C:\windows\syswow64\ADVAPI32.dll
C:\windows\syswow64\COMDLG32.dll
C:\windows\syswow64\CRYPTBASE.dll
C:\windows\syswow64\GDI32.dll
C:\windows\syswow64\kernel32.dll
C:\windows\syswow64\KERNELBASE.dll
C:\windows\syswow64\LPK.dll
C:\windows\syswow64\MSCTF.dll
C:\windows\syswow64\msvcrt.dll
C:\windows\SysWOW64\ntdll.dll
C:\windows\SysWOW64\nvinit.dll
C:\windows\syswow64\ole32.dll
C:\windows\syswow64\OLEAUT32.dll
C:\windows\syswow64\RPCRT4.dll
C:\windows\SysWOW64\sechost.dll
C:\windows\syswow64\SHELL32.dll
C:\windows\syswow64\SHLWAPI.dll
C:\windows\syswow64\SspiCli.dll
C:\windows\syswow64\USER32.dll
C:\windows\syswow64\USP10.dll
C:\windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18201_none_ec80f00e8593ece5\COMCTL32.dll
--------------------
Autostart folders:
[Startup (3)]
desktop.ini
Dropbox.lnk
oawl99f.lnk
[User Startup (3)]
desktop.ini
Dropbox.lnk
oawl99f.lnk
[Common Startup (3)]
Adobe Gamma Loader.lnk
Bluetooth.lnk
desktop.ini
[User Common Startup (3)]
Adobe Gamma Loader.lnk
Bluetooth.lnk
desktop.ini
--------------------
Task Scheduler jobs (5):
Adobe Flash Player Updater.job
GoogleUpdateTaskMachineCore1ce80169cac8ff2.job
GoogleUpdateTaskMachineUA1cef16f91ad9948.job
Online Backup Update Notifier.job
SOS Online Backup -
[email protected]
--------------------
IniMapping values:
System NT shell = explorer.exe
--------------------
On-reboot actions:
BootExecute = autocheck autochk *
--------------------
Shell commands:
.bat - Windows Batch File - "%1" %*
.cmd - Windows Command Script - "%1" %*
.com - MS-DOS Application - "%1" %*
.exe - Application - "%1" %*
.hta - HTML Application - C:\Windows\SysWOW64\mshta.exe "%1" %*
.js - JavaScript File - C:\Windows\System32\WScript.exe "%1" %*
.jse - JScript Encoded File - C:\Windows\System32\WScript.exe "%1" %*
.pif - Shortcut to MS-DOS Program - "%1" %*
.scr - Screen saver - "%1" /S
.txt - Text Document - C:\windows\system32\NOTEPAD.EXE %1
.vbe - VBScript Encoded File - "C:\windows\System32\WScript.exe" "%1" %*
.vbs - VBScript Script File - "C:\windows\System32\WScript.exe" "%1" %*
.wsf - Windows Script File - "C:\windows\System32\WScript.exe" "%1" %*
.wsh - Windows Script Host Settings File - "C:\windows\System32\WScript.exe" "%1" %*
--------------------
Services:
[NT Services (75)]
@%ProgramFiles%\Windows Defender\MsMpRes.dll,-103 = C:\windows\System32\svchost.exe -k secsvcs
@%SystemRoot%\system32\audiosrv.dll,-200 = C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
@%SystemRoot%\system32\audiosrv.dll,-204 = C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
@%SystemRoot%\system32\bfe.dll,-1001 = C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
@%systemroot%\system32\browser.dll,-100 = C:\windows\System32\svchost.exe -k netsvcs
@%SystemRoot%\system32\cryptsvc.dll,-1001 = C:\windows\system32\svchost.exe -k NetworkService
@%SystemRoot%\system32\dhcpcore.dll,-100 = C:\windows\system32\svchost.exe -k LocalServiceNetworkRestricted
@%SystemRoot%\System32\dnsapi.dll,-101 = C:\windows\system32\svchost.exe -k NetworkService
@%systemroot%\system32\dps.dll,-500 = C:\windows\System32\svchost.exe -k LocalServiceNoNetwork
@%SystemRoot%\system32\dwm.exe,-2000 = C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
@%SystemRoot%\system32\efssvc.dll,-100 = C:\windows\System32\lsass.exe
@%systemroot%\system32\fdrespub.dll,-100 = C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
@%SystemRoot%\system32\FirewallAPI.dll,-23090 = C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
@%systemroot%\system32\FntCache.dll,-100 = C:\windows\system32\svchost.exe -k LocalService
@%SystemRoot%\system32\ikeext.dll,-501 = C:\windows\system32\svchost.exe -k netsvcs
@%SystemRoot%\system32\iphlpsvc.dll,-500 = C:\windows\System32\svchost.exe -k NetSvcs
@%SystemRoot%\system32\lmhsvc.dll,-101 = C:\windows\system32\svchost.exe -k LocalServiceNetworkRestricted
@%systemroot%\system32\mmcss.dll,-100 = C:\windows\system32\svchost.exe -k netsvcs
@%SystemRoot%\System32\nlasvc.dll,-1 = C:\windows\System32\svchost.exe -k NetworkService
@%SystemRoot%\system32\nsisvc.dll,-200 = C:\windows\system32\svchost.exe -k LocalService
@%SystemRoot%\system32\pcasvc.dll,-1 = C:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted
@%SystemRoot%\System32\polstore.dll,-5010 = C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
@%systemroot%\system32\profsvc.dll,-300 = C:\windows\system32\svchost.exe -k netsvcs
@%SystemRoot%\system32\samsrv.dll,-1 = C:\windows\system32\lsass.exe
@%SystemRoot%\system32\schedsvc.dll,-100 = C:\windows\system32\svchost.exe -k netsvcs
@%systemroot%\system32\SearchIndexer.exe,-103 = C:\windows\system32\SearchIndexer.exe /Embedding
@%SystemRoot%\system32\Sens.dll,-200 = C:\windows\system32\svchost.exe -k netsvcs
@%SystemRoot%\System32\shsvcs.dll,-12288 = C:\windows\System32\svchost.exe -k netsvcs
@%systemroot%\system32\spoolsv.exe,-1 = C:\windows\System32\spoolsv.exe
@%SystemRoot%\system32\sppsvc.exe,-101 = C:\windows\system32\sppsvc.exe
@%systemroot%\system32\srvsvc.dll,-100 = C:\windows\system32\svchost.exe -k netsvcs
@%SystemRoot%\system32\sysmain.dll,-1000 = C:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted
@%SystemRoot%\System32\themeservice.dll,-8192 = C:\windows\System32\svchost.exe -k netsvcs
@%SystemRoot%\system32\trkwks.dll,-1 = C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
@%SystemRoot%\system32\umpnpmgr.dll,-100 = C:\windows\system32\svchost.exe -k DcomLaunch
@%SystemRoot%\system32\umpo.dll,-100 = C:\windows\system32\svchost.exe -k DcomLaunch
@%SystemRoot%\system32\vaultsvc.dll,-1003 = C:\windows\system32\lsass.exe
@%Systemroot%\system32\wbem\wmisvc.dll,-205 = C:\windows\system32\svchost.exe -k netsvcs
@%SystemRoot%\system32\wevtsvc.dll,-200 = C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
@%SystemRoot%\system32\wiaservc.dll,-9 = C:\windows\system32\svchost.exe -k imgsvc
@%systemroot%\system32\wkssvc.dll,-100 = C:\windows\System32\svchost.exe -k NetworkService
@%SystemRoot%\System32\wlansvc.dll,-257 = C:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted
@%SystemRoot%\System32\wscsvc.dll,-200 = C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
@%systemroot%\system32\wuaueng.dll,-105 = C:\windows\system32\svchost.exe -k netsvcs
@%SystemRoot%\System32\wwansvc.dll,-257 = C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
@%windir%\system32\RpcEpMap.dll,-1001 = C:\windows\system32\svchost.exe -k RPCSS
@comres.dll,-2450 = C:\windows\system32\svchost.exe -k LocalService
@gpapi.dll,-112 = C:\windows\system32\svchost.exe -k netsvcs
@oleres.dll,-5010 = C:\windows\system32\svchost.exe -k rpcss
@oleres.dll,-5012 = C:\windows\system32\svchost.exe -k DcomLaunch
Adobe Acrobat Update Service = "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
Apple Mobile Device = "C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
Application Virtualization Client = "C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe"
Bluetooth Service = C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe
Bonjour Service = "C:\Program Files\Bonjour\mDNSResponder.exe"
Canon Inkjet Printer/Scanner/Fax Extended Survey Program = C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE
Client Virtualization Handler = "C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE"
ESET Service = "C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe"
Google Update Service (gupdate) = "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc
Intel(R) Management and Security Application Local Management Service = C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
Intel(R) Management and Security Application User Notification Service = "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
Intel(R) PROSet/Wireless Event Log = C:\Program Files\Intel\WiFi\bin\EvtEng.exe
Intel(R) PROSet/Wireless Registry Service = C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
Intel(R) Rapid Storage Technology = "C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
MBAMScheduler = "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe"
MBAMService = "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe"
Microsoft .NET Framework NGEN v4.0.30319_X64 = C:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
Microsoft .NET Framework NGEN v4.0.30319_X86 = C:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
MSCamSvc = "C:\Program Files\Microsoft LifeCam\MSCamS64.exe"
NVIDIA Driver Helper Service = C:\windows\system32\nvvsvc.exe
NVIDIA Update Service Daemon = C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
RealNetworks Downloader Resolver Service = "C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe"
UMVPFSrv = C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
vToolbarUpdater15.3.0 = C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.3.0\ToolbarUpdater.exe
Windows Live ID Sign-in Assistant = "C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
[SafeBoot services (Minimal boot)]
* CD-ROM Drive *
{4D36E965-E325-11CE-BFC1-08002BE10318}
* DiskDrive *
{4D36E967-E325-11CE-BFC1-08002BE10318}
* Driver *
sermouse.sys
vga.sys
vgasave.sys
volmgr.sys
volmgrx.sys
WudfPf
WudfRd
* Driver Group *
Base
Boot Bus Extender
Boot file system
File system
Filter
PCI Configuration
PNP Filter
Primary disk
SCSI Class
System Bus Extender
* Floppy disk drive *
{4D36E980-E325-11CE-BFC1-08002BE10318}
* Hdc *
{4D36E96A-E325-11CE-BFC1-08002BE10318}
* Human Interface Devices *
{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}
* IEEE 1394 Bus host controllers *
{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}
* Keyboard *
{4D36E96B-E325-11CE-BFC1-08002BE10318}
* Mouse *
{4D36E96F-E325-11CE-BFC1-08002BE10318}
* PCMCIA Adapters *
{4D36E977-E325-11CE-BFC1-08002BE10318}
* SBP2 IEEE 1394 Devices *
{D48179BE-EC20-11D1-B6B8-00C04FA372A7}
* SCSIAdapter *
{4D36E97B-E325-11CE-BFC1-08002BE10318}
* SecurityDevices *
{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}
* Service *
AppInfo
AppMgmt
CryptSvc
DcomLaunch
EFS
EventLog
HelpSvc
KeyIso
Netlogon
NTDS
PlugPlay
Power
ProfSvc
RpcEptMapper
RpcSs
sacsvr
SWPRV
TabletInputService
TBS
TrustedInstaller
VDS
vmms
WinDefend
WinMgmt
WudfSvc
* Standard floppy disk controller *
{4D36E969-E325-11CE-BFC1-08002BE10318}
* System *
{4D36E97D-E325-11CE-BFC1-08002BE10318}
* Universal Serial Bus controllers *
{36FC9E60-C465-11CF-8056-444553540000}
* Volume *
{71A27CDD-812A-11D0-BEC7-08002BE2092F}
* Volume shadow copy *
{533C5B84-EC70-11D2-9505-00C04F79DEAF}
[SafeBoot services (Minimal boot + network support)]
* CD-ROM Drive *
{4D36E965-E325-11CE-BFC1-08002BE10318}
* DiskDrive *
{4D36E967-E325-11CE-BFC1-08002BE10318}
* Driver *
bowser
dfsc
ipnat.sys
MPSDrv
mrxsmb
mrxsmb10
mrxsmb20
ndiscap
nsiproxy.sys
rdbss
rdpencdd.sys
sermouse.sys
vga.sys
vgasave.sys
volmgr.sys
volmgrx.sys
WudfPf
WudfRd
WudfUsbccidDriver
* Driver Group *
Base
Boot Bus Extender
Boot file system
File system
Filter
NDIS
NDIS Wrapper
NetBIOSGroup
NetDDEGroup
Network
NetworkProvider
PCI Configuration
PNP Filter
PNP_TDI
Primary disk
SCSI Class
Streams Drivers
System Bus Extender
TDI
* Floppy disk drive *
{4D36E980-E325-11CE-BFC1-08002BE10318}
* Hdc *
{4D36E96A-E325-11CE-BFC1-08002BE10318}
* Human Interface Devices *
{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}
* IEEE 1394 Bus host controllers *
{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}
* Keyboard *
{4D36E96B-E325-11CE-BFC1-08002BE10318}
* Mouse *
{4D36E96F-E325-11CE-BFC1-08002BE10318}
* Net *
{4D36E972-E325-11CE-BFC1-08002BE10318}
* NetClient *
{4D36E973-E325-11CE-BFC1-08002BE10318}
* NetService *
{4D36E974-E325-11CE-BFC1-08002BE10318}
* NetTrans *
{4D36E975-E325-11CE-BFC1-08002BE10318}
* PCMCIA Adapters *
{4D36E977-E325-11CE-BFC1-08002BE10318}
* SBP2 IEEE 1394 Devices *
{D48179BE-EC20-11D1-B6B8-00C04FA372A7}
* SCSIAdapter *
{4D36E97B-E325-11CE-BFC1-08002BE10318}
* SecurityDevices *
{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}
* Service *
AFD
AppInfo
AppMgmt
BFE
Browser
CryptSvc
DcomLaunch
Dhcp
DnsCache
Dot3Svc
Eaphost
EFS
EventLog
HelpSvc
IKEEXT
KeyIso
LanmanServer
LanmanWorkstation
LmHosts
Messenger
MPSSvc
NativeWifiP
Ndisuio
NetBIOS
NetBT
Netlogon
NetMan
netprofm
NlaSvc
Nsi
NTDS
PlugPlay
PolicyAgent
Power
ProfSvc
rdsessmgr
RpcEptMapper
RpcSs
sacsvr
SCardSvr
SharedAccess
SWPRV
TabletInputService
TBS
Tcpip
TrustedInstaller
VaultSvc
VDS
vmms
WinDefend
WinMgmt
Wlansvc
WudfSvc
* Smart card readers *
{50DD5230-BA8A-11D1-BF5D-0000F805F530}
* Standard floppy disk controller *
{4D36E969-E325-11CE-BFC1-08002BE10318}
* System *
{4D36E97D-E325-11CE-BFC1-08002BE10318}
* Universal Serial Bus controllers *
{36FC9E60-C465-11CF-8056-444553540000}
* Volume *
{71A27CDD-812A-11D0-BEC7-08002BE2092F}
* Volume shadow copy *
{533C5B84-EC70-11D2-9505-00C04F79DEAF}
[SafeBoot: Alternate shell]
cmd.exe (not enabled)
--------------------
Driver filters:
[Class filters]
* Disk drives *
- Upper filters
LHDmgr.sys
PartMgr.sys
* DVD/CD-ROM drives *
- Upper filters
GEARAspiWDM.sys
* Imaging devices *
- Upper filters
ksthunk.sys
* Infrared devices *
- Upper filters
IRENUM.sys
* Keyboards *
- Upper filters
kbdclass.sys
* Medium Changer devices *
- Upper filters
GEARAspiWDM.sys
* Mice and other pointing devices *
- Upper filters
mouclass.sys
* Smart card readers *
- Upper filters
scfilter.sys
* Sound, video and game controllers *
- Upper filters
ksthunk.sys
* Storage Volumes *
- Lower filters
fvevol.sys
rdyboost.sys
* Tape drives *
- Upper filters
GEARAspiWDM.sys