ESET SystemStatus log, versions: ev 1236 (20130614), gv ESI 1.2.042.0, lv 1.0 Session start: 15 Oct 2014, 19:50:18 Session end: 15 Oct 2014, 19:55:18 Flags: 64bit Description: SysInspector-HP-141015-1950full 01) Running processes: - system *0,263A* - system *4,263A* - c:\windows\system32\smss.exe *308,F99D* - c:\windows\system32\csrss.exe *496,A7D9* - c:\windows\system32\wininit.exe *592,64EC* - c:\windows\system32\csrss.exe *608,A7D9* - c:\windows\system32\winlogon.exe *636,3746* - c:\windows\system32\services.exe *696,B9DC* - c:\windows\system32\lsass.exe *708,B17A* - c:\windows\system32\svchost.exe *768,2392* - c:\windows\system32\svchost.exe *800,EE22* - c:\windows\system32\dwm.exe *900,10A9* - c:\program files\bitdefender\bitdefender\vsserv.exe *908,9F5* - c:\windows\system32\atiesrxx.exe *864,239B* - c:\windows\system32\svchost.exe *1032,C97E* - c:\windows\system32\svchost.exe *1060,AB40* - c:\windows\system32\svchost.exe *1104,80D7* - c:\windows\system32\atieclxx.exe *1152,2526* - c:\windows\system32\svchost.exe *1164,7478* - c:\windows\system32\svchost.exe *1320,8F31* - c:\windows\system32\spoolsv.exe *1540,B1AD* - c:\windows\system32\svchost.exe *1612,9B8B* - c:\program files (x86)\hp\common\hpsupportsolutionsframeworkservice.exe *1712,5819* - c:\program files\intel\icls client\heciserver.exe *1868,710* - c:\program files (x86)\intel\intel(r) management engine components\dal\jhi_service.exe *1896,11A3* - c:\program files (x86)\secunia\psi\psia.exe *1964,1C53* - c:\program files\shield\shdserv.exe *2012,2E99* - c:\program files\bitdefender\bitdefender\updatesrv.exe *1280,EA8E* - c:\program files\shield\shieldclnt.exe *1704,CE12* - c:\windows\system32\svchost.exe *2252,5015* - c:\windows\system32\taskhostex.exe *2552,AA0A* - c:\windows\explorer.exe *2652,C836* - c:\windows\system32\svchost.exe *1276,E4E5* - c:\windows\system32\searchindexer.exe *2704,F876* - c:\windows\system32\igfxtray.exe *2692,C09A* - c:\windows\system32\hkcmd.exe *2092,FC3E* - c:\windows\system32\igfxpers.exe *1600,BE2A* - c:\program files\synaptics\syntp\syntpenh.exe *3096,CD17* - c:\program files\bitdefender\bitdefender\bdagent.exe *3192,742* - c:\program files\shield\shdtray.exe *3200,4245* - c:\program files\bitdefender\bitdefender\pmbxag.exe *3216,777F* - c:\program files\synaptics\syntp\syntphelper.exe *3260,4C64* - c:\program files\bitdefender\bitdefender\antispam32\bdapppassmgr.exe *3380,A826* - c:\windows\system32\wwahost.exe *3932,8852* - c:\program files (x86)\intel\intel(r) management engine components\fwservice\intelmefwservice.exe *3984,DEA3* - c:\program files (x86)\intel\intel(r) management engine components\lms\lms.exe *4008,4B2* - c:\windows\system32\runtimebroker.exe *4068,61A2* - c:\program files (x86)\intel\intel(r) management engine components\uns\uns.exe *3332,892F* - c:\users\hp_home\desktop\nowy folder\firefoxportable\firefoxportable.exe *896,97F3* - c:\users\hp_home\desktop\nowy folder\firefoxportable\app\firefox\firefox.exe *1268,2DFB* - c:\windows\microsoft.net\framework64\v3.0\wpf\presentationfontcache.exe *4092,C18C* - c:\program files (x86)\xirrus\xirrus wi-fi inspector\xirrus wi-fi inspector.exe *4796,DD36* - c:\program files (x86)\secunia\psi\sua.exe *1572,2936* - c:\windows\system32\searchprotocolhost.exe *2132,AD96* - c:\windows\system32\searchfilterhost.exe *4500,FA91* - c:\windows\system32\dllhost.exe *120,E428* - c:\windows\system32\audiodg.exe *3768,8ADF* - c:\windows\system32\dllhost.exe *3636,4E0C* - c:\windows\system32\dllhost.exe *2336,45F9* - c:\users\hp_home\desktop\sysinspector.com.exe *2232,B56D* 02) Loaded modules: - system - c:\windows\system32\ntdll.dll - c:\windows\system32\kernel32.dll - c:\windows\system32\kernelbase.dll - c:\windows\system32\msvcrt.dll - c:\windows\system32\rpcrt4.dll - c:\windows\system32\sechost.dll - c:\windows\system32\profapi.dll - c:\windows\system32\wininitext.dll - c:\windows\system32\user32.dll - c:\windows\system32\gdi32.dll - c:\windows\system32\ws2_32.dll - c:\windows\system32\nsi.dll - c:\windows\system32\mswsock.dll - c:\windows\system32\sspicli.dll - c:\windows\system32\advapi32.dll - c:\windows\system32\powrprof.dll - c:\windows\system32\winlogonext.dll - c:\windows\system32\imm32.dll - c:\windows\system32\msctf.dll - c:\windows\system32\winsta.dll - c:\windows\system32\uxinit.dll - c:\windows\system32\uxtheme.dll - c:\windows\system32\combase.dll - c:\windows\system32\crypt32.dll - c:\windows\system32\msasn1.dll - c:\windows\system32\dpapi.dll - c:\windows\system32\cryptbase.dll - c:\windows\system32\bcryptprimitives.dll - c:\windows\system32\apphelp.dll - c:\windows\system32\ntmarta.dll - c:\windows\system32\mpr.dll - c:\windows\system32\sspisrv.dll - c:\windows\system32\lsasrv.dll - c:\windows\system32\cfgmgr32.dll - c:\windows\system32\samsrv.dll - c:\windows\system32\bcrypt.dll - c:\windows\system32\ncrypt.dll - c:\windows\system32\ntasn1.dll - c:\windows\system32\msprivs.dll - c:\windows\system32\netjoin.dll - c:\windows\system32\negoexts.dll - c:\windows\system32\cryptdll.dll - c:\windows\system32\kerberos.dll - c:\windows\system32\cryptsp.dll - c:\windows\system32\msv1_0.dll - c:\windows\system32\netlogon.dll - c:\windows\system32\dnsapi.dll - c:\windows\system32\logoncli.dll - c:\windows\system32\userenv.dll - c:\windows\system32\tspkg.dll - c:\windows\system32\pku2u.dll - c:\windows\system32\livessp.dll - c:\windows\system32\rsaenh.dll - c:\windows\system32\wdigest.dll - c:\windows\system32\schannel.dll - c:\windows\system32\efslsaext.dll - c:\windows\system32\dpapisrv.dll - c:\windows\system32\scecli.dll - c:\windows\system32\netutils.dll - c:\windows\system32\wevtapi.dll - c:\windows\system32\ncryptsslp.dll - c:\windows\system32\ncryptprov.dll - c:\windows\system32\dssenh.dll - c:\windows\system32\gpapi.dll - c:\windows\system32\iphlpapi.dll - c:\windows\system32\winnsi.dll - c:\windows\system32\wkscli.dll - c:\windows\system32\fveapi.dll - c:\windows\system32\bcd.dll - c:\windows\system32\fvecerts.dll - c:\windows\system32\keyiso.dll - c:\windows\system32\authz.dll - c:\windows\system32\vaultsvc.dll - c:\windows\system32\secur32.dll - c:\windows\system32\wldap32.dll - c:\windows\system32\umpnpmgr.dll - c:\windows\system32\umpo.dll - c:\windows\system32\umpoext.dll - c:\windows\system32\pcwum.dll - c:\windows\system32\hid.dll - c:\windows\system32\rpcss.dll - c:\windows\system32\bisrv.dll - c:\windows\system32\oleaut32.dll - c:\windows\system32\psmsrv.dll - c:\windows\system32\lsm.dll - c:\windows\system32\sysntfy.dll - c:\windows\system32\wmsgapi.dll - c:\windows\system32\devobj.dll - c:\windows\system32\kernel.appcore.dll - c:\windows\system32\systemeventsbrokerserver.dll - c:\windows\system32\bi.dll - c:\windows\system32\dab.dll - c:\windows\system32\clbcatq.dll - c:\windows\system32\wtsapi32.dll - c:\windows\system32\actxprxy.dll - c:\windows\system32\twinapi.dll - c:\windows\system32\shcore.dll - c:\windows\system32\rpcepmap.dll - c:\windows\system32\rpcrtremote.dll - c:\windows\system32\firewallapi.dll - c:\windows\system32\fwpuclnt.dll - c:\windows\system32\dwmredir.dll - c:\windows\system32\dwmcore.dll - c:\windows\system32\dcomp.dll - c:\windows\system32\windowscodecs.dll - c:\windows\system32\wmiclnt.dll - c:\windows\system32\d3d11.dll - c:\windows\system32\dxgi.dll - c:\windows\system32\avrt.dll - c:\windows\system32\aticfx64.dll - c:\windows\system32\version.dll - c:\windows\system32\atiuxp64.dll - c:\windows\system32\igd10umd64.dll - c:\windows\system32\atidxx64.dll - c:\windows\system32\udwm.dll - c:\windows\system32\uianimation.dll - c:\windows\system32\d2d1.dll - c:\windows\system32\xmllite.dll - c:\windows\system32\d3d10warp.dll - c:\program files\bitdefender\bitdefender\txmlutil.dll - c:\windows\system32\shell32.dll - c:\windows\system32\ole32.dll - c:\windows\system32\shlwapi.dll - c:\windows\system32\msvcp100.dll - c:\windows\system32\winmm.dll - c:\windows\system32\msvcr100.dll - c:\windows\system32\winmmbase.dll - c:\program files\bitdefender\bitdefender\log.dll - c:\program files\bitdefender\bitdefender\strdecoder.dll - c:\program files\bitdefender\bitdefender\iservconfig.dll - c:\program files\bitdefender\bitdefender\bdch.dll - c:\program files\bitdefender\bitdefender\dbghelp.dll - c:\windows\system32\psapi.dll - c:\program files\bitdefender\bitdefender\watchdog.dll - c:\program files\bitdefender\bitdefender\npcomm.dll - c:\program files\bitdefender\bitdefender\ui\vsserv.ui - c:\program files\bitdefender\bitdefender\ui\logger.ui - c:\program files\bitdefender\bitdefender\framework.dll - c:\program files\bitdefender\bitdefender\settings.dll - c:\program files\bitdefender\bitdefender\sfal.dll - c:\program files\bitdefender\bitdefender\gzfltdp.dll - c:\program files\bitdefender\bitdefender\gzfltum.dll - c:\windows\system32\fltlib.dll - c:\program files\bitdefender\bitdefender\procinfo.dll - c:\program files\bitdefender\bitdefender\bdutils.dll - c:\program files\bitdefender\bitdefender\accessal.dll - c:\program files\bitdefender\bitdefender\scansp.dll - c:\program files\common files\bitdefender\bitdefender threat scanner\bdsmartdb.dll - c:\program files\bitdefender\bitdefender\modernuiapprem.dll - c:\program files\common files\bitdefender\bitdefender threat scanner\scan.dll - c:\program files\bitdefender\bitdefender\bdsubmit.dll - c:\windows\system32\wininet.dll - c:\windows\system32\iertutil.dll - c:\program files\bitdefender\bitdefender\quarcore.dll - \\?\c:\program files\common files\bitdefender\bitdefender threat scanner\trufos.dll - c:\program files\bitdefender\bitdefender\wslib.dll - c:\program files\bitdefender\bitdefender\wsutils.dll - c:\program files\bitdefender\bitdefender\wspack.dll - c:\windows\system32\netapi32.dll - c:\windows\system32\srvcli.dll - c:\windows\system32\winhttp.dll - \\?\c:\program files\bitdefender\bitdefender\bdnc.dll - c:\windows\system32\dhcpcsvc6.dll - c:\windows\system32\wintrust.dll - c:\windows\system32\dhcpcsvc.dll - c:\program files\bitdefender\bitdefender\apprep.dll - c:\program files\bitdefender\bitdefender\avcal.dll - c:\program files\bitdefender\bitdefender\avccore.dll - c:\program files\bitdefender\bitdefender\avcbd64.dll - c:\program files\bitdefender\bitdefender\smartcachesp.dll - c:\program files\bitdefender\bitdefender\accessl.dll - c:\program files\bitdefender\bitdefender\excludemgr.dll - c:\program files\bitdefender\bitdefender\regal.dll - c:\program files\bitdefender\bitdefender\langmgr.dll - c:\program files\bitdefender\bitdefender\ui\accessl.ui - c:\program files\bitdefender\bitdefender\fwal.dll - c:\program files\bitdefender\bitdefender\producttweaks.dll - c:\windows\system32\setupapi.dll - c:\program files\bitdefender\bitdefender\connector.dll - c:\program files\bitdefender\bitdefender\bdmltusrsrv.dll - c:\program files\bitdefender\bitdefender\loggeral.dll - c:\program files\bitdefender\bitdefender\sqlite3.dll - c:\program files\bitdefender\bitdefender\bdfirewallsdk.dll - c:\program files\bitdefender\bitdefender\bdfwcore.dll - c:\windows\system32\netprofm.dll - c:\windows\system32\wlanapi.dll - c:\program files\bitdefender\bitdefender\netscanal.dll - c:\program files\bitdefender\bitdefender\emaildp.dll - c:\program files\bitdefender\bitdefender\bdpop3p.dll - c:\program files\bitdefender\bitdefender\bdpredir_ssl.dll - c:\windows\system32\httpapi.dll - c:\program files\bitdefender\bitdefender\libeay32.dll - c:\program files\bitdefender\bitdefender\ssleay32.dll - c:\program files\bitdefender\bitdefender\bdpredir.dll - c:\program files\bitdefender\bitdefender\mimepack.dll - c:\program files\bitdefender\bitdefender\bdsmtpp.dll - c:\program files\bitdefender\bitdefender\wsc.dll - c:\program files\bitdefender\bitdefender\ui\wsc.ui - c:\program files\bitdefender\bitdefender\bdquar.dll - c:\program files\bitdefender\bitdefender\ondemandal.dll - c:\program files\bitdefender\bitdefender\bdaphsp.dll - c:\windows\system32\samcli.dll - c:\windows\system32\samlib.dll - c:\program files\bitdefender\bitdefender\updatecomm.dll - c:\program files\bitdefender\bitdefender\bdassp.dll - c:\program files\bitdefender\bitdefender\bdcloud.dll - c:\program files\bitdefender\bitdefender\bdtl.dll - c:\program files\bitdefender\bitdefender\netdefendervs10xu.dll - c:\program files\bitdefender\bitdefender\nxbasevs10xu.dll - c:\program files\bitdefender\bitdefender\nxsysvs10xu.dll - c:\program files\bitdefender\bitdefender\nxstringvs10xu.dll - c:\program files\bitdefender\bitdefender\nxxmlvs10xu.dll - c:\program files\bitdefender\bitdefender\nxvfsvs10xu.dll - c:\program files\bitdefender\bitdefender\nxlogvs10xu.dll - c:\program files\bitdefender\bitdefender\ui\bdtl.tmp - c:\program files\bitdefender\bitdefender\httpvs10xu.dll - c:\program files\bitdefender\bitdefender\nxnetvs10xu.dll - c:\program files\bitdefender\bitdefender\nxcryptvs10xu.dll - c:\program files\bitdefender\bitdefender\nxnosqldbvs10xu.dll - c:\program files\bitdefender\bitdefender\gzipvs10xu.http.dll - c:\program files\bitdefender\bitdefender\nxzipvs10xu.dll - c:\program files\bitdefender\bitdefender\nxfidvs10xu.dll - c:\program files\bitdefender\bitdefender\deflatevs10xu.http.dll - c:\program files\bitdefender\bitdefender\zlibvs10xu.http.dll - c:\program files\bitdefender\bitdefender\chunkedvs10xu.http.dll - c:\program files\bitdefender\bitdefender\alertvs10xu.http.dll - c:\program files\bitdefender\bitdefender\amvs10xu.http.dll - c:\program files\bitdefender\bitdefender\aphvs10xu.http.dll - c:\program files\bitdefender\bitdefender\cloudvs10xu.http.dll - c:\program files\bitdefender\bitdefender\htmlvs10xu.http.dll - c:\program files\bitdefender\bitdefender\nxhtmlvs10xu.dll - c:\program files\bitdefender\bitdefender\huivs10xu.http.dll - c:\program files\bitdefender\bitdefender\lsvs10xu.http.dll - c:\program files\bitdefender\bitdefender\resourcevs10xu.http.dll - c:\program files\bitdefender\bitdefender\wbvs10xu.http.dll - c:\program files\bitdefender\bitdefender\wfvs10xu.http.dll - c:\program files\bitdefender\bitdefender\settingsvs10xu.http.dll - c:\program files\bitdefender\bitdefender\privacyvs10xu.http.dll - c:\program files\bitdefender\bitdefender\bdsafego.dll - c:\program files\bitdefender\bitdefender\idwatchdogal.dll - c:\program files\bitdefender\bitdefender\sabal.dll - c:\program files\bitdefender\bitdefender\updateeventsal.dll - c:\program files\bitdefender\bitdefender\vulnerabilityal.dll - c:\program files\bitdefender\bitdefender\bdelev.dll - c:\program files\bitdefender\bitdefender\bdusers.dll - c:\program files\bitdefender\bitdefender\serverpush.dll - c:\program files\bitdefender\bitdefender\remotemanagemental.dll - c:\windows\system32\wbem\wbemprox.dll - c:\windows\system32\wbemcomn.dll - c:\program files\bitdefender\bitdefender\issues.dll - c:\program files\bitdefender\bitdefender\parentalcontrolstatus.dll - c:\program files\bitdefender\bitdefender\safebootal.dll - c:\windows\winsxs\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.8387_none_08e793bfa83a89b5\msvcp90.dll - c:\windows\winsxs\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.8387_none_08e793bfa83a89b5\msvcr90.dll - c:\program files\bitdefender\bitdefender\securityreport.dll - c:\program files\bitdefender\bitdefender\bssettingsal.dll - c:\windows\system32\mfc100u.dll - c:\windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.9600.16384_none_34a8918f959016ea\comctl32.dll - c:\windows\system32\msimg32.dll - c:\windows\system32\dwmapi.dll - c:\program files\bitdefender\bitdefender\perfal.dll - c:\program files\bitdefender\bitdefender\loadusage.dll - c:\windows\system32\wuapi.dll - c:\windows\system32\cabinet.dll - c:\program files\bitdefender\bitdefender\avccom.dll - c:\program files\bitdefender\bitdefender\ipm.dll - c:\program files\bitdefender\bitdefender\imsecurityal.dll - c:\program files\bitdefender\bitdefender\ymdp.dll - c:\program files\bitdefender\bitdefender\ycryptp.dll - c:\program files\bitdefender\bitdefender\ui\imsecurityal.ui - c:\program files\bitdefender\bitdefender\eventlistener.dll - c:\program files\bitdefender\bitdefender\privscan_old.dll - c:\windows\system32\mlang.dll - c:\windows\system32\napinsp.dll - c:\windows\system32\pnrpnsp.dll - c:\windows\system32\nlaapi.dll - c:\windows\system32\winrnr.dll - c:\windows\system32\imagehlp.dll - c:\windows\system32\cryptnet.dll - c:\windows\system32\npmproxy.dll - c:\windows\system32\wbem\wbemsvc.dll - c:\windows\system32\wbem\fastprox.dll - c:\windows\system32\webio.dll - c:\windows\system32\rasadhlp.dll - c:\program files\bitdefender\bitdefender\ui\pmbxinst.ui - c:\program files\bitdefender\bitdefender\otengines_00047_002\otcore.dll - c:\program files\bitdefender\bitdefender\otengines_00047_002\ashttpbr.mdl - c:\program files\bitdefender\bitdefender\otengines_00047_002\ashttpdsp.mdl - c:\program files\bitdefender\bitdefender\otengines_00047_002\ashttpph.mdl - c:\program files\bitdefender\bitdefender\otengines_00047_002\ashttprbl.mdl - c:\program files\bitdefender\bitdefender\otengines_00047_002\asunicode.dll - c:\program files\bitdefender\bitdefender\otengines_00047_002\asregex.dll - c:\windows\system32\wscproxystub.dll - c:\windows\system32\sxs.dll - c:\program files\bitdefender\bitdefender\ui\eventlistener.ui - c:\program files\common files\bitdefender\bitdefender threat scanner\antivirus_23839_011\bdcore.dll - c:\windows\system32\wevtsvc.dll - c:\windows\system32\audiosrv.dll - c:\windows\system32\ksuser.dll - c:\windows\system32\mmdevapi.dll - c:\windows\system32\lmhsvc.dll - c:\windows\system32\nrpsrv.dll - c:\windows\system32\wcmsvc.dll - c:\windows\system32\wcmcsp.dll - c:\windows\system32\dhcpcore.dll - c:\windows\system32\dhcpcore6.dll - c:\windows\system32\wlanhlp.dll - c:\windows\system32\subscriptionmgr.dll - c:\windows\system32\wcmapi.dll - c:\windows\system32\propsys.dll - c:\windows\system32\audioses.dll - c:\windows\system32\deviceaccess.dll - c:\windows\system32\wscsvc.dll - c:\windows\system32\dbghelp.dll - c:\windows\system32\provsvc.dll - c:\windows\system32\shacct.dll - c:\windows\system32\idstore.dll - c:\windows\system32\fundisc.dll - c:\windows\system32\fdproxy.dll - c:\windows\system32\profsvc.dll - c:\windows\system32\gpsvc.dll - c:\windows\system32\themeservice.dll - c:\windows\system32\dsrole.dll - c:\windows\system32\profsvcext.dll - c:\windows\system32\ntdsapi.dll - c:\windows\system32\atl.dll - c:\windows\system32\sens.dll - c:\windows\system32\shsvcs.dll - c:\windows\system32\schedsvc.dll - c:\windows\system32\ubpm.dll - c:\windows\system32\ktmw32.dll - c:\windows\system32\dabapi.dll - c:\windows\system32\csystemeventsbrokerclient.dll - c:\windows\system32\eventaggregation.dll - c:\windows\system32\proximityservice.dll - c:\windows\system32\proximityservicepal.dll - c:\windows\system32\proximitycommon.dll - c:\windows\system32\proximitycommonpal.dll - c:\windows\system32\taskcomp.dll - c:\windows\system32\ikeext.dll - c:\windows\system32\wbem\wmisvc.dll - c:\windows\system32\vssapi.dll - c:\windows\system32\vsstrace.dll - c:\windows\system32\iphlpsvc.dll - c:\windows\system32\rtutils.dll - c:\windows\system32\srvsvc.dll - c:\windows\system32\httpprxm.dll - c:\windows\system32\adhsvc.dll - c:\windows\system32\sqmapi.dll - c:\windows\system32\nci.dll - c:\windows\system32\wdscore.dll - c:\windows\system32\sscore.dll - c:\windows\system32\sscoreext.dll - c:\windows\system32\mi.dll - c:\windows\system32\miutils.dll - c:\windows\system32\wmidcom.dll - c:\windows\system32\resutils.dll - c:\windows\system32\clusapi.dll - c:\windows\system32\browser.dll - c:\windows\system32\activeds.dll - c:\windows\system32\adsldpc.dll - c:\windows\system32\cscapi.dll - c:\windows\system32\wbem\wbemcore.dll - c:\windows\system32\wbem\esscli.dll - c:\windows\system32\wbem\wmiutils.dll - c:\windows\system32\wbem\repdrvfs.dll - c:\windows\system32\wbem\wmiprvsd.dll - c:\windows\system32\ncobjapi.dll - c:\windows\system32\wbem\wbemess.dll - c:\windows\system32\appinfo.dll - c:\windows\system32\wbem\ncprov.dll - c:\windows\system32\rasapi32.dll - c:\windows\system32\rasman.dll - c:\windows\system32\wuaueng.dll - c:\windows\system32\esent.dll - c:\windows\system32\winspool.drv - c:\windows\system32\mspatcha.dll - c:\windows\system32\slc.dll - c:\windows\system32\sppc.dll - c:\windows\system32\webservices.dll - c:\windows\system32\devrtl.dll - c:\windows\system32\drvstore.dll - c:\windows\system32\spinf.dll - c:\windows\system32\advpack.dll - c:\windows\system32\msi.dll - c:\windows\system32\wer.dll - c:\windows\system32\urlmon.dll - c:\windows\system32\aelupsvc.dll - c:\windows\system32\mmcss.dll - c:\windows\system32\credentialmigrationhandler.dll - c:\windows\system32\es.dll - c:\windows\system32\fntcache.dll - c:\windows\system32\nsisvc.dll - c:\windows\system32\wdi.dll - c:\windows\system32\netprofmsvc.dll - c:\windows\system32\perftrack.dll - c:\windows\system32\aepic.dll - c:\windows\system32\sfc_os.dll - c:\windows\system32\fdwsd.dll - c:\windows\system32\wsdapi.dll - c:\windows\system32\fdssdp.dll - c:\windows\system32\ssdpapi.dll - c:\windows\system32\taskschd.dll - c:\windows\system32\fdphost.dll - c:\windows\system32\difxapi.dll - c:\windows\system32\atiadlxx.dll - c:\windows\system32\audioendpointbuilder.dll - c:\windows\system32\wlansvc.dll - c:\windows\system32\wlanmsm.dll - c:\windows\system32\onex.dll - c:\windows\system32\wlansec.dll - c:\windows\system32\eappprxy.dll - c:\windows\system32\wlansvcpal.dll - c:\windows\system32\msxml6.dll - c:\windows\system32\tetheringieprovider.dll - c:\windows\system32\wifidisplay.dll - c:\windows\system32\wlgpclnt.dll - c:\windows\system32\l2gpstore.dll - c:\windows\system32\netcfgx.dll - c:\windows\system32\pcasvc.dll - c:\windows\system32\sysmain.dll - c:\windows\system32\trkwks.dll - c:\windows\system32\hidserv.dll - c:\windows\system32\portabledeviceapi.dll - c:\windows\system32\portabledeviceconnectapi.dll - c:\windows\system32\systemeventsbrokerclient.dll - c:\windows\system32\ncbservice.dll - c:\windows\system32\brokerlib.dll - c:\windows\system32\das.dll - c:\windows\system32\dnsrslvr.dll - c:\windows\system32\dnsext.dll - c:\windows\system32\wkssvc.dll - c:\windows\system32\cryptsvc.dll - c:\windows\system32\crypttpmeksvc.dll - c:\windows\system32\cryptcatsvc.dll - c:\windows\system32\nlasvc.dll - c:\windows\system32\ncsi.dll - c:\windows\system32\localspl.dll - c:\windows\system32\spoolss.dll - c:\windows\system32\printisolationproxy.dll - c:\windows\system32\fxsmon.dll - c:\windows\system32\tcpmon.dll - c:\windows\system32\snmpapi.dll - c:\windows\system32\wsnmp32.dll - c:\windows\system32\usbmon.dll - c:\windows\system32\wsdmon.dll - c:\windows\system32\fdpnp.dll - c:\windows\system32\spool\prtprocs\x64\winprint.dll - c:\windows\system32\win32spl.dll - c:\windows\system32\inetpp.dll - c:\windows\system32\bfe.dll - c:\windows\system32\mpssvc.dll - c:\windows\system32\adhapi.dll - c:\windows\system32\wfapigp.dll - c:\windows\system32\dps.dll - c:\windows\system32\mrmcorer.dll - c:\windows\system32\bcp47langs.dll - c:\windows\system32\windows.ui.dll - c:\windows\system32\ninput.dll - c:\windows\system32\diagperf.dll - c:\windows\system32\pnpts.dll - c:\windows\system32\srumsvc.dll - c:\windows\system32\wdiasqmmodule.dll - c:\windows\system32\nduprov.dll - c:\windows\system32\wpnsruprov.dll - c:\windows\system32\appsruprov.dll - c:\windows\system32\ncuprov.dll - c:\windows\system32\wwapi.dll - c:\windows\system32\energyprov.dll - c:\windows\system32\srumapi.dll - c:\windows\system32\radardt.dll - c:\windows\system32\wow64.dll - c:\windows\system32\wow64win.dll - c:\windows\system32\wow64cpu.dll - c:\windows\syswow64\ntdll.dll - c:\windows\syswow64\mscoree.dll - c:\windows\syswow64\kernel32.dll - c:\windows\syswow64\kernelbase.dll - c:\windows\syswow64\advapi32.dll - c:\windows\syswow64\msvcrt.dll - c:\windows\syswow64\sechost.dll - c:\windows\syswow64\rpcrt4.dll - c:\windows\syswow64\sspicli.dll - c:\windows\syswow64\cryptbase.dll - c:\windows\syswow64\bcryptprimitives.dll - c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll - c:\windows\syswow64\shlwapi.dll - c:\windows\syswow64\combase.dll - c:\windows\syswow64\user32.dll - c:\windows\syswow64\gdi32.dll - c:\windows\microsoft.net\framework\v4.0.30319\clr.dll - c:\windows\syswow64\msvcr120_clr0400.dll - c:\windows\assembly\nativeimages_v4.0.30319_32\mscorlib\fdce42fe303a68bcdb6241815b89127c\mscorlib.ni.dll - c:\windows\syswow64\ole32.dll - c:\windows\syswow64\kernel.appcore.dll - c:\windows\microsoft.net\framework\v4.0.30319\clrjit.dll - c:\windows\syswow64\oleaut32.dll - c:\windows\assembly\nativeimages_v4.0.30319_32\system\68f57d6dc4f735888e32615313c2d75e\system.ni.dll - c:\windows\assembly\nativeimages_v4.0.30319_32\system.serv759bfb78#\30c8a4cf8ca04afb39f17347420b28da\system.serviceprocess.ni.dll - c:\windows\assembly\nativeimages_v4.0.30319_32\system.core\2741b44f6d41056466878851dcf3cf38\system.core.ni.dll - c:\windows\assembly\nativeimages_v4.0.30319_32\system.configuration\e895a9b9ed773cb32902cce678467b67\system.configuration.ni.dll - c:\windows\syswow64\cryptsp.dll - c:\windows\syswow64\rsaenh.dll - c:\windows\syswow64\bcrypt.dll - c:\windows\syswow64\version.dll - c:\windows\assembly\nativeimages_v4.0.30319_32\system.xml\1b4b22e3c67e66be0641d6199b2b7146\system.xml.ni.dll - c:\windows\syswow64\httpapi.dll - c:\windows\syswow64\shell32.dll - c:\windows\syswow64\shcore.dll - c:\windows\syswow64\profapi.dll - c:\windows\syswow64\crypt32.dll - c:\windows\syswow64\msasn1.dll - c:\windows\syswow64\ncrypt.dll - c:\windows\syswow64\ntasn1.dll - c:\windows\syswow64\urlmon.dll - c:\windows\syswow64\iertutil.dll - c:\windows\syswow64\wininet.dll - c:\windows\syswow64\userenv.dll - c:\windows\syswow64\secur32.dll - c:\windows\assembly\nativeimages_v4.0.30319_32\system.drawing\a71114bae1c919319bb7895f6d8a2158\system.drawing.ni.dll - c:\windows\assembly\nativeimages_v4.0.30319_32\system.windows.forms\b20b4d5996714e1b974da98c5119c953\system.windows.forms.ni.dll - c:\windows\syswow64\ws2_32.dll - c:\windows\syswow64\nsi.dll - c:\windows\syswow64\mswsock.dll - c:\windows\syswow64\dnsapi.dll - c:\windows\syswow64\rasadhlp.dll - c:\windows\syswow64\fwpuclnt.dll - c:\windows\syswow64\msvcp100.dll - c:\windows\syswow64\msvcr100.dll - c:\windows\syswow64\psapi.dll - c:\windows\syswow64\netapi32.dll - c:\windows\syswow64\iphlpapi.dll - c:\windows\syswow64\fltlib.dll - c:\windows\syswow64\netutils.dll - c:\windows\syswow64\srvcli.dll - c:\windows\syswow64\wkscli.dll - c:\windows\syswow64\winnsi.dll - c:\windows\syswow64\clbcatq.dll - c:\windows\syswow64\ntmarta.dll - c:\windows\syswow64\jscript.dll - c:\windows\syswow64\ondemandconnroutehelper.dll - c:\windows\syswow64\winhttp.dll - c:\windows\syswow64\dhcpcsvc6.dll - c:\windows\syswow64\dhcpcsvc.dll - c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7\comctl32.dll - c:\windows\syswow64\schannel.dll - c:\windows\syswow64\wintrust.dll - c:\windows\syswow64\gpapi.dll - c:\windows\syswow64\cryptnet.dll - c:\windows\syswow64\wldap32.dll - c:\windows\syswow64\webio.dll - c:\windows\syswow64\ncryptsslp.dll - c:\windows\syswow64\cscapi.dll - c:\program files\shield\shdapi.dll - c:\program files\shield\shdpub.dll - c:\program files\shield\shdservps.dll - c:\program files\bitdefender\bitdefender\updatemgr.dll - c:\windows\system32\ipsecsvc.dll - c:\windows\system32\fwremotesvr.dll - c:\program files\bitdefender\bitdefender\active virus control\avc3_00261_002\avcuf64.dll - c:\windows\system32\playsndsrv.dll - c:\windows\system32\msctfmonitor.dll - c:\windows\system32\msutb.dll - c:\windows\system32\wdmaud.drv - c:\windows\system32\msacm32.drv - c:\windows\system32\msacm32.dll - c:\windows\system32\midimap.dll - c:\program files\internet explorer\sqmapi.dll - c:\windows\system32\profext.dll - c:\windows\system32\settingsyncpolicy.dll - c:\windows\system32\dui70.dll - c:\windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1\comctl32.dll - c:\windows\system32\duser.dll - c:\windows\system32\sndvolsso.dll - c:\windows\system32\oleacc.dll - c:\windows\system32\windows.ui.immersive.dll - c:\windows\system32\twinui.dll - c:\windows\system32\twinapi.appcore.dll - c:\windows\system32\explorerframe.dll - c:\windows\system32\windows.immersiveshell.serviceprovider.dll - c:\windows\system32\wldp.dll - c:\windows\system32\photometadatahandler.dll - c:\windows\system32\twinui.appcore.dll - c:\windows\system32\wpncore.dll - c:\windows\system32\dwrite.dll - c:\windows\system32\wlidprov.dll - c:\windows\system32\thumbcache.dll - c:\windows\system32\windows.networking.connectivity.dll - c:\windows\system32\inputswitch.dll - c:\windows\system32\linkinfo.dll - c:\windows\system32\lockscreencn.dll - c:\windows\system32\uiautomationcore.dll - c:\windows\system32\msftedit.dll - c:\program files\common files\microsoft shared\ink\tiptsf.dll - c:\windows\system32\stobject.dll - c:\windows\system32\batmeter.dll - c:\windows\system32\prnfldr.dll - c:\windows\system32\dxp.dll - c:\windows\winsxs\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9600.17227_none_932c0e57474f5080\gdiplus.dll - c:\windows\system32\shdocvw.dll - c:\windows\system32\actioncenter.dll - c:\windows\system32\syncreg.dll - c:\windows\system32\alttab.dll - c:\windows\system32\authui.dll - c:\windows\system32\ntshrui.dll - c:\windows\system32\pnidui.dll - c:\windows\system32\wpdshserviceobj.dll - c:\windows\system32\networkstatus.dll - c:\windows\system32\windows.globalization.fontgroups.dll - c:\windows\system32\portabledevicetypes.dll - c:\windows\system32\bthprops.cpl - c:\windows\system32\bluetoothapis.dll - c:\windows\system32\settingmonitor.dll - c:\program files\windows portable devices\sqmapi.dll - c:\windows\system32\srchadmin.dll - c:\windows\system32\windows.ui.search.dll - c:\windows\system32\wincorlib.dll - c:\windows\system32\wsclient.dll - c:\windows\system32\wsshared.dll - c:\windows\system32\wssync.dll - c:\windows\system32\elscore.dll - c:\windows\system32\netshell.dll - c:\windows\system32\mssprxy.dll - c:\windows\system32\windows.ui.xaml.dll - c:\windows\system32\wintypes.dll - c:\windows\system32\searchfolder.dll - c:\windows\system32\structuredquery.dll - c:\windows\system32\synccenter.dll - c:\windows\system32\ehstorshell.dll - c:\windows\system32\imapi2.dll - c:\windows\system32\hgcpl.dll - c:\windows\system32\ieframe.dll - c:\windows\system32\apprepapi.dll - c:\windows\system32\tbs.dll - c:\windows\system32\pcacli.dll - c:\windows\system32\wscinterop.dll - c:\windows\system32\wscapi.dll - c:\windows\system32\wscui.cpl - c:\windows\system32\werconcpl.dll - c:\windows\system32\framedynos.dll - c:\windows\system32\wercplsupport.dll - c:\windows\system32\hcproviders.dll - c:\windows\system32\uiribbonres.dll - c:\windows\system32\networkexplorer.dll - c:\windows\system32\dlnashext.dll - c:\windows\system32\workfoldersshell.dll - c:\windows\system32\devdispitemprovider.dll - c:\windows\system32\skydriveshell.dll - c:\windows\system32\van.dll - c:\windows\system32\dot3mm.dll - c:\windows\system32\wlanmm.dll - c:\windows\system32\tetheringstation.dll - c:\windows\system32\ondemandconnroutehelper.dll - c:\windows\system32\wlanconn.dll - c:\windows\system32\eappcfg.dll - c:\windows\system32\datusage.dll - c:\windows\system32\iconcodecservice.dll - c:\windows\system32\timedate.cpl - c:\program files\internet explorer\ieproxy.dll - c:\windows\system32\setnetworklocation.dll - c:\program files\bitdefender\bitdefender\ui\fshredctx.ui - c:\windows\system32\igfxrplk.lrc - c:\program files\bitdefender\bitdefender\bdshellext.dll - c:\program files\bitdefender\bitdefender\ui\bdshellext.ui - c:\program files\winrar\rarext.dll - c:\windows\system32\syncui.dll - c:\windows\system32\synceng.dll - c:\program files\bitdefender\bitdefender\fshredctx.dll - c:\windows\system32\chartv.dll - c:\windows\system32\twext.dll - c:\program files\shield\shdext.dll - c:\windows\system32\acppage.dll - c:\windows\system32\sfc.dll - c:\windows\system32\playtodevice.dll - c:\windows\system32\ehstorapi.dll - c:\windows\system32\timebrokerserver.dll - c:\windows\system32\fdrespub.dll - c:\windows\system32\tquery.dll - c:\windows\system32\mssrch.dll - c:\windows\system32\msidle.dll - c:\windows\system32\mswb7.dll - c:\windows\system32\elslad.dll - c:\windows\system32\naturallanguage6.dll - c:\windows\system32\nlsdata0416.dll - c:\windows\system32\nlslexicons0416.dll - c:\windows\system32\hccutils.dll - c:\windows\system32\igfxsrvc.dll - c:\windows\system32\igfxress.dll - c:\windows\system32\icclibdll_x64.dll - c:\windows\system32\comdlg32.dll - c:\windows\system32\syncom.dll - c:\windows\system32\syntpapi.dll - c:\program files\synaptics\syntp\syntpres.dll - c:\program files\bitdefender\bitdefender\bdhtmldialogs.dll - c:\program files\bitdefender\bitdefender\htmlayout.dll - c:\windows\system32\mfc100enu.dll - c:\program files\bitdefender\bitdefender\ui\bdagent.ui - c:\program files\bitdefender\bitdefender\updategui.dll - c:\program files\bitdefender\bitdefender\ui\updategui.ui - c:\program files\bitdefender\bitdefender\uienvironment.dll - c:\program files\bitdefender\bitdefender\issuesclient.dll - c:\program files\bitdefender\bitdefender\ui\issuesclient.ui - c:\program files\bitdefender\bitdefender\popup.dll - c:\program files\bitdefender\bitdefender\ui\popup.ui - c:\program files\bitdefender\bitdefender\win8ui.dll - c:\program files\bitdefender\bitdefender\ondemandcomm.dll - c:\program files\bitdefender\bitdefender\bdnc.dll - c:\windows\system32\wpnapps.dll - c:\program files\shield\mfc90u.dll - c:\program files\shield\shdui.dll - c:\program files\shield\shdidle.dll - c:\program files\bitdefender\bitdefender\ui\pmbxag.ui - c:\windows\system32\msxml3.dll - c:\program files\bitdefender\bitdefender\antispam32\htmlayout.dll - c:\program files\bitdefender\bitdefender\antispam32\txmlutil.dll - c:\windows\syswow64\oleacc.dll - c:\windows\syswow64\comdlg32.dll - c:\windows\syswow64\imm32.dll - c:\windows\syswow64\winmm.dll - c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.9600.16384_none_7c55c866aa0c3ff0\comctl32.dll - c:\windows\syswow64\msctf.dll - c:\windows\syswow64\winmmbase.dll - c:\windows\syswow64\cfgmgr32.dll - c:\windows\syswow64\devobj.dll - c:\windows\syswow64\uxtheme.dll - c:\program files\bitdefender\bitdefender\antispam32\bdsecurepass.dll - c:\windows\system32\rometadata.dll - c:\windows\system32\mshtml.dll - c:\windows\system32\msimtf.dll - c:\windows\system32\wwaapi.dll - c:\windows\system32\jscript9.dll - c:\windows\winstore\winstoreui.dll - c:\windows\system32\windows.graphics.dll - c:\windows\system32\windows.storage.applicationdata.dll - c:\windows\syswow64\setupapi.dll - c:\windows\syswow64\wsock32.dll - c:\program files (x86)\intel\intel(r) management engine components\uns\ace.dll - c:\program files (x86)\intel\intel(r) management engine components\uns\wsmanclient.dll - c:\program files (x86)\intel\intel(r) management engine components\uns\common.dll - c:\program files (x86)\intel\intel(r) management engine components\uns\gmscommon.dll - c:\windows\syswow64\imagehlp.dll - c:\program files (x86)\intel\intel(r) management engine components\uns\configurator.dll - c:\program files (x86)\intel\intel(r) management engine components\uns\eventmanager.dll - c:\program files (x86)\intel\intel(r) management engine components\uns\statuseventhandler.dll - c:\windows\syswow64\dpapi.dll - c:\program files\bitdefender\bitdefender\active virus control\avc3_00261_002\avcuf32.dll - c:\windows\syswow64\shfolder.dll - c:\windows\syswow64\propsys.dll - c:\users\hp_home\appdata\local\temp\nsbfc9b.tmp\registry.dll - c:\users\hp_home\appdata\local\temp\nsbfc9b.tmp\newadvsplash.dll - c:\windows\syswow64\asycfilt.dll - c:\windows\syswow64\dwmapi.dll - c:\users\hp_home\appdata\local\temp\nsbfc9b.tmp\system.dll - c:\windows\syswow64\apphelp.dll - c:\users\hp_home\desktop\nowy folder\firefoxportable\app\firefox\msvcr100.dll - c:\users\hp_home\desktop\nowy folder\firefoxportable\app\firefox\mozglue.dll - c:\users\hp_home\desktop\nowy folder\firefoxportable\app\firefox\msvcp100.dll - c:\users\hp_home\desktop\nowy folder\firefoxportable\app\firefox\nss3.dll - c:\users\hp_home\desktop\nowy folder\firefoxportable\app\firefox\mozjs.dll - c:\users\hp_home\desktop\nowy folder\firefoxportable\app\firefox\icuin52.dll - c:\users\hp_home\desktop\nowy folder\firefoxportable\app\firefox\icuuc52.dll - c:\users\hp_home\desktop\nowy folder\firefoxportable\app\firefox\icudt52.dll - c:\users\hp_home\desktop\nowy folder\firefoxportable\app\firefox\mozalloc.dll - c:\users\hp_home\desktop\nowy folder\firefoxportable\app\firefox\gkmedias.dll - c:\windows\syswow64\usp10.dll - c:\windows\syswow64\msimg32.dll - c:\users\hp_home\desktop\nowy folder\firefoxportable\app\firefox\xul.dll - c:\windows\syswow64\wtsapi32.dll - c:\windows\syswow64\pdh.dll - c:\windows\syswow64\samcli.dll - c:\windows\syswow64\dwrite.dll - c:\windows\syswow64\dbghelp.dll - c:\users\hp_home\desktop\nowy folder\firefoxportable\app\firefox\browser\components\browsercomps.dll - c:\windows\syswow64\wbem\wbemprox.dll - c:\windows\syswow64\wbemcomn.dll - c:\windows\syswow64\napinsp.dll - c:\windows\syswow64\pnrpnsp.dll - c:\windows\syswow64\nlaapi.dll - c:\windows\syswow64\wbem\wbemsvc.dll - c:\windows\syswow64\winrnr.dll - c:\windows\syswow64\wbem\fastprox.dll - c:\windows\syswow64\winsta.dll - c:\windows\syswow64\wpc.dll - c:\windows\syswow64\normaliz.dll - c:\windows\syswow64\wevtapi.dll - c:\windows\syswow64\mmdevapi.dll - c:\windows\syswow64\audioses.dll - c:\windows\syswow64\powrprof.dll - c:\windows\syswow64\dxgi.dll - c:\windows\syswow64\d3d10_1.dll - c:\windows\syswow64\d3d10_1core.dll - c:\windows\syswow64\d3d11.dll - c:\windows\syswow64\aticfx32.dll - c:\windows\syswow64\atiuxpag.dll - c:\windows\syswow64\igd10umd32.dll - c:\windows\syswow64\atidxx32.dll - c:\windows\syswow64\d2d1.dll - c:\windows\syswow64\mscms.dll - c:\users\hp_home\desktop\nowy folder\firefoxportable\app\firefox\softokn3.dll - c:\users\hp_home\desktop\nowy folder\firefoxportable\app\firefox\nssdbm3.dll - c:\users\hp_home\desktop\nowy folder\firefoxportable\app\firefox\freebl3.dll - c:\users\hp_home\desktop\nowy folder\firefoxportable\app\firefox\nssckbi.dll - c:\windows\syswow64\explorerframe.dll - c:\windows\syswow64\duser.dll - c:\windows\syswow64\dui70.dll - c:\windows\syswow64\twinapi.dll - c:\windows\syswow64\bcp47langs.dll - c:\windows\syswow64\linkinfo.dll - c:\windows\syswow64\ntshrui.dll - c:\windows\syswow64\mfplat.dll - c:\windows\syswow64\rtworkq.dll - c:\windows\syswow64\avrt.dll - c:\windows\syswow64\mfreadwrite.dll - c:\windows\syswow64\mf.dll - c:\windows\syswow64\dxva2.dll - c:\windows\syswow64\d3d9.dll - c:\windows\syswow64\atiu9pag.dll - c:\windows\syswow64\igdumd32.dll - c:\windows\syswow64\atiumdag.dll - c:\windows\syswow64\mfmp4srcsnk.dll - c:\windows\syswow64\msmpeg2vdec.dll - c:\windows\syswow64\mfcore.dll - c:\windows\syswow64\ksuser.dll - c:\windows\syswow64\windowscodecs.dll - c:\windows\syswow64\thumbcache.dll - c:\windows\syswow64\icm32.dll - c:\windows\syswow64\windows.globalization.dll - c:\windows\syswow64\globinputhost.dll - c:\program files (x86)\common files\microsoft shared\ink\tiptsf.dll - c:\windows\syswow64\structuredquery.dll - c:\windows\syswow64\actxprxy.dll - c:\windows\syswow64\searchfolder.dll - c:\windows\syswow64\samlib.dll - c:\windows\syswow64\networkexplorer.dll - c:\windows\syswow64\twinapi.appcore.dll - c:\windows\syswow64\mpr.dll - c:\windows\syswow64\drprov.dll - c:\windows\syswow64\ntlanman.dll - c:\windows\syswow64\davclnt.dll - c:\windows\syswow64\davhlpr.dll - c:\windows\syswow64\mssprxy.dll - c:\windows\syswow64\dlnashext.dll - c:\windows\syswow64\playtodevice.dll - c:\windows\syswow64\devdispitemprovider.dll - c:\windows\syswow64\portabledeviceapi.dll - c:\windows\syswow64\netshell.dll - c:\windows\syswow64\provsvc.dll - c:\windows\system32\mscoree.dll - c:\windows\microsoft.net\framework64\v4.0.30319\mscoreei.dll - c:\windows\microsoft.net\framework64\v2.0.50727\mscorwks.dll - c:\windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.8428_none_88dcdb0b2fb19957\msvcr80.dll - c:\windows\assembly\nativeimages_v2.0.50727_64\mscorlib\6227ee011c9930128c5ad76841ecf2ee\mscorlib.ni.dll - c:\windows\assembly\nativeimages_v2.0.50727_64\system\3e4f48ccbad3f6afbd04a395a7109c4c\system.ni.dll - c:\windows\assembly\nativeimages_v2.0.50727_64\system.serviceproce#\dffbacf0a86b03913a7df1f5dde6fe25\system.serviceprocess.ni.dll - c:\windows\microsoft.net\framework64\v2.0.50727\mscorjit.dll - c:\windows\assembly\nativeimages_v2.0.50727_64\windowsbase\0562ef3ba8cba3a9be93515d6d0edac4\windowsbase.ni.dll - c:\windows\assembly\nativeimages_v2.0.50727_64\presentationcore\08ee9f522c4c0f67c7311154d993c08d\presentationcore.ni.dll - c:\windows\microsoft.net\framework64\v3.0\wpf\wpfgfx_v0300.dll - c:\windows\system32\shfolder.dll - c:\windows\assembly\gac_msil\system.serviceprocess.resources\2.0.0.0_pl_b03f5f7f11d50a3a\system.serviceprocess.resources.dll - c:\windows\microsoft.net\framework\v2.0.50727\mscorwks.dll - c:\windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.8428_none_d08a11e2442dc25d\msvcr80.dll - c:\windows\assembly\nativeimages_v2.0.50727_32\mscorlib\5bd3374f05d46ba0563f44d032209f08\mscorlib.ni.dll - c:\windows\microsoft.net\framework\v2.0.50727\mscorjit.dll - c:\windows\assembly\nativeimages_v2.0.50727_32\system\c5e6cfdeeb03ad6caf5496c5e5dd3da0\system.ni.dll - c:\windows\assembly\nativeimages_v2.0.50727_32\system.drawing\2ac71cd31db4f848bd0ef4488c790f84\system.drawing.ni.dll - c:\windows\assembly\nativeimages_v2.0.50727_32\system.windows.forms\a6fc3b6cf36a875f67adc3d3749184fb\system.windows.forms.ni.dll - c:\program files (x86)\xirrus\xirrus wi-fi inspector\devexpress.xtrabars.v8.3.dll - c:\program files (x86)\xirrus\xirrus wi-fi inspector\devexpress.utils.v8.3.dll - c:\program files (x86)\xirrus\xirrus wi-fi inspector\devexpress.data.v8.3.dll - c:\program files (x86)\xirrus\xirrus wi-fi inspector\sharpwrapi_win32.dll - c:\windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.8428_none_d08a11e2442dc25d\msvcp80.dll - c:\program files (x86)\xirrus\xirrus wi-fi inspector\librsvg.dll - c:\program files (x86)\xirrus\xirrus wi-fi inspector\cairo.dll - c:\windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.8428_none_d08a11e2442dc25d\msvcm80.dll - c:\program files (x86)\xirrus\xirrus wi-fi inspector\gobject.dll - c:\program files (x86)\xirrus\xirrus wi-fi inspector\glib.dll - c:\program files (x86)\xirrus\xirrus wi-fi inspector\libjpeg.dll - c:\program files (x86)\xirrus\xirrus wi-fi inspector\libtiff.dll - c:\program files (x86)\xirrus\xirrus wi-fi inspector\pango.dll - c:\program files (x86)\xirrus\xirrus wi-fi inspector\pangocairo.dll - c:\program files (x86)\xirrus\xirrus wi-fi inspector\libpng.dll - c:\program files (x86)\xirrus\xirrus wi-fi inspector\libxml2.dll - c:\program files (x86)\xirrus\xirrus wi-fi inspector\gmodule.dll - c:\program files (x86)\xirrus\xirrus wi-fi inspector\zlib.dll - c:\program files (x86)\xirrus\xirrus wi-fi inspector\devexpress.xtraeditors.v8.3.dll - c:\windows\assembly\gac_msil\mscorlib.resources\2.0.0.0_pl_b77a5c561934e089\mscorlib.resources.dll - c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9600.17227_none_dad9452e5bcb7986\gdiplus.dll - c:\windows\assembly\nativeimages_v2.0.50727_32\system.xml\f80da12b77d2fef2b7dab9a22ac752f1\system.xml.ni.dll - c:\program files (x86)\xirrus\xirrus wi-fi inspector\devexpress.xtragrid.v8.3.dll - c:\program files (x86)\xirrus\xirrus wi-fi inspector\devexpress.xtralayout.v8.3.dll - c:\windows\assembly\nativeimages_v2.0.50727_32\system.data\2f3238ebb7cf75987a203aaf7c0b131d\system.data.ni.dll - c:\windows\assembly\gac_32\system.data\2.0.0.0__b77a5c561934e089\system.data.dll - c:\program files (x86)\xirrus\xirrus wi-fi inspector\devexpress.xtracharts.v8.3.ui.dll - c:\program files (x86)\xirrus\xirrus wi-fi inspector\devexpress.xtracharts.v8.3.dll - c:\program files (x86)\xirrus\xirrus wi-fi inspector\devexpress.charts.v8.3.core.dll - c:\windows\assembly\nativeimages_v2.0.50727_32\system.web\34eaf4269fdd2210cb7fd83c0986371e\system.web.ni.dll - c:\windows\syswow64\wlanapi.dll - c:\windows\assembly\nativeimages_v2.0.50727_32\accessibility\a8a310b81c76f8e79a1a7fc309a098bf\accessibility.ni.dll - c:\windows\assembly\gac_msil\system.design\2.0.0.0__b03f5f7f11d50a3a\system.design.dll - c:\program files (x86)\xirrus\xirrus wi-fi inspector\iwifioperations.dll - c:\windows\syswow64\wpdshext.dll - c:\windows\assembly\nativeimages_v2.0.50727_32\system.runtime.remo#\e0e70a8e811842f3be4718070535b659\system.runtime.remoting.ni.dll - c:\program files (x86)\xirrus\xirrus wi-fi inspector\interop.netconlib.dll - c:\windows\syswow64\hnetcfg.dll - c:\windows\syswow64\atl.dll - c:\windows\assembly\nativeimages_v2.0.50727_32\system.configuration\af8101077ec0f53a1ed79ceb9c3f5632\system.configuration.ni.dll - c:\windows\assembly\gac_msil\system.resources\2.0.0.0_pl_b77a5c561934e089\system.resources.dll - c:\windows\microsoft.net\framework\v2.0.50727\diasymreader.dll - c:\windows\syswow64\mlang.dll - c:\windows\syswow64\rasapi32.dll - c:\windows\syswow64\rasman.dll - c:\windows\syswow64\rtutils.dll - c:\windows\assembly\gac_msil\system.windows.forms.resources\2.0.0.0_pl_b77a5c561934e089\system.windows.forms.resources.dll - c:\windows\system32\msshooks.dll - c:\windows\system32\mssph.dll - c:\windows\system32\mapi32.dll - c:\windows\system32\query.dll - c:\windows\system32\rtffilt.dll - c:\windows\system32\riched32.dll - c:\windows\system32\riched20.dll - c:\windows\system32\usp10.dll - c:\windows\system32\msls31.dll - c:\windows\system32\schedcli.dll 03) TCP connections: - 192.168.2.102:50043 <-> 91.228.167.11:80 (TIME_WAIT), owner: system - 192.168.2.102:50062 <-> 173.194.112.121:80 (TIME_WAIT), owner: system - 192.168.2.102:50065 <-> 64.233.165.156:80 (TIME_WAIT), owner: system - 192.168.2.102:50067 <-> 173.194.112.109:80 (TIME_WAIT), owner: system - 192.168.2.102:50072 <-> 173.194.112.112:80 (TIME_WAIT), owner: system - 192.168.2.102:50087 <-> 173.194.112.111:80 (TIME_WAIT), owner: system - 192.168.2.102:50089 <-> 173.194.112.101:80 (TIME_WAIT), owner: system - 192.168.2.102:50090 <-> 173.194.112.101:80 (TIME_WAIT), owner: system - 192.168.2.102:50096 <-> 54.230.200.83:80 (TIME_WAIT), owner: system - 192.168.2.102:50097 <-> 54.230.201.18:80 (TIME_WAIT), owner: system - 192.168.2.102:50113 <-> 173.194.112.121:80 (TIME_WAIT), owner: system - 192.168.2.102:50135 <-> 173.194.112.121:80 (TIME_WAIT), owner: system - 192.168.2.102:50151 <-> 23.64.210.110:443 (TIME_WAIT), owner: system - 192.168.2.102:50169 <-> 90.84.60.90:443 (TIME_WAIT), owner: system - 192.168.2.102:50187 <-> 148.251.76.152:80 (TIME_WAIT), owner: system - 192.168.2.102:50191 <-> 91.201.154.215:80 (TIME_WAIT), owner: system - 192.168.2.102:50193 <-> 23.64.223.139:80 (TIME_WAIT), owner: system - 192.168.2.102:50194 <-> 91.201.154.215:80 (TIME_WAIT), owner: system - 192.168.2.102:50195 <-> 90.84.60.89:80 (TIME_WAIT), owner: system - 192.168.2.102:50198 <-> 148.251.76.152:80 (TIME_WAIT), owner: system - 192.168.2.102:50199 <-> 91.201.154.215:80 (TIME_WAIT), owner: system - 192.168.2.102:50200 <-> 23.64.223.139:80 (TIME_WAIT), owner: system - 192.168.2.102:50201 <-> 173.194.112.122:80 (TIME_WAIT), owner: system - 192.168.2.102:50202 <-> 173.194.112.122:80 (TIME_WAIT), owner: system - 192.168.2.102:50203 <-> 90.84.60.89:80 (TIME_WAIT), owner: system - 192.168.2.102:50214 <-> 23.52.53.163:80 (SYN_SENT), owner: c:\windows\explorer.exe - 192.168.2.102:50215 <-> 23.52.59.27:80 (SYN_SENT), owner: c:\windows\explorer.exe - 192.168.2.102:50216 <-> 23.52.53.163:80 (SYN_SENT), owner: c:\windows\explorer.exe - 192.168.2.102:50218 <-> 148.251.76.152:80 (TIME_WAIT), owner: system - Active connection: 127.0.0.1:49154 -> 127.0.0.1:49155, owner: c:\program files\bitdefender\bitdefender\vsserv.exe - Active connection: 127.0.0.1:49155 -> 127.0.0.1:49154, owner: c:\program files\bitdefender\bitdefender\vsserv.exe - Active connection: 127.0.0.1:49156 -> 127.0.0.1:49157, owner: c:\program files\bitdefender\bitdefender\vsserv.exe - Active connection: 127.0.0.1:49157 -> 127.0.0.1:49156, owner: c:\program files\bitdefender\bitdefender\vsserv.exe - Active connection: 127.0.0.1:49158 -> 127.0.0.1:49159, owner: c:\program files\bitdefender\bitdefender\vsserv.exe - Active connection: 127.0.0.1:49159 -> 127.0.0.1:49158, owner: c:\program files\bitdefender\bitdefender\vsserv.exe - Active connection: 127.0.0.1:49160 -> 127.0.0.1:49161, owner: c:\program files\bitdefender\bitdefender\vsserv.exe - Active connection: 127.0.0.1:49161 -> 127.0.0.1:49160, owner: c:\program files\bitdefender\bitdefender\vsserv.exe - Active connection: 127.0.0.1:49256 -> 127.0.0.1:49257, owner: c:\program files\bitdefender\bitdefender\bdagent.exe - Active connection: 127.0.0.1:49257 -> 127.0.0.1:49256, owner: c:\program files\bitdefender\bitdefender\bdagent.exe - Active connection: 127.0.0.1:49258 -> 127.0.0.1:49259, owner: c:\program files\bitdefender\bitdefender\bdagent.exe - Active connection: 127.0.0.1:49259 -> 127.0.0.1:49258, owner: c:\program files\bitdefender\bitdefender\bdagent.exe - Active connection: 127.0.0.1:49260 -> 127.0.0.1:49261, owner: c:\program files\bitdefender\bitdefender\bdagent.exe - Active connection: 127.0.0.1:49261 -> 127.0.0.1:49260, owner: c:\program files\bitdefender\bitdefender\bdagent.exe - Active connection: 127.0.0.1:49262 -> 127.0.0.1:49263, owner: c:\program files\bitdefender\bitdefender\bdagent.exe - Active connection: 127.0.0.1:49263 -> 127.0.0.1:49262, owner: c:\program files\bitdefender\bitdefender\bdagent.exe - Active connection: 127.0.0.1:49426 -> 127.0.0.1:49427, owner: c:\users\hp_home\desktop\nowy folder\firefoxportable\app\firefox\firefox.exe - Active connection: 127.0.0.1:49427 -> 127.0.0.1:49426, owner: c:\users\hp_home\desktop\nowy folder\firefoxportable\app\firefox\firefox.exe - Active connection: 192.168.2.102:50024 -> 31.13.93.33:443, owner: c:\users\hp_home\desktop\nowy folder\firefoxportable\app\firefox\firefox.exe - Active connection: 192.168.2.102:50140 -> 88.198.157.122:4004, owner: c:\program files\bitdefender\bitdefender\vsserv.exe - Active connection: 192.168.2.102:50144 -> 64.233.165.156:80, owner: c:\users\hp_home\desktop\nowy folder\firefoxportable\app\firefox\firefox.exe - Active connection: 192.168.2.102:50152 -> 173.194.112.109:80, owner: c:\users\hp_home\desktop\nowy folder\firefoxportable\app\firefox\firefox.exe - Active connection: 192.168.2.102:50156 -> 173.194.112.112:80, owner: c:\users\hp_home\desktop\nowy folder\firefoxportable\app\firefox\firefox.exe - Active connection: 192.168.2.102:50158 -> 173.194.112.111:80, owner: c:\users\hp_home\desktop\nowy folder\firefoxportable\app\firefox\firefox.exe - Active connection: 192.168.2.102:50168 -> 90.84.60.27:443, owner: c:\users\hp_home\desktop\nowy folder\firefoxportable\app\firefox\firefox.exe - Listening on *, port 135 (epmap), owner: c:\windows\system32\svchost.exe - Listening on *, port 445 (microsoft-ds), owner: system - Listening on *, port 49152, owner: c:\windows\system32\wininit.exe - Listening on *, port 49153, owner: c:\windows\system32\lsass.exe - Listening on *, port 49174, owner: c:\windows\system32\svchost.exe - Listening on *, port 49175, owner: c:\windows\system32\svchost.exe - Listening on *, port 49176, owner: c:\windows\system32\spoolsv.exe - Listening on *, port 49216, owner: c:\windows\system32\services.exe - Listening on *, port 49217, owner: c:\windows\system32\svchost.exe - Listening on *, port 5357 (wsd), owner: system - Listening on *, port 8092, owner: system - Listening on 127.0.0.1, port 3939, owner: system - Listening on 127.127.127.127, port 3939, owner: system - Listening on 192.168.2.102, port 139 (netbios-ssn), owner: system 04) UDP endpoints: - 0.0.0.0, port 3702 (ws-discovery), owner: c:\windows\system32\svchost.exe - 0.0.0.0, port 3702 (ws-discovery), owner: c:\windows\system32\svchost.exe - 0.0.0.0, port 3702 (ws-discovery), owner: c:\windows\system32\svchost.exe - 0.0.0.0, port 3702 (ws-discovery), owner: c:\windows\system32\svchost.exe - 0.0.0.0, port 4500 (ipsec-msft), owner: c:\windows\system32\svchost.exe - 0.0.0.0, port 500 (isakmp), owner: c:\windows\system32\svchost.exe - 0.0.0.0, port 5355 (llmnr), owner: c:\windows\system32\svchost.exe - 0.0.0.0, port 53556, owner: c:\windows\system32\svchost.exe - 0.0.0.0, port 63199, owner: c:\windows\system32\svchost.exe - 192.168.2.102, port 137 (netbios-ns) - 192.168.2.102, port 138 (netbios-dgm) 05) DNS server entries: - 192.168.2.1 06) Important registry entries: * Category: Standard Autostart (10 items) HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows - LoadAppInit_DLLs = 0x00 - AppInit_DLLs = HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon - Userinit = C:\Windows\system32\userinit.exe, - Shell = explorer.exe - VMApplet = SystemPropertiesPerformance.exe /pagefile HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run - IgfxTray = "C:\Windows\system32\igfxtray.exe" - HotKeysCmds = "C:\Windows\system32\hkcmd.exe" - Persistence = "C:\Windows\system32\igfxpers.exe" - SynTPEnh = %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe - Bdagent = "C:\Program Files\Bitdefender\Bitdefender\bdagent.exe" - Shield = "C:\Program Files\Shield\shdtray.exe" HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce - NCPluginUpdater = "C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe" Update HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad - WebCheck = {E6FB5E20-DE35-11CF-9C87-00AA005127ED} HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\KnownDLLs - rpcrt4 = rpcrt4.dll - DllDirectory = %SystemRoot%\system32 - combase = combase.dll - gdiplus = gdiplus.dll - IMAGEHLP = IMAGEHLP.dll - MSVCRT = MSVCRT.dll - SHLWAPI = SHLWAPI.dll - COMDLG32 = COMDLG32.dll - NORMALIZ = NORMALIZ.dll - PSAPI = PSAPI.DLL - WLDAP32 = WLDAP32.dll - ole32 = ole32.dll - DllDirectory32 = %SystemRoot%\syswow64 - IMM32 = IMM32.dll - _Wow64cpu = Wow64cpu.dll - MSCTF = MSCTF.dll - _Wow64win = Wow64win.dll - OLEAUT32 = OLEAUT32.dll - LPK = LPK.dll - clbcatq = clbcatq.dll - WS2_32 = WS2_32.dll - SHELL32 = SHELL32.dll - gdi32 = gdi32.dll - _Wow64 = Wow64.dll - DifxApi = difxapi.dll - Setupapi = Setupapi.dll - kernel32 = kernel32.dll - advapi32 = advapi32.dll - user32 = user32.dll - NSI = NSI.dll - sechost = sechost.dll HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run - Agent Portfela Bitdefender = "C:\Program Files\Bitdefender\Bitdefender\pmbxag.exe" - Portfel Bitdefender = "C:\Program Files\Bitdefender\Bitdefender\pwdmanui.exe" --hidden --nowizard - Agent aplikacji Portfel Bitdefender = "C:\Program Files\Bitdefender\Bitdefender\antispam32\bdapppassmgr.exe" HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run - Agent Portfela Bitdefender = "C:\Program Files\Bitdefender\Bitdefender\pmbxag.exe" - Portfel Bitdefender = "C:\Program Files\Bitdefender\Bitdefender\pwdmanui.exe" --hidden --nowizard - Agent aplikacji Portfel Bitdefender = "C:\Program Files\Bitdefender\Bitdefender\antispam32\bdapppassmgr.exe" HKU\S-1-5-21-1582120339-517770455-3037123893-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Run - Agent Portfela Bitdefender = "C:\Program Files\Bitdefender\Bitdefender\pmbxag.exe" - Portfel Bitdefender = "C:\Program Files\Bitdefender\Bitdefender\pwdmanui.exe" --hidden --nowizard - Agent aplikacji Portfel Bitdefender = "C:\Program Files\Bitdefender\Bitdefender\antispam32\bdapppassmgr.exe" HKU\S-1-5-21-1582120339-517770455-3037123893-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce - empty = (null) * Category: Winlogon Notify (1 item) HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui - DLLName = igfxdev.dll * Category: Browser Helper Objects (3 items) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects - empty = (null) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - CLSID = C:\Program Files\Bitdefender\Bitdefender\pmbxie.dll - Default = Portfel Bitdefender - NoExplorer = 0x01 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - CLSID = C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll - Default = HP Network Check Helper - NoExplorer = 0x01 * Category: Internet Explorer (4 items) HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{25510184-5A38-4A99-B273-DCA8EEF6CD08} - Exec = C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe HKLM\SOFTWARE\Microsoft\Internet Explorer\Main - Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 - Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141 - Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141 - Local Page = C:\Windows\System32\blank.htm - Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 HKU\S-1-5-21-1582120339-517770455-3037123893-1001\SOFTWARE\Microsoft\Internet Explorer\Main - Local Page = C:\Windows\system32\blank.htm - Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 - Start Page = https://google,pl/ HKU\S-1-5-21-1582120339-517770455-3037123893-1001\SOFTWARE\Microsoft\Internet Explorer\UrlSearchHooks - C:\Windows\System32\ieframe.dll = * Category: Shell Open Commands (297 items) HKLM\SOFTWARE\Classes\Application.Manifest\shell\open\command - Default = "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\dfshim.dll",ShOpenVerbApplication %1 HKLM\SOFTWARE\Classes\Application.Reference\shell\open\command - Default = "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\dfshim.dll",ShOpenVerbShortcut %1|%2 HKLM\SOFTWARE\Classes\CABFolder\shell\open\command - Default = %SystemRoot%\Explorer.exe /idlist,%I,%L HKLM\SOFTWARE\Classes\CATFile\shell\open\command - Default = %SystemRoot%\system32\rundll32.exe cryptext.dll,CryptExtOpenCAT %1 HKLM\SOFTWARE\Classes\CERFile\shell\open\command - Default = %SystemRoot%\system32\rundll32.exe cryptext.dll,CryptExtOpenCER %1 HKLM\SOFTWARE\Classes\CRLFile\shell\open\command - Default = %SystemRoot%\system32\rundll32.exe cryptext.dll,CryptExtOpenCRL %1 HKLM\SOFTWARE\Classes\CertificateStoreFile\shell\open\command - Default = %SystemRoot%\system32\rundll32.exe cryptext.dll,CryptExtOpenSTR %1 HKLM\SOFTWARE\Classes\CompressedFolder\shell\open\command - Default = %SystemRoot%\Explorer.exe /idlist,%I,%L HKLM\SOFTWARE\Classes\DLNA-PLAYSINGLE\shell\open\command - Default = "%ProgramFiles(x86)%\Windows Media Player\wmplayer.exe" "%L" HKLM\SOFTWARE\Classes\Diagnostic.Cabinet\shell\open\command - Default = %SystemRoot%\system32\msdt.exe /cab "%1" HKLM\SOFTWARE\Classes\Diagnostic.Config\shell\open\command - Default = %SystemRoot%\system32\msdt.exe /path "%1" HKLM\SOFTWARE\Classes\Diagnostic.Document\shell\open\command - Default = %SystemRoot%\system32\msdt.exe /path "%1" HKLM\SOFTWARE\Classes\Diagnostic.Perfmon.Config\shell\open\command - Default = %SystemRoot%\system32\perfmon /sys /load "%1" HKLM\SOFTWARE\Classes\Diagnostic.Perfmon.Document\shell\open\command - Default = %SystemRoot%\system32\perfmon /sys /open "%1" HKLM\SOFTWARE\Classes\Diagnostic.Resmon.Config\shell\open\command - Default = %SystemRoot%\system32\perfmon /res /load "%1" HKLM\SOFTWARE\Classes\Explorer.AssocActionId.BurnSelection\shell\open\command - Default = %SystemRoot%\explorer.exe HKLM\SOFTWARE\Classes\Explorer.AssocActionId.EraseDisc\shell\open\command - Default = %SystemRoot%\explorer.exe HKLM\SOFTWARE\Classes\Explorer.AssocActionId.ZipSelection\shell\open\command - Default = %SystemRoot%\explorer.exe HKLM\SOFTWARE\Classes\Explorer.AssocProtocol.search-ms\shell\open\command - Default = %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L HKLM\SOFTWARE\Classes\FaxCover.Document\shell\open\command - Default = C:\Windows\System32\fxscover.exe "%1" HKLM\SOFTWARE\Classes\Folder\shell\open\command - Default = %SystemRoot%\Explorer.exe HKLM\SOFTWARE\Classes\GPMGMT.MigTable\shell\open\command - Default = "%SystemRoot%\System32\mtedit.exe" "%1" HKLM\SOFTWARE\Classes\HPHDDCheck\shell\open\command - Default = "C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPHDDCheck\HPHDDCheck.exe" %1 HKLM\SOFTWARE\Classes\HPNetworkCheck\shell\open\command - Default = "C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheck.exe" %1 HKLM\SOFTWARE\Classes\HPODDCheck\shell\open\command - Default = "C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPODDCheck\HPODDCheck.exe" %1 HKLM\SOFTWARE\Classes\HPSALauncher\shell\open\command - Default = "C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPSALauncher.exe" %1 HKLM\SOFTWARE\Classes\HPSAObject-diskcleanup-help\shell\open\command - Default = C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Solutions\LaunchMsHelpTopic.exe mshelp://windows/?id=1264bc24-72a8-48aa-84e3-a355327139d9 HKLM\SOFTWARE\Classes\HPSAObject-diskcleanup\shell\open\command - Default = c:\windows\system32\cleanmgr.exe HKLM\SOFTWARE\Classes\HPSAObjectMetrics\shell\open\command - Default = "C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Solutions\HPSAObjectMetrics.exe" %1 HKLM\SOFTWARE\Classes\HPSupportAssistant\shell\open\command - Default = "C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe" %1 HKLM\SOFTWARE\Classes\HPSystemBoardCheck\shell\open\command - Default = "C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPSystemBoardCheck\HPSystemBoardCheck.exe" %1 HKLM\SOFTWARE\Classes\HPTVTunerCheck\shell\open\command - Default = "C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPTVTunerCheck\HPTVTunerCheck.exe" %1 HKLM\SOFTWARE\Classes\HPTouchCheck\shell\open\command - Default = "C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPTouchCheck\HPTouchCheck.exe" %1 HKLM\SOFTWARE\Classes\HPVideoCheck\shell\open\command - Default = "C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPVideoCheck\HPVideoCheck.exe" %1 HKLM\SOFTWARE\Classes\HPWebcamCheck\shell\open\command - Default = "C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWebcamCheck\HPWebcamCheck.exe" %1 HKLM\SOFTWARE\Classes\IE.AssocFile.HTM\shell\open\command - Default = "C:\Program Files\Internet Explorer\iexplore.exe" %1 HKLM\SOFTWARE\Classes\IE.AssocFile.MHT\shell\open\command - Default = "C:\Program Files\Internet Explorer\iexplore.exe" %1 HKLM\SOFTWARE\Classes\IE.AssocFile.PARTIAL\shell\open\command - Default = "C:\Program Files\Internet Explorer\iexplore.exe" %1 HKLM\SOFTWARE\Classes\IE.AssocFile.SVG\shell\open\command - Default = "C:\Program Files\Internet Explorer\iexplore.exe" %1 HKLM\SOFTWARE\Classes\IE.AssocFile.URL\shell\open\command - Default = "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l HKLM\SOFTWARE\Classes\IE.AssocFile.WEBSITE\shell\open\command - Default = "C:\Program Files\Internet Explorer\iexplore.exe" -w "%l" %* HKLM\SOFTWARE\Classes\IE.AssocFile.XHT\shell\open\command - Default = "C:\Program Files\Internet Explorer\iexplore.exe" %1 HKLM\SOFTWARE\Classes\IE.FTP\shell\open\command - Default = "C:\Program Files\Internet Explorer\iexplore.exe" %1 HKLM\SOFTWARE\Classes\IE.HTTPS\shell\open\command - Default = "C:\Program Files\Internet Explorer\iexplore.exe" %1 HKLM\SOFTWARE\Classes\IE.HTTP\shell\open\command - Default = "C:\Program Files\Internet Explorer\iexplore.exe" %1 HKLM\SOFTWARE\Classes\IMEDictionaryCompiler\shell\open\command - Default = "%WINDIR%\system32\IME\SHARED\imewdbld.exe" "%1" %* HKLM\SOFTWARE\Classes\InternetShortcut\shell\open\command - Default = "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l HKLM\SOFTWARE\Classes\IrfanView.aif\shell\open\command - Default = "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1" HKLM\SOFTWARE\Classes\IrfanView.ani\shell\open\command - Default = "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1" HKLM\SOFTWARE\Classes\IrfanView.asf\shell\open\command - Default = "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1" HKLM\SOFTWARE\Classes\IrfanView.au\shell\open\command - Default = "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1" HKLM\SOFTWARE\Classes\IrfanView.avi\shell\open\command - Default = "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1" HKLM\SOFTWARE\Classes\IrfanView.b3d\shell\open\command - Default = "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1" HKLM\SOFTWARE\Classes\IrfanView.bmp\shell\open\command - Default = "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1" HKLM\SOFTWARE\Classes\IrfanView.cam\shell\open\command - Default = "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1" HKLM\SOFTWARE\Classes\IrfanView.clp\shell\open\command - Default = "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1" HKLM\SOFTWARE\Classes\IrfanView.cr2\shell\open\command - Default = "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1" HKLM\SOFTWARE\Classes\IrfanView.crw\shell\open\command - Default = "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1" HKLM\SOFTWARE\Classes\IrfanView.cur\shell\open\command - Default = "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1" HKLM\SOFTWARE\Classes\IrfanView.dcm\shell\open\command - Default = "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1" HKLM\SOFTWARE\Classes\IrfanView.dcx\shell\open\command - Default = "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1" HKLM\SOFTWARE\Classes\IrfanView.dds\shell\open\command - Default = "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1" HKLM\SOFTWARE\Classes\IrfanView.djvu\shell\open\command - Default = "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1" HKLM\SOFTWARE\Classes\IrfanView.dxf\shell\open\command - Default = "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1" HKLM\SOFTWARE\Classes\IrfanView.ecw\shell\open\command - Default = "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1" HKLM\SOFTWARE\Classes\IrfanView.emf\shell\open\command - Default = "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1" HKLM\SOFTWARE\Classes\IrfanView.eps\shell\open\command - Default = "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1" HKLM\SOFTWARE\Classes\IrfanView.exr\shell\open\command - Default = "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1" HKLM\SOFTWARE\Classes\IrfanView.flv\shell\open\command - Default = "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1" HKLM\SOFTWARE\Classes\IrfanView.fpx\shell\open\command - Default = "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1" HKLM\SOFTWARE\Classes\IrfanView.g3\shell\open\command - Default = "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1" HKLM\SOFTWARE\Classes\IrfanView.gif\shell\open\command - Default = "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1" HKLM\SOFTWARE\Classes\IrfanView.hdp\shell\open\command - Default = "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1" HKLM\SOFTWARE\Classes\IrfanView.icl\shell\open\command - Default = "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1" HKLM\SOFTWARE\Classes\IrfanView.ico\shell\open\command - Default = "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1" HKLM\SOFTWARE\Classes\IrfanView.iff\shell\open\command - Default = "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1" HKLM\SOFTWARE\Classes\IrfanView.img\shell\open\command - Default = "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1" HKLM\SOFTWARE\Classes\IrfanView.jls\shell\open\command - Default = "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1" HKLM\SOFTWARE\Classes\IrfanView.jng\shell\open\command - Default = "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1" HKLM\SOFTWARE\Classes\IrfanView.jp2\shell\open\command - Default = "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1" HKLM\SOFTWARE\Classes\IrfanView.jpg\shell\open\command - Default = "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1" HKLM\SOFTWARE\Classes\IrfanView.jpm\shell\open\command - Default = "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1" HKLM\SOFTWARE\Classes\IrfanView.kdc\shell\open\command - Default = "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1" HKLM\SOFTWARE\Classes\IrfanView.med\shell\open\command - Default = "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1" HKLM\SOFTWARE\Classes\IrfanView.mid\shell\open\command - Default = "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1" HKLM\SOFTWARE\Classes\IrfanView.mng\shell\open\command - Default = "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1" HKLM\SOFTWARE\Classes\IrfanView.mov\shell\open\command - Default = "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1" HKLM\SOFTWARE\Classes\IrfanView.mp3\shell\open\command - Default = "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1" HKLM\SOFTWARE\Classes\IrfanView.mpe\shell\open\command - Default = "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1" HKLM\SOFTWARE\Classes\IrfanView.mpg\shell\open\command - Default = "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1" HKLM\SOFTWARE\Classes\IrfanView.ogg\shell\open\command - Default = "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1" HKLM\SOFTWARE\Classes\IrfanView.pbm\shell\open\command - Default = "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1" HKLM\SOFTWARE\Classes\IrfanView.pcd\shell\open\command - Default = "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1" HKLM\SOFTWARE\Classes\IrfanView.pcx\shell\open\command - Default = "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1" HKLM\SOFTWARE\Classes\IrfanView.pgm\shell\open\command - Default = "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1" HKLM\SOFTWARE\Classes\IrfanView.png\shell\open\command - Default = "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1" HKLM\SOFTWARE\Classes\IrfanView.ppm\shell\open\command - Default = "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1" HKLM\SOFTWARE\Classes\IrfanView.psd\shell\open\command - Default = "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1" HKLM\SOFTWARE\Classes\IrfanView.psp\shell\open\command - Default = "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1" HKLM\SOFTWARE\Classes\IrfanView.ra\shell\open\command - Default = "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1" HKLM\SOFTWARE\Classes\IrfanView.ras\shell\open\command - Default = "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1" HKLM\SOFTWARE\Classes\IrfanView.raw\shell\open\command - Default = "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1" HKLM\SOFTWARE\Classes\IrfanView.rle\shell\open\command - Default = "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1" HKLM\SOFTWARE\Classes\IrfanView.rmi\shell\open\command - Default = "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1" HKLM\SOFTWARE\Classes\IrfanView.sff\shell\open\command - Default = "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1" HKLM\SOFTWARE\Classes\IrfanView.sfw\shell\open\command - Default = "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1" HKLM\SOFTWARE\Classes\IrfanView.sgi\shell\open\command - Default = "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1" HKLM\SOFTWARE\Classes\IrfanView.sid\shell\open\command - Default = "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1" HKLM\SOFTWARE\Classes\IrfanView.swf\shell\open\command - Default = "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1" HKLM\SOFTWARE\Classes\IrfanView.tga\shell\open\command - Default = "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1" HKLM\SOFTWARE\Classes\IrfanView.tif\shell\open\command - Default = "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1" HKLM\SOFTWARE\Classes\IrfanView.ttf\shell\open\command - Default = "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1" HKLM\SOFTWARE\Classes\IrfanView.wav\shell\open\command - Default = "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1" HKLM\SOFTWARE\Classes\IrfanView.wbmp\shell\open\command - Default = "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1" HKLM\SOFTWARE\Classes\IrfanView.webp\shell\open\command - Default = "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1" HKLM\SOFTWARE\Classes\IrfanView.wma\shell\open\command - Default = "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1" HKLM\SOFTWARE\Classes\IrfanView.wmf\shell\open\command - Default = "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1" HKLM\SOFTWARE\Classes\IrfanView.wmv\shell\open\command - Default = "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1" HKLM\SOFTWARE\Classes\IrfanView.xbm\shell\open\command - Default = "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1" HKLM\SOFTWARE\Classes\IrfanView.xpm\shell\open\command - Default = "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1" HKLM\SOFTWARE\Classes\IrfanView\shell\open\command - Default = "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1" HKLM\SOFTWARE\Classes\JSEFile\shell\open\command - Default = C:\Windows\System32\WScript.exe "%1" %* HKLM\SOFTWARE\Classes\JSFile\shell\open\command - Default = C:\Windows\System32\WScript.exe "%1" %* HKLM\SOFTWARE\Classes\LDAP\shell\open\command - Default = "%ProgramFiles%\Windows Mail\wab.exe" "/ldap:%1" HKLM\SOFTWARE\Classes\MMS\shell\open\command - Default = "%ProgramFiles(x86)%\Windows Media Player\wmplayer.exe" "%L" HKLM\SOFTWARE\Classes\MSDASC\shell\open\command - Default = Rundll32.exe "%CommonProgramFiles%\System\OLE DB\oledb32.dll",OpenDSLFile %1 HKLM\SOFTWARE\Classes\MSInfoFile\shell\open\command - Default = %SystemRoot%\system32\msinfo32.exe "%1" HKLM\SOFTWARE\Classes\MSSppLicenseFile\shell\open\command - Default = "iexplore.exe" "%1" HKLM\SOFTWARE\Classes\MacromediaFlashPaper.MacromediaFlashPaper\shell\open\command - Default = "%ProgramFiles%\Internet Explorer\iexplore.exe" "%1" HKLM\SOFTWARE\Classes\Microsoft.PowerShellConsole.1\shell\open\command - Default = "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -p "%1" HKLM\SOFTWARE\Classes\Microsoft.PowerShellData.1\shell\open\command - Default = "C:\Windows\System32\notepad.exe" "%1" HKLM\SOFTWARE\Classes\Microsoft.PowerShellModule.1\shell\open\command - Default = "C:\Windows\System32\notepad.exe" "%1" HKLM\SOFTWARE\Classes\Microsoft.PowerShellScript.1\shell\open\command - Default = "C:\Windows\System32\notepad.exe" "%1" HKLM\SOFTWARE\Classes\Microsoft.System.Update.1\shell\open\command - Default = "%systemroot%\system32\wusa.exe" "%1" %* HKLM\SOFTWARE\Classes\Microsoft.Website\shell\open\command - Default = "C:\Program Files\Internet Explorer\iexplore.exe" -w "%l" %* HKLM\SOFTWARE\Classes\Microsoft.Workfolders\shell\open\command - Default = C:\Windows\System32\control /name Microsoft.WorkFolders HKLM\SOFTWARE\Classes\Msi.Package\shell\open\command - Default = "%SystemRoot%\System32\msiexec.exe" /i "%1" %* HKLM\SOFTWARE\Classes\Msi.Patch\shell\open\command - Default = "%SystemRoot%\System32\msiexec.exe" /p "%1" %* HKLM\SOFTWARE\Classes\P7RFile\shell\open\command - Default = %SystemRoot%\system32\rundll32.exe cryptext.dll,CryptExtOpenP7R %1 HKLM\SOFTWARE\Classes\P7SFile\shell\open\command - Default = %SystemRoot%\system32\\rundll32.exe cryptext.dll,CryptExtOpenPKCS7 %1 HKLM\SOFTWARE\Classes\PSGRedirector-HPSALowDiskEx1\shell\open\command - Default = C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Solutions\PSGRedirector.exe NextUrlPlaceHolder HPSALowDiskEx1 HKLM\SOFTWARE\Classes\PSGRedirector-HPSALowDiskEx2\shell\open\command - Default = C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Solutions\PSGRedirector.exe NextUrlPlaceHolder HPSALowDiskEx2 HKLM\SOFTWARE\Classes\PSGRedirector-HPSALowDiskEx3\shell\open\command - Default = C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Solutions\PSGRedirector.exe NextUrlPlaceHolder HPSALowDiskEx3 HKLM\SOFTWARE\Classes\PSGRedirector-HPSALowDiskEx\shell\open\command - Default = C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Solutions\PSGRedirector.exe NextUrlPlaceHolder HPSALowDiskEx HKLM\SOFTWARE\Classes\PSGRedirector\shell\open\command - Default = "C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Solutions\PSGRedirector.exe" %1 HKLM\SOFTWARE\Classes\Paint.Picture\shell\open\command - Default = %SystemRoot%\System32\rundll32.exe "%ProgramFiles%\Windows Photo Viewer\PhotoViewer.dll", ImageView_Fullscreen %1 HKLM\SOFTWARE\Classes\PerfFile\shell\open\command - Default = %SystemRoot%\system32\mmc.exe %systemroot%\system32\perfmon.msc /F "%1" HKLM\SOFTWARE\Classes\PhotoViewer.FileAssoc.Bitmap\shell\open\command - Default = %SystemRoot%\System32\rundll32.exe "%ProgramFiles%\Windows Photo Viewer\PhotoViewer.dll", ImageView_Fullscreen %1 HKLM\SOFTWARE\Classes\PhotoViewer.FileAssoc.JFIF\shell\open\command - Default = %SystemRoot%\System32\rundll32.exe "%ProgramFiles%\Windows Photo Viewer\PhotoViewer.dll", ImageView_Fullscreen %1 HKLM\SOFTWARE\Classes\PhotoViewer.FileAssoc.Jpeg\shell\open\command - Default = %SystemRoot%\System32\rundll32.exe "%ProgramFiles%\Windows Photo Viewer\PhotoViewer.dll", ImageView_Fullscreen %1 HKLM\SOFTWARE\Classes\PhotoViewer.FileAssoc.Png\shell\open\command - Default = %SystemRoot%\System32\rundll32.exe "%ProgramFiles%\Windows Photo Viewer\PhotoViewer.dll", ImageView_Fullscreen %1 HKLM\SOFTWARE\Classes\PhotoViewer.FileAssoc.Tiff\shell\open\command - Default = %SystemRoot%\System32\rundll32.exe "%ProgramFiles%\Windows Photo Viewer\PhotoViewer.dll", ImageView_Fullscreen %1 HKLM\SOFTWARE\Classes\PhotoViewer.FileAssoc.Wdp\shell\open\command - Default = %SystemRoot%\System32\rundll32.exe "%ProgramFiles%\Windows Photo Viewer\PhotoViewer.dll", ImageView_Fullscreen %1 HKLM\SOFTWARE\Classes\RDP.File\shell\open\command - Default = "%systemroot%\system32\mstsc.exe" "%1" HKLM\SOFTWARE\Classes\RemoteAssistance.1\shell\open\command - Default = "%systemRoot%\system32\msra.exe" -openfile "%1" HKLM\SOFTWARE\Classes\SHCmdFile\shell\open\command - Default = %SystemRoot%\explorer.exe HKLM\SOFTWARE\Classes\SPCFile\shell\open\command - Default = %SystemRoot%\system32\rundll32.exe cryptext.dll,CryptExtOpenPKCS7 %1 HKLM\SOFTWARE\Classes\SavedDsQuery\shell\open\command - Default = %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\dsquery.dll,OpenSavedDsQuery %1 HKLM\SOFTWARE\Classes\TIFImage.Document\shell\open\command - Default = %SystemRoot%\System32\rundll32.exe "%ProgramFiles%\Windows Photo Viewer\PhotoViewer.dll", ImageView_Fullscreen %1 HKLM\SOFTWARE\Classes\Undecided\shell\open\command - Default = %SystemRoot%\system32\OpenWith.exe "%1" HKLM\SOFTWARE\Classes\Unknown\shell\open\command - Default = %SystemRoot%\system32\OpenWith.exe "%1" HKLM\SOFTWARE\Classes\VBEFile\shell\open\command - Default = "%SystemRoot%\System32\WScript.exe" "%1" %* HKLM\SOFTWARE\Classes\VBSFile\shell\open\command - Default = "%SystemRoot%\System32\WScript.exe" "%1" %* HKLM\SOFTWARE\Classes\WAB.AssocProtocol.LDAP\shell\open\command - Default = "%ProgramFiles%\Windows Mail\wab.exe" "/ldap:%1" HKLM\SOFTWARE\Classes\WMP.DVR-MSFile\shell\open\command - Default = "%ProgramFiles(x86)%\Windows Media Player\wmplayer.exe" /Open "%L" HKLM\SOFTWARE\Classes\WMP.WTVFile\shell\open\command - Default = "%ProgramFiles(x86)%\Windows Media Player\wmplayer.exe" /Open "%L" HKLM\SOFTWARE\Classes\WMP11.AssocFile.3G2\shell\open\command - Default = "%ProgramFiles(x86)%\Windows Media Player\wmplayer.exe" /prefetch:6 /Open "%L" HKLM\SOFTWARE\Classes\WMP11.AssocFile.3GP\shell\open\command - Default = "%ProgramFiles(x86)%\Windows Media Player\wmplayer.exe" /prefetch:6 /Open "%L" HKLM\SOFTWARE\Classes\WMP11.AssocFile.ADTS\shell\open\command - Default = "%ProgramFiles(x86)%\Windows Media Player\wmplayer.exe" /prefetch:6 /Open "%L" HKLM\SOFTWARE\Classes\WMP11.AssocFile.AIFF\shell\open\command - Default = "%ProgramFiles(x86)%\Windows Media Player\wmplayer.exe" /Open "%L" HKLM\SOFTWARE\Classes\WMP11.AssocFile.ASF\shell\open\command - Default = "%ProgramFiles(x86)%\Windows Media Player\wmplayer.exe" /prefetch:7 /Open "%L" HKLM\SOFTWARE\Classes\WMP11.AssocFile.ASX\shell\open\command - Default = "%ProgramFiles(x86)%\Windows Media Player\wmplayer.exe" /Open "%L" HKLM\SOFTWARE\Classes\WMP11.AssocFile.AU\shell\open\command - Default = "%ProgramFiles(x86)%\Windows Media Player\wmplayer.exe" /Open "%L" HKLM\SOFTWARE\Classes\WMP11.AssocFile.AVI\shell\open\command - Default = "%ProgramFiles(x86)%\Windows Media Player\wmplayer.exe" /prefetch:8 /Open "%L" HKLM\SOFTWARE\Classes\WMP11.AssocFile.CDA\shell\open\command - Default = "%ProgramFiles(x86)%\Windows Media Player\wmplayer.exe" /Open "%L" HKLM\SOFTWARE\Classes\WMP11.AssocFile.M2TS\shell\open\command - Default = "%ProgramFiles(x86)%\Windows Media Player\wmplayer.exe" /prefetch:12 /Open "%L" HKLM\SOFTWARE\Classes\WMP11.AssocFile.M4A\shell\open\command - Default = "%ProgramFiles(x86)%\Windows Media Player\wmplayer.exe" /prefetch:6 /Open "%L" HKLM\SOFTWARE\Classes\WMP11.AssocFile.MIDI\shell\open\command - Default = "%ProgramFiles(x86)%\Windows Media Player\wmplayer.exe" /Open "%L" HKLM\SOFTWARE\Classes\WMP11.AssocFile.MOV\shell\open\command - Default = "%ProgramFiles(x86)%\Windows Media Player\wmplayer.exe" /prefetch:6 /Open "%L" HKLM\SOFTWARE\Classes\WMP11.AssocFile.MP3\shell\open\command - Default = "%ProgramFiles(x86)%\Windows Media Player\wmplayer.exe" /prefetch:6 /Open "%L" HKLM\SOFTWARE\Classes\WMP11.AssocFile.MP4\shell\open\command - Default = "%ProgramFiles(x86)%\Windows Media Player\wmplayer.exe" /prefetch:6 /Open "%L" HKLM\SOFTWARE\Classes\WMP11.AssocFile.MPEG\shell\open\command - Default = "%ProgramFiles(x86)%\Windows Media Player\wmplayer.exe" /prefetch:9 /Open "%L" HKLM\SOFTWARE\Classes\WMP11.AssocFile.TTS\shell\open\command - Default = "%ProgramFiles(x86)%\Windows Media Player\wmplayer.exe" /prefetch:12 /Open "%L" HKLM\SOFTWARE\Classes\WMP11.AssocFile.WAV\shell\open\command - Default = "%ProgramFiles(x86)%\Windows Media Player\wmplayer.exe" /Open "%L" HKLM\SOFTWARE\Classes\WMP11.AssocFile.WAX\shell\open\command - Default = "%ProgramFiles(x86)%\Windows Media Player\wmplayer.exe" /Open "%L" HKLM\SOFTWARE\Classes\WMP11.AssocFile.WMD\shell\open\command - Default = "%ProgramFiles(x86)%\Windows Media Player\wmplayer.exe" /WMPackage:"%L" HKLM\SOFTWARE\Classes\WMP11.AssocFile.WMS\shell\open\command - Default = "%ProgramFiles(x86)%\Windows Media Player\wmplayer.exe" /layout:"%L" HKLM\SOFTWARE\Classes\WMP11.AssocFile.WMV\shell\open\command - Default = "%ProgramFiles(x86)%\Windows Media Player\wmplayer.exe" /prefetch:7 /Open "%L" HKLM\SOFTWARE\Classes\WMP11.AssocFile.WMZ\shell\open\command - Default = "%ProgramFiles(x86)%\Windows Media Player\wmplayer.exe" /layout:"%L" HKLM\SOFTWARE\Classes\WMP11.AssocFile.WPL\shell\open\command - Default = "%ProgramFiles(x86)%\Windows Media Player\wmplayer.exe" /Open "%L" HKLM\SOFTWARE\Classes\WMP11.AssocFile.WVX\shell\open\command - Default = "%ProgramFiles(x86)%\Windows Media Player\wmplayer.exe" /Open "%L" HKLM\SOFTWARE\Classes\WMP11.AssocFile.m3u\shell\open\command - Default = "%ProgramFiles(x86)%\Windows Media Player\wmplayer.exe" /prefetch:6 /Open "%L" HKLM\SOFTWARE\Classes\WMP11.AssocFile.wma\shell\open\command - Default = "%ProgramFiles(x86)%\Windows Media Player\wmplayer.exe" /prefetch:5 /Open "%L" HKLM\SOFTWARE\Classes\WMP11.AssocProtocol.DLNA-PLAYSINGLE\shell\open\command - Default = "%ProgramFiles(x86)%\Windows Media Player\wmplayer.exe" "%L" HKLM\SOFTWARE\Classes\WMP11.AssocProtocol.MMS\shell\open\command - Default = "%ProgramFiles(x86)%\Windows Media Player\wmplayer.exe" "%L" HKLM\SOFTWARE\Classes\WPDContextMenu.Url\shell\open\command - Default = "%SystemRoot%\System32\rundll32.exe" "%SystemRoot%\System32\ieframe.dll",OpenURL %l HKLM\SOFTWARE\Classes\WSFFile\shell\open\command - Default = "%SystemRoot%\System32\WScript.exe" "%1" %* HKLM\SOFTWARE\Classes\WSHFile\shell\open\command - Default = "%SystemRoot%\System32\WScript.exe" "%1" %* HKLM\SOFTWARE\Classes\WinRAR.REV\shell\open\command - Default = "C:\Program Files\WinRAR\WinRAR.exe" "%1" HKLM\SOFTWARE\Classes\WinRAR.ZIP\shell\open\command - Default = "C:\Program Files\WinRAR\WinRAR.exe" "%1" HKLM\SOFTWARE\Classes\WinRAR\shell\open\command - Default = "C:\Program Files\WinRAR\WinRAR.exe" "%1" HKLM\SOFTWARE\Classes\Windows.CompositeFont\shell\open\command - Default = "%SystemRoot%\System32\notepad.exe" "%1" HKLM\SOFTWARE\Classes\Windows.XPSReachViewer\shell\open\command - Default = %SystemRoot%\System32\xpsrchvw.exe "%1" %* HKLM\SOFTWARE\Classes\Windows.XamlDocument\shell\open\command - Default = "C:\Windows\System32\PresentationHost.exe" "%1" %* HKLM\SOFTWARE\Classes\Windows.Xbap\shell\open\command - Default = "C:\Windows\System32\PresentationHost.exe" "%1" %* HKLM\SOFTWARE\Classes\Wordpad.Document.1\shell\open\command - Default = "%ProgramFiles%\Windows NT\Accessories\WORDPAD.EXE" "%1" HKLM\SOFTWARE\Classes\batfile\shell\open\command - Default = "%1" %* HKLM\SOFTWARE\Classes\bdlaunch\shell\open\command - Default = "C:\Program Files\Bitdefender\Bitdefender\bdlaunch.exe" "%1" HKLM\SOFTWARE\Classes\certificate_wab_auto_file\shell\open\command - Default = "%ProgramFiles%\Windows Mail\wab.exe" /certificate "%1" HKLM\SOFTWARE\Classes\chm.file\shell\open\command - Default = "%SystemRoot%\hh.exe" %1 HKLM\SOFTWARE\Classes\cmdfile\shell\open\command - Default = "%1" %* HKLM\SOFTWARE\Classes\comfile\shell\open\command - Default = "%1" %* HKLM\SOFTWARE\Classes\contact_wab_auto_file\shell\open\command - Default = "%ProgramFiles%\Windows Mail\wab.exe" /contact "%1" HKLM\SOFTWARE\Classes\desktopthemepackfile\shell\open\command - Default = %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\themecpl.dll,OpenThemeAction %1 HKLM\SOFTWARE\Classes\docxfile\shell\open\command - Default = "%ProgramFiles%\Windows NT\Accessories\WORDPAD.EXE" "%1" HKLM\SOFTWARE\Classes\emffile\shell\open\command - Default = "%systemroot%\system32\mspaint.exe" "%1" HKLM\SOFTWARE\Classes\evtfile\shell\open\command - Default = %SystemRoot%\system32\eventvwr.exe /l:"%1" HKLM\SOFTWARE\Classes\evtxfile\shell\open\command - Default = %SystemRoot%\system32\eventvwr.exe /l:"%1" HKLM\SOFTWARE\Classes\exefile\shell\open\command - Default = "%1" %* HKLM\SOFTWARE\Classes\ftp\shell\open\command - Default = "C:\Program Files\Internet Explorer\iexplore.exe" %1 HKLM\SOFTWARE\Classes\giffile\shell\open\command - Default = "C:\Program Files\Internet Explorer\iexplore.exe" %1 HKLM\SOFTWARE\Classes\group_wab_auto_file\shell\open\command - Default = "%ProgramFiles%\Windows Mail\wab.exe" /Group "%1" HKLM\SOFTWARE\Classes\hlpfile\shell\open\command - Default = %SystemRoot%\winhlp32.exe %1 HKLM\SOFTWARE\Classes\htafile\shell\open\command - Default = C:\Windows\SysWOW64\mshta.exe "%1" {1E460BD7-F1C3-4B2E-88BF-4E770A288AF5}%U{1E460BD7-F1C3-4B2E-88BF-4E770A288AF5} %* HKLM\SOFTWARE\Classes\htmlfile\shell\open\command - Default = "C:\Program Files\Internet Explorer\iexplore.exe" %1 HKLM\SOFTWARE\Classes\http\shell\open\command - Default = "C:\Program Files\Internet Explorer\iexplore.exe" %1 HKLM\SOFTWARE\Classes\https\shell\open\command - Default = "C:\Program Files\Internet Explorer\iexplore.exe" %1 HKLM\SOFTWARE\Classes\icofile\shell\open\command - Default = %SystemRoot%\System32\rundll32.exe "%ProgramFiles%\Windows Photo Viewer\PhotoViewer.dll", ImageView_Fullscreen %1 HKLM\SOFTWARE\Classes\imesxfile\shell\open\command - Default = "%WINDIR%\system32\IME\SHARED\imesearch.exe" "%1" HKLM\SOFTWARE\Classes\inffile\shell\open\command - Default = %SystemRoot%\system32\NOTEPAD.EXE %1 HKLM\SOFTWARE\Classes\inifile\shell\open\command - Default = %SystemRoot%\system32\NOTEPAD.EXE %1 HKLM\SOFTWARE\Classes\jntfile\shell\open\command - Default = "%ProgramFiles%\Windows Journal\Journal.exe" "%1" HKLM\SOFTWARE\Classes\jpegfile\shell\open\command - Default = %SystemRoot%\System32\rundll32.exe "%ProgramFiles%\Windows Photo Viewer\PhotoViewer.dll", ImageView_Fullscreen %1 HKLM\SOFTWARE\Classes\jtpfile\shell\open\command - Default = "%ProgramFiles%\Windows Journal\Journal.exe" "%1" HKLM\SOFTWARE\Classes\mhtmlfile\shell\open\command - Default = "C:\Program Files\Internet Explorer\iexplore.exe" %1 HKLM\SOFTWARE\Classes\migfile\shell\open\command - Default = "C:\Windows\System32\migwiz\migwiz.exe" /Restore "%1" HKLM\SOFTWARE\Classes\mscfile\shell\open\command - Default = %SystemRoot%\system32\mmc.exe "%1" %* HKLM\SOFTWARE\Classes\msstylesfile\shell\open\command - Default = %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,Control_RunDLL %SystemRoot%\system32\desk.cpl desk,@Appearance /Action:OpenMSTheme /file:"%1" HKLM\SOFTWARE\Classes\odtfile\shell\open\command - Default = "%ProgramFiles%\Windows NT\Accessories\WORDPAD.EXE" "%1" HKLM\SOFTWARE\Classes\opensearchdescription\shell\open\command - Default = %SystemRoot%\explorer.exe HKLM\SOFTWARE\Classes\opensearchfilefolderresult\shell\open\command - Default = HKLM\SOFTWARE\Classes\opensearchresult\shell\open\command - Default = HKLM\SOFTWARE\Classes\pbkfile\shell\open\command - Default = %SystemRoot%\system32\rasphone.exe -f "%1" HKLM\SOFTWARE\Classes\piffile\shell\open\command - Default = "%1" %* HKLM\SOFTWARE\Classes\pjpegfile\shell\open\command - Default = %SystemRoot%\System32\rundll32.exe "%ProgramFiles%\Windows Photo Viewer\PhotoViewer.dll", ImageView_Fullscreen %1 HKLM\SOFTWARE\Classes\pngfile\shell\open\command - Default = %SystemRoot%\System32\rundll32.exe "%ProgramFiles%\Windows Photo Viewer\PhotoViewer.dll", ImageView_Fullscreen %1 HKLM\SOFTWARE\Classes\prffile\shell\open\command - Default = "%SystemRoot%\System32\rundll32.exe" "%SystemRoot%\System32\msrating.dll",ClickedOnPRF %1 HKLM\SOFTWARE\Classes\ratfile\shell\open\command - Default = "%SystemRoot%\System32\rundll32.exe" "%SystemRoot%\System32\msrating.dll",ClickedOnRAT %1 HKLM\SOFTWARE\Classes\regedit\shell\open\command - Default = regedit.exe "%1" HKLM\SOFTWARE\Classes\regfile\shell\open\command - Default = regedit.exe "%1" HKLM\SOFTWARE\Classes\rlefile\shell\open\command - Default = "%systemroot%\system32\mspaint.exe" "%1" HKLM\SOFTWARE\Classes\rlogin\shell\open\command - Default = "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\url.dll",TelnetProtocolHandler %l HKLM\SOFTWARE\Classes\rtffile\shell\open\command - Default = "%ProgramFiles%\Windows NT\Accessories\WORDPAD.EXE" "%1" HKLM\SOFTWARE\Classes\scrfile\shell\open\command - Default = "%1" /S HKLM\SOFTWARE\Classes\scriptletfile\shell\open\command - Default = "C:\Windows\System32\NOTEPAD.EXE" "%1" HKLM\SOFTWARE\Classes\search-ms\shell\open\command - Default = %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L HKLM\SOFTWARE\Classes\search\shell\open\command - Default = %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L HKLM\SOFTWARE\Classes\svgfile\shell\open\command - Default = "C:\Program Files\Internet Explorer\iexplore.exe" %1 HKLM\SOFTWARE\Classes\telnet\shell\open\command - Default = "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\url.dll",TelnetProtocolHandler %l HKLM\SOFTWARE\Classes\textfile\shell\open\command - Default = "%ProgramFiles%\Windows NT\Accessories\WORDPAD.EXE" "%1" HKLM\SOFTWARE\Classes\themefile\shell\open\command - Default = %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\themecpl.dll,OpenThemeAction %1 HKLM\SOFTWARE\Classes\themepackfile\shell\open\command - Default = %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\themecpl.dll,OpenThemeAction %1 HKLM\SOFTWARE\Classes\tn3270\shell\open\command - Default = "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\url.dll",TelnetProtocolHandler %l HKLM\SOFTWARE\Classes\txtfile\shell\open\command - Default = %SystemRoot%\system32\NOTEPAD.EXE %1 HKLM\SOFTWARE\Classes\vcard_wab_auto_file\shell\open\command - Default = "%ProgramFiles%\Windows Mail\wab.exe" /vcard "%1" HKLM\SOFTWARE\Classes\wab_auto_file\shell\open\command - Default = "%ProgramFiles%\Windows Mail\wab.exe" /Import "%1" HKLM\SOFTWARE\Classes\wcxfile\shell\open\command - Default = "C:\Windows\System32\xwizard.exe" RunWizard /u {7940acf8-60ba-4213-a7c3-f3b400ee266d} /z%1 HKLM\SOFTWARE\Classes\wdpfile\shell\open\command - Default = %SystemRoot%\System32\rundll32.exe "%ProgramFiles%\Windows Photo Viewer\PhotoViewer.dll", ImageView_Fullscreen %1 HKLM\SOFTWARE\Classes\webpnpFile\shell\open\command - Default = %SystemRoot%\system32\wpnpinst.exe %1 HKLM\SOFTWARE\Classes\wmffile\shell\open\command - Default = "%systemroot%\system32\mspaint.exe" "%1" HKLM\SOFTWARE\Classes\xhtmlfile\shell\open\command - Default = "C:\Program Files\Internet Explorer\iexplore.exe" %1 HKLM\SOFTWARE\Classes\xmlfile\shell\open\command - Default = "C:\Program Files\Internet Explorer\iexplore.exe" %1 HKLM\SOFTWARE\Classes\xslfile\shell\open\command - Default = "C:\Program Files\Internet Explorer\iexplore.exe" %1 HKLM\SOFTWARE\Clients\Contacts\Address Book\Protocols\LDAP\shell\open\command - Default = "%ProgramFiles%\Windows Mail\wab.exe" "/ldap:%1" HKLM\SOFTWARE\Clients\Contacts\Address Book\Protocols\certificate_wab_auto_file\shell\open\command - Default = "%ProgramFiles%\Windows Mail\wab.exe" /certificate "%1" HKLM\SOFTWARE\Clients\Contacts\Address Book\Protocols\contact_wab_auto_file\shell\open\command - Default = "%ProgramFiles%\Windows Mail\wab.exe" /contact "%1" HKLM\SOFTWARE\Clients\Contacts\Address Book\Protocols\group_wab_auto_file\shell\open\command - Default = "%ProgramFiles%\Windows Mail\wab.exe" /Group "%1" HKLM\SOFTWARE\Clients\Contacts\Address Book\Protocols\vcard_wab_auto_file\shell\open\command - Default = "%ProgramFiles%\Windows Mail\wab.exe" /vcard "%1" HKLM\SOFTWARE\Clients\Contacts\Address Book\shell\open\command - Default = "%ProgramFiles%\Windows Mail\wab.exe" /showexisting HKLM\SOFTWARE\Clients\Mail\Hotmail\Protocols\mailto\shell\open\command - Default = %SystemRoot%\system32\rundll32.exe "%ProgramFiles%\Internet Explorer\hmmapi.dll",MailToProtocolHandler %1 HKLM\SOFTWARE\Clients\Mail\Hotmail\shell\open\command - Default = %systemRoot%\system32\rundll32.exe "%ProgramFiles%\Internet Explorer\hmmapi.dll",OpenInboxHandler HKLM\SOFTWARE\Clients\Mail\Windows Mail\Envelope\CLSID - Default = %ProgramFiles%\Windows Mail\msoe.dll HKLM\SOFTWARE\Clients\Media\Windows Media Player\shell\open\command - Default = %ProgramFiles(x86)%\Windows Media Player\wmplayer.exe HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\naom\command - Default = "C:\Program Files\Internet Explorer\iexplore.exe" -extoff HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command - Default = C:\Program Files\Internet Explorer\iexplore.exe HKLM\SOFTWARE\Wow6432Node\Clients\Contacts\Address Book\Protocols\LDAP\shell\open\command - Default = "%ProgramFiles%\Windows Mail\wab.exe" "/ldap:%1" HKLM\SOFTWARE\Wow6432Node\Clients\Contacts\Address Book\Protocols\certificate_wab_auto_file\shell\open\command - Default = "%ProgramFiles%\Windows Mail\wab.exe" /certificate "%1" HKLM\SOFTWARE\Wow6432Node\Clients\Contacts\Address Book\Protocols\contact_wab_auto_file\shell\open\command - Default = "%ProgramFiles%\Windows Mail\wab.exe" /contact "%1" HKLM\SOFTWARE\Wow6432Node\Clients\Contacts\Address Book\Protocols\group_wab_auto_file\shell\open\command - Default = "%ProgramFiles%\Windows Mail\wab.exe" /Group "%1" HKLM\SOFTWARE\Wow6432Node\Clients\Contacts\Address Book\Protocols\vcard_wab_auto_file\shell\open\command - Default = "%ProgramFiles%\Windows Mail\wab.exe" /vcard "%1" HKLM\SOFTWARE\Wow6432Node\Clients\Contacts\Address Book\shell\open\command - Default = "%ProgramFiles%\Windows Mail\wab.exe" /showexisting HKLM\SOFTWARE\Wow6432Node\Clients\Mail\Hotmail\Protocols\mailto\shell\open\command - Default = %SystemRoot%\system32\rundll32.exe "%ProgramFiles%\Internet Explorer\hmmapi.dll",MailToProtocolHandler %1 HKLM\SOFTWARE\Wow6432Node\Clients\Mail\Hotmail\shell\open\command - Default = %systemRoot%\system32\rundll32.exe "%ProgramFiles%\Internet Explorer\hmmapi.dll",OpenInboxHandler HKLM\SOFTWARE\Wow6432Node\Clients\Mail\Windows Mail\Envelope\CLSID - Default = %ProgramFiles%\Windows Mail\msoe.dll HKLM\SOFTWARE\Wow6432Node\Clients\Media\Windows Media Player\shell\open\command - Default = %ProgramFiles(x86)%\Windows Media Player\wmplayer.exe HKLM\SOFTWARE\Wow6432Node\Clients\StartMenuInternet\IEXPLORE.EXE\shell\naom\command - Default = "C:\Program Files\Internet Explorer\iexplore.exe" -extoff HKLM\SOFTWARE\Wow6432Node\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command - Default = C:\Program Files\Internet Explorer\iexplore.exe * Category: Network (192 items) HKLM\SYSTEM\CurrentControlSet\Control\Lsa\AccessProviders\Windows NT Access Provider - ProviderPath = %SystemRoot%\system32\ntmarta.dll HKLM\SYSTEM\CurrentControlSet\Control\NetworkProvider\Order - ProviderOrder = RDPNP,LanmanWorkstation,webclient HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders - SecurityProviders = credssp.dll HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL - EventLogging = 0x01 HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\CipherSuites - empty = (null) HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers - empty = (null) HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Hashes - empty = (null) HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\KeyExchangeAlgorithms - empty = (null) HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols - empty = (null) HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\SSL 2.0 - empty = (null) HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\SSL 2.0\Client - DisabledByDefault = 0x01 HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\SaslProfiles - GSSAPI = Kerberos HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\WDigest - UTF8SASL = 0x01 - Debuglevel = 0x00 - UTF8HTTP = 0x01 - Negotiate = 0x00 - DigestEncryptionAlgorithms = 3des,rc4 HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000001 - LibraryPath = %SystemRoot%\system32\napinsp.dll HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000002 - LibraryPath = %SystemRoot%\system32\pnrpnsp.dll HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000003 - LibraryPath = %SystemRoot%\system32\pnrpnsp.dll HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000004 - LibraryPath = %SystemRoot%\system32\NLAapi.dll HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000005 - LibraryPath = %SystemRoot%\System32\mswsock.dll HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000006 - LibraryPath = %SystemRoot%\System32\winrnr.dll HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001 - LibraryPath = %SystemRoot%\system32\napinsp.dll HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002 - LibraryPath = %SystemRoot%\system32\pnrpnsp.dll HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003 - LibraryPath = %SystemRoot%\system32\pnrpnsp.dll HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004 - LibraryPath = %SystemRoot%\system32\NLAapi.dll HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005 - LibraryPath = %SystemRoot%\System32\mswsock.dll HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006 - LibraryPath = %SystemRoot%\System32\winrnr.dll HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000001 - PackedCatalogItem = %SystemRoot%\system32\mswsock.dll HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000002 - PackedCatalogItem = %SystemRoot%\system32\mswsock.dll HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000003 - PackedCatalogItem = %SystemRoot%\system32\mswsock.dll HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000004 - PackedCatalogItem = %SystemRoot%\system32\mswsock.dll HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000005 - PackedCatalogItem = %SystemRoot%\system32\mswsock.dll HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000006 - PackedCatalogItem = %SystemRoot%\system32\mswsock.dll HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000007 - PackedCatalogItem = %SystemRoot%\system32\mswsock.dll HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000008 - PackedCatalogItem = %SystemRoot%\system32\mswsock.dll HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000009 - PackedCatalogItem = %SystemRoot%\system32\mswsock.dll HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000010 - PackedCatalogItem = %SystemRoot%\system32\mswsock.dll HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000001 - PackedCatalogItem = %SystemRoot%\system32\mswsock.dll HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000002 - PackedCatalogItem = %SystemRoot%\system32\mswsock.dll HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000003 - PackedCatalogItem = %SystemRoot%\system32\mswsock.dll HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000004 - PackedCatalogItem = %SystemRoot%\system32\mswsock.dll HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000005 - PackedCatalogItem = %SystemRoot%\system32\mswsock.dll HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000006 - PackedCatalogItem = %SystemRoot%\system32\mswsock.dll HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000007 - PackedCatalogItem = %SystemRoot%\system32\mswsock.dll HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000008 - PackedCatalogItem = %SystemRoot%\system32\mswsock.dll HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000009 - PackedCatalogItem = %SystemRoot%\system32\mswsock.dll HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000010 - PackedCatalogItem = %SystemRoot%\system32\mswsock.dll HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings - User Agent = Mozilla/4.0 (compatible; MSIE 8.0; Win32) - IE5_UA_Backup_Flag = 5.0 - ZonesSecurityUpgrade = F5 51 1E 7B 46 9F CE 01 - EnableNegotiate = 0x01 - ProxyEnable = 0x00 HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0 - empty = (null) HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache - empty = (null) HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content - CachePrefix = - CacheLimit = 0x3e800 (256000) HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies - CachePrefix = Cookie: - CacheLimit = 0x01 HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History - CachePrefix = Visited: - CacheLimit = 0x01 HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections - DefaultConnectionSettings = 46 00 00 00 02 00 00 00 09 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 - SavedLegacySettings = 46 00 00 00 0D 00 00 00 09 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones - empty = (null) HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0 - Default = - DisplayName = Computer - PMDisplayName = Computer [Protected Mode] - Description = Your computer - Icon = shell32.dll#0016 - LowIcon = inetcpl.cpl#005422 - CurrentLevel = 0x00 - Flags = 0x21 (33) - 1200 = 0x03 - 1400 = 0x01 HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1 - Default = - DisplayName = Local intranet - PMDisplayName = Local intranet [Protected Mode] - Description = This zone contains all Web sites that are on your organization's intranet. - Icon = shell32.dll#0018 - LowIcon = inetcpl.cpl#005423 - CurrentLevel = 0x00 - Flags = 0xdb (219) - 1200 = 0x03 - 1400 = 0x01 HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2 - Default = - DisplayName = Trusted sites - PMDisplayName = Trusted sites [Protected Mode] - Description = This zone contains Web sites that you trust not to damage your computer or data. - Icon = inetcpl.cpl#00004480 - LowIcon = inetcpl.cpl#005424 - CurrentLevel = 0x00 - Flags = 0x21 (33) - 1200 = 0x03 - 1400 = 0x01 HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3 - Default = - DisplayName = Internet - PMDisplayName = Internet [Protected Mode] - Description = This zone contains all Web sites you haven't placed in other zones - Icon = inetcpl.cpl#001313 - LowIcon = inetcpl.cpl#005425 - CurrentLevel = 0x00 - Flags = 0x21 (33) - 1200 = 0x03 - 1400 = 0x01 HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4 - Default = - DisplayName = Restricted sites - PMDisplayName = Restricted sites [Protected Mode] - Description = This zone contains Web sites that could potentially damage your computer or data. - Icon = inetcpl.cpl#00004481 - LowIcon = inetcpl.cpl#005426 - CurrentLevel = 0x00 - Flags = 0x21 (33) - 1200 = 0x03 - 1400 = 0x03 HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap - Default = - ProxyByPass = 0x01 - IntranetName = 0x01 - UNCAsIntranet = 0x01 - AutoDetect = 0x00 HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains - Default = HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults - Default = - http = 0x03 - https = 0x03 - ftp = 0x03 - file = 0x03 - @ivt = 0x01 - shell = 0x00 - knownfolder = 0x00 HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges - Default = HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones - Default = - SelfHealCount = 0x01 HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0 - Default = - DisplayName = Computer - PMDisplayName = Computer [Protected Mode] - Description = Your computer - Icon = shell32.dll#0016 - LowIcon = inetcpl.cpl#005422 - CurrentLevel = 0x00 - Flags = 0x21 (33) - 1200 = 0x00 - 1400 = 0x00 HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1 - Default = - DisplayName = Local intranet - PMDisplayName = Local intranet [Protected Mode] - Description = This zone contains all Web sites that are on your organization's intranet. - Icon = shell32.dll#0018 - LowIcon = inetcpl.cpl#005423 - CurrentLevel = 0x10500 (66816) - Flags = 0xdb (219) - 1200 = 0x00 - 1400 = 0x00 - 2500 = 0x03 HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2 - Default = - DisplayName = Trusted sites - PMDisplayName = Trusted sites [Protected Mode] - Description = This zone contains Web sites that you trust not to damage your computer or data. - Icon = inetcpl.cpl#00004480 - LowIcon = inetcpl.cpl#005424 - CurrentLevel = 0x11000 (69632) - Flags = 0x47 (71) - 1200 = 0x00 - 1400 = 0x00 HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 - Default = - DisplayName = Internet - PMDisplayName = Internet [Protected Mode] - Description = This zone contains all Web sites you haven't placed in other zones - Icon = inetcpl.cpl#001313 - LowIcon = inetcpl.cpl#005425 - CurrentLevel = 0x11500 (70912) - Flags = 0x01 - 1200 = 0x00 - 1400 = 0x00 HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 - Default = - DisplayName = Restricted sites - PMDisplayName = Restricted sites [Protected Mode] - Description = This zone contains Web sites that could potentially damage your computer or data. - Icon = inetcpl.cpl#00004481 - LowIcon = inetcpl.cpl#005426 - CurrentLevel = 0x12000 (73728) - Flags = 0x03 - 1200 = 0x03 - 1400 = 0x03 HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings - User Agent = Mozilla/4.0 (compatible; MSIE 8.0; Win32) - IE5_UA_Backup_Flag = 5.0 - ZonesSecurityUpgrade = F5 51 1E 7B 46 9F CE 01 - EnableNegotiate = 0x01 - ProxyEnable = 0x00 HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0 - empty = (null) HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache - empty = (null) HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content - CachePrefix = - CacheLimit = 0x3e800 (256000) HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies - CachePrefix = Cookie: - CacheLimit = 0x01 HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History - CachePrefix = Visited: - CacheLimit = 0x01 HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections - DefaultConnectionSettings = 46 00 00 00 02 00 00 00 09 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 - SavedLegacySettings = 46 00 00 00 0D 00 00 00 09 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones - empty = (null) HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0 - Default = - DisplayName = Computer - PMDisplayName = Computer [Protected Mode] - Description = Your computer - Icon = shell32.dll#0016 - LowIcon = inetcpl.cpl#005422 - CurrentLevel = 0x00 - Flags = 0x21 (33) - 1200 = 0x03 - 1400 = 0x01 HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1 - Default = - DisplayName = Local intranet - PMDisplayName = Local intranet [Protected Mode] - Description = This zone contains all Web sites that are on your organization's intranet. - Icon = shell32.dll#0018 - LowIcon = inetcpl.cpl#005423 - CurrentLevel = 0x00 - Flags = 0xdb (219) - 1200 = 0x03 - 1400 = 0x01 HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2 - Default = - DisplayName = Trusted sites - PMDisplayName = Trusted sites [Protected Mode] - Description = This zone contains Web sites that you trust not to damage your computer or data. - Icon = inetcpl.cpl#00004480 - LowIcon = inetcpl.cpl#005424 - CurrentLevel = 0x00 - Flags = 0x21 (33) - 1200 = 0x03 - 1400 = 0x01 HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3 - Default = - DisplayName = Internet - PMDisplayName = Internet [Protected Mode] - Description = This zone contains all Web sites you haven't placed in other zones - Icon = inetcpl.cpl#001313 - LowIcon = inetcpl.cpl#005425 - CurrentLevel = 0x00 - Flags = 0x21 (33) - 1200 = 0x03 - 1400 = 0x01 HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4 - Default = - DisplayName = Restricted sites - PMDisplayName = Restricted sites [Protected Mode] - Description = This zone contains Web sites that could potentially damage your computer or data. - Icon = inetcpl.cpl#00004481 - LowIcon = inetcpl.cpl#005426 - CurrentLevel = 0x00 - Flags = 0x21 (33) - 1200 = 0x03 - 1400 = 0x03 HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap - Default = - ProxyByPass = 0x01 - IntranetName = 0x01 - UNCAsIntranet = 0x01 - AutoDetect = 0x00 HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains - Default = HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults - Default = - http = 0x03 - https = 0x03 - ftp = 0x03 - file = 0x03 - @ivt = 0x01 - shell = 0x00 - knownfolder = 0x00 HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges - Default = HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones - Default = - SelfHealCount = 0x01 HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0 - Default = - DisplayName = Computer - PMDisplayName = Computer [Protected Mode] - Description = Your computer - Icon = shell32.dll#0016 - LowIcon = inetcpl.cpl#005422 - CurrentLevel = 0x00 - Flags = 0x21 (33) - 1200 = 0x00 - 1400 = 0x00 HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1 - Default = - DisplayName = Local intranet - PMDisplayName = Local intranet [Protected Mode] - Description = This zone contains all Web sites that are on your organization's intranet. - Icon = shell32.dll#0018 - LowIcon = inetcpl.cpl#005423 - CurrentLevel = 0x10500 (66816) - Flags = 0xdb (219) - 1200 = 0x00 - 1400 = 0x00 - 2500 = 0x03 HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2 - Default = - DisplayName = Trusted sites - PMDisplayName = Trusted sites [Protected Mode] - Description = This zone contains Web sites that you trust not to damage your computer or data. - Icon = inetcpl.cpl#00004480 - LowIcon = inetcpl.cpl#005424 - CurrentLevel = 0x11000 (69632) - Flags = 0x47 (71) - 1200 = 0x00 - 1400 = 0x00 HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 - Default = - DisplayName = Internet - PMDisplayName = Internet [Protected Mode] - Description = This zone contains all Web sites you haven't placed in other zones - Icon = inetcpl.cpl#001313 - LowIcon = inetcpl.cpl#005425 - CurrentLevel = 0x11500 (70912) - Flags = 0x01 - 1200 = 0x00 - 1400 = 0x00 HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 - Default = - DisplayName = Restricted sites - PMDisplayName = Restricted sites [Protected Mode] - Description = This zone contains Web sites that could potentially damage your computer or data. - Icon = inetcpl.cpl#00004481 - LowIcon = inetcpl.cpl#005426 - CurrentLevel = 0x12000 (73728) - Flags = 0x03 - 1200 = 0x03 - 1400 = 0x03 HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings - User Agent = Mozilla/4.0 (compatible; MSIE 8.0; Win32) - IE5_UA_Backup_Flag = 5.0 - ZonesSecurityUpgrade = 69 16 B2 07 96 E0 CF 01 HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0 - empty = (null) HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache - empty = (null) HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections - empty = (null) HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Http Filters - empty = (null) HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Http Filters\RPA - empty = (null) HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones - empty = (null) HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0 - Default = - DisplayName = Computer - PMDisplayName = Computer [Protected Mode] - Description = Your computer - Icon = shell32.dll#0016 - LowIcon = inetcpl.cpl#005422 - CurrentLevel = 0x00 - Flags = 0x21 (33) - 1200 = 0x03 - 1400 = 0x01 HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1 - Default = - DisplayName = Local intranet - PMDisplayName = Local intranet [Protected Mode] - Description = This zone contains all Web sites that are on your organization's intranet. - Icon = shell32.dll#0018 - LowIcon = inetcpl.cpl#005423 - CurrentLevel = 0x00 - Flags = 0xdb (219) - 1200 = 0x03 - 1400 = 0x01 HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2 - Default = - DisplayName = Trusted sites - PMDisplayName = Trusted sites [Protected Mode] - Description = This zone contains Web sites that you trust not to damage your computer or data. - Icon = inetcpl.cpl#00004480 - LowIcon = inetcpl.cpl#005424 - CurrentLevel = 0x00 - Flags = 0x21 (33) - 1200 = 0x03 - 1400 = 0x01 HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3 - Default = - DisplayName = Internet - PMDisplayName = Internet [Protected Mode] - Description = This zone contains all Web sites you haven't placed in other zones - Icon = inetcpl.cpl#001313 - LowIcon = inetcpl.cpl#005425 - CurrentLevel = 0x00 - Flags = 0x21 (33) - 1200 = 0x03 - 1400 = 0x01 HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4 - Default = - DisplayName = Restricted sites - PMDisplayName = Restricted sites [Protected Mode] - Description = This zone contains Web sites that could potentially damage your computer or data. - Icon = inetcpl.cpl#00004481 - LowIcon = inetcpl.cpl#005426 - CurrentLevel = 0x00 - Flags = 0x21 (33) - 1200 = 0x03 - 1400 = 0x03 HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\P3P - empty = (null) HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History - empty = (null) HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Passport - empty = (null) HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad - empty = (null) HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\80-1f-02-d6-34-8a - WpadDecisionReason = 0x01 - WpadDecisionTime = D0 86 5D 7E 9D E8 CF 01 - WpadDecision = 0x00 HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap - Default = - ProxyByPass = 0x01 - IntranetName = 0x01 - UNCAsIntranet = 0x01 - AutoDetect = 0x00 HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains - Default = HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults - Default = - http = 0x03 - https = 0x03 - ftp = 0x03 - file = 0x03 - @ivt = 0x01 - shell = 0x00 - knownfolder = 0x00 HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges - Default = HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones - Default = - SelfHealCount = 0x01 HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0 - Default = - DisplayName = Computer - PMDisplayName = Computer [Protected Mode] - Description = Your computer - Icon = shell32.dll#0016 - LowIcon = inetcpl.cpl#005422 - CurrentLevel = 0x00 - Flags = 0x21 (33) - 1200 = 0x00 - 1400 = 0x00 HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1 - Default = - DisplayName = Local intranet - PMDisplayName = Local intranet [Protected Mode] - Description = This zone contains all Web sites that are on your organization's intranet. - Icon = shell32.dll#0018 - LowIcon = inetcpl.cpl#005423 - CurrentLevel = 0x10500 (66816) - Flags = 0xdb (219) - 1200 = 0x00 - 1400 = 0x00 - 2500 = 0x03 HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2 - Default = - DisplayName = Trusted sites - PMDisplayName = Trusted sites [Protected Mode] - Description = This zone contains Web sites that you trust not to damage your computer or data. - Icon = inetcpl.cpl#00004480 - LowIcon = inetcpl.cpl#005424 - CurrentLevel = 0x11000 (69632) - Flags = 0x47 (71) - 1200 = 0x00 - 1400 = 0x00 HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 - Default = - DisplayName = Internet - PMDisplayName = Internet [Protected Mode] - Description = This zone contains all Web sites you haven't placed in other zones - Icon = inetcpl.cpl#001313 - LowIcon = inetcpl.cpl#005425 - CurrentLevel = 0x11500 (70912) - Flags = 0x01 - 1200 = 0x00 - 1400 = 0x00 HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 - Default = - DisplayName = Restricted sites - PMDisplayName = Restricted sites [Protected Mode] - Description = This zone contains Web sites that could potentially damage your computer or data. - Icon = inetcpl.cpl#00004481 - LowIcon = inetcpl.cpl#005426 - CurrentLevel = 0x12000 (73728) - Flags = 0x03 - 1200 = 0x03 - 1400 = 0x03 HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings - User Agent = Mozilla/5.0 (compatible; MSIE 9.0; Win32) - IE5_UA_Backup_Flag = 5.0 HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0 - empty = (null) HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache - empty = (null) HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections - empty = (null) HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Http Filters - empty = (null) HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Http Filters\RPA - empty = (null) HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\P3P - empty = (null) HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History - empty = (null) HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Passport - empty = (null) HKU\S-1-5-21-1582120339-517770455-3037123893-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings - User Agent = Mozilla/4.0 (compatible; MSIE 8.0; Win32) - IE5_UA_Backup_Flag = 5.0 - ZonesSecurityUpgrade = 02 8B 7E 60 3A DF CF 01 - EmailName = User@ - AutoConfigProxy = wininet.dll - MimeExclusionListForCache = multipart/mixed multipart/x-mixed-replace multipart/x-byteranges - WarnOnPost = 01 00 00 00 - UseSchannelDirectly = 01 00 00 00 - EnableHttp1_1 = 0x01 - UrlEncoding = 0x00 - SecureProtocols = 0xaa0 (2720) - PrivacyAdvanced = 0x00 - DisableCachingOfSSLPages = 0x00 - WarnonZoneCrossing = 0x00 - CertificateRevocation = 0x01 - EnableNegotiate = 0x01 - MigrateProxy = 0x01 - ProxyEnable = 0x00 HKU\S-1-5-21-1582120339-517770455-3037123893-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0 - empty = (null) HKU\S-1-5-21-1582120339-517770455-3037123893-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache - Version = 0x01 - ContentLimit = 0xfa (250) - TotalContentLimit = 0x00 - AppContainerTotalContentLimit = 0x3e8 (1000) - AppContainerContentLimit = 0x32 (50) HKU\S-1-5-21-1582120339-517770455-3037123893-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content - CachePrefix = - CacheLimit = 0x3e800 (256000) HKU\S-1-5-21-1582120339-517770455-3037123893-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies - CachePrefix = Cookie: - CacheLimit = 0x01 HKU\S-1-5-21-1582120339-517770455-3037123893-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache - empty = (null) HKU\S-1-5-21-1582120339-517770455-3037123893-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DNTException - CachePrefix = DNTException: - CachePath = %USERPROFILE%\AppData\Local\Microsoft\Windows\DNTException - CacheOptions = 0x300 (768) - CacheRepair = 0x00 - CacheLimit = 0x01 HKU\S-1-5-21-1582120339-517770455-3037123893-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore - CachePrefix = DOMStore - CachePath = %USERPROFILE%\AppData\Local\Microsoft\Internet Explorer\DOMStore - CacheOptions = 0x08 - CacheRepair = 0x00 - CacheLimit = 0x3e8 (1000) HKU\S-1-5-21-1582120339-517770455-3037123893-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\EmieSiteList - CachePrefix = EmieSiteList: - CachePath = %USERPROFILE%\AppData\Local\EmieSiteList - CacheOptions = 0x300 (768) - CacheRepair = 0x00 - CacheLimit = 0x01 HKU\S-1-5-21-1582120339-517770455-3037123893-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\EmieUserList - CachePrefix = EmieUserList: - CachePath = %USERPROFILE%\AppData\Local\EmieUserList - CacheOptions = 0x300 (768) - CacheRepair = 0x00 - CacheLimit = 0x01 HKU\S-1-5-21-1582120339-517770455-3037123893-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData - CachePrefix = UserData - CachePath = %APPDATA%\Microsoft\Internet Explorer\UserData - CacheOptions = 0x08 - CacheRepair = 0x00 - CacheLimit = 0x3e8 (1000) HKU\S-1-5-21-1582120339-517770455-3037123893-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat - CachePrefix = feedplat: - CachePath = %USERPROFILE%\AppData\Local\Microsoft\Feeds Cache - CacheOptions = 0x00 - CacheRepair = 0x00 - CacheLimit = 0x01 HKU\S-1-5-21-1582120339-517770455-3037123893-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat - CachePrefix = iecompat: - CachePath = %USERPROFILE%\AppData\Local\Microsoft\Windows\IECompatCache - CacheOptions = 0x309 (777) - CacheRepair = 0x00 - CacheLimit = 0x01 HKU\S-1-5-21-1582120339-517770455-3037123893-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompatua - CachePrefix = iecompatua: - CachePath = %USERPROFILE%\AppData\Local\Microsoft\Windows\iecompatuaCache - CacheOptions = 0x309 (777) - CacheRepair = 0x00 - CacheLimit = 0x01 HKU\S-1-5-21-1582120339-517770455-3037123893-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iedownload - CachePrefix = iedownload: - CachePath = %USERPROFILE%\AppData\Local\Microsoft\Windows\IEDownloadHistory - CacheOptions = 0x09 - CacheRepair = 0x00 - CacheLimit = 0x01 HKU\S-1-5-21-1582120339-517770455-3037123893-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ieflipahead - CachePrefix = ieflipahead: - CachePath = %USERPROFILE%\AppData\Local\Microsoft\Internet Explorer\IEFlipAheadCache - CacheOptions = 0x300 (768) - CacheRepair = 0x00 - CacheLimit = 0x01 HKU\S-1-5-21-1582120339-517770455-3037123893-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\wpnidm - CachePrefix = wpnidm: - CachePath = %USERPROFILE%\AppData\Local\Microsoft\Windows\Notifications\2e18b1664b2e11e4825038eaa7f9e795 - CacheOptions = 0x09 - CacheRepair = 0x00 - CacheLimit = 0x100000 (1048576) HKU\S-1-5-21-1582120339-517770455-3037123893-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History - CachePrefix = Visited: - CacheLimit = 0x01 HKU\S-1-5-21-1582120339-517770455-3037123893-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache - empty = (null) HKU\S-1-5-21-1582120339-517770455-3037123893-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\Content - CachePrefix = - CacheLimit = 0x3e800 (256000) HKU\S-1-5-21-1582120339-517770455-3037123893-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\Cookies - CachePrefix = Cookie: - CacheLimit = 0x01 HKU\S-1-5-21-1582120339-517770455-3037123893-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\Extensible Cache - empty = (null) HKU\S-1-5-21-1582120339-517770455-3037123893-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\Extensible Cache\DNTException - CachePrefix = DNTException: - CachePath = %USERPROFILE%\AppData\Local\Microsoft\Windows\DNTException\Low - CacheOptions = 0x300 (768) - CacheRepair = 0x00 - CacheLimit = 0x01 HKU\S-1-5-21-1582120339-517770455-3037123893-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\Extensible Cache\DOMStore - CachePrefix = DOMStore - CachePath = %USERPROFILE%\AppData\LocalLow\Microsoft\Internet Explorer\DOMStore - CacheOptions = 0x08 - CacheRepair = 0x00 - CacheLimit = 0x3e8 (1000) HKU\S-1-5-21-1582120339-517770455-3037123893-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\Extensible Cache\EmieSiteList - CachePrefix = EmieSiteList: - CachePath = %USERPROFILE%\AppData\LocalLow\EmieSiteList - CacheOptions = 0x300 (768) - CacheRepair = 0x00 - CacheLimit = 0x01 HKU\S-1-5-21-1582120339-517770455-3037123893-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\Extensible Cache\EmieUserList - CachePrefix = EmieUserList: - CachePath = %USERPROFILE%\AppData\LocalLow\EmieUserList - CacheOptions = 0x300 (768) - CacheRepair = 0x00 - CacheLimit = 0x01 HKU\S-1-5-21-1582120339-517770455-3037123893-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\Extensible Cache\feedplat - CachePrefix = feedplat: - CachePath = %USERPROFILE%\AppData\Local\Microsoft\Feeds Cache - CacheOptions = 0x00 - CacheRepair = 0x00 - CacheLimit = 0x01 HKU\S-1-5-21-1582120339-517770455-3037123893-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\Extensible Cache\iecompat - CachePrefix = iecompat: - CachePath = %USERPROFILE%\AppData\Local\Microsoft\Windows\IECompatCache\Low - CacheOptions = 0x309 (777) - CacheRepair = 0x00 - CacheLimit = 0x01 HKU\S-1-5-21-1582120339-517770455-3037123893-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\Extensible Cache\iecompatua - CachePrefix = iecompatua: - CachePath = %USERPROFILE%\AppData\Local\Microsoft\Windows\iecompatuaCache\Low - CacheOptions = 0x309 (777) - CacheRepair = 0x00 - CacheLimit = 0x01 HKU\S-1-5-21-1582120339-517770455-3037123893-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\Extensible Cache\iedownload - CachePrefix = iedownload: - CachePath = %USERPROFILE%\AppData\Local\Microsoft\Windows\IEDownloadHistory - CacheOptions = 0x09 - CacheRepair = 0x00 - CacheLimit = 0x01 HKU\S-1-5-21-1582120339-517770455-3037123893-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\History - CachePrefix = Visited: - CacheLimit = 0x01 HKU\S-1-5-21-1582120339-517770455-3037123893-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent - empty = (null) HKU\S-1-5-21-1582120339-517770455-3037123893-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform - empty = (null) HKU\S-1-5-21-1582120339-517770455-3037123893-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\CACHE - Persistent = 0x01 HKU\S-1-5-21-1582120339-517770455-3037123893-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections - DefaultConnectionSettings = 46 00 00 00 0D 00 00 00 09 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 02 00 00 00 02 00 00 00 C0 A8 02 66 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 17 00 00 00 00 00 00 00 20 01 00 00 5E F5 79 FD 1C 21 05 C3 3F 57 FD 99 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 - SavedLegacySettings = 46 00 00 00 65 00 00 00 09 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 02 00 00 00 02 00 00 00 C0 A8 02 66 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 17 00 00 00 00 00 00 00 20 01 00 00 5E F5 79 FD 1C 21 05 C3 3F 57 FD 99 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 HKU\S-1-5-21-1582120339-517770455-3037123893-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Http Filters - empty = (null) HKU\S-1-5-21-1582120339-517770455-3037123893-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Http Filters\RPA - empty = (null) HKU\S-1-5-21-1582120339-517770455-3037123893-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones - empty = (null) HKU\S-1-5-21-1582120339-517770455-3037123893-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0 - Default = - DisplayName = Computer - PMDisplayName = Computer [Protected Mode] - Description = Your computer - Icon = shell32.dll#0016 - LowIcon = inetcpl.cpl#005422 - CurrentLevel = 0x00 - Flags = 0x21 (33) - 1200 = 0x03 - 1400 = 0x01 HKU\S-1-5-21-1582120339-517770455-3037123893-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1 - Default = - DisplayName = Local intranet - PMDisplayName = Local intranet [Protected Mode] - Description = This zone contains all Web sites that are on your organization's intranet. - Icon = shell32.dll#0018 - LowIcon = inetcpl.cpl#005423 - CurrentLevel = 0x00 - Flags = 0xdb (219) - 1200 = 0x03 - 1400 = 0x01 HKU\S-1-5-21-1582120339-517770455-3037123893-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2 - Default = - DisplayName = Trusted sites - PMDisplayName = Trusted sites [Protected Mode] - Description = This zone contains Web sites that you trust not to damage your computer or data. - Icon = inetcpl.cpl#00004480 - LowIcon = inetcpl.cpl#005424 - CurrentLevel = 0x00 - Flags = 0x21 (33) - 1200 = 0x03 - 1400 = 0x01 HKU\S-1-5-21-1582120339-517770455-3037123893-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3 - Default = - DisplayName = Internet - PMDisplayName = Internet [Protected Mode] - Description = This zone contains all Web sites you haven't placed in other zones - Icon = inetcpl.cpl#001313 - LowIcon = inetcpl.cpl#005425 - CurrentLevel = 0x00 - Flags = 0x21 (33) - 1200 = 0x03 - 1400 = 0x01 HKU\S-1-5-21-1582120339-517770455-3037123893-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4 - Default = - DisplayName = Restricted sites - PMDisplayName = Restricted sites [Protected Mode] - Description = This zone contains Web sites that could potentially damage your computer or data. - Icon = inetcpl.cpl#00004481 - LowIcon = inetcpl.cpl#005426 - CurrentLevel = 0x00 - Flags = 0x21 (33) - 1200 = 0x03 - 1400 = 0x03 HKU\S-1-5-21-1582120339-517770455-3037123893-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\P3P - empty = (null) HKU\S-1-5-21-1582120339-517770455-3037123893-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History - empty = (null) HKU\S-1-5-21-1582120339-517770455-3037123893-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Passport - empty = (null) HKU\S-1-5-21-1582120339-517770455-3037123893-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Passport\LowDAMap - empty = (null) HKU\S-1-5-21-1582120339-517770455-3037123893-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad - empty = (null) HKU\S-1-5-21-1582120339-517770455-3037123893-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap - Default = - ProxyByPass = 0x01 - IntranetName = 0x01 - UNCAsIntranet = 0x00 - AutoDetect = 0x01 HKU\S-1-5-21-1582120339-517770455-3037123893-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains - Default = HKU\S-1-5-21-1582120339-517770455-3037123893-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\bingi.com - empty = (null) HKU\S-1-5-21-1582120339-517770455-3037123893-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\bingi.com\www - http = 0x04 HKU\S-1-5-21-1582120339-517770455-3037123893-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\google,pl - https = 0x01 HKU\S-1-5-21-1582120339-517770455-3037123893-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\onet.pl - http = 0x01 HKU\S-1-5-21-1582120339-517770455-3037123893-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains - empty = (null) HKU\S-1-5-21-1582120339-517770455-3037123893-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\microsoft.com - empty = (null) HKU\S-1-5-21-1582120339-517770455-3037123893-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\microsoft.com\*.update - http = 0x02 - https = 0x02 HKU\S-1-5-21-1582120339-517770455-3037123893-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults - Default = - http = 0x03 - https = 0x03 - ftp = 0x03 - file = 0x03 - @ivt = 0x01 - shell = 0x00 - knownfolder = 0x00 HKU\S-1-5-21-1582120339-517770455-3037123893-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges - Default = HKU\S-1-5-21-1582120339-517770455-3037123893-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones - Default = - SelfHealCount = 0x01 - SecuritySafe = 0x01 HKU\S-1-5-21-1582120339-517770455-3037123893-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0 - Default = - DisplayName = Computer - PMDisplayName = Computer [Protected Mode] - Description = Your computer - Icon = shell32.dll#0016 - LowIcon = inetcpl.cpl#005422 - CurrentLevel = 0x00 - Flags = 0x21 (33) - 1200 = 0x00 - 1400 = 0x00 - 2001 = 0x00 - 2004 = 0x00 - 2007 = 0x03 HKU\S-1-5-21-1582120339-517770455-3037123893-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1 - Default = - DisplayName = Lokalny intranet - PMDisplayName = Local intranet [Protected Mode] - Description = Ta strefa zawiera wszystkie witryny sieci Web, które znajdują się w firmowym intranecie. - Icon = shell32.dll#0018 - LowIcon = inetcpl.cpl#005423 - CurrentLevel = 0x11500 (70912) - Flags = 0x15f (351) - 1200 = 0x00 - 1400 = 0x00 - 2500 = 0x00 - 2001 = 0x00 - 2004 = 0x00 - 2007 = 0x10000 (65536) - 2200 = 0x03 - 1809 = 0x00 - 1A00 = 0x20000 (131072) - 2201 = 0x03 - 1A02 = 0x00 - 1A03 = 0x00 - 140A = 0x00 - 1A04 = 0x03 - 1A05 = 0x01 - 1A06 = 0x00 - 2300 = 0x01 - 2301 = 0x00 - 1201 = 0x03 - 2302 = 0x03 - 1206 = 0x03 - 1207 = 0x03 - 1208 = 0x03 - 2400 = 0x03 - 1209 = 0x03 - 1C00 = 0x10000 (65536) - 2401 = 0x00 - 2402 = 0x03 - 160A = 0x03 - 270B = 0x03 - 160B = 0x00 - 270C = 0x00 - 270D = 0x03 - 1402 = 0x00 - 1405 = 0x00 - 1406 = 0x03 - 1407 = 0x01 - 1408 = 0x03 - 2600 = 0x00 - 1409 = 0x00 - 2700 = 0x00 - 2701 = 0x00 - 1601 = 0x00 - 2702 = 0x00 - 2703 = 0x03 - 2704 = 0x00 - 1604 = 0x00 - 1605 = 0x00 - 1606 = 0x00 - 1607 = 0x03 - 2708 = 0x03 - 1608 = 0x00 - 2000 = 0x00 - 2709 = 0x03 - 1609 = 0x01 - 120A = 0x03 - 2005 = 0x03 - 120B = 0x03 - 2100 = 0x00 - 2101 = 0x00 - 1001 = 0x01 - 1812 = 0x01 - 2102 = 0x03 - 1802 = 0x00 - 2103 = 0x03 - 1803 = 0x00 - 2104 = 0x03 - 1004 = 0x03 - 1804 = 0x01 - 2105 = 0x03 - 2106 = 0x00 - 2107 = 0x03 - 2707 = 0x00 HKU\S-1-5-21-1582120339-517770455-3037123893-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2 - Default = - DisplayName = Zaufane witryny - PMDisplayName = Trusted sites [Protected Mode] - Description = Ta strefa zawiera witryny sieci Web, którym ufasz, że nie uszkodzą tego komputera ani danych. - Icon = inetcpl.cpl#00004480 - LowIcon = inetcpl.cpl#005424 - CurrentLevel = 0x11000 (69632) - Flags = 0x47 (71) - 1200 = 0x00 - 1400 = 0x00 - 2001 = 0x00 - 2004 = 0x00 - 2007 = 0x10000 (65536) - 2200 = 0x03 - 1809 = 0x00 - 1A00 = 0x20000 (131072) - 2201 = 0x03 - 1A02 = 0x00 - 1A03 = 0x00 - 140A = 0x00 - 1A04 = 0x03 - 1A05 = 0x01 - 1A06 = 0x00 - 2300 = 0x01 - 2301 = 0x00 - 1201 = 0x03 - 2302 = 0x03 - 1206 = 0x03 - 1207 = 0x00 - 1208 = 0x00 - 2400 = 0x00 - 1209 = 0x03 - 1C00 = 0x10000 (65536) - 2401 = 0x00 - 2402 = 0x00 - 160A = 0x00 - 270B = 0x00 - 160B = 0x00 - 270C = 0x03 - 270D = 0x00 - 1402 = 0x00 - 1405 = 0x00 - 1406 = 0x03 - 1407 = 0x01 - 1408 = 0x00 - 2600 = 0x00 - 1409 = 0x00 - 2700 = 0x03 - 2701 = 0x00 - 1601 = 0x00 - 2702 = 0x00 - 2703 = 0x00 - 2704 = 0x00 - 1604 = 0x00 - 1605 = 0x00 - 1606 = 0x00 - 1607 = 0x03 - 2708 = 0x03 - 1608 = 0x00 - 2000 = 0x00 - 2709 = 0x03 - 1609 = 0x01 - 120A = 0x03 - 2005 = 0x00 - 120B = 0x00 - 2100 = 0x00 - 2101 = 0x00 - 1001 = 0x01 - 1812 = 0x00 - 2102 = 0x03 - 1802 = 0x00 - 2103 = 0x00 - 1803 = 0x00 - 2104 = 0x00 - 1004 = 0x03 - 1804 = 0x01 - 2105 = 0x00 - 2106 = 0x00 - 2107 = 0x00 - 2108 = 0x03 - 2500 = 0x00 - 2707 = 0x00 HKU\S-1-5-21-1582120339-517770455-3037123893-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 - Default = - DisplayName = Internet - PMDisplayName = Internet [Protected Mode] - Description = Ta strefa zawiera wszystkie witryny sieci Web, których nie umieszczono w innych strefach. - Icon = inetcpl.cpl#001313 - LowIcon = inetcpl.cpl#005425 - CurrentLevel = 0x11500 (70912) - Flags = 0x01 - 1200 = 0x00 - 1400 = 0x00 - 2001 = 0x00 - 2004 = 0x00 - 2007 = 0x10000 (65536) - {AEBA21FA-782A-4A90-978D-B72164C80120} = 1A 37 61 59 23 52 35 0C 7A 5F 20 17 2F 1E 1A 19 0E 2B 01 73 1E 28 1A 04 1B 0C 3B C2 21 27 53 0D 36 05 2C 05 04 3D 4F 3A 4A 44 33 3A 0A 06 12 68 53 7C 20 13 35 5D 4C 10 27 01 56 7A 2D 3F 38 4F 79 0F 16 26 75 53 1C 31 00 56 7A 3E 32 24 4F 79 1B 00 33 71 4D 23 32 29 7C 6A 35 31 34 40 72 3B 01 2E 5D 4C 2A 07 15 48 72 38 12 00 56 7A 3E 16 3C 71 4D 24 33 35 7C 72 35 0E 3C 1A 41 44 19 0F 31 3A 56 7A 2E 3E 31 0C 7C 6A 10 27 0C 05 5D 4C 39 19 12 15 61 54 2E 00 33 32 40 52 03 25 1F 05 5D 4C 2C 0C 0A 15 61 54 1A 26 1F 05 5D 4C 10 21 1D 1B 71 4D 3B 24 3A 21 6D 72 24 16 3C 32 40 72 21 0F 3A 1A 41 44 1B 1E 01 01 71 4D 32 23 30 27 6D 4D 1F 28 10 3C 56 7A 2F 2E 32 16 7C 6A 3A 12 3B 28 75 53 0B 3F 12 01 71 4D 23 32 29 27 75 53 12 30 32 1E 4F 79 12 38 17 01 71 4D 30 3E 37 27 6D 72 38 12 3F 04 41 44 0A 0E 32 28 49 5F 1C 24 0B 1B 36 21 41 7B 5B 24 39 31 7C 6A 2B 0E 25 75 53 1A 2E 26 41 72 34 16 26 71 4D 30 30 3A 7C 6A 07 33 1A 56 7A 3A 00 33 71 4D 23 32 29 7C 6A 1A 26 1A 40 52 24 3F 1A 6D 4D 1C 22 28 75 53 13 25 20 41 44 0A 0E 32 75 53 08 07 20 71 4D 10 27 0D 05 5D 4C 24 1A 1E 1B 71 4D 3F 20 3F 21 6D 4D 10 27 0C 05 5D 4C 39 19 12 3A 56 7A 3A 20 2C 0C 7C 6A 3E 0C 37 07 75 53 12 30 32 3A 56 7A 25 2D 23 0C 7C 6A 2B 08 21 3A 56 7A 22 3A 32 3A 56 72 24 1E 26 1A 41 44 07 1F 03 1B 75 53 1C 31 01 01 71 4D 32 23 30 27 6D 72 34 1E 30 04 41 44 1B 1E 3B 28 49 5F 07 33 12 1B 5D 4C 35 0B 0A 1F 75 53 0B 00 34 28 40 72 3B 01 2D 04 41 44 01 05 34 28 40 52 22 36 04 34 48 72 38 12 3F 04 41 44 0A 0E 1F 01 71 4D 24 33 35 27 06 1C 68 53 49 14 21 01 40 52 10 27 0D 40 52 2C 29 05 6D 4D 1F 28 05 56 7A 2F 2E 32 75 53 07 33 12 40 52 3F 3A 19 6D 72 20 00 34 71 4D 1A 26 1A 40 52 24 3F 1A 6D 72 35 08 38 5D 4C 2D 01 18 48 7A 27 23 1F 56 7A 3B 2F 3F 4F 79 08 39 01 1B 71 72 33 1F 39 3A 56 7A 2E 3E 31 0C 7C 72 35 0E 3F 1A 41 44 0A 0A 35 3A 56 7A 3A 20 2C 0C 7C 6A 03 25 1F 05 5D 4C 2C 0C 0A 15 61 54 27 05 34 32 40 52 10 21 09 05 5D 4C 2D 01 18 15 61 54 07 37 17 05 5D 4C 1C 24 03 1B 71 4D 30 30 3B 27 6D 72 33 17 3F 28 40 72 34 1E 30 04 41 44 1B 1E 00 01 71 4D 2F 2C 2C 27 6D 4D 0B 26 3F 3C 56 7A 3A 20 23 16 7C 6A 35 05 33 28 75 53 12 30 17 01 71 4D 30 3E 37 27 75 53 13 25 20 1E 4F 79 1F 29 1F 01 71 4D 24 33 35 27 06 21 41 7B 5B 3D 24 37 7C 6A 2B 0E 25 40 72 33 1F 39 5D 72 34 1E 30 5D 4C 2A 0D 18 48 7A 27 12 3B 71 4D 23 32 12 56 72 20 0C 2E 5D 4C 2C 0C 0A 75 53 1A 26 1F 40 72 35 08 38 5D 4C 2D 01 18 75 53 0F 21 27 41 44 07 1F 3E 61 54 3D 06 22 32 40 52 2C 29 05 32 48 72 34 1E 05 1B 71 4D 10 27 0C 05 5D 4C 39 19 1A 1B 71 4D 23 32 24 21 6D 4D 03 25 1F 05 5D 4C 2C 0C 0A 3A 56 7A 25 2D 23 0C 7C 6A 2B 08 21 07 75 53 13 25 20 3A 56 7A 3E 3E 3B 0C 7C 6A 3F 0F 23 3A 56 7A 2F 2E 3D 3C 56 72 33 1F 39 04 41 44 1A 0E 05 01 75 53 1C 31 00 01 71 4D 2F 2C 2C 27 6D 72 20 0C 2D 04 41 44 06 18 2A 28 49 5F 1A 26 1A 1B 5D 4C 2C 0C 0F 1F 75 53 1C 1C 3E 28 40 72 38 12 3F 04 41 44 0A 16 3C 28 40 52 3E 39 06 34 21 21 41 7B 5B 23 27 3C 7C 6A 17 37 17 40 52 32 24 05 6D 4D 0E 21 2C 75 53 0B 31 31 75 53 08 3E 21 41 44 07 1E 3C 61 54 17 37 17 05 5D 4C 00 33 1E 1B 71 4D 2E 39 3B 21 6D 72 20 06 32 32 40 72 21 0F 3C 1A 41 44 1A 0E 1F 01 71 4D 20 2C 30 27 6D 4D 0E 21 2C 3C 56 7A 3A 2E 2D 16 7C 6A 3F 07 22 28 6E 02 68 4A 7C 21 09 26 5D 4C 29 1D 1F 56 7A 3F 32 38 4F 79 1E 30 01 56 7A 3A 2E 2D 4F 79 14 07 22 71 4D 24 30 3B 7C 6A 2A 1E 2F 07 75 53 0C 2D 26 3A 56 7A 31 25 3D 0C 7C 6A 3E 0E 35 3A 56 7A 3B 2F 3D 3A 56 72 34 1E 26 04 41 44 0B 0A 1E 01 75 53 0E 38 01 01 71 4D 23 30 2B 27 6D 72 21 0F 3C 04 28 1B 67 6B 5F 00 22 10 75 53 1F 21 27 41 44 0B 0A 31 75 53 0E 1D 22 71 4D 03 27 1D 40 52 3E 39 08 75 53 08 31 21 41 44 1A 0E 32 3A 56 7A 3F 32 38 0C 7C 6A 06 3E 0D 05 5D 4C 35 0D 09 15 61 54 29 07 22 32 40 52 17 37 17 1B 5D 4C 3A 19 16 1F 61 54 06 3E 0D 1B 5D 4C 03 27 11 01 71 4D 24 33 3B 27 06 21 41 73 41 11 25 1D 56 7A 2E 3E 3B 4F 79 18 12 3F 71 4D 2E 39 3B 7C 6A 3E 0E 35 40 72 21 0F 3C 5D 4C 36 0D 19 48 72 34 1E 1F 1B 71 4D 00 33 16 05 5D 4C 38 04 01 1B 71 4D 23 30 2B 21 6D 4D 1C 24 0D 05 5D 4C 29 1D 17 3C 56 7A 3F 32 38 16 7C 6A 39 09 25 09 75 53 0B 31 31 3C 56 7A 3B 2F 3D 16 15 39 5F 7B 42 03 38 02 40 20 2C 1E 4F 37 41 7B 5B 23 27 3C 7C 14 07 22 6E 14 68 4A 7C 20 13 35 5D 30 37 08 06 37 41 7B 5B 23 27 3C 7C 1B 39 1D 30 02 7C 50 68 3A 3B 34 4F 1B 1E 3B 6E 14 68 73 41 0B 22 0A 56 12 30 32 28 09 67 73 41 0B 22 2A 41 2C 0C 0F 21 37 41 7B 5B 23 27 3C 7C 08 1C 3E 66 0E 44 4F 56 06 13 05 61 27 23 1F 4F 3F 5B 53 7C 20 13 35 5D 3E 39 06 06 0A 68 53 7C 21 09 26 5D 32 12 3F 6E 14 68 4A 44 3E 37 02 6D 1C 24 01 4F 3F 5B 73 41 08 38 27 41 38 04 19 6E 14 68 4A 44 3E 37 02 6D 3E 0E 35 3B 37 41 7B 5B 24 39 31 7C 08 39 00 4F 3F 7C 50 68 3B 1D 3C 71 25 2D 2C 20 3A 7C 50 68 3B 25 3B 4F 01 1D 2A 6E 14 68 4A 44 3E 37 02 6D 10 21 09 29 1F 5E 45 67 14 30 07 49 12 16 3C 66 0E 44 73 41 08 38 27 41 36 0A 1B 21 3F 42 73 41 10 3B 2D 41 00 33 1E 4F 3F 5B 53 5E 2E 07 1D 75 21 07 22 66 0E 7C 50 68 23 24 31 4F 0D 15 01 4F 3F 5B 53 5E 2E 07 1D 48 0B 18 3C 6E 14 68 4A 44 26 36 0C 6D 2B 06 25 66 37 41 7B 5B 14 21 01 40 3A 31 24 15 37 41 7B 5B 3C 3E 3F 7C 12 38 17 4F 3F 5B 53 5E 2E 07 1D 75 35 08 38 36 03 56 76 74 37 08 19 40 07 37 17 29 1F 7C 50 68 23 24 31 4F 07 1F 3E 16 17 7C 50 68 20 3A 39 75 25 12 3F 66 0E 44 4F 56 1C 12 1D 56 1C 24 0D 29 37 41 7B 5B 3D 24 37 7C 1E 1D 22 66 0E 44 4F 56 1C 12 30 61 23 13 11 4F 3F 5B 53 5E 2F 01 15 48 10 27 0C 6E 14 68 4A 7C 36 12 38 5D 24 3F 19 6E 14 68 4A 44 21 2C 04 6D 35 05 34 66 0E 44 4F 56 1C 12 1D 56 1C 3B 25 28 09 67 6B 5F 01 2C 28 75 24 1E 26 36 37 41 7B 5B 3D 24 37 7C 14 3A 0B 30 37 41 7B 5B 36 0C 7C - 1A10 = 0x01 - {A8A88C49-5EB2-4990-A1A2-0876022C854F} = 1A 37 61 59 23 52 35 0C 7A 5F 20 17 2F 1E 1A 19 0E 2B 01 73 1E 28 1A 04 1B 0C 3B C2 21 2D 53 49 07 25 0F 29 01 7C 50 68 3A 3B 34 4F 79 08 39 0D 49 72 33 1F 39 5D 4C 17 37 05 56 7A 2F 2E 32 4F 79 1F 12 3B 75 53 0B 3F 12 56 7A 3A 20 23 4F 79 12 05 33 71 4D 3A 31 29 7C 6A 2B 08 21 40 72 38 12 3F 5D 4C 39 1D 17 48 72 21 0F 03 56 7A 2F 06 22 32 40 52 2C 29 05 3A 56 7A 2E 3E 31 0C 7C 6A 2B 06 25 32 40 52 33 24 01 32 75 53 0B 3F 32 04 4F 79 1B 3B 1F 0C 40 72 3B 01 2D 1A 75 53 12 30 3F 04 4F 79 08 3F 09 0C 75 53 13 25 20 04 75 53 07 37 17 05 5D 4C 36 0A 1B 3A 56 72 35 0E 3C 3C 56 7A 2D 3F 38 16 7C 6A 17 37 01 1B 5D 4C 2A 0D 18 1F 61 54 12 12 3B 28 40 52 3F 3A 19 34 48 72 20 0C 17 01 71 4D 1A 26 1A 1B 5D 4C 2C 0C 17 01 71 4D 30 3E 37 27 6D 4D 1B 3B 0C 1B 5D 4C 39 1D 17 3C 56 7A 3B 2F 3F 16 15 39 5F 7B 42 29 1D 3C 71 4D 30 06 22 71 4D 32 23 30 7C 6A 2A 1E 19 75 53 1C 31 20 41 72 24 12 3B 71 4D 23 32 24 7C 6A 03 25 17 56 7A 25 05 33 71 4D 3A 31 29 7C 6A 10 21 09 40 52 27 2C 0B 6D 4D 0F 28 2A 75 53 08 3E 23 41 44 1B 1E 3C 3A 56 7A 12 34 16 05 75 53 1F 21 2D 04 4F 79 10 27 0C 05 5D 4C 39 19 12 15 75 53 0B 3F 32 04 4F 79 1B 00 34 32 40 52 24 3F 19 32 48 7A 2C 10 17 1B 71 4D 30 1C 3E 32 40 52 27 2C 0B 32 48 7A 27 16 3C 32 40 52 3E 07 20 3A 56 7A 2F 2E 3D 16 7C 6A 12 34 1E 01 71 4D 17 37 01 1B 5D 4C 2A 0D 18 3C 56 7A 3E 32 24 16 7C 6A 3E 0C 34 09 75 53 0B 3F 3F 1E 4F 79 12 38 12 01 71 72 3B 01 2E 3C 56 7A 2F 24 39 16 7C 72 38 12 3F 04 41 44 0A 0E 32 3C 56 7A 3B 2F 3F 16 15 39 7C 50 68 23 24 31 4F 79 08 39 0D 49 5F 12 34 16 40 52 17 37 01 40 52 22 38 0B 6D 4D 0F 34 1A 56 7A 3A 20 2C 75 53 03 25 1F 40 52 24 3F 19 6D 72 3B 05 34 71 4D 10 21 09 40 52 27 2C 0B 6D 72 24 1E 26 5D 4C 36 0A 1B 48 7A 36 13 01 1B 71 4D 32 23 30 21 6D 4D 17 37 01 3A 56 7A 2F 06 25 32 40 52 33 24 01 3A 56 7A 3A 20 2C 0C 7C 6A 3E 00 34 32 40 52 24 3F 19 32 75 53 12 30 3F 04 4F 79 08 3F 09 0C 40 72 38 12 3F 1A 75 53 0F 21 27 04 4F 79 14 3A 0B 0C 75 53 1C 31 21 1E 75 53 12 34 16 1B 5D 4C 29 1D 1D 3C 56 72 35 0E 3F 3C 56 7A 3E 32 24 16 7C 6A 03 25 1A 1B 5D 4C 35 0B 0F 1F 61 54 27 05 33 28 40 52 24 3F 1A 34 48 72 35 08 1D 01 71 4D 1B 3B 0C 1B 5D 4C 39 1D 1F 01 71 4D 24 33 35 27 06 1C 7C 50 68 20 3A 39 4F 79 08 06 22 71 4D 32 23 30 7C 6A 2A 1E 19 40 72 35 0E 3F 5D 72 24 1A 25 5D 4C 35 0B 0A 48 7A 23 00 34 71 4D 3A 31 12 56 72 3B 01 2E 5D 4C 2A 07 15 75 53 1B 3B 0C 40 72 24 1E 26 5D 4C 36 0A 1B 75 53 1C 31 21 04 4F 79 0A 2A 06 0C 40 72 34 1E 30 1A 41 44 1B 1E 3B 3A 56 7A 07 33 12 05 75 53 0B 3F 32 04 4F 79 03 25 1F 05 5D 4C 2C 0C 0A 15 75 53 12 30 3F 04 4F 79 08 1C 3E 32 40 52 27 2C 0B 32 48 7A 27 23 1F 1B 71 4D 24 07 20 32 40 52 22 38 08 34 48 7A 34 17 3F 28 40 52 23 16 26 3C 56 7A 2F 2E 32 16 7C 6A 07 33 1A 01 71 4D 03 25 1A 1B 5D 4C 35 0B 0F 3C 56 7A 25 2D 2C 16 7C 6A 35 31 37 09 75 53 1C 3B 25 1E 4F 79 13 35 00 01 71 72 24 1E 26 3C 56 7A 3B 2F 3F 16 15 21 41 7B 5B 23 27 3C 7C 6A 2A 16 3C 71 4D 20 2C 30 7C 6A 06 3E 0D 40 52 3F 38 18 6D 4D 08 27 2C 75 53 08 31 21 75 53 1F 21 27 04 4F 79 18 2D 06 0C 75 53 0E 38 21 04 75 53 03 27 1D 05 5D 4C 36 0A 19 3A 56 72 34 1E 26 3C 56 7A 3F 32 38 16 7C 6A 06 3E 0D 1B 5D 4C 35 0D 09 1F 61 54 29 07 22 28 29 01 5E 45 67 14 30 1F 56 7A 17 37 17 40 72 25 1A 39 5D 4C 38 04 01 56 7A 3A 2E 2D 4F 79 14 3A 01 56 7A 3B 2E 3D 4F 79 0F 16 3C 32 40 52 32 24 05 32 48 7A 18 28 01 1B 71 4D 23 06 32 32 40 52 3E 39 08 32 48 7A 37 16 3C 28 40 52 32 12 3F 3C 56 7A 31 25 3D 16 7C 6A 03 27 11 01 71 4D 1C 24 0D 1B 36 1D 56 76 74 14 21 01 40 52 23 28 02 6D 4D 0C 34 2B 75 53 0E 38 21 41 44 06 1E 2C 75 53 08 07 22 71 4D 1C 27 0D 40 52 23 28 02 3A 56 7A 3F 32 38 0C 7C 6A 39 1D 22 32 40 52 3F 38 18 32 75 53 08 3E 21 04 4F 79 0F 29 07 02 40 72 25 1A 39 04 75 53 0E 38 21 1E 4F 79 1B 39 1D 02 75 53 08 3E 21 1E 6E 02 7C 50 68 20 3A 39 4F 79 0F 16 3C 75 53 0C 2D 1E 56 7A 31 25 3D 4F 79 1B 06 32 71 4D 24 33 3B 7C 6A 3F 0E 25 40 72 34 1E 26 1A 41 44 0B 0A 31 3A 56 7A 06 3E 0D 05 75 53 0B 31 31 04 4F 79 1C 24 0D 05 5D 4C 29 1D 17 1F 75 53 0C 2D 26 1E 4F 79 1E 1D 22 28 40 52 3F 38 18 34 48 7A 22 12 01 01 66 1C 44 73 41 0B 22 2A 41 3A 19 16 21 2D 42 73 41 0B 22 2A 41 1C 24 01 4F 2D 5B 53 5E 35 1E 22 75 27 1D 22 66 1C 7C 50 68 3A 3B 34 4F 06 1E 11 4F 2D 5B 53 5E 35 1E 22 48 1C 18 2D 6E 02 68 4A 44 3F 2D 31 6D 35 05 33 66 21 41 7B 5B 03 38 02 40 3A 31 29 15 21 41 7B 5B 23 27 3C 7C 08 3F 1D 4F 2D 5B 53 5E 35 1E 22 75 24 1E 26 36 1D 56 76 74 3E 03 1C 40 1C 24 0B 29 01 7C 50 68 3B 25 3B 4F 0B 0A 31 16 05 7C 50 68 3B 25 3B 75 21 07 22 66 1C 44 4F 56 07 15 1F 56 06 3E 0D 29 21 41 7B 5B 24 39 31 7C 1B 06 32 66 1C 44 4F 56 07 15 32 61 36 13 00 4F 2D 5B 53 5E 36 04 17 48 1A 26 1A 6E 02 68 4A 7C 21 09 26 5D 24 3F 1A 6E 02 68 4A 44 3E 37 02 6D 2B 1C 3E 66 1C 44 4F 56 07 15 1F 56 0F 21 27 28 1B 67 6B 5F 08 21 2A 75 21 0F 3A 36 21 41 7B 5B 3C 3E 3F 7C 18 2D 06 30 21 41 7B 5B 3C 3E 05 56 1C 24 0D 29 01 5E 45 67 0C 1C 26 75 27 09 3C 6E 02 68 4A 44 26 36 0C 6D 03 27 1D 29 01 5E 45 67 0C 3F 31 49 3D 06 25 66 1C 44 4F 56 1F 14 38 75 3B 01 12 4F 2D 5B 73 41 10 3B 2D 41 2C 0C 17 4F 2D 5B 53 5E 2E 07 1D 48 10 21 09 29 01 5E 45 67 0C 1C 26 71 3E 3E 3B 20 28 74 4E 68 2A 29 05 56 08 3E 23 6E 02 68 4A 44 21 2C 04 6D 3B 1A 20 6E 02 68 4A 44 21 1A 3E 75 21 0F 3C 36 1D 56 76 74 15 3B 1D 56 0E 38 01 4F 2D 5B 53 5E 2F 01 15 75 20 0E 2C 36 1D 56 76 74 28 02 21 40 10 27 0C 29 01 5E 45 67 0D 35 1D 56 12 05 33 66 1C 7C 50 68 20 3A 39 4F 01 05 34 66 1C 44 4F 56 1C 12 30 75 35 08 38 36 1D 56 76 74 15 3B 09 40 2F 20 31 15 39 5F 7B 42 20 1A 3E 71 3B 2F 03 4F 2D 5B 53 5E 20 39 74 - 2200 = 0x03 - 1809 = 0x00 - 1A00 = 0x20000 (131072) - 2201 = 0x03 - 1A02 = 0x00 - 1A03 = 0x00 - 140A = 0x00 - 1A04 = 0x03 - 1A05 = 0x01 - 1A06 = 0x00 - 2300 = 0x01 - 2301 = 0x00 - 1201 = 0x03 - 2302 = 0x03 - 1206 = 0x03 - 1207 = 0x03 - 1208 = 0x03 - 2400 = 0x03 - 1209 = 0x03 - 1C00 = 0x10000 (65536) - 2401 = 0x00 - 2402 = 0x03 - 160A = 0x03 - 270B = 0x03 - 160B = 0x00 - 270C = 0x00 - 270D = 0x03 - 1402 = 0x00 - 1405 = 0x00 - 1406 = 0x03 - 1407 = 0x01 - 1408 = 0x03 - 2600 = 0x00 - 1409 = 0x00 - 2700 = 0x00 - 2701 = 0x00 - 1601 = 0x00 - 2702 = 0x00 - 2703 = 0x03 - 2704 = 0x00 - 1604 = 0x00 - 1605 = 0x00 - 1606 = 0x00 - 1607 = 0x03 - 2708 = 0x03 - 1608 = 0x00 - 2000 = 0x00 - 2709 = 0x03 - 1609 = 0x01 - 120A = 0x03 - 2005 = 0x03 - 120B = 0x03 - 2100 = 0x00 - 2101 = 0x00 - 1001 = 0x01 - 1812 = 0x01 - 2102 = 0x03 - 1802 = 0x00 - 2103 = 0x03 - 1803 = 0x00 - 2104 = 0x03 - 1004 = 0x03 - 1804 = 0x01 - 2105 = 0x03 - 2106 = 0x00 - 2107 = 0x03 - 2500 = 0x00 - 2707 = 0x00 HKU\S-1-5-21-1582120339-517770455-3037123893-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 - Default = - DisplayName = Witryny z ograniczeniami - PMDisplayName = Restricted sites [Protected Mode] - Description = Ta strefa zawiera witryny sieci Web, które mogą uszkodzić komputer lub dane. - Icon = inetcpl.cpl#00004481 - LowIcon = inetcpl.cpl#005426 - CurrentLevel = 0x00 - Flags = 0x03 - 1200 = 0x03 - 1400 = 0x03 - 2001 = 0x01 - 2004 = 0x03 - 2007 = 0x03 - 1C00 = 0x00 - {AEBA21FA-782A-4A90-978D-B72164C80120} = 1A 37 61 59 23 52 35 0C 7A 5F 20 17 2F 1E 1A 19 0E 2B 01 73 13 37 13 12 14 1A 15 39 - 1A10 = 0x03 - {A8A88C49-5EB2-4990-A1A2-0876022C854F} = 1A 37 61 59 23 52 35 0C 7A 5F 20 17 2F 1E 1A 19 0E 2B 01 73 13 37 13 12 14 1A 15 39 - 2200 = 0x03 - 1809 = 0x00 - 1A00 = 0x10000 (65536) - 2201 = 0x03 - 1A02 = 0x03 - 1A03 = 0x03 - 140A = 0x00 - 1A04 = 0x03 - 1A05 = 0x03 - 1A06 = 0x03 - 2300 = 0x03 - 2301 = 0x00 - 1201 = 0x03 - 2302 = 0x03 - 1206 = 0x03 - 1207 = 0x03 - 1208 = 0x03 - 2400 = 0x01 - 1209 = 0x03 - 2401 = 0x03 - 2402 = 0x03 - 160A = 0x03 - 270B = 0x03 - 160B = 0x00 - 270C = 0x00 - 270D = 0x03 - 1402 = 0x03 - 1405 = 0x03 - 1406 = 0x03 - 1407 = 0x03 - 1408 = 0x03 - 2600 = 0x03 - 1409 = 0x03 - 180B = 0x01 - 2700 = 0x00 - 2701 = 0x03 - 1601 = 0x03 - 2702 = 0x00 - 2703 = 0x03 - 2704 = 0x03 - 1604 = 0x03 - 1605 = 0x00 - 1606 = 0x03 - 1607 = 0x03 - 2708 = 0x03 - 1608 = 0x03 - 2000 = 0x03 - 2709 = 0x03 - 1609 = 0x01 - 120A = 0x03 - 2005 = 0x03 - 120B = 0x00 - 2100 = 0x03 - 2101 = 0x03 - 1001 = 0x03 - 1812 = 0x01 - 2102 = 0x03 - 1802 = 0x01 - 2103 = 0x03 - 1803 = 0x03 - 2104 = 0x03 - 1004 = 0x03 - 1804 = 0x03 - 2105 = 0x03 - 2106 = 0x03 - 2107 = 0x03 - 2500 = 0x03 - 2707 = 0x00 - 1806 = 0x03 * Category: Shell Execute Hooks (98 items) HKLM\SOFTWARE\Classes\*\shellex - empty = (null) HKLM\SOFTWARE\Classes\*\shellex\ContextMenuHandlers - empty = (null) HKLM\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\BriefcaseMenu - Default = %SystemRoot%\system32\syncui.dll HKLM\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\Open With - Default = %SystemRoot%\system32\shell32.dll HKLM\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\Open With EncryptionMenu - Default = %SystemRoot%\system32\shell32.dll HKLM\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\Sharing - Default = %SystemRoot%\system32\ntshrui.dll HKLM\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\ShdExt - Default = C:\Program Files\Shield\shdext.dll HKLM\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\WinRAR - Default = C:\Program Files\WinRAR\rarext.dll HKLM\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\WinRAR32 - Default = {B41DB860-8EE4-11D2-9906-E49FADC173CA} HKLM\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\WorkFolders - Default = C:\Windows\System32\WorkfoldersShell.dll HKLM\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\{4CE485DD-C395-46C4-A929-7B771D8A5655} - empty = (null) HKLM\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\{90AA3A4E-1CBA-4233-B8BB-535773D48449} - Default = Taskband Pin HKLM\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\{D653647D-D607-4df6-A5B8-48D2BA195F7B} - empty = (null) HKLM\SOFTWARE\Classes\*\shellex\PropertySheetHandlers - empty = (null) HKLM\SOFTWARE\Classes\*\shellex\PropertySheetHandlers\BriefcasePage - Default = %SystemRoot%\system32\syncui.dll HKLM\SOFTWARE\Classes\*\shellex\PropertySheetHandlers\CryptoSignMenu - Default = %SystemRoot%\system32\cryptext.dll HKLM\SOFTWARE\Classes\*\shellex\PropertySheetHandlers\FCI Properties - Default = C:\Windows\System32\srmshell.dll HKLM\SOFTWARE\Classes\*\shellex\PropertySheetHandlers\{1f2e5c40-9550-11ce-99d2-00aa006e086c} - empty = (null) HKLM\SOFTWARE\Classes\*\shellex\PropertySheetHandlers\{3EA48300-8CF6-101B-84FB-666CCB9BCD32} - Default = OLE DocFile Property Page HKLM\SOFTWARE\Classes\*\shellex\PropertySheetHandlers\{883373C3-BF89-11D1-BE35-080036B11A03} - Default = Summary Properties Page HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks - empty = (null) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers - empty = (null) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\EnhancedStorageShell - Default = C:\Windows\System32\EhStorShell.dll HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved - %CommonProgramFiles%\System\wab32.dll = .contact shell extension handler - C:\Windows\System32\webcheck.dll = WebCheckWebCrawler - {0F8604A5-4ECE-4DE1-BA7D-CF10F8AA4F48} = Contacts folder - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} = WebCheck - C:\Windows\System32\dlnashext.dll = DLNA Namespace Extension - C:\Windows\System32\wshext.dll = Shell extensions for Windows Script Host - C:\Windows\System32\inetcomm.dll = Microsoft Windows Mail Html Preview Handler - C:\Program Files\Common Files\Microsoft Shared\Microsoft Camera Codec Pack\MicrosoftRawCodec.dll = Microsoft Camera Raw Property Store - {5E2121EE-0300-11D4-8D3B-444553540000} = Catalyst Context Menu extension - %ProgramFiles%\Synaptics\SynTP\SynTPCpl.dll = Synaptics Control Panel - {B41DB860-8EE4-11D2-9906-E49FADC173CA} = WinRAR shell extension - C:\Program Files\WinRAR\rarext.dll = WinRAR shell extension - C:\Program Files\Shield\shdext.dll = ShdExt Extensions HKLM\Software\Classes\AllFilesystemObjects\shellex - empty = (null) HKLM\Software\Classes\AllFilesystemObjects\shellex\ContextMenuHandlers - empty = (null) HKLM\Software\Classes\AllFilesystemObjects\shellex\ContextMenuHandlers\CopyAsPathMenu - Default = %SystemRoot%\system32\shell32.dll HKLM\Software\Classes\AllFilesystemObjects\shellex\ContextMenuHandlers\SendTo - Default = %SystemRoot%\system32\shell32.dll HKLM\Software\Classes\AllFilesystemObjects\shellex\ContextMenuHandlers\{596AB062-B4D2-4215-9F74-E9109B0A8153} - empty = (null) HKLM\Software\Classes\AllFilesystemObjects\shellex\PropertySheetHandlers - empty = (null) HKLM\Software\Classes\AllFilesystemObjects\shellex\PropertySheetHandlers\{596AB062-B4D2-4215-9F74-E9109B0A8153} - empty = (null) HKLM\Software\Classes\Directory\Background\shellex - empty = (null) HKLM\Software\Classes\Directory\Background\shellex\ContextMenuHandlers - empty = (null) HKLM\Software\Classes\Directory\Background\shellex\ContextMenuHandlers\ACE - Default = {5E2121EE-0300-11D4-8D3B-444553540000} HKLM\Software\Classes\Directory\Background\shellex\ContextMenuHandlers\New - Default = %SystemRoot%\system32\shell32.dll HKLM\Software\Classes\Directory\Background\shellex\ContextMenuHandlers\Sharing - Default = %SystemRoot%\system32\ntshrui.dll HKLM\Software\Classes\Directory\Background\shellex\ContextMenuHandlers\WorkFolders - Default = C:\Windows\System32\WorkfoldersShell.dll HKLM\Software\Classes\Directory\Background\shellex\ContextMenuHandlers\igfxcui - Default = C:\Windows\system32\igfxpph.dll HKLM\Software\Classes\Directory\shellex - empty = (null) HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers - empty = (null) HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\EncryptionMenu - Default = %SystemRoot%\system32\shell32.dll HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\Sharing - Default = %SystemRoot%\system32\ntshrui.dll HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\ShdExt - Default = C:\Program Files\Shield\shdext.dll HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\WorkFolders - Default = C:\Windows\System32\WorkfoldersShell.dll HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\{4CE485DD-C395-46C4-A929-7B771D8A5655} - empty = (null) HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\{596AB062-B4D2-4215-9F74-E9109B0A8153} - empty = (null) HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\{D653647D-D607-4df6-A5B8-48D2BA195F7B} - empty = (null) HKLM\Software\Classes\Directory\shellex\CopyHookHandlers - empty = (null) HKLM\Software\Classes\Directory\shellex\CopyHookHandlers\FileSystem - Default = %SystemRoot%\system32\shell32.dll HKLM\Software\Classes\Directory\shellex\CopyHookHandlers\Sharing - Default = %SystemRoot%\system32\ntshrui.dll HKLM\Software\Classes\Directory\shellex\PropertySheetHandlers - empty = (null) HKLM\Software\Classes\Directory\shellex\PropertySheetHandlers\Sharing - Default = %SystemRoot%\system32\ntshrui.dll HKLM\Software\Classes\Directory\shellex\PropertySheetHandlers\{1f2e5c40-9550-11ce-99d2-00aa006e086c} - empty = (null) HKLM\Software\Classes\Directory\shellex\PropertySheetHandlers\{4a7ded0a-ad25-11d0-98a8-0800361b1103} - empty = (null) HKLM\Software\Classes\Directory\shellex\PropertySheetHandlers\{596AB062-B4D2-4215-9F74-E9109B0A8153} - empty = (null) HKLM\Software\Classes\Directory\shellex\PropertySheetHandlers\{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6} - empty = (null) HKLM\Software\Classes\Directory\shellex\PropertySheetHandlers\{ef43ecfe-2ab9-4632-bf21-58909dd177f0} - Default = HKLM\Software\Classes\Drive\shellex - empty = (null) HKLM\Software\Classes\Drive\shellex\ContextMenuHandlers - empty = (null) HKLM\Software\Classes\Drive\shellex\ContextMenuHandlers\EnhancedStorageShell - Default = C:\Windows\System32\EhStorShell.dll HKLM\Software\Classes\Drive\shellex\ContextMenuHandlers\Sharing - Default = %SystemRoot%\system32\ntshrui.dll HKLM\Software\Classes\Drive\shellex\ContextMenuHandlers\{59099400-57FF-11CE-BD94-0020AF85B590} - Default = HKLM\Software\Classes\Drive\shellex\ContextMenuHandlers\{596AB062-B4D2-4215-9F74-E9109B0A8153} - empty = (null) HKLM\Software\Classes\Drive\shellex\ContextMenuHandlers\{82363864-57FA-4DAC-B7E6-699B51F7C73E} - Default = BdUsbIzContextMenu HKLM\Software\Classes\Drive\shellex\ContextMenuHandlers\{D6791A63-E7E2-4fee-BF52-5DED8E86E9B8} - {D6791A63-E7E2-4fee-BF52-5DED8E86E9B8} = Portable Devices Menu HKLM\Software\Classes\Drive\shellex\ContextMenuHandlers\{fbeb8a05-beee-4442-804e-409d6c4515e9} - Default = HKLM\Software\Classes\Drive\shellex\DragDropHandlers - empty = (null) HKLM\Software\Classes\Drive\shellex\DragDropHandlers\WinRAR - Default = C:\Program Files\WinRAR\rarext.dll HKLM\Software\Classes\Drive\shellex\DragDropHandlers\WinRAR32 - Default = {B41DB860-8EE4-11D2-9906-E49FADC173CA} HKLM\Software\Classes\Drive\shellex\FolderExtensions - empty = (null) HKLM\Software\Classes\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9} - DriveMask = 0x20 (32) HKLM\Software\Classes\Drive\shellex\PropertySheetHandlers - Default = %SystemRoot%\system32\shell32.dll HKLM\Software\Classes\Drive\shellex\PropertySheetHandlers\Sharing - Default = %SystemRoot%\system32\ntshrui.dll HKLM\Software\Classes\Drive\shellex\PropertySheetHandlers\{1f2e5c40-9550-11ce-99d2-00aa006e086c} - empty = (null) HKLM\Software\Classes\Drive\shellex\PropertySheetHandlers\{4a7ded0a-ad25-11d0-98a8-0800361b1103} - empty = (null) HKLM\Software\Classes\Drive\shellex\PropertySheetHandlers\{55B3A0BD-4D28-42fe-8CFB-FA3EDFF969B8} - empty = (null) HKLM\Software\Classes\Drive\shellex\PropertySheetHandlers\{596AB062-B4D2-4215-9F74-E9109B0A8153} - empty = (null) HKLM\Software\Classes\Drive\shellex\PropertySheetHandlers\{5F5295E0-429F-1069-A2E2-08002B30309D} - empty = (null) HKLM\Software\Classes\Drive\shellex\PropertySheetHandlers\{7988B573-EC89-11cf-9C00-00AA00A14F56} - Default = HKLM\Software\Classes\Drive\shellex\PropertySheetHandlers\{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6} - empty = (null) HKLM\Software\Classes\Drive\shellex\PropertySheetHandlers\{ef43ecfe-2ab9-4632-bf21-58909dd177f0} - Default = HKLM\Software\Classes\Drive\shellex\PropertySheetHandlers\{fbeb8a05-beee-4442-804e-409d6c4515e9} - Default = HKLM\Software\Classes\Folder\shellex - empty = (null) HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers - empty = (null) HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\BriefcaseMenu - Default = %SystemRoot%\system32\syncui.dll HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\Library Location - Default = %SystemRoot%\system32\shell32.dll HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\PintoStartScreen - Default = %SystemRoot%\system32\shell32.dll HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\WinRAR - Default = C:\Program Files\WinRAR\rarext.dll HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\WinRAR32 - Default = {B41DB860-8EE4-11D2-9906-E49FADC173CA} HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\{4CE485DD-C395-46C4-A929-7B771D8A5655} - empty = (null) HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\{D653647D-D607-4df6-A5B8-48D2BA195F7B} - empty = (null) HKLM\Software\Classes\Folder\shellex\DragDropHandlers - empty = (null) HKLM\Software\Classes\Folder\shellex\DragDropHandlers\WinRAR - Default = C:\Program Files\WinRAR\rarext.dll HKLM\Software\Classes\Folder\shellex\DragDropHandlers\WinRAR32 - Default = {B41DB860-8EE4-11D2-9906-E49FADC173CA} HKLM\Software\Classes\Folder\shellex\DragDropHandlers\{BD472F60-27FA-11cf-B8B4-444553540000} - Default = HKLM\Software\Classes\Folder\shellex\PropertySheetHandlers - empty = (null) HKLM\Software\Classes\Folder\shellex\PropertySheetHandlers\BriefcasePage - Default = %SystemRoot%\system32\syncui.dll HKLM\Software\Classes\Folder\shellex\PropertySheetHandlers\FCI Properties - Default = C:\Windows\System32\srmshell.dll * Category: Print Monitors (5 items) HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors\Local Port - Driver = localspl.dll HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors\Microsoft Shared Fax Monitor - Driver = FXSMON.DLL HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors\Standard TCP/IP Port - Driver = tcpmon.dll HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors\USB Monitor - Driver = usbmon.dll HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors\WSD Port - Driver = WSDMon.dll * Category: TypeLibs (485 items) HKLM\SOFTWARE\Classes\TypeLib\{00000200-0000-0010-8000-00AA006D2EA4}\2.0\0\win32 - Default = C:\Program Files (x86)\Common Files\System\ado\msado20.tlb HKLM\SOFTWARE\Classes\TypeLib\{00000200-0000-0010-8000-00AA006D2EA4}\2.0\0\win64 - Default = C:\Program Files\Common Files\System\ado\msado20.tlb HKLM\SOFTWARE\Classes\TypeLib\{00000201-0000-0010-8000-00AA006D2EA4}\2.1\0\win32 - Default = C:\Program Files (x86)\Common Files\System\ado\msado21.tlb HKLM\SOFTWARE\Classes\TypeLib\{00000201-0000-0010-8000-00AA006D2EA4}\2.1\0\win64 - Default = C:\Program Files\Common Files\System\ado\msado21.tlb HKLM\SOFTWARE\Classes\TypeLib\{00000205-0000-0010-8000-00AA006D2EA4}\2.5\0\win32 - Default = C:\Program Files (x86)\Common Files\System\ado\msado25.tlb HKLM\SOFTWARE\Classes\TypeLib\{00000205-0000-0010-8000-00AA006D2EA4}\2.5\0\win64 - Default = C:\Program Files\Common Files\System\ado\msado25.tlb HKLM\SOFTWARE\Classes\TypeLib\{00000206-0000-0010-8000-00AA006D2EA4}\2.6\0\win32 - Default = C:\Program Files (x86)\Common Files\System\ado\msado26.tlb HKLM\SOFTWARE\Classes\TypeLib\{00000206-0000-0010-8000-00AA006D2EA4}\2.6\0\win64 - Default = C:\Program Files\Common Files\System\ado\msado26.tlb HKLM\SOFTWARE\Classes\TypeLib\{00000300-0000-0010-8000-00AA006D2EA4}\2.8\0\win32 - Default = C:\Program Files (x86)\Common Files\System\ado\msador28.tlb HKLM\SOFTWARE\Classes\TypeLib\{00000300-0000-0010-8000-00AA006D2EA4}\2.8\0\win64 - Default = C:\Program Files\Common Files\System\ado\msador28.tlb HKLM\SOFTWARE\Classes\TypeLib\{00000300-0000-0010-8000-00AA006D2EA4}\6.0\0\win32 - Default = C:\Program Files (x86)\Common Files\System\ado\msador15.dll HKLM\SOFTWARE\Classes\TypeLib\{00000300-0000-0010-8000-00AA006D2EA4}\6.0\0\win64 - Default = C:\Program Files\Common Files\System\ado\msador15.dll HKLM\SOFTWARE\Classes\TypeLib\{00000600-0000-0010-8000-00AA006D2EA4}\2.8\0\win32 - Default = C:\Program Files (x86)\Common Files\System\ado\msadox28.tlb HKLM\SOFTWARE\Classes\TypeLib\{00000600-0000-0010-8000-00AA006D2EA4}\2.8\0\win64 - Default = C:\Program Files\Common Files\System\ado\msadox28.tlb HKLM\SOFTWARE\Classes\TypeLib\{00000600-0000-0010-8000-00AA006D2EA4}\6.0\0\win32 - Default = C:\Program Files (x86)\Common Files\System\ado\msadox.dll HKLM\SOFTWARE\Classes\TypeLib\{00000600-0000-0010-8000-00AA006D2EA4}\6.0\0\win64 - Default = C:\Program Files\Common Files\System\ado\msadox.dll HKLM\SOFTWARE\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\1.0\0\win32 - Default = C:\Windows\System32\stdole32.tlb HKLM\SOFTWARE\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0\win32 - Default = C:\Windows\SysWOW64\stdole2.tlb HKLM\SOFTWARE\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0\win64 - Default = C:\Windows\System32\stdole2.tlb HKLM\SOFTWARE\Classes\TypeLib\{000204EF-0000-0000-C000-000000000046}\6.0\9\win32 - Default = C:\Windows\SysWOW64\msvbvm60.dll HKLM\SOFTWARE\Classes\TypeLib\{00025E01-0000-0000-C000-000000000046}\5.0\0\win32 - Default = %CommonProgramFiles%\Microsoft Shared\DAO\dao360.dll HKLM\SOFTWARE\Classes\TypeLib\{000C1092-0000-0000-C000-000000000046}\1.0\409\win32 - Default = C:\Windows\System32\msi.dll HKLM\SOFTWARE\Classes\TypeLib\{00A40DB9-D8B4-40B3-8E0C-A8E8C6B3B720}\1.0\0\win32 - Default = C:\Windows\System32\sdchange.exe HKLM\SOFTWARE\Classes\TypeLib\{00F25AE8-3625-4E34-92D4-F0918CF010EE}\1.0\0\win32 - Default = %ProgramFiles%\Windows Photo Viewer\PhotoAcq.dll HKLM\SOFTWARE\Classes\TypeLib\{00F25AE8-3625-4E34-92D4-F0918CF010EE}\1.0\0\win64 - Default = %ProgramFiles%\Windows Photo Viewer\PhotoAcq.dll HKLM\SOFTWARE\Classes\TypeLib\{00d25261-a9e4-40b2-bf1e-a8a13df2542a}\1.0\0\win32 - Default = C:\Windows\SysWOW64\IME\IMEJP\imjpapi.dll HKLM\SOFTWARE\Classes\TypeLib\{00d25261-a9e4-40b2-bf1e-a8a13df2542a}\1.0\0\win64 - Default = C:\Windows\System32\IME\IMEJP\imjpapi.dll HKLM\SOFTWARE\Classes\TypeLib\{0109E0F4-91AE-4736-A2CE-9D63E89D0EF6}\1.0\0\win32 - Default = %SystemRoot%\system32\XPSSHHDR.DLL HKLM\SOFTWARE\Classes\TypeLib\{01909337-73C8-40B2-96DC-8E67F34ED562}\1.0\0\win32 - Default = %SystemRoot%\System32\gpregistrybrowser.dll HKLM\SOFTWARE\Classes\TypeLib\{01909337-73C8-40B2-96DC-8E67F34ED562}\1.0\0\win64 - Default = %SystemRoot%\System32\gpregistrybrowser.dll HKLM\SOFTWARE\Classes\TypeLib\{0249F559-489F-4977-A0EF-21352C5AD247}\1.0\0\win64 - Default = C:\Windows\system32\wbem\Win32_EncryptableVolume.dll HKLM\SOFTWARE\Classes\TypeLib\{03837500-098B-11D8-9414-505054503030}\1.0\0\win32 - Default = %systemroot%\system32\pla.dll HKLM\SOFTWARE\Classes\TypeLib\{03837500-098B-11D8-9414-505054503030}\1.0\0\win64 - Default = %systemroot%\system32\pla.dll HKLM\SOFTWARE\Classes\TypeLib\{05589FA0-C356-11CE-BF01-00AA0055595A}\2.0\0\win32 - Default = C:\Windows\System32\amcompat.tlb HKLM\SOFTWARE\Classes\TypeLib\{058F2991-6ADD-4948-89AF-82F58BCF2CCD}\1.0\0\win32 - Default = C:\Windows\SysWOW64\wuwebv.dll HKLM\SOFTWARE\Classes\TypeLib\{058F2991-6ADD-4948-89AF-82F58BCF2CCD}\1.0\0\win64 - Default = C:\Windows\System32\wuwebv.dll HKLM\SOFTWARE\Classes\TypeLib\{06290C00-48AA-11D2-8432-006008C3FBFC}\1.0\0\win32 - Default = C:\Windows\SysWOW64\scrobj.dll HKLM\SOFTWARE\Classes\TypeLib\{06290C00-48AA-11D2-8432-006008C3FBFC}\1.0\0\win64 - Default = C:\Windows\System32\scrobj.dll HKLM\SOFTWARE\Classes\TypeLib\{06af565f-771e-47a3-a501-f41b3e8bdac9}\1.0\0\win32 - Default = C:\Windows\SysWOW64\IME\SHARED\imefiles.dll HKLM\SOFTWARE\Classes\TypeLib\{06af565f-771e-47a3-a501-f41b3e8bdac9}\1.0\0\win64 - Default = C:\Windows\System32\IME\SHARED\imefiles.dll HKLM\SOFTWARE\Classes\TypeLib\{0A055C02-BABE-4480-BB7B-A8EC723CE9C0}\1.0\0\win32 - Default = %SystemRoot%\system32\shgina.dll HKLM\SOFTWARE\Classes\TypeLib\{0E59F1D2-1FBE-11D0-8FF2-00A0D10038BC}\1.0\0\win32 - Default = C:\Windows\SysWOW64\msscript.ocx HKLM\SOFTWARE\Classes\TypeLib\{0FFF9602-69CF-4728-9EA4-141514866CA2}\1.0\0\win32 - Default = C:\Windows\SysWOW64\findnetprinters.dll HKLM\SOFTWARE\Classes\TypeLib\{0FFF9602-69CF-4728-9EA4-141514866CA2}\1.0\0\win64 - Default = C:\Windows\System32\findnetprinters.dll HKLM\SOFTWARE\Classes\TypeLib\{10E3A8C1-B46C-4B6C-B3EF-8E2F48D527D0}\1.0\0\win32 - Default = %SystemRoot%\System32\sppwmi.dll HKLM\SOFTWARE\Classes\TypeLib\{11A8B8EE-BF30-409A-8EF7-3A143EF70332}\1.0\0\win32 - Default = %systemroot%\system32\azroles.dll HKLM\SOFTWARE\Classes\TypeLib\{11DD5EA9-F8DB-4F6E-BF7C-6AADBA404A3D}\1.0\0\win32 - Default = C:\Windows\SysWOW64\ndfapi.dll HKLM\SOFTWARE\Classes\TypeLib\{11DD5EA9-F8DB-4F6E-BF7C-6AADBA404A3D}\1.0\0\win64 - Default = C:\Windows\System32\ndfapi.dll HKLM\SOFTWARE\Classes\TypeLib\{121932AD-6881-46E4-BCA8-9155A87E77F9}\1.0\0\win32 - Default = C:\Windows\SysWOW64\wlidcli.dll HKLM\SOFTWARE\Classes\TypeLib\{121932AD-6881-46E4-BCA8-9155A87E77F9}\1.0\0\win64 - Default = C:\Windows\System32\wlidcli.dll HKLM\SOFTWARE\Classes\TypeLib\{122F1BB4-2723-4ac2-A36A-16BB9E8B99A6}\1.0\0\win32 - Default = %SystemRoot%\system32\netcenter.dll HKLM\SOFTWARE\Classes\TypeLib\{122F1BB4-2723-4ac2-A36A-16BB9E8B99A6}\1.0\0\win64 - Default = %SystemRoot%\system32\netcenter.dll HKLM\SOFTWARE\Classes\TypeLib\{13199C00-7494-11D0-8816-00A0C903B83C}\1.0\0\win32 - Default = %systemroot%\system32\certenc.dll HKLM\SOFTWARE\Classes\TypeLib\{132b42fb-871b-4077-ae2e-bf7fd772385e}\1.0\0\win64 - Default = C:\Windows\System32\ICSvc.dll HKLM\SOFTWARE\Classes\TypeLib\{150E2D7A-DAC1-4582-947D-2A8FD78B82CD}\1.0\0\win32 - Default = C:\Windows\System32\msaatext.dll HKLM\SOFTWARE\Classes\TypeLib\{157702D8-B1C1-40B8-8B46-AF2B40022085}\1.0\0\win32 - Default = %SystemRoot%\system32\wlanpref.dll HKLM\SOFTWARE\Classes\TypeLib\{157702D8-B1C1-40B8-8B46-AF2B40022085}\1.0\0\win64 - Default = %SystemRoot%\system32\wlanpref.dll HKLM\SOFTWARE\Classes\TypeLib\{16986d82-12a9-4dd8-a72b-2a40d8a9ceee}\1.0\0\win64 - Default = C:\Windows\System32\workfolderssvc.dll HKLM\SOFTWARE\Classes\TypeLib\{1878A0BC-B9A1-4BD0-B67E-BE35EDE35A96}\1.0\0\win32 - Default = C:\Windows\SysWOW64\MbaeApi.dll HKLM\SOFTWARE\Classes\TypeLib\{1878A0BC-B9A1-4BD0-B67E-BE35EDE35A96}\1.0\0\win64 - Default = C:\Windows\System32\MbaeApi.dll HKLM\SOFTWARE\Classes\TypeLib\{192EDB33-396A-4128-8765-3E6FA8A0DDE7}\1.0\0\win64 - Default = C:\Program Files\Bitdefender\Bitdefender\bdelev.dll HKLM\SOFTWARE\Classes\TypeLib\{1B773E42-2509-11CF-942F-008029004347}\3.7\0\win64 - Default = C:\Windows\System32\sysmon.ocx HKLM\SOFTWARE\Classes\TypeLib\{1B8D8AE1-A595-4687-A7AD-9E3828E09B79}\1.0\0\win32 - Default = %systemroot%\system32\wksprt.exe HKLM\SOFTWARE\Classes\TypeLib\{1C565858-F302-471E-B409-F180AA4ABEC6}\1.0\0\win32 - Default = C:\Windows\System32\hnetcfg.dll\2 HKLM\SOFTWARE\Classes\TypeLib\{1C82EAD8-508E-11D1-8DCF-00C04FB951F9}\1.0\0\win32 - Default = C:\Windows\SysWOW64\inetcomm.dll HKLM\SOFTWARE\Classes\TypeLib\{1C82EAD8-508E-11D1-8DCF-00C04FB951F9}\1.0\0\win64 - Default = C:\Windows\System32\inetcomm.dll HKLM\SOFTWARE\Classes\TypeLib\{1EA4DBF0-3C3B-11CF-810C-00AA00389B71}\1.1\0\win32 - Default = C:\Windows\SysWOW64\oleacc.dll HKLM\SOFTWARE\Classes\TypeLib\{1EA4DBF0-3C3B-11CF-810C-00AA00389B71}\1.1\0\win64 - Default = C:\Windows\System32\oleacc.dll HKLM\SOFTWARE\Classes\TypeLib\{1F001332-1A57-4934-BE31-AFFC99F4EE0A}\1.0\0\win32 - Default = C:\Windows\SysWOW64\PortableDeviceApi.dll HKLM\SOFTWARE\Classes\TypeLib\{1F001332-1A57-4934-BE31-AFFC99F4EE0A}\1.0\0\win64 - Default = C:\Windows\System32\PortableDeviceApi.dll HKLM\SOFTWARE\Classes\TypeLib\{1c200370-f887-4b0e-9958-0b980f410639}\1.0\0\win64 - Default = C:\Windows\System32\SyncEngine.dll\2 HKLM\SOFTWARE\Classes\TypeLib\{1fda955a-61ff-11da-978c-0008744faab7}\1.0\0\win32 - Default = %SystemRoot%\system32\dtsh.dll HKLM\SOFTWARE\Classes\TypeLib\{1fda955a-61ff-11da-978c-0008744faab7}\1.0\0\win64 - Default = %SystemRoot%\system32\dtsh.dll HKLM\SOFTWARE\Classes\TypeLib\{204810B3-73B2-11D4-BF42-00B0D0118B56}\1.0\0\win32 - Default = %SystemRoot%\system32\upnpcont.exe HKLM\SOFTWARE\Classes\TypeLib\{215D64D2-031C-33C7-96E3-61794CD1EE61}\2.0\0\win32 - Default = C:\Windows\Microsoft.NET\Framework\v2.0.50727\System.Windows.Forms.tlb HKLM\SOFTWARE\Classes\TypeLib\{215D64D2-031C-33C7-96E3-61794CD1EE61}\2.0\0\win64 - Default = C:\Windows\Microsoft.NET\Framework64\v2.0.50727\System.Windows.Forms.tlb HKLM\SOFTWARE\Classes\TypeLib\{215D64D2-031C-33C7-96E3-61794CD1EE61}\2.4\0\win32 - Default = C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.Windows.Forms.tlb HKLM\SOFTWARE\Classes\TypeLib\{215D64D2-031C-33C7-96E3-61794CD1EE61}\2.4\0\win64 - Default = C:\Windows\Microsoft.NET\Framework64\v4.0.30319\System.Windows.Forms.tlb HKLM\SOFTWARE\Classes\TypeLib\{21D6D480-A88B-11D0-83DD-00AA003CCABD}\1.0\0\win32 - Default = C:\Windows\System32\tapi3.dll HKLM\SOFTWARE\Classes\TypeLib\{2206CEB0-19C1-11D1-89E0-00C04FD7A829}\1.0\0\win32 - Default = C:\Program Files (x86)\Common Files\System\Ole DB\oledb32.dll HKLM\SOFTWARE\Classes\TypeLib\{2206CEB0-19C1-11D1-89E0-00C04FD7A829}\1.0\0\win64 - Default = C:\Program Files\Common Files\System\Ole DB\oledb32.dll HKLM\SOFTWARE\Classes\TypeLib\{22813728-8BD3-11D0-B4EF-00A0C9138CA4}\2.8\0\win32 - Default = C:\Program Files (x86)\Common Files\System\ado\msadomd28.tlb HKLM\SOFTWARE\Classes\TypeLib\{22813728-8BD3-11D0-B4EF-00A0C9138CA4}\2.8\0\win64 - Default = C:\Program Files\Common Files\System\ado\msadomd28.tlb HKLM\SOFTWARE\Classes\TypeLib\{22813728-8BD3-11D0-B4EF-00A0C9138CA4}\6.0\0\win32 - Default = C:\Program Files (x86)\Common Files\System\ado\msadomd.dll HKLM\SOFTWARE\Classes\TypeLib\{22813728-8BD3-11D0-B4EF-00A0C9138CA4}\6.0\0\win64 - Default = C:\Program Files\Common Files\System\ado\msadomd.dll HKLM\SOFTWARE\Classes\TypeLib\{22D6F304-B0F6-11D0-94AB-0080C74C7E95}\1.0\0\win32 - Default = C:\Windows\System32\msdxm.tlb HKLM\SOFTWARE\Classes\TypeLib\{2358C810-62BA-11D1-B3DB-00600832C573}\4.0\0\win32 - Default = C:\Windows\SysWOW64\msjtes40.dll HKLM\SOFTWARE\Classes\TypeLib\{244B6BCD-AC0E-4F8D-BC75-0909CF809018}\1.0\0\win64 - Default = C:\Program Files\Bitdefender\Bitdefender\bdshellext.dll HKLM\SOFTWARE\Classes\TypeLib\{24679880-E6F6-4C96-B7F5-44316AFE5093}\1.0\0\win32 - Default = C:\Program Files\Bitdefender\Bitdefender\Antispam32\pmbxie.dll HKLM\SOFTWARE\Classes\TypeLib\{2518e514-ebe3-4284-bcb6-e77fa7d84882}\1.0\0\win32 - Default = C:\Windows\SysWOW64\IME\IMEJP\imjpdapi.dll HKLM\SOFTWARE\Classes\TypeLib\{2518e514-ebe3-4284-bcb6-e77fa7d84882}\1.0\0\win64 - Default = C:\Windows\System32\IME\IMEJP\imjpdapi.dll HKLM\SOFTWARE\Classes\TypeLib\{2735412F-7F64-5B0F-8F00-5D77AFBE261E}\1.0\0\win64 - Default = C:\Windows\System32\imapi2.dll HKLM\SOFTWARE\Classes\TypeLib\{28DCD85B-ACA4-11D0-A028-00AA00B605A4}\1.0\0\win32 - Default = C:\Windows\System32\termmgr.dll HKLM\SOFTWARE\Classes\TypeLib\{2A005C00-A5DE-11CF-9E66-00AA00A3F464}\1.0\0\win32 - Default = C:\Windows\SysWOW64\comsvcs.dll HKLM\SOFTWARE\Classes\TypeLib\{2A005C00-A5DE-11CF-9E66-00AA00A3F464}\1.0\0\win64 - Default = C:\Windows\System32\comsvcs.dll HKLM\SOFTWARE\Classes\TypeLib\{2A75196C-D9EB-4129-B803-931327F72D5C}\2.8\0\win32 - Default = C:\Program Files (x86)\Common Files\System\ado\msado28.tlb HKLM\SOFTWARE\Classes\TypeLib\{2A75196C-D9EB-4129-B803-931327F72D5C}\2.8\0\win64 - Default = C:\Program Files\Common Files\System\ado\msado28.tlb HKLM\SOFTWARE\Classes\TypeLib\{2A833A82-6641-11D3-B5FE-00104B0A87C2}\1.0\0\win32 - Default = C:\Program Files\Synaptics\SynTP\SynTPCOM.dll HKLM\SOFTWARE\Classes\TypeLib\{2B00BA2F-E750-4BEB-9235-97142EDE1D3E}\1.0\0\win32 - Default = C:\Windows\SysWOW64\PortableDeviceTypes.dll HKLM\SOFTWARE\Classes\TypeLib\{2B00BA2F-E750-4BEB-9235-97142EDE1D3E}\1.0\0\win64 - Default = C:\Windows\System32\PortableDeviceTypes.dll HKLM\SOFTWARE\Classes\TypeLib\{2BF34C1A-8CAC-419F-8547-32FDF6505DB8}\1.0\0\win32 - Default = C:\Windows\SysWOW64\fxscomex.dll HKLM\SOFTWARE\Classes\TypeLib\{2BF34C1A-8CAC-419F-8547-32FDF6505DB8}\1.0\0\win64 - Default = C:\Windows\System32\fxscomex.dll HKLM\SOFTWARE\Classes\TypeLib\{2C941FD0-975B-59BE-A960-9A2A262853A5}\1.0\0\win64 - Default = C:\Windows\System32\imapi2fs.dll HKLM\SOFTWARE\Classes\TypeLib\{2D4BAA21-A123-4C97-AA2E-23A7836DE1D0}\2.0\0\win32 - Default = C:\Windows\SysWOW64\cprepsrv.dll HKLM\SOFTWARE\Classes\TypeLib\{2D4BAA21-A123-4C97-AA2E-23A7836DE1D0}\2.0\0\win64 - Default = C:\Windows\System32\cprepsrv.dll HKLM\SOFTWARE\Classes\TypeLib\{2E7D6A71-56CE-4A77-B58F-05DFFF85E251}\1.0\0\win64 - Default = C:\Windows\System32\TabBtnEx.dll HKLM\SOFTWARE\Classes\TypeLib\{3050F1C5-98B5-11CF-BB82-00AA00BDCE0B}\4.0\0\win32 - Default = C:\Windows\SysWOW64\mshtml.tlb HKLM\SOFTWARE\Classes\TypeLib\{3050F1C5-98B5-11CF-BB82-00AA00BDCE0B}\4.0\0\win64 - Default = C:\Windows\System32\mshtml.tlb HKLM\SOFTWARE\Classes\TypeLib\{3050F4E0-98B5-11CF-BB82-00AA00BDCE0B}\1.0\0\win32 - Default = C:\Windows\SysWOW64\mshtmled.dll HKLM\SOFTWARE\Classes\TypeLib\{3050F4E0-98B5-11CF-BB82-00AA00BDCE0B}\1.0\0\win64 - Default = C:\Windows\System32\mshtmled.dll HKLM\SOFTWARE\Classes\TypeLib\{306F05ED-1019-42A4-B94F-88A057E6736A}\1.0\0\win32 - Default = %ProgramFiles%\Windows Journal\MSPVWCTL.DLL HKLM\SOFTWARE\Classes\TypeLib\{32BAED35-34B5-11D3-9315-00C04F72D6CF}\1.0\0\win32 - Default = C:\Windows\System32\msscp.dll HKLM\SOFTWARE\Classes\TypeLib\{333C7BC1-460F-11D0-BC04-0080C7055A83}\1.1\0\win32 - Default = C:\Windows\SysWOW64\tdc.ocx HKLM\SOFTWARE\Classes\TypeLib\{333C7BC1-460F-11D0-BC04-0080C7055A83}\1.1\0\win64 - Default = C:\Windows\System32\tdc.ocx HKLM\SOFTWARE\Classes\TypeLib\{353D638F-C81B-4476-8323-63A7EE274205}\1.0\0\win32 - Default = %SystemRoot%\System32\BdeUISrv.exe HKLM\SOFTWARE\Classes\TypeLib\{353D638F-C81B-4476-8323-63A7EE274205}\1.0\0\win64 - Default = %SystemRoot%\System32\BdeUISrv.exe HKLM\SOFTWARE\Classes\TypeLib\{35DE99A0-7FB6-11D0-8817-00A0C903B83C}\1.0\0\win32 - Default = %systemroot%\system32\certadm.dll HKLM\SOFTWARE\Classes\TypeLib\{372FCE32-4324-11D0-8810-00A0C903B83C}\1.0\0\win32 - Default = %systemroot%\system32\certcli.dll HKLM\SOFTWARE\Classes\TypeLib\{39c0a710-7636-11d0-b413-00a0c91bbf8c}\1.0\0\win32 - Default = %systemroot%\system32\certadm.dll\2 HKLM\SOFTWARE\Classes\TypeLib\{3A0B7540-C2C8-11D2-B313-00C04F79DC72}\1.0\0\win32 - Default = %systemroot%\system32\certpdef.dll HKLM\SOFTWARE\Classes\TypeLib\{3AB1674B-CCFF-11D2-8B20-00A0C93CB1F4}\1.0\0\win64 - Default = C:\Windows\system32\igfxpph.dll HKLM\SOFTWARE\Classes\TypeLib\{3AC987E2-437A-3836-BA37-12287FD1D20D}\2.0\0\win32 - Default = %SystemRoot%\System32\gpmgmt.dll\2 HKLM\SOFTWARE\Classes\TypeLib\{3BAA3119-ECA1-4A32-9A08-595E71AE9DA9}\1.0\0\win32 - Default = C:\Windows\System32\WSTPager.ax HKLM\SOFTWARE\Classes\TypeLib\{3D5905E0-523C-11D1-9FEA-00600832DB4A}\1.0\0\win32 - Default = %SystemRoot%\system32\cic.dll HKLM\SOFTWARE\Classes\TypeLib\{3D5905E0-523C-11D1-9FEA-00600832DB4A}\1.0\0\win64 - Default = %SystemRoot%\system32\cic.dll HKLM\SOFTWARE\Classes\TypeLib\{3DE641EF-0556-4D4A-98D5-7DBD8AD5D70F}\1.0\0\win32 - Default = %systemroot%\system32\eventcls.dll HKLM\SOFTWARE\Classes\TypeLib\{3EA49599-AF67-4142-B379-C54786F112B2}\1.0\0\win32 - Default = C:\Windows\SysWOW64\MsRdpWebAccess.dll HKLM\SOFTWARE\Classes\TypeLib\{3EA49599-AF67-4142-B379-C54786F112B2}\1.0\0\win64 - Default = C:\Windows\System32\MsRdpWebAccess.dll HKLM\SOFTWARE\Classes\TypeLib\{3F4DACA7-160D-11D2-A8E9-00104B365C9F}\1.0\0\win32 - Default = C:\Windows\SysWOW64\vbscript.dll\2 HKLM\SOFTWARE\Classes\TypeLib\{3F4DACA7-160D-11D2-A8E9-00104B365C9F}\1.0\0\win64 - Default = C:\Windows\System32\vbscript.dll\2 HKLM\SOFTWARE\Classes\TypeLib\{3F4DACA7-160D-11D2-A8E9-00104B365C9F}\5.5\0\win32 - Default = C:\Windows\SysWOW64\vbscript.dll\3 HKLM\SOFTWARE\Classes\TypeLib\{3F4DACA7-160D-11D2-A8E9-00104B365C9F}\5.5\0\win64 - Default = C:\Windows\System32\vbscript.dll\3 HKLM\SOFTWARE\Classes\TypeLib\{3e15c914-280e-4550-a5c0-8c1a8bf8ad52}\1.0\0\win32 - Default = C:\Windows\SysWOW64\IME\IMEJP\imjpcmld.dll HKLM\SOFTWARE\Classes\TypeLib\{3e15c914-280e-4550-a5c0-8c1a8bf8ad52}\1.0\0\win64 - Default = C:\Windows\System32\IME\IMEJP\imjpcmld.dll HKLM\SOFTWARE\Classes\TypeLib\{410381CD-AF42-11D1-8F10-00C04FC2C17B}\1.0\0\win32 - Default = C:\Windows\SysWOW64\comsnap.dll HKLM\SOFTWARE\Classes\TypeLib\{410381CD-AF42-11D1-8F10-00C04FC2C17B}\1.0\0\win64 - Default = C:\Windows\System32\comsnap.dll HKLM\SOFTWARE\Classes\TypeLib\{420B2830-E718-11CF-893D-00A0C9054228}\1.0\0\win32 - Default = C:\Windows\SysWOW64\scrrun.dll HKLM\SOFTWARE\Classes\TypeLib\{420B2830-E718-11CF-893D-00A0C9054228}\1.0\0\win64 - Default = C:\Windows\System32\scrrun.dll HKLM\SOFTWARE\Classes\TypeLib\{43136EB0-D36C-11CF-ADBC-00AA00A80033}\1.0\0\win32 - Default = %SystemRoot%\system32\mmcndmgr.dll HKLM\SOFTWARE\Classes\TypeLib\{43136EB0-D36C-11CF-ADBC-00AA00A80033}\1.0\0\win64 - Default = %SystemRoot%\system32\mmcndmgr.dll HKLM\SOFTWARE\Classes\TypeLib\{43724D8D-D2FF-457C-AEFA-69B7FB2C6558}\1.0\0\win32 - Default = C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll HKLM\SOFTWARE\Classes\TypeLib\{438EDB38-282C-435D-8BE3-4AB90B83CEF5}\1.0\0\win32 - Default = %systemroot%\system32\printui.dll\1 HKLM\SOFTWARE\Classes\TypeLib\{43E734CA-043D-4A70-9A2C-A8F254063D91}\1.0\0\win32 - Default = %SystemRoot%\system32\hnetcfg.dll HKLM\SOFTWARE\Classes\TypeLib\{44269C1B-E2E4-40A7-ACE4-A2A27A3FB59A}\1.0\0\win64 - Default = C:\Program Files\Bitdefender\Bitdefender\fshredctx.dll HKLM\SOFTWARE\Classes\TypeLib\{4486DF98-22A5-4F6B-BD5C-8CADCEC0A6DE}\1.0\0\win32 - Default = C:\Windows\SysWOW64\LocationApi.dll HKLM\SOFTWARE\Classes\TypeLib\{4486DF98-22A5-4F6B-BD5C-8CADCEC0A6DE}\1.0\0\win64 - Default = C:\Windows\System32\LocationApi.dll HKLM\SOFTWARE\Classes\TypeLib\{44EC0535-400F-11D0-9DCD-00A0C90391D3}\1.0\0\win32 - Default = C:\Windows\SysWOW64\atl.dll HKLM\SOFTWARE\Classes\TypeLib\{44EC0535-400F-11D0-9DCD-00A0C90391D3}\1.0\0\win64 - Default = C:\Windows\System32\atl.dll HKLM\SOFTWARE\Classes\TypeLib\{453E9E02-8BA4-474C-BFA0-37727E44F6AE}\1.0\0\win32 - Default = %PROGRAMFILES%\Windows Media Player\wmpnssci.dll HKLM\SOFTWARE\Classes\TypeLib\{453E9E02-8BA4-474C-BFA0-37727E44F6AE}\1.0\0\win64 - Default = %PROGRAMFILES%\Windows Media Player\wmpnssci.dll HKLM\SOFTWARE\Classes\TypeLib\{45413F04-DF86-11D1-AE27-00C04FA35813}\1.0\0\win32 - Default = %SystemRoot%\system32\tsuserex.dll HKLM\SOFTWARE\Classes\TypeLib\{461E01A2-1F91-4FA7-9E6F-2DB84E5F9D02}\1.0\0\win32 - Default = %systemroot%\system32\certtmpl.dll HKLM\SOFTWARE\Classes\TypeLib\{4B2E957D-0393-11D1-B1AB-00AA00BA3258}\1.0\0\win32 - Default = C:\Windows\SysWOW64\comsvcs.dll HKLM\SOFTWARE\Classes\TypeLib\{4E14FB90-2E22-11D1-9964-00C04FBBB345}\1.0\0\win32 - Default = C:\Windows\SysWOW64\es.dll HKLM\SOFTWARE\Classes\TypeLib\{4E14FB90-2E22-11D1-9964-00C04FBBB345}\1.0\0\win64 - Default = C:\Windows\System32\es.dll HKLM\SOFTWARE\Classes\TypeLib\{4FB2D46F-EFC8-4643-BCD0-6E5BFA6A174C}\2.0\0\win32 - Default = C:\Windows\Microsoft.NET\Framework\v2.0.50727\System.EnterpriseServices.tlb HKLM\SOFTWARE\Classes\TypeLib\{4FB2D46F-EFC8-4643-BCD0-6E5BFA6A174C}\2.0\0\win64 - Default = C:\Windows\Microsoft.NET\Framework64\v2.0.50727\System.EnterpriseServices.tlb HKLM\SOFTWARE\Classes\TypeLib\{4FB2D46F-EFC8-4643-BCD0-6E5BFA6A174C}\2.4\0\win32 - Default = C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.EnterpriseServices.tlb HKLM\SOFTWARE\Classes\TypeLib\{4FB2D46F-EFC8-4643-BCD0-6E5BFA6A174C}\2.4\0\win64 - Default = C:\Windows\Microsoft.NET\Framework64\v4.0.30319\System.EnterpriseServices.tlb HKLM\SOFTWARE\Classes\TypeLib\{4b21f542-0eb5-4205-a12b-59bf2f2555fe}\1.0\0\win32 - Default = C:\Windows\SysWOW64\sdiageng.dll HKLM\SOFTWARE\Classes\TypeLib\{4b21f542-0eb5-4205-a12b-59bf2f2555fe}\1.0\0\win64 - Default = C:\Windows\System32\sdiageng.dll HKLM\SOFTWARE\Classes\TypeLib\{501D5FC6-FEA2-4453-B1CF-17E462143EE6}\1.0\0\win32 - Default = %ProgramFiles%\Windows Journal\JNTFiltr.dll HKLM\SOFTWARE\Classes\TypeLib\{50A7E9B0-70EF-11D1-B75A-00A0C90564FE}\1.0\0\win32 - Default = C:\Windows\SysWOW64\shell32.dll HKLM\SOFTWARE\Classes\TypeLib\{5190C4AF-AB0F-4235-B12F-D5A8FA3F854B}\1.0\0\win32 - Default = C:\Windows\System32\RACPLDlg.dll HKLM\SOFTWARE\Classes\TypeLib\{54314D1D-35FE-11D1-81A1-0000F87557DB}\1.1\0\win32 - Default = C:\Windows\SysWOW64\Dxtrans.dll HKLM\SOFTWARE\Classes\TypeLib\{54314D1D-35FE-11D1-81A1-0000F87557DB}\1.1\0\win64 - Default = C:\Windows\System32\Dxtrans.dll HKLM\SOFTWARE\Classes\TypeLib\{5477469E-83B1-11D2-8B49-00A0C9B7C9C4}\2.0\0\win32 - Default = C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscoree.tlb HKLM\SOFTWARE\Classes\TypeLib\{5477469E-83B1-11D2-8B49-00A0C9B7C9C4}\2.0\0\win64 - Default = C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscoree.tlb HKLM\SOFTWARE\Classes\TypeLib\{5477469E-83B1-11D2-8B49-00A0C9B7C9C4}\2.4\0\win32 - Default = C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoree.tlb HKLM\SOFTWARE\Classes\TypeLib\{5477469E-83B1-11D2-8B49-00A0C9B7C9C4}\2.4\0\win64 - Default = C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoree.tlb HKLM\SOFTWARE\Classes\TypeLib\{54930801-3612-4DA9-9E8C-0F3D1784E57C}\1.0\0\win32 - Default = C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPDeviceDetection3.exe HKLM\SOFTWARE\Classes\TypeLib\{54AF9343-1923-11D3-9CA4-00C04F72C514}\2.32\0\win32 - Default = C:\Windows\SysWOW64\odbcconf.dll HKLM\SOFTWARE\Classes\TypeLib\{54AF9343-1923-11D3-9CA4-00C04F72C514}\2.32\0\win64 - Default = C:\Windows\System32\odbcconf.dll HKLM\SOFTWARE\Classes\TypeLib\{563DC060-B09A-11D2-A24D-00104BD35090}\1.0\0\win32 - Default = C:\Windows\SysWOW64\wshcon.dll HKLM\SOFTWARE\Classes\TypeLib\{563DC060-B09A-11D2-A24D-00104BD35090}\1.0\0\win64 - Default = C:\Windows\System32\wshcon.dll HKLM\SOFTWARE\Classes\TypeLib\{565783C6-CB41-11D1-8B02-00600806D9B6}\1.2\0\win32 - Default = C:\Windows\SysWOW64\wbem\wbemdisp.TLB HKLM\SOFTWARE\Classes\TypeLib\{565783C6-CB41-11D1-8B02-00600806D9B6}\1.2\0\win64 - Default = C:\Windows\System32\wbem\wbemdisp.TLB HKLM\SOFTWARE\Classes\TypeLib\{56A868B0-0AD4-11CE-B03A-0020AF0BA770}\1.0\0\win32 - Default = C:\Windows\System32\quartz.dll HKLM\SOFTWARE\Classes\TypeLib\{56BC53D1-96DB-11D1-BF3F-000000000000}\1.0\0\win32 - Default = C:\Windows\SysWOW64\iassdo.dll\2 HKLM\SOFTWARE\Classes\TypeLib\{56BC53D1-96DB-11D1-BF3F-000000000000}\1.0\0\win64 - Default = C:\Windows\System32\iassdo.dll\2 HKLM\SOFTWARE\Classes\TypeLib\{56D04F5D-964F-4DBF-8D23-B97989E53418}\1.5\0\win32 - Default = C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\Inkdiv.dll HKLM\SOFTWARE\Classes\TypeLib\{56D04F5D-964F-4DBF-8D23-B97989E53418}\1.5\0\win64 - Default = C:\Program Files\Common Files\Microsoft Shared\Ink\Inkdiv.dll HKLM\SOFTWARE\Classes\TypeLib\{57A0E746-3863-4D20-A811-950C84F1DB9B}\1.1\0\win32 - Default = C:\Windows\System32\Macromed\Flash\Flash.ocx\2 HKLM\SOFTWARE\Classes\TypeLib\{57DACAE6-5313-4E27-B109-E6E3D415730C}\1.0\0\win32 - Default = %SystemRoot%\system32\GenValObj.exe HKLM\SOFTWARE\Classes\TypeLib\{58FBCF7C-E7A9-467C-80B3-FC65E8FCCA08}\1.0\0\win32 - Default = C:\Windows\SysWOW64\FirewallAPI.dll HKLM\SOFTWARE\Classes\TypeLib\{58FBCF7C-E7A9-467C-80B3-FC65E8FCCA08}\1.0\0\win64 - Default = C:\Windows\System32\FirewallAPI.dll HKLM\SOFTWARE\Classes\TypeLib\{5C65924B-E236-11D2-8899-00104B2AFB46}\1.0\0\win32 - Default = C:\Windows\SysWOW64\wbem\wbemcntl.dll HKLM\SOFTWARE\Classes\TypeLib\{5C65924B-E236-11D2-8899-00104B2AFB46}\1.0\0\win64 - Default = C:\Windows\System32\wbem\wbemcntl.dll HKLM\SOFTWARE\Classes\TypeLib\{5CB42160-CD7C-4806-9367-1C4A65153F4A}\1.0\0\win32 - Default = %SystemRoot%\system32\wmpshell.dll HKLM\SOFTWARE\Classes\TypeLib\{5CC8DC80-C2C8-11D2-B313-00C04F79DC72}\1.0\0\win32 - Default = %systemroot%\system32\certxds.dll HKLM\SOFTWARE\Classes\TypeLib\{5E77EB03-937C-11D1-B047-00AA003B6061}\1.1\0\win32 - Default = C:\Windows\SysWOW64\Dxtmsft.dll HKLM\SOFTWARE\Classes\TypeLib\{5E77EB03-937C-11D1-B047-00AA003B6061}\1.1\0\win64 - Default = C:\Windows\System32\Dxtmsft.dll HKLM\SOFTWARE\Classes\TypeLib\{5F099F16-6A6E-4BBC-8BD8-98F3221D58C4}\1.0\0\win64 - Default = C:\Windows\System32\wbem\ncprov.dll HKLM\SOFTWARE\Classes\TypeLib\{602049D1-C87D-456F-9BA9-9EA06A97A205}\1.0\0\win32 - Default = C:\Windows\system32\igfxress.dll HKLM\SOFTWARE\Classes\TypeLib\{61E207A5-827C-42E9-ADFA-165C6A745EE4}\1.0\0\win32 - Default = C:\Windows\syswow64\wbem\Win32_TPM.dll HKLM\SOFTWARE\Classes\TypeLib\{61E207A5-827C-42E9-ADFA-165C6A745EE4}\1.0\0\win64 - Default = C:\Windows\system32\wbem\Win32_TPM.dll HKLM\SOFTWARE\Classes\TypeLib\{635587FC-9875-43C1-96FF-F5B13BC4C19C}\1.0\0\win32 - Default = C:\Program Files\Bitdefender\Bitdefender\pmbxie.dll HKLM\SOFTWARE\Classes\TypeLib\{640D3148-A423-11D2-B943-00C04F79D22F}\1.0\0\win32 - Default = C:\Windows\SysWOW64\catsrvut.dll HKLM\SOFTWARE\Classes\TypeLib\{640D3148-A423-11D2-B943-00C04F79D22F}\1.0\0\win64 - Default = C:\Windows\System32\catsrvut.dll HKLM\SOFTWARE\Classes\TypeLib\{6430CF95-081A-4428-B727-E1A1EC513751}\1.0\0\win32 - Default = C:\Program Files\Bitdefender\Bitdefender\antispam32\bdo.dll HKLM\SOFTWARE\Classes\TypeLib\{6430CF95-081A-4428-B727-E1A1EC513751}\1.0\0\win64 - Default = C:\Program Files\Bitdefender\Bitdefender\bdo.dll HKLM\SOFTWARE\Classes\TypeLib\{6444C2D2-25E4-4619-A88C-32A5B6780C7C}\1.0\0\win32 - Default = C:\Program Files (x86)\Hp\Common\AclmControl.tlb HKLM\SOFTWARE\Classes\TypeLib\{662901FC-6951-4854-9EB2-D9A2570F2B2E}\5.1\0\win32 - Default = %SystemRoot%\system32\winhttp.dll HKLM\SOFTWARE\Classes\TypeLib\{66A2DB80-D706-11D0-A37B-00C04FC9DA04}\1.0\0\win64 - Default = C:\Windows\System32\rrasprxy.dll HKLM\SOFTWARE\Classes\TypeLib\{66DBA565-0D3D-4D8A-9391-A2A4CF16DF40}\1.0\0\win32 - Default = C:\Windows\SysWow64\IntelCpHeciSvc.exe HKLM\SOFTWARE\Classes\TypeLib\{675ba678-c0a4-4ff6-b432-553eb46cf217}\1.0\0\win32 - Default = %systemroot%\system32\xpsshhdr.dll HKLM\SOFTWARE\Classes\TypeLib\{680C64B0-8DA2-4399-BF4B-E94C1E52983E}\1.0\0\win32 - Default = %SystemRoot%\system32\mmc.exe\4 HKLM\SOFTWARE\Classes\TypeLib\{680C64B0-8DA2-4399-BF4B-E94C1E52983E}\1.0\0\win64 - Default = %SystemRoot%\system32\mmc.exe\4 HKLM\SOFTWARE\Classes\TypeLib\{686ba761-d755-4927-929f-94c8f67af1df}\1.0\0\win32 - Default = C:\Windows\SysWOW64\sdiagnhost.exe HKLM\SOFTWARE\Classes\TypeLib\{686ba761-d755-4927-929f-94c8f67af1df}\1.0\0\win64 - Default = C:\Windows\System32\sdiagnhost.exe HKLM\SOFTWARE\Classes\TypeLib\{6B100E1A-1385-4D1F-A02E-6E705A76BB6C}\1.0\0\win64 - Default = C:\Windows\System32\wbem\krnlprov.dll HKLM\SOFTWARE\Classes\TypeLib\{6BC09690-0CE6-11D1-BAAE-00C04FC2E20D}\1.0\0\win32 - Default = C:\Windows\SysWOW64\iassvcs.dll HKLM\SOFTWARE\Classes\TypeLib\{6BC09690-0CE6-11D1-BAAE-00C04FC2E20D}\1.0\0\win64 - Default = C:\Windows\System32\iassvcs.dll HKLM\SOFTWARE\Classes\TypeLib\{6BC096BB-0CE6-11D1-BAAE-00C04FC2E20D}\1.0\0\win32 - Default = C:\Windows\SysWOW64\iashlpr.dll HKLM\SOFTWARE\Classes\TypeLib\{6BC096BB-0CE6-11D1-BAAE-00C04FC2E20D}\1.0\0\win64 - Default = C:\Windows\System32\iashlpr.dll HKLM\SOFTWARE\Classes\TypeLib\{6BC096C5-0CE6-11D1-BAAE-00C04FC2E20D}\1.0\0\win32 - Default = C:\Windows\SysWOW64\iasads.dll HKLM\SOFTWARE\Classes\TypeLib\{6BC096C5-0CE6-11D1-BAAE-00C04FC2E20D}\1.0\0\win64 - Default = C:\Windows\System32\iasads.dll HKLM\SOFTWARE\Classes\TypeLib\{6BC09890-0CE6-11D1-BAAE-00C04FC2E20D}\1.0\0\win32 - Default = C:\Windows\SysWOW64\iasrad.dll HKLM\SOFTWARE\Classes\TypeLib\{6BC09890-0CE6-11D1-BAAE-00C04FC2E20D}\1.0\0\win64 - Default = C:\Windows\System32\iasrad.dll HKLM\SOFTWARE\Classes\TypeLib\{6BC098A0-0CE6-11D1-BAAE-00C04FC2E20D}\1.0\0\win32 - Default = C:\Windows\SysWOW64\iasnap.dll HKLM\SOFTWARE\Classes\TypeLib\{6BC098A0-0CE6-11D1-BAAE-00C04FC2E20D}\1.0\0\win64 - Default = C:\Windows\System32\iasnap.dll HKLM\SOFTWARE\Classes\TypeLib\{6BF52A50-394A-11D3-B153-00C04F79FAA6}\1.0\0\win32 - Default = %SystemRoot%\system32\wmp.dll HKLM\SOFTWARE\Classes\TypeLib\{6CAAAA3B-6502-40FE-97FC-72A290DC63CF}\1.0\0\win32 - Default = %SystemRoot%\system32\corrEngine.dll HKLM\SOFTWARE\Classes\TypeLib\{6EB22880-8A19-11D0-81B6-00A0C9231C29}\1.0\0\win32 - Default = C:\Windows\SysWOW64\Com\mtsadmin.tlb HKLM\SOFTWARE\Classes\TypeLib\{6EB22880-8A19-11D0-81B6-00A0C9231C29}\1.0\0\win64 - Default = C:\Windows\System32\Com\mtsadmin.tlb HKLM\SOFTWARE\Classes\TypeLib\{6EC6C744-355F-11D3-8470-00C04F79DBC0}\1.0\0\win32 - Default = %systemroot%\System32\mswmdm.dll HKLM\SOFTWARE\Classes\TypeLib\{7071EC00-663B-4BC1-A1FA-B97F3B917C55}\1.0\0\win32 - Default = C:\Windows\SysWOW64\tsworkspace.dll HKLM\SOFTWARE\Classes\TypeLib\{7071EC00-663B-4BC1-A1FA-B97F3B917C55}\1.0\0\win64 - Default = C:\Windows\System32\tsworkspace.dll HKLM\SOFTWARE\Classes\TypeLib\{714DD4F6-7676-4BDE-925A-C2FEC2073F36}\1.0\0\win32 - Default = C:\Windows\SysWOW64\AccessibilityCpl.dll HKLM\SOFTWARE\Classes\TypeLib\{714DD4F6-7676-4BDE-925A-C2FEC2073F36}\1.0\0\win64 - Default = C:\Windows\System32\AccessibilityCpl.dll HKLM\SOFTWARE\Classes\TypeLib\{728ab348-217d-11da-b2a4-000e7bbb2b09}\1.0\0\win32 - Default = %systemroot%\system32\CertEnroll.dll HKLM\SOFTWARE\Classes\TypeLib\{73CA1716-D932-4015-A5DA-0B8037C24788}\1.0\0\win32 - Default = C:\Windows\SysWOW64\iassam.dll HKLM\SOFTWARE\Classes\TypeLib\{73CA1716-D932-4015-A5DA-0B8037C24788}\1.0\0\win64 - Default = C:\Windows\System32\iassam.dll HKLM\SOFTWARE\Classes\TypeLib\{73F0DD5C-D071-46B6-A8BF-897C84EAAC49}\1.0\0\win32 - Default = C:\Windows\System32\wmpdxm.dll HKLM\SOFTWARE\Classes\TypeLib\{73c381a8-548c-49f8-8ad3-c845d12d3c22}\1.0\0\win64 - Default = %PROGRAMFILES%\Windows Media Player\wmpnetwk.exe HKLM\SOFTWARE\Classes\TypeLib\{7444C709-39BF-11D1-8CD9-00C04FC29D45}\1.0\0\win32 - Default = %SystemRoot%\system32\cryptext.dll HKLM\SOFTWARE\Classes\TypeLib\{74C08640-CEDB-11CF-8B49-00AA00B8A790}\1.0\0\win32 - Default = C:\Windows\SysWOW64\comsvcs.dll HKLM\SOFTWARE\Classes\TypeLib\{7586B340-EC08-11D0-A466-00C04FC30DF6}\1.0\0\win32 - Default = %SystemRoot%\system32\oleprn.dll HKLM\SOFTWARE\Classes\TypeLib\{7621FD16-FAF2-43D2-B400-133D5BAAECED}\1.0\0\win32 - Default = C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\IntelWebAPIIPTActiveX.dll HKLM\SOFTWARE\Classes\TypeLib\{773F1B9A-35B9-4E95-83A0-A210F2DE3B37}\1.0\0\win32 - Default = %SystemRoot%\System32\wisp.dll HKLM\SOFTWARE\Classes\TypeLib\{773F1B9A-35B9-4E95-83A0-A210F2DE3B37}\1.0\0\win64 - Default = %SystemRoot%\System32\wisp.dll HKLM\SOFTWARE\Classes\TypeLib\{7756C433-95F2-41A3-8BDB-1C14DF279C87}\1.0\0\win64 - Default = C:\Program Files\Intel\iCLS Client\HeciServer.exe HKLM\SOFTWARE\Classes\TypeLib\{777BA810-2498-4875-933A-3067DE883070}\1.0\0\win32 - Default = %SystemRoot%\system32\xwizards.dll HKLM\SOFTWARE\Classes\TypeLib\{777BA810-2498-4875-933A-3067DE883070}\1.0\0\win64 - Default = %SystemRoot%\system32\xwizards.dll HKLM\SOFTWARE\Classes\TypeLib\{777BA8F1-2498-4875-933A-3067DE883070}\1.0\0\win32 - Default = %SystemRoot%\system32\xwreg.dll HKLM\SOFTWARE\Classes\TypeLib\{777BA8F1-2498-4875-933A-3067DE883070}\1.0\0\win64 - Default = %SystemRoot%\system32\xwreg.dll HKLM\SOFTWARE\Classes\TypeLib\{77A6BD8A-AB60-49FF-853C-B6EE7BABAF96}\1.0\0\win32 - Default = C:\Windows\SysWOW64\wiascanprofiles.dll HKLM\SOFTWARE\Classes\TypeLib\{77A6BD8A-AB60-49FF-853C-B6EE7BABAF96}\1.0\0\win64 - Default = C:\Windows\System32\wiascanprofiles.dll HKLM\SOFTWARE\Classes\TypeLib\{78530B68-61F9-11D2-8CAD-00A024580902}\1.0\0\win32 - Default = C:\Windows\System32\qedit.dll HKLM\SOFTWARE\Classes\TypeLib\{7988B57C-EC89-11cf-9C00-00AA00A14F56}\1.0\0\win32 - Default = %SystemRoot%\System32\dskquota.dll HKLM\SOFTWARE\Classes\TypeLib\{7999FC20-D3C6-11CF-ACAB-00A024A55AEF}\1.0\0\win32 - Default = C:\Windows\SysWOW64\comsvcs.dll HKLM\SOFTWARE\Classes\TypeLib\{7C0FFAB0-CD84-11D0-949A-00A0C91110ED}\1.0\0\win32 - Default = C:\Windows\SysWOW64\msdatsrc.tlb HKLM\SOFTWARE\Classes\TypeLib\{7C0FFAB0-CD84-11D0-949A-00A0C91110ED}\1.0\0\win64 - Default = C:\Windows\System32\msdatsrc.tlb HKLM\SOFTWARE\Classes\TypeLib\{7CDB4C42-D09D-4532-AF9D-B941DF2F3E24}\1.0\0\win32 - Default = %SystemRoot%\System32\cttunesvr.exe HKLM\SOFTWARE\Classes\TypeLib\{7D868ACD-1A5D-4A47-A247-F39741353012}\1.0\0\win32 - Default = C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\InkObj.dll HKLM\SOFTWARE\Classes\TypeLib\{7D868ACD-1A5D-4A47-A247-F39741353012}\1.0\0\win64 - Default = C:\Program Files\Common Files\Microsoft Shared\Ink\InkObj.dll HKLM\SOFTWARE\Classes\TypeLib\{7E8BC440-AEFF-11D1-89C2-00C04FB6BFC4}\1.0\0\win32 - Default = C:\Windows\SysWOW64\iepeers.dll HKLM\SOFTWARE\Classes\TypeLib\{7E8BC440-AEFF-11D1-89C2-00C04FB6BFC4}\1.0\0\win64 - Default = C:\Windows\System32\iepeers.dll HKLM\SOFTWARE\Classes\TypeLib\{81DDF732-4AA8-4A35-BDFF-8B42EFE7C624}\1.0\0\win32 - Default = C:\Windows\SysWOW64\iassdo.dll\1 HKLM\SOFTWARE\Classes\TypeLib\{81DDF732-4AA8-4A35-BDFF-8B42EFE7C624}\1.0\0\win64 - Default = C:\Windows\System32\iassdo.dll\1 HKLM\SOFTWARE\Classes\TypeLib\{82D70786-7968-46EA-836D-203AEBCA4481}\1.0\0\win32 - Default = C:\Windows\system32\SynCOM.dll\3 HKLM\SOFTWARE\Classes\TypeLib\{833E4000-AFF7-4AC3-AAC2-9F24C1457BCE}\1.0\0\win32 - empty = (null) HKLM\SOFTWARE\Classes\TypeLib\{833E4000-AFF7-4AC3-AAC2-9F24C1457BCE}\1.0\0\win64 - Default = C:\Windows\System32\MsraLegacy.tlb HKLM\SOFTWARE\Classes\TypeLib\{8405D0DF-9FDD-4829-AEAD-8E2B0A18FEA4}\1.0\0\win32 - Default = C:\Windows\SysWOW64\Inked.dll HKLM\SOFTWARE\Classes\TypeLib\{8405D0DF-9FDD-4829-AEAD-8E2B0A18FEA4}\1.0\0\win64 - Default = C:\Windows\System32\Inked.dll HKLM\SOFTWARE\Classes\TypeLib\{858EE29E-B84D-49A8-992E-3A0E5BCC6545}\1.0\0\win64 - Default = C:\Windows\System32\NdisImPlatform.dll HKLM\SOFTWARE\Classes\TypeLib\{85a81b5c-b3d8-4696-bdf5-2fe3256ed031}\1.0\0\win64 - Default = C:\Windows\System32\skydrive.exe\1 HKLM\SOFTWARE\Classes\TypeLib\{8628F27C-64A2-4ED6-906B-E6155314C16A}\1.0\0\win32 - Default = C:\Windows\SysWOW64\oleacc.dll\2 HKLM\SOFTWARE\Classes\TypeLib\{8628F27C-64A2-4ED6-906B-E6155314C16A}\1.0\0\win64 - Default = C:\Windows\System32\oleacc.dll\2 HKLM\SOFTWARE\Classes\TypeLib\{87099223-C7AF-11D0-B225-00C04FB6C2F5}\1.0\0\win32 - Default = C:\Windows\SysWOW64\FXSCOM.dll HKLM\SOFTWARE\Classes\TypeLib\{87099223-C7AF-11D0-B225-00C04FB6C2F5}\1.0\0\win64 - Default = C:\Windows\System32\FXSCOM.dll HKLM\SOFTWARE\Classes\TypeLib\{87D5F036-FAC3-4390-A1E8-DFA8A62C09E7}\1.0\0\win32 - Default = C:\Windows\system32\SysFxUI.dll HKLM\SOFTWARE\Classes\TypeLib\{8A47B139-2245-430F-87A5-CB268331302F}\1.0\0\win32 - Default = %systemroot%\system32\ocsprevp.dll HKLM\SOFTWARE\Classes\TypeLib\{8AA720BF-7468-4DA1-97DA-66D2E41B3DDA}\1.0\0\win32 - Default = C:\Windows\System32\msnetobj.dll HKLM\SOFTWARE\Classes\TypeLib\{8C11EFA1-92C3-11D1-BC1E-00C04FA31489}\1.0\0\win32 - Default = C:\Windows\SysWOW64\mstscax.dll HKLM\SOFTWARE\Classes\TypeLib\{8C11EFA1-92C3-11D1-BC1E-00C04FA31489}\1.0\0\win64 - Default = C:\Windows\System32\mstscax.dll HKLM\SOFTWARE\Classes\TypeLib\{8C389764-F036-48F2-9AE2-88C260DCF43B}\1.0\0\win64 - Default = C:\Program Files\Windows Defender\MsMpCom.dll HKLM\SOFTWARE\Classes\TypeLib\{8CC497C9-A1DF-11CE-8098-00AA0047BE5D}\1.0\0\win32 - Default = C:\Windows\SysWOW64\RICHED20.dll HKLM\SOFTWARE\Classes\TypeLib\{8CC497C9-A1DF-11CE-8098-00AA0047BE5D}\1.0\0\win64 - Default = C:\Windows\System32\RICHED20.dll HKLM\SOFTWARE\Classes\TypeLib\{8E80422B-CAC4-472B-B272-9635F1DFEF3B}\1.0\0\win32 - Default = %SystemRoot%\system32\mmc.exe HKLM\SOFTWARE\Classes\TypeLib\{8E80422B-CAC4-472B-B272-9635F1DFEF3B}\1.0\0\win64 - Default = %SystemRoot%\system32\mmc.exe HKLM\SOFTWARE\Classes\TypeLib\{8FE73967-AAE2-4D77-9921-0C4962631056}\1.0\0\win32 - Default = C:\Windows\SysWOW64\PortableDeviceConnectApi.dll HKLM\SOFTWARE\Classes\TypeLib\{8FE73967-AAE2-4D77-9921-0C4962631056}\1.0\0\win64 - Default = C:\Windows\System32\PortableDeviceConnectApi.dll HKLM\SOFTWARE\Classes\TypeLib\{8acc2016-04a3-4343-b8e1-1870e35d6a41}\1.0\0\win64 - Default = C:\Windows\System32\UIAutomationCore.dll\2 HKLM\SOFTWARE\Classes\TypeLib\{8cec5857-07a1-11d9-b15e-000d56bfe6ee}\1.0\0\win32 - Default = C:\Windows\SysWOW64\HelpPaneProxy.dll HKLM\SOFTWARE\Classes\TypeLib\{8cec5857-07a1-11d9-b15e-000d56bfe6ee}\1.0\0\win64 - Default = C:\Windows\System32\HelpPaneProxy.dll HKLM\SOFTWARE\Classes\TypeLib\{8cec5860-07a1-11d9-b15e-000d56bfe6ee}\1.0\0\win32 - Default = C:\Windows\HelpPane.exe HKLM\SOFTWARE\Classes\TypeLib\{8cec5860-07a1-11d9-b15e-000d56bfe6ee}\1.0\0\win64 - Default = C:\Windows\HelpPane.exe HKLM\SOFTWARE\Classes\TypeLib\{8cec5899-07a1-11d9-b15e-000d56bfe6ee}\1.0\0\win32 - Default = C:\Windows\SysWOW64\ApDs.dll HKLM\SOFTWARE\Classes\TypeLib\{8cec5899-07a1-11d9-b15e-000d56bfe6ee}\1.0\0\win64 - Default = C:\Windows\System32\ApDs.dll HKLM\SOFTWARE\Classes\TypeLib\{913AD8CB-E288-40B7-9F7D-6B7A4EA08EA8}\1.0\0\win64 - Default = C:\Windows\System32\WorkFoldersShell.dll\1 HKLM\SOFTWARE\Classes\TypeLib\{91CE54EE-C67C-4B46-A4FF-99416F27A8BF}\1.0\0\win32 - Default = C:\Windows\SysWow64\PrintConfig.dll\1 HKLM\SOFTWARE\Classes\TypeLib\{91CE54EE-C67C-4B46-A4FF-99416F27A8BF}\1.0\0\win64 - Default = C:\Windows\system32\spool\drivers\x64\3\PrintConfig.dll\1 HKLM\SOFTWARE\Classes\TypeLib\{928CEF0C-5A84-48AC-BF37-C5C21039B83A}\1.0\0\win32 - Default = C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\micaut.dll HKLM\SOFTWARE\Classes\TypeLib\{928CEF0C-5A84-48AC-BF37-C5C21039B83A}\1.0\0\win64 - Default = C:\Program Files\Common Files\Microsoft Shared\Ink\micaut.dll HKLM\SOFTWARE\Classes\TypeLib\{92AD68AA-17E0-11D1-B230-00C04FB9473F}\1.0\0\win32 - Default = C:\Windows\SysWOW64\stclient.dll HKLM\SOFTWARE\Classes\TypeLib\{92AD68AA-17E0-11D1-B230-00C04FB9473F}\1.0\0\win64 - Default = C:\Windows\System32\stclient.dll HKLM\SOFTWARE\Classes\TypeLib\{92F94BE2-8C2E-4cd6-88ED-774A5DF42AD3}\1.0\0\win32 - Default = C:\Windows\System32\psisdecd.dll\2 HKLM\SOFTWARE\Classes\TypeLib\{944DE083-8FB8-45CF-BCB7-C477ACB2F897}\1.0\0\win32 - Default = C:\Windows\SysWOW64\UIAutomationCore.dll HKLM\SOFTWARE\Classes\TypeLib\{944DE083-8FB8-45CF-BCB7-C477ACB2F897}\1.0\0\win64 - Default = C:\Windows\System32\UIAutomationCore.dll HKLM\SOFTWARE\Classes\TypeLib\{94A0E92D-43C0-494E-AC29-FD45948A5221}\1.0\0\win32 - Default = %SystemRoot%\System32\wiaaut.dll HKLM\SOFTWARE\Classes\TypeLib\{94A67BDD-80F7-4E36-A15D-E8B08806A7AD}\1.0\0\win32 - Default = C:\Windows\SysWOW64\tsworkspace.dll HKLM\SOFTWARE\Classes\TypeLib\{94A67BDD-80F7-4E36-A15D-E8B08806A7AD}\1.0\0\win64 - Default = C:\Windows\System32\tsworkspace.dll HKLM\SOFTWARE\Classes\TypeLib\{94F6FF32-37C3-11D2-8840-00104B2AFB46}\1.0\0\win64 - Default = C:\Windows\System32\wbem\mmfutil.dll HKLM\SOFTWARE\Classes\TypeLib\{95CEF0E5-A4ED-4703-B501-AE70A153697A}\1.0\0\win32 - Default = C:\Windows\SysWOW64\wshext.dll HKLM\SOFTWARE\Classes\TypeLib\{95CEF0E5-A4ED-4703-B501-AE70A153697A}\1.0\0\win64 - Default = C:\Windows\System32\wshext.dll HKLM\SOFTWARE\Classes\TypeLib\{97d25db0-0363-11cf-abc4-02608c9e7553}\1.0\0\win32 - Default = %SystemRoot%\system32\activeds.tlb HKLM\SOFTWARE\Classes\TypeLib\{97d25db0-0363-11cf-abc4-02608c9e7553}\1.0\0\win64 - Default = %SystemRoot%\system32\activeds.tlb HKLM\SOFTWARE\Classes\TypeLib\{98315905-7BE5-11D2-ADC1-00A02463D6E7}\1.0\0\win32 - Default = C:\Windows\SysWOW64\comrepl.dll HKLM\SOFTWARE\Classes\TypeLib\{98315905-7BE5-11D2-ADC1-00A02463D6E7}\1.0\0\win64 - Default = C:\Windows\System32\comrepl.dll HKLM\SOFTWARE\Classes\TypeLib\{9853D245-3E9D-4946-895A-F30D6396DEA6}\1.0\0\win32 - Default = C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe HKLM\SOFTWARE\Classes\TypeLib\{991705AE-217D-4ACA-A0FF-07CF4FDC292D}\1.0\0\win32 - Default = %SystemRoot%\system32\RDSPnf.exe HKLM\SOFTWARE\Classes\TypeLib\{9B085638-018E-11D3-9D8E-00C04F72D980}\1.0\0\win32 - Default = C:\Windows\System32\msvidctl.dll\2 HKLM\SOFTWARE\Classes\TypeLib\{9C757116-4367-4DA9-AC0E-6C6577AD5560}\1.0\0\win32 - Default = C:\Windows\System32\mstsc.exe HKLM\SOFTWARE\Classes\TypeLib\{9CDCD9C9-BC40-41C6-89C5-230466DB0BD0}\2.0\0\win32 - Default = C:\Windows\SysWOW64\msfeeds.dll HKLM\SOFTWARE\Classes\TypeLib\{9CDCD9C9-BC40-41C6-89C5-230466DB0BD0}\2.0\0\win64 - Default = C:\Windows\System32\msfeeds.dll HKLM\SOFTWARE\Classes\TypeLib\{9D8D1D89-5F94-4F5E-80F2-A94B11734433}\1.0\0\win32 - Default = C:\Windows\system32\SynCOM.dll\2 HKLM\SOFTWARE\Classes\TypeLib\{9E175B60-F52A-11D8-B9A5-505054503030}\1.0\0\win32 - Default = %systemroot%\system32\mssrch.dll HKLM\SOFTWARE\Classes\TypeLib\{9E175B61-F52A-11D8-B9A5-505054503030}\1.0\0\win32 - Default = %systemroot%\system32\mssitlb.dll HKLM\SOFTWARE\Classes\TypeLib\{9F7668BC-E163-414C-92C6-01228863FF5A}\1.0\0\win32 - Default = C:\Windows\system32\igfxTMM.dll HKLM\SOFTWARE\Classes\TypeLib\{A0AB1CDD-CB2C-418D-9460-28B1333C6D78}\1.0\0\win32 - Default = %systemroot%\system32\DFSRHelper.dll HKLM\SOFTWARE\Classes\TypeLib\{A1B9E03C-3226-11D2-883E-00104B2AFB46}\1.0\0\win64 - Default = C:\Windows\System32\wbem\servdeps.dll HKLM\SOFTWARE\Classes\TypeLib\{A3AF4E63-207B-4EC3-AE13-1A418D83B70D}\1.0\0\win32 - Default = C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe HKLM\SOFTWARE\Classes\TypeLib\{A47EDEDD-2921-4E5A-9B91-13C953EC7FE3}\1.0\0\win32 - Default = %systemroot%\system32\wkspbrokerAx.dll HKLM\SOFTWARE\Classes\TypeLib\{A7C01D63-4403-4BE2-B1AF-6EE0A2E6A1E9}\1.0\0\win32 - Default = C:\Windows\System32\RAServer.exe HKLM\SOFTWARE\Classes\TypeLib\{A87F050D-3FFD-4682-8E77-34E530624CB4}\1.0\0\win64 - Default = C:\Windows\System32\sessionmsg.exe HKLM\SOFTWARE\Classes\TypeLib\{A961FA8D-32A6-4285-A23B-C2147A507400}\1.0\0\win32 - Default = C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\IntelWebAPIUpdaterActiveX.dll HKLM\SOFTWARE\Classes\TypeLib\{A9BF4065-8A09-457B-99D3-A78FEC725279}\1.2\0\win32 - Default = %SystemRoot%\System32\gppref.dll HKLM\SOFTWARE\Classes\TypeLib\{ABBA0019-3075-11D6-88A4-00B0D0200F88}\1.0\0\win32 - Default = C:\Windows\System32\psisdecd.dll HKLM\SOFTWARE\Classes\TypeLib\{AC3B8B4C-B6CA-11D1-9F31-00C04FC29D52}\2.6\0\win32 - Default = C:\Program Files (x86)\Common Files\System\ado\msjro.dll HKLM\SOFTWARE\Classes\TypeLib\{ADB55E1E-B550-4081-A6FC-DF44053F332B}\1.0\0\win32 - Default = C:\Windows\SysWOW64\srm.dll\2 HKLM\SOFTWARE\Classes\TypeLib\{ADB55E1E-B550-4081-A6FC-DF44053F332B}\1.0\0\win64 - Default = C:\Windows\System32\srm.dll\2 HKLM\SOFTWARE\Classes\TypeLib\{ADB880A2-D8FF-11CF-9377-00AA003B7A11}\4.0\0\win32 - Default = C:\Windows\SysWOW64\hhctrl.ocx HKLM\SOFTWARE\Classes\TypeLib\{ADB880A2-D8FF-11CF-9377-00AA003B7A11}\4.0\0\win64 - Default = C:\Windows\System32\hhctrl.ocx HKLM\SOFTWARE\Classes\TypeLib\{ADE6CC63-3C0E-4B9B-8C59-2DF6E652990A}\1.0\0\win32 - Default = C:\Windows\SysWOW64\RegCtrl.dll HKLM\SOFTWARE\Classes\TypeLib\{ADE6CC63-3C0E-4B9B-8C59-2DF6E652990A}\1.0\0\win64 - Default = C:\Windows\System32\RegCtrl.dll HKLM\SOFTWARE\Classes\TypeLib\{AEB84C80-95DC-11D0-B7FC-B61140119C4A}\1.0\0\win32 - Default = %SystemRoot%\System32\dmview.ocx HKLM\SOFTWARE\Classes\TypeLib\{B009308D-E21E-4B9F-A00B-78A1D0C6B719}\1.0\0\win64 - Default = C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\atiacm64.dll HKLM\SOFTWARE\Classes\TypeLib\{B0A20F08-4B8A-4BDE-9735-8CFC250A6B4B}\1.0\0\win32 - Default = C:\Windows\SysWOW64\TSTheme.exe HKLM\SOFTWARE\Classes\TypeLib\{B0A20F08-4B8A-4BDE-9735-8CFC250A6B4B}\1.0\0\win64 - Default = C:\Windows\System32\TSTheme.exe HKLM\SOFTWARE\Classes\TypeLib\{B0C2A63F-AFF8-40E3-B42D-8A542DC909EC}\1.0\0\win64 - Default = C:\Windows\System32\sppcomapi.dll HKLM\SOFTWARE\Classes\TypeLib\{B0EDF154-910A-11D2-B632-00C04F79498E}\1.0\0\win32 - Default = C:\Windows\System32\msvidctl.dll HKLM\SOFTWARE\Classes\TypeLib\{B17EA879-719E-4C0A-AC55-A9DC04B172AF}\1.0\0\win32 - Default = C:\Program Files (x86)\Hewlett-Packard\Shared\hputils64.dll HKLM\SOFTWARE\Classes\TypeLib\{B3A00612-1423-4072-A4F9-DE2ADCAA7F3C}\1.0\0\win64 - Default = C:\Windows\System32\EhStorShell.dll HKLM\SOFTWARE\Classes\TypeLib\{B5068196-C89F-4eb0-9F4F-85C05029CDB4}\1.0\0\win64 - Default = C:\Windows\System32\RoamingSecurity.dll HKLM\SOFTWARE\Classes\TypeLib\{B52A4496-7753-4F74-BE64-C2072E308122}\1.0\0\win32 - Default = C:\Windows\SysWOW64\wscapi.dll HKLM\SOFTWARE\Classes\TypeLib\{B52A4496-7753-4F74-BE64-C2072E308122}\1.0\0\win64 - Default = C:\Windows\System32\wscapi.dll HKLM\SOFTWARE\Classes\TypeLib\{B596CC9F-56E5-419E-A622-E01BB457431E}\2.0\0\win32 - Default = C:\Windows\SysWOW64\wuapi.dll HKLM\SOFTWARE\Classes\TypeLib\{B596CC9F-56E5-419E-A622-E01BB457431E}\2.0\0\win64 - Default = C:\Windows\System32\wuapi.dll HKLM\SOFTWARE\Classes\TypeLib\{B63D57B5-46CE-4929-ACC3-E1280FAC9880}\1.0\0\win64 - Default = C:\Windows\System32\DMRServer.exe HKLM\SOFTWARE\Classes\TypeLib\{B691E011-1797-432E-907A-4D8C69339129}\6.0\0\win32 - Default = C:\Program Files (x86)\Common Files\System\ado\msado60.tlb HKLM\SOFTWARE\Classes\TypeLib\{B691E011-1797-432E-907A-4D8C69339129}\6.0\0\win64 - Default = C:\Program Files\Common Files\System\ado\msado60.tlb HKLM\SOFTWARE\Classes\TypeLib\{B691E011-1797-432E-907A-4D8C69339129}\6.1\0\win32 - Default = C:\Program Files (x86)\Common Files\System\ado\msado15.dll HKLM\SOFTWARE\Classes\TypeLib\{B691E011-1797-432E-907A-4D8C69339129}\6.1\0\win64 - Default = C:\Program Files\Common Files\System\ado\msado15.dll HKLM\SOFTWARE\Classes\TypeLib\{B806F1A7-6278-405A-ABE4-E1AA3A3A550B}\1.0\0\win64 - Default = C:\Windows\System32\ndiscapCfg.dll HKLM\SOFTWARE\Classes\TypeLib\{B9B6535E-7706-490C-84A5-F40E125AD4B5}\1.0\0\win32 - Default = C:\Windows\SysWOW64\wpdsp.dll HKLM\SOFTWARE\Classes\TypeLib\{B9B6535E-7706-490C-84A5-F40E125AD4B5}\1.0\0\win64 - Default = C:\Windows\System32\wpdsp.dll HKLM\SOFTWARE\Classes\TypeLib\{B9C76E7B-D029-44EB-896F-F02FC6E9ABD5}\1.0\0\win32 - Default = %SystemRoot%\system32\firewallcontrolpanel.dll HKLM\SOFTWARE\Classes\TypeLib\{BACEDF3E-74AB-11D0-B162-00AA00BA3258}\1.0\0\win32 - Default = C:\Windows\SysWOW64\comsvcs.dll HKLM\SOFTWARE\Classes\TypeLib\{BB74AF42-DC70-11D2-B561-00A0C92E6848}\1.0\0\win64 - Default = C:\Windows\system32\igfxdev.dll HKLM\SOFTWARE\Classes\TypeLib\{BD96C556-65A3-11D0-983A-00C04FC29E30}\1.5\0\win32 - Default = C:\Program Files (x86)\Common Files\System\msadc\msadco.dll HKLM\SOFTWARE\Classes\TypeLib\{BD96C556-65A3-11D0-983A-00C04FC29E30}\1.5\0\win64 - Default = C:\Program Files\Common Files\System\msadc\msadco.dll HKLM\SOFTWARE\Classes\TypeLib\{BED7F4EA-1A96-11D2-8F08-00A0C9A6186D}\2.0\0\win32 - Default = C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorlib.tlb HKLM\SOFTWARE\Classes\TypeLib\{BED7F4EA-1A96-11D2-8F08-00A0C9A6186D}\2.0\0\win64 - Default = C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorlib.tlb HKLM\SOFTWARE\Classes\TypeLib\{BED7F4EA-1A96-11D2-8F08-00A0C9A6186D}\2.4\0\win32 - Default = C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorlib.tlb HKLM\SOFTWARE\Classes\TypeLib\{BED7F4EA-1A96-11D2-8F08-00A0C9A6186D}\2.4\0\win64 - Default = C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorlib.tlb HKLM\SOFTWARE\Classes\TypeLib\{BEE4BFEC-6683-3E67-9167-3C0CBC68F40A}\2.0\0\win32 - Default = C:\Windows\Microsoft.NET\Framework\v2.0.50727\System.tlb HKLM\SOFTWARE\Classes\TypeLib\{BEE4BFEC-6683-3E67-9167-3C0CBC68F40A}\2.0\0\win64 - Default = C:\Windows\Microsoft.NET\Framework64\v2.0.50727\System.tlb HKLM\SOFTWARE\Classes\TypeLib\{BEE4BFEC-6683-3E67-9167-3C0CBC68F40A}\2.4\0\win32 - Default = C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.tlb HKLM\SOFTWARE\Classes\TypeLib\{BEE4BFEC-6683-3E67-9167-3C0CBC68F40A}\2.4\0\win64 - Default = C:\Windows\Microsoft.NET\Framework64\v4.0.30319\System.tlb HKLM\SOFTWARE\Classes\TypeLib\{C01E034F-3BBF-403E-8CB9-5251AB0A7724}\1.0\0\win32 - Default = C:\Program Files (x86)\SystemRequirementsLab\srldetect_intel_4.5.24.0.dll HKLM\SOFTWARE\Classes\TypeLib\{C0653E9C-DB3B-4E9E-B3AB-B8E1DF53972F}\1.0\0\win32 - Default = %systemroot%\system32\wkspbroker.exe HKLM\SOFTWARE\Classes\TypeLib\{C0FFA723-FF4C-4983-8565-66D78E73036E}\1.0\0\win32 - Default = C:\Windows\SysWOW64\PortableDeviceClassExtension.dll HKLM\SOFTWARE\Classes\TypeLib\{C0FFA723-FF4C-4983-8565-66D78E73036E}\1.0\0\win64 - Default = C:\Windows\System32\PortableDeviceClassExtension.dll HKLM\SOFTWARE\Classes\TypeLib\{C17FED9F-5F21-4955-A572-FA22FDDB38E7}\1.0\0\win64 - Default = C:\Program Files\Shield\shdserv.exe HKLM\SOFTWARE\Classes\TypeLib\{C20B0F44-2F31-458A-9A96-ABF947A596A0}\1.0\0\win64 - Default = C:\Program Files\Shield\shdext.dll HKLM\SOFTWARE\Classes\TypeLib\{C21E9CE5-B317-463B-A1B1-B5E36EED59D0}\1.0\0\win32 - Default = %PROGRAMFILES%\Windows Media Player\WMPMediaSharing.dll HKLM\SOFTWARE\Classes\TypeLib\{C21E9CE5-B317-463B-A1B1-B5E36EED59D0}\1.0\0\win64 - Default = %PROGRAMFILES%\Windows Media Player\WMPMediaSharing.dll HKLM\SOFTWARE\Classes\TypeLib\{C2A2B169-4052-4037-88D9-E274AF31C6F7}\1.0\0\win32 - Default = C:\Windows\System32\wscui.cpl HKLM\SOFTWARE\Classes\TypeLib\{C2F48CC2-305B-4672-BAA7-76A57738F48A}\1.0\0\win32 - Default = %SystemRoot%\System32\gpmgmt.dll HKLM\SOFTWARE\Classes\TypeLib\{C3A407A9-3409-4028-ACCF-9225FD9688D7}\1.0\0\win64 - Default = C:\Windows\System32\rdpcorets.dll HKLM\SOFTWARE\Classes\TypeLib\{C4F9D6EB-4FBB-3341-A582-AEA37ED6DA94}\8.0\0\win32 - Default = C:\Windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Vsa.Vb.CodeDOMProcessor.tlb HKLM\SOFTWARE\Classes\TypeLib\{C58F1580-0DF3-401C-93B1-2D9DDA61CF04}\1.0\0\win32 - Default = %ProgramFiles%\Windows Media Player\mpvis.dll HKLM\SOFTWARE\Classes\TypeLib\{C5C5C500-3ABC-11D6-B25B-00C04FA0C026}\1.0\0\win32 - Default = C:\Windows\System32\tvratings.dll HKLM\SOFTWARE\Classes\TypeLib\{C736E83D-8599-4483-9F94-02D98B6810A9}\1.0\0\win32 - Default = C:\Windows\SysWOW64\portabledevicewmdrm.dll HKLM\SOFTWARE\Classes\TypeLib\{C736E83D-8599-4483-9F94-02D98B6810A9}\1.0\0\win64 - Default = C:\Windows\System32\portabledevicewmdrm.dll HKLM\SOFTWARE\Classes\TypeLib\{C849A630-C13D-4148-BA9E-E4D57D128F0E}\1.0\0\win32 - Default = %SystemRoot%\System32\GPOAdminCustom.dll HKLM\SOFTWARE\Classes\TypeLib\{C866CA3A-32F7-11D2-9602-00C04F8EE628}\5.4\0\win32 - Default = %SystemRoot%\System32\Speech\Common\sapi.dll HKLM\SOFTWARE\Classes\TypeLib\{C866CA3A-32F7-11D2-9602-00C04F8EE628}\5.4\0\win64 - Default = %SystemRoot%\System32\Speech\Common\sapi.dll HKLM\SOFTWARE\Classes\TypeLib\{CB72A544-F75E-42CB-932E-EB06A7063A66}\1.0\0\win32 - Default = %SystemRoot%\system32\wlanui.dll HKLM\SOFTWARE\Classes\TypeLib\{CBD2B18F-598B-4551-9FAD-4CCEDBB5A488}\1.0\0\win64 - Default = C:\Windows\System32\SyncEngine.dll\3 HKLM\SOFTWARE\Classes\TypeLib\{CC802D05-AE07-4C15-B496-DB9D22AA0A84}\1.0\0\win32 - Default = C:\Windows\SysWOW64\rdpencom.dll HKLM\SOFTWARE\Classes\TypeLib\{CC802D05-AE07-4C15-B496-DB9D22AA0A84}\1.0\0\win64 - Default = C:\Windows\System32\rdpencom.dll HKLM\SOFTWARE\Classes\TypeLib\{CD000000-8B95-11D1-82DB-00C04FB1625D}\1.0\0\win32 - Default = C:\Windows\SysWOW64\cdosys.dll HKLM\SOFTWARE\Classes\TypeLib\{CD000000-8B95-11D1-82DB-00C04FB1625D}\1.0\0\win64 - Default = C:\Windows\System32\cdosys.dll HKLM\SOFTWARE\Classes\TypeLib\{CD12A3C0-9C42-11D2-BEED-0060082F2054}\1.0\0\win32 - Default = C:\Windows\System32\WMNetMgr.dll HKLM\SOFTWARE\Classes\TypeLib\{CD6C7865-5864-11D0-ABF0-0020AF6B0B7A}\1.0\0\win32 - Default = C:\Windows\System32\dmocx.dll HKLM\SOFTWARE\Classes\TypeLib\{CDFA97AF-30C4-46B3-BDF8-66B95F676C0A}\1.0\0\win32 - Default = %SystemRoot%\System32\GPOAdmin.dll HKLM\SOFTWARE\Classes\TypeLib\{CFADAC75-E12C-11D1-B34C-00C04F990D54}\1.0\0\win32 - Default = C:\Windows\SysWOW64\catsrvut.dll HKLM\SOFTWARE\Classes\TypeLib\{CFADAC75-E12C-11D1-B34C-00C04F990D54}\1.0\0\win64 - Default = C:\Windows\System32\catsrvut.dll HKLM\SOFTWARE\Classes\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0\0\win32 - Default = C:\Windows\System32\Macromed\Flash\Flash.ocx HKLM\SOFTWARE\Classes\TypeLib\{D3295D86-D604-11D4-A704-00C04FA137E4}\8.0\0\win32 - Default = C:\Windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Vsa.tlb HKLM\SOFTWARE\Classes\TypeLib\{D3295D86-D604-11D4-A704-00C04FA137E4}\8.0\0\win64 - Default = C:\Windows\Microsoft.NET\Framework64\v2.0.50727\Microsoft.Vsa.tlb HKLM\SOFTWARE\Classes\TypeLib\{D3295D87-D604-11D4-A704-00C04FA137E4}\8.0\0\win32 - Default = C:\Windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.JScript.tlb HKLM\SOFTWARE\Classes\TypeLib\{D3295D87-D604-11D4-A704-00C04FA137E4}\8.0\0\win64 - Default = C:\Windows\Microsoft.NET\Framework64\v2.0.50727\Microsoft.JScript.tlb HKLM\SOFTWARE\Classes\TypeLib\{D3295D87-D604-11D4-A704-00C04FA137E4}\a.0\0\win32 - Default = C:\Windows\Microsoft.NET\Framework\v4.0.30319\Microsoft.JScript.tlb HKLM\SOFTWARE\Classes\TypeLib\{D3295D87-D604-11D4-A704-00C04FA137E4}\a.0\0\win64 - Default = C:\Windows\Microsoft.NET\Framework64\v4.0.30319\Microsoft.JScript.tlb HKLM\SOFTWARE\Classes\TypeLib\{D37E2A3E-8545-3A39-9F4F-31827C9124AB}\2.0\0\win32 - Default = C:\Windows\Microsoft.NET\Framework\v2.0.50727\System.Drawing.tlb HKLM\SOFTWARE\Classes\TypeLib\{D37E2A3E-8545-3A39-9F4F-31827C9124AB}\2.0\0\win64 - Default = C:\Windows\Microsoft.NET\Framework64\v2.0.50727\System.Drawing.tlb HKLM\SOFTWARE\Classes\TypeLib\{D37E2A3E-8545-3A39-9F4F-31827C9124AB}\2.4\0\win32 - Default = C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.Drawing.tlb HKLM\SOFTWARE\Classes\TypeLib\{D37E2A3E-8545-3A39-9F4F-31827C9124AB}\2.4\0\win64 - Default = C:\Windows\Microsoft.NET\Framework64\v4.0.30319\System.Drawing.tlb HKLM\SOFTWARE\Classes\TypeLib\{D4FA3D41-BE69-11D4-AA30-00902704C6BF}\1.0\0\win32 - Default = C:\Windows\system32\igfxdo.dll HKLM\SOFTWARE\Classes\TypeLib\{D597DEED-5B9F-11D1-8DD2-00AA004ABD5E}\2.0\0\win32 - Default = %SystemRoot%\System32\sens.dll HKLM\SOFTWARE\Classes\TypeLib\{D7CA032C-B7D0-429E-9FD7-82241C356B4A}\1.0\0\win32 - Default = C:\Program Files (x86)\Common Files\microsoft shared\ink\tiptsf.dll HKLM\SOFTWARE\Classes\TypeLib\{D7CA032C-B7D0-429E-9FD7-82241C356B4A}\1.0\0\win64 - Default = C:\Program Files\Common Files\microsoft shared\ink\tiptsf.dll HKLM\SOFTWARE\Classes\TypeLib\{D808BD12-DD1E-4cbc-8A3A-0A35010F078A}\1.0\0\win32 - Default = %SystemRoot%\system32\usercpl.dll HKLM\SOFTWARE\Classes\TypeLib\{DB3442A7-A2E9-4A59-9CB5-F5C1A5D901E5}\1.0\0\win32 - Default = C:\Windows\SysWOW64\upnp.dll HKLM\SOFTWARE\Classes\TypeLib\{DB3442A7-A2E9-4A59-9CB5-F5C1A5D901E5}\1.0\0\win64 - Default = C:\Windows\System32\upnp.dll HKLM\SOFTWARE\Classes\TypeLib\{DCB00D01-570F-4A9B-8D69-199FDBA5723B}\1.0\0\win32 - Default = %SystemRoot%\system32\netprofm.dll HKLM\SOFTWARE\Classes\TypeLib\{DCB00D01-570F-4A9B-8D69-199FDBA5723B}\1.0\0\win64 - Default = %SystemRoot%\system32\netprofm.dll HKLM\SOFTWARE\Classes\TypeLib\{DCB82247-779E-405C-932D-2F123364DF86}\1.0\0\win32 - Default = C:\Windows\SysWOW64\WcsPlugInService.dll HKLM\SOFTWARE\Classes\TypeLib\{DCB82247-779E-405C-932D-2F123364DF86}\1.0\0\win64 - Default = C:\Windows\System32\WcsPlugInService.dll HKLM\SOFTWARE\Classes\TypeLib\{DCBBBAB6-0001-4BBB-AAEE-338E368AF6FA}\1.0\0\win32 - Default = %SystemRoot%\system32\wwanapi.dll HKLM\SOFTWARE\Classes\TypeLib\{DD6F48D7-D5B2-4901-BE88-D140D1C40A07}\1.0\0\win32 - Default = C:\Windows\System32\bcdsrv.dll HKLM\SOFTWARE\Classes\TypeLib\{DD93A163-1406-47E0-A820-92C5ACE61614}\1.0\0\win32 - Default = C:\Windows\SysWOW64\srm.dll\1 HKLM\SOFTWARE\Classes\TypeLib\{DD93A163-1406-47E0-A820-92C5ACE61614}\1.0\0\win64 - Default = C:\Windows\System32\srm.dll\1 HKLM\SOFTWARE\Classes\TypeLib\{E0E270C2-C0BE-11D0-8FE4-00A0C90A6341}\1.5\0\win32 - Default = C:\Windows\SysWOW64\simpdata.tlb HKLM\SOFTWARE\Classes\TypeLib\{E0E270C2-C0BE-11D0-8FE4-00A0C90A6341}\1.5\0\win64 - Default = C:\Windows\System32\simpdata.tlb HKLM\SOFTWARE\Classes\TypeLib\{E2489565-2CE5-4690-9111-76E79A9F6CCD}\2.0\0\win32 - Default = C:\Windows\system32\SynCOM.dll\1 HKLM\SOFTWARE\Classes\TypeLib\{E4DE3030-0142-4ACA-BA48-8613B56A2555}\1.0\0\win64 - Default = C:\Windows\System32\Setup\FXSOCM.dll HKLM\SOFTWARE\Classes\TypeLib\{E9970F91-B6AA-11D9-B032-000D56C25C27}\1.0\0\win32 - Default = C:\Windows\SysWOW64\sdohlp.dll\1 HKLM\SOFTWARE\Classes\TypeLib\{E9970F91-B6AA-11D9-B032-000D56C25C27}\1.0\0\win64 - Default = C:\Windows\System32\sdohlp.dll\1 HKLM\SOFTWARE\Classes\TypeLib\{EA39B853-5769-4937-8ECE-736DE4F469BC}\1.0\0\win32 - Default = C:\Windows\SysWOW64\UIAutomationCoreRes.dll HKLM\SOFTWARE\Classes\TypeLib\{EA39B853-5769-4937-8ECE-736DE4F469BC}\1.0\0\win64 - Default = C:\Windows\System32\UIAutomationCoreRes.dll HKLM\SOFTWARE\Classes\TypeLib\{EA544A21-C82D-11D1-A3E4-00A0C90AEA82}\6.0\9\win32 - Default = C:\Windows\SysWOW64\msvbvm60.dll\3 HKLM\SOFTWARE\Classes\TypeLib\{EAB22AC0-30C1-11CF-A7EB-0000C05BAE0B}\1.1\0\win32 - Default = C:\Windows\SysWOW64\ieframe.dll HKLM\SOFTWARE\Classes\TypeLib\{EAB22AC0-30C1-11CF-A7EB-0000C05BAE0B}\1.1\0\win64 - Default = C:\Windows\System32\ieframe.dll HKLM\SOFTWARE\Classes\TypeLib\{EABAA706-4A6D-4E45-A255-A6E86C403ADB}\1.0\0\win32 - Default = C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\Journal.dll HKLM\SOFTWARE\Classes\TypeLib\{EABAA706-4A6D-4E45-A255-A6E86C403ADB}\1.0\0\win64 - Default = C:\Program Files\Common Files\Microsoft Shared\Ink\Journal.dll HKLM\SOFTWARE\Classes\TypeLib\{EB2114C0-CB02-467A-AE4D-2ED171F05E6A}\a.0\0\win32 - Default = C:\Windows\SysWOW64\speech\engines\tts\MSTTSEngine.dll HKLM\SOFTWARE\Classes\TypeLib\{EB2114C0-CB02-467A-AE4D-2ED171F05E6A}\a.0\0\win64 - Default = C:\Windows\System32\speech\engines\tts\MSTTSEngine.dll HKLM\SOFTWARE\Classes\TypeLib\{ECCDF535-45CC-11CE-B9BF-0080C87CDBA6}\1.0\0\win32 - Default = C:\Windows\SysWOW64\DfsShlEx.dll HKLM\SOFTWARE\Classes\TypeLib\{ECCDF535-45CC-11CE-B9BF-0080C87CDBA6}\1.0\0\win64 - Default = C:\Windows\System32\DfsShlEx.dll HKLM\SOFTWARE\Classes\TypeLib\{EE574957-4077-4AD6-8658-327C2C86C5AA}\1.0\0\win64 - Default = C:\Windows\System32\slui.exe HKLM\SOFTWARE\Classes\TypeLib\{EF53050B-882E-4776-B643-EDA472E8E3F2}\2.7\0\win32 - Default = C:\Program Files (x86)\Common Files\System\ado\msado27.tlb HKLM\SOFTWARE\Classes\TypeLib\{EF53050B-882E-4776-B643-EDA472E8E3F2}\2.7\0\win64 - Default = C:\Program Files\Common Files\System\ado\msado27.tlb HKLM\SOFTWARE\Classes\TypeLib\{EFD856A4-5A85-4A1B-ADD5-2EADACE6F6A2}\1.0\0\win32 - Default = C:\Windows\System32\RendezvousSession.tlb HKLM\SOFTWARE\Classes\TypeLib\{F010BE25-296D-4036-980F-5A0669A17577}\1.0\0\win32 - Default = C:\Windows\SysWOW64\WsmAuto.dll HKLM\SOFTWARE\Classes\TypeLib\{F010BE25-296D-4036-980F-5A0669A17577}\1.0\0\win64 - Default = C:\Windows\System32\WsmAuto.dll HKLM\SOFTWARE\Classes\TypeLib\{F31091E5-B0A8-11D6-B6FC-005056C00008}\2.0\0\win32 - Default = %systemroot%\system32\AdvancedInstallers\cmiv2.dll HKLM\SOFTWARE\Classes\TypeLib\{F31091E5-B0A8-11D6-B6FC-005056C00008}\2.0\0\win64 - Default = %systemroot%\system32\AdvancedInstallers\cmiv2.dll HKLM\SOFTWARE\Classes\TypeLib\{F5078F18-C551-11D3-89B9-0000F81FE221}\3.0\0\win32 - Default = C:\Windows\SysWOW64\msxml3.dll HKLM\SOFTWARE\Classes\TypeLib\{F5078F18-C551-11D3-89B9-0000F81FE221}\3.0\0\win64 - Default = C:\Windows\System32\msxml3.dll HKLM\SOFTWARE\Classes\TypeLib\{F5078F18-C551-11D3-89B9-0000F81FE221}\6.0\0\win32 - Default = C:\Windows\SysWOW64\msxml6.dll HKLM\SOFTWARE\Classes\TypeLib\{F5078F18-C551-11D3-89B9-0000F81FE221}\6.0\0\win64 - Default = C:\Windows\System32\msxml6.dll HKLM\SOFTWARE\Classes\TypeLib\{F618C513-DFB8-11D1-A2CF-00805FC79235}\1.0\0\win32 - Default = C:\Windows\SysWOW64\Com\comadmin.dll HKLM\SOFTWARE\Classes\TypeLib\{F618C513-DFB8-11D1-A2CF-00805FC79235}\1.0\0\win64 - Default = C:\Windows\System32\Com\comadmin.dll HKLM\SOFTWARE\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win32 - Default = C:\Windows\SysWOW64\wshom.ocx HKLM\SOFTWARE\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win64 - Default = C:\Windows\System32\wshom.ocx HKLM\SOFTWARE\Classes\TypeLib\{FA258721-CF24-45D7-A9CB-80047D7FEC35}\1.0\0\win32 - Default = %ProgramFiles%\Windows Media Player\wmprph.exe HKLM\SOFTWARE\Classes\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0\0\win32 - Default = C:\Windows\System32\Macromed\Flash\FlashUtil_ActiveX.exe HKLM\SOFTWARE\Classes\TypeLib\{FC5988CF-6D6A-4812-ADD9-2DDE4F47346F}\1.0\0\win64 - Default = C:\Windows\System32\TSWbPrxy.exe HKLM\SOFTWARE\Classes\TypeLib\{FCDECE01-A39D-11D0-ABE7-00AA0064D470}\1.0\0\win32 - Default = C:\Windows\SysWOW64\scripto.dll HKLM\SOFTWARE\Classes\TypeLib\{FCDECE01-A39D-11D0-ABE7-00AA0064D470}\1.0\0\win64 - Default = C:\Windows\System32\scripto.dll HKLM\SOFTWARE\Classes\TypeLib\{FD609BF1-0E01-403F-8F20-EA238F5CDCC3}\1.0\0\win32 - Default = C:\Windows\SysWOW64\WindowsLiveLogin.dll HKLM\SOFTWARE\Classes\TypeLib\{FD609BF1-0E01-403F-8F20-EA238F5CDCC3}\1.0\0\win64 - Default = C:\Windows\System32\WindowsLiveLogin.dll HKLM\SOFTWARE\Classes\TypeLib\{a68752ea-f302-48a4-b898-e437c6eac39a}\1.0\0\win32 - Default = C:\Windows\SysWOW64\IME\SHARED\imesearch.exe HKLM\SOFTWARE\Classes\TypeLib\{a68752ea-f302-48a4-b898-e437c6eac39a}\1.0\0\win64 - Default = C:\Windows\System32\IME\SHARED\imesearch.exe HKLM\SOFTWARE\Classes\TypeLib\{acdf1c98-a273-43b0-959d-6935f7a723be}\1.0\0\win32 - Default = C:\Windows\SysWOW64\IME\IMEKR\imkrapi.dll HKLM\SOFTWARE\Classes\TypeLib\{acdf1c98-a273-43b0-959d-6935f7a723be}\1.0\0\win64 - Default = C:\Windows\System32\IME\IMEKR\imkrapi.dll HKLM\SOFTWARE\Classes\TypeLib\{c8b522d5-5cf3-11ce-ade5-00aa0044773d}\1.0\0\win32 - Default = C:\Program Files (x86)\Common Files\System\Ole DB\oledb32.dll\2 HKLM\SOFTWARE\Classes\TypeLib\{c8b522d5-5cf3-11ce-ade5-00aa0044773d}\1.0\0\win64 - Default = C:\Program Files\Common Files\System\Ole DB\oledb32.dll\2 HKLM\SOFTWARE\Classes\TypeLib\{cf30ade7-9965-4cf8-bb05-524086fbccb2}\1.0\0\win32 - Default = C:\Windows\SysWOW64\IME\IMEKR\imkrudt.dll HKLM\SOFTWARE\Classes\TypeLib\{cf30ade7-9965-4cf8-bb05-524086fbccb2}\1.0\0\win64 - Default = C:\Windows\System32\IME\IMEKR\imkrudt.dll HKLM\SOFTWARE\Classes\TypeLib\{d0b7e02b-e1a3-11dc-81ff-001185ae5e76}\1.0\0\win32 - Default = %SystemRoot%\System32\diagcpl.dll HKLM\SOFTWARE\Classes\TypeLib\{d5090061-1f23-4611-8821-7b759123ae68}\1.0\0\win32 - Default = C:\Windows\SysWOW64\IME\IMEKR\DICTS\imkrhjd.dll HKLM\SOFTWARE\Classes\TypeLib\{d5090061-1f23-4611-8821-7b759123ae68}\1.0\0\win64 - Default = C:\Windows\System32\IME\IMEKR\DICTS\imkrhjd.dll HKLM\SOFTWARE\Classes\TypeLib\{da524058-bdb4-482a-997a-338ae04d7156}\1.0\0\win32 - Default = C:\Windows\SysWOW64\IME\shared\imjkapi.dll HKLM\SOFTWARE\Classes\TypeLib\{da524058-bdb4-482a-997a-338ae04d7156}\1.0\0\win64 - Default = C:\Windows\System32\IME\shared\imjkapi.dll HKLM\SOFTWARE\Classes\TypeLib\{dfdfb4eb-32b7-4b7f-a3d4-f798f75d3a46}\1.0\0\win32 - Default = C:\Windows\SysWOW64\iasdatastore.dll HKLM\SOFTWARE\Classes\TypeLib\{dfdfb4eb-32b7-4b7f-a3d4-f798f75d3a46}\1.0\0\win64 - Default = C:\Windows\System32\iasdatastore.dll HKLM\SOFTWARE\Classes\TypeLib\{e34cb9f1-c7f7-424c-be29-027dcc09363a}\1.0\0\win32 - Default = C:\Windows\SysWOW64\taskschd.dll HKLM\SOFTWARE\Classes\TypeLib\{e34cb9f1-c7f7-424c-be29-027dcc09363a}\1.0\0\win64 - Default = C:\Windows\System32\taskschd.dll HKLM\SOFTWARE\Classes\TypeLib\{ff9d683b-b90a-49b4-9649-f93756bad71f}\1.0\0\win32 - Default = C:\Windows\SysWOW64\EhStorAPI.dll HKLM\SOFTWARE\Classes\TypeLib\{ff9d683b-b90a-49b4-9649-f93756bad71f}\1.0\0\win64 - Default = C:\Windows\System32\EhStorAPI.dll * Category: Protocols (20 items) HKLM\SOFTWARE\Classes\PROTOCOLS\Filter\application/octet-stream - CLSID = C:\Windows\System32\mscoree.dll HKLM\SOFTWARE\Classes\PROTOCOLS\Filter\application/x-complus - CLSID = C:\Windows\System32\mscoree.dll HKLM\SOFTWARE\Classes\PROTOCOLS\Filter\application/x-msdownload - CLSID = C:\Windows\System32\mscoree.dll HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\about - CLSID = C:\Windows\System32\mshtml.dll HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\cdl - CLSID = C:\Windows\System32\urlmon.dll HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\dvd - CLSID = C:\Windows\System32\msvidctl.dll HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\file - CLSID = C:\Windows\System32\urlmon.dll HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\ftp - CLSID = C:\Windows\System32\urlmon.dll HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\http - CLSID = C:\Windows\System32\urlmon.dll HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\https - CLSID = C:\Windows\System32\urlmon.dll HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\its - CLSID = C:\Windows\System32\itss.dll HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\javascript - CLSID = C:\Windows\System32\mshtml.dll HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\local - CLSID = C:\Windows\System32\urlmon.dll HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\mailto - CLSID = C:\Windows\System32\mshtml.dll HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\mhtml - CLSID = C:\Windows\System32\inetcomm.dll HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\mk - CLSID = C:\Windows\System32\urlmon.dll HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\ms-its - CLSID = C:\Windows\System32\itss.dll HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\res - CLSID = C:\Windows\System32\mshtml.dll HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\tv - CLSID = C:\Windows\System32\msvidctl.dll HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\vbscript - CLSID = C:\Windows\System32\mshtml.dll * Category: Desktop (1 item) HKU\S-1-5-21-1582120339-517770455-3037123893-1001\Control Panel\Desktop - Wallpaper = C:\Users\hp_home\Desktop\tapety.pinger.pl_14402_tapetki[1].jpg * Category: Active Setup (7 items) HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - StubPath = %SystemRoot%\system32\unregmp2.exe /ShowWMP HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED} - StubPath = /UserInstall HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C} - StubPath = "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6} - StubPath = %SystemRoot%\system32\unregmp2.exe /FirstLogon HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340} - StubPath = U HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383} - StubPath = C:\Windows\System32\ie4uinit.exe -UserConfig HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820} - StubPath = C:\Windows\System32\Rundll32.exe C:\Windows\System32\mscories.dll,Install * Category: Drivers (1 item) HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 - msacm.l3acm = C:\Windows\System32\l3codeca.acm - VIDC.YUY2 = msyuv.dll - vidc.i420 = iyuv_32.dll - msacm.msgsm610 = msgsm32.acm - msacm.msg711 = msg711.acm - VIDC.YVYU = msyuv.dll - VIDC.YVU9 = tsbyuv.dll - wavemapper = msacm32.drv - midimapper = midimap.dll - VIDC.UYVY = msyuv.dll - VIDC.IYUV = iyuv_32.dll - vidc.mrle = msrle32.dll - msacm.imaadpcm = imaadp32.acm - msacm.msadpcm = msadp32.acm - vidc.msvc = msvidc32.dll - wave = wdmaud.drv - midi = wdmaud.drv - mixer = wdmaud.drv - aux = wdmaud.drv - wave1 = wdmaud.drv - midi1 = wdmaud.drv - mixer1 = wdmaud.drv - aux1 = wdmaud.drv - MSVideo8 = VfWWDM32.dll 07) Services: - Name: Użytkowanie aplikacji, exe path: c:\windows\system32\aelupsvc.dll, state: Running, startup: Manual - Name: Usługa bramy warstwy aplikacji, exe path: c:\windows\system32\alg.exe, state: Stopped, startup: Manual - Name: AMD External Events Utility, exe path: c:\windows\system32\atiesrxx.exe, state: Running, startup: Automatic - Name: Tożsamość aplikacji, exe path: c:\windows\system32\appidsvc.dll, state: Stopped, startup: Manual - Name: Informacje o aplikacji, exe path: c:\windows\system32\appinfo.dll, state: Running, startup: Manual - Name: Przygotowywanie aplikacji, exe path: c:\windows\system32\appreadiness.dll, state: Stopped, startup: Manual - Name: AppX Deployment Service (AppXSVC), exe path: c:\windows\system32\appxdeploymentserver.dll, state: Stopped, startup: Manual - Name: Konstruktor punktów końcowych audio systemu Windows, exe path: c:\windows\system32\audioendpointbuilder.dll, state: Running, startup: Automatic - Name: Windows Audio, exe path: c:\windows\system32\audiosrv.dll, state: Running, startup: Automatic - Name: Instalator kontrolek ActiveX (AxInstSV), exe path: c:\windows\system32\axinstsv.dll, state: Stopped, startup: Manual - Name: Bitdefender Desktop Parental Control, exe path: c:\program files\bitdefender\bitdefender\bdparentalservice.exe, state: Stopped, startup: Disabled - Name: Usługa szyfrowania dysków funkcją BitLocker, exe path: c:\windows\system32\bdesvc.dll, state: Stopped, startup: Manual - Name: Podstawowy aparat filtrowania, exe path: c:\windows\system32\bfe.dll, state: Running, startup: Automatic - Name: Usługa inteligentnego transferu w tle, exe path: c:\windows\system32\qmgr.dll, state: Stopped, startup: Manual - Name: Usługa infrastruktury zadań w tle, exe path: c:\windows\system32\bisrv.dll, state: Running, startup: Automatic - Name: Przeglądarka komputera, exe path: c:\windows\system32\browser.dll, state: Running, startup: Manual - Name: Usługa obsługi Bluetooth, exe path: c:\windows\system32\bthserv.dll, state: Stopped, startup: Manual - Name: Propagacja certyfikatu, exe path: c:\windows\system32\certprop.dll, state: Stopped, startup: Manual - Name: Aplikacja systemowa modelu COM+, exe path: c:\windows\system32\dllhost.exe /processid:{02d4b3f1-fd88-11d1-960d-00805fc79235}, state: Stopped, startup: Manual - Name: Intel(R) Content Protection HECI Service, exe path: c:\windows\syswow64\intelcphecisvc.exe, state: Stopped, startup: Manual - Name: Usługi kryptograficzne, exe path: c:\windows\system32\cryptsvc.dll, state: Running, startup: Automatic - Name: Program uruchamiający proces serwera DCOM, exe path: c:\windows\system32\rpcss.dll, state: Running, startup: Automatic - Name: Optymalizowanie dysków, exe path: c:\windows\system32\defragsvc.dll, state: Stopped, startup: Manual - Name: Usługa kojarzenia urządzeń, exe path: c:\windows\system32\das.dll, state: Stopped, startup: Manual - Name: Usługa instalacji urządzeń, exe path: c:\windows\system32\umpnpmgr.dll, state: Stopped, startup: Manual - Name: Klient DHCP, exe path: c:\windows\system32\dhcpcore.dll, state: Running, startup: Automatic - Name: Klient DNS, exe path: c:\windows\system32\dnsrslvr.dll, state: Running, startup: Automatic - Name: Automatyczna konfiguracja sieci przewodowej, exe path: c:\windows\system32\dot3svc.dll, state: Stopped, startup: Manual - Name: Usługa zasad diagnostyki, exe path: c:\windows\system32\dps.dll, state: Running, startup: Automatic - Name: Menedżer konfiguracji urządzeń, exe path: c:\windows\system32\devicesetupmanager.dll, state: Stopped, startup: Manual - Name: Protokół uwierzytelniania rozszerzonego (EAP), exe path: c:\windows\system32\eapsvc.dll, state: Stopped, startup: Manual - Name: System szyfrowania plików (EFS), exe path: c:\windows\system32\efssvc.dll, state: Stopped, startup: Manual - Name: Dziennik zdarzeń Windows, exe path: c:\windows\system32\svchost.exe -k localservicenetworkrestricted, state: Running, startup: Automatic - Name: System zdarzeń COM+, exe path: c:\windows\system32\es.dll, state: Running, startup: Automatic - Name: Faks, exe path: c:\windows\system32\fxssvc.exe, state: Stopped, startup: Manual - Name: Host dostawcy odnajdowania funkcji, exe path: c:\windows\system32\fdphost.dll, state: Running, startup: Manual - Name: Publikacja zasobów odnajdowania funkcji, exe path: c:\windows\system32\fdrespub.dll, state: Running, startup: Manual - Name: Usługa historii plików, exe path: c:\windows\system32\fhsvc.dll, state: Stopped, startup: Manual - Name: Usług systemu Windows buforowania czcionek, exe path: c:\windows\system32\fntcache.dll, state: Running, startup: Automatic - Name: Usługa buforowania czcionek platformy Windows Presentation Foundation, wersja 3.0.0.0, exe path: c:\windows\microsoft.net\framework64\v3.0\wpf\presentationfontcache.exe, state: Running, startup: Manual - Name: Klient zasad grupy, exe path: c:\windows\system32\gpsvc.dll, state: Stopped, startup: Automatic - Name: Usługa urządzeń interfejsu HID, exe path: c:\windows\system32\hidserv.dll, state: Running, startup: Manual - Name: Zarządzanie kluczami i certyfikatami kondycji, exe path: c:\windows\system32\kmsvc.dll, state: Stopped, startup: Manual - Name: Usługa nasłuchująca grup domowych, exe path: c:\windows\system32\listsvc.dll, state: Stopped, startup: Manual - Name: Dostawca grupy domowej, exe path: c:\windows\system32\provsvc.dll, state: Running, startup: Manual - Name: HP Software Framework Service, exe path: c:\program files (x86)\hewlett-packard\shared\hpqwmiex.exe, state: Stopped, startup: Manual - Name: HP Support Solutions Framework Service, exe path: c:\program files (x86)\hp\common\hpsupportsolutionsframeworkservice.exe, state: Running, startup: Automatic - Name: Usługa kolektora funkcji ETW programu Explorer Internet, exe path: c:\windows\system32\ieetwcollector.exe /v, state: Stopped, startup: Manual - Name: Moduły obsługi kluczy IPsec IKE i AuthIP, exe path: c:\windows\system32\ikeext.dll, state: Running, startup: Automatic - Name: Intel(R) Capability Licensing Service Interface, exe path: c:\program files\intel\icls client\heciserver.exe, state: Running, startup: Automatic - Name: Intel(R) ME Service, exe path: c:\program files (x86)\intel\intel(r) management engine components\fwservice\intelmefwservice.exe, state: Running, startup: Automatic - Name: Pomoc IP, exe path: c:\windows\system32\iphlpsvc.dll, state: Running, startup: Automatic - Name: Intel(R) Dynamic Application Loader Host Interface Service, exe path: c:\program files (x86)\intel\intel(r) management engine components\dal\jhi_service.exe, state: Running, startup: Automatic - Name: Izolacja klucza CNG, exe path: c:\windows\system32\keyiso.dll, state: Running, startup: Manual - Name: Usługa KTMRM dla usługi Koordynator transakcji rozproszonych, exe path: c:\windows\system32\msdtckrm.dll, state: Stopped, startup: Manual - Name: Serwer, exe path: c:\windows\system32\srvsvc.dll, state: Running, startup: Automatic - Name: Stacja robocza, exe path: c:\windows\system32\wkssvc.dll, state: Running, startup: Automatic - Name: Usługa struktury położenia systemu Windows, exe path: c:\windows\system32\geofencemonitorservice.dll, state: Stopped, startup: Manual - Name: Mapowanie z odnajdywaniem topologii warstwy linku, exe path: c:\windows\system32\lltdsvc.dll, state: Stopped, startup: Manual - Name: Pomoc TCP/IP NetBIOS, exe path: c:\windows\system32\lmhsvc.dll, state: Running, startup: Automatic - Name: Intel(R) Management and Security Application Local Management Service, exe path: c:\program files (x86)\intel\intel(r) management engine components\lms\lms.exe, state: Running, startup: Automatic - Name: Menedżer sesji lokalnej, exe path: c:\windows\system32\lsm.dll, state: Running, startup: Automatic - Name: Harmonogram klas multimediów, exe path: c:\windows\system32\mmcss.dll, state: Running, startup: Automatic - Name: Zapora systemu Windows, exe path: c:\windows\system32\mpssvc.dll, state: Running, startup: Automatic - Name: Koordynator transakcji rozproszonych, exe path: c:\windows\system32\msdtc.exe, state: Stopped, startup: Manual - Name: Usługa inicjatora iSCSI firmy Microsoft, exe path: c:\windows\system32\iscsiexe.dll, state: Stopped, startup: Manual - Name: Instalator Windows, exe path: c:\windows\system32\msiexec.exe /v, state: Stopped, startup: Manual - Name: Agent ochrony dostępu do sieci, exe path: c:\windows\system32\qagentrt.dll, state: Stopped, startup: Manual - Name: Asystent łączności sieciowej, exe path: c:\windows\system32\ncasvc.dll, state: Stopped, startup: Manual - Name: Broker połączeń sieciowych, exe path: c:\windows\system32\ncbservice.dll, state: Running, startup: Manual - Name: Autokonfiguracja urządzeń podłączonych do sieci, exe path: c:\windows\system32\ncdautosetup.dll, state: Stopped, startup: Manual - Name: NetLogon, exe path: c:\windows\system32\netlogon.dll, state: Stopped, startup: Manual - Name: Połączenia sieciowe, exe path: c:\windows\system32\netman.dll, state: Stopped, startup: Manual - Name: Usługa listy sieci, exe path: c:\windows\system32\netprofmsvc.dll, state: Running, startup: Manual - Name: Usługa udostępniania portów Net.Tcp, exe path: c:\windows\microsoft.net\framework64\v4.0.30319\smsvchost.exe, state: Stopped, startup: Disabled - Name: Rozpoznawanie lokalizacji w sieci, exe path: c:\windows\system32\nlasvc.dll, state: Running, startup: Automatic - Name: Usługa interfejsu magazynu sieciowego, exe path: c:\windows\system32\nsisvc.dll, state: Running, startup: Automatic - Name: Menedżer tożsamości sieci równorzędnej, exe path: c:\windows\system32\pnrpsvc.dll, state: Stopped, startup: Manual - Name: Grupowanie sieci równorzędnej, exe path: c:\windows\system32\p2psvc.dll, state: Stopped, startup: Manual - Name: Usługa Asystent zgodności programów, exe path: c:\windows\system32\pcasvc.dll, state: Running, startup: Automatic - Name: Performance Counter DLL Host, exe path: c:\windows\syswow64\perfhost.exe, state: Stopped, startup: Manual - Name: Dzienniki wydajności i &alerty, exe path: c:\windows\system32\pla.dll, state: Stopped, startup: Manual - Name: Plug and Play, exe path: c:\windows\system32\umpnpmgr.dll, state: Running, startup: Manual - Name: Usługa publikowania nazw komputerów PNRP, exe path: c:\windows\system32\pnrpauto.dll, state: Stopped, startup: Manual - Name: Protokół rozpoznawania nazw równorzędnych, exe path: c:\windows\system32\pnrpsvc.dll, state: Stopped, startup: Manual - Name: Agent zasad IPsec, exe path: c:\windows\system32\ipsecsvc.dll, state: Running, startup: Manual - Name: Zasilanie, exe path: c:\windows\system32\umpo.dll, state: Running, startup: Automatic - Name: Rozszerzenia i powiadomienia drukarek, exe path: c:\windows\system32\spool\drivers\x64\3\printconfig.dll, state: Stopped, startup: Manual - Name: Usługa profilów użytkowników, exe path: c:\windows\system32\profsvc.dll, state: Running, startup: Automatic - Name: Quality Windows Audio Video Experience, exe path: c:\windows\system32\qwave.dll, state: Stopped, startup: Manual - Name: Menedżer autopołączenia dostępu zdalnego, exe path: c:\windows\system32\rasauto.dll, state: Stopped, startup: Manual - Name: Menedżer połączeń usługi Dostęp zdalny, exe path: c:\windows\system32\rasmans.dll, state: Stopped, startup: Manual - Name: Routing i dostęp zdalny, exe path: c:\windows\system32\mprdim.dll, state: Stopped, startup: Disabled - Name: Rejestr zdalny, exe path: c:\windows\system32\regsvc.dll, state: Stopped, startup: Disabled - Name: Program mapowania punktów końcowych wywołań RPC, exe path: c:\windows\system32\rpcepmap.dll, state: Running, startup: Automatic - Name: Lokalizator usługi zdalnego wywołania procedury (RPC), exe path: c:\windows\system32\locator.exe, state: Stopped, startup: Manual - Name: Zdalne wywoływanie procedur (RPC), exe path: c:\windows\system32\rpcss.dll, state: Running, startup: Automatic - Name: Menedżer kont zabezpieczeń, exe path: c:\windows\system32\lsass.exe, state: Running, startup: Automatic - Name: Karta inteligentna, exe path: c:\windows\system32\scardsvr.dll, state: Stopped, startup: Disabled - Name: Usługa wyliczania urządzeń karty inteligentnej, exe path: c:\windows\system32\scdeviceenum.dll, state: Stopped, startup: Manual - Name: Harmonogram zadań, exe path: c:\windows\system32\schedsvc.dll, state: Running, startup: Automatic - Name: Zasady usuwania karty inteligentnej, exe path: c:\windows\system32\certprop.dll, state: Stopped, startup: Manual - Name: Logowanie pomocnicze, exe path: c:\windows\system32\seclogon.dll, state: Stopped, startup: Manual - Name: Secunia PSI Agent, exe path: "c:\program files (x86)\secunia\psi\psia.exe" --start-service, state: Running, startup: Automatic - Name: Secunia Update Agent, exe path: "c:\program files (x86)\secunia\psi\sua.exe" --start-service, state: Running, startup: Automatic - Name: Usługa powiadamiania o zdarzeniach systemowych, exe path: c:\windows\system32\sens.dll, state: Running, startup: Automatic - Name: Usługa monitorowania czujników, exe path: c:\windows\system32\sensrsvc.dll, state: Stopped, startup: Manual - Name: Menedżer konfiguracji usług pulpitu zdalnego, exe path: c:\windows\system32\sessenv.dll, state: Stopped, startup: Manual - Name: Udostępnianie połączenia internetowego (ICS), exe path: c:\windows\system32\ipnathlp.dll, state: Stopped, startup: Disabled - Name: ShdServ, exe path: c:\program files\shield\shdserv.exe, state: Running, startup: Automatic - Name: Wykrywanie sprzętu powłoki, exe path: c:\windows\system32\shsvcs.dll, state: Running, startup: Automatic - Name: Shield Client Service, exe path: c:\program files\shield\shieldclnt.exe, state: Running, startup: Automatic - Name: Miejsca do magazynowania firmy Microsoft — SMP, exe path: c:\windows\system32\smphost.dll, state: Stopped, startup: Manual - Name: SNMP Trap, exe path: c:\windows\system32\snmptrap.exe, state: Stopped, startup: Manual - Name: Bufor wydruku, exe path: c:\windows\system32\spoolsv.exe, state: Running, startup: Automatic - Name: Ochrona oprogramowania, exe path: c:\windows\system32\sppsvc.exe, state: Stopped, startup: Automatic - Name: Odnajdywanie SSDP, exe path: c:\windows\system32\ssdpsrv.dll, state: Stopped, startup: Manual - Name: Usługa Protokół SSTP, exe path: c:\windows\system32\sstpsvc.dll, state: Stopped, startup: Manual - Name: Windows Image Acquisition (WIA), exe path: c:\windows\system32\wiaservc.dll, state: Stopped, startup: Manual - Name: Usługa magazynu, exe path: c:\windows\system32\storsvc.dll, state: Stopped, startup: Manual - Name: Weryfikator punktowy, exe path: c:\windows\system32\svsvc.dll, state: Stopped, startup: Manual - Name: Dostawca kopiowania w tle oprogramowania firmy Microsoft, exe path: c:\windows\system32\swprv.dll, state: Stopped, startup: Manual - Name: Wstępne ładowanie do pamięci, exe path: c:\windows\system32\sysmain.dll, state: Running, startup: Automatic - Name: Broker zdarzeń systemowych, exe path: c:\windows\system32\systemeventsbrokerserver.dll, state: Running, startup: Automatic - Name: Usługa klawiatury dotykowej i panelu pisma ręcznego, exe path: c:\windows\system32\tabsvc.dll, state: Stopped, startup: Manual - Name: Telefonia, exe path: c:\windows\system32\tapisrv.dll, state: Stopped, startup: Manual - Name: Usługi pulpitu zdalnego, exe path: c:\windows\system32\termsrv.dll, state: Stopped, startup: Manual - Name: Kompozycje, exe path: c:\windows\system32\themeservice.dll, state: Running, startup: Automatic - Name: Serwer porządkujący wątki, exe path: c:\windows\system32\mmcss.dll, state: Stopped, startup: Manual - Name: Broker czasu, exe path: c:\windows\system32\timebrokerserver.dll, state: Running, startup: Manual - Name: Klient śledzenia linków rozproszonych, exe path: c:\windows\system32\trkwks.dll, state: Running, startup: Automatic - Name: Instalator modułów systemu Windows, exe path: c:\windows\servicing\trustedinstaller.exe, state: Stopped, startup: Manual - Name: Wykrywanie usług interakcyjnych, exe path: c:\windows\system32\ui0detect.exe, state: Stopped, startup: Manual - Name: Przekierowanie portu trybu użytkownika usług pulpitu zdalnego, exe path: c:\windows\system32\umrdp.dll, state: Stopped, startup: Manual - Name: Intel(R) Management and Security Application User Notification Service, exe path: c:\program files (x86)\intel\intel(r) management engine components\uns\uns.exe, state: Running, startup: Automatic - Name: Bitdefender Desktop Update Service, exe path: "c:\program files\bitdefender\bitdefender\updatesrv.exe" /service, state: Running, startup: Automatic - Name: Host urządzenia UPnP, exe path: c:\windows\system32\upnphost.dll, state: Stopped, startup: Manual - Name: Menedżer poświadczeń, exe path: c:\windows\system32\vaultsvc.dll, state: Running, startup: Manual - Name: Dysk wirtualny, exe path: c:\windows\system32\vds.exe, state: Stopped, startup: Manual - Name: Interfejs usługi gościa funkcji Hyper-V, exe path: c:\windows\system32\icsvc.dll, state: Stopped, startup: Manual - Name: Usługa pulsu funkcji Hyper-V, exe path: c:\windows\system32\icsvc.dll, state: Stopped, startup: Manual - Name: Usługa wymiany danych funkcji Hyper-V, exe path: c:\windows\system32\icsvc.dll, state: Stopped, startup: Manual - Name: Usługa wirtualizacji pulpitu zdalnego funkcji Hyper-V, exe path: c:\windows\system32\icsvc.dll, state: Stopped, startup: Manual - Name: Usługa zamykania systemu gościa funkcji Hyper-V, exe path: c:\windows\system32\icsvc.dll, state: Stopped, startup: Manual - Name: Usługa synchronizacji czasu funkcji Hyper-V, exe path: c:\windows\system32\icsvc.dll, state: Stopped, startup: Manual - Name: Obiekt żądający usługi kopiowania woluminów w tle funkcji Hyper-V, exe path: c:\windows\system32\icsvc.dll, state: Stopped, startup: Manual - Name: Kopiowanie woluminów w tle, exe path: c:\windows\system32\vssvc.exe, state: Stopped, startup: Manual - Name: Bitdefender Virus Shield, exe path: "c:\program files\bitdefender\bitdefender\vsserv.exe" /service, state: Running, startup: Automatic - Name: Windows Time, exe path: c:\windows\system32\w32time.dll, state: Stopped, startup: Manual - Name: Usługa Aparat kopii zapasowej na poziomie bloku, exe path: c:\windows\system32\wbengine.exe, state: Stopped, startup: Manual - Name: Usługa biometryczna systemu Windows, exe path: c:\windows\system32\wbiosrvc.dll, state: Stopped, startup: Manual - Name: Menedżer połączeń systemu Windows, exe path: c:\windows\system32\wcmsvc.dll, state: Running, startup: Automatic - Name: Połącz teraz w systemie Windows — Rejestrator konfiguracji, exe path: c:\windows\system32\wcncsvc.dll, state: Stopped, startup: Manual - Name: Kolory w systemie Windows, exe path: c:\windows\system32\wcspluginservice.dll, state: Stopped, startup: Manual - Name: Host usługi diagnostyki, exe path: c:\windows\system32\wdi.dll, state: Running, startup: Manual - Name: Host systemu diagnostyki, exe path: c:\windows\system32\wdi.dll, state: Stopped, startup: Manual - Name: Usługa inspekcji sieci Windows Defender, exe path: c:\program files\windows defender\nissrv.exe, state: Stopped, startup: Manual - Name: WebClient, exe path: c:\windows\system32\webclnt.dll, state: Stopped, startup: Manual - Name: Kolektor zdarzeń systemu Windows, exe path: c:\windows\system32\wecsvc.dll, state: Stopped, startup: Manual - Name: Usługa hosta dostawcy szyfrowania systemu Windows, exe path: c:\windows\system32\wephostsvc.dll, state: Stopped, startup: Manual - Name: Pomoc techniczna panelu sterowania Raporty i rozwiązania problemów, exe path: c:\windows\system32\wercplsupport.dll, state: Stopped, startup: Manual - Name: Usługa raportowania błędów systemu Windows, exe path: c:\windows\system32\wersvc.dll, state: Stopped, startup: Manual - Name: Zdarzenia pozyskiwania obrazów nieruchomych, exe path: c:\windows\system32\wiarpc.dll, state: Stopped, startup: Manual - Name: Usługa Windows Defender, exe path: c:\program files\windows defender\msmpeng.exe, state: Stopped, startup: Manual - Name: Usługa autowykrywania serwera proxy w sieci Web WinHTTP, exe path: c:\windows\system32\winhttp.dll, state: Running, startup: Manual - Name: Instrumentacja zarządzania Windows, exe path: c:\windows\system32\wbem\wmisvc.dll, state: Running, startup: Automatic - Name: Zdalne zarządzanie systemem Windows (WS-Management), exe path: c:\windows\system32\wsmsvc.dll, state: Stopped, startup: Manual - Name: Autokonfiguracja sieci WLAN, exe path: c:\windows\system32\wlansvc.dll, state: Running, startup: Automatic - Name: Asystent logowania za pomocą konta Microsoft, exe path: c:\windows\system32\wlidsvc.dll, state: Stopped, startup: Manual - Name: Karta wydajności WMI, exe path: c:\windows\system32\wbem\wmiapsrv.exe, state: Stopped, startup: Manual - Name: Usługa udostępniania w sieci programu Windows Media Player, exe path: c:\program files\windows media player\wmpnetwk.exe, state: Stopped, startup: Manual - Name: Foldery robocze, exe path: c:\windows\system32\workfolderssvc.dll, state: Stopped, startup: Manual - Name: Bezpieczeństwo rodzinne, exe path: c:\windows\system32\wpcsvc.dll, state: Stopped, startup: Manual - Name: Usługa modułu wyliczającego urządzenia przenośne, exe path: c:\windows\system32\wpdbusenum.dll, state: Stopped, startup: Manual - Name: Centrum zabezpieczeń, exe path: c:\windows\system32\wscsvc.dll, state: Running, startup: Automatic - Name: Windows Search, exe path: c:\windows\system32\searchindexer.exe /embedding, state: Running, startup: Automatic - Name: Usługa Sklep Windows (WSService), exe path: c:\windows\system32\wsservice.dll, state: Stopped, startup: Manual - Name: Windows Update, exe path: c:\windows\system32\wuaueng.dll, state: Running, startup: Manual - Name: Windows Driver Foundation — User-mode Driver Framework, exe path: c:\windows\system32\wudfsvc.dll, state: Stopped, startup: Manual - Name: Automatyczne konfigurowanie bezprzewodowej sieci WAN, exe path: c:\windows\system32\wwansvc.dll, state: Stopped, startup: Manual 08) Drivers: - Name: Usługa struktur sterowników trybu jądra, exe path: c:\windows\system32\drivers\wdf01000.sys, state: Running, startup: Boot - Name: Microsoft ACPIEx Driver, exe path: c:\windows\system32\drivers\acpiex.sys, state: Running, startup: Boot - Name: msisadrv, exe path: c:\windows\system32\drivers\msisadrv.sys, state: Running, startup: Boot - Name: ? (1), exe path: c:\windows\system32\drivers\pci.sys, state: Running, startup: Boot - Name: isapnp, exe path: c:\windows\system32\drivers\isapnp.sys, state: Stopped, startup: Boot - Name: ? (1), exe path: c:\windows\system32\drivers\vdrvroot.sys, state: Running, startup: Boot - Name: Menedżer partycji, exe path: c:\windows\system32\drivers\partmgr.sys, state: Running, startup: Boot - Name: Kontroler PDC, exe path: c:\windows\system32\drivers\pdc.sys, state: Running, startup: Boot - Name: trufos, exe path: c:\windows\system32\drivers\trufos.sys, state: Running, startup: Boot - Name: ? (1), exe path: c:\windows\system32\drivers\spaceport.sys, state: Running, startup: Boot - Name: ? (1), exe path: c:\windows\system32\drivers\volmgr.sys, state: Running, startup: Boot - Name: Menedżer woluminów dynamicznych, exe path: c:\windows\system32\drivers\volmgrx.sys, state: Running, startup: Boot - Name: Shdbus, exe path: c:\windows\system32\drivers\shdbus.sys, state: Running, startup: Boot - Name: Magistrala maszyny wirtualnej, exe path: c:\windows\system32\drivers\vmbus.sys, state: Stopped, startup: Boot - Name: nvraid, exe path: c:\windows\system32\drivers\nvraid.sys, state: Stopped, startup: Boot - Name: pciide, exe path: c:\windows\system32\drivers\pciide.sys, state: Stopped, startup: Boot - Name: intelide, exe path: c:\windows\system32\drivers\intelide.sys, state: Stopped, startup: Boot - Name: viaide, exe path: c:\windows\system32\drivers\viaide.sys, state: Stopped, startup: Boot - Name: ? (1), exe path: c:\windows\system32\drivers\bxvbda.sys, state: Stopped, startup: Boot - Name: ? (1), exe path: c:\windows\system32\drivers\evbda.sys, state: Stopped, startup: Boot - Name: pcmcia, exe path: c:\windows\system32\drivers\pcmcia.sys, state: Stopped, startup: Boot - Name: Menedżer punktów instalacji, exe path: c:\windows\system32\drivers\mountmgr.sys, state: Running, startup: Boot - Name: ? (1), exe path: c:\windows\system32\drivers\iastorv.sys, state: Stopped, startup: Boot - Name: nvstor, exe path: c:\windows\system32\drivers\nvstor.sys, state: Stopped, startup: Boot - Name: LSI_SAS, exe path: c:\windows\system32\drivers\lsi_sas.sys, state: Stopped, startup: Boot - Name: LSI_SAS2, exe path: c:\windows\system32\drivers\lsi_sas2.sys, state: Stopped, startup: Boot - Name: LSI_SAS3, exe path: c:\windows\system32\drivers\lsi_sas3.sys, state: Stopped, startup: Boot - Name: LSI_SSS, exe path: c:\windows\system32\drivers\lsi_sss.sys, state: Stopped, startup: Boot - Name: 3ware, exe path: c:\windows\system32\drivers\3ware.sys, state: Stopped, startup: Boot - Name: mvumis, exe path: c:\windows\system32\drivers\mvumis.sys, state: Stopped, startup: Boot - Name: ? (1), exe path: c:\windows\system32\drivers\vstxraid.sys, state: Stopped, startup: Boot - Name: megasas, exe path: c:\windows\system32\drivers\megasas.sys, state: Stopped, startup: Boot - Name: megasr, exe path: c:\windows\system32\drivers\megasr.sys, state: Stopped, startup: Boot - Name: ? (1), exe path: c:\windows\system32\drivers\iastorav.sys, state: Stopped, startup: Boot - Name: amdsata, exe path: c:\windows\system32\drivers\amdsata.sys, state: Stopped, startup: Boot - Name: amdxata, exe path: c:\windows\system32\drivers\amdxata.sys, state: Stopped, startup: Boot - Name: amdsbs, exe path: c:\windows\system32\drivers\amdsbs.sys, state: Stopped, startup: Boot - Name: ? (1), exe path: c:\windows\system32\drivers\arcsas.sys, state: Stopped, startup: Boot - Name: vsmraid, exe path: c:\windows\system32\drivers\vsmraid.sys, state: Stopped, startup: Boot - Name: SiSRaid2, exe path: c:\windows\system32\drivers\sisraid2.sys, state: Stopped, startup: Boot - Name: SiSRaid4, exe path: c:\windows\system32\drivers\sisraid4.sys, state: Stopped, startup: Boot - Name: ? (1), exe path: c:\windows\system32\drivers\atapi.sys, state: Stopped, startup: Boot - Name: ? (1), exe path: c:\windows\system32\drivers\storahci.sys, state: Running, startup: Boot - Name: ? (1), exe path: c:\windows\system32\drivers\stornvme.sys, state: Stopped, startup: Boot - Name: stexstor, exe path: c:\windows\system32\drivers\stexstor.sys, state: Stopped, startup: Boot - Name: ADP80XX, exe path: c:\windows\system32\drivers\adp80xx.sys, state: Stopped, startup: Boot - Name: HpSAMD, exe path: c:\windows\system32\drivers\hpsamd.sys, state: Stopped, startup: Boot - Name: ? (1), exe path: c:\windows\system32\drivers\ehstortcgdrv.sys, state: Stopped, startup: Boot - Name: Enhanced Storage Filter Driver, exe path: c:\windows\system32\drivers\ehstorclass.sys, state: Running, startup: Boot - Name: FltMgr, exe path: c:\windows\system32\drivers\fltmgr.sys, state: Running, startup: Boot - Name: File Information FS MiniFilter, exe path: c:\windows\system32\drivers\fileinfo.sys, state: Running, startup: Boot - Name: Windows Overlay File System Filter Driver, exe path: c:\windows\system32\drivers\wof.sys, state: Running, startup: Boot - Name: avc3, exe path: c:\windows\system32\drivers\avc3.sys, state: Running, startup: Boot - Name: gzflt, exe path: c:\windows\system32\drivers\gzflt.sys, state: Running, startup: Boot - Name: Common Log (CLFS), exe path: c:\windows\system32\drivers\clfs.sys, state: Running, startup: Boot - Name: Shieldm, exe path: c:\windows\system32\drivers\shieldm.sys, state: Running, startup: Boot - Name: Shieldf, exe path: c:\windows\system32\drivers\shieldf.sys, state: Running, startup: Boot - Name: Shield, exe path: c:\windows\system32\drivers\shield.sys, state: Running, startup: Boot - Name: KSecDD, exe path: c:\windows\system32\drivers\ksecdd.sys, state: Running, startup: Boot - Name: storvsc, exe path: c:\windows\system32\drivers\storvsc.sys, state: Stopped, startup: Boot - Name: Performance Counters for Windows Driver, exe path: c:\windows\system32\drivers\pcw.sys, state: Running, startup: Boot - Name: Sterownik systemowy NDIS, exe path: c:\windows\system32\drivers\ndis.sys, state: Running, startup: Boot - Name: KSecPkg, exe path: c:\windows\system32\drivers\ksecpkg.sys, state: Running, startup: Boot - Name: Sterownik protokołu TCP/IP, exe path: c:\windows\system32\drivers\tcpip.sys, state: Running, startup: Boot - Name: Microsoft Windows Filtering Platform, exe path: c:\windows\system32\drivers\wfplwfs.sys, state: Running, startup: Boot - Name: Akcelerator magazynu funkcji Hyper-V, exe path: c:\windows\system32\drivers\vmstorfl.sys, state: Stopped, startup: Boot - Name: ? (1), exe path: c:\windows\system32\drivers\acpi.sys, state: Running, startup: Boot - Name: ? (1), exe path: c:\windows\system32\drivers\agp440.sys, state: Stopped, startup: Boot - Name: ? (1), exe path: c:\windows\system32\drivers\amdkmpfd.sys, state: Running, startup: Boot - Name: bdelam, exe path: c:\windows\system32\drivers\bdelam.sys, state: Stopped, startup: Boot - Name: CNG, exe path: c:\windows\system32\drivers\cng.sys, state: Running, startup: Boot - Name: ? (1), exe path: c:\windows\system32\drivers\disk.sys, state: Running, startup: Boot - Name: Sterownik filtru szyfrowania dysków funkcją BitLocker, exe path: c:\windows\system32\drivers\fvevol.sys, state: Running, startup: Boot - Name: ? (1), exe path: c:\windows\system32\drivers\gagp30kx.sys, state: Stopped, startup: Boot - Name: Hardware Policy Driver, exe path: c:\windows\system32\drivers\hwpolicy.sys, state: Stopped, startup: Boot - Name: ? (1), exe path: c:\windows\system32\drivers\intelpep.sys, state: Running, startup: Boot - Name: MUP, exe path: c:\windows\system32\drivers\mup.sys, state: Running, startup: Boot - Name: ? (1), exe path: c:\windows\system32\drivers\nv_agp.sys, state: Stopped, startup: Boot - Name: ReadyBoost, exe path: c:\windows\system32\drivers\rdyboost.sys, state: Running, startup: Boot - Name: ? (1), exe path: c:\windows\system32\drivers\sbp2port.sys, state: Stopped, startup: Boot - Name: ? (1), exe path: c:\windows\system32\drivers\uagp35.sys, state: Stopped, startup: Boot - Name: ? (1), exe path: c:\windows\system32\drivers\uliagpkx.sys, state: Stopped, startup: Boot - Name: ? (1), exe path: c:\windows\system32\drivers\volsnap.sys, state: Running, startup: Boot - Name: ? (1), exe path: c:\windows\system32\drivers\cdrom.sys, state: Running, startup: System - Name: Beep, exe path: c:\windows\system32\drivers\beep.sys, state: Running, startup: System - Name: Null, exe path: c:\windows\system32\drivers\null.sys, state: Running, startup: System - Name: BasicRender, exe path: c:\windows\system32\drivers\basicrender.sys, state: Running, startup: System - Name: BasicDisplay, exe path: c:\windows\system32\drivers\basicdisplay.sys, state: Running, startup: System - Name: Msfs, exe path: c:\windows\system32\drivers\msfs.sys, state: Running, startup: System - Name: Npfs, exe path: c:\windows\system32\drivers\npfs.sys, state: Running, startup: System - Name: ? (1), exe path: c:\program files\common files\bitdefender\bitdefender firewall\bdfndisf6.sys, state: Running, startup: System - Name: bdfwfpf, exe path: c:\program files\common files\bitdefender\bitdefender firewall\bdfwfpf.sys, state: Running, startup: System - Name: Sterownik obsługi starszych urządzeń TDI NetIO, exe path: c:\windows\system32\drivers\tdx.sys, state: Running, startup: System - Name: Sterownik funkcji pomocniczej usługi Winsock, exe path: c:\windows\system32\drivers\afd.sys, state: Running, startup: System - Name: NETBT, exe path: c:\windows\system32\drivers\netbt.sys, state: Running, startup: System - Name: Harmonogram pakietów QoS, exe path: c:\windows\system32\drivers\pacer.sys, state: Running, startup: System - Name: Virtual WiFi Filter Driver, exe path: c:\windows\system32\drivers\vwififlt.sys, state: Running, startup: System - Name: ? (1), exe path: c:\windows\system32\drivers\netbios.sys, state: Running, startup: System - Name: Application Compatibility Cache, exe path: c:\windows\system32\drivers\ahcache.sys, state: Running, startup: System - Name: Desktop Activity Moderator Driver, exe path: c:\windows\system32\drivers\dam.sys, state: Stopped, startup: System - Name: Sterownik klienta przestrzeni nazw systemu plików DFS, exe path: c:\windows\system32\drivers\dfsc.sys, state: Running, startup: System - Name: ? (1), exe path: c:\windows\system32\drivers\mssmbios.sys, state: Running, startup: System - Name: ? (1), exe path: c:\windows\system32\drivers\npsvctrig.sys, state: Running, startup: System - Name: NSI Proxy Service Driver, exe path: c:\windows\system32\drivers\nsiproxy.sys, state: Running, startup: System - Name: Podsystem buforowania przekierowywanych danych, exe path: c:\windows\system32\drivers\rdbss.sys, state: Running, startup: System - Name: Sterownik usługi Dostęp zdalny IPv6 ARP, exe path: c:\windows\system32\drivers\wanarp.sys, state: Running, startup: System - Name: ? (1), exe path: c:\windows\system32\drivers\i8042prt.sys, state: Running, startup: Manual - Name: ? (1), exe path: c:\windows\system32\drivers\ialpssi_gpio.sys, state: Stopped, startup: Manual - Name: ? (1), exe path: c:\windows\system32\drivers\ialpssi_i2c.sys, state: Stopped, startup: Manual - Name: igfx, exe path: c:\windows\system32\drivers\igdkmd64.sys, state: Running, startup: Manual - Name: ? (1), exe path: c:\windows\system32\drivers\intelppm.sys, state: Running, startup: Manual - Name: Sterownik filtru ruchu IP, exe path: c:\windows\system32\drivers\ipfltdrv.sys, state: Stopped, startup: Manual - Name: IPMIDRV, exe path: c:\windows\system32\drivers\ipmidrv.sys, state: Stopped, startup: Manual - Name: IP Network Address Translator, exe path: c:\windows\system32\drivers\ipnat.sys, state: Stopped, startup: Manual - Name: IR Bus Enumerator, exe path: c:\windows\system32\drivers\irenum.sys, state: Stopped, startup: Manual - Name: ? (1), exe path: c:\windows\system32\drivers\msiscsi.sys, state: Stopped, startup: Manual - Name: ? (1), exe path: c:\windows\system32\drivers\kbdclass.sys, state: Running, startup: Manual - Name: ? (1), exe path: c:\windows\system32\drivers\kbdhid.sys, state: Running, startup: Manual - Name: ? (1), exe path: c:\windows\system32\drivers\kdnic.sys, state: Running, startup: Manual - Name: Sterownik We/Wy mapowania z odnajdywaniem topologii warstwy linku, exe path: c:\windows\system32\drivers\lltdio.sys, state: Running, startup: Automatic - Name: Wirtualizacja pliku UAC, exe path: c:\windows\system32\drivers\luafv.sys, state: Running, startup: Automatic - Name: ? (1), exe path: c:\windows\system32\drivers\hecix64.sys, state: Running, startup: Manual - Name: Modem, exe path: c:\windows\system32\drivers\modem.sys, state: Stopped, startup: Manual - Name: ? (1), exe path: c:\windows\system32\drivers\monitor.sys, state: Running, startup: Manual - Name: ? (1), exe path: c:\windows\system32\drivers\mouclass.sys, state: Running, startup: Manual - Name: ? (1), exe path: c:\windows\system32\drivers\mouhid.sys, state: Running, startup: Manual - Name: Sterownik uwierzytelniania Zapory systemu Windows, exe path: c:\windows\system32\drivers\mpsdrv.sys, state: Running, startup: Manual - Name: Sterownik przekierowań klienta WebDav, exe path: c:\windows\system32\drivers\mrxdav.sys, state: Stopped, startup: Manual - Name: Otoka i aparat minireadresatora SMB, exe path: c:\windows\system32\drivers\mrxsmb.sys, state: Running, startup: Manual - Name: Minireadresator SMB 1.x, exe path: c:\windows\system32\drivers\mrxsmb10.sys, state: Running, startup: Automatic - Name: Minireadresator SMB 2.0, exe path: c:\windows\system32\drivers\mrxsmb20.sys, state: Running, startup: Manual - Name: Mostek Microsoft MAC, exe path: c:\windows\system32\drivers\bridge.sys, state: Stopped, startup: Manual - Name: ? (1), exe path: c:\windows\system32\drivers\msgpiowin32.sys, state: Stopped, startup: Manual - Name: Pass-through HID to KMDF Filter Driver, exe path: c:\windows\system32\drivers\mshidkmdf.sys, state: Stopped, startup: Manual - Name: Sterownik przekazywania między obiektem HID a UMDF, exe path: c:\windows\system32\drivers\mshidumdf.sys, state: Stopped, startup: Manual - Name: ? (1), exe path: c:\windows\system32\drivers\mskssrv.sys, state: Stopped, startup: Manual - Name: Protokół LLDP (Link-Layer Discovery Protocol) firmy Microsoft, exe path: c:\windows\system32\drivers\mslldp.sys, state: Stopped, startup: Manual - Name: ? (1), exe path: c:\windows\system32\drivers\mspclock.sys, state: Stopped, startup: Manual - Name: ? (1), exe path: c:\windows\system32\drivers\mspqm.sys, state: Stopped, startup: Manual - Name: MsRPC, exe path: c:\windows\system32\drivers\msrpc.sys, state: Stopped, startup: Manual - Name: ? (1), exe path: c:\windows\system32\drivers\mstee.sys, state: Stopped, startup: Manual - Name: ? (1), exe path: c:\windows\system32\drivers\mtconfig.sys, state: Stopped, startup: Manual - Name: Kernel Streaming Thunks, exe path: c:\windows\system32\drivers\ksthunk.sys, state: Running, startup: Manual - Name: Filtr NativeWiFi, exe path: c:\windows\system32\drivers\nwifi.sys, state: Running, startup: Automatic - Name: ? (1), exe path: c:\windows\system32\drivers\acpipagr.sys, state: Stopped, startup: Manual - Name: Przechwytywanie NDIS firmy Microsoft, exe path: c:\windows\system32\drivers\ndiscap.sys, state: Stopped, startup: Manual - Name: Protokół multipleksera karty sieciowej firmy Microsoft, exe path: c:\windows\system32\drivers\ndisimplatform.sys, state: Stopped, startup: Manual - Name: Sterownik usługi Dostęp zdalny NDIS TAPI, exe path: c:\windows\system32\drivers\ndistapi.sys, state: Stopped, startup: Manual - Name: ? (1), exe path: c:\windows\system32\drivers\ndisuio.sys, state: Running, startup: Manual - Name: Moduł wyliczający wirtualnej karty sieciowej firmy Microsoft, exe path: c:\windows\system32\drivers\ndisvirtualbus.sys, state: Running, startup: Manual - Name: Sterownik usługi Dostęp zdalny NDIS WAN, exe path: c:\windows\system32\drivers\ndiswan.sys, state: Stopped, startup: Manual - Name: Starszy sterownik usługi Dostęp zdalny NDIS WAN, exe path: c:\windows\system32\drivers\ndiswan.sys, state: Stopped, startup: Manual - Name: NDProxy, exe path: c:\windows\system32\drivers\ndproxy.sys, state: Stopped, startup: Manual - Name: Windows Network Data Usage Monitoring Driver, exe path: c:\windows\system32\drivers\ndu.sys, state: Running, startup: Automatic - Name: ? (1), exe path: c:\windows\system32\drivers\acpipmi.sys, state: Stopped, startup: Manual - Name: ? (1), exe path: c:\windows\system32\drivers\acpitime.sys, state: Stopped, startup: Manual - Name: ? (1), exe path: c:\windows\system32\drivers\netr28x.sys, state: Running, startup: Manual - Name: netvsc, exe path: c:\windows\system32\drivers\netvsc63.sys, state: Stopped, startup: Manual - Name: ? (1), exe path: c:\windows\system32\drivers\amdk8.sys, state: Stopped, startup: Manual - Name: amdkmdag, exe path: c:\windows\system32\drivers\atikmdag.sys, state: Running, startup: Manual - Name: amdkmdap, exe path: c:\windows\system32\drivers\atikmpag.sys, state: Running, startup: Manual - Name: Ntfs, exe path: c:\windows\system32\drivers\ntfs.sys, state: Running, startup: Manual - Name: ? (1), exe path: c:\windows\system32\drivers\amdppm.sys, state: Stopped, startup: Manual - Name: Sterownik AppID, exe path: c:\windows\system32\drivers\appid.sys, state: Stopped, startup: Manual - Name: Sterownik multimediów asynchronicznych RAS, exe path: c:\windows\system32\drivers\asyncmac.sys, state: Stopped, startup: Manual - Name: ? (1), exe path: c:\windows\system32\drivers\avchv.sys, state: Running, startup: Manual - Name: ? (1), exe path: c:\windows\system32\drivers\parport.sys, state: Stopped, startup: Manual - Name: avckf, exe path: c:\windows\system32\drivers\avckf.sys, state: Running, startup: Manual - Name: ? (1), exe path: c:\windows\system32\drivers\bcmfn2.sys, state: Stopped, startup: Manual - Name: bdfwfpf_pc, exe path: c:\program files\common files\bitdefender\bitdefender firewall\bdfwfpf_pc.sys, state: Stopped, startup: Manual - Name: BDSandBox, exe path: c:\windows\system32\drivers\bdsandbox.sys, state: Stopped, startup: Manual - Name: ? (1), exe path: c:\windows\system32\drivers\1394ohci.sys, state: Stopped, startup: Manual - Name: Sterownik obsługi przeglądarki, exe path: c:\windows\system32\drivers\bowser.sys, state: Running, startup: Manual - Name: PEAUTH, exe path: c:\windows\system32\drivers\peauth.sys, state: Running, startup: Automatic - Name: Miniport WAN (PPTP), exe path: c:\windows\system32\drivers\raspptp.sys, state: Stopped, startup: Manual - Name: ? (1), exe path: c:\windows\system32\drivers\processr.sys, state: Stopped, startup: Manual - Name: ? (1), exe path: c:\windows\system32\drivers\bthavrcptg.sys, state: Stopped, startup: Manual - Name: PSI, exe path: c:\windows\system32\drivers\psi_mf_amd64.sys, state: Running, startup: Manual - Name: Sterownik QWAVE, exe path: c:\windows\system32\drivers\qwavedrv.sys, state: Stopped, startup: Manual - Name: Remote Access Auto Connection Driver, exe path: c:\windows\system32\drivers\rasacd.sys, state: Stopped, startup: Manual - Name: ? (1), exe path: c:\windows\system32\drivers\agilevpn.sys, state: Stopped, startup: Manual - Name: Miniport WAN (L2TP), exe path: c:\windows\system32\drivers\rasl2tp.sys, state: Stopped, startup: Manual - Name: Sterownik usługi Dostęp zdalny PPPOE, exe path: c:\windows\system32\drivers\raspppoe.sys, state: Stopped, startup: Manual - Name: WAN Miniport (SSTP), exe path: c:\windows\system32\drivers\rassstp.sys, state: Stopped, startup: Manual - Name: ? (1), exe path: c:\windows\system32\drivers\bthhfenum.sys, state: Stopped, startup: Manual - Name: ? (1), exe path: c:\windows\system32\drivers\rdpbus.sys, state: Running, startup: Manual - Name: Remote Desktop Device Redirector Driver, exe path: c:\windows\system32\drivers\rdpdr.sys, state: Stopped, startup: Manual - Name: Remote Desktop Video Miniport Driver, exe path: c:\windows\system32\drivers\rdpvideominiport.sys, state: Stopped, startup: Manual - Name: ? (1), exe path: c:\windows\system32\drivers\bthhfhid.sys, state: Stopped, startup: Manual - Name: ReFS, exe path: c:\windows\system32\drivers\refs.sys, state: Stopped, startup: Manual - Name: ? (1), exe path: c:\windows\system32\drivers\rtsp2stor.sys, state: Running, startup: Manual - Name: Responder odnajdywania topologii warstwy linku, exe path: c:\windows\system32\drivers\rspndr.sys, state: Running, startup: Automatic - Name: ? (1), exe path: c:\windows\system32\drivers\rtbth.sys, state: Running, startup: Manual - Name: ? (1), exe path: c:\windows\system32\drivers\rt630x64.sys, state: Stopped, startup: Manual - Name: s3cap, exe path: c:\windows\system32\drivers\vms3cap.sys, state: Stopped, startup: Manual - Name: ? (1), exe path: c:\windows\system32\drivers\bthmodem.sys, state: Stopped, startup: Manual - Name: Sterownik filtru klas karty inteligentnej PnP, exe path: c:\windows\system32\drivers\scfilter.sys, state: Stopped, startup: Manual - Name: sdbus, exe path: c:\windows\system32\drivers\sdbus.sys, state: Stopped, startup: Manual - Name: ? (1), exe path: c:\windows\system32\drivers\sdstor.sys, state: Stopped, startup: Manual - Name: Security Driver, exe path: c:\windows\system32\drivers\secdrv.sys, state: Running, startup: Automatic - Name: Serial UART Support Library, exe path: c:\windows\system32\drivers\sercx.sys, state: Stopped, startup: Manual - Name: Serial UART Support Library, exe path: c:\windows\system32\drivers\sercx2.sys, state: Stopped, startup: Manual - Name: ? (1), exe path: c:\windows\system32\drivers\serenum.sys, state: Stopped, startup: Manual - Name: ? (1), exe path: c:\windows\system32\drivers\serial.sys, state: Stopped, startup: Manual - Name: ? (1), exe path: c:\windows\system32\drivers\sermouse.sys, state: Stopped, startup: Manual - Name: ? (1), exe path: c:\windows\system32\drivers\sfloppy.sys, state: Stopped, startup: Manual - Name: CD/DVD File System Reader, exe path: c:\windows\system32\drivers\cdfs.sys, state: Stopped, startup: Disabled - Name: ? (1), exe path: c:\windows\system32\drivers\circlass.sys, state: Stopped, startup: Manual - Name: ? (1), exe path: c:\windows\system32\drivers\cmbatt.sys, state: Running, startup: Manual - Name: ? (1), exe path: c:\windows\system32\drivers\compositebus.sys, state: Running, startup: Manual - Name: Console Driver, exe path: c:\windows\system32\drivers\condrv.sys, state: Running, startup: Manual - Name: cpudrv64, exe path: c:\program files (x86)\systemrequirementslab\cpudrv64.sys, state: Stopped, startup: Manual - Name: dmvsc, exe path: c:\windows\system32\drivers\dmvsc.sys, state: Stopped, startup: Manual - Name: Simple Peripheral Bus Support Library, exe path: c:\windows\system32\drivers\spbcx.sys, state: Stopped, startup: Manual - Name: Sterownik serwera SMB 1.xxx, exe path: c:\windows\system32\drivers\srv.sys, state: Running, startup: Automatic - Name: Sterownik serwera SMB 2.xxx, exe path: c:\windows\system32\drivers\srv2.sys, state: Running, startup: Manual - Name: srvnet, exe path: c:\windows\system32\drivers\srvnet.sys, state: Running, startup: Manual - Name: ? (1), exe path: c:\windows\system32\drivers\drmkaud.sys, state: Stopped, startup: Manual - Name: LDDM Graphics Subsystem, exe path: c:\windows\system32\drivers\dxgkrnl.sys, state: Running, startup: Manual - Name: ? (1), exe path: c:\windows\system32\drivers\errdev.sys, state: Stopped, startup: Manual - Name: esihdrv, exe path: c:\users\hp_home\appdata\local\temp\esihdrv.sys, state: Running, startup: Manual - Name: exFAT File System Driver, exe path: c:\windows\system32\drivers\exfat.sys, state: Stopped, startup: Manual - Name: ? (1), exe path: c:\windows\system32\drivers\swenum.sys, state: Running, startup: Manual - Name: ? (1), exe path: c:\windows\system32\drivers\syntp.sys, state: Running, startup: Manual - Name: FAT12/16/32 File System Driver, exe path: c:\windows\system32\drivers\fastfat.sys, state: Running, startup: Manual - Name: ? (1), exe path: c:\windows\system32\drivers\tcpip.sys, state: Stopped, startup: Manual - Name: TCP/IP Registry Compatibility, exe path: c:\windows\system32\drivers\tcpipreg.sys, state: Running, startup: Automatic - Name: ? (1), exe path: c:\windows\system32\drivers\fdc.sys, state: Stopped, startup: Manual - Name: ? (1), exe path: c:\windows\system32\drivers\terminpt.sys, state: Stopped, startup: Manual - Name: ? (1), exe path: c:\windows\system32\drivers\tpm.sys, state: Stopped, startup: Manual - Name: FileTrace, exe path: c:\windows\system32\drivers\filetrace.sys, state: Stopped, startup: Manual - Name: TsUsbFlt, exe path: c:\windows\system32\drivers\tsusbflt.sys, state: Stopped, startup: Manual - Name: ? (1), exe path: c:\windows\system32\drivers\tsusbgd.sys, state: Stopped, startup: Manual - Name: ? (1), exe path: c:\windows\system32\drivers\tunnel.sys, state: Running, startup: Manual - Name: ? (1), exe path: c:\windows\system32\drivers\flpydisk.sys, state: Stopped, startup: Manual - Name: ? (1), exe path: c:\windows\system32\drivers\uaspstor.sys, state: Stopped, startup: Manual - Name: USB Controller Extension, exe path: c:\windows\system32\drivers\ucx01000.sys, state: Running, startup: Manual - Name: udfs, exe path: c:\windows\system32\drivers\udfs.sys, state: Stopped, startup: Disabled - Name: ? (1), exe path: c:\windows\system32\drivers\uefi.sys, state: Stopped, startup: Manual - Name: File System Dependency Minifilter, exe path: c:\windows\system32\drivers\fsdepends.sys, state: Stopped, startup: Manual - Name: ? (1), exe path: c:\windows\system32\drivers\umbus.sys, state: Running, startup: Manual - Name: ? (1), exe path: c:\windows\system32\drivers\umpass.sys, state: Stopped, startup: Manual - Name: ? (1), exe path: c:\windows\system32\drivers\usbccgp.sys, state: Running, startup: Manual - Name: ? (1), exe path: c:\windows\system32\drivers\usbcir.sys, state: Stopped, startup: Manual - Name: ? (1), exe path: c:\windows\system32\drivers\usbehci.sys, state: Running, startup: Manual - Name: ? (1), exe path: c:\windows\system32\drivers\usbhub.sys, state: Running, startup: Manual - Name: ? (1), exe path: c:\windows\system32\drivers\usbhub3.sys, state: Running, startup: Manual - Name: ? (1), exe path: c:\windows\system32\drivers\usbohci.sys, state: Stopped, startup: Manual - Name: ? (1), exe path: c:\windows\system32\drivers\usbprint.sys, state: Stopped, startup: Manual - Name: ? (1), exe path: c:\windows\system32\drivers\usbstor.sys, state: Stopped, startup: Manual - Name: ? (1), exe path: c:\windows\system32\drivers\usbuhci.sys, state: Stopped, startup: Manual - Name: ? (1), exe path: c:\windows\system32\drivers\usbvideo.sys, state: Running, startup: Manual - Name: ? (1), exe path: c:\windows\system32\drivers\usbxhci.sys, state: Running, startup: Manual - Name: ? (1), exe path: c:\windows\system32\drivers\fxppm.sys, state: Stopped, startup: Manual - Name: Driver Verifier Extension, exe path: c:\windows\system32\drivers\verifierext.sys, state: Stopped, startup: Manual - Name: vhdmp, exe path: c:\windows\system32\drivers\vhdmp.sys, state: Stopped, startup: Manual - Name: ? (1), exe path: c:\windows\system32\drivers\vmgencounter.sys, state: Stopped, startup: Manual - Name: Microsoft GPIO Class Extension Driver, exe path: c:\windows\system32\drivers\msgpioclx.sys, state: Stopped, startup: Manual - Name: VMBusHID, exe path: c:\windows\system32\drivers\vmbushid.sys, state: Stopped, startup: Manual - Name: ? (1), exe path: c:\windows\system32\drivers\hdaudio.sys, state: Running, startup: Manual - Name: ? (1), exe path: c:\windows\system32\drivers\hdaudbus.sys, state: Running, startup: Manual - Name: ? (1), exe path: c:\windows\system32\drivers\hidbatt.sys, state: Stopped, startup: Manual - Name: ? (1), exe path: c:\windows\system32\drivers\vpci.sys, state: Stopped, startup: Manual - Name: ? (1), exe path: c:\windows\system32\drivers\hidbth.sys, state: Stopped, startup: Manual - Name: ? (1), exe path: c:\windows\system32\drivers\hidi2c.sys, state: Stopped, startup: Manual - Name: Sterownik wirtualnej magistrali WiFi, exe path: c:\windows\system32\drivers\vwifibus.sys, state: Running, startup: Manual - Name: ? (1), exe path: c:\windows\system32\drivers\hidir.sys, state: Stopped, startup: Manual - Name: Virtual WiFi Miniport Service, exe path: c:\windows\system32\drivers\vwifimp.sys, state: Running, startup: Manual - Name: ? (1), exe path: c:\windows\system32\drivers\wacompen.sys, state: Stopped, startup: Manual - Name: Sterownik usługi Dostęp zdalny IP ARP, exe path: c:\windows\system32\drivers\wanarp.sys, state: Stopped, startup: Manual - Name: ? (1), exe path: c:\windows\system32\drivers\hidusb.sys, state: Running, startup: Manual - Name: Sterownik rozruchu usługi Windows Defender, exe path: c:\windows\system32\drivers\wdboot.sys, state: Stopped, startup: Manual - Name: Usługa HTTP, exe path: c:\windows\system32\drivers\http.sys, state: Running, startup: Manual - Name: Sterownik minifiltru usługi Windows Defender, exe path: c:\windows\system32\drivers\wdfilter.sys, state: Stopped, startup: Manual - Name: Sterownik systemowy usługi inspekcji sieci Windows Defender, exe path: c:\windows\system32\drivers\wdnisdrv.sys, state: Stopped, startup: Manual - Name: hyperkbd, exe path: c:\windows\system32\drivers\hyperkbd.sys, state: Stopped, startup: Manual - Name: WIMMount, exe path: c:\windows\system32\drivers\wimmount.sys, state: Stopped, startup: Manual - Name: ? (1), exe path: c:\windows\system32\drivers\wmiacpi.sys, state: Running, startup: Manual - Name: HyperVideo, exe path: c:\windows\system32\drivers\hypervideo.sys, state: Stopped, startup: Manual - Name: Family Safety Filter Driver, exe path: c:\windows\system32\drivers\wpcfltr.sys, state: Stopped, startup: Manual - Name: WPD Upper Class Filter Driver, exe path: c:\windows\system32\drivers\wpdupfltr.sys, state: Stopped, startup: Manual - Name: Sterownik Winsock IFS, exe path: c:\windows\system32\drivers\ws2ifsl.sys, state: Stopped, startup: Disabled - Name: User Mode Driver Frameworks Platform Driver, exe path: c:\windows\system32\drivers\wudfpf.sys, state: Stopped, startup: Manual - Name: ? (1), exe path: c:\windows\system32\drivers\wudfrd.sys, state: Stopped, startup: Manual - Name: ? (1), exe path: c:\windows\system32\drivers\wudfrd.sys, state: Stopped, startup: Manual 09) Critical files: * File: hosts * File: system.ini - [386Enh] - woafont=dosapp.fon - EGA80WOA.FON=EGA80WOA.FON - EGA40WOA.FON=EGA40WOA.FON - CGA80WOA.FON=CGA80WOA.FON - CGA40WOA.FON=CGA40WOA.FON - [drivers] - wave=mmdrv.dll - timer=timer.drv - [mci] * File: win.ini - [fonts] - [extensions] - [mci extensions] - [files] - [Mail] - MAPI=1 10) Scheduled tasks: - c:\program files\bitdefender\bitdefender\mtasklaunch.exe scantask - c:\windows\browserchoice\browserchoice.exe /createapptileandlaunch - c:\program files (x86)\hewlett-packard\hp support framework\hpsf.exe /taskrestart - c:\program files (x86)\hewlett-packard\hp support framework\hptuneup.exe - c:\program files (x86)\hewlett-packard\hp support framework\hpsf.exe /l analysis - c:\program files (x86)\hewlett-packard\hp support framework\hpsf.exe /l tuneuptimer - c:\programdata\hewlett-packard\hp support framework\resources\updater7\hpsfupdater.exe /s /p 1 - c:\program files (x86)\hewlett-packard\hp support framework\resources\hpwarrantycheck\hpwarrantychecker.exe - c:\program files (x86)\hewlett-packard\hp support framework\resources\hpwarrantycheck\hpwarrantychecker.exe /devicescanr6 - %windir%\system32\appidpolicyconverter.exe - %windir%\system32\appidcertstorecheck.exe - aitagent /increment - %windir%\system32\rundll32.exe aepdu.dll,aepdurunupdate -nolegacy - %windir%\system32\rundll32.exe aepdu.dll,aepdurunupdate - %windir%\system32\rundll32.exe startupscan.dll,susruntask - %windir%\system32\rundll32.exe windows.storage.applicationdata.dll,cleanuptemporarystate - %windir%\system32\rundll32.exe %windir%\system32\appxdeploymentclient.dll,appxprestagecleanupruntask - %windir%\system32\rundll32.exe /d acproxy.dll,performautochkoperations - bthudtask.exe $(arg0) - %systemroot%\system32\wsqmcons.exe - %windir%\system32\wsqmcons.exe -u - %windir%\system32\defrag.exe -c -h -o -$ - %windir%\system32\cleanmgr.exe /autoclean /d %systemdrive% - %windir%\system32\rundll32.exe dfdts.dll,dfdgetdefaultpolicyandsmart - %windir%\system32\dfdwiz.exe - %windir%\system32\locationnotifications.exe - %systemroot%\system32\mbaeparsertask.exe - %windir%\system32\lpremove.exe - %windir%\system32\gathernetworkinfo.vbs - %systemroot%\system32\drvinst.exe 6 - %windir%\system32\raserver.exe /offerraupdate - c:\windows\system32\mrt.exe /ehb /q - %windir%\system32\wpcmon.exe - %windir%\system32\spaceagent.exe - %windir%\system32\rundll32.exe sysmain.dll,pfsvwsswapassessmenttask - %windir%\system32\srtasks.exe executescheduledsppcreation - %windir%\system32\sc.exe start w32time task_started - %windir%\system32\tzsync.exe - sc.exe config upnphost start= auto - %windir%\system32\wermgr.exe -queuereporting - %windir%\system32\rundll32.exe bfe.dll,bfeonservicestarttypechange - "%programfiles%\windows media player\wmpnscfg.exe" - c:\windows\system32\sc.exe start wuauserv - c:\windows\system32\sc.exe start wuauserv - %systemroot%\system32\autoworkplace.exe join - rundll32.exe wsclient.dll,wsptlr licensing - rundll32.exe wsclient.dll,refreshbannedappslist - c:\windows\system32\msfeedssync.exe sync - c:\windows\system32\msfeedssync.exe sync - %windir%\system32\rundll32.exe portabledeviceapi.dll,#1 - %windir%\system32\rundll32.exe portabledeviceapi.dll,#1 - c:\windows\system32\pcalua.exe -a c:\users\hp_home\downloads\cwk252_setup_[www.programosy.pl].exe -d c:\users\hp_home\downloads