLocalSystem ### Service: NVIDIA Display Container LS Status: Start Type: loaded automatically by Server Manager Actual File: .exe * Container service for NVIDIA root features NVIDIA Display Container LS!$*C:\WINDOWS\SYSTEM32\DRIVERSTORE\FILEREPOSITORY\NVMDI.INF_AMD64_6A0632B60438E56D\DISPLAY.NVCONTAINER\NVDISPLAY.CONTAINER.EXE -S NVDISPLAY.CONTAINERLOCALSYSTEM -F %PROGRAMDATA%\NVIDIA\NVDISPLAY.CONTAINERLOCALSYSTEM.LOG -L 3 -D C:\WINDOWS\SYSTEM32\DRIVERSTORE\FILEREPOSITORY\NVMDI.INF_AMD64_6A0632B60438E56D\DISPLAY.NVCONTAINER\PLUGINS\LOCALSYSTEM -R -P 30000 -CFG NVDISPLAY.CONTAINERLOCALSYSTEM\LOCALSYSTEM [Auto Services] :HKLM OneSyncSvc ### Service: Hôte de synchronisation Status: Start Type: loaded automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Ce service synchronise la messagerie, les contacts, le calendrier et diverses autres données utilisateur. La messagerie et d'autres applications dépendantes de cette fonctionnalité ne fonctionnent pas correctement lorsque ce service n'est pas exécuté. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K UNISTACKSVCGROUP [Auto Services] :HKLM OneSyncSvc_1a8ea6 ### Service: Hôte de synchronisation_1a8ea6 Status: Start Type: loaded automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Ce service synchronise la messagerie, les contacts, le calendrier et diverses autres données utilisateur. La messagerie et d'autres applications dépendantes de cette fonctionnalité ne fonctionnent pas correctement lorsque ce service n'est pas exécuté. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K UNISTACKSVCGROUP [Auto Services] :HKLM OVRLibraryService ### Service: Oculus VR Library Service Status: Start Type: loaded manually on demand Actual File: D:\OCULUS\SUPPORT\OCULUS-LIBRARIAN\OVRLIBRARYSERVICE.EXE * The Oculus Library Service keeps your library up to date and secure. Disabling this service will prevent Oculus from running on your computer. OVRLibraryService Facebook Technologies, LLC OVRLibraryService 1.16.0.0 !$*"D:\OCULUS\SUPPORT\OCULUS-LIBRARIAN\OVRLIBRARYSERVICE.EXE" [Auto Services] :HKLM OVRService ### Service: Oculus VR Runtime Service Status: Start Type: loaded automatically by Server Manager Actual File: D:\OCULUS\SUPPORT\OCULUS-RUNTIME\OVRSERVICELAUNCHER.EXE * The Oculus Runtime Service powers your headset. Disabling this service will prevent Oculus from running on your computer. OVR Service Launcher Facebook Technologies, LLC OVR Service Launcher 29.0.0.54.528 !$*"D:\OCULUS\SUPPORT\OCULUS-RUNTIME\OVRSERVICELAUNCHER.EXE" [Auto Services] :HKLM p2pimsvc ### Service: Gestionnaire d’identité réseau homologue Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Fournit des services d’identité pour le protocole PNRP et les services de groupement homologue. S’il est désactivé, le protocole PNRP et les services de groupement homologue peuvent ne pas fonctionner, et certaines applications, telles que Groupement résidentiel et Assistance à distance, peuvent ne pas fonctionner correctement. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICEPEERNET [Auto Services] :HKLM p2psvc ### Service: Groupement de mise en réseau de pairs Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Permet la communication multipartie à l’aide du groupement homologue. S’il est désactivé, certaines applications, telles que Groupement résidentiel, peuvent ne pas fonctionner. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICEPEERNET [Auto Services] :HKLM PcaSvc ### Service: Service de l’Assistant Compatibilité des programmes Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Ce service fournit une prise en charge de l’Assistant Compatibilité des programmes. Cet Assistant surveille les programmes installés et exécutés par l’utilisateur et détecte les problèmes de compatibilité connus. Si ce service est arrêté, cet Assistant ne fonctionnera pas correctement. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED -P [Auto Services] :HKLM perceptionsimulation ### Service: Service de simulation de perception Windows Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\System32\PERCEPTIONSIMULATION\PERCEPTIONSIMULATIONSERVICE.EXE * Permet la simulation de perception spatiale, la gestion de la caméra virtuelle et la simulation d'entrée spatiale. Service de simulation de perception Windows Microsoft Corporation Système d'exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\PERCEPTIONSIMULATION\PERCEPTIONSIMULATIONSERVICE.EXE [Auto Services] :HKLM PerfHost ### Service: Hôte de DLL de compteur de performance Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSWOW64\PERFHOST.EXE * Permet aux utilisateurs à distances et aux processus 64 bits d’interroger les compteurs de performances fournis par des DLL 32 bits. Si ce service est arrêté, seuls les utilisateurs locaux et les processus 32 bits peuvent interroger les compteurs fournis par des DLL 32 bits. Hôte de DLL de compteur de performance Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.1 !$*%SYSTEMROOT%\SYSWOW64\PERFHOST.EXE [Auto Services] :HKLM PhoneSvc ### Service: Service téléphonique Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Gère l'état de téléphonie de l'appareil Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE -P [Auto Services] :HKLM PimIndexMaintenanceSvc ### Service: Données de contacts Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Indexe les données de contacts pour une recherche des contacts plus rapide. Si vous arrêtez ou désactivez ce service, des contacts risquent de manquer dans vos résultats de recherche. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K UNISTACKSVCGROUP [Auto Services] :HKLM PimIndexMaintenanceSvc_1a8ea6 ### Service: Données de contacts_1a8ea6 Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Indexe les données de contacts pour une recherche des contacts plus rapide. Si vous arrêtez ou désactivez ce service, des contacts risquent de manquer dans vos résultats de recherche. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K UNISTACKSVCGROUP [Auto Services] :HKLM pla ### Service: Journaux & alertes de performance Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Le service des journaux et des alertes de performance collecte des données de performance sur des ordinateurs locaux ou distants, en se basant sur des paramètres de planification préconfigurés, puis écrit ces données dans un journal ou déclenche une alerte. Si ce service est arrêté, les informations de performance ne seront plus collectées. Si ce service est désactivé, tous les services qui en dépendent explicitement ne pourront plus démarrer. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICENONETWORK -P [Auto Services] :HKLM PlugPlay ### Service: Plug-and-Play Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Permet à l’ordinateur de reconnaître et d’adapter les modifications matérielles avec peu ou pas du tout d’intervention de l’utilisateur. Arrêter ou désactiver ce service provoque une instabilité du système. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K DCOMLAUNCH -P [Auto Services] :HKLM PNRPAutoReg ### Service: Service de publication des noms d’ordinateurs PNRP Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Ce service publie un nom d’ordinateur à l’aide du protocole PNRP (Peer Name Resolution Protocol). Sa configuration est gérée par le contexte netsh « p2p pnrp peer ». Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICEPEERNET [Auto Services] :HKLM PNRPsvc ### Service: Protocole PNRP Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Permet la résolution de noms d’homologues sans serveur via Internet, à l’aide du protocole PNRP. Si cette fonction est désactivée, certaines applications pair à pair et collaboratives, telles que Assistance à distance, peuvent ne pas fonctionner. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICEPEERNET [Auto Services] :HKLM PolicyAgent ### Service: Agent de stratégie IPsec Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * La sécurité du protocole Internet (IPSec) prend en charge l’authentification de l’homologue réseau, l’authentification de l’origine des données, l’intégrité des données, la confidentialité des données (chiffrement) et la protection de la relecture. Ce service met en œuvre des stratégies IPSec créées via le composant logiciel enfichable Stratégies de sécurité IP ou l’outil de ligne de commande « netsh ipsec ». Si vous arrêtez ce service, vous pourrez rencontrer des problèmes de connectivité réseau si votre stratégie nécessite des connexions IPSec. En outre, la gestion à distance du Pare-feu Windows Defender n’est pas disponible lorsque ce service est arrêté. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETWORKSERVICENETWORKRESTRICTED -P [Auto Services] :HKLM Power ### Service: Alimentation Status: Start Type: loaded automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Gère la stratégie d’alimentation et la remise de notification de stratégie d’alimentation. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K DCOMLAUNCH -P [Auto Services] :HKLM PrintNotify ### Service: Extensions et notifications des imprimantes Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Ce service ouvre les boîtes de dialogue d’impression personnalisée et gère les notifications d’une imprimante ou d’un serveur d’impression distant. Si vous désactivez ce service, vous ne pourrez plus voir les extensions ou notifications relatives aux imprimantes. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K PRINT [Auto Services] :HKLM PrintWorkflowUserSvc ### Service: PrintWorkflow Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Assure la prise en charge des applications Flux de travail d’impression. Si vous désactivez ce service, vous risquez de ne pas pouvoir imprimer correctement. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K PRINTWORKFLOW [Auto Services] :HKLM PrintWorkflowUserSvc_1a8ea6 ### Service: PrintWorkflow_1a8ea6 Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Assure la prise en charge des applications Flux de travail d’impression. Si vous désactivez ce service, vous risquez de ne pas pouvoir imprimer correctement. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K PRINTWORKFLOW [Auto Services] :HKLM ProfSvc ### Service: Service de profil utilisateur Status: Start Type: loaded automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Ce service est responsable du chargement et du déchargement des profils utilisateur. Si ce service est arrêté ou désactivé, les utilisateurs ne pourront plus se connecter ou se déconnecter, les applications pourront avoir des problèmes pour obtenir les données des utilisateurs, et les composants inscrits pour recevoir les notifications d’événements de profils ne les recevront pas. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS -P [Auto Services] :HKLM PushToInstall ### Service: Service PushToInstall de Windows Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Offre une prise en charge de l'infrastructure pour le Microsoft Store. Ce service est démarré automatiquement, et les installations distantes ne fonctionneront pas correctement, s'il est désactivé. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS -P [Auto Services] :HKLM QWAVE ### Service: Expérience audio-vidéo haute qualité Windows Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * qWave (Quality Windows Audio Video Experience) est une plateforme réseau destinée aux applications de flux AV (Audio Video) sur des réseaux domestiques IP. qWave améliore les performances et la fiabilité des flux AV en assurant la qualité de service (QoS) sur le réseau des applications AV. Cette plateforme fournit des mécanismes concernant le contrôle d’admission, l’analyse et la mise en œuvre des principes de protection des informations personnelles à l’exécution, la rétroaction des applications et la définition des priorités du trafic. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%WINDIR%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICEANDNOIMPERSONATION -P [Auto Services] :HKLM RasAuto ### Service: Gestionnaire des connexions automatiques d’accès à distance Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Crée une connexion vers un réseau distant à chaque fois qu’un programme référence un nom ou une adresse DNS ou NetBIOS distant. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS -P [Auto Services] :HKLM RasMan ### Service: Gestionnaire des connexions d’accès à distance Status: Start Type: loaded automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Gère les connexions d’accès à distance et les connexions de réseau privé virtuel (VPN) entre cet ordinateur et Internet ou d’autres réseaux distants. Si ce service est désactivé, les services qui en dépendent explicitement ne pourront pas démarrer. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS [Auto Services] :HKLM RemoteAccess ### Service: Routage et accès distant Status: Start Type: disabled Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Offre aux entreprises des services de routage dans les environnements de réseau local ou étendu. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS [Auto Services] :HKLM RemoteRegistry ### Service: Registre à distance Status: Start Type: disabled Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Permet aux utilisateurs à distance de modifier les paramètres du Registre sur cet ordinateur. Si ce service est arrêté, le Registre ne pourra être modifié que par les utilisateurs de cet ordinateur. Si ce service est désactivé, tout service en dépendant explicitement ne démarrera pas. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE -P [Auto Services] :HKLM RetailDemo ### Service: Service de démo du magasin Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Le service de démo du magasin contrôle l'activité du périphérique pendant que celui-ci est en mode démo. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K RDXGROUP [Auto Services] :HKLM RmSvc ### Service: Service de gestion radio Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Service de gestion radio et de mode Avion Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICENETWORKRESTRICTED [Auto Services] :HKLM Rockstar Service ### Service: Rockstar Game Library Service Status: Start Type: loaded manually on demand Actual File: D:\PROGRAM FILES\ROCKSTAR GAMES\LAUNCHER\ROCKSTARSERVICE.EXE * This service ensures the integrity of your Rockstar game library and is used to install, update and uninstall titles. Rockstar Games Launcher Service Rockstar Games Rockstar Games Launcher Service 1.0.41.364 !$*"D:\PROGRAM FILES\ROCKSTAR GAMES\LAUNCHER\ROCKSTARSERVICE.EXE" [Auto Services] :HKLM RpcEptMapper ### Service: Mappeur de point de terminaison RPC Status: Start Type: loaded automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Résout les identificateurs des interfaces RPC en points de terminaison de transport. Si ce service est arrêté ou désactivé, les programmes utilisant des services d’appel de procédure distante (RPC) ne fonctionneront pas correctement. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K RPCSS -P [Auto Services] :HKLM RpcLocator ### Service: Localisateur d’appels de procédure distante (RPC) Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\System32\LOCATOR.EXE * Dans Windows 2003 et les versions antérieures de Windows, le service Localisateur d’appels de procédure distante (RPC) gère la base de données du service de nom RPC. Dans Windows Vista et les versions ultérieures de Windows, ce service ne fournit aucune fonctionnalité et est présent à des fins de compatibilité applicative. Localisateur d’appels de procédure distante Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\LOCATOR.EXE [Auto Services] :HKLM RunSwUSB ### Service: RunSwUSB Status: Start Type: loaded automatically by Server Manager Actual File: C:\WINDOWS\RUNSW.EXE * runSW Application 1, 1005, 415, 2014 !$*C:\WINDOWS\RUNSW.EXE [Auto Services] :HKLM SCardSvr ### Service: Carte à puce Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Gère l’accès aux cartes à puce lues par cet ordinateur. Si ce service est arrêté, cet ordinateur ne pourra plus lire de cartes à puces. Si ce service est désactivé, tout service en dépendant explicitement ne démarrera pas. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICEANDNOIMPERSONATION [Auto Services] :HKLM ScDeviceEnum ### Service: Service d’énumération de périphériques de carte à puce Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Crée des nœuds de périphériques logiciels pour tous les lecteurs de cartes à puce accessibles à une session donnée. Si ce service est désactivé, les API WinRT ne peuvent pas énumérer les lecteurs de cartes à puce. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED [Auto Services] :HKLM Schedule ### Service: Planificateur de tâches Status: Start Type: loaded automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Permet à un utilisateur de configurer et de planifier des tâches automatisées sur cet ordinateur. Le service héberge également plusieurs tâches critiques du système Windows. Si ce service est arrêté ou désactivé, ces tâches ne seront pas exécutées à l’heure prévue. Si ce service est désactivé, tout service en dépendant explicitement ne démarrera pas. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS -P [Auto Services] :HKLM SCPolicySvc ### Service: Stratégie de retrait de la carte à puce Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Autorise le système à être configuré pour verrouiller le Bureau de l’utilisateur au moment du retrait de la carte à puce. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS [Auto Services] :HKLM SDRSVC ### Service: Sauvegarde Windows Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Sauvegarde Windows et fonctionnalités de restauration. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K SDRSVC [Auto Services] :HKLM seclogon ### Service: Ouverture de session secondaire Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Permet le démarrage des processus sous d’autres informations d’identification. Si ce service est arrêté, ce type d’ouverture de session sera indisponible. Si ce service est désactivé, tout service en dépendant explicitement ne démarrera pas. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%WINDIR%\SYSTEM32\SVCHOST.EXE -K NETSVCS -P [Auto Services] :HKLM SecurityHealthService ### Service: Service Sécurité Windows Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\System32\SECURITYHEALTHSERVICE.EXE * Le service Sécurité Windows gère la protection unifiée des appareils et les informations d'intégrité Windows Security Health Service Microsoft Corporation Microsoft® Windows® Operating System 4.18.1907.16384 !$*%SYSTEMROOT%\SYSTEM32\SECURITYHEALTHSERVICE.EXE [Auto Services] :HKLM SEMgrSvc ### Service: Gestionnaires des paiements et des éléments sécurisés NFC Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Gère les paiements et les éléments sécurisés basés sur la communication en champ proche (NFC). Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE -P [Auto Services] :HKLM SENS ### Service: Service de notification d’événements système Status: Start Type: loaded automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Analyse les événements système et notifie leur existence aux abonnés du système d’événements COM+. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS -P [Auto Services] :HKLM SensorDataService ### Service: Service Données de capteur Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\System32\SENSORDATASERVICE.EXE * Fournit les données d'une variété de capteurs Service Données de capteur Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SENSORDATASERVICE.EXE [Auto Services] :HKLM SensorService ### Service: Service de capteur Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Service pour les capteurs permettant de gérer différentes fonctionnalités. Gère l'orientation de périphérique simple et l'historique des capteurs. Charge le capteur d'orientation de périphérique simple rapportant les changements d'orientation du périphérique. Si le service est interrompu ou désactivé, le capteur d'orientation de périphérique simple ne sera pas chargé et la rotation automatique n'aura pas lieu. La collecte d'historiques des capteurs sera également interrompue. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED -P [Auto Services] :HKLM SensrSvc ### Service: Service de surveillance des capteurs Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Surveille plusieurs capteurs pour exposer les données et s’adapter aux divers états utilisateur et du système. Si le service est arrêté ou désactivé, la brillance de l’affichage ne s’adaptera pas aux conditions d’éclairage. L’arrêt de ce service peut également affecter d’autres fonctionnalités du système. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICEANDNOIMPERSONATION -P [Auto Services] :HKLM SessionEnv ### Service: Configuration des services Bureau à distance Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Le service Configuration des services Bureau à distance (RDCS) est responsable de toutes les activités de maintenance de session et de configuration du Bureau à distance et des services Bureau à distance nécessitant un contexte SYSTEM. Il faut y inclure les dossiers temporaires par session, ainsi que les thèmes et certificats des services Bureau à distance. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS -P [Auto Services] :HKLM SgrmBroker ### Service: Service Broker du moniteur d'exécution System Guard Status: Start Type: loaded automatically by Server Manager Actual File: C:\WINDOWS\System32\SGRMBROKER.EXE * Surveille et garantit l'intégrité de la plateforme Windows. Service Broker du moniteur d'exécution System Guard Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SGRMBROKER.EXE [Auto Services] :HKLM SharedAccess ### Service: Partage de connexion Internet (ICS) Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Assure la traduction d’adresses de réseau, l’adressage, les services de résolution de noms et/ou les services de prévention d’intrusion pour un réseau de petite entreprise ou un réseau domestique. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS -P [Auto Services] :HKLM SharedRealitySvc ### Service: Service de données spatiales Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Ce service est utilisé pour les scénarios de la Perception spatiale Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE -P [Auto Services] :HKLM ShellHWDetection ### Service: Détection matériel noyau Status: Start Type: loaded automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Fournit des notifications à des événements matériel de lecture automatique. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS -P [Auto Services] :HKLM shpamsvc ### Service: Shared PC Account Manager Status: Start Type: disabled Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Manages profiles and accounts on a SharedPC configured device Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS -P [Auto Services] :HKLM smphost ### Service: SMP de l’Espace de stockages Microsoft Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Service hôte du fournisseur de gestion de l’Espace de stockages Microsoft. Si ce service est arrêté ou désactivé, l’Espace de stockages ne peut pas être géré. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K SMPHOST [Auto Services] :HKLM SmsRouter ### Service: Service Routeur SMS Microsoft Windows. Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Achemine les messages vers les clients appropriés sur la base de règles. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICENETWORKRESTRICTED -P [Auto Services] :HKLM SNMPTRAP ### Service: Interruption SNMP Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\System32\SNMPTRAP.EXE * Reçoit les messages d’interception générés par les agents SNMP (Simple Network Management Protocol) locaux ou distants et transmet les messages aux programmes de gestion SNMP s’exécutant sur cet ordinateur. Si ce service est arrêté, les programmes à base SNMP sur cet ordinateur ne recevront pas les messages d’interception SNMP. Si ce service est désactivé, tous les services qui en dépendent explicitement ne pourront pas démarrer. Interruption SNMP Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SNMPTRAP.EXE [Auto Services] :HKLM spectrum ### Service: Service de perception Windows Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\System32\SPECTRUM.EXE * Active la perception spatiale, les entrées spatiales et le rendu holographique. Service de perception Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SPECTRUM.EXE [Auto Services] :HKLM Spooler ### Service: Spouleur d’impression Status: Start Type: loaded automatically by Server Manager Actual File: C:\WINDOWS\System32\SPOOLSV.EXE * Ce service met en spoule les travaux d’impression et gère l’interaction avec l’imprimante. Si vous arrêtez ce service, vous ne pourrez plus imprimer ni voir vos imprimantes. Application sous-système spouleur Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SPOOLSV.EXE [Auto Services] :HKLM sppsvc ### Service: Protection logicielle Status: Start Type: loaded automatically by Server Manager Actual File: C:\WINDOWS\System32\SPPSVC.EXE * Permet le téléchargement, l’installation et l’application de licences numériques pour Windows et des applications Windows. Si le service est désactivé, le système d’exploitation et les applications sous licence peuvent s’exécuter dans un mode de notification. Et il est instamment recommandé de ne pas désactiver le service de protection logicielle. Service de la plateforme de protection logicielle Microsoft Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SPPSVC.EXE [Auto Services] :HKLM SSDPSRV ### Service: Découverte SSDP Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Découvre les périphériques et services en réseau qui utilisent le protocole de découverte SSDP, tels que les périphériques UPnP. Annonce également les périphériques et services SSDP exécutés sur l’ordinateur local. Si ce service est arrêté, les périphériques SSDP ne seront pas découverts. S’il est désactivé, tous les services qui dépendent explicitement de lui ne démarreront pas. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICEANDNOIMPERSONATION -P [Auto Services] :HKLM ssh-agent ### Service: OpenSSH Authentication Agent Status: Start Type: disabled Actual File: C:\WINDOWS\System32\OPENSSH\SSH-AGENT.EXE * Agent to hold private keys used for public key authentication. OpenSSH for Windows OpenSSH_8.1p1 for Windows !$*%SYSTEMROOT%\SYSTEM32\OPENSSH\SSH-AGENT.EXE [Auto Services] :HKLM SstpSvc ### Service: Service SSTP (Secure Socket Tunneling Protocol) Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Prend en charge la connexion par le protocole SSTP (Secure Socket Tunneling Protocol) à des ordinateurs distants via un réseau VPN. Si ce service est désactivé, les utilisateurs ne peuvent pas utiliser le protocole SSTP pour accéder à des serveurs distants. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE -P [Auto Services] :HKLM StateRepository ### Service: Service State Repository (StateRepository) Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Fournit la prise en charge d'infrastructure nécessaire au modèle d'application. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K APPMODEL -P [Auto Services] :HKLM Steam Client Service ### Service: Steam Client Service Status: Start Type: loaded manually on demand Actual File: C:\PROGRAM FILES (X86)\COMMON FILES\STEAM\STEAMSERVICE.EXE * Steam Client Service monitors and updates Steam content Steam Client Service Valve Corporation Steam Client Service 01.00.00.01 ->STEAM CLIENT SERVICE (BUILDBOT_STEAM-RELCLIENT-WIN32-BUILDER_STEAM_REL_CLIENT_WIN32@STEAM-RELCLIENT-WIN32-BUILDER) !$*"C:\PROGRAM FILES (X86)\COMMON FILES\STEAM\STEAMSERVICE.EXE" /RUNASSERVICE [Auto Services] :HKLM SteelSeriesUpdateService ### Service: SteelSeries Update Service Status: Start Type: loaded manually on demand Actual File: C:\PROGRAM FILES\STEELSERIES\STEELSERIES ENGINE 3\STEELSERIESUPDATESERVICE.EXE * Handles update and setup operations for SteelSeries software SteelSeriesUpdateService SteelSeriesUpdateService 1.0.0.0 !$*"C:\PROGRAM FILES\STEELSERIES\STEELSERIES ENGINE 3\STEELSERIESUPDATESERVICE.EXE" [Auto Services] :HKLM stisvc ### Service: Acquisition d’image Windows (WIA) Status: Start Type: loaded automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Fournit des services d’acquisition d’images pour les scanneurs et les appareils photo. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K IMGSVC [Auto Services] :HKLM StorSvc ### Service: Service de stockage Status: Start Type: loaded automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Fournit des services d'activation pour les paramètres de stockage et l'extension de stockage externe Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED -P [Auto Services] :HKLM svsvc ### Service: Vérificateur de points Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Vérifie les endommagements potentiels du système de fichiers. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED -P [Auto Services] :HKLM swprv ### Service: Fournisseur de cliché instantané de logiciel Microsoft Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Gère les copies logicielles de clichés instantanés de volumes créés par le service de cliché instantané de volumes. Si ce service est arrêté, les copies logicielles de clichés instantanés ne peuvent pas être gérées. Si le service est désactivé, les services qui en dépendent ne pourront pas démarrer. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K SWPRV [Auto Services] :HKLM SysMain ### Service: SysMain Status: Start Type: loaded automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Gère et améliore les performances du système dans le temps. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED -P [Auto Services] :HKLM SystemEventsBroker ### Service: Service Broker des événements système Status: Start Type: loaded automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Coordonne l’exécution de travail en arrière-plan pour l’application WinRT. Si ce service est arrêté ou désactivé, le travail en arrière-plan risque de ne pas être déclenché. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K DCOMLAUNCH -P [Auto Services] :HKLM TabletInputService ### Service: Service du clavier tactile et du volet d’écriture manuscrite Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Active les fonctionnalités de stylet et d’entrée manuscrite du clavier tactile et du volet d’écriture manuscrite Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED -P [Auto Services] :HKLM TapiSrv ### Service: Téléphonie Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Prend en charge l’interface TAPI (Telephony API) pour les programmes qui contrôlent les périphériques de téléphonie sur l’ordinateur local et, via le réseau local (LAN), sur les serveurs qui exécutent également le service. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETWORKSERVICE -P [Auto Services] :HKLM TeamViewer ### Service: TeamViewer Status: Start Type: loaded automatically by Server Manager Actual File: C:\PROGRAM FILES\TEAMVIEWER\TEAMVIEWER_SERVICE.EXE * TeamViewer Remote Software TeamViewer TeamViewer Germany GmbH TeamViewer 15.16.8.0 ->TEAMVIEWER !$*"C:\PROGRAM FILES\TEAMVIEWER\TEAMVIEWER_SERVICE.EXE" [Auto Services] :HKLM TermService ### Service: Services Bureau à distance Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Autorise les utilisateurs à se connecter de manière interactive à un ordinateur distant. Le Bureau à distance et le serveur hôte de session Bureau à distance dépendent de ce service. Pour empêcher l’utilisation à distance de cet ordinateur, désactivez les cases à cocher situées sous l’onglet Utilisation à distance des Propriétés système via l’élément Système du Panneau de configuration. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETWORKSERVICE [Auto Services] :HKLM Themes ### Service: Thèmes Status: Start Type: loaded automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Fournit un système de gestion de thème de l’expérience utilisateur. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS -P [Auto Services] :HKLM TieringEngineService ### Service: Gestion des niveaux de stockage Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\System32\TIERINGENGINESERVICE.EXE * Optimise le placement des données dans les niveaux de stockage de tous les espaces de stockage à plusieurs niveaux sur le système. Gestion des niveaux de stockage Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\TIERINGENGINESERVICE.EXE [Auto Services] :HKLM TimeBrokerSvc ### Service: Service Broker pour les événements horaires Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Coordonne l’exécution de travail en arrière-plan pour l’application WinRT. Si ce service est arrêté ou désactivé, le travail en arrière-plan risque de ne pas être déclenché. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICENETWORKRESTRICTED -P [Auto Services] :HKLM TokenBroker ### Service: Gestionnaire de comptes web Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Ce service est utilisé par le Gestionnaire de comptes web pour fournir une authentification unique aux applications et aux services. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS -P [Auto Services] :HKLM TroubleshootingSvc ### Service: Service de résolution des problèmes recommandé Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Permet l'atténuation automatique pour des problèmes connus en appliquant la résolution des problèmes recommandée. S'il est arrêté, votre appareil n'obtiendra pas la résolution des problèmes recommandée pour les problèmes de votre appareil. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS -P [Auto Services] :HKLM tzautoupdate ### Service: Programme de mise à jour automatique du fuseau horaire Status: Start Type: disabled Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Définit automatiquement le fuseau horaire système. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE -P [Auto Services] :HKLM udfs ### Driver: udfs Status: Start Type: disabled Actual File: C:\WINDOWS\SYSTEM32\DRIVERS\UDFS.SYS * Reads/Writes UDF 1.02,1.5,2.0x,2.5 disc formats, usually found on C/DVD discs. (Core) (All pieces) UDF File System Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*C:\WINDOWS\SYSTEM32\DRIVERS\UDFS.SYS [Auto Services] :HKLM UdkUserSvc ### Service: Service utilisateur du kit de développement sans station d’accueil Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Service de composants d'environnement Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K UDKSVCGROUP [Auto Services] :HKLM UdkUserSvc_1a8ea6 ### Service: Service utilisateur du kit de développement sans station d’accueil_1a8ea6 Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Service de composants d'environnement Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K UDKSVCGROUP [Auto Services] :HKLM UmRdpService ### Service: Redirecteur de port du mode utilisateur des services Bureau à distance Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Permet la redirection des imprimantes/unités/ports pour les connexions RDP Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED -P [Auto Services] :HKLM UnistoreSvc ### Service: Stockage des données utilisateur Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Gère le stockage des données utilisateur structurées, notamment les coordonnées, les calendriers, les messages et d’autres éléments de contenu. Si vous arrêtez ou désactivez ce service, les applications qui utilisent ces données risquent de ne pas fonctionner correctement. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K UNISTACKSVCGROUP [Auto Services] :HKLM UnistoreSvc_1a8ea6 ### Service: Stockage des données utilisateur_1a8ea6 Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Gère le stockage des données utilisateur structurées, notamment les coordonnées, les calendriers, les messages et d’autres éléments de contenu. Si vous arrêtez ou désactivez ce service, les applications qui utilisent ces données risquent de ne pas fonctionner correctement. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K UNISTACKSVCGROUP [Auto Services] :HKLM Updater ### Service: Updater Status: Start Type: loaded manually on demand Actual File: D:\PROGRAM FILES\VIRTUAL DESKTOP STREAMER\UPDATER.EXE * Updater Support Service Updater 1.20.7 Virtual Desktop, Inc. Virtual Desktop Streamer 1.20.7 !$*"D:\PROGRAM FILES\VIRTUAL DESKTOP STREAMER\UPDATER.EXE" /RUNSERVICE [Auto Services] :HKLM upnphost ### Service: Hôte de périphérique UPnP Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Autorise l’hébergement des périphériques UPnP sur cet ordinateur. Si ce service est arrêté, tous les périphériques UPnP hébergés cesseront de fonctionner et aucun autre périphérique hébergé ne pourra être ajouté. Si ce service est désactivé, tous les services qui dépendent explicitement de lui ne démarreront pas. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICEANDNOIMPERSONATION -P [Auto Services] :HKLM UserDataSvc ### Service: Accès aux données utilisateur Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Fournit l’accès des applications aux données utilisateur structurées, notamment aux coordonnées, calendriers, messages et autres éléments de contenu. Si vous arrêtez ou désactivez ce service, les applications qui utilisent ces données risquent de ne pas fonctionner correctement. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K UNISTACKSVCGROUP [Auto Services] :HKLM UserDataSvc_1a8ea6 ### Service: Accès aux données utilisateur_1a8ea6 Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Fournit l’accès des applications aux données utilisateur structurées, notamment aux coordonnées, calendriers, messages et autres éléments de contenu. Si vous arrêtez ou désactivez ce service, les applications qui utilisent ces données risquent de ne pas fonctionner correctement. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K UNISTACKSVCGROUP [Auto Services] :HKLM UserManager ### Service: Gestionnaire des utilisateurs Status: Start Type: loaded automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Le Gestionnaire des utilisateurs fournit les composants d'exécution requis pour une interaction multi-utilisateur. Si ce service est arrêté, certaines applications risquent de ne pas fonctionner correctement. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS -P [Auto Services] :HKLM UsoSvc ### Service: Mettre à jour le service Orchestrator Status: Start Type: loaded automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Gère les mises à jour Windows. Si cette fonctionnalité est arrêtée, vos appareils ne pourront pas télécharger ni installer les dernières mises à jour. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS -P [Auto Services] :HKLM VacSvc ### Service: Service de composition audio volumétrique Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Héberge l'analyse spatiale pour la simulation audio de Mixed Reality. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICENETWORKRESTRICTED -P [Auto Services] :HKLM VaultSvc ### Service: Gestionnaire d’informations d’identification Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\System32\LSASS.EXE * Offre un service de stockage et de récupération sécurisé des informations d’identification pour les utilisateurs, les applications et les packages de services de sécurité. Local Security Authority Process Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.906 !$*%SYSTEMROOT%\SYSTEM32\LSASS.EXE [Auto Services] :HKLM vds ### Service: Disque virtuel Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\System32\VDS.EXE * Fournit des services de gestion des disques, des volumes, des systèmes de fichiers et des groupes de stockage. Service de disque virtuel Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\VDS.EXE [Auto Services] :HKLM VerifierExt ### Driver: Extension du vérificateur de pilotes Status: Start Type: disabled Actual File: C:\WINDOWS\SYSTEM32\DRIVERS\VERIFIEREXT.SYS * Composant du vérificateur de pilotes contribuant à la détection de bogues dans les pilotes des appareils. Extension du vérificateur de pilotes Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\SYSTEM32\DRIVERS\VERIFIEREXT.SYS [Auto Services] :HKLM VirtualDesktop.Service.exe ### Service: Virtual Desktop Service Status: Start Type: loaded automatically by Server Manager Actual File: C:\PROGRAM FILES\VIRTUAL DESKTOP\VIRTUALDESKTOP.SERVICE.EXE * Provides background services for Virtual Desktop. Virtual Desktop Service Virtual Desktop, Inc. Virtual Desktop 1.18.5.0 !$*"C:\PROGRAM FILES\VIRTUAL DESKTOP\VIRTUALDESKTOP.SERVICE.EXE" [Auto Services] :HKLM vmicguestinterface ### Service: Interface de services d’invité Hyper-V Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Fournit une interface à l’hôte Hyper-V afin qu’il puisse interagir avec des services spécifiques s’exécutant sur l’ordinateur virtuel. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED -P [Auto Services] :HKLM vmicheartbeat ### Service: Service Pulsation Microsoft Hyper-V Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Surveille l‘état de cet ordinateur virtuel en émettant une pulsation à intervalles réguliers. Ce service vous permet d’identifier les ordinateurs virtuels en cours d’exécution qui ne répondent plus. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K ICSERVICE -P [Auto Services] :HKLM vmickvpexchange ### Service: Service Échange de données Microsoft Hyper-V Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Propose un mécanisme d’échange de données entre l’ordinateur virtuel et le système d’exploitation exécuté sur l’ordinateur physique. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED -P [Auto Services] :HKLM vmicrdv ### Service: Service de virtualisation Bureau à distance Hyper-V Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Fournit une plateforme pour la communication entre l’ordinateur virtuel et le système d’exploitation exécuté sur l’ordinateur physique. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K ICSERVICE -P [Auto Services] :HKLM vmicshutdown ### Service: Service Arrêt de l’invité Microsoft Hyper-V Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Propose un mécanisme permettant d’arrêter le système d’exploitation de cet ordinateur virtuel à partir des interfaces de gestion de l’ordinateur physique. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED -P [Auto Services] :HKLM vmictimesync ### Service: Service Synchronisation date/heure Microsoft Hyper-V Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Synchronise l’heure système de cet ordinateur virtuel avec l’heure système de l’ordinateur physique. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICENETWORKRESTRICTED -P [Auto Services] :HKLM vmicvmsession ### Service: Service Hyper-V PowerShell Direct Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Fournit un mécanisme de gestion des ordinateurs virtuels avec PowerShell via une session d'ordinateur virtuel sans réseau virtuel. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED -P [Auto Services] :HKLM vmicvss ### Service: Requête du service VSS Microsoft Hyper-V Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Coordonne les communications nécessaires à l’utilisation du service VSS afin de sauvegarder les applications et les données de cet ordinateur virtuel à partir du système d’exploitation de l’ordinateur physique. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED -P [Auto Services] :HKLM VSS ### Service: Cliché instantané des volumes Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\System32\VSSVC.EXE * Gère et implémente les clichés instantanés de volumes pour les sauvegardes et autres utilisations. Si ce service est arrêté, les clichés instantanés ne seront pas disponibles pour la sauvegarde et la sauvegarde échouera. Si ce service est désactivé, les services en dépendant explicitement ne démarreront pas. Service de cliché instantané de volumes Microsoft® Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\VSSVC.EXE [Auto Services] :HKLM W32Time ### Service: Temps Windows Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Conserve la synchronisation de la date et de l’heure sur tous les clients et serveurs sur le réseau. Si ce service est arrêté, la synchronisation de la date et de l’heure sera indisponible. Si ce service est désactivé, tout service en dépendant explicitement ne démarrera pas. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE [Auto Services] :HKLM WaaSMedicSvc ### Service: @WaaSMedicSvc.dll,-100 Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Active la correction et la protection des composants Windows Update. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K WUSVCS -P [Auto Services] :HKLM WalletService ### Service: WalletService Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Objets d'hôtes utilisés par les clients du portefeuille Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K APPMODEL -P [Auto Services] :HKLM Wallpaper Engine Service ### Service: Wallpaper Engine Service Status: Start Type: loaded automatically by Server Manager Actual File: D:\STEAMLIBRARY\STEAMAPPS\COMMON\WALLPAPER_ENGINE\BIN\WALLPAPERSERVICE32_C.EXE * !$*"D:\STEAMLIBRARY\STEAMAPPS\COMMON\WALLPAPER_ENGINE\BIN\WALLPAPERSERVICE32_C.EXE" [Auto Services] :HKLM WarpJITSvc ### Service: WarpJITSvc Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Provides a JIT out of process service for WARP when running with ACG enabled. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICENETWORKRESTRICTED [Auto Services] :HKLM wbengine ### Service: Service de moteur de sauvegarde en mode bloc Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\System32\WBENGINE.EXE * Le service WBENGINE est utilisé par la sauvegarde Windows pour effectuer les opérations de sauvegarde et de récupération. Si ce service est arrêté par un utilisateur, l’opération de sauvegarde ou de récupération en cours risque d’échouer. La désactivation de ce service peut désactiver les opérations de sauvegarde et de récupération effectuées à l’aide de la sauvegarde Windows sur cet ordinateur. Exécutable du service de moteur de sauvegarde en mode bloc Microsoft® Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*"%SYSTEMROOT%\SYSTEM32\WBENGINE.EXE" [Auto Services] :HKLM WbioSrvc ### Service: Service de biométrie Windows Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Le service de biométrie Windows permet aux applications clientes de capturer, comparer, manipuler et stocker des données biométriques sans avoir directement accès au matériel ou aux échantillons. Le service est hébergé dans un processus SVCHOST privilégié. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K WBIOSVCGROUP [Auto Services] :HKLM Wcmsvc ### Service: Gestionnaire des connexions Windows Status: Start Type: loaded automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Prends des décisions automatiques de connexion/déconnexion en fonction des options de connectivité réseau actuellement disponibles à l’ordinateur, et active la gestion de la connectivité réseau en fonction des paramètres de la stratégie de groupe. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICENETWORKRESTRICTED -P [Auto Services] :HKLM wcncsvc ### Service: Windows Connect Now - Registre de configuration Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * WCNCSVC héberge la configuration de connexion immédiate Windows, qui est l'implémentation Microsoft du protocole WPS (Wireless Protected Setup). On l'utilise pour configurer des paramètres de réseau local sans fil pour un point d'accès ou un périphérique sans fil. Le service est démarré par programme en cas de besoin. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICEANDNOIMPERSONATION -P [Auto Services] :HKLM WdNisSvc ### Service: Service d’inspection réseau de l’antivirus Microsoft Defender Status: Start Type: loaded manually on demand Actual File: C:\ProgramData\MICROSOFT\WINDOWS DEFENDER\PLATFORM\4.18.2105.5-0\NISSRV.EXE * Empêche les tentatives d’intrusion ciblant les vulnérabilités connues et nouvellement découvertes des protocoles réseau Microsoft Network Realtime Inspection Service Microsoft Corporation Microsoft® Windows® Operating System 4.18.2105.5 !$*"%PROGRAMDATA%\MICROSOFT\WINDOWS DEFENDER\PLATFORM\4.18.2105.5-0\NISSRV.EXE" [Auto Services] :HKLM WebClient ### Service: WebClient Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Permet à un programme fonctionnant sous Windows de créer, modifier et accéder à des fichiers Internet. Si ce service est arrêté, ces fonctions ne sont pas disponibles. Si ce service est désactivé, tous les services qui en dépendent explicitement ne peuvent plus démarrer. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE -P [Auto Services] :HKLM Wecsvc ### Service: Collecteur d’événements de Windows Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Ce service gère des abonnements persistants à des événements de sources distantes prenant en charge le protocole Gestion de services Web. Cela inclut les journaux d’événements de Windows Vista, les sources d’événements matériels et IPMI. Le service stocke les événements transférés dans un journal d’événements local. Si ce service est arrêté ou désactivé, des abonnements aux événements ne peuvent pas être créés et les événements transférés ne peuvent pas être acceptés. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETWORKSERVICE -P [Auto Services] :HKLM WEPHOSTSVC ### Service: Service hôte du fournisseur de chiffrement Windows Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Le service hôte du fournisseur de chiffrement Windows négocie les fonctionnalités liées au chiffrement avec les fournisseurs de chiffrement tiers pour les processus qui ont besoin d’évaluer et d’appliquer des stratégies EAS. L’arrêt de cette activité compromettra les vérifications de conformité EAS qui ont été établies par les comptes de messagerie connectés. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K WEPHOSTSVCGROUP [Auto Services] :HKLM wercplsupport ### Service: Prise en charge du Panneau de configuration Rapports de problèmes Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Ce service prend en charge l’affichage, l’envoi et la suppression de rapports de problèmes au niveau du système pour l’application Rapports de problèmes du Panneau de configuration. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS -P [Auto Services] :HKLM WerSvc ### Service: Service de rapport d’erreurs Windows Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Autorise le signalement des erreurs lorsque des programmes cessent de fonctionner ou de répondre, ainsi que la fourniture de solutions existantes. Autorise également la génération de journaux pour les services de diagnostic et de réparation. Si ce service est arrêté, le signalement des erreurs risque de ne pas fonctionner correctement ; par ailleurs, les résultats des services de diagnostic et de réparation risquent de ne pas s’afficher. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K WERSVCGROUP [Auto Services] :HKLM WFDSConMgrSvc ### Service: Service Wi-Fi Direct Service de gestionnaire de connexions Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Gère les connexions aux services sans fil, y compris l’affichage sans fil et la station d’accueil. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICENETWORKRESTRICTED -P [Auto Services] :HKLM WiaRpc ### Service: Événements d’acquisition d’images fixes Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Lance les applications associées aux événements d’acquisition d’images fixes. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED -P [Auto Services] :HKLM WinDefend ### Service: Service antivirus Microsoft Defender Status: Start Type: loaded automatically by Server Manager Actual File: C:\PROGRAMDATA\MICROSOFT\WINDOWS DEFENDER\PLATFORM\4.18.2105.5-0\MSMPENG.EXE * Protège les utilisateurs contre les logiciels malveillants et les autres logiciels potentiellement indésirables Antimalware Service Executable Microsoft Corporation Microsoft® Windows® Operating System 4.18.2105.5 !$*"C:\PROGRAMDATA\MICROSOFT\WINDOWS DEFENDER\PLATFORM\4.18.2105.5-0\MSMPENG.EXE" [Auto Services] :HKLM WinHttpAutoProxySvc ### Service: Service de découverte automatique de Proxy Web pour les services HTTP Windows Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * WinHTTP implémente la pile HTTP du client et fournit aux développeurs une API Win32 et un composant d’automatisation COM pour l’envoi des demandes HTTP et la réception des réponses. En outre, WinHTTP prend en charge la découverte automatique d’une configuration de proxy via son implémentation du protocole WPAD (Web Proxy Auto-Discovery). Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICENETWORKRESTRICTED -P [Auto Services] :HKLM Winmgmt ### Service: Infrastructure de gestion Windows Status: Start Type: loaded automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Fournit une interface commune et un modèle objet pour accéder aux informations de gestion du système d’exploitation, des périphériques, des applications et des services. Si ce service est arrêté, la plupart des logiciels sur base Windows ne fonctionneront pas correctement. Si ce service est désactivé, tout service qui en dépend explicitement ne démarrera pas. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS -P [Auto Services] :HKLM WinRM ### Service: Gestion à distance de Windows (Gestion WSM) Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Le service Gestion à distance de Windows implémente le protocole Gestion des services Web pour la gestion à distance. La Gestion des services Web est un protocole standard utilisé pour la gestion à distance de logiciels et de matériels. Le service Gestion à distance de Windows traite les demandes Gestion des services Web. Il doit être configuré à l’aide de l’outil winrm.cmd ou via la stratégie de groupe. Ce service donne accès aux données WMI et permet le recueil d’événements. Le recueil d’événements et l’abonnement exigent que ce service s'exécute. Les messages du service Gestion à distance de Windows utilisent HTTP et HTTPS. Le service Gestion à distance de Windows ne dépend pas d’IIS mais partage un port avec IIS sur la même machine. Le service Gestion à distance de Windows réserve le préfixe d’URL /wsman. Pour éviter les conflits avec IIS, vérifiez que les sites Web hébergés sur IIS n’utilisent pas le préfixe d’URL /wsman. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETWORKSERVICE -P [Auto Services] :HKLM wisvc ### Service: Service Windows Insider Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Offre la prise en charge de l'infrastructure pour le Programme Windows Insider. Ce service doit rester actif pour que le Programme Windows Insider fonctionne. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS -P [Auto Services] :HKLM WlanSvc ### Service: Service de configuration automatique WLAN Status: Start Type: loaded automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Le service WLANSVC fournit la logique nécessaire pour configurer, découvrir, se connecter et se déconnecter d’un réseau local sans fil (WLAN) tel que défini par les normes IEEE 802.11. Il contient également la logique permettant de convertir votre ordinateur en un point d’accès logiciel de sorte que d’autres périphériques ou ordinateurs puissent se connecter à votre ordinateur sans fil à l’aide d’une carte WLAN prenant en charge cette fonctionnalité. L’arrêt ou la désactivation du service WLANSVC rendront toutes les cartes WLAN sur votre ordinateur inaccessibles à partir de l’interface utilisateur de mise en réseau Windows. Il est vivement recommandé d’exécuter le service WLANSVC si votre ordinateur possède une carte WLAN. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED -P [Auto Services] :HKLM wlidsvc ### Service: Assistant Connexion avec un compte Microsoft Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Autorise la connexion des utilisateurs par le biais des services d’identité de compte Microsoft. Si ce service est arrêté, les utilisateurs ne pourront pas ouvrir une session sur l’ordinateur avec leur compte Microsoft. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS -P [Auto Services] :HKLM wlpasvc ### Service: Service de l’Assistant de profil local Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Ce service fournit la gestion du profil pour les modules d’identité d’abonné Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICENETWORKRESTRICTED -P [Auto Services] :HKLM WManSvc ### Service: Service de gestion de Windows Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Effectue la gestion, notamment les activités d'approvisionnement et d'inscription Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS -P [Auto Services] :HKLM wmiApSrv ### Service: Carte de performance WMI Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\System32\WBEM\WMIAPSRV.EXE * Fournit des informations concernant la bibliothèque de performance à partir des fournisseurs HiPerf WMI (Windows Management Instrumentation) à des clients sur le réseau. Ce service s’exécute uniquement quand l’assistant de performance des données est activé. Adaptateur inverse de performance WMI Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\WBEM\WMIAPSRV.EXE [Auto Services] :HKLM WMPNetworkSvc ### Service: Service Partage réseau du Lecteur Windows Media Status: Start Type: loaded manually on demand Actual File: C:\Program Files\WINDOWS MEDIA PLAYER\WMPNETWK.EXE * Partage les bibliothèques du Lecteur Windows Media avec des lecteurs réseau et des appareils multimédias qui utilisent le Plug-and-Play universel Service Partage réseau du Lecteur Windows Media Microsoft Corporation Système d’exploitation Microsoft® Windows® 12.0.19041.1 ->WINDOWS MEDIA PLAYER NETWORK SHARING SERVICE !$*"%PROGRAMFILES%\WINDOWS MEDIA PLAYER\WMPNETWK.EXE" [Auto Services] :HKLM workfolderssvc ### Service: Dossiers de travail Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Ce service synchronise des fichiers avec le serveur Dossiers de travail, vous permettant ainsi d’utiliser ces fichiers sur tous les PC et appareils sur lesquels vous avez configuré la fonctionnalité Dossiers de travail. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE -P [Auto Services] :HKLM WpcMonSvc ### Service: Contrôle parental Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Applique le contrôle parental aux comptes enfant dans Windows. Si ce service est arrêté ou désactivé, le contrôle parental peut ne pas être appliqué. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE [Auto Services] :HKLM WPDBusEnum ### Service: Service Énumérateur d’appareil mobile Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Met en place une stratégie de groupe pour les dispositifs de stockage de masse amovibles. Permet à des applications telles que le Lecteur Windows Media et l’Assistant Importation d’images de transférer et de synchroniser du contenu à l’aide de dispositifs de stockage de masse amovibles. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED [Auto Services] :HKLM WpnService ### Service: Service du système de notifications Push Windows Status: Start Type: loaded automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Ce service s’exécute dans la session 0 et héberge la plateforme de notification et le fournisseur de connexion qui gère la connexion entre l’appareil et le serveur WNS. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS -P [Auto Services] :HKLM WpnUserService ### Service: Service utilisateur de notifications Push Windows Status: Start Type: loaded automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Ce service héberge la plateforme de notification Windows qui fournit la prise en charge des notifications locales et Push. Les notifications prises en charge sont tile, toast et raw. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K UNISTACKSVCGROUP [Auto Services] :HKLM WpnUserService_1a8ea6 ### Service: Service utilisateur de notifications Push Windows_1a8ea6 Status: Start Type: loaded automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Ce service héberge la plateforme de notification Windows qui fournit la prise en charge des notifications locales et Push. Les notifications prises en charge sont tile, toast et raw. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K UNISTACKSVCGROUP [Auto Services] :HKLM ws2ifsl ### Driver: Pilote IFS Winsock Status: Start Type: disabled Actual File: C:\WINDOWS\SYSTEM32\DRIVERS\WS2IFSL.SYS * Pilote IFS Winsock Couche IFS Winsock2 Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\SYSTEM32\DRIVERS\WS2IFSL.SYS [Auto Services] :HKLM wscsvc ### Service: Centre de sécurité Status: Start Type: loaded automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Le service WSCSVC (Centre de sécurité Windows) surveille et affiche les paramètres d'intégrité de la sécurité de l'ordinateur. Parmi les paramètres d'intégrité figurent ceux du pare-feu (activé/désactivé), de l'antivirus (activé/désactivé/périmé), du logiciel anti-espion (activé/désactivé/périmé), de Windows Update (téléchargement et installation automatiques/manuels des mises à jour), du Contrôle de compte d'utilisateur (activé/désactivé) et des paramètres Internet (recommandés/non recommandés). Le service fournit des API COM à l'intention des éditeurs de logiciels indépendants pour qu'ils s'inscrivent et enregistrent l'état de leurs produits auprès du service Centre de sécurité. L'interface utilisateur de la fonctionnalité Sécurité et maintenance utilise le service pour fournir des alertes dans la zone de notification et une vue graphique des états d'intégrité de la sécurité dans le panneau de configuration de Sécurité et maintenance. La Protection d'accès réseau (NAP) utilise le service pour signaler les états d'intégrité de la sécurité des clients au serveur NPS (Network Policy Server) et prendre les décisions de mise en quarantaine réseau. Le service contient également une API publique permettant aux consommateurs externes de récupérer par programme l'état d'intégrité consolidé de la sécurité du système. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSERVICENETWORKRESTRICTED -P [Auto Services] :HKLM WSearch ### Service: Windows Search Status: Start Type: loaded automatically by Server Manager Actual File: C:\WINDOWS\SYSTEM32\SEARCHINDEXER.EXE * Fournit des fonctionnalités d’indexation de contenu, de mise en cache des propriétés, de résultats de recherche pour les fichiers, les messages électroniques et autres contenus. Indexeur Microsoft Windows Search Microsoft Corporation Windows® Search 7.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SEARCHINDEXER.EXE /EMBEDDING [Auto Services] :HKLM wuauserv ### Service: Windows Update Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Active la détection, le téléchargement et l’installation des mises à jour de Windows et d’autres programmes. Si ce service est désactivé, les utilisateurs de cet ordinateur ne pourront pas utiliser Windows Update ou sa fonctionnalité de mise à jour automatique, et les programmes ne pourront pas utiliser l’API de l’Agent de mise à jour automatique Windows Update (WUA). Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS -P [Auto Services] :HKLM WwanSvc ### Service: Service de configuration automatique WWAN Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Ce service gère les connexions et adaptateurs de module intégré/carte de données à haut débit mobile (GSM & CDMA) en configurant automatiquement les réseaux. Il est vivement recommandé de laisser ce service s’exécuter afin d’améliorer l’expérience des utilisateurs de haut débit mobile. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED -P [Auto Services] :HKLM XblAuthManager ### Service: Gestionnaire d'authentification Xbox Live Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Fournit des services d'authentification et d'autorisation pour interagir avec Xbox Live. Si ce service est arrêté, certaines applications peuvent ne pas fonctionner correctement. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS -P [Auto Services] :HKLM XblGameSave ### Service: Jeu sauvegardé sur Xbox Live Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Ce service synchronise les données enregistrées pour les jeux dont la sauvegarde sur Xbox Live est activée. Si ce service est arrêté, les données enregistrées des jeux ne seront téléchargées ni vers, ni depuis Xbox Live. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS -P [Auto Services] :HKLM XboxGipSvc ### Service: Xbox Accessory Management Service Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * This service manages connected Xbox Accessories. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS -P [Auto Services] :HKLM XboxNetApiSvc ### Service: Service de mise en réseau Xbox Live Status: Start Type: loaded manually on demand Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE * Ce service prend en charge l'interface de programmation d'application Windows.Networking.XboxLive. Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE -K NETSVCS -P [Auto Services] :HKLM ZeroTierOneService ### Service: ZeroTier One Status: Start Type: loaded automatically by Server Manager Actual File: C:\PROGRAMDATA\ZEROTIER\ONE\ZEROTIER-ONE_X64.EXE * Ethernet Virtualization Service !$*C:\PROGRAMDATA\ZEROTIER\ONE\ZEROTIER-ONE_X64.EXE [Auto Services] :HKLM DCOMLAUNCH ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K DCOMLAUNCH -P Service registry key doesn't exist or hidden. Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE WMI!!! [Auto Services] :HKLM DPS ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K LOCALSERVICENONETWORK -P Service registry key doesn't exist or hidden. Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE WMI!!! [Auto Services] :HKLM GPSVC ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS -P Service registry key doesn't exist or hidden. Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE WMI!!! [Auto Services] :HKLM RPCSS ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K RPCSS -P Service registry key doesn't exist or hidden. Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE WMI!!! [Auto Services] :HKLM SAMSS ### Local Security Authority Process Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.906 !$*C:\WINDOWS\SYSTEM32\LSASS.EXE Service registry key doesn't exist or hidden. Actual File: C:\WINDOWS\SYSTEM32\LSASS.EXE WMI!!! [Auto Services] :HKLM TRKWKS ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED -P Service registry key doesn't exist or hidden. Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE WMI!!! [Auto Services] :HKLM TRUSTEDINSTALLER ### Programme d’installation pour les modules Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\SERVICING\TRUSTEDINSTALLER.EXE Service registry key doesn't exist or hidden. Actual File: C:\WINDOWS\SERVICING\TRUSTEDINSTALLER.EXE WMI!!! [Auto Services] :HKLM WDISERVICEHOST ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE -P Service registry key doesn't exist or hidden. Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE WMI!!! [Auto Services] :HKLM WDISYSTEMHOST ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K LOCALSYSTEMNETWORKRESTRICTED -P Service registry key doesn't exist or hidden. Actual File: C:\WINDOWS\SYSTEM32\SVCHOST.EXE WMI!!! [Svchost DLLs] :HKLM CertPropSvc=C:\WINDOWS\System32\CERTPROP.DLL ### Service de propagation de certificats de cartes à puce Microsoft Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\certprop.dll [Svchost DLLs] :HKLM SCPolicySvc=C:\WINDOWS\System32\CERTPROP.DLL ### Service de propagation de certificats de cartes à puce Microsoft Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\certprop.dll [Svchost DLLs] :HKLM lanmanserver=C:\WINDOWS\System32\SRVSVC.DLL ### DLL du service Serveur Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\system32\srvsvc.dll [Svchost DLLs] :HKLM gpsvc=C:\WINDOWS\System32\GPSVC.DLL ### Client de stratégie de groupe Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\gpsvc.dll [Svchost DLLs] :HKLM iphlpsvc=C:\WINDOWS\System32\IPHLPSVC.DLL ### Service offrant une connectivité IPv6 sur un réseau IPv4. Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\iphlpsvc.dll [Svchost DLLs] :HKLM msiscsi=C:\WINDOWS\System32\ISCSIEXE.DLL ### Service de découverte iSCSI Microsoft Corporation Système d'exploitation Microsoft® Windows® 10.0.19041.867 =>ISCSIEXE.EXE.MUI !$*%systemroot%\system32\iscsiexe.dll [Svchost DLLs] :HKLM schedule=C:\WINDOWS\System32\SCHEDSVC.DLL ### Service du Planificateur de tâches Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 ->SCHEDULE !$*%systemroot%\system32\schedsvc.dll [Svchost DLLs] :HKLM winmgmt=C:\WINDOWS\System32\WBEM\WMISVC.DLL ### WMI Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\system32\wbem\WMIsvc.dll [Svchost DLLs] :HKLM SessionEnv=C:\WINDOWS\System32\SESSENV.DLL ### Service Configuration des services Bureau à distance Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\system32\sessenv.dll [Svchost DLLs] :HKLM TokenBroker=C:\WINDOWS\System32\TOKENBROKER.DLL ### Broker à jetons Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 ->TOKEN BROKER !$*%SystemRoot%\System32\TokenBroker.dll [Svchost DLLs] :HKLM UserManager=C:\WINDOWS\System32\USERMGR.DLL ### UserMgr Microsoft Corporation Système d'exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\usermgr.dll [Svchost DLLs] :HKLM FastUserSwitchingCompatibility [Svchost DLLs] :HKLM Ias [Svchost DLLs] :HKLM Irmon [Svchost DLLs] :HKLM Nla [Svchost DLLs] :HKLM Ntmssvc [Svchost DLLs] :HKLM NWCWorkstation [Svchost DLLs] :HKLM Nwsapagent [Svchost DLLs] :HKLM Rasauto=C:\WINDOWS\System32\RASAUTO.DLL ### Gestionnaire de numérotation automatique d’accès distant Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\rasauto.dll [Svchost DLLs] :HKLM Rasman=C:\WINDOWS\System32\RASMANS.DLL ### Gestionnaire des connexions d’accès à distance Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\rasmans.dll [Svchost DLLs] :HKLM Remoteaccess=C:\WINDOWS\System32\MPRDIM.DLL ### Gestionnaire d’interface dynamique Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\mprdim.dll [Svchost DLLs] :HKLM SENS=C:\WINDOWS\System32\SENS.DLL ### Service de notification d’événements système (SENS) Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\sens.dll [Svchost DLLs] :HKLM Sharedaccess=C:\WINDOWS\System32\IPNATHLP.DLL ### Composants de l’application d’assistance à Microsoft NAT Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\ipnathlp.dll [Svchost DLLs] :HKLM SRService [Svchost DLLs] :HKLM Tapisrv=C:\WINDOWS\System32\TAPISRV.DLL ### Serveur de téléphonie Microsoft® Windows(TM) Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 ->TELEPHONY SERVICE =>TAPISRV.EXE.MUI !$*%SystemRoot%\System32\tapisrv.dll [Svchost DLLs] :HKLM Wmi [Svchost DLLs] :HKLM WmdmPmSp [Svchost DLLs] :HKLM wuauserv=C:\WINDOWS\System32\WUAUENG.DLL ### Agent de mise à jour automatique Windows Update Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%systemroot%\system32\wuaueng.dll [Svchost DLLs] :HKLM BITS=C:\WINDOWS\System32\QMGR.DLL ### Service de transfert intelligent en arrière-plan Microsoft Corporation Système d’exploitation Microsoft® Windows® 7.8.19041.867 !$*%SystemRoot%\System32\qmgr.dll [Svchost DLLs] :HKLM ShellHWDetection=C:\WINDOWS\System32\SHSVCS.DLL ### Dll des services Windows Shell Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\shsvcs.dll [Svchost DLLs] :HKLM LogonHours [Svchost DLLs] :HKLM PCAudit [Svchost DLLs] :HKLM helpsvc [Svchost DLLs] :HKLM uploadmgr [Svchost DLLs] :HKLM ScDeviceEnum=C:\WINDOWS\System32\SCDEVICEENUM.DLL ### Service d’énumération de périphériques de carte à puce Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\ScDeviceEnum.dll [Svchost DLLs] :HKLM WiaRpc=C:\WINDOWS\System32\WIARPC.DLL ### DLL de client RPC d’acquisition d’image Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\wiarpc.dll [Svchost DLLs] :HKLM AudioEndpointBuilder=C:\WINDOWS\System32\AUDIOENDPOINTBUILDER.DLL ### Générateur de points de terminaison du service Audio Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 ->AUDIOEPB.DLL =>AUDIOEPB.DLL.MUI !$*%SystemRoot%\System32\AudioEndpointBuilder.dll [Svchost DLLs] :HKLM dot3svc=C:\WINDOWS\System32\DOT3SVC.DLL ### Service de configuration automatique de réseau câblé Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\dot3svc.dll [Svchost DLLs] :HKLM DeviceAssociationService=C:\WINDOWS\System32\DAS.DLL ### Service d’association de périphérique Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\system32\das.dll [Svchost DLLs] :HKLM Netman=C:\WINDOWS\System32\NETMAN.DLL ### Gestionnaire de connexions réseau Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\netman.dll [Svchost DLLs] :HKLM wlansvc=C:\WINDOWS\System32\WLANSVC.DLL ### DLL du service de configuration automatique WLAN de Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\wlansvc.dll [Svchost DLLs] :HKLM NcbService=C:\WINDOWS\System32\NCBSERVICE.DLL ### Service Broker pour les connexions réseau Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\ncbservice.dll [Svchost DLLs] :HKLM WPDBusEnum=C:\WINDOWS\System32\WPDBUSENUM.DLL ### Énumérateur d’appareil mobile Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\system32\wpdbusenum.dll [Svchost DLLs] :HKLM MixedRealityOpenXRSvc=C:\WINDOWS\System32\MIXEDREALITYRUNTIME.DLL ### MixedRealityRuntime DLL Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 ->MIXEDREALITYRUNTIME DLL !$*%SystemRoot%\System32\MixedRealityRuntime.dll [Svchost DLLs] :HKLM netprofm=C:\WINDOWS\System32\NETPROFMSVC.DLL ### DLL du service de profil réseau Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 ->NETWORK PROFILE SERVICE DLL !$*%SystemRoot%\System32\netprofmsvc.dll [Svchost DLLs] :HKLM WinHttpAutoProxySvc=C:\WINDOWS\System32\WINHTTP.DLL ### Services HTTP Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\system32\winhttp.dll [Svchost DLLs] :HKLM WebClient=C:\WINDOWS\System32\WEBCLNT.DLL ### Fichier DLL du service DAV pour le Web Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 ->DAVSVC.DLL =>DAVSVC.DLL.MUI !$*%SystemRoot%\System32\webclnt.dll [Svchost DLLs] :HKLM StiSvc=C:\WINDOWS\System32\WIASERVC.DLL ### Service de périphériques d’images fixes Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\wiaservc.dll [Svchost DLLs] :HKLM PLA=C:\WINDOWS\System32\PLA.DLL ### Journaux & alertes de performance Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%systemroot%\system32\pla.dll [Svchost DLLs] :HKLM smphost=C:\WINDOWS\System32\SMPHOST.DLL ### Storage Management Provider (SMP) host service Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.867 !$*%Systemroot%\System32\smphost.dll [Svchost DLLs] :HKLM RpcSs=C:\WINDOWS\System32\RPCSS.DLL ### Distributed COM Services Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1052 !$*%SystemRoot%\system32\rpcss.dll [Svchost DLLs] :HKLM AudioSrv=C:\WINDOWS\System32\AUDIOSRV.DLL ### Service Audio Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\Audiosrv.dll [Svchost DLLs] :HKLM wscsvc=C:\WINDOWS\System32\WSCSVC.DLL ### Service Centre de sécurité de Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\wscsvc.dll [Svchost DLLs] :HKLM LmHosts=C:\WINDOWS\System32\LMHSVC.DLL ### DLL des services de transport NetBIOS sur TCP/IP Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\lmhsvc.dll [Svchost DLLs] :HKLM DHCP=C:\WINDOWS\System32\DHCPCORE.DLL ### Service client DHCP Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\system32\dhcpcore.dll [Svchost DLLs] :HKLM PNRPSvc=C:\WINDOWS\System32\PNRPSVC.DLL ### DLL du service PNRP Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\system32\pnrpsvc.dll [Svchost DLLs] :HKLM p2pimsvc=C:\WINDOWS\System32\PNRPSVC.DLL ### DLL du service PNRP Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\system32\pnrpsvc.dll [Svchost DLLs] :HKLM p2psvc=C:\WINDOWS\System32\P2PSVC.DLL ### Services pair à pair Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\system32\p2psvc.dll [Svchost DLLs] :HKLM PnrpAutoReg [Svchost DLLs] :HKLM StateRepository=C:\WINDOWS\System32\WINDOWS.STATEREPOSITORY.DLL ### Serveur d'API Windows StateRepository Microsoft Corporation Système d'exploitation Microsoft® Windows® 10.0.19041.867 ->WINDOWS STATEREPOSITORY API SERVER !$*%SystemRoot%\system32\windows.staterepository.dll [Svchost DLLs] :HKLM camsvc=C:\WINDOWS\System32\CAPABILITYACCESSMANAGER.DLL ### Service Gestionnaire d’accès aux fonctionnalités Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 ->CAPABILITY ACCESS MANAGER SERVICE !$*%SystemRoot%\system32\CapabilityAccessManager.dll [Svchost DLLs] :HKLM SSDPSRV=C:\WINDOWS\System32\SSDPSRV.DLL ### DLL du service SSDP Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\ssdpsrv.dll [Svchost DLLs] :HKLM upnphost=C:\WINDOWS\System32\UPNPHOST.DLL ### Hôte de périphérique UPnP Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 ->UNPNHOST.DLL =>UNPNHOST.DLL.MUI !$*%SystemRoot%\System32\upnphost.dll [Svchost DLLs] :HKLM SCardSvr=C:\WINDOWS\System32\SCARDSVR.DLL ### Serveur de gestion de ressources des cartes à puce Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 ->SCARDSVR.EXE =>SCARDSVR.EXE.MUI !$*%SystemRoot%\System32\SCardSvr.dll [Svchost DLLs] :HKLM BthHFSrv [Svchost DLLs] :HKLM QWAVE=C:\WINDOWS\SYSTEM32\QWAVE.DLL ### Windows NT Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 ->QWAVEDLL !$*%windir%\system32\qwave.dll [Svchost DLLs] :HKLM wcncsvc=C:\WINDOWS\System32\WCNCSVC.DLL ### Windows Connect Now - Service de registre de configuration Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\wcncsvc.dll [Svchost DLLs] :HKLM DcomLaunch=C:\WINDOWS\System32\RPCSS.DLL ### Distributed COM Services Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1052 !$*%SystemRoot%\system32\rpcss.dll [Svchost DLLs] :HKLM DeviceInstall=C:\WINDOWS\System32\UMPNPMGR.DLL ### Service mode utilisateur de Plug-and-Play Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\system32\umpnpmgr.dll [Svchost DLLs] :HKLM PrintWorkflowUserSvc=C:\WINDOWS\System32\PRINTWORKFLOWSERVICE.DLL ### Workflow d’impression Microsoft Windows service interne Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 ->WINDOWS.GRAPHICS.INTERNAL.PRINTING.WORKFLOWSERVICE =>WINDOWS.GRAPHICS.INTERNAL.PRINTING.WORKFLOWSERVICE.DLL.MUI !$*%SystemRoot%\System32\PrintWorkflowService.dll [Svchost DLLs] :HKLM AarSvc=C:\WINDOWS\System32\AARSVC.DLL ### Agent Activation Runtime Service Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1023 !$*%SystemRoot%\System32\AarSvc.dll [Svchost DLLs] :HKLM DeviceAssociationBrokerSvc=C:\WINDOWS\System32\DEVICEACCESS.DLL ### Device Broker And Policy COM Server Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.746 !$*%SystemRoot%\System32\deviceaccess.dll [Svchost DLLs] :HKLM CryptSvc=C:\WINDOWS\System32\CRYPTSVC.DLL ### Services de chiffrement Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\system32\cryptsvc.dll [Svchost DLLs] :HKLM WinRM=C:\WINDOWS\System32\WSMSVC.DLL ### Service WSMan Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\system32\WsmSvc.dll [Svchost DLLs] :HKLM WECSVC=C:\WINDOWS\System32\WECSVC.DLL ### Service Collecteur d’événements Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\system32\wecsvc.dll [Svchost DLLs] :HKLM TermService=C:\WINDOWS\System32\TERMSRV.DLL ### Gestionnaire des connexions distantes du serveur hôte de session Bureau à distance Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\termsrv.dll [Svchost DLLs] :HKLM DNSCache=C:\WINDOWS\System32\DNSRSLVR.DLL ### Service de résolution du cache DNS Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\dnsrslvr.dll [Svchost DLLs] :HKLM AJRouter=C:\WINDOWS\System32\AJROUTER.DLL ### DLL du service de routeur AllJoyn Microsoft Corporation Système d'exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\AJRouter.dll [Svchost DLLs] :HKLM AppIDSvc=C:\WINDOWS\System32\APPIDSVC.DLL ### Service d’identité de l’application Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\appidsvc.dll [Svchost DLLs] :HKLM Appinfo=C:\WINDOWS\System32\APPINFO.DLL ### Service Informations d’application Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\appinfo.dll [Svchost DLLs] :HKLM AppReadiness=C:\WINDOWS\System32\APPREADINESS.DLL ### AppReadiness Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\system32\AppReadiness.dll [Svchost DLLs] :HKLM autotimesvc=C:\WINDOWS\System32\AUTOTIMESVC.DLL ### Service AutoTime Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 ->AUTOTIME SERVICE !$*%SystemRoot%\System32\autotimesvc.dll [Svchost DLLs] :HKLM AxInstSV=C:\WINDOWS\System32\AXINSTSV.DLL ### Service de l’installateur ActiveX Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\AxInstSV.dll [Svchost DLLs] :HKLM BcastDVRUserService=C:\WINDOWS\System32\BCASTDVRUSERSERVICE.DLL ### Service utilisateur DVR de diffusion Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 ->BROADCAST DVR USER SERVICE =>BCASTDVRUSERSVC.DLL.MUI !$*%SystemRoot%\System32\BcastDVRUserService.dll [Svchost DLLs] :HKLM BDESVC=C:\WINDOWS\System32\BDESVC.DLL ### Service BDE Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\bdesvc.dll [Svchost DLLs] :HKLM BFE=C:\WINDOWS\System32\BFE.DLL ### Moteur de filtrage de base Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\bfe.dll [Svchost DLLs] :HKLM BluetoothUserService=C:\WINDOWS\System32\MICROSOFT.BLUETOOTH.USERSERVICE.DLL ### Service de support des utilisateurs du Bluetooth Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\Microsoft.Bluetooth.UserService.dll [Svchost DLLs] :HKLM BrokerInfrastructure=C:\WINDOWS\System32\PSMSRV.DLL ### Process State Manager (PSM) Service Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*%SystemRoot%\System32\psmsrv.dll [Svchost DLLs] :HKLM Browser=C:\WINDOWS\System32\BROWSER.DLL ### DLL du service Explorateur d’ordinateurs Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\browser.dll [Svchost DLLs] :HKLM BTAGService=C:\WINDOWS\System32\BTAGSERVICE.DLL ### Service de passerelle audio Bluetooth Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 ->BLUETOOTH AUDIO GATEWAY SERVICE !$*%SystemRoot%\System32\BTAGService.dll [Svchost DLLs] :HKLM BthAvctpSvc=C:\WINDOWS\System32\BTHAVCTPSVC.DLL ### DLL du service Bluetooth AVRCP Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 ->BLUETOOTH AVCTP SERVICE DLL !$*%SystemRoot%\System32\BthAvctpSvc.dll [Svchost DLLs] :HKLM bthserv=C:\WINDOWS\System32\BTHSERV.DLL ### Service de prise en charge Bluetooth Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\system32\bthserv.dll [Svchost DLLs] :HKLM CaptureService=C:\WINDOWS\System32\CAPTURESERVICE.DLL ### Service utilisateur de Capture Microsoft Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\CaptureService.dll [Svchost DLLs] :HKLM cbdhsvc=C:\WINDOWS\System32\CBDHSVC.DLL ### Historique du Presse-papiers Microsoft (R) Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\cbdhsvc.dll [Svchost DLLs] :HKLM CDPSvc=C:\WINDOWS\System32\CDPSVC.DLL ### Service CDP Microsoft (R) Microsoft Corporation Système d'exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\CDPSvc.dll [Svchost DLLs] :HKLM CDPUserSvc=C:\WINDOWS\System32\CDPUSERSVC.DLL ### Composants utilisateur Microsoft (R) CDP Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\CDPUserSvc.dll [Svchost DLLs] :HKLM ClipSVC=C:\WINDOWS\System32\CLIPSVC.DLL ### Service de licences de client Microsoft Corporation Système d'exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\ClipSVC.dll [Svchost DLLs] :HKLM ConsentUxUserSvc=C:\WINDOWS\System32\CONSENTUXCLIENT.DLL ### Implémentation de l'API UX de consentement côté client Microsoft Corporation Système d'exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\ConsentUxClient.dll [Svchost DLLs] :HKLM CoreMessagingRegistrar=C:\WINDOWS\System32\COREMESSAGING.DLL ### Microsoft CoreMessaging Dll Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.867 !$*%SystemRoot%\system32\coremessaging.dll [Svchost DLLs] :HKLM defragsvc=C:\WINDOWS\System32\DEFRAGSVC.DLL ### Microsoft\Optimiseur de lecteur Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%Systemroot%\System32\defragsvc.dll [Svchost DLLs] :HKLM DevicePickerUserSvc=C:\WINDOWS\System32\WINDOWS.DEVICES.PICKER.DLL ### Sélecteur d’appareil Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\Windows.Devices.Picker.dll [Svchost DLLs] :HKLM DevicesFlowUserSvc=C:\WINDOWS\System32\DEVICESFLOWBROKER.DLL ### Répartiteur des flux d’appareils Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 ->DEVICESFLOW BROKER !$*%SystemRoot%\System32\DevicesFlowBroker.dll [Svchost DLLs] :HKLM DevQueryBroker=C:\WINDOWS\System32\DEVQUERYBROKER.DLL ### Service Broker de découverte en arrière-plan DevQuery Microsoft Corporation Système d'exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\system32\DevQueryBroker.dll [Svchost DLLs] :HKLM diagsvc=C:\WINDOWS\System32\DIAGSVC.DLL ### Microsoft Windows operating system Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.789 ->DIAGNOSTIC EXECUTION SERVICE DLL !$*%systemroot%\system32\DiagSvc.dll [Svchost DLLs] :HKLM DiagTrack=C:\WINDOWS\System32\DIAGTRACK.DLL ### Suivi des diagnostics Microsoft Windows Microsoft Corporation Système d'exploitation Microsoft® Windows® 10.0.19041.1023 !$*%SystemRoot%\system32\diagtrack.dll [Svchost DLLs] :HKLM DispBrokerDesktopSvc=C:\WINDOWS\System32\DISPBROKER.DESKTOP.DLL ### Courtier d'affichage du bureau Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\DispBroker.Desktop.dll [Svchost DLLs] :HKLM DisplayEnhancementService=C:\WINDOWS\System32\MICROSOFT.GRAPHICS.DISPLAY.DISPLAYENHANCEMENTSERVICE.DLL ### DLL Microsoft.Graphics.Display.DisplayEnhancementService Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\system32\Microsoft.Graphics.Display.DisplayEnhancementService.dll [Svchost DLLs] :HKLM DmEnrollmentSvc=C:\WINDOWS\System32\WINDOWS.INTERNAL.MANAGEMENT.DLL ### DLL Windows Management Service Microsoft Corporation Système d'exploitation Microsoft® Windows® 10.0.19041.867 !$*%systemroot%\system32\Windows.Internal.Management.dll [Svchost DLLs] :HKLM dmwappushservice=C:\WINDOWS\System32\DMWAPPUSHSVC.DLL ### dmwappushsvc Microsoft Corporation Système d'exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\system32\dmwappushsvc.dll [Svchost DLLs] :HKLM DPS=C:\WINDOWS\System32\DPS.DLL ### Service de stratégie de diagnostic WDI Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\system32\dps.dll [Svchost DLLs] :HKLM DsmSvc=C:\WINDOWS\System32\DEVICESETUPMANAGER.DLL ### Gestionnaire d’installation de périphérique Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\DeviceSetupManager.dll [Svchost DLLs] :HKLM DsSvc=C:\WINDOWS\System32\DSSVC.DLL ### Service NT de partage des données Service DLL Microsoft Corporation Système d'exploitation Microsoft® Windows® 10.0.19041.867 ->DATA SHARING SERVICE NT SERVICE DLL !$*%SystemRoot%\System32\DsSvc.dll [Svchost DLLs] :HKLM DusmSvc=C:\WINDOWS\System32\DUSMSVC.DLL ### Service Consommation des données Microsoft Corporation Système d'exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\dusmsvc.dll [Svchost DLLs] :HKLM Eaphost=C:\WINDOWS\System32\EAPSVC.DLL ### Service EAPHost Microsoft Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\eapsvc.dll [Svchost DLLs] :HKLM EFS=C:\WINDOWS\System32\EFSSVC.DLL ### Service EFS Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\system32\efssvc.dll [Svchost DLLs] :HKLM embeddedmode=C:\WINDOWS\System32\EMBEDDEDMODESVC.DLL ### Service d'enregistrement de débogage Microsoft Corporation Système d'exploitation Microsoft® Windows® 10.0.19041.867 ->DEBUG REGISTER SERVICE =>EMBEDDEDMODESVC.EXE.MUI !$*%SystemRoot%\System32\embeddedmodesvc.dll [Svchost DLLs] :HKLM EventLog=C:\WINDOWS\System32\WEVTSVC.DLL ### Service journal des événements Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\wevtsvc.dll [Svchost DLLs] :HKLM EventSystem=C:\WINDOWS\System32\ES.DLL ### COM+ Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.572 !$*%systemroot%\system32\es.dll [Svchost DLLs] :HKLM fdPHost=C:\WINDOWS\System32\FDPHOST.DLL ### Service hôte du fournisseur de découverte de réseau Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\system32\fdPHost.dll [Svchost DLLs] :HKLM FDResPub=C:\WINDOWS\System32\FDRESPUB.DLL ### Service de publication des ressources de découverte de fonctions Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\system32\fdrespub.dll [Svchost DLLs] :HKLM fhsvc=C:\WINDOWS\System32\FHSVC.DLL ### Service d’historique des fichiers Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\system32\fhsvc.dll [Svchost DLLs] :HKLM FontCache=C:\WINDOWS\System32\FNTCACHE.DLL ### Service de cache de police Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 ->FONTCACHESERVICE !$*%SystemRoot%\system32\FntCache.dll [Svchost DLLs] :HKLM GraphicsPerfSvc=C:\WINDOWS\System32\GRAPHICSPERFSVC.DLL ### GraphicsPerfSvc Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.746 !$*%SystemRoot%\System32\GraphicsPerfSvc.dll [Svchost DLLs] :HKLM hidserv=C:\WINDOWS\System32\HIDSERV.DLL ### Service du périphérique d’interface utilisateur Microsoft Corporation Système d'exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\system32\hidserv.dll [Svchost DLLs] :HKLM HomeGroupListener=C:\WINDOWS\System32\LISTSVC.DLL ### Groupement résidentiel Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\system32\ListSvc.dll [Svchost DLLs] :HKLM HomeGroupProvider=C:\WINDOWS\System32\PROVSVC.DLL ### Groupement résidentiel Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\system32\provsvc.dll [Svchost DLLs] :HKLM HvHost=C:\WINDOWS\System32\HVHOSTSVC.DLL ### Service d'hôte hyperviseur Microsoft Microsoft Corporation Système d'exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\hvhostsvc.dll [Svchost DLLs] :HKLM icssvc=C:\WINDOWS\System32\TETHERINGSERVICE.DLL ### Service Connexion Microsoft Corporation Système d'exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\tetheringservice.dll [Svchost DLLs] :HKLM IKEEXT=C:\WINDOWS\System32\IKEEXT.DLL ### Extension IKE Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\ikeext.dll [Svchost DLLs] :HKLM InstallService=C:\WINDOWS\System32\INSTALLSERVICE.DLL ### InstallService Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\system32\InstallService.dll [Svchost DLLs] :HKLM IpxlatCfgSvc=C:\WINDOWS\System32\IPXLATCFG.DLL ### Service de configuration de conversion IP Microsoft Corporation Système d'exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\IpxlatCfg.dll [Svchost DLLs] :HKLM KeyIso=C:\WINDOWS\System32\KEYISO.DLL ### Service d’isolation de clé CNG Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\system32\keyiso.dll [Svchost DLLs] :HKLM KtmRm=C:\WINDOWS\System32\MSDTCKRM.DLL ### Microsoft Distributed Transaction Coordinator OLE Transactions KTM Resource Manager DLL Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*%systemroot%\system32\msdtckrm.dll [Svchost DLLs] :HKLM LanmanWorkstation=C:\WINDOWS\System32\WKSSVC.DLL ### DLL du service Station de travail Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\wkssvc.dll [Svchost DLLs] :HKLM lfsvc=C:\WINDOWS\System32\LFSVC.DLL ### Service de géolocalisation Microsoft Corporation Système d'exploitation Microsoft® Windows® 10.0.19041.867 ->GEOLOCATION SERVICE !$*%SystemRoot%\System32\lfsvc.dll [Svchost DLLs] :HKLM LicenseManager=C:\WINDOWS\System32\LICENSEMANAGERSVC.DLL ### LicenseManagerSvc Microsoft Corporation Système d'exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\system32\LicenseManagerSvc.dll [Svchost DLLs] :HKLM lltdsvc=C:\WINDOWS\System32\LLTDSVC.DLL ### Link-Layer Topology Mapper Service Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.746 !$*%SystemRoot%\System32\lltdsvc.dll [Svchost DLLs] :HKLM LSM=C:\WINDOWS\System32\LSM.DLL ### Service du gestionnaire de session locale Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\lsm.dll [Svchost DLLs] :HKLM LxpSvc=C:\WINDOWS\System32\LANGUAGEOVERLAYSERVER.DLL ### Fournit une prise en charge de l'infrastructure permettant de déployer et de configurer des ressources Windows localisées. Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\LanguageOverlayServer.dll [Svchost DLLs] :HKLM MapsBroker=C:\WINDOWS\System32\MOSHOST.DLL ### Gestionnaire des cartes téléchargées Microsoft Corporation Système d'exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\moshost.dll [Svchost DLLs] :HKLM MessagingService=C:\WINDOWS\System32\MESSAGINGSERVICE.DLL ### Service de messagerie Microsoft Corporation Système d'exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\MessagingService.dll [Svchost DLLs] :HKLM mpssvc=C:\WINDOWS\System32\MPSSVC.DLL ### Service de protection Microsoft Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\system32\mpssvc.dll [Svchost DLLs] :HKLM NaturalAuthentication=C:\WINDOWS\System32\NATURALAUTH.DLL ### Service d’authentification naturelle Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\NaturalAuth.dll [Svchost DLLs] :HKLM NcaSvc=C:\WINDOWS\System32\NCASVC.DLL ### Service Assistant Connectivité réseau Microsoft Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\ncasvc.dll [Svchost DLLs] :HKLM NcdAutoSetup=C:\WINDOWS\System32\NCDAUTOSETUP.DLL ### DLL du service Configuration automatique des périphériques connectés au réseau Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\NcdAutoSetup.dll [Svchost DLLs] :HKLM Netlogon=C:\WINDOWS\System32\NETLOGON.DLL ### DLL des services Net Logon Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\system32\netlogon.dll [Svchost DLLs] :HKLM NetSetupSvc=C:\WINDOWS\System32\NETSETUPSVC.DLL ### Service Configuration du réseau Microsoft Corporation Système d'exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\NetSetupSvc.dll [Svchost DLLs] :HKLM NgcCtnrSvc=C:\WINDOWS\System32\NGCCTNRSVC.DLL ### Service de conteneur Microsoft Passport Microsoft Corporation Système d'exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\NgcCtnrSvc.dll [Svchost DLLs] :HKLM NgcSvc=C:\WINDOWS\System32\NGCSVC.DLL ### Service Microsoft Passport Microsoft Corporation Système d'exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\system32\ngcsvc.dll [Svchost DLLs] :HKLM NlaSvc=C:\WINDOWS\System32\NLASVC.DLL ### Connaissance des emplacements réseau 2 Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\nlasvc.dll [Svchost DLLs] :HKLM nsi=C:\WINDOWS\System32\NSISVC.DLL ### Serveur RPC de l’interface du magasin réseau Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%systemroot%\system32\nsisvc.dll [Svchost DLLs] :HKLM OneSyncSvc=C:\WINDOWS\System32\APHOSTSERVICE.DLL ### Accounts Host Service Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.746 !$*%SystemRoot%\System32\APHostService.dll [Svchost DLLs] :HKLM PcaSvc=C:\WINDOWS\System32\PCASVC.DLL ### Service de l’Assistant Compatibilité des programmes Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\pcasvc.dll [Svchost DLLs] :HKLM PhoneSvc=C:\WINDOWS\System32\PHONESERVICE.DLL ### The service used to manage phone calls and other telephony related functionality Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.746 !$*%SystemRoot%\System32\PhoneService.dll [Svchost DLLs] :HKLM PimIndexMaintenanceSvc=C:\WINDOWS\System32\PIMINDEXMAINTENANCE.DLL ### Service en charge de l'indexation des contacts et autres tâches connexes de données utilisateur Microsoft Corporation Système d'exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\PimIndexMaintenance.dll [Svchost DLLs] :HKLM PlugPlay=C:\WINDOWS\System32\UMPNPMGR.DLL ### Service mode utilisateur de Plug-and-Play Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\system32\umpnpmgr.dll [Svchost DLLs] :HKLM PolicyAgent=C:\WINDOWS\System32\IPSECSVC.DLL ### DLL du serveur SPD IPsec Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\ipsecsvc.dll [Svchost DLLs] :HKLM Power=C:\WINDOWS\System32\UMPO.DLL ### Service d’alimentation en mode utilisateur Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\system32\umpo.dll [Svchost DLLs] :HKLM PrintNotify=C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\X64\3\PRINTCONFIG.DLL ### Interface utilisateur PrintConfig Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.1052 !$*C:\WINDOWS\system32\spool\drivers\x64\3\PrintConfig.dll [Svchost DLLs] :HKLM ProfSvc=C:\WINDOWS\System32\PROFSVC.DLL ### ProfSvc Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%systemroot%\system32\profsvc.dll [Svchost DLLs] :HKLM PushToInstall=C:\WINDOWS\System32\PUSHTOINSTALL.DLL ### PushToInstall Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\system32\PushToInstall.dll [Svchost DLLs] :HKLM RemoteRegistry=C:\WINDOWS\System32\REGSVC.DLL ### Service d’accès à distance au Registre Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\system32\regsvc.dll [Svchost DLLs] :HKLM RetailDemo=C:\WINDOWS\System32\RDXSERVICE.DLL ### RDXService Microsoft Corporation Système d'exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\system32\RDXService.dll [Svchost DLLs] :HKLM RmSvc=C:\WINDOWS\System32\RMAPI.DLL ### Radio Manager API Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\RMapi.dll [Svchost DLLs] :HKLM RpcEptMapper=C:\WINDOWS\System32\RPCEPMAP.DLL ### Mappeur de point de terminaison RPC Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\RpcEpMap.dll [Svchost DLLs] :HKLM SDRSVC=C:\WINDOWS\System32\SDRSVC.DLL ### Service de sauvegarde Microsoft® Windows Microsoft Corporation Système d'exploitation Microsoft® Windows® 10.0.19041.867 !$*%Systemroot%\System32\SDRSVC.dll [Svchost DLLs] :HKLM seclogon=C:\WINDOWS\SYSTEM32\SECLOGON.DLL ### DLL de service d’ouverture de session secondaire Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 ->SECLOGON.EXE =>SECLOGON.EXE.MUI !$*%windir%\system32\seclogon.dll [Svchost DLLs] :HKLM SEMgrSvc=C:\WINDOWS\System32\SEMGRSVC.DLL ### DLL du service de gestion des éléments sécurisés NFC Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\system32\SEMgrSvc.dll [Svchost DLLs] :HKLM SensorService=C:\WINDOWS\System32\SENSORSERVICE.DLL ### Service de capteur Microsoft Corporation Système d'exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\system32\SensorService.dll [Svchost DLLs] :HKLM SensrSvc=C:\WINDOWS\System32\SENSRSVC.DLL ### Service de surveillance des capteurs Microsoft Windows Microsoft Corporation Système d'exploitation Microsoft® Windows® 10.0.19041.867 ->MICROSOFT WINDOWS SENSOR MONITORING SERVICE !$*%SystemRoot%\system32\sensrsvc.dll [Svchost DLLs] :HKLM SharedRealitySvc=C:\WINDOWS\System32\SHAREDREALITYSVC.DLL ### Service de données spatiales Microsoft (R) Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\SharedRealitySvc.dll [Svchost DLLs] :HKLM shpamsvc=C:\WINDOWS\System32\WINDOWS.SHAREDPC.ACCOUNTMANAGER.DLL ### SharedPC.AccountManager Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.789 ->SHAREDPC.ACCOUNTMANAGER =>SHAREDPC.ACCOUNTMANAGER.DLL !$*%systemroot%\system32\Windows.SharedPC.AccountManager.dll [Svchost DLLs] :HKLM SmsRouter=C:\WINDOWS\System32\SMSROUTERSVC.DLL ### Service Routeur SMS Windows Microsoft Corporation Système d'exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\system32\SmsRouterSvc.dll [Svchost DLLs] :HKLM SstpSvc=C:\WINDOWS\System32\SSTPSVC.DLL ### Permet d’utiliser le protocole SSTP (Secure Socket Tunneling Protocol) pour se connecter à des ordinateurs distants (via un réseau VPN). Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\system32\sstpsvc.dll [Svchost DLLs] :HKLM StorSvc=C:\WINDOWS\System32\STORSVC.DLL ### Services de stockage Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\system32\storsvc.dll [Svchost DLLs] :HKLM svsvc=C:\WINDOWS\System32\SVSVC.DLL ### Microsoft\Vérificateur de points Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\system32\svsvc.dll [Svchost DLLs] :HKLM swprv=C:\WINDOWS\System32\SWPRV.DLL ### Fournisseur logiciel du service Microsoft® de cliché instantané des volumes Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%Systemroot%\System32\swprv.dll [Svchost DLLs] :HKLM SysMain=C:\WINDOWS\System32\SYSMAIN.DLL ### Hôte de Service SysMain Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%systemroot%\system32\sysmain.dll [Svchost DLLs] :HKLM SystemEventsBroker=C:\WINDOWS\System32\SYSTEMEVENTSBROKERSERVER.DLL ### Service Broker pour les événements système Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\SystemEventsBrokerServer.dll [Svchost DLLs] :HKLM TabletInputService=C:\WINDOWS\System32\TABSVC.DLL ### Service Clavier tactile et volet d’écriture manuscrite Microsoft Microsoft Corporation Système d'exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\TabSvc.dll [Svchost DLLs] :HKLM Themes=C:\WINDOWS\System32\THEMESERVICE.DLL ### DLL du service des thèmes Windows Shell Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\system32\themeservice.dll [Svchost DLLs] :HKLM TimeBrokerSvc=C:\WINDOWS\System32\TIMEBROKERSERVER.DLL ### Service Broker pour les événements horaires Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\TimeBrokerServer.dll [Svchost DLLs] :HKLM TrkWks=C:\WINDOWS\System32\TRKWKS.DLL ### Client de suivi de lien distribué Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\trkwks.dll [Svchost DLLs] :HKLM TroubleshootingSvc=C:\WINDOWS\System32\MITIGATIONCLIENT.DLL ### MitigationClient Microsoft Corporation Système d'exploitation Microsoft® Windows® 10.0.19041.867 !$*%systemroot%\system32\MitigationClient.dll [Svchost DLLs] :HKLM tzautoupdate=C:\WINDOWS\System32\TZAUTOUPDATE.DLL ### Programme de mise à jour automatique du fuseau horaire Microsoft Corporation Système d'exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\system32\tzautoupdate.dll [Svchost DLLs] :HKLM UdkUserSvc=C:\WINDOWS\System32\WINDOWSUDK.SHELLCOMMON.DLL ### DLL Shellcommon du kit de développement sans station d’accueil Windows Microsoft Corporation Système d'exploitation Microsoft® Windows® 10.0.19041.867 ->WINDOWS UNDOCKED DEV KIT SHELLCOMMON DLL !$*%SystemRoot%\System32\windowsudk.shellcommon.dll [Svchost DLLs] :HKLM UmRdpService=C:\WINDOWS\System32\UMRDP.DLL ### Service Redirecteur de périphériques des services Bureau à distance Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\umrdp.dll [Svchost DLLs] :HKLM UnistoreSvc=C:\WINDOWS\System32\UNISTORE.DLL ### Magasin unifié Microsoft Corporation Système d'exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\unistore.dll [Svchost DLLs] :HKLM UserDataSvc=C:\WINDOWS\System32\USERDATASERVICE.DLL ### Point de terminaison des API tierces permettant la lecture/écriture des données utilisateur Microsoft Corporation Système d'exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\userdataservice.dll [Svchost DLLs] :HKLM UsoSvc=C:\WINDOWS\System32\USOSVC.DLL ### Mettre à jour la session du service Orchestrator Microsoft Corporation Système d'exploitation Microsoft® Windows® 10.0.19041.867 ->UPDATE SESSION ORCHESTRATOR SERVICE !$*%systemroot%\system32\usosvc.dll [Svchost DLLs] :HKLM VacSvc=C:\WINDOWS\System32\VAC.DLL ### Service de composition audio volumétrique Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\vac.dll [Svchost DLLs] :HKLM VaultSvc=C:\WINDOWS\SYSTEM32\VAULTSVC.DLL ### Service de gestion des informations d’identification Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\Windows\System32\vaultsvc.dll [Svchost DLLs] :HKLM vmicguestinterface=C:\WINDOWS\System32\ICSVC.DLL ### Service de composants d'intégration d'ordinateur virtuel Microsoft Corporation Système d'exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\icsvc.dll [Svchost DLLs] :HKLM vmicheartbeat=C:\WINDOWS\System32\ICSVC.DLL ### Service de composants d'intégration d'ordinateur virtuel Microsoft Corporation Système d'exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\icsvc.dll [Svchost DLLs] :HKLM vmickvpexchange=C:\WINDOWS\System32\ICSVC.DLL ### Service de composants d'intégration d'ordinateur virtuel Microsoft Corporation Système d'exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\icsvc.dll [Svchost DLLs] :HKLM vmicrdv=C:\WINDOWS\System32\ICSVCEXT.DLL ### Service de composants d’intégration d’ordinateur virtuel Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\icsvcext.dll [Svchost DLLs] :HKLM vmicshutdown=C:\WINDOWS\System32\ICSVC.DLL ### Service de composants d'intégration d'ordinateur virtuel Microsoft Corporation Système d'exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\icsvc.dll [Svchost DLLs] :HKLM vmictimesync=C:\WINDOWS\System32\ICSVC.DLL ### Service de composants d'intégration d'ordinateur virtuel Microsoft Corporation Système d'exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\icsvc.dll [Svchost DLLs] :HKLM vmicvmsession=C:\WINDOWS\System32\ICSVC.DLL ### Service de composants d'intégration d'ordinateur virtuel Microsoft Corporation Système d'exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\icsvc.dll [Svchost DLLs] :HKLM vmicvss=C:\WINDOWS\System32\ICSVCEXT.DLL ### Service de composants d’intégration d’ordinateur virtuel Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\icsvcext.dll [Svchost DLLs] :HKLM W32Time=C:\WINDOWS\System32\W32TIME.DLL ### Service de temps Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%systemroot%\system32\w32time.dll [Svchost DLLs] :HKLM WaaSMedicSvc=C:\WINDOWS\System32\WAASMEDICSVC.DLL ### DLL du service WaasMedic Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\WaaSMedicSvc.dll [Svchost DLLs] :HKLM WalletService=C:\WINDOWS\System32\WALLETSERVICE.DLL ### Service Portefeuille Microsoft Corporation Système d'exploitation Microsoft® Windows® 10.0.19041.867 ->WALLET SERVICE !$*%SystemRoot%\system32\WalletService.dll [Svchost DLLs] :HKLM WarpJITSvc=C:\WINDOWS\System32\WINDOWS.WARP.JITSERVICE.DLL ### WARP.JITService Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 ->WARP.JITSERVICE =>WARP.JITSERVICE.DLL !$*%SystemRoot%\System32\Windows.WARP.JITService.dll [Svchost DLLs] :HKLM WbioSrvc=C:\WINDOWS\System32\WBIOSRVC.DLL ### Service de biométrie Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\wbiosrvc.dll [Svchost DLLs] :HKLM Wcmsvc=C:\WINDOWS\System32\WCMSVC.DLL ### DLL du service de gestion des connexions Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\wcmsvc.dll [Svchost DLLs] :HKLM WdiServiceHost=C:\WINDOWS\System32\WDI.DLL ### Infrastructure de diagnostics Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\system32\wdi.dll [Svchost DLLs] :HKLM WdiSystemHost=C:\WINDOWS\System32\WDI.DLL ### Infrastructure de diagnostics Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\system32\wdi.dll [Svchost DLLs] :HKLM WEPHOSTSVC=C:\WINDOWS\System32\WEPHOSTSVC.DLL ### Service hôte WEP Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%systemroot%\system32\wephostsvc.dll [Svchost DLLs] :HKLM wercplsupport=C:\WINDOWS\System32\WERCPLSUPPORT.DLL ### Rapports de problèmes Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 ->ERC !$*%SystemRoot%\System32\wercplsupport.dll [Svchost DLLs] :HKLM WerSvc=C:\WINDOWS\System32\WERSVC.DLL ### Service de rapport d’erreurs Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\WerSvc.dll [Svchost DLLs] :HKLM WFDSConMgrSvc=C:\WINDOWS\System32\WFDSCONMGRSVC.DLL ### Service Wi-Fi Direct Service de gestionnaire de connexions Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\wfdsconmgrsvc.dll [Svchost DLLs] :HKLM wisvc=C:\WINDOWS\System32\FLIGHTSETTINGS.DLL ### Paramètres de vol Microsoft Corporation Système d'exploitation Microsoft® Windows® 10.0.19041.867 !$*%systemroot%\system32\flightsettings.dll [Svchost DLLs] :HKLM wlidsvc=C:\WINDOWS\System32\WLIDSVC.DLL ### Service de compte Microsoft® Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\system32\wlidsvc.dll [Svchost DLLs] :HKLM wlpasvc=C:\WINDOWS\System32\LPASVC.DLL ### Service de l’Assistant de profil local Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\lpasvc.dll [Svchost DLLs] :HKLM WManSvc=C:\WINDOWS\System32\WINDOWS.MANAGEMENT.SERVICE.DLL ### DLL du Service de gestion de Windows Microsoft Corporation Système d'exploitation Microsoft® Windows® 10.0.19041.867 !$*%systemroot%\system32\Windows.Management.Service.dll [Svchost DLLs] :HKLM workfolderssvc=C:\WINDOWS\System32\WORKFOLDERSSVC.DLL ### Service Dossiers de travail Microsoft (C) Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%systemroot%\system32\workfolderssvc.dll [Svchost DLLs] :HKLM WpcMonSvc=C:\WINDOWS\System32\WPCDESKTOPMONSVC.DLL ### WpcMonSvc.dll Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1023 ->WPCMONSVC.DLL !$*%SystemRoot%\System32\WpcDesktopMonSvc.dll [Svchost DLLs] :HKLM WpnUserService=C:\WINDOWS\System32\WPNUSERSERVICE.DLL ### Service utilisateur de notifications Push Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\WpnUserService.dll [Svchost DLLs] :HKLM WwanSvc=C:\WINDOWS\System32\WWANSVC.DLL ### Service de configuration automatique WWAN Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\wwansvc.dll [Svchost DLLs] :HKLM XblAuthManager=C:\WINDOWS\System32\XBLAUTHMANAGER.DLL ### Xbox Live Auth Manager Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*%SystemRoot%\System32\XblAuthManager.dll [Svchost DLLs] :HKLM XblGameSave=C:\WINDOWS\System32\XBLGAMESAVE.DLL ### Xbox Live Game Save Service Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 ->XBOX LIVE GAME SAVE SERVICE !$*%SystemRoot%\System32\XblGameSave.dll [Svchost DLLs] :HKLM XboxGipSvc=C:\WINDOWS\System32\XBOXGIPSVC.DLL ### Xbox Gip Management Service Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 ->XBOX GIP MANAGEMENT SERVICE !$*%SystemRoot%\System32\XboxGipSvc.dll [Svchost DLLs] :HKLM XboxNetApiSvc=C:\WINDOWS\System32\XBOXNETAPISVC.DLL ### Xbox Live Networking Service Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 ->XBOX LIVE NETWORKING SERVICE !$*%SystemRoot%\system32\XboxNetApiSvc.dll [Bootexecute] :HKLM BootExecute=autocheck autochk * [Winlogon System] :HKLM system="" [Winlogon System] :HKLM taskman="" [Winlogon System] :HKLM UIHost="" [Winlogon Autostart] :HKLM VmApplet="" [Winlogon Autostart] :HKLM AppSetup="" [Environment - Path] :HKLM Path=D:\Oculus\Support\oculus-runtime;C:\Program Files (x86)\Common Files\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Windows\System32\OpenSSH\;C:\Program Files\NVIDIA Corporation\NVIDIA NvDLISR;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\WINDOWS\System32\WindowsPowerShell\v1.0\;C:\WINDOWS\System32\OpenSSH\;C:\Program Files (x86)\ZeroTier\One\;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;%SYSTEMROOT%\System32\OpenSSH\ [List of Injected DLLs] :HKLM AppInit_DLLs="" [List of Injected DLLs(x64)] :HKLM AppInit_DLLs=D:\Program,Files\Virtual,Desktop,Streamer\VirtualDesktop.Injector64.dll ### Virtual Desktop, Inc. Virtual Desktop 1.13.1.0 ->VIRTUALDESKTOP.INJECTOR !$*D:\Program Files\Virtual Desktop Streamer\VirtualDesktop.Injector64.dll [LSA Notification Packages] :HKLM scecli=C:\WINDOWS\SYSTEM32\SCECLI.DLL ### scecli Moteur du client de l’Éditeur de configuration de sécurité Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*scecli.dll [Print Providers] :HKLM Internet Print Provider=C:\WINDOWS\SYSTEM32\INETPP.DLL ### Display Name: HTTP Print Services * DLL du service d’impression Internet Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*inetpp.dll [Print Providers] :HKLM LanMan Print Services=C:\WINDOWS\SYSTEM32\WIN32SPL.DLL ### Display Name: LanMan Print Services * Fournisseur d’impression de rendu côté client Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*win32spl.dll [Eventlog Application DLL] :HKLM Application Error=C:\WINDOWS\System32\WER.DLL ### DLL du rapport d’erreurs Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\wer.dll [Eventlog Application DLL] :HKLM Application Hang=C:\WINDOWS\System32\WERSVC.DLL ### Service de rapport d’erreurs Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\wersvc.dll [Eventlog Application DLL] :HKLM Application-Addon-Event-Provider=C:\WINDOWS\System32\IEFRAME.DLL ### Navigateur Internet Microsoft Corporation Internet Explorer 11.00.19041.867 !$*%SystemRoot%\system32\ieframe.dll [Eventlog Application DLL] :HKLM ASP.NET 2.0.50727.0=C:\WINDOWS\MICROSOFT.NET\FRAMEWORK64\V2.0.50727\FR\ASPNET_RC.DLL ### aspnet_rc.dll Microsoft Corporation Microsoft® .NET Framework 2.0.50727.9149 !$*C:\WINDOWS\Microsoft.NET\Framework64\v2.0.50727\fr\aspnet_rc.dll [Eventlog Application DLL] :HKLM Brave-Browser=C:\PROGRAM FILES\BRAVESOFTWARE\BRAVE-BROWSER\APPLICATION\91.1.25.73\EVENTLOG_PROVIDER.DLL ### Brave Browser Brave Software, Inc. Brave Browser 91.1.25.73 ->EVENTLOG_PROVIDER_DLL !$*C:\Program Files\BraveSoftware\Brave-Browser\Application\91.1.25.73\eventlog_provider.dll [Eventlog Application DLL] :HKLM CardSpace 4.0.0.0=C:\WINDOWS\MICROSOFT.NET\FRAMEWORK64\V4.0.30319\SERVICEMODELEVENTS.DLL ### Descriptions des événements associés à ServiceModel Microsoft Corporation Microsoft® .NET Framework 4.8.4084.0 !$*C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ServiceModelEvents.dll [Eventlog Application DLL] :HKLM CardSpace 4.0.0.0=C:\Windows\System32\icardres.dll ### File is missing. !$*C:\Windows\System32\icardres.dll [Eventlog Application DLL] :HKLM Chkdsk=C:\WINDOWS\System32\ULIB.DLL ### DLL de gestion des utilitaires de fichiers Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.1023 !$*%SystemRoot%\System32\ulib.dll [Eventlog Application DLL] :HKLM Desktop Window Manager=C:\WINDOWS\System32\DWM.EXE ### Gestionnaire de fenêtres du Bureau Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\system32\dwm.exe [Eventlog Application DLL] :HKLM DiskQuota=C:\WINDOWS\System32\DSKQUOTA.DLL ### DLL Windows Shell de prise en charge de quota de disque Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\dskquota.dll [Eventlog Application DLL] :HKLM Dwminit=C:\WINDOWS\System32\DWMINIT.DLL ### DWMInit Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\system32\dwminit.dll [Eventlog Application DLL] :HKLM Edge=C:\PROGRAM FILES (X86)\MICROSOFT\EDGE\APPLICATION\91.0.864.48\EVENTLOG_PROVIDER.DLL ### Microsoft Edge Microsoft Corporation Microsoft Edge 91.0.864.48 ->EVENTLOG_PROVIDER_DLL !$*C:\Program Files (x86)\Microsoft\Edge\Application\91.0.864.48\eventlog_provider.dll [Eventlog Application DLL] :HKLM edgeupdate=C:\PROGRAM FILES (X86)\MICROSOFT\EDGEUPDATE\1.3.143.57\MSEDGEUPDATE.DLL ### Microsoft Edge Update Microsoft Corporation Microsoft Edge Update 1.3.143.57 ->MICROSOFT EDGE UPDATE !$*C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.143.57\msedgeupdate.dll [Eventlog Application DLL] :HKLM edgeupdatem=C:\PROGRAM FILES (X86)\MICROSOFT\EDGEUPDATE\1.3.143.57\MSEDGEUPDATE.DLL ### Microsoft Edge Update Microsoft Corporation Microsoft Edge Update 1.3.143.57 ->MICROSOFT EDGE UPDATE !$*C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.143.57\msedgeupdate.dll [Eventlog Application DLL] :HKLM Error Instrument=C:\WINDOWS\System32\USER32.DLL ### DLL client de l’API uilisateur de Windows multi-utilisateurs Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\system32\user32.dll [Eventlog Application DLL] :HKLM ESENT=C:\WINDOWS\System32\ESENT.DLL ### Moteur de stockage extensible (ESE) pour Microsoft(R) Windows(R) Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.1 !$*%systemroot%\system32\esent.dll [Eventlog Application DLL] :HKLM Folder Redirection=C:\WINDOWS\System32\FDEPLOY.DLL ### Extension Stratégie de groupe de redirection de dossier Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\fdeploy.dll [Eventlog Application DLL] :HKLM LogMeIn Guardian=C:\PROGRAM FILES (X86)\LOGMEIN HAMACHI\X64\LMIGUARDIANEVT.DLL ### LMIGuardianEvt LogMeIn, Inc. LMIGuardianEvt 10.1.1742 !$*C:\Program Files (x86)\LogMeIn Hamachi\x64\LMIGuardianEvt.dll [Eventlog Application DLL] :HKLM MBAMService=C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\MBAMSERVICE.EXE ### Malwarebytes Service Malwarebytes Malwarebytes Service 3.2.0.943 !$*C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [Eventlog Application DLL] :HKLM Microsoft Fax=C:\WINDOWS\SYSTEM32\FXSEVENT.DLL ### DLL de prise en charge du journal d'événement Microsoft Fax Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\Windows\System32\fxsevent.dll [Eventlog Application DLL] :HKLM Microsoft-Windows-ApplicationExperienceInfrastructure=C:\WINDOWS\System32\APPHELP.DLL ### Fichier DLL du client de compatibilité des applications Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\system32\apphelp.dll [Eventlog Application DLL] :HKLM Microsoft-Windows-AppModel-Runtime=C:\WINDOWS\System32\MICROSOFT-WINDOWS-SYSTEM-EVENTS.DLL ### Microsoft-Windows-Système-Ressources des événements Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\system32\Microsoft-Windows-System-Events.dll [Eventlog Application DLL] :HKLM Microsoft-Windows-AppModel-State=C:\WINDOWS\System32\MICROSOFT-WINDOWS-SYSTEM-EVENTS.DLL ### Microsoft-Windows-Système-Ressources des événements Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\system32\Microsoft-Windows-System-Events.dll [Eventlog Application DLL] :HKLM Microsoft-Windows-Audio=C:\WINDOWS\System32\AUDIOSES.DLL ### Session audio Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 ->AUDIOSESSION !$*%SystemRoot%\System32\audioses.dll [Eventlog Application DLL] :HKLM Microsoft-Windows-Audit-CVE=C:\WINDOWS\System32\MICROSOFT-WINDOWS-SYSTEM-EVENTS.DLL ### Microsoft-Windows-Système-Ressources des événements Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\system32\Microsoft-Windows-System-Events.dll [Eventlog Application DLL] :HKLM Microsoft-Windows-AxInstallService=C:\WINDOWS\System32\AXINSTSV.DLL ### Service de l’installateur ActiveX Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\AxInstSv.dll [Eventlog Application DLL] :HKLM Microsoft-Windows-Backup=C:\WINDOWS\SYSTEM32\BLBEVENTS.DLL ### Blb Publisher Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%windir%\system32\BlbEvents.dll [Eventlog Application DLL] :HKLM Microsoft-Windows-CAPI2=C:\WINDOWS\System32\CRYPT32.DLL ### Crypto API32 Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\crypt32.dll [Eventlog Application DLL] :HKLM Microsoft-Windows-CertificateServicesClient=C:\WINDOWS\System32\DIMSJOB.DLL ### DLL des travaux du service de gestion d’identité numérique (DIMS) Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\system32\dimsjob.dll [Eventlog Application DLL] :HKLM Microsoft-Windows-CertificateServicesClient-AutoEnrollment=C:\WINDOWS\System32\PAUTOENR.DLL ### DLL Inscription automatique Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 ->AUTO ENROLLMENT DLL !$*%SystemRoot%\system32\pautoenr.dll [Eventlog Application DLL] :HKLM Microsoft-Windows-CertificateServicesClient-CertEnroll=C:\WINDOWS\System32\CERTENROLL.DLL ### Client d’inscription des services de certificats de Microsoft® Active Directory Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\system32\certenroll.dll [Eventlog Application DLL] :HKLM Microsoft-Windows-CertificateServicesClient-CredentialRoaming=C:\WINDOWS\System32\DIMSROAM.DLL ### DLL du fournisseur du service de gestion d’identité numérique (DIMS) de clés communes Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\system32\dimsroam.dll [Eventlog Application DLL] :HKLM Microsoft-Windows-CertificationAuthorityClient-CertCli=C:\WINDOWS\System32\CERTCLI.DLL ### Client Microsoft® Active Directory Certificate Services Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\system32\certcli.dll [Eventlog Application DLL] :HKLM Microsoft-Windows-COMRuntime=C:\WINDOWS\System32\COMBASE.DLL ### Microsoft COM pour Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%systemroot%\system32\combase.dll [Eventlog Application DLL] :HKLM Microsoft-Windows-DeliveryOptimization=C:\WINDOWS\System32\DOSVC.DLL ### Optimisation de livraison Microsoft Corporation Système d'exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\dosvc.dll [Eventlog Application DLL] :HKLM Microsoft-Windows-DirectShow-Core=C:\WINDOWS\System32\QUARTZ.DLL ### Module d’exécution DirectShow. Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\system32\quartz.dll [Eventlog Application DLL] :HKLM Microsoft-Windows-DirectShow-KernelSupport=C:\WINDOWS\System32\KSPROXY.AX ### WDM Streaming ActiveMovie Proxy Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*%SystemRoot%\System32\ksproxy.ax [Eventlog Application DLL] :HKLM Microsoft-Windows-EapHost=C:\WINDOWS\System32\EAPSVC.DLL ### Service EAPHost Microsoft Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%systemroot%\system32\eapsvc.dll [Eventlog Application DLL] :HKLM Microsoft-Windows-EFS=C:\WINDOWS\System32\EFSCORE.DLL ### Bibliothèque principale EFS Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\system32\efscore.dll [Eventlog Application DLL] :HKLM Microsoft-Windows-EventCollector=C:\WINDOWS\System32\WECSVC.DLL ### Service Collecteur d’événements Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\system32\wecsvc.dll [Eventlog Application DLL] :HKLM Microsoft-Windows-Folder Redirection=C:\WINDOWS\System32\FDEPLOY.DLL ### Extension Stratégie de groupe de redirection de dossier Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\fdeploy.dll [Eventlog Application DLL] :HKLM Microsoft-Windows-Immersive-Shell=C:\WINDOWS\System32\TWINUI.APPCORE.DLL ### TWINUI.APPCORE Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\system32\twinui.appcore.dll [Eventlog Application DLL] :HKLM Microsoft-Windows-PerfCtrs=C:\WINDOWS\System32\PERFCTRS.DLL ### Compteurs de performance Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\system32\perfctrs.dll [Eventlog Application DLL] :HKLM Microsoft-Windows-PerfDisk=C:\WINDOWS\System32\PERFDISK.DLL ### DLL d’objets Performance de disque Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\system32\perfdisk.dll [Eventlog Application DLL] :HKLM Microsoft-Windows-Perflib=C:\WINDOWS\System32\PRFLBMSG.DLL ### Messages d’événements Perflib Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\system32\prflbmsg.dll [Eventlog Application DLL] :HKLM Microsoft-Windows-PerfNet=C:\WINDOWS\System32\PERFNET.DLL ### DLL d’objets Performance de service réseau Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\system32\perfnet.dll [Eventlog Application DLL] :HKLM Microsoft-Windows-PerfOS=C:\WINDOWS\System32\PERFOS.DLL ### DLL d’objets Performances système Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\system32\perfos.dll [Eventlog Application DLL] :HKLM Microsoft-Windows-PerfProc=C:\WINDOWS\System32\PERFPROC.DLL ### DLL d’objets Performances de processus système Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\system32\perfproc.dll [Eventlog Application DLL] :HKLM Microsoft-Windows-RemoteApp and Desktop Connections=C:\WINDOWS\System32\TSWORKSPACE.DLL ### Composant Connexion RemoteApp et Bureau à distance Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\system32\TSWorkspace.dll [Eventlog Application DLL] :HKLM Microsoft-Windows-RemoteAssistance=C:\WINDOWS\System32\MSRA.EXE ### Assistance à distance Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%systemroot%\system32\msra.exe [Eventlog Application DLL] :HKLM Microsoft-Windows-RestartManager=C:\WINDOWS\System32\RSTRTMGR.DLL ### Gestionnaire de démarrage Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\RstrtMgr.dll [Eventlog Application DLL] :HKLM Microsoft-Windows-RPC-Events=C:\WINDOWS\System32\RPCRT4.DLL ### Runtime d’appel de procédure distante Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\system32\rpcrt4.dll [Eventlog Application DLL] :HKLM Microsoft-Windows-Search=C:\WINDOWS\System32\TQUERY.DLL ### Microsoft Tripoli Query Microsoft Corporation Windows® Search 7.0.19041.867 !$*%SystemRoot%\system32\tquery.dll [Eventlog Application DLL] :HKLM Microsoft-Windows-Security-EnterpriseData-FileRevocationManager=C:\WINDOWS\System32\EFSWRT.DLL ### Storage Protection Windows Runtime DLL Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.746 !$*%SystemRoot%\system32\efswrt.dll [Eventlog Application DLL] :HKLM Microsoft-Windows-Security-SPP=C:\WINDOWS\SYSTEM32\SPPSVC.EXE ### Service de la plateforme de protection logicielle Microsoft Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%windir%\system32\sppsvc.exe [Eventlog Application DLL] :HKLM Microsoft-Windows-SoftwareRestrictionPolicies=C:\WINDOWS\System32\MICROSOFT-WINDOWS-SYSTEM-EVENTS.DLL ### Microsoft-Windows-Système-Ressources des événements Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\system32\Microsoft-Windows-System-Events.dll [Eventlog Application DLL] :HKLM Microsoft-Windows-Spell-Checking=C:\WINDOWS\System32\MSSPELLCHECKINGFACILITY.DLL ### Fonctions de vérification de l’orthographe Microsoft Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%systemroot%\System32\MsSpellCheckingFacility.dll [Eventlog Application DLL] :HKLM Microsoft-Windows-SpellChecker=C:\WINDOWS\System32\MSSPELLCHECKINGFACILITY.DLL ### Fonctions de vérification de l’orthographe Microsoft Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%systemroot%\System32\MsSpellCheckingFacility.dll [Eventlog Application DLL] :HKLM Microsoft-Windows-Spellchecking-Host=C:\WINDOWS\System32\MSSPELLCHECKINGHOST.EXE ### Microsoft Spell Checking Host Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.746 !$*%systemroot%\System32\MsSpellCheckingHost.exe [Eventlog Application DLL] :HKLM Microsoft-Windows-System-Restore=C:\WINDOWS\SYSTEM32\SREVENTS.DLL ### SrEvents Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*%windir%\system32\SrEvents.dll [Eventlog Application DLL] :HKLM Microsoft-Windows-TerminalServices-ClientActiveXCore=C:\WINDOWS\System32\MSTSCAX.DLL ### Client ActiveX des services Bureau à distance Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\system32\mstscax.dll [Eventlog Application DLL] :HKLM Microsoft-Windows-User Profiles General=C:\WINDOWS\System32\USERENV.DLL ### Userenv Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\userenv.dll [Eventlog Application DLL] :HKLM Microsoft-Windows-User Profiles Service=C:\WINDOWS\System32\PROFSVC.DLL ### ProfSvc Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\profsvc.dll [Eventlog Application DLL] :HKLM Microsoft-Windows-User-Loader=C:\WINDOWS\System32\MICROSOFT-WINDOWS-SYSTEM-EVENTS.DLL ### Microsoft-Windows-Système-Ressources des événements Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\system32\Microsoft-Windows-System-Events.dll [Eventlog Application DLL] :HKLM Microsoft-Windows-Video-For-Windows=C:\WINDOWS\System32\MCIAVI32.DLL ### Pilote MCI Video for Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\system32\mciavi32.dll [Eventlog Application DLL] :HKLM Microsoft-Windows-WindowsSystemAssessmentTool=C:\WINDOWS\System32\WINSAT.EXE ### Outil d’évaluation du système Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\system32\WINSAT.EXE [Eventlog Application DLL] :HKLM Microsoft-Windows-Winsrv=C:\WINDOWS\System32\WINSRV.DLL ### DLL serveur de Windows multi-utilisateurs Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\system32\winsrv.dll [Eventlog Application DLL] :HKLM Microsoft-Windows-WMI=C:\WINDOWS\System32\WBEM\WINMGMTR.DLL ### WMI Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\system32\wbem\WinMgmtR.dll [Eventlog Application DLL] :HKLM Microsoft-Windows-XWizards=C:\WINDOWS\SYSTEM32\XWIZARDS.DLL ### Module Gestionnaire d’Assistants extensible Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%windir%\system32\xwizards.dll [Eventlog Application DLL] :HKLM Microsoft.Transactions.Bridge 3.0.0.0=C:\WINDOWS\MICROSOFT.NET\FRAMEWORK64\V3.0\WINDOWS COMMUNICATION FOUNDATION\SERVICEMODELEVENTS.DLL ### Descriptions des événements associés à ServiceModel Microsoft Corporation Microsoft® .NET Framework 3.0.4506.9135 !$*C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\ServiceModelEvents.dll [Eventlog Application DLL] :HKLM Microsoft.Transactions.Bridge 4.0.0.0=C:\WINDOWS\MICROSOFT.NET\FRAMEWORK64\V4.0.30319\SERVICEMODELEVENTS.DLL ### Descriptions des événements associés à ServiceModel Microsoft Corporation Microsoft® .NET Framework 4.8.4084.0 !$*C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ServiceModelEvents.dll [Eventlog Application DLL] :HKLM NVIDIA OpenGL Driver=C:\WINDOWS\SYSTEM32\DRIVERSTORE\FILEREPOSITORY\NVMDI.INF_AMD64_6A0632B60438E56D\NVOGLV64.DLL ### NVIDIA Compatible OpenGL ICD NVIDIA Corporation NVIDIA Compatible OpenGL ICD 27.21.14.6677 !$*C:\WINDOWS\System32\DriverStore\FileRepository\nvmdi.inf_amd64_6a0632b60438e56d\nvoglv64.dll [Eventlog Application DLL] :HKLM Profsvc=C:\WINDOWS\System32\PROFSVC.DLL ### ProfSvc Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\profsvc.dll [Eventlog Application DLL] :HKLM SceCli=C:\WINDOWS\System32\SCECLI.DLL ### Moteur du client de l’Éditeur de configuration de sécurité Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\scecli.dll [Eventlog Application DLL] :HKLM SceSrv=C:\WINDOWS\System32\SCESRV.DLL ### Moteur de l’Éditeur de configuration de sécurité Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\scesrv.dll [Eventlog Application DLL] :HKLM SecurityCenter=C:\WINDOWS\System32\WSCSVC.DLL ### Service Centre de sécurité de Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\wscsvc.dll [Eventlog Application DLL] :HKLM ServiceModel Audit 3.0.0.0=C:\WINDOWS\MICROSOFT.NET\FRAMEWORK64\V3.0\WINDOWS COMMUNICATION FOUNDATION\SERVICEMODELEVENTS.DLL ### Descriptions des événements associés à ServiceModel Microsoft Corporation Microsoft® .NET Framework 3.0.4506.9135 !$*C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\ServiceModelEvents.dll [Eventlog Application DLL] :HKLM ServiceModel Audit 4.0.0.0=C:\WINDOWS\MICROSOFT.NET\FRAMEWORK64\V4.0.30319\SERVICEMODELEVENTS.DLL ### Descriptions des événements associés à ServiceModel Microsoft Corporation Microsoft® .NET Framework 4.8.4084.0 !$*C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ServiceModelEvents.dll [Eventlog Application DLL] :HKLM SideBySide=C:\WINDOWS\System32\SXS.DLL ### Fusion 2.5 Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\sxs.dll [Eventlog Application DLL] :HKLM Software Protection Platform Service=C:\WINDOWS\System32\SPPSVC.EXE ### Service de la plateforme de protection logicielle Microsoft Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\system32\sppsvc.exe [Eventlog Application DLL] :HKLM SpeechRuntime=C:\WINDOWS\SYSTEM32\SPEECH_ONECORE\COMMON\SAPI_ONECORE.DLL ### Speech API Microsoft Corporation Microsoft® Speech Recognizer 11.1 5.3.19041.1023 ->SAPI.DLL !$*C:\Windows\System32\Speech_OneCore\Common\sapi_onecore.dll [Eventlog Application DLL] :HKLM Steam Client Service=C:\Program Files (x86)\Steam\bin\steamservice.exe ### File is missing. !$*C:\Program Files (x86)\Steam\bin\steamservice.exe [Eventlog Application DLL] :HKLM SteelSeriesUpdateService=C:\WINDOWS\MICROSOFT.NET\FRAMEWORK64\V4.0.30319\EVENTLOGMESSAGES.DLL ### EventLogMessages.dll Microsoft Corporation Microsoft® .NET Framework 4.8.4084.0 !$*C:\Windows\Microsoft.NET\Framework64\v4.0.30319\EventLogMessages.dll [Eventlog Application DLL] :HKLM System.IdentityModel 3.0.0.0=C:\WINDOWS\MICROSOFT.NET\FRAMEWORK64\V3.0\WINDOWS COMMUNICATION FOUNDATION\SERVICEMODELEVENTS.DLL ### Descriptions des événements associés à ServiceModel Microsoft Corporation Microsoft® .NET Framework 3.0.4506.9135 !$*C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\ServiceModelEvents.dll [Eventlog Application DLL] :HKLM System.IdentityModel 4.0.0.0=C:\WINDOWS\MICROSOFT.NET\FRAMEWORK64\V4.0.30319\SERVICEMODELEVENTS.DLL ### Descriptions des événements associés à ServiceModel Microsoft Corporation Microsoft® .NET Framework 4.8.4084.0 !$*C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ServiceModelEvents.dll [Eventlog Application DLL] :HKLM System.IO.Log 3.0.0.0=C:\WINDOWS\MICROSOFT.NET\FRAMEWORK64\V3.0\WINDOWS COMMUNICATION FOUNDATION\SERVICEMODELEVENTS.DLL ### Descriptions des événements associés à ServiceModel Microsoft Corporation Microsoft® .NET Framework 3.0.4506.9135 !$*C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\ServiceModelEvents.dll [Eventlog Application DLL] :HKLM System.IO.Log 4.0.0.0=C:\WINDOWS\MICROSOFT.NET\FRAMEWORK64\V4.0.30319\SERVICEMODELEVENTS.DLL ### Descriptions des événements associés à ServiceModel Microsoft Corporation Microsoft® .NET Framework 4.8.4084.0 !$*C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ServiceModelEvents.dll [Eventlog Application DLL] :HKLM System.Runtime.Serialization 3.0.0.0=C:\WINDOWS\MICROSOFT.NET\FRAMEWORK64\V3.0\WINDOWS COMMUNICATION FOUNDATION\SERVICEMODELEVENTS.DLL ### Descriptions des événements associés à ServiceModel Microsoft Corporation Microsoft® .NET Framework 3.0.4506.9135 !$*C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\ServiceModelEvents.dll [Eventlog Application DLL] :HKLM System.Runtime.Serialization 4.0.0.0=C:\WINDOWS\MICROSOFT.NET\FRAMEWORK64\V4.0.30319\SERVICEMODELEVENTS.DLL ### Descriptions des événements associés à ServiceModel Microsoft Corporation Microsoft® .NET Framework 4.8.4084.0 !$*C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ServiceModelEvents.dll [Eventlog Application DLL] :HKLM System.ServiceModel 3.0.0.0=C:\WINDOWS\MICROSOFT.NET\FRAMEWORK64\V3.0\WINDOWS COMMUNICATION FOUNDATION\SERVICEMODELEVENTS.DLL ### Descriptions des événements associés à ServiceModel Microsoft Corporation Microsoft® .NET Framework 3.0.4506.9135 !$*C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\ServiceModelEvents.dll [Eventlog Application DLL] :HKLM System.ServiceModel 4.0.0.0=C:\WINDOWS\MICROSOFT.NET\FRAMEWORK64\V4.0.30319\SERVICEMODELEVENTS.DLL ### Descriptions des événements associés à ServiceModel Microsoft Corporation Microsoft® .NET Framework 4.8.4084.0 !$*C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ServiceModelEvents.dll [Eventlog Application DLL] :HKLM usbperf=C:\WINDOWS\System32\USBPERF.DLL ### DLL des objets de performance USB Microsoft Corporation Système d'exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\system32\usbperf.dll [Eventlog Application DLL] :HKLM Userenv=C:\WINDOWS\System32\USERENV.DLL ### Userenv Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\userenv.dll [Eventlog Application DLL] :HKLM VBRuntime=C:\WINDOWS\SYSWOW64\MSVBVM60.DLL ### Visual Basic Virtual Machine Microsoft Corporation Visual Basic 6.00.9848 !$*C:\Windows\SysWOW64\msvbvm60.dll [Eventlog Application DLL] :HKLM Virtual Desktop Service=C:\WINDOWS\MICROSOFT.NET\FRAMEWORK64\V4.0.30319\EVENTLOGMESSAGES.DLL ### EventLogMessages.dll Microsoft Corporation Microsoft® .NET Framework 4.8.4084.0 !$*C:\Windows\Microsoft.NET\Framework64\v4.0.30319\EventLogMessages.dll [Eventlog Application DLL] :HKLM VSSetup=g:\1f7fce1c581552a6e22287131dfdf12c\DW\DW20.exe ### File is missing. !$*g:\1f7fce1c581552a6e22287131dfdf12c\DW\DW20.exe [Eventlog Application DLL] :HKLM Windows Error Reporting=C:\WINDOWS\System32\WER.DLL ### DLL du rapport d’erreurs Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\wer.dll [Eventlog Application DLL] :HKLM Wininit=C:\WINDOWS\System32\WININIT.EXE ### Application de démarrage de Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\wininit.exe [Eventlog Application DLL] :HKLM Winlogon=C:\WINDOWS\System32\WINLOGON.EXE ### Application d’ouverture de session Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\winlogon.exe [Eventlog Application DLL] :HKLM Wlclntfy=C:\WINDOWS\System32\WINLOGON.EXE ### Application d’ouverture de session Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\winlogon.exe [Eventlog Application DLL] :HKLM WMI.NET Provider Extension=C:\WINDOWS\MICROSOFT.NET\FRAMEWORK64\V4.0.30319\EVENTLOGMESSAGES.DLL ### EventLogMessages.dll Microsoft Corporation Microsoft® .NET Framework 4.8.4084.0 !$*C:\Windows\Microsoft.NET\Framework64\v4.0.30319\EventLogMessages.dll [Eventlog Application DLL] :HKLM Wow64 Emulation Layer=C:\WINDOWS\System32\NTVDM64.DLL ### Émulation 16 bits sur NT64 Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\ntvdm64.dll [Eventlog Application DLL] :HKLM WSH=C:\WINDOWS\System32\WSHEXT.DLL ### Microsoft ® Shell Extension for Windows Script Host Microsoft Corporation Microsoft ® Windows Script Host 5.812.10240.16384 !$*%SystemRoot%\System32\wshext.dll [Drivers] :HKLM 1394ohci=C:\WINDOWS\SYSTEM32\DRIVERS\1394OHCI.SYS ### 1394 OpenHCI Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*\SystemRoot\System32\drivers\1394ohci.sys [Drivers] :HKLM 3ware=C:\WINDOWS\SYSTEM32\DRIVERS\3WARE.SYS ### LSI 3ware SCSI Storport Driver LSI LSI 3ware RAID Controller WindowsBlue !$*C:\WINDOWS\System32\drivers\3ware.sys [Drivers] :HKLM A7000=C:\WINDOWS\SYSTEM32\DRIVERS\A7000.SYS ### Realtek WLAN USB NDIS Driver 60477 Realtek Semiconductor Corporation Realtek WLAN Wireless USB 2.0 Adapter 1030.25.0701.2017 ->RTWLANU.SYS !$*\SystemRoot\system32\DRIVERS\A7000.sys [Drivers] :HKLM ACPI=C:\WINDOWS\SYSTEM32\DRIVERS\ACPI.SYS ### Pilote ACPI pour NT Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.1 !$*C:\WINDOWS\System32\drivers\ACPI.sys [Drivers] :HKLM AcpiDev=C:\WINDOWS\SYSTEM32\DRIVERS\ACPIDEV.SYS ### ACPI Devices Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*\SystemRoot\System32\drivers\AcpiDev.sys [Drivers] :HKLM acpiex=C:\WINDOWS\SYSTEM32\DRIVERS\ACPIEX.SYS ### ACPIEx Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*C:\WINDOWS\System32\Drivers\acpiex.sys [Drivers] :HKLM acpipagr=C:\WINDOWS\SYSTEM32\DRIVERS\ACPIPAGR.SYS ### ACPI Processor Aggregator Device Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*\SystemRoot\System32\drivers\acpipagr.sys [Drivers] :HKLM AcpiPmi=C:\WINDOWS\SYSTEM32\DRIVERS\ACPIPMI.SYS ### ACPI Power Metering Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*\SystemRoot\System32\drivers\acpipmi.sys [Drivers] :HKLM acpitime=C:\WINDOWS\SYSTEM32\DRIVERS\ACPITIME.SYS ### ACPI Wake Alarm Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*\SystemRoot\System32\drivers\acpitime.sys [Drivers] :HKLM Acx01000=C:\WINDOWS\SYSTEM32\DRIVERS\ACX01000.SYS ### Audio KMDF Class Extension Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*C:\WINDOWS\system32\drivers\Acx01000.sys [Drivers] :HKLM ADP80XX=C:\WINDOWS\SYSTEM32\DRIVERS\ADP80XX.SYS ### PMC-Sierra Storport Driver For SPC8x6G SAS/SATA controller PMC-Sierra PMC-Sierra HBA Controller 1.3.0.10769 !$*C:\WINDOWS\System32\drivers\ADP80XX.SYS [Drivers] :HKLM AFD=C:\WINDOWS\SYSTEM32\DRIVERS\AFD.SYS ### Pilote de fonction connexe pour WinSock Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*\SystemRoot\system32\drivers\afd.sys [Drivers] :HKLM afunix=C:\WINDOWS\SYSTEM32\DRIVERS\AFUNIX.SYS ### AF_UNIX socket provider Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.488 !$*\SystemRoot\system32\drivers\afunix.sys [Drivers] :HKLM ahcache=C:\WINDOWS\SYSTEM32\DRIVERS\AHCACHE.SYS ### Application Compatibility Cache Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.928 !$*C:\WINDOWS\system32\DRIVERS\ahcache.sys [Drivers] :HKLM amdgpio2=C:\WINDOWS\SYSTEM32\DRIVERS\AMDGPIO2.SYS ### AMD GPIO Controller Driver Advanced Micro Devices, Inc AMD GPIO Controller Driver 2.2.0.71 !$*\SystemRoot\System32\drivers\amdgpio2.sys [Drivers] :HKLM amdi2c=C:\WINDOWS\SYSTEM32\DRIVERS\AMDI2C.SYS ### AMD I2C Controller Driver Advanced Micro Devices, Inc AMD I2C Controller Driver 1.2.0.99 !$*\SystemRoot\System32\drivers\amdi2c.sys [Drivers] :HKLM AmdK8=C:\WINDOWS\SYSTEM32\DRIVERS\AMDK8.SYS ### Processor Device Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.546 !$*\SystemRoot\System32\drivers\amdk8.sys [Drivers] :HKLM AmdPPM=C:\WINDOWS\SYSTEM32\DRIVERS\AMDPPM.SYS ### Processor Device Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.546 !$*\SystemRoot\System32\drivers\amdppm.sys [Drivers] :HKLM amdsata=C:\WINDOWS\SYSTEM32\DRIVERS\AMDSATA.SYS ### AHCI 1.3 Device Driver Advanced Micro Devices AHCI 1.3 Device Driver 1.1.3.277 !$*C:\WINDOWS\System32\drivers\amdsata.sys [Drivers] :HKLM amdsbs=C:\WINDOWS\SYSTEM32\DRIVERS\AMDSBS.SYS ### AMD Technology AHCI Compatible Controller Driver for Windows - AMD64 platform AMD Technologies Inc. AMD Technology AHCI Compatible Controller 3.7.1540.43 !$*C:\WINDOWS\System32\drivers\amdsbs.sys [Drivers] :HKLM amdxata=C:\WINDOWS\SYSTEM32\DRIVERS\AMDXATA.SYS ### Storage Filter Driver Advanced Micro Devices Storage Filter Driver 1.1.3.277 !$*C:\WINDOWS\System32\drivers\amdxata.sys [Drivers] :HKLM ampa=C:\WINDOWS\SYSTEM32\AMPA.SYS ### !$*\??\C:\WINDOWS\system32\ampa.sys [Drivers] :HKLM AppID=C:\WINDOWS\SYSTEM32\DRIVERS\APPID.SYS ### AppID Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1023 !$*C:\WINDOWS\system32\drivers\appid.sys [Drivers] :HKLM applockerfltr=C:\WINDOWS\SYSTEM32\DRIVERS\APPLOCKERFLTR.SYS ### Applocker Filter Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.546 !$*C:\WINDOWS\system32\drivers\applockerfltr.sys [Drivers] :HKLM arcsas=C:\WINDOWS\SYSTEM32\DRIVERS\ARCSAS.SYS ### Adaptec SAS RAID WS03 Driver PMC-Sierra, Inc. Adaptec RAID Controller 7.5.0.32048 ->ARCSAS.SYS.B32048.MCB !$*C:\WINDOWS\System32\drivers\arcsas.sys [Drivers] :HKLM AsyncMac=C:\WINDOWS\SYSTEM32\DRIVERS\ASYNCMAC.SYS ### MS Remote Access serial network driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*\SystemRoot\System32\drivers\asyncmac.sys [Drivers] :HKLM atapi=C:\WINDOWS\SYSTEM32\DRIVERS\ATAPI.SYS ### ATAPI IDE Miniport Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.906 !$*C:\WINDOWS\System32\drivers\atapi.sys [Drivers] :HKLM b06bdrv=C:\WINDOWS\SYSTEM32\DRIVERS\BXVBDA.SYS ### QLogic Gigabit Ethernet VBD QLogic Corporation QLogic Gigabit Ethernet 7.12.31.105 !$*C:\WINDOWS\System32\drivers\bxvbda.sys [Drivers] :HKLM bam=C:\WINDOWS\SYSTEM32\DRIVERS\BAM.SYS ### BAM Kernel Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*C:\WINDOWS\system32\drivers\bam.sys [Drivers] :HKLM BasicDisplay=C:\WINDOWS\SYSTEM32\DRIVERSTORE\FILEREPOSITORY\BASICDISPLAY.INF_AMD64_65AB9A260DBF7467\BASICDISPLAY.SYS ### Microsoft Basic Display Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.868 !$*\SystemRoot\System32\DriverStore\FileRepository\basicdisplay.inf_amd64_65ab9a260dbf7467\BasicDisplay.sys [Drivers] :HKLM BasicRender=C:\WINDOWS\SYSTEM32\DRIVERSTORE\FILEREPOSITORY\BASICRENDER.INF_AMD64_DF49C4DAA6251397\BASICRENDER.SYS ### Microsoft Basic Render Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.868 !$*\SystemRoot\System32\DriverStore\FileRepository\basicrender.inf_amd64_df49c4daa6251397\BasicRender.sys [Drivers] :HKLM bcmfn2=C:\WINDOWS\SYSTEM32\DRIVERS\BCMFN2.SYS ### BCM Function 2 Device Driver Windows (R) Win 7 DDK provider Windows (R) Win 7 DDK driver 6.3.9600.17336 !$*\SystemRoot\System32\drivers\bcmfn2.sys [Drivers] :HKLM bindflt=C:\WINDOWS\SYSTEM32\DRIVERS\BINDFLT.SYS ### Windows Bind Filter Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1052 !$*\SystemRoot\system32\drivers\bindflt.sys [Drivers] :HKLM bowser=C:\WINDOWS\SYSTEM32\DRIVERS\BOWSER.SYS ### NT Lan Manager Datagram Receiver Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.746 ->BROWSER.SYS !$*C:\WINDOWS\system32\DRIVERS\bowser.sys [Drivers] :HKLM BthA2dp=C:\WINDOWS\SYSTEM32\DRIVERS\BTHA2DP.SYS ### Bluetooth A2DP Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*\SystemRoot\System32\drivers\BthA2dp.sys [Drivers] :HKLM BthEnum=C:\WINDOWS\SYSTEM32\DRIVERS\BTHENUM.SYS ### Extension de bus Bluetooth Microsoft Corporation Système d'exploitation Microsoft® Windows® 10.0.19041.985 !$*\SystemRoot\System32\drivers\BthEnum.sys [Drivers] :HKLM BthHFEnum=C:\WINDOWS\SYSTEM32\DRIVERS\BTHHFENUM.SYS ### Bluetooth Hands-Free Audio and Call Control HID Enumerator Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*\SystemRoot\System32\drivers\bthhfenum.sys [Drivers] :HKLM BthLEEnum=C:\WINDOWS\SYSTEM32\DRIVERS\MICROSOFT.BLUETOOTH.LEGACY.LEENUMERATOR.SYS ### Legacy Bluetooth LE Bus Enumerator Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.488 !$*\SystemRoot\System32\drivers\Microsoft.Bluetooth.Legacy.LEEnumerator.sys [Drivers] :HKLM BthMini=C:\WINDOWS\SYSTEM32\DRIVERS\BTHMINI.SYS ### Bluetooth Transport Extensibility Miniport Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.985 !$*\SystemRoot\System32\drivers\BTHMINI.sys [Drivers] :HKLM BTHMODEM=C:\WINDOWS\SYSTEM32\DRIVERS\BTHMODEM.SYS ### Bluetooth Communications Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*\SystemRoot\System32\drivers\bthmodem.sys [Drivers] :HKLM BTHPORT=C:\WINDOWS\SYSTEM32\DRIVERS\BTHPORT.SYS ### Pilote de bus Bluetooth Microsoft Corporation Système d'exploitation Microsoft® Windows® 10.0.19041.985 !$*\SystemRoot\System32\drivers\BTHport.sys [Drivers] :HKLM BTHUSB=C:\WINDOWS\SYSTEM32\DRIVERS\BTHUSB.SYS ### Pilote de Miniport Bluetooth Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.985 !$*\SystemRoot\System32\drivers\BTHUSB.sys [Drivers] :HKLM bttflt=C:\WINDOWS\SYSTEM32\DRIVERS\BTTFLT.SYS ### VHD BTT Filter Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*C:\WINDOWS\System32\drivers\bttflt.sys [Drivers] :HKLM buttonconverter=C:\WINDOWS\SYSTEM32\DRIVERS\BUTTONCONVERTER.SYS ### Button Converter Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 ->BTNCONV.SYS !$*\SystemRoot\System32\drivers\buttonconverter.sys [Drivers] :HKLM CAD=C:\WINDOWS\SYSTEM32\DRIVERS\CAD.SYS ### Charge Arbiration Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*\SystemRoot\System32\drivers\CAD.sys [Drivers] :HKLM cdfs=C:\WINDOWS\SYSTEM32\DRIVERS\CDFS.SYS ### CD-ROM File System Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*C:\WINDOWS\system32\DRIVERS\cdfs.sys [Drivers] :HKLM cdrom=C:\WINDOWS\SYSTEM32\DRIVERS\CDROM.SYS ### SCSI CD-ROM Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*\SystemRoot\System32\drivers\cdrom.sys [Drivers] :HKLM cht4iscsi=C:\WINDOWS\SYSTEM32\DRIVERS\CHT4SX64.SYS ### Chelsio iSCSI VMiniport Driver Chelsio Communications Chelsio Communications iSCSI Controller 10.0.10011.16384 ->CHT4ISCSI.SYS !$*C:\WINDOWS\System32\drivers\cht4sx64.sys [Drivers] :HKLM cht4vbd=C:\WINDOWS\SYSTEM32\DRIVERS\CHT4VX64.SYS ### Virtual Bus Driver for Chelsio ® T5/T6 Chipset Chelsio Communications Chelsio Communications Unified Network I/O Controller 10.0.10011.16384 ->CHT4VBD.SYS !$*\SystemRoot\System32\drivers\cht4vx64.sys [Drivers] :HKLM circlass=C:\WINDOWS\SYSTEM32\DRIVERS\CIRCLASS.SYS ### Consumer IR Class Driver for eHome Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*\SystemRoot\System32\drivers\circlass.sys [Drivers] :HKLM CldFlt=C:\WINDOWS\SYSTEM32\DRIVERS\CLDFLT.SYS ### Cloud Files Mini Filter Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1052 !$*C:\WINDOWS\system32\drivers\cldflt.sys [Drivers] :HKLM CLFS=C:\WINDOWS\SYSTEM32\DRIVERS\CLFS.SYS ### Common Log File System Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1052 !$*C:\WINDOWS\System32\drivers\CLFS.sys [Drivers] :HKLM CmBatt=C:\WINDOWS\SYSTEM32\DRIVERS\CMBATT.SYS ### Control Method Battery Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*\SystemRoot\System32\drivers\CmBatt.sys [Drivers] :HKLM CNG=C:\WINDOWS\SYSTEM32\DRIVERS\CNG.SYS ### Kernel Cryptography, Next Generation Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1023 !$*C:\WINDOWS\System32\Drivers\cng.sys [Drivers] :HKLM cnghwassist=C:\WINDOWS\SYSTEM32\DRIVERS\CNGHWASSIST.SYS ### CNG Hardware Assist algorithm provider Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*C:\WINDOWS\System32\DRIVERS\cnghwassist.sys [Drivers] :HKLM CompositeBus=C:\WINDOWS\SYSTEM32\DRIVERSTORE\FILEREPOSITORY\COMPOSITEBUS.INF_AMD64_7500CFFA210C6946\COMPOSITEBUS.SYS ### Multi-Transport Composite Bus Enumerator Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*\SystemRoot\System32\DriverStore\FileRepository\compositebus.inf_amd64_7500cffa210c6946\CompositeBus.sys [Drivers] :HKLM condrv=C:\WINDOWS\SYSTEM32\DRIVERS\CONDRV.SYS ### Console Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.928 !$*C:\WINDOWS\System32\drivers\condrv.sys [Drivers] :HKLM dam=C:\WINDOWS\SYSTEM32\DRIVERS\DAM.SYS ### DAM Kernel Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1052 !$*C:\WINDOWS\system32\drivers\dam.sys [Drivers] :HKLM ddmdrv=C:\WINDOWS\SYSTEM32\DDMDRV.SYS ### !$*\??\C:\WINDOWS\system32\ddmdrv.sys [Drivers] :HKLM Dfsc=C:\WINDOWS\SYSTEM32\DRIVERS\DFSC.SYS ### DFS Namespace Client Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.844 ->DFSCLIENT.SYS !$*C:\WINDOWS\System32\Drivers\dfsc.sys [Drivers] :HKLM disk=C:\WINDOWS\SYSTEM32\DRIVERS\DISK.SYS ### PnP Disk Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*C:\WINDOWS\System32\drivers\disk.sys [Drivers] :HKLM dmvsc=C:\WINDOWS\SYSTEM32\DRIVERS\DMVSC.SYS ### Mémoire dynamique Microsoft Corporation Système d'exploitation Microsoft® Windows® 10.0.19041.1 !$*\SystemRoot\System32\drivers\dmvsc.sys [Drivers] :HKLM drmkaud=C:\WINDOWS\SYSTEM32\DRIVERS\DRMKAUD.SYS ### Microsoft Trusted Audio Drivers Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.746 !$*\SystemRoot\System32\drivers\drmkaud.sys [Drivers] :HKLM dtlitescsibus=C:\WINDOWS\SYSTEM32\DRIVERS\DTLITESCSIBUS.SYS ### DAEMON Tools Lite Virtual SCSI Bus Driver Disc Soft Ltd DAEMON Tools Lite Virtual SCSI Bus 5.29.0.0 !$*\SystemRoot\System32\drivers\dtlitescsibus.sys [Drivers] :HKLM dtliteusbbus=C:\WINDOWS\SYSTEM32\DRIVERS\DTLITEUSBBUS.SYS ### DAEMON Tools Lite Virtual USB Bus Driver Disc Soft Ltd DAEMON Tools Lite Virtual USB Bus 3.05.0.0 !$*\SystemRoot\System32\drivers\dtliteusbbus.sys [Drivers] :HKLM DXGKrnl=C:\WINDOWS\SYSTEM32\DRIVERS\DXGKRNL.SYS ### DirectX Graphics Kernel Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1023 !$*\SystemRoot\System32\drivers\dxgkrnl.sys [Drivers] :HKLM e1dexpress=C:\WINDOWS\SYSTEM32\DRIVERSTORE\FILEREPOSITORY\E1D68X64.INF_AMD64_26255692C8B1C6B6\E1D68X64.SYS ### Intel(R) Gigabit Adapter NDIS 6.x driver Intel Corporation Intel(R) Gigabit Adapter 12.19.0.16 !$*\SystemRoot\System32\DriverStore\FileRepository\e1d68x64.inf_amd64_26255692c8b1c6b6\e1d68x64.sys [Drivers] :HKLM ebdrv=C:\WINDOWS\SYSTEM32\DRIVERS\EVBDA.SYS ### QLogic 10 GigE VBD QLogic Corporation QLogic 10 GigE 7.13.65.105 ->EVBDA.SYS" FW VER:7.13.1.0 FW COMPILE:1 !$*C:\WINDOWS\System32\drivers\evbda.sys [Drivers] :HKLM EhStorClass=C:\WINDOWS\SYSTEM32\DRIVERS\EHSTORCLASS.SYS ### Enhanced Storage Class driver for IEEE 1667 devices Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.964 !$*C:\WINDOWS\System32\drivers\EhStorClass.sys [Drivers] :HKLM EhStorTcgDrv=C:\WINDOWS\SYSTEM32\DRIVERS\EHSTORTCGDRV.SYS ### Microsoft driver for storage devices supporting IEEE 1667 and TCG protocols Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*C:\WINDOWS\System32\drivers\EhStorTcgDrv.sys [Drivers] :HKLM ErrDev=C:\WINDOWS\SYSTEM32\DRIVERS\ERRDEV.SYS ### Error Device Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*\SystemRoot\System32\drivers\errdev.sys [Drivers] :HKLM fdc=C:\WINDOWS\SYSTEM32\DRIVERS\FDC.SYS ### Floppy Disk Controller Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*\SystemRoot\System32\drivers\fdc.sys [Drivers] :HKLM FileCrypt=C:\WINDOWS\SYSTEM32\DRIVERS\FILECRYPT.SYS ### Windows sandboxing and encryption filter Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*C:\WINDOWS\system32\drivers\filecrypt.sys [Drivers] :HKLM FileInfo=C:\WINDOWS\SYSTEM32\DRIVERS\FILEINFO.SYS ### FileInfo Filter Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*C:\WINDOWS\System32\drivers\fileinfo.sys [Drivers] :HKLM Filetrace=C:\WINDOWS\SYSTEM32\DRIVERS\FILETRACE.SYS ### File Trace Filter Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*C:\WINDOWS\system32\drivers\filetrace.sys [Drivers] :HKLM flpydisk=C:\WINDOWS\SYSTEM32\DRIVERS\FLPYDISK.SYS ### Floppy Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 ->FLOPPY.SYS !$*\SystemRoot\System32\drivers\flpydisk.sys [Drivers] :HKLM FltMgr=C:\WINDOWS\SYSTEM32\DRIVERS\FLTMGR.SYS ### Gestionnaire de filtres de système de fichiers Microsoft Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\drivers\fltmgr.sys [Drivers] :HKLM FsDepends=C:\WINDOWS\SYSTEM32\DRIVERS\FSDEPENDS.SYS ### File System Dependency Manager Mini Filter Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.928 !$*C:\WINDOWS\System32\drivers\FsDepends.sys [Drivers] :HKLM fvevol=C:\WINDOWS\SYSTEM32\DRIVERS\FVEVOL.SYS ### BitLocker Drive Encryption Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.867 !$*C:\WINDOWS\System32\DRIVERS\fvevol.sys [Drivers] :HKLM gameflt=C:\WINDOWS\SYSTEM32\DRIVERSTORE\FILEREPOSITORY\GAMEFLT.INF_AMD64_B38109E173F2592D\GAMEFLT.SYS ### Gaming Filter Microsoft Corporation Microsoft Gaming Install Filter Driver 10.0.19041.7181 !$*\SystemRoot\System32\DriverStore\FileRepository\gameflt.inf_amd64_b38109e173f2592d\gameflt.sys [Drivers] :HKLM gencounter=C:\WINDOWS\SYSTEM32\DRIVERS\VMGENCOUNTER.SYS ### Virtual Machine Generation Counter Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*\SystemRoot\System32\drivers\vmgencounter.sys [Drivers] :HKLM genericusbfn=C:\WINDOWS\SYSTEM32\DRIVERSTORE\FILEREPOSITORY\GENERICUSBFN.INF_AMD64_53931F0AE21D6D2C\GENERICUSBFN.SYS ### Generic USB Function Class Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*\SystemRoot\System32\DriverStore\FileRepository\genericusbfn.inf_amd64_53931f0ae21d6d2c\genericusbfn.sys [Drivers] :HKLM GPIOClx0101=C:\WINDOWS\SYSTEM32\DRIVERS\MSGPIOCLX.SYS ### GPIO Class Extension Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.488 !$*C:\WINDOWS\System32\Drivers\msgpioclx.sys [Drivers] :HKLM gpsvc=C:\WINDOWS\SYSTEM32\DRIVERS\MSGPIOCLX.SYS ### GPIO Class Extension Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.488 !$*C:\WINDOWS\System32\Drivers\msgpioclx.sys [Drivers] :HKLM GpuEnergyDrv=C:\WINDOWS\SYSTEM32\DRIVERS\GPUENERGYDRV.SYS ### GPU Energy Kernel Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*C:\WINDOWS\System32\drivers\gpuenergydrv.sys [Drivers] :HKLM Hamachi=C:\WINDOWS\SYSTEM32\DRIVERS\HAMDRV.SYS ### LogMeIn Hamachi Virtual Miniport Driver LogMeIn Inc. LogMeIn Hamachi Virtual Network Adapter 8.01.04.0001 !$*\SystemRoot\System32\drivers\Hamdrv.sys [Drivers] :HKLM HdAudAddService=C:\WINDOWS\SYSTEM32\DRIVERS\HDAUDIO.SYS ### High Definition Audio Function Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.264 !$*\SystemRoot\System32\drivers\HdAudio.sys [Drivers] :HKLM HDAudBus=C:\WINDOWS\SYSTEM32\DRIVERS\HDAUDBUS.SYS ### High Definition Audio Bus Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*\SystemRoot\System32\drivers\HDAudBus.sys [Drivers] :HKLM HidBatt=C:\WINDOWS\SYSTEM32\DRIVERS\HIDBATT.SYS ### Hid Battery Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*\SystemRoot\System32\drivers\HidBatt.sys [Drivers] :HKLM HidBth=C:\WINDOWS\SYSTEM32\DRIVERS\HIDBTH.SYS ### Pilote de miniport Bluetooth pour les périphériques HID Microsoft Corporation Système d'exploitation Microsoft® Windows® 10.0.19041.1 !$*\SystemRoot\System32\drivers\hidbth.sys [Drivers] :HKLM hidi2c=C:\WINDOWS\SYSTEM32\DRIVERS\HIDI2C.SYS ### I2C HID Miniport Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*\SystemRoot\System32\drivers\hidi2c.sys [Drivers] :HKLM hidinterrupt=C:\WINDOWS\SYSTEM32\DRIVERS\HIDINTERRUPT.SYS ### HID Button over Interrupt Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*\SystemRoot\System32\drivers\hidinterrupt.sys [Drivers] :HKLM HidIr=C:\WINDOWS\SYSTEM32\DRIVERS\HIDIR.SYS ### Infrared Miniport Driver for Input Devices Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*\SystemRoot\System32\drivers\hidir.sys [Drivers] :HKLM hidspi=C:\WINDOWS\SYSTEM32\DRIVERS\HIDSPI.SYS ### SPI HID Miniport Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*\SystemRoot\System32\drivers\hidspi.sys [Drivers] :HKLM HidUsb=C:\WINDOWS\SYSTEM32\DRIVERS\HIDUSB.SYS ### USB Miniport Driver for Input Devices Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.868 !$*\SystemRoot\System32\drivers\hidusb.sys [Drivers] :HKLM HpSAMD=C:\WINDOWS\SYSTEM32\DRIVERS\HPSAMD.SYS ### Smart Array SAS/SATA Controller Media Driver Hewlett-Packard Company Smart Array SAS/SATA Controller Media Driver 8.0.4.0 Build 1 Media Driver (x86-64) !$*C:\WINDOWS\System32\drivers\HpSAMD.sys [Drivers] :HKLM HTTP=C:\WINDOWS\SYSTEM32\DRIVERS\HTTP.SYS ### HTTP Pile du protocole Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\drivers\HTTP.sys [Drivers] :HKLM hvcrash=C:\WINDOWS\SYSTEM32\DRIVERS\HVCRASH.SYS ### Hyper-V Crashdump Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*\SystemRoot\System32\drivers\hvcrash.sys [Drivers] :HKLM hvservice=C:\WINDOWS\SYSTEM32\DRIVERS\HVSERVICE.SYS ### Hypervisor Boot Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*C:\WINDOWS\system32\drivers\hvservice.sys [Drivers] :HKLM HwNClx0101=C:\WINDOWS\SYSTEM32\DRIVERS\MSHWNCLX.SYS ### Hardware Notification Class Extension Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*C:\WINDOWS\System32\Drivers\mshwnclx.sys [Drivers] :HKLM hwpolicy=C:\WINDOWS\SYSTEM32\DRIVERS\HWPOLICY.SYS ### Hardware Policy Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.423 !$*C:\WINDOWS\System32\drivers\hwpolicy.sys [Drivers] :HKLM hyperkbd=C:\WINDOWS\SYSTEM32\DRIVERS\HYPERKBD.SYS ### Microsoft VMBus Synthetic Keyboard Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*\SystemRoot\System32\drivers\hyperkbd.sys [Drivers] :HKLM HyperVideo=C:\WINDOWS\SYSTEM32\DRIVERS\HYPERVIDEO.SYS ### Microsoft VMBus Video Device Miniport Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*\SystemRoot\System32\drivers\HyperVideo.sys [Drivers] :HKLM i8042prt=C:\WINDOWS\SYSTEM32\DRIVERS\I8042PRT.SYS ### Pilote de port i8042 Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.1 !$*\SystemRoot\System32\drivers\i8042prt.sys [Drivers] :HKLM iagpio=C:\WINDOWS\SYSTEM32\DRIVERS\IAGPIO.SYS ### Intel(R) Serial IO GPIO Controller Driver Intel(R) Corporation Intel(R) Serial IO GPIO Controller Driver 1.1.1.0 !$*\SystemRoot\System32\drivers\iagpio.sys [Drivers] :HKLM iai2c=C:\WINDOWS\SYSTEM32\DRIVERS\IAI2C.SYS ### Intel(R) Serial IO I2C Driver Intel(R) Corporation Intel(R) Serial IO I2C Driver 1.1.1.0 !$*\SystemRoot\System32\drivers\iai2c.sys [Drivers] :HKLM iaLPSS2i_GPIO2=C:\WINDOWS\SYSTEM32\DRIVERS\IALPSS2I_GPIO2.SYS ### Intel(R) Serial IO GPIO Driver v2 Intel Corporation Intel(R) Serial IO Driver 30.100.1816.3 !$*\SystemRoot\System32\drivers\iaLPSS2i_GPIO2.sys [Drivers] :HKLM iaLPSS2i_GPIO2_BXT_P=C:\WINDOWS\SYSTEM32\DRIVERS\IALPSS2I_GPIO2_BXT_P.SYS ### Intel(R) Serial IO GPIO Driver v2 Intel Corporation Intel(R) Serial IO Driver 30.100.1816.1 !$*\SystemRoot\System32\drivers\iaLPSS2i_GPIO2_BXT_P.sys [Drivers] :HKLM iaLPSS2i_GPIO2_CNL=C:\WINDOWS\SYSTEM32\DRIVERS\IALPSS2I_GPIO2_CNL.SYS ### Intel(R) Serial IO GPIO Driver v2 Intel Corporation Intel(R) Serial IO Driver 30.100.1816.3 !$*\SystemRoot\System32\drivers\iaLPSS2i_GPIO2_CNL.sys [Drivers] :HKLM iaLPSS2i_GPIO2_GLK=C:\WINDOWS\SYSTEM32\DRIVERS\IALPSS2I_GPIO2_GLK.SYS ### Intel(R) Serial IO GPIO Driver v2 Intel Corporation Intel(R) Serial IO Driver 30.100.1820.1 !$*\SystemRoot\System32\drivers\iaLPSS2i_GPIO2_GLK.sys [Drivers] :HKLM iaLPSS2i_I2C=C:\WINDOWS\SYSTEM32\DRIVERS\IALPSS2I_I2C.SYS ### Intel(R) Serial IO I2C Driver v2 Intel Corporation Intel(R) Serial IO Driver 30.100.1816.3 !$*\SystemRoot\System32\drivers\iaLPSS2i_I2C.sys [Drivers] :HKLM iaLPSS2i_I2C_BXT_P=C:\WINDOWS\SYSTEM32\DRIVERS\IALPSS2I_I2C_BXT_P.SYS ### Intel(R) Serial IO I2C Driver v2 Intel Corporation Intel(R) Serial IO Driver 30.100.1816.1 !$*\SystemRoot\System32\drivers\iaLPSS2i_I2C_BXT_P.sys [Drivers] :HKLM iaLPSS2i_I2C_CNL=C:\WINDOWS\SYSTEM32\DRIVERS\IALPSS2I_I2C_CNL.SYS ### Intel(R) Serial IO I2C Driver v2 Intel Corporation Intel(R) Serial IO Driver 30.100.1929.1 !$*\SystemRoot\System32\drivers\iaLPSS2i_I2C_CNL.sys [Drivers] :HKLM iaLPSS2i_I2C_GLK=C:\WINDOWS\SYSTEM32\DRIVERS\IALPSS2I_I2C_GLK.SYS ### Intel(R) Serial IO I2C Driver v2 Intel Corporation Intel(R) Serial IO Driver 30.100.1820.1 !$*\SystemRoot\System32\drivers\iaLPSS2i_I2C_GLK.sys [Drivers] :HKLM iaLPSSi_GPIO=C:\WINDOWS\SYSTEM32\DRIVERS\IALPSSI_GPIO.SYS ### Intel(R) Serial IO GPIO Controller Driver Intel Corporation Intel(R) Serial IO Driver 1.1.250.0 !$*\SystemRoot\System32\drivers\iaLPSSi_GPIO.sys [Drivers] :HKLM iaLPSSi_I2C=C:\WINDOWS\SYSTEM32\DRIVERS\IALPSSI_I2C.SYS ### Intel(R) Serial IO I2C Controller Driver Intel Corporation Intel(R) Serial IO Driver 1.1.253.0 !$*\SystemRoot\System32\drivers\iaLPSSi_I2C.sys [Drivers] :HKLM iaStorAVC=C:\WINDOWS\SYSTEM32\DRIVERS\IASTORAVC.SYS ### Intel(R) Rapid Storage Technology driver (inbox) - x64 Intel Corporation Intel(R) Rapid Storage Technology driver (inbox) 15.44.0.1015 !$*C:\WINDOWS\System32\drivers\iaStorAVC.sys [Drivers] :HKLM iaStorV=C:\WINDOWS\SYSTEM32\DRIVERS\IASTORV.SYS ### Intel Matrix Storage Manager driver - x64 Intel Corporation Intel Matrix Storage Manager driver 8.6.2.1019 ->IASTOR.SYS !$*C:\WINDOWS\System32\drivers\iaStorV.sys [Drivers] :HKLM ibbus=C:\WINDOWS\SYSTEM32\DRIVERS\IBBUS.SYS ### InfiniBand Fabric Bus Driver Mellanox OpenFabrics Windows 10.0.10011.16384 !$*\SystemRoot\System32\drivers\ibbus.sys [Drivers] :HKLM igfx=C:\WINDOWS\SYSTEM32\DRIVERS\IGDKMD64.SYS ### Intel Graphics Kernel Mode Driver Intel Corporation Intel HD Graphics Drivers for Windows(R) 20.19.15.4624 ->IGDKMD32.SYS !$*\SystemRoot\system32\DRIVERS\igdkmd64.sys [Drivers] :HKLM IndirectKmd=C:\WINDOWS\SYSTEM32\DRIVERS\INDIRECTKMD.SYS ### Indirect displays kernel-mode filter driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.867 !$*\SystemRoot\System32\drivers\IndirectKmd.sys [Drivers] :HKLM IntcDAud=C:\WINDOWS\SYSTEM32\DRIVERS\INTCDAUD.SYS ### Intel(R) Display Audio Driver Intel(R) Corporation Intel(R) Display Audio 6.16.00.3197 !$*\SystemRoot\System32\drivers\IntcDAud.sys [Drivers] :HKLM intelide=C:\WINDOWS\SYSTEM32\DRIVERS\INTELIDE.SYS ### Intel PCI IDE Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.906 !$*C:\WINDOWS\System32\drivers\intelide.sys [Drivers] :HKLM intelpep=C:\WINDOWS\SYSTEM32\DRIVERS\INTELPEP.SYS ### Intel Power Engine Plugin Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.662 !$*C:\WINDOWS\System32\drivers\intelpep.sys [Drivers] :HKLM intelpmax=C:\WINDOWS\SYSTEM32\DRIVERS\INTELPMAX.SYS ### Intel Power Limit Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*\SystemRoot\System32\drivers\intelpmax.sys [Drivers] :HKLM intelppm=C:\WINDOWS\SYSTEM32\DRIVERS\INTELPPM.SYS ### Processor Device Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.546 !$*\SystemRoot\System32\drivers\intelppm.sys [Drivers] :HKLM iorate=C:\WINDOWS\SYSTEM32\DRIVERS\IORATE.SYS ### Filtre de contrôle de taux d’E/S Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\drivers\iorate.sys [Drivers] :HKLM IpFilterDriver=C:\WINDOWS\SYSTEM32\DRIVERS\IPFLTDRV.SYS ### IP FILTER DRIVER Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.964 !$*C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys [Drivers] :HKLM IPMIDRV=C:\WINDOWS\SYSTEM32\DRIVERS\IPMIDRV.SYS ### PILOT IPMI WMI Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.1 !$*\SystemRoot\System32\drivers\IPMIDrv.sys [Drivers] :HKLM IPNAT=C:\WINDOWS\SYSTEM32\DRIVERS\IPNAT.SYS ### IP Network Address Translator Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*C:\WINDOWS\System32\drivers\ipnat.sys [Drivers] :HKLM IPT=C:\WINDOWS\SYSTEM32\DRIVERS\IPT.SYS ### IPT Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*\SystemRoot\System32\drivers\ipt.sys [Drivers] :HKLM isapnp=C:\WINDOWS\SYSTEM32\DRIVERS\ISAPNP.SYS ### Pilote de bus PNP ISA Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.1 !$*C:\WINDOWS\System32\drivers\isapnp.sys [Drivers] :HKLM iScsiPrt=C:\WINDOWS\SYSTEM32\DRIVERS\MSISCSI.SYS ### Microsoft iSCSI Initiator Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.789 ->ISCSI VERSION : MIN - 0, MAX - 0 !$*\SystemRoot\System32\drivers\msiscsi.sys [Drivers] :HKLM ItSas35i=C:\WINDOWS\SYSTEM32\DRIVERS\ITSAS35I.SYS ### Avago SAS Gen3.5 Driver (StorPort) Avago Technologies Windows (R) Win 7 DDK driver 10.0.10011.16384 ->ITSAS35I-2.60.94.80 (WINDOWS 10 X64) !$*C:\WINDOWS\System32\drivers\ItSas35i.sys [Drivers] :HKLM kbdclass=C:\WINDOWS\SYSTEM32\DRIVERS\KBDCLASS.SYS ### Pilote de la classe Clavier Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.1 !$*\SystemRoot\System32\drivers\kbdclass.sys [Drivers] :HKLM kbdhid=C:\WINDOWS\SYSTEM32\DRIVERS\KBDHID.SYS ### Pilote de filtre clavier HID Microsoft Corporation Système d'exploitation Microsoft® Windows® 10.0.19041.1 !$*\SystemRoot\System32\drivers\kbdhid.sys [Drivers] :HKLM kdnic=C:\WINDOWS\SYSTEM32\DRIVERS\KDNIC.SYS ### Microsoft Kernel Debugger Network Miniport Microsoft Corporation Microsoft Kernel Debugger Network Adapter (NDIS 6.20 Miniport) 6.01.00.0000 !$*\SystemRoot\System32\drivers\kdnic.sys [Drivers] :HKLM KSecDD=C:\WINDOWS\SYSTEM32\DRIVERS\KSECDD.SYS ### Kernel Security Support Provider Interface Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.906 !$*C:\WINDOWS\System32\Drivers\ksecdd.sys [Drivers] :HKLM KSecPkg=C:\WINDOWS\SYSTEM32\DRIVERS\KSECPKG.SYS ### Kernel Security Support Provider Interface Packages Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1023 !$*C:\WINDOWS\System32\Drivers\ksecpkg.sys [Drivers] :HKLM ksthunk=C:\WINDOWS\SYSTEM32\DRIVERS\KSTHUNK.SYS ### Kernel Streaming WOW Thunk Service Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*\SystemRoot\system32\drivers\ksthunk.sys [Drivers] :HKLM lltdio=C:\WINDOWS\SYSTEM32\DRIVERS\LLTDIO.SYS ### Link-Layer Topology Mapper I/O Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*C:\WINDOWS\system32\drivers\lltdio.sys [Drivers] :HKLM LSI_SAS=C:\WINDOWS\SYSTEM32\DRIVERS\LSI_SAS.SYS ### LSI Fusion-MPT SAS Driver (StorPort) LSI Corporation LSI Fusion-MPT SAS Driver (StorPort) 1.34.03.83 ->LSI_SAS-1.34.03.83 (NT4) !$*C:\WINDOWS\System32\drivers\lsi_sas.sys [Drivers] :HKLM LSI_SAS2i=C:\WINDOWS\SYSTEM32\DRIVERS\LSI_SAS2I.SYS ### LSI SAS Gen2 Driver (StorPort) LSI Corporation Windows (R) Win 7 DDK driver 10.0.10011.16384 ->LSI_SAS2I-2.00.79.82 (NT4) !$*C:\WINDOWS\System32\drivers\lsi_sas2i.sys [Drivers] :HKLM LSI_SAS3i=C:\WINDOWS\SYSTEM32\DRIVERS\LSI_SAS3I.SYS ### Avago SAS Gen3 Driver (StorPort) Avago Technologies Windows (R) Win 7 DDK driver 10.0.10011.16384 ->LSI_SAS3I-2.51.26.80 (NT4) !$*C:\WINDOWS\System32\drivers\lsi_sas3i.sys [Drivers] :HKLM LSI_SSS=C:\WINDOWS\SYSTEM32\DRIVERS\LSI_SSS.SYS ### LSI SSS PCIe/Flash Driver (StorPort) LSI Corporation LSI SSS PCIe/Flash Driver (StorPort) 2.10.61.81 ->LSI_SSS-2.10.61.81 (NT4) !$*C:\WINDOWS\System32\drivers\lsi_sss.sys [Drivers] :HKLM luafv=C:\WINDOWS\SYSTEM32\DRIVERS\LUAFV.SYS ### Pilote de filtre de virtualisation de fichier LUA Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*\SystemRoot\system32\drivers\luafv.sys [Drivers] :HKLM mausbhost=C:\WINDOWS\SYSTEM32\DRIVERS\MAUSBHOST.SYS ### MA-USB Host Controller Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*\SystemRoot\System32\drivers\mausbhost.sys [Drivers] :HKLM mausbip=C:\WINDOWS\SYSTEM32\DRIVERS\MAUSBIP.SYS ### MA-USB IP Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 =>MAUSHIP.SYS !$*\SystemRoot\System32\drivers\mausbip.sys [Drivers] :HKLM MBAMChameleon=C:\WINDOWS\SYSTEM32\DRIVERS\MBAMCHAMELEON.SYS ### Malwarebytes Chameleon Malwarebytes Malwarebytes Chameleon 3.1.0.328 !$*\SystemRoot\System32\Drivers\MbamChameleon.sys [Drivers] :HKLM MbamElam=C:\WINDOWS\SYSTEM32\DRIVERS\MBAMELAM.SYS ### Malwarebytes Early Launch Anti-Malware Driver Malwarebytes Malwarebytes Early Launch Anti-Malware Driver 3.1.0.19 !$*C:\WINDOWS\system32\DRIVERS\MbamElam.sys [Drivers] :HKLM MBAMSwissArmy=C:\WINDOWS\SYSTEM32\DRIVERS\MBAMSWISSARMY.SYS ### Malwarebytes SwissArmy Malwarebytes Malwarebytes SwissArmy 4.3.0.179 !$*\SystemRoot\System32\Drivers\mbamswissarmy.sys [Drivers] :HKLM MbbCx=C:\WINDOWS\SYSTEM32\DRIVERS\MBBCX.SYS ### Windows Mobile Broadband Class Extension Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.423 !$*C:\WINDOWS\system32\drivers\MbbCx.sys [Drivers] :HKLM megasas=C:\WINDOWS\SYSTEM32\DRIVERS\MEGASAS.SYS ### MEGASAS RAID Controller Driver for Windows Avago Technologies MEGASAS RAID Controller Driver for Windows 6.706.06.00 ->MEGASAS2.SYS !$*C:\WINDOWS\System32\drivers\megasas.sys [Drivers] :HKLM megasas2i=C:\WINDOWS\SYSTEM32\DRIVERS\MEGASAS2I.SYS ### MEGASAS RAID Controller Driver for Windows Avago Technologies MEGASAS RAID Controller Driver for Windows 6.714.20.00 ->MEGASAS2.SYS !$*C:\WINDOWS\System32\drivers\MegaSas2i.sys [Drivers] :HKLM megasas35i=C:\WINDOWS\SYSTEM32\DRIVERS\MEGASAS35I.SYS ### MEGASAS RAID Controller Driver for Windows Avago Technologies MEGASAS RAID Controller Driver for Windows 7.710.10.00 ->MEGASAS35.SYS !$*C:\WINDOWS\System32\drivers\megasas35i.sys [Drivers] :HKLM megasr=C:\WINDOWS\SYSTEM32\DRIVERS\MEGASR.SYS ### LSI MegaRAID Software RAID Driver LSI Corporation, Inc. MegaRAID Software RAID 15.02.2013.0129 !$*C:\WINDOWS\System32\drivers\megasr.sys [Drivers] :HKLM MEIx64=C:\WINDOWS\SYSTEM32\DRIVERS\TEEDRIVERW8X64.SYS ### Intel(R) Management Engine Interface Intel Corporation Intel(R) Management Engine Interface 11.7.0.1045 ->TEEDRIVERX64.SYS !$*\SystemRoot\System32\drivers\TeeDriverW8x64.sys [Drivers] :HKLM Microsoft_Bluetooth_AvrcpTransport=C:\WINDOWS\SYSTEM32\DRIVERS\MICROSOFT.BLUETOOTH.AVRCPTRANSPORT.SYS ### Pilote de transport Microsoft Bluetooth Avrcp Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.1 !$*\SystemRoot\System32\drivers\Microsoft.Bluetooth.AvrcpTransport.sys [Drivers] :HKLM mlx4_bus=C:\WINDOWS\SYSTEM32\DRIVERS\MLX4_BUS.SYS ### MLX4 Bus Driver Mellanox OpenFabrics Windows 10.0.10011.16384 !$*\SystemRoot\System32\drivers\mlx4_bus.sys [Drivers] :HKLM MMCSS=C:\WINDOWS\SYSTEM32\DRIVERS\MMCSS.SYS ### MMCSS Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.546 !$*\SystemRoot\system32\drivers\mmcss.sys [Drivers] :HKLM Modem=C:\WINDOWS\SYSTEM32\DRIVERS\MODEM.SYS ### Pilote de périphérique modem Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\drivers\modem.sys [Drivers] :HKLM monitor=C:\WINDOWS\SYSTEM32\DRIVERS\MONITOR.SYS ### Monitor Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.488 !$*\SystemRoot\System32\drivers\monitor.sys [Drivers] :HKLM mouclass=C:\WINDOWS\SYSTEM32\DRIVERS\MOUCLASS.SYS ### Pilote de la classe Souris Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.1 !$*\SystemRoot\System32\drivers\mouclass.sys [Drivers] :HKLM mouhid=C:\WINDOWS\SYSTEM32\DRIVERS\MOUHID.SYS ### Pilote de filtre souris HID Microsoft Corporation Système d'exploitation Microsoft® Windows® 10.0.19041.1 !$*\SystemRoot\System32\drivers\mouhid.sys [Drivers] :HKLM mountmgr=C:\WINDOWS\SYSTEM32\DRIVERS\MOUNTMGR.SYS ### Gestionnaire des points de montage Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\System32\drivers\mountmgr.sys [Drivers] :HKLM MpKsla284fd35=C:\PROGRAMDATA\MICROSOFT\WINDOWS DEFENDER\DEFINITION UPDATES\{A48230EF-0041-4AF8-A738-63B8ABCA3B04}\MPKSLDRV.SYS ### KSLD Microsoft Corporation Microsoft Malware Protection 1.1.18200.1 ->KSLD =>KSLD.SYS !$*\??\C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{A48230EF-0041-4AF8-A738-63B8ABCA3B04}\MpKslDrv.sys [Drivers] :HKLM mpsdrv=C:\WINDOWS\SYSTEM32\DRIVERS\MPSDRV.SYS ### Microsoft Protection Service Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*C:\WINDOWS\System32\drivers\mpsdrv.sys [Drivers] :HKLM mracdrv=C:\WINDOWS\SYSTEM32\DRIVERS\MRACDRV1.SYS ### Mail.Ru AntiCheat Driver LLC Mail.Ru Mail.Ru AntiCheat 3.25.0 ->MRACDRV.SYS !$*\SystemRoot\System32\drivers\mracdrv1.sys [Drivers] :HKLM MRxDAV=C:\WINDOWS\SYSTEM32\DRIVERS\MRXDAV.SYS ### Windows NT WebDav Minirdr Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*\SystemRoot\system32\drivers\mrxdav.sys [Drivers] :HKLM mrxsmb=C:\WINDOWS\SYSTEM32\DRIVERS\MRXSMB.SYS ### Minirdr SMB Windows NT Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\DRIVERS\mrxsmb.sys [Drivers] :HKLM mrxsmb10=C:\WINDOWS\SYSTEM32\DRIVERS\MRXSMB10.SYS ### Longhorn SMB Downlevel SubRdr Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.488 ->MRXSMB0.SYS !$*C:\WINDOWS\system32\DRIVERS\mrxsmb10.sys [Drivers] :HKLM mrxsmb20=C:\WINDOWS\SYSTEM32\DRIVERS\MRXSMB20.SYS ### Longhorn SMB 2.0 Redirector Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.906 !$*C:\WINDOWS\system32\DRIVERS\mrxsmb20.sys [Drivers] :HKLM MsBridge=C:\WINDOWS\SYSTEM32\DRIVERS\BRIDGE.SYS ### MAC Bridge Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*C:\WINDOWS\System32\drivers\bridge.sys [Drivers] :HKLM msgpiowin32=C:\WINDOWS\SYSTEM32\DRIVERS\MSGPIOWIN32.SYS ### GPIO Button Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*\SystemRoot\System32\drivers\msgpiowin32.sys [Drivers] :HKLM mshidkmdf=C:\WINDOWS\SYSTEM32\DRIVERS\MSHIDKMDF.SYS ### Pass-through HID to KMDF Filter Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*\SystemRoot\System32\drivers\mshidkmdf.sys [Drivers] :HKLM mshidumdf=C:\WINDOWS\SYSTEM32\DRIVERS\MSHIDUMDF.SYS ### Pilote direct pour interface HID-UMDF Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*\SystemRoot\System32\drivers\mshidumdf.sys [Drivers] :HKLM msisadrv=C:\WINDOWS\SYSTEM32\DRIVERS\MSISADRV.SYS ### ISA Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*C:\WINDOWS\System32\drivers\msisadrv.sys [Drivers] :HKLM MSKSSRV=C:\WINDOWS\SYSTEM32\DRIVERS\MSKSSRV.SYS ### MS KS Server Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.630 !$*\SystemRoot\System32\drivers\MSKSSRV.sys [Drivers] :HKLM MsLldp=C:\WINDOWS\SYSTEM32\DRIVERS\MSLLDP.SYS ### Pilote de protocole LLDP (Link Layer Discovery Protocol) Microsoft Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\drivers\mslldp.sys [Drivers] :HKLM MSPCLOCK=C:\WINDOWS\SYSTEM32\DRIVERS\MSPCLOCK.SYS ### MS Proxy Clock Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*\SystemRoot\System32\drivers\MSPCLOCK.sys [Drivers] :HKLM MSPQM=C:\WINDOWS\SYSTEM32\DRIVERS\MSPQM.SYS ### MS Proxy Quality Manager Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*\SystemRoot\System32\drivers\MSPQM.sys [Drivers] :HKLM MsQuic=C:\WINDOWS\SYSTEM32\DRIVERS\MSQUIC.SYS ### Windows QUIC Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.488 !$*C:\WINDOWS\system32\drivers\msquic.sys [Drivers] :HKLM mssmbios=C:\WINDOWS\SYSTEM32\DRIVERS\MSSMBIOS.SYS ### System Management BIOS Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 ->SMBIOS.SYS =>SMBIOS.SYS.MUI !$*\SystemRoot\System32\drivers\mssmbios.sys [Drivers] :HKLM MSTEE=C:\WINDOWS\SYSTEM32\DRIVERS\MSTEE.SYS ### WDM Tee/Communication Transform Filter Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*\SystemRoot\System32\drivers\MSTEE.sys [Drivers] :HKLM MTConfig=C:\WINDOWS\SYSTEM32\DRIVERS\MTCONFIG.SYS ### Pilote HID multipoint Microsoft Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.1 !$*\SystemRoot\System32\drivers\MTConfig.sys [Drivers] :HKLM Mup=C:\WINDOWS\SYSTEM32\DRIVERS\MUP.SYS ### Pilote de fournisseur UNC multiples Microsoft Corporation Système d'exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\System32\Drivers\mup.sys [Drivers] :HKLM mvumis=C:\WINDOWS\SYSTEM32\DRIVERS\MVUMIS.SYS ### Marvell Flash Controller Driver Marvell Semiconductor, Inc. Marvell Flash Controller 1.0.5.1016 ->SPEEDYST.SYS !$*C:\WINDOWS\System32\drivers\mvumis.sys [Drivers] :HKLM NativeWifiP=C:\WINDOWS\SYSTEM32\DRIVERS\NWIFI.SYS ### Pilote de miniport WiFi natif Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\DRIVERS\nwifi.sys [Drivers] :HKLM ndfltr=C:\WINDOWS\SYSTEM32\DRIVERS\NDFLTR.SYS ### NetworkDirect Support Filter Driver Mellanox OpenFabrics Windows 10.0.10011.16384 !$*\SystemRoot\System32\drivers\ndfltr.sys [Drivers] :HKLM NDIS=C:\WINDOWS\SYSTEM32\DRIVERS\NDIS.SYS ### NDIS (Network Driver Interface Specification) Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\drivers\ndis.sys [Drivers] :HKLM NdisCap=C:\WINDOWS\SYSTEM32\DRIVERS\NDISCAP.SYS ### Microsoft NDIS Packet Capture Filter Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.867 !$*C:\WINDOWS\System32\drivers\ndiscap.sys [Drivers] :HKLM NdisImPlatform=C:\WINDOWS\SYSTEM32\DRIVERS\NDISIMPLATFORM.SYS ### Microsoft Network Adapter Multiplexor Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.867 !$*C:\WINDOWS\System32\drivers\NdisImPlatform.sys [Drivers] :HKLM NdisTapi=C:\WINDOWS\SYSTEM32\DRIVERS\NDISTAPI.SYS ### NDIS 3.0 connection wrapper driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.546 !$*C:\WINDOWS\System32\DRIVERS\ndistapi.sys [Drivers] :HKLM Ndisuio=C:\WINDOWS\SYSTEM32\DRIVERS\NDISUIO.SYS ### Pilote d’E/S du mode utilisateur NDIS Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\drivers\ndisuio.sys [Drivers] :HKLM NdisVirtualBus=C:\WINDOWS\SYSTEM32\DRIVERS\NDISVIRTUALBUS.SYS ### Énumérateur de cartes réseau virtuelles Microsoft Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*\SystemRoot\System32\drivers\NdisVirtualBus.sys [Drivers] :HKLM NdisWan=C:\WINDOWS\SYSTEM32\DRIVERS\NDISWAN.SYS ### MS PPP Framing Driver (Strong Encryption) Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.488 !$*\SystemRoot\System32\drivers\ndiswan.sys [Drivers] :HKLM ndiswanlegacy=C:\WINDOWS\SYSTEM32\DRIVERS\NDISWAN.SYS ### MS PPP Framing Driver (Strong Encryption) Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.488 !$*C:\WINDOWS\System32\DRIVERS\ndiswan.sys [Drivers] :HKLM NDKPing=C:\WINDOWS\SYSTEM32\DRIVERS\NDKPING.SYS ### RDMA Sample Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 ->RDMASAMPLE.SYS !$*C:\WINDOWS\system32\drivers\NDKPing.sys [Drivers] :HKLM ndproxy=C:\WINDOWS\SYSTEM32\DRIVERS\NDPROXY.SYS ### NDIS Proxy Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.546 !$*C:\WINDOWS\System32\DRIVERS\NDProxy.sys [Drivers] :HKLM Ndu=C:\WINDOWS\SYSTEM32\DRIVERS\NDU.SYS ### Windows Network Data Usage Monitoring Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*C:\WINDOWS\system32\drivers\Ndu.sys [Drivers] :HKLM NetAdapterCx=C:\WINDOWS\SYSTEM32\DRIVERS\NETADAPTERCX.SYS ### Network Adapter Class Extension for WDF Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.789 !$*C:\WINDOWS\system32\drivers\NetAdapterCx.sys [Drivers] :HKLM NetBIOS=C:\WINDOWS\SYSTEM32\DRIVERS\NETBIOS.SYS ### NetBIOS interface driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*C:\WINDOWS\system32\drivers\netbios.sys [Drivers] :HKLM NetBT=C:\WINDOWS\SYSTEM32\DRIVERS\NETBT.SYS ### MBT Transport driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.572 !$*C:\WINDOWS\System32\DRIVERS\netbt.sys [Drivers] :HKLM netvsc=C:\WINDOWS\SYSTEM32\DRIVERS\NETVSC.SYS ### Miniport NDIS virtuel Microsoft Corporation Système d'exploitation Microsoft® Windows® 10.0.19041.1 !$*\SystemRoot\System32\drivers\netvsc.sys [Drivers] :HKLM npsvctrig=C:\WINDOWS\SYSTEM32\DRIVERS\NPSVCTRIG.SYS ### Named pipe service triggers Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*\SystemRoot\System32\drivers\npsvctrig.sys [Drivers] :HKLM nsiproxy=C:\WINDOWS\SYSTEM32\DRIVERS\NSIPROXY.SYS ### NSI Proxy Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.546 !$*C:\WINDOWS\system32\drivers\nsiproxy.sys [Drivers] :HKLM nvdimm=C:\WINDOWS\SYSTEM32\DRIVERS\NVDIMM.SYS ### Pilote de périphérique NVDIMM Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.1 !$*C:\WINDOWS\System32\drivers\nvdimm.sys [Drivers] :HKLM NVHDA=C:\WINDOWS\SYSTEM32\DRIVERS\NVHDA64V.SYS ### NVIDIA HDMI Audio Driver NVIDIA Corporation NVIDIA HDMI Audio Driver 1.3.38.60 ->NVHDA.SYS !$*\SystemRoot\system32\drivers\nvhda64v.sys [Drivers] :HKLM nvlddmkm=C:\WINDOWS\SYSTEM32\DRIVERSTORE\FILEREPOSITORY\NVMDI.INF_AMD64_6A0632B60438E56D\NVLDDMKM.SYS ### NVIDIA Windows Kernel Mode Driver, Version 466.77 NVIDIA Corporation NVIDIA Windows Kernel Mode Driver, Version 466.77 27.21.14.6677 ->NVLDDMKM.SYS, NV_LDDM:10011, NV_LDDM_DDK_BUILD:UNUSED !$*\SystemRoot\System32\DriverStore\FileRepository\nvmdi.inf_amd64_6a0632b60438e56d\nvlddmkm.sys [Drivers] :HKLM NvModuleTracker=C:\WINDOWS\SYSTEM32\DRIVERS\NVMODULETRACKER.SYS ### Process and module monitoring driver NVIDIA Corporation Process and module monitoring driver 1.00.0.2 !$*\SystemRoot\System32\drivers\NvModuleTracker.sys [Drivers] :HKLM nvraid=C:\WINDOWS\SYSTEM32\DRIVERS\NVRAID.SYS ### NVIDIA® nForce(TM) RAID Driver NVIDIA Corporation NVIDIA nForce(TM) RAID Driver 10.6.0.23 ->NVIDIA NFORCE(TM) RAID DRIVER !$*C:\WINDOWS\System32\drivers\nvraid.sys [Drivers] :HKLM nvstor=C:\WINDOWS\SYSTEM32\DRIVERS\NVSTOR.SYS ### NVIDIA® nForce(TM) Sata Performance Driver NVIDIA Corporation NVIDIA nForce(TM) SATA Driver 10.6.0.23 ->NVIDIA NFORCE(TM) SATA DRIVER !$*C:\WINDOWS\System32\drivers\nvstor.sys [Drivers] :HKLM nvvad_WaveExtensible=C:\WINDOWS\SYSTEM32\DRIVERS\NVVAD64V.SYS ### NVIDIA Virtual Audio Driver NVIDIA Corporation NVIDIA Virtual Audio Driver 4.13.0.0 ->NVVAD.SYS !$*\SystemRoot\system32\drivers\nvvad64v.sys [Drivers] :HKLM nvvhci=C:\WINDOWS\SYSTEM32\DRIVERS\NVVHCI.SYS ### Virtual USB Host Controller driver NVIDIA Corporation Virtual USB Host Controller driver 3.04.0.1 !$*\SystemRoot\System32\drivers\nvvhci.sys [Drivers] :HKLM oculusvad_oculusvad=C:\WINDOWS\SYSTEM32\DRIVERS\OCULUSVAD.SYS ### Oculus Virtual Audio Driver Windows (R) Win 7 DDK provider Windows (R) Win 7 DDK driver 10.0.10011.16384 !$*\SystemRoot\System32\drivers\oculusvad.sys [Drivers] :HKLM Oculus_ViGEmBus=C:\WINDOWS\SYSTEM32\DRIVERS\OCULUS_VIGEMBUS.SYS ### Oculus Virtual Gamepad Emulation Bus Driver Facebook Inc. Oculus Virtual Gamepad Emulation Bus Driver 1.5.8.0 ->OCULUS VIRTUAL GAMEPAD EMULATION BUS DRIVER !$*\SystemRoot\System32\drivers\Oculus_ViGEmBus.sys [Drivers] :HKLM Parport=C:\WINDOWS\SYSTEM32\DRIVERS\PARPORT.SYS ### Pilote de port parallèle Microsoft Corporation Système d'exploitation Microsoft® Windows® 10.0.19041.1 !$*\SystemRoot\System32\drivers\parport.sys [Drivers] :HKLM partmgr=C:\WINDOWS\SYSTEM32\DRIVERS\PARTMGR.SYS ### Partition driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.867 !$*C:\WINDOWS\System32\drivers\partmgr.sys [Drivers] :HKLM pci=C:\WINDOWS\SYSTEM32\DRIVERS\PCI.SYS ### Énumérateur Plug-and-Play PCI pour NT Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.1 !$*C:\WINDOWS\System32\drivers\pci.sys [Drivers] :HKLM pciide=C:\WINDOWS\SYSTEM32\DRIVERS\PCIIDE.SYS ### Generic PCI IDE Bus Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.906 !$*C:\WINDOWS\System32\drivers\pciide.sys [Drivers] :HKLM pcmcia=C:\WINDOWS\SYSTEM32\DRIVERS\PCMCIA.SYS ### Pilote de bus PCMCIA Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.1 !$*C:\WINDOWS\System32\drivers\pcmcia.sys [Drivers] :HKLM pcw=C:\WINDOWS\SYSTEM32\DRIVERS\PCW.SYS ### Performance Counters for Windows Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*C:\WINDOWS\System32\drivers\pcw.sys [Drivers] :HKLM pdc=C:\WINDOWS\SYSTEM32\DRIVERS\PDC.SYS ### Power Dependency Coordinator Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.867 !$*C:\WINDOWS\system32\drivers\pdc.sys [Drivers] :HKLM PEAUTH=C:\WINDOWS\SYSTEM32\DRIVERS\PEAUTH.SYS ### Protected Environment Authentication and Authorization Export Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1023 !$*C:\WINDOWS\system32\drivers\peauth.sys [Drivers] :HKLM percsas2i=C:\WINDOWS\SYSTEM32\DRIVERS\PERCSAS2I.SYS ### MEGASAS RAID Controller Driver for Windows Avago Technologies MEGASAS RAID Controller Driver for Windows 6.805.03.00 !$*C:\WINDOWS\System32\drivers\percsas2i.sys [Drivers] :HKLM percsas3i=C:\WINDOWS\SYSTEM32\DRIVERS\PERCSAS3I.SYS ### MEGASAS RAID Controller Driver for Windows Avago Technologies MEGASAS RAID Controller Driver for Windows 6.604.06.00 ->PERCSAS3.SYS !$*C:\WINDOWS\System32\drivers\percsas3i.sys [Drivers] :HKLM PktMon=C:\WINDOWS\SYSTEM32\DRIVERS\PKTMON.SYS ### Pilote du moniteur de paquets Microsoft Corporation Système d'exploitation Microsoft® Windows® 10.0.19041.906 !$*C:\WINDOWS\system32\drivers\PktMon.sys [Drivers] :HKLM pmem=C:\WINDOWS\SYSTEM32\DRIVERS\PMEM.SYS ### Pilote de mémoire persistante Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.1 !$*C:\WINDOWS\System32\drivers\pmem.sys [Drivers] :HKLM PNPMEM=C:\WINDOWS\SYSTEM32\DRIVERS\PNPMEM.SYS ### Pilote mémoire Plug and Play Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.1 !$*\SystemRoot\System32\drivers\pnpmem.sys [Drivers] :HKLM portcfg=C:\WINDOWS\SYSTEM32\DRIVERS\PORTCFG.SYS ### Port Device Class Configuration Filter Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*\SystemRoot\System32\drivers\portcfg.sys [Drivers] :HKLM PptpMiniport=C:\WINDOWS\SYSTEM32\DRIVERS\RASPPTP.SYS ### Peer-to-Peer Tunneling Protocol Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.488 !$*\SystemRoot\System32\drivers\raspptp.sys [Drivers] :HKLM Processor=C:\WINDOWS\SYSTEM32\DRIVERS\PROCESSR.SYS ### Processor Device Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*\SystemRoot\System32\drivers\processr.sys [Drivers] :HKLM Psched=C:\WINDOWS\SYSTEM32\DRIVERS\PACER.SYS ### Planificateur de paquets QoS Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\System32\drivers\pacer.sys [Drivers] :HKLM QWAVEdrv=C:\WINDOWS\SYSTEM32\DRIVERS\QWAVEDRV.SYS ### Pilote du support de Microsoft Quality Windows Audio Video Experience (qWave) Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*\SystemRoot\system32\drivers\qwavedrv.sys [Drivers] :HKLM Ramdisk=C:\WINDOWS\SYSTEM32\DRIVERS\RAMDISK.SYS ### RAM Disk Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*C:\WINDOWS\system32\DRIVERS\ramdisk.sys [Drivers] :HKLM RasAcd=C:\WINDOWS\SYSTEM32\DRIVERS\RASACD.SYS ### RAS Automatic Connection Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.546 !$*C:\WINDOWS\System32\DRIVERS\rasacd.sys [Drivers] :HKLM RasAgileVpn=C:\WINDOWS\SYSTEM32\DRIVERS\AGILEVPN.SYS ### Gestionnaire d'appels RAS Agile Vpn Miniport Microsoft Corporation Système d'exploitation Microsoft® Windows® 10.0.19041.867 !$*\SystemRoot\System32\drivers\AgileVpn.sys [Drivers] :HKLM Rasl2tp=C:\WINDOWS\SYSTEM32\DRIVERS\RASL2TP.SYS ### RAS L2TP mini-port/call-manager driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.488 !$*\SystemRoot\System32\drivers\rasl2tp.sys [Drivers] :HKLM RasPppoe=C:\WINDOWS\SYSTEM32\DRIVERS\RASPPPOE.SYS ### RAS PPPoE mini-port/call-manager driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*C:\WINDOWS\System32\DRIVERS\raspppoe.sys [Drivers] :HKLM RasSstp=C:\WINDOWS\SYSTEM32\DRIVERS\RASSSTP.SYS ### RAS SSTP Miniport Call Manager Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.488 !$*\SystemRoot\System32\drivers\rassstp.sys [Drivers] :HKLM rdbss=C:\WINDOWS\SYSTEM32\DRIVERS\RDBSS.SYS ### Pilote du sous-système de mise en mémoire tampon de lecteur redirigé Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\DRIVERS\rdbss.sys [Drivers] :HKLM rdpbus=C:\WINDOWS\SYSTEM32\DRIVERS\RDPBUS.SYS ### Microsoft RDP Bus Device driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*\SystemRoot\System32\drivers\rdpbus.sys [Drivers] :HKLM RDPDR=C:\WINDOWS\SYSTEM32\DRIVERS\RDPDR.SYS ### Redirecteur de périphérique de Microsoft RDP Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\System32\drivers\rdpdr.sys [Drivers] :HKLM RdpVideoMiniport=C:\WINDOWS\SYSTEM32\DRIVERS\RDPVIDEOMINIPORT.SYS ### Microsoft RDP Video Miniport driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.928 !$*C:\WINDOWS\System32\drivers\rdpvideominiport.sys [Drivers] :HKLM rdyboost=C:\WINDOWS\SYSTEM32\DRIVERS\RDYBOOST.SYS ### ReadyBoost Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*C:\WINDOWS\System32\drivers\rdyboost.sys [Drivers] :HKLM RFCOMM=C:\WINDOWS\SYSTEM32\DRIVERS\RFCOMM.SYS ### Bluetooth RFCOMM Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*\SystemRoot\System32\drivers\rfcomm.sys [Drivers] :HKLM rhproxy=C:\WINDOWS\SYSTEM32\DRIVERS\RHPROXY.SYS ### ResourceHub Proxy Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*\SystemRoot\System32\drivers\rhproxy.sys [Drivers] :HKLM rspndr=C:\WINDOWS\SYSTEM32\DRIVERS\RSPNDR.SYS ### Link-Layer Topology Responder Driver for NDIS 6 Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*C:\WINDOWS\system32\drivers\rspndr.sys [Drivers] :HKLM RTCore64=D:\PROGRAM FILES (X86)\MSI AFTERBURNER\RTCORE64.SYS ### !$*\??\D:\Program Files (x86)\MSI Afterburner\RTCore64.sys [Drivers] :HKLM s3cap=C:\WINDOWS\SYSTEM32\DRIVERS\VMS3CAP.SYS ### Microsoft S3 Emulated Device Cap Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*\SystemRoot\System32\drivers\vms3cap.sys [Drivers] :HKLM SamSs=C:\WINDOWS\SYSTEM32\DRIVERS\VMS3CAP.SYS ### Microsoft S3 Emulated Device Cap Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*\SystemRoot\System32\drivers\vms3cap.sys [Drivers] :HKLM sbp2port=C:\WINDOWS\SYSTEM32\DRIVERS\SBP2PORT.SYS ### SBP-2 Protocol Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1023 !$*C:\WINDOWS\System32\drivers\sbp2port.sys [Drivers] :HKLM scfilter=C:\WINDOWS\SYSTEM32\DRIVERS\SCFILTER.SYS ### Pilote de filtre de lecteur de carte à puce Microsoft Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\System32\DRIVERS\scfilter.sys [Drivers] :HKLM scmbus=C:\WINDOWS\SYSTEM32\DRIVERS\SCMBUS.SYS ### Pilote de bus de mémoire de classe stockage Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.1 !$*C:\WINDOWS\System32\drivers\scmbus.sys [Drivers] :HKLM sdbus=C:\WINDOWS\SYSTEM32\DRIVERS\SDBUS.SYS ### Pilote du bus numérique sécurisé (SD) Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.1 !$*\SystemRoot\System32\drivers\sdbus.sys [Drivers] :HKLM SDFRd=C:\WINDOWS\SYSTEM32\DRIVERS\SDFRD.SYS ### SDF Reflector Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*\SystemRoot\System32\drivers\SDFRd.sys [Drivers] :HKLM sdstor=C:\WINDOWS\SYSTEM32\DRIVERS\SDSTOR.SYS ### Pilote de classe de stockage SD Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.1 !$*\SystemRoot\System32\drivers\sdstor.sys [Drivers] :HKLM SerCx=C:\WINDOWS\SYSTEM32\DRIVERS\SERCX.SYS ### Serial Class Extension Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*C:\WINDOWS\system32\drivers\SerCx.sys [Drivers] :HKLM SerCx2=C:\WINDOWS\SYSTEM32\DRIVERS\SERCX2.SYS ### Serial Class Extension V2 Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*C:\WINDOWS\system32\drivers\SerCx2.sys [Drivers] :HKLM Serenum=C:\WINDOWS\SYSTEM32\DRIVERS\SERENUM.SYS ### Serial Port Enumerator Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*\SystemRoot\System32\drivers\serenum.sys [Drivers] :HKLM Serial=C:\WINDOWS\SYSTEM32\DRIVERS\SERIAL.SYS ### Pilote de périphérique série Microsoft Corporation Système d'exploitation Microsoft® Windows® 10.0.19041.1 !$*\SystemRoot\System32\drivers\serial.sys [Drivers] :HKLM sermouse=C:\WINDOWS\SYSTEM32\DRIVERS\SERMOUSE.SYS ### Pilote de filtre souris série Microsoft Corporation Système d'exploitation Microsoft® Windows® 10.0.19041.1 !$*\SystemRoot\System32\drivers\sermouse.sys [Drivers] :HKLM sfloppy=C:\WINDOWS\SYSTEM32\DRIVERS\SFLOPPY.SYS ### SCSI Floppy Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*\SystemRoot\System32\drivers\sfloppy.sys [Drivers] :HKLM SgrmAgent=C:\WINDOWS\SYSTEM32\DRIVERS\SGRMAGENT.SYS ### System Guard Runtime Monitor Agent Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*C:\WINDOWS\system32\drivers\SgrmAgent.sys [Drivers] :HKLM SiSRaid2=C:\WINDOWS\SYSTEM32\DRIVERS\SISRAID2.SYS ### SiS RAID Stor Miniport Driver Silicon Integrated Systems Corp. Microsoft® Windows® Operating System 2.60.01 ->SISRAID2.SYS 2.60.01 !$*C:\WINDOWS\System32\drivers\SiSRaid2.sys [Drivers] :HKLM SiSRaid4=C:\WINDOWS\SYSTEM32\DRIVERS\SISRAID4.SYS ### SiS AHCI Stor-Miniport Driver Silicon Integrated Systems Microsoft® Windows® Operating System 6.1.6918.0 !$*C:\WINDOWS\System32\drivers\sisraid4.sys [Drivers] :HKLM SmartSAMD=C:\WINDOWS\SYSTEM32\DRIVERS\SMARTSAMD.SYS ### Storport Miniport Driver for SmartRAID/SmartHBA Controllers Microsemi Corportation SmartRAID, SmartHBA PQI Storport Driver 1.50.1.0 !$*C:\WINDOWS\System32\drivers\SmartSAMD.sys [Drivers] :HKLM spaceparser=C:\WINDOWS\SYSTEM32\DRIVERS\SPACEPARSER.SYS ### Storage Spaces Parser Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*C:\WINDOWS\system32\drivers\spaceparser.sys [Drivers] :HKLM spaceport=C:\WINDOWS\SYSTEM32\DRIVERS\SPACEPORT.SYS ### Storage Spaces Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*C:\WINDOWS\System32\drivers\spaceport.sys [Drivers] :HKLM SpatialGraphFilter=C:\WINDOWS\SYSTEM32\DRIVERS\SPATIALGRAPHFILTER.SYS ### Holographic Spatial Graph Filter Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*C:\WINDOWS\System32\drivers\SpatialGraphFilter.sys [Drivers] :HKLM SpbCx=C:\WINDOWS\SYSTEM32\DRIVERS\SPBCX.SYS ### SPB Class Extension Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*C:\WINDOWS\system32\drivers\SpbCx.sys [Drivers] :HKLM srv2=C:\WINDOWS\SYSTEM32\DRIVERS\SRV2.SYS ### Pilote de serveur SMB 2.0 Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\System32\DRIVERS\srv2.sys [Drivers] :HKLM srvnet=C:\WINDOWS\SYSTEM32\DRIVERS\SRVNET.SYS ### Server Network driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1052 !$*C:\WINDOWS\System32\DRIVERS\srvnet.sys [Drivers] :HKLM ssdevfactory=C:\WINDOWS\SYSTEM32\DRIVERS\SSDEVFACTORY.SYS ### SteelSeries Device Factory Driver SteelSeries ApS !$*\SystemRoot\System32\drivers\ssdevfactory.sys [Drivers] :HKLM stexstor=C:\WINDOWS\SYSTEM32\DRIVERS\STEXSTOR.SYS ### Promise SuperTrak EX Series Driver for Windows x64 Promise Technology, Inc. Promise® SuperTrak EX Series 5.1.0000.10 !$*C:\WINDOWS\System32\drivers\stexstor.sys [Drivers] :HKLM storahci=C:\WINDOWS\SYSTEM32\DRIVERS\STORAHCI.SYS ### MS AHCI Storport Miniport Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.906 !$*C:\WINDOWS\System32\drivers\storahci.sys [Drivers] :HKLM storflt=C:\WINDOWS\SYSTEM32\DRIVERS\VMSTORFL.SYS ### Pilote de filtre de stockage virtuel Microsoft Corporation Système d'exploitation Microsoft® Windows® 10.0.19041.1 !$*C:\WINDOWS\System32\drivers\vmstorfl.sys [Drivers] :HKLM stornvme=C:\WINDOWS\SYSTEM32\DRIVERS\STORNVME.SYS ### Microsoft NVM Express Storport Miniport Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.844 !$*C:\WINDOWS\System32\drivers\stornvme.sys [Drivers] :HKLM storqosflt=C:\WINDOWS\SYSTEM32\DRIVERS\STORQOSFLT.SYS ### Filtre de qualité de service de stockage Microsoft Corporation Système d'exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\drivers\storqosflt.sys [Drivers] :HKLM storufs=C:\WINDOWS\SYSTEM32\DRIVERS\STORUFS.SYS ### MS UFS Storport Miniport Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1023 !$*C:\WINDOWS\System32\drivers\storufs.sys [Drivers] :HKLM storvsc=C:\WINDOWS\SYSTEM32\DRIVERS\STORVSC.SYS ### Storage VSC Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*C:\WINDOWS\System32\drivers\storvsc.sys [Drivers] :HKLM swenum=C:\WINDOWS\SYSTEM32\DRIVERSTORE\FILEREPOSITORY\SWENUM.INF_AMD64_16A14542B63C02AF\SWENUM.SYS ### Plug and Play Software Device Enumerator Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*\SystemRoot\System32\DriverStore\FileRepository\swenum.inf_amd64_16a14542b63c02af\swenum.sys [Drivers] :HKLM Synth3dVsc=C:\WINDOWS\SYSTEM32\DRIVERS\SYNTH3DVSC.SYS ### Microsoft RemoteFX Synth3D Video VSC Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.928 !$*\SystemRoot\System32\drivers\Synth3dVsc.sys [Drivers] :HKLM tap0901=C:\WINDOWS\SYSTEM32\DRIVERS\TAP0901.SYS ### TAP-Windows Virtual Network Driver (NDIS 6.0) The OpenVPN Project TAP-Windows Virtual Network Driver (NDIS 6.0) 9.21.2 9/21 !$*\SystemRoot\System32\drivers\tap0901.sys [Drivers] :HKLM Tcpip=C:\WINDOWS\SYSTEM32\DRIVERS\TCPIP.SYS ### Pilote TCP/IP Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.1052 !$*C:\WINDOWS\System32\drivers\tcpip.sys [Drivers] :HKLM Tcpip6=C:\WINDOWS\SYSTEM32\DRIVERS\TCPIP.SYS ### Pilote TCP/IP Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.1052 !$*C:\WINDOWS\System32\drivers\tcpip.sys [Drivers] :HKLM tcpipreg=C:\WINDOWS\SYSTEM32\DRIVERS\TCPIPREG.SYS ### TCP/IP Registry Compatibility Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*C:\WINDOWS\System32\drivers\tcpipreg.sys [Drivers] :HKLM tdx=C:\WINDOWS\SYSTEM32\DRIVERS\TDX.SYS ### TDI Translation Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*\SystemRoot\system32\DRIVERS\tdx.sys [Drivers] :HKLM Telemetry=C:\WINDOWS\SYSTEM32\DRIVERS\INTELTA.SYS ### Intel Telemetry Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.546 !$*C:\WINDOWS\System32\drivers\IntelTA.sys [Drivers] :HKLM terminpt=C:\WINDOWS\SYSTEM32\DRIVERS\TERMINPT.SYS ### Terminal Server Input Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*\SystemRoot\System32\drivers\terminpt.sys [Drivers] :HKLM TPM=C:\WINDOWS\SYSTEM32\DRIVERS\TPM.SYS ### Pilote de périphérique TPM Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.1 !$*\SystemRoot\System32\drivers\tpm.sys [Drivers] :HKLM TrkWks=C:\WINDOWS\SYSTEM32\DRIVERS\TPM.SYS ### Pilote de périphérique TPM Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.1 !$*\SystemRoot\System32\drivers\tpm.sys [Drivers] :HKLM TsUsbFlt=C:\WINDOWS\SYSTEM32\DRIVERS\TSUSBFLT.SYS ### Pilote de filtre pour concentrateur USB du Bureau à distance Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\drivers\tsusbflt.sys [Drivers] :HKLM TsUsbGD=C:\WINDOWS\SYSTEM32\DRIVERS\TSUSBGD.SYS ### Remote Desktop Generic USB Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*\SystemRoot\System32\drivers\TsUsbGD.sys [Drivers] :HKLM tunnel=C:\WINDOWS\SYSTEM32\DRIVERS\TUNNEL.SYS ### Pilote d’interface de tunnel Microsoft Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\System32\drivers\tunnel.sys [Drivers] :HKLM UASPStor=C:\WINDOWS\SYSTEM32\DRIVERS\UASPSTOR.SYS ### Microsoft Uasp Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1023 ->UASP VERSION : MIN - 0, MAX - 0 =>UASP.SYS !$*\SystemRoot\System32\drivers\uaspstor.sys [Drivers] :HKLM UcmCx0101=C:\WINDOWS\SYSTEM32\DRIVERS\UCMCX.SYS ### USB Connector Manager KMDF Class Extension Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.906 !$*C:\WINDOWS\System32\Drivers\UcmCx.sys [Drivers] :HKLM UcmTcpciCx0101=C:\WINDOWS\SYSTEM32\DRIVERS\UCMTCPCICX.SYS ### UCM-TCPCI KMDF Class Extension Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*C:\WINDOWS\System32\Drivers\UcmTcpciCx.sys [Drivers] :HKLM UcmUcsiAcpiClient=C:\WINDOWS\SYSTEM32\DRIVERS\UCMUCSIACPICLIENT.SYS ### UCM-UCSI ACPI Client Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*\SystemRoot\System32\drivers\UcmUcsiAcpiClient.sys [Drivers] :HKLM UcmUcsiCx0101=C:\WINDOWS\SYSTEM32\DRIVERS\UCMUCSICX.SYS ### UCM-UCSI KMDF Class Extension Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.488 !$*C:\WINDOWS\System32\Drivers\UcmUcsiCx.sys [Drivers] :HKLM Ucx01000=C:\WINDOWS\SYSTEM32\DRIVERS\UCX01000.SYS ### USB Controller Extension Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*C:\WINDOWS\system32\drivers\ucx01000.sys [Drivers] :HKLM UdeCx=C:\WINDOWS\SYSTEM32\DRIVERS\UDECX.SYS ### "udecx.DRIVER" Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 ->"UDECX.DRIVER" !$*C:\WINDOWS\system32\drivers\udecx.sys [Drivers] :HKLM udfs=C:\WINDOWS\SYSTEM32\DRIVERS\UDFS.SYS ### UDF File System Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*C:\WINDOWS\system32\DRIVERS\udfs.sys [Drivers] :HKLM UEFI=C:\WINDOWS\SYSTEM32\DRIVERSTORE\FILEREPOSITORY\UEFI.INF_AMD64_C1628FFA62C8E54C\UEFI.SYS ### UEFI Driver for NT Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*\SystemRoot\System32\DriverStore\FileRepository\uefi.inf_amd64_c1628ffa62c8e54c\UEFI.sys [Drivers] :HKLM Ufx01000=C:\WINDOWS\SYSTEM32\DRIVERS\UFX01000.SYS ### USB Function Driver Class Extension Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.789 !$*C:\WINDOWS\system32\drivers\ufx01000.sys [Drivers] :HKLM UfxChipidea=C:\WINDOWS\SYSTEM32\DRIVERSTORE\FILEREPOSITORY\UFXCHIPIDEA.INF_AMD64_1C78775FFFAB6A0A\UFXCHIPIDEA.SYS ### UFX Chipidea Client Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*\SystemRoot\System32\DriverStore\FileRepository\ufxchipidea.inf_amd64_1c78775fffab6a0a\UfxChipidea.sys [Drivers] :HKLM ufxsynopsys=C:\WINDOWS\SYSTEM32\DRIVERS\UFXSYNOPSYS.SYS ### UFX Synopsys Client Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.662 !$*\SystemRoot\System32\drivers\ufxsynopsys.sys [Drivers] :HKLM umbus=C:\WINDOWS\SYSTEM32\DRIVERSTORE\FILEREPOSITORY\UMBUS.INF_AMD64_B78A9C5B6FD62C27\UMBUS.SYS ### User-Mode Bus Enumerator Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*\SystemRoot\System32\DriverStore\FileRepository\umbus.inf_amd64_b78a9c5b6fd62c27\umbus.sys [Drivers] :HKLM UmPass=C:\WINDOWS\SYSTEM32\DRIVERS\UMPASS.SYS ### Generic pass-through driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 =>FUMPASS.SYS !$*\SystemRoot\System32\drivers\umpass.sys [Drivers] :HKLM UrsChipidea=C:\WINDOWS\SYSTEM32\DRIVERSTORE\FILEREPOSITORY\URSCHIPIDEA.INF_AMD64_78AD1C14E33DF968\URSCHIPIDEA.SYS ### USB Role-Switch Driver for Chipidea Core Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*\SystemRoot\System32\DriverStore\FileRepository\urschipidea.inf_amd64_78ad1c14e33df968\urschipidea.sys [Drivers] :HKLM UrsCx01000=C:\WINDOWS\SYSTEM32\DRIVERS\URSCX01000.SYS ### USB Role-Switch Class Extension Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*C:\WINDOWS\system32\drivers\urscx01000.sys [Drivers] :HKLM UrsSynopsys=C:\WINDOWS\SYSTEM32\DRIVERSTORE\FILEREPOSITORY\URSSYNOPSYS.INF_AMD64_057FA37902020500\URSSYNOPSYS.SYS ### USB Role-Switch Driver for Synopsys Core Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*\SystemRoot\System32\DriverStore\FileRepository\urssynopsys.inf_amd64_057fa37902020500\urssynopsys.sys [Drivers] :HKLM usbaudio=C:\WINDOWS\SYSTEM32\DRIVERS\USBAUDIO.SYS ### USB Audio Class Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.964 !$*\SystemRoot\system32\drivers\usbaudio.sys [Drivers] :HKLM usbaudio2=C:\WINDOWS\SYSTEM32\DRIVERS\USBAUDIO2.SYS ### Microsoft USB Audio Class 2.0 Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*\SystemRoot\System32\drivers\usbaudio2.sys [Drivers] :HKLM usbccgp=C:\WINDOWS\SYSTEM32\DRIVERS\USBCCGP.SYS ### USB Common Class Generic Parent Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.488 !$*\SystemRoot\System32\drivers\usbccgp.sys [Drivers] :HKLM usbcir=C:\WINDOWS\SYSTEM32\DRIVERS\USBCIR.SYS ### USB Consumer IR Driver for eHome Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*\SystemRoot\System32\drivers\usbcir.sys [Drivers] :HKLM usbehci=C:\WINDOWS\SYSTEM32\DRIVERS\USBEHCI.SYS ### EHCI eUSB Miniport Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*\SystemRoot\System32\drivers\usbehci.sys [Drivers] :HKLM usbhub=C:\WINDOWS\SYSTEM32\DRIVERS\USBHUB.SYS ### Pilote de concentrateur USB par défaut Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.1 !$*\SystemRoot\System32\drivers\usbhub.sys [Drivers] :HKLM USBHUB3=C:\WINDOWS\SYSTEM32\DRIVERS\USBHUB3.SYS ### Pilote de concentrateur USB3 Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.1 !$*\SystemRoot\System32\drivers\UsbHub3.sys [Drivers] :HKLM usbohci=C:\WINDOWS\SYSTEM32\DRIVERS\USBOHCI.SYS ### OHCI USB Miniport Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*\SystemRoot\System32\drivers\usbohci.sys [Drivers] :HKLM usbprint=C:\WINDOWS\SYSTEM32\DRIVERS\USBPRINT.SYS ### USB Printer driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*\SystemRoot\System32\drivers\usbprint.sys [Drivers] :HKLM usbser=C:\WINDOWS\SYSTEM32\DRIVERS\USBSER.SYS ### USB Serial Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.906 !$*\SystemRoot\System32\drivers\usbser.sys [Drivers] :HKLM USBSTOR=C:\WINDOWS\SYSTEM32\DRIVERS\USBSTOR.SYS ### Pilote de classe de stockage de masse USB Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.1 !$*\SystemRoot\System32\drivers\USBSTOR.SYS [Drivers] :HKLM usbuhci=C:\WINDOWS\SYSTEM32\DRIVERS\USBUHCI.SYS ### UHCI USB Miniport Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*\SystemRoot\System32\drivers\usbuhci.sys [Drivers] :HKLM usbvideo=C:\WINDOWS\SYSTEM32\DRIVERS\USBVIDEO.SYS ### USB Video Class Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.964 !$*\SystemRoot\System32\Drivers\usbvideo.sys [Drivers] :HKLM USBXHCI=C:\WINDOWS\SYSTEM32\DRIVERS\USBXHCI.SYS ### Pilote XHCI USB Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.1 !$*\SystemRoot\System32\drivers\USBXHCI.SYS [Drivers] :HKLM vdrvroot=C:\WINDOWS\SYSTEM32\DRIVERS\VDRVROOT.SYS ### Virtual Drive Root Enumerator Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*C:\WINDOWS\System32\drivers\vdrvroot.sys [Drivers] :HKLM vdvad_WaveExtensible=C:\WINDOWS\SYSTEM32\DRIVERS\VDVAD.SYS ### Virtual Desktop Audio Virtual Desktop Virtual Desktop Audio 1.5.0.0 !$*\SystemRoot\System32\drivers\vdvad.sys [Drivers] :HKLM vdvge=C:\WINDOWS\SYSTEM32\DRIVERS\VDVGE.SYS ### Virtual Desktop Gamepad Emulation Driver Virtual Desktop, Inc. Virtual Desktop Gamepad Emulation Driver 1.0.1.0 !$*\SystemRoot\System32\drivers\vdvge.sys [Drivers] :HKLM VerifierExt=C:\WINDOWS\SYSTEM32\DRIVERS\VERIFIEREXT.SYS ### Extension du vérificateur de pilotes Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\System32\drivers\VerifierExt.sys [Drivers] :HKLM vhdmp=C:\WINDOWS\SYSTEM32\DRIVERS\VHDMP.SYS ### VHD Miniport Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*\SystemRoot\System32\drivers\vhdmp.sys [Drivers] :HKLM vhf=C:\WINDOWS\SYSTEM32\DRIVERS\VHF.SYS ### Virtual HID Framework (VHF) Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*\SystemRoot\System32\drivers\vhf.sys [Drivers] :HKLM Vid=C:\WINDOWS\SYSTEM32\DRIVERS\VID.SYS ### Microsoft Hyper-V Virtualization Infrastructure Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1052 !$*\SystemRoot\System32\drivers\Vid.sys [Drivers] :HKLM VirtualRender=C:\WINDOWS\SYSTEM32\DRIVERSTORE\FILEREPOSITORY\VRD.INF_AMD64_81FBD405FF2470FC\VRD.SYS ### Microsoft Virtual Render Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*\SystemRoot\System32\DriverStore\FileRepository\vrd.inf_amd64_81fbd405ff2470fc\vrd.sys [Drivers] :HKLM vmbus=C:\WINDOWS\SYSTEM32\DRIVERS\VMBUS.SYS ### Pilote enfant de bus VMBus sous Microsoft Hyper-V Microsoft Corporation Système d'exploitation Microsoft® Windows® 10.0.19041.1 !$*C:\WINDOWS\System32\drivers\vmbus.sys [Drivers] :HKLM VMBusHID=C:\WINDOWS\SYSTEM32\DRIVERS\VMBUSHID.SYS ### Microsoft VMBus HID Miniport Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*\SystemRoot\System32\drivers\VMBusHID.sys [Drivers] :HKLM vmgid=C:\WINDOWS\SYSTEM32\DRIVERS\VMGID.SYS ### Virtual Machine Guest Infrastructure Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*\SystemRoot\System32\drivers\vmgid.sys [Drivers] :HKLM volmgr=C:\WINDOWS\SYSTEM32\DRIVERS\VOLMGR.SYS ### Pilote du gestionnaire de volumes Microsoft Corporation Système d'exploitation Microsoft® Windows® 10.0.19041.1 !$*C:\WINDOWS\System32\drivers\volmgr.sys [Drivers] :HKLM volmgrx=C:\WINDOWS\SYSTEM32\DRIVERS\VOLMGRX.SYS ### Pilote d’extension du gestionnaire de volumes Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\System32\drivers\volmgrx.sys [Drivers] :HKLM volsnap=C:\WINDOWS\SYSTEM32\DRIVERS\VOLSNAP.SYS ### Pilote de cliché instantané du volume Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\System32\drivers\volsnap.sys [Drivers] :HKLM volume=C:\WINDOWS\SYSTEM32\DRIVERS\VOLUME.SYS ### Volume driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*C:\WINDOWS\System32\drivers\volume.sys [Drivers] :HKLM vpci=C:\WINDOWS\SYSTEM32\DRIVERS\VPCI.SYS ### Virtual PCI Bus Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*C:\WINDOWS\System32\drivers\vpci.sys [Drivers] :HKLM vsmraid=C:\WINDOWS\SYSTEM32\DRIVERS\VSMRAID.SYS ### VIA RAID DRIVER FOR AMD-X86-64 VIA Technologies Inc.,Ltd VIA RAID driver 7.0.9600,6352 !$*C:\WINDOWS\System32\drivers\vsmraid.sys [Drivers] :HKLM VSTXRAID=C:\WINDOWS\SYSTEM32\DRIVERS\VSTXRAID.SYS ### VIA StorX RAID Controller Driver VIA Corporation VIA StorX RAID Controller Driver 8.0.9200.8110 !$*C:\WINDOWS\System32\drivers\vstxraid.sys [Drivers] :HKLM vwifibus=C:\WINDOWS\SYSTEM32\DRIVERS\VWIFIBUS.SYS ### Virtual Wireless Bus Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*\SystemRoot\System32\drivers\vwifibus.sys [Drivers] :HKLM vwififlt=C:\WINDOWS\SYSTEM32\DRIVERS\VWIFIFLT.SYS ### Virtual WiFi Filter Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*C:\WINDOWS\System32\drivers\vwififlt.sys [Drivers] :HKLM vwifimp=C:\WINDOWS\SYSTEM32\DRIVERS\VWIFIMP.SYS ### Virtual WiFi Miniport Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*\SystemRoot\System32\drivers\vwifimp.sys [Drivers] :HKLM WacomPen=C:\WINDOWS\SYSTEM32\DRIVERS\WACOMPEN.SYS ### Pilote de tablette Wacom à stylet série Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.1 !$*\SystemRoot\System32\drivers\wacompen.sys [Drivers] :HKLM wanarp=C:\WINDOWS\SYSTEM32\DRIVERS\WANARP.SYS ### MS Remote Access and Routing ARP Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.546 !$*C:\WINDOWS\System32\DRIVERS\wanarp.sys [Drivers] :HKLM wanarpv6=C:\WINDOWS\SYSTEM32\DRIVERS\WANARP.SYS ### MS Remote Access and Routing ARP Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.546 !$*C:\WINDOWS\System32\DRIVERS\wanarp.sys [Drivers] :HKLM wcifs=C:\WINDOWS\SYSTEM32\DRIVERS\WCIFS.SYS ### Windows Container Isolation FS Filter Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.844 !$*\SystemRoot\system32\drivers\wcifs.sys [Drivers] :HKLM wcnfs=C:\WINDOWS\SYSTEM32\DRIVERS\WCNFS.SYS ### Windows Container Name Virtualization FS Filter Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.844 !$*\SystemRoot\system32\drivers\wcnfs.sys [Drivers] :HKLM WdBoot=C:\WINDOWS\SYSTEM32\DRIVERS\WD\WDBOOT.SYS ### Microsoft antimalware boot driver Microsoft Corporation Microsoft® Windows® Operating System 4.18.2105.5 !$*C:\WINDOWS\system32\drivers\wd\WdBoot.sys [Drivers] :HKLM Wdf01000=C:\WINDOWS\SYSTEM32\DRIVERS\WDF01000.SYS ### Runtime de l’infrastructure de pilotes en mode noyau Microsoft Corporation Système d’exploitation Microsoft® Windows® 1.31.19041.867 !$*C:\WINDOWS\system32\drivers\Wdf01000.sys [Drivers] :HKLM WdFilter=C:\WINDOWS\SYSTEM32\DRIVERS\WD\WDFILTER.SYS ### Microsoft antimalware file system filter driver Microsoft Corporation Microsoft® Windows® Operating System 4.18.2105.5 !$*C:\WINDOWS\system32\drivers\wd\WdFilter.sys [Drivers] :HKLM WdiServiceHost=C:\WINDOWS\SYSTEM32\DRIVERS\WD\WDFILTER.SYS ### Microsoft antimalware file system filter driver Microsoft Corporation Microsoft® Windows® Operating System 4.18.2105.5 !$*C:\WINDOWS\system32\drivers\wd\WdFilter.sys [Drivers] :HKLM WdiSystemHost=C:\WINDOWS\SYSTEM32\DRIVERS\WD\WDFILTER.SYS ### Microsoft antimalware file system filter driver Microsoft Corporation Microsoft® Windows® Operating System 4.18.2105.5 !$*C:\WINDOWS\system32\drivers\wd\WdFilter.sys [Drivers] :HKLM wdiwifi=C:\WINDOWS\SYSTEM32\DRIVERS\WDIWIFI.SYS ### WDI Driver Framework Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1023 !$*C:\WINDOWS\system32\DRIVERS\wdiwifi.sys [Drivers] :HKLM WdmCompanionFilter=C:\WINDOWS\SYSTEM32\DRIVERS\WDMCOMPANIONFILTER.SYS ### WDM Companion Filter Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*C:\WINDOWS\system32\drivers\WdmCompanionFilter.sys [Drivers] :HKLM WdNisDrv=C:\WINDOWS\SYSTEM32\DRIVERS\WD\WDNISDRV.SYS ### Windows Defender Network Stream Filter Microsoft Corporation Microsoft® Windows® Operating System 4.18.2105.5 !$*C:\WINDOWS\system32\drivers\wd\WdNisDrv.sys [Drivers] :HKLM WFPLWFS=C:\WINDOWS\SYSTEM32\DRIVERS\WFPLWFS.SYS ### WFP NDIS 6.30 Lightweight Filter Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.867 !$*C:\WINDOWS\System32\drivers\wfplwfs.sys [Drivers] :HKLM WIMMount=C:\WINDOWS\SYSTEM32\DRIVERS\WIMMOUNT.SYS ### Wim file system Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.964 ->WIMFLTR.SYS !$*C:\WINDOWS\system32\drivers\wimmount.sys [Drivers] :HKLM WindowsTrustedRT=C:\WINDOWS\SYSTEM32\DRIVERS\WINDOWSTRUSTEDRT.SYS ### Windows Trusted Runtime Interface Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*C:\WINDOWS\system32\drivers\WindowsTrustedRT.sys [Drivers] :HKLM WindowsTrustedRTProxy=C:\WINDOWS\SYSTEM32\DRIVERS\WINDOWSTRUSTEDRTPROXY.SYS ### Windows Trusted Runtime Service Proxy Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*C:\WINDOWS\System32\drivers\WindowsTrustedRTProxy.sys [Drivers] :HKLM WinMad=C:\WINDOWS\SYSTEM32\DRIVERS\WINMAD.SYS ### Kernel WinMad Mellanox OpenFabrics Windows 10.0.10011.16384 !$*\SystemRoot\System32\drivers\winmad.sys [Drivers] :HKLM WinNat=C:\WINDOWS\SYSTEM32\DRIVERS\WINNAT.SYS ### Pilote NAT Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\drivers\winnat.sys [Drivers] :HKLM WINUSB=C:\WINDOWS\SYSTEM32\DRIVERS\WINUSB.SYS ### Windows WinUSB Class Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*\SystemRoot\System32\drivers\WinUSB.SYS [Drivers] :HKLM WinVerbs=C:\WINDOWS\SYSTEM32\DRIVERS\WINVERBS.SYS ### Kernel WinVerbs Mellanox OpenFabrics Windows 10.0.10011.16384 !$*\SystemRoot\System32\drivers\winverbs.sys [Drivers] :HKLM WmiAcpi=C:\WINDOWS\SYSTEM32\DRIVERS\WMIACPI.SYS ### Windows Management Interface for ACPI Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*\SystemRoot\System32\drivers\wmiacpi.sys [Drivers] :HKLM WpdUpFltr=C:\WINDOWS\SYSTEM32\DRIVERS\WPDUPFLTR.SYS ### Windows Portable Device Upper Class Filter Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*C:\WINDOWS\System32\drivers\WpdUpFltr.sys [Drivers] :HKLM ws2ifsl=C:\WINDOWS\SYSTEM32\DRIVERS\WS2IFSL.SYS ### Couche IFS Winsock2 Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*\SystemRoot\system32\drivers\ws2ifsl.sys [Drivers] :HKLM WSDPrintDevice=C:\WINDOWS\SYSTEM32\DRIVERS\WSDPRINT.SYS ### Web Services Print Device Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*\SystemRoot\System32\drivers\WSDPrint.sys [Drivers] :HKLM WSDScan=C:\WINDOWS\SYSTEM32\DRIVERS\WSDSCAN.SYS ### Web Service Based Scan Device Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.264 !$*\SystemRoot\system32\DRIVERS\WSDScan.sys [Drivers] :HKLM WudfPf=C:\WINDOWS\SYSTEM32\DRIVERS\WUDFPF.SYS ### Windows Driver Foundation - User-mode Driver Framework Platform Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*C:\WINDOWS\system32\drivers\WudfPf.sys [Drivers] :HKLM WUDFRd=C:\WINDOWS\SYSTEM32\DRIVERS\WUDFRD.SYS ### Windows Driver Foundation - User-mode Driver Framework Reflector Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*\SystemRoot\System32\drivers\WUDFRd.sys [Drivers] :HKLM WUDFWpdFs=C:\WINDOWS\SYSTEM32\DRIVERS\WUDFRD.SYS ### Windows Driver Foundation - User-mode Driver Framework Reflector Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*\SystemRoot\system32\DRIVERS\WUDFRd.sys [Drivers] :HKLM xboxgip=C:\WINDOWS\SYSTEM32\DRIVERS\XBOXGIP.SYS ### Game Input Protocol Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.844 !$*\SystemRoot\System32\drivers\xboxgip.sys [Drivers] :HKLM xinputhid=C:\WINDOWS\SYSTEM32\DRIVERS\XINPUTHID.SYS ### XINPUT filter driver for HID Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.844 !$*\SystemRoot\System32\drivers\xinputhid.sys [Drivers] :HKLM XtuAcpiDriver=C:\WINDOWS\SYSTEM32\DRIVERS\XTUACPIDRIVER.SYS ### Intel(R) Acpi Control Driver Intel Corporation Intel(R) Extreme Tuning Utility Performance Tuning Driver 4.0.0.14 !$*\SystemRoot\System32\drivers\XtuAcpiDriver.sys [Drivers] :HKLM Xvdd=C:\WINDOWS\SYSTEM32\DRIVERSTORE\FILEREPOSITORY\XVDD.INF_AMD64_3DF14D8AE1A3457F\XVDD.SYS ### XVD Disk Driver Microsoft Corporation Microsoft Gaming Filesystem Driver 10.0.19041.7129 !$*\SystemRoot\System32\DriverStore\FileRepository\xvdd.inf_amd64_3df14d8ae1a3457f\xvdd.sys [Drivers] :HKLM zttap300=C:\WINDOWS\SYSTEM32\DRIVERS\ZTTAP300.SYS ### ZeroTier One Virtual Network Port ZeroTier Networks LLC ZeroTier One Virtual Network Port 3.0.0 3/0 !$*\SystemRoot\System32\drivers\zttap300.sys [Codecs] :HKLM aux=C:\WINDOWS\SYSTEM32\WDMAUD.DRV ### Pilote du système audio Winmm Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*wdmaud.drv [Codecs] :HKLM midi=C:\WINDOWS\SYSTEM32\WDMAUD.DRV ### Pilote du système audio Winmm Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*wdmaud.drv [Codecs] :HKLM midimapper=C:\WINDOWS\SYSTEM32\MIDIMAP.DLL ### Microsoft MIDI Mapper Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.488 !$*midimap.dll [Codecs] :HKLM mixer=C:\WINDOWS\SYSTEM32\WDMAUD.DRV ### Pilote du système audio Winmm Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*wdmaud.drv [Codecs] :HKLM msacm.imaadpcm=C:\WINDOWS\SYSTEM32\IMAADP32.ACM ### Codec IMA ADPCM pour MSACM Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 ->IMA ADPCM CODEC FOR MSACM !$*imaadp32.acm [Codecs] :HKLM msacm.msadpcm=C:\WINDOWS\SYSTEM32\MSADP32.ACM ### Codec Microsoft ADPCM pour MSACM Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 ->MICROSOFT ADPCM CODEC FOR MSACM !$*msadp32.acm [Codecs] :HKLM msacm.msg711=C:\WINDOWS\SYSTEM32\MSG711.ACM ### CODEC A-Law et u-Law pour MSACM Microsoft CCITT G.711 Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 ->MICROSOFT CCITT G.711 (A-LAW AND U-LAW) CODEC FOR MSACM !$*msg711.acm [Codecs] :HKLM msacm.msgsm610=C:\WINDOWS\SYSTEM32\MSGSM32.ACM ### Codec audio Microsoft GSM 6.10 pour MSACM Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 ->MICROSOFT GSM 6.10 AUDIO CODEC FOR MSACM !$*msgsm32.acm [Codecs] :HKLM vidc.cvid=C:\WINDOWS\Syswow64\ICCVID.DLL ### Codec Cinepak® Radius Inc. Cinepak pour Windows 32 1.10.0.0 =>ICCVID.DRV.MUI !$*iccvid.dll [Codecs] :HKLM vidc.i420=C:\WINDOWS\SYSTEM32\IYUV_32.DLL ### Codec vidéo YUV Intel Indeo(R) Microsoft Corporation Système d'exploitation Microsoft® Windows® 10.0.19041.867 !$*iyuv_32.dll [Codecs] :HKLM vidc.iyuv=C:\WINDOWS\SYSTEM32\IYUV_32.DLL ### Codec vidéo YUV Intel Indeo(R) Microsoft Corporation Système d'exploitation Microsoft® Windows® 10.0.19041.867 !$*iyuv_32.dll [Codecs] :HKLM vidc.mrle=C:\WINDOWS\SYSTEM32\MSRLE32.DLL ### Microsoft RLE Compressor Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*msrle32.dll [Codecs] :HKLM vidc.msvc=C:\WINDOWS\SYSTEM32\MSVIDC32.DLL ### Compresseur Microsoft Vidéo 1 Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*msvidc32.dll [Codecs] :HKLM vidc.uyvy=C:\WINDOWS\SYSTEM32\MSYUV.DLL ### Microsoft UYVY Video Decompressor Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*msyuv.dll [Codecs] :HKLM vidc.yuy2=C:\WINDOWS\SYSTEM32\MSYUV.DLL ### Microsoft UYVY Video Decompressor Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*msyuv.dll [Codecs] :HKLM vidc.yvu9=C:\WINDOWS\SYSTEM32\TSBYUV.DLL ### Toshiba Video Codec Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*tsbyuv.dll [Codecs] :HKLM vidc.yvyu=C:\WINDOWS\SYSTEM32\MSYUV.DLL ### Microsoft UYVY Video Decompressor Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*msyuv.dll [Codecs] :HKLM wave=C:\WINDOWS\SYSTEM32\WDMAUD.DRV ### Pilote du système audio Winmm Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*wdmaud.drv [Codecs] :HKLM wavemapper=C:\WINDOWS\SYSTEM32\MSACM32.DRV ### Microsoft Sound Mapper Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.488 ->MICROSOFT SOUND MAPPER =>MSACM32.ACM.MUI !$*msacm32.drv [Codecs] :HKLM msacm.l3acm=C:\WINDOWS\SYSWOW64\L3CODECA.ACM ### MPEG Layer-3 Audio Codec for MSACM Fraunhofer Institut Integrierte Schaltungen IIS Codec audio MPEG Layer-3 pour MSACM 1, 0, 0, 0 ->L3CODEC.ACM =>L3CODEC.ACM.MUI !$*C:\Windows\SysWOW64\l3codeca.acm [Codecs] :HKLM VIDC.RTV1=C:\WINDOWS\Syswow64\RTVCVFW32.DLL ### !$*rtvcvfw32.dll [Codecs] :HKLM aux1=C:\WINDOWS\SYSTEM32\WDMAUD.DRV ### Pilote du système audio Winmm Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*wdmaud.drv [Codecs] :HKLM aux2=C:\WINDOWS\SYSTEM32\WDMAUD.DRV ### Pilote du système audio Winmm Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*wdmaud.drv [Codecs] :HKLM aux3=C:\WINDOWS\SYSTEM32\WDMAUD.DRV ### Pilote du système audio Winmm Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*wdmaud.drv [Codecs] :HKLM midi1=C:\WINDOWS\SYSTEM32\WDMAUD.DRV ### Pilote du système audio Winmm Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*wdmaud.drv [Codecs] :HKLM midi2=C:\WINDOWS\SYSTEM32\WDMAUD.DRV ### Pilote du système audio Winmm Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*wdmaud.drv [Codecs] :HKLM midi3=C:\WINDOWS\SYSTEM32\WDMAUD.DRV ### Pilote du système audio Winmm Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*wdmaud.drv [Codecs] :HKLM mixer1=C:\WINDOWS\SYSTEM32\WDMAUD.DRV ### Pilote du système audio Winmm Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*wdmaud.drv [Codecs] :HKLM mixer2=C:\WINDOWS\SYSTEM32\WDMAUD.DRV ### Pilote du système audio Winmm Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*wdmaud.drv [Codecs] :HKLM mixer3=C:\WINDOWS\SYSTEM32\WDMAUD.DRV ### Pilote du système audio Winmm Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*wdmaud.drv [Codecs] :HKLM wave1=C:\WINDOWS\SYSTEM32\WDMAUD.DRV ### Pilote du système audio Winmm Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*wdmaud.drv [Codecs] :HKLM wave2=C:\WINDOWS\SYSTEM32\WDMAUD.DRV ### Pilote du système audio Winmm Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*wdmaud.drv [Codecs] :HKLM wave3=C:\WINDOWS\SYSTEM32\WDMAUD.DRV ### Pilote du système audio Winmm Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*wdmaud.drv [Codecs] :HKLM midi4=C:\WINDOWS\SYSTEM32\WDMAUD.DRV ### Pilote du système audio Winmm Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*wdmaud.drv [Codecs] :HKLM mixer4=C:\WINDOWS\SYSTEM32\WDMAUD.DRV ### Pilote du système audio Winmm Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*wdmaud.drv [Codecs] :HKLM wave4=C:\WINDOWS\SYSTEM32\WDMAUD.DRV ### Pilote du système audio Winmm Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*wdmaud.drv [Codecs] :HKLM midi5=C:\WINDOWS\SYSTEM32\WDMAUD.DRV ### Pilote du système audio Winmm Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*wdmaud.drv [Codecs] :HKLM mixer5=C:\WINDOWS\SYSTEM32\WDMAUD.DRV ### Pilote du système audio Winmm Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*wdmaud.drv [Codecs] :HKLM wave5=C:\WINDOWS\SYSTEM32\WDMAUD.DRV ### Pilote du système audio Winmm Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*wdmaud.drv [Codecs] :HKLM mixer6=C:\WINDOWS\SYSTEM32\WDMAUD.DRV ### Pilote du système audio Winmm Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*wdmaud.drv [Codecs] :HKLM wave6=C:\WINDOWS\SYSTEM32\WDMAUD.DRV ### Pilote du système audio Winmm Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*wdmaud.drv [Codecs] :HKLM mixer7=C:\WINDOWS\SYSTEM32\WDMAUD.DRV ### Pilote du système audio Winmm Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*wdmaud.drv [Codecs] :HKLM wave7=C:\WINDOWS\SYSTEM32\WDMAUD.DRV ### Pilote du système audio Winmm Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*wdmaud.drv [Codecs] :HKLM aux4=C:\WINDOWS\SYSTEM32\WDMAUD.DRV ### Pilote du système audio Winmm Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*wdmaud.drv [Codecs] :HKLM midi6=C:\WINDOWS\SYSTEM32\WDMAUD.DRV ### Pilote du système audio Winmm Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*wdmaud.drv [Codecs] :HKLM mixer8=C:\WINDOWS\SYSTEM32\WDMAUD.DRV ### Pilote du système audio Winmm Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*wdmaud.drv [Codecs] :HKLM wave8=C:\WINDOWS\SYSTEM32\WDMAUD.DRV ### Pilote du système audio Winmm Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*wdmaud.drv [DCOM Components] :HKLM {F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}="" [DCOM Components] :HKLM {5839FCA9-774D-42A1-ACDA-D6A79037F57F}="" [DCOM Components] :HKLM {42AEDC87-2188-41FD-B9A3-0C966FEABEC1}="" [DCOM User Components] :HKCU {F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}="" [DCOM User Components] :HKCU {FBEB8A05-BEEE-4442-804E-409D6C4515E9}="" [DCOM User Components] :HKCU {42AEDC87-2188-41FD-B9A3-0C966FEABEC1}="" [Auto Start Apps] [Registry Run] :HKCU Discord=C:\USERS\USER\APPDATA\LOCAL\DISCORD\UPDATE.EXE ### Update GitHub Update 1.1.1.0 !$*C:\Users\user\AppData\Local\Discord\Update.exe --processStart Discord.exe [Registry Run] :HKCU DAEMON Tools Lite Automount=C:\PROGRAM FILES\DAEMON TOOLS LITE\DTAGENT.EXE ### DAEMON Tools Lite Agent Disc Soft Ltd DAEMON Tools Lite 10.14.0.1709 !$*"C:\Program Files\DAEMON Tools Lite\DTAgent.exe" -autorun [Registry Run] :HKLM SunJavaUpdateSched=C:\PROGRAM FILES (X86)\COMMON FILES\JAVA\JAVA UPDATE\JUSCHED.EXE ### Java Update Scheduler Oracle Corporation Java Platform SE Auto Updater 2.8.291.10 ->JAVA UPDATE SCHEDULER !$*"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [Registry Run] :HKLM LogMeIn Hamachi Ui=C:\PROGRAM FILES (X86)\LOGMEIN HAMACHI\HAMACHI-2-UI.EXE ### Hamachi Client Application LogMeIn Inc. Hamachi Client 2, 0, 0, 0 !$*"C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start [Registry Run(x64)] :HKLM SecurityHealth=C:\WINDOWS\SYSTEM32\SECURITYHEALTHSYSTRAY.EXE ### Windows Security notification icon Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*%windir%\system32\SecurityHealthSystray.exe [Registry Run(x64)] :HKLM ctfmon=C:\WINDOWS\SYSTEM32\CTFMON.EXE ### Chargeur CTF Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\Windows\System32\ctfmon.exe [Registry Run(x64)] :HKLM SteelSeriesGG=C:\PROGRAM FILES\STEELSERIES\STEELSERIES ENGINE 3\STEELSERIESGG.EXE ### SteelSeries GG SteelSeries ApS SteelSeries GG 3.1.0.0 !$*"C:\Program Files\SteelSeries\SteelSeries Engine 3\SteelSeriesGG.exe" -dataPath="C:\ProgramData\SteelSeries\SteelSeries Engine 3" -dbEnv=production -auto=true [Win.ini] :HKCU load="" [Win.ini] :HKCU run="" [Common Startup Folder] NETGEAR A7000 Genie.lnk=C:\PROGRAM FILES (X86)\NETGEAR\A7000\RTLSERVICE.EXE ### Realtek RtlService Application Realtek Semiconductor Corp. Realtek RtlService Application 700, 1007, 509, 2012 !$*C:\Program Files (x86)\NETGEAR\A7000\RtlService.exe -b [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Agent Activation Runtime\S-1-5-21-2089416355-1224182416-3757198850-1001=C:\WINDOWS\SYSTEM32\AGENTACTIVATIONRUNTIMESTARTER.EXE ### !$*C:\WINDOWS\System32\AgentActivationRuntimeStarter.exe Status: Disabled Description: 0 Parameters: 0 [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\CCleaner Update=I:\ccleaner\CCUpdate.exe ### File is missing. !$*I:\ccleaner\CCUpdate.exe Description: 0 Parameters: 0 [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\CCleanerSkipUAC="I:\ccleaner\CCleaner.exe" ### File is missing. !$*"I:\ccleaner\CCleaner.exe" Description: 0 Parameters: $(Arg0) [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\InstallShield® Setup Engine Kernel=C:\PROGRAM FILES (X86)\COMMON FILES\INSTALLSHIELD\ENGINE\8\INTEL 32\IKERNEL.EXE ### InstallShield (R) Setup Engine InstallShield Software Corporation InstallShield (R) 6, 31 ->KERNEL !$*"C:\Program Files (x86)\Common Files\installshield\engine\8\intel 32\iKernel.exe" Description: 0 Parameters: 0 [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\Windows\AppID\PolicyConverter=C:\WINDOWS\SYSTEM32\APPIDPOLICYCONVERTER.EXE ### AppID Policy Converter Task Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.906 !$*%windir%\system32\appidpolicyconverter.exe Status: Disabled Description: $(@%systemroot%\system32\appidsvc.dll,-302) Parameters: 0 [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\Windows\AppID\VerifiedPublisherCertStoreCheck=C:\WINDOWS\SYSTEM32\APPIDCERTSTORECHECK.EXE ### AppID Certificate Store Verification Task Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.906 !$*%windir%\system32\appidcertstorecheck.exe Status: Disabled Description: $(@%systemroot%\system32\appidsvc.dll,-202) Parameters: 0 [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser=C:\WINDOWS\SYSTEM32\COMPATTELRUNNER.EXE ### Microsoft Compatibility Telemetry Microsoft Corporation Microsoft® Windows® Operating System 10.0.19645.1029 !$*%windir%\system32\compattelrunner.exe Description: $(@%SystemRoot%\system32\compattelrunner.exe,-503) Parameters: 0 [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\Windows\Application Experience\PcaPatchDbTask=C:\WINDOWS\SYSTEM32\PCASVC.DLL ### Service de l’Assistant Compatibilité des programmes Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%windir%\system32\rundll32.exe %windir%\system32\PcaSvc.dll,PcaPatchSdbTask Description: Updates compatibility database Parameters: %windir%\system32\PcaSvc.dll,PcaPatchSdbTask [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\Windows\Application Experience\ProgramDataUpdater=C:\WINDOWS\SYSTEM32\COMPATTELRUNNER.EXE ### Microsoft Compatibility Telemetry Microsoft Corporation Microsoft® Windows® Operating System 10.0.19645.1029 !$*%windir%\system32\compattelrunner.exe Description: $(@%SystemRoot%\system32\invagent.dll,-702) Parameters: -maintenance [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\Windows\Application Experience\StartupAppTask=C:\WINDOWS\SYSTEM32\STARTUPSCAN.DLL ### DLL de tâche d’analyse de démarrage Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%windir%\system32\rundll32.exe Startupscan.dll,SusRunTask Description: $(@%SystemRoot%\system32\Startupscan.dll,-702) Parameters: Startupscan.dll,SusRunTask [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\Windows\applicationdata\appuriverifierdaily=C:\WINDOWS\SYSTEM32\APPHOSTREGISTRATIONVERIFIER.EXE ### Vérificateur de l’inscription des gestionnaires d’URI d’applications Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 ->APP URI HANDLERS REGISTRATION VERIFIER =>APPHOSTNAMEREGISTRATIONVERIFIER.EXE.MUI !$*%windir%\system32\AppHostRegistrationVerifier.exe Description: $(@%systemroot%\system32\AppHostRegistrationVerifi Parameters: 0 [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\Windows\applicationdata\appuriverifierinstall=C:\WINDOWS\SYSTEM32\APPHOSTREGISTRATIONVERIFIER.EXE ### Vérificateur de l’inscription des gestionnaires d’URI d’applications Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 ->APP URI HANDLERS REGISTRATION VERIFIER =>APPHOSTNAMEREGISTRATIONVERIFIER.EXE.MUI !$*%windir%\system32\AppHostRegistrationVerifier.exe Description: $(@%systemroot%\system32\AppHostRegistrationVerifi Parameters: 0 [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\Windows\applicationdata\CleanupTemporaryState=C:\WINDOWS\SYSTEM32\WINDOWS.STORAGE.APPLICATIONDATA.DLL ### Windows Application Data API Server Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 ->WINDOWS APPLICATION DATA API SERVER !$*%windir%\system32\rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState Description: $(@%systemroot%\system32\Windows.Storage.Applicati Parameters: Windows.Storage.ApplicationData.dll,CleanupTemporaryState [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\Windows\applicationdata\DsSvcCleanup=C:\WINDOWS\SYSTEM32\DSTOKENCLEAN.EXE ### Data Sharing Service Maintenance Driver Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.84 ->DATA SHARING SERVICE MAINTENANCE DRIVER !$*%windir%\system32\dstokenclean.exe Description: $(@%systemroot%\system32\dssvc.dll,-10006) Parameters: 0 [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup=C:\WINDOWS\SYSTEM32\APPXDEPLOYMENTCLIENT.DLL ### DLL du client de déploiement d’AppX Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%windir%\system32\rundll32.exe %windir%\system32\AppxDeploymentClient.dll,AppxPreStageCleanupRunTask Description: 0 Parameters: %windir%\system32\AppxDeploymentClient.dll,AppxPreStageCleanupRunTask [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\Windows\Autochk\Proxy=C:\WINDOWS\SYSTEM32\ACPROXY.DLL ### DLL de proxy Autochk Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%windir%\system32\rundll32.exe /d acproxy.dll,PerformAutochkOperations Description: $(@%systemroot%\system32\acproxy.dll,-102) Parameters: /d acproxy.dll,PerformAutochkOperations [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\Windows\Bluetooth\UninstallDeviceTask=C:\WINDOWS\SYSTEM32\BTHUDTASK.EXE ### Tâche de désinstallation du périphérique Bluetooth Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*BthUdTask.exe Description: $(@%SystemRoot%\system32\BthUdTask.exe,-1001) Parameters: $(Arg0) [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\Windows\Chkdsk\SyspartRepair=C:\WINDOWS\SYSTEM32\BCDBOOT.EXE ### Utilitaire Bcdboot Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%windir%\system32\bcdboot.exe Description: 0 Parameters: %windir% /sysrepair [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\Windows\Clip\License Validation=C:\WINDOWS\System32\CLIPUP.EXE ### Client License Platform migration tool Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1052 ->CLIENT LICENSE PLATFORM MIGRATION TOOL !$*%SystemRoot%\system32\ClipUp.exe Status: Disabled Description: $(@%SystemRoot%\system32\ClipUp.exe,-101) Parameters: -p -s -o [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\Windows\Customer Experience Improvement Program\Consolidator=C:\WINDOWS\System32\WSQMCONS.EXE ### Consolidateur SQM Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\wsqmcons.exe Description: $(@%systemRoot%\system32\wsqmcons.exe,-107) Parameters: 0 [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\Windows\Defrag\ScheduledDefrag=C:\WINDOWS\SYSTEM32\DEFRAG.EXE ### Module de défragmenteur de disque Microsoft Corp. Optimiseur de lecteur Windows 10.0.19041.867 !$*%windir%\system32\defrag.exe Description: $(@%systemroot%\system32\defragsvc.dll,-802) Parameters: -c -h -o -$ [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\Windows\Device Information\Device=C:\WINDOWS\SYSTEM32\DEVICECENSUS.EXE ### Device Census Microsoft Corporation Microsoft® Windows® Operating System 10.0.19645.1029 !$*%windir%\system32\devicecensus.exe Description: 0 Parameters: SystemCxt [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\Windows\Device Information\Device User=C:\WINDOWS\SYSTEM32\DEVICECENSUS.EXE ### Device Census Microsoft Corporation Microsoft® Windows® Operating System 10.0.19645.1029 !$*%windir%\system32\devicecensus.exe Description: 0 Parameters: UserCxt [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\Windows\DirectX\DirectXDatabaseUpdater=C:\WINDOWS\SYSTEM32\DIRECTXDATABASEUPDATER.EXE ### DirectX Database Updater Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.928 !$*%windir%\system32\directxdatabaseupdater.exe Description: 0 Parameters: 0 [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\Windows\DirectX\DXGIAdapterCache=C:\WINDOWS\SYSTEM32\DXGIADAPTERCACHE.EXE ### DXGI Adapter Cache Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.928 !$*%windir%\system32\dxgiadaptercache.exe Description: 0 Parameters: 0 [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\Windows\DiskCleanup\SilentCleanup=C:\WINDOWS\SYSTEM32\CLEANMGR.EXE ### Gestionnaire de nettoyage de disque pour Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 =>CLEANMGR.DLL.MUI !$*%windir%\system32\cleanmgr.exe Description: $(@%systemroot%\system32\cleanmgr.exe,-1301) Parameters: /autoclean /d %systemdrive% [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector=C:\WINDOWS\SYSTEM32\DFDTS.DLL ### Module de diagnostics des erreurs de disque Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%windir%\system32\rundll32.exe dfdts.dll,DfdGetDefaultPolicyAndSMART Description: $(@%SystemRoot%\System32\DFDTS.dll,-119) Parameters: dfdts.dll,DfdGetDefaultPolicyAndSMART [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticResolver=C:\WINDOWS\SYSTEM32\DFDWIZ.EXE ### Outil de résolution des défaillances disque Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%windir%\system32\DFDWiz.exe Status: Disabled Description: $(@%SystemRoot%\System32\DFDTS.dll,-118) Parameters: 0 [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\Windows\DiskFootprint\Diagnostics=C:\WINDOWS\SYSTEM32\DISKSNAPSHOT.EXE ### DiskSnapshot.exe Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*%windir%\system32\disksnapshot.exe Description: 0 Parameters: -z [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\Windows\DUSM\dusmtask=C:\WINDOWS\System32\DUSMTASK.EXE ### DUSM Task Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*%SystemRoot%\System32\dusmtask.exe Description: 0 Parameters: 0 [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\Windows\EnterpriseMgmt\MDMMaintenenceTask=C:\WINDOWS\SYSTEM32\MDMAGENT.EXE ### MDMAgent Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1023 !$*%windir%\system32\MDMAgent.exe Description: 0 Parameters: 0 [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\Windows\Feedback\Siuf\DmClient=C:\WINDOWS\SYSTEM32\DMCLIENT.EXE ### Microsoft Feedback SIUF Deployment Manager Client Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.746 !$*%windir%\system32\dmclient.exe Description: $(@%systemRoot%\system32\dmclient.exe,-202) Parameters: 0 [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\Windows\Feedback\Siuf\DmClientOnScenarioDownload=C:\WINDOWS\SYSTEM32\DMCLIENT.EXE ### Microsoft Feedback SIUF Deployment Manager Client Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.746 !$*%windir%\system32\dmclient.exe Description: $(@%systemRoot%\system32\dmclient.exe,-202) Parameters: utcwnf [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\Windows\HelloFace\FODCleanupTask=C:\WINDOWS\SYSTEM32\WINBIOPLUGINS\FACEFODUNINSTALLER.EXE ### !$*%WinDir%\System32\WinBioPlugIns\FaceFodUninstaller.exe Description: 0 Parameters: 0 [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\Windows\Location\Notifications=C:\WINDOWS\SYSTEM32\LOCATIONNOTIFICATIONWINDOWS.EXE ### Notification d'emplacement Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 ->LOCATIONNOTIFICATION !$*%windir%\System32\LocationNotificationWindows.exe Description: $(@%systemRoot%\system32\LocationNotificationWindo Parameters: 0 [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\Windows\Location\WindowsActionDialog=C:\WINDOWS\SYSTEM32\WINDOWSACTIONDIALOG.EXE ### Service Broker pour la boîte de dialogue Action Windows Microsoft Corporation Système d'exploitation Microsoft® Windows® 10.0.19041.867 !$*%windir%\System32\WindowsActionDialog.exe Description: $(@%systemRoot%\System32\WindowsActionDialog.exe,- Parameters: 0 [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\Windows\Management\Provisioning\Cellular=C:\WINDOWS\SYSTEM32\PROVTOOL.EXE ### Provisioning package runtime processing tool Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.844 !$*%windir%\system32\ProvTool.exe Description: 0 Parameters: /turn 7 /source CellStateChangeTask [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\Windows\Management\Provisioning\Logon=C:\WINDOWS\SYSTEM32\PROVTOOL.EXE ### Provisioning package runtime processing tool Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.844 !$*%windir%\system32\ProvTool.exe Description: 0 Parameters: /turn 5 /source LogonIdleTask [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\Windows\Management\Provisioning\Retry=C:\WINDOWS\SYSTEM32\PROVTOOL.EXE ### Provisioning package runtime processing tool Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.844 !$*%windir%\system32\ProvTool.exe Status: Disabled Description: 0 Parameters: /turn 5 /source ProvRetryTask [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\Windows\Management\Provisioning\RunOnReboot=C:\WINDOWS\SYSTEM32\PROVTOOL.EXE ### Provisioning package runtime processing tool Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.844 !$*%windir%\system32\ProvTool.exe Status: Disabled Description: 0 Parameters: /turn 5 /source ContinueSessionTask [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser=C:\WINDOWS\System32\MBAEPARSERTASK.EXE ### Tâche de l’analyseur d’expérience de compte haut débit mobile Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 ->MBAE PARSER TASK !$*%SystemRoot%\System32\MbaeParserTask.exe Description: $(@%SystemRoot%\system32\MbaeParserTask.exe,-1903) Parameters: 0 [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\Windows\MUI\LPRemove=C:\WINDOWS\SYSTEM32\LPREMOVE.EXE ### MUI Language pack cleanup Microsoft Corporation Système d'exploitation Microsoft® Windows® 10.0.19041.867 !$*%windir%\system32\lpremove.exe Description: $(@%systemRoot%\System32\lpremove.exe,-101) Parameters: 0 [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\Windows\NetTrace\GatherNetworkInfo=C:\WINDOWS\SYSTEM32\GATHERNETWORKINFO.VBS ### !$*%windir%\system32\gatherNetworkInfo.vbs Description: $(@%SystemRoot%\system32\nettrace.dll,-6912) Parameters: 0 [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\Windows\NlaSvc\WiFiTask=C:\WINDOWS\System32\WIFITASK.EXE ### Tâche sans fil en arrière-plan Microsoft Corporation Système d'exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\WiFiTask.exe Description: $(@%SystemRoot%\system32\wifitask.exe,-2) Parameters: nla [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\Windows\Plug and Play\Sysprep Generalize Drivers=C:\WINDOWS\System32\DRVINST.EXE ### Driver Installation Module Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1023 !$*%SystemRoot%\System32\drvinst.exe Description: $(@%SystemRoot%\System32\sppnp.dll,-2001) Parameters: 6 [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\Windows\Printing\EduPrintProv=C:\WINDOWS\SYSTEM32\EDUPRINTPROV.EXE ### Printer Provision Utility for EDU Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*%windir%\system32\eduprintprov.exe Description: 0 Parameters: 0 [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\Windows\PushToInstall\LoginCheck=C:\WINDOWS\SYSTEM32\SC.EXE ### Outil de configuration du Gestionnaire de contrôle des services Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%windir%\system32\sc.exe Status: Disabled Description: 0 Parameters: start pushtoinstall login [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\Windows\PushToInstall\Registration=C:\WINDOWS\SYSTEM32\SC.EXE ### Outil de configuration du Gestionnaire de contrôle des services Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%windir%\system32\sc.exe Description: 0 Parameters: start pushtoinstall registration [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\Windows\RemoteAssistance\RemoteAssistanceTask=C:\WINDOWS\SYSTEM32\RASERVER.EXE ### Serveur COM d’assistance à distance Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%windir%\system32\RAServer.exe Description: $(@%systemroot%\system32\msra.exe,-688) Parameters: /offerraupdate [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\Windows\Setup\SnapshotCleanupTask=C:\WINDOWS\SYSTEM32\OOBE\SETUPPLATFORM\SETUPPLATFORM.EXE ### SetupPlatform module Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1022 !$*C:\Windows\System32\OOBE\SetupPlatform\SetupPlatform.exe Description: 0 Parameters: -removesnapshot [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\Windows\SharedPC\Account Cleanup=C:\WINDOWS\SYSTEM32\WINDOWS.SHAREDPC.ACCOUNTMANAGER.DLL ### SharedPC.AccountManager Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.789 ->SHAREDPC.ACCOUNTMANAGER =>SHAREDPC.ACCOUNTMANAGER.DLL !$*%windir%\System32\rundll32.exe %windir%\System32\Windows.SharedPC.AccountManager.dll,StartMaintenance Status: Disabled Description: 0 Parameters: %windir%\System32\Windows.SharedPC.AccountManager.dll,StartMaintenance [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\Windows\Shell\FamilySafetyMonitor=C:\WINDOWS\SYSTEM32\WPCMON.EXE ### Moniteur du contrôle parental Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%windir%\System32\wpcmon.exe Description: $(@%SystemRoot%\System32\wpcmon.exe,-32015) Parameters: 0 [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\Windows\SMB\UninstallSMB1ClientTask=C:\WINDOWS\SYSTEM32\WINDOWSPOWERSHELL\V1.0\MODULES\SMBSHARE\DISABLEUNUSEDSMB1.PS1 ### !$*%windir%\system32\WindowsPowerShell\v1.0\powershell.exe -ExecutionPolicy Unrestricted -NonInteractive -NoProfile -WindowStyle Hidden "& %windir%\system32\WindowsPowerShell\v1.0\Modules\SmbShare\DisableUnusedSmb1.ps1 -Scenario Client" Description: 0 Parameters: -ExecutionPolicy Unrestricted -NonInteractive -NoProfile -WindowStyle Hidden "& %windir%\system32\WindowsPowerShell\v1.0\Modules\SmbShare\DisableUnusedSmb1.ps1 -Scenario Client" [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\Windows\SMB\UninstallSMB1ServerTask=C:\WINDOWS\SYSTEM32\WINDOWSPOWERSHELL\V1.0\MODULES\SMBSHARE\DISABLEUNUSEDSMB1.PS1 ### !$*%windir%\system32\WindowsPowerShell\v1.0\powershell.exe -ExecutionPolicy Unrestricted -NonInteractive -NoProfile -WindowStyle Hidden "& %windir%\system32\WindowsPowerShell\v1.0\Modules\SmbShare\DisableUnusedSmb1.ps1 -Scenario Server" Description: 0 Parameters: -ExecutionPolicy Unrestricted -NonInteractive -NoProfile -WindowStyle Hidden "& %windir%\system32\WindowsPowerShell\v1.0\Modules\SmbShare\DisableUnusedSmb1.ps1 -Scenario Server" [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\Windows\SpacePort\SpaceAgentTask=C:\WINDOWS\SYSTEM32\SPACEAGENT.EXE ### Paramètres des espaces de stockage Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%windir%\system32\SpaceAgent.exe Description: $(@%SystemRoot%\system32\SpaceAgent.exe,-3) Parameters: 0 [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\Windows\SpacePort\SpaceManagerTask=C:\WINDOWS\SYSTEM32\SPACEMAN.EXE ### Storage Spaces Manager Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.867 !$*%windir%\system32\spaceman.exe Description: $(@%SystemRoot%\system32\spaceman.exe,-3) Parameters: /Work [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\Windows\Speech\SpeechModelDownloadTask=C:\WINDOWS\SYSTEM32\SPEECH_ONECORE\COMMON\SPEECHMODELDOWNLOAD.EXE ### Speech Model Download Executable Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1023 ->SPEECH MODEL DOWNLOAD EXECUTABLE !$*%windir%\system32\speech_onecore\common\SpeechModelDownload.exe Description: 0 Parameters: 0 [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\Windows\StateRepository\MaintenanceTasks=C:\WINDOWS\SYSTEM32\WINDOWS.STATEREPOSITORYCLIENT.DLL ### Windows StateRepository Client API Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.844 ->WINDOWS STATEREPOSITORY CLIENT API !$*%windir%\system32\rundll32.exe %windir%\system32\Windows.StateRepositoryClient.dll,StateRepositoryDoMaintenanceTasks Description: $(@%SystemRoot%\system32\Windows.StateRepositoryCl Parameters: %windir%\system32\Windows.StateRepositoryClient.dll,StateRepositoryDoMaintenanceTasks [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\Windows\Storage Tiers Management\Storage Tiers Optimization=C:\WINDOWS\SYSTEM32\DEFRAG.EXE ### Module de défragmenteur de disque Microsoft Corp. Optimiseur de lecteur Windows 10.0.19041.867 !$*%windir%\system32\defrag.exe Status: Disabled Description: $(@%systemroot%\system32\TieringEngineService.exe, Parameters: -c -h -g -# -m 8 -i 13500 [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\Windows\Subscription\EnableLicenseAcquisition=C:\WINDOWS\System32\CLIPRENEW.EXE ### Acquire License From Store Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 ->ACQUIRE LICENSE FROM STORE !$*%SystemRoot%\system32\ClipRenew.exe Description: $(@%SystemRoot%\system32\ClipRenew.exe,-101) Parameters: -e [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\Windows\Subscription\LicenseAcquisition=C:\WINDOWS\System32\CLIPRENEW.EXE ### Acquire License From Store Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 ->ACQUIRE LICENSE FROM STORE !$*%SystemRoot%\system32\ClipRenew.exe Status: Disabled Description: $(@%SystemRoot%\system32\ClipRenew.exe,-102) Parameters: 0 [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\Windows\Sysmain\WsSwapAssessmentTask=C:\WINDOWS\SYSTEM32\SYSMAIN.DLL ### Hôte de Service SysMain Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%windir%\system32\rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask Description: $(@%systemRoot%\System32\sysmain.dll,-3001) Parameters: sysmain.dll,PfSvWsSwapAssessmentTask [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\Windows\SystemRestore\SR=C:\WINDOWS\SYSTEM32\SRTASKS.EXE ### Tâches de fond de la protection du système Microsoft® Windows. Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%windir%\system32\srtasks.exe Description: $(@%systemroot%\system32\srrstr.dll,-322) Parameters: ExecuteScheduledSPPCreation [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\Windows\Time Synchronization\SynchronizeTime=C:\WINDOWS\SYSTEM32\SC.EXE ### Outil de configuration du Gestionnaire de contrôle des services Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%windir%\system32\sc.exe Description: $(@%systemroot%\system32\w32time.dll,-201) Parameters: start w32time task_started [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\Windows\Time Zone\SynchronizeTimeZone=C:\WINDOWS\SYSTEM32\TZSYNC.EXE ### TimeZone Sync Task Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*%windir%\system32\tzsync.exe Description: $(@%SystemRoot%\system32\tzsyncres.dll,-102) Parameters: 0 [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\Windows\UNP\RunUpdateNotificationMgr=C:\WINDOWS\SYSTEM32\UNP\UPDATENOTIFICATIONMGR.EXE ### Update Notification Pipeline Manager Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.746 !$*%windir%\System32\UNP\UpdateNotificationMgr.exe Status: Disabled Description: 0 Parameters: 0 [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\Windows\UpdateOrchestrator\Reboot_AC=C:\WINDOWS\System32\MUSNOTIFICATION.EXE ### MusNotificationBroker Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1023 ->MUSNOTIFICATIONBROKER !$*%systemroot%\system32\MusNotification.exe Status: Disabled Description: 0 Parameters: /RunOnAC RebootDialog [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\Windows\UpdateOrchestrator\Reboot_Battery=C:\WINDOWS\System32\MUSNOTIFICATION.EXE ### MusNotificationBroker Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1023 ->MUSNOTIFICATIONBROKER !$*%systemroot%\system32\MusNotification.exe Status: Disabled Description: 0 Parameters: /RunOnBattery RebootDialog [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\Windows\UpdateOrchestrator\Report policies=C:\WINDOWS\System32\USOCLIENT.EXE ### UsoClient Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.906 !$*%systemroot%\system32\usoclient.exe Description: 0 Parameters: ReportPolicies [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\Windows\UpdateOrchestrator\Schedule Maintenance Work=C:\WINDOWS\System32\USOCLIENT.EXE ### UsoClient Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.906 !$*%systemroot%\system32\usoclient.exe Status: Disabled Description: 0 Parameters: StartMaintenanceWork [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\Windows\UpdateOrchestrator\Schedule Scan=C:\WINDOWS\System32\USOCLIENT.EXE ### UsoClient Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.906 !$*%systemroot%\system32\usoclient.exe Description: 0 Parameters: StartScan [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\Windows\UpdateOrchestrator\Schedule Scan Static Task=C:\WINDOWS\System32\USOCLIENT.EXE ### UsoClient Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.906 !$*%systemroot%\system32\usoclient.exe Description: $(@%systemRoot%\system32\usosvc.dll,-105) Parameters: StartScan [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\Windows\UpdateOrchestrator\Schedule Wake To Work=C:\WINDOWS\System32\USOCLIENT.EXE ### UsoClient Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.906 !$*%systemroot%\system32\usoclient.exe Status: Disabled Description: 0 Parameters: StartWork [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\Windows\UpdateOrchestrator\Schedule Work=C:\WINDOWS\System32\USOCLIENT.EXE ### UsoClient Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.906 !$*%systemroot%\system32\usoclient.exe Status: Disabled Description: 0 Parameters: StartWork [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\Windows\UpdateOrchestrator\UpdateModelTask=C:\WINDOWS\System32\USOCLIENT.EXE ### UsoClient Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.906 !$*%systemroot%\system32\usoclient.exe Description: $(@%systemRoot%\system32\usosvc.dll,-108) Parameters: StartModelUpdates [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker=C:\WINDOWS\System32\MUSNOTIFICATION.EXE ### MusNotificationBroker Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1023 ->MUSNOTIFICATIONBROKER !$*%systemroot%\system32\MusNotification.exe Description: $(@%systemRoot%\system32\usosvc.dll,-106) Parameters: 0 [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\Windows\UPnP\UPnPHostConfig=C:\WINDOWS\SYSTEM32\SC.EXE ### Outil de configuration du Gestionnaire de contrôle des services Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*sc.exe Description: $(@%systemroot%\system32\upnphost.dll,-216) Parameters: config upnphost start= auto [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\Windows\WCM\WiFiTask=C:\WINDOWS\System32\WIFITASK.EXE ### Tâche sans fil en arrière-plan Microsoft Corporation Système d'exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\WiFiTask.exe Description: $(@%SystemRoot%\system32\wifitask.exe,-2) Parameters: 0 [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance=C:\PROGRAMDATA\MICROSOFT\WINDOWS DEFENDER\PLATFORM\4.18.2105.5-0\MPCMDRUN.EXE ### Microsoft Malware Protection Command Line Utility Microsoft Corporation Microsoft® Windows® Operating System 4.18.2105.5 !$*C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2105.5-0\MpCmdRun.exe Description: Tâche de maintenance périodique. Parameters: -IdleTask -TaskName WdCacheMaintenance [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\Windows\Windows Defender\Windows Defender Cleanup=C:\PROGRAMDATA\MICROSOFT\WINDOWS DEFENDER\PLATFORM\4.18.2105.5-0\MPCMDRUN.EXE ### Microsoft Malware Protection Command Line Utility Microsoft Corporation Microsoft® Windows® Operating System 4.18.2105.5 !$*C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2105.5-0\MpCmdRun.exe Description: Tâche de nettoyage périodique. Parameters: -IdleTask -TaskName WdCleanup [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan=C:\PROGRAMDATA\MICROSOFT\WINDOWS DEFENDER\PLATFORM\4.18.2105.5-0\MPCMDRUN.EXE ### Microsoft Malware Protection Command Line Utility Microsoft Corporation Microsoft® Windows® Operating System 4.18.2105.5 !$*C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2105.5-0\MpCmdRun.exe Description: Tâche d’analyse périodique. Parameters: Scan -ScheduleJob -ScanTrigger 55 -IdleScheduledJob [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\Windows\Windows Defender\Windows Defender Verification=C:\PROGRAMDATA\MICROSOFT\WINDOWS DEFENDER\PLATFORM\4.18.2105.5-0\MPCMDRUN.EXE ### Microsoft Malware Protection Command Line Utility Microsoft Corporation Microsoft® Windows® Operating System 4.18.2105.5 !$*C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2105.5-0\MpCmdRun.exe Description: Tâche de vérification périodique. Parameters: -IdleTask -TaskName WdVerification [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\Windows\Windows Error Reporting\QueueReporting=C:\WINDOWS\SYSTEM32\WERMGR.EXE ### Windows Problem Reporting Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1023 !$*%windir%\system32\wermgr.exe Description: $(@%SystemRoot%\system32\wer.dll,-294) Parameters: -upload [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\Windows\Windows Filtering Platform\BfeOnServiceStartTypeChange=C:\WINDOWS\SYSTEM32\BFE.DLL ### Moteur de filtrage de base Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*%windir%\system32\rundll32.exe bfe.dll,BfeOnServiceStartTypeChange Description: $(@%SystemRoot%\system32\bfe.dll,-2002) Parameters: bfe.dll,BfeOnServiceStartTypeChange [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\Windows\Windows Media Sharing\UpdateLibrary=C:\Program Files\WINDOWS MEDIA PLAYER\WMPNSCFG.EXE ### Application de configuration du service Partage réseau du Lecteur Windows Media Microsoft Corporation Système d’exploitation Microsoft® Windows® 12.0.19041.1 !$*"%ProgramFiles%\Windows Media Player\wmpnscfg.exe" Description: $(@%ProgramFiles%\Windows Media Player\wmpnscfg.ex Parameters: 0 [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\Windows\WindowsUpdate\Scheduled Start=C:\WINDOWS\SYSTEM32\SC.EXE ### Outil de configuration du Gestionnaire de contrôle des services Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\sc.exe Description: Cette tâche permet de démarrer le service Windows Parameters: start wuauserv [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\Windows\Workplace Join\Automatic-Device-Join=C:\WINDOWS\System32\DSREGCMD.EXE ### Outil de ligne de commande DSREG Microsoft Corporation Système d'exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\dsregcmd.exe Status: Disabled Description: $(@%SystemRoot%\system32\dsregcmd.exe,-101) Parameters: $(Arg0) $(Arg1) $(Arg2) [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\Windows\Workplace Join\Recovery-Check=C:\WINDOWS\System32\DSREGCMD.EXE ### Outil de ligne de commande DSREG Microsoft Corporation Système d'exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\dsregcmd.exe Status: Disabled Description: $(@%SystemRoot%\system32\dsregcmd.exe,-102) Parameters: /checkrecovery [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\Windows\WwanSvc\NotificationTask=C:\WINDOWS\System32\WIFITASK.EXE ### Tâche sans fil en arrière-plan Microsoft Corporation Système d'exploitation Microsoft® Windows® 10.0.19041.867 !$*%SystemRoot%\System32\WiFiTask.exe Description: $(@%SystemRoot%\system32\wifitask.exe,-2) Parameters: wwan [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Microsoft\XblGameSave\XblGameSaveTask=C:\WINDOWS\SYSTEM32\XBLGAMESAVETASK.EXE ### XblGameSave Standby Task Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.264 ->XBLGAMESAVE STANDBY TASK !$*%windir%\System32\XblGameSaveTask.exe Description: XblGameSave Standby Task Parameters: standby [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\MicrosoftEdgeUpdateTaskMachineCore1d72055f9b4a414=C:\PROGRAM FILES (X86)\MICROSOFT\EDGEUPDATE\MICROSOFTEDGEUPDATE.EXE ### Microsoft Edge Update Microsoft Corporation Microsoft Edge Update 1.3.135.29 ->MICROSOFT EDGE UPDATE =>MSEDGEUPDATE.DLL !$*C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe Description: Maintient votre logiciel Microsoft à jour. Si cett Parameters: /c [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\MicrosoftEdgeUpdateTaskMachineUA=C:\PROGRAM FILES (X86)\MICROSOFT\EDGEUPDATE\MICROSOFTEDGEUPDATE.EXE ### Microsoft Edge Update Microsoft Corporation Microsoft Edge Update 1.3.135.29 ->MICROSOFT EDGE UPDATE =>MSEDGEUPDATE.DLL !$*C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe Description: Maintient votre logiciel Microsoft à jour. Si cett Parameters: /ua /installsource scheduler [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\MSIAfterburner=D:\PROGRAM FILES (X86)\MSI AFTERBURNER\MSIAFTERBURNER.EXE ### MSIAfterburner MSIAfterburner 4, 6, 3, 16094 !$*D:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe Description: 0 Parameters: /s [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}=C:\PROGRAM FILES\NVIDIA CORPORATION\NVCONTAINER\NVCONTAINER.EXE ### NVIDIA Container NVIDIA Corporation NVIDIA Container gcomp_dev 28356155 !$*C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe Description: Enables BatteryBoost on supported systems before G Parameters: -d "C:\Program Files\NVIDIA Corporation\NvBackend\NvBatteryBoostCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerBatteryBoostCheck.log [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}=C:\PROGRAM FILES\NVIDIA CORPORATION\NVCONTAINER\NVCONTAINER.EXE ### NVIDIA Container NVIDIA Corporation NVIDIA Container gcomp_dev 28356155 !$*C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe Description: Checks for NVIDIA driver updates before GeForce Ex Parameters: -d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}=C:\PROGRAM FILES\NVIDIA CORPORATION\NVIDIA GEFORCE EXPERIENCE\NVIDIA GEFORCE EXPERIENCE.EXE ### NVIDIA GeForce Experience NVIDIA Corporation NVIDIA GeForce Experience rel_03_22/c97700a !$*"C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe" Description: 0 Parameters: 0 [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}=C:\PROGRAM FILES (X86)\NVIDIA CORPORATION\NVNODE\NVNODEJSLAUNCHER.EXE ### NVIDIA nodejs launcher NVIDIA Corporation NVIDIA GeForce Experience 3.22.0.32 ->NVIDIA NODEJS LAUNCHER !$*C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe Description: NVIDIA NvNode Launcher Parameters: --launcher=TaskScheduler [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}=C:\PROGRAM FILES\NVIDIA CORPORATION\UPDATE CORE\NVPROFILEUPDATER64.EXE ### NVIDIA driver profile updater NVIDIA Corporation NVIDIA driver profile updater 38.0.7.0 ->NVIDIA DRIVER PROFILE UPDATER =>NVPROFILEUPDATER.EXE !$*C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe Description: NVIDIA Profile Updater Parameters: 0 [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}=C:\PROGRAM FILES\NVIDIA CORPORATION\UPDATE CORE\NVPROFILEUPDATER64.EXE ### NVIDIA driver profile updater NVIDIA Corporation NVIDIA driver profile updater 38.0.7.0 ->NVIDIA DRIVER PROFILE UPDATER =>NVPROFILEUPDATER.EXE !$*C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe Description: NVIDIA Profile Updater Parameters: 0 [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}=C:\PROGRAM FILES\NVIDIA CORPORATION\NVBACKEND\NVTMREP.EXE ### NVIDIA crash and telemetry reporter NVIDIA Corporation NVIDIA crash and telemetry reporter 38.0.7.0 ->NVIDIA CRASH AND TELEMETRY REPORTER !$*C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe Description: NVIDIA crash reporter Parameters: 0 [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}=C:\PROGRAM FILES\NVIDIA CORPORATION\NVBACKEND\NVTMREP.EXE ### NVIDIA crash and telemetry reporter NVIDIA Corporation NVIDIA crash and telemetry reporter 38.0.7.0 ->NVIDIA CRASH AND TELEMETRY REPORTER !$*C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe Description: NVIDIA crash reporter Parameters: 0 [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}=C:\PROGRAM FILES\NVIDIA CORPORATION\NVBACKEND\NVTMREP.EXE ### NVIDIA crash and telemetry reporter NVIDIA Corporation NVIDIA crash and telemetry reporter 38.0.7.0 ->NVIDIA CRASH AND TELEMETRY REPORTER !$*C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe Description: NVIDIA crash reporter Parameters: 0 [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}=C:\PROGRAM FILES\NVIDIA CORPORATION\NVBACKEND\NVTMREP.EXE ### NVIDIA crash and telemetry reporter NVIDIA Corporation NVIDIA crash and telemetry reporter 38.0.7.0 ->NVIDIA CRASH AND TELEMETRY REPORTER !$*C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe Description: NVIDIA crash reporter Parameters: 0 [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\OneDrive Standalone Update Task-S-1-5-21-1038550290-3477332594-2832121129-500=C:\Users\user\AppData\Local\MICROSOFT\ONEDRIVE\ONEDRIVESTANDALONEUPDATER.EXE ### Standalone Updater Microsoft Corporation Microsoft OneDrive 21.030.0211.0002 !$*%localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe Description: 0 [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\Optimize Thumbnail Cache=C:\PROGRAM FILES (X86)\COMMON FILES\INSTALLSHIELD\ENGINE\8\INTEL 32\ISUPDATE.EXE ### InstallShield® Application Updater InstallShield® 23.1.3.16 !$*"C:\Program Files (x86)\Common Files\installshield\engine\8\intel 32\isupdate.exe" Description: 0 Parameters: 0 [Scheduled Tasks 2] C:\WINDOWS\SYSNATIVE\TASKS\User_Feed_Synchronization-{534CE546-81E7-41D2-8944-29001CF015EB}=C:\WINDOWS\SYSTEM32\MSFEEDSSYNC.EXE ### Microsoft Feeds Synchronization Microsoft Corporation Internet Explorer 11.00.19041.1 !$*C:\WINDOWS\system32\msfeedssync.exe Description: Met à jour les flux système obsolètes. Parameters: sync [Scheduled Tasks 2.0 Cached] :HKLM CCleaner Update=I:\ccleaner\CCUpdate.exe ### File is missing. !$*I:\ccleaner\CCUpdate.exe [Scheduled Tasks 2.0 Cached] :HKLM CCleanerSkipUAC="I:\ccleaner\CCleaner.exe" ### File is missing. !$*"I:\ccleaner\CCleaner.exe" Parameters: $(Arg0) [Scheduled Tasks 2.0 Cached] :HKLM InstallShield® Setup Engine Kernel=C:\PROGRAM FILES (X86)\COMMON FILES\INSTALLSHIELD\ENGINE\8\INTEL 32\IKERNEL.EXE ### InstallShield (R) Setup Engine InstallShield Software Corporation InstallShield (R) 6, 31 ->KERNEL !$*"C:\Program Files (x86)\Common Files\installshield\engine\8\intel 32\iKernel.exe" [Scheduled Tasks 2.0 Cached] :HKLM MicrosoftEdgeUpdateTaskMachineCore1d72055f9b4a414=C:\PROGRAM FILES (X86)\MICROSOFT\EDGEUPDATE\MICROSOFTEDGEUPDATE.EXE ### Microsoft Edge Update Microsoft Corporation Microsoft Edge Update 1.3.135.29 ->MICROSOFT EDGE UPDATE =>MSEDGEUPDATE.DLL !$*C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe Maintient votre logiciel Microsoft à jour. Si cette tâche est désactivée ou arrêtée, votre logiciel Microsoft n'est pas mis à jour, ce qui signifie que les potentielles failles de sécurité peuvent ne pas être corrigées et que certaines fonctionnalités risquent de ne pas être opérationnelles. Cette tâche se désinstalle d'elle-même si aucun logiciel Microsoft ne l'utilise. Parameters: /c [Scheduled Tasks 2.0 Cached] :HKLM MicrosoftEdgeUpdateTaskMachineUA=C:\PROGRAM FILES (X86)\MICROSOFT\EDGEUPDATE\MICROSOFTEDGEUPDATE.EXE ### Microsoft Edge Update Microsoft Corporation Microsoft Edge Update 1.3.135.29 ->MICROSOFT EDGE UPDATE =>MSEDGEUPDATE.DLL !$*C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe Maintient votre logiciel Microsoft à jour. Si cette tâche est désactivée ou arrêtée, votre logiciel Microsoft n'est pas mis à jour, ce qui signifie que les potentielles failles de sécurité peuvent ne pas être corrigées et que certaines fonctionnalités risquent de ne pas être opérationnelles. Cette tâche se désinstalle d'elle-même si aucun logiciel Microsoft ne l'utilise. Parameters: /ua /installsource scheduler [Scheduled Tasks 2.0 Cached] :HKLM MSIAfterburner=D:\PROGRAM FILES (X86)\MSI AFTERBURNER\MSIAFTERBURNER.EXE ### MSIAfterburner MSIAfterburner 4, 6, 3, 16094 !$*D:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe Parameters: /s [Scheduled Tasks 2.0 Cached] :HKLM NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}=C:\PROGRAM FILES\NVIDIA CORPORATION\NVCONTAINER\NVCONTAINER.EXE ### NVIDIA Container NVIDIA Corporation NVIDIA Container gcomp_dev 28356155 !$*C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe Enables BatteryBoost on supported systems before GeForce Experience is first launched Parameters: -d "C:\Program Files\NVIDIA Corporation\NvBackend\NvBatteryBoostCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerBatteryBoostCheck.log [Scheduled Tasks 2.0 Cached] :HKLM NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}=C:\PROGRAM FILES\NVIDIA CORPORATION\NVCONTAINER\NVCONTAINER.EXE ### NVIDIA Container NVIDIA Corporation NVIDIA Container gcomp_dev 28356155 !$*C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe Checks for NVIDIA driver updates before GeForce Experience is first launched Parameters: -d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log [Scheduled Tasks 2.0 Cached] :HKLM NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}=C:\PROGRAM FILES\NVIDIA CORPORATION\NVIDIA GEFORCE EXPERIENCE\NVIDIA GEFORCE EXPERIENCE.EXE ### NVIDIA GeForce Experience NVIDIA Corporation NVIDIA GeForce Experience rel_03_22/c97700a !$*"C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe" [Scheduled Tasks 2.0 Cached] :HKLM NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}=C:\PROGRAM FILES (X86)\NVIDIA CORPORATION\NVNODE\NVNODEJSLAUNCHER.EXE ### NVIDIA nodejs launcher NVIDIA Corporation NVIDIA GeForce Experience 3.22.0.32 ->NVIDIA NODEJS LAUNCHER !$*C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe NVIDIA NvNode Launcher Parameters: --launcher=TaskScheduler [Scheduled Tasks 2.0 Cached] :HKLM NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}=C:\PROGRAM FILES\NVIDIA CORPORATION\UPDATE CORE\NVPROFILEUPDATER64.EXE ### NVIDIA driver profile updater NVIDIA Corporation NVIDIA driver profile updater 38.0.7.0 ->NVIDIA DRIVER PROFILE UPDATER =>NVPROFILEUPDATER.EXE !$*C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe NVIDIA Profile Updater [Scheduled Tasks 2.0 Cached] :HKLM NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}=C:\PROGRAM FILES\NVIDIA CORPORATION\UPDATE CORE\NVPROFILEUPDATER64.EXE ### NVIDIA driver profile updater NVIDIA Corporation NVIDIA driver profile updater 38.0.7.0 ->NVIDIA DRIVER PROFILE UPDATER =>NVPROFILEUPDATER.EXE !$*C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe NVIDIA Profile Updater [Scheduled Tasks 2.0 Cached] :HKLM NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}=C:\PROGRAM FILES\NVIDIA CORPORATION\NVBACKEND\NVTMREP.EXE ### NVIDIA crash and telemetry reporter NVIDIA Corporation NVIDIA crash and telemetry reporter 38.0.7.0 ->NVIDIA CRASH AND TELEMETRY REPORTER !$*C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe NVIDIA crash reporter [Scheduled Tasks 2.0 Cached] :HKLM NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}=C:\PROGRAM FILES\NVIDIA CORPORATION\NVBACKEND\NVTMREP.EXE ### NVIDIA crash and telemetry reporter NVIDIA Corporation NVIDIA crash and telemetry reporter 38.0.7.0 ->NVIDIA CRASH AND TELEMETRY REPORTER !$*C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe NVIDIA crash reporter [Scheduled Tasks 2.0 Cached] :HKLM NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}=C:\PROGRAM FILES\NVIDIA CORPORATION\NVBACKEND\NVTMREP.EXE ### NVIDIA crash and telemetry reporter NVIDIA Corporation NVIDIA crash and telemetry reporter 38.0.7.0 ->NVIDIA CRASH AND TELEMETRY REPORTER !$*C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe NVIDIA crash reporter [Scheduled Tasks 2.0 Cached] :HKLM NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}=C:\PROGRAM FILES\NVIDIA CORPORATION\NVBACKEND\NVTMREP.EXE ### NVIDIA crash and telemetry reporter NVIDIA Corporation NVIDIA crash and telemetry reporter 38.0.7.0 ->NVIDIA CRASH AND TELEMETRY REPORTER !$*C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe NVIDIA crash reporter [Scheduled Tasks 2.0 Cached] :HKLM Optimize Thumbnail Cache=C:\PROGRAM FILES (X86)\COMMON FILES\INSTALLSHIELD\ENGINE\8\INTEL 32\ISUPDATE.EXE ### InstallShield® Application Updater InstallShield® 23.1.3.16 !$*"C:\Program Files (x86)\Common Files\installshield\engine\8\intel 32\isupdate.exe" [Scheduled Tasks 2.0 Cached] :HKLM User_Feed_Synchronization-{534CE546-81E7-41D2-8944-29001CF015EB}=C:\WINDOWS\SYSTEM32\MSFEEDSSYNC.EXE ### Microsoft Feeds Synchronization Microsoft Corporation Internet Explorer 11.00.19041.1 !$*C:\WINDOWS\system32\msfeedssync.exe Met à jour les flux système obsolètes. Parameters: sync [Unwanted Software Files] :HKLM Hotspot Shield=C:\PROGRAM FILES (X86)\HOTSPOT SHIELD\ [Unwanted Software Files] :HKLM Hotspot Shield=C:\PROGRAMDATA\HOTSPOT SHIELD\ [Detected using Heuristic Algorithm] :HKLM COMMON FILES=C:\PROGRAM FILES (X86)\COMMON FILES\ ### "ADOBE\" "BATTLEYE\" "INSTALLSHIELD\" "INTEL\" "JAVA\" "MICROSOFT SHARED\" "ORACLE\" "SERVICES\" "STEAM\" "SYSTEM\" [Detected using Heuristic Algorithm] :HKLM INTEL=C:\PROGRAM FILES (X86)\COMMON FILES\INTEL\ ### "OPENCL\" "OpenCL: LLVM_RELEASE_LICENSE.TXT" "README.TXT" "VERSION.INI" "OpenCL\bin\common: CLBLTFNSHARED.RTL" "OpenCL\bin\x64: CLANG_COMPILER64.DLL" "CLBLTFNE9.RTL" "CLBLTFNE9_IMG_CBK.O" "CLBLTFNE9_IMG_CBK.RTL" "CLBLTFNH8.RTL" "CLBLTFNH8_IMG_CBK.O" "CLBL [Detected using Heuristic Algorithm] :HKLM MICROSOFT SHARED=C:\PROGRAM FILES (X86)\COMMON FILES\MICROSOFT SHARED\ ### "DAO\" "FILTERS\" "INK\" "MSINFO\" "STATIONERY\" "TEXTCONV\" "TRIEDIT\" "VC\" "VGX\" "DAO: DAO360.DLL" "Filters: TIFFFILT.DLL" [Detected using Heuristic Algorithm] :HKLM STEAM=C:\PROGRAM FILES (X86)\COMMON FILES\STEAM\ ### "DRIVERS\" "DRIVERS.EXE" "SECURE_DESKTOP_CAPTURE.EXE" "SERVICE_DEFAULT_PUBLIC_VERSIONS.VDF" "SERVICE_LOG.TXT" "SERVICE_MINIMUM_VERSIONS.VDF" "STEAMSERVICE.DLL" "STEAMSERVICE.EXE" "STEAMXBOXUTIL64.EXE" "drivers\Windows10\x64: STEAMSTREAMINGMICROPHONE.CAT" " [Detected using Heuristic Algorithm] :HKLM MICROSOFT=C:\PROGRAM FILES (X86)\MICROSOFT\ ### "EDGE\" "EDGECORE\" "EDGEUPDATE\" "EDGEWEBVIEW\" "TEMP\" "Edge: EDGE.DAT" "EDGE.DAT.LOG1" "EDGE.DAT.LOG2" "EdgeCore\91.0.864.48: 91.0.864.48.MANIFEST" "CONCRT140.DLL" "COOKIE_EXPORTER.EXE" "D3DCOMPILER_47.DLL" "EdgeUpdate: MICROSOFTEDGEUPDATE.EXE" "EdgeU [Detected using Heuristic Algorithm] :HKLM MSBUILD=C:\PROGRAM FILES (X86)\MSBUILD\ ### "MICROSOFT\" "Microsoft\Windows Workflow Foundation\v3.0: WORKFLOW.TARGETS" "WORKFLOW.VISUALBASIC.TARGETS" "Microsoft\Windows Workflow Foundation\v3.5: WORKFLOW.TARGETS" "WORKFLOW.VISUALBASIC.TARGETS" [Detected using Heuristic Algorithm] :HKLM REFERENCE ASSEMBLIES=C:\PROGRAM FILES (X86)\REFERENCE ASSEMBLIES\ ### "MICROSOFT\" "Microsoft\Framework\v3.0: PRESENTATIONBUILDTASKS.DLL" "PRESENTATIONCORE.DLL" "PRESENTATIONFRAMEWORK.AERO.DLL" "PRESENTATIONFRAMEWORK.CLASSIC.DLL" "PRESENTATIONFRAMEWORK.DLL" "PRESENTATIONFRAMEWORK.LUNA.DLL" "PRESENTATIONFRAMEWORK.ROYALE.DLL" [Detected using Heuristic Algorithm] :HKLM WINDOWS DEFENDER=C:\PROGRAM FILES (X86)\WINDOWS DEFENDER\ ### "EN-US\" "EPPMANIFEST.DLL" "FR-FR\" "MPASDESC.DLL" "MPCLIENT.DLL" "MPOAV.DLL" "MSMPLICS.DLL" "en-US: EPPMANIFEST.DLL.MUI" "MPASDESC.DLL.MUI" "fr-FR: EPPMANIFEST.DLL.MUI" "MPASDESC.DLL.MUI" [Detected using Heuristic Algorithm] :HKLM WINDOWS MEDIA PLAYER=C:\PROGRAM FILES (X86)\WINDOWS MEDIA PLAYER\ ### "EN-US\" "FR-FR\" "ICONS\" "MEDIA RENDERER\" "MPVIS.DLL" "NETWORK SHARING\" "SETUP_WM.EXE" "SKINS\" "VISUALIZATIONS\" "WMLAUNCH.EXE" "WMPCONFIG.EXE" [Detected using Heuristic Algorithm] :HKLM WINDOWS PHOTO VIEWER=C:\PROGRAM FILES (X86)\WINDOWS PHOTO VIEWER\ ### "EN-US\" "FR-FR\" "IMAGINGDEVICES.EXE" "IMAGINGENGINE.DLL" "PHOTOACQ.DLL" "PHOTOBASE.DLL" "PHOTOVIEWER.DLL" "en-US: IMAGINGDEVICES.EXE.MUI" "PHOTOACQ.DLL.MUI" "PHOTOVIEWER.DLL.MUI" "fr-FR: IMAGINGDEVICES.EXE.MUI" "PHOTOACQ.DLL.MUI" "PHOTOVIEWER.DLL.MUI" [Detected using Heuristic Algorithm] :HKLM MICROSOFT SHARED=C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\ ### "INK\" "MSINFO\" "STATIONERY\" "TEXTCONV\" "TRIEDIT\" "VC\" "VGX\" "ink: ALPHABET.XML" "CONTENT.XML" "HWRCOMMONLM.DAT" "HWRENCLM.DAT" "MSInfo: MSINFO32.EXE" "MSInfo\en-US: MSINFO32.EXE.MUI" "MSInfo\fr-FR: MSINFO32.EXE.MUI" "VC: MSDIA100.DLL" "MSDIA90.D [Detected using Heuristic Algorithm] :HKLM INTEL=C:\PROGRAM FILES\INTEL\ ### "MEDIA SDK\" "Media SDK: CPA_32.VP" "CPA_64.VP" "C_32.CPA" "C_64.CPA" "DEV_32.VP" "DEV_64.VP" "H265E_32.VP" "H265E_64.VP" "HE_32.VP" "HE_64.VP" [Detected using Heuristic Algorithm] :HKLM MICROSOFT UPDATE HEALTH TOOLS=C:\PROGRAM FILES\MICROSOFT UPDATE HEALTH TOOLS\ ### "EXPEDITEUPDATER.EXE" "LOGS\" "QUALITYUPDATEASSISTANT.DLL" "SEDPLUGINS.DLL" "UHSSVC.EXE" "UNIFIEDINSTALLER.DLL" [Detected using Heuristic Algorithm] :HKLM MSBUILD=C:\PROGRAM FILES\MSBUILD\ ### "MICROSOFT\" "Microsoft\Windows Workflow Foundation\v3.0: WORKFLOW.TARGETS" "WORKFLOW.VISUALBASIC.TARGETS" "Microsoft\Windows Workflow Foundation\v3.5: WORKFLOW.TARGETS" "WORKFLOW.VISUALBASIC.TARGETS" [Detected using Heuristic Algorithm] :HKLM REFERENCE ASSEMBLIES=C:\PROGRAM FILES\REFERENCE ASSEMBLIES\ ### "MICROSOFT\" "Microsoft\Framework\v3.0: PRESENTATIONBUILDTASKS.DLL" "PRESENTATIONCORE.DLL" "PRESENTATIONFRAMEWORK.AERO.DLL" "PRESENTATIONFRAMEWORK.CLASSIC.DLL" "PRESENTATIONFRAMEWORK.DLL" "PRESENTATIONFRAMEWORK.LUNA.DLL" "PRESENTATIONFRAMEWORK.ROYALE.DLL" [Detected using Heuristic Algorithm] :HKLM TEAMVIEWER=C:\PROGRAM FILES\TEAMVIEWER\ ### "COPYRIGHTS.TXT" "LICENSE.TXT" "OUTLOOK\" "PRINTER\" "ROLLOUTFILE.TV13" "TEAMVIEWER.EXE" "TEAMVIEWER15_LOGFILE.LOG" "TEAMVIEWER15_LOGFILE_OLD.LOG" "TEAMVIEWER_DESKTOP.EXE" "TEAMVIEWER_NOTE.EXE" "TEAMVIEWER_RESOURCE_AR.DLL" [Detected using Heuristic Algorithm] :HKLM WINDOWS DEFENDER=C:\PROGRAM FILES\WINDOWS DEFENDER\ ### "AMMONITORINGINSTALL.MOF" "AMMONITORINGPROVIDER.DLL" "AMSTATUSINSTALL.MOF" "CLIENTWMIINSTALL.MOF" "CONFIGSECURITYPOLICY.EXE" "DEFENDERCSP.DLL" "EN-US\" "EPPMANIFEST.DLL" "FEPUNREGISTER.MOF" "FR-FR\" "MPASDESC.DLL" [Detected using Heuristic Algorithm] :HKLM WINDOWS MEDIA PLAYER=C:\PROGRAM FILES\WINDOWS MEDIA PLAYER\ ### "EN-US\" "FR-FR\" "ICONS\" "MEDIA RENDERER\" "MPVIS.DLL" "NETWORK SHARING\" "SETUP_WM.EXE" "SKINS\" "VISUALIZATIONS\" "WMLAUNCH.EXE" "WMPCONFIG.EXE" [Detected using Heuristic Algorithm] :HKLM WINDOWS NT=C:\PROGRAM FILES\WINDOWS NT\ ### "ACCESSOIRES\" "ACCESSORIES\" "TABLETEXTSERVICE\" "Accessoires: WORDPAD.EXE" "WORDPADFILTER.DLL" "Accessoires\en-US: WORDPAD.EXE.MUI" "Accessoires\fr-FR: WORDPAD.EXE.MUI" "Accessories: WORDPAD.EXE" "WORDPADFILTER.DLL" "Accessories\en-US: WORDPAD.EXE.MUI [Detected using Heuristic Algorithm] :HKLM WINDOWS PHOTO VIEWER=C:\PROGRAM FILES\WINDOWS PHOTO VIEWER\ ### "EN-US\" "FR-FR\" "IMAGINGDEVICES.EXE" "IMAGINGENGINE.DLL" "PHOTOACQ.DLL" "PHOTOBASE.DLL" "PHOTOVIEWER.DLL" "en-US: IMAGINGDEVICES.EXE.MUI" "PHOTOACQ.DLL.MUI" "PHOTOVIEWER.DLL.MUI" "fr-FR: IMAGINGDEVICES.EXE.MUI" "PHOTOACQ.DLL.MUI" "PHOTOVIEWER.DLL.MUI" [Detected using Heuristic Algorithm] :HKLM WINDOWSAPPS=C:\PROGRAM FILES\WINDOWSAPPS\ ### "DELETED\" "DELETEDALLUSERPACKAGES\" "DOLBYLABORATORIES.DOLBYACCESS_3.7.2028.0_X64__RZ1TEBTTYB220\" "HELLOGAMES.NOMANSSKY_3.51.8054.0_X64__BS190HZG1SESY\" "MICROSOFT.549981C3F5F10_3.2105.19601.0_NEUTRAL_~_8WEKYB3D8BBWE\" "MICROSOFT.549981C3F5F10_3.2105.19 [Detected using Heuristic Algorithm] :HKLM APPLICATION DATA=C:\PROGRAMDATA\APPLICATION DATA\ ### "ADOBE\" "AGE OF EMPIRES 3\" "AOMEIBR\" "APPLICATION DATA\" "BUREAU\" "CANONBJ\" "CAPHYON\" "DISC-SOFT\" "DOCUMENTS\" "DRIVERSCLOUD.COM\" "EPIC\" [Detected using Heuristic Algorithm] :HKLM DOCUMENTS=C:\PROGRAMDATA\DOCUMENTS\ ### "CATCH!\" "DAEMON TOOLS IMAGES\" "DESKTOP.INI" "MA MUSIQUE\" "MES IMAGES\" "MES VIDÉOS\" "ONLINEFIX\" "REGRUNINFO\" "SPORTS INTERACTIVE\" "STEAM\" "THE WITCHER\" [Detected using Heuristic Algorithm] :HKLM MICROSOFT=C:\PROGRAMDATA\MICROSOFT\ ### "CRYPTO\" "DEVICE STAGE\" "DEVICESYNC\" "DIAGNOSIS\" "DIAGNOSTICLOGCSP\" "DRM\" "EDGEUPDATE\" "EVENT VIEWER\" "GAMINGSERVICES\" "IDENTITYCRL\" "MAPDATA\" [Detected using Heuristic Algorithm] :HKLM MICROSOFT ONEDRIVE=C:\PROGRAMDATA\MICROSOFT ONEDRIVE\ ### "SETUP\" "setup: REFCOUNT.INI" [Detected using Heuristic Algorithm] :HKLM NVIDIA=C:\PROGRAMDATA\NVIDIA\ ### "DISPLAYSESSIONCONTAINER1.LOG" "DISPLAYSESSIONCONTAINER1.LOG_BACKUP1" "DISPLAYSESSIONCONTAINER10.LOG" "DISPLAYSESSIONCONTAINER10.LOG_BACKUP1" "DISPLAYSESSIONCONTAINER11.LOG" "DISPLAYSESSIONCONTAINER11.LOG_BACKUP1" "DISPLAYSESSIONCONTAINER12.LOG" "DISPLAYS [Detected using Heuristic Algorithm] :HKLM REGID.1991-06.COM.MICROSOFT=C:\PROGRAMDATA\REGID.1991-06.COM.MICROSOFT\ ### "REGID.1991-06.COM.MICROSOFT_WINDOWS-10-HOME.SWIDTAG" [Detected using Heuristic Algorithm] :HKLM REGID.2010-01.COM.ZEROTIER=C:\PROGRAMDATA\REGID.2010-01.COM.ZEROTIER\ ### "REGID.2010-01.COM.ZEROTIER_ZEROTIERONE.SWIDTAG" [Detected using Heuristic Algorithm] :HKLM USOPRIVATE=C:\PROGRAMDATA\USOPRIVATE\ ### "UPDATESTORE\" "UpdateStore: STORE.DB" [Detected using Heuristic Algorithm] :HKLM USVFS=C:\PROGRAMDATA\USVFS\ [Detected using Heuristic Algorithm] :HKLM 3D OBJECTS=C:\USERS\USER\3D OBJECTS\ ### "DESKTOP.INI" [Detected using Heuristic Algorithm] :HKLM APPDATA=C:\USERS\USER\APPDATA\ ### "LOCAL\" "LOCALLOW\" "ROAMING\" "Local: FILE__0.LOCALSTORAGE" "ICONCACHE.DB" "Local\Application Data: FILE__0.LOCALSTORAGE" "ICONCACHE.DB" "Local\BANDAI NAMCO Entertainment\DB Xenoverse 2: CONFIG.INI" "EAC-LOG.TXT" "Local\BattlEye: CE" "Local\Bilago\Fall [Detected using Heuristic Algorithm] :HKLM APPLICATION DATA=C:\USERS\USER\APPDATA\LOCAL\APPLICATION DATA\ ### "ADOBE\" "APPLICATION DATA\" "BANDAI NAMCO ENTERTAINMENT\" "BATTLEYE\" "BILAGO\" "BRAVESOFTWARE\" "CACHE\" "CEF\" "COMMS\" "CONNECTEDDEVICESPLATFORM\" "CRASHDUMPS\" [Detected using Heuristic Algorithm] :HKLM CACHE=C:\USERS\USER\APPDATA\LOCAL\CACHE\ ### "QTSHADERCACHE-X86_64-LITTLE_ENDIAN-LLP64\" "qtshadercache-x86_64-little_endian-llp64: 4104E6C58A35843832EA0F84185F63EC3B6D62BD" "5CC098BC5354D98253495E89CC26CA4BA78A3A15" "7D5F9FC417D36376DBFBEBF864483ACA3A25AC1A" "B9EC05F41810B130C38C3DC281312718D7EEDE5 [Detected using Heuristic Algorithm] :HKLM CRASHDUMPS=C:\USERS\USER\APPDATA\LOCAL\CRASHDUMPS\ ### "DBXV2.EXE.8400.DMP" "EXPLORER.EXE.16612.DMP" "MALWAREBYTES\" "SKYRIMSE.EXE.16904.DMP" "SKYRIMSE.EXE.17356.DMP" "SKYRIMSE.EXE.17544.DMP" "SKYRIMSE.EXE.18996.DMP" "SKYRIMSE.EXE.19664.DMP" "SKYRIMSE.EXE.19776.DMP" "SKYRIMSE.EXE.20272.DMP" "SKYRIMSE.EXE.8276 [Detected using Heuristic Algorithm] :HKLM D3DSCACHE=C:\USERS\USER\APPDATA\LOCAL\D3DSCACHE\ [Detected using Heuristic Algorithm] :HKLM DISCORD=C:\USERS\USER\APPDATA\LOCAL\DISCORD\ ### "APP-0.0.309\" "APP-1.0.9002\" "APP.ICO" "DISCORD_UPDATER_R00000.LOG" "DISCORD_UPDATER_R00001.LOG" "DISCORD_UPDATER_R00002.LOG" "DISCORD_UPDATER_RCURRENT.LOG" "INSTALLER.DB" "PACKAGES\" "SQUIRRELSETUP.LOG" "UPDATE.EXE" [Detected using Heuristic Algorithm] :HKLM HISTORIQUE=C:\USERS\USER\APPDATA\LOCAL\HISTORIQUE\ ### "DESKTOP.INI" "HISTORY.IE5\" "LOW\" "History.IE5: CONTAINER.DAT" "History.IE5\MSHist012021052420210531: CONTAINER.DAT" "History.IE5\MSHist012021053120210607: CONTAINER.DAT" "History.IE5\MSHist012021060720210614: CONTAINER.DAT" "History.IE5\MSHist012021 [Detected using Heuristic Algorithm] :HKLM LOGMEIN HAMACHI=C:\USERS\USER\APPDATA\LOCAL\LOGMEIN HAMACHI\ ### "H2-UI-NETS.INI" "H2-UI-PEERS.CFG" "H2-UI-PEERS.INI" "H2-UI.CFG" "H2-UI.CFG.BAK" "H2-UI.INI" "H2-UI.INI.BAK" "H2-UI.LOG" [Detected using Heuristic Algorithm] :HKLM LOOT=C:\USERS\USER\APPDATA\LOCAL\LOOT\ ### "FALLOUT4\" "LOOTDEBUGLOG.TXT" "OBLIVION\" "SETTINGS.TOML" "SKYRIM SPECIAL EDITION\" "Fallout4: MASTERLIST.YAML" "Fallout4\.git: CONFIG" "DESCRIPTION" "FETCH_HEAD" "Skyrim Special Edition: MASTERLIST.YAML" "Skyrim Special Edition\.git: CONFIG" "DESCRIPTI [Detected using Heuristic Algorithm] :HKLM MICROSOFT=C:\USERS\USER\APPDATA\LOCAL\MICROSOFT\ ### "CLR_V2.0\" "CLR_V2.0_32\" "CLR_V4.0\" "CLR_V4.0_32\" "CREDENTIALS\" "EDGE\" "EDGEBHO\" "EDP\" "EVENT VIEWER\" "FEEDS\" "FEEDS CACHE\" [Detected using Heuristic Algorithm] :HKLM MODORGANIZER=C:\USERS\USER\APPDATA\LOCAL\MODORGANIZER\ ### "CACHE\" "NXMHANDLER.INI" "NXMHANDLER.LOG" "SKYRIM SPECIAL EDITION\" "cache\qmlcache: 49F32D2B3CDA9688A0B84E3DC1D974F93ABF69DA.JSC" "A80177DF7573E61461C56129F7F21441E6A9BE14.QMLC" "D899D0A600C5F72C69FABD420345D7A1309EC98C.QMLC" "DA0AA5C2815A41335845003F85D [Detected using Heuristic Algorithm] :HKLM NVIDIA=C:\USERS\USER\APPDATA\LOCAL\NVIDIA\ ### "ACCOUNTS" "GLCACHE\" "LOGS\" "NVBACKEND\" "GLCache\f7d46caff6609b5597d4b3ea44cbcf72\af8f27f6fb583081: 56CC73003308CCE8.BIN" "56CC73003308CCE8.TOC" "NvBackend: BACKEND.LOG" "BACKEND.LOG.BAK" "CONFIG.XML" "DRIVERRECOMMENDATIONS.DAT" [Detected using Heuristic Algorithm] :HKLM NVIDIA CORPORATION=C:\USERS\USER\APPDATA\LOCAL\NVIDIA CORPORATION\ ### "GEFORCENOW\" "GFNRUNTIMESDK\" "INSTALLER2\" "NVABHUB\" "NVIDIA GEFORCE EXPERIENCE\" "NVIDIA NOTIFICATION\" "NVIDIA SHARE\" "NVNODE\" "NVPROFILEUPDATER\" "NVTMREP\" "NVXCODE\" [Detected using Heuristic Algorithm] :HKLM OCULUS=C:\USERS\USER\APPDATA\LOCAL\OCULUS\ ### "COMPATIBILITY.JSON" "DEVICECACHE.JSON" "GUARDIANBOUNDARY_2021-06-14_23.17.26.TXT" "GUARDIANBOUNDARY_2021-06-16_20.27.18.TXT" "GUARDIANBOUNDARY_2021-06-17_22.16.23.TXT" "GUARDIANBOUNDARY_2021-06-19_00.12.58.TXT" "GUARDIANBOUNDARY_2021-06-19_02.18.54.TXT" [Detected using Heuristic Algorithm] :HKLM PACKAGES=C:\USERS\USER\APPDATA\LOCAL\PACKAGES\ ### "1527C705-839A-4832-9118-54D4BD6A0C89_CW5N1H2TXYEWY\" "ACTIVESYNC\" "ADOBE.ACROBATREADERDC.PROTECTEDMODE\" "C5E2524A-EA46-4F67-841F-6A9465D9D515_CW5N1H2TXYEWY\" "DOLBYLABORATORIES.DOLBYACCESS_RZ1TEBTTYB220\" "E2A4F912-2574-4A75-9BB0-0D023378592B_CW5N1H2TX [Detected using Heuristic Algorithm] :HKLM PLACEHOLDERTILELOGOFOLDER=C:\USERS\USER\APPDATA\LOCAL\PLACEHOLDERTILELOGOFOLDER\ ### "9NBLGGH4RV3K\" "9NBLGGH4RV3P\" "9NBLGGH4SVJT\" "9NPV76S164X5\" "BQVQTL3PCH05\" "MICROSOFT.WINDOWS.PHOTOS_8WEKYB3D8BBWE_LARGE.JPG" "MICROSOFT.WINDOWS.PHOTOS_8WEKYB3D8BBWE_LOGO.JPG" "MICROSOFT.WINDOWS.PHOTOS_8WEKYB3D8BBWE_SMALL.JPG" "MICROSOFT.WINDOWS.PHOT [Detected using Heuristic Algorithm] :HKLM SKYRIM SPECIAL EDITION=C:\USERS\USER\APPDATA\LOCAL\SKYRIM SPECIAL EDITION\ ### "LOADORDER.TXT" "PLUGINS.SSEVIEWSETTINGS" "PLUGINS.TXT" [Detected using Heuristic Algorithm] :HKLM TEMP=C:\USERS\USER\APPDATA\LOCAL\TEMP\ ### "03296DDC-DAE3-4157-8A6D-905DC396D007.TMP" "03DF4598-816B-4A66-8B53-8C84A84C651D.TMP" "25C8D299-710B-4F79-9EA2-05BCD327B334.TMP" "2EE1DCCB-4E8E-45AA-A405-38B6FCA4A937.TMP" "4479B4B1-9516-4EC9-8734-6A0A2D5ADDE3.TMP" "50815663-7F76-4DAB-97DA-57B4B12CB488.TM [Detected using Heuristic Algorithm] :HKLM TEMPORARY INTERNET FILES=C:\USERS\USER\APPDATA\LOCAL\TEMPORARY INTERNET FILES\ ### "CONTENT.IE5\" "IE\" "LOW\" "VIRTUALIZED\" "Content.IE5: CONTAINER.DAT" "Content.IE5\CPR7B0RZ: MOSTLYCLOUDYDAY[1].SVG" "WINDOWS[1].JSON" "WINDOWS[2].JSON" "Content.IE5\D269UQOB: 2[1]" "MOSTLYCLOUDYNIGHT[1].SVG" "WINDOWS-APP-WEB-LINK[1].JSON" "Content.IE [Detected using Heuristic Algorithm] :HKLM DISCORD=C:\USERS\USER\APPDATA\ROAMING\DISCORD\ ### "1.0.9002\" "BADGE-1.ICO" "BADGE-10.ICO" "BADGE-11.ICO" "BADGE-2.ICO" "BADGE-3.ICO" "BADGE-4.ICO" "BADGE-5.ICO" "BADGE-6.ICO" "BADGE-7.ICO" "BADGE-8.ICO" [Detected using Heuristic Algorithm] :HKLM MICROSOFT=C:\USERS\USER\APPDATA\ROAMING\MICROSOFT\ ### "CREDENTIALS\" "CRYPTO\" "IME\" "INPUTMETHOD\" "INTERNET EXPLORER\" "MMC\" "NETWORK\" "PROTECT\" "SPEECH\" "SPELLING\" "SYSTEMCERTIFICATES\" [Detected using Heuristic Algorithm] :HKLM STEELSERIES-ENGINE-3-CLIENT=C:\USERS\USER\APPDATA\ROAMING\STEELSERIES-ENGINE-3-CLIENT\ ### "BLOB_STORAGE\" "CACHE\" "CODE CACHE\" "COOKIES" "COOKIES-JOURNAL" "DICTIONARIES\" "GPUCACHE\" "LOCAL STORAGE\" "NETWORK PERSISTENT STATE" "PREFERENCES" "SESSION STORAGE\" [Detected using Heuristic Algorithm] :HKLM VORTEX=C:\USERS\USER\APPDATA\ROAMING\VORTEX\ ### ".UPDATERID" "BLADEANDSORCERY\" "BLOB_STORAGE\" "CACHE\" "CODE CACHE\" "COOKIES" "COOKIES-JOURNAL" "CRASHPAD\" "DICTIONARIES\" "FALLOUT4\" "FALLOUT4VR\" [Detected using Heuristic Algorithm] :HKLM ZEDIT=C:\USERS\USER\APPDATA\ROAMING\ZEDIT\ ### "000053.LOG" "BLOB_STORAGE\" "CACHE\" "CODE CACHE\" "COOKIES" "COOKIES-JOURNAL" "CURRENT" "GPUCACHE\" "LOCK" "LOG" "LOG.OLD" [Detected using Heuristic Algorithm] :HKLM APPLICATION DATA=C:\USERS\USER\APPLICATION DATA\ ### ".MINECRAFT\" "1.EFFECTS\" "ADOBE\" "BRAWLHALLAAIR\" "DAEMON TOOLS LITE\" "DISC-SOFT\" "DISCORD\" "DVDCSS\" "EASYANTICHEAT\" "FUNCOMLAUNCHER\" "GOLDBERG STEAMEMU SAVES\" [Detected using Heuristic Algorithm] :HKLM BRAWLHALLAREPLAYS=C:\USERS\USER\BRAWLHALLAREPLAYS\ ### "[5.06] APOCALYPSE (1).REPLAY" "[5.06] APOCALYPSE (2).REPLAY" "[5.06] APOCALYPSE (3).REPLAY" "[5.06] APOCALYPSE (4).REPLAY" "[5.06] APOCALYPSE (5).REPLAY" "[5.06] APOCALYPSE (6).REPLAY" "[5.06] APOCALYPSE.REPLAY" "[5.06] BIGMIAMIDOME.REPLAY" "[5.06] BLACK [Detected using Heuristic Algorithm] :HKLM CONTACTS=C:\USERS\USER\CONTACTS\ ### "DESKTOP.INI" [Detected using Heuristic Algorithm] :HKLM COOKIES=C:\USERS\USER\COOKIES\ ### "CONTAINER.DAT" "DEPRECATED.COOKIE" "DNTEXCEPTION\" "ESE\" "LOW\" "PRIVACIE\" "DNTException: CONTAINER.DAT" "ESE: CONTAINER.DAT" "Low\ESE: CONTAINER.DAT" [Detected using Heuristic Algorithm] :HKLM DESKTOP=C:\USERS\USER\DESKTOP\ ### "ADDITION.TXT" "APPLICATIONS\" "ASSISTANT MISE À JOUR DE WINDOWS 10.LNK" "DESKTOP.INI" "FORTNITE.URL" "FRST\" "FRST.TXT" "FRST64.EXE" "FURMARK.LNK" "JEUX\" "KIRO.LNK" [Detected using Heuristic Algorithm] :HKLM DOCUMENTS=C:\USERS\USER\DOCUMENTS\ ### "3DMARK\" "ATTENTION PREMIÈRE RELANCE.EML" "BIOWARE\" "CONQUEROR'S BLADE\" "DESKTOP.INI" "DRAGONBORNSPEAKSNATURALLY\" "MA MUSIQUE\" "MES IMAGES\" "MES VIDÉOS\" "MOUNT AND BLADE II BANNERLORD\" "MOUNT&BLADE WARBAND\" [Detected using Heuristic Algorithm] :HKLM DOWNLOADS=C:\USERS\USER\DOWNLOADS\ ### "DESKTOP.INI" "JUSTIN-OAKSFORD-MUD-MONSTER.JPG" "UNKNOWN.PNG" [Detected using Heuristic Algorithm] :HKLM FAVORITES=C:\USERS\USER\FAVORITES\ ### "ACADÉMIE DE MONTPELLIER.URL" "BING.URL" "DESKTOP.INI" "EDUCAGRI.FR LE SITE D'INFORMATION ET DE PROMOTION DES ÉTABLISSEMENTS PUBLICS D'ENSEIGNEMENT AGRICOLE.URL" "ENT - ACADEMIE LANGUEDOC-ROUSSILLON.URL" "GOOGLE.URL" "HP\" "LA CHAÎNE YOUTUBE DE LA RÉGION. [Detected using Heuristic Algorithm] :HKLM LINKS=C:\USERS\USER\LINKS\ ### "DESKTOP.INI" "DESKTOP.LNK" "DOWNLOADS.LNK" [Detected using Heuristic Algorithm] :HKLM LOCAL SETTINGS=C:\USERS\USER\LOCAL SETTINGS\ ### "ADOBE\" "APPLICATION DATA\" "BANDAI NAMCO ENTERTAINMENT\" "BATTLEYE\" "BILAGO\" "BRAVESOFTWARE\" "CACHE\" "CEF\" "COMMS\" "CONNECTEDDEVICESPLATFORM\" "CRASHDUMPS\" [Detected using Heuristic Algorithm] :HKLM MENU DÉMARRER=C:\USERS\USER\MENU DÉMARRER\ ### "DESKTOP.INI" "PROGRAMMES\" "PROGRAMS\" "Programmes: DESKTOP.INI" "EXCEL.LNK" "NVIDIA GEFORCE NOW.LNK" "ONEDRIVE.LNK" "OUTLOOK.LNK" "PCSX2 1.6.0.LNK" "Programs: DESKTOP.INI" "EXCEL.LNK" "NVIDIA GEFORCE NOW.LNK" "ONEDRIVE.LNK" "OUTLOOK.LNK" "PCSX2 1.6.0.L [Detected using Heuristic Algorithm] :HKLM MES DOCUMENTS=C:\USERS\USER\MES DOCUMENTS\ ### "3DMARK\" "ATTENTION PREMIÈRE RELANCE.EML" "BIOWARE\" "CONQUEROR'S BLADE\" "DESKTOP.INI" "DRAGONBORNSPEAKSNATURALLY\" "MA MUSIQUE\" "MES IMAGES\" "MES VIDÉOS\" "MOUNT AND BLADE II BANNERLORD\" "MOUNT&BLADE WARBAND\" [Detected using Heuristic Algorithm] :HKLM MODÈLES=C:\USERS\USER\MODÈLES\ [Detected using Heuristic Algorithm] :HKLM MUSIC=C:\USERS\USER\MUSIC\ ### "DESKTOP.INI" [Detected using Heuristic Algorithm] :HKLM PICTURES=C:\USERS\USER\PICTURES\ ### "CAMERA ROLL\" "DESKTOP.INI" "INKEDUNKNOWN_LI.JPG" "SAVED PICTURES\" "SCREENSHOTS\" "Camera Roll: DESKTOP.INI" "Saved Pictures: DESKTOP.INI" "Screenshots: CAPTURE D’ÉCRAN (1).PNG" "CAPTURE D’ÉCRAN (10).PNG" "CAPTURE D’ÉCRAN (11).PNG" "CAPTURE D’ÉCRAN (1 [Detected using Heuristic Algorithm] :HKLM RECENT=C:\USERS\USER\RECENT\ ### "(PART 1) ENGINE FIXES-17230-5-6-0-1611442568 (1).ZIP.LNK" "(PART 2) ENGINE FIXES - SKSE64 PRELOADER AND TBB LIB-17230-2020-3-1611367474 (1).7Z.LNK" ".TELECHARGEMENTS.LNK" "@.TXT.LNK" "ABSOLUTE ARACHNOPHOBIA.LNK" "ADDITION.TXT.LNK" "ALL IN ONE-32444-2-158 [Detected using Heuristic Algorithm] :HKLM SAVED GAMES=C:\USERS\USER\SAVED GAMES\ ### "DESKTOP.INI" [Detected using Heuristic Algorithm] :HKLM SEARCHES=C:\USERS\USER\SEARCHES\ ### "DESKTOP.INI" "EVERYWHERE.SEARCH-MS" "INDEXED LOCATIONS.SEARCH-MS" "WINRT--{S-1-5-21-2089416355-1224182416-3757198850-1001}-.SEARCHCONNECTOR-MS" [Detected using Heuristic Algorithm] :HKLM SENDTO=C:\USERS\USER\SENDTO\ ### "COMPRESSED (ZIPPED) FOLDER.ZFSENDTOTARGET" "DESKTOP (CREATE SHORTCUT).DESKLINK" "DESKTOP.INI" "DESTINATAIRE DE TÉLÉCOPIE.LNK" "DOCUMENTS.MYDOCS" "FAX RECIPIENT.LNK" "MAIL RECIPIENT.MAPIMAIL" "TEAMVIEWER.LNK" "TRANSFERT DE FICHIERS BLUETOOTH.LNK" [Detected using Heuristic Algorithm] :HKLM VIDEOS=C:\USERS\USER\VIDEOS\ ### "CAPTURES\" "DESKTOP.INI" "NVIDIA\" "STEELSERIES MOMENTS\" "Captures: DESKTOP.INI" "DRAGON BALL XENOVERSE 2 27_03_2021 03_28_15.PNG" "DRAGON BALL XENOVERSE 2 27_03_2021 03_34_09.PNG" "DRAGON BALL XENOVERSE 2 27_03_2021 03_36_35.PNG" "NVIDIA\GeForce NOW\Cy [Detected using Heuristic Algorithm] :HKLM VOISINAGE D'IMPRESSION=C:\USERS\USER\VOISINAGE D'IMPRESSION\ [Detected using Heuristic Algorithm] :HKLM VOISINAGE RÉSEAU=C:\USERS\USER\VOISINAGE RÉSEAU\ [In memory] [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\LSASS.EXE ### Local Security Authority Process Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.906 !$*C:\WINDOWS\system32\lsass.exe [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\WINLOGON.EXE ### Application d’ouverture de session Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*winlogon.exe [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k DcomLaunch -p [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\FONTDRVHOST.EXE ### Usermode Font Driver Host Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.906 !$*"fontdrvhost.exe" [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\FONTDRVHOST.EXE ### Usermode Font Driver Host Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.906 !$*"fontdrvhost.exe" [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k RPCSS -p [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k DcomLaunch -p -s LSM [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\DWM.EXE ### Gestionnaire de fenêtres du Bureau Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*"dwm.exe" [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -p -s NcbService [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted -p -s TimeBrokerSvc [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork -p [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted -p -s hidserv [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted -p -s EventLog [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -p -s StorSvc [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted -p -s DevQueryBroker [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k LocalService -p -s nsi [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s gpsvc [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k LocalService -p [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted -p -s Dhcp [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k LocalService -p -s DispBrokerDesktopSvc [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\DRIVERSTORE\FILEREPOSITORY\NVMDI.INF_AMD64_6A0632B60438E56D\DISPLAY.NVCONTAINER\NVDISPLAY.CONTAINER.EXE ### NVIDIA Container NVIDIA Corporation NVIDIA Container gcomp_dev 28519944 ->NVCONTAINER =>NVCONTAINER.EXE !$*C:\WINDOWS\System32\DriverStore\FileRepository\nvmdi.inf_amd64_6a0632b60438e56d\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log -l 3 -d C:\WINDOWS\System32\DriverStore\FileRepository\nvmdi.inf_amd64_6a0632b60438e56d\Display.NvContainer\plugins\LocalSystem -r -p 30000 -cfg NVDisplay.ContainerLocalSystem\LocalSystem [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\WUDFHOST.EXE ### Windows Driver Foundation - Processus hôte de l’infrastructure de pilotes en mode utilisateur Microsoft Corporation Système d'exploitation Microsoft® Windows® 10.0.19041.867 !$*"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:\UMDFCommunicationPorts\WUDF\HostProcess-181309fe-3d82-4937-bfb7-fa955ec62562 -SystemEventPortName:\UMDFCommunicationPorts\WUDF\HostProcess-286451a3-f613-49c0-9c6d-dd75363154b7 -IoCancelEventPortName:\UMDFCommunicationPorts\WUDF\HostProcess-c44e094d-de4b-484c-a6c4-72c462546399 -NonStateChangingEventPortName:\UMDFCommunicationPorts\WUDF\HostProcess-48eec4bf-fec8-42b9-a326-d504e861e028 -LifetimeId:06514144-d9ff-4c07-a022-5dd822180cb5 -DeviceGroupId:WpdFsGroup -HostArg:0 [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s Schedule [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s ProfSvc [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted -p -s SysMain [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k LocalService -p -s EventSystem [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\System32\svchost.exe -k netsvcs -p -s Themes [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k appmodel -p -s camsvc [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k appmodel -p -s StateRepository [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\System32\svchost.exe -k NetworkService -p -s NlaSvc [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s SENS [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\IGFXCUISERVICE.EXE ### igfxCUIService Module Intel Corporation Intel(R) Common User Interface 6.15.10.4624 !$*C:\WINDOWS\system32\igfxCUIService.exe [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s UserManager [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\System32\svchost.exe -k LocalService -p -s netprofm [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k LocalService -p -s FontCache [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -p -s AudioEndpointBuilder [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s Winmgmt [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\WBEM\WMIPRVSE.EXE ### WMI Provider Host Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.546 !$*C:\WINDOWS\system32\wbem\wmiprvse.exe [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted -p [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s Dnscache [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted -p [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted -p [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted -p -s WinHttpAutoProxySvc [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted -p [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\System32\svchost.exe -k netsvcs -p -s ShellHWDetection [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SPOOLSV.EXE ### Application sous-système spouleur Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\System32\spoolsv.exe [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetworkFirewall -p [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\WLANEXT.EXE ### Infrastructure d’extensibilité pour les services réseau Windows sans fil 802.11 Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\WLANExt.exe 2272965310336 [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\System32\svchost.exe -k NetworkService -p -s LanmanWorkstation [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\CONHOST.EXE ### Hôte de la fenêtre de la console Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*\??\C:\WINDOWS\system32\conhost.exe 0x4 [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted -p -s DeviceAssociationService [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\System32\svchost.exe -k utcsvc -p [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\System32\svchost.exe -k NetSvcs -p -s iphlpsvc [Running Processes] :HKLM C:\PROGRAM FILES (X86)\NETGEAR\A7000\RTLSERVICE.EXE ### Realtek RtlService Application Realtek Semiconductor Corp. Realtek RtlService Application 700, 1007, 509, 2012 !$*"C:\Program Files (x86)\NETGEAR\A7000\RtlService.exe" [Running Processes] :HKLM C:\PROGRAM FILES (X86)\LOGMEIN HAMACHI\X64\LMIGUARDIANSVC.EXE ### LMIGuardianSvc LogMeIn, Inc. LMIGuardianSvc 10.1.1742 !$*"C:\Program Files (x86)\LogMeIn Hamachi\x64\LMIGuardianSvc.exe" [Running Processes] :HKLM C:\PROGRAM FILES\NVIDIA CORPORATION\NVCONTAINER\NVCONTAINER.EXE ### NVIDIA Container NVIDIA Corporation NVIDIA Container gcomp_dev 28356155 !$*"C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe" -s NvContainerLocalSystem -f "C:\ProgramData\NVIDIA\NvContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\NvContainer\plugins\LocalSystem" -r -p 30000 -st "C:\Program Files\NVIDIA Corporation\NvContainer\NvContainerTelemetryApi.dll" [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\System32\svchost.exe -k LocalServiceNoNetwork -p -s DPS [Running Processes] :HKLM C:\PROGRAM FILES (X86)\HOTSPOT SHIELD\BIN\CMW_SRV.EXE ### Hss.Service.Application AnchorFree Inc. Hotspot Shield 9.21.3.11422 !$*"C:\Program Files (x86)\Hotspot Shield\bin\cmw_srv.exe" [Running Processes] :HKLM D:\OCULUS\SUPPORT\OCULUS-RUNTIME\OVRSERVICELAUNCHER.EXE ### OVR Service Launcher Facebook Technologies, LLC OVR Service Launcher 29.0.0.54.528 !$*"D:\Oculus\Support\oculus-runtime\OVRServiceLauncher.exe" [Running Processes] :HKLM C:\PROGRAM FILES (X86)\LOGMEIN HAMACHI\X64\HAMACHI-2.EXE ### Hamachi Client Tunneling Engine LogMeIn Inc. Hamachi Client 2, 0, 0, 0 ->H2-ENGINE !$*"C:\Program Files (x86)\LogMeIn Hamachi\x64\hamachi-2.exe" -s [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k LocalService -p -s SstpSvc [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s CryptSvc [Running Processes] :HKLM C:\WINDOWS\RUNSW.EXE ### runSW Application 1, 1005, 415, 2014 !$*C:\Windows\runSW.exe [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k imgsvc [Running Processes] :HKLM C:\PROGRAM FILES\TEAMVIEWER\TEAMVIEWER_SERVICE.EXE ### TeamViewer TeamViewer Germany GmbH TeamViewer 15.16.8.0 ->TEAMVIEWER !$*"C:\Program Files\TeamViewer\TeamViewer_Service.exe" [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s LanmanServer [Running Processes] :HKLM C:\PROGRAM FILES\VIRTUAL DESKTOP\VIRTUALDESKTOP.SERVICE.EXE ### Virtual Desktop Service Virtual Desktop, Inc. Virtual Desktop 1.18.5.0 !$*"C:\Program Files\Virtual Desktop\VirtualDesktop.Service.exe" [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -p -s TrkWks [Running Processes] :HKLM D:\STEAMLIBRARY\STEAMAPPS\COMMON\WALLPAPER_ENGINE\BIN\WALLPAPERSERVICE32_C.EXE ### !$*"D:\SteamLibrary\steamapps\common\wallpaper_engine\bin\wallpaperservice32_c.exe" [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s WpnService [Running Processes] :HKLM C:\PROGRAMDATA\ZEROTIER\ONE\ZEROTIER-ONE_X64.EXE ### !$*C:\ProgramData\ZeroTier\One\zerotier-one_x64.exe [Running Processes] :HKLM C:\PROGRAM FILES\WINDOWSAPPS\MICROSOFT.GAMINGSERVICES_2.53.17003.0_X64__8WEKYB3D8BBWE\GAMINGSERVICESNET.EXE ### GamingServices Microsoft Corporation Microsoft Gaming Install Services 10.0.19041.7259 ->GAMINGSERVICES.EXE !$*"C:\Program Files\WindowsApps\Microsoft.GamingServices_2.53.17003.0_x64__8wekyb3d8bbwe\GamingServicesNet.exe" [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\DASHOST.EXE ### Device Association Framework Provider Host Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*dashost.exe {81beea8c-dbcb-4525-928f5fded87e6fb6} [Running Processes] :HKLM C:\PROGRAM FILES\WINDOWSAPPS\MICROSOFT.GAMINGSERVICES_2.53.17003.0_X64__8WEKYB3D8BBWE\GAMINGSERVICES.EXE ### GamingServices Microsoft Corporation Microsoft Gaming Install Services 10.0.19041.7259 !$*"C:\Program Files\WindowsApps\Microsoft.GamingServices_2.53.17003.0_x64__8wekyb3d8bbwe\GamingServices.exe" [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\System32\svchost.exe -k netsvcs [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\System32\svchost.exe -k LocalService -p -s WdiServiceHost [Running Processes] :HKLM C:\WINDOWS\SWUSB.EXE ### Switch USB2.0/USB3.0 for WinXP SP2+ ~ Win8.1 Realtek 500, 1038, 1209, 2016 !$*C:\Windows\SwUSB.exe [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\WBEM\WMIPRVSE.EXE ### WMI Provider Host Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.546 !$*C:\WINDOWS\system32\wbem\wmiprvse.exe [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation -p -s SSDPSRV [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k DcomLaunch -p -s DeviceInstall [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k NetworkServiceNetworkRestricted -p -s PolicyAgent [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\RUNDLL32.EXE ### Processus hôte Windows (Rundll32) Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 ->RUNDLL !$*rundll32.exe "c:\program files\nvidia corporation\nvstreamsrv\rxdiag.dll" RxDiagSetRuntimeMessagePump [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -p -s Netman [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k LocalService -p -s fdPHost [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation -p -s FDResPub [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted -p -s lmhosts [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\System32\svchost.exe -k LocalServiceNoNetwork -p -s NcdAutoSetup [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\System32\svchost.exe -k netsvcs -p [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s wuauserv [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\DRIVERSTORE\FILEREPOSITORY\NVMDI.INF_AMD64_6A0632B60438E56D\DISPLAY.NVCONTAINER\NVDISPLAY.CONTAINER.EXE ### NVIDIA Container NVIDIA Corporation NVIDIA Container gcomp_dev 28519944 ->NVCONTAINER =>NVCONTAINER.EXE !$*"C:\WINDOWS\System32\DriverStore\FileRepository\nvmdi.inf_amd64_6a0632b60438e56d\Display.NvContainer\NVDisplay.Container.exe" -f %ProgramData%\NVIDIA\DisplaySessionContainer%d.log -d C:\WINDOWS\System32\DriverStore\FileRepository\nvmdi.inf_amd64_6a0632b60438e56d\Display.NvContainer\plugins\Session -r -l 3 -p 30000 -cfg NVDisplay.ContainerLocalSystem\Session -c [Running Processes] :HKLM C:\PROGRAM FILES\NVIDIA CORPORATION\NVCONTAINER\NVCONTAINER.EXE ### NVIDIA Container NVIDIA Corporation NVIDIA Container gcomp_dev 28356155 !$*"C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe" -f "C:\ProgramData\NVIDIA\NvContainerUser%d.log" -d "C:\Program Files\NVIDIA Corporation\NvContainer\plugins\User" -r -l 3 -p 30000 -st "C:\Program Files\NVIDIA Corporation\NvContainer\NvContainerTelemetryApi.dll" -c [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SIHOST.EXE ### Shell Infrastructure Host Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.746 !$*sihost.exe [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup -s CDPUserSvc [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s XblAuthManager [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup -s WpnUserService [Running Processes] :HKLM C:\WINDOWS\MICROSOFT.NET\FRAMEWORK64\V3.0\WPF\PRESENTATIONFONTCACHE.EXE ### PresentationFontCache.exe Microsoft Corporation Microsoft® .NET Framework 3.0.6920.9141 !$*C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [Running Processes] :HKLM C:\PROGRAM FILES (X86)\COMMON FILES\INSTALLSHIELD\ENGINE\8\INTEL 32\IKERNEL.EXE ### InstallShield (R) Setup Engine InstallShield Software Corporation InstallShield (R) 6, 31 ->KERNEL !$*"C:\Program Files (x86)\Common Files\installshield\engine\8\intel 32\iKernel.exe" [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s TokenBroker [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\TASKHOSTW.EXE ### Processus hôte pour Tâches Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*taskhostw.exe {222A245B-E637-4AE9-A93F-A59CA119A75E} [Running Processes] :HKLM D:\PROGRAM FILES (X86)\MSI AFTERBURNER\MSIAFTERBURNER.EXE ### MSIAfterburner MSIAfterburner 4, 6, 3, 16094 !$*"D:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe" /s [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -p -s TabletInputService [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\CTFMON.EXE ### Chargeur CTF Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*"ctfmon.exe" [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k LocalService -p -s CDPSvc [Running Processes] :HKLM C:\WINDOWS\EXPLORER.EXE ### Explorateur Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.1023 !$*C:\WINDOWS\Explorer.EXE [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted -s RmSvc [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted -p -s NgcSvc [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted -p -s NgcCtnrSvc [Running Processes] :HKLM C:\PROGRAM FILES (X86)\NETGEAR\A7000\A7000.EXE ### A7000 Genie MFC Application NETGEAR Genie Application 1.0.0.15 ->GENIE !$*A7000.exe /H [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k ClipboardSvcGroup -p -s cbdhsvc [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\IGFXEM.EXE ### igfxEM Module Intel Corporation Intel(R) Common User Interface 6.15.10.4624 !$*igfxEM.exe [Running Processes] :HKLM D:\OCULUS\SUPPORT\OCULUS-RUNTIME\OVRSERVER_X64.EXE ### OVRServer_x64.exe (CAPI: 1.61.0) 9cb886ebea76-public SC:4423061915976049 Facebook Technologies, LLC OVR Service 29.0.0.54.528 ->OVRSERVICE.EXE !$*bc 15c [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\CONHOST.EXE ### Hôte de la fenêtre de la console Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*\??\C:\WINDOWS\system32\conhost.exe 0x4 [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\DLLHOST.EXE ### COM Surrogate Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.546 !$*C:\WINDOWS\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} [Running Processes] :HKLM C:\PROGRAM FILES (X86)\NVIDIA CORPORATION\NVNODE\NVIDIA WEB HELPER.EXE ### NVIDIA Web Helper Service Node.js Node.js 11.13.0 ->NODE =>NODE.EXE !$*"C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe" index.js [Running Processes] :HKLM D:\OCULUS\SUPPORT\OCULUS-RUNTIME\OVRREDIR.EXE ### OVR Redir Facebook Technologies, LLC OVR Redir 29.0.0.54.528 !$*bc 15c [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\CONHOST.EXE ### Hôte de la fenêtre de la console Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*\??\C:\WINDOWS\system32\conhost.exe 0x4 [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\AUDIODG.EXE ### Isolation graphique de périphérique audio Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 ->AUDIOADG.EXE =>AUDIOADG.EXE.MUI !$*C:\WINDOWS\system32\AUDIODG.EXE 0x444 [Running Processes] :HKLM C:\WINDOWS\SYSTEMAPPS\MICROSOFT.WINDOWS.STARTMENUEXPERIENCEHOST_CW5N1H2TXYEWY\STARTMENUEXPERIENCEHOST.EXE ### !$*"C:\WINDOWS\SystemApps\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\StartMenuExperienceHost.exe" -ServerName:App.AppXywbrabmsek0gm3tkwpr5kwzbs55tkqay.mca [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\RUNTIMEBROKER.EXE ### Runtime Broker Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.746 !$*C:\Windows\System32\RuntimeBroker.exe -Embedding [Running Processes] :HKLM C:\WINDOWS\SYSTEMAPPS\MICROSOFT.WINDOWS.SEARCH_CW5N1H2TXYEWY\SEARCHAPP.EXE ### Search application Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1023 !$*"C:\WINDOWS\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe" -ServerName:CortanaUI.AppX8z9r6jm96hw4bsbneegw0kyxx296wr9t.mca [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SEARCHINDEXER.EXE ### Indexeur Microsoft Windows Search Microsoft Corporation Windows® Search 7.0.19041.867 !$*C:\WINDOWS\system32\SearchIndexer.exe /Embedding [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\RUNTIMEBROKER.EXE ### Runtime Broker Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.746 !$*C:\Windows\System32\RuntimeBroker.exe -Embedding [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\System32\svchost.exe -k LocalService -p -s LicenseManager [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SETTINGSYNCHOST.EXE ### Host Process for Setting Synchronization Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.746 !$*C:\WINDOWS\system32\SettingSyncHost.exe -Embedding [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SMARTSCREEN.EXE ### Windows Defender SmartScreen Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\Windows\System32\smartscreen.exe -Embedding [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SECURITYHEALTHSYSTRAY.EXE ### Windows Security notification icon Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1 !$*"C:\Windows\System32\SecurityHealthSystray.exe" [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s Appinfo [Running Processes] :HKLM C:\PROGRAM FILES\STEELSERIES\STEELSERIES ENGINE 3\STEELSERIESGG.EXE ### SteelSeries GG SteelSeries ApS SteelSeries GG 3.1.0.0 !$*"C:\Program Files\SteelSeries\SteelSeries Engine 3\SteelSeriesGG.exe" -dataPath="C:\ProgramData\SteelSeries\SteelSeries Engine 3" -dbEnv=production -auto=true [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted -p -s PcaSvc [Running Processes] :HKLM C:\PROGRAM FILES\STEELSERIES\STEELSERIES ENGINE 3\STEELSERIESENGINE.EXE ### SteelSeries GG Core SteelSeries ApS SteelSeries GG 3.1.0.0 !$*"C:\Program Files\SteelSeries\SteelSeries Engine 3\SteelSeriesEngine.exe" -auto -dbEnv=production "-momentsDataPath=C:\ProgramData\SteelSeries\SteelSeries Engine 3" [Running Processes] :HKLM C:\PROGRAM FILES (X86)\BRAVESOFTWARE\UPDATE\BRAVEUPDATE.EXE ### BraveSoftware Update BraveSoftware Inc. BraveSoftware Update 1.3.101.0 ->BRAVESOFTWARE UPDATE !$*"C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe" /c [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -p -s WdiSystemHost [Running Processes] :HKLM C:\PROGRAM FILES\WINDOWSAPPS\MICROSOFT.549981C3F5F10_3.2105.19601.0_X64__8WEKYB3D8BBWE\CORTANA.EXE ### Cortana Microsoft Corporation Cortana 3.2105.19601.0-gabf71c0e !$*"C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_3.2105.19601.0_x64__8wekyb3d8bbwe\Cortana.exe" -ServerName:App.AppX2y379sjp88wjq1y80217mddj3fargf2y.mca [Running Processes] :HKLM C:\PROGRAM FILES (X86)\COMMON FILES\JAVA\JAVA UPDATE\JUSCHED.EXE ### Java Update Scheduler Oracle Corporation Java Platform SE Auto Updater 2.8.291.10 ->JAVA UPDATE SCHEDULER !$*"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [Running Processes] :HKLM C:\USERS\USER\APPDATA\LOCAL\DISCORD\APP-1.0.9002\DISCORD.EXE ### Discord Discord Inc. Discord 1.0.9002 !$*"C:\Users\user\AppData\Local\Discord\app-1.0.9002\Discord.exe" [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\RUNTIMEBROKER.EXE ### Runtime Broker Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.746 !$*C:\Windows\System32\RuntimeBroker.exe -Embedding [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k LocalService -p -s BthAvctpSvc [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k AarSvcGroup -p -s AarSvc [Running Processes] :HKLM C:\PROGRAM FILES\STEELSERIES\STEELSERIES ENGINE 3\MOMENTS\STEELSERIESSVCLAUNCHER.EXE ### SteelSeries Capture Service Launcher SteelSeries ApS SteelSeries GG 1.0.0.1 !$*"C:\Program Files\SteelSeries\SteelSeries Engine 3\moments\SteelSeriesSvcLauncher.exe" \\.\pipe\8f6e5598-12dd-40d9-aa41-cbd6d51d19a3 "C:\Program Files\SteelSeries\SteelSeries Engine 3\moments\gsdk.dll" [Running Processes] :HKLM C:\USERS\USER\APPDATA\LOCAL\DISCORD\APP-1.0.9002\DISCORD.EXE ### Discord Discord Inc. Discord 1.0.9002 !$*C:\Users\user\AppData\Local\Discord\app-1.0.9002\Discord.exe --type=crashpad-handler --user-data-dir=C:\Users\user\AppData\Roaming\discord /prefetch:7 --no-rate-limit --no-upload-gzip --monitor-self-annotation=ptype=crashpad-handler --database=C:\Users\user\AppData\Roaming\discord\Crashpad --url=https://sentry.io/api/146342/minidump/?sentry_key=384ce4413de74fe0be270abe03b2b35a "--annotation=_companyName=Discord Inc." --annotation=_productName=Discord --annotation=_version=1.0.9002 --annotation=prod=Electron --annotation=ver=9.3.5 --initial-client-data=0x468,0x46c,0x470,0x444,0x474,0x67d4078,0x67d4088,0x67d4094 [Running Processes] :HKLM C:\USERS\USER\APPDATA\LOCAL\DISCORD\APP-1.0.9002\DISCORD.EXE ### Discord Discord Inc. Discord 1.0.9002 !$*"C:\Users\user\AppData\Local\Discord\app-1.0.9002\Discord.exe" --type=gpu-process --field-trial-handle=1636,13188244586898724403,13825501306207673117,131072 --enable-features=WebComponentsV0Enabled --disable-features=SpareRendererForSitePerProcess --gpu-preferences=MAAAAAAAAADgAAAwAAAAAAAAAAAAAAAAAABgAAAAAAAQAAAAAAAAAAAAAAAAAAAAKAAAAAQAAAAgAAAAAAAAACgAAAAAAAAAMAAAAAAAAAA4AAAAAAAAABAAAAAAAAAAAAAAAAUAAAAQAAAAAAAAAAAAAAAGAAAAEAAAAAAAAAABAAAABQAAABAAAAAAAAAAAQAAAAYAAAA= --mojo-platform-channel-handle=1672 /prefetch:2 [Running Processes] :HKLM C:\USERS\USER\APPDATA\LOCAL\DISCORD\APP-1.0.9002\DISCORD.EXE ### Discord Discord Inc. Discord 1.0.9002 !$*"C:\Users\user\AppData\Local\Discord\app-1.0.9002\Discord.exe" --type=utility --field-trial-handle=1636,13188244586898724403,13825501306207673117,131072 --enable-features=WebComponentsV0Enabled --disable-features=SpareRendererForSitePerProcess --lang=fr --service-sandbox-type=network --mojo-platform-channel-handle=2124 /prefetch:8 [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s UsoSvc [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\MOUSOCOREWORKER.EXE ### MoUSO Core Worker Process Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.1023 ->MOUSO CORE WORKER PROCESS !$*C:\Windows\System32\mousocoreworker.exe -Embedding [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k WbioSvcGroup -s WbioSrvc [Running Processes] :HKLM C:\USERS\USER\APPDATA\LOCAL\DISCORD\APP-1.0.9002\DISCORD.EXE ### Discord Discord Inc. Discord 1.0.9002 !$*"C:\Users\user\AppData\Local\Discord\app-1.0.9002\Discord.exe" --type=utility --field-trial-handle=1636,13188244586898724403,13825501306207673117,131072 --enable-features=WebComponentsV0Enabled --disable-features=SpareRendererForSitePerProcess --lang=fr --service-sandbox-type=proxy_resolver --mojo-platform-channel-handle=2668 /prefetch:8 [Running Processes] :HKLM C:\USERS\USER\APPDATA\LOCAL\DISCORD\APP-1.0.9002\DISCORD.EXE ### Discord Discord Inc. Discord 1.0.9002 !$*"C:\Users\user\AppData\Local\Discord\app-1.0.9002\Discord.exe" --type=renderer --autoplay-policy=no-user-gesture-required --field-trial-handle=1636,13188244586898724403,13825501306207673117,131072 --enable-features=WebComponentsV0Enabled --disable-features=SpareRendererForSitePerProcess --lang=fr --app-user-model-id=com.squirrel.Discord.Discord --app-path="C:\Users\user\AppData\Local\Discord\app-1.0.9002\resources\app.asar" --no-sandbox --no-zygote --native-window-open --preload="C:\Users\user\AppData\Local\Discord\app-1.0.9002\modules\discord_desktop_core-1\discord_desktop_core\core.asar\app\mainScreenPreload.js" --context-isolation --background-color=#202225 --enable-spellcheck --enable-websql --device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-activation --renderer-client-id=8 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=3300 /prefetch:1 --enable-node-leakage-in-renderers [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup [Running Processes] :HKLM C:\USERS\USER\APPDATA\LOCAL\DISCORD\APP-1.0.9002\DISCORD.EXE ### Discord Discord Inc. Discord 1.0.9002 !$*"C:\Users\user\AppData\Local\Discord\app-1.0.9002\Discord.exe" --type=utility --field-trial-handle=1636,13188244586898724403,13825501306207673117,131072 --enable-features=WebComponentsV0Enabled --disable-features=SpareRendererForSitePerProcess --lang=fr --service-sandbox-type=audio --mojo-platform-channel-handle=3552 /prefetch:8 [Running Processes] :HKLM C:\PROGRAM FILES\BRAVESOFTWARE\BRAVE-BROWSER\APPLICATION\BRAVE.EXE ### Brave Browser Brave Software, Inc. Brave Browser 91.1.25.73 ->BRAVE_EXE !$*"C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe" [Running Processes] :HKLM C:\PROGRAM FILES\BRAVESOFTWARE\BRAVE-BROWSER\APPLICATION\BRAVE.EXE ### Brave Browser Brave Software, Inc. Brave Browser 91.1.25.73 ->BRAVE_EXE !$*"C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe" --type=crashpad-handler "--user-data-dir=C:\Users\user\AppData\Local\BraveSoftware\Brave-Browser\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\user\AppData\Local\BraveSoftware\Brave-Browser\User Data\Crashpad" "--metrics-dir=C:\Users\user\AppData\Local\BraveSoftware\Brave-Browser\User Data" --url=https://cr.brave.com --annotation=plat=Win64 --annotation=prod=Brave --annotation=ver=91.1.25.73 --initial-client-data=0xfc,0x100,0x104,0xd8,0x108,0x7ffa83905430,0x7ffa83905440,0x7ffa83905450 [Running Processes] :HKLM C:\PROGRAM FILES\BRAVESOFTWARE\BRAVE-BROWSER\APPLICATION\BRAVE.EXE ### Brave Browser Brave Software, Inc. Brave Browser 91.1.25.73 ->BRAVE_EXE !$*"C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe" --type=gpu-process --field-trial-handle=1700,16814878375827632891,6835281291522425617,131072 --enable-features=AutoupgradeMixedContent,LegacyTLSEnforced,PasswordImport,PrefetchPrivacyChanges,ReducedReferrerGranularity,SafetyTip,WebUIDarkMode,WinrtGeolocationImplementation --disable-features=AutofillEnableAccountWalletStorage,AutofillServerCommunication,DirectSockets,EnableProfilePickerOnStartup,FederatedLearningOfCohorts,FirstPartySets,FledgeInterestGroupAPI,FledgeInterestGroups,FlocIdComputedEventLogging,HandwritingRecognitionWebPlatformApi,HandwritingRecognitionWebPlatformApiFinch,IdleDetection,InterestCohortAPIOriginTrial,InterestCohortFeaturePolicy,LangClientHintHeader,LiveCaption,NetworkTimeServiceQuerying,NotificationTriggers,SharingQRCodeGenerator,SignedExchangePrefetchCacheForNavigations,SignedExchangeSubresourcePrefetch,SubresourceWebBundles,TabHoverCards,TextFragmentAnchor,TrustTokens,WebOTP --start-stack-profiler --gpu-preferences=SAAAAAAAAADgAAAwAAAAAAAAAAAAAAAAAABgAAAAAAAoAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAB4AAAAAAAAAHgAAAAAAAAAKAAAAAQAAAAgAAAAAAAAACgAAAAAAAAAMAAAAAAAAAA4AAAAAAAAABAAAAAAAAAAAAAAAAUAAAAQAAAAAAAAAAAAAAAGAAAAEAAAAAAAAAABAAAABQAAABAAAAAAAAAAAQAAAAYAAAAIAAAAAAAAAAgAAAAAAAAA --mojo-platform-channel-handle=1744 /prefetch:2 [Running Processes] :HKLM C:\PROGRAM FILES\BRAVESOFTWARE\BRAVE-BROWSER\APPLICATION\BRAVE.EXE ### Brave Browser Brave Software, Inc. Brave Browser 91.1.25.73 ->BRAVE_EXE !$*"C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1700,16814878375827632891,6835281291522425617,131072 --enable-features=AutoupgradeMixedContent,LegacyTLSEnforced,PasswordImport,PrefetchPrivacyChanges,ReducedReferrerGranularity,SafetyTip,WebUIDarkMode,WinrtGeolocationImplementation --disable-features=AutofillEnableAccountWalletStorage,AutofillServerCommunication,DirectSockets,EnableProfilePickerOnStartup,FederatedLearningOfCohorts,FirstPartySets,FledgeInterestGroupAPI,FledgeInterestGroups,FlocIdComputedEventLogging,HandwritingRecognitionWebPlatformApi,HandwritingRecognitionWebPlatformApiFinch,IdleDetection,InterestCohortAPIOriginTrial,InterestCohortFeaturePolicy,LangClientHintHeader,LiveCaption,NetworkTimeServiceQuerying,NotificationTriggers,SharingQRCodeGenerator,SignedExchangePrefetchCacheForNavigations,SignedExchangeSubresourcePrefetch,SubresourceWebBundles,TabHoverCards,TextFragmentAnchor,TrustTokens,WebOTP --lang=fr --service-sandbox-type=none --start-stack-profiler --mojo-platform-channel-handle=2132 /prefetch:8 [Running Processes] :HKLM C:\PROGRAM FILES\BRAVESOFTWARE\BRAVE-BROWSER\APPLICATION\BRAVE.EXE ### Brave Browser Brave Software, Inc. Brave Browser 91.1.25.73 ->BRAVE_EXE !$*"C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --field-trial-handle=1700,16814878375827632891,6835281291522425617,131072 --enable-features=AutoupgradeMixedContent,LegacyTLSEnforced,PasswordImport,PrefetchPrivacyChanges,ReducedReferrerGranularity,SafetyTip,WebUIDarkMode,WinrtGeolocationImplementation --disable-features=AutofillEnableAccountWalletStorage,AutofillServerCommunication,DirectSockets,EnableProfilePickerOnStartup,FederatedLearningOfCohorts,FirstPartySets,FledgeInterestGroupAPI,FledgeInterestGroups,FlocIdComputedEventLogging,HandwritingRecognitionWebPlatformApi,HandwritingRecognitionWebPlatformApiFinch,IdleDetection,InterestCohortAPIOriginTrial,InterestCohortFeaturePolicy,LangClientHintHeader,LiveCaption,NetworkTimeServiceQuerying,NotificationTriggers,SharingQRCodeGenerator,SignedExchangePrefetchCacheForNavigations,SignedExchangeSubresourcePrefetch,SubresourceWebBundles,TabHoverCards,TextFragmentAnchor,TrustTokens,WebOTP --lang=fr --service-sandbox-type=utility --mojo-platform-channel-handle=2464 /prefetch:8 [Running Processes] :HKLM C:\PROGRAM FILES\BRAVESOFTWARE\BRAVE-BROWSER\APPLICATION\BRAVE.EXE ### Brave Browser Brave Software, Inc. Brave Browser 91.1.25.73 ->BRAVE_EXE !$*"C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe" --type=utility --utility-sub-type=bat_ledger.mojom.BatLedgerService --field-trial-handle=1700,16814878375827632891,6835281291522425617,131072 --enable-features=AutoupgradeMixedContent,LegacyTLSEnforced,PasswordImport,PrefetchPrivacyChanges,ReducedReferrerGranularity,SafetyTip,WebUIDarkMode,WinrtGeolocationImplementation --disable-features=AutofillEnableAccountWalletStorage,AutofillServerCommunication,DirectSockets,EnableProfilePickerOnStartup,FederatedLearningOfCohorts,FirstPartySets,FledgeInterestGroupAPI,FledgeInterestGroups,FlocIdComputedEventLogging,HandwritingRecognitionWebPlatformApi,HandwritingRecognitionWebPlatformApiFinch,IdleDetection,InterestCohortAPIOriginTrial,InterestCohortFeaturePolicy,LangClientHintHeader,LiveCaption,NetworkTimeServiceQuerying,NotificationTriggers,SharingQRCodeGenerator,SignedExchangePrefetchCacheForNavigations,SignedExchangeSubresourcePrefetch,SubresourceWebBundles,TabHoverCards,TextFragmentAnchor,TrustTokens,WebOTP --lang=fr --service-sandbox-type=none --mojo-platform-channel-handle=2508 /prefetch:8 [Running Processes] :HKLM C:\PROGRAM FILES\BRAVESOFTWARE\BRAVE-BROWSER\APPLICATION\BRAVE.EXE ### Brave Browser Brave Software, Inc. Brave Browser 91.1.25.73 ->BRAVE_EXE !$*"C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe" --type=renderer --field-trial-handle=1700,16814878375827632891,6835281291522425617,131072 --enable-features=AutoupgradeMixedContent,LegacyTLSEnforced,PasswordImport,PrefetchPrivacyChanges,ReducedReferrerGranularity,SafetyTip,WebUIDarkMode,WinrtGeolocationImplementation --disable-features=AutofillEnableAccountWalletStorage,AutofillServerCommunication,DirectSockets,EnableProfilePickerOnStartup,FederatedLearningOfCohorts,FirstPartySets,FledgeInterestGroupAPI,FledgeInterestGroups,FlocIdComputedEventLogging,HandwritingRecognitionWebPlatformApi,HandwritingRecognitionWebPlatformApiFinch,IdleDetection,InterestCohortAPIOriginTrial,InterestCohortFeaturePolicy,LangClientHintHeader,LiveCaption,NetworkTimeServiceQuerying,NotificationTriggers,SharingQRCodeGenerator,SignedExchangePrefetchCacheForNavigations,SignedExchangeSubresourcePrefetch,SubresourceWebBundles,TabHoverCards,TextFragmentAnchor,TrustTokens,WebOTP --lang=fr --origin-trial-public-key=bYUKPJoPnCxeNvu72j4EmPuK7tr1PAC7SHh8ld9Mw3E=,fMS4mpO6buLQ/QMd+zJmxzty/VQ6B1EUZqoCU04zoRU= --start-stack-profiler --brave_session_token=6704221578705972092 --device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-activation --renderer-client-id=8 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2960 /prefetch:1 [Running Processes] :HKLM C:\PROGRAM FILES\BRAVESOFTWARE\BRAVE-BROWSER\APPLICATION\BRAVE.EXE ### Brave Browser Brave Software, Inc. Brave Browser 91.1.25.73 ->BRAVE_EXE !$*"C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe" --type=renderer --field-trial-handle=1700,16814878375827632891,6835281291522425617,131072 --enable-features=AutoupgradeMixedContent,LegacyTLSEnforced,PasswordImport,PrefetchPrivacyChanges,ReducedReferrerGranularity,SafetyTip,WebUIDarkMode,WinrtGeolocationImplementation --disable-features=AutofillEnableAccountWalletStorage,AutofillServerCommunication,DirectSockets,EnableProfilePickerOnStartup,FederatedLearningOfCohorts,FirstPartySets,FledgeInterestGroupAPI,FledgeInterestGroups,FlocIdComputedEventLogging,HandwritingRecognitionWebPlatformApi,HandwritingRecognitionWebPlatformApiFinch,IdleDetection,InterestCohortAPIOriginTrial,InterestCohortFeaturePolicy,LangClientHintHeader,LiveCaption,NetworkTimeServiceQuerying,NotificationTriggers,SharingQRCodeGenerator,SignedExchangePrefetchCacheForNavigations,SignedExchangeSubresourcePrefetch,SubresourceWebBundles,TabHoverCards,TextFragmentAnchor,TrustTokens,WebOTP --lang=fr --extension-process --origin-trial-public-key=bYUKPJoPnCxeNvu72j4EmPuK7tr1PAC7SHh8ld9Mw3E=,fMS4mpO6buLQ/QMd+zJmxzty/VQ6B1EUZqoCU04zoRU= --brave_session_token=6704221578705972092 --device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-activation --renderer-client-id=6 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=3616 /prefetch:1 [Running Processes] :HKLM C:\PROGRAM FILES\BRAVESOFTWARE\BRAVE-BROWSER\APPLICATION\BRAVE.EXE ### Brave Browser Brave Software, Inc. Brave Browser 91.1.25.73 ->BRAVE_EXE !$*"C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe" --type=utility --utility-sub-type=proxy_resolver.mojom.ProxyResolverFactory --field-trial-handle=1700,16814878375827632891,6835281291522425617,131072 --enable-features=AutoupgradeMixedContent,LegacyTLSEnforced,PasswordImport,PrefetchPrivacyChanges,ReducedReferrerGranularity,SafetyTip,WebUIDarkMode,WinrtGeolocationImplementation --disable-features=AutofillEnableAccountWalletStorage,AutofillServerCommunication,DirectSockets,EnableProfilePickerOnStartup,FederatedLearningOfCohorts,FirstPartySets,FledgeInterestGroupAPI,FledgeInterestGroups,FlocIdComputedEventLogging,HandwritingRecognitionWebPlatformApi,HandwritingRecognitionWebPlatformApiFinch,IdleDetection,InterestCohortAPIOriginTrial,InterestCohortFeaturePolicy,LangClientHintHeader,LiveCaption,NetworkTimeServiceQuerying,NotificationTriggers,SharingQRCodeGenerator,SignedExchangePrefetchCacheForNavigations,SignedExchangeSubresourcePrefetch,SubresourceWebBundles,TabHoverCards,TextFragmentAnchor,TrustTokens,WebOTP --lang=fr --service-sandbox-type=proxy_resolver --mojo-platform-channel-handle=3872 /prefetch:8 [Running Processes] :HKLM C:\WINDOWS\SYSTEMAPPS\MICROSOFTWINDOWS.CLIENT.CBS_CW5N1H2TXYEWY\INPUTAPP\TEXTINPUTHOST.EXE ### Microsoft Corporation Microsoft® Windows® Operating System 2001.22012.0.2020 !$*"C:\WINDOWS\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\InputApp\TextInputHost.exe" -ServerName:InputApp.AppX9jnwykgrccxc8by3hsrsh07r423xzvav.mca [Running Processes] :HKLM C:\PROGRAM FILES\BRAVESOFTWARE\BRAVE-BROWSER\APPLICATION\BRAVE.EXE ### Brave Browser Brave Software, Inc. Brave Browser 91.1.25.73 ->BRAVE_EXE !$*"C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe" --type=utility --utility-sub-type=bat_ads.mojom.BatAdsService --field-trial-handle=1700,16814878375827632891,6835281291522425617,131072 --enable-features=AutoupgradeMixedContent,LegacyTLSEnforced,PasswordImport,PrefetchPrivacyChanges,ReducedReferrerGranularity,SafetyTip,WebUIDarkMode,WinrtGeolocationImplementation --disable-features=AutofillEnableAccountWalletStorage,AutofillServerCommunication,DirectSockets,EnableProfilePickerOnStartup,FederatedLearningOfCohorts,FirstPartySets,FledgeInterestGroupAPI,FledgeInterestGroups,FlocIdComputedEventLogging,HandwritingRecognitionWebPlatformApi,HandwritingRecognitionWebPlatformApiFinch,IdleDetection,InterestCohortAPIOriginTrial,InterestCohortFeaturePolicy,LangClientHintHeader,LiveCaption,NetworkTimeServiceQuerying,NotificationTriggers,SharingQRCodeGenerator,SignedExchangePrefetchCacheForNavigations,SignedExchangeSubresourcePrefetch,SubresourceWebBundles,TabHoverCards,TextFragmentAnchor,TrustTokens,WebOTP --lang=fr --service-sandbox-type=utility --mojo-platform-channel-handle=4932 /prefetch:8 [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\APPLICATIONFRAMEHOST.EXE ### Application Frame Host Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.746 ->APPLICATION FRAME HOST !$*C:\WINDOWS\system32\ApplicationFrameHost.exe -Embedding [Running Processes] :HKLM C:\PROGRAM FILES\WINDOWSAPPS\MICROSOFT.WINDOWSSTORE_12011.1001.1.0_X64__8WEKYB3D8BBWE\WINSTORE.APP.EXE ### Store Microsoft Corporation Windows Store 12011.1001.1.0 !$*"C:\Program Files\WindowsApps\Microsoft.WindowsStore_12011.1001.1.0_x64__8wekyb3d8bbwe\WinStore.App.exe" -ServerName:App.AppXc75wvwned5vhz4xyxxecvgdjhdkgsdza.mca [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\RUNTIMEBROKER.EXE ### Runtime Broker Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.746 !$*C:\Windows\System32\RuntimeBroker.exe -Embedding [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s wlidsvc [Running Processes] :HKLM C:\PROGRAM FILES\BRAVESOFTWARE\BRAVE-BROWSER\APPLICATION\BRAVE.EXE ### Brave Browser Brave Software, Inc. Brave Browser 91.1.25.73 ->BRAVE_EXE !$*"C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe" --type=renderer --field-trial-handle=1700,16814878375827632891,6835281291522425617,131072 --enable-features=AutoupgradeMixedContent,LegacyTLSEnforced,PasswordImport,PrefetchPrivacyChanges,ReducedReferrerGranularity,SafetyTip,WebUIDarkMode,WinrtGeolocationImplementation --disable-features=AutofillEnableAccountWalletStorage,AutofillServerCommunication,DirectSockets,EnableProfilePickerOnStartup,FederatedLearningOfCohorts,FirstPartySets,FledgeInterestGroupAPI,FledgeInterestGroups,FlocIdComputedEventLogging,HandwritingRecognitionWebPlatformApi,HandwritingRecognitionWebPlatformApiFinch,IdleDetection,InterestCohortAPIOriginTrial,InterestCohortFeaturePolicy,LangClientHintHeader,LiveCaption,NetworkTimeServiceQuerying,NotificationTriggers,SharingQRCodeGenerator,SignedExchangePrefetchCacheForNavigations,SignedExchangeSubresourcePrefetch,SubresourceWebBundles,TabHoverCards,TextFragmentAnchor,TrustTokens,WebOTP --lang=fr --origin-trial-public-key=bYUKPJoPnCxeNvu72j4EmPuK7tr1PAC7SHh8ld9Mw3E=,fMS4mpO6buLQ/QMd+zJmxzty/VQ6B1EUZqoCU04zoRU= --brave_session_token=6704221578705972092 --device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-activation --renderer-client-id=13 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=664 /prefetch:1 [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\DLLHOST.EXE ### COM Surrogate Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.546 !$*C:\WINDOWS\system32\DllHost.exe /Processid:{973D20D7-562D-44B9-B70B-5A0F49CCDF3F} [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\RUNTIMEBROKER.EXE ### Runtime Broker Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.746 !$*C:\Windows\System32\RuntimeBroker.exe -Embedding [Running Processes] :HKLM C:\PROGRAM FILES\BRAVESOFTWARE\BRAVE-BROWSER\APPLICATION\BRAVE.EXE ### Brave Browser Brave Software, Inc. Brave Browser 91.1.25.73 ->BRAVE_EXE !$*"C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe" --type=renderer --field-trial-handle=1700,16814878375827632891,6835281291522425617,131072 --enable-features=AutoupgradeMixedContent,LegacyTLSEnforced,PasswordImport,PrefetchPrivacyChanges,ReducedReferrerGranularity,SafetyTip,WebUIDarkMode,WinrtGeolocationImplementation --disable-features=AutofillEnableAccountWalletStorage,AutofillServerCommunication,DirectSockets,EnableProfilePickerOnStartup,FederatedLearningOfCohorts,FirstPartySets,FledgeInterestGroupAPI,FledgeInterestGroups,FlocIdComputedEventLogging,HandwritingRecognitionWebPlatformApi,HandwritingRecognitionWebPlatformApiFinch,IdleDetection,InterestCohortAPIOriginTrial,InterestCohortFeaturePolicy,LangClientHintHeader,LiveCaption,NetworkTimeServiceQuerying,NotificationTriggers,SharingQRCodeGenerator,SignedExchangePrefetchCacheForNavigations,SignedExchangeSubresourcePrefetch,SubresourceWebBundles,TabHoverCards,TextFragmentAnchor,TrustTokens,WebOTP --lang=fr --origin-trial-public-key=bYUKPJoPnCxeNvu72j4EmPuK7tr1PAC7SHh8ld9Mw3E=,fMS4mpO6buLQ/QMd+zJmxzty/VQ6B1EUZqoCU04zoRU= --brave_session_token=6704221578705972092 --device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-activation --renderer-client-id=14 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=3496 /prefetch:1 [Running Processes] :HKLM C:\PROGRAM FILES\BRAVESOFTWARE\BRAVE-BROWSER\APPLICATION\BRAVE.EXE ### Brave Browser Brave Software, Inc. Brave Browser 91.1.25.73 ->BRAVE_EXE !$*"C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe" --type=renderer --field-trial-handle=1700,16814878375827632891,6835281291522425617,131072 --enable-features=AutoupgradeMixedContent,LegacyTLSEnforced,PasswordImport,PrefetchPrivacyChanges,ReducedReferrerGranularity,SafetyTip,WebUIDarkMode,WinrtGeolocationImplementation --disable-features=AutofillEnableAccountWalletStorage,AutofillServerCommunication,DirectSockets,EnableProfilePickerOnStartup,FederatedLearningOfCohorts,FirstPartySets,FledgeInterestGroupAPI,FledgeInterestGroups,FlocIdComputedEventLogging,HandwritingRecognitionWebPlatformApi,HandwritingRecognitionWebPlatformApiFinch,IdleDetection,InterestCohortAPIOriginTrial,InterestCohortFeaturePolicy,LangClientHintHeader,LiveCaption,NetworkTimeServiceQuerying,NotificationTriggers,SharingQRCodeGenerator,SignedExchangePrefetchCacheForNavigations,SignedExchangeSubresourcePrefetch,SubresourceWebBundles,TabHoverCards,TextFragmentAnchor,TrustTokens,WebOTP --lang=fr --origin-trial-public-key=bYUKPJoPnCxeNvu72j4EmPuK7tr1PAC7SHh8ld9Mw3E=,fMS4mpO6buLQ/QMd+zJmxzty/VQ6B1EUZqoCU04zoRU= --start-stack-profiler --brave_session_token=6704221578705972092 --device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-activation --renderer-client-id=15 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=5524 /prefetch:1 [Running Processes] :HKLM C:\PROGRAM FILES\BRAVESOFTWARE\BRAVE-BROWSER\APPLICATION\BRAVE.EXE ### Brave Browser Brave Software, Inc. Brave Browser 91.1.25.73 ->BRAVE_EXE !$*"C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe" --type=renderer --field-trial-handle=1700,16814878375827632891,6835281291522425617,131072 --enable-features=AutoupgradeMixedContent,LegacyTLSEnforced,PasswordImport,PrefetchPrivacyChanges,ReducedReferrerGranularity,SafetyTip,WebUIDarkMode,WinrtGeolocationImplementation --disable-features=AutofillEnableAccountWalletStorage,AutofillServerCommunication,DirectSockets,EnableProfilePickerOnStartup,FederatedLearningOfCohorts,FirstPartySets,FledgeInterestGroupAPI,FledgeInterestGroups,FlocIdComputedEventLogging,HandwritingRecognitionWebPlatformApi,HandwritingRecognitionWebPlatformApiFinch,IdleDetection,InterestCohortAPIOriginTrial,InterestCohortFeaturePolicy,LangClientHintHeader,LiveCaption,NetworkTimeServiceQuerying,NotificationTriggers,SharingQRCodeGenerator,SignedExchangePrefetchCacheForNavigations,SignedExchangeSubresourcePrefetch,SubresourceWebBundles,TabHoverCards,TextFragmentAnchor,TrustTokens,WebOTP --lang=fr --origin-trial-public-key=bYUKPJoPnCxeNvu72j4EmPuK7tr1PAC7SHh8ld9Mw3E=,fMS4mpO6buLQ/QMd+zJmxzty/VQ6B1EUZqoCU04zoRU= --brave_session_token=6704221578705972092 --device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-activation --renderer-client-id=16 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=5540 /prefetch:1 [Running Processes] :HKLM C:\PROGRAM FILES\BRAVESOFTWARE\BRAVE-BROWSER\APPLICATION\BRAVE.EXE ### Brave Browser Brave Software, Inc. Brave Browser 91.1.25.73 ->BRAVE_EXE !$*"C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe" --type=renderer --field-trial-handle=1700,16814878375827632891,6835281291522425617,131072 --enable-features=AutoupgradeMixedContent,LegacyTLSEnforced,PasswordImport,PrefetchPrivacyChanges,ReducedReferrerGranularity,SafetyTip,WebUIDarkMode,WinrtGeolocationImplementation --disable-features=AutofillEnableAccountWalletStorage,AutofillServerCommunication,DirectSockets,EnableProfilePickerOnStartup,FederatedLearningOfCohorts,FirstPartySets,FledgeInterestGroupAPI,FledgeInterestGroups,FlocIdComputedEventLogging,HandwritingRecognitionWebPlatformApi,HandwritingRecognitionWebPlatformApiFinch,IdleDetection,InterestCohortAPIOriginTrial,InterestCohortFeaturePolicy,LangClientHintHeader,LiveCaption,NetworkTimeServiceQuerying,NotificationTriggers,SharingQRCodeGenerator,SignedExchangePrefetchCacheForNavigations,SignedExchangeSubresourcePrefetch,SubresourceWebBundles,TabHoverCards,TextFragmentAnchor,TrustTokens,WebOTP --lang=fr --origin-trial-public-key=bYUKPJoPnCxeNvu72j4EmPuK7tr1PAC7SHh8ld9Mw3E=,fMS4mpO6buLQ/QMd+zJmxzty/VQ6B1EUZqoCU04zoRU= --brave_session_token=6704221578705972092 --device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-activation --renderer-client-id=17 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=5292 /prefetch:1 [Running Processes] :HKLM C:\PROGRAM FILES\BRAVESOFTWARE\BRAVE-BROWSER\APPLICATION\BRAVE.EXE ### Brave Browser Brave Software, Inc. Brave Browser 91.1.25.73 ->BRAVE_EXE !$*"C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe" --type=renderer --field-trial-handle=1700,16814878375827632891,6835281291522425617,131072 --enable-features=AutoupgradeMixedContent,LegacyTLSEnforced,PasswordImport,PrefetchPrivacyChanges,ReducedReferrerGranularity,SafetyTip,WebUIDarkMode,WinrtGeolocationImplementation --disable-features=AutofillEnableAccountWalletStorage,AutofillServerCommunication,DirectSockets,EnableProfilePickerOnStartup,FederatedLearningOfCohorts,FirstPartySets,FledgeInterestGroupAPI,FledgeInterestGroups,FlocIdComputedEventLogging,HandwritingRecognitionWebPlatformApi,HandwritingRecognitionWebPlatformApiFinch,IdleDetection,InterestCohortAPIOriginTrial,InterestCohortFeaturePolicy,LangClientHintHeader,LiveCaption,NetworkTimeServiceQuerying,NotificationTriggers,SharingQRCodeGenerator,SignedExchangePrefetchCacheForNavigations,SignedExchangeSubresourcePrefetch,SubresourceWebBundles,TabHoverCards,TextFragmentAnchor,TrustTokens,WebOTP --lang=fr --origin-trial-public-key=bYUKPJoPnCxeNvu72j4EmPuK7tr1PAC7SHh8ld9Mw3E=,fMS4mpO6buLQ/QMd+zJmxzty/VQ6B1EUZqoCU04zoRU= --brave_session_token=6704221578705972092 --device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-activation --renderer-client-id=23 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=6228 /prefetch:1 [Running Processes] :HKLM C:\PROGRAM FILES\BRAVESOFTWARE\BRAVE-BROWSER\APPLICATION\BRAVE.EXE ### Brave Browser Brave Software, Inc. Brave Browser 91.1.25.73 ->BRAVE_EXE !$*"C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe" --type=renderer --field-trial-handle=1700,16814878375827632891,6835281291522425617,131072 --enable-features=AutoupgradeMixedContent,LegacyTLSEnforced,PasswordImport,PrefetchPrivacyChanges,ReducedReferrerGranularity,SafetyTip,WebUIDarkMode,WinrtGeolocationImplementation --disable-features=AutofillEnableAccountWalletStorage,AutofillServerCommunication,DirectSockets,EnableProfilePickerOnStartup,FederatedLearningOfCohorts,FirstPartySets,FledgeInterestGroupAPI,FledgeInterestGroups,FlocIdComputedEventLogging,HandwritingRecognitionWebPlatformApi,HandwritingRecognitionWebPlatformApiFinch,IdleDetection,InterestCohortAPIOriginTrial,InterestCohortFeaturePolicy,LangClientHintHeader,LiveCaption,NetworkTimeServiceQuerying,NotificationTriggers,SharingQRCodeGenerator,SignedExchangePrefetchCacheForNavigations,SignedExchangeSubresourcePrefetch,SubresourceWebBundles,TabHoverCards,TextFragmentAnchor,TrustTokens,WebOTP --lang=fr --origin-trial-public-key=bYUKPJoPnCxeNvu72j4EmPuK7tr1PAC7SHh8ld9Mw3E=,fMS4mpO6buLQ/QMd+zJmxzty/VQ6B1EUZqoCU04zoRU= --start-stack-profiler --brave_session_token=6704221578705972092 --device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-activation --renderer-client-id=24 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=6232 /prefetch:1 [Running Processes] :HKLM C:\PROGRAM FILES\BRAVESOFTWARE\BRAVE-BROWSER\APPLICATION\BRAVE.EXE ### Brave Browser Brave Software, Inc. Brave Browser 91.1.25.73 ->BRAVE_EXE !$*"C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe" --type=renderer --field-trial-handle=1700,16814878375827632891,6835281291522425617,131072 --enable-features=AutoupgradeMixedContent,LegacyTLSEnforced,PasswordImport,PrefetchPrivacyChanges,ReducedReferrerGranularity,SafetyTip,WebUIDarkMode,WinrtGeolocationImplementation --disable-features=AutofillEnableAccountWalletStorage,AutofillServerCommunication,DirectSockets,EnableProfilePickerOnStartup,FederatedLearningOfCohorts,FirstPartySets,FledgeInterestGroupAPI,FledgeInterestGroups,FlocIdComputedEventLogging,HandwritingRecognitionWebPlatformApi,HandwritingRecognitionWebPlatformApiFinch,IdleDetection,InterestCohortAPIOriginTrial,InterestCohortFeaturePolicy,LangClientHintHeader,LiveCaption,NetworkTimeServiceQuerying,NotificationTriggers,SharingQRCodeGenerator,SignedExchangePrefetchCacheForNavigations,SignedExchangeSubresourcePrefetch,SubresourceWebBundles,TabHoverCards,TextFragmentAnchor,TrustTokens,WebOTP --lang=fr --origin-trial-public-key=bYUKPJoPnCxeNvu72j4EmPuK7tr1PAC7SHh8ld9Mw3E=,fMS4mpO6buLQ/QMd+zJmxzty/VQ6B1EUZqoCU04zoRU= --brave_session_token=6704221578705972092 --device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-activation --renderer-client-id=25 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=6744 /prefetch:1 [Running Processes] :HKLM C:\PROGRAM FILES\BRAVESOFTWARE\BRAVE-BROWSER\APPLICATION\BRAVE.EXE ### Brave Browser Brave Software, Inc. Brave Browser 91.1.25.73 ->BRAVE_EXE !$*"C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe" --type=renderer --field-trial-handle=1700,16814878375827632891,6835281291522425617,131072 --enable-features=AutoupgradeMixedContent,LegacyTLSEnforced,PasswordImport,PrefetchPrivacyChanges,ReducedReferrerGranularity,SafetyTip,WebUIDarkMode,WinrtGeolocationImplementation --disable-features=AutofillEnableAccountWalletStorage,AutofillServerCommunication,DirectSockets,EnableProfilePickerOnStartup,FederatedLearningOfCohorts,FirstPartySets,FledgeInterestGroupAPI,FledgeInterestGroups,FlocIdComputedEventLogging,HandwritingRecognitionWebPlatformApi,HandwritingRecognitionWebPlatformApiFinch,IdleDetection,InterestCohortAPIOriginTrial,InterestCohortFeaturePolicy,LangClientHintHeader,LiveCaption,NetworkTimeServiceQuerying,NotificationTriggers,SharingQRCodeGenerator,SignedExchangePrefetchCacheForNavigations,SignedExchangeSubresourcePrefetch,SubresourceWebBundles,TabHoverCards,TextFragmentAnchor,TrustTokens,WebOTP --lang=fr --origin-trial-public-key=bYUKPJoPnCxeNvu72j4EmPuK7tr1PAC7SHh8ld9Mw3E=,fMS4mpO6buLQ/QMd+zJmxzty/VQ6B1EUZqoCU04zoRU= --start-stack-profiler --brave_session_token=6704221578705972092 --device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-activation --renderer-client-id=29 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=6936 /prefetch:1 [Running Processes] :HKLM C:\PROGRAM FILES\BRAVESOFTWARE\BRAVE-BROWSER\APPLICATION\BRAVE.EXE ### Brave Browser Brave Software, Inc. Brave Browser 91.1.25.73 ->BRAVE_EXE !$*"C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe" --type=renderer --field-trial-handle=1700,16814878375827632891,6835281291522425617,131072 --enable-features=AutoupgradeMixedContent,LegacyTLSEnforced,PasswordImport,PrefetchPrivacyChanges,ReducedReferrerGranularity,SafetyTip,WebUIDarkMode,WinrtGeolocationImplementation --disable-features=AutofillEnableAccountWalletStorage,AutofillServerCommunication,DirectSockets,EnableProfilePickerOnStartup,FederatedLearningOfCohorts,FirstPartySets,FledgeInterestGroupAPI,FledgeInterestGroups,FlocIdComputedEventLogging,HandwritingRecognitionWebPlatformApi,HandwritingRecognitionWebPlatformApiFinch,IdleDetection,InterestCohortAPIOriginTrial,InterestCohortFeaturePolicy,LangClientHintHeader,LiveCaption,NetworkTimeServiceQuerying,NotificationTriggers,SharingQRCodeGenerator,SignedExchangePrefetchCacheForNavigations,SignedExchangeSubresourcePrefetch,SubresourceWebBundles,TabHoverCards,TextFragmentAnchor,TrustTokens,WebOTP --lang=fr --origin-trial-public-key=bYUKPJoPnCxeNvu72j4EmPuK7tr1PAC7SHh8ld9Mw3E=,fMS4mpO6buLQ/QMd+zJmxzty/VQ6B1EUZqoCU04zoRU= --start-stack-profiler --brave_session_token=6704221578705972092 --device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-activation --renderer-client-id=31 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=6708 /prefetch:1 [Running Processes] :HKLM C:\PROGRAM FILES\BRAVESOFTWARE\BRAVE-BROWSER\APPLICATION\BRAVE.EXE ### Brave Browser Brave Software, Inc. Brave Browser 91.1.25.73 ->BRAVE_EXE !$*"C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe" --type=renderer --field-trial-handle=1700,16814878375827632891,6835281291522425617,131072 --enable-features=AutoupgradeMixedContent,LegacyTLSEnforced,PasswordImport,PrefetchPrivacyChanges,ReducedReferrerGranularity,SafetyTip,WebUIDarkMode,WinrtGeolocationImplementation --disable-features=AutofillEnableAccountWalletStorage,AutofillServerCommunication,DirectSockets,EnableProfilePickerOnStartup,FederatedLearningOfCohorts,FirstPartySets,FledgeInterestGroupAPI,FledgeInterestGroups,FlocIdComputedEventLogging,HandwritingRecognitionWebPlatformApi,HandwritingRecognitionWebPlatformApiFinch,IdleDetection,InterestCohortAPIOriginTrial,InterestCohortFeaturePolicy,LangClientHintHeader,LiveCaption,NetworkTimeServiceQuerying,NotificationTriggers,SharingQRCodeGenerator,SignedExchangePrefetchCacheForNavigations,SignedExchangeSubresourcePrefetch,SubresourceWebBundles,TabHoverCards,TextFragmentAnchor,TrustTokens,WebOTP --lang=fr --origin-trial-public-key=bYUKPJoPnCxeNvu72j4EmPuK7tr1PAC7SHh8ld9Mw3E=,fMS4mpO6buLQ/QMd+zJmxzty/VQ6B1EUZqoCU04zoRU= --start-stack-profiler --brave_session_token=6704221578705972092 --device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-activation --renderer-client-id=32 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=7068 /prefetch:1 [Running Processes] :HKLM C:\PROGRAM FILES\BRAVESOFTWARE\BRAVE-BROWSER\APPLICATION\BRAVE.EXE ### Brave Browser Brave Software, Inc. Brave Browser 91.1.25.73 ->BRAVE_EXE !$*"C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe" --type=renderer --field-trial-handle=1700,16814878375827632891,6835281291522425617,131072 --enable-features=AutoupgradeMixedContent,LegacyTLSEnforced,PasswordImport,PrefetchPrivacyChanges,ReducedReferrerGranularity,SafetyTip,WebUIDarkMode,WinrtGeolocationImplementation --disable-features=AutofillEnableAccountWalletStorage,AutofillServerCommunication,DirectSockets,EnableProfilePickerOnStartup,FederatedLearningOfCohorts,FirstPartySets,FledgeInterestGroupAPI,FledgeInterestGroups,FlocIdComputedEventLogging,HandwritingRecognitionWebPlatformApi,HandwritingRecognitionWebPlatformApiFinch,IdleDetection,InterestCohortAPIOriginTrial,InterestCohortFeaturePolicy,LangClientHintHeader,LiveCaption,NetworkTimeServiceQuerying,NotificationTriggers,SharingQRCodeGenerator,SignedExchangePrefetchCacheForNavigations,SignedExchangeSubresourcePrefetch,SubresourceWebBundles,TabHoverCards,TextFragmentAnchor,TrustTokens,WebOTP --lang=fr --origin-trial-public-key=bYUKPJoPnCxeNvu72j4EmPuK7tr1PAC7SHh8ld9Mw3E=,fMS4mpO6buLQ/QMd+zJmxzty/VQ6B1EUZqoCU04zoRU= --brave_session_token=6704221578705972092 --device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-activation --renderer-client-id=33 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=7208 /prefetch:1 [Running Processes] :HKLM C:\PROGRAM FILES\DAEMON TOOLS LITE\DTSHELLHLP.EXE ### DAEMON Tools Shell Extensions Helper Disc Soft Ltd DAEMON Tools Lite 10.14.0.1709 !$*"C:\Program Files\DAEMON Tools Lite\DTShellHlp.exe" [Running Processes] :HKLM C:\PROGRAM FILES\DAEMON TOOLS LITE\DISCSOFTBUSSERVICELITE.EXE ### Disc Soft Bus Service Lite Disc Soft Ltd DAEMON Tools Lite 10.14.0.1709 !$*"C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe" [Running Processes] :HKLM C:\PROGRAM FILES\BRAVESOFTWARE\BRAVE-BROWSER\APPLICATION\BRAVE.EXE ### Brave Browser Brave Software, Inc. Brave Browser 91.1.25.73 ->BRAVE_EXE !$*"C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe" --type=renderer --field-trial-handle=1700,16814878375827632891,6835281291522425617,131072 --enable-features=AutoupgradeMixedContent,LegacyTLSEnforced,PasswordImport,PrefetchPrivacyChanges,ReducedReferrerGranularity,SafetyTip,WebUIDarkMode,WinrtGeolocationImplementation --disable-features=AutofillEnableAccountWalletStorage,AutofillServerCommunication,DirectSockets,EnableProfilePickerOnStartup,FederatedLearningOfCohorts,FirstPartySets,FledgeInterestGroupAPI,FledgeInterestGroups,FlocIdComputedEventLogging,HandwritingRecognitionWebPlatformApi,HandwritingRecognitionWebPlatformApiFinch,IdleDetection,InterestCohortAPIOriginTrial,InterestCohortFeaturePolicy,LangClientHintHeader,LiveCaption,NetworkTimeServiceQuerying,NotificationTriggers,SharingQRCodeGenerator,SignedExchangePrefetchCacheForNavigations,SignedExchangeSubresourcePrefetch,SubresourceWebBundles,TabHoverCards,TextFragmentAnchor,TrustTokens,WebOTP --lang=fr --origin-trial-public-key=bYUKPJoPnCxeNvu72j4EmPuK7tr1PAC7SHh8ld9Mw3E=,fMS4mpO6buLQ/QMd+zJmxzty/VQ6B1EUZqoCU04zoRU= --brave_session_token=6704221578705972092 --device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-activation --renderer-client-id=37 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=7956 /prefetch:1 [Running Processes] :HKLM D:\PROGRAM FILES (X86)\GREATIS\REANIMATOR\REANIMATOR.EXE ### RegRun Start Control Greatis Software RegRun Security Suite 12.60 ->REGRUN2.EXE !$*"D:\Program Files (x86)\Greatis\Reanimator\reanimator.exe" [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SEARCHPROTOCOLHOST.EXE ### Microsoft Windows Search Protocol Host Microsoft Corporation Windows® Search 7.0.19041.1023 !$*"C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe1_ Global\UsGthrCtrlFltPipeMssGthrPipe1 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" [Running Processes] :HKLM C:\WINDOWS\SYSTEM32\SEARCHFILTERHOST.EXE ### Microsoft Windows Search Filter Host Microsoft Corporation Windows® Search 7.0.19041.1023 !$*"C:\WINDOWS\system32\SearchFilterHost.exe" 0 808 812 820 8192 816 792 [Running Services] Appinfo ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k netsvcs -p Service registry key doesn't exist or hidden. [Running Services] AppXSvc ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k wsappx -p Service registry key doesn't exist or hidden. [Running Services] AudioEndpointBuilder ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -p Service registry key doesn't exist or hidden. [Running Services] Audiosrv ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted -p Service registry key doesn't exist or hidden. [Running Services] BFE ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetworkFirewall -p Service registry key doesn't exist or hidden. [Running Services] BrokerInfrastructure ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k DcomLaunch -p Service registry key doesn't exist or hidden. [Running Services] BthAvctpSvc ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k LocalService -p Service registry key doesn't exist or hidden. [Running Services] camsvc ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k appmodel -p Service registry key doesn't exist or hidden. [Running Services] CDPSvc ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k LocalService -p Service registry key doesn't exist or hidden. [Running Services] ClipSVC ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\System32\svchost.exe -k wsappx -p Service registry key doesn't exist or hidden. [Running Services] CoreMessagingRegistrar ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork -p Service registry key doesn't exist or hidden. [Running Services] CryptSvc ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k NetworkService -p Service registry key doesn't exist or hidden. [Running Services] DcomLaunch ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k DcomLaunch -p Service registry key doesn't exist or hidden. [Running Services] DeviceAssociationService ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted -p Service registry key doesn't exist or hidden. [Running Services] DeviceInstall ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k DcomLaunch -p Service registry key doesn't exist or hidden. [Running Services] DevQueryBroker ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted -p Service registry key doesn't exist or hidden. [Running Services] Dhcp ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted -p Service registry key doesn't exist or hidden. [Running Services] DiagTrack ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\System32\svchost.exe -k utcsvc -p Service registry key doesn't exist or hidden. [Running Services] Disc Soft Lite Bus Service ### Disc Soft Bus Service Lite Disc Soft Ltd DAEMON Tools Lite 10.14.0.1709 !$*"C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe" Service registry key doesn't exist or hidden. [Running Services] DispBrokerDesktopSvc ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k LocalService -p Service registry key doesn't exist or hidden. [Running Services] Dnscache ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k NetworkService -p Service registry key doesn't exist or hidden. [Running Services] DoSvc ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\System32\svchost.exe -k NetworkService -p Service registry key doesn't exist or hidden. [Running Services] DPS ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\System32\svchost.exe -k LocalServiceNoNetwork -p Service registry key doesn't exist or hidden. [Running Services] DusmSvc ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted -p Service registry key doesn't exist or hidden. [Running Services] EFS ### Local Security Authority Process Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.906 !$*C:\WINDOWS\System32\lsass.exe Service registry key doesn't exist or hidden. [Running Services] EventLog ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted -p Service registry key doesn't exist or hidden. [Running Services] EventSystem ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k LocalService -p Service registry key doesn't exist or hidden. [Running Services] fdPHost ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k LocalService -p Service registry key doesn't exist or hidden. [Running Services] FDResPub ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation -p Service registry key doesn't exist or hidden. [Running Services] FontCache ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k LocalService -p Service registry key doesn't exist or hidden. [Running Services] FontCache3.0.0.0 ### PresentationFontCache.exe Microsoft Corporation Microsoft® .NET Framework 3.0.6920.9141 !$*C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe Service registry key doesn't exist or hidden. [Running Services] GamingServices ### GamingServices Microsoft Corporation Microsoft Gaming Install Services 10.0.19041.7259 !$*C:\Program Files\WindowsApps\Microsoft.GamingServices_2.53.17003.0_x64__8wekyb3d8bbwe\GamingServices.exe Service registry key doesn't exist or hidden. [Running Services] GamingServicesNet ### GamingServices Microsoft Corporation Microsoft Gaming Install Services 10.0.19041.7259 !$*C:\Program Files\WindowsApps\Microsoft.GamingServices_2.53.17003.0_x64__8wekyb3d8bbwe\GamingServices.exe Service registry key doesn't exist or hidden. [Running Services] gpsvc ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k netsvcs -p Service registry key doesn't exist or hidden. [Running Services] Hamachi2Svc ### Hamachi Client Tunneling Engine LogMeIn Inc. Hamachi Client 2, 0, 0, 0 ->H2-ENGINE !$*"C:\Program Files (x86)\LogMeIn Hamachi\x64\hamachi-2.exe" -s Service registry key doesn't exist or hidden. [Running Services] hidserv ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted -p Service registry key doesn't exist or hidden. [Running Services] hshld ### Hss.Service.Application AnchorFree Inc. Hotspot Shield 9.21.3.11422 !$*"C:\Program Files (x86)\Hotspot Shield\bin\cmw_srv.exe" Service registry key doesn't exist or hidden. [Running Services] igfxCUIService2.0.0.0 ### igfxCUIService Module Intel Corporation Intel(R) Common User Interface 6.15.10.4624 !$*C:\WINDOWS\system32\igfxCUIService.exe Service registry key doesn't exist or hidden. [Running Services] InstallService ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\System32\svchost.exe -k netsvcs -p Service registry key doesn't exist or hidden. [Running Services] iphlpsvc ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\System32\svchost.exe -k NetSvcs -p Service registry key doesn't exist or hidden. [Running Services] KeyIso ### Local Security Authority Process Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.906 !$*C:\WINDOWS\system32\lsass.exe Service registry key doesn't exist or hidden. [Running Services] LanmanServer ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k netsvcs -p Service registry key doesn't exist or hidden. [Running Services] LanmanWorkstation ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\System32\svchost.exe -k NetworkService -p Service registry key doesn't exist or hidden. [Running Services] LicenseManager ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\System32\svchost.exe -k LocalService -p Service registry key doesn't exist or hidden. [Running Services] lmhosts ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted -p Service registry key doesn't exist or hidden. [Running Services] LMIGuardianSvc ### LMIGuardianSvc LogMeIn, Inc. LMIGuardianSvc 10.1.1742 !$*"C:\Program Files (x86)\LogMeIn Hamachi\x64\LMIGuardianSvc.exe" Service registry key doesn't exist or hidden. [Running Services] LSM ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k DcomLaunch -p Service registry key doesn't exist or hidden. [Running Services] mpssvc ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetworkFirewall -p Service registry key doesn't exist or hidden. [Running Services] NcbService ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -p Service registry key doesn't exist or hidden. [Running Services] NcdAutoSetup ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\System32\svchost.exe -k LocalServiceNoNetwork -p Service registry key doesn't exist or hidden. [Running Services] NetgearA7000 ### Realtek RtlService Application Realtek Semiconductor Corp. Realtek RtlService Application 700, 1007, 509, 2012 !$*C:\Program Files (x86)\NETGEAR\A7000\RtlService.exe Service registry key doesn't exist or hidden. [Running Services] Netman ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -p Service registry key doesn't exist or hidden. [Running Services] netprofm ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\System32\svchost.exe -k LocalService -p Service registry key doesn't exist or hidden. [Running Services] NgcCtnrSvc ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted -p Service registry key doesn't exist or hidden. [Running Services] NgcSvc ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted -p Service registry key doesn't exist or hidden. [Running Services] NlaSvc ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\System32\svchost.exe -k NetworkService -p Service registry key doesn't exist or hidden. [Running Services] nsi ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k LocalService -p Service registry key doesn't exist or hidden. [Running Services] NvContainerLocalSystem ### NVIDIA Container NVIDIA Corporation NVIDIA Container gcomp_dev 28356155 !$*"C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe" -s NvContainerLocalSystem -f "C:\ProgramData\NVIDIA\NvContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\NvContainer\plugins\LocalSystem" -r -p 30000 -st "C:\Program Files\NVIDIA Corporation\NvContainer\NvContainerTelemetryApi.dll" Service registry key doesn't exist or hidden. [Running Services] NVDisplay.ContainerLocalSystem ### NVIDIA Container NVIDIA Corporation NVIDIA Container gcomp_dev 28519944 ->NVCONTAINER =>NVCONTAINER.EXE !$*C:\WINDOWS\System32\DriverStore\FileRepository\nvmdi.inf_amd64_6a0632b60438e56d\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log -l 3 -d C:\WINDOWS\System32\DriverStore\FileRepository\nvmdi.inf_amd64_6a0632b60438e56d\Display.NvContainer\plugins\LocalSystem -r -p 30000 -cfg NVDisplay.ContainerLocalSystem\LocalSystem Service registry key doesn't exist or hidden. [Running Services] OVRService ### OVR Service Launcher Facebook Technologies, LLC OVR Service Launcher 29.0.0.54.528 !$*"D:\Oculus\Support\oculus-runtime\OVRServiceLauncher.exe" Service registry key doesn't exist or hidden. [Running Services] PcaSvc ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted -p Service registry key doesn't exist or hidden. [Running Services] PlugPlay ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k DcomLaunch -p Service registry key doesn't exist or hidden. [Running Services] PolicyAgent ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k NetworkServiceNetworkRestricted -p Service registry key doesn't exist or hidden. [Running Services] Power ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k DcomLaunch -p Service registry key doesn't exist or hidden. [Running Services] ProfSvc ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k netsvcs -p Service registry key doesn't exist or hidden. [Running Services] RasMan ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\System32\svchost.exe -k netsvcs Service registry key doesn't exist or hidden. [Running Services] RmSvc ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted Service registry key doesn't exist or hidden. [Running Services] RpcEptMapper ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k RPCSS -p Service registry key doesn't exist or hidden. [Running Services] RpcSs ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k rpcss -p Service registry key doesn't exist or hidden. [Running Services] RunSwUSB ### runSW Application 1, 1005, 415, 2014 !$*C:\Windows\runSW.exe Service registry key doesn't exist or hidden. [Running Services] SamSs ### Local Security Authority Process Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.906 !$*C:\WINDOWS\system32\lsass.exe Service registry key doesn't exist or hidden. [Running Services] Schedule ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k netsvcs -p Service registry key doesn't exist or hidden. [Running Services] SecurityHealthService ### Windows Security Health Service Microsoft Corporation Microsoft® Windows® Operating System 4.18.1907.16384 !$*C:\WINDOWS\system32\SecurityHealthService.exe Service registry key doesn't exist or hidden. [Running Services] SEMgrSvc ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k LocalService -p Service registry key doesn't exist or hidden. [Running Services] SENS ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k netsvcs -p Service registry key doesn't exist or hidden. [Running Services] SgrmBroker ### Service Broker du moniteur d'exécution System Guard Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\SgrmBroker.exe Service registry key doesn't exist or hidden. [Running Services] ShellHWDetection ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\System32\svchost.exe -k netsvcs -p Service registry key doesn't exist or hidden. [Running Services] Spooler ### Application sous-système spouleur Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\System32\spoolsv.exe Service registry key doesn't exist or hidden. [Running Services] SSDPSRV ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation -p Service registry key doesn't exist or hidden. [Running Services] SstpSvc ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k LocalService -p Service registry key doesn't exist or hidden. [Running Services] StateRepository ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k appmodel -p Service registry key doesn't exist or hidden. [Running Services] stisvc ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k imgsvc Service registry key doesn't exist or hidden. [Running Services] StorSvc ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -p Service registry key doesn't exist or hidden. [Running Services] SysMain ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted -p Service registry key doesn't exist or hidden. [Running Services] SystemEventsBroker ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k DcomLaunch -p Service registry key doesn't exist or hidden. [Running Services] TabletInputService ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -p Service registry key doesn't exist or hidden. [Running Services] TeamViewer ### TeamViewer TeamViewer Germany GmbH TeamViewer 15.16.8.0 ->TEAMVIEWER !$*"C:\Program Files\TeamViewer\TeamViewer_Service.exe" Service registry key doesn't exist or hidden. [Running Services] Themes ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\System32\svchost.exe -k netsvcs -p Service registry key doesn't exist or hidden. [Running Services] TimeBrokerSvc ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted -p Service registry key doesn't exist or hidden. [Running Services] TokenBroker ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k netsvcs -p Service registry key doesn't exist or hidden. [Running Services] TrkWks ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -p Service registry key doesn't exist or hidden. [Running Services] UserManager ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k netsvcs -p Service registry key doesn't exist or hidden. [Running Services] UsoSvc ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k netsvcs -p Service registry key doesn't exist or hidden. [Running Services] VaultSvc ### Local Security Authority Process Microsoft Corporation Microsoft® Windows® Operating System 10.0.19041.906 !$*C:\WINDOWS\system32\lsass.exe Service registry key doesn't exist or hidden. [Running Services] VirtualDesktop.Service.exe ### Virtual Desktop Service Virtual Desktop, Inc. Virtual Desktop 1.18.5.0 !$*"C:\Program Files\Virtual Desktop\VirtualDesktop.Service.exe" Service registry key doesn't exist or hidden. [Running Services] Wallpaper Engine Service ### !$*"D:\SteamLibrary\steamapps\common\wallpaper_engine\bin\wallpaperservice32_c.exe" Service registry key doesn't exist or hidden. [Running Services] WbioSrvc ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k WbioSvcGroup Service registry key doesn't exist or hidden. [Running Services] Wcmsvc ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted -p Service registry key doesn't exist or hidden. [Running Services] WdiServiceHost ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\System32\svchost.exe -k LocalService -p Service registry key doesn't exist or hidden. [Running Services] WdiSystemHost ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -p Service registry key doesn't exist or hidden. [Running Services] WdNisSvc ### Microsoft Network Realtime Inspection Service Microsoft Corporation Microsoft® Windows® Operating System 4.18.2105.5 !$*"C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2105.5-0\NisSrv.exe" Service registry key doesn't exist or hidden. [Running Services] WinDefend ### Antimalware Service Executable Microsoft Corporation Microsoft® Windows® Operating System 4.18.2105.5 !$*"C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2105.5-0\MsMpEng.exe" Service registry key doesn't exist or hidden. [Running Services] WinHttpAutoProxySvc ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted -p Service registry key doesn't exist or hidden. [Running Services] Winmgmt ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k netsvcs -p Service registry key doesn't exist or hidden. [Running Services] WlanSvc ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted -p Service registry key doesn't exist or hidden. [Running Services] wlidsvc ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k netsvcs -p Service registry key doesn't exist or hidden. [Running Services] WpnService ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k netsvcs -p Service registry key doesn't exist or hidden. [Running Services] wscsvc ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted -p Service registry key doesn't exist or hidden. [Running Services] WSearch ### Indexeur Microsoft Windows Search Microsoft Corporation Windows® Search 7.0.19041.867 !$*C:\WINDOWS\system32\SearchIndexer.exe /Embedding Service registry key doesn't exist or hidden. [Running Services] wuauserv ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k netsvcs -p Service registry key doesn't exist or hidden. [Running Services] XblAuthManager ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k netsvcs -p Service registry key doesn't exist or hidden. [Running Services] ZeroTierOneService ### !$*C:\ProgramData\ZeroTier\One\zerotier-one_x64.exe Service registry key doesn't exist or hidden. [Running Services] AarSvc_1a8ea6 ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k AarSvcGroup -p Service registry key doesn't exist or hidden. [Running Services] cbdhsvc_1a8ea6 ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k ClipboardSvcGroup -p Service registry key doesn't exist or hidden. [Running Services] CDPUserSvc_1a8ea6 ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup Service registry key doesn't exist or hidden. [Running Services] OneSyncSvc_1a8ea6 ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup Service registry key doesn't exist or hidden. [Running Services] WpnUserService_1a8ea6 ### Processus hôte pour les services Windows Microsoft Corporation Système d’exploitation Microsoft® Windows® 10.0.19041.867 !$*C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup Service registry key doesn't exist or hidden. [Uninstall] [Applications] :HKLM {BD95A8CD-1D9F-35AD-981A-3E7925026EBB}=MsiExec.exe /X{BD95A8CD-1D9F-35AD-981A-3E7925026EBB} ### Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030 - (19) 06-2021 [Applications] :HKLM {B931FB80-537A-4600-00AD-AC5DEDB6C25B}=G:\Games\BFME2WKe\EAUninstall.exe ### L'Avènement du Roi-sorcier™ - (19) 06-2021 [Applications] :HKLM {B175520C-86A2-35A7-8619-86DC379688B9}=MsiExec.exe /X{B175520C-86A2-35A7-8619-86DC379688B9} ### Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030 - (19) 06-2021 [Applications] :HKLM {BEE64C14-BEF1-4610-8A68-A16EAA47B882} ### - (19) 06-2021 [Applications] :HKLM {ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}="C:\ProgramData\Package Cache\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}\vcredist_x64.exe" /uninstall /quiet ### Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 - (19) 06-2021 [Applications] :HKLM {C83D4B4A-C7D0-4C01-995E-17081DAE5CEF}=MsiExec.exe /X{C83D4B4A-C7D0-4C01-995E-17081DAE5CEF} ### Epic Games Launcher - (19) 06-2021 [Applications] :HKLM {BF634210-A0D4-443F-A657-0DCE38040374}_is1="D:\Program Files (x86)\LOOT\unins000.exe" /SILENT ### LOOT version 0.16.1 - (19) 06-2021 [Applications] :HKLM {86493ADD-824D-4B8E-BD72-8C5DCDC52A71}=MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71} ### MSXML 4.0 SP2 (KB954430) - (19) 06-2021 [Applications] :HKLM {855e31d2-9031-46e1-b06d-c9d7777deefb}="C:\ProgramData\Package Cache\{855e31d2-9031-46e1-b06d-c9d7777deefb}\VC_redist.x64.exe" /uninstall /quiet ### Microsoft Visual C++ 2015-2019 Redistributable (x64) - 14.28.29913 - (19) 06-2021 [Applications] :HKLM {7299052b-02a4-4627-81f2-1818da5d550d}=MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d} ### Microsoft Visual C++ 2005 Redistributable - (19) 06-2021 [Applications] :HKLM {911FBC64-4C64-4B8F-A637-B34832638C86}=MsiExec.exe /X{911FBC64-4C64-4B8F-A637-B34832638C86} ### Minecraft Launcher - (19) 06-2021 [Applications] :HKLM {A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}=MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2} ### Google Update Helper - (19) 06-2021 [Applications] :HKLM {9BE518E6-ECC6-35A9-88E4-87755C07200F}=MsiExec.exe /X{9BE518E6-ECC6-35A9-88E4-87755C07200F} ### Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 - (19) 06-2021 [Applications] :HKLM {9A25302D-30C0-39D9-BD6F-21E6EC160475}=MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475} ### Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 - (19) 06-2021 [Applications] :HKLM {D5C69738-B486-402E-85AC-2456D98A64E4}="C:\Windows10Upgrade\Windows10UpgraderApp.exe" /Uninstall ### Assistant Mise à jour de Windows 10 - (19) 06-2021 [Applications] :HKLM {F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB982573 ### - (19) 06-2021 [Applications] :HKLM {F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2565063 ### - (19) 06-2021 [Applications] :HKLM {F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2549743 ### - (19) 06-2021 [Applications] :HKLM {F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}="C:\Program Files (x86)\Intel\Intel(R) Processor Graphics\Uninstall\setup.exe" -uninstall ### Intel(R) Processor Graphics - (19) 06-2021 [Applications] :HKLM {F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}=MsiExec.exe /X{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185} ### Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 - (19) 06-2021 [Applications] :HKLM {F662A8E6-F4DC-41A2-901E-8C11F044BDEC}=MsiExec.exe /I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC} ### MSXML 4.0 SP2 (KB973688) - (19) 06-2021 [Applications] :HKLM {f65db027-aff3-4070-886a-0d87064aabb1}="C:\ProgramData\Package Cache\{f65db027-aff3-4070-886a-0d87064aabb1}\vcredist_x86.exe" /uninstall /quiet ### Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 - (19) 06-2021 [Applications] :HKLM {F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}=MsiExec.exe /X{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5} ### Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 - (19) 06-2021 [Applications] :HKLM {ECC0FA07-863E-44BC-8B1D-DA22F96E5FB7}=MsiExec.exe /I{ECC0FA07-863E-44BC-8B1D-DA22F96E5FB7} ### LogMeIn Hamachi - (19) 06-2021 [Applications] :HKLM {E34F424D-99BB-4176-8BCB-F0A749D744B4}=MsiExec.exe /I{E34F424D-99BB-4176-8BCB-F0A749D744B4} ### NETGEAR A7000 Genie - (19) 06-2021 [Applications] :HKLM {F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2151757 ### - (19) 06-2021 [Applications] :HKLM {F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2544655 ### - (19) 06-2021 [Applications] :HKLM {F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2524860 ### - (19) 06-2021 [Applications] :HKLM {F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2467173 ### - (19) 06-2021 [Applications] :HKLM {7258BA11-600C-430E-A759-27E2C691A335}_is1="C:\Program Files (x86)\GOG Galaxy\unins000.exe" /SILENT ### GOG GALAXY - (19) 06-2021 [Applications] :HKLM {6236EBBD-F50F-40B3-B819-8DB0C608308C}=MsiExec.exe /I{6236EBBD-F50F-40B3-B819-8DB0C608308C} ### Microsoft Visual C++ 2019 X86 Minimum Runtime - 14.28.29913 - (19) 06-2021 [Applications] :HKLM {5EFC6C07-6B87-43FC-9524-F9E967241741}="D:\Program Files\Rockstar Games\Launcher\Launcher.exe" -enableFullMode -uninstall=gta5 ### Grand Theft Auto V - (19) 06-2021 [Applications] :HKLM Microsoft Edge Update ### Microsoft Edge Update - (19) 06-2021 [Applications] :HKLM Microsoft EdgeWebView="C:\Program Files (x86)\Microsoft\EdgeWebView\Application\91.0.864.48\Installer\setup.exe" --uninstall --msedgewebview --system-level --verbose-logging ### Microsoft Edge WebView2 Runtime - (19) 06-2021 [Applications] :HKLM 1971477531_is1="G:\GOG Galaxy\Games\Gwent\unins000.exe" /SILENT ### Gwent - (19) 06-2021 [Applications] :HKLM {572DCD10-CF2E-43D1-8151-8BD9AC9086D0}=MsiExec.exe /I{572DCD10-CF2E-43D1-8151-8BD9AC9086D0} ### Microsoft Visual C++ 2019 X86 Additional Runtime - 14.28.29913 - (19) 06-2021 [Applications] :HKLM {33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}="C:\ProgramData\Package Cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}\vcredist_x86.exe" /uninstall /quiet ### Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 - (19) 06-2021 [Applications] :HKLM {2A9F95AB-65A3-432c-8631-B8BC5BF7477A}=G:\Games\BFME2\EAUninstall.exe ### La Bataille pour la Terre du Milieu™ II - (19) 06-2021 [Applications] :HKLM {2397CAD4-2263-4CD0-96BE-E43A980B9C9A}_is1="D:\Program Files (x86)\Geeks3D\Benchmarks\FurMark\unins000.exe" /SILENT ### Geeks3D FurMark 1.26.0.0 - (19) 06-2021 [Applications] :HKLM {4A03706F-666A-4037-7777-5F2748764D10} ### Java Auto Updater - (19) 06-2021 [Applications] :HKLM {43a03b9c-4770-409c-a999-587b60700b63}="C:\ProgramData\Package Cache\{43a03b9c-4770-409c-a999-587b60700b63}\LauncherPrereqSetup_x64.exe" /uninstall /quiet ### Launcher Prerequisites (x64) - (19) 06-2021 [Applications] :HKLM {3B721AC6-50BD-410C-8E5F-9076234F4C46}=MsiExec.exe /X{3B721AC6-50BD-410C-8E5F-9076234F4C46} ### ZeroTier One - (19) 06-2021 [Applications] :HKLM GameReplaysRotWK="G:\Games\BFME2WKe\uninstall02.exe" ### Rise of the Witch-King 2.02 - (19) 06-2021 [Applications] :HKLM BFME2 Patch Switcher=G:\Games\BFME2 Patch Switcher\BFME2 Patch Switcher\Uninstall.exe ### BFME2 Patch Switcher - (19) 06-2021 [Applications] :HKLM Aomei Partition Assistant_is1=C:\Program Files (x86)\AOMEI Partition Assistant\unins000.exe ### - (19) 06-2021 [Applications] :HKLM Dragon Ball Xenoverse 2_is1="D:\Games\Dragon Ball Xenoverse 2\unins000.exe" /SILENT ### Dragon Ball Xenoverse 2 - (19) 06-2021 [Applications] :HKLM Fallout 4 VR_is1="D:\Program Files (x86)\Fallout 4 VR\unins000.exe" /SILENT ### Fallout 4 VR - (19) 06-2021 [Applications] :HKLM BraveSoftware Brave-Browser="C:\Program Files\BraveSoftware\Brave-Browser\Application\91.1.25.73\Installer\setup.exe" --uninstall --system-level ### Brave - (19) 06-2021 [Applications] :HKLM Age of Empires III - Complete Collection_is1="G:\Games\Age of Empires III - Complete Collection\unins000.exe" /SILENT ### Age of Empires III - Complete Collection - (19) 06-2021 [Applications] :HKLM LogMeIn Hamachi=C:\WINDOWS\SysWOW64\\msiexec.exe /i {ECC0FA07-863E-44BC-8B1D-DA22F96E5FB7} REMOVE=ALL ### LogMeIn Hamachi - (19) 06-2021 [Applications] :HKLM Mass Effect Ultimate Edition_is1="D:\Program Files (x86)\Mass Effect Ultimate Edition\unins000.exe" /SILENT ### Mass Effect Ultimate Edition version 1.02 - (19) 06-2021 [Applications] :HKLM Microsoft Edge="C:\Program Files (x86)\Microsoft\Edge\Application\91.0.864.48\Installer\setup.exe" --uninstall --msedge --system-level --verbose-logging ### Microsoft Edge - (19) 06-2021 [Applications] :HKLM Afterburner="D:\Program Files (x86)\MSI Afterburner\uninstall.exe" ### MSI Afterburner 4.6.4 Beta 3 - (19) 06-2021 [Applications] :HKLM InstallShield Uninstall Information ### - (19) 06-2021 [Applications] :HKLM InstallShield_{E34F424D-99BB-4176-8BCB-F0A749D744B4}="C:\Program Files (x86)\InstallShield Installation Information\{E34F424D-99BB-4176-8BCB-F0A749D744B4}\setup.exe" -runfromtemp -l0x040c -removeonly ### NETGEAR A7000 Genie - (19) 06-2021 [Applications] :HKLM {1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB982573 ### - (19) 06-2021 [Applications] :HKLM Steam=C:\Program Files (x86)\Steam\uninstall.exe ### Steam - (19) 06-2021 [Applications] :HKLM SOULCALIBUR VI_is1="G:\Games\SOULCALIBUR VI\unins000.exe" /SILENT ### SOULCALIBUR VI - (19) 06-2021 [Applications] :HKLM 1207658930_is1="G:\GOG Galaxy\Games\The Witcher 2\unins000.exe" /SILENT ### The Witcher 2 - Assassins of Kings Enhanced Edition - (19) 06-2021 [Applications] :HKLM Unigine Valley Benchmark_is1="D:\Program Files (x86)\Unigine\Valley Benchmark 1.0\unins000.exe" /SILENT ### Unigine Valley Benchmark version 1.0 - (19) 06-2021 [Applications] :HKLM UnHackMe Update - Reanimator_is1="D:\Program Files (x86)\Greatis\Reanimator\unins000.exe" /SILENT ### RegRun Reanimator - (19) 06-2021 [Applications] :HKLM The Elder Scrolls V Skyrim VR_is1="D:\Program Files (x86)\The Elder Scrolls V Skyrim VR\unins000.exe" /SILENT ### The Elder Scrolls V Skyrim VR - (19) 06-2021 [Applications] :HKLM Red Dead Redemption 2="D:\Program Files\Rockstar Games\Launcher\Launcher.exe" -enableFullMode -uninstall=rdr2 ### Red Dead Redemption 2 - (19) 06-2021 [Applications] :HKLM qBittorrent="C:\Program Files\qBittorrent\uninst.exe" ### qBittorrent 4.3.4.1 - (19) 06-2021 [Applications] :HKLM pcsx2=C:\Program Files (x86)\PCSX2\Uninst-pcsx2.exe ### PCSX2 - Playstation 2 Emulator - (19) 06-2021 [Applications] :HKLM RTSS="D:\Program Files (x86)\RivaTuner Statistics Server\uninstall.exe" ### RivaTuner Statistics Server 7.3.2 Beta 2 - (19) 06-2021 [Applications] :HKLM Rockstar Games Social Club=C:\Program Files\Rockstar Games\Social Club\uninstallRGSCRedistributable.exe ### Rockstar Games Social Club - (19) 06-2021 [Applications] :HKLM Rockstar Games Launcher="D:\Program Files\Rockstar Games\Launcher\uninstall.exe" /S ### Rockstar Games Launcher - (19) 06-2021 [Applications] :HKLM 1495134320_is1="D:\Games\GOG Galaxy\Games\The Witcher 3 Wild Hunt GOTY\unins000.exe" /SILENT ### The Witcher 3: Wild Hunt - Game of the Year Edition - (19) 06-2021 [Applications] :HKLM {1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2524860 ### - (19) 06-2021 [Applications] :HKLM {1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2467173 ### - (19) 06-2021 [Applications] :HKLM {1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2151757 ### - (19) 06-2021 [Applications] :HKLM {1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2565063 ### - (19) 06-2021 [Applications] :HKLM {1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2549743 ### - (19) 06-2021 [Applications] :HKLM {1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2544655 ### - (19) 06-2021 [Applications] :HKLM {03d1453c-7d5c-479c-afea-8482f406e036}="C:\ProgramData\Package Cache\{03d1453c-7d5c-479c-afea-8482f406e036}\VC_redist.x86.exe" /uninstall /quiet ### Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.28.29913 - (19) 06-2021 [Applications] :HKLM {02F850ED-FD0E-4ED1-BE0B-54981f5BD3D4}_is1="C:\Program Files (x86)\AOMEI Partition Assistant\unins000.exe" /SILENT ### AOMEI Partition Assistant 9.1 - (19) 06-2021 [Applications] :HKLM ZeroTier One 1.6.5=msiexec.exe /x {3B721AC6-50BD-410C-8E5F-9076234F4C46} AI_UNINSTALLER_CTP=1 ### ZeroTier One - (19) 06-2021 [Applications] :HKLM {13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}=MsiExec.exe /X{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E} ### Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 - (19) 06-2021 [Applications] :HKLM {083F9D87-14FF-4A82-90C6-FCCB97A25932}=MsiExec.exe /X{083F9D87-14FF-4A82-90C6-FCCB97A25932} ### Futuremark SystemInfo - (19) 06-2021 [Applications] :HKLM {050d4fc8-5d48-4b8f-8972-47c82c46020f}="C:\ProgramData\Package Cache\{050d4fc8-5d48-4b8f-8972-47c82c46020f}\vcredist_x64.exe" /uninstall /quiet ### Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 - (19) 06-2021 [Applications] :HKLM 1207658924_is1="G:\GOG Galaxy\Games\The Witcher Enhanced Edition\unins000.exe" /SILENT ### The Witcher Enhanced Edition Director's Cut - (19) 06-2021 [Applications] :HKLM SteelSeries Engine 3=C:\Program Files\SteelSeries\SteelSeries Engine 3\uninst.exe ### SteelSeries GG 3.1.0 - (19) 06-2021 [Applications] :HKLM Steam App 905370="C:\Program Files (x86)\Steam\steam.exe" steam://uninstall/905370 ### Conqueror's Blade - (19) 06-2021 [Applications] :HKLM {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience="C:\WINDOWS\SysWOW64\RunDll32.EXE" "C:\Program Files\NVIDIA Corporation\Installer2\InstallerCore\NVI2.DLL",UninstallPackage Display.GFExperience ### NVIDIA GeForce Experience 3.22.0.32 - (19) 06-2021 [Applications] :HKLM TAP-Windows=C:\Program Files\TAP-Windows\Uninstall.exe ### TAP-Windows 9.21.2 - (19) 06-2021 [Applications] :HKLM VulkanRT1.0.65.1=C:\Program Files (x86)\VulkanRT\1.0.65.1\UninstallVulkanRT.exe ### Vulkan Run Time Libraries 1.0.65.1 - (19) 06-2021 [Applications] :HKLM VLC media player="C:\Program Files\VideoLAN\VLC\uninstall.exe" ### VLC media player - (19) 06-2021 [Applications] :HKLM TeamViewer="C:\Program Files\TeamViewer\uninstall.exe" ### TeamViewer - (19) 06-2021 [Applications] :HKLM {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GFExperience.NvStreamSrv ### NVIDIA SHIELD Streaming - (19) 06-2021 [Applications] :HKLM {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver="C:\WINDOWS\SysWOW64\RunDll32.EXE" "C:\Program Files\NVIDIA Corporation\Installer2\InstallerCore\NVI2.DLL",UninstallPackage HDAudio.Driver ### NVIDIA Pilote audio HD : 1.3.38.60 - (19) 06-2021 [Applications] :HKLM {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer ### NVIDIA Install Application - (19) 06-2021 [Applications] :HKLM {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_FrameViewSdk="C:\WINDOWS\SysWOW64\RunDll32.EXE" "C:\Program Files\NVIDIA Corporation\Installer2\InstallerCore\NVI2.DLL",UninstallPackage FrameViewSdk ### NVIDIA FrameView SDK 1.1.4923.29781331 - (19) 06-2021 [Applications] :HKLM {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Optimus ### NVIDIA Optimus Update 38.0.7.0 - (19) 06-2021 [Applications] :HKLM {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX="C:\Windows\SysWOW64\RunDll32.EXE" "C:\Program Files\NVIDIA Corporation\Installer2\InstallerCore\NVI2.DLL",UninstallPackage Display.PhysX ### NVIDIA Logiciel système PhysX 9.19.0218 - (19) 06-2021 [Applications] :HKLM {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update ### Mises à jour NVIDIA 38.0.7.0 - (19) 06-2021 [Applications] :HKLM {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver="C:\WINDOWS\SysWOW64\RunDll32.EXE" "C:\Program Files\NVIDIA Corporation\Installer2\InstallerCore\NVI2.DLL",UninstallPackage Display.Driver ### NVIDIA Pilote graphique 466.77 - (19) 06-2021 [Applications] :HKLM {620A7633-7A09-42A8-8580-076A4483C4B0}=MsiExec.exe /I{620A7633-7A09-42A8-8580-076A4483C4B0} ### Microsoft Visual C++ 2019 X64 Additional Runtime - 14.28.29913 - (19) 06-2021 [Applications] :HKLM {5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}=MsiExec.exe /X{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4} ### Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 - (19) 06-2021 [Applications] :HKLM {37B8F9C7-03FB-3253-8781-2517C99D7C00}=MsiExec.exe /X{37B8F9C7-03FB-3253-8781-2517C99D7C00} ### Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030 - (19) 06-2021 [Applications] :HKLM {719C64E2-9BD5-4C6B-A13B-36E1DD27B015}=MsiExec.exe /X{719C64E2-9BD5-4C6B-A13B-36E1DD27B015} ### Hotspot Shield 9.21.3 Pre-Active - (19) 06-2021 [Applications] :HKLM {A749D8E6-B613-3BE3-8F5F-045C84EBA29B}=MsiExec.exe /X{A749D8E6-B613-3BE3-8F5F-045C84EBA29B} ### Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.21005 - (19) 06-2021 [Applications] :HKLM {929FBD26-9020-399B-9A7A-751D61F0B942}=MsiExec.exe /X{929FBD26-9020-399B-9A7A-751D61F0B942} ### Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.21005 - (19) 06-2021 [Applications] :HKLM {8345D0DF-6F2B-42B5-BEA4-9D7B0F532294}=MsiExec.exe /X{8345D0DF-6F2B-42B5-BEA4-9D7B0F532294} ### DriversCloud.com (64 bits) - (19) 06-2021 [Applications] :HKLM {1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG8200_series="C:\Windows\system32\CanonIJ Uninstaller Information\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG8200_series\DelDrv64.exe" /U:{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG8200_series /L0x000c ### Canon MG8200 series MP Drivers - (19) 06-2021 [Applications] :HKLM {071c9b48-7c32-4621-a0ac-3f809523288f}=MsiExec.exe /X{071c9b48-7c32-4621-a0ac-3f809523288f} ### Microsoft Visual C++ 2005 Redistributable (x64) - (19) 06-2021 [Applications] :HKLM WinRAR archiver=C:\Program Files\WinRAR\uninstall.exe ### WinRAR 6.00 (64-bit) - (19) 06-2021 [Applications] :HKLM {1D8E6291-B0D5-35EC-8441-6616F567A0F7}=MsiExec.exe /X{1D8E6291-B0D5-35EC-8441-6616F567A0F7} ### Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 - (19) 06-2021 [Applications] :HKLM {35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1="C:\Program Files\Malwarebytes\Anti-Malware\mbuns.exe" /Uninstall ### Malwarebytes version 4.3.0.98 - (19) 06-2021 [Applications] :HKLM {272B1192-65BE-4BDE-894B-6D3AD8BF7FD2}=MsiExec.exe /X{272B1192-65BE-4BDE-894B-6D3AD8BF7FD2} ### ZeroTier One Virtual Network Port - (19) 06-2021 [Applications] :HKLM {26A24AE4-039D-4CA4-87B4-2F64180291F0}=MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F64180291F0} ### Java 8 Update 291 (64-bit) - (19) 06-2021 [Applications] :HKLM {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvAbHub ### NVIDIA ABHub - (19) 06-2021 [Applications] :HKLM {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_OSC ### Nvidia Share - (19) 06-2021 [Applications] :HKLM {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvPlugin.Watchdog ### NVIDIA Watchdog Plugin for NvContainer - (19) 06-2021 [Applications] :HKLM {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvNodejs ### NVIDIA NodeJS - (19) 06-2021 [Applications] :HKLM {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_ShadowPlay ### NVIDIA ShadowPlay 3.22.0.32 - (19) 06-2021 [Applications] :HKLM {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvTelemetry ### NVIDIA Telemetry Client - (19) 06-2021 [Applications] :HKLM {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvVHCI ### NVIDIA Virtual Host Controller - (19) 06-2021 [Applications] :HKLM {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.ServiceUser ### NVIDIA NetworkService Container - (19) 06-2021 [Applications] :HKLM {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.NvapiMonitor ### NVAPI Monitor plugin for NvContainer - (19) 06-2021 [Applications] :HKLM {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.MessageBus ### NVIDIA Message Bus for NvContainer - (19) 06-2021 [Applications] :HKLM {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvModuleTracker.Driver ### NvModuleTracker - (19) 06-2021 [Applications] :HKLM {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.User ### NVIDIA User Container - (19) 06-2021 [Applications] :HKLM {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.Session ### NVIDIA Session Container - (19) 06-2021 [Applications] :HKLM {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer ### NVIDIA Container - (19) 06-2021 [Applications] :HKLM {CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}=MsiExec.exe /X{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97} ### Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030 - (19) 06-2021 [Applications] :HKLM {C5223DFE-7D6F-4902-88AE-BAA7FC73EFF1}=MsiExec.exe /X{C5223DFE-7D6F-4902-88AE-BAA7FC73EFF1} ### Virtual Desktop Streamer - (19) 06-2021 [Applications] :HKLM {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvBackend ### NVIDIA Backend - (19) 06-2021 [Applications] :HKLM {EC4A7B11-5AD2-49A7-BB93-15D0EB9E7106}=MsiExec.exe /X{EC4A7B11-5AD2-49A7-BB93-15D0EB9E7106} ### Virtual Desktop Service - (19) 06-2021 [Applications] :HKLM {EECDD137-13DA-46ED-ADA0-BDF7F8BE65B8}=MsiExec.exe /I{EECDD137-13DA-46ED-ADA0-BDF7F8BE65B8} ### Microsoft Visual C++ 2019 X64 Minimum Runtime - 14.28.29913 - (19) 06-2021 [Applications] :HKLM {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_ShieldWirelessController ### NVIDIA SHIELD Wireless Controller Driver - (19) 06-2021 [Applications] :HKLM {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.LocalSystem ### NVIDIA LocalSystem Container - (19) 06-2021 [Applications] :HKLM {F9C5C994-F6B9-4D75-B3E7-AD01B84073E9}=MsiExec.exe /X{F9C5C994-F6B9-4D75-B3E7-AD01B84073E9} ### Epic Games Launcher Prerequisites (x64) - (19) 06-2021 [Applications] :HKLM {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_VirtualAudio.Driver ### NVIDIA Virtual Audio 4.13.0.0 - (19) 06-2021 [Applications] :HKLM {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.ContainerTelemetryApiHelper ### NVIDIA TelemetryApi helper for NvContainer - (19) 06-2021 [Applications] :HKLM {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Update.Core ### NVIDIA Update Core - (19) 06-2021 [Applications] :HKLM Steam App 739630="D:\Steam\steam.exe" steam://uninstall/739630 ### Phasmophobia - (19) 06-2021 [Applications] :HKLM Steam App 582010="D:\Steam\steam.exe" steam://uninstall/582010 ### Monster Hunter: World - (19) 06-2021 [Applications] :HKLM Oculus=D:\Oculus\OculusSetup.exe /uninstall ### Oculus - (19) 06-2021 [Applications] :HKLM 57979c68-f490-55b8-8fed-8b017a5af2fe="D:\Program Files\Black Tree Gaming Ltd\Vortex\Uninstall Vortex.exe" /allusers ### Vortex - (19) 06-2021 [Applications] :HKLM Steam App 1151340="D:\Steam\steam.exe" steam://uninstall/1151340 ### Fallout 76 - (19) 06-2021 [Applications] :HKLM Steam App 1546860="C:\Program Files (x86)\Steam\steam.exe" steam://uninstall/1546860 ### Saiko no sutoka - (19) 06-2021 [Applications] :HKLM Steam App 1361000="C:\Program Files (x86)\Steam\steam.exe" steam://uninstall/1361000 ### In Silence - (19) 06-2021 [Applications] :HKLM DAEMON Tools Lite=C:\Program Files\DAEMON Tools Lite\uninst.exe ### DAEMON Tools Lite - (19) 06-2021 [Applications] :HKLM Hotspot Shield 9.21.3 Pre-Active 9.21.3.11422=C:\ProgramData\Caphyon\Advanced Installer\{719C64E2-9BD5-4C6B-A13B-36E1DD27B015}\HotspotShield-9.21.3-plain-773-PreActive.exe /x {719C64E2-9BD5-4C6B-A13B-36E1DD27B015} AI_UNINSTALLER_CTP=1 ### Hotspot Shield 9.21.3 Pre-Active - (19) 06-2021 [Applications] :HKLM CCleaner ### - (19) 06-2021 [Applications] :HKLM Microsoft Edge ### - (19) 06-2021 [Applications] :HKLM aG9tZXN3ZWV0aG9tZQ_is1="D:\Program Files\Home Sweet Home\unins000.exe" /SILENT ### Home Sweet Home v1.0.1 - (19) 06-2021 [Applications] :HKLM Steam App 22330="D:\Steam\steam.exe" steam://uninstall/22330 ### The Elder Scrolls IV: Oblivion - (19) 06-2021 [Applications] :HKLM Steam App 4000="D:\Steam\steam.exe" steam://uninstall/4000 ### Garry's Mod - (19) 06-2021 [Applications] :HKLM Steam App 381210="D:\Steam\steam.exe" steam://uninstall/381210 ### Dead by Daylight - (19) 06-2021 [Applications] :HKLM Steam App 431960="C:\Program Files (x86)\Steam\steam.exe" steam://uninstall/431960 ### Wallpaper Engine - (19) 06-2021 [Applications] :HKLM Steam App 489830="D:\Steam\steam.exe" steam://uninstall/489830 ### The Elder Scrolls V: Skyrim Special Edition - (19) 06-2021 [Applications] :HKLM Steam App 440900="D:\Steam\steam.exe" steam://uninstall/440900 ### Conan Exiles - (19) 06-2021 [Applications] :HKLM Steam App 231350="D:\Steam\steam.exe" steam://uninstall/231350 ### 3DMark Demo - (19) 06-2021 [Applications] :HKLM Steam App 230410="D:\Steam\steam.exe" steam://uninstall/230410 ### Warframe - (19) 06-2021 [Applications] :HKLM Steam App 250820="D:\Steam\steam.exe" steam://uninstall/250820 ### SteamVR - (19) 06-2021 [Applications] :HKLM Steam App 377160="D:\Steam\steam.exe" steam://uninstall/377160 ### Fallout 4 - (19) 06-2021 [Applications] :HKLM Steam App 291550="D:\Steam\steam.exe" steam://uninstall/291550 ### Brawlhalla - (19) 06-2021 [Applications] :HKLM {E5A95BC5-81DF-4F0C-B910-B59DD012F037}=MsiExec.exe /X{E5A95BC5-81DF-4F0C-B910-B59DD012F037} ### Microsoft Update Health Tools - (19) 06-2021 [Applications] :HKCU roblox-player="C:\Users\user\AppData\Local\Roblox\Versions\version-8d4ea819d4ec4cf1\RobloxPlayerLauncher.exe" -uninstall ### Roblox Player for Kiro - (19) 06-2021 [Applications] :HKCU OneDriveSetup.exe=C:\Users\user\AppData\Local\Microsoft\OneDrive\21.030.0211.0002\OneDriveSetup.exe /uninstall ### Microsoft OneDrive - (19) 06-2021 [Applications] :HKCU {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer ### NVIDIA Install Application - (19) 06-2021 [Applications] :HKCU {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GeforceNOW="C:\WINDOWS\SysWOW64\RunDll32.EXE" "C:\Users\user\AppData\Local\NVIDIA Corporation\Installer2\InstallerCore\NVI2.DLL",UninstallPackage GeforceNOW -noUAC ### NVIDIA GeForce NOW 2.0.28.140 - (19) 06-2021 [Applications] :HKCU Discord=C:\Users\user\AppData\Local\Discord\Update.exe --uninstall -s ### Discord - (19) 06-2021 [Applications] :HKCU 1fc5b090eab9aa41f8a2f5987367e6da="C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --profile-directory=Default --uninstall-app-id=leffmjdabcgaflkikcefahmlgpodjkdm ### Excel - (19) 06-2021 [Applications] :HKCU 1b837d0bf93d01407352736c91b7bf50="C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --profile-directory=Default --uninstall-app-id=hikhggiobiflkdfdgdajcfklmcibbopi ### Word - (19) 06-2021 [Applications] :HKCU 6b0f23e57a39ebfbf2814acb1a24293d="C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --profile-directory=Default --uninstall-app-id=bjhmmnoficofgoiacjaajpkfndojknpb ### Outlook - (19) 06-2021 [Applications] :HKCU 319814cb56b667dff88f54e08be8f51f="C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --profile-directory=Default --uninstall-app-id=opfacbhaojodjaojgocnibmklknchehf ### PowerPoint - (19) 06-2021 [Applications] :HKLM MPlayer2 ### - (07) 12-2019 [Applications] :HKLM MPlayer2 ### - (07) 12-2019 [Applications] :HKLM DXM_Runtime ### - (07) 12-2019 [Applications] :HKLM DXM_Runtime ### - (07) 12-2019 [Applications] :HKLM MobileOptionPack ### - (07) 12-2019 [Applications] :HKLM IEData ### - (07) 12-2019 [Applications] :HKLM WIC ### - (07) 12-2019 [Applications] :HKLM SchedulingAgent ### - (07) 12-2019 [Applications] :HKLM AddressBook ### - (07) 12-2019 [Applications] :HKLM Connection Manager ### - (07) 12-2019 [Applications] :HKLM DirectDrawEx ### - (07) 12-2019 [Applications] :HKLM Fontcore ### - (07) 12-2019 [Applications] :HKLM IE4Data ### - (07) 12-2019 [Applications] :HKLM IE5BAKEX ### - (07) 12-2019 [Applications] :HKLM IE40 ### - (07) 12-2019 [Applications] :HKLM IE40 ### - (07) 12-2019 [Applications] :HKLM Fontcore ### - (07) 12-2019 [Applications] :HKLM AddressBook ### - (07) 12-2019 [Applications] :HKLM Connection Manager ### - (07) 12-2019 [Applications] :HKLM DirectDrawEx ### - (07) 12-2019 [Applications] :HKLM MobileOptionPack ### - (07) 12-2019 [Applications] :HKLM SchedulingAgent ### - (07) 12-2019 [Applications] :HKLM WIC ### - (07) 12-2019 [Applications] :HKLM IE4Data ### - (07) 12-2019 [Applications] :HKLM IE5BAKEX ### - (07) 12-2019 [Applications] :HKLM IEData ### - (07) 12-2019 [FI20] FI2=-1,,,0,, FI2=1151488,366FAEB98DC10E0453337D60940F8C4EF3FEDB7B6B7B3EB047490F35B3EF5A54,21F6DBF0E4A4AC9CDE24DED06A8FC509,2,,C:\PROGRAM FILES (X86)\AOMEI PARTITION ASSISTANT\7Z.DLL FI2=297472,6278CAAE9A11D5EF01301741B9C40B5DA5178315A698E95E58DD19A5600BCC85,87FB0397F19D8656887B4BEBE8E56CA7,2,,C:\PROGRAM FILES (X86)\AOMEI PARTITION ASSISTANT\7Z.EXE FI2=95400,056F844CAB51F6A8CCA4E6F35725A6517EBC83FF70094EDC20188FDB89DA15A8,2B22508A41B8A3FF84B17D9EB7700006,1,"AOMEI International Network Limited",C:\PROGRAM FILES (X86)\AOMEI PARTITION ASSISTANT\AMBOOTER.EXE FI2=152464,EEF9B9A18A70A1B148E7F2158F6003E9312785051CC3E07FAEECE03B1C1546AF,94294C3D1C41E6207C7E5D0CD0F80B2F,1,"Microsoft Corporation",C:\PROGRAM FILES (X86)\AOMEI PARTITION ASSISTANT\BCDBOOT.EXE FI2=35840,A4B61626A1626FDABEC794E4F323484AA0644BAA1C905A5DCF785DC34564F008,0177746573EED407F8DCA8A9E441AA49,2,,C:\PROGRAM FILES (X86)\AOMEI PARTITION ASSISTANT\BOTVA2.DLL FI2=4096,68F42A7823ED7EE88A5C59020AC52D4BBCADF1036611E96E470D986C8FAA172D,F07E819BA2E46A897CFABF816D7557B2,2,,C:\PROGRAM FILES (X86)\AOMEI PARTITION ASSISTANT\CALLBACKCTRL.DLL FI2=8742056,9567193937290AF3FEEF58FB47E81F75BE2F87E4534009453B4B0FBE8A4BDA20,62242FA24E67EC81964D48B43FB9E795,1,"AOMEI International Network Limited",C:\PROGRAM FILES (X86)\AOMEI PARTITION ASSISTANT\PARTASSIST.EXE FI2=162400,56C8BABEC5CDCC1AE2B3B5DFEF321334CB1295ED56480E9D86570A3A65BA00D8,A79EA7CE19AC671E0A2B62971CD462F0,1,"Brave Software, Inc.",C:\PROGRAM FILES (X86)\BRAVESOFTWARE\UPDATE\BRAVEUPDATE.EXE FI2=8896304,EB3973FEA022968E72C4D7C44E9C5981467D367C7DEC284F7E73489F54B8E953,14C69E93D45998946D68338B5B551467,1,"BattlEye Innovations e.K.",C:\PROGRAM FILES (X86)\COMMON FILES\BATTLEYE\BESERVICE.EXE FI2=8896304,EB3973FEA022968E72C4D7C44E9C5981467D367C7DEC284F7E73489F54B8E953,14C69E93D45998946D68338B5B551467,1,"BattlEye Innovations e.K.",C:\PROGRAM FILES (X86)\COMMON FILES\BATTLEYE\BESERVICE_CE.EXE FI2=72880,17FE63C10C3972244152780F75E723914C2CA4DD1A03FF2DC9C4D6B999A99505,10624FF0808205154A2D7B864A8858F3,2,,C:\PROGRAM FILES (X86)\COMMON FILES\INSTALLSHIELD\ENGINE\8\INTEL 32\IKERNEL.EXE FI2=61104,EBAB797D4E6D1C6F184B52752EDE21356E84EEB229D6D6C0383921BDFB569257,629CCD1670E6302123E1E4E8CF2F83DF,2,,C:\PROGRAM FILES (X86)\COMMON FILES\INSTALLSHIELD\ENGINE\8\INTEL 32\ISUPDATE.EXE FI2=706288,F19CB42516DE588759130E64504EBBDE7DD54F61AB60EF32A61293BE1AEA64AF,9A0B4D176145136D8D62B7D809304463,1,"Oracle America, Inc.",C:\PROGRAM FILES (X86)\COMMON FILES\JAVA\JAVA UPDATE\JUSCHED.EXE FI2=7432056,CDF0D84A9266EC746161C07AE61B7B26880E6F0A71AB4EA306EADDEC438488F3,36F81FE613CF5C5A6FF3344BE3D81C61,1,"Valve",C:\PROGRAM FILES (X86)\COMMON FILES\STEAM\DRIVERS.EXE FI2=2944232,320B31EE89943A60EDD48CAA7947338DB4BBDD6D142FCE2D763B170FF0BBFC42,504976AB6791826869B2F64512ABA357,1,"Valve",C:\PROGRAM FILES (X86)\COMMON FILES\STEAM\SECURE_DESKTOP_CAPTURE.EXE FI2=3237096,DD99CFF4530CB16E36E67A08B730A9A2501B44F64BB56750584D9EB639F317D4,08C6615DCB0D1272CD27F405C9F38B8B,1,"Valve",C:\PROGRAM FILES (X86)\COMMON FILES\STEAM\STEAMSERVICE.DLL FI2=2790632,DDB3655CBD11F1A23B2BE6103D22AA309C3A8E6088A0AC7BD69536B0FBB86AD2,A65CE4215E625D137C7ACB34CDE46BB4,1,"Valve",C:\PROGRAM FILES (X86)\COMMON FILES\STEAM\STEAMSERVICE.EXE FI2=783080,571F3E6662EFC5DF68CDAED223D4343C38EF92A68EBC6847D6C1D7B9FF23775E,816A9E166F5E1A5EAD85975B7749813B,1,"Valve",C:\PROGRAM FILES (X86)\COMMON FILES\STEAM\STEAMXBOXUTIL64.EXE FI2=743936,DBFC906D8ACC7E6F276AC228B45A836C97AFDDF547F093CC48D6F1880F73A036,D2C313C4832C0640F847038461F668E5,1,"Microsoft Windows",C:\PROGRAM FILES (X86)\COMMON FILES\SYSTEM\WAB32.DLL FI2=964096,68646BF0E4E7CFB6A6CC05C3234BF7F224ADE48CBE03D583D0DFF56B48E55263,974390FE6E8F14CCFD3273643DD86DDF,1,"Microsoft Windows",C:\PROGRAM FILES (X86)\COMMON FILES\SYSTEM\WAB32RES.DLL FI2=784512,C634129DE3B3E164622DAF559868FA1527B751B7F1E83F37371A2EB47CABD4E7,86CAA3DB376C9E00F7FC1F318EA4695B,1,"EasyAntiCheat Oy",C:\PROGRAM FILES (X86)\EASYANTICHEAT\EASYANTICHEAT.EXE FI2=2382784,3085C3BE9683D028E4FC042AA7ED7B5E267ADEAEDF40164DE25942CF72557622,F68D351DB911609553420FDE060D791B,1,"EasyAntiCheat Oy",C:\PROGRAM FILES (X86)\EASYANTICHEAT\EASYANTICHEAT.SYS FI2=342456,5990EBDB4713E9537B7D8E248AC0A81353C1294CB3E3F2D9C69B21B2F1B9C77F,12BB368B41B4D8E973609A35C9B09356,1,"FUTUREMARK INC",C:\PROGRAM FILES (X86)\FUTUREMARK\SYSTEMINFO\FMSISVC.EXE FI2=721480,FB621BF90B82BD310BAE1B6EF4780EEE909572763D959E15D6262A2EA56941A8,6E6483AFA345877A1906AE6D31B60C15,1,"GOG Sp. z o.o.",C:\PROGRAM FILES (X86)\GOG GALAXY\CHROME_ELF.DLL FI2=260960,FB39720AB3CAAD13D56028C2B2245B750CAB0BC3BBC33E4D116019CF8CB46756,F8A302680EB36366827D460619D164AC,1,"GOG Sp. z o.o.",C:\PROGRAM FILES (X86)\GOG GALAXY\CRASHREPORTER.EXE FI2=3657992,8BF0EEB5081D8397E2F84F69449C8A80D9C0CDCF82BCEF7A484309046ADCB081,F76B1D2CD95385B21E61874761DDB53A,1,"Microsoft Corporation",C:\PROGRAM FILES (X86)\GOG GALAXY\D3DCOMPILER_47.DLL FI2=152648,1AED4E1E29F45B24534755D551BF50D93C110FB66F431D2A904531AB2BBEBC90,8AB9126EAF960AF3ED7BEB4D350D2544,1,"GOG Sp. z o.o.",C:\PROGRAM FILES (X86)\GOG GALAXY\EXPAT.DLL FI2=1619808,1FFFA889FE35524E1C5230799EC8B577428E92954C8E34C014AC0AF9F18023C9,8A087C19EEA7BD0D63F177255F8D2564,1,"GOG Sp. z o.o.",C:\PROGRAM FILES (X86)\GOG GALAXY\GALAXYCLIENT HELPER.EXE FI2=14916448,1A9D77EAC935AF16AECDD35C18A383FCD3E71D8DD9D303661D19D0E51311703B,4D84B7702E93B868EE31E4C2088F959A,1,"GOG Sp. z o.o.",C:\PROGRAM FILES (X86)\GOG GALAXY\GALAXYCLIENT.EXE FI2=1874272,FA34E8C103267B8D70854D17F34182F9153228ADF6A76218F3DBF93822D0B2E7,7ED811F005A1C67F2DF7F9A9A63F0F04,1,"GOG Sp. z o.o.",C:\PROGRAM FILES (X86)\GOG GALAXY\GALAXYCLIENTSERVICE.EXE FI2=192384,E119E53BFC8584699F4509975575CA793AD073B3A17D5C6753DF509B8A9FC8B3,4BF95F316A2B7DB768FD3555EF013A43,2,"AnchorFree Inc",C:\PROGRAM FILES (X86)\HOTSPOT SHIELD\BIN\CMW_SRV.EXE FI2=358272,4A477E679DD5857F2FF98CA605EE3C45B39DF9059B0C537C8D8C38458D0680AA,CAF795BF036C99CB66FB725EBE244C06,2,"AnchorFree Inc",C:\PROGRAM FILES (X86)\HOTSPOT SHIELD\BIN\HSSCP.EXE FI2=1271296,C437A50CC4B311E613C5CC95A0D5C80CAEC36D0969EC6684F2F6FB95D28891AD,993A079A1FF55BD602BA3E5C0413AB29,2,,C:\PROGRAM FILES (X86)\INSTALLSHIELD INSTALLATION INFORMATION\{E34F424D-99BB-4176-8BCB-F0A749D744B4}\SETUP.EXE FI2=45056,D8820E333BE39B27712C42766D1F141CB45FFBE183C43286E55ECC1B9A82FA4B,3253FD643C51C133C3489A146781913B,1,"Microsoft Windows",C:\PROGRAM FILES (X86)\INTERNET EXPLORER\EXTEXPORT.EXE FI2=50176,4F54F910A146DA2E489827C1B55342B73F4CE7ADC2C7C9E49CEA6DA1D9343B82,F4C3438230D0A5769080C7022AB48F28,1,"Microsoft Windows",C:\PROGRAM FILES (X86)\INTERNET EXPLORER\HMMAPI.DLL FI2=480256,A71004C20ABC2216D52137A41B72703841DA8BAB3A97A60EEDF77A37E951609F,7871873BABCEA94FBA13900B561C7C55,1,"Microsoft Windows",C:\PROGRAM FILES (X86)\INTERNET EXPLORER\IEINSTAL.EXE FI2=221696,30E2D946D30D0A88DE97301661B47E1BA797D7787CF054231FB35144BEF4339B,650FE7460630188008BF8C8153526CEB,1,"Microsoft Windows",C:\PROGRAM FILES (X86)\INTERNET EXPLORER\IELOWUTIL.EXE FI2=315392,C6303FB193FD809C7305E57B48AAB504E9F55CBD912EC2D61F6921BC261782F0,CEF76AE6CE140CFE4B0F8707B790FC19,1,"Microsoft Windows",C:\PROGRAM FILES (X86)\INTERNET EXPLORER\IESHIMS.DLL FI2=816072,E582676EC900249B408AB4E37976AE8C443635A7DA77755DAF6F896A172856A3,2E414291458B49ACDA42C80A4C10DE7E,1,"Microsoft Windows",C:\PROGRAM FILES (X86)\INTERNET EXPLORER\IEXPLORE.EXE FI2=5890504,5233B61006E3CB16935DE073B880AE1902C22575B282766AF96FFCEF944471CA,8E7A3CAA9432693EF68A2A7840E0FB0A,1,"LogMeIn, Inc.",C:\PROGRAM FILES (X86)\LOGMEIN HAMACHI\HAMACHI-2-UI.EXE FI2=1908144,B792819FA670104666B82DFCFBCE79146F43F56F42A1CBEE154B9ACF1239C380,A308AA323E4F244EDAE9F92ACED1E717,1,"LogMeIn, Inc.",C:\PROGRAM FILES (X86)\LOGMEIN HAMACHI\LMIGUARDIANDLL.DLL FI2=312240,CEFDE8949C29F390AD51AEF4F4F6CDAAB7D9E46301396FB574A267F787FDE988,70FA35FBF8DD4CB513A4C5D149BE801D,1,"LogMeIn, Inc.",C:\PROGRAM FILES (X86)\LOGMEIN HAMACHI\LMIGUARDIANEVT.DLL FI2=405424,26C855264896DB95ED46E502F2D318E5F2AD25B59BDC47BD7FFE92646102AE0D,93A4E2B886E2815B6B732A2380B0F068,1,"LogMeIn, Inc.",C:\PROGRAM FILES (X86)\LOGMEIN HAMACHI\LMIGUARDIANSVC.EXE FI2=3361736,372F040E11E93784FF36A3ED0F9E6A62E98E101DF873E19BC76EE53E4547A869,CCBC802D45A5DFA02CDB24083EDAC0D8,1,"LogMeIn, Inc.",C:\PROGRAM FILES (X86)\LOGMEIN HAMACHI\X64\HAMACHI-2.EXE FI2=312752,2E20274B539358A7F3F709A474CB6D42C9C91E8A24433EAB02DF64C00695E168,3F2969F27F61470DDBBD3BD0DB8D625D,1,"LogMeIn, Inc.",C:\PROGRAM FILES (X86)\LOGMEIN HAMACHI\X64\LMIGUARDIANEVT.DLL FI2=419248,A57D5CE0CBA04806EB0C6D8943D85C5AB63119A99FA8F8000BDF54CCCD1C1BF9,0554F3B69D39D175DD110D765C11347A,1,"LogMeIn, Inc.",C:\PROGRAM FILES (X86)\LOGMEIN HAMACHI\X64\LMIGUARDIANSVC.EXE FI2=406912,E4549F2D03C142AC01EC155D19643F4004C2AB20E318A2AD75BB8F3F8CDEA279,799B600C40D83AC4A3342E575AF2042B,1,"Microsoft Corporation",C:\PROGRAM FILES (X86)\MICROSOFT\EDGE\APPLICATION\91.0.864.48\BHO\IE_TO_EDGE_BHO.DLL FI2=523648,115570BDF8C1007A875A9BCA2E05EE067CCD424818AF1456A7CF6AC32EB567EF,1E488F1A95C2E1C26B926CA50CC46EB5,1,"Microsoft Corporation",C:\PROGRAM FILES (X86)\MICROSOFT\EDGE\APPLICATION\91.0.864.48\BHO\IE_TO_EDGE_BHO_64.DLL FI2=1639808,06DEC7550A6761ADE635C3A4D1DBF6CDE91DC60D4D7B6D33113D18A049F63735,4AE669AE00251D24E31999E70430DE8D,1,"Microsoft Corporation",C:\PROGRAM FILES (X86)\MICROSOFT\EDGE\APPLICATION\91.0.864.48\ELEVATION_SERVICE.EXE FI2=14720,9BF237DB498B703D83623745BBC5AE434F30EAC696230B56897DAAAC54EF49A7,DCD906E0FD20D445DD62FE8F7EB945BE,1,"Microsoft Corporation",C:\PROGRAM FILES (X86)\MICROSOFT\EDGE\APPLICATION\91.0.864.48\EVENTLOG_PROVIDER.DLL FI2=3278208,ACB63F45B2BF6AD2BC084F9347CF978CEE7228137D2F5B31716ADAA773ECDF0F,88B07986ADE051CDC1AF7FA0CE875D51,1,"Microsoft Corporation",C:\PROGRAM FILES (X86)\MICROSOFT\EDGE\APPLICATION\MSEDGE.EXE FI2=2554784,7D3F4E7A5ECFA260582B80D5A04C118320274A5E421D99E6C39D875FF8A80B9C,2141E11F0E1AAED7BDBCADF58FAD0357,1,"Microsoft Corporation",C:\PROGRAM FILES (X86)\MICROSOFT\EDGEUPDATE\1.3.143.57\MSEDGEUPDATE.DLL FI2=213920,A0628836960198F937F134E8A9C12A5EA38D682DA3DD5E026170DFBC3EAA992E,F5801470145FE1B446E98E7709311271,1,"Microsoft Corporation",C:\PROGRAM FILES (X86)\MICROSOFT\EDGEUPDATE\MICROSOFTEDGEUPDATE.EXE FI2=3409240,161BA4C1B21CD20B15573F0CCFC4A5CBAB8DEDD94C722CD60AFB8551D8D91DC2,0501B8EB39F00DCAA3C89CCEC2FBDE17,1,"Mojang AB",C:\PROGRAM FILES (X86)\MINECRAFT LAUNCHER\MINECRAFTLAUNCHER.EXE FI2=6117496,51808552B77ACC61A997D0B16305C441B9A54F8885C00E381632B2AFF517C85B,082767B672E6CF024F93E4E873CBBBA2,1,"NETGEAR TAIWAN CO., LTD",C:\PROGRAM FILES (X86)\NETGEAR\A7000\A7000.EXE FI2=32240,A68B3FD4CC2CA0336FD9FA75D318F1CF91D610E6EFC7C45B4BBD9A0DB1ED0A08,5406D76DC20667C1DCE5168D0291AB34,1,"Netgear Incorporated",C:\PROGRAM FILES (X86)\NETGEAR\A7000\RESTART.EXE FI2=45784,6D2493F981246375B045AA60DE4F029E71437E54DFF5F7A293C02E5BFA5424CA,87DE3968098F5811906550CED6735C6D,1,"NETGEAR",C:\PROGRAM FILES (X86)\NETGEAR\A7000\RTLSERVICE.EXE FI2=29443440,61FADC00123C7451C165E26F696743D5F0FDE374C50F03840408F7B4D6DE8210,6B5E08C608A57C95EFBFE78C8890E863,1,"NVIDIA Corporation",C:\PROGRAM FILES (X86)\NVIDIA CORPORATION\NVNODE\NVIDIA WEB HELPER.EXE FI2=645488,D76984EC98C6075BB6042B77C1B72E7C954E87C03520084DC58C3211E407BF91,4B508B097596947FAED12459FAB9D9DC,1,"NVIDIA Corporation",C:\PROGRAM FILES (X86)\NVIDIA CORPORATION\NVNODE\NVNODEJSLAUNCHER.EXE FI2=10190336,E387C713005082A19DB33F4E163A7F48671C1F9EA06BFD76C6F120B246043E59,8EA60A3FB6ADA3F42A15EFA9C1C320B4,2,,C:\PROGRAM FILES (X86)\PCSX2\PCSX2.EXE FI2=94579,63386D86BCECD9D5B945F7CA2449F892ACB2744EC543B3DECCE88A6A9C477DCE,781D3A2B1CD90DE0C1C6A083FEB5DD23,2,,C:\PROGRAM FILES (X86)\PCSX2\UNINST-PCSX2.EXE FI2=-1,,,0,,C:\PROGRAM FILES (X86)\STEAM\BIN\STEAMSERVICE.EXE FI2=732984,5A00C04781FF45A57DA3E8F8B070E1AC17C67065EFF31EEBD625D7D868AB4694,BEC13BAE81A43F179F613EFE8D4EF717,1,"Microsoft Windows",C:\PROGRAM FILES (X86)\WINDOWS DEFENDER\EPPMANIFEST.DLL FI2=95048,ED825851A6988B2B8AD046014B8B10B0106323A0C1257BC3FF2020BF499404CF,FFB737855A63E310877A4BFC722E3E50,1,"Microsoft Windows",C:\PROGRAM FILES (X86)\WINDOWS DEFENDER\MPASDESC.DLL FI2=693984,AC1A2FC2506F04F4D67A55ADF6BD9B41E423F233972E0D82BD220468072D153D,DA39834E043BD8371F4719978D6BA26E,1,"Microsoft Windows",C:\PROGRAM FILES (X86)\WINDOWS DEFENDER\MPCLIENT.DLL FI2=221920,98DE88CF9688BE36BAC221B8BDEA6E974C2CABBC3112E171FEF5B2F0989E54FC,F15594CFDF962582D6265CAA8C7FB73D,1,"Microsoft Windows",C:\PROGRAM FILES (X86)\WINDOWS DEFENDER\MPOAV.DLL FI2=13024,AEA16D34C312EB8706705CB3751FE7A56FA1E97B2974FCABE89555DF9AD0A250,1152D8A0B208B371FB64BF02A67C8732,1,"Microsoft Windows",C:\PROGRAM FILES (X86)\WINDOWS DEFENDER\MSMPLICS.DLL FI2=516608,2682086ACE1970D5573F971669591B731F87D749406927BD7A7A4B58C3C662E9,251E51E2FEDCE8BB82763D39D631EF89,1,"Microsoft Windows",C:\PROGRAM FILES (X86)\WINDOWS MAIL\WAB.EXE FI2=43008,B045B87B55ECDAB45FA0CF991A2894746E3A9786B184D7A02B377D65FF56F943,FC4B029F420E639835A882A7C4A4F7E8,1,"Microsoft Windows",C:\PROGRAM FILES (X86)\WINDOWS MAIL\WABIMP.DLL FI2=66048,B165040EB5857AC06F6F058ED316F41A8CAE13BC3F24B14A1F1865A391A9B00E,BBC90B164F1D84DEDC1DC30F290EC5F6,1,"Microsoft Windows",C:\PROGRAM FILES (X86)\WINDOWS MAIL\WABMIG.EXE FI2=162816,5238A1D5CBD90E3DA4474377C4DECEC3434E0CD54EA425F7D07F50FC3568F451,583F88513D74DD09215199D050AD0628,1,"Microsoft Windows",C:\PROGRAM FILES (X86)\WINDOWS MEDIA PLAYER\MPVIS.DLL FI2=1802240,FBA35A87DD152D0095435F5AB941694AFC0E35F811CB5877C7230EF6B187489F,A7BE61A382E168DC4056B530053FE3C2,1,"Microsoft Windows",C:\PROGRAM FILES (X86)\WINDOWS MEDIA PLAYER\SETUP_WM.EXE FI2=72192,6AC5FDF6C77EE474767A22900E81C26D8DDCBB1B2E611B0E5172AA343F81F95D,C57FD32FF3978E1A8160B4E73AB9B9C4,1,"Microsoft Windows",C:\PROGRAM FILES (X86)\WINDOWS MEDIA PLAYER\WMLAUNCH.EXE FI2=102400,3E4B017078F73D387FE9AFE46E09DAF87EBFC536BC1BC15C6362C8722A950056,4ACC57344531EEAC412463137996B8C1,1,"Microsoft Windows",C:\PROGRAM FILES (X86)\WINDOWS MEDIA PLAYER\WMPCONFIG.EXE FI2=40232,42FC546B7096FD1737AD976F631757A8E71084561FA77D30FA4A12F92F0A43AF,65B41C0C4AE256376FF7191EE872E31F,1,"Microsoft Windows",C:\PROGRAM FILES (X86)\WINDOWS MULTIMEDIA PLATFORM\SQMAPI.DLL FI2=96192,3B08281FA642225F812960AA29A2A3D9A7B0156E454A8EFC1FA9B6F6CD7DD46E,3F6F254D24C457BF33227502ED4F0988,1,"Microsoft Windows",C:\PROGRAM FILES (X86)\WINDOWS PHOTO VIEWER\IMAGINGDEVICES.EXE FI2=1905152,1160360F25D5D1E263C7EADF03240B251B1DCB4263CB2AFCF431619A08346D0E,D48617A39EFAE91973DD8A9458140896,1,"Microsoft Windows",C:\PROGRAM FILES (X86)\WINDOWS PHOTO VIEWER\IMAGINGENGINE.DLL FI2=1638912,CE368C2ADE0D8B1EC1D977C5AFE2AF000E5ED01512A7B225D805287E25A0E637,398AD5674842257E93A04F2F2DB1280E,1,"Microsoft Windows",C:\PROGRAM FILES (X86)\WINDOWS PHOTO VIEWER\PHOTOACQ.DLL FI2=37888,6C385E16F5AFF3F9B30F2B0E96C39A85BB084FCD2E9046210E83111EE2E0EF66,7204F74DB7AB66DE93BB6074FD642CAD,1,"Microsoft Windows",C:\PROGRAM FILES (X86)\WINDOWS PHOTO VIEWER\PHOTOBASE.DLL FI2=1532928,074D56986EFBABECCADC0BB485ABB4D1C8FE9BA5C4230C980EC264F10674B533,9403E29B1A224281EBAB2CC391C7FD3C,1,"Microsoft Windows",C:\PROGRAM FILES (X86)\WINDOWS PHOTO VIEWER\PHOTOVIEWER.DLL FI2=40232,60D291C3EBDFFAE55BB843C00014115AD6DA32173A237D435D14065F92A3CB01,B0DA107B1A4AD2E9DA5114051AD11360,1,"Microsoft Windows",C:\PROGRAM FILES (X86)\WINDOWS PORTABLE DEVICES\SQMAPI.DLL FI2=12232,09EA3CC8DCB70767C098A6BD30C47D002BB281485F8F97860B91B982427732B0,D28C34ED449BF3D74B448993ABC14CE3,1,"Brave Software, Inc.",C:\PROGRAM FILES\BRAVESOFTWARE\BRAVE-BROWSER\APPLICATION\91.1.25.73\EVENTLOG_PROVIDER.DLL FI2=2256328,CB7A0D8F0699611543540BC6E3C3860275189A9F00ECEB1BA030A6E2A1E917DC,7B65BF43899CCC928B22032391163B70,1,"Brave Software, Inc.",C:\PROGRAM FILES\BRAVESOFTWARE\BRAVE-BROWSER\APPLICATION\BRAVE.EXE FI2=890880,0F3B0DFFEF11A24171EFEC96839B815BDA96685D10CF482A1E94418293D541D3,95394E1E14DAE41AE21DA11420011157,1,"Microsoft Windows",C:\PROGRAM FILES\COMMON FILES\SYSTEM\WAB32.DLL FI2=964096,3A8C5344810B5B1791B249132FA26CD3CFDC8EE46E765688F013DE6B9F3513C2,0E55AECEE926C513D0D2A8C0C03744C3,1,"Microsoft Windows",C:\PROGRAM FILES\COMMON FILES\SYSTEM\WAB32RES.DLL FI2=1489728,DF89154AFA43FA16D37B93646E25AADC05388917044470D04A9EE4F81C95E51A,F7CA889DCA24770B9B9AF44C999BF0FA,1,"AVB Disc Soft, SIA",C:\PROGRAM FILES\DAEMON TOOLS LITE\DISCSOFT.NET.COMMON.DLL FI2=4993344,696059D1FEBAC8D75C2DC110379363C0227A0E340F17665A2638731BABCFA2A4,2C6AED167A3134501E966D382E07403D,1,"AVB Disc Soft, SIA",C:\PROGRAM FILES\DAEMON TOOLS LITE\DISCSOFTBUSSERVICELITE.EXE FI2=856896,D8BC1127A815D337165FCAF3CE5EC74C280446F06CDB4CDB1A5A52C021BB70BD,2865DFC93A57B79E58317B41DBF09C5A,1,"AVB Disc Soft, SIA",C:\PROGRAM FILES\DAEMON TOOLS LITE\DOTNETCOMMON.DLL FI2=408896,1D8267584BD88B693EF3C3574C25D699C6440FA203D77828672A44223D65F724,879DC994BFECA2E452A411FE823EAAC7,1,"AVB Disc Soft, SIA",C:\PROGRAM FILES\DAEMON TOOLS LITE\DTAGENT.EXE FI2=879936,107F0DC0822AE82C831C5A5FE831DC55D4DB7062DAC162D96FC3F8BD92CFD3FF,A8F84B20CBDFEA6FC1BB2E7463A279DE,1,"AVB Disc Soft, SIA",C:\PROGRAM FILES\DAEMON TOOLS LITE\DTCOMMANDLINE.EXE FI2=5031744,DF10985025B562ACC8BDA088F02E382B044ECBCAEF69AE30306BC45C4977FA8B,33574A32C8E7A062B79F35C9624D90AC,1,"AVB Disc Soft, SIA",C:\PROGRAM FILES\DAEMON TOOLS LITE\DTCOMMONRES.DLL FI2=389440,94E411694D5C03D8690F01C6367E837562985CDF0BD83ABB374FC845E2BD51F0,853FF63379152FCBB563059DE7F251EA,1,"AVB Disc Soft, SIA",C:\PROGRAM FILES\DAEMON TOOLS LITE\DTHELPER.EXE FI2=12114752,4E3BCC531607750850E9BBF364B9583904D88E99FF9DE91B3A026D6DA3B8BD02,F3A1BB825B50634BFE5B03A43078E583,1,"AVB Disc Soft, SIA",C:\PROGRAM FILES\DAEMON TOOLS LITE\DTLITE.EXE FI2=168768,9E9ED5A196D63F34FDED83C8B0180ADCB2F3DADCE5189B30EB32FF4468BEAF2F,C0D14C1E2F8FFABC1B23092BD552252E,1,"AVB Disc Soft, SIA",C:\PROGRAM FILES\DAEMON TOOLS LITE\DTLITEHELPER.EXE FI2=3740480,B4886EF126C18BCDC07382D9BB55FBA7CE5D53456DD6359D60623C491F1507C6,78CF17DF2CEFF2E8F0C706198514DDC6,1,"AVB Disc Soft, SIA",C:\PROGRAM FILES\DAEMON TOOLS LITE\DTSHELLHLP.EXE FI2=943016,52065BB5943315087A1ACB498FD4136FD995BA9E7CE5BFE96E933BF5509DAA68,9525B39A17F48A446E2DE3FAA9061EBA,1,"CYBELSOFT",C:\PROGRAM FILES\DRIVERSCLOUD.COM\DCCRYPT.DLL FI2=6898600,F9603C9FC7D9ACB6E1DC792600437043229714FD977BC7D10D572EE58E01CD99,C3B10686B418086C26003AAA69CD8073,1,"CYBELSOFT",C:\PROGRAM FILES\DRIVERSCLOUD.COM\DCENGINE.DLL FI2=9947048,4B40F697E4524829CC2792011A379A92D1DF4A4D314509D7B46F270C862A3204,33EABC72B99057C221F831D320F44466,1,"CYBELSOFT",C:\PROGRAM FILES\DRIVERSCLOUD.COM\DRIVERSCLOUD.EXE FI2=1978880,FF9D4F7BDDC946C05276B92C687A00B4B15F99481028AF22D6890F034CA327A5,A50B51B38F957A20931E67CBCB2CE14E,1,"CYBELSOFT",C:\PROGRAM FILES\DRIVERSCLOUD.COM\SQLITE3X64.DLL FI2=54784,EDC454BCA93A7D41D193A59953BDE82766FC6874345A71BEA2A8C52E71D06E29,B11437540BDFC36FEE80CAEFFF057D41,1,"Microsoft Windows",C:\PROGRAM FILES\INTERNET EXPLORER\EXTEXPORT.EXE FI2=54784,10A763B9599282D19757C670CDA735946DD11A376209683375A69D7382292DF5,8A6CDDCF40441607860950C0C110698A,1,"Microsoft Windows",C:\PROGRAM FILES\INTERNET EXPLORER\HMMAPI.DLL FI2=515072,C6AA1294F6A5AA52DC8CA2800065F22F7A0A8B5C1F5EC3E1761145D2E12024BE,FDB6320E118647D5697F2CA473C8731C,1,"Microsoft Windows",C:\PROGRAM FILES\INTERNET EXPLORER\IEDIAGCMD.EXE FI2=504832,CC57D54C0D17F5E786A75BC28CE2133499672FE378B6F62C8117F2F0C191E932,C9EDD394EB4D0996EE43CB67563DF50C,1,"Microsoft Windows",C:\PROGRAM FILES\INTERNET EXPLORER\IEINSTAL.EXE FI2=224768,3099B6CF67191B1A7E4D8463576FE85835E8DF2296DBA3470B0CD42BABD336C8,D831180F7596E0D2BB87B2CC57ECFCA2,1,"Microsoft Windows",C:\PROGRAM FILES\INTERNET EXPLORER\IELOWUTIL.EXE FI2=421888,F7B44947D5EC4A3DFC8D9CA7462B3640D8DCBF64D2AA0046095257BDBA5BDF85,B221F698EB537D7250F3F57EA84FDCDF,1,"Microsoft Windows",C:\PROGRAM FILES\INTERNET EXPLORER\IESHIMS.DLL FI2=819136,F76F00939F1BE76152809C37591EF75D3C150745232E35697D99CAE09E31C2BC,6BFE7CA23C89FD5809A48355EC5625EE,1,"Microsoft Windows",C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE FI2=347936,A444988052EC1A2B4CCCEF44C4879DAF41ABB98C938687A6C01850E5F5DCD2B7,A6650B94D058B525961956435BBD777E,1,"Oracle America, Inc.",C:\PROGRAM FILES\JAVA\JRE1.8.0_291\BIN\JP2SSV.DLL FI2=733984,B4ADC3DC87522EAD49CE435A782734E74F82F02138BBDB4BF3130FC2E3FF752B,87D8B3973B9B9EA4FCFD581086DE5C4E,1,"Oracle America, Inc.",C:\PROGRAM FILES\JAVA\JRE1.8.0_291\BIN\SSV.DLL FI2=14198872,D004A71F19C5CEF590D84240642E849BF6DF740DB7003E11ED65A710FF544D5E,9D1CFC7037EFE988CD01281D62E3776D,1,"Malwarebytes Inc",C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\MBAM.EXE FI2=7456464,340E72FF6E0AD4D48749EED73452EBB5A6B7679BFB98FBBEDF8C4C6A2B3D118C,9A463A0386D75F5EE3D496966FA5E466,1,"Malwarebytes Inc",C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\MBAMSERVICE.EXE FI2=312632,0EA85C05CFEB3F3B120824ADAC02AF1D9C1734C54D4C3615ADBC512C935E6521,71F5E415A9DE6F686CF727B211D724B8,1,"Microsoft Windows",C:\PROGRAM FILES\MICROSOFT UPDATE HEALTH TOOLS\EXPEDITEUPDATER.EXE FI2=470328,0D1C04FDC332380FD05F68A92AC12D1B087FCD3486CA7C15447CD388122E2BF7,0CDAB7BA836AA623CD54AF9CF6F04DAE,1,"Microsoft Windows",C:\PROGRAM FILES\MICROSOFT UPDATE HEALTH TOOLS\QUALITYUPDATEASSISTANT.DLL FI2=725304,7D1E53D71F7FDF202CB671106F9CED705830EA24F89EA19382C2CFC28D6B1E2A,6753C32DFCE9017B44EE371803F9A147,1,"Microsoft Windows",C:\PROGRAM FILES\MICROSOFT UPDATE HEALTH TOOLS\SEDPLUGINS.DLL FI2=335672,C7664DF416694E3545F2B4BCB82A36614DA1B18618FD3EF70474BC0E785B5CD3,931255341ADB0480D8C8CB1A2ED82FDA,1,"Microsoft Windows",C:\PROGRAM FILES\MICROSOFT UPDATE HEALTH TOOLS\UHSSVC.EXE FI2=197944,D50574758581F59C62536814A77C9DD3E22D54487E170414D08B0DF768182855,9353D339405F4E124E8ECB556336CA04,1,"Microsoft Windows",C:\PROGRAM FILES\MICROSOFT UPDATE HEALTH TOOLS\UNIFIEDINSTALLER.DLL FI2=409456,0BABD6F1AFA4182564715B7D14CFE43F9E618B90E713E245B6A660384580B345,2E0CED998A70B77085363636C67FF49D,1,"NVIDIA Corporation",C:\PROGRAM FILES\NVIDIA CORPORATION\FRAMEVIEWSDK\NVFVSDKSVC_X64.EXE FI2=1260400,0BCD737BAC1DF1046F7615DA880782532FE5E5405AFFF8280ECDF19568C958DC,A25655283D1D4B1945CFEEDA550D0D4D,1,"NVIDIA Corporation",C:\PROGRAM FILES\NVIDIA CORPORATION\NVBACKEND\NVTMREP.EXE FI2=874472,B28ECA3B53B6D3E55725BD2CF76D8A9E67FA0F85F2BC575AA39815DE4CA25183,EC37EFD653F9FAEA7526C055735E1DE3,1,"NVIDIA Corporation",C:\PROGRAM FILES\NVIDIA CORPORATION\NVCONTAINER\NVCONTAINER.EXE FI2=3336560,B7F319E4B59F470BEF573852F8EB15F2F0E0E8EBE23910AFB98F0CE761F88FCC,00F22085A81E10B10DADE73CE242FCEE,1,"NVIDIA Corporation",C:\PROGRAM FILES\NVIDIA CORPORATION\NVIDIA GEFORCE EXPERIENCE\NVIDIA GEFORCE EXPERIENCE.EXE FI2=905584,564E2EE833333FCA401F41F140FEE23341671F030C56A444EBACA5C2D744DB9E,A2E863F57464A444E4142089E2DA7DD9,1,"NVIDIA Corporation",C:\PROGRAM FILES\NVIDIA CORPORATION\UPDATE CORE\NVPROFILEUPDATER64.EXE FI2=26243584,2369A5090FCB27C03036AABD6001DA41DA876DC220F03F56E19AF9719D6478F3,C1D7A5C800B77E4A3EA98C5E8857F163,2,,C:\PROGRAM FILES\QBITTORRENT\QBITTORRENT.EXE FI2=112822,4EDF43CFF10B740A2260BEBB3BCE54029E3ECDA17C01FAC84CFC1C13FA573024,654229386351D18077BCC43B663E0E6C,2,,C:\PROGRAM FILES\QBITTORRENT\UNINST.EXE FI2=509776,85B4BC1CE57FA9C8BF94F2AAF72C8C975A21462098BA63847ADA633EDE6E25FF,4814BE1A3FFCA456B047D0112C81E46A,1,"SteelSeries ApS",C:\PROGRAM FILES\STEELSERIES\STEELSERIES ENGINE 3\MOMENTS\STEELSERIESSVCLAUNCHER.EXE FI2=21954896,2385527CCEDD691DA0AF0A9C36C0F6827570EA9BDB494DAA2353D5BB49706E66,C6CE99BAE50E2C14E6F8B83523EE6664,1,"SteelSeries ApS",C:\PROGRAM FILES\STEELSERIES\STEELSERIES ENGINE 3\STEELSERIESENGINE.EXE FI2=15176528,52DC6E2394EE31A43DC7D6070926B657E63A2E159ED89A72E5C9DAC7A276BE9A,128C365F4C1917D55D39D22D9F01040C,1,"SteelSeries ApS",C:\PROGRAM FILES\STEELSERIES\STEELSERIES ENGINE 3\STEELSERIESGG.EXE FI2=31568,39392A8C639C405A8507EF7756F4B774C655A55AE7724D46095093A5C132844C,76A0E85624D8DCD30AFC44630FC47B4D,1,"SteelSeries ApS",C:\PROGRAM FILES\STEELSERIES\STEELSERIES ENGINE 3\STEELSERIESUPDATESERVICE.EXE FI2=83811,D858454B7CA0629F84A0BA95B8257B00D4FBAB318882D9882B6C5A15E67E2E34,7A39C7E83F8DBB5835C354A30F4C47D9,2,,C:\PROGRAM FILES\TAP-WINDOWS\UNINSTALL.EXE FI2=62654480,2DD1A79D51B3C48A41CA17CE9384EACFA28157029DC0DD1E535A2259ABBBD36A,9445473A907C4AAB2748A3B92E4D91B7,1,"TeamViewer Germany GmbH",C:\PROGRAM FILES\TEAMVIEWER\TEAMVIEWER.EXE FI2=12074792,E25EB5E2D00494EAD5F73F520C5256374512F3047319EE2B1A4D09DEEB5B68F8,55F4ED54092951D498D609C890A48A93,1,"TeamViewer Germany GmbH",C:\PROGRAM FILES\TEAMVIEWER\TEAMVIEWER_DESKTOP.EXE FI2=644392,F818AB4DC0A063042D1DB26DFEE52F58484A9F7A3E5336DC273B011B305E3681,F38A84A47335C3A20CB12C02F6BE2F39,1,"TeamViewer Germany GmbH",C:\PROGRAM FILES\TEAMVIEWER\TEAMVIEWER_NOTE.EXE FI2=338728,F92001F8045BC1A96F528C86A82F5A5AEA158D86CC00C8D18498E868518DDB44,8FE36BCF2EEF37D4AE25163103FEC6ED,1,"TeamViewer Germany GmbH",C:\PROGRAM FILES\TEAMVIEWER\TEAMVIEWER_RESOURCE_AR.DLL FI2=14249256,6E65F397829D90E0AE9883502945C767AD4164FFB2C93221640D925E8AB38658,74F470833579430C5C73822067A64EA8,1,"TeamViewer Germany GmbH",C:\PROGRAM FILES\TEAMVIEWER\TEAMVIEWER_SERVICE.EXE FI2=985800,4A6DEA6A201472896281201006DFD65DE7FF325E9DE02AE0B0C5C45A647D5F99,3FB97050A420F75BC2FFA7AFE0457448,1,"VideoLAN",C:\PROGRAM FILES\VIDEOLAN\VLC\VLC.EXE FI2=27136,C8CE81EF62B91A8DFE12E203C24A7EFBC081478BE9CD0E04F8AC29517DE09C0E,0380E2ACDAC8FE78FAC9A412A023B55C,2,,C:\PROGRAM FILES\VIRTUAL DESKTOP\VIRTUALDESKTOP.GAMEPADEMULATION.DLL FI2=4198168,7C7A25F141A9DE7F612AFE8D39CBB43C1960C046E6E01E8AEC63D8C204B73F95,01A19EE54C097C40BD84EA52CB7C2B66,1,"Virtual Desktop, Inc.",C:\PROGRAM FILES\VIRTUAL DESKTOP\VIRTUALDESKTOP.SERVER.EXE FI2=1964824,E2BCBA671E00DFB2C01F398AAE04CF0C2F8A59F0FDA5035031A9A605900E27DF,7806D7C2EA17E2A741BDBBC325345B42,1,"Virtual Desktop, Inc.",C:\PROGRAM FILES\VIRTUAL DESKTOP\VIRTUALDESKTOP.SERVICE.EXE FI2=204624,3326478396F2FA4AAB9A448596EF4782389225DED7350E3D26FD86F3380C1FDB,B6C93C7F77A88476FFC954FC37E0BB8B,1,"Microsoft Windows",C:\PROGRAM FILES\WINDOWS DEFENDER\AMMONITORINGPROVIDER.DLL FI2=318776,65FA5DB3C388AAC18E01075A805DAD89B02A4C69297009E9E4BC81D6F66198D0,A38A5F40469F8D5B622989C2DF55D2D3,1,"Microsoft Windows",C:\PROGRAM FILES\WINDOWS DEFENDER\CONFIGSECURITYPOLICY.EXE FI2=210872,E9E08A225FD2B0E405FCDF941AB801A392C730B21A960012AF5DA583731E2586,A9665CB49312498993A85D7F42E05F01,1,"Microsoft Windows",C:\PROGRAM FILES\WINDOWS DEFENDER\DEFENDERCSP.DLL FI2=733200,00395278372FAAA6D1218598EDCF71C518A25FE1294444BA925D185340669F5E,54ABD7931A6492B29BBB3BB413B036BF,1,"Microsoft Windows",C:\PROGRAM FILES\WINDOWS DEFENDER\EPPMANIFEST.DLL FI2=95048,66C7358A1FFE55C283C61E09A8454F44D8BF8962902BE0D0828F4C0D3BE43093,5835BAF776446D1F42738F6371DC8B6F,1,"Microsoft Windows",C:\PROGRAM FILES\WINDOWS DEFENDER\MPASDESC.DLL FI2=518656,02EA7B9948DFC54980FD86DC40B38575C1F401A5A466E5F9FBF9DED33EB1F6A7,DBB30349963DBF34B6A50E6A2C3F3644,1,"Microsoft Windows",C:\PROGRAM FILES\WINDOWS MAIL\WAB.EXE FI2=50688,F8C04A859D14A9376C392B4C43A23E4A660FE11D4FDD84241C278C0F8663D562,EB17E4D3CAA4F9E614E519DC31BB8113,1,"Microsoft Windows",C:\PROGRAM FILES\WINDOWS MAIL\WABIMP.DLL FI2=70144,5AD4FA74E71FB4CE0A885B1EFB912A00C2CE3C7B4AD251AE67E6C3A8676EDE02,B9AC6F8EA946CB0F4B1AB79E2172FD83,1,"Microsoft Windows",C:\PROGRAM FILES\WINDOWS MAIL\WABMIG.EXE FI2=190976,C65E464623FD1F652BADB275F71F98FE615D344FBE7A6B89A3721F853840058D,2EE650292748E6BAEBAA84C607BD3C36,1,"Microsoft Windows",C:\PROGRAM FILES\WINDOWS MEDIA PLAYER\MPVIS.DLL FI2=1857024,5BD21E8EA31BF1593BBF276F7474EA6526E7D2B348CAA6AE2B4968EEF5A73E89,15243A35BD48BCF0AA90DCCC35B87522,1,"Microsoft Windows",C:\PROGRAM FILES\WINDOWS MEDIA PLAYER\SETUP_WM.EXE FI2=96256,2830C077D731BF14BF8CEF25E69862FED93EF4FFC0AEEEDD0B80B246F57695C0,C8BCC18E4197CD207596A0AD4CDAACAC,1,"Microsoft Windows",C:\PROGRAM FILES\WINDOWS MEDIA PLAYER\WMLAUNCH.EXE FI2=104448,1119C7BCCAD7C5A290AB2515A5CB3BBBA047ECF98B2230C9EB3111E4B5E8F5D0,29E52BFB44C74B2E3730F79D04082692,1,"Microsoft Windows",C:\PROGRAM FILES\WINDOWS MEDIA PLAYER\WMPCONFIG.EXE FI2=955904,D261B853B0367D5C724319AA4D7008851F48D3E110823E0B650B07D981CA9C0E,9D840006F1ABEA529AACBED5827C9FB7,1,"Microsoft Windows",C:\PROGRAM FILES\WINDOWS MEDIA PLAYER\WMPNETWK.EXE FI2=71168,42CF12CCE4C991C6C2C93147FEE7D3193341C03B2A65938F521ACC7000C4A6D5,F912FF78DE347834EA56CEB0E12F80EC,1,"Microsoft Windows",C:\PROGRAM FILES\WINDOWS MEDIA PLAYER\WMPNSCFG.EXE FI2=48536,5E8039AEF0F2A580F652AB33C11AD8527C30BD251CE1BB1D8BBFBB5CBD0E13F6,635FCC405EC2D776816EA7E5D426823E,1,"Microsoft Windows",C:\PROGRAM FILES\WINDOWS MULTIMEDIA PLATFORM\SQMAPI.DLL FI2=3059712,F2F824571EE2EE27628C9A6EE19AD07E11276F330A5B4222196874AFFB3AC385,FDBA1F6BA7F4766FB835F662A34BEBC8,1,"Microsoft Windows",C:\PROGRAM FILES\WINDOWS NT\ACCESSORIES\WORDPAD.EXE FI2=98248,B722655B93BCB804802F6A20D17492F9C0F08B197B09E8CD57CF3B087CA5A347,00C143B07DDBF5995BD03F79A1EBD945,1,"Microsoft Windows",C:\PROGRAM FILES\WINDOWS PHOTO VIEWER\IMAGINGDEVICES.EXE FI2=2251264,994476041A9AF3E546706B016A8890B7830FD94FF9C766DD18FF36530E456987,24793468692097532EBE317A7B1B772A,1,"Microsoft Windows",C:\PROGRAM FILES\WINDOWS PHOTO VIEWER\IMAGINGENGINE.DLL FI2=1975296,54B2AE125983B8B91BD84C0F0936154FDCF021986FEAB07B7F6A066B0C8B4E31,FB28D6E5F23962014E6D6341287545CA,1,"Microsoft Windows",C:\PROGRAM FILES\WINDOWS PHOTO VIEWER\PHOTOACQ.DLL FI2=51200,4ADCAD2A87ECD6CD8B47BAE8107EA36A9BDA8AD508B3CF78AC08279E1F060507,3519FC7720BC96D1FA924E5C5C8BCCE0,1,"Microsoft Windows",C:\PROGRAM FILES\WINDOWS PHOTO VIEWER\PHOTOBASE.DLL FI2=1753088,1065D1D6EDD217244AF008021D41FDBD277C81E695DF81CE662856859DBDC595,9EDAC43AF0A7B3B7D0C9AF56D6553F49,1,"Microsoft Windows",C:\PROGRAM FILES\WINDOWS PHOTO VIEWER\PHOTOVIEWER.DLL FI2=48528,C9FC6942D17085C15D34F1CA3D64AA73E2383D4A5AE7CEE4A3A5D45D908B829E,02AC176283867FBA4408EC169DB4D7F3,1,"Microsoft Windows",C:\PROGRAM FILES\WINDOWS PORTABLE DEVICES\SQMAPI.DLL FI2=22016,61F3BD29C28B64C20CB6124CAD88743C295682A125B13F5CA2A9F90DF5C01B32,F5374814DF65DDFA4F8C173DF495E1FD,2,,C:\PROGRAM FILES\WINDOWSAPPS\MICROSOFT.549981C3F5F10_3.2105.19601.0_X64__8WEKYB3D8BBWE\CORTANA.EXE FI2=50104,144298D19616681579CB722CB8C5AB92F0E714EC573945A0C83A972C02975895,2AFAC7537DBC32F6DF4DB2956613D485,1,"Microsoft Corporation",C:\PROGRAM FILES\WINDOWSAPPS\MICROSOFT.GAMINGSERVICES_2.53.17003.0_X64__8WEKYB3D8BBWE\GAMINGSERVICES.EXE FI2=50104,144298D19616681579CB722CB8C5AB92F0E714EC573945A0C83A972C02975895,2AFAC7537DBC32F6DF4DB2956613D485,1,"Microsoft Corporation",C:\PROGRAM FILES\WINDOWSAPPS\MICROSOFT.GAMINGSERVICES_2.53.17003.0_X64__8WEKYB3D8BBWE\GAMINGSERVICESNET.EXE FI2=19456,29163B7BA95324898CF3AEBA2A40BC77960409D2E6E50ABFBF82A458FE2316CD,2CB4A6BEC02764BC6DE39152FE3DB14D,2,,C:\PROGRAM FILES\WINDOWSAPPS\MICROSOFT.WINDOWSSTORE_12011.1001.1.0_X64__8WEKYB3D8BBWE\WINSTORE.APP.EXE FI2=209408,FC831C36755602B29B042E7E8079CEA4639489BD72FBACA0835CDE93AFF7885E,275114D5C4EE6285991160671424E162,2,,C:\PROGRAM FILES\WINRAR\7ZXA.DLL FI2=330508,7AE89B5CE837430EE0B173752667CDD2DE99EC9D18DD11C826139869B1BDEB29,76D881B42345A5C92023C7470C4AF2F1,2,,C:\PROGRAM FILES\WINRAR\DEFAULT.SFX FI2=380684,D0AE2012100D494C68792691CA108E2A70849A7917B4A836DC59EAA793927EE4,5A6F57988A0AC0D447D6C10D58A40D19,2,,C:\PROGRAM FILES\WINRAR\DEFAULT64.SFX FI2=629296,49CA94987B4E9A7DA5D986705C0F0A69B7686F3ADD317EF2EAC12CF59A24AB0D,9A5DBF7677E33719243E9ABDF1F783EE,1,"win.rar GmbH",C:\PROGRAM FILES\WINRAR\RAR.EXE FI2=567344,B05F91EE2C33B3BC6D594CC921130EDF1EE2D92D8BB9B42C3F6E9290D92B040D,8405A23BC29AC5DD1DDEE92E4B5A5E47,1,"win.rar GmbH",C:\PROGRAM FILES\WINRAR\RAREXT.DLL FI2=493104,84974A5EA7F3C3D345CEE26E16ADE6BFD49E1F611E4AF24A87A9FD1FAACC71CE,8C7B466C9D39C23AD65780E94880E1C3,1,"win.rar GmbH",C:\PROGRAM FILES\WINRAR\RAREXT32.DLL FI2=6840672,197F6E3E1A0D786190CFBEF866E00F2332DD892F790D955069B762EEF74CA1E2,948B890B3DA8BB5146F8CC65C0451F5B,1,"GOG Sp. z o.o.",C:\PROGRAMDATA\GOG.COM\GALAXY\REDISTS\GALAXYCOMMUNICATION.EXE FI2=107744,74E239238B95E5C66C655F0F8823F1E7B1757FAB0C572C9FFCD60A351741E48F,081F49A0E9C980D3BAA181195C7A557B,1,"Microsoft Windows",C:\PROGRAMDATA\MICROSOFT\WINDOWS DEFENDER\DEFINITION UPDATES\{A48230EF-0041-4AF8-A738-63B8ABCA3B04}\MPKSLDRV.SYS FI2=644888,71CAFC2CE5B1ADCAD16C53220A818E2DB8545482506A683674F452741EB933AB,86CF2E5256E9650CC1ACCA023D0E20C7,1,"Microsoft Windows Publisher",C:\PROGRAMDATA\MICROSOFT\WINDOWS DEFENDER\PLATFORM\4.18.2105.5-0\MPCMDRUN.EXE FI2=136656,404D8D6AC0005CD7B57AA779FF7ACA223C27CEF4820C94DE0A39C21604D4652B,CECD78F3EE9D8D5CDB381F3C60AE8B1A,1,"Microsoft Windows Publisher",C:\PROGRAMDATA\MICROSOFT\WINDOWS DEFENDER\PLATFORM\4.18.2105.5-0\MSMPENG.EXE FI2=2644776,E7B89288F624B164AB1CD8ACE901F29FB8DA2D5F6F27256AB77DA64E7D121625,37DC362F5213EA59F046CB2525F53F8A,1,"Microsoft Windows Publisher",C:\PROGRAMDATA\MICROSOFT\WINDOWS DEFENDER\PLATFORM\4.18.2105.5-0\NISSRV.EXE FI2=195088,296B4E27F04D1295D73DE2C6297A8367947E7DDC18C4F06125EA2315D1E5E71E,BB6B8C478E384D5EABF0EADBF975992C,1,"Hugh Bailey",C:\PROGRAMDATA\OBS-STUDIO-HOOK\GRAPHICS-HOOK32.DLL FI2=221712,ED1D5EDEEAFF39E835AC845609C494563EB904B0B5522FA1D1DB9D88E832FDD6,830A5EC204FEA553EEE07450BDE99599,1,"Hugh Bailey",C:\PROGRAMDATA\OBS-STUDIO-HOOK\GRAPHICS-HOOK64.DLL FI2=92028384,9310AB9B1BB948661C6D1B8014C1BDA15E0697C26138155145933547F4DC6992,2BB5E072F8723C9527EB93DAA3BC91D3,1,"Black Tree Gaming Limited",C:\PROGRAMDATA\VORTEX\INSTALLER.EXE FI2=1702272,913B335434250F6ABFDFCAA1F973979BC684A9630D66B8C8E9FAABBA0157709E,DBE4DC6060ECFEEE2A42900822FCC0C7,1,"ZeroTier, Inc.",C:\PROGRAMDATA\ZEROTIER\ONE\ZEROTIER-ONE_X64.EXE FI2=95631528,F6C115C3AACDBA8E9892D7090A4DD6A2F836077BF9E5A1FC352CD327857CE48A,CFFC5E6F5AB2AB20E38270E7450245B7,1,"Discord Inc.",C:\USERS\USER\APPDATA\LOCAL\DISCORD\APP-1.0.9002\DISCORD.EXE FI2=1512760,9B2DE7E18319BC24FFADAC02E1A1ADC82571BE94B4C63B075435868F232E2724,13E3F1E318224A1593F8783086ACA044,1,"Discord Inc.",C:\USERS\USER\APPDATA\LOCAL\DISCORD\UPDATE.EXE FI2=2882408,97716206CF8B5C00F556F81166D6381FD55F8C89F26DF3B79FE6FDD08D8D95BC,641CBDEFD6C6BDD30E59ACEADB99F7C5,1,"Microsoft Corporation",C:\USERS\USER\APPDATA\LOCAL\MICROSOFT\ONEDRIVE\ONEDRIVESTANDALONEUPDATER.EXE FI2=3555184,7501F1ABD7FE440E0A00A3F2F21BEF973E2BA8C98B4D214A70A5F31D643531D6,CC5AB07FDA9BD8CF221B335676AF3B38,1,"NVIDIA Corporation",C:\USERS\USER\APPDATA\LOCAL\NVIDIA CORPORATION\GEFORCENOW\CEF\GEFORCENOW.EXE FI2=1845128,84BC4B1943B10A6CE8376850AED7C7223B87F4F583380D3C59016BC7675D069C,66937C584704C4A5284AA86D6EFC865D,1,"Roblox Corporation",C:\USERS\USER\APPDATA\LOCAL\ROBLOX\VERSIONS\ROBLOXSTUDIOLAUNCHERBETA.EXE FI2=1665928,1B5B1CFE2714EDA0BC89E11AD552C6DF4A96CA25775423EEC8364358E007CF5B,E545982B67EF4A7FA8662B947B228A43,1,"Roblox Corporation",C:\USERS\USER\APPDATA\LOCAL\ROBLOX\VERSIONS\VERSION-8D4EA819D4EC4CF1\ROBLOXPLAYERLAUNCHER.EXE FI2=2300416,452A6813F7670415D338A706A24A4F929E6EB912CBC3A187090CD50AD047BCF8,66D5F38C2A3BEB190ECA93AB617C3DF6,2,,C:\USERS\USER\DESKTOP\FRST64.EXE FI2=4891752,63F8608B5EB6BA2D37FFFAF46F86363FAF15684A367C1603CEB06F0693C877BA,4BF8CF1A2379B0054860EC220CA329B9,1,"Microsoft Windows",C:\WINDOWS\EXPLORER.EXE FI2=99704,91B02F162EFD696D39075330304C02460D0D3FEF1638FCCB519DB8F41F81D121,A11B44D3E887024B164B72BDBB97E89B,1,"Microsoft Windows",C:\WINDOWS\MICROSOFT.NET\FRAMEWORK64\V2.0.50727\FR\ASPNET_RC.DLL FI2=11128,4BACB1686A688112A4133AD01461F750D9F63287082586D672D8B3EFC96C856E,9BA1525CBF7CC37D9C374AEC1E5046E0,1,"Microsoft Windows",C:\WINDOWS\MICROSOFT.NET\FRAMEWORK64\V3.0\WINDOWS COMMUNICATION FOUNDATION\SERVICEMODELEVENTS.DLL FI2=46184,80982C4DA12FDD501C234782A14243DFFA8AA4D6EB94BA5E37E3575ADE53000D,91857D4F6633493CF03C22BD86ED7F81,1,"Microsoft Windows",C:\WINDOWS\MICROSOFT.NET\FRAMEWORK64\V3.0\WPF\PRESENTATIONFONTCACHE.EXE FI2=805648,01D279310172522ABDBFAC16669D99DBD948ED268ACC659E1A3EBC972CBDD238,6735D7C8ECA0A2E51AF86F4224182EF8,1,"Microsoft Windows",C:\WINDOWS\MICROSOFT.NET\FRAMEWORK64\V4.0.30319\EVENTLOGMESSAGES.DLL FI2=19432,AC6E91554EC23CB087DBADEDEB20D75BD73448B27EAF02E78AF50278B2120EF8,0CB5A70C05319020C97CDA029D186CD1,1,"Microsoft Windows",C:\WINDOWS\MICROSOFT.NET\FRAMEWORK64\V4.0.30319\SERVICEMODELEVENTS.DLL FI2=139256,75DCE4E5FA08CCEAF4D3D30FE8E26903FCDD14CC852E820F63B40F374C706DBD,B9D455C60292DF5FCB064834CA5802AA,1,"Microsoft Windows",C:\WINDOWS\MICROSOFT.NET\FRAMEWORK64\V4.0.30319\SMSVCHOST.EXE FI2=44528,324E44A8E9CE0DD650E030DEC167DD7FBB749BF2A972AAAA949CB6CA5DE766CD,4D26051BD7778D7C88DD6C7E3C419D49,1,"Netgear Incorporated",C:\WINDOWS\RUNSW.EXE FI2=156480,3759AB1B549F440D6769F9BDDF38A5562B0AB938B93A1CD172BEFAF133963EDE,00C358B55509EAAE79292D8E61FC317E,1,"Microsoft Windows",C:\WINDOWS\SERVICING\TRUSTEDINSTALLER.EXE FI2=499184,B5A288FF6B9CCE341B407A206A4A406B653CD614214AD6D63CBE900A983B5661,8BEA8BB8AE04B709E30AA3A78C389762,1,"Netgear Incorporated",C:\WINDOWS\SWUSB.EXE FI2=2560,B10ACD7AA94FFA1155816EBDAD9E11F0723B1676A214D9A02306B6F7141F1325,594DC05001C49200B6617FC002B9D271,1,"Microsoft Windows",C:\WINDOWS\SYSNATIVE\COMRES.DLL FI2=14336,F6592E0998D2C0C0E3FB9E50C71102D35CE5CF1300D51CC10FB32AF0B3E4F050,8F7F0D8C6CA4ECAB7A1E041A4DBD5DDC,1,"Microsoft Windows",C:\WINDOWS\SYSNATIVE\D3D8THK.DLL FI2=592384,6C8044E85369C22E136D571C68922556DCCAD70D9495116AE6C200F7CA024080,215218FD324CFB4DC4248204FD2B0176,1,"Microsoft Windows",C:\WINDOWS\SYSNATIVE\DDRAW.DLL FI2=829504,13234B716FD6945725047564155BBBCC696A9146F6254A019F56A62218A27CC1,C123B395A027AF02EC36CEAA8A75690B,1,"Microsoft Windows",C:\WINDOWS\SYSNATIVE\DNSAPI.DLL FI2=615424,7E7D1D2E2DCA3D228A4A1C6A33885096CC884281A69963670851AA51CF093D1C,E6A43513FF267EAF7A112F94A403A5A5,1,"Microsoft Windows",C:\WINDOWS\SYSNATIVE\DSOUND.DLL FI2=402432,4460708EB7CF6B3240B8C2E1E26B391EBDB5F61FB193DA1E4B9DB0B5B382200A,59AB1D7453792E34B1BC6F48EC15C304,1,"Microsoft Windows",C:\WINDOWS\SYSNATIVE\HNETCFG.DLL FI2=185448,00053AA7BE3825828AD7C8C1C9F9AD29DF07F5538107479886D8427DF86BB4F0,669D9741E74156425354DDAB8BCC581E,1,"Microsoft Windows",C:\WINDOWS\SYSNATIVE\IMM32.DLL FI2=230392,41F7A696A02B5DCBA85E12A4999423BDEBB1215662059ADAE955F8081E3FFA78,567A217405F41CAEA18F4BAB50D480FD,1,"Microsoft Windows",C:\WINDOWS\SYSNATIVE\IPHLPAPI.DLL FI2=23264,D284E0301679ECEF1B763ADDD6BECE589BB16E4B7D5C4FBE3D8684121E8F0B74,0A8F948D4A63F5C70F9E0A6525E1B07E,1,"Microsoft Windows",C:\WINDOWS\SYSNATIVE\KSUSER.DLL FI2=3072,63F5E2194D63AC11A2B231C9D4AE10F07AE9C451F1420606888E0786F8DD0EDA,735F69CD4593180ECD3E0E3A9E1940F9,1,"Microsoft Windows",C:\WINDOWS\SYSNATIVE\LPK.DLL FI2=26624,7B09440B1F018B5AF02001C4832B284ACFEE6C7BD94EC003BB97152D7EC7D614,935AC506D4344DD6A9FA2D1230D20388,1,"Microsoft Windows",C:\WINDOWS\SYSNATIVE\MIDIMAP.DLL FI2=10752,D04C4BA8DE116B4E97F9315267C0F132CB012031033B16BA7C40861E99DE4574,10755FC2FC8FDA921FB2897E19DC7A67,1,"Microsoft Windows",C:\WINDOWS\SYSNATIVE\MSCTFIME.IME FI2=23449600,2A0991A46E13DC3A1E9056B90D9593B42F176FE35F5CA54E910F8A420480725B,E3458A2E2AF1E610040E893AB4F7291B,1,"Microsoft Windows",C:\WINDOWS\SYSNATIVE\MSHTML.DLL FI2=8192,A4612A0DC28EDC05F30E42E101878FD769E3B453A46E96241F582CD8BF1F8110,77A4D54797FB8141238188025249A655,1,"Microsoft Windows",C:\WINDOWS\SYSNATIVE\MSIMG32.DLL FI2=418416,055F34466511DBEBA4F082B110216CE9C1C7F056D4F1440D62D5442971A7B1CC,89CA286E36756DD0DDE53ACD953F44DC,1,"Microsoft Windows",C:\WINDOWS\SYSNATIVE\MSWSOCK.DLL FI2=70144,0A8C9CDE1DC0575DCF76512FCDEC87D70CFE15771417642642CA7D011A4AE2A0,5CFFCD8657BD679A9A27B724F00AEA3A,1,"Microsoft Windows",C:\WINDOWS\SYSNATIVE\NAPINSP.DLL FI2=97280,3E50715AAB283921A9BBA428095394CB7A3BE80B76E73FFC160183BB10EA94B0,EE3CE6D4F6ED928DFC5EC34177646404,1,"Microsoft Windows",C:\WINDOWS\SYSNATIVE\NLAAPI.DLL FI2=89088,0C65ED5C1EE3B0C8103D911F3FB2C9A7A8F0B398A9B349786F0C66313839C3AE,F5141D957403B35702947066051CB944,1,"Microsoft Windows",C:\WINDOWS\SYSNATIVE\PNRPNSP.DLL FI2=17408,09C0AE0B24ECD58687CF629AE25348EECEEA7347E7D425F0ECCC74B808A5D1F3,1FA4C02BE0E529389C1C7243C3A23B34,1,"Microsoft Windows",C:\WINDOWS\SYSNATIVE\RASADHLP.DLL FI2=975872,FE9A467804D9CFED433FEDE8848CEBBA7CEA1F8477614C70A551969070360C7E,F784A6970481BAF4E8639F325243C417,1,"Microsoft Windows",C:\WINDOWS\SYSNATIVE\RASAPI32.DLL FI2=1330176,79AACCB16ED20D2683B1231BDBC3E69F9EF6F85F7DEF2B2FF5607BB9525C71FA,EBD998A6A7842E695702A978BBABDD46,1,"Microsoft Windows",C:\WINDOWS\SYSNATIVE\RPCSS.DLL FI2=344064,C27C201DF01753AC06609F240CDB8168D3ADC2918A9B4C1D8E1AF06A9AE6A36A,0A7E6CE68D60D0F1D272B82002E6B535,1,"Microsoft Windows",C:\WINDOWS\SYSNATIVE\SCECLI.DLL FI2=714856,DFBEA9E8C316D9BC118B454B0C722CD674C30D0A256340200E2C3A7480CBA674,D8E577BF078C45954F4531885478D5A9,1,"Microsoft Windows",C:\WINDOWS\SYSNATIVE\SERVICES.EXE FI2=1213744,1F0875F49E31DE740CD7C61214C581C19EC7A8FCEE3845DCA2D5268D0B1AE340,43138F021C2CAD9B0261BC76D5FA024D,1,"Microsoft Windows",C:\WINDOWS\SYSNATIVE\TASKMGR.EXE FI2=1702416,8BD5191AD142A6E9F9648434FBBB14B0E2FF2FD7CF445D90F0791CBFC2D23805,A344B6C6304FCD7DAE72DACA784EE53C,1,"Microsoft Windows",C:\WINDOWS\SYSNATIVE\USER32.DLL FI2=627712,8AD2C6EFCD9DBCD0C14BC38208E03E283B3DBBD4C2523B3DF409A9B498F05DBD,22F5532482C54298DB01CBA965444A3D,1,"Microsoft Windows",C:\WINDOWS\SYSNATIVE\UXTHEME.DLL FI2=907776,6BCB35BA7CDFE08E2C3A2E77CAC9FACC8152A97DF411A4EEC1985D0B09CF6E8C,EE86712DDF0C59E6921D548B5548FF9C,1,"Microsoft Windows",C:\WINDOWS\SYSNATIVE\WINLOGON.EXE FI2=49152,A47CE5A6EED111C67CD7C2FC6B4B9C44426115DF723B94644EF6FAF8BBA95712,11B768C4A439A4D895F511836C18F3C5,1,"Microsoft Windows",C:\WINDOWS\SYSNATIVE\WINRNR.DLL FI2=4608,B45001D6EAABD3C87EAA1038C3FC8E912258FA7896C2B65117ED7DE2E83683F9,1EB8F9A912715EA39EB85617FB12608A,1,"Microsoft Windows",C:\WINDOWS\SYSNATIVE\WS2HELP.DLL FI2=64000,FACAB1FB45CC5689D131B17DC094A4E44068F00C2D447BB78CB74E880CB004C6,5D45B3C64D79C5120F4C48B4D77CF99D,1,"Microsoft Windows",C:\WINDOWS\SYSNATIVE\WSHBTH.DLL FI2=475136,2894D16C80C6F70BD92BAC113160056D9C2DA84CC672CB4903CA33314761ACCA,5D3EF673CC789ABCD1F1B1A0F17EF8B8,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\AARSVC.DLL FI2=13312,B8AF48FC5DC8371D6B00B16029E9AB9027E2DA86FA6D8DBDA181DF464226A3A8,1E997CFEB32F22E84B4EA3DB2EA66B56,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\ACPROXY.DLL FI2=13312,BF515AA1BB9865424FA665D4E781980135CB44422A84E8C63ED18B000E7541B8,A49C26AA0CADD994DE158F51CB7EEFBC,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\AGENTACTIVATIONRUNTIMESTARTER.EXE FI2=26112,4E2623243A9BB61F7211E591C24EDB70B07974A7FA21E3F14C683F27E975777F,526FE18DB976D9A1AE19FBC53FA690B1,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\AJROUTER.DLL FI2=95744,6ABE94DF833EC0E6D145429BBA99FDCA9AD3FCBB685A432B20C04F74DE9A42A5,551C155F4FCE82BBA4CC92E56F1ECB84,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\ALG.EXE FI2=38320,01D51DF682136CCE453BB1DA8964073E6BC7297CE4DAE7301C753BB618A69469,D0C50C113FE59C21AD59932E6B9C202F,1,"CHENGDU AOMEI Tech Co., Ltd.",C:\WINDOWS\SYSTEM32\AMPA.SYS FI2=351744,CE1B45DC50B6D82D85DAE5EEED4EA2A7D3E5AFAB24957437679CB366B6BE33C4,8BBF06E5B2A4E5A1A74230003F6AAAA7,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\APHOSTSERVICE.DLL FI2=1487360,EF13B9BC77036F0453948372989FE62AD6F48C1933A91E21F16868888A2DA67A,D07E57989147F3777A1D9C728630DFCD,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\APMON.DLL FI2=570880,426772C63E04E58AE45494D063AB7CA551E69D1CE7B9972CEC9E25FA8F427C1C,A1F85CED28142B87D7564C686456E620,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\APPHELP.DLL FI2=120320,69C0D08149AEE10F9A6EE68D19143E2CE80047AB9E07FBDA5B2BF964E06A03CE,9709FB202693DBEC05127519EE4B65A9,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\APPHOSTREGISTRATIONVERIFIER.EXE FI2=64000,AA10B8BA3C2F360FFF0177C67762FE87FE1BB514BB92A4CB2DB875FD58877CED,CFC695546BEBF7EB14DD80A2B72A5A4B,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\APPIDCERTSTORECHECK.EXE FI2=160768,919004EED67BDFDC78B786913B9BB811C87526A42381633B27D69D32E5F3E143,B930ECCB83FF928D9D2E921BAFA904BD,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\APPIDPOLICYCONVERTER.EXE FI2=85504,BF06A9EDC745FC31F94CD0226F4220C827564F63C6B84B5A318C01A167794EE9,1A01661551D2C7A41B82D45D9DC66B72,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\APPIDSVC.DLL FI2=221184,9213405FD3EE00890A7AB682011C3E6922A2CF452BBF5ECB79FB2883164595FF,F68CF722F0F7562CC6BF9CA4E253833B,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\APPINFO.DLL FI2=78456,CF58E424B86775E6F2354291052126A646F842FFF811B730714DFBBD8EBC71A4,D58A8A987A8DAFAD9DC32A548CC061E7,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\APPLICATIONFRAMEHOST.EXE FI2=114688,99FD880D97056FAB285D44BAEBE68290C5BA262BAFDD0DD9282D624B38EF472E,C2D57123BE9D92C387344C9EC3D34EA7,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\APPMON.DLL FI2=651776,C406658C076AB5295F5B3830125D39E3A8049EF4E01C453FE4CB411C31D50C78,188973F42C88B759B60AB3C39231C9DC,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\APPREADINESS.DLL FI2=1014400,9566AA7E57D0741BBEEB8FE4841ADD4C756D0DE80F10E8983D9B9B5F0DB14CA7,54693C61BBC07F3C9AE5FA49AA7ED8D5,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\APPXDEPLOYMENTCLIENT.DLL FI2=585240,BE7B4D24854A80A2CB08F3F7E8C09E3B06C86B420DC867120306AAA6981A40CC,FDBB767A71F688E46B329072806EEA51,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\AUDIODG.EXE FI2=751616,C53E8048F2DF625473D08D7AED1E8DC5213A12FA77257CC72B223633F0A7843A,38E334B05DAB2D676B905F52286A1783,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\AUDIOENDPOINTBUILDER.DLL FI2=1566608,BE10BA8B5E9F79F5C992E61C15C0048AE062911775A8F8ABF2BED8D371242853,7941CFC895732B9494F1B12016FF805A,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\AUDIOSES.DLL FI2=1843712,DC3DCAF17A0E931546EE5B100F9E01D58ACDBBF1FF52A7D297C3D2812D5F13BD,32BDE5C10D948F258F4D1DCB45899959,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\AUDIOSRV.DLL FI2=114176,7DBF94761B806AB47DBC948E723D718852416DC0E311CB40F31A55DA0DCB267F,A0F7C552FA2B0D848758F5010A7B3AE3,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\AUTOTIMESVC.DLL FI2=116736,EB39D46FA07E7DC9028C671F45C5B51D8DC9B41977AC26D318AB39CD4382A0FB,FCE104053ECADACF4AFAFEC2FE805DBB,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\AXINSTSV.DLL FI2=1384448,80ABB04EDCB43F3119E267F0F12D12C113C38BE045AC5E1B6D02AB5B824795C1,590C5EC2F45F7602824E3CFA857F59CB,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\BCASTDVRUSERSERVICE.DLL FI2=244736,852709D2AD935F5137C8BFF7325B4BD3868B37019F1DE11680BB60C1BE98E48C,5CB8F213EDA3EF00F690A760E41A9E69,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\BCDBOOT.EXE FI2=555008,799FBAC959604DCD74F39A33B0CAFE3BE91281BA11813FEF9F048B2A5B2D854C,4E1A85F8F93B8F77EF564D269E5153D9,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\BDESVC.DLL FI2=887296,48935DA14CE82F01D417246A8F51FCB3B7C5806C7745EF2388005EEA2BE643DD,EBB00FFDDBE1F5C16C35B5FA50A97EC9,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\BFE.DLL FI2=77824,017FB0D2F56AAEA5C76CCE05FD601EB94A48056E1A3285BE1AECEFBE42E1D98B,31B5040254E636587C7C9B20B702752F,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\BLBEVENTS.DLL FI2=140800,169C56B69240CBE2E045CA26B6F6BF29E406D9D8EF40BA55FFE0667F6BB6D75B,35F152A2299ABF0CFB101DF5001CD7E2,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\BROWSER.DLL FI2=1023488,0002AEED8641E41CB078E421177E359B801776206582FA0BE0EF7AF01D6ACC8A,B3EEA459B367A168F8769625A76BF792,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\BTAGSERVICE.DLL FI2=392192,C9E7026721376AF34BE93090CD51EA87CA6847C0266E4750D6F1B79DFC57B0D5,CA357A092094B5550CB646ACF8F75773,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\BTHAVCTPSVC.DLL FI2=213504,1E536D8863D695944214D55E9B0B4BFE04F705DB7ECA18A0CF8B37AAF4893B1E,D293AC628357F2F75B8579087F732970,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\BTHSERV.DLL FI2=40448,CF5AE95C9FDAFE5F0CC9D7010412E84502FE66AD60F57DFDF68735B9315FF444,4DCD6FCABF20FBC8BFB11A9F6E4B77F0,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\BTHUDTASK.EXE FI2=391168,D3681399A0458B9183C12B7F26980959EBD4BB0AEA1084497F2436339AD9E758,54C6958CF06D6BB1776844811C34868C,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\CAPABILITYACCESSMANAGER.DLL FI2=130560,196215BFE0F198C8201B407C7E39A15E3180E8D03A051B3CEBE88FFFAB4072CE,D73124119E80A2E13A1D5A7B7CD00889,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\CAPTURESERVICE.DLL FI2=1024000,2A2F5993F3BEB7786B7315C54D13508A4665B368859CAAEF428FF903F6994D0F,D1A0272EAA07B5AF0A79B3691501B7B2,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\CBDHSVC.DLL FI2=611328,F832A896ACD0F22BBFBEC91A07DC302C861D36E465B5BA5AB748126599DA737D,7BAF54DBBE25E778A8C8884ADD37E4A1,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\CDPSVC.DLL FI2=491520,690A495C13EFAF52ECA123C460B9308E0B67C57C118EDC5944E852641ED95736,CBCBFB017C73DB757A2058876FAA85B9,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\CDPUSERSVC.DLL FI2=558080,32561C3E308C98F0A0873B5D52EF81EE5E7718232018C4EF308AB7E0EECDCB30,A8467102D2300595BC0B8F2C2EC4642D,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\CERTCLI.DLL FI2=3311104,4329E0C118712038213FC0CF06A3830F70CB5C9E808A8ABBF8759B39B73E829A,A2C12821FEB7FCF6EF30F15C634868A2,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\CERTENROLL.DLL FI2=196608,9319B5AA78248E53DA529567CBA4D57DD7D93A43218FD66C9EFE2A10C7430581,90A4F493C691ABF5A0C231A62F309D88,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\CERTPROP.DLL FI2=320000,87D5153BEC20F9B2E61FB6C6E4F0E49E48AE50691912CE793A599299D31EF671,EF759FBF8AEE871C4ACCAC4A2EF8F9EE,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\CLEANMGR.EXE FI2=152080,F6E6F9043A1DDB2028D7960E9269E174ACBB54242099B0F6160E081DFBF564CE,F9C43C85CB2068DF7DEB1C9D58046400,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\CLIPRENEW.EXE FI2=1124432,503D725BF319EEC6FFA3863BBC89C309DBB4FB28150600FAF81CE3355160DF7F,587124D2946FFD179D8399AC3FF85D06,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\CLIPSVC.DLL FI2=1128536,976124D09BE547F08E23B8CBB8116CD95146F9E0B366DD76963055A3BB0AF2CB,30858F924D2F706A63F2A0686A055BB3,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\CLIPUP.EXE FI2=3505456,0C62473726A957F33C9FCDB356CA337C80D30A329A8FD2DECECC0FCCE287B213,0880703D53BE0E46CDB679D5ED60D222,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\COMBASE.DLL FI2=160072,2BF5D8E400FE776B3A9F5400BA212AD8D638CC44E7F906E7800BE5054445EECC,68BA4D63EA7CC43189EAD2EB67C7756B,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\COMPATTELRUNNER.EXE FI2=875008,6651AB6C5C6D85C86B0C6C532115662E09F338FA8CC1233E1434139346F25EF6,81CA40085FC75BABD2C91D18AA9FFA68,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\CONHOST.EXE FI2=170496,CAAC41134F6E01815888707D2FB76703B7A869912832D2173726B17511C3B17F,30567F197E1E1415FD5813FCE895E332,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\CONSENTUXCLIENT.DLL FI2=986464,C01C15C82A8568BA99BF193FBC4893D990102B0CBAAFE04F4F02B9FE44AE6C76,724677D5055D40798DB093C26CEFD179,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\COREMESSAGING.DLL FI2=388888,2675AFF8FB16240C5A91ECFA5F80EED5A3574E4C5BC51EE2F814915518CB5726,07F6D0B58C5D34233D6AB67CDB917D6E,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\CREDENTIALENROLLMENTMANAGER.EXE FI2=1425440,0C53A18434AD6686CB146CE4DB01759D1941EE01B6977E123DF3D2EABCAF963E,DF2A83302FE5497B9D1BF17AB432D7F6,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\CRYPT32.DLL FI2=104960,5171ED876E0EC5CAE2BE9161ACC90F4865FF6416EFA376C82D8A5B65724A8910,8AB3568419872D1A8A7B45153AF7B3D4,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\CRYPTSVC.DLL FI2=11264,484FED5F039F429ED933931BA607B7EFDA7D1A343D79CFAB60910E1843147012,B625C18E177D5BEB5A6F6432CCF46FB3,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\CTFMON.EXE FI2=489472,50663E38F9E5207F3F4B57AEDD6710DC7326514F8CE8A220C8046108A5B46128,0CE0E536400C33F01675B1B553388338,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DAS.DLL FI2=98816,88FD7E7E15D4C8B22C355ED56EDD45734F05A55A5BDC18EC1917583194ECD981,B3EEF1835548CEB20C282AAC9AA8E387,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DASHOST.EXE FI2=35760,7BE327777B40547625E9BF5B91B00B7AE0B5507DB85DE9741B995A4F6AFEFC12,DF6465F349C9CBDF3FCEB3F198E8FCB6,1,"CHENGDU AOMEI Tech Co., Ltd.",C:\WINDOWS\SYSTEM32\DDMDRV.SYS FI2=210432,7A18DBBE6CA138389424A7B2C0135BA4A7541C33E0443227F3CF505B58B52A85,E2601E315E9A9837279A23963F5819B0,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DEFRAG.EXE FI2=557056,35336104BAF044D366C39ECE466FE6C73E24F6598ABE4C220F8F4CAEC97C4FB7,F7A5EFB32CF4216226AD16B8D35044CC,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DEFRAGSVC.DLL FI2=240688,8ECC1BFC020320F45AB8CC8CDDFF36E0A656C013C6777A1F5CF3644B48C7143C,972BAD4EF3561D3E8E5B34C1E563D9A9,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DEVICEACCESS.DLL FI2=57672,787BABC5276737F5F0D1063300883D3381C57A344CC787DEB16BADAAB6D04DD7,E4E45A9E9E546C9553820B2D876A3BA3,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DEVICECENSUS.EXE FI2=288256,3C0FE5F039318C57C06FE733FAC00C2753B25905833DC4D76304757EBA5155A5,25260949377D51A7DF55CC4116D1E328,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DEVICESETUPMANAGER.DLL FI2=598016,1B5B06E47CBEFA8495BEF86F00AF926D3039039CCE8DB740537F757907BDE475,1FB4EE20C9D333C3F8D90C3726C60E3E,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DEVICESFLOWBROKER.DLL FI2=65024,EABF953864C0AE4FB6426C0B7E92DD81EE4A8852081F9D2EA02B61D4C8DB6188,F8BE99B9EA9B110F7CB3F46BA844C1FF,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DEVQUERYBROKER.DLL FI2=47616,AAF48536FF3F62D533FD60BEB025C39ED54BD2ECDB5083310450A15FE1CBD268,9E909D27F17231BD05946EF22BD3E18F,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DFDTS.DLL FI2=54784,548A3C7EC9AD1BB63F6CC21F4AE2A3B2317EFAD5B02031F542A18E3132022972,41ABE514F48858221260F689DC214B3A,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DFDWIZ.EXE FI2=400384,27249AD224AE3017638E3F39411B7F2DD200F65F18484CD234D819E913AA25EF,8AC7ACB73C07E9AEAE67CF340B2E465B,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DHCPCORE.DLL FI2=237056,F89F4B31E7C3A5DE7E8CD2C50BA763514A0BF189E9C46A520B8FFE7515EF6229,5B72264FDBF129F1C93881A0F9D1E7E6,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DIAGSVC.DLL FI2=94208,F4306705AB7722EB68CF4E24FFA1353B3D36B475B57F90B9E9AE8D16CF64E6B2,3F598EED05480B8D64631D2EEA3A6F20,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DIAGSVCS\DIAGNOSTICSHUB.STANDARDCOLLECTOR.SERVICE.EXE FI2=3816960,CF3139E74D920E10FA759CC349B3D61A5C2611AF610224FED1B29BB74C587E83,597DAA1AA825FF7B5F809ED8231F0F0D,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DIAGTRACK.DLL FI2=44544,E14B46BEB19687C0995D8EDEFF7B90F94C6545984451F827D853F72E597D6A6F,4FFD43A733E4F0EC06DD32552CBE36A6,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DIMSJOB.DLL FI2=48640,A0AC67687618623AA7472111165B728530B002E8FDCF2FA290967D8EC56107DA,94BDBB4A57106949E4DC0E1256C30D19,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DIMSROAM.DLL FI2=285696,991CE997A7016BDE458D4F30635099E3F70F4BC0D8BF392D95A411FA7A173A53,A5B525B394B82D4F4054C79BBE771451,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DIRECTXDATABASEUPDATER.EXE FI2=84480,2AF7212A150B721D0105928864DF0049A4D959AD7B5B997DF47BA69B434404B3,FD450157FCC92C0A80EC3CF22AB5E4B3,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DISKSNAPSHOT.EXE FI2=382976,E5F370678ED7F66D05C134638C035DC6005522ED57FB612A6FDA3E1E20942879,86FE9C6E85152A177BE5B3BC75525409,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DISPBROKER.DESKTOP.DLL FI2=21312,E7FC40B41AA8B83841A0B96D169EAF0800AA784733E636935374D56536253F10,08EB78E5BE019DF044C26B14703BD1FA,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DLLHOST.EXE FI2=121344,3D97CAB2179C3AB9C975808A12C97A9A06D672B180AE04880DDFFE69925AAEFF,FD408CADC0ABF7D23D62FB913BA5F02E,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DMCLIENT.EXE FI2=58880,2FDB34E2A61457308B0FEC938A2D6351F63D02BB67DC87FE4F2534E0048C8E89,2E8A026D6680C301ADF6D4B301A4CE8B,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DMWAPPUSHSVC.DLL FI2=356352,5D0470B1C50BA09EDDF8459D0240543C584C87A2573DBF4D054513CBBAB57C4B,26C675BAD11B01826CC8BF6758CC4FF8,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DNSRSLVR.DLL FI2=1494528,84B8159E50A884759EFA29D215A1A6CD63CB36831789E3F02E5EF5A7516694C3,6BA7BB408F4FB342F299932810F44003,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DOSVC.DLL FI2=279552,B2AB5F05F8ECE1FE7AE0AE8D4194473F6A4EAABEEF832515790F49AB610C302C,7C9284102021F132941C0A364E6BFE0C,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DOT3SVC.DLL FI2=175616,A8707BD19D584DAECA39990A2E791194140AFCA4FCE31F23CC7E931DF8C17361,9E65C33CB7FB50453F7F4407070EAF53,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DPS.DLL FI2=266240,3D6E0579821BFA91B7F0A6E6DDC6E03BD3389202AD1A079B825D18D2A76250A0,AF50A9D10FF7B1D999BA99D00CC128B3,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\1394OHCI.SYS FI2=107320,5A29D80AF47D08998125CB81BC1D4E84093291A74DE422B63F7BBDA7BDE95311,1C29610EDF5FE3C9D313207BD65BCDD0,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\3WARE.SYS FI2=7957576,23C4DA3BC8768B6769CBF623496739804C33C6B362B32772AE336C2C9F29305D,AD7C104E7D096622034B5A955D0BC69E,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\A7000.SYS FI2=809288,37328E9BDF7242B8A44CE71A2750FFB7BB7B3C761BD3214C16A36D4E2944840B,43FB8BB52B9333E8C6A76DDEC0BF8CFC,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\ACPI.SYS FI2=23040,1D576471A8035AD3FF5B0616F47B79E43AA367ECDF009D7CADDA0F11F13A1345,6A424E6ABD1970E23ECF3DA85725B6BF,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\ACPIDEV.SYS FI2=139792,34856C805B67F3EE4ABFD81B61879112344C343BC7E76A7A466FAD276E0E5165,70D9FC69CED08E86B888717CC5C37367,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\ACPIEX.SYS FI2=14336,3A9A504797FD22BB5447BB36597D5001320ABC0D4A1853D478C038EAC6847913,EF7CB34FB2D56305EF942012499AB8F7,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\ACPIPAGR.SYS FI2=18432,1E7C5FADA2486EE31289A4BEFB70AEA173190671C64995441651903CF31E5033,33B5ED555018128792AFFCDC9AF7AFD2,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\ACPIPMI.SYS FI2=16384,72D35F5DB8714D38E4050A7F7A457C4AD99E3EA212040704F1C1ECBB70E865E9,85A86944A6163F0B7A8B10203B70CB9A,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\ACPITIME.SYS FI2=415232,897A9C367AD464F0CB4DEB4E53CD788D75673B0F84241D5CEE2DBE64BE038818,0A5B95079E8854FFDB8ABC057812AD8B,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\ACX01000.SYS FI2=1135416,B83072D77685F973701EC6629D8AC2626FDEFD657A4DB9AA7D532960A29FC67C,B4B75D49BFBCFB2762593F77E5BD7789,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\ADP80XX.SYS FI2=653624,2309ECF28B2FC55B9F3267824153E07E65AE7ACF5F871FF5354F2D1FFDACB84C,0DB0095571042B928E301005C35A8FF3,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\AFD.SYS FI2=41984,D83B788A59F84071260695A6C71ACF6AD4760C11F0E249E266A666E4648B3C9A,F7EE34360235227A7AC164215A583EE6,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\AFUNIX.SYS FI2=113152,725FD3D8D03FF6272568761BBC19D3E35736909521470BC1F8485D5172CA6497,121A6FDCFF9EBB6C40B5C98D882C0644,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\AGILEVPN.SYS FI2=292352,F2BBD6F46E55B64F0F5798A029DD51433E961712C1FED12999199FA49058776D,E6C21EB564C1A177B484C3A53AEA49BF,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\AHCACHE.SYS FI2=18432,46A53925BAA34FA9D87E7C3157504A4557D81CD8B8608E7AB6CAF02F482F7792,55578CF027B0AE9F0D653B209C9F1B6D,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\AMDGPIO2.SYS FI2=45568,387811D57DEF06C9736D9F0BAB0DFB0F83DBAB19E5489BF9A6DCDCBD682DD8FE,D0E26E590DE1424CCC4F77D1687049EF,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\AMDI2C.SYS FI2=207160,1DE9419C351546F4B8747AA46422311F8D1610CCA4FD050D2E2D63B6A5A839C3,532C470012279A4E43BB2ECFB5485F95,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\AMDK8.SYS FI2=211256,DBAA893F1889C5B433786A1F0A5491389A8ED465E1BF2E9C486605F0D4F054CF,6EAC24D762ED653A5FB78B9BD871C200,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\AMDPPM.SYS FI2=83256,D5231F97E5432234A8A19904E59C324E825AF04881AA195C19CCC9E6A7684B14,70D7BE6BB8D22A38AD0040A1EC41C1FE,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\AMDSATA.SYS FI2=259384,71C7E7E5AA74596A6725D8F70F1DE9A0C63D3C3E120D9CCF8A508854AC340A23,C47EDC5D81546677A772CFC86281ED29,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\AMDSBS.SYS FI2=26936,1FC1D4287DB56A387BDF917C0CB3BFC30CA5D792A350E2EDBBDDEBF8127E1AF9,F1A1CA86A1E3782A0CABB07EF3663C70,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\AMDXATA.SYS FI2=208712,2540C72862908F3D4FE510CF824347175D4F28F8155BD7CE5BB7B56B792362C2,85DE5D778496C6031F103376EB7679B0,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\APPID.SYS FI2=18432,1E8729E07A039CB6D0FC911911FE8E5BB1DA977181703B48C9F95DE8B1756629,736774D0D8EBD02D09E95D31091F0046,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\APPLOCKERFLTR.SYS FI2=131896,96DCA25AE619F38640B22702A10BC3191626F3A36DE0E1B0EDA3B079EA9DEB24,46FD8469080917EE12425AF692C4BC20,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\ARCSAS.SYS FI2=31232,14985D6D2D52689C1B012F64ED0D7C9C5F6BADB51C4528BF6456D3EAE2FE69A7,D930AAE80A55116D07C41E95DE5671DB,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\ASYNCMAC.SYS FI2=30008,9254320E8144FF1F4AA964B77D916D0261F28EA56F71E2DC0D5E6F01582EFD82,EB97D643FAC7A8EB66A53E87D85E8C64,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\ATAPI.SYS FI2=78136,7D06B6499FE915480DF4DAD658281C8B85F7AD71F49B089A270AE0B45713F2E9,26E2320D24C66EB72B36EB71EBEF2558,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\BAM.SYS FI2=9728,9AD12E18A042C5B8EFB19297BC2E7BD1FEF75A138FEFB64C6BF0261FD3E53AB1,739D089777D2B66DBE7201E5EA4BA2D7,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\BCMFN2.SYS FI2=148808,435A3617B1D57D0E5464052FC0FEF168024E8069B5C4F5946EE794106124933D,6EB4925504548515C019D5581D08C915,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\BINDFLT.SYS FI2=117760,43B59FBBF26B3DA74CE5C760DCC08E5DA371ABB3E8AAE0474C87B0E5ECD4F233,C924FC7D0E2CFC70BC94CB8B2B74D405,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\BOWSER.SYS FI2=127488,A3AA5D51E34657479CFCDC3DBB7821B7255F7CB57D5686B7F709A7953AD537EB,E587396A4C8151ABBF13A96C4465DE31,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\BRIDGE.SYS FI2=279040,0442A18BBED4E323265C66561C8F8C171D8E934E9089C12B94D1DFDBB057B737,7F09708B8C651A0C0E2A2725136BA254,2,,C:\WINDOWS\SYSTEM32\DRIVERS\BTHA2DP.SYS FI2=113664,98D6B28C34477FB77B6B91B8761352CF8E01C10D3A51AB3D9112A555EA6B1DA2,950DC925935B5BFD6394F90AE305D126,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\BTHENUM.SYS FI2=144896,91C72C54142A0D4E5A5F33268850CEB8315AA30C2F0B74A9FFA962887ABAC797,7AE44E94C6B1DF488AA309824DEAD643,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\BTHHFENUM.SYS FI2=45568,BF7B8D5F71DA193EE3DFFA4D414F77348E06206D5D7AADAF944B9EA15BCBB1A9,DAEAEFF6DEDF1440803A0F237FF90A77,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\BTHMINI.SYS FI2=76800,9412DC92F16C0B8A937D6FB1AD83D7169F4EC0F08FAE0E2B244346428CE99EE1,11D609CC74F0EB1DF6C0171331CDE9A1,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\BTHMODEM.SYS FI2=1560064,CDC51348E2B9FA59BC6042BE12831E5CA4CA07A4DE76E5C16E2F316392A69551,811DC6B7EA2DEE5B3BCF3B5483CF84DF,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\BTHPORT.SYS FI2=110592,67CF0AF898F7F3BED0BC715A6BE61020E7F1CF284DEB50C357E2DB5FC7D4962C,A33172999C91BD87FF1598EE4FAC9989,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\BTHUSB.SYS FI2=43832,8DE3B7C87D88CF375417355A7C5052B2DE38805B563D61D0E483DB4AD96BD741,4FF20E869FE2B5A0B8CE2E8BE61C7F7F,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\BTTFLT.SYS FI2=44032,16A900FBAB30D008F01F4CAE96347BF313D9D13C7FE430249A0BF4322534CB18,EF2A1F3C5EC4EFFFBE9A69B892FBA29C,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\BUTTONCONVERTER.SYS FI2=533816,FEB2771428706126FEA1CC9A50EBE3CF4F8E8FB6FCB3CA19996497CA44FDAC45,638C59D330A7AF943074678A70F22E7C,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\BXVBDA.SYS FI2=66576,CDBD820B6D383EC0A8151EA4300435C2BAD085EC55DB185C5E16CAF961443888,E7690568D2A5FA3D4E6D28B42358A122,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\CAD.SYS FI2=100864,9E0B3102BE75FB571A884D8CDD79F3A104DD63A53C8A6815C0992232A888321E,764FE2149251A246F6B047A0F09F5F0B,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\CDFS.SYS FI2=181248,0DC465C0A3C08386A019C4A870569E9C5B8A2B214E6293E09228FA79F42DC3F4,7639D45899CC9DB44F106671F8D456AA,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\CDROM.SYS FI2=319800,5A7FD2D58C433B9B498A1B37A2F2D877061215360D8E6A752601F2ED4F283A8F,198D403332FB8F2DA289BEBFEC8199AD,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\CHT4SX64.SYS FI2=1853752,83E2C81274DDBE695EF845E541F7A2DB60EF5E195AE14FACDEEEBD30C0EF4E67,77065056FBE4E29054CB1D20303B9F59,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\CHT4VX64.SYS FI2=52224,564FA08C5BEC6DAF1A83C80C9139A6E1AA7E05D251DB3BA379B57C9FDAE83E1B,115CC1E142CE29C9006D59943108DF47,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\CIRCLASS.SYS FI2=496128,237DD4DA714C708046F91FBE4518F0AF9619CBF8188953E7FF8C78F2BEC28932,BB9373B4E4AC006E34F6F8A257D2BC8B,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\CLDFLT.SYS FI2=411464,54DCDE184634A12555B6DF21B7C747ADC059D37304BC18734322B8BD8088425E,B4558C5F4A1989CADBE9695AA9CFEBA4,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\CLFS.SYS FI2=36864,209723632369404308EF6DF734077A99A295C2E380DB85AD1F8498CC8DFBC88A,E127E772A705CD32BE34166F679C61C8,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\CMBATT.SYS FI2=746400,E9581D34C3D637BF11EC5F0D12EBC56DDA653011152ABA48700782C7FD39D892,CFCC8F1DE0A953C69721BBF80C5484ED,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\CNG.SYS FI2=40968,A06B8002E7A708890222C777DDF8B67FED7015C0943C1FC4F9036E9F9DC14494,A46B4D1484227900F7615FE2A569D828,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\CNGHWASSIST.SYS FI2=57160,2BA33D0D7F9DC35E4EF65128B803EDAF1DD72FE8A6CC7756C0E905F3A7AC4FB7,5EF5AEC75F1F6A3DC8A368D01F58C03D,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\CONDRV.SYS FI2=97096,7B34CD50996D7F1B9636C8CD6612991039C4806B7094CC66CEECBB28E5F8D3F3,4233BF1BA4FDD55A14DA16BE864B7504,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\DAM.SYS FI2=152064,32B76819586DEE9C50215CC74E2BCD41F29BD29A5225F67A363FA40EC93F7E21,3D3CCAFC76E02403E2963A2CB45D61F7,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\DFSC.SYS FI2=98624,30451B36BB163EF5C03EA596B3DE1C658326094FDAF3BEF712D1660CF64F2D4A,E16969E7B0C2759CBFA48DDFF758FD9B,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\DISK.SYS FI2=59192,6604DC0E7607E46B83F1239934646AC4ADF5CA4CC463FB9DF521B243F434579B,48AA813AAA7E347CD7D6D56FE32144C6,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\DMVSC.SYS FI2=16128,8A97F4C5FC8BB83C819409B1E3F70F87D13034B9E6F8F0A041E38ADAADED1D8D,6ADB3F56899519673D735C3C09476234,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\DRMKAUD.SYS FI2=42256,EC601CE7FA6B1B20711993079E5B8323357E9EBB2C40B896DEC2315EBA74D958,9E101F28BB8422848C524E8311E9C0D6,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\DTLITESCSIBUS.SYS FI2=59360,DA09C5C764E200838AE12B5BB2673A6C05FE27A57BAAFE9EC9B4D31671D8F605,1F9F0C5C668AB9AE89FBC1A29ACC4AE0,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\DTLITEUSBBUS.SYS FI2=3784520,6EB89D581C456735EC224534F4E7CA27F0030E47624CE8C9005F60A6B7125145,7E1559D0779B23DC920AF73DD44E6F0F,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\DXGKRNL.SYS FI2=95032,7F5E80B866BAF62CD4A5667F91F05B6AF094BE2EBD4067BBBABA7A9C1C1E6ECB,75335F1918D78A10B8DBD220F394FA75,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\EHSTORCLASS.SYS FI2=124728,514A0687D2ABE6C52D6BFF8F0F5E47DD77EBEEDC4E6C6539B05BD0EC27B6704D,9F04CF369B93A78B2E56A3DF9B41F25F,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\EHSTORTCGDRV.SYS FI2=15872,BF14DB2762B48ACE54977E98DC2A4060B8B1122B58FDEFBB4C84546ABEB410A5,E87F3FA1F9133DEEC1B3692976487777,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\ERRDEV.SYS FI2=3418936,48D9F61E943A7855562950FF26B866BD51A27D980757B065504FCD3F1A1D6F07,E7B7E38AD720352CFE9A5FF3A82AB124,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\EVBDA.SYS FI2=34816,26BC9C2F1D42CE5BEF55E98DC0DA557F09B747186580C796003CF84229F6D151,F567A0C101AECF4548E0BF61EE25D332,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\FDC.SYS FI2=59392,CFFFD7007AB7FB04ECB44D0079BFE8EEB53AECC988135199C388AF425EBCF2AD,8E59D944EE4EFAED65A341A71297C4CD,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\FILECRYPT.SYS FI2=94736,832BF32B9EFA04FBDD9638D00B209DFC88C4C69E0AEC7FF1B5AD4DDEC0F20878,EE7605E60374CBD2DDAAA120FA2E458A,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\FILEINFO.SYS FI2=40448,42C56B93FF52CAC5B74CE0A16D9D4425E8B3E690B3BD76A5A3C657655B62A34A,C7F6F4B73E410087C6DE5658AAD70232,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\FILETRACE.SYS FI2=28672,1534A840C56912D34DEC8F487683C0A782070A89726BF87DFAAF7F953A18A1DA,C867FE1865F45469DD96957900073361,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\FLPYDISK.SYS FI2=430392,6390C3D54E955C42E73B74B1FDFB7BA45965DCBA273B34EDADAC265ADCDD9731,823F66F291F30493AD4120CDD7D377C5,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\FLTMGR.SYS FI2=69968,A5BBD7AC9F33D59DA8DB084E24EB7DA9EC76BB25A27A511FF0271EFC9B590A7D,D444357297A81C6A23BFF8090F03DBC7,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\FSDEPENDS.SYS FI2=800056,7F869115E2121C9CBEE6EE563356415FA453F23B0D313B3F7A08BA052EA523C2,149461E0844403F9CDC21A55A4DCC405,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\FVEVOL.SYS FI2=8704,3E0CC301249B7D8D5BEB932F4DFD1EAB8037679EC153772F63B430713903B0AC,8C06046B6A8C1ACDAEA15682058FDFB4,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\GPUENERGYDRV.SYS FI2=45680,4B576903A83F33A8CF31D3887144A3D51C56D1187115C83AC99C0E9F6B4BF128,7F79205B4EFA98F0767309479C8C01C6,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\HAMDRV.SYS FI2=132608,A73E21AE0EEF6C49D91524B3CF118148809662D7346E6AA335CEAD12164DF073,4BFD517F80F247590AB6C03E3FF55E1A,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\HDAUDBUS.SYS FI2=430080,3BAB7BEB30ED64634587B6EBE625FB78A8C58058AED4151FF83231E0D5CBEFDE,6A3D89AC2F01A375CC6F12FEC588EFC9,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\HDAUDIO.SYS FI2=39440,D773640F980BF832D74FBB5E19FC1FFC06F9401C10698C0C26CFB7C067F3DB73,05FC1B768ACB2D5CADDCA2F2E89F579C,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\HIDBATT.SYS FI2=120320,7704F6F7716D9DF1C3CD81A228B361574A5783DC89A8DFE9B27318EBE3131345,BAA82FAEFCCA50270C6F38D4108403A3,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\HIDBTH.SYS FI2=57344,C161D2122638690CE4DA546CE8827B4BBD96747A4A7D799A776FEC5BC57D1582,1E129E905072A79282D6CC929284DFE5,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\HIDI2C.SYS FI2=55824,60CF06F1668FFFB870E76D8231A090AB3AD7EA44F1F45A36FC28814CC845B94D,1E9F3C9B201614CF4816C5D5B6C570D8,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\HIDINTERRUPT.SYS FI2=48640,6089305AF73CC584963865482448CD5CA4252EC9BD3E72AF16D45E4F95C3EBF2,6B46E3061EC0523CB46ED28060FCD946,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\HIDIR.SYS FI2=66560,EBE1B4498E2214AFD03B6FD8BEF52E07017A45BC7AB1501BA4BEC563C2F16F0D,8E8C163D599B0F075841893DB1CAFB4B,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\HIDSPI.SYS FI2=44032,3D7E7BCE4A5654AEEC62482C850869E20A1AB505B16BD690BA63886C20F25D1D,F59F3C6CAD709A8EFAFC60F989A466EC,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\HIDUSB.SYS FI2=64312,0ADE20523619D5705B941591DF0C19D6B0030F96FECEBBC7A4ADEF963A476383,530C0E730B5E6BA332FB4AC98F760789,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\HPSAMD.SYS FI2=1564984,F4960DC36275DCBFEDA3B6A23691007FA344D2F43322DDAFD7E5C15AE3AB4F6D,1E560F55C14C9CC246B9EF6DDC23627F,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\HTTP.SYS FI2=35128,A5F6858AA556D9180C303EA3ED02EB6D6D8EB55A100B3918654281A01198D8E8,849A66D34BC2DAD0044FAC2FEE1AF956,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\HVCRASH.SYS FI2=95056,D34F93405BE4EA7AEC6A7B5F3CEDC42DC1AD1BA682748C3296439406E1D692D2,F61B11B99BF68F1094C394F2D0317BAE,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\HVSERVICE.SYS FI2=33096,F1CCE47AEC0E653CA6DC04C21CBC78EC6C6D74D4BF329D50BE9A7497ADD1FB3F,D734926DC33F9D7E306F8B3BF68EAC57,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\HWPOLICY.SYS FI2=27448,3DCA435A621FC3CD786E02D013B363ADA9399839E0A31F2969E094F69AD3A183,22362F7C8B7B1456DDF019BFB0523C26,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\HYPERKBD.SYS FI2=41784,157D5626090149A2F71BB483C57CB20259B98C61C35185AA7C6FCD533ABE7D90,BE7559280E3327E9B35E843414957438,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\HYPERVIDEO.SYS FI2=118272,E1887A4E678BBA7226E7EBE5B49EC821C2F23642D321A9E1513F7477E4B9340D,E4B36C6EAAAB703CBFECB92EE590FB31,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\I8042PRT.SYS FI2=36352,FAAA46F22944E043A90AE6E9F0F86AF187FC2819C563DA375B2A409347BB2C35,9E5AECAB5F05218D9AC923E7CEA1CE15,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\IAGPIO.SYS FI2=91136,9296A14590DFD94A3C728CAF3CA91BA211F27974F9CFF8417CDDC00D1453315C,48EDB9B5DAB7D294951A520330F13715,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\IAI2C.SYS FI2=79360,6FF5D13EF69E8FBCB4772C7B5C4D5770C78E0B29F9164FA1611EFDE91CE876BE,6C3EDE394C71D5A67A504F55E35B6F47,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\IALPSS2I_GPIO2.SYS FI2=93184,2141DE558461B592D4111A0388D1AAC8062FA72CD1E2A2D2D68279A9633288E9,806D14CEAF25E5F2DFCBA8E7E33B86BB,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\IALPSS2I_GPIO2_BXT_P.SYS FI2=112128,E353D90D0B79A70F976FD5EA1CB7E25A97835E25116962EA035424715B2F43FE,87DDDAE1693484BD0A210C877BDA00C2,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\IALPSS2I_GPIO2_CNL.SYS FI2=96256,71FDC25244298D62A335769D6ED43394C33FBD8DB05AA54CA924A2977F37858F,8D3E3C431367E3BA632B4396CA662E1A,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\IALPSS2I_GPIO2_GLK.SYS FI2=171520,3F1F9EC7571D0F82D3F5BBA298965491260708F05EBAAA2CC23483521A5FF079,149F1260537C4F68C3F67C363B62F3C5,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\IALPSS2I_I2C.SYS FI2=175104,BF354297A55713D9E2DD4044D42810C007733EE54D5A80D58B96DD279D92C716,3E641E905A6DBF29CBA1E72BBE349808,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\IALPSS2I_I2C_BXT_P.SYS FI2=177152,F105EDD16E38F5C0044CC7139E4084A04B0AE3212171A1C7F6FE759F3F5F77FC,897478D8FACEAE8681F6F3502201EC68,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\IALPSS2I_I2C_CNL.SYS FI2=177664,A92487129B81376471C842B9932FF3A7B3ABBBB89797978E3FDEAF71A6FD5E3F,2ED3B41C7CB4101ACB15D84D8AB5AA9D,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\IALPSS2I_I2C_GLK.SYS FI2=38128,F77696AE55B992154A3B35F7660BD73E0AB35A6ECEEC1931C0D35748CFA605C0,16A10CCEDCF5AC4CAAE43DC9FC40392F,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\IALPSSI_GPIO.SYS FI2=113152,8445E41BAB21964C7F014742795E462BDDC6C37A261990B3D6BF4E637A719547,EB82A11613326691508D9ED9A4FE29E7,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\IALPSSI_I2C.SYS FI2=884752,7274F33E5EED8AF739FFCC80B9A62CDF12553EBD2724E2F8E93FD67376CC6E84,E2E64636CD6A6902BD81AC3B90089484,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\IASTORAVC.SYS FI2=412176,30BEE94794953E2DBF0FC5AFCE0566F335AF022E89819DE145329E7C09C636BD,215525477CBDCD07A82AC518BAE3DEC3,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\IASTORV.SYS FI2=558904,0F3E4F33B019B278B6657B4ECEC25D04B128578622539FF5855330BDB6537545,329F2FEC47FD8754FC44A8F3F283C915,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\IBBUS.SYS FI2=7961584,44D4CEB5B4B981838CE9A969F14DAEB3E2B0AD8415FCF984194EC7DF9F514699,E4E5B3C6EC025DFC8DEB31BA9EACC3F3,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\IGDKMD64.SYS FI2=47104,2F4FE50C3ABB7A37E0ADB4429F18B8067EDE0608BC4539BAC626C2C6D75844B7,9B943585EF2A4917E1BC2186045E4B64,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\INDIRECTKMD.SYS FI2=491048,8B2C30B5FF050B9C313A41B6826D21E3615F44DB18F33B5664AF35DE1B56BA33,D97D001DA974DF9EE4DF9FDC9E5840AB,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\INTCDAUD.SYS FI2=19776,80A7C86087AC43446D46623F0BF1B4FA2CE4B3D654C9C9E311636DD6DC93D220,BA128AB8D0EC8675F88F10534C7DBDF4,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\INTELIDE.SYS FI2=418800,93FB2E2ADD362E93CB95CFC21EB5D4E2476003E6358C7DF03C541ACA1718070D,55DC96148BF90F5032FA5F762112028B,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\INTELPEP.SYS FI2=30720,A62F436C66DEFEB438A7891857DFB830995714A7E4FE4BDCA6B4EB1606BD2101,AECBF5BE2F9A2A50B978E0BF31041A81,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\INTELPMAX.SYS FI2=230728,4827A84CDF5276A12DD1EC09596C29CE9A2A931313CAADEABE2232A0F470CEC0,CDB9CAF7DDFF9B44D568D2CF42C32243,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\INTELPPM.SYS FI2=26608,B2E02C5049357A2DFF1CF4F6F64AC6E1DCCEDC245E96D5BC0585E88E7622D1B9,2213610676B404B157ADFFE312567458,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\INTELTA.SYS FI2=57168,CD855142F264A9756ED8DF075C044C82117C1C0EAB84A1567EF3DC3B8E9CE1FF,BCDEA9631377ADEC401C734B48FD5E40,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\IORATE.SYS FI2=90112,5372C765D38376F62C0CE77E7BB0A9A79069826F507A9B096E8EA9FFCB6A23BA,5C153A211F3D8B8E69CABFBA2BF5BD7E,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\IPFLTDRV.SYS FI2=117584,B3B22C1098303A89A8BD15157C899634475AAC18A4A25383BC7D4C7185AD1B90,401845D7F55CD1EB6AC00DEBCA3FB0B5,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\IPMIDRV.SYS FI2=225280,B71EB3CC4EC95BC9A3FA217736C6C36C756935714D7E16E34C05D913B829CB9C,F63572DF4295C78B3F7036AEDA878176,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\IPNAT.SYS FI2=59704,7A2D92A2274E0379B5FA6351D18E2F0DD55960BB783EA3528FE9E303E1A4256D,B5B6D1F86E40E785D6650DB923DB6BEA,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\IPT.SYS FI2=22840,574968A5B8EED68D0A71466BE2A4AD432871907C2A255EFE156BBDCAD5987E3E,31500D8C02A45E1C5DE00BDEC46AEAA3,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\ISAPNP.SYS FI2=172344,A66C90009C7B20736A8B291889C518CBAF9D0C32A5EC720330EF25F30C056F1B,2DAB988FDD06CACD99B9DB2A05569449,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\ITSAS35I.SYS FI2=71480,7639DCD4328C14F3FB522EC501F4DF374CCBE87699EB4A2B238C9F9C526FDF59,02A6967D5AEF2F15AA9C838DBF3E1C04,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\KBDCLASS.SYS FI2=46592,4DDDE0AF2816A5302511E99FD26F77517EA5C2C6D9BE76D70199A33BF3EE9FE3,DD56D35E1708207B5006B491AFBD47D7,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\KBDHID.SYS FI2=33296,F14AC6EF3695E05CD2D5CD9524AF7D0327E11A8B2BA9315A1EBF53828A608D33,6B7422A382C1788AAF7C6CE6D4A4B375,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\KDNIC.SYS FI2=147280,D93F228DD96076C81AF611F4339E674EDBDD47654A8B3BD2576FB6AEE1D37B64,2F4D89DC6D01C6E2934463F84154040D,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\KSECDD.SYS FI2=180048,D2E2914311BF4A51F88D2DC2532E6C50893A2A99F474BAB686BC9F5D25774340,E4DE0D3E136C7F2C99DE2BDE3248B70B,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\KSECPKG.SYS FI2=29696,491802A11F9E563369DB69E1D838C6F0F54F69F31BDC14018339CEE1B6C9C3CA,E5304DE29BB9666DF0E57E5BA71C0E10,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\KSTHUNK.SYS FI2=72704,05EC91E194336D1BB1EE323E70FAC54F6DC0CEF53FD4925F394399531A37A0DD,78779BD92081CB27967E77561683AFBE,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\LLTDIO.SYS FI2=108856,36857AFABD064196B7D2A7CFAE3696D96C1FE13431DB49ACE161E706680231DA,89EB90814DA5FB6F5299240AD8B9C7A7,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\LSI_SAS.SYS FI2=124216,7EA218BB57843B80AB5A987BA915829B8262629F72EEC84238634A016D05504E,2FD85E518EA97BB642B018EEB453401A,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\LSI_SAS2I.SYS FI2=135992,2EE68AFEB6D5EC98A996C1722057275C1648411898359248D390B6AA9F697AB5,8B7995D9E487C8F90BEA8F1EF6331C10,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\LSI_SAS3I.SYS FI2=82744,FFDDB7BA54C999D5689152E4EDACC838A769B6C479F0A0FCF294C8632F4E4C1F,ED902EBC8DEEF6E5FC00D0816DDFFB42,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\LSI_SSS.SYS FI2=140800,907EFCD1CEB5ECAFCCF11DCA8489E9C5335E876D0B6F422D9EA1EBE573C8707B,C6B6FB92C850206A5701F353047FD530,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\LUAFV.SYS FI2=537608,DA40E73A7F584D944F58C7F489B701315B8D30A29E5A6C840C9D291302271834,6C965A0AC264AF1A8E0A69882A7EAFDC,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\MAUSBHOST.SYS FI2=64016,AEADB11E2BE2EEB4BB5E4E13ADDA4633475022312AEE777CFE7FEB27C490B54C,6C6C1EFC46A62091224333E1E9304FBC,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\MAUSBIP.SYS FI2=220752,6519A70E8AFFE122E1DB69BA22CF14EC9B88BDA5AA4031FF0EC9834AC18D57BE,E8AAA5EF5EBD3BBFFFA581B14056C1B9,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\MBAMCHAMELEON.SYS FI2=19912,43309A4DBCF15F09AB3066E96C498785C4F41DBCA8467B0385FCA467AE370980,BF46AFE0CC03D9A5883E74438170B841,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\MBAMELAM.SYS FI2=248992,1B62082ACA96EF78A61AFDB33EF77260292C5D08E5E35B56F7F8F0A3A837ED9B,0B17A8F4956ABD5FA1A0851B59FF960E,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\MBAMSWISSARMY.SYS FI2=386048,7579489DB1BDCC4A4BE0CEDBC76ACE58E0CB9185F8D8508DF1B7AB9E2C3E8CC6,78E352A45506B8AA6C1A343F1BCFA13F,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\MBBCX.SYS FI2=59704,9041FDEB932F2CBBCE4A017256C81B3733604403AA343D4532910436E8288CA9,CE4B01081B8FD211A7A34219D5E8154A,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\MEGASAS.SYS FI2=81720,6D67F52F0B63724126DD7B75B3489D14A6CBC3BD1E0D19188026DA21E85A620A,F3C6B901E3FF70F27A17CFDDD7BA85AA,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\MEGASAS2I.SYS FI2=105480,83C982FC61094A9E9F3E3CB5174B7409698C12FE3B6BF9B2F4C9365E56C642B2,EB84966D14F9342C8AD3D78BA9AA8754,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\MEGASAS35I.SYS FI2=575800,8A902DDB6016E4D5C28808FBA5741751D94FFBD4B55724D47BBA0A8C29900E53,A4DC7070D92AD82A7BDF2F69C155AF69,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\MEGASR.SYS FI2=65024,76F71824E80D10EB71BEDE5EE3A64CAD7CAC3DDFBB6670D1537E6B75FF0217E9,B74FFC6301B3312A9F59E04E487BC72A,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\MICROSOFT.BLUETOOTH.AVRCPTRANSPORT.SYS FI2=106496,7B2C116DB586ADF3175AE4DC630C2BB9043CF3EE57A22A8DBFE55127F6065A51,0825C3B0D4A788E95DE80739E52C9174,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\MICROSOFT.BLUETOOTH.LEGACY.LEENUMERATOR.SYS FI2=1131320,2C6B268486AD0F3BFB82DE0F61D076DF7C334C1C94A0316084713EBDB0C9C518,517DC2DF12A391699F8432AF89947F2B,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\MLX4_BUS.SYS FI2=53248,56AC6F16B94E9BF9EB140B21C8397CBBE2DB9D6C6B01D2879C5ABEE060631138,F087703FAC478379323262C54CE85DD4,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\MMCSS.SYS FI2=47104,F1DBC9307B3FCA67CFBF3DE4F1FF62B25B85BC832B2C05B96CA5EC0130B41108,BF7ECB119071501EAB6C01374CBD25A0,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\MODEM.SYS FI2=80896,8EE02548C82E966104DA1BCAA61F5EE7D5D81F794350DD39F01CA232A339F1F6,074D2516B7435B3560BF2A69F10BBF22,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\MONITOR.SYS FI2=67600,DB5D99DBFF8C84A7D87109DFB71396DF8E0F0754FC0D263E45116915A39735CE,4352C109DD892A5A5413897A74103024,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\MOUCLASS.SYS FI2=35328,3A05D657E03B6CD9D62023061F9C652357F16DA2F2337FB6C617AEEFFAD794B4,66E41E31DEBD4E1A2762945B4F15C780,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\MOUHID.SYS FI2=110392,EE3598DECA591E8735DE0F449F292E9DDDBCE28A8A7B814E78DFD90AC867B7F2,180D9E273A958B6D2B55410DB2C431C4,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\MOUNTMGR.SYS FI2=80896,E9AF731D982F2E6D6DEF9239E4912881043804E6C557C6DBA9B16AD6AE0473F7,19623B4213820840730EF00BA52201B6,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\MPSDRV.SYS FI2=20986200,B7149A7C6D0182D9609EFC0E94DE294A7C63FBD8AA3204877037FDE275174923,38DED6894C4D3B8C669587B57D475DE4,1,"Mail.Ru LLC",C:\WINDOWS\SYSTEM32\DRIVERS\MRACDRV1.SYS FI2=157696,CC06B99F3F67A90E0B5FC3B2FD7A0DBB23B0D766DDCC94FF6C72B1C2C6C913DF,186251D6489F7470616862DD15644177,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\MRXDAV.SYS FI2=577848,B61E8C234A4DB1175D17C2150941610998820860756BB5784E2D1394E1C4A697,9D0A38D9C9D55617114FCD2017175811,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\MRXSMB.SYS FI2=307712,186B0F89930A9F2F23A53B87273665CEF7F22C60EE414DE30CDE33518015A69A,7969C9FAC344990A26D20549627A276A,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\MRXSMB10.SYS FI2=264008,40A8A53D3EB2DC7FED565E64731D2A4F03314C382BB8A9C2C0F8FFD9B9602A7B,1ECC779D10D17CCC766E29E354098501,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\MRXSMB20.SYS FI2=183112,1019FF6F1B423CBF1512F15EA72536F93D0380B052D5C679313F5FFF8BB0A4DF,E0C0B02E56EE1E639CA3928F55D59D59,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\MSGPIOCLX.SYS FI2=56120,B45F9D3A71FC8A73AED3C5B8CF6F14A25EBDD3D4D47C9F39FFCD75C7D22F4A9E,6092FD060EC4132A799BDAD61845DDB7,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\MSGPIOWIN32.SYS FI2=8192,C656B13E0329B86663C2382943B1DD6F6E5080FAC71E3FEFA056D261F30E273E,78689B7121F3DA06A879FBBD039B29AA,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\MSHIDKMDF.SYS FI2=12288,1FDB7E28CCAF757603C4B754E1AC9C470E5E60E85DE067375902F108F5E34608,9E90FE6DF363D2427A5C773120E7B27D,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\MSHIDUMDF.SYS FI2=30208,69714A8B74EB02282572B34E156051FFC10693B816905CE18A8C6C8CCB95B846,5DC7DFED5FEDD923B874B51D0C6752BB,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\MSHWNCLX.SYS FI2=20280,83AEF35DC458621A5FD84311EC2FB6A7319EE274ADB0A96521A2F527D44D8262,AA319FAE5B8B9637E9F0D243A92D856B,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\MSISADRV.SYS FI2=292672,B1DEBA209C78BA8BF4201DAEA18BC16DD958D791851095F70D99D99967A637ED,CA8EDB92163744F0510D9106CD33358F,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\MSISCSI.SYS FI2=34816,82C74A2AAACC3CD06187365D40EC1C122A01CDB6915B18FE2DD97E17764DAF21,26854C1F5500455757BC00365CEF9483,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\MSKSSRV.SYS FI2=78848,0EC3E53C5B1B202440DE22A5BF7E1EBE9AF5BBB6BA69DB9D018A6D8EC97B477E,9FB5040C8CEAE4C32B7884ECBBCAFDAF,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\MSLLDP.SYS FI2=11264,6E5DAA5D9826A3165514CE2AC4AEC23033D7BA993F06D2BDFFC68052CA71C4A0,4B5CD00DEAB6BC5FE650D5E90BA5719A,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\MSPCLOCK.SYS FI2=11264,AD55F307A8146BC2ACB1B2437C19B405F7BC3F5E4A81DB685B0C046FEC4C30BC,3FC09B334BB53D2EB289887CFBD79D0B,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\MSPQM.SYS FI2=322376,65739D981DFD66C092F781FE1CB1BF07FCF4CD0DA969103E527D4982CA3A30AB,1B9172B25182BE5F3560F76F4085A5B7,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\MSQUIC.SYS FI2=47928,360A199A6D4690FE248C6EAA4E84673F299FA4CA6C21E940F4DF1B28216BA23C,DB89919F84809686BD4F8C24EB6CB3FA,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\MSSMBIOS.SYS FI2=12288,808FF81F0030CC7390B4790F91CE1763EAC02CCECA6014A2D9D990A40DBD0580,244C73253E165582DDC43AF4467D23DF,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\MSTEE.SYS FI2=17920,E37965B9EFD9ADA6A81585DD792A20CD03BFC28512E92FC63CD2CBAE9A41AD1A,8EE2EEE12398FEA5BC8E37AAAFE59852,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\MTCONFIG.SYS FI2=132920,757E91D214B38D75819B8FE0E0D9D10E648660244CBEA79C588C9E62CB71AC74,6AD1255EDF789EDB771EB04B062BF007,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\MUP.SYS FI2=63800,69FBB0692C37DA498014CC6CDC609E612A3207A17B280EDE5C02248571F91F11,82B656712713424A707F1E127C68E02F,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\MVUMIS.SYS FI2=146232,E3708D62DEA31BA03D7CE7EEF6A270DA2B3556559140B556F5AB4EA289F921E2,D62777BD13AC73F8FB20039B701D5292,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\NDFLTR.SYS FI2=1475912,E7FDB82678CF9FB694290040498F316D2B067738A8DA03E7363D30880E6CBD99,DB7ACE82570BF951A8FC9A1A88E2DA1C,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\NDIS.SYS FI2=54272,5F6395268CBD26A4B90960479040C114B2C8A3F24C188C2D5F62D6AB43A637D1,6BEC0929C7A7BF2A7C44F585ECC7DAEB,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\NDISCAP.SYS FI2=135168,A8C470C3429D693678F16CE47BD104B8F1E8870600C54F81058951D4A0C8A125,FF4D48CB9B1FA642E9DE8C4EAF05C980,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\NDISIMPLATFORM.SYS FI2=28672,58FDA9DC5748D4F102F6B9BC6EEED687244ED74B32D584119750BF964ECD807E,8F6BC1F9E7331F564367456649CD3C84,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\NDISTAPI.SYS FI2=70656,3D7685D3960382FB102E225634D54A2370DA53DEB89CAE4765AD00C9AFE030B7,09BD40437780ED584D06519373ACEDC7,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\NDISUIO.SYS FI2=23040,2960AF22637EDA95DF6ED154278B23AC157AF2DE6F342DA7D8083E4F7F70730F,31AE9050FF9D6CBE1BC2A7EA5F98D6A3,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\NDISVIRTUALBUS.SYS FI2=206848,2666A2E880BCD839D9F0D51F21CFA12FDB13FE75061D47DE1974F0A67B6BF611,E48770FA7691847311752AE892FCC6B4,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\NDISWAN.SYS FI2=72720,DAAEACDB4506D2BDDED61957D92FB4983E11D9CE6E7B25119B4CBFB431C945F4,33CDAEDC7CBE8339A8324CEC2461BFB4,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\NDKPING.SYS FI2=93696,502AE6F59243354366ABE8DDB1F26BA79C5A08E56F9369525678CC072CF65486,EBB9D06E3C9F01FE299E9508D5B19BEB,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\NDPROXY.SYS FI2=131584,8228B7D1237A0FFABCCC150B299EA494C8F0CB4CCB51AB0DBFF08CBAA9EFC4BB,77621E74FD79B267071A0D12C643A48A,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\NDU.SYS FI2=207360,A7FEA3ADDF86904F83602638B05562197BCB7094AE289C4C5E4802020BBA1576,EA21A1CC5482642E9A8850E88DB24039,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\NETADAPTERCX.SYS FI2=64312,E7F7F30D9513FDD2236FCFD5549DCD93101562BA1117213EA4DF32B70BB48A73,4687FAC962855BDB1896C02334E95D54,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\NETBIOS.SYS FI2=341504,679A89E9078D5865C52FCAE3A86D5AD252BF22B819901303F186D55EC976E1CD,49F7DE6F689C47B64A2C2D46CD98E327,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\NETBT.SYS FI2=250192,F0F911B8C8EB24F2A8FF68D9092A37076E840504EB594E01D5BD7C5457494BE5,759A278622CC8EA153A4CDD11F1406F2,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\NETVSC.SYS FI2=27648,CA3657D9365D34FFECF6B5DE8E5905A2491756B1CC227D9AB8762B09111E9860,B2B57F620C085F2EA764BDF79AF7BE30,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\NPSVCTRIG.SYS FI2=48640,4E6E391847B90C796BC7B208614F66F48BD0A6CE253295DC24DFA47E9D214151,099D027B23831D009DEB40031795A915,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\NSIPROXY.SYS FI2=168464,C0515F0F429A3B60AEC5F9F2AEDCF387CF941D306A21C9BCB56571C83560C6C1,BEB8637D4B098B286B8B4F46E88A57AD,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\NVDIMM.SYS FI2=136472,7CAA7FCCC5AF518007A6CCA8D14BFDA2B197F5A54786A476C81F176CAB558396,2FFC074B408FAF8F35813EA54D175011,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\NVHDA64V.SYS FI2=43416,BFAD15740F78A8F6AF744FAFD470C56A10B4FEDF611B455EFC123A2D19486CCD,2218A7DE62CB9BE281A28A84DDBCA3D5,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\NVMODULETRACKER.SYS FI2=150328,628927EB91C6A323CA67B97EF743775B68D30599A0F0593BC3B5C0BA6C5AB82C,5281A4F23E594AE6EDE1E38B1F8518E0,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\NVRAID.SYS FI2=166200,F07CD88B7939C53DF83E93D40FB5AB115946393AFBE8DBA75FEE7247BF3063A9,A11D15751217EEB734033BB5A929B1CD,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\NVSTOR.SYS FI2=69840,A9F15A301414205060CFECD4984632F4993C9548D42405C55573305D9413C96F,AD226D9879217AFE36EBBE9FA36F6048,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\NVVAD64V.SYS FI2=67456,69BF7571E15DF3785F421B4FAA25C10FA3278FD983F3EB76A9A294F1A3E3FDA5,8DA6939DF7D55222FC7B97C89487D15E,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\NVVHCI.SYS FI2=741376,33A3A1D9AB0DC7D4177E43E3A56DA6F304E2FA74433AA2D9E792102CCCAC37E1,D4CE423B81A8BED4C36D26D641DE2E62,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\NWIFI.SYS FI2=32856,9AD25311A37D179B02917065648BFB9F2DEE4DB3E00FD5A8A55672B6609B755B,4DF2CC9DA1B978CF6BB67AC82E09ECD5,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\OCULUS_VIGEMBUS.SYS FI2=75280,DB74C6C5C190FFB06A003CD22D4243CCAD824FB33302E43F23A202C61C960819,261F6F8964C2A2BAFE934777529C7DAF,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\OCULUSVAD.SYS FI2=161608,7906E70262F7D47A22CC18361749106E5B377660EF17A0F2AEB44B019F825A95,4E750557E2310F3875CC8CEAB4CCA2CB,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\PACER.SYS FI2=109056,1E59DE429B54E910688BF917F2AD97E66241EE3FB924C24E3627E9603E8A9C5D,138FDB1EBCB61287A645BD3B06DBED5E,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\PARPORT.SYS FI2=182592,EDF6F50C7B558BFC0B15B7BDFF625C6A7FBE7BE670E142B2B5C18410C1E70A1B,F08C0D5949AEBE93D5915A029F236D59,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\PARTMGR.SYS FI2=469304,24A44B37F46DC55B6B6E81B40DD6C844BA90C565716BFB2E22B1B20ACBC9E09B,CDD225BEAF56BC5E22470CD0E49D7B00,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\PCI.SYS FI2=16712,29DC84F04B90635825E621C7D249824C9C6F46112AFEF59E24B489C18C66507D,BAD670FD9848C0CF6DE1F5186581AF7E,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\PCIIDE.SYS FI2=127800,CD84890DEB63C782A51A7F4D962B88CAC9AA226C3C7DDC2D2B0A56E81B00B07C,0543F01C97CE2D3ABB4F8CEA56B99721,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\PCMCIA.SYS FI2=57656,94CF7ECBE1F62A1952FF8E3FF8799ADCAA1AA3211B18395875A75EFCEA786DBC,FE3E9C016B908745987C45D40A31F4ED,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\PCW.SYS FI2=159056,D9D4EC0EC8E7419263DC95F5CEBC24FD5F19E9FE902E902D45FAC46F4FA8E5E3,7C5587B5911A96C10E670DFA54C9BB91,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\PDC.SYS FI2=823296,4E0FA5A2069C03E9872130F0BFE0C1EA80D61BB97F9EEFF3AF68891100AE887B,F4693413E31B2744BEB5AAB5632AFBB3,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\PEAUTH.SYS FI2=58680,D6B8116E5C920032A5926D5D047BFD72B05ACBB08E26F177A0B0E6B4EC735FA1,2E2E8BA514A93C297F124BAB53F4E921,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\PERCSAS2I.SYS FI2=68408,92017ECB36EAA35AC454E890734915A658EB898C95970531D43C19461BE6562B,1C6720616FF300235509D5EFBB2CAE20,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\PERCSAS3I.SYS FI2=129872,E34AB76E01B834314C0B09A0F92F8D9AE066B326BFD8B28F6778BCC13E2AB197,E70542D4BBD65D4F117A2C1C4BFF13AB,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\PKTMON.SYS FI2=138040,0C0C05CD071BADD691C99CB08EF6CEEB1DF9B0F011F4499C22BBE4636E7521A3,8D8575D069381877BAED88D2FC98EC11,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\PMEM.SYS FI2=17408,B8345C32585C45E6248D7194B1071F2B8617718E7C9B270AAF44C132D029DB4C,2769F200292C0F941A10BD60C33EA4A6,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\PNPMEM.SYS FI2=27136,65C33D25E0C00731D7DEF3F127523AA5178133481915287F3267A52C74577572,562B9409AA8777204E78C629647344EC,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\PORTCFG.SYS FI2=216376,CCA7B29F8C552E48FD6B4D45DDDB2A8428E82747FB2ED847F3A54F87B4325DC8,60D37A270C6787EE0A1B6C88DD221A55,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\PROCESSR.SYS FI2=53248,706D683CAF92C259C121222446D34ED43F6E8872407C3615E2ED118ACD24D21D,CE51A9A997D2830C6C64A36D7F8D8879,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\QWAVEDRV.SYS FI2=42296,D461798C6348C5D96EA002E4A1AC588B87A1A9B01AD84AB1FA6D9C6393616892,9D377A5872A0A7A33E258FFCBDB3F25F,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\RAMDISK.SYS FI2=20480,3A79A1C48768C72B49913647336BF75CAFC10DCB8C6C54E4D05FBDC88FDADBCA,9500BA0F8F8E48449810BA0E802DF2CA,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\RASACD.SYS FI2=110080,69F7181CB25E6E32E7B9C68BC76F21A5C7311ADAF6CD35B0B54EC4B7095B46CC,40CBDB4B80284451536C8CA49561E5CD,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\RASL2TP.SYS FI2=87552,83B6ABFC0C5700089EA967939564EF5FA2F5C40D2CA378D427CE59FFACD99D71,E250ADBB0C3E564BAF7CBBA4BAFE0A60,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\RASPPPOE.SYS FI2=101888,9124AF703B5032254AAA9F42A2CC9FE5B26C0048B4C21FF14382935797F4D245,CC6EDCFAF5A19B948C46F92791AC452F,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\RASPPTP.SYS FI2=86016,6EC56F7E87D4D6241DD0E94148E388816EF9613B482DBD1891E698B2E7F0F585,FCF941424AB1AB3EF57B0ABE6DBCDF77,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\RASSSTP.SYS FI2=455480,C8960C4CA0153815621894C01D0BC3ABE855666D4EE76CB375C5E4CAFCF5E54F,C82AD8E0F9B74C20F8097CA5797691E2,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\RDBSS.SYS FI2=28672,056495FB4A54984CE9D28D7B45550990D4A4B0736669F0F69138BEF51A695EFA,B7BAD23CA994EFF8EA11261626326004,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\RDPBUS.SYS FI2=169984,9580C67C2891C34A23970B705BC64AC19CCA16AE5A6F141F59FA6AFD89F7EC44,64991B36F0BD38026F7589572C98E3D6,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\RDPDR.SYS FI2=31544,E4675C277BE4C32E01BCDD7ABD7EA182C587F3CB15453D2362A55BC2755BCA47,C18A026DDE98695368EA87C85CC77EA1,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\RDPVIDEOMINIPORT.SYS FI2=297784,F906865E349390D24A3DCBC563154BBB9F307B97361832BE93BC9D44A9F3B486,B4A6F3BFB5A07DAF4E18C14A6337A226,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\RDYBOOST.SYS FI2=213504,825C918D22FC8DBF3EE9BDB41D121A0AC3CCBFFBA147E2B26F0197552E0675DE,D2EE9CCE0187C616E50D61EB30ECA262,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\RFCOMM.SYS FI2=115712,DF04978AF6CD34C8251B3DDE381CD77518684DCB1D2B16BD2DAFEE63AC9D5858,4DD0EFE49F0C020DAFEAE6F5F231362C,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\RHPROXY.SYS FI2=89088,9067160F566220A2B21FEEE181729A796A3F3EECF75FFB75815BE5CCC7BBA64F,EABD30C39742A79913B595A5B6F809D4,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\RSPNDR.SYS FI2=116536,7F56A791B05B2AA96D85473BA5491568C67E7E54FE41166B4A2D86A8C9E03340,BAC407B1CC364A3B471AFA06A6029E23,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\SBP2PORT.SYS FI2=44032,B4A2BFADDA5925DD02FBDBE9CD3F508840F8F241EA4C2E11FC35CDBC4C576F1A,EC9BDBAF319AB30D1BB25A478E169CEF,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\SCFILTER.SYS FI2=158736,A321C20A1221AC1F6D7BDEF9FAF0C6AE138353EF5F859EBF1ECF55A97414FBA3,14DD371343EFEC95013A273DEBCFE96F,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\SCMBUS.SYS FI2=305472,65D81CB144754C3A5B472E7869C5C9504A560C0014527B007B51D77995AF359D,A97C8FF1615960B453EF511BED5735ED,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\SDBUS.SYS FI2=35128,5E940CA63AD21CEA08C334AC61D985BAFDBA7DCB2D388F355B5C72EFA3E23E0A,3200667DB433F0A2032FAF4DC02E2089,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\SDFRD.SYS FI2=103760,943BF79279719A7E7E2FAF4E5B72F1F6E0D995A2D95896126EAA61D11F267EB0,3CB8A2CD2B5634CD0B97D85C47FE3427,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\SDSTOR.SYS FI2=86328,45F87C7D04B8F20290BBA8517BACE138D1E2112A268CCFFC2DFC407A81C0A197,22068CA363EAF69A8EF6EBBBD580A8E8,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\SERCX.SYS FI2=173072,8F1BCEDC5FEA5AF0260B573EE171E1D895EBAB5A51BEA1F84D3043F6612050A9,A5E6D99D319610030C3CA982DCAA3624,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\SERCX2.SYS FI2=27648,9A4EC5EAF65ECB6518C462E837EB76286F1BA7A8C9E26DC46586DC4F189BD1B7,7A289A4FFAA43D81F091A302512059A6,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\SERENUM.SYS FI2=90624,024C1F9FBEFDCBC174733A5C97B121A6D7AD30E836C1820054BCB45F99FB4373,DCE5D050F3B06D30985EE126257DEEB6,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\SERIAL.SYS FI2=29184,C812F61726BDFEFFE468DFA3491E5F465D22835C54E3559E04B452940C0EEEEE,B13F5A8574F0B71B2E4C84B171C28724,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\SERMOUSE.SYS FI2=19456,63881202D6D900656F50A0E40CB743D0769C2AD9810FE96387E9DAF2BC89E4C5,AD1B790A42984A825068B849A88AD322,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\SFLOPPY.SYS FI2=88080,C65D8FEDDCD9A52B04F42C64DAD2A499BF51246D36042E8DC09DD04C4C0B7BEE,C05648C2BE6176BE557D9C7F02916388,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\SGRMAGENT.SYS FI2=44856,567710C90BD71600A31A3408DB065B43C844DCFD12045FDE04CD59D932DC8353,9AB1BADC5A324DA39186B81BC6CE6E2E,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\SISRAID2.SYS FI2=81720,718C833E5EDFE642F3B254515E29641BF2D8E56E22F6B795024BF64721AB874E,60213AF297023C005453E1CBF7CB6FE7,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\SISRAID4.SYS FI2=209720,4EF7BE37F92557C8B0D30999541F284CC4A3E8FD98E0D78146F9F00D54E11BB9,196A46BA842A219EC6DE7B7B7D9AAB7E,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\SMARTSAMD.SYS FI2=26624,879AFDC8C50487ED0D3CB58C70A206E185F94BE75C25C31C387F3F08740771F9,27B7D9E872939EBB34C30343F991893D,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\SPACEPARSER.SYS FI2=677712,56E61EEF45C7534A5168BE0745B1BD30488C727AF4AEBACFCBB912314D7EFF74,2C7EA4A2A4EA5E0DA7E319B67216916E,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\SPACEPORT.SYS FI2=90936,D2EA0C5FC534C89310207AA26A8816B30FEEF3F2708A067D8BB93D3CFF9C3936,AB3BDEC793187CEDF1229AC98BB7DEDF,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\SPATIALGRAPHFILTER.SYS FI2=87352,E8A7BB7D299B457EF9E3E32893E5DCF3DEE1704B9E02A0583439941CA6E1C9AD,B6029A86D8DE5AE85E01506E0222A491,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\SPBCX.SYS FI2=787968,EC1137DE2D89BD9C9B2481A390FC89301A4A7E7C963B888A241148C098E7DD32,F27E32CF8419B68A21F4A786AFB01BA2,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\SRV2.SYS FI2=315392,4141ED779A2B6576DCB2ABF11912D3635E15EDE66B532C6009E9A42FAF9B81F2,C563F1743D05977EE8F295165ED5CBE1,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\SRVNET.SYS FI2=48848,49E69A7F24C38810CE375D83A0589F0F3BDCF6D97324F525C46DA7DA5D787BEC,1C9B3C9A177A1F5016DEBFF68D06E2DC,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\SSDEVFACTORY.SYS FI2=31032,766FD1E1D2F73DE202FB337F6A6A5BA0317772AAAA644E9103BB5DF438162F51,09DC471B4573F3D01D7E448B526AE70A,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\STEXSTOR.SYS FI2=186168,D66DBF1DB502F92AD657A31F4553C01263803DA3362180B483C8D099F723F3E5,3BF9A305AE7104D0B6AEAAFF408F99D4,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\STORAHCI.SYS FI2=155960,895E525F3D40604EF16274475857512517DEC93BDBA41A91F1D18191ECE849EE,1DEF1E3DC73EDD14F3AA039FB88CE97B,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\STORNVME.SYS FI2=92984,E86386156F982B59C00991D40A6E1862CA322F151BF965B14572D13AA207D614,995F082126674C6D1423E29FBCEA9F39,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\STORQOSFLT.SYS FI2=60728,943B543F1B67ADFF29186BFBAEC98420EE4119786926F9DDCCB8AEFE6BE628CC,D606EB769D858B548FF05EDABB485A0C,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\STORUFS.SYS FI2=44048,B44327F3134FA0166ED9E31BC724120B642AE5E96CEFF599867F03463ABB1406,0A13C67C267BFA1A0D1FE72A9D65BD5F,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\STORVSC.SYS FI2=6656,52A4DBA20C16B2E34FBDDDE966700A3E8E183011A44ABECADCD4D3F93D29637B,B39DC667DF14C7F1B9A58DE17BD45BE3,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\SYNTH3DVSC.SYS FI2=27136,89C5CA1440DF186497CE158EB71C0C6BF570A75B6BC1880EAC7C87A0250201C0,D765F43CBEA72D14C04AF3D2B9C8E54B,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\TAP0901.SYS FI2=2991928,03BE519763E63D33E2572EFC666F7C274389AC4EC5AD3BB9E774F2FC437AF65C,A6DEAF3FABF725B370DCB3C2AB69A14F,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\TCPIP.SYS FI2=54784,EDD4C58EDAB985C87D6101D9CA5620146EE2BB8A1B899C635DD4CD36541DD46E,57BE670CF1D93717B628271B404D658A,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\TCPIPREG.SYS FI2=117560,6516ED3DF480BA6071C8D97EFC0A7E2C78182BC7546B7DBEFCD010E9F3CC9500,9C4C6E0C590F789CECB7A6D437E5A284,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\TDX.SYS FI2=206496,ECC894FCF4C3F2364883BA55242C432E9E416D93E71B67985DF24ECB39F9BAC4,F1E754DEEB3369BCCE2228D5C10DE101,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\TEEDRIVERW8X64.SYS FI2=41272,6F88375DD12A648B77BB6EB4BE527FF6678EE76A2059DB5B4CC971CDB31D0DB8,C225B94F2B27AC97C3E66C0550AEA249,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\TERMINPT.SYS FI2=255288,62ECE387CEAAD6296A35632AFC96E8A4E7018BD0A1037CD4AF8951F833AC38DA,8D0C4B0F6D48CF4750403971D7BF494D,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\TPM.SYS FI2=66560,AD6DE675AC033BE6BF75FF6303EAED4B5C672689D3AEC6DB94816D60E19B7030,F613A8618CC19DD96D1E0C81C5DCB7D1,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\TSUSBFLT.SYS FI2=37888,EA6AE80568B8FEB5EAE213EC8222AD72FFD99D80321D7F2A52C1B42A88F583AD,BF1D6924E7949102DA6F14F7EFE8D2D5,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\TSUSBGD.SYS FI2=129024,C32908B3C5800CD52EF9BDD26C77B8162831CFD19DBF1D399941B17FB909AD94,6244FD1056BF170E38245B4B9042BFDF,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\TUNNEL.SYS FI2=79160,63A6158F57D05DB58C45C6D14232B7BC810A9FA534807FE21E50B1A6DE653AA8,EB7C07C41F8B2907F40540FA0BF98071,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\UASPSTOR.SYS FI2=166400,C516019E7B9FE09B4307269DD8F266B5600D735C229FFD8317FB4CD63CEEC741,BF087CF6398F25E940882E094EB71ADB,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\UCMCX.SYS FI2=188416,E70A2D9EEEF0C6894A0DB7990CFF6ECE3B8F389FD30B7B1949FCBDD3300B6148,229B33B8499F4F2AAB1F3B590423611F,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\UCMTCPCICX.SYS FI2=36864,3626760AEE42EE36E047DA6899A81E0646DFBA344A234270EAE5D635F049BE37,7FDC3A6FD8547468CE554C8821640103,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\UCMUCSIACPICLIENT.SYS FI2=113152,3E5CDCC098149853A7EFA05EA1B714182C82E4153F2DA3C50BA30DF2B3E05EB6,1ADE4D1F65B4A1E52F701C69FB455769,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\UCMUCSICX.SYS FI2=259896,2F5A5BA7AEC40C1A440C8DFF81DCE5AB0BDF9CC70ADDE48F8B652665B61F9915,D6BEDCCB2E48589944EDC675D335677E,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\UCX01000.SYS FI2=52736,4F8193C0A3525B78CA3CAF4731AE997A214F3DF180F0A3ADCEB2D31D3217850C,6861422B7FFADDEAAA64A0539C910178,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\UDECX.SYS FI2=344064,AB809F7EDC5C8A6EEE9610477A79131EA6C3D1BDD3D837B56B6AFF3572923DB7,26D2727935221EFB0063B43A74B375BE,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\UDFS.SYS FI2=321856,96FEB3DF819AAD727A91F0359ECCCCFAD455BC900FA302F004EEFA22974748C8,FE96D3238836601C5D03623BD440F2C3,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\UFX01000.SYS FI2=168264,51F112449305C5F03FEA6F046CA007A8056A65EF84986393A1B4203F53A08833,E884B3B8DDA9442F58E41C2ADE3C4234,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\UFXSYNOPSYS.SYS FI2=15360,3062B25A7747BC417E1D498DB1B11C9631D80F57E4A048101EF5AA26206AE838,493AF687E60E144F59E3F5B7E27AA39B,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\UMPASS.SYS FI2=76304,BC0982BEFE4CABEA1E260C8A3266EA18A4CA158A07D1C5176890A04CC3B6A84A,ADFAB87405AE22290E24D0E8E6141AF1,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\URSCX01000.SYS FI2=210432,D44D2859DFC64016959F9180CC21CF33C69AC4148A2BCAF784F9A2F7EA977CF8,A0AEFF16C4C55CBC3E89EF8D24CF64BA,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\USBAUDIO.SYS FI2=260608,7D38FA294DA179E5535E3E481746F07E2AE47CE57192C2D1C5B780B583FD9C6D,FB9F25ACEBCBAEABFE30CACCB17D4EE6,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\USBAUDIO2.SYS FI2=185664,D49772661BABE6FF688F6C1D21BA04BC0E0492432664C413F851264695A3D3A2,C6D1E24E96FCE7662F7C09394241CC8F,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\USBCCGP.SYS FI2=107520,2AD595BF4ABC146D8F533981848FF8271E983038566937BEB48A6A8F09BC60FB,11561FC5BAA2DEB5AC8B179B591A882E,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\USBCIR.SYS FI2=86544,3AE5ED5EAFBC52028D082D3EC04B526EF60F5D74BBC79DD210A22D9238C61262,D1E576C8A94A27D896B56F923ED4E4D6,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\USBEHCI.SYS FI2=528184,42404EC0F658121F6553B7DAA3511ED512B7F4B336C2032BA85CD91E8879EEAE,804C51B11057869624D9292040B45E56,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\USBHUB.SYS FI2=653136,9D22DB8178B983F39DCC9DFC1FB616D07CCD5DD4F928675D47AF036CC630FF51,3942EC2884CE00104F7B63992BD9B449,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\USBHUB3.SYS FI2=30208,8E2B1A8E3F8E1F88E73AE2A34B1726B5C5F6753BAE3FAB1E7CC82C53FF7EE891,4E8C3BD185042836203F3AA26B1DE6BC,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\USBOHCI.SYS FI2=35328,7AC5FAC0D8E0A86CBD67407EA9EF95C6A2CBAA397EB959E074B6D87E85CEBD0A,E7D67614480D6365CA96FA6919F6CFF0,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\USBPRINT.SYS FI2=88064,84D1B97E92854EE23F08055B7C932D02A1EB6B8AD70F99C397B663EE3E6F35F7,AF024852586879C6D643B85DDAD94C09,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\USBSER.SYS FI2=135480,9DF8CAE1B763B19B900DA8FA7C54056980E38019C4DB0CBCFD140964B21BA623,FAB5619DEFA6BFF8D5D4586D4C554247,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\USBSTOR.SYS FI2=39424,3D602EA3F0A83F8FA7B9FED579B21881BB92272307634B24E0423A9A482D2CD6,3D45E616CC66D475E7261875344622F1,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\USBUHCI.SYS FI2=329040,35F0F8F089353524DE2AB308D5CDA641F1EC7B6A0D8F37C4124494B20B2031D7,38A6980D2DAA486177E86DE24E15BE88,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\USBVIDEO.SYS FI2=602440,2D9590A58AF7A139C3080154E07532B7429B6B4E11772C3807F06B4DB6DD94E9,290C7E9C815B2AF0865D0B019124F695,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\USBXHCI.SYS FI2=67384,2BE132106C26A9073B6E9CB646E6A2C003558B8924ED0BDC3A0533FC98E03BF4,661233B58190B487682839F1559A7962,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\VDRVROOT.SYS FI2=41072,9FEB19044F8E77DF66D2EC3CC1BEECEE4BE5105AB2F0BB241A0169A8AF21DC2B,2BA129C22CFDDFC50E45428AFB692A46,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\VDVAD.SYS FI2=77864,3A6DB61A8412E2486603DF69E4117BC086E777CAE24CD77A72F2340AF8F0B610,E69F994761A4BBE70CBDC7CAC61C7385,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\VDVGE.SYS FI2=347448,A25DFDA0572EF014905619DF21427518EA5C01CFB13B9927ADA305B29DBBFEFE,46684A95E908F0A6A2355AA46A3B2A77,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\VERIFIEREXT.SYS FI2=820560,A47000322938CEDE3A661E91CA7C0D616EE3F5A4DA1C677671C218417A5A8F8E,9BF651CB9913A9F68A444454F0D181E0,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\VHDMP.SYS FI2=47616,98188182D328414832D06E957601A997AD2B2B0F088B089181EDE8FAB0AF733C,7F2F04A354582D3D34F5B2B4EFF07189,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\VHF.SYS FI2=644424,56CD63B2CF22FA888B56E30AD2C54D2FEC4F6E34B50EBA2D8EC84F1224CB8E61,77752F7B4BA26DF40EC86AA1D59D8A74,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\VID.SYS FI2=160072,E7C944B8B7AC6AB4DAA817E548BA35B2484611D8E2F77602E47DC981AB0DDD99,8400F5228F706F501CF87E0402FEC491,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\VMBUS.SYS FI2=36664,43DF7A6DD305D1696D28A54E12B75AE041B075E789DB5D0C8DDF250E75585AA1,C29F63BB3B99B3F2030113160A741684,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\VMBUSHID.SYS FI2=23864,DA46502C009FD4C847A547610DEE2684A5A583467BF76009BD46104AAE2F6B1B,A1E06E4E8CB863C74DE428D4D6681185,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\VMGENCOUNTER.SYS FI2=19768,E13E8F9523F51F976084561C9D0A843CAF550FA233521FF13FFE1C5634CA6472,E5BB075B6B5A1DA3C3F48CA5DFF54E77,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\VMGID.SYS FI2=18960,54BB8636F27282B396D487B3FEA8BD73F2F6FE6DA4DE8D718EE498F75A6A5DCE,5914CC0C1E99A3C1711BDB1E224526D1,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\VMS3CAP.SYS FI2=54080,EEF4D748F421A65B0CEECC3F499574FD1B4B2E654428C0693D76074A2BC257B7,5A129E186A7A4E3CCBF090682D48F8EB,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\VMSTORFL.SYS FI2=90960,A03B110C6711EFBD8BCF4391941A2E77AEDAC5462C10479050F9318E94C62CED,0733F8C791B54D422EA7D44CDF009EC3,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\VOLMGR.SYS FI2=389432,71CE8D930AE82C2B2628CBF3BB3AE1A8CF039BD702BDE912D499FCF45332F5A6,796F1C83861C02A97571D0EDAB490B70,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\VOLMGRX.SYS FI2=429880,CFEE4616C10EB0CDA65D4FCC2488B879D577E0F95B5E9AB9B61258F249ED6AC6,988A7A685BB51BAC62F4E176BE5432AC,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\VOLSNAP.SYS FI2=16696,C03E3367B92307993BC169583CB298265FC1C35CF5973EC352C1E08FFCFD1928,770E710BEA3CCC595EE3703297B40D76,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\VOLUME.SYS FI2=89400,9E99D9D27BA3DFA6F89C77B9AD91BE495F15E4F612BB63B209157DFA13BCD7E0,A37A7788DABE4FF6E33FE50D7A33D8E8,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\VPCI.SYS FI2=166712,E70778AF6B0C9709CB8CEF655C6DD8B5A61CC70BFD35A43304C1308EA478C550,1A4D9FAED669BC42E5A1CD8442729AB2,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\VSMRAID.SYS FI2=305464,33DAF53C81D5BAF9337192A84DF50C108BAE9B8A858081E2208939CCFF2622F8,6E0092973E35BE6A1F5ED5CBDD202036,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\VSTXRAID.SYS FI2=29184,373C85F659F07366649697823B4A8B14313F0042A7A04E932429D049D18C7646,7BC30ADCCC9BCF2B0A29A320A395EC3B,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\VWIFIBUS.SYS FI2=77824,2ABE2311C9C429308BA0D6BC490AC1C9570ECBC83D9BEDC561E438B7BB4436B2,E52E3DD859D4095E314E3EC78F9AD4E4,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\VWIFIFLT.SYS FI2=50688,8E62D4CE0EE294B403AC2FC334C44D4AFFA3ACF07DF5E54645C271FFB0F27E40,39E78C9E9463C8D096021EA08682B5C3,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\VWIFIMP.SYS FI2=31232,E4F672C7E58490F82F859CAEEDD57D8ABCC31DE62A42A956BEE47113D365BE35,1F16C8283230EF1F1C4E135D1C2C859B,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\WACOMPEN.SYS FI2=93184,161F9F1F666717D95AF7EC984DDDC4D7E13844617108346FFC49A4EE99AE812F,438B3E55D9D700C1C0424642872C2E28,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\WANARP.SYS FI2=202544,E159FCE548156118ED6F2901314FB6C9A944623D1B267B5B00F1FB9B1B5C8D44,D853E4A4415D945A2E8622863D4A3EF4,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\WCIFS.SYS FI2=93184,ACC9B126A8A5D58AF76F0A492C0EBC75925C3B59EAE89062AEF0FFADF60E3A2B,2F814379FE1FF9DC891953674406BCA1,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\WCNFS.SYS FI2=49568,BC41BC9DDA02D76A55064BE5D51BEEAF6DA6966F433AA16EB95CE3582D801E59,5635B4F1EBB0D8663B3323A51C22D9B7,1,"Microsoft Windows Early Launch Anti-malware Publisher",C:\WINDOWS\SYSTEM32\DRIVERS\WD\WDBOOT.SYS FI2=425184,5CD8D86C0DAD560315EA81F398EFE050F46452F5FB0BBC4F633C24FB80D09A6A,2366497DA35AF5B9A3FDAB2C86ECB14B,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\WD\WDFILTER.SYS FI2=76000,CE364B3B1BE7745025BC24D2F3AD5C4FCA43EDA2412C3FEB9182C10F03424935,F154F0340C2A9B16A406321B289DB1E6,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\WD\WDNISDRV.SYS FI2=832832,7213AC38D3C971E1C774B813FD5125524E630C7C520E9476280FEA18776EA6CA,3BC34854E67B86952D8D0455E8C67D61,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\WDF01000.SYS FI2=958976,60C1C978DC3864C86B48D880D5C8DB9FC682ACE28AC4DA7731A35E84B4D6DDCC,4BF306F088218690D20A13F7AE050E27,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\WDIWIFI.SYS FI2=23560,85C54A99DD43DC1FAC7FD2A31288CEC7501F795DE8FA86857790F4CCD5AF7C18,A6C92A5F2982EBB8788E0690C19048C4,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\WDMCOMPANIONFILTER.SYS FI2=180024,5577559B942D8BB70B8FB65F3C12423FABEF4F922F336ACB658C0AD00823D662,AEB8C2228CA9B0C0588C41E4B3758102,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\WFPLWFS.SYS FI2=39736,E47BDCF775229A739C81A6EE243CBB2919A9364554991AA22DDDB4FEA1F5DC77,5C0439FA47EB0BEF013D59CC7BD7E6F9,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\WIMMOUNT.SYS FI2=76984,64EEB8093BA2590E83D83C5AF7C2A025B88AF5681143BCA83671104266FEEA99,B434A84F46C70F4E67B70ED70F024B7F,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\WINDOWSTRUSTEDRT.SYS FI2=18920,090C4CE6B76B3904B5AE73E4F1EEBCE619194C358874D7584537012F954C54BE,982774B74EE1419D641CEB66E394A4BA,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\WINDOWSTRUSTEDRTPROXY.SYS FI2=36152,F6A9E7026AA60A6627680F232AE785EA9CF55FE970708E6E49151F601CC42FEE,0816C30E3395E667EFFFB92B4EA66A05,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\WINMAD.SYS FI2=259584,8C7345B9A8A96AABC29342E214EE7FD7BADC38DD5915840B15FDF065FB4E535A,EE9539E7C30E2046E7A906681DE9464C,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\WINNAT.SYS FI2=107008,6F8F89B350FC6BC0D23A50C593F02514854AB7D6CD234D8C8AD4B5DDDD586BA0,91D3DC62C6EDDB6554CE14C0E0B4290F,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\WINUSB.SYS FI2=73016,D2A5ED039ED83010E0BB4BB1A69F9D142D42BE2C75E56CFCF3F157A735CB688E,F4C4FD42F8DD657157823DB617CC3A3D,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\WINVERBS.SYS FI2=19456,98455DD24AE076A2413EA599F83E0894F608C335F3FF2F3624A17E8EAF3B3C42,E4F25E6E790747073A09F9F8C997889C,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\WMIACPI.SYS FI2=32568,F4D464BC02C7B96EF72AA9229A99A1AD32F56390F97972C33525EF0D85304261,024924C9E79F51560B9133EEAB866BBF,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\WPDUPFLTR.SYS FI2=25088,DAFF7CE8868299AF5EFA844C2E1F84B7EE7E498B1AFF16965CE41C2E75B2F4E4,2B98DFC181823C8D8AA39C4CC577DE3E,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\WS2IFSL.SYS FI2=23552,96A41C32F8724EAB8B2E88D1A21AB5B725616759E1FB731DEC0562F871ED7AB3,3B974B8EAED22593AC3B946C694E08D9,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\WSDPRINT.SYS FI2=26112,14D496507FC7C5A99B3EB193D7903F0079C8CEDF9DA1B3E114D28303536824E9,35CA90061A756AF955978F0E3E88FD82,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\WSDSCAN.SYS FI2=136192,15444A3E540EAD214A674FF0EB99CD42899D6A1139E59D69DE1C2B6BA364A9E0,7FC0072ECE3F5F860990EF4E10D3F8F4,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\WUDFPF.SYS FI2=315392,64BEEA0C054C91AD2CEB9F6B9238A8ED3696FC20B8CC4753D88B8BC482D766C0,24B093F34B25076A2A6605DDAC8A629B,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\WUDFRD.SYS FI2=329216,CAD30647531CEB44039968BB6B588F4FF976B89C0D15918BF4ECF3B46CEF1ECC,27FD0CDC191131BB09069FCAAFAA2315,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\XBOXGIP.SYS FI2=51712,EC775B54DB846271789D90AE3CC445FFF0EB3DE3154453F341BA9B86218880D2,563F1F5C9AA93D575BC2D263066F3198,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\XINPUTHID.SYS FI2=62856,424805E73AA04A3FA48D21FFE59E2761D823553C50F0E0D052ED9D90491AED4A,18AA1E9D5E9497EDBDC0D849163A2721,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\XTUACPIDRIVER.SYS FI2=31744,4221486A0D36EF96AB1ED2A537747388655C4C2E470911646F4102D0B88FBDC6,0B0AD286240CA941246BBE71FB84672B,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERS\ZTTAP300.SYS FI2=68608,9AAC2211BE296E8F5DD105CA6F06BA590B005BEFF1DB32E5D163151143BCCB90,22AB02CEB277A793603A1AF748D2486D,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERSTORE\FILEREPOSITORY\BASICDISPLAY.INF_AMD64_65AB9A260DBF7467\BASICDISPLAY.SYS FI2=38912,215FF8E0F393DF8992BF2A278F581F62A8D2ED0A10B30A45FBD96242B468BD27,045E627AE5033B924B79CB451A792EE5,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERSTORE\FILEREPOSITORY\BASICRENDER.INF_AMD64_DF49C4DAA6251397\BASICRENDER.SYS FI2=41984,63CEF51971EB85D9823CE9A95F1ED9907D20525ED8E32230068CC36E9082A8C3,99392FDADF3CE5EB47403E5A52866E6F,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERSTORE\FILEREPOSITORY\COMPOSITEBUS.INF_AMD64_7500CFFA210C6946\COMPOSITEBUS.SYS FI2=600936,D04F090BB64D6CB2B16D7C77C0AEAC72C18DABFFD8B85BFAACF7459D44253B49,C35A1F7CD9C980E13F0E5D47484F03BF,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERSTORE\FILEREPOSITORY\E1D68X64.INF_AMD64_26255692C8B1C6B6\E1D68X64.SYS FI2=73584,570F97F6615A8DF8F0EA693CE995FB1A3E324780898501B297200181C0C3F9F1,F1BB7B8EAF6F140C6B72342FEA95505B,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERSTORE\FILEREPOSITORY\GAMEFLT.INF_AMD64_B38109E173F2592D\GAMEFLT.SYS FI2=23040,B263D352479812A4DEB6BB8AF573150491EA9F5D55DCD00185AF6759FF2601F6,DF2344160D1E58AB5E1DDB174D46853D,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERSTORE\FILEREPOSITORY\GENERICUSBFN.INF_AMD64_53931F0AE21D6D2C\GENERICUSBFN.SYS FI2=891664,820C4795C855D6BCAFFC72FA8BC482B96EB43994AD857B30C6BDBD5561DEA1BA,14C60619F233B96A1B74D5934884B8D7,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERSTORE\FILEREPOSITORY\NVMDI.INF_AMD64_6A0632B60438E56D\DISPLAY.NVCONTAINER\NVDISPLAY.CONTAINER.EXE FI2=38754064,FF1D498853C532735264609CC22C237F5102F7C079B8C76115309C2D3A490668,716885C042DC37C5A042F89FBF989E3D,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERSTORE\FILEREPOSITORY\NVMDI.INF_AMD64_6A0632B60438E56D\NVLDDMKM.SYS FI2=43608880,A10BBE577E2E12C9003605D6487BED57CFD17B966FB93367F0870391E584E390,8D42D88AEA707E62AA7C91377CBFDD81,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERSTORE\FILEREPOSITORY\NVMDI.INF_AMD64_6A0632B60438E56D\NVOGLV64.DLL FI2=18952,D618F57B78B3FFEC29E8C4472E0AA72EF1CA0C83DE968373B818ABA4D9747E2D,0547BB19EFA07BEF0F679A054EB5CFEC,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERSTORE\FILEREPOSITORY\SWENUM.INF_AMD64_16A14542B63C02AF\SWENUM.SYS FI2=34104,3EF244E91851E03BE77DE49FA7E36769DE287B0CB732CD0140C39FE5118D80B9,264C183C222EF95D4C64DFA8BA5F0479,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERSTORE\FILEREPOSITORY\UEFI.INF_AMD64_C1628FFA62C8E54C\UEFI.SYS FI2=110608,70FEAD3371792160701D47A808FC78786766E4C7CA7C5ED8DA356BFC991A275A,EEEECAFD642DB20A8470090C2ACAA6AC,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERSTORE\FILEREPOSITORY\UFXCHIPIDEA.INF_AMD64_1C78775FFFAB6A0A\UFXCHIPIDEA.SYS FI2=58368,7802DCDA6F49494245EC9304AECED7BB2E90908BED25A4D47F1FF4615B03DED0,E0E764F688DCACBA011BAEB2017B903F,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERSTORE\FILEREPOSITORY\UMBUS.INF_AMD64_B78A9C5B6FD62C27\UMBUS.SYS FI2=32056,A5BB54ABBB0F7B13ACCA0997F567A81395688C6D68EB87F67F688737DC16918F,5C33B91675BE0C9693358C1AAA723D20,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERSTORE\FILEREPOSITORY\URSCHIPIDEA.INF_AMD64_78AD1C14E33DF968\URSCHIPIDEA.SYS FI2=29496,5A8CC47603A1C9D58A30A5E897F1BCDC56199B08317B9FF319D469D6DD6CAAF0,BBDE7BF496327115DD744E7D4105C7BC,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERSTORE\FILEREPOSITORY\URSSYNOPSYS.INF_AMD64_057FA37902020500\URSSYNOPSYS.SYS FI2=11264,6281D573D9AD9AA204778C3823737726E882B17657B23CF5458C012FF7990E52,B37F0BF662BB504F0A9C247F24C281AD,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERSTORE\FILEREPOSITORY\VRD.INF_AMD64_81FBD405FF2470FC\VRD.SYS FI2=543080,164470FF75CF73B3CEF030CDBC8C063B2B58FF0345953F6F5BC7F7E488A0DD18,45D26AA39401C2ECE3EE1BC2BD652ADD,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRIVERSTORE\FILEREPOSITORY\XVDD.INF_AMD64_3DF14D8AE1A3457F\XVDD.SYS FI2=344576,CBFECC0BBF10B8107595621C95639D2F5BA1D88D99552D11A2190CCB29EF3AD7,D4D60CB59AB2AB7E4305D0D2E6653740,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DRVINST.EXE FI2=134656,E495FBA81F619DF4884538FB1B4F2D865551089D707885D449D54B42E7DBE839,F547BD22AAA872BB319F86F534608FB1,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DSKQUOTA.DLL FI2=468992,1994847136C7CB04CFC8B6186D84990394F56B9B0F6B0AF421C39B83E5935AEF,DF3C00E4B4A7FDC2FA6109814BB9C092,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DSREGCMD.EXE FI2=162816,30B4DD37228E0FE50C200F511505C09D3FD5B3395E5AE49931E752463424C302,4B903583999E571ED2B3B1CB6D694605,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DSSVC.DLL FI2=13312,CD3BD705613B8CD0F25159B32ADF38F73FD0B5BB9F384C08BDE8214509E0D716,79546C85EE91F2AEC0B1BC79B07AB154,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DSTOKENCLEAN.EXE FI2=341504,65AEE1E876CBE801A763F14930D15CF2E6A10697620B5903AA04BA30585A5676,81DF23EC4009D307479D5C169539CD67,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DUSMSVC.DLL FI2=40960,C604F3C971220C04DB7ACEBE9585C49AA55718C16D042E6B67F76485EBE65477,A9BE64A9C8EA10E9C6864D1694244F98,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DUSMTASK.EXE FI2=94720,0AC827C9E35CDAA492DDD435079415805DCC276352112B040BCD34EF122CF565,5C27608411832C5B39BA04E33D53536C,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DWM.EXE FI2=50192,0A4D029D295C64A3B3B82E004F5737AC508497768352E5A82674460470BDE047,A69D51B45433829E59B0574754D6AB48,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DWMINIT.DLL FI2=236032,4BEA9F741FE4CA9D6262477849896B9FA6377326D11AF044561C31BDE2D994B5,E62F89130B7253F7780A862ED9AFF294,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\DXGIADAPTERCACHE.EXE FI2=112640,C89BE2506C647924E94FA2F44AA4AF9EAA2F794FA444C8854FEA5B3F563AC185,AF7B5676A104F8A7D87DDA84DDFD5240,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\EAPSVC.DLL FI2=100352,1D3595FC64E37533FBBFC26EA27E6F66420759BD9341321435A5872ECFC13D8C,F934BBA57ED7661BC892763F023EB54C,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\EDUPRINTPROV.EXE FI2=1178952,3798D7ED22365536AE8E202AFC057014FC3DEA870C2F1D52031746FDE1A03B43,7787C219A5AF253FE32B65EAF521504A,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\EFSCORE.DLL FI2=83456,2B96E1724E7783B7AC8F9C17F25D31735C75F6CB9C26E3E7D9A2493EA1952F8B,9948F64DC8C831952EF1C4E84A144D33,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\EFSSVC.DLL FI2=887808,9510A7BB1016A364F51E374A90B0D595D37FFAECA998758C4DE63B16F8632924,C7D75A8F8468A5FA50841254B581ED7C,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\EFSWRT.DLL FI2=159744,DEC15E25420771EC4CB2D724D5F5B8627E9DFA3F56C4ACFFB01D8DF688D3617F,48066A0A516271CF80868075216A7A41,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\EMBEDDEDMODESVC.DLL FI2=414720,B8F3E0026D2DC9F473C261209D618338CE5773DE201734BCC4609DD55BECBF21,0760BA6539B9ED22A77D2366E8E4C5FE,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\ES.DLL FI2=3330560,ECE0A545A9E01A60D65202349A1AFF986A4D47B18CDDE04A664F326AA7AC460C,EEF495775DAD1D3EBEA677AC577A0A29,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\ESENT.DLL FI2=164352,94195CAB2AFA9ECAE8CAD29A211D15B09B8D421D507D73D04A0E7ED4003F6DC0,8BAE50BDABFDB3B0DB6FEC66F5538FAF,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\FDEPLOY.DLL FI2=21504,0918728669077235B2F2DB7EE22CE819FA570D8A7A497BA5F11E76774EA75099,0439B82F6034ADA3E71C0C9F169082BD,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\FDPHOST.DLL FI2=35840,056E1091468D268E7970045AB329EB3DFF48BB6B22448046A14C309678847B6E,AD64C91B3CC71226785DCE688842E5AB,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\FDRESPUB.DLL FI2=124416,620378D2EC9FFCEC6739406DA00392C55C11BDAD0D5259CE0B9AAB5A44BA1975,E750F8DF83922796598EEB49AE0B592B,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\FHSVC.DLL FI2=938952,CF1EFAFFCE216BDD747A0C496DBF3AFA9689709579409E0A486DC09A7DF18D83,2E575D58347E1274DAE5142DF52102CF,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\FLIGHTSETTINGS.DLL FI2=1423360,08C30B35B80FE01D09E30817703DBFF112BE6B1267EB34746C65349E78C3229B,08821E36B69A444C395F77B757FF2483,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\FNTCACHE.DLL FI2=825880,AD6731A03531B1214E9FBD8AFDF925EBF8ADB490E79127729F0312316ADD3207,2CDE36034913CB3869C8CFCDD5A616FF,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\FONTDRVHOST.EXE FI2=8192,D35F6447870180F0FF1D7B731A7FC0D171A41D21992DECD618B008BB2A62883A,148367EA43ABE5E705A80761C4E43BE8,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\FXSEVENT.DLL FI2=49152,B31A009ED60B0CD403A8E60B8540F115047304D2B6F009EFDA22A5A54C2E0C43,6E0E0C3E504E45C8694BB42849EA74F2,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\FXSMON.DLL FI2=661504,F5F1381269A303798D5C879CCA0F7F627BE5081AB292FE652A86564010CD7E6E,BAF9A183EB3A3BF5EC0F2137BF389922,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\FXSSVC.EXE FI2=88781,D906D6126A1E9C9569EF81605D02F03EF94AA57B3AB9CBD56C996BAF22FA461B,2E6AF4D5BF6E31E728F409984C3045D4,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\GATHERNETWORKINFO.VBS FI2=1334784,136E4C472E4D3E2C9C76CD1E372BC8003AAF8ABC85B48405849C4EFA8D4FC9AB,7ED34918A575234DAAFC544417F05A2B,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\GPSVC.DLL FI2=106496,7C059098A69C513CB93BF15583C9D11E4E83096FB94FD5C46584E74A988D6828,98C05369D9E8AFF249F6AB0837E87912,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\GRAPHICSPERFSVC.DLL FI2=36352,2B6EC0692A09E5943C5BBA0E3AEFC746E96412E1836C84B1857B4DCF242DD28B,2A41AF60430E686985E9101C07A77B80,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\HIDSERV.DLL FI2=66360,776C772E69CF9D81D8511201813DD79F2106DC7D2547B4FA700432AE9B73C202,855F55BB462B7D8B6BC31A94A592DF3D,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\HVHOSTSVC.DLL FI2=-1,,,0,,C:\WINDOWS\SYSTEM32\ICARDRES.DLL FI2=293176,BD96CD0EF7B84C55DB525D655F19DE7B63756B7F3554AEBDF8F4A7A0BF2507FC,8486D6F63D5CF87CA08E3B3604DCB631,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\ICSVC.DLL FI2=304640,FB6CA91F6F3FC650A9D12D54CFD25331A31404181755E7CADBC80A0A57327AEA,D222598C027A7D87382C0CB8D0CD3994,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\ICSVCEXT.DLL FI2=7634432,A7B6D20DDBAC5AF68D975E33812C9C9B05288D4DAA07AE647568E75227AD501B,DBA90E892B3334BC93EFED99789B50E4,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\IEFRAME.DLL FI2=365040,0E07CB97A539A536BBD1D989FB1C547686B69259D9DA83B4EF939DC9617A2DFD,4548476A880376F4EA87908543F11DDB,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\IGFXCUISERVICE.EXE FI2=346096,D4D244D06543C6FF786622B217E5FD7FABD181BF8136B88BDAD395FAC02980AC,15A2257E0C994E9B5952CA2BDDA447E4,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\IGFXEM.EXE FI2=1051136,9D1C87E15E5150844FB788DDAA2610805E960112A894A8043962E14FA62B8F14,B5FF91C5559E7BBE14F1328F906254B6,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\IKEEXT.DLL FI2=37440,2284C0EFE326182946E960E3CB20FDE964A8C6080FB0EDEDB3FDA481274CA5E0,8589CE299828E4FFA9943CCA8094E6B6,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\IMAADP32.ACM FI2=184320,B0310442FBFC81F39375CE8A611ACA4C72FD6184C3A088A9B3F8BF48D5F99530,F583129497057B8F6177349C3AF9EFFF,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\INETPP.DLL FI2=2434560,712CBD68FF72C3DF3B975EFBB668E00E5A514822506ECAEF5E5DF5A2CC82F070,BC650015006D1E10EEB0ED10EBA46D33,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\INSTALLSERVICE.DLL FI2=836096,41E2C248EBDCCCB3401B391943B4A24672E7C41494FC662199A90285D4BBCA52,23E484F9DF7D44925F48975E349A0046,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\IPHLPSVC.DLL FI2=619008,8BC382EC4102A118006E8CC67763198852BEB1DEE40184FDB384744D782C62A4,12C9DC58F761E72F9C889B213698AB67,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\IPNATHLP.DLL FI2=463360,3A44DE9764FA279CA56BBD5850CAD9CECF38F96AA858A725E283AE094B4C1964,B142CEA84B7894B529333184C282E0A7,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\IPSECSVC.DLL FI2=66048,B778D4BC71A5F5CF687175CA53AC342E4740156D4B96E6E96D918BD46C2C1459,77494E26B28465D2A09B9455F8A3B34E,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\IPXLATCFG.DLL FI2=160256,7202B00E92DCA1232E93D04E1FA695281132E4EFEE325EEFF34B872B000922F7,7643DE5E3FD4BE1917B8D830E67E79E5,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\ISCSIEXE.DLL FI2=54272,A7AD025FF011D215C7CB648F0231C4C5A40738C91F012FC4B29190E69680E03D,35256B0E5B3FFF977BD48310D5552CF7,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\IYUV_32.DLL FI2=94208,0B92E3C62FD0729F8608CA812F2C78DC7C3608EB5DC9099572B14C4C568EC00B,9E474D2EF2484C441925A5B39F4A97F7,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\KEYISO.DLL FI2=304128,8390BC797FE6EFB21C1898713CD4DB3E4301E837FFC1F1A8F5D8041C883E348E,8D7B58FD57A8930A8E7D84042F203620,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\KSPROXY.AX FI2=302080,D6E70EE54A15198C628A48D3D763DC80967E5EE081DEB7CDB82A9576DBD545BE,56FBEA44FE310698220D2194FF15267E,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\LANGUAGEOVERLAYSERVER.DLL FI2=48640,A0B145041F984DD4E0A6F8D0E9C8363DA6F2DA7460E140F028C320CEAC03759C,A997488F4EDAAD59C748CF9FB1D9DAC0,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\LFSVC.DLL FI2=51200,2146FE84B3AC6EB3D91AC56F5A4A25D005E36FF7A1B01E1051271776C59538F6,98B6DF0BC14DC6BE7FEF49998FA36896,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\LICENSEMANAGERSVC.DLL FI2=286208,09211F825142F591B0613EBCD6A81E34C1146B2F1DB11D1C8546367A3A462F7F,80F65BD56B52B57C6803042EA527B389,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\LISTSVC.DLL FI2=284672,164B6C738FC416143C49BF0D1CFDCC952360693F41F799B79FEBA72CD542F9B6,199738EF3AFC628823A7A5C74D5CA887,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\LLTDSVC.DLL FI2=26112,71F33FD997D36B8CFB7FD36397CB768AEF1B6329B3882D445B72246621F3BD7E,4A501E9429650B678610ABCCAD1D2609,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\LMHSVC.DLL FI2=1283584,5062ADC6A513FE1CA34E07ADC45A56F988A12D62B5A4C58A0121E28BD09FDDEA,AA80A5C58E7179541ED9ED5DC533681B,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\LOCALSPL.DLL FI2=71168,A9024C4C0ED03730085FB529828A917F701E3DCA30D3286AE0D41E9FFF33F445,9BAD04696E81E4420A99660C8D1388A1,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\LOCATIONNOTIFICATIONWINDOWS.EXE FI2=11264,E13985D667F66B7A0082356F23270F61A57B8C2DD211B1E09D66D7970D7B4D6A,D45676C47616B9ABBFAEC97DD3B240A8,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\LOCATOR.EXE FI2=1253888,6CC12957A0E7FF3DCCA28D8B715EDE9C94F329FD5BAB3366D4C70362325B31CE,1B279ADD6A4150FD49A6276147098803,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\LPASVC.DLL FI2=72704,6220BA55D96DDAFB6B573B2405DB412F7420C77D09B5C1A1637D558EA5480057,272B5EA7309039A904D254EDCC9796AB,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\LPREMOVE.EXE FI2=59448,362AB9743FF5D0F95831306A780FC3E418990F535013C80212DD85CB88EF7427,15A556DEF233F112D127025AB51AC2D3,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\LSASS.EXE FI2=849920,A03B0A5C92C4888B848DD5A2A5534FA325603647846C0AFBDD39114D79DF6E30,3ED230D2E9A5962F20F3D320CB270FC3,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\LSM.DLL FI2=119296,E7EC0402B1FB18E41A6AE0F88464D0E07F314FBB418C93771CA94EB0EC60D4EC,D8728CC5E5D3CB8A04972D2E0C21EE3A,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\MBAEPARSERTASK.EXE FI2=103936,30317E32D7F5E36AD2674353A198F5B2760FF121C40CC0CF11BE0CF9729FADB5,E9944F49DFAA4D580DDFBD676D61D397,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\MCIAVI32.DLL FI2=165376,A3012E93BAF33E278DEBA76563B10CAD1776EF2786505737374BEEF93DF9F271,5D60CCF3041687929C2A00B9C379E88E,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\MDMAGENT.EXE FI2=91648,10411BA97B3479F22655C4A9949DFBD037843030538FAA881529048D28E8FC4E,38A4736FC5B74F176BDD592EF95AB035,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\MESSAGINGSERVICE.DLL FI2=500736,E8034B600E9E1A56A8DE14988476B8C5556128E35967F95EBAF8DF153FA9ECB6,399F428646DE8D9B82B9C833FD9DBC32,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\MICROSOFT.BLUETOOTH.USERSERVICE.DLL FI2=1192448,43E01AEC265954E5E47EED1F9CA4872A1AEE9DCCE8536993AEA2CD5440BAF2CA,38D8C032C7AFBA2725A98719C2E03FCE,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\MICROSOFT.GRAPHICS.DISPLAY.DISPLAYENHANCEMENTSERVICE.DLL FI2=488776,6E1DA6D17EA73A82F6EA805E2E3896C7FF25FB6FED3B6F342ED3598851F765DA,3C7746F102D9FD5FA9CF51E4DA8AE0A3,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\MICROSOFT-WINDOWS-SYSTEM-EVENTS.DLL FI2=26624,7B09440B1F018B5AF02001C4832B284ACFEE6C7BD94EC003BB97152D7EC7D614,935AC506D4344DD6A9FA2D1230D20388,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\MIDIMAP.DLL FI2=418816,74EC1CAF70EEE9A371695094E3E0B7EC088BB2FE5DC5AF348D1CF63E9F34D52E,C87B6854C4D0DB8FB3BA538D5FBFFCF0,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\MITIGATIONCLIENT.DLL FI2=134768,2E78475D0F618A2F988727F5C21DC083546A6DDAB24E1152DCBF9C993EE419C7,AF70C76096A5C905D195ED0F40E0A294,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\MIXEDREALITYRUNTIME.DLL FI2=94720,F5172A1A3E24FC5271FCB0118861EA0EC33AA8ABB01AE9CAD50E2F032B92486C,AE03D8F1B7863268EAED2FE0105ED75F,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\MOSHOST.DLL FI2=1553408,6D17958C6527346036F35C6D9DB2F5C8D820CBFBD043588304C7BEDDF7EA8641,FD33757FA1522B4555E8D8D61BD18A07,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\MOUSOCOREWORKER.EXE FI2=520192,05E45B1E73205F2A4CC62A602DB40FD25E40E5FC733CBBDEDFDB377226792C70,53186BEA68E790FBC0CD98AF571CC3CE,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\MPRDIM.DLL FI2=1102848,0C21C50084603239275935580D28C56E73316721168C9698FEE0E2B10E82515B,386FA25D83CB835F9E9085E83C5473FE,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\MPSSVC.DLL FI2=21753376,226F7A60C87F2D3BCA1DD3F6983C0288C9F9C3869E7F37E45A04F95FA84174C6,06A7A902FEA35B080D8D653BA38C0844,1,"Mail.Ru LLC",C:\WINDOWS\SYSTEM32\MRACSVC.EXE FI2=30208,A3EC3A9F614B1675EF3C5466A56A266C1FE0B8FDCC45E7BE32593ACDF0D424BC,27388B3F540C3F2979EE9CAE97D14208,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\MSACM32.DRV FI2=34600,322DF17DC25B5DD63191D23BC0C32B00E9F6D16E9F93C029996971267CF095B5,4D4AC56D7A60742B6318A6325FD80953,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\MSADP32.ACM FI2=148480,EDFE71025C352D0DABEC7B9506C5945BB0EC11F8DB540DB8CB1116C2EA1648A8,2EF846AC66E181BE820B513DBC15B5D2,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\MSDTC.EXE FI2=375296,672CA98525D6DD799A01A3BC3A62AB7B4544D62ECEB3615FAC05BFB97B389D23,DAE67BD7EC6ED569438F5CA38BFBB458,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\MSDTCKRM.DLL FI2=14848,D842C0AA333567D6B14A5F7429282652917A10B449BBAB8A79D7F4C4821A5D9F,C80939122EEC4C9583A521F673ED8DCC,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\MSFEEDSSYNC.EXE FI2=25824,189897F423D56B60C28FAA7C4F2BDB2AA5CCCCEE9D5F32E43103950189C912AD,AA98E9C4CA0A38D72D110439E4C24D2D,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\MSG711.ACM FI2=42904,3DAF84D26C05B80BFC38BFC43AE3A7BC0DA325CF374DCE0AB3318A7CCBBB8420,AB34B364C726818D899A53078CA50761,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\MSGSM32.ACM FI2=69632,0A8797D088023A7F17BB00B22FF7C91036070CCA561BFF5337C472313C0CB4AD,E5DA170027542E25EDE42FC54C929077,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\MSIEXEC.EXE FI2=588800,1A6947DB303418AB94C7BE6D13AB47C19FABEFABA883897677660C2BF88178D7,78AC5B8AF542A7CD4FB1B53BF1CE93C3,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\MSRA.EXE FI2=18432,2311837868254D225D2B2340B03F621EFA4D7D0377C2DA8052FF4BA513543928,41CCAA3F7571324A1F29311DAF6D002E,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\MSRLE32.DLL FI2=937984,8837F281116CFD78B61675E1F945637F24999FEE825CF63D7253E92C67C5B755,DC6CDC1CAF16FBA043C6C042AF20D7E1,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\MSSPELLCHECKINGFACILITY.DLL FI2=84480,FBD55B94C083844AB2C93AE623255B6A5A5C109FCAE9FCB99CA1B9CF627D2DEF,E8755CB0466F8AF54FBB748DAD98C7AA,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\MSSPELLCHECKINGHOST.EXE FI2=8239104,36CD4825AB9F83DDE7107C3154AEEEC044526D98AB04A9B33A197313247D4FDB,52C877EBCB669BADA98794A22E7D62E4,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\MSTSCAX.DLL FI2=39936,DA163EDD62279ADE83F461BE149027E940AB999B639DD6314D95EAAE0A93F917,6CE2B64AFE92D892974B233DB91F9433,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\MSVIDC32.DLL FI2=27648,117C431DB0FB66DB952E8D4C29226D34D8E7462CD65ACBCC84B7D63BE3F5B942,29E343D48791A239499395EC49DD7E22,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\MSYUV.DLL FI2=689664,363456023A0BAF3B2339A3664C803FC4B961A46995FD20309B81204A6EEF98BD,241D37875FE58198DC42BF626277AD38,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\MUSNOTIFICATION.EXE FI2=454656,9C7EC8118B3550829215665F2C7D537E691BA6035432CC36834039D8D64D8A60,1E641165EADCE9085810CCD4E1AAF443,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\NATURALAUTH.DLL FI2=171520,7B0187BE9705ED2F925616C13B3744BAC0A9C96B21BE503D96BC9EE7EE125B33,D47A20839608B8213065D7AFC8C42195,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\NCASVC.DLL FI2=382464,51B060250DF29BA189307554A05E97A951007330CD015837A32B7A67D3C15C77,ECD81E3CD27CCC5945A15377CE194E07,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\NCBSERVICE.DLL FI2=92672,F853F526C811893BD40B1124BAEC543099381E7BF091729B6A6665DF3CE10B94,8C938E851CDF2CE30BBEA14555B61820,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\NCDAUTOSETUP.DLL FI2=866816,78607F6AE85B8399436E35BF9A20A1A8CBDFCDCE666E9215C70CE459A14A53B7,30F2F1D095AA286C044B7BC99D31F353,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\NETLOGON.DLL FI2=288768,4AB8B86B076320DE116F42DACC83DC95C635CB32392F3EBBE0FC64F22E7BF70A,62D46DA273CB543BB1671FE708A280CA,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\NETMAN.DLL FI2=881664,CA78A64A86D8875DEB9C9E8E7CA8A6E36A7BDE222698F187BAEEEB5A023DE0DD,A510EE633987CE98E6389E5D8F3DF91D,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\NETPROFMSVC.DLL FI2=309760,D45037ADD9AF6C488AC0A11356367EC684BF36E6A48625247B9BECCB4AF29C24,4CEFFE7F3483FFC5D50CAB27818A7C3B,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\NETSETUPSVC.DLL FI2=770048,3AADF924FD9729B040D4063E2721E465EF385944F8BE60A3A9DCB0CAC2B7188C,393E333035EBA76AA01B62DAFE29310A,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\NGCCTNRSVC.DLL FI2=924672,C21BBD70CFA83F796949A6C43DFDCA77501C621044FDD1ADED5F59A9CACD1D58,B52F2A6D1756DB934ACE03F61B418B15,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\NGCSVC.DLL FI2=388608,CE9558F169F8D27368E3E1B760BF0CB1BB3B309FC249A7942D35D5D0D74A43EC,5A97FDAAED1ED33589A46645336BF674,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\NLASVC.DLL FI2=34304,85449DBDBD24D72E0BAD82C81306F5AEC18F7CF23631BCFC09E8AEE4C7C646BE,0FA6DD9E38FF747C54FF5AE05F304327,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\NSISVC.DLL FI2=19456,B9590B5369538C32D36B4DBA35779B750A757268B00B33C95862314CCE5BFCD5,3C4855F7897A505619BD8ED648475C72,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\NTVDM64.DLL FI2=169808,3BD70DCA52E28298C2604D6B130493B6A40589600FBC7A7353B1D47BE9CB3AC9,0425BE72E8F805DD946C0AA37F62F1E2,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\OOBE\SETUPPLATFORM\SETUPPLATFORM.EXE FI2=382976,71F4CC7595C6D5E93AAA14259DF817C6C1D4BBCF285545FD980F6DBC86A30379,66969AA56E77953E596470C73A9004E0,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\OPENSSH\SSH-AGENT.EXE FI2=439808,46F5EA2E3D590FB10E14BC811612B6EF87C805B359A652D2C6BFE4840D5D6AA2,DA97CD5815EC123BC88382C08D465B9E,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\P2PSVC.DLL FI2=67072,97238D08DB2635C160698F9533EB58F37627B6C56C094F04B72E0CBE2AFFF1F7,5D24C1565593C63088A2A4D7205732DC,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\PAUTOENR.DLL FI2=872784,D12B04CB5BA852281002F9C6CB44A229000E0A0BEFEF92A11FE501EF0F9AFE28,9D21BE4D5FAD82D07149CD8DAFD6B473,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\PCASVC.DLL FI2=106496,F4A1550BFEFBDC09DA82F53CE94EF3261C75DB1CC7C1EDD1074D31F828A47316,217DD189B66B68149ED4F7E8C9BA1DD9,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\PERCEPTIONSIMULATION\PERCEPTIONSIMULATIONSERVICE.EXE FI2=47616,5A21833091835DE5D1D3D40579B0B4EF1D442F9843568A7696DA7804F76207CF,9D8502EAB14478DF7CB3B764E8890ED2,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\PERFCTRS.DLL FI2=43008,A44164C842887DBF0C70F2D1EDB7A10FC458264032FD13F06735049C90FE6004,DA412E9F96345DADB13F1FF9CDE95B11,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\PERFDISK.DLL FI2=27136,96DEF0B53135F0C594A864DF3B9D554EAFD7650BB6CCA9B3164B9DE4F45DFF06,9DC2A3AA16E779D3FE9C258B48CCE847,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\PERFNET.DLL FI2=42496,77BC475C0534FF96AC7805C621CC32EF4AA6DD25D5439B96FCCADE51EB4D7B22,98B8E200162DC922905E9E8A96226DD8,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\PERFOS.DLL FI2=46080,4D682F54776008AA4FD4DBBB5C091C549CBF88E48C458ABE1256E71F6F68F33B,86469971580B94755D8D651CCA9DD4D9,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\PERFPROC.DLL FI2=957440,8CC03BB83DAC8E988A3F9BE5D895F34708EF0B0AA579899C1E1504D125529B17,1D3DD2C778ABFA5AC62B995ACE39CEFB,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\PHONESERVICE.DLL FI2=196096,EF9BD3DA0E2BF4BE221D8EBD846EFB511E3AAB5AE35BEBE5588E4BBBA8D50D02,D6784996CCCF3CE1FCFB692D74F639D3,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\PIMINDEXMAINTENANCE.DLL FI2=1493504,44C16E194258C9143A45F4022F9C5DE229E217D6FF7F944F105FE631BE9EF4A7,9E431A5D697432DD6F4DB48C9A185104,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\PLA.DLL FI2=352768,E7DC2FBA4CDBB0A35CC58E0FDF37D68891F18A80E449C0AA2C66C43A596EC4A9,F8CE0B4F1BC5E4FBDD66C1CAC4D58314,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\PNRPSVC.DLL FI2=13824,73B88E1238AB71ED4142952F06E49D230F611C28CEEAC263820F6AF148D2965B,54FB96FFB3E2984755F82CFFF72E317A,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\PRFLBMSG.DLL FI2=182272,B3DF926CD3FEC9B8C9AC1FDB57393824BAEE84DBFB2F9789BD7C63862C344217,415528FD79A105F4C16FD25526D0F6BB,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\PRINTWORKFLOWSERVICE.DLL FI2=487936,4CB4C4A614A0BB0501DFA21B5BAEFEBC5C08A6E78EF7B97631CD7DC57579AFD1,585DDB93534E1082F2433BBC7E83574A,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\PROFSVC.DLL FI2=486912,73749AAE44BF7A066C52C708A222D3E54E80BD5094C6B834A81F54D3859698CB,5FC19A76BCD4D18B32E17B93898B981C,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\PROVSVC.DLL FI2=87040,E0D2C66CC92A80C77AB29A56641505036130A8B01BCBAFB866E28729F4985E4A,380B6AA8DE133A523F008E1C78EBADA0,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\PROVTOOL.EXE FI2=247296,172A1392937C7B8BEB91427918B5A47B1AD7FC329AD410527C3683289C739AA5,666794D3C28A67355B71406ACAC34C54,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\PSMSRV.DLL FI2=281088,AD97109BA3CB2F3C63A7F3131EB889752FF54867B1229B26B03F01DC8C769947,035CB63DB5FDE94BC90AC4F477B491E3,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\PUSHTOINSTALL.DLL FI2=1481216,0ACFE40D4D3D5E5E44B0BABADB9E712893EA6E952128897831F7C3FFFE895C72,5732D33B38B48A322D7F6A3510387D2B,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\QMGR.DLL FI2=1687552,63019DA8121C3E4830957131D6FCF760FF47083D466945758868C32FF12FF990,26B8F128B13A3955AAC30034DCBE1581,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\QUARTZ.DLL FI2=287232,BE1A79A6498697EB86FC29638324A853197B49BC06AE3EB1130793F710926998,2F3808790D517E5E5E6ABF7177875C02,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\QWAVE.DLL FI2=111616,B9970819DB91FDF78D655A9A8A03ED9EE020B1F722DC4AB9D003CA0B3287FCCD,AC0179CC701DEBE60FF3ABACF1EFE18E,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\RASAUTO.DLL FI2=135168,4081A6FC67F46AAF3107BE428890629FE1B5AEA623F64076C572EB77A4F52EB1,4FCF0FF47567BA876A803BBC2703E4E9,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\RASERVER.EXE FI2=967168,156DE77570BBD1E6FCDF7D871E2C93981D33970FACD4D924B9379E571C36A17B,14776644698C6329CC0B215ED0F50132,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\RASMANS.DLL FI2=734720,12C6773C1ADBB53F55900F751D5717D754D57E51A2FBFE5D53436910A677DE51,3432CBF3D68E3DC486BAA84B3DA715B2,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\RDXSERVICE.DLL FI2=166912,60360DD8EA1802C8F95EB93531FF9666BE1148253E6A1BD706D4CA98955C0F6E,58B3C0A2B0C130838588EF519ADCE495,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\REGSVC.DLL FI2=152576,0257C0CFBE9001DFC51D382977C77BB1B52984D01BE38E47C6B8A0018AF1CAB0,2A10F8D56DB7BA8FD83FD7BAD2F9E94F,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\RMAPI.DLL FI2=84480,3B39E86C0434EE91765BF818B8D1001AC0B44B86665EDE87E770302D4102574E,E54BB972A5D80219D640F4C8FEB5D05A,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\RPCEPMAP.DLL FI2=1220520,3799B21FF924D5E0B5D4967332D03E50C548A32622BD69CF54CC37B0A712CBCB,846C68EEE19E80C5544D1F23663F0FEF,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\RPCRT4.DLL FI2=1330176,79AACCB16ED20D2683B1231BDBC3E69F9EF6F85F7DEF2B2FF5607BB9525C71FA,EBD998A6A7842E695702A978BBABDD46,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\RPCSS.DLL FI2=206848,82BD7CFA6ECF118CA59EC9BCA0FD4883455C3444DE99D3B260B1F95703A9AE71,87DBC7F78A25B2F855621C6D99DAE9A4,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\RSTRTMGR.DLL FI2=71680,B53F3C0CD32D7F20849850768DA6431E5F876B7BFA61DB0AA0700B02873393FA,EF3179D498793BF4234F708D3BE28633,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\RUNDLL32.EXE FI2=103288,E86870769EE6C797E09457BD99C58D9BF2303CF0193A24EF9B1222C2C3DAF628,BA4CFE6461AFA1004C52F19C8F2169DC,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\RUNTIMEBROKER.EXE FI2=72192,41F067C3A11B02FE39947F9EBA68AE5C7CB5BD1872A6009A4CD1506554A9ABA9,3FB5CF71F7E7EB49790CB0E663434D80,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\SC.EXE FI2=265216,7D40987B55BE7BA484E33CF60B63197059A3B92BBE84B3BD28CD0C25F6B02F92,51EB2F7EE69BC9ED017D60441F0D1CE5,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\SCARDSVR.DLL FI2=205312,1C656503302139A11BAE19BBDBEAABF5B31F292BFA7D952E8B4693FB59018FAA,238D26351D9394A1A4A1682CEC9BD868,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\SCDEVICEENUM.DLL FI2=344064,C27C201DF01753AC06609F240CDB8168D3ADC2918A9B4C1D8E1AF06A9AE6A36A,0A7E6CE68D60D0F1D272B82002E6B535,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\SCECLI.DLL FI2=581632,D05EEE0B81274ACAFB8CA010753095BE9ABC47F4CEC77D403896613C627911E8,759A13348A43871EEAB082FC2A2EC29E,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\SCESRV.DLL FI2=861696,3F095BDA566769F426FC6F49A35EE1F6A77DA3A6DF7A7D67D43555DD5C9CFDB4,B1101788B5C90B6859DB8280D2912EA2,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\SCHEDSVC.DLL FI2=154112,13C5BE584FE5F9F991338E9F1CC538B8C4F389E897E48DD7BA13DEC2CA56032A,7D630290A1CB82946484DEC5F8EFD295,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\SDRSVC.DLL FI2=272384,09A2CD711FD5076160FF590FCBC83CE4FC422C89E7373373CF3EDA471C6D819A,EBF92961AA0CCC0AC803FDFA859D85D4,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\SEARCHFILTERHOST.EXE FI2=935424,E1BD5D2944C4DDFE7CBF6A5A14D8F06A35598A02A5AD824304F0B7936C410D7F,3EFFDB0C80E124422002C4C9AB44260B,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\SEARCHINDEXER.EXE FI2=419328,62D8455EE452BE6AA6164426E43F2F1461858DD305A3E784DBD01E32691F30DC,98FFD56887C1511E98A5542531829025,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\SEARCHPROTOCOLHOST.EXE FI2=32768,39A114EB591E243E0429DA7279413F046626DE7B52E057DDBCD26A0A1BF327FB,016706A76857F914C99D2472B1E79BF9,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\SECLOGON.DLL FI2=987552,428853C320F204C5C2019E70CDAB1BC64E5D81D321D405DEB2A6340BDD489CCA,B76F2005B6C0756EB978201FEB6AB1B1,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\SECURITYHEALTHSERVICE.EXE FI2=86016,570B37A7A3FFDAFCCECCC33CBC1968FEB857B73CA3CB4DFFEDC2E67E9ABD0878,783C99AFD4C2AE6950FA5694389D2CFA,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\SECURITYHEALTHSYSTRAY.EXE FI2=1223680,0FAAA993D43EE8F397A8B05B38F4C5D20F310F66FD6DB9AE335B3DB294D4BFD4,E580AAE89E9AD4190DEF77BD9F7180F9,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\SEMGRSVC.DLL FI2=77824,56A94B1617815C1E8A79D832B0F0CBA683C3080105CC4C87DBB9B8EAB4CD2690,1EA7972A4C7163FF1D3EFE9988404D4E,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\SENS.DLL FI2=1265152,C3DE970DAA10864AD81F1D9B264C2043F7C7C77288E4F7CC38A56E0C724CCFFC,5A3B2A346DD3822803FAE613842839BE,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\SENSORDATASERVICE.EXE FI2=466432,FD98FF3DF2A33E4893D0E8E8E48F88DEC42443B9CDA289EA755D53471988488A,207FA2E4C1C74D930C61F01E3DD8EAD6,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\SENSORSERVICE.DLL FI2=181760,A0B73C1BF636F14504B69606999287B6FE148C958A4F6E31E9022FF129A048E0,0BCFFAD6F3B180DD60C941B01768F733,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\SENSRSVC.DLL FI2=515072,FEAB610F6B5E644D961B43C225A04F635F429F3BC8375BC704797F80FFF05076,2A22DD7A1CDA78F3725D203F49C465EE,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\SESSENV.DLL FI2=968528,321656887526B439967B377C20C3AE04F48B11A77EEA11F7FEBE47D30B3F7BC7,E60933F971F523D62331BC69B79F00B3,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\SETTINGSYNCHOST.EXE FI2=329504,F9CBF1FF87D6F11920C4B7367EA2178BF13AA276C65D918950683983F268BC1F,3BA1A18A0DC30A0545E7765CB97D8E63,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\SGRMBROKER.EXE FI2=307200,8E8EB9441DCB707810D64B6D30D1CADE1268A209C14D7F1353176F974CCF3235,5A908C65D3CFF0236DF9B9D49514283B,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\SHAREDREALITYSVC.DLL FI2=259584,07888C7575A1D7D46AE375B1CE6C13665CCEE0F0672EA8FDE71B955B5BC0EA70,BE44F2B19C4F61FED874C7FE26DF92AA,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\SHSVCS.DLL FI2=111616,8EE21A0BA8849D31C265B4090A9E2EBE8BA66F58A8F71D4E96509E8A78F7DB00,A21E7719D73D0322E2E7D61802CB8F80,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\SIHOST.EXE FI2=2378752,9605680FC164ACB985C031ECA2C8BC4909CF8B749C571DB6DE2B0B2C204C2163,521ED922765BCA8F79BD76188F879311,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\SMARTSCREEN.EXE FI2=36176,505355174B613DE52D233F8BB1322CDCE1A251084D5DFCC819327485AE6247BB,CFD5A1637EAA3262742D1993156799DA,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\SMPHOST.DLL FI2=624640,7F21D9C372946C08223DE716915FC0E6D2D08E5A503B218565D5360BFDCCD78E,B93199C67FD01A22DD402F457D00372C,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\SMSROUTERSVC.DLL FI2=16896,9D665698FF26ED333AD385B4B7A6C0F2B6806371D278E281FA4188002A5317E8,1971BBC71602B928CF9257759E3C05E8,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\SNMPTRAP.EXE FI2=165376,0793CD515F80FB8025924418C7E289047BBC15019ACEA868914EA0015FCB6ADA,2542D5C20AC5E8CEB42113529AD0BFDA,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\SPACEAGENT.EXE FI2=86840,5CCF6EE934B0A4EAC6BC823EC49376DE8DFF3C453F6D911E944BF82B995860D5,990688F9AC02D6E71BD9447A3A4094DD,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\SPACEMAN.EXE FI2=877056,327C97EBD48C86081164971661F943D389BFBA3CA52DEE84BEEF1B29491998CE,59AD6E59DE9E738C7B7C10C117209369,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\SPECTRUM.EXE FI2=5172224,8BC3745AF61D0072C21C82B6AA810F346B2142A7786D56CC3444E3379E4E0EB5,C31A39D0F3CACA4B26CBFD7C16FF7097,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\SPEECH_ONECORE\COMMON\SAPI_ONECORE.DLL FI2=182272,DEC41328D36106BA78DBBB59875FB3566091428C0DEB98D381D8E08B26A1679D,3C5DAD72201E770A089AC64486F03D2B,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\SPEECH_ONECORE\COMMON\SPEECHMODELDOWNLOAD.EXE FI2=3595776,1F067D862ECE38294B8ACDFEC0F50A82F1E4B1B5A6ACDB7A8F5EC6D0B7D9C3A5,207791C6CF332C53C72BB2E66AB13C6E,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\X64\3\PRINTCONFIG.DLL FI2=802304,9173A9237B82B7A2BF80D7D70FF65F09A89097CB32F04725B861D8FAF6515F9A,7F6BA33968C1B2DE5289DB60D4E6B3B1,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\SPOOLSV.EXE FI2=4629312,ACA01EC021704B7C814EA3925930441EEF77687A295162438A471FDA824896B6,FE9A6468754A05492BE3EEA92083C7AB,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\SPPSVC.EXE FI2=5120,36CE0D808A5BF49CAA8BCA12F8EB71D8C34C879DCC4208E94F47CF2D9D7995C1,446107D68A7F9F1E8A8EDDDEA64E4C55,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\SREVENTS.DLL FI2=59392,40E27A9039A2E4A731EA6A74291840FB13C679A1E8AE5B523016AA15727D8A58,2694D2D28C368B921686FE567BD319EB,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\SRTASKS.EXE FI2=301568,EB1FD7247E8C17DA0EE0728FDA50AAFF1EA56C150739B59A6E472E3F1DF30B81,93A1623588FB4E1CEE36B86DB28C8566,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\SRVSVC.DLL FI2=242688,2F00674E4ADDC2E2F001F4008E0D382AD3E4A5AC842136A9632CBEFE3073F998,3CC31E5EAA65FEC6591A32A202437E7C,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\SSDPSRV.DLL FI2=211968,EDAE87919A509204967AFD9500021DCAE4EE9DC2D89DEF7960D5DDB1A594C9D3,2775EF3E0E76D9A44AB60D6143FA92A5,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\SSTPSVC.DLL FI2=25088,8B49B3F3D7773802CBB1E1400504FA5AD437502A3752F8149E6BB8D231A2522F,4EA151DBB72D2BB5C73E16A91547E453,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\STARTUPSCAN.DLL FI2=1095168,7699B128B863A1CB6EB83340BC6B67DDB629271507E350DC381F8C6A80F72DB3,50D0680C66E639090AAF9F82FA397E6A,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\STORSVC.DLL FI2=57360,643EC58E82E0272C97C2A59F6020970D881AF19C0AD5029DB9C958C13B6558C7,F586835082F632DC8D9404D83BC16316,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\SVCHOST.EXE FI2=14336,0DC828C46E057ADA9934424BF00067B17EEB8E0108CE1E309C8DEA4CC42448BA,D73F83E795F3BC100C21EDA2BD6DE307,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\SVSVC.DLL FI2=465920,9DFAEB2E3951A93236EE6BAF5328D46FB062D31A1077305A8A5B16039FA620AA,126DFCA3C36BCA7BBB359CDC92C5C271,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\SWPRV.DLL FI2=660592,5EF409446A98E87175D7C5E514D19A630AD5B5C6B8B303540E78F6C101842FF2,64218EA95B94609C455D8D72B8CA1FBB,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\SXS.DLL FI2=1006592,CC59F0C50BD877C7972403692B9CD4708FA65158341AB44E1167EE7C98502016,D898D409D20F00AE8F29E6076BE16CFC,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\SYSMAIN.DLL FI2=251904,F7D2CFF58621200AF6318FB4BAC53A5E595F7A76CB2FAB0272414AFA2702512E,A44A39FB49D1820AAB221A2EF5DC8BBB,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\SYSTEMEVENTSBROKERSERVER.DLL FI2=235008,6385EE02D392FCFFB41CE5C5D4CD03C245828D98DCB01F0B4358B431257F9F5B,055070E3AC1F342125E3296641BDC4D3,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\TABSVC.DLL FI2=316928,439559DE34BE096824CB70A97524E843CE2802092A9C882167F4CB08FE9664A7,20CEAECE4ECDEBC89C82F1998696D596,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\TAPISRV.DLL FI2=97096,0322728DBCE3A577C4A13B907AD7375D27E74880B63F7371384F67D19197A0AD,564E4806AB18F93B93D551CD10C1598E,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\TASKHOSTW.EXE FI2=225280,8A5B62C249188151CF773A5C30BABFE48E150F3E8DF3B735E10F2CCE7FB987DC,02B923CB420D5F6EA6E03DE016AF8F3D,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\TCPMON.DLL FI2=1133056,C855F313000F64BE891B3BAA356136583D83F4FB0A163DE834114CE423733F65,1500F0E1078DF51144C6A7533BC509F3,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\TERMSRV.DLL FI2=238080,12AD73C3C3D5354AFF5284590288D3C664F40AA2437FBCB619F90C2F678CF9A3,933AB796194214F99353FE2525942BC9,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\TETHERINGSERVICE.DLL FI2=70656,8DD5348A4983C376F63E6B209227D4D02300555F8C80A0E0DB2EA16074ABC334,8EC4197962A0349DFFBDC11586099DB8,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\THEMESERVICE.DLL FI2=326144,4CCDB591EE16507879D8F12C0BDD40FACBEEF03BFC553A84270284D4930B433F,761EBB96C8217CF5795ACF429BDF9E88,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\TIERINGENGINESERVICE.EXE FI2=179712,C4E63135EB9BAAB1B7DE928C914CACEAB1E4862D6C5913B23EFC5B8986B1D91E,6B761253F07F46BE2B16C768B1F22551,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\TIMEBROKERSERVER.DLL FI2=1522688,F76B9A9DB0A802341545812922C4EDE1FE659ABFC5571FD27BE7BF888ADCC620,F628CB9D66A9A3CC4A8F08B703E78B33,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\TOKENBROKER.DLL FI2=3301376,320B251951B7E822E0455A0214A3341F359A82AD6DBB51A33A6A8EA9F065BF03,BA24F2FC8E61523FE1C42414D73A2F1E,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\TQUERY.DLL FI2=114688,F121E79E0A15ED6E362D7DEF72F9C1D2D5CC50BBEC3541DFAB91691BC3AFB191,62636F77E0C51D59F043D9197C897AD4,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\TRKWKS.DLL FI2=16896,AE395FD799A07B2E9B5DD9FE68C2FA494D837D6D2FBB8B56AF30F91A4A2C446F,66FBDC3059D28CC35C45BA9D3DD8B153,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\TSBYUV.DLL FI2=1249792,E3C5F67C281EDCFC652D4B3BD9EF3EB1730FE45BAA56934E3E1E8CD1A66342A8,4A282820CF5AB6984DE2BE66B1312566,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\TSWORKSPACE.DLL FI2=660480,E67A291CF2A27F29AEEDDFBFC0F277C2F241A4BAEEA6606D93764E9CD00045CA,016B2598B3AD0BCE0D4CF4DEC504A735,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\TWINUI.APPCORE.DLL FI2=97792,1E2E68E68380CFE42C2D975E826F6301AA7F35566E9A733B881BDC6271EC1981,A7C58987094E1EEBD63FB94BBE5FBC2C,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\TZAUTOUPDATE.DLL FI2=70144,3C4DE3F013D4611BBDB14EA17207E4D93EB406E14E639B1D87CE217C96747CF2,433D943CE267EAA3485137E0D21A7348,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\TZSYNC.EXE FI2=185656,CC1AE7A8B966C5FFF14D8B2686497E59875693B8CF74536EAECE1C9FC5D99C7B,51C9273087234EEB15F91073518DFB32,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\ULIB.DLL FI2=133120,954BBFB9E4C7FF79A811123D31954840590837ECDC9108161717EE29C8EFB676,47997A891009AD881DFA69E018D3DF41,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\UMPNPMGR.DLL FI2=178176,EE47BBDB755155592EC9D0C203E14D9E48CD3DC8FC9F9A136548046BF34FBEA7,FFDECF73BCDC6E124ACCEA0A3DC6DB3D,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\UMPO.DLL FI2=396800,C55B91BBA36FBD18C43FC367C54267EF28CEB5CCCF04EA7E44FB4778748DF005,A4AA744447EEB2B46EC60C7AA487B072,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\UMRDP.DLL FI2=1191936,971440911B04DAD4F9F7C5621EBFE5C1E69B7A8455F2F3D33A1D96FFA1171A81,DA04AA3DA8CD89AC26095DFCABA7740E,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\UNISTORE.DLL FI2=458056,B5608C0E24EB01C1FEF289F15B60A380CA9CCB5BA4919746CE400C1BCE11A588,A6F44C104B59FA71205C4F75D466303D,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\UNP\UPDATENOTIFICATIONMGR.EXE FI2=265216,21F41FEA24DDDC8A32F902AF7B0387A53A745013429D8FD3F5FA6916EADC839D,A6FC8CE566DEC7C5873CB9D02D7B874E,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\UNREGMP2.EXE FI2=471552,0C0C7524F1A6D375D5D60DC8C602A75CB79B7311C0735956A2F42152A15C5F40,8BFFE0333C9EA9C54797C7F0E6F7769A,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\UPNPHOST.DLL FI2=931328,32A77B1718C4D21142AB7EA55080CFEA6DD230F3C63EB76BE855A7A1F060FB46,C77BA7AA97458ACF44C94D754A434888,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\USBMON.DLL FI2=14336,8CE394C87B7948178FF162F9045D87B37F09443B3B8D9FFD6053ACEB836ED044,1ABB49F2AB96DBBA56BB7FAAB4E2BC6E,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\USBPERF.DLL FI2=1702416,8BD5191AD142A6E9F9648434FBBB14B0E2FF2FD7CF445D90F0791CBFC2D23805,A344B6C6304FCD7DAE72DACA784EE53C,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\USER32.DLL FI2=1554944,45B8C4BE560AB5C7BDF250DB4CB68FA4712570B841A11BB43722A14812376DCC,B1F3989A13B65D3CAD4778F9D92418AC,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\USERDATASERVICE.DLL FI2=176656,DE6F6CD7D703DCA17C147B358FB0DED9B763C5642C56DCA0280204A8D3E2CDC3,6331627F363F17F1B1D28C4FE3FB433B,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\USERENV.DLL FI2=34816,EDA7EE39D4DB8142A1E0788E205E80AE798035D60273E74981E09E98C8D0E740,582A919CA5F944AA83895A5C633C122C,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\USERINIT.EXE FI2=1485312,A0D752CB8418EB492AE4135CB9A43D79B7D8F2AC386FA917724ADF7651249AD9,F9E1B05E0E502F29D1AC74807E6B5EBF,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\USERMGR.DLL FI2=89600,278567A8A88FB508453C6E415EBA46E1D23A419FC2D09992DF95883C9F37CEBB,CB83DB7ACB08CCD0370200EED9A1803B,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\USOCLIENT.EXE FI2=569856,FBA3364DF3DCD351F47502E81D6390AE9D95D3DF9865167DBC01A9F5C24B4E75,15FB95B2BFAA8BE549479F5572ED3F5C,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\USOSVC.DLL FI2=382720,97AA8A487DAF0699E569B3E657EAC605302C74B75DAF2058856D799D32EA8026,5C5DC8E40CFC3979E793348A009434B7,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\VAC.DLL FI2=371200,101ABA197D6A9D48FAE78239F042263EB77F5F24B1A2141978E013EEE27D20EF,5A54C98227CB936C2F95D26132640769,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\VAULTSVC.DLL FI2=675840,250173049A54473E149FD6F58D45665469B497F6C181925D5FC4ED15F019DE55,D28FB8A8DD61CFA35B6DE838E0A3978A,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\VDS.EXE FI2=1477120,AED19CA1EEDF716640FAF70B1A4A10736C6C7ED0E2149C3D6CAA4D5E6DA8899A,AA98234C89499A69BD55C2DCCC4BCCC9,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\VSSVC.EXE FI2=479744,EDABA8F659EBEC01487D1A5B85ACC355EA79EE3E493E313E9DB786C1CB24CDFD,F547820151D4E231184F1625CF6A5086,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\W32TIME.DLL FI2=407552,17D04E719009E5C5CF5A68CDCFC9B5C20E5001E2698C9CDB024BEEBBAC3AED6C,328BEF384D31C91D7C55E87EC1B0B1EA,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\WAASMEDICSVC.DLL FI2=442368,AC2F0A68A2BCAAF2DECB0AAF1B50D652ED8B631B08D06B910B407FEF9069412E,D765B98325D89C076FEEAB1282CD08EA,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\WALLETSERVICE.DLL FI2=33792,C3F8A0A48933D458D7410E1BF6DA1499D24C92E5067B7B8AE802CD3D20CC18BF,2AB9224D01328E1DC94A8085BE52B17B,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\WBEM\WINMGMTR.DLL FI2=209920,4B5E41EEF2CD86B36B702CE00F6B8F97F9AA483FC0D91538DF5E2CA421B69E3B,3C65841009FFA5A7C1F05E3555F40759,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\WBEM\WMIAPSRV.EXE FI2=496640,2198A7B58BCCB758036B969DDAE6CC2ECE07565E2659A7C541A313A0492231A3,60FF40CFD7FB8FE41EE4FE9AE5FE1C51,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\WBEM\WMIPRVSE.EXE FI2=243712,65E8FAF81245C08B6668EFB5B7264B2EEBCC90F30F714E1B60C2F7B60AE070C5,E2376F73AAA2A4BBEF5F94DE095C788A,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\WBEM\WMISVC.DLL FI2=1585152,9954394B43783061F9290706320CC65597C29176D5B8E7A26FA1D6B3536832B4,17270A354A66590953C4AAC1CF54E507,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\WBENGINE.EXE FI2=883200,36C5D99C8237CD51B688CC5AFAA724E44C6949B8AF0093DD14663564F8F87B9F,647988450BAB664975432725E3025B68,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\WBIOSRVC.DLL FI2=995840,C8BD074149E697994E2C5BFB57F2EC84FE193AFFE5C66A362196AB000ECE14CD,D56A3E8B6C302F9591A2AC39B6CE285E,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\WCMSVC.DLL FI2=483840,ACBBCBFE7A953F3CFF10A035A52984D7DB0C0B4C6B735F53006036F4CCC15059,6CDE91D497A3EC19796DE53DEBD74FB0,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\WCNCSVC.DLL FI2=105472,4662064205BEC0DB7B10F1412E0A09A6E5E3B16DE443AEF7F79ACA3ACE24A51D,BB37AF6E45E0F69222E057A74B4AFE1E,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\WDI.DLL FI2=259584,F9134058D8C29D0B3A5A340796D155555FEE431B7D6E5A44840CA76E307FCAB2,8750E6E6368665EAA7563892E3AAE69B,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\WDMAUD.DRV FI2=231936,89F67C978A7F58FF1E51CE6DE17FE8FAF64A52A2E96BD188E911517AF1949275,4A81FA6E29A3909FC620EC8B7AE0C8FF,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\WEBCLNT.DLL FI2=205312,B78334BEB2E83564A0775133F517D545B580ED14408D91F6C03A01C8AA8283EF,BDD1061D880EC049CC42E5AED90AF4C6,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\WECSVC.DLL FI2=28672,EF2FEAD68FE003DAC52BC2098962F397DF80B7DCD79A8F45012A050C7C0E2DB1,CBA85827716DE89106F8E4AD7430620C,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\WEPHOSTSVC.DLL FI2=881688,D7F87976C8B2093BDA69AEAE28CE6C932611EC689FB928AD8BA73442F0178E6A,E5B1B09E81FFE2C5F997FC6DCC42A399,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\WER.DLL FI2=127488,A9D569B6B06B2DD4880ED62D2D9520BB10828E0EA65F1ACF9C8C4134611D1C58,0CA02EBDA174768BE1BFA3FB9090448F,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\WERCPLSUPPORT.DLL FI2=228664,8FF10133FA972E400BC6B8A4CE92B55326FEA4F99D1D9EB3331FDAB85289B9ED,9E589E1CC3656DA4013DD6EFFB304CC9,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\WERMGR.EXE FI2=246272,6E6B3A8A9E33CAE73F69B1D2D1543FEE9CDEEE6AC12C52765BA6304D88F06D58,24FD4F8F7BBC74C74D2552E16384FFC3,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\WERSVC.DLL FI2=1886720,89F5F0B8295616E9A147D5178AF4662C003F530CCD35A6D76581A118CEC26F64,3BD227BC792F127915E655E13E57FD20,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\WEVTSVC.DLL FI2=675840,473C61E7F4D734AE9C4BD2E111C6DCE595E9EF167C001CEDC35E53213F2987F6,39B758E2093B9FB42A086BF4BB1B8BEC,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\WFDSCONMGRSVC.DLL FI2=87040,A58CB62992AB846A31E197DF5161F50323D120DF73B7D33FE7D5F5B1AF209291,7AE4D5A054C5EEF9EF9F42926B52FA47,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\WIARPC.DLL FI2=687616,84816CB7033FDEDA560E03995C254577E5BB23E15C7C03FB68074C2E60F31B66,27CCDFB300302826F5CCFF0678F20D80,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\WIASERVC.DLL FI2=132408,88BBB8B8AA5449C9C7415E206EBB508DA779F9D905B7D6BAE41D0C8BF53A6005,DE86CCE40CC4C9C3561772023DD242B1,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\WIFITASK.EXE FI2=885248,F6C48F493F3773018EEA49FCFEC4784FE7BC5F08112970E5CC97F8592D965119,A9E36095EF93FC356922959AB4BFB28F,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\WIN32SPL.DLL FI2=507392,963EB37BBDA94584AC435C585B90D04C4D04CA5BBBD1EA6527DBF1E6181D6DB3,1ABBB4E1B9EDB0C1EDEFC6DF5F82BCD2,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\WINBIOPLUGINS\FACEFODUNINSTALLER.EXE FI2=482816,284C05EEF03BC72B5C2E847B83476328DDDE1063C77E711925F1D1992EC689F9,E028B669FEC9762B5D7D93E5933BBBBA,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\WINDOWS.DEVICES.PICKER.DLL FI2=1020416,0BFFAFA552D4E76A63ECA85EC3C6B9F11E4258ABC014AEF6CB07B95DB63FD1D6,A6B30AB6F0AAD932BB7545E2E582EE6C,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\WINDOWS.INTERNAL.MANAGEMENT.DLL FI2=941568,32160AE072D6652B1B4E04A9AC71B160B6CB5B9FA1F8A8FC7CEA0547946035EA,E516F354E30DB4B8B4B3BF23170BD4B3,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\WINDOWS.MANAGEMENT.SERVICE.DLL FI2=223232,EB0EBAFDE3CBE9DB4BCF8735138BF36E55E9CFE2B7C11C2772776CCB18D9C86C,2EA0380DAB8422E9648FD22AC88C281A,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\WINDOWS.SHAREDPC.ACCOUNTMANAGER.DLL FI2=5858144,777BAEE42BFF1C1EAC599C227D4940C3047071A36B3B5043854D0F88C25AF6C1,23001D13F66F284991D77BC1EA8277FF,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\WINDOWS.STATEREPOSITORY.DLL FI2=249680,1201997C3E05D4C8356B13BE5BCE8F78832D27A3CB91AC42F29FAFC63D25E39C,60D2A220D97920D739864D9BD9CCEE89,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\WINDOWS.STATEREPOSITORYCLIENT.DLL FI2=390464,FEBB8AE767B2E5D305F4AF6A15EA54AEDBF0901DAC925382B387EDA187CF596D,7BC1A26DD9BD33C8849559FD0D2F7239,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\WINDOWS.STORAGE.APPLICATIONDATA.DLL FI2=65536,8FD3B9C72066D6A983D062DE72EEF9769339EACBF4E0D303B9E12343C9D5DE6C,8449398F11D49864117105679B539816,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\WINDOWS.WARP.JITSERVICE.DLL FI2=62464,0C6397BFBCD7B1FCEFB6DE01A506578E36651725A61078C69708F1F92C41EA31,73C523B6556F2DC7EEFC662338D66F8D,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\WINDOWSACTIONDIALOG.EXE FI2=2526,68671808AA3893E2926C2832522538F90B492B64C3305DCE1AF861AFC615D39D,A372FF468587C93E1C4B9CCA886FBBA6,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\WINDOWSPOWERSHELL\V1.0\MODULES\SMBSHARE\DISABLEUNUSEDSMB1.PS1 FI2=452608,9F914D42706FE215501044ACD85A32D58AAEF1419D404FDDFA5D3B48F66CCD9F,04029E121A0CFA5991749937DD22A1D9,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\WINDOWSPOWERSHELL\V1.0\POWERSHELL.EXE FI2=2111488,60226D4829AF8F3077BBA69264F076BA94C1E977B6ECE691D83A0C6918FE3571,EFBDDA16F267167505DB05E69AECF701,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\WINDOWSUDK.SHELLCOMMON.DLL FI2=1087752,5C9E5280B13F27A0516B6ED259306CE2A8A1CF3E9E128FF5FCCC8B9254D7E97B,E21E5B5B1E5D145060A1DAAB8DA1DB12,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\WINHTTP.DLL FI2=419432,268CA325C8F12E68B6728FF24D6536030AAB6E05603D0179033B1E51D8476D86,9EF51C8AD595C5E2A123C06AD39FCCD7,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\WININIT.EXE FI2=907776,6BCB35BA7CDFE08E2C3A2E77CAC9FACC8152A97DF411A4EEC1985D0B09CF6E8C,EE86712DDF0C59E6921D548B5548FF9C,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\WINLOGON.EXE FI2=2809856,CC31FDCDCE05144EF750B01233D57614CDA7364A73CA26FF68886EBDC650E367,715DB53A8064C6DECCF68B7501DF3386,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\WINSAT.EXE FI2=62976,7F2A683F28877562409D810946DDCA2F069715CDFB249602251DFA50065FFF7A,19979E1729CFA0E56EB4CCCB198DFD05,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\WINSRV.DLL FI2=296448,FB5EBB8B33653C3BE1201760847603C0B08F37F0110261DB5DCD7276E9973680,3E00624F5436B0F43C60BB3222E23545,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\WKSSVC.DLL FI2=103424,8456099DEB994F309FDE890E4F0E571A0A67F9B7DD079516905175CD1500FA52,D178119D8DE4E18B05C3DEFB22B6D3CC,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\WLANEXT.EXE FI2=2652160,11A63FA04434E211800276C4D4B4AE70BEE237EB3C425992B211E6E0D58B6947,E67DD68467D50BF91E95A6EC93FA561F,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\WLANSVC.DLL FI2=2242048,1885F8AC0F95A3B891833A07193819894E3F6E00790B51C0E55AA63D57BD3FB0,48AE66A72ECA846D1A0216D4CE2955E6,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\WLIDSVC.DLL FI2=2246480,893DC216AE6D48A5A37FF60D4E62109AAE56CBF3F3EF7299076BF4058AFECE35,06C7A91BC84A2C287F67C7CCFB9D218F,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\WORKFOLDERSSVC.DLL FI2=1867264,478F39B386377BFF2761B432C4261388C170BF0E9603359109A3DADAD63A5F4F,88F1A7D009AACCB326D94AB2CDDC2349,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\WPCDESKTOPMONSVC.DLL FI2=1177624,7EFA00DB7DD75BBF48D7246FCE684B5F0C83C054EAC92774F4AD9D4D1D018D60,3296BC84A6DE10F04739CD8EE44FF932,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\WPCMON.EXE FI2=87040,0744CBBD9F2B867DF456E2B0E113897B654F07E1C96FCB32D4B4B57BE6A3BE81,02876C4F9F4EEC8AC30BBCFFE3447AB6,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\WPDBUSENUM.DLL FI2=85504,ECD704FE62C8920D7AC2B3DC040E9D41D8A6BEBCB457888B411D133635291F36,3D1B4E335BB9CA8A998CD5E1B2EDE855,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\WPNUSERSERVICE.DLL FI2=331312,2BE313764D9830C9B4072A2CF98B4895A66BD83200A350D7ED7C8764AB2316D7,E2BDC4D8D6090ED797FBD39FC097576F,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\WSCSVC.DLL FI2=103424,97C564C604B61DBB13063623A504085E2208EDC8F98AE3B4B02C9623F6002A67,EE63C9957D221991216724CE2B09F33B,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\WSHEXT.DLL FI2=2823168,5E9A4B51B2C9763B51AFBA51A93EACA13570BBC8DF5FC5157B044E72FE160D94,5D698B4D953060214F62E6BB3E1E186E,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\WSMSVC.DLL FI2=114688,B78663AF2C7177CBB51A1CB62219D8737ACC5BD76A0D9C037C949406FF5768CB,78EBE5D865E3618F6275EFC7A54963C9,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\WSQMCONS.EXE FI2=3394048,59A0D89617045C4A53B1083D4612BB898033393937E4F0E316E1760D89E0156D,9C7065E8738C87A3026F72795BDBF0C3,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\WUAUENG.DLL FI2=271872,E6F5DE8BC3FC572D9A2866024C5AF3A83A4D70F4D38810B9E7679A2E9F89775C,8E3F4F1D20179DB86CAF4C7E110DFC18,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\WUDFHOST.EXE FI2=1516544,5A53FE0235681DCF08BC1FCF14BB249095F0A326C3B3D66BC329D0ACD74B7470,B84D258D94782B98774CDC5DAEB3663C,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\WWANSVC.DLL FI2=1049088,DBC40FA04195FC2FAFD404993187E50BF5CA40B7256F3F415AB3AE475A656F49,75EBC3A65D03A7F9395B63AD77C2757B,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\XBLAUTHMANAGER.DLL FI2=1270272,78BBC0FDCBD91394E2C74205568703FD5AEE39C54BA43AA78E95ADE9DC75A8E6,E079354E7F1DEA98C8F1A6AF3F0618C3,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\XBLGAMESAVE.DLL FI2=33792,A6F8B7E0547ACE0D54485AA79FDC4C7C83EE9E363EB30E8E401CB57B4494619A,B3D4334C3207386D47C8B5E0C21210F6,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\XBLGAMESAVETASK.EXE FI2=72704,ACC3A8180601054BFD8FBE743A7F9CB5F2398FD463FD7EA5EF2EF78953BADBBD,04BE9428D1E276DF3F6A7A5552AAB546,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\XBOXGIPSVC.DLL FI2=1295360,8BB5D0ABF6DF5E48F17480AE72D568EBBF59E2D69E359AD951970A5BF35BFDD8,5A4F5B800B1AE1B196D3D09D1E973C9F,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\XBOXNETAPISVC.DLL FI2=452608,F6DF46869F1CBE945DC2C3B7C284150CB0B01548CCD1E8CEC3F6F00FA4702BEA,D7A835246FF39FC8FA607BB028FBDC12,1,"Microsoft Windows",C:\WINDOWS\SYSTEM32\XWIZARDS.DLL FI2=3403576,24F4282C6898DD4B85D4FAFA52014362CBEFF81F1EA433F2BA44717F2D6F1656,A2E28A0B40A5FB362B6B33612B76E8AF,1,"Microsoft Windows",C:\WINDOWS\SYSTEMAPPS\MICROSOFT.WINDOWS.SEARCH_CW5N1H2TXYEWY\SEARCHAPP.EXE FI2=793416,03F57900A9324DF23DA95A46F58245649B0357F065B7F4128E387507CE9582E6,6AECA53F405206CAD08032B2FE2423D7,1,"Microsoft Windows",C:\WINDOWS\SYSTEMAPPS\MICROSOFT.WINDOWS.STARTMENUEXPERIENCEHOST_CW5N1H2TXYEWY\STARTMENUEXPERIENCEHOST.EXE FI2=18168,791202D8DA61BF6527EB8008DD16297DA1C64CC01BEDCEFCCB5FD4004493CACF,AABF7EF96B7C99430E0247FBB91971C1,1,"Microsoft Windows",C:\WINDOWS\SYSTEMAPPS\MICROSOFTWINDOWS.CLIENT.CBS_CW5N1H2TXYEWY\INPUTAPP\TEXTINPUTHOST.EXE FI2=714752,0C66111CF2BF9F3E9C82D173D7BAF2FB233F14E9CE372E4C78A76B7C07CF376B,D963F54FB4D483EB0809CF5359305DE9,1,"Microsoft Windows",C:\WINDOWS\SYSWOW64\D3D8.DLL FI2=588288,9626BC3509C5A445605DD25CA13707F789AA5AEF987BB9AEA8416BD533CF4606,FC2A488D91040FF1F0471801D78B7E34,1,"Microsoft Windows",C:\WINDOWS\SYSWOW64\DNSAPI.DLL FI2=84992,C11795A6125FEA7B279C4B0B53C344E179100C51797A8F1F7085500120BD7773,FDB9B9D303BDC92D8DDD7CE090B3960B,1,"Microsoft Windows",C:\WINDOWS\SYSWOW64\ICCVID.DLL FI2=292848,A81A6625CC6BEA439E9654E1142061B6E4CC7AF6D83E09547D956B8C4FA411DB,C248D1CD850BDB079AE0B9774FA2EE79,1,"Microsoft Windows",C:\WINDOWS\SYSWOW64\INTELCPHECISVC.EXE FI2=69120,60A8D7341215E5A83FCCE9000F9269BC0B3EEE10591DB62E299D3D1EEF5C85BE,A86E96179821A3088E57D5B138F64C53,1,"Microsoft Windows",C:\WINDOWS\SYSWOW64\L3CODECA.ACM FI2=1436032,898288BD3B21D0E7D5F406DF2E0B69A5BBFA4F241BAF29A2CDF8A3CF4D4619F2,25F62C02619174B35851B0E0455B3D94,1,"Microsoft Windows",C:\WINDOWS\SYSWOW64\MSVBVM60.DLL FI2=324416,D0A0FA22428119878FBB3D451FFFDD21602C9196FFE5EFB989F44816D3280C6E,32ACBB4A0F2EB31E8E69AEF3CBCD8B73,1,"Microsoft Windows",C:\WINDOWS\SYSWOW64\MSWSOCK.DLL FI2=54784,BD79D40AEFCDDE1F962590EAD0DEB71620442FD47FC65DBAE21625E603D47ABA,84164976D5F384E872D8E88D1B1C4802,1,"Microsoft Windows",C:\WINDOWS\SYSWOW64\NAPINSP.DLL FI2=71168,B325CCE02C70CD7A4D296F0BA88C9F0AF4942276BCB1F215B1AF625FB0536AB4,A8C60D96FFD9A90C03B9AB33F3E719A9,1,"Microsoft Windows",C:\WINDOWS\SYSWOW64\NLAAPI.DLL FI2=88576,36EBB5C7C10FB1D140C72DDBA5A11778D33DF771A81F87BD5B649B92A496D363,C6575E5E95754390A7CE8BE0A66A3735,1,"Microsoft Windows",C:\WINDOWS\SYSWOW64\OLEPRO32.DLL FI2=21504,41D7DA706F0CF613DF768B6795CD09C5C1035F9F101051FB58F5042EB4352DB6,2FC7CFCEDBF7E038351C7CEB1036D2E1,1,"Microsoft Windows",C:\WINDOWS\SYSWOW64\PERFHOST.EXE FI2=70656,A3BB65262B6A2643AB538FF1A953764AB0FF7870387CFD3CF32F0B3FA92A9E5B,C71D4893EDE8FCE255CDBC518FEDB4E7,1,"Microsoft Windows",C:\WINDOWS\SYSWOW64\PNRPNSP.DLL FI2=247296,746F4CCFD2752BC9E741977772647E00E63C340C57599008D6E900A24E40AD50,03944ABAE856DC164BD167526E07E953,2,,C:\WINDOWS\SYSWOW64\RTVCVFW32.DLL FI2=34304,0E4C139F6F7A4AC6826CD6204B49336476544F57267FCA89D24954B2ED336AA8,3C568EA1CDA978943DCA7AB304FC7581,1,"Microsoft Windows",C:\WINDOWS\SYSWOW64\WINRNR.DLL FI2=50688,F82D2D0D51428D07B08856F0BBD819366A8356AA08AC6A89104C4A4EB12251C1,20052F9B72217B3962E4B520C7D122B3,1,"Microsoft Windows",C:\WINDOWS\SYSWOW64\WSHBTH.DLL FI2=1956256,DAABB3AEF3BA7BB5EF598F7C755CA417844622954A3D7128A3DBD0A5A40474F8,4B24D6DD32482D252DD61F856C719531,1,"Microsoft Corporation",C:\WINDOWS10UPGRADE\WINDOWS10UPGRADERAPP.EXE FI2=22798336,D2E6AC61766076C995E22FCCC172AED97CDF924E34E4FCADF3C6F7A439B1B752,861D83FB0BFD2DFE4B9360C544318F41,2,,D:\GAMES\DRAGON BALL XENOVERSE 2\BIN\DBXV2.EXE FI2=4512256,D15721785E28047AC8C15AB5C644D51441FF9C128930DE1370D3430ABF948635,E022D25234E7664BD64900DD454F15EA,2,,D:\MODDING\MO2\MODORGANIZER.EXE FI2=71224320,CF56EDEFA41DB11FAB5C081E003BE59AA0AC577D2ED038D05E9C13116EE8AA3B,A14DBDD42D10013C63BE1B616E5BF677,2,,D:\OCULUS\SUPPORT\OCULUS-CLIENT\OCULUSCLIENT.EXE FI2=144632,9D746000E0187AA47727BED089A5BE461CC07F9782303DE247F7E0F25A2452AE,C4CD896EF27565CCFC3A070CAE90E28E,1,"Oculus VR, LLC",D:\OCULUS\SUPPORT\OCULUS-LIBRARIAN\OVRLIBRARYSERVICE.EXE FI2=1186552,497F6C107D4FFB353A9DB1EB7D18919D388AE6A6E876F2438A01CE6D75C25B00,F44B0D884ACB49DFD3516656836DB221,1,"Oculus VR, LLC",D:\OCULUS\SUPPORT\OCULUS-RUNTIME\OVRREDIR.EXE FI2=9302264,7BAE1FEB5FF98C2009CD1E25C64044CF6C5D19855A36A9F94ACF255F7A47A335,9B2E26D23D44C1D94C982F53A0B06F2C,1,"Oculus VR, LLC",D:\OCULUS\SUPPORT\OCULUS-RUNTIME\OVRSERVER_X64.EXE FI2=511736,59876F8FEF5BD25132F94061276A565F8B28466A8C5366F90B36828B0AAD1FCB,1B054646C036BE26759EBF065AA3CC53,1,"Oculus VR, LLC",D:\OCULUS\SUPPORT\OCULUS-RUNTIME\OVRSERVICELAUNCHER.EXE FI2=2786272,DF445A3D96FB95973B9D52D46B23DF293FD5841A3DB742B6B28248E4E032FB2F,8AB6030EBC9A5111229FFBD7C07E0772,1,"Epic Games Inc.",D:\PROGRAM FILES (X86)\EPIC GAMES\LAUNCHER\PORTAL\BINARIES\WIN32\EPICGAMESLAUNCHER.EXE FI2=65969872,875A9A3FB50A0C41D8BB20848977106498DF1FFA8B4F7D5FEDA01F6F346C307A,A23C24CFAF891C248315D06B6E19C56D,2,,D:\PROGRAM FILES (X86)\FALLOUT 4 VR\FALLOUT4VR.EXE FI2=2827776,F2AA2B021BFFC2C8FE92CE94EC386F5300B792F8F3670A2E6F761EFD99ADF181,BB2C0D6845257F10155ADA43E1201B4D,2,,D:\PROGRAM FILES (X86)\GEEKS3D\BENCHMARKS\FURMARK\FURMARK.EXE FI2=15291232,467931615F4D8D386BB676727A4CB78CA2B843C4ED6A1A8B7F7F38E0C6A71DF1,30CA7D59800B7FD483B945336F3A1773,1,"Greatis Software LLC",D:\PROGRAM FILES (X86)\GREATIS\REANIMATOR\REANIMATOR.EXE FI2=1967104,FFA374C3DB6A46780F957A75B973B75C175038642950E19959A33D2F498F6539,A58CB992766247AD76039F55927238D2,2,,D:\PROGRAM FILES (X86)\LOOT\LOOT.EXE FI2=730344,F2F035E71766C571B1A1DC4ED0503B17C6679954961EB8839DCCE02D76FBDB33,FEA1961D173EFBE36A5D01301EB78B05,1,"BioWare",D:\PROGRAM FILES (X86)\MASS EFFECT ULTIMATE EDITION\MASSEFFECTLAUNCHER.EXE FI2=792120,9649118D0CCCA3E8C81451286FF9C023861DAEA45DA2780D920DEB6195BE44C4,A287435C3F55CB23D4EDEC4619A9F42C,1,"MICRO-STAR INTERNATIONAL CO., LTD.",D:\PROGRAM FILES (X86)\MSI AFTERBURNER\MSIAFTERBURNER.EXE FI2=36824,F1C8CA232789C2F11A511C8CD95A9F3830DD719CAD5AA22CB7C3539AB8CB4DC3,0A2EC9E3E236698185978A5FC76E74E6,1,"MICRO-STAR INTERNATIONAL CO., LTD.",D:\PROGRAM FILES (X86)\MSI AFTERBURNER\RTCORE64.SYS FI2=35530960,745D4ABDD0D0D361CAF6079C3798C57EA19511E3F13CD3EA5F4F478D9089A3B1,0B79A6818CE0C60681FCD8363EB8BF0C,2,,D:\PROGRAM FILES (X86)\THE ELDER SCROLLS V SKYRIM VR\SKYRIMVR.EXE FI2=448512,E286B426C996DF0AEEFE0EB2639FA52CCFA72D5D630E6878FE75AB21C0F4BAC6,6422694FA00C11A4FD4D9BB4C01616C5,2,,D:\PROGRAM FILES\HOME SWEET HOME\HOMESWEETHOME.EXE FI2=205984,E54D28C3854703D81B7E160867D9B8E13C355C7BB71FDDCDB1DBA51C103F7384,1C5E4F113A5D54AF5FAE9626DFB670BE,1,"Rockstar Games, Inc.",D:\PROGRAM FILES\ROCKSTAR GAMES\GRAND THEFT AUTO V\PLAYGTAV.EXE FI2=507288,06FEFA489BB4F669FC5369561EF9B91D899148745CCB57880820714B3EB52826,26F750B2E3CF6ED3B74DD43CC02EB0D8,1,"Rockstar Games, Inc.",D:\PROGRAM FILES\ROCKSTAR GAMES\LAUNCHER\LAUNCHERPATCHER.EXE FI2=2219416,468EE6653FCF0D7EE8CB0BECEB70625BA4B22DF0A7BCD32CEF317146F6D61565,D8ADA01249EDA224063FC7D889B097F9,1,"Rockstar Games, Inc.",D:\PROGRAM FILES\ROCKSTAR GAMES\LAUNCHER\ROCKSTARSERVICE.EXE FI2=87348120,A1F9B3D424FF72791CB048CCCE5AE131EF96A6E9FF771E5033C43537EA9BE3E4,FCB68B6DBA506D3CC42421F0F9D0EE74,1,"Rockstar Games, Inc.",D:\PROGRAM FILES\ROCKSTAR GAMES\RED DEAD REDEMPTION 2\RDR2.EXE FI2=1116440,A33A27CEA3A768D74D8B8D7D711016C1B6C65A0900AAD47D0C73E8DBC29D86B1,14B0989F5F3D3EAD4828242568A4DE00,1,"Virtual Desktop, Inc.",D:\PROGRAM FILES\VIRTUAL DESKTOP STREAMER\UPDATER.EXE FI2=132376,F79960EE77FA652DFA1A053D6CBC445C1F39B1B4E9BF1759138C97C4638B0FDD,FF50ECDF82671D3EF8713CDE751E79DF,1,"Virtual Desktop, Inc.",D:\PROGRAM FILES\VIRTUAL DESKTOP STREAMER\VIRTUALDESKTOP.INJECTOR64.DLL FI2=4109032,1BAA41599C508A95A530E8F1D7C5B5B1AA01231FFAB38681DC48898F0F8F2CE4,E2A6C4989779D2B5DABE624F4DC24A0A,1,"Valve",D:\STEAM\STEAM.EXE FI2=520288,607DCE4B0DF2878155C7C34AB5C8DAEF87536C82227C9CA8E9CC397C084A2069,DA3C164CF89441620E470DC657FDF318,1,"Skutta, Kristjan",D:\STEAMLIBRARY\STEAMAPPS\COMMON\WALLPAPER_ENGINE\BIN\WALLPAPERSERVICE32_C.EXE FI2=-1,,,0,,G:\1F7FCE1C581552A6E22287131DFDF12C\DW\DW20.EXE FI2=-1,,,0,,I:\CCLEANER\CCLEANER.EXE FI2=-1,,,0,,I:\CCLEANER\CCUPDATE.EXE === [MBR] [MD5=6F5C728704818D7DC62499B0E441E6D3] AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAA= === [PT] 0xee Unknown, 1, -1 === [VBR] 61iQTVNET1M1LjAAAgL+GQIAAAAA+AAAPwD/AAAIAAAAIAMAAQMAAAAAAAACAAAAAQAGAAAA AAAAAAAAAAAAAIAAKSILjPJOTyBOQU1FICAgIEZBVDMyICAgM8mO0bz0e47Bjtm9AHyIVkCI TgKKVkC0QbuqVc0TchCB+1WqdQr2wQF0Bf5GAustilZAtAjNE3MFuf//ivFmD7bGQGYPttGA 4j/34obNwO0GQWYPt8lm9+FmiUb4g34WAHU5g34qAHczZotGHGaDwAy7AIC5AQDoLADpqAOh +H2AxHyL8KyEwHQXPP90CbQOuwcAzRDr7qH6fevkoX2A69+YzRbNGWZggH4CAA+EIABmagBm UAZTZmgQAAEAtEKKVkCL9M0TZlhmWGZYZljrM2Y7RvhyA/nrKmYz0mYPt04YZvfx/sKKymaL 0GbB6hD3dhqG1opWQIrowOQGCsy4AQLNE2ZhD4J0/4HDAAJmQEl1lMNCT09UTUdSICAgIAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAANCkVy ci4gZGlzcXVl/w0KUHJlc3NleiB1bmUgdG91Y2hlIHBvdXIgcmVkgm1hcnJlcg0KAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAArAG6AQAAVapSUmFBAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAcnJBYQIWAQB6cAAAAAAAAAAAAAAAAAAAAABVqgAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAFWqAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA61iQTVNE T1M1LjAAAgL+GQIAAAAA+AAAPwD/AAAIAAAAIAMAAQMAAAAAAAACAAAAAQAGAAAAAAAAAAAA AAAAAIAAKSILjPJOTyBOQU1FICAgIEZBVDMyICAgM8mO0bz0e47Bjtm9AHyIVkCITgKKVkC0 QbuqVc0TchCB+1WqdQr2wQF0Bf5GAustilZAtAjNE3MFuf//ivFmD7bGQGYPttGA4j/34obN wO0GQWYPt8lm9+FmiUb4g34WAHU5g34qAHczZotGHGaDwAy7AIC5AQDoLADpqAOh+H2AxHyL 8KyEwHQXPP90CbQOuwcAzRDr7qH6fevkoX2A69+YzRbNGWZggH4CAA+EIABmagBmUAZTZmgQ AAEAtEKKVkCL9M0TZlhmWGZYZljrM2Y7RvhyA/nrKmYz0mYPt04YZvfx/sKKymaL0GbB6hD3 dhqG1opWQIrowOQGCsy4AQLNE2ZhD4J0/4HDAAJmQEl1lMNCT09UTUdSICAgIAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAANCkVyci4gZGlz cXVl/w0KUHJlc3NleiB1bmUgdG91Y2hlIHBvdXIgcmVkgm1hcnJlcg0KAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAArAG6AQAAVapSUmFBAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAcnJBYf////8CAAAAAAAAAAAAAAAAAAAAAABVqgAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAFWq === [STAT]u\\UkVBTg-- ===